Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-Powered-By
Pragma
CF-Cache-Status
Link
ETag
Expect-CT
Via
Age
X-Cache
CF-RAY
X-XSS-Protection
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-Xss-Protection
X-Cache-Hits
X-Amz-Cf-Pop
Referrer-Policy
P3P
CF-Ray
X-Amz-Cf-Id
X-UA-Compatible
X-Served-By
Alt-Svc
X-Varnish
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-FRAME-OPTIONS
X-Drupal-Cache
X-Check
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Cacheable
X-Permitted-Cross-Domain-Policies
X-DNS-Prefetch-Control
X-Cache-Status
X-Generator
Timing-Allow-Origin
X-Iinfo
P3p
X-Ua-Compatible
X-Template
X-Language
X-AspNetMvc-Version
Status
Upgrade
X-CDN
X-Content-Security-Policy
X-Buckets
Content-Encoding
Access-Control-Expose-Headers
X-Request-ID
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Via
X-Turbo-Charged-By
X-AH-Environment
X-Drupal-Dynamic-Cache
X-Envoy-Upstream-Service-Time
X-Cache-Group
X-Pass-Why
X-Ws-Request-Id
X-Backend
X-Age
X-Server
EagleId
X-Proxy-Cache
X-Amz-Id-2
X-Amz-Request-Id
Xkey
X-Robots-Tag
X-Page-Speed
X-Hacker
X-Pingback
X-Server-Powered-By
Feature-Policy
Server-Timing
X-Swift-CacheTime
X-Swift-SaveTime
Request-Context
Ali-Swift-Global-Savetime
X-Nginx-Cache-Status
Grace
X-Varnish-Cache
X-UA-Device
X-Amz-Version-Id
Cf-Railgun
Report-To
X-OneAgent-JS-Injection
X-Rq
X-LiteSpeed-Cache
X-Device
X-Origin-Cache
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Server-Id
EagleEye-TraceId
X-Backend-Server
X-Host
X-Node
X-Vhost
X-Response-Time
NEL
X-Dispatcher
X-WebKit-CSP
X-Ac
X-Cache-Lookup
X-Readtime
X-Origin-Upstream-Status
Surrogate-Control
Request-Id
Content-Location
X-Ruxit-JS-Agent
X-Application-Context
Fusion-Component-Id
Fusion-Source
Fusion-Content-Source
Fusion-Template-Id
Fusion-Content-Id
X-HW
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Cnection
X-DataDome
X-Country
X-Mod-Pagespeed
X-Cloud-Trace-Context
X-Akam-SW-Version
Edge-Control
X-Rack-Cache
Rating
X-Url
X-Clacks-Overhead
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
RTSS
X-FTR-Request-ID
X-PC
X-Vname
X-TtlSet
X-Goog-Hash
X-Country-Code
X-Varnish-TTL
X-ASPNET-VERSION
X-DynaTrace
X-Instart-Request-ID
Service-Worker-Allowed
Allow
X-GitHub-Request-Id
Verso
X-Dns-Prefetch-Control
Content-MD5
X-Server-Name
X-D2id
Pinterest-Generated-By
X-Exp-Variant
X-Exp-Id
X-Use-Magma
X-GoogleNews-Bot
X-Kinja
X-Kinja-Revision
X-Cdn-Fetch
X-Kinja-Server
X-Kinja-Build
X-MS-InvokeApp
X-ESI
X-Server-ID
SPRequestGuid
X-Cached
Fusion-Deployment-Id
X-Powered-By-Plesk
X-Navigation-Version
X-Forwarded-Proto
TCN
X-Abt-Application-Version
X-Amz-Server-Side-Encryption
X-Trace
X-Amz-Rid
X-B3-TraceId
Public-Key-Pins
X-Vcache
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Debug
X-Fastly-Request-ID
X-SharePointHealthScore
Nginx-Cache
X-Ttl
X-MSEdge-Ref
X-Vcap-Request-Id
Accept-CH
X-VARITI-CCR
Charset
Arr-Disable-Session-Affinity
MS-Author-Via
X-Accel-Expires
X-Px
X-Cache-TTL
X-NF-Request-ID
SPRequestDuration
SPIisLatency
Pagespeed
X-Middleton-Response
Display
X-Middleton-Display
Response
Realpath
Edge-Cache-Tag
X-Content-Type
Accept-CH-Lifetime
X-Fastcgi-Cache
X-Sol
Accept-Ch
X-Ser
X-Client-IP
X-DynaTrace-JS-Agent
Cache-Tag
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Version
NR-ENABLED
X-Powered-CMS
Front-End-Https
X-Webkit-Csp
X-Pinterest-Rid
Pinterest-Version
X-Id
Access-Control-Request-Method
X-Grace
X-Jurisdiction
X-Upstream
X-Hp-Webp
AR-ATIME
S
AR-PoweredBy
AR-Request-ID
Accept-Ch-Lifetime
X-T
X-Hits
X-Content-Digest
X-Amz-Meta-S3cmd-Attrs
X-Element-Page-Cache
Mrf-Cache-Status
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
MRF-Tech
X-Forwarded-For
DynaTrace
X-Dw-Request-Base-Id
Ar-Sid
AR-CACHE
Fastcgi-Cache
X-Shield-Request-Id
X-Node-Name
ServerID
X-Mobile-URL
X-Cache-Hit
WPE-Backend
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-Cache-Status
X-Country-Code-Real
X-Recruiting
X-FTR-Realm
X-FTR-Backend
X-FTR-DC
PB-PID
PB-RID
Server-Node
X-GUploader-UploadID
Powered
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Storage-Class
X-HS-Cache-Config
TP-Cache
X-Frontend
X-HS-Content-Id
X-HS-Hub-Id
TP-L2-Cache
Arc-Version
X-FTR-Expires
X-Mobile-Rewrite
AMP-Access-Control-Allow-Source-Origin
X-XRDS-Location
X-DIS-Request-ID
Upgrade-Insecure-Requests
X-Amzn-Trace-Id
X-Request-Received
X-Request-Processing-Time
X-Ezoic-Cdn
X-Shard
Refresh
X-HS-Combine-CSS
Alternate-Protocol
X-NWS-LOG-UUID
X-Correlation-Id
Fastly-Restarts
X-Logged-In
X-Varnish-Age
X-TTL
X-Request-Handler-Origin-Region
X-Microsite
Server-Name
X-FTR-Cache-Host
X-F-Cache
X-Geo-Country
X-B
X-Page-Id
X-Akamai-Edgescape
X-User-Agent
X-N
Backend-Timing
X-ATS-Timestamp
X-LB-Cache
X-Rid
Host-Header
MicrosoftSharePointTeamServices
X-Content-Security-Policy-Report-Only
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Via-JSL
Host
X-Zen-Fury
X-XRDS-LOCATION
X-Origin-Server
X-Varnish-Grace
Cache-Status
X-ORACLE-APMCS-REQUEST-ID
X-ORACLE-APMCS-TAG
X-Kinsta-Cache
X-Content-Options
Healthy
X-Request-Guid
Fastcgi-Useragent
X-Hostname
X-B3-Sampled
X-B-Cache
X-Revision
X-Git-Hash
X-Instance
X-ATG-Version
X-Signature
X-FB-Debug
X-AOL-HN
X-App-Environment
Section-Io-Cache
Access-Control-Allow-Method
X-TT
Frame-Options
X-Type
Paypal-Debug-Id
X-Jobs
X-Amz-Replication-Status
X-Cache-Action
X-Debug-Info
X-Whom
X-Varnish-Backend
X-Tumblr-User
X-Tumblr-Pixel-0
Actual-Object-TTL
X-Tumblr-Pixel
Trailer
X-WebKit-CSP-Report-Only
X-Cluster
Liferay-Portal
X-Seen-By
X-Amz-Apigw-Id
X-Content-Powered-By
X-Cache-Rule
X-Cache-Operation
X-Tt-Trace-Tag
X-Cache-Age
X-Tt-Trace-Host
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-FastCGI-Cache
X-Contextid
Tracecode
X-Cache-Key
X-FireWall-Port
X-PHP-Backend
X-Amzn-Requestid
X-Endurance-Cache-Level
X-Activity-Id
X-AppVersion
X-Az
X-Host-Name
X-Framework
X-Daa-Tunnel
X-WA-Info
Source
X-Cached-By
Retry-After
X-IPLB-Instance
X-Presslabs-Stats
X-Upgrade-Enabled
X-Srv
X-Mobile
Accept-Charset
X-Response-Served-From
NGB
X-Accel-Buffering
X-RemovedCookies
X-ProcessESI
Srv
X-Rendered-As
X-UUID
X-Is-Bot
DC
X-FW-Type
X-Handled-By
X-FW-Static
X-RateLimit-Remaining
X-FW-Server
X-FW-Hash
Xserver
X-FW-Serve
X-Adobe-Loc
Surrogate-Key
X-Adobe-Content
X-Cacheable-TTL
Payment
X-GeoIP
X-L-Path
X-RequestSource
Eomportal-Instance
X-Region
X-Environment-Context
X-Varnish-Server
X-Cache-NE
X-Tumblr-Pixel-1
X-Tumblr-Pixel-2
From-Origin
Filters
X-Origin-Response-Time
X-Varnish-Hostname
X-UA-Device-Type
X-Cache-TTL-Remaining
X-Time-Microsecs
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Wix-Request-Id
X-Proxy
X-EdgeConnect-Cache-Status
Filterid
X-Cache-Server
Server-Info
X-APP-VERSION
X-NGENIX-Cache
X-Cache-2
Cache-Tv-Group
X-Unique-Id
X-Backend-Name
Datacenter
X-Esi
MS-CV
Version
X-TIME
X-Akamai-Transformed
X-Cache-Time
X-Cache-Enabled
X-Status
X-Oss-Object-Type
X-Oss-Server-Time
X-Oss-Request-Id
X-CST
X-Cache-Control
X-Oss-Hash-Crc64ecma
X-Oss-Storage-Class
X-Mode
S-Cnection
X-Yottaa-Optimizations
X-Yottaa-Metrics
GEO-INFO
Meta-Geo
X-CCM
X-Cache-Var
X-Cache-Var-Map
X-ES-SERVER
X-Path-Route
X-Loop
X-TNCMS
X-IP
X-Detected-As
X-RN-RSRV
Ec-Rule-Version
X-TX-ID
X-ApacheServer
S-Rt
ServedBy
X-Proto
Webserver
Country
X-PERF
OT-Force-Account-Verify
X-FW-Dynamic
X-Forwarded-Host
Cache-Tags
X-R9-Blue-Green-Version
X-Ua-Device
X-Via-Fastly
X-Adobe-Source
X-AWS-Id
Decoy-Debug-Key
Cache-Key
Section-Io-Origin-Time-Seconds
DB-Nickname
Content-Disposition
Decoy-Debug-Status
Section-Io-Origin-Status
X-Akamai-Request-ID2
Cleartype
Section-Origin-Responded
Webcakes-Region
X-Alternate-Cache-Key
TWC-GeoIP-Country
Origin-Edge-Control
Akamai-GRN
Access-Control-Request-Headers
TWC-Locale-Group
TWC-GeoIP-LatLong
NGX
Property-Id
Webcakes-App-Name
Webcakes-App-Version
Section-Io-Id
TWC-Privacy
X-Amzn-Remapped-Content-Length
TWC-Device-Class
TWC-Connection-Speed
Decoy-Debug-TTL
X-Redis-Cache
X-Proxy-Cache-Status
X-Shopify-Generated-Cart-Token
X-ShopId
X-Shopify-Stage
X-Origin-Hint
X-Sorting-Hat-PodId
X-Origin
X-Pubstack
X-RCS-CacheZone
X-Say-TTL
X-SayCDN-TTL
X-Say-Cacheable
X-ShardId
X-Real-IP
Origin-Cache-Control
X-Sorting-Hat-ShopId
X-Soup
X-EIG-Tracking-Id
X-Web-Node
X-Device-Type
X-Debug-Cache
X-Cache-Status-Check
X-VWS-Id
X-FC-Vary-Parameters
X-Locale
X-LJ-Flow-ID
X-Human
X-Hosted-By
X-Tb
X-Xfnlog-Site
X-Zipkin-Id
X-ServerID
X-Site-Version
X-Section
X-Vgn-Hpd-Reason
X-Www-Served-By
X-ProxyCache-Status
X-Format
X-Generated
X-Goog-Meta-Goog-Reserved-File-Mtime
X-FB-TRIP-ID
X-BCube-Filmed-By
X-BYPASS-REASON
X-Content-Age
X-Access
X-MP-GENERATED-AT
X-Cache-Config
X-Request-Time
X-ProxyCache-Key
X-Proxied
X-NCache
X-NYM-Debug-Backend
X-Routing-Service
Mn-Server-Ip
Azure-SiteName
Azure-Version
Azure-RegionName
Azure-InstanceId
X-HTML-Minification-Powered-By
X-Aspnetmvc-Version
Cross-Origin-Window-Policy
Azure-SlotName
Now
Node
X-Hl-Ver
X-Viewer-Country
X-SaId
X-JoinUs
X-Dc
X-IPS-LoggedIn
X-Akamai-Request-ID
Cache-Hits
X-Varnish-Hits
X-Pad
X-Cdn
X-Cache-Remote
X-CACHE-KEY
X-Timing-Wait
Selected-Fe
X-Proxy-Build
X-Generated-By
Odigeo-Trace-Id
X-B3-Traceid
X-EC-Lua
X-Geo
X-No-Session
X-PressLabs-Stats
Nel
X-Microcachable
X-NewRelic-App-Data
X-Rule
X-Drupal-Cache-Tags
Accept-Language
X-Amzn-RequestId
X-Cache-NGX
X-Backend-TTL
Time
Cf-Ipcountry
X-Azure-Ref
X-From
X-Uri
X-RateLimit-Limit
X-SS-Set-Cookie
X-Webkit-CSP
FilterID
X-NWS-UUID-VERIFY
X-App-Server
X-Source
X-RTag
X-CF-Powered-By
Ms-Operation-Id
X-OCL
X-Qloud-Router
X-PCL
User-Agent
X-PHP-Host
X-Labrador-Cache-Channel
X-Varnish-Cache-Hits
X-SERVER
X-GoCache-CacheStatus
X-Old-Content-Length
Proxy-Connection
X-Hyper-Cache
Uber-Trace-Id
X-Nginx-Cache
X-NC
Cache-Name
X-Cache-Grace
X-Info
X-Storage
X-Drupal-Cache-Contexts
X-Newrelic-Synthetics
X-CS
Request-Country
Request-EU
ServerName
X-Processor
T-Server
X-Aed
X-CF-Lambda-Fn
X-OVcl
X-Cdn-Srv
X-OVcl-Cache
Rendered-Blocks
True-Client-Country-4JS
Viewtype
X-A-Dcw
X-A-Dam
X-A-Dgt
X-A-Wwc
X-Accel-Expires-Debug
X-A-Ccd
X-A
VivaBuild
X-B-Cookie
X-ARC
X-Application
X-CF-Lambda-Version
X-Edge-Location
GEO-REGION-INFO
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Handled
X-External-Request-Id
X-G
X-GeoIP-Country-Code
AsisCache
Arc-Country
Fastcgi-X-Cache-Version
A
X-DPWN-IS-SECURE
Meta-Geo-Continent
Mobile-Detection-Method
X-VCT
X-Connection-Hash
MD5-Digest
Machine
X-Developer
X-Destination
X-Date
X-D
BehaviorPad-Version
X-PAYTM-SRV-ID
X-Vtex-Remote-Cache
X-Rojux
X-S
X-S-Cookie
X-Edge-O15-RID
X-Rewrite-Enabled
X-Request-UUID
X-Request-URI
X-VG-WebCache
X-Vtex-Processado-Em
X-VG-WebServer
X-Region-Sid
X-Transaction
X-Trv-Group
Xc-Version
X-Twitter-Response-Tags
X-Litespeed-Cache
X-SRCache-Key
X-Reboot
X-Session-Fingerprint
X-Vdms-Version
X-ScT
X-VCache
X-Time
X-GeoIP-City
Content-Style-Type
X-Geo-Header
X-Generated-On
X-FW-Version
X-Sn-Servicetimems
Content-Script-Type
X-Has-Esi
X-Is-Gdpr
Cache-Cookie-Set-Lfrom
Thinkindot-Control
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
Server-Host
Rt-Fastcgi-Cache
X-Varnish-Beresp-Status
X-Core-Value
PFcat
Memcached
N-Cache
X-Varnish-Beresp-Grace
X-Trafficlayer-App-Version
X-Cdn-Origin
X-Thinkindot-L3
X-DevSite-Last-Modified
X-Trafficlayer-App-Name
X-Trafficlayer-App-Scope
Cache-Cookie-Set-Idcheck
X-Cluster-Node
X-LI-Proto
X-Served-From
X-Backend-State
X-JWT-State
X-Li-Pop
X-Li-Fabric
Cache-Cookie-Set-From
X-UA
X-Rocket-Nginx-Bypass
X-LI-UUID
X-Level-Front-Cache
X-ServiceProvider
X-VG-TLSProxy
X-Matched-Rule
X-VServer
X-Servername
User-Cache-Control
X-S-Maxage
X-Cluster-Name
X-Agile-Id
X-Variation
X-Var-Ttl
X-WADP-Cache
X-Agile
X-Clara-WADP
X-App-Name
X-Urbn-Context-Path
X-Cms-Context
X-CGP
X-Urbn-Site-Id
X-We-Are-Hiring
X-Backend-Host
X-BBXSRF
X-Cache-Bucket
X-Block-Status
X-Wikidot-Static-Cache
X-Contensis-Viewer-Groups
X-Bc-Bl
X-Wikidot-Backend
X-Cache-Expired-At
X-Agile-Age
X-Cache-URL
X-VC-Cache
X-Varnish-Cacheable
X-Cache-Tags
X-Cache-Info
X-Cache-FS-Status
X-Webstats-RespID
X-Varnish-Authentication
X-Fetched-On
X-Logging-Id
X-Micro-Cache
X-Ms-Request-Id
X-Ms-Version
X-Scheme
X-LAGOON
X-Instart-Isnd
X-Skip-Cache
X-SIPLIST1
X-Server-W
X-Nginx-Cache-Key
X-NodeID
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Proxy-Upstream
X-RateLimit-Remaining-Second
X-Platform-Server
X-Owner
X-NX-Host
X-Origin-Date
X-Origin-Expires
X-Req
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-Device-Os
X-Dispatch
X-Dispatcher-Server
X-Distributor
X-Developers
X-Debug-Log
X-TT-TIMESTAMP
X-Core-Mission
X-CUA
X-Debug-Cookies
X-Trace-Id
X-Epic-Correlation-Id
X-Gen-Mode
X-Slack-Backend
X-Hash
X-Hnp-Log
X-Gamma-Serve
X-Fmm-Version
X-Eu-Site
X-Swa-Ws
X-Fastly-Cache
X-RateLimit-Limit-Second
X-Tumblr-Pixel-3
X-Cache-ASPX
Platform
CDCHOST
Country-Code
On-Server
Mail-Subject
Cache-Host
AKAMAI
Adler-Geo
Server-Cache-Control
Ha-Gx-Prefs
RNT-Machine
Locid
Locale
Is-Eu
IsBot
Heartbleed
HA-Ipaddr
Group
Kp-EeAlive
FNAC-ModuleRouting
L5d-Success-Class
Fastly-Drupal-HTML
Fastly-SIE
Fastly-SWR
Server-ID
RNT-Time
V-Age
We-Hiring
Web-Mar-Node
Wxu-Next-Commit
Wxu-Next-Hostname
Viewport
W
Server-Surrogate-Control
X-Varnish-Beresp-Ttl
Wxu-Next-Region
X-Thanos
X-UnsetCookies
X-Nc
X-WebServer
X-Distil-CS
Gh-Request-Id
Cache
X-TrackingId
X-Generated-In
X-Irp-Debug
X-Rocket-Build-Number
X-Response-By
X-Request-Host
X-Sucuri-ID
X-Hit
X-Sigma
Geo-Info
X-Generation-Time
Countrycode
Powered-By-ChinaCache
X-Magnolia-Registration
X-Sigma-Backend
X-Auto-Login
X-Clientip
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Bip
X-Debug-Cache-Expiry
X-C
X-VHOST
X-Node-Id
Mime-Version
X-Instart-Info
SD-X-WS
X-Edge
X-Refresh
X-RESPONSE-TIME
X-MCACHE
X-URL
Pramga
X-Lb-Id
X-CDN-Forward
Cloudfront-Viewer-Country
X-APP
X-Service
Proxy-Firewall
X-SN
X-CLOUD-TRACE-CONTEXT
X-ND-Cache
X-TA-CDN-Provider
X-Load-Cache
HitType
X-B3-Spanid
Vix-Hermes-Req-Id
X-ECACHE
Environment
Request-Time
X-Varnish-URL
X-Pjax-Url
X-Mid
M-TraceId
X-Varnish-Ttl
Origin
X-Cache-PHP
X-Parent-Response-Time
X-Wa
X-Vdms-Path
NM-Fastcgi-Cache
X-App-Version
CF-Cached-On
X-MSEdge-Flight
X-Correlation-ID
X-CSRF-Token
X-BACKEND-TTL
X-MSEdge-Features
X-CSRF-TOKEN
Hostname
Sever-Int
X-Ua
Server-Hostname
X-Up
Pagetype
Server-Ext
Fastly-Backend-Name
PICS-Label
X-Origin-TTL
X-Be
X-Origin-CC
X-Ratelimit-Remaining
Geoip-City
Geoip-Latitude
X-FPC
HostName
X-Method
X-COUNTRY
X-Wix-Viewer-Type
GeoIp-Country-Code
X-Pinterest-Direct
X-Server-Time
X-Cdn-Forward
Pragrma
Cdn-Request-Time
Cdn-Host
X-Via-PopH
X-Worker
Magicmarker
X-TT-LOGID
X-Edge-Server
X-Via-PopV
X-FORWARDED-FOR
X-Protected-By
X-ECache
NtCoent-Length
X-Servedbyhost
X-Myra-Origin2
X-Envoy-Upstream-Healthchecked-Cluster
X-Newrelic-App-Data
X-Branch-Name
TTL
Cdn
X-HS-Status
X-DC
X-AK-Request-ID
Memory
Cdncip
X-Referer
X-Request-Start
Cdnsip
X-Azure-Ref-OriginShield
X-Vcl-Version
X-Cache-Metadata
X-GEO
CACHE
XServer
X-C-Zone
X-C-Key
X-Bc
Resin-Trace
X-ZONE
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Policy
Dt-Cache-Category
X-Zone
X-BC
X-NU-AKA-ACS-Version
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Dynatrace-Js-Agent
Cteonnt-Length
Lb
SRV
Esi-Enabled
X-VCL-Version
Release
X-Air-Hostname
Ohc-File-Size
X-Cache-Host
X-SRV
X-Oneagent-Js-Injection
X-Ratelimit-Limit
Who
X-Reqid
X-ServedByHost
X-Pf-Uncompressing
Ttl
Load-Balancing
X-Swift-Error
X-NGINX-Cache
X-Cache-Debug
GeoIP-Country-Code
RequestId
X-Via-Ucdn
X-TH-Server
X-Configured-By
X-Tec-Api-Origin
X-AIR-PT
X-Esi-Check
X-Country-IP
X-Tec-Api-Version
GeoIP-Latitude
GeoIP-City
IBM-Web2-Location
X-Cache-Id
X-Tec-Api-Root
Dnion-Transfer-Encoding
Ohc-Cache-HIT
X-Ruxit-Js-Agent
X-Datadome
X-Gzip
UCS
X-Fastly-Country-Code
Pics-Label
X-VarnishDD-TTL
X-Fpc
X-Node-ID
Product
Server-Int
FSS-Cache
X-Tb-Optimization-Total-Bytes-Saved
MIME-Version
X-Unique-ID
LB
X-WA
Powered-By
X-WPE-Loopback-Upstream-Addr
Sid
X-Ocache
X-PJAX-URL
X-SERVER-NAME
X-Fastly-Backend-Reqs
X-RAMCache
X-Svr
X-PF-Uncompressing
X-B3-SpanId
X-Server-IP
X-Powered-Y
Fastly-SSL
Fastly-Soc-X-Request-Id
Lfy
X-Varnish-Url
X-Fastly-Request-Id
X-DSS
X-Apw-Hits
X-RPM
X-Apw-Access-Token
X-MID
X-RSL
X-RPS
X-Action
X-SD-PageType
X-Apw-Access-Object
X-DB
X-BE
X-DW
X-Varnish-Beresp-TTL
X-Apw-Access-Action
X-DI
X-Flog
C-Via
X-Page-Impression-Id
X-Flow-Id
X-ABtesting
Amp-Access-Control-Allow-Source-Origin
X-Hello
Xet-Cookie
X-LiteSpeed-Cache-Control
CDN
X-Zalando-Child-Request-Id
FSS-Proxy
Requestid
X-Agile-Brick-Ok
X-ElasticPress-Search
CF-IPCountry
L
X-Compress-Hint
X-Amzn-Remapped-Connection
X-Location
X-Debug-Controller
X-Debug-Revision
X-Aicache-OS
My-App
SN
X-Check-Cacheable
Host-ID
X-Render-Time
X-B3-Parentspanid
X-Amzn-Remapped-Date
Cneonction
ProcessTime
X-UPSTREAM-Address
X-Via-CDN
X-Request-Url
URI
X-Fastly-Cache-Hits
X-Sucuri-Cache
X-User
X-Cache-Backend
CloudFront-Viewer-Country
X-Request-URL
X-LB-ID
DataCenter
X-MiniProfiler-Ids
X-Nananana
X-App
X-Dw-Trace-Id