Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-Powered-By
Pragma
CF-Cache-Status
Link
ETag
Expect-CT
Via
Age
X-Cache
X-XSS-Protection
CF-RAY
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-Xss-Protection
X-Cache-Hits
X-Amz-Cf-Pop
Referrer-Policy
X-Amz-Cf-Id
CF-Ray
P3P
X-UA-Compatible
X-Served-By
Alt-Svc
X-Varnish
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-FRAME-OPTIONS
X-Drupal-Cache
X-Check
X-Adblock-Key
Content-Security-Policy-Report-Only
P3p
X-Ua-Compatible
X-Cacheable
X-Permitted-Cross-Domain-Policies
X-DNS-Prefetch-Control
X-Generator
X-Cache-Status
Timing-Allow-Origin
X-Iinfo
X-Template
X-Language
Status
Upgrade
X-Content-Security-Policy
X-Request-ID
X-CDN
X-Buckets
X-AspNetMvc-Version
Content-Encoding
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Via
X-Turbo-Charged-By
X-AH-Environment
X-Drupal-Dynamic-Cache
X-Envoy-Upstream-Service-Time
X-Cache-Group
X-Pass-Why
X-Ws-Request-Id
X-Backend
X-Age
EagleId
X-Server
X-Proxy-Cache
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
Xkey
X-Page-Speed
X-Hacker
X-Server-Powered-By
Feature-Policy
X-Pingback
Server-Timing
Request-Context
X-Swift-SaveTime
X-Swift-CacheTime
X-Nginx-Cache-Status
Ali-Swift-Global-Savetime
Grace
X-Varnish-Cache
X-UA-Device
X-Amz-Version-Id
Cf-Railgun
Report-To
X-OneAgent-JS-Injection
X-LiteSpeed-Cache
X-Rq
X-Server-Id
X-Device
X-Origin-Cache
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
EagleEye-TraceId
X-Vhost
X-Host
X-Backend-Server
X-Node
X-Response-Time
NEL
X-Dispatcher
X-Ac
X-WebKit-CSP
X-Cache-Lookup
X-Origin-Upstream-Status
X-Readtime
Surrogate-Control
Request-Id
Content-Location
X-Ruxit-JS-Agent
X-Application-Context
Fusion-Component-Id
Fusion-Content-Id
Fusion-Content-Source
Fusion-Template-Id
Fusion-Source
X-HW
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Cnection
X-DataDome
X-Country
X-Mod-Pagespeed
X-Akam-SW-Version
X-Url
X-Cloud-Trace-Context
Edge-Control
Rating
X-Rack-Cache
X-Clacks-Overhead
RTSS
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-FTR-Request-ID
X-PC
X-TtlSet
X-Vname
X-Goog-Hash
X-Varnish-TTL
X-Country-Code
X-DynaTrace
X-ASPNET-VERSION
X-Instart-Request-ID
Service-Worker-Allowed
Verso
X-GitHub-Request-Id
Allow
X-Dns-Prefetch-Control
Content-MD5
X-D2id
X-MS-InvokeApp
X-Server-Name
Fusion-Deployment-Id
X-Kinja-Revision
X-Use-Magma
X-Exp-Id
X-Kinja-Server
X-Kinja-Build
X-Cdn-Fetch
X-Exp-Variant
X-GoogleNews-Bot
X-Kinja
Pinterest-Generated-By
X-ESI
SPRequestGuid
X-Cached
X-Ttl
X-Powered-By-Plesk
X-Navigation-Version
X-Forwarded-Proto
X-Vcache
Accept-CH
TCN
X-Trace
X-Abt-Application-Version
X-Amz-Server-Side-Encryption
X-TEC-API-ROOT
X-Amz-Rid
X-TEC-API-VERSION
X-TEC-API-ORIGIN
Public-Key-Pins
X-SharePointHealthScore
X-Fastly-Request-ID
X-Debug
Nginx-Cache
X-MSEdge-Ref
X-Vcap-Request-Id
X-B3-TraceId
X-VARITI-CCR
Accept-CH-Lifetime
Arr-Disable-Session-Affinity
MS-Author-Via
Charset
SPRequestDuration
SPIisLatency
X-Accel-Expires
X-Cache-TTL
X-NF-Request-ID
X-Px
Display
X-Fastcgi-Cache
X-Middleton-Response
Pagespeed
Response
X-Middleton-Display
X-Content-Type
Realpath
Edge-Cache-Tag
X-Sol
X-Ser
X-DynaTrace-JS-Agent
X-Client-IP
NR-ENABLED
Cache-Tag
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Server-ID
X-Aspnetmvc-Version
X-Version
Front-End-Https
Access-Control-Request-Method
X-Powered-CMS
X-Id
S
X-Grace
X-Pinterest-Rid
Pinterest-Version
AR-Request-ID
AR-ATIME
AR-PoweredBy
X-Hp-Webp
X-Jurisdiction
X-Upstream
X-Webkit-Csp
Accept-Ch
X-T
X-Hits
X-Element-Page-Cache
X-Amz-Meta-S3cmd-Attrs
X-Content-Digest
X-Forwarded-For
MRF-Tech
X-B3-TraceId-Primal
X-Mrf-Section-Lastmod
DynaTrace
X-Dw-Request-Base-Id
X-Mrf-Item-Lastmod
Mrf-Cache-Status
X-Shield-Request-Id
AR-CACHE
Ar-Sid
WPE-Backend
Fastcgi-Cache
X-Node-Name
ServerID
X-Cache-Hit
Accept-Ch-Lifetime
X-Mobile-URL
X-Recruiting
X-FTR-Backend
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Balancer
X-FTR-Realm
X-FTR-Backend-Server
X-FTR-DC
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Generation
PB-RID
Powered
Server-Node
PB-PID
X-XRDS-Location
AMP-Access-Control-Allow-Source-Origin
TP-Cache
X-Frontend
X-HS-Content-Id
TP-L2-Cache
X-HS-Hub-Id
X-HS-Cache-Config
X-FTR-Expires
Arc-Version
X-Mobile-Rewrite
X-DIS-Request-ID
Upgrade-Insecure-Requests
X-Request-Processing-Time
X-Request-Received
X-Correlation-Id
Refresh
X-Shard
X-Ezoic-Cdn
X-Amzn-Trace-Id
X-HS-Combine-CSS
X-SERVER
Alternate-Protocol
X-NWS-LOG-UUID
Server-Name
X-Logged-In
X-Microsite
X-Request-Handler-Origin-Region
Fastly-Restarts
X-Varnish-Age
X-Geo-Country
X-FTR-Cache-Host
X-Page-Id
X-LB-Cache
Host-Header
X-F-Cache
X-Rid
X-User-Agent
X-N
X-B
X-Akamai-Edgescape
Backend-Timing
X-ATS-Timestamp
X-Content-Security-Policy-Report-Only
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
MicrosoftSharePointTeamServices
X-Via-JSL
X-TTL
X-Zen-Fury
Healthy
X-ORACLE-APMCS-REQUEST-ID
X-Kinsta-Cache
Host
X-ORACLE-APMCS-TAG
X-Origin-Server
X-Varnish-Grace
X-XRDS-LOCATION
Cache-Status
X-Content-Options
X-Request-Guid
Fastcgi-Useragent
X-Hostname
X-FB-Debug
X-App-Environment
X-AOL-HN
Section-Io-Cache
Access-Control-Allow-Method
X-ATG-Version
X-B-Cache
X-Signature
X-Instance
X-Git-Hash
X-B3-Sampled
X-TT
X-Jobs
X-Debug-Info
X-Cache-Action
X-Amz-Replication-Status
Actual-Object-TTL
X-Revision
X-Tumblr-Pixel
X-Type
X-Tumblr-User
X-Tumblr-Pixel-0
X-Whom
Paypal-Debug-Id
Frame-Options
X-Varnish-Backend
X-WebKit-CSP-Report-Only
Trailer
X-Cache-Key
X-Cluster
X-Seen-By
X-Cache-Age
X-Cache-Rule
Liferay-Portal
X-Cache-Operation
X-Content-Powered-By
X-Amz-Apigw-Id
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Contextid
X-Endurance-Cache-Level
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Activity-Id
X-Az
Tracecode
X-AppVersion
X-PHP-Backend
Source
X-FireWall-Port
X-Host-Name
X-Daa-Tunnel
X-FastCGI-Cache
X-Framework
X-WA-Info
Xserver
X-IPLB-Instance
X-Upgrade-Enabled
Retry-After
Accept-Charset
X-Mobile
X-Cached-By
X-Response-Served-From
X-Accel-Buffering
NGB
DC
X-ProcessESI
X-RemovedCookies
Srv
X-Amzn-Requestid
X-UUID
From-Origin
X-Is-Bot
X-Rendered-As
X-Handled-By
X-FW-Serve
X-FW-Hash
X-Cacheable-TTL
X-FW-Type
X-Adobe-Content
X-RateLimit-Remaining
Payment
Surrogate-Key
X-FW-Server
X-Adobe-Loc
X-FW-Static
X-RequestSource
X-GeoIP
X-Environment-Context
X-Tumblr-Pixel-1
Eomportal-Instance
X-Cache-NE
X-Region
X-Tumblr-Pixel-2
X-L-Path
X-Varnish-Server
Filters
X-UA-Device-Type
X-Srv
X-Presslabs-Stats
X-Origin-Response-Time
X-Varnish-Hostname
X-Time-Microsecs
X-Cache-TTL-Remaining
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Wix-Request-Id
X-Proxy
X-Unique-Id
X-EdgeConnect-Cache-Status
X-NGENIX-Cache
X-Cache-Server
X-Webkit-CSP
X-Backend-Name
MS-CV
Datacenter
Server-Info
X-APP-VERSION
X-Akamai-Transformed
X-Esi
X-Cache-Time
Cache-Tv-Group
X-Cache-2
Version
Filterid
X-Cache-Control
X-Status
X-Cache-Enabled
X-Mode
S-Cnection
X-Oss-Storage-Class
X-Yottaa-Optimizations
X-PressLabs-Stats
X-Yottaa-Metrics
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Oss-Request-Id
Meta-Geo
X-Cache-Var
X-CCM
X-ES-SERVER
X-CST
X-Cache-Var-Map
X-B3-Traceid
X-Path-Route
X-TNCMS
Ec-Rule-Version
X-Loop
X-IP
X-Detected-As
X-TIME
Webserver
X-RN-RSRV
X-TX-ID
X-Via-Fastly
X-R9-Blue-Green-Version
X-Real-IP
X-PERF
X-Adobe-Source
X-Proto
X-ApacheServer
ServedBy
S-Rt
X-FW-Dynamic
Cleartype
Cache-Tags
X-Hl-Ver
OT-Force-Account-Verify
X-Forwarded-Host
X-FC-Vary-Parameters
Country
TWC-Privacy
Decoy-Debug-Status
Decoy-Debug-Key
TWC-Device-Class
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Locale-Group
X-Web-Node
Decoy-Debug-TTL
Section-Io-Id
Section-Io-Origin-Status
Now
X-Redis-Cache
Property-Id
Origin-Edge-Control
Section-Io-Origin-Time-Seconds
X-ProxyCache-Key
X-Proxy-Cache-Status
X-ProxyCache-Status
TWC-Connection-Speed
NGX
Section-Origin-Responded
X-Pubstack
Webcakes-Region
X-BYPASS-REASON
X-Soup
X-Cache-Config
X-Tb
X-ShardId
X-Vgn-Hpd-Reason
X-ServerID
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Cache-Status-Check
X-EIG-Tracking-Id
X-Device-Type
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Hosted-By
X-Shopify-Stage
X-Shopify-Generated-Cart-Token
X-VWS-Id
X-Debug-Cache
X-ShopId
X-Akamai-Request-ID2
X-Alternate-Cache-Key
X-RCS-CacheZone
X-Origin
X-Origin-Hint
Webcakes-App-Version
DB-Nickname
X-SayCDN-TTL
X-AWS-Id
X-LJ-Flow-ID
X-Human
X-Locale
X-Say-Cacheable
X-Say-TTL
X-Amzn-Remapped-Content-Length
Webcakes-App-Name
Origin-Cache-Control
Access-Control-Request-Headers
Cache-Key
Akamai-GRN
Content-Disposition
Cache-Hits
X-MP-GENERATED-AT
X-NYM-Debug-Backend
X-Www-Served-By
X-NCache
X-Format
X-BCube-Filmed-By
X-Access
X-Timing-Wait
X-FB-TRIP-ID
X-Site-Version
X-JoinUs
X-Xfnlog-Site
X-Routing-Service
X-SaId
X-Section
X-Generated
Cross-Origin-Window-Policy
X-Request-Time
X-Proxied
X-Proxy-Build
X-Zipkin-Id
X-Amzn-RequestId
X-HTML-Minification-Powered-By
X-Content-Age
Azure-SlotName
Azure-InstanceId
Azure-Version
Mn-Server-Ip
Azure-RegionName
Azure-SiteName
Selected-Fe
X-Viewer-Country
Node
X-Ua-Device
X-Cache-Remote
Odigeo-Trace-Id
X-Rule
X-Geo
GEO-INFO
X-IPS-LoggedIn
X-Akamai-Request-ID
X-Pad
X-Varnish-Hits
X-Microcachable
X-Cdn
X-NewRelic-App-Data
X-No-Session
X-Generated-By
X-EC-Lua
FilterID
X-Cache-NGX
X-Backend-TTL
X-Drupal-Cache-Tags
Accept-Language
Nel
X-From
X-CACHE-KEY
X-Azure-Ref
Cf-Ipcountry
X-Dc
X-CF-Powered-By
Time
X-NWS-UUID-VERIFY
X-RateLimit-Limit
X-Uri
X-RTag
Ms-Operation-Id
X-Source
X-NC
User-Agent
X-PCL
X-Qloud-Router
X-OCL
X-PHP-Host
X-Labrador-Cache-Channel
X-App-Server
X-Old-Content-Length
X-Varnish-Cache-Hits
X-Newrelic-Synthetics
Uber-Trace-Id
X-SS-Set-Cookie
X-Time
X-Nginx-Cache
Cache-Name
X-Cache-Grace
X-VCT
Proxy-Connection
X-GoCache-CacheStatus
X-Hyper-Cache
X-CS
Geo-Info
X-Info
X-Drupal-Cache-Contexts
X-Storage
Request-EU
ServerName
Request-Country
Rendered-Blocks
GEO-REGION-INFO
Apple-News-Services-Request-Url
Arc-Country
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
A
Apple-News-Services-Handled
AsisCache
BehaviorPad-Version
MD5-Digest
Meta-Geo-Continent
Machine
T-Server
Fastcgi-X-Cache-Version
Mobile-Detection-Method
X-D
X-Rewrite-Enabled
X-Request-UUID
X-Rojux
X-S
X-S-Cookie
X-Request-URI
X-Region-Sid
X-OVcl-Cache
X-PAYTM-SRV-ID
X-Processor
X-Reboot
X-ScT
X-Session-Fingerprint
X-VG-WebServer
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-VG-WebCache
X-Vdms-Version
X-SRCache-Key
X-Transaction
X-Trv-Group
X-Twitter-Response-Tags
X-OVcl
X-GeoIP-Country-Code
X-A-Dgt
X-A-Wwc
X-Accel-Expires-Debug
X-Aed
X-A-Dcw
X-A-Dam
Viewtype
VivaBuild
X-A
X-A-Ccd
X-Application
X-ARC
X-Developer
X-DPWN-IS-SECURE
X-External-Request-Id
X-G
X-Destination
X-Date
X-Cdn-Srv
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Connection-Hash
True-Client-Country-4JS
X-B-Cookie
X-Edge-Location
X-Cluster-Name
X-Core-Value
X-DevSite-Last-Modified
X-Cdn-Origin
X-FW-Version
X-Has-Esi
X-GeoIP-City
X-Geo-Header
X-Generated-On
X-Cache-Expired-At
X-Backend-State
Server-Host
Rt-Fastcgi-Cache
PFcat
N-Cache
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-Varnish-Beresp-Grace
Viewport
X-Varnish-Beresp-Status
Thinkindot-Control
X-IN-APIGATEWAY
X-Is-Gdpr
X-Trafficlayer-App-Name
X-Thinkindot-L3
X-Sn-Servicetimems
X-ServiceProvider
X-Trafficlayer-App-Scope
X-Trafficlayer-App-Version
X-Rocket-Nginx-Bypass
X-VServer
X-VG-TLSProxy
X-Servername
X-Served-From
X-Level-Front-Cache
X-JWT-State
Memcached
X-Li-Fabric
X-Li-Pop
Cache
X-Matched-Rule
X-LI-Proto
X-IN-APIGATEWAYSSL
X-LI-UUID
Content-Script-Type
Cache-Cookie-Set-From
X-Magnolia-Registration
Content-Style-Type
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
X-Edge
X-MCACHE
X-S-Maxage
X-Cluster-Node
User-Cache-Control
X-Epic-Correlation-Id
X-Gamma-Serve
X-Eu-Site
X-Fmm-Version
X-Fetched-On
X-Fastly-Cache
X-Hash
X-LAGOON
X-Logging-Id
X-Micro-Cache
X-Ms-Request-Id
X-Irp-Debug
X-Instart-Isnd
AKAMAI
X-Distributor
Adler-Geo
X-Generated-In
X-Dispatch
X-CGP
X-Cache-URL
X-Clara-WADP
X-Clientip
X-Cms-Context
X-Cache-Tags
X-Cache-Info
X-Bc-Bl
X-Bip
X-Cache-ASPX
X-Cache-FS-Status
X-Contensis-Viewer-Groups
X-Core-Mission
X-Developers
X-Device-Os
X-Ms-Version
X-Dispatcher-Server
X-Debug-Log
X-Debug-Cookies
X-CUA
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Distil-CS
X-Origin-Date
X-Varnish-Authentication
X-Varnish-Cacheable
X-VC-Cache
X-WADP-Cache
X-Variation
X-Var-Ttl
X-TT-TIMESTAMP
X-Tumblr-Pixel-3
X-Urbn-Context-Path
X-Urbn-Site-Id
X-We-Are-Hiring
X-WebServer
X-Hnp-Log
X-Request-Host
X-Slack-Backend
X-Cache-Bucket
X-Gen-Mode
X-Block-Status
X-Webstats-RespID
X-Wikidot-Backend
X-Wikidot-Static-Cache
Web-Mar-Node
X-TrackingId
X-Trace-Id
Country-Code
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Rebelmouse-Cache-Control
X-Platform-Server
X-Owner
X-NodeID
X-NX-Host
X-BBXSRF
X-Origin-Expires
X-Rebelmouse-Surrogate-Control
X-Req
X-SIPLIST1
X-Skip-Cache
X-Swa-Ws
X-Thanos
X-Sigma-Backend
X-Sigma
X-Rocket-Build-Number
X-Scheme
X-Server-W
X-Nginx-Cache-Key
X-Proxy-Upstream
FNAC-ModuleRouting
Server-Cache-Control
Fastly-SWR
Server-ID
RNT-Time
RNT-Machine
X-Agile-Age
X-Agile
Wxu-Next-Commit
Fastly-SIE
Fastly-Drupal-HTML
Countrycode
CDCHOST
Wxu-Next-Region
Wxu-Next-Hostname
V-Age
Server-Surrogate-Control
Cache-Host
L5d-Success-Class
Gh-Request-Id
X-Agile-Id
Locid
Mail-Subject
IsBot
X-Auto-Login
Locale
X-Backend-Host
Kp-EeAlive
X-App-Name
Is-Eu
Heartbleed
HA-Ipaddr
Platform
Group
On-Server
We-Hiring
W
Ha-Gx-Prefs
X-CDN-Forward
X-Generation-Time
X-ECACHE
X-UnsetCookies
X-Response-By
X-Varnish-Beresp-Ttl
SD-X-WS
X-Hit
X-Instart-Info
X-SN
X-C
X-UA
X-Node-Id
X-Refresh
Proxy-Firewall
X-APP
Mime-Version
Vix-Hermes-Req-Id
X-Sucuri-ID
X-RESPONSE-TIME
Powered-By-ChinaCache
X-Pinterest-Direct
X-Mid
X-CSRF-Token
Request-Time
X-Cache-PHP
X-Lb-Id
X-Nc
Pramga
X-CLOUD-TRACE-CONTEXT
X-TA-CDN-Provider
CF-Cached-On
X-ND-Cache
X-App-Version
NM-Fastcgi-Cache
X-Vdms-Path
X-Varnish-URL
Cloudfront-Viewer-Country
X-Service
X-Ua
X-Edge-O15-RID
X-B3-Spanid
HitType
X-VCache
X-Pjax-Url
X-Wa
M-TraceId
X-Parent-Response-Time
Origin
X-Load-Cache
X-Varnish-Ttl
Sever-Int
Server-Ext
Server-Hostname
Environment
X-MSEdge-Flight
X-MSEdge-Features
Pagetype
X-DC
HostName
PICS-Label
X-Method
X-Ratelimit-Remaining
X-FPC
X-Up
Fastly-Backend-Name
Magicmarker
X-Via-PopH
X-Worker
X-Via-PopV
X-BACKEND-TTL
X-Protected-By
Hostname
X-Be
X-CSRF-TOKEN
Geoip-City
X-Envoy-Upstream-Healthchecked-Cluster
X-Wix-Viewer-Type
Geoip-Latitude
X-Request-Start
X-Branch-Name
X-HS-Status
X-SRV
X-Origin-TTL
X-Origin-CC
X-C-Zone
X-FORWARDED-FOR
X-C-Key
X-Correlation-ID
X-Azure-Ref-OriginShield
X-Policy
GeoIp-Country-Code
X-Server-Time
Dt-Cache-Category
X-ECache
Pragrma
X-Servedbyhost
Memory
X-URL
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
NtCoent-Length
X-Planisys-CDN-TTL
X-TT-LOGID
X-Newrelic-App-Data
Cdn-Host
X-Myra-Origin2
X-Edge-Server
Cdn-Request-Time
X-Cdn-Forward
X-VCL-Version
X-Referer
TTL
X-Zone
X-Litespeed-Cache
X-Bc
Esi-Enabled
Cdn
X-Cache-Metadata
X-GEO
X-Vcl-Version
Cdnsip
X-ZONE
Cdncip
Resin-Trace
X-AK-Request-ID
X-Cache-Host
X-BC
Who
X-Reqid
Ttl
Cteonnt-Length
Lb
X-Dynatrace-Js-Agent
SRV
CACHE
X-Via-Ucdn
X-SVT-ORM-RULES
X-VHOST
GeoIP-Country-Code
X-SVT-ORM-VERSION
Release
X-NU-AKA-ACS-Version
X-Oneagent-Js-Injection
X-Ratelimit-Limit
X-SERVER-NAME
X-Fastly-Country-Code
X-Pf-Uncompressing
X-ServedByHost
UCS
Load-Balancing
GeoIP-City
GeoIP-Latitude
X-Air-Hostname
X-Country-IP
X-NGINX-Cache
XServer
X-Swift-Error
Ohc-File-Size
Product
X-AIR-PT
Pics-Label
X-TH-Server
X-Configured-By
X-Cache-Debug
X-Fpc
X-Cache-Id
X-Tec-Api-Version
X-Tec-Api-Root
X-Esi-Check
RequestId
Dnion-Transfer-Encoding
X-Tec-Api-Origin
X-Ruxit-Js-Agent
X-Node-ID
X-COUNTRY
X-Datadome
FSS-Cache
IBM-Web2-Location
Sid
X-Gzip
Ohc-Cache-HIT
X-B3-SpanId
X-VarnishDD-TTL
X-Server-IP
MIME-Version
X-WPE-Loopback-Upstream-Addr
Server-Int
X-WA
X-Tb-Optimization-Total-Bytes-Saved
LB
X-BE
X-PJAX-URL
X-Powered-Y
X-Svr
Powered-By
X-RAMCache
C-Via
X-Ocache
X-Unique-ID
X-Fastly-Backend-Reqs
X-PF-Uncompressing
X-Varnish-Beresp-TTL
X-Fastly-Request-Id
X-Varnish-Url
Lfy
X-SD-PageType
Fastly-Soc-X-Request-Id
My-App
X-MID
X-LiteSpeed-Cache-Control
X-Location
X-Apw-Access-Action
Fastly-SSL
X-Apw-Access-Object
X-Apw-Hits
X-Apw-Access-Token
X-Flow-Id
X-Page-Impression-Id
X-RPM
X-Sucuri-Cache
X-UPSTREAM-Address
X-Mvc-Supplant-Cachable
X-RSL
Xet-Cookie
X-RPS
X-Zalando-Child-Request-Id
X-DB
X-Nananana
Requestid
X-Sucuri-Id
X-Agile-Brick-Ok
X-DI
X-Action
X-ElasticPress-Search
Amp-Access-Control-Allow-Source-Origin
X-DW
X-DSS
CF-IPCountry
X-Flog
X-Debug-Controller
CDN
X-Aicache-OS
X-Compress-Hint
X-Hello
X-Cache-Backend
X-Check-Cacheable
X-ElasticPress-Query
FSS-Proxy
X-B3-Parentspanid
X-Debug-Revision
X-ABtesting
L
X-Mvc-Supplant-OutputCached
Cneonction
URI
CloudFront-Viewer-Country
SN
X-Amzn-Remapped-Date
X-App
X-Amzn-Remapped-Connection
DataCenter
X-Request-Url
X-Dw-Trace-Id
X-Request-URL
X-MiniProfiler-Ids
Host-ID
X-Fastly-Cache-Hits
X-Render-Time
X-LB-ID