Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
CF-RAY
CF-Cache-Status
Link
X-Powered-By
X-XSS-Protection
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Alt-Svc
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
Content-Security-Policy-Report-Only
X-Generator
X-Cacheable
X-Cache-Status
X-Permitted-Cross-Domain-Policies
X-Xss-Protection
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Template
X-Language
X-Iinfo
Status
X-Content-Security-Policy
Content-Encoding
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Request-ID
X-Buckets
X-Kinja-Server-Push
Xkey
Upgrade
X-Via
Access-Control-Expose-Headers
X-Turbo-Charged-By
Keep-Alive
Access-Control-Max-Age
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Pass-Why
P3p
X-Age
EagleId
X-Backend
X-Envoy-Upstream-Service-Time
X-Robots-Tag
X-Amz-Request-Id
X-Amz-Id-2
X-Page-Speed
X-CDN
X-Ua-Compatible
X-Pingback
X-Server-Powered-By
X-Proxy-Cache
X-UA-Device
X-Hacker
X-AH-Environment
X-Server
Request-Context
X-Nginx-Cache-Status
X-Swift-CacheTime
X-Swift-SaveTime
Grace
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-Cdn
X-LiteSpeed-Cache
Cf-Railgun
Server-Timing
X-Amz-Version-Id
Feature-Policy
X-WebKit-CSP
X-Device
X-Server-Id
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-OneAgent-JS-Injection
X-Rq
X-Ac
X-Cnection
Report-To
X-Cloud-Trace-Context
EagleEye-TraceId
X-Response-Time
X-Backend-Server
Request-Id
X-Host
X-Node
Content-Location
X-Origin-Cache
X-Readtime
X-Vhost
X-Application-Context
X-Cache-Lookup
X-Dns-Prefetch-Control
X-ORACLE-DMS-ECID
X-Dispatcher
NEL
X-DataDome
X-Ruxit-JS-Agent
X-ORACLE-DMS-RID
X-Origin-Upstream-Status
X-Rack-Cache
Surrogate-Control
X-HW
Allow
Rating
X-Country-Code
X-Clacks-Overhead
X-FTR-Request-ID
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Country
X-Url
X-DynaTrace
X-Instart-Request-ID
Fusion-Template-Id
Fusion-Source
Fusion-Content-Source
Fusion-Content-Id
Fusion-Component-Id
X-MS-InvokeApp
X-TTL
X-Goog-Hash
X-PC
X-Vname
X-TtlSet
X-Varnish-TTL
X-Ah-Environment
Verso
X-Powered-By-Plesk
RTSS
Public-Key-Pins
Pinterest-Generated-By
X-Px
X-Mod-Pagespeed
Edge-Control
X-VARITI-CCR
X-Middleton-Response
X-Middleton-Display
Display
Response
X-Sol
X-CST
X-Recruiting
X-D2id
X-Use-Magma
X-Exp-Id
X-GoogleNews-Bot
X-Cdn-Fetch
X-Kinja-Server
X-Kinja
X-Kinja-Build
X-Kinja-Revision
X-Exp-Variant
Service-Worker-Allowed
X-SharePointHealthScore
SPRequestGuid
X-B3-TraceId
X-Akam-SW-Version
X-Vcap-Request-Id
X-Version
X-ESI
Accept-CH
SPIisLatency
SPRequestDuration
X-GitHub-Request-Id
TCN
X-Abt-Application-Version
X-Powered-CMS
X-Navigation-Version
MS-Author-Via
X-Server-Name
X-Shard
Accept-Ch-Lifetime
X-Trace
Charset
Fastly-Restarts
X-RateLimit-Remaining
X-Upstream
X-Amz-Server-Side-Encryption
Nginx-Cache
X-Debug
X-Amz-Rid
AR-ATIME
AR-CACHE
AR-PoweredBy
Ar-Sid
X-SRCache-Fetch-Status
X-Forwarded-Proto
X-SRCache-Store-Status
Realpath
X-Aspnetmvc-Version
X-Ezoic-Cdn
Front-End-Https
X-Cached
X-XRDS-Location
X-NF-Request-ID
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Metageneration
X-MSEdge-Ref
Pagespeed
X-VCache
AR-Request-ID
X-Shield-Request-Id
Access-Control-Request-Method
X-Mrf-Item-Lastmod
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-Mrf-Section-Lastmod
Arr-Disable-Session-Affinity
X-FTR-Cache-Status
X-Country-Code-Real
X-FTR-Expires
Content-MD5
MicrosoftSharePointTeamServices
Paypal-Debug-Id
X-Amz-Meta-S3cmd-Attrs
X-Id
X-Goog-Storage-Class
S
X-FTR-Backend
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-DC
X-FTR-Realm
X-T
X-Fastly-Request-ID
ServerID
X-Varnish-Age
X-Via-JSL
X-Client-IP
DynaTrace
X-Ser
X-Content-Type
X-DynaTrace-JS-Agent
X-Hits
X-Accel-Expires
X-Correlation-Id
X-Grace
X-Dw-Request-Base-Id
X-Amzn-Trace-Id
X-Server-ID
X-FastCGI-Cache
Fastcgi-Cache
X-Content-Digest
X-SERVER
Powered
X-Frontend
X-DIS-Request-ID
X-Forwarded-For
X-N
AMP-Access-Control-Allow-Source-Origin
X-Mobile-Rewrite
PB-RID
X-FTR-Cache-Host
Edge-Cache-Tag
Arc-Version
PB-PID
X-HS-Content-Id
X-HS-Hub-Id
Server-Name
X-Logged-In
X-Vcache
X-RateLimit-Limit
Accept-Ch
TP-L2-Cache
TP-Cache
X-GUploader-UploadID
X-Microsite
X-Request-Handler-Origin-Region
X-Request-Processing-Time
X-Request-Received
X-Zen-Fury
X-B3-Sampled
X-Kinsta-Cache
X-Cache-Age
Pinterest-Version
X-Pinterest-Rid
X-Type
X-Analytics
X-IPLB-Instance
X-Rid
X-Az
X-Activity-Id
Backend-Timing
X-AppVersion
X-User-Agent
X-Fastcgi-Cache
X-Time
X-LB-Cache
X-Revision
Healthy
Retry-After
X-Whom
X-Node-Name
X-Cache-Hit
FilterID
X-Srv
X-B3-Traceid
Server-Node
X-NWS-LOG-UUID
X-F-Cache
Accept-Charset
Alternate-Protocol
X-Hp-Webp
X-Cache-2
Cache-Tag
X-Cache-Rule
X-Akamai-Edgescape
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Cache-Status
X-Content-Security-Policy-Report-Only
X-Content-Options
X-Erf-Bev-Bev-Is-Generated
Surrogate-Key
X-Erf-Bev-Bev
Refresh
X-AOL-HN
Tracecode
X-Instance
X-Forwarded-Host
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Content-Powered-By
X-Tumblr-User
Access-Control-Allow-Method
X-Tumblr-Pixel
X-Debug-Info
X-Webkit-CSP
X-Tumblr-Pixel-0
DC
MS-CV
Source
X-Cluster
X-Varnish-Grace
X-Jobs
X-FB-Debug
X-Request-Guid
X-App-Environment
X-PHP-Backend
X-Page-Id
Fastcgi-Useragent
X-Framework
X-FW-Type
X-FW-Hash
X-FW-Server
X-FW-Serve
X-FW-Static
X-B
X-App-Server
Frame-Options
X-Cache-Operation
Host
X-TA-CDN-Provider
Actual-Object-TTL
X-Mobile-URL
X-Seen-By
X-Cache-TTL
X-Cache-Key
X-Hostname
X-Esi
X-Geo-Country
Accept-CH-Lifetime
X-Cache-Control
Cleartype
NR-ENABLED
X-B-Cache
X-Signature
X-Host-Name
X-Cached-By
X-BCube-Filmed-By
Upgrade-Insecure-Requests
X-Acc-Meta-Resource-Type
X-Pad
X-Amz-Replication-Status
X-Varnish-Backend
X-Git-Hash
X-TT
NGB
X-Response-Served-From
X-WebKit-CSP-Report-Only
X-Mobile
X-Adobe-Loc
X-Adobe-Content
GEO-INFO
X-ATG-Version
X-ProcessESI
X-RemovedCookies
X-Tumblr-Pixel-1
X-TT-TIMESTAMP
WPE-Backend
Webserver
Payment
X-Tumblr-Pixel-2
Cache-Tv-Group
X-Handled-By
X-Drupal-Cache-Tags
Ms-Operation-Id
X-RTag
Eomportal-Instance
X-RequestSource
X-UA-Device-Type
From-Origin
X-TX-ID
X-Cache-Remote
X-GeoIP
Liferay-Portal
Filters
X-Status
X-Cacheable-TTL
X-Origin-Server
X-Cache-TTL-Remaining
X-Daa-Tunnel
X-Presslabs-Stats
X-FW-Dynamic
X-EdgeConnect-Cache-Status
X-WA-Info
X-Cache-Action
X-Wix-Request-Id
Xserver
X-Content-Age
X-Hyper-Cache
X-HS-Cache-Config
X-Contextid
X-Edge-Location
X-Element-Page-Cache
Viewport
Datacenter
X-Region
X-CF-Powered-By
X-Storage
Version
X-Ratelimit-Reset
Cache
X-Varnish-Hostname
X-Accel-Buffering
Ohc-File-Size
X-Akamai-Transformed
X-Cache-NE
PageSpeed
Host-Header
X-PressLabs-Stats
X-ES-SERVER
X-RN-RSRV
Meta-Geo
X-Cache-Var-Map
X-Cache-Var
X-Path-Route
Load-Balancing
X-Varnish-Server
X-IP
X-Cache-Server
Cache-Tags
S-Cnection
X-Proto
X-Proxy
X-NewRelic-App-Data
Vix-Hermes-Req-Id
X-Access
X-Akamai-Request-ID
X-Section
X-Yottaa-Metrics
X-Origin-Response-Time
Release
X-Tumblr-Pixel-3
X-Viewer-Country
Ec-Rule-Version
Cache-Name
X-CS
X-Loop
X-NCache
X-TNCMS
X-Via-Fastly
X-Yottaa-Optimizations
X-Cache-Enabled
X-Cache-Config
Cache-Hits
Azure-Version
Azure-SlotName
TWC-Privacy
Decoy-Debug-TTL
Rt-Fastcgi-Cache
Decoy-Debug-Key
DB-Nickname
Country
Azure-SiteName
Azure-RegionName
Property-Id
X-R9-Blue-Green-Version
TWC-GeoIP-Country
TWC-Device-Class
Mn-Server-Ip
TWC-GeoIP-LatLong
TWC-Locale-Group
S-Rt
Azure-InstanceId
TWC-Connection-Speed
X-Device-Type
X-Upstream-HT
X-PCL
X-Varnish-Cache-Hits
X-Upstream-CT
Webcakes-App-Name
X-PERF
X-Cluster-Node
X-Web-Node
Decoy-Debug-Status
X-Labrador-Cache-Channel
X-FC-Vary-Parameters
X-OCL
X-Origin
X-Xfnlog-Site
X-Origin-Hint
X-Time-Microsecs
X-Upgrade-Enabled
X-ApacheServer
X-Backend-Name
X-Format
X-Akamai-Request-ID2
Webcakes-App-Version
Webcakes-Region
X-Backend-TTL
X-Drupal-Cache-Contexts
X-Cache-Time
X-Cache-Grace
X-Rule
X-Hosted-By
X-Site-Version
X-Debug-Cache
X-Goog-Meta-Goog-Reserved-File-Mtime
X-From
X-Generated
X-Human
X-Hit
X-Locale
X-CCM
X-Cache-Host
X-Www-Served-By
X-Proxy-Build
X-UnsetCookies
X-Timing-Wait
X-EIG-Tracking-Id
X-JoinUs
Selected-Fe
Cache-Key
Ohc-Cache-HIT
X-XRDS-LOCATION
X-FireWall-Port
Server-Info
Time
X-Vgn-Hpd-Reason
X-Trace-Id
X-VCT
X-Ttl
DSUID
X-Varnish-Hits
X-S
X-Rendered-As
X-HS-Combine-CSS
X-OVcl
X-FW-Version
X-Upstream-Proxy
X-OVcl-Cache
X-Tec-Api-Root
X-Tec-Api-Origin
X-SS-Set-Cookie
X-Real-IP
X-Ua
Now
X-NGENIX-Cache
X-Tec-Api-Version
X-APP-VERSION
L5d-Success-Class
OT-Force-Account-Verify
X-Pubstack
Fastcgi-X-Cache-Version
Origin-Edge-Control
X-Redis-Cache
Origin-Cache-Control
Hostname
X-Litespeed-Cache
Access-Control-Request-Headers
X-FB-TRIP-ID
X-VG-TLSProxy
Origin
Fastly-SSL
ServedBy
Cteonnt-Length
X-VG-WebCache
X-Parent-Response-Time
Accept-Language
X-Cluster-Name
X-UUID
X-Origin-CC
X-Alternate-Cache-Key
X-Origin-TTL
X-Shopify-Stage
Machine
X-B3-Spanid
X-ShopId
X-Sorting-Hat-PodId
X-Tb
X-Sorting-Hat-ShopId
X-ShardId
NtCoent-Length
X-GoCache-CacheStatus
X-Load-Cache
X-NC
X-ServerID
X-CSRF-TOKEN
X-Rocket-Nginx-Bypass
X-Tt-Trace-Tag
X-L-Path
IBM-Web2-Location
X-ECACHE
X-Environment-Context
X-Soup
X-Trafficlayer-App-Name
NGX
X-Trafficlayer-App-Scope
SRV
X-App-Version
Mime-Version
X-No-Session
X-Is-Bot
Nel
X-B3-Parentspanid
X-Uri
CF-IPCountry
X-DataStream-Cache-Status
X-Nginx-Cache
X-CACHE-KEY
X-Magnolia-Registration
X-Endurance-Cache-Level
X-GEO
X-Amzn-Remapped-Content-Length
X-DPWN-IS-SECURE
X-External-Request-Id
X-Instart-Info
X-Developer
X-G
X-Hl-Ver
X-Destination
Apple-News-Services-Parsed-Url
X-Date
Apple-News-Services-Request-Url
Apple-News-Services-Host
Apple-News-Services-Handled
X-PAYTM-SRV-ID
A
X-Detected-As
X-Request-UUID
X-VG-WebServer
X-Twitter-Response-Tags
X-Trv-Group
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-Worker
X-Node-Id
X-Transaction
X-Rojux
X-Rewrite-Enabled
Arc-Country
X-S-Cookie
X-ScT
X-SRCache-Key
X-Server-Time
X-Region-Sid
Cache-Prefix
X-A-Dam
X-A-Ccd
Meta-Geo-Continent
X-A-Dcw
X-A-Dgt
Memcached
X-A-Wwc
X-A
Mobile-Detection-Method
Odigeo-Trace-Id
ServerName
Rendered-Blocks
T-Server
Node
VivaBuild
Viewtype
X-Accel-Expires-Debug
X-Aed
X-CF-Lambda-Version
Content-Script-Type
Content-Style-Type
X-Connection-Hash
X-D
BehaviorPad-Version
Rt-Proxy-Cache
Cross-Origin-Window-Policy
Fly-Cache
X-ARC
X-Application
X-AIR-PT
MD5-Digest
X-CF-Lambda-Fn
Fly-Request-Id
GEO-REGION-INFO
AsisCache
X-B-Cookie
Akamai-GRN
X-MServer
Backend-Name
X-UA
X-Oneagent-Js-Injection
X-SVT-ORM-RULES
X-Developers
X-Cache-Bucket
X-Fastly-Cache
X-SVT-ORM-VERSION
X-ProxyCache-Status
Uber-Trace-Id
X-BYPASS-REASON
X-ProxyCache-Key
X-S-Maxage
We-Hiring
IsBot
X-Origin-Date
X-Origin-Expires
N-Cache
Request-Country
Fastly-Soc-X-Request-Id
Section-Io-Cache
Request-EU
X-Up
X-SIPLIST1
X-Azure-Ref
Request-Time
X-Cdn-Srv
X-VC-Cache
Mail-Subject
X-Azure-Ref-OriginShield
Proxy-Connection
X-Cms-Context
X-Generated-By
User-Cache-Control
X-AWS-Id
X-VWS-Id
X-LJ-Flow-ID
X-Backend-Url
Magicmarker
RNT-Time
X-Hnp-Log
X-CGP
X-Geo-Header
X-C
Server-Int
RNT-Machine
X-Cdn-Origin
X-Generation-Time
X-Location
X-Matched-Rule
X-Cache-Info
X-Irp-Debug
X-NX-Host
X-Nginx-Cache-Key
X-Method
X-Backend-Host
X-Clientip
X-Debug-Log
Srv
Locale
X-Debug-Cookies
X-Debug-Cache-Store
X-Core-Mission
X-App-Name
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
X-Block-Status
X-Auto-Login
Thinkindot-Control
X-CUA
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-Clara-WADP
X-Eu-Site
X-Distil-CS
X-Distributor
W
X-ElasticPress-Search
X-Gen-Mode
L
X-Sn-Servicetimems
AKAMAI
X-Thinkindot-L3
X-TrackingId
X-Skip-Cache
CDCHOST
Fastly-SIE
Esi-Enabled
Countrycode
X-Mode
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Has-Esi
X-Is-Gdpr
X-JWT-State
X-Compress-Hint
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-Var-Ttl
X-VServer
X-WADP-Cache
X-We-Are-Hiring
Fastly-SWR
Content-Disposition
X-Rebelmouse-Surrogate-Control
X-Proxy-Upstream
Gh-Request-Id
HA-Ipaddr
X-Rebelmouse-Cache-Control
Ha-Gx-Prefs
X-Reboot
X-Proxy-Cache-Status
X-Release
X-Info
X-Dc
X-Microcachable
X-Swa-Ws
X-Level-Front-Cache
X-Thanos
X-Li-Pop
X-LI-Proto
X-Li-Fabric
X-User
X-WebServer
X-Platform-Server
X-Old-Content-Length
X-PHP-Host
X-Policy
X-MSEdge-Flight
X-MSEdge-Features
X-Key
X-Webstats-RespID
X-Variation
X-Dispatch
X-Generated-In
X-Generated-On
X-Internal-Host
X-Cache-Id
X-Fetched-On
X-Request-URI
X-GeoIP-City
X-IN-APIGATEWAY
X-Request-Start
X-Reqid
X-Hash
X-Say-Cacheable
X-B3-SpanId
X-Service
X-IN-APIGATEWAYSSL
X-Device-Os
X-ServiceProvider
X-Servername
X-Server-IP
X-Say-TTL
X-Epic-Correlation-Id
X-SayCDN-TTL
X-Edge-Server
X-Qloud-Router
X-LI-UUID
Server-Host
Served-By
Pramga
True-Client-Country-4JS
Web-Mar-Node
Wxu-Next-Region
Wxu-Next-Hostname
Wxu-Next-Commit
Adler-Geo
PFcat
Cdn-Request-Time
Cdn-Host
X-Cache-FS-Status
Heartbleed
Is-Eu
Pagetype
Memory
Kp-EeAlive
X-Guploader-Uploadid
Platform
X-Amz-Meta-Cache-Control
X-Backend-State
X-BBXSRF
X-Bip
X-Via-CDN
Server-ID
Cache-Provider
X-SD-PageType
X-GDPR
V-Age
SD-X-WS
X-Request-Time
X-Geo
Resin-Trace
X-Owner
X-Dispatcher-Server
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Cdn-Forward
X-COUNTRY
X-FPC
X-Lb-Id
X-NWS-UUID-VERIFY
X-Org
X-Oracle-Dms-Rid
X-Hello
X-Wa
X-URL
X-Flog
SS
X-Nc
X-ABtesting
X-Ratelimit-Limit
X-Svr
X-Cache-URL
X-DC
X-Be
X-Instart-Isnd
X-Servedbyhost
X-Dynatrace
REQUESTUUID
X-IPS-LoggedIn
X-RateLimit-Reset
Country-Code
X-Scheme
Dynatrace
X-Unique-ID
X-Response-By
X-CDN-Forward
X-Zipkin-Id
Cache-Cookie-Set-From
Cache-Cookie-Set-Lfrom
X-Proxied
Cache-Cookie-Set-Idcheck
X-Routing-Service
X-Processor
X-Datadome
X-Dynatrace-Js-Agent
X-VCL-Version
X-Cache-Backend
X-Page-Type
X-DataStream-Origin-MEX-Latency
X-DataStream-MidMile-RTT
UCS
X-NodeID
XServer
Group
PICS-Label
X-Server-W
X-SN
X-Pjax-Url
X-Oss-Request-Id
X-Oss-Object-Type
X-Oss-Storage-Class
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-MP-GENERATED-AT
X-Ruxit-Js-Agent
Cache-Host
Powered-By-ChinaCache
Ajk
X-Logtrace-Id
ProcessTime
X-Tb-Optimization-Total-Bytes-Saved
CACHE
X-Varnish-Beresp-Ttl
X-Webkit-Csp
X-HS-Status
X-Ftr-Request-Id
Proxy-Firewall
X-SRV
X-ZONE
X-Zone
X-HTML-Minification-Powered-By
Ttl
X-Pf-Uncompressing
X-Via-Ucdn
X-Ms-Version
Powered-By
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
SN
X-Ms-Request-Id
X-Source
X-EC-Lua
X-Newrelic-Synthetics
X-GRACE
Geoip-City
GeoIp-Country-Code
Geoip-Latitude
X-Grey
X-Session-Fingerprint
X-Cache-Category-Id
X-Ratelimit-Remaining
X-Varnish-Beresp-TTL
X-APP
X-Cache-Debug
Lfy
X-TH-Server
X-Agile-Age
X-Agile-Id
X-Agile
GeoIP-Latitude
Fastly-Backend-Name
X-Sucuri-Id
GeoIP-Country-Code
X-PF-Uncompressing
GeoIP-City
X-LiteSpeed-Cache-Control
X-Check-Cacheable
X-NODE
X-Fastly-Country-Code
X-Ftr-Cache-Host
X-7Graus-Varnish-XKeys
X-7Graus-Varnish-Cache-Control
MIME-Version
X-Bc
X-Cache-Miss-From
Cdn
X-Sedo-Request-Id
GW-Server
X-Tt-Trace-Host
X-Logging-Id
X-Aicache-OS
Environment
X-FORWARDED-FOR
X-LAGOON
CF-Cached-On
X-Edge
Pics-Label
X-CSRF-Token
X-Unique-Id
LB
X-Sucuri-ID
WWW
X-Gannett-Site-Version
X-BC
X-Varnish-Url
M-TraceId
X-Secret
X-RCS-CacheZone
X-Core-Value
X-Ftr-Balancer
X-Ftr-Dc
X-Ftr-Backend
X-Ftr-Realm
X-Ftr-Backend-Server
WZWS-RAY
X-PJAX-URL
X-Vcl-Version
X-Fastly-Backend-Reqs
X-Mid
Requestid
Ohc-Response-Time
X-Cache-Ttl
Cf-Ipcountry
X-UPSTREAM-Address
X-MCACHE
X-AK-Request-ID
X-Cache-Tag
X-Swift-Error
DataCenter
On-Server
Cdnsip
X-TT-LOGID
Cdncip
X-Vdms-Version
X-CDN-Cache
X-Varnish-Cacheable
X-Varnish-Ttl
X-NGINX-Cache
Amp-Access-Control-Allow-Source-Origin
HostName
X-Fstrz
X-Sigma
X-Sucuri-Cache
X-Sigma-Backend
X-Akamai-SSL-Client-Sid
X-GeoIP-Country-Code
X-Litespeed-Cache-Control
User-Agent
X-Rocket-Build-Number
Lb
URI
X-RPS
CDN
X-RSL
X-DW
Xkeyrz
X-DI
Inserted-Into-Cache-At
X-BE
X-DSS
X-DB
X-RPM
X-Proxy-Cacherz
X-Action
X-SERVER-NAME
X-NU-AKA-ACS-Version
X-Via-NSCOPI
SID
Pragrma
Host-ID
Who
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Shopify-Generated-Cart-Token
X-Crawler
X-ServedByHost
RequestUuid
X-Correlation-ID
Warning
X-WA
X-Flow-Id
X-Fastly-Cache-Hits
X-Render-Time
X-Fpc
Server-Id
X-Page-Impression-Id
Get-Access-Time
X-WR-MODIFICATION
Xkeypdq
X-Zalando-Child-Request-Id
Is-Session-Tracking
FNAC-ModuleRouting
X-Amzn-Remapped-Date
X-Refresh
X-LB-ID
X-FE
X-Amzn-Remapped-Connection
X-Nananana
Correlation-Id
X-SB
TTL
X-MID
X-ND-Cache
X-VC
X-Cf-Powered-By
X-SaId
X-Request-URL
Processtime
X-ECache
X-Trafficlayer-App-Version
X-Akamai-ERPolicy
X-Cdn-Request-ID
X-Fe
X-Micro-Cache
X-Akamai-ERRuleID
HitType
X-Bug-Bounty
X-Dw-Trace-Id
X-Gdpr
V-Cache
Xet-Cookie
Cneonction
X-Gen-Id
X-ServerName
X-LiteSpeed-Tag
X-Newrelic-App-Data
X-MiniProfiler-Ids
RequestId