Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
CF-RAY
ETag
X-XSS-Protection
Accept-Ranges
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-Served-By
X-UA-Compatible
P3P
X-Xss-Protection
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-FRAME-OPTIONS
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Content-Security-Policy-Report-Only
P3p
X-AspNet-Version
X-Runtime
X-DNS-Prefetch-Control
Accept-CH
X-Ua-Compatible
X-Cache-Status
X-Drupal-Cache
Accept-CH-Lifetime
X-Check
X-Generator
X-Cacheable
Server-Timing
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Iinfo
X-Request-ID
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
Feature-Policy
X-Content-Security-Policy
Content-Encoding
X-CDN
Status
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
CF-Ray
X-Amz-Id-2
Host-Header
Allow
X-Backend
Cf-Edge-Cache
X-Cache-Group
Request-Context
X-Robots-Tag
Keep-Alive
X-Server
X-Hacker
X-AH-Environment
X-Turbo-Charged-By
X-UA-Device
X-Ws-Request-Id
X-Proxy-Cache
X-Vhost
Xkey
X-Rq
X-Age
EagleId
X-Dispatcher
X-Server-Powered-By
X-Amz-Version-Id
X-Varnish-Cache
Grace
X-LiteSpeed-Cache
Cf-Apo-Via
X-Page-Speed
X-Pingback
Cf-Railgun
EagleEye-TraceId
X-Device
X-Swift-CacheTime
X-Swift-SaveTime
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Dns-Prefetch-Control
X-Aws-Lambda-Call-Status
Ali-Swift-Global-Savetime
X-CST
X-OneAgent-JS-Injection
X-WebKit-CSP
X-Backend-Server
Permissions-Policy
Accept-Ch-Lifetime
X-Server-Id
X-Readtime
X-Host
X-Response-Time
Request-Id
X-Akam-SW-Version
Surrogate-Control
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Nginx-Upstream-Cache-Status
X-HW
X-Cloud-Trace-Context
X-Nginx-Cache-Status
X-Node
X-Application-Context
X-Country-Code
X-Ruxit-JS-Agent
X-Trace
X-Cache-Lookup
Content-Location
X-Url
Service-Worker-Allowed
X-Oneagent-Js-Injection
X-Content-Type
X-Country
X-Clacks-Overhead
X-ECACHE
X-Litespeed-Cache
X-Edge
X-Origin-Cache-Key
X-Mod-Pagespeed
Accept-Ch
X-Amz-Server-Side-Encryption
X-FTR-Request-ID
X-Rack-Cache
X-Midtier
Cross-Origin-Opener-Policy
Cache-Tag
X-Mcache
X-MS-InvokeApp
X-Upstream
Nginx-Cache
X-ESI
X-Vname
X-PC
X-TtlSet
X-Powered-By-Plesk
Rating
Edge-Control
X-Browser-Type
X-D2id
X-Element-Page-Cache
Verso
X-Kinja-Server
X-GoogleNews-Bot
X-Cdn-Fetch
X-Exp-Id
X-Exp-Variant
X-Kinja-Revision
X-Kinja
X-Kinja-Build
X-Times
X-Server-Name
X-Cnection
X-Ac
SPRequestDuration
SPIisLatency
X-B3-TraceId
AR-ATIME
AR-PoweredBy
AR-SID
AR-Request-ID
X-Vcap-Request-Id
X-Navigation-Version
X-Ruxit-Js-Agent
X-Abt-Application-Version
SPRequestGuid
X-SharePointHealthScore
X-RateLimit-Remaining
X-NF-Request-ID
X-Dw-Request-Base-Id
X-GitHub-Request-Id
X-Ser
X-VARITI-CCR
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
AR-CACHE
S
X-Cache-Key
X-Mg-S
RTSS
X-Client-IP
X-Cache-TTL
Origin-Trial
X-Sol
X-Webkit-Csp
Display
X-Middleton-Display
Pagespeed
X-Ua-Device
Edge-Cache-Tag
X-Amz-Rid
X-Amzn-Trace-Id
Fastly-Restarts
X-Goog-Hash
X-NWS-LOG-UUID
X-Powered-CMS
X-Ttl
X-Varnish-TTL
X-Content-Security-Policy-Report-Only
X-Instrumentation
X-Server-ID
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Kinsta-Cache
Cache-Status
X-Edge-Location-Klb
X-Version
Access-Control-Request-Method
X-Recruiting
X-ARC
X-Content-Digest
Arr-Disable-Session-Affinity
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-TraceId
X-T
X-MSEdge-Ref
X-Forwarded-For
X-Middleton-Response
Response
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
Content-MD5
MicrosoftSharePointTeamServices
X-Accel-Expires
TP-Cache
X-Hits
X-Shield-Request-Id
X-Cached
X-RateLimit-Limit
X-Fastcgi-Cache
Public-Key-Pins
X-FTR-Balancer
X-FTR-Cache-Status
X-Country-Code-Real
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Expires
X-Id
Server-Node
X-Request-Processing-Time
X-Request-Received
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Combine-CSS
Payment
X-Frontend
X-HS-Cache-Config
MS-Author-Via
X-Ua-Browser
Front-End-Https
X-DIS-Request-ID
Cross-Origin-Resource-Policy
X-Forwarded-Proto
X-LLID
X-GUploader-UploadID
X-HP-Trace-Id
X-HP-Webp
X-Jurisdiction
X-WebKit-CSP-Report-Only
Cache-Tags
X-Daa-Tunnel
TP-L2-Cache
X-LB-Cache
Realpath
X-Amz-Apigw-Id
X-Kinja-CCPA
X-ORACLE-DMS-RID
X-Amzn-RequestId
X-Protected-By
X-Origin-Server
X-Distributor
Count-Hit
X-TTL
X-FastCGI-Cache
X-Request-Handler-Origin-Region
X-Microsite
X-Page-Id
X-F-Cache
X-Www-Served-By
X-Az
X-NGENIX-Cache
X-B3-TraceId-Primal
MRF-Tech
X-Activity-Id
X-PressLabs-Stats
X-AppVersion
Mrf-Cache-Status
X-Varnish-Backend
Accept-Charset
X-Cluster-Name
X-Geo-Country
X-Hostname
Referer-Policy
X-Debug-Info
X-App-Server
X-Envoy-Decorator-Operation
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Varnish-Server
Host
X-FB-Debug
Fastcgi-Cache
X-Goog-Metageneration
X-ORACLE-DMS-ECID
Access-Control-Allow-Method
X-Correlation-Id
X-Git-Hash
X-Rid
X-RateLimit-Reset
X-XRDS-LOCATION
Retry-After
Server-Name
X-Load-Cache
X-Fastly-Request-ID
X-Px
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Content-Options
DC
X-Flags
X-Providence-Cookie
X-Contextid
X-Aspnet-Duration-Ms
X-Is-Crawler
X-Request-Guid
X-Route-Name
X-Origin-Cache
X-Revision
X-B3-Sampled
X-CSRF-Token
X-B-Cache
X-Oracle-Dms-Ecid
X-Signature
X-App-Environment
X-Trace-Id
X-Type
X-Grace
X-Cache-Control
Paypal-Debug-Id
Cleartype
Charset
X-Mobile
X-ASPNET-VERSION
X-TEC-API-VERSION
X-TT
X-TEC-API-ORIGIN
X-B
X-Upgrade-Enabled
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-TEC-API-ROOT
X-Amz-Meta-S3cmd-Attrs
Section-Io-Cache
X-Fb-Rlafr
X-Seen-By
X-Language
Frame-Options
X-Amz-Replication-Status
X-Ratelimit-Limit
X-Ezoic-Cdn
TCN
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Whom
X-Logged-In
X-Goog-Generation
Filterid
X-Wix-Request-Id
Healthy
X-Magnolia-Registration
X-EdgeConnect-Cache-Status
X-Node-Name
X-Oracle-Dms-Rid
X-Newrelic-App-Data
X-Azure-Ref
X-App-Version
Content-Disposition
X-N
X-Proxy
Backend
X-Fastly-Request-Id
Akamai-GRN
X-Varnish-Ttl
X-Template
Upgrade-Insecure-Requests
NGB
Refresh
X-Air-Pt
X-Proxy-Cache-Info
X-Original-Request-Id
X-Response-Served-From
X-Is-Bot
X-Rendered-As
X-ProcessESI
X-Page-View
X-Servername
X-Yottaa-Metrics
X-Yottaa-Optimizations
VIX-Pulpo-Node
X-Unique-Id
VIX-Pulpo-Upstream-Status
SD-X-WS
X-RemovedCookies
X-B3-SpanId
Viewport
Url
X-WP-CF-Super-Cache
X-Amzn-Remapped-Content-Length
Ms-Operation-Id
X-Adobe-Content
X-Datadog-Sampled
X-Adobe-Loc
X-Debug-IsConnected
X-Debug-IsPreview
X-WP-CF-Super-Cache-Cache-Control
MS-CV
X-Tumblr-Pixel-1
X-RTag
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel
Liferay-Portal
X-Instance
X-Varnish-Grace
X-Ratelimit-Remaining
X-UUID
Fastly-SWR
X-Cache-Grace
X-FW-Serve
X-G
X-FW-Version
X-IPS-LoggedIn
X-User-Agent
X-Region
X-FW-Type
X-FW-Static
X-Debug
X-FW-Dynamic
X-FW-Hash
X-FW-Server
X-Cacheable-TTL
Fastly-SIE
X-L-Path
X-Environment-Context
X-Device-Type
From-Origin
X-NYM-Debug-Backend
X-Jobs
X-Cache-Hit
Country
X-Rule
X-Status
X-Hl-Ver
X-Backend-Name
Surrogate-Key
X-Hosted-By
X-Webkit-CSP
ServerID
X-Air-Hostname
X-Air-Trace-Id
X-Air-Source
X-Cache-Age
X-Tec-Api-Root
X-Tec-Api-Version
X-Tec-Api-Origin
X-Time
X-Http-Reason
X-Content-Powered-By
Alternate-Protocol
X-VC-Cache
Protected
X-Akamai-Request-ID2
X-Origin-CC
X-Cache-Status-Check
X-Origin-TTL
X-XRDS-Location
X-NODE
Amp-Access-Control-Allow-Source-Origin
Countrycode
WPO-Cache-Status
X-Hcs-Proxy-Type
WPO-Cache-Message
X-Use-Magma
X-CCDN-Origin-Time
X-CCDN-CacheTTL
Version
X-B3-Traceid
X-HTML-Minification-Powered-By
X-Via-JSL
X-INCAP-ABP
X-Akamai-Edgescape
X-Rocket-Nginx-Serving-Static
X-Nginx-Cache
X-CDN-Forward
SRV
X-Framework
CF-IPCountry
GEO-INFO
X-Edge-Location
Front
X-WP-CF-Super-Cache-Active
X-Cache-Rule
X-Storage
X-Source
X-Accel-Version
Access-Control-Request-Headers
X-Httpd
X-Mode
X-Use-Mantle
CDN-RequestId
X-Endurance-Cache-Level
X-UPSTREAM-Address
X-Xfnlog-Site
X-Upstream-Ct
X-VC
X-Cache-Operation
X-Rn-Rsrv
Filters
Webserver
OT-Force-Account-Verify
Meta-Geo
X-Upstream-Ht
X-Real-IP
X-Rewrite-Enabled
Xet-Cookie
Accept-Language
X-JoinUs
X-Director
X-Proxy-Build
X-Soup
X-Cache-Debug
Selected-Fe
X-Served-From
X-SaId
X-Detected-As
X-Timing-Wait
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
X-Sql-Count
X-ProxyCache-Status
X-Redis-Cache
X-Say-Cacheable
X-Worker
ServedBy
X-BYPASS-REASON
X-Lambda-Id
X-Handled-By
X-Cms-Context
X-Loop
X-Say-TTL
X-Adobe-Source
X-ProxyCache-Key
X-SayCDN-TTL
X-Sql-Duration-Ms
X-Tncms
X-Cache-Time
X-Varnish-Cache-Hits
X-Varnish-Age
X-PHP-Host
Property-Id
DB-Nickname
X-No-Session
Azure-SlotName
Azure-InstanceId
Apigw-Requestid
Azure-RegionName
Azure-SiteName
TWC-Connection-Speed
Azure-Version
TWC-GeoIP-LatLong
X-Skip-Cache
Webcakes-Region
X-Labrador-Cache-Channel
X-Format
X-GeoCountry
X-GeoCode
Webcakes-App-Version
Webcakes-App-Name
X-Server-W
TWC-GeoIP-Country
TWC-Locale-Group
TWC-Privacy
Web-Mar-Node
TWC-Device-Class
X-Origin-Hint
X-Restarts
Xserver
X-S
X-RM-Cache-TTL
AMP-Access-Control-Allow-Source-Origin
X-Varnish-Beresp-Grace
X-Logging-Id
X-Cache-Server
X-VCT
X-Cache-Host
Mn-Server-Ip
X-IPLB-Request-ID
X-Container-Uri
X-LJ-Flow-ID
X-Fetched-On
X-VWS-Id
X-Git-Commit
X-IPLB-Instance
X-RCS-CacheZone
X-Generation-Time
X-DynaTrace
X-AWS-Id
X-AB
X-ServerID
X-Ms-Request-Id
X-Routing-Service
X-Frame-Option
X-COUNTRY
X-Forwarded-Host
X-Extlb
X-Zipkin-Id
X-Cluster
X-Browser-Name
X-Proxied
X-Origin
X-Vercel-Id
X-Ms-Version
X-Tcp-Rtt
X-Tb
X-Vercel-Cache
X-Provided-By
X-Is-Desktop
X-Geo-Region
X-Is-Mobile
X-Is-Supported-Browser
X-Reqid
X-Is-Tablet
Node
X-Uri
X-R9-Blue-Green-Version
Cache-Tv-Group
Section-Io-Id
X-Locale
X-Site-Version
Priority
X-Platform-Processor
X-FB-TRIP-ID
X-Platform-Cluster
X-Platform-Router
X-Web-Node
Source
Content-Secure-Policy
X-Vcache
X-Webstats-RespID
Cross-Origin-Embedder-Policy
X-Drupal-Cache-Contexts
X-Drupal-Cache-Tags
X-MP-GENERATED-AT
Fastcgi-Useragent
WP-Super-Cache
WZWS-RAY
X-Vcl-Version
CDN-RequestPullCode
CDN-RequestPullSuccess
X-Origin-Date
CDN-Uid
CDN-EdgeStorageId
CDN-RequestCountryCode
CDN-CachedAt
CDN-PullZone
Onion-Location
CDN-Cache
X-Shopify-Stage
X-Storefront-Renderer-Rendered
X-Alternate-Cache-Key
X-Content-Age
Locale
X-Urbn-Site-Id
X-Urbn-Context-Path
S-Rt
X-Generated-By
X-ShardId
X-ShopId
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Ua
X-Newrelic-Synthetics
X-Sucuri-Cache
X-Cdn-Origin
X-Cluster-Node
X-SRV
X-Pass-Why
X-Varnish-Beresp-Ttl
X-Sucuri-ID
Sid
X-Buckets
X-Proxy-Cache-Status
X-Cache-Action
X-TT-LOGID
X-Correlation-ID
X-Mg-Request-UUID
X-Cache-Expired-At
Cross-Origin-Window-Policy
X-VCache
X-Xrds-Location
Cross-Origin-Embedder-Policy-Report-Only
Thinkindot-CacheControl-Type
TDXMobile
X-Thinkindot-L3
X-Scope-Id
X-CMSURLCustom
Thinkindot-Control
Thinkindot-CacheControl
X-Shield-Cache-Expires
X-Datadome
X-LSADC-Cache
Fastly-Drupal-HTML
Cache
X-Request-URI
HostName
X-DataDome
X-Optimistic-Header
X-Aspnetmvc-Version
X-Destination
Candidate-Md5Url
CDCHOST
X-PAYTM-SRV-ID
X-Vtex-Remote-Cache
X-Epic-Correlation-Id
X-Ec-GeoHdr
X-Ec-Custom-Error
X-Developer
X-Ec-Fail
X-External-Request-Id
X-BCube-Filmed-By
Origin-Agent-Cluster
X-TIM-N
X-A-Dcw
X-A-Dam
Origin
X-A-Dgt
Ngx.Var.Host
X-Viewer-Country
X-SRCache-Key
X-A-Ccd
X-A
X-Vdms-Version
T-Server
Type
X-Vdms-Path
Surrogated-Key
Redirect-Candidate
Rendered-Blocks
Sslversion
Ngx-Var-Key
X-A-Wwc
Environment
X-Bl-Debug
Gannett-Cam-Experience-Id
X-Bc-Bl
DCR-Processing-Time-Ms
DCR-Decision-By
X-Conf
X-Cache-NE
X-Cache-Bucket
X-B-Cookie
X-Application
X-ScT
MD5-Digest
Meta-Geo-Continent
X-Scheme
X-Aed
X-Rojux
Lang
X-S-Cookie
X-D
X-GEO
Atl-Traceid
X-WP-CF-Super-Cache-Cookies-Bypass
Edge-Copy-Time
X-TimeS
X-Via-SSL
X-Via-CDN
X-Via-Edge
X-Thanos
X-Platform
X-TH-Server
X-Cache-Info
X-Pool
X-Core-Value
X-Proxied-Request
X-Sigma-Backend
X-Origin-Time
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Handled
X-Op-Id-All
X-Debug-Cache-Store
X-Pubstack
Pramga
X-Debug-Cache-Fetch
X-Up
X-Bip
L
X-Rocket-Build-Number
X-Access
X-Acquia-Purge-Cdn-Unconfigured
X-Aicache-OS
X-SD-PageType
X-SB
Magicmarker
Host-ID
X-Request-Time
X-Req
X-Section
X-Server-IP
Fastly-GeoIP-CountryCode
Fastly-SSL
X-B3-Trace-ID
X-BBC-Edge-Cache-Status
X-Request-Start
X-Sigma
X-Dispatcher-Server
X-Gdpr
Vix-Hermes-Req-Id
X-Generated-On
Sever-Int
X-Forwarded-Site
Server-Hostname
X-Varnish-Beresp-Status
X-Fastly-Cache
Server-Host
X-We-Are-Hiring
X-Varnish-Hostname
V-Age
X-Instance-Name
X-Human
X-VG-WebCache
X-VG-TLSProxy
X-Varnishpool
Ssr
X-GeoIP-Country-Code
X-GeoIP-Region-Code
Server-Ext
X-Level-Front-Cache
Req-ID
Release
X-Varnish-Director
X-VServer
X-Men
X-Nyt-Route
X-Loc
Req-Svc-Chain
X-Node-Id
X-Mly-Id
X-TA-CDN-Provider
X-Service
User-Cache-Control
X-Var-Ttl
Uber-Trace-Id
Tube-Return
X-Ad-Load-Variation
Wxu-Next-Region
We-Hiring
Web-Mar-Region
X-SVT-ORM-VERSION
Wxu-Next-Commit
X-UA-Device-Type
X-SVT-ORM-RULES
Wxu-Next-Hostname
X-V-Cache
X-Zen-Fury
X-FC-Vary-Parameters
X-Fmm-Version
X-From
X-Fastly-Backend
X-Esi-Check
X-Mvc-Supplant-OutputCached
X-Mvc-Supplant-Cachable
X-Micro-Cache
X-Gen-Mode
X-Geo-Header
Tube-Got-Results
X-HS-Content-Campaign-Id
X-Hnp-Log
X-Hash
X-Gzip
X-GeoIP
X-GeoIP-City
X-Irp-Debug
X-NCache
X-Nginx-Cache-Key
X-Cache-Date
X-Cache-Id
X-Policy
X-Block-Status
X-RateLimit-Limit-Second
DSUID
X-Auto-Login
X-RateLimit-Remaining-Second
X-Cache-TTL-Remaining
X-Core-Mission
X-DPWN-IS-SECURE
X-Old-Content-Length
X-NMSegId
X-Device-Os
X-Org
X-PERF
X-Origin-Response-Time
X-ApacheServer
On-Server
Click-Count-Action-Start
Click-Count-Error
NM-Fastcgi-Cache
Tube-Got-Eval
Producers
Country-Code
Mail-Subject
Is-Eu
Gh-Request-Id
Esi-Enabled
Machine
X-WA-Info
Platform
True-Client-Country-4JS
Cache-Provider
Canary
Tube-Get-Contents
X-Clientip
C-Via
Adler-Geo
X-DC
X-Via-Popv
AKAMAI
X-Slack-Shared-Secret-Outcome
X-Test
X-CacheTTL
X-Edge-Server
X-SIPLIST1
Cdn-Host
X-Cdn-Srv
X-Sn-Servicetimems
Cf-Device-Type
Cdn-Request-Time
X-GoCache-CacheStatus
X-Request-Host
X-Slack-Backend
X-ZONE
W
X-Via-Popn
X-Via-Poph
Proxy-Firewall
Pics-Label
X-HA-Backend
X-App-Name
IsBot
X-Proto
Cluster
X-Parent-Response-Time
X-Dc
X-Tt-Logid
Expiry
X-Connection-Hash
X-Contensis-Viewer-Groups
A
Content-Script-Type
Content-Style-Type
LB
X-Wikidot-Static-Cache
X-Branch-Name
X-Owner
X-Moov-Xdn-Version
X-Moov-T
X-Wikidot-Backend
X-Eu-Site
X-Varnish-Authentication
X-Csrf-Jwt
L5d-Success-Class
X-Amz-Meta-Cb-Modifiedtime
N-Cache
HA-Ipaddr
Expect-Staple
Ha-Gx-Prefs
Fastly-Backend-Name
X-Date
NGX
X-Accel-Expires-Debug
X-CGP
X-Cache-Aspx
X-Ah-Environment
X-CF-Lambda-Fn
X-CF-Lambda-Version
Datacenter
X-Shop-Environment
X-Orig-Expires
RNT-Machine
X-LB-NoCache
Cache-Key
X-Qloud-Router
RNT-Time
X-Cache-Type
X-Tenant
Xc-Version
X-Forwarded-Path
X-AK-Request-ID
Yak-Timeinfo
Cdncip
Cdnsip
X-Gamma-Serve
Cdn-Requestid
Locid
X-Region-Sid
X-LB-ID
X-ND-Cache
X-NGINX-Cache
X-Ratelimit-Reset
Cdn
X-Amz-Storage-Class
Server-ID
X-VarnishDD-TTL
X-HN
X-Tx-Id
PFcat
X-Varnish-Hits
Cmsid
Cmstype
X-Refresh
X-VHOST
SID
X-Vmg-Version
X-Servedbyhost
RATING
NtCoent-Length
X-CDN-Cache-Status
X-Wa
X-Cdn-Diag
X-DynaTrace-JS-Agent
CPC-Age
X-Backend-Instance
X-Tb-Optimization-Total-Bytes-Saved
GeoIp-Country-Code
X-Nc
CPC-Cache
X-Azure-Ref-OriginShield
X-Srv
XM
X-LAGOON
X-Api-Version
X-TX-ID
X-Fpc
X-Nananana
CloudFront-Viewer-Country
X-API-Version
X-Cache-Backend
X-Origin-Expires
X-Akamai-Transformed
X-TIME
X-Via-Fastly
X-B3-Parentspanid
CacheControlHeader
X-Variation
Resin-Trace
X-Lagoon
X-Hit
Tcn
X-Nf-Request-Id
Uri
XkeyRZ
X-CACHE-AGE
X-Proxy-CacheRZ
User-Agent
X-Client-Ip
X-LiteSpeed-Tag
X-Fastly-Country-Code
X-URL
X-Zone
X-NewRelic-App-Data
X-Datacenter
X-LiteSpeed-Cache-Control
MIME-Version
VNS-Age
VNS-Cache
X-Amz-Meta-Opti
Cross-Origin-Opener-Policy-Report-Only
True-Client-Ip
X-Info
X-Geo
Cache-Name
X-UA
X-MCACHE
Lb
X-Dynatrace-Js-Agent
X-Vc
X-HostName
DataCenter
X-DataCenter
True-Client-IP
X-Ig-Origin-Region
GeoIP-Latitude
X-Location
X-Presslabs-Stats
X-CSRF-TOKEN
Mime-Version
Hostname
Cache-Hits
X-AIR-PT
Fusion-Deployment-Id
Fusion-Source
Fusion-Content-Source
Fusion-Component-Id
X-NWS-UUID-VERIFY
Fusion-Content-Id
Fusion-Template-Id
X-Dispatcher-Number
Fastly-Drupal-Html
X-B3-Spanid
Powered-By
X-Cached-By
Origin-EX
Origin-CC
Cf-Ipcountry
X-CUA
X-Cloudmap
X-Jungle-Id
X-Mid
X-Cdn-Forward
X-Webkit-Csp-Report-Only
X-IAuth-Set-Uid
X-User
X-Segment-20210421
X-RID
Srv
X-CS
Ohc-File-Size
Debug
BehaviorPad-Version
X-ECache
X-Varnish-Beresp-TTL
X-FPC
Cl-Cache
X-Esi
X-Render-Time
GeoIP-Country-Code
X-Dispatch
X-Litespeed-Tag
Ohc-Cache-HIT
CDN
X-Oracle-DMS-ECID
X-WA
X-NC
X-ServedByHost
X-Cs
X-Powered-By-VTEX-Cache
Load-Balancing
X-VTEX-Cache-Time
X-Cdn-Cache-Status
X-Wormhole-Sdk
X-Cache-Enabled
X-VTEX-Cache-Server
CountryCode
Edge-Cache
X-Auth-Group-Type
Server-Info
Server-Id
YJS-ID
My-App
X-Lb-Id
Location
X-Fastly-Backend-Reqs
X-Traceid
X-Snapshot-Date
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
CF-Ctrl
X-Internal-Host
X-Lb-Nocache
X-VCL-Version
X-ID
Ms-Author-Via
X-Litespeed-Cache-Control
Wpo-Cache-Message
Wpo-Cache-Status
Xkey-La3
Xkeylog
X-Nitro-Rev
X-Ig-Push-State
X-Nitro-Cache
X-App
X-Proxy-Cache-La3
CF-Cached-On
Section-Origin-Responded
X-Nitro-Cache-From
Section-Io-Origin-Status
X-MiniProfiler-Ids
X-MSEdge-Flight
X-MSEdge-Features
X-Cdn-Request-ID
X-Akamai-Pragma-Client-IP
X-NodeID
Section-Io-Origin-Time-Seconds
X-Dw-Trace-Id
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Acquia-Site
X-Acquia-Purge-Tags
OriginIP
Memcached
Time
X-Acquia-Application-Trace
X-Acquia-Application-UUID
Memory
Srvid
Odigeo-Trace-Id
X-Cache-FS-Status
X-FL-EDGE
X-FL-QIT-DEBUG
X-APP-VERSION
FSS-Cache
Geoip-Latitude
Ngx
X-Sorting-Hat-Shopid
X-Shardid
X-Cache-Version
X-Shopid
X-Sorting-Hat-Podid
X-Pad
Akamai-Cache-Status
X-Http-Duration-Ms
X-Http-Count
X-Vgn-Hpd-Reason
X-Mg-Cache
X-Ha-Backend
X-Udemy-Cache-App-Namespace
X-Fastly-Cache-Hits
X-Via-PopV
X-RequestId
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Sucuri-Id
X-Th-Server
X-Via-PopN
X-Via-PopH
X-Service-Response-Time
X-Web-Server
X-Te-Duration-Ms
X-Serial
X-Check-Cacheable
X-Lsadc-Cache
Sm-Log-Id
X-Te-Count