Threat Level: green Handler on Duty: Rick Wanner

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
X-XSS-Protection
Accept-Ranges
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
P3P
X-Served-By
X-Xss-Protection
X-Request-Id
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
X-FRAME-OPTIONS
Access-Control-Allow-Credentials
X-AspNet-Version
Content-Security-Policy-Report-Only
X-Runtime
Accept-CH
X-DNS-Prefetch-Control
P3p
X-Cache-Status
Accept-CH-Lifetime
X-Drupal-Cache
X-Check
X-Ua-Compatible
X-Generator
Server-Timing
X-Cacheable
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Iinfo
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
X-Content-Security-Policy
Feature-Policy
Content-Encoding
X-CDN
Status
X-AspNetMvc-Version
Upgrade
X-Request-ID
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
X-Amz-Id-2
CF-Ray
Host-Header
Cf-Edge-Cache
X-Backend
Allow
Request-Context
Keep-Alive
X-UA-Device
X-Robots-Tag
X-Server
X-Cache-Group
X-Hacker
X-AH-Environment
X-Turbo-Charged-By
X-Ws-Request-Id
X-Proxy-Cache
Xkey
X-Age
EagleId
X-Rq
X-Vhost
X-Dispatcher
X-Server-Powered-By
X-Amz-Version-Id
X-Varnish-Cache
Grace
Cf-Apo-Via
X-Page-Speed
X-Swift-CacheTime
X-Swift-SaveTime
X-Pingback
Cf-Railgun
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Ali-Swift-Global-Savetime
X-Device
X-WebKit-CSP
EagleEye-TraceId
X-Dns-Prefetch-Control
X-Aws-Lambda-Call-Status
X-CST
X-OneAgent-JS-Injection
X-LiteSpeed-Cache
Permissions-Policy
X-Backend-Server
X-Server-Id
X-Litespeed-Cache
X-Readtime
X-Response-Time
X-Host
X-Akam-SW-Version
Request-Id
Surrogate-Control
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-HW
X-Nginx-Upstream-Cache-Status
X-Cache-Lookup
X-Cloud-Trace-Context
X-Node
X-Nginx-Cache-Status
X-Application-Context
X-Country-Code
Content-Location
X-Trace
X-Country
Service-Worker-Allowed
X-Ruxit-JS-Agent
X-Url
X-Content-Type
X-Oneagent-Js-Injection
X-Clacks-Overhead
X-Origin-Cache-Key
Accept-Ch-Lifetime
X-Edge
X-Rack-Cache
Cross-Origin-Opener-Policy
Cache-Tag
X-FTR-Request-ID
X-Amz-Server-Side-Encryption
X-Midtier
X-Mcache
X-Mod-Pagespeed
X-MS-InvokeApp
X-Vname
X-ECACHE
X-TtlSet
X-PC
Nginx-Cache
X-ESI
X-Upstream
X-Powered-By-Plesk
Rating
Edge-Control
X-Server-Name
X-Browser-Type
Verso
X-Cnection
X-Times
X-Element-Page-Cache
X-Exp-Id
X-Cdn-Fetch
X-Kinja-Build
X-Exp-Variant
X-Kinja-Revision
X-Kinja
X-GoogleNews-Bot
X-Kinja-Server
X-D2id
X-Ac
X-Ruxit-Js-Agent
SPRequestDuration
SPIisLatency
AR-ATIME
AR-SID
AR-PoweredBy
AR-Request-ID
X-B3-TraceId
SPRequestGuid
X-SharePointHealthScore
X-NWS-LOG-UUID
X-Ser
X-Abt-Application-Version
X-GitHub-Request-Id
X-NF-Request-ID
X-Vcap-Request-Id
X-Navigation-Version
X-Dw-Request-Base-Id
X-RateLimit-Remaining
AR-CACHE
Pinterest-Version
X-Ttl
Pinterest-Generated-By
X-Pinterest-Rid
X-Mg-S
X-VARITI-CCR
S
X-Client-IP
Pagespeed
X-Middleton-Display
Display
X-Sol
Edge-Cache-Tag
X-Cache-Key
RTSS
Fastly-Restarts
X-Amzn-Trace-Id
X-Amz-Rid
X-Cache-TTL
X-Powered-CMS
Cache-Status
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev
X-Kinsta-Cache
X-Edge-Location-Klb
X-Version
X-Goog-Hash
X-Server-ID
Access-Control-Request-Method
X-Recruiting
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-Varnish-TTL
X-ARC
Response
X-Middleton-Response
X-Content-Digest
X-TraceId
X-Forwarded-For
Arr-Disable-Session-Affinity
X-T
Origin-Trial
Content-MD5
X-MSEdge-Ref
X-Daa-Tunnel
MicrosoftSharePointTeamServices
X-SRCache-Store-Status
TP-Cache
X-SRCache-Fetch-Status
X-Accel-Expires
X-Shield-Request-Id
Front-End-Https
X-Content-Security-Policy-Report-Only
Cross-Origin-Resource-Policy
X-Hits
X-Cached
X-Id
MS-Author-Via
Public-Key-Pins
X-FTR-Backend
X-FTR-Cache-Status
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Balancer
Server-Node
X-Forwarded-Proto
X-FTR-Expires
X-Fastcgi-Cache
X-Ua-Browser
X-DIS-Request-ID
X-HS-Cache-Config
X-HS-Combine-CSS
X-HS-Hub-Id
Payment
X-Request-Received
X-Request-Processing-Time
X-HS-Content-Id
X-Frontend
X-Webkit-Csp
X-LLID
Realpath
X-HP-Webp
X-Jurisdiction
X-HP-Trace-Id
X-Protected-By
TP-L2-Cache
X-GUploader-UploadID
X-ORACLE-DMS-RID
X-Distributor
X-FastCGI-Cache
X-LB-Cache
Cache-Tags
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Origin-Server
X-Ratelimit-Limit
X-Microsite
X-Request-Handler-Origin-Region
X-RateLimit-Limit
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Referer-Policy
X-Page-Id
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
Count-Hit
X-Hostname
X-Debug-Info
X-Cluster-Name
X-NGENIX-Cache
X-Www-Served-By
Host
X-Varnish-Server
X-AppVersion
X-Az
X-Activity-Id
X-Varnish-Backend
Fastcgi-Cache
X-Correlation-Id
X-F-Cache
X-Envoy-Decorator-Operation
Accept-Charset
X-Geo-Country
X-App-Server
X-Ua-Device
X-ORACLE-DMS-ECID
X-XRDS-LOCATION
X-FB-Debug
X-PressLabs-Stats
X-Goog-Metageneration
Retry-After
X-Upgrade-Enabled
X-Ezoic-Cdn
X-CSRF-Token
X-Git-Hash
Access-Control-Allow-Method
X-Fastly-Request-Id
X-Load-Cache
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Content-Options
X-Seen-By
X-Varnish-Ttl
X-TTL
X-RateLimit-Reset
X-Px
Server-Name
Section-Io-Cache
X-Contextid
X-Request-Guid
X-Revision
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Amz-Meta-S3cmd-Attrs
X-Trace-Id
X-Cache-Control
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Datadog-Trace-Id
X-Oracle-Dms-Ecid
TCN
Cleartype
X-Grace
Charset
X-B
X-Type
Healthy
X-B3-Sampled
X-TT
Paypal-Debug-Id
X-Whom
DC
X-Signature
X-Wix-Request-Id
X-Fb-Rlafr
X-B-Cache
X-Newrelic-App-Data
X-App-Environment
X-Node-Name
X-Origin-Cache
Frame-Options
Accept-Ch
X-Proxy
X-Azure-Ref
X-Magnolia-Registration
X-Amz-Replication-Status
X-Mobile
X-Rid
X-Oracle-Dms-Rid
X-Air-Pt
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Storage-Class
X-Fastly-Request-ID
X-Goog-Stored-Content-Length
X-N
X-Ratelimit-Remaining
X-WebKit-CSP-Report-Only
X-EdgeConnect-Cache-Status
Filterid
X-Language
X-Logged-In
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Route-Name
X-Is-Crawler
X-Flags
X-Providence-Cookie
X-Aspnet-Duration-Ms
X-Kinja-CCPA
Content-Disposition
Akamai-GRN
Backend
NGB
VIX-Pulpo-Node
X-Original-Request-Id
VIX-Pulpo-Upstream-Status
X-Response-Served-From
X-Time
X-Is-Bot
X-Template
X-Rendered-As
X-Varnish-Grace
Upgrade-Insecure-Requests
X-Servername
X-Yottaa-Metrics
X-Debug-IsConnected
X-Cache-Age
X-Yottaa-Optimizations
Viewport
Liferay-Portal
X-Debug-IsPreview
X-Debug
X-FW-Version
X-FW-Server
Refresh
X-FW-Type
X-FW-Serve
X-FW-Hash
X-Proxy-Cache-Info
X-Datadog-Sampled
X-FW-Dynamic
X-Instance
X-Tumblr-User
X-NYM-Debug-Backend
X-RemovedCookies
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-RTag
X-Tumblr-Pixel
X-FW-Static
X-ProcessESI
Ms-Operation-Id
MS-CV
X-Adobe-Loc
X-Unique-Id
X-Adobe-Content
X-IPS-LoggedIn
X-L-Path
X-Environment-Context
X-Region
X-Amzn-Remapped-Content-Length
X-G
X-Cache-Grace
SD-X-WS
Fastly-SWR
X-App-Version
X-Cacheable-TTL
X-CCDN-CacheTTL
Fastly-SIE
X-CCDN-Origin-Time
X-Backend-Name
X-Hcs-Proxy-Type
X-Device-Type
From-Origin
X-Hl-Ver
X-UUID
X-User-Agent
X-Via-JSL
ServerID
Country
X-Status
X-Cache-Hit
X-B3-SpanId
Url
X-Rule
X-Jobs
X-Webkit-CSP
X-VC-Cache
X-INCAP-ABP
Countrycode
WPO-Cache-Status
Version
WPO-Cache-Message
Alternate-Protocol
X-Cache-Status-Check
X-HTML-Minification-Powered-By
X-Air-Source
X-Air-Hostname
X-Origin-CC
X-Air-Trace-Id
X-Origin-TTL
X-NODE
X-Source
X-Nginx-Cache
X-Page-View
X-Akamai-Request-ID2
Surrogate-Key
GEO-INFO
X-Hosted-By
X-Content-Powered-By
CDN-RequestId
X-Storage
Amp-Access-Control-Allow-Source-Origin
X-B3-Traceid
SRV
X-WP-CF-Super-Cache-Active
Protected
X-Rocket-Nginx-Serving-Static
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
OT-Force-Account-Verify
X-Akamai-Edgescape
X-Accel-Version
X-Real-IP
Access-Control-Request-Headers
X-Edge-Location
X-VC
AMP-Access-Control-Allow-Source-Origin
X-CDN-Forward
CF-IPCountry
X-Framework
X-ServerID
X-Cache-Time
X-Cache-Rule
X-Use-Mantle
Front
X-Mode
X-Rn-Rsrv
Filters
Meta-Geo
X-Rewrite-Enabled
X-Upstream-Ht
Webserver
X-Xfnlog-Site
X-Upstream-Ct
X-UPSTREAM-Address
Accept-Language
X-Cache-Operation
X-Http-Reason
X-Soup
Section-Io-Id
X-LJ-Flow-ID
X-Timing-Wait
ServedBy
X-JoinUs
X-Served-From
Cross-Origin-Embedder-Policy
X-Proxy-Build
X-Handled-By
X-Detected-As
X-Origin
X-SaId
Mn-Server-Ip
X-Director
Selected-Fe
X-Cache-Debug
X-Varnish-Cache-Hits
X-VWS-Id
X-AWS-Id
X-Restarts
X-No-Session
X-Extlb
X-Routing-Service
X-Say-Cacheable
Property-Id
Node
X-Web-Node
X-Redis-Cache
Apigw-Requestid
X-Logging-Id
X-PHP-Host
X-Lambda-Id
X-Proxied
Xserver
X-ProxyCache-Key
X-Origin-Hint
X-Labrador-Cache-Channel
X-ProxyCache-Status
X-Zipkin-Id
X-Say-TTL
X-SayCDN-TTL
TWC-GeoIP-Country
X-Httpd
Web-Mar-Node
X-Tumblr-Pixel-2
TWC-Device-Class
Xet-Cookie
X-Vcache
X-Tumblr-Pixel-3
Webcakes-App-Name
TWC-GeoIP-LatLong
TWC-Locale-Group
X-Cluster
X-BYPASS-REASON
Webcakes-Region
X-Format
TWC-Privacy
X-Adobe-Source
Webcakes-App-Version
TWC-Connection-Speed
X-Loop
X-AB
X-Cms-Context
X-Is-Mobile
Azure-Version
X-Is-Desktop
DB-Nickname
X-Geo-Region
X-Platform-Router
X-Platform-Processor
X-Forwarded-Host
X-Tncms
X-Skip-Cache
X-Tcp-Rtt
X-Platform-Cluster
X-Endurance-Cache-Level
X-VCT
X-Browser-Name
X-Varnish-Beresp-Grace
X-TT-LOGID
X-Locale
X-Site-Version
X-S
X-IPLB-Instance
X-RCS-CacheZone
X-IPLB-Request-ID
Azure-InstanceId
Azure-SiteName
Azure-RegionName
Azure-SlotName
X-GeoCountry
X-RM-Cache-TTL
X-Is-Supported-Browser
X-GeoCode
X-Is-Tablet
X-Drupal-Cache-Tags
X-Cache-Host
X-Cache-Server
X-Server-W
X-Webstats-RespID
X-Fetched-On
X-Generation-Time
X-Vercel-Id
X-Drupal-Cache-Contexts
X-Tb
X-Varnish-Age
X-Vercel-Cache
X-Git-Commit
X-Frame-Option
X-Container-Uri
X-Reqid
X-Worker
X-Provided-By
X-R9-Blue-Green-Version
X-Ms-Version
X-Ms-Request-Id
CDN-Cache
CDN-RequestPullSuccess
CDN-CachedAt
X-Storefront-Renderer-Rendered
CDN-PullZone
CDN-RequestCountryCode
X-Shopify-Stage
CDN-EdgeStorageId
X-Alternate-Cache-Key
X-MP-GENERATED-AT
X-Uri
CDN-Uid
CDN-RequestPullCode
X-Origin-Date
X-XRDS-Location
WP-Super-Cache
X-DynaTrace
X-ShardId
X-ShopId
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Sucuri-Cache
Fastcgi-Useragent
Source
X-Sucuri-ID
X-Vcl-Version
X-Cdn-Origin
Cache-Tv-Group
Cross-Origin-Embedder-Policy-Report-Only
Content-Secure-Policy
X-FB-TRIP-ID
X-Generated-By
X-Xrds-Location
X-Sql-Count
X-Sql-Duration-Ms
Priority
Atl-Traceid
Locale
X-Pass-Why
X-Urbn-Context-Path
X-Urbn-Site-Id
X-SRV
X-Content-Age
X-Buckets
Onion-Location
Sid
X-DataDome
X-Scope-Id
X-Shield-Cache-Expires
X-CMSURLCustom
Thinkindot-Control
X-Thinkindot-L3
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
TDXMobile
HostName
Cross-Origin-Window-Policy
X-Newrelic-Synthetics
X-LSADC-Cache
X-Cluster-Node
Cache
WZWS-RAY
X-Proxy-Cache-Status
X-Varnish-Beresp-Ttl
S-Rt
X-Cache-Action
X-GEO
Edge-Copy-Time
X-Via-CDN
X-Cache-Expired-At
X-WP-CF-Super-Cache-Cookies-Bypass
X-Optimistic-Header
X-Via-SSL
X-Via-Edge
X-TA-CDN-Provider
Expiry
X-Connection-Hash
User-Cache-Control
X-Platform
Fastly-Drupal-HTML
Origin-Agent-Cluster
X-A-Dcw
X-A-Dam
DCR-Decision-By
X-Vdms-Version
DCR-Processing-Time-Ms
Origin
X-Aed
X-Vdms-Path
Candidate-Md5Url
CDCHOST
X-B-Cookie
X-Application
Apple-News-Services-Handled
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
A
X-Bc-Bl
X-BCube-Filmed-By
X-Vtex-Remote-Cache
X-PAYTM-SRV-ID
X-A-Wwc
X-Cache-NE
Sever-Int
X-Cache-Bucket
X-Bl-Debug
X-Access
X-Conf
X-Op-Id-All
X-A-Dgt
Redirect-Candidate
X-External-Request-Id
X-Section
L
X-ScT
Surrogated-Key
Ngx.Var.Host
X-Ec-Fail
X-Ec-GeoHdr
X-Epic-Correlation-Id
X-Correlation-ID
X-Scheme
X-S-Cookie
Server-Ext
MD5-Digest
Meta-Geo-Continent
Server-Hostname
X-Request-Start
Magicmarker
Lang
X-Rojux
Sslversion
Vix-Hermes-Req-Id
X-Ec-Custom-Error
Ngx-Var-Key
X-D
Req-ID
X-A-Ccd
X-A
Rendered-Blocks
X-Developer
X-Destination
X-TIM-N
X-Ua
Gannett-Cam-Experience-Id
Apple-News-Services-Host
X-Dispatcher-Server
T-Server
X-SRCache-Key
X-TimeS
X-Dc
DSUID
C-Via
V-Age
Cache-Provider
Host-ID
X-Moov-Xdn-Version
X-AK-Request-ID
Wxu-Next-Commit
X-Mly-Id
X-Loc
Environment
Wxu-Next-Hostname
X-Human
Yak-Timeinfo
Cdnsip
Type
X-Moov-T
X-WA-Info
NM-Fastcgi-Cache
Content-Script-Type
Cdncip
Fastly-SSL
X-VG-TLSProxy
Wxu-Next-Region
Fastly-GeoIP-CountryCode
X-We-Are-Hiring
Content-Style-Type
X-Acquia-Purge-Cdn-Unconfigured
X-Cache-TTL-Remaining
Release
X-TH-Server
X-Pool
X-Viewer-Country
Req-Svc-Chain
X-GeoIP-Region-Code
X-Thanos
X-Amz-Meta-Cb-Modifiedtime
Pramga
X-GeoIP-Country-Code
X-UA-Device-Type
X-Varnish-Hostname
X-Esi-Check
X-SB
Ssr
X-Rocket-Build-Number
X-Request-URI
X-Fastly-Cache
X-Varnishpool
X-Sigma-Backend
X-Zen-Fury
X-Sigma
X-Proxied-Request
X-Forwarded-Site
X-Varnish-Beresp-Status
X-BBC-Edge-Cache-Status
X-NCache
X-Nginx-Cache-Key
X-NMSegId
X-Azure-Ref-OriginShield
X-B3-Trace-ID
Server-Host
X-Auto-Login
X-Instance-Name
X-ND-Cache
X-Bip
X-Block-Status
X-Pubstack
X-VG-WebCache
X-Gzip
X-Varnish-Director
X-VServer
X-Hnp-Log
X-Branch-Name
X-Cache-Id
X-Cache-Info
X-Gen-Mode
X-Request-Time
X-Origin-Response-Time
Tube-Get-Contents
Tube-Got-Results
Tube-Return
Tube-Got-Eval
True-Client-Country-4JS
X-Cache-Date
X-DPWN-IS-SECURE
X-Eu-Site
X-Device-Os
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-FC-Vary-Parameters
X-Fmm-Version
X-Generated-On
X-Geo-Header
X-Gdpr
X-GeoIP-City
X-From
X-Csrf-Jwt
X-Core-Value
X-Ad-Load-Variation
X-Aicache-OS
Web-Mar-Region
We-Hiring
W
X-ApacheServer
X-Cache-Aspx
X-Clientip
X-Contensis-Viewer-Groups
X-CGP
X-GoCache-CacheStatus
X-Cdn-Srv
Uber-Trace-Id
Click-Count-Error
X-Node-Id
X-VarnishDD-TTL
X-Nyt-Route
X-Old-Content-Length
X-PERF
X-Mvc-Supplant-OutputCached
X-HN
Canary
Click-Count-Action-Start
X-Amz-Storage-Class
Adler-Geo
X-Mvc-Supplant-Cachable
X-Varnish-Authentication
X-Var-Ttl
X-Request-Host
X-SD-PageType
X-Req
X-Region-Sid
X-Mg-Request-UUID
X-ECache
X-Server-IP
X-GeoIP
X-V-Cache
X-Policy
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
Cluster
X-Origin-Time
Locid
Machine
L5d-Success-Class
Is-Eu
Ha-Gx-Prefs
HA-Ipaddr
Country-Code
X-Level-Front-Cache
RNT-Machine
RNT-Time
Producers
Platform
On-Server
Gh-Request-Id
Mail-Subject
Esi-Enabled
X-Men
X-Micro-Cache
PFcat
X-Datadome
X-VCache
X-Service
X-Sn-Servicetimems
X-Slack-Shared-Secret-Outcome
X-Slack-Backend
Cdn-Host
X-HS-Content-Campaign-Id
X-Up
X-App-Name
X-Edge-Server
Cdn-Request-Time
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Backend-Instance
Proxy-Firewall
X-DC
X-Wikidot-Backend
X-Fastly-Backend
Cf-Device-Type
Cache-Key
X-Test
AKAMAI
X-Hash
X-Wikidot-Static-Cache
X-Org
X-Ratelimit-Reset
X-CacheTTL
Fastly-Backend-Name
X-Ah-Environment
XM
X-Irp-Debug
Pics-Label
X-Tx-Id
X-Accel-Expires-Debug
X-Parent-Response-Time
X-Proto
X-LB-ID
X-Date
X-Lagoon
LB
X-Cache-Backend
X-COUNTRY
NGX
X-Origin-Expires
X-Owner
X-Servedbyhost
Cdn
X-Via-Poph
X-UA
X-Core-Mission
X-Tb-Optimization-Total-Bytes-Saved
X-HA-Backend
X-Varnish-Hits
X-CACHE-GROUP
X-ZONE
X-API-Version
X-SIPLIST1
X-Via-Popv
X-Via-Popn
IsBot
X-RID
X-Refresh
X-LB-NoCache
X-DynaTrace-JS-Agent
Datacenter
X-VHOST
SID
RATING
NtCoent-Length
X-Qloud-Router
X-Use-Magma
Cdn-Requestid
X-NGINX-Cache
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Wa
X-Srv
Server-ID
GeoIp-Country-Code
Expect-Staple
X-CDN-Cache-Status
N-Cache
X-Nc
X-Zone
X-Via-Fastly
X-Orig-Expires
X-Nananana
X-Shop-Environment
X-Cache-Type
X-Forwarded-Path
X-Tenant
Xc-Version
CloudFront-Viewer-Country
Cache-Hits
X-Presslabs-Stats
Cmsid
Cross-Origin-Opener-Policy-Report-Only
X-Gamma-Serve
Cmstype
X-Fpc
GeoIP-Latitude
X-B3-Parentspanid
X-Location
X-Hit
CPC-Age
CPC-Cache
X-Ig-Origin-Region
X-Akamai-Transformed
DataCenter
X-TX-ID
User-Agent
Uri
X-Cdn-Diag
Fusion-Component-Id
Resin-Trace
XkeyRZ
X-Nf-Request-Id
Fusion-Source
Fusion-Template-Id
X-Proxy-CacheRZ
X-Vmg-Version
Fusion-Content-Id
X-Cloudmap
Fusion-Content-Source
Fusion-Deployment-Id
X-Client-Ip
X-DataCenter
X-CS
Powered-By
X-URL
Origin-CC
X-TIME
X-CUA
X-Info
True-Client-Ip
X-Amz-Meta-Opti
X-Jungle-Id
X-Tt-Logid
Origin-EX
Tcn
X-User
X-Variation
X-NWS-UUID-VERIFY
Mime-Version
X-Fastly-Country-Code
MIME-Version
X-IAuth-Set-Uid
CacheControlHeader
X-HostName
X-LAGOON
X-NewRelic-App-Data
X-Segment-20210421
Fastly-Drupal-Html
X-CACHE-AGE
X-Datacenter
True-Client-IP
X-Cached-By
X-Geo
X-Dynatrace-Js-Agent
Srv
Cf-Ipcountry
X-Render-Time
Load-Balancing
X-Webkit-Csp-Report-Only
X-Cdn-Forward
X-B3-Spanid
CDN
X-Vc
X-LiteSpeed-Tag
VNS-Age
VNS-Cache
X-VTEX-Cache-Server
X-VTEX-Cache-Time
X-HOST
X-Powered-By-VTEX-Cache
Debug
X-Wormhole-Sdk
X-Varnish-Beresp-TTL
X-LiteSpeed-Cache-Control
X-Auth-Group-Type
X-AIR-PT
X-Api-Version
Lb
Ohc-File-Size
Cl-Cache
X-CSRF-TOKEN
X-Dispatch
Edge-Cache
Hostname
Ohc-Cache-HIT
X-Dispatcher-Number
X-MCACHE
X-FPC
GeoIP-Country-Code
X-Ig-Push-State
X-NodeID
X-NC
X-Esi
X-Cdn-Cache-Status
X-WA
Server-Id
Cache-Name
Odigeo-Trace-Id
X-Lb-Nocache
X-Cs
X-Custom-Header
X-APP-VERSION
X-Oracle-DMS-ECID
X-Litespeed-Tag
X-PHP-Backend
X-Mid
X-Depends
X-Vgn-Hpd-Reason
X-Cache-Ttl
X-Pad
X-DefHash
X-ServedByHost
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-Via-PopN
X-Via-PopV
X-Via-PopH
X-Fastly-Backend-Reqs
CountryCode
X-DefElseHash
X-Ha-Backend
X-Srcache-Fetch-Status
Ms-Author-Via
X-Srcache-Store-Status
X-Litespeed-Cache-Control
X-VCL-Version
Ngx
X-Lb-Id
X-MiniProfiler-Ids
Xkey-La3
X-RequestId
X-Akamai-Pragma-Client-IP
X-Cdn-Request-ID
X-MSEdge-Flight
X-M-Reqid
X-VC-TTL
X-M-Log
PICS-Label
Xkeylog
X-MSEdge-Features
BehaviorPad-Version
X-Proxy-Cache-La3
X-Web-Server
X-Snapshot-Date
OriginIP
X-Cache-Enabled
X-Acquia-Site
Memcached
Time
Memory
FSS-Cache
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-Acquia-Purge-Tags
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-Sorting-Hat-Shopid
X-Cache-Version
X-Sorting-Hat-Podid
X-Shopid
X-Shardid
X-Cache-FS-Status
Epwk-X-Cache
X-Check-Cacheable
X-FL-EDGE
CF-Cached-On
X-Serial
Sm-Log-Id
Warning
X-Sucuri-Id
X-Udemy-Cache-App-Namespace
X-FL-QIT-DEBUG
X-Mg-Cache
YJS-ID
Location
X-Dw-Trace-Id
Geoip-Latitude
Server-Info
X-Th-Server
X-Lsadc-Cache
X-Wp-Cf-Super-Cache-Cookies-Bypass
Srvid
Akamai-Cache-Status
X-Service-Response-Time