Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
Last-Modified
Pragma
Accept-Ranges
X-Content-Type-Options
X-Powered-By
CF-RAY
ETag
Link
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Access-Control-Allow-Origin
Content-Security-Policy
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Served-By
X-Amz-Cf-Id
X-Varnish
Referrer-Policy
X-Timer
CF-Cache-Status
X-Xss-Protection
X-Request-Id
X-FRAME-OPTIONS
Access-Control-Allow-Headers
X-AspNet-Version
Access-Control-Allow-Methods
X-Runtime
X-Download-Options
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Cacheable
Alt-Svc
X-Generator
Content-Security-Policy-Report-Only
X-Request-ID
X-AspNetMvc-Version
Status
X-Check
X-Cache-Status
X-Adblock-Key
Timing-Allow-Origin
X-Iinfo
X-DNS-Prefetch-Control
X-Permitted-Cross-Domain-Policies
X-Template
Content-Encoding
X-Language
X-Content-Security-Policy
X-Turbo-Charged-By
X-CDN
X-Type
Keep-Alive
Xkey
X-Buckets
X-Backend
X-AH-Environment
WPE-Backend
Access-Control-Max-Age
X-Pass-Why
X-Age
X-Cache-Group
X-Server
CF-Ray
Upgrade
X-POWERED-BY
EagleId
P3p
Access-Control-Expose-Headers
X-Via
X-Nginx-Cache-Status
X-Server-Powered-By
X-Pingback
X-Drupal-Dynamic-Cache
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Grace
X-Hacker
X-Amz-Id-2
X-Amz-Request-Id
X-UA-Device
Ali-Swift-Global-Savetime
X-Robots-Tag
Cf-Railgun
X-LiteSpeed-Cache
X-Envoy-Upstream-Service-Time
X-Proxy-Cache
X-Page-Speed
X-Ua-Compatible
Request-Context
Content-Location
X-Device
X-Ac
X-Node
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cnection
X-Host
X-Server-Id
X-Cache-Lookup
X-Amz-Version-Id
Surrogate-Control
X-WebKit-CSP
X-Backend-Server
X-Rack-Cache
X-Rq
X-Response-Time
X-Application-Context
X-Readtime
X-CST
X-Dns-Prefetch-Control
EagleEye-TraceId
Server-Timing
Pinterest-Generated-By
X-Cloud-Trace-Context
X-TTL
X-Url
X-Instart-Request-ID
X-OneAgent-JS-Injection
Request-Id
X-Px
Report-To
X-Country
X-ORACLE-DMS-ECID
X-Clacks-Overhead
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Rating
Feature-Policy
Edge-Control
Allow
X-Country-Code
X-DynaTrace-JS-Agent
Charset
X-DataDome
X-Server-Name
X-Powered-CMS
X-FTR-Request-ID
X-PC
X-Vname
X-TtlSet
X-ESI
X-Origin-Cache
X-DynaTrace
NEL
X-MS-InvokeApp
X-ORACLE-DMS-RID
X-Goog-Hash
X-Recruiting
X-Varnish-TTL
X-Cached
X-VARITI-CCR
X-Vhost
Content-MD5
X-GitHub-Request-Id
RTSS
X-F-Cache
X-Version
X-Kinja-Revision
X-Geo-Segment
X-Kinja-Server
X-Cdn-Fetch
X-Kinja
X-GoogleNews-Bot
X-Exp-Id
X-Kinja-Build
X-Exp-Variant
X-Powered-By-Plesk
X-CF-Powered-By
Public-Key-Pins
Pinterest-Version
X-Pinterest-Rid
X-Upstream-Env
PB-PID
PB-RID
Arc-Version
X-Mod-Pagespeed
X-Mobile-Rewrite
X-Client-IP
Verso
SPRequestGuid
X-D2id
X-Abt-Application-Version
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-N
MS-Author-Via
Accept-CH
Permitted-Cross-Domain-Policies
X-Do-Not-Hack
X-HeyJason
AR-ATIME
AR-PoweredBy
X-Dispatcher
X-SharePointHealthScore
AR-CACHE
X-Amz-Rid
X-T
X-Navigation-Version
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
DynaTrace
Nginx-Cache
Paypal-Debug-Id
X-Dw-Request-Base-Id
X-Grace
X-Upstream
X-Trace
X-Fastly-Request-ID
X-Varnish-Age
Arr-Disable-Session-Affinity
X-FastCGI-Cache
Accept-CH-Lifetime
X-Hits
TCN
X-Shield-Request-Id
X-Id
X-Amz-Meta-S3cmd-Attrs
X-Forwarded-Proto
X-DIS-Request-ID
X-Pad
X-Origin-Upstream-Status
X-XRDS-Location
SPRequestDuration
SPIisLatency
X-Cache-Hit
X-Content-Options
X-Ruxit-JS-Agent
X-Logged-In
X-Content-Digest
X-Cdn
Realpath
X-IPLB-Instance
X-Kinsta-Cache
Access-Control-Request-Method
X-B
X-Acc-Meta-Resource-Type
Mrf-Cache-Status
X-Mrf-Section-Lastmod
MRF-Tech
X-Mrf-Item-Lastmod
X-NF-Request-ID
AR-SID
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-SS-Set-Cookie
X-HW
X-Vcap-Request-Id
X-MSEdge-Ref
S
X-Debug
Service-Worker-Allowed
Server-Name
X-Ser
X-FTR-Backend-Server
X-PressLabs-Stats
X-FTR-Backend
X-FTR-DC
X-Country-Code-Real
X-FTR-Realm
X-FTR-Cache-Status
X-FTR-Balancer
X-Frontend
Tracecode
X-FTR-Expires
X-Wix-Server-Artifact-Id
Fastcgi-Cache
Rt-Fastcgi-Cache
X-Cache-Key
Eomportal-Instance
X-Server-ID
AMP-Access-Control-Allow-Source-Origin
X-GUploader-UploadID
Surrogate-Key
X-Webkit-CSP
Alternate-Protocol
X-Oneagent-Js-Injection
X-Forwarded-For
Cleartype
X-Cache-Rule
X-NewRelic-App-Data
Cache-Status
X-Srv
X-NWS-LOG-UUID
X-HS-Hub-Id
X-Analytics
X-HS-Content-Id
Backend-Timing
X-VCache
TP-L2-Cache
Host
TP-Cache
X-User-Agent
X-Revision
X-Rid
X-Debug-Info
X-Whom
FilterID
X-FTR-Cache-Host
Public-Key-Pins-Report-Only
X-AOL-HN
Fastly-Restarts
X-Via-JSL
X-Varnish-Backend
X-Akam-SW-Version
X-Cache-2
ServerID
X-Content-Powered-By
X-RateLimit-Remaining
X-Request-Received
X-Request-Processing-Time
X-Zen-Fury
Viewport
X-Accel-Buffering
Accept-Charset
X-Kinja-Server-Push
X-Mobile
X-WPE-Loopback-Upstream-Addr
Front-End-Https
X-Oracle-Dms-Rid
X-Ttl
X-Cached-By
Liferay-Portal
X-Node-Name
X-App-Environment
X-Hostname
X-B3-Traceid
Host-Header
X-Cache-Control
X-LB-Cache
X-Varnish-Hostname
X-Handled-By
X-B3-Sampled
X-Cluster
X-Content-Security-Policy-Report-Only
X-Magnolia-Registration
X-Tumblr-Pixel
Cache-Tag
X-Request-Guid
X-Tumblr-User
X-Tumblr-Pixel-0
X-Akamai-Edgescape
X-B-Cache
X-Page-Id
Upgrade-Insecure-Requests
X-FB-Debug
X-Instance
X-TT
X-Signature
X-Platform-Server
X-BCube-Filmed-By
X-Framework
X-Device-Type
X-Cache-Server
DC
X-Origin-Server
Server-Node
X-TT-TIMESTAMP
X-TA-CDN-Provider
X-XRDS-LOCATION
Retry-After
Source
MicrosoftSharePointTeamServices
X-Accel-Expires
X-Contextid
X-Servedby
Server-Info
HitInfo
X-WA-Info
HitType
X-Cache-Action
X-Amzn-Trace-Id
X-Varnish-Server
X-Cache-Operation
Display
X-Correlation-Id
X-Middleton-Display
X-Sol
X-URL
X-Port
X-APP-VERSION
X-Daa-Tunnel
X-Generated-By
X-Distil-CS
X-Geo-Country
X-Edge-Location
X-Hyper-Cache
AsisCache
X-Amz-Replication-Status
X-GeoIP
Content-Script-Type
Content-Style-Type
X-Esi
X-S
X-RequestSource
Webserver
GEO-INFO
ServedBy
Actual-Object-TTL
X-Wix-Request-Id
X-WebKit-CSP-Report-Only
X-Locale
X-Newrelic-App-Data
X-Seen-By
X-Tumblr-Pixel-2
X-TX-ID
X-Tumblr-Pixel-1
X-Edge-Cache-Key
X-FW-Hash
X-Edge-Cache
X-Jobs
X-UUID
X-FW-Serve
X-Region
X-FW-Type
X-Status
X-FW-Static
X-FW-Server
X-Varnish-Hits
X-Drupal-Cache-Tags
X-Adobe-Content
X-Adobe-Loc
Healthy
X-Varnish-Grace
X-Response-Served-From
X-DataStream-Cache-Status
User-Agent
SRV
Filters
X-Amz-Server-Side-Encryption
NGB
S-Cnection
X-Proxied
Refresh
Response
X-Middleton-Response
X-Yottaa-Optimizations
X-Cache-TTL-Remaining
X-Yottaa-Metrics
AR-Request-ID
X-Correlation-ID
X-CDN-Forward
IBM-Web2-Location
X-Fastcgi-Cache
X-AppVersion
X-Activity-Id
X-Cache-Age
X-Az
X-App-Server
X-Pc-Key
X-Pc-Appver
X-Pc-Hit
X-Cache-Remote
X-Content-Type
Cache
X-Cacheable-TTL
Payment
X-UA
X-Cache-NE
X-Unique-ID
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Ruxit-Js-Agent
X-Cache-TTL
X-Vg-Webcache
Country
Served-By
X-Akamai-Transformed
X-Mode
Datacenter
X-RN-RSRV
Machine
Edge-Cache-Tag
X-Is-Bot
X-RemovedCookies
X-Sucuri-ID
X-HS-Cache-Config
X-ProcessESI
Load-Balancing
X-Detected-As
X-Rendered-As
X-Source
HostName
Meta-Geo
X-OCL
User-Cache-Control
X-PCL
X-ProxyCache-Status
X-Backend-Name
X-BYPASS-REASON
X-Cache-Category-Id
X-ApacheServer
X-Debug-Cache
X-Human
X-Amz-Meta-Surrogate-Control
X-PERF
Webcakes-Region
Webcakes-App-Version
Mn-Server-Ip
X-Proxy
X-ProxyCache-Key
X-Origin
X-Origin-Hint
X-Hosted-By
X-Varnish-IP
X-Tb
X-Rocket-Nginx-Bypass
X-Viewer-Country
Cache-Name
TWC-Privacy
TWC-Locale-Group
TWC-GeoIP-LatLong
Cache-Key
TWC-GeoIP-Country
Backend
X-Grey
X-FC-Vary-Parameters
X-Pubstack
Webcakes-App-Name
TWC-Device-Class
TWC-Connection-Speed
Property-Id
DB-Nickname
X-ATG-Version
X-CDN-Cache
X-CCM
X-Cache-Config
Access-Control-Allow-Method
X-EIG-Tracking-Id
X-Environment-Context
Now
X-Generated
X-Format
Access-Control-Request-Headers
Azure-InstanceId
X-Access
ServerName
L5d-Success-Class
S-Rt
Azure-Version
Azure-SlotName
X-L-Path
Azure-RegionName
Azure-SiteName
X-BB-IP
X-Hit
X-Site-Version
X-ServerID
X-Section
X-Varnish-Cacheable
X-TNCMS
X-Varnish-Cache-Hits
X-Upgrade-Enabled
X-OVcl-Cache
X-Routing-Service
X-OVcl
X-Zipkin-Id
X-Loop
X-NodeID
X-Via-Fastly
X-Original-Request
X-Agile-Age
X-Www-Served-By
X-Real-IP
X-Agile-Id
X-VWS-Id
X-Agile
X-AWS-Id
X-NGENIX-Cache
X-IP
X-JoinUs
X-Ocache
X-LJ-Flow-ID
X-TWH-CORRELATION-ID
X-SplitTest
X-App-Name
X-Xfnlog-Site
X-Storage
X-Pc-Host
X-Drupal-Cache-Contexts
X-Pc-Date
X-Origin-CC
X-Akamai-Request-ID
X-Rule
Selected-FE
X-HS-Combine-CSS
X-Proxy-Build
X-Timing-Wait
XServer
X-Cache-Var-Map
X-Cache-Var
X-Upstream-CT
X-Upstream-HT
X-NC
X-Time-Microsecs
X-Vgn-Hpd-Reason
X-PHP-Backend
From-Origin
X-UA-Device-Type
OT-Force-Account-Verify
X-RateLimit-Limit
X-NCache
X-Litespeed-Cache
X-Internal-Host
X-Microcachable
X-Nginx-Cache
X-Distributor
X-Release
Ar-Sid
X-Mrs-Cache-Hits
X-Mshield-Cache-Status
X-Forwarded-Host
X-Mrs-Cache
X-Mrs-Age
Fastcgi-Useragent
X-Feature
Fastcgi-X-Cache-Version
LB
Fastcgi-X-Cache
Fastly-SSL
X-Amz-Apigw-Id
X-Amzn-RequestId
X-M-Reqid
X-M-Log
X-Qnm-Cache
Pagetype
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-Ms-Request-Id
X-Ms-Version
X-Ms-Lease-Status
X-Ms-Blob-Type
X-Cache-Backend
X-Birta-Served
X-Birta-Cache-Post
X-Twitter-Response-Tags
X-Transaction
NtCoent-Length
X-Connection-Hash
MIME-Version
Pagespeed
Powered-By-ChinaCache
X-Labrador-Cache-Channel
X-B3-Spanid
X-EdgeConnect-Cache-Status
X-Instance-Name
X-V
Frame-Options
X-Webkit-Csp
X-VG-TLSProxy
X-GZip
X-Ah-Environment
X-Varnish-Beresp-Ttl
X-Web-Node
PageSpeed
X-C
Time
X-IN-APIGATEWAY
Fly-Request-Id
X-PAYTM-SRV-ID
Fly-Cache
Viewtype
X-IN-WAF
V-Age
X-IN-SSL-APIGATEWAY
VivaBuild
X-SRCache-Key
X-SIPLIST1
X-Server-Time
X-A-Ccd
X-UE-Client-Country
X-A
X-Developer
X-CF-Lambda-Fn
X-Hnp-Log
Www
X-DPWN-IS-SECURE
Web-Mar-Node
X-CF-Lambda-Version
Arc-Country
T-Server
X-No-Session
AKAMAI
Server-Int
BehaviorPad-Version
X-Dispatcher-Server
X-Logtrace-Id
Cache-Prefix
Ajk
X-NU-AKA-ACS-Version
X-ScT
Rendered-Blocks
X-Via-SSL
X-Redis-Cache
MD5-Digest
X-Org
Ec-Rule-Version
Meta-Geo-Continent
X-Died
X-Trv-Group
NGX
X-From
X-WebServer
X-Date
X-Block-Status
X-Region-Sid
X-D
X-S-Cookie
X-CS
X-G
X-CUA
X-Request-URI
X-VG-WebServer
X-Application
X-ARC
X-Via-CDN
X-Rewrite-Enabled
X-Destination
Host-ID
X-Rojux
X-Request-UUID
X-BB-ID
X-Gen-Mode
X-Cache-Bucket
X-Generation-Time
Xc-Version
X-Generated-In
X-A-Wwc
X-A-Dgt
X-A-Dam
X-A-Dcw
X-Server-By
X-Via-Edge
X-Accel-Expires-Debug
X-B-Cookie
IsBot
X-SERVER-NAME
X-FireWall-Port
Cneonction
MI-API
MI-Cache-Age
X-F5-Cache
X-External-Request-Id
Magicmarker
X-Layer
X-MI-In-Market
Request-EU
GMS-Ver
X-ElasticPress-Search
Decoy-Debug-Key
Esi-Enabled
Kp-EeAlive
X-HTML-Minification-Powered-By
X-Irp-Debug
Server-Host
Request-Country
X-Fastly-Cache
Decoy-Debug-Status
Decoy-Debug-TTL
X-GeoIP-City
X-Core-Value
Release
X-Var-Ttl
X-Wikidot-Static-Cache
Proxy-Connection
X-CACHE-GROUP
CDCHOST
X-S-Maxage
X-UnsetCookies
X-Atg-Version
X-Cache-Enabled
X-Cache-CFC
X-Sf
X-ServiceProvider
X-Wikidot-Backend
X-Csrf-Token
X-Amz-Meta-Cache-Control
X-We-Are-Hiring
X-Varnish-Action
X-RateLimit-Remaining-Second
X-RCS-CacheZone
X-Sucuri-Cache
X-Powered-By-ANYU
WZWS-RAY
X-Node-Id
SN
Cache-Tags
Backend-Name
Origin-Edge-Control
X-VServer
MI-Cache
X-RateLimit-Limit-Second
Origin-Cache-Control
X-Origin-TTL
X-Phone
True-Client-Country-4JS
Pragrma
On-Server
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Storage-Class
X-NWS-UUID-VERIFY
X-App-Version
X-Webstats-RespID
Cteonnt-Length
X-HOST
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Cdn-Origin
X-Cache-Host
X-Cache-Srv
X-Cache-Expires
X-Backend-Url
X-Backend-TTL
X-Cache-URL
X-Cdn-Srv
X-Crawler
X-Content-Age
X-Ckpd-Fst-Backend
X-CGP
X-Croise-Owner
X-Nginx-Cache-Key
X-Reboot
X-Tumblr-Pixel-3
X-Backend-State
X-Shopify-Stage
Mobile-Detection-Method
X-Skip-Cache
X-Sn-Servicetimems
X-Platform
X-Passed-To-PostProcessResponse
X-Stale
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Up
X-Worker
X-Returned-From-DLL
X-Returned-From-BeforeDispatch
X-Returned-From-PostProcessResponse
X-Server-IP
X-Secret
X-Returned-From
X-Response-By
X-Variation
X-ShopId
X-ShardId
X-Request-Time
X-TT-LOGID
X-Swa-Ws
X-FW-Version
X-Fstrz
X-Gannett-Site-Version
X-GeoIP-Country-Code
X-Hash
X-Fetched-On
X-Eu-Site
X-Debug-Log
X-Developers
X-Device-Os
X-Epic-Correlation-Id
X-Hl-Ver
X-Key
X-Passed-To-BeforeDispatch
X-Passed-To
X-Passed-To-DLL
X-Trace-Id
X-Thinkindot-L3
X-Owner
X-NX-Host
X-Location
X-Matched-Rule
X-MSEdge-Features
X-MSEdge-Flight
X-Debug-Cookies
Thinkindot-CacheControl-Type
RNT-Machine
HA-Geolat
Is-Eu
RNT-Time
Section-Io-Cache
Thinkindot-CacheControl
HA-Geocountry
Server-ID
Request-Time
HA-Geocity
X-Backend-Host
Odigeo-Trace-Id
NodeID
Origin
PFcat
Platform
HA-Cloudapp
Heartbleed
Thinkindot-Control
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
X-Actual-URL
Apple-News-Services-Host
Apple-News-Services-Handled
HA-Geolon
X-Alternate-Cache-Key
Adler-Geo
HA-Georegion
Ha-Gx-Prefs
Uber-Trace-Id
HA-Urlpath
HA-Servedtime
HA-Ipaddr
HA-Host
Country-Code
Fastly-Backend-Name
X-CACHE-AGE
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
HTTPS
Resin-Trace
X-Clientip
Sid
Content-Disposition
X-VCT
Countrycode
X-Core-Mission
Fastly-SIE
Fastly-SWR
X-Servername
X-Store
X-Alicdn-Da-Ups-Status
X-Ezoic-Cdn
X-COUNTRY
CDN
X-Planisys-CDN-Cache
X-Iejgwucgyu
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Pf-Uncompressing
WP-Super-Cache
RequestId
X-Servedbyhost
X-Cache-ASPX
X-GEO
X-TIME
Warning
X-Real-Ip
CF-IPCountry
REQUESTUUID
X-Policy
ProcessTime
Powered
X-Ua
X-Cluster-Node
Dnion-Transfer-Encoding
We-Hiring
NODE
X-GoCache-CacheStatus
X-Refresh
X-Proto
Mail-Subject
X-DC
Xserver
X-Pjax-Url
Cache-Cookie-Set-Lfrom
ViewerVersion
X-Dc
Cache-Cookie-Set-From
Cache-Cookie-Set-Idcheck
X-B3-TraceId
X-Req
NnCoection
X-Origin-Date
X-Origin-Expires
X-Page-Type
X-Varnish-Ttl
X-Endurance-Cache-Level
X-Server-W
GeoIp-Country-Code
X-Newrelic-Synthetics
X-Cache-Control-Set-By
X-Varnish-HitMiss
X-Surge-Debug
X-HCF
X-Edge-IP
Geoip-Latitude
X-CLOUD-TRACE-CONTEXT
X-Time
Hostname
X-Nc
X-Guploader-Uploadid
WWW-Authenticate
X-Server-Group
X-Aed
X-Oracle-Dms-Ecid
Processtime
Geoip-City
X-Ms-Lease-State
SD-X-WS
Pramga
MS-CV
X-Wix-Route-ID
X-CSRF-Token
CACHE
PICS-Label
TSSecure
X-Wa
A
X-Aicache-OS
X-Varnish-Url
X-GRACE
X-Varnish-Beresp-TTL
X-Datadome
X-Varnish-URL
Dont-Set-Cookie
X-Cdn-Forward
Cdn-Request-Time
X-ABtesting
X-From-Cache
X-Flog
X-Edge-Server
X-Akamai-Request-ID2
X-Hello
Cdn-Host
X-Gdpr
X-DataStream-Origin-MEX-Latency
X-DataStream-MidMile-RTT
X-Ratelimit-Limit
DataCenter
X-Geo
X-WA
Cdn
X-Nananana
Node
Lb
X-UPSTREAM-Address
Lfy
X-RTag
Ms-Operation-Id
Mime-Version
X-Use-Magma
COMMERCE-SERVER-SOFTWARE
X-Optimization
X-Auto-Login
Is-Session-Tracking
FSS-Cache
FSS-Proxy
X-Cache-HT
X-Env
Get-Access-Time
X-Load-Cache
Who
X-Wix-Petri-Ex
PageType
X-EC-Security-Audit
X-APP
GeoIP-Country-Code
GeoIP-City
GeoIP-Latitude
X-Fastly-Backend-Reqs
X-SRV
X-WR-MODIFICATION
X-Gen-Id
Rt-Proxy-Cache
X-PAGE-TYPE
X-Unique-Id
X-Sentry-ID
X-CACHE-KEY
X-Cache-FS-Status
X-Ver
X-Check-Cacheable
X-Ibm-Trace
X-GDPR
X-Meta-Tbi-Cache-Vertical
X-Via-NSCOPI
Ws
X-Served-From
X-Cookie
X-Cache-Id
X-Dynatrace-Js-Agent
X-FORWARDED-FOR
X-Cache-Info
X-MP-GENERATED-AT
Memcached
Httpd-Identifier
X-NGINX-Cache
Ohc-File-Size
X-PJAX-URL
X-Bip
X-Path-Route
X-Proxy-Server
X-Thanos
X-Be
Powered-By
Pics-Label
X-SVT-ORM-RULES
X-Swift-Error
X-SVT-ORM-VERSION
X-Dw-Trace-Id
Version
URI
X-B3-SpanId
X-Fe
Memory
V-Cache
X-Cache-Ttl
X-RateLimit-Reset
Group
X-Fastly-Cache-Hits
X-CDN-Pop-IP
Cf-Ipcountry
X-CDN-Pop
X-P-T
X-LiteSpeed-Cache-Control
X-ServedByHost
X-Request-Start
X-Shard
X-HS-Status
Apicache-Version
X-ID
Amp-Access-Control-Allow-Source-Origin
Apicache-Store
Xet-Cookie
Requestid
Ohc-Response-Time
X-GZIP
X-PF-Uncompressing
UCS
AGE-Hash
NX-Cache
GW-Server
X-VC
X-SB
X-Bug-Bounty
Fastly-Soc-X-Request-Id
Serverid
X-StackifyID
X-Varnish-Info
N-Cache
X-User
X-CacheKey
CDN-Node
If-Modified-Since
X-Info
X-Akamai-ERPolicy
X-Micro-Cache
X-Ratelimit-Remaining
CDN-Cache
CDN-Cache-Hit
X-Akamai-ERRuleID
X-Distil-Cs
X-Route-Name
X-Cache-Handler
X-Flags
X-Litespeed-Cache-Control
X-RequestId
X-RAMCache
X-Is-Crawler
X-Providence-Cookie
X-BBXSRF
X-Grace-Duration
Https
X-ServerName
X-SD-PageType