Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
CF-RAY
ETag
X-XSS-Protection
Accept-Ranges
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-Served-By
X-UA-Compatible
P3P
X-Xss-Protection
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
X-FRAME-OPTIONS
Access-Control-Allow-Credentials
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
P3p
Accept-CH
X-DNS-Prefetch-Control
X-Cache-Status
X-Drupal-Cache
X-Ua-Compatible
Accept-CH-Lifetime
X-Check
X-Generator
X-Cacheable
Server-Timing
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Iinfo
X-Request-ID
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
X-Content-Security-Policy
Feature-Policy
Content-Encoding
X-CDN
Status
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
X-Amz-Id-2
CF-Ray
Host-Header
Allow
Cf-Edge-Cache
X-Backend
Request-Context
X-UA-Device
X-Robots-Tag
Keep-Alive
X-Server
X-Cache-Group
X-Hacker
X-AH-Environment
X-Turbo-Charged-By
X-Ws-Request-Id
X-Proxy-Cache
X-Age
Xkey
X-Rq
X-Vhost
EagleId
X-Dispatcher
X-Server-Powered-By
X-Amz-Version-Id
X-Varnish-Cache
Grace
Cf-Apo-Via
X-Dns-Prefetch-Control
X-LiteSpeed-Cache
X-Page-Speed
X-Pingback
X-Swift-CacheTime
X-Swift-SaveTime
Cf-Railgun
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
EagleEye-TraceId
Ali-Swift-Global-Savetime
X-Aws-Lambda-Call-Status
X-WebKit-CSP
X-CST
X-OneAgent-JS-Injection
X-Backend-Server
Permissions-Policy
X-Readtime
X-Server-Id
X-Response-Time
X-Host
X-Akam-SW-Version
Request-Id
Surrogate-Control
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-HW
X-Nginx-Upstream-Cache-Status
X-Cloud-Trace-Context
Accept-Ch-Lifetime
X-Nginx-Cache-Status
X-Node
X-Litespeed-Cache
X-Cache-Lookup
X-Application-Context
X-Country-Code
X-Trace
Content-Location
X-Ruxit-JS-Agent
X-Oneagent-Js-Injection
X-Country
Service-Worker-Allowed
X-Url
X-Content-Type
X-Clacks-Overhead
X-Origin-Cache-Key
X-Edge
X-Rack-Cache
X-Amz-Server-Side-Encryption
X-ECACHE
X-Mcache
Cross-Origin-Opener-Policy
X-FTR-Request-ID
Cache-Tag
X-Mod-Pagespeed
X-Midtier
Accept-Ch
Nginx-Cache
X-MS-InvokeApp
X-PC
X-Upstream
X-Vname
X-TtlSet
X-ESI
X-Powered-By-Plesk
Rating
Edge-Control
X-Browser-Type
X-Server-Name
X-D2id
X-Element-Page-Cache
Verso
X-Times
X-Kinja-Build
X-Kinja-Server
X-GoogleNews-Bot
X-Kinja-Revision
X-Exp-Variant
X-Kinja
X-Cdn-Fetch
X-Exp-Id
X-Cnection
X-Ac
SPIisLatency
SPRequestDuration
AR-PoweredBy
X-Ruxit-Js-Agent
AR-SID
AR-ATIME
AR-Request-ID
X-B3-TraceId
X-Abt-Application-Version
X-SharePointHealthScore
SPRequestGuid
X-Navigation-Version
X-Vcap-Request-Id
X-NF-Request-ID
X-Dw-Request-Base-Id
X-GitHub-Request-Id
X-Ser
X-NWS-LOG-UUID
AR-CACHE
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
X-Mg-S
X-VARITI-CCR
X-RateLimit-Remaining
S
Pagespeed
X-Middleton-Display
Display
X-Client-IP
X-Sol
Edge-Cache-Tag
RTSS
X-Cache-Key
X-Server-ID
X-Ttl
Fastly-Restarts
X-Amzn-Trace-Id
X-Amz-Rid
X-Cache-TTL
X-Powered-CMS
X-Goog-Hash
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Instrumentation
X-Kraken-Loop-Name
X-Kinsta-Cache
Cache-Status
X-Edge-Location-Klb
X-Version
Access-Control-Request-Method
X-Recruiting
Origin-Trial
X-ARC
X-Varnish-TTL
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-Content-Security-Policy-Report-Only
X-Content-Digest
X-TraceId
X-Middleton-Response
Response
X-Webkit-Csp
Arr-Disable-Session-Affinity
X-Forwarded-For
X-T
X-MSEdge-Ref
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Content-MD5
MicrosoftSharePointTeamServices
TP-Cache
X-Accel-Expires
X-Hits
X-Shield-Request-Id
X-Cached
Public-Key-Pins
X-Daa-Tunnel
X-Id
Front-End-Https
Cross-Origin-Resource-Policy
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Backend
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-Expires
MS-Author-Via
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Cache-Config
Payment
X-Ua-Browser
Server-Node
X-Request-Processing-Time
X-Request-Received
X-DIS-Request-ID
X-Frontend
X-Fastcgi-Cache
X-Forwarded-Proto
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-LLID
X-GUploader-UploadID
Realpath
TP-L2-Cache
X-Protected-By
X-FastCGI-Cache
X-LB-Cache
Cache-Tags
X-RateLimit-Limit
X-Amz-Apigw-Id
X-ORACLE-DMS-RID
X-Amzn-RequestId
X-Distributor
X-Origin-Server
X-Request-Handler-Origin-Region
X-Microsite
Count-Hit
X-Page-Id
X-F-Cache
X-Hostname
X-Cluster-Name
X-Az
X-AppVersion
X-Activity-Id
Mrf-Cache-Status
X-Varnish-Backend
X-B3-TraceId-Primal
Referer-Policy
MRF-Tech
X-Kong-Proxy-Latency
X-Debug-Info
X-Kong-Upstream-Latency
X-Correlation-Id
Accept-Charset
X-NGENIX-Cache
X-Www-Served-By
Fastcgi-Cache
X-Geo-Country
X-Ratelimit-Limit
X-PressLabs-Stats
X-App-Server
X-Envoy-Decorator-Operation
X-Varnish-Server
Host
X-Goog-Metageneration
X-ORACLE-DMS-ECID
X-WebKit-CSP-Report-Only
X-Ua-Device
X-FB-Debug
X-TTL
Access-Control-Allow-Method
X-XRDS-LOCATION
X-Git-Hash
X-Kinja-CCPA
Retry-After
X-Fastly-Request-Id
X-Upgrade-Enabled
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Load-Cache
X-RateLimit-Reset
Server-Name
X-Oracle-Dms-Ecid
X-CSRF-Token
X-Content-Options
X-Ezoic-Cdn
X-Tt-Trace-Host
X-Rid
X-Px
X-Tt-Trace-Tag
X-Contextid
TCN
X-Request-Guid
X-Seen-By
Charset
X-Revision
X-Datadog-Trace-Id
X-Datadog-Parent-Id
X-Varnish-Ttl
X-Trace-Id
X-Datadog-Sampling-Priority
X-Cache-Control
X-Type
DC
X-Amz-Meta-S3cmd-Attrs
X-B-Cache
X-Signature
Section-Io-Cache
X-Grace
X-B3-Sampled
Paypal-Debug-Id
Cleartype
X-App-Environment
X-B
X-TT
X-Whom
X-Wix-Request-Id
Healthy
X-Oracle-Dms-Rid
X-Fb-Rlafr
X-Origin-Cache
X-ASPNET-VERSION
X-Ratelimit-Remaining
X-Mobile
X-EdgeConnect-Cache-Status
Frame-Options
X-Providence-Cookie
X-Node-Name
X-Amz-Replication-Status
X-Aspnet-Duration-Ms
X-Flags
X-Is-Crawler
X-Route-Name
X-Magnolia-Registration
X-Newrelic-App-Data
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Language
X-Logged-In
Filterid
X-Azure-Ref
X-Proxy
X-N
X-Air-Pt
X-Fastly-Request-ID
Content-Disposition
Akamai-GRN
Backend
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-NODE
X-App-Version
X-Template
X-Response-Served-From
NGB
X-Original-Request-Id
Upgrade-Insecure-Requests
SD-X-WS
X-Proxy-Cache-Info
X-Is-Bot
X-Rendered-As
Refresh
X-Yottaa-Optimizations
VIX-Pulpo-Node
X-Yottaa-Metrics
VIX-Pulpo-Upstream-Status
X-Instance
X-Tumblr-Pixel-1
X-Datadog-Sampled
X-Tumblr-User
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Servername
Liferay-Portal
X-Debug
X-FW-Type
X-FW-Version
X-FW-Static
X-FW-Server
Viewport
X-FW-Serve
X-FW-Hash
X-FW-Dynamic
X-ProcessESI
X-Amzn-Remapped-Content-Length
X-Unique-Id
X-Varnish-Grace
X-RTag
X-RemovedCookies
Ms-Operation-Id
X-UUID
MS-CV
X-Debug-IsPreview
X-Debug-IsConnected
X-Adobe-Content
X-IPS-LoggedIn
X-Adobe-Loc
X-Cache-Grace
Fastly-SIE
Fastly-SWR
X-Rule
X-Cacheable-TTL
X-User-Agent
X-G
X-Region
X-NYM-Debug-Backend
X-Device-Type
Url
X-Environment-Context
X-Cache-Age
X-Cache-Hit
X-Backend-Name
X-L-Path
X-Hl-Ver
X-Status
Country
X-Time
From-Origin
ServerID
X-Jobs
X-B3-SpanId
X-Page-View
Countrycode
X-Via-JSL
X-Origin-CC
Surrogate-Key
X-Origin-TTL
X-VC-Cache
X-Hosted-By
X-Webkit-CSP
X-INCAP-ABP
X-Air-Source
Alternate-Protocol
WPO-Cache-Status
X-Air-Trace-Id
WPO-Cache-Message
Amp-Access-Control-Allow-Source-Origin
X-Air-Hostname
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-HTML-Minification-Powered-By
X-Cache-Status-Check
Version
X-Content-Powered-By
X-Akamai-Request-ID2
Protected
GEO-INFO
CDN-RequestId
X-Rocket-Nginx-Serving-Static
X-Nginx-Cache
SRV
X-Source
X-Akamai-Edgescape
X-Http-Reason
X-WP-CF-Super-Cache-Active
X-B3-Traceid
X-Storage
X-Accel-Version
X-Framework
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
Access-Control-Request-Headers
X-VC
X-Edge-Location
X-Cache-Rule
CF-IPCountry
X-CDN-Forward
Front
OT-Force-Account-Verify
X-Real-IP
X-Mode
X-Xfnlog-Site
X-Rewrite-Enabled
X-Upstream-Ct
Webserver
Meta-Geo
X-Rn-Rsrv
X-Upstream-Ht
X-Cache-Operation
Filters
X-UPSTREAM-Address
Accept-Language
X-JoinUs
Xet-Cookie
X-SaId
X-Httpd
X-Director
X-Cache-Debug
X-Endurance-Cache-Level
X-Web-Node
X-Use-Mantle
X-Tumblr-Pixel-2
X-Worker
X-Logging-Id
ServedBy
X-Cache-Time
X-Tumblr-Pixel-3
X-Varnish-Cache-Hits
X-Served-From
X-Proxy-Build
Selected-Fe
X-Handled-By
X-Say-Cacheable
X-Origin
X-Say-TTL
X-SayCDN-TTL
X-Soup
X-Timing-Wait
X-Detected-As
X-Restarts
X-GeoCode
X-Loop
Xserver
X-Tncms
Web-Mar-Node
X-PHP-Host
Azure-Version
X-Varnish-Age
X-Format
Azure-SlotName
Azure-SiteName
Azure-InstanceId
Azure-RegionName
X-ServerID
X-VCT
X-Adobe-Source
X-Labrador-Cache-Channel
X-BYPASS-REASON
X-ProxyCache-Status
X-Redis-Cache
X-ProxyCache-Key
X-GeoCountry
X-Lambda-Id
X-Cms-Context
X-Tb
TWC-Connection-Speed
X-Vercel-Id
Section-Io-Id
X-Container-Uri
X-Server-W
X-Vercel-Cache
X-Git-Commit
X-Generation-Time
X-RM-Cache-TTL
TWC-GeoIP-Country
X-No-Session
Webcakes-App-Version
X-IPLB-Instance
X-IPLB-Request-ID
Webcakes-Region
Webcakes-App-Name
TWC-Privacy
TWC-GeoIP-LatLong
TWC-Device-Class
TWC-Locale-Group
X-Varnish-Beresp-Grace
X-Origin-Hint
Apigw-Requestid
Property-Id
X-VWS-Id
X-Vcache
X-Skip-Cache
X-AWS-Id
X-DynaTrace
Node
X-Cache-Host
X-Reqid
X-Provided-By
X-LJ-Flow-ID
X-Frame-Option
X-Cache-Server
X-Cluster
Mn-Server-Ip
Cross-Origin-Embedder-Policy
X-Browser-Name
X-AB
AMP-Access-Control-Allow-Source-Origin
X-Is-Mobile
X-Routing-Service
X-Proxied
X-Site-Version
X-Uri
DB-Nickname
X-Forwarded-Host
X-Locale
X-Extlb
X-Is-Supported-Browser
X-Is-Desktop
X-Is-Tablet
X-S
X-Tcp-Rtt
X-Geo-Region
X-Zipkin-Id
X-Ms-Version
X-Ms-Request-Id
X-R9-Blue-Green-Version
X-Webstats-RespID
X-Platform-Router
X-Platform-Cluster
X-RCS-CacheZone
X-Platform-Processor
X-Fetched-On
X-Drupal-Cache-Tags
X-MP-GENERATED-AT
X-Sql-Count
X-Drupal-Cache-Contexts
X-Sql-Duration-Ms
X-TT-LOGID
Cache-Tv-Group
X-Xrds-Location
WP-Super-Cache
X-Origin-Date
Fastcgi-Useragent
CDN-RequestPullSuccess
Source
X-XRDS-Location
X-FB-TRIP-ID
CDN-Uid
CDN-RequestPullCode
CDN-Cache
CDN-RequestCountryCode
CDN-CachedAt
CDN-PullZone
CDN-EdgeStorageId
X-Vcl-Version
Content-Secure-Policy
X-Alternate-Cache-Key
X-Storefront-Renderer-Rendered
X-Sucuri-Cache
X-Shopify-Stage
Priority
X-Use-Magma
X-Generated-By
Onion-Location
X-Sucuri-ID
X-ShardId
X-Sorting-Hat-PodId
X-ShopId
X-Sorting-Hat-ShopId
X-Content-Age
X-Urbn-Site-Id
X-Cdn-Origin
X-Urbn-Context-Path
Locale
X-SRV
Sid
S-Rt
WZWS-RAY
X-Pass-Why
Cross-Origin-Embedder-Policy-Report-Only
X-Newrelic-Synthetics
X-Buckets
X-Cluster-Node
X-Ua
X-Shield-Cache-Expires
X-Thinkindot-L3
Thinkindot-CacheControl-Type
TDXMobile
Thinkindot-CacheControl
Thinkindot-Control
X-CMSURLCustom
X-Scope-Id
X-Varnish-Beresp-Ttl
X-Proxy-Cache-Status
Cache
X-DataDome
Atl-Traceid
X-Cache-Action
X-LSADC-Cache
Cross-Origin-Window-Policy
X-Cache-Expired-At
X-GEO
HostName
X-COUNTRY
X-Via-SSL
X-WP-CF-Super-Cache-Cookies-Bypass
X-Via-CDN
Edge-Copy-Time
X-Via-Edge
Lang
X-A-Wwc
X-BCube-Filmed-By
X-A-Dam
X-Rojux
X-A-Dgt
DCR-Decision-By
X-Cache-Bucket
X-Viewer-Country
X-A-Dcw
X-ScT
X-Epic-Correlation-Id
X-Bl-Debug
X-SRCache-Key
X-Aed
Rendered-Blocks
X-B-Cookie
X-Application
Gannett-Cam-Experience-Id
X-S-Cookie
X-Bc-Bl
X-Vdms-Version
Surrogated-Key
X-Request-URI
X-Conf
X-Vdms-Path
X-Cache-NE
X-External-Request-Id
CDCHOST
X-Optimistic-Header
X-Developer
Ngx.Var.Host
X-Ec-Custom-Error
DCR-Processing-Time-Ms
X-Destination
MD5-Digest
X-D
Origin-Agent-Cluster
X-TIM-N
Origin
Type
X-Ec-Fail
X-Vtex-Remote-Cache
X-A
Meta-Geo-Continent
Candidate-Md5Url
X-A-Ccd
X-Ec-GeoHdr
Sslversion
Ngx-Var-Key
Redirect-Candidate
T-Server
X-Aspnetmvc-Version
Fastly-Drupal-HTML
X-Mg-Request-UUID
Apple-News-Services-Request-Url
X-GeoIP-Country-Code
Cluster
Fastly-GeoIP-CountryCode
X-GeoIP-Region-Code
X-Cache-Info
Apple-News-Services-Handled
Environment
X-Clientip
DSUID
Fastly-SSL
X-Debug-Cache-Store
X-Debug-Cache-Fetch
Apple-News-Services-Host
X-Gdpr
X-Forwarded-Site
Apple-News-Services-Parsed-Url
L
X-We-Are-Hiring
Server-Host
X-SD-PageType
X-Request-Start
X-Varnish-Hostname
X-PAYTM-SRV-ID
X-VCache
X-Human
X-Origin-Time
X-Platform
V-Age
X-Scheme
Server-Hostname
Sever-Int
X-SB
Server-Ext
X-Correlation-ID
X-Proxied-Request
X-Pubstack
Release
X-Section
Vix-Hermes-Req-Id
X-Varnish-Beresp-Status
X-Access
X-Nyt-Route
X-Varnish-Director
Host-ID
X-Instance-Name
X-Loc
X-VG-WebCache
Req-ID
X-VServer
X-Node-Id
Magicmarker
X-TH-Server
X-Connection-Hash
Expiry
User-Cache-Control
X-TimeS
X-Origin-Response-Time
X-Datadome
X-Auto-Login
Web-Mar-Region
X-B3-Trace-ID
X-Acquia-Purge-Cdn-Unconfigured
True-Client-Country-4JS
We-Hiring
Ssr
X-Level-Front-Cache
X-Op-Id-All
X-Policy
X-Pool
X-Mly-Id
X-VG-TLSProxy
X-WA-Info
X-UA-Device-Type
X-Mvc-Supplant-Cachable
X-Mvc-Supplant-OutputCached
A
X-Gzip
X-Esi-Check
X-Request-Time
X-Cache-Id
X-Rocket-Build-Number
X-Thanos
X-Request-Host
X-Req
X-Dispatcher-Server
X-Core-Value
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Moov-Xdn-Version
X-Var-Ttl
X-Generated-On
X-GoCache-CacheStatus
X-Hnp-Log
X-HS-Content-Campaign-Id
X-Gen-Mode
X-FC-Vary-Parameters
X-Block-Status
X-Cache-Aspx
X-Contensis-Viewer-Groups
X-Fastly-Cache
X-Irp-Debug
X-SVT-ORM-RULES
X-Server-IP
X-Zen-Fury
X-Varnish-Authentication
X-Moov-T
X-Sigma
X-Sigma-Backend
X-Men
X-SVT-ORM-VERSION
X-Varnishpool
X-Bip
X-BBC-Edge-Cache-Status
C-Via
Req-Svc-Chain
Pramga
On-Server
Mail-Subject
Gh-Request-Id
Cache-Provider
X-TA-CDN-Provider
X-Service
Platform
Content-Script-Type
X-Fmm-Version
Click-Count-Action-Start
X-Device-Os
X-Fastly-Backend
Content-Style-Type
NM-Fastcgi-Cache
X-Cdn-Srv
X-Geo-Header
Canary
X-Cache-Date
Is-Eu
X-Nginx-Cache-Key
X-Micro-Cache
X-DC
X-Wikidot-Backend
X-Up
X-V-Cache
X-NMSegId
X-Old-Content-Length
X-Wikidot-Static-Cache
X-Amz-Meta-Cb-Modifiedtime
X-Org
Click-Count-Error
X-NCache
X-PERF
X-Proto
X-Cache-TTL-Remaining
Adler-Geo
X-GeoIP
X-GeoIP-City
Machine
Producers
Uber-Trace-Id
Tube-Return
X-Dc
X-Aicache-OS
X-DPWN-IS-SECURE
Wxu-Next-Region
Wxu-Next-Hostname
Wxu-Next-Commit
X-App-Name
X-ApacheServer
X-Ad-Load-Variation
Tube-Got-Results
Country-Code
Tube-Got-Eval
X-Branch-Name
Tube-Get-Contents
X-Parent-Response-Time
Cdn-Request-Time
Cdnsip
Cf-Device-Type
Yak-Timeinfo
X-Edge-Server
X-ND-Cache
X-Hash
X-AK-Request-ID
X-Slack-Shared-Secret-Outcome
X-Test
RNT-Machine
Locid
RNT-Time
X-From
Cdn-Host
X-Sn-Servicetimems
W
X-Slack-Backend
Cdncip
X-Csrf-Jwt
Ha-Gx-Prefs
L5d-Success-Class
Esi-Enabled
AKAMAI
Cache-Key
X-CGP
Proxy-Firewall
X-CacheTTL
HA-Ipaddr
X-Eu-Site
Fastly-Backend-Name
IsBot
X-Ah-Environment
X-Region-Sid
X-Core-Mission
X-SIPLIST1
X-Accel-Expires-Debug
X-Ratelimit-Reset
X-Tx-Id
Pics-Label
X-Date
NGX
X-ZONE
X-Azure-Ref-OriginShield
Datacenter
PFcat
X-Backend-Instance
X-Amz-Storage-Class
X-LB-ID
X-Qloud-Router
LB
X-VarnishDD-TTL
X-Via-Poph
X-HN
X-HA-Backend
X-Via-Popv
X-Owner
X-Via-Popn
X-CF-Lambda-Fn
Cdn
X-Refresh
Expect-Staple
X-LB-NoCache
XM
X-Servedbyhost
X-Tb-Optimization-Total-Bytes-Saved
X-CACHE-GROUP
X-CF-Lambda-Version
N-Cache
X-Shop-Environment
X-API-Version
X-DynaTrace-JS-Agent
Xc-Version
X-Cache-Type
X-NGINX-Cache
X-Cache-Backend
X-Orig-Expires
X-Forwarded-Path
NtCoent-Length
X-Tenant
X-Varnish-Hits
X-Origin-Expires
X-VHOST
X-Lagoon
GeoIp-Country-Code
X-CDN-Cache-Status
X-Wa
RATING
X-Nc
X-Gamma-Serve
Cdn-Requestid
X-ECache
SID
CPC-Cache
CPC-Age
Cmsid
Cmstype
X-Srv
CloudFront-Viewer-Country
Server-ID
X-Vmg-Version
Resin-Trace
X-Zone
X-Nananana
X-Cdn-Diag
X-Tt-Logid
X-Akamai-Transformed
X-TX-ID
X-Fpc
Cross-Origin-Opener-Policy-Report-Only
X-UA
X-Hit
X-Via-Fastly
Uri
X-LAGOON
User-Agent
X-TIME
X-B3-Parentspanid
X-Proxy-CacheRZ
XkeyRZ
GeoIP-Latitude
CacheControlHeader
X-Nf-Request-Id
Cache-Hits
X-Client-Ip
X-RID
X-Api-Version
X-Variation
X-Presslabs-Stats
X-Ig-Origin-Region
X-URL
X-NewRelic-App-Data
Fusion-Content-Id
Fusion-Component-Id
Fusion-Content-Source
Fusion-Template-Id
Fusion-Source
Fusion-Deployment-Id
MIME-Version
X-Amz-Meta-Opti
DataCenter
X-Fastly-Country-Code
X-Location
X-Info
X-DataCenter
Tcn
Powered-By
True-Client-Ip
X-Datacenter
Lb
VNS-Cache
X-CACHE-AGE
True-Client-IP
X-Cloudmap
VNS-Age
X-NWS-UUID-VERIFY
X-Dynatrace-Js-Agent
X-HostName
X-B3-Spanid
X-CUA
Origin-EX
Origin-CC
Mime-Version
X-Jungle-Id
X-LiteSpeed-Tag
X-Geo
Fastly-Drupal-Html
X-CS
X-LiteSpeed-Cache-Control
Cf-Ipcountry
X-Cached-By
X-IAuth-Set-Uid
Cache-Name
X-Cdn-Forward
Hostname
X-Segment-20210421
X-HOST
X-User
X-Vc
Srv
X-Webkit-Csp-Report-Only
Load-Balancing
X-CSRF-TOKEN
X-Varnish-Beresp-TTL
Cl-Cache
X-Render-Time
X-AIR-PT
Debug
X-Dispatcher-Number
X-VTEX-Cache-Time
X-VTEX-Cache-Server
X-Powered-By-VTEX-Cache
CDN
X-Mid
Edge-Cache
X-FPC
X-MCACHE
X-Wormhole-Sdk
X-Auth-Group-Type
GeoIP-Country-Code
X-Dispatch
Ohc-File-Size
Server-Id
X-Esi
X-Litespeed-Tag
X-Cdn-Cache-Status
X-NC
X-Ig-Push-State
X-WA
X-Oracle-DMS-ECID
BehaviorPad-Version
Ohc-Cache-HIT
X-Cs
Odigeo-Trace-Id
X-ServedByHost
X-NodeID
X-APP-VERSION
X-Lb-Nocache
X-Cache-Ttl
CountryCode
X-Vgn-Hpd-Reason
X-Custom-Header
X-Fastly-Backend-Reqs
YJS-ID
X-Cache-Enabled
X-Lb-Id
X-VCL-Version
X-Litespeed-Cache-Control
Ms-Author-Via
My-App
X-Depends
Xkeylog
Location
X-Snapshot-Date
X-Via-PopV
X-Via-PopN
Server-Info
X-PHP-Backend
X-Via-PopH
X-Cdn-Request-ID
Xkey-La3
X-MSEdge-Features
X-Akamai-Pragma-Client-IP
X-MiniProfiler-Ids
X-MSEdge-Flight
X-Ha-Backend
X-Proxy-Cache-La3
X-Pad
X-Acquia-Application-Trace
X-Acquia-Application-UUID
Time
Memory
CF-Ctrl
X-Acquia-Purge-Tags
X-Acquia-Site
X-Wp-Cf-Super-Cache
FSS-Cache
X-Internal-Host
X-Varnish-Remaining-TTL
X-Wp-Cf-Super-Cache-Cache-Control
Memcached
CF-Cached-On
X-FL-EDGE
Ngx
Srvid
X-Varnish-CookieINHashed-On
X-DefHash
X-Varnish-CookieHashed-On
OriginIP
X-FL-QIT-DEBUG
X-DefElseHash
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-Shardid
Wpo-Cache-Status
X-Sorting-Hat-Shopid
X-Cache-Version
Wpo-Cache-Message
X-Sorting-Hat-Podid
X-Shopid
PICS-Label
X-M-Reqid
Akamai-Cache-Status
Warning
X-M-Log
Section-Io-Origin-Status
X-Th-Server
X-Wp-Cf-Super-Cache-Cookies-Bypass
Geoip-Latitude
X-RequestId
X-Sucuri-Id
X-Nitro-Rev
X-Nitro-Cache
X-Nitro-Cache-From
X-Lsadc-Cache
X-Udemy-Cache-App-Namespace
X-App
X-Web-Server
X-Dw-Trace-Id
X-Mg-Cache
Section-Origin-Responded
X-Service-Response-Time
X-Serial
Section-Io-Origin-Time-Seconds
Sm-Log-Id
X-Check-Cacheable
X-Fastly-Cache-Hits