Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
CF-RAY
CF-Cache-Status
Link
X-XSS-Protection
X-Powered-By
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Alt-Svc
Access-Control-Allow-Credentials
X-Runtime
X-FRAME-OPTIONS
X-Drupal-Cache
X-Adblock-Key
X-Check
Content-Security-Policy-Report-Only
X-Xss-Protection
X-Generator
X-Cacheable
X-Cache-Status
X-Permitted-Cross-Domain-Policies
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Template
X-Language
X-Request-ID
X-Iinfo
X-Content-Security-Policy
Status
Content-Encoding
X-AspNetMvc-Version
X-Buckets
X-Kinja-Server-Push
Xkey
Upgrade
X-Via
Access-Control-Expose-Headers
X-Turbo-Charged-By
Access-Control-Max-Age
Keep-Alive
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Pass-Why
X-Age
EagleId
X-Backend
X-Envoy-Upstream-Service-Time
X-Robots-Tag
X-CDN
X-Amz-Request-Id
X-Amz-Id-2
X-Page-Speed
X-Pingback
X-Server-Powered-By
X-AH-Environment
X-Server
X-UA-Device
X-Proxy-Cache
X-Hacker
Request-Context
X-Swift-SaveTime
X-Swift-CacheTime
X-Nginx-Cache-Status
Grace
Ali-Swift-Global-Savetime
X-Varnish-Cache
X-Cdn
X-LiteSpeed-Cache
P3p
Cf-Railgun
Server-Timing
Feature-Policy
X-Amz-Version-Id
X-Ua-Compatible
X-Device
X-Server-Id
X-WebKit-CSP
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
X-Rq
X-Ac
EagleEye-TraceId
X-Cnection
Report-To
Request-Id
X-Cloud-Trace-Context
X-Response-Time
X-Backend-Server
X-Node
Content-Location
X-Host
X-Readtime
X-Origin-Cache
X-Vhost
X-Cache-Lookup
X-Application-Context
X-DataDome
X-ORACLE-DMS-ECID
X-Dispatcher
NEL
X-ORACLE-DMS-RID
X-Ruxit-JS-Agent
X-Rack-Cache
X-HW
X-Origin-Upstream-Status
Surrogate-Control
X-Clacks-Overhead
Rating
X-Country-Code
Allow
X-Dns-Prefetch-Control
X-Country
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-FTR-Request-ID
X-Url
X-DynaTrace
X-MS-InvokeApp
X-Goog-Hash
Fusion-Template-Id
Fusion-Content-Source
Fusion-Source
Fusion-Component-Id
Fusion-Content-Id
X-Instart-Request-ID
X-TTL
X-Vname
X-PC
X-TtlSet
X-Varnish-TTL
Pinterest-Generated-By
X-B3-TraceId
Verso
X-Powered-By-Plesk
X-Px
Public-Key-Pins
RTSS
Edge-Control
X-Mod-Pagespeed
SPRequestGuid
Display
X-Middleton-Response
X-Sol
Response
X-Middleton-Display
X-Akam-SW-Version
X-VARITI-CCR
X-SharePointHealthScore
X-D2id
X-Cdn-Fetch
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Kinja
X-Kinja-Build
X-Exp-Id
X-Exp-Variant
X-GoogleNews-Bot
X-ESI
X-Recruiting
X-Ah-Environment
Service-Worker-Allowed
SPRequestDuration
SPIisLatency
Accept-Ch-Lifetime
X-Vcap-Request-Id
X-CST
X-Server-Name
X-GitHub-Request-Id
X-Powered-CMS
X-Version
MS-Author-Via
X-Navigation-Version
X-Abt-Application-Version
X-Trace
TCN
Charset
X-Debug
X-Amz-Server-Side-Encryption
X-Shard
Accept-CH
Fastly-Restarts
X-Amz-Rid
Nginx-Cache
X-Upstream
Realpath
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Aspnetmvc-Version
AR-CACHE
AR-PoweredBy
AR-ATIME
Ar-Sid
X-NF-Request-ID
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Forwarded-Proto
X-Ezoic-Cdn
Front-End-Https
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-RateLimit-Remaining
X-MSEdge-Ref
DynaTrace
Access-Control-Request-Method
X-Cached
Arr-Disable-Session-Affinity
Content-MD5
Pagespeed
X-Shield-Request-Id
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
MicrosoftSharePointTeamServices
AR-Request-ID
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Expires
X-DynaTrace-JS-Agent
X-Amz-Meta-S3cmd-Attrs
S
X-Goog-Storage-Class
X-Fastly-Request-ID
X-Ser
X-T
X-XRDS-Location
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Backend
X-FTR-DC
X-FTR-Realm
X-Varnish-Age
X-VCache
Paypal-Debug-Id
X-Id
ServerID
X-Via-JSL
X-Grace
Accept-Ch
X-Accel-Expires
X-Correlation-Id
X-Client-IP
X-Vcache
X-Fastcgi-Cache
Edge-Cache-Tag
X-Content-Type
X-Dw-Request-Base-Id
X-Amzn-Trace-Id
Fastcgi-Cache
X-Hits
X-Frontend
X-DIS-Request-ID
X-Content-Digest
X-Forwarded-For
Powered
X-Pinterest-Rid
Pinterest-Version
X-N
X-HS-Content-Id
X-HS-Hub-Id
PB-PID
PB-RID
X-Mobile-Rewrite
Arc-Version
X-FTR-Cache-Host
AMP-Access-Control-Allow-Source-Origin
X-Logged-In
Server-Name
TP-L2-Cache
TP-Cache
X-Request-Processing-Time
X-Kinsta-Cache
X-Request-Received
X-Cache-Hit
X-Request-Handler-Origin-Region
X-Microsite
X-Server-ID
X-Zen-Fury
X-Az
X-AppVersion
X-Activity-Id
X-Rid
X-User-Agent
X-Revision
X-LB-Cache
X-Cache-Age
X-IPLB-Instance
Healthy
X-Type
X-FastCGI-Cache
Retry-After
X-Whom
X-GUploader-UploadID
Server-Node
X-Analytics
Backend-Timing
X-Node-Name
X-B3-Sampled
X-Time
FilterID
X-Srv
X-NWS-LOG-UUID
Cache-Tag
X-Hp-Webp
X-RateLimit-Limit
Alternate-Protocol
NR-ENABLED
X-F-Cache
Accept-Charset
X-Akamai-Edgescape
X-Content-Security-Policy-Report-Only
X-SERVER
X-Content-Options
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
Cache-Status
X-Cache-Rule
DC
X-Content-Powered-By
X-Amz-Apigw-Id
MS-CV
VIX-Pulpo-Upstream-Status
X-Amzn-RequestId
VIX-Pulpo-Node
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-User
X-AOL-HN
X-Cluster
Refresh
Access-Control-Allow-Method
X-FB-Debug
X-Instance
X-Framework
X-App-Environment
X-Debug-Info
X-Jobs
X-Varnish-Grace
Source
X-Webkit-CSP
X-Cache-2
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Tracecode
X-Page-Id
X-B
X-PHP-Backend
Actual-Object-TTL
X-Forwarded-Host
X-Seen-By
X-Request-Guid
X-Mobile-URL
Fastcgi-Useragent
Surrogate-Key
X-Cache-TTL
Host
Frame-Options
X-Cache-Operation
X-App-Server
X-Cache-Key
X-Geo-Country
X-Cache-Control
X-Cached-By
X-FW-Server
X-FW-Type
X-FW-Serve
X-FW-Hash
X-FW-Static
X-Element-Page-Cache
X-Host-Name
X-Pad
X-TA-CDN-Provider
Cleartype
X-Hostname
X-B-Cache
X-Signature
Upgrade-Insecure-Requests
X-WebKit-CSP-Report-Only
X-HS-Cache-Config
X-Git-Hash
X-Mobile
X-ATG-Version
X-Varnish-Backend
X-Response-Served-From
NGB
X-Esi
Xserver
X-BCube-Filmed-By
X-Daa-Tunnel
X-UA-Device-Type
X-XRDS-LOCATION
X-TT
X-GeoIP
X-RTag
Ms-Operation-Id
X-ProcessESI
X-RemovedCookies
WPE-Backend
X-Amz-Replication-Status
X-Origin-Server
Cache-Tv-Group
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
Webserver
Filters
X-Handled-By
Eomportal-Instance
X-Adobe-Content
GEO-INFO
X-TX-ID
X-EdgeConnect-Cache-Status
From-Origin
X-Drupal-Cache-Tags
X-Cacheable-TTL
X-Adobe-Loc
X-RequestSource
Payment
Cache
X-Wix-Request-Id
X-TT-TIMESTAMP
X-B3-Traceid
Datacenter
X-Cache-TTL-Remaining
X-Status
X-Cache-Remote
X-WA-Info
X-Hyper-Cache
X-FW-Dynamic
Liferay-Portal
Accept-CH-Lifetime
X-Contextid
X-Webkit-Csp
X-Region
X-Cache-Action
Version
X-Presslabs-Stats
X-Edge-Location
X-HS-Combine-CSS
X-Ratelimit-Reset
X-Content-Age
Viewport
X-Akamai-Transformed
X-Cache-NE
X-PressLabs-Stats
X-Ttl
X-Acc-Meta-Resource-Type
X-Varnish-Hostname
X-Storage
X-Cache-Server
X-CF-Powered-By
PageSpeed
X-Varnish-Server
X-Path-Route
X-ES-SERVER
X-Cache-Enabled
Load-Balancing
X-RN-RSRV
Host-Header
X-Cache-Var
X-Cache-Var-Map
Meta-Geo
X-Viewer-Country
X-IP
X-Cache-Grace
Cache-Tags
Country
X-CCM
X-Cache-Config
X-Proxy
X-Via-Fastly
X-Xfnlog-Site
X-Oneagent-Js-Injection
X-Akamai-Request-ID2
X-NCache
X-UnsetCookies
X-PCL
X-Proto
Vix-Hermes-Req-Id
X-Loop
Cache-Hits
Release
X-Yottaa-Metrics
X-Yottaa-Optimizations
Cache-Name
Rt-Fastcgi-Cache
X-Labrador-Cache-Channel
DB-Nickname
X-OCL
X-Cache-Time
X-Cache-Host
X-TNCMS
X-Debug-Cache
X-Accel-Buffering
X-Www-Served-By
X-Trace-Id
Webcakes-App-Name
Property-Id
S-Cnection
X-Web-Node
Selected-Fe
S-Rt
X-JoinUs
X-From
X-R9-Blue-Green-Version
X-Backend-Name
X-Hosted-By
X-Goog-Meta-Goog-Reserved-File-Mtime
Webcakes-App-Version
Webcakes-Region
Decoy-Debug-Key
Decoy-Debug-Status
X-Backend-TTL
X-CS
Ec-Rule-Version
DSUID
Decoy-Debug-TTL
X-Human
TWC-Connection-Speed
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-Device-Class
X-Origin-Hint
X-Proxy-Build
TWC-Privacy
X-Timing-Wait
X-Time-Microsecs
X-EIG-Tracking-Id
X-Upgrade-Enabled
X-Origin
X-NewRelic-App-Data
X-Varnish-Hits
X-Varnish-Cache-Hits
X-FC-Vary-Parameters
TWC-GeoIP-Country
X-Vgn-Hpd-Reason
X-Rule
Azure-Version
X-Drupal-Cache-Contexts
Cache-Key
X-PERF
X-Akamai-Request-ID
X-Generated
X-ApacheServer
X-FireWall-Port
X-Device-Type
X-VCT
X-Locale
X-Site-Version
X-Origin-Response-Time
X-Tumblr-Pixel-3
Azure-SlotName
Mn-Server-Ip
Ohc-File-Size
Azure-InstanceId
Azure-SiteName
Azure-RegionName
X-Real-IP
X-Section
X-Pubstack
X-Hit
X-Access
X-Cluster-Node
X-OVcl
X-Format
X-OVcl-Cache
Origin-Cache-Control
Origin-Edge-Control
X-Rendered-As
Server-Info
X-Trafficlayer-App-Name
L5d-Success-Class
X-Trafficlayer-App-Scope
X-Redis-Cache
X-S
X-Ua
Time
X-Origin-CC
Ohc-Cache-HIT
X-Origin-TTL
X-FW-Version
Now
X-NGENIX-Cache
Fastly-SSL
Fastcgi-X-Cache-Version
OT-Force-Account-Verify
X-SS-Set-Cookie
X-Litespeed-Cache
ServedBy
X-APP-VERSION
X-Cluster-Name
Origin
Hostname
X-ServerID
X-Load-Cache
X-Alternate-Cache-Key
X-Sorting-Hat-ShopId
Access-Control-Request-Headers
X-Upstream-CT
X-UUID
X-Upstream-HT
X-Shopify-Stage
X-ShopId
X-ShardId
Cteonnt-Length
X-Soup
X-GoCache-CacheStatus
X-Rocket-Nginx-Bypass
X-Sorting-Hat-PodId
X-FB-TRIP-ID
Mime-Version
X-Parent-Response-Time
X-Guploader-Uploadid
NtCoent-Length
X-App-Version
X-VG-WebCache
X-Is-Bot
NGX
Accept-Language
Odigeo-Trace-Id
X-VG-TLSProxy
X-Info
Machine
X-Uri
X-Geo
IBM-Web2-Location
X-UA
Nel
X-Upstream-Proxy
X-ProxyCache-Key
X-ProxyCache-Status
X-BYPASS-REASON
X-No-Session
X-ECACHE
X-Node-Id
X-MServer
X-Environment-Context
X-L-Path
Srv
X-Tb
X-B3-SpanId
Uber-Trace-Id
X-PHP-Host
ServerName
Proxy-Connection
X-CACHE-KEY
X-CSRF-TOKEN
X-Request-UUID
X-Aed
X-AIR-PT
X-Application
X-B-Cookie
X-ARC
X-Accel-Expires-Debug
X-A-Wwc
X-A-Ccd
X-A
X-A-Dam
X-A-Dcw
X-A-Dgt
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-G
X-External-Request-Id
X-Hl-Ver
X-Instart-Info
X-Region-Sid
X-PAYTM-SRV-ID
X-DPWN-IS-SECURE
X-Developer
X-Connection-Hash
X-Cms-Context
X-D
X-Date
X-Detected-As
X-Destination
VivaBuild
Viewtype
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
GEO-REGION-INFO
Apple-News-Services-Host
A
Apple-News-Services-Handled
Arc-Country
BehaviorPad-Version
Fly-Request-Id
Cross-Origin-Window-Policy
Content-Style-Type
Content-Script-Type
Cache-Prefix
X-ScT
MD5-Digest
Memcached
Xc-Version
Request-EU
Rt-Proxy-Cache
X-Rewrite-Enabled
T-Server
X-Server-Time
Request-Country
Rendered-Blocks
Mobile-Detection-Method
Meta-Geo-Continent
Node
X-S-Cookie
X-Rojux
Fly-Cache
AsisCache
X-Vtex-Remote-Cache
X-Twitter-Response-Tags
X-VG-WebServer
X-Vtex-Processado-Em
X-Transaction
X-Trv-Group
Request-Time
X-B3-Parentspanid
X-SRCache-Key
X-Endurance-Cache-Level
X-Generated-By
X-Cdn-Forward
Backend-Name
X-Nc
User-Cache-Control
X-Tt-Trace-Tag
X-S-Maxage
X-Cdn-Srv
X-Cache-Info
X-Request-URI
X-Cdn-Origin
X-Clara-WADP
X-Tec-Api-Origin
X-Tec-Api-Root
X-NC
X-Tec-Api-Version
X-Block-Status
X-Proxy-Cache-Status
IsBot
CF-IPCountry
X-Proxy-Upstream
N-Cache
X-Sn-Servicetimems
X-WADP-Cache
X-Via-CDN
X-Is-Gdpr
X-Hnp-Log
X-JWT-State
X-Cache-Bucket
X-SVT-ORM-VERSION
X-NX-Host
X-SVT-ORM-RULES
X-Amzn-Remapped-Content-Length
X-Has-Esi
X-SIPLIST1
X-Device-Os
X-ElasticPress-Search
X-Debug-Cookies
X-Debug-Log
X-Gen-Mode
We-Hiring
Mail-Subject
Server-Int
Server-Host
Thinkindot-CacheControl-Type
X-Hash
X-Generated-In
Web-Mar-Node
True-Client-Country-4JS
Thinkindot-Control
Thinkindot-CacheControl
Served-By
X-VServer
X-Request-Start
X-Fetched-On
X-TrackingId
X-Svr
X-IN-APIGATEWAY
Pagetype
PFcat
Pramga
X-GeoIP-City
RNT-Time
X-Up
RNT-Machine
X-Distributor
X-Fastly-Cache
Section-Io-Cache
X-Var-Ttl
X-Developers
X-Clientip
X-Generated-On
X-Dispatch
X-Cache-FS-Status
X-Cache-Id
X-NWS-UUID-VERIFY
X-Compress-Hint
X-Generation-Time
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-Geo-Header
X-CUA
X-Policy
X-Reqid
X-Dispatcher-Server
X-Variation
X-Webstats-RespID
X-Debug-Cache-Store
X-User
X-Urbn-Context-Path
X-Urbn-Site-Id
X-WebServer
X-Amz-Meta-Cache-Control
X-BBXSRF
X-Bip
X-Backend-Url
X-Backend-Host
X-VC-Cache
X-Auto-Login
X-B3-Spanid
Platform
X-Matched-Rule
X-Magnolia-Registration
X-Release
X-RateLimit-Limit-Second
X-Worker
X-Server-IP
X-Swa-Ws
X-RateLimit-Remaining-Second
X-Irp-Debug
Fastly-Soc-X-Request-Id
Adler-Geo
Countrycode
CDCHOST
X-LI-UUID
X-Li-Fabric
X-Li-Pop
X-Level-Front-Cache
X-Reboot
AKAMAI
X-Location
Content-Disposition
X-SayCDN-TTL
X-Service
X-Origin-Expires
X-Say-Cacheable
Kp-EeAlive
X-Say-TTL
X-Origin-Date
Locale
X-Owner
X-Thinkindot-L3
X-Platform-Server
X-IN-APIGATEWAYSSL
X-We-Are-Hiring
X-Thanos
X-Skip-Cache
Is-Eu
Heartbleed
X-Old-Content-Length
Gh-Request-Id
X-Nginx-Cache
X-Distil-CS
X-ServiceProvider
X-Azure-Ref
X-Nginx-Cache-Key
X-Wikidot-Static-Cache
X-Qloud-Router
X-Azure-Ref-OriginShield
X-C
X-Core-Mission
X-SD-PageType
X-CGP
X-Method
X-Cache-URL
X-Epic-Correlation-Id
Akamai-GRN
X-Eu-Site
X-LI-Proto
Esi-Enabled
X-Wikidot-Backend
V-Age
Wxu-Next-Commit
X-Instart-Isnd
X-Key
Wxu-Next-Hostname
X-Dc
Ha-Gx-Prefs
L
Magicmarker
Resin-Trace
HA-Ipaddr
Wxu-Next-Region
SD-X-WS
X-Microcachable
X-Ruxit-Js-Agent
X-Cache-Backend
X-Rebelmouse-Cache-Control
Fastly-SWR
Fastly-SIE
X-MSEdge-Flight
X-Internal-Host
Cache-Provider
X-Rebelmouse-Surrogate-Control
X-Backend-State
X-App-Name
X-MSEdge-Features
Server-ID
W
X-Scheme
X-Lb-Id
SRV
X-Servername
X-FPC
X-Ratelimit-Limit
X-Processor
REQUESTUUID
X-DC
Memory
Group
X-Be
X-NodeID
X-Webapp-Samesite-None-Activated-N
X-GEO
Cdn-Host
Cdn-Request-Time
X-Edge-Server
X-VWS-Id
X-LJ-Flow-ID
X-AWS-Id
X-Pjax-Url
Cache-Host
X-GDPR
X-Ratelimit-Remaining
X-Mode
X-Hello
X-ABtesting
X-Servedbyhost
X-Org
X-Flog
X-Wa
X-Request-Time
X-Datadome
SS
X-Ms-Version
X-Ms-Request-Id
X-Server-W
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
X-Unique-ID
X-Oss-Object-Type
X-Oss-Server-Time
X-SRV
X-Oss-Request-Id
X-Response-By
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
X-CDN-Forward
X-IPS-LoggedIn
X-VCL-Version
X-Session-Fingerprint
X-Page-Type
X-SN
Country-Code
Lfy
X-Via-Ucdn
X-Zone
X-Oracle-Dms-Rid
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-From
Cache-Cookie-Set-Idcheck
X-Cache-Debug
X-EC-Lua
X-Agile-Id
PICS-Label
X-Agile
X-Agile-Age
X-Ftr-Request-Id
X-Tb-Optimization-Total-Bytes-Saved
X-Dynatrace
X-HS-Status
UCS
Ttl
X-URL
X-COUNTRY
X-Zipkin-Id
X-Routing-Service
X-Proxied
Powered-By-ChinaCache
X-7Graus-Varnish-XKeys
X-7Graus-Varnish-Cache-Control
X-Pf-Uncompressing
X-GRACE
Geoip-Latitude
Geoip-City
SN
GeoIp-Country-Code
Environment
X-Fastly-Country-Code
X-Cache-Miss-From
X-Logging-Id
X-Sedo-Request-Id
X-CSRF-Token
Ajk
X-Sucuri-ID
GeoIP-Latitude
GeoIP-City
GeoIP-Country-Code
Proxy-Firewall
X-APP
X-Logtrace-Id
X-Unique-Id
X-Varnish-Beresp-TTL
X-Sucuri-Id
X-Bc
X-Source
X-PF-Uncompressing
X-MP-GENERATED-AT
XServer
X-Core-Value
X-Newrelic-Synthetics
X-ZONE
X-Ftr-Cache-Host
X-Grey
ProcessTime
Powered-By
X-Cache-Category-Id
Cdn
X-RateLimit-Reset
X-CLOUD-TRACE-CONTEXT
Pics-Label
X-Tt-Trace-Host
X-Vcl-Version
M-TraceId
X-Vdms-Version
X-HTML-Minification-Powered-By
Cf-Ipcountry
Amp-Access-Control-Allow-Source-Origin
X-LiteSpeed-Cache-Control
X-FORWARDED-FOR
X-Check-Cacheable
X-Sucuri-Cache
X-AK-Request-ID
X-Edge
Cdncip
CF-Cached-On
Cdnsip
X-Aicache-OS
Fastly-Backend-Name
X-TH-Server
X-Planisys-CDN-Cache
X-Fstrz
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Sigma-Backend
X-Rocket-Build-Number
MIME-Version
X-DataStream-Cache-Status
X-Shopify-Generated-Cart-Token
X-Sigma
WWW
X-Ftr-Balancer
X-Ftr-Realm
X-Ftr-Backend
X-Dynatrace-Js-Agent
X-Ftr-Dc
X-Ftr-Backend-Server
X-Cache-Tag
Pragrma
X-RCS-CacheZone
X-Mid
X-ServedByHost
CACHE
X-Via-NSCOPI
Requestid
X-ORACLE-APMCS-REQUEST-ID
X-SaId
X-ORACLE-APMCS-TAG
X-Fastly-Backend-Reqs
GW-Server
X-MCACHE
X-Swift-Error
X-UPSTREAM-Address
X-LAGOON
X-NGINX-Cache
HostName
X-WA
X-Varnish-Ttl
X-BE
X-Edge-O15-RID
LB
X-Gannett-Site-Version
X-TT-LOGID
URI
TTL
X-ND-Cache
X-Secret
X-Upstream-Ct
X-PJAX-URL
X-Upstream-Ht
Lb
Tcn
X-RPM
X-Refresh
X-DW
X-Trafficlayer-App-Version
X-Cache-Ttl
X-RPS
X-DI
X-TIME
X-RSL
X-DSS
X-DB
X-Action
X-DataStream-Origin-MEX-Latency
X-Litespeed-Cache-Control
X-Varnish-Url
Ohc-Response-Time
X-BC
X-DataStream-MidMile-RTT
Dynatrace
X-ID
X-WR-MODIFICATION
X-Varnish-Cacheable
Host-ID
X-Via-SSL
X-Cf-Powered-By
X-Via-Edge
X-Served-From
RequestUuid
X-CDN-Cache
On-Server
X-Correlation-ID
DataCenter
X-Fpc
CDN
X-Fastly-Cache-Hits
User-Agent
Gannett-Cam-Experience-Id
Is-Session-Tracking
Get-Access-Time
X-Flow-Id
Xkeyrz
X-Pod
X-Req
Xkeypdq
X-Zalando-Child-Request-Id
X-Proxy-Cacherz
X-Gamma-Serve
X-GeoIP-Country-Code
Locid
X-Page-Impression-Id
Server-Id
X-ATS-Timestamp
WZWS-RAY
X-VC
Correlation-Id
X-SB
X-MID
FNAC-ModuleRouting
X-Dw-Trace-Id
X-HostName
X-ServerName
X-LB-ID
Inserted-Into-Cache-At
Warning
X-Nananana
X-Amzn-Remapped-Date
X-Li-Proto
Thinkindot-Cache-Type
X-Amzn-Remapped-Connection
X-Bug-Bounty
Xet-Cookie
RequestId
X-Newrelic-App-Data
V-Cache
Cneonction
X-Gdpr
X-MiniProfiler-Ids
HitType
Processtime
X-Akamai-ERPolicy
X-ECache
X-LiteSpeed-Tag
X-Gen-Id
X-Akamai-ERRuleID