Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
Last-Modified
Accept-Ranges
Pragma
X-Content-Type-Options
X-Powered-By
CF-RAY
ETag
Link
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Access-Control-Allow-Origin
Content-Security-Policy
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Served-By
X-Amz-Cf-Id
X-Varnish
Referrer-Policy
X-FRAME-OPTIONS
X-Timer
CF-Cache-Status
Access-Control-Allow-Headers
X-AspNet-Version
X-Request-Id
Access-Control-Allow-Methods
X-Xss-Protection
X-Runtime
X-Download-Options
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Cacheable
Alt-Svc
X-Request-ID
X-Generator
Content-Security-Policy-Report-Only
X-Check
X-AspNetMvc-Version
Status
X-Cache-Status
X-Adblock-Key
Timing-Allow-Origin
X-Iinfo
X-Permitted-Cross-Domain-Policies
X-DNS-Prefetch-Control
X-Template
Content-Encoding
X-Language
X-Content-Security-Policy
X-Turbo-Charged-By
X-CDN
X-Type
Keep-Alive
X-Buckets
Xkey
X-Backend
X-Cache-Group
X-AH-Environment
Access-Control-Max-Age
WPE-Backend
X-Pass-Why
X-Age
X-Server
CF-Ray
Upgrade
X-POWERED-BY
EagleId
Access-Control-Expose-Headers
X-Via
X-Nginx-Cache-Status
X-Server-Powered-By
X-Pingback
X-Drupal-Dynamic-Cache
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Grace
X-Hacker
X-Amz-Request-Id
X-Amz-Id-2
X-UA-Device
Ali-Swift-Global-Savetime
X-Robots-Tag
Cf-Railgun
P3p
X-LiteSpeed-Cache
X-Envoy-Upstream-Service-Time
X-Proxy-Cache
X-Page-Speed
X-Ua-Compatible
Request-Context
Content-Location
X-Device
X-Ac
X-Node
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Cnection
X-Host
X-Cache-Lookup
X-Amz-Version-Id
Surrogate-Control
X-Server-Id
X-WebKit-CSP
X-Backend-Server
X-Rack-Cache
X-Response-Time
X-Rq
X-Application-Context
X-Readtime
X-CST
EagleEye-TraceId
X-Dns-Prefetch-Control
Pinterest-Generated-By
Server-Timing
X-Url
X-Cloud-Trace-Context
X-TTL
X-OneAgent-JS-Injection
X-Instart-Request-ID
Request-Id
X-Px
Report-To
X-Country
X-ORACLE-DMS-ECID
X-Clacks-Overhead
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Feature-Policy
Rating
Edge-Control
X-Country-Code
Allow
X-DynaTrace-JS-Agent
Charset
X-ESI
X-Server-Name
X-Powered-CMS
X-DataDome
X-FTR-Request-ID
X-PC
X-Vname
X-TtlSet
X-Origin-Cache
X-DynaTrace
NEL
X-MS-InvokeApp
X-ORACLE-DMS-RID
X-Goog-Hash
X-Recruiting
X-Varnish-TTL
X-Cached
X-VARITI-CCR
X-Vhost
Content-MD5
X-GitHub-Request-Id
RTSS
X-F-Cache
X-Version
X-Exp-Id
X-GoogleNews-Bot
X-Kinja
X-Kinja-Build
X-Kinja-Server
X-Geo-Segment
X-Exp-Variant
X-Kinja-Revision
X-Cdn-Fetch
X-Powered-By-Plesk
Public-Key-Pins
Pinterest-Version
PB-RID
PB-PID
X-Pinterest-Rid
X-Upstream-Env
X-Mobile-Rewrite
Arc-Version
X-Mod-Pagespeed
X-CF-Powered-By
Verso
X-Client-IP
SPRequestGuid
X-Abt-Application-Version
MS-Author-Via
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Accept-CH
X-D2id
X-N
X-Dispatcher
X-SharePointHealthScore
AR-ATIME
AR-PoweredBy
X-Amz-Rid
AR-CACHE
Permitted-Cross-Domain-Policies
X-Do-Not-Hack
X-HeyJason
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-T
Nginx-Cache
DynaTrace
X-Navigation-Version
X-Dw-Request-Base-Id
Paypal-Debug-Id
X-Trace
X-Fastly-Request-ID
X-Upstream
Accept-CH-Lifetime
Arr-Disable-Session-Affinity
X-Varnish-Age
TCN
X-Hits
X-Amz-Meta-S3cmd-Attrs
X-Forwarded-Proto
X-Grace
X-Id
X-DIS-Request-ID
X-Origin-Upstream-Status
X-Shield-Request-Id
X-FastCGI-Cache
X-Pad
SPRequestDuration
SPIisLatency
X-Content-Options
X-Cache-Hit
X-Ruxit-JS-Agent
Realpath
AR-SID
X-Kinsta-Cache
X-Logged-In
Access-Control-Request-Method
X-NF-Request-ID
X-Acc-Meta-Resource-Type
X-IPLB-Instance
X-Content-Digest
X-B
MRF-Tech
Mrf-Cache-Status
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
X-XRDS-Location
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-SS-Set-Cookie
X-Server-ID
X-Vcap-Request-Id
X-HW
S
X-Debug
X-MSEdge-Ref
Service-Worker-Allowed
X-Ser
Server-Name
X-PressLabs-Stats
X-FTR-Balancer
X-FTR-Realm
X-FTR-Cache-Status
X-FTR-Backend-Server
X-FTR-DC
X-Frontend
X-FTR-Backend
X-Country-Code-Real
X-Wix-Server-Artifact-Id
Tracecode
X-FTR-Expires
X-Cache-Key
X-NewRelic-App-Data
Fastcgi-Cache
Rt-Fastcgi-Cache
AMP-Access-Control-Allow-Source-Origin
X-GUploader-UploadID
Alternate-Protocol
X-Forwarded-For
Eomportal-Instance
Surrogate-Key
X-Oneagent-Js-Injection
X-Cache-Rule
Cleartype
Cache-Status
X-Srv
X-HS-Hub-Id
X-HS-Content-Id
X-Analytics
X-NWS-LOG-UUID
Backend-Timing
Host
TP-Cache
TP-L2-Cache
X-User-Agent
X-Revision
X-VCache
FilterID
X-Rid
Fastly-Restarts
X-Whom
X-Debug-Info
X-FTR-Cache-Host
Public-Key-Pins-Report-Only
X-Akam-SW-Version
X-AOL-HN
X-Cache-2
ServerID
X-Via-JSL
X-RateLimit-Remaining
X-Varnish-Backend
X-Content-Powered-By
X-Accel-Buffering
X-Request-Received
X-Request-Processing-Time
Accept-Charset
X-Webkit-CSP
Front-End-Https
X-Zen-Fury
X-Cdn
X-Mobile
Viewport
X-Kinja-Server-Push
X-Ttl
X-Oracle-Dms-Rid
X-Cached-By
X-Node-Name
X-WPE-Loopback-Upstream-Addr
Liferay-Portal
X-XRDS-LOCATION
X-App-Environment
X-LB-Cache
X-Cache-Control
X-Page-Id
Host-Header
X-Cluster
X-Varnish-Hostname
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Framework
X-Handled-By
X-Request-Guid
X-TT
X-Device-Type
X-Magnolia-Registration
X-Content-Security-Policy-Report-Only
X-Akamai-Edgescape
X-Platform-Server
X-Signature
X-Hostname
X-B3-Sampled
X-B-Cache
Cache-Tag
X-BCube-Filmed-By
X-Instance
Upgrade-Insecure-Requests
DC
X-FB-Debug
X-Cache-Server
X-B3-Traceid
Server-Node
X-Origin-Server
X-TT-TIMESTAMP
Source
MicrosoftSharePointTeamServices
X-Correlation-Id
X-TA-CDN-Provider
Retry-After
X-Amzn-Trace-Id
X-WA-Info
X-Accel-Expires
X-Servedby
X-Contextid
HitType
HitInfo
Server-Info
X-Cache-Action
X-Varnish-Server
X-Cache-Operation
X-Distil-CS
Display
X-Sol
X-Middleton-Display
X-Port
X-Daa-Tunnel
X-Generated-By
X-APP-VERSION
X-Edge-Location
AsisCache
X-Geo-Country
X-GeoIP
X-Amz-Replication-Status
X-Wix-Request-Id
X-Seen-By
X-S
GEO-INFO
Content-Script-Type
X-RequestSource
Content-Style-Type
X-Tumblr-Pixel-1
X-Tumblr-Pixel-2
X-TX-ID
Webserver
ServedBy
X-Locale
Actual-Object-TTL
X-WebKit-CSP-Report-Only
X-Hyper-Cache
X-Fastcgi-Cache
X-Status
Healthy
X-Region
X-UUID
X-Response-Served-From
X-Varnish-Hits
X-Jobs
X-FW-Serve
X-FW-Server
X-FW-Type
X-FW-Hash
X-Edge-Cache-Key
X-Adobe-Content
X-Edge-Cache
X-Adobe-Loc
X-FW-Static
X-Drupal-Cache-Tags
User-Agent
X-Varnish-Grace
X-DataStream-Cache-Status
SRV
X-Newrelic-App-Data
S-Cnection
Filters
Refresh
X-Yottaa-Optimizations
X-Amz-Server-Side-Encryption
X-Yottaa-Metrics
NGB
IBM-Web2-Location
X-Proxied
X-Cache-TTL-Remaining
X-Cache-Age
Response
X-Middleton-Response
X-Esi
Cache
AR-Request-ID
X-App-Server
X-CDN-Forward
X-Cache-NE
X-Cache-Remote
Payment
X-Content-Type
X-Pc-Appver
X-Pc-Key
X-Pc-Hit
X-Activity-Id
X-URL
X-AppVersion
X-Az
X-Correlation-ID
X-Cacheable-TTL
X-Unique-ID
X-ATG-Version
X-Ruxit-Js-Agent
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Datacenter
Served-By
Country
X-Vg-Webcache
X-UA
X-Cache-TTL
Edge-Cache-Tag
X-Mode
X-HS-Cache-Config
X-Sucuri-ID
X-Akamai-Transformed
X-Real-IP
X-Rendered-As
Load-Balancing
X-Is-Bot
Meta-Geo
Machine
X-Detected-As
X-RN-RSRV
X-PCL
X-ProxyCache-Key
X-ProcessESI
X-FC-Vary-Parameters
User-Cache-Control
X-BYPASS-REASON
X-Rocket-Nginx-Bypass
X-OCL
X-ProxyCache-Status
X-RemovedCookies
X-Proxy
X-Varnish-IP
X-Varnish-Cacheable
X-Viewer-Country
TWC-Device-Class
TWC-GeoIP-Country
TWC-Connection-Speed
Now
Property-Id
X-PERF
L5d-Success-Class
X-Tb
Access-Control-Allow-Method
X-ServerID
X-Pubstack
Backend
Cache-Key
TWC-GeoIP-LatLong
DB-Nickname
Cache-Name
Mn-Server-Ip
TWC-Privacy
TWC-Locale-Group
X-EIG-Tracking-Id
X-Debug-Cache
X-Cache-Config
X-Grey
X-Hosted-By
X-Origin
X-Origin-Hint
X-Human
X-Cache-Category-Id
X-Source
Webcakes-Region
X-BB-IP
X-ApacheServer
X-Amz-Meta-Surrogate-Control
Webcakes-App-Version
Webcakes-App-Name
X-Hit
S-Rt
X-NodeID
X-JoinUs
X-Loop
Access-Control-Request-Headers
X-L-Path
Azure-SlotName
X-Environment-Context
X-Backend-Name
X-CDN-Cache
X-CCM
X-Format
X-Generated
Azure-RegionName
Azure-Version
X-Access
Azure-InstanceId
Azure-SiteName
X-Section
X-TNCMS
X-Site-Version
X-Routing-Service
X-Zipkin-Id
Selected-FE
ServerName
X-Varnish-Cache-Hits
X-TWH-CORRELATION-ID
X-Upgrade-Enabled
X-Proxy-Build
X-Xfnlog-Site
X-Via-Fastly
X-Agile-Id
X-IP
X-Ocache
X-Original-Request
HostName
X-App-Name
X-Rule
X-Agile-Age
X-Agile
X-Timing-Wait
X-Drupal-Cache-Contexts
X-HS-Combine-CSS
X-NGENIX-Cache
X-Storage
X-Origin-CC
X-Cache-Var-Map
X-Cache-Var
X-OVcl-Cache
X-OVcl
X-VWS-Id
X-AWS-Id
X-SplitTest
X-Www-Served-By
X-Akamai-Request-ID
X-Pc-Date
X-LJ-Flow-ID
X-Pc-Host
X-Upstream-HT
X-Upstream-CT
X-NC
X-RateLimit-Limit
OT-Force-Account-Verify
X-Vgn-Hpd-Reason
X-Nginx-Cache
X-Time-Microsecs
From-Origin
X-Mshield-Cache-Status
X-Mrs-Cache-Hits
X-Mrs-Age
X-Mrs-Cache
X-UA-Device-Type
XServer
X-Litespeed-Cache
Fastcgi-X-Cache
Fastcgi-Useragent
Fastcgi-X-Cache-Version
X-Internal-Host
X-NCache
Powered-By-ChinaCache
X-PHP-Backend
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Distributor
Fastly-SSL
X-Microcachable
X-Release
X-Forwarded-Host
X-Varnish-Beresp-Status
X-Qnm-Cache
X-M-Reqid
X-Feature
X-M-Log
X-Varnish-Beresp-Grace
LB
X-Ms-Request-Id
X-Ms-Blob-Type
X-Ms-Lease-Status
X-Ms-Version
Pagetype
X-Iejgwucgyu
X-Birta-Cache-Post
X-Birta-Served
X-Cache-Backend
X-Labrador-Cache-Channel
Pagespeed
X-EdgeConnect-Cache-Status
MIME-Version
X-Twitter-Response-Tags
X-Transaction
X-Connection-Hash
X-VG-TLSProxy
X-V
NtCoent-Length
X-Instance-Name
X-Webkit-Csp
Frame-Options
X-App-Version
X-Ah-Environment
Time
X-Web-Node
X-B3-Spanid
Ar-Sid
X-Varnish-Beresp-Ttl
X-PAYTM-SRV-ID
X-VG-WebServer
X-Hnp-Log
X-Accel-Expires-Debug
X-A-Dcw
X-A-Dgt
X-A-Wwc
X-Via-CDN
X-Via-Edge
X-B-Cookie
X-BB-ID
X-WebServer
Arc-Country
X-ARC
X-A-Dam
X-Application
X-Via-SSL
X-Logtrace-Id
X-Request-UUID
VivaBuild
X-IN-WAF
Web-Mar-Node
X-IN-SSL-APIGATEWAY
Viewtype
X-Trv-Group
Server-Int
V-Age
X-Irp-Debug
X-IN-APIGATEWAY
Www
X-A-Ccd
Ajk
X-Request-URI
X-Region-Sid
X-Redis-Cache
X-UE-Client-Country
Rendered-Blocks
X-A
X-Block-Status
BehaviorPad-Version
X-Gen-Mode
Ec-Rule-Version
X-G
X-DPWN-IS-SECURE
X-Dispatcher-Server
X-Destination
X-Developer
X-Died
X-Org
X-Server-Time
X-ScT
X-From
X-GZip
X-Rojux
X-NU-AKA-ACS-Version
Fly-Cache
X-Server-By
Fly-Request-Id
X-S-Cookie
X-Rewrite-Enabled
NGX
X-CF-Lambda-Fn
X-CF-Lambda-Version
Xc-Version
X-Generated-In
X-Generation-Time
T-Server
X-SRCache-Key
Cache-Prefix
Meta-Geo-Continent
MD5-Digest
X-D
X-Date
Host-ID
X-Cache-Bucket
X-SIPLIST1
IsBot
X-CS
X-CUA
X-Sucuri-Cache
X-FireWall-Port
X-C
Cneonction
X-SERVER-NAME
HA-Ipaddr
HA-Host
X-Debug-Log
X-ElasticPress-Search
HA-Servedtime
HA-Urlpath
Kp-EeAlive
X-Crawler
X-Debug-Cookies
HA-Georegion
HA-Geolon
HA-Geocity
X-Fastly-Cache
HA-Cloudapp
X-F5-Cache
X-External-Request-Id
HA-Geolat
X-Eu-Site
HA-Geocountry
Magicmarker
X-Core-Value
GMS-Ver
Proxy-Connection
X-Hl-Ver
X-Layer
Release
X-Key
Request-EU
Request-Country
X-HTML-Minification-Powered-By
Origin-Edge-Control
Origin-Cache-Control
X-Cache-Enabled
SN
X-CGP
X-Cache-CFC
NodeID
On-Server
X-Amz-Meta-Cache-Control
True-Client-Country-4JS
Request-Time
Ha-Gx-Prefs
X-Phone
Cteonnt-Length
X-Platform
X-RCS-CacheZone
WZWS-RAY
X-Powered-By-ANYU
Cache-Tags
Backend-Name
AKAMAI
X-No-Session
X-UnsetCookies
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-S-Maxage
Mobile-Detection-Method
X-We-Are-Hiring
X-VServer
PageSpeed
X-Var-Ttl
X-Varnish-Action
CDCHOST
X-Sf
X-Origin-TTL
Esi-Enabled
X-NX-Host
X-Node-Id
X-Owner
Country-Code
X-NWS-UUID-VERIFY
X-HOST
X-Webstats-RespID
X-Backend-Url
X-Returned-From-DLL
X-Returned-From-BeforeDispatch
X-Developers
MI-API
X-Backend-Host
X-Alternate-Cache-Key
X-Swa-Ws
X-Backend-State
X-Device-Os
Decoy-Debug-Status
Decoy-Debug-Key
X-Response-By
X-Passed-To
X-Returned-From
X-Actual-URL
X-Hash
Decoy-Debug-TTL
X-Variation
Fastly-Backend-Name
X-GeoIP-Country-Code
X-Clientip
X-Ckpd-Fst-Backend
X-Passed-To-DLL
X-Cdn-Srv
X-Content-Age
X-Skip-Cache
X-VCT
X-Returned-From-PostProcessResponse
X-Croise-Owner
X-Passed-To-BeforeDispatch
X-Cache-URL
X-Sorting-Hat-ShopId
X-GeoIP-City
X-Up
X-Cache-Expires
X-Sorting-Hat-PodId
X-Cache-Srv
X-Worker
X-Cache-Host
X-Stale
X-Request-Time
Is-Eu
Adler-Geo
X-MI-In-Market
Pragrma
X-MSEdge-Features
X-MSEdge-Flight
RNT-Time
Countrycode
X-Epic-Correlation-Id
X-Passed-To-PostProcessResponse
Platform
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Odigeo-Trace-Id
MI-Cache-Age
Origin
Apple-News-Services-Host
X-Location
PFcat
Apple-News-Services-Handled
Section-Io-Cache
RNT-Machine
X-Secret
X-Fstrz
X-RateLimit-Remaining-Second
Server-Host
X-TT-LOGID
X-ShardId
X-Server-IP
X-Shopify-Stage
X-Tumblr-Pixel-3
X-ShopId
X-RateLimit-Limit-Second
Uber-Trace-Id
X-Trace-Id
X-ServiceProvider
X-Nginx-Cache-Key
Server-ID
MI-Cache
X-Gannett-Site-Version
X-Csrf-Token
X-CACHE-AGE
X-FW-Version
X-Oss-Storage-Class
X-Oss-Object-Type
X-Oss-Request-Id
X-Servername
X-Oss-Server-Time
X-Reboot
Resin-Trace
Sid
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-Thinkindot-L3
X-Matched-Rule
Fastly-SWR
Fastly-SIE
Heartbleed
Thinkindot-Control
X-Rebelmouse-Cache-Control
X-Sn-Servicetimems
X-Core-Mission
X-Store
X-Cdn-Origin
X-Backend-TTL
X-Rebelmouse-Surrogate-Control
X-Fetched-On
X-Alicdn-Da-Ups-Status
X-Oss-Hash-Crc64ecma
X-Ua
X-Policy
CDN
Content-Disposition
WP-Super-Cache
HTTPS
X-Pf-Uncompressing
X-Servedbyhost
X-Planisys-CDN-Rules
ProcessTime
X-Planisys-CDN-Cache
X-Cluster-Node
X-Planisys-CDN-TTL
X-Refresh
X-Ezoic-Cdn
Warning
CF-IPCountry
Xserver
RequestId
ViewerVersion
Powered
X-Proto
REQUESTUUID
X-GEO
X-B3-TraceId
X-Atg-Version
We-Hiring
Mail-Subject
X-Cache-ASPX
X-Real-Ip
X-TIME
X-Dc
X-Req
X-GoCache-CacheStatus
Cache-Cookie-Set-Idcheck
X-Datadome
Dnion-Transfer-Encoding
X-Pjax-Url
Cache-Cookie-Set-Lfrom
X-Endurance-Cache-Level
Cache-Cookie-Set-From
NODE
X-DC
X-Newrelic-Synthetics
Hostname
X-Varnish-Ttl
X-Time
NnCoection
X-Server-W
X-Page-Type
X-Surge-Debug
X-Origin-Date
X-Edge-IP
X-Origin-Expires
X-CLOUD-TRACE-CONTEXT
X-Aed
X-COUNTRY
X-GRACE
X-Varnish-HitMiss
X-HCF
Geoip-Latitude
X-Cache-Control-Set-By
GeoIp-Country-Code
X-Guploader-Uploadid
X-Nc
Pramga
X-Ms-Lease-State
X-CSRF-Token
X-Oracle-Dms-Ecid
SD-X-WS
WWW-Authenticate
Processtime
X-Server-Group
X-Varnish-Beresp-TTL
TSSecure
X-Cdn-Forward
CACHE
X-Aicache-OS
X-Varnish-Url
A
Geoip-City
X-Flog
X-ABtesting
X-Hello
PICS-Label
MS-CV
X-DataStream-MidMile-RTT
X-Amz-Cf-Pop
X-Wa
X-Varnish-URL
X-Geo
X-DataStream-Origin-MEX-Latency
X-Wix-Route-ID
X-WA
X-Ratelimit-Limit
Dont-Set-Cookie
X-Edge-Server
X-Auto-Login
X-Gdpr
X-Akamai-Request-ID2
Cdn-Request-Time
Cdn
X-From-Cache
Node
Cdn-Host
Lfy
FSS-Proxy
FSS-Cache
Lb
X-Use-Magma
DataCenter
Mime-Version
X-UPSTREAM-Address
GeoIP-Latitude
X-EC-Security-Audit
X-Gen-Id
GeoIP-Country-Code
X-Sentry-ID
COMMERCE-SERVER-SOFTWARE
X-APP
X-Nananana
Ms-Operation-Id
X-RTag
X-WR-MODIFICATION
X-PAGE-TYPE
X-Optimization
X-Via-NSCOPI
X-Env
Rt-Proxy-Cache
GeoIP-City
X-Cache-HT
Get-Access-Time
X-Check-Cacheable
PageType
Is-Session-Tracking
X-Fastly-Backend-Reqs
X-SRV
X-Load-Cache
X-CACHE-KEY
Who
X-Cache-Id
X-Served-From
X-Cookie
X-Unique-Id
X-Cache-FS-Status
X-Proxy-Server
X-Wix-Petri-Ex
X-Cache-Info
X-GDPR
Memcached
X-Bip
X-Thanos
X-Dynatrace-Js-Agent
X-Meta-Tbi-Cache-Vertical
X-MP-GENERATED-AT
Ws
X-Ver
X-Ibm-Trace
X-FORWARDED-FOR
X-Cache-Ttl
X-Request-Start
X-Be
Pics-Label
Httpd-Identifier
Memory
X-Swift-Error
X-PJAX-URL
X-NGINX-Cache
X-B3-SpanId
X-SVT-ORM-RULES
X-HS-Status
Powered-By
X-SVT-ORM-VERSION
X-Fe
Ohc-File-Size
X-RateLimit-Reset
V-Cache
Group
X-Fastly-Cache-Hits
X-Path-Route
X-CDN-Pop-IP
X-CDN-Pop
Cf-Ipcountry
Requestid
X-Shard
X-Dw-Trace-Id
GW-Server
X-ServedByHost
URI
Version
UCS
X-ID
Amp-Access-Control-Allow-Source-Origin
X-User
Xet-Cookie
X-GZIP
NX-Cache
X-P-T
X-VC
X-SB
AGE-Hash
X-Bug-Bounty
X-PF-Uncompressing
X-LiteSpeed-Cache-Control
Serverid
X-Varnish-Info
Cache-Hits
X-Akamai-ERRuleID
X-Akamai-ERPolicy
X-StackifyID
X-CacheKey
X-Ratelimit-Remaining
Ohc-Response-Time
Apicache-Store
Apicache-Version
Fastly-Soc-X-Request-Id
CDN-Cache
N-Cache
CDN-Node
Https
CDN-Cache-Hit
If-Modified-Since
X-Micro-Cache
X-Route-Name
X-ServerName
X-Providence-Cookie
X-Goog-Meta-Goog-Reserved-File-Mtime
X-BE
X-Info
X-Grace-Duration
X-RequestId
X-Cache-Handler
X-SD-PageType
X-Litespeed-Cache-Control
X-Flags
X-Is-Crawler