Threat Level: green Handler on Duty: Rick Wanner

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
Accept-Ranges
Expect-CT
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-Xss-Protection
X-UA-Compatible
P3P
X-Served-By
X-Request-Id
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
X-FRAME-OPTIONS
Access-Control-Allow-Credentials
X-AspNet-Version
Content-Security-Policy-Report-Only
X-Runtime
X-DNS-Prefetch-Control
Accept-CH
P3p
X-Cache-Status
Accept-CH-Lifetime
X-Drupal-Cache
X-Check
X-Ua-Compatible
X-Generator
Server-Timing
X-Cacheable
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Iinfo
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
X-Content-Security-Policy
Feature-Policy
Content-Encoding
X-CDN
Status
X-AspNetMvc-Version
Upgrade
X-Request-ID
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
X-Amz-Id-2
CF-Ray
Host-Header
Cf-Edge-Cache
X-Backend
Allow
Request-Context
Keep-Alive
X-Robots-Tag
X-Server
X-Cache-Group
X-Hacker
X-UA-Device
X-AH-Environment
X-Turbo-Charged-By
X-Ws-Request-Id
X-Proxy-Cache
Xkey
X-Age
X-Rq
EagleId
X-Vhost
X-Dispatcher
X-Server-Powered-By
X-Amz-Version-Id
X-Varnish-Cache
Grace
Cf-Apo-Via
X-Page-Speed
X-Swift-SaveTime
X-Swift-CacheTime
X-Pingback
Cf-Railgun
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
Ali-Swift-Global-Savetime
X-Device
EagleEye-TraceId
X-Dns-Prefetch-Control
X-LiteSpeed-Cache
X-WebKit-CSP
X-Aws-Lambda-Call-Status
X-CST
X-OneAgent-JS-Injection
Permissions-Policy
X-Backend-Server
X-Server-Id
X-Readtime
X-Response-Time
X-Host
X-Akam-SW-Version
Request-Id
Surrogate-Control
X-Litespeed-Cache
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-HW
X-Nginx-Upstream-Cache-Status
X-Cache-Lookup
X-Cloud-Trace-Context
X-Node
X-Nginx-Cache-Status
X-Application-Context
X-Country-Code
Content-Location
X-Trace
X-Country
Service-Worker-Allowed
X-Ruxit-JS-Agent
X-Url
X-Content-Type
X-Clacks-Overhead
X-Oneagent-Js-Injection
X-Origin-Cache-Key
Accept-Ch-Lifetime
X-Edge
X-Rack-Cache
Cache-Tag
Cross-Origin-Opener-Policy
X-Amz-Server-Side-Encryption
X-FTR-Request-ID
X-Midtier
X-Mcache
X-Mod-Pagespeed
X-MS-InvokeApp
X-TtlSet
X-PC
Nginx-Cache
X-Vname
X-ECACHE
X-ESI
X-Upstream
X-Powered-By-Plesk
Rating
Edge-Control
X-Server-Name
X-Browser-Type
X-D2id
X-Cnection
X-Element-Page-Cache
Verso
X-Times
X-Cdn-Fetch
X-Kinja
X-Kinja-Build
X-GoogleNews-Bot
X-Exp-Id
X-Kinja-Revision
X-Kinja-Server
X-Exp-Variant
X-Ac
SPIisLatency
SPRequestDuration
X-Ruxit-Js-Agent
AR-PoweredBy
AR-ATIME
AR-SID
AR-Request-ID
X-NWS-LOG-UUID
X-B3-TraceId
SPRequestGuid
X-SharePointHealthScore
X-RateLimit-Remaining
X-Ser
X-Abt-Application-Version
X-Navigation-Version
X-NF-Request-ID
X-GitHub-Request-Id
X-Vcap-Request-Id
X-Dw-Request-Base-Id
AR-CACHE
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-Mg-S
X-VARITI-CCR
S
X-Client-IP
Pagespeed
X-Sol
Accept-Ch
X-Middleton-Display
Display
Edge-Cache-Tag
X-Cache-Key
X-Ttl
RTSS
Fastly-Restarts
X-Amzn-Trace-Id
X-Amz-Rid
X-Cache-TTL
X-Powered-CMS
Cache-Status
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Edge-Location-Klb
X-Kinsta-Cache
X-Goog-Hash
X-Version
Access-Control-Request-Method
X-Server-ID
X-Recruiting
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-Varnish-TTL
X-ARC
Response
X-Middleton-Response
X-Webkit-Csp
X-Content-Digest
X-TraceId
X-Forwarded-For
X-T
Arr-Disable-Session-Affinity
Origin-Trial
X-Daa-Tunnel
X-MSEdge-Ref
Content-MD5
X-Ua-Device
X-SRCache-Store-Status
X-SRCache-Fetch-Status
TP-Cache
MicrosoftSharePointTeamServices
X-Accel-Expires
Front-End-Https
X-Shield-Request-Id
X-Content-Security-Policy-Report-Only
Cross-Origin-Resource-Policy
X-Cached
X-Hits
MS-Author-Via
Public-Key-Pins
X-Id
X-FTR-Cache-Status
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Backend
X-Country-Code-Real
X-Fastcgi-Cache
X-HS-Cache-Config
X-HS-Combine-CSS
X-FTR-Expires
X-HS-Content-Id
X-Ua-Browser
Server-Node
X-HS-Hub-Id
X-Forwarded-Proto
X-Request-Processing-Time
X-Request-Received
X-DIS-Request-ID
Payment
X-Frontend
X-ORACLE-DMS-RID
X-LLID
Realpath
X-HP-Webp
X-HP-Trace-Id
X-Jurisdiction
X-Protected-By
X-RateLimit-Limit
TP-L2-Cache
X-GUploader-UploadID
X-Distributor
X-FastCGI-Cache
Cache-Tags
X-LB-Cache
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Origin-Server
X-Microsite
X-Request-Handler-Origin-Region
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Referer-Policy
Mrf-Cache-Status
X-Hostname
X-Page-Id
X-B3-TraceId-Primal
MRF-Tech
X-AppVersion
X-Az
X-XRDS-LOCATION
X-Debug-Info
X-Activity-Id
Count-Hit
X-NGENIX-Cache
X-Cluster-Name
X-Www-Served-By
Host
X-Varnish-Backend
X-Varnish-Server
Fastcgi-Cache
X-Envoy-Decorator-Operation
X-F-Cache
Accept-Charset
X-App-Server
X-Geo-Country
X-Ratelimit-Limit
X-ORACLE-DMS-ECID
X-PressLabs-Stats
X-Correlation-Id
X-TTL
X-FB-Debug
X-Goog-Metageneration
Retry-After
X-Upgrade-Enabled
X-Ezoic-Cdn
X-RateLimit-Reset
Access-Control-Allow-Method
X-CSRF-Token
X-Git-Hash
X-Load-Cache
X-Fastly-Request-Id
X-Content-Options
X-Seen-By
X-Varnish-Ttl
X-Px
Server-Name
X-Request-Guid
X-Contextid
Section-Io-Cache
X-Revision
X-Datadog-Trace-Id
X-Cache-Control
X-Amz-Meta-S3cmd-Attrs
X-Datadog-Parent-Id
X-Grace
X-Datadog-Sampling-Priority
X-Type
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Trace-Id
X-B
Charset
Cleartype
X-TT
Paypal-Debug-Id
X-B3-Sampled
Healthy
X-TEC-API-ROOT
X-TEC-API-VERSION
DC
X-TEC-API-ORIGIN
X-Whom
X-Fb-Rlafr
X-Signature
X-B-Cache
X-Wix-Request-Id
TCN
X-Newrelic-App-Data
X-App-Environment
X-Node-Name
X-Origin-Cache
X-Mobile
Frame-Options
X-Proxy
X-Amz-Replication-Status
X-Azure-Ref
X-Magnolia-Registration
X-Oracle-Dms-Ecid
X-WebKit-CSP-Report-Only
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Fastly-Request-ID
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-N
X-EdgeConnect-Cache-Status
Filterid
X-Logged-In
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Air-Pt
X-Language
X-Rid
X-Is-Crawler
X-Providence-Cookie
X-Aspnet-Duration-Ms
X-Route-Name
X-Flags
X-Kinja-CCPA
Content-Disposition
Akamai-GRN
X-Oracle-Dms-Rid
Backend
NGB
X-Template
X-Response-Served-From
VIX-Pulpo-Upstream-Status
X-Original-Request-Id
VIX-Pulpo-Node
X-Time
X-Is-Bot
X-Rendered-As
X-Debug-IsPreview
X-Datadog-Sampled
X-Debug-IsConnected
X-RTag
X-Tumblr-User
X-Tumblr-Pixel-1
Upgrade-Insecure-Requests
X-Unique-Id
X-Tumblr-Pixel
Liferay-Portal
X-Varnish-Grace
X-Yottaa-Metrics
Ms-Operation-Id
SD-X-WS
Viewport
X-Servername
X-Cache-Age
X-Ratelimit-Remaining
X-ProcessESI
X-RemovedCookies
X-Tumblr-Pixel-0
X-Yottaa-Optimizations
MS-CV
X-FW-Server
X-Amzn-Remapped-Content-Length
X-FW-Static
X-Adobe-Loc
X-Adobe-Content
X-Debug
Refresh
X-FW-Hash
X-FW-Dynamic
X-FW-Serve
X-Proxy-Cache-Info
X-Instance
X-UUID
X-NYM-Debug-Backend
X-FW-Version
X-FW-Type
X-IPS-LoggedIn
X-Cache-Grace
X-G
X-Cacheable-TTL
X-App-Version
X-Hl-Ver
X-Environment-Context
Fastly-SIE
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-Backend-Name
X-L-Path
X-Region
Fastly-SWR
X-Device-Type
X-User-Agent
From-Origin
X-Via-JSL
Country
X-Cache-Hit
X-Status
X-Rule
ServerID
X-B3-SpanId
Url
X-VC-Cache
X-Webkit-CSP
X-INCAP-ABP
X-Jobs
Countrycode
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
WPO-Cache-Status
Alternate-Protocol
Version
WPO-Cache-Message
X-Source
X-Cache-Status-Check
X-HTML-Minification-Powered-By
X-Air-Trace-Id
X-Origin-TTL
X-NODE
X-Air-Source
X-Origin-CC
X-Air-Hostname
X-Akamai-Request-ID2
GEO-INFO
X-Page-View
Surrogate-Key
X-Nginx-Cache
X-Content-Powered-By
X-Hosted-By
X-WP-CF-Super-Cache-Active
X-Storage
X-B3-Traceid
SRV
X-Rocket-Nginx-Serving-Static
AMP-Access-Control-Allow-Source-Origin
Protected
X-Accel-Version
OT-Force-Account-Verify
CDN-RequestId
X-Akamai-Edgescape
X-Real-IP
Access-Control-Request-Headers
X-VC
X-Edge-Location
X-CDN-Forward
Amp-Access-Control-Allow-Source-Origin
X-Framework
CF-IPCountry
X-ServerID
X-Use-Mantle
X-Mode
X-Cache-Time
Front
X-Cache-Rule
Webserver
X-Rn-Rsrv
Filters
Accept-Language
Xet-Cookie
Meta-Geo
X-Rewrite-Enabled
X-Xfnlog-Site
X-Upstream-Ht
X-UPSTREAM-Address
X-Cache-Operation
X-Http-Reason
X-Upstream-Ct
Selected-Fe
Mn-Server-Ip
Section-Io-Id
X-AWS-Id
X-Director
X-Cache-Debug
X-Detected-As
ServedBy
X-Endurance-Cache-Level
X-Handled-By
X-LJ-Flow-ID
X-Proxy-Build
X-JoinUs
Cross-Origin-Embedder-Policy
X-Origin
X-VWS-Id
X-Tumblr-Pixel-3
X-Served-From
X-Tumblr-Pixel-2
X-SaId
X-Soup
X-Varnish-Cache-Hits
X-Timing-Wait
Apigw-Requestid
X-BYPASS-REASON
X-Cluster
X-ProxyCache-Status
X-Extlb
X-Httpd
X-Cms-Context
X-Web-Node
Webcakes-Region
Xserver
TWC-GeoIP-LatLong
Node
TWC-GeoIP-Country
TWC-Device-Class
Property-Id
TWC-Locale-Group
X-Zipkin-Id
Webcakes-App-Name
Webcakes-App-Version
X-Worker
Web-Mar-Node
TWC-Privacy
X-Adobe-Source
X-Format
X-No-Session
X-Routing-Service
TWC-Connection-Speed
X-Logging-Id
X-Labrador-Cache-Channel
X-Lambda-Id
X-Say-Cacheable
X-Say-TTL
X-SayCDN-TTL
X-Restarts
X-Origin-Hint
X-PHP-Host
X-ProxyCache-Key
X-Proxied
X-Redis-Cache
X-S
X-Platform-Router
X-Loop
X-Platform-Processor
X-RCS-CacheZone
X-Drupal-Cache-Tags
X-RM-Cache-TTL
X-Platform-Cluster
X-Browser-Name
X-Tcp-Rtt
X-IPLB-Request-ID
X-Is-Desktop
X-IPLB-Instance
X-GeoCountry
X-Skip-Cache
X-Forwarded-Host
X-GeoCode
X-Tncms
X-Is-Mobile
X-Varnish-Beresp-Grace
X-Geo-Region
X-Locale
X-Varnish-Age
X-Site-Version
X-Is-Supported-Browser
X-Is-Tablet
X-AB
X-VCT
DB-Nickname
Azure-SiteName
Azure-SlotName
Azure-Version
Azure-RegionName
Azure-InstanceId
X-Cache-Server
X-Container-Uri
X-Fetched-On
X-Generation-Time
X-Vercel-Cache
X-Reqid
X-Server-W
X-Webstats-RespID
X-R9-Blue-Green-Version
X-Tb
X-Drupal-Cache-Contexts
X-Git-Commit
X-Cache-Host
X-Vercel-Id
X-Ms-Request-Id
X-Frame-Option
X-Provided-By
X-Ms-Version
CDN-PullZone
CDN-EdgeStorageId
CDN-RequestCountryCode
CDN-RequestPullSuccess
X-MP-GENERATED-AT
CDN-CachedAt
CDN-Cache
X-Storefront-Renderer-Rendered
X-Uri
CDN-Uid
X-Alternate-Cache-Key
X-Shopify-Stage
CDN-RequestPullCode
X-Vcache
X-Origin-Date
X-TT-LOGID
WP-Super-Cache
X-Sucuri-Cache
X-XRDS-Location
X-DynaTrace
X-ShopId
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-ShardId
Source
Cache-Tv-Group
Fastcgi-Useragent
X-Sucuri-ID
X-Vcl-Version
Cross-Origin-Embedder-Policy-Report-Only
X-Cdn-Origin
X-FB-TRIP-ID
Content-Secure-Policy
X-Sql-Duration-Ms
X-Sql-Count
X-Generated-By
Sid
Priority
Onion-Location
Atl-Traceid
X-Urbn-Site-Id
X-Pass-Why
X-Urbn-Context-Path
X-SRV
Locale
X-Content-Age
X-Buckets
X-Thinkindot-L3
X-Scope-Id
TDXMobile
X-Shield-Cache-Expires
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Thinkindot-Control
X-CMSURLCustom
X-Newrelic-Synthetics
Cross-Origin-Window-Policy
X-Correlation-ID
Cache
HostName
WZWS-RAY
X-LSADC-Cache
X-Cluster-Node
X-DataDome
X-Varnish-Beresp-Ttl
X-Proxy-Cache-Status
S-Rt
X-Xrds-Location
X-Cache-Action
X-WP-CF-Super-Cache-Cookies-Bypass
X-Optimistic-Header
X-Via-SSL
X-Via-CDN
Edge-Copy-Time
X-Via-Edge
X-Cache-Expired-At
X-Dc
X-TA-CDN-Provider
User-Cache-Control
X-Connection-Hash
Expiry
Vix-Hermes-Req-Id
X-A-Wwc
Gannett-Cam-Experience-Id
X-Viewer-Country
X-Ec-Fail
X-Ec-GeoHdr
X-Access
X-Op-Id-All
Magicmarker
X-Platform
MD5-Digest
Meta-Geo-Continent
X-PAYTM-SRV-ID
Lang
X-A-Dgt
X-Ec-Custom-Error
X-Instance-Name
L
X-Aed
DCR-Decision-By
Apple-News-Services-Handled
CDCHOST
X-A-Ccd
A
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
X-A
Candidate-Md5Url
Apple-News-Services-Request-Url
X-Vtex-Remote-Cache
X-A-Dam
X-GEO
X-Vdms-Version
X-Epic-Correlation-Id
X-Dispatcher-Server
X-Vdms-Path
X-External-Request-Id
X-A-Dcw
X-Varnish-Hostname
X-TIM-N
DCR-Processing-Time-Ms
X-Cache-NE
X-SRCache-Key
X-B-Cookie
Req-ID
X-Scheme
X-SB
X-S-Cookie
X-Rojux
Redirect-Candidate
Rendered-Blocks
X-ScT
X-Bc-Bl
Server-Host
Server-Hostname
X-D
X-Section
Server-Ext
Sever-Int
X-Ua
X-BCube-Filmed-By
Sslversion
X-Application
X-Developer
X-Destination
X-Bl-Debug
Origin-Agent-Cluster
Origin
Surrogated-Key
Ngx.Var.Host
X-Request-Start
X-Cache-Bucket
Ngx-Var-Key
T-Server
X-Conf
X-VCache
X-TimeS
X-Datadome
Wxu-Next-Hostname
X-Varnish-Director
X-VG-WebCache
Cdnsip
X-Varnish-Beresp-Status
NM-Fastcgi-Cache
X-VG-TLSProxy
Wxu-Next-Region
Wxu-Next-Commit
Cdncip
Cluster
Environment
DSUID
Release
X-Debug-Cache-Store
V-Age
Fastly-GeoIP-CountryCode
Pramga
Ssr
X-Esi-Check
X-Core-Value
Fastly-SSL
Req-Svc-Chain
X-Debug-Cache-Fetch
Host-ID
Type
Content-Style-Type
Content-Script-Type
X-Fastly-Cache
X-Moov-Xdn-Version
X-Varnishpool
X-Pool
X-Proxied-Request
X-Pubstack
X-Req
X-Block-Status
X-Mly-Id
X-Cache-Id
X-AK-Request-ID
X-Hnp-Log
Cache-Provider
X-Amz-Meta-Cb-Modifiedtime
X-Cache-Info
X-Origin-Time
X-Request-Time
X-Level-Front-Cache
X-SD-PageType
X-Sigma-Backend
X-Sigma
X-UA-Device-Type
X-Bip
X-Thanos
X-BBC-Edge-Cache-Status
X-B3-Trace-ID
X-Rocket-Build-Number
X-Request-URI
X-Loc
X-TH-Server
X-Clientip
X-Auto-Login
X-Gzip
X-Human
X-NMSegId
X-Nginx-Cache-Key
X-Gdpr
X-Zen-Fury
X-Node-Id
X-Gen-Mode
X-NCache
X-Azure-Ref-OriginShield
X-VServer
C-Via
X-Forwarded-Site
X-Moov-T
X-We-Are-Hiring
X-WA-Info
Yak-Timeinfo
X-Generated-On
X-GeoIP-Region-Code
X-Acquia-Purge-Cdn-Unconfigured
X-Cache-TTL-Remaining
X-GeoIP-Country-Code
X-Nyt-Route
X-ND-Cache
X-Service
Fastly-Drupal-HTML
X-Origin-Response-Time
Uber-Trace-Id
We-Hiring
X-Ad-Load-Variation
Web-Mar-Region
Tube-Got-Results
Tube-Return
W
Tube-Got-Eval
X-Aicache-OS
X-Contensis-Viewer-Groups
X-Csrf-Jwt
X-Cache-Date
X-Cache-Aspx
X-Branch-Name
Tube-Get-Contents
X-ApacheServer
True-Client-Country-4JS
X-CGP
X-Geo-Header
X-V-Cache
X-HS-Content-Campaign-Id
X-SVT-ORM-VERSION
X-Men
X-Micro-Cache
X-SVT-ORM-RULES
X-VarnishDD-TTL
X-GoCache-CacheStatus
X-Amz-Storage-Class
PFcat
RNT-Time
X-GeoIP-City
X-HN
X-Cdn-Srv
X-Server-IP
X-Org
X-PERF
X-Old-Content-Length
X-Mvc-Supplant-OutputCached
X-Mvc-Supplant-Cachable
X-Policy
X-Mg-Request-UUID
X-Region-Sid
X-Request-Host
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-ECache
X-From
X-GeoIP
Mail-Subject
Gh-Request-Id
X-Var-Ttl
X-Device-Os
On-Server
Machine
Ha-Gx-Prefs
X-DPWN-IS-SECURE
Locid
L5d-Success-Class
Is-Eu
HA-Ipaddr
Esi-Enabled
Country-Code
Canary
X-FC-Vary-Parameters
X-Varnish-Authentication
X-Fmm-Version
Adler-Geo
Click-Count-Action-Start
RNT-Machine
X-Eu-Site
Platform
Producers
Click-Count-Error
X-Proto
X-Slack-Shared-Secret-Outcome
X-Fastly-Backend
X-Hash
X-Test
X-Edge-Server
X-Slack-Backend
X-Sn-Servicetimems
X-Up
X-Backend-Instance
Proxy-Firewall
Cdn-Request-Time
Cf-Device-Type
X-RID
Cdn-Host
X-App-Name
Cache-Key
X-Wikidot-Backend
X-Wikidot-Static-Cache
AKAMAI
X-LB-ID
Pics-Label
X-Irp-Debug
X-Ah-Environment
X-Parent-Response-Time
XM
Fastly-Backend-Name
X-CacheTTL
X-Date
X-Accel-Expires-Debug
LB
X-Lagoon
X-DC
X-COUNTRY
X-Owner
X-API-Version
X-Tx-Id
X-Varnish-Hits
X-Cache-Backend
NGX
X-Origin-Expires
X-UA
X-Tb-Optimization-Total-Bytes-Saved
X-DynaTrace-JS-Agent
X-CACHE-GROUP
X-SIPLIST1
X-Servedbyhost
X-ZONE
X-Via-Poph
Cdn-Requestid
X-HA-Backend
X-Core-Mission
X-Via-Popv
IsBot
X-Via-Popn
X-Ratelimit-Reset
X-Refresh
X-LB-NoCache
X-VHOST
Datacenter
Cdn
X-CDN-Cache-Status
RATING
X-Qloud-Router
NtCoent-Length
GeoIp-Country-Code
X-NGINX-Cache
X-Use-Magma
X-CF-Lambda-Version
X-CF-Lambda-Fn
Server-ID
Expect-Staple
N-Cache
X-Srv
X-Zone
X-Orig-Expires
Xc-Version
SID
X-Forwarded-Path
X-Via-Fastly
X-Shop-Environment
CloudFront-Viewer-Country
X-Cache-Type
X-Nc
Cache-Hits
X-Nananana
X-Wa
X-Tenant
X-TX-ID
Cmsid
X-Gamma-Serve
Cross-Origin-Opener-Policy-Report-Only
Cmstype
X-Akamai-Transformed
DataCenter
X-Fpc
GeoIP-Latitude
X-Hit
X-Location
CPC-Cache
X-B3-Parentspanid
CPC-Age
Resin-Trace
X-Ig-Origin-Region
Tcn
Fusion-Content-Source
Fusion-Content-Id
User-Agent
X-Proxy-CacheRZ
XkeyRZ
Fusion-Deployment-Id
X-Cdn-Diag
Fusion-Component-Id
X-Nf-Request-Id
Fusion-Source
X-Cloudmap
Uri
X-Vmg-Version
X-Tt-Logid
Fusion-Template-Id
X-Client-Ip
X-CS
X-Presslabs-Stats
Powered-By
X-URL
Origin-EX
Origin-CC
X-Info
True-Client-Ip
X-DataCenter
X-Amz-Meta-Opti
Mime-Version
X-Jungle-Id
X-TIME
X-CUA
Fastly-Drupal-Html
X-Geo
X-User
CacheControlHeader
X-Fastly-Country-Code
X-NWS-UUID-VERIFY
X-Variation
X-Datacenter
X-IAuth-Set-Uid
X-NewRelic-App-Data
X-HostName
X-LAGOON
True-Client-IP
CDN
X-Cached-By
X-CACHE-AGE
X-Segment-20210421
MIME-Version
X-AIR-PT
Srv
X-Dynatrace-Js-Agent
Cf-Ipcountry
X-Oracle-DMS-ECID
X-Render-Time
Load-Balancing
X-Cdn-Forward
X-B3-Spanid
X-LiteSpeed-Tag
X-Powered-By-VTEX-Cache
Debug
X-HOST
VNS-Cache
VNS-Age
X-VTEX-Cache-Time
X-VTEX-Cache-Server
X-Vc
X-LiteSpeed-Cache-Control
X-Varnish-Beresp-TTL
X-Wormhole-Sdk
Lb
Edge-Cache
X-Api-Version
Ohc-File-Size
X-Auth-Group-Type
X-Webkit-Csp-Report-Only
Cl-Cache
X-Dispatch
Hostname
X-CSRF-TOKEN
X-FPC
X-MCACHE
X-NC
X-Ig-Push-State
X-WA
X-Dispatcher-Number
Ohc-Cache-HIT
GeoIP-Country-Code
X-Esi
Server-Id
Odigeo-Trace-Id
Cache-Name
X-NodeID
X-APP-VERSION
X-Vgn-Hpd-Reason
X-Cs
X-Cdn-Cache-Status
X-Lb-Nocache
X-Custom-Header
X-Litespeed-Tag
X-Mid
X-PDP-UNCACHING-HASH
X-ServedByHost
X-Depends
X-PHP-Backend
X-Pad
X-Cache-Ttl
X-DefElseHash
X-DefHash
X-Varnish-CookieINHashed-On
X-Fastly-Backend-Reqs
X-Varnish-CookieHashed-On
X-Ha-Backend
X-Via-PopH
X-Via-PopV
X-Via-PopN
X-Varnish-Remaining-TTL
CountryCode
X-VCL-Version
X-Srcache-Store-Status
X-Srcache-Fetch-Status
Ms-Author-Via
X-Litespeed-Cache-Control
X-M-Log
PICS-Label
X-Lb-Id
X-M-Reqid
X-Cdn-Request-ID
X-VC-TTL
Xkey-La3
BehaviorPad-Version
X-Proxy-Cache-La3
Ngx
X-MSEdge-Flight
X-MSEdge-Features
Xkeylog
X-Akamai-Pragma-Client-IP
X-MiniProfiler-Ids
Geoip-Latitude
X-Web-Server
FSS-Cache
X-Snapshot-Date
OriginIP
X-Cache-Enabled
X-RequestId
X-IN-APIGATEWAY
X-Acquia-Application-UUID
Time
Memory
Memcached
X-Acquia-Purge-Tags
X-Acquia-Application-Trace
X-IN-APIGATEWAYSSL
X-Acquia-Site
X-Sorting-Hat-Podid
X-Sorting-Hat-Shopid
X-Cache-Version
X-Shopid
X-Shardid
Location
X-FL-QIT-DEBUG
Server-Info
X-APP
Warning
Srvid
Epwk-X-Cache
X-Cache-FS-Status
X-FL-EDGE
X-Requestid
X-Sucuri-Id
X-Dw-Trace-Id
Sm-Log-Id
X-Check-Cacheable
X-Serial
X-Service-Response-Time
X-Mg-Cache
X-Udemy-Cache-App-Namespace
CF-Cached-On
X-Lsadc-Cache
X-Th-Server
Akamai-Cache-Status
X-Wp-Cf-Super-Cache-Cookies-Bypass
YJS-ID