Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
CF-RAY
CF-Cache-Status
Link
X-Powered-By
ETag
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Alt-Svc
Access-Control-Allow-Credentials
X-Runtime
X-Xss-Protection
X-Drupal-Cache
X-Adblock-Key
X-Check
Content-Security-Policy-Report-Only
X-Generator
X-Cacheable
X-Cache-Status
X-Permitted-Cross-Domain-Policies
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Template
X-Language
X-Iinfo
Content-Encoding
Status
X-Content-Security-Policy
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
X-Kinja-Server-Push
Xkey
Upgrade
X-Request-ID
X-Via
Access-Control-Expose-Headers
X-Turbo-Charged-By
Access-Control-Max-Age
Keep-Alive
X-Drupal-Dynamic-Cache
X-Pass-Why
X-Cache-Group
X-Age
EagleId
X-Backend
X-Envoy-Upstream-Service-Time
X-Robots-Tag
X-Amz-Id-2
X-Amz-Request-Id
X-CDN
X-Page-Speed
X-Ua-Compatible
X-Pingback
X-Server-Powered-By
X-AH-Environment
X-Server
X-Proxy-Cache
X-UA-Device
X-Hacker
Request-Context
X-Nginx-Cache-Status
X-Swift-CacheTime
X-Swift-SaveTime
Grace
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-Cdn
X-LiteSpeed-Cache
P3p
Cf-Railgun
Server-Timing
Feature-Policy
X-Amz-Version-Id
X-Device
X-Server-Id
X-WebKit-CSP
X-OneAgent-JS-Injection
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Rq
X-Ac
X-Cnection
EagleEye-TraceId
Report-To
X-Cloud-Trace-Context
X-Response-Time
Request-Id
X-Backend-Server
X-Host
X-Node
Content-Location
X-Readtime
X-Origin-Cache
X-Vhost
X-Application-Context
X-Cache-Lookup
X-ORACLE-DMS-ECID
X-DataDome
X-Dispatcher
X-Ruxit-JS-Agent
NEL
X-ORACLE-DMS-RID
X-Origin-Upstream-Status
X-Rack-Cache
X-HW
Surrogate-Control
Rating
X-Country-Code
Allow
X-Dns-Prefetch-Control
X-Clacks-Overhead
X-Country
X-Url
X-FTR-Request-ID
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-DynaTrace
X-Instart-Request-ID
X-MS-InvokeApp
Fusion-Content-Source
Fusion-Component-Id
Fusion-Template-Id
Fusion-Content-Id
Fusion-Source
X-Goog-Hash
X-Vname
X-PC
X-TtlSet
X-Varnish-TTL
X-TTL
Pinterest-Generated-By
X-B3-TraceId
Verso
X-Powered-By-Plesk
Public-Key-Pins
RTSS
X-Px
X-ESI
Edge-Control
X-Mod-Pagespeed
X-Middleton-Response
X-Sol
Response
Display
X-Middleton-Display
X-VARITI-CCR
Accept-Ch-Lifetime
SPRequestGuid
X-Exp-Id
X-Cdn-Fetch
X-GoogleNews-Bot
X-D2id
X-Exp-Variant
X-Kinja
X-Use-Magma
X-Kinja-Revision
X-Kinja-Server
X-Kinja-Build
X-SharePointHealthScore
X-Recruiting
X-CST
X-Ah-Environment
X-Akam-SW-Version
Service-Worker-Allowed
X-Vcap-Request-Id
SPIisLatency
SPRequestDuration
X-Version
X-Server-Name
X-GitHub-Request-Id
X-Abt-Application-Version
TCN
X-Powered-CMS
X-Navigation-Version
MS-Author-Via
X-Trace
X-Shard
Charset
Fastly-Restarts
X-Debug
Nginx-Cache
X-Amz-Server-Side-Encryption
Realpath
X-Amz-Rid
X-Upstream
AR-ATIME
AR-CACHE
Ar-Sid
AR-PoweredBy
X-Aspnetmvc-Version
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Forwarded-Proto
X-RateLimit-Remaining
Accept-CH
X-Ezoic-Cdn
X-VCache
X-NF-Request-ID
Front-End-Https
X-Cached
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Goog-Generation
Pagespeed
X-MSEdge-Ref
Access-Control-Request-Method
Arr-Disable-Session-Affinity
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Shield-Request-Id
Mrf-Cache-Status
MRF-Tech
X-Mrf-Item-Lastmod
X-B3-TraceId-Primal
X-Mrf-Section-Lastmod
AR-Request-ID
DynaTrace
Content-MD5
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Expires
MicrosoftSharePointTeamServices
S
X-T
X-Amz-Meta-S3cmd-Attrs
Accept-Ch
X-Fastly-Request-ID
X-Id
Paypal-Debug-Id
X-Goog-Storage-Class
X-XRDS-Location
X-FTR-Backend
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-DC
X-FTR-Realm
X-Ser
X-Varnish-Age
ServerID
X-DynaTrace-JS-Agent
X-Via-JSL
X-Client-IP
X-Grace
X-Content-Type
X-Accel-Expires
X-Correlation-Id
X-Dw-Request-Base-Id
X-Forwarded-For
X-Hits
Fastcgi-Cache
Edge-Cache-Tag
X-Amzn-Trace-Id
X-Content-Digest
Powered
X-Frontend
X-DIS-Request-ID
AMP-Access-Control-Allow-Source-Origin
X-N
X-FTR-Cache-Host
X-Mobile-Rewrite
PB-PID
PB-RID
Arc-Version
X-HS-Content-Id
X-FastCGI-Cache
X-HS-Hub-Id
Pinterest-Version
X-Pinterest-Rid
X-Logged-In
Server-Name
X-Fastcgi-Cache
TP-L2-Cache
TP-Cache
X-Request-Received
X-Request-Processing-Time
X-Request-Handler-Origin-Region
X-Server-ID
X-Microsite
X-GUploader-UploadID
X-Webkit-CSP
X-Kinsta-Cache
X-Zen-Fury
X-Time
X-Cache-Hit
X-Type
X-AppVersion
X-Activity-Id
X-Az
X-IPLB-Instance
X-Rid
X-LB-Cache
X-Vcache
X-Analytics
Healthy
X-Revision
Backend-Timing
X-Cache-Age
X-User-Agent
Retry-After
X-B3-Sampled
X-Whom
X-Srv
X-Node-Name
FilterID
Server-Node
X-RateLimit-Limit
X-NWS-LOG-UUID
Alternate-Protocol
X-Hp-Webp
Cache-Tag
X-F-Cache
Accept-Charset
X-Akamai-Edgescape
Cache-Status
X-SERVER
X-Cache-Rule
X-Content-Security-Policy-Report-Only
X-Content-Options
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Kong-Upstream-Latency
X-Cache-2
X-Kong-Proxy-Latency
DC
X-Tumblr-Pixel
X-Tumblr-User
X-Instance
X-Tumblr-Pixel-0
X-Amz-Apigw-Id
X-Amzn-RequestId
MS-CV
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Content-Powered-By
X-Varnish-Grace
X-App-Environment
X-Debug-Info
Refresh
Access-Control-Allow-Method
NR-ENABLED
Tracecode
X-PHP-Backend
X-Forwarded-Host
Surrogate-Key
X-AOL-HN
X-Jobs
X-Framework
X-Cluster
X-Page-Id
Fastcgi-Useragent
Source
X-FB-Debug
X-Cache-TTL
X-Request-Guid
X-B
Actual-Object-TTL
Host
X-App-Server
X-Cache-Operation
X-Seen-By
X-Mobile-URL
X-FW-Hash
X-FW-Static
X-FW-Serve
X-FW-Type
X-FW-Server
Frame-Options
X-Cache-Key
X-Cache-Control
X-Hostname
X-Geo-Country
X-Cached-By
X-TA-CDN-Provider
Cleartype
X-Host-Name
X-Pad
X-B-Cache
X-Signature
X-BCube-Filmed-By
Upgrade-Insecure-Requests
X-Git-Hash
X-Mobile
X-WebKit-CSP-Report-Only
X-Varnish-Backend
X-Response-Served-From
NGB
X-Presslabs-Stats
X-XRDS-LOCATION
X-ATG-Version
X-Element-Page-Cache
X-TT
WPE-Backend
X-Amz-Replication-Status
X-RequestSource
X-Handled-By
X-ProcessESI
Webserver
X-RemovedCookies
X-UA-Device-Type
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
X-RTag
X-Drupal-Cache-Tags
X-GeoIP
Cache-Tv-Group
Filters
GEO-INFO
Ms-Operation-Id
Payment
From-Origin
X-Ttl
Eomportal-Instance
X-Cacheable-TTL
X-Origin-Server
X-HS-Cache-Config
X-Adobe-Loc
X-Adobe-Content
X-TT-TIMESTAMP
X-Daa-Tunnel
X-EdgeConnect-Cache-Status
X-TX-ID
X-B3-Traceid
Xserver
X-Acc-Meta-Resource-Type
X-Wix-Request-Id
Liferay-Portal
X-Status
X-Cache-TTL-Remaining
X-FW-Dynamic
X-WA-Info
X-Cache-Remote
Datacenter
X-Esi
X-Hyper-Cache
Cache
X-Cache-Action
X-Region
X-Edge-Location
X-Contextid
Viewport
X-Content-Age
Version
X-Ratelimit-Reset
X-Cache-NE
X-CF-Powered-By
X-Varnish-Hostname
X-Storage
X-Akamai-Transformed
PageSpeed
X-Cache-Server
X-Tec-Api-Version
Ohc-File-Size
X-Accel-Buffering
X-Tec-Api-Root
X-Tec-Api-Origin
X-HS-Combine-CSS
Load-Balancing
X-Cache-Var-Map
X-RN-RSRV
X-Path-Route
X-Varnish-Server
X-ES-SERVER
Meta-Geo
X-Cache-Var
Host-Header
Accept-CH-Lifetime
X-IP
X-Proxy
Cache-Tags
X-TNCMS
X-Section
X-Access
Rt-Fastcgi-Cache
X-Cluster-Node
TWC-Connection-Speed
X-Cache-Enabled
Webcakes-Region
X-Cache-Config
Cache-Name
X-NCache
Release
TWC-GeoIP-LatLong
X-Viewer-Country
Webcakes-App-Version
TWC-Privacy
X-Varnish-Cache-Hits
TWC-Locale-Group
X-Via-Fastly
X-Origin-Hint
X-Loop
X-Tumblr-Pixel-3
X-Proto
Property-Id
TWC-Device-Class
X-Device-Type
Country
Webcakes-App-Name
TWC-GeoIP-Country
Vix-Hermes-Req-Id
X-FC-Vary-Parameters
X-Drupal-Cache-Contexts
X-CS
X-Trafficlayer-App-Name
X-Format
X-From
X-Proxy-Build
X-Origin-Response-Time
X-NGENIX-Cache
X-Human
X-Trafficlayer-App-Scope
X-Cache-Grace
S-Rt
Mn-Server-Ip
Ec-Rule-Version
DSUID
Selected-Fe
Cache-Hits
X-Backend-TTL
X-Backend-Name
X-Akamai-Request-ID2
X-Akamai-Request-ID
X-Rule
X-R9-Blue-Green-Version
X-UnsetCookies
X-Origin
X-Cache-Time
DB-Nickname
X-Upgrade-Enabled
X-Xfnlog-Site
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-PCL
X-OCL
X-Www-Served-By
X-Debug-Cache
X-VCT
X-Timing-Wait
X-Vgn-Hpd-Reason
S-Cnection
X-Labrador-Cache-Channel
X-Cache-Host
X-PressLabs-Stats
X-Site-Version
X-PERF
Decoy-Debug-TTL
X-ApacheServer
X-EIG-Tracking-Id
X-Time-Microsecs
X-Generated
X-Hosted-By
X-JoinUs
X-Web-Node
X-Locale
X-Trace-Id
X-Hit
X-NewRelic-App-Data
Decoy-Debug-Status
Azure-InstanceId
Azure-RegionName
Azure-SlotName
Azure-SiteName
Azure-Version
Ohc-Cache-HIT
Decoy-Debug-Key
X-CCM
X-Goog-Meta-Goog-Reserved-File-Mtime
X-FireWall-Port
Cache-Key
X-Rendered-As
X-Real-IP
X-OVcl
X-Varnish-Hits
X-OVcl-Cache
Server-Info
Time
X-S
X-Pubstack
L5d-Success-Class
Origin-Cache-Control
X-FW-Version
X-APP-VERSION
X-Redis-Cache
Origin-Edge-Control
Now
X-Upstream-HT
X-SS-Set-Cookie
X-Upstream-CT
Fastcgi-X-Cache-Version
X-Ua
X-Litespeed-Cache
OT-Force-Account-Verify
Fastly-SSL
Access-Control-Request-Headers
ServedBy
Cteonnt-Length
Origin
X-FB-TRIP-ID
X-Cluster-Name
X-Upstream-Proxy
X-Origin-TTL
X-UUID
X-Origin-CC
X-VG-TLSProxy
X-VG-WebCache
X-Load-Cache
X-ServerID
Hostname
X-Sorting-Hat-PodId
NtCoent-Length
X-Rocket-Nginx-Bypass
X-Soup
X-Sorting-Hat-ShopId
X-Shopify-Stage
X-ShardId
X-ShopId
X-Alternate-Cache-Key
X-GoCache-CacheStatus
X-Parent-Response-Time
Accept-Language
Mime-Version
Machine
X-Tb
X-B3-Spanid
X-Is-Bot
X-App-Version
X-UA
NGX
X-No-Session
Odigeo-Trace-Id
IBM-Web2-Location
X-ECACHE
X-Uri
Nel
CF-IPCountry
X-L-Path
X-Environment-Context
X-MServer
X-CACHE-KEY
X-Tt-Trace-Tag
X-NC
X-B3-Parentspanid
X-VG-WebServer
X-Trv-Group
X-Node-Id
X-BYPASS-REASON
X-Twitter-Response-Tags
Uber-Trace-Id
X-DPWN-IS-SECURE
X-Vtex-Processado-Em
X-Destination
X-Detected-As
X-Vtex-Remote-Cache
X-Developer
X-External-Request-Id
X-Info
Xc-Version
X-Worker
X-Date
Arc-Country
X-Hl-Ver
T-Server
X-G
Viewtype
VivaBuild
ServerName
Rt-Proxy-Cache
X-Request-UUID
Rendered-Blocks
X-Region-Sid
X-PAYTM-SRV-ID
X-Instart-Info
X-D
X-Connection-Hash
X-Accel-Expires-Debug
X-A-Wwc
X-Aed
X-AIR-PT
X-Application
X-A-Dgt
X-B-Cookie
X-CF-Lambda-Version
X-A
X-A-Ccd
X-A-Dam
X-CF-Lambda-Fn
Node
Mobile-Detection-Method
X-SRCache-Key
X-ARC
AsisCache
BehaviorPad-Version
Cache-Prefix
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
X-ProxyCache-Status
X-ProxyCache-Key
A
Apple-News-Services-Handled
Apple-News-Services-Host
X-Server-Time
X-ScT
GEO-REGION-INFO
Fly-Request-Id
MD5-Digest
Memcached
Meta-Geo-Continent
Fly-Cache
Cross-Origin-Window-Policy
Content-Script-Type
X-S-Cookie
X-Rojux
Content-Style-Type
X-Rewrite-Enabled
X-Transaction
X-A-Dcw
X-CSRF-TOKEN
Proxy-Connection
Request-Time
Backend-Name
X-Oneagent-Js-Injection
X-Amzn-Remapped-Content-Length
X-Endurance-Cache-Level
X-Cms-Context
X-Is-Gdpr
Fastly-Soc-X-Request-Id
X-Developers
X-S-Maxage
We-Hiring
X-Geo
Request-EU
Request-Country
X-SVT-ORM-VERSION
X-JWT-State
Mail-Subject
X-Has-Esi
IsBot
N-Cache
X-Compress-Hint
SRV
X-SVT-ORM-RULES
X-Cdn-Srv
X-Cache-Bucket
Akamai-GRN
X-SIPLIST1
X-Magnolia-Registration
User-Cache-Control
X-IN-APIGATEWAYSSL
X-Level-Front-Cache
X-Irp-Debug
X-Hnp-Log
X-IN-APIGATEWAY
Served-By
Pramga
X-Proxy-Upstream
Pagetype
X-Reboot
X-Reqid
X-Release
X-Proxy-Cache-Status
Section-Io-Cache
X-Origin-Date
X-NX-Host
X-Origin-Expires
Server-Host
Wxu-Next-Commit
X-Location
X-Ratelimit-Limit
X-Block-Status
X-C
X-Bip
X-Debug-Log
X-Backend-Url
X-BBXSRF
X-Cache-Info
X-Cdn-Origin
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-Clientip
X-CGP
X-Debug-Cookies
X-Debug-Cache-Store
X-Backend-Host
X-Dispatch
X-Generated-On
X-Generated-By
X-Generation-Time
X-Geo-Header
Wxu-Next-Region
X-Hash
X-Gen-Mode
X-Fastly-Cache
X-Azure-Ref
X-Azure-Ref-OriginShield
X-Auto-Login
X-Distil-CS
X-Eu-Site
X-ElasticPress-Search
Wxu-Next-Hostname
L
X-Wikidot-Backend
X-TrackingId
X-Dc
X-Thanos
X-Wikidot-Static-Cache
Srv
X-Nc
Countrycode
X-Webstats-RespID
X-Var-Ttl
X-User
CDCHOST
X-Up
X-We-Are-Hiring
X-VC-Cache
X-Sn-Servicetimems
X-Device-Os
X-Service
Heartbleed
X-CUA
X-WADP-Cache
X-Via-CDN
X-Server-IP
Content-Disposition
HA-Ipaddr
X-Skip-Cache
X-Nginx-Cache
Ha-Gx-Prefs
X-Clara-WADP
AKAMAI
Gh-Request-Id
X-PHP-Host
X-CACHE-GROUP
X-Microcachable
X-Request-Start
X-Platform-Server
X-Owner
X-Variation
X-Cache-FS-Status
X-Request-URI
X-Amz-Meta-Cache-Control
X-WebServer
X-Old-Content-Length
X-LI-UUID
X-Li-Fabric
X-GeoIP-City
X-Fetched-On
X-Li-Pop
X-Distributor
X-LI-Proto
RNT-Time
X-Dispatcher-Server
X-Epic-Correlation-Id
X-VServer
X-Policy
X-Qloud-Router
X-Swa-Ws
X-Thinkindot-L3
X-Nginx-Cache-Key
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Say-TTL
X-Say-Cacheable
X-Servername
X-Rebelmouse-Cache-Control
X-Method
X-Matched-Rule
Is-Eu
Adler-Geo
X-Generated-In
PFcat
Platform
X-SayCDN-TTL
X-B3-SpanId
X-Urbn-Context-Path
X-Lb-Id
X-Key
X-Urbn-Site-Id
RNT-Machine
X-Rebelmouse-Surrogate-Control
X-App-Name
Server-Int
Magicmarker
X-Backend-State
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Web-Mar-Node
W
Thinkindot-Control
Locale
Cache-Provider
Fastly-SIE
X-Core-Mission
Esi-Enabled
X-Guploader-Uploadid
Fastly-SWR
Kp-EeAlive
X-GEO
X-NWS-UUID-VERIFY
SD-X-WS
X-Svr
True-Client-Country-4JS
X-Cache-Id
X-ServiceProvider
Resin-Trace
X-MSEdge-Features
X-Internal-Host
X-MSEdge-Flight
X-SD-PageType
X-LJ-Flow-ID
X-VWS-Id
X-Cdn-Forward
X-AWS-Id
V-Age
X-FPC
Server-ID
X-Edge-Server
Memory
Cdn-Request-Time
Cdn-Host
X-Instart-Isnd
X-Cache-URL
X-Be
X-Mode
X-Scheme
REQUESTUUID
X-GDPR
X-Cache-Backend
X-Org
X-Processor
X-Request-Time
X-DC
SS
X-Wa
X-ABtesting
X-Hello
X-Flog
X-CDN-Forward
Group
X-NodeID
X-Servedbyhost
X-IPS-LoggedIn
X-Datadome
X-Unique-ID
X-Response-By
X-Pjax-Url
Country-Code
X-Server-W
Cache-Host
X-DataStream-Cache-Status
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-From
Cache-Cookie-Set-Lfrom
X-EC-Lua
X-Oss-Storage-Class
X-VCL-Version
X-Oss-Server-Time
X-Ms-Version
X-Oss-Object-Type
X-Ms-Request-Id
X-Oss-Request-Id
X-Routing-Service
X-Proxied
X-Zipkin-Id
X-Oss-Hash-Crc64ecma
X-SN
PICS-Label
X-Page-Type
X-Ratelimit-Remaining
X-Ruxit-Js-Agent
X-Varnish-Beresp-Grace
X-Oracle-Dms-Rid
X-Varnish-Beresp-Status
X-Varnish-Beresp-Ttl
UCS
X-Webkit-Csp
X-RateLimit-Reset
Lfy
XServer
X-SRV
X-Via-Ucdn
X-HS-Status
X-Ftr-Request-Id
X-Session-Fingerprint
X-Tb-Optimization-Total-Bytes-Saved
X-Dynatrace
X-Zone
Ajk
X-MP-GENERATED-AT
X-URL
X-Agile-Id
X-Agile-Age
X-Agile
X-Logtrace-Id
Ttl
X-Cache-Debug
X-COUNTRY
Geoip-City
X-Pf-Uncompressing
GeoIp-Country-Code
Geoip-Latitude
X-GRACE
X-Fastly-Country-Code
ProcessTime
SN
Powered-By-ChinaCache
Proxy-Firewall
X-CSRF-Token
X-Varnish-Beresp-TTL
X-Source
X-ZONE
X-APP
Powered-By
X-Webapp-Samesite-None-Activated-N
X-7Graus-Varnish-Cache-Control
X-7Graus-Varnish-XKeys
X-HTML-Minification-Powered-By
X-Sedo-Request-Id
X-Cache-Miss-From
X-Sucuri-ID
X-Logging-Id
X-Grey
X-PF-Uncompressing
GeoIP-City
GeoIP-Country-Code
GeoIP-Latitude
Environment
X-Newrelic-Synthetics
X-Cache-Category-Id
X-DataStream-Origin-MEX-Latency
X-NODE
X-DataStream-MidMile-RTT
CACHE
X-Unique-Id
X-Ftr-Cache-Host
X-TH-Server
X-Sucuri-Id
X-Dynatrace-Js-Agent
X-Bc
X-CLOUD-TRACE-CONTEXT
X-Tt-Trace-Host
Cdn
Fastly-Backend-Name
M-TraceId
X-LiteSpeed-Cache-Control
X-Vcl-Version
X-Check-Cacheable
Pics-Label
CF-Cached-On
X-Core-Value
X-Edge
MIME-Version
X-Aicache-OS
GW-Server
WWW
X-Vdms-Version
X-Sucuri-Cache
X-Ftr-Backend
X-Ftr-Balancer
X-Ftr-Realm
Dynatrace
HostName
X-Ftr-Dc
X-Ftr-Backend-Server
X-Sigma-Backend
X-AK-Request-ID
X-NGINX-Cache
LB
X-Sigma
Requestid
X-RCS-CacheZone
X-Rocket-Build-Number
Cdnsip
X-Mid
X-Fastly-Backend-Reqs
Cdncip
X-LAGOON
Cf-Ipcountry
X-BC
X-Secret
X-FORWARDED-FOR
X-Planisys-CDN-TTL
Ohc-Response-Time
X-Varnish-Ttl
X-Shopify-Generated-Cart-Token
X-Gannett-Site-Version
X-Cache-Tag
X-Planisys-CDN-Cache
X-PJAX-URL
X-Fstrz
X-UPSTREAM-Address
X-MCACHE
X-Varnish-Url
X-Planisys-CDN-Rules
Pragrma
Amp-Access-Control-Allow-Source-Origin
X-Litespeed-Cache-Control
X-Via-NSCOPI
URI
X-TT-LOGID
X-ServedByHost
Lb
WZWS-RAY
X-Swift-Error
X-DB
X-CDN-Cache
X-BE
X-DW
X-RPS
X-RPM
X-RSL
X-DSS
X-DI
DataCenter
X-WA
X-Varnish-Cacheable
X-Action
On-Server
X-Cache-Ttl
X-SaId
X-ORACLE-APMCS-TAG
X-ORACLE-APMCS-REQUEST-ID
TTL
X-GeoIP-Country-Code
Xkeyrz
X-Proxy-Cacherz
Host-ID
Server-Id
User-Agent
X-WR-MODIFICATION
X-ND-Cache
RequestUuid
X-Correlation-ID
CDN
Is-Session-Tracking
Get-Access-Time
X-Trafficlayer-App-Version
X-Zalando-Child-Request-Id
X-Page-Impression-Id
X-Fastly-Cache-Hits
X-Flow-Id
X-Akamai-SSL-Client-Sid
X-Fpc
X-Upstream-Ct
Inserted-Into-Cache-At
X-Upstream-Ht
Xkeypdq
X-Nananana
X-Dw-Trace-Id
X-Via-SSL
X-Crawler
Warning
X-Refresh
X-Gen-Id
X-Via-Edge
X-NU-AKA-ACS-Version
X-Served-From
X-MID
X-VC
Who
Locid
SID
X-SB
Correlation-Id
X-Cf-Powered-By
X-Akamai-ERPolicy
X-Akamai-ERRuleID
Thinkindot-Cache-Type
X-Amzn-Remapped-Date
X-Amzn-Remapped-Connection
Gannett-Cam-Experience-Id
X-Req
Cneonction
X-Render-Time
X-ServerName
X-Newrelic-App-Data
X-Bug-Bounty
HitType
Processtime
X-ECache
X-Request-URL
X-FE
RequestId
X-LB-ID
Xet-Cookie
V-Cache
X-MiniProfiler-Ids
X-Gdpr
X-LiteSpeed-Tag