Threat Level: green Handler on Duty: Richard Porter

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
Expect-CT
CF-RAY
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Xss-Protection
X-Cache-Hits
X-UA-Compatible
X-Served-By
P3P
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
X-AspNet-Version
Content-Security-Policy-Report-Only
X-Runtime
Accept-CH
P3p
X-DNS-Prefetch-Control
X-Drupal-Cache
X-Cache-Status
Accept-CH-Lifetime
CF-Ray
X-Ua-Compatible
X-Generator
X-Check
Server-Timing
X-Cacheable
X-Envoy-Upstream-Service-Time
X-Request-ID
Timing-Allow-Origin
X-Iinfo
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
X-Content-Security-Policy
Feature-Policy
Content-Encoding
X-CDN
Status
X-AspNetMvc-Version
Upgrade
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
X-Amz-Id-2
Host-Header
Cf-Edge-Cache
X-Backend
Request-Context
Keep-Alive
X-UA-Device
Allow
X-Robots-Tag
X-Server
X-Cache-Group
X-Hacker
X-AH-Environment
X-Turbo-Charged-By
X-Ws-Request-Id
EagleId
X-Proxy-Cache
X-Age
X-Rq
Xkey
X-Vhost
X-Dispatcher
X-Amz-Version-Id
X-Server-Powered-By
X-Varnish-Cache
Grace
Cf-Apo-Via
X-Dns-Prefetch-Control
X-Swift-CacheTime
X-Swift-SaveTime
X-Page-Speed
X-Pingback
Ali-Swift-Global-Savetime
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-LiteSpeed-Cache
X-Device
Cf-Railgun
EagleEye-TraceId
Permissions-Policy
X-OneAgent-JS-Injection
X-WebKit-CSP
X-CST
X-Backend-Server
X-Aws-Lambda-Call-Status
X-Host
X-Readtime
X-Response-Time
X-Server-Id
X-Akam-SW-Version
X-Cache-Lookup
Request-Id
Surrogate-Control
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-HW
X-Litespeed-Cache
X-Nginx-Upstream-Cache-Status
X-Cloud-Trace-Context
X-Node
X-Nginx-Cache-Status
X-Application-Context
X-Country-Code
Content-Location
X-Country
X-Trace
Service-Worker-Allowed
X-Ruxit-JS-Agent
X-Url
X-Content-Type
X-Clacks-Overhead
X-Oneagent-Js-Injection
Accept-Ch-Lifetime
Rating
X-Origin-Cache-Key
X-Rack-Cache
Cache-Tag
X-Amz-Server-Side-Encryption
X-Edge
Cross-Origin-Opener-Policy
X-FTR-Request-ID
X-Midtier
X-PC
X-Vname
X-TtlSet
Nginx-Cache
X-Mcache
X-MS-InvokeApp
X-Mod-Pagespeed
X-ECACHE
X-Upstream
X-Powered-By-Plesk
X-ESI
X-Server-Name
Edge-Control
X-NWS-LOG-UUID
X-Browser-Type
X-Cnection
X-Times
X-D2id
X-Element-Page-Cache
Verso
X-Exp-Variant
X-Exp-Id
X-Kinja-Revision
X-Cdn-Fetch
X-Kinja-Build
X-Kinja
X-GoogleNews-Bot
X-Kinja-Server
X-Ruxit-Js-Agent
X-Ac
SPIisLatency
X-Ser
SPRequestDuration
AR-Request-ID
AR-SID
AR-PoweredBy
AR-ATIME
X-SharePointHealthScore
SPRequestGuid
X-GitHub-Request-Id
X-Navigation-Version
X-Abt-Application-Version
X-Dw-Request-Base-Id
X-RateLimit-Remaining
X-B3-TraceId
X-Ttl
X-Vcap-Request-Id
X-NF-Request-ID
AR-CACHE
X-Mg-S
X-Server-ID
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
S
Display
Pagespeed
X-Sol
X-Middleton-Display
X-Client-IP
Edge-Cache-Tag
X-VARITI-CCR
X-Cache-Key
Fastly-Restarts
X-Amzn-Trace-Id
RTSS
X-Amz-Rid
X-Cache-TTL
X-Erf-Bev-Bev-Is-Generated
Cache-Status
X-Instrumentation
X-Erf-Bev-Bev
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Powered-CMS
X-Kinsta-Cache
X-Edge-Location-Klb
X-Version
Access-Control-Request-Method
X-Goog-Hash
X-Daa-Tunnel
X-Recruiting
Response
X-Middleton-Response
X-Content-Digest
X-ARC
X-Webkit-Csp
X-Forwarded-For
X-TraceId
X-Varnish-TTL
X-T
Arr-Disable-Session-Affinity
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-MSEdge-Ref
Content-MD5
Cross-Origin-Resource-Policy
MS-Author-Via
X-SRCache-Fetch-Status
X-SRCache-Store-Status
MicrosoftSharePointTeamServices
TP-Cache
Front-End-Https
X-Shield-Request-Id
X-Accel-Expires
X-Hits
X-Cached
X-FTR-Backend-Server
X-FTR-Balancer
Public-Key-Pins
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Backend
Server-Node
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Hub-Id
X-FTR-Expires
X-Request-Processing-Time
X-Ua-Browser
X-Request-Received
X-Forwarded-Proto
X-Id
X-FastCGI-Cache
Payment
X-Content-Security-Policy-Report-Only
X-Frontend
X-DIS-Request-ID
Realpath
X-LLID
X-Protected-By
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-Fastcgi-Cache
Origin-Trial
X-RateLimit-Limit
X-Distributor
X-Hostname
X-ORACLE-DMS-RID
X-GUploader-UploadID
TP-L2-Cache
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-LB-Cache
Cache-Tags
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Microsite
X-Request-Handler-Origin-Region
X-Debug-Info
X-Origin-Server
Referer-Policy
Host
X-Page-Id
X-Envoy-Decorator-Operation
Mrf-Cache-Status
X-Activity-Id
X-AppVersion
X-Az
MRF-Tech
X-B3-TraceId-Primal
Fastcgi-Cache
Count-Hit
X-Cluster-Name
X-NGENIX-Cache
X-Geo-Country
X-Www-Served-By
X-Varnish-Backend
X-Varnish-Server
Accept-Charset
X-Correlation-Id
X-Ratelimit-Limit
X-App-Server
X-F-Cache
X-Ua-Device
X-PressLabs-Stats
X-Fastly-Request-ID
X-XRDS-LOCATION
X-Varnish-Ttl
X-Ezoic-Cdn
Retry-After
X-FB-Debug
TCN
X-Load-Cache
X-Goog-Metageneration
X-ORACLE-DMS-ECID
X-Upgrade-Enabled
X-CSRF-Token
X-Px
Access-Control-Allow-Method
X-Git-Hash
X-Seen-By
X-Webkit-CSP
Server-Name
X-RateLimit-Reset
X-Amz-Meta-S3cmd-Attrs
X-Tt-Trace-Host
Cleartype
X-Tt-Trace-Tag
Section-Io-Cache
X-TEC-API-ORIGIN
X-Revision
X-TEC-API-VERSION
X-Request-Guid
X-TEC-API-ROOT
X-Contextid
X-Cache-Control
X-Trace-Id
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Grace
X-Datadog-Parent-Id
X-Content-Options
X-B
X-Oracle-Dms-Ecid
X-Type
Charset
X-B3-Sampled
Paypal-Debug-Id
X-Whom
Healthy
X-TT
DC
X-Fb-Rlafr
X-Azure-Ref
X-Wix-Request-Id
X-Proxy
X-Signature
X-B-Cache
X-App-Environment
X-Node-Name
X-Mobile
X-Air-Pt
X-Magnolia-Registration
X-Origin-Cache
Accept-Ch
X-Newrelic-App-Data
X-N
X-Oracle-Dms-Rid
Frame-Options
X-Ratelimit-Remaining
X-Amz-Replication-Status
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-EdgeConnect-Cache-Status
Filterid
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-TTL
X-Goog-Generation
X-Logged-In
X-Fastly-Request-Id
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-WebKit-CSP-Report-Only
Backend
X-Time
Content-Disposition
NGB
Viewport
X-Original-Request-Id
Akamai-GRN
X-Response-Served-From
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Is-Bot
X-Rendered-As
X-Tumblr-User
X-Varnish-Grace
Ms-Operation-Id
X-Tumblr-Pixel
MS-CV
X-Unique-Id
X-ProcessESI
X-Rid
X-Tumblr-Pixel-0
Liferay-Portal
X-Hl-Ver
X-Cache-Age
X-Yottaa-Optimizations
X-Servername
X-RTag
SD-X-WS
X-RemovedCookies
X-Debug-IsConnected
X-Tumblr-Pixel-1
X-Datadog-Sampled
X-Yottaa-Metrics
X-Debug-IsPreview
X-Adobe-Loc
X-Debug
X-FW-Version
X-FW-Dynamic
X-FW-Hash
X-Amzn-Remapped-Content-Length
X-Adobe-Content
X-Backend-Name
X-FW-Static
X-FW-Server
X-FW-Serve
X-FW-Type
X-UUID
X-IPS-LoggedIn
X-Language
X-Instance
Upgrade-Insecure-Requests
X-Via-JSL
X-NYM-Debug-Backend
X-L-Path
X-Cacheable-TTL
X-Cache-Grace
Fastly-SWR
X-G
Fastly-SIE
X-Environment-Context
ServerID
X-Proxy-Cache-Info
From-Origin
X-Region
X-B3-Traceid
X-Device-Type
X-User-Agent
Country
X-Rule
X-Template
Refresh
X-Cache-Hit
X-Aspnet-Duration-Ms
X-Is-Crawler
X-Providence-Cookie
X-Status
X-Flags
X-VC-Cache
X-Route-Name
Url
X-INCAP-ABP
Version
X-B3-SpanId
Countrycode
X-Source
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
X-Cache-Status-Check
GEO-INFO
X-HTML-Minification-Powered-By
X-App-Version
Alternate-Protocol
SRV
X-NODE
X-Jobs
X-Storage
CDN-RequestId
WPO-Cache-Status
WPO-Cache-Message
X-WP-CF-Super-Cache-Active
X-Nginx-Cache
X-Air-Hostname
X-Air-Trace-Id
X-Air-Source
OT-Force-Account-Verify
Amp-Access-Control-Allow-Source-Origin
X-Akamai-Request-ID2
X-Real-IP
X-CDN-Forward
X-Origin-TTL
X-Origin-CC
X-Content-Powered-By
Protected
X-Rocket-Nginx-Serving-Static
Surrogate-Key
X-VC
X-Hosted-By
X-Accel-Version
X-ServerID
Access-Control-Request-Headers
X-Cache-Time
CF-IPCountry
X-Handled-By
X-Akamai-Edgescape
AMP-Access-Control-Allow-Source-Origin
X-Cache-Rule
X-Use-Mantle
X-Cache-Operation
X-Kinja-CCPA
X-Mode
X-Upstream-Ct
X-Platform-Router
Webserver
X-Platform-Processor
Xet-Cookie
X-Platform-Cluster
X-Xfnlog-Site
X-Edge-Location
Filters
Meta-Geo
X-Endurance-Cache-Level
X-Page-View
X-Upstream-Ht
X-Rn-Rsrv
X-UPSTREAM-Address
X-Framework
X-Rewrite-Enabled
X-JoinUs
X-SaId
X-Origin
X-Proxy-Build
Cross-Origin-Embedder-Policy
X-AWS-Id
X-Soup
X-LJ-Flow-ID
X-Cache-Debug
X-Served-From
X-Detected-As
X-Tumblr-Pixel-2
X-Director
Section-Io-Id
X-Varnish-Cache-Hits
X-Tumblr-Pixel-3
Selected-Fe
ServedBy
X-Timing-Wait
X-VWS-Id
X-BYPASS-REASON
X-Origin-Hint
X-Extlb
X-Cluster
X-No-Session
X-Cms-Context
X-Sucuri-Cache
X-Drupal-Cache-Tags
X-Lambda-Id
TWC-Locale-Group
TWC-Privacy
Property-Id
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-LatLong
TWC-GeoIP-Country
Node
Mn-Server-Ip
X-Labrador-Cache-Channel
Webcakes-Region
Webcakes-App-Version
Front
Web-Mar-Node
Webcakes-App-Name
X-Adobe-Source
X-Proxied
X-PHP-Host
X-Logging-Id
Accept-Language
X-Zipkin-Id
X-SayCDN-TTL
X-Web-Node
X-Vcache
X-Redis-Cache
X-Webstats-RespID
X-Worker
X-Say-Cacheable
X-Say-TTL
X-Routing-Service
X-ProxyCache-Key
X-Restarts
X-ProxyCache-Status
X-IPLB-Request-ID
X-S
X-VCT
X-Skip-Cache
X-Format
X-Is-Desktop
X-Drupal-Cache-Contexts
X-Tcp-Rtt
X-Browser-Name
X-AB
X-Tncms
X-Varnish-Age
X-Is-Supported-Browser
X-RM-Cache-TTL
X-Varnish-Beresp-Grace
X-IPLB-Instance
X-Is-Mobile
Azure-SiteName
Azure-SlotName
Azure-Version
Azure-RegionName
Azure-InstanceId
X-GeoCode
Apigw-Requestid
X-Locale
X-Loop
X-Site-Version
X-Is-Tablet
X-Geo-Region
X-RCS-CacheZone
X-GeoCountry
X-Reqid
X-Alternate-Cache-Key
X-Generation-Time
X-Shopify-Stage
X-Cache-Host
X-Git-Commit
X-Cache-Server
X-Forwarded-Host
X-Container-Uri
X-Vercel-Cache
CDN-RequestCountryCode
CDN-RequestPullCode
X-Httpd
X-Sucuri-ID
CDN-PullZone
X-Origin-Date
CDN-EdgeStorageId
CDN-Cache
X-R9-Blue-Green-Version
Xserver
X-Vercel-Id
X-Tb
X-Storefront-Renderer-Rendered
CDN-RequestPullSuccess
X-Fetched-On
CDN-Uid
CDN-CachedAt
X-Ms-Request-Id
X-Provided-By
X-Frame-Option
X-Ms-Version
DB-Nickname
X-TT-LOGID
X-Sorting-Hat-ShopId
Atl-Traceid
X-Sorting-Hat-PodId
X-ShopId
X-ShardId
X-Server-W
X-XRDS-Location
WP-Super-Cache
X-Cdn-Origin
X-MP-GENERATED-AT
X-Uri
X-Http-Reason
Cross-Origin-Embedder-Policy-Report-Only
Fastcgi-Useragent
Cache-Tv-Group
Source
X-Vcl-Version
X-Xrds-Location
X-Generated-By
Sid
X-FB-TRIP-ID
X-Pass-Why
Content-Secure-Policy
X-DynaTrace
Cross-Origin-Window-Policy
X-Scope-Id
X-CMSURLCustom
X-Thinkindot-L3
X-Shield-Cache-Expires
X-Buckets
Thinkindot-CacheControl-Type
Priority
TDXMobile
Thinkindot-Control
Thinkindot-CacheControl
Onion-Location
X-DataDome
Cache
X-Urbn-Site-Id
X-Urbn-Context-Path
X-Azure-Ref-OriginShield
Locale
X-SRV
X-LSADC-Cache
X-Content-Age
X-RID
HostName
X-Sql-Duration-Ms
X-Sql-Count
X-Varnish-Beresp-Ttl
X-WP-CF-Super-Cache-Cookies-Bypass
X-Optimistic-Header
X-GEO
X-TA-CDN-Provider
X-Cluster-Node
X-Proxy-Cache-Status
X-Cache-Action
X-Newrelic-Synthetics
X-Dc
Expiry
X-UA
WZWS-RAY
X-Connection-Hash
X-Request-URI
User-Cache-Control
Lang
X-Aed
Fastly-Drupal-HTML
X-External-Request-Id
X-A-Wwc
X-Instance-Name
X-A-Dam
X-A-Ccd
X-A-Dcw
X-A-Dgt
A
MD5-Digest
Meta-Geo-Continent
X-Ec-Custom-Error
X-Cache-NE
X-B-Cookie
X-Conf
Magicmarker
X-Cache-Bucket
X-Bc-Bl
X-BCube-Filmed-By
X-D
X-Application
X-Bl-Debug
X-Ec-Fail
X-Ec-GeoHdr
X-Dispatcher-Server
X-Developer
X-A
X-Destination
X-Epic-Correlation-Id
Gannett-Cam-Experience-Id
X-Scheme
X-ScT
Origin
Server-Host
X-SB
X-S-Cookie
Sslversion
Sever-Int
Server-Hostname
X-Rojux
Server-Ext
X-Vdms-Version
Origin-Agent-Cluster
DCR-Decision-By
DCR-Processing-Time-Ms
X-Varnish-Hostname
X-TIM-N
Redirect-Candidate
X-Vdms-Path
Req-ID
X-SRCache-Key
Rendered-Blocks
X-Viewer-Country
X-Request-Start
Vix-Hermes-Req-Id
Ngx.Var.Host
X-PAYTM-SRV-ID
X-Correlation-ID
Candidate-Md5Url
Ngx-Var-Key
X-ND-Cache
X-Platform
X-Op-Id-All
T-Server
Surrogated-Key
X-Vtex-Remote-Cache
X-TimeS
X-Amz-Storage-Class
Ssr
Wxu-Next-Hostname
Wxu-Next-Region
Wxu-Next-Commit
Locid
Pramga
Req-Svc-Chain
V-Age
NM-Fastcgi-Cache
X-AK-Request-ID
X-Amz-Meta-Cb-Modifiedtime
X-B3-Trace-ID
X-Auto-Login
X-BBC-Edge-Cache-Status
X-Acquia-Purge-Cdn-Unconfigured
X-Access
X-Human
X-Sigma
X-Section
X-Sigma-Backend
X-TH-Server
X-Thanos
X-SD-PageType
X-Rocket-Build-Number
X-Proxied-Request
X-Pool
X-Pubstack
X-Req
X-Request-Time
X-UA-Device-Type
X-Varnish-Beresp-Status
C-Via
X-Zen-Fury
DSUID
Release
Yak-Timeinfo
X-We-Are-Hiring
X-WA-Info
X-Varnishpool
X-Varnish-Director
X-VG-TLSProxy
X-VG-WebCache
X-VServer
X-Origin-Time
X-Nyt-Route
X-Fastly-Cache
X-Esi-Check
X-Forwarded-Site
X-Gdpr
X-Gen-Mode
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Cache-Id
X-Block-Status
X-Cache-TTL-Remaining
X-Clientip
X-Core-Value
X-Generated-On
X-GeoIP-Country-Code
X-NCache
X-Mly-Id
X-Nginx-Cache-Key
X-NMSegId
X-Node-Id
X-Loc
X-Level-Front-Cache
X-GeoIP-Region-Code
X-Gzip
X-Hnp-Log
L
X-Bip
X-Cache-Info
X-Cache-Expired-At
Cluster
Content-Script-Type
Content-Style-Type
Environment
Cdnsip
Cdncip
Apple-News-Services-Handled
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
CDCHOST
Fastly-GeoIP-CountryCode
Apple-News-Services-Request-Url
Host-ID
Fastly-SSL
Edge-Copy-Time
X-Via-Edge
X-Lagoon
X-Via-SSL
X-Via-CDN
X-Service
X-Origin-Response-Time
LB
X-Server-IP
X-ApacheServer
X-Aicache-OS
X-Branch-Name
X-Ad-Load-Variation
X-PERF
X-Request-Host
X-Cache-Aspx
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Backend-Instance
X-Policy
X-Region-Sid
X-Org
X-GeoIP
X-GeoIP-City
X-Contensis-Viewer-Groups
X-Geo-Header
X-From
X-Device-Os
X-FC-Vary-Parameters
X-Fmm-Version
X-GoCache-CacheStatus
X-HN
X-Mvc-Supplant-Cachable
X-Old-Content-Length
Is-Eu
X-Micro-Cache
X-Cdn-Srv
X-HS-Content-Campaign-Id
X-ECache
X-Men
X-Origin-Expires
Adler-Geo
Gh-Request-Id
X-Moov-Xdn-Version
RNT-Time
RNT-Machine
On-Server
S-Rt
X-SVT-ORM-RULES
XM
Click-Count-Error
Mail-Subject
X-Moov-T
Country-Code
Platform
Tube-Return
PFcat
Esi-Enabled
X-Cache-Date
Producers
Tube-Get-Contents
Tube-Got-Eval
Tube-Got-Results
Machine
Click-Count-Action-Start
Web-Mar-Region
We-Hiring
X-Var-Ttl
X-SVT-ORM-VERSION
True-Client-Country-4JS
X-DPWN-IS-SECURE
Cache-Provider
X-V-Cache
X-Varnish-Authentication
Canary
Uber-Trace-Id
X-VarnishDD-TTL
X-Datadome
X-Test
X-Sn-Servicetimems
X-API-Version
X-Fastly-Backend
X-Edge-Server
X-Cache-Backend
X-Eu-Site
X-Slack-Shared-Secret-Outcome
X-Proto
X-DC
X-Ratelimit-Reset
X-Wikidot-Backend
X-Slack-Backend
X-Mvc-Supplant-OutputCached
X-Wikidot-Static-Cache
X-Up
X-Hash
W
X-CGP
Cache-Key
AKAMAI
X-Csrf-Jwt
X-App-Name
Cdn-Request-Time
Cdn-Host
HA-Ipaddr
Ha-Gx-Prefs
L5d-Success-Class
Proxy-Firewall
Cf-Device-Type
X-Tx-Id
X-Mg-Request-UUID
X-LB-ID
X-VCache
X-CacheTTL
X-Accel-Expires-Debug
X-Parent-Response-Time
Fastly-Backend-Name
X-Ah-Environment
Type
X-Date
X-Ua
X-Varnish-Hits
X-Tb-Optimization-Total-Bytes-Saved
NGX
X-Servedbyhost
X-COUNTRY
Cache-Hits
X-HA-Backend
X-Via-Popn
X-CACHE-GROUP
X-DynaTrace-JS-Agent
Pics-Label
X-Via-Poph
X-Via-Popv
X-Nf-Request-Id
Cdn
X-Zone
X-Srv
X-Refresh
X-LB-NoCache
NtCoent-Length
X-Via-Fastly
X-Irp-Debug
X-VHOST
Datacenter
X-Owner
X-Cloudmap
Cdn-Requestid
X-NGINX-Cache
X-Core-Mission
X-ZONE
GeoIp-Country-Code
X-SIPLIST1
X-Ig-Origin-Region
X-CDN-Cache-Status
IsBot
X-Location
Server-ID
X-Nc
X-Wa
X-PDP-UNCACHING-HASH
Fusion-Component-Id
SID
Fusion-Content-Id
Fusion-Template-Id
X-Akamai-Transformed
Fusion-Source
Fusion-Deployment-Id
Fusion-Content-Source
Resin-Trace
X-NWS-UUID-VERIFY
Cross-Origin-Opener-Policy-Report-Only
Powered-By
X-Fpc
X-Qloud-Router
GeoIP-Latitude
X-CUA
Origin-CC
X-CF-Lambda-Fn
X-Jungle-Id
X-B3-Parentspanid
N-Cache
Expect-Staple
Origin-EX
X-CF-Lambda-Version
X-Nananana
X-Hit
DataCenter
X-TX-ID
X-Tt-Logid
X-Orig-Expires
X-Cache-Type
CloudFront-Viewer-Country
X-Forwarded-Path
XkeyRZ
X-Proxy-CacheRZ
X-User
Xc-Version
X-NewRelic-App-Data
X-Tenant
X-Shop-Environment
X-Client-Ip
Cmsid
X-URL
Cmstype
X-DataCenter
X-Segment-20210421
Uri
X-CS
X-Gamma-Serve
X-Presslabs-Stats
User-Agent
X-TIME
X-Amz-Meta-Opti
X-IAuth-Set-Uid
CPC-Cache
CPC-Age
True-Client-Ip
X-Render-Time
X-Cached-By
MIME-Version
X-Wormhole-Sdk
X-VTEX-Cache-Time
Debug
Mime-Version
X-B3-Spanid
X-Vmg-Version
X-Powered-By-VTEX-Cache
X-Esi
X-Cdn-Diag
X-VTEX-Cache-Server
X-Info
X-LiteSpeed-Tag
X-Fastly-Country-Code
Fastly-Drupal-Html
True-Client-IP
X-CACHE-AGE
X-Geo
Edge-Cache
X-Auth-Group-Type
X-Dynatrace-Js-Agent
X-Dispatch
X-Oracle-DMS-ECID
CDN
X-Datacenter
X-LAGOON
Load-Balancing
Cf-Ipcountry
Srv
CacheControlHeader
X-HOST
X-Variation
X-Ig-Push-State
X-Vc
X-Varnish-Beresp-TTL
X-Cs
X-LiteSpeed-Cache-Control
Ohc-File-Size
Odigeo-Trace-Id
X-Webkit-Csp-Report-Only
X-Cdn-Forward
X-Vgn-Hpd-Reason
X-Custom-Header
Cl-Cache
X-NodeID
X-CSRF-TOKEN
Hostname
X-AIR-PT
X-PHP-Backend
Tcn
X-APP-VERSION
X-MCACHE
X-Pad
X-Depends
VNS-Age
VNS-Cache
GeoIP-Country-Code
X-FPC
Ohc-Cache-HIT
X-DefElseHash
X-Varnish-Remaining-TTL
X-Cdn-Cache-Status
X-NC
X-DefHash
Server-Id
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-WA
X-HostName
X-M-Log
X-Lb-Nocache
X-VC-TTL
X-M-Reqid
X-VCL-Version
X-Dispatcher-Number
X-Api-Version
X-Cache-Ttl
X-Cache-FS-Status
X-Fastly-Backend-Reqs
X-Litespeed-Tag
X-Via-PopH
X-Via-PopV
PICS-Label
X-Via-PopN
X-Ha-Backend
X-MSEdge-Features
Epwk-X-Cache
X-MSEdge-Flight
Geoip-Latitude
Lb
X-ServedByHost
CountryCode
X-Litespeed-Cache-Control
X-Srcache-Store-Status
X-Srcache-Fetch-Status
X-Use-Magma
X-Lb-Id
X-MiniProfiler-Ids
Cloudfront-Viewer-Country
Ngx
X-Proxy-Cache-La3
Xkeylog
X-Cdn-Request-ID
X-APP
Xkey-La3
Cache-Name
X-Snapshot-Date
X-IN-APIGATEWAY
X-Mid
X-IN-APIGATEWAYSSL
OriginIP
X-RequestId
X-Acquia-Purge-Tags
X-Acquia-Site
X-Acquia-Application-UUID
X-Acquia-Application-Trace
Time
Memory
Memcached
X-Web-Server
X-Sorting-Hat-Shopid
X-Sorting-Hat-Podid
X-Shopid
X-Shardid
X-Cache-Version
Server-Info
Warning
X-Requestid
FSS-Cache
X-App
X-Ramcache
X-Mg-Cache
X-Serial
X-Service-Response-Time
X-Check-Cacheable
X-Akamai-Pragma-Client-IP
Sm-Log-Id
X-Dw-Trace-Id
X-Udemy-Cache-App-Namespace
X-Sucuri-Id
X-Th-Server
X-Wp-Cf-Super-Cache-Cookies-Bypass
Akamai-Cache-Status
CF-Cached-On