Threat Level: green Handler on Duty: Manuel Humberto Santander Pelaez

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
CF-RAY
CF-Cache-Status
Link
X-Powered-By
X-XSS-Protection
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Alt-Svc
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
Content-Security-Policy-Report-Only
X-Generator
X-Cacheable
X-Cache-Status
X-Permitted-Cross-Domain-Policies
X-Xss-Protection
X-Request-ID
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Template
X-Language
X-Iinfo
Status
X-Content-Security-Policy
Content-Encoding
X-AspNetMvc-Version
X-Buckets
X-Kinja-Server-Push
Xkey
Upgrade
X-Via
Access-Control-Expose-Headers
X-Turbo-Charged-By
Keep-Alive
Access-Control-Max-Age
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Pass-Why
P3p
X-Age
EagleId
X-Backend
X-Envoy-Upstream-Service-Time
X-Robots-Tag
X-Amz-Id-2
X-Amz-Request-Id
X-Page-Speed
X-CDN
X-Ua-Compatible
X-Pingback
X-Server-Powered-By
X-AH-Environment
X-Proxy-Cache
X-UA-Device
X-Hacker
X-Server
Request-Context
X-Nginx-Cache-Status
Grace
X-Swift-CacheTime
X-Swift-SaveTime
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-Cdn
Cf-Railgun
X-LiteSpeed-Cache
Server-Timing
X-Amz-Version-Id
Feature-Policy
X-Server-Id
X-WebKit-CSP
X-Device
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
X-Rq
X-Ac
X-Cnection
X-Cloud-Trace-Context
Report-To
EagleEye-TraceId
X-Response-Time
X-Host
X-Backend-Server
Request-Id
X-Node
Content-Location
X-Origin-Cache
X-Readtime
X-Vhost
X-Application-Context
X-Cache-Lookup
X-Dns-Prefetch-Control
X-ORACLE-DMS-ECID
X-Dispatcher
X-ORACLE-DMS-RID
NEL
X-DataDome
X-Ruxit-JS-Agent
X-Origin-Upstream-Status
X-Rack-Cache
Surrogate-Control
X-HW
Allow
Rating
X-Country-Code
X-Clacks-Overhead
X-FTR-Request-ID
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Country
X-Url
X-DynaTrace
X-Instart-Request-ID
Fusion-Component-Id
Fusion-Template-Id
Fusion-Source
Fusion-Content-Source
Fusion-Content-Id
X-TTL
X-MS-InvokeApp
X-Goog-Hash
X-Vname
X-Varnish-TTL
X-TtlSet
X-PC
X-Powered-By-Plesk
Verso
RTSS
Pinterest-Generated-By
Public-Key-Pins
Edge-Control
X-Px
X-Mod-Pagespeed
X-CST
X-VARITI-CCR
X-Recruiting
X-Sol
X-Middleton-Response
X-Middleton-Display
Response
Display
X-B3-TraceId
X-Cdn-Fetch
X-Kinja-Server
X-Use-Magma
X-Exp-Id
X-Exp-Variant
X-Kinja-Build
X-Kinja
X-GoogleNews-Bot
X-Kinja-Revision
X-D2id
Service-Worker-Allowed
X-SharePointHealthScore
SPRequestGuid
X-Ah-Environment
X-Vcap-Request-Id
X-Version
X-Akam-SW-Version
X-ESI
Accept-CH
X-Server-Name
SPIisLatency
SPRequestDuration
MS-Author-Via
TCN
X-GitHub-Request-Id
X-Abt-Application-Version
X-Powered-CMS
X-Navigation-Version
Accept-Ch-Lifetime
X-Shard
Charset
Fastly-Restarts
X-Upstream
X-RateLimit-Remaining
X-Amz-Server-Side-Encryption
X-Trace
AR-PoweredBy
Ar-Sid
AR-CACHE
Nginx-Cache
AR-ATIME
Realpath
X-Amz-Rid
X-Debug
X-Forwarded-Proto
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Aspnetmvc-Version
X-XRDS-Location
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Ezoic-Cdn
Front-End-Https
X-Cached
X-NF-Request-ID
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Generation
AR-Request-ID
Pagespeed
X-MSEdge-Ref
Mrf-Cache-Status
MRF-Tech
X-Shield-Request-Id
X-B3-TraceId-Primal
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
Access-Control-Request-Method
Arr-Disable-Session-Affinity
X-FTR-Cache-Status
X-FTR-Expires
X-Country-Code-Real
Content-MD5
X-VCache
Paypal-Debug-Id
MicrosoftSharePointTeamServices
X-Id
X-Goog-Storage-Class
X-FTR-Realm
X-FTR-DC
X-T
X-FTR-Backend
X-FTR-Balancer
X-FTR-Backend-Server
X-Amz-Meta-S3cmd-Attrs
S
X-Fastly-Request-ID
ServerID
DynaTrace
X-Via-JSL
X-Varnish-Age
X-Client-IP
X-Content-Type
X-Ser
X-Dw-Request-Base-Id
X-Hits
X-Amzn-Trace-Id
X-Correlation-Id
X-Grace
X-Accel-Expires
Fastcgi-Cache
X-SERVER
Powered
X-Content-Digest
X-Vcache
X-Frontend
X-DynaTrace-JS-Agent
X-DIS-Request-ID
X-FTR-Cache-Host
X-N
AMP-Access-Control-Allow-Source-Origin
Arc-Version
PB-PID
PB-RID
X-Mobile-Rewrite
X-FastCGI-Cache
X-Forwarded-For
Edge-Cache-Tag
Server-Name
X-Logged-In
X-HS-Hub-Id
X-HS-Content-Id
X-RateLimit-Limit
X-Fastcgi-Cache
Accept-Ch
X-GUploader-UploadID
TP-L2-Cache
TP-Cache
X-Request-Handler-Origin-Region
X-Server-ID
X-Microsite
X-B3-Sampled
X-Request-Received
X-Request-Processing-Time
X-Zen-Fury
X-Pinterest-Rid
Pinterest-Version
X-Kinsta-Cache
X-Cache-Age
X-Az
X-Type
X-Activity-Id
X-AppVersion
Backend-Timing
X-IPLB-Instance
X-User-Agent
X-Rid
X-Analytics
X-Revision
X-LB-Cache
Healthy
FilterID
X-Whom
Retry-After
X-Node-Name
X-Time
X-Cache-Hit
X-NWS-LOG-UUID
Server-Node
X-F-Cache
X-Srv
Alternate-Protocol
Accept-Charset
X-Cache-2
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Cache-Rule
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Amzn-RequestId
X-Hp-Webp
X-Amz-Apigw-Id
Cache-Status
X-B3-Traceid
Cache-Tag
X-Akamai-Edgescape
X-Content-Options
X-Content-Security-Policy-Report-Only
X-TA-CDN-Provider
Surrogate-Key
DC
Refresh
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Content-Powered-By
X-AOL-HN
X-Forwarded-Host
X-Instance
X-Debug-Info
Access-Control-Allow-Method
X-Tumblr-User
X-Tumblr-Pixel-0
X-Webkit-CSP
X-Tumblr-Pixel
Tracecode
X-Jobs
X-Framework
X-Cluster
X-Varnish-Grace
X-PHP-Backend
MS-CV
Fastcgi-Useragent
Source
X-App-Environment
X-Request-Guid
X-Page-Id
X-FB-Debug
X-FW-Hash
X-FW-Static
X-FW-Serve
X-FW-Type
X-FW-Server
X-B
X-App-Server
Frame-Options
X-Cache-Operation
Host
Actual-Object-TTL
X-Esi
X-Hostname
X-Cache-TTL
X-Mobile-URL
X-Seen-By
X-Geo-Country
Cleartype
X-Cache-Control
X-B-Cache
X-Signature
X-Cache-Key
X-Acc-Meta-Resource-Type
X-BCube-Filmed-By
X-Host-Name
X-Cached-By
X-Git-Hash
NR-ENABLED
X-TT
X-Amz-Replication-Status
X-Pad
Upgrade-Insecure-Requests
X-Mobile
X-Varnish-Backend
NGB
X-Response-Served-From
X-Adobe-Content
X-WebKit-CSP-Report-Only
Accept-CH-Lifetime
X-Adobe-Loc
X-TT-TIMESTAMP
WPE-Backend
From-Origin
Eomportal-Instance
X-RTag
Filters
X-ProcessESI
X-Handled-By
GEO-INFO
Ms-Operation-Id
X-ATG-Version
Cache-Tv-Group
Payment
X-RemovedCookies
Liferay-Portal
Webserver
X-TX-ID
X-Tumblr-Pixel-1
X-Drupal-Cache-Tags
X-Tumblr-Pixel-2
X-RequestSource
X-Cache-Remote
X-GeoIP
X-Cacheable-TTL
X-Status
X-UA-Device-Type
X-Litespeed-Cache
X-FW-Dynamic
X-Cache-TTL-Remaining
X-Origin-Server
X-Presslabs-Stats
X-EdgeConnect-Cache-Status
X-Daa-Tunnel
X-WA-Info
X-Content-Age
X-Cache-Action
X-Wix-Request-Id
X-Edge-Location
X-Hyper-Cache
X-Storage
Viewport
X-Contextid
Xserver
Datacenter
X-Region
Version
X-Ratelimit-Reset
X-CF-Powered-By
X-Varnish-Hostname
X-HS-Cache-Config
X-Accel-Buffering
X-Element-Page-Cache
Ohc-File-Size
Cache
PageSpeed
Host-Header
X-Akamai-Transformed
X-Cache-NE
X-PressLabs-Stats
X-RN-RSRV
X-ES-SERVER
Load-Balancing
X-Path-Route
X-Varnish-Server
Meta-Geo
X-Cache-Var
X-Cache-Var-Map
X-Yottaa-Metrics
X-Yottaa-Optimizations
S-Cnection
X-IP
X-Cache-Server
Cache-Name
Cache-Tags
X-TNCMS
X-Time-Microsecs
X-Section
X-Tumblr-Pixel-3
X-Proto
X-Akamai-Request-ID2
X-Akamai-Request-ID
X-Access
X-Cache-Enabled
X-Loop
X-CS
X-NCache
Vix-Hermes-Req-Id
X-PERF
Decoy-Debug-Status
Decoy-Debug-Key
Decoy-Debug-TTL
Ec-Rule-Version
Rt-Fastcgi-Cache
X-R9-Blue-Green-Version
X-Cluster-Node
Cache-Hits
X-Cache-Config
X-Proxy
X-Via-Fastly
X-Origin-Response-Time
X-ApacheServer
X-Viewer-Country
X-OCL
Cache-Key
X-Proxy-Build
X-Cache-Time
Azure-RegionName
Azure-InstanceId
DB-Nickname
X-Backend-TTL
X-Drupal-Cache-Contexts
X-Origin
S-Rt
Selected-Fe
X-PCL
X-Cache-Grace
X-Rule
X-From
Azure-Version
Azure-SlotName
Azure-SiteName
X-Human
X-CCM
X-FC-Vary-Parameters
X-Format
Webcakes-Region
Country
Mn-Server-Ip
Property-Id
X-NewRelic-App-Data
X-Origin-Hint
X-Www-Served-By
X-Varnish-Cache-Hits
TWC-Connection-Speed
TWC-Device-Class
Webcakes-App-Name
Webcakes-App-Version
X-Labrador-Cache-Channel
TWC-Privacy
TWC-Locale-Group
TWC-GeoIP-Country
TWC-GeoIP-LatLong
X-Web-Node
X-Xfnlog-Site
X-Upstream-HT
X-Upgrade-Enabled
X-Timing-Wait
X-Trace-Id
X-Upstream-CT
X-EIG-Tracking-Id
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Debug-Cache
X-Locale
X-Backend-Name
X-JoinUs
X-Hosted-By
X-Site-Version
X-Hit
X-Upstream-Proxy
X-Cache-Host
X-Generated
X-UnsetCookies
Ohc-Cache-HIT
Server-Info
X-Device-Type
X-Ua
Release
X-FireWall-Port
Time
X-Ttl
X-VCT
X-Vgn-Hpd-Reason
DSUID
X-Rendered-As
X-S
X-Varnish-Hits
X-FW-Version
Now
X-OVcl-Cache
X-OVcl
Hostname
X-Real-IP
X-Pubstack
X-NGENIX-Cache
X-SS-Set-Cookie
X-HS-Combine-CSS
OT-Force-Account-Verify
X-Redis-Cache
ServedBy
Origin-Cache-Control
Origin-Edge-Control
Fastcgi-X-Cache-Version
Access-Control-Request-Headers
X-VG-TLSProxy
L5d-Success-Class
X-APP-VERSION
Cteonnt-Length
Origin
X-DataStream-Cache-Status
Accept-Language
X-VG-WebCache
X-ShardId
X-ShopId
Fastly-SSL
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Shopify-Stage
X-FB-TRIP-ID
X-Alternate-Cache-Key
NtCoent-Length
X-XRDS-LOCATION
X-Tb
X-CSRF-TOKEN
Machine
X-Parent-Response-Time
X-Cluster-Name
X-Origin-CC
X-Origin-TTL
X-App-Version
SRV
X-UUID
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
X-Tt-Trace-Tag
X-NC
X-Load-Cache
X-GoCache-CacheStatus
X-CACHE-KEY
X-No-Session
X-Rocket-Nginx-Bypass
X-B3-Spanid
X-L-Path
X-Environment-Context
X-ServerID
IBM-Web2-Location
X-ECACHE
X-GEO
X-Soup
NGX
X-Nginx-Cache
X-B3-Parentspanid
X-Is-Bot
X-Uri
Nel
X-Endurance-Cache-Level
CF-IPCountry
X-Amzn-Remapped-Content-Length
X-Magnolia-Registration
Proxy-Connection
Mime-Version
Akamai-GRN
ServerName
Fly-Request-Id
Fly-Cache
Cross-Origin-Window-Policy
GEO-REGION-INFO
Memcached
Odigeo-Trace-Id
Rendered-Blocks
Node
Mobile-Detection-Method
Meta-Geo-Continent
MD5-Digest
Content-Style-Type
AsisCache
BehaviorPad-Version
Arc-Country
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Cache-Prefix
Content-Script-Type
A
Apple-News-Services-Handled
Apple-News-Services-Host
Rt-Proxy-Cache
X-Node-Id
X-Application
X-Request-UUID
X-Rewrite-Enabled
X-Rojux
X-S-Cookie
X-Region-Sid
X-PAYTM-SRV-ID
X-DPWN-IS-SECURE
X-External-Request-Id
X-Instart-Info
X-ScT
X-Server-Time
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
X-Worker
Xc-Version
X-VG-WebServer
X-Twitter-Response-Tags
X-SRCache-Key
X-Transaction
X-Trv-Group
X-Developer
X-Detected-As
X-A-Dcw
X-A-Dgt
X-A-Wwc
X-Accel-Expires-Debug
X-A-Dam
X-A-Ccd
Viewtype
VivaBuild
X-A
X-Aed
X-AIR-PT
X-Connection-Hash
X-D
X-Date
X-Destination
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-MServer
X-ARC
X-B-Cookie
T-Server
X-G
Request-Time
X-Generated-By
X-Mode
Backend-Name
X-Oneagent-Js-Injection
X-Origin-Expires
N-Cache
Fastly-Soc-X-Request-Id
X-Developers
X-Azure-Ref
X-Azure-Ref-OriginShield
X-Origin-Date
X-Cache-Bucket
X-Fastly-Cache
X-Cms-Context
X-B3-SpanId
X-Cdn-Srv
IsBot
X-Release
Locale
X-Hl-Ver
X-VC-Cache
Mail-Subject
X-SVT-ORM-VERSION
X-SIPLIST1
Request-EU
Section-Io-Cache
X-Up
X-Urbn-Site-Id
X-Urbn-Context-Path
Request-Country
X-SVT-ORM-RULES
X-S-Maxage
We-Hiring
X-AWS-Id
X-VWS-Id
User-Cache-Control
X-LJ-Flow-ID
X-Clara-WADP
Thinkindot-CacheControl
X-Clientip
X-Auto-Login
X-Core-Mission
X-Compress-Hint
X-App-Name
Thinkindot-CacheControl-Type
True-Client-Country-4JS
X-Bip
Uber-Trace-Id
X-Backend-Host
X-Backend-Url
X-C
X-CUA
X-BBXSRF
Thinkindot-Control
W
X-Cache-Info
X-Cdn-Origin
X-Generated-On
X-Reboot
X-We-Are-Hiring
X-WADP-Cache
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Qloud-Router
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Server-IP
X-Service
X-Thinkindot-L3
X-TrackingId
X-VServer
X-Thanos
X-Swa-Ws
X-ServiceProvider
X-Skip-Cache
X-Sn-Servicetimems
X-Policy
X-Wikidot-Backend
X-Gen-Mode
Server-Int
X-Generation-Time
X-ElasticPress-Search
X-Edge-Server
X-Distil-CS
X-Distributor
X-Dc
X-Geo-Header
X-Hnp-Log
X-Method
X-Nginx-Cache-Key
X-Wikidot-Static-Cache
X-Matched-Rule
X-Location
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Level-Front-Cache
X-Device-Os
X-Block-Status
L
Pramga
Fastly-SWR
Content-Disposition
AKAMAI
CDCHOST
Cdn-Host
X-Var-Ttl
Cdn-Request-Time
Magicmarker
Countrycode
Heartbleed
RNT-Machine
RNT-Time
Fastly-SIE
X-Trafficlayer-App-Name
Gh-Request-Id
Esi-Enabled
X-Trafficlayer-App-Scope
X-Microcachable
X-Request-Time
HA-Ipaddr
X-Proxy-Upstream
Cache-Provider
X-Internal-Host
X-GeoIP-City
Kp-EeAlive
X-Fetched-On
X-Proxy-Cache-Status
X-NX-Host
X-Epic-Correlation-Id
Served-By
Pagetype
Ha-Gx-Prefs
X-GDPR
X-ProxyCache-Status
X-WebServer
X-Request-Start
X-JWT-State
X-Is-Gdpr
X-Has-Esi
X-Request-URI
X-Say-Cacheable
X-Via-CDN
X-Variation
X-Servername
X-SayCDN-TTL
X-Say-TTL
X-Platform-Server
Adler-Geo
X-Reqid
X-User
X-LI-UUID
X-LI-Proto
X-Li-Pop
X-MSEdge-Features
X-MSEdge-Flight
X-PHP-Host
X-Owner
X-Webstats-RespID
X-Old-Content-Length
X-Li-Fabric
X-ProxyCache-Key
X-Hash
Web-Mar-Node
X-Debug-Cache-Fetch
X-Eu-Site
X-Debug-Cache-Store
X-Amz-Meta-Cache-Control
Memory
X-Debug-Cookies
X-Guploader-Uploadid
X-Backend-State
Platform
X-BYPASS-REASON
Wxu-Next-Region
Server-Host
X-CGP
X-Debug-Cache-Expiry
X-Generated-In
PFcat
X-Debug-Log
V-Age
X-Dispatch
Wxu-Next-Hostname
Is-Eu
X-Irp-Debug
X-UA
Srv
X-Cache-FS-Status
X-Cache-Id
Wxu-Next-Commit
X-Org
X-Dispatcher-Server
X-Key
SD-X-WS
Resin-Trace
X-SD-PageType
Server-ID
X-Info
X-Cdn-Forward
X-NWS-UUID-VERIFY
X-COUNTRY
X-Wa
X-Lb-Id
X-ABtesting
X-FPC
X-Flog
X-Hello
X-Dynatrace-Js-Agent
X-Geo
X-Servedbyhost
SS
X-DC
X-Nc
REQUESTUUID
X-URL
X-DataStream-MidMile-RTT
X-Be
X-DataStream-Origin-MEX-Latency
X-Unique-ID
X-Svr
X-Cache-URL
X-Response-By
X-Routing-Service
X-Proxied
X-IPS-LoggedIn
X-Zipkin-Id
X-Ratelimit-Limit
X-RateLimit-Reset
Cache-Cookie-Set-Lfrom
X-Instart-Isnd
Cache-Cookie-Set-Idcheck
Country-Code
Cache-Cookie-Set-From
X-SRV
X-VCL-Version
X-Scheme
X-CDN-Forward
XServer
X-Cache-Backend
X-Page-Type
X-Processor
X-Datadome
X-NodeID
UCS
X-MP-GENERATED-AT
CACHE
X-Pjax-Url
X-Varnish-Beresp-Ttl
Group
X-SN
X-Oss-Storage-Class
X-ZONE
Ajk
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Logtrace-Id
X-Oss-Request-Id
Powered-By-ChinaCache
X-Oss-Server-Time
X-Ruxit-Js-Agent
Cache-Host
X-Server-W
X-Oracle-Dms-Rid
Dynatrace
X-HTML-Minification-Powered-By
ProcessTime
Proxy-Firewall
PICS-Label
X-Webkit-Csp
X-Varnish-Beresp-Status
X-Ftr-Request-Id
X-Tb-Optimization-Total-Bytes-Saved
X-Varnish-Beresp-Grace
X-HS-Status
Powered-By
X-Newrelic-Synthetics
X-Dynatrace
X-Ms-Version
X-Grey
X-Ms-Request-Id
SN
Ttl
X-Via-Ucdn
X-Cache-Category-Id
X-GRACE
X-Source
X-EC-Lua
X-Zone
X-Pf-Uncompressing
X-Ratelimit-Remaining
X-FORWARDED-FOR
GeoIP-Latitude
X-APP
X-TH-Server
GeoIP-City
X-PF-Uncompressing
Fastly-Backend-Name
X-Session-Fingerprint
GeoIP-Country-Code
Geoip-City
Lfy
GeoIp-Country-Code
Geoip-Latitude
X-Sucuri-Id
X-LiteSpeed-Cache-Control
X-Varnish-Beresp-TTL
X-Agile
X-Agile-Id
X-Agile-Age
MIME-Version
X-Cache-Debug
X-Check-Cacheable
X-NODE
GW-Server
X-Ftr-Cache-Host
X-Fastly-Country-Code
X-BC
LB
Cdn
X-7Graus-Varnish-Cache-Control
X-Logging-Id
Pics-Label
X-7Graus-Varnish-XKeys
Environment
X-LAGOON
X-Tt-Trace-Host
X-RCS-CacheZone
X-Bc
X-Edge
X-Secret
X-Varnish-Url
X-Aicache-OS
X-Gannett-Site-Version
X-Sedo-Request-Id
CF-Cached-On
X-Cache-Miss-From
WZWS-RAY
M-TraceId
X-PJAX-URL
WWW
X-Unique-Id
X-CSRF-Token
X-Ftr-Backend
X-Ftr-Balancer
X-Ftr-Realm
X-Ftr-Backend-Server
X-Ftr-Dc
X-Mid
X-CDN-Cache
X-Varnish-Cacheable
X-Core-Value
Ohc-Response-Time
On-Server
Requestid
X-Akamai-SSL-Client-Sid
X-Sucuri-ID
Cf-Ipcountry
Cdnsip
Cdncip
User-Agent
X-MCACHE
X-Cache-Tag
X-Cache-Ttl
X-GeoIP-Country-Code
X-AK-Request-ID
X-UPSTREAM-Address
DataCenter
X-Vcl-Version
X-Fastly-Backend-Reqs
X-Varnish-Ttl
Amp-Access-Control-Allow-Source-Origin
X-Vdms-Version
X-TT-LOGID
CDN
Inserted-Into-Cache-At
X-Sucuri-Cache
X-Litespeed-Cache-Control
X-Swift-Error
X-NGINX-Cache
Lb
X-BE
X-NU-AKA-ACS-Version
X-DI
X-DB
X-DSS
X-Action
X-DW
X-RPS
X-Sigma-Backend
X-Sigma
Xkeyrz
X-Proxy-Cacherz
URI
X-Fstrz
X-Rocket-Build-Number
SID
X-RPM
X-RSL
HostName
X-Render-Time
Who
X-Shopify-Generated-Cart-Token
X-Crawler
RequestUuid
X-Planisys-CDN-TTL
Host-ID
Pragrma
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Correlation-ID
Get-Access-Time
Server-Id
Is-Session-Tracking
X-Refresh
X-Via-NSCOPI
X-Fastly-Cache-Hits
Xkeypdq
X-Fpc
X-Flow-Id
X-WA
X-WR-MODIFICATION
X-LB-ID
Warning
X-Page-Impression-Id
X-ServedByHost
X-Zalando-Child-Request-Id
X-FE
X-MID
X-Cdn-Request-ID
X-SB
X-Micro-Cache
FNAC-ModuleRouting
X-Nananana
Correlation-Id
X-TIME
X-VC
X-Cf-Powered-By
X-Gdpr
X-LiteSpeed-Tag
X-Via-SSL
X-Akamai-ERRuleID
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
X-Akamai-ERPolicy
X-Trafficlayer-App-Version
X-Via-Edge
TTL
X-Served-From
X-Request-URL
Xet-Cookie
HitType
X-Bug-Bounty
X-MiniProfiler-Ids
X-Newrelic-App-Data
X-ServerName
X-ECache
Processtime
X-Dw-Trace-Id
X-Fe
RequestId
V-Cache
Cneonction
X-Gen-Id