Threat Level: green Handler on Duty: Rick Wanner

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
Last-Modified
Accept-Ranges
Pragma
X-Content-Type-Options
X-Powered-By
CF-RAY
ETag
Link
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Access-Control-Allow-Origin
Content-Security-Policy
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Served-By
X-Amz-Cf-Id
X-Varnish
Referrer-Policy
X-Timer
X-Xss-Protection
CF-Cache-Status
X-FRAME-OPTIONS
X-Request-Id
Access-Control-Allow-Headers
X-AspNet-Version
Access-Control-Allow-Methods
X-Runtime
X-Download-Options
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Cacheable
Alt-Svc
X-Generator
Content-Security-Policy-Report-Only
X-Request-ID
X-Check
X-AspNetMvc-Version
Status
X-Cache-Status
X-Adblock-Key
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Iinfo
X-Permitted-Cross-Domain-Policies
X-Template
Content-Encoding
X-Language
X-Content-Security-Policy
X-Turbo-Charged-By
X-CDN
X-Type
Keep-Alive
X-Buckets
Xkey
X-AH-Environment
X-Backend
X-Cache-Group
WPE-Backend
Access-Control-Max-Age
X-Pass-Why
X-Age
X-Server
CF-Ray
Upgrade
X-POWERED-BY
EagleId
Access-Control-Expose-Headers
X-Via
X-Nginx-Cache-Status
X-Server-Powered-By
X-Pingback
X-Drupal-Dynamic-Cache
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Grace
X-Hacker
X-Amz-Id-2
X-Amz-Request-Id
X-UA-Device
Ali-Swift-Global-Savetime
X-Robots-Tag
Cf-Railgun
P3p
X-Envoy-Upstream-Service-Time
X-Proxy-Cache
X-LiteSpeed-Cache
X-Page-Speed
X-Ua-Compatible
Request-Context
Content-Location
X-Device
X-Ac
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Node
X-Cnection
X-Host
X-Server-Id
X-Amz-Version-Id
X-Cache-Lookup
Surrogate-Control
X-WebKit-CSP
X-Backend-Server
X-Rack-Cache
X-Rq
X-Response-Time
X-Application-Context
X-Readtime
X-CST
EagleEye-TraceId
Server-Timing
X-Url
Pinterest-Generated-By
X-Cloud-Trace-Context
X-TTL
X-OneAgent-JS-Injection
X-Instart-Request-ID
Request-Id
Report-To
X-Px
X-Country
X-Dns-Prefetch-Control
X-ORACLE-DMS-ECID
X-Clacks-Overhead
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Feature-Policy
Rating
Edge-Control
X-Country-Code
Allow
X-DynaTrace-JS-Agent
X-DataDome
Charset
X-Powered-CMS
X-FTR-Request-ID
X-PC
X-TtlSet
X-Vname
X-ESI
X-Origin-Cache
X-Server-Name
X-DynaTrace
NEL
X-ORACLE-DMS-RID
X-MS-InvokeApp
X-Goog-Hash
X-Recruiting
X-Varnish-TTL
X-Cached
X-Vhost
X-VARITI-CCR
X-GitHub-Request-Id
RTSS
Content-MD5
X-F-Cache
X-Version
X-Kinja-Build
X-Kinja
X-Geo-Segment
X-Kinja-Revision
X-GoogleNews-Bot
X-Exp-Variant
X-Exp-Id
X-Cdn-Fetch
X-Kinja-Server
X-Powered-By-Plesk
Public-Key-Pins
Accept-CH
PB-PID
PB-RID
Arc-Version
X-Mobile-Rewrite
X-Pinterest-Rid
X-Upstream-Env
X-Mod-Pagespeed
Pinterest-Version
X-D2id
Verso
X-Client-IP
MS-Author-Via
SPRequestGuid
X-CF-Powered-By
X-Abt-Application-Version
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-N
X-Dispatcher
X-SharePointHealthScore
X-Amz-Rid
AR-PoweredBy
AR-ATIME
AR-CACHE
X-Navigation-Version
Accept-CH-Lifetime
Nginx-Cache
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-T
X-Trace
DynaTrace
X-Dw-Request-Base-Id
X-Fastly-Request-ID
Paypal-Debug-Id
X-HeyJason
Permitted-Cross-Domain-Policies
X-Do-Not-Hack
X-Grace
X-Upstream
X-Varnish-Age
Arr-Disable-Session-Affinity
TCN
X-Forwarded-Proto
X-FastCGI-Cache
X-DIS-Request-ID
X-Amz-Meta-S3cmd-Attrs
X-Id
X-Hits
X-Origin-Upstream-Status
X-Shield-Request-Id
SPRequestDuration
X-Pad
SPIisLatency
AR-SID
X-Content-Options
X-Ruxit-JS-Agent
X-Content-Digest
X-Cache-Hit
Realpath
X-NF-Request-ID
X-Kinsta-Cache
X-IPLB-Instance
X-Logged-In
Access-Control-Request-Method
Mrf-Cache-Status
X-Mrf-Section-Lastmod
MRF-Tech
X-Acc-Meta-Resource-Type
X-Mrf-Item-Lastmod
X-B
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-SS-Set-Cookie
X-HW
X-Vcap-Request-Id
X-XRDS-Location
S
X-Debug
X-MSEdge-Ref
Service-Worker-Allowed
X-Ser
Server-Name
X-Wix-Server-Artifact-Id
X-FTR-Cache-Status
X-FTR-Balancer
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Backend
X-FTR-DC
X-FTR-Realm
X-PressLabs-Stats
X-Frontend
Tracecode
X-Cache-Key
AMP-Access-Control-Allow-Source-Origin
X-NewRelic-App-Data
X-FTR-Expires
Rt-Fastcgi-Cache
X-Server-ID
Fastcgi-Cache
X-GUploader-UploadID
X-Oneagent-Js-Injection
Eomportal-Instance
Surrogate-Key
Alternate-Protocol
Cleartype
X-Cache-Rule
X-Forwarded-For
Cache-Status
Backend-Timing
X-Analytics
X-HS-Content-Id
Fastly-Restarts
X-HS-Hub-Id
X-Revision
X-VCache
TP-L2-Cache
TP-Cache
Host
X-NWS-LOG-UUID
X-Rid
X-Srv
FilterID
X-User-Agent
X-Whom
Public-Key-Pins-Report-Only
X-FTR-Cache-Host
X-Debug-Info
X-RateLimit-Remaining
X-Akam-SW-Version
X-AOL-HN
ServerID
X-Accel-Buffering
X-Cache-2
X-Varnish-Backend
X-Content-Powered-By
X-Via-JSL
X-Request-Processing-Time
X-Request-Received
Accept-Charset
X-XRDS-LOCATION
Front-End-Https
X-Zen-Fury
X-Mobile
X-Webkit-CSP
X-Cdn
X-TA-CDN-Provider
Viewport
X-Kinja-Server-Push
X-WPE-Loopback-Upstream-Addr
X-Ttl
X-Cached-By
X-Oracle-Dms-Rid
X-Node-Name
Liferay-Portal
X-B3-Traceid
X-LB-Cache
X-Magnolia-Registration
X-App-Environment
Host-Header
X-Cluster
X-Content-Security-Policy-Report-Only
X-Tumblr-Pixel-0
X-Varnish-Hostname
X-Page-Id
X-Tumblr-Pixel
X-Tumblr-User
X-B3-Sampled
X-TT
X-Cache-Control
X-Framework
X-Request-Guid
X-Handled-By
Upgrade-Insecure-Requests
X-Platform-Server
X-Instance
X-Akamai-Edgescape
X-B-Cache
X-Signature
X-Device-Type
X-FB-Debug
X-BCube-Filmed-By
X-Hostname
DC
Cache-Tag
X-Cache-Server
X-Correlation-Id
Server-Node
X-Origin-Server
X-TT-TIMESTAMP
MicrosoftSharePointTeamServices
Source
Retry-After
X-Accel-Expires
X-Amzn-Trace-Id
X-WA-Info
X-Servedby
X-Contextid
Display
X-Sol
X-APP-VERSION
X-Middleton-Display
HitInfo
HitType
Server-Info
X-Cache-Action
X-Varnish-Server
X-Distil-CS
X-Cache-Operation
X-Port
X-Esi
Content-Script-Type
Content-Style-Type
X-Edge-Location
X-Amz-Replication-Status
X-Seen-By
X-Wix-Request-Id
Webserver
AsisCache
X-Generated-By
X-S
X-Daa-Tunnel
X-GeoIP
X-Geo-Country
X-WebKit-CSP-Report-Only
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
X-Status
Actual-Object-TTL
X-Locale
GEO-INFO
X-TX-ID
Healthy
X-FW-Type
X-FW-Server
ServedBy
X-Varnish-Hits
X-FW-Hash
X-FW-Serve
X-Hyper-Cache
X-FW-Static
X-UUID
X-Region
X-RequestSource
X-Response-Served-From
User-Agent
X-Adobe-Loc
X-Adobe-Content
X-Drupal-Cache-Tags
X-Edge-Cache
X-Edge-Cache-Key
X-Jobs
X-DataStream-Cache-Status
SRV
X-Newrelic-App-Data
Refresh
X-Varnish-Grace
X-Litespeed-Cache
X-Yottaa-Metrics
Filters
X-Yottaa-Optimizations
Response
IBM-Web2-Location
X-Middleton-Response
X-Amz-Server-Side-Encryption
X-Cache-TTL-Remaining
S-Cnection
NGB
X-Fastcgi-Cache
X-Cache-Age
X-CDN-Forward
X-ATG-Version
X-Cache-NE
X-Proxied
X-Az
X-AppVersion
X-Activity-Id
X-Content-Type
Payment
X-Pc-Key
X-Pc-Appver
X-Pc-Hit
X-App-Server
X-Cache-Remote
AR-Request-ID
X-Cacheable-TTL
Datacenter
X-Ruxit-Js-Agent
X-Unique-ID
X-Cache-TTL
X-Vg-Webcache
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Country
X-UA
Cache
X-Akamai-Transformed
Edge-Cache-Tag
X-HS-Cache-Config
X-Mode
X-Correlation-ID
Served-By
X-Sucuri-ID
X-RemovedCookies
X-Varnish-IP
X-RN-RSRV
X-Rendered-As
X-ProcessESI
Machine
X-Detected-As
Load-Balancing
Meta-Geo
X-Is-Bot
X-Rocket-Nginx-Bypass
X-FC-Vary-Parameters
X-Proxy
Backend
X-ProxyCache-Key
X-ProxyCache-Status
DB-Nickname
Access-Control-Allow-Method
X-OCL
X-BYPASS-REASON
X-Hosted-By
X-Human
X-Grey
X-Origin
X-PCL
X-Varnish-Cacheable
X-Cache-Category-Id
X-Amz-Meta-Surrogate-Control
X-ServerID
X-Tb
X-BB-IP
User-Cache-Control
Cache-Name
X-Iejgwucgyu
X-JoinUs
Azure-Version
Azure-SlotName
Cache-Key
X-Generated
X-Format
L5d-Success-Class
Azure-SiteName
X-Hit
Azure-InstanceId
X-OVcl
X-OVcl-Cache
X-PERF
X-Original-Request
X-Origin-Hint
X-Environment-Context
X-L-Path
X-Loop
Azure-RegionName
X-EIG-Tracking-Id
TWC-Privacy
TWC-Locale-Group
TWC-GeoIP-LatLong
Webcakes-App-Name
Webcakes-App-Version
X-ApacheServer
X-Access
Webcakes-Region
TWC-GeoIP-Country
TWC-Device-Class
X-CDN-Cache
Now
Mn-Server-Ip
X-Cache-Config
Property-Id
TWC-Connection-Speed
ServerName
S-Rt
X-Pubstack
X-NodeID
X-Cache-Var-Map
X-Cache-Var
X-Viewer-Country
X-Zipkin-Id
X-TNCMS
X-Rule
X-Routing-Service
X-Varnish-Cache-Hits
X-Section
X-Site-Version
X-Upgrade-Enabled
X-VWS-Id
X-Agile
X-Via-Fastly
X-CCM
X-Agile-Age
X-Backend-Name
X-Agile-Id
X-IP
X-Debug-Cache
X-HS-Combine-CSS
X-Www-Served-By
X-AWS-Id
X-LJ-Flow-ID
X-NGENIX-Cache
X-Ocache
X-SplitTest
X-TWH-CORRELATION-ID
X-App-Name
X-Proxy-Build
X-Origin-CC
X-Real-IP
X-Source
X-Timing-Wait
Selected-FE
X-Drupal-Cache-Contexts
Access-Control-Request-Headers
X-Xfnlog-Site
X-Akamai-Request-ID
X-URL
X-Storage
HostName
OT-Force-Account-Verify
X-Upstream-CT
X-Upstream-HT
X-Pc-Date
X-Pc-Host
X-Nginx-Cache
X-NC
X-Vgn-Hpd-Reason
X-Mshield-Cache-Status
X-Mrs-Age
X-Mrs-Cache
X-Mrs-Cache-Hits
Powered-By-ChinaCache
X-RateLimit-Limit
From-Origin
Fastcgi-Useragent
Fastcgi-X-Cache
Fastcgi-X-Cache-Version
X-Time-Microsecs
X-Amz-Apigw-Id
Pagespeed
X-NCache
X-Forwarded-Host
X-Amzn-RequestId
X-Internal-Host
XServer
X-SERVER-NAME
Fastly-SSL
X-Microcachable
X-M-Log
X-Qnm-Cache
X-Release
X-Feature
X-M-Reqid
X-Distributor
X-UA-Device-Type
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
LB
X-PHP-Backend
X-Birta-Cache-Post
X-Birta-Served
X-Ms-Blob-Type
X-Ms-Lease-Status
X-Ms-Version
X-Labrador-Cache-Channel
Pagetype
X-Ms-Request-Id
NtCoent-Length
X-Cache-Backend
X-VG-TLSProxy
X-Connection-Hash
X-Transaction
MIME-Version
X-EdgeConnect-Cache-Status
X-Twitter-Response-Tags
X-Webkit-Csp
X-B3-Spanid
Time
Frame-Options
X-GZip
X-V
X-C
X-Instance-Name
X-Web-Node
Ajk
AKAMAI
X-Generated-In
X-From
X-G
X-IN-WAF
X-Logtrace-Id
X-No-Session
Cneonction
Arc-Country
X-IN-SSL-APIGATEWAY
X-Sucuri-Cache
X-IN-APIGATEWAY
X-Generation-Time
X-Developer
X-A-Wwc
X-A-Dgt
X-A-Dcw
X-Accel-Expires-Debug
X-Application
X-B-Cookie
Rendered-Blocks
X-ARC
X-A-Dam
X-A-Ccd
VivaBuild
Viewtype
V-Age
T-Server
Www
X-A
Server-Int
X-BB-ID
X-Cache-Bucket
X-Date
X-D
Fly-Cache
Ec-Rule-Version
X-Destination
Cache-Prefix
X-DPWN-IS-SECURE
X-Died
Fly-Request-Id
Host-ID
Meta-Geo-Continent
Mobile-Detection-Method
NGX
MD5-Digest
IsBot
X-CF-Lambda-Version
X-CF-Lambda-Fn
BehaviorPad-Version
X-Irp-Debug
X-SRCache-Key
X-Org
X-Via-SSL
X-SIPLIST1
X-Server-Time
X-Via-Edge
X-Via-CDN
X-Trv-Group
X-Request-UUID
X-UE-Client-Country
X-VG-WebServer
X-Redis-Cache
X-PAYTM-SRV-ID
X-S-Cookie
X-NU-AKA-ACS-Version
X-Rewrite-Enabled
X-Rojux
X-Server-By
Xc-Version
X-Region-Sid
X-ScT
WZWS-RAY
X-FireWall-Port
X-Powered-By-ANYU
HA-Cloudapp
HA-Georegion
HA-Geolon
HA-Geocity
HA-Geolat
HA-Geocountry
X-Phone
X-Debug-Log
Country-Code
X-Dispatcher-Server
X-CUA
Ha-Gx-Prefs
X-Core-Value
X-CS
X-Platform
GMS-Ver
X-RateLimit-Remaining-Second
Release
Pragrma
Origin-Edge-Control
X-Amz-Meta-Cache-Control
X-S-Maxage
X-Request-URI
Web-Mar-Node
SN
Origin-Cache-Control
X-Block-Status
HA-Urlpath
HA-Servedtime
HA-Ipaddr
X-CGP
Magicmarker
X-Cache-CFC
NodeID
X-RateLimit-Limit-Second
HA-Host
X-Debug-Cookies
X-Gen-Mode
X-Origin-TTL
X-Varnish-Action
X-Owner
X-NX-Host
X-We-Are-Hiring
X-GeoIP-City
X-Layer
X-Key
X-VServer
X-Hnp-Log
X-Hl-Ver
X-Fastly-Cache
X-WebServer
X-External-Request-Id
X-Node-Id
X-F5-Cache
X-Eu-Site
Backend-Name
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-HOST
X-Varnish-Beresp-Ttl
X-NWS-UUID-VERIFY
X-Request-Time
X-App-Version
X-Location
X-Matched-Rule
X-Backend-Url
X-Backend-TTL
X-MSEdge-Features
X-Returned-From-BeforeDispatch
X-MI-In-Market
X-Store
X-Sn-Servicetimems
X-Backend-State
X-Returned-From-PostProcessResponse
X-Backend-Host
X-Secret
X-ServiceProvider
X-VCT
X-MSEdge-Flight
X-Actual-URL
X-Sf
X-Returned-From-DLL
X-Reboot
X-Server-IP
X-Nginx-Cache-Key
X-Cache-URL
X-Croise-Owner
X-Fetched-On
X-Passed-To
X-Crawler
X-Tumblr-Pixel-3
X-Gannett-Site-Version
X-FW-Version
X-Thinkindot-L3
X-Passed-To-BeforeDispatch
X-Developers
X-Passed-To-DLL
X-Epic-Correlation-Id
X-Passed-To-PostProcessResponse
X-Trace-Id
X-TT-LOGID
X-Returned-From
X-UnsetCookies
X-Up
Uber-Trace-Id
X-ElasticPress-Search
X-Cdn-Origin
X-Variation
X-Cache-Srv
X-Cache-Enabled
X-Cache-Host
X-HTML-Minification-Powered-By
X-Cdn-Srv
X-Clientip
X-GeoIP-Country-Code
X-Swa-Ws
X-Var-Ttl
X-Response-By
X-Stale
X-RCS-CacheZone
Request-Country
MI-API
MI-Cache
Kp-EeAlive
Is-Eu
Heartbleed
MI-Cache-Age
Odigeo-Trace-Id
Platform
PFcat
Origin
On-Server
Esi-Enabled
Decoy-Debug-TTL
Apple-News-Services-Host
Apple-News-Services-Handled
Adler-Geo
True-Client-Country-4JS
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Decoy-Debug-Status
Decoy-Debug-Key
Countrycode
CDCHOST
Proxy-Connection
Cache-Tags
Thinkindot-CacheControl-Type
Section-Io-Cache
Thinkindot-Control
Request-Time
Request-EU
Server-Host
Thinkindot-CacheControl
X-Sorting-Hat-PodId
X-ShardId
X-CACHE-AGE
X-Webstats-RespID
X-Alternate-Cache-Key
X-ShopId
X-Shopify-Stage
X-Sorting-Hat-ShopId
X-Hash
X-Ezoic-Cdn
X-Fstrz
X-Skip-Cache
Content-Disposition
Server-ID
Sid
X-Cache-Expires
PageSpeed
X-Rebelmouse-Surrogate-Control
X-Core-Mission
X-Rebelmouse-Cache-Control
X-Worker
X-Alicdn-Da-Ups-Status
Resin-Trace
Fastly-Backend-Name
X-Servername
Fastly-SWR
RNT-Machine
RNT-Time
HTTPS
X-Content-Age
Fastly-SIE
X-Ckpd-Fst-Backend
X-Cluster-Node
X-Ua
Powered
REQUESTUUID
X-Policy
ViewerVersion
X-Csrf-Token
X-Device-Os
Cteonnt-Length
X-Oss-Server-Time
X-Oss-Storage-Class
WP-Super-Cache
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Oss-Request-Id
RequestId
X-Refresh
ProcessTime
X-Real-Ip
X-Pf-Uncompressing
CDN
Warning
Ar-Sid
X-Servedbyhost
X-Planisys-CDN-TTL
CF-IPCountry
X-Planisys-CDN-Rules
X-Proto
X-Planisys-CDN-Cache
X-TIME
Xserver
X-Dc
X-Newrelic-Synthetics
Cache-Cookie-Set-From
Mail-Subject
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
We-Hiring
X-GEO
X-Endurance-Cache-Level
X-Cache-ASPX
X-Req
CACHE
Dnion-Transfer-Encoding
X-Surge-Debug
X-B3-TraceId
X-Atg-Version
Hostname
X-Pjax-Url
X-GoCache-CacheStatus
X-DC
NODE
X-Varnish-Ttl
X-Aed
X-Edge-IP
X-CLOUD-TRACE-CONTEXT
NnCoection
X-CSRF-Token
GeoIp-Country-Code
Pramga
Geoip-Latitude
X-COUNTRY
X-Origin-Date
X-Origin-Expires
X-Page-Type
X-Time
X-Varnish-Beresp-TTL
X-Nc
X-Guploader-Uploadid
TSSecure
X-Server-W
X-HCF
X-Cache-Control-Set-By
X-Varnish-HitMiss
X-Ms-Lease-State
X-Amz-Cf-Pop
X-Oracle-Dms-Ecid
X-Aicache-OS
SD-X-WS
X-Geo
X-Ratelimit-Limit
MS-CV
X-Server-Group
X-DataStream-MidMile-RTT
X-ABtesting
A
X-DataStream-Origin-MEX-Latency
X-Varnish-Url
X-Flog
WWW-Authenticate
X-Hello
Processtime
X-GRACE
X-Datadome
Geoip-City
X-WA
X-Cdn-Forward
PICS-Label
Lfy
X-Wix-Route-ID
X-Auto-Login
X-Varnish-URL
X-Wa
FSS-Cache
FSS-Proxy
X-SRV
X-UPSTREAM-Address
X-Akamai-Request-ID2
Cdn
Node
X-From-Cache
Cdn-Host
Lb
X-Edge-Server
X-APP
X-Gdpr
Dont-Set-Cookie
Cdn-Request-Time
X-Use-Magma
Mime-Version
Rt-Proxy-Cache
X-PAGE-TYPE
X-Via-NSCOPI
X-EC-Security-Audit
X-Sentry-ID
Ms-Operation-Id
X-RTag
X-Nananana
X-FORWARDED-FOR
COMMERCE-SERVER-SOFTWARE
PageType
X-Cache-Id
GeoIP-Latitude
X-Gen-Id
GeoIP-City
GeoIP-Country-Code
X-WR-MODIFICATION
DataCenter
X-Env
X-Optimization
X-Served-From
X-Unique-Id
X-Check-Cacheable
X-Thanos
X-Bip
X-Cookie
Memcached
X-Cache-HT
Is-Session-Tracking
X-Fastly-Backend-Reqs
X-CACHE-KEY
Get-Access-Time
X-Cache-Info
X-Load-Cache
X-GDPR
X-Proxy-Server
Who
X-Dynatrace-Js-Agent
X-Fastly-Cache-Hits
X-Cache-FS-Status
X-Request-Start
Memory
X-Be
X-PJAX-URL
X-MP-GENERATED-AT
X-Ibm-Trace
Ws
X-HS-Status
X-Meta-Tbi-Cache-Vertical
X-Swift-Error
X-Wix-Petri-Ex
Pics-Label
X-Ver
X-Cache-Ttl
GW-Server
UCS
X-Fe
V-Cache
Group
Httpd-Identifier
X-RateLimit-Reset
X-B3-SpanId
X-HITS
X-User
X-CDN-Pop
X-CDN-Pop-IP
Powered-By
Cf-Ipcountry
X-NGINX-Cache
X-Dw-Trace-Id
URI
X-SVT-ORM-RULES
X-ServedByHost
X-SVT-ORM-VERSION
X-Shard
Amp-Access-Control-Allow-Source-Origin
X-ID
Ohc-File-Size
X-VC
AGE-Hash
Cache-Hits
X-SB
Version
X-Path-Route
Requestid
NX-Cache
Xet-Cookie
X-PF-Uncompressing
X-Bug-Bounty
X-GZIP
Serverid
X-Ratelimit-Remaining
CDN-Node
X-P-T
CDN-Cache
X-StackifyID
CDN-Cache-Hit
X-Varnish-Info
X-Goog-Meta-Goog-Reserved-File-Mtime
X-LiteSpeed-Cache-Control
N-Cache
X-CacheKey
X-LI-Proto
X-LI-UUID
X-SD-PageType
X-Li-Fabric
X-Cache-Debug
Apicache-Version
X-Li-Pop
X-Route-Name
Ohc-Response-Time
X-Akamai-ERPolicy
X-RequestId
X-Grace-Duration
Https
X-Akamai-ERRuleID
X-Litespeed-Cache-Control
Fastly-Soc-X-Request-Id
X-Providence-Cookie
X-Is-Crawler
Apicache-Store
X-ServerName
X-Cache-Handler
X-Flags