Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
CF-RAY
ETag
X-XSS-Protection
Accept-Ranges
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
X-Served-By
P3P
X-Download-Options
X-Xss-Protection
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
X-FRAME-OPTIONS
Access-Control-Allow-Credentials
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
P3p
X-DNS-Prefetch-Control
Accept-CH
Accept-CH-Lifetime
X-Cache-Status
X-Drupal-Cache
X-Check
X-Generator
X-Ua-Compatible
Server-Timing
X-Cacheable
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Iinfo
X-Request-ID
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
X-Content-Security-Policy
Feature-Policy
Content-Encoding
X-CDN
Status
X-AspNetMvc-Version
Upgrade
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
X-Amz-Id-2
Host-Header
CF-Ray
Cf-Edge-Cache
X-Backend
Allow
Request-Context
X-UA-Device
Keep-Alive
X-Robots-Tag
X-Server
X-Cache-Group
X-Hacker
X-AH-Environment
X-Turbo-Charged-By
X-Ws-Request-Id
X-Proxy-Cache
X-Age
X-Rq
Xkey
X-Vhost
EagleId
X-Dispatcher
X-Server-Powered-By
X-Amz-Version-Id
X-Varnish-Cache
Grace
Cf-Apo-Via
X-Page-Speed
X-Pingback
X-Swift-CacheTime
X-Swift-SaveTime
Cf-Railgun
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
Ali-Swift-Global-Savetime
X-WebKit-CSP
EagleEye-TraceId
X-LiteSpeed-Cache
X-Aws-Lambda-Call-Status
X-CST
X-Dns-Prefetch-Control
X-OneAgent-JS-Injection
X-Backend-Server
Permissions-Policy
X-Server-Id
X-Readtime
X-Response-Time
X-Host
X-Akam-SW-Version
Request-Id
Surrogate-Control
X-Litespeed-Cache
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-HW
X-Nginx-Upstream-Cache-Status
X-Cloud-Trace-Context
X-Cache-Lookup
X-Node
X-Nginx-Cache-Status
X-Application-Context
X-Country-Code
Content-Location
X-Trace
X-Ruxit-JS-Agent
X-Country
Service-Worker-Allowed
X-Url
X-Content-Type
X-Clacks-Overhead
X-Oneagent-Js-Injection
X-Origin-Cache-Key
X-Edge
Accept-Ch-Lifetime
X-Rack-Cache
X-Amz-Server-Side-Encryption
Cross-Origin-Opener-Policy
Cache-Tag
X-FTR-Request-ID
X-Mcache
X-Midtier
X-Mod-Pagespeed
X-ECACHE
Nginx-Cache
X-MS-InvokeApp
X-TtlSet
X-Vname
X-PC
X-ESI
X-Upstream
X-Powered-By-Plesk
Rating
Edge-Control
X-Server-Name
X-Browser-Type
X-D2id
X-Element-Page-Cache
X-Times
Verso
X-GoogleNews-Bot
X-Exp-Id
X-Kinja
X-Cdn-Fetch
X-Kinja-Build
X-Kinja-Revision
X-Kinja-Server
X-Exp-Variant
X-Cnection
X-Ac
SPIisLatency
SPRequestDuration
X-B3-TraceId
AR-Request-ID
AR-PoweredBy
AR-ATIME
AR-SID
X-Ruxit-Js-Agent
SPRequestGuid
X-SharePointHealthScore
X-Abt-Application-Version
X-Navigation-Version
X-Vcap-Request-Id
X-Ser
X-NF-Request-ID
X-Dw-Request-Base-Id
X-GitHub-Request-Id
X-NWS-LOG-UUID
AR-CACHE
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
X-RateLimit-Remaining
X-Mg-S
X-VARITI-CCR
S
X-Sol
Display
X-Middleton-Display
Pagespeed
X-Client-IP
X-Ttl
Edge-Cache-Tag
X-Cache-Key
RTSS
Fastly-Restarts
X-Amz-Rid
X-Amzn-Trace-Id
X-Cache-TTL
X-Powered-CMS
X-Goog-Hash
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Erf-Bev-Bev
Cache-Status
X-Kinsta-Cache
X-Edge-Location-Klb
X-Version
Accept-Ch
Access-Control-Request-Method
X-Recruiting
X-Server-ID
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-Varnish-TTL
X-ARC
Origin-Trial
X-Middleton-Response
Response
X-Content-Digest
X-TraceId
X-Forwarded-For
Arr-Disable-Session-Affinity
X-T
X-Content-Security-Policy-Report-Only
X-MSEdge-Ref
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Content-MD5
MicrosoftSharePointTeamServices
X-Accel-Expires
X-Daa-Tunnel
TP-Cache
X-Shield-Request-Id
X-Hits
X-Cached
Cross-Origin-Resource-Policy
Front-End-Https
Public-Key-Pins
X-Id
X-FTR-Backend-Server
MS-Author-Via
X-Country-Code-Real
X-FTR-Backend
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-Expires
X-Request-Received
X-Request-Processing-Time
X-DIS-Request-ID
X-Ua-Browser
Server-Node
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Content-Id
Payment
X-HS-Hub-Id
X-Forwarded-Proto
X-Frontend
X-Fastcgi-Cache
X-LLID
X-HP-Webp
X-Jurisdiction
X-HP-Trace-Id
X-ORACLE-DMS-RID
X-Webkit-Csp
Realpath
X-Protected-By
X-FastCGI-Cache
X-GUploader-UploadID
TP-L2-Cache
X-LB-Cache
X-Ratelimit-Limit
Cache-Tags
X-Distributor
X-Origin-Server
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Request-Handler-Origin-Region
X-Microsite
Count-Hit
Referer-Policy
X-Hostname
X-Page-Id
X-B3-TraceId-Primal
X-Kong-Proxy-Latency
Mrf-Cache-Status
X-Kong-Upstream-Latency
MRF-Tech
X-Geo-Country
X-Debug-Info
X-Cluster-Name
X-AppVersion
X-Az
X-Activity-Id
X-ORACLE-DMS-ECID
X-Www-Served-By
X-Varnish-Backend
X-RateLimit-Limit
X-Correlation-Id
X-F-Cache
Fastcgi-Cache
Accept-Charset
Host
X-App-Server
X-NGENIX-Cache
X-Envoy-Decorator-Operation
X-XRDS-LOCATION
X-Varnish-Server
X-FB-Debug
X-Goog-Metageneration
X-Ua-Device
X-PressLabs-Stats
X-TTL
Access-Control-Allow-Method
X-Git-Hash
Retry-After
X-CSRF-Token
X-Fastly-Request-Id
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Upgrade-Enabled
X-Ezoic-Cdn
X-Load-Cache
X-RateLimit-Reset
X-Content-Options
Server-Name
X-WebKit-CSP-Report-Only
X-Seen-By
X-Px
X-Datadog-Parent-Id
X-Contextid
X-Datadog-Sampling-Priority
X-Revision
X-Datadog-Trace-Id
Charset
X-Tt-Trace-Tag
TCN
X-Tt-Trace-Host
X-Request-Guid
X-Cache-Control
X-Amz-Meta-S3cmd-Attrs
X-Trace-Id
X-Grace
Section-Io-Cache
DC
X-Kinja-CCPA
X-Type
X-Varnish-Ttl
X-TT
Cleartype
Paypal-Debug-Id
X-B
X-B3-Sampled
X-App-Environment
X-Fb-Rlafr
X-Newrelic-App-Data
X-Rid
X-Signature
X-B-Cache
Healthy
X-Whom
X-Ratelimit-Remaining
X-Wix-Request-Id
X-Oracle-Dms-Ecid
X-Node-Name
X-Origin-Cache
X-Mobile
Frame-Options
X-Magnolia-Registration
X-Amz-Replication-Status
X-EdgeConnect-Cache-Status
X-Azure-Ref
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Proxy
X-Is-Crawler
X-Flags
X-Providence-Cookie
X-Aspnet-Duration-Ms
X-Route-Name
X-Language
X-Logged-In
Filterid
X-N
X-Oracle-Dms-Rid
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Air-Pt
X-Fastly-Request-ID
Backend
Content-Disposition
Akamai-GRN
NGB
X-Original-Request-Id
X-Template
Upgrade-Insecure-Requests
X-Time
X-Response-Served-From
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Cache-Age
X-Proxy-Cache-Info
X-Yottaa-Optimizations
X-Is-Bot
X-Datadog-Sampled
X-Debug-IsConnected
SD-X-WS
X-Yottaa-Metrics
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Tumblr-User
X-Debug-IsPreview
X-Tumblr-Pixel
X-ProcessESI
X-RemovedCookies
X-Varnish-Grace
X-Unique-Id
X-Rendered-As
Refresh
X-UUID
X-Adobe-Loc
Liferay-Portal
Ms-Operation-Id
MS-CV
Viewport
X-App-Version
X-Adobe-Content
X-IPS-LoggedIn
X-Servername
X-RTag
X-Instance
X-FW-Server
X-FW-Serve
X-FW-Static
X-G
X-FW-Version
X-Cache-Grace
X-FW-Type
X-Debug
X-Cacheable-TTL
X-FW-Dynamic
X-FW-Hash
X-Amzn-Remapped-Content-Length
X-L-Path
X-Region
From-Origin
X-User-Agent
X-Environment-Context
Fastly-SIE
Fastly-SWR
Country
X-NYM-Debug-Backend
X-Backend-Name
X-Device-Type
X-Hl-Ver
X-Cache-Hit
X-Status
ServerID
X-Rule
X-Jobs
Url
X-B3-SpanId
X-CCDN-CacheTTL
X-Via-JSL
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-VC-Cache
X-Origin-CC
X-Origin-TTL
WPO-Cache-Status
Countrycode
WPO-Cache-Message
X-INCAP-ABP
X-Page-View
X-Webkit-CSP
Alternate-Protocol
Version
X-Air-Source
X-Hosted-By
X-Cache-Status-Check
X-Air-Hostname
Surrogate-Key
X-Air-Trace-Id
X-HTML-Minification-Powered-By
X-Akamai-Request-ID2
X-Source
X-Content-Powered-By
GEO-INFO
Protected
X-NODE
CDN-RequestId
X-WP-CF-Super-Cache-Active
Amp-Access-Control-Allow-Source-Origin
X-Rocket-Nginx-Serving-Static
X-Nginx-Cache
X-Storage
X-Akamai-Edgescape
X-B3-Traceid
X-Accel-Version
OT-Force-Account-Verify
SRV
X-Tec-Api-Origin
X-Tec-Api-Version
X-Framework
Access-Control-Request-Headers
X-Tec-Api-Root
X-VC
X-Real-IP
X-Edge-Location
X-Http-Reason
X-Cache-Rule
Front
X-Mode
X-ServerID
X-CDN-Forward
Webserver
X-Cache-Operation
CF-IPCountry
X-Cache-Time
X-Upstream-Ct
X-UPSTREAM-Address
X-Rn-Rsrv
X-Upstream-Ht
X-Rewrite-Enabled
AMP-Access-Control-Allow-Source-Origin
Filters
X-Httpd
Xet-Cookie
X-Xfnlog-Site
Meta-Geo
X-Director
X-SaId
Selected-Fe
X-Served-From
X-Tumblr-Pixel-3
X-Proxy-Build
X-JoinUs
Accept-Language
X-Tumblr-Pixel-2
X-Soup
X-Origin
X-Varnish-Cache-Hits
X-Timing-Wait
X-PHP-Host
X-Detected-As
X-Logging-Id
X-Endurance-Cache-Level
Node
X-Redis-Cache
X-SayCDN-TTL
X-Say-TTL
X-Cache-Debug
X-Adobe-Source
ServedBy
X-Handled-By
X-Web-Node
X-Labrador-Cache-Channel
X-Say-Cacheable
X-Use-Mantle
X-Worker
DB-Nickname
X-Is-Mobile
Apigw-Requestid
X-Is-Desktop
X-Is-Supported-Browser
X-Varnish-Age
Property-Id
X-Geo-Region
Azure-SiteName
X-Varnish-Beresp-Grace
X-Loop
X-GeoCode
Azure-RegionName
Azure-SlotName
X-Browser-Name
X-GeoCountry
X-AB
X-VCT
Azure-Version
X-Is-Tablet
Azure-InstanceId
X-ProxyCache-Key
Section-Io-Id
Xserver
X-Tncms
X-Format
X-Cms-Context
X-Lambda-Id
X-No-Session
X-ProxyCache-Status
X-Restarts
TWC-Connection-Speed
X-Server-W
X-Origin-Hint
X-S
X-RM-Cache-TTL
X-BYPASS-REASON
TWC-Privacy
TWC-Device-Class
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-GeoIP-Country
Web-Mar-Node
X-Skip-Cache
X-Tcp-Rtt
Webcakes-Region
Webcakes-App-Name
Webcakes-App-Version
X-DynaTrace
X-Tb
X-Generation-Time
X-RCS-CacheZone
X-VWS-Id
X-Site-Version
X-Fetched-On
X-Cache-Host
X-Vercel-Id
X-Vercel-Cache
X-LJ-Flow-ID
X-IPLB-Instance
X-AWS-Id
Mn-Server-Ip
Cross-Origin-Embedder-Policy
X-Locale
X-IPLB-Request-ID
X-Cache-Server
X-Platform-Processor
X-Platform-Router
X-Cluster
X-Platform-Cluster
X-TT-LOGID
X-Ms-Request-Id
X-Provided-By
X-Extlb
X-Routing-Service
X-Ms-Version
X-Zipkin-Id
X-Proxied
X-Container-Uri
X-Git-Commit
X-R9-Blue-Green-Version
X-Forwarded-Host
X-Frame-Option
X-Vcache
X-Webstats-RespID
X-Uri
X-Reqid
X-MP-GENERATED-AT
X-Drupal-Cache-Tags
X-Drupal-Cache-Contexts
X-Origin-Date
WP-Super-Cache
CDN-RequestPullSuccess
Cache-Tv-Group
X-Alternate-Cache-Key
X-Shopify-Stage
CDN-Uid
CDN-Cache
CDN-PullZone
CDN-RequestCountryCode
CDN-EdgeStorageId
CDN-CachedAt
CDN-RequestPullCode
X-Storefront-Renderer-Rendered
Source
Priority
Fastcgi-Useragent
X-Sucuri-Cache
X-XRDS-Location
Content-Secure-Policy
X-Sql-Duration-Ms
X-Vcl-Version
X-FB-TRIP-ID
X-Sql-Count
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-ShopId
X-Sucuri-ID
X-ShardId
X-Generated-By
X-Cdn-Origin
X-SRV
Cross-Origin-Embedder-Policy-Report-Only
X-Newrelic-Synthetics
Onion-Location
X-Xrds-Location
X-Urbn-Context-Path
X-Content-Age
Locale
X-Urbn-Site-Id
Sid
X-Pass-Why
X-Buckets
X-Cluster-Node
WZWS-RAY
S-Rt
Atl-Traceid
X-Thinkindot-L3
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
Thinkindot-Control
X-CMSURLCustom
X-Shield-Cache-Expires
X-Scope-Id
TDXMobile
Cache
X-DataDome
X-Cache-Action
Cross-Origin-Window-Policy
HostName
X-LSADC-Cache
X-Proxy-Cache-Status
X-Use-Magma
X-WP-CF-Super-Cache-Cookies-Bypass
X-GEO
X-Varnish-Beresp-Ttl
X-Cache-Expired-At
X-Ua
X-Optimistic-Header
X-Via-SSL
X-Via-CDN
X-Via-Edge
Edge-Copy-Time
X-Scheme
Candidate-Md5Url
X-S-Cookie
CDCHOST
DCR-Decision-By
X-Rojux
X-ScT
X-PAYTM-SRV-ID
X-SRCache-Key
DCR-Processing-Time-Ms
X-Platform
X-Cache-Bucket
Origin-Agent-Cluster
X-A-Ccd
X-A-Dam
X-A-Dcw
X-A
X-D
Type
X-Destination
Vix-Hermes-Req-Id
X-A-Dgt
X-A-Wwc
X-Bc-Bl
X-BCube-Filmed-By
X-Bl-Debug
X-B-Cookie
X-Application
X-Conf
X-Aed
X-Cache-NE
X-Developer
T-Server
Ngx.Var.Host
X-Epic-Correlation-Id
Origin
Ngx-Var-Key
X-External-Request-Id
Lang
MD5-Digest
Meta-Geo-Continent
X-Ec-GeoHdr
X-Ec-Fail
X-Dispatcher-Server
Sslversion
Surrogated-Key
Server-Host
Req-ID
X-Ec-Custom-Error
Redirect-Candidate
Rendered-Blocks
Gannett-Cam-Experience-Id
X-Request-Start
X-Viewer-Country
X-Vdms-Version
X-Varnish-Hostname
X-TIM-N
X-Vdms-Path
X-Vtex-Remote-Cache
X-Request-URI
User-Cache-Control
Expiry
X-Connection-Hash
Environment
X-Core-Value
Fastly-GeoIP-CountryCode
DSUID
X-Dc
X-GeoIP-Country-Code
X-Human
X-Instance-Name
X-Level-Front-Cache
X-Loc
Cluster
X-Gzip
X-We-Are-Hiring
X-GeoIP-Region-Code
Content-Style-Type
Content-Script-Type
A
Apple-News-Services-Handled
L
Server-Ext
X-Esi-Check
NM-Fastcgi-Cache
X-TA-CDN-Provider
X-VCache
Pramga
X-Access
Release
Sever-Int
Server-Hostname
V-Age
X-Fastly-Cache
Host-ID
X-Debug-Cache-Fetch
X-Generated-On
Ssr
X-Debug-Cache-Store
Apple-News-Services-Host
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
X-Forwarded-Site
Magicmarker
Fastly-SSL
X-WA-Info
X-Section
X-Cache-Id
X-Request-Time
X-Pubstack
X-Varnish-Beresp-Status
X-Varnish-Director
X-SB
X-Pool
X-Rocket-Build-Number
X-Bip
X-Sigma
X-Sigma-Backend
Fastly-Drupal-HTML
X-TH-Server
X-Branch-Name
X-Mg-Request-UUID
X-Thanos
X-SD-PageType
X-Cache-Info
X-Proxied-Request
X-Node-Id
X-Varnishpool
X-Correlation-ID
X-NMSegId
X-VG-WebCache
X-Mly-Id
X-Op-Id-All
X-VG-TLSProxy
X-VServer
X-Datadome
X-Origin-Response-Time
X-Service
X-TimeS
X-Contensis-Viewer-Groups
X-NCache
X-B3-Trace-ID
X-Cache-Date
X-Amz-Meta-Cb-Modifiedtime
X-Auto-Login
X-Device-Os
X-Moov-Xdn-Version
X-Block-Status
X-Clientip
X-Req
X-Moov-T
X-Gen-Mode
X-UA-Device-Type
X-Cache-TTL-Remaining
X-BBC-Edge-Cache-Status
X-Nginx-Cache-Key
X-Zen-Fury
X-Hnp-Log
X-GeoIP
X-Org
X-Origin-Time
X-PERF
X-Old-Content-Length
X-Nyt-Route
X-Mvc-Supplant-Cachable
X-Mvc-Supplant-OutputCached
X-Policy
X-RateLimit-Limit-Second
X-V-Cache
X-Server-IP
X-SVT-ORM-VERSION
X-Var-Ttl
X-Varnish-Authentication
X-RateLimit-Remaining-Second
X-Request-Host
X-Micro-Cache
X-Men
Req-Svc-Chain
Cache-Provider
C-Via
Wxu-Next-Commit
Wxu-Next-Hostname
X-DPWN-IS-SECURE
Wxu-Next-Region
X-FC-Vary-Parameters
X-From
X-GoCache-CacheStatus
X-Irp-Debug
X-GeoIP-City
X-SVT-ORM-RULES
X-Gdpr
X-Geo-Header
X-Acquia-Purge-Cdn-Unconfigured
X-Aicache-OS
X-Ad-Load-Variation
Platform
On-Server
Producers
True-Client-Country-4JS
We-Hiring
Web-Mar-Region
Mail-Subject
Machine
Canary
Adler-Geo
X-Cache-Aspx
X-ApacheServer
Esi-Enabled
Is-Eu
Gh-Request-Id
Uber-Trace-Id
X-ECache
X-Proto
X-ND-Cache
Cdncip
Yak-Timeinfo
X-Slack-Backend
X-Sn-Servicetimems
X-Slack-Shared-Secret-Outcome
Cdnsip
AKAMAI
Cf-Device-Type
X-HS-Content-Campaign-Id
Cdn-Request-Time
Cdn-Host
Cache-Key
X-App-Name
X-Test
X-Up
Tube-Got-Eval
Country-Code
Click-Count-Error
Locid
Tube-Get-Contents
RNT-Time
RNT-Machine
Click-Count-Action-Start
Tube-Got-Results
X-Cdn-Srv
X-Fmm-Version
X-Wikidot-Backend
X-Wikidot-Static-Cache
Tube-Return
W
X-Hash
X-Region-Sid
Proxy-Firewall
X-AK-Request-ID
X-Edge-Server
X-Fastly-Backend
X-Parent-Response-Time
X-Azure-Ref-OriginShield
X-HN
NGX
X-CGP
X-Accel-Expires-Debug
X-Ratelimit-Reset
PFcat
X-CacheTTL
X-DC
X-Csrf-Jwt
X-Date
X-Eu-Site
HA-Ipaddr
L5d-Success-Class
Fastly-Backend-Name
X-Amz-Storage-Class
X-VarnishDD-TTL
Ha-Gx-Prefs
X-Ah-Environment
X-Backend-Instance
X-Tx-Id
X-LB-ID
X-Core-Mission
Pics-Label
X-Owner
X-ZONE
X-HA-Backend
X-DynaTrace-JS-Agent
X-Via-Popv
X-COUNTRY
IsBot
X-Via-Poph
X-Via-Popn
X-SIPLIST1
XM
Datacenter
LB
X-NGINX-Cache
X-Tb-Optimization-Total-Bytes-Saved
NtCoent-Length
X-Origin-Expires
X-Servedbyhost
X-CACHE-GROUP
X-Refresh
X-Varnish-Hits
X-Qloud-Router
X-Cache-Backend
Cdn
X-Lagoon
X-LB-NoCache
X-API-Version
Expect-Staple
X-CF-Lambda-Fn
X-CF-Lambda-Version
N-Cache
X-VHOST
X-UA
Xc-Version
X-Forwarded-Path
X-Orig-Expires
X-Cache-Type
GeoIp-Country-Code
X-Shop-Environment
X-CDN-Cache-Status
SID
RATING
X-Tenant
Cdn-Requestid
Server-ID
X-Gamma-Serve
X-Nananana
X-Srv
X-Wa
Cmsid
X-Nc
CloudFront-Viewer-Country
Cmstype
X-Zone
X-RID
CPC-Age
CPC-Cache
Cross-Origin-Opener-Policy-Report-Only
X-B3-Parentspanid
X-Via-Fastly
X-TX-ID
X-Fpc
X-Vmg-Version
X-Cdn-Diag
X-Presslabs-Stats
X-Akamai-Transformed
Cache-Hits
X-Hit
Resin-Trace
GeoIP-Latitude
Uri
X-Tt-Logid
User-Agent
X-Nf-Request-Id
X-Ig-Origin-Region
X-Location
XkeyRZ
X-Proxy-CacheRZ
DataCenter
X-Client-Ip
Fusion-Source
Fusion-Deployment-Id
X-Variation
X-URL
X-LAGOON
Fusion-Template-Id
Fusion-Content-Source
Fusion-Component-Id
CacheControlHeader
Fusion-Content-Id
X-Cloudmap
Powered-By
X-Api-Version
X-TIME
X-DataCenter
X-Amz-Meta-Opti
X-Info
True-Client-Ip
X-Fastly-Country-Code
Tcn
X-CS
Fastly-Drupal-Html
Origin-EX
Origin-CC
X-NWS-UUID-VERIFY
MIME-Version
True-Client-IP
X-Jungle-Id
X-Datacenter
X-CUA
Cf-Ipcountry
Lb
Mime-Version
X-Cdn-Forward
Srv
X-HostName
X-B3-Spanid
X-NewRelic-App-Data
VNS-Cache
X-CACHE-AGE
VNS-Age
X-Cached-By
X-User
X-IAuth-Set-Uid
X-Geo
X-Dynatrace-Js-Agent
X-LiteSpeed-Tag
X-Segment-20210421
Debug
X-Varnish-Beresp-TTL
Load-Balancing
X-LiteSpeed-Cache-Control
X-Webkit-Csp-Report-Only
X-Vc
X-HOST
X-Render-Time
X-Powered-By-VTEX-Cache
X-VTEX-Cache-Server
Hostname
X-Dispatcher-Number
CDN
X-VTEX-Cache-Time
X-AIR-PT
Cache-Name
X-Auth-Group-Type
Cl-Cache
Edge-Cache
X-FPC
X-Wormhole-Sdk
Ohc-File-Size
X-CSRF-TOKEN
X-MCACHE
GeoIP-Country-Code
X-Dispatch
Server-Id
Ohc-Cache-HIT
X-Litespeed-Tag
X-Esi
X-Mid
X-Cdn-Cache-Status
X-WA
X-NC
X-Ig-Push-State
X-APP-VERSION
X-Cs
X-NodeID
Odigeo-Trace-Id
X-Oracle-DMS-ECID
X-Lb-Nocache
X-Custom-Header
X-ServedByHost
BehaviorPad-Version
X-Vgn-Hpd-Reason
X-Cache-Ttl
X-PHP-Backend
X-Depends
X-Cache-Enabled
CountryCode
X-Fastly-Backend-Reqs
Ms-Author-Via
X-Litespeed-Cache-Control
X-Pad
X-VCL-Version
X-MiniProfiler-Ids
X-Akamai-Pragma-Client-IP
X-Ha-Backend
X-MSEdge-Features
X-Lb-Id
YJS-ID
X-MSEdge-Flight
X-Via-PopH
X-Via-PopN
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Varnish-CookieHashed-On
X-DefHash
X-Via-PopV
X-DefElseHash
Server-Info
X-Cdn-Request-ID
Xkey-La3
X-Proxy-Cache-La3
Xkeylog
X-IN-APIGATEWAYSSL
X-Snapshot-Date
Srvid
X-FL-QIT-DEBUG
FSS-Cache
X-IN-APIGATEWAY
PICS-Label
X-M-Reqid
X-VC-TTL
X-M-Log
My-App
Location
OriginIP
X-FL-EDGE
Time
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Acquia-Site
Ngx
Memcached
Memory
X-Acquia-Purge-Tags
X-Sorting-Hat-Shopid
X-Cache-Version
X-Sorting-Hat-Podid
X-Shopid
X-Shardid
CF-Ctrl
X-Udemy-Cache-App-Namespace
X-RequestId
X-Serial
CF-Cached-On
X-Web-Server
X-Th-Server
X-Sucuri-Id
Warning
Geoip-Latitude
X-Dw-Trace-Id
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Internal-Host
Sm-Log-Id
X-Mg-Cache
Akamai-Cache-Status
X-Check-Cacheable
X-Fastly-Cache-Hits
X-Lsadc-Cache
X-Service-Response-Time