Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
X-XSS-Protection
CF-RAY
ETag
Accept-Ranges
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-Served-By
X-UA-Compatible
P3P
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Xss-Protection
X-Varnish
X-Adblock-Key
X-FRAME-OPTIONS
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Content-Security-Policy-Report-Only
P3p
X-AspNet-Version
X-Runtime
X-DNS-Prefetch-Control
Accept-CH
X-Ua-Compatible
X-Cache-Status
X-Drupal-Cache
Accept-CH-Lifetime
X-Check
X-Generator
X-Cacheable
Server-Timing
X-Envoy-Upstream-Service-Time
X-Request-ID
Timing-Allow-Origin
X-Iinfo
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
Feature-Policy
X-Content-Security-Policy
Content-Encoding
X-CDN
Status
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
CF-Ray
X-Amz-Id-2
Host-Header
Allow
X-Backend
Cf-Edge-Cache
X-Cache-Group
Request-Context
X-Robots-Tag
Keep-Alive
X-Server
X-Hacker
X-UA-Device
X-AH-Environment
X-Turbo-Charged-By
X-Ws-Request-Id
X-Proxy-Cache
X-Vhost
Xkey
X-Rq
X-Age
EagleId
X-Dispatcher
X-Server-Powered-By
X-Amz-Version-Id
X-Varnish-Cache
Grace
X-LiteSpeed-Cache
Cf-Apo-Via
X-Page-Speed
X-Pingback
Cf-Railgun
EagleEye-TraceId
X-Device
X-Swift-CacheTime
X-Swift-SaveTime
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Dns-Prefetch-Control
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
X-CST
X-OneAgent-JS-Injection
X-WebKit-CSP
X-Backend-Server
Permissions-Policy
X-Server-Id
X-Readtime
X-Host
X-Response-Time
Request-Id
X-Akam-SW-Version
Surrogate-Control
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Nginx-Upstream-Cache-Status
X-HW
Accept-Ch-Lifetime
X-Cloud-Trace-Context
X-Nginx-Cache-Status
X-Node
X-Application-Context
X-Country-Code
X-Ruxit-JS-Agent
X-Trace
X-Cache-Lookup
Content-Location
X-Url
Service-Worker-Allowed
X-Oneagent-Js-Injection
X-Content-Type
X-Country
X-Clacks-Overhead
X-ECACHE
X-Litespeed-Cache
X-Edge
X-Origin-Cache-Key
X-Mod-Pagespeed
Accept-Ch
X-Amz-Server-Side-Encryption
X-Rack-Cache
X-FTR-Request-ID
X-Midtier
Cache-Tag
Cross-Origin-Opener-Policy
X-Mcache
X-MS-InvokeApp
Nginx-Cache
X-Upstream
X-Vname
X-TtlSet
X-PC
X-Powered-By-Plesk
Rating
X-ESI
Edge-Control
X-D2id
X-Browser-Type
X-Element-Page-Cache
X-Cdn-Fetch
Verso
X-Kinja
X-Kinja-Build
X-Exp-Id
X-Kinja-Revision
X-Exp-Variant
X-GoogleNews-Bot
X-Kinja-Server
X-Times
X-Server-Name
X-Cnection
X-Ac
SPRequestDuration
SPIisLatency
X-B3-TraceId
AR-ATIME
AR-Request-ID
AR-PoweredBy
AR-SID
X-Vcap-Request-Id
X-Navigation-Version
X-Ruxit-Js-Agent
X-Abt-Application-Version
SPRequestGuid
X-SharePointHealthScore
X-RateLimit-Remaining
X-Dw-Request-Base-Id
X-NF-Request-ID
X-GitHub-Request-Id
X-Ser
X-VARITI-CCR
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
AR-CACHE
S
X-Cache-Key
X-Mg-S
RTSS
X-Client-IP
X-Cache-TTL
Origin-Trial
X-Middleton-Display
X-Sol
Edge-Cache-Tag
Display
Pagespeed
X-Webkit-Csp
X-Amz-Rid
Fastly-Restarts
X-Amzn-Trace-Id
X-Goog-Hash
X-NWS-LOG-UUID
X-Powered-CMS
X-Ttl
X-Varnish-TTL
X-Content-Security-Policy-Report-Only
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Server-ID
X-Erf-Bev-Bev
Cache-Status
X-Kinsta-Cache
X-Edge-Location-Klb
X-Version
Access-Control-Request-Method
X-ARC
X-Recruiting
X-Content-Digest
Arr-Disable-Session-Affinity
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-TraceId
X-T
X-MSEdge-Ref
X-Forwarded-For
X-Middleton-Response
Response
X-Ua-Device
Content-MD5
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
MicrosoftSharePointTeamServices
X-Accel-Expires
TP-Cache
X-Shield-Request-Id
X-Hits
X-Cached
X-RateLimit-Limit
X-FTR-Backend-Server
X-FTR-Cache-Status
X-Country-Code-Real
Public-Key-Pins
X-FTR-Backend
X-FTR-Balancer
X-FTR-Expires
X-Request-Received
Server-Node
X-Id
X-Request-Processing-Time
Payment
X-HS-Combine-CSS
X-Ua-Browser
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
MS-Author-Via
X-Frontend
Front-End-Https
X-DIS-Request-ID
Cross-Origin-Resource-Policy
X-LLID
X-Forwarded-Proto
X-GUploader-UploadID
X-Jurisdiction
X-HP-Webp
X-FastCGI-Cache
X-HP-Trace-Id
X-WebKit-CSP-Report-Only
X-Fastcgi-Cache
Cache-Tags
X-Daa-Tunnel
TP-L2-Cache
X-LB-Cache
Realpath
X-Amzn-RequestId
X-Kinja-CCPA
X-ORACLE-DMS-RID
X-Amz-Apigw-Id
X-Protected-By
X-Origin-Server
X-Distributor
X-TTL
Count-Hit
X-Microsite
X-Request-Handler-Origin-Region
X-Page-Id
X-F-Cache
X-NGENIX-Cache
X-Www-Served-By
X-AppVersion
Mrf-Cache-Status
MRF-Tech
X-Activity-Id
X-Az
X-B3-TraceId-Primal
X-PressLabs-Stats
X-Cluster-Name
Accept-Charset
X-Varnish-Backend
Referer-Policy
X-Geo-Country
X-Correlation-Id
X-Debug-Info
X-App-Server
X-Envoy-Decorator-Operation
Host
X-FB-Debug
X-Goog-Metageneration
X-Kong-Proxy-Latency
Fastcgi-Cache
X-Kong-Upstream-Latency
X-Varnish-Server
X-ORACLE-DMS-ECID
X-Hostname
Access-Control-Allow-Method
X-Git-Hash
X-Rid
X-RateLimit-Reset
X-XRDS-LOCATION
Retry-After
X-TEC-API-ORIGIN
Server-Name
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Content-Options
X-Tt-Trace-Tag
X-Load-Cache
X-Tt-Trace-Host
X-Px
X-Fastly-Request-ID
DC
X-Route-Name
X-Request-Guid
X-Is-Crawler
X-Flags
X-Contextid
X-Origin-Cache
X-Providence-Cookie
X-Aspnet-Duration-Ms
X-Revision
X-CSRF-Token
X-B3-Sampled
X-App-Environment
X-Grace
X-Type
X-Signature
X-Oracle-Dms-Ecid
X-Trace-Id
X-B-Cache
Charset
Cleartype
X-Cache-Control
X-Mobile
Paypal-Debug-Id
X-Upgrade-Enabled
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-B
X-Datadog-Trace-Id
X-TT
X-ASPNET-VERSION
X-Fb-Rlafr
Section-Io-Cache
X-Amz-Meta-S3cmd-Attrs
X-Language
X-Seen-By
Frame-Options
X-Amz-Replication-Status
X-Ezoic-Cdn
X-Ratelimit-Limit
TCN
X-Goog-Stored-Content-Encoding
X-Whom
X-Goog-Stored-Content-Length
X-Logged-In
X-Goog-Generation
X-Goog-Storage-Class
Healthy
X-Wix-Request-Id
Filterid
X-Magnolia-Registration
X-Oracle-Dms-Rid
X-Node-Name
X-EdgeConnect-Cache-Status
X-Newrelic-App-Data
X-Azure-Ref
X-App-Version
Content-Disposition
X-N
X-Proxy
Backend
X-Fastly-Request-Id
X-Varnish-Ttl
Akamai-GRN
X-Template
Upgrade-Insecure-Requests
Refresh
NGB
X-Air-Pt
X-Proxy-Cache-Info
X-Response-Served-From
X-Original-Request-Id
X-Rendered-As
X-Is-Bot
X-Tumblr-Pixel-0
X-B3-SpanId
X-Tumblr-Pixel
X-Servername
X-Tumblr-Pixel-1
X-Tumblr-User
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Unique-Id
X-RemovedCookies
SD-X-WS
X-ProcessESI
X-Page-View
X-Yottaa-Metrics
X-Yottaa-Optimizations
Url
X-Datadog-Sampled
X-Adobe-Loc
Ms-Operation-Id
X-Amzn-Remapped-Content-Length
Liferay-Portal
Viewport
X-WP-CF-Super-Cache-Cache-Control
X-Varnish-Grace
X-Debug-IsConnected
X-Adobe-Content
X-WP-CF-Super-Cache
X-Debug-IsPreview
X-Instance
X-RTag
MS-CV
X-Cache-Grace
Fastly-SWR
X-Debug
X-FW-Hash
X-Cacheable-TTL
Fastly-SIE
X-FW-Dynamic
X-FW-Type
X-Ratelimit-Remaining
X-G
X-IPS-LoggedIn
X-FW-Version
X-Region
X-User-Agent
X-FW-Serve
X-FW-Server
X-FW-Static
X-UUID
X-Jobs
X-NYM-Debug-Backend
X-Environment-Context
X-Device-Type
From-Origin
X-L-Path
X-Rule
Country
X-Cache-Hit
X-Status
Surrogate-Key
X-Backend-Name
X-Hosted-By
X-Hl-Ver
X-Air-Hostname
X-Webkit-CSP
X-Air-Trace-Id
ServerID
X-Air-Source
X-Cache-Age
X-Time
X-Http-Reason
X-Content-Powered-By
X-VC-Cache
Alternate-Protocol
X-Cache-Status-Check
X-Akamai-Request-ID2
Protected
Amp-Access-Control-Allow-Source-Origin
X-Origin-CC
X-Origin-TTL
X-XRDS-Location
Countrycode
X-NODE
WPO-Cache-Status
WPO-Cache-Message
X-Hcs-Proxy-Type
X-Use-Magma
X-CCDN-Origin-Time
X-CCDN-CacheTTL
Version
X-B3-Traceid
X-HTML-Minification-Powered-By
X-Via-JSL
X-INCAP-ABP
X-Akamai-Edgescape
X-Rocket-Nginx-Serving-Static
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
X-Framework
SRV
X-CDN-Forward
GEO-INFO
CDN-RequestId
X-Edge-Location
X-Cache-Rule
X-WP-CF-Super-Cache-Active
Front
X-Storage
X-Accel-Version
X-Source
Access-Control-Request-Headers
CF-IPCountry
X-Nginx-Cache
X-Httpd
X-Mode
X-Use-Mantle
X-Endurance-Cache-Level
Accept-Language
X-Xfnlog-Site
Webserver
OT-Force-Account-Verify
X-Real-IP
X-UPSTREAM-Address
X-Upstream-Ht
X-Upstream-Ct
Xet-Cookie
X-VC
X-Rn-Rsrv
X-Cache-Operation
X-Rewrite-Enabled
Meta-Geo
Filters
X-Proxy-Build
X-Cache-Debug
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
X-Detected-As
X-Soup
X-SaId
Selected-Fe
X-JoinUs
X-Timing-Wait
X-Director
X-Served-From
ServedBy
X-Worker
X-Say-Cacheable
X-Say-TTL
X-SayCDN-TTL
X-Cache-Time
X-ProxyCache-Status
X-Handled-By
X-Sql-Count
X-Sql-Duration-Ms
X-Tncms
X-Varnish-Cache-Hits
X-ProxyCache-Key
X-Redis-Cache
X-Cms-Context
X-Varnish-Age
X-Adobe-Source
X-Lambda-Id
X-Loop
X-BYPASS-REASON
AMP-Access-Control-Allow-Source-Origin
Azure-InstanceId
X-PHP-Host
X-Server-W
X-Restarts
TWC-GeoIP-LatLong
TWC-GeoIP-Country
X-Origin-Hint
Azure-RegionName
TWC-Device-Class
TWC-Connection-Speed
X-GeoCountry
Property-Id
X-S
X-RM-Cache-TTL
DB-Nickname
Azure-SlotName
Azure-Version
TWC-Privacy
Azure-SiteName
TWC-Locale-Group
X-Logging-Id
X-Skip-Cache
Webcakes-App-Version
X-GeoCode
X-Varnish-Beresp-Grace
X-Format
X-Labrador-Cache-Channel
Xserver
Webcakes-Region
Web-Mar-Node
X-No-Session
Webcakes-App-Name
X-Fetched-On
Mn-Server-Ip
X-VCT
X-AWS-Id
X-IPLB-Instance
X-DynaTrace
X-IPLB-Request-ID
X-VWS-Id
Apigw-Requestid
X-Cache-Server
X-LJ-Flow-ID
X-RCS-CacheZone
X-Cache-Host
X-Container-Uri
X-Generation-Time
X-Git-Commit
X-Extlb
X-Cluster
X-Routing-Service
X-Is-Supported-Browser
X-Provided-By
X-Proxied
X-Ms-Version
X-COUNTRY
Node
X-Forwarded-Host
X-Vercel-Id
X-Tb
X-Tcp-Rtt
X-Vercel-Cache
X-Frame-Option
X-Reqid
X-Ms-Request-Id
X-Is-Tablet
X-Origin
X-Is-Mobile
X-ServerID
X-Is-Desktop
X-Geo-Region
X-AB
X-Zipkin-Id
X-Browser-Name
Cache-Tv-Group
Section-Io-Id
X-Uri
X-R9-Blue-Green-Version
X-Site-Version
X-Locale
X-FB-TRIP-ID
X-Platform-Processor
Priority
X-Web-Node
X-Platform-Cluster
X-Platform-Router
Content-Secure-Policy
X-Webstats-RespID
X-Vcache
Source
X-MP-GENERATED-AT
X-Drupal-Cache-Tags
X-Drupal-Cache-Contexts
Cross-Origin-Embedder-Policy
Fastcgi-Useragent
X-Vcl-Version
WP-Super-Cache
CDN-RequestPullSuccess
CDN-Uid
CDN-RequestPullCode
CDN-PullZone
X-Origin-Date
Onion-Location
CDN-RequestCountryCode
CDN-Cache
CDN-EdgeStorageId
CDN-CachedAt
X-Alternate-Cache-Key
X-Shopify-Stage
X-Storefront-Renderer-Rendered
WZWS-RAY
X-Urbn-Site-Id
X-Urbn-Context-Path
Locale
X-Content-Age
X-SRV
X-Generated-By
S-Rt
X-Newrelic-Synthetics
X-Ua
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-ShopId
X-ShardId
X-Pass-Why
X-Sucuri-Cache
X-TT-LOGID
X-Cluster-Node
X-Cdn-Origin
Sid
X-Buckets
X-Sucuri-ID
X-Cache-Action
X-Proxy-Cache-Status
X-Varnish-Beresp-Ttl
X-Mg-Request-UUID
X-Cache-Expired-At
Cross-Origin-Window-Policy
Cross-Origin-Embedder-Policy-Report-Only
X-Xrds-Location
X-VCache
X-Scope-Id
X-CMSURLCustom
X-Shield-Cache-Expires
TDXMobile
Thinkindot-CacheControl
X-Thinkindot-L3
Thinkindot-CacheControl-Type
Thinkindot-Control
X-LSADC-Cache
X-Datadome
Fastly-Drupal-HTML
Cache
X-GEO
HostName
X-DataDome
X-Request-URI
X-Optimistic-Header
X-Aspnetmvc-Version
X-A-Dcw
X-Aed
X-A-Dam
X-TIM-N
X-Viewer-Country
X-A-Wwc
Redirect-Candidate
Rendered-Blocks
X-Vtex-Remote-Cache
X-A-Ccd
X-A-Dgt
X-Scheme
Sslversion
X-Vdms-Version
X-Vdms-Path
Surrogated-Key
Type
CDCHOST
Candidate-Md5Url
DCR-Decision-By
X-Correlation-ID
Origin-Agent-Cluster
X-ScT
X-A
DCR-Processing-Time-Ms
Meta-Geo-Continent
X-D
T-Server
X-Conf
X-S-Cookie
MD5-Digest
X-Rojux
X-External-Request-Id
X-Destination
X-Developer
X-Ec-Fail
X-Ec-GeoHdr
X-Epic-Correlation-Id
X-PAYTM-SRV-ID
Lang
Environment
X-Bc-Bl
X-SRCache-Key
X-B-Cookie
X-Ec-Custom-Error
X-Application
Origin
X-BCube-Filmed-By
Gannett-Cam-Experience-Id
X-Cache-NE
Ngx-Var-Key
X-Cache-Bucket
Ngx.Var.Host
X-Bl-Debug
Atl-Traceid
Edge-Copy-Time
X-TimeS
X-WP-CF-Super-Cache-Cookies-Bypass
X-Via-Edge
X-Via-CDN
X-Via-SSL
X-Generated-On
X-Gdpr
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-Forwarded-Site
Magicmarker
X-Origin-Time
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Human
X-Dispatcher-Server
X-Fastly-Cache
Host-ID
X-Mly-Id
X-Men
X-SD-PageType
X-Nyt-Route
X-Node-Id
X-Loc
X-Level-Front-Cache
X-SB
X-Core-Value
X-Instance-Name
Fastly-SSL
X-Op-Id-All
L
X-Platform
X-Request-Start
X-Req
X-Request-Time
Vix-Hermes-Req-Id
X-Proxied-Request
Server-Ext
V-Age
Sever-Int
Ssr
X-Pubstack
Server-Hostname
Server-Host
X-Section
Req-Svc-Chain
X-B3-Trace-ID
X-Pool
X-BBC-Edge-Cache-Status
X-Bip
X-Rocket-Build-Number
X-Aicache-OS
Pramga
Req-ID
X-Access
Release
X-Acquia-Purge-Cdn-Unconfigured
X-Cache-Info
Fastly-GeoIP-CountryCode
X-TH-Server
X-Thanos
X-Sigma-Backend
X-Sigma
Apple-News-Services-Host
Apple-News-Services-Handled
X-Up
X-Varnish-Beresp-Status
X-VG-WebCache
X-VServer
X-VG-TLSProxy
X-Varnishpool
X-Varnish-Director
X-Varnish-Hostname
Apple-News-Services-Parsed-Url
X-We-Are-Hiring
Apple-News-Services-Request-Url
X-Server-IP
X-Origin-Response-Time
X-Service
User-Cache-Control
DSUID
X-Clientip
X-Policy
X-Auto-Login
Tube-Get-Contents
X-Block-Status
X-WA-Info
X-Cache-TTL-Remaining
X-Cache-Id
X-PERF
X-Cache-Date
X-ApacheServer
X-Ad-Load-Variation
We-Hiring
Click-Count-Action-Start
Uber-Trace-Id
Click-Count-Error
Web-Mar-Region
Wxu-Next-Commit
Wxu-Next-Region
Tube-Got-Eval
Tube-Got-Results
Wxu-Next-Hostname
Tube-Return
X-DPWN-IS-SECURE
X-Org
X-Irp-Debug
X-HS-Content-Campaign-Id
X-Hnp-Log
X-Hash
X-Micro-Cache
X-Old-Content-Length
X-Nginx-Cache-Key
X-NCache
X-Mvc-Supplant-OutputCached
X-Mvc-Supplant-Cachable
X-Gzip
X-GeoIP-City
X-Fastly-Backend
X-Esi-Check
True-Client-Country-4JS
X-Device-Os
X-FC-Vary-Parameters
X-Fmm-Version
X-GeoIP
X-Geo-Header
X-Gen-Mode
X-From
X-Core-Mission
X-Zen-Fury
X-SVT-ORM-VERSION
Platform
On-Server
Producers
Cache-Provider
Country-Code
X-UA-Device-Type
NM-Fastcgi-Cache
C-Via
Gh-Request-Id
Esi-Enabled
X-NMSegId
Is-Eu
Adler-Geo
Mail-Subject
Machine
X-V-Cache
X-SVT-ORM-RULES
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
Canary
X-Var-Ttl
X-DC
W
Proxy-Firewall
X-Slack-Backend
X-Request-Host
X-SIPLIST1
X-Proto
Pics-Label
X-Cdn-Srv
X-Via-Poph
X-Via-Popn
X-Edge-Server
Cluster
Cf-Device-Type
X-Sn-Servicetimems
X-CacheTTL
X-Slack-Shared-Secret-Outcome
X-ZONE
Cdn-Request-Time
AKAMAI
Cdn-Host
X-Via-Popv
X-HA-Backend
IsBot
X-GoCache-CacheStatus
X-App-Name
X-Test
Expiry
X-Dc
X-TA-CDN-Provider
X-Connection-Hash
X-Parent-Response-Time
Content-Style-Type
X-Varnish-Authentication
Content-Script-Type
LB
X-Branch-Name
HA-Ipaddr
L5d-Success-Class
NGX
X-Eu-Site
X-Ah-Environment
Ha-Gx-Prefs
N-Cache
A
X-Date
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Amz-Meta-Cb-Modifiedtime
X-Owner
X-Accel-Expires-Debug
Expect-Staple
X-NGINX-Cache
X-Cache-Aspx
X-CF-Lambda-Fn
X-Moov-T
X-Csrf-Jwt
X-Moov-Xdn-Version
Fastly-Backend-Name
X-Contensis-Viewer-Groups
X-CGP
X-CF-Lambda-Version
Datacenter
X-Tenant
X-Shop-Environment
X-Orig-Expires
RNT-Time
X-Qloud-Router
X-Cache-Type
Xc-Version
Cache-Key
X-Forwarded-Path
RNT-Machine
X-Tt-Logid
X-AK-Request-ID
X-LB-NoCache
Yak-Timeinfo
X-Gamma-Serve
X-LB-ID
Cdnsip
Locid
X-ND-Cache
X-Region-Sid
Cdncip
X-Ratelimit-Reset
Cdn
X-HN
PFcat
X-Amz-Storage-Class
X-Varnish-Hits
Cmstype
X-VarnishDD-TTL
X-Refresh
Cmsid
X-Tx-Id
SID
X-VHOST
X-Wa
X-Vmg-Version
X-Servedbyhost
X-Tb-Optimization-Total-Bytes-Saved
NtCoent-Length
X-Backend-Instance
X-CDN-Cache-Status
X-Cdn-Diag
Server-ID
X-DynaTrace-JS-Agent
CPC-Cache
X-Nc
RATING
GeoIp-Country-Code
CPC-Age
X-Azure-Ref-OriginShield
Cdn-Requestid
XM
X-LAGOON
X-Api-Version
X-TX-ID
X-API-Version
X-Cache-Backend
X-Origin-Expires
X-Fpc
X-Nananana
X-TIME
X-Srv
X-Akamai-Transformed
CloudFront-Viewer-Country
X-B3-Parentspanid
CacheControlHeader
X-Via-Fastly
Resin-Trace
X-Hit
X-Lagoon
X-Variation
Tcn
X-HostName
X-Nf-Request-Id
X-Proxy-CacheRZ
XkeyRZ
User-Agent
X-CACHE-AGE
Uri
X-Client-Ip
X-Zone
X-LiteSpeed-Tag
X-Fastly-Country-Code
Cross-Origin-Opener-Policy-Report-Only
X-URL
X-NewRelic-App-Data
VNS-Cache
X-Amz-Meta-Opti
MIME-Version
VNS-Age
X-LiteSpeed-Cache-Control
X-Datacenter
X-Info
Cache-Name
X-UA
X-MCACHE
Lb
X-Esi
True-Client-IP
True-Client-Ip
X-Vc
X-Dynatrace-Js-Agent
DataCenter
X-Location
X-DataCenter
GeoIP-Latitude
X-Geo
X-Presslabs-Stats
X-Ig-Origin-Region
Mime-Version
X-CSRF-TOKEN
Cache-Hits
Hostname
X-AIR-PT
Fusion-Content-Source
Cf-Ipcountry
X-Dispatcher-Number
Fusion-Content-Id
Fusion-Component-Id
X-NWS-UUID-VERIFY
Fusion-Deployment-Id
Fusion-Template-Id
Fusion-Source
Fastly-Drupal-Html
X-B3-Spanid
Powered-By
X-Cached-By
Origin-EX
X-CUA
X-Jungle-Id
X-Mid
Origin-CC
X-Cloudmap
X-Cdn-Forward
X-Webkit-Csp-Report-Only
X-RID
X-User
X-Segment-20210421
X-IAuth-Set-Uid
X-Varnish-Beresp-TTL
X-CS
Srv
Ohc-File-Size
Debug
BehaviorPad-Version
X-ECache
X-Render-Time
GeoIP-Country-Code
Cl-Cache
X-FPC
X-Dispatch
CDN
Ohc-Cache-HIT
X-Litespeed-Tag
X-VTEX-Cache-Time
X-NC
X-VTEX-Cache-Server
X-Cdn-Cache-Status
X-WA
X-Powered-By-VTEX-Cache
X-ServedByHost
Server-Id
Load-Balancing
X-Oracle-DMS-ECID
X-Cache-Enabled
X-Wormhole-Sdk
X-Cs
CountryCode
X-Lb-Id
YJS-ID
Edge-Cache
X-Lb-Nocache
My-App
Location
Server-Info
X-Auth-Group-Type
X-Snapshot-Date
X-Internal-Host
X-Fastly-Backend-Reqs
CF-Ctrl
X-Traceid
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
Ms-Author-Via
X-ID
X-VCL-Version
Wpo-Cache-Message
X-Litespeed-Cache-Control
Wpo-Cache-Status
Xkeylog
Xkey-La3
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
X-MSEdge-Features
X-NodeID
X-Nitro-Rev
X-Ig-Push-State
X-Nitro-Cache
Section-Origin-Responded
X-Proxy-Cache-La3
X-MiniProfiler-Ids
X-Nitro-Cache-From
X-Akamai-Pragma-Client-IP
X-Cdn-Request-ID
X-App
CF-Cached-On
X-MSEdge-Flight
X-Dw-Trace-Id
X-IN-APIGATEWAY
OriginIP
X-IN-APIGATEWAYSSL
X-Acquia-Application-Trace
Time
Srvid
X-FL-EDGE
X-APP-VERSION
Memory
X-Acquia-Site
Ngx
Memcached
X-Cache-FS-Status
Geoip-Latitude
X-Acquia-Purge-Tags
FSS-Cache
X-Acquia-Application-UUID
X-FL-QIT-DEBUG
Odigeo-Trace-Id
X-Sorting-Hat-Shopid
X-Sorting-Hat-Podid
X-Shopid
X-Cache-Version
X-Shardid
Akamai-Cache-Status
X-Via-PopH
X-Ha-Backend
X-Te-Duration-Ms
X-Te-Count
X-Lsadc-Cache
X-Via-PopN
X-Vgn-Hpd-Reason
Cloudfront-Viewer-Country
X-Fastly-Cache-Hits
X-Via-PopV
X-Pad
X-Http-Duration-Ms
X-Udemy-Cache-App-Namespace
X-RequestId
X-Service-Response-Time
X-Serial
X-Check-Cacheable
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Th-Server
X-Http-Count
X-Web-Server
X-Mg-Cache
X-Sucuri-Id
Sm-Log-Id