Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
CF-RAY
CF-Cache-Status
Link
X-Powered-By
ETag
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Alt-Svc
Access-Control-Allow-Credentials
X-Runtime
X-Xss-Protection
X-Drupal-Cache
X-Adblock-Key
X-Check
Content-Security-Policy-Report-Only
X-Generator
X-Cacheable
X-Cache-Status
X-Permitted-Cross-Domain-Policies
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Template
X-Language
X-Iinfo
Status
Content-Encoding
X-Content-Security-Policy
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
X-Kinja-Server-Push
Xkey
Upgrade
X-Request-ID
X-Via
Access-Control-Expose-Headers
X-Turbo-Charged-By
Access-Control-Max-Age
Keep-Alive
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Pass-Why
X-Age
EagleId
X-Backend
X-Envoy-Upstream-Service-Time
X-Robots-Tag
X-Amz-Id-2
X-Amz-Request-Id
X-Page-Speed
X-Ua-Compatible
X-Pingback
X-Server-Powered-By
X-AH-Environment
X-Server
X-CDN
X-Proxy-Cache
X-UA-Device
X-Hacker
Request-Context
X-Nginx-Cache-Status
X-Swift-SaveTime
X-Swift-CacheTime
Grace
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-Cdn
X-LiteSpeed-Cache
P3p
Cf-Railgun
Server-Timing
Feature-Policy
X-Amz-Version-Id
X-Device
X-WebKit-CSP
X-Server-Id
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
X-Rq
X-Ac
X-Cnection
EagleEye-TraceId
Report-To
X-Cloud-Trace-Context
X-Response-Time
X-Backend-Server
Request-Id
X-Host
X-Node
Content-Location
X-Readtime
X-Origin-Cache
X-Vhost
X-Application-Context
X-Cache-Lookup
X-ORACLE-DMS-ECID
X-DataDome
X-Dispatcher
X-Ruxit-JS-Agent
NEL
X-ORACLE-DMS-RID
X-Origin-Upstream-Status
X-Rack-Cache
X-HW
Surrogate-Control
Rating
Allow
X-Country-Code
X-Clacks-Overhead
X-Dns-Prefetch-Control
X-Country
X-Url
X-FTR-Request-ID
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-DynaTrace
X-Instart-Request-ID
X-MS-InvokeApp
Fusion-Component-Id
Fusion-Content-Source
Fusion-Template-Id
Fusion-Source
Fusion-Content-Id
X-Goog-Hash
X-TTL
X-TtlSet
X-Vname
X-PC
X-Varnish-TTL
Pinterest-Generated-By
X-B3-TraceId
Verso
X-Powered-By-Plesk
Public-Key-Pins
RTSS
X-Px
Edge-Control
X-Mod-Pagespeed
Display
X-Sol
X-Middleton-Response
X-Middleton-Display
Response
X-VARITI-CCR
X-Cdn-Fetch
X-Kinja
X-Kinja-Build
X-Kinja-Server
X-Kinja-Revision
X-GoogleNews-Bot
X-Use-Magma
X-Exp-Id
X-Exp-Variant
X-D2id
SPRequestGuid
X-ESI
X-Recruiting
X-CST
X-SharePointHealthScore
X-Ah-Environment
X-Akam-SW-Version
Service-Worker-Allowed
X-Vcap-Request-Id
Accept-Ch-Lifetime
SPRequestDuration
SPIisLatency
X-Version
X-Server-Name
X-GitHub-Request-Id
X-Abt-Application-Version
TCN
X-Powered-CMS
X-Navigation-Version
MS-Author-Via
X-Trace
X-Shard
Charset
Fastly-Restarts
X-Debug
Accept-CH
Nginx-Cache
X-Amz-Server-Side-Encryption
Realpath
X-Upstream
X-Amz-Rid
X-RateLimit-Remaining
X-Aspnetmvc-Version
AR-ATIME
AR-PoweredBy
AR-CACHE
X-Forwarded-Proto
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Ar-Sid
X-Ezoic-Cdn
X-NF-Request-ID
Front-End-Https
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Cached
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-MSEdge-Ref
Pagespeed
Access-Control-Request-Method
Arr-Disable-Session-Affinity
X-VCache
X-Shield-Request-Id
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
AR-Request-ID
DynaTrace
Content-MD5
X-FTR-Expires
X-FTR-Cache-Status
X-Country-Code-Real
MicrosoftSharePointTeamServices
X-XRDS-Location
S
X-Id
X-T
X-Amz-Meta-S3cmd-Attrs
X-Goog-Storage-Class
Paypal-Debug-Id
X-Fastly-Request-ID
X-FTR-DC
X-FTR-Balancer
X-FTR-Backend
X-FTR-Backend-Server
X-FTR-Realm
X-Varnish-Age
X-Ser
ServerID
X-DynaTrace-JS-Agent
X-Via-JSL
X-Client-IP
Accept-Ch
X-Grace
X-Accel-Expires
X-Content-Type
X-Correlation-Id
X-Dw-Request-Base-Id
X-Hits
Edge-Cache-Tag
X-Amzn-Trace-Id
Fastcgi-Cache
X-Content-Digest
Powered
X-Frontend
X-DIS-Request-ID
X-Forwarded-For
AMP-Access-Control-Allow-Source-Origin
X-N
X-FTR-Cache-Host
Arc-Version
PB-PID
X-Mobile-Rewrite
PB-RID
X-FastCGI-Cache
X-HS-Content-Id
X-HS-Hub-Id
X-Pinterest-Rid
Pinterest-Version
X-Logged-In
Server-Name
X-Vcache
X-Fastcgi-Cache
TP-Cache
TP-L2-Cache
X-GUploader-UploadID
X-Request-Processing-Time
X-Request-Handler-Origin-Region
X-Microsite
X-Server-ID
X-Request-Received
X-Kinsta-Cache
X-Time
X-Cache-Hit
X-Zen-Fury
X-Type
X-Rid
X-Activity-Id
X-Az
X-AppVersion
Backend-Timing
X-Analytics
X-LB-Cache
X-IPLB-Instance
Retry-After
X-Revision
X-Cache-Age
Healthy
X-User-Agent
X-B3-Sampled
X-Whom
X-Node-Name
X-RateLimit-Limit
FilterID
Server-Node
X-Srv
X-NWS-LOG-UUID
X-Hp-Webp
Cache-Tag
Alternate-Protocol
X-F-Cache
Accept-Charset
X-Akamai-Edgescape
X-SERVER
Cache-Status
X-Cache-Rule
X-Content-Security-Policy-Report-Only
X-Content-Options
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Cache-2
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
DC
VIX-Pulpo-Upstream-Status
X-Tumblr-Pixel-0
MS-CV
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Instance
X-Content-Powered-By
X-Tumblr-User
VIX-Pulpo-Node
X-Tumblr-Pixel
X-App-Environment
X-Webkit-CSP
Refresh
X-Debug-Info
X-Framework
NR-ENABLED
X-PHP-Backend
X-Forwarded-Host
X-Jobs
Surrogate-Key
Access-Control-Allow-Method
Tracecode
X-Cluster
X-Varnish-Grace
X-AOL-HN
Fastcgi-Useragent
X-FB-Debug
X-Page-Id
X-Request-Guid
X-B
X-Cache-TTL
Source
Actual-Object-TTL
Host
X-App-Server
X-Mobile-URL
X-Seen-By
X-Cache-Operation
X-FW-Server
X-FW-Serve
X-FW-Hash
X-FW-Static
X-FW-Type
Frame-Options
X-Cache-Key
X-Cache-Control
X-Hostname
X-Geo-Country
Cleartype
X-TA-CDN-Provider
X-Cached-By
X-Host-Name
X-B-Cache
X-Pad
X-Signature
X-BCube-Filmed-By
Upgrade-Insecure-Requests
X-Git-Hash
X-WebKit-CSP-Report-Only
X-Mobile
X-Response-Served-From
X-Varnish-Backend
X-Esi
NGB
X-ATG-Version
X-Element-Page-Cache
X-Amz-Replication-Status
X-TT
WPE-Backend
X-Handled-By
X-RemovedCookies
Ms-Operation-Id
X-Tumblr-Pixel-1
Cache-Tv-Group
Filters
X-Tumblr-Pixel-2
X-RequestSource
X-RTag
X-ProcessESI
Webserver
X-GeoIP
GEO-INFO
Eomportal-Instance
From-Origin
Payment
X-Drupal-Cache-Tags
X-Origin-Server
X-UA-Device-Type
X-Adobe-Loc
X-Adobe-Content
X-Cacheable-TTL
X-HS-Cache-Config
X-TT-TIMESTAMP
X-EdgeConnect-Cache-Status
X-Daa-Tunnel
X-B3-Traceid
X-Presslabs-Stats
X-TX-ID
Xserver
X-Acc-Meta-Resource-Type
X-Wix-Request-Id
Liferay-Portal
X-FW-Dynamic
X-Status
X-Cache-TTL-Remaining
X-XRDS-LOCATION
X-WA-Info
X-Cache-Remote
Datacenter
X-Hyper-Cache
Cache
Accept-CH-Lifetime
X-Cache-Action
X-Region
X-Contextid
X-Edge-Location
Viewport
X-Content-Age
X-Ratelimit-Reset
Version
X-Ttl
X-Cache-NE
X-CF-Powered-By
X-Varnish-Hostname
X-Storage
X-Akamai-Transformed
PageSpeed
Ohc-File-Size
X-Cache-Server
X-Accel-Buffering
X-PressLabs-Stats
X-Varnish-Server
X-Cache-Var
X-Cache-Var-Map
X-ES-SERVER
X-Path-Route
Meta-Geo
X-RN-RSRV
X-HS-Combine-CSS
Load-Balancing
X-IP
Host-Header
Cache-Tags
X-NCache
X-Origin-Hint
X-Cache-Enabled
X-Access
Webcakes-Region
X-Cache-Config
X-Proxy
Webcakes-App-Version
X-Loop
X-Via-Fastly
TWC-Device-Class
TWC-GeoIP-Country
TWC-Connection-Speed
Rt-Fastcgi-Cache
Cache-Name
Property-Id
TWC-GeoIP-LatLong
TWC-Locale-Group
X-Tumblr-Pixel-3
X-TNCMS
Webcakes-App-Name
X-Viewer-Country
TWC-Privacy
X-Section
Vix-Hermes-Req-Id
X-Varnish-Cache-Hits
X-Vgn-Hpd-Reason
S-Rt
Selected-Fe
X-Rule
X-Timing-Wait
Ec-Rule-Version
X-Www-Served-By
X-UnsetCookies
X-Upgrade-Enabled
X-Origin
X-Cache-Time
Country
DB-Nickname
X-R9-Blue-Green-Version
X-Proxy-Build
X-CS
X-Cluster-Node
X-Drupal-Cache-Contexts
X-FC-Vary-Parameters
X-From
X-Format
X-Human
X-Cache-Grace
X-Proto
X-Akamai-Request-ID
X-Origin-Response-Time
X-NGENIX-Cache
X-Backend-TTL
X-Backend-Name
X-Xfnlog-Site
Cache-Hits
X-Yottaa-Optimizations
S-Cnection
X-Yottaa-Metrics
X-PCL
X-OCL
Azure-Version
Azure-SiteName
Azure-InstanceId
Azure-RegionName
X-Trace-Id
Azure-SlotName
X-Labrador-Cache-Channel
Mn-Server-Ip
Decoy-Debug-TTL
Decoy-Debug-Status
Decoy-Debug-Key
X-NewRelic-App-Data
X-Site-Version
X-ApacheServer
X-PERF
X-Locale
X-Hit
X-Generated
Ohc-Cache-HIT
X-Akamai-Request-ID2
X-JoinUs
X-Debug-Cache
X-Web-Node
X-Time-Microsecs
X-EIG-Tracking-Id
X-Hosted-By
X-Device-Type
X-Trafficlayer-App-Name
X-Trafficlayer-App-Scope
Release
X-FireWall-Port
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Cache-Host
X-CCM
Cache-Key
X-VCT
DSUID
X-Varnish-Hits
X-OVcl
X-OVcl-Cache
X-Rendered-As
X-Real-IP
Time
Server-Info
X-Tec-Api-Version
X-S
X-Pubstack
X-Tec-Api-Origin
X-Tec-Api-Root
L5d-Success-Class
Origin-Cache-Control
Origin-Edge-Control
X-APP-VERSION
X-FW-Version
X-Redis-Cache
Now
X-SS-Set-Cookie
X-Upstream-CT
X-Upstream-HT
Fastcgi-X-Cache-Version
X-Ua
OT-Force-Account-Verify
X-Litespeed-Cache
Fastly-SSL
Access-Control-Request-Headers
ServedBy
Cteonnt-Length
X-FB-TRIP-ID
X-Cluster-Name
X-Origin-TTL
X-UUID
X-Upstream-Proxy
X-Origin-CC
Origin
X-VG-TLSProxy
Hostname
X-VG-WebCache
X-Load-Cache
X-Sorting-Hat-ShopId
X-Rocket-Nginx-Bypass
X-ServerID
X-GoCache-CacheStatus
NtCoent-Length
X-Alternate-Cache-Key
X-Shopify-Stage
X-ShardId
X-Sorting-Hat-PodId
X-ShopId
X-Parent-Response-Time
X-Soup
Machine
Mime-Version
Accept-Language
X-Tb
X-B3-Spanid
X-Is-Bot
X-App-Version
X-UA
NGX
X-ECACHE
X-No-Session
IBM-Web2-Location
CF-IPCountry
X-Uri
X-CSRF-TOKEN
Nel
X-L-Path
X-Environment-Context
Odigeo-Trace-Id
X-B3-Parentspanid
X-CACHE-KEY
X-Tt-Trace-Tag
X-NC
X-B-Cookie
Uber-Trace-Id
X-CF-Lambda-Version
Xc-Version
X-Worker
X-D
Proxy-Connection
X-MServer
X-CF-Lambda-Fn
X-Node-Id
X-Info
X-ARC
Content-Style-Type
ServerName
Cross-Origin-Window-Policy
Content-Script-Type
T-Server
Cache-Prefix
VivaBuild
Viewtype
Rt-Proxy-Cache
Rendered-Blocks
Meta-Geo-Continent
Memcached
MD5-Digest
Mobile-Detection-Method
Node
Fly-Cache
Fly-Request-Id
GEO-REGION-INFO
X-A
X-A-Ccd
X-Accel-Expires-Debug
X-A-Wwc
A
X-Aed
X-AIR-PT
X-ProxyCache-Key
X-ProxyCache-Status
X-Application
X-A-Dgt
X-A-Dcw
AsisCache
BehaviorPad-Version
X-A-Dam
Arc-Country
Apple-News-Services-Request-Url
Apple-News-Services-Handled
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
X-BYPASS-REASON
X-Connection-Hash
X-Developer
X-ScT
X-VG-WebServer
X-S-Cookie
X-Vtex-Processado-Em
X-Transaction
X-Twitter-Response-Tags
X-Server-Time
X-DPWN-IS-SECURE
X-Trv-Group
X-Date
X-External-Request-Id
X-G
X-SRCache-Key
X-Vtex-Remote-Cache
X-Detected-As
X-Destination
X-Hl-Ver
X-Region-Sid
X-Instart-Info
X-PAYTM-SRV-ID
X-Request-UUID
X-Rojux
X-Rewrite-Enabled
X-Endurance-Cache-Level
Backend-Name
X-Amzn-Remapped-Content-Length
X-Oneagent-Js-Injection
N-Cache
X-SVT-ORM-VERSION
X-S-Maxage
X-JWT-State
X-Has-Esi
X-Is-Gdpr
IsBot
Fastly-Soc-X-Request-Id
X-SVT-ORM-RULES
X-SIPLIST1
Akamai-GRN
Request-Time
X-Geo
X-Nginx-Cache
Request-EU
X-Compress-Hint
Request-Country
X-Cms-Context
SRV
X-Cdn-Srv
X-Developers
X-Cache-Bucket
User-Cache-Control
X-Magnolia-Registration
X-Origin-Expires
X-Clientip
X-Release
X-Level-Front-Cache
X-Origin-Date
X-Geo-Header
L
Wxu-Next-Hostname
Wxu-Next-Commit
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-We-Are-Hiring
X-Location
Pramga
X-Webstats-RespID
X-Reboot
Served-By
X-Hnp-Log
Section-Io-Cache
X-Irp-Debug
X-VC-Cache
X-C
X-Block-Status
X-ElasticPress-Search
X-WADP-Cache
X-Azure-Ref
X-Azure-Ref-OriginShield
X-Bip
X-Thanos
X-TrackingId
X-Backend-Url
X-Backend-Host
X-Distil-CS
X-Auto-Login
X-Fastly-Cache
X-Up
X-Server-IP
X-Generated-On
X-BBXSRF
X-Clara-WADP
X-Cdn-Origin
X-Service
X-Gen-Mode
X-Sn-Servicetimems
X-Device-Os
X-Skip-Cache
X-Cache-Info
X-Generation-Time
Wxu-Next-Region
Mail-Subject
Srv
Heartbleed
Content-Disposition
AKAMAI
Countrycode
X-Nc
X-Dc
Gh-Request-Id
We-Hiring
CDCHOST
X-PHP-Host
X-Microcachable
X-Proxy-Upstream
X-Proxy-Cache-Status
X-Say-Cacheable
X-Policy
X-RateLimit-Remaining-Second
X-Rebelmouse-Cache-Control
X-Reqid
X-Qloud-Router
X-RateLimit-Limit-Second
X-Rebelmouse-Surrogate-Control
X-Method
X-Debug-Cache-Store
X-Debug-Cookies
X-Debug-Log
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-Core-Mission
X-CUA
X-Dispatch
X-Eu-Site
X-Matched-Rule
X-Say-TTL
X-Nginx-Cache-Key
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-Generated-By
X-Hash
X-NX-Host
X-Swa-Ws
X-Li-Fabric
X-Li-Pop
X-LI-Proto
X-GeoIP-City
X-Fetched-On
X-Distributor
X-Epic-Correlation-Id
X-LI-UUID
X-Old-Content-Length
X-WebServer
X-Request-URI
X-Variation
X-Request-Start
X-Owner
X-Platform-Server
X-B3-SpanId
X-Cache-FS-Status
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Var-Ttl
X-Thinkindot-L3
X-CGP
X-Servername
X-Guploader-Uploadid
X-VServer
Adler-Geo
RNT-Time
X-Amz-Meta-Cache-Control
RNT-Machine
Platform
Is-Eu
PFcat
X-SayCDN-TTL
X-User
Thinkindot-Control
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
W
Web-Mar-Node
X-App-Name
Cache-Provider
Server-Int
Server-Host
Magicmarker
Locale
HA-Ipaddr
Ha-Gx-Prefs
Fastly-SWR
Esi-Enabled
Fastly-SIE
X-Backend-State
Pagetype
X-Via-CDN
X-NWS-UUID-VERIFY
X-Ratelimit-Limit
X-GEO
True-Client-Country-4JS
X-Lb-Id
X-Generated-In
Kp-EeAlive
X-Svr
X-Key
X-MSEdge-Features
X-Internal-Host
X-MSEdge-Flight
X-Cache-Id
X-SD-PageType
X-ServiceProvider
SD-X-WS
X-Dispatcher-Server
Resin-Trace
Server-ID
X-LJ-Flow-ID
X-Cdn-Forward
X-VWS-Id
X-AWS-Id
X-Cache-URL
X-Edge-Server
Cdn-Request-Time
X-FPC
Cdn-Host
V-Age
Memory
X-GDPR
X-Mode
X-Scheme
REQUESTUUID
X-Instart-Isnd
X-Be
X-Cache-Backend
X-Processor
X-Org
X-Request-Time
X-DC
X-Hello
X-ABtesting
SS
X-Wa
X-Flog
Group
X-CDN-Forward
X-Servedbyhost
X-NodeID
X-IPS-LoggedIn
X-Datadome
X-Unique-ID
Cache-Host
Country-Code
X-Pjax-Url
X-Response-By
X-Server-W
X-DataStream-Cache-Status
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-From
X-SRV
X-EC-Lua
X-Zipkin-Id
X-Ms-Request-Id
X-Page-Type
X-Proxied
X-SN
X-Ms-Version
X-VCL-Version
X-Routing-Service
PICS-Label
X-Ruxit-Js-Agent
X-Varnish-Beresp-Status
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
UCS
X-Oss-Object-Type
X-Varnish-Beresp-Ttl
X-Oracle-Dms-Rid
X-Oss-Server-Time
X-Varnish-Beresp-Grace
X-Oss-Storage-Class
X-Webkit-Csp
X-RateLimit-Reset
XServer
X-Tb-Optimization-Total-Bytes-Saved
X-Ftr-Request-Id
X-HS-Status
X-Via-Ucdn
X-Session-Fingerprint
Lfy
X-Dynatrace
X-Zone
X-Cache-Debug
X-Agile-Id
X-MP-GENERATED-AT
X-Pf-Uncompressing
X-Agile
X-COUNTRY
Ttl
X-Logtrace-Id
X-URL
Ajk
Powered-By-ChinaCache
X-Agile-Age
X-GRACE
SN
Geoip-Latitude
Geoip-City
X-Fastly-Country-Code
Proxy-Firewall
GeoIp-Country-Code
ProcessTime
X-Source
X-ZONE
X-Varnish-Beresp-TTL
X-Ratelimit-Remaining
X-7Graus-Varnish-Cache-Control
X-Webapp-Samesite-None-Activated-N
Powered-By
X-7Graus-Varnish-XKeys
X-APP
X-HTML-Minification-Powered-By
GeoIP-Latitude
X-Newrelic-Synthetics
GeoIP-Country-Code
X-Sedo-Request-Id
X-PF-Uncompressing
X-Cache-Miss-From
X-Logging-Id
GeoIP-City
X-Grey
Environment
X-Cache-Category-Id
X-CSRF-Token
X-Sucuri-ID
CACHE
X-DataStream-Origin-MEX-Latency
X-NODE
X-Unique-Id
X-DataStream-MidMile-RTT
X-Dynatrace-Js-Agent
X-Ftr-Cache-Host
X-Sucuri-Id
X-TH-Server
X-Bc
X-CLOUD-TRACE-CONTEXT
X-Tt-Trace-Host
Fastly-Backend-Name
Cdn
X-LiteSpeed-Cache-Control
X-FORWARDED-FOR
MIME-Version
Pics-Label
X-Edge
X-Aicache-OS
X-Core-Value
M-TraceId
X-Check-Cacheable
X-Vcl-Version
CF-Cached-On
WWW
X-Vdms-Version
GW-Server
X-Sucuri-Cache
X-Ftr-Backend-Server
HostName
Dynatrace
X-Ftr-Dc
X-Ftr-Realm
X-Ftr-Balancer
X-Ftr-Backend
Cdncip
X-Mid
X-LAGOON
Requestid
Cdnsip
X-Sigma-Backend
X-Sigma
X-RCS-CacheZone
LB
X-Fastly-Backend-Reqs
X-Rocket-Build-Number
X-AK-Request-ID
Cf-Ipcountry
X-UPSTREAM-Address
X-BC
X-Varnish-Url
X-Shopify-Generated-Cart-Token
X-Varnish-Ttl
Ohc-Response-Time
X-MCACHE
X-Cache-Tag
X-Gannett-Site-Version
X-Fstrz
X-Secret
X-PJAX-URL
X-NGINX-Cache
Amp-Access-Control-Allow-Source-Origin
URI
X-Planisys-CDN-Cache
Pragrma
X-Planisys-CDN-TTL
X-ServedByHost
X-TT-LOGID
X-Via-NSCOPI
X-Litespeed-Cache-Control
X-Planisys-CDN-Rules
Lb
X-Swift-Error
WZWS-RAY
X-DB
X-RSL
X-WA
X-Varnish-Cacheable
X-RPS
On-Server
X-DW
X-DSS
X-DI
X-RPM
X-Cache-Ttl
DataCenter
X-CDN-Cache
X-Action
X-BE
X-ORACLE-APMCS-TAG
X-ORACLE-APMCS-REQUEST-ID
X-SaId
X-GeoIP-Country-Code
RequestUuid
X-Proxy-Cacherz
X-WR-MODIFICATION
User-Agent
X-ND-Cache
TTL
Xkeyrz
Host-ID
X-Correlation-ID
Xkeypdq
X-Zalando-Child-Request-Id
X-Upstream-Ht
X-Akamai-SSL-Client-Sid
Inserted-Into-Cache-At
Server-Id
X-Fastly-Cache-Hits
Is-Session-Tracking
Get-Access-Time
CDN
X-Upstream-Ct
X-Dw-Trace-Id
X-Flow-Id
X-Nananana
X-Page-Impression-Id
X-Fpc
Who
AR-SID
X-Crawler
X-Refresh
X-Served-From
Locid
X-Trafficlayer-App-Version
SID
X-LB-ID
X-Gen-Id
X-NU-AKA-ACS-Version
X-SB
Warning
X-MID
X-VC
Correlation-Id
X-Cf-Powered-By
X-Amzn-Remapped-Date
X-Amzn-Remapped-Connection
X-Akamai-ERPolicy
X-Akamai-ERRuleID
HitType
X-Via-Edge
X-Pod
X-Req
Thinkindot-Cache-Type
Gannett-Cam-Experience-Id
X-Via-SSL
X-ECache
X-Newrelic-App-Data
X-Gdpr
Cneonction
X-Bug-Bounty
X-Render-Time
X-ServerName
X-LiteSpeed-Tag
X-MiniProfiler-Ids
RequestId
Processtime
X-FE
Xet-Cookie
V-Cache
X-Request-URL