Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
Last-Modified
Accept-Ranges
Pragma
X-Content-Type-Options
X-Powered-By
CF-RAY
ETag
Link
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Access-Control-Allow-Origin
Content-Security-Policy
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Served-By
X-Amz-Cf-Id
X-Varnish
Referrer-Policy
X-Timer
X-Xss-Protection
CF-Cache-Status
X-FRAME-OPTIONS
X-Request-Id
Access-Control-Allow-Headers
X-AspNet-Version
Access-Control-Allow-Methods
X-Runtime
X-Download-Options
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Cacheable
Alt-Svc
X-Generator
Content-Security-Policy-Report-Only
X-Request-ID
X-AspNetMvc-Version
Status
X-Check
X-Cache-Status
X-Adblock-Key
Timing-Allow-Origin
X-Iinfo
X-Permitted-Cross-Domain-Policies
X-DNS-Prefetch-Control
X-Template
Content-Encoding
X-Language
X-Content-Security-Policy
X-Turbo-Charged-By
X-CDN
X-Type
Keep-Alive
Xkey
X-Buckets
X-Backend
X-AH-Environment
WPE-Backend
Access-Control-Max-Age
X-Pass-Why
X-Age
X-Cache-Group
CF-Ray
X-Server
X-POWERED-BY
Upgrade
EagleId
Access-Control-Expose-Headers
X-Via
X-Nginx-Cache-Status
X-Server-Powered-By
X-Pingback
X-Drupal-Dynamic-Cache
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Grace
X-Hacker
X-Amz-Request-Id
X-Amz-Id-2
Ali-Swift-Global-Savetime
X-UA-Device
X-Robots-Tag
Cf-Railgun
X-LiteSpeed-Cache
X-Envoy-Upstream-Service-Time
X-Proxy-Cache
X-Ua-Compatible
X-Page-Speed
Request-Context
Content-Location
X-Device
X-Ac
X-Node
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cnection
X-Host
X-Cache-Lookup
X-Server-Id
Surrogate-Control
X-Amz-Version-Id
X-WebKit-CSP
X-Backend-Server
X-Rack-Cache
X-Response-Time
X-Rq
X-CST
X-Application-Context
X-Readtime
X-Dns-Prefetch-Control
EagleEye-TraceId
P3p
Pinterest-Generated-By
Server-Timing
X-Url
X-Cloud-Trace-Context
X-TTL
X-Instart-Request-ID
X-Px
Request-Id
X-OneAgent-JS-Injection
Report-To
X-Country
X-ORACLE-DMS-ECID
X-Clacks-Overhead
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Allow
Rating
Feature-Policy
Edge-Control
X-Country-Code
X-DynaTrace-JS-Agent
Charset
X-DataDome
X-ESI
X-Server-Name
X-Powered-CMS
X-FTR-Request-ID
X-Vname
X-PC
X-TtlSet
X-Origin-Cache
X-DynaTrace
NEL
X-MS-InvokeApp
X-ORACLE-DMS-RID
X-Goog-Hash
X-Recruiting
X-Varnish-TTL
X-Cached
X-VARITI-CCR
X-Vhost
Content-MD5
RTSS
X-GitHub-Request-Id
X-Version
X-F-Cache
X-Cdn-Fetch
X-Kinja-Server
X-Kinja-Build
X-Kinja
X-GoogleNews-Bot
X-Exp-Variant
X-Geo-Segment
X-Exp-Id
X-Kinja-Revision
X-Powered-By-Plesk
X-CF-Powered-By
Public-Key-Pins
Pinterest-Version
X-Upstream-Env
X-Pinterest-Rid
PB-PID
PB-RID
X-Mobile-Rewrite
Arc-Version
X-Mod-Pagespeed
Verso
SPRequestGuid
X-Client-IP
X-D2id
X-Abt-Application-Version
Permitted-Cross-Domain-Policies
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Do-Not-Hack
X-HeyJason
X-N
Accept-CH
MS-Author-Via
AR-PoweredBy
AR-ATIME
AR-CACHE
X-Dispatcher
X-SharePointHealthScore
X-Amz-Rid
X-T
X-Navigation-Version
X-TEC-API-ORIGIN
X-TEC-API-ROOT
DynaTrace
X-TEC-API-VERSION
Nginx-Cache
Paypal-Debug-Id
X-Dw-Request-Base-Id
X-Grace
X-Upstream
X-Trace
X-Fastly-Request-ID
X-Varnish-Age
Arr-Disable-Session-Affinity
X-Hits
Accept-CH-Lifetime
TCN
X-FastCGI-Cache
X-Id
X-Shield-Request-Id
X-Amz-Meta-S3cmd-Attrs
X-Forwarded-Proto
X-Origin-Upstream-Status
X-Pad
X-DIS-Request-ID
X-Cache-Hit
SPRequestDuration
SPIisLatency
X-Content-Options
X-Content-Digest
X-Logged-In
X-IPLB-Instance
Access-Control-Request-Method
X-Kinsta-Cache
Realpath
MRF-Tech
X-B
X-Mrf-Section-Lastmod
Mrf-Cache-Status
X-Mrf-Item-Lastmod
X-Acc-Meta-Resource-Type
X-NF-Request-ID
X-Ruxit-JS-Agent
AR-SID
X-XRDS-Location
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Goog-Generation
X-SS-Set-Cookie
X-HW
X-Vcap-Request-Id
S
X-MSEdge-Ref
X-Debug
Service-Worker-Allowed
X-Ser
Server-Name
X-PressLabs-Stats
X-FTR-Realm
X-FTR-Cache-Status
X-Country-Code-Real
X-FTR-Backend
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-DC
X-Frontend
X-Server-ID
X-Webkit-CSP
X-Oneagent-Js-Injection
X-FTR-Expires
Eomportal-Instance
Fastcgi-Cache
Tracecode
Rt-Fastcgi-Cache
X-Wix-Server-Artifact-Id
X-Cache-Key
Alternate-Protocol
Surrogate-Key
X-NewRelic-App-Data
Cleartype
AMP-Access-Control-Allow-Source-Origin
X-GUploader-UploadID
X-Forwarded-For
X-Cache-Rule
X-NWS-LOG-UUID
X-Srv
Cache-Status
X-HS-Content-Id
X-HS-Hub-Id
X-VCache
Backend-Timing
X-Analytics
Host
X-Revision
TP-L2-Cache
TP-Cache
FilterID
X-User-Agent
X-Rid
X-Debug-Info
X-Whom
X-FTR-Cache-Host
X-Via-JSL
Fastly-Restarts
X-AOL-HN
Public-Key-Pins-Report-Only
X-Akam-SW-Version
X-Varnish-Backend
ServerID
X-Cache-2
X-Content-Powered-By
X-Request-Processing-Time
X-RateLimit-Remaining
X-Request-Received
X-Cdn
Viewport
X-Kinja-Server-Push
X-Zen-Fury
Accept-Charset
X-Oracle-Dms-Rid
X-Ttl
X-Accel-Buffering
X-Mobile
X-XRDS-LOCATION
Front-End-Https
X-WPE-Loopback-Upstream-Addr
Liferay-Portal
X-Cached-By
X-Node-Name
X-Hostname
X-App-Environment
X-LB-Cache
X-B3-Traceid
X-Tumblr-Pixel
X-Page-Id
X-Varnish-Hostname
X-Tumblr-User
X-Cache-Control
X-Tumblr-Pixel-0
X-Content-Security-Policy-Report-Only
X-Magnolia-Registration
X-Cluster
Host-Header
X-Akamai-Edgescape
Cache-Tag
X-TT
X-Request-Guid
X-B3-Sampled
X-Framework
X-Handled-By
X-Device-Type
X-B-Cache
Upgrade-Insecure-Requests
X-Platform-Server
X-Signature
X-FB-Debug
X-BCube-Filmed-By
X-Instance
X-Cache-Server
DC
Server-Node
X-Origin-Server
X-TT-TIMESTAMP
Source
Retry-After
MicrosoftSharePointTeamServices
X-WA-Info
X-Servedby
X-Contextid
X-Accel-Expires
Server-Info
HitInfo
HitType
X-TA-CDN-Provider
X-Correlation-Id
X-Cache-Action
X-Daa-Tunnel
X-Amzn-Trace-Id
X-Cache-Operation
X-Varnish-Server
X-Port
X-Sol
X-Distil-CS
X-Middleton-Display
Display
X-APP-VERSION
X-Geo-Country
X-Generated-By
X-Edge-Location
X-Hyper-Cache
AsisCache
Content-Style-Type
X-Amz-Replication-Status
X-GeoIP
Content-Script-Type
Webserver
X-Tumblr-Pixel-2
X-WebKit-CSP-Report-Only
X-RequestSource
X-Tumblr-Pixel-1
X-S
GEO-INFO
Actual-Object-TTL
X-TX-ID
X-Locale
X-Wix-Request-Id
ServedBy
X-Seen-By
X-Region
X-FW-Hash
X-Status
X-FW-Type
X-FW-Server
X-FW-Serve
X-Edge-Cache-Key
X-Varnish-Hits
X-Jobs
X-Edge-Cache
X-FW-Static
X-UUID
Healthy
X-DataStream-Cache-Status
X-Drupal-Cache-Tags
X-Adobe-Loc
X-Varnish-Grace
X-Adobe-Content
X-Response-Served-From
User-Agent
Filters
X-Newrelic-App-Data
NGB
SRV
X-Proxied
S-Cnection
Refresh
X-Amz-Server-Side-Encryption
X-Fastcgi-Cache
X-URL
Response
X-Cache-Age
AR-Request-ID
X-Middleton-Response
X-Cache-TTL-Remaining
IBM-Web2-Location
X-Esi
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-CDN-Forward
X-AppVersion
X-App-Server
X-Az
X-Activity-Id
Cache
X-Pc-Key
X-Pc-Appver
X-Pc-Hit
X-Cache-Remote
X-Correlation-ID
X-Cacheable-TTL
X-Content-Type
X-Ruxit-Js-Agent
Payment
X-Cache-NE
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Unique-ID
X-UA
X-Cache-TTL
Datacenter
X-Akamai-Transformed
Served-By
X-Vg-Webcache
Country
X-Mode
Edge-Cache-Tag
X-HS-Cache-Config
X-Source
X-ATG-Version
Meta-Geo
X-ProcessESI
HostName
Load-Balancing
X-Detected-As
X-RemovedCookies
X-Rendered-As
Machine
X-RN-RSRV
X-Is-Bot
X-OCL
User-Cache-Control
X-Rocket-Nginx-Bypass
X-FC-Vary-Parameters
X-PCL
X-ProxyCache-Status
X-Real-IP
X-BYPASS-REASON
X-Backend-Name
X-Proxy
X-ProxyCache-Key
X-Amz-Meta-Surrogate-Control
Mn-Server-Ip
X-BB-IP
X-Debug-Cache
X-Hosted-By
TWC-Connection-Speed
X-Cache-Config
Webcakes-App-Version
Cache-Name
Property-Id
Cache-Key
X-Viewer-Country
Webcakes-Region
X-ApacheServer
X-EIG-Tracking-Id
TWC-Privacy
TWC-GeoIP-LatLong
X-Human
X-Origin-Hint
TWC-GeoIP-Country
X-Pubstack
X-PERF
X-Varnish-Cacheable
X-Varnish-IP
Backend
X-Origin
X-ServerID
Now
Webcakes-App-Name
TWC-Device-Class
X-Sucuri-ID
Access-Control-Allow-Method
TWC-Locale-Group
L5d-Success-Class
X-Tb
Azure-Version
Azure-SlotName
Azure-SiteName
Access-Control-Request-Headers
X-Zipkin-Id
X-Access
DB-Nickname
Azure-InstanceId
Azure-RegionName
X-Hit
X-Original-Request
X-OVcl
X-Via-Fastly
X-NodeID
X-Loop
X-OVcl-Cache
X-Varnish-Cache-Hits
X-Routing-Service
X-Site-Version
X-TNCMS
X-Upgrade-Enabled
X-Cache-Category-Id
X-L-Path
X-Storage
X-Environment-Context
X-CDN-Cache
S-Rt
X-CCM
X-Format
X-Generated
ServerName
X-JoinUs
X-Section
X-Grey
Selected-FE
X-LJ-Flow-ID
X-SplitTest
X-Proxy-Build
X-TWH-CORRELATION-ID
X-VWS-Id
X-Xfnlog-Site
X-Www-Served-By
X-Ocache
X-NGENIX-Cache
X-Agile-Id
X-Agile-Age
X-App-Name
X-AWS-Id
X-IP
X-Agile
X-Timing-Wait
X-Pc-Date
X-Akamai-Request-ID
X-Origin-CC
X-Drupal-Cache-Contexts
X-Rule
X-Pc-Host
X-HS-Combine-CSS
X-Vgn-Hpd-Reason
X-Cache-Var-Map
X-PHP-Backend
X-Cache-Var
X-Time-Microsecs
XServer
X-Upstream-CT
X-Upstream-HT
X-RateLimit-Limit
X-NC
X-UA-Device-Type
From-Origin
X-NCache
OT-Force-Account-Verify
X-Microcachable
X-Internal-Host
Ar-Sid
X-Release
X-Feature
X-Nginx-Cache
X-Distributor
X-Forwarded-Host
X-Mrs-Cache
X-Mrs-Age
X-Mrs-Cache-Hits
X-Mshield-Cache-Status
X-Qnm-Cache
Fastly-SSL
X-M-Log
Fastcgi-Useragent
X-M-Reqid
Fastcgi-X-Cache-Version
Fastcgi-X-Cache
LB
X-Varnish-Beresp-Status
X-Amzn-RequestId
X-Varnish-Beresp-Grace
X-Amz-Apigw-Id
Pagetype
X-Cache-Backend
X-Ms-Version
X-Ms-Request-Id
X-Ms-Blob-Type
X-Ms-Lease-Status
X-Birta-Served
X-Birta-Cache-Post
X-Twitter-Response-Tags
X-Transaction
X-Connection-Hash
X-Webkit-Csp
NtCoent-Length
X-Instance-Name
X-EdgeConnect-Cache-Status
MIME-Version
X-V
X-Ah-Environment
X-Labrador-Cache-Channel
X-B3-Spanid
Frame-Options
X-VG-TLSProxy
X-GZip
Pagespeed
X-Web-Node
PageSpeed
X-Varnish-Beresp-Ttl
Powered-By-ChinaCache
X-SERVER-NAME
X-C
X-Redis-Cache
X-Gen-Mode
X-Accel-Expires-Debug
X-Generated-In
X-IN-APIGATEWAY
X-A-Ccd
X-From
X-Server-Time
X-Region-Sid
X-A-Dam
X-A-Dcw
X-A-Dgt
X-Generation-Time
X-Request-UUID
X-A-Wwc
X-Server-By
X-A
Www
Ec-Rule-Version
NGX
Rendered-Blocks
Server-Int
Cache-Prefix
Fly-Cache
Fly-Request-Id
X-PAYTM-SRV-ID
Host-ID
IsBot
MD5-Digest
Meta-Geo-Continent
BehaviorPad-Version
Arc-Country
Web-Mar-Node
X-NU-AKA-ACS-Version
Time
X-No-Session
X-ScT
VivaBuild
Viewtype
X-Org
T-Server
V-Age
AKAMAI
Ajk
X-Hnp-Log
X-G
X-CS
X-CUA
X-Application
X-D
X-S-Cookie
X-Via-SSL
X-CF-Lambda-Version
X-VG-WebServer
X-Via-CDN
X-Via-Edge
X-Date
X-SRCache-Key
X-CACHE-GROUP
X-Rojux
X-IN-WAF
X-Irp-Debug
X-Dispatcher-Server
X-Rewrite-Enabled
X-Destination
Xc-Version
X-Developer
X-Died
X-CF-Lambda-Fn
X-IN-SSL-APIGATEWAY
X-UE-Client-Country
X-Cache-Bucket
X-Block-Status
X-BB-ID
X-ARC
X-B-Cookie
X-Logtrace-Id
X-SIPLIST1
X-Trv-Group
Cneonction
Cteonnt-Length
X-Oss-Request-Id
X-App-Version
X-Oss-Server-Time
X-Oss-Storage-Class
X-NWS-UUID-VERIFY
X-Oss-Object-Type
X-FireWall-Port
X-HOST
X-Oss-Hash-Crc64ecma
Origin-Edge-Control
HA-Servedtime
Origin-Cache-Control
X-Amz-Meta-Cache-Control
X-Owner
Pragrma
Kp-EeAlive
X-Origin-TTL
HA-Urlpath
On-Server
Proxy-Connection
MI-Cache-Age
MI-Cache
X-MI-In-Market
X-Key
X-DPWN-IS-SECURE
Magicmarker
NodeID
MI-API
Request-EU
X-Core-Value
X-Eu-Site
X-Layer
X-ElasticPress-Search
X-Cache-CFC
X-Crawler
X-GeoIP-City
X-External-Request-Id
X-Fastly-Cache
X-Node-Id
X-NX-Host
X-CGP
Server-Host
Request-Time
HA-Ipaddr
Request-Country
X-F5-Cache
SN
X-HTML-Minification-Powered-By
X-Debug-Cookies
X-Debug-Log
True-Client-Country-4JS
Release
X-RateLimit-Remaining-Second
X-Platform
X-RateLimit-Limit-Second
X-Varnish-Action
Country-Code
Decoy-Debug-Key
X-Request-URI
Decoy-Debug-TTL
Decoy-Debug-Status
X-RCS-CacheZone
X-Hl-Ver
X-Wikidot-Backend
X-WebServer
X-We-Are-Hiring
Backend-Name
Cache-Tags
CDCHOST
X-Wikidot-Static-Cache
HA-Host
Esi-Enabled
X-ServiceProvider
HA-Geocountry
HA-Cloudapp
X-Sf
X-UnsetCookies
X-S-Maxage
Ha-Gx-Prefs
HA-Georegion
HA-Geolon
HA-Geolat
GMS-Ver
HA-Geocity
X-Var-Ttl
X-Phone
X-Webstats-RespID
X-Powered-By-ANYU
X-Sucuri-Cache
WZWS-RAY
X-Cache-Expires
X-Backend-TTL
X-Location
X-Tumblr-Pixel-3
X-Cdn-Origin
X-Clientip
X-Ckpd-Fst-Backend
X-Cache-URL
X-Cache-Host
X-Cache-Srv
X-Content-Age
X-Cache-Enabled
X-Cdn-Srv
X-Matched-Rule
X-TT-LOGID
X-Backend-Url
X-Variation
X-Thinkindot-L3
X-Shopify-Stage
X-ShopId
X-Fetched-On
X-Skip-Cache
X-Sn-Servicetimems
X-Fstrz
X-FW-Version
X-GeoIP-Country-Code
X-Hash
X-Server-IP
X-Gannett-Site-Version
X-ShardId
X-Sorting-Hat-PodId
X-Epic-Correlation-Id
X-Trace-Id
X-Worker
X-Returned-From-PostProcessResponse
X-Croise-Owner
X-VServer
X-Backend-State
X-Developers
X-Stale
X-Sorting-Hat-ShopId
X-Swa-Ws
Mobile-Detection-Method
X-Device-Os
X-Returned-From-DLL
X-MSEdge-Features
Section-Io-Cache
X-Backend-Host
RNT-Time
RNT-Machine
X-Secret
Apple-News-Services-Request-Url
Thinkindot-CacheControl
Uber-Trace-Id
Apple-News-Services-Parsed-Url
Thinkindot-Control
Thinkindot-CacheControl-Type
Countrycode
Platform
X-Passed-To-DLL
Is-Eu
X-Passed-To-PostProcessResponse
Heartbleed
X-Passed-To-BeforeDispatch
Odigeo-Trace-Id
PFcat
Fastly-Backend-Name
Origin
X-Passed-To
Apple-News-Services-Host
Server-ID
X-Response-By
X-Request-Time
X-Actual-URL
X-MSEdge-Flight
X-Returned-From-BeforeDispatch
X-Alternate-Cache-Key
X-Reboot
X-Returned-From
Adler-Geo
X-Up
X-Nginx-Cache-Key
Apple-News-Services-Handled
X-Atg-Version
X-Planisys-CDN-Cache
X-Core-Mission
X-Alicdn-Da-Ups-Status
Fastly-SIE
X-Csrf-Token
X-Rebelmouse-Cache-Control
X-Servername
Resin-Trace
HTTPS
X-Rebelmouse-Surrogate-Control
Fastly-SWR
X-Planisys-CDN-TTL
Content-Disposition
X-VCT
X-Planisys-CDN-Rules
Sid
CDN
X-CACHE-AGE
X-Ezoic-Cdn
X-Store
X-GEO
X-Servedbyhost
ProcessTime
RequestId
X-Policy
X-Pf-Uncompressing
X-Ua
WP-Super-Cache
X-Cache-ASPX
Dnion-Transfer-Encoding
Warning
X-Proto
NODE
CF-IPCountry
Powered
X-Refresh
REQUESTUUID
X-GoCache-CacheStatus
X-TIME
X-Real-Ip
X-Cluster-Node
Xserver
Mail-Subject
We-Hiring
X-Pjax-Url
X-DC
X-B3-TraceId
X-Dc
X-Req
NnCoection
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-From
X-Origin-Date
X-Origin-Expires
Cache-Cookie-Set-Lfrom
X-Varnish-Ttl
X-Cache-Control-Set-By
X-HCF
ViewerVersion
X-Litespeed-Cache
X-Newrelic-Synthetics
X-Varnish-HitMiss
X-CLOUD-TRACE-CONTEXT
X-Endurance-Cache-Level
Geoip-Latitude
X-Time
GeoIp-Country-Code
X-Edge-IP
X-Page-Type
X-COUNTRY
X-Server-W
X-Surge-Debug
X-Nc
X-Guploader-Uploadid
Hostname
WWW-Authenticate
X-Server-Group
Processtime
X-Oracle-Dms-Ecid
X-CSRF-Token
X-Iejgwucgyu
Geoip-City
X-Aed
SD-X-WS
X-Ms-Lease-State
Pramga
PICS-Label
A
X-Wix-Route-ID
MS-CV
X-Datadome
X-Varnish-Url
X-Varnish-URL
X-Wa
X-GRACE
X-Varnish-Beresp-TTL
Dont-Set-Cookie
X-Aicache-OS
TSSecure
X-Cdn-Forward
X-Edge-Server
Cdn-Host
Cdn-Request-Time
X-From-Cache
X-Akamai-Request-ID2
X-Gdpr
X-WA
Cdn
X-ABtesting
CACHE
X-Flog
X-Hello
Node
X-DataStream-Origin-MEX-Latency
X-DataStream-MidMile-RTT
Lb
Ms-Operation-Id
X-Nananana
X-RTag
DataCenter
Mime-Version
X-Use-Magma
X-Ratelimit-Limit
X-Cache-HT
X-Auto-Login
Get-Access-Time
Is-Session-Tracking
X-Optimization
X-UPSTREAM-Address
Lfy
X-Env
X-Geo
COMMERCE-SERVER-SOFTWARE
X-Load-Cache
X-Fastly-Backend-Reqs
PageType
Who
X-APP
FSS-Cache
FSS-Proxy
GeoIP-Latitude
GeoIP-Country-Code
X-SRV
X-PAGE-TYPE
X-Wix-Petri-Ex
GeoIP-City
X-WR-MODIFICATION
X-Sentry-ID
X-Gen-Id
X-EC-Security-Audit
X-CACHE-KEY
X-Cache-FS-Status
X-Unique-Id
X-Via-NSCOPI
X-Check-Cacheable
X-Meta-Tbi-Cache-Vertical
X-GDPR
Ws
Rt-Proxy-Cache
X-Ibm-Trace
X-Ver
X-Dynatrace-Js-Agent
X-Cookie
Httpd-Identifier
X-NGINX-Cache
X-Served-From
X-Cache-Id
X-FORWARDED-FOR
Ohc-File-Size
X-Bip
X-Path-Route
Powered-By
X-Cache-Info
X-MP-GENERATED-AT
X-PJAX-URL
X-Thanos
Memcached
X-Proxy-Server
Pics-Label
X-Swift-Error
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Dw-Trace-Id
X-RateLimit-Reset
X-Be
Version
X-Cache-Ttl
V-Cache
Group
X-Fastly-Cache-Hits
X-B3-SpanId
X-Fe
URI
Memory
X-CDN-Pop
X-CDN-Pop-IP
Cf-Ipcountry
X-P-T
X-Request-Start
X-ServedByHost
X-Shard
X-LiteSpeed-Cache-Control
X-HS-Status
Apicache-Store
Apicache-Version
X-ID
Amp-Access-Control-Allow-Source-Origin
Xet-Cookie
NX-Cache
Requestid
X-GZIP
X-SB
Fastly-Soc-X-Request-Id
AGE-Hash
Ohc-Response-Time
X-VC
X-PF-Uncompressing
X-Bug-Bounty
Serverid
X-Info
X-Akamai-ERRuleID
UCS
N-Cache
X-Varnish-Info
X-CacheKey
X-StackifyID
GW-Server
CDN-Node
X-Micro-Cache
X-Akamai-ERPolicy
X-Ratelimit-Remaining
CDN-Cache-Hit
If-Modified-Since
CDN-Cache
X-SD-PageType
X-User
X-Route-Name
X-Flags
X-Litespeed-Cache-Control
X-RequestId
X-RAMCache
X-Is-Crawler
X-Providence-Cookie
X-BBXSRF
Https
X-Cache-Handler
X-ServerName
X-Grace-Duration