Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
CF-RAY
ETag
X-XSS-Protection
Accept-Ranges
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
X-AspNet-Version
Content-Security-Policy-Report-Only
X-Runtime
Accept-CH
X-Drupal-Cache
X-Cache-Status
Accept-CH-Lifetime
X-DNS-Prefetch-Control
P3p
X-Generator
X-Check
X-Ua-Compatible
Server-Timing
X-Cacheable
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Iinfo
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
X-Content-Security-Policy
Feature-Policy
X-Request-ID
X-CDN
Content-Encoding
Status
X-AspNetMvc-Version
Upgrade
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
X-Amz-Id-2
Host-Header
CF-Ray
Cf-Edge-Cache
X-Backend
X-UA-Device
Keep-Alive
Request-Context
X-Robots-Tag
X-Server
X-Cache-Group
Allow
EagleId
X-Hacker
X-AH-Environment
X-Turbo-Charged-By
X-Ws-Request-Id
X-Proxy-Cache
Xkey
X-Age
X-Rq
X-Dns-Prefetch-Control
X-Vhost
X-Amz-Version-Id
X-Dispatcher
X-Server-Powered-By
X-Varnish-Cache
Grace
Cf-Apo-Via
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Page-Speed
X-Pingback
Permissions-Policy
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
Cf-Railgun
EagleEye-TraceId
X-OneAgent-JS-Injection
X-WebKit-CSP
X-Backend-Server
X-CST
X-Cache-Lookup
X-Host
X-Server-Id
X-Readtime
X-Aws-Lambda-Call-Status
X-Response-Time
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-HW
X-Nginx-Upstream-Cache-Status
Accept-Ch-Lifetime
X-Cloud-Trace-Context
X-Node
X-Litespeed-Cache
X-Nginx-Cache-Status
X-Application-Context
Content-Location
X-Country-Code
X-Country
X-Ruxit-JS-Agent
Service-Worker-Allowed
X-Trace
X-Url
X-Content-Type
X-Clacks-Overhead
X-Oneagent-Js-Injection
Rating
Cache-Tag
X-Rack-Cache
X-Amz-Server-Side-Encryption
X-FTR-Request-ID
Cross-Origin-Opener-Policy
Nginx-Cache
X-TtlSet
X-Vname
X-PC
X-Mcache
X-Edge
X-NWS-LOG-UUID
X-Midtier
X-Times
X-MS-InvokeApp
X-Origin-Cache-Key
X-Upstream
X-Mod-Pagespeed
X-Server-Name
X-ECACHE
X-Powered-By-Plesk
X-Browser-Type
Edge-Control
X-Cnection
X-D2id
X-Element-Page-Cache
X-Kinja-Build
X-Kinja-Revision
X-Exp-Id
X-Cdn-Fetch
X-GoogleNews-Bot
X-Kinja
X-ESI
X-Kinja-Server
X-Exp-Variant
Verso
X-Ser
AR-Request-ID
AR-SID
AR-ATIME
AR-PoweredBy
X-Ac
X-RateLimit-Remaining
SPIisLatency
SPRequestDuration
X-SharePointHealthScore
SPRequestGuid
X-GitHub-Request-Id
X-Ruxit-Js-Agent
X-B3-TraceId
X-NF-Request-ID
X-Abt-Application-Version
X-Navigation-Version
X-Dw-Request-Base-Id
X-Vcap-Request-Id
AR-CACHE
X-Mg-S
X-Client-IP
Pagespeed
Display
X-Middleton-Display
X-Sol
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
S
Edge-Cache-Tag
X-Ttl
X-Daa-Tunnel
X-Webkit-Csp
Fastly-Restarts
X-Cache-Key
X-Cache-TTL
X-VARITI-CCR
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Amz-Rid
X-Amzn-Trace-Id
Cache-Status
X-Powered-CMS
X-Edge-Location-Klb
RTSS
X-Kinsta-Cache
X-Version
Access-Control-Request-Method
X-Goog-Hash
X-Varnish-TTL
Response
X-Middleton-Response
X-Server-ID
X-Recruiting
X-FastCGI-Cache
X-Content-Digest
X-TraceId
X-ARC
X-Forwarded-For
X-T
X-MSEdge-Ref
Arr-Disable-Session-Affinity
Cross-Origin-Resource-Policy
MS-Author-Via
Content-MD5
MicrosoftSharePointTeamServices
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Front-End-Https
TP-Cache
X-Shield-Request-Id
X-RateLimit-Limit
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-Cache-Status
X-Country-Code-Real
X-FTR-Backend
X-Accel-Expires
X-Id
X-Forwarded-Proto
X-Hits
X-Cached
Realpath
X-HS-Combine-CSS
X-Request-Received
X-FTR-Expires
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
X-Request-Processing-Time
Public-Key-Pins
X-Ua-Browser
Server-Node
X-Frontend
X-Fastly-Request-ID
Payment
X-ORACLE-DMS-RID
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-Protected-By
X-LLID
X-HP-Trace-Id
X-HP-Webp
X-Jurisdiction
X-Content-Security-Policy-Report-Only
X-Distributor
X-DIS-Request-ID
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Correlation-Id
X-GUploader-UploadID
X-ORACLE-DMS-ECID
X-LB-Cache
TP-L2-Cache
X-XRDS-LOCATION
Cache-Tags
Fastcgi-Cache
X-Microsite
X-Request-Handler-Origin-Region
Count-Hit
Referer-Policy
X-AppVersion
X-Az
X-Amz-Apigw-Id
Mrf-Cache-Status
X-Amzn-RequestId
Host
X-Activity-Id
MRF-Tech
X-B3-TraceId-Primal
X-Debug-Info
X-Hostname
X-NGENIX-Cache
X-Cluster-Name
X-Www-Served-By
X-Envoy-Decorator-Operation
X-Origin-Server
X-Varnish-Backend
X-Varnish-Server
Accept-Charset
X-Page-Id
X-Geo-Country
X-App-Server
X-Ezoic-Cdn
X-PressLabs-Stats
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-F-Cache
Retry-After
X-Px
X-RateLimit-Reset
X-Goog-Metageneration
X-Load-Cache
X-FB-Debug
Origin-Trial
X-Upgrade-Enabled
X-CSRF-Token
X-Seen-By
Server-Name
X-Ratelimit-Limit
X-Amz-Meta-S3cmd-Attrs
Cleartype
Access-Control-Allow-Method
X-Git-Hash
X-Fastcgi-Cache
X-Tt-Trace-Tag
X-Tt-Trace-Host
TCN
X-Request-Guid
Section-Io-Cache
X-Cache-Control
X-TTL
X-Grace
X-Azure-Ref
X-TT
X-B
X-Trace-Id
X-Revision
X-Contextid
X-B3-Sampled
X-Webkit-CSP
Healthy
X-Whom
Paypal-Debug-Id
Charset
X-Type
DC
X-Fb-Rlafr
X-Datadog-Parent-Id
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Proxy
X-Content-Options
X-Wix-Request-Id
X-Mobile
X-N
X-Newrelic-App-Data
X-Signature
X-B-Cache
X-App-Environment
X-Node-Name
X-Magnolia-Registration
X-CCDN-CacheTTL
X-Varnish-Ttl
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
Accept-Ch
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
Filterid
X-Amz-Replication-Status
X-Oracle-Dms-Ecid
X-Origin-Cache
X-Goog-Generation
Frame-Options
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Time
X-Air-Pt
X-Logged-In
X-EdgeConnect-Cache-Status
Viewport
X-Unique-Id
NGB
X-Debug
Content-Disposition
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Cache-Grace
X-Oracle-Dms-Rid
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Yottaa-Optimizations
Backend
X-Debug-IsPreview
X-Debug-IsConnected
X-ProcessESI
X-Yottaa-Metrics
X-Tumblr-User
X-Is-Bot
X-Rendered-As
X-RemovedCookies
X-Varnish-Grace
Ms-Operation-Id
X-Adobe-Loc
X-Datadog-Sampled
X-G
X-RTag
X-Servername
SD-X-WS
Fastly-SIE
Liferay-Portal
X-Adobe-Content
MS-CV
Fastly-SWR
X-FW-Static
X-NYM-Debug-Backend
X-FW-Server
X-FW-Serve
X-FW-Hash
X-Hl-Ver
X-Amzn-Remapped-Content-Length
X-FW-Type
X-WebKit-CSP-Report-Only
X-FW-Dynamic
X-Cache-Age
X-Instance
X-FW-Version
X-IPS-LoggedIn
X-Backend-Name
X-UUID
From-Origin
ServerID
X-Cacheable-TTL
X-VC-Cache
X-Original-Request-Id
X-Response-Served-From
X-Device-Type
X-Proxy-Cache-Info
X-User-Agent
X-L-Path
X-Region
X-Environment-Context
X-Via-JSL
Version
X-Ratelimit-Remaining
X-Cache-Hit
Upgrade-Insecure-Requests
X-Rule
Akamai-GRN
Country
X-Status
X-Ua-Device
X-B3-SpanId
X-Source
Refresh
X-Template
X-INCAP-ABP
SRV
GEO-INFO
Countrycode
CDN-RequestId
X-Storage
X-Language
Url
X-HTML-Minification-Powered-By
X-Rid
OT-Force-Account-Verify
X-Air-Source
X-Air-Hostname
X-Air-Trace-Id
X-Cache-Status-Check
X-WP-CF-Super-Cache-Active
X-NODE
AMP-Access-Control-Allow-Source-Origin
X-Real-IP
Alternate-Protocol
WPO-Cache-Message
X-App-Version
X-ServerID
X-Origin-TTL
X-Origin-CC
WPO-Cache-Status
X-CDN-Forward
X-B3-Traceid
X-Jobs
X-Fastly-Request-Id
X-VC
X-Akamai-Request-ID2
Surrogate-Key
X-Is-Crawler
X-Sucuri-Cache
X-Providence-Cookie
X-Route-Name
X-Aspnet-Duration-Ms
X-Flags
Access-Control-Request-Headers
X-Content-Powered-By
X-Cache-Time
X-TT-LOGID
Protected
X-Sucuri-ID
X-Rocket-Nginx-Serving-Static
X-Mode
X-Handled-By
Amp-Access-Control-Allow-Source-Origin
Xet-Cookie
X-Accel-Version
Meta-Geo
X-Hosted-By
Filters
X-Rewrite-Enabled
X-Akamai-Edgescape
X-Upstream-Ct
X-Upstream-Ht
X-Xfnlog-Site
Webserver
X-UPSTREAM-Address
X-Endurance-Cache-Level
X-Rn-Rsrv
Cross-Origin-Embedder-Policy
X-Cache-Rule
Section-Io-Id
Front
X-Cache-Operation
X-RM-Cache-TTL
X-Detected-As
X-Timing-Wait
X-SaId
X-Proxy-Build
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
X-Worker
X-VWS-Id
X-Origin
X-LJ-Flow-ID
X-AWS-Id
X-Adobe-Source
ServedBy
X-Cache-Debug
X-Drupal-Cache-Tags
X-JoinUs
X-Edge-Location
Selected-Fe
X-Webstats-RespID
X-Nginx-Cache
Webcakes-App-Name
Web-Mar-Node
Webcakes-App-Version
X-Cluster
X-Director
TWC-Privacy
Webcakes-Region
TWC-Locale-Group
Property-Id
Node
Mn-Server-Ip
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-LatLong
TWC-GeoIP-Country
X-Drupal-Cache-Contexts
X-Framework
X-Served-From
X-Routing-Service
X-Restarts
X-Soup
X-Varnish-Cache-Hits
X-Zipkin-Id
X-Web-Node
X-Redis-Cache
X-Proxied
X-Labrador-Cache-Channel
X-Extlb
X-Logging-Id
X-No-Session
X-PHP-Host
X-Origin-Hint
Atl-Traceid
X-Cms-Context
X-Geo-Region
X-Forwarded-Host
X-IPLB-Instance
X-IPLB-Request-ID
X-Is-Mobile
X-Is-Desktop
X-Tb
X-Tcp-Rtt
X-AB
X-Varnish-Age
X-Tncms
X-Browser-Name
X-Say-Cacheable
X-Is-Supported-Browser
X-Is-Tablet
X-RCS-CacheZone
X-ProxyCache-Status
X-SayCDN-TTL
X-Say-TTL
X-S
X-ProxyCache-Key
X-Origin-Date
X-Lambda-Id
X-Skip-Cache
X-Locale
X-Site-Version
X-Loop
X-VCT
X-BYPASS-REASON
Apigw-Requestid
Xserver
X-RID
X-GeoCode
Azure-SiteName
X-Generation-Time
X-R9-Blue-Green-Version
X-GeoCountry
X-Httpd
CDN-RequestPullCode
Azure-RegionName
X-Fetched-On
CDN-EdgeStorageId
X-Tec-Api-Root
X-Cache-Host
X-Cdn-Origin
X-Format
Azure-Version
Azure-SlotName
X-Tec-Api-Version
CDN-CachedAt
Azure-InstanceId
CDN-Cache
X-Container-Uri
X-Git-Commit
X-Tec-Api-Origin
CDN-RequestCountryCode
X-Vercel-Id
CDN-Uid
CDN-RequestPullSuccess
X-Reqid
X-Vercel-Cache
CDN-PullZone
X-Varnish-Beresp-Grace
X-Platform-Router
X-Provided-By
X-Storefront-Renderer-Rendered
X-Platform-Cluster
Accept-Language
X-Frame-Option
X-Ms-Request-Id
X-Ms-Version
X-Alternate-Cache-Key
X-Shopify-Stage
X-Platform-Processor
X-Cache-Server
Fastcgi-Useragent
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-ShopId
X-ShardId
X-Vcache
DB-Nickname
Cross-Origin-Window-Policy
X-XRDS-Location
X-Azure-Ref-OriginShield
X-SRV
WP-Super-Cache
X-Vcl-Version
X-Server-W
Source
CF-IPCountry
X-Uri
X-MP-GENERATED-AT
X-PDP-UNCACHING-HASH
Thinkindot-Control
Sid
Thinkindot-CacheControl
X-CMSURLCustom
Thinkindot-CacheControl-Type
Cross-Origin-Embedder-Policy-Report-Only
X-Thinkindot-L3
X-Generated-By
TDXMobile
X-Scope-Id
X-Shield-Cache-Expires
X-Page-View
Cache
X-UA
X-Pass-Why
Cache-Tv-Group
X-FB-TRIP-ID
Content-Secure-Policy
X-Buckets
X-Optimistic-Header
X-Lagoon
X-LSADC-Cache
HostName
Onion-Location
X-Urbn-Site-Id
Locale
X-Urbn-Context-Path
X-Dc
X-WP-CF-Super-Cache-Cookies-Bypass
X-Datadome
X-Content-Age
Priority
X-Use-Mantle
X-Request-URI
X-Http-Reason
X-DataDome
X-GEO
User-Cache-Control
X-Xrds-Location
Locid
X-DynaTrace
Expiry
X-Connection-Hash
X-ND-Cache
X-ScT
X-TIM-N
A
Meta-Geo-Continent
MD5-Digest
Ngx-Var-Key
Ngx.Var.Host
Origin
X-A-Ccd
Magicmarker
X-A-Dam
Gannett-Cam-Experience-Id
Lang
LB
Origin-Agent-Cluster
Redirect-Candidate
Sever-Int
Sslversion
Surrogated-Key
T-Server
Server-Hostname
Server-Host
X-A
Rendered-Blocks
Req-ID
Server-Ext
X-A-Dcw
X-A-Dgt
X-Conf
X-D
Vix-Hermes-Req-Id
X-Platform
Candidate-Md5Url
X-Developer
X-Op-Id-All
X-SB
X-Ec-GeoHdr
X-Ec-Fail
X-Dispatcher-Server
X-Cache-NE
X-Cache-Bucket
X-BCube-Filmed-By
X-Bc-Bl
X-Aed
X-A-Wwc
DCR-Processing-Time-Ms
DCR-Decision-By
X-Bl-Debug
X-UA-Device-Type
X-Rojux
X-Request-Start
X-Epic-Correlation-Id
X-SRCache-Key
X-Vtex-Remote-Cache
X-Viewer-Country
X-Cluster-Node
X-Vdms-Version
X-Vdms-Path
X-Varnish-Hostname
X-NWS-UUID-VERIFY
X-Proxy-Cache-Status
Cache-Hits
X-Auto-Login
X-Application
X-Cache-Action
Content-Style-Type
X-B3-Trace-ID
X-B-Cookie
Content-Script-Type
Cdnsip
X-Cache-Id
C-Via
X-Cache-TTL-Remaining
X-PAYTM-SRV-ID
X-S-Cookie
X-Block-Status
X-NCache
Cdncip
X-Bip
Cluster
X-Req
V-Age
X-TA-CDN-Provider
Wxu-Next-Commit
Wxu-Next-Hostname
NM-Fastcgi-Cache
Pramga
X-Pubstack
Release
X-Varnishpool
True-Client-Country-4JS
Yak-Timeinfo
Wxu-Next-Region
X-AK-Request-ID
X-Amz-Meta-Cb-Modifiedtime
X-Origin-Time
Environment
Fastly-SSL
X-Zen-Fury
X-Loc
Host-ID
X-Level-Front-Cache
DSUID
CDCHOST
X-Nyt-Route
X-Forwarded-Site
X-Clientip
X-NMSegId
X-Varnish-Beresp-Ttl
X-Fastly-Cache
X-Kinja-CCPA
X-Esi-Check
X-External-Request-Id
X-Gdpr
X-Gen-Mode
X-Gzip
X-Thanos
X-Hnp-Log
X-Nginx-Cache-Key
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-Generated-On
X-GeoIP
X-GeoIP-City
X-Ec-Custom-Error
X-Node-Id
X-WA-Info
X-Debug-Cache-Store
X-Scheme
X-Debug-Cache-Fetch
X-SD-PageType
X-Core-Value
X-Destination
X-Origin-Expires
X-Device-Os
X-Service
X-Origin-Response-Time
X-Cache-Expired-At
X-Men
Tube-Return
Uber-Trace-Id
X-Pool
X-HN
X-GoCache-CacheStatus
X-PERF
X-VarnishDD-TTL
X-Human
Ssr
X-V-Cache
X-Contensis-Viewer-Groups
X-HS-Content-Campaign-Id
X-Cdn-Srv
Tube-Got-Eval
Tube-Get-Contents
X-Policy
X-Proxied-Request
Tube-Got-Results
X-Geo-Header
X-Amz-Storage-Class
X-FC-Vary-Parameters
X-Fmm-Version
X-Org
X-Newrelic-Synthetics
X-ApacheServer
X-DPWN-IS-SECURE
X-Backend-Instance
X-BBC-Edge-Cache-Status
X-From
X-Ad-Load-Variation
X-Cache-Aspx
X-Old-Content-Length
Web-Mar-Region
X-Cache-Info
RNT-Time
X-VG-TLSProxy
X-Acquia-Purge-Cdn-Unconfigured
X-Access
X-VG-WebCache
We-Hiring
RNT-Machine
Apple-News-Services-Request-Url
Canary
Click-Count-Action-Start
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Adler-Geo
Apple-News-Services-Handled
Click-Count-Error
Country-Code
X-Mly-Id
Gh-Request-Id
Fastly-GeoIP-CountryCode
Esi-Enabled
X-Request-Time
X-Request-Host
X-We-Are-Hiring
X-Sql-Count
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Varnish-Beresp-Status
X-TH-Server
X-Var-Ttl
X-Varnish-Authentication
X-Sn-Servicetimems
X-Moov-Xdn-Version
X-Section
X-Sql-Duration-Ms
X-Moov-T
X-Server-IP
X-Mvc-Supplant-Cachable
X-Varnish-Director
Is-Eu
Cache-Provider
Producers
X-Aicache-OS
Mail-Subject
Platform
PFcat
X-Region-Sid
On-Server
X-RateLimit-Remaining-Second
Machine
X-Micro-Cache
XM
Req-Svc-Chain
L
X-RateLimit-Limit-Second
X-NGINX-Cache
X-VCache
X-Test
X-Mvc-Supplant-OutputCached
AKAMAI
X-CGP
X-Wikidot-Backend
X-Up
X-Hash
X-ECache
X-Eu-Site
X-Fastly-Backend
Proxy-Firewall
X-Proto
X-Edge-Server
X-Slack-Shared-Secret-Outcome
X-Slack-Backend
X-Csrf-Jwt
Cdn-Request-Time
L5d-Success-Class
X-App-Name
X-Wikidot-Static-Cache
W
Cf-Device-Type
X-Instance-Name
Cache-Key
Cdn-Host
X-Cache-Backend
HA-Ipaddr
Ha-Gx-Prefs
X-Esi
X-Cloudmap
X-VServer
X-Sigma
Fastly-Backend-Name
X-Via-Fastly
X-Accel-Expires-Debug
X-Tb-Optimization-Total-Bytes-Saved
NGX
X-Sigma-Backend
X-Rocket-Build-Number
X-CacheTTL
Fastly-Drupal-HTML
X-Date
X-Cache-Date
X-LB-ID
WZWS-RAY
X-Ah-Environment
X-Mg-Request-UUID
X-COUNTRY
X-Ig-Origin-Region
X-Via-Popv
X-DC
X-Parent-Response-Time
X-HA-Backend
X-API-Version
X-DynaTrace-JS-Agent
X-Via-Popn
X-Branch-Name
Pics-Label
X-Tx-Id
X-Via-Poph
X-Location
NtCoent-Length
X-Zone
X-Varnish-Hits
Datacenter
Fusion-Component-Id
Fusion-Content-Id
X-CACHE-GROUP
X-Refresh
Fusion-Source
Fusion-Template-Id
Fusion-Deployment-Id
X-Via-CDN
X-Via-Edge
Edge-Copy-Time
X-Via-SSL
Fusion-Content-Source
X-Ratelimit-Reset
X-Correlation-ID
S-Rt
GeoIp-Country-Code
X-Wormhole-Sdk
X-Akamai-Transformed
X-Servedbyhost
Type
X-CDN-Cache-Status
X-VHOST
X-CUA
X-Jungle-Id
Powered-By
Cdn
X-ZONE
X-User
Origin-EX
Origin-CC
Resin-Trace
X-Ua
X-LB-NoCache
X-TX-ID
SID
X-Irp-Debug
Cf-Ipcountry
Cdn-Requestid
Server-ID
X-Wa
X-Srv
X-Owner
X-Nc
X-Core-Mission
X-Render-Time
X-VTEX-Cache-Time
X-VTEX-Cache-Server
IsBot
X-SIPLIST1
Cross-Origin-Opener-Policy-Report-Only
X-Powered-By-VTEX-Cache
X-Nananana
Fastly-Drupal-Html
X-LiteSpeed-Tag
GeoIP-Latitude
X-Hit
X-Cached-By
X-AIR-PT
X-NewRelic-App-Data
Edge-Cache
CloudFront-Viewer-Country
X-Nf-Request-Id
Uri
XkeyRZ
X-B3-Parentspanid
X-Proxy-CacheRZ
X-Fpc
X-Qloud-Router
X-Client-Ip
X-Cs
DataCenter
Mime-Version
X-Presslabs-Stats
X-Auth-Group-Type
Debug
X-CS
True-Client-IP
X-URL
X-IAuth-Set-Uid
X-DataCenter
X-Segment-20210421
X-LiteSpeed-Cache-Control
X-Ig-Push-State
X-Amz-Meta-Opti
X-TIME
Tcn
Expect-Staple
X-CF-Lambda-Version
X-CF-Lambda-Fn
N-Cache
X-PHP-Backend
X-Varnish-Beresp-TTL
CDN
X-Tenant
Xc-Version
X-Cache-Type
X-Forwarded-Path
X-Shop-Environment
X-Orig-Expires
Odigeo-Trace-Id
X-HostName
X-CACHE-AGE
X-NodeID
X-Gamma-Serve
X-Custom-Header
X-Vgn-Hpd-Reason
MIME-Version
True-Client-Ip
Cmstype
X-Geo
X-Tt-Logid
Cmsid
X-Dynatrace-Js-Agent
CPC-Age
X-Vmg-Version
X-Info
X-Pad
X-Dispatch
CPC-Cache
User-Agent
Load-Balancing
X-Api-Version
X-B3-Spanid
Srv
X-Depends
X-HOST
X-Cdn-Diag
X-WA
X-Fastly-Country-Code
X-FPC
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-Vc
X-NC
X-Varnish-CookieHashed-On
X-DefElseHash
X-DefHash
Request-ID
X-VC-TTL
X-M-Reqid
X-M-Log
Ohc-File-Size
X-Cdn-Forward
X-Webkit-Csp-Report-Only
Cl-Cache
Server-Id
Geoip-Latitude
X-CSRF-TOKEN
X-Variation
X-Datacenter
Hostname
X-APP-VERSION
X-APP
X-Lb-Nocache
CacheControlHeader
X-Cache-FS-Status
X-TimeS
Ohc-Cache-HIT
X-LAGOON
X-ServedByHost
GeoIP-Country-Code
Cloudfront-Viewer-Country
X-Cdn-Cache-Status
X-Oracle-DMS-ECID
VNS-Age
Epwk-X-Cache
Server-Info
FSS-Cache
VNS-Cache
X-Cache-Ttl
X-Via-PopV
PICS-Label
X-Via-PopN
X-Via-PopH
X-Ha-Backend
X-MSEdge-Flight
CountryCode
ServerHost
Srvid
X-FL-QIT-DEBUG
BehaviorPad-Version
X-Litespeed-Tag
X-MSEdge-Features
X-Fastly-Backend-Reqs
Rtss
X-VCL-Version
X-Litespeed-Cache-Control
X-Srcache-Store-Status
X-Srcache-Fetch-Status
X-Proxy-Cache-La3
X-Lb-Id
X-Cdn-Request-ID
Xkeylog
Xkey-La3
X-Acquia-Site
X-Serial
X-Akamai-Pragma-Client-IP
X-Acquia-Purge-Tags
X-Acquia-Application-Trace
Memcached
X-Web-Server
Time
X-Th-Server
X-Acquia-Application-UUID
X-Check-Cacheable
OriginIP
Ngx
X-MiniProfiler-Ids
Memory
X-RequestId
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Snapshot-Date
X-Dispatcher-Number
X-Shardid
X-Cache-Version
X-Sorting-Hat-Podid
X-Sorting-Hat-Shopid
X-Shopid
X-Sucuri-Id
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Ramcache
X-Udemy-Cache-App-Namespace
X-RAMCache
Sm-Log-Id
X-Requestid
Warning
X-Mg-Cache
X-Dw-Trace-Id
X-Service-Response-Time
Akamai-Cache-Status