Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Accept-Ranges
Pragma
X-Powered-By
CF-RAY
Link
X-XSS-Protection
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-UA-Compatible
Referrer-Policy
X-Served-By
X-Varnish
CF-Cache-Status
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
Access-Control-Allow-Credentials
X-Runtime
X-FRAME-OPTIONS
X-Drupal-Cache
X-Adblock-Key
Alt-Svc
X-Check
X-Cacheable
X-Generator
X-Xss-Protection
Content-Security-Policy-Report-Only
X-Cache-Status
X-Permitted-Cross-Domain-Policies
X-AspNetMvc-Version
X-Ua-Compatible
Status
P3p
Timing-Allow-Origin
X-Template
Content-Encoding
X-DNS-Prefetch-Control
X-Language
X-Content-Security-Policy
X-Iinfo
X-Request-ID
X-CDN
Upgrade
X-Buckets
Xkey
X-Kinja-Server-Push
X-Turbo-Charged-By
X-Via
Access-Control-Expose-Headers
Keep-Alive
Access-Control-Max-Age
X-AH-Environment
CF-Ray
X-Pass-Why
X-Drupal-Dynamic-Cache
X-Age
X-Cache-Group
X-Backend
X-Server
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Page-Speed
X-Envoy-Upstream-Service-Time
X-Pingback
X-Hacker
X-Varnish-Cache
X-Server-Powered-By
X-Nginx-Cache-Status
EagleId
X-Proxy-Cache
Grace
X-UA-Device
Request-Context
Cf-Railgun
WPE-Backend
X-Swift-CacheTime
X-Swift-SaveTime
X-Amz-Version-Id
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-LiteSpeed-Cache
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Server-Id
X-OneAgent-JS-Injection
Feature-Policy
X-Ac
X-Node
Content-Location
X-Rq
EagleEye-TraceId
X-Host
X-Backend-Server
X-Cnection
Server-Timing
Allow
Report-To
X-Response-Time
X-Cache-Lookup
X-Application-Context
Request-Id
X-Dns-Prefetch-Control
Surrogate-Control
X-Origin-Cache
X-Readtime
Pinterest-Generated-By
X-Cloud-Trace-Context
X-ORACLE-DMS-ECID
X-CST
NEL
X-Ruxit-JS-Agent
X-Rack-Cache
X-FTR-Request-ID
X-HW
X-Vhost
X-Country
X-Clacks-Overhead
X-Country-Code
X-DynaTrace
Rating
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Goog-Hash
X-Instart-Request-ID
X-Origin-Upstream-Status
X-Dispatcher
X-Url
X-Mod-Pagespeed
X-DataDome
X-Px
Edge-Control
X-VARITI-CCR
X-Vname
X-PC
X-TtlSet
Service-Worker-Allowed
X-MS-InvokeApp
Accept-CH
Verso
X-DataStream-Cache-Status
X-Varnish-TTL
X-Powered-By-Plesk
X-Kinja-Revision
X-Kinja-Build
X-Cdn-Fetch
X-Kinja-Server
X-Use-Magma
X-Kinja
X-Exp-Id
X-GoogleNews-Bot
X-Exp-Variant
X-Recruiting
X-Server-Name
SPRequestGuid
AR-CACHE
AR-PoweredBy
AR-ATIME
X-Vcap-Request-Id
X-ESI
X-D2id
X-GitHub-Request-Id
X-Amz-Server-Side-Encryption
Content-MD5
MS-Author-Via
AR-Request-ID
X-ORACLE-DMS-RID
X-Abt-Application-Version
Public-Key-Pins
X-Version
X-SharePointHealthScore
Ar-Sid
X-Cached
X-Middleton-Response
X-Middleton-Display
Response
Display
X-Sol
X-DynaTrace-JS-Agent
RTSS
Arc-Version
X-Mobile-Rewrite
X-Pinterest-Rid
X-Upstream-Proxy
X-Navigation-Version
Pinterest-Version
Nginx-Cache
PB-RID
PB-PID
DynaTrace
Charset
X-Amz-Rid
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Goog-Generation
Realpath
ServerID
X-XRDS-Location
Fusion-Content-Id
Fusion-Component-Id
Fusion-Content-Source
Fusion-Source
Fusion-Template-Id
X-Oracle-Dms-Rid
X-Akam-SW-Version
X-Powered-CMS
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Client-IP
X-Forwarded-Proto
X-TTL
X-Shield-Request-Id
TCN
X-FTR-Cache-Status
X-FTR-DC
X-Country-Code-Real
X-FTR-Backend-Server
X-FTR-Backend
X-Trace
X-FTR-Realm
X-FTR-Balancer
X-RateLimit-Remaining
X-FTR-Expires
X-Goog-Storage-Class
X-B3-TraceId
X-Amz-Meta-S3cmd-Attrs
X-Ttl
SPRequestDuration
SPIisLatency
X-Dw-Request-Base-Id
X-Debug
X-Ser
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
Alternate-Protocol
X-Id
X-VCache
X-Shard
Paypal-Debug-Id
X-Fastly-Request-ID
X-FTR-Cache-Host
X-Varnish-Age
X-Upstream
S
X-MSEdge-Ref
Fastcgi-Cache
X-T
X-Acc-Meta-Resource-Type
X-Hits
X-Litespeed-Cache
Host
X-Ezoic-Cdn
MicrosoftSharePointTeamServices
X-B3-TraceId-Primal
MRF-Tech
X-Mrf-Section-Lastmod
Mrf-Cache-Status
X-Mrf-Item-Lastmod
X-NF-Request-ID
Front-End-Https
X-DIS-Request-ID
Access-Control-Request-Method
X-Content-Digest
X-DataStream-MidMile-RTT
X-DataStream-Origin-MEX-Latency
X-Logged-In
X-Frontend
Arr-Disable-Session-Affinity
Server-Name
X-HS-Hub-Id
X-HS-Content-Id
X-N
Pagespeed
X-Server-ID
X-Amzn-Trace-Id
X-Kinsta-Cache
X-B3-Sampled
X-Forwarded-For
X-IPLB-Instance
X-Srv
X-Fastcgi-Cache
X-Pad
X-Request-Handler-Origin-Region
X-Microsite
X-Content-Type
AMP-Access-Control-Allow-Source-Origin
Edge-Cache-Tag
X-AOL-HN
FilterID
TP-Cache
X-Accel-Expires
TP-L2-Cache
X-Type
X-Debug-Info
X-Rid
X-Request-Received
X-Cdn
X-Request-Processing-Time
Surrogate-Key
X-RateLimit-Limit
X-Node-Name
X-LB-Cache
Accept-Ch-Lifetime
Tracecode
X-Via-JSL
X-Analytics
Backend-Timing
Accept-CH-Lifetime
X-Hostname
X-Grace
X-FastCGI-Cache
X-Page-Id
Accept-Charset
Healthy
X-Cache-Rule
X-Whom
X-GUploader-UploadID
X-Revision
X-Varnish-Backend
X-Webkit-Csp
X-Content-Options
X-Cache-2
X-NWS-LOG-UUID
X-Content-Security-Policy-Report-Only
X-Cache-Age
X-B3-Traceid
X-Cached-By
X-User-Agent
Host-Header
X-Content-Powered-By
X-FB-Debug
X-Framework
X-Varnish-Hostname
X-Amz-Replication-Status
X-TT
X-Mobile
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Cache-Control
X-PHP-Backend
X-Cluster
Powered
X-Akamai-Edgescape
Source
X-BCube-Filmed-By
X-Tumblr-User
X-Tumblr-Pixel-0
X-Instance
X-Tumblr-Pixel
Upgrade-Insecure-Requests
Cache-Status
X-App-Environment
X-Varnish-Grace
X-Request-Guid
X-Correlation-Id
Fastly-Restarts
X-Vcache
Server-Info
Cleartype
X-Jobs
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Cache-Hit
Access-Control-Allow-Method
X-Zen-Fury
X-Az
X-AppVersion
X-Drupal-Cache-Tags
X-Activity-Id
X-Cache-TTL
X-Cache-Remote
X-Platform-Server
Retry-After
Actual-Object-TTL
X-ATG-Version
X-FW-Static
X-Cache-Key
X-FW-Serve
X-FW-Hash
X-FW-Server
X-FW-Type
X-Iejgwucgyu
X-Cache-Action
X-Oneagent-Js-Injection
X-Forwarded-Host
X-CF-Powered-By
X-Cache-Operation
X-WebKit-CSP-Report-Only
X-Esi
Payment
X-Response-Served-From
X-F-Cache
X-Adobe-Loc
X-Geo-Country
X-Adobe-Content
X-Content-Age
X-TT-TIMESTAMP
X-TX-ID
X-RemovedCookies
X-Storage
Server-Node
X-ProcessESI
Cache
X-Yottaa-Optimizations
X-VG-WebCache
X-Yottaa-Metrics
X-Tumblr-Pixel-1
Eomportal-Instance
X-Tumblr-Pixel-2
X-UA-Device-Type
X-Cache-NE
X-Varnish-Hits
X-Handled-By
Filters
Cache-Tv-Group
X-B
Cache-Tags
X-URL
X-GeoIP
X-Cacheable-TTL
DC
X-RequestSource
Refresh
X-Daa-Tunnel
X-Real-IP
X-Guploader-Uploadid
X-Accel-Buffering
Cache-Tag
PageSpeed
X-Git-Hash
X-PressLabs-Stats
X-Redis-Cache
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Webserver
From-Origin
Viewport
Frame-Options
MS-CV
X-App-Server
X-Host-Name
Datacenter
X-UUID
X-Origin-Server
X-WA-Info
X-Rendered-As
X-Contextid
X-Ratelimit-Reset
X-Cache-TTL-Remaining
Xserver
X-TA-CDN-Provider
X-Mode
X-FB-TRIP-ID
X-Magnolia-Registration
X-Cache-Enabled
X-FW-Dynamic
Country
X-Varnish-Server
X-Locale
X-Hl-Ver
X-Cache-Var-Map
X-Upstream-CT
X-Routing-Service
X-Path-Route
X-Zipkin-Id
X-ES-SERVER
X-Proxied
X-RN-RSRV
X-From
X-Upstream-HT
X-Ua
X-Signature
Meta-Geo
Load-Balancing
X-B-Cache
Machine
X-Cache-Var
X-ProxyCache-Status
X-Backend-Name
X-Rocket-Nginx-Bypass
NGX
X-Viewer-Country
X-ServerID
Cache-Key
X-Cache-Config
X-Goog-Meta-Goog-Reserved-File-Mtime
GEO-INFO
X-BYPASS-REASON
X-ProxyCache-Key
Now
X-NCache
X-VG-TLSProxy
X-Hit
ServedBy
X-Region
X-Web-Node
X-JoinUs
L5d-Success-Class
Vix-Hermes-Req-Id
X-GRACE
X-L-Path
X-Labrador-Cache-Channel
Mn-Server-Ip
X-Cache-Host
X-Environment-Context
Uber-Trace-Id
X-CCM
X-Trace-Id
X-Rule
X-Debug-Cache
X-Varnish-IP
X-Varnish-Cache-Hits
X-Proto
X-XRDS-LOCATION
X-Upgrade-Enabled
X-EIG-Tracking-Id
X-FC-Vary-Parameters
X-Origin-Response-Time
X-Pubstack
X-EdgeConnect-Cache-Status
X-LJ-Flow-ID
Powered-By-ChinaCache
X-Cache-Category-Id
X-OCL
X-MP-GENERATED-AT
X-R9-Blue-Green-Version
X-Human
X-AWS-Id
X-Cache-Backend
X-Grey
X-Akamai-Request-ID
X-PCL
X-RCS-CacheZone
X-Hosted-By
X-VWS-Id
Cteonnt-Length
X-Via-Fastly
X-TNCMS
X-Tumblr-Pixel-3
DB-Nickname
DSUID
X-Access
Mail-Subject
X-VCT
X-APP-VERSION
X-Www-Served-By
X-Site-Version
X-Loop
X-Section
X-Vgn-Hpd-Reason
X-S
X-Generated
X-Mobile-URL
X-Xfnlog-Site
X-Device-Type
X-Hp-Webp
We-Hiring
Selected-FE
Origin-Cache-Control
Origin-Edge-Control
Release
X-Timing-Wait
X-Is-Bot
X-Proxy-Build
X-Detected-As
X-NewRelic-App-Data
OT-Force-Account-Verify
Nel
Cache-Name
HitType
Fastcgi-Useragent
X-NGENIX-Cache
S-Cnection
X-B3-Spanid
Rt-Fastcgi-Cache
X-Nginx-Cache
X-Seen-By
X-Cache-Grace
X-Source
Served-By
X-Drupal-Cache-Contexts
X-Tb
X-BACKEND-TTL
X-Webkit-CSP
SRV
X-Birta-Served
X-Birta-Cache-Post
X-Generated-By
Hostname
X-Cluster-Node
X-Format
X-UnsetCookies
Ms-Operation-Id
X-Microcachable
X-RTag
X-Time
X-Presslabs-Stats
X-Cache-Server
X-Proxy
X-Status
X-ApacheServer
Fastcgi-X-Cache-Version
X-PERF
X-SS-Set-Cookie
X-Endurance-Cache-Level
Decoy-Debug-Status
X-Time-Microsecs
X-ShardId
X-Alternate-Cache-Key
Decoy-Debug-TTL
Decoy-Debug-Key
X-Akamai-Transformed
X-ShopId
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Shopify-Stage
X-OVcl-Cache
IBM-Web2-Location
X-OVcl
Azure-SlotName
Azure-Version
Azure-SiteName
Azure-InstanceId
X-IP
Azure-RegionName
X-FW-Version
Access-Control-Request-Headers
X-B3-Parentspanid
Origin
NGB
X-Geo
X-Origin-TTL
X-Origin
X-Cdn-Forward
X-Origin-CC
X-Via-CDN
Fastly-SSL
X-Info
Ec-Rule-Version
Property-Id
TWC-GeoIP-LatLong
TWC-Locale-Group
TWC-Device-Class
TWC-Connection-Speed
X-Origin-Hint
TWC-Privacy
TWC-GeoIP-Country
Webcakes-App-Version
Webcakes-Region
Webcakes-App-Name
X-Application
X-Aed
X-ARC
X-B-Cookie
X-Cache-Bucket
X-Accel-Expires-Debug
X-A-Dgt
X-Cdn-Origin
X-A-Dam
X-A-Ccd
X-A-Dcw
X-A
X-A-Wwc
X-Core-Value
X-Developer
X-Destination
X-DPWN-IS-SECURE
Meta-Geo-Continent
X-G
X-Date
X-D
X-Cluster-Name
X-CF-Lambda-Version
X-Connection-Hash
X-Core-Mission
Apple-News-Services-Handled
X-CF-Lambda-Fn
Www
Fly-Cache
Fly-Request-Id
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Cross-Origin-Window-Policy
Thinkindot-Control
GEO-REGION-INFO
Server-Int
MD5-Digest
Node
Rendered-Blocks
IsBot
Rt-Proxy-Cache
Viewtype
Content-Style-Type
AsisCache
X-IN-APIGATEWAY
Arc-Country
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
BehaviorPad-Version
Cache-Cookie-Set-From
VivaBuild
Content-Script-Type
Cache-Prefix
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-Idcheck
Apple-News-Services-Host
X-External-Request-Id
X-PAYTM-SRV-ID
X-Phone
X-Thinkindot-L3
X-Processor
X-Transaction
X-Trv-Group
X-Org
X-App-Version
X-VG-WebServer
X-Twitter-Response-Tags
X-SRCache-Key
X-Sn-Servicetimems
X-S-Cookie
X-ServiceProvider
X-ScT
X-Server-Time
X-Rojux
X-Rewrite-Enabled
X-Region-Sid
X-SIPLIST1
X-Request-UUID
X-NU-AKA-ACS-Version
X-Via-NSCOPI
X-Request-Time
X-Matched-Rule
S-Rt
X-Worker
X-Instart-Info
X-IN-WAF
X-ND-Cache
Xc-Version
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
X-ElasticPress-Search
X-Ruxit-Js-Agent
WZWS-RAY
X-Nc
Proxy-Connection
Backend-Name
X-Varnish-Cacheable
HTTPS
Request-EU
On-Server
Request-Country
Web-Mar-Node
RNT-Time
V-Age
User-Cache-Control
True-Client-Country-4JS
X-VC-Cache
Server-Host
ServerName
Resin-Trace
X-Swa-Ws
RNT-Machine
Request-Time
X-Rebelmouse-Surrogate-Control
X-Level-Front-Cache
X-Irp-Debug
X-Distributor
X-Debug-Log
X-Nginx-Cache-Key
X-NX-Host
X-No-Session
X-Instart-Isnd
X-Fastly-Cache
X-Generation-Time
X-Geo-Header
X-Hash
X-Generated-On
X-Gen-Mode
X-Fetched-On
X-Gannett-Site-Version
X-Origin-Date
X-Cache-Info
X-Rebelmouse-Cache-Control
X-Protected-By
X-PHP-Host
X-Hnp-Log
X-Request-URI
X-Secret
X-S-Maxage
X-App-Name
X-Page-Type
X-Cache-FS-Status
X-Cache-Id
X-Cache-Debug
X-Origin-Expires
X-Block-Status
X-C
X-Served-From
X-Debug-Cookies
Gh-Request-Id
Backend
X-Real-Ip
CDCHOST
Country-Code
Esi-Enabled
Memcached
Fastly-SWR
Fastly-SIE
X-Eu-Site
X-GeoIP-Country-Code
X-GeoIP-City
X-HS-Combine-CSS
X-HS-Cache-Config
X-Dispatcher-Server
X-Bip
X-BBXSRF
X-Auto-Login
X-Cache-Expires
X-Cdn-Srv
X-Developers
X-Cms-Context
X-CGP
X-Epic-Correlation-Id
X-UA
X-Via-Edge
X-Varnish-Action
X-Variation
X-Thanos
X-Via-SSL
X-WebServer
Version
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-SN
X-Skip-Cache
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
X-Owner
X-Amz-Meta-Cache-Control
X-Qloud-Router
X-Reboot
X-Server-IP
X-Reqid
X-Release
X-Key
X-Planisys-CDN-Rules
Is-Eu
AKAMAI
Adler-Geo
ProcessTime
Pramga
HA-Ipaddr
Ha-Gx-Prefs
UCS
Epwk-Cache
Fastly-Soc-X-Request-Id
Content-Disposition
Platform
REQUESTUUID
X-IPS-LoggedIn
Group
X-FireWall-Port
Server-ID
Wxu-Next-Commit
X-Device-Os
SD-X-WS
X-Refresh
Wxu-Next-Hostname
X-Crawler
X-Agile-Id
Who
X-Agile
X-LI-UUID
X-Li-Pop
X-Li-Fabric
X-Location
Mime-Version
X-Distil-CS
Wxu-Next-Region
X-Agile-Age
X-LAGOON
X-SVT-ORM-VERSION
Heartbleed
X-Backend-State
X-TH-Server
X-CDN-Cache
X-Webstats-RespID
X-SVT-ORM-RULES
X-TIME
X-CACHE-GROUP
X-Edge-Location
X-AIR-PT
X-Dc
X-AssetVersion
Memory
Mobile-Detection-Method
X-NC
Time
FNAC-ModuleRouting
X-GEO
X-Wix-Request-Id
X-Load-Cache
Akamai-GRN
SS
Cache-Hits
X-LI-Proto
X-FPC
X-Var-Ttl
X-Sf
Accept-Ch
X-Clientip
X-CACHE-KEY
X-WPE-Loopback-Upstream-Addr
Countrycode
X-Servername
X-Parent-Response-Time
X-Internal-Host
X-We-Are-Hiring
Amp-Access-Control-Allow-Source-Origin
Cache-Provider
X-Policy
NtCoent-Length
X-Unique-ID
X-DC
Cdn
CF-IPCountry
X-CLOUD-TRACE-CONTEXT
X-CDN-Forward
X-Micro-Cache
GW-Server
X-NWS-UUID-VERIFY
A
Fastcgi-X-Cache
X-Varnish-Beresp-Ttl
X-Datadome
X-Servedbyhost
X-Gdpr
X-Tb-Optimization-Total-Bytes-Saved
RequestId
X-SERVER-NAME
X-Be
X-ZONE
X-SD-PageType
Liferay-Portal
X-Zone
Ohc-Cache-HIT
Ohc-File-Size
X-ECACHE
X-Web-Server
X-Cache-URL
Cf-Ipcountry
X-Response-By
X-Ratelimit-Remaining
X-Hyper-Cache
X-Apm-Svc-Key
X-Varnish-Beresp-Status
X-Dynatrace-Js-Agent
GeoIp-Country-Code
Geoip-City
X-Varnish-Beresp-Grace
SN
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Apm-Inst-Hash
Ajk
X-Logtrace-Id
Geoip-Latitude
X-Apm-App-Name
CF-Cached-On
HostName
PICS-Label
Proxy-Firewall
X-Fstrz
X-VCL-Version
X-APP
X-Request-Start
X-UPSTREAM-Address
X-Vcl-Version
Odigeo-Trace-Id
X-LiteSpeed-Cache-Control
AR-SID
X-Aicache-OS
X-Fastly-Country-Code
X-Varnish-Beresp-TTL
X-MServer
MIME-Version
X-Pf-Uncompressing
Section-Io-Cache
CDN
X-Lb-Id
GeoIP-Latitude
GeoIP-Country-Code
X-Dispatch
X-HS-Status
X-Cache-Ttl
GeoIP-City
X-NodeID
X-Newrelic-Synthetics
WebServer
X-Method
Cdn-Request-Time
X-Server-Group
X-Amzn-Remapped-Date
Get-Access-Time
X-Amzn-Remapped-Connection
Cdn-Host
PFcat
XServer
Is-Session-Tracking
X-Edge-Server
X-FORWARDED-FOR
X-Ratelimit-Limit
X-Nananana
X-Erf-Bev-Bev-Is-Generated
Requestid
LB
X-Erf-Bev-Bev
X-Correlation-ID
X-CS
X-ServedByHost
X-Pjax-Url
X-SRV
X-B3-SpanId
X-COUNTRY
X-PF-Uncompressing
X-Backend-TTL
X-VServer
X-Fastly-Backend-Reqs
X-Newrelic-App-Data
X-Check-Cacheable
X-Powered-By-Defense
Pragrma
Host-ID
X-Up
X-RequestId
X-WA
X-Dynatrace
X-CSRF-TOKEN
X-Azure-Ref-OriginShield
Lb
X-Compress-Hint
X-Amzn-Remapped-Content-Length
X-Azure-Ref
X-HTML-Minification-Powered-By
CACHE
X-Server-W
Powered-By
X-CUA
Sid
X-LiteSpeed-Tag
X-Cache-ASPX
X-Oss-Request-Id
X-MSEdge-Features
X-Wa
X-Oss-Object-Type
X-Backend-Host
X-Varnish-Authentication
X-Backend-Url
X-Oss-Server-Time
X-Contensis-Viewer-Groups
X-Oss-Storage-Class
X-MSEdge-Flight
X-Oss-Hash-Crc64ecma
Server-Surrogate-Control
Server-Cache-Control
X-WR-MODIFICATION
X-Debug-Cache-Expiry
TTL
X-PJAX-URL
Correlation-Id
X-Debug-Cache-Store
X-EC-Lua
X-Debug-Cache-Fetch
X-F5-Cache
X-Gateway-Skip-Cache
X-User
X-LB-ID
X-Bc
X-Edge
X-Gateway-Cache-Status
W
X-Gateway-Cache-Key
Dynatrace
X-Akamai-Request-ID2
X-Got-Non-Ke-Cookie
Cneonction
X-Clara-WADP
X-Request-Url
X-Generated-In
X-Dw-Trace-Id
X-Fpc
L
X-ServerName
X-NGINX-Cache
User-Agent
X-WADP-Cache
Accept-Language
X-Svr
X-BC
URI
X-Edge-IP
X-Html-Edge-Cache
X-Varnish-Url
X-Li-Proto
X-Urbn-Context-Path
Locale
286prxHost
X-Cache-Miss-From
X-Urbn-Site-Id
189phosttRef
178proxuri
219prxHost
409pxxline
Pagetype
X-Requestid
188prxHost
225prxHost
X-Fastly-Cache-Hits
X-HTML-Edge-Cache
N-Cache
X-Swift-Error
352pxline
Xxline
X-Sedo-Request-Id
X-MID
Magicmarker
355prline
X-BE
X-Proxy-Upstream
X-Proxy-Cache-Status
X-Via-Ucdn
X-Mid
X-TT-LOGID
X-CSRF-Token
Warning
Ttl
X-ABtesting
WP-Super-Cache
X-Hello
X-Unique-Id
X-Cache-Tag
X-Flog
X-Exp-Se
X-Akamai-SSL-Client-Sid
Srv
RequestUuid
Https
Lfy
X-Platform
Dnion-Transfer-Encoding
FSS-Proxy
X-Sucuri-ID
X-Sucuri-Cache
X-Alicdn-Da-Ups-Status
X-GDPR
X-Gen-Id
V-Cache
X-Cache-Detail
FSS-Cache
X-App
Ohc-Response-Time
Server-Id
X-MCACHE