Threat Level: green Handler on Duty: Richard Porter

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
CF-RAY
ETag
Accept-Ranges
Expect-CT
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-Xss-Protection
P3P
X-Served-By
X-UA-Compatible
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
X-AspNet-Version
Content-Security-Policy-Report-Only
X-Runtime
Accept-CH
P3p
X-DNS-Prefetch-Control
X-Drupal-Cache
Accept-CH-Lifetime
X-Cache-Status
X-Ua-Compatible
X-Generator
X-Check
Server-Timing
X-Cacheable
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Iinfo
X-Request-ID
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
X-Content-Security-Policy
Feature-Policy
Content-Encoding
X-CDN
Status
X-AspNetMvc-Version
Upgrade
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
X-Amz-Id-2
Host-Header
CF-Ray
Cf-Edge-Cache
X-Backend
Request-Context
Keep-Alive
X-UA-Device
Allow
X-Robots-Tag
X-Server
X-Cache-Group
X-Hacker
X-AH-Environment
X-Turbo-Charged-By
EagleId
X-Ws-Request-Id
X-Proxy-Cache
X-Age
X-Rq
Xkey
X-Vhost
X-Dispatcher
X-Amz-Version-Id
X-Server-Powered-By
X-Dns-Prefetch-Control
X-Varnish-Cache
Grace
Cf-Apo-Via
X-Swift-CacheTime
X-Swift-SaveTime
X-Page-Speed
Ali-Swift-Global-Savetime
X-Pingback
X-LiteSpeed-Cache
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
Cf-Railgun
Permissions-Policy
EagleEye-TraceId
X-OneAgent-JS-Injection
X-WebKit-CSP
X-Backend-Server
X-CST
X-Aws-Lambda-Call-Status
X-Server-Id
X-Host
X-Readtime
X-Response-Time
X-Cache-Lookup
X-Akam-SW-Version
Request-Id
Surrogate-Control
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-HW
X-Litespeed-Cache
X-Nginx-Upstream-Cache-Status
X-Cloud-Trace-Context
X-Node
X-Nginx-Cache-Status
X-Application-Context
X-Country-Code
Content-Location
X-Country
X-Ruxit-JS-Agent
X-Trace
Service-Worker-Allowed
X-Content-Type
X-Clacks-Overhead
X-Url
X-Oneagent-Js-Injection
Rating
X-Rack-Cache
Cache-Tag
X-Origin-Cache-Key
Accept-Ch-Lifetime
X-Amz-Server-Side-Encryption
X-FTR-Request-ID
X-Edge
Cross-Origin-Opener-Policy
X-Midtier
X-TtlSet
X-PC
X-Vname
Nginx-Cache
X-Mcache
X-MS-InvokeApp
X-Mod-Pagespeed
X-ECACHE
X-Upstream
X-Powered-By-Plesk
X-Server-Name
X-NWS-LOG-UUID
Edge-Control
X-Browser-Type
X-Cnection
X-Times
X-ESI
X-D2id
X-Element-Page-Cache
Verso
X-Exp-Id
X-Cdn-Fetch
X-Exp-Variant
X-Kinja-Build
X-Kinja-Server
X-Kinja-Revision
X-Kinja
X-GoogleNews-Bot
X-Ac
X-Ser
AR-ATIME
SPIisLatency
AR-PoweredBy
AR-Request-ID
SPRequestDuration
AR-SID
X-RateLimit-Remaining
X-B3-TraceId
X-Ruxit-Js-Agent
X-SharePointHealthScore
SPRequestGuid
X-GitHub-Request-Id
X-NF-Request-ID
X-Abt-Application-Version
X-Navigation-Version
X-Dw-Request-Base-Id
X-Vcap-Request-Id
AR-CACHE
X-Ttl
X-Mg-S
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-Middleton-Display
S
X-Sol
Pagespeed
Display
Edge-Cache-Tag
X-VARITI-CCR
Fastly-Restarts
X-Client-IP
X-Amzn-Trace-Id
RTSS
X-Cache-TTL
X-Amz-Rid
X-Cache-Key
X-Webkit-Csp
X-Instrumentation
X-Erf-Bev-Bev
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Erf-Bev-Bev-Is-Generated
Cache-Status
X-Powered-CMS
X-Kinsta-Cache
X-Edge-Location-Klb
X-Version
Access-Control-Request-Method
X-Daa-Tunnel
X-Goog-Hash
X-Server-ID
X-Recruiting
Response
X-Middleton-Response
X-Varnish-TTL
X-Content-Digest
X-ARC
X-Forwarded-For
X-TraceId
X-T
Arr-Disable-Session-Affinity
X-MSEdge-Ref
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
Content-MD5
Cross-Origin-Resource-Policy
MS-Author-Via
X-SRCache-Fetch-Status
MicrosoftSharePointTeamServices
X-SRCache-Store-Status
Front-End-Https
TP-Cache
X-Shield-Request-Id
X-Accel-Expires
X-FastCGI-Cache
X-RateLimit-Limit
X-Hits
X-Cached
X-FTR-Cache-Status
X-FTR-Balancer
X-FTR-Backend
X-FTR-Backend-Server
X-Country-Code-Real
Public-Key-Pins
Server-Node
X-HS-Combine-CSS
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Content-Id
X-Forwarded-Proto
X-Ua-Browser
X-Request-Received
X-Request-Processing-Time
X-Id
X-FTR-Expires
Payment
X-Content-Security-Policy-Report-Only
X-Frontend
Realpath
X-Protected-By
X-DIS-Request-ID
X-LLID
X-HP-Trace-Id
X-HP-Webp
X-Jurisdiction
X-ORACLE-DMS-RID
X-Distributor
X-GUploader-UploadID
TP-L2-Cache
X-Fastcgi-Cache
Origin-Trial
X-Hostname
X-LB-Cache
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Cache-Tags
X-Request-Handler-Origin-Region
X-Microsite
X-Amzn-RequestId
X-Debug-Info
X-Amz-Apigw-Id
X-Origin-Server
Host
Fastcgi-Cache
Count-Hit
X-Page-Id
Referer-Policy
X-AppVersion
X-Activity-Id
MRF-Tech
Mrf-Cache-Status
X-Az
X-B3-TraceId-Primal
X-Envoy-Decorator-Operation
X-Www-Served-By
X-NGENIX-Cache
X-Cluster-Name
X-Varnish-Backend
X-Varnish-Server
X-Correlation-Id
Accept-Charset
X-Geo-Country
X-App-Server
X-Fastly-Request-ID
X-XRDS-LOCATION
X-PressLabs-Stats
X-F-Cache
X-ORACLE-DMS-ECID
X-Ua-Device
X-Ezoic-Cdn
Retry-After
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-FB-Debug
X-Load-Cache
X-RateLimit-Reset
X-Goog-Metageneration
X-Upgrade-Enabled
X-Px
X-Ratelimit-Limit
Access-Control-Allow-Method
TCN
X-Git-Hash
X-Seen-By
Server-Name
X-Amz-Meta-S3cmd-Attrs
X-CSRF-Token
X-Tt-Trace-Host
Cleartype
X-Tt-Trace-Tag
Section-Io-Cache
X-Contextid
X-Revision
X-Request-Guid
X-Trace-Id
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Cache-Control
X-Datadog-Parent-Id
X-Grace
X-Content-Options
Charset
X-Type
X-Varnish-Ttl
X-B
X-Whom
X-B3-Sampled
Paypal-Debug-Id
X-TT
X-Azure-Ref
Healthy
DC
X-Fb-Rlafr
X-Oracle-Dms-Ecid
X-TTL
X-Wix-Request-Id
X-Proxy
X-Newrelic-App-Data
X-B-Cache
X-Signature
X-App-Environment
X-Mobile
X-Air-Pt
X-Node-Name
X-Magnolia-Registration
X-N
Frame-Options
X-Amz-Replication-Status
Filterid
X-Origin-Cache
Accept-Ch
X-EdgeConnect-Cache-Status
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Oracle-Dms-Rid
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-Logged-In
X-CCDN-Origin-Time
X-WebKit-CSP-Report-Only
X-Fastly-Request-Id
Content-Disposition
Backend
Viewport
NGB
VIX-Pulpo-Node
X-Original-Request-Id
VIX-Pulpo-Upstream-Status
Akamai-GRN
X-Response-Served-From
X-Rendered-As
X-Is-Bot
X-Time
X-Tumblr-Pixel-1
X-Servername
X-Varnish-Grace
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Datadog-Sampled
X-Debug-IsPreview
X-Tumblr-User
X-ProcessESI
Liferay-Portal
X-RemovedCookies
X-Hl-Ver
X-Unique-Id
X-RTag
MS-CV
X-Debug-IsConnected
SD-X-WS
Ms-Operation-Id
X-Amzn-Remapped-Content-Length
X-UUID
X-Adobe-Content
X-Backend-Name
X-FW-Type
X-FW-Version
X-FW-Server
X-FW-Serve
X-FW-Dynamic
X-FW-Hash
X-Debug
X-FW-Static
X-Instance
X-IPS-LoggedIn
Upgrade-Insecure-Requests
X-Adobe-Loc
X-Environment-Context
X-Via-JSL
Fastly-SWR
Fastly-SIE
X-L-Path
X-Cache-Grace
ServerID
X-NYM-Debug-Backend
X-Cacheable-TTL
X-G
X-Device-Type
X-Proxy-Cache-Info
From-Origin
X-Region
X-Language
X-User-Agent
X-Rule
Country
X-Cache-Hit
X-Cache-Age
X-Ratelimit-Remaining
X-Rid
X-Status
X-VC-Cache
Refresh
X-Template
X-B3-SpanId
Version
X-Providence-Cookie
X-Flags
X-Route-Name
X-Aspnet-Duration-Ms
X-Is-Crawler
Url
X-Source
X-INCAP-ABP
Countrycode
X-Webkit-CSP
GEO-INFO
SRV
X-Cache-Status-Check
X-HTML-Minification-Powered-By
CDN-RequestId
X-App-Version
X-Storage
X-Air-Trace-Id
X-Air-Source
Alternate-Protocol
X-Air-Hostname
WPO-Cache-Message
WPO-Cache-Status
X-Jobs
OT-Force-Account-Verify
X-WP-CF-Super-Cache-Active
X-NODE
X-Origin-TTL
X-Nginx-Cache
X-CDN-Forward
X-Origin-CC
X-Akamai-Request-ID2
X-Real-IP
X-Content-Powered-By
X-B3-Traceid
Amp-Access-Control-Allow-Source-Origin
Protected
X-ServerID
X-Rocket-Nginx-Serving-Static
Surrogate-Key
AMP-Access-Control-Allow-Source-Origin
X-Hosted-By
X-Cache-Time
X-Tec-Api-Origin
X-Tec-Api-Version
Access-Control-Request-Headers
X-Accel-Version
X-Tec-Api-Root
X-Handled-By
X-Cache-Rule
X-Cache-Operation
X-Akamai-Edgescape
X-VC
X-Mode
X-TT-LOGID
X-Xfnlog-Site
X-XRDS-Location
X-Platform-Processor
Xet-Cookie
X-Platform-Router
X-Platform-Cluster
Webserver
X-Edge-Location
X-Upstream-Ht
Filters
X-Rn-Rsrv
CF-IPCountry
X-Rewrite-Enabled
X-UPSTREAM-Address
Meta-Geo
X-Endurance-Cache-Level
X-Framework
X-Upstream-Ct
X-AWS-Id
X-SaId
X-Cache-Debug
X-Detected-As
X-Sucuri-Cache
X-Director
ServedBy
X-Served-From
X-Origin
Cross-Origin-Embedder-Policy
Section-Io-Id
Selected-Fe
X-LJ-Flow-ID
X-JoinUs
X-Proxy-Build
X-VWS-Id
X-Varnish-Cache-Hits
X-Soup
X-Tumblr-Pixel-3
X-Timing-Wait
X-Tumblr-Pixel-2
TWC-GeoIP-Country
TWC-GeoIP-LatLong
X-Web-Node
TWC-Locale-Group
X-PHP-Host
X-Routing-Service
Web-Mar-Node
X-No-Session
TWC-Privacy
X-Origin-Hint
TWC-Connection-Speed
Front
X-Restarts
X-Lambda-Id
X-Labrador-Cache-Channel
Mn-Server-Ip
Node
TWC-Device-Class
X-Webstats-RespID
Webcakes-App-Version
Property-Id
X-Worker
Webcakes-App-Name
X-Kinja-CCPA
X-SayCDN-TTL
X-ProxyCache-Status
X-BYPASS-REASON
X-Cms-Context
X-Redis-Cache
X-Use-Mantle
X-Extlb
X-Drupal-Cache-Tags
X-Zipkin-Id
X-Cluster
X-Adobe-Source
X-Logging-Id
X-ProxyCache-Key
X-Say-TTL
X-Proxied
Webcakes-Region
X-Say-Cacheable
X-Geo-Region
X-Is-Supported-Browser
X-AB
X-Is-Mobile
X-Drupal-Cache-Contexts
X-Is-Tablet
X-GeoCode
X-GeoCountry
X-RM-Cache-TTL
X-Site-Version
X-IPLB-Instance
X-IPLB-Request-ID
X-Browser-Name
X-Is-Desktop
X-Tcp-Rtt
X-Loop
X-Page-View
X-Format
X-Sucuri-ID
X-VCT
X-Tncms
Accept-Language
X-RCS-CacheZone
X-S
X-Varnish-Beresp-Grace
X-Skip-Cache
Azure-SiteName
Azure-InstanceId
Azure-SlotName
X-Varnish-Age
Azure-Version
Apigw-Requestid
Azure-RegionName
X-Locale
X-Cache-Server
CDN-RequestCountryCode
X-Forwarded-Host
CDN-PullZone
CDN-RequestPullSuccess
X-Cache-Host
Xserver
CDN-EdgeStorageId
X-Generation-Time
X-Storefront-Renderer-Rendered
X-Container-Uri
X-R9-Blue-Green-Version
CDN-Cache
CDN-CachedAt
CDN-RequestPullCode
X-Fetched-On
X-Origin-Date
X-Git-Commit
X-Reqid
X-Shopify-Stage
X-Tb
X-Vercel-Cache
X-Vercel-Id
CDN-Uid
X-Alternate-Cache-Key
X-Httpd
X-Vcache
X-Ms-Version
X-Provided-By
X-Frame-Option
X-Ms-Request-Id
DB-Nickname
X-ShardId
X-Sorting-Hat-ShopId
Atl-Traceid
X-ShopId
X-Sorting-Hat-PodId
X-Server-W
WP-Super-Cache
X-Cdn-Origin
Fastcgi-Useragent
X-MP-GENERATED-AT
X-Uri
X-Vcl-Version
Cross-Origin-Embedder-Policy-Report-Only
Source
X-Generated-By
Cache-Tv-Group
X-Http-Reason
X-SRV
X-Pass-Why
Cross-Origin-Window-Policy
X-FB-TRIP-ID
Content-Secure-Policy
Thinkindot-Control
X-CMSURLCustom
TDXMobile
X-Shield-Cache-Expires
X-Scope-Id
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-RID
X-Thinkindot-L3
Sid
X-Buckets
X-Azure-Ref-OriginShield
Cache
X-DynaTrace
Onion-Location
X-Urbn-Site-Id
Priority
X-Urbn-Context-Path
Locale
X-DataDome
X-LSADC-Cache
X-Content-Age
X-Optimistic-Header
HostName
X-Sql-Count
X-Sql-Duration-Ms
X-WP-CF-Super-Cache-Cookies-Bypass
X-GEO
X-Varnish-Beresp-Ttl
X-Proxy-Cache-Status
X-Cluster-Node
X-Xrds-Location
X-UA
X-Dc
X-Newrelic-Synthetics
X-Request-URI
X-TA-CDN-Provider
User-Cache-Control
X-Lagoon
Expiry
X-Cache-Action
X-Connection-Hash
X-Cache-Bucket
X-Cache-NE
X-Conf
X-Bl-Debug
X-BCube-Filmed-By
X-Aed
X-A-Wwc
X-Application
X-B-Cookie
X-Bc-Bl
X-A-Dgt
A
Ngx-Var-Key
Meta-Geo-Continent
Ngx.Var.Host
Origin
Redirect-Candidate
Origin-Agent-Cluster
X-Vtex-Remote-Cache
MD5-Digest
DCR-Processing-Time-Ms
Gannett-Cam-Experience-Id
DCR-Decision-By
X-Viewer-Country
Magicmarker
Lang
Rendered-Blocks
Candidate-Md5Url
X-D
T-Server
Vix-Hermes-Req-Id
X-A
X-A-Dam
X-A-Ccd
Surrogated-Key
Sslversion
Server-Ext
Req-ID
Server-Host
Server-Hostname
Sever-Int
X-A-Dcw
X-Ec-Fail
X-SB
X-Vdms-Path
X-External-Request-Id
X-Scheme
X-Epic-Correlation-Id
X-ScT
X-Rojux
X-Request-Start
X-Op-Id-All
X-ND-Cache
X-Instance-Name
X-Varnish-Hostname
X-Platform
X-PAYTM-SRV-ID
X-Ec-GeoHdr
X-S-Cookie
X-Ec-Custom-Error
X-Dispatcher-Server
X-Destination
X-SRCache-Key
X-Developer
X-Vdms-Version
X-TIM-N
WZWS-RAY
Locid
X-Origin-Time
Wxu-Next-Commit
Ssr
Wxu-Next-Hostname
X-Varnish-Director
Fastly-SSL
V-Age
X-UA-Device-Type
X-Nyt-Route
X-Pool
X-Req
NM-Fastcgi-Cache
Host-ID
X-Sigma-Backend
X-Sigma
X-Varnish-Beresp-Status
X-SD-PageType
X-Node-Id
Pramga
X-Section
X-Pubstack
Req-Svc-Chain
X-Thanos
X-Rocket-Build-Number
X-Request-Time
X-Proxied-Request
X-Level-Front-Cache
X-BBC-Edge-Cache-Status
X-Esi-Check
X-Bip
X-B3-Trace-ID
X-Fastly-Cache
X-Forwarded-Site
X-Amz-Storage-Class
X-Auto-Login
X-Block-Status
Fastly-GeoIP-CountryCode
X-Core-Value
X-Debug-Cache-Store
X-VG-TLSProxy
X-Clientip
X-VG-WebCache
X-Cache-Id
X-Cache-Info
X-Cache-TTL-Remaining
X-Amz-Meta-Cb-Modifiedtime
X-AK-Request-ID
X-Debug-Cache-Fetch
X-Human
X-Hnp-Log
X-Loc
X-Mly-Id
X-NMSegId
X-Nginx-Cache-Key
X-NCache
X-Gzip
X-GeoIP-Region-Code
X-Acquia-Purge-Cdn-Unconfigured
X-Gdpr
X-Varnishpool
X-Access
X-Gen-Mode
X-GeoIP-Country-Code
X-Generated-On
Wxu-Next-Region
L
Cluster
X-We-Are-Hiring
Apple-News-Services-Request-Url
X-WA-Info
Content-Script-Type
Cdnsip
Cdncip
CDCHOST
X-Zen-Fury
Fastly-Drupal-HTML
X-Datadome
Content-Style-Type
C-Via
Release
Apple-News-Services-Host
Apple-News-Services-Handled
Environment
X-Cache-Expired-At
X-Correlation-ID
X-VServer
Apple-News-Services-Parsed-Url
DSUID
Yak-Timeinfo
LB
X-Service
X-TimeS
X-Origin-Response-Time
X-Policy
X-Origin-Expires
X-Cache-Date
X-Branch-Name
X-Cache-Aspx
X-PERF
X-RateLimit-Remaining-Second
Tube-Got-Eval
Tube-Get-Contents
X-Aicache-OS
X-Ad-Load-Variation
X-ApacheServer
X-Org
Tube-Return
X-RateLimit-Limit-Second
Tube-Got-Results
X-Backend-Instance
X-Cdn-Srv
XM
X-DPWN-IS-SECURE
X-Device-Os
X-SVT-ORM-VERSION
X-GeoIP-City
X-GeoIP
X-VarnishDD-TTL
X-Fmm-Version
X-FC-Vary-Parameters
X-Geo-Header
X-SVT-ORM-RULES
X-GoCache-CacheStatus
X-Micro-Cache
X-Mvc-Supplant-Cachable
X-Old-Content-Length
X-Moov-Xdn-Version
X-Region-Sid
X-Men
X-HN
X-HS-Content-Campaign-Id
X-Contensis-Viewer-Groups
X-Moov-T
X-Request-Host
Cache-Provider
RNT-Time
RNT-Machine
X-Var-Ttl
True-Client-Country-4JS
Uber-Trace-Id
X-TH-Server
Country-Code
Canary
Platform
X-V-Cache
PFcat
Producers
Mail-Subject
On-Server
Machine
Is-Eu
Adler-Geo
Click-Count-Action-Start
X-Varnish-Authentication
Gh-Request-Id
Click-Count-Error
X-Server-IP
X-From
Esi-Enabled
We-Hiring
Web-Mar-Region
X-Via-Edge
X-Via-CDN
Edge-Copy-Time
X-Via-SSL
Ha-Gx-Prefs
S-Rt
X-Fastly-Backend
X-ECache
HA-Ipaddr
X-Test
Cf-Device-Type
X-Up
X-Esi
L5d-Success-Class
X-Edge-Server
X-Eu-Site
Cdn-Host
X-Cache-Backend
X-Slack-Shared-Secret-Outcome
X-Sn-Servicetimems
X-Wikidot-Static-Cache
X-Proto
X-App-Name
W
X-Slack-Backend
X-Hash
AKAMAI
Proxy-Firewall
Cdn-Request-Time
X-Csrf-Jwt
Cache-Key
X-CGP
X-VCache
X-Mvc-Supplant-OutputCached
X-Wikidot-Backend
X-Mg-Request-UUID
X-DC
X-LB-ID
X-Date
X-CacheTTL
X-Parent-Response-Time
X-Accel-Expires-Debug
X-API-Version
Fastly-Backend-Name
NGX
X-Tx-Id
X-Varnish-Hits
Type
X-Tb-Optimization-Total-Bytes-Saved
Cache-Hits
X-Ah-Environment
X-Ua
X-Via-Popv
X-Via-Poph
X-PDP-UNCACHING-HASH
X-Via-Popn
X-Servedbyhost
X-COUNTRY
X-HA-Backend
Pics-Label
X-Zone
X-URL
X-Via-Fastly
NtCoent-Length
X-NGINX-Cache
X-CACHE-GROUP
X-DynaTrace-JS-Agent
X-Refresh
Cdn
Datacenter
X-Ratelimit-Reset
X-Cloudmap
GeoIp-Country-Code
X-CDN-Cache-Status
X-Irp-Debug
X-LB-NoCache
X-NWS-UUID-VERIFY
X-Client-Ip
X-VHOST
X-Owner
X-Ig-Origin-Region
SID
X-Location
Cdn-Requestid
Server-ID
X-Srv
IsBot
Fusion-Template-Id
Fusion-Source
X-SIPLIST1
Fusion-Content-Id
X-Core-Mission
Fusion-Component-Id
X-Wa
X-Nc
X-ZONE
Fusion-Deployment-Id
Fusion-Content-Source
Resin-Trace
Powered-By
X-Akamai-Transformed
Origin-EX
Cross-Origin-Opener-Policy-Report-Only
X-Qloud-Router
X-Jungle-Id
X-TX-ID
X-CUA
Origin-CC
GeoIP-Latitude
X-Fpc
X-Nananana
Expect-Staple
X-User
DataCenter
N-Cache
X-CF-Lambda-Fn
X-Hit
X-TIME
X-Wormhole-Sdk
X-CF-Lambda-Version
X-CS
CloudFront-Viewer-Country
XkeyRZ
X-DataCenter
X-B3-Parentspanid
X-Proxy-CacheRZ
Xc-Version
X-Cache-Type
X-Orig-Expires
Mime-Version
X-Nf-Request-Id
X-Forwarded-Path
X-Shop-Environment
X-Tenant
X-NewRelic-App-Data
X-Segment-20210421
Cmsid
Uri
X-Presslabs-Stats
Cmstype
X-Cached-By
X-IAuth-Set-Uid
X-Render-Time
X-Gamma-Serve
X-CACHE-AGE
X-VTEX-Cache-Server
User-Agent
Debug
True-Client-IP
X-Tt-Logid
X-VTEX-Cache-Time
X-Amz-Meta-Opti
CPC-Age
X-Powered-By-VTEX-Cache
CPC-Cache
Fastly-Drupal-Html
X-Info
Edge-Cache
X-Cdn-Diag
X-Auth-Group-Type
X-Vmg-Version
True-Client-Ip
Cf-Ipcountry
X-LiteSpeed-Tag
X-Dynatrace-Js-Agent
X-Fastly-Country-Code
CDN
MIME-Version
X-Vc
X-Geo
X-Dispatch
Load-Balancing
X-Datacenter
X-Oracle-DMS-ECID
X-CSRF-TOKEN
X-Varnish-Beresp-TTL
X-Ig-Push-State
X-B3-Spanid
Tcn
Odigeo-Trace-Id
X-Variation
Srv
CacheControlHeader
X-HOST
X-LAGOON
X-Cs
X-LiteSpeed-Cache-Control
Hostname
X-HostName
X-Vgn-Hpd-Reason
X-NodeID
X-PHP-Backend
Ohc-File-Size
X-Custom-Header
X-AIR-PT
X-Cdn-Forward
X-Webkit-Csp-Report-Only
X-Pad
Cl-Cache
X-FPC
X-Depends
X-APP-VERSION
X-MCACHE
Server-Id
X-NC
X-DefElseHash
VNS-Cache
VNS-Age
X-WA
X-Varnish-CookieHashed-On
X-DefHash
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
Ohc-Cache-HIT
X-Lb-Nocache
X-M-Reqid
X-VC-TTL
X-M-Log
X-Api-Version
GeoIP-Country-Code
X-Cdn-Cache-Status
X-APP
X-Cache-FS-Status
X-Dispatcher-Number
Geoip-Latitude
X-CACHE-KEY
X-ServedByHost
Epwk-X-Cache
X-Cache-Ttl
X-Litespeed-Tag
X-MSEdge-Features
X-Fastly-Backend-Reqs
X-MSEdge-Flight
Lb
Cloudfront-Viewer-Country
X-Ha-Backend
CountryCode
X-Via-PopH
PICS-Label
X-Via-PopN
X-Via-PopV
X-VCL-Version
X-Litespeed-Cache-Control
X-Srcache-Fetch-Status
X-Use-Magma
X-Srcache-Store-Status
Xkeylog
X-Lb-Id
X-Proxy-Cache-La3
X-Akamai-Pragma-Client-IP
X-Cdn-Request-ID
Xkey-La3
Cache-Name
Server-Info
X-MiniProfiler-Ids
X-Mid
X-IN-APIGATEWAYSSL
OriginIP
X-IN-APIGATEWAY
FSS-Cache
X-Snapshot-Date
Memcached
X-Web-Server
X-Acquia-Application-UUID
X-Acquia-Site
X-Acquia-Purge-Tags
X-Acquia-Application-Trace
Time
Ngx
X-RequestId
X-Th-Server
Memory
X-Sorting-Hat-Shopid
X-Shopid
X-Sorting-Hat-Podid
X-Cache-Version
X-Shardid
X-RAMCache
X-Ramcache
X-FL-QIT-DEBUG
Srvid
Serverhost
X-Requestid
Sm-Log-Id
Akamai-Cache-Status
CF-Cached-On
X-Mg-Cache
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Service-Response-Time
X-Serial
X-Udemy-Cache-App-Namespace
Warning
X-Dw-Trace-Id
X-Check-Cacheable
X-Sucuri-Id