Threat Level: green Handler on Duty: Manuel Humberto Santander Pelaez

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
CF-RAY
CF-Cache-Status
Link
X-Powered-By
ETag
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Alt-Svc
Access-Control-Allow-Credentials
X-Runtime
X-Xss-Protection
X-FRAME-OPTIONS
X-Drupal-Cache
X-Adblock-Key
X-Check
Content-Security-Policy-Report-Only
X-Generator
X-Cacheable
X-Cache-Status
X-Permitted-Cross-Domain-Policies
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Template
X-Language
X-Iinfo
X-Content-Security-Policy
Content-Encoding
Status
X-Buckets
X-AspNetMvc-Version
X-Kinja-Server-Push
Xkey
Upgrade
X-Request-ID
X-Via
Access-Control-Expose-Headers
X-Turbo-Charged-By
Access-Control-Max-Age
Keep-Alive
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Pass-Why
X-Age
EagleId
X-Backend
X-Envoy-Upstream-Service-Time
X-Robots-Tag
X-Amz-Id-2
X-Amz-Request-Id
X-Ua-Compatible
X-Page-Speed
X-Pingback
X-Server-Powered-By
X-CDN
X-Server
X-UA-Device
X-Proxy-Cache
X-Hacker
X-AH-Environment
Request-Context
X-Nginx-Cache-Status
X-Swift-SaveTime
X-Swift-CacheTime
Grace
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-Cdn
X-LiteSpeed-Cache
P3p
Cf-Railgun
Server-Timing
Feature-Policy
X-Amz-Version-Id
X-Device
X-Server-Id
X-WebKit-CSP
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
X-Rq
X-Ac
X-Cnection
EagleEye-TraceId
Report-To
X-Cloud-Trace-Context
Request-Id
X-Backend-Server
X-Response-Time
X-Host
Content-Location
X-Node
X-Readtime
X-Origin-Cache
X-Vhost
X-Cache-Lookup
X-Application-Context
X-DataDome
X-ORACLE-DMS-ECID
X-Dispatcher
X-Ruxit-JS-Agent
NEL
X-ORACLE-DMS-RID
X-Rack-Cache
X-Origin-Upstream-Status
X-HW
Surrogate-Control
Rating
X-Clacks-Overhead
Allow
X-Country-Code
X-Dns-Prefetch-Control
X-Country
X-Url
X-FTR-Request-ID
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-DynaTrace
X-MS-InvokeApp
X-Instart-Request-ID
Fusion-Component-Id
Fusion-Template-Id
Fusion-Content-Source
Fusion-Source
Fusion-Content-Id
X-Goog-Hash
X-TtlSet
X-Vname
X-PC
X-Varnish-TTL
X-Ah-Environment
X-B3-TraceId
X-TTL
Verso
Pinterest-Generated-By
X-Powered-By-Plesk
X-Aspnetmvc-Version
X-Px
Public-Key-Pins
RTSS
Edge-Control
X-Mod-Pagespeed
SPRequestGuid
X-VARITI-CCR
X-Middleton-Response
X-Sol
X-Middleton-Display
Response
Display
X-Cdn-Fetch
X-SharePointHealthScore
X-Exp-Variant
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Kinja-Build
X-Kinja
X-Akam-SW-Version
X-GoogleNews-Bot
X-Exp-Id
X-D2id
X-ESI
X-Recruiting
X-CST
Service-Worker-Allowed
X-Vcap-Request-Id
Accept-Ch-Lifetime
SPRequestDuration
SPIisLatency
X-Server-Name
X-Version
X-Powered-CMS
TCN
X-GitHub-Request-Id
MS-Author-Via
X-Abt-Application-Version
X-Navigation-Version
X-Trace
X-Debug
Charset
X-Shard
Fastly-Restarts
Nginx-Cache
X-Amz-Rid
X-Amz-Server-Side-Encryption
X-Upstream
Accept-CH
Realpath
AR-ATIME
AR-CACHE
Ar-Sid
AR-PoweredBy
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-RateLimit-Remaining
X-Forwarded-Proto
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-NF-Request-ID
X-Ezoic-Cdn
Front-End-Https
X-Cached
X-MSEdge-Ref
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Metageneration
Arr-Disable-Session-Affinity
Access-Control-Request-Method
DynaTrace
Pagespeed
Content-MD5
X-Shield-Request-Id
AR-Request-ID
X-B3-TraceId-Primal
X-Mrf-Item-Lastmod
Mrf-Cache-Status
X-Mrf-Section-Lastmod
MRF-Tech
X-FTR-Cache-Status
MicrosoftSharePointTeamServices
X-FTR-Expires
X-Country-Code-Real
X-VCache
S
X-DynaTrace-JS-Agent
X-Amz-Meta-S3cmd-Attrs
X-Goog-Storage-Class
X-Fastly-Request-ID
X-T
X-FTR-Realm
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Balancer
X-FTR-DC
X-Ser
X-Id
X-XRDS-Location
Paypal-Debug-Id
X-Varnish-Age
ServerID
X-Via-JSL
X-Grace
Accept-Ch
X-Accel-Expires
X-Content-Type
X-Correlation-Id
X-Client-IP
Edge-Cache-Tag
X-Dw-Request-Base-Id
X-Forwarded-For
Fastcgi-Cache
X-Amzn-Trace-Id
X-Hits
X-Content-Digest
X-Frontend
X-DIS-Request-ID
Powered
AMP-Access-Control-Allow-Source-Origin
X-Fastcgi-Cache
X-N
X-Mobile-Rewrite
PB-RID
PB-PID
Arc-Version
X-FTR-Cache-Host
X-HS-Hub-Id
X-Vcache
X-HS-Content-Id
X-Pinterest-Rid
Pinterest-Version
Server-Name
X-Logged-In
TP-Cache
TP-L2-Cache
X-FastCGI-Cache
X-Request-Received
X-Request-Processing-Time
X-Kinsta-Cache
X-Microsite
X-Request-Handler-Origin-Region
X-Server-ID
X-Zen-Fury
X-Cache-Hit
X-LB-Cache
X-Time
X-Rid
X-AppVersion
X-Activity-Id
X-Type
X-IPLB-Instance
X-Az
X-Revision
X-Cache-Age
X-User-Agent
Healthy
X-GUploader-UploadID
Retry-After
X-Whom
Backend-Timing
X-Analytics
X-Srv
X-Node-Name
X-B3-Sampled
Server-Node
FilterID
X-NWS-LOG-UUID
X-RateLimit-Limit
Alternate-Protocol
X-Hp-Webp
Cache-Tag
Accept-Charset
X-F-Cache
X-Akamai-Edgescape
X-Content-Security-Policy-Report-Only
X-SERVER
Cache-Status
X-Cache-Rule
NR-ENABLED
X-Content-Options
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Cluster
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Amz-Apigw-Id
X-Amzn-RequestId
X-AOL-HN
X-FB-Debug
X-Jobs
X-Varnish-Grace
X-App-Environment
DC
X-Webkit-CSP
X-Content-Powered-By
X-Cache-2
Access-Control-Allow-Method
MS-CV
VIX-Pulpo-Upstream-Status
X-Instance
VIX-Pulpo-Node
X-Debug-Info
Tracecode
X-Page-Id
X-B
Refresh
X-Framework
Source
X-PHP-Backend
X-Cache-TTL
X-Request-Guid
Surrogate-Key
X-Seen-By
Actual-Object-TTL
X-Forwarded-Host
Host
X-App-Server
X-Mobile-URL
Fastcgi-Useragent
X-Cache-Operation
Frame-Options
X-Geo-Country
X-Cache-Key
X-FW-Serve
X-FW-Server
X-FW-Type
X-FW-Static
X-FW-Hash
X-Cache-Control
X-Cached-By
X-Pad
X-TA-CDN-Provider
X-Host-Name
X-Hostname
Cleartype
X-B-Cache
X-Signature
X-Element-Page-Cache
Upgrade-Insecure-Requests
X-BCube-Filmed-By
X-WebKit-CSP-Report-Only
X-Git-Hash
X-Response-Served-From
NGB
X-Varnish-Backend
X-Mobile
X-Esi
X-ATG-Version
Xserver
X-XRDS-LOCATION
X-HS-Cache-Config
X-GeoIP
X-UA-Device-Type
Webserver
X-Tumblr-Pixel-1
Filters
X-TT
Eomportal-Instance
X-Tumblr-Pixel-2
Cache-Tv-Group
WPE-Backend
X-Adobe-Content
GEO-INFO
X-RTag
X-Daa-Tunnel
Ms-Operation-Id
X-Amz-Replication-Status
X-EdgeConnect-Cache-Status
X-RemovedCookies
X-ProcessESI
X-Handled-By
X-Drupal-Cache-Tags
X-Adobe-Loc
X-Origin-Server
X-RequestSource
Payment
X-Cacheable-TTL
X-TX-ID
From-Origin
X-Ttl
X-TT-TIMESTAMP
X-Wix-Request-Id
X-Cache-TTL-Remaining
X-Presslabs-Stats
X-Cache-Remote
Datacenter
X-Status
Liferay-Portal
X-FW-Dynamic
Cache
X-WA-Info
X-Hyper-Cache
X-Region
X-Contextid
X-Cache-Action
X-Acc-Meta-Resource-Type
X-Edge-Location
Version
X-Content-Age
X-Ratelimit-Reset
Accept-CH-Lifetime
X-CF-Powered-By
X-Cache-NE
Viewport
X-Varnish-Hostname
X-HS-Combine-CSS
X-Akamai-Transformed
X-Storage
X-B3-Traceid
PageSpeed
X-Cache-Server
X-Varnish-Server
X-PressLabs-Stats
X-ES-SERVER
Load-Balancing
X-Path-Route
X-Cache-Var
X-RN-RSRV
Meta-Geo
X-Cache-Var-Map
Host-Header
X-Accel-Buffering
X-IP
Ohc-File-Size
Country
X-Xfnlog-Site
X-Proxy
X-Cache-Enabled
X-Viewer-Country
X-UnsetCookies
X-Debug-Cache
X-Via-Fastly
X-Cache-Config
X-CCM
X-Loop
X-TNCMS
Cache-Name
X-Tumblr-Pixel-3
DB-Nickname
X-Device-Type
Rt-Fastcgi-Cache
X-Proto
Cache-Tags
X-Yottaa-Optimizations
Ec-Rule-Version
X-Yottaa-Metrics
X-PCL
X-Upgrade-Enabled
X-EIG-Tracking-Id
DSUID
X-Rule
X-FC-Vary-Parameters
X-Backend-TTL
X-Origin
X-CS
Selected-Fe
S-Rt
Release
Webcakes-App-Version
Property-Id
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-LatLong
X-Cache-Host
TWC-GeoIP-Country
TWC-Privacy
X-From
X-Labrador-Cache-Channel
Vix-Hermes-Req-Id
X-Origin-Hint
Webcakes-Region
X-OCL
X-Varnish-Cache-Hits
X-Cache-Time
X-Akamai-Request-ID2
TWC-Locale-Group
X-JoinUs
X-Proxy-Build
X-NCache
X-Timing-Wait
X-Hosted-By
X-Backend-Name
Webcakes-App-Name
X-Web-Node
X-Varnish-Hits
X-Time-Microsecs
X-Human
X-Vgn-Hpd-Reason
Decoy-Debug-Key
Azure-SlotName
Azure-Version
X-VCT
Cache-Hits
X-Akamai-Request-ID
X-Drupal-Cache-Contexts
Decoy-Debug-TTL
Decoy-Debug-Status
X-FireWall-Port
X-Cache-Grace
X-Generated
X-Goog-Meta-Goog-Reserved-File-Mtime
X-NewRelic-App-Data
Azure-SiteName
Mn-Server-Ip
Azure-RegionName
X-Origin-Response-Time
X-R9-Blue-Green-Version
S-Cnection
Azure-InstanceId
X-ApacheServer
X-Section
X-PERF
X-Hit
X-Access
X-Www-Served-By
X-Rendered-As
X-OVcl
X-Format
X-OVcl-Cache
X-Cluster-Node
X-Real-IP
Time
Ohc-Cache-HIT
X-Trace-Id
X-Locale
Cache-Key
X-S
X-Site-Version
Server-Info
X-Ua
Origin-Cache-Control
Origin-Edge-Control
X-Pubstack
X-NGENIX-Cache
L5d-Success-Class
X-Redis-Cache
X-Trafficlayer-App-Scope
X-Trafficlayer-App-Name
X-FW-Version
Now
Fastcgi-X-Cache-Version
X-SS-Set-Cookie
Fastly-SSL
OT-Force-Account-Verify
X-Litespeed-Cache
X-Upstream-HT
X-APP-VERSION
X-Upstream-CT
X-ServerID
X-Origin-CC
X-Origin-TTL
X-Cluster-Name
Cteonnt-Length
Access-Control-Request-Headers
X-Load-Cache
X-Sorting-Hat-PodId
X-Shopify-Stage
Hostname
X-Sorting-Hat-ShopId
X-FB-TRIP-ID
X-ShopId
X-ShardId
Origin
Mime-Version
X-Alternate-Cache-Key
X-UUID
X-GoCache-CacheStatus
X-Rocket-Nginx-Bypass
ServedBy
X-Parent-Response-Time
X-Soup
X-VG-WebCache
X-Tec-Api-Origin
X-Tec-Api-Root
X-App-Version
X-Webkit-Csp
X-Tec-Api-Version
X-VG-TLSProxy
Accept-Language
X-Is-Bot
NtCoent-Length
X-Upstream-Proxy
Machine
Odigeo-Trace-Id
X-Uri
NGX
IBM-Web2-Location
X-No-Session
X-Tb
Nel
X-Info
X-L-Path
X-Environment-Context
X-ProxyCache-Status
X-Guploader-Uploadid
X-BYPASS-REASON
X-MServer
X-ProxyCache-Key
X-ECACHE
X-Node-Id
X-B3-SpanId
X-UA
X-CACHE-KEY
X-Geo
X-CSRF-TOKEN
Apple-News-Services-Host
Apple-News-Services-Handled
X-Region-Sid
Uber-Trace-Id
X-PAYTM-SRV-ID
A
X-Rewrite-Enabled
X-ScT
X-S-Cookie
X-Destination
X-Server-Time
X-Application
X-Rojux
X-Aed
X-Request-UUID
X-A-Dgt
X-A-Wwc
X-Accel-Expires-Debug
Apple-News-Services-Parsed-Url
X-A-Dcw
AsisCache
Node
X-G
Rendered-Blocks
Mobile-Detection-Method
Meta-Geo-Continent
MD5-Digest
Memcached
Request-Country
Request-EU
X-DPWN-IS-SECURE
T-Server
Viewtype
ServerName
VivaBuild
X-External-Request-Id
Rt-Proxy-Cache
X-Developer
X-Hl-Ver
Cache-Prefix
X-A-Ccd
Content-Script-Type
X-A-Dam
BehaviorPad-Version
Arc-Country
X-ARC
Content-Style-Type
Cross-Origin-Window-Policy
X-Detected-As
X-Instart-Info
GEO-REGION-INFO
Fly-Request-Id
X-A
Fly-Cache
Apple-News-Services-Request-Url
X-AIR-PT
X-Transaction
X-Connection-Hash
CF-IPCountry
Xc-Version
X-B-Cookie
X-Twitter-Response-Tags
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Vtex-Processado-Em
X-VG-WebServer
Request-Time
X-SRCache-Key
Proxy-Connection
X-Cms-Context
X-Trv-Group
X-D
X-Vtex-Remote-Cache
X-Date
Backend-Name
X-Oneagent-Js-Injection
X-Endurance-Cache-Level
X-Nc
X-Tt-Trace-Tag
Srv
X-Has-Esi
X-Device-Os
X-Cdn-Srv
X-PHP-Host
N-Cache
X-WADP-Cache
X-Generated-By
IsBot
X-Nginx-Cache
We-Hiring
X-Worker
X-JWT-State
X-B3-Parentspanid
X-Clara-WADP
Mail-Subject
X-SIPLIST1
X-S-Maxage
X-Cache-Bucket
X-NC
X-Is-Gdpr
X-Amzn-Remapped-Content-Length
User-Cache-Control
X-Via-CDN
Is-Eu
Fastly-Soc-X-Request-Id
X-Hash
X-IN-APIGATEWAYSSL
Gh-Request-Id
X-CUA
X-IN-APIGATEWAY
X-Irp-Debug
Platform
X-Dispatch
X-Ratelimit-Limit
RNT-Time
Section-Io-Cache
Served-By
X-WebServer
X-Distributor
Server-Host
RNT-Machine
X-Compress-Hint
Pagetype
X-Generation-Time
X-Developers
X-Block-Status
X-Fetched-On
X-We-Are-Hiring
X-Fastly-Cache
X-Cache-FS-Status
X-Debug-Log
X-Reqid
X-Debug-Cache-Expiry
X-Request-Start
X-Proxy-Cache-Status
X-Release
X-NX-Host
X-Reboot
X-TrackingId
X-Backend-Host
X-SVT-ORM-VERSION
X-B3-Spanid
X-SVT-ORM-RULES
X-Debug-Cache-Store
X-Skip-Cache
X-Auto-Login
X-Request-URI
X-Clientip
X-Server-IP
X-Dispatcher-Server
X-Proxy-Upstream
X-Debug-Cache-Fetch
X-Amz-Meta-Cache-Control
X-Variation
X-Platform-Server
X-Backend-Url
X-LI-UUID
X-Debug-Cookies
X-Location
X-Li-Pop
Content-Disposition
Countrycode
X-Li-Fabric
X-BBXSRF
X-Cache-Info
X-Hnp-Log
X-Magnolia-Registration
X-Origin-Date
Adler-Geo
X-Origin-Expires
X-Webstats-RespID
X-Var-Ttl
X-Old-Content-Length
X-ElasticPress-Search
X-Up
X-User
X-Gen-Mode
Akamai-GRN
X-Cdn-Forward
X-Core-Mission
X-Owner
X-Cdn-Origin
X-Cache-Id
Web-Mar-Node
True-Client-Country-4JS
X-Generated-In
X-Thanos
X-RateLimit-Limit-Second
X-Policy
X-Matched-Rule
X-VC-Cache
Thinkindot-Control
CDCHOST
X-Wikidot-Static-Cache
X-Wikidot-Backend
Kp-EeAlive
Locale
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
Server-Int
X-RateLimit-Remaining-Second
X-Say-Cacheable
X-Key
X-Level-Front-Cache
X-LI-Proto
X-Nginx-Cache-Key
X-GeoIP-City
X-Geo-Header
X-Epic-Correlation-Id
X-Eu-Site
X-Generated-On
X-Svr
X-VServer
X-SD-PageType
X-Service
X-Say-TTL
X-SayCDN-TTL
X-Sn-Servicetimems
X-Urbn-Site-Id
X-Urbn-Context-Path
X-Thinkindot-L3
X-Distil-CS
X-Bip
Wxu-Next-Hostname
Wxu-Next-Region
Ha-Gx-Prefs
Wxu-Next-Commit
X-Dc
Pramga
Esi-Enabled
Heartbleed
SD-X-WS
X-Azure-Ref
Magicmarker
AKAMAI
X-CGP
HA-Ipaddr
X-C
PFcat
X-Azure-Ref-OriginShield
SRV
X-NWS-UUID-VERIFY
X-Microcachable
L
X-Cache-URL
Fastly-SWR
X-Method
X-MSEdge-Features
X-MSEdge-Flight
X-Servername
Fastly-SIE
Cache-Provider
V-Age
Resin-Trace
X-Lb-Id
X-Qloud-Router
X-Internal-Host
Memory
X-Rebelmouse-Cache-Control
X-Swa-Ws
Server-ID
X-Rebelmouse-Surrogate-Control
W
X-Backend-State
X-App-Name
X-ServiceProvider
X-Instart-Isnd
X-FPC
X-Cache-Backend
X-GEO
X-Scheme
X-DC
X-Processor
Cdn-Host
X-VWS-Id
Cdn-Request-Time
X-Edge-Server
X-LJ-Flow-ID
X-AWS-Id
X-Be
X-GDPR
REQUESTUUID
X-Mode
X-Org
X-Request-Time
Group
X-Wa
X-NodeID
X-ABtesting
X-Hello
X-Pjax-Url
X-Servedbyhost
X-Flog
SS
X-Datadome
Cache-Host
X-Response-By
X-Server-W
X-CDN-Forward
X-IPS-LoggedIn
Country-Code
X-Oss-Request-Id
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
X-Unique-ID
X-Oss-Storage-Class
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-From
X-SN
X-Ms-Version
X-Ms-Request-Id
X-VCL-Version
Cache-Cookie-Set-Lfrom
X-Page-Type
X-Ratelimit-Remaining
X-Ruxit-Js-Agent
X-Session-Fingerprint
X-Oracle-Dms-Rid
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
PICS-Label
X-Proxied
X-EC-Lua
X-Zipkin-Id
X-Routing-Service
X-Zone
UCS
X-Ftr-Request-Id
X-Via-Ucdn
X-HS-Status
X-SRV
Lfy
X-Tb-Optimization-Total-Bytes-Saved
X-Cache-Debug
X-Dynatrace
Ttl
X-URL
X-COUNTRY
Powered-By-ChinaCache
X-Webapp-Samesite-None-Activated-N
X-DataStream-Cache-Status
X-GRACE
X-7Graus-Varnish-Cache-Control
Geoip-Latitude
GeoIp-Country-Code
SN
Geoip-City
Ajk
X-Agile
X-Agile-Age
X-Agile-Id
X-7Graus-Varnish-XKeys
X-Pf-Uncompressing
X-Logtrace-Id
X-MP-GENERATED-AT
X-RateLimit-Reset
X-Varnish-Beresp-TTL
X-CSRF-Token
GeoIP-Latitude
GeoIP-City
X-Fastly-Country-Code
X-Sedo-Request-Id
Environment
GeoIP-Country-Code
X-Cache-Miss-From
Proxy-Firewall
X-Unique-Id
ProcessTime
X-Source
X-Sucuri-Id
X-Grey
X-Logging-Id
X-ZONE
X-Cache-Category-Id
X-PF-Uncompressing
X-APP
X-Newrelic-Synthetics
Powered-By
X-Bc
X-HTML-Minification-Powered-By
X-NODE
XServer
X-Sucuri-ID
Cdn
X-Ftr-Cache-Host
X-CLOUD-TRACE-CONTEXT
X-Vcl-Version
X-Tt-Trace-Host
X-Core-Value
X-TH-Server
X-Check-Cacheable
M-TraceId
X-LiteSpeed-Cache-Control
CF-Cached-On
X-Edge
X-DataStream-Origin-MEX-Latency
Fastly-Backend-Name
Pics-Label
CACHE
X-DataStream-MidMile-RTT
X-Vdms-Version
X-Aicache-OS
WWW
X-AK-Request-ID
Cf-Ipcountry
Cdncip
Cdnsip
X-Swift-Error
X-Ftr-Backend-Server
X-Ftr-Dc
X-Ftr-Backend
X-Ftr-Balancer
X-Dynatrace-Js-Agent
HostName
X-Ftr-Realm
X-Fstrz
Pragrma
X-Rocket-Build-Number
X-Sigma-Backend
X-Shopify-Generated-Cart-Token
Requestid
X-RCS-CacheZone
X-Mid
GW-Server
X-Sigma
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Sucuri-Cache
X-Fastly-Backend-Reqs
MIME-Version
X-MCACHE
X-Varnish-Ttl
LB
X-LAGOON
X-FORWARDED-FOR
X-ServedByHost
X-Cache-Tag
Amp-Access-Control-Allow-Source-Origin
X-ORACLE-APMCS-TAG
X-SaId
X-UPSTREAM-Address
X-WA
X-BE
Ohc-Response-Time
X-Via-NSCOPI
X-NGINX-Cache
X-ORACLE-APMCS-REQUEST-ID
X-Secret
X-BC
X-Litespeed-Cache-Control
X-Gannett-Site-Version
X-TT-LOGID
X-Varnish-Url
URI
Lb
X-DI
X-DSS
TTL
X-RPS
X-RPM
X-DW
X-Action
X-RSL
X-DB
X-PJAX-URL
X-Cache-Ttl
X-ND-Cache
X-CDN-Cache
X-Upstream-Ct
X-Upstream-Ht
Dynatrace
X-Varnish-Cacheable
X-Trafficlayer-App-Version
Host-ID
On-Server
RequestUuid
X-WR-MODIFICATION
X-GeoIP-Country-Code
X-Refresh
WZWS-RAY
DataCenter
X-Correlation-ID
X-Via-Edge
X-Via-SSL
Server-Id
CDN
Get-Access-Time
Is-Session-Tracking
Xkeypdq
X-Fastly-Cache-Hits
X-Page-Impression-Id
X-Flow-Id
Xkeyrz
X-Fpc
Inserted-Into-Cache-At
X-Zalando-Child-Request-Id
User-Agent
X-Proxy-Cacherz
X-Nananana
X-Served-From
X-SB
Warning
X-VC
X-MID
Locid
Correlation-Id
X-Pod
X-Dw-Trace-Id
X-Req
Gannett-Cam-Experience-Id
X-Gamma-Serve
X-Akamai-SSL-Client-Sid
X-Cf-Powered-By
Thinkindot-Cache-Type
X-Li-Proto
FNAC-ModuleRouting
X-Request-URL
X-Akamai-ERPolicy
X-Amzn-Remapped-Date
X-NU-AKA-ACS-Version
X-Akamai-ERRuleID
X-Amzn-Remapped-Connection
X-LiteSpeed-Tag
X-MiniProfiler-Ids
X-Newrelic-App-Data
RequestId
Cneonction
Xet-Cookie
V-Cache
X-Gdpr
X-LB-ID
X-ServerName
Who
X-ECache
Processtime
X-Gen-Id
HitType
X-Crawler
X-Bug-Bounty
SID