Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
X-Frame-Options
Expires
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
CF-RAY
ETag
Accept-Ranges
Expect-CT
X-XSS-Protection
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Xss-Protection
X-Served-By
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
X-AspNet-Version
Content-Security-Policy-Report-Only
X-Runtime
Accept-CH
X-Drupal-Cache
X-Cache-Status
Accept-CH-Lifetime
X-DNS-Prefetch-Control
P3p
X-Generator
X-Check
X-Ua-Compatible
Server-Timing
X-Cacheable
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Iinfo
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
X-Content-Security-Policy
Feature-Policy
X-Request-ID
X-CDN
Content-Encoding
Status
X-AspNetMvc-Version
Upgrade
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
X-Amz-Id-2
CF-Ray
Host-Header
Cf-Edge-Cache
X-Backend
X-UA-Device
Keep-Alive
Request-Context
X-Dns-Prefetch-Control
X-Robots-Tag
X-Server
X-Cache-Group
Allow
EagleId
X-Hacker
X-AH-Environment
X-Turbo-Charged-By
X-Ws-Request-Id
X-Proxy-Cache
Xkey
X-Age
X-Rq
X-Vhost
X-Dispatcher
X-Amz-Version-Id
X-Server-Powered-By
X-Varnish-Cache
Grace
Cf-Apo-Via
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Page-Speed
X-Pingback
Permissions-Policy
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
Cf-Railgun
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Backend-Server
X-WebKit-CSP
X-CST
X-Cache-Lookup
X-Host
X-Server-Id
X-Aws-Lambda-Call-Status
X-Readtime
X-Response-Time
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-HW
X-Nginx-Upstream-Cache-Status
Accept-Ch-Lifetime
X-Cloud-Trace-Context
X-Node
X-Litespeed-Cache
X-Nginx-Cache-Status
X-Application-Context
Content-Location
X-Country-Code
X-Country
X-Ruxit-JS-Agent
Service-Worker-Allowed
X-Trace
X-Url
X-Content-Type
X-Clacks-Overhead
X-Oneagent-Js-Injection
Cache-Tag
Rating
X-Rack-Cache
X-Amz-Server-Side-Encryption
X-FTR-Request-ID
Nginx-Cache
X-TtlSet
X-Vname
X-PC
Cross-Origin-Opener-Policy
X-Mcache
X-Edge
X-NWS-LOG-UUID
X-Midtier
X-Times
X-MS-InvokeApp
X-Origin-Cache-Key
X-Server-Name
X-Mod-Pagespeed
X-Upstream
X-ECACHE
X-Powered-By-Plesk
X-Browser-Type
Edge-Control
X-Cnection
X-D2id
X-Element-Page-Cache
X-Kinja-Build
X-Kinja-Revision
X-ESI
X-GoogleNews-Bot
X-Exp-Id
X-Cdn-Fetch
X-Kinja-Server
X-Exp-Variant
X-Kinja
X-Ser
Verso
AR-PoweredBy
AR-Request-ID
AR-SID
AR-ATIME
X-RateLimit-Remaining
X-Ac
SPRequestDuration
SPIisLatency
SPRequestGuid
X-SharePointHealthScore
X-GitHub-Request-Id
X-Ruxit-Js-Agent
X-NF-Request-ID
X-B3-TraceId
X-Navigation-Version
X-Abt-Application-Version
X-Vcap-Request-Id
X-Dw-Request-Base-Id
AR-CACHE
X-Mg-S
X-Client-IP
X-Sol
Display
X-Middleton-Display
Pagespeed
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
Edge-Cache-Tag
S
X-Daa-Tunnel
X-Ttl
X-Webkit-Csp
Fastly-Restarts
X-Cache-Key
X-Cache-TTL
X-VARITI-CCR
X-Erf-Bev-Bev
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Amz-Rid
X-Amzn-Trace-Id
Cache-Status
X-Powered-CMS
X-Edge-Location-Klb
RTSS
X-Kinsta-Cache
X-Version
Access-Control-Request-Method
X-Varnish-TTL
X-Middleton-Response
Response
X-Goog-Hash
X-Server-ID
X-Recruiting
X-FastCGI-Cache
X-Content-Digest
X-TraceId
X-ARC
X-Forwarded-For
X-T
Arr-Disable-Session-Affinity
X-MSEdge-Ref
MS-Author-Via
Cross-Origin-Resource-Policy
Content-MD5
MicrosoftSharePointTeamServices
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Front-End-Https
TP-Cache
X-RateLimit-Limit
X-Shield-Request-Id
X-FTR-Backend-Server
X-FTR-Backend
X-Country-Code-Real
X-FTR-Balancer
X-FTR-Cache-Status
Realpath
X-Id
X-Forwarded-Proto
X-Cached
X-Hits
X-Accel-Expires
X-Ua-Browser
X-Request-Received
X-FTR-Expires
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
X-Request-Processing-Time
X-HS-Combine-CSS
X-Fastly-Request-ID
X-ORACLE-DMS-RID
Server-Node
Payment
Public-Key-Pins
X-Frontend
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-Protected-By
X-LLID
X-HP-Webp
X-HP-Trace-Id
X-Jurisdiction
X-DIS-Request-ID
X-Distributor
X-Content-Security-Policy-Report-Only
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Correlation-Id
X-GUploader-UploadID
X-ORACLE-DMS-ECID
X-LB-Cache
X-XRDS-LOCATION
TP-L2-Cache
Fastcgi-Cache
X-Microsite
X-Request-Handler-Origin-Region
Cache-Tags
Count-Hit
Referer-Policy
X-Amz-Apigw-Id
X-Amzn-RequestId
X-AppVersion
X-Az
X-Activity-Id
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-NGENIX-Cache
X-Cluster-Name
X-Envoy-Decorator-Operation
X-Hostname
X-Www-Served-By
Host
X-Debug-Info
X-Varnish-Server
X-Varnish-Backend
Accept-Charset
X-Page-Id
X-Geo-Country
X-Origin-Server
X-App-Server
X-Ezoic-Cdn
X-PressLabs-Stats
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
Retry-After
X-F-Cache
X-Px
X-Load-Cache
X-RateLimit-Reset
Origin-Trial
X-Goog-Metageneration
X-FB-Debug
X-CSRF-Token
X-Upgrade-Enabled
X-Seen-By
X-Amz-Meta-S3cmd-Attrs
Server-Name
X-Ratelimit-Limit
Cleartype
Access-Control-Allow-Method
X-Git-Hash
X-Fastcgi-Cache
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Request-Guid
TCN
X-Cache-Control
Section-Io-Cache
X-Grace
X-Azure-Ref
X-TT
X-B
X-B3-Sampled
X-Webkit-CSP
X-TTL
X-Revision
Paypal-Debug-Id
Healthy
X-Trace-Id
X-Whom
X-Contextid
DC
X-Type
X-Proxy
X-Datadog-Sampling-Priority
X-Fb-Rlafr
X-Datadog-Parent-Id
X-Datadog-Trace-Id
Charset
X-Content-Options
X-Wix-Request-Id
X-Mobile
X-Newrelic-App-Data
X-N
X-App-Environment
X-B-Cache
X-Signature
X-Node-Name
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-Varnish-Ttl
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
Accept-Ch
Filterid
X-Magnolia-Registration
X-Amz-Replication-Status
X-Oracle-Dms-Ecid
X-Origin-Cache
X-Goog-Generation
Frame-Options
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Time
X-Air-Pt
X-Logged-In
Viewport
X-EdgeConnect-Cache-Status
NGB
X-Unique-Id
X-Debug
X-Oracle-Dms-Rid
Content-Disposition
X-Cache-Grace
X-Tumblr-Pixel-0
X-Is-Bot
X-RemovedCookies
X-Rendered-As
X-Tumblr-User
X-ProcessESI
X-Tumblr-Pixel-1
X-Debug-IsPreview
X-Debug-IsConnected
X-Tumblr-Pixel
X-Adobe-Loc
X-Yottaa-Metrics
Backend
X-Datadog-Sampled
X-Yottaa-Optimizations
X-Varnish-Grace
X-G
VIX-Pulpo-Upstream-Status
Fastly-SIE
MS-CV
Ms-Operation-Id
SD-X-WS
X-RTag
Liferay-Portal
X-Servername
VIX-Pulpo-Node
X-Adobe-Content
Fastly-SWR
X-NYM-Debug-Backend
X-IPS-LoggedIn
X-FW-Dynamic
X-FW-Static
X-FW-Serve
X-FW-Server
X-FW-Hash
X-FW-Type
X-Cache-Age
X-Instance
X-Amzn-Remapped-Content-Length
X-FW-Version
X-UUID
X-Backend-Name
ServerID
X-Cacheable-TTL
From-Origin
X-VC-Cache
X-Original-Request-Id
X-Hl-Ver
X-Response-Served-From
X-WebKit-CSP-Report-Only
X-Region
X-Proxy-Cache-Info
X-User-Agent
X-Via-JSL
X-Device-Type
Upgrade-Insecure-Requests
X-Rule
X-L-Path
X-Cache-Hit
X-Environment-Context
Version
X-Ratelimit-Remaining
Akamai-GRN
X-Ua-Device
X-Status
Country
X-B3-SpanId
X-Source
Refresh
X-INCAP-ABP
X-Template
Countrycode
SRV
GEO-INFO
X-Storage
Url
CDN-RequestId
X-Language
X-HTML-Minification-Powered-By
X-Rid
X-Air-Trace-Id
X-Air-Source
OT-Force-Account-Verify
X-Air-Hostname
X-WP-CF-Super-Cache-Active
X-Cache-Status-Check
Alternate-Protocol
AMP-Access-Control-Allow-Source-Origin
X-NODE
X-Real-IP
WPO-Cache-Message
X-Origin-CC
X-App-Version
WPO-Cache-Status
X-Origin-TTL
X-CDN-Forward
X-ServerID
X-B3-Traceid
X-Jobs
X-Fastly-Request-Id
X-VC
X-Akamai-Request-ID2
Surrogate-Key
X-Is-Crawler
X-Flags
X-Aspnet-Duration-Ms
X-Sucuri-Cache
X-Providence-Cookie
X-Route-Name
Access-Control-Request-Headers
X-Cache-Time
X-Content-Powered-By
X-TT-LOGID
X-Sucuri-ID
Protected
X-Handled-By
X-Mode
Amp-Access-Control-Allow-Source-Origin
X-Rocket-Nginx-Serving-Static
Xet-Cookie
X-Accel-Version
X-Endurance-Cache-Level
X-Hosted-By
X-Rn-Rsrv
Meta-Geo
Filters
X-Xfnlog-Site
X-Upstream-Ht
X-UPSTREAM-Address
X-Rewrite-Enabled
Webserver
X-Upstream-Ct
X-Akamai-Edgescape
X-RM-Cache-TTL
Front
X-Tumblr-Pixel-3
X-Tumblr-Pixel-2
Cross-Origin-Embedder-Policy
X-Timing-Wait
X-SaId
X-Adobe-Source
X-Edge-Location
X-Drupal-Cache-Tags
X-JoinUs
X-LJ-Flow-ID
X-Origin
X-VWS-Id
X-Detected-As
X-Proxy-Build
X-AWS-Id
X-Cache-Debug
X-Worker
Selected-Fe
X-Webstats-RespID
X-Nginx-Cache
X-No-Session
X-Logging-Id
X-Cms-Context
X-Origin-Hint
X-PHP-Host
X-Routing-Service
X-Restarts
X-Proxied
X-Labrador-Cache-Channel
Atl-Traceid
X-Cache-Operation
X-Cache-Rule
TWC-Device-Class
X-Extlb
X-Director
X-Drupal-Cache-Contexts
X-Framework
X-Cluster
X-Redis-Cache
TWC-Locale-Group
Section-Io-Id
Property-Id
TWC-Privacy
Node
TWC-GeoIP-LatLong
ServedBy
TWC-Connection-Speed
X-Zipkin-Id
X-Web-Node
TWC-GeoIP-Country
Mn-Server-Ip
Web-Mar-Node
Webcakes-Region
X-Served-From
Webcakes-App-Version
Webcakes-App-Name
X-Browser-Name
CDN-Uid
Apigw-Requestid
X-AB
X-Forwarded-Host
X-Geo-Region
CDN-RequestCountryCode
X-BYPASS-REASON
CDN-CachedAt
CDN-Cache
CDN-PullZone
CDN-RequestPullCode
CDN-EdgeStorageId
CDN-RequestPullSuccess
X-IPLB-Request-ID
X-Skip-Cache
X-Soup
X-Site-Version
X-RCS-CacheZone
X-ProxyCache-Status
X-Tb
X-Tcp-Rtt
X-VCT
Xserver
X-Varnish-Cache-Hits
X-Varnish-Age
X-Tncms
X-ProxyCache-Key
X-S
X-Is-Mobile
X-Is-Desktop
X-Is-Supported-Browser
X-Is-Tablet
X-Locale
X-Origin-Date
X-Lambda-Id
X-IPLB-Instance
X-RID
X-Loop
X-Storefront-Renderer-Rendered
X-Vercel-Cache
X-Fetched-On
X-Httpd
X-Vercel-Id
X-Shopify-Stage
X-Cdn-Origin
X-Git-Commit
X-Reqid
X-R9-Blue-Green-Version
X-Cache-Host
X-Say-Cacheable
X-SayCDN-TTL
X-Alternate-Cache-Key
X-Say-TTL
X-Container-Uri
X-Generation-Time
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
Azure-SiteName
Azure-SlotName
Azure-Version
X-Platform-Cluster
X-Ms-Request-Id
Azure-RegionName
Azure-InstanceId
X-GeoCountry
X-Varnish-Beresp-Grace
X-GeoCode
X-Frame-Option
X-Format
X-Platform-Processor
X-Ms-Version
Accept-Language
X-Platform-Router
X-Provided-By
X-ShopId
X-Cache-Server
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-ShardId
Fastcgi-Useragent
X-Vcache
DB-Nickname
Cross-Origin-Window-Policy
Source
X-Server-W
X-Vcl-Version
X-XRDS-Location
X-Azure-Ref-OriginShield
X-SRV
CF-IPCountry
X-MP-GENERATED-AT
WP-Super-Cache
X-PDP-UNCACHING-HASH
X-Uri
Thinkindot-CacheControl-Type
X-Scope-Id
TDXMobile
X-CMSURLCustom
Sid
X-Thinkindot-L3
Thinkindot-Control
Cross-Origin-Embedder-Policy-Report-Only
Thinkindot-CacheControl
X-Shield-Cache-Expires
X-Generated-By
X-Page-View
Cache
X-Pass-Why
X-UA
Cache-Tv-Group
X-FB-TRIP-ID
X-Buckets
Content-Secure-Policy
X-Optimistic-Header
X-Lagoon
X-LSADC-Cache
HostName
Onion-Location
X-Dc
Locale
X-Urbn-Context-Path
X-Urbn-Site-Id
X-WP-CF-Super-Cache-Cookies-Bypass
X-Datadome
X-Content-Age
X-Use-Mantle
Priority
X-DataDome
X-Http-Reason
User-Cache-Control
X-Xrds-Location
X-GEO
Locid
X-Connection-Hash
X-DynaTrace
Expiry
X-Request-URI
X-Cache-NE
X-ScT
X-Cache-Bucket
X-SRCache-Key
X-BCube-Filmed-By
X-Bc-Bl
X-A-Dam
X-A-Dcw
X-Bl-Debug
X-SB
X-Platform
X-Aed
X-Conf
X-A-Dgt
X-D
X-A-Wwc
A
X-UA-Device-Type
Redirect-Candidate
X-Developer
Req-ID
X-TIM-N
Candidate-Md5Url
X-Vtex-Remote-Cache
Surrogated-Key
X-Vdms-Version
T-Server
Lang
LB
MD5-Digest
Sslversion
Magicmarker
X-A
Gannett-Cam-Experience-Id
DCR-Decision-By
X-Request-Start
X-Rojux
X-Varnish-Hostname
DCR-Processing-Time-Ms
X-Ec-Fail
X-Ec-GeoHdr
X-Cluster-Node
Meta-Geo-Continent
X-Vdms-Path
Server-Ext
X-ND-Cache
Origin-Agent-Cluster
Server-Host
X-A-Ccd
X-Dispatcher-Server
Origin
X-Op-Id-All
Server-Hostname
Ngx-Var-Key
Sever-Int
Ngx.Var.Host
Rendered-Blocks
X-NWS-UUID-VERIFY
Cache-Hits
X-Proxy-Cache-Status
X-Auto-Login
Wxu-Next-Commit
Content-Style-Type
X-B-Cookie
DSUID
Pramga
Cdnsip
Wxu-Next-Hostname
Cluster
Wxu-Next-Region
CDCHOST
Content-Script-Type
X-Req
X-Amz-Meta-Cb-Modifiedtime
NM-Fastcgi-Cache
Cdncip
X-AK-Request-ID
Release
X-S-Cookie
C-Via
True-Client-Country-4JS
Host-ID
X-B3-Trace-ID
X-SD-PageType
X-Application
Vix-Hermes-Req-Id
V-Age
Fastly-SSL
Environment
X-WA-Info
XM
X-External-Request-Id
Yak-Timeinfo
X-Hnp-Log
X-Fastly-Cache
X-Zen-Fury
X-Esi-Check
X-Generated-On
X-Destination
X-Nginx-Cache-Key
X-Cache-Action
X-Epic-Correlation-Id
X-TA-CDN-Provider
X-Gzip
X-GeoIP-City
X-Gdpr
X-GeoIP
X-Varnishpool
X-Gen-Mode
X-NMSegId
X-GeoIP-Country-Code
X-Nyt-Route
X-Forwarded-Site
X-GeoIP-Region-Code
X-Node-Id
X-Viewer-Country
X-Device-Os
X-Origin-Time
X-Clientip
X-Cache-TTL-Remaining
X-Block-Status
X-Debug-Cache-Store
X-Thanos
X-Cache-Id
X-Kinja-CCPA
X-Bip
X-Origin-Expires
X-NCache
X-Debug-Cache-Fetch
X-Varnish-Beresp-Ttl
X-Level-Front-Cache
X-Core-Value
X-Service
X-Cache-Expired-At
X-Origin-Response-Time
X-Moov-T
Ssr
X-Geo-Header
X-Moov-Xdn-Version
X-HN
RNT-Time
X-Loc
X-HS-Content-Campaign-Id
X-Human
RNT-Machine
X-Pubstack
X-GoCache-CacheStatus
X-RateLimit-Limit-Second
X-Men
X-Micro-Cache
We-Hiring
X-Contensis-Viewer-Groups
X-Amz-Storage-Class
X-Ad-Load-Variation
X-Acquia-Purge-Cdn-Unconfigured
X-Org
X-ApacheServer
X-PAYTM-SRV-ID
X-Cache-Aspx
X-Cache-Backend
X-PERF
X-Cdn-Srv
X-Old-Content-Length
X-DPWN-IS-SECURE
X-From
X-Pool
Tube-Return
Tube-Got-Results
Tube-Got-Eval
X-Policy
X-Fmm-Version
X-Ec-Custom-Error
Web-Mar-Region
X-Backend-Instance
X-FC-Vary-Parameters
Tube-Get-Contents
X-SVT-ORM-RULES
X-Request-Time
Country-Code
Click-Count-Error
X-Request-Host
Esi-Enabled
X-Sql-Count
X-We-Are-Hiring
X-VarnishDD-TTL
Click-Count-Action-Start
Canary
X-Aicache-OS
X-Scheme
X-Server-IP
Adler-Geo
X-Sn-Servicetimems
Cache-Provider
X-SVT-ORM-VERSION
X-Mvc-Supplant-Cachable
X-V-Cache
X-TH-Server
X-Sql-Duration-Ms
L
On-Server
Machine
X-RateLimit-Remaining-Second
Mail-Subject
X-Region-Sid
PFcat
X-Var-Ttl
Platform
Gh-Request-Id
Is-Eu
X-Varnish-Authentication
Producers
X-NGINX-Cache
X-VCache
Proxy-Firewall
X-Slack-Backend
X-Slack-Shared-Secret-Outcome
X-CGP
X-BBC-Edge-Cache-Status
X-Varnish-Director
X-Up
X-Wikidot-Backend
X-Fastly-Backend
X-Varnish-Beresp-Status
X-Cache-Info
X-Wikidot-Static-Cache
X-Eu-Site
X-Test
X-Csrf-Jwt
X-Edge-Server
Apple-News-Services-Request-Url
X-Proto
Uber-Trace-Id
X-Instance-Name
Fastly-GeoIP-CountryCode
X-Section
X-Hash
Ha-Gx-Prefs
HA-Ipaddr
X-Mvc-Supplant-OutputCached
Req-Svc-Chain
X-Mly-Id
X-ECache
X-Proxied-Request
L5d-Success-Class
X-VG-WebCache
W
Apple-News-Services-Handled
Apple-News-Services-Host
AKAMAI
X-VG-TLSProxy
X-App-Name
Cf-Device-Type
Apple-News-Services-Parsed-Url
Cdn-Host
X-Access
Cdn-Request-Time
Cache-Key
X-Newrelic-Synthetics
X-Cloudmap
X-Via-Fastly
Fastly-Drupal-HTML
X-LB-ID
X-VServer
X-CacheTTL
NGX
X-Sigma-Backend
X-Rocket-Build-Number
X-Tb-Optimization-Total-Bytes-Saved
X-Cache-Date
X-Sigma
X-Accel-Expires-Debug
Fastly-Backend-Name
X-Date
X-Esi
WZWS-RAY
X-Ah-Environment
X-Mg-Request-UUID
X-DC
X-COUNTRY
X-Ig-Origin-Region
X-Via-Poph
X-API-Version
X-DynaTrace-JS-Agent
Pics-Label
X-HA-Backend
X-Via-Popn
X-Via-Popv
X-Parent-Response-Time
X-Varnish-Hits
X-Branch-Name
X-Tx-Id
X-Zone
X-Location
NtCoent-Length
Datacenter
Fusion-Template-Id
Fusion-Deployment-Id
Fusion-Source
X-CACHE-GROUP
X-Via-SSL
Fusion-Component-Id
X-Refresh
Edge-Copy-Time
Fusion-Content-Source
X-Via-CDN
Fusion-Content-Id
X-Via-Edge
S-Rt
X-Ratelimit-Reset
X-Correlation-ID
X-Wormhole-Sdk
X-CDN-Cache-Status
X-Akamai-Transformed
Type
X-Servedbyhost
GeoIp-Country-Code
X-VHOST
X-Jungle-Id
Powered-By
X-CUA
Cdn
X-ZONE
X-User
Origin-EX
Origin-CC
Resin-Trace
X-Ua
X-LB-NoCache
X-TX-ID
SID
X-Irp-Debug
Cf-Ipcountry
Cdn-Requestid
Server-ID
X-Wa
X-Srv
X-Owner
X-Nc
X-Core-Mission
X-Render-Time
X-VTEX-Cache-Time
X-VTEX-Cache-Server
IsBot
X-SIPLIST1
Cross-Origin-Opener-Policy-Report-Only
X-Powered-By-VTEX-Cache
X-Nananana
Fastly-Drupal-Html
X-LiteSpeed-Tag
GeoIP-Latitude
X-Hit
X-Cached-By
X-AIR-PT
X-NewRelic-App-Data
Edge-Cache
CloudFront-Viewer-Country
X-Nf-Request-Id
Uri
XkeyRZ
X-B3-Parentspanid
X-Proxy-CacheRZ
X-Fpc
X-Qloud-Router
X-Client-Ip
X-Cs
DataCenter
Mime-Version
X-Presslabs-Stats
X-Auth-Group-Type
Debug
X-CS
True-Client-IP
X-URL
X-IAuth-Set-Uid
X-DataCenter
X-Segment-20210421
X-LiteSpeed-Cache-Control
X-Ig-Push-State
X-Amz-Meta-Opti
X-TIME
Tcn
Expect-Staple
X-CF-Lambda-Version
X-CF-Lambda-Fn
N-Cache
X-PHP-Backend
CDN
X-Cache-Type
X-Tenant
Xc-Version
X-Varnish-Beresp-TTL
X-Forwarded-Path
Odigeo-Trace-Id
X-Shop-Environment
X-Orig-Expires
X-HostName
X-CACHE-AGE
X-NodeID
X-Gamma-Serve
X-Custom-Header
X-Vgn-Hpd-Reason
MIME-Version
True-Client-Ip
Cmstype
X-Geo
X-Tt-Logid
Cmsid
X-Dynatrace-Js-Agent
CPC-Age
X-Vmg-Version
X-Info
X-Pad
X-Dispatch
CPC-Cache
User-Agent
Load-Balancing
X-Api-Version
X-B3-Spanid
Srv
X-Depends
X-HOST
X-Cdn-Diag
X-WA
X-Fastly-Country-Code
X-FPC
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-Vc
X-NC
X-Varnish-CookieHashed-On
X-DefElseHash
X-DefHash
Request-ID
X-M-Reqid
X-M-Log
X-VC-TTL
Ohc-File-Size
X-Cdn-Forward
X-Webkit-Csp-Report-Only
Hostname
X-CSRF-TOKEN
Geoip-Latitude
X-Variation
Cl-Cache
X-Datacenter
X-APP-VERSION
X-Cache-FS-Status
X-APP
Server-Id
CacheControlHeader
X-TimeS
Ohc-Cache-HIT
X-LAGOON
GeoIP-Country-Code
X-ServedByHost
X-Lb-Nocache
Cloudfront-Viewer-Country
X-Cdn-Cache-Status
X-Oracle-DMS-ECID
FSS-Cache
VNS-Cache
VNS-Age
Server-Info
Epwk-X-Cache
X-Cache-Ttl
X-Ha-Backend
X-FL-QIT-DEBUG
PICS-Label
X-Via-PopN
X-Via-PopV
Srvid
CountryCode
ServerHost
X-Litespeed-Tag
X-Via-PopH
X-Fastly-Backend-Reqs
BehaviorPad-Version
X-Litespeed-Cache-Control
X-VCL-Version
Rtss
X-Srcache-Store-Status
X-Srcache-Fetch-Status
X-Lb-Id
X-MSEdge-Flight
X-Cdn-Request-ID
Xkey-La3
X-Proxy-Cache-La3
Xkeylog
X-MSEdge-Features
X-Acquia-Site
OriginIP
X-Acquia-Application-Trace
X-Th-Server
X-Akamai-Pragma-Client-IP
X-Check-Cacheable
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
Time
X-Serial
X-Snapshot-Date
X-MiniProfiler-Ids
X-Web-Server
X-RequestId
Memory
Ngx
X-IN-APIGATEWAY
Memcached
X-Dispatcher-Number
X-IN-APIGATEWAYSSL
X-Sorting-Hat-Shopid
X-Shardid
X-Cache-Version
X-Sorting-Hat-Podid
X-Shopid
X-Ramcache
X-RAMCache
X-Sucuri-Id
Sm-Log-Id
X-Udemy-Cache-App-Namespace
Akamai-Cache-Status
X-Mg-Cache
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Service-Response-Time
X-Dw-Trace-Id
Warning
X-Requestid