Threat Level: green Handler on Duty: Manuel Humberto Santander Pelaez

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
CF-RAY
CF-Cache-Status
Link
X-Powered-By
ETag
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Xss-Protection
X-Download-Options
X-AspNet-Version
Alt-Svc
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
Content-Security-Policy-Report-Only
X-Generator
X-Cacheable
X-Cache-Status
X-Permitted-Cross-Domain-Policies
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Template
X-Language
X-Iinfo
Content-Encoding
X-Content-Security-Policy
Status
X-FRAME-OPTIONS
X-AspNetMvc-Version
X-Request-ID
X-Buckets
X-Kinja-Server-Push
Xkey
Upgrade
X-Via
Access-Control-Expose-Headers
X-Turbo-Charged-By
Access-Control-Max-Age
Keep-Alive
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Pass-Why
X-Age
EagleId
X-Backend
X-Envoy-Upstream-Service-Time
X-Robots-Tag
X-Ua-Compatible
X-Amz-Id-2
X-Amz-Request-Id
X-Page-Speed
X-Pingback
X-Server-Powered-By
X-AH-Environment
X-Server
X-Proxy-Cache
X-UA-Device
X-Hacker
X-CDN
Request-Context
X-Nginx-Cache-Status
X-Swift-SaveTime
X-Swift-CacheTime
Grace
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-Cdn
P3p
Cf-Railgun
X-LiteSpeed-Cache
Server-Timing
Feature-Policy
X-Amz-Version-Id
X-Device
X-WebKit-CSP
X-Server-Id
X-OneAgent-JS-Injection
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Rq
X-Ac
EagleEye-TraceId
X-Cnection
Report-To
X-Cloud-Trace-Context
Request-Id
X-Backend-Server
X-Response-Time
X-Host
Content-Location
X-Node
X-Readtime
X-Origin-Cache
X-Vhost
X-Cache-Lookup
X-Application-Context
X-ORACLE-DMS-ECID
X-DataDome
X-Dispatcher
X-Ruxit-JS-Agent
NEL
X-ORACLE-DMS-RID
X-Origin-Upstream-Status
X-Rack-Cache
X-HW
Surrogate-Control
X-Dns-Prefetch-Control
Rating
X-Country-Code
Allow
X-Country
X-Clacks-Overhead
X-Url
X-FTR-Request-ID
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-DynaTrace
X-Instart-Request-ID
X-MS-InvokeApp
Fusion-Component-Id
Fusion-Content-Source
Fusion-Template-Id
Fusion-Source
Fusion-Content-Id
X-Goog-Hash
X-TtlSet
X-Vname
X-PC
X-TTL
X-Varnish-TTL
X-B3-TraceId
Pinterest-Generated-By
Verso
X-Powered-By-Plesk
Public-Key-Pins
X-Px
RTSS
Accept-Ch-Lifetime
Edge-Control
X-Mod-Pagespeed
X-ESI
X-Middleton-Display
X-Middleton-Response
Display
X-Sol
Response
X-Ah-Environment
X-VARITI-CCR
X-D2id
X-Kinja-Build
X-Kinja
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-GoogleNews-Bot
SPRequestGuid
X-Exp-Variant
X-Cdn-Fetch
X-Exp-Id
X-SharePointHealthScore
X-Akam-SW-Version
X-Recruiting
Service-Worker-Allowed
X-CST
X-Vcap-Request-Id
SPIisLatency
SPRequestDuration
X-Version
X-Server-Name
X-GitHub-Request-Id
TCN
X-Powered-CMS
X-Abt-Application-Version
X-Navigation-Version
MS-Author-Via
X-Trace
Charset
X-Shard
X-Debug
Fastly-Restarts
Nginx-Cache
X-Aspnetmvc-Version
Realpath
X-Amz-Rid
X-Amz-Server-Side-Encryption
X-Upstream
X-RateLimit-Remaining
AR-CACHE
Ar-Sid
AR-PoweredBy
AR-ATIME
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Forwarded-Proto
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Ezoic-Cdn
X-NF-Request-ID
Accept-CH
Front-End-Https
X-Cached
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Stored-Content-Length
X-MSEdge-Ref
Arr-Disable-Session-Affinity
DynaTrace
Access-Control-Request-Method
Pagespeed
X-Shield-Request-Id
Content-MD5
AR-Request-ID
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
X-VCache
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Expires
MicrosoftSharePointTeamServices
Accept-Ch
X-XRDS-Location
S
X-Goog-Storage-Class
X-Fastly-Request-ID
X-Amz-Meta-S3cmd-Attrs
Paypal-Debug-Id
X-Id
X-DynaTrace-JS-Agent
X-FTR-Backend-Server
X-FTR-DC
X-FTR-Backend
X-FTR-Balancer
X-FTR-Realm
X-T
X-Ser
X-Varnish-Age
ServerID
X-Via-JSL
X-Client-IP
X-Grace
X-Content-Type
X-Accel-Expires
X-Correlation-Id
X-Dw-Request-Base-Id
X-Forwarded-For
Fastcgi-Cache
Edge-Cache-Tag
X-Hits
X-Amzn-Trace-Id
X-Content-Digest
Powered
X-Fastcgi-Cache
X-Frontend
X-DIS-Request-ID
AMP-Access-Control-Allow-Source-Origin
X-N
X-FTR-Cache-Host
PB-RID
X-Mobile-Rewrite
Arc-Version
PB-PID
X-HS-Content-Id
X-HS-Hub-Id
X-Vcache
X-Pinterest-Rid
Pinterest-Version
X-Logged-In
Server-Name
X-Server-ID
TP-L2-Cache
TP-Cache
X-Kinsta-Cache
X-Microsite
X-Request-Handler-Origin-Region
X-GUploader-UploadID
X-Cache-Hit
X-Request-Received
X-Request-Processing-Time
X-Zen-Fury
X-FastCGI-Cache
X-Time
X-Type
X-Activity-Id
X-AppVersion
X-Az
X-IPLB-Instance
X-LB-Cache
Healthy
X-Revision
Backend-Timing
X-Analytics
X-Rid
Retry-After
X-Cache-Age
X-User-Agent
X-Whom
X-B3-Sampled
X-Node-Name
FilterID
X-RateLimit-Limit
Server-Node
X-NWS-LOG-UUID
X-Srv
X-Hp-Webp
Alternate-Protocol
X-SERVER
Accept-Charset
Cache-Tag
X-F-Cache
Cache-Status
X-Akamai-Edgescape
X-Content-Options
X-Webkit-CSP
X-Content-Security-Policy-Report-Only
X-Cache-Rule
X-Erf-Bev-Bev
NR-ENABLED
X-Erf-Bev-Bev-Is-Generated
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Cache-2
DC
X-Content-Powered-By
X-Instance
MS-CV
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-FB-Debug
X-Cluster
X-Amzn-RequestId
X-AOL-HN
X-Debug-Info
X-Amz-Apigw-Id
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Jobs
X-App-Environment
Tracecode
X-Tumblr-User
X-Varnish-Grace
Refresh
Access-Control-Allow-Method
Surrogate-Key
X-Framework
X-PHP-Backend
X-Page-Id
X-Forwarded-Host
X-B
Fastcgi-Useragent
Source
X-Request-Guid
X-Cache-TTL
Host
X-Seen-By
Actual-Object-TTL
X-App-Server
X-Mobile-URL
X-Cache-Operation
X-FW-Static
Frame-Options
X-FW-Server
X-FW-Serve
X-FW-Hash
X-FW-Type
X-Geo-Country
X-TA-CDN-Provider
X-Cache-Control
X-Hostname
X-Cached-By
Cleartype
X-Pad
X-Host-Name
X-Cache-Key
X-Signature
X-B-Cache
Upgrade-Insecure-Requests
X-Git-Hash
X-BCube-Filmed-By
X-Element-Page-Cache
X-Mobile
X-WebKit-CSP-Report-Only
NGB
X-Response-Served-From
Xserver
X-Varnish-Backend
X-ATG-Version
X-GeoIP
X-UA-Device-Type
X-RemovedCookies
X-ProcessESI
X-Drupal-Cache-Tags
Filters
X-TT
WPE-Backend
Webserver
X-Handled-By
X-Amz-Replication-Status
Ms-Operation-Id
X-Daa-Tunnel
GEO-INFO
X-RTag
X-RequestSource
Eomportal-Instance
X-Presslabs-Stats
Payment
X-HS-Cache-Config
X-Tumblr-Pixel-2
X-Adobe-Content
X-Origin-Server
X-Adobe-Loc
X-Cacheable-TTL
From-Origin
X-Tumblr-Pixel-1
Cache-Tv-Group
X-EdgeConnect-Cache-Status
X-TT-TIMESTAMP
X-TX-ID
X-Litespeed-Cache
X-XRDS-LOCATION
X-Cache-Remote
X-Cache-TTL-Remaining
X-Wix-Request-Id
Datacenter
X-Status
Cache
X-FW-Dynamic
X-Esi
Liferay-Portal
X-WA-Info
X-Acc-Meta-Resource-Type
X-Hyper-Cache
X-Region
X-Contextid
Version
X-Cache-Action
X-Ratelimit-Reset
X-Edge-Location
X-Ttl
Viewport
X-Content-Age
X-Cache-NE
X-B3-Traceid
X-CF-Powered-By
X-Varnish-Hostname
PageSpeed
X-Storage
X-Akamai-Transformed
X-Cache-Server
Ohc-File-Size
X-Varnish-Server
X-HS-Combine-CSS
X-ES-SERVER
X-Cache-Var-Map
X-Path-Route
Load-Balancing
Meta-Geo
X-Accel-Buffering
X-RN-RSRV
X-Cache-Var
Host-Header
X-IP
X-Xfnlog-Site
Country
X-Via-Fastly
X-Viewer-Country
X-Proxy
Cache-Tags
X-Cache-Enabled
X-PressLabs-Stats
Release
X-Proto
X-PCL
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Origin
X-Origin-Hint
X-OCL
X-CCM
X-TNCMS
X-Section
X-Upgrade-Enabled
X-Varnish-Cache-Hits
X-Cache-Config
Vix-Hermes-Req-Id
X-NCache
X-Loop
TWC-GeoIP-LatLong
TWC-Locale-Group
TWC-GeoIP-Country
TWC-Device-Class
Rt-Fastcgi-Cache
TWC-Connection-Speed
TWC-Privacy
Webcakes-App-Version
X-Debug-Cache
X-Device-Type
X-Cache-Time
X-Access
Webcakes-Region
Property-Id
Webcakes-App-Name
X-Proxy-Build
X-R9-Blue-Green-Version
X-Origin-Response-Time
S-Rt
X-NGENIX-Cache
Selected-Fe
Mn-Server-Ip
X-Akamai-Request-ID2
DB-Nickname
Cache-Name
X-Format
Ec-Rule-Version
X-Rule
X-Cache-Grace
X-Cache-Host
X-Labrador-Cache-Channel
X-CS
X-Drupal-Cache-Contexts
X-EIG-Tracking-Id
X-FC-Vary-Parameters
X-From
X-Cluster-Node
X-Hosted-By
X-JoinUs
X-Akamai-Request-ID
X-Human
X-Backend-Name
X-Backend-TTL
X-Timing-Wait
DSUID
X-Www-Served-By
S-Cnection
X-UnsetCookies
X-VCT
X-Tumblr-Pixel-3
X-Vgn-Hpd-Reason
X-FireWall-Port
Decoy-Debug-Status
X-ApacheServer
X-Hit
Cache-Hits
X-Web-Node
X-Trace-Id
X-Time-Microsecs
X-Locale
X-Generated
Ohc-Cache-HIT
Decoy-Debug-TTL
X-Goog-Meta-Goog-Reserved-File-Mtime
X-PERF
Azure-InstanceId
X-Site-Version
Azure-SiteName
Azure-RegionName
Decoy-Debug-Key
Azure-SlotName
Azure-Version
X-NewRelic-App-Data
X-Varnish-Hits
X-Ua
X-OVcl
X-Real-IP
Cache-Key
X-Rendered-As
X-OVcl-Cache
X-S
Origin-Cache-Control
Origin-Edge-Control
Server-Info
X-Pubstack
Time
L5d-Success-Class
X-Redis-Cache
X-Trafficlayer-App-Name
X-Trafficlayer-App-Scope
Now
X-FW-Version
Accept-CH-Lifetime
X-SS-Set-Cookie
X-Upstream-HT
Fastcgi-X-Cache-Version
X-Upstream-CT
OT-Force-Account-Verify
Fastly-SSL
X-Origin-CC
X-Origin-TTL
Access-Control-Request-Headers
X-Cluster-Name
X-APP-VERSION
Mime-Version
X-ServerID
ServedBy
Origin
X-Alternate-Cache-Key
X-Shopify-Stage
X-ShopId
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
Cteonnt-Length
X-FB-TRIP-ID
X-ShardId
X-App-Version
X-UUID
X-Load-Cache
X-Tec-Api-Version
Hostname
X-Tec-Api-Root
X-Parent-Response-Time
X-Tec-Api-Origin
X-GoCache-CacheStatus
X-Rocket-Nginx-Bypass
X-VG-TLSProxy
NtCoent-Length
X-CACHE-KEY
X-Soup
X-VG-WebCache
X-Upstream-Proxy
Accept-Language
Machine
X-Is-Bot
X-Uri
Nel
X-Tb
IBM-Web2-Location
X-ECACHE
Odigeo-Trace-Id
X-CSRF-TOKEN
NGX
X-No-Session
X-Node-Id
X-BYPASS-REASON
X-ProxyCache-Key
X-L-Path
X-MServer
X-Environment-Context
CF-IPCountry
X-ProxyCache-Status
X-Info
X-Nc
X-Tt-Trace-Tag
X-Oneagent-Js-Injection
Cache-Prefix
Uber-Trace-Id
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
A
AsisCache
Apple-News-Services-Request-Url
BehaviorPad-Version
Rt-Proxy-Cache
X-External-Request-Id
X-DPWN-IS-SECURE
X-G
X-Hl-Ver
X-PAYTM-SRV-ID
X-Instart-Info
X-Developer
X-Detected-As
X-Cms-Context
X-CF-Lambda-Version
X-Connection-Hash
X-D
X-Destination
X-Date
X-Region-Sid
X-Request-UUID
X-VG-WebServer
X-Twitter-Response-Tags
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-Worker
X-Trv-Group
X-Transaction
X-Rojux
X-Rewrite-Enabled
X-S-Cookie
X-ScT
X-SRCache-Key
X-Server-Time
X-CF-Lambda-Fn
X-B-Cookie
Node
Mobile-Detection-Method
Rendered-Blocks
Request-Country
ServerName
Request-EU
Meta-Geo-Continent
Memcached
Cross-Origin-Window-Policy
Content-Style-Type
Fly-Cache
Fly-Request-Id
MD5-Digest
GEO-REGION-INFO
T-Server
Viewtype
X-Aed
X-Accel-Expires-Debug
X-AIR-PT
X-Geo
X-ARC
X-Application
X-A-Wwc
X-A-Dgt
X-A
VivaBuild
X-A-Ccd
X-A-Dam
X-A-Dcw
Content-Script-Type
Arc-Country
Request-Time
X-Nginx-Cache
X-B3-Parentspanid
Proxy-Connection
X-B3-SpanId
Backend-Name
X-Endurance-Cache-Level
X-UA
X-SVT-ORM-VERSION
We-Hiring
X-Compress-Hint
X-Cache-Bucket
X-WADP-Cache
Fastly-Soc-X-Request-Id
IsBot
N-Cache
X-Developers
X-Device-Os
X-JWT-State
X-B3-Spanid
X-S-Maxage
X-Is-Gdpr
X-Has-Esi
X-SVT-ORM-RULES
Mail-Subject
X-SIPLIST1
Srv
X-Clara-WADP
X-Amzn-Remapped-Content-Length
X-PHP-Host
User-Cache-Control
Akamai-GRN
X-Distributor
X-Epic-Correlation-Id
X-Distil-CS
X-Dispatch
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Dispatcher-Server
X-Hnp-Log
X-Generated-By
X-Generated-On
X-Geo-Header
X-Fetched-On
CDCHOST
X-Debug-Cache-Expiry
X-Fastly-Cache
X-Eu-Site
X-Webstats-RespID
X-Guploader-Uploadid
X-Auto-Login
X-Azure-Ref
X-Block-Status
X-Amz-Meta-Cache-Control
Wxu-Next-Commit
Wxu-Next-Hostname
Wxu-Next-Region
X-Azure-Ref-OriginShield
X-BBXSRF
X-CGP
X-Clientip
X-GeoIP-City
X-Cdn-Srv
X-Cache-FS-Status
X-Bip
X-C
X-CUA
X-IN-APIGATEWAY
X-NC
X-Service
X-Skip-Cache
X-Server-IP
X-Wikidot-Static-Cache
X-Request-Start
X-Debug-Log
X-Cache-Info
X-Debug-Cookies
X-Thanos
X-Variation
X-Cdn-Origin
X-VC-Cache
X-Var-Ttl
X-User
X-TrackingId
X-Up
X-Reqid
X-Release
X-Li-Fabric
X-Li-Pop
X-LI-Proto
X-Level-Front-Cache
X-Irp-Debug
X-Proxy-Cache-Status
X-IN-APIGATEWAYSSL
X-LI-UUID
X-Gen-Mode
X-Owner
X-Platform-Server
X-Reboot
X-Origin-Expires
X-Origin-Date
X-Wikidot-Backend
X-Magnolia-Registration
X-Hash
X-NX-Host
Pagetype
L
X-Sn-Servicetimems
Is-Eu
PFcat
Platform
RNT-Time
RNT-Machine
Pramga
Heartbleed
HA-Ipaddr
AKAMAI
X-WebServer
Adler-Geo
X-Via-CDN
Content-Disposition
Countrycode
X-Request-URI
Gh-Request-Id
X-We-Are-Hiring
Section-Io-Cache
Ha-Gx-Prefs
Server-Host
Served-By
X-Proxy-Upstream
X-Ratelimit-Limit
SRV
X-Microcachable
X-NWS-UUID-VERIFY
X-VServer
X-App-Name
X-Generated-In
X-Policy
Thinkindot-CacheControl
X-Generation-Time
Kp-EeAlive
X-Urbn-Site-Id
Server-Int
Magicmarker
X-Rebelmouse-Cache-Control
X-Key
Fastly-SWR
X-Rebelmouse-Surrogate-Control
X-Location
X-Servername
X-SD-PageType
X-ElasticPress-Search
Thinkindot-Control
True-Client-Country-4JS
X-Say-Cacheable
Web-Mar-Node
X-Qloud-Router
Locale
W
X-Urbn-Context-Path
Esi-Enabled
X-Method
X-Nginx-Cache-Key
X-SayCDN-TTL
X-Old-Content-Length
X-Lb-Id
Thinkindot-CacheControl-Type
X-Backend-Url
X-Backend-State
X-Backend-Host
X-Swa-Ws
X-Matched-Rule
X-RateLimit-Limit-Second
X-Thinkindot-L3
X-Core-Mission
X-RateLimit-Remaining-Second
Fastly-SIE
SD-X-WS
X-Cache-Id
X-Svr
X-Say-TTL
X-Cdn-Forward
X-Dc
X-Internal-Host
Resin-Trace
X-Cache-URL
Cache-Provider
X-MSEdge-Flight
Server-ID
X-Instart-Isnd
X-ServiceProvider
X-MSEdge-Features
V-Age
X-GEO
X-AWS-Id
Cdn-Request-Time
X-DC
X-VWS-Id
X-FPC
Memory
X-LJ-Flow-ID
X-Scheme
X-Edge-Server
Cdn-Host
X-Cache-Backend
X-Be
REQUESTUUID
X-GDPR
X-Processor
X-Mode
X-Org
X-Request-Time
Group
SS
X-NodeID
X-Pjax-Url
X-Wa
X-ABtesting
X-Hello
X-Servedbyhost
X-Flog
X-Datadome
X-Response-By
Cache-Host
X-Server-W
X-CDN-Forward
X-IPS-LoggedIn
Country-Code
X-Unique-ID
X-SRV
X-VCL-Version
X-Oss-Server-Time
X-Oss-Object-Type
X-Page-Type
X-Oss-Hash-Crc64ecma
Cache-Cookie-Set-Idcheck
X-Oss-Request-Id
Cache-Cookie-Set-From
X-Oss-Storage-Class
X-SN
Cache-Cookie-Set-Lfrom
X-Ms-Request-Id
X-Ms-Version
X-Ruxit-Js-Agent
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Status
X-HS-Status
X-Varnish-Beresp-Grace
X-Oracle-Dms-Rid
X-Routing-Service
X-Proxied
X-Zipkin-Id
X-EC-Lua
X-Webkit-Csp
Lfy
X-Session-Fingerprint
X-Ftr-Request-Id
PICS-Label
X-Tb-Optimization-Total-Bytes-Saved
X-Via-Ucdn
UCS
X-Dynatrace
X-Zone
X-URL
X-Cache-Debug
X-Agile-Id
X-Agile
Ttl
X-COUNTRY
X-Agile-Age
X-GRACE
X-DataStream-Cache-Status
Ajk
SN
Powered-By-ChinaCache
X-Logtrace-Id
X-RateLimit-Reset
X-Ratelimit-Remaining
X-Varnish-Beresp-TTL
X-MP-GENERATED-AT
GeoIP-City
Proxy-Firewall
GeoIp-Country-Code
X-PF-Uncompressing
Geoip-City
X-Webapp-Samesite-None-Activated-N
Geoip-Latitude
GeoIP-Country-Code
X-Pf-Uncompressing
X-7Graus-Varnish-Cache-Control
X-7Graus-Varnish-XKeys
X-Fastly-Country-Code
GeoIP-Latitude
ProcessTime
X-Sucuri-Id
X-Source
X-Logging-Id
Environment
X-ZONE
X-APP
X-Cache-Category-Id
X-CSRF-Token
Powered-By
X-Grey
X-NODE
X-Unique-Id
X-HTML-Minification-Powered-By
XServer
X-Cache-Miss-From
X-Sedo-Request-Id
Cdn
X-Newrelic-Synthetics
X-Ftr-Cache-Host
X-Sucuri-ID
X-Bc
X-CLOUD-TRACE-CONTEXT
Pics-Label
X-Tt-Trace-Host
X-TH-Server
X-Core-Value
X-DataStream-Origin-MEX-Latency
X-Edge
CACHE
CF-Cached-On
M-TraceId
X-DataStream-MidMile-RTT
X-Check-Cacheable
Fastly-Backend-Name
X-Vcl-Version
X-LiteSpeed-Cache-Control
X-Sucuri-Cache
WWW
X-Vdms-Version
X-Aicache-OS
X-Ftr-Backend
X-Dynatrace-Js-Agent
HostName
X-Ftr-Realm
X-Ftr-Dc
X-Ftr-Balancer
X-Ftr-Backend-Server
Cdncip
Requestid
X-Rocket-Build-Number
X-Mid
X-RCS-CacheZone
X-Fastly-Backend-Reqs
X-Sigma-Backend
X-Sigma
X-AK-Request-ID
GW-Server
Cdnsip
Cf-Ipcountry
MIME-Version
X-Planisys-CDN-TTL
X-LAGOON
LB
Pragrma
X-MCACHE
X-Planisys-CDN-Rules
X-Varnish-Ttl
X-Shopify-Generated-Cart-Token
X-Cache-Tag
X-Planisys-CDN-Cache
X-Swift-Error
X-Fstrz
X-FORWARDED-FOR
Amp-Access-Control-Allow-Source-Origin
X-Varnish-Url
X-Secret
X-NGINX-Cache
X-BC
X-ServedByHost
X-TT-LOGID
X-UPSTREAM-Address
X-Litespeed-Cache-Control
X-Gannett-Site-Version
Ohc-Response-Time
Lb
X-RSL
URI
X-DB
X-CDN-Cache
X-WA
X-Cache-Ttl
X-BE
X-RPS
X-Via-NSCOPI
X-Action
X-PJAX-URL
X-DW
X-DI
X-RPM
X-DSS
Dynatrace
X-SaId
X-WR-MODIFICATION
X-Varnish-Cacheable
On-Server
X-ORACLE-APMCS-REQUEST-ID
X-GeoIP-Country-Code
RequestUuid
Host-ID
WZWS-RAY
X-ORACLE-APMCS-TAG
TTL
X-ND-Cache
DataCenter
X-Correlation-ID
CDN
Inserted-Into-Cache-At
User-Agent
X-Fpc
X-Nananana
X-Fastly-Cache-Hits
Xkeyrz
X-Trafficlayer-App-Version
Xkeypdq
X-Proxy-Cacherz
X-Flow-Id
Is-Session-Tracking
Server-Id
X-Upstream-Ht
X-Zalando-Child-Request-Id
X-Upstream-Ct
X-Page-Impression-Id
Get-Access-Time
Correlation-Id
X-Served-From
X-Refresh
Locid
Warning
X-Via-Edge
X-Via-SSL
X-VC
X-SB
X-MID
X-Dw-Trace-Id
X-Gen-Id
X-Akamai-SSL-Client-Sid
X-Cf-Powered-By
SID
X-Amzn-Remapped-Date
X-Amzn-Remapped-Connection
X-Akamai-ERPolicy
X-Akamai-ERRuleID
Who
X-NU-AKA-ACS-Version
X-Pod
X-Req
Thinkindot-Cache-Type
Gannett-Cam-Experience-Id
X-Request-URL
X-Crawler
Processtime
X-Gdpr
X-LiteSpeed-Tag
V-Cache
Xet-Cookie
RequestId
Cneonction
X-MiniProfiler-Ids
HitType
X-ECache
X-Bug-Bounty
X-ServerName
X-Newrelic-App-Data
X-LB-ID