Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
X-XSS-Protection
CF-RAY
ETag
Accept-Ranges
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
X-Served-By
P3P
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Xss-Protection
X-Varnish
X-Adblock-Key
X-FRAME-OPTIONS
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Content-Security-Policy-Report-Only
P3p
X-Runtime
X-AspNet-Version
X-DNS-Prefetch-Control
Accept-CH
X-Cache-Status
X-Drupal-Cache
Accept-CH-Lifetime
X-Ua-Compatible
X-Check
X-Generator
X-Cacheable
Server-Timing
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Iinfo
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
X-Request-ID
Feature-Policy
Content-Encoding
X-Content-Security-Policy
X-CDN
Status
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
CF-Ray
X-Amz-Id-2
Host-Header
X-Backend
Allow
Cf-Edge-Cache
X-Cache-Group
X-Robots-Tag
Request-Context
X-Server
Keep-Alive
X-Hacker
X-UA-Device
X-AH-Environment
X-Turbo-Charged-By
X-Ws-Request-Id
X-Vhost
X-Proxy-Cache
X-Rq
X-Age
Xkey
EagleId
X-Dispatcher
X-Server-Powered-By
X-Amz-Version-Id
X-Varnish-Cache
Grace
Cf-Apo-Via
X-LiteSpeed-Cache
X-Page-Speed
X-Pingback
Cf-Railgun
EagleEye-TraceId
X-Device
X-Swift-SaveTime
X-Swift-CacheTime
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Dns-Prefetch-Control
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
X-CST
X-WebKit-CSP
X-Backend-Server
X-OneAgent-JS-Injection
Permissions-Policy
X-Server-Id
Accept-Ch-Lifetime
X-Readtime
X-Host
X-Response-Time
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Nginx-Upstream-Cache-Status
X-HW
X-Cloud-Trace-Context
X-Nginx-Cache-Status
X-Node
X-Application-Context
X-Oneagent-Js-Injection
X-Country-Code
X-Trace
Content-Location
X-Cache-Lookup
X-Ruxit-JS-Agent
X-Url
Service-Worker-Allowed
X-Content-Type
X-Country
X-Clacks-Overhead
X-ECACHE
X-Litespeed-Cache
X-Edge
X-Mod-Pagespeed
Accept-Ch
X-Amz-Server-Side-Encryption
X-Rack-Cache
X-Midtier
X-Origin-Cache-Key
Cache-Tag
Cross-Origin-Opener-Policy
X-FTR-Request-ID
X-MS-InvokeApp
X-Mcache
X-Upstream
X-ESI
X-Vname
X-TtlSet
X-PC
Nginx-Cache
X-Powered-By-Plesk
Rating
Edge-Control
X-Ruxit-Js-Agent
X-D2id
X-Browser-Type
X-Element-Page-Cache
Verso
X-Cdn-Fetch
X-Kinja-Server
X-Exp-Variant
X-Exp-Id
X-Kinja-Revision
X-Kinja-Build
X-Kinja
X-GoogleNews-Bot
X-Times
X-Ac
X-Cnection
X-Server-Name
SPRequestDuration
SPIisLatency
X-Vcap-Request-Id
AR-Request-ID
AR-ATIME
AR-PoweredBy
AR-SID
X-Navigation-Version
X-SharePointHealthScore
X-Dw-Request-Base-Id
SPRequestGuid
X-RateLimit-Remaining
X-Abt-Application-Version
X-VARITI-CCR
X-NF-Request-ID
X-Pinterest-Rid
X-Ser
Pinterest-Version
Pinterest-Generated-By
X-GitHub-Request-Id
X-B3-TraceId
Origin-Trial
AR-CACHE
S
X-Cache-Key
X-Cache-TTL
X-Mg-S
RTSS
Edge-Cache-Tag
X-Middleton-Display
Display
X-Sol
X-Amz-Rid
Pagespeed
X-Goog-Hash
X-Content-Security-Policy-Report-Only
X-Amzn-Trace-Id
Fastly-Restarts
X-Powered-CMS
X-Client-IP
X-Ttl
X-Varnish-TTL
X-NWS-LOG-UUID
X-Server-ID
X-Version
X-Instrumentation
X-Kraken-Loop-Name
Access-Control-Request-Method
X-Erf-Bev-Bev-Is-Generated
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev
X-Edge-Location-Klb
X-ARC
X-Kinsta-Cache
Cache-Status
X-Recruiting
X-Webkit-Csp
Arr-Disable-Session-Affinity
X-Content-Digest
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-T
X-MSEdge-Ref
X-Forwarded-For
X-Ua-Device
Content-MD5
X-Middleton-Response
Response
X-TraceId
MicrosoftSharePointTeamServices
X-Accel-Expires
X-Hits
X-Shield-Request-Id
TP-Cache
X-Cached
X-RateLimit-Limit
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
Public-Key-Pins
X-Fastcgi-Cache
X-Frontend
X-Id
X-Request-Processing-Time
Server-Node
X-Country-Code-Real
X-Request-Received
X-FTR-Cache-Status
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-Backend
Payment
X-FTR-Expires
X-HS-Combine-CSS
X-HS-Hub-Id
X-Ua-Browser
X-HS-Cache-Config
X-HS-Content-Id
MS-Author-Via
X-WebKit-CSP-Report-Only
X-DIS-Request-ID
X-Kinja-CCPA
Front-End-Https
X-ORACLE-DMS-RID
X-GUploader-UploadID
Cross-Origin-Resource-Policy
X-LLID
X-Forwarded-Proto
X-HP-Trace-Id
X-HP-Webp
X-Jurisdiction
Cache-Tags
X-LB-Cache
X-Amzn-RequestId
TP-L2-Cache
X-Amz-Apigw-Id
Realpath
X-Protected-By
X-FastCGI-Cache
X-PressLabs-Stats
X-Daa-Tunnel
Count-Hit
X-Origin-Server
X-Distributor
X-Microsite
X-TTL
X-Request-Handler-Origin-Region
X-ORACLE-DMS-ECID
X-Page-Id
X-Cluster-Name
X-F-Cache
X-Az
Accept-Charset
X-AppVersion
Mrf-Cache-Status
X-Activity-Id
X-B3-TraceId-Primal
MRF-Tech
X-NGENIX-Cache
X-Www-Served-By
X-Varnish-Backend
X-Rid
X-Geo-Country
X-App-Server
X-Correlation-Id
X-FB-Debug
Referer-Policy
X-Hostname
X-Kong-Proxy-Latency
X-Goog-Metageneration
X-Kong-Upstream-Latency
X-Varnish-Server
X-Debug-Info
Host
X-Envoy-Decorator-Operation
Fastcgi-Cache
Access-Control-Allow-Method
X-Git-Hash
X-RateLimit-Reset
Retry-After
X-XRDS-LOCATION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
Server-Name
X-Px
DC
X-Content-Options
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Load-Cache
X-B3-Sampled
X-Is-Crawler
X-Request-Guid
X-Flags
X-Contextid
X-Fastly-Request-ID
X-Providence-Cookie
X-Aspnet-Duration-Ms
X-Route-Name
X-Revision
X-Mobile
TCN
X-Trace-Id
X-Language
X-B-Cache
Cleartype
X-Type
X-Signature
X-App-Environment
Paypal-Debug-Id
X-Grace
X-Origin-Cache
X-TT
X-Fb-Rlafr
Charset
X-B
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-ASPNET-VERSION
X-Datadog-Trace-Id
X-CSRF-Token
X-Cache-Control
Frame-Options
X-Amz-Meta-S3cmd-Attrs
Section-Io-Cache
X-Ratelimit-Limit
X-Goog-Storage-Class
X-Amz-Replication-Status
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Logged-In
X-Upgrade-Enabled
Filterid
X-Newrelic-App-Data
X-Seen-By
X-Whom
X-Magnolia-Registration
X-Ezoic-Cdn
X-Oracle-Dms-Ecid
Healthy
X-EdgeConnect-Cache-Status
X-Wix-Request-Id
X-App-Version
X-Node-Name
X-B3-Traceid
X-Azure-Ref
Content-Disposition
X-Proxy
Backend
X-N
X-Oracle-Dms-Rid
Akamai-GRN
X-Fastly-Request-Id
X-Template
X-Varnish-Ttl
Upgrade-Insecure-Requests
X-Proxy-Cache-Info
NGB
Refresh
X-Air-Pt
X-Original-Request-Id
X-Response-Served-From
X-Servername
X-Rendered-As
X-Is-Bot
X-RemovedCookies
Liferay-Portal
MS-CV
X-RTag
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-1
Ms-Operation-Id
SD-X-WS
X-Page-View
X-Datadog-Sampled
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-ProcessESI
Url
X-Unique-Id
X-Tumblr-Pixel-0
X-Environment-Context
X-Debug-IsConnected
X-Adobe-Content
X-Instance
X-L-Path
X-Varnish-Grace
X-UUID
X-Cacheable-TTL
X-Amzn-Remapped-Content-Length
X-User-Agent
X-Cache-Grace
Viewport
X-Debug-IsPreview
X-Adobe-Loc
X-Region
X-Jobs
X-Ratelimit-Remaining
X-IPS-LoggedIn
X-Yottaa-Metrics
X-G
X-Yottaa-Optimizations
X-Debug
From-Origin
X-FW-Dynamic
Fastly-SWR
X-FW-Server
X-FW-Type
Country
X-FW-Static
Fastly-SIE
X-Cache-Hit
X-FW-Serve
X-FW-Hash
X-B3-SpanId
X-Use-Magma
X-FW-Version
X-Rule
X-Device-Type
X-Status
Surrogate-Key
X-NYM-Debug-Backend
X-Hosted-By
X-Hl-Ver
X-Air-Trace-Id
X-Air-Source
X-Air-Hostname
X-Backend-Name
X-WP-CF-Super-Cache-Cache-Control
X-Webkit-CSP
X-WP-CF-Super-Cache
ServerID
X-Cache-Age
Protected
X-Http-Reason
X-Content-Powered-By
X-Cache-Status-Check
X-Akamai-Request-ID2
X-XRDS-Location
X-Time
X-NODE
X-Origin-CC
Version
X-Origin-TTL
Amp-Access-Control-Allow-Source-Origin
X-VC-Cache
Alternate-Protocol
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-HTML-Minification-Powered-By
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
X-Akamai-Edgescape
WPO-Cache-Message
Countrycode
WPO-Cache-Status
X-INCAP-ABP
X-Rocket-Nginx-Serving-Static
X-Framework
X-Nginx-Cache
X-CDN-Forward
X-Edge-Location
CF-IPCountry
Front
Access-Control-Request-Headers
SRV
X-Source
GEO-INFO
X-Cache-Rule
X-Via-JSL
X-Storage
X-Httpd
X-Accel-Version
X-Mode
X-Endurance-Cache-Level
X-WP-CF-Super-Cache-Active
X-Use-Mantle
X-Cache-Operation
Filters
Webserver
OT-Force-Account-Verify
X-Rewrite-Enabled
X-Upstream-Ct
Accept-Language
X-VC
X-Xfnlog-Site
X-Upstream-Ht
X-UPSTREAM-Address
X-Rn-Rsrv
Meta-Geo
CDN-RequestId
X-Lambda-Id
X-Loop
X-Proxy-Build
X-Director
X-Detected-As
Selected-Fe
X-Cache-Debug
X-SaId
X-Served-From
X-Tumblr-Pixel-3
X-Varnish-Age
X-Real-IP
X-Tumblr-Pixel-2
X-Tncms
X-Soup
X-Timing-Wait
Xet-Cookie
X-JoinUs
X-Cache-Time
X-Sql-Count
X-Sql-Duration-Ms
AMP-Access-Control-Allow-Source-Origin
X-Skip-Cache
X-BYPASS-REASON
X-Redis-Cache
ServedBy
X-ProxyCache-Status
X-ProxyCache-Key
X-Cms-Context
X-Adobe-Source
X-Varnish-Cache-Hits
Apigw-Requestid
X-Varnish-Beresp-Grace
X-Handled-By
Azure-RegionName
Azure-SiteName
Azure-SlotName
Azure-Version
Azure-InstanceId
X-No-Session
X-Cache-Host
X-Format
X-Logging-Id
X-Origin-Hint
Property-Id
X-Restarts
TWC-Locale-Group
X-Uri
DB-Nickname
TWC-Privacy
Web-Mar-Node
Webcakes-Region
Webcakes-App-Version
Webcakes-App-Name
TWC-GeoIP-LatLong
X-COUNTRY
X-Say-TTL
X-Say-Cacheable
X-S
TWC-Connection-Speed
X-SayCDN-TTL
X-Server-W
TWC-Device-Class
TWC-GeoIP-Country
X-Browser-Name
X-AWS-Id
X-Forwarded-Host
X-Container-Uri
X-Cache-Server
X-Extlb
X-DynaTrace
X-Fetched-On
X-Is-Tablet
X-Tcp-Rtt
X-VCT
X-Tb
X-ServerID
X-Routing-Service
X-Vercel-Cache
X-Vercel-Id
X-Worker
Xserver
X-Zipkin-Id
X-VWS-Id
X-RM-Cache-TTL
X-RCS-CacheZone
X-IPLB-Request-ID
X-Is-Desktop
X-IPLB-Instance
X-Git-Commit
X-Geo-Region
X-Is-Mobile
X-Is-Supported-Browser
X-Proxied
X-PHP-Host
X-LJ-Flow-ID
X-Labrador-Cache-Channel
X-Generation-Time
X-Origin
X-AB
Mn-Server-Ip
X-Frame-Option
Cache-Tv-Group
X-Provided-By
X-Cluster
Node
X-Ms-Request-Id
X-Reqid
X-Ms-Version
X-GeoCountry
X-R9-Blue-Green-Version
X-GeoCode
X-FB-TRIP-ID
Section-Io-Id
Content-Secure-Policy
Priority
X-Locale
X-Site-Version
X-Vcache
X-Platform-Router
X-Platform-Processor
X-Platform-Cluster
X-MP-GENERATED-AT
Source
X-Webstats-RespID
Fastcgi-Useragent
WZWS-RAY
X-Drupal-Cache-Tags
X-Vcl-Version
X-Drupal-Cache-Contexts
Onion-Location
WP-Super-Cache
X-Web-Node
S-Rt
CDN-PullZone
CDN-RequestCountryCode
CDN-RequestPullCode
Cross-Origin-Embedder-Policy
CDN-Cache
X-Urbn-Context-Path
X-Origin-Date
X-Urbn-Site-Id
X-Shopify-Stage
X-Alternate-Cache-Key
X-Storefront-Renderer-Rendered
CDN-CachedAt
CDN-EdgeStorageId
Locale
CDN-RequestPullSuccess
X-Content-Age
X-Ua
CDN-Uid
X-Sorting-Hat-ShopId
X-ShardId
X-Sorting-Hat-PodId
X-ShopId
X-Cache-Action
X-Generated-By
X-Cluster-Node
X-Varnish-Beresp-Ttl
X-SRV
X-Cdn-Origin
X-Sucuri-Cache
X-Pass-Why
Sid
X-Proxy-Cache-Status
X-Buckets
X-Mg-Request-UUID
X-Sucuri-ID
X-Newrelic-Synthetics
Cross-Origin-Window-Policy
X-Cache-Expired-At
X-VCache
X-Xrds-Location
X-TT-LOGID
X-Datadome
Fastly-Drupal-HTML
X-Request-URI
X-Thinkindot-L3
Cache
TDXMobile
X-Shield-Cache-Expires
Thinkindot-CacheControl
X-Scope-Id
X-CMSURLCustom
Thinkindot-CacheControl-Type
Thinkindot-Control
X-DataDome
HostName
X-LSADC-Cache
Cross-Origin-Embedder-Policy-Report-Only
X-Aspnetmvc-Version
X-Developer
X-Bl-Debug
X-A-Wwc
X-Destination
X-A
X-Cache-NE
X-Bc-Bl
X-Cache-Bucket
X-A-Dcw
X-B-Cookie
X-Conf
X-Application
X-Aed
X-A-Dam
X-BCube-Filmed-By
X-A-Ccd
X-A-Dgt
X-D
X-Epic-Correlation-Id
X-Rojux
DCR-Processing-Time-Ms
Redirect-Candidate
Rendered-Blocks
DCR-Decision-By
Gannett-Cam-Experience-Id
Origin
X-ScT
X-Scheme
Origin-Agent-Cluster
X-PAYTM-SRV-ID
X-Correlation-ID
T-Server
Type
V-Age
X-Vdms-Path
X-Men
Surrogated-Key
Lang
X-Vdms-Version
Sslversion
X-Viewer-Country
X-S-Cookie
Candidate-Md5Url
Ngx-Var-Key
Meta-Geo-Continent
X-Ec-GeoHdr
X-SRCache-Key
X-Ec-Custom-Error
X-External-Request-Id
MD5-Digest
Environment
Ngx.Var.Host
CDCHOST
X-Up
X-TIM-N
X-Ec-Fail
X-Vtex-Remote-Cache
X-Service
X-Via-SSL
X-Optimistic-Header
Edge-Copy-Time
X-GEO
X-TimeS
X-Via-CDN
X-Via-Edge
Vix-Hermes-Req-Id
Host-ID
X-Access
Server-Hostname
L
Pramga
Fastly-GeoIP-CountryCode
Fastly-SSL
Req-Svc-Chain
Server-Ext
Ssr
Sever-Int
Server-Host
Magicmarker
X-Gdpr
X-SD-PageType
X-SB
X-Section
X-Sigma
X-Sigma-Backend
X-Rocket-Build-Number
X-Request-Time
X-Pool
X-Proxied-Request
X-Pubstack
X-Req
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-VG-WebCache
X-VServer
X-We-Are-Hiring
X-Server-IP
X-VG-TLSProxy
X-Varnish-Hostname
X-Thanos
X-V-Cache
X-Varnish-Beresp-Status
X-Varnish-Director
X-Platform
X-Origin-Time
X-Debug-Cache-Fetch
X-Core-Value
X-Debug-Cache-Store
X-Dispatcher-Server
X-Fastly-Backend
X-Core-Mission
X-Cache-Info
X-Aicache-OS
X-B3-Trace-ID
X-BBC-Edge-Cache-Status
X-Bip
X-Fastly-Cache
X-Generated-On
X-Loc
X-Mly-Id
X-Nyt-Route
X-Op-Id-All
X-Level-Front-Cache
X-Instance-Name
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-Hash
X-Human
X-Acquia-Purge-Cdn-Unconfigured
Release
Apple-News-Services-Handled
X-Tt-Logid
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Country-Code
Apple-News-Services-Request-Url
User-Cache-Control
X-Parent-Response-Time
X-GoCache-CacheStatus
X-Esi-Check
X-Gzip
X-HA-Backend
X-FC-Vary-Parameters
X-Gen-Mode
X-Geo-Header
X-GeoIP-City
X-From
X-Fmm-Version
X-GeoIP
X-Clientip
X-ApacheServer
X-Auto-Login
Wxu-Next-Region
Wxu-Next-Hostname
Web-Mar-Region
Wxu-Next-Commit
Atl-Traceid
X-Block-Status
X-CacheTTL
X-Hnp-Log
X-Cache-TTL-Remaining
X-Cache-Id
X-Cache-Date
X-Device-Os
X-Irp-Debug
X-Via-Poph
X-Via-Popn
X-Var-Ttl
X-UA-Device-Type
X-Slack-Shared-Secret-Outcome
X-Sn-Servicetimems
X-Via-Popv
X-WA-Info
X-TH-Server
X-Varnishpool
X-Request-Start
X-Node-Id
Req-ID
X-Forwarded-Site
X-Slack-Backend
X-Request-Host
X-NCache
X-Nginx-Cache-Key
X-Mvc-Supplant-OutputCached
X-Mvc-Supplant-Cachable
We-Hiring
X-Micro-Cache
X-NMSegId
X-Old-Content-Length
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
DSUID
X-PERF
X-Org
X-Origin-Response-Time
X-HS-Content-Campaign-Id
X-Policy
On-Server
NM-Fastcgi-Cache
Cache-Provider
Gh-Request-Id
Click-Count-Action-Start
Machine
Canary
Tube-Got-Results
Tube-Return
Tube-Get-Contents
Esi-Enabled
Click-Count-Error
Tube-Got-Eval
Mail-Subject
Proxy-Firewall
Uber-Trace-Id
C-Via
X-WP-CF-Super-Cache-Cookies-Bypass
X-DC
True-Client-Country-4JS
X-TA-CDN-Provider
Cdn-Host
N-Cache
Cdn-Request-Time
X-CF-Lambda-Fn
Producers
X-Date
X-Edge-Server
X-DPWN-IS-SECURE
Platform
Pics-Label
X-Cdn-Srv
X-Owner
X-CF-Lambda-Version
AKAMAI
Adler-Geo
X-Proto
X-Accel-Expires-Debug
Cf-Device-Type
Is-Eu
X-Ad-Load-Variation
Expect-Staple
LB
X-Zen-Fury
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-Test
IsBot
X-ZONE
X-SIPLIST1
X-App-Name
W
X-Dc
Cluster
X-Eu-Site
X-Forwarded-Path
Fastly-Backend-Name
X-Ah-Environment
HA-Ipaddr
X-Qloud-Router
X-Orig-Expires
NGX
X-Shop-Environment
Ha-Gx-Prefs
L5d-Success-Class
Xc-Version
X-Tenant
X-Csrf-Jwt
X-Cache-Type
X-CGP
X-Amz-Meta-Cb-Modifiedtime
Expiry
Datacenter
X-Connection-Hash
Content-Style-Type
A
Content-Script-Type
X-Branch-Name
X-Moov-Xdn-Version
X-Gamma-Serve
X-LB-NoCache
X-Moov-T
RNT-Time
Cmsid
X-NGINX-Cache
Cache-Key
Cdn-Requestid
X-LB-ID
RNT-Machine
X-Contensis-Viewer-Groups
X-Varnish-Authentication
Server-ID
Cmstype
X-Cache-Aspx
Locid
Cdn
X-Ratelimit-Reset
SID
X-Varnish-Hits
X-Cdn-Diag
CPC-Age
CPC-Cache
X-Vmg-Version
X-Refresh
X-Region-Sid
Yak-Timeinfo
X-ND-Cache
X-Tx-Id
X-Nf-Request-Id
X-DynaTrace-JS-Agent
X-VHOST
X-Api-Version
Cdnsip
RATING
PFcat
X-HN
X-Amz-Storage-Class
X-Tb-Optimization-Total-Bytes-Saved
X-Servedbyhost
X-LAGOON
X-Wa
GeoIp-Country-Code
NtCoent-Length
X-MCACHE
X-VarnishDD-TTL
Cdncip
X-AK-Request-ID
X-Nc
X-Client-Ip
X-CDN-Cache-Status
X-Srv
X-Fpc
X-Backend-Instance
X-TX-ID
CacheControlHeader
X-Nananana
X-B3-Parentspanid
XM
CloudFront-Viewer-Country
X-TIME
X-Akamai-Transformed
X-Hit
X-Azure-Ref-OriginShield
Resin-Trace
X-API-Version
X-Via-Fastly
X-Cache-Backend
X-Variation
X-Origin-Expires
X-CACHE-AGE
Uri
X-LiteSpeed-Tag
User-Agent
X-Lagoon
X-Proxy-CacheRZ
VNS-Age
X-LiteSpeed-Cache-Control
X-Fastly-Country-Code
VNS-Cache
X-CSRF-TOKEN
X-Zone
XkeyRZ
X-URL
Cache-Name
MIME-Version
X-Datacenter
True-Client-Ip
X-Info
Cross-Origin-Opener-Policy-Report-Only
X-Amz-Meta-Opti
X-Geo
Tcn
X-B3-Spanid
X-Vc
Lb
DataCenter
X-HostName
X-Dispatcher-Number
Mime-Version
X-Dynatrace-Js-Agent
X-DataCenter
Hostname
X-NewRelic-App-Data
True-Client-IP
X-AIR-PT
X-UA
X-Location
GeoIP-Latitude
X-Cached-By
X-Ig-Origin-Region
Cache-Hits
Fastly-Drupal-Html
Fusion-Content-Source
X-NWS-UUID-VERIFY
X-Mid
Fusion-Deployment-Id
Fusion-Template-Id
Fusion-Source
Fusion-Component-Id
Fusion-Content-Id
Cf-Ipcountry
X-Presslabs-Stats
Powered-By
X-Cdn-Forward
X-Webkit-Csp-Report-Only
X-CUA
BehaviorPad-Version
X-IAuth-Set-Uid
X-Cloudmap
X-Jungle-Id
Srv
X-Traceid
Origin-EX
X-User
Origin-CC
X-CS
X-ECache
CountryCode
X-Varnish-Beresp-TTL
X-Cache-Enabled
X-Esi
X-Dispatch
Ohc-File-Size
GeoIP-Country-Code
Debug
X-Segment-20210421
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
X-NC
X-WA
X-Oracle-DMS-ECID
Cl-Cache
X-Render-Time
Server-Info
X-Cdn-Cache-Status
X-FPC
Location
My-App
X-Cs
Wpo-Cache-Status
CDN
Ohc-Cache-HIT
Wpo-Cache-Message
X-Snapshot-Date
X-Litespeed-Tag
X-VTEX-Cache-Time
X-Internal-Host
X-VTEX-Cache-Server
X-Wormhole-Sdk
CF-Ctrl
X-Powered-By-VTEX-Cache
X-ServedByHost
X-Lb-Id
YJS-ID
Server-Id
Load-Balancing
X-Auth-Group-Type
Edge-Cache
Rtss
Section-Io-Origin-Status
Section-Origin-Responded
X-Nitro-Cache
X-Fastly-Backend-Reqs
Section-Io-Origin-Time-Seconds
X-Lb-Nocache
X-App
X-MSEdge-Features
X-MSEdge-Flight
X-Litespeed-Cache-Control
Ms-Author-Via
X-ID
X-VCL-Version
X-Cache-FS-Status
X-Proxy-Cache-La3
Xkeylog
X-MiniProfiler-Ids
CF-Cached-On
X-Nitro-Cache-From
X-Akamai-Pragma-Client-IP
X-Nitro-Rev
X-Cdn-Request-ID
Xkey-La3
X-Dw-Trace-Id
X-RID
X-FL-QIT-DEBUG
OriginIP
X-Th-Server
Time
X-NodeID
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Acquia-Site
Srvid
X-FL-EDGE
X-Acquia-Application-UUID
Ngx
FSS-Cache
Memory
X-Acquia-Purge-Tags
X-Acquia-Application-Trace
Geoip-Latitude
Memcached
X-Ig-Push-State
X-APP-VERSION
X-Sorting-Hat-Shopid
X-Cache-Version
X-Sorting-Hat-Podid
X-Shardid
X-Shopid
X-Http-Duration-Ms
X-Pad
Akamai-Cache-Status
X-Te-Count
X-Mg-Cache
X-DefHash
X-DefElseHash
X-RequestId
X-Via-PopN
X-Via-PopH
X-Lsadc-Cache
X-Http-Count
X-Via-PopV
X-Varnish-CookieHashed-On
X-Vary
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-Sucuri-Id
X-Wp-Cf-Super-Cache-Cookies-Bypass
Sm-Log-Id
X-Check-Cacheable
X-Serial
X-Service-Response-Time
X-Te-Duration-Ms
Yjs-Id
X-Fastly-Cache-Hits
X-Udemy-Cache-App-Namespace
X-Ha-Backend
X-Web-Server