Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
Last-Modified
Accept-Ranges
Pragma
X-Content-Type-Options
X-Powered-By
CF-RAY
ETag
Link
Expect-CT
Via
X-XSS-Protection
X-Cache
Age
Access-Control-Allow-Origin
Content-Security-Policy
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Served-By
X-Amz-Cf-Id
X-Varnish
Referrer-Policy
X-FRAME-OPTIONS
X-Xss-Protection
X-Timer
CF-Cache-Status
Access-Control-Allow-Headers
X-AspNet-Version
Access-Control-Allow-Methods
X-Request-Id
X-Runtime
X-Download-Options
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Request-ID
X-Cacheable
Alt-Svc
X-Generator
Content-Security-Policy-Report-Only
X-Check
X-AspNetMvc-Version
Status
X-Adblock-Key
X-Cache-Status
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Iinfo
X-Permitted-Cross-Domain-Policies
X-Template
Content-Encoding
X-Language
X-Content-Security-Policy
X-Turbo-Charged-By
X-CDN
X-Type
X-Buckets
Keep-Alive
Xkey
X-AH-Environment
X-Cache-Group
X-Backend
Access-Control-Max-Age
WPE-Backend
X-Pass-Why
X-Age
CF-Ray
X-POWERED-BY
X-Server
Upgrade
EagleId
Access-Control-Expose-Headers
X-Via
X-Nginx-Cache-Status
X-Server-Powered-By
X-Drupal-Dynamic-Cache
X-Pingback
X-Varnish-Cache
Grace
X-Amz-Request-Id
X-Amz-Id-2
X-Hacker
X-Swift-SaveTime
X-Swift-CacheTime
X-UA-Device
X-Robots-Tag
Ali-Swift-Global-Savetime
P3p
Cf-Railgun
X-LiteSpeed-Cache
X-Proxy-Cache
X-Envoy-Upstream-Service-Time
X-Ua-Compatible
X-Page-Speed
Request-Context
Content-Location
X-Device
X-Ac
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cnection
X-Node
X-Amz-Version-Id
X-Host
X-Cache-Lookup
Surrogate-Control
X-WebKit-CSP
X-Server-Id
X-Backend-Server
X-Rack-Cache
X-Rq
X-Response-Time
X-Application-Context
X-Readtime
EagleEye-TraceId
X-CST
Server-Timing
Pinterest-Generated-By
X-Cloud-Trace-Context
X-TTL
X-Url
Request-Id
X-OneAgent-JS-Injection
Report-To
X-Instart-Request-ID
X-Country
X-Px
X-ORACLE-DMS-ECID
X-Clacks-Overhead
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Feature-Policy
Edge-Control
Rating
X-Country-Code
Allow
X-DynaTrace-JS-Agent
X-Dns-Prefetch-Control
X-ESI
X-Powered-CMS
Charset
X-Server-Name
X-PC
X-Vname
X-TtlSet
X-FTR-Request-ID
X-DataDome
X-DynaTrace
X-Origin-Cache
NEL
X-MS-InvokeApp
X-Cached
X-Goog-Hash
X-Recruiting
X-Vhost
X-Varnish-TTL
X-ORACLE-DMS-RID
X-VARITI-CCR
X-GitHub-Request-Id
RTSS
Content-MD5
X-F-Cache
X-Version
X-Exp-Variant
X-Cdn-Fetch
X-Geo-Segment
X-Exp-Id
X-Kinja-Revision
X-Kinja-Server
X-Kinja-Build
X-GoogleNews-Bot
X-Kinja
X-Powered-By-Plesk
Public-Key-Pins
PB-RID
PB-PID
X-Mobile-Rewrite
Arc-Version
X-Mod-Pagespeed
X-Pinterest-Rid
Pinterest-Version
X-Upstream-Env
Verso
Accept-CH
MS-Author-Via
X-Client-IP
X-Abt-Application-Version
X-D2id
SPRequestGuid
X-CF-Powered-By
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Dispatcher
X-N
X-SharePointHealthScore
X-Amz-Rid
Nginx-Cache
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Trace
AR-ATIME
AR-PoweredBy
X-Dw-Request-Base-Id
Accept-CH-Lifetime
X-Fastly-Request-ID
X-Navigation-Version
X-T
DynaTrace
AR-CACHE
Paypal-Debug-Id
X-Server-ID
X-Varnish-Age
X-Upstream
X-Hits
Arr-Disable-Session-Affinity
TCN
X-DIS-Request-ID
X-Forwarded-Proto
X-Origin-Upstream-Status
X-Id
X-Amz-Meta-S3cmd-Attrs
X-Ruxit-JS-Agent
SPRequestDuration
SPIisLatency
X-Grace
X-Pad
X-Shield-Request-Id
X-Content-Options
X-NF-Request-ID
Realpath
X-Content-Digest
X-HeyJason
X-Do-Not-Hack
Permitted-Cross-Domain-Policies
AR-SID
X-Cache-Hit
X-Kinsta-Cache
X-IPLB-Instance
Access-Control-Request-Method
X-Acc-Meta-Resource-Type
X-Mrf-Section-Lastmod
X-Logged-In
MRF-Tech
X-Mrf-Item-Lastmod
Mrf-Cache-Status
X-FastCGI-Cache
X-B
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-HW
X-Vcap-Request-Id
X-SS-Set-Cookie
X-Debug
X-XRDS-Location
S
X-Ser
Service-Worker-Allowed
X-Wix-Server-Artifact-Id
X-MSEdge-Ref
Server-Name
X-PressLabs-Stats
X-Frontend
Tracecode
X-Cache-Key
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Realm
X-FTR-Balancer
X-FTR-Backend
X-FTR-Cache-Status
X-Oneagent-Js-Injection
X-FTR-DC
AMP-Access-Control-Allow-Source-Origin
X-NewRelic-App-Data
X-FTR-Expires
Rt-Fastcgi-Cache
Fastcgi-Cache
X-Forwarded-For
Surrogate-Key
X-GUploader-UploadID
Eomportal-Instance
Fastly-Restarts
Alternate-Protocol
X-Cache-Rule
Cleartype
Cache-Status
Backend-Timing
X-Analytics
X-Srv
Host
X-Oracle-Dms-Rid
TP-L2-Cache
X-Revision
X-HS-Content-Id
TP-Cache
X-HS-Hub-Id
X-Accel-Buffering
X-Rid
X-Whom
X-TA-CDN-Provider
X-User-Agent
FilterID
Public-Key-Pins-Report-Only
X-VCache
X-RateLimit-Remaining
X-FTR-Cache-Host
X-Debug-Info
X-Akam-SW-Version
X-NWS-LOG-UUID
ServerID
X-AOL-HN
X-XRDS-LOCATION
X-Cache-2
X-Varnish-Backend
X-Webkit-CSP
X-Via-JSL
X-Cdn
Front-End-Https
Accept-Charset
X-Mobile
X-Content-Powered-By
X-Kinja-Server-Push
X-Request-Received
X-Request-Processing-Time
X-Zen-Fury
X-Cached-By
Viewport
X-WPE-Loopback-Upstream-Addr
X-Node-Name
X-App-Environment
X-LB-Cache
X-Tumblr-Pixel
X-Varnish-Hostname
X-Tumblr-User
X-Tumblr-Pixel-0
X-Magnolia-Registration
Host-Header
X-Cluster
X-Page-Id
X-Akamai-Edgescape
X-TT
X-Framework
X-Device-Type
X-Cache-Control
X-Content-Security-Policy-Report-Only
X-Request-Guid
X-Handled-By
X-Instance
Liferay-Portal
X-Platform-Server
X-Correlation-Id
X-B-Cache
X-B3-Sampled
X-Signature
X-BCube-Filmed-By
Upgrade-Insecure-Requests
DC
X-FB-Debug
Cache-Tag
X-Cache-Server
X-Hostname
X-B3-Traceid
X-Origin-Server
Server-Node
MicrosoftSharePointTeamServices
X-TT-TIMESTAMP
X-Ttl
X-Amzn-Trace-Id
Source
X-Fastcgi-Cache
X-Sol
X-Middleton-Display
X-Accel-Expires
Display
X-Contextid
X-WA-Info
Retry-After
X-Servedby
X-Varnish-Server
X-Cache-Action
HitInfo
HitType
Server-Info
X-Distil-CS
X-Cache-Operation
X-APP-VERSION
X-Wix-Request-Id
X-Seen-By
X-GeoIP
X-Port
Webserver
User-Agent
X-Tumblr-Pixel-1
Content-Script-Type
X-Tumblr-Pixel-2
GEO-INFO
X-S
Content-Style-Type
X-RequestSource
X-Generated-By
X-Status
X-WebKit-CSP-Report-Only
X-Jobs
Healthy
X-Edge-Location
X-Locale
Actual-Object-TTL
X-Varnish-Hits
X-UUID
X-Region
X-Response-Served-From
X-Amz-Replication-Status
AsisCache
ServedBy
X-TX-ID
X-Geo-Country
X-FW-Hash
X-FW-Server
X-FW-Static
X-FW-Serve
X-FW-Type
X-Edge-Cache
X-Edge-Cache-Key
X-Newrelic-App-Data
X-Adobe-Loc
X-Adobe-Content
X-Drupal-Cache-Tags
SRV
X-Hyper-Cache
X-Daa-Tunnel
Refresh
X-DataStream-Cache-Status
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-ATG-Version
X-Iejgwucgyu
X-Esi
X-Cache-NE
X-Varnish-Grace
X-Cache-TTL-Remaining
Filters
X-Middleton-Response
Response
IBM-Web2-Location
S-Cnection
X-Amz-Server-Side-Encryption
X-URL
X-Cache-Age
NGB
Payment
X-Content-Type
Datacenter
X-Pc-Key
X-Pc-Appver
X-Pc-Hit
X-Proxied
X-Cache-Remote
X-CDN-Forward
X-Vg-Webcache
X-Cacheable-TTL
X-AppVersion
X-Az
X-Activity-Id
Country
X-App-Server
X-HS-Cache-Config
Served-By
Edge-Cache-Tag
Cache
X-Cache-TTL
X-Unique-ID
X-Kong-Upstream-Latency
X-Sucuri-ID
X-Kong-Proxy-Latency
X-UA
X-Mode
X-RN-RSRV
X-HS-Combine-CSS
X-Rendered-As
X-Cache-Var
X-Detected-As
X-Is-Bot
Machine
Meta-Geo
Load-Balancing
X-Akamai-Transformed
X-Cache-Var-Map
X-Varnish-IP
X-Rocket-Nginx-Bypass
X-Proxy
AR-Request-ID
X-ProcessESI
X-Ruxit-Js-Agent
X-RemovedCookies
X-Rule
X-FC-Vary-Parameters
X-Origin-Hint
TWC-Locale-Group
DB-Nickname
TWC-Privacy
Webcakes-App-Name
X-PCL
User-Cache-Control
X-Origin
TWC-GeoIP-LatLong
Property-Id
Mn-Server-Ip
TWC-Connection-Speed
X-OCL
TWC-GeoIP-Country
TWC-Device-Class
Webcakes-App-Version
X-Human
X-EIG-Tracking-Id
X-Cache-Category-Id
X-ServerID
Cache-Name
Access-Control-Allow-Method
X-Tb
X-BYPASS-REASON
X-ProxyCache-Status
X-Amz-Meta-Surrogate-Control
Webcakes-Region
X-BB-IP
X-ProxyCache-Key
X-Grey
X-Hosted-By
X-Varnish-Cacheable
Backend
X-Format
L5d-Success-Class
X-Routing-Service
Now
X-Original-Request
X-Site-Version
Azure-Version
Azure-InstanceId
X-TNCMS
Azure-RegionName
Azure-SiteName
Azure-SlotName
S-Rt
X-NodeID
X-Debug-Cache
X-CDN-Cache
X-Hit
X-Environment-Context
X-Generated
X-Correlation-ID
X-JoinUs
X-Real-IP
X-Access
X-Loop
X-L-Path
X-Varnish-Cache-Hits
X-Section
X-Zipkin-Id
X-Viewer-Country
X-PERF
Selected-FE
X-Via-Fastly
X-Pubstack
X-SplitTest
OT-Force-Account-Verify
X-Ocache
X-Proxy-Build
X-Agile-Age
X-LJ-Flow-ID
X-IP
X-Cache-Config
X-AWS-Id
X-App-Name
X-HOST
X-Agile-Id
X-ApacheServer
X-Agile
ServerName
X-VWS-Id
Cache-Key
X-Upgrade-Enabled
X-Timing-Wait
Access-Control-Request-Headers
X-Www-Served-By
X-TWH-CORRELATION-ID
X-Origin-CC
X-Drupal-Cache-Contexts
X-RateLimit-Limit
X-NGENIX-Cache
X-CCM
X-Backend-Name
HostName
X-OVcl
X-OVcl-Cache
X-Mrs-Cache-Hits
X-Mrs-Age
Fastcgi-X-Cache-Version
X-Mshield-Cache-Status
X-Nginx-Cache
X-Mrs-Cache
X-Xfnlog-Site
Fastcgi-Useragent
Fastcgi-X-Cache
X-Source
X-Pc-Host
X-Pc-Date
X-Upstream-CT
Powered-By-ChinaCache
X-Upstream-HT
X-Akamai-Request-ID
X-Storage
From-Origin
X-Litespeed-Cache
Pagespeed
X-Amz-Apigw-Id
X-Vgn-Hpd-Reason
X-Amzn-RequestId
X-Forwarded-Host
Fastly-SSL
X-Feature
X-NC
X-Internal-Host
X-M-Reqid
X-Varnish-Beresp-Grace
X-Qnm-Cache
X-NCache
X-Varnish-Beresp-Status
X-M-Log
X-Time-Microsecs
LB
X-Release
X-Ms-Request-Id
X-Ms-Version
X-Ms-Lease-Status
X-Ms-Blob-Type
X-Distributor
X-UA-Device-Type
X-Labrador-Cache-Channel
X-Birta-Served
X-Birta-Cache-Post
NtCoent-Length
X-VG-TLSProxy
X-Microcachable
Pagetype
X-EdgeConnect-Cache-Status
XServer
X-App-Version
X-Webkit-Csp
X-Cache-Backend
X-Transaction
X-Twitter-Response-Tags
X-Connection-Hash
Time
X-B3-Spanid
X-SERVER-NAME
X-PHP-Backend
X-Sucuri-Cache
Frame-Options
MIME-Version
X-S-Cookie
X-Rojux
X-NU-AKA-ACS-Version
X-Request-UUID
X-Redis-Cache
Host-ID
Fly-Cache
X-Region-Sid
X-Org
Fly-Request-Id
X-PAYTM-SRV-ID
X-Rewrite-Enabled
X-SIPLIST1
X-Via-CDN
X-VG-WebServer
Ajk
X-Via-Edge
X-Via-SSL
Xc-Version
X-WebServer
Arc-Country
BehaviorPad-Version
Ec-Rule-Version
X-Server-Time
X-Server-By
X-SRCache-Key
X-Trv-Group
X-UE-Client-Country
Cache-Prefix
X-ScT
X-IN-APIGATEWAY
X-D
X-CUA
X-CS
X-CF-Lambda-Version
X-A
Www
X-Developer
X-Destination
X-Date
X-CF-Lambda-Fn
X-Cache-Bucket
X-Application
X-Accel-Expires-Debug
X-A-Dcw
X-A-Wwc
X-A-Dam
X-ARC
X-BB-ID
X-A-Ccd
X-B-Cookie
X-Died
VivaBuild
X-Generation-Time
MD5-Digest
X-Generated-In
Meta-Geo-Continent
IsBot
X-A-Dgt
X-Irp-Debug
X-IN-WAF
X-IN-SSL-APIGATEWAY
Mobile-Detection-Method
NGX
V-Age
Viewtype
X-Dispatcher-Server
X-DPWN-IS-SECURE
T-Server
Rendered-Blocks
X-G
X-From
X-Logtrace-Id
Server-Int
X-Powered-By-ANYU
X-FireWall-Port
ViewerVersion
X-Web-Node
WZWS-RAY
X-NWS-UUID-VERIFY
X-Instance-Name
X-Key
HA-Urlpath
X-Layer
X-Cluster-Node
X-Hl-Ver
X-Node-Id
Magicmarker
X-Hash
HA-Servedtime
X-Hnp-Log
HA-Ipaddr
HA-Geolat
HA-Geocountry
HA-Geocity
GMS-Ver
HA-Geolon
HA-Georegion
HA-Host
X-GeoIP-City
Ha-Gx-Prefs
X-No-Session
X-Fastly-Cache
X-Cache-CFC
X-Cache-Enabled
X-CGP
Release
X-Block-Status
X-C
Web-Mar-Node
SN
X-Amz-Meta-Cache-Control
X-Core-Value
X-Crawler
X-Eu-Site
X-External-Request-Id
X-F5-Cache
X-NX-Host
NodeID
X-Debug-Log
Origin-Edge-Control
Origin-Cache-Control
X-Debug-Cookies
X-Gen-Mode
HA-Cloudapp
Cneonction
X-Store
X-VServer
X-We-Are-Hiring
X-UnsetCookies
X-Varnish-Action
X-VCT
X-S-Maxage
Backend-Name
AKAMAI
Country-Code
X-Platform
X-Phone
X-Var-Ttl
X-Request-Time
X-Owner
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Origin-TTL
X-Webstats-RespID
X-V
X-GZip
X-CACHE-AGE
X-Clientip
X-Croise-Owner
X-Core-Mission
X-Up
X-Variation
X-Cache-Host
X-Backend-Host
X-Actual-URL
Powered
X-Policy
X-Backend-State
X-Backend-Url
X-Cache-URL
X-Cache-Srv
X-Cache-Expires
X-Varnish-Beresp-Ttl
X-Cdn-Srv
X-Swa-Ws
X-Passed-To-PostProcessResponse
Uber-Trace-Id
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Request-URI
X-RCS-CacheZone
X-Passed-To-DLL
X-Location
X-Passed-To-BeforeDispatch
X-Passed-To
X-Nginx-Cache-Key
X-MSEdge-Flight
X-MSEdge-Features
X-Response-By
X-Returned-From
X-Gannett-Site-Version
X-Stale
X-Trace-Id
X-TT-LOGID
X-Epic-Correlation-Id
X-Tumblr-Pixel-3
X-Sf
X-Server-IP
X-Returned-From-DLL
X-Returned-From-BeforeDispatch
X-Returned-From-PostProcessResponse
X-Secret
X-GeoIP-Country-Code
X-Developers
X-HTML-Minification-Powered-By
Origin
PFcat
Odigeo-Trace-Id
Kp-EeAlive
Is-Eu
Platform
Pragrma
Section-Io-Cache
Request-EU
Request-Country
Proxy-Connection
Esi-Enabled
Countrycode
X-Shopify-Stage
X-Sorting-Hat-PodId
X-ShopId
X-ShardId
X-Alternate-Cache-Key
X-Sorting-Hat-ShopId
Adler-Geo
CDCHOST
Apple-News-Services-Request-Url
Apple-News-Services-Host
Apple-News-Services-Handled
Server-Host
Apple-News-Services-Parsed-Url
X-Ua
Thinkindot-CacheControl
MI-API
Thinkindot-CacheControl-Type
X-Matched-Rule
X-MI-In-Market
X-FW-Version
Heartbleed
X-Fstrz
X-ElasticPress-Search
X-Device-Os
MI-Cache-Age
MI-Cache
X-Fetched-On
Fastly-SWR
Fastly-SIE
Server-ID
X-Servername
Thinkindot-Control
X-Thinkindot-L3
REQUESTUUID
X-Worker
True-Client-Country-4JS
ProcessTime
X-Rebelmouse-Cache-Control
Fastly-Backend-Name
X-Rebelmouse-Surrogate-Control
X-Reboot
Cache-Tags
On-Server
X-Sn-Servicetimems
X-Alicdn-Da-Ups-Status
RNT-Time
X-Ckpd-Fst-Backend
Sid
X-Content-Age
RNT-Machine
X-Backend-TTL
X-Cdn-Origin
Request-Time
Resin-Trace
PageSpeed
Xserver
Content-Disposition
Decoy-Debug-Key
HTTPS
Decoy-Debug-TTL
X-Skip-Cache
X-ServiceProvider
Decoy-Debug-Status
X-Csrf-Token
X-Ezoic-Cdn
X-Endurance-Cache-Level
X-B3-TraceId
Cache-Cookie-Set-Lfrom
X-Dc
Cache-Cookie-Set-From
X-Pf-Uncompressing
Cache-Cookie-Set-Idcheck
Cteonnt-Length
Warning
X-Req
CF-IPCountry
X-Proto
RequestId
WP-Super-Cache
X-Oss-Request-Id
X-Real-Ip
X-Oss-Object-Type
X-Oss-Storage-Class
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-Refresh
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
We-Hiring
X-Datadome
X-Servedbyhost
Mail-Subject
CDN
X-Newrelic-Synthetics
X-TIME
CACHE
X-Surge-Debug
X-Pjax-Url
X-GEO
Ar-Sid
Dnion-Transfer-Encoding
X-Aed
X-Time
X-Cache-ASPX
X-Nc
X-Varnish-Ttl
X-GoCache-CacheStatus
Pramga
X-GRACE
X-Atg-Version
Hostname
X-CLOUD-TRACE-CONTEXT
X-DC
X-COUNTRY
TSSecure
X-CSRF-Token
X-Geo
X-Edge-IP
X-Guploader-Uploadid
X-Varnish-Beresp-TTL
X-Server-W
X-Page-Type
X-Ms-Lease-State
GeoIp-Country-Code
Geoip-Latitude
NODE
X-Oracle-Dms-Ecid
NnCoection
X-Origin-Date
X-DataStream-Origin-MEX-Latency
X-Flog
X-Origin-Expires
X-ABtesting
X-DataStream-MidMile-RTT
X-Hello
X-Cdn-Forward
A
X-Varnish-HitMiss
X-Varnish-Url
X-Aicache-OS
X-HCF
X-Cache-Control-Set-By
X-WA
X-Amz-Cf-Pop
X-Auto-Login
SD-X-WS
Lfy
Cdn
WWW-Authenticate
X-Akamai-Request-ID2
FSS-Proxy
FSS-Cache
X-Server-Group
X-Ratelimit-Limit
MS-CV
Node
Mime-Version
X-UPSTREAM-Address
Geoip-City
X-Wa
Processtime
PICS-Label
Rt-Proxy-Cache
X-Varnish-URL
X-Wix-Route-ID
X-Via-NSCOPI
X-Sentry-ID
X-Use-Magma
GeoIP-Country-Code
X-PAGE-TYPE
GeoIP-Latitude
X-APP
X-Unique-Id
X-Check-Cacheable
X-EC-Security-Audit
X-From-Cache
X-Cache-Id
X-Nananana
X-NODE
Lb
X-Thanos
X-Bip
X-Served-From
PageType
X-Gdpr
X-Edge-Server
Cdn-Host
GeoIP-City
Memcached
X-SRV
X-Cache-Info
Cdn-Request-Time
Dont-Set-Cookie
X-Gen-Id
X-CACHE-KEY
X-Cookie
COMMERCE-SERVER-SOFTWARE
X-Be
X-Proxy-Server
X-GDPR
X-MP-GENERATED-AT
X-Request-Start
X-Fastly-Backend-Reqs
X-RTag
Ms-Operation-Id
X-Dynatrace-Js-Agent
X-WR-MODIFICATION
DataCenter
X-Load-Cache
X-Env
X-HS-Status
X-FORWARDED-FOR
X-Optimization
X-Cache-HT
Is-Session-Tracking
Get-Access-Time
X-Fastly-Cache-Hits
X-Cache-Ttl
X-Swift-Error
GW-Server
UCS
X-B3-SpanId
X-PJAX-URL
Pics-Label
Who
Memory
X-User
X-Ver
V-Cache
X-ServedByHost
X-RateLimit-Reset
X-Cache-FS-Status
Group
Cache-Hits
X-Fe
Requestid
URI
Ws
X-Ibm-Trace
X-Dw-Trace-Id
X-Meta-Tbi-Cache-Vertical
X-CDN-Pop-IP
X-CDN-Pop
Cf-Ipcountry
X-ID
Amp-Access-Control-Allow-Source-Origin
AGE-Hash
X-Shard
X-VC
X-SB
X-PF-Uncompressing
NX-Cache
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Bug-Bounty
X-GZIP
Httpd-Identifier
Xet-Cookie
Accept-Language
Serverid
X-NGINX-Cache
Locale
X-BBXSRF
Powered-By
N-Cache
CDN-Cache
CDN-Cache-Hit
X-Content-Encoded-By
X-Li-Fabric
X-Urbn-Context-Path
X-Urbn-Site-Id
X-LI-UUID
X-LI-Proto
X-Li-Pop
X-Wix-Petri-Ex
CDN-Node
X-CacheKey
X-SVT-ORM-VERSION
Https
X-Ratelimit-Remaining
X-Varnish-Info
X-SVT-ORM-RULES
Version
X-Cache-Debug
X-Cache-Handler
X-BE
X-Grace-Duration
X-RequestId
X-Flags
X-Litespeed-Cache-Control
X-StackifyID
X-Akamai-ERRuleID
X-ServerName
X-Route-Name
X-Is-Crawler
Ohc-File-Size
X-Providence-Cookie
X-Akamai-ERPolicy