Threat Level: green Handler on Duty: Richard Porter

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Strict-Transport-Security
X-Frame-Options
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
CF-RAY
ETag
X-XSS-Protection
Accept-Ranges
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
X-Served-By
P3P
X-Download-Options
X-Xss-Protection
X-Request-Id
X-Timer
X-FRAME-OPTIONS
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Content-Security-Policy-Report-Only
X-Runtime
X-AspNet-Version
P3p
X-DNS-Prefetch-Control
Accept-CH
X-Cache-Status
X-Drupal-Cache
Accept-CH-Lifetime
X-Check
X-Generator
X-Ua-Compatible
X-Cacheable
Server-Timing
X-Envoy-Upstream-Service-Time
X-Request-ID
Timing-Allow-Origin
X-Iinfo
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
X-Content-Security-Policy
Feature-Policy
Content-Encoding
X-CDN
Status
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
X-Amz-Id-2
Host-Header
CF-Ray
Allow
X-Backend
Cf-Edge-Cache
Request-Context
X-Robots-Tag
Keep-Alive
X-Server
X-Cache-Group
X-UA-Device
X-Hacker
X-AH-Environment
X-Turbo-Charged-By
X-Ws-Request-Id
X-Proxy-Cache
X-Age
Xkey
X-Vhost
X-Rq
EagleId
X-Dispatcher
X-Server-Powered-By
X-Amz-Version-Id
X-Varnish-Cache
Grace
Cf-Apo-Via
X-Dns-Prefetch-Control
X-LiteSpeed-Cache
X-Page-Speed
X-Pingback
Cf-Railgun
X-Swift-SaveTime
X-Swift-CacheTime
X-Device
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
EagleEye-TraceId
Ali-Swift-Global-Savetime
X-Aws-Lambda-Call-Status
X-WebKit-CSP
X-CST
X-OneAgent-JS-Injection
X-Backend-Server
Permissions-Policy
X-Server-Id
X-Readtime
X-Response-Time
X-Host
X-Akam-SW-Version
Request-Id
Surrogate-Control
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Nginx-Upstream-Cache-Status
X-HW
X-Cloud-Trace-Context
X-Nginx-Cache-Status
X-Node
Accept-Ch-Lifetime
X-Litespeed-Cache
X-Application-Context
X-Cache-Lookup
X-Country-Code
X-Trace
Content-Location
X-Ruxit-JS-Agent
X-Oneagent-Js-Injection
Service-Worker-Allowed
X-Url
X-Content-Type
X-Country
X-Clacks-Overhead
X-Edge
X-ECACHE
X-Origin-Cache-Key
X-Rack-Cache
X-Mcache
X-Amz-Server-Side-Encryption
Cross-Origin-Opener-Policy
X-Mod-Pagespeed
X-Midtier
Cache-Tag
X-FTR-Request-ID
Accept-Ch
Nginx-Cache
X-MS-InvokeApp
X-TtlSet
X-Upstream
X-PC
X-Vname
X-Powered-By-Plesk
Rating
X-ESI
Edge-Control
X-Browser-Type
X-Server-Name
X-D2id
X-Element-Page-Cache
Verso
X-Kinja-Build
X-Kinja-Revision
X-Kinja
X-Kinja-Server
X-Exp-Id
X-Cdn-Fetch
X-Times
X-Exp-Variant
X-GoogleNews-Bot
X-Cnection
X-Ac
X-B3-TraceId
SPIisLatency
SPRequestDuration
AR-PoweredBy
AR-SID
AR-Request-ID
AR-ATIME
X-Ruxit-Js-Agent
X-Abt-Application-Version
X-Vcap-Request-Id
X-Navigation-Version
X-SharePointHealthScore
SPRequestGuid
X-NF-Request-ID
X-GitHub-Request-Id
X-Dw-Request-Base-Id
X-RateLimit-Remaining
X-Ser
AR-CACHE
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
X-VARITI-CCR
X-Mg-S
X-NWS-LOG-UUID
S
X-Cache-Key
Pagespeed
RTSS
X-Sol
X-Middleton-Display
Display
Edge-Cache-Tag
Fastly-Restarts
X-Amz-Rid
X-Amzn-Trace-Id
X-Client-IP
X-Ttl
X-Cache-TTL
X-Powered-CMS
X-Goog-Hash
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev-Is-Generated
X-Instrumentation
X-Erf-Bev-Bev
Origin-Trial
Cache-Status
X-Edge-Location-Klb
X-Kinsta-Cache
X-Varnish-TTL
X-Version
Access-Control-Request-Method
X-Server-ID
X-Content-Security-Policy-Report-Only
X-Recruiting
X-ARC
X-TraceId
X-Content-Digest
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
Arr-Disable-Session-Affinity
X-Middleton-Response
Response
X-Webkit-Csp
X-T
X-MSEdge-Ref
X-Forwarded-For
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Content-MD5
X-Ua-Device
X-Accel-Expires
MicrosoftSharePointTeamServices
TP-Cache
X-Shield-Request-Id
X-Hits
X-Cached
X-Id
Public-Key-Pins
X-RateLimit-Limit
X-Country-Code-Real
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-Cache-Status
X-FTR-Backend
X-FTR-Expires
MS-Author-Via
X-Ua-Browser
Cross-Origin-Resource-Policy
X-Request-Received
X-HS-Combine-CSS
X-Request-Processing-Time
X-HS-Cache-Config
X-HS-Content-Id
Server-Node
X-HS-Hub-Id
Front-End-Https
Payment
X-Frontend
X-DIS-Request-ID
X-Daa-Tunnel
X-FastCGI-Cache
X-Forwarded-Proto
X-LLID
X-GUploader-UploadID
TP-L2-Cache
X-Protected-By
X-LB-Cache
Realpath
X-HP-Webp
X-HP-Trace-Id
X-Jurisdiction
X-Fastcgi-Cache
Cache-Tags
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Origin-Server
X-Distributor
X-Request-Handler-Origin-Region
X-Microsite
Count-Hit
X-WebKit-CSP-Report-Only
X-Page-Id
X-AppVersion
X-Az
X-Activity-Id
X-F-Cache
X-B3-TraceId-Primal
X-TTL
MRF-Tech
Mrf-Cache-Status
X-Cluster-Name
X-Hostname
Referer-Policy
X-Geo-Country
X-Debug-Info
X-Www-Served-By
X-Varnish-Backend
X-Correlation-Id
X-ORACLE-DMS-RID
Accept-Charset
X-NGENIX-Cache
Fastcgi-Cache
X-PressLabs-Stats
X-App-Server
X-Kinja-CCPA
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Envoy-Decorator-Operation
Host
X-Varnish-Server
X-Goog-Metageneration
X-FB-Debug
Access-Control-Allow-Method
X-Git-Hash
X-Oracle-Dms-Ecid
X-RateLimit-Reset
Retry-After
X-Rid
X-ORACLE-DMS-ECID
Server-Name
X-Content-Options
X-Load-Cache
X-Oracle-Dms-Rid
X-Ratelimit-Limit
X-Upgrade-Enabled
X-Px
X-Tt-Trace-Tag
X-XRDS-LOCATION
X-Tt-Trace-Host
X-Aspnet-Duration-Ms
X-Providence-Cookie
X-Revision
X-Route-Name
DC
TCN
X-Contextid
X-Request-Guid
X-Flags
X-Is-Crawler
X-TEC-API-ORIGIN
Charset
X-TEC-API-ROOT
X-App-Environment
X-Trace-Id
X-TEC-API-VERSION
X-Datadog-Parent-Id
X-Datadog-Trace-Id
X-Cache-Control
X-Datadog-Sampling-Priority
X-Type
X-Seen-By
Paypal-Debug-Id
X-CSRF-Token
X-Ezoic-Cdn
Cleartype
X-Signature
X-B-Cache
X-B3-Sampled
X-Grace
X-Origin-Cache
X-Fastly-Request-Id
Section-Io-Cache
X-Amz-Meta-S3cmd-Attrs
X-B
X-TT
X-Mobile
X-Fb-Rlafr
X-Amz-Replication-Status
X-ASPNET-VERSION
Frame-Options
Healthy
X-Wix-Request-Id
X-Whom
X-Fastly-Request-ID
X-Magnolia-Registration
X-Goog-Generation
X-Language
X-Goog-Storage-Class
X-Node-Name
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
Filterid
X-EdgeConnect-Cache-Status
X-Logged-In
X-Azure-Ref
X-Varnish-Ttl
X-Proxy
X-Newrelic-App-Data
X-N
X-Air-Pt
Content-Disposition
X-Ratelimit-Remaining
X-App-Version
Backend
Akamai-GRN
Upgrade-Insecure-Requests
X-Template
X-Proxy-Cache-Info
X-Original-Request-Id
X-Response-Served-From
NGB
Refresh
X-Is-Bot
SD-X-WS
X-Tumblr-User
X-ProcessESI
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Unique-Id
VIX-Pulpo-Upstream-Status
X-RemovedCookies
X-Rendered-As
VIX-Pulpo-Node
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-WP-CF-Super-Cache-Cache-Control
X-WP-CF-Super-Cache
X-Tumblr-Pixel-0
Viewport
X-Page-View
MS-CV
Ms-Operation-Id
X-RTag
X-Datadog-Sampled
X-Amzn-Remapped-Content-Length
X-Varnish-Grace
X-Instance
X-Servername
Liferay-Portal
X-FW-Serve
X-FW-Dynamic
X-Debug
X-FW-Static
X-FW-Version
X-FW-Type
X-IPS-LoggedIn
X-FW-Hash
X-UUID
X-FW-Server
X-Debug-IsConnected
X-Debug-IsPreview
X-Adobe-Content
X-User-Agent
X-Cache-Grace
Fastly-SWR
X-Adobe-Loc
X-Cacheable-TTL
Fastly-SIE
X-Region
From-Origin
X-NYM-Debug-Backend
Url
X-Rule
X-G
Country
X-L-Path
X-Jobs
X-Cache-Hit
X-Device-Type
X-Environment-Context
X-B3-SpanId
X-Hl-Ver
X-Status
X-Backend-Name
Amp-Access-Control-Allow-Source-Origin
ServerID
X-Time
Surrogate-Key
X-Hosted-By
X-Air-Source
X-Air-Trace-Id
Countrycode
X-Air-Hostname
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Origin-TTL
X-Origin-CC
X-VC-Cache
Alternate-Protocol
X-Webkit-CSP
X-Via-JSL
X-Cache-Age
X-Akamai-Request-ID2
X-Cache-Status-Check
X-INCAP-ABP
X-Tec-Api-Origin
X-Tec-Api-Version
Version
X-Tec-Api-Root
X-Content-Powered-By
Protected
WPO-Cache-Message
WPO-Cache-Status
X-HTML-Minification-Powered-By
X-Http-Reason
SRV
X-NODE
X-XRDS-Location
X-Rocket-Nginx-Serving-Static
X-Nginx-Cache
GEO-INFO
X-Akamai-Edgescape
CDN-RequestId
CF-IPCountry
X-B3-Traceid
X-CDN-Forward
X-Framework
X-Source
X-Storage
X-WP-CF-Super-Cache-Active
X-Accel-Version
X-Edge-Location
Access-Control-Request-Headers
X-Cache-Rule
Front
X-Real-IP
OT-Force-Account-Verify
X-Mode
X-Httpd
Accept-Language
X-Endurance-Cache-Level
Meta-Geo
X-UPSTREAM-Address
X-Cache-Operation
X-Upstream-Ht
X-Xfnlog-Site
X-Upstream-Ct
Filters
X-Rewrite-Enabled
X-Rn-Rsrv
X-Soup
X-Proxy-Build
X-Director
X-JoinUs
X-Timing-Wait
X-Served-From
X-Tumblr-Pixel-3
X-SaId
X-Tumblr-Pixel-2
Webserver
Selected-Fe
X-Handled-By
ServedBy
X-Logging-Id
X-Detected-As
X-SayCDN-TTL
X-Redis-Cache
X-Cache-Debug
X-Say-Cacheable
X-Say-TTL
X-Worker
X-Origin
X-Varnish-Cache-Hits
X-Use-Magma
X-Use-Mantle
X-Format
X-Tncms
Azure-SlotName
Property-Id
X-Vcache
X-GeoCode
TWC-Connection-Speed
Azure-Version
Azure-SiteName
X-Restarts
Xserver
Azure-InstanceId
DB-Nickname
X-Cms-Context
X-Cache-Time
TWC-Device-Class
X-RM-Cache-TTL
Azure-RegionName
X-GeoCountry
Webcakes-App-Version
TWC-GeoIP-Country
X-Server-W
X-Labrador-Cache-Channel
Webcakes-Region
X-VC
X-Sql-Count
X-Lambda-Id
X-Sql-Duration-Ms
X-Adobe-Source
Webcakes-App-Name
TWC-Privacy
TWC-Locale-Group
TWC-GeoIP-LatLong
X-Origin-Hint
Web-Mar-Node
X-Varnish-Age
X-Loop
X-PHP-Host
X-AWS-Id
Mn-Server-Ip
X-Vercel-Id
X-Vercel-Cache
X-VWS-Id
X-RCS-CacheZone
X-BYPASS-REASON
X-ProxyCache-Status
X-VCT
X-Container-Uri
X-Git-Commit
X-No-Session
Apigw-Requestid
Xet-Cookie
X-Skip-Cache
X-LJ-Flow-ID
X-Tb
X-Fetched-On
X-Generation-Time
X-Varnish-Beresp-Grace
X-ProxyCache-Key
X-ServerID
X-IPLB-Instance
X-IPLB-Request-ID
X-Web-Node
X-Cache-Host
X-Provided-By
X-Cache-Server
Section-Io-Id
X-DynaTrace
X-Frame-Option
X-Forwarded-Host
X-Cluster
X-Extlb
X-Is-Tablet
X-Is-Supported-Browser
X-Browser-Name
X-Proxied
X-Is-Desktop
X-Is-Mobile
X-Geo-Region
Node
X-Site-Version
X-Locale
X-Routing-Service
X-Tcp-Rtt
X-AB
X-Reqid
X-S
X-Zipkin-Id
X-Ms-Request-Id
X-Ms-Version
X-Uri
X-Platform-Processor
X-Platform-Router
Cross-Origin-Embedder-Policy
X-Platform-Cluster
X-R9-Blue-Green-Version
Cache-Tv-Group
X-Webstats-RespID
X-Drupal-Cache-Tags
Priority
X-MP-GENERATED-AT
Source
Fastcgi-Useragent
X-Drupal-Cache-Contexts
X-FB-TRIP-ID
X-COUNTRY
Content-Secure-Policy
WP-Super-Cache
CDN-CachedAt
X-Vcl-Version
CDN-EdgeStorageId
CDN-Cache
CDN-RequestCountryCode
CDN-Uid
AMP-Access-Control-Allow-Source-Origin
CDN-RequestPullSuccess
CDN-RequestPullCode
X-Origin-Date
CDN-PullZone
X-TT-LOGID
X-Generated-By
Onion-Location
X-Storefront-Renderer-Rendered
X-Shopify-Stage
X-Alternate-Cache-Key
X-Urbn-Site-Id
X-Sucuri-Cache
X-Urbn-Context-Path
Locale
X-Content-Age
X-ShardId
X-Sorting-Hat-ShopId
S-Rt
X-Sorting-Hat-PodId
X-ShopId
X-Xrds-Location
X-Pass-Why
X-SRV
WZWS-RAY
X-Cdn-Origin
X-Sucuri-ID
X-Newrelic-Synthetics
X-Buckets
X-Ua
X-Varnish-Beresp-Ttl
Cross-Origin-Embedder-Policy-Report-Only
Sid
X-Cluster-Node
X-DataDome
X-Cache-Action
X-Proxy-Cache-Status
X-Thinkindot-L3
X-CMSURLCustom
TDXMobile
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-Scope-Id
X-Shield-Cache-Expires
Thinkindot-Control
X-Cache-Expired-At
Cross-Origin-Window-Policy
Cache
X-LSADC-Cache
Atl-Traceid
X-GEO
Fastly-Drupal-HTML
X-Via-Edge
Edge-Copy-Time
X-Via-CDN
X-Request-URI
X-Via-SSL
X-Cache-NE
X-Conf
X-A-Ccd
X-Cache-Bucket
X-Mg-Request-UUID
X-Bl-Debug
X-A
T-Server
X-Destination
X-Developer
Type
DCR-Decision-By
X-D
Candidate-Md5Url
Sslversion
X-B-Cookie
X-Bc-Bl
X-Application
X-Aed
Surrogated-Key
X-A-Dgt
X-Ec-Fail
X-A-Dcw
X-A-Dam
X-BCube-Filmed-By
CDCHOST
X-Vtex-Remote-Cache
X-A-Wwc
X-Ec-Custom-Error
Meta-Geo-Continent
X-PAYTM-SRV-ID
X-Optimistic-Header
X-Scheme
X-Vdms-Path
X-ScT
X-S-Cookie
Origin-Agent-Cluster
X-TIM-N
Ngx.Var.Host
Gannett-Cam-Experience-Id
X-Rojux
Origin
X-Vdms-Version
X-WP-CF-Super-Cache-Cookies-Bypass
X-External-Request-Id
Lang
X-SRCache-Key
X-Epic-Correlation-Id
X-Ec-GeoHdr
Ngx-Var-Key
Rendered-Blocks
DCR-Processing-Time-Ms
X-Viewer-Country
Redirect-Candidate
MD5-Digest
X-Aspnetmvc-Version
Host-ID
Magicmarker
Fastly-GeoIP-CountryCode
Req-ID
Release
Server-Ext
Server-Hostname
Server-Host
Sever-Int
DSUID
Fastly-SSL
Pramga
L
Environment
Ssr
X-Debug-Cache-Fetch
X-Rocket-Build-Number
X-SB
X-SD-PageType
X-Section
X-Request-Time
X-Request-Start
X-Pool
X-Proxied-Request
X-Pubstack
X-Sigma
X-Sigma-Backend
X-Varnishpool
X-VG-WebCache
X-VServer
X-We-Are-Hiring
X-Varnish-Hostname
X-Varnish-Director
X-TH-Server
X-Thanos
X-Varnish-Beresp-Status
X-Origin-Time
X-Op-Id-All
X-Debug-Cache-Store
X-Dispatcher-Server
X-Fastly-Cache
X-Forwarded-Site
X-Cache-Info
X-Bip
Vix-Hermes-Req-Id
X-Access
X-Aicache-OS
X-Gdpr
X-Generated-On
X-Loc
X-Node-Id
X-Nyt-Route
X-Level-Front-Cache
X-Instance-Name
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-Human
V-Age
X-Clientip
X-VCache
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-Correlation-ID
Apple-News-Services-Request-Url
Apple-News-Services-Handled
User-Cache-Control
X-TimeS
HostName
X-Origin-Response-Time
X-TA-CDN-Provider
X-Datadome
X-DC
Wxu-Next-Commit
Wxu-Next-Hostname
X-Esi-Check
X-Device-Os
X-Gen-Mode
X-Geo-Header
Uber-Trace-Id
Web-Mar-Region
X-GeoIP
Cluster
X-Core-Value
X-BBC-Edge-Cache-Status
X-Acquia-Purge-Cdn-Unconfigured
X-B3-Trace-ID
X-Auto-Login
Wxu-Next-Region
X-GeoIP-City
X-Cache-Id
X-Cache-Date
X-Block-Status
X-ApacheServer
X-Gzip
X-RateLimit-Remaining-Second
X-Req
X-RateLimit-Limit-Second
X-Policy
X-Platform
X-Request-Host
X-Server-IP
X-V-Cache
X-UA-Device-Type
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-PERF
X-VG-TLSProxy
X-Men
True-Client-Country-4JS
X-HS-Content-Campaign-Id
X-Hnp-Log
X-Zen-Fury
X-Mly-Id
X-Org
X-Nginx-Cache-Key
X-WA-Info
X-NCache
X-Var-Ttl
X-NMSegId
Gh-Request-Id
C-Via
Cache-Provider
Req-Svc-Chain
Machine
NM-Fastcgi-Cache
On-Server
X-Connection-Hash
Expiry
X-Service
X-Fmm-Version
Content-Script-Type
X-Old-Content-Length
Is-Eu
Producers
X-FC-Vary-Parameters
X-App-Name
X-Ad-Load-Variation
Esi-Enabled
X-Fastly-Backend
X-Moov-T
X-Mvc-Supplant-OutputCached
X-Mvc-Supplant-Cachable
AKAMAI
Mail-Subject
Adler-Geo
X-From
X-Hash
Content-Style-Type
IsBot
X-Micro-Cache
Platform
X-Irp-Debug
X-Cache-TTL-Remaining
X-Varnish-Authentication
X-Cache-Aspx
X-Core-Mission
W
We-Hiring
X-Contensis-Viewer-Groups
X-GoCache-CacheStatus
Tube-Get-Contents
Tube-Got-Eval
Tube-Got-Results
Tube-Return
Click-Count-Action-Start
Click-Count-Error
X-Branch-Name
X-Cdn-Srv
X-DPWN-IS-SECURE
X-SIPLIST1
A
Country-Code
X-Moov-Xdn-Version
X-Up
Canary
X-Test
X-Edge-Server
X-Amz-Meta-Cb-Modifiedtime
X-Proto
X-Sn-Servicetimems
Cdn-Host
Cf-Device-Type
Cache-Key
X-Slack-Shared-Secret-Outcome
X-Slack-Backend
X-Wikidot-Static-Cache
Fastly-Backend-Name
X-Wikidot-Backend
Cdn-Request-Time
X-ZONE
Datacenter
Proxy-Firewall
Pics-Label
X-Parent-Response-Time
X-Via-Popv
X-Via-Popn
X-CacheTTL
X-Eu-Site
Locid
X-Qloud-Router
HA-Ipaddr
X-HA-Backend
RNT-Machine
RNT-Time
L5d-Success-Class
Ha-Gx-Prefs
LB
X-Owner
X-Via-Poph
Cdnsip
X-AK-Request-ID
X-Tx-Id
X-Date
X-CGP
Cdncip
X-Region-Sid
X-Csrf-Jwt
Yak-Timeinfo
X-ND-Cache
X-Dc
X-Ah-Environment
X-Accel-Expires-Debug
X-Amz-Storage-Class
X-LB-NoCache
X-HN
Cdn
X-VarnishDD-TTL
PFcat
Expect-Staple
X-CF-Lambda-Fn
N-Cache
NGX
X-CF-Lambda-Version
X-Azure-Ref-OriginShield
X-URL
X-Refresh
X-Cache-Type
X-Forwarded-Path
X-Orig-Expires
Xc-Version
SID
X-LB-ID
X-Shop-Environment
X-Tb-Optimization-Total-Bytes-Saved
X-Backend-Instance
X-Servedbyhost
X-Tenant
X-CACHE-GROUP
X-Ratelimit-Reset
X-NGINX-Cache
XM
GeoIp-Country-Code
X-CDN-Cache-Status
X-Wa
X-Gamma-Serve
X-Nc
X-VHOST
NtCoent-Length
Cmstype
RATING
Server-ID
X-Client-Ip
X-Tt-Logid
Cmsid
X-Cache-Backend
X-Origin-Expires
X-DynaTrace-JS-Agent
X-API-Version
X-Varnish-Hits
Cdn-Requestid
X-Vmg-Version
CPC-Age
X-Srv
CPC-Cache
CloudFront-Viewer-Country
X-Lagoon
X-Cdn-Diag
X-Fpc
X-Nananana
X-Akamai-Transformed
X-TIME
X-Via-Fastly
X-TX-ID
Resin-Trace
X-B3-Parentspanid
X-LAGOON
X-Api-Version
X-UA
X-Zone
X-CACHE-AGE
X-Hit
CacheControlHeader
Uri
Cross-Origin-Opener-Policy-Report-Only
X-NewRelic-App-Data
X-Nf-Request-Id
X-Proxy-CacheRZ
User-Agent
XkeyRZ
X-Variation
X-Presslabs-Stats
GeoIP-Latitude
MIME-Version
Cache-Hits
True-Client-IP
X-Location
X-Fastly-Country-Code
X-Amz-Meta-Opti
X-Vc
X-Info
X-Ig-Origin-Region
X-DataCenter
X-ECache
Hostname
Tcn
X-LiteSpeed-Tag
X-Dynatrace-Js-Agent
VNS-Cache
True-Client-Ip
Fusion-Component-Id
VNS-Age
Fusion-Source
X-Datacenter
Fusion-Template-Id
Fusion-Deployment-Id
Fusion-Content-Source
Lb
Fusion-Content-Id
X-NWS-UUID-VERIFY
DataCenter
X-Esi
X-B3-Spanid
X-HostName
X-LiteSpeed-Cache-Control
X-CSRF-TOKEN
X-Geo
X-CS
X-RID
Powered-By
Cache-Name
X-Cloudmap
X-CUA
Origin-EX
X-Jungle-Id
Mime-Version
X-Cached-By
Origin-CC
Fastly-Drupal-Html
X-HOST
X-IAuth-Set-Uid
X-User
X-Dispatcher-Number
X-Segment-20210421
Cf-Ipcountry
Debug
X-AIR-PT
X-Webkit-Csp-Report-Only
X-Cdn-Forward
X-Varnish-Beresp-TTL
Cl-Cache
X-Mid
X-Render-Time
Load-Balancing
Srv
X-VTEX-Cache-Server
X-Wormhole-Sdk
X-VTEX-Cache-Time
X-Powered-By-VTEX-Cache
X-MCACHE
Ohc-File-Size
CDN
BehaviorPad-Version
X-Auth-Group-Type
Edge-Cache
X-Dispatch
GeoIP-Country-Code
X-FPC
X-Litespeed-Tag
X-Cdn-Cache-Status
X-Oracle-DMS-ECID
Server-Id
Ohc-Cache-HIT
X-WA
YJS-ID
X-Lb-Id
X-ServedByHost
X-Ig-Push-State
X-Cache-Enabled
X-NC
X-Cs
X-Cache-Ttl
X-Wp-Cf-Super-Cache-Cache-Control
X-Wp-Cf-Super-Cache
Location
My-App
Odigeo-Trace-Id
CountryCode
X-NodeID
Server-Info
X-Fastly-Backend-Reqs
X-Lb-Nocache
Wpo-Cache-Message
X-APP-VERSION
Wpo-Cache-Status
X-Litespeed-Cache-Control
Ms-Author-Via
X-VCL-Version
Xkey-La3
X-Proxy-Cache-La3
CF-Ctrl
Xkeylog
X-Akamai-Pragma-Client-IP
X-Cdn-Request-ID
X-Vgn-Hpd-Reason
CF-Cached-On
X-Custom-Header
X-Internal-Host
X-MSEdge-Flight
X-Snapshot-Date
X-MSEdge-Features
Ngx
X-MiniProfiler-Ids
Memory
Memcached
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
Section-Io-Origin-Status
X-Acquia-Application-Trace
X-Acquia-Site
FSS-Cache
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-IN-APIGATEWAY
Time
X-IN-APIGATEWAYSSL
OriginIP
X-FL-EDGE
X-Nitro-Cache
X-Nitro-Cache-From
Srvid
X-Nitro-Rev
X-FL-QIT-DEBUG
X-Via-PopN
X-Ha-Backend
X-App
X-Via-PopV
X-PHP-Backend
X-Depends
X-Via-PopH
X-Cache-Version
X-Sorting-Hat-Shopid
X-Shardid
X-Shopid
X-Sorting-Hat-Podid
Akamai-Cache-Status
X-Mg-Cache
X-Pad
X-Fastly-Cache-Hits
X-Lsadc-Cache
X-Sucuri-Id
X-Te-Duration-Ms
X-Te-Count
X-Cache-FS-Status
X-Http-Count
X-Http-Duration-Ms
X-Th-Server
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Serial
X-Service-Response-Time
X-Web-Server
X-Check-Cacheable
Sm-Log-Id
Geoip-Latitude
X-RequestId
X-Udemy-Cache-App-Namespace
X-Dw-Trace-Id