Threat Level: green Handler on Duty: Richard Porter

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
CF-RAY
ETag
Accept-Ranges
Expect-CT
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-Xss-Protection
X-Served-By
P3P
X-UA-Compatible
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
X-AspNet-Version
Content-Security-Policy-Report-Only
X-Runtime
Accept-CH
P3p
X-DNS-Prefetch-Control
X-Ua-Compatible
X-Drupal-Cache
X-Cache-Status
Accept-CH-Lifetime
X-Generator
X-Check
Server-Timing
X-Cacheable
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Iinfo
X-Request-ID
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
X-Content-Security-Policy
Feature-Policy
Content-Encoding
X-CDN
Status
X-AspNetMvc-Version
Upgrade
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
X-Amz-Id-2
CF-Ray
Host-Header
Cf-Edge-Cache
X-Backend
Request-Context
Keep-Alive
X-UA-Device
Allow
X-Robots-Tag
X-Server
X-Cache-Group
X-Hacker
X-AH-Environment
X-Turbo-Charged-By
X-Ws-Request-Id
EagleId
X-Proxy-Cache
X-Age
Xkey
X-Rq
X-Vhost
X-Dispatcher
X-Amz-Version-Id
X-Server-Powered-By
X-Varnish-Cache
Grace
Cf-Apo-Via
X-Dns-Prefetch-Control
X-Swift-SaveTime
X-Swift-CacheTime
X-Page-Speed
X-Pingback
Ali-Swift-Global-Savetime
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Cf-Railgun
X-Device
X-LiteSpeed-Cache
EagleEye-TraceId
X-WebKit-CSP
Permissions-Policy
X-OneAgent-JS-Injection
X-CST
X-Backend-Server
X-Aws-Lambda-Call-Status
X-Host
X-Readtime
X-Server-Id
X-Response-Time
X-Akam-SW-Version
X-Cache-Lookup
Request-Id
Surrogate-Control
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Litespeed-Cache
X-HW
X-Nginx-Upstream-Cache-Status
X-Cloud-Trace-Context
X-Nginx-Cache-Status
X-Application-Context
X-Node
X-Country-Code
Content-Location
X-Country
X-Trace
Service-Worker-Allowed
X-Ruxit-JS-Agent
X-Url
X-Content-Type
X-Clacks-Overhead
X-Oneagent-Js-Injection
Accept-Ch-Lifetime
Rating
X-Origin-Cache-Key
X-Rack-Cache
Cache-Tag
X-Amz-Server-Side-Encryption
X-FTR-Request-ID
X-Edge
Cross-Origin-Opener-Policy
X-Midtier
X-Vname
X-PC
X-TtlSet
Nginx-Cache
X-MS-InvokeApp
X-Mcache
X-Mod-Pagespeed
X-Upstream
X-ECACHE
X-Powered-By-Plesk
X-ESI
X-Server-Name
Edge-Control
X-NWS-LOG-UUID
X-Browser-Type
X-Cnection
X-Times
Verso
X-Element-Page-Cache
X-D2id
X-Kinja-Build
X-Exp-Variant
X-Exp-Id
X-GoogleNews-Bot
X-Kinja
X-Kinja-Revision
X-Cdn-Fetch
X-Kinja-Server
X-Ruxit-Js-Agent
X-Ac
SPRequestDuration
SPIisLatency
AR-Request-ID
AR-PoweredBy
AR-SID
X-Ser
AR-ATIME
X-SharePointHealthScore
SPRequestGuid
X-B3-TraceId
X-Ttl
X-Navigation-Version
X-GitHub-Request-Id
X-NF-Request-ID
X-Abt-Application-Version
X-Dw-Request-Base-Id
X-RateLimit-Remaining
X-Vcap-Request-Id
AR-CACHE
X-Mg-S
X-Server-ID
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
S
Edge-Cache-Tag
Display
X-Client-IP
X-Sol
X-Middleton-Display
Pagespeed
X-VARITI-CCR
X-Cache-Key
Fastly-Restarts
RTSS
X-Amzn-Trace-Id
X-Amz-Rid
X-Cache-TTL
X-Kraken-Loop-Name
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Server-Lifecycle-Phase
X-Instrumentation
Cache-Status
X-Powered-CMS
X-Edge-Location-Klb
X-Kinsta-Cache
X-Version
Access-Control-Request-Method
X-Goog-Hash
X-Daa-Tunnel
X-Recruiting
X-Middleton-Response
Response
X-Content-Digest
X-ARC
X-Webkit-Csp
X-Forwarded-For
X-TraceId
X-Varnish-TTL
X-T
Arr-Disable-Session-Affinity
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-MSEdge-Ref
Content-MD5
Cross-Origin-Resource-Policy
MS-Author-Via
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Front-End-Https
MicrosoftSharePointTeamServices
TP-Cache
X-Shield-Request-Id
X-Accel-Expires
X-Hits
X-Cached
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-Backend-Server
Public-Key-Pins
X-FTR-Backend
X-Country-Code-Real
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Combine-CSS
X-Fastcgi-Cache
X-HS-Hub-Id
X-FTR-Expires
X-Forwarded-Proto
Server-Node
X-Id
X-Request-Processing-Time
Payment
X-Request-Received
X-Ua-Browser
X-Content-Security-Policy-Report-Only
X-Frontend
X-DIS-Request-ID
Realpath
X-Protected-By
X-HP-Trace-Id
X-HP-Webp
X-Jurisdiction
X-LLID
Origin-Trial
X-RateLimit-Limit
X-Distributor
X-ORACLE-DMS-RID
X-FastCGI-Cache
X-Hostname
TP-L2-Cache
X-GUploader-UploadID
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-LB-Cache
Cache-Tags
X-Request-Handler-Origin-Region
X-Microsite
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Debug-Info
Referer-Policy
X-Origin-Server
X-Page-Id
Fastcgi-Cache
Mrf-Cache-Status
MRF-Tech
X-NGENIX-Cache
X-AppVersion
X-Cluster-Name
X-Activity-Id
X-Envoy-Decorator-Operation
X-B3-TraceId-Primal
Host
X-Az
X-Www-Served-By
Count-Hit
X-Varnish-Backend
X-Varnish-Server
X-Geo-Country
Accept-Charset
X-Correlation-Id
X-App-Server
X-F-Cache
X-Ratelimit-Limit
X-Ua-Device
X-PressLabs-Stats
X-XRDS-LOCATION
X-Ezoic-Cdn
X-Fastly-Request-ID
X-Varnish-Ttl
Retry-After
X-Load-Cache
X-ORACLE-DMS-ECID
TCN
X-FB-Debug
X-Goog-Metageneration
X-Px
X-Upgrade-Enabled
X-CSRF-Token
X-TEC-API-ORIGIN
Access-Control-Allow-Method
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Seen-By
X-Git-Hash
Server-Name
X-RateLimit-Reset
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Amz-Meta-S3cmd-Attrs
Section-Io-Cache
Cleartype
X-Contextid
X-Request-Guid
X-Revision
X-Content-Options
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Trace-Id
X-Datadog-Parent-Id
Charset
X-Oracle-Dms-Ecid
X-B
X-Cache-Control
X-Type
X-Grace
X-Whom
X-B3-Sampled
X-TT
Healthy
Paypal-Debug-Id
X-Fb-Rlafr
DC
X-Air-Pt
X-Wix-Request-Id
X-Azure-Ref
X-Signature
X-B-Cache
X-Proxy
X-App-Environment
X-Node-Name
Accept-Ch
X-Mobile
X-Origin-Cache
X-Magnolia-Registration
X-Oracle-Dms-Rid
X-N
X-Newrelic-App-Data
Frame-Options
X-EdgeConnect-Cache-Status
X-Amz-Replication-Status
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Ratelimit-Remaining
Filterid
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Logged-In
X-NODE
X-Fastly-Request-Id
Backend
Content-Disposition
X-WebKit-CSP-Report-Only
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
NGB
X-Time
X-CCDN-CacheTTL
X-Response-Served-From
VIX-Pulpo-Node
Akamai-GRN
VIX-Pulpo-Upstream-Status
Viewport
X-Original-Request-Id
X-Is-Bot
X-Rendered-As
X-Servername
Liferay-Portal
X-Yottaa-Metrics
X-Yottaa-Optimizations
SD-X-WS
X-Datadog-Sampled
MS-CV
Ms-Operation-Id
X-Tumblr-User
X-Varnish-Grace
X-RTag
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Debug
X-FW-Static
X-FW-Server
X-FW-Type
X-FW-Version
X-Instance
X-Hl-Ver
X-FW-Serve
X-FW-Hash
X-Backend-Name
X-Adobe-Loc
X-Cache-Age
X-Debug-IsConnected
X-FW-Dynamic
X-Debug-IsPreview
X-Adobe-Content
X-UUID
X-Rid
X-Language
X-TTL
X-Amzn-Remapped-Content-Length
X-Cache-Grace
X-Via-JSL
ServerID
X-Unique-Id
X-Environment-Context
X-L-Path
X-NYM-Debug-Backend
X-ProcessESI
Upgrade-Insecure-Requests
X-IPS-LoggedIn
X-RemovedCookies
X-G
X-Device-Type
Fastly-SIE
Fastly-SWR
X-Cacheable-TTL
X-Region
X-Rule
X-Cache-Hit
X-Template
X-User-Agent
X-Proxy-Cache-Info
From-Origin
Refresh
X-Status
X-Aspnet-Duration-Ms
X-Flags
X-VC-Cache
Country
X-Route-Name
X-Is-Crawler
X-Providence-Cookie
X-B3-SpanId
X-INCAP-ABP
X-Webkit-CSP
Version
Url
X-Source
Countrycode
X-HTML-Minification-Powered-By
X-App-Version
X-Cache-Status-Check
GEO-INFO
SRV
Alternate-Protocol
CDN-RequestId
X-Storage
WPO-Cache-Status
WPO-Cache-Message
X-WP-CF-Super-Cache-Active
X-Jobs
X-Nginx-Cache
X-B3-Traceid
X-Air-Hostname
X-Air-Trace-Id
OT-Force-Account-Verify
X-Air-Source
Amp-Access-Control-Allow-Source-Origin
X-Tec-Api-Root
X-Tec-Api-Origin
X-Akamai-Request-ID2
X-Content-Powered-By
X-Tec-Api-Version
X-Real-IP
X-Origin-CC
X-Origin-TTL
X-CDN-Forward
Protected
X-Rocket-Nginx-Serving-Static
Surrogate-Key
X-ServerID
X-Hosted-By
X-Accel-Version
Access-Control-Request-Headers
X-VC
X-Cache-Time
CF-IPCountry
AMP-Access-Control-Allow-Source-Origin
X-Cache-Rule
X-Mode
X-Kinja-CCPA
X-Handled-By
X-Cache-Operation
X-Use-Mantle
X-Akamai-Edgescape
Xet-Cookie
X-Rewrite-Enabled
X-Rn-Rsrv
Meta-Geo
X-Upstream-Ht
X-Page-View
Webserver
X-Upstream-Ct
X-Xfnlog-Site
Filters
X-UPSTREAM-Address
X-Edge-Location
Section-Io-Id
X-Endurance-Cache-Level
X-Detected-As
X-SaId
X-Origin
X-Director
X-Varnish-Cache-Hits
X-JoinUs
X-Platform-Cluster
X-Cache-Debug
ServedBy
X-Framework
X-Platform-Router
X-Platform-Processor
X-TT-LOGID
X-Webstats-RespID
X-Worker
X-VWS-Id
X-Say-TTL
X-Proxied
X-Say-Cacheable
X-ProxyCache-Key
X-Sucuri-Cache
X-ProxyCache-Status
X-Restarts
X-Routing-Service
X-Proxy-Build
X-Logging-Id
X-Web-Node
X-SayCDN-TTL
X-Zipkin-Id
X-Timing-Wait
X-Cms-Context
X-Drupal-Cache-Tags
X-Extlb
X-Cluster
X-BYPASS-REASON
Web-Mar-Node
X-Adobe-Source
X-AWS-Id
X-Labrador-Cache-Channel
X-Lambda-Id
Selected-Fe
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
X-Soup
X-Served-From
X-LJ-Flow-ID
Node
X-PHP-Host
Front
Cross-Origin-Embedder-Policy
X-Vcache
Accept-Language
Webcakes-App-Version
Webcakes-Region
X-Varnish-Beresp-Grace
X-Browser-Name
X-Tncms
X-Varnish-Age
Webcakes-App-Name
TWC-Locale-Group
TWC-Connection-Speed
Property-Id
TWC-Device-Class
TWC-GeoIP-Country
X-Tcp-Rtt
TWC-GeoIP-LatLong
TWC-Privacy
X-Format
X-S
X-Is-Tablet
X-Is-Supported-Browser
X-Loop
X-No-Session
X-Origin-Hint
X-Redis-Cache
X-Is-Mobile
X-Is-Desktop
X-Geo-Region
Mn-Server-Ip
X-GeoCode
X-GeoCountry
X-IPLB-Request-ID
X-IPLB-Instance
X-Drupal-Cache-Contexts
X-AB
Azure-InstanceId
Azure-SiteName
Azure-RegionName
Apigw-Requestid
X-VCT
Azure-SlotName
Azure-Version
CDN-PullZone
X-Cache-Host
X-Tb
X-Shopify-Stage
X-Container-Uri
X-Storefront-Renderer-Rendered
X-Forwarded-Host
X-Reqid
X-Origin-Date
X-R9-Blue-Green-Version
X-Locale
X-RM-Cache-TTL
X-Generation-Time
X-Git-Commit
X-Sucuri-ID
X-Vercel-Id
X-Site-Version
CDN-RequestPullSuccess
CDN-Uid
Xserver
CDN-Cache
CDN-RequestCountryCode
CDN-EdgeStorageId
CDN-CachedAt
X-Skip-Cache
CDN-RequestPullCode
X-Vercel-Cache
X-Alternate-Cache-Key
X-Frame-Option
X-Cache-Server
X-Httpd
X-Provided-By
DB-Nickname
X-Ms-Request-Id
X-RCS-CacheZone
X-Ms-Version
X-ShopId
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-ShardId
Atl-Traceid
X-Fetched-On
X-XRDS-Location
WP-Super-Cache
X-MP-GENERATED-AT
X-Server-W
X-Uri
X-Cdn-Origin
X-Vcl-Version
X-Http-Reason
Cache-Tv-Group
Fastcgi-Useragent
Cross-Origin-Embedder-Policy-Report-Only
X-Generated-By
Source
Content-Secure-Policy
X-Pass-Why
X-FB-TRIP-ID
X-Xrds-Location
X-SRV
X-DynaTrace
X-Shield-Cache-Expires
X-Thinkindot-L3
Thinkindot-CacheControl-Type
Thinkindot-Control
TDXMobile
Thinkindot-CacheControl
X-Scope-Id
X-CMSURLCustom
Priority
X-Buckets
Cross-Origin-Window-Policy
Onion-Location
Sid
Cache
X-Urbn-Context-Path
Locale
X-Urbn-Site-Id
X-Content-Age
X-DataDome
X-RID
X-Azure-Ref-OriginShield
X-Sql-Count
X-Sql-Duration-Ms
HostName
X-LSADC-Cache
X-Optimistic-Header
X-WP-CF-Super-Cache-Cookies-Bypass
X-Varnish-Beresp-Ttl
X-TA-CDN-Provider
X-Cluster-Node
X-Proxy-Cache-Status
X-GEO
User-Cache-Control
X-Request-URI
X-Cache-Action
Expiry
WZWS-RAY
X-Connection-Hash
X-Dc
X-ScT
X-Ec-GeoHdr
DCR-Decision-By
X-Epic-Correlation-Id
X-Application
X-A-Ccd
X-Ec-Fail
X-Bc-Bl
X-BCube-Filmed-By
X-B-Cookie
X-External-Request-Id
X-Platform
X-Cache-NE
X-SRCache-Key
X-A-Dgt
X-TIM-N
X-A-Dcw
X-Cache-Bucket
DCR-Processing-Time-Ms
X-Lagoon
X-A-Dam
X-A-Wwc
X-Bl-Debug
Candidate-Md5Url
Gannett-Cam-Experience-Id
X-A
Vix-Hermes-Req-Id
Req-ID
Rendered-Blocks
X-Destination
Redirect-Candidate
Server-Ext
X-Request-Start
Sslversion
Surrogated-Key
Sever-Int
Server-Hostname
X-D
Server-Host
Origin-Agent-Cluster
Origin
X-Developer
Magicmarker
Lang
X-S-Cookie
X-SB
T-Server
X-Aed
MD5-Digest
Ngx-Var-Key
Ngx.Var.Host
X-Rojux
X-Conf
Meta-Geo-Continent
X-Varnish-Hostname
X-Ec-Custom-Error
A
X-Viewer-Country
X-Vdms-Path
X-ND-Cache
X-Vdms-Version
X-Correlation-ID
X-Vtex-Remote-Cache
X-Instance-Name
X-Newrelic-Synthetics
Fastly-Drupal-HTML
X-TimeS
X-Varnish-Director
Cdnsip
Cdncip
X-PAYTM-SRV-ID
Cluster
Release
X-SD-PageType
X-Section
X-Varnish-Beresp-Status
X-Cache-Id
Apple-News-Services-Request-Url
X-GeoIP-Country-Code
X-Node-Id
X-VServer
CDCHOST
Req-Svc-Chain
X-Esi-Check
X-Block-Status
X-Scheme
Host-ID
X-Dispatcher-Server
V-Age
X-We-Are-Hiring
L
X-Mly-Id
Locid
X-Proxied-Request
Fastly-SSL
Fastly-GeoIP-CountryCode
X-VG-TLSProxy
X-Req
Apple-News-Services-Host
Environment
X-Loc
X-Clientip
X-VG-WebCache
X-GeoIP-Region-Code
Apple-News-Services-Parsed-Url
X-Gen-Mode
X-TH-Server
X-BBC-Edge-Cache-Status
X-Gdpr
Yak-Timeinfo
X-Forwarded-Site
Apple-News-Services-Handled
X-Op-Id-All
X-Hnp-Log
X-B3-Trace-ID
X-Debug-Cache-Fetch
X-Gzip
X-Pubstack
DSUID
X-Auto-Login
X-UA-Device-Type
X-Human
X-Cache-TTL-Remaining
X-Nyt-Route
X-Access
X-Amz-Meta-Cb-Modifiedtime
X-Core-Value
X-Acquia-Purge-Cdn-Unconfigured
X-Cache-Info
X-Debug-Cache-Store
X-WA-Info
X-Zen-Fury
C-Via
X-AK-Request-ID
X-Origin-Time
X-API-Version
X-Via-CDN
X-Service
Edge-Copy-Time
X-UA
LB
X-Via-Edge
X-Origin-Response-Time
X-Via-SSL
Tube-Get-Contents
Ssr
Tube-Got-Eval
X-Request-Time
RNT-Machine
RNT-Time
X-NMSegId
X-Contensis-Viewer-Groups
X-Amz-Storage-Class
X-Aicache-OS
X-Old-Content-Length
X-Backend-Instance
Click-Count-Error
Click-Count-Action-Start
X-Ad-Load-Variation
On-Server
We-Hiring
X-Request-Host
X-Nginx-Cache-Key
Web-Mar-Region
Wxu-Next-Commit
Wxu-Next-Region
Wxu-Next-Hostname
True-Client-Country-4JS
Gh-Request-Id
X-Fastly-Cache
X-Sigma-Backend
X-SVT-ORM-VERSION
X-FC-Vary-Parameters
X-Fmm-Version
X-Sigma
X-Cdn-Srv
X-SVT-ORM-RULES
X-Server-IP
Cache-Provider
Adler-Geo
X-Pool
XM
X-RateLimit-Remaining-Second
X-Var-Ttl
X-Varnish-Authentication
X-Varnishpool
X-RateLimit-Limit-Second
X-Generated-On
X-Policy
X-Origin-Expires
X-HS-Content-Campaign-Id
X-Thanos
Tube-Got-Results
X-Moov-Xdn-Version
X-ECache
NM-Fastcgi-Cache
X-Rocket-Build-Number
X-Mvc-Supplant-Cachable
Mail-Subject
Tube-Return
Platform
X-NCache
X-Cache-Expired-At
Producers
Pramga
X-Micro-Cache
X-GoCache-CacheStatus
X-Level-Front-Cache
Country-Code
Content-Style-Type
Content-Script-Type
X-Moov-T
X-DPWN-IS-SECURE
X-Cache-Aspx
Is-Eu
X-Bip
X-Men
S-Rt
X-Datadome
X-CGP
X-Device-Os
X-HN
X-From
X-Geo-Header
X-GeoIP
X-GeoIP-City
X-Fastly-Backend
X-PERF
X-Mvc-Supplant-OutputCached
X-Csrf-Jwt
X-Proto
X-Edge-Server
X-Eu-Site
X-Org
Ha-Gx-Prefs
Cf-Device-Type
Cdn-Request-Time
Esi-Enabled
X-Cache-Date
X-Cache-Backend
X-Up
Cdn-Host
Canary
X-VarnishDD-TTL
X-V-Cache
X-Sn-Servicetimems
X-Slack-Shared-Secret-Outcome
X-DC
X-Slack-Backend
L5d-Success-Class
HA-Ipaddr
Uber-Trace-Id
X-Wikidot-Static-Cache
Machine
X-App-Name
X-Branch-Name
X-Region-Sid
PFcat
X-ApacheServer
Proxy-Firewall
X-Wikidot-Backend
X-Tx-Id
X-Mg-Request-UUID
X-Ua
X-VCache
X-LB-ID
X-Parent-Response-Time
X-Ah-Environment
X-Ratelimit-Reset
X-Hash
X-Test
Cache-Key
X-CacheTTL
Fastly-Backend-Name
AKAMAI
X-Accel-Expires-Debug
X-Date
Type
W
X-Servedbyhost
X-Tb-Optimization-Total-Bytes-Saved
NGX
X-Varnish-Hits
X-COUNTRY
Cache-Hits
X-Via-Popv
Pics-Label
X-Via-Popn
X-Via-Poph
X-CACHE-GROUP
X-HA-Backend
Cdn
X-Zone
X-DynaTrace-JS-Agent
X-LB-NoCache
NtCoent-Length
X-Irp-Debug
X-VHOST
X-Owner
X-Refresh
X-Via-Fastly
Cdn-Requestid
Datacenter
SID
X-Cloudmap
X-NGINX-Cache
X-Ig-Origin-Region
X-Nc
X-Wa
X-SIPLIST1
X-Core-Mission
IsBot
Server-ID
X-CDN-Cache-Status
X-Srv
GeoIp-Country-Code
X-ZONE
Fusion-Source
Fusion-Template-Id
Fusion-Content-Id
Fusion-Component-Id
X-Location
X-Akamai-Transformed
Fusion-Deployment-Id
X-PDP-UNCACHING-HASH
Fusion-Content-Source
X-NWS-UUID-VERIFY
GeoIP-Latitude
X-Fpc
Cross-Origin-Opener-Policy-Report-Only
X-Qloud-Router
Powered-By
Resin-Trace
X-CUA
Origin-CC
X-Hit
Origin-EX
X-Jungle-Id
N-Cache
X-B3-Parentspanid
DataCenter
X-CF-Lambda-Fn
Expect-Staple
X-Nananana
X-CF-Lambda-Version
X-TX-ID
X-NewRelic-App-Data
X-Orig-Expires
X-Nf-Request-Id
Xc-Version
X-Proxy-CacheRZ
XkeyRZ
X-DataCenter
X-Tenant
X-Cache-Type
X-Forwarded-Path
CloudFront-Viewer-Country
X-Shop-Environment
X-Client-Ip
Uri
X-Gamma-Serve
Cmstype
Cmsid
X-Presslabs-Stats
X-User
X-Segment-20210421
X-CS
X-URL
X-Amz-Meta-Opti
X-Cached-By
X-IAuth-Set-Uid
User-Agent
CPC-Age
X-Tt-Logid
X-Render-Time
CPC-Cache
X-TIME
X-Wormhole-Sdk
X-Cdn-Diag
X-Info
True-Client-Ip
X-VTEX-Cache-Time
X-VTEX-Cache-Server
X-Esi
X-Powered-By-VTEX-Cache
Mime-Version
X-Vmg-Version
MIME-Version
X-LiteSpeed-Tag
X-Dynatrace-Js-Agent
True-Client-IP
X-CACHE-AGE
Fastly-Drupal-Html
Debug
X-Fastly-Country-Code
X-Geo
Edge-Cache
Load-Balancing
X-Auth-Group-Type
Cf-Ipcountry
X-Oracle-DMS-ECID
CDN
X-B3-Spanid
X-LiteSpeed-Cache-Control
X-Vc
X-HOST
X-Variation
CacheControlHeader
X-Datacenter
X-Dispatch
X-Ig-Push-State
Srv
X-Varnish-Beresp-TTL
X-LAGOON
X-Cs
Odigeo-Trace-Id
Ohc-File-Size
X-Cdn-Forward
X-Webkit-Csp-Report-Only
X-Vgn-Hpd-Reason
Hostname
X-Custom-Header
Cl-Cache
X-NodeID
X-CSRF-TOKEN
Tcn
X-APP-VERSION
X-PHP-Backend
X-Depends
VNS-Cache
VNS-Age
X-FPC
X-MCACHE
X-Pad
Ohc-Cache-HIT
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-NC
Server-Id
GeoIP-Country-Code
X-DefElseHash
X-Varnish-CookieHashed-On
X-DefHash
X-WA
X-AIR-PT
X-HostName
X-Lb-Nocache
X-M-Reqid
X-VC-TTL
X-M-Log
X-Cdn-Cache-Status
X-Litespeed-Tag
X-MSEdge-Features
X-Dispatcher-Number
X-MSEdge-Flight
X-Cache-Ttl
X-Ha-Backend
CountryCode
X-ServedByHost
X-Cache-FS-Status
X-Fastly-Backend-Reqs
X-APP
X-Via-PopV
X-Via-PopN
Lb
X-Via-PopH
PICS-Label
Geoip-Latitude
X-VCL-Version
X-Litespeed-Cache-Control
X-Srcache-Store-Status
X-Srcache-Fetch-Status
X-Use-Magma
X-Proxy-Cache-La3
Epwk-X-Cache
X-Snapshot-Date
Ngx
Cloudfront-Viewer-Country
Xkeylog
X-MiniProfiler-Ids
X-Lb-Id
X-Cdn-Request-ID
Xkey-La3
Cache-Name
X-Api-Version
Memory
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
OriginIP
X-Mid
X-RequestId
X-Web-Server
Memcached
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Acquia-Application-Trace
Time
X-Acquia-Site
X-Cache-Version
X-Sorting-Hat-Shopid
X-Shopid
X-Sorting-Hat-Podid
X-Shardid
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Th-Server
X-Sucuri-Id
X-Udemy-Cache-App-Namespace
X-Ramcache
Sm-Log-Id
FSS-Cache
X-Requestid
Warning
CF-Cached-On
X-Dw-Trace-Id
X-Mg-Cache
X-Service-Response-Time
X-Serial
X-Check-Cacheable
Akamai-Cache-Status
X-Akamai-Pragma-Client-IP