Threat Level: green Handler on Duty: Rob VandenBrink

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-Powered-By
Pragma
CF-Cache-Status
Link
ETag
Expect-CT
Via
Age
X-Cache
X-XSS-Protection
CF-RAY
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-Xss-Protection
CF-Ray
P3P
X-Cache-Hits
X-Amz-Cf-Pop
Referrer-Policy
X-Amz-Cf-Id
X-UA-Compatible
X-Served-By
Alt-Svc
X-Request-Id
X-Varnish
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-FRAME-OPTIONS
X-Drupal-Cache
X-Check
X-Adblock-Key
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-Cacheable
X-Permitted-Cross-Domain-Policies
X-Cache-Status
X-Generator
Timing-Allow-Origin
X-Iinfo
X-Template
X-AspNetMvc-Version
X-Language
Status
Upgrade
X-Ua-Compatible
X-CDN
X-Content-Security-Policy
X-Buckets
Content-Encoding
Access-Control-Expose-Headers
P3p
Access-Control-Max-Age
X-Kinja-Server-Push
X-Via
Keep-Alive
X-Turbo-Charged-By
X-Request-ID
X-AH-Environment
X-Drupal-Dynamic-Cache
X-Envoy-Upstream-Service-Time
X-Cache-Group
X-Server
X-Pass-Why
X-Ws-Request-Id
X-Backend
X-Age
EagleId
X-Proxy-Cache
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
Xkey
X-Page-Speed
X-Hacker
X-Pingback
X-Server-Powered-By
Server-Timing
Feature-Policy
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
Request-Context
X-Nginx-Cache-Status
Grace
X-Varnish-Cache
X-UA-Device
X-Amz-Version-Id
Cf-Railgun
Report-To
X-OneAgent-JS-Injection
X-LiteSpeed-Cache
X-Rq
X-Device
X-Server-Id
X-Origin-Cache
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
EagleEye-TraceId
X-Backend-Server
X-Host
X-Node
X-Vhost
X-Response-Time
X-Dispatcher
X-Cache-Lookup
X-Ac
X-WebKit-CSP
NEL
X-Readtime
Surrogate-Control
X-Origin-Upstream-Status
Content-Location
Request-Id
X-Ruxit-JS-Agent
X-Application-Context
Fusion-Component-Id
Fusion-Source
Fusion-Content-Source
Fusion-Template-Id
Fusion-Content-Id
X-HW
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Cnection
X-Country
X-Mod-Pagespeed
X-DataDome
X-Cloud-Trace-Context
X-Akam-SW-Version
X-Url
Edge-Control
X-Rack-Cache
Rating
X-Clacks-Overhead
RTSS
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-FTR-Request-ID
X-Goog-Hash
X-TtlSet
X-PC
X-Vname
X-DynaTrace
X-Country-Code
X-Instart-Request-ID
Allow
X-Varnish-TTL
X-ASPNET-VERSION
Service-Worker-Allowed
Content-MD5
Verso
X-GitHub-Request-Id
X-Server-Name
X-D2id
Pinterest-Generated-By
X-ESI
X-Exp-Variant
X-Kinja-Build
X-Kinja-Revision
X-Exp-Id
X-Cdn-Fetch
X-Kinja
X-Kinja-Server
X-Use-Magma
X-GoogleNews-Bot
X-MS-InvokeApp
SPRequestGuid
X-Cached
X-Navigation-Version
X-Powered-By-Plesk
X-Vcache
X-B3-TraceId
X-Forwarded-Proto
X-Amz-Server-Side-Encryption
X-Abt-Application-Version
X-Debug
X-Amz-Rid
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
Public-Key-Pins
X-Fastly-Request-ID
X-Trace
X-SharePointHealthScore
X-MSEdge-Ref
Nginx-Cache
Fusion-Deployment-Id
X-Vcap-Request-Id
X-Webkit-Csp
TCN
X-VARITI-CCR
X-Ttl
Accept-Ch
MS-Author-Via
X-Server-ID
Arr-Disable-Session-Affinity
Charset
X-Px
X-Fastcgi-Cache
X-NF-Request-ID
X-Accel-Expires
X-Cache-TTL
SPIisLatency
SPRequestDuration
Edge-Cache-Tag
Realpath
Pagespeed
Response
Display
Accept-CH
X-Middleton-Response
X-Middleton-Display
X-Content-Type
X-Ser
X-Sol
X-Client-IP
Accept-Ch-Lifetime
X-Version
X-SRCache-Fetch-Status
Cache-Tag
X-SRCache-Store-Status
X-DynaTrace-JS-Agent
NR-ENABLED
Front-End-Https
X-Powered-CMS
X-Pinterest-Rid
Pinterest-Version
X-Id
Access-Control-Request-Method
Accept-CH-Lifetime
X-Grace
X-Hp-Webp
X-Jurisdiction
AR-Request-ID
AR-ATIME
AR-PoweredBy
X-Upstream
S
X-Forwarded-For
X-Dns-Prefetch-Control
Mrf-Cache-Status
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
X-T
X-B3-TraceId-Primal
MRF-Tech
X-Hits
X-Amz-Meta-S3cmd-Attrs
X-Content-Digest
X-Element-Page-Cache
DynaTrace
X-Dw-Request-Base-Id
AR-CACHE
Ar-Sid
Fastcgi-Cache
ServerID
X-Node-Name
X-Mobile-URL
X-Shield-Request-Id
X-Cache-Hit
PB-PID
PB-RID
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-FTR-Backend
X-Country-Code-Real
X-FTR-Backend-Server
X-Recruiting
X-GUploader-UploadID
X-FTR-Balancer
X-FTR-Realm
X-Goog-Storage-Class
X-FTR-DC
X-Goog-Generation
X-FTR-Cache-Status
X-Goog-Metageneration
Server-Node
Powered
Arc-Version
X-Aspnet-Version
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
X-Frontend
X-Mobile-Rewrite
X-Amzn-Trace-Id
TP-L2-Cache
TP-Cache
WPE-Backend
X-FTR-Expires
AMP-Access-Control-Allow-Source-Origin
X-DIS-Request-ID
Upgrade-Insecure-Requests
X-Shard
X-Ezoic-Cdn
X-Request-Received
X-Request-Processing-Time
X-NWS-LOG-UUID
Refresh
Alternate-Protocol
Fastly-Restarts
X-TTL
X-HS-Combine-CSS
X-Logged-In
X-Correlation-Id
X-Varnish-Age
X-XRDS-LOCATION
X-Request-Handler-Origin-Region
X-Microsite
Server-Name
X-FTR-Cache-Host
X-B
X-F-Cache
X-LB-Cache
X-Page-Id
X-Akamai-Edgescape
Backend-Timing
X-ATS-Timestamp
X-Rid
X-User-Agent
MicrosoftSharePointTeamServices
X-Geo-Country
X-Content-Security-Policy-Report-Only
X-XRDS-Location
X-N
X-Via-JSL
Host-Header
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Host
X-Zen-Fury
Cache-Status
X-ORACLE-APMCS-TAG
X-ORACLE-APMCS-REQUEST-ID
X-Origin-Server
X-Varnish-Grace
X-Content-Options
X-Kinsta-Cache
X-B3-Sampled
X-Revision
X-ATG-Version
X-AOL-HN
X-TT
Healthy
X-App-Environment
X-B-Cache
Paypal-Debug-Id
Actual-Object-TTL
X-Amz-Replication-Status
X-Signature
X-Jobs
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Type
X-Tumblr-User
X-Instance
X-Request-Guid
X-Cache-Action
X-FB-Debug
Section-Io-Cache
Access-Control-Allow-Method
X-Varnish-Backend
X-Git-Hash
X-Amz-Apigw-Id
Fastcgi-Useragent
X-Debug-Info
Frame-Options
X-Whom
X-WebKit-CSP-Report-Only
Liferay-Portal
X-Content-Powered-By
X-Hostname
X-Cluster
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Seen-By
X-Daa-Tunnel
X-Cache-Rule
X-Cache-Operation
X-Erf-Bev-Bev-Is-Generated
X-Cache-Age
X-Srv
X-Erf-Bev-Bev
X-Cache-Key
X-Az
X-PHP-Backend
X-Activity-Id
X-AppVersion
X-FireWall-Port
X-Framework
X-Endurance-Cache-Level
X-Cached-By
Trailer
Tracecode
X-Contextid
X-Amzn-Requestid
X-WA-Info
X-Mobile
Source
Retry-After
X-Host-Name
Xserver
X-IPLB-Instance
NGB
X-Response-Served-From
X-Accel-Buffering
Srv
X-RemovedCookies
Accept-Charset
X-Presslabs-Stats
X-ProcessESI
X-Upgrade-Enabled
Surrogate-Key
X-GeoIP
X-FW-Type
X-Adobe-Loc
X-Adobe-Content
X-Tumblr-Pixel-2
X-Cache-NE
X-RequestSource
X-Tumblr-Pixel-1
X-Is-Bot
X-L-Path
X-UUID
X-FW-Server
X-FW-Serve
X-FW-Static
X-Environment-Context
X-FW-Hash
Eomportal-Instance
X-Rendered-As
X-Region
Payment
DC
X-Cacheable-TTL
X-Handled-By
X-Varnish-Server
X-Varnish-Hostname
X-Origin-Response-Time
Filters
X-FastCGI-Cache
X-UA-Device-Type
From-Origin
X-RateLimit-Remaining
X-CST
X-Cache-TTL-Remaining
X-Proxy
X-Time-Microsecs
X-EdgeConnect-Cache-Status
X-Wix-Request-Id
VIX-Pulpo-Upstream-Status
X-Backend-Name
VIX-Pulpo-Node
Nel
Server-Info
X-Cache-2
X-Cache-Server
Cache-Tv-Group
MS-CV
X-APP-VERSION
X-NGENIX-Cache
Datacenter
X-Oss-Server-Time
X-Oss-Storage-Class
Version
Filterid
X-Akamai-Transformed
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Cache-Enabled
X-Status
X-TIME
X-Unique-Id
S-Cnection
X-Mode
X-Cache-Time
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Cache-Control
X-Cache-Var-Map
X-Cache-Var
X-Dc
X-Path-Route
Meta-Geo
X-ES-SERVER
X-CCM
X-RN-RSRV
X-Hl-Ver
X-PERF
GEO-INFO
Cleartype
Country
X-R9-Blue-Green-Version
Cache-Tags
X-IPS-LoggedIn
X-Forwarded-Host
X-ApacheServer
ServedBy
X-Via-Fastly
Akamai-GRN
X-Cache-Status-Check
NGX
X-Debug-Cache
X-Device-Type
X-LJ-Flow-ID
X-Origin
Webcakes-App-Version
Origin-Cache-Control
X-Origin-Hint
X-AWS-Id
TWC-Privacy
TWC-GeoIP-LatLong
X-Akamai-Request-ID2
TWC-Connection-Speed
X-Alternate-Cache-Key
TWC-GeoIP-Country
OT-Force-Account-Verify
X-Proto
Property-Id
Webcakes-App-Name
Origin-Edge-Control
X-FC-Vary-Parameters
Decoy-Debug-Key
X-Shopify-Stage
X-TX-ID
X-Vgn-Hpd-Reason
Decoy-Debug-Status
TWC-Locale-Group
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Sorting-Hat-ShopId
TWC-Device-Class
X-Sorting-Hat-PodId
Decoy-Debug-TTL
X-VWS-Id
X-Redis-Cache
Webcakes-Region
X-Pubstack
X-Tb
X-FW-Dynamic
X-ServerID
DB-Nickname
X-Shopify-Generated-Cart-Token
X-ShopId
X-ShardId
X-EIG-Tracking-Id
Now
X-Pad
X-Proxied
X-NCache
X-Loop
X-Proxy-Build
X-Proxy-Cache-Status
X-Say-Cacheable
X-SaId
X-Routing-Service
X-Locale
X-JoinUs
X-Content-Age
X-Cache-Config
X-Amzn-Remapped-Content-Length
X-Detected-As
X-Format
X-Say-TTL
X-IP
X-Hosted-By
X-Access
X-SayCDN-TTL
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Io-Id
X-BYPASS-REASON
X-Human
X-RCS-CacheZone
X-ProxyCache-Status
X-ProxyCache-Key
Cache-Key
X-Zipkin-Id
X-Soup
X-Site-Version
X-Section
X-Timing-Wait
X-TNCMS
X-Xfnlog-Site
X-Www-Served-By
X-Web-Node
Selected-Fe
X-Generated
Azure-RegionName
Azure-SiteName
Azure-SlotName
Azure-Version
Mn-Server-Ip
Azure-InstanceId
Content-Disposition
Cross-Origin-Window-Policy
Ec-Rule-Version
Access-Control-Request-Headers
X-Viewer-Country
X-NYM-Debug-Backend
X-Ua-Device
X-FB-TRIP-ID
X-MP-GENERATED-AT
X-Varnish-Hits
S-Rt
Webserver
X-EC-Lua
X-Geo
X-Real-IP
X-Akamai-Request-ID
X-Cache-Remote
X-Request-Time
X-BCube-Filmed-By
X-Generated-By
X-Esi
X-NewRelic-App-Data
X-HTML-Minification-Powered-By
Cache-Hits
X-PressLabs-Stats
Node
X-Adobe-Source
X-CACHE-KEY
X-Cdn
X-Amzn-RequestId
X-Edge-O15-RID
Odigeo-Trace-Id
X-No-Session
X-B3-Traceid
FilterID
X-Microcachable
Accept-Language
X-Drupal-Cache-Tags
X-SS-Set-Cookie
X-Rule
X-Uri
Cf-Ipcountry
X-App-Server
Ms-Operation-Id
X-NWS-UUID-VERIFY
X-Azure-Ref
X-From
X-RTag
Time
X-Cache-NGX
X-PCL
X-Source
X-Qloud-Router
X-OCL
X-CF-Powered-By
X-Varnish-Cache-Hits
User-Agent
Proxy-Connection
X-Hyper-Cache
X-RateLimit-Limit
X-Labrador-Cache-Channel
X-PHP-Host
X-Info
X-UA
X-Old-Content-Length
X-Nginx-Cache
X-Backend-TTL
X-Time
X-Nc
X-Storage
X-GoCache-CacheStatus
Cache-Name
X-Newrelic-Synthetics
X-Cache-Grace
Uber-Trace-Id
X-Transaction
Apple-News-Services-Request-Url
Arc-Country
Apple-News-Services-Handled
Xc-Version
X-Vdms-Version
X-VG-WebCache
X-VG-WebServer
X-Vtex-Remote-Cache
X-SRCache-Key
A
X-Twitter-Response-Tags
Apple-News-Services-Host
X-Drupal-Cache-Contexts
X-Vtex-Processado-Em
X-CS
X-Trv-Group
Apple-News-Services-Parsed-Url
Request-Country
X-CF-Lambda-Fn
X-Cdn-Srv
X-Request-URI
X-CF-Lambda-Version
X-Connection-Hash
X-B-Cookie
X-ARC
X-Rewrite-Enabled
X-Aed
X-Application
X-Request-UUID
X-D
X-Date
X-OVcl-Cache
X-OVcl
X-PAYTM-SRV-ID
X-Processor
X-Region-Sid
X-GeoIP-Country-Code
X-G
X-Destination
X-Developer
X-DPWN-IS-SECURE
X-External-Request-Id
X-A-Wwc
X-A-Dgt
X-Session-Fingerprint
Mobile-Detection-Method
X-ScT
Rendered-Blocks
Request-EU
Meta-Geo-Continent
MD5-Digest
BehaviorPad-Version
Fastcgi-X-Cache-Version
GEO-REGION-INFO
Machine
ServerName
T-Server
X-A-Ccd
X-A-Dam
X-Rojux
X-A-Dcw
X-A
VivaBuild
X-S-Cookie
True-Client-Country-4JS
Viewtype
X-S
AsisCache
X-Accel-Expires-Debug
X-Varnish-Beresp-Status
X-Cluster-Node
X-Varnish-Beresp-Grace
X-Cluster-Name
X-ServiceProvider
X-Served-From
X-Magnolia-Registration
X-Rocket-Nginx-Bypass
Thinkindot-CacheControl
X-Sn-Servicetimems
X-Thinkindot-L3
Thinkindot-Control
Server-Host
Thinkindot-CacheControl-Type
X-Core-Value
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-GeoIP-City
X-Geo-Header
X-Generated-On
X-Level-Front-Cache
PFcat
X-Cdn-Origin
Content-Script-Type
Content-Style-Type
X-Matched-Rule
X-Reboot
X-UnsetCookies
X-Trafficlayer-App-Version
Viewport
X-Cache-Expired-At
X-Edge-Location
X-Trafficlayer-App-Scope
X-VG-TLSProxy
X-Trafficlayer-App-Name
Geo-Info
X-Varnish-Ttl
X-S-Maxage
Rt-Fastcgi-Cache
User-Cache-Control
X-Distributor
X-Dispatch
X-Backend-State
X-Distil-CS
X-Backend-Host
X-BBXSRF
X-Bc-Bl
X-Dispatcher-Server
X-Fastly-Cache
X-Gamma-Serve
X-Agile-Id
X-Agile-Age
X-Agile
X-FW-Version
X-App-Name
X-Device-Os
X-Fetched-On
X-Auto-Login
X-Eu-Site
X-Debug-Log
X-Cache-FS-Status
Powered-By-ChinaCache
X-Cache-Bucket
X-Contensis-Viewer-Groups
X-Gen-Mode
X-Cms-Context
X-CGP
X-Clara-WADP
X-Cache-Info
X-Cache-ASPX
X-Block-Status
X-Cache-URL
X-Debug-Cache-Store
X-Debug-Cookies
X-Load-Cache
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-Core-Mission
X-Bip
X-CUA
X-Developers
X-Li-Fabric
X-TT-TIMESTAMP
X-TrackingId
X-Tumblr-Pixel-3
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Trace-Id
X-Thanos
X-Sigma-Backend
X-Sigma
X-SIPLIST1
X-Slack-Backend
X-Swa-Ws
X-Var-Ttl
X-Varnish-Authentication
X-Wikidot-Static-Cache
X-Wikidot-Backend
Cache-Cookie-Set-From
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
X-Webstats-RespID
X-WebServer
X-Varnish-Cacheable
X-VC-Cache
X-VServer
X-WADP-Cache
X-Server-W
X-Rocket-Build-Number
X-LI-Proto
X-Li-Pop
X-LI-UUID
X-Logging-Id
X-Micro-Cache
X-LAGOON
X-JWT-State
X-Hash
X-Has-Esi
X-Hnp-Log
X-Instart-Isnd
X-Is-Gdpr
X-Ms-Request-Id
X-Ms-Version
X-RateLimit-Limit-Second
X-Proxy-Upstream
X-RateLimit-Remaining-Second
X-Req
X-Request-Host
X-Owner
X-Origin-Expires
X-Nginx-Cache-Key
X-NodeID
X-NX-Host
X-Origin-Date
X-Generated-In
X-Irp-Debug
Pramga
X-VCT
On-Server
N-Cache
X-Varnish-Beresp-Ttl
Memcached
RNT-Machine
RNT-Time
V-Age
W
Server-Surrogate-Control
Server-ID
Server-Cache-Control
Locid
Locale
FNAC-ModuleRouting
Gh-Request-Id
Country-Code
CDCHOST
AKAMAI
Cache-Host
Group
Ha-Gx-Prefs
Kp-EeAlive
L5d-Success-Class
IsBot
Heartbleed
HA-Ipaddr
We-Hiring
Mail-Subject
Wxu-Next-Hostname
Wxu-Next-Commit
Wxu-Next-Region
Web-Mar-Node
X-Lb-Id
X-Rebelmouse-Surrogate-Control
X-Skip-Cache
Platform
Fastly-SWR
Mime-Version
Is-Eu
X-Hit
X-Rebelmouse-Cache-Control
Fastly-Drupal-HTML
X-Generation-Time
X-Epic-Correlation-Id
Countrycode
Cloudfront-Viewer-Country
X-Platform-Server
X-DevSite-Last-Modified
Fastly-SIE
X-Fmm-Version
X-Servername
X-We-Are-Hiring
X-Clientip
X-Variation
X-C
Adler-Geo
X-Cache-Tags
X-Sucuri-ID
X-NC
X-Node-Id
X-ND-Cache
X-Response-By
X-BACKEND-TTL
X-Service
X-Refresh
X-Scheme
X-VHOST
HitType
X-RESPONSE-TIME
X-TA-CDN-Provider
Cache
X-SN
Environment
X-Instart-Info
SD-X-WS
X-CLOUD-TRACE-CONTEXT
X-MCACHE
X-Edge
X-Ratelimit-Remaining
Proxy-Firewall
X-Pjax-Url
X-B3-Spanid
X-APP
X-Cdn-Forward
X-Parent-Response-Time
X-App-Version
X-CSRF-Token
Vix-Hermes-Req-Id
Origin
X-Varnish-URL
Hostname
X-VCache
X-CDN-Forward
Request-Time
X-MSEdge-Features
M-TraceId
X-MSEdge-Flight
X-Cache-PHP
X-Origin-TTL
X-Origin-CC
X-Up
X-Mid
NM-Fastcgi-Cache
X-Correlation-ID
CF-Cached-On
X-Vdms-Path
Fastly-Backend-Name
X-FPC
X-ECACHE
X-Server-Time
Geoip-City
Geoip-Latitude
PICS-Label
X-Wa
X-CSRF-TOKEN
X-Be
Cdn-Request-Time
X-Edge-Server
Cdn-Host
X-ECache
TTL
Pragrma
X-TT-LOGID
Pagetype
Sever-Int
Server-Hostname
Server-Ext
GeoIp-Country-Code
X-Ua
X-Vcl-Version
X-Wix-Viewer-Type
X-Webkit-CSP
NtCoent-Length
Cdn
HostName
CACHE
X-Method
X-AK-Request-ID
X-HS-Status
Cdnsip
Cdncip
X-Protected-By
X-URL
X-Via-PopV
Ohc-File-Size
Magicmarker
X-SVT-ORM-VERSION
X-Worker
X-Newrelic-App-Data
X-SVT-ORM-RULES
X-Via-PopH
X-Myra-Origin2
X-Cache-Host
X-Bc
X-Zone
X-NU-AKA-ACS-Version
Memory
X-Air-Hostname
X-Branch-Name
X-Envoy-Upstream-Healthchecked-Cluster
X-Referer
X-Ratelimit-Limit
X-Request-Start
X-Litespeed-Cache
X-Cache-Metadata
Cteonnt-Length
X-BC
X-Policy
X-Azure-Ref-OriginShield
X-Servedbyhost
Resin-Trace
X-ZONE
Dt-Cache-Category
X-ServedByHost
X-Dynatrace-Js-Agent
X-Pinterest-Direct
SRV
X-DC
X-Cache-Debug
X-Planisys-CDN-TTL
RequestId
X-FORWARDED-FOR
Release
X-C-Key
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-C-Zone
X-Pf-Uncompressing
X-Oneagent-Js-Injection
X-GEO
X-Swift-Error
Ohc-Cache-HIT
X-TH-Server
Esi-Enabled
Load-Balancing
XServer
X-NGINX-Cache
X-Unique-ID
X-Reqid
Lb
IBM-Web2-Location
Who
X-VCL-Version
GeoIP-Country-Code
X-Via-Ucdn
X-Tb-Optimization-Total-Bytes-Saved
Dnion-Transfer-Encoding
X-Cache-Id
X-Esi-Check
X-AIR-PT
X-Tec-Api-Origin
Server-Int
X-Configured-By
X-Tec-Api-Root
Pics-Label
Ttl
X-SRV
X-Tec-Api-Version
X-Ruxit-Js-Agent
GeoIP-Latitude
UCS
X-Fastly-Country-Code
X-Country-IP
X-Ocache
X-Datadome
X-WA
Powered-By
X-COUNTRY
X-Gzip
X-Node-ID
GeoIP-City
LB
Tcn
FSS-Cache
Product
X-B3-SpanId
X-Fpc
MIME-Version
X-VarnishDD-TTL
Fastly-Soc-X-Request-Id
Fastly-SSL
X-PF-Uncompressing
X-Powered-Y
X-Action
X-Svr
X-SERVER-NAME
X-RAMCache
X-Varnish-Url
Sid
X-RSL
X-RPS
X-RPM
Lfy
X-ABtesting
X-Fastly-Request-Id
X-Hello
X-Flog
X-DSS
X-DI
X-DB
X-Fastly-Backend-Reqs
X-PJAX-URL
X-Server-IP
X-DW
X-WPE-Loopback-Upstream-Addr
Host-ID
X-Apw-Hits
X-MID
X-HostName
X-Apw-Access-Token
X-Apw-Access-Action
X-Apw-Access-Object
X-SD-PageType
FSS-Proxy
X-Varnish-Beresp-TTL
X-Cache-Backend
X-Agile-Brick-Ok
X-Page-Impression-Id
X-Via-CDN
ProcessTime
X-Zalando-Child-Request-Id
Xet-Cookie
X-LiteSpeed-Cache-Control
C-Via
X-Render-Time
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
Amp-Access-Control-Allow-Source-Origin
X-Flow-Id
Requestid
X-BE
X-ElasticPress-Search
CF-IPCountry
X-Debug-Revision
X-Debug-Controller
X-B3-Parentspanid
WZWS-RAY
X-Aicache-OS
L
X-Compress-Hint
Cneonction
WebServer
SN
X-Check-Cacheable
CDN
X-User
X-UPSTREAM-Address
X-Litespeed-Cache-Control
X-LB-ID
X-App
X-Internal-Host
CloudFront-Viewer-Country
X-Beluga-Cache-Status
X-Key
X-Beluga-Trace
X-MiniProfiler-Ids
X-Fastly-Cache-Hits
X-Request-Url
DataCenter
X-Nananana
X-Dw-Trace-Id
X-Request-URL
X-Beluga-Record
X-Beluga-Response-Time
X-Beluga-Status
X-Beluga-Node