Threat Level: green Handler on Duty: Manuel Humberto Santander Pelaez

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
CF-RAY
CF-Cache-Status
Link
X-Powered-By
ETag
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Alt-Svc
Access-Control-Allow-Credentials
X-Runtime
X-Xss-Protection
X-Drupal-Cache
X-Adblock-Key
X-Check
Content-Security-Policy-Report-Only
X-Generator
X-Cacheable
X-Cache-Status
X-Permitted-Cross-Domain-Policies
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Template
X-Language
X-Iinfo
X-Content-Security-Policy
Status
Content-Encoding
X-FRAME-OPTIONS
X-AspNetMvc-Version
X-Buckets
X-Request-ID
X-Kinja-Server-Push
Xkey
Upgrade
X-Via
Access-Control-Expose-Headers
X-Turbo-Charged-By
Access-Control-Max-Age
Keep-Alive
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Pass-Why
X-Age
EagleId
X-Backend
X-Envoy-Upstream-Service-Time
X-Robots-Tag
X-Ua-Compatible
X-Amz-Id-2
X-Amz-Request-Id
X-Page-Speed
X-Pingback
X-Server-Powered-By
X-AH-Environment
X-Server
X-Proxy-Cache
X-UA-Device
X-Hacker
X-CDN
Request-Context
X-Nginx-Cache-Status
X-Swift-SaveTime
X-Swift-CacheTime
Grace
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-Cdn
P3p
X-LiteSpeed-Cache
Cf-Railgun
Server-Timing
Feature-Policy
X-Amz-Version-Id
X-Device
X-WebKit-CSP
X-Server-Id
X-OneAgent-JS-Injection
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Rq
X-Ac
X-Cnection
EagleEye-TraceId
Report-To
X-Cloud-Trace-Context
X-Response-Time
Request-Id
X-Backend-Server
X-Host
Content-Location
X-Node
X-Readtime
X-Origin-Cache
X-Vhost
X-Cache-Lookup
X-Application-Context
X-ORACLE-DMS-ECID
X-DataDome
X-Dispatcher
X-Ruxit-JS-Agent
NEL
X-ORACLE-DMS-RID
X-Rack-Cache
X-Origin-Upstream-Status
X-HW
Surrogate-Control
X-Dns-Prefetch-Control
Rating
X-Country-Code
X-Clacks-Overhead
Allow
X-Country
X-Url
X-FTR-Request-ID
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-DynaTrace
X-MS-InvokeApp
X-Instart-Request-ID
Fusion-Template-Id
Fusion-Content-Id
Fusion-Component-Id
Fusion-Content-Source
Fusion-Source
X-Goog-Hash
X-PC
X-Vname
X-TtlSet
X-Varnish-TTL
X-B3-TraceId
X-TTL
Pinterest-Generated-By
Verso
X-Powered-By-Plesk
Public-Key-Pins
X-Px
RTSS
Edge-Control
X-Mod-Pagespeed
X-Middleton-Response
X-Middleton-Display
X-ESI
Display
Response
X-Sol
X-Ah-Environment
X-VARITI-CCR
X-Kinja-Build
X-Exp-Variant
SPRequestGuid
X-Cdn-Fetch
X-Exp-Id
X-GoogleNews-Bot
X-Use-Magma
X-Kinja-Revision
X-Kinja
X-Kinja-Server
X-SharePointHealthScore
X-D2id
Accept-Ch-Lifetime
X-Recruiting
X-Akam-SW-Version
X-CST
Service-Worker-Allowed
X-Vcap-Request-Id
SPIisLatency
SPRequestDuration
X-Version
X-Server-Name
X-GitHub-Request-Id
TCN
X-Abt-Application-Version
X-Powered-CMS
MS-Author-Via
X-Navigation-Version
X-Trace
X-Shard
Charset
X-Debug
Nginx-Cache
Fastly-Restarts
X-Aspnetmvc-Version
Realpath
X-Amz-Server-Side-Encryption
X-Amz-Rid
X-RateLimit-Remaining
X-Upstream
AR-CACHE
Ar-Sid
AR-ATIME
AR-PoweredBy
Accept-CH
X-Forwarded-Proto
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Ezoic-Cdn
X-NF-Request-ID
Front-End-Https
X-Cached
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-MSEdge-Ref
DynaTrace
Access-Control-Request-Method
Arr-Disable-Session-Affinity
Pagespeed
AR-Request-ID
X-Shield-Request-Id
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
Content-MD5
X-VCache
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Expires
MicrosoftSharePointTeamServices
X-XRDS-Location
S
X-Amz-Meta-S3cmd-Attrs
X-T
X-Goog-Storage-Class
X-Fastly-Request-ID
X-Id
X-FTR-DC
Paypal-Debug-Id
X-FTR-Balancer
X-FTR-Backend
X-FTR-Backend-Server
X-FTR-Realm
X-DynaTrace-JS-Agent
X-Varnish-Age
X-Ser
ServerID
Accept-Ch
X-Via-JSL
X-Client-IP
X-Grace
X-Content-Type
X-Accel-Expires
X-Correlation-Id
X-Dw-Request-Base-Id
Edge-Cache-Tag
X-Forwarded-For
X-Hits
Fastcgi-Cache
X-Amzn-Trace-Id
X-Fastcgi-Cache
Powered
X-Frontend
X-DIS-Request-ID
X-Content-Digest
AMP-Access-Control-Allow-Source-Origin
X-N
X-FTR-Cache-Host
PB-PID
X-HS-Content-Id
X-HS-Hub-Id
PB-RID
X-Mobile-Rewrite
Arc-Version
Pinterest-Version
X-Pinterest-Rid
X-Vcache
X-Logged-In
Server-Name
X-Server-ID
TP-L2-Cache
TP-Cache
X-Request-Received
X-Request-Processing-Time
X-Request-Handler-Origin-Region
X-Microsite
X-Kinsta-Cache
X-GUploader-UploadID
X-Cache-Hit
X-FastCGI-Cache
X-Zen-Fury
X-Time
X-LB-Cache
X-IPLB-Instance
X-Rid
Healthy
X-Analytics
Backend-Timing
X-Revision
X-Type
X-Cache-Age
Retry-After
X-User-Agent
X-Az
X-Activity-Id
X-AppVersion
X-Whom
X-Srv
X-B3-Sampled
X-Node-Name
FilterID
X-RateLimit-Limit
Server-Node
X-NWS-LOG-UUID
X-Hp-Webp
Cache-Tag
Alternate-Protocol
Accept-Charset
X-SERVER
X-F-Cache
Cache-Status
X-Akamai-Edgescape
X-Content-Options
X-Webkit-CSP
X-Cache-Rule
X-Content-Security-Policy-Report-Only
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
NR-ENABLED
X-Content-Powered-By
X-Amzn-RequestId
X-Cluster
X-Amz-Apigw-Id
X-Kong-Upstream-Latency
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Debug-Info
X-Instance
DC
X-Kong-Proxy-Latency
X-Tumblr-Pixel
X-Cache-2
X-Tumblr-User
X-Tumblr-Pixel-0
Tracecode
X-AOL-HN
X-FB-Debug
MS-CV
Access-Control-Allow-Method
X-Varnish-Grace
X-Jobs
Refresh
X-App-Environment
X-Page-Id
X-PHP-Backend
X-Forwarded-Host
Surrogate-Key
X-Framework
Source
Fastcgi-Useragent
X-B
X-Request-Guid
Actual-Object-TTL
X-App-Server
X-Cache-TTL
Host
X-Cache-Operation
X-Mobile-URL
X-Seen-By
X-FW-Type
X-FW-Serve
Frame-Options
X-FW-Hash
X-FW-Static
X-FW-Server
X-Cache-Control
X-TA-CDN-Provider
X-Geo-Country
X-Cached-By
X-Hostname
Cleartype
X-Host-Name
X-Cache-Key
X-Pad
X-Signature
X-B-Cache
Upgrade-Insecure-Requests
X-Git-Hash
X-BCube-Filmed-By
X-Element-Page-Cache
X-Mobile
X-Response-Served-From
X-WebKit-CSP-Report-Only
NGB
Xserver
X-Varnish-Backend
X-ATG-Version
X-Ttl
WPE-Backend
X-UA-Device-Type
X-RequestSource
X-TT
X-Tumblr-Pixel-1
X-RemovedCookies
X-Tumblr-Pixel-2
X-ProcessESI
GEO-INFO
Webserver
X-Drupal-Cache-Tags
X-Handled-By
X-GeoIP
X-Daa-Tunnel
X-HS-Cache-Config
X-Cacheable-TTL
X-Adobe-Content
Eomportal-Instance
X-Origin-Server
X-Amz-Replication-Status
Payment
X-Adobe-Loc
From-Origin
Ms-Operation-Id
X-RTag
Filters
Cache-Tv-Group
X-TT-TIMESTAMP
X-EdgeConnect-Cache-Status
X-TX-ID
X-Cache-Remote
X-XRDS-LOCATION
X-Cache-TTL-Remaining
X-Status
X-Presslabs-Stats
X-Wix-Request-Id
Datacenter
X-Esi
X-FW-Dynamic
Liferay-Portal
Cache
X-WA-Info
X-Acc-Meta-Resource-Type
X-Hyper-Cache
X-Edge-Location
X-Cache-Action
X-Region
Version
X-Contextid
X-Ratelimit-Reset
Viewport
X-Content-Age
X-Cache-NE
X-B3-Traceid
X-Varnish-Hostname
X-CF-Powered-By
PageSpeed
X-PressLabs-Stats
X-Akamai-Transformed
X-Storage
X-Cache-Server
X-HS-Combine-CSS
Ohc-File-Size
X-Varnish-Server
X-Cache-Var-Map
Accept-CH-Lifetime
X-Accel-Buffering
X-Path-Route
X-ES-SERVER
Load-Balancing
Meta-Geo
X-RN-RSRV
X-Cache-Var
X-Xfnlog-Site
Host-Header
X-IP
X-Via-Fastly
X-Viewer-Country
X-Cache-Enabled
X-OCL
Webcakes-App-Version
Webcakes-Region
X-Yottaa-Optimizations
X-Cache-Time
X-Yottaa-Metrics
TWC-GeoIP-Country
X-PCL
Cache-Tags
DB-Nickname
Country
Cache-Name
Property-Id
Release
TWC-Locale-Group
TWC-Privacy
TWC-GeoIP-LatLong
TWC-Device-Class
TWC-Connection-Speed
Webcakes-App-Name
X-Debug-Cache
X-Origin
X-Proto
Vix-Hermes-Req-Id
X-NCache
X-CCM
X-Proxy
X-Cache-Config
X-Varnish-Cache-Hits
X-UnsetCookies
X-Tumblr-Pixel-3
X-TNCMS
X-Loop
X-Origin-Hint
X-Device-Type
X-Section
X-Timing-Wait
X-Rule
X-Backend-Name
X-EIG-Tracking-Id
X-Proxy-Build
Mn-Server-Ip
X-Drupal-Cache-Contexts
X-Cluster-Node
X-VCT
Ec-Rule-Version
X-Upgrade-Enabled
X-Cache-Grace
X-Www-Served-By
X-Vgn-Hpd-Reason
Rt-Fastcgi-Cache
X-NGENIX-Cache
X-Akamai-Request-ID
X-Access
X-From
X-JoinUs
X-Hosted-By
X-Cache-Host
X-Labrador-Cache-Channel
Cache-Hits
S-Rt
X-FC-Vary-Parameters
Selected-Fe
X-CS
X-Origin-Response-Time
X-Human
DSUID
S-Cnection
X-FireWall-Port
X-Generated
X-Backend-TTL
X-Hit
X-Web-Node
X-Varnish-Hits
X-Goog-Meta-Goog-Reserved-File-Mtime
X-ApacheServer
X-Akamai-Request-ID2
Ohc-Cache-HIT
X-Site-Version
X-Locale
X-R9-Blue-Green-Version
X-PERF
X-Format
Azure-InstanceId
X-Time-Microsecs
Azure-RegionName
Azure-SiteName
Azure-Version
Azure-SlotName
X-Trace-Id
X-Ua
Decoy-Debug-Key
Decoy-Debug-Status
X-NewRelic-App-Data
Decoy-Debug-TTL
X-OVcl-Cache
Cache-Key
X-Rendered-As
X-OVcl
X-S
Origin-Edge-Control
X-Real-IP
Origin-Cache-Control
Time
Server-Info
X-Pubstack
L5d-Success-Class
X-Redis-Cache
X-FW-Version
Now
X-Trafficlayer-App-Name
X-SS-Set-Cookie
X-Litespeed-Cache
X-Trafficlayer-App-Scope
X-Upstream-HT
Fastcgi-X-Cache-Version
X-Upstream-CT
OT-Force-Account-Verify
X-Origin-TTL
X-Origin-CC
Fastly-SSL
Mime-Version
X-Cluster-Name
Access-Control-Request-Headers
X-APP-VERSION
ServedBy
X-ServerID
X-Shopify-Stage
X-Sorting-Hat-ShopId
X-App-Version
X-Sorting-Hat-PodId
X-Alternate-Cache-Key
Origin
X-ShardId
Cteonnt-Length
X-ShopId
X-FB-TRIP-ID
X-Parent-Response-Time
X-Tec-Api-Root
X-Tec-Api-Origin
X-Tec-Api-Version
X-Load-Cache
X-UUID
Hostname
NtCoent-Length
X-VG-TLSProxy
X-Soup
X-VG-WebCache
X-Rocket-Nginx-Bypass
X-GoCache-CacheStatus
X-CACHE-KEY
X-Upstream-Proxy
Machine
X-Is-Bot
Accept-Language
X-Tb
X-Uri
Nel
IBM-Web2-Location
NGX
Odigeo-Trace-Id
X-ECACHE
X-CSRF-TOKEN
X-Environment-Context
X-Node-Id
X-L-Path
X-MServer
X-Info
CF-IPCountry
X-ProxyCache-Key
X-ProxyCache-Status
X-BYPASS-REASON
X-Tt-Trace-Tag
X-Oneagent-Js-Injection
X-No-Session
Content-Script-Type
Cache-Prefix
Cross-Origin-Window-Policy
Fly-Request-Id
AsisCache
Arc-Country
X-B3-Parentspanid
A
Apple-News-Services-Host
Uber-Trace-Id
Apple-News-Services-Handled
Content-Style-Type
Proxy-Connection
Request-Time
BehaviorPad-Version
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Fly-Cache
X-Geo
X-VG-WebServer
X-Vtex-Processado-Em
X-Twitter-Response-Tags
X-Trv-Group
X-Transaction
X-Detected-As
X-Vtex-Remote-Cache
X-Destination
X-Connection-Hash
X-CF-Lambda-Fn
Xc-Version
X-Worker
X-Date
X-D
X-SRCache-Key
X-Developer
X-Hl-Ver
X-Rewrite-Enabled
X-Instart-Info
X-PAYTM-SRV-ID
X-Request-UUID
X-Region-Sid
X-G
X-Rojux
X-ScT
X-Server-Time
X-DPWN-IS-SECURE
X-S-Cookie
X-External-Request-Id
X-B3-SpanId
X-CF-Lambda-Version
ServerName
Rt-Proxy-Cache
Request-EU
T-Server
Viewtype
X-A-Ccd
VivaBuild
Request-Country
Rendered-Blocks
Memcached
MD5-Digest
GEO-REGION-INFO
Meta-Geo-Continent
X-Nginx-Cache
Node
Mobile-Detection-Method
X-A-Dam
X-A
X-A-Dcw
X-Accel-Expires-Debug
X-AIR-PT
X-Application
X-B-Cookie
X-ARC
X-NC
X-Aed
X-A-Wwc
X-A-Dgt
Backend-Name
X-Cdn-Srv
X-Cache-Bucket
IsBot
X-Clara-WADP
X-Compress-Hint
X-S-Maxage
X-WADP-Cache
X-SIPLIST1
X-Device-Os
X-Cms-Context
We-Hiring
X-Nc
X-UA
X-Amzn-Remapped-Content-Length
Mail-Subject
Srv
X-B3-Spanid
User-Cache-Control
Akamai-GRN
X-PHP-Host
X-Endurance-Cache-Level
Platform
X-Distributor
L
X-Epic-Correlation-Id
Pramga
X-Distil-CS
RNT-Machine
X-Developers
X-Dispatch
X-Dispatcher-Server
X-Hash
X-Has-Esi
N-Cache
X-Generated-By
X-Fastly-Cache
X-Hnp-Log
X-NX-Host
X-Eu-Site
X-GeoIP-City
PFcat
Pagetype
RNT-Time
X-Guploader-Uploadid
X-Debug-Cache-Expiry
X-Sn-Servicetimems
X-Bip
Wxu-Next-Region
Wxu-Next-Hostname
X-BBXSRF
X-Backend-Url
X-Amz-Meta-Cache-Control
X-Azure-Ref
X-Azure-Ref-OriginShield
X-Backend-Host
Wxu-Next-Commit
X-Cache-FS-Status
X-Debug-Cache-Fetch
Served-By
Section-Io-Cache
X-Debug-Cache-Store
X-Gen-Mode
X-Proxy-Upstream
X-Request-URI
X-CGP
X-Clientip
X-CUA
X-Proxy-Cache-Status
X-IN-APIGATEWAYSSL
X-SVT-ORM-RULES
X-Skip-Cache
Adler-Geo
X-SVT-ORM-VERSION
X-Thanos
X-Service
X-Server-IP
X-Release
X-Reqid
X-Request-Start
X-Block-Status
X-TrackingId
X-Via-CDN
X-Webstats-RespID
X-WebServer
X-Wikidot-Backend
X-Wikidot-Static-Cache
CDCHOST
X-We-Are-Hiring
X-VC-Cache
X-Up
X-User
X-Var-Ttl
X-Variation
X-Cache-Info
X-Platform-Server
X-Li-Fabric
X-JWT-State
X-Li-Pop
X-LI-Proto
X-LI-UUID
X-Is-Gdpr
Gh-Request-Id
X-Auto-Login
X-IN-APIGATEWAY
HA-Ipaddr
Ha-Gx-Prefs
X-Irp-Debug
Fastly-Soc-X-Request-Id
X-ElasticPress-Search
X-Origin-Expires
X-Owner
X-Debug-Cookies
X-Cdn-Origin
X-Origin-Date
X-Old-Content-Length
Countrycode
X-Location
X-Magnolia-Registration
X-Debug-Log
Is-Eu
X-Ratelimit-Limit
SRV
X-NWS-UUID-VERIFY
X-Nginx-Cache-Key
X-Method
X-Cache-Id
X-App-Name
Esi-Enabled
X-Reboot
X-Svr
Content-Disposition
X-VServer
Heartbleed
SD-X-WS
Web-Mar-Node
X-Policy
X-Level-Front-Cache
X-Generated-In
X-SD-PageType
Magicmarker
X-Servername
True-Client-Country-4JS
AKAMAI
X-Geo-Header
X-Lb-Id
X-RateLimit-Limit-Second
X-Key
X-Generated-On
X-Generation-Time
X-Fetched-On
Server-Host
X-Say-TTL
X-Say-Cacheable
X-Swa-Ws
X-Core-Mission
X-C
X-Qloud-Router
X-SayCDN-TTL
Fastly-SWR
X-Backend-State
Fastly-SIE
X-Rebelmouse-Surrogate-Control
W
Server-Int
X-RateLimit-Remaining-Second
Kp-EeAlive
X-Rebelmouse-Cache-Control
X-Microcachable
X-Dc
X-Cdn-Forward
V-Age
X-Instart-Isnd
Cache-Provider
X-Internal-Host
Locale
Server-ID
X-Urbn-Site-Id
X-Thinkindot-L3
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-Urbn-Context-Path
X-MSEdge-Flight
Resin-Trace
X-Cache-URL
X-MSEdge-Features
Thinkindot-Control
X-Matched-Rule
X-GEO
Cdn-Request-Time
X-LJ-Flow-ID
X-DC
Cdn-Host
Memory
X-Edge-Server
X-AWS-Id
X-ServiceProvider
X-VWS-Id
X-FPC
X-Cache-Backend
X-GDPR
X-Scheme
X-Processor
X-Be
X-Mode
X-Request-Time
X-Org
REQUESTUUID
Group
X-Flog
SS
X-NodeID
X-Servedbyhost
X-ABtesting
X-Wa
X-Hello
X-Pjax-Url
X-Datadome
X-Server-W
X-Response-By
Cache-Host
X-CDN-Forward
X-IPS-LoggedIn
X-Unique-ID
Country-Code
X-Page-Type
X-VCL-Version
X-SN
X-Oss-Storage-Class
X-Ms-Version
X-Ms-Request-Id
X-Oss-Request-Id
Cache-Cookie-Set-From
X-Oss-Server-Time
Cache-Cookie-Set-Lfrom
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
Cache-Cookie-Set-Idcheck
X-Ruxit-Js-Agent
X-HS-Status
X-Varnish-Beresp-Status
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Grace
X-Oracle-Dms-Rid
X-Proxied
X-Routing-Service
X-Zipkin-Id
X-Webkit-Csp
X-EC-Lua
UCS
X-Ftr-Request-Id
X-Session-Fingerprint
Lfy
X-Via-Ucdn
X-SRV
X-Tb-Optimization-Total-Bytes-Saved
PICS-Label
X-Dynatrace
X-Zone
X-Agile-Age
X-Agile-Id
X-Cache-Debug
X-Agile
X-COUNTRY
X-URL
Ttl
X-GRACE
X-DataStream-Cache-Status
X-Logtrace-Id
SN
Ajk
Powered-By-ChinaCache
X-RateLimit-Reset
X-Ratelimit-Remaining
X-Varnish-Beresp-TTL
X-MP-GENERATED-AT
X-7Graus-Varnish-XKeys
Proxy-Firewall
X-7Graus-Varnish-Cache-Control
GeoIP-City
X-PF-Uncompressing
GeoIP-Country-Code
GeoIP-Latitude
X-Webapp-Samesite-None-Activated-N
Geoip-Latitude
X-Pf-Uncompressing
X-Fastly-Country-Code
Geoip-City
GeoIp-Country-Code
X-Sucuri-Id
ProcessTime
X-Source
X-ZONE
X-Sedo-Request-Id
X-Cache-Miss-From
Powered-By
Environment
X-Grey
X-Cache-Category-Id
X-APP
X-Logging-Id
X-CSRF-Token
X-HTML-Minification-Powered-By
X-NODE
X-Unique-Id
XServer
X-Newrelic-Synthetics
Cdn
X-Ftr-Cache-Host
X-Sucuri-ID
X-Bc
X-CLOUD-TRACE-CONTEXT
X-Tt-Trace-Host
X-TH-Server
X-Check-Cacheable
Fastly-Backend-Name
CACHE
Pics-Label
CF-Cached-On
M-TraceId
X-Edge
X-DataStream-Origin-MEX-Latency
X-Vcl-Version
X-DataStream-MidMile-RTT
X-LiteSpeed-Cache-Control
X-Vdms-Version
WWW
X-Core-Value
X-Aicache-OS
X-Sucuri-Cache
HostName
X-Ftr-Balancer
X-Ftr-Backend
X-Ftr-Dc
X-Dynatrace-Js-Agent
X-Ftr-Realm
X-Ftr-Backend-Server
GW-Server
X-RCS-CacheZone
X-Mid
Cdnsip
X-Sigma-Backend
X-Sigma
X-AK-Request-ID
Cdncip
X-Rocket-Build-Number
Requestid
X-Fastly-Backend-Reqs
MIME-Version
Cf-Ipcountry
X-Cache-Tag
Pragrma
X-Fstrz
X-LAGOON
X-MCACHE
LB
X-FORWARDED-FOR
X-Varnish-Ttl
X-Shopify-Generated-Cart-Token
Amp-Access-Control-Allow-Source-Origin
X-Secret
X-UPSTREAM-Address
X-Varnish-Url
X-BC
X-ServedByHost
X-Gannett-Site-Version
X-NGINX-Cache
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Via-NSCOPI
X-TT-LOGID
X-Planisys-CDN-TTL
X-Litespeed-Cache-Control
Ohc-Response-Time
X-Swift-Error
Lb
X-BE
X-DSS
X-DB
X-PJAX-URL
X-DW
X-Action
X-DI
X-RPM
URI
X-RSL
X-WA
X-RPS
X-CDN-Cache
X-Cache-Ttl
X-ORACLE-APMCS-REQUEST-ID
Dynatrace
X-ORACLE-APMCS-TAG
X-SaId
X-ND-Cache
WZWS-RAY
On-Server
X-WR-MODIFICATION
TTL
RequestUuid
X-Varnish-Cacheable
X-GeoIP-Country-Code
Host-ID
X-Correlation-ID
DataCenter
X-Page-Impression-Id
Is-Session-Tracking
Inserted-Into-Cache-At
X-Proxy-Cacherz
X-Flow-Id
User-Agent
CDN
X-Nananana
Xkeyrz
X-Fastly-Cache-Hits
Xkeypdq
Server-Id
Get-Access-Time
X-Fpc
X-Zalando-Child-Request-Id
X-Upstream-Ct
X-Upstream-Ht
X-Refresh
Warning
X-Gen-Id
X-Trafficlayer-App-Version
Locid
X-VC
X-SB
X-MID
X-Dw-Trace-Id
X-Via-Edge
X-Via-SSL
X-Served-From
Correlation-Id
X-Cf-Powered-By
X-Akamai-SSL-Client-Sid
X-Pod
X-Req
X-ECache
X-Amzn-Remapped-Date
X-Akamai-ERRuleID
X-Amzn-Remapped-Connection
X-Akamai-ERPolicy
Gannett-Cam-Experience-Id
X-NU-AKA-ACS-Version
Who
Xet-Cookie
X-Request-URL
X-Newrelic-App-Data
X-MiniProfiler-Ids
V-Cache
Cneonction
SID
RequestId
X-LiteSpeed-Tag
X-Bug-Bounty
Processtime
X-Crawler
X-ServerName
X-LB-ID
X-Gdpr
HitType