Threat Level: green Handler on Duty: Rick Wanner

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
Accept-Ranges
Expect-CT
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-Xss-Protection
X-UA-Compatible
P3P
X-Served-By
X-Request-Id
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
X-FRAME-OPTIONS
Access-Control-Allow-Credentials
X-AspNet-Version
Content-Security-Policy-Report-Only
X-Runtime
Accept-CH
P3p
X-DNS-Prefetch-Control
X-Cache-Status
Accept-CH-Lifetime
X-Drupal-Cache
X-Check
X-Ua-Compatible
X-Generator
Server-Timing
X-Cacheable
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Iinfo
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
X-Content-Security-Policy
Feature-Policy
Content-Encoding
X-CDN
Status
X-AspNetMvc-Version
Upgrade
X-Request-ID
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
X-Amz-Id-2
CF-Ray
Host-Header
Cf-Edge-Cache
X-Backend
Allow
Request-Context
Keep-Alive
X-UA-Device
X-Robots-Tag
X-Server
X-Cache-Group
X-Hacker
X-AH-Environment
X-Turbo-Charged-By
X-Ws-Request-Id
X-Proxy-Cache
X-Age
Xkey
X-Rq
EagleId
X-Vhost
X-Dispatcher
X-Server-Powered-By
X-Amz-Version-Id
X-Varnish-Cache
Grace
Cf-Apo-Via
X-Dns-Prefetch-Control
X-Page-Speed
X-Swift-SaveTime
X-Swift-CacheTime
X-Pingback
Cf-Railgun
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Ali-Swift-Global-Savetime
X-Device
EagleEye-TraceId
X-LiteSpeed-Cache
X-WebKit-CSP
X-Aws-Lambda-Call-Status
X-CST
X-OneAgent-JS-Injection
Permissions-Policy
X-Backend-Server
X-Server-Id
X-Readtime
X-Response-Time
X-Host
X-Akam-SW-Version
Request-Id
Surrogate-Control
X-Litespeed-Cache
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-HW
X-Cache-Lookup
X-Nginx-Upstream-Cache-Status
X-Cloud-Trace-Context
X-Node
X-Nginx-Cache-Status
X-Application-Context
X-Country-Code
Content-Location
X-Trace
X-Country
Service-Worker-Allowed
X-Ruxit-JS-Agent
X-Url
X-Content-Type
X-Clacks-Overhead
X-Oneagent-Js-Injection
X-Origin-Cache-Key
Accept-Ch-Lifetime
X-Edge
X-Rack-Cache
Cross-Origin-Opener-Policy
Cache-Tag
X-Amz-Server-Side-Encryption
X-FTR-Request-ID
X-Midtier
X-Mcache
X-Mod-Pagespeed
X-MS-InvokeApp
Nginx-Cache
X-TtlSet
X-PC
X-Vname
X-ECACHE
X-Upstream
X-Powered-By-Plesk
Rating
X-ESI
Edge-Control
X-Server-Name
X-Browser-Type
X-Cnection
X-D2id
X-Element-Page-Cache
Verso
X-Times
X-GoogleNews-Bot
X-Cdn-Fetch
X-Kinja-Revision
X-Kinja-Build
X-Exp-Id
X-Kinja
X-Exp-Variant
X-Kinja-Server
SPRequestDuration
SPIisLatency
X-Ac
X-Ruxit-Js-Agent
AR-SID
AR-PoweredBy
AR-Request-ID
AR-ATIME
X-NWS-LOG-UUID
X-B3-TraceId
SPRequestGuid
X-SharePointHealthScore
X-RateLimit-Remaining
X-Ser
X-Abt-Application-Version
X-Navigation-Version
X-NF-Request-ID
X-GitHub-Request-Id
X-Vcap-Request-Id
X-Dw-Request-Base-Id
AR-CACHE
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
X-Mg-S
X-VARITI-CCR
S
X-Client-IP
Display
Pagespeed
X-Middleton-Display
X-Sol
Edge-Cache-Tag
X-Cache-Key
X-Ttl
RTSS
Fastly-Restarts
X-Amzn-Trace-Id
X-Amz-Rid
X-Cache-TTL
X-Powered-CMS
Cache-Status
X-Erf-Bev-Bev
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Kinsta-Cache
X-Edge-Location-Klb
X-Goog-Hash
X-Version
Access-Control-Request-Method
X-Server-ID
X-Recruiting
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-Varnish-TTL
X-ARC
Response
X-Middleton-Response
X-Webkit-Csp
X-Content-Digest
X-TraceId
X-Forwarded-For
Arr-Disable-Session-Affinity
X-T
X-Daa-Tunnel
Content-MD5
Origin-Trial
X-MSEdge-Ref
TP-Cache
X-SRCache-Store-Status
X-SRCache-Fetch-Status
MicrosoftSharePointTeamServices
X-Accel-Expires
Front-End-Https
X-Shield-Request-Id
X-Content-Security-Policy-Report-Only
Cross-Origin-Resource-Policy
X-Cached
X-Hits
MS-Author-Via
Public-Key-Pins
X-Id
X-Country-Code-Real
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-Backend
X-HS-Content-Id
X-Ua-Browser
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Combine-CSS
Server-Node
X-FTR-Expires
X-Request-Received
X-Request-Processing-Time
X-Forwarded-Proto
X-DIS-Request-ID
Payment
X-Frontend
X-FastCGI-Cache
X-ORACLE-DMS-RID
X-LLID
Realpath
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-Fastcgi-Cache
X-Protected-By
TP-L2-Cache
X-RateLimit-Limit
X-GUploader-UploadID
X-Distributor
Cache-Tags
X-LB-Cache
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Origin-Server
X-Microsite
X-Request-Handler-Origin-Region
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Referer-Policy
Mrf-Cache-Status
X-Page-Id
MRF-Tech
X-B3-TraceId-Primal
X-XRDS-LOCATION
X-AppVersion
X-Activity-Id
Count-Hit
X-Az
X-Debug-Info
X-Cluster-Name
Host
X-NGENIX-Cache
X-Www-Served-By
Fastcgi-Cache
X-Varnish-Backend
X-Varnish-Server
X-Envoy-Decorator-Operation
X-Geo-Country
X-Correlation-Id
Accept-Charset
X-F-Cache
X-App-Server
X-Hostname
X-PressLabs-Stats
X-ORACLE-DMS-ECID
X-Ratelimit-Limit
X-Ua-Device
X-TTL
X-FB-Debug
X-Goog-Metageneration
Retry-After
X-RateLimit-Reset
X-Ezoic-Cdn
Access-Control-Allow-Method
X-Upgrade-Enabled
X-CSRF-Token
X-Git-Hash
X-Load-Cache
X-Fastly-Request-Id
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Content-Options
X-Varnish-Ttl
X-Seen-By
X-Px
Server-Name
X-Revision
X-Request-Guid
X-Contextid
Section-Io-Cache
X-Grace
X-Amz-Meta-S3cmd-Attrs
X-Datadog-Trace-Id
X-Cache-Control
X-Trace-Id
X-Type
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
Cleartype
Charset
X-B
X-B3-Sampled
X-TT
Paypal-Debug-Id
Healthy
DC
X-Whom
X-Signature
X-Fb-Rlafr
X-B-Cache
TCN
X-App-Environment
X-Wix-Request-Id
X-Node-Name
X-Origin-Cache
X-Mobile
Frame-Options
X-Proxy
Accept-Ch
X-Amz-Replication-Status
X-Azure-Ref
X-Magnolia-Registration
X-WebKit-CSP-Report-Only
X-Newrelic-App-Data
X-Oracle-Dms-Ecid
X-Goog-Storage-Class
X-Fastly-Request-ID
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-N
Filterid
X-EdgeConnect-Cache-Status
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Logged-In
X-Air-Pt
X-Language
X-Rid
X-Providence-Cookie
X-Route-Name
X-Aspnet-Duration-Ms
X-Flags
X-Is-Crawler
X-Kinja-CCPA
Content-Disposition
Akamai-GRN
Backend
X-Oracle-Dms-Rid
NGB
X-Time
VIX-Pulpo-Upstream-Status
X-Response-Served-From
X-Original-Request-Id
VIX-Pulpo-Node
X-Template
X-Is-Bot
X-Rendered-As
X-ProcessESI
X-Unique-Id
X-Yottaa-Metrics
Ms-Operation-Id
X-Debug-IsConnected
X-RemovedCookies
X-Debug-IsPreview
X-Varnish-Grace
X-Cache-Age
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-Yottaa-Optimizations
Viewport
X-Tumblr-Pixel-0
X-Ratelimit-Remaining
X-Datadog-Sampled
X-Servername
X-RTag
SD-X-WS
Upgrade-Insecure-Requests
X-Tumblr-User
MS-CV
Liferay-Portal
X-Proxy-Cache-Info
Refresh
X-FW-Hash
X-FW-Serve
X-NYM-Debug-Backend
X-FW-Version
X-FW-Dynamic
X-Adobe-Loc
X-Instance
X-Debug
X-Amzn-Remapped-Content-Length
X-IPS-LoggedIn
X-FW-Static
X-FW-Server
X-Adobe-Content
X-FW-Type
X-UUID
X-Cacheable-TTL
X-Cache-Grace
X-Environment-Context
Fastly-SIE
X-L-Path
X-Backend-Name
X-Hl-Ver
Fastly-SWR
X-G
X-Region
X-CCDN-Origin-Time
X-App-Version
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-Device-Type
From-Origin
X-Via-JSL
X-User-Agent
X-Status
X-Cache-Hit
ServerID
X-Rule
Country
X-B3-SpanId
Url
X-VC-Cache
X-Jobs
X-Webkit-CSP
X-INCAP-ABP
Countrycode
Alternate-Protocol
Version
WPO-Cache-Message
WPO-Cache-Status
X-HTML-Minification-Powered-By
X-Source
X-Cache-Status-Check
X-NODE
X-Air-Hostname
X-Origin-CC
X-Origin-TTL
X-Air-Trace-Id
X-Air-Source
GEO-INFO
X-Akamai-Request-ID2
X-Page-View
Surrogate-Key
CDN-RequestId
X-Hosted-By
X-Content-Powered-By
X-WP-CF-Super-Cache-Active
X-B3-Traceid
X-Storage
X-Rocket-Nginx-Serving-Static
AMP-Access-Control-Allow-Source-Origin
Protected
SRV
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
X-Nginx-Cache
X-Accel-Version
OT-Force-Account-Verify
X-Akamai-Edgescape
X-Real-IP
Access-Control-Request-Headers
X-VC
Amp-Access-Control-Allow-Source-Origin
X-Edge-Location
X-CDN-Forward
X-Framework
X-ServerID
X-Cache-Time
X-Cache-Rule
X-Use-Mantle
X-Mode
Front
Filters
X-Xfnlog-Site
Meta-Geo
X-Rewrite-Enabled
Accept-Language
X-Cache-Operation
Xet-Cookie
X-Rn-Rsrv
Webserver
X-Upstream-Ct
X-UPSTREAM-Address
X-Upstream-Ht
X-Http-Reason
X-Varnish-Cache-Hits
X-Handled-By
X-Endurance-Cache-Level
X-Timing-Wait
X-Proxy-Build
X-LJ-Flow-ID
Section-Io-Id
X-Origin
CF-IPCountry
X-Cache-Debug
X-Detected-As
Selected-Fe
ServedBy
X-JoinUs
X-VWS-Id
X-Tumblr-Pixel-3
Cross-Origin-Embedder-Policy
X-Tumblr-Pixel-2
X-AWS-Id
X-Soup
Mn-Server-Ip
X-Served-From
X-SaId
X-Director
Apigw-Requestid
X-Labrador-Cache-Channel
X-PHP-Host
Property-Id
X-Format
X-Origin-Hint
Node
X-Logging-Id
X-No-Session
X-Extlb
X-Proxied
X-Lambda-Id
X-Redis-Cache
X-SayCDN-TTL
X-Web-Node
X-Worker
X-ProxyCache-Key
X-Say-Cacheable
Webcakes-App-Version
Webcakes-Region
X-BYPASS-REASON
X-Cluster
X-Httpd
X-Adobe-Source
X-Cms-Context
Webcakes-App-Name
X-Say-TTL
Web-Mar-Node
X-ProxyCache-Status
TWC-GeoIP-Country
TWC-Device-Class
TWC-Connection-Speed
TWC-Locale-Group
TWC-GeoIP-LatLong
Xserver
X-Zipkin-Id
X-Restarts
X-Routing-Service
TWC-Privacy
Azure-Version
X-Forwarded-Host
X-Geo-Region
X-AB
Azure-SlotName
DB-Nickname
X-Browser-Name
X-Locale
X-RCS-CacheZone
X-Tncms
X-Platform-Cluster
Azure-SiteName
X-Varnish-Beresp-Grace
X-Loop
X-Drupal-Cache-Tags
X-RM-Cache-TTL
X-Site-Version
X-Skip-Cache
X-Tcp-Rtt
X-S
X-TT-LOGID
X-Platform-Processor
X-Is-Tablet
X-IPLB-Instance
X-Varnish-Age
X-VCT
X-GeoCountry
X-GeoCode
Azure-InstanceId
X-Platform-Router
X-Is-Mobile
X-Is-Supported-Browser
Azure-RegionName
X-Is-Desktop
X-IPLB-Request-ID
X-Cache-Server
X-Vercel-Id
X-Vercel-Cache
X-Tb
X-Container-Uri
X-Git-Commit
X-Generation-Time
X-Fetched-On
X-R9-Blue-Green-Version
X-Reqid
X-Webstats-RespID
X-Server-W
X-Drupal-Cache-Contexts
X-Cache-Host
X-Frame-Option
X-Provided-By
X-Ms-Version
X-Ms-Request-Id
CDN-EdgeStorageId
CDN-CachedAt
CDN-PullZone
CDN-RequestCountryCode
CDN-RequestPullCode
CDN-Cache
X-Storefront-Renderer-Rendered
X-Vcache
X-Uri
X-MP-GENERATED-AT
X-Alternate-Cache-Key
X-Shopify-Stage
CDN-RequestPullSuccess
CDN-Uid
X-Origin-Date
X-Sucuri-Cache
WP-Super-Cache
X-DynaTrace
X-XRDS-Location
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-ShardId
X-ShopId
Fastcgi-Useragent
Source
Cache-Tv-Group
X-Sucuri-ID
X-Vcl-Version
X-Cdn-Origin
Cross-Origin-Embedder-Policy-Report-Only
Content-Secure-Policy
X-FB-TRIP-ID
X-Sql-Count
X-Sql-Duration-Ms
X-Generated-By
Priority
Sid
Atl-Traceid
Onion-Location
X-Urbn-Site-Id
X-Urbn-Context-Path
X-Pass-Why
X-SRV
Locale
X-Content-Age
X-Buckets
Thinkindot-CacheControl-Type
Thinkindot-Control
X-CMSURLCustom
X-Shield-Cache-Expires
Thinkindot-CacheControl
X-Scope-Id
X-Thinkindot-L3
TDXMobile
Cross-Origin-Window-Policy
Cache
HostName
X-LSADC-Cache
WZWS-RAY
X-Cluster-Node
X-Newrelic-Synthetics
X-DataDome
X-Proxy-Cache-Status
X-Xrds-Location
S-Rt
X-Cache-Action
X-WP-CF-Super-Cache-Cookies-Bypass
X-Optimistic-Header
X-Via-SSL
X-Via-CDN
Edge-Copy-Time
X-Varnish-Beresp-Ttl
X-Via-Edge
X-GEO
X-Dc
X-Cache-Expired-At
Expiry
User-Cache-Control
X-Connection-Hash
DCR-Processing-Time-Ms
DCR-Decision-By
Sslversion
X-Access
X-Aed
X-Developer
X-Application
X-Instance-Name
X-B-Cookie
Gannett-Cam-Experience-Id
X-Platform
X-Varnish-Hostname
X-D
Server-Hostname
X-Destination
Sever-Int
X-Bc-Bl
X-BCube-Filmed-By
X-A-Wwc
X-A-Dcw
Apple-News-Services-Handled
Candidate-Md5Url
CDCHOST
A
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
X-Vdms-Version
X-Vtex-Remote-Cache
Apple-News-Services-Request-Url
Vix-Hermes-Req-Id
X-Ec-Custom-Error
X-Op-Id-All
Surrogated-Key
X-A-Dam
Server-Host
X-Ec-GeoHdr
T-Server
X-A
X-A-Ccd
X-Dispatcher-Server
X-A-Dgt
X-PAYTM-SRV-ID
X-External-Request-Id
X-SRCache-Key
Meta-Geo-Continent
X-S-Cookie
X-Ec-Fail
MD5-Digest
Rendered-Blocks
Magicmarker
Redirect-Candidate
X-Rojux
X-Vdms-Path
X-Ua
Ngx.Var.Host
X-ScT
X-TIM-N
X-Section
X-Cache-NE
X-Scheme
Origin-Agent-Cluster
X-SB
Ngx-Var-Key
X-Bl-Debug
X-Cache-Bucket
X-Viewer-Country
X-Conf
X-Correlation-ID
X-Epic-Correlation-Id
L
X-Request-Start
Server-Ext
Lang
Req-ID
Origin
X-Datadome
X-TA-CDN-Provider
X-VCache
X-TimeS
Cdncip
Req-Svc-Chain
Pramga
X-VServer
X-Forwarded-Site
NM-Fastcgi-Cache
X-VG-TLSProxy
X-Generated-On
X-Gen-Mode
Host-ID
V-Age
Type
Environment
X-Varnish-Director
Content-Style-Type
DSUID
Ssr
Release
X-GeoIP-Country-Code
Content-Script-Type
X-GeoIP-Region-Code
Fastly-SSL
X-VG-WebCache
Cdnsip
X-Gzip
Cluster
X-Varnish-Beresp-Status
Fastly-GeoIP-CountryCode
X-Gdpr
X-Hnp-Log
X-Req
X-Clientip
X-Esi-Check
X-Request-Time
X-TH-Server
X-Core-Value
X-Pubstack
X-Debug-Cache-Store
X-BBC-Edge-Cache-Status
X-Debug-Cache-Fetch
X-Pool
X-Proxied-Request
X-Bip
X-Request-URI
X-Sigma-Backend
X-Cache-Info
X-Sigma
X-Cache-TTL-Remaining
X-Varnishpool
X-Cache-Id
X-Moov-Xdn-Version
X-Thanos
X-Rocket-Build-Number
X-Block-Status
X-Mly-Id
X-Moov-T
X-B3-Trace-ID
X-Origin-Time
X-Nginx-Cache-Key
X-NCache
X-NMSegId
X-Node-Id
X-Nyt-Route
X-Azure-Ref-OriginShield
Wxu-Next-Region
Wxu-Next-Commit
C-Via
Wxu-Next-Hostname
X-WA-Info
X-We-Are-Hiring
X-Zen-Fury
X-SD-PageType
X-Auto-Login
X-Amz-Meta-Cb-Modifiedtime
X-Level-Front-Cache
X-Loc
X-Fastly-Cache
X-AK-Request-ID
X-ND-Cache
Yak-Timeinfo
X-UA-Device-Type
X-Acquia-Purge-Cdn-Unconfigured
X-Human
Cache-Provider
X-Origin-Response-Time
Fastly-Drupal-HTML
X-Service
X-Amz-Storage-Class
PFcat
X-HS-Content-Campaign-Id
X-RateLimit-Limit-Second
X-Ad-Load-Variation
On-Server
X-RateLimit-Remaining-Second
X-Contensis-Viewer-Groups
X-Server-IP
We-Hiring
W
X-Mvc-Supplant-Cachable
Web-Mar-Region
X-Csrf-Jwt
X-ECache
Adler-Geo
X-HN
X-Aicache-OS
X-Mvc-Supplant-OutputCached
X-V-Cache
X-Eu-Site
X-SVT-ORM-VERSION
X-Branch-Name
X-SVT-ORM-RULES
X-Cache-Aspx
X-Micro-Cache
X-Cdn-Srv
X-ApacheServer
X-Region-Sid
X-CGP
X-Request-Host
X-Var-Ttl
X-Men
X-VarnishDD-TTL
Canary
X-Policy
Is-Eu
L5d-Success-Class
Locid
HA-Ipaddr
RNT-Machine
Gh-Request-Id
Ha-Gx-Prefs
RNT-Time
Machine
Mail-Subject
X-Old-Content-Length
X-DPWN-IS-SECURE
X-Varnish-Authentication
Platform
X-From
X-Device-Os
Producers
X-Geo-Header
X-Fmm-Version
Tube-Got-Results
Tube-Got-Eval
Tube-Get-Contents
Tube-Return
X-Mg-Request-UUID
X-PERF
X-FC-Vary-Parameters
Uber-Trace-Id
X-Cache-Date
Click-Count-Action-Start
Esi-Enabled
X-GeoIP
X-Org
X-GeoIP-City
Country-Code
X-GoCache-CacheStatus
True-Client-Country-4JS
Click-Count-Error
X-Fastly-Backend
X-Proto
X-Edge-Server
X-RID
X-Backend-Instance
AKAMAI
X-Wikidot-Backend
X-Slack-Backend
Cache-Key
Cdn-Host
Proxy-Firewall
Cf-Device-Type
Cdn-Request-Time
X-Hash
X-Wikidot-Static-Cache
X-Slack-Shared-Secret-Outcome
X-Test
X-Sn-Servicetimems
X-Up
X-App-Name
X-Ah-Environment
Fastly-Backend-Name
NGX
XM
Pics-Label
X-Date
X-Parent-Response-Time
X-LB-ID
X-Irp-Debug
X-CacheTTL
X-Accel-Expires-Debug
X-Lagoon
LB
X-Owner
X-Tx-Id
X-Cache-Backend
X-API-Version
X-Origin-Expires
X-DC
X-Varnish-Hits
X-COUNTRY
X-UA
X-NGINX-Cache
X-ZONE
X-SIPLIST1
X-HA-Backend
X-Core-Mission
X-Servedbyhost
IsBot
X-Via-Poph
X-Tb-Optimization-Total-Bytes-Saved
X-Via-Popn
X-DynaTrace-JS-Agent
X-Via-Popv
X-CACHE-GROUP
X-Ratelimit-Reset
X-Refresh
X-VHOST
Datacenter
Cdn
X-LB-NoCache
RATING
NtCoent-Length
X-Qloud-Router
X-CDN-Cache-Status
GeoIp-Country-Code
X-Use-Magma
Cdn-Requestid
X-Srv
Expect-Staple
N-Cache
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-Zone
X-Via-Fastly
X-Nc
SID
X-Tenant
X-Cache-Type
X-Orig-Expires
X-Forwarded-Path
X-Wa
X-Nananana
X-Shop-Environment
Server-ID
Cache-Hits
Xc-Version
CloudFront-Viewer-Country
X-Gamma-Serve
Cmsid
Cross-Origin-Opener-Policy-Report-Only
Cmstype
X-TX-ID
X-Akamai-Transformed
X-Location
X-Ig-Origin-Region
GeoIP-Latitude
X-Fpc
Resin-Trace
CPC-Cache
CPC-Age
X-Hit
DataCenter
X-B3-Parentspanid
Tcn
Fusion-Deployment-Id
Fusion-Content-Source
X-Cloudmap
Fusion-Content-Id
X-Vmg-Version
XkeyRZ
X-Cdn-Diag
User-Agent
Fusion-Component-Id
X-Proxy-CacheRZ
Fusion-Source
Uri
X-Nf-Request-Id
X-NewRelic-App-Data
Fusion-Template-Id
X-HostName
X-Client-Ip
X-CS
X-URL
Powered-By
X-Presslabs-Stats
X-Jungle-Id
X-Amz-Meta-Opti
X-Tt-Logid
Origin-EX
Mime-Version
X-DataCenter
X-CUA
Origin-CC
X-TIME
X-Info
Fastly-Drupal-Html
CacheControlHeader
True-Client-Ip
X-Datacenter
X-Fastly-Country-Code
X-User
True-Client-IP
X-IAuth-Set-Uid
X-Esi
X-NWS-UUID-VERIFY
Cf-Ipcountry
X-Variation
X-LAGOON
X-CACHE-AGE
X-Segment-20210421
MIME-Version
X-Geo
CDN
X-Cached-By
X-AIR-PT
Srv
X-Dynatrace-Js-Agent
X-Oracle-DMS-ECID
X-Varnish-Beresp-TTL
Load-Balancing
X-Render-Time
X-B3-Spanid
X-Cdn-Forward
X-HOST
X-Powered-By-VTEX-Cache
VNS-Cache
X-VTEX-Cache-Server
X-Vc
X-VTEX-Cache-Time
X-LiteSpeed-Tag
VNS-Age
Debug
X-LiteSpeed-Cache-Control
X-Api-Version
Lb
Edge-Cache
X-Auth-Group-Type
Ohc-File-Size
X-Wormhole-Sdk
X-Webkit-Csp-Report-Only
Hostname
X-Dispatch
Cl-Cache
X-FPC
X-CSRF-TOKEN
X-Ig-Push-State
X-Dispatcher-Number
Server-Id
X-MCACHE
X-WA
X-NC
Ohc-Cache-HIT
X-Lb-Nocache
X-NodeID
GeoIP-Country-Code
Odigeo-Trace-Id
Cache-Name
X-Vgn-Hpd-Reason
X-APP-VERSION
X-Cs
X-Cdn-Cache-Status
X-Custom-Header
X-Litespeed-Tag
X-PHP-Backend
X-Mid
X-Depends
X-ServedByHost
X-PDP-UNCACHING-HASH
X-Pad
X-Cache-Ttl
X-Fastly-Backend-Reqs
CountryCode
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-DefElseHash
X-Varnish-Remaining-TTL
X-DefHash
X-Via-PopN
X-Via-PopV
X-Ha-Backend
X-Via-PopH
X-VCL-Version
Ms-Author-Via
X-Litespeed-Cache-Control
X-Srcache-Store-Status
X-Srcache-Fetch-Status
X-Lb-Id
X-VC-TTL
X-Cdn-Request-ID
PICS-Label
X-M-Log
X-M-Reqid
Xkeylog
Xkey-La3
X-Proxy-Cache-La3
X-MSEdge-Flight
X-MSEdge-Features
BehaviorPad-Version
X-Akamai-Pragma-Client-IP
X-MiniProfiler-Ids
FSS-Cache
Geoip-Latitude
X-Web-Server
X-Snapshot-Date
OriginIP
X-Cache-Enabled
Ngx
X-RequestId
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-IN-APIGATEWAY
Memory
Memcached
X-Acquia-Purge-Tags
Time
X-Acquia-Site
X-IN-APIGATEWAYSSL
X-Shopid
X-Sorting-Hat-Podid
X-Cache-Version
X-Sorting-Hat-Shopid
X-Shardid
Warning
Cloudfront-Viewer-Country
Location
X-FL-EDGE
Server-Info
X-APP
X-Cache-FS-Status
Srvid
X-FL-QIT-DEBUG
Epwk-X-Cache
X-Requestid
X-Sucuri-Id
X-Dw-Trace-Id
Sm-Log-Id
X-Check-Cacheable
X-Serial
X-Service-Response-Time
X-Mg-Cache
X-Udemy-Cache-App-Namespace
CF-Cached-On
X-Lsadc-Cache
X-Th-Server
Akamai-Cache-Status
X-Wp-Cf-Super-Cache-Cookies-Bypass
YJS-ID