Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
X-XSS-Protection
Accept-Ranges
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-Served-By
X-UA-Compatible
P3P
X-Xss-Protection
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
X-FRAME-OPTIONS
Access-Control-Allow-Credentials
Content-Security-Policy-Report-Only
P3p
X-Runtime
X-AspNet-Version
Accept-CH
X-DNS-Prefetch-Control
X-Cache-Status
X-Drupal-Cache
X-Ua-Compatible
Accept-CH-Lifetime
X-Check
X-Generator
Server-Timing
X-Cacheable
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Iinfo
X-Request-ID
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
X-Content-Security-Policy
Feature-Policy
Content-Encoding
X-CDN
Status
X-AspNetMvc-Version
Upgrade
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
CF-Ray
X-Amz-Id-2
Host-Header
Allow
X-Backend
Cf-Edge-Cache
Request-Context
X-UA-Device
Keep-Alive
X-Robots-Tag
X-Server
X-Cache-Group
X-Hacker
X-AH-Environment
X-Turbo-Charged-By
X-Ws-Request-Id
X-Proxy-Cache
X-Age
X-Rq
X-Vhost
Xkey
EagleId
X-Dispatcher
X-Server-Powered-By
X-Amz-Version-Id
X-Varnish-Cache
Grace
Cf-Apo-Via
X-Dns-Prefetch-Control
X-Page-Speed
X-Pingback
X-LiteSpeed-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Cf-Railgun
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
EagleEye-TraceId
Ali-Swift-Global-Savetime
X-Aws-Lambda-Call-Status
X-CST
X-WebKit-CSP
X-Backend-Server
Permissions-Policy
X-OneAgent-JS-Injection
X-Server-Id
X-Readtime
X-Response-Time
X-Host
X-Akam-SW-Version
Request-Id
Surrogate-Control
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-HW
X-Nginx-Upstream-Cache-Status
X-Cloud-Trace-Context
Accept-Ch-Lifetime
X-Node
X-Nginx-Cache-Status
X-Litespeed-Cache
X-Cache-Lookup
X-Application-Context
X-Country-Code
X-Oneagent-Js-Injection
Content-Location
X-Country
X-Trace
Service-Worker-Allowed
X-Url
X-Content-Type
X-Clacks-Overhead
X-Ruxit-JS-Agent
X-Origin-Cache-Key
X-Edge
Cross-Origin-Opener-Policy
X-Rack-Cache
X-Amz-Server-Side-Encryption
X-ECACHE
X-Mcache
X-Midtier
X-Mod-Pagespeed
Cache-Tag
X-FTR-Request-ID
Nginx-Cache
X-MS-InvokeApp
X-PC
X-Vname
X-TtlSet
X-Upstream
X-ESI
X-Powered-By-Plesk
Rating
Edge-Control
X-Ruxit-Js-Agent
X-Browser-Type
X-Server-Name
X-D2id
X-Element-Page-Cache
Verso
X-Kinja
X-Kinja-Build
X-GoogleNews-Bot
X-Exp-Variant
X-Cdn-Fetch
X-Exp-Id
X-Kinja-Revision
X-Kinja-Server
X-Times
X-Cnection
SPIisLatency
SPRequestDuration
X-Ac
AR-PoweredBy
AR-SID
AR-Request-ID
AR-ATIME
X-B3-TraceId
SPRequestGuid
X-SharePointHealthScore
X-Navigation-Version
X-Abt-Application-Version
X-Vcap-Request-Id
X-Dw-Request-Base-Id
X-Ser
X-NF-Request-ID
X-GitHub-Request-Id
X-RateLimit-Remaining
X-NWS-LOG-UUID
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
AR-CACHE
X-VARITI-CCR
Display
Pagespeed
X-Middleton-Display
S
X-Sol
X-Mg-S
Edge-Cache-Tag
X-Client-IP
X-Cache-Key
RTSS
X-Ttl
Fastly-Restarts
X-Amzn-Trace-Id
X-Amz-Rid
X-Cache-TTL
Accept-Ch
X-Powered-CMS
X-Erf-Bev-Bev-Is-Generated
X-Kraken-Loop-Name
X-Erf-Bev-Bev
X-Goog-Hash
X-Instrumentation
Cache-Status
X-Server-Lifecycle-Phase
X-Server-ID
X-Edge-Location-Klb
X-Kinsta-Cache
Access-Control-Request-Method
X-Version
X-Recruiting
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-ARC
Origin-Trial
X-Content-Digest
X-Middleton-Response
Response
X-Webkit-Csp
X-TraceId
X-Varnish-TTL
X-Forwarded-For
Arr-Disable-Session-Affinity
X-T
X-Content-Security-Policy-Report-Only
X-MSEdge-Ref
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Content-MD5
MicrosoftSharePointTeamServices
X-Accel-Expires
TP-Cache
X-Shield-Request-Id
X-Hits
X-Cached
Cross-Origin-Resource-Policy
Public-Key-Pins
X-Id
Front-End-Https
X-Daa-Tunnel
MS-Author-Via
Server-Node
X-Ua-Browser
X-Request-Received
X-Request-Processing-Time
X-DIS-Request-ID
X-FTR-Balancer
X-HS-Content-Id
X-FTR-Backend-Server
X-HS-Cache-Config
X-HS-Combine-CSS
X-Country-Code-Real
X-HS-Hub-Id
X-FTR-Cache-Status
X-FTR-Backend
X-Forwarded-Proto
X-FTR-Expires
X-Frontend
Payment
X-FastCGI-Cache
X-LLID
X-HP-Trace-Id
X-HP-Webp
X-Jurisdiction
X-ORACLE-DMS-RID
X-Fastcgi-Cache
Realpath
X-GUploader-UploadID
TP-L2-Cache
X-Protected-By
X-RateLimit-Limit
X-LB-Cache
Cache-Tags
X-Distributor
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Origin-Server
X-Request-Handler-Origin-Region
X-Microsite
Count-Hit
X-Az
X-F-Cache
X-AppVersion
Mrf-Cache-Status
X-Activity-Id
X-B3-TraceId-Primal
X-Hostname
Referer-Policy
X-ORACLE-DMS-ECID
MRF-Tech
X-Kong-Proxy-Latency
X-Cluster-Name
X-Kong-Upstream-Latency
X-Page-Id
X-XRDS-LOCATION
X-Www-Served-By
X-Geo-Country
X-Varnish-Backend
Host
X-Debug-Info
X-Envoy-Decorator-Operation
X-NGENIX-Cache
X-App-Server
Accept-Charset
X-Varnish-Server
Fastcgi-Cache
X-Correlation-Id
X-Ua-Device
X-Ratelimit-Limit
X-PressLabs-Stats
X-TTL
X-FB-Debug
X-Goog-Metageneration
X-Varnish-Ttl
Access-Control-Allow-Method
X-Git-Hash
X-CSRF-Token
Retry-After
X-Upgrade-Enabled
X-WebKit-CSP-Report-Only
X-RateLimit-Reset
X-Load-Cache
X-Ezoic-Cdn
X-ASPNET-VERSION
X-Content-Options
X-Kinja-CCPA
X-Fastly-Request-Id
X-Px
Server-Name
X-Rid
X-Datadog-Parent-Id
X-Contextid
Charset
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Revision
X-Tt-Trace-Tag
X-Grace
X-Seen-By
X-Type
DC
X-Amz-Meta-S3cmd-Attrs
TCN
X-Tt-Trace-Host
X-TT
Cleartype
X-Cache-Control
Paypal-Debug-Id
X-Signature
X-B-Cache
Section-Io-Cache
X-Trace-Id
X-B3-Sampled
X-B
X-App-Environment
X-Fb-Rlafr
Healthy
X-Request-Guid
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Newrelic-App-Data
X-Whom
X-Node-Name
Frame-Options
X-Wix-Request-Id
X-Mobile
X-Amz-Replication-Status
X-Magnolia-Registration
X-Origin-Cache
X-Aspnet-Duration-Ms
X-Providence-Cookie
X-Route-Name
X-Flags
X-Is-Crawler
X-EdgeConnect-Cache-Status
X-Oracle-Dms-Ecid
X-Azure-Ref
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Logged-In
X-Proxy
X-Language
X-Fastly-Request-ID
X-N
Filterid
X-Ratelimit-Remaining
Content-Disposition
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
Backend
Akamai-GRN
X-Oracle-Dms-Rid
X-Air-Pt
X-App-Version
VIX-Pulpo-Node
X-Original-Request-Id
X-Response-Served-From
Upgrade-Insecure-Requests
NGB
X-Template
VIX-Pulpo-Upstream-Status
X-Proxy-Cache-Info
Refresh
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Debug-IsPreview
X-Debug-IsConnected
X-Datadog-Sampled
X-Tumblr-Pixel
X-RemovedCookies
X-ProcessESI
X-Unique-Id
X-Tumblr-User
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-UUID
MS-CV
X-Cache-Age
Viewport
X-RTag
X-Time
Ms-Operation-Id
X-IPS-LoggedIn
X-Adobe-Loc
X-Adobe-Content
X-Amzn-Remapped-Content-Length
X-FW-Version
X-Instance
X-G
X-Rendered-As
X-Is-Bot
SD-X-WS
X-Varnish-Grace
X-FW-Serve
Liferay-Portal
X-FW-Static
X-FW-Dynamic
X-Debug
X-FW-Server
X-FW-Hash
X-FW-Type
X-Cacheable-TTL
From-Origin
X-Environment-Context
X-L-Path
X-Region
X-Servername
X-Cache-Grace
X-User-Agent
X-NYM-Debug-Backend
X-Device-Type
Country
X-Hl-Ver
Fastly-SWR
Fastly-SIE
X-Rule
X-Cache-Hit
X-Backend-Name
X-Status
Url
X-Jobs
ServerID
X-Page-View
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-Webkit-CSP
X-CCDN-Origin-Time
X-Via-JSL
X-VC-Cache
WPO-Cache-Message
WPO-Cache-Status
Countrycode
X-B3-SpanId
X-INCAP-ABP
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
X-Air-Hostname
X-Cache-Status-Check
Surrogate-Key
X-Air-Trace-Id
X-Air-Source
X-Origin-TTL
X-Origin-CC
Alternate-Protocol
X-HTML-Minification-Powered-By
X-NODE
Version
X-Content-Powered-By
X-Akamai-Request-ID2
X-Nginx-Cache
X-Hosted-By
X-Source
X-B3-Traceid
Protected
X-Rocket-Nginx-Serving-Static
GEO-INFO
X-Akamai-Edgescape
X-Storage
SRV
X-Http-Reason
X-Accel-Version
Amp-Access-Control-Allow-Source-Origin
X-WP-CF-Super-Cache-Active
Access-Control-Request-Headers
OT-Force-Account-Verify
X-Framework
X-CDN-Forward
X-VC
X-Edge-Location
CDN-RequestId
X-Cache-Rule
AMP-Access-Control-Allow-Source-Origin
Front
X-Real-IP
CF-IPCountry
X-Use-Mantle
X-Mode
X-Rewrite-Enabled
X-Cache-Operation
Filters
Meta-Geo
X-Upstream-Ht
Webserver
X-Xfnlog-Site
X-Httpd
X-Upstream-Ct
X-UPSTREAM-Address
X-Rn-Rsrv
X-Cache-Time
X-ServerID
X-Tumblr-Pixel-2
X-Timing-Wait
X-Tumblr-Pixel-3
X-Varnish-Cache-Hits
X-Served-From
X-SaId
X-Origin
X-Proxy-Build
X-JoinUs
Selected-Fe
Xet-Cookie
ServedBy
X-PHP-Host
X-Worker
Accept-Language
X-Soup
X-Labrador-Cache-Channel
Node
X-Endurance-Cache-Level
X-Director
X-S
X-AB
X-Adobe-Source
X-Say-Cacheable
X-GeoCode
X-Skip-Cache
X-SayCDN-TTL
X-Say-TTL
X-Redis-Cache
X-Browser-Name
X-Is-Tablet
X-Is-Supported-Browser
X-Is-Mobile
X-GeoCountry
X-Logging-Id
Xserver
X-Geo-Region
Section-Io-Id
X-Handled-By
X-Varnish-Age
X-Format
X-Lambda-Id
X-BYPASS-REASON
Webcakes-Region
Webcakes-App-Version
X-No-Session
X-Origin-Hint
X-Server-W
X-Restarts
X-ProxyCache-Status
X-ProxyCache-Key
Webcakes-App-Name
TWC-Privacy
X-Web-Node
Apigw-Requestid
X-VCT
X-Varnish-Beresp-Grace
DB-Nickname
Property-Id
TWC-Connection-Speed
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Device-Class
X-Tcp-Rtt
X-Is-Desktop
Azure-SiteName
Azure-RegionName
Azure-SlotName
Azure-InstanceId
Azure-Version
X-LJ-Flow-ID
X-Cache-Server
X-Locale
X-IPLB-Request-ID
X-Loop
X-Vercel-Cache
X-Cms-Context
X-AWS-Id
X-Generation-Time
X-Fetched-On
X-IPLB-Instance
X-R9-Blue-Green-Version
X-Cache-Host
X-Tncms
X-RCS-CacheZone
Mn-Server-Ip
Cross-Origin-Embedder-Policy
X-Vercel-Id
X-VWS-Id
X-Tb
X-RM-Cache-TTL
Web-Mar-Node
X-Zipkin-Id
X-Ms-Version
X-Uri
X-Ms-Request-Id
X-Forwarded-Host
X-Git-Commit
X-Cache-Debug
X-Container-Uri
X-DynaTrace
X-Proxied
X-Cluster
X-Reqid
X-Routing-Service
X-Frame-Option
X-Site-Version
X-Detected-As
X-Extlb
X-MP-GENERATED-AT
X-Platform-Processor
X-Platform-Cluster
X-Platform-Router
X-Drupal-Cache-Tags
X-Webstats-RespID
X-Drupal-Cache-Contexts
X-XRDS-Location
X-Provided-By
X-Sql-Count
WP-Super-Cache
X-Sql-Duration-Ms
Cache-Tv-Group
X-Shopify-Stage
X-Alternate-Cache-Key
Priority
Fastcgi-Useragent
X-TT-LOGID
X-Storefront-Renderer-Rendered
X-Origin-Date
Source
CDN-RequestCountryCode
CDN-RequestPullCode
X-FB-TRIP-ID
CDN-RequestPullSuccess
CDN-Uid
Content-Secure-Policy
CDN-PullZone
CDN-CachedAt
X-Vcache
CDN-EdgeStorageId
CDN-Cache
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-ShopId
X-Vcl-Version
X-ShardId
X-Cdn-Origin
X-Sucuri-Cache
Onion-Location
Sid
X-Generated-By
X-Sucuri-ID
Cross-Origin-Embedder-Policy-Report-Only
X-Content-Age
X-Pass-Why
X-Urbn-Context-Path
X-Urbn-Site-Id
Locale
S-Rt
WZWS-RAY
X-Newrelic-Synthetics
X-Buckets
X-SRV
X-Cluster-Node
X-Thinkindot-L3
TDXMobile
Atl-Traceid
X-Use-Magma
Thinkindot-Control
Thinkindot-CacheControl
X-Scope-Id
Thinkindot-CacheControl-Type
X-CMSURLCustom
X-Shield-Cache-Expires
X-Ua
X-Varnish-Beresp-Ttl
X-LSADC-Cache
X-Proxy-Cache-Status
Cross-Origin-Window-Policy
X-Xrds-Location
Cache
HostName
X-Cache-Expired-At
X-Cache-Action
X-VCache
Edge-Copy-Time
X-Via-SSL
X-Via-Edge
X-Via-CDN
X-Datadome
X-DataDome
X-SRCache-Key
X-Vdms-Path
X-Varnish-Hostname
X-TIM-N
Candidate-Md5Url
X-Aed
X-A-Wwc
X-Application
X-B-Cookie
X-Bc-Bl
X-A-Dgt
X-A-Dcw
Vix-Hermes-Req-Id
Type
X-A
X-A-Ccd
X-A-Dam
X-BCube-Filmed-By
X-Bl-Debug
X-Ec-Fail
X-Dispatcher-Server
X-Ec-GeoHdr
X-Epic-Correlation-Id
X-External-Request-Id
X-Developer
X-Destination
X-Cache-Bucket
X-Cache-NE
X-Conf
X-D
T-Server
Surrogated-Key
DCR-Decision-By
X-Platform
DCR-Processing-Time-Ms
X-PAYTM-SRV-ID
Gannett-Cam-Experience-Id
CDCHOST
X-Vdms-Version
X-Scheme
X-S-Cookie
X-Rojux
X-Request-Start
Lang
MD5-Digest
Rendered-Blocks
Redirect-Candidate
Req-ID
Server-Host
Sslversion
Origin-Agent-Cluster
Origin
Meta-Geo-Continent
X-Optimistic-Header
Ngx-Var-Key
Ngx.Var.Host
X-ScT
X-Viewer-Country
X-Correlation-ID
X-GEO
X-WP-CF-Super-Cache-Cookies-Bypass
X-Vtex-Remote-Cache
X-Dc
X-Connection-Hash
Expiry
X-TimeS
X-Gdpr
Magicmarker
X-Esi-Check
NM-Fastcgi-Cache
X-NMSegId
Release
X-Node-Id
Host-ID
X-Origin-Time
X-Pool
Cluster
X-Proxied-Request
X-Pubstack
L
DSUID
X-Mg-Request-UUID
Fastly-GeoIP-CountryCode
Environment
Ssr
X-Mly-Id
X-Op-Id-All
X-Clientip
X-GeoIP-Country-Code
X-Core-Value
X-Debug-Cache-Fetch
X-Section
X-SB
X-Debug-Cache-Store
X-GeoIP-Region-Code
X-Gzip
X-Generated-On
X-Ec-Custom-Error
V-Age
X-Loc
X-Level-Front-Cache
X-Cache-Id
X-Bip
X-Instance-Name
X-Access
X-Nyt-Route
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-TH-Server
X-Thanos
X-Rocket-Build-Number
X-Sigma-Backend
Apple-News-Services-Handled
X-We-Are-Hiring
X-WA-Info
A
X-Sigma
X-Varnish-Beresp-Status
Apple-News-Services-Request-Url
X-Varnishpool
X-Request-Time
X-VG-TLSProxy
X-Service
X-Request-URI
User-Cache-Control
Fastly-Drupal-HTML
X-Zen-Fury
X-Moov-Xdn-Version
X-VG-WebCache
X-UA-Device-Type
X-VServer
X-Forwarded-Site
X-ApacheServer
X-Moov-T
X-Ad-Load-Variation
X-BBC-Edge-Cache-Status
X-B3-Trace-ID
X-Fastly-Cache
X-Auto-Login
X-Cache-TTL-Remaining
X-Men
We-Hiring
X-Branch-Name
X-Micro-Cache
X-From
X-NCache
X-V-Cache
X-GeoIP
X-GeoIP-City
X-Contensis-Viewer-Groups
X-Var-Ttl
X-Req
X-Geo-Header
X-Device-Os
X-Varnish-Authentication
X-DPWN-IS-SECURE
X-GoCache-CacheStatus
X-Human
X-Cache-Date
X-Varnish-Director
X-SVT-ORM-RULES
X-Cache-Info
X-SVT-ORM-VERSION
X-RateLimit-Remaining-Second
X-Nginx-Cache-Key
X-Cache-Aspx
X-Amz-Meta-Cb-Modifiedtime
X-Org
Mail-Subject
C-Via
Machine
Server-Hostname
Sever-Int
Platform
On-Server
X-SD-PageType
Is-Eu
Gh-Request-Id
Content-Style-Type
Content-Script-Type
Canary
X-RateLimit-Limit-Second
Req-Svc-Chain
Adler-Geo
Fastly-SSL
X-PERF
Esi-Enabled
Pramga
Server-Ext
Wxu-Next-Commit
X-Server-IP
Wxu-Next-Hostname
Producers
Wxu-Next-Region
True-Client-Country-4JS
Uber-Trace-Id
X-Acquia-Purge-Cdn-Unconfigured
X-Origin-Response-Time
X-Block-Status
RNT-Machine
Click-Count-Action-Start
Country-Code
X-ND-Cache
X-Request-Host
Click-Count-Error
X-Proto
X-Mvc-Supplant-Cachable
X-Policy
X-Wikidot-Static-Cache
Yak-Timeinfo
X-Up
X-Old-Content-Length
Tube-Got-Results
Tube-Return
X-Hnp-Log
X-Sn-Servicetimems
Tube-Got-Eval
Tube-Get-Contents
X-Irp-Debug
X-Wikidot-Backend
X-HS-Content-Campaign-Id
X-Mvc-Supplant-OutputCached
Cache-Provider
X-Cdn-Srv
RNT-Time
X-Test
X-Hash
W
X-Gen-Mode
X-Region-Sid
Web-Mar-Region
Cache-Key
Proxy-Firewall
X-Aicache-OS
Cf-Device-Type
X-Edge-Server
AKAMAI
Cdn-Request-Time
X-TA-CDN-Provider
X-FC-Vary-Parameters
Cdn-Host
X-Parent-Response-Time
HA-Ipaddr
X-Fmm-Version
Ha-Gx-Prefs
L5d-Success-Class
Pics-Label
Cdnsip
X-Owner
Fastly-Backend-Name
X-AK-Request-ID
Locid
Cdncip
NGX
X-Eu-Site
X-Ah-Environment
X-VarnishDD-TTL
X-Date
X-Fastly-Backend
X-Slack-Shared-Secret-Outcome
X-Slack-Backend
X-CGP
X-HN
PFcat
X-Csrf-Jwt
X-App-Name
X-Amz-Storage-Class
X-CacheTTL
X-Accel-Expires-Debug
X-Azure-Ref-OriginShield
X-ZONE
IsBot
X-COUNTRY
X-DC
X-Via-Popv
X-Via-Popn
X-Core-Mission
X-Via-Poph
X-SIPLIST1
X-LB-ID
X-HA-Backend
X-CACHE-GROUP
XM
Cdn
X-Qloud-Router
X-Backend-Instance
X-DynaTrace-JS-Agent
LB
Cdn-Requestid
X-Ratelimit-Reset
Datacenter
X-Tx-Id
X-Servedbyhost
X-Cache-Backend
X-LB-NoCache
X-Tb-Optimization-Total-Bytes-Saved
X-API-Version
X-Varnish-Hits
X-Srv
NtCoent-Length
X-CF-Lambda-Fn
X-CF-Lambda-Version
N-Cache
X-Refresh
Expect-Staple
X-VHOST
X-Lagoon
X-Origin-Expires
RATING
X-Shop-Environment
X-Tenant
X-Cache-Type
X-Forwarded-Path
Xc-Version
X-Orig-Expires
X-ECache
X-NGINX-Cache
Cmsid
X-CDN-Cache-Status
GeoIp-Country-Code
Cmstype
X-Gamma-Serve
Server-ID
X-UA
X-Wa
CPC-Cache
X-TX-ID
X-Nananana
X-Nc
SID
CPC-Age
CloudFront-Viewer-Country
Cross-Origin-Opener-Policy-Report-Only
X-Cdn-Diag
X-Vmg-Version
X-Fpc
Resin-Trace
X-Zone
X-Tt-Logid
X-Akamai-Transformed
X-Hit
X-Via-Fastly
X-B3-Parentspanid
User-Agent
X-Nf-Request-Id
Uri
XkeyRZ
Cache-Hits
X-Proxy-CacheRZ
X-RID
DataCenter
X-Client-Ip
X-Ig-Origin-Region
X-LAGOON
X-Presslabs-Stats
X-Location
CacheControlHeader
X-URL
GeoIP-Latitude
X-Variation
Fusion-Component-Id
Fusion-Content-Source
X-Datacenter
X-Info
X-Fastly-Country-Code
X-TIME
Fusion-Template-Id
Fusion-Deployment-Id
Fusion-Content-Id
X-Amz-Meta-Opti
X-Api-Version
True-Client-Ip
Fusion-Source
Tcn
Powered-By
X-Cloudmap
Fastly-Drupal-Html
X-Geo
Lb
X-B3-Spanid
X-NewRelic-App-Data
X-HostName
X-Jungle-Id
VNS-Age
MIME-Version
Origin-EX
X-DataCenter
True-Client-IP
Origin-CC
VNS-Cache
Mime-Version
X-CACHE-AGE
X-CS
X-NWS-UUID-VERIFY
X-AIR-PT
X-Dynatrace-Js-Agent
Cf-Ipcountry
X-IAuth-Set-Uid
X-CUA
X-LiteSpeed-Tag
X-User
X-Cdn-Forward
X-Vc
X-Cached-By
Srv
Debug
X-HOST
X-Segment-20210421
Load-Balancing
X-Varnish-Beresp-TTL
X-LiteSpeed-Cache-Control
X-Render-Time
X-Dispatcher-Number
Cl-Cache
Hostname
Cache-Name
X-Webkit-Csp-Report-Only
X-CSRF-TOKEN
CDN
X-VTEX-Cache-Time
Edge-Cache
X-Powered-By-VTEX-Cache
X-MCACHE
X-FPC
X-Auth-Group-Type
X-VTEX-Cache-Server
X-Dispatch
X-Mid
Ohc-File-Size
X-Esi
GeoIP-Country-Code
X-Wormhole-Sdk
Server-Id
X-Litespeed-Tag
X-NC
X-Ig-Push-State
X-WA
X-Cdn-Cache-Status
X-Oracle-DMS-ECID
X-Cs
Ohc-Cache-HIT
X-APP-VERSION
X-Lb-Nocache
X-ServedByHost
Odigeo-Trace-Id
X-NodeID
BehaviorPad-Version
X-Cache-Ttl
CountryCode
X-Custom-Header
X-Cache-Enabled
X-Fastly-Backend-Reqs
Ms-Author-Via
X-VCL-Version
X-Litespeed-Cache-Control
X-MiniProfiler-Ids
X-Depends
X-MSEdge-Flight
YJS-ID
X-PHP-Backend
Xkeylog
X-Cdn-Request-ID
X-Proxy-Cache-La3
X-MSEdge-Features
Server-Info
Xkey-La3
X-Lb-Id
X-Akamai-Pragma-Client-IP
X-Vgn-Hpd-Reason
X-Pad
X-Acquia-Site
X-Acquia-Application-UUID
X-Acquia-Application-Trace
My-App
X-Acquia-Purge-Tags
X-Ha-Backend
X-Snapshot-Date
Srvid
Location
Time
X-Via-PopH
X-Via-PopN
Ngx
X-IN-APIGATEWAY
X-Via-PopV
OriginIP
FSS-Cache
X-FL-EDGE
X-FL-QIT-DEBUG
X-Varnish-Remaining-TTL
X-IN-APIGATEWAYSSL
X-DefElseHash
Memcached
X-DefHash
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
Memory
X-Shardid
X-Shopid
X-Sorting-Hat-Shopid
X-Sorting-Hat-Podid
X-Cache-Version
X-VC-TTL
X-M-Log
X-M-Reqid
PICS-Label
X-Lsadc-Cache
X-Th-Server
X-Check-Cacheable
X-Internal-Host
X-Serial
Sm-Log-Id
Geoip-Latitude
X-Udemy-Cache-App-Namespace
X-RequestId
X-Service-Response-Time
X-Web-Server
CF-Ctrl
X-Fastly-Cache-Hits
Akamai-Cache-Status
X-Mg-Cache
X-Sucuri-Id
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Dw-Trace-Id
CF-Cached-On