Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-Powered-By
Pragma
CF-Cache-Status
Link
ETag
Expect-CT
Via
X-XSS-Protection
Age
X-Cache
CF-RAY
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
CF-Ray
P3P
X-Xss-Protection
X-Cache-Hits
X-Amz-Cf-Pop
Referrer-Policy
X-Amz-Cf-Id
X-UA-Compatible
X-Served-By
Alt-Svc
X-Request-Id
X-Varnish
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-FRAME-OPTIONS
X-Drupal-Cache
X-Check
X-Adblock-Key
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-Cacheable
X-Permitted-Cross-Domain-Policies
X-Cache-Status
X-Generator
Timing-Allow-Origin
X-Iinfo
X-Template
X-Language
X-AspNetMvc-Version
Status
Upgrade
X-CDN
X-Ua-Compatible
X-Content-Security-Policy
Content-Encoding
X-Buckets
Access-Control-Expose-Headers
P3p
Access-Control-Max-Age
X-Kinja-Server-Push
X-Via
Keep-Alive
X-Turbo-Charged-By
X-AH-Environment
X-Drupal-Dynamic-Cache
X-Pass-Why
X-Envoy-Upstream-Service-Time
X-Cache-Group
X-Server
X-Ws-Request-Id
X-Backend
X-Age
EagleId
X-Proxy-Cache
X-Amz-Request-Id
X-Amz-Id-2
Xkey
X-Robots-Tag
X-Page-Speed
X-Hacker
X-Request-ID
X-Pingback
X-Server-Powered-By
Server-Timing
X-Swift-CacheTime
X-Swift-SaveTime
Feature-Policy
Ali-Swift-Global-Savetime
Request-Context
X-Nginx-Cache-Status
X-Varnish-Cache
Grace
X-UA-Device
X-Amz-Version-Id
Cf-Railgun
Report-To
X-LiteSpeed-Cache
X-OneAgent-JS-Injection
X-Rq
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Origin-Cache
X-Server-Id
EagleEye-TraceId
X-Backend-Server
X-Host
X-Node
X-Vhost
X-Response-Time
X-Ac
X-Dispatcher
X-Cache-Lookup
NEL
X-Readtime
Surrogate-Control
X-Origin-Upstream-Status
X-WebKit-CSP
Content-Location
Request-Id
X-Ruxit-JS-Agent
X-Application-Context
Fusion-Component-Id
Fusion-Content-Id
Fusion-Content-Source
Fusion-Template-Id
Fusion-Source
X-HW
X-Cnection
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Country
X-Cloud-Trace-Context
X-Mod-Pagespeed
X-DataDome
X-Akam-SW-Version
X-Rack-Cache
Edge-Control
Rating
X-Clacks-Overhead
X-Url
RTSS
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-FTR-Request-ID
X-Vname
X-PC
X-Goog-Hash
X-TtlSet
Allow
X-DynaTrace
X-Instart-Request-ID
X-Country-Code
Content-MD5
X-ASPNET-VERSION
X-Varnish-TTL
Service-Worker-Allowed
Verso
X-GitHub-Request-Id
X-Webkit-Csp
X-ESI
Pinterest-Generated-By
X-Server-Name
X-D2id
X-Cdn-Fetch
X-Exp-Id
X-Kinja-Server
X-Use-Magma
X-Kinja-Revision
X-Kinja-Build
X-Kinja
X-Exp-Variant
X-GoogleNews-Bot
X-MS-InvokeApp
X-Vcache
SPRequestGuid
X-Navigation-Version
X-Powered-By-Plesk
X-Cached
X-Server-ID
X-B3-TraceId
X-Amz-Server-Side-Encryption
X-Forwarded-Proto
X-Debug
X-Abt-Application-Version
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Amz-Rid
Accept-Ch
X-Trace
X-Fastly-Request-ID
X-MSEdge-Ref
Public-Key-Pins
X-SharePointHealthScore
X-Vcap-Request-Id
Nginx-Cache
X-VARITI-CCR
MS-Author-Via
X-Fastcgi-Cache
Charset
TCN
Arr-Disable-Session-Affinity
X-Px
X-NF-Request-ID
X-Accel-Expires
X-Cache-TTL
X-Ttl
Edge-Cache-Tag
Accept-Ch-Lifetime
Pagespeed
Response
X-Middleton-Display
Display
X-Middleton-Response
Realpath
SPIisLatency
SPRequestDuration
X-Sol
Fusion-Deployment-Id
X-Content-Type
X-Version
X-Ser
X-Client-IP
Cache-Tag
X-SRCache-Fetch-Status
X-SRCache-Store-Status
AR-ATIME
Accept-CH
AR-Request-ID
AR-PoweredBy
X-DynaTrace-JS-Agent
X-Powered-CMS
Pinterest-Version
Front-End-Https
X-Pinterest-Rid
Access-Control-Request-Method
X-Id
NR-ENABLED
X-Hp-Webp
X-Jurisdiction
Mrf-Cache-Status
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
X-B3-TraceId-Primal
MRF-Tech
X-Upstream
X-Grace
X-Forwarded-For
AR-CACHE
Ar-Sid
X-Dns-Prefetch-Control
X-Content-Digest
X-T
X-Amz-Meta-S3cmd-Attrs
X-Hits
X-Element-Page-Cache
S
DynaTrace
X-Dw-Request-Base-Id
Accept-CH-Lifetime
Fastcgi-Cache
ServerID
X-Mobile-URL
X-Node-Name
PB-RID
PB-PID
X-Amzn-Trace-Id
X-FTR-Backend
X-FTR-Cache-Status
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Realm
X-FTR-Balancer
X-FTR-DC
X-TTL
X-XRDS-LOCATION
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
X-Recruiting
X-Goog-Stored-Content-Length
X-Cache-Hit
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Metageneration
X-Mobile-Rewrite
Arc-Version
X-HS-Hub-Id
X-FTR-Expires
X-HS-Content-Id
X-HS-Cache-Config
Server-Node
X-Frontend
Powered
X-Shard
X-Ezoic-Cdn
TP-Cache
TP-L2-Cache
X-Shield-Request-Id
X-DIS-Request-ID
AMP-Access-Control-Allow-Source-Origin
Fastly-Restarts
X-NWS-LOG-UUID
Upgrade-Insecure-Requests
X-Request-Received
X-Request-Processing-Time
X-HS-Combine-CSS
Alternate-Protocol
Refresh
X-Logged-In
X-Varnish-Age
WPE-Backend
X-Correlation-Id
X-Microsite
X-Request-Handler-Origin-Region
Server-Name
X-FTR-Cache-Host
MicrosoftSharePointTeamServices
X-LB-Cache
X-B
X-Akamai-Edgescape
X-Content-Security-Policy-Report-Only
X-Page-Id
X-User-Agent
X-F-Cache
X-ATS-Timestamp
X-Rid
Backend-Timing
X-Geo-Country
X-N
X-Via-JSL
Host
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Cache-Status
X-Zen-Fury
X-ORACLE-APMCS-REQUEST-ID
X-ORACLE-APMCS-TAG
X-Content-Options
Host-Header
X-Origin-Server
X-Varnish-Grace
X-Kinsta-Cache
X-Revision
X-B3-Sampled
X-Amz-Apigw-Id
X-AOL-HN
X-TT
X-Amz-Replication-Status
X-ATG-Version
X-App-Environment
X-Tumblr-Pixel
X-XRDS-Location
X-Tumblr-Pixel-0
X-WebKit-CSP-Report-Only
X-Type
X-Instance
X-FB-Debug
X-Jobs
Actual-Object-TTL
Paypal-Debug-Id
X-Tumblr-User
Access-Control-Allow-Method
X-Request-Guid
X-Cache-Action
X-Signature
X-B-Cache
X-Varnish-Backend
X-Content-Powered-By
X-Git-Hash
X-Debug-Info
Fastcgi-Useragent
Healthy
X-Whom
Liferay-Portal
Frame-Options
X-Srv
Section-Io-Cache
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Cache-Key
X-Cluster
X-Cached-By
X-Seen-By
X-Cache-Rule
X-Hostname
X-Daa-Tunnel
X-PHP-Backend
X-Az
X-Activity-Id
X-AppVersion
X-CST
X-Cache-Operation
X-Framework
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-FireWall-Port
Tracecode
X-Cache-Age
X-WA-Info
X-Endurance-Cache-Level
X-Mobile
X-Presslabs-Stats
X-Amzn-Requestid
Retry-After
X-Contextid
X-IPLB-Instance
Xserver
Source
X-Host-Name
X-Response-Served-From
NGB
X-Accel-Buffering
Accept-Charset
X-Upgrade-Enabled
X-ProcessESI
X-RemovedCookies
Surrogate-Key
Eomportal-Instance
DC
X-Is-Bot
X-GeoIP
X-Region
X-Rendered-As
X-FW-Type
X-Tumblr-Pixel-1
X-Tumblr-Pixel-2
X-FW-Serve
X-Cache-NE
Filters
X-Environment-Context
X-FW-Hash
X-FW-Server
X-Varnish-Hostname
X-FW-Static
X-L-Path
X-Adobe-Content
X-Handled-By
X-Cacheable-TTL
Payment
X-Adobe-Loc
X-Varnish-Server
X-RequestSource
X-Origin-Response-Time
Srv
Trailer
X-UUID
X-EdgeConnect-Cache-Status
X-UA-Device-Type
From-Origin
X-Cache-2
Server-Info
X-Backend-Name
X-Cache-TTL-Remaining
X-Proxy
X-Time-Microsecs
X-APP-VERSION
X-RateLimit-Remaining
Cache-Tv-Group
X-Wix-Request-Id
X-Edge-O15-RID
X-Cache-Server
Nel
VIX-Pulpo-Upstream-Status
MS-CV
VIX-Pulpo-Node
X-Oss-Hash-Crc64ecma
X-Oss-Storage-Class
X-Oss-Request-Id
X-FastCGI-Cache
X-Oss-Object-Type
X-Oss-Server-Time
X-Cache-Enabled
X-Akamai-Transformed
X-Dc
Version
X-NGENIX-Cache
Datacenter
X-Status
X-Unique-Id
X-TIME
X-Mode
S-Cnection
X-IPS-LoggedIn
GEO-INFO
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Cache-Var
X-RN-RSRV
X-Cache-Var-Map
X-CCM
Meta-Geo
X-ES-SERVER
FilterID
X-Path-Route
X-TX-ID
X-Hl-Ver
X-ApacheServer
ServedBy
X-NewRelic-App-Data
X-Cache-Time
X-Forwarded-Host
X-Via-Fastly
X-PERF
Decoy-Debug-TTL
X-Pad
Decoy-Debug-Key
Decoy-Debug-Status
X-Redis-Cache
Cache-Tags
Country
X-Cache-Status-Check
Cleartype
X-Goog-Meta-Goog-Reserved-File-Mtime
X-FW-Dynamic
X-Akamai-Request-ID2
X-Tb
X-LJ-Flow-ID
X-ServerID
Origin-Cache-Control
X-Debug-Cache
Now
X-AWS-Id
DB-Nickname
Akamai-GRN
X-Device-Type
Origin-Edge-Control
X-Cache-Control
X-FC-Vary-Parameters
OT-Force-Account-Verify
X-Hosted-By
X-Varnish-Hits
X-Origin
X-VWS-Id
X-Proto
X-R9-Blue-Green-Version
X-Pubstack
X-Vgn-Hpd-Reason
Content-Disposition
Cross-Origin-Window-Policy
X-Www-Served-By
X-Zipkin-Id
Property-Id
TWC-Connection-Speed
X-Say-TTL
X-SayCDN-TTL
TWC-Device-Class
X-Say-Cacheable
Cache-Key
X-Routing-Service
X-SaId
X-Web-Node
X-Cache-Config
Selected-Fe
X-Alternate-Cache-Key
X-Proxy-Cache-Status
X-Proxy-Build
X-Access
Webserver
X-Amzn-Remapped-Content-Length
X-ProxyCache-Key
X-BYPASS-REASON
X-Detected-As
Mn-Server-Ip
NGX
X-ProxyCache-Status
X-Viewer-Country
Ec-Rule-Version
TWC-GeoIP-Country
X-Proxied
X-Site-Version
X-NCache
X-Shopify-Stage
Webcakes-Region
X-Origin-Hint
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Loop
X-Locale
X-Soup
X-JoinUs
X-Human
X-IP
X-Timing-Wait
X-Shopify-Generated-Cart-Token
X-Format
TWC-Locale-Group
TWC-GeoIP-LatLong
X-EIG-Tracking-Id
X-Section
X-ShopId
X-ShardId
Webcakes-App-Name
X-Generated
Webcakes-App-Version
TWC-Privacy
X-TNCMS
X-MP-GENERATED-AT
X-Generated-By
X-NYM-Debug-Backend
X-Akamai-Request-ID
X-RCS-CacheZone
X-Xfnlog-Site
X-FB-TRIP-ID
S-Rt
Azure-Version
Azure-InstanceId
Azure-RegionName
X-SS-Set-Cookie
Filterid
Azure-SlotName
X-Ua-Device
Azure-SiteName
X-HTML-Minification-Powered-By
Access-Control-Request-Headers
X-Content-Age
X-Request-Time
X-BCube-Filmed-By
X-Geo
X-Cache-Remote
X-Real-IP
Node
Cache-Hits
X-Amzn-RequestId
X-EC-Lua
X-App-Server
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Io-Id
Section-Origin-Responded
X-B3-Traceid
Accept-Language
X-Drupal-Cache-Tags
X-Uri
X-PressLabs-Stats
X-No-Session
X-Adobe-Source
X-Rule
X-Microcachable
Odigeo-Trace-Id
X-PCL
X-OCL
Cf-Ipcountry
X-CACHE-KEY
X-UA
X-Qloud-Router
Ms-Operation-Id
X-RTag
X-NWS-UUID-VERIFY
X-Varnish-Cache-Hits
X-Source
Time
X-Azure-Ref
User-Agent
X-Hyper-Cache
X-From
X-Esi
X-Nc
X-PHP-Host
X-Labrador-Cache-Channel
Proxy-Connection
X-Time
X-Storage
X-Cache-NGX
X-Info
X-Load-Cache
X-Cluster-Node
X-Backend-TTL
X-RateLimit-Limit
X-Old-Content-Length
X-CF-Powered-By
X-Nginx-Cache
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
X-ARC
X-DPWN-IS-SECURE
X-A-Wwc
X-Request-URI
Mobile-Detection-Method
X-Aed
X-Request-UUID
X-Rewrite-Enabled
X-PAYTM-SRV-ID
X-OVcl-Cache
X-Processor
X-Accel-Expires-Debug
X-OVcl
X-Application
X-Region-Sid
X-A-Dam
T-Server
ServerName
GEO-REGION-INFO
Fastcgi-X-Cache-Version
True-Client-Country-4JS
Viewtype
Content-Script-Type
Content-Style-Type
Meta-Geo-Continent
X-External-Request-Id
Rendered-Blocks
Machine
X-GeoIP-Country-Code
MD5-Digest
Request-Country
X-G
Request-EU
VivaBuild
X-A
X-Cache-Grace
X-A-Dcw
A
Uber-Trace-Id
Cache-Name
X-GoCache-CacheStatus
X-A-Dgt
X-A-Ccd
Apple-News-Services-Handled
Arc-Country
AsisCache
BehaviorPad-Version
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
X-Rojux
Apple-News-Services-Host
X-Drupal-Cache-Contexts
X-ScT
X-Twitter-Response-Tags
Powered-By-ChinaCache
X-Vdms-Version
X-VG-WebCache
X-Trv-Group
X-TA-CDN-Provider
X-Destination
X-Transaction
X-UnsetCookies
X-VG-WebServer
X-Vtex-Processado-Em
Xc-Version
X-D
X-Connection-Hash
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-Vtex-Remote-Cache
X-Magnolia-Registration
X-Cdn-Srv
X-SRCache-Key
X-Date
X-Session-Fingerprint
X-B-Cookie
X-S
X-S-Cookie
X-Developer
Rt-Fastcgi-Cache
X-Cluster-Name
X-CS
X-Newrelic-Synthetics
X-Cdn-Origin
X-ServiceProvider
X-Geo-Header
X-Rocket-Nginx-Bypass
Server-Host
X-Served-From
X-VG-TLSProxy
Viewport
X-Cache-Expired-At
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Sn-Servicetimems
X-GeoIP-City
X-Thinkindot-L3
X-Edge-Location
Thinkindot-CacheControl-Type
PFcat
Thinkindot-CacheControl
X-Generated-On
Thinkindot-Control
X-Matched-Rule
X-Level-Front-Cache
X-Reboot
X-Service
X-Trafficlayer-App-Name
X-Trafficlayer-App-Scope
X-Trafficlayer-App-Version
X-Varnish-Ttl
X-Auto-Login
X-CGP
X-Cms-Context
X-Gen-Mode
X-Generated-In
X-CUA
X-Generation-Time
X-Core-Mission
Pramga
X-Gamma-Serve
RNT-Time
X-Fetched-On
RNT-Machine
X-FW-Version
X-Clara-WADP
Server-ID
X-Cache-Info
X-Debug-Cache-Store
X-Agile
X-Device-Os
X-App-Name
X-Bip
X-Debug-Cache-Fetch
X-Agile-Age
X-Debug-Cookies
X-Dispatcher-Server
X-Distil-CS
X-Dispatch
X-Agile-Id
X-Debug-Log
X-Bc-Bl
X-Block-Status
X-Backend-State
We-Hiring
V-Age
User-Cache-Control
X-Eu-Site
Web-Mar-Node
X-BBXSRF
X-Debug-Cache-Expiry
X-C
X-Cache-Bucket
X-Cache-FS-Status
X-Developers
X-Cache-URL
X-Nginx-Cache-Key
X-Varnish-Beresp-Ttl
X-Request-Host
X-RateLimit-Remaining-Second
X-Rocket-Build-Number
X-Server-W
X-SIPLIST1
X-Sigma-Backend
X-Sigma
X-RateLimit-Limit-Second
X-Proxy-Upstream
X-NodeID
X-Core-Value
X-ND-Cache
X-NX-Host
On-Server
X-Owner
X-Origin-Expires
X-Slack-Backend
X-Swa-Ws
X-WebServer
X-WADP-Cache
X-VServer
X-Webstats-RespID
X-Wikidot-Backend
Mime-Version
X-Wikidot-Static-Cache
X-VC-Cache
X-Varnish-Cacheable
X-TrackingId
X-Trace-Id
X-Thanos
X-TT-TIMESTAMP
X-Tumblr-Pixel-3
X-Urbn-Site-Id
X-Urbn-Context-Path
X-Ms-Version
X-Origin-Date
X-Irp-Debug
X-Instart-Isnd
Memcached
X-Is-Gdpr
L5d-Success-Class
Locale
X-JWT-State
X-Hnp-Log
X-Ms-Request-Id
Heartbleed
Mail-Subject
HA-Ipaddr
Ha-Gx-Prefs
Gh-Request-Id
Group
Locid
X-Li-Fabric
X-Micro-Cache
N-Cache
Kp-EeAlive
CDCHOST
AKAMAI
Cache-Host
X-Hash
X-Logging-Id
X-Has-Esi
Country-Code
X-LI-UUID
X-Li-Pop
X-LI-Proto
IsBot
X-S-Maxage
X-We-Are-Hiring
FNAC-ModuleRouting
X-Req
X-Backend-Host
Wxu-Next-Region
Wxu-Next-Hostname
Wxu-Next-Commit
X-Fastly-Cache
X-DevSite-Last-Modified
X-Lb-Id
X-Platform-Server
X-Epic-Correlation-Id
X-Distributor
X-LAGOON
X-Servername
X-Variation
X-Var-Ttl
X-Hit
X-Skip-Cache
X-Varnish-Authentication
X-Cache-Tags
Countrycode
Cloudfront-Viewer-Country
Adler-Geo
Fastly-Drupal-HTML
Is-Eu
Server-Surrogate-Control
Server-Cache-Control
Platform
W
HitType
X-Clientip
X-Cache-ASPX
X-Contensis-Viewer-Groups
X-Node-Id
X-Sucuri-ID
X-Rebelmouse-Surrogate-Control
X-BACKEND-TTL
X-Response-By
Fastly-SIE
X-Ratelimit-Remaining
Environment
X-Rebelmouse-Cache-Control
Fastly-SWR
Geo-Info
X-VHOST
Hostname
Cache-Cookie-Set-From
Cache-Cookie-Set-Lfrom
X-RESPONSE-TIME
X-Fmm-Version
Cache-Cookie-Set-Idcheck
X-VCT
X-URL
X-NC
X-Scheme
X-CLOUD-TRACE-CONTEXT
X-Parent-Response-Time
X-Refresh
X-Cdn-Forward
Cache
X-Pjax-Url
X-B3-Spanid
X-Origin-TTL
X-CSRF-Token
X-Origin-CC
X-Instart-Info
X-VCache
X-APP
X-Up
Fastly-Backend-Name
SD-X-WS
X-SN
X-Varnish-URL
X-MCACHE
X-FPC
X-Server-Time
Geoip-Latitude
Origin
X-Edge
Proxy-Firewall
Geoip-City
X-App-Version
X-MSEdge-Flight
X-TT-LOGID
X-MSEdge-Features
X-CDN-Forward
X-Correlation-ID
Cdn-Host
PICS-Label
Pragrma
Vix-Hermes-Req-Id
X-Edge-Server
M-TraceId
GeoIp-Country-Code
Cdn-Request-Time
X-Vcl-Version
X-Cache-PHP
TTL
Request-Time
X-CSRF-TOKEN
NM-Fastcgi-Cache
CACHE
X-Vdms-Path
X-ECache
X-Wix-Viewer-Type
Cdncip
Cdnsip
X-AK-Request-ID
CF-Cached-On
X-Cache-Host
X-Be
Ohc-File-Size
X-HS-Status
X-SVT-ORM-RULES
X-Mid
X-Wa
X-SVT-ORM-VERSION
NtCoent-Length
Sever-Int
Pagetype
Server-Ext
X-NU-AKA-ACS-Version
X-Air-Hostname
Server-Hostname
X-Ratelimit-Limit
X-ECACHE
X-Myra-Origin2
X-ServedByHost
Cdn
X-Ua
HostName
SRV
X-Cache-Debug
Memory
X-Bc
Magicmarker
X-Method
RequestId
X-Zone
Resin-Trace
X-Pf-Uncompressing
X-Cache-Metadata
Tcn
Ohc-Cache-HIT
X-Worker
X-TH-Server
Cteonnt-Length
X-BC
X-ZONE
X-Via-PopH
X-Via-PopV
X-Dynatrace-Js-Agent
X-Swift-Error
X-Newrelic-App-Data
X-Branch-Name
X-Oneagent-Js-Injection
X-Protected-By
X-Request-Start
X-Referer
Release
IBM-Web2-Location
X-FORWARDED-FOR
X-NGINX-Cache
X-GEO
Server-Int
X-Servedbyhost
Load-Balancing
Dt-Cache-Category
X-Policy
X-Envoy-Upstream-Healthchecked-Cluster
X-Azure-Ref-OriginShield
Dnion-Transfer-Encoding
X-Unique-ID
XServer
X-Ocache
X-Tb-Optimization-Total-Bytes-Saved
X-Planisys-CDN-Cache
X-Fastly-Country-Code
Lb
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
Powered-By
X-Esi-Check
X-Tec-Api-Version
X-Tec-Api-Root
Esi-Enabled
X-Configured-By
X-C-Zone
X-Reqid
X-Cache-Id
X-Tec-Api-Origin
X-C-Key
X-AIR-PT
X-WA
X-Ruxit-Js-Agent
X-DC
X-Node-ID
X-COUNTRY
Ttl
Who
X-Gzip
Pics-Label
X-VCL-Version
X-B3-SpanId
X-Datadome
Fastly-Soc-X-Request-Id
Fastly-SSL
GeoIP-Country-Code
X-Via-Ucdn
X-Action
X-SRV
MIME-Version
X-Hello
X-ABtesting
X-DSS
X-DB
X-DW
X-DI
X-VarnishDD-TTL
X-RPM
UCS
X-Country-IP
X-RPS
X-RSL
GeoIP-Latitude
GeoIP-City
X-Flog
X-HostName
X-Varnish-Url
Product
LB
X-RAMCache
X-Svr
X-Powered-Y
X-Fpc
FSS-Cache
X-WPE-Loopback-Upstream-Addr
X-SERVER-NAME
X-PF-Uncompressing
Host-ID
X-Cache-Backend
X-Fastly-Backend-Reqs
X-Amzn-Remapped-Date
X-Fastly-Request-Id
X-Render-Time
X-PJAX-URL
X-Via-CDN
X-Amzn-Remapped-Connection
Lfy
ProcessTime
X-Pinterest-Direct
X-Varnish-Beresp-TTL
X-MID
Sid
FSS-Proxy
X-Server-IP
X-UPSTREAM-Address
X-SD-PageType
X-User
X-Page-Impression-Id
X-Flow-Id
X-Zalando-Child-Request-Id
Amp-Access-Control-Allow-Source-Origin
X-Beluga-Record
Xet-Cookie
X-Beluga-Response-Time
X-Beluga-Node
X-Beluga-Status
X-Beluga-Trace
X-Beluga-Cache-Status
X-Agile-Brick-Ok
X-Internal-Host
X-Apw-Hits
Requestid
X-Apw-Access-Token
X-Apw-Access-Action
X-LiteSpeed-Cache-Control
X-Key
Cneonction
X-Apw-Access-Object
CF-IPCountry
X-Tid
X-B3-Parentspanid
L
SN
X-Sucuri-Cache
WZWS-RAY
CDN
X-Check-Cacheable
X-Compress-Hint
X-Aicache-OS
X-Debug-Revision
X-BE
X-Debug-Controller
X-Litespeed-Cache-Control
X-Sucuri-Id
CloudFront-Viewer-Country
X-MiniProfiler-Ids
C-Via
X-LB-ID
X-Nananana
X-ElasticPress-Search
X-Request-URL
DataCenter
X-Location
X-Request-Url
X-Fastly-Cache-Hits
X-Dw-Trace-Id
X-App