Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
CF-RAY
ETag
Accept-Ranges
Expect-CT
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
X-Xss-Protection
P3P
X-Served-By
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
X-AspNet-Version
Content-Security-Policy-Report-Only
X-Runtime
Accept-CH
P3p
Accept-CH-Lifetime
X-Drupal-Cache
X-Cache-Status
X-DNS-Prefetch-Control
X-Generator
X-Check
X-Ua-Compatible
Server-Timing
X-Cacheable
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Iinfo
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
X-Content-Security-Policy
Feature-Policy
Content-Encoding
X-CDN
X-Request-ID
Status
X-AspNetMvc-Version
Upgrade
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
X-Amz-Id-2
Host-Header
CF-Ray
Cf-Edge-Cache
X-Backend
X-UA-Device
Keep-Alive
Request-Context
X-Robots-Tag
Allow
X-Server
X-Cache-Group
X-Hacker
X-AH-Environment
EagleId
X-Turbo-Charged-By
X-Ws-Request-Id
X-Proxy-Cache
Xkey
X-Age
X-Rq
X-Dns-Prefetch-Control
X-Vhost
X-Dispatcher
X-Amz-Version-Id
X-Server-Powered-By
X-Varnish-Cache
Grace
Cf-Apo-Via
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Page-Speed
X-Pingback
X-LiteSpeed-Cache
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Permissions-Policy
X-Device
Cf-Railgun
EagleEye-TraceId
X-OneAgent-JS-Injection
X-WebKit-CSP
X-Backend-Server
X-CST
X-Cache-Lookup
X-Server-Id
X-Aws-Lambda-Call-Status
X-Host
X-Readtime
X-Response-Time
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-HW
X-Litespeed-Cache
X-Nginx-Upstream-Cache-Status
X-Cloud-Trace-Context
X-Node
X-Nginx-Cache-Status
X-Application-Context
X-Country-Code
Content-Location
X-Country
X-Ruxit-JS-Agent
Service-Worker-Allowed
X-Trace
X-Url
X-Content-Type
X-Clacks-Overhead
X-Oneagent-Js-Injection
Rating
X-Rack-Cache
Cache-Tag
Accept-Ch-Lifetime
X-Amz-Server-Side-Encryption
X-FTR-Request-ID
Cross-Origin-Opener-Policy
X-Vname
X-PC
X-TtlSet
X-Edge
X-Mcache
Nginx-Cache
X-Origin-Cache-Key
X-Midtier
X-MS-InvokeApp
X-NWS-LOG-UUID
X-Mod-Pagespeed
X-Upstream
X-Times
X-Powered-By-Plesk
X-Server-Name
Edge-Control
X-Browser-Type
X-ECACHE
X-ESI
X-Cnection
X-Cdn-Fetch
X-D2id
X-Exp-Id
X-Kinja-Revision
X-Kinja-Build
X-Kinja-Server
X-GoogleNews-Bot
X-Element-Page-Cache
X-Exp-Variant
X-Kinja
Verso
X-Ser
AR-PoweredBy
AR-Request-ID
AR-SID
AR-ATIME
X-Ac
SPRequestDuration
SPIisLatency
X-RateLimit-Remaining
X-SharePointHealthScore
SPRequestGuid
X-B3-TraceId
X-Ruxit-Js-Agent
X-GitHub-Request-Id
X-Abt-Application-Version
X-NF-Request-ID
X-Navigation-Version
X-Vcap-Request-Id
X-Ttl
X-Dw-Request-Base-Id
AR-CACHE
X-Mg-S
X-Client-IP
Pagespeed
X-Sol
X-Middleton-Display
Display
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
Edge-Cache-Tag
S
Fastly-Restarts
X-Cache-Key
X-VARITI-CCR
X-Cache-TTL
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-Erf-Bev-Bev
X-Amz-Rid
X-Amzn-Trace-Id
RTSS
X-Daa-Tunnel
Cache-Status
X-Powered-CMS
X-Kinsta-Cache
X-Edge-Location-Klb
X-Version
Access-Control-Request-Method
X-Goog-Hash
X-Server-ID
Response
X-Middleton-Response
X-Recruiting
X-Varnish-TTL
X-Content-Digest
X-Webkit-Csp
X-ARC
X-TraceId
X-Forwarded-For
X-FastCGI-Cache
X-T
Arr-Disable-Session-Affinity
X-MSEdge-Ref
Cross-Origin-Resource-Policy
MS-Author-Via
Content-MD5
X-SRCache-Store-Status
MicrosoftSharePointTeamServices
X-SRCache-Fetch-Status
TP-Cache
Front-End-Https
X-Shield-Request-Id
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-Accel-Expires
X-FTR-Cache-Status
X-FTR-Balancer
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Backend
X-Cached
X-Hits
X-Forwarded-Proto
X-Request-Received
X-Id
X-Ua-Browser
X-Request-Processing-Time
Public-Key-Pins
Realpath
Server-Node
X-FTR-Expires
X-ORACLE-DMS-RID
Payment
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Combine-CSS
X-HS-Cache-Config
X-Frontend
X-Protected-By
X-LLID
X-RateLimit-Limit
X-Content-Security-Policy-Report-Only
X-DIS-Request-ID
X-HP-Webp
X-HP-Trace-Id
X-Jurisdiction
X-Distributor
X-Kong-Proxy-Latency
X-GUploader-UploadID
X-Kong-Upstream-Latency
TP-L2-Cache
X-ORACLE-DMS-ECID
X-LB-Cache
X-Fastly-Request-ID
Cache-Tags
X-Correlation-Id
X-XRDS-LOCATION
X-Request-Handler-Origin-Region
X-Microsite
Count-Hit
X-Debug-Info
Fastcgi-Cache
X-Amz-Apigw-Id
X-Page-Id
Referer-Policy
X-Amzn-RequestId
X-Hostname
Host
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-Envoy-Decorator-Operation
X-Origin-Server
X-Www-Served-By
X-AppVersion
X-Activity-Id
X-Cluster-Name
X-Az
X-NGENIX-Cache
X-Varnish-Backend
X-Varnish-Server
Accept-Charset
X-Geo-Country
X-App-Server
Origin-Trial
X-PressLabs-Stats
X-Ezoic-Cdn
X-TEC-API-ORIGIN
X-F-Cache
X-TEC-API-ROOT
X-Ratelimit-Limit
X-TEC-API-VERSION
Retry-After
X-Fastcgi-Cache
X-Px
X-Load-Cache
X-RateLimit-Reset
X-Goog-Metageneration
X-FB-Debug
X-CSRF-Token
X-Seen-By
X-Upgrade-Enabled
TCN
Server-Name
Cleartype
Access-Control-Allow-Method
X-Amz-Meta-S3cmd-Attrs
X-Git-Hash
Section-Io-Cache
X-Tt-Trace-Host
X-Grace
X-Tt-Trace-Tag
X-Request-Guid
X-Cache-Control
X-Revision
X-Contextid
X-Varnish-Ttl
X-B3-Sampled
X-TT
X-B
X-Whom
X-Trace-Id
Healthy
X-Webkit-CSP
Paypal-Debug-Id
Charset
X-Type
X-Azure-Ref
DC
X-Datadog-Parent-Id
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Fb-Rlafr
X-Content-Options
X-Proxy
X-Wix-Request-Id
X-Mobile
X-Air-Pt
X-Signature
X-B-Cache
X-N
X-App-Environment
X-Newrelic-App-Data
X-Node-Name
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
Accept-Ch
X-Magnolia-Registration
Filterid
X-Amz-Replication-Status
X-Oracle-Dms-Ecid
Frame-Options
X-Origin-Cache
X-Goog-Stored-Content-Length
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-CCDN-CacheTTL
X-EdgeConnect-Cache-Status
X-Logged-In
X-Time
Viewport
Backend
NGB
X-Unique-Id
X-TTL
VIX-Pulpo-Node
X-Original-Request-Id
VIX-Pulpo-Upstream-Status
X-Oracle-Dms-Rid
X-Response-Served-From
Content-Disposition
X-Debug-IsPreview
X-Tumblr-Pixel-1
X-RemovedCookies
X-Yottaa-Metrics
X-ProcessESI
X-WebKit-CSP-Report-Only
X-Is-Bot
X-Yottaa-Optimizations
X-Rendered-As
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-User
X-Debug-IsConnected
X-Cache-Grace
X-Debug
X-Adobe-Loc
X-Datadog-Sampled
X-Adobe-Content
SD-X-WS
Liferay-Portal
X-FW-Hash
X-FW-Static
X-G
X-FW-Type
X-FW-Version
X-Varnish-Grace
X-FW-Server
X-Servername
X-FW-Serve
X-FW-Dynamic
X-RTag
Ms-Operation-Id
X-NYM-Debug-Backend
X-IPS-LoggedIn
X-Backend-Name
Fastly-SIE
X-Instance
X-Amzn-Remapped-Content-Length
X-Hl-Ver
Fastly-SWR
X-UUID
MS-CV
From-Origin
X-Via-JSL
ServerID
X-VC-Cache
X-Cacheable-TTL
X-Device-Type
X-Fastly-Request-Id
Akamai-GRN
X-Cache-Age
X-Proxy-Cache-Info
X-L-Path
Upgrade-Insecure-Requests
X-Region
X-Environment-Context
X-User-Agent
X-Cache-Hit
X-Ratelimit-Remaining
X-Rule
X-Ua-Device
Version
Country
X-Status
X-B3-SpanId
X-Template
Refresh
X-Source
X-Language
Countrycode
X-INCAP-ABP
CDN-RequestId
GEO-INFO
Url
X-Storage
X-HTML-Minification-Powered-By
X-Air-Trace-Id
X-Cache-Status-Check
X-Rid
SRV
X-Air-Source
X-WP-CF-Super-Cache-Active
X-Air-Hostname
Alternate-Protocol
X-Origin-TTL
X-Origin-CC
X-NODE
OT-Force-Account-Verify
X-Route-Name
X-Real-IP
WPO-Cache-Status
AMP-Access-Control-Allow-Source-Origin
X-Is-Crawler
X-Flags
WPO-Cache-Message
X-Aspnet-Duration-Ms
X-Providence-Cookie
X-Jobs
X-App-Version
X-ServerID
X-B3-Traceid
X-Akamai-Request-ID2
Surrogate-Key
X-CDN-Forward
X-Content-Powered-By
X-VC
Protected
Access-Control-Request-Headers
X-Cache-Time
X-Sucuri-Cache
X-Rocket-Nginx-Serving-Static
X-Mode
X-Hosted-By
Xet-Cookie
X-Accel-Version
X-Handled-By
Amp-Access-Control-Allow-Source-Origin
X-Sucuri-ID
X-Akamai-Edgescape
X-Rewrite-Enabled
X-Endurance-Cache-Level
X-Rn-Rsrv
X-Upstream-Ct
X-Cache-Rule
X-Upstream-Ht
Webserver
X-TT-LOGID
X-UPSTREAM-Address
Meta-Geo
X-Cache-Operation
Filters
X-Web-Node
X-Tumblr-Pixel-2
X-Timing-Wait
X-GeoCode
X-GeoCountry
X-Tumblr-Pixel-3
X-Worker
X-Webstats-RespID
X-Xfnlog-Site
X-Labrador-Cache-Channel
Selected-Fe
X-Cache-Debug
X-Proxy-Build
X-Nginx-Cache
X-PHP-Host
X-Adobe-Source
X-JoinUs
X-Origin
Cross-Origin-Embedder-Policy
X-Framework
Section-Io-Id
X-SaId
X-Edge-Location
X-Detected-As
ServedBy
Atl-Traceid
X-AWS-Id
X-Extlb
X-Drupal-Cache-Tags
Webcakes-App-Name
Webcakes-App-Version
Webcakes-Region
X-Cms-Context
X-Director
X-Served-From
X-Drupal-Cache-Contexts
X-Say-TTL
X-Proxied
X-Platform-Router
Property-Id
X-Soup
X-Redis-Cache
X-Platform-Processor
X-Platform-Cluster
X-Logging-Id
X-LJ-Flow-ID
Mn-Server-Ip
Node
X-Origin-Hint
TWC-Connection-Speed
X-RM-Cache-TTL
X-Zipkin-Id
TWC-Locale-Group
X-VWS-Id
TWC-Privacy
X-Varnish-Cache-Hits
TWC-GeoIP-LatLong
X-SayCDN-TTL
X-Routing-Service
TWC-Device-Class
Web-Mar-Node
TWC-GeoIP-Country
X-Say-Cacheable
Front
X-AB
X-Is-Desktop
X-ProxyCache-Status
X-ProxyCache-Key
X-RCS-CacheZone
X-Restarts
X-Is-Supported-Browser
X-Is-Tablet
X-Skip-Cache
X-Locale
X-Lambda-Id
X-Loop
X-No-Session
X-Origin-Date
X-S
X-Is-Mobile
X-Tcp-Rtt
X-Forwarded-Host
X-Tb
X-Cluster
X-BYPASS-REASON
X-Geo-Region
X-Site-Version
Xserver
X-VCT
X-Varnish-Age
X-Tncms
X-Browser-Name
CDN-PullZone
CDN-RequestCountryCode
CDN-RequestPullSuccess
CDN-EdgeStorageId
CDN-CachedAt
CDN-Cache
CDN-Uid
CDN-RequestPullCode
X-RID
X-Git-Commit
X-IPLB-Instance
X-IPLB-Request-ID
X-Generation-Time
X-Fetched-On
X-Cache-Host
X-Container-Uri
Accept-Language
X-Format
X-Tec-Api-Root
X-Vercel-Id
X-Vercel-Cache
X-R9-Blue-Green-Version
X-Shopify-Stage
X-Alternate-Cache-Key
X-Varnish-Beresp-Grace
X-Storefront-Renderer-Rendered
X-Tec-Api-Version
X-Tec-Api-Origin
X-Httpd
Azure-Version
Apigw-Requestid
Azure-SlotName
Azure-SiteName
Azure-InstanceId
Azure-RegionName
X-Provided-By
X-Cdn-Origin
X-Ms-Request-Id
X-Ms-Version
X-Reqid
X-Frame-Option
X-Vcache
X-Cache-Server
X-ShardId
X-Sorting-Hat-ShopId
X-ShopId
Fastcgi-Useragent
X-Sorting-Hat-PodId
DB-Nickname
X-Server-W
WP-Super-Cache
X-Vcl-Version
X-XRDS-Location
X-Page-View
X-SRV
CF-IPCountry
X-MP-GENERATED-AT
Source
Cross-Origin-Window-Policy
X-Generated-By
X-Azure-Ref-OriginShield
Cross-Origin-Embedder-Policy-Report-Only
X-Uri
Sid
X-Use-Mantle
X-Thinkindot-L3
X-Shield-Cache-Expires
X-Scope-Id
X-CMSURLCustom
Thinkindot-Control
Thinkindot-CacheControl-Type
TDXMobile
Thinkindot-CacheControl
Cache
X-Pass-Why
Cache-Tv-Group
X-FB-TRIP-ID
X-Buckets
Content-Secure-Policy
X-UA
X-Kinja-CCPA
X-DataDome
X-Optimistic-Header
Onion-Location
Priority
HostName
X-LSADC-Cache
Locale
X-Urbn-Site-Id
X-ECache
X-Http-Reason
X-Urbn-Context-Path
X-PDP-UNCACHING-HASH
X-Dc
X-Content-Age
X-Lagoon
X-WP-CF-Super-Cache-Cookies-Bypass
X-DynaTrace
X-GEO
X-Xrds-Location
X-TA-CDN-Provider
X-Request-URI
X-Newrelic-Synthetics
LB
X-Cluster-Node
Locid
Rendered-Blocks
Origin-Agent-Cluster
Redirect-Candidate
DCR-Processing-Time-Ms
DCR-Decision-By
Expiry
Cdnsip
Cdncip
A
Candidate-Md5Url
Gannett-Cam-Experience-Id
Lang
Ngx-Var-Key
Ngx.Var.Host
Meta-Geo-Continent
MD5-Digest
Magicmarker
Origin
X-Conf
X-ND-Cache
X-Op-Id-All
X-Platform
X-Request-Start
X-External-Request-Id
X-Epic-Correlation-Id
X-Developer
X-Dispatcher-Server
X-Ec-Fail
X-Ec-GeoHdr
X-Rojux
X-S-Cookie
X-Vdms-Version
X-Viewer-Country
X-Vtex-Remote-Cache
X-Zen-Fury
X-Vdms-Path
X-Varnish-Hostname
X-ScT
X-SRCache-Key
X-TIM-N
X-Destination
X-D
X-A
X-A-Ccd
X-A-Dam
X-A-Dgt
Vix-Hermes-Req-Id
T-Server
Server-Host
Sslversion
Surrogated-Key
X-A-Wwc
X-Aed
X-Bl-Debug
X-Cache-Bucket
X-Cache-NE
X-Connection-Hash
X-BCube-Filmed-By
X-Bc-Bl
X-AK-Request-ID
X-Application
X-B-Cookie
Req-ID
X-A-Dcw
X-Datadome
X-Proxy-Cache-Status
X-Sql-Duration-Ms
X-Cache-Action
User-Cache-Control
X-Sql-Count
X-Forwarded-Site
Is-Eu
Content-Script-Type
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Device-Os
X-Ec-Custom-Error
X-Esi-Check
Host-ID
X-Fastly-Cache
X-DPWN-IS-SECURE
X-Generated-On
X-Gzip
X-GeoIP-Region-Code
Environment
X-Level-Front-Cache
X-Loc
X-GeoIP-Country-Code
Fastly-SSL
Content-Style-Type
X-Core-Value
X-GeoIP
X-GeoIP-City
X-Gdpr
X-Varnish-Beresp-Ttl
X-Auto-Login
X-B3-Trace-ID
Sever-Int
Server-Hostname
True-Client-Country-4JS
X-Ad-Load-Variation
Wxu-Next-Commit
V-Age
Wxu-Next-Hostname
Wxu-Next-Region
Server-Ext
X-Bip
X-Cache-TTL-Remaining
Cluster
X-Clientip
NM-Fastcgi-Cache
X-Cache-Id
Platform
X-Cache-Aspx
Release
Producers
Pramga
X-Contensis-Viewer-Groups
DSUID
X-PAYTM-SRV-ID
X-Varnish-Authentication
C-Via
X-Origin-Time
X-Nyt-Route
X-Origin-Expires
Adler-Geo
X-Pubstack
X-Scheme
X-SD-PageType
X-SB
X-Thanos
X-UA-Device-Type
X-Req
X-Node-Id
X-Varnishpool
Yak-Timeinfo
XM
X-NCache
X-Nginx-Cache-Key
X-WA-Info
X-NMSegId
X-Service
X-Origin-Response-Time
X-V-Cache
X-Block-Status
X-We-Are-Hiring
X-SVT-ORM-RULES
Web-Mar-Region
X-TH-Server
X-Cache-Expired-At
X-SVT-ORM-VERSION
X-Cache-Backend
X-Var-Ttl
X-Aicache-OS
X-Sn-Servicetimems
X-Amz-Meta-Cb-Modifiedtime
X-VG-TLSProxy
X-Amz-Storage-Class
X-VG-WebCache
X-Backend-Instance
X-VarnishDD-TTL
X-Acquia-Purge-Cdn-Unconfigured
X-ApacheServer
X-Varnish-Beresp-Status
X-BBC-Edge-Cache-Status
X-Varnish-Director
X-Access
X-Request-Time
We-Hiring
X-Hnp-Log
X-HN
X-GoCache-CacheStatus
X-Org
X-Old-Content-Length
X-HS-Content-Campaign-Id
X-Human
X-Micro-Cache
X-Moov-T
X-Men
X-Moov-Xdn-Version
X-Instance-Name
X-Mvc-Supplant-Cachable
X-Gen-Mode
X-PERF
X-Request-Host
X-Region-Sid
X-Mly-Id
X-Cdn-Srv
X-Cache-Info
X-Section
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-From
X-Policy
X-Pool
X-Fmm-Version
X-Proxied-Request
X-FC-Vary-Parameters
X-Server-IP
X-Geo-Header
Apple-News-Services-Parsed-Url
Gh-Request-Id
Cache-Hits
Tube-Get-Contents
Tube-Got-Eval
Tube-Got-Results
Esi-Enabled
Mail-Subject
CDCHOST
RNT-Time
RNT-Machine
Apple-News-Services-Request-Url
Cache-Provider
Canary
Ssr
Req-Svc-Chain
Apple-News-Services-Host
Click-Count-Action-Start
On-Server
L
Fastly-GeoIP-CountryCode
Country-Code
Click-Count-Error
Tube-Return
PFcat
Apple-News-Services-Handled
Uber-Trace-Id
Machine
Fastly-Drupal-HTML
X-NGINX-Cache
AKAMAI
X-CGP
X-Proto
Cdn-Request-Time
X-Fastly-Backend
Ha-Gx-Prefs
Cf-Device-Type
L5d-Success-Class
X-Mvc-Supplant-OutputCached
X-Eu-Site
Cache-Key
Cdn-Host
X-Edge-Server
X-Zone
X-Csrf-Jwt
W
X-Wikidot-Backend
X-App-Name
WZWS-RAY
X-Test
X-VServer
X-Up
X-Wikidot-Static-Cache
X-Slack-Shared-Secret-Outcome
X-Slack-Backend
X-Sigma
HA-Ipaddr
X-Rocket-Build-Number
Proxy-Firewall
X-Sigma-Backend
X-Hash
X-Cache-Date
X-Correlation-ID
X-NWS-UUID-VERIFY
X-Accel-Expires-Debug
X-CacheTTL
X-Date
X-Tb-Optimization-Total-Bytes-Saved
Fastly-Backend-Name
X-LB-ID
NGX
X-VCache
X-Mg-Request-UUID
X-Cloudmap
X-Ah-Environment
X-Tx-Id
X-Branch-Name
X-Via-Fastly
X-API-Version
Edge-Copy-Time
X-Via-CDN
X-Via-SSL
X-Via-Edge
NtCoent-Length
X-Parent-Response-Time
X-DynaTrace-JS-Agent
X-DC
X-Varnish-Hits
S-Rt
X-COUNTRY
X-Refresh
X-Location
X-Ig-Origin-Region
X-Via-Popv
X-Via-Popn
X-HA-Backend
X-Via-Poph
X-CACHE-GROUP
X-Servedbyhost
Type
Pics-Label
X-Ratelimit-Reset
Datacenter
Fusion-Deployment-Id
Fusion-Content-Id
Fusion-Component-Id
X-CDN-Cache-Status
Fusion-Source
Fusion-Content-Source
GeoIp-Country-Code
Fusion-Template-Id
X-VHOST
Cdn
X-Ua
X-Esi
X-Jungle-Id
X-CUA
X-Wormhole-Sdk
Powered-By
Origin-CC
Origin-EX
X-Akamai-Transformed
Resin-Trace
X-LB-NoCache
X-Irp-Debug
X-Wa
X-Owner
SID
X-Core-Mission
X-Nc
Cdn-Requestid
Cf-Ipcountry
IsBot
X-Srv
GeoIP-Latitude
Cross-Origin-Opener-Policy-Report-Only
X-SIPLIST1
X-TX-ID
Server-ID
X-User
X-Qloud-Router
X-Fpc
DataCenter
X-Hit
X-ZONE
X-LiteSpeed-Tag
X-CS
X-NewRelic-App-Data
X-Nf-Request-Id
X-Render-Time
X-VTEX-Cache-Time
X-VTEX-Cache-Server
X-Powered-By-VTEX-Cache
X-Nananana
Debug
X-B3-Parentspanid
X-Proxy-CacheRZ
XkeyRZ
Mime-Version
Fastly-Drupal-Html
X-Client-Ip
CloudFront-Viewer-Country
X-Cached-By
True-Client-IP
Expect-Staple
X-IAuth-Set-Uid
Uri
X-Segment-20210421
X-DataCenter
X-Presslabs-Stats
X-URL
N-Cache
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Tt-Logid
X-Orig-Expires
Xc-Version
X-Cache-Type
X-Amz-Meta-Opti
Edge-Cache
X-TIME
X-Forwarded-Path
X-TimeS
X-Tenant
X-Auth-Group-Type
X-Shop-Environment
X-Varnish-Beresp-TTL
CDN
X-Ig-Push-State
Cmstype
Cmsid
X-Gamma-Serve
X-Cs
X-LiteSpeed-Cache-Control
X-HostName
Srv
X-PHP-Backend
CPC-Cache
CPC-Age
Odigeo-Trace-Id
User-Agent
X-Geo
True-Client-Ip
X-Info
X-CACHE-AGE
X-Vmg-Version
MIME-Version
X-Dynatrace-Js-Agent
X-Fastly-Country-Code
X-Cdn-Diag
Load-Balancing
X-Custom-Header
X-Vgn-Hpd-Reason
Tcn
X-NodeID
X-AIR-PT
X-Cdn-Forward
X-B3-Spanid
X-Dispatch
X-HOST
X-FPC
X-Pad
X-Vc
X-Depends
Request-ID
X-Variation
X-WA
Ohc-File-Size
X-APP-VERSION
X-Varnish-Remaining-TTL
X-DefHash
X-DefElseHash
X-Datacenter
X-NC
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Webkit-Csp-Report-Only
X-M-Reqid
Cl-Cache
CacheControlHeader
Server-Id
X-M-Log
X-VC-TTL
Hostname
X-CSRF-TOKEN
X-Api-Version
X-LAGOON
X-Lb-Nocache
Ohc-Cache-HIT
X-APP
X-Cache-FS-Status
Geoip-Latitude
GeoIP-Country-Code
X-Cdn-Cache-Status
X-ServedByHost
X-Oracle-DMS-ECID
VNS-Age
VNS-Cache
X-Ha-Backend
PICS-Label
Cloudfront-Viewer-Country
Epwk-X-Cache
X-Cache-Ttl
CountryCode
X-Via-PopN
X-Fastly-Backend-Reqs
FSS-Cache
X-Litespeed-Tag
Server-Info
X-Via-PopV
X-Via-PopH
X-Litespeed-Cache-Control
X-VCL-Version
X-Srcache-Store-Status
X-Srcache-Fetch-Status
ServerHost
BehaviorPad-Version
X-Lb-Id
Srvid
Xkey-La3
Xkeylog
X-MSEdge-Flight
X-FL-QIT-DEBUG
X-Cdn-Request-ID
X-Dispatcher-Number
X-MSEdge-Features
X-Snapshot-Date
X-Proxy-Cache-La3
X-MiniProfiler-Ids
X-IN-APIGATEWAYSSL
X-Akamai-Pragma-Client-IP
X-Check-Cacheable
X-IN-APIGATEWAY
OriginIP
X-Th-Server
Ngx
X-RequestId
X-Web-Server
X-Serial
X-Acquia-Application-Trace
Memcached
X-Acquia-Application-UUID
X-Acquia-Site
Time
X-Acquia-Purge-Tags
Memory
X-Cache-Version
X-Shardid
X-Sorting-Hat-Shopid
X-Shopid
X-Sorting-Hat-Podid
X-Ramcache
X-Sucuri-Id
X-RAMCache
X-Mid
Warning
X-Service-Response-Time
X-Dw-Trace-Id
X-Mg-Cache
Sm-Log-Id
Akamai-Cache-Status
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Udemy-Cache-App-Namespace
X-Requestid