Threat Level: green Handler on Duty: Richard Porter

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
CF-RAY
ETag
Accept-Ranges
Expect-CT
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-Xss-Protection
X-UA-Compatible
X-Served-By
P3P
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
X-AspNet-Version
Content-Security-Policy-Report-Only
X-Runtime
Accept-CH
P3p
X-Drupal-Cache
X-Cache-Status
Accept-CH-Lifetime
X-DNS-Prefetch-Control
X-Generator
X-Check
X-Ua-Compatible
Server-Timing
X-Cacheable
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Iinfo
X-Request-ID
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
X-Content-Security-Policy
Feature-Policy
Content-Encoding
X-CDN
Status
X-AspNetMvc-Version
Upgrade
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
X-Amz-Id-2
Host-Header
CF-Ray
Cf-Edge-Cache
X-Backend
Request-Context
Keep-Alive
X-UA-Device
Allow
X-Robots-Tag
X-Server
X-Cache-Group
X-Hacker
X-AH-Environment
X-Turbo-Charged-By
EagleId
X-Ws-Request-Id
X-Proxy-Cache
X-Age
Xkey
X-Rq
X-Vhost
X-Dns-Prefetch-Control
X-Dispatcher
X-Amz-Version-Id
X-Server-Powered-By
X-Varnish-Cache
Grace
Cf-Apo-Via
X-Swift-CacheTime
X-Swift-SaveTime
X-Page-Speed
Ali-Swift-Global-Savetime
X-Pingback
X-LiteSpeed-Cache
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
Cf-Railgun
Permissions-Policy
EagleEye-TraceId
X-OneAgent-JS-Injection
X-WebKit-CSP
X-Backend-Server
X-CST
X-Aws-Lambda-Call-Status
X-Server-Id
X-Host
X-Readtime
X-Response-Time
X-Akam-SW-Version
X-Cache-Lookup
Request-Id
Surrogate-Control
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-HW
X-Litespeed-Cache
X-Nginx-Upstream-Cache-Status
X-Cloud-Trace-Context
X-Node
Accept-Ch-Lifetime
X-Nginx-Cache-Status
X-Application-Context
X-Country-Code
Content-Location
X-Country
X-Trace
Service-Worker-Allowed
X-Ruxit-JS-Agent
X-Content-Type
X-Clacks-Overhead
X-Url
X-Oneagent-Js-Injection
Rating
X-Rack-Cache
Cache-Tag
X-Origin-Cache-Key
X-Amz-Server-Side-Encryption
X-FTR-Request-ID
Cross-Origin-Opener-Policy
X-Edge
X-TtlSet
X-Vname
X-PC
Nginx-Cache
X-Midtier
X-Mcache
X-MS-InvokeApp
X-Mod-Pagespeed
X-Upstream
X-ECACHE
X-Powered-By-Plesk
X-Server-Name
X-NWS-LOG-UUID
Edge-Control
X-Browser-Type
X-Cnection
X-ESI
X-Times
X-D2id
X-Element-Page-Cache
Verso
X-Cdn-Fetch
X-Kinja-Server
X-Exp-Variant
X-Kinja-Build
X-Kinja-Revision
X-Exp-Id
X-GoogleNews-Bot
X-Kinja
X-Ac
X-Ser
AR-Request-ID
AR-SID
AR-ATIME
AR-PoweredBy
X-RateLimit-Remaining
SPIisLatency
SPRequestDuration
X-Ruxit-Js-Agent
X-B3-TraceId
SPRequestGuid
X-SharePointHealthScore
X-NF-Request-ID
X-GitHub-Request-Id
X-Navigation-Version
X-Abt-Application-Version
X-Dw-Request-Base-Id
X-Vcap-Request-Id
AR-CACHE
X-Ttl
X-Mg-S
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
Pagespeed
X-Middleton-Display
Display
X-Sol
Edge-Cache-Tag
S
X-VARITI-CCR
Fastly-Restarts
X-Client-IP
X-Amzn-Trace-Id
X-Cache-TTL
RTSS
X-Cache-Key
X-Webkit-Csp
X-Amz-Rid
X-Instrumentation
X-Erf-Bev-Bev
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Erf-Bev-Bev-Is-Generated
Accept-Ch
Cache-Status
X-Powered-CMS
X-Edge-Location-Klb
X-Kinsta-Cache
X-Version
Access-Control-Request-Method
X-Daa-Tunnel
X-Goog-Hash
X-Server-ID
X-Recruiting
X-Middleton-Response
Response
X-Varnish-TTL
X-Content-Digest
X-ARC
X-TraceId
X-Forwarded-For
X-T
Arr-Disable-Session-Affinity
X-MSEdge-Ref
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
Content-MD5
Cross-Origin-Resource-Policy
MS-Author-Via
X-SRCache-Fetch-Status
X-SRCache-Store-Status
MicrosoftSharePointTeamServices
TP-Cache
Front-End-Https
X-Shield-Request-Id
X-Accel-Expires
X-RateLimit-Limit
X-FastCGI-Cache
X-Cached
X-Hits
X-FTR-Balancer
X-FTR-Backend
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Backend-Server
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Combine-CSS
X-Request-Processing-Time
Server-Node
Public-Key-Pins
X-Request-Received
X-FTR-Expires
X-Ua-Browser
X-Forwarded-Proto
X-Id
X-Frontend
X-Content-Security-Policy-Report-Only
Payment
Realpath
X-Protected-By
X-LLID
X-DIS-Request-ID
X-HP-Trace-Id
X-Jurisdiction
X-HP-Webp
X-ORACLE-DMS-RID
X-Distributor
X-GUploader-UploadID
X-Fastcgi-Cache
TP-L2-Cache
Origin-Trial
X-Kong-Upstream-Latency
X-Hostname
X-Kong-Proxy-Latency
Cache-Tags
X-LB-Cache
X-Request-Handler-Origin-Region
X-Microsite
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Debug-Info
X-Origin-Server
Count-Hit
Host
Referer-Policy
Fastcgi-Cache
X-Envoy-Decorator-Operation
Mrf-Cache-Status
X-Page-Id
MRF-Tech
X-Activity-Id
X-Az
X-B3-TraceId-Primal
X-AppVersion
X-Cluster-Name
X-Www-Served-By
X-Varnish-Server
X-Varnish-Backend
X-Correlation-Id
Accept-Charset
X-Geo-Country
X-NGENIX-Cache
X-XRDS-LOCATION
X-App-Server
X-Fastly-Request-ID
X-F-Cache
X-PressLabs-Stats
X-ORACLE-DMS-ECID
X-Ua-Device
Retry-After
X-Ezoic-Cdn
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-FB-Debug
X-RateLimit-Reset
X-Goog-Metageneration
X-Load-Cache
X-Upgrade-Enabled
X-Px
X-Ratelimit-Limit
X-Git-Hash
X-Seen-By
TCN
Access-Control-Allow-Method
X-CSRF-Token
Server-Name
X-Amz-Meta-S3cmd-Attrs
Cleartype
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Request-Guid
X-Revision
Section-Io-Cache
X-Contextid
X-Type
X-Trace-Id
X-Datadog-Trace-Id
Charset
X-Grace
X-B
X-Cache-Control
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Content-Options
X-Varnish-Ttl
Paypal-Debug-Id
X-B3-Sampled
X-Azure-Ref
DC
Healthy
X-TT
X-Whom
X-Fb-Rlafr
X-TTL
X-Wix-Request-Id
X-Proxy
X-B-Cache
X-Signature
X-Air-Pt
X-Newrelic-App-Data
X-App-Environment
X-Oracle-Dms-Ecid
X-Mobile
X-Node-Name
X-N
Frame-Options
X-Magnolia-Registration
X-Amz-Replication-Status
X-EdgeConnect-Cache-Status
Filterid
X-WP-CF-Super-Cache
X-Origin-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Stored-Content-Length
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-Oracle-Dms-Rid
X-Logged-In
X-Time
X-WebKit-CSP-Report-Only
Content-Disposition
X-Fastly-Request-Id
Backend
NGB
Viewport
X-Original-Request-Id
Akamai-GRN
X-Response-Served-From
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Rendered-As
X-Is-Bot
X-Debug-IsPreview
SD-X-WS
X-Debug-IsConnected
X-Varnish-Grace
X-ProcessESI
X-RemovedCookies
X-Tumblr-Pixel-0
X-RTag
X-Tumblr-Pixel-1
X-Unique-Id
X-Tumblr-User
X-Tumblr-Pixel
Ms-Operation-Id
Liferay-Portal
X-Servername
MS-CV
X-Yottaa-Metrics
X-FW-Serve
X-Amzn-Remapped-Content-Length
X-FW-Hash
X-Adobe-Loc
X-FW-Server
X-Adobe-Content
X-Datadog-Sampled
X-Yottaa-Optimizations
X-Debug
X-FW-Dynamic
X-FW-Version
X-Instance
X-Hl-Ver
X-FW-Static
X-IPS-LoggedIn
X-FW-Type
X-UUID
X-NYM-Debug-Backend
X-Cache-Grace
Upgrade-Insecure-Requests
ServerID
Fastly-SIE
X-Cacheable-TTL
Fastly-SWR
X-Environment-Context
X-G
X-L-Path
From-Origin
X-Region
X-Proxy-Cache-Info
X-Backend-Name
X-Language
X-Cache-Age
X-Cache-Hit
X-Via-JSL
X-User-Agent
X-Ratelimit-Remaining
Country
X-VC-Cache
X-Status
X-Template
X-Device-Type
X-Rule
X-Rid
X-B3-SpanId
Refresh
Version
X-Route-Name
X-Flags
X-Is-Crawler
X-Aspnet-Duration-Ms
X-Providence-Cookie
Url
X-Source
X-INCAP-ABP
SRV
X-Webkit-CSP
Countrycode
CDN-RequestId
GEO-INFO
X-App-Version
X-Storage
X-HTML-Minification-Powered-By
X-Air-Source
X-Air-Hostname
Alternate-Protocol
X-Air-Trace-Id
X-Cache-Status-Check
X-Jobs
WPO-Cache-Message
WPO-Cache-Status
X-WP-CF-Super-Cache-Active
X-NODE
OT-Force-Account-Verify
X-CDN-Forward
X-Origin-TTL
X-Origin-CC
X-Akamai-Request-ID2
X-Real-IP
X-Nginx-Cache
Amp-Access-Control-Allow-Source-Origin
X-Content-Powered-By
X-B3-Traceid
Protected
X-Rocket-Nginx-Serving-Static
X-Hosted-By
AMP-Access-Control-Allow-Source-Origin
X-ServerID
X-Accel-Version
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
X-Cache-Time
Access-Control-Request-Headers
Surrogate-Key
X-Cache-Rule
X-Cache-Operation
X-Akamai-Edgescape
X-Handled-By
X-VC
X-Mode
X-TT-LOGID
X-Endurance-Cache-Level
X-XRDS-Location
X-UPSTREAM-Address
X-Upstream-Ct
X-Upstream-Ht
X-Platform-Processor
Meta-Geo
X-Platform-Router
Filters
Xet-Cookie
X-Edge-Location
CF-IPCountry
X-Rewrite-Enabled
X-Rn-Rsrv
X-Xfnlog-Site
X-Platform-Cluster
X-Varnish-Cache-Hits
X-LJ-Flow-ID
X-Origin
X-Sucuri-Cache
X-Tumblr-Pixel-2
Section-Io-Id
X-Tumblr-Pixel-3
X-AWS-Id
X-Cache-Debug
X-SaId
X-Detected-As
X-VWS-Id
X-Director
X-JoinUs
X-Soup
Webserver
Cross-Origin-Embedder-Policy
X-Framework
X-Labrador-Cache-Channel
X-Served-From
X-SayCDN-TTL
Front
X-Say-TTL
Mn-Server-Ip
TWC-Connection-Speed
Property-Id
Node
X-Say-Cacheable
X-Lambda-Id
X-PHP-Host
X-Proxied
X-Use-Mantle
X-Origin-Hint
X-Redis-Cache
X-Routing-Service
X-Kinja-CCPA
X-Restarts
TWC-Device-Class
ServedBy
X-Worker
Webcakes-Region
Webcakes-App-Version
X-Extlb
X-Drupal-Cache-Tags
X-Web-Node
X-Cluster
X-Cms-Context
Webcakes-App-Name
X-Adobe-Source
X-Zipkin-Id
Web-Mar-Node
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Privacy
TWC-Locale-Group
Azure-SlotName
Azure-Version
Azure-RegionName
X-GeoCountry
Azure-SiteName
X-GeoCode
X-Page-View
X-Format
X-Loop
X-No-Session
X-BYPASS-REASON
X-Drupal-Cache-Contexts
Apigw-Requestid
X-Skip-Cache
X-Tncms
X-Logging-Id
X-Webstats-RespID
Azure-InstanceId
X-Varnish-Age
X-RM-Cache-TTL
X-Sucuri-ID
Accept-Language
X-ProxyCache-Status
X-ProxyCache-Key
X-RCS-CacheZone
CDN-EdgeStorageId
CDN-PullZone
CDN-CachedAt
Xserver
CDN-RequestCountryCode
CDN-Cache
X-Fetched-On
X-Vercel-Cache
X-Container-Uri
X-Vercel-Id
X-VCT
CDN-Uid
CDN-RequestPullSuccess
X-Generation-Time
X-Forwarded-Host
CDN-RequestPullCode
X-Git-Commit
X-Shopify-Stage
X-Is-Tablet
X-Is-Supported-Browser
X-S
X-Locale
X-Cache-Server
X-Proxy-Build
X-Reqid
X-Site-Version
X-Is-Mobile
X-Tcp-Rtt
X-Httpd
X-Timing-Wait
X-IPLB-Instance
X-Tb
X-Is-Desktop
X-IPLB-Request-ID
X-Storefront-Renderer-Rendered
X-Varnish-Beresp-Grace
X-Geo-Region
Selected-Fe
X-Browser-Name
X-Alternate-Cache-Key
X-AB
X-Cache-Host
X-Ms-Request-Id
X-Ms-Version
X-Origin-Date
X-R9-Blue-Green-Version
X-Frame-Option
X-Vcache
X-Provided-By
DB-Nickname
X-Sorting-Hat-ShopId
X-ShopId
X-Sorting-Hat-PodId
X-ShardId
X-Server-W
WP-Super-Cache
Atl-Traceid
X-Cdn-Origin
Fastcgi-Useragent
X-MP-GENERATED-AT
X-Uri
X-Vcl-Version
Cross-Origin-Embedder-Policy-Report-Only
X-Generated-By
Source
Cache-Tv-Group
X-Http-Reason
X-SRV
Cross-Origin-Window-Policy
X-Pass-Why
X-FB-TRIP-ID
Content-Secure-Policy
X-Shield-Cache-Expires
X-Thinkindot-L3
X-Scope-Id
Sid
X-CMSURLCustom
TDXMobile
X-RID
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
Thinkindot-Control
X-Buckets
X-Azure-Ref-OriginShield
Cache
Onion-Location
X-DynaTrace
X-Urbn-Context-Path
Priority
X-Urbn-Site-Id
Locale
X-LSADC-Cache
X-Content-Age
X-DataDome
HostName
X-Sql-Duration-Ms
X-WP-CF-Super-Cache-Cookies-Bypass
X-Sql-Count
X-GEO
X-Optimistic-Header
X-Varnish-Beresp-Ttl
X-Dc
X-Xrds-Location
X-Cluster-Node
X-UA
X-Proxy-Cache-Status
X-Newrelic-Synthetics
X-Request-URI
X-Connection-Hash
X-Lagoon
X-TA-CDN-Provider
User-Cache-Control
X-Cache-Action
Expiry
DCR-Processing-Time-Ms
X-S-Cookie
A
DCR-Decision-By
Candidate-Md5Url
Vix-Hermes-Req-Id
X-TIM-N
X-Vdms-Version
X-Viewer-Country
X-Vtex-Remote-Cache
Gannett-Cam-Experience-Id
X-Vdms-Path
X-Varnish-Hostname
X-Scheme
X-ScT
X-SRCache-Key
X-SB
X-Instance-Name
X-Cache-Bucket
X-Bl-Debug
Rendered-Blocks
X-BCube-Filmed-By
X-Cache-NE
Surrogated-Key
Redirect-Candidate
X-D
X-Conf
Server-Ext
X-B-Cookie
X-A-Wwc
X-A-Dgt
X-A-Dcw
X-A-Dam
Sever-Int
Server-Hostname
X-A-Ccd
X-Application
X-Aed
X-Destination
X-Developer
Ngx-Var-Key
Ngx.Var.Host
X-Op-Id-All
X-ND-Cache
Meta-Geo-Continent
MD5-Digest
X-PAYTM-SRV-ID
Lang
Magicmarker
Sslversion
Origin
X-Ec-Fail
Origin-Agent-Cluster
X-Ec-Custom-Error
X-Dispatcher-Server
X-Ec-GeoHdr
X-Epic-Correlation-Id
X-A
X-External-Request-Id
T-Server
X-Rojux
Server-Host
WZWS-RAY
Locid
X-Bc-Bl
X-Block-Status
X-BBC-Edge-Cache-Status
X-B3-Trace-ID
X-Amz-Storage-Class
X-Auto-Login
X-Cache-Id
X-Cache-TTL-Remaining
X-Esi-Check
X-Fastly-Cache
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Amz-Meta-Cb-Modifiedtime
X-Core-Value
X-Cache-Info
X-AK-Request-ID
Pramga
Req-ID
Req-Svc-Chain
NM-Fastcgi-Cache
L
Fastly-SSL
Host-ID
Ssr
X-Correlation-ID
Wxu-Next-Region
X-Access
X-Acquia-Purge-Cdn-Unconfigured
Wxu-Next-Hostname
Wxu-Next-Commit
V-Age
X-Cache-Expired-At
X-Gdpr
X-Generated-On
X-SD-PageType
X-Section
X-Sigma
X-Rocket-Build-Number
X-Request-Time
X-Req
X-Request-Start
X-Sigma-Backend
X-UA-Device-Type
X-We-Are-Hiring
X-Zen-Fury
C-Via
X-VServer
X-VG-WebCache
X-Varnish-Director
X-VG-TLSProxy
X-Proxied-Request
X-Pool
X-Hnp-Log
X-Human
X-Level-Front-Cache
X-Gzip
X-GeoIP-Region-Code
Fastly-GeoIP-CountryCode
X-GeoIP-Country-Code
X-Mly-Id
X-NCache
X-Origin-Time
X-Platform
X-Nyt-Route
X-NMSegId
X-Datadome
X-Nginx-Cache-Key
X-Gen-Mode
X-Loc
Cdnsip
Apple-News-Services-Handled
Cluster
Content-Script-Type
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
CDCHOST
Cdncip
Apple-News-Services-Request-Url
Fastly-Drupal-HTML
Content-Style-Type
Environment
X-TimeS
X-Service
LB
X-Origin-Response-Time
X-Cache-Date
X-Device-Os
Adler-Geo
X-Fmm-Version
X-DPWN-IS-SECURE
X-From
X-GeoIP-City
X-GoCache-CacheStatus
X-GeoIP
X-Geo-Header
X-Contensis-Viewer-Groups
X-Forwarded-Site
X-Cdn-Srv
Cache-Provider
X-Bip
XM
X-Backend-Instance
Yak-Timeinfo
X-ApacheServer
X-Branch-Name
X-Cache-Aspx
X-Moov-T
Tube-Return
X-Moov-Xdn-Version
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Clientip
X-HS-Content-Campaign-Id
X-VarnishDD-TTL
X-Varnishpool
X-Varnish-Beresp-Status
X-Varnish-Authentication
X-Thanos
X-V-Cache
X-WA-Info
Click-Count-Action-Start
Release
Tube-Get-Contents
On-Server
DSUID
Click-Count-Error
X-TH-Server
X-RateLimit-Remaining-Second
Tube-Got-Results
X-Node-Id
X-Micro-Cache
X-Men
Tube-Got-Eval
X-Aicache-OS
X-Old-Content-Length
X-Pubstack
X-RateLimit-Limit-Second
X-PERF
X-Origin-Expires
X-Org
X-HN
X-Request-Host
PFcat
True-Client-Country-4JS
We-Hiring
Web-Mar-Region
Machine
RNT-Time
RNT-Machine
Producers
Platform
Esi-Enabled
Is-Eu
Country-Code
Mail-Subject
Uber-Trace-Id
X-Ad-Load-Variation
X-Via-SSL
Edge-Copy-Time
X-Via-CDN
X-Via-Edge
X-Test
X-Wikidot-Static-Cache
X-Slack-Shared-Secret-Outcome
X-Slack-Backend
Cdn-Request-Time
X-ECache
X-Edge-Server
X-VCache
X-Fastly-Backend
X-FC-Vary-Parameters
X-Hash
X-Mvc-Supplant-Cachable
S-Rt
Gh-Request-Id
X-Region-Sid
X-Cache-Backend
X-Policy
Proxy-Firewall
X-Server-IP
X-Wikidot-Backend
Canary
X-App-Name
X-Up
X-Sn-Servicetimems
X-Var-Ttl
Cache-Key
AKAMAI
Cf-Device-Type
W
Cdn-Host
X-DC
X-Mvc-Supplant-OutputCached
X-Csrf-Jwt
X-CGP
L5d-Success-Class
HA-Ipaddr
NGX
Ha-Gx-Prefs
X-API-Version
Fastly-Backend-Name
X-Proto
X-Accel-Expires-Debug
X-Eu-Site
X-Parent-Response-Time
X-Date
X-Esi
X-Tx-Id
X-Mg-Request-UUID
X-Varnish-Hits
X-CacheTTL
X-LB-ID
Type
X-Ah-Environment
X-Tb-Optimization-Total-Bytes-Saved
X-Ua
Cache-Hits
X-PDP-UNCACHING-HASH
X-Via-Popv
X-COUNTRY
X-Servedbyhost
X-Via-Poph
Pics-Label
X-HA-Backend
X-Via-Popn
X-URL
X-Zone
X-CACHE-GROUP
X-NGINX-Cache
X-Refresh
X-DynaTrace-JS-Agent
X-Via-Fastly
Datacenter
Cdn
X-Ratelimit-Reset
GeoIp-Country-Code
NtCoent-Length
X-Irp-Debug
X-CDN-Cache-Status
X-LB-NoCache
X-Cloudmap
X-VHOST
X-NWS-UUID-VERIFY
X-Ig-Origin-Region
SID
X-Client-Ip
X-Owner
X-Location
Cdn-Requestid
X-Core-Mission
Fusion-Deployment-Id
Fusion-Source
Fusion-Template-Id
X-Wa
Fusion-Content-Id
X-Nc
IsBot
X-Akamai-Transformed
Fusion-Content-Source
Server-ID
X-ZONE
Fusion-Component-Id
X-SIPLIST1
X-Srv
Powered-By
Resin-Trace
X-TX-ID
X-Fpc
Origin-EX
X-Nananana
Cross-Origin-Opener-Policy-Report-Only
Origin-CC
GeoIP-Latitude
X-Qloud-Router
X-Jungle-Id
X-CF-Lambda-Fn
X-CF-Lambda-Version
DataCenter
X-User
X-Hit
Expect-Staple
N-Cache
X-Wormhole-Sdk
X-CUA
X-CS
X-Cache-Type
X-DataCenter
Mime-Version
CloudFront-Viewer-Country
X-B3-Parentspanid
X-Proxy-CacheRZ
X-Shop-Environment
X-Nf-Request-Id
X-Orig-Expires
XkeyRZ
X-NewRelic-App-Data
Xc-Version
X-Forwarded-Path
X-Tenant
X-Segment-20210421
X-Presslabs-Stats
X-Render-Time
X-Cached-By
X-IAuth-Set-Uid
Uri
X-Gamma-Serve
Cmstype
Cmsid
X-CACHE-AGE
X-VTEX-Cache-Server
X-VTEX-Cache-Time
X-Powered-By-VTEX-Cache
X-Amz-Meta-Opti
Debug
True-Client-IP
X-TIME
User-Agent
CPC-Age
CPC-Cache
X-Tt-Logid
Fastly-Drupal-Html
True-Client-Ip
X-Cdn-Diag
Cf-Ipcountry
Edge-Cache
X-Auth-Group-Type
X-Info
X-Vmg-Version
X-Dynatrace-Js-Agent
X-LiteSpeed-Tag
X-Fastly-Country-Code
X-Geo
X-Vc
CDN
MIME-Version
X-Dispatch
X-Oracle-DMS-ECID
X-Datacenter
X-Varnish-Beresp-TTL
X-Ig-Push-State
Load-Balancing
X-CSRF-TOKEN
Tcn
X-B3-Spanid
CacheControlHeader
X-Variation
Odigeo-Trace-Id
Srv
X-HOST
X-LiteSpeed-Cache-Control
X-Cs
Hostname
X-LAGOON
X-Vgn-Hpd-Reason
X-NodeID
X-HostName
X-Custom-Header
Ohc-File-Size
X-Cdn-Forward
X-Webkit-Csp-Report-Only
X-PHP-Backend
X-AIR-PT
X-FPC
Cl-Cache
X-Depends
X-Pad
X-APP-VERSION
X-DefElseHash
VNS-Age
X-WA
VNS-Cache
X-NC
X-DefHash
Server-Id
X-MCACHE
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Varnish-CookieHashed-On
Ohc-Cache-HIT
GeoIP-Country-Code
X-Lb-Nocache
X-M-Log
X-M-Reqid
X-Api-Version
X-VC-TTL
X-Cdn-Cache-Status
Geoip-Latitude
X-APP
X-Dispatcher-Number
Epwk-X-Cache
X-ServedByHost
X-Cache-FS-Status
X-Cache-Ttl
X-CACHE-KEY
Lb
Cloudfront-Viewer-Country
X-Litespeed-Tag
X-Fastly-Backend-Reqs
X-MSEdge-Features
X-MSEdge-Flight
X-Via-PopN
X-Via-PopV
X-Via-PopH
PICS-Label
CountryCode
X-Ha-Backend
X-Use-Magma
X-Srcache-Fetch-Status
X-Litespeed-Cache-Control
X-Srcache-Store-Status
X-VCL-Version
X-Cdn-Request-ID
Xkeylog
X-Proxy-Cache-La3
Xkey-La3
X-Lb-Id
X-Akamai-Pragma-Client-IP
Cache-Name
Server-Info
FSS-Cache
OriginIP
X-Snapshot-Date
X-Web-Server
Ngx
X-Mid
X-IN-APIGATEWAYSSL
X-MiniProfiler-Ids
X-RequestId
X-IN-APIGATEWAY
Memory
Memcached
Time
X-Acquia-Site
X-Th-Server
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
X-Acquia-Application-Trace
X-Shopid
X-Sorting-Hat-Shopid
X-Sorting-Hat-Podid
X-Shardid
X-Cache-Version
X-RAMCache
X-Ramcache
X-FL-QIT-DEBUG
Srvid
X-Requestid
X-Udemy-Cache-App-Namespace
X-Service-Response-Time
CF-Cached-On
X-Dw-Trace-Id
Akamai-Cache-Status
X-Serial
X-Check-Cacheable
Warning
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Mg-Cache
Sm-Log-Id
X-Sucuri-Id