Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
CF-RAY
CF-Cache-Status
Link
X-XSS-Protection
X-Powered-By
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Alt-Svc
Access-Control-Allow-Credentials
X-Runtime
X-FRAME-OPTIONS
X-Drupal-Cache
X-Adblock-Key
X-Check
Content-Security-Policy-Report-Only
X-Xss-Protection
X-Generator
X-Cacheable
X-Cache-Status
X-Permitted-Cross-Domain-Policies
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Template
X-Language
X-Iinfo
X-Content-Security-Policy
Status
Content-Encoding
X-AspNetMvc-Version
X-Request-ID
X-Buckets
X-Kinja-Server-Push
Upgrade
Xkey
X-Via
Access-Control-Expose-Headers
X-Turbo-Charged-By
Access-Control-Max-Age
Keep-Alive
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Pass-Why
EagleId
X-Age
X-Backend
X-Envoy-Upstream-Service-Time
X-Robots-Tag
X-Amz-Id-2
X-Amz-Request-Id
X-Page-Speed
X-CDN
X-Pingback
X-Server-Powered-By
X-Server
X-AH-Environment
X-Proxy-Cache
X-UA-Device
X-Hacker
Request-Context
X-Swift-CacheTime
X-Swift-SaveTime
X-Nginx-Cache-Status
Grace
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-Cdn
P3p
X-LiteSpeed-Cache
Cf-Railgun
Server-Timing
X-Ua-Compatible
Feature-Policy
X-Amz-Version-Id
X-Device
X-Server-Id
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-WebKit-CSP
X-OneAgent-JS-Injection
X-Rq
X-Ac
EagleEye-TraceId
X-Cnection
Report-To
X-Cloud-Trace-Context
Request-Id
X-Backend-Server
X-Response-Time
X-Node
Content-Location
X-Host
X-Readtime
X-Origin-Cache
X-Vhost
X-Dns-Prefetch-Control
X-Cache-Lookup
X-Application-Context
X-DataDome
X-ORACLE-DMS-ECID
X-Dispatcher
NEL
X-ORACLE-DMS-RID
X-Ruxit-JS-Agent
X-Rack-Cache
X-Origin-Upstream-Status
X-HW
Surrogate-Control
X-Clacks-Overhead
Rating
X-Country-Code
Allow
X-Country
X-FTR-Request-ID
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Url
X-DynaTrace
X-MS-InvokeApp
X-Goog-Hash
Fusion-Content-Id
Fusion-Component-Id
Fusion-Content-Source
Fusion-Source
X-Instart-Request-ID
Fusion-Template-Id
X-TTL
X-PC
X-Vname
X-TtlSet
X-Varnish-TTL
X-B3-TraceId
Pinterest-Generated-By
Verso
X-Powered-By-Plesk
X-Px
Public-Key-Pins
RTSS
Edge-Control
X-Mod-Pagespeed
X-ESI
SPRequestGuid
X-Middleton-Display
Response
Display
X-Ah-Environment
X-Sol
X-Middleton-Response
X-VARITI-CCR
X-Exp-Variant
X-Exp-Id
X-Use-Magma
X-Kinja-Server
X-Kinja-Build
X-Kinja
X-Cdn-Fetch
X-SharePointHealthScore
X-Kinja-Revision
X-GoogleNews-Bot
X-D2id
X-Akam-SW-Version
Accept-Ch-Lifetime
X-Recruiting
Service-Worker-Allowed
SPIisLatency
SPRequestDuration
X-Vcap-Request-Id
X-CST
X-Server-Name
X-GitHub-Request-Id
X-Version
X-Powered-CMS
MS-Author-Via
X-Navigation-Version
X-Abt-Application-Version
TCN
X-Trace
Charset
X-Debug
X-Shard
X-Amz-Server-Side-Encryption
Fastly-Restarts
X-Amz-Rid
X-Aspnetmvc-Version
Nginx-Cache
Realpath
X-Upstream
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
Accept-CH
Ar-Sid
AR-PoweredBy
AR-CACHE
AR-ATIME
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-NF-Request-ID
X-Forwarded-Proto
X-Ezoic-Cdn
Front-End-Https
X-Goog-Metageneration
X-RateLimit-Remaining
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-MSEdge-Ref
DynaTrace
Access-Control-Request-Method
X-Cached
Arr-Disable-Session-Affinity
Content-MD5
Pagespeed
X-Shield-Request-Id
AR-Request-ID
MRF-Tech
X-Mrf-Item-Lastmod
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Mrf-Section-Lastmod
MicrosoftSharePointTeamServices
X-FTR-Cache-Status
X-Country-Code-Real
X-FTR-Expires
X-Amz-Meta-S3cmd-Attrs
S
X-Goog-Storage-Class
X-DynaTrace-JS-Agent
X-Ser
X-VCache
X-Fastly-Request-ID
X-T
X-Id
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-DC
X-FTR-Realm
X-FTR-Backend
X-Varnish-Age
X-XRDS-Location
Paypal-Debug-Id
Accept-Ch
ServerID
X-Via-JSL
X-Fastcgi-Cache
X-Grace
X-Accel-Expires
X-Correlation-Id
X-Content-Type
X-Client-IP
X-Dw-Request-Base-Id
X-Forwarded-For
Edge-Cache-Tag
Fastcgi-Cache
X-Amzn-Trace-Id
X-Hits
X-Frontend
X-Vcache
X-Content-Digest
Powered
X-DIS-Request-ID
X-N
X-Pinterest-Rid
Pinterest-Version
X-HS-Hub-Id
X-HS-Content-Id
PB-RID
Arc-Version
X-Mobile-Rewrite
PB-PID
X-FTR-Cache-Host
AMP-Access-Control-Allow-Source-Origin
X-Logged-In
Server-Name
X-Server-ID
TP-L2-Cache
TP-Cache
X-Kinsta-Cache
X-Request-Processing-Time
X-Request-Received
X-Cache-Hit
X-Microsite
X-Request-Handler-Origin-Region
X-Zen-Fury
X-Activity-Id
X-Az
X-AppVersion
X-LB-Cache
X-IPLB-Instance
X-Cache-Age
X-User-Agent
X-Rid
X-Revision
X-Type
Healthy
Retry-After
X-Time
X-Whom
X-Srv
Backend-Timing
X-Analytics
X-Node-Name
X-FastCGI-Cache
X-GUploader-UploadID
X-B3-Sampled
Server-Node
FilterID
X-NWS-LOG-UUID
X-RateLimit-Limit
Cache-Tag
X-Hp-Webp
Alternate-Protocol
Accept-Charset
X-SERVER
X-F-Cache
NR-ENABLED
X-Akamai-Edgescape
X-Content-Security-Policy-Report-Only
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Webkit-CSP
X-Cache-Rule
X-Content-Options
Cache-Status
DC
X-Amzn-RequestId
MS-CV
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Amz-Apigw-Id
X-Content-Powered-By
Refresh
X-Tumblr-User
X-Tumblr-Pixel-0
X-AOL-HN
X-Cluster
Access-Control-Allow-Method
X-FB-Debug
X-Tumblr-Pixel
X-Instance
X-Framework
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-App-Environment
X-Cache-2
X-Debug-Info
X-Varnish-Grace
X-Jobs
Tracecode
Source
X-B
X-Page-Id
X-PHP-Backend
X-Forwarded-Host
Actual-Object-TTL
X-Seen-By
X-Request-Guid
X-Cache-TTL
Fastcgi-Useragent
Surrogate-Key
X-Mobile-URL
Frame-Options
X-Cache-Operation
X-App-Server
Host
X-Geo-Country
X-Cache-Control
X-FW-Hash
X-FW-Static
X-FW-Server
X-FW-Serve
X-FW-Type
X-Cache-Key
X-TA-CDN-Provider
X-Cached-By
X-Host-Name
X-Pad
Cleartype
X-Element-Page-Cache
X-Signature
X-Hostname
X-B-Cache
Upgrade-Insecure-Requests
X-WebKit-CSP-Report-Only
X-Git-Hash
X-Mobile
X-XRDS-LOCATION
X-ATG-Version
X-BCube-Filmed-By
X-Response-Served-From
X-Varnish-Backend
NGB
X-HS-Cache-Config
Xserver
X-UA-Device-Type
X-GeoIP
X-RemovedCookies
X-Daa-Tunnel
X-ProcessESI
WPE-Backend
Ms-Operation-Id
X-RTag
Filters
X-Amz-Replication-Status
Cache-Tv-Group
Eomportal-Instance
Webserver
X-EdgeConnect-Cache-Status
X-Handled-By
X-TT
X-Tumblr-Pixel-1
X-Origin-Server
X-Tumblr-Pixel-2
X-Adobe-Loc
X-Adobe-Content
X-Drupal-Cache-Tags
X-TX-ID
GEO-INFO
From-Origin
X-Cacheable-TTL
X-RequestSource
Payment
X-TT-TIMESTAMP
X-Wix-Request-Id
Cache
X-Cache-TTL-Remaining
X-Status
X-Cache-Remote
Datacenter
X-Esi
X-Webkit-Csp
X-WA-Info
X-FW-Dynamic
Liferay-Portal
X-Presslabs-Stats
X-Hyper-Cache
X-Contextid
X-Region
Version
X-Cache-Action
X-Ratelimit-Reset
X-Edge-Location
X-Ttl
X-Acc-Meta-Resource-Type
Viewport
X-Content-Age
X-Cache-NE
X-Akamai-Transformed
X-B3-Traceid
X-HS-Combine-CSS
X-Storage
X-PressLabs-Stats
PageSpeed
X-Varnish-Hostname
X-Cache-Server
X-CF-Powered-By
Accept-CH-Lifetime
X-Oneagent-Js-Injection
X-Varnish-Server
X-ES-SERVER
Meta-Geo
X-RN-RSRV
Load-Balancing
X-Path-Route
X-Cache-Var
X-Cache-Var-Map
Host-Header
X-Cache-Grace
X-Cache-Enabled
X-IP
X-Viewer-Country
X-Accel-Buffering
X-CCM
Cache-Tags
X-Cache-Config
Ohc-File-Size
X-Via-Fastly
Country
X-Proxy
X-Xfnlog-Site
Cache-Hits
X-Yottaa-Metrics
Cache-Name
X-Loop
X-PCL
X-Akamai-Request-ID2
X-Proto
Vix-Hermes-Req-Id
X-TNCMS
X-OCL
X-Yottaa-Optimizations
X-NCache
X-UnsetCookies
X-Labrador-Cache-Channel
DB-Nickname
Release
Rt-Fastcgi-Cache
X-Debug-Cache
X-Cache-Host
X-Cache-Time
Decoy-Debug-TTL
Webcakes-App-Version
TWC-Privacy
Property-Id
TWC-Connection-Speed
Decoy-Debug-Status
S-Rt
Selected-Fe
X-Rule
X-R9-Blue-Green-Version
X-Proxy-Build
X-Origin-Hint
X-Origin
TWC-Locale-Group
X-JoinUs
X-Human
TWC-GeoIP-LatLong
X-Hosted-By
DSUID
TWC-Device-Class
Decoy-Debug-Key
TWC-GeoIP-Country
X-Goog-Meta-Goog-Reserved-File-Mtime
Ec-Rule-Version
Webcakes-App-Name
X-Vgn-Hpd-Reason
X-Trace-Id
X-Web-Node
X-Www-Served-By
X-Tumblr-Pixel-3
X-Upgrade-Enabled
X-Varnish-Hits
X-Varnish-Cache-Hits
X-Backend-TTL
X-Backend-Name
Webcakes-Region
X-Timing-Wait
X-From
X-Device-Type
X-EIG-Tracking-Id
X-CS
S-Cnection
X-FC-Vary-Parameters
X-Time-Microsecs
X-VCT
Azure-Version
Cache-Key
X-Generated
Mn-Server-Ip
X-NewRelic-App-Data
X-FireWall-Port
X-Cluster-Node
Azure-SlotName
X-PERF
Azure-SiteName
X-Akamai-Request-ID
X-Site-Version
X-Origin-Response-Time
X-ApacheServer
Azure-InstanceId
X-Locale
X-Drupal-Cache-Contexts
Azure-RegionName
X-Pubstack
X-Access
X-Section
X-Hit
X-OVcl-Cache
X-Real-IP
X-OVcl
X-Rendered-As
Origin-Edge-Control
Origin-Cache-Control
X-Format
X-S
Server-Info
Ohc-Cache-HIT
X-Trafficlayer-App-Name
X-Trafficlayer-App-Scope
X-Redis-Cache
L5d-Success-Class
Time
X-NGENIX-Cache
X-Ua
X-Origin-CC
X-Origin-TTL
X-FW-Version
X-Litespeed-Cache
Now
Fastcgi-X-Cache-Version
X-SS-Set-Cookie
Fastly-SSL
OT-Force-Account-Verify
ServedBy
Hostname
Origin
X-Upstream-HT
X-Cluster-Name
X-Upstream-CT
X-ServerID
X-APP-VERSION
Cteonnt-Length
X-Alternate-Cache-Key
X-ShardId
X-UUID
Access-Control-Request-Headers
Mime-Version
X-Guploader-Uploadid
X-ShopId
X-App-Version
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Shopify-Stage
X-Load-Cache
X-Rocket-Nginx-Bypass
X-GoCache-CacheStatus
X-FB-TRIP-ID
X-Soup
X-Parent-Response-Time
NtCoent-Length
X-VG-WebCache
Accept-Language
NGX
X-Is-Bot
X-VG-TLSProxy
Machine
X-UA
Odigeo-Trace-Id
X-Upstream-Proxy
X-Info
X-Uri
Nel
X-B3-SpanId
IBM-Web2-Location
X-Geo
X-CACHE-KEY
X-No-Session
X-Tb
X-MServer
X-ECACHE
X-BYPASS-REASON
X-ProxyCache-Status
X-L-Path
X-ProxyCache-Key
X-Node-Id
X-Environment-Context
X-Nc
Srv
X-Cdn-Forward
X-Tt-Trace-Tag
A
X-ARC
X-Application
X-Cms-Context
X-Rewrite-Enabled
X-Connection-Hash
X-Rojux
X-CF-Lambda-Version
X-PHP-Host
X-Tec-Api-Version
X-S-Cookie
Uber-Trace-Id
X-Tec-Api-Root
X-Tec-Api-Origin
X-B-Cookie
Xc-Version
X-AIR-PT
Arc-Country
ServerName
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
T-Server
GEO-REGION-INFO
Viewtype
Fly-Cache
Fly-Request-Id
Rt-Proxy-Cache
MD5-Digest
X-VG-WebServer
Request-Country
Rendered-Blocks
Request-EU
Node
Memcached
Meta-Geo-Continent
Mobile-Detection-Method
VivaBuild
Cross-Origin-Window-Policy
BehaviorPad-Version
X-Aed
X-Accel-Expires-Debug
AsisCache
X-D
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Cache-Prefix
X-A-Wwc
X-A
Content-Script-Type
Content-Style-Type
X-A-Ccd
X-A-Dam
X-A-Dgt
X-A-Dcw
Apple-News-Services-Handled
X-CF-Lambda-Fn
X-DPWN-IS-SECURE
X-Server-Time
X-Developer
X-Detected-As
X-Transaction
X-Destination
X-External-Request-Id
X-Instart-Info
X-Trv-Group
X-Hl-Ver
X-Region-Sid
X-Twitter-Response-Tags
X-G
X-Request-UUID
X-CSRF-TOKEN
Proxy-Connection
X-SRCache-Key
X-Date
X-PAYTM-SRV-ID
X-B3-Parentspanid
X-ScT
Request-Time
User-Cache-Control
X-Endurance-Cache-Level
Backend-Name
IsBot
X-Worker
X-Is-Gdpr
X-ElasticPress-Search
X-Gen-Mode
X-Has-Esi
X-NX-Host
X-Hnp-Log
X-SVT-ORM-RULES
X-SIPLIST1
X-Proxy-Cache-Status
X-JWT-State
X-Proxy-Upstream
X-WADP-Cache
X-Generated-By
N-Cache
X-Debug-Log
X-S-Maxage
X-Cache-Bucket
X-Cache-Info
X-Amzn-Remapped-Content-Length
X-Debug-Cookies
X-SVT-ORM-VERSION
X-Cdn-Srv
X-Cdn-Origin
X-Block-Status
X-Sn-Servicetimems
X-Request-URI
X-Device-Os
X-Clara-WADP
X-Nginx-Cache
We-Hiring
X-Via-CDN
Mail-Subject
CF-IPCountry
X-Li-Fabric
Pramga
Section-Io-Cache
X-Level-Front-Cache
RNT-Time
Served-By
True-Client-Country-4JS
Thinkindot-CacheControl-Type
Server-Int
X-Magnolia-Registration
X-Matched-Rule
X-Irp-Debug
Server-Host
X-Location
X-Li-Pop
Thinkindot-Control
RNT-Machine
Thinkindot-CacheControl
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-Fastly-Cache
X-Developers
X-Bip
X-User
X-Dispatch
X-BBXSRF
X-Backend-Host
X-Backend-Url
X-Cache-FS-Status
X-Cache-Id
X-Debug-Cache-Expiry
X-Clientip
X-Compress-Hint
X-Debug-Cache-Fetch
X-VC-Cache
X-Urbn-Site-Id
X-Debug-Cache-Store
X-Dispatcher-Server
X-Distributor
X-Generation-Time
X-Generated-On
X-Generated-In
X-Geo-Header
X-GeoIP-City
X-Hash
Web-Mar-Node
X-Var-Ttl
X-Up
X-LI-UUID
X-Auto-Login
X-Amz-Meta-Cache-Control
X-Urbn-Context-Path
X-Fetched-On
X-CUA
X-Variation
Fastly-Soc-X-Request-Id
X-Say-TTL
X-Say-Cacheable
Platform
X-Owner
X-Platform-Server
X-SayCDN-TTL
X-Webstats-RespID
Adler-Geo
CDCHOST
X-WebServer
X-Old-Content-Length
X-Origin-Date
X-Origin-Expires
AKAMAI
X-Thanos
X-Dc
X-Reboot
X-TrackingId
X-Thinkindot-L3
X-Skip-Cache
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-NC
X-Service
X-Request-Start
X-Swa-Ws
X-Policy
X-Reqid
X-Release
X-Server-IP
Content-Disposition
X-Svr
X-VServer
Kp-EeAlive
X-We-Are-Hiring
Heartbleed
Is-Eu
Locale
Countrycode
Gh-Request-Id
Pagetype
PFcat
X-Ruxit-Js-Agent
X-NWS-UUID-VERIFY
L
Wxu-Next-Hostname
X-Core-Mission
X-CGP
X-SD-PageType
X-Distil-CS
HA-Ipaddr
X-LI-Proto
X-Eu-Site
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Key
X-Lb-Id
X-Method
Resin-Trace
X-ServiceProvider
X-Epic-Correlation-Id
X-Cache-URL
X-B3-Spanid
Magicmarker
SD-X-WS
Ha-Gx-Prefs
X-Azure-Ref-OriginShield
X-Azure-Ref
Fastly-SWR
X-Wikidot-Backend
X-Wikidot-Static-Cache
Fastly-SIE
V-Age
Wxu-Next-Region
Wxu-Next-Commit
Esi-Enabled
Akamai-GRN
X-C
X-Qloud-Router
X-Instart-Isnd
X-Nginx-Cache-Key
X-Microcachable
SRV
X-Backend-State
X-MSEdge-Flight
X-Ratelimit-Limit
X-Cache-Backend
Cache-Provider
X-Scheme
W
X-MSEdge-Features
X-App-Name
X-Internal-Host
Server-ID
X-Processor
Memory
X-FPC
X-Servername
X-Be
REQUESTUUID
Cdn-Request-Time
X-Edge-Server
X-GEO
Cdn-Host
X-VWS-Id
X-DC
X-AWS-Id
Group
X-LJ-Flow-ID
X-Pjax-Url
X-NodeID
X-GDPR
X-Ratelimit-Remaining
X-Mode
X-ABtesting
X-Hello
X-Org
Cache-Host
X-Flog
X-Datadome
X-Request-Time
X-Servedbyhost
SS
X-Wa
X-Server-W
X-Unique-ID
X-Response-By
X-Ms-Request-Id
X-Ms-Version
X-IPS-LoggedIn
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
X-Oss-Object-Type
X-Oss-Storage-Class
X-Oss-Request-Id
X-Page-Type
X-Varnish-Beresp-Status
X-Webapp-Samesite-None-Activated-N
Country-Code
X-Varnish-Beresp-Grace
X-SN
X-Varnish-Beresp-Ttl
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-Idcheck
X-Oracle-Dms-Rid
X-VCL-Version
Cache-Cookie-Set-From
X-Session-Fingerprint
Lfy
X-Via-Ucdn
X-CDN-Forward
X-EC-Lua
X-Zone
X-Cache-Debug
X-Ftr-Request-Id
X-SRV
X-Dynatrace
X-Proxied
X-Agile-Id
X-Agile
X-Agile-Age
X-COUNTRY
X-URL
X-Routing-Service
UCS
PICS-Label
X-Tb-Optimization-Total-Bytes-Saved
X-HS-Status
X-Zipkin-Id
X-GRACE
X-7Graus-Varnish-XKeys
X-7Graus-Varnish-Cache-Control
Geoip-City
SN
Powered-By-ChinaCache
Ttl
GeoIp-Country-Code
Geoip-Latitude
X-Pf-Uncompressing
X-CSRF-Token
X-Logging-Id
Proxy-Firewall
X-Logtrace-Id
X-Sedo-Request-Id
X-Fastly-Country-Code
Environment
Ajk
X-Cache-Miss-From
X-Sucuri-Id
X-Source
X-Varnish-Beresp-TTL
X-PF-Uncompressing
X-MP-GENERATED-AT
GeoIP-City
X-APP
GeoIP-Latitude
GeoIP-Country-Code
X-Sucuri-ID
X-Bc
XServer
X-ZONE
ProcessTime
X-Grey
X-Newrelic-Synthetics
Powered-By
X-Unique-Id
X-Cache-Category-Id
Cdn
X-Ftr-Cache-Host
X-CLOUD-TRACE-CONTEXT
X-RateLimit-Reset
X-Core-Value
X-Vcl-Version
X-HTML-Minification-Powered-By
X-Tt-Trace-Host
Pics-Label
M-TraceId
Amp-Access-Control-Allow-Source-Origin
X-LiteSpeed-Cache-Control
Cf-Ipcountry
X-Vdms-Version
X-Aicache-OS
X-TH-Server
CF-Cached-On
X-Edge
Fastly-Backend-Name
X-Check-Cacheable
X-AK-Request-ID
Cdncip
WWW
X-DataStream-Cache-Status
X-Sucuri-Cache
Cdnsip
X-Ftr-Balancer
X-Ftr-Backend
X-Dynatrace-Js-Agent
X-Ftr-Backend-Server
X-Ftr-Realm
X-Ftr-Dc
X-Planisys-CDN-TTL
X-Fstrz
X-ServedByHost
X-Mid
Pragrma
X-Planisys-CDN-Rules
Requestid
X-Rocket-Build-Number
X-Planisys-CDN-Cache
X-Sigma
X-Sigma-Backend
X-Shopify-Generated-Cart-Token
CACHE
MIME-Version
HostName
X-LAGOON
X-MCACHE
X-Varnish-Ttl
X-RCS-CacheZone
X-FORWARDED-FOR
X-Fastly-Backend-Reqs
X-WA
X-Via-NSCOPI
X-Swift-Error
X-Cache-Tag
GW-Server
X-ORACLE-APMCS-TAG
X-TT-LOGID
X-SaId
X-ORACLE-APMCS-REQUEST-ID
X-Secret
TTL
X-UPSTREAM-Address
X-Gannett-Site-Version
LB
X-NGINX-Cache
Lb
Tcn
X-BE
X-RSL
X-RPM
X-RPS
X-BC
X-PJAX-URL
X-DW
X-DSS
X-Action
X-DB
X-DI
X-ND-Cache
X-DataStream-Origin-MEX-Latency
URI
Ohc-Response-Time
X-Litespeed-Cache-Control
X-Varnish-Url
X-Cache-Ttl
X-DataStream-MidMile-RTT
X-Upstream-Ht
X-Upstream-Ct
Dynatrace
Host-ID
X-Cf-Powered-By
On-Server
RequestUuid
X-Varnish-Cacheable
X-CDN-Cache
X-Refresh
X-Trafficlayer-App-Version
X-Correlation-ID
DataCenter
X-Via-Edge
X-Served-From
X-Via-SSL
Get-Access-Time
X-Zalando-Child-Request-Id
Xkeyrz
X-Proxy-Cacherz
CDN
X-GeoIP-Country-Code
Server-Id
User-Agent
Xkeypdq
Is-Session-Tracking
X-Fpc
X-WR-MODIFICATION
X-Page-Impression-Id
X-Flow-Id
X-Fastly-Cache-Hits
WZWS-RAY
X-TIME
Correlation-Id
X-Req
X-SB
Warning
X-Dw-Trace-Id
Gannett-Cam-Experience-Id
Locid
X-VC
X-Pod
X-Gamma-Serve
X-MID
X-ServerName
X-Nananana
X-Edge-O15-RID
X-HostName
Inserted-Into-Cache-At
Thinkindot-Cache-Type
HitType
RequestId
X-Newrelic-App-Data
Xet-Cookie
Processtime
FNAC-ModuleRouting
X-ECache
X-MiniProfiler-Ids
X-Li-Proto
X-Amzn-Remapped-Connection
Cneonction
X-Gdpr
V-Cache
X-Gen-Id
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-Bug-Bounty
X-Amzn-Remapped-Date
X-LiteSpeed-Tag
X-LB-ID