Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Accept-Ranges
Pragma
X-Powered-By
CF-RAY
Link
ETag
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-UA-Compatible
Referrer-Policy
X-Served-By
X-Varnish
CF-Cache-Status
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
Access-Control-Allow-Credentials
X-Runtime
X-FRAME-OPTIONS
X-Drupal-Cache
X-Adblock-Key
Alt-Svc
X-Check
X-Cacheable
X-Xss-Protection
X-Generator
Content-Security-Policy-Report-Only
X-Cache-Status
X-Permitted-Cross-Domain-Policies
X-Ua-Compatible
X-AspNetMvc-Version
P3p
Status
Timing-Allow-Origin
X-Template
Content-Encoding
X-Language
X-Request-ID
X-Content-Security-Policy
X-Iinfo
X-DNS-Prefetch-Control
X-CDN
Upgrade
X-Buckets
Xkey
X-Kinja-Server-Push
X-Turbo-Charged-By
X-Via
Keep-Alive
Access-Control-Expose-Headers
Access-Control-Max-Age
CF-Ray
X-AH-Environment
X-Pass-Why
X-Drupal-Dynamic-Cache
X-Age
X-Cache-Group
X-Backend
X-Server
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Envoy-Upstream-Service-Time
X-Page-Speed
X-Pingback
X-Hacker
X-Varnish-Cache
X-Server-Powered-By
X-Nginx-Cache-Status
EagleId
X-Proxy-Cache
Grace
X-UA-Device
Request-Context
Cf-Railgun
X-Amz-Version-Id
X-Swift-CacheTime
X-Swift-SaveTime
WPE-Backend
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-LiteSpeed-Cache
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Server-Id
X-OneAgent-JS-Injection
Feature-Policy
X-Ac
X-Node
X-Dns-Prefetch-Control
Content-Location
X-Rq
EagleEye-TraceId
X-Host
X-Backend-Server
X-Cnection
Server-Timing
Allow
Report-To
X-Response-Time
X-Cache-Lookup
X-Application-Context
Request-Id
Surrogate-Control
X-Origin-Cache
Pinterest-Generated-By
X-Readtime
X-ORACLE-DMS-ECID
X-Cloud-Trace-Context
X-CST
NEL
X-Ruxit-JS-Agent
X-Rack-Cache
X-FTR-Request-ID
X-HW
X-Vhost
X-Country
X-Clacks-Overhead
X-Country-Code
X-DynaTrace
Rating
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Goog-Hash
X-Instart-Request-ID
X-Origin-Upstream-Status
X-Dispatcher
X-Url
X-Mod-Pagespeed
X-Px
Edge-Control
X-DataDome
X-VARITI-CCR
X-PC
X-TtlSet
X-Vname
Service-Worker-Allowed
X-MS-InvokeApp
Accept-CH
Verso
X-Server-Name
X-Varnish-TTL
X-DataStream-Cache-Status
X-Powered-By-Plesk
X-Cdn-Fetch
X-Kinja-Build
X-Exp-Id
X-Kinja-Server
X-Use-Magma
X-Kinja
X-Kinja-Revision
X-GoogleNews-Bot
X-Exp-Variant
SPRequestGuid
X-ESI
X-Recruiting
X-Vcap-Request-Id
AR-PoweredBy
AR-ATIME
AR-CACHE
X-D2id
X-GitHub-Request-Id
X-Amz-Server-Side-Encryption
Content-MD5
MS-Author-Via
AR-Request-ID
Ar-Sid
X-Abt-Application-Version
Public-Key-Pins
X-Version
X-SharePointHealthScore
X-Oracle-Dms-Rid
Display
X-Middleton-Display
X-Middleton-Response
Response
X-Sol
X-Cached
RTSS
Nginx-Cache
DynaTrace
Pinterest-Version
X-Pinterest-Rid
X-Navigation-Version
X-Upstream-Proxy
PB-RID
X-Mobile-Rewrite
Arc-Version
PB-PID
Charset
X-Amz-Rid
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-ORACLE-DMS-RID
X-Goog-Generation
X-Goog-Stored-Content-Length
X-DynaTrace-JS-Agent
ServerID
Realpath
Fusion-Content-Id
Fusion-Component-Id
Fusion-Template-Id
Fusion-Content-Source
Fusion-Source
X-XRDS-Location
X-Ttl
X-Akam-SW-Version
X-Powered-CMS
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Client-IP
X-Trace
X-Forwarded-Proto
X-Shield-Request-Id
X-RateLimit-Remaining
TCN
X-FTR-Cache-Status
X-FTR-DC
X-FTR-Balancer
X-Country-Code-Real
X-FTR-Backend
X-FTR-Realm
X-FTR-Backend-Server
X-FTR-Expires
X-Goog-Storage-Class
X-Amz-Meta-S3cmd-Attrs
X-VCache
X-Dw-Request-Base-Id
SPIisLatency
SPRequestDuration
X-Debug
X-B3-TraceId
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Ser
Alternate-Protocol
X-Id
X-TTL
X-Shard
Paypal-Debug-Id
X-Fastly-Request-ID
X-FTR-Cache-Host
X-Varnish-Age
X-Upstream
S
X-Litespeed-Cache
Fastcgi-Cache
X-MSEdge-Ref
X-T
X-Hits
X-Acc-Meta-Resource-Type
Host
X-Ezoic-Cdn
MicrosoftSharePointTeamServices
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-NF-Request-ID
X-DIS-Request-ID
X-Content-Digest
Access-Control-Request-Method
Front-End-Https
X-Logged-In
X-Frontend
X-DataStream-MidMile-RTT
Pagespeed
X-DataStream-Origin-MEX-Latency
Arr-Disable-Session-Affinity
Server-Name
X-Server-ID
X-N
X-HS-Hub-Id
X-HS-Content-Id
X-Amzn-Trace-Id
X-Kinsta-Cache
X-IPLB-Instance
X-B3-Sampled
X-Forwarded-For
X-Srv
X-Pad
X-Request-Handler-Origin-Region
X-Fastcgi-Cache
X-Content-Type
X-Microsite
X-Cdn
Edge-Cache-Tag
FilterID
Accept-CH-Lifetime
AMP-Access-Control-Allow-Source-Origin
X-AOL-HN
X-Type
X-RateLimit-Limit
TP-Cache
TP-L2-Cache
X-Accel-Expires
X-Debug-Info
X-LB-Cache
X-Rid
Surrogate-Key
X-Request-Received
X-Node-Name
X-Request-Processing-Time
Tracecode
X-Grace
X-FastCGI-Cache
X-Via-JSL
Backend-Timing
X-Analytics
Accept-Ch-Lifetime
X-Hostname
X-Page-Id
X-GUploader-UploadID
X-Webkit-Csp
Healthy
X-B3-Traceid
Accept-Charset
X-Cache-Rule
X-Whom
X-Revision
X-Cache-2
X-Varnish-Backend
X-Content-Options
Host-Header
X-Cached-By
X-Cache-Age
X-Content-Powered-By
X-Content-Security-Policy-Report-Only
X-NWS-LOG-UUID
X-Amz-Replication-Status
X-Framework
X-FB-Debug
X-Varnish-Hostname
X-Correlation-Id
X-PHP-Backend
X-Cache-Control
X-User-Agent
X-Mobile
X-Cluster
VIX-Pulpo-Upstream-Status
Powered
X-Request-Guid
Source
VIX-Pulpo-Node
X-TT
X-Instance
X-Akamai-Edgescape
X-Tumblr-Pixel
X-BCube-Filmed-By
X-Tumblr-User
X-Tumblr-Pixel-0
X-Varnish-Grace
X-App-Environment
Upgrade-Insecure-Requests
Cache-Status
Fastly-Restarts
Server-Info
Cleartype
X-Jobs
X-Cache-Hit
X-Cache-TTL
X-Zen-Fury
X-Amz-Apigw-Id
X-Amzn-RequestId
Access-Control-Allow-Method
X-Vcache
X-Drupal-Cache-Tags
X-Activity-Id
X-Az
X-AppVersion
X-Cache-Key
X-Cache-Remote
Actual-Object-TTL
X-Oneagent-Js-Injection
Retry-After
X-Platform-Server
X-ATG-Version
X-FW-Hash
X-FW-Serve
X-FW-Static
X-FW-Server
X-FW-Type
X-CF-Powered-By
X-Cache-Action
X-Cache-Operation
X-Forwarded-Host
X-URL
X-WebKit-CSP-Report-Only
X-Response-Served-From
X-Geo-Country
X-Adobe-Content
X-Adobe-Loc
Payment
X-F-Cache
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
X-RemovedCookies
X-TT-TIMESTAMP
X-Content-Age
Server-Node
X-ProcessESI
X-TX-ID
X-Storage
X-Real-IP
X-Yottaa-Metrics
Eomportal-Instance
X-VG-WebCache
X-UA-Device-Type
X-Yottaa-Optimizations
X-B
X-Varnish-Hits
X-Handled-By
Filters
Cache-Tv-Group
X-Cacheable-TTL
X-Cache-NE
Cache
X-GeoIP
Cache-Tags
X-RequestSource
DC
X-Accel-Buffering
Refresh
Webserver
Cache-Tag
X-Daa-Tunnel
X-Git-Hash
X-Redis-Cache
X-Iejgwucgyu
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Esi
X-Guploader-Uploadid
X-TA-CDN-Provider
PageSpeed
Viewport
From-Origin
Frame-Options
X-App-Server
X-Host-Name
MS-CV
X-Rendered-As
X-UUID
X-PressLabs-Stats
Datacenter
X-Contextid
X-Cache-TTL-Remaining
X-Origin-Server
X-WA-Info
X-Magnolia-Registration
X-Ratelimit-Reset
X-Cache-Enabled
X-FB-TRIP-ID
X-Mode
X-FW-Dynamic
Country
Xserver
X-Varnish-Server
X-Locale
Machine
X-XRDS-LOCATION
X-From
X-Routing-Service
X-ES-SERVER
X-Rule
X-Upstream-CT
X-Upstream-HT
X-Cache-Var
X-Cache-Var-Map
X-Zipkin-Id
Load-Balancing
X-Path-Route
X-Hl-Ver
Meta-Geo
X-RN-RSRV
X-Proxied
X-Viewer-Country
X-NCache
X-Web-Node
X-Goog-Meta-Goog-Reserved-File-Mtime
X-ProxyCache-Key
X-Backend-Name
Cache-Key
X-Signature
X-B-Cache
X-BYPASS-REASON
X-Cache-Backend
GEO-INFO
X-ProxyCache-Status
X-Rocket-Nginx-Bypass
X-Cache-Config
X-ServerID
NGX
X-APP-VERSION
X-Human
Mn-Server-Ip
X-Labrador-Cache-Channel
X-Cache-Host
X-Hit
Now
X-Proto
X-OCL
Uber-Trace-Id
X-VG-TLSProxy
X-PCL
Origin-Cache-Control
Origin-Edge-Control
X-FC-Vary-Parameters
X-L-Path
X-JoinUs
ServedBy
X-Hosted-By
Vix-Hermes-Req-Id
X-Environment-Context
X-Debug-Cache
X-EdgeConnect-Cache-Status
X-Pubstack
L5d-Success-Class
X-Region
X-RCS-CacheZone
X-Tumblr-Pixel-3
X-TNCMS
X-Grey
X-Site-Version
X-Trace-Id
X-Upgrade-Enabled
X-Via-Fastly
X-Varnish-IP
X-Varnish-Cache-Hits
X-VWS-Id
X-R9-Blue-Green-Version
X-LJ-Flow-ID
X-Loop
X-Mobile-URL
X-MP-GENERATED-AT
X-Cache-Category-Id
X-CCM
X-Generated
Cteonnt-Length
X-EIG-Tracking-Id
X-Akamai-Request-ID
X-AWS-Id
X-S
X-Hp-Webp
X-Origin-Response-Time
DB-Nickname
X-Vgn-Hpd-Reason
DSUID
Mail-Subject
X-Device-Type
X-Section
X-Xfnlog-Site
X-VCT
X-Www-Served-By
Nel
X-NewRelic-App-Data
X-Access
We-Hiring
Selected-FE
X-Proxy-Build
X-Detected-As
X-Is-Bot
X-Timing-Wait
X-B3-Spanid
Release
Fastcgi-Useragent
Cache-Name
OT-Force-Account-Verify
Powered-By-ChinaCache
X-Ua
Rt-Fastcgi-Cache
X-GRACE
S-Cnection
HitType
X-Seen-By
X-NGENIX-Cache
X-Webkit-CSP
X-Source
X-Cache-Grace
SRV
Served-By
X-Tb
X-Birta-Served
X-Birta-Cache-Post
X-Presslabs-Stats
X-Nginx-Cache
X-Drupal-Cache-Contexts
Hostname
X-BACKEND-TTL
X-Generated-By
X-Cluster-Node
X-Microcachable
X-Format
X-UnsetCookies
X-Proxy
X-RTag
Ms-Operation-Id
Fastcgi-X-Cache-Version
X-Status
X-Cache-Server
X-ApacheServer
X-PERF
X-SS-Set-Cookie
X-Endurance-Cache-Level
Decoy-Debug-Status
Decoy-Debug-TTL
Decoy-Debug-Key
X-OVcl
X-OVcl-Cache
X-ShopId
X-Sorting-Hat-ShopId
X-Shopify-Stage
X-Alternate-Cache-Key
X-Sorting-Hat-PodId
X-ShardId
X-Time
X-Time-Microsecs
IBM-Web2-Location
X-Akamai-Transformed
Origin
Azure-InstanceId
Azure-SlotName
Azure-Version
Azure-SiteName
Azure-RegionName
X-UA
X-IP
X-B3-Parentspanid
X-Info
X-Origin-CC
Fastly-SSL
Access-Control-Request-Headers
NGB
X-Origin-TTL
X-Via-CDN
X-FW-Version
WZWS-RAY
Ec-Rule-Version
S-Rt
X-Ruxit-Js-Agent
X-Origin
X-Server-Time
HTTPS
GEO-REGION-INFO
Content-Style-Type
IsBot
Cross-Origin-Window-Policy
Fly-Cache
X-ScT
Rendered-Blocks
X-Rojux
Rt-Proxy-Cache
X-Rewrite-Enabled
X-S-Cookie
Node
Content-Script-Type
MD5-Digest
Meta-Geo-Continent
X-NU-AKA-ACS-Version
Cache-Cookie-Set-Lfrom
X-SRCache-Key
X-Sn-Servicetimems
X-SIPLIST1
X-ServiceProvider
X-IN-APIGATEWAY
X-IN-WAF
X-ND-Cache
X-Irp-Debug
X-Instart-Info
Apple-News-Services-Handled
Apple-News-Services-Host
X-Hnp-Log
Cache-Cookie-Set-From
Cache-Cookie-Set-Idcheck
Server-Int
BehaviorPad-Version
AsisCache
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Arc-Country
Cache-Prefix
Thinkindot-CacheControl-Type
X-ARC
X-B-Cookie
X-Processor
X-Block-Status
X-Application
X-Region-Sid
X-PAYTM-SRV-ID
X-Accel-Expires-Debug
X-Aed
X-Cache-Bucket
X-Cache-Info
X-Core-Mission
X-Core-Value
X-D
X-Date
X-Connection-Hash
X-Cluster-Name
X-Cdn-Origin
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-A-Wwc
X-A-Dgt
VivaBuild
Web-Mar-Node
X-Gen-Mode
Www
Viewtype
User-Cache-Control
Thinkindot-CacheControl
X-Phone
Thinkindot-Control
X-Org
X-A
X-A-Dcw
X-DPWN-IS-SECURE
X-Developer
X-Destination
X-External-Request-Id
X-Fastly-Cache
X-G
X-A-Ccd
X-A-Dam
X-Request-UUID
Fly-Request-Id
X-Trv-Group
X-Via-NSCOPI
X-Cdn-Forward
TWC-Privacy
X-Vtex-Remote-Cache
Xc-Version
TWC-Locale-Group
X-VG-WebServer
TWC-GeoIP-Country
X-Twitter-Response-Tags
TWC-Device-Class
TWC-GeoIP-LatLong
TWC-Connection-Speed
X-Worker
Webcakes-App-Name
Webcakes-App-Version
X-Thinkindot-L3
X-Matched-Rule
Webcakes-Region
X-Origin-Hint
X-Vtex-Processado-Em
Property-Id
X-Transaction
Proxy-Connection
X-ElasticPress-Search
X-Request-Time
X-TIME
X-Geo
X-Varnish-Cacheable
Backend-Name
X-Page-Type
RNT-Machine
Server-Host
RNT-Time
Request-EU
X-Origin-Expires
Memcached
X-Gannett-Site-Version
X-Origin-Date
X-Fetched-On
On-Server
Request-Time
ServerName
Request-Country
X-VC-Cache
Resin-Trace
X-PHP-Host
X-Via-SSL
X-Protected-By
X-App-Name
X-Rebelmouse-Cache-Control
X-BBXSRF
X-C
X-Cdn-Srv
X-Cache-Id
X-Cache-FS-Status
X-Cache-Debug
X-Rebelmouse-Surrogate-Control
X-Reboot
X-Debug-Log
V-Age
True-Client-Country-4JS
X-Distributor
X-Debug-Cookies
X-Secret
X-Amz-Meta-Cache-Control
X-Reqid
X-Request-URI
X-Via-Edge
X-S-Maxage
X-Geo-Header
X-No-Session
X-Hash
CDCHOST
X-Generation-Time
Esi-Enabled
Country-Code
X-Nginx-Cache-Key
X-Wikidot-Static-Cache
X-Key
X-Level-Front-Cache
X-IPS-LoggedIn
X-Instart-Isnd
X-Wikidot-Backend
X-Swa-Ws
Fastly-SIE
Backend
Gh-Request-Id
X-NX-Host
X-Generated-On
X-App-Version
X-Served-From
Fastly-SWR
X-Nc
X-FireWall-Port
Group
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
Pramga
Ha-Gx-Prefs
X-Qloud-Router
X-Cms-Context
X-Planisys-CDN-Rules
X-Location
X-Agile-Id
X-Agile-Age
X-Skip-Cache
X-SN
X-Release
X-Auto-Login
HA-Ipaddr
X-CGP
X-LI-UUID
X-Li-Fabric
X-Li-Pop
X-GEO
X-Cache-Expires
X-Varnish-Action
X-Bip
X-Planisys-CDN-TTL
X-CDN-Cache
X-Backend-State
X-TH-Server
X-Agile
X-Thanos
Adler-Geo
Mime-Version
UCS
X-WebServer
X-Dispatcher-Server
X-Webstats-RespID
X-Eu-Site
X-Variation
Platform
ProcessTime
X-GeoIP-City
X-Epic-Correlation-Id
X-GeoIP-Country-Code
X-Developers
Version
X-HS-Combine-CSS
AKAMAI
X-Planisys-CDN-Cache
Fastly-Soc-X-Request-Id
REQUESTUUID
X-HS-Cache-Config
Epwk-Cache
Is-Eu
SD-X-WS
X-Owner
X-Server-IP
Content-Disposition
X-CACHE-GROUP
X-Real-Ip
X-Edge-Location
X-Crawler
X-Distil-CS
Heartbleed
X-LAGOON
X-Device-Os
Wxu-Next-Commit
Wxu-Next-Region
Wxu-Next-Hostname
X-AIR-PT
X-Dc
Who
X-NC
Mobile-Detection-Method
Server-ID
X-Refresh
Akamai-GRN
X-AssetVersion
X-Wix-Request-Id
Time
Memory
X-LI-Proto
FNAC-ModuleRouting
X-Load-Cache
SS
X-FPC
Accept-Ch
Countrycode
X-Var-Ttl
X-Clientip
X-We-Are-Hiring
X-Servername
X-Sf
X-Parent-Response-Time
Cache-Hits
Amp-Access-Control-Allow-Source-Origin
Cache-Provider
CF-IPCountry
X-Unique-ID
X-Policy
X-CDN-Forward
X-WPE-Loopback-Upstream-Addr
X-CLOUD-TRACE-CONTEXT
NtCoent-Length
X-Dynatrace-Js-Agent
X-Internal-Host
Cdn
GW-Server
X-DC
X-CACHE-KEY
Fastcgi-X-Cache
X-Micro-Cache
A
X-Datadome
X-NWS-UUID-VERIFY
X-Be
X-ZONE
RequestId
X-Varnish-Beresp-Ttl
X-SD-PageType
Ohc-Cache-HIT
Ohc-File-Size
X-Response-By
X-Servedbyhost
X-Gdpr
X-ECACHE
X-Tb-Optimization-Total-Bytes-Saved
X-Web-Server
Geoip-City
Geoip-Latitude
GeoIp-Country-Code
X-Zone
Liferay-Portal
X-Ratelimit-Remaining
X-Hyper-Cache
SN
X-Cache-URL
X-Varnish-Beresp-Grace
CF-Cached-On
X-Varnish-Beresp-Status
Cf-Ipcountry
X-Apm-App-Name
Ajk
X-Logtrace-Id
X-RateLimit-Limit-Second
X-Apm-Inst-Hash
X-Fstrz
X-RateLimit-Remaining-Second
X-Apm-Svc-Key
Proxy-Firewall
X-APP
X-VCL-Version
X-UPSTREAM-Address
X-Request-Start
X-Pf-Uncompressing
Odigeo-Trace-Id
PICS-Label
X-Vcl-Version
HostName
X-LiteSpeed-Cache-Control
Section-Io-Cache
XServer
X-MServer
X-Fastly-Country-Code
X-Aicache-OS
X-SERVER-NAME
CDN
X-Lb-Id
X-HS-Status
X-Varnish-Beresp-TTL
X-Dispatch
MIME-Version
Is-Session-Tracking
X-Newrelic-Synthetics
Get-Access-Time
Cdn-Request-Time
GeoIP-Country-Code
Cdn-Host
GeoIP-Latitude
X-NodeID
X-Method
GeoIP-City
X-Edge-Server
PFcat
X-Ratelimit-Limit
X-FORWARDED-FOR
X-VServer
X-ServedByHost
X-Server-Group
X-Amzn-Remapped-Date
X-Amzn-Remapped-Connection
X-CS
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Pjax-Url
X-SRV
LB
X-Cache-Ttl
X-Nananana
X-Backend-TTL
X-COUNTRY
X-Fastly-Backend-Reqs
Requestid
WebServer
X-Check-Cacheable
X-PF-Uncompressing
X-WA
X-B3-SpanId
Pragrma
Host-ID
X-Powered-By-Defense
X-Dynatrace
X-Correlation-ID
CACHE
X-Newrelic-App-Data
X-Up
X-HTML-Minification-Powered-By
X-Azure-Ref
X-RequestId
X-Azure-Ref-OriginShield
Powered-By
AR-SID
X-Compress-Hint
X-Server-W
X-Amzn-Remapped-Content-Length
X-LiteSpeed-Tag
X-CUA
Sid
X-CSRF-TOKEN
Lb
X-NGINX-Cache
X-Edge
X-WR-MODIFICATION
X-Clara-WADP
X-WADP-Cache
TTL
X-Contensis-Viewer-Groups
X-Varnish-Authentication
X-Oss-Storage-Class
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
X-Oss-Server-Time
X-EC-Lua
X-MSEdge-Features
X-Cache-ASPX
Correlation-Id
X-Backend-Url
X-Bc
X-MSEdge-Flight
Server-Cache-Control
W
X-Backend-Host
X-Wa
Server-Surrogate-Control
Dynatrace
L
X-Html-Edge-Cache
X-ServerName
X-Gateway-Cache-Status
Cneonction
X-Gateway-Skip-Cache
X-Dw-Trace-Id
X-LB-ID
X-Request-Url
X-PJAX-URL
X-Debug-Cache-Expiry
X-Svr
X-BC
User-Agent
X-Gateway-Cache-Key
X-Debug-Cache-Fetch
X-User
X-Swift-Error
X-F5-Cache
X-Debug-Cache-Store
X-Mid
Magicmarker
X-Fpc
X-Cache-Tag
URI
X-Akamai-Request-ID2
X-Fastly-Cache-Hits
X-Li-Proto
X-Via-Ucdn
X-Varnish-Url
X-RateLimit-Reset
X-HTML-Edge-Cache
X-Requestid
X-Got-Non-Ke-Cookie
X-Edge-IP
N-Cache
X-Generated-In
Accept-Language
352pxline
286prxHost
225prxHost
189phosttRef
219prxHost
355prline
X-MCACHE
409pxxline
X-Proxy-Cache-Status
X-Proxy-Upstream
188prxHost
Pagetype
Locale
X-TT-LOGID
X-Urbn-Context-Path
Ttl
X-Cache-Miss-From
X-Sedo-Request-Id
Server-Id
X-CSRF-Token
Warning
X-MID
DataCenter
WP-Super-Cache
X-BE
178proxuri
X-Unique-Id
X-Urbn-Site-Id
Xxline
X-Akamai-SSL-Client-Sid
RequestUuid
FSS-Proxy
FSS-Cache
X-Cache-Detail
X-ABtesting
X-Exp-Se
X-Hello
X-Flog
V-Cache
X-Sucuri-Cache
X-App
X-Alicdn-Da-Ups-Status
X-Gen-Id
X-GDPR
X-Sucuri-ID
Ohc-Response-Time