Threat Level: green Handler on Duty: Richard Porter

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
CF-RAY
ETag
X-XSS-Protection
Accept-Ranges
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-Served-By
X-UA-Compatible
P3P
X-Download-Options
X-Xss-Protection
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
X-FRAME-OPTIONS
Access-Control-Allow-Credentials
Content-Security-Policy-Report-Only
X-Runtime
X-AspNet-Version
P3p
X-DNS-Prefetch-Control
Accept-CH
X-Cache-Status
X-Drupal-Cache
X-Ua-Compatible
Accept-CH-Lifetime
X-Check
X-Generator
X-Cacheable
Server-Timing
X-Envoy-Upstream-Service-Time
X-Request-ID
Timing-Allow-Origin
X-Iinfo
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
X-Content-Security-Policy
Feature-Policy
Content-Encoding
X-CDN
Status
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
X-Amz-Id-2
Host-Header
CF-Ray
Allow
X-Backend
Cf-Edge-Cache
Request-Context
X-Robots-Tag
Keep-Alive
X-Cache-Group
X-Server
X-UA-Device
X-Hacker
X-AH-Environment
X-Turbo-Charged-By
X-Ws-Request-Id
X-Proxy-Cache
X-Age
X-Rq
Xkey
X-Vhost
EagleId
X-Dispatcher
X-Server-Powered-By
X-Amz-Version-Id
X-Varnish-Cache
Grace
Cf-Apo-Via
X-Dns-Prefetch-Control
X-LiteSpeed-Cache
X-Page-Speed
X-Pingback
Cf-Railgun
X-Swift-SaveTime
X-Swift-CacheTime
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
EagleEye-TraceId
Ali-Swift-Global-Savetime
X-Aws-Lambda-Call-Status
X-WebKit-CSP
X-CST
X-Backend-Server
Permissions-Policy
X-OneAgent-JS-Injection
X-Server-Id
X-Readtime
X-Response-Time
X-Host
X-Akam-SW-Version
Request-Id
Surrogate-Control
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-HW
X-Nginx-Upstream-Cache-Status
X-Cloud-Trace-Context
X-Node
X-Nginx-Cache-Status
Accept-Ch-Lifetime
X-Litespeed-Cache
X-Application-Context
X-Oneagent-Js-Injection
X-Cache-Lookup
X-Country-Code
X-Trace
Content-Location
X-Url
Service-Worker-Allowed
X-Ruxit-JS-Agent
X-Content-Type
X-Clacks-Overhead
X-Country
X-Edge
X-ECACHE
X-Origin-Cache-Key
X-Mcache
X-Rack-Cache
X-Amz-Server-Side-Encryption
X-Mod-Pagespeed
Cross-Origin-Opener-Policy
X-Midtier
Cache-Tag
X-FTR-Request-ID
Accept-Ch
Nginx-Cache
X-MS-InvokeApp
X-Upstream
X-PC
X-TtlSet
X-Vname
X-ESI
X-Powered-By-Plesk
Rating
Edge-Control
X-Ruxit-Js-Agent
X-Browser-Type
X-Server-Name
X-D2id
X-Element-Page-Cache
Verso
X-Exp-Id
X-Kinja
X-Kinja-Revision
X-Kinja-Build
X-Kinja-Server
X-Cdn-Fetch
X-Exp-Variant
X-Times
X-GoogleNews-Bot
X-Cnection
X-Ac
SPRequestDuration
SPIisLatency
X-B3-TraceId
AR-ATIME
AR-SID
AR-Request-ID
AR-PoweredBy
X-Abt-Application-Version
X-Navigation-Version
X-Vcap-Request-Id
SPRequestGuid
X-SharePointHealthScore
X-NF-Request-ID
X-Dw-Request-Base-Id
X-GitHub-Request-Id
X-Ser
X-RateLimit-Remaining
AR-CACHE
X-VARITI-CCR
Pinterest-Generated-By
X-Pinterest-Rid
Pinterest-Version
X-Mg-S
X-NWS-LOG-UUID
S
X-Cache-Key
X-Sol
Display
X-Middleton-Display
Pagespeed
RTSS
Edge-Cache-Tag
Fastly-Restarts
X-Amz-Rid
X-Amzn-Trace-Id
X-Client-IP
X-Ttl
X-Cache-TTL
X-Powered-CMS
X-Goog-Hash
X-Kraken-Loop-Name
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-Erf-Bev-Bev
X-Server-Lifecycle-Phase
Origin-Trial
Cache-Status
X-Edge-Location-Klb
X-Kinsta-Cache
X-Varnish-TTL
X-Version
Access-Control-Request-Method
X-Content-Security-Policy-Report-Only
X-Server-ID
X-Recruiting
X-ARC
X-TraceId
X-Content-Digest
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
Arr-Disable-Session-Affinity
X-Middleton-Response
Response
X-Webkit-Csp
X-T
X-Forwarded-For
X-MSEdge-Ref
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Content-MD5
X-Ua-Device
X-Accel-Expires
MicrosoftSharePointTeamServices
TP-Cache
X-Shield-Request-Id
X-Hits
X-Cached
X-Id
Public-Key-Pins
X-RateLimit-Limit
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Balancer
X-FTR-Cache-Status
X-Country-Code-Real
X-FTR-Expires
MS-Author-Via
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
Server-Node
X-Ua-Browser
Cross-Origin-Resource-Policy
X-HS-Combine-CSS
Payment
X-Request-Received
Front-End-Https
X-Request-Processing-Time
X-Daa-Tunnel
X-Frontend
X-DIS-Request-ID
X-FastCGI-Cache
X-Forwarded-Proto
X-LLID
X-HP-Trace-Id
X-Jurisdiction
X-HP-Webp
X-GUploader-UploadID
TP-L2-Cache
X-LB-Cache
Realpath
X-Protected-By
X-Fastcgi-Cache
Cache-Tags
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Origin-Server
X-Distributor
X-Microsite
X-WebKit-CSP-Report-Only
X-Request-Handler-Origin-Region
Count-Hit
X-AppVersion
X-Az
X-Activity-Id
X-Page-Id
MRF-Tech
Mrf-Cache-Status
X-Hostname
X-F-Cache
X-TTL
X-B3-TraceId-Primal
X-Cluster-Name
X-Varnish-Backend
X-Geo-Country
X-Www-Served-By
Referer-Policy
X-Debug-Info
X-Correlation-Id
Accept-Charset
X-NGENIX-Cache
X-ORACLE-DMS-RID
Fastcgi-Cache
X-Kong-Upstream-Latency
X-PressLabs-Stats
X-Kinja-CCPA
X-Kong-Proxy-Latency
X-App-Server
X-Envoy-Decorator-Operation
Host
X-Varnish-Server
X-Goog-Metageneration
X-FB-Debug
Access-Control-Allow-Method
X-Git-Hash
X-RateLimit-Reset
X-Oracle-Dms-Ecid
Retry-After
X-Rid
Server-Name
X-Content-Options
X-ORACLE-DMS-ECID
X-Load-Cache
X-Upgrade-Enabled
X-Tt-Trace-Tag
X-Px
X-Tt-Trace-Host
X-XRDS-LOCATION
X-Ratelimit-Limit
X-Oracle-Dms-Rid
X-Is-Crawler
X-Request-Guid
X-Revision
X-Route-Name
X-Providence-Cookie
TCN
X-Aspnet-Duration-Ms
DC
X-Contextid
X-Flags
Charset
X-App-Environment
X-TEC-API-VERSION
X-Trace-Id
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Ezoic-Cdn
X-CSRF-Token
X-Cache-Control
X-Type
X-Datadog-Parent-Id
Paypal-Debug-Id
X-Seen-By
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Grace
X-Origin-Cache
X-B3-Sampled
Cleartype
X-Signature
X-Amz-Meta-S3cmd-Attrs
X-B-Cache
Section-Io-Cache
X-Fastly-Request-Id
X-Mobile
X-B
X-TT
X-Fb-Rlafr
Healthy
X-Whom
X-Wix-Request-Id
X-Amz-Replication-Status
X-ASPNET-VERSION
Frame-Options
X-Magnolia-Registration
X-Fastly-Request-ID
X-Node-Name
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Logged-In
X-Language
Filterid
X-EdgeConnect-Cache-Status
X-Varnish-Ttl
X-Azure-Ref
X-Proxy
X-Newrelic-App-Data
X-N
X-Ratelimit-Remaining
X-Air-Pt
Content-Disposition
X-App-Version
Backend
Akamai-GRN
Upgrade-Insecure-Requests
X-Template
X-Original-Request-Id
Refresh
NGB
X-Proxy-Cache-Info
X-Response-Served-From
X-Tumblr-Pixel
X-Rendered-As
X-Tumblr-Pixel-0
X-Tumblr-User
X-ProcessESI
X-Unique-Id
X-RemovedCookies
X-Tumblr-Pixel-1
X-Is-Bot
X-Yottaa-Metrics
SD-X-WS
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-Yottaa-Optimizations
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
Viewport
Ms-Operation-Id
X-Datadog-Sampled
X-RTag
X-Instance
X-Amzn-Remapped-Content-Length
MS-CV
X-Page-View
X-Servername
X-Varnish-Grace
X-FW-Static
X-FW-Dynamic
X-Debug-IsPreview
Liferay-Portal
X-Debug
X-IPS-LoggedIn
X-FW-Hash
X-FW-Server
X-FW-Version
X-FW-Serve
X-UUID
X-Debug-IsConnected
X-FW-Type
X-Cache-Grace
Fastly-SWR
X-Adobe-Content
X-Cacheable-TTL
Fastly-SIE
X-Region
X-Adobe-Loc
From-Origin
Url
X-Device-Type
X-G
X-NYM-Debug-Backend
X-User-Agent
X-Rule
X-Jobs
X-L-Path
Country
X-Cache-Hit
X-Environment-Context
X-Hl-Ver
X-Status
X-B3-SpanId
Amp-Access-Control-Allow-Source-Origin
X-Backend-Name
ServerID
X-Time
Surrogate-Key
X-Hosted-By
X-Origin-CC
X-Origin-TTL
X-CCDN-Origin-Time
X-Air-Hostname
X-Air-Source
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-Air-Trace-Id
X-Webkit-CSP
X-VC-Cache
Alternate-Protocol
Countrycode
X-Via-JSL
X-Cache-Age
X-Content-Powered-By
X-Akamai-Request-ID2
X-INCAP-ABP
Version
X-Tec-Api-Origin
X-HTML-Minification-Powered-By
X-Tec-Api-Root
X-Tec-Api-Version
X-Cache-Status-Check
WPO-Cache-Status
WPO-Cache-Message
Protected
SRV
X-XRDS-Location
X-NODE
X-Http-Reason
GEO-INFO
X-Nginx-Cache
X-Rocket-Nginx-Serving-Static
X-Akamai-Edgescape
CDN-RequestId
CF-IPCountry
X-B3-Traceid
X-CDN-Forward
X-Framework
X-Storage
X-Source
X-WP-CF-Super-Cache-Active
X-Accel-Version
X-Edge-Location
X-Cache-Rule
Access-Control-Request-Headers
Front
X-Real-IP
X-Mode
OT-Force-Account-Verify
X-Httpd
X-Xfnlog-Site
X-UPSTREAM-Address
Webserver
X-Rn-Rsrv
X-Rewrite-Enabled
X-Upstream-Ht
X-Upstream-Ct
Filters
X-Cache-Operation
Meta-Geo
Accept-Language
X-Endurance-Cache-Level
X-Tumblr-Pixel-2
X-Tumblr-Pixel-3
X-Proxy-Build
X-Director
Selected-Fe
X-Served-From
X-SaId
X-Timing-Wait
X-JoinUs
X-Soup
X-Cache-Debug
X-SayCDN-TTL
X-Origin
ServedBy
X-Use-Mantle
X-Use-Magma
X-Logging-Id
X-Redis-Cache
X-Varnish-Cache-Hits
X-Handled-By
X-Worker
X-Detected-As
X-Say-Cacheable
X-Say-TTL
Webcakes-App-Name
TWC-Locale-Group
TWC-Privacy
X-RM-Cache-TTL
Web-Mar-Node
Webcakes-Region
X-Adobe-Source
TWC-GeoIP-LatLong
Webcakes-App-Version
X-Format
X-Lambda-Id
X-Labrador-Cache-Channel
TWC-Connection-Speed
TWC-Device-Class
X-PHP-Host
Property-Id
X-Restarts
DB-Nickname
X-Origin-Hint
X-Loop
X-GeoCountry
X-GeoCode
Azure-SlotName
Azure-SiteName
Azure-RegionName
Azure-InstanceId
X-ProxyCache-Status
TWC-GeoIP-Country
X-Cms-Context
X-ProxyCache-Key
X-Cache-Time
Azure-Version
X-BYPASS-REASON
X-Varnish-Age
X-VC
X-VCT
Xserver
X-Tncms
X-Vcache
X-Sql-Count
X-Sql-Duration-Ms
X-Server-W
X-No-Session
X-RCS-CacheZone
X-VWS-Id
X-Git-Commit
X-Vercel-Id
Mn-Server-Ip
X-AWS-Id
X-Fetched-On
X-Container-Uri
X-Cache-Server
X-Generation-Time
X-DynaTrace
X-Vercel-Cache
X-ServerID
Apigw-Requestid
X-Skip-Cache
Xet-Cookie
X-LJ-Flow-ID
X-IPLB-Instance
X-Tb
X-Varnish-Beresp-Grace
X-IPLB-Request-ID
Node
Section-Io-Id
X-Reqid
X-Cache-Host
X-Provided-By
X-Cluster
X-Web-Node
X-Frame-Option
X-Proxied
X-Is-Supported-Browser
X-Geo-Region
X-Is-Tablet
X-Is-Desktop
X-Extlb
X-Forwarded-Host
X-Is-Mobile
X-Browser-Name
X-AB
X-Zipkin-Id
X-Routing-Service
X-Locale
X-Site-Version
X-Ms-Request-Id
X-Ms-Version
X-Tcp-Rtt
X-S
X-Platform-Router
X-Platform-Processor
X-Platform-Cluster
X-R9-Blue-Green-Version
Cross-Origin-Embedder-Policy
X-Uri
X-Webstats-RespID
Cache-Tv-Group
X-Drupal-Cache-Tags
Priority
X-Drupal-Cache-Contexts
Source
Fastcgi-Useragent
X-MP-GENERATED-AT
X-FB-TRIP-ID
X-Origin-Date
WP-Super-Cache
Content-Secure-Policy
X-COUNTRY
CDN-Uid
AMP-Access-Control-Allow-Source-Origin
CDN-Cache
CDN-RequestCountryCode
CDN-EdgeStorageId
CDN-RequestPullCode
CDN-CachedAt
CDN-RequestPullSuccess
CDN-PullZone
X-Vcl-Version
X-TT-LOGID
X-Generated-By
Onion-Location
X-Storefront-Renderer-Rendered
X-Shopify-Stage
X-Alternate-Cache-Key
X-Urbn-Site-Id
X-Sucuri-Cache
X-Urbn-Context-Path
Locale
X-Content-Age
X-ShardId
X-Sorting-Hat-ShopId
S-Rt
X-Sorting-Hat-PodId
X-ShopId
X-Xrds-Location
X-Pass-Why
X-SRV
WZWS-RAY
X-Cdn-Origin
X-Sucuri-ID
X-Newrelic-Synthetics
X-Cluster-Node
X-Buckets
X-Varnish-Beresp-Ttl
X-Ua
Cross-Origin-Embedder-Policy-Report-Only
Sid
X-DataDome
X-Cache-Action
X-Proxy-Cache-Status
X-Thinkindot-L3
X-CMSURLCustom
TDXMobile
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-Scope-Id
X-Shield-Cache-Expires
Thinkindot-Control
X-Cache-Expired-At
Cross-Origin-Window-Policy
Cache
X-LSADC-Cache
Atl-Traceid
X-GEO
Fastly-Drupal-HTML
X-Via-Edge
Edge-Copy-Time
X-Via-CDN
X-Request-URI
X-Via-SSL
X-Cache-NE
X-Conf
X-A-Ccd
X-Cache-Bucket
X-Mg-Request-UUID
X-Bl-Debug
X-A
T-Server
X-Destination
X-Developer
Type
DCR-Decision-By
X-D
Candidate-Md5Url
Sslversion
X-B-Cookie
X-Bc-Bl
X-Application
X-Aed
Surrogated-Key
X-A-Dgt
X-Ec-Fail
X-A-Dcw
X-A-Dam
X-BCube-Filmed-By
CDCHOST
X-Vtex-Remote-Cache
X-A-Wwc
X-Ec-Custom-Error
Meta-Geo-Continent
X-PAYTM-SRV-ID
X-Optimistic-Header
X-Scheme
X-Vdms-Path
X-ScT
X-S-Cookie
Origin-Agent-Cluster
X-TIM-N
Ngx.Var.Host
Gannett-Cam-Experience-Id
X-Rojux
Origin
X-Vdms-Version
X-WP-CF-Super-Cache-Cookies-Bypass
X-External-Request-Id
Lang
X-SRCache-Key
X-Epic-Correlation-Id
X-Ec-GeoHdr
Ngx-Var-Key
Rendered-Blocks
DCR-Processing-Time-Ms
X-Viewer-Country
Redirect-Candidate
MD5-Digest
X-Aspnetmvc-Version
Host-ID
Magicmarker
Fastly-GeoIP-CountryCode
Req-ID
Release
Server-Ext
Server-Hostname
Server-Host
Sever-Int
DSUID
Fastly-SSL
Pramga
L
Environment
Ssr
X-Debug-Cache-Fetch
X-Rocket-Build-Number
X-SB
X-SD-PageType
X-Section
X-Request-Time
X-Request-Start
X-Platform
X-Pool
X-Proxied-Request
X-Sigma
X-Sigma-Backend
X-Varnishpool
X-VG-WebCache
X-VServer
X-We-Are-Hiring
X-Varnish-Hostname
X-Varnish-Director
X-TH-Server
X-Thanos
X-Varnish-Beresp-Status
X-Origin-Time
X-Op-Id-All
X-Debug-Cache-Store
X-Dispatcher-Server
X-Fastly-Cache
X-Forwarded-Site
X-Cache-Info
X-Bip
Vix-Hermes-Req-Id
X-Access
X-Aicache-OS
X-Gdpr
X-Generated-On
X-Loc
X-Node-Id
X-Nyt-Route
X-Level-Front-Cache
X-Instance-Name
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-Human
V-Age
X-Clientip
X-VCache
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Handled
X-Correlation-ID
Apple-News-Services-Request-Url
X-Origin-Response-Time
HostName
X-TA-CDN-Provider
User-Cache-Control
X-TimeS
X-Datadome
X-DC
X-Gen-Mode
Wxu-Next-Commit
Web-Mar-Region
X-FC-Vary-Parameters
We-Hiring
Uber-Trace-Id
X-GeoIP-City
X-GeoIP
X-Geo-Header
Wxu-Next-Hostname
X-Esi-Check
X-Cache-Id
X-Cache-Date
X-Block-Status
X-B3-Trace-ID
X-Auto-Login
X-Core-Value
X-Device-Os
Wxu-Next-Region
X-Acquia-Purge-Cdn-Unconfigured
X-ApacheServer
X-BBC-Edge-Cache-Status
X-Irp-Debug
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Server-IP
X-Request-Host
X-Req
X-UA-Device-Type
X-V-Cache
X-Zen-Fury
Cluster
X-WA-Info
X-VG-TLSProxy
X-Var-Ttl
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Men
X-Mly-Id
True-Client-Country-4JS
X-HS-Content-Campaign-Id
X-Hnp-Log
X-Mvc-Supplant-Cachable
X-Mvc-Supplant-OutputCached
X-PERF
X-Pubstack
X-Org
X-Nginx-Cache-Key
X-NCache
X-Gzip
X-NMSegId
Mail-Subject
Cache-Provider
Canary
Req-Svc-Chain
C-Via
Machine
On-Server
NM-Fastcgi-Cache
Expiry
X-Service
X-Connection-Hash
X-Test
Country-Code
X-Up
X-Core-Mission
Click-Count-Action-Start
Is-Eu
X-App-Name
X-Old-Content-Length
Click-Count-Error
X-From
X-Policy
Platform
X-Cdn-Srv
Esi-Enabled
IsBot
X-SIPLIST1
Gh-Request-Id
X-Proto
Producers
X-Cache-TTL-Remaining
X-Ad-Load-Variation
AKAMAI
X-Hash
W
A
X-Branch-Name
Tube-Return
Tube-Got-Results
Adler-Geo
X-Fmm-Version
X-Fastly-Backend
Tube-Get-Contents
Tube-Got-Eval
Content-Script-Type
Content-Style-Type
X-Cache-Aspx
X-Moov-T
X-GoCache-CacheStatus
X-Contensis-Viewer-Groups
X-Moov-Xdn-Version
X-Varnish-Authentication
X-DPWN-IS-SECURE
X-Micro-Cache
L5d-Success-Class
HA-Ipaddr
X-Eu-Site
Pics-Label
X-CGP
X-Csrf-Jwt
X-Edge-Server
X-ZONE
Ha-Gx-Prefs
Proxy-Firewall
Cdn-Request-Time
Cf-Device-Type
Cdn-Host
X-Wikidot-Backend
X-Wikidot-Static-Cache
Datacenter
X-Amz-Meta-Cb-Modifiedtime
X-Sn-Servicetimems
Cache-Key
X-Slack-Shared-Secret-Outcome
X-Slack-Backend
Fastly-Backend-Name
X-CacheTTL
X-Parent-Response-Time
X-HA-Backend
Cdncip
X-AK-Request-ID
X-Owner
X-ND-Cache
Yak-Timeinfo
X-Region-Sid
Cdnsip
RNT-Machine
X-Via-Popn
X-Via-Poph
X-Dc
X-Via-Popv
LB
Locid
X-Qloud-Router
RNT-Time
X-Tx-Id
X-Date
X-Ah-Environment
X-Accel-Expires-Debug
PFcat
X-Amz-Storage-Class
X-CF-Lambda-Fn
Cdn
Expect-Staple
X-HN
X-VarnishDD-TTL
X-LB-NoCache
NGX
X-CF-Lambda-Version
N-Cache
X-Azure-Ref-OriginShield
X-Tenant
X-Tb-Optimization-Total-Bytes-Saved
SID
X-Refresh
X-Orig-Expires
X-Cache-Type
X-Servedbyhost
X-Shop-Environment
Xc-Version
X-Backend-Instance
X-LB-ID
X-CACHE-GROUP
X-Forwarded-Path
X-Ratelimit-Reset
X-CDN-Cache-Status
GeoIp-Country-Code
XM
X-Gamma-Serve
X-NGINX-Cache
X-Wa
X-Nc
X-VHOST
X-Client-Ip
X-Origin-Expires
X-API-Version
X-Cache-Backend
Cmstype
X-DynaTrace-JS-Agent
Cmsid
X-Tt-Logid
NtCoent-Length
RATING
Server-ID
X-Varnish-Hits
Cdn-Requestid
CPC-Age
X-Srv
CPC-Cache
X-Lagoon
X-Vmg-Version
CloudFront-Viewer-Country
X-Cdn-Diag
X-Nananana
X-Fpc
X-Akamai-Transformed
X-TIME
X-TX-ID
X-B3-Parentspanid
Resin-Trace
X-Via-Fastly
X-LAGOON
X-Zone
X-UA
X-CACHE-AGE
X-Api-Version
X-NewRelic-App-Data
X-Hit
Uri
CacheControlHeader
Cross-Origin-Opener-Policy-Report-Only
X-Proxy-CacheRZ
X-Nf-Request-Id
XkeyRZ
User-Agent
X-Variation
X-Presslabs-Stats
GeoIP-Latitude
MIME-Version
X-URL
Cache-Hits
X-Amz-Meta-Opti
X-Location
X-Ig-Origin-Region
X-Info
X-Fastly-Country-Code
X-DataCenter
True-Client-IP
X-Vc
X-ECache
X-Dynatrace-Js-Agent
Tcn
X-LiteSpeed-Tag
Hostname
X-Datacenter
X-NWS-UUID-VERIFY
VNS-Age
Fusion-Deployment-Id
Fusion-Template-Id
Lb
Fusion-Source
Fusion-Content-Source
VNS-Cache
Fusion-Content-Id
Fusion-Component-Id
True-Client-Ip
DataCenter
X-LiteSpeed-Cache-Control
X-CSRF-TOKEN
X-HostName
X-B3-Spanid
X-Geo
Powered-By
X-CS
X-RID
Cache-Name
X-Cloudmap
Origin-EX
Mime-Version
X-Jungle-Id
Origin-CC
X-CUA
X-Cached-By
Fastly-Drupal-Html
X-HOST
X-Dispatcher-Number
X-User
X-IAuth-Set-Uid
X-Segment-20210421
Cf-Ipcountry
X-AIR-PT
Debug
X-Cdn-Forward
X-Webkit-Csp-Report-Only
X-Mid
X-Render-Time
Load-Balancing
Cl-Cache
X-Varnish-Beresp-TTL
Srv
X-Wormhole-Sdk
X-VTEX-Cache-Time
X-VTEX-Cache-Server
X-MCACHE
X-Powered-By-VTEX-Cache
X-Auth-Group-Type
X-Esi
CDN
BehaviorPad-Version
X-Dispatch
Edge-Cache
Ohc-File-Size
X-FPC
GeoIP-Country-Code
X-Litespeed-Tag
CountryCode
X-Cdn-Cache-Status
X-Oracle-DMS-ECID
Server-Id
Ohc-Cache-HIT
X-ServedByHost
X-Lb-Id
YJS-ID
X-NC
X-Ig-Push-State
X-Cache-Enabled
X-WA
X-Cs
X-Cache-Ttl
Server-Info
My-App
X-Fastly-Backend-Reqs
X-Lb-Nocache
X-Wp-Cf-Super-Cache
X-Wp-Cf-Super-Cache-Cache-Control
X-NodeID
Odigeo-Trace-Id
Location
X-APP-VERSION
Ms-Author-Via
Wpo-Cache-Status
Wpo-Cache-Message
X-Litespeed-Cache-Control
X-VCL-Version
Ngx
Xkey-La3
X-Proxy-Cache-La3
Xkeylog
X-Cdn-Request-ID
CF-Ctrl
X-MSEdge-Flight
CF-Cached-On
X-Custom-Header
X-Snapshot-Date
X-Vgn-Hpd-Reason
X-Internal-Host
X-MSEdge-Features
X-Akamai-Pragma-Client-IP
X-MiniProfiler-Ids
Memory
Memcached
X-App
X-Nitro-Rev
X-PHP-Backend
X-Acquia-Application-Trace
X-Acquia-Site
X-Nitro-Cache
X-Depends
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
Time
Section-Io-Origin-Status
X-Nitro-Cache-From
OriginIP
X-IN-APIGATEWAYSSL
X-FL-EDGE
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
Srvid
X-Via-PopV
X-Via-PopN
X-Ha-Backend
X-IN-APIGATEWAY
X-Via-PopH
FSS-Cache
X-FL-QIT-DEBUG
X-Sorting-Hat-Shopid
X-Shopid
X-Cache-Version
X-Sorting-Hat-Podid
X-Shardid
Akamai-Cache-Status
X-Mg-Cache
X-Pad
X-Fastly-Cache-Hits
X-Lsadc-Cache
X-Sucuri-Id
X-Te-Duration-Ms
X-Te-Count
X-Cache-FS-Status
X-Http-Count
X-Http-Duration-Ms
X-Th-Server
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Serial
X-Service-Response-Time
X-Web-Server
X-Check-Cacheable
Sm-Log-Id
Geoip-Latitude
X-RequestId
X-Udemy-Cache-App-Namespace
X-Dw-Trace-Id