Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
CF-RAY
CF-Cache-Status
Link
X-XSS-Protection
X-Powered-By
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Alt-Svc
Access-Control-Allow-Credentials
X-Runtime
X-FRAME-OPTIONS
X-Drupal-Cache
X-Adblock-Key
X-Check
Content-Security-Policy-Report-Only
X-Xss-Protection
X-Generator
X-Cacheable
X-Cache-Status
X-Permitted-Cross-Domain-Policies
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Template
X-Language
X-Iinfo
X-Content-Security-Policy
Status
Content-Encoding
X-AspNetMvc-Version
X-Buckets
X-Request-ID
X-Kinja-Server-Push
Upgrade
Xkey
X-Via
Access-Control-Expose-Headers
X-Turbo-Charged-By
Access-Control-Max-Age
Keep-Alive
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Pass-Why
EagleId
X-Age
X-Backend
X-Envoy-Upstream-Service-Time
X-Robots-Tag
X-Amz-Request-Id
X-Amz-Id-2
X-Page-Speed
X-CDN
X-Pingback
X-Server-Powered-By
X-Server
X-AH-Environment
X-UA-Device
X-Proxy-Cache
X-Hacker
Request-Context
X-Swift-CacheTime
X-Swift-SaveTime
X-Nginx-Cache-Status
Grace
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-Cdn
P3p
X-LiteSpeed-Cache
Cf-Railgun
Server-Timing
X-Ua-Compatible
Feature-Policy
X-Amz-Version-Id
X-Device
X-WebKit-CSP
X-Server-Id
X-OneAgent-JS-Injection
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Rq
X-Ac
EagleEye-TraceId
X-Cnection
Report-To
X-Cloud-Trace-Context
Request-Id
X-Backend-Server
X-Response-Time
X-Node
Content-Location
X-Host
X-Readtime
X-Origin-Cache
X-Vhost
X-Cache-Lookup
X-Application-Context
X-DataDome
X-ORACLE-DMS-ECID
X-Dispatcher
NEL
X-ORACLE-DMS-RID
X-Ruxit-JS-Agent
X-Rack-Cache
X-Origin-Upstream-Status
X-HW
X-Dns-Prefetch-Control
Surrogate-Control
X-Clacks-Overhead
Rating
X-Country-Code
Allow
X-Country
X-FTR-Request-ID
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-DynaTrace
X-Url
X-MS-InvokeApp
X-Goog-Hash
X-Instart-Request-ID
Fusion-Content-Id
Fusion-Template-Id
Fusion-Content-Source
Fusion-Component-Id
Fusion-Source
X-TTL
X-Vname
X-PC
X-TtlSet
X-Varnish-TTL
X-B3-TraceId
Pinterest-Generated-By
Verso
X-Powered-By-Plesk
X-Px
Public-Key-Pins
RTSS
Edge-Control
X-ESI
X-Mod-Pagespeed
X-Ah-Environment
SPRequestGuid
Display
X-Sol
X-Middleton-Display
Response
X-Middleton-Response
X-VARITI-CCR
X-Akam-SW-Version
X-SharePointHealthScore
X-Kinja-Server
X-GoogleNews-Bot
X-Kinja
X-Kinja-Build
X-Kinja-Revision
X-Exp-Variant
X-Use-Magma
X-Exp-Id
X-Cdn-Fetch
X-D2id
Accept-Ch-Lifetime
X-Recruiting
Service-Worker-Allowed
SPRequestDuration
SPIisLatency
X-Vcap-Request-Id
X-CST
X-Server-Name
X-Version
X-GitHub-Request-Id
X-Powered-CMS
MS-Author-Via
TCN
X-Navigation-Version
X-Abt-Application-Version
X-Trace
Charset
X-Debug
X-Shard
X-Amz-Server-Side-Encryption
Fastly-Restarts
X-Amz-Rid
X-Aspnetmvc-Version
Realpath
Nginx-Cache
X-Upstream
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
Accept-CH
AR-ATIME
AR-PoweredBy
AR-CACHE
Ar-Sid
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-NF-Request-ID
X-Forwarded-Proto
X-RateLimit-Remaining
X-Ezoic-Cdn
Front-End-Https
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-MSEdge-Ref
Access-Control-Request-Method
DynaTrace
X-Cached
Arr-Disable-Session-Affinity
Content-MD5
Pagespeed
X-Shield-Request-Id
AR-Request-ID
Mrf-Cache-Status
X-Mrf-Section-Lastmod
MRF-Tech
X-Mrf-Item-Lastmod
X-B3-TraceId-Primal
MicrosoftSharePointTeamServices
X-VCache
X-FTR-Cache-Status
X-Country-Code-Real
X-FTR-Expires
X-XRDS-Location
X-Amz-Meta-S3cmd-Attrs
S
X-Goog-Storage-Class
X-DynaTrace-JS-Agent
X-Ser
X-Fastly-Request-ID
X-T
X-Id
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Realm
X-FTR-DC
X-FTR-Balancer
X-Varnish-Age
Paypal-Debug-Id
Accept-Ch
X-Server-ID
ServerID
X-Via-JSL
X-Accel-Expires
X-Content-Type
X-Client-IP
X-Dw-Request-Base-Id
X-Forwarded-For
Edge-Cache-Tag
X-Grace
Fastcgi-Cache
X-Amzn-Trace-Id
X-Hits
X-Frontend
X-Fastcgi-Cache
X-Content-Digest
X-Correlation-Id
X-DIS-Request-ID
Powered
X-N
Pinterest-Version
X-Pinterest-Rid
X-HS-Content-Id
X-HS-Hub-Id
PB-RID
PB-PID
X-Mobile-Rewrite
Arc-Version
X-FTR-Cache-Host
AMP-Access-Control-Allow-Source-Origin
X-Logged-In
Server-Name
X-Vcache
TP-L2-Cache
TP-Cache
X-Kinsta-Cache
X-Request-Received
X-Request-Processing-Time
X-Cache-Hit
X-FastCGI-Cache
X-Microsite
X-Request-Handler-Origin-Region
X-Zen-Fury
X-AppVersion
X-Az
X-Time
X-Activity-Id
X-Revision
X-User-Agent
X-LB-Cache
X-IPLB-Instance
X-Rid
X-Cache-Age
X-Type
Healthy
Retry-After
X-Whom
X-Srv
X-Analytics
Backend-Timing
X-Node-Name
X-B3-Sampled
X-GUploader-UploadID
Server-Node
FilterID
X-RateLimit-Limit
X-NWS-LOG-UUID
X-Hp-Webp
Cache-Tag
Alternate-Protocol
Accept-Charset
X-F-Cache
X-SERVER
NR-ENABLED
X-Content-Security-Policy-Report-Only
X-Akamai-Edgescape
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Webkit-CSP
X-Cache-Rule
X-Content-Options
Cache-Status
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Content-Powered-By
DC
VIX-Pulpo-Node
MS-CV
VIX-Pulpo-Upstream-Status
X-Cluster
X-Framework
X-AOL-HN
Refresh
Access-Control-Allow-Method
X-Instance
X-FB-Debug
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel
X-Varnish-Grace
Source
X-Cache-2
X-Kong-Upstream-Latency
Tracecode
X-Debug-Info
X-App-Environment
X-Kong-Proxy-Latency
X-Jobs
X-PHP-Backend
X-Page-Id
X-B
Actual-Object-TTL
X-Forwarded-Host
X-Request-Guid
X-Cache-TTL
X-Seen-By
Surrogate-Key
X-Mobile-URL
Host
Frame-Options
X-Cache-Operation
X-App-Server
X-Geo-Country
Fastcgi-Useragent
X-FW-Serve
X-FW-Hash
X-FW-Static
X-FW-Server
X-FW-Type
X-Cache-Control
X-TA-CDN-Provider
X-Cached-By
X-Host-Name
X-Pad
X-Hostname
Cleartype
X-Element-Page-Cache
X-Cache-Key
X-Signature
X-B-Cache
Upgrade-Insecure-Requests
X-WebKit-CSP-Report-Only
X-Git-Hash
X-Mobile
X-ATG-Version
X-BCube-Filmed-By
NGB
X-Varnish-Backend
X-Response-Served-From
X-HS-Cache-Config
Xserver
X-UA-Device-Type
X-RTag
Ms-Operation-Id
WPE-Backend
X-GeoIP
X-Daa-Tunnel
X-ProcessESI
X-RemovedCookies
X-Tumblr-Pixel-1
X-Amz-Replication-Status
X-Origin-Server
Cache-Tv-Group
X-Tumblr-Pixel-2
Filters
Eomportal-Instance
X-EdgeConnect-Cache-Status
Webserver
X-Handled-By
X-TT
X-Drupal-Cache-Tags
X-Cacheable-TTL
X-TX-ID
X-Adobe-Loc
From-Origin
X-Adobe-Content
GEO-INFO
Payment
X-RequestSource
X-TT-TIMESTAMP
Cache
X-Cache-TTL-Remaining
X-Wix-Request-Id
X-XRDS-LOCATION
X-Cache-Remote
Datacenter
X-Status
X-Esi
X-WA-Info
X-FW-Dynamic
Liferay-Portal
X-Hyper-Cache
X-Presslabs-Stats
X-Contextid
X-Region
Version
X-Edge-Location
X-Ratelimit-Reset
X-Cache-Action
X-Ttl
X-Acc-Meta-Resource-Type
X-Content-Age
Viewport
X-Cache-NE
X-CF-Powered-By
X-B3-Traceid
X-Akamai-Transformed
X-HS-Combine-CSS
X-Storage
X-PressLabs-Stats
PageSpeed
X-Varnish-Hostname
X-Cache-Server
Accept-CH-Lifetime
X-Varnish-Server
X-ES-SERVER
X-Path-Route
X-Cache-Var-Map
Load-Balancing
X-RN-RSRV
Meta-Geo
X-Cache-Var
Host-Header
X-IP
X-Cache-Grace
X-Viewer-Country
X-Cache-Enabled
X-CCM
Ohc-File-Size
X-Accel-Buffering
X-Xfnlog-Site
X-Cache-Config
Cache-Tags
X-Via-Fastly
Country
X-Proxy
X-Cache-Time
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Cache-Host
X-PCL
X-Device-Type
X-Labrador-Cache-Channel
X-Akamai-Request-ID2
X-Proto
Vix-Hermes-Req-Id
Cache-Hits
X-Loop
Cache-Name
X-UnsetCookies
X-TNCMS
DB-Nickname
X-OCL
Release
X-Debug-Cache
X-NCache
Rt-Fastcgi-Cache
X-From
Ec-Rule-Version
DSUID
X-Varnish-Hits
X-Varnish-Cache-Hits
S-Rt
X-Proxy-Build
Property-Id
Decoy-Debug-TTL
Decoy-Debug-Status
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Hosted-By
X-Human
X-Www-Served-By
X-Web-Node
Decoy-Debug-Key
X-EIG-Tracking-Id
Selected-Fe
TWC-Connection-Speed
X-Backend-TTL
X-Backend-Name
X-Tumblr-Pixel-3
X-Trace-Id
X-FC-Vary-Parameters
X-CS
X-Time-Microsecs
X-Timing-Wait
X-Upgrade-Enabled
Webcakes-Region
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Device-Class
TWC-Locale-Group
TWC-Privacy
Webcakes-App-Version
Webcakes-App-Name
X-JoinUs
X-Vgn-Hpd-Reason
X-Origin-Hint
X-Rule
X-R9-Blue-Green-Version
X-NewRelic-App-Data
X-Origin
S-Cnection
X-Generated
X-Locale
X-FireWall-Port
X-Origin-Response-Time
Mn-Server-Ip
X-VCT
Cache-Key
X-ApacheServer
X-Cluster-Node
X-Akamai-Request-ID
Azure-RegionName
X-PERF
X-Site-Version
X-Drupal-Cache-Contexts
Azure-SiteName
Azure-InstanceId
Azure-Version
Azure-SlotName
X-OVcl-Cache
X-Real-IP
X-OVcl
X-Section
X-Access
X-Ua
X-Pubstack
X-Hit
X-Rendered-As
Origin-Edge-Control
Origin-Cache-Control
X-Format
X-S
Time
X-Trafficlayer-App-Scope
Server-Info
X-Trafficlayer-App-Name
Ohc-Cache-HIT
L5d-Success-Class
X-Redis-Cache
X-NGENIX-Cache
X-Origin-CC
X-Litespeed-Cache
Now
X-Origin-TTL
X-FW-Version
Fastcgi-X-Cache-Version
X-SS-Set-Cookie
OT-Force-Account-Verify
Fastly-SSL
ServedBy
X-Upstream-HT
X-Cluster-Name
X-ServerID
X-Upstream-CT
Hostname
Origin
X-ShardId
X-Sorting-Hat-ShopId
X-ShopId
X-UUID
Access-Control-Request-Headers
X-Sorting-Hat-PodId
X-Shopify-Stage
X-APP-VERSION
X-App-Version
X-Alternate-Cache-Key
X-Guploader-Uploadid
X-Load-Cache
Mime-Version
Cteonnt-Length
X-FB-TRIP-ID
X-Rocket-Nginx-Bypass
X-Soup
X-GoCache-CacheStatus
X-Webkit-Csp
X-Parent-Response-Time
X-CACHE-KEY
X-VG-WebCache
NtCoent-Length
Accept-Language
X-VG-TLSProxy
NGX
X-Is-Bot
Odigeo-Trace-Id
Machine
X-Uri
X-Upstream-Proxy
X-Info
Nel
IBM-Web2-Location
X-B3-SpanId
X-CSRF-TOKEN
X-ProxyCache-Key
X-BYPASS-REASON
X-ProxyCache-Status
X-No-Session
X-ECACHE
X-L-Path
X-MServer
X-Environment-Context
X-Node-Id
X-Tb
X-Nc
X-Cdn-Forward
X-UA
Srv
X-Tt-Trace-Tag
X-Oneagent-Js-Injection
X-Instart-Info
X-Destination
X-Application
X-ARC
X-AIR-PT
Rendered-Blocks
Request-Country
X-B-Cookie
Node
MD5-Digest
X-CF-Lambda-Fn
Memcached
Meta-Geo-Continent
Mobile-Detection-Method
Request-EU
X-Aed
VivaBuild
X-A
ServerName
Viewtype
T-Server
X-A-Ccd
X-A-Dam
X-A-Wwc
X-Accel-Expires-Debug
X-A-Dgt
Rt-Proxy-Cache
X-A-Dcw
X-CF-Lambda-Version
X-Cms-Context
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Arc-Country
AsisCache
BehaviorPad-Version
Apple-News-Services-Host
Apple-News-Services-Handled
X-PHP-Host
Uber-Trace-Id
X-G
A
X-External-Request-Id
X-DPWN-IS-SECURE
Cache-Prefix
Fly-Cache
X-D
Fly-Request-Id
GEO-REGION-INFO
X-Connection-Hash
X-Date
Cross-Origin-Window-Policy
X-Developer
X-Detected-As
Content-Script-Type
Content-Style-Type
X-Hl-Ver
X-PAYTM-SRV-ID
X-Request-UUID
X-Vtex-Remote-Cache
X-SRCache-Key
X-Tec-Api-Origin
X-Rojux
X-Vtex-Processado-Em
X-VG-WebServer
X-Server-Time
X-Region-Sid
X-Twitter-Response-Tags
X-ScT
X-Trv-Group
X-Tec-Api-Root
X-Rewrite-Enabled
X-Transaction
X-B3-Parentspanid
Request-Time
Xc-Version
X-Geo
X-S-Cookie
X-Tec-Api-Version
Proxy-Connection
User-Cache-Control
Backend-Name
X-Endurance-Cache-Level
X-Clara-WADP
X-Debug-Log
X-Generated-By
X-Block-Status
N-Cache
X-S-Maxage
X-Has-Esi
X-ElasticPress-Search
X-Request-URI
X-Cache-Bucket
X-Gen-Mode
IsBot
X-WADP-Cache
X-Debug-Cookies
X-Cdn-Srv
X-SIPLIST1
X-Sn-Servicetimems
X-Amzn-Remapped-Content-Length
X-SVT-ORM-RULES
X-JWT-State
X-Is-Gdpr
X-Hnp-Log
X-Worker
X-Device-Os
X-Cache-Info
X-SVT-ORM-VERSION
X-NX-Host
X-Cdn-Origin
X-Proxy-Cache-Status
X-Proxy-Upstream
Mail-Subject
CF-IPCountry
We-Hiring
X-Via-CDN
X-Nginx-Cache
X-Thanos
X-Cache-Id
X-Cache-FS-Status
X-Swa-Ws
X-Backend-Host
X-We-Are-Hiring
X-VServer
X-VC-Cache
X-Variation
X-WebServer
Web-Mar-Node
Thinkindot-Control
X-Svr
X-Webstats-RespID
X-Var-Ttl
X-User
X-Backend-Url
X-BBXSRF
X-TrackingId
X-Bip
X-Auto-Login
X-Up
X-Urbn-Site-Id
X-Urbn-Context-Path
X-Amz-Meta-Cache-Control
X-Thinkindot-L3
X-Say-TTL
X-IN-APIGATEWAY
X-Policy
X-Platform-Server
Thinkindot-CacheControl-Type
X-Hash
X-RateLimit-Limit-Second
X-GeoIP-City
X-Release
X-Reboot
X-RateLimit-Remaining-Second
X-IN-APIGATEWAYSSL
X-Owner
X-Li-Fabric
X-Li-Pop
X-LI-UUID
X-Magnolia-Registration
X-Level-Front-Cache
X-Matched-Rule
X-Origin-Expires
X-Origin-Date
X-Irp-Debug
X-Old-Content-Length
X-Geo-Header
X-Generation-Time
X-Service
X-Server-IP
X-SayCDN-TTL
X-Location
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Compress-Hint
X-CUA
X-Skip-Cache
X-Debug-Cache-Expiry
X-Developers
X-Dispatch
X-Request-Start
X-Reqid
X-Generated-In
X-Generated-On
X-Fetched-On
X-Fastly-Cache
X-Say-Cacheable
X-Dispatcher-Server
X-Distributor
X-Clientip
True-Client-Country-4JS
Pagetype
Content-Disposition
X-NC
Countrycode
Platform
Pramga
Adler-Geo
AKAMAI
Locale
Gh-Request-Id
Fastly-Soc-X-Request-Id
Heartbleed
Is-Eu
Thinkindot-CacheControl
Kp-EeAlive
RNT-Machine
PFcat
X-Dc
Section-Io-Cache
Served-By
CDCHOST
RNT-Time
Server-Int
Server-Host
X-NWS-UUID-VERIFY
X-Ruxit-Js-Agent
HA-Ipaddr
X-Instart-Isnd
X-SD-PageType
X-Cache-URL
X-Eu-Site
V-Age
X-CGP
Akamai-GRN
Fastly-SIE
X-Rebelmouse-Cache-Control
Esi-Enabled
Fastly-SWR
X-Rebelmouse-Surrogate-Control
X-Epic-Correlation-Id
X-Qloud-Router
X-Core-Mission
Ha-Gx-Prefs
X-Distil-CS
SD-X-WS
X-LI-Proto
X-Method
X-B3-Spanid
X-Wikidot-Backend
X-Wikidot-Static-Cache
Resin-Trace
X-Lb-Id
X-Azure-Ref
X-Azure-Ref-OriginShield
Magicmarker
X-C
X-ServiceProvider
X-Key
Wxu-Next-Commit
Wxu-Next-Region
X-Nginx-Cache-Key
Wxu-Next-Hostname
L
SRV
X-Microcachable
X-Cache-Backend
X-Internal-Host
X-MSEdge-Features
Cache-Provider
X-MSEdge-Flight
X-Servername
X-App-Name
Server-ID
W
X-Scheme
Memory
X-Backend-State
X-GEO
X-Processor
X-Ratelimit-Limit
X-URL
X-Be
Cdn-Request-Time
Cdn-Host
X-Edge-Server
REQUESTUUID
X-FPC
Group
X-DC
X-VWS-Id
X-LJ-Flow-ID
X-AWS-Id
X-Pjax-Url
X-GDPR
X-NodeID
Cache-Host
X-Flog
X-Org
X-Hello
X-Mode
X-Servedbyhost
X-ABtesting
X-Wa
X-Request-Time
X-Datadome
SS
X-Server-W
X-Unique-ID
X-Response-By
X-Ms-Request-Id
X-GRACE
X-Ms-Version
X-IPS-LoggedIn
Country-Code
X-Oss-Request-Id
X-Oss-Storage-Class
X-Page-Type
X-SN
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Status
X-Oss-Object-Type
X-Varnish-Beresp-Grace
X-Webapp-Samesite-None-Activated-N
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-Ratelimit-Remaining
X-VCL-Version
X-Oracle-Dms-Rid
X-Session-Fingerprint
Lfy
Cache-Cookie-Set-From
Cache-Cookie-Set-Lfrom
X-Via-Ucdn
Cache-Cookie-Set-Idcheck
X-Zone
X-CDN-Forward
X-EC-Lua
X-Ftr-Request-Id
X-SRV
X-Cache-Debug
X-Dynatrace
X-COUNTRY
X-Tb-Optimization-Total-Bytes-Saved
X-Agile
UCS
X-HS-Status
PICS-Label
X-Routing-Service
X-Proxied
X-Zipkin-Id
X-Agile-Id
X-Agile-Age
X-7Graus-Varnish-Cache-Control
X-7Graus-Varnish-XKeys
Ttl
SN
Powered-By-ChinaCache
GeoIP-Latitude
X-Pf-Uncompressing
X-Logging-Id
GeoIP-City
GeoIP-Country-Code
X-Fastly-Country-Code
GeoIp-Country-Code
Ajk
Geoip-City
Proxy-Firewall
Environment
X-PF-Uncompressing
X-Cache-Miss-From
X-Sedo-Request-Id
Geoip-Latitude
X-Logtrace-Id
X-Sucuri-Id
X-Source
X-Varnish-Beresp-TTL
X-Newrelic-Synthetics
X-CSRF-Token
X-MP-GENERATED-AT
X-Bc
X-Sucuri-ID
XServer
X-ZONE
Powered-By
X-Grey
X-APP
Cdn
ProcessTime
X-Unique-Id
X-Cache-Category-Id
X-Ftr-Cache-Host
X-CLOUD-TRACE-CONTEXT
X-RateLimit-Reset
X-Vcl-Version
X-Tt-Trace-Host
Pics-Label
M-TraceId
X-HTML-Minification-Powered-By
X-Core-Value
Cf-Ipcountry
X-LiteSpeed-Cache-Control
Amp-Access-Control-Allow-Source-Origin
X-TH-Server
X-Edge
Fastly-Backend-Name
X-Aicache-OS
X-Check-Cacheable
CF-Cached-On
X-Vdms-Version
Cdnsip
Cdncip
X-AK-Request-ID
WWW
X-Sucuri-Cache
X-DataStream-Cache-Status
X-Ftr-Dc
X-Ftr-Balancer
X-Dynatrace-Js-Agent
X-Ftr-Realm
X-Ftr-Backend-Server
X-Ftr-Backend
X-Mid
X-Sigma
X-Rocket-Build-Number
Requestid
X-Sigma-Backend
CACHE
X-Planisys-CDN-Cache
X-Fstrz
X-Planisys-CDN-Rules
X-Shopify-Generated-Cart-Token
X-Planisys-CDN-TTL
Pragrma
X-Correlation-ID
MIME-Version
X-Via-NSCOPI
X-ServedByHost
HostName
GW-Server
X-MCACHE
X-RCS-CacheZone
X-Swift-Error
X-LAGOON
X-Fastly-Backend-Reqs
X-FORWARDED-FOR
X-Cache-Tag
X-Varnish-Ttl
TTL
X-NGINX-Cache
X-TT-LOGID
X-SaId
X-Gannett-Site-Version
X-Secret
X-WA
LB
X-ORACLE-APMCS-REQUEST-ID
X-ORACLE-APMCS-TAG
X-UPSTREAM-Address
Lb
X-DSS
X-ND-Cache
X-DI
X-BE
X-BC
X-Action
X-DB
X-PJAX-URL
X-Litespeed-Cache-Control
X-Cache-Ttl
X-RSL
Ohc-Response-Time
X-Varnish-Url
X-DataStream-MidMile-RTT
X-DW
URI
X-DataStream-Origin-MEX-Latency
X-RPM
X-RPS
Dynatrace
X-Upstream-Ht
X-Upstream-Ct
X-Trafficlayer-App-Version
X-Refresh
Host-ID
On-Server
X-Fpc
X-CDN-Cache
X-Varnish-Cacheable
RequestUuid
DataCenter
Get-Access-Time
CDN
X-GeoIP-Country-Code
Is-Session-Tracking
X-Via-SSL
X-Via-Edge
X-WR-MODIFICATION
X-Fastly-Cache-Hits
X-Served-From
Server-Id
Xkeyrz
X-Zalando-Child-Request-Id
X-Proxy-Cacherz
Xkeypdq
X-Page-Impression-Id
X-Flow-Id
User-Agent
WZWS-RAY
X-MID
Inserted-Into-Cache-At
Locid
Gannett-Cam-Experience-Id
X-Req
X-Dw-Trace-Id
X-VC
X-SB
Warning
X-Pod
X-Nananana
Correlation-Id
X-Gamma-Serve
X-Cf-Powered-By
X-Amzn-Remapped-Connection
X-Akamai-ERRuleID
X-App
FNAC-ModuleRouting
X-Li-Proto
Thinkindot-Cache-Type
X-Amzn-Remapped-Date
Processtime
X-Newrelic-App-Data
Xet-Cookie
X-MiniProfiler-Ids
Cneonction
V-Cache
X-Gdpr
X-ServerName
RequestId
X-Gen-Id
X-LiteSpeed-Tag
X-ECache
HitType
X-LB-ID
X-Bug-Bounty
X-Akamai-ERPolicy