Threat Level: green Handler on Duty: Richard Porter

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
Accept-Ranges
Expect-CT
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-Xss-Protection
X-Served-By
P3P
X-UA-Compatible
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
X-AspNet-Version
Content-Security-Policy-Report-Only
X-Runtime
Accept-CH
P3p
X-DNS-Prefetch-Control
X-Ua-Compatible
X-Drupal-Cache
X-Cache-Status
Accept-CH-Lifetime
X-Generator
X-Check
Server-Timing
X-Cacheable
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Iinfo
X-Request-ID
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
X-Content-Security-Policy
Feature-Policy
Content-Encoding
X-CDN
Status
X-AspNetMvc-Version
Upgrade
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
X-Amz-Id-2
CF-Ray
Host-Header
Cf-Edge-Cache
X-Backend
Request-Context
Keep-Alive
X-UA-Device
Allow
X-Robots-Tag
X-Server
X-Cache-Group
X-Hacker
X-AH-Environment
X-Turbo-Charged-By
X-Ws-Request-Id
EagleId
X-Proxy-Cache
X-Age
X-Rq
Xkey
X-Vhost
X-Dispatcher
X-Amz-Version-Id
X-Server-Powered-By
X-Varnish-Cache
Grace
Cf-Apo-Via
X-Dns-Prefetch-Control
X-Swift-SaveTime
X-Swift-CacheTime
X-Page-Speed
X-Pingback
Ali-Swift-Global-Savetime
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-LiteSpeed-Cache
X-Device
Cf-Railgun
EagleEye-TraceId
X-WebKit-CSP
Permissions-Policy
X-OneAgent-JS-Injection
X-CST
X-Backend-Server
X-Aws-Lambda-Call-Status
X-Host
X-Readtime
X-Response-Time
X-Server-Id
X-Akam-SW-Version
X-Cache-Lookup
Request-Id
Surrogate-Control
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Litespeed-Cache
X-HW
X-Nginx-Upstream-Cache-Status
X-Cloud-Trace-Context
X-Nginx-Cache-Status
X-Application-Context
X-Node
X-Country-Code
Content-Location
X-Country
X-Trace
Service-Worker-Allowed
X-Ruxit-JS-Agent
X-Url
X-Content-Type
X-Clacks-Overhead
X-Oneagent-Js-Injection
Accept-Ch-Lifetime
Rating
X-Origin-Cache-Key
X-Rack-Cache
Cache-Tag
X-Amz-Server-Side-Encryption
X-Edge
X-FTR-Request-ID
Cross-Origin-Opener-Policy
X-Midtier
X-Vname
X-PC
X-TtlSet
Nginx-Cache
X-Mcache
X-MS-InvokeApp
X-Mod-Pagespeed
X-ECACHE
X-Upstream
X-Powered-By-Plesk
X-ESI
X-Server-Name
Edge-Control
X-NWS-LOG-UUID
X-Browser-Type
X-Cnection
X-Times
X-D2id
X-Element-Page-Cache
Verso
X-Kinja-Build
X-Kinja-Server
X-GoogleNews-Bot
X-Exp-Id
X-Cdn-Fetch
X-Kinja-Revision
X-Exp-Variant
X-Kinja
X-Ruxit-Js-Agent
X-Ac
SPIisLatency
SPRequestDuration
X-Ser
AR-SID
AR-Request-ID
AR-PoweredBy
AR-ATIME
X-SharePointHealthScore
X-B3-TraceId
SPRequestGuid
X-Ttl
X-GitHub-Request-Id
X-Abt-Application-Version
X-NF-Request-ID
X-Navigation-Version
X-RateLimit-Remaining
X-Dw-Request-Base-Id
X-Vcap-Request-Id
AR-CACHE
X-Mg-S
X-Server-ID
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-Sol
X-Middleton-Display
Pagespeed
S
Display
Edge-Cache-Tag
X-Client-IP
X-VARITI-CCR
X-Cache-Key
Fastly-Restarts
X-Amzn-Trace-Id
X-Cache-TTL
RTSS
X-Amz-Rid
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-Kraken-Loop-Name
X-Erf-Bev-Bev
X-Server-Lifecycle-Phase
Cache-Status
X-Powered-CMS
X-Edge-Location-Klb
X-Kinsta-Cache
X-Version
Access-Control-Request-Method
X-Goog-Hash
X-Daa-Tunnel
X-Recruiting
Response
X-Middleton-Response
X-Content-Digest
X-ARC
X-Webkit-Csp
X-Forwarded-For
X-TraceId
X-Varnish-TTL
X-T
Arr-Disable-Session-Affinity
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-MSEdge-Ref
Content-MD5
Cross-Origin-Resource-Policy
MS-Author-Via
X-SRCache-Fetch-Status
X-SRCache-Store-Status
MicrosoftSharePointTeamServices
Front-End-Https
TP-Cache
X-Shield-Request-Id
X-Accel-Expires
X-Hits
X-Cached
X-Country-Code-Real
X-Fastcgi-Cache
Public-Key-Pins
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Balancer
X-FTR-Cache-Status
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Cache-Config
Server-Node
X-Forwarded-Proto
X-Ua-Browser
X-Request-Received
X-FTR-Expires
X-Id
X-Request-Processing-Time
Payment
X-Content-Security-Policy-Report-Only
X-Frontend
X-DIS-Request-ID
Realpath
X-Protected-By
X-LLID
X-HP-Webp
X-Jurisdiction
X-HP-Trace-Id
Origin-Trial
X-RateLimit-Limit
X-Distributor
X-ORACLE-DMS-RID
X-FastCGI-Cache
X-Hostname
X-GUploader-UploadID
TP-L2-Cache
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-LB-Cache
Cache-Tags
X-Microsite
X-Amzn-RequestId
X-Request-Handler-Origin-Region
X-Amz-Apigw-Id
X-Debug-Info
X-Origin-Server
Referer-Policy
Host
X-Page-Id
Fastcgi-Cache
X-AppVersion
X-Az
X-B3-TraceId-Primal
X-Envoy-Decorator-Operation
X-Activity-Id
Count-Hit
Mrf-Cache-Status
MRF-Tech
X-Www-Served-By
X-NGENIX-Cache
X-Geo-Country
X-Cluster-Name
X-Varnish-Server
X-Varnish-Backend
Accept-Charset
X-Ratelimit-Limit
X-Correlation-Id
X-App-Server
X-F-Cache
X-Ua-Device
X-PressLabs-Stats
X-Fastly-Request-ID
X-XRDS-LOCATION
X-Ezoic-Cdn
X-Varnish-Ttl
Retry-After
X-FB-Debug
X-Goog-Metageneration
TCN
X-Load-Cache
X-ORACLE-DMS-ECID
X-TEC-API-VERSION
X-Upgrade-Enabled
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-CSRF-Token
X-Px
Access-Control-Allow-Method
X-Seen-By
X-Git-Hash
Server-Name
X-Amz-Meta-S3cmd-Attrs
X-RateLimit-Reset
X-Tt-Trace-Tag
X-Tt-Trace-Host
Cleartype
X-Contextid
X-Revision
Section-Io-Cache
X-Request-Guid
X-Datadog-Trace-Id
X-Grace
X-Trace-Id
X-Cache-Control
X-Content-Options
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Oracle-Dms-Ecid
X-B
Charset
X-Type
X-TT
Paypal-Debug-Id
X-B3-Sampled
X-Whom
Healthy
DC
X-Fb-Rlafr
X-Azure-Ref
X-Air-Pt
X-Wix-Request-Id
X-Proxy
X-Signature
X-B-Cache
X-App-Environment
X-Node-Name
X-Mobile
Accept-Ch
X-Magnolia-Registration
X-Origin-Cache
X-N
X-Oracle-Dms-Rid
X-Ratelimit-Remaining
X-Newrelic-App-Data
Frame-Options
X-Amz-Replication-Status
X-EdgeConnect-Cache-Status
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
Filterid
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Generation
X-NODE
X-Logged-In
X-Fastly-Request-Id
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-WebKit-CSP-Report-Only
X-Time
Content-Disposition
Backend
NGB
Viewport
VIX-Pulpo-Node
X-Response-Served-From
VIX-Pulpo-Upstream-Status
X-Original-Request-Id
Akamai-GRN
X-Is-Bot
X-Rendered-As
X-Tumblr-Pixel-1
X-Yottaa-Metrics
X-Varnish-Grace
MS-CV
X-Yottaa-Optimizations
X-Debug-IsPreview
SD-X-WS
Liferay-Portal
X-RTag
X-Servername
X-Tumblr-Pixel
Ms-Operation-Id
X-Debug-IsConnected
X-Datadog-Sampled
X-Tumblr-Pixel-0
X-RemovedCookies
X-ProcessESI
X-Tumblr-User
X-Hl-Ver
X-Unique-Id
X-Rid
X-Cache-Age
X-Amzn-Remapped-Content-Length
X-IPS-LoggedIn
X-FW-Server
X-FW-Static
X-FW-Type
X-TTL
X-FW-Version
X-Instance
X-UUID
Upgrade-Insecure-Requests
X-FW-Serve
X-Debug
X-FW-Hash
X-Language
X-Adobe-Content
X-Adobe-Loc
X-FW-Dynamic
X-Backend-Name
X-Via-JSL
X-Cache-Grace
Fastly-SWR
X-G
X-L-Path
X-NYM-Debug-Backend
ServerID
X-Cacheable-TTL
X-Environment-Context
Fastly-SIE
X-Region
From-Origin
X-Proxy-Cache-Info
X-Device-Type
X-User-Agent
Country
X-Rule
Refresh
X-Cache-Hit
X-Template
X-Aspnet-Duration-Ms
X-Providence-Cookie
X-Flags
X-Is-Crawler
X-Route-Name
X-VC-Cache
X-Status
X-B3-SpanId
X-INCAP-ABP
Url
X-Webkit-CSP
Version
X-Source
Countrycode
X-App-Version
X-HTML-Minification-Powered-By
GEO-INFO
X-Cache-Status-Check
SRV
Alternate-Protocol
CDN-RequestId
X-Jobs
X-Storage
X-Nginx-Cache
WPO-Cache-Status
WPO-Cache-Message
X-WP-CF-Super-Cache-Active
X-Air-Trace-Id
X-Air-Hostname
X-Air-Source
X-B3-Traceid
Amp-Access-Control-Allow-Source-Origin
OT-Force-Account-Verify
X-Akamai-Request-ID2
X-Tec-Api-Origin
X-CDN-Forward
X-Origin-TTL
X-Origin-CC
X-Real-IP
X-Content-Powered-By
X-Tec-Api-Root
X-Tec-Api-Version
Protected
Surrogate-Key
X-Rocket-Nginx-Serving-Static
X-Hosted-By
Access-Control-Request-Headers
X-Accel-Version
X-ServerID
X-VC
X-Cache-Time
CF-IPCountry
AMP-Access-Control-Allow-Source-Origin
X-Akamai-Edgescape
X-Handled-By
X-Cache-Rule
X-Cache-Operation
X-Mode
X-Use-Mantle
X-Kinja-CCPA
Webserver
Xet-Cookie
X-Endurance-Cache-Level
Filters
X-Edge-Location
Meta-Geo
X-Page-View
X-Rewrite-Enabled
X-Rn-Rsrv
X-Xfnlog-Site
X-Framework
X-Upstream-Ht
X-Platform-Cluster
X-Upstream-Ct
X-UPSTREAM-Address
X-Platform-Processor
X-Platform-Router
X-Director
X-Soup
X-TT-LOGID
X-Tumblr-Pixel-2
X-JoinUs
X-Origin
X-Timing-Wait
Cross-Origin-Embedder-Policy
Section-Io-Id
X-Detected-As
X-Tumblr-Pixel-3
ServedBy
X-VWS-Id
X-AWS-Id
X-Served-From
Selected-Fe
X-SaId
X-Proxy-Build
X-Varnish-Cache-Hits
X-LJ-Flow-ID
X-Cache-Debug
X-No-Session
X-Sucuri-Cache
X-Lambda-Id
TWC-GeoIP-Country
X-Adobe-Source
Webcakes-Region
Webcakes-App-Version
Webcakes-App-Name
X-BYPASS-REASON
X-Extlb
X-Cms-Context
X-Cluster
X-Drupal-Cache-Tags
Web-Mar-Node
TWC-Privacy
Node
Mn-Server-Ip
Front
Property-Id
TWC-Connection-Speed
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-Device-Class
X-Labrador-Cache-Channel
X-ProxyCache-Key
X-Redis-Cache
X-Webstats-RespID
X-ProxyCache-Status
X-Routing-Service
X-Worker
X-Say-Cacheable
X-SayCDN-TTL
X-Vcache
X-Zipkin-Id
X-Say-TTL
X-Logging-Id
X-Web-Node
X-PHP-Host
X-Origin-Hint
X-Proxied
Accept-Language
X-Restarts
X-Geo-Region
X-GeoCode
X-RM-Cache-TTL
X-S
X-Browser-Name
X-Drupal-Cache-Contexts
X-Tncms
X-Tcp-Rtt
X-Site-Version
X-Varnish-Age
X-Format
X-Varnish-Beresp-Grace
X-AB
X-GeoCountry
X-RCS-CacheZone
X-Is-Tablet
X-Is-Supported-Browser
Azure-InstanceId
Azure-Version
Apigw-Requestid
Azure-RegionName
Azure-SiteName
Azure-SlotName
X-VCT
X-Skip-Cache
X-Is-Mobile
X-IPLB-Instance
X-Loop
X-IPLB-Request-ID
X-Locale
X-Is-Desktop
X-Vercel-Cache
X-Fetched-On
X-Shopify-Stage
X-Storefront-Renderer-Rendered
X-R9-Blue-Green-Version
CDN-Uid
X-Tb
CDN-Cache
X-Reqid
CDN-EdgeStorageId
X-Httpd
X-Origin-Date
CDN-PullZone
X-Git-Commit
CDN-CachedAt
CDN-RequestPullCode
CDN-RequestCountryCode
Xserver
CDN-RequestPullSuccess
X-Container-Uri
X-Generation-Time
X-Forwarded-Host
X-Vercel-Id
X-Cache-Host
X-Cache-Server
X-Sucuri-ID
X-Alternate-Cache-Key
DB-Nickname
X-Provided-By
X-Ms-Version
X-Frame-Option
X-Ms-Request-Id
X-Server-W
Atl-Traceid
X-ShopId
X-ShardId
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-XRDS-Location
WP-Super-Cache
X-Cdn-Origin
X-MP-GENERATED-AT
X-Uri
X-Vcl-Version
X-Http-Reason
Cross-Origin-Embedder-Policy-Report-Only
Fastcgi-Useragent
Source
Cache-Tv-Group
X-Xrds-Location
X-Generated-By
X-Pass-Why
X-FB-TRIP-ID
Content-Secure-Policy
X-SRV
X-DynaTrace
Cross-Origin-Window-Policy
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
TDXMobile
Thinkindot-Control
X-Shield-Cache-Expires
X-Thinkindot-L3
Priority
X-CMSURLCustom
X-Scope-Id
X-Buckets
Sid
Onion-Location
Cache
Locale
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Azure-Ref-OriginShield
X-DataDome
X-LSADC-Cache
X-Content-Age
X-RID
HostName
X-Sql-Count
X-Sql-Duration-Ms
X-WP-CF-Super-Cache-Cookies-Bypass
X-Optimistic-Header
X-Varnish-Beresp-Ttl
X-GEO
X-Cluster-Node
X-TA-CDN-Provider
X-Proxy-Cache-Status
WZWS-RAY
X-Connection-Hash
X-Request-URI
User-Cache-Control
Expiry
X-Dc
X-Cache-Action
X-Application
Vix-Hermes-Req-Id
X-Op-Id-All
Fastly-Drupal-HTML
X-Lagoon
X-Instance-Name
X-ND-Cache
X-BCube-Filmed-By
X-PAYTM-SRV-ID
X-Bc-Bl
X-Bl-Debug
DCR-Decision-By
MD5-Digest
Meta-Geo-Continent
Server-Ext
Magicmarker
X-D
Server-Host
Lang
X-Conf
Ngx-Var-Key
Redirect-Candidate
Rendered-Blocks
Req-ID
X-Cache-NE
Origin-Agent-Cluster
Ngx.Var.Host
Origin
X-Destination
X-Developer
X-External-Request-Id
X-Epic-Correlation-Id
X-Ec-GeoHdr
Sslversion
Candidate-Md5Url
T-Server
Surrogated-Key
X-Ec-Fail
DCR-Processing-Time-Ms
X-Cache-Bucket
Server-Hostname
Gannett-Cam-Experience-Id
X-Dispatcher-Server
X-Ec-Custom-Error
Sever-Int
A
X-Platform
X-SRCache-Key
X-Vtex-Remote-Cache
X-Varnish-Hostname
X-Request-Start
X-Vdms-Version
X-A-Ccd
X-B-Cookie
X-Rojux
X-Viewer-Country
X-A-Dcw
X-Vdms-Path
X-ScT
X-Scheme
X-S-Cookie
X-SB
X-Aed
X-A-Dam
X-Correlation-ID
X-TIM-N
X-A
X-A-Dgt
X-A-Wwc
X-Newrelic-Synthetics
X-TimeS
Fastly-SSL
Fastly-GeoIP-CountryCode
Yak-Timeinfo
Cdnsip
X-Varnishpool
Cdncip
X-Acquia-Purge-Cdn-Unconfigured
X-Fastly-Cache
X-Varnish-Beresp-Status
Content-Script-Type
Content-Style-Type
Environment
X-Esi-Check
Cluster
X-B3-Trace-ID
X-Varnish-Director
X-Access
X-Debug-Cache-Fetch
X-Clientip
X-Cache-Id
Release
X-Auto-Login
NM-Fastcgi-Cache
Pramga
X-Cache-TTL-Remaining
X-Cache-Expired-At
Req-Svc-Chain
X-Amz-Storage-Class
X-Amz-Meta-Cb-Modifiedtime
X-AK-Request-ID
DSUID
C-Via
X-UA-Device-Type
L
X-Debug-Cache-Store
Host-ID
X-VG-WebCache
X-VServer
Locid
X-Zen-Fury
X-We-Are-Hiring
X-Core-Value
X-WA-Info
X-VG-TLSProxy
Apple-News-Services-Request-Url
X-Hnp-Log
X-Human
X-Rocket-Build-Number
X-Level-Front-Cache
V-Age
Ssr
X-SD-PageType
X-Proxied-Request
X-Origin-Time
X-Pubstack
X-Request-Time
X-Loc
X-NMSegId
X-Node-Id
X-Nyt-Route
Wxu-Next-Region
X-Nginx-Cache-Key
X-NCache
X-Bip
X-Mly-Id
X-Req
X-BBC-Edge-Cache-Status
X-Section
Apple-News-Services-Handled
X-Gen-Mode
X-Generated-On
X-TH-Server
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
X-Thanos
X-Gdpr
Wxu-Next-Hostname
X-Gzip
X-Cache-Info
X-GeoIP-Region-Code
Wxu-Next-Commit
X-Sigma
X-GeoIP-Country-Code
X-Sigma-Backend
X-Pool
CDCHOST
X-Block-Status
X-Forwarded-Site
Edge-Copy-Time
LB
X-UA
X-Origin-Response-Time
X-API-Version
X-Via-Edge
X-Via-CDN
X-Service
X-Via-SSL
X-Cache-Aspx
X-Branch-Name
X-Backend-Instance
X-Micro-Cache
X-Request-Host
X-Server-IP
X-V-Cache
X-Region-Sid
X-RateLimit-Remaining-Second
X-PERF
X-Policy
X-RateLimit-Limit-Second
X-Var-Ttl
X-Cache-Date
Tube-Get-Contents
Tube-Got-Eval
Tube-Got-Results
On-Server
Click-Count-Error
X-Varnish-Authentication
X-VarnishDD-TTL
Click-Count-Action-Start
X-Origin-Expires
X-Org
X-FC-Vary-Parameters
X-Fmm-Version
X-Moov-T
X-DPWN-IS-SECURE
X-Moov-Xdn-Version
X-Contensis-Viewer-Groups
X-SVT-ORM-RULES
X-Device-Os
X-From
X-Geo-Header
X-Men
X-Mvc-Supplant-Cachable
X-Old-Content-Length
X-HS-Content-Campaign-Id
X-HN
X-GeoIP
X-GeoIP-City
X-GoCache-CacheStatus
X-Cdn-Srv
Platform
Gh-Request-Id
X-ECache
Producers
Cache-Provider
RNT-Time
Tube-Return
Is-Eu
Canary
Machine
Mail-Subject
Adler-Geo
PFcat
Esi-Enabled
RNT-Machine
True-Client-Country-4JS
XM
X-SVT-ORM-VERSION
We-Hiring
Web-Mar-Region
Country-Code
X-Ad-Load-Variation
Uber-Trace-Id
X-Aicache-OS
X-ApacheServer
S-Rt
X-Ua
X-Datadome
Cdn-Host
X-Proto
X-Eu-Site
X-DC
X-Fastly-Backend
Cf-Device-Type
X-Test
X-Slack-Shared-Secret-Outcome
X-Slack-Backend
X-App-Name
X-Ratelimit-Reset
X-Sn-Servicetimems
X-Mvc-Supplant-OutputCached
AKAMAI
X-Hash
X-Up
X-Edge-Server
Cache-Key
Cdn-Request-Time
L5d-Success-Class
W
X-Csrf-Jwt
X-Wikidot-Static-Cache
X-CGP
HA-Ipaddr
Proxy-Firewall
X-Wikidot-Backend
Ha-Gx-Prefs
X-Cache-Backend
X-Tx-Id
X-Mg-Request-UUID
X-LB-ID
X-VCache
X-CacheTTL
X-Ah-Environment
X-Parent-Response-Time
X-Accel-Expires-Debug
Type
X-Date
Fastly-Backend-Name
X-Tb-Optimization-Total-Bytes-Saved
X-Varnish-Hits
NGX
X-COUNTRY
X-Servedbyhost
Cache-Hits
Pics-Label
X-Via-Popv
X-CACHE-GROUP
X-HA-Backend
X-Via-Poph
X-Via-Popn
Cdn
X-Zone
X-Via-Fastly
X-DynaTrace-JS-Agent
X-Irp-Debug
X-LB-NoCache
NtCoent-Length
Datacenter
X-VHOST
X-Refresh
X-Owner
SID
Cdn-Requestid
X-NGINX-Cache
X-Cloudmap
X-CDN-Cache-Status
X-Core-Mission
X-Nc
X-Location
X-Wa
X-SIPLIST1
GeoIp-Country-Code
Server-ID
X-Ig-Origin-Region
X-ZONE
IsBot
X-Srv
X-PDP-UNCACHING-HASH
X-Akamai-Transformed
Fusion-Source
Fusion-Content-Source
Fusion-Content-Id
Fusion-Component-Id
Fusion-Template-Id
Fusion-Deployment-Id
X-NWS-UUID-VERIFY
Resin-Trace
X-Qloud-Router
Powered-By
GeoIP-Latitude
Cross-Origin-Opener-Policy-Report-Only
X-Fpc
Expect-Staple
X-CF-Lambda-Version
X-Nananana
X-Hit
X-CF-Lambda-Fn
Origin-CC
N-Cache
X-B3-Parentspanid
DataCenter
Origin-EX
X-CUA
X-Jungle-Id
X-TX-ID
Xc-Version
X-Proxy-CacheRZ
X-Forwarded-Path
CloudFront-Viewer-Country
XkeyRZ
X-Cache-Type
X-Nf-Request-Id
X-Tenant
X-NewRelic-App-Data
X-User
X-Orig-Expires
X-DataCenter
X-Shop-Environment
X-Client-Ip
X-URL
Uri
X-Gamma-Serve
Cmsid
X-Presslabs-Stats
X-Segment-20210421
Cmstype
X-CS
X-IAuth-Set-Uid
CPC-Cache
CPC-Age
X-Tt-Logid
X-Cached-By
X-TIME
User-Agent
X-Render-Time
X-Wormhole-Sdk
X-Amz-Meta-Opti
True-Client-Ip
Mime-Version
X-Cdn-Diag
MIME-Version
X-Powered-By-VTEX-Cache
X-VTEX-Cache-Server
Debug
X-VTEX-Cache-Time
X-Info
X-Esi
X-Vmg-Version
X-Dynatrace-Js-Agent
X-LiteSpeed-Tag
Fastly-Drupal-Html
X-Geo
X-Fastly-Country-Code
Edge-Cache
X-CACHE-AGE
True-Client-IP
X-Auth-Group-Type
X-Dispatch
CDN
X-Oracle-DMS-ECID
Cf-Ipcountry
Load-Balancing
X-B3-Spanid
X-LiteSpeed-Cache-Control
CacheControlHeader
X-Datacenter
Srv
X-Variation
X-HOST
X-Ig-Push-State
X-Vc
X-LAGOON
X-Varnish-Beresp-TTL
X-Cs
Odigeo-Trace-Id
Ohc-File-Size
X-Webkit-Csp-Report-Only
X-Cdn-Forward
Hostname
Cl-Cache
X-Vgn-Hpd-Reason
X-Custom-Header
X-NodeID
X-CSRF-TOKEN
Tcn
X-APP-VERSION
X-PHP-Backend
X-MCACHE
GeoIP-Country-Code
VNS-Cache
X-FPC
X-Depends
VNS-Age
Ohc-Cache-HIT
X-Pad
X-NC
X-Varnish-CookieINHashed-On
X-DefElseHash
X-DefHash
X-Varnish-CookieHashed-On
X-WA
Server-Id
X-Varnish-Remaining-TTL
X-Cdn-Cache-Status
X-HostName
X-AIR-PT
X-Lb-Nocache
X-M-Reqid
X-VC-TTL
X-M-Log
X-Litespeed-Tag
X-MSEdge-Features
X-MSEdge-Flight
X-Dispatcher-Number
X-Cache-Ttl
X-Fastly-Backend-Reqs
X-Via-PopN
X-Cache-FS-Status
X-Via-PopH
Geoip-Latitude
PICS-Label
X-ServedByHost
X-Ha-Backend
X-Via-PopV
Lb
CountryCode
X-APP
Epwk-X-Cache
X-Srcache-Store-Status
X-Use-Magma
X-Srcache-Fetch-Status
X-VCL-Version
X-Litespeed-Cache-Control
Xkey-La3
X-Snapshot-Date
X-Lb-Id
Ngx
Xkeylog
Cloudfront-Viewer-Country
X-Proxy-Cache-La3
X-MiniProfiler-Ids
X-Cdn-Request-ID
Cache-Name
X-Api-Version
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Web-Server
X-Acquia-Site
X-RequestId
X-Mid
Memcached
OriginIP
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Acquia-Application-Trace
Memory
Time
X-Cache-Version
X-Sorting-Hat-Shopid
X-Sorting-Hat-Podid
X-Shardid
X-Shopid
Warning
X-Ramcache
X-Requestid
FSS-Cache
Server-Info
X-Serial
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Udemy-Cache-App-Namespace
X-Th-Server
X-Sucuri-Id
CF-Cached-On
Sm-Log-Id
X-Akamai-Pragma-Client-IP
X-Mg-Cache
X-Dw-Trace-Id
X-Service-Response-Time
X-Check-Cacheable
Akamai-Cache-Status