Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-Powered-By
Pragma
CF-Cache-Status
Link
ETag
Expect-CT
Via
Age
X-Cache
CF-RAY
X-XSS-Protection
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-Xss-Protection
X-Cache-Hits
P3P
X-Amz-Cf-Pop
Referrer-Policy
CF-Ray
X-Amz-Cf-Id
X-UA-Compatible
X-Served-By
Alt-Svc
X-Varnish
X-Request-Id
X-Timer
Access-Control-Allow-Headers
X-FRAME-OPTIONS
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Check
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Cacheable
X-Permitted-Cross-Domain-Policies
X-DNS-Prefetch-Control
X-Cache-Status
X-Generator
Timing-Allow-Origin
X-Iinfo
P3p
X-Ua-Compatible
X-Template
X-Language
X-AspNetMvc-Version
Status
Upgrade
X-CDN
X-Content-Security-Policy
X-Buckets
Content-Encoding
Access-Control-Expose-Headers
X-Request-ID
Access-Control-Max-Age
X-Kinja-Server-Push
X-XSS-PROTECTION
Keep-Alive
X-Via
X-Turbo-Charged-By
X-AH-Environment
X-Drupal-Dynamic-Cache
X-Envoy-Upstream-Service-Time
X-Cache-Group
X-Pass-Why
X-Ws-Request-Id
X-Backend
X-Age
X-Server
EagleId
X-Proxy-Cache
X-Amz-Id-2
X-Amz-Request-Id
Xkey
X-Robots-Tag
X-Page-Speed
X-Hacker
X-Pingback
X-Server-Powered-By
Feature-Policy
Server-Timing
X-Swift-SaveTime
X-Swift-CacheTime
Request-Context
Ali-Swift-Global-Savetime
X-Nginx-Cache-Status
Grace
X-Varnish-Cache
X-UA-Device
X-Amz-Version-Id
Cf-Railgun
Report-To
CONTENT-SECURITY-POLICY
X-LiteSpeed-Cache
X-Rq
X-OneAgent-JS-Injection
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Origin-Cache
X-Server-Id
EagleEye-TraceId
X-Host
X-Backend-Server
X-Vhost
X-Node
X-Response-Time
NEL
X-Dispatcher
X-WebKit-CSP
X-Ac
X-Cache-Lookup
X-Origin-Upstream-Status
X-Readtime
Surrogate-Control
Request-Id
Content-Location
X-Application-Context
Fusion-Source
Fusion-Content-Source
Fusion-Content-Id
Fusion-Component-Id
Fusion-Template-Id
X-Ruxit-JS-Agent
X-HW
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Cnection
X-DataDome
X-Country
X-Mod-Pagespeed
X-Cloud-Trace-Context
X-Akam-SW-Version
X-Url
Edge-Control
X-Rack-Cache
Rating
X-Clacks-Overhead
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
RTSS
X-FTR-Request-ID
X-Goog-Hash
X-PC
X-TtlSet
X-Vname
X-Varnish-TTL
X-Country-Code
X-ASPNET-VERSION
X-DynaTrace
X-Instart-Request-ID
Service-Worker-Allowed
Allow
Verso
X-GitHub-Request-Id
Content-MD5
X-Dns-Prefetch-Control
X-Server-Name
X-D2id
Pinterest-Generated-By
X-Exp-Variant
X-Exp-Id
X-GoogleNews-Bot
X-Kinja-Revision
X-Use-Magma
X-Kinja-Server
X-Cdn-Fetch
X-Kinja
X-Kinja-Build
X-MS-InvokeApp
X-ESI
Fusion-Deployment-Id
X-Cached
SPRequestGuid
X-Powered-By-Plesk
X-Navigation-Version
X-Forwarded-Proto
X-Vcache
TCN
X-Abt-Application-Version
X-Amz-Server-Side-Encryption
X-B3-TraceId
X-Trace
X-Amz-Rid
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
Public-Key-Pins
X-Fastly-Request-ID
X-Debug
Nginx-Cache
X-Ttl
X-SharePointHealthScore
X-MSEdge-Ref
X-Vcap-Request-Id
X-Server-ID
X-VARITI-CCR
Accept-CH
Arr-Disable-Session-Affinity
MS-Author-Via
Charset
X-Accel-Expires
X-Px
X-Cache-TTL
X-NF-Request-ID
SPIisLatency
SPRequestDuration
X-Middleton-Response
Response
Pagespeed
Display
X-Middleton-Display
Realpath
X-Content-Type
Edge-Cache-Tag
X-Fastcgi-Cache
Accept-CH-Lifetime
Accept-Ch
X-Sol
X-Ser
X-Client-IP
X-DynaTrace-JS-Agent
Cache-Tag
X-SRCache-Store-Status
X-Version
X-SRCache-Fetch-Status
NR-ENABLED
Front-End-Https
X-Powered-CMS
X-Webkit-Csp
X-Id
Pinterest-Version
Access-Control-Request-Method
X-Pinterest-Rid
X-Grace
S
X-Jurisdiction
AR-PoweredBy
AR-ATIME
AR-Request-ID
X-Hp-Webp
X-Upstream
Accept-Ch-Lifetime
X-Hits
X-T
X-Element-Page-Cache
X-Content-Digest
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Mrf-Section-Lastmod
MRF-Tech
X-Mrf-Item-Lastmod
X-Amz-Meta-S3cmd-Attrs
X-Forwarded-For
DynaTrace
X-Dw-Request-Base-Id
AR-CACHE
Ar-Sid
Fastcgi-Cache
X-Shield-Request-Id
X-Node-Name
ServerID
X-Cache-Hit
X-Mobile-URL
WPE-Backend
X-Recruiting
X-Country-Code-Real
PB-RID
X-FTR-Backend-Server
X-FTR-Realm
X-FTR-DC
X-FTR-Cache-Status
X-FTR-Balancer
X-FTR-Backend
PB-PID
X-Goog-Generation
X-GUploader-UploadID
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
Powered
TP-Cache
Server-Node
TP-L2-Cache
X-Frontend
X-HS-Cache-Config
X-HS-Content-Id
Arc-Version
X-HS-Hub-Id
X-Mobile-Rewrite
X-FTR-Expires
AMP-Access-Control-Allow-Source-Origin
X-DIS-Request-ID
Upgrade-Insecure-Requests
X-XRDS-Location
X-Amzn-Trace-Id
X-Request-Received
X-Request-Processing-Time
X-Ezoic-Cdn
X-Shard
Refresh
Alternate-Protocol
X-HS-Combine-CSS
X-NWS-LOG-UUID
X-Correlation-Id
Fastly-Restarts
X-Logged-In
X-Varnish-Age
X-TTL
X-Request-Handler-Origin-Region
Server-Name
X-Microsite
X-Page-Id
X-FTR-Cache-Host
X-Geo-Country
X-F-Cache
X-LB-Cache
X-B
X-Rid
X-User-Agent
X-N
X-Akamai-Edgescape
Backend-Timing
X-ATS-Timestamp
Host-Header
X-Content-Security-Policy-Report-Only
MicrosoftSharePointTeamServices
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Via-JSL
Host
X-Zen-Fury
X-XRDS-LOCATION
X-ORACLE-APMCS-REQUEST-ID
X-ORACLE-APMCS-TAG
X-Origin-Server
X-Varnish-Grace
Cache-Status
X-Kinsta-Cache
Healthy
X-Content-Options
X-Request-Guid
Fastcgi-Useragent
X-Hostname
Section-Io-Cache
X-App-Environment
Access-Control-Allow-Method
X-B-Cache
X-FB-Debug
X-Git-Hash
X-AOL-HN
X-TT
X-Signature
X-B3-Sampled
X-ATG-Version
X-Instance
X-Amz-Replication-Status
Frame-Options
X-Revision
X-Cache-Action
X-Jobs
X-Debug-Info
X-Tumblr-Pixel-0
X-Type
X-Tumblr-Pixel
Paypal-Debug-Id
Actual-Object-TTL
X-Tumblr-User
X-Varnish-Backend
X-Whom
X-WebKit-CSP-Report-Only
Trailer
Liferay-Portal
X-Cluster
X-Content-Powered-By
X-Seen-By
X-Amz-Apigw-Id
X-Cache-Rule
X-Cache-Operation
X-Tt-Trace-Host
X-Cache-Age
X-Tt-Trace-Tag
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-FastCGI-Cache
X-PHP-Backend
X-Contextid
X-Endurance-Cache-Level
X-FireWall-Port
Tracecode
X-Amzn-Requestid
X-Cache-Key
X-Activity-Id
X-Az
X-AppVersion
X-Framework
X-WA-Info
X-Host-Name
X-Daa-Tunnel
X-Cached-By
Retry-After
X-IPLB-Instance
Source
X-Srv
X-Upgrade-Enabled
X-Mobile
Accept-Charset
NGB
X-Response-Served-From
X-Accel-Buffering
X-ProcessESI
X-RemovedCookies
DC
Srv
X-Is-Bot
X-Rendered-As
X-UUID
X-FW-Server
X-FW-Type
X-Handled-By
X-RateLimit-Remaining
Xserver
X-FW-Static
X-Adobe-Content
X-FW-Serve
Payment
X-Adobe-Loc
Surrogate-Key
X-FW-Hash
X-Cacheable-TTL
X-Tumblr-Pixel-2
X-Varnish-Server
X-Tumblr-Pixel-1
X-L-Path
X-Environment-Context
X-Cache-NE
X-Region
X-RequestSource
Eomportal-Instance
X-Presslabs-Stats
From-Origin
X-GeoIP
Filters
X-Origin-Response-Time
X-Varnish-Hostname
X-UA-Device-Type
X-Cache-TTL-Remaining
X-Time-Microsecs
X-Proxy
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Wix-Request-Id
Filterid
X-EdgeConnect-Cache-Status
X-NGENIX-Cache
Server-Info
X-Backend-Name
X-APP-VERSION
X-Cache-Server
X-Esi
X-Unique-Id
Cache-Tv-Group
X-Cache-2
MS-CV
Datacenter
X-TIME
X-Akamai-Transformed
Version
X-Cache-Enabled
X-Status
X-Oss-Request-Id
X-CST
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Oss-Storage-Class
X-Cache-Time
X-Oss-Server-Time
X-Cache-Control
X-Mode
S-Cnection
X-Yottaa-Metrics
X-Yottaa-Optimizations
GEO-INFO
X-CCM
X-Path-Route
X-Cache-Var-Map
Meta-Geo
X-Cache-Var
X-ES-SERVER
Webserver
X-Detected-As
X-RN-RSRV
X-Loop
X-TNCMS
Ec-Rule-Version
X-IP
X-Via-Fastly
X-R9-Blue-Green-Version
X-Real-IP
X-Ua-Device
Cleartype
ServedBy
X-FC-Vary-Parameters
Cache-Tags
X-Hl-Ver
X-PERF
X-ApacheServer
S-Rt
X-Forwarded-Host
X-Adobe-Source
X-FW-Dynamic
X-TX-ID
Country
OT-Force-Account-Verify
Webcakes-App-Version
Webcakes-Region
Akamai-GRN
TWC-Locale-Group
TWC-Privacy
Content-Disposition
Webcakes-App-Name
X-Amzn-Remapped-Content-Length
X-BYPASS-REASON
X-Cache-Config
Cache-Key
TWC-Connection-Speed
TWC-Device-Class
X-Alternate-Cache-Key
TWC-GeoIP-Country
X-Vgn-Hpd-Reason
X-Proto
X-Locale
X-Shopify-Stage
Property-Id
Now
X-Sorting-Hat-PodId
NGX
X-Sorting-Hat-ShopId
Section-Io-Id
Origin-Cache-Control
X-Shopify-Generated-Cart-Token
X-Say-TTL
Origin-Edge-Control
X-Say-Cacheable
X-ServerID
X-Origin-Hint
X-ShopId
X-Origin
X-ShardId
Section-Io-Origin-Status
X-Human
TWC-GeoIP-LatLong
Decoy-Debug-TTL
X-Pubstack
Decoy-Debug-Status
Decoy-Debug-Key
X-SayCDN-TTL
DB-Nickname
X-Web-Node
X-EIG-Tracking-Id
X-Tb
Section-Io-Origin-Time-Seconds
X-RCS-CacheZone
X-Hosted-By
X-ProxyCache-Key
X-ProxyCache-Status
Section-Origin-Responded
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Redis-Cache
Selected-Fe
X-Zipkin-Id
X-Xfnlog-Site
X-Proxy-Build
X-Proxied
X-Proxy-Cache-Status
X-SaId
X-Routing-Service
X-Soup
X-JoinUs
X-NYM-Debug-Backend
X-Section
X-MP-GENERATED-AT
X-Site-Version
X-LJ-Flow-ID
X-Generated
X-Timing-Wait
X-Cache-Status-Check
X-Content-Age
X-BCube-Filmed-By
X-AWS-Id
X-Akamai-Request-ID2
X-Debug-Cache
X-Device-Type
X-Format
X-Request-Time
X-VWS-Id
X-Www-Served-By
X-FB-TRIP-ID
X-Access
Mn-Server-Ip
Azure-SiteName
Azure-SlotName
Azure-RegionName
X-Aspnetmvc-Version
X-HTML-Minification-Powered-By
Access-Control-Request-Headers
Azure-Version
Azure-InstanceId
X-PressLabs-Stats
Cross-Origin-Window-Policy
Cache-Hits
X-Viewer-Country
Node
X-NCache
X-Dc
X-IPS-LoggedIn
X-Akamai-Request-ID
X-Cdn
X-Cache-Remote
X-Varnish-Hits
X-CACHE-KEY
X-Pad
Odigeo-Trace-Id
X-Generated-By
X-Geo
X-B3-Traceid
X-EC-Lua
X-NewRelic-App-Data
Nel
X-Microcachable
X-Rule
X-No-Session
X-Drupal-Cache-Tags
X-Cache-NGX
Accept-Language
X-Amzn-RequestId
X-Backend-TTL
X-Uri
Time
X-From
Cf-Ipcountry
X-Azure-Ref
X-SS-Set-Cookie
X-RateLimit-Limit
Ms-Operation-Id
X-Webkit-CSP
X-RTag
X-NWS-UUID-VERIFY
X-Source
FilterID
X-App-Server
X-OCL
X-PCL
User-Agent
X-Qloud-Router
X-PHP-Host
X-CF-Powered-By
X-Labrador-Cache-Channel
X-Varnish-Cache-Hits
X-GoCache-CacheStatus
X-SERVER
X-Hyper-Cache
Proxy-Connection
X-Old-Content-Length
X-Nginx-Cache
Uber-Trace-Id
Cache-Name
X-Cache-Grace
X-Info
X-NC
X-Drupal-Cache-Contexts
X-Storage
X-Newrelic-Synthetics
X-Oneagent-Js-Injection
X-CS
X-VCT
X-Aed
X-ARC
X-Accel-Expires-Debug
X-B-Cookie
X-Cdn-Srv
X-Application
ServerName
Apple-News-Services-Request-Url
Arc-Country
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Mobile-Detection-Method
Apple-News-Services-Handled
AsisCache
BehaviorPad-Version
GEO-REGION-INFO
Fastcgi-X-Cache-Version
Machine
MD5-Digest
Meta-Geo-Continent
A
Rendered-Blocks
X-A-Ccd
X-A
X-A-Dam
X-A-Dcw
X-A-Dgt
VivaBuild
Viewtype
Request-EU
Request-Country
T-Server
True-Client-Country-4JS
X-Edge-Location
X-A-Wwc
X-G
X-Rewrite-Enabled
X-Request-UUID
X-Rojux
X-S
X-S-Cookie
X-Request-URI
X-Region-Sid
X-OVcl-Cache
X-PAYTM-SRV-ID
X-CF-Lambda-Fn
X-Reboot
X-ScT
X-Session-Fingerprint
X-VG-WebServer
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-VG-WebCache
X-Vdms-Version
X-SRCache-Key
X-Transaction
X-Trv-Group
X-Twitter-Response-Tags
X-OVcl
X-Processor
X-Destination
X-Developer
X-DPWN-IS-SECURE
X-Date
X-Edge-O15-RID
X-CF-Lambda-Version
X-Connection-Hash
X-D
X-GeoIP-Country-Code
X-External-Request-Id
X-Time
X-Cluster-Name
X-Backend-State
X-Cdn-Origin
X-Thinkindot-L3
X-Level-Front-Cache
X-Sn-Servicetimems
N-Cache
X-Matched-Rule
X-LI-UUID
X-Core-Value
X-Li-Pop
Content-Style-Type
X-VServer
Memcached
PFcat
X-LI-Proto
X-VG-TLSProxy
X-DevSite-Last-Modified
X-GeoIP-City
X-Geo-Header
Rt-Fastcgi-Cache
X-JWT-State
Thinkindot-CacheControl
X-Has-Esi
Thinkindot-Control
Thinkindot-CacheControl-Type
X-Generated-On
X-Rocket-Nginx-Bypass
X-Served-From
X-Servername
X-ServiceProvider
Viewport
X-Li-Fabric
Content-Script-Type
X-FW-Version
X-Is-Gdpr
X-Cache-Expired-At
Cache-Cookie-Set-Idcheck
X-Varnish-Beresp-Status
Cache-Cookie-Set-From
X-UA
X-Cluster-Node
X-Varnish-Beresp-Grace
Cache-Cookie-Set-Lfrom
X-S-Maxage
User-Cache-Control
X-Varnish-Beresp-Ttl
X-BBXSRF
X-Backend-Host
X-Req
X-Auto-Login
X-Bc-Bl
X-Bip
X-Rebelmouse-Cache-Control
X-RateLimit-Remaining-Second
X-Cache-FS-Status
X-Cache-Bucket
X-Rebelmouse-Surrogate-Control
X-Block-Status
X-Cache-ASPX
X-Request-Host
X-App-Name
Wxu-Next-Region
X-SIPLIST1
X-Sigma-Backend
Wxu-Next-Hostname
X-Irp-Debug
Web-Mar-Node
Wxu-Next-Commit
X-Sigma
X-IN-APIGATEWAYSSL
X-Scheme
X-Rocket-Build-Number
X-Agile-Id
X-Agile-Age
X-Agile
X-LAGOON
X-RateLimit-Limit-Second
X-Cache-Info
X-Distil-CS
X-Distributor
X-NodeID
X-Device-Os
X-Developers
X-Debug-Cache-Store
X-Origin-Date
X-Nginx-Cache-Key
X-Ms-Version
X-Fetched-On
X-Magnolia-Registration
X-Fastly-Cache
X-Micro-Cache
X-Epic-Correlation-Id
X-Ms-Request-Id
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-Gamma-Serve
X-Logging-Id
X-Clara-WADP
X-Cache-URL
W
X-Generated-In
X-Gen-Mode
X-Clientip
X-Cms-Context
X-Owner
X-Origin-Expires
X-Platform-Server
X-CUA
X-Contensis-Viewer-Groups
X-Core-Mission
X-Fmm-Version
X-Server-W
Platform
X-IN-APIGATEWAY
X-VC-Cache
X-Urbn-Context-Path
X-Urbn-Site-Id
FNAC-ModuleRouting
X-Tumblr-Pixel-3
X-Trafficlayer-App-Version
X-Trafficlayer-App-Scope
X-Variation
X-TT-TIMESTAMP
Fastly-SWR
On-Server
Adler-Geo
Locid
X-Hnp-Log
Locale
X-Varnish-Cacheable
Gh-Request-Id
IsBot
X-Var-Ttl
AKAMAI
CDCHOST
Is-Eu
Cache-Host
RNT-Machine
Fastly-SIE
X-Wikidot-Backend
Heartbleed
X-Webstats-RespID
Country-Code
X-Varnish-Authentication
Group
X-Wikidot-Static-Cache
X-Skip-Cache
X-Slack-Backend
V-Age
X-Swa-Ws
Countrycode
X-WebServer
Server-Host
Fastly-Drupal-HTML
Server-Cache-Control
X-Trafficlayer-App-Name
RNT-Time
X-WADP-Cache
Server-ID
X-We-Are-Hiring
X-Thanos
X-Trace-Id
Server-Surrogate-Control
X-TrackingId
X-Debug-Log
X-Debug-Cookies
X-Eu-Site
Powered-By-ChinaCache
X-Generation-Time
Geo-Info
Ha-Gx-Prefs
X-Dispatch
X-Dispatcher-Server
X-NX-Host
X-CGP
X-Hash
X-UnsetCookies
X-Cache-Tags
X-C
HA-Ipaddr
Cache
X-Hit
X-Nc
X-Response-By
Mail-Subject
L5d-Success-Class
X-Instart-Isnd
Kp-EeAlive
X-Proxy-Upstream
We-Hiring
X-Sucuri-ID
X-MCACHE
X-Node-Id
X-VHOST
X-Edge
SD-X-WS
X-Lb-Id
Pramga
X-Instart-Info
X-Refresh
X-RESPONSE-TIME
Mime-Version
X-CDN-Forward
X-SN
X-CLOUD-TRACE-CONTEXT
Cloudfront-Viewer-Country
X-ND-Cache
Proxy-Firewall
X-Service
X-APP
X-TA-CDN-Provider
X-Load-Cache
X-ECACHE
X-B3-Spanid
HitType
Vix-Hermes-Req-Id
X-Varnish-URL
X-VCache
X-Cache-PHP
Environment
X-Mid
X-Vdms-Path
Request-Time
X-Varnish-Ttl
X-Parent-Response-Time
X-Wa
Origin
X-Pjax-Url
M-TraceId
CF-Cached-On
X-App-Version
X-MSEdge-Features
X-MSEdge-Flight
X-BACKEND-TTL
X-CSRF-Token
NM-Fastcgi-Cache
X-CSRF-TOKEN
X-Correlation-ID
X-Ruxit-Js-Agent
X-Ua
Server-Ext
X-Up
Hostname
Server-Hostname
Sever-Int
Fastly-Backend-Name
PICS-Label
X-Origin-CC
X-Ratelimit-Remaining
X-Origin-TTL
Geoip-City
Geoip-Latitude
X-FPC
X-COUNTRY
Pagetype
HostName
X-Be
Pragrma
X-Cdn-Forward
X-Server-Time
X-Pinterest-Direct
X-Method
X-Wix-Viewer-Type
X-FORWARDED-FOR
X-Via-PopV
GeoIp-Country-Code
X-ECache
X-Worker
X-TT-LOGID
X-Via-PopH
X-Edge-Server
Cdn-Host
X-Protected-By
Cdn-Request-Time
Magicmarker
X-URL
X-Envoy-Upstream-Healthchecked-Cluster
X-Newrelic-App-Data
X-Servedbyhost
X-Request-Start
Cdn
X-Branch-Name
X-Myra-Origin2
TTL
NtCoent-Length
X-HS-Status
X-DC
X-Policy
X-Litespeed-Cache
X-Referer
Dt-Cache-Category
Memory
Cdnsip
X-Azure-Ref-OriginShield
X-AK-Request-ID
Cdncip
X-Vcl-Version
X-C-Key
CACHE
X-GEO
X-C-Zone
X-Cache-Metadata
X-SRV
X-Planisys-CDN-Cache
X-NU-AKA-ACS-Version
Resin-Trace
X-BC
XServer
X-Zone
X-SVT-ORM-VERSION
X-ZONE
X-SVT-ORM-RULES
X-Planisys-CDN-TTL
X-Bc
X-Planisys-CDN-Rules
Cteonnt-Length
SRV
Lb
X-Dynatrace-Js-Agent
Esi-Enabled
X-Air-Hostname
Release
X-Cache-Host
Ohc-File-Size
X-VCL-Version
X-Ratelimit-Limit
X-Pf-Uncompressing
Load-Balancing
Who
Ttl
X-ServedByHost
X-NGINX-Cache
X-Swift-Error
RequestId
GeoIP-Country-Code
X-Via-Ucdn
X-Cache-Debug
X-TH-Server
X-Reqid
X-Esi-Check
X-Configured-By
X-Cache-Id
X-Tec-Api-Origin
X-Tec-Api-Root
X-AIR-PT
IBM-Web2-Location
Dnion-Transfer-Encoding
GeoIP-Latitude
X-Tec-Api-Version
X-Country-IP
GeoIP-City
Ohc-Cache-HIT
X-Fastly-Country-Code
X-Gzip
UCS
Pics-Label
X-Node-ID
X-VarnishDD-TTL
X-Datadome
X-Fpc
Server-Int
X-Tb-Optimization-Total-Bytes-Saved
Product
FSS-Cache
MIME-Version
X-Unique-ID
LB
X-WA
X-Ocache
Sid
Powered-By
X-WPE-Loopback-Upstream-Addr
X-Svr
X-Powered-Y
X-PJAX-URL
X-Fastly-Backend-Reqs
X-Server-IP
X-RAMCache
X-B3-SpanId
X-SERVER-NAME
X-PF-Uncompressing
Fastly-SSL
Lfy
X-Fastly-Request-Id
Fastly-Soc-X-Request-Id
X-Varnish-Url
X-DSS
X-MID
X-RPM
X-DB
X-DW
X-DI
C-Via
X-Apw-Hits
X-Action
X-RSL
X-Varnish-Beresp-TTL
X-Apw-Access-Token
X-SD-PageType
X-BE
X-RPS
X-Apw-Access-Object
X-Apw-Access-Action
X-Zalando-Child-Request-Id
X-Hello
X-Flow-Id
X-Flog
Amp-Access-Control-Allow-Source-Origin
FSS-Proxy
CDN
X-Page-Impression-Id
X-LiteSpeed-Cache-Control
X-ABtesting
Requestid
X-ElasticPress-Search
X-Agile-Brick-Ok
Xet-Cookie
CF-IPCountry
X-Aicache-OS
SN
X-Amzn-Remapped-Date
X-Amzn-Remapped-Connection
X-B3-Parentspanid
X-Debug-Revision
X-LB-ID
L
X-Compress-Hint
X-Location
X-Debug-Controller
Host-ID
X-Render-Time
My-App
X-Check-Cacheable
X-Sucuri-Cache
X-UPSTREAM-Address
X-Mvc-Supplant-OutputCached
Cneonction
URI
X-Mvc-Supplant-Cachable
X-Fastly-Cache-Hits
X-Via-CDN
X-User
X-MiniProfiler-Ids
X-App
CloudFront-Viewer-Country
X-Dw-Trace-Id
DataCenter
X-Request-URL
X-Cache-Backend
X-Nananana
X-Request-Url
ProcessTime