Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
X-XSS-Protection
Last-Modified
Cf-Request-Id
CF-Cache-Status
CF-RAY
ETag
Accept-Ranges
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
X-Served-By
P3P
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
X-Xss-Protection
X-FRAME-OPTIONS
Access-Control-Allow-Credentials
Content-Security-Policy-Report-Only
X-AspNet-Version
X-Runtime
P3p
X-DNS-Prefetch-Control
Accept-CH
X-Cache-Status
X-Drupal-Cache
Accept-CH-Lifetime
X-Check
X-Generator
X-Ua-Compatible
X-Cacheable
Server-Timing
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Iinfo
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
Feature-Policy
Content-Encoding
X-Content-Security-Policy
X-Request-ID
X-CDN
Status
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
X-Amz-Id-2
Host-Header
CF-Ray
X-Backend
Allow
Cf-Edge-Cache
X-Cache-Group
Request-Context
X-Robots-Tag
X-Server
Keep-Alive
X-Hacker
X-UA-Device
X-AH-Environment
X-Turbo-Charged-By
X-Ws-Request-Id
X-Vhost
X-Rq
X-Proxy-Cache
X-Age
Xkey
EagleId
X-Dispatcher
X-Server-Powered-By
X-Amz-Version-Id
X-Varnish-Cache
Grace
X-LiteSpeed-Cache
Cf-Apo-Via
X-Pingback
Cf-Railgun
X-Page-Speed
EagleEye-TraceId
X-Device
X-Swift-CacheTime
X-Swift-SaveTime
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-WebKit-CSP
X-Aws-Lambda-Call-Status
X-Dns-Prefetch-Control
Ali-Swift-Global-Savetime
X-CST
X-OneAgent-JS-Injection
X-Backend-Server
Permissions-Policy
X-Server-Id
X-Host
X-Readtime
X-Response-Time
X-Akam-SW-Version
Surrogate-Control
Request-Id
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Nginx-Upstream-Cache-Status
X-HW
X-Cloud-Trace-Context
X-Nginx-Cache-Status
Accept-Ch-Lifetime
X-Node
X-Application-Context
X-Country-Code
X-Trace
X-Oneagent-Js-Injection
Content-Location
X-Ruxit-JS-Agent
X-Cache-Lookup
Service-Worker-Allowed
X-Country
X-Content-Type
X-Clacks-Overhead
X-ECACHE
X-Url
X-Edge
X-Litespeed-Cache
X-Mod-Pagespeed
X-Rack-Cache
X-Amz-Server-Side-Encryption
X-Origin-Cache-Key
X-Midtier
X-FTR-Request-ID
Cache-Tag
Cross-Origin-Opener-Policy
Accept-Ch
X-MS-InvokeApp
X-Mcache
X-Powered-By-Plesk
X-Upstream
X-Vname
X-PC
Nginx-Cache
X-TtlSet
Rating
Edge-Control
X-ESI
X-Exp-Variant
X-Cdn-Fetch
X-GoogleNews-Bot
X-Exp-Id
X-Kinja-Build
X-Kinja-Server
X-Browser-Type
X-Kinja-Revision
X-Element-Page-Cache
X-Kinja
X-D2id
Verso
X-Times
X-Ruxit-Js-Agent
X-Ac
X-Server-Name
X-Cnection
SPRequestDuration
SPIisLatency
X-Vcap-Request-Id
AR-SID
AR-Request-ID
AR-PoweredBy
AR-ATIME
X-Abt-Application-Version
X-Navigation-Version
X-RateLimit-Remaining
X-B3-TraceId
X-Dw-Request-Base-Id
X-SharePointHealthScore
SPRequestGuid
X-NF-Request-ID
X-Ser
X-VARITI-CCR
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
Origin-Trial
X-GitHub-Request-Id
RTSS
AR-CACHE
S
X-Cache-Key
X-Cache-TTL
X-Mg-S
X-Content-Security-Policy-Report-Only
X-Goog-Hash
X-Amz-Rid
Edge-Cache-Tag
Pagespeed
X-Middleton-Display
X-Sol
Display
Fastly-Restarts
X-Amzn-Trace-Id
X-Varnish-TTL
X-Powered-CMS
X-NWS-LOG-UUID
X-Ttl
X-Erf-Bev-Bev
X-Version
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Erf-Bev-Bev-Is-Generated
X-ARC
X-Instrumentation
X-Kinsta-Cache
X-Edge-Location-Klb
Access-Control-Request-Method
X-Recruiting
X-Client-IP
X-Server-ID
Cache-Status
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Content-Digest
Arr-Disable-Session-Affinity
X-T
X-MSEdge-Ref
Content-MD5
X-Middleton-Response
Response
X-Forwarded-For
X-Accel-Expires
MicrosoftSharePointTeamServices
X-Ua-Device
X-TraceId
X-Hits
X-RateLimit-Limit
TP-Cache
X-Shield-Request-Id
X-Cached
Public-Key-Pins
X-WebKit-CSP-Report-Only
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-Id
X-FTR-Backend-Server
X-FTR-Balancer
X-Country-Code-Real
X-Frontend
X-FTR-Backend
X-FTR-Cache-Status
X-Request-Received
X-Request-Processing-Time
Server-Node
X-FTR-Expires
X-Ua-Browser
X-Kinja-CCPA
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
Payment
MS-Author-Via
X-Fastcgi-Cache
X-DIS-Request-ID
X-LLID
Cross-Origin-Resource-Policy
Front-End-Https
X-Webkit-Csp
X-Forwarded-Proto
X-GUploader-UploadID
Cache-Tags
X-FastCGI-Cache
X-HP-Webp
X-Jurisdiction
TP-L2-Cache
X-HP-Trace-Id
X-TTL
X-LB-Cache
X-Amz-Apigw-Id
X-Amzn-RequestId
Realpath
X-Protected-By
X-Origin-Server
X-PressLabs-Stats
Count-Hit
X-Distributor
X-ORACLE-DMS-RID
X-Daa-Tunnel
X-Microsite
X-Request-Handler-Origin-Region
X-F-Cache
Mrf-Cache-Status
X-Page-Id
X-B3-TraceId-Primal
X-Cluster-Name
MRF-Tech
Accept-Charset
X-AppVersion
X-Az
X-Correlation-Id
X-Activity-Id
X-Varnish-Backend
X-Www-Served-By
X-NGENIX-Cache
X-Geo-Country
X-App-Server
X-Rid
X-FB-Debug
Referer-Policy
X-Debug-Info
X-Hostname
X-Varnish-Server
X-Goog-Metageneration
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Host
Fastcgi-Cache
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Envoy-Decorator-Operation
X-Git-Hash
Access-Control-Allow-Method
X-ORACLE-DMS-ECID
X-RateLimit-Reset
Retry-After
Server-Name
X-Px
DC
X-Tt-Trace-Tag
X-Content-Options
X-Tt-Trace-Host
X-B3-Sampled
X-Oracle-Dms-Ecid
X-Fastly-Request-ID
X-Load-Cache
X-Aspnet-Duration-Ms
X-Route-Name
X-Providence-Cookie
X-Request-Guid
X-Flags
X-Is-Crawler
X-Contextid
X-Revision
X-Origin-Cache
X-Mobile
X-App-Environment
Cleartype
X-B-Cache
X-Signature
X-Type
X-TT
Paypal-Debug-Id
TCN
X-Trace-Id
X-Grace
Charset
X-Language
X-Fb-Rlafr
X-B
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
Frame-Options
Section-Io-Cache
X-Newrelic-App-Data
X-Amz-Meta-S3cmd-Attrs
X-Logged-In
X-Cache-Control
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Amz-Replication-Status
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-ASPNET-VERSION
X-Seen-By
X-Oracle-Dms-Rid
Filterid
X-XRDS-LOCATION
X-Whom
X-EdgeConnect-Cache-Status
X-Wix-Request-Id
X-Magnolia-Registration
X-Ezoic-Cdn
X-Ratelimit-Limit
X-Upgrade-Enabled
Healthy
Content-Disposition
X-Azure-Ref
X-App-Version
X-CSRF-Token
X-Node-Name
Backend
X-Proxy
X-N
Akamai-GRN
X-Air-Pt
Upgrade-Insecure-Requests
X-Template
X-Fastly-Request-Id
NGB
X-Use-Magma
X-Proxy-Cache-Info
X-XRDS-Location
Refresh
X-Varnish-Ttl
X-B3-SpanId
X-Original-Request-Id
X-Response-Served-From
X-Is-Bot
X-Servername
X-Rendered-As
X-Tumblr-User
X-Unique-Id
VIX-Pulpo-Node
X-NODE
X-Page-View
X-Tumblr-Pixel
X-Tumblr-Pixel-1
Liferay-Portal
MS-CV
Ms-Operation-Id
X-RemovedCookies
SD-X-WS
X-ProcessESI
Url
X-Tumblr-Pixel-0
VIX-Pulpo-Upstream-Status
X-RTag
X-Instance
X-Jobs
X-Datadog-Sampled
X-L-Path
X-Cacheable-TTL
X-Debug-IsPreview
X-Debug-IsConnected
X-Cache-Grace
X-UUID
X-Environment-Context
X-Adobe-Loc
Viewport
X-Adobe-Content
X-FW-Version
X-IPS-LoggedIn
X-Amzn-Remapped-Content-Length
X-Varnish-Grace
X-Yottaa-Optimizations
X-FW-Type
X-FW-Dynamic
X-FW-Hash
X-Yottaa-Metrics
X-FW-Server
X-FW-Static
X-FW-Serve
X-G
X-Region
X-Cache-Hit
X-User-Agent
X-NYM-Debug-Backend
From-Origin
Fastly-SWR
Fastly-SIE
X-Debug
X-Hosted-By
X-Status
X-B3-Traceid
Country
X-Rule
Surrogate-Key
Amp-Access-Control-Allow-Source-Origin
X-Device-Type
X-Ratelimit-Remaining
X-Air-Source
X-Air-Trace-Id
X-Air-Hostname
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Hl-Ver
ServerID
Protected
X-Http-Reason
X-Content-Powered-By
X-Backend-Name
X-Webkit-CSP
X-Akamai-Request-ID2
X-Origin-CC
X-Origin-TTL
Version
Alternate-Protocol
X-VC-Cache
X-Cache-Status-Check
X-Akamai-Edgescape
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
WPO-Cache-Message
WPO-Cache-Status
X-Cache-Age
X-CDN-Forward
X-Framework
Countrycode
X-Rocket-Nginx-Serving-Static
X-Nginx-Cache
X-Time
X-Edge-Location
X-INCAP-ABP
Front
CF-IPCountry
X-Cache-Rule
X-HTML-Minification-Powered-By
X-Source
CDN-RequestId
Access-Control-Request-Headers
SRV
GEO-INFO
X-Storage
X-Via-JSL
X-Endurance-Cache-Level
X-Httpd
X-Mode
X-Accel-Version
X-WP-CF-Super-Cache-Active
Xet-Cookie
X-UPSTREAM-Address
X-Upstream-Ht
X-Upstream-Ct
X-Cache-Operation
Filters
X-Rewrite-Enabled
X-Rn-Rsrv
X-Xfnlog-Site
Meta-Geo
X-JoinUs
X-Real-IP
X-Lambda-Id
X-Cache-Debug
X-Cache-Time
X-Loop
X-Tumblr-Pixel-3
X-Soup
X-Tec-Api-Version
Accept-Language
X-Tec-Api-Root
X-SaId
X-Tec-Api-Origin
X-Vcache
X-Tncms
X-Tumblr-Pixel-2
X-Director
X-Detected-As
X-Varnish-Age
Apigw-Requestid
X-Cms-Context
X-Use-Mantle
X-Varnish-Cache-Hits
X-Skip-Cache
X-SayCDN-TTL
Xserver
X-Sql-Count
X-Sql-Duration-Ms
OT-Force-Account-Verify
X-Say-TTL
X-Adobe-Source
X-Redis-Cache
X-Served-From
X-Say-Cacheable
X-Format
TWC-Device-Class
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Connection-Speed
Web-Mar-Node
X-Cache-Host
Azure-Version
Azure-SlotName
Azure-SiteName
Azure-RegionName
DB-Nickname
Webcakes-Region
Property-Id
Azure-InstanceId
Webcakes-App-Name
Webcakes-App-Version
TWC-Privacy
X-Handled-By
X-ProxyCache-Status
X-Labrador-Cache-Channel
X-BYPASS-REASON
ServedBy
X-Logging-Id
X-Varnish-Beresp-Grace
X-Restarts
X-PHP-Host
X-Uri
X-Origin-Hint
TWC-Locale-Group
X-ProxyCache-Key
X-GeoCode
X-GeoCountry
X-Vercel-Cache
X-Extlb
X-Timing-Wait
X-Worker
X-Origin
X-Geo-Region
X-Routing-Service
X-Forwarded-Host
X-Proxied
X-Tb
X-Generation-Time
X-Tcp-Rtt
X-AB
X-Server-W
X-RCS-CacheZone
X-Is-Desktop
X-Is-Mobile
X-Is-Supported-Browser
X-Container-Uri
X-Is-Tablet
X-Proxy-Build
X-Zipkin-Id
X-Browser-Name
Selected-Fe
X-S
X-RM-Cache-TTL
X-Git-Commit
X-Vercel-Id
Mn-Server-Ip
Webserver
X-LJ-Flow-ID
X-No-Session
X-Frame-Option
X-VWS-Id
X-IPLB-Request-ID
X-Fetched-On
Priority
X-Provided-By
X-AWS-Id
X-DynaTrace
X-IPLB-Instance
X-ServerID
Cache-Tv-Group
X-VCT
X-Cache-Server
X-COUNTRY
X-Reqid
X-R9-Blue-Green-Version
X-FB-TRIP-ID
X-VC
X-Cluster
Node
Section-Io-Id
Content-Secure-Policy
X-Ms-Version
X-Ms-Request-Id
X-Locale
X-Site-Version
Fastcgi-Useragent
X-Platform-Router
X-Platform-Cluster
X-Platform-Processor
X-Vcl-Version
Onion-Location
X-MP-GENERATED-AT
Source
X-SRV
X-Drupal-Cache-Tags
S-Rt
WP-Super-Cache
AMP-Access-Control-Allow-Source-Origin
X-Drupal-Cache-Contexts
WZWS-RAY
X-Webstats-RespID
X-Urbn-Context-Path
X-Ua
X-Urbn-Site-Id
X-Content-Age
Locale
CDN-CachedAt
CDN-Cache
X-Storefront-Renderer-Rendered
CDN-EdgeStorageId
CDN-RequestCountryCode
CDN-Uid
CDN-RequestPullSuccess
CDN-RequestPullCode
X-Shopify-Stage
X-Web-Node
CDN-PullZone
X-Alternate-Cache-Key
X-Generated-By
Cross-Origin-Embedder-Policy
X-Origin-Date
X-ShopId
X-ShardId
X-Cache-Action
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Pass-Why
X-Varnish-Beresp-Ttl
X-Proxy-Cache-Status
X-Sucuri-Cache
X-Cdn-Origin
X-Mg-Request-UUID
X-Cluster-Node
X-Sucuri-ID
X-DataDome
X-Buckets
Cross-Origin-Window-Policy
Fastly-Drupal-HTML
X-Cache-Expired-At
X-TT-LOGID
Sid
X-Newrelic-Synthetics
X-Request-URI
X-Client-Ip
Thinkindot-Control
X-Shield-Cache-Expires
X-Thinkindot-L3
Thinkindot-CacheControl
Cache
TDXMobile
X-GEO
X-Scope-Id
X-CMSURLCustom
X-Xrds-Location
X-URL
Thinkindot-CacheControl-Type
X-LSADC-Cache
X-A
Type
X-A-Ccd
Sslversion
V-Age
X-A-Dam
T-Server
Surrogated-Key
Cross-Origin-Embedder-Policy-Report-Only
Redirect-Candidate
X-D
X-Conf
X-Cache-NE
X-Destination
X-Developer
Candidate-Md5Url
CDCHOST
DCR-Decision-By
DCR-Processing-Time-Ms
X-Bl-Debug
X-BCube-Filmed-By
Lang
X-Bc-Bl
X-Cache-Bucket
Environment
Gannett-Cam-Experience-Id
X-Ec-Custom-Error
X-Ec-Fail
X-Application
Origin-Agent-Cluster
Origin
X-Aed
Rendered-Blocks
X-A-Dgt
X-A-Wwc
Ngx.Var.Host
Ngx-Var-Key
MD5-Digest
X-Ec-GeoHdr
X-Epic-Correlation-Id
Meta-Geo-Continent
X-B-Cookie
X-External-Request-Id
X-A-Dcw
X-Men
X-Viewer-Country
X-Up
X-PAYTM-SRV-ID
X-DC
X-SRCache-Key
X-Vtex-Remote-Cache
X-ScT
X-TIM-N
X-Vdms-Version
X-Vdms-Path
X-Scheme
X-S-Cookie
X-Rojux
X-Aspnetmvc-Version
X-Service
Req-Svc-Chain
X-Sigma-Backend
X-Dispatcher-Server
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Loc
X-Acquia-Purge-Cdn-Unconfigured
Apple-News-Services-Handled
X-Sigma
X-Section
Apple-News-Services-Host
X-Core-Value
X-SD-PageType
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
X-Access
X-VServer
X-Varnish-Hostname
X-Varnish-Director
X-V-Cache
L
Magicmarker
X-BBC-Edge-Cache-Status
X-VG-WebCache
X-VG-TLSProxy
X-B3-Trace-ID
Host-ID
Fastly-SSL
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-SB
Country-Code
X-VCache
X-Cache-Info
Fastly-GeoIP-CountryCode
Pramga
X-Aicache-OS
X-Core-Mission
X-Correlation-ID
X-Mly-Id
Ssr
X-Nyt-Route
X-GeoIP-Country-Code
Sever-Int
X-Proxied-Request
X-Pool
X-Origin-Time
X-Op-Id-All
X-Level-Front-Cache
X-Instance-Name
X-Human
X-Generated-On
X-GeoIP-Region-Code
Vix-Hermes-Req-Id
X-Fastly-Cache
X-Fastly-Backend
X-Request-Time
X-Req
X-We-Are-Hiring
Server-Ext
X-Rocket-Build-Number
X-Gdpr
Server-Hostname
Server-Host
X-Datadome
X-Via-SSL
X-Via-CDN
X-Via-Edge
X-Optimistic-Header
X-Parent-Response-Time
HostName
Edge-Copy-Time
X-TimeS
X-Tt-Logid
X-Server-IP
X-Via-Popv
Web-Mar-Region
Wxu-Next-Commit
X-Pubstack
X-WA-Info
X-Bip
Release
X-Ad-Load-Variation
X-Zen-Fury
X-Hash
X-Platform
Wxu-Next-Region
Wxu-Next-Hostname
X-ApacheServer
X-Thanos
X-Via-Popn
X-Varnish-Beresp-Status
X-Slack-Shared-Secret-Outcome
X-Gzip
X-HA-Backend
X-Hnp-Log
X-RateLimit-Limit-Second
X-GoCache-CacheStatus
X-Geo-Header
X-GeoIP-City
X-HS-Content-Campaign-Id
X-PERF
X-NCache
X-Micro-Cache
X-Nginx-Cache-Key
X-Old-Content-Length
X-Origin-Response-Time
X-Org
X-Gen-Mode
X-From
X-TH-Server
X-Cache-TTL-Remaining
X-Clientip
X-Cache-Id
X-Cache-Date
X-Via-Poph
X-UA-Device-Type
X-Sn-Servicetimems
X-Slack-Backend
X-Fmm-Version
X-RateLimit-Remaining-Second
X-Request-Host
X-Esi-Check
X-Device-Os
X-DPWN-IS-SECURE
X-Auto-Login
X-Block-Status
Machine
Click-Count-Action-Start
Platform
Producers
Is-Eu
DSUID
Click-Count-Error
Cache-Provider
C-Via
Adler-Geo
Proxy-Firewall
On-Server
Tube-Got-Eval
Tube-Get-Contents
Tube-Got-Results
Tube-Return
LB
User-Cache-Control
True-Client-Country-4JS
X-WP-CF-Super-Cache-Cookies-Bypass
Uber-Trace-Id
AKAMAI
X-Edge-Server
X-Varnishpool
X-SIPLIST1
X-Request-Start
X-Wikidot-Backend
X-TA-CDN-Provider
X-Date
NM-Fastcgi-Cache
Cf-Device-Type
Cdn-Request-Time
Cdn-Host
X-Forwarded-Site
Req-ID
X-Mvc-Supplant-Cachable
X-Mvc-Supplant-OutputCached
X-FC-Vary-Parameters
X-Irp-Debug
X-GeoIP
Atl-Traceid
X-NMSegId
X-Owner
Datacenter
X-Var-Ttl
Esi-Enabled
Gh-Request-Id
X-Policy
X-Wikidot-Static-Cache
X-Node-Id
X-App-Name
X-CF-Lambda-Fn
Pics-Label
N-Cache
Expect-Staple
IsBot
X-CF-Lambda-Version
X-Cdn-Srv
X-Accel-Expires-Debug
SID
X-Proto
Canary
X-Test
X-Tenant
Fastly-Backend-Name
NGX
Xc-Version
W
X-Qloud-Router
Mail-Subject
X-CacheTTL
X-Orig-Expires
We-Hiring
X-ZONE
X-Shop-Environment
X-Amz-Meta-Cb-Modifiedtime
X-Cache-Type
X-Forwarded-Path
X-Eu-Site
X-Csrf-Jwt
X-Ah-Environment
HA-Ipaddr
X-Tx-Id
Ha-Gx-Prefs
X-LB-NoCache
L5d-Success-Class
X-CGP
X-Gamma-Serve
Cluster
X-Connection-Hash
Expiry
Content-Style-Type
Cmsid
X-Branch-Name
X-Varnish-Authentication
Content-Script-Type
Server-ID
X-TIME
Cmstype
X-Moov-T
X-Cache-Aspx
A
X-Moov-Xdn-Version
X-Contensis-Viewer-Groups
X-Dc
Cdn
CPC-Cache
CPC-Age
X-Api-Version
X-Refresh
X-NGINX-Cache
RNT-Machine
X-Wa
X-LB-ID
Locid
X-Nc
X-Varnish-Hits
Cache-Key
RNT-Time
X-Servedbyhost
X-Vmg-Version
X-LAGOON
X-Ratelimit-Reset
X-Region-Sid
X-ND-Cache
X-Cdn-Diag
X-AK-Request-ID
Cdnsip
Cdncip
Yak-Timeinfo
X-Nf-Request-Id
X-Fpc
X-CACHE-AGE
X-VHOST
X-CSRF-TOKEN
RATING
X-CDN-Cache-Status
X-VarnishDD-TTL
X-Tb-Optimization-Total-Bytes-Saved
PFcat
X-MCACHE
X-HN
GeoIp-Country-Code
X-Amz-Storage-Class
NtCoent-Length
Cdn-Requestid
X-Nananana
CloudFront-Viewer-Country
X-Backend-Instance
X-DynaTrace-JS-Agent
X-Akamai-Transformed
XM
X-B3-Parentspanid
X-Via-Fastly
CacheControlHeader
X-Azure-Ref-OriginShield
X-Variation
Resin-Trace
X-Hit
X-Srv
X-Esi
X-TX-ID
Uri
X-Origin-Expires
X-Cache-Backend
X-API-Version
X-Vc
X-Zone
VNS-Age
X-Fastly-Country-Code
User-Agent
X-LiteSpeed-Tag
VNS-Cache
MIME-Version
X-Lagoon
Cache-Name
XkeyRZ
X-Proxy-CacheRZ
Hostname
X-LiteSpeed-Cache-Control
X-Info
X-Amz-Meta-Opti
X-DataCenter
Cross-Origin-Opener-Policy-Report-Only
X-Dynatrace-Js-Agent
Tcn
X-Dispatcher-Number
True-Client-Ip
X-Datacenter
Lb
True-Client-IP
X-HostName
X-Geo
X-Cached-By
GeoIP-Latitude
X-NewRelic-App-Data
X-UA
X-Location
X-Traceid
DataCenter
Mime-Version
X-Ig-Origin-Region
X-B3-Spanid
Cache-Hits
X-Mid
Fusion-Template-Id
Fusion-Content-Id
Fusion-Source
Fusion-Component-Id
Fusion-Content-Source
X-NWS-UUID-VERIFY
Fusion-Deployment-Id
X-AIR-PT
X-Presslabs-Stats
Cf-Ipcountry
BehaviorPad-Version
Powered-By
Fastly-Drupal-Html
X-Cdn-Forward
X-Webkit-Csp-Report-Only
X-CS
X-IAuth-Set-Uid
X-CUA
Origin-CC
Origin-EX
X-Cloudmap
X-Jungle-Id
Srv
X-User
X-Segment-20210421
Ohc-File-Size
X-ECache
CountryCode
X-Varnish-Beresp-TTL
Server-Info
X-Cache-Enabled
X-Dispatch
Location
Debug
GeoIP-Country-Code
CF-Ctrl
X-Oracle-DMS-ECID
Cl-Cache
X-Render-Time
X-Cdn-Cache-Status
X-Internal-Host
X-FPC
My-App
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-Litespeed-Tag
Ohc-Cache-HIT
Wpo-Cache-Status
CDN
Wpo-Cache-Message
X-Wormhole-Sdk
X-VTEX-Cache-Time
X-App
Server-Id
X-WA
X-ServedByHost
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
X-Lb-Id
X-Fastly-Backend-Reqs
YJS-ID
Section-Origin-Responded
X-VTEX-Cache-Server
X-Snapshot-Date
X-Nitro-Cache
X-Powered-By-VTEX-Cache
X-NC
Load-Balancing
X-Cs
X-Akamai-Pragma-Client-IP
X-Auth-Group-Type
X-MSEdge-Flight
X-Cache-FS-Status
Edge-Cache
X-MSEdge-Features
X-Lb-Nocache
X-Litespeed-Cache-Control
X-VCL-Version
Ms-Author-Via
X-ID
X-Nitro-Rev
Xkey-La3
X-Nitro-Cache-From
X-Proxy-Cache-La3
Xkeylog
CF-Cached-On
X-Cdn-Request-ID
X-MiniProfiler-Ids
X-Dw-Trace-Id
X-RID
X-Acquia-Purge-Tags
Time
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-Acquia-Site
Memcached
OriginIP
X-Ig-Push-State
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-NodeID
Memory
X-DefHash
Srvid
X-FL-EDGE
X-Th-Server
X-DefElseHash
WebServer
X-Varnish-Remaining-TTL
X-FL-QIT-DEBUG
X-Check-Cacheable
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
Ngx
X-APP-VERSION
X-Serial
FSS-Cache
X-Cache-Version
X-Shardid
X-Sorting-Hat-Podid
X-Sorting-Hat-Shopid
X-Shopid
Yjs-Id
X-Http-Count
X-Vary
Akamai-Cache-Status
X-Http-Duration-Ms
X-Mg-Cache
X-Via-PopH
X-Lsadc-Cache
Inserted-Into-Cache-At
X-Fastly-Cache-Hits
X-Sucuri-Id
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-RequestId
Geoip-Latitude
Sm-Log-Id
X-Service-Response-Time
X-Ha-Backend
X-Te-Duration-Ms
X-Te-Count
X-Udemy-Cache-App-Namespace
X-Via-PopN
X-Web-Server
X-Via-PopV
X-Pad