Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
CF-RAY
X-XSS-Protection
Accept-Ranges
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
P3P
X-Served-By
X-Xss-Protection
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
X-AspNet-Version
Content-Security-Policy-Report-Only
X-Runtime
Accept-CH
X-DNS-Prefetch-Control
P3p
X-Cache-Status
Accept-CH-Lifetime
X-Drupal-Cache
X-Ua-Compatible
X-Check
X-Generator
Server-Timing
X-Cacheable
X-Envoy-Upstream-Service-Time
X-FRAME-OPTIONS
Timing-Allow-Origin
X-Iinfo
X-Request-ID
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
X-Content-Security-Policy
Feature-Policy
Content-Encoding
X-CDN
Status
X-AspNetMvc-Version
Upgrade
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
X-Amz-Id-2
CF-Ray
Host-Header
Cf-Edge-Cache
X-Backend
Request-Context
Allow
Keep-Alive
X-UA-Device
X-Robots-Tag
X-Server
X-Cache-Group
X-Hacker
X-AH-Environment
X-Turbo-Charged-By
X-Ws-Request-Id
X-Proxy-Cache
EagleId
Xkey
X-Age
X-Rq
X-Vhost
X-Dispatcher
X-Server-Powered-By
X-Amz-Version-Id
X-Varnish-Cache
Grace
Cf-Apo-Via
X-Swift-SaveTime
X-Swift-CacheTime
X-Page-Speed
X-Pingback
Ali-Swift-Global-Savetime
Cf-Railgun
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
X-LiteSpeed-Cache
EagleEye-TraceId
X-Dns-Prefetch-Control
X-WebKit-CSP
X-Aws-Lambda-Call-Status
X-CST
Permissions-Policy
X-OneAgent-JS-Injection
X-Backend-Server
X-Readtime
X-Host
X-Server-Id
X-Response-Time
X-Akam-SW-Version
Request-Id
Surrogate-Control
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Cache-Lookup
X-Litespeed-Cache
X-HW
X-Nginx-Upstream-Cache-Status
X-Cloud-Trace-Context
X-Node
X-Nginx-Cache-Status
X-Application-Context
X-Country-Code
Content-Location
X-Country
X-Trace
Service-Worker-Allowed
X-Ruxit-JS-Agent
X-Url
X-Content-Type
X-Clacks-Overhead
X-Oneagent-Js-Injection
X-Origin-Cache-Key
Accept-Ch-Lifetime
X-Edge
X-Rack-Cache
Cache-Tag
Cross-Origin-Opener-Policy
X-FTR-Request-ID
X-Amz-Server-Side-Encryption
X-Midtier
X-Mcache
X-Mod-Pagespeed
X-TtlSet
X-PC
X-Vname
X-MS-InvokeApp
Rating
Nginx-Cache
X-ECACHE
X-ESI
X-Upstream
X-Powered-By-Plesk
Edge-Control
X-Server-Name
X-Browser-Type
X-Cnection
X-D2id
X-Times
X-Element-Page-Cache
Verso
X-Kinja-Revision
X-Kinja-Server
X-Kinja-Build
X-Cdn-Fetch
X-Exp-Variant
X-Kinja
X-GoogleNews-Bot
X-Exp-Id
X-NWS-LOG-UUID
SPRequestDuration
X-Ac
X-Ruxit-Js-Agent
SPIisLatency
AR-Request-ID
AR-PoweredBy
AR-SID
AR-ATIME
X-Ser
SPRequestGuid
X-SharePointHealthScore
X-Abt-Application-Version
X-Navigation-Version
X-GitHub-Request-Id
X-Dw-Request-Base-Id
X-B3-TraceId
X-RateLimit-Remaining
X-Vcap-Request-Id
X-NF-Request-ID
AR-CACHE
X-Ttl
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
X-Mg-S
X-Client-IP
X-VARITI-CCR
S
Edge-Cache-Tag
Pagespeed
Display
X-Sol
X-Middleton-Display
X-Server-ID
X-Cache-Key
Fastly-Restarts
RTSS
X-Cache-TTL
X-Amz-Rid
X-Amzn-Trace-Id
Cache-Status
X-Kraken-Loop-Name
X-Instrumentation
X-Erf-Bev-Bev
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev-Is-Generated
X-Powered-CMS
X-Version
X-Edge-Location-Klb
X-Kinsta-Cache
Access-Control-Request-Method
X-Goog-Hash
X-Recruiting
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-ARC
Response
X-Middleton-Response
X-Content-Digest
X-Varnish-TTL
X-Daa-Tunnel
X-TraceId
X-Forwarded-For
X-T
Arr-Disable-Session-Affinity
Content-MD5
X-MSEdge-Ref
MicrosoftSharePointTeamServices
X-SRCache-Store-Status
X-SRCache-Fetch-Status
TP-Cache
Front-End-Https
Origin-Trial
X-Accel-Expires
Cross-Origin-Resource-Policy
X-Shield-Request-Id
X-Cached
X-Content-Security-Policy-Report-Only
MS-Author-Via
Public-Key-Pins
X-FTR-Backend-Server
X-Id
X-Country-Code-Real
X-FTR-Cache-Status
X-Hits
X-FTR-Backend
X-FTR-Balancer
X-HS-Content-Id
X-HS-Hub-Id
X-FTR-Expires
X-HS-Cache-Config
X-HS-Combine-CSS
Server-Node
X-Forwarded-Proto
X-Ua-Browser
X-DIS-Request-ID
X-Frontend
Payment
X-Request-Received
X-Request-Processing-Time
X-FastCGI-Cache
X-Webkit-Csp
X-LLID
Realpath
X-Jurisdiction
X-HP-Webp
X-HP-Trace-Id
X-Fastcgi-Cache
X-Protected-By
TP-L2-Cache
X-GUploader-UploadID
X-ORACLE-DMS-RID
X-Distributor
Cache-Tags
X-LB-Cache
X-Hostname
X-Ratelimit-Limit
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Request-Handler-Origin-Region
X-Kong-Proxy-Latency
X-Microsite
X-Kong-Upstream-Latency
X-RateLimit-Limit
X-Origin-Server
X-B3-TraceId-Primal
X-Debug-Info
Referer-Policy
MRF-Tech
Mrf-Cache-Status
X-Az
X-Activity-Id
Host
X-AppVersion
X-Page-Id
Count-Hit
X-NGENIX-Cache
Fastcgi-Cache
X-Www-Served-By
X-Geo-Country
X-Envoy-Decorator-Operation
X-Cluster-Name
X-Varnish-Server
X-Varnish-Backend
X-Correlation-Id
Accept-Charset
X-F-Cache
X-Ua-Device
X-App-Server
X-PressLabs-Stats
X-XRDS-LOCATION
X-Varnish-Ttl
X-FB-Debug
X-Goog-Metageneration
Retry-After
X-ORACLE-DMS-ECID
X-Load-Cache
X-Ezoic-Cdn
Access-Control-Allow-Method
X-CSRF-Token
X-Upgrade-Enabled
X-Git-Hash
TCN
X-Seen-By
X-RateLimit-Reset
X-Px
X-Content-Options
Server-Name
X-TTL
X-Revision
X-Contextid
X-Request-Guid
Section-Io-Cache
X-Cache-Control
X-Tt-Trace-Host
X-Trace-Id
X-Tt-Trace-Tag
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Type
X-Oracle-Dms-Ecid
X-Datadog-Trace-Id
X-Webkit-CSP
X-B
Healthy
X-Grace
Charset
X-Amz-Meta-S3cmd-Attrs
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
Cleartype
X-TT
X-B3-Sampled
X-Fastly-Request-Id
X-Whom
X-Fb-Rlafr
DC
Paypal-Debug-Id
X-Fastly-Request-ID
X-Wix-Request-Id
X-Signature
X-B-Cache
X-Node-Name
X-App-Environment
X-Origin-Cache
X-Proxy
X-Mobile
X-Azure-Ref
Accept-Ch
X-Magnolia-Registration
X-Newrelic-App-Data
X-Oracle-Dms-Rid
Frame-Options
X-Ratelimit-Remaining
X-Amz-Replication-Status
X-Air-Pt
X-WP-CF-Super-Cache-Cache-Control
X-WebKit-CSP-Report-Only
X-Goog-Generation
X-Goog-Stored-Content-Length
X-WP-CF-Super-Cache
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-N
Filterid
X-Rid
X-Logged-In
X-EdgeConnect-Cache-Status
Content-Disposition
X-Providence-Cookie
X-Flags
X-Is-Crawler
X-Aspnet-Duration-Ms
X-Route-Name
X-Language
Backend
Akamai-GRN
X-Time
NGB
X-Response-Served-From
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-Original-Request-Id
X-Datadog-Sampled
X-Yottaa-Metrics
X-Debug-IsConnected
X-Unique-Id
X-Cache-Age
SD-X-WS
Ms-Operation-Id
X-Is-Bot
X-ProcessESI
X-Rendered-As
X-Yottaa-Optimizations
X-RemovedCookies
X-Debug-IsPreview
X-Servername
MS-CV
X-Varnish-Grace
X-RTag
X-Tumblr-User
Liferay-Portal
X-Hl-Ver
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Via-JSL
Upgrade-Insecure-Requests
X-Adobe-Loc
Viewport
X-Adobe-Content
X-UUID
Fastly-SWR
X-Amzn-Remapped-Content-Length
X-L-Path
X-NYM-Debug-Backend
X-Region
X-G
X-Environment-Context
X-Cacheable-TTL
X-Backend-Name
Fastly-SIE
X-Template
X-FW-Type
X-FW-Static
X-FW-Version
X-Instance
From-Origin
X-IPS-LoggedIn
X-FW-Server
X-Kinja-CCPA
X-Device-Type
X-Debug
X-FW-Dynamic
X-Cache-Grace
X-FW-Hash
X-FW-Serve
X-Proxy-Cache-Info
Refresh
X-User-Agent
X-Rule
X-B3-Traceid
X-Cache-Hit
Country
ServerID
X-Status
Url
X-VC-Cache
X-App-Version
X-Tec-Api-Version
X-Tec-Api-Root
X-B3-SpanId
Countrycode
X-Tec-Api-Origin
X-INCAP-ABP
X-Jobs
Version
X-Source
Alternate-Protocol
X-HTML-Minification-Powered-By
WPO-Cache-Message
X-Cache-Status-Check
WPO-Cache-Status
X-NODE
GEO-INFO
CDN-RequestId
X-Air-Hostname
X-Air-Trace-Id
X-Nginx-Cache
X-Air-Source
X-WP-CF-Super-Cache-Active
X-Akamai-Request-ID2
X-Origin-CC
X-Origin-TTL
Surrogate-Key
X-Storage
Amp-Access-Control-Allow-Source-Origin
X-Content-Powered-By
X-Hosted-By
SRV
Protected
OT-Force-Account-Verify
X-Page-View
X-Rocket-Nginx-Serving-Static
X-Real-IP
X-Accel-Version
X-VC
Access-Control-Request-Headers
X-CDN-Forward
X-Akamai-Edgescape
AMP-Access-Control-Allow-Source-Origin
X-ServerID
X-Edge-Location
X-Framework
CF-IPCountry
X-Use-Mantle
X-Mode
X-Cache-Time
X-Cache-Operation
X-Cache-Rule
X-Rn-Rsrv
Meta-Geo
X-Rewrite-Enabled
X-Xfnlog-Site
X-UPSTREAM-Address
Front
Filters
Cross-Origin-Embedder-Policy
X-Proxy-Build
X-AWS-Id
X-Served-From
X-Soup
X-LJ-Flow-ID
X-Origin
Accept-Language
X-SaId
X-Cache-Debug
X-Handled-By
Selected-Fe
Webserver
Mn-Server-Ip
X-Detected-As
X-Endurance-Cache-Level
X-Timing-Wait
X-VWS-Id
Xet-Cookie
X-JoinUs
ServedBy
X-Adobe-Source
X-Proxied
X-Director
X-Tumblr-Pixel-3
Node
X-BYPASS-REASON
X-Cluster
X-Cms-Context
X-ProxyCache-Key
X-ProxyCache-Status
X-Tumblr-Pixel-2
X-Extlb
X-No-Session
Section-Io-Id
X-Platform-Cluster
X-Lambda-Id
Xserver
X-Web-Node
X-Worker
X-Zipkin-Id
X-Platform-Processor
X-Varnish-Cache-Hits
X-Say-Cacheable
X-Routing-Service
X-Say-TTL
X-SayCDN-TTL
Apigw-Requestid
X-Logging-Id
X-Platform-Router
Webcakes-App-Name
TWC-GeoIP-Country
Webcakes-App-Version
TWC-Device-Class
X-AB
TWC-Privacy
Webcakes-Region
TWC-Locale-Group
Web-Mar-Node
TWC-Connection-Speed
TWC-GeoIP-LatLong
X-Redis-Cache
X-Site-Version
X-Webstats-RespID
X-S
X-RM-Cache-TTL
X-Restarts
X-VCT
X-Skip-Cache
Property-Id
X-Tcp-Rtt
X-Upstream-Ct
X-Upstream-Ht
X-Varnish-Beresp-Grace
X-RCS-CacheZone
X-PHP-Host
X-Geo-Region
X-GeoCode
X-Forwarded-Host
X-Format
X-Drupal-Cache-Tags
X-GeoCountry
X-Is-Desktop
X-Labrador-Cache-Channel
X-Origin-Hint
X-Is-Tablet
X-Is-Supported-Browser
X-Is-Mobile
X-Browser-Name
DB-Nickname
X-Httpd
X-Vcache
X-Git-Commit
X-IPLB-Instance
X-Generation-Time
X-Fetched-On
X-Container-Uri
X-Drupal-Cache-Contexts
X-IPLB-Request-ID
X-Tncms
X-Http-Reason
X-Loop
X-Reqid
X-Locale
X-R9-Blue-Green-Version
X-Varnish-Age
CDN-EdgeStorageId
X-Server-W
CDN-Cache
X-Alternate-Cache-Key
X-Ms-Version
CDN-PullZone
X-Storefront-Renderer-Rendered
CDN-RequestPullCode
CDN-RequestPullSuccess
X-Vercel-Id
X-Vercel-Cache
CDN-Uid
CDN-RequestCountryCode
X-Ms-Request-Id
CDN-CachedAt
X-Tb
X-Cache-Server
X-Shopify-Stage
X-Cache-Host
Azure-Version
Azure-SlotName
Azure-SiteName
Azure-RegionName
Azure-InstanceId
X-Origin-Date
X-Provided-By
X-MP-GENERATED-AT
X-Sucuri-Cache
X-TT-LOGID
X-Uri
Fastcgi-Useragent
X-XRDS-Location
X-Frame-Option
X-Sucuri-ID
Source
Cache-Tv-Group
X-ShardId
X-DynaTrace
X-ShopId
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
WP-Super-Cache
X-Cdn-Origin
Atl-Traceid
X-Vcl-Version
Content-Secure-Policy
Cross-Origin-Embedder-Policy-Report-Only
X-FB-TRIP-ID
X-Generated-By
X-Xrds-Location
Sid
Priority
X-Pass-Why
X-Sql-Count
X-Sql-Duration-Ms
X-Urbn-Context-Path
Locale
X-Urbn-Site-Id
X-Content-Age
Onion-Location
Cross-Origin-Window-Policy
X-DataDome
X-Buckets
X-CMSURLCustom
X-SRV
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
TDXMobile
X-Scope-Id
Thinkindot-Control
X-Thinkindot-L3
Cache
X-Shield-Cache-Expires
HostName
X-LSADC-Cache
X-Cluster-Node
X-Varnish-Beresp-Ttl
WZWS-RAY
X-Proxy-Cache-Status
X-WP-CF-Super-Cache-Cookies-Bypass
X-Optimistic-Header
X-Newrelic-Synthetics
X-GEO
X-Cache-Action
S-Rt
X-Cache-Expired-At
X-Azure-Ref-OriginShield
User-Cache-Control
Expiry
X-Via-SSL
X-Connection-Hash
Edge-Copy-Time
X-Via-Edge
X-Via-CDN
X-External-Request-Id
X-Access
X-Developer
X-Bl-Debug
X-Cache-Bucket
X-Cache-NE
X-BCube-Filmed-By
X-Bc-Bl
X-Application
X-B-Cookie
X-Conf
X-D
X-Ec-Fail
Fastly-Drupal-HTML
X-Ec-GeoHdr
X-Ec-Custom-Error
X-Dispatcher-Server
X-Destination
X-A-Wwc
X-Epic-Correlation-Id
Surrogated-Key
Redirect-Candidate
Rendered-Blocks
X-TIM-N
Origin-Agent-Cluster
Ngx.Var.Host
Origin
X-SRCache-Key
Req-ID
X-ScT
X-Scheme
Server-Host
X-Section
Server-Ext
X-Varnish-Hostname
DCR-Decision-By
X-Vtex-Remote-Cache
MD5-Digest
Magicmarker
Lang
L
X-Viewer-Country
Meta-Geo-Continent
DCR-Processing-Time-Ms
X-Dc
X-Vdms-Path
X-Vdms-Version
Ngx-Var-Key
X-SB
X-S-Cookie
Apple-News-Services-Host
Apple-News-Services-Handled
X-ND-Cache
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
X-A
A
X-A-Dam
X-A-Dcw
X-Instance-Name
Gannett-Cam-Experience-Id
X-A-Ccd
Vix-Hermes-Req-Id
X-Correlation-ID
Sslversion
CDCHOST
Sever-Int
Server-Hostname
X-Rojux
X-Request-Start
Candidate-Md5Url
X-PAYTM-SRV-ID
X-Op-Id-All
X-Platform
T-Server
X-Aed
X-A-Dgt
X-TimeS
X-TA-CDN-Provider
Req-Svc-Chain
X-Sigma
X-Sigma-Backend
X-TH-Server
X-Thanos
Release
X-SD-PageType
X-Rocket-Build-Number
Ssr
X-Pubstack
X-Req
X-Request-Time
X-Request-URI
Pramga
PFcat
X-VServer
X-VG-WebCache
X-WA-Info
X-Zen-Fury
Host-ID
Yak-Timeinfo
X-VG-TLSProxy
X-Varnishpool
X-Varnish-Beresp-Status
X-UA-Device-Type
NM-Fastcgi-Cache
X-Varnish-Director
X-VarnishDD-TTL
X-Pool
X-Node-Id
X-Fastly-Cache
X-Core-Value
X-Forwarded-Site
X-Acquia-Purge-Cdn-Unconfigured
X-Generated-On
X-Gen-Mode
X-Clientip
X-Cache-TTL-Remaining
X-BBC-Edge-Cache-Status
X-Amz-Storage-Class
X-Bip
X-Block-Status
X-Cache-Info
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-NCache
X-Moov-Xdn-Version
X-Nginx-Cache-Key
X-NMSegId
Wxu-Next-Commit
Wxu-Next-Hostname
X-Moov-T
X-Mly-Id
X-Hnp-Log
X-HN
X-Human
X-Level-Front-Cache
X-Loc
X-AK-Request-ID
Wxu-Next-Region
Content-Style-Type
DSUID
Cdnsip
Cdncip
Cache-Provider
C-Via
Environment
Content-Script-Type
Fastly-SSL
X-Service
X-Ua
X-Origin-Response-Time
Locid
X-Gzip
X-Request-Host
X-Aicache-OS
X-We-Are-Hiring
X-Ad-Load-Variation
X-Region-Sid
X-Device-Os
X-DPWN-IS-SECURE
Type
Tube-Return
Tube-Got-Results
Uber-Trace-Id
V-Age
X-GeoIP-City
Adler-Geo
W
X-Debug-Cache-Store
X-GeoIP
X-FC-Vary-Parameters
X-Esi-Check
X-Fmm-Version
X-V-Cache
X-Server-IP
X-CGP
X-SVT-ORM-RULES
X-Eu-Site
X-SVT-ORM-VERSION
X-Cache-Id
X-Debug-Cache-Fetch
X-Gdpr
X-Auto-Login
X-Csrf-Jwt
X-B3-Trace-ID
Tube-Got-Eval
X-Cache-Date
X-From
X-Nyt-Route
X-Amz-Meta-Cb-Modifiedtime
X-HS-Content-Campaign-Id
X-Proxied-Request
X-Policy
Platform
X-Mvc-Supplant-Cachable
X-Origin-Time
Esi-Enabled
X-Mvc-Supplant-OutputCached
Cluster
Producers
X-Men
Click-Count-Error
Click-Count-Action-Start
L5d-Success-Class
X-ECache
Fastly-GeoIP-CountryCode
HA-Ipaddr
Country-Code
Canary
Ha-Gx-Prefs
True-Client-Country-4JS
Is-Eu
X-Org
Tube-Get-Contents
X-Old-Content-Length
X-Datadome
X-Mg-Request-UUID
X-Var-Ttl
X-Ratelimit-Reset
X-Varnish-Authentication
X-Branch-Name
X-Cache-Aspx
Mail-Subject
X-Sn-Servicetimems
X-Slack-Shared-Secret-Outcome
X-Slack-Backend
Gh-Request-Id
X-Contensis-Viewer-Groups
Machine
X-Cdn-Srv
X-PERF
X-Fastly-Backend
X-Up
X-VCache
RNT-Time
X-Hash
On-Server
X-RID
Web-Mar-Region
We-Hiring
X-RateLimit-Limit-Second
XM
X-RateLimit-Remaining-Second
X-GoCache-CacheStatus
RNT-Machine
X-DC
X-Geo-Header
X-ApacheServer
X-Micro-Cache
X-Proto
X-Backend-Instance
X-Tx-Id
LB
X-Ah-Environment
Cache-Key
X-Origin-Expires
X-LB-ID
X-UA
X-Edge-Server
X-CacheTTL
X-Parent-Response-Time
X-Wikidot-Backend
Cdn-Host
AKAMAI
Cf-Device-Type
X-App-Name
X-Test
Cdn-Request-Time
Proxy-Firewall
X-Wikidot-Static-Cache
NGX
X-Lagoon
X-Irp-Debug
X-Accel-Expires-Debug
X-COUNTRY
X-Varnish-Hits
X-Cache-Backend
X-API-Version
Fastly-Backend-Name
X-Servedbyhost
X-Date
Pics-Label
X-DynaTrace-JS-Agent
X-Via-Poph
X-Via-Popn
X-Via-Popv
X-Owner
X-Refresh
X-HA-Backend
X-CACHE-GROUP
Cdn
IsBot
X-Core-Mission
X-SIPLIST1
X-LB-NoCache
X-Tb-Optimization-Total-Bytes-Saved
X-Srv
X-Nf-Request-Id
X-VHOST
X-ZONE
X-Zone
NtCoent-Length
Cache-Hits
Cdn-Requestid
Datacenter
X-NGINX-Cache
GeoIp-Country-Code
X-Wa
Server-ID
X-Nc
X-CDN-Cache-Status
X-Qloud-Router
X-Via-Fastly
Expect-Staple
N-Cache
X-CF-Lambda-Fn
X-Nananana
X-CF-Lambda-Version
SID
X-Fpc
X-Shop-Environment
X-Tenant
Xc-Version
Cross-Origin-Opener-Policy-Report-Only
GeoIP-Latitude
X-Ig-Origin-Region
X-Orig-Expires
CloudFront-Viewer-Country
X-Forwarded-Path
X-Cache-Type
X-Akamai-Transformed
X-Cloudmap
X-Gamma-Serve
Fusion-Content-Source
X-Location
Fusion-Component-Id
Fusion-Source
DataCenter
Fusion-Template-Id
Fusion-Deployment-Id
Cmstype
X-Hit
Resin-Trace
Cmsid
X-B3-Parentspanid
Fusion-Content-Id
X-TX-ID
Uri
CPC-Cache
X-Proxy-CacheRZ
XkeyRZ
CPC-Age
X-NewRelic-App-Data
Powered-By
X-Tt-Logid
X-Client-Ip
X-Vmg-Version
X-CS
Origin-CC
User-Agent
X-CUA
X-Presslabs-Stats
X-Cdn-Diag
X-Jungle-Id
Origin-EX
X-DataCenter
X-URL
X-Use-Magma
X-TIME
X-Info
X-NWS-UUID-VERIFY
X-User
True-Client-Ip
X-Amz-Meta-Opti
RATING
MIME-Version
Mime-Version
X-Fastly-Country-Code
X-Segment-20210421
X-IAuth-Set-Uid
X-B3-Spanid
X-Cached-By
Fastly-Drupal-Html
True-Client-IP
CacheControlHeader
Srv
X-Variation
X-CACHE-AGE
X-Geo
X-Dynatrace-Js-Agent
X-LAGOON
X-VTEX-Cache-Server
X-VTEX-Cache-Time
X-Powered-By-VTEX-Cache
Load-Balancing
X-Datacenter
X-Oracle-DMS-ECID
X-Render-Time
Cf-Ipcountry
Tcn
CDN
X-Cdn-Forward
X-LiteSpeed-Tag
X-Vc
Debug
X-Auth-Group-Type
Edge-Cache
X-Wormhole-Sdk
X-HOST
X-Varnish-Beresp-TTL
X-LiteSpeed-Cache-Control
X-Dispatch
X-AIR-PT
VNS-Cache
VNS-Age
X-HostName
Ohc-File-Size
X-Webkit-Csp-Report-Only
X-PDP-UNCACHING-HASH
Hostname
X-Ig-Push-State
X-CSRF-TOKEN
Cl-Cache
X-FPC
Odigeo-Trace-Id
X-NodeID
GeoIP-Country-Code
X-MCACHE
Lb
X-Cs
X-Api-Version
Ohc-Cache-HIT
X-APP-VERSION
X-Esi
X-Vgn-Hpd-Reason
X-Custom-Header
X-WA
X-NC
X-Cdn-Cache-Status
Server-Id
X-Dispatcher-Number
X-Lb-Nocache
X-PHP-Backend
X-Pad
X-Litespeed-Tag
Cache-Name
X-Depends
X-DefHash
X-DefElseHash
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-Varnish-Remaining-TTL
X-VCL-Version
X-Cache-Ttl
X-Ha-Backend
X-Fastly-Backend-Reqs
CountryCode
X-Mid
X-ServedByHost
X-M-Log
X-Via-PopH
X-Via-PopN
X-M-Reqid
PICS-Label
X-Via-PopV
X-Litespeed-Cache-Control
X-Srcache-Store-Status
Ms-Author-Via
X-Srcache-Fetch-Status
Xkey-La3
X-Sorting-Hat-Podid
Xkeylog
X-Shardid
X-Cdn-Request-ID
X-MSEdge-Flight
X-Proxy-Cache-La3
X-Akamai-Pragma-Client-IP
X-VC-TTL
X-MSEdge-Features
X-Lb-Id
X-Sorting-Hat-Shopid
X-Shopid
X-Cache-FS-Status
Epwk-X-Cache
X-Acquia-Application-UUID
Geoip-Latitude
Ngx
X-Web-Server
X-RequestId
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-Snapshot-Date
BehaviorPad-Version
OriginIP
Memory
Memcached
X-Acquia-Site
X-Acquia-Purge-Tags
Time
X-MiniProfiler-Ids
X-Acquia-Application-Trace
X-Cache-Version
X-App
X-Sucuri-Id
X-Requestid
X-APP
Cloudfront-Viewer-Country
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Th-Server
Warning
X-Lsadc-Cache
Akamai-Cache-Status
X-Cache-Enabled
X-Dw-Trace-Id
FSS-Cache
CF-Cached-On
X-Service-Response-Time
X-Mg-Cache
Sm-Log-Id
X-Check-Cacheable
X-Serial
X-Udemy-Cache-App-Namespace