Threat Level: green Handler on Duty: Richard Porter

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
CF-RAY
ETag
X-XSS-Protection
Accept-Ranges
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
X-Served-By
P3P
X-Xss-Protection
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-FRAME-OPTIONS
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Content-Security-Policy-Report-Only
P3p
X-Runtime
X-AspNet-Version
X-DNS-Prefetch-Control
Accept-CH
X-Cache-Status
X-Drupal-Cache
Accept-CH-Lifetime
X-Ua-Compatible
X-Check
X-Generator
X-Cacheable
Server-Timing
X-Envoy-Upstream-Service-Time
X-Request-ID
Timing-Allow-Origin
X-Iinfo
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
Feature-Policy
X-Content-Security-Policy
Content-Encoding
X-CDN
Status
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
CF-Ray
X-Amz-Id-2
Host-Header
Allow
X-Backend
Cf-Edge-Cache
X-Cache-Group
Request-Context
X-Robots-Tag
Keep-Alive
X-Server
X-Hacker
X-UA-Device
X-AH-Environment
X-Turbo-Charged-By
X-Ws-Request-Id
X-Proxy-Cache
Xkey
X-Age
X-Rq
X-Vhost
EagleId
X-Dispatcher
X-Server-Powered-By
X-Amz-Version-Id
X-Varnish-Cache
Grace
X-Dns-Prefetch-Control
Cf-Apo-Via
X-LiteSpeed-Cache
X-Page-Speed
X-Pingback
Cf-Railgun
X-Swift-CacheTime
X-Swift-SaveTime
X-Pantheon-Styx-Hostname
X-Device
X-Styx-Req-Id
EagleEye-TraceId
X-WebKit-CSP
Ali-Swift-Global-Savetime
X-Aws-Lambda-Call-Status
X-CST
X-OneAgent-JS-Injection
X-Backend-Server
Permissions-Policy
X-Server-Id
X-Readtime
X-Response-Time
X-Host
X-Akam-SW-Version
Request-Id
Surrogate-Control
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Nginx-Upstream-Cache-Status
X-HW
Accept-Ch-Lifetime
X-Cloud-Trace-Context
X-Nginx-Cache-Status
X-Node
X-Application-Context
X-Country-Code
X-Cache-Lookup
X-Ruxit-JS-Agent
X-Litespeed-Cache
X-Trace
Content-Location
Service-Worker-Allowed
X-Url
X-Content-Type
X-Country
X-Clacks-Overhead
X-Oneagent-Js-Injection
X-ECACHE
X-Edge
X-Origin-Cache-Key
X-Mcache
Accept-Ch
X-Mod-Pagespeed
X-Amz-Server-Side-Encryption
Cross-Origin-Opener-Policy
X-Midtier
X-Rack-Cache
X-FTR-Request-ID
Cache-Tag
X-MS-InvokeApp
Nginx-Cache
X-Upstream
X-TtlSet
X-Vname
X-PC
X-ESI
X-Powered-By-Plesk
Rating
Edge-Control
X-Browser-Type
X-D2id
X-Server-Name
X-Element-Page-Cache
Verso
X-Exp-Id
X-Kinja-Revision
X-Kinja-Server
X-Kinja-Build
X-Kinja
X-GoogleNews-Bot
X-Exp-Variant
X-Cdn-Fetch
X-B3-TraceId
X-Times
X-Cnection
SPRequestDuration
SPIisLatency
X-Ac
AR-Request-ID
AR-ATIME
AR-PoweredBy
AR-SID
X-Abt-Application-Version
X-Vcap-Request-Id
X-SharePointHealthScore
X-Navigation-Version
SPRequestGuid
X-RateLimit-Remaining
X-NF-Request-ID
X-Dw-Request-Base-Id
X-Ruxit-Js-Agent
X-GitHub-Request-Id
X-Ser
X-VARITI-CCR
AR-CACHE
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-Mg-S
S
X-Cache-Key
Pagespeed
Display
RTSS
X-Middleton-Display
X-Sol
X-Client-IP
X-NWS-LOG-UUID
X-Ttl
Edge-Cache-Tag
X-Cache-TTL
Fastly-Restarts
X-Amzn-Trace-Id
X-Amz-Rid
X-Powered-CMS
Origin-Trial
X-Goog-Hash
X-Varnish-TTL
X-Erf-Bev-Bev
X-Instrumentation
X-Kraken-Loop-Name
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
Cache-Status
X-Version
X-Edge-Location-Klb
X-Server-ID
X-Kinsta-Cache
Access-Control-Request-Method
X-Content-Security-Policy-Report-Only
X-Recruiting
X-ARC
X-TraceId
X-Content-Digest
Arr-Disable-Session-Affinity
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-T
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-MSEdge-Ref
X-Middleton-Response
X-Forwarded-For
Response
X-Ua-Device
Content-MD5
X-Accel-Expires
MicrosoftSharePointTeamServices
TP-Cache
X-Shield-Request-Id
X-Hits
X-Cached
X-Id
X-FTR-Cache-Status
X-FTR-Backend
X-FTR-Balancer
X-FTR-Backend-Server
X-Country-Code-Real
Public-Key-Pins
X-FTR-Expires
MS-Author-Via
Server-Node
X-Request-Processing-Time
X-Request-Received
Payment
X-HS-Cache-Config
X-HS-Content-Id
X-Ua-Browser
X-HS-Hub-Id
X-HS-Combine-CSS
Front-End-Https
Cross-Origin-Resource-Policy
X-DIS-Request-ID
X-Frontend
X-Webkit-Csp
X-RateLimit-Limit
X-Forwarded-Proto
X-Daa-Tunnel
X-LLID
X-HP-Webp
X-GUploader-UploadID
X-HP-Trace-Id
X-Jurisdiction
X-Fastcgi-Cache
X-FastCGI-Cache
TP-L2-Cache
Realpath
X-LB-Cache
X-Protected-By
Cache-Tags
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Origin-Server
X-Distributor
X-WebKit-CSP-Report-Only
Count-Hit
X-Microsite
X-Request-Handler-Origin-Region
X-Page-Id
X-ORACLE-DMS-RID
X-B3-TraceId-Primal
X-F-Cache
Mrf-Cache-Status
MRF-Tech
X-AppVersion
X-Kinja-CCPA
X-Activity-Id
X-NGENIX-Cache
X-Az
X-Www-Served-By
X-Cluster-Name
X-Hostname
Referer-Policy
Accept-Charset
X-Varnish-Backend
X-Debug-Info
X-Geo-Country
X-Correlation-Id
X-App-Server
X-Envoy-Decorator-Operation
Fastcgi-Cache
X-PressLabs-Stats
X-Kong-Proxy-Latency
X-Varnish-Server
X-Kong-Upstream-Latency
Host
X-TTL
X-Goog-Metageneration
X-FB-Debug
Access-Control-Allow-Method
X-Git-Hash
X-RateLimit-Reset
X-ORACLE-DMS-ECID
X-Oracle-Dms-Ecid
Retry-After
X-Ratelimit-Limit
X-XRDS-LOCATION
X-Rid
Server-Name
X-Content-Options
X-Load-Cache
X-CSRF-Token
X-Tt-Trace-Tag
X-Upgrade-Enabled
X-Tt-Trace-Host
X-Px
X-Is-Crawler
X-Aspnet-Duration-Ms
X-Contextid
X-Flags
X-Providence-Cookie
X-Route-Name
X-Request-Guid
X-Revision
DC
X-Cache-Control
TCN
X-App-Environment
X-Grace
Charset
X-Origin-Cache
X-B-Cache
X-Trace-Id
X-Signature
X-Datadog-Parent-Id
X-B
X-Datadog-Trace-Id
Paypal-Debug-Id
X-Type
X-Datadog-Sampling-Priority
Cleartype
X-Seen-By
X-ASPNET-VERSION
X-Oracle-Dms-Rid
X-Ezoic-Cdn
Section-Io-Cache
X-TT
X-B3-Sampled
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Amz-Meta-S3cmd-Attrs
X-Mobile
X-Fastly-Request-ID
X-Fb-Rlafr
X-Amz-Replication-Status
Frame-Options
Healthy
X-Magnolia-Registration
X-Language
X-Wix-Request-Id
X-Whom
X-Logged-In
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Node-Name
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Fastly-Request-Id
Filterid
X-EdgeConnect-Cache-Status
X-Azure-Ref
X-Proxy
X-Newrelic-App-Data
X-N
Content-Disposition
X-App-Version
X-Air-Pt
Backend
X-Varnish-Ttl
Akamai-GRN
X-Template
NGB
Upgrade-Insecure-Requests
Refresh
X-Proxy-Cache-Info
X-Response-Served-From
X-Original-Request-Id
X-Is-Bot
X-Rendered-As
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
VIX-Pulpo-Node
X-Tumblr-User
X-Unique-Id
X-Yottaa-Optimizations
X-Yottaa-Metrics
SD-X-WS
X-RemovedCookies
X-Tumblr-Pixel
X-Page-View
X-ProcessESI
VIX-Pulpo-Upstream-Status
X-Varnish-Grace
X-UUID
X-WP-CF-Super-Cache
X-Debug-IsPreview
X-WP-CF-Super-Cache-Cache-Control
X-Debug-IsConnected
MS-CV
Liferay-Portal
X-Datadog-Sampled
Ms-Operation-Id
Viewport
X-Servername
X-RTag
X-Instance
X-Amzn-Remapped-Content-Length
X-Adobe-Content
X-Adobe-Loc
Fastly-SIE
X-Debug
Fastly-SWR
X-FW-Static
X-FW-Version
X-FW-Type
X-G
X-Ratelimit-Remaining
X-B3-SpanId
X-FW-Server
X-IPS-LoggedIn
X-FW-Hash
X-FW-Serve
X-FW-Dynamic
X-Device-Type
X-Cacheable-TTL
X-NYM-Debug-Backend
X-Cache-Grace
Url
X-User-Agent
X-Region
From-Origin
X-Rule
X-Environment-Context
X-L-Path
X-Cache-Hit
X-Jobs
Country
X-Backend-Name
X-Hl-Ver
X-Status
ServerID
X-Webkit-CSP
Surrogate-Key
X-Air-Hostname
X-Air-Trace-Id
X-Air-Source
Countrycode
X-Hosted-By
X-Cache-Age
X-Time
Alternate-Protocol
X-Tec-Api-Root
X-Origin-TTL
X-Tec-Api-Origin
X-Tec-Api-Version
X-VC-Cache
X-Origin-CC
X-CCDN-CacheTTL
X-Content-Powered-By
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-Http-Reason
Amp-Access-Control-Allow-Source-Origin
X-Akamai-Request-ID2
X-NODE
X-Cache-Status-Check
X-Via-JSL
X-INCAP-ABP
X-HTML-Minification-Powered-By
Protected
WPO-Cache-Status
WPO-Cache-Message
Version
X-Akamai-Edgescape
X-Rocket-Nginx-Serving-Static
GEO-INFO
CDN-RequestId
X-Framework
X-Storage
X-WP-CF-Super-Cache-Active
SRV
X-Edge-Location
X-Accel-Version
X-Source
Access-Control-Request-Headers
X-Cache-Rule
X-CDN-Forward
CF-IPCountry
X-XRDS-Location
Front
X-Nginx-Cache
X-Httpd
OT-Force-Account-Verify
X-Real-IP
X-Use-Mantle
X-Use-Magma
X-Mode
X-UPSTREAM-Address
X-Upstream-Ct
X-Xfnlog-Site
X-Upstream-Ht
X-Endurance-Cache-Level
Filters
Accept-Language
Meta-Geo
X-Cache-Operation
X-Rn-Rsrv
X-Rewrite-Enabled
Webserver
X-VC
X-Director
X-Cache-Debug
X-Served-From
X-SaId
X-Proxy-Build
X-Detected-As
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
X-JoinUs
X-Soup
X-Timing-Wait
Selected-Fe
X-Adobe-Source
X-Handled-By
X-BYPASS-REASON
X-Say-TTL
X-ProxyCache-Status
X-Redis-Cache
X-ProxyCache-Key
X-Logging-Id
X-Sql-Duration-Ms
X-Origin
X-Say-Cacheable
X-SayCDN-TTL
ServedBy
X-Varnish-Cache-Hits
X-Sql-Count
X-Worker
X-Cms-Context
X-Cache-Time
Web-Mar-Node
TWC-GeoIP-LatLong
TWC-Locale-Group
TWC-Privacy
TWC-GeoIP-Country
TWC-Device-Class
TWC-Connection-Speed
Property-Id
DB-Nickname
Webcakes-App-Name
Azure-SiteName
Azure-RegionName
Azure-SlotName
Azure-Version
Webcakes-App-Version
Webcakes-Region
Azure-InstanceId
X-Tncms
X-Varnish-Age
X-Labrador-Cache-Channel
Xserver
X-Lambda-Id
X-Restarts
X-RM-Cache-TTL
X-VCT
X-Server-W
X-S
X-B3-Traceid
X-GeoCountry
X-No-Session
X-Loop
AMP-Access-Control-Allow-Source-Origin
Xet-Cookie
X-Origin-Hint
X-GeoCode
X-PHP-Host
X-Format
X-Skip-Cache
X-LJ-Flow-ID
X-RCS-CacheZone
X-Vercel-Id
X-Generation-Time
X-Git-Commit
X-Fetched-On
X-Cache-Server
X-DynaTrace
X-Tb
X-AWS-Id
X-Container-Uri
X-Vercel-Cache
X-VWS-Id
X-IPLB-Request-ID
X-IPLB-Instance
X-Varnish-Beresp-Grace
Mn-Server-Ip
Apigw-Requestid
X-Ms-Version
X-Cluster
X-Provided-By
X-Cache-Host
X-Reqid
X-Ms-Request-Id
X-Is-Tablet
X-Geo-Region
X-Frame-Option
X-Is-Desktop
X-Is-Mobile
X-Is-Supported-Browser
X-Browser-Name
X-Tcp-Rtt
Section-Io-Id
Node
X-AB
X-Web-Node
X-ServerID
X-R9-Blue-Green-Version
X-Routing-Service
X-Extlb
X-Locale
X-Site-Version
X-Proxied
X-Forwarded-Host
X-Zipkin-Id
X-Uri
X-Platform-Router
X-Platform-Processor
Cross-Origin-Embedder-Policy
X-Platform-Cluster
Cache-Tv-Group
X-Webstats-RespID
X-COUNTRY
Source
X-Drupal-Cache-Contexts
X-FB-TRIP-ID
X-Drupal-Cache-Tags
Priority
Content-Secure-Policy
X-Vcache
X-MP-GENERATED-AT
Fastcgi-Useragent
WP-Super-Cache
X-Vcl-Version
X-Origin-Date
CDN-RequestPullSuccess
CDN-Uid
CDN-RequestCountryCode
CDN-PullZone
CDN-CachedAt
CDN-EdgeStorageId
CDN-Cache
CDN-RequestPullCode
Onion-Location
X-Alternate-Cache-Key
X-Storefront-Renderer-Rendered
X-Shopify-Stage
X-Generated-By
X-TT-LOGID
X-Xrds-Location
Locale
WZWS-RAY
X-SRV
X-Urbn-Site-Id
X-Urbn-Context-Path
X-Content-Age
X-ShardId
X-Sucuri-Cache
X-Sorting-Hat-PodId
X-ShopId
S-Rt
X-Sorting-Hat-ShopId
X-Pass-Why
X-Newrelic-Synthetics
X-Cdn-Origin
X-Sucuri-ID
X-Ua
X-Cluster-Node
Sid
X-Buckets
X-Proxy-Cache-Status
X-Varnish-Beresp-Ttl
Cross-Origin-Embedder-Policy-Report-Only
X-Cache-Action
X-Cache-Expired-At
X-CMSURLCustom
X-Shield-Cache-Expires
X-Thinkindot-L3
Cross-Origin-Window-Policy
X-VCache
TDXMobile
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Thinkindot-Control
X-Scope-Id
Cache
X-LSADC-Cache
X-DataDome
X-GEO
Atl-Traceid
Fastly-Drupal-HTML
HostName
X-Mg-Request-UUID
X-Request-URI
X-Via-Edge
X-Aspnetmvc-Version
X-Via-CDN
X-Via-SSL
Edge-Copy-Time
X-Application
Lang
Origin-Agent-Cluster
X-Bl-Debug
X-A-Dcw
X-BCube-Filmed-By
Origin
X-B-Cookie
X-Bc-Bl
Type
Gannett-Cam-Experience-Id
X-Vdms-Version
X-A-Dam
X-A-Wwc
X-Epic-Correlation-Id
X-External-Request-Id
CDCHOST
X-D
X-Ec-GeoHdr
X-Ec-Fail
Candidate-Md5Url
X-Developer
X-Aed
X-Ec-Custom-Error
X-Conf
X-SRCache-Key
Ngx-Var-Key
X-Cache-Bucket
Ngx.Var.Host
X-Destination
Environment
DCR-Processing-Time-Ms
Meta-Geo-Continent
X-Cache-NE
MD5-Digest
DCR-Decision-By
X-A-Dgt
X-Vdms-Path
X-TIM-N
X-Rojux
X-Viewer-Country
Redirect-Candidate
X-S-Cookie
Rendered-Blocks
Sslversion
X-PAYTM-SRV-ID
X-Optimistic-Header
X-Vtex-Remote-Cache
X-Correlation-ID
T-Server
Surrogated-Key
X-A-Ccd
X-ScT
X-Scheme
X-A
X-WP-CF-Super-Cache-Cookies-Bypass
X-Datadome
X-TimeS
Apple-News-Services-Request-Url
Host-ID
X-Dispatcher-Server
X-Proxied-Request
X-Pool
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
Vix-Hermes-Req-Id
X-Acquia-Purge-Cdn-Unconfigured
V-Age
X-Platform
X-Pubstack
Sever-Int
Apple-News-Services-Host
X-Debug-Cache-Store
X-Rocket-Build-Number
X-Aicache-OS
X-Request-Time
Fastly-SSL
Fastly-GeoIP-CountryCode
X-SB
DSUID
X-Cache-Info
X-Request-Start
X-Debug-Cache-Fetch
Magicmarker
Ssr
X-Core-Value
X-Clientip
X-Req
X-Bip
Server-Hostname
X-Human
X-Instance-Name
Pramga
X-Mly-Id
Req-ID
X-Thanos
X-Sigma
X-TH-Server
Req-Svc-Chain
Release
X-VG-TLSProxy
X-Loc
X-Level-Front-Cache
X-WA-Info
X-Sigma-Backend
X-Varnish-Hostname
X-Varnishpool
X-Varnish-Beresp-Status
X-Varnish-Director
X-VG-WebCache
X-GeoIP-Region-Code
X-GeoIP-Country-Code
Server-Ext
X-Fastly-Cache
X-Access
Server-Host
X-Op-Id-All
X-SD-PageType
X-Origin-Time
X-BBC-Edge-Cache-Status
X-B3-Trace-ID
X-Nyt-Route
X-VServer
X-Section
X-We-Are-Hiring
X-Forwarded-Site
X-Generated-On
L
X-Node-Id
X-Gdpr
User-Cache-Control
X-Origin-Response-Time
We-Hiring
Wxu-Next-Hostname
Wxu-Next-Region
Wxu-Next-Commit
Web-Mar-Region
Uber-Trace-Id
X-Ad-Load-Variation
X-Hnp-Log
X-NMSegId
X-Zen-Fury
X-Old-Content-Length
X-Org
X-Nginx-Cache-Key
X-NCache
Cluster
X-Mvc-Supplant-Cachable
X-Mvc-Supplant-OutputCached
X-V-Cache
X-PERF
X-UA-Device-Type
X-Server-IP
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Up
X-Request-Host
X-Policy
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Var-Ttl
X-Micro-Cache
X-DPWN-IS-SECURE
X-Esi-Check
X-FC-Vary-Parameters
X-Fmm-Version
X-Device-Os
X-Cache-TTL-Remaining
X-Block-Status
X-Cache-Date
X-Cache-Id
X-From
X-Gen-Mode
X-Irp-Debug
Tube-Return
X-Men
X-HS-Content-Campaign-Id
X-Gzip
X-Geo-Header
X-GeoIP
X-GeoIP-City
X-Auto-Login
X-ApacheServer
Country-Code
Canary
NM-Fastcgi-Cache
On-Server
C-Via
X-TA-CDN-Provider
Mail-Subject
Tube-Got-Results
Adler-Geo
Click-Count-Error
Is-Eu
Machine
Producers
Platform
Click-Count-Action-Start
Cache-Provider
Esi-Enabled
Tube-Get-Contents
Gh-Request-Id
Tube-Got-Eval
True-Client-Country-4JS
X-Connection-Hash
Expiry
X-DC
X-Service
X-Contensis-Viewer-Groups
A
X-Branch-Name
X-Test
Cdn-Host
Cf-Device-Type
X-Core-Mission
X-Moov-Xdn-Version
X-GoCache-CacheStatus
X-Cdn-Srv
Content-Script-Type
Cdn-Request-Time
X-Varnish-Authentication
Content-Style-Type
IsBot
X-Proto
X-SIPLIST1
X-Fastly-Backend
X-ZONE
X-Hash
X-Edge-Server
W
X-Cache-Aspx
X-App-Name
AKAMAI
X-Moov-T
X-Dc
X-Parent-Response-Time
X-Via-Poph
X-Eu-Site
Cache-Key
X-Via-Popv
X-Via-Popn
X-Sn-Servicetimems
RNT-Machine
L5d-Success-Class
X-Amz-Meta-Cb-Modifiedtime
X-Csrf-Jwt
NGX
Pics-Label
X-Ah-Environment
X-HA-Backend
Proxy-Firewall
Ha-Gx-Prefs
HA-Ipaddr
RNT-Time
X-Wikidot-Static-Cache
X-CGP
X-Slack-Shared-Secret-Outcome
X-Wikidot-Backend
Fastly-Backend-Name
X-Slack-Backend
X-CacheTTL
X-NGINX-Cache
Datacenter
X-Qloud-Router
X-Owner
X-CF-Lambda-Fn
N-Cache
Cdnsip
LB
X-Accel-Expires-Debug
X-AK-Request-ID
X-ND-Cache
Yak-Timeinfo
X-Region-Sid
Cdncip
X-Date
X-CF-Lambda-Version
Locid
Expect-Staple
X-Tenant
X-HN
X-VarnishDD-TTL
X-Amz-Storage-Class
Xc-Version
X-LB-NoCache
X-LB-ID
X-Orig-Expires
PFcat
X-Shop-Environment
X-Cache-Type
X-Forwarded-Path
X-Ratelimit-Reset
Cdn
X-Backend-Instance
X-Gamma-Serve
X-Refresh
X-Varnish-Hits
X-Tb-Optimization-Total-Bytes-Saved
X-Tx-Id
X-Azure-Ref-OriginShield
X-VHOST
RATING
X-Tt-Logid
X-Servedbyhost
X-Nc
X-CDN-Cache-Status
X-Wa
X-DynaTrace-JS-Agent
NtCoent-Length
Cmsid
XM
SID
Cmstype
GeoIp-Country-Code
Cdn-Requestid
CPC-Cache
CPC-Age
X-Cdn-Diag
X-Vmg-Version
X-Origin-Expires
Server-ID
X-API-Version
X-Cache-Backend
X-TX-ID
X-Nananana
X-Srv
X-Akamai-Transformed
X-Lagoon
X-TIME
X-Fpc
X-Via-Fastly
X-LAGOON
CloudFront-Viewer-Country
X-Api-Version
X-Hit
CacheControlHeader
X-NewRelic-App-Data
Resin-Trace
X-B3-Parentspanid
X-Zone
User-Agent
X-Proxy-CacheRZ
X-Nf-Request-Id
X-Variation
Uri
XkeyRZ
Cross-Origin-Opener-Policy-Report-Only
X-Client-Ip
X-UA
X-CACHE-AGE
X-URL
X-Presslabs-Stats
MIME-Version
X-Info
X-Amz-Meta-Opti
X-Fastly-Country-Code
X-LiteSpeed-Tag
Tcn
X-Location
GeoIP-Latitude
Cache-Hits
Lb
X-Ig-Origin-Region
True-Client-IP
X-Datacenter
VNS-Cache
True-Client-Ip
VNS-Age
X-DataCenter
DataCenter
X-Dynatrace-Js-Agent
X-HostName
X-LiteSpeed-Cache-Control
X-Geo
Cache-Name
Fusion-Content-Source
Mime-Version
Fusion-Component-Id
Fusion-Deployment-Id
X-NWS-UUID-VERIFY
Fusion-Content-Id
X-Vc
Fusion-Source
X-RID
Fusion-Template-Id
Hostname
Cf-Ipcountry
Powered-By
X-B3-Spanid
Fastly-Drupal-Html
X-Cdn-Forward
X-CUA
X-Cached-By
Origin-CC
Origin-EX
X-Dispatcher-Number
X-Jungle-Id
X-HOST
X-Cloudmap
Srv
X-CSRF-TOKEN
X-User
X-IAuth-Set-Uid
X-Segment-20210421
X-AIR-PT
X-CS
X-Webkit-Csp-Report-Only
X-Mid
Debug
X-Varnish-Beresp-TTL
X-MCACHE
X-Render-Time
Cl-Cache
Load-Balancing
X-ECache
X-Powered-By-VTEX-Cache
BehaviorPad-Version
X-VTEX-Cache-Server
CDN
GeoIP-Country-Code
X-VTEX-Cache-Time
X-Dispatch
X-Wormhole-Sdk
X-Esi
Ohc-File-Size
X-FPC
X-Litespeed-Tag
X-WA
X-Oracle-DMS-ECID
X-Auth-Group-Type
Edge-Cache
X-ServedByHost
X-Cdn-Cache-Status
X-NC
X-Cs
Server-Id
Ohc-Cache-HIT
X-Lb-Id
X-Cache-Enabled
YJS-ID
X-Lb-Nocache
CountryCode
Server-Info
X-Fastly-Backend-Reqs
X-Wp-Cf-Super-Cache-Cache-Control
My-App
X-Ig-Push-State
X-Wp-Cf-Super-Cache
Location
X-NodeID
X-Litespeed-Cache-Control
Ms-Author-Via
Wpo-Cache-Message
Wpo-Cache-Status
X-APP-VERSION
X-VCL-Version
X-Internal-Host
Odigeo-Trace-Id
Xkeylog
Xkey-La3
X-Snapshot-Date
X-Proxy-Cache-La3
X-MiniProfiler-Ids
X-MSEdge-Flight
X-MSEdge-Features
X-Akamai-Pragma-Client-IP
CF-Cached-On
X-Cdn-Request-ID
CF-Ctrl
X-Custom-Header
OriginIP
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
Time
X-Acquia-Site
X-Vgn-Hpd-Reason
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
Memory
X-Acquia-Application-Trace
Memcached
X-FL-EDGE
X-App
X-FL-QIT-DEBUG
Srvid
Geoip-Latitude
FSS-Cache
Ngx
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
X-Pad
Section-Origin-Responded
X-Nitro-Rev
X-Nitro-Cache
X-Nitro-Cache-From
X-Sorting-Hat-Podid
X-Shopid
X-Sorting-Hat-Shopid
X-Cache-Version
X-Shardid
Cloudfront-Viewer-Country
X-PHP-Backend
PICS-Label
X-Depends
X-Mg-Cache
Akamai-Cache-Status
X-Te-Count
X-Via-PopH
X-Via-PopN
X-Via-PopV
X-Fastly-Cache-Hits
X-Ha-Backend
X-Te-Duration-Ms
X-Cache-FS-Status
X-Http-Count
X-Http-Duration-Ms
X-Lsadc-Cache
X-Sucuri-Id
X-Check-Cacheable
X-Serial
X-Service-Response-Time
X-Web-Server
Sm-Log-Id
X-Udemy-Cache-App-Namespace
X-Th-Server
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-RequestId
X-Dw-Trace-Id