Threat Level: green Handler on Duty: Manuel Humberto Santander Pelaez

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
CF-RAY
CF-Cache-Status
Link
X-Powered-By
ETag
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Alt-Svc
Access-Control-Allow-Credentials
X-Runtime
X-Xss-Protection
X-Drupal-Cache
X-Adblock-Key
X-Check
Content-Security-Policy-Report-Only
X-Generator
X-Cacheable
X-Cache-Status
X-Permitted-Cross-Domain-Policies
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Template
X-Language
X-Iinfo
Content-Encoding
X-Content-Security-Policy
Status
X-FRAME-OPTIONS
X-AspNetMvc-Version
X-Buckets
X-Request-ID
X-Kinja-Server-Push
Xkey
Upgrade
X-Via
Access-Control-Expose-Headers
X-Turbo-Charged-By
Access-Control-Max-Age
Keep-Alive
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Pass-Why
X-Age
EagleId
X-Backend
X-Envoy-Upstream-Service-Time
X-Robots-Tag
X-Ua-Compatible
X-Amz-Request-Id
X-Amz-Id-2
X-Page-Speed
X-CDN
X-Pingback
X-Server-Powered-By
X-AH-Environment
X-Server
X-UA-Device
X-Proxy-Cache
X-Hacker
Request-Context
X-Nginx-Cache-Status
X-Swift-CacheTime
X-Swift-SaveTime
Grace
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-Cdn
P3p
X-LiteSpeed-Cache
Cf-Railgun
Server-Timing
Feature-Policy
X-Amz-Version-Id
X-Device
X-WebKit-CSP
X-Server-Id
X-OneAgent-JS-Injection
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Rq
X-Ac
EagleEye-TraceId
X-Cnection
Report-To
X-Cloud-Trace-Context
Request-Id
X-Response-Time
X-Backend-Server
X-Host
Content-Location
X-Node
X-Readtime
X-Origin-Cache
X-Vhost
X-Cache-Lookup
X-Application-Context
X-ORACLE-DMS-ECID
X-DataDome
X-Dispatcher
NEL
X-ORACLE-DMS-RID
X-Ruxit-JS-Agent
X-Origin-Upstream-Status
X-Rack-Cache
X-HW
Surrogate-Control
X-Dns-Prefetch-Control
Rating
X-Country-Code
X-Clacks-Overhead
Allow
X-Country
X-FTR-Request-ID
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Url
X-DynaTrace
X-MS-InvokeApp
X-Instart-Request-ID
Fusion-Component-Id
Fusion-Content-Source
Fusion-Source
Fusion-Content-Id
Fusion-Template-Id
X-Goog-Hash
X-TtlSet
X-Vname
X-TTL
X-PC
X-Varnish-TTL
X-B3-TraceId
Pinterest-Generated-By
Verso
X-Powered-By-Plesk
Public-Key-Pins
X-Px
RTSS
Accept-Ch-Lifetime
Edge-Control
X-ESI
X-Mod-Pagespeed
X-Middleton-Display
X-Sol
Display
X-Middleton-Response
Response
X-Ah-Environment
X-VARITI-CCR
SPRequestGuid
X-Kinja
X-Use-Magma
X-D2id
X-Exp-Id
X-Exp-Variant
X-GoogleNews-Bot
X-Cdn-Fetch
X-Kinja-Build
X-Kinja-Server
X-Kinja-Revision
X-SharePointHealthScore
X-Recruiting
X-Akam-SW-Version
X-CST
Service-Worker-Allowed
X-Vcap-Request-Id
SPIisLatency
SPRequestDuration
X-Version
X-Server-Name
X-GitHub-Request-Id
TCN
X-Abt-Application-Version
X-Navigation-Version
X-Powered-CMS
MS-Author-Via
X-Trace
X-Shard
Charset
X-Debug
Fastly-Restarts
Nginx-Cache
X-Aspnetmvc-Version
Realpath
X-Amz-Server-Side-Encryption
X-Amz-Rid
X-RateLimit-Remaining
X-Upstream
Ar-Sid
AR-ATIME
AR-CACHE
AR-PoweredBy
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Forwarded-Proto
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Ezoic-Cdn
X-NF-Request-ID
Accept-CH
Front-End-Https
X-Cached
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-MSEdge-Ref
Pagespeed
DynaTrace
Arr-Disable-Session-Affinity
Access-Control-Request-Method
Content-MD5
X-Shield-Request-Id
AR-Request-ID
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Mrf-Item-Lastmod
MRF-Tech
X-VCache
X-FTR-Cache-Status
X-Country-Code-Real
X-FTR-Expires
MicrosoftSharePointTeamServices
Accept-Ch
X-XRDS-Location
S
X-DynaTrace-JS-Agent
X-Goog-Storage-Class
X-T
X-Amz-Meta-S3cmd-Attrs
X-Fastly-Request-ID
Paypal-Debug-Id
X-Id
X-FTR-Backend-Server
X-FTR-DC
X-FTR-Backend
X-FTR-Balancer
X-FTR-Realm
X-Ser
X-Varnish-Age
ServerID
X-Via-JSL
X-Server-ID
X-Client-IP
X-Content-Type
X-Accel-Expires
X-Dw-Request-Base-Id
X-Forwarded-For
Edge-Cache-Tag
Fastcgi-Cache
X-Hits
X-Amzn-Trace-Id
X-Grace
X-Correlation-Id
Powered
X-Content-Digest
X-Frontend
X-DIS-Request-ID
X-N
X-Mobile-Rewrite
PB-PID
X-FTR-Cache-Host
PB-RID
Arc-Version
X-HS-Hub-Id
X-HS-Content-Id
X-Vcache
Pinterest-Version
X-Pinterest-Rid
AMP-Access-Control-Allow-Source-Origin
X-Fastcgi-Cache
Server-Name
X-Logged-In
X-FastCGI-Cache
TP-Cache
TP-L2-Cache
X-Request-Processing-Time
X-Request-Received
X-Request-Handler-Origin-Region
X-Kinsta-Cache
X-Microsite
X-Cache-Hit
X-Zen-Fury
X-Time
X-Type
X-Rid
X-Activity-Id
X-AppVersion
X-IPLB-Instance
X-LB-Cache
X-Az
Healthy
X-Revision
Backend-Timing
X-Analytics
X-Cache-Age
X-User-Agent
Retry-After
X-GUploader-UploadID
X-Whom
X-Srv
X-B3-Sampled
X-Node-Name
Server-Node
FilterID
X-RateLimit-Limit
X-NWS-LOG-UUID
X-Hp-Webp
Alternate-Protocol
Cache-Tag
Accept-Charset
X-SERVER
X-F-Cache
Cache-Status
X-Akamai-Edgescape
X-Webkit-CSP
X-Content-Options
X-Cache-Rule
X-Content-Security-Policy-Report-Only
NR-ENABLED
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Kong-Upstream-Latency
X-Content-Powered-By
X-Cache-2
X-Kong-Proxy-Latency
DC
X-Debug-Info
X-AOL-HN
X-Instance
VIX-Pulpo-Upstream-Status
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-User
MS-CV
X-Cluster
X-Amzn-RequestId
X-Amz-Apigw-Id
X-FB-Debug
VIX-Pulpo-Node
Access-Control-Allow-Method
Refresh
X-Varnish-Grace
X-App-Environment
Tracecode
X-Jobs
X-Forwarded-Host
X-Framework
X-Page-Id
Surrogate-Key
X-PHP-Backend
X-B
Source
Fastcgi-Useragent
X-Request-Guid
X-Cache-TTL
Actual-Object-TTL
X-App-Server
Host
X-Seen-By
X-Mobile-URL
X-Cache-Operation
X-FW-Static
X-FW-Type
Frame-Options
X-FW-Hash
X-FW-Server
X-FW-Serve
X-TA-CDN-Provider
X-Geo-Country
X-Cache-Control
X-Hostname
X-Cached-By
Cleartype
X-Host-Name
X-Pad
X-Cache-Key
X-B-Cache
X-Signature
Upgrade-Insecure-Requests
X-Git-Hash
X-BCube-Filmed-By
X-Mobile
X-Element-Page-Cache
X-WebKit-CSP-Report-Only
NGB
X-Response-Served-From
Xserver
X-ATG-Version
X-Varnish-Backend
WPE-Backend
X-GeoIP
X-UA-Device-Type
X-RemovedCookies
X-ProcessESI
X-RequestSource
X-Daa-Tunnel
X-Handled-By
X-Drupal-Cache-Tags
X-RTag
X-Tumblr-Pixel-1
X-Tumblr-Pixel-2
Cache-Tv-Group
X-Amz-Replication-Status
Ms-Operation-Id
X-TT
Eomportal-Instance
Webserver
Filters
X-HS-Cache-Config
GEO-INFO
From-Origin
X-Adobe-Loc
X-Origin-Server
X-Cacheable-TTL
Payment
X-Adobe-Content
X-EdgeConnect-Cache-Status
X-TT-TIMESTAMP
X-TX-ID
X-XRDS-LOCATION
X-Cache-Remote
X-Cache-TTL-Remaining
X-Wix-Request-Id
X-Presslabs-Stats
Datacenter
X-Status
Cache
Liferay-Portal
X-FW-Dynamic
X-Esi
X-WA-Info
X-Acc-Meta-Resource-Type
X-Hyper-Cache
X-Region
X-Contextid
X-Cache-Action
X-Edge-Location
Version
X-Ratelimit-Reset
X-Ttl
Viewport
X-Content-Age
X-Cache-NE
X-B3-Traceid
X-CF-Powered-By
X-Varnish-Hostname
X-Akamai-Transformed
X-PressLabs-Stats
PageSpeed
X-Storage
X-Cache-Server
X-HS-Combine-CSS
Ohc-File-Size
X-Varnish-Server
X-RN-RSRV
Meta-Geo
X-Accel-Buffering
X-ES-SERVER
X-Cache-Var
X-Cache-Var-Map
Load-Balancing
X-Path-Route
X-Xfnlog-Site
X-IP
Host-Header
X-Cache-Enabled
X-Proxy
Cache-Tags
X-Via-Fastly
X-Viewer-Country
Country
Cache-Name
TWC-Connection-Speed
X-Yottaa-Optimizations
DB-Nickname
X-NCache
X-Loop
X-Yottaa-Metrics
TWC-Device-Class
TWC-GeoIP-Country
X-Cache-Time
X-Device-Type
X-Debug-Cache
X-Cache-Config
Vix-Hermes-Req-Id
TWC-Locale-Group
TWC-GeoIP-LatLong
X-PCL
X-Section
X-Access
X-CCM
Webcakes-Region
X-TNCMS
X-Upgrade-Enabled
X-UnsetCookies
X-Tumblr-Pixel-3
Webcakes-App-Name
Property-Id
X-OCL
TWC-Privacy
X-Origin
X-Origin-Hint
Rt-Fastcgi-Cache
Release
X-Proto
Webcakes-App-Version
X-Varnish-Cache-Hits
S-Rt
Ec-Rule-Version
Mn-Server-Ip
DSUID
Selected-Fe
X-From
X-Rule
X-Timing-Wait
X-R9-Blue-Green-Version
X-Proxy-Build
X-Labrador-Cache-Channel
X-VCT
X-Vgn-Hpd-Reason
X-Cache-Grace
X-Akamai-Request-ID2
Cache-Hits
X-Www-Served-By
X-Origin-Response-Time
X-NGENIX-Cache
X-Drupal-Cache-Contexts
X-EIG-Tracking-Id
X-Cluster-Node
X-Backend-TTL
X-Backend-Name
X-FC-Vary-Parameters
X-Format
X-JoinUs
X-Human
X-Hosted-By
X-Cache-Host
X-Akamai-Request-ID
X-CS
S-Cnection
X-Trace-Id
X-Varnish-Hits
X-Web-Node
Decoy-Debug-TTL
X-Time-Microsecs
X-PERF
X-ApacheServer
Ohc-Cache-HIT
X-Goog-Meta-Goog-Reserved-File-Mtime
Decoy-Debug-Status
Decoy-Debug-Key
Azure-RegionName
Azure-InstanceId
X-Locale
X-Hit
Azure-SiteName
Azure-SlotName
X-FireWall-Port
X-Site-Version
Azure-Version
X-Generated
X-NewRelic-App-Data
X-Ua
X-Real-IP
X-S
X-OVcl-Cache
X-Rendered-As
Cache-Key
X-OVcl
Origin-Edge-Control
Time
Origin-Cache-Control
X-Pubstack
Server-Info
L5d-Success-Class
X-Trafficlayer-App-Scope
X-Redis-Cache
X-Trafficlayer-App-Name
Now
X-FW-Version
X-SS-Set-Cookie
Accept-CH-Lifetime
X-Litespeed-Cache
X-Upstream-HT
Fastcgi-X-Cache-Version
X-Upstream-CT
OT-Force-Account-Verify
Fastly-SSL
X-Origin-TTL
X-Origin-CC
Cteonnt-Length
Mime-Version
ServedBy
X-APP-VERSION
X-Cluster-Name
X-ServerID
Access-Control-Request-Headers
X-UUID
X-Load-Cache
Origin
X-Alternate-Cache-Key
X-ShardId
X-App-Version
X-Sorting-Hat-ShopId
X-FB-TRIP-ID
X-ShopId
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Tec-Api-Root
X-Tec-Api-Origin
X-Tec-Api-Version
X-Parent-Response-Time
Hostname
X-VG-TLSProxy
X-VG-WebCache
X-Soup
X-Rocket-Nginx-Bypass
X-CACHE-KEY
X-GoCache-CacheStatus
X-Upstream-Proxy
NtCoent-Length
Accept-Language
Machine
X-Is-Bot
X-Tb
Nel
X-Uri
X-ECACHE
NGX
X-Guploader-Uploadid
IBM-Web2-Location
Odigeo-Trace-Id
X-No-Session
X-CSRF-TOKEN
X-Nc
X-Environment-Context
X-MServer
X-Node-Id
X-ProxyCache-Status
X-Info
X-BYPASS-REASON
X-ProxyCache-Key
X-L-Path
X-Oneagent-Js-Injection
X-Tt-Trace-Tag
X-Detected-As
VivaBuild
MD5-Digest
X-Hl-Ver
X-S-Cookie
Uber-Trace-Id
X-Destination
X-A-Dcw
Request-Time
Memcached
X-B-Cookie
X-A-Dgt
X-G
X-External-Request-Id
X-Application
Cross-Origin-Window-Policy
X-Developer
Fly-Cache
Fly-Request-Id
Content-Style-Type
Content-Script-Type
AsisCache
BehaviorPad-Version
Cache-Prefix
X-Accel-Expires-Debug
Viewtype
Proxy-Connection
X-ScT
X-Server-Time
X-ARC
X-A
GEO-REGION-INFO
X-A-Wwc
X-AIR-PT
X-B3-Parentspanid
T-Server
X-DPWN-IS-SECURE
X-A-Ccd
Apple-News-Services-Handled
Apple-News-Services-Host
X-D
Node
Apple-News-Services-Parsed-Url
X-Worker
Rendered-Blocks
Request-EU
X-Aed
X-Trv-Group
X-Request-UUID
X-Region-Sid
X-Vtex-Processado-Em
X-Transaction
X-Instart-Info
X-Connection-Hash
X-Vtex-Remote-Cache
X-Rojux
Arc-Country
X-A-Dam
X-B3-SpanId
X-Rewrite-Enabled
Mobile-Detection-Method
ServerName
Request-Country
X-Date
Apple-News-Services-Request-Url
Meta-Geo-Continent
Rt-Proxy-Cache
X-Cms-Context
X-CF-Lambda-Fn
X-CF-Lambda-Version
Xc-Version
X-Nginx-Cache
X-PAYTM-SRV-ID
A
X-Twitter-Response-Tags
X-SRCache-Key
X-VG-WebServer
Backend-Name
CF-IPCountry
X-Endurance-Cache-Level
X-JWT-State
X-SIPLIST1
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Clara-WADP
X-Has-Esi
X-Compress-Hint
X-S-Maxage
X-Device-Os
X-WADP-Cache
X-Developers
IsBot
X-Cache-Bucket
X-Cdn-Srv
N-Cache
X-Is-Gdpr
Fastly-Soc-X-Request-Id
We-Hiring
X-Ruxit-Js-Agent
X-B3-Spanid
Srv
Mail-Subject
X-UA
X-Amzn-Remapped-Content-Length
Akamai-GRN
X-Cdn-Forward
User-Cache-Control
X-PHP-Host
X-Generated-By
X-Geo
X-Origin-Date
X-Origin-Expires
X-Old-Content-Length
X-Auto-Login
X-Azure-Ref
X-Azure-Ref-OriginShield
X-LI-UUID
X-Location
X-Amz-Meta-Cache-Control
X-Magnolia-Registration
X-Owner
Wxu-Next-Commit
X-Thanos
X-Skip-Cache
X-Service
Server-Host
Served-By
X-Eu-Site
Section-Io-Cache
X-Server-IP
X-Request-Start
Wxu-Next-Hostname
Wxu-Next-Region
X-LI-Proto
X-Reboot
X-Reqid
X-Release
X-Platform-Server
X-Bip
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Generation-Time
X-Debug-Cache-Expiry
X-Geo-Header
X-GeoIP-City
X-CUA
X-Generated-On
X-Dispatch
X-Fastly-Cache
X-Epic-Correlation-Id
X-Fetched-On
X-Distributor
X-Dispatcher-Server
X-Distil-CS
X-Hash
X-IN-APIGATEWAY
X-C
X-NC
X-Up
X-BBXSRF
X-Li-Pop
X-Backend-Url
X-Li-Fabric
X-Cache-FS-Status
X-Clientip
X-Dc
X-IN-APIGATEWAYSSL
X-Irp-Debug
X-Level-Front-Cache
X-CGP
X-Backend-Host
X-TrackingId
X-Proxy-Upstream
Adler-Geo
Heartbleed
HA-Ipaddr
X-Gen-Mode
Is-Eu
X-Request-URI
L
X-Sn-Servicetimems
Ha-Gx-Prefs
Countrycode
X-Cache-Info
X-Cdn-Origin
X-Debug-Cookies
RNT-Time
X-Block-Status
Gh-Request-Id
AKAMAI
X-ElasticPress-Search
X-Via-CDN
Content-Disposition
Pramga
Platform
X-Proxy-Cache-Status
X-We-Are-Hiring
X-VC-Cache
X-Variation
RNT-Machine
X-User
X-Var-Ttl
X-Debug-Log
PFcat
X-Wikidot-Static-Cache
CDCHOST
X-Hnp-Log
X-Wikidot-Backend
X-NX-Host
Pagetype
X-WebServer
X-Webstats-RespID
X-NWS-UUID-VERIFY
X-Microcachable
SRV
X-Ratelimit-Limit
X-RateLimit-Remaining-Second
X-Urbn-Site-Id
X-VServer
X-Urbn-Context-Path
X-RateLimit-Limit-Second
X-Svr
X-Rebelmouse-Cache-Control
X-SayCDN-TTL
X-Say-TTL
X-Swa-Ws
X-Rebelmouse-Surrogate-Control
X-Thinkindot-L3
X-Say-Cacheable
X-Cache-Id
Locale
Server-Int
Thinkindot-CacheControl
Kp-EeAlive
Fastly-SWR
X-Servername
X-Qloud-Router
Fastly-SIE
X-Nginx-Cache-Key
Thinkindot-CacheControl-Type
X-Lb-Id
X-Key
X-Matched-Rule
X-Generated-In
Web-Mar-Node
X-Method
Thinkindot-Control
True-Client-Country-4JS
X-Policy
X-SD-PageType
X-App-Name
X-GEO
Esi-Enabled
Magicmarker
W
SD-X-WS
X-Core-Mission
X-Backend-State
X-MSEdge-Features
X-ServiceProvider
X-Internal-Host
Cache-Provider
X-Instart-Isnd
X-MSEdge-Flight
Server-ID
Memory
X-Cache-URL
Resin-Trace
V-Age
X-VWS-Id
X-Edge-Server
Cdn-Host
Cdn-Request-Time
X-LJ-Flow-ID
X-AWS-Id
X-Scheme
X-Be
X-URL
X-Cache-Backend
REQUESTUUID
X-Processor
X-GDPR
X-FPC
X-DC
X-Mode
X-Request-Time
X-Org
Group
X-Wa
X-ABtesting
X-NodeID
X-Servedbyhost
SS
X-Pjax-Url
X-Hello
X-Flog
X-Unique-ID
X-Datadome
X-Response-By
X-Server-W
Cache-Host
X-GRACE
X-IPS-LoggedIn
Country-Code
Cache-Cookie-Set-From
X-SN
Cache-Cookie-Set-Idcheck
X-Ms-Version
X-Page-Type
X-Ms-Request-Id
Cache-Cookie-Set-Lfrom
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-CDN-Forward
X-Varnish-Beresp-Ttl
X-VCL-Version
X-Varnish-Beresp-Grace
X-Oracle-Dms-Rid
X-HS-Status
X-Varnish-Beresp-Status
X-Routing-Service
X-Webkit-Csp
X-Proxied
X-Zone
X-Zipkin-Id
X-EC-Lua
X-Tb-Optimization-Total-Bytes-Saved
UCS
X-Session-Fingerprint
X-Ftr-Request-Id
Lfy
PICS-Label
X-Via-Ucdn
X-SRV
X-Dynatrace
X-COUNTRY
X-Cache-Debug
X-Agile-Id
X-Agile-Age
X-Agile
X-DataStream-Cache-Status
Ajk
Ttl
SN
Powered-By-ChinaCache
X-Logtrace-Id
X-MP-GENERATED-AT
X-Varnish-Beresp-TTL
X-Ratelimit-Remaining
X-RateLimit-Reset
X-Pf-Uncompressing
X-Webapp-Samesite-None-Activated-N
X-7Graus-Varnish-XKeys
X-7Graus-Varnish-Cache-Control
Geoip-City
GeoIp-Country-Code
GeoIP-City
Geoip-Latitude
Proxy-Firewall
X-PF-Uncompressing
X-Fastly-Country-Code
GeoIP-Country-Code
GeoIP-Latitude
X-Sucuri-Id
X-Source
ProcessTime
X-Cache-Miss-From
X-Logging-Id
X-Cache-Category-Id
Powered-By
X-Sedo-Request-Id
Environment
X-APP
X-CSRF-Token
X-Grey
XServer
X-NODE
X-HTML-Minification-Powered-By
X-Bc
Cdn
X-Ftr-Cache-Host
X-ZONE
X-Newrelic-Synthetics
X-Sucuri-ID
X-CLOUD-TRACE-CONTEXT
X-TH-Server
X-Unique-Id
X-Vcl-Version
X-Tt-Trace-Host
Pics-Label
Amp-Access-Control-Allow-Source-Origin
X-DataStream-Origin-MEX-Latency
CF-Cached-On
X-DataStream-MidMile-RTT
X-Core-Value
X-Check-Cacheable
M-TraceId
Fastly-Backend-Name
X-Edge
CACHE
X-LiteSpeed-Cache-Control
Cf-Ipcountry
X-Vdms-Version
X-Aicache-OS
X-Sucuri-Cache
WWW
X-Dynatrace-Js-Agent
X-Ftr-Backend
X-Ftr-Realm
X-Ftr-Balancer
X-Ftr-Backend-Server
X-Ftr-Dc
HostName
Cdncip
X-Mid
X-AK-Request-ID
Requestid
X-Rocket-Build-Number
X-RCS-CacheZone
Cdnsip
GW-Server
X-Fastly-Backend-Reqs
X-Sigma
X-Sigma-Backend
X-Correlation-ID
MIME-Version
X-Planisys-CDN-Rules
X-Shopify-Generated-Cart-Token
X-Planisys-CDN-TTL
X-Cache-Tag
X-Varnish-Ttl
X-LAGOON
X-Fstrz
LB
Pragrma
X-Swift-Error
X-FORWARDED-FOR
X-MCACHE
X-Planisys-CDN-Cache
X-NGINX-Cache
X-TT-LOGID
X-Secret
X-Gannett-Site-Version
Ohc-Response-Time
X-Varnish-Url
X-Litespeed-Cache-Control
X-Via-NSCOPI
X-ServedByHost
X-UPSTREAM-Address
Lb
X-Cache-Ttl
X-BC
X-Action
X-CDN-Cache
X-BE
X-DB
X-RPS
X-RSL
X-PJAX-URL
URI
X-WA
X-RPM
X-DI
TTL
X-DSS
X-DW
X-ORACLE-APMCS-REQUEST-ID
Dynatrace
X-ORACLE-APMCS-TAG
X-SaId
X-Varnish-Cacheable
X-WR-MODIFICATION
On-Server
X-ND-Cache
Host-ID
X-GeoIP-Country-Code
X-Fpc
RequestUuid
WZWS-RAY
DataCenter
X-Zalando-Child-Request-Id
X-Refresh
X-Fastly-Cache-Hits
X-Proxy-Cacherz
X-Nananana
Get-Access-Time
CDN
Is-Session-Tracking
User-Agent
X-Trafficlayer-App-Version
X-Page-Impression-Id
X-Upstream-Ct
Inserted-Into-Cache-At
X-Upstream-Ht
Server-Id
Xkeyrz
Xkeypdq
X-Flow-Id
X-Via-Edge
Locid
X-Via-SSL
X-Served-From
Warning
X-Dw-Trace-Id
Correlation-Id
X-SB
X-MID
X-VC
X-Cf-Powered-By
X-Akamai-SSL-Client-Sid
X-Akamai-ERPolicy
X-NU-AKA-ACS-Version
X-Amzn-Remapped-Date
X-Amzn-Remapped-Connection
X-Akamai-ERRuleID
Gannett-Cam-Experience-Id
X-Pod
X-Req
X-Gamma-Serve
Thinkindot-Cache-Type
SID
Processtime
Who
X-Bug-Bounty
X-Gen-Id
Cneonction
X-Gdpr
V-Cache
X-LB-ID
Xet-Cookie
X-MiniProfiler-Ids
X-LiteSpeed-Tag
HitType
X-Request-URL
RequestId
X-Crawler
X-Newrelic-App-Data
X-ServerName
X-ECache