Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
CF-RAY
CF-Cache-Status
Link
X-XSS-Protection
X-Powered-By
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Alt-Svc
Access-Control-Allow-Credentials
X-Runtime
X-FRAME-OPTIONS
X-Drupal-Cache
X-Adblock-Key
X-Check
Content-Security-Policy-Report-Only
X-Xss-Protection
X-Generator
X-Cacheable
X-Cache-Status
X-Permitted-Cross-Domain-Policies
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Template
X-Language
X-Iinfo
X-Content-Security-Policy
Status
Content-Encoding
X-AspNetMvc-Version
X-Buckets
X-Request-ID
X-Kinja-Server-Push
Upgrade
Xkey
X-Via
Access-Control-Expose-Headers
X-Turbo-Charged-By
Access-Control-Max-Age
Keep-Alive
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Pass-Why
EagleId
X-Age
X-Backend
X-Envoy-Upstream-Service-Time
X-Robots-Tag
X-Amz-Request-Id
X-Amz-Id-2
X-Page-Speed
X-CDN
X-Pingback
X-Server-Powered-By
X-Server
X-AH-Environment
X-Proxy-Cache
X-UA-Device
X-Hacker
Request-Context
X-Swift-CacheTime
X-Swift-SaveTime
X-Nginx-Cache-Status
Grace
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-Cdn
P3p
X-LiteSpeed-Cache
Cf-Railgun
Server-Timing
X-Ua-Compatible
Feature-Policy
X-Amz-Version-Id
X-Device
X-WebKit-CSP
X-Server-Id
X-OneAgent-JS-Injection
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Rq
X-Ac
EagleEye-TraceId
X-Cnection
Report-To
X-Cloud-Trace-Context
Request-Id
X-Backend-Server
X-Response-Time
X-Node
Content-Location
X-Host
X-Readtime
X-Origin-Cache
X-Vhost
X-Cache-Lookup
X-Application-Context
X-DataDome
X-ORACLE-DMS-ECID
X-Dispatcher
NEL
X-ORACLE-DMS-RID
X-Ruxit-JS-Agent
X-Rack-Cache
X-HW
X-Origin-Upstream-Status
Surrogate-Control
X-Dns-Prefetch-Control
X-Clacks-Overhead
Rating
X-Country-Code
Allow
X-Country
X-Url
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-FTR-Request-ID
X-DynaTrace
X-MS-InvokeApp
X-Goog-Hash
X-Instart-Request-ID
Fusion-Template-Id
Fusion-Component-Id
Fusion-Content-Id
Fusion-Content-Source
Fusion-Source
X-TTL
X-TtlSet
X-Vname
X-PC
X-Varnish-TTL
X-B3-TraceId
Pinterest-Generated-By
Verso
X-Powered-By-Plesk
X-Px
Public-Key-Pins
RTSS
Edge-Control
X-ESI
X-Mod-Pagespeed
SPRequestGuid
X-Ah-Environment
Display
X-Middleton-Response
X-Sol
X-Middleton-Display
Response
X-VARITI-CCR
X-Akam-SW-Version
X-SharePointHealthScore
X-D2id
X-Cdn-Fetch
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Kinja
X-Kinja-Build
X-GoogleNews-Bot
X-Exp-Variant
X-Exp-Id
Accept-Ch-Lifetime
X-Recruiting
Service-Worker-Allowed
SPIisLatency
SPRequestDuration
X-Vcap-Request-Id
X-CST
X-Server-Name
X-GitHub-Request-Id
X-Powered-CMS
MS-Author-Via
X-Version
TCN
X-Navigation-Version
X-Abt-Application-Version
X-Trace
Charset
X-Debug
X-Amz-Server-Side-Encryption
X-Shard
Fastly-Restarts
X-Aspnetmvc-Version
X-Amz-Rid
Realpath
Nginx-Cache
X-Upstream
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
Ar-Sid
Accept-CH
AR-ATIME
AR-PoweredBy
AR-CACHE
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-NF-Request-ID
X-RateLimit-Remaining
X-Forwarded-Proto
X-Ezoic-Cdn
Front-End-Https
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-MSEdge-Ref
DynaTrace
Access-Control-Request-Method
X-Cached
Arr-Disable-Session-Affinity
Content-MD5
X-Shield-Request-Id
Pagespeed
AR-Request-ID
MRF-Tech
Mrf-Cache-Status
X-Mrf-Item-Lastmod
X-B3-TraceId-Primal
X-Mrf-Section-Lastmod
MicrosoftSharePointTeamServices
X-VCache
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Expires
X-XRDS-Location
X-Amz-Meta-S3cmd-Attrs
X-Goog-Storage-Class
S
X-DynaTrace-JS-Agent
X-Ser
X-Fastly-Request-ID
X-T
X-Id
X-FTR-Backend-Server
X-FTR-Realm
X-FTR-Balancer
X-FTR-DC
X-FTR-Backend
Paypal-Debug-Id
X-Varnish-Age
Accept-Ch
X-Server-ID
ServerID
X-Via-JSL
X-Fastcgi-Cache
X-Accel-Expires
X-Content-Type
X-Client-IP
X-Forwarded-For
Edge-Cache-Tag
X-Dw-Request-Base-Id
X-Grace
Fastcgi-Cache
X-Amzn-Trace-Id
X-Frontend
X-Hits
X-Content-Digest
X-Correlation-Id
Powered
X-DIS-Request-ID
X-N
AMP-Access-Control-Allow-Source-Origin
X-Pinterest-Rid
Pinterest-Version
X-HS-Content-Id
X-HS-Hub-Id
X-Mobile-Rewrite
PB-RID
PB-PID
Arc-Version
X-FTR-Cache-Host
Server-Name
X-Vcache
X-Logged-In
TP-Cache
TP-L2-Cache
X-Request-Received
X-Kinsta-Cache
X-Request-Processing-Time
X-Cache-Hit
X-Request-Handler-Origin-Region
X-Zen-Fury
X-Microsite
X-Time
X-Activity-Id
X-AppVersion
X-Az
X-User-Agent
X-IPLB-Instance
X-Rid
X-LB-Cache
X-Cache-Age
X-Revision
X-Type
Healthy
Retry-After
X-Whom
X-Srv
X-Analytics
Backend-Timing
X-Node-Name
Server-Node
X-GUploader-UploadID
X-FastCGI-Cache
X-B3-Sampled
X-RateLimit-Limit
FilterID
X-NWS-LOG-UUID
X-Hp-Webp
Cache-Tag
Alternate-Protocol
X-F-Cache
X-SERVER
Accept-Charset
NR-ENABLED
X-Akamai-Edgescape
X-Content-Security-Policy-Report-Only
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Webkit-CSP
X-Content-Options
X-Cache-Rule
Cache-Status
VIX-Pulpo-Upstream-Status
X-Content-Powered-By
MS-CV
VIX-Pulpo-Node
DC
Access-Control-Allow-Method
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-User
X-Cluster
X-AOL-HN
X-FB-Debug
X-Instance
X-Amzn-RequestId
X-Framework
Refresh
X-Amz-Apigw-Id
Source
X-Cache-2
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Tracecode
X-Debug-Info
X-Jobs
X-Varnish-Grace
X-App-Environment
X-B
X-Forwarded-Host
Actual-Object-TTL
X-Request-Guid
X-Seen-By
X-Page-Id
X-PHP-Backend
Surrogate-Key
X-Mobile-URL
X-Cache-TTL
X-App-Server
Host
Frame-Options
X-Cache-Operation
Fastcgi-Useragent
X-Geo-Country
X-FW-Server
X-FW-Static
X-FW-Type
X-FW-Hash
X-FW-Serve
X-Cache-Control
X-TA-CDN-Provider
X-Cached-By
X-Host-Name
X-Pad
X-Hostname
Cleartype
X-Element-Page-Cache
X-Cache-Key
X-B-Cache
X-Signature
Upgrade-Insecure-Requests
X-WebKit-CSP-Report-Only
X-Git-Hash
X-Mobile
X-BCube-Filmed-By
X-ATG-Version
X-Varnish-Backend
X-HS-Cache-Config
X-Response-Served-From
NGB
Xserver
X-UA-Device-Type
X-ProcessESI
WPE-Backend
Ms-Operation-Id
X-RemovedCookies
X-RTag
X-Daa-Tunnel
X-GeoIP
X-Tumblr-Pixel-2
Filters
Eomportal-Instance
X-Amz-Replication-Status
X-Origin-Server
Webserver
X-Tumblr-Pixel-1
X-EdgeConnect-Cache-Status
X-TT
Cache-Tv-Group
X-Handled-By
From-Origin
X-Drupal-Cache-Tags
X-Adobe-Loc
X-Adobe-Content
GEO-INFO
X-TX-ID
X-Cacheable-TTL
Payment
X-RequestSource
X-TT-TIMESTAMP
X-Wix-Request-Id
Cache
X-Cache-TTL-Remaining
X-XRDS-LOCATION
Datacenter
X-Cache-Remote
X-Status
X-Esi
Liferay-Portal
X-FW-Dynamic
X-Hyper-Cache
X-WA-Info
X-Presslabs-Stats
X-Region
X-Contextid
Version
X-Edge-Location
X-Cache-Action
X-Ratelimit-Reset
X-Ttl
X-Acc-Meta-Resource-Type
Viewport
X-Content-Age
X-CF-Powered-By
X-Cache-NE
X-B3-Traceid
X-HS-Combine-CSS
X-Akamai-Transformed
X-Varnish-Hostname
PageSpeed
X-PressLabs-Stats
X-Storage
X-Cache-Server
Accept-CH-Lifetime
X-Varnish-Server
X-ES-SERVER
X-RN-RSRV
Load-Balancing
X-Cache-Var
Meta-Geo
X-Cache-Var-Map
X-Path-Route
X-Viewer-Country
X-Cache-Grace
X-Cache-Enabled
X-Xfnlog-Site
Country
Ohc-File-Size
X-Proxy
X-Via-Fastly
X-CCM
X-Cache-Config
Host-Header
X-Accel-Buffering
Cache-Tags
X-Yottaa-Optimizations
X-Labrador-Cache-Channel
X-Yottaa-Metrics
X-Cache-Host
X-Cache-Time
X-Proto
Cache-Hits
Release
X-UnsetCookies
X-NCache
X-OCL
DB-Nickname
X-Device-Type
Vix-Hermes-Req-Id
X-Akamai-Request-ID2
X-PCL
Cache-Name
X-TNCMS
X-Loop
Rt-Fastcgi-Cache
Webcakes-App-Version
Webcakes-App-Name
TWC-Privacy
TWC-Locale-Group
Webcakes-Region
X-Backend-Name
X-Debug-Cache
X-CS
X-Backend-TTL
TWC-GeoIP-LatLong
TWC-GeoIP-Country
DSUID
Decoy-Debug-TTL
Decoy-Debug-Status
Ec-Rule-Version
Property-Id
TWC-Device-Class
TWC-Connection-Speed
Selected-Fe
X-EIG-Tracking-Id
X-FC-Vary-Parameters
X-Upgrade-Enabled
X-Tumblr-Pixel-3
X-Trace-Id
X-Time-Microsecs
X-Varnish-Cache-Hits
X-Varnish-Hits
X-Www-Served-By
X-Web-Node
X-Vgn-Hpd-Reason
X-Rule
X-R9-Blue-Green-Version
X-Hosted-By
X-Goog-Meta-Goog-Reserved-File-Mtime
X-From
X-Human
X-JoinUs
X-Proxy-Build
X-Origin-Hint
X-Origin
Decoy-Debug-Key
X-Timing-Wait
S-Cnection
X-NewRelic-App-Data
X-IP
S-Rt
X-Akamai-Request-ID
Cache-Key
X-VCT
X-ApacheServer
X-Site-Version
X-Generated
X-Origin-Response-Time
X-PERF
X-Locale
Azure-InstanceId
Mn-Server-Ip
X-Drupal-Cache-Contexts
Azure-RegionName
Azure-SiteName
Azure-Version
Azure-SlotName
X-Cluster-Node
X-Hit
X-Pubstack
X-Section
X-FireWall-Port
X-Ua
X-Access
X-OVcl-Cache
X-OVcl
Origin-Cache-Control
Origin-Edge-Control
X-Format
X-Real-IP
Time
X-S
Ohc-Cache-HIT
X-Trafficlayer-App-Scope
Server-Info
X-Trafficlayer-App-Name
L5d-Success-Class
X-Redis-Cache
X-NGENIX-Cache
X-Rendered-As
X-FW-Version
X-Origin-CC
X-Litespeed-Cache
X-Origin-TTL
Now
Fastcgi-X-Cache-Version
X-SS-Set-Cookie
Fastly-SSL
OT-Force-Account-Verify
ServedBy
X-Upstream-CT
Origin
X-ServerID
Hostname
X-Cluster-Name
X-Upstream-HT
Cteonnt-Length
Access-Control-Request-Headers
X-Load-Cache
X-APP-VERSION
Mime-Version
X-ShardId
X-ShopId
X-Shopify-Stage
X-App-Version
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-UUID
X-Alternate-Cache-Key
X-Guploader-Uploadid
X-Rocket-Nginx-Bypass
X-GoCache-CacheStatus
X-Soup
X-FB-TRIP-ID
X-Webkit-Csp
X-Parent-Response-Time
X-CACHE-KEY
NtCoent-Length
X-VG-WebCache
Accept-Language
NGX
X-VG-TLSProxy
Odigeo-Trace-Id
Machine
X-Upstream-Proxy
X-Uri
X-Info
Nel
X-Is-Bot
X-B3-SpanId
IBM-Web2-Location
X-CSRF-TOKEN
X-ProxyCache-Status
X-BYPASS-REASON
X-MServer
X-Tb
X-ECACHE
X-Node-Id
X-ProxyCache-Key
X-Environment-Context
X-No-Session
X-L-Path
X-Tt-Trace-Tag
X-Nc
Srv
X-UA
X-Cdn-Forward
X-Oneagent-Js-Injection
X-Destination
X-Detected-As
X-Trv-Group
X-Transaction
X-D
X-Developer
Cross-Origin-Window-Policy
Mobile-Detection-Method
Node
X-B3-Parentspanid
Request-Time
Meta-Geo-Continent
Memcached
Content-Style-Type
X-Instart-Info
X-Date
MD5-Digest
Content-Script-Type
Fly-Cache
X-PHP-Host
X-Cms-Context
X-CF-Lambda-Version
Apple-News-Services-Request-Url
X-G
A
Apple-News-Services-Host
Apple-News-Services-Handled
X-External-Request-Id
X-Connection-Hash
Arc-Country
AsisCache
Fly-Request-Id
X-Twitter-Response-Tags
Cache-Prefix
X-Tec-Api-Root
GEO-REGION-INFO
X-Hl-Ver
BehaviorPad-Version
Uber-Trace-Id
X-DPWN-IS-SECURE
X-CF-Lambda-Fn
Apple-News-Services-Parsed-Url
Proxy-Connection
X-A-Dgt
X-A-Wwc
Rt-Proxy-Cache
X-A-Dcw
X-A-Dam
X-Server-Time
X-Accel-Expires-Debug
X-Aed
Rendered-Blocks
X-AIR-PT
Request-Country
X-VG-WebServer
Request-EU
X-Region-Sid
X-Vtex-Remote-Cache
X-Rojux
X-Tec-Api-Origin
Viewtype
T-Server
X-Tec-Api-Version
X-S-Cookie
X-Rewrite-Enabled
X-Request-UUID
X-A
X-A-Ccd
X-ScT
VivaBuild
ServerName
X-Geo
X-Vtex-Processado-Em
X-ARC
X-Application
Xc-Version
X-SRCache-Key
X-PAYTM-SRV-ID
X-B-Cookie
User-Cache-Control
Backend-Name
X-Endurance-Cache-Level
X-SVT-ORM-RULES
X-ElasticPress-Search
X-Debug-Cookies
IsBot
X-WADP-Cache
X-Block-Status
X-Worker
X-NX-Host
N-Cache
X-S-Maxage
X-Device-Os
X-Generated-By
X-Debug-Log
X-Request-URI
X-SVT-ORM-VERSION
X-Gen-Mode
X-Cdn-Origin
X-Sn-Servicetimems
X-Proxy-Cache-Status
X-SIPLIST1
X-Cache-Info
X-Cdn-Srv
X-Hnp-Log
X-Has-Esi
X-JWT-State
X-Clara-WADP
X-Cache-Bucket
X-Amzn-Remapped-Content-Length
X-Is-Gdpr
X-Proxy-Upstream
We-Hiring
X-Via-CDN
Mail-Subject
CF-IPCountry
X-Nginx-Cache
Thinkindot-Control
X-Backend-Host
X-Backend-Url
True-Client-Country-4JS
X-BBXSRF
Web-Mar-Node
X-Amz-Meta-Cache-Control
X-Clientip
X-Compress-Hint
X-CUA
X-Cache-FS-Status
X-Auto-Login
X-Bip
X-Cache-Id
X-Debug-Cache-Expiry
X-IN-APIGATEWAYSSL
X-Variation
X-Webstats-RespID
X-VC-Cache
X-Skip-Cache
X-Platform-Server
X-VServer
X-Owner
X-Origin-Expires
X-Swa-Ws
X-Var-Ttl
X-Svr
X-Old-Content-Length
X-Origin-Date
X-Policy
X-Service
X-WebServer
X-SayCDN-TTL
X-Say-TTL
X-Say-Cacheable
X-We-Are-Hiring
X-Request-Start
X-Reqid
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Reboot
X-Server-IP
X-Release
X-Matched-Rule
X-Magnolia-Registration
X-Generated-On
X-Generated-In
X-Generation-Time
X-Geo-Header
X-Hash
X-GeoIP-City
X-Fetched-On
X-Fastly-Cache
X-Developers
X-Debug-Cache-Store
X-Dispatch
X-Dispatcher-Server
X-Distributor
X-IN-APIGATEWAY
X-Up
X-Thanos
X-Thinkindot-L3
X-Urbn-Context-Path
X-Urbn-Site-Id
X-User
X-Location
X-TrackingId
X-Level-Front-Cache
X-Irp-Debug
X-Li-Fabric
X-Li-Pop
X-LI-UUID
X-Debug-Cache-Fetch
Thinkindot-CacheControl-Type
RNT-Time
RNT-Machine
Kp-EeAlive
Section-Io-Cache
Served-By
Locale
Pagetype
Pramga
Platform
X-NC
PFcat
Server-Host
Is-Eu
AKAMAI
X-Dc
Content-Disposition
CDCHOST
Countrycode
Server-Int
Heartbleed
Gh-Request-Id
Fastly-Soc-X-Request-Id
Adler-Geo
Thinkindot-CacheControl
X-Ruxit-Js-Agent
X-NWS-UUID-VERIFY
Wxu-Next-Commit
X-Core-Mission
Fastly-SWR
Ha-Gx-Prefs
X-CGP
X-SD-PageType
Wxu-Next-Hostname
HA-Ipaddr
X-B3-Spanid
X-Wikidot-Backend
X-Eu-Site
X-Epic-Correlation-Id
Akamai-GRN
X-Instart-Isnd
V-Age
Wxu-Next-Region
Esi-Enabled
X-Wikidot-Static-Cache
Fastly-SIE
X-Lb-Id
X-Rebelmouse-Cache-Control
Magicmarker
X-LI-Proto
X-Nginx-Cache-Key
X-Distil-CS
X-Azure-Ref-OriginShield
Resin-Trace
X-Qloud-Router
X-C
X-ServiceProvider
X-Method
L
SD-X-WS
X-Azure-Ref
X-Rebelmouse-Surrogate-Control
X-Cache-URL
X-Microcachable
SRV
X-Scheme
X-Cache-Backend
X-MSEdge-Features
X-Key
X-Internal-Host
X-MSEdge-Flight
X-Servername
Memory
X-Backend-State
X-App-Name
Server-ID
W
X-GEO
Cache-Provider
X-Processor
X-Be
X-Ratelimit-Limit
X-FPC
REQUESTUUID
X-Edge-Server
Cdn-Host
Cdn-Request-Time
Group
X-LJ-Flow-ID
X-VWS-Id
X-DC
X-AWS-Id
X-GDPR
X-NodeID
X-Pjax-Url
X-Org
Cache-Host
X-Mode
X-Servedbyhost
X-Wa
X-ABtesting
X-Flog
X-Hello
X-Datadome
X-Request-Time
SS
X-Server-W
X-Unique-ID
X-Response-By
X-GRACE
X-Ms-Request-Id
X-Ms-Version
X-IPS-LoggedIn
X-Page-Type
X-Webapp-Samesite-None-Activated-N
X-SN
X-Oss-Hash-Crc64ecma
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Status
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Object-Type
X-Varnish-Beresp-Grace
X-Oss-Request-Id
Country-Code
X-Ratelimit-Remaining
X-Via-Ucdn
X-Oracle-Dms-Rid
Cache-Cookie-Set-From
X-Session-Fingerprint
Lfy
X-VCL-Version
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
X-CDN-Forward
X-EC-Lua
X-Zone
X-Ftr-Request-Id
X-Cache-Debug
X-SRV
X-Dynatrace
X-URL
UCS
X-COUNTRY
X-Zipkin-Id
X-Agile
X-Agile-Age
PICS-Label
X-Agile-Id
X-HS-Status
X-Routing-Service
X-Tb-Optimization-Total-Bytes-Saved
X-Proxied
X-7Graus-Varnish-XKeys
SN
Ttl
X-7Graus-Varnish-Cache-Control
Powered-By-ChinaCache
Geoip-City
X-PF-Uncompressing
Proxy-Firewall
Ajk
Environment
Geoip-Latitude
GeoIP-Latitude
X-Pf-Uncompressing
GeoIP-Country-Code
GeoIP-City
X-Cache-Miss-From
X-Logging-Id
GeoIp-Country-Code
X-Logtrace-Id
X-Fastly-Country-Code
X-Sedo-Request-Id
X-Sucuri-Id
X-Source
X-Varnish-Beresp-TTL
X-MP-GENERATED-AT
X-Newrelic-Synthetics
X-CSRF-Token
X-Sucuri-ID
XServer
X-Bc
X-Grey
X-Unique-Id
Cdn
X-ZONE
ProcessTime
Powered-By
X-Ftr-Cache-Host
X-Cache-Category-Id
X-APP
X-CLOUD-TRACE-CONTEXT
X-RateLimit-Reset
X-Core-Value
X-Tt-Trace-Host
Pics-Label
M-TraceId
X-Vcl-Version
X-HTML-Minification-Powered-By
Cf-Ipcountry
X-LiteSpeed-Cache-Control
Fastly-Backend-Name
X-Vdms-Version
X-Edge
CF-Cached-On
X-Aicache-OS
X-Check-Cacheable
X-TH-Server
Cdnsip
Cdncip
X-AK-Request-ID
X-Sucuri-Cache
X-DataStream-Cache-Status
WWW
X-Ftr-Backend
X-Ftr-Realm
X-Dynatrace-Js-Agent
X-Ftr-Dc
X-Ftr-Balancer
X-Ftr-Backend-Server
X-Planisys-CDN-Cache
X-Rocket-Build-Number
X-Planisys-CDN-Rules
X-Sigma-Backend
X-Sigma
X-Mid
X-Fstrz
X-Shopify-Generated-Cart-Token
Pragrma
Requestid
X-Planisys-CDN-TTL
CACHE
MIME-Version
X-Correlation-ID
X-MCACHE
HostName
X-FORWARDED-FOR
X-Fastly-Backend-Reqs
X-RCS-CacheZone
X-Varnish-Ttl
X-ServedByHost
GW-Server
X-LAGOON
X-Swift-Error
X-Cache-Tag
X-Via-NSCOPI
Amp-Access-Control-Allow-Source-Origin
X-SaId
X-ORACLE-APMCS-TAG
X-Gannett-Site-Version
X-Secret
LB
X-ORACLE-APMCS-REQUEST-ID
X-NGINX-Cache
X-TT-LOGID
X-UPSTREAM-Address
X-WA
TTL
Lb
X-DSS
X-DW
X-DI
X-DB
X-ND-Cache
X-BE
X-PJAX-URL
X-RSL
X-RPS
X-Action
X-RPM
X-Cache-Ttl
X-Varnish-Url
X-BC
X-DataStream-Origin-MEX-Latency
X-DataStream-MidMile-RTT
Ohc-Response-Time
X-Litespeed-Cache-Control
URI
X-Upstream-Ht
X-Upstream-Ct
Dynatrace
On-Server
X-Fpc
Host-ID
X-CDN-Cache
X-Varnish-Cacheable
X-Trafficlayer-App-Version
X-Refresh
RequestUuid
DataCenter
Is-Session-Tracking
CDN
Xkeypdq
Get-Access-Time
X-Proxy-Cacherz
X-GeoIP-Country-Code
X-Zalando-Child-Request-Id
Server-Id
Xkeyrz
X-Page-Impression-Id
User-Agent
X-Served-From
X-Via-Edge
X-Via-SSL
X-WR-MODIFICATION
X-Flow-Id
X-Fastly-Cache-Hits
WZWS-RAY
X-MID
X-SB
X-Req
Inserted-Into-Cache-At
Locid
X-Gamma-Serve
Correlation-Id
X-VC
X-Nananana
X-Dw-Trace-Id
X-Pod
Warning
Gannett-Cam-Experience-Id
X-Cf-Powered-By
X-Li-Proto
FNAC-ModuleRouting
X-Amzn-Remapped-Connection
X-Akamai-ERRuleID
Thinkindot-Cache-Type
X-Amzn-Remapped-Date
X-LB-ID
X-Newrelic-App-Data
X-ServerName
V-Cache
X-Gdpr
X-MiniProfiler-Ids
Cneonction
X-Bug-Bounty
HitType
X-Gen-Id
X-LiteSpeed-Tag
RequestId
Xet-Cookie
X-ECache
Processtime
X-Akamai-ERPolicy