Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
CF-RAY
CF-Cache-Status
Link
X-Powered-By
ETag
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Alt-Svc
Access-Control-Allow-Credentials
X-Runtime
X-Xss-Protection
X-Drupal-Cache
X-Adblock-Key
X-Check
Content-Security-Policy-Report-Only
X-Generator
X-Cacheable
X-Cache-Status
X-Permitted-Cross-Domain-Policies
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Template
X-Language
X-Iinfo
Status
Content-Encoding
X-Content-Security-Policy
X-FRAME-OPTIONS
X-AspNetMvc-Version
X-Buckets
X-Request-ID
X-Kinja-Server-Push
Xkey
Upgrade
X-Via
Access-Control-Expose-Headers
X-Turbo-Charged-By
Access-Control-Max-Age
Keep-Alive
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Pass-Why
EagleId
X-Age
X-Backend
X-Envoy-Upstream-Service-Time
X-Robots-Tag
X-Ua-Compatible
X-Amz-Request-Id
X-Amz-Id-2
X-Page-Speed
X-Pingback
X-CDN
X-Server-Powered-By
X-AH-Environment
X-Server
X-Proxy-Cache
X-UA-Device
X-Hacker
Request-Context
X-Nginx-Cache-Status
X-Swift-SaveTime
X-Swift-CacheTime
Grace
Ali-Swift-Global-Savetime
X-Varnish-Cache
X-Cdn
P3p
Cf-Railgun
X-LiteSpeed-Cache
Server-Timing
Feature-Policy
X-Amz-Version-Id
X-WebKit-CSP
X-Device
X-Server-Id
X-OneAgent-JS-Injection
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Rq
X-Ac
X-Cnection
EagleEye-TraceId
Report-To
X-Cloud-Trace-Context
Request-Id
X-Response-Time
X-Backend-Server
X-Host
Content-Location
X-Node
X-Readtime
X-Origin-Cache
X-Vhost
X-Cache-Lookup
X-Application-Context
X-ORACLE-DMS-ECID
X-Dispatcher
X-DataDome
NEL
X-ORACLE-DMS-RID
X-Ruxit-JS-Agent
X-Origin-Upstream-Status
X-Rack-Cache
X-HW
Surrogate-Control
X-Dns-Prefetch-Control
Rating
X-Country-Code
Allow
X-Clacks-Overhead
X-Country
X-Url
X-FTR-Request-ID
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-DynaTrace
X-MS-InvokeApp
X-Instart-Request-ID
Fusion-Template-Id
Fusion-Source
Fusion-Component-Id
Fusion-Content-Source
Fusion-Content-Id
X-TTL
X-Goog-Hash
X-Vname
X-TtlSet
X-PC
X-Varnish-TTL
Pinterest-Generated-By
X-Powered-By-Plesk
Verso
X-B3-TraceId
Public-Key-Pins
RTSS
X-Px
X-Mod-Pagespeed
Edge-Control
X-ESI
Response
X-Middleton-Display
X-Sol
X-Middleton-Response
Display
X-Ah-Environment
X-VARITI-CCR
SPRequestGuid
X-Exp-Variant
X-SharePointHealthScore
X-Exp-Id
X-Kinja
X-GoogleNews-Bot
X-Cdn-Fetch
X-Kinja-Revision
X-Kinja-Build
X-Kinja-Server
X-Use-Magma
X-D2id
X-Recruiting
Accept-Ch-Lifetime
X-CST
Service-Worker-Allowed
X-Akam-SW-Version
X-Vcap-Request-Id
SPIisLatency
SPRequestDuration
X-Version
X-Server-Name
TCN
X-Abt-Application-Version
X-GitHub-Request-Id
X-Powered-CMS
X-Navigation-Version
MS-Author-Via
X-Trace
X-Shard
Charset
Fastly-Restarts
Nginx-Cache
X-Debug
Realpath
X-Amz-Rid
X-Upstream
X-Amz-Server-Side-Encryption
X-Aspnetmvc-Version
X-RateLimit-Remaining
Accept-CH
AR-ATIME
Ar-Sid
AR-PoweredBy
AR-CACHE
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Forwarded-Proto
X-Ezoic-Cdn
X-NF-Request-ID
Front-End-Https
X-Cached
X-VCache
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-MSEdge-Ref
Pagespeed
Access-Control-Request-Method
Arr-Disable-Session-Affinity
X-Shield-Request-Id
AR-Request-ID
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-XRDS-Location
DynaTrace
MicrosoftSharePointTeamServices
Content-MD5
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Expires
S
X-Amz-Meta-S3cmd-Attrs
X-Id
X-T
X-Goog-Storage-Class
Paypal-Debug-Id
X-Fastly-Request-ID
X-FTR-Realm
X-FTR-DC
X-FTR-Backend
X-FTR-Backend-Server
X-FTR-Balancer
X-DynaTrace-JS-Agent
X-Varnish-Age
Accept-Ch
X-Via-JSL
ServerID
X-Ser
X-Server-ID
X-Client-IP
X-Content-Type
X-Accel-Expires
X-Correlation-Id
X-Dw-Request-Base-Id
X-Forwarded-For
Fastcgi-Cache
X-Hits
X-Amzn-Trace-Id
Edge-Cache-Tag
X-Frontend
X-Content-Digest
X-Grace
Powered
X-DIS-Request-ID
X-N
X-FastCGI-Cache
X-Mobile-Rewrite
PB-PID
Arc-Version
PB-RID
X-FTR-Cache-Host
X-HS-Hub-Id
X-HS-Content-Id
AMP-Access-Control-Allow-Source-Origin
Server-Name
X-Logged-In
Pinterest-Version
X-Pinterest-Rid
TP-L2-Cache
TP-Cache
X-Request-Received
X-Microsite
X-Request-Handler-Origin-Region
X-Request-Processing-Time
X-GUploader-UploadID
X-Vcache
X-Fastcgi-Cache
X-Kinsta-Cache
X-Time
X-Cache-Age
X-Cache-Hit
X-Zen-Fury
X-User-Agent
X-Revision
X-Az
X-LB-Cache
Healthy
Backend-Timing
X-Type
X-Activity-Id
X-Analytics
X-Rid
X-AppVersion
X-Whom
X-RateLimit-Limit
X-IPLB-Instance
X-B3-Sampled
Retry-After
X-Node-Name
X-Srv
FilterID
Server-Node
X-NWS-LOG-UUID
Alternate-Protocol
X-Hp-Webp
X-SERVER
Accept-Charset
X-F-Cache
Cache-Tag
X-Cache-Rule
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
Cache-Status
X-Akamai-Edgescape
X-Cache-2
X-Webkit-CSP
X-Content-Options
Tracecode
X-Kong-Proxy-Latency
X-Content-Security-Policy-Report-Only
X-Kong-Upstream-Latency
Refresh
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Framework
X-Content-Powered-By
DC
X-Forwarded-Host
X-AOL-HN
X-Tumblr-User
X-Tumblr-Pixel-0
Access-Control-Allow-Method
X-Amzn-RequestId
X-Debug-Info
X-Jobs
X-Amz-Apigw-Id
X-Tumblr-Pixel
X-Varnish-Grace
Surrogate-Key
MS-CV
Source
X-Cluster
X-PHP-Backend
X-App-Environment
X-Instance
X-Request-Guid
X-FB-Debug
X-Page-Id
Fastcgi-Useragent
X-Cache-TTL
X-App-Server
X-B
NR-ENABLED
X-Cache-Operation
Actual-Object-TTL
Host
X-Mobile-URL
X-FW-Serve
X-FW-Server
X-FW-Static
X-Seen-By
X-FW-Hash
X-FW-Type
Frame-Options
X-Geo-Country
X-TA-CDN-Provider
X-Cache-Control
X-Hostname
Cleartype
X-Cache-Key
X-Pad
X-Cached-By
X-Host-Name
X-B-Cache
X-Signature
Upgrade-Insecure-Requests
X-BCube-Filmed-By
X-Mobile
X-Git-Hash
X-Response-Served-From
NGB
X-TT
X-WebKit-CSP-Report-Only
X-Adobe-Content
GEO-INFO
X-Adobe-Loc
X-Amz-Replication-Status
WPE-Backend
X-Varnish-Backend
X-B3-Traceid
Eomportal-Instance
X-GeoIP
Cache-Tv-Group
X-ProcessESI
X-UA-Device-Type
X-RemovedCookies
Filters
X-ATG-Version
X-RequestSource
X-Drupal-Cache-Tags
Payment
X-Handled-By
X-Litespeed-Cache
From-Origin
X-TT-TIMESTAMP
Ms-Operation-Id
X-RTag
X-Tumblr-Pixel-2
Webserver
X-Tumblr-Pixel-1
X-Cacheable-TTL
X-Daa-Tunnel
X-TX-ID
X-Acc-Meta-Resource-Type
Xserver
X-Origin-Server
X-EdgeConnect-Cache-Status
X-Element-Page-Cache
X-Status
Liferay-Portal
X-HS-Cache-Config
X-Cache-TTL-Remaining
X-WA-Info
X-FW-Dynamic
X-Wix-Request-Id
X-Cache-Remote
X-Presslabs-Stats
X-Esi
Datacenter
X-Cache-Action
X-Contextid
X-Content-Age
X-Region
Cache
X-Hyper-Cache
X-Ratelimit-Reset
X-Edge-Location
Viewport
Version
X-XRDS-LOCATION
X-CF-Powered-By
X-Cache-NE
PageSpeed
X-Varnish-Hostname
X-Storage
X-Akamai-Transformed
X-PressLabs-Stats
Ohc-File-Size
X-Accel-Buffering
X-Cache-Server
Accept-CH-Lifetime
X-Cache-Var
Load-Balancing
X-ES-SERVER
Meta-Geo
X-Varnish-Server
X-Cache-Var-Map
X-Path-Route
X-RN-RSRV
Host-Header
X-Proxy
X-Proto
X-Cache-Enabled
X-IP
Ohc-Cache-HIT
Cache-Name
Cache-Tags
X-Origin-Response-Time
S-Cnection
Release
Mn-Server-Ip
Ec-Rule-Version
Rt-Fastcgi-Cache
X-Viewer-Country
X-NewRelic-App-Data
X-Device-Type
X-HS-Combine-CSS
Country
X-TNCMS
X-Cache-Config
X-R9-Blue-Green-Version
X-Loop
X-Access
Vix-Hermes-Req-Id
Cache-Hits
X-Akamai-Request-ID
X-Section
X-NGENIX-Cache
X-Varnish-Cache-Hits
X-Rule
Selected-Fe
Webcakes-Region
X-Yottaa-Optimizations
X-Yottaa-Metrics
DSUID
TWC-Connection-Speed
X-Tumblr-Pixel-3
X-Akamai-Request-ID2
X-PCL
X-Timing-Wait
TWC-Device-Class
Property-Id
X-Origin-Hint
X-Trace-Id
X-Cache-Grace
X-OCL
X-EIG-Tracking-Id
X-NCache
X-CS
X-VCT
X-Format
X-Vgn-Hpd-Reason
X-Debug-Cache
X-Www-Served-By
X-Proxy-Build
X-Cluster-Node
X-Web-Node
X-UnsetCookies
X-Upgrade-Enabled
X-Labrador-Cache-Channel
Webcakes-App-Name
Webcakes-App-Version
TWC-GeoIP-LatLong
X-FC-Vary-Parameters
TWC-Locale-Group
X-Cache-Host
X-Via-Fastly
X-From
X-Human
X-Xfnlog-Site
TWC-GeoIP-Country
TWC-Privacy
X-Ttl
X-Generated
X-Drupal-Cache-Contexts
S-Rt
X-Locale
Decoy-Debug-Status
Decoy-Debug-TTL
X-Goog-Meta-Goog-Reserved-File-Mtime
DB-Nickname
X-Hosted-By
X-Backend-Name
X-JoinUs
X-Origin
X-Cache-Time
Decoy-Debug-Key
X-Hit
X-Site-Version
X-PERF
Cache-Key
Server-Info
X-CCM
X-Ua
X-Time-Microsecs
X-ApacheServer
X-Tec-Api-Origin
Azure-SlotName
Azure-Version
Azure-RegionName
Azure-InstanceId
X-FireWall-Port
X-Tec-Api-Version
Azure-SiteName
X-Tec-Api-Root
X-Backend-TTL
Time
X-OVcl-Cache
X-Rendered-As
X-OVcl
X-S
X-Real-IP
X-Varnish-Hits
L5d-Success-Class
X-Redis-Cache
X-Upstream-HT
X-Upstream-CT
Now
Origin-Cache-Control
X-Pubstack
Origin-Edge-Control
X-Trafficlayer-App-Name
X-FW-Version
X-Trafficlayer-App-Scope
X-SS-Set-Cookie
Fastcgi-X-Cache-Version
OT-Force-Account-Verify
Fastly-SSL
Origin
X-Upstream-Proxy
Access-Control-Request-Headers
ServedBy
Hostname
X-FB-TRIP-ID
Cteonnt-Length
X-VG-TLSProxy
X-Origin-CC
X-App-Version
X-APP-VERSION
X-Cluster-Name
X-UUID
X-Origin-TTL
X-VG-WebCache
X-ServerID
X-GoCache-CacheStatus
X-ShopId
Mime-Version
X-Alternate-Cache-Key
X-ShardId
X-Shopify-Stage
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Load-Cache
X-CACHE-KEY
NtCoent-Length
X-Parent-Response-Time
X-Soup
X-Rocket-Nginx-Bypass
X-Tb
Machine
Accept-Language
X-ECACHE
NGX
IBM-Web2-Location
X-CSRF-TOKEN
X-Tt-Trace-Tag
X-Is-Bot
Nel
Odigeo-Trace-Id
X-No-Session
X-B3-Parentspanid
X-B3-Spanid
X-Environment-Context
X-L-Path
X-MServer
X-Oneagent-Js-Injection
X-Uri
X-Date
X-Request-UUID
X-Info
X-Detected-As
X-Region-Sid
X-D
Apple-News-Services-Handled
A
X-Rewrite-Enabled
CF-IPCountry
X-ScT
X-B-Cookie
X-DPWN-IS-SECURE
X-Server-Time
X-Node-Id
X-Rojux
Apple-News-Services-Host
X-Developer
X-Destination
Apple-News-Services-Request-Url
T-Server
X-AIR-PT
X-External-Request-Id
ServerName
Rt-Proxy-Cache
X-Instart-Info
X-Hl-Ver
Rendered-Blocks
Viewtype
VivaBuild
X-A-Dgt
X-A-Wwc
X-Accel-Expires-Debug
X-A-Dcw
X-A-Dam
X-G
X-A
X-A-Ccd
Node
Mobile-Detection-Method
X-PAYTM-SRV-ID
Content-Script-Type
Content-Style-Type
Cache-Prefix
BehaviorPad-Version
Proxy-Connection
Arc-Country
AsisCache
Cross-Origin-Window-Policy
X-ARC
MD5-Digest
Memcached
Meta-Geo-Continent
X-Application
GEO-REGION-INFO
Fly-Cache
Fly-Request-Id
Apple-News-Services-Parsed-Url
X-S-Cookie
X-Transaction
X-Connection-Hash
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
X-CF-Lambda-Version
X-VG-WebServer
X-Trv-Group
X-Twitter-Response-Tags
X-Aed
X-Compress-Hint
SRV
Request-Time
X-Nginx-Cache
Xc-Version
X-CF-Lambda-Fn
X-B3-SpanId
X-Worker
X-SRCache-Key
X-Endurance-Cache-Level
Backend-Name
Uber-Trace-Id
X-ProxyCache-Status
X-BYPASS-REASON
X-NC
X-Magnolia-Registration
X-ProxyCache-Key
X-Azure-Ref
X-Up
X-UA
Srv
X-Cdn-Srv
X-Has-Esi
X-Cms-Context
X-Is-Gdpr
Section-Io-Cache
X-Cache-Bucket
Request-Country
X-Fastly-Cache
X-JWT-State
IsBot
X-Origin-Date
X-Origin-Expires
X-Azure-Ref-OriginShield
Fastly-Soc-X-Request-Id
X-VC-Cache
X-Var-Ttl
We-Hiring
Mail-Subject
X-Nc
X-S-Maxage
X-Developers
Request-EU
X-SIPLIST1
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-CUA
X-Release
X-Amzn-Remapped-Content-Length
User-Cache-Control
X-Geo
X-Debug-Log
Server-Int
Served-By
X-Hash
X-Geo-Header
Server-Host
X-IN-APIGATEWAY
X-Core-Mission
X-Eu-Site
N-Cache
X-Device-Os
Pagetype
X-IN-APIGATEWAYSSL
X-Clara-WADP
X-Hnp-Log
X-We-Are-Hiring
X-Cache-Info
Thinkindot-CacheControl
Wxu-Next-Region
Wxu-Next-Hostname
Wxu-Next-Commit
X-Sn-Servicetimems
X-Bip
X-Block-Status
X-Cdn-Forward
RNT-Machine
X-Guploader-Uploadid
X-C
X-Gen-Mode
W
Thinkindot-CacheControl-Type
X-Irp-Debug
X-Webstats-RespID
X-Generated-On
Thinkindot-Control
RNT-Time
X-WADP-Cache
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-Generation-Time
X-Server-IP
X-Clientip
CDCHOST
X-ElasticPress-Search
X-Proxy-Cache-Status
Akamai-GRN
Content-Disposition
X-Cdn-Origin
Countrycode
X-Service
X-Proxy-Upstream
X-Qloud-Router
X-CGP
AKAMAI
X-Reboot
X-Rebelmouse-Cache-Control
X-Reqid
X-TrackingId
X-Debug-Cookies
X-BBXSRF
X-Thinkindot-L3
X-NX-Host
X-User
Heartbleed
HA-Ipaddr
Ha-Gx-Prefs
X-Thanos
Kp-EeAlive
L
X-VServer
X-Rebelmouse-Surrogate-Control
X-App-Name
X-Level-Front-Cache
X-Distributor
X-Swa-Ws
Fastly-SWR
X-Location
X-Distil-CS
X-Matched-Rule
Fastly-SIE
X-Method
X-Ruxit-Js-Agent
X-Via-CDN
X-GEO
X-Microcachable
X-Dispatch
X-Servername
X-Li-Pop
X-LI-Proto
X-LI-UUID
X-Li-Fabric
X-GeoIP-City
X-Dispatcher-Server
X-Epic-Correlation-Id
X-Fetched-On
X-Old-Content-Length
X-Owner
X-Cache-Id
X-PHP-Host
X-Request-URI
X-WebServer
X-Variation
X-Platform-Server
X-Request-Start
X-Amz-Meta-Cache-Control
Platform
X-Policy
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Nginx-Cache-Key
X-Lb-Id
X-Generated-In
X-Internal-Host
X-Key
X-Say-Cacheable
X-Say-TTL
Adler-Geo
Is-Eu
PFcat
X-Urbn-Site-Id
X-Urbn-Context-Path
X-SayCDN-TTL
X-Skip-Cache
X-Generated-By
X-Backend-Url
Magicmarker
Memory
Web-Mar-Node
Locale
Gh-Request-Id
Cache-Provider
Esi-Enabled
X-Debug-Cache-Store
Pramga
X-Debug-Cache-Fetch
X-Backend-Host
X-Backend-State
X-Auto-Login
X-Debug-Cache-Expiry
X-NWS-UUID-VERIFY
X-LJ-Flow-ID
X-VWS-Id
X-Ratelimit-Limit
X-AWS-Id
SD-X-WS
True-Client-Country-4JS
X-Cache-URL
X-Svr
Cdn-Host
X-MSEdge-Flight
X-MSEdge-Features
X-ServiceProvider
Cdn-Request-Time
X-Cache-FS-Status
X-SD-PageType
X-Edge-Server
Server-ID
X-Dc
Resin-Trace
X-Mode
X-GDPR
X-Instart-Isnd
V-Age
X-DC
X-Be
X-Scheme
X-FPC
REQUESTUUID
X-Request-Time
X-Org
X-ABtesting
X-Flog
X-Hello
X-Wa
X-Processor
SS
X-Cache-Backend
X-Unique-ID
X-Servedbyhost
X-Datadome
Group
X-IPS-LoggedIn
X-Response-By
X-Pjax-Url
X-NodeID
Country-Code
X-DataStream-Cache-Status
Cache-Host
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-From
Cache-Cookie-Set-Idcheck
X-CDN-Forward
X-GRACE
X-VCL-Version
X-Server-W
X-Zipkin-Id
X-Routing-Service
X-Page-Type
X-Proxied
X-SN
X-Oss-Server-Time
X-Via-Ucdn
UCS
X-Oss-Storage-Class
X-Oracle-Dms-Rid
X-Oss-Request-Id
X-Ms-Request-Id
X-Oss-Hash-Crc64ecma
X-Ms-Version
X-Oss-Object-Type
X-RateLimit-Reset
X-Webkit-Csp
X-EC-Lua
X-Ftr-Request-Id
X-Varnish-Beresp-Status
X-SRV
X-Tb-Optimization-Total-Bytes-Saved
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Ttl
PICS-Label
X-HS-Status
X-Dynatrace
X-URL
X-Session-Fingerprint
Lfy
X-COUNTRY
X-MP-GENERATED-AT
Ajk
X-Logtrace-Id
X-Zone
X-Agile-Age
X-Agile
X-Cache-Debug
Powered-By-ChinaCache
X-Agile-Id
Proxy-Firewall
Ttl
SN
ProcessTime
X-APP
XServer
X-Source
X-Varnish-Beresp-TTL
X-ZONE
X-Ratelimit-Remaining
X-PF-Uncompressing
GeoIP-City
GeoIP-Country-Code
X-Fastly-Country-Code
Geoip-City
X-Pf-Uncompressing
Powered-By
GeoIp-Country-Code
Geoip-Latitude
X-Newrelic-Synthetics
GeoIP-Latitude
X-Sucuri-Id
X-HTML-Minification-Powered-By
X-Logging-Id
Environment
X-Grey
X-Cache-Category-Id
X-DataStream-Origin-MEX-Latency
CACHE
X-NODE
X-DataStream-MidMile-RTT
X-Dynatrace-Js-Agent
X-TH-Server
X-Ftr-Cache-Host
X-7Graus-Varnish-XKeys
X-Sedo-Request-Id
X-Cache-Miss-From
X-7Graus-Varnish-Cache-Control
X-CSRF-Token
Pics-Label
Cdn
Fastly-Backend-Name
X-Tt-Trace-Host
X-Bc
X-LiteSpeed-Cache-Control
X-Sucuri-ID
X-Aicache-OS
X-Core-Value
X-Unique-Id
X-Check-Cacheable
M-TraceId
CF-Cached-On
X-Edge
Amp-Access-Control-Allow-Source-Origin
X-Vcl-Version
WWW
X-Webapp-Samesite-None-Activated-N
GW-Server
X-Ftr-Realm
Dynatrace
X-Ftr-Balancer
Cf-Ipcountry
X-Ftr-Backend-Server
X-Ftr-Backend
MIME-Version
X-Ftr-Dc
X-Fastly-Backend-Reqs
X-Mid
X-LAGOON
LB
X-Sucuri-Cache
X-Vdms-Version
Requestid
HostName
X-Sigma
X-Sigma-Backend
X-Cache-Tag
Ohc-Response-Time
X-FORWARDED-FOR
X-BC
X-Gannett-Site-Version
X-RCS-CacheZone
X-MCACHE
X-Rocket-Build-Number
X-UPSTREAM-Address
X-Varnish-Ttl
X-Varnish-Url
X-Secret
X-Fstrz
X-AK-Request-ID
Cdnsip
Cdncip
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-NGINX-Cache
X-Shopify-Generated-Cart-Token
X-TT-LOGID
Pragrma
X-Litespeed-Cache-Control
X-Planisys-CDN-Cache
X-PJAX-URL
X-Swift-Error
Lb
WZWS-RAY
X-Via-NSCOPI
X-DI
X-DSS
X-RPM
X-DB
X-Action
X-BE
URI
X-Varnish-Cacheable
On-Server
X-Cache-Ttl
X-DW
X-RSL
X-ServedByHost
DataCenter
X-RPS
X-CDN-Cache
X-GeoIP-Country-Code
Host-ID
RequestUuid
X-Proxy-Cacherz
Xkeyrz
User-Agent
X-WA
X-Correlation-ID
Is-Session-Tracking
Server-Id
Get-Access-Time
CDN
TTL
X-Zalando-Child-Request-Id
X-SaId
X-ORACLE-APMCS-TAG
X-Upstream-Ct
X-Akamai-SSL-Client-Sid
X-Flow-Id
X-ORACLE-APMCS-REQUEST-ID
X-Fpc
Xkeypdq
Inserted-Into-Cache-At
X-Fastly-Cache-Hits
X-WR-MODIFICATION
X-Page-Impression-Id
X-Upstream-Ht
X-VC
X-ND-Cache
X-MID
X-Trafficlayer-App-Version
X-Nananana
X-Crawler
X-Dw-Trace-Id
Warning
Correlation-Id
SID
X-NU-AKA-ACS-Version
X-Refresh
X-SB
Who
X-Cf-Powered-By
X-Via-Edge
X-Via-SSL
Locid
Processtime
X-Akamai-ERRuleID
X-Amzn-Remapped-Date
X-Akamai-ERPolicy
X-Amzn-Remapped-Connection
X-Request-URL
X-LB-ID
X-FE
X-Newrelic-App-Data
X-MiniProfiler-Ids
Cneonction
V-Cache
X-Gdpr
Xet-Cookie
X-ServerName
X-Gen-Id
X-ECache
HitType
X-Bug-Bounty
RequestId
X-Render-Time
X-LiteSpeed-Tag