Threat Level: green Handler on Duty: Manuel Humberto Santander Pelaez

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
CF-RAY
CF-Cache-Status
Link
X-Powered-By
ETag
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Xss-Protection
X-Download-Options
X-AspNet-Version
Alt-Svc
Access-Control-Allow-Credentials
X-Runtime
X-FRAME-OPTIONS
X-Drupal-Cache
X-Adblock-Key
X-Check
Content-Security-Policy-Report-Only
X-Generator
X-Cacheable
X-Cache-Status
X-Permitted-Cross-Domain-Policies
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Template
X-Language
X-Iinfo
X-Content-Security-Policy
Content-Encoding
Status
X-AspNetMvc-Version
X-Buckets
X-Kinja-Server-Push
Xkey
Upgrade
X-Request-ID
X-Via
Access-Control-Expose-Headers
X-Turbo-Charged-By
Access-Control-Max-Age
Keep-Alive
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Pass-Why
X-Age
EagleId
X-Backend
X-Envoy-Upstream-Service-Time
X-Robots-Tag
X-Amz-Id-2
X-Amz-Request-Id
X-CDN
X-Ua-Compatible
X-Page-Speed
X-Pingback
X-Server-Powered-By
X-Server
X-UA-Device
X-Proxy-Cache
X-Hacker
X-AH-Environment
Request-Context
X-Nginx-Cache-Status
X-Swift-SaveTime
X-Swift-CacheTime
Grace
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-Cdn
X-LiteSpeed-Cache
P3p
Cf-Railgun
Server-Timing
Feature-Policy
X-Amz-Version-Id
X-Device
X-WebKit-CSP
X-Server-Id
X-OneAgent-JS-Injection
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Rq
X-Ac
X-Cnection
EagleEye-TraceId
Report-To
X-Cloud-Trace-Context
Request-Id
X-Backend-Server
X-Response-Time
X-Host
Content-Location
X-Node
X-Readtime
X-Origin-Cache
X-Vhost
X-Cache-Lookup
X-Application-Context
X-Dns-Prefetch-Control
X-DataDome
X-ORACLE-DMS-ECID
X-Dispatcher
X-Ruxit-JS-Agent
NEL
X-ORACLE-DMS-RID
X-Rack-Cache
X-Origin-Upstream-Status
X-HW
Surrogate-Control
Rating
X-Clacks-Overhead
Allow
X-Country-Code
X-Country
X-Url
X-FTR-Request-ID
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-DynaTrace
X-MS-InvokeApp
Fusion-Template-Id
Fusion-Content-Id
Fusion-Content-Source
Fusion-Source
Fusion-Component-Id
X-Instart-Request-ID
X-Goog-Hash
X-TTL
X-TtlSet
X-PC
X-Vname
X-Varnish-TTL
X-Ah-Environment
X-B3-TraceId
Verso
X-Powered-By-Plesk
Pinterest-Generated-By
X-Px
Public-Key-Pins
RTSS
Edge-Control
X-Mod-Pagespeed
X-VARITI-CCR
SPRequestGuid
Display
Response
X-D2id
X-Middleton-Response
X-Middleton-Display
X-Sol
X-Kinja-Revision
X-Use-Magma
X-Kinja-Build
X-Cdn-Fetch
X-Exp-Variant
X-Exp-Id
X-Akam-SW-Version
X-GoogleNews-Bot
X-Kinja
X-Kinja-Server
X-SharePointHealthScore
X-ESI
X-CST
X-Recruiting
Service-Worker-Allowed
X-Vcap-Request-Id
Accept-Ch-Lifetime
SPIisLatency
SPRequestDuration
X-Version
X-GitHub-Request-Id
TCN
X-Navigation-Version
X-Powered-CMS
X-Abt-Application-Version
MS-Author-Via
X-Server-Name
X-Trace
X-Debug
Charset
X-Shard
Accept-CH
Nginx-Cache
Fastly-Restarts
X-Amz-Server-Side-Encryption
X-Amz-Rid
X-Upstream
Realpath
Ar-Sid
AR-PoweredBy
AR-CACHE
AR-ATIME
X-Aspnetmvc-Version
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-RateLimit-Remaining
X-Forwarded-Proto
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-NF-Request-ID
X-Ezoic-Cdn
Front-End-Https
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-MSEdge-Ref
X-Cached
DynaTrace
Access-Control-Request-Method
Arr-Disable-Session-Affinity
Pagespeed
Content-MD5
X-Shield-Request-Id
AR-Request-ID
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
MicrosoftSharePointTeamServices
X-FTR-Cache-Status
X-FTR-Expires
X-Country-Code-Real
X-VCache
S
X-DynaTrace-JS-Agent
X-Amz-Meta-S3cmd-Attrs
X-Goog-Storage-Class
X-Fastly-Request-ID
X-XRDS-Location
X-T
X-Ser
X-FTR-DC
X-FTR-Backend-Server
X-FTR-Backend
Paypal-Debug-Id
X-FTR-Realm
X-FTR-Balancer
X-Id
X-Varnish-Age
ServerID
X-Via-JSL
X-Grace
Accept-Ch
X-Accel-Expires
X-Content-Type
X-Client-IP
X-Correlation-Id
X-Server-ID
X-Dw-Request-Base-Id
Edge-Cache-Tag
X-Forwarded-For
Fastcgi-Cache
X-Hits
X-Amzn-Trace-Id
X-Content-Digest
X-Frontend
X-DIS-Request-ID
Powered
AMP-Access-Control-Allow-Source-Origin
X-N
X-Fastcgi-Cache
X-Vcache
PB-RID
X-Mobile-Rewrite
Arc-Version
PB-PID
X-FTR-Cache-Host
X-HS-Hub-Id
X-HS-Content-Id
Pinterest-Version
X-Pinterest-Rid
Server-Name
X-Logged-In
TP-L2-Cache
TP-Cache
X-FastCGI-Cache
X-Request-Received
X-Request-Processing-Time
X-Kinsta-Cache
X-Microsite
X-Request-Handler-Origin-Region
X-Zen-Fury
X-Cache-Hit
X-Rid
X-LB-Cache
X-Time
X-IPLB-Instance
X-AppVersion
X-Activity-Id
X-Type
Healthy
X-Az
X-GUploader-UploadID
X-User-Agent
X-Revision
X-Cache-Age
Retry-After
X-Whom
Backend-Timing
X-Analytics
X-Srv
X-B3-Sampled
X-Node-Name
Server-Node
FilterID
X-NWS-LOG-UUID
X-RateLimit-Limit
Alternate-Protocol
X-Hp-Webp
Cache-Tag
Accept-Charset
X-F-Cache
X-Akamai-Edgescape
X-SERVER
X-Content-Security-Policy-Report-Only
Cache-Status
X-Content-Options
NR-ENABLED
X-Cache-Rule
X-Erf-Bev-Bev
DC
X-Erf-Bev-Bev-Is-Generated
X-Amz-Apigw-Id
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-User
X-Cluster
X-AOL-HN
X-Kong-Upstream-Latency
X-Amzn-RequestId
X-Content-Powered-By
X-Kong-Proxy-Latency
X-FB-Debug
Refresh
VIX-Pulpo-Node
MS-CV
X-Cache-2
X-Varnish-Grace
Access-Control-Allow-Method
X-Jobs
VIX-Pulpo-Upstream-Status
X-Webkit-CSP
X-App-Environment
X-Instance
X-Debug-Info
X-Page-Id
Tracecode
X-PHP-Backend
X-B
X-Framework
Source
X-Cache-TTL
X-Seen-By
X-Request-Guid
X-Forwarded-Host
Actual-Object-TTL
Surrogate-Key
X-App-Server
X-Mobile-URL
Host
Fastcgi-Useragent
X-Cache-Operation
X-Cache-Key
X-Geo-Country
Frame-Options
X-FW-Static
X-FW-Server
X-FW-Type
X-FW-Hash
X-FW-Serve
X-Cache-Control
X-Pad
X-Cached-By
X-Hostname
X-Host-Name
Cleartype
X-TA-CDN-Provider
X-Element-Page-Cache
X-B-Cache
X-Signature
Upgrade-Insecure-Requests
X-WebKit-CSP-Report-Only
X-Git-Hash
X-BCube-Filmed-By
X-Mobile
X-ATG-Version
X-Varnish-Backend
X-Response-Served-From
NGB
X-XRDS-LOCATION
Xserver
X-Esi
X-HS-Cache-Config
X-GeoIP
X-RemovedCookies
X-ProcessESI
X-UA-Device-Type
X-Tumblr-Pixel-2
Webserver
Eomportal-Instance
X-Amz-Replication-Status
X-Tumblr-Pixel-1
Filters
Cache-Tv-Group
X-TT
X-EdgeConnect-Cache-Status
X-Handled-By
X-RTag
X-Drupal-Cache-Tags
Ms-Operation-Id
X-Daa-Tunnel
X-Adobe-Content
X-Adobe-Loc
GEO-INFO
WPE-Backend
Payment
X-RequestSource
X-Cacheable-TTL
X-Origin-Server
From-Origin
X-TX-ID
X-TT-TIMESTAMP
X-Wix-Request-Id
X-Cache-TTL-Remaining
X-Cache-Remote
X-B3-Traceid
X-Presslabs-Stats
Datacenter
X-Status
Liferay-Portal
Cache
X-FW-Dynamic
X-WA-Info
X-Hyper-Cache
Accept-CH-Lifetime
X-Contextid
X-Region
X-Cache-Action
X-Acc-Meta-Resource-Type
Version
X-Edge-Location
X-Content-Age
Viewport
X-Ratelimit-Reset
X-CF-Powered-By
X-Ttl
X-Cache-NE
X-Varnish-Hostname
X-HS-Combine-CSS
X-Akamai-Transformed
X-Storage
X-Cache-Server
PageSpeed
X-PressLabs-Stats
X-Varnish-Server
Meta-Geo
X-ES-SERVER
X-Cache-Var-Map
X-RN-RSRV
Load-Balancing
X-Path-Route
X-Cache-Var
X-Accel-Buffering
Host-Header
X-IP
Country
X-Via-Fastly
X-Proxy
X-Xfnlog-Site
X-Cache-Enabled
Ohc-File-Size
X-Viewer-Country
X-Device-Type
Cache-Name
X-CCM
X-Proto
DB-Nickname
X-UnsetCookies
X-Cache-Time
Rt-Fastcgi-Cache
X-Tumblr-Pixel-3
X-Cache-Config
X-Debug-Cache
Cache-Tags
X-Loop
X-NCache
X-TNCMS
Ec-Rule-Version
DSUID
Webcakes-Region
X-Varnish-Cache-Hits
X-OCL
X-Www-Served-By
X-Upgrade-Enabled
X-PCL
X-FC-Vary-Parameters
X-Proxy-Build
X-Yottaa-Metrics
X-Labrador-Cache-Channel
X-Cache-Host
X-EIG-Tracking-Id
Vix-Hermes-Req-Id
X-CS
X-Rule
X-Akamai-Request-ID2
X-Cache-Grace
X-Timing-Wait
X-From
X-Backend-TTL
TWC-Device-Class
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Connection-Speed
Selected-Fe
Release
S-Rt
TWC-Locale-Group
TWC-Privacy
X-Origin-Hint
X-Backend-Name
X-Yottaa-Optimizations
X-JoinUs
X-Origin
X-Hosted-By
Webcakes-App-Version
Property-Id
Webcakes-App-Name
X-NewRelic-App-Data
X-Drupal-Cache-Contexts
Decoy-Debug-TTL
X-FireWall-Port
X-Akamai-Request-ID
X-Time-Microsecs
X-Web-Node
X-Varnish-Hits
Mn-Server-Ip
Decoy-Debug-Status
X-Generated
X-VCT
X-Origin-Response-Time
X-R9-Blue-Green-Version
X-Site-Version
X-Vgn-Hpd-Reason
X-Locale
Decoy-Debug-Key
X-Human
Cache-Hits
Azure-Version
X-Goog-Meta-Goog-Reserved-File-Mtime
Azure-SiteName
Azure-InstanceId
Azure-SlotName
S-Cnection
Azure-RegionName
X-Hit
X-PERF
X-ApacheServer
X-Section
X-Access
X-OVcl
X-Rendered-As
X-Real-IP
X-OVcl-Cache
X-Format
X-Cluster-Node
Ohc-Cache-HIT
X-S
Cache-Key
Time
X-Trace-Id
Server-Info
X-Ua
Origin-Cache-Control
Origin-Edge-Control
X-NGENIX-Cache
L5d-Success-Class
X-Pubstack
X-Redis-Cache
X-APP-VERSION
X-Trafficlayer-App-Name
X-Trafficlayer-App-Scope
X-FW-Version
Now
Fastcgi-X-Cache-Version
OT-Force-Account-Verify
X-Litespeed-Cache
Fastly-SSL
X-SS-Set-Cookie
X-Upstream-CT
X-Upstream-HT
X-Cluster-Name
X-Origin-TTL
X-ServerID
X-Origin-CC
Cteonnt-Length
X-Load-Cache
Access-Control-Request-Headers
Hostname
X-UUID
X-FB-TRIP-ID
X-ShardId
X-Alternate-Cache-Key
Mime-Version
Origin
X-ShopId
X-Shopify-Stage
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-GoCache-CacheStatus
X-Parent-Response-Time
X-Rocket-Nginx-Bypass
ServedBy
X-VG-WebCache
X-Soup
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
X-Webkit-Csp
Accept-Language
X-VG-TLSProxy
NtCoent-Length
Machine
X-Upstream-Proxy
X-Is-Bot
Odigeo-Trace-Id
NGX
X-Uri
X-App-Version
IBM-Web2-Location
X-Info
Nel
X-Tb
X-No-Session
X-ProxyCache-Key
X-BYPASS-REASON
X-Node-Id
X-ProxyCache-Status
X-ECACHE
X-Environment-Context
X-Guploader-Uploadid
X-MServer
X-L-Path
X-UA
X-CACHE-KEY
X-CSRF-TOKEN
X-Geo
X-Connection-Hash
X-A-Ccd
X-CF-Lambda-Version
X-A-Dam
X-A-Dcw
X-CF-Lambda-Fn
X-A
X-S-Cookie
X-Cms-Context
Viewtype
VivaBuild
X-Rewrite-Enabled
X-Rojux
X-A-Dgt
X-A-Wwc
X-Server-Time
X-Destination
X-Detected-As
X-Application
X-ScT
X-B-Cookie
X-Date
X-Aed
X-Accel-Expires-Debug
X-AIR-PT
X-Developer
X-D
X-ARC
ServerName
Fly-Cache
Cross-Origin-Window-Policy
Content-Style-Type
Fly-Request-Id
GEO-REGION-INFO
Uber-Trace-Id
X-PAYTM-SRV-ID
Content-Script-Type
Cache-Prefix
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
A
Arc-Country
BehaviorPad-Version
AsisCache
X-Instart-Info
X-Hl-Ver
Rt-Proxy-Cache
Request-EU
Request-Country
X-External-Request-Id
Apple-News-Services-Handled
T-Server
X-Request-UUID
Rendered-Blocks
X-G
X-Region-Sid
MD5-Digest
Memcached
Meta-Geo-Continent
Node
Mobile-Detection-Method
X-DPWN-IS-SECURE
X-B3-Parentspanid
CF-IPCountry
X-Transaction
X-VG-WebServer
X-SRCache-Key
Xc-Version
X-B3-Spanid
X-Vtex-Remote-Cache
X-Trv-Group
Request-Time
Proxy-Connection
X-Vtex-Processado-Em
X-Twitter-Response-Tags
X-Nc
Srv
X-Oneagent-Js-Injection
X-Endurance-Cache-Level
Backend-Name
X-Tt-Trace-Tag
X-WADP-Cache
X-PHP-Host
X-B3-SpanId
Mail-Subject
X-Worker
N-Cache
IsBot
X-Has-Esi
X-Is-Gdpr
X-JWT-State
X-Device-Os
X-Nginx-Cache
We-Hiring
X-Generated-By
X-Clara-WADP
X-S-Maxage
X-Cdn-Srv
X-Cache-Bucket
X-SVT-ORM-RULES
X-SIPLIST1
X-Amzn-Remapped-Content-Length
X-SVT-ORM-VERSION
X-NC
X-Via-CDN
User-Cache-Control
X-Debug-Cookies
RNT-Time
RNT-Machine
X-Gen-Mode
X-ElasticPress-Search
X-Debug-Log
X-Fetched-On
PFcat
X-Cache-Info
X-GeoIP-City
X-Block-Status
X-Clientip
X-Cdn-Origin
X-Geo-Header
X-Generation-Time
X-Fastly-Cache
Pagetype
Platform
X-Hnp-Log
X-Backend-Url
X-BBXSRF
X-Hash
X-Debug-Cache-Expiry
X-Request-URI
X-Debug-Cache-Fetch
X-Sn-Servicetimems
X-Backend-Host
X-Auto-Login
X-Amz-Meta-Cache-Control
X-Proxy-Upstream
X-Cache-FS-Status
X-NX-Host
X-Debug-Cache-Store
Server-Host
Served-By
X-Distributor
X-Proxy-Cache-Status
X-CUA
X-Developers
X-Dispatch
X-Dispatcher-Server
Section-Io-Cache
X-IN-APIGATEWAYSSL
X-Var-Ttl
X-Release
X-Magnolia-Registration
X-Variation
X-Reqid
X-Request-Start
X-Platform-Server
X-LI-UUID
X-Location
X-VC-Cache
X-Ratelimit-Limit
Adler-Geo
X-We-Are-Hiring
X-Origin-Date
X-Origin-Expires
X-Old-Content-Length
AKAMAI
X-Reboot
X-Webstats-RespID
X-WebServer
Content-Disposition
X-User
X-Skip-Cache
X-Server-IP
X-IN-APIGATEWAY
X-Compress-Hint
X-Irp-Debug
Gh-Request-Id
Fastly-Soc-X-Request-Id
Is-Eu
X-Li-Pop
X-Up
X-Li-Fabric
Countrycode
X-TrackingId
Akamai-GRN
X-Cdn-Forward
X-Say-Cacheable
X-Svr
X-Say-TTL
X-VServer
X-Thanos
X-Urbn-Context-Path
X-Urbn-Site-Id
X-SayCDN-TTL
X-Core-Mission
X-Thinkindot-L3
X-SD-PageType
X-Wikidot-Backend
X-Generated-On
Thinkindot-CacheControl
Server-Int
Locale
Kp-EeAlive
Thinkindot-CacheControl-Type
X-Level-Front-Cache
X-Cache-Id
Web-Mar-Node
X-Service
Thinkindot-Control
X-Key
X-Generated-In
X-LI-Proto
X-Wikidot-Static-Cache
X-Distil-CS
True-Client-Country-4JS
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Nginx-Cache-Key
X-Method
X-Matched-Rule
CDCHOST
X-Eu-Site
X-Epic-Correlation-Id
X-Policy
X-Owner
X-Bip
Ha-Gx-Prefs
HA-Ipaddr
X-Azure-Ref
Wxu-Next-Region
Wxu-Next-Hostname
X-Dc
Wxu-Next-Commit
X-Azure-Ref-OriginShield
SD-X-WS
Magicmarker
X-CGP
Pramga
L
Heartbleed
X-C
Esi-Enabled
X-Microcachable
X-NWS-UUID-VERIFY
SRV
X-Swa-Ws
X-MSEdge-Features
X-MSEdge-Flight
X-Servername
X-Qloud-Router
X-ServiceProvider
Memory
V-Age
X-Rebelmouse-Surrogate-Control
Cache-Provider
X-Internal-Host
X-Lb-Id
X-Rebelmouse-Cache-Control
Server-ID
X-Cache-URL
Fastly-SIE
Fastly-SWR
W
X-App-Name
Resin-Trace
X-Backend-State
X-FPC
X-Oracle-Dms-Rid
X-Instart-Isnd
X-Scheme
X-Cache-Backend
X-GEO
X-Processor
Cdn-Host
Cdn-Request-Time
X-AWS-Id
X-DC
X-Edge-Server
X-VWS-Id
X-LJ-Flow-ID
REQUESTUUID
X-Be
X-GDPR
X-Mode
X-Request-Time
X-Org
Group
X-ABtesting
SS
X-Wa
X-Flog
X-Servedbyhost
X-Pjax-Url
X-Hello
X-NodeID
X-Datadome
X-Server-W
X-CDN-Forward
Cache-Host
X-Response-By
X-IPS-LoggedIn
X-Unique-ID
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
X-Oss-Storage-Class
Country-Code
X-Oss-Request-Id
X-Oss-Object-Type
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
X-Page-Type
X-SN
X-Ms-Version
Cache-Cookie-Set-From
X-VCL-Version
X-Ms-Request-Id
X-Ratelimit-Remaining
X-Ruxit-Js-Agent
X-Varnish-Beresp-Status
X-Session-Fingerprint
X-Varnish-Beresp-Grace
PICS-Label
X-Varnish-Beresp-Ttl
X-Zipkin-Id
X-Routing-Service
X-EC-Lua
X-Proxied
X-Zone
X-SRV
X-Via-Ucdn
X-HS-Status
X-Ftr-Request-Id
UCS
X-Cache-Debug
Lfy
X-Tb-Optimization-Total-Bytes-Saved
X-Dynatrace
X-Webapp-Samesite-None-Activated-N
Ttl
X-Pf-Uncompressing
X-COUNTRY
X-URL
Powered-By-ChinaCache
X-GRACE
X-DataStream-Cache-Status
X-Agile-Id
X-7Graus-Varnish-XKeys
X-Agile
X-Agile-Age
SN
X-Logtrace-Id
Ajk
GeoIp-Country-Code
Geoip-City
X-7Graus-Varnish-Cache-Control
Geoip-Latitude
X-CSRF-Token
X-Varnish-Beresp-TTL
X-MP-GENERATED-AT
X-RateLimit-Reset
Proxy-Firewall
Environment
GeoIP-Latitude
X-Fastly-Country-Code
GeoIP-Country-Code
GeoIP-City
X-Sedo-Request-Id
X-Cache-Miss-From
X-Unique-Id
X-Source
ProcessTime
X-Cache-Category-Id
Powered-By
X-APP
X-Sucuri-Id
X-Newrelic-Synthetics
X-Logging-Id
X-ZONE
X-Grey
X-PF-Uncompressing
XServer
X-Bc
X-NODE
X-Sucuri-ID
X-HTML-Minification-Powered-By
X-Ftr-Cache-Host
Cdn
X-CLOUD-TRACE-CONTEXT
X-Vcl-Version
X-Tt-Trace-Host
X-TH-Server
X-Core-Value
X-Check-Cacheable
M-TraceId
X-LiteSpeed-Cache-Control
CF-Cached-On
X-Edge
Pics-Label
X-DataStream-MidMile-RTT
X-Vdms-Version
X-Aicache-OS
CACHE
Fastly-Backend-Name
X-DataStream-Origin-MEX-Latency
WWW
Cdncip
Cdnsip
X-AK-Request-ID
Cf-Ipcountry
X-Ftr-Realm
X-Swift-Error
X-Ftr-Backend
HostName
X-Ftr-Backend-Server
X-Dynatrace-Js-Agent
X-Ftr-Balancer
X-Ftr-Dc
X-Shopify-Generated-Cart-Token
X-Fstrz
GW-Server
X-Mid
X-Planisys-CDN-Cache
X-Fastly-Backend-Reqs
Pragrma
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Sigma
Requestid
X-Rocket-Build-Number
X-RCS-CacheZone
X-Sucuri-Cache
X-Sigma-Backend
MIME-Version
X-ServedByHost
X-FORWARDED-FOR
X-Varnish-Ttl
LB
X-Cache-Tag
X-Via-NSCOPI
X-LAGOON
X-MCACHE
Amp-Access-Control-Allow-Source-Origin
X-BE
X-TT-LOGID
X-NGINX-Cache
X-BC
X-Gannett-Site-Version
X-SaId
X-WA
X-ORACLE-APMCS-TAG
X-ORACLE-APMCS-REQUEST-ID
X-Litespeed-Cache-Control
Ohc-Response-Time
X-Varnish-Url
X-Secret
X-UPSTREAM-Address
URI
X-SERVER-NAME
Lb
X-CDN-Cache
X-Action
TTL
X-ND-Cache
X-DB
X-DI
X-RPM
X-PJAX-URL
X-DW
X-DSS
X-RSL
X-RPS
X-Cache-Ttl
X-Upstream-Ht
X-Upstream-Ct
Dynatrace
On-Server
RequestUuid
WZWS-RAY
Host-ID
X-Varnish-Cacheable
X-WR-MODIFICATION
X-Trafficlayer-App-Version
X-GeoIP-Country-Code
X-Refresh
DataCenter
X-Correlation-ID
CDN
X-Via-Edge
X-Via-SSL
X-Fpc
Is-Session-Tracking
X-Flow-Id
Server-Id
X-Fastly-Cache-Hits
Inserted-Into-Cache-At
Get-Access-Time
Xkeyrz
X-Page-Impression-Id
X-Zalando-Child-Request-Id
User-Agent
Xkeypdq
X-Proxy-Cacherz
X-Gamma-Serve
X-Nananana
Gannett-Cam-Experience-Id
X-Pod
X-Req
X-Dw-Trace-Id
X-MID
Warning
X-Served-From
X-SB
X-VC
Locid
Correlation-Id
X-Cf-Powered-By
X-Akamai-SSL-Client-Sid
X-Akamai-ERPolicy
FNAC-ModuleRouting
X-Akamai-ERRuleID
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
X-Li-Proto
X-Crawler
Thinkindot-Cache-Type
X-LB-ID
X-ServerName
Xet-Cookie
X-Request-URL
X-Newrelic-App-Data
V-Cache
X-MiniProfiler-Ids
Cneonction
X-Gdpr
Processtime
RequestId
SID
HitType
Who
X-LiteSpeed-Tag
X-Gen-Id
X-ECache
X-NU-AKA-ACS-Version
X-Bug-Bounty