Threat Level: green Handler on Duty: Rob VandenBrink

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-Powered-By
Pragma
CF-Cache-Status
Link
ETag
Expect-CT
Via
Age
X-Cache
X-XSS-Protection
CF-RAY
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-Xss-Protection
P3P
X-Cache-Hits
X-Amz-Cf-Pop
CF-Ray
Referrer-Policy
X-Amz-Cf-Id
X-UA-Compatible
X-Served-By
Alt-Svc
X-Request-Id
X-Varnish
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-FRAME-OPTIONS
X-Drupal-Cache
X-Check
X-Adblock-Key
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-Cacheable
X-Permitted-Cross-Domain-Policies
X-Cache-Status
X-Generator
Timing-Allow-Origin
X-Iinfo
X-Template
X-AspNetMvc-Version
X-Language
X-Ua-Compatible
Status
Upgrade
X-CDN
X-Content-Security-Policy
X-Buckets
Content-Encoding
Access-Control-Expose-Headers
P3p
Access-Control-Max-Age
X-Kinja-Server-Push
X-Via
Keep-Alive
X-Turbo-Charged-By
X-AH-Environment
X-Drupal-Dynamic-Cache
X-Envoy-Upstream-Service-Time
X-Pass-Why
X-Cache-Group
X-Server
X-Ws-Request-Id
X-Backend
X-Age
EagleId
X-Proxy-Cache
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
Xkey
X-Page-Speed
X-Request-ID
X-Hacker
X-Pingback
X-Server-Powered-By
Server-Timing
Feature-Policy
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
Request-Context
X-Nginx-Cache-Status
Grace
X-Varnish-Cache
X-UA-Device
X-Amz-Version-Id
Cf-Railgun
Report-To
X-OneAgent-JS-Injection
X-LiteSpeed-Cache
X-Rq
X-Device
X-Origin-Cache
X-Server-Id
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
EagleEye-TraceId
X-Backend-Server
X-Host
X-Node
X-Vhost
X-Response-Time
X-WebKit-CSP
NEL
X-Dispatcher
X-Ac
X-Cache-Lookup
X-Readtime
Surrogate-Control
X-Origin-Upstream-Status
Content-Location
Request-Id
X-Ruxit-JS-Agent
X-Application-Context
Fusion-Component-Id
Fusion-Template-Id
Fusion-Content-Id
Fusion-Source
Fusion-Content-Source
X-HW
X-ORACLE-DMS-ECID
X-Cnection
X-ORACLE-DMS-RID
X-Country
X-Mod-Pagespeed
X-DataDome
X-Cloud-Trace-Context
X-Akam-SW-Version
Edge-Control
X-Rack-Cache
Rating
X-Url
X-Clacks-Overhead
RTSS
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Vname
X-Goog-Hash
X-PC
X-TtlSet
X-FTR-Request-ID
X-Varnish-TTL
X-DynaTrace
X-Country-Code
X-ASPNET-VERSION
X-Instart-Request-ID
Allow
Content-MD5
Service-Worker-Allowed
Verso
X-GitHub-Request-Id
X-ESI
X-Server-Name
Pinterest-Generated-By
X-D2id
X-GoogleNews-Bot
X-Exp-Id
X-Cdn-Fetch
X-Exp-Variant
X-Kinja
X-Kinja-Build
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-MS-InvokeApp
SPRequestGuid
X-Cached
X-Navigation-Version
X-Powered-By-Plesk
X-Forwarded-Proto
X-Amz-Server-Side-Encryption
X-Debug
X-Vcache
X-Amz-Rid
X-Abt-Application-Version
X-Webkit-Csp
Public-Key-Pins
X-Fastly-Request-ID
X-Trace
X-MSEdge-Ref
X-B3-TraceId
X-SharePointHealthScore
Nginx-Cache
Accept-Ch
X-Vcap-Request-Id
X-Server-ID
X-VARITI-CCR
TCN
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
Fusion-Deployment-Id
MS-Author-Via
Charset
Arr-Disable-Session-Affinity
X-Px
X-NF-Request-ID
X-Accel-Expires
X-Cache-TTL
Edge-Cache-Tag
SPIisLatency
SPRequestDuration
X-Ttl
Realpath
Response
Pagespeed
Display
X-Middleton-Display
X-Middleton-Response
Accept-Ch-Lifetime
X-Content-Type
X-Ser
X-Sol
X-Fastcgi-Cache
X-Client-IP
Accept-CH
X-Version
Cache-Tag
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-DynaTrace-JS-Agent
X-Powered-CMS
Front-End-Https
Pinterest-Version
X-Pinterest-Rid
NR-ENABLED
X-Dns-Prefetch-Control
X-Id
Access-Control-Request-Method
AR-Request-ID
AR-PoweredBy
AR-ATIME
X-Grace
X-Jurisdiction
X-Hp-Webp
X-Upstream
X-Forwarded-For
Mrf-Cache-Status
X-Mrf-Item-Lastmod
S
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
MRF-Tech
Accept-CH-Lifetime
X-T
X-Hits
X-Content-Digest
X-Amz-Meta-S3cmd-Attrs
X-Element-Page-Cache
DynaTrace
Ar-Sid
AR-CACHE
X-Dw-Request-Base-Id
Fastcgi-Cache
ServerID
X-TTL
X-Mobile-URL
X-Node-Name
X-Cache-Hit
X-Shield-Request-Id
PB-RID
PB-PID
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Balancer
X-FTR-Cache-Status
X-Country-Code-Real
X-FTR-Realm
X-FTR-DC
X-Recruiting
X-GUploader-UploadID
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Stored-Content-Length
Server-Node
X-Mobile-Rewrite
X-Amzn-Trace-Id
Arc-Version
Powered
X-HS-Cache-Config
X-Frontend
X-HS-Hub-Id
X-HS-Content-Id
TP-Cache
TP-L2-Cache
X-FTR-Expires
AMP-Access-Control-Allow-Source-Origin
X-DIS-Request-ID
X-Shard
Upgrade-Insecure-Requests
X-Ezoic-Cdn
WPE-Backend
X-Request-Processing-Time
X-Request-Received
X-NWS-LOG-UUID
Refresh
Fastly-Restarts
Alternate-Protocol
X-HS-Combine-CSS
X-Logged-In
X-Varnish-Age
X-Correlation-Id
X-Request-Handler-Origin-Region
X-Microsite
Server-Name
X-XRDS-LOCATION
X-FTR-Cache-Host
X-XRDS-Location
X-F-Cache
X-Page-Id
X-LB-Cache
X-Akamai-Edgescape
X-B
Backend-Timing
X-User-Agent
X-Rid
X-ATS-Timestamp
MicrosoftSharePointTeamServices
X-Geo-Country
X-Content-Security-Policy-Report-Only
X-N
X-Via-JSL
Host-Header
Host
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Zen-Fury
Cache-Status
X-Origin-Server
X-ORACLE-APMCS-REQUEST-ID
X-ORACLE-APMCS-TAG
X-Content-Options
X-Varnish-Grace
X-Kinsta-Cache
X-Revision
X-B3-Sampled
X-AOL-HN
X-ATG-Version
X-TT
X-Tumblr-Pixel-0
X-Tumblr-Pixel
Healthy
Paypal-Debug-Id
X-Type
Actual-Object-TTL
X-Tumblr-User
X-B-Cache
X-Instance
X-Cache-Action
X-FB-Debug
X-Jobs
X-Request-Guid
X-App-Environment
X-Amz-Replication-Status
X-Signature
X-Amz-Apigw-Id
Access-Control-Allow-Method
Section-Io-Cache
X-Varnish-Backend
X-Git-Hash
X-Whom
X-WebKit-CSP-Report-Only
Fastcgi-Useragent
X-Debug-Info
Frame-Options
Liferay-Portal
X-Content-Powered-By
X-Hostname
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Cluster
X-Srv
X-Seen-By
X-Cache-Rule
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Cache-Operation
X-Activity-Id
X-AppVersion
X-Az
X-FastCGI-Cache
X-Cache-Age
X-Daa-Tunnel
X-PHP-Backend
X-Amzn-Requestid
X-Framework
X-Cached-By
X-FireWall-Port
X-Endurance-Cache-Level
Tracecode
X-Cache-Key
X-Contextid
X-WA-Info
X-Mobile
Retry-After
X-Presslabs-Stats
X-Host-Name
Source
X-IPLB-Instance
X-Response-Served-From
X-Accel-Buffering
NGB
X-ProcessESI
X-RemovedCookies
X-Upgrade-Enabled
Accept-Charset
Srv
Surrogate-Key
Xserver
Eomportal-Instance
Trailer
X-FW-Type
X-FW-Serve
X-FW-Server
X-FW-Static
X-Is-Bot
X-GeoIP
X-Region
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
X-Adobe-Content
X-Adobe-Loc
X-UUID
X-RequestSource
X-Rendered-As
Filters
DC
X-Environment-Context
X-Cache-NE
Payment
X-FW-Hash
X-L-Path
X-Origin-Response-Time
X-Handled-By
X-Varnish-Server
X-Cacheable-TTL
X-Varnish-Hostname
X-RateLimit-Remaining
From-Origin
X-UA-Device-Type
X-CST
X-Cache-TTL-Remaining
X-Proxy
X-EdgeConnect-Cache-Status
X-Time-Microsecs
X-Cache-2
Server-Info
X-Wix-Request-Id
X-Backend-Name
X-Cache-Server
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-APP-VERSION
Cache-Tv-Group
MS-CV
X-Oss-Storage-Class
X-NGENIX-Cache
X-Oss-Request-Id
X-Oss-Object-Type
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-TIME
X-Akamai-Transformed
Datacenter
Version
X-Cache-Enabled
X-Status
Filterid
X-B3-Traceid
S-Cnection
X-Dc
X-Unique-Id
X-Mode
X-Cache-Time
X-Yottaa-Metrics
GEO-INFO
X-Yottaa-Optimizations
X-Cache-Var
Meta-Geo
X-Cache-Var-Map
X-CCM
X-ES-SERVER
X-Cache-Control
X-Path-Route
X-IPS-LoggedIn
X-RN-RSRV
Decoy-Debug-Status
X-PERF
X-Cache-Status-Check
Decoy-Debug-TTL
X-Pad
X-ApacheServer
ServedBy
X-Forwarded-Host
Cleartype
Cache-Tags
X-Via-Fastly
X-R9-Blue-Green-Version
Country
X-Hl-Ver
X-Ua-Device
Decoy-Debug-Key
TWC-GeoIP-Country
TWC-GeoIP-LatLong
Webcakes-Region
X-Pubstack
X-Akamai-Request-ID2
Webcakes-App-Version
Webcakes-App-Name
TWC-Privacy
TWC-Locale-Group
Origin-Edge-Control
X-Proto
X-Origin
Webserver
DB-Nickname
Akamai-GRN
X-TX-ID
NGX
Property-Id
TWC-Connection-Speed
OT-Force-Account-Verify
Origin-Cache-Control
Now
TWC-Device-Class
X-Redis-Cache
X-ShardId
X-ServerID
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Debug-Cache
X-Origin-Hint
X-ShopId
X-EIG-Tracking-Id
X-Device-Type
X-Shopify-Generated-Cart-Token
X-FC-Vary-Parameters
X-VWS-Id
X-AWS-Id
X-Tb
X-Alternate-Cache-Key
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Sorting-Hat-ShopId
X-LJ-Flow-ID
X-FW-Dynamic
X-Vgn-Hpd-Reason
Ec-Rule-Version
Content-Disposition
X-Format
X-Generated
Cross-Origin-Window-Policy
X-Detected-As
X-JoinUs
X-Human
X-Cache-Config
X-Locale
X-Access
X-Amzn-Remapped-Content-Length
X-IP
X-Content-Age
X-NCache
Mn-Server-Ip
Selected-Fe
X-Hosted-By
X-Loop
X-ProxyCache-Key
Azure-InstanceId
Section-Io-Origin-Status
Section-Io-Id
X-Proxy-Build
X-Routing-Service
Section-Io-Origin-Time-Seconds
X-Say-TTL
Section-Origin-Responded
X-SaId
X-Proxy-Cache-Status
X-RCS-CacheZone
X-Site-Version
X-Zipkin-Id
Cache-Key
X-Xfnlog-Site
Azure-Version
X-ProxyCache-Status
X-Say-Cacheable
X-TNCMS
X-Varnish-Hits
Azure-RegionName
Azure-SiteName
X-Timing-Wait
Azure-SlotName
X-Www-Served-By
X-Web-Node
X-Section
X-Soup
X-SayCDN-TTL
X-BYPASS-REASON
X-Proxied
X-Akamai-Request-ID
X-MP-GENERATED-AT
X-FB-TRIP-ID
S-Rt
X-Viewer-Country
Access-Control-Request-Headers
X-NYM-Debug-Backend
X-CACHE-KEY
X-Real-IP
X-Cache-Remote
X-Generated-By
X-Cdn
X-Request-Time
X-BCube-Filmed-By
Cache-Hits
X-HTML-Minification-Powered-By
X-NewRelic-App-Data
X-Edge-O15-RID
X-Adobe-Source
Node
FilterID
X-EC-Lua
Nel
X-SS-Set-Cookie
X-Geo
X-PressLabs-Stats
X-Microcachable
Odigeo-Trace-Id
X-No-Session
X-Rule
X-Drupal-Cache-Tags
Accept-Language
X-Amzn-RequestId
X-Uri
X-App-Server
Cf-Ipcountry
X-PCL
X-OCL
X-Azure-Ref
X-From
X-Qloud-Router
X-RTag
Ms-Operation-Id
X-Esi
Time
X-Cache-NGX
X-NWS-UUID-VERIFY
X-CF-Powered-By
X-Source
X-RateLimit-Limit
X-Varnish-Cache-Hits
User-Agent
X-Hyper-Cache
X-UA
X-Labrador-Cache-Channel
X-Backend-TTL
X-PHP-Host
X-Info
Proxy-Connection
X-Storage
X-Old-Content-Length
X-GoCache-CacheStatus
X-Newrelic-Synthetics
X-Cache-Grace
X-Nc
Cache-Name
X-DPWN-IS-SECURE
X-External-Request-Id
X-Developer
X-S-Cookie
X-Date
X-CF-Lambda-Fn
X-Cdn-Srv
X-CF-Lambda-Version
X-Connection-Hash
X-Session-Fingerprint
X-D
X-Destination
X-OVcl
X-Vdms-Version
X-VG-WebServer
X-Drupal-Cache-Contexts
X-Request-URI
X-Rojux
X-Rewrite-Enabled
X-Request-UUID
X-Vtex-Processado-Em
X-Region-Sid
X-VG-WebCache
X-GeoIP-Country-Code
X-OVcl-Cache
X-PAYTM-SRV-ID
X-Processor
X-ScT
X-G
X-Application
MD5-Digest
Machine
GEO-REGION-INFO
Fastcgi-X-Cache-Version
Meta-Geo-Continent
Mobile-Detection-Method
Request-Country
Rendered-Blocks
X-Twitter-Response-Tags
Content-Style-Type
Content-Script-Type
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Handled
Apple-News-Services-Request-Url
Arc-Country
BehaviorPad-Version
X-Vtex-Remote-Cache
AsisCache
Request-EU
X-Trv-Group
X-Accel-Expires-Debug
X-A-Wwc
X-A-Dgt
X-Aed
A
Uber-Trace-Id
X-B-Cookie
X-ARC
X-A-Dcw
X-A-Dam
True-Client-Country-4JS
T-Server
ServerName
Viewtype
VivaBuild
X-A-Ccd
X-A
X-Transaction
X-SRCache-Key
X-Varnish-Beresp-Status
X-S
X-Nginx-Cache
X-Cluster-Node
X-Time
X-Varnish-Beresp-Grace
Xc-Version
X-CS
X-Cluster-Name
PFcat
X-VCache
X-Trafficlayer-App-Scope
X-Trafficlayer-App-Version
X-Thinkindot-L3
X-Magnolia-Registration
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
Thinkindot-Control
X-Sn-Servicetimems
Viewport
Server-Host
X-Core-Value
X-Served-From
X-Matched-Rule
X-Reboot
Powered-By-ChinaCache
X-Load-Cache
X-Rocket-Nginx-Bypass
X-Level-Front-Cache
X-IN-APIGATEWAYSSL
X-Generated-On
X-Cdn-Origin
X-Geo-Header
X-GeoIP-City
X-IN-APIGATEWAY
X-ServiceProvider
X-Cache-Expired-At
X-Trafficlayer-App-Name
X-VG-TLSProxy
X-UnsetCookies
X-Edge-Location
User-Cache-Control
X-S-Maxage
Rt-Fastcgi-Cache
X-Cache-URL
X-CGP
X-Cache-Info
X-Slack-Backend
X-Cache-Bucket
X-Clara-WADP
X-Cache-ASPX
X-Cache-FS-Status
X-Contensis-Viewer-Groups
X-Debug-Cache-Store
X-Debug-Cookies
X-Debug-Log
X-Developers
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-C
X-Core-Mission
X-CUA
X-Cms-Context
AKAMAI
X-WADP-Cache
X-TrackingId
X-Trace-Id
X-App-Name
X-Agile-Id
X-Agile-Age
X-Webstats-RespID
X-WebServer
X-Agile
X-Auto-Login
X-Backend-Host
X-Request-Host
X-Device-Os
X-Bip
X-Swa-Ws
X-Thanos
X-Backend-State
X-BBXSRF
X-VC-Cache
X-Block-Status
X-Dispatcher-Server
X-Logging-Id
X-Req
X-Micro-Cache
X-Ms-Request-Id
X-LI-UUID
X-LI-Proto
X-LAGOON
X-Li-Fabric
X-Li-Pop
X-Ms-Version
X-Nginx-Cache-Key
X-Owner
X-Proxy-Upstream
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Varnish-Beresp-Ttl
X-Origin-Expires
X-NodeID
X-NX-Host
X-Origin-Date
X-Server-W
X-JWT-State
X-Eu-Site
X-Fastly-Cache
X-Fetched-On
X-FW-Version
X-Sigma
X-Sigma-Backend
X-Dispatch
X-Distil-CS
X-Distributor
X-Gamma-Serve
X-Gen-Mode
X-Instart-Isnd
X-Irp-Debug
X-Is-Gdpr
X-Hnp-Log
X-Hash
X-Generated-In
X-Generation-Time
X-Has-Esi
X-SIPLIST1
X-Bc-Bl
Mail-Subject
Memcached
X-Rocket-Build-Number
Locid
Locale
Kp-EeAlive
L5d-Success-Class
N-Cache
On-Server
RNT-Time
Server-Cache-Control
RNT-Machine
X-TT-TIMESTAMP
X-Tumblr-Pixel-3
Pramga
IsBot
X-Urbn-Context-Path
CDCHOST
Country-Code
X-Var-Ttl
Cache-Host
Cache-Cookie-Set-Idcheck
X-Wikidot-Static-Cache
Cache-Cookie-Set-From
FNAC-ModuleRouting
Cache-Cookie-Set-Lfrom
Heartbleed
X-Urbn-Site-Id
HA-Ipaddr
Ha-Gx-Prefs
Gh-Request-Id
Group
X-Varnish-Authentication
X-VServer
V-Age
Server-Surrogate-Control
Wxu-Next-Region
Wxu-Next-Commit
Wxu-Next-Hostname
X-Varnish-Cacheable
Server-ID
X-Wikidot-Backend
Web-Mar-Node
W
We-Hiring
X-NC
X-VCT
Fastly-SIE
X-Lb-Id
X-Servername
X-Hit
X-Platform-Server
Fastly-SWR
X-Service
X-Variation
Geo-Info
X-ND-Cache
Mime-Version
Is-Eu
X-DevSite-Last-Modified
Countrycode
X-Fmm-Version
Platform
Fastly-Drupal-HTML
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
Cloudfront-Viewer-Country
X-We-Are-Hiring
X-Epic-Correlation-Id
X-Cache-Tags
Adler-Geo
X-Clientip
X-Skip-Cache
X-Sucuri-ID
X-Node-Id
X-VHOST
X-Response-By
X-Scheme
HitType
X-URL
X-Refresh
X-RESPONSE-TIME
X-TA-CDN-Provider
Environment
X-BACKEND-TTL
X-CLOUD-TRACE-CONTEXT
Cache
SD-X-WS
X-SN
X-B3-Spanid
X-Instart-Info
X-Edge
X-MCACHE
X-Varnish-URL
X-APP
Hostname
Proxy-Firewall
X-CDN-Forward
X-Parent-Response-Time
X-Varnish-Ttl
X-Cdn-Forward
X-Pjax-Url
Origin
Vix-Hermes-Req-Id
X-Ratelimit-Remaining
X-Origin-CC
X-Origin-TTL
X-CSRF-TOKEN
X-Cache-PHP
X-Correlation-ID
Request-Time
Fastly-Backend-Name
X-MSEdge-Flight
X-MSEdge-Features
M-TraceId
X-App-Version
X-Up
X-CSRF-Token
X-Server-Time
X-Wa
X-Vdms-Path
X-FPC
NM-Fastcgi-Cache
PICS-Label
Geoip-City
Geoip-Latitude
X-ECACHE
CF-Cached-On
X-Mid
X-Be
Cdn-Request-Time
Pragrma
X-Edge-Server
GeoIp-Country-Code
Cdn-Host
X-TT-LOGID
Server-Hostname
X-Wix-Viewer-Type
TTL
Server-Ext
X-HS-Status
Sever-Int
Pagetype
CACHE
X-Vcl-Version
X-Ua
X-ECache
NtCoent-Length
X-AK-Request-ID
Cdncip
Cdnsip
HostName
X-Method
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
Ohc-File-Size
X-Myra-Origin2
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
Cdn
X-Newrelic-App-Data
Cteonnt-Length
X-Cache-Host
X-BC
X-Air-Hostname
X-ZONE
X-Via-PopH
Magicmarker
X-NU-AKA-ACS-Version
X-Litespeed-Cache
X-Worker
X-Protected-By
X-Via-PopV
X-Cache-Metadata
X-GEO
Memory
X-Request-Start
X-Branch-Name
Resin-Trace
XServer
X-Envoy-Upstream-Healthchecked-Cluster
X-Referer
X-Servedbyhost
X-Dynatrace-Js-Agent
SRV
X-Ratelimit-Limit
Release
X-ServedByHost
X-Bc
X-Pf-Uncompressing
X-FORWARDED-FOR
X-Oneagent-Js-Injection
X-Zone
X-NGINX-Cache
X-Azure-Ref-OriginShield
X-Policy
RequestId
X-Cache-Debug
Dt-Cache-Category
X-Swift-Error
X-TH-Server
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
Load-Balancing
Ohc-Cache-HIT
X-C-Zone
X-C-Key
X-Unique-ID
X-DC
X-VCL-Version
X-Reqid
IBM-Web2-Location
Lb
Esi-Enabled
Ttl
X-Configured-By
X-AIR-PT
X-Cache-Id
X-Esi-Check
Server-Int
Who
Dnion-Transfer-Encoding
X-Ruxit-Js-Agent
X-Ocache
X-Tb-Optimization-Total-Bytes-Saved
X-Via-Ucdn
GeoIP-Country-Code
Powered-By
X-Datadome
X-Node-ID
X-Gzip
X-Fastly-Country-Code
X-COUNTRY
Pics-Label
Tcn
GeoIP-Latitude
X-WA
GeoIP-City
X-SRV
UCS
X-Country-IP
MIME-Version
X-Pinterest-Direct
Product
LB
X-VarnishDD-TTL
X-Fpc
FSS-Cache
X-B3-SpanId
Fastly-Soc-X-Request-Id
Fastly-SSL
X-Powered-Y
X-PJAX-URL
X-SERVER-NAME
X-Svr
X-RAMCache
X-PF-Uncompressing
X-Action
X-RPM
X-DSS
X-Varnish-Url
X-RPS
X-DB
X-DI
X-Fastly-Request-Id
X-ABtesting
Lfy
Sid
X-Hello
X-Fastly-Backend-Reqs
X-Flog
X-RSL
X-DW
X-WPE-Loopback-Upstream-Addr
X-HostName
X-Server-IP
X-Varnish-Beresp-TTL
X-MID
X-SD-PageType
FSS-Proxy
Host-ID
X-Cache-Backend
Requestid
X-LiteSpeed-Cache-Control
X-Zalando-Child-Request-Id
X-Page-Impression-Id
X-Flow-Id
X-Amzn-Remapped-Connection
ProcessTime
X-Apw-Access-Action
X-Amzn-Remapped-Date
X-Apw-Hits
X-ElasticPress-Search
CDN
Amp-Access-Control-Allow-Source-Origin
X-Agile-Brick-Ok
X-Render-Time
X-Via-CDN
X-Apw-Access-Object
Xet-Cookie
X-Apw-Access-Token
CF-IPCountry
WZWS-RAY
C-Via
X-Aicache-OS
X-Debug-Revision
X-Debug-Controller
Cneonction
X-BE
X-User
X-B3-Parentspanid
SN
X-Compress-Hint
X-Check-Cacheable
L
X-UPSTREAM-Address
X-Litespeed-Cache-Control
CloudFront-Viewer-Country
X-Nananana
X-Beluga-Trace
X-Key
X-Internal-Host
X-Request-URL
X-Dw-Trace-Id
X-App
DataCenter
X-Request-Url
X-Fastly-Cache-Hits
X-MiniProfiler-Ids
X-Beluga-Cache-Status
X-LB-ID
X-Beluga-Response-Time
X-Beluga-Record
X-Beluga-Node
X-Beluga-Status