Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Link
CF-Cache-Status
X-Powered-By
Pragma
ETag
CF-RAY
Expect-CT
X-XSS-Protection
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-UA-Compatible
X-Xss-Protection
X-Served-By
Alt-Svc
X-Varnish
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Adblock-Key
X-Drupal-Cache
X-Check
Content-Security-Policy-Report-Only
X-Permitted-Cross-Domain-Policies
X-Cache-Status
X-Generator
CF-Ray
X-DNS-Prefetch-Control
X-Cacheable
X-Kinja-Server-Push
Timing-Allow-Origin
X-Template
X-Language
X-FRAME-OPTIONS
X-AspNetMvc-Version
X-Iinfo
X-Buckets
X-Ua-Compatible
Status
X-Content-Security-Policy
Content-Encoding
Access-Control-Expose-Headers
P3p
X-CDN
Upgrade
X-Request-ID
X-Envoy-Upstream-Service-Time
Access-Control-Max-Age
Keep-Alive
X-Via
X-Drupal-Dynamic-Cache
X-Ws-Request-Id
X-Backend
X-Age
X-Server
X-AH-Environment
X-Turbo-Charged-By
X-Cache-Group
X-Robots-Tag
Feature-Policy
Request-Context
X-Proxy-Cache
Xkey
X-Amz-Request-Id
X-Amz-Id-2
EagleId
X-Hacker
X-Page-Speed
X-UA-Device
X-Server-Powered-By
X-Nginx-Cache-Status
Grace
X-Pingback
Server-Timing
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
X-LiteSpeed-Cache
Ali-Swift-Global-Savetime
Report-To
X-Amz-Version-Id
X-Server-Id
Cf-Railgun
X-Rq
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-WebKit-CSP
X-OneAgent-JS-Injection
EagleEye-TraceId
X-Origin-Cache
X-Host
Surrogate-Control
X-Device
X-Response-Time
X-Vhost
X-Readtime
X-Cache-Lookup
X-Ac
X-Node
X-Backend-Server
X-Dns-Prefetch-Control
X-Dispatcher
NEL
X-Origin-Upstream-Status
Content-Location
X-HW
Fusion-Template-Id
Fusion-Component-Id
Fusion-Source
Fusion-Content-Id
Fusion-Content-Source
X-Mod-Pagespeed
Request-Id
X-DataDome
X-Application-Context
X-ORACLE-DMS-ECID
X-Akam-SW-Version
X-Ruxit-JS-Agent
Fusion-Deployment-Id
X-ORACLE-DMS-RID
X-Country
Allow
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Cloud-Trace-Context
Rating
Accept-CH
X-Country-Code
X-Cnection
X-Rack-Cache
X-Url
Edge-Control
RTSS
Accept-CH-Lifetime
Host-Header
MS-Author-Via
X-Clacks-Overhead
X-Px
X-FTR-Request-ID
X-PC
X-Vname
X-TtlSet
X-Goog-Hash
Verso
X-Powered-By-Plesk
X-Varnish-TTL
Service-Worker-Allowed
X-B3-TraceId
X-GoogleNews-Bot
X-Exp-Id
X-Cdn-Fetch
X-Kinja
X-Exp-Variant
X-Kinja-Server
X-Kinja-Revision
X-Kinja-Build
X-Use-Magma
X-GitHub-Request-Id
Arr-Disable-Session-Affinity
Public-Key-Pins
X-Forwarded-Proto
X-MS-InvokeApp
X-Amz-Server-Side-Encryption
X-Middleton-Response
X-Middleton-Display
Response
Display
X-Sol
Pagespeed
X-Cache-TTL
X-DynaTrace
X-Content-Type
X-D2id
X-Amz-Rid
X-NF-Request-ID
X-Cached
TCN
X-Vcap-Request-Id
X-Abt-Application-Version
X-VARITI-CCR
X-CST
X-Cdn
Pinterest-Generated-By
X-Ttl
AR-ATIME
AR-PoweredBy
AR-Request-ID
Ar-Sid
AR-CACHE
X-ESI
X-Navigation-Version
X-Version
X-Powered-CMS
X-Upstream
X-Fastly-Request-ID
Cache-Tag
X-Server-Name
X-Debug
X-Grace
X-XRDS-Location
X-Instart-Request-ID
Access-Control-Request-Method
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
Charset
X-MSEdge-Ref
X-Element-Page-Cache
Nginx-Cache
X-Mrf-Section-Lastmod
Mrf-Cache-Status
X-B3-TraceId-Primal
Content-MD5
MRF-Tech
X-Mrf-Item-Lastmod
Accept-Ch
Realpath
X-Accel-Expires
X-Ezoic-Cdn
X-DynaTrace-JS-Agent
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Shield-Request-Id
SPRequestDuration
SPIisLatency
X-Jurisdiction
SPRequestGuid
X-Hp-Webp
X-SharePointHealthScore
X-Pinterest-Rid
Pinterest-Version
Accept-Ch-Lifetime
S
X-Amz-Meta-S3cmd-Attrs
X-Recruiting
X-Id
X-Dw-Request-Base-Id
X-Kinsta-Cache
X-TTL
X-T
X-Content-Digest
X-Cache-Key
Fastcgi-Cache
X-Trace
X-Logged-In
X-Node-Name
X-NWS-LOG-UUID
TP-L2-Cache
TP-Cache
X-Mobile-URL
X-Hostname
Fastly-Restarts
X-Request-Received
X-Request-Processing-Time
X-Frontend
X-Cache-Hit
ServerID
Front-End-Https
X-Amzn-Trace-Id
X-Cache-Age
Server-Node
X-Oneagent-Js-Injection
X-Client-IP
X-FastCGI-Cache
X-Forwarded-For
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-Backend
X-FTR-DC
X-FTR-Realm
X-Country-Code-Real
Edge-Cache-Tag
X-Yandex-Sdch-Disable
X-FTR-Expires
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
X-Goog-Stored-Content-Length
Powered
X-Goog-Metageneration
Server-Name
X-Pass-Why
X-Server-ID
PB-PID
PB-RID
Arc-Version
X-Request-Handler-Origin-Region
X-Microsite
X-User-Agent
X-Content-Security-Policy-Report-Only
X-DIS-Request-ID
X-Page-Id
X-Hits
Filters
X-LB-Cache
X-F-Cache
X-Revision
X-Kong-Upstream-Latency
X-Jobs
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Kong-Proxy-Latency
X-Akamai-Edgescape
X-Fastcgi-Cache
X-Correlation-Id
X-Zen-Fury
Alternate-Protocol
DynaTrace
X-ORACLE-APMCS-TAG
X-ORACLE-APMCS-REQUEST-ID
X-Origin-Server
AMP-Access-Control-Allow-Source-Origin
X-Mobile-Rewrite
X-Geo-Country
X-Content-Powered-By
X-HS-Cache-Config
X-HS-Combine-CSS
X-HS-Content-Id
X-HS-Hub-Id
X-Daa-Tunnel
X-Varnish-Age
Accept-Charset
X-FTR-Cache-Host
X-N
X-RateLimit-Remaining
X-B
Cache-Tags
X-Varnish-Backend
X-Ruxit-Js-Agent
Retry-After
X-Amz-Replication-Status
X-Rid
X-WebKit-CSP-Report-Only
X-Varnish-Grace
X-Type
Section-Io-Cache
X-Content-Options
Surrogate-Key
X-Git-Hash
X-Whom
X-Ser
Host
DC
X-FB-Debug
X-TT
X-App-Environment
X-B-Cache
X-Signature
X-Request-Guid
Paypal-Debug-Id
X-Edge
X-Activity-Id
X-Az
X-AppVersion
X-Esi
Fastcgi-Useragent
X-Via-JSL
X-IPLB-Instance
X-Debug-Info
Frame-Options
X-Status
Actual-Object-TTL
MicrosoftSharePointTeamServices
Healthy
X-Endurance-Cache-Level
X-ATG-Version
X-ATS-Timestamp
Backend-Timing
X-Webkit-CSP
X-HTML-Minification-Powered-By
Srv
Nel
X-App-Server
X-AOL-HN
X-Contextid
X-Cache-Action
X-Seen-By
Refresh
X-Amzn-RequestId
X-ECACHE
X-B3-Sampled
X-Release
From-Origin
Content-Disposition
X-Amz-Apigw-Id
Access-Control-Allow-Method
X-Pinterest-Direct
X-Accel-Buffering
X-Protected-By
X-Cache-Rule
X-Response-Served-From
X-ProcessESI
X-Upgrade-Enabled
X-Cache-Operation
X-RemovedCookies
VIX-Pulpo-Node
X-Tumblr-Pixel-0
X-Rendered-As
X-Tumblr-User
X-Cacheable-TTL
X-Is-Bot
X-MCACHE
X-Mid
Odigeo-Trace-Id
X-Tumblr-Pixel
VIX-Pulpo-Upstream-Status
X-Region
X-L-Path
X-Instance
X-WA-Info
X-Environment-Context
X-UUID
X-Drupal-Cache-Tags
Datacenter
X-FW-Type
X-FW-Static
X-FW-Serve
Eomportal-Instance
X-FW-Server
X-Host-Name
X-FW-Hash
X-FW-Dynamic
X-Varnish-Server
Payment
X-Rule
X-Time
MS-CV
X-Cache-Time
X-Adobe-Loc
X-Adobe-Content
Countrycode
X-Ah-Environment
Uber-Trace-Id
X-EdgeConnect-Cache-Status
X-Cached-By
X-Proxy
X-Litespeed-Cache
X-Akamai-Request-ID2
Source
X-Load-Cache
Xserver
X-Cache-Control
X-Cache-Server
X-Mobile
X-NewRelic-App-Data
X-UnsetCookies
X-PHP-Backend
Access-Control-Request-Headers
X-Azure-Ref
X-Akamai-Transformed
Accept-Language
X-GeoIP
X-Yottaa-Metrics
X-Air-Hostname
X-Yottaa-Optimizations
X-Tt-Trace-Host
X-NGENIX-Cache
X-Tt-Trace-Tag
X-Origin-Response-Time
Version
X-Cache-NGX
X-Backend-Name
X-SERVER-NAME
X-Handled-By
X-NWS-UUID-VERIFY
Server-Info
Liferay-Portal
X-Wix-Request-Id
X-Mode
Filterid
Cache-Status
X-Framework
X-CSRF-Token
X-RateLimit-Limit
X-Vcache
X-Cluster
X-Correlation-ID
Load-Balancing
X-FireWall-Port
X-Ua
X-Via-Fastly
X-Adobe-Source
X-VWS-Id
Cross-Origin-Window-Policy
X-Zipkin-Id
X-RN-RSRV
X-Proxied
X-UPSTREAM-Address
X-URL
X-PERF
X-Routing-Service
X-Presslabs-Stats
X-AWS-Id
X-LJ-Flow-ID
X-ES-SERVER
Cache
X-Cache-Var-Map
X-CCM
X-Cache-Var
X-ApacheServer
X-IPS-LoggedIn
X-UA-Device-Type
X-Path-Route
Meta-Geo
X-Locale
DSUID
Cache-Hits
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
Mn-Server-Ip
X-Qloud-Router
X-Viewer-Country
X-MP-GENERATED-AT
X-TX-ID
X-Real-IP
X-Www-Served-By
X-Detected-As
ServedBy
X-Cache-Status-Check
X-Site-Version
X-Section
X-Pubstack
X-Web-Node
Decoy-Debug-Key
X-NCache
Cleartype
Cache-Name
Akamai-GRN
Now
Cache-Tv-Group
X-Format
X-Access
X-IP
Decoy-Debug-TTL
X-Info
X-OCL
X-Human
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
X-Cache-Config
X-PCL
X-R9-Blue-Green-Version
Section-Origin-Responded
Decoy-Debug-Status
X-SayCDN-TTL
X-Say-TTL
X-Redis-Cache
X-Say-Cacheable
X-Storage
Section-Io-Id
X-Unique-Id
X-PressLabs-Stats
X-ShardId
X-ProxyCache-Status
X-ProxyCache-Key
X-ShopId
X-Shopify-Stage
X-Sorting-Hat-ShopId
Origin-Cache-Control
X-PHP-Host
X-Labrador-Cache-Channel
X-Cache-Host
X-Cache-Enabled
X-Cache-Remote
NGB
X-EIG-Tracking-Id
X-Hosted-By
X-FC-Vary-Parameters
Property-Id
S-Rt
X-Device-Type
X-CS
X-Bc-Bl
X-FW-Version
X-Origin-Hint
X-Varnish-Cache-Hits
X-ServerID
Webcakes-Region
Webcakes-App-Version
TWC-GeoIP-Country
TWC-Device-Class
TWC-Connection-Speed
TWC-GeoIP-LatLong
TWC-Locale-Group
Webcakes-App-Name
TWC-Privacy
X-BYPASS-REASON
X-Sorting-Hat-PodId
Fastly-SSL
Webserver
X-Hyper-Cache
X-Alternate-Cache-Key
X-Geo
X-From
X-Loop
X-JoinUs
X-Proxy-Build
X-FB-TRIP-ID
X-Hl-Ver
X-BCube-Filmed-By
X-TNCMS
X-Time-Microsecs
X-SaId
Selected-Fe
X-Origin
X-Timing-Wait
X-NYM-Debug-Backend
X-Content-Age
DB-Nickname
X-RTag
Ms-Operation-Id
X-Amzn-Remapped-Content-Length
Apigw-Requestid
X-No-Session
Azure-InstanceId
X-APP-VERSION
X-Generated
Azure-RegionName
X-Cache-2
Azure-Version
Ec-Rule-Version
Azure-SiteName
Azure-SlotName
Locale
X-Urbn-Site-Id
X-Cache-TTL-Remaining
X-Urbn-Context-Path
X-Drupal-Cache-Contexts
X-VCache
X-XRDS-LOCATION
X-EC-Lua
X-Xfnlog-Site
Time
Origin-Edge-Control
SD-X-WS
X-Goog-Meta-Goog-Reserved-File-Mtime
X-SRV
Country
X-Debug-Cache
X-CDN-Forward
X-Source
X-Pad
X-App-Version
X-Soup
X-Old-Content-Length
Upgrade-Insecure-Requests
X-Cluster-Node
X-Varnish-Hostname
Geo-Info
X-Backend-TTL
X-RequestSource
X-Storefront-Renderer-Rendered
X-Proto
X-Akamai-Request-ID
X-DC
X-Tb
User-Agent
X-Cache-NE
X-RCS-CacheZone
LB
X-Parent-Response-Time
X-Cache-PHP
X-NC
X-TA-CDN-Provider
X-Cache-Backend
X-App
Proxy-Connection
Cache-Key
Referer-Policy
X-Cache-Grace
X-Magnolia-Registration
X-Origin-TTL
X-Origin-CC
FilterID
X-Proxy-Cache-Status
X-Client-Ip
Content-Script-Type
X-SIPLIST1
BehaviorPad-Version
True-Client-Country-4JS
UCS
T-Server
Viewtype
X-Vtex-Processado-Em
X-SD-PageType
Who
VivaBuild
X-Vtex-Remote-Cache
ServerName
Rendered-Blocks
NGX
Arc-Country
GEO-REGION-INFO
Machine
M-TraceId
X-SVT-ORM-RULES
FNAC-ModuleRouting
AsisCache
Mobile-Detection-Method
N-Cache
Meta-Geo-Continent
Content-Style-Type
Fastcgi-X-Cache-Version
MD5-Digest
IsBot
X-VG-WebCache
X-Rewrite-Enabled
X-Response-By
X-B-Cookie
X-G
X-Rojux
X-S
X-ARC
X-Scheme
X-S-Cookie
X-Geo-Header
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Region-Sid
X-External-Request-Id
X-Dispatch
X-SVT-ORM-VERSION
X-DevSite-Last-Modified
X-Developer
X-Connection-Hash
X-D
X-Date
X-Destination
X-Processor
X-Application
X-Vdms-Version
X-A-Dgt
X-SRCache-Key
X-Vdms-Path
X-A-Dcw
Xc-Version
X-A-Ccd
X-PAYTM-SRV-ID
X-A-Dam
X-VG-WebServer
X-Twitter-Response-Tags
X-NodeID
X-Nginx-Cache-Key
X-Method
X-Accel-Expires-Debug
X-Aed
X-Swa-Ws
X-Trace-Id
X-ScT
X-Trv-Group
X-Transaction
X-A
X-A-Wwc
X-FORWARDED-FOR
X-Forwarded-Host
X-Uri
User-Cache-Control
Release
X-Loc
X-Backend-State
X-ServiceProvider
X-Agile-Id
X-Matched-Rule
X-Logging-Id
X-Servername
Pagetype
X-Skip-Cache
Magicmarker
Mail-Subject
X-Level-Front-Cache
X-User
X-Cache-Bucket
X-AIR-PT
X-Thinkindot-L3
X-SN
NM-Fastcgi-Cache
X-Bip
X-Block-Status
X-Thanos
X-Agile-Age
Server-Host
Web-Mar-Node
X-RateLimit-Limit-Second
We-Hiring
Vix-Hermes-Req-Id
X-RateLimit-Remaining-Second
Wxu-Next-Commit
Wxu-Next-Hostname
X-Node-Id
X-Owner
X-Policy
Wxu-Next-Region
X-Tumblr-Pixel-3
Viewport
X-Req
Sever-Int
X-Reqid
Server-Hostname
X-LAGOON
X-Agile
Thinkindot-CacheControl
V-Age
X-Micro-Cache
Thinkindot-Control
Thinkindot-CacheControl-Type
Server-Ext
X-Cache-FS-Status
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Handled
X-Developers
Apple-News-Services-Request-Url
X-Cms-Context
CDCHOST
On-Server
X-Compress-Hint
X-Distributor
X-Edge-Location
X-Dispatcher-Server
Node
X-Fmm-Version
X-Gen-Mode
X-Generated-In
X-Generation-Time
X-Generated-On
X-Device-Os
CacheControlHeader
X-Hash
AKAMAI
X-Hnp-Log
Kp-EeAlive
X-WADP-Cache
X-Key
X-Cache-Info
X-VC-Cache
X-Cache-URL
X-Clara-WADP
X-Varnish-Cacheable
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-Worker
OT-Force-Account-Verify
X-Hit
X-Esi-Check
X-Epic-Correlation-Id
X-Envoy-Decorator-Operation
X-Distil-CS
X-Fastly-Cache
X-Mvc-Supplant-Cachable
X-Irp-Debug
X-Core-Value
X-Core-Mission
X-NU-AKA-ACS-Version
X-Cluster-Name
X-Gzip
X-Clientip
X-Cache-Tags
X-BBXSRF
X-CGP
X-Cache-Id
Rt-Fastcgi-Cache
Fastly-SIE
Fastly-Drupal-HTML
Gh-Request-Id
X-Auto-Login
Fastly-SWR
X-Webstats-RespID
HA-Ipaddr
X-Origin-Date
X-VServer
X-We-Are-Hiring
C-Via
Adler-Geo
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
Pragrma
X-Server-W
X-Location
X-Has-Esi
X-Is-Gdpr
X-JWT-State
X-VG-TLSProxy
Ha-Gx-Prefs
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
W
Is-Eu
X-Eu-Site
GEO-INFO
X-Session-Fingerprint
X-Request-Host
X-Request-UUID
Platform
X-TrackingId
X-Var-Ttl
L5d-Success-Class
X-TH-Server
X-Slack-Backend
X-Origin-Expires
X-Variation
X-Varnish-Authentication
MIME-Version
X-Cache-ASPX
X-Li-Pop
X-Li-Fabric
Sid
X-Backend-Host
X-LI-Proto
X-LI-UUID
X-Contensis-Viewer-Groups
X-GoCache-CacheStatus
X-Reboot
Memcached
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-From
RNT-Machine
Cache-Cookie-Set-Lfrom
RNT-Time
X-ZONE
X-BC
X-Wa
X-Newrelic-Synthetics
X-Nc
X-Up
X-Be
Fastly-Backend-Name
X-Via-CDN
X-Batcache
X-Branch-Name
X-Refresh
X-Minions-Version
X-Cache-Debug
X-Varnish-URL
X-Configured-By
Cf-Ipcountry
X-Srv
X-Dc
S-Cnection
X-Nginx-Cache
X-ElasticPress-Query
HostName
X-Servedbyhost
X-Instart-Info
X-Aicache-OS
X-Ua-Device
X-Via-PopH
X-Envoy-Upstream-Healthchecked-Cluster
X-Via-PopV
X-Mvc-Supplant-OutputCached
CACHE
X-Platform-Server
X-Microcachable
X-Cdn-Forward
X-UA
X-B3-Traceid
X-VCL-Version
X-TT-TIMESTAMP
DCR-Decision-By
DCR-Processing-Time-Ms
X-Ms-Request-Id
X-Ms-Version
X-Sucuri-ID
X-MSEdge-Flight
Memory
Pramga
X-Fastly-Cache-Status
X-MSEdge-Features
X-ND-Cache
X-PF-Uncompressing
X-Pjax-Url
X-BE
Hostname
X-Varnishpool
X-Ratelimit-Reset
X-TIME
X-Debug-Panamera-Host
GeoIP-Country-Code
HitType
Esi-Enabled
Location
X-Debug-Panamera-Sitecode
NtCoent-Length
Powered-By-ChinaCache
GeoIP-Latitude
X-LB-ID
L
X-Vgn-Hpd-Reason
X-App-Name
X-COUNTRY
X-Original-Request-Id
Server-ID
X-CF-Powered-By
X-Zone
FSS-Cache
X-Bc
X-Sucuri-Cache
X-Check-Cacheable
X-Oss-Server-Time
X-FPC
X-Oss-Request-Id
X-Oss-Object-Type
X-Oss-Storage-Class
X-Server-IP
Cache-Host
X-Oss-Hash-Crc64ecma
X-VarnishDD-TTL
X-OVcl-Cache
PFcat
X-BACKEND-TTL
X-OVcl
X-Cdn-Srv
Ohc-File-Size
X-GEO
X-Svr
X-Azure-Ref-OriginShield
X-Unique-ID
Server-Cache-Control
X-Vgn-Hpd-Variations-Key
Resin-Trace
X-Generated-By
Server-Surrogate-Control
X-Vgn-Hpd-Ssi
X-Vgn-Hpd-Cached
X-Instart-Isnd
NR-ENABLED
WPE-Backend
X-S-Maxage
X-Fastly-Backend-Reqs
X-Varnish-Ttl
X-Render-Time
Ohc-Response-Time
X-Platform
Cteonnt-Length
X-Fpc
X-Rocket-Nginx-Bypass
X-HS-Status
X-Fastly-Country-Code
Tracecode
X-VCT
X-CUA
X-VHOST
X-Edge-Server
X-Cache-Expired-At
Epwk-X-Cache
X-PJAX-URL
Cdn-Host
Request-Country
Request-EU
Cdn-Request-Time
Locid
Heartbleed
Pics-Label
X-Varnish-Hits
X-CSRF-TOKEN
GeoIp-Country-Code
X-Request-URI
Geoip-Latitude
SRV
CF-Cached-On
X-Newrelic-App-Data
Backend-Name
X-Ratelimit-Remaining
Backend
Lfy
X-Pf-Uncompressing
X-Vcl-Version
X-RunCloud-Cache
SN
X-Via-Poph
X-Oracle-Dms-Rid
X-CACHE-AGE
X-Csrf-Jwt
X-Gamma-Serve
X-CLOUD-TRACE-CONTEXT
X-StackifyID
X-Via-Popv
WWW-Authenticate
X-ECache
X-NGINX-Cache
X-CACHE-KEY
X-Ratelimit-Limit
X-Amzn-Remapped-Connection
X-Rocket-Build-Number
X-Sigma
X-Sigma-Backend
XServer
X-ServedByHost
X-WebServer
X-Request-Time
X-Amzn-Remapped-Date
X-Varnish-Url
Amp-Access-Control-Allow-Source-Origin
X-Shopify-Generated-Cart-Token
X-Ftr-Cache-Host
X-Oss-Cdn-Auth
CloudFront-Viewer-Country
Product
X-Tec-Api-Origin
X-Tec-Api-Version
X-Proxy-Upstream
Host-ID
X-Tec-Api-Root
URI
WZWS-RAY
X-Fetched-On
X-DPWN-IS-SECURE
X-Apw-Hits
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Sn-Servicetimems
My-App
X-Cdn-Origin
X-Apw-Access-Object
X-Nananana
X-Apw-Access-Action
CF-IPCountry
X-Apw-Access-Token
Lb
X-Cache-Tag
Server-Ttl
PICS-Label
Cloudfront-Viewer-Country
X-Debug-Do-Not-Cache-Uri
X-Debug-Cache-Bypass
A
X-GeoIP-Country-Code
X-B3-Spanid
SID
X-Tb-Optimization-Total-Bytes-Saved
X-Debug-Cache-String
X-Debug-Cache-Status
X-Debug-Xas-Auth
Country-Code
X-LiteSpeed-Cache-Control
Mime-Version
X-Debug-Ysi-Auth
X-Cache-Version
CDN-RequestId
CDN-Uid
X-Via-Ucdn
CDN-EdgeStorageId
Dnion-Transfer-Encoding
CDN-Cache
CDN-CachedAt
CDN-PullZone
CDN-RequestCountryCode
X-Acquia-Purge-Tags
X-Acquia-Application-Trace
X-Acquia-Site
X-B3-SpanId
Ohc-Cache-HIT
Dt-Cache-Category
Cneonction
X-Acquia-Application-UUID
Proxy-Firewall
X-WA
X-Html-Edge-Cache
X-WR-MODIFICATION
X-IN-APIGATEWAYSSL
X-Request-URL
X-Request-Start
Cdn
X-IN-APIGATEWAY
X-ElasticPress-Search
FSS-Proxy
Warning
X-Dw-Trace-Id
X-SB
Cf-Alt-Svc
Inserted-Into-Cache-At
X-Varnish-Beresp-TTL
X-VC
X-Swift-Error
X-Snapshot-Date