Threat Level: green Handler on Duty: Manuel Humberto Santander Pelaez

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
CF-RAY
CF-Cache-Status
Link
X-Powered-By
X-XSS-Protection
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Alt-Svc
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
Content-Security-Policy-Report-Only
X-Generator
X-Cacheable
X-Cache-Status
X-Permitted-Cross-Domain-Policies
X-Xss-Protection
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Template
X-Language
X-Request-ID
X-Iinfo
Status
X-Content-Security-Policy
Content-Encoding
X-AspNetMvc-Version
X-Buckets
X-Kinja-Server-Push
Xkey
Upgrade
X-Via
Access-Control-Expose-Headers
X-Turbo-Charged-By
Keep-Alive
Access-Control-Max-Age
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Pass-Why
P3p
X-Age
EagleId
X-Backend
X-Envoy-Upstream-Service-Time
X-Robots-Tag
X-Amz-Id-2
X-Amz-Request-Id
X-Page-Speed
X-CDN
X-Ua-Compatible
X-Pingback
X-Server-Powered-By
X-AH-Environment
X-Proxy-Cache
X-UA-Device
X-Hacker
X-Server
Request-Context
X-Nginx-Cache-Status
Grace
X-Swift-SaveTime
X-Swift-CacheTime
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-Cdn
X-LiteSpeed-Cache
Cf-Railgun
Server-Timing
X-Amz-Version-Id
Feature-Policy
X-Server-Id
X-WebKit-CSP
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-OneAgent-JS-Injection
X-Rq
X-Ac
X-Cnection
X-Cloud-Trace-Context
Report-To
EagleEye-TraceId
X-Response-Time
X-Host
X-Backend-Server
Request-Id
X-Node
Content-Location
X-Origin-Cache
X-Readtime
X-Vhost
X-Application-Context
X-Cache-Lookup
X-Dns-Prefetch-Control
X-ORACLE-DMS-ECID
X-Dispatcher
NEL
X-ORACLE-DMS-RID
X-DataDome
X-Ruxit-JS-Agent
X-Rack-Cache
X-Origin-Upstream-Status
Surrogate-Control
X-HW
Allow
Rating
X-Country-Code
X-FTR-Request-ID
X-Clacks-Overhead
X-Country
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Url
X-DynaTrace
X-Instart-Request-ID
Fusion-Source
Fusion-Template-Id
Fusion-Content-Source
Fusion-Content-Id
Fusion-Component-Id
X-MS-InvokeApp
X-Goog-Hash
X-TTL
X-Varnish-TTL
X-Vname
X-TtlSet
X-PC
X-Powered-By-Plesk
Verso
Pinterest-Generated-By
RTSS
Public-Key-Pins
X-Px
Edge-Control
X-VARITI-CCR
X-Mod-Pagespeed
X-CST
X-Recruiting
Display
X-Middleton-Display
X-Middleton-Response
X-B3-TraceId
Response
X-Sol
X-Exp-Id
X-Exp-Variant
X-Kinja-Revision
X-Use-Magma
X-Kinja-Build
X-Cdn-Fetch
X-GoogleNews-Bot
X-Kinja
X-Kinja-Server
X-D2id
Service-Worker-Allowed
X-SharePointHealthScore
SPRequestGuid
X-Ah-Environment
Accept-CH
X-Vcap-Request-Id
X-Version
X-Akam-SW-Version
X-ESI
X-Server-Name
SPRequestDuration
SPIisLatency
MS-Author-Via
X-GitHub-Request-Id
TCN
X-Abt-Application-Version
X-Powered-CMS
X-Navigation-Version
X-Shard
Accept-Ch-Lifetime
Charset
X-Upstream
Fastly-Restarts
X-RateLimit-Remaining
X-Amz-Server-Side-Encryption
X-Trace
AR-PoweredBy
AR-ATIME
AR-CACHE
Nginx-Cache
Ar-Sid
Realpath
X-Amz-Rid
X-Forwarded-Proto
X-Debug
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Aspnetmvc-Version
X-XRDS-Location
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Ezoic-Cdn
Front-End-Https
X-Cached
X-NF-Request-ID
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Generation
AR-Request-ID
Pagespeed
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
MRF-Tech
X-MSEdge-Ref
X-Shield-Request-Id
Access-Control-Request-Method
Arr-Disable-Session-Affinity
X-Country-Code-Real
X-FTR-Expires
X-FTR-Cache-Status
X-VCache
Content-MD5
MicrosoftSharePointTeamServices
Paypal-Debug-Id
X-Id
X-Goog-Storage-Class
X-FTR-Backend-Server
X-FTR-Realm
X-FTR-Balancer
X-FTR-DC
X-FTR-Backend
X-T
X-Amz-Meta-S3cmd-Attrs
X-Fastly-Request-ID
ServerID
S
DynaTrace
X-Via-JSL
X-Varnish-Age
X-Client-IP
X-Content-Type
X-Ser
X-Dw-Request-Base-Id
X-Hits
X-Correlation-Id
X-Amzn-Trace-Id
X-Grace
X-Accel-Expires
Fastcgi-Cache
X-SERVER
Powered
X-DynaTrace-JS-Agent
X-Frontend
X-Vcache
X-Content-Digest
X-DIS-Request-ID
X-FTR-Cache-Host
AMP-Access-Control-Allow-Source-Origin
X-N
PB-PID
PB-RID
Arc-Version
X-Mobile-Rewrite
X-FastCGI-Cache
Edge-Cache-Tag
X-Forwarded-For
Server-Name
X-Logged-In
X-HS-Content-Id
X-HS-Hub-Id
X-RateLimit-Limit
X-Fastcgi-Cache
X-GUploader-UploadID
TP-Cache
TP-L2-Cache
X-Microsite
X-Request-Handler-Origin-Region
X-Server-ID
X-B3-Sampled
X-Request-Received
X-Request-Processing-Time
X-Pinterest-Rid
Pinterest-Version
X-Cache-Age
X-Zen-Fury
X-Kinsta-Cache
X-User-Agent
X-Rid
X-Analytics
Backend-Timing
X-Revision
X-IPLB-Instance
X-Type
X-LB-Cache
X-AppVersion
Healthy
X-Activity-Id
X-Az
X-Whom
FilterID
Retry-After
X-Node-Name
X-Time
X-Cache-Hit
Accept-Ch
X-Srv
X-NWS-LOG-UUID
X-F-Cache
Server-Node
Accept-Charset
Alternate-Protocol
X-Cache-2
X-Kong-Proxy-Latency
X-Erf-Bev-Bev
X-Kong-Upstream-Latency
X-Erf-Bev-Bev-Is-Generated
X-Cache-Rule
Cache-Status
X-Amzn-RequestId
X-Hp-Webp
X-Amz-Apigw-Id
X-B3-Traceid
Cache-Tag
X-Content-Options
X-TA-CDN-Provider
X-Akamai-Edgescape
Surrogate-Key
X-Content-Security-Policy-Report-Only
Refresh
X-Instance
VIX-Pulpo-Upstream-Status
DC
X-Forwarded-Host
VIX-Pulpo-Node
X-Content-Powered-By
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Debug-Info
Access-Control-Allow-Method
X-AOL-HN
X-Webkit-CSP
X-Cluster
Tracecode
X-Jobs
X-Varnish-Grace
X-Framework
X-PHP-Backend
Fastcgi-Useragent
X-Page-Id
X-Request-Guid
X-App-Environment
MS-CV
Source
X-FB-Debug
X-FW-Hash
X-FW-Serve
X-FW-Type
X-FW-Server
X-FW-Static
X-App-Server
X-B
Frame-Options
X-Cache-Operation
X-Esi
X-Mobile-URL
Actual-Object-TTL
X-Hostname
Host
X-Cache-TTL
X-Geo-Country
X-Seen-By
X-Cache-Control
Cleartype
X-Signature
X-B-Cache
X-Acc-Meta-Resource-Type
Accept-CH-Lifetime
X-Cache-Key
X-BCube-Filmed-By
X-Cached-By
X-Host-Name
X-Git-Hash
X-TT
NR-ENABLED
X-Pad
Upgrade-Insecure-Requests
X-Amz-Replication-Status
X-Varnish-Backend
X-Response-Served-From
X-Mobile
NGB
X-Adobe-Content
X-Adobe-Loc
X-TT-TIMESTAMP
X-WebKit-CSP-Report-Only
WPE-Backend
X-ATG-Version
From-Origin
Payment
X-Handled-By
GEO-INFO
Liferay-Portal
X-ProcessESI
X-RemovedCookies
X-Drupal-Cache-Tags
Eomportal-Instance
Webserver
Ms-Operation-Id
X-RTag
X-Tumblr-Pixel-1
X-Tumblr-Pixel-2
X-TX-ID
X-RequestSource
X-Cacheable-TTL
X-UA-Device-Type
Cache-Tv-Group
Filters
X-Status
X-Cache-Remote
X-GeoIP
X-Origin-Server
X-FW-Dynamic
X-Cache-TTL-Remaining
X-WA-Info
X-Daa-Tunnel
X-EdgeConnect-Cache-Status
X-Content-Age
X-Cache-Action
X-Presslabs-Stats
X-Edge-Location
X-Hyper-Cache
X-Storage
X-Wix-Request-Id
Xserver
Viewport
Datacenter
X-Contextid
X-Ttl
Version
X-Region
X-CF-Powered-By
X-Ratelimit-Reset
X-Varnish-Hostname
X-HS-Cache-Config
X-PressLabs-Stats
X-Accel-Buffering
X-Element-Page-Cache
Cache
Ohc-File-Size
X-Akamai-Transformed
Host-Header
PageSpeed
X-Cache-NE
X-ES-SERVER
Load-Balancing
X-RN-RSRV
X-Path-Route
X-Cache-Var-Map
X-Varnish-Server
Meta-Geo
X-Cache-Var
X-Yottaa-Optimizations
S-Cnection
X-IP
X-Yottaa-Metrics
Cache-Name
X-Cache-Server
X-Time-Microsecs
X-Tumblr-Pixel-3
X-TNCMS
X-Loop
X-Cache-Enabled
Cache-Hits
Vix-Hermes-Req-Id
X-PERF
X-Origin-Response-Time
X-Cluster-Node
X-ApacheServer
Cache-Tags
X-Akamai-Request-ID
Ec-Rule-Version
X-Cache-Config
X-Proto
X-Viewer-Country
X-Via-Fastly
X-CS
X-NCache
X-Human
Azure-SlotName
X-OCL
X-From
X-FC-Vary-Parameters
Cache-Key
X-Access
Azure-Version
X-Section
X-Labrador-Cache-Channel
X-Cache-Time
X-PCL
DB-Nickname
X-Proxy-Build
X-CCM
X-Origin
X-R9-Blue-Green-Version
Azure-InstanceId
X-Drupal-Cache-Contexts
Rt-Fastcgi-Cache
Azure-RegionName
Decoy-Debug-TTL
Selected-Fe
X-Cache-Grace
Decoy-Debug-Status
S-Rt
Decoy-Debug-Key
X-Rule
Azure-SiteName
Webcakes-Region
Property-Id
TWC-Connection-Speed
TWC-Device-Class
Mn-Server-Ip
X-Xfnlog-Site
X-Www-Served-By
X-NewRelic-App-Data
TWC-GeoIP-Country
TWC-GeoIP-LatLong
X-Origin-Hint
X-Proxy
X-Varnish-Cache-Hits
X-Akamai-Request-ID2
Webcakes-App-Version
TWC-Privacy
Webcakes-App-Name
X-Web-Node
TWC-Locale-Group
X-Trace-Id
X-Timing-Wait
X-Debug-Cache
X-EIG-Tracking-Id
X-Cache-Host
X-JoinUs
X-Backend-TTL
X-Site-Version
X-UnsetCookies
X-Hit
X-Hosted-By
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Generated
X-Locale
X-Format
X-Upgrade-Enabled
X-Backend-Name
X-Upstream-Proxy
Country
X-Upstream-CT
X-Upstream-HT
Ohc-Cache-HIT
X-Device-Type
Release
X-FireWall-Port
Server-Info
X-Ua
Time
X-Vgn-Hpd-Reason
X-VCT
DSUID
X-S
X-Rendered-As
X-FW-Version
X-Varnish-Hits
Now
X-OVcl-Cache
X-OVcl
Hostname
X-Real-IP
X-NGENIX-Cache
X-Pubstack
OT-Force-Account-Verify
X-HS-Combine-CSS
X-SS-Set-Cookie
Origin-Edge-Control
ServedBy
X-Redis-Cache
Access-Control-Request-Headers
Origin-Cache-Control
Fastcgi-X-Cache-Version
X-Litespeed-Cache
X-VG-TLSProxy
L5d-Success-Class
X-APP-VERSION
X-DataStream-Cache-Status
Origin
X-VG-WebCache
Cteonnt-Length
X-ShardId
X-Sorting-Hat-PodId
X-Shopify-Stage
X-FB-TRIP-ID
X-Sorting-Hat-ShopId
X-ShopId
X-Alternate-Cache-Key
X-NC
X-XRDS-LOCATION
NtCoent-Length
Fastly-SSL
Accept-Language
Machine
X-CSRF-TOKEN
X-Parent-Response-Time
X-Tb
X-App-Version
X-Origin-CC
X-Origin-TTL
X-Cluster-Name
SRV
X-Tt-Trace-Tag
X-UUID
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
X-CACHE-KEY
X-GoCache-CacheStatus
X-L-Path
X-Load-Cache
X-B3-Spanid
X-Environment-Context
X-ECACHE
X-Rocket-Nginx-Bypass
IBM-Web2-Location
X-Soup
X-GEO
X-ServerID
X-No-Session
NGX
X-Nginx-Cache
X-B3-Parentspanid
X-Is-Bot
X-Uri
Nel
Proxy-Connection
X-Magnolia-Registration
CF-IPCountry
Mime-Version
X-Amzn-Remapped-Content-Length
ServerName
Akamai-GRN
Odigeo-Trace-Id
X-Region-Sid
X-Accel-Expires-Debug
Rendered-Blocks
X-Application
X-A-Wwc
Node
X-CF-Lambda-Version
X-A-Ccd
Meta-Geo-Continent
X-A
Mobile-Detection-Method
X-SRCache-Key
X-Aed
Viewtype
T-Server
X-AIR-PT
X-Twitter-Response-Tags
Request-Time
X-Connection-Hash
X-Trv-Group
VivaBuild
Rt-Proxy-Cache
X-MServer
X-B-Cookie
X-Transaction
X-Server-Time
X-CF-Lambda-Fn
Fly-Cache
Fly-Request-Id
X-S-Cookie
Cross-Origin-Window-Policy
Content-Style-Type
GEO-REGION-INFO
Memcached
X-Request-UUID
X-A-Dam
X-Rewrite-Enabled
X-Rojux
X-A-Dcw
Content-Script-Type
Cache-Prefix
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
X-ScT
A
Apple-News-Services-Request-Url
Arc-Country
X-A-Dgt
BehaviorPad-Version
X-ARC
AsisCache
MD5-Digest
X-Node-Id
X-PAYTM-SRV-ID
X-G
X-Destination
X-Worker
X-External-Request-Id
X-DPWN-IS-SECURE
Xc-Version
X-Developer
X-Detected-As
X-Date
X-Generated-By
X-Vtex-Remote-Cache
X-D
X-VG-WebServer
X-Endurance-Cache-Level
X-Vtex-Processado-Em
X-Instart-Info
Backend-Name
X-Oneagent-Js-Injection
X-Mode
X-Cdn-Srv
We-Hiring
Request-Country
Section-Io-Cache
X-Azure-Ref-OriginShield
Request-EU
X-Azure-Ref
X-Fastly-Cache
X-Hl-Ver
X-Cache-Bucket
IsBot
X-Release
X-Origin-Expires
X-B3-SpanId
X-S-Maxage
X-Origin-Date
Mail-Subject
X-SIPLIST1
X-Up
X-VC-Cache
X-LJ-Flow-ID
User-Cache-Control
X-AWS-Id
X-VWS-Id
X-WADP-Cache
X-BBXSRF
Locale
X-We-Are-Hiring
Pramga
X-Compress-Hint
X-IN-APIGATEWAYSSL
X-Thanos
X-Wikidot-Static-Cache
X-App-Name
X-IN-APIGATEWAY
X-Hnp-Log
X-Dc
N-Cache
X-TrackingId
X-Bip
X-Block-Status
X-Swa-Ws
X-Qloud-Router
X-VServer
W
X-Nginx-Cache-Key
X-RateLimit-Remaining-Second
X-Rebelmouse-Cache-Control
X-Var-Ttl
X-Location
X-Method
X-Urbn-Site-Id
X-RateLimit-Limit-Second
Uber-Trace-Id
True-Client-Country-4JS
L
RNT-Time
RNT-Machine
X-Backend-Host
Server-Int
X-Auto-Login
X-Urbn-Context-Path
X-Rebelmouse-Surrogate-Control
X-Backend-Url
Magicmarker
X-Cdn-Origin
X-CUA
X-Skip-Cache
X-Cache-Info
X-SVT-ORM-VERSION
Cdn-Host
X-Sn-Servicetimems
CDCHOST
X-Clientip
X-ElasticPress-Search
X-Device-Os
X-Developers
X-Service
X-Distil-CS
X-Server-IP
X-Edge-Server
X-Clara-WADP
X-Distributor
Cdn-Request-Time
X-Cms-Context
Fastly-Soc-X-Request-Id
Fastly-SIE
Gh-Request-Id
X-Policy
X-SVT-ORM-RULES
X-Wikidot-Backend
X-Gen-Mode
Fastly-SWR
X-Core-Mission
Countrycode
Esi-Enabled
X-Request-Time
X-LI-UUID
X-Li-Pop
X-GeoIP-City
X-LI-Proto
X-GDPR
X-Owner
X-Backend-State
X-Matched-Rule
X-Geo-Header
X-MSEdge-Flight
X-Level-Front-Cache
X-Epic-Correlation-Id
X-C
X-Old-Content-Length
X-Platform-Server
X-Cache-Id
X-Cache-FS-Status
X-Internal-Host
X-Generation-Time
X-Generated-On
X-PHP-Host
X-Li-Fabric
X-Say-Cacheable
X-CGP
X-BYPASS-REASON
Wxu-Next-Region
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
X-Debug-Cookies
X-Debug-Cache-Store
X-Guploader-Uploadid
Wxu-Next-Hostname
X-Amz-Meta-Cache-Control
Ha-Gx-Prefs
Kp-EeAlive
Pagetype
Wxu-Next-Commit
Served-By
X-Debug-Log
X-Dispatch
X-ProxyCache-Key
X-Proxy-Upstream
X-ProxyCache-Status
X-Reqid
X-Webstats-RespID
X-User
X-Proxy-Cache-Status
X-NX-Host
Srv
X-Eu-Site
X-UA
X-Generated-In
X-Irp-Debug
X-Hash
X-WebServer
HA-Ipaddr
Memory
X-Request-URI
PFcat
Is-Eu
Content-Disposition
X-MSEdge-Features
Cache-Provider
X-Request-Start
Platform
V-Age
Web-Mar-Node
Thinkindot-Control
Thinkindot-CacheControl-Type
X-Reboot
Thinkindot-CacheControl
X-Say-TTL
Heartbleed
X-ServiceProvider
X-SayCDN-TTL
X-Variation
X-Via-CDN
X-Servername
X-Thinkindot-L3
Adler-Geo
AKAMAI
X-Trafficlayer-App-Scope
X-Trafficlayer-App-Name
X-Microcachable
X-Fetched-On
X-Has-Esi
X-JWT-State
Server-ID
X-Is-Gdpr
SD-X-WS
X-Org
Server-Host
X-SD-PageType
X-Dispatcher-Server
X-Info
X-Key
Resin-Trace
X-Cdn-Forward
X-Lb-Id
X-Wa
X-FPC
X-Hello
X-COUNTRY
X-ABtesting
X-NWS-UUID-VERIFY
X-Flog
X-Dynatrace-Js-Agent
X-Geo
X-URL
SS
X-Servedbyhost
X-DC
X-DataStream-Origin-MEX-Latency
X-DataStream-MidMile-RTT
X-Response-By
X-Svr
REQUESTUUID
X-Cache-URL
X-Unique-ID
X-IPS-LoggedIn
X-Be
X-Ratelimit-Limit
X-Proxied
X-Routing-Service
X-Zipkin-Id
X-RateLimit-Reset
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-From
Cache-Cookie-Set-Idcheck
X-Instart-Isnd
X-Nc
Country-Code
X-VCL-Version
XServer
X-CDN-Forward
X-Cache-Backend
X-Processor
X-Page-Type
X-Datadome
UCS
X-Scheme
X-NodeID
X-MP-GENERATED-AT
CACHE
X-Pjax-Url
X-Varnish-Beresp-Ttl
Group
X-SRV
X-Oss-Object-Type
Powered-By-ChinaCache
X-Oss-Storage-Class
X-Oss-Request-Id
Ajk
X-Oss-Hash-Crc64ecma
X-SN
X-ZONE
X-Logtrace-Id
X-Oss-Server-Time
X-Ruxit-Js-Agent
PICS-Label
X-Server-W
Dynatrace
X-HTML-Minification-Powered-By
ProcessTime
Cache-Host
Proxy-Firewall
X-Oracle-Dms-Rid
X-Webkit-Csp
X-HS-Status
X-Ftr-Request-Id
X-Tb-Optimization-Total-Bytes-Saved
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
Powered-By
X-Newrelic-Synthetics
X-Dynatrace
Ttl
X-Cache-Category-Id
SN
X-Via-Ucdn
X-Ms-Request-Id
X-Ms-Version
X-Grey
X-GRACE
X-EC-Lua
X-Zone
X-Source
X-Pf-Uncompressing
X-Ratelimit-Remaining
Fastly-Backend-Name
GeoIP-Country-Code
X-FORWARDED-FOR
X-APP
GeoIP-Latitude
Lfy
X-PF-Uncompressing
Geoip-City
Geoip-Latitude
X-Session-Fingerprint
X-TH-Server
GeoIP-City
GeoIp-Country-Code
X-Sucuri-Id
X-Varnish-Beresp-TTL
X-LiteSpeed-Cache-Control
MIME-Version
X-Cache-Debug
X-Agile
X-Agile-Id
X-Agile-Age
X-Check-Cacheable
X-NODE
X-Ftr-Cache-Host
GW-Server
X-Fastly-Country-Code
X-BC
X-Tt-Trace-Host
X-LAGOON
Cdn
X-7Graus-Varnish-Cache-Control
Environment
X-7Graus-Varnish-XKeys
X-Logging-Id
LB
X-RCS-CacheZone
X-Bc
X-Secret
Pics-Label
CF-Cached-On
X-Varnish-Url
X-Edge
X-Cache-Miss-From
X-Aicache-OS
X-Gannett-Site-Version
X-Sedo-Request-Id
X-PJAX-URL
WWW
WZWS-RAY
M-TraceId
X-Ftr-Realm
X-Unique-Id
X-Ftr-Backend
X-Ftr-Balancer
X-Ftr-Backend-Server
X-CSRF-Token
X-Ftr-Dc
Ohc-Response-Time
X-Varnish-Cacheable
X-Mid
On-Server
X-Cache-Tag
Requestid
X-CDN-Cache
X-Akamai-SSL-Client-Sid
Cf-Ipcountry
X-Sucuri-ID
X-AK-Request-ID
X-MCACHE
Cdnsip
User-Agent
X-Varnish-Ttl
X-Cache-Ttl
DataCenter
X-GeoIP-Country-Code
X-Fastly-Backend-Reqs
X-UPSTREAM-Address
X-Vcl-Version
X-Core-Value
Cdncip
Amp-Access-Control-Allow-Source-Origin
X-TT-LOGID
X-Sucuri-Cache
X-Vdms-Version
CDN
Inserted-Into-Cache-At
X-Litespeed-Cache-Control
Lb
X-NGINX-Cache
X-RPS
X-Rocket-Build-Number
X-RSL
X-Sigma
X-Sigma-Backend
X-Fstrz
X-RPM
X-DW
X-Action
X-DB
X-DI
X-DSS
X-BE
Xkeyrz
X-NU-AKA-ACS-Version
URI
SID
X-Proxy-Cacherz
HostName
X-Swift-Error
Pragrma
X-Crawler
RequestUuid
Who
Host-ID
X-Render-Time
X-Shopify-Generated-Cart-Token
X-Correlation-ID
Get-Access-Time
X-WR-MODIFICATION
X-Page-Impression-Id
X-Via-NSCOPI
X-Fpc
Warning
X-Refresh
X-Planisys-CDN-Cache
X-Flow-Id
X-Planisys-CDN-TTL
Xkeypdq
X-Fastly-Cache-Hits
X-LB-ID
Server-Id
X-ServedByHost
X-Planisys-CDN-Rules
X-WA
Is-Session-Tracking
X-Zalando-Child-Request-Id
FNAC-ModuleRouting
X-Cdn-Request-ID
X-Micro-Cache
X-SB
X-Nananana
X-VC
X-MID
X-TIME
Correlation-Id
X-FE
X-Cf-Powered-By
X-Newrelic-App-Data
HitType
X-ECache
X-ServerName
X-Bug-Bounty
X-Trafficlayer-App-Version
X-Akamai-ERRuleID
X-Amzn-Remapped-Connection
X-LiteSpeed-Tag
X-Akamai-ERPolicy
X-Amzn-Remapped-Date
TTL
X-Served-From
V-Cache
RequestId
X-Via-SSL
X-Request-URL
Xet-Cookie
X-Via-Edge
X-Gdpr
X-Gen-Id
X-MiniProfiler-Ids
Cneonction
X-Fe
X-Dw-Trace-Id
Processtime