Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
CF-RAY
CF-Cache-Status
Link
X-XSS-Protection
X-Powered-By
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Alt-Svc
Access-Control-Allow-Credentials
X-Runtime
X-FRAME-OPTIONS
X-Drupal-Cache
X-Adblock-Key
X-Check
Content-Security-Policy-Report-Only
X-Xss-Protection
X-Generator
X-Cacheable
X-Cache-Status
X-Permitted-Cross-Domain-Policies
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Template
X-Language
X-Iinfo
X-Content-Security-Policy
Status
Content-Encoding
X-AspNetMvc-Version
X-Buckets
X-Request-ID
X-Kinja-Server-Push
Upgrade
Xkey
X-Via
Access-Control-Expose-Headers
X-Turbo-Charged-By
Access-Control-Max-Age
Keep-Alive
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Pass-Why
X-Age
EagleId
X-Backend
X-Envoy-Upstream-Service-Time
X-Robots-Tag
X-CDN
X-Amz-Request-Id
X-Amz-Id-2
X-Page-Speed
X-Pingback
X-Server-Powered-By
X-AH-Environment
X-Server
X-UA-Device
X-Proxy-Cache
X-Hacker
Request-Context
X-Swift-CacheTime
X-Swift-SaveTime
X-Nginx-Cache-Status
Grace
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-Cdn
X-LiteSpeed-Cache
P3p
Cf-Railgun
Server-Timing
Feature-Policy
X-Amz-Version-Id
X-Ua-Compatible
X-Device
X-Server-Id
X-WebKit-CSP
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
X-Rq
X-Ac
EagleEye-TraceId
X-Cnection
Report-To
Request-Id
X-Cloud-Trace-Context
X-Backend-Server
X-Response-Time
X-Node
Content-Location
X-Host
X-Readtime
X-Origin-Cache
X-Vhost
X-Cache-Lookup
X-Application-Context
X-DataDome
X-ORACLE-DMS-ECID
X-Dispatcher
NEL
X-ORACLE-DMS-RID
X-Ruxit-JS-Agent
X-Rack-Cache
X-HW
X-Origin-Upstream-Status
Surrogate-Control
X-Clacks-Overhead
Rating
X-Country-Code
X-Dns-Prefetch-Control
Allow
X-Country
X-FTR-Request-ID
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Url
X-DynaTrace
X-MS-InvokeApp
X-Goog-Hash
Fusion-Content-Source
X-Instart-Request-ID
Fusion-Content-Id
Fusion-Source
Fusion-Component-Id
Fusion-Template-Id
X-TTL
X-Vname
X-PC
X-TtlSet
X-Varnish-TTL
X-B3-TraceId
Pinterest-Generated-By
Verso
X-Powered-By-Plesk
X-Px
Public-Key-Pins
RTSS
Edge-Control
X-ESI
X-Mod-Pagespeed
SPRequestGuid
X-Middleton-Response
X-Middleton-Display
X-Sol
Display
Response
X-Akam-SW-Version
Accept-Ch-Lifetime
X-SharePointHealthScore
X-VARITI-CCR
X-D2id
X-Cdn-Fetch
X-Exp-Id
X-Kinja-Revision
X-Use-Magma
X-Kinja-Build
X-Kinja-Server
X-Kinja
X-GoogleNews-Bot
X-Exp-Variant
X-Ah-Environment
X-Recruiting
SPIisLatency
Service-Worker-Allowed
SPRequestDuration
X-Vcap-Request-Id
X-CST
X-Server-Name
X-GitHub-Request-Id
X-Version
MS-Author-Via
X-Navigation-Version
X-Powered-CMS
X-Abt-Application-Version
X-Trace
TCN
X-Debug
Charset
X-Shard
Fastly-Restarts
Nginx-Cache
X-Amz-Rid
Realpath
X-Amz-Server-Side-Encryption
X-Upstream
X-Aspnetmvc-Version
AR-ATIME
Ar-Sid
AR-PoweredBy
AR-CACHE
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-NF-Request-ID
X-Forwarded-Proto
Accept-CH
X-Ezoic-Cdn
Front-End-Https
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-RateLimit-Remaining
DynaTrace
X-MSEdge-Ref
Access-Control-Request-Method
X-Cached
Arr-Disable-Session-Affinity
Content-MD5
Pagespeed
X-Shield-Request-Id
X-B3-TraceId-Primal
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
MRF-Tech
Mrf-Cache-Status
MicrosoftSharePointTeamServices
AR-Request-ID
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Expires
X-DynaTrace-JS-Agent
S
X-Ser
X-Goog-Storage-Class
X-Fastly-Request-ID
X-T
X-Amz-Meta-S3cmd-Attrs
Accept-Ch
X-Id
X-FTR-DC
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Backend
X-FTR-Realm
X-Varnish-Age
X-VCache
Paypal-Debug-Id
X-XRDS-Location
ServerID
X-Via-JSL
X-Grace
X-Accel-Expires
X-Correlation-Id
X-Fastcgi-Cache
X-Vcache
X-Client-IP
Edge-Cache-Tag
X-Content-Type
X-Dw-Request-Base-Id
X-Forwarded-For
Fastcgi-Cache
X-Amzn-Trace-Id
X-Hits
X-Frontend
X-DIS-Request-ID
X-Content-Digest
Powered
Pinterest-Version
X-Pinterest-Rid
X-N
X-HS-Content-Id
X-HS-Hub-Id
X-Mobile-Rewrite
PB-PID
PB-RID
Arc-Version
X-FTR-Cache-Host
AMP-Access-Control-Allow-Source-Origin
X-Logged-In
Server-Name
TP-L2-Cache
TP-Cache
X-Kinsta-Cache
X-Request-Processing-Time
X-Request-Received
X-Cache-Hit
X-Server-ID
X-Microsite
X-Request-Handler-Origin-Region
X-Zen-Fury
X-AppVersion
X-Az
X-Activity-Id
X-LB-Cache
X-Cache-Age
X-Revision
X-IPLB-Instance
X-Rid
X-Type
Healthy
X-User-Agent
Retry-After
X-FastCGI-Cache
X-Srv
X-Whom
X-GUploader-UploadID
Backend-Timing
X-Analytics
Server-Node
X-B3-Sampled
X-Node-Name
X-Time
FilterID
X-NWS-LOG-UUID
Cache-Tag
X-Hp-Webp
Alternate-Protocol
X-RateLimit-Limit
Accept-Charset
X-F-Cache
NR-ENABLED
X-Akamai-Edgescape
X-Content-Security-Policy-Report-Only
X-SERVER
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Content-Options
Cache-Status
X-Cache-Rule
DC
X-Content-Powered-By
MS-CV
X-Tumblr-Pixel-0
X-FB-Debug
X-Tumblr-User
X-Framework
X-Tumblr-Pixel
X-AOL-HN
Refresh
X-Amz-Apigw-Id
Access-Control-Allow-Method
X-Cluster
X-Amzn-RequestId
X-Varnish-Grace
VIX-Pulpo-Node
X-Webkit-CSP
VIX-Pulpo-Upstream-Status
Source
X-Instance
X-App-Environment
X-Jobs
X-Cache-2
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Page-Id
X-PHP-Backend
Tracecode
X-Debug-Info
X-B
Actual-Object-TTL
X-Seen-By
X-Request-Guid
X-Mobile-URL
X-Forwarded-Host
Fastcgi-Useragent
Surrogate-Key
X-Cache-TTL
Host
Frame-Options
X-Cache-Operation
X-App-Server
X-Cache-Key
X-Cache-Control
X-Geo-Country
X-FW-Serve
X-FW-Server
X-FW-Hash
X-FW-Type
X-FW-Static
X-Cached-By
X-Pad
X-Element-Page-Cache
X-Host-Name
X-TA-CDN-Provider
X-XRDS-LOCATION
Cleartype
X-Hostname
X-B-Cache
X-Signature
Upgrade-Insecure-Requests
X-WebKit-CSP-Report-Only
X-Git-Hash
X-HS-Cache-Config
X-Mobile
X-ATG-Version
X-Varnish-Backend
Xserver
X-Response-Served-From
X-BCube-Filmed-By
NGB
X-Daa-Tunnel
X-UA-Device-Type
X-RemovedCookies
X-RTag
X-ProcessESI
X-GeoIP
Ms-Operation-Id
Cache-Tv-Group
X-Amz-Replication-Status
X-Handled-By
X-Origin-Server
X-TT
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
Filters
Eomportal-Instance
Webserver
WPE-Backend
X-Drupal-Cache-Tags
X-Cacheable-TTL
From-Origin
X-TX-ID
X-Adobe-Content
X-EdgeConnect-Cache-Status
GEO-INFO
X-Adobe-Loc
Payment
X-RequestSource
X-Wix-Request-Id
X-TT-TIMESTAMP
X-Presslabs-Stats
X-Cache-TTL-Remaining
Datacenter
X-Cache-Remote
X-Status
Cache
X-Hyper-Cache
X-FW-Dynamic
X-WA-Info
Liferay-Portal
X-Esi
X-Webkit-Csp
X-Region
X-Contextid
X-Cache-Action
Version
X-Edge-Location
X-Cache-NE
X-Akamai-Transformed
X-Content-Age
X-HS-Combine-CSS
Viewport
X-Ratelimit-Reset
X-Ttl
X-Acc-Meta-Resource-Type
X-Varnish-Hostname
X-Storage
X-B3-Traceid
X-Cache-Server
X-CF-Powered-By
PageSpeed
X-PressLabs-Stats
X-Varnish-Server
X-Cache-Enabled
Meta-Geo
X-Cache-Var-Map
X-Path-Route
X-ES-SERVER
X-Cache-Var
Host-Header
Load-Balancing
X-RN-RSRV
Accept-CH-Lifetime
X-IP
X-Xfnlog-Site
Country
X-Viewer-Country
X-Proxy
X-Oneagent-Js-Injection
X-Via-Fastly
X-CCM
X-PCL
DB-Nickname
X-Cache-Config
X-TNCMS
X-Accel-Buffering
X-Loop
X-OCL
Cache-Hits
X-Cache-Host
Rt-Fastcgi-Cache
X-Akamai-Request-ID2
X-Cache-Time
X-NCache
X-Proto
X-Labrador-Cache-Channel
X-Debug-Cache
Cache-Name
Cache-Tags
Release
X-UnsetCookies
X-Backend-TTL
X-From
Decoy-Debug-TTL
Ec-Rule-Version
Decoy-Debug-Status
X-Backend-Name
DSUID
TWC-Privacy
S-Rt
TWC-Device-Class
TWC-GeoIP-Country
X-CS
TWC-Connection-Speed
X-EIG-Tracking-Id
Selected-Fe
TWC-GeoIP-LatLong
TWC-Locale-Group
Webcakes-App-Version
X-FC-Vary-Parameters
Decoy-Debug-Key
Webcakes-App-Name
Vix-Hermes-Req-Id
Property-Id
X-Cache-Grace
S-Cnection
X-Varnish-Cache-Hits
X-Timing-Wait
X-Time-Microsecs
X-Trace-Id
X-Upgrade-Enabled
X-Varnish-Hits
X-Origin
X-Rule
X-Proxy-Build
X-NewRelic-App-Data
X-R9-Blue-Green-Version
X-Origin-Hint
X-Vgn-Hpd-Reason
Webcakes-Region
X-Www-Served-By
X-Hosted-By
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Human
X-Web-Node
X-JoinUs
Azure-SlotName
X-ApacheServer
X-Akamai-Request-ID
Azure-SiteName
Azure-Version
Azure-RegionName
X-VCT
X-Site-Version
X-Tumblr-Pixel-3
Mn-Server-Ip
Cache-Key
Ohc-File-Size
X-Locale
X-Drupal-Cache-Contexts
X-FireWall-Port
Azure-InstanceId
X-PERF
X-Generated
X-Origin-Response-Time
X-Device-Type
X-Real-IP
X-Section
X-Hit
X-Cluster-Node
X-Access
X-Format
X-OVcl-Cache
X-OVcl
Origin-Cache-Control
X-Pubstack
X-Rendered-As
Origin-Edge-Control
Server-Info
L5d-Success-Class
X-Trafficlayer-App-Name
X-S
X-Redis-Cache
X-Trafficlayer-App-Scope
Time
X-Origin-CC
Ohc-Cache-HIT
X-Origin-TTL
Now
X-NGENIX-Cache
X-FW-Version
X-Ua
Fastcgi-X-Cache-Version
Fastly-SSL
X-Litespeed-Cache
X-SS-Set-Cookie
OT-Force-Account-Verify
X-APP-VERSION
X-ServerID
X-Cluster-Name
Origin
X-Load-Cache
ServedBy
Mime-Version
X-Soup
Hostname
X-GoCache-CacheStatus
X-Sorting-Hat-ShopId
X-Upstream-CT
X-Shopify-Stage
Access-Control-Request-Headers
X-ShopId
X-Sorting-Hat-PodId
X-Rocket-Nginx-Bypass
X-Alternate-Cache-Key
X-Upstream-HT
X-ShardId
Cteonnt-Length
X-UUID
X-FB-TRIP-ID
X-App-Version
X-Guploader-Uploadid
X-Parent-Response-Time
X-Tec-Api-Origin
X-VG-WebCache
NtCoent-Length
X-Tec-Api-Root
X-Tec-Api-Version
Odigeo-Trace-Id
X-UA
X-Is-Bot
NGX
Accept-Language
X-VG-TLSProxy
X-Info
Machine
X-Uri
IBM-Web2-Location
X-Geo
Nel
X-BYPASS-REASON
X-ProxyCache-Key
X-ProxyCache-Status
X-Upstream-Proxy
X-Nc
X-B3-SpanId
X-ECACHE
X-Tb
X-No-Session
X-MServer
X-Node-Id
X-L-Path
X-Environment-Context
X-CACHE-KEY
Uber-Trace-Id
X-PHP-Host
X-Connection-Hash
Content-Style-Type
X-D
Cache-Prefix
X-Date
Proxy-Connection
Content-Script-Type
X-B3-Parentspanid
X-CF-Lambda-Fn
Fly-Cache
Fly-Request-Id
X-CF-Lambda-Version
X-Cms-Context
Cross-Origin-Window-Policy
X-Destination
Request-Time
X-VG-WebServer
AsisCache
X-Hl-Ver
X-Developer
X-Detected-As
A
X-DPWN-IS-SECURE
Xc-Version
X-G
X-External-Request-Id
Apple-News-Services-Handled
Apple-News-Services-Host
Arc-Country
X-Vtex-Processado-Em
X-PAYTM-SRV-ID
Apple-News-Services-Request-Url
X-Vtex-Remote-Cache
Apple-News-Services-Parsed-Url
X-Instart-Info
BehaviorPad-Version
GEO-REGION-INFO
X-Rojux
X-S-Cookie
X-A-Ccd
X-ScT
X-Rewrite-Enabled
X-A-Dam
X-Trv-Group
X-Request-UUID
X-Transaction
X-A
X-Server-Time
X-SRCache-Key
Rt-Proxy-Cache
T-Server
ServerName
Viewtype
VivaBuild
Rendered-Blocks
Request-Country
Request-EU
X-Twitter-Response-Tags
X-A-Dcw
Memcached
X-AIR-PT
Meta-Geo-Continent
X-A-Dgt
MD5-Digest
X-ARC
X-Application
X-B-Cookie
Mobile-Detection-Method
X-Aed
X-A-Wwc
Node
X-Accel-Expires-Debug
X-Region-Sid
X-Generated-By
X-Cdn-Forward
Srv
Backend-Name
X-Endurance-Cache-Level
User-Cache-Control
X-Tt-Trace-Tag
X-Block-Status
X-Cache-Bucket
IsBot
N-Cache
X-Cdn-Srv
X-SVT-ORM-VERSION
X-Clara-WADP
X-Via-CDN
X-Device-Os
X-Gen-Mode
X-Proxy-Cache-Status
X-Hnp-Log
X-Proxy-Upstream
X-SIPLIST1
CF-IPCountry
X-Has-Esi
X-Amzn-Remapped-Content-Length
X-WADP-Cache
X-Is-Gdpr
X-CSRF-TOKEN
X-SVT-ORM-RULES
X-S-Maxage
X-JWT-State
Mail-Subject
X-Dc
We-Hiring
X-Auto-Login
X-Amz-Meta-Cache-Control
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Urbn-Site-Id
X-Backend-Url
X-Owner
X-Cache-FS-Status
X-Cache-Id
X-Cache-Info
X-Platform-Server
X-Bip
X-Policy
X-Backend-Host
X-BBXSRF
X-User
X-Reqid
X-Sn-Servicetimems
X-Skip-Cache
X-Service
X-Thanos
True-Client-Country-4JS
Thinkindot-Control
X-Swa-Ws
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Web-Mar-Node
X-Server-IP
X-Release
X-Up
X-Reboot
X-Var-Ttl
X-Request-Start
X-Thinkindot-L3
X-TrackingId
X-Request-URI
X-Urbn-Context-Path
X-Old-Content-Length
X-Hash
X-Dispatch
X-Dispatcher-Server
X-Distributor
X-Developers
X-We-Are-Hiring
X-Irp-Debug
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-GeoIP-City
X-Geo-Header
X-Webstats-RespID
X-Svr
X-Generated-On
X-Worker
X-Fetched-On
X-Fastly-Cache
X-Generation-Time
X-ElasticPress-Search
X-WebServer
Server-Int
X-VServer
X-Clientip
X-Matched-Rule
X-Compress-Hint
X-Magnolia-Registration
X-NX-Host
X-Generated-In
X-VC-Cache
X-Origin-Expires
X-Origin-Date
X-Location
X-LI-UUID
X-Debug-Cache-Store
X-Level-Front-Cache
X-Debug-Cookies
X-Debug-Log
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-CUA
X-Li-Pop
X-Li-Fabric
X-Variation
X-Cdn-Origin
Pramga
Locale
CDCHOST
Content-Disposition
Countrycode
Platform
Gh-Request-Id
Adler-Geo
AKAMAI
Pagetype
PFcat
Kp-EeAlive
Is-Eu
Section-Io-Cache
Heartbleed
Served-By
Fastly-Soc-X-Request-Id
Server-Host
RNT-Machine
RNT-Time
X-B3-Spanid
X-NWS-UUID-VERIFY
Esi-Enabled
X-Cache-URL
Akamai-GRN
X-Core-Mission
X-CGP
X-Distil-CS
X-LI-Proto
SRV
X-ServiceProvider
X-SD-PageType
X-NC
X-Wikidot-Backend
X-Instart-Isnd
X-Wikidot-Static-Cache
X-SayCDN-TTL
X-Say-TTL
X-Key
X-Eu-Site
X-Lb-Id
X-Nginx-Cache-Key
X-Say-Cacheable
X-Qloud-Router
X-Epic-Correlation-Id
X-Method
Magicmarker
HA-Ipaddr
Wxu-Next-Commit
Resin-Trace
V-Age
L
X-Azure-Ref-OriginShield
X-Azure-Ref
Wxu-Next-Hostname
SD-X-WS
X-C
Ha-Gx-Prefs
Wxu-Next-Region
X-Ruxit-Js-Agent
X-Ratelimit-Limit
X-Microcachable
X-Nginx-Cache
X-Cache-Backend
X-MSEdge-Features
W
Server-ID
Fastly-SWR
X-MSEdge-Flight
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Scheme
X-App-Name
X-Internal-Host
X-Backend-State
Fastly-SIE
Cache-Provider
X-FPC
X-Servername
X-Processor
X-Be
Memory
REQUESTUUID
Group
X-NodeID
Cdn-Host
Cdn-Request-Time
X-Pjax-Url
X-GEO
X-Edge-Server
X-VWS-Id
X-Webapp-Samesite-None-Activated-N
X-AWS-Id
X-LJ-Flow-ID
X-DC
Cache-Host
X-GDPR
X-Ratelimit-Remaining
X-Hello
X-Org
X-Flog
X-Mode
X-ABtesting
X-Datadome
X-Request-Time
X-Ms-Request-Id
X-Server-W
X-Servedbyhost
SS
X-Ms-Version
X-Wa
X-Unique-ID
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Object-Type
X-Response-By
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
X-IPS-LoggedIn
X-CDN-Forward
Lfy
X-Page-Type
Country-Code
X-Session-Fingerprint
X-SN
X-Via-Ucdn
X-Cache-Debug
X-VCL-Version
X-Oracle-Dms-Rid
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-From
Cache-Cookie-Set-Idcheck
X-Zone
X-EC-Lua
X-Tb-Optimization-Total-Bytes-Saved
X-SRV
X-Ftr-Request-Id
PICS-Label
X-Agile-Id
X-Agile-Age
X-Agile
X-Dynatrace
X-7Graus-Varnish-XKeys
X-7Graus-Varnish-Cache-Control
X-HS-Status
Geoip-Latitude
X-Zipkin-Id
X-Routing-Service
X-Proxied
Geoip-City
X-COUNTRY
X-URL
X-CSRF-Token
X-Pf-Uncompressing
GeoIp-Country-Code
Powered-By-ChinaCache
UCS
X-GRACE
X-Fastly-Country-Code
X-Sedo-Request-Id
SN
Ttl
X-Cache-Miss-From
X-Logging-Id
Environment
X-APP
Proxy-Firewall
X-Logtrace-Id
Ajk
X-Sucuri-ID
X-Sucuri-Id
X-Varnish-Beresp-TTL
X-Unique-Id
X-Source
GeoIP-Latitude
GeoIP-Country-Code
X-PF-Uncompressing
GeoIP-City
X-MP-GENERATED-AT
XServer
X-Bc
X-Cache-Category-Id
Powered-By
X-ZONE
Cdn
X-Vcl-Version
M-TraceId
X-Ftr-Cache-Host
X-Newrelic-Synthetics
ProcessTime
X-Grey
X-Core-Value
X-RateLimit-Reset
X-CLOUD-TRACE-CONTEXT
X-LiteSpeed-Cache-Control
Pics-Label
X-Tt-Trace-Host
X-Check-Cacheable
X-Aicache-OS
X-Vdms-Version
X-HTML-Minification-Powered-By
Amp-Access-Control-Allow-Source-Origin
CACHE
Cf-Ipcountry
X-Edge
X-Sucuri-Cache
X-AK-Request-ID
CF-Cached-On
Cdnsip
Cdncip
Fastly-Backend-Name
X-TH-Server
X-Sigma-Backend
X-DataStream-Cache-Status
X-Planisys-CDN-TTL
WWW
Pragrma
X-ServedByHost
X-Shopify-Generated-Cart-Token
X-Fstrz
X-Planisys-CDN-Cache
X-Sigma
X-Rocket-Build-Number
X-Planisys-CDN-Rules
X-Ftr-Backend-Server
X-Ftr-Backend
X-Dynatrace-Js-Agent
X-Ftr-Dc
X-Ftr-Balancer
HostName
X-Ftr-Realm
X-Cache-Tag
Requestid
X-NGINX-Cache
X-Via-NSCOPI
X-Mid
X-RCS-CacheZone
X-WA
X-ORACLE-APMCS-TAG
X-SaId
MIME-Version
X-ORACLE-APMCS-REQUEST-ID
X-Fastly-Backend-Reqs
X-Swift-Error
X-MCACHE
X-FORWARDED-FOR
X-Varnish-Ttl
X-LAGOON
GW-Server
TTL
X-TT-LOGID
X-ND-Cache
X-Secret
X-Upstream-Ct
URI
X-Edge-O15-RID
X-Upstream-Ht
X-Gannett-Site-Version
LB
X-UPSTREAM-Address
Tcn
Lb
X-DW
X-DSS
X-DI
X-Action
X-Cache-Ttl
X-TIME
X-DB
X-DataStream-Origin-MEX-Latency
X-Refresh
Ohc-Response-Time
X-Trafficlayer-App-Version
X-PJAX-URL
X-DataStream-MidMile-RTT
X-RPS
X-BE
X-RPM
X-RSL
X-Varnish-Url
X-Litespeed-Cache-Control
X-BC
Dynatrace
X-WR-MODIFICATION
X-Served-From
X-CDN-Cache
X-Cf-Powered-By
X-Via-SSL
Host-ID
X-Varnish-Cacheable
RequestUuid
X-Via-Edge
On-Server
X-Correlation-ID
DataCenter
X-GeoIP-Country-Code
X-Gamma-Serve
X-Pod
X-Req
X-Flow-Id
X-Fastly-Cache-Hits
Server-Id
User-Agent
Is-Session-Tracking
Locid
Gannett-Cam-Experience-Id
X-Fpc
X-Proxy-Cacherz
X-Zalando-Child-Request-Id
Get-Access-Time
Xkeyrz
Xkeypdq
CDN
X-Page-Impression-Id
X-ATS-Timestamp
WZWS-RAY
FNAC-ModuleRouting
X-MID
Inserted-Into-Cache-At
X-Nananana
X-SB
X-HostName
X-VC
Warning
X-Dw-Trace-Id
Correlation-Id
X-ServerName
Cneonction
Thinkindot-Cache-Type
X-Amzn-Remapped-Date
X-MiniProfiler-Ids
V-Cache
X-Gdpr
X-Li-Proto
X-Bug-Bounty
X-Newrelic-App-Data
X-ECache
Processtime
X-LB-ID
RequestId
Xet-Cookie
X-Gen-Id
X-Akamai-ERRuleID
X-Akamai-ERPolicy
HitType
X-LiteSpeed-Tag
X-Amzn-Remapped-Connection