Threat Level: green Handler on Duty: Richard Porter

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
CF-RAY
ETag
X-XSS-Protection
Accept-Ranges
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-Served-By
X-UA-Compatible
P3P
X-Xss-Protection
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-FRAME-OPTIONS
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Content-Security-Policy-Report-Only
P3p
X-Runtime
X-AspNet-Version
X-DNS-Prefetch-Control
Accept-CH
X-Ua-Compatible
X-Cache-Status
X-Drupal-Cache
Accept-CH-Lifetime
X-Check
X-Generator
X-Cacheable
Server-Timing
X-Envoy-Upstream-Service-Time
X-Request-ID
Timing-Allow-Origin
X-Iinfo
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
Feature-Policy
X-Content-Security-Policy
Content-Encoding
X-CDN
Status
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
CF-Ray
X-Amz-Id-2
Host-Header
Allow
X-Backend
Cf-Edge-Cache
X-Cache-Group
Request-Context
X-Robots-Tag
Keep-Alive
X-Server
X-Hacker
X-UA-Device
X-AH-Environment
X-Turbo-Charged-By
X-Ws-Request-Id
X-Proxy-Cache
Xkey
X-Age
X-Rq
X-Vhost
EagleId
X-Dispatcher
X-Server-Powered-By
X-Amz-Version-Id
X-Varnish-Cache
Grace
X-Dns-Prefetch-Control
Cf-Apo-Via
X-Page-Speed
X-Pingback
Cf-Railgun
X-LiteSpeed-Cache
X-Swift-CacheTime
X-Swift-SaveTime
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
EagleEye-TraceId
X-WebKit-CSP
Ali-Swift-Global-Savetime
X-Aws-Lambda-Call-Status
X-CST
X-OneAgent-JS-Injection
X-Backend-Server
Permissions-Policy
X-Server-Id
X-Readtime
X-Response-Time
X-Host
X-Akam-SW-Version
Request-Id
Surrogate-Control
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Nginx-Upstream-Cache-Status
X-HW
Accept-Ch-Lifetime
X-Cloud-Trace-Context
X-Nginx-Cache-Status
X-Litespeed-Cache
X-Node
X-Application-Context
X-Country-Code
X-Cache-Lookup
X-Ruxit-JS-Agent
X-Trace
Content-Location
Service-Worker-Allowed
X-Url
X-Content-Type
X-Country
X-Clacks-Overhead
X-Oneagent-Js-Injection
X-Edge
X-ECACHE
X-Origin-Cache-Key
X-Mcache
Accept-Ch
X-Mod-Pagespeed
X-Amz-Server-Side-Encryption
X-Midtier
Cross-Origin-Opener-Policy
X-FTR-Request-ID
X-Rack-Cache
Cache-Tag
X-MS-InvokeApp
Nginx-Cache
X-Upstream
X-PC
X-ESI
X-TtlSet
X-Vname
X-Powered-By-Plesk
Rating
Edge-Control
X-Browser-Type
X-D2id
X-Element-Page-Cache
Verso
X-Server-Name
X-Kinja-Revision
X-GoogleNews-Bot
X-Exp-Variant
X-Exp-Id
X-Kinja
X-Kinja-Build
X-Kinja-Server
X-Cdn-Fetch
X-Times
X-B3-TraceId
X-Cnection
SPIisLatency
SPRequestDuration
X-Ac
AR-Request-ID
AR-SID
AR-PoweredBy
AR-ATIME
X-Abt-Application-Version
X-SharePointHealthScore
X-Navigation-Version
X-Vcap-Request-Id
SPRequestGuid
X-RateLimit-Remaining
X-NF-Request-ID
X-Dw-Request-Base-Id
X-Ruxit-Js-Agent
X-GitHub-Request-Id
X-Ser
X-VARITI-CCR
AR-CACHE
Pinterest-Generated-By
X-Pinterest-Rid
Pinterest-Version
X-Mg-S
X-Cache-Key
S
Display
RTSS
Pagespeed
X-Middleton-Display
X-Sol
X-Client-IP
X-Ttl
X-NWS-LOG-UUID
X-Cache-TTL
Edge-Cache-Tag
Fastly-Restarts
X-Amzn-Trace-Id
X-Amz-Rid
Origin-Trial
X-Powered-CMS
X-Goog-Hash
X-Erf-Bev-Bev
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-Kraken-Loop-Name
X-Version
X-Server-ID
Cache-Status
X-Edge-Location-Klb
X-Kinsta-Cache
Access-Control-Request-Method
X-Varnish-TTL
X-Content-Security-Policy-Report-Only
X-Recruiting
X-ARC
X-TraceId
X-Content-Digest
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
Arr-Disable-Session-Affinity
X-T
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Response
X-Middleton-Response
X-MSEdge-Ref
X-Forwarded-For
X-Ua-Device
Content-MD5
MicrosoftSharePointTeamServices
X-Accel-Expires
TP-Cache
X-Shield-Request-Id
X-Cached
X-Hits
X-Id
X-FTR-Backend
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Cache-Status
X-Country-Code-Real
Public-Key-Pins
X-FTR-Expires
X-Request-Processing-Time
MS-Author-Via
X-Request-Received
X-Ua-Browser
Front-End-Https
Server-Node
Payment
Cross-Origin-Resource-Policy
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Hub-Id
X-Frontend
X-Webkit-Csp
X-DIS-Request-ID
X-RateLimit-Limit
X-Forwarded-Proto
X-LLID
X-Daa-Tunnel
X-HP-Trace-Id
X-GUploader-UploadID
X-HP-Webp
X-Jurisdiction
X-Fastcgi-Cache
X-FastCGI-Cache
TP-L2-Cache
X-LB-Cache
Realpath
X-Protected-By
Cache-Tags
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Origin-Server
X-WebKit-CSP-Report-Only
X-Distributor
Count-Hit
X-Request-Handler-Origin-Region
X-Microsite
X-Page-Id
X-ORACLE-DMS-RID
X-F-Cache
X-NGENIX-Cache
X-Kinja-CCPA
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-Www-Served-By
X-Activity-Id
X-AppVersion
X-Az
Referer-Policy
X-Hostname
Accept-Charset
X-Cluster-Name
X-Debug-Info
X-Varnish-Backend
X-Geo-Country
X-App-Server
X-Envoy-Decorator-Operation
X-Correlation-Id
Fastcgi-Cache
X-PressLabs-Stats
Host
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Varnish-Server
X-TTL
X-Goog-Metageneration
X-FB-Debug
Access-Control-Allow-Method
X-Git-Hash
X-RateLimit-Reset
X-ORACLE-DMS-ECID
Retry-After
X-Oracle-Dms-Ecid
X-Ratelimit-Limit
X-XRDS-LOCATION
X-Rid
Server-Name
X-Content-Options
X-Load-Cache
X-CSRF-Token
X-Px
X-Upgrade-Enabled
X-Contextid
X-Fastly-Request-Id
X-Aspnet-Duration-Ms
X-Tt-Trace-Host
X-Request-Guid
X-Tt-Trace-Tag
X-Flags
X-Route-Name
X-Providence-Cookie
X-Is-Crawler
DC
X-Revision
X-Origin-Cache
X-Cache-Control
TCN
X-B-Cache
X-Signature
X-Grace
X-App-Environment
Charset
X-Datadog-Parent-Id
Paypal-Debug-Id
X-Type
X-Trace-Id
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Oracle-Dms-Rid
Section-Io-Cache
X-B
Cleartype
X-Seen-By
X-Ezoic-Cdn
X-TT
X-ASPNET-VERSION
X-Amz-Meta-S3cmd-Attrs
X-Mobile
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-B3-Sampled
X-Fb-Rlafr
Healthy
Frame-Options
X-Amz-Replication-Status
X-Wix-Request-Id
X-Whom
X-Varnish-Ttl
X-Magnolia-Registration
X-Language
X-Logged-In
X-Goog-Stored-Content-Encoding
X-Node-Name
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Storage-Class
Filterid
X-EdgeConnect-Cache-Status
X-Azure-Ref
X-Fastly-Request-ID
X-Proxy
X-Newrelic-App-Data
X-N
X-Air-Pt
X-App-Version
Backend
Content-Disposition
Akamai-GRN
X-Template
NGB
Upgrade-Insecure-Requests
Refresh
X-Proxy-Cache-Info
X-Response-Served-From
X-Original-Request-Id
X-Rendered-As
X-Is-Bot
X-Tumblr-Pixel-1
VIX-Pulpo-Node
X-Tumblr-Pixel-0
X-Page-View
X-ProcessESI
X-Yottaa-Optimizations
X-Tumblr-User
X-RemovedCookies
X-Tumblr-Pixel
X-Unique-Id
SD-X-WS
VIX-Pulpo-Upstream-Status
X-Yottaa-Metrics
X-Datadog-Sampled
X-Amzn-Remapped-Content-Length
X-Debug-IsConnected
X-Debug-IsPreview
Viewport
X-Adobe-Content
X-Adobe-Loc
X-Instance
X-Servername
X-WP-CF-Super-Cache
Liferay-Portal
X-Varnish-Grace
X-WP-CF-Super-Cache-Cache-Control
X-UUID
MS-CV
X-B3-SpanId
Fastly-SWR
Ms-Operation-Id
X-RTag
X-G
Fastly-SIE
X-IPS-LoggedIn
X-Ratelimit-Remaining
X-NYM-Debug-Backend
X-Cacheable-TTL
X-FW-Server
X-FW-Hash
X-Device-Type
X-FW-Dynamic
X-Debug
X-FW-Serve
X-FW-Static
X-FW-Type
Url
X-Cache-Grace
X-User-Agent
X-Region
X-FW-Version
From-Origin
X-Rule
Country
X-Jobs
X-Cache-Hit
X-Status
X-Environment-Context
X-L-Path
X-Backend-Name
X-Hl-Ver
ServerID
Surrogate-Key
X-Webkit-CSP
X-Hosted-By
X-Air-Source
X-Air-Hostname
X-Cache-Age
X-Air-Trace-Id
Countrycode
X-Time
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
X-VC-Cache
X-Origin-TTL
X-Origin-CC
Alternate-Protocol
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-Content-Powered-By
X-Http-Reason
X-NODE
Amp-Access-Control-Allow-Source-Origin
X-Akamai-Request-ID2
X-Cache-Status-Check
X-INCAP-ABP
Protected
X-Via-JSL
WPO-Cache-Status
WPO-Cache-Message
X-HTML-Minification-Powered-By
Version
X-Rocket-Nginx-Serving-Static
X-Akamai-Edgescape
GEO-INFO
X-Framework
CDN-RequestId
X-Storage
X-WP-CF-Super-Cache-Active
X-Edge-Location
X-Source
SRV
X-Accel-Version
Access-Control-Request-Headers
X-Cache-Rule
X-CDN-Forward
X-XRDS-Location
CF-IPCountry
X-Nginx-Cache
Front
X-Httpd
X-Use-Magma
X-Use-Mantle
OT-Force-Account-Verify
X-Real-IP
Accept-Language
X-UPSTREAM-Address
X-Cache-Operation
X-Upstream-Ht
Meta-Geo
X-Upstream-Ct
X-Endurance-Cache-Level
X-Rn-Rsrv
Webserver
Filters
X-Rewrite-Enabled
X-Proxy-Build
X-Detected-As
X-Cache-Debug
X-JoinUs
X-VC
X-Tumblr-Pixel-3
X-Soup
X-Timing-Wait
X-Served-From
X-Xfnlog-Site
X-SaId
X-Director
X-Tumblr-Pixel-2
Selected-Fe
X-Sql-Duration-Ms
X-Mode
X-Handled-By
ServedBy
X-Cms-Context
X-Adobe-Source
X-Worker
X-Sql-Count
X-Origin
X-ProxyCache-Key
X-SayCDN-TTL
X-Varnish-Cache-Hits
X-Say-TTL
X-Say-Cacheable
X-Redis-Cache
X-BYPASS-REASON
X-Logging-Id
X-ProxyCache-Status
X-Varnish-Age
DB-Nickname
X-Cache-Time
X-GeoCode
TWC-Locale-Group
Webcakes-Region
X-Format
Azure-InstanceId
Azure-RegionName
Azure-SlotName
Azure-Version
TWC-Privacy
X-RM-Cache-TTL
X-S
X-PHP-Host
TWC-Connection-Speed
Web-Mar-Node
Xet-Cookie
TWC-Device-Class
TWC-GeoIP-Country
X-Labrador-Cache-Channel
Xserver
TWC-GeoIP-LatLong
X-GeoCountry
X-VCT
X-Tncms
X-Origin-Hint
Azure-SiteName
Property-Id
Webcakes-App-Version
X-B3-Traceid
Webcakes-App-Name
X-Loop
X-Cache-Server
X-Container-Uri
X-No-Session
X-Tb
X-Skip-Cache
X-Git-Commit
X-Varnish-Beresp-Grace
X-Vercel-Cache
X-Lambda-Id
X-Vercel-Id
X-Server-W
AMP-Access-Control-Allow-Source-Origin
X-Fetched-On
X-Restarts
X-DynaTrace
X-Generation-Time
X-RCS-CacheZone
X-Browser-Name
X-Ms-Request-Id
X-Provided-By
X-Ms-Version
X-AB
X-Web-Node
X-Tcp-Rtt
Section-Io-Id
X-Is-Tablet
X-Is-Supported-Browser
X-Geo-Region
X-Frame-Option
X-IPLB-Instance
X-IPLB-Request-ID
X-Is-Mobile
X-Is-Desktop
X-Cache-Host
Mn-Server-Ip
Apigw-Requestid
X-ServerID
Node
X-Vcache
X-Site-Version
X-Forwarded-Host
X-Locale
X-Reqid
X-Cluster
X-R9-Blue-Green-Version
Cross-Origin-Embedder-Policy
X-VWS-Id
X-LJ-Flow-ID
X-Platform-Router
X-Platform-Cluster
X-Platform-Processor
X-AWS-Id
X-COUNTRY
X-Uri
X-Webstats-RespID
Source
X-Routing-Service
Priority
X-Proxied
X-Zipkin-Id
X-Drupal-Cache-Contexts
X-FB-TRIP-ID
Cache-Tv-Group
X-Extlb
X-MP-GENERATED-AT
X-Drupal-Cache-Tags
Fastcgi-Useragent
Content-Secure-Policy
CDN-RequestPullCode
CDN-Uid
CDN-RequestPullSuccess
WP-Super-Cache
CDN-CachedAt
CDN-EdgeStorageId
CDN-PullZone
CDN-RequestCountryCode
X-Vcl-Version
CDN-Cache
X-Origin-Date
X-Alternate-Cache-Key
X-Shopify-Stage
X-Storefront-Renderer-Rendered
Onion-Location
X-TT-LOGID
X-Generated-By
WZWS-RAY
X-Urbn-Site-Id
X-SRV
Locale
X-Urbn-Context-Path
X-Xrds-Location
X-Content-Age
X-Sucuri-Cache
X-ShardId
S-Rt
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-ShopId
X-Pass-Why
X-Cdn-Origin
X-Newrelic-Synthetics
X-Sucuri-ID
X-Ua
X-Cluster-Node
Sid
X-Buckets
X-Proxy-Cache-Status
X-Varnish-Beresp-Ttl
Cross-Origin-Embedder-Policy-Report-Only
X-Cache-Action
X-Cache-Expired-At
Thinkindot-Control
Thinkindot-CacheControl-Type
X-CMSURLCustom
X-Thinkindot-L3
Cross-Origin-Window-Policy
TDXMobile
X-Shield-Cache-Expires
X-Scope-Id
Thinkindot-CacheControl
X-DataDome
X-LSADC-Cache
Cache
Atl-Traceid
X-GEO
HostName
Fastly-Drupal-HTML
X-Mg-Request-UUID
Edge-Copy-Time
X-Via-SSL
X-Via-Edge
X-Via-CDN
X-Request-URI
X-Aspnetmvc-Version
DCR-Decision-By
Origin-Agent-Cluster
X-Rojux
Redirect-Candidate
DCR-Processing-Time-Ms
Sslversion
Rendered-Blocks
X-Viewer-Country
Lang
MD5-Digest
Meta-Geo-Continent
X-Vtex-Remote-Cache
X-TIM-N
X-Vdms-Path
X-Optimistic-Header
Ngx-Var-Key
Gannett-Cam-Experience-Id
X-Vdms-Version
Origin
Ngx.Var.Host
Environment
X-A-Dam
X-Destination
X-Application
X-Correlation-ID
X-Aed
X-Developer
X-Ec-Fail
X-Ec-Custom-Error
X-B-Cookie
X-D
X-Bl-Debug
X-Cache-Bucket
X-Scheme
X-VCache
X-BCube-Filmed-By
X-Conf
X-Bc-Bl
X-A-Wwc
X-A-Dgt
X-SRCache-Key
X-ScT
X-S-Cookie
Type
Surrogated-Key
T-Server
X-External-Request-Id
X-A
X-PAYTM-SRV-ID
Candidate-Md5Url
X-A-Dcw
X-A-Ccd
X-Ec-GeoHdr
X-Cache-NE
X-Epic-Correlation-Id
X-WP-CF-Super-Cache-Cookies-Bypass
X-Datadome
X-TimeS
X-Human
X-Instance-Name
X-Section
L
X-GeoIP-Region-Code
X-GeoIP-Country-Code
Vix-Hermes-Req-Id
X-Gdpr
X-Generated-On
Host-ID
X-Forwarded-Site
X-Node-Id
X-SD-PageType
X-Mly-Id
X-Nyt-Route
CDCHOST
X-Loc
DSUID
X-Level-Front-Cache
Fastly-SSL
Fastly-GeoIP-CountryCode
V-Age
X-Fastly-Cache
Server-Host
X-Core-Value
X-B3-Trace-ID
X-Sigma-Backend
X-Debug-Cache-Fetch
Pramga
Ssr
X-Clientip
Release
X-Bip
X-BBC-Edge-Cache-Status
X-Debug-Cache-Store
X-Aicache-OS
X-Access
Req-ID
Req-Svc-Chain
Magicmarker
X-Dispatcher-Server
X-Sigma
X-Acquia-Purge-Cdn-Unconfigured
X-TH-Server
X-Thanos
X-Cache-Info
Apple-News-Services-Request-Url
X-Varnish-Beresp-Status
X-WA-Info
X-Op-Id-All
X-Pubstack
X-Request-Start
Apple-News-Services-Handled
X-Platform
X-Req
X-Varnish-Hostname
X-VServer
X-Origin-Time
X-We-Are-Hiring
X-VG-WebCache
X-Varnishpool
X-VG-TLSProxy
Apple-News-Services-Host
X-Varnish-Director
X-Pool
X-Proxied-Request
X-Rocket-Build-Number
X-Request-Time
Apple-News-Services-Parsed-Url
X-Origin-Response-Time
True-Client-Country-4JS
X-Esi-Check
Tube-Got-Results
X-SVT-ORM-RULES
Tube-Get-Contents
Tube-Got-Eval
X-Zen-Fury
Sever-Int
X-RateLimit-Remaining-Second
X-FC-Vary-Parameters
X-TA-CDN-Provider
Server-Ext
Server-Hostname
X-Cache-Date
X-SVT-ORM-VERSION
X-NMSegId
X-Auto-Login
X-ApacheServer
X-SB
Wxu-Next-Commit
Web-Mar-Region
Wxu-Next-Hostname
Wxu-Next-Region
X-Policy
X-PERF
X-V-Cache
We-Hiring
X-Ad-Load-Variation
Uber-Trace-Id
X-DPWN-IS-SECURE
X-Cache-Id
X-RateLimit-Limit-Second
X-Cache-TTL-Remaining
X-Device-Os
Cluster
Tube-Return
X-From
Adler-Geo
X-Mvc-Supplant-Cachable
X-Request-Host
Gh-Request-Id
X-Irp-Debug
X-Server-IP
X-Mvc-Supplant-OutputCached
Is-Eu
Esi-Enabled
X-Men
X-Old-Content-Length
Click-Count-Error
Click-Count-Action-Start
X-Var-Ttl
X-Micro-Cache
X-Up
Country-Code
Machine
Mail-Subject
X-Geo-Header
X-GeoIP
X-GeoIP-City
Platform
Cache-Provider
X-Fmm-Version
Canary
Producers
On-Server
NM-Fastcgi-Cache
X-NCache
X-HS-Content-Campaign-Id
X-Gzip
X-Org
X-Service
X-DC
Expiry
X-Connection-Hash
User-Cache-Control
Content-Style-Type
X-Proto
X-Branch-Name
X-Block-Status
A
X-Gen-Mode
Content-Script-Type
X-Fastly-Backend
X-Edge-Server
X-Hash
X-Core-Mission
X-Nginx-Cache-Key
X-Hnp-Log
X-Cdn-Srv
X-Contensis-Viewer-Groups
Cdn-Host
X-ZONE
X-Moov-T
Cdn-Request-Time
X-UA-Device-Type
X-Cache-Aspx
W
Cf-Device-Type
X-Test
C-Via
X-Varnish-Authentication
X-Moov-Xdn-Version
AKAMAI
X-App-Name
X-GoCache-CacheStatus
X-Parent-Response-Time
X-Dc
RNT-Time
L5d-Success-Class
IsBot
NGX
X-Eu-Site
Pics-Label
X-Wikidot-Static-Cache
HA-Ipaddr
Cache-Key
X-Ah-Environment
Fastly-Backend-Name
X-Sn-Servicetimems
RNT-Machine
X-Slack-Backend
X-Slack-Shared-Secret-Outcome
X-Wikidot-Backend
X-CacheTTL
X-SIPLIST1
X-Csrf-Jwt
X-CGP
Proxy-Firewall
Ha-Gx-Prefs
Datacenter
X-NGINX-Cache
X-Via-Popv
X-ND-Cache
Expect-Staple
N-Cache
X-HA-Backend
X-Via-Poph
X-Via-Popn
Yak-Timeinfo
X-Amz-Meta-Cb-Modifiedtime
LB
Cdncip
Cdnsip
X-Date
Locid
X-Accel-Expires-Debug
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Qloud-Router
X-AK-Request-ID
X-Region-Sid
X-Owner
X-HN
PFcat
X-LB-NoCache
X-Cache-Type
X-Tx-Id
X-Tenant
X-Amz-Storage-Class
X-Orig-Expires
X-LB-ID
Xc-Version
X-Shop-Environment
X-Forwarded-Path
X-VarnishDD-TTL
X-Ratelimit-Reset
Cdn
X-Backend-Instance
X-Tb-Optimization-Total-Bytes-Saved
X-Gamma-Serve
X-Azure-Ref-OriginShield
X-Refresh
X-VHOST
X-Nc
Cmstype
SID
X-Varnish-Hits
X-Wa
X-Tt-Logid
RATING
NtCoent-Length
Cmsid
X-DynaTrace-JS-Agent
XM
X-Servedbyhost
GeoIp-Country-Code
X-CDN-Cache-Status
Cdn-Requestid
X-Origin-Expires
X-API-Version
X-Cache-Backend
CPC-Cache
CPC-Age
Server-ID
X-Cdn-Diag
X-Vmg-Version
X-Nananana
X-TIME
X-Akamai-Transformed
X-Lagoon
X-Srv
X-Fpc
CloudFront-Viewer-Country
X-Via-Fastly
X-TX-ID
X-LAGOON
X-Api-Version
Resin-Trace
X-B3-Parentspanid
X-Hit
X-NewRelic-App-Data
CacheControlHeader
X-Zone
XkeyRZ
Cross-Origin-Opener-Policy-Report-Only
X-Proxy-CacheRZ
User-Agent
X-Variation
X-Nf-Request-Id
Uri
X-UA
X-Client-Ip
X-CACHE-AGE
X-Presslabs-Stats
X-URL
X-Fastly-Country-Code
X-Amz-Meta-Opti
MIME-Version
GeoIP-Latitude
X-Info
Tcn
X-LiteSpeed-Tag
X-ECache
True-Client-Ip
True-Client-IP
Cache-Hits
X-DataCenter
VNS-Age
X-Datacenter
VNS-Cache
X-Ig-Origin-Region
X-Location
Lb
X-Dynatrace-Js-Agent
X-LiteSpeed-Cache-Control
X-HostName
DataCenter
Fusion-Deployment-Id
X-Geo
Fusion-Source
Fusion-Template-Id
X-RID
Mime-Version
X-Vc
Fusion-Component-Id
Cache-Name
Fusion-Content-Source
Fusion-Content-Id
X-NWS-UUID-VERIFY
Powered-By
Hostname
Cf-Ipcountry
Fastly-Drupal-Html
X-B3-Spanid
X-Cdn-Forward
Srv
X-HOST
X-Cached-By
X-Dispatcher-Number
X-Jungle-Id
X-CUA
X-CSRF-TOKEN
X-CS
Origin-CC
X-IAuth-Set-Uid
X-Segment-20210421
X-AIR-PT
X-User
Origin-EX
X-Webkit-Csp-Report-Only
X-Cloudmap
Debug
X-Mid
X-Varnish-Beresp-TTL
Cl-Cache
X-MCACHE
Load-Balancing
X-Esi
X-Render-Time
X-VTEX-Cache-Server
X-Powered-By-VTEX-Cache
X-FPC
Ohc-File-Size
X-VTEX-Cache-Time
X-Wormhole-Sdk
GeoIP-Country-Code
BehaviorPad-Version
CDN
X-Dispatch
X-Litespeed-Tag
X-Cs
X-Oracle-DMS-ECID
Edge-Cache
Server-Id
X-WA
X-Auth-Group-Type
X-Cdn-Cache-Status
X-NC
Ohc-Cache-HIT
X-Lb-Id
YJS-ID
X-Cache-Enabled
X-ServedByHost
X-Lb-Nocache
X-Ig-Push-State
X-NodeID
CountryCode
Location
X-Fastly-Backend-Reqs
My-App
Server-Info
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
Wpo-Cache-Message
Ms-Author-Via
X-Litespeed-Cache-Control
X-APP-VERSION
Wpo-Cache-Status
X-VCL-Version
CF-Cached-On
X-Akamai-Pragma-Client-IP
CF-Ctrl
X-Proxy-Cache-La3
Odigeo-Trace-Id
Xkeylog
X-MiniProfiler-Ids
X-Cdn-Request-ID
X-MSEdge-Features
X-Snapshot-Date
X-Internal-Host
Xkey-La3
X-MSEdge-Flight
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-Acquia-Site
Time
X-Acquia-Application-Trace
X-Acquia-Application-UUID
Memory
Memcached
OriginIP
X-App
Section-Origin-Responded
X-Nitro-Cache-From
Srvid
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
X-FL-EDGE
X-FL-QIT-DEBUG
FSS-Cache
X-Pad
X-Vgn-Hpd-Reason
Ngx
X-Acquia-Purge-Tags
X-Nitro-Rev
X-Nitro-Cache
X-Custom-Header
X-Sorting-Hat-Shopid
X-Sorting-Hat-Podid
X-Cache-Version
X-Shardid
X-Shopid
X-Te-Count
Akamai-Cache-Status
PICS-Label
X-Depends
X-PHP-Backend
Cloudfront-Viewer-Country
X-Te-Duration-Ms
X-Http-Count
X-Http-Duration-Ms
X-Cache-FS-Status
X-Check-Cacheable
X-RequestId
X-Udemy-Cache-App-Namespace
X-Fastly-Cache-Hits
Geoip-Latitude
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Lsadc-Cache
X-Sucuri-Id
X-Th-Server
X-Via-PopV
X-Via-PopN
X-Service-Response-Time
X-Web-Server
X-Dw-Trace-Id
X-Serial
Sm-Log-Id
X-Via-PopH
X-Ha-Backend
X-Mg-Cache