Threat Level: green Handler on Duty: Manuel Humberto Santander Pelaez

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
CF-RAY
CF-Cache-Status
Link
X-Powered-By
ETag
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Alt-Svc
Access-Control-Allow-Credentials
X-Runtime
X-Xss-Protection
X-Drupal-Cache
X-Adblock-Key
X-Check
Content-Security-Policy-Report-Only
X-Generator
X-Cacheable
X-Cache-Status
X-Permitted-Cross-Domain-Policies
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Template
X-Language
X-Iinfo
Content-Encoding
X-Content-Security-Policy
Status
X-FRAME-OPTIONS
X-AspNetMvc-Version
X-Buckets
X-Request-ID
X-Kinja-Server-Push
Xkey
Upgrade
X-Via
Access-Control-Expose-Headers
X-Turbo-Charged-By
Access-Control-Max-Age
Keep-Alive
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Pass-Why
X-Age
EagleId
X-Backend
X-Envoy-Upstream-Service-Time
X-Robots-Tag
X-Ua-Compatible
X-Amz-Request-Id
X-Amz-Id-2
X-Page-Speed
X-CDN
X-Pingback
X-Server-Powered-By
X-AH-Environment
X-Server
X-UA-Device
X-Proxy-Cache
X-Hacker
Request-Context
X-Nginx-Cache-Status
X-Swift-CacheTime
X-Swift-SaveTime
Grace
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-Cdn
P3p
X-LiteSpeed-Cache
Cf-Railgun
Server-Timing
Feature-Policy
X-Amz-Version-Id
X-Device
X-WebKit-CSP
X-Server-Id
X-OneAgent-JS-Injection
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Rq
X-Ac
EagleEye-TraceId
X-Cnection
Report-To
X-Cloud-Trace-Context
X-Response-Time
Request-Id
X-Backend-Server
X-Host
Content-Location
X-Node
X-Readtime
X-Origin-Cache
X-Vhost
X-Cache-Lookup
X-Application-Context
X-ORACLE-DMS-ECID
X-DataDome
X-Dispatcher
NEL
X-ORACLE-DMS-RID
X-Ruxit-JS-Agent
X-Origin-Upstream-Status
X-Rack-Cache
X-HW
Surrogate-Control
X-Dns-Prefetch-Control
Rating
X-Country-Code
X-Clacks-Overhead
Allow
X-Country
X-FTR-Request-ID
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Url
X-DynaTrace
X-Instart-Request-ID
X-MS-InvokeApp
Fusion-Component-Id
Fusion-Content-Id
Fusion-Template-Id
Fusion-Source
Fusion-Content-Source
X-Goog-Hash
X-TTL
X-PC
X-TtlSet
X-Vname
X-Varnish-TTL
X-B3-TraceId
Pinterest-Generated-By
Verso
X-Powered-By-Plesk
Public-Key-Pins
X-Px
RTSS
Accept-Ch-Lifetime
Edge-Control
X-Mod-Pagespeed
X-ESI
Display
X-Middleton-Display
X-Sol
Response
X-Middleton-Response
X-Ah-Environment
X-VARITI-CCR
X-Use-Magma
X-Kinja-Server
SPRequestGuid
X-D2id
X-Kinja-Build
X-Kinja-Revision
X-Kinja
X-GoogleNews-Bot
X-Exp-Id
X-Exp-Variant
X-Cdn-Fetch
X-SharePointHealthScore
X-Recruiting
X-Akam-SW-Version
X-CST
Service-Worker-Allowed
X-Vcap-Request-Id
SPRequestDuration
SPIisLatency
X-Version
X-Server-Name
X-GitHub-Request-Id
TCN
X-Abt-Application-Version
X-Powered-CMS
X-Navigation-Version
MS-Author-Via
X-Trace
Charset
X-Shard
X-Debug
Fastly-Restarts
Nginx-Cache
X-Aspnetmvc-Version
Realpath
X-Amz-Rid
X-Amz-Server-Side-Encryption
X-Upstream
X-RateLimit-Remaining
AR-ATIME
Ar-Sid
AR-PoweredBy
AR-CACHE
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Forwarded-Proto
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Ezoic-Cdn
X-NF-Request-ID
Accept-CH
Front-End-Https
X-Cached
X-Goog-Generation
X-Goog-Stored-Content-Length
X-MSEdge-Ref
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
DynaTrace
Arr-Disable-Session-Affinity
Pagespeed
Access-Control-Request-Method
X-Shield-Request-Id
Content-MD5
AR-Request-ID
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Mrf-Item-Lastmod
MRF-Tech
X-VCache
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Expires
MicrosoftSharePointTeamServices
Accept-Ch
X-XRDS-Location
S
X-Amz-Meta-S3cmd-Attrs
X-T
X-DynaTrace-JS-Agent
X-Goog-Storage-Class
X-Id
Paypal-Debug-Id
X-Fastly-Request-ID
X-FTR-DC
X-FTR-Realm
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-Backend
X-Varnish-Age
X-Ser
ServerID
X-Via-JSL
X-Server-ID
X-Client-IP
X-Content-Type
X-Accel-Expires
X-Dw-Request-Base-Id
X-Forwarded-For
Edge-Cache-Tag
X-Amzn-Trace-Id
X-Hits
X-Grace
X-Correlation-Id
Fastcgi-Cache
Powered
X-Content-Digest
X-Frontend
X-DIS-Request-ID
X-N
X-Mobile-Rewrite
PB-RID
Arc-Version
PB-PID
X-FTR-Cache-Host
X-HS-Hub-Id
X-HS-Content-Id
X-Vcache
X-Pinterest-Rid
AMP-Access-Control-Allow-Source-Origin
Pinterest-Version
X-Fastcgi-Cache
Server-Name
X-Logged-In
X-FastCGI-Cache
TP-Cache
TP-L2-Cache
X-Request-Received
X-Request-Processing-Time
X-Kinsta-Cache
X-Request-Handler-Origin-Region
X-Microsite
X-Cache-Hit
X-Zen-Fury
X-Time
X-Type
Healthy
X-Az
X-Activity-Id
X-IPLB-Instance
X-AppVersion
X-Revision
X-LB-Cache
X-Rid
Backend-Timing
X-User-Agent
X-Analytics
X-Cache-Age
Retry-After
X-GUploader-UploadID
X-Whom
X-Srv
X-B3-Sampled
X-Node-Name
Server-Node
FilterID
X-RateLimit-Limit
X-NWS-LOG-UUID
X-Hp-Webp
Alternate-Protocol
Cache-Tag
X-SERVER
Accept-Charset
X-F-Cache
Cache-Status
X-Akamai-Edgescape
X-Content-Security-Policy-Report-Only
X-Webkit-CSP
X-Cache-Rule
X-Content-Options
NR-ENABLED
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Content-Powered-By
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Cache-2
DC
X-Instance
X-Cluster
VIX-Pulpo-Node
X-Amzn-RequestId
X-FB-Debug
MS-CV
VIX-Pulpo-Upstream-Status
X-Debug-Info
X-AOL-HN
X-Amz-Apigw-Id
Tracecode
X-Jobs
Access-Control-Allow-Method
X-App-Environment
X-Varnish-Grace
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-B
X-Forwarded-Host
Refresh
X-PHP-Backend
X-Page-Id
X-Framework
Surrogate-Key
Source
Fastcgi-Useragent
X-Cache-TTL
Actual-Object-TTL
X-App-Server
Host
X-Seen-By
X-Request-Guid
X-Cache-Operation
X-Mobile-URL
X-FW-Type
Frame-Options
X-FW-Static
X-FW-Serve
X-FW-Server
X-FW-Hash
X-Geo-Country
X-TA-CDN-Provider
X-Cache-Control
X-Hostname
Cleartype
X-Pad
X-Host-Name
X-Cached-By
X-Cache-Key
X-B-Cache
X-Signature
Upgrade-Insecure-Requests
X-Git-Hash
X-BCube-Filmed-By
X-Element-Page-Cache
X-Mobile
X-WebKit-CSP-Report-Only
NGB
X-Response-Served-From
X-Varnish-Backend
X-ATG-Version
Xserver
X-ProcessESI
WPE-Backend
X-RemovedCookies
X-GeoIP
X-UA-Device-Type
Filters
Eomportal-Instance
GEO-INFO
X-HS-Cache-Config
X-Handled-By
X-Drupal-Cache-Tags
Cache-Tv-Group
X-TT
X-Daa-Tunnel
Webserver
X-RequestSource
Ms-Operation-Id
X-RTag
X-Amz-Replication-Status
From-Origin
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
X-Cacheable-TTL
X-Adobe-Content
X-Origin-Server
Payment
X-Adobe-Loc
X-EdgeConnect-Cache-Status
X-TX-ID
X-TT-TIMESTAMP
X-XRDS-LOCATION
X-Cache-Remote
X-Wix-Request-Id
X-Cache-TTL-Remaining
X-Status
X-Presslabs-Stats
X-FW-Dynamic
Datacenter
X-Esi
Liferay-Portal
Cache
X-WA-Info
X-Acc-Meta-Resource-Type
X-Hyper-Cache
X-Region
X-Cache-Action
X-Ratelimit-Reset
Version
X-Edge-Location
X-Contextid
X-Ttl
X-Content-Age
Viewport
X-Cache-NE
X-B3-Traceid
X-CF-Powered-By
X-Varnish-Hostname
X-PressLabs-Stats
X-Akamai-Transformed
PageSpeed
X-Storage
X-Cache-Server
X-HS-Combine-CSS
X-Varnish-Server
Ohc-File-Size
X-Accel-Buffering
Meta-Geo
X-Cache-Var-Map
X-Cache-Var
Load-Balancing
X-RN-RSRV
X-Path-Route
X-ES-SERVER
X-IP
X-Xfnlog-Site
Host-Header
Country
X-Via-Fastly
X-Viewer-Country
Cache-Tags
X-Origin
X-TNCMS
X-CCM
X-Proxy
X-Section
X-UnsetCookies
X-Proto
X-Varnish-Cache-Hits
X-Yottaa-Metrics
Vix-Hermes-Req-Id
X-Upgrade-Enabled
X-Cache-Config
X-Origin-Hint
X-Debug-Cache
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-Country
Rt-Fastcgi-Cache
Release
Cache-Name
DB-Nickname
Property-Id
TWC-GeoIP-LatLong
TWC-Locale-Group
X-Cache-Time
X-Device-Type
X-Loop
X-Cache-Enabled
X-Access
TWC-Privacy
Webcakes-App-Version
Webcakes-Region
X-Yottaa-Optimizations
Webcakes-App-Name
X-Tumblr-Pixel-3
X-Backend-TTL
X-Backend-Name
X-Www-Served-By
X-VCT
X-Cluster-Node
DSUID
X-Akamai-Request-ID2
X-CS
X-Cache-Grace
X-Cache-Host
S-Rt
Mn-Server-Ip
Ec-Rule-Version
Selected-Fe
X-PCL
X-Akamai-Request-ID
X-Labrador-Cache-Channel
X-OCL
X-EIG-Tracking-Id
X-Drupal-Cache-Contexts
X-NCache
Cache-Hits
X-JoinUs
X-NGENIX-Cache
X-Vgn-Hpd-Reason
X-Proxy-Build
X-Origin-Response-Time
X-Human
X-Hosted-By
X-Format
X-R9-Blue-Green-Version
S-Cnection
X-Timing-Wait
X-From
X-Time-Microsecs
X-Site-Version
X-Trace-Id
X-Locale
X-Generated
X-FireWall-Port
X-ApacheServer
X-Hit
X-FC-Vary-Parameters
X-Goog-Meta-Goog-Reserved-File-Mtime
X-PERF
Azure-InstanceId
Azure-SiteName
Azure-RegionName
Azure-SlotName
X-Web-Node
X-Varnish-Hits
Ohc-Cache-HIT
Azure-Version
Decoy-Debug-Status
X-Ua
Decoy-Debug-Key
X-NewRelic-App-Data
Decoy-Debug-TTL
X-S
X-Real-IP
Cache-Key
X-Rule
X-Rendered-As
Time
X-OVcl
X-OVcl-Cache
X-Pubstack
L5d-Success-Class
Server-Info
Origin-Edge-Control
Origin-Cache-Control
X-Redis-Cache
X-Trafficlayer-App-Scope
X-Trafficlayer-App-Name
X-FW-Version
Now
Accept-CH-Lifetime
X-SS-Set-Cookie
X-Litespeed-Cache
X-Upstream-HT
Fastcgi-X-Cache-Version
X-Upstream-CT
OT-Force-Account-Verify
Fastly-SSL
X-Origin-CC
X-Origin-TTL
ServedBy
Mime-Version
X-ServerID
X-Cluster-Name
X-APP-VERSION
Access-Control-Request-Headers
X-Shopify-Stage
X-ShopId
X-ShardId
X-Load-Cache
Origin
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-FB-TRIP-ID
X-App-Version
X-UUID
X-Alternate-Cache-Key
Cteonnt-Length
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
X-Parent-Response-Time
Hostname
X-CACHE-KEY
X-VG-WebCache
X-Soup
X-VG-TLSProxy
X-GoCache-CacheStatus
X-Rocket-Nginx-Bypass
X-Upstream-Proxy
NtCoent-Length
Accept-Language
Machine
X-Is-Bot
X-Uri
X-Tb
Nel
X-ECACHE
IBM-Web2-Location
Odigeo-Trace-Id
NGX
X-No-Session
X-CSRF-TOKEN
X-Guploader-Uploadid
X-BYPASS-REASON
X-ProxyCache-Status
X-L-Path
X-Node-Id
X-Nc
X-ProxyCache-Key
X-MServer
X-Environment-Context
X-Oneagent-Js-Injection
X-Info
X-Tt-Trace-Tag
X-SRCache-Key
Uber-Trace-Id
X-Server-Time
X-Region-Sid
X-A-Dgt
X-A-Dcw
X-A-Wwc
X-Accel-Expires-Debug
X-AIR-PT
X-Aed
X-A-Dam
X-A-Ccd
T-Server
X-Instart-Info
Viewtype
VivaBuild
X-A
X-Hl-Ver
X-Application
X-ARC
X-Destination
X-Date
X-Detected-As
X-Developer
X-External-Request-Id
X-DPWN-IS-SECURE
X-D
X-Connection-Hash
X-CF-Lambda-Fn
X-B-Cookie
X-CF-Lambda-Version
X-G
X-Cms-Context
ServerName
Rt-Proxy-Cache
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Arc-Country
AsisCache
Cache-Prefix
BehaviorPad-Version
Apple-News-Services-Host
Apple-News-Services-Handled
X-Rojux
X-S-Cookie
X-Rewrite-Enabled
X-Request-UUID
A
X-PAYTM-SRV-ID
Content-Script-Type
Mobile-Detection-Method
Meta-Geo-Continent
Node
Rendered-Blocks
Request-EU
Request-Country
Memcached
MD5-Digest
Cross-Origin-Window-Policy
Content-Style-Type
Fly-Cache
Fly-Request-Id
GEO-REGION-INFO
X-ScT
X-B3-Parentspanid
Xc-Version
X-Transaction
X-Twitter-Response-Tags
X-Vtex-Processado-Em
X-Nginx-Cache
X-VG-WebServer
X-Worker
Request-Time
Proxy-Connection
X-Vtex-Remote-Cache
X-Trv-Group
X-B3-SpanId
CF-IPCountry
X-Endurance-Cache-Level
Backend-Name
IsBot
Fastly-Soc-X-Request-Id
X-S-Maxage
Mail-Subject
X-UA
X-Clara-WADP
X-Compress-Hint
X-Developers
X-Device-Os
Srv
X-B3-Spanid
X-JWT-State
X-Is-Gdpr
X-WADP-Cache
X-Has-Esi
We-Hiring
N-Cache
X-Amzn-Remapped-Content-Length
X-SIPLIST1
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
User-Cache-Control
X-PHP-Host
X-Cdn-Forward
Akamai-GRN
X-Ruxit-Js-Agent
X-Geo
X-Hash
X-Proxy-Upstream
X-Auto-Login
Wxu-Next-Commit
Wxu-Next-Hostname
X-IN-APIGATEWAY
X-Request-URI
X-Sn-Servicetimems
Wxu-Next-Region
X-GeoIP-City
X-NX-Host
RNT-Machine
RNT-Time
X-Hnp-Log
X-Service
Platform
Pramga
X-We-Are-Hiring
Section-Io-Cache
X-Azure-Ref
X-Proxy-Cache-Status
X-Up
Server-Host
Served-By
X-IN-APIGATEWAYSSL
X-Backend-Url
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
X-CUA
X-Fetched-On
X-Clientip
X-Eu-Site
X-Debug-Cache-Store
X-Thanos
X-Distributor
X-Epic-Correlation-Id
X-Distil-CS
X-Dispatcher-Server
X-Dispatch
X-CGP
X-NC
X-Generation-Time
X-Bip
X-Level-Front-Cache
X-Geo-Header
X-Backend-Host
X-C
X-Cache-Bucket
X-Cdn-Srv
X-Skip-Cache
X-Generated-By
X-Cache-FS-Status
X-Generated-On
X-Azure-Ref-OriginShield
X-User
X-Block-Status
X-Origin-Date
Countrycode
X-Origin-Expires
Content-Disposition
PFcat
X-Old-Content-Length
HA-Ipaddr
Ha-Gx-Prefs
X-Magnolia-Registration
Gh-Request-Id
X-Owner
X-Platform-Server
X-Request-Start
X-Via-CDN
X-Webstats-RespID
X-WebServer
X-Server-IP
Adler-Geo
X-Reboot
CDCHOST
AKAMAI
X-Release
Heartbleed
X-VC-Cache
X-Li-Pop
X-Li-Fabric
X-Cdn-Origin
L
X-Debug-Cookies
X-Gen-Mode
X-LI-Proto
X-LI-UUID
X-Debug-Log
X-Var-Ttl
Is-Eu
X-Location
Pagetype
X-ElasticPress-Search
X-Variation
SRV
X-NWS-UUID-VERIFY
X-Ratelimit-Limit
X-Microcachable
X-Dc
Fastly-SIE
X-Matched-Rule
X-Thinkindot-L3
X-Fastly-Cache
X-Urbn-Context-Path
X-Wikidot-Static-Cache
X-Generated-In
X-Wikidot-Backend
X-Svr
X-Lb-Id
X-SD-PageType
X-TrackingId
X-Reqid
Fastly-SWR
X-Urbn-Site-Id
X-VServer
X-Key
X-Qloud-Router
X-Say-TTL
X-SayCDN-TTL
X-Cache-Info
X-Cache-Id
X-Say-Cacheable
X-Nginx-Cache-Key
X-RateLimit-Limit-Second
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Method
X-Swa-Ws
X-Policy
Thinkindot-CacheControl
Server-Int
Locale
X-Servername
X-RateLimit-Remaining-Second
Thinkindot-CacheControl-Type
X-Irp-Debug
Web-Mar-Node
True-Client-Country-4JS
Thinkindot-Control
Kp-EeAlive
X-Amz-Meta-Cache-Control
SD-X-WS
Magicmarker
X-BBXSRF
X-Backend-State
X-App-Name
Esi-Enabled
X-Core-Mission
X-GEO
W
Memory
X-Instart-Isnd
Server-ID
Resin-Trace
Cache-Provider
X-ServiceProvider
X-MSEdge-Flight
X-MSEdge-Features
X-Internal-Host
V-Age
X-Cache-URL
X-Edge-Server
X-VWS-Id
X-LJ-Flow-ID
X-Scheme
Cdn-Request-Time
Cdn-Host
X-AWS-Id
X-Cache-Backend
X-Be
X-FPC
X-Processor
X-GDPR
REQUESTUUID
X-Mode
X-DC
X-URL
X-Request-Time
X-Org
Group
X-Pjax-Url
SS
X-Servedbyhost
X-Hello
X-ABtesting
X-NodeID
X-Wa
X-Flog
X-Unique-ID
X-Datadome
Cache-Host
X-Server-W
X-Response-By
X-GRACE
X-IPS-LoggedIn
Country-Code
X-Ms-Version
X-Ms-Request-Id
X-Page-Type
X-CDN-Forward
X-Oss-Object-Type
X-Oss-Request-Id
X-Oss-Server-Time
Cache-Cookie-Set-Lfrom
X-Oss-Hash-Crc64ecma
Cache-Cookie-Set-From
X-Oss-Storage-Class
X-SN
Cache-Cookie-Set-Idcheck
X-Varnish-Beresp-Status
X-Varnish-Beresp-Ttl
X-VCL-Version
X-Oracle-Dms-Rid
X-HS-Status
X-Varnish-Beresp-Grace
X-Routing-Service
X-Zipkin-Id
X-Webkit-Csp
X-EC-Lua
X-Proxied
X-Session-Fingerprint
PICS-Label
X-Via-Ucdn
Lfy
X-SRV
UCS
X-Ftr-Request-Id
X-Tb-Optimization-Total-Bytes-Saved
X-Zone
X-Dynatrace
X-COUNTRY
X-Agile-Id
X-Agile
X-Cache-Debug
X-Agile-Age
X-DataStream-Cache-Status
X-Logtrace-Id
Ttl
Powered-By-ChinaCache
Ajk
SN
X-MP-GENERATED-AT
X-Varnish-Beresp-TTL
X-Ratelimit-Remaining
X-RateLimit-Reset
X-Webapp-Samesite-None-Activated-N
Geoip-Latitude
Proxy-Firewall
GeoIP-City
X-7Graus-Varnish-XKeys
GeoIp-Country-Code
GeoIP-Latitude
X-7Graus-Varnish-Cache-Control
GeoIP-Country-Code
X-PF-Uncompressing
X-Fastly-Country-Code
X-Pf-Uncompressing
Geoip-City
ProcessTime
X-Source
X-Sucuri-Id
Powered-By
X-Cache-Miss-From
X-Sedo-Request-Id
X-Grey
X-Logging-Id
X-Cache-Category-Id
X-CSRF-Token
Environment
X-APP
X-HTML-Minification-Powered-By
XServer
X-NODE
X-Ftr-Cache-Host
X-ZONE
X-Newrelic-Synthetics
Cdn
X-CLOUD-TRACE-CONTEXT
X-Bc
X-Sucuri-ID
Pics-Label
X-Tt-Trace-Host
X-Vcl-Version
X-TH-Server
X-Unique-Id
Amp-Access-Control-Allow-Source-Origin
X-DataStream-MidMile-RTT
CACHE
X-Edge
M-TraceId
X-DataStream-Origin-MEX-Latency
CF-Cached-On
X-Core-Value
Fastly-Backend-Name
X-Check-Cacheable
X-LiteSpeed-Cache-Control
WWW
X-Vdms-Version
X-Aicache-OS
Cf-Ipcountry
X-Sucuri-Cache
X-Ftr-Dc
X-Dynatrace-Js-Agent
X-Ftr-Realm
X-Ftr-Backend-Server
X-Ftr-Balancer
HostName
X-Ftr-Backend
X-Sigma
X-Rocket-Build-Number
X-Fastly-Backend-Reqs
X-Sigma-Backend
Cdncip
GW-Server
Requestid
X-Mid
Cdnsip
X-RCS-CacheZone
X-AK-Request-ID
X-Correlation-ID
MIME-Version
X-Planisys-CDN-TTL
X-Shopify-Generated-Cart-Token
X-Planisys-CDN-Rules
Pragrma
X-MCACHE
X-Planisys-CDN-Cache
X-Fstrz
X-FORWARDED-FOR
X-LAGOON
X-Swift-Error
LB
X-Varnish-Ttl
X-Cache-Tag
X-Via-NSCOPI
X-UPSTREAM-Address
X-ServedByHost
X-Secret
X-Litespeed-Cache-Control
Ohc-Response-Time
X-Varnish-Url
X-TT-LOGID
X-Gannett-Site-Version
X-NGINX-Cache
Lb
X-DI
X-BE
X-DB
X-RPM
URI
X-CDN-Cache
TTL
X-PJAX-URL
X-RSL
X-DW
X-BC
X-RPS
X-DSS
X-Action
X-Cache-Ttl
X-WA
X-ORACLE-APMCS-TAG
X-SaId
X-ORACLE-APMCS-REQUEST-ID
Dynatrace
X-WR-MODIFICATION
RequestUuid
X-Fpc
On-Server
X-ND-Cache
X-Varnish-Cacheable
WZWS-RAY
X-GeoIP-Country-Code
Host-ID
DataCenter
Server-Id
X-Trafficlayer-App-Version
Xkeypdq
X-Upstream-Ct
X-Upstream-Ht
Is-Session-Tracking
Inserted-Into-Cache-At
X-Refresh
CDN
Xkeyrz
X-Fastly-Cache-Hits
Get-Access-Time
X-Page-Impression-Id
X-Flow-Id
X-Zalando-Child-Request-Id
User-Agent
X-Nananana
X-Proxy-Cacherz
X-Served-From
Locid
X-Dw-Trace-Id
X-Via-SSL
Correlation-Id
Warning
X-Via-Edge
X-VC
X-SB
X-MID
X-Akamai-SSL-Client-Sid
X-Cf-Powered-By
X-Akamai-ERPolicy
X-ServerName
X-Req
X-Pod
X-Amzn-Remapped-Connection
Thinkindot-Cache-Type
X-MiniProfiler-Ids
X-Amzn-Remapped-Date
Gannett-Cam-Experience-Id
X-Gamma-Serve
X-Akamai-ERRuleID
X-LiteSpeed-Tag
X-LB-ID
X-Newrelic-App-Data
V-Cache
RequestId
X-NU-AKA-ACS-Version
Xet-Cookie
X-Request-URL
X-Gdpr
Processtime
HitType
Who
X-Bug-Bounty
Cneonction
X-Gen-Id
X-ECache
SID
X-Crawler