Threat Level: green Handler on Duty: Rick Wanner

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
Last-Modified
Accept-Ranges
Pragma
X-Content-Type-Options
X-Powered-By
CF-RAY
ETag
Link
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Access-Control-Allow-Origin
Content-Security-Policy
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Served-By
X-Amz-Cf-Id
X-Varnish
Referrer-Policy
X-Timer
CF-Cache-Status
X-FRAME-OPTIONS
X-Request-Id
Access-Control-Allow-Headers
X-AspNet-Version
Access-Control-Allow-Methods
X-Xss-Protection
X-Runtime
X-Download-Options
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Cacheable
Alt-Svc
X-Generator
Content-Security-Policy-Report-Only
X-Request-ID
X-Check
X-AspNetMvc-Version
Status
X-Cache-Status
X-Adblock-Key
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Iinfo
X-Permitted-Cross-Domain-Policies
X-Template
Content-Encoding
X-Language
X-Content-Security-Policy
X-Turbo-Charged-By
X-CDN
X-Type
Keep-Alive
X-Buckets
Xkey
X-AH-Environment
X-Backend
X-Cache-Group
WPE-Backend
Access-Control-Max-Age
X-Pass-Why
P3p
X-Age
CF-Ray
X-POWERED-BY
X-Server
Upgrade
EagleId
Access-Control-Expose-Headers
X-Via
X-Nginx-Cache-Status
X-Server-Powered-By
X-Pingback
X-Drupal-Dynamic-Cache
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Grace
X-Hacker
X-Amz-Id-2
X-Amz-Request-Id
X-UA-Device
Ali-Swift-Global-Savetime
X-Robots-Tag
Cf-Railgun
X-LiteSpeed-Cache
X-Envoy-Upstream-Service-Time
X-Proxy-Cache
X-Ua-Compatible
X-Page-Speed
Request-Context
Content-Location
X-Device
X-Ac
X-Node
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Cnection
X-Host
X-Cache-Lookup
X-Amz-Version-Id
Surrogate-Control
X-Server-Id
X-WebKit-CSP
X-Backend-Server
X-Rack-Cache
X-Rq
X-Response-Time
X-Application-Context
X-Readtime
X-CST
EagleEye-TraceId
Server-Timing
X-Url
Pinterest-Generated-By
X-Cloud-Trace-Context
X-TTL
X-OneAgent-JS-Injection
Request-Id
X-Instart-Request-ID
X-Dns-Prefetch-Control
X-Px
Report-To
X-Country
X-ORACLE-DMS-ECID
X-Clacks-Overhead
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Feature-Policy
Edge-Control
Rating
X-Country-Code
Allow
Charset
X-DynaTrace-JS-Agent
X-DataDome
X-ESI
X-Powered-CMS
X-Server-Name
X-FTR-Request-ID
X-PC
X-Vname
X-TtlSet
X-Origin-Cache
X-DynaTrace
NEL
X-MS-InvokeApp
X-Goog-Hash
X-Recruiting
X-Varnish-TTL
X-Cached
X-ORACLE-DMS-RID
X-VARITI-CCR
X-Vhost
X-GitHub-Request-Id
Content-MD5
RTSS
X-F-Cache
X-Version
X-Geo-Segment
X-GoogleNews-Bot
X-Kinja-Build
X-Exp-Variant
X-Kinja
X-Exp-Id
X-Cdn-Fetch
X-Kinja-Revision
X-Kinja-Server
X-Powered-By-Plesk
Public-Key-Pins
PB-PID
PB-RID
Accept-CH
Arc-Version
X-Mobile-Rewrite
Pinterest-Version
X-Pinterest-Rid
X-Upstream-Env
X-Mod-Pagespeed
X-D2id
Verso
SPRequestGuid
X-CF-Powered-By
MS-Author-Via
X-Client-IP
X-Abt-Application-Version
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-N
X-Dispatcher
X-SharePointHealthScore
AR-PoweredBy
AR-ATIME
X-Amz-Rid
AR-CACHE
X-Navigation-Version
Accept-CH-Lifetime
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-T
X-HeyJason
Nginx-Cache
DynaTrace
Permitted-Cross-Domain-Policies
X-Do-Not-Hack
X-Trace
Paypal-Debug-Id
X-Dw-Request-Base-Id
X-Fastly-Request-ID
X-Grace
X-Upstream
X-Hits
Arr-Disable-Session-Affinity
X-Varnish-Age
TCN
X-Forwarded-Proto
X-Amz-Meta-S3cmd-Attrs
X-FastCGI-Cache
X-DIS-Request-ID
X-Origin-Upstream-Status
X-Id
X-Shield-Request-Id
SPIisLatency
SPRequestDuration
X-Pad
X-Content-Options
AR-SID
X-Logged-In
X-Content-Digest
X-Cache-Hit
Realpath
X-IPLB-Instance
Access-Control-Request-Method
X-Kinsta-Cache
X-NF-Request-ID
MRF-Tech
Mrf-Cache-Status
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
X-Ruxit-JS-Agent
X-Acc-Meta-Resource-Type
X-B
X-Server-ID
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Metageneration
X-HW
X-Vcap-Request-Id
X-SS-Set-Cookie
X-XRDS-Location
S
X-Debug
X-MSEdge-Ref
X-Ser
Service-Worker-Allowed
Server-Name
X-Country-Code-Real
X-FTR-Realm
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-DC
X-NewRelic-App-Data
X-FTR-Backend
X-FTR-Cache-Status
X-Frontend
X-PressLabs-Stats
Tracecode
X-Wix-Server-Artifact-Id
X-Cache-Key
X-Oneagent-Js-Injection
X-FTR-Expires
AMP-Access-Control-Allow-Source-Origin
Rt-Fastcgi-Cache
Fastcgi-Cache
Eomportal-Instance
X-Forwarded-For
Alternate-Protocol
Surrogate-Key
Cleartype
X-Cache-Rule
X-GUploader-UploadID
Cache-Status
X-Srv
X-Analytics
Backend-Timing
X-NWS-LOG-UUID
X-HS-Hub-Id
X-HS-Content-Id
X-VCache
X-Oracle-Dms-Rid
X-Revision
X-User-Agent
Host
Fastly-Restarts
FilterID
TP-L2-Cache
TP-Cache
X-Rid
X-FTR-Cache-Host
X-Whom
X-Debug-Info
Public-Key-Pins-Report-Only
X-Akam-SW-Version
X-AOL-HN
X-Cache-2
X-Varnish-Backend
ServerID
X-Via-JSL
X-Content-Powered-By
X-XRDS-LOCATION
X-Webkit-CSP
X-Cdn
X-RateLimit-Remaining
X-Request-Processing-Time
X-Accel-Buffering
X-Request-Received
X-Kinja-Server-Push
Accept-Charset
Front-End-Https
X-Zen-Fury
Viewport
X-Ttl
X-Mobile
X-WPE-Loopback-Upstream-Addr
X-Cached-By
Liferay-Portal
X-Node-Name
X-App-Environment
X-LB-Cache
Host-Header
X-Cluster
X-Content-Security-Policy-Report-Only
X-Page-Id
X-Tumblr-Pixel
X-Magnolia-Registration
X-Tumblr-Pixel-0
X-Varnish-Hostname
X-Tumblr-User
X-Akamai-Edgescape
X-TT
X-Correlation-Id
X-Request-Guid
Cache-Tag
X-Cache-Control
X-Framework
X-B3-Sampled
X-Device-Type
X-B-Cache
X-Signature
Upgrade-Insecure-Requests
X-Handled-By
X-FB-Debug
DC
X-Instance
X-Platform-Server
X-BCube-Filmed-By
X-Cache-Server
X-B3-Traceid
X-Hostname
Server-Node
X-TA-CDN-Provider
X-Origin-Server
X-TT-TIMESTAMP
MicrosoftSharePointTeamServices
Source
Retry-After
X-Amzn-Trace-Id
X-Servedby
X-Contextid
X-WA-Info
X-Accel-Expires
HitInfo
Server-Info
HitType
X-Cache-Action
X-Varnish-Server
X-Sol
Display
X-Middleton-Display
X-Cache-Operation
X-Distil-CS
X-Daa-Tunnel
X-Amz-Replication-Status
X-Generated-By
AsisCache
X-Port
Content-Script-Type
Content-Style-Type
X-GeoIP
X-APP-VERSION
X-WebKit-CSP-Report-Only
X-Tumblr-Pixel-1
X-Edge-Location
X-Geo-Country
X-Tumblr-Pixel-2
X-S
X-TX-ID
X-Locale
Healthy
X-Hyper-Cache
X-Wix-Request-Id
GEO-INFO
X-Seen-By
ServedBy
X-Status
Actual-Object-TTL
Webserver
X-RequestSource
X-Varnish-Hits
X-Response-Served-From
X-Edge-Cache-Key
X-Region
User-Agent
X-Jobs
X-Edge-Cache
X-Adobe-Content
X-FW-Serve
X-Adobe-Loc
X-UUID
X-FW-Server
X-FW-Static
X-FW-Type
X-FW-Hash
X-Drupal-Cache-Tags
X-DataStream-Cache-Status
SRV
X-Varnish-Grace
S-Cnection
Refresh
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Fastcgi-Cache
Filters
X-Amz-Server-Side-Encryption
X-Cache-Age
X-Esi
IBM-Web2-Location
NGB
X-Cache-TTL-Remaining
X-Proxied
Response
X-Cache-NE
X-Middleton-Response
X-Content-Type
X-AppVersion
X-Az
AR-Request-ID
X-Activity-Id
X-ATG-Version
X-Pc-Key
X-Pc-Hit
X-Newrelic-App-Data
X-Pc-Appver
X-App-Server
X-CDN-Forward
X-Ruxit-Js-Agent
Payment
X-Cache-Remote
X-Cacheable-TTL
Datacenter
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Cache-TTL
X-UA
Cache
Country
X-Unique-ID
Served-By
X-Akamai-Transformed
Edge-Cache-Tag
X-Mode
X-HS-Cache-Config
X-Vg-Webcache
X-Sucuri-ID
Load-Balancing
X-Detected-As
Machine
Meta-Geo
X-RemovedCookies
X-Rendered-As
X-RN-RSRV
X-Is-Bot
X-Varnish-IP
X-ProcessESI
X-Rocket-Nginx-Bypass
X-FC-Vary-Parameters
X-BYPASS-REASON
User-Cache-Control
X-Proxy
X-ProxyCache-Status
X-ProxyCache-Key
X-ServerID
X-Viewer-Country
X-EIG-Tracking-Id
X-Cache-Config
Backend
X-OCL
X-Hosted-By
X-PERF
X-ApacheServer
X-Pubstack
X-BB-IP
DB-Nickname
Now
X-PCL
Cache-Name
X-Correlation-ID
X-Debug-Cache
X-CDN-Cache
X-Environment-Context
X-Generated
X-Hit
X-Grey
X-CCM
X-Cache-Category-Id
L5d-Success-Class
Cache-Key
Access-Control-Request-Headers
Mn-Server-Ip
ServerName
X-Backend-Name
X-Amz-Meta-Surrogate-Control
X-Human
X-JoinUs
X-Via-Fastly
X-Varnish-Cacheable
X-TNCMS
X-Zipkin-Id
X-Cache-Var
X-Rule
X-Cache-Var-Map
X-Site-Version
X-Routing-Service
X-Loop
X-L-Path
X-Origin
X-Original-Request
X-OVcl-Cache
X-OVcl
Access-Control-Allow-Method
X-Tb
Azure-RegionName
Azure-InstanceId
X-NGENIX-Cache
X-Agile
Azure-SiteName
Azure-SlotName
X-Agile-Age
X-Agile-Id
Azure-Version
X-Ocache
X-NodeID
X-Varnish-Cache-Hits
X-Upgrade-Enabled
X-TWH-CORRELATION-ID
X-Timing-Wait
S-Rt
Selected-FE
X-Source
X-Proxy-Build
X-Www-Served-By
Webcakes-Region
Webcakes-App-Name
TWC-Connection-Speed
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Locale-Group
TWC-Device-Class
TWC-Privacy
Webcakes-App-Version
X-AWS-Id
X-Origin-Hint
X-URL
X-SplitTest
X-VWS-Id
X-Origin-CC
X-LJ-Flow-ID
Property-Id
X-HS-Combine-CSS
X-IP
X-Storage
X-App-Name
X-Xfnlog-Site
HostName
X-Access
X-Format
X-Real-IP
X-Section
X-Pc-Host
X-Pc-Date
X-Drupal-Cache-Contexts
X-Upstream-CT
X-Upstream-HT
OT-Force-Account-Verify
X-Akamai-Request-ID
X-Vgn-Hpd-Reason
X-Time-Microsecs
X-Mrs-Cache
X-Mrs-Age
X-Mrs-Cache-Hits
X-Mshield-Cache-Status
X-Nginx-Cache
X-Litespeed-Cache
From-Origin
Fastcgi-Useragent
X-UA-Device-Type
X-NC
X-NCache
Fastcgi-X-Cache-Version
X-Feature
X-Amzn-RequestId
XServer
X-Amz-Apigw-Id
Powered-By-ChinaCache
X-Internal-Host
X-RateLimit-Limit
Fastcgi-X-Cache
Fastly-SSL
X-Iejgwucgyu
X-Forwarded-Host
X-Microcachable
X-Varnish-Beresp-Status
X-Release
X-Varnish-Beresp-Grace
X-Distributor
X-Qnm-Cache
X-PHP-Backend
X-M-Reqid
X-M-Log
X-Ms-Request-Id
X-Ms-Lease-Status
X-Ms-Blob-Type
X-Ms-Version
X-Birta-Served
X-Birta-Cache-Post
Pagespeed
X-Cache-Backend
NtCoent-Length
LB
X-Labrador-Cache-Channel
X-Webkit-Csp
Pagetype
X-App-Version
X-Twitter-Response-Tags
X-EdgeConnect-Cache-Status
X-Transaction
X-Connection-Hash
X-VG-TLSProxy
X-V
X-B3-Spanid
X-Instance-Name
Frame-Options
Time
MIME-Version
X-GZip
X-Web-Node
X-SERVER-NAME
X-Hnp-Log
X-IN-APIGATEWAY
X-IN-SSL-APIGATEWAY
X-No-Session
X-Logtrace-Id
Cneonction
X-Irp-Debug
X-IN-WAF
Ajk
AKAMAI
X-DPWN-IS-SECURE
X-B-Cookie
X-BB-ID
X-ARC
X-Application
Server-Int
Rendered-Blocks
X-Block-Status
Meta-Geo-Continent
Mobile-Detection-Method
NGX
X-Cache-Bucket
T-Server
X-Accel-Expires-Debug
VivaBuild
X-A-Ccd
Web-Mar-Node
X-A
Viewtype
X-A-Dam
X-A-Wwc
X-A-Dgt
X-A-Dcw
V-Age
MD5-Digest
IsBot
X-From
Ec-Rule-Version
Fly-Cache
Fly-Request-Id
X-G
X-Gen-Mode
X-Generation-Time
BehaviorPad-Version
Cache-Prefix
X-Generated-In
X-ScT
X-Dispatcher-Server
X-CS
Host-ID
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-CUA
X-D
X-Died
X-Developer
X-Destination
X-Date
Arc-Country
X-NU-AKA-ACS-Version
X-Rewrite-Enabled
X-Via-SSL
X-UE-Client-Country
X-PAYTM-SRV-ID
X-Trv-Group
X-SIPLIST1
X-Request-URI
X-Request-UUID
Www
X-Rojux
X-Server-Time
X-Server-By
X-Redis-Cache
Xc-Version
X-SRCache-Key
X-Org
X-VG-WebServer
X-Via-Edge
X-WebServer
X-Via-CDN
X-Region-Sid
X-S-Cookie
X-Varnish-Beresp-Ttl
X-HOST
WZWS-RAY
X-Sucuri-Cache
X-Powered-By-ANYU
X-NWS-UUID-VERIFY
X-C
GMS-Ver
Request-EU
X-Cache-Enabled
X-Debug-Log
Request-Time
X-NX-Host
NodeID
On-Server
X-ElasticPress-Search
Origin-Cache-Control
X-Varnish-Action
Origin-Edge-Control
X-Debug-Cookies
Request-Country
Magicmarker
X-Cache-CFC
Proxy-Connection
Pragrma
Kp-EeAlive
Release
MI-API
X-We-Are-Hiring
X-External-Request-Id
MI-Cache
X-Crawler
X-Core-Value
MI-Cache-Age
Country-Code
X-Key
X-Layer
X-Sf
True-Client-Country-4JS
X-HTML-Minification-Powered-By
X-Phone
X-GeoIP-City
X-ServiceProvider
X-UnsetCookies
X-Var-Ttl
X-Origin-TTL
X-Node-Id
X-S-Maxage
X-Owner
X-MI-In-Market
X-VCT
SN
X-Hl-Ver
X-Fastly-Cache
X-Amz-Meta-Cache-Control
Decoy-Debug-Key
Decoy-Debug-Status
Esi-Enabled
Decoy-Debug-TTL
Server-Host
X-RCS-CacheZone
Ar-Sid
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Webstats-RespID
X-FireWall-Port
X-Backend-TTL
X-Shopify-Stage
X-Returned-From-PostProcessResponse
X-Returned-From-DLL
X-Cache-Expires
X-Actual-URL
X-ShardId
X-Alternate-Cache-Key
X-Returned-From-BeforeDispatch
X-Returned-From
X-ShopId
X-Wikidot-Backend
X-Passed-To-PostProcessResponse
X-Passed-To-DLL
X-Store
X-Swa-Ws
X-Platform
X-Fstrz
X-FW-Version
X-Stale
X-Thinkindot-L3
X-Passed-To-BeforeDispatch
X-Variation
X-Passed-To
X-Nginx-Cache-Key
X-Matched-Rule
X-Location
X-Trace-Id
X-Tumblr-Pixel-3
X-Hash
X-Fetched-On
X-CGP
X-VServer
X-Ckpd-Fst-Backend
X-Skip-Cache
X-Cdn-Srv
X-Cache-Srv
X-Response-By
X-Cdn-Origin
X-Croise-Owner
X-Sn-Servicetimems
X-Reboot
X-Eu-Site
X-F5-Cache
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Wikidot-Static-Cache
X-Device-Os
X-Cache-Host
RNT-Machine
CDCHOST
Odigeo-Trace-Id
Fastly-Backend-Name
Is-Eu
Cache-Tags
Origin
Platform
HA-Cloudapp
Backend-Name
PFcat
Heartbleed
HA-Urlpath
HA-Geolon
HA-Geolat
HA-Geocountry
HA-Geocity
HA-Georegion
Ha-Gx-Prefs
HA-Servedtime
HA-Ipaddr
HA-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Thinkindot-CacheControl-Type
Thinkindot-Control
Thinkindot-CacheControl
Server-ID
PageSpeed
Apple-News-Services-Host
RNT-Time
Uber-Trace-Id
Adler-Geo
Apple-News-Services-Handled
X-TT-LOGID
X-Developers
X-Policy
X-Up
X-Worker
Cteonnt-Length
X-Core-Mission
Fastly-SWR
X-Server-IP
X-Rebelmouse-Cache-Control
X-MSEdge-Flight
X-MSEdge-Features
X-GeoIP-Country-Code
X-Rebelmouse-Surrogate-Control
X-Gannett-Site-Version
Fastly-SIE
Countrycode
Content-Disposition
X-Request-Time
X-Epic-Correlation-Id
X-Secret
X-Backend-Host
Section-Io-Cache
X-Backend-State
HTTPS
X-Backend-Url
Resin-Trace
X-Clientip
X-Alicdn-Da-Ups-Status
X-Content-Age
X-Cache-URL
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Request-Id
REQUESTUUID
ProcessTime
X-Real-Ip
WP-Super-Cache
Powered
Sid
X-CACHE-AGE
X-Servername
X-Cluster-Node
X-Csrf-Token
X-GEO
X-Ua
X-Refresh
X-B3-TraceId
X-Ezoic-Cdn
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Dc
RequestId
CDN
Xserver
Warning
X-Proto
X-Pf-Uncompressing
ViewerVersion
X-Servedbyhost
X-TIME
X-Cache-ASPX
We-Hiring
Cache-Cookie-Set-Idcheck
Mail-Subject
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-From
X-Endurance-Cache-Level
CF-IPCountry
X-Guploader-Uploadid
X-Req
X-GoCache-CacheStatus
X-Atg-Version
Dnion-Transfer-Encoding
X-Newrelic-Synthetics
X-Pjax-Url
NODE
X-Surge-Debug
X-Varnish-Ttl
Hostname
X-CLOUD-TRACE-CONTEXT
CACHE
X-Nc
NnCoection
X-DC
X-Aed
X-Origin-Expires
X-Edge-IP
X-Time
X-COUNTRY
X-Origin-Date
X-Page-Type
X-Ms-Lease-State
X-Server-W
Pramga
GeoIp-Country-Code
Geoip-Latitude
X-Cache-Control-Set-By
X-HCF
X-Varnish-HitMiss
X-CSRF-Token
X-Oracle-Dms-Ecid
TSSecure
X-Varnish-Beresp-TTL
SD-X-WS
X-Cdn-Forward
X-Ratelimit-Limit
X-Server-Group
A
WWW-Authenticate
X-Varnish-Url
X-Aicache-OS
Processtime
X-DataStream-MidMile-RTT
X-WA
X-Flog
X-GRACE
X-Hello
Geoip-City
X-Datadome
MS-CV
X-ABtesting
X-Amz-Cf-Pop
X-DataStream-Origin-MEX-Latency
X-Dynatrace-Js-Agent
X-Wix-Route-ID
X-Varnish-URL
Cdn
PICS-Label
X-From-Cache
X-Wa
X-Geo
Lfy
X-Auto-Login
X-Akamai-Request-ID2
Node
Mime-Version
Cdn-Request-Time
X-Gdpr
X-UPSTREAM-Address
Lb
FSS-Cache
Cdn-Host
FSS-Proxy
Dont-Set-Cookie
X-Edge-Server
PageType
X-Use-Magma
X-EC-Security-Audit
X-APP
X-Sentry-ID
X-Gen-Id
X-Nananana
X-Unique-Id
X-Check-Cacheable
X-PAGE-TYPE
Ms-Operation-Id
X-Via-NSCOPI
GeoIP-City
GeoIP-Latitude
Rt-Proxy-Cache
GeoIP-Country-Code
X-RTag
X-SRV
COMMERCE-SERVER-SOFTWARE
X-WR-MODIFICATION
DataCenter
X-Cache-Id
X-Cookie
X-Cache-HT
X-Served-From
Is-Session-Tracking
X-Fastly-Backend-Reqs
X-CACHE-KEY
Get-Access-Time
X-Optimization
X-Env
X-Load-Cache
X-Cache-Info
X-GDPR
X-Bip
X-Proxy-Server
Who
X-Thanos
Memcached
X-Cache-FS-Status
X-FORWARDED-FOR
X-Be
X-Ibm-Trace
Memory
X-Swift-Error
Ws
X-PJAX-URL
X-Request-Start
X-Ver
Pics-Label
X-Fastly-Cache-Hits
X-Wix-Petri-Ex
X-Meta-Tbi-Cache-Vertical
X-Ratelimit-Remaining
Cf-Ipcountry
X-Cache-Ttl
X-Fe
Httpd-Identifier
X-B3-SpanId
X-ServedByHost
X-HS-Status
X-MP-GENERATED-AT
X-RateLimit-Reset
Group
V-Cache
X-SVT-ORM-VERSION
UCS
X-SVT-ORM-RULES
X-Dw-Trace-Id
X-CDN-Pop
X-CDN-Pop-IP
X-Shard
X-NGINX-Cache
GW-Server
URI
Powered-By
Amp-Access-Control-Allow-Source-Origin
X-ID
Ohc-File-Size
X-GZIP
X-VC
X-PF-Uncompressing
AGE-Hash
Requestid
Version
X-SB
NX-Cache
X-Bug-Bounty
X-Path-Route
Serverid
X-CacheKey
CDN-Cache-Hit
X-Varnish-Info
CDN-Node
Xet-Cookie
N-Cache
Cache-Hits
X-User
X-LiteSpeed-Cache-Control
X-StackifyID
CDN-Cache
X-P-T
X-Akamai-ERPolicy
X-ServerName
X-Route-Name
X-Cache-Handler
X-Grace-Duration
X-VG-WebCache
X-Goog-Meta-Goog-Reserved-File-Mtime
SID
X-Akamai-ERRuleID
Fastly-Soc-X-Request-Id
Apicache-Store
X-Is-Crawler
X-Flags
X-SD-PageType
Https
Ohc-Response-Time
X-RequestId
X-Providence-Cookie
X-Litespeed-Cache-Control
Apicache-Version