Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
Last-Modified
Accept-Ranges
Pragma
X-Content-Type-Options
X-Powered-By
CF-RAY
ETag
Link
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Access-Control-Allow-Origin
Content-Security-Policy
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Served-By
X-Amz-Cf-Id
X-Varnish
Referrer-Policy
X-Timer
CF-Cache-Status
X-Request-Id
X-FRAME-OPTIONS
Access-Control-Allow-Headers
X-AspNet-Version
Access-Control-Allow-Methods
X-Xss-Protection
X-Runtime
X-Download-Options
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Cacheable
Alt-Svc
X-Generator
Content-Security-Policy-Report-Only
X-Request-ID
X-Check
X-AspNetMvc-Version
Status
X-Cache-Status
X-Adblock-Key
Timing-Allow-Origin
X-Iinfo
X-DNS-Prefetch-Control
X-Permitted-Cross-Domain-Policies
X-Template
Content-Encoding
X-Language
X-Content-Security-Policy
X-Turbo-Charged-By
X-CDN
X-Type
Keep-Alive
Xkey
X-Buckets
X-Backend
X-AH-Environment
Access-Control-Max-Age
WPE-Backend
X-Pass-Why
X-Age
X-Cache-Group
X-Server
CF-Ray
Upgrade
X-POWERED-BY
EagleId
Access-Control-Expose-Headers
X-Via
X-Nginx-Cache-Status
X-Server-Powered-By
X-Pingback
X-Drupal-Dynamic-Cache
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Grace
X-Hacker
X-Amz-Request-Id
X-Amz-Id-2
X-UA-Device
Ali-Swift-Global-Savetime
X-Robots-Tag
Cf-Railgun
P3p
X-LiteSpeed-Cache
X-Envoy-Upstream-Service-Time
X-Proxy-Cache
X-Page-Speed
X-Ua-Compatible
Request-Context
Content-Location
X-Device
X-Ac
X-Node
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cnection
X-Host
X-Cache-Lookup
Surrogate-Control
X-Amz-Version-Id
X-Server-Id
X-WebKit-CSP
X-Backend-Server
X-Rack-Cache
X-Response-Time
X-Rq
X-Application-Context
X-Readtime
X-CST
EagleEye-TraceId
X-Dns-Prefetch-Control
Server-Timing
Pinterest-Generated-By
X-Url
X-Cloud-Trace-Context
X-Instart-Request-ID
X-OneAgent-JS-Injection
X-TTL
X-Px
Request-Id
Report-To
X-Country
X-ORACLE-DMS-ECID
X-Clacks-Overhead
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Feature-Policy
Rating
Edge-Control
Allow
X-Country-Code
X-DynaTrace-JS-Agent
Charset
X-Server-Name
X-Powered-CMS
X-FTR-Request-ID
X-DataDome
X-Vname
X-PC
X-TtlSet
X-ESI
X-Origin-Cache
X-DynaTrace
NEL
X-MS-InvokeApp
X-ORACLE-DMS-RID
X-Goog-Hash
X-Recruiting
X-Varnish-TTL
X-Cached
X-VARITI-CCR
X-Vhost
Content-MD5
X-GitHub-Request-Id
RTSS
X-Version
X-F-Cache
X-Exp-Variant
X-Geo-Segment
X-GoogleNews-Bot
X-Kinja
X-Kinja-Revision
X-Exp-Id
X-Kinja-Server
X-Kinja-Build
X-Cdn-Fetch
X-Powered-By-Plesk
Public-Key-Pins
X-CF-Powered-By
X-Pinterest-Rid
Pinterest-Version
X-Upstream-Env
PB-RID
PB-PID
X-Mod-Pagespeed
X-Mobile-Rewrite
Arc-Version
Verso
X-Client-IP
SPRequestGuid
X-D2id
X-Abt-Application-Version
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Accept-CH
X-N
MS-Author-Via
X-Do-Not-Hack
Permitted-Cross-Domain-Policies
X-HeyJason
AR-ATIME
AR-PoweredBy
X-Dispatcher
X-SharePointHealthScore
AR-CACHE
X-Amz-Rid
X-Navigation-Version
X-T
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
DynaTrace
Nginx-Cache
Paypal-Debug-Id
X-Dw-Request-Base-Id
X-Trace
X-Upstream
X-Grace
X-Fastly-Request-ID
Accept-CH-Lifetime
Arr-Disable-Session-Affinity
X-Varnish-Age
X-FastCGI-Cache
X-Hits
TCN
X-Id
X-Amz-Meta-S3cmd-Attrs
X-Shield-Request-Id
X-Forwarded-Proto
X-DIS-Request-ID
X-Pad
X-Origin-Upstream-Status
X-XRDS-Location
SPRequestDuration
SPIisLatency
X-Cache-Hit
X-Content-Options
X-Ruxit-JS-Agent
X-Content-Digest
X-Logged-In
X-IPLB-Instance
Realpath
X-Kinsta-Cache
Access-Control-Request-Method
X-B
X-Acc-Meta-Resource-Type
X-Mrf-Section-Lastmod
X-NF-Request-ID
MRF-Tech
Mrf-Cache-Status
X-Mrf-Item-Lastmod
AR-SID
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Metageneration
X-Server-ID
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-SS-Set-Cookie
X-Vcap-Request-Id
X-HW
S
X-MSEdge-Ref
X-Debug
Service-Worker-Allowed
X-Ser
Server-Name
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Balancer
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Realm
X-PressLabs-Stats
X-FTR-DC
X-Frontend
Tracecode
X-FTR-Expires
X-Wix-Server-Artifact-Id
Fastcgi-Cache
X-Cache-Key
Rt-Fastcgi-Cache
Eomportal-Instance
X-GUploader-UploadID
AMP-Access-Control-Allow-Source-Origin
Alternate-Protocol
Surrogate-Key
X-Forwarded-For
X-Webkit-CSP
X-Oneagent-Js-Injection
Cleartype
X-Cache-Rule
X-NewRelic-App-Data
X-Srv
Cache-Status
X-NWS-LOG-UUID
X-HS-Hub-Id
X-HS-Content-Id
Backend-Timing
X-Analytics
X-VCache
Host
TP-Cache
X-User-Agent
X-Revision
TP-L2-Cache
X-Rid
FilterID
X-FTR-Cache-Host
X-Whom
X-Debug-Info
Fastly-Restarts
X-Ttl
Public-Key-Pins-Report-Only
X-AOL-HN
X-Akam-SW-Version
X-Via-JSL
X-Varnish-Backend
X-Cache-2
ServerID
X-Content-Powered-By
X-RateLimit-Remaining
X-Request-Processing-Time
X-Request-Received
X-Zen-Fury
Accept-Charset
Viewport
X-Cdn
X-Accel-Buffering
X-Mobile
X-Kinja-Server-Push
Front-End-Https
X-WPE-Loopback-Upstream-Addr
X-Oracle-Dms-Rid
Liferay-Portal
X-Cached-By
X-Node-Name
X-B3-Traceid
X-App-Environment
X-Hostname
X-LB-Cache
X-Page-Id
X-Varnish-Hostname
X-Tumblr-Pixel-0
X-Cluster
X-Tumblr-User
X-Cache-Control
X-Content-Security-Policy-Report-Only
Host-Header
X-Magnolia-Registration
X-Tumblr-Pixel
X-Akamai-Edgescape
X-Handled-By
X-Device-Type
X-Framework
X-B3-Sampled
Cache-Tag
X-Request-Guid
X-TT
X-Signature
X-BCube-Filmed-By
X-Instance
X-B-Cache
Upgrade-Insecure-Requests
X-FB-Debug
X-Platform-Server
DC
X-Origin-Server
X-Cache-Server
X-TT-TIMESTAMP
Server-Node
X-TA-CDN-Provider
X-XRDS-LOCATION
Source
Retry-After
MicrosoftSharePointTeamServices
X-WA-Info
X-Servedby
X-Accel-Expires
X-Contextid
Server-Info
HitInfo
HitType
X-Cache-Action
X-Amzn-Trace-Id
X-Varnish-Server
X-Cache-Operation
X-Correlation-Id
X-APP-VERSION
X-Sol
X-Middleton-Display
Display
X-Port
X-Daa-Tunnel
X-Distil-CS
X-Edge-Location
X-Geo-Country
X-Generated-By
AsisCache
X-Esi
X-Hyper-Cache
Webserver
X-Amz-Replication-Status
X-GeoIP
X-RequestSource
X-Tumblr-Pixel-2
X-WebKit-CSP-Report-Only
X-S
X-Tumblr-Pixel-1
GEO-INFO
X-Newrelic-App-Data
X-Seen-By
Actual-Object-TTL
ServedBy
Content-Script-Type
X-TX-ID
Content-Style-Type
X-Locale
X-Wix-Request-Id
X-FW-Server
X-FW-Type
X-FW-Static
X-FW-Serve
X-Jobs
X-Region
X-UUID
X-Varnish-Hits
X-Status
X-Edge-Cache-Key
X-FW-Hash
X-Edge-Cache
Healthy
X-Adobe-Content
X-Adobe-Loc
X-Drupal-Cache-Tags
X-Varnish-Grace
User-Agent
X-Response-Served-From
SRV
Filters
X-DataStream-Cache-Status
X-Amz-Server-Side-Encryption
S-Cnection
NGB
Refresh
X-Proxied
X-Middleton-Response
Response
X-Yottaa-Optimizations
Cache
X-Yottaa-Metrics
X-Cache-TTL-Remaining
X-Correlation-ID
IBM-Web2-Location
AR-Request-ID
X-Fastcgi-Cache
X-Cache-Age
X-URL
X-AppVersion
X-Az
X-Activity-Id
X-App-Server
X-CDN-Forward
X-Pc-Hit
X-Pc-Appver
X-Cache-Remote
X-Pc-Key
X-Content-Type
Payment
X-Cacheable-TTL
X-Cache-NE
X-Unique-ID
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Ruxit-Js-Agent
X-Cache-TTL
Datacenter
X-UA
X-Vg-Webcache
Country
X-Akamai-Transformed
Served-By
X-ATG-Version
X-Mode
HostName
X-HS-Cache-Config
X-Real-IP
Edge-Cache-Tag
X-Sucuri-ID
X-Detected-As
Machine
Load-Balancing
X-Is-Bot
X-RN-RSRV
X-Source
X-Rendered-As
Meta-Geo
X-ProcessESI
X-Proxy
X-ProxyCache-Status
X-ProxyCache-Key
X-BYPASS-REASON
User-Cache-Control
X-OCL
X-FC-Vary-Parameters
X-PCL
X-RemovedCookies
X-Rocket-Nginx-Bypass
X-BB-IP
X-Pubstack
X-ServerID
X-Cache-Config
X-Cache-Category-Id
DB-Nickname
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Device-Class
TWC-Privacy
Webcakes-App-Name
X-ApacheServer
X-Amz-Meta-Surrogate-Control
Webcakes-Region
Webcakes-App-Version
TWC-Connection-Speed
Property-Id
Cache-Name
Cache-Key
Backend
X-PERF
L5d-Success-Class
X-Backend-Name
X-Origin
Now
X-Origin-Hint
Mn-Server-Ip
Access-Control-Allow-Method
X-Tb
X-Varnish-IP
X-EIG-Tracking-Id
X-Debug-Cache
X-Grey
X-Varnish-Cacheable
X-Viewer-Country
X-Human
X-Hosted-By
Azure-SiteName
Azure-SlotName
Azure-InstanceId
X-Zipkin-Id
Azure-Version
X-Hit
Azure-RegionName
X-OVcl
X-Format
X-Generated
S-Rt
ServerName
X-JoinUs
X-Environment-Context
X-OVcl-Cache
X-Via-Fastly
X-Original-Request
X-L-Path
X-Access
Access-Control-Request-Headers
X-CCM
X-Loop
X-Routing-Service
X-CDN-Cache
X-NodeID
X-Site-Version
X-Section
X-Upgrade-Enabled
X-TNCMS
X-Varnish-Cache-Hits
X-IP
X-Agile
X-App-Name
X-Xfnlog-Site
Selected-FE
X-Storage
X-Ocache
X-Proxy-Build
X-Timing-Wait
X-Agile-Id
X-NGENIX-Cache
X-TWH-CORRELATION-ID
X-Agile-Age
X-Drupal-Cache-Contexts
X-Rule
X-Origin-CC
X-HS-Combine-CSS
X-Pc-Host
X-Pc-Date
X-Akamai-Request-ID
X-LJ-Flow-ID
X-VWS-Id
X-SplitTest
X-Www-Served-By
X-AWS-Id
X-RateLimit-Limit
X-Cache-Var
X-Cache-Var-Map
X-Vgn-Hpd-Reason
X-NC
X-Upstream-HT
X-Upstream-CT
X-Time-Microsecs
X-PHP-Backend
XServer
X-UA-Device-Type
From-Origin
OT-Force-Account-Verify
X-NCache
X-Litespeed-Cache
X-Internal-Host
X-Microcachable
X-Nginx-Cache
X-Distributor
X-Release
X-Mshield-Cache-Status
X-Forwarded-Host
X-Mrs-Cache
X-Mrs-Age
Ar-Sid
X-Mrs-Cache-Hits
X-M-Log
Fastcgi-X-Cache-Version
Fastcgi-X-Cache
Fastcgi-Useragent
X-Feature
Fastly-SSL
X-Qnm-Cache
LB
X-M-Reqid
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
Pagetype
X-Ms-Blob-Type
X-Ms-Lease-Status
X-Ms-Version
X-Cache-Backend
X-Ms-Request-Id
X-Birta-Served
X-Birta-Cache-Post
Powered-By-ChinaCache
X-Connection-Hash
X-Transaction
NtCoent-Length
X-Twitter-Response-Tags
X-Labrador-Cache-Channel
MIME-Version
X-EdgeConnect-Cache-Status
X-V
X-Instance-Name
X-B3-Spanid
PageSpeed
X-VG-TLSProxy
Frame-Options
X-Webkit-Csp
X-Ah-Environment
X-Varnish-Beresp-Ttl
X-Web-Node
X-GZip
X-C
Pagespeed
Time
Server-Int
T-Server
X-UE-Client-Country
Rendered-Blocks
V-Age
X-Region-Sid
VivaBuild
X-A
X-Request-URI
Www
Web-Mar-Node
X-PAYTM-SRV-ID
Viewtype
Meta-Geo-Continent
Cache-Prefix
Ec-Rule-Version
BehaviorPad-Version
Arc-Country
AKAMAI
X-Redis-Cache
Fly-Cache
Fly-Request-Id
MD5-Digest
Ajk
IsBot
X-Request-UUID
X-A-Ccd
NGX
X-A-Wwc
X-Dispatcher-Server
X-DPWN-IS-SECURE
X-Logtrace-Id
X-Died
X-Developer
X-Date
X-Destination
X-From
X-G
X-Hnp-Log
X-IN-WAF
X-IN-APIGATEWAY
X-Irp-Debug
X-Generation-Time
X-Gen-Mode
X-Generated-In
X-D
X-CUA
X-NU-AKA-ACS-Version
X-Application
X-ARC
X-Org
X-Accel-Expires-Debug
X-A-Dcw
X-A-Dgt
X-B-Cookie
X-BB-ID
X-CF-Lambda-Version
X-CS
X-CF-Lambda-Fn
X-No-Session
X-Block-Status
X-Cache-Bucket
X-A-Dam
Host-ID
Xc-Version
X-WebServer
X-Rojux
X-Rewrite-Enabled
X-Trv-Group
X-VG-WebServer
X-Via-CDN
X-Via-Edge
X-IN-SSL-APIGATEWAY
X-Server-Time
X-Via-SSL
X-Server-By
X-SRCache-Key
X-ScT
X-SIPLIST1
X-S-Cookie
Cneonction
X-SERVER-NAME
X-FireWall-Port
Kp-EeAlive
X-Owner
X-Debug-Log
Magicmarker
X-Node-Id
X-Wikidot-Static-Cache
HA-Ipaddr
HA-Geolon
HA-Georegion
HA-Geolat
HA-Geocountry
HA-Geocity
Ha-Gx-Prefs
HA-Host
X-Amz-Meta-Cache-Control
X-Wikidot-Backend
HA-Urlpath
HA-Servedtime
X-Debug-Cookies
X-Platform
On-Server
Request-Country
Release
Proxy-Connection
Pragrma
Request-EU
Request-Time
SN
True-Client-Country-4JS
Server-Host
X-CGP
X-Core-Value
X-Crawler
X-Phone
NodeID
MI-Cache-Age
MI-Cache
HA-Cloudapp
X-Cache-CFC
X-Cache-Enabled
Origin-Edge-Control
Origin-Cache-Control
MI-API
X-RateLimit-Limit-Second
Backend-Name
X-Fastly-Cache
GMS-Ver
X-VServer
X-We-Are-Hiring
X-F5-Cache
CDCHOST
Cache-Tags
X-UnsetCookies
X-Key
X-Csrf-Token
X-Var-Ttl
X-Varnish-Action
WZWS-RAY
X-NX-Host
X-CACHE-GROUP
X-Sucuri-Cache
X-Powered-By-ANYU
X-Layer
X-External-Request-Id
X-Origin-TTL
X-MI-In-Market
X-HTML-Minification-Powered-By
X-S-Maxage
X-RCS-CacheZone
X-Sf
X-RateLimit-Remaining-Second
X-Eu-Site
Esi-Enabled
Decoy-Debug-Key
X-ServiceProvider
Country-Code
X-ElasticPress-Search
X-Hl-Ver
Decoy-Debug-Status
Decoy-Debug-TTL
X-NWS-UUID-VERIFY
X-Oss-Server-Time
X-Oss-Storage-Class
X-HOST
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
Cteonnt-Length
X-Webstats-RespID
X-Oss-Request-Id
X-App-Version
X-Sorting-Hat-ShopId
X-Cache-Expires
X-Cache-Srv
X-MSEdge-Flight
X-Backend-Host
X-Cache-Host
X-Backend-State
X-Backend-TTL
X-Backend-Url
X-Nginx-Cache-Key
X-ShardId
X-Location
X-Fstrz
X-Fetched-On
X-Epic-Correlation-Id
X-Matched-Rule
X-FW-Version
X-Gannett-Site-Version
X-Hash
X-Secret
X-GeoIP-Country-Code
X-GeoIP-City
X-Server-IP
X-MSEdge-Features
X-Device-Os
X-Clientip
X-Content-Age
X-Ckpd-Fst-Backend
X-Cdn-Srv
X-Cdn-Origin
X-Croise-Owner
X-Sorting-Hat-PodId
X-ShopId
X-Developers
X-Shopify-Stage
X-Skip-Cache
X-Sn-Servicetimems
X-Cache-URL
Section-Io-Cache
PFcat
Origin
Odigeo-Trace-Id
X-Worker
Platform
X-Tumblr-Pixel-3
RNT-Time
RNT-Machine
Apple-News-Services-Parsed-Url
Mobile-Detection-Method
X-Alternate-Cache-Key
X-Request-Time
Apple-News-Services-Host
Countrycode
X-Reboot
Apple-News-Services-Request-Url
Fastly-Backend-Name
Apple-News-Services-Handled
Is-Eu
X-Variation
Adler-Geo
Heartbleed
Server-ID
X-Returned-From-PostProcessResponse
X-Passed-To
X-Returned-From
X-Returned-From-DLL
X-Passed-To-BeforeDispatch
X-Response-By
X-Trace-Id
X-Thinkindot-L3
X-Returned-From-BeforeDispatch
X-Stale
X-Actual-URL
X-Swa-Ws
X-TT-LOGID
X-Up
Uber-Trace-Id
Thinkindot-CacheControl
Thinkindot-Control
X-Passed-To-DLL
Thinkindot-CacheControl-Type
X-Passed-To-PostProcessResponse
X-CACHE-AGE
Resin-Trace
X-Rebelmouse-Surrogate-Control
X-Servername
Content-Disposition
Fastly-SWR
Sid
Fastly-SIE
X-Core-Mission
X-Rebelmouse-Cache-Control
X-VCT
X-Atg-Version
X-Ua
X-Ezoic-Cdn
CDN
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
X-Store
HTTPS
X-Alicdn-Da-Ups-Status
X-Iejgwucgyu
X-Planisys-CDN-Rules
X-Servedbyhost
X-Policy
ProcessTime
X-Pf-Uncompressing
WP-Super-Cache
X-GEO
Warning
Xserver
CF-IPCountry
X-Proto
X-Cache-ASPX
RequestId
Powered
Dnion-Transfer-Encoding
X-Cluster-Node
REQUESTUUID
Mail-Subject
We-Hiring
X-Refresh
NODE
X-TIME
X-GoCache-CacheStatus
X-Real-Ip
X-DC
X-Datadome
X-Pjax-Url
X-B3-TraceId
X-Req
Cache-Cookie-Set-From
ViewerVersion
Cache-Cookie-Set-Lfrom
X-Dc
Cache-Cookie-Set-Idcheck
NnCoection
X-Origin-Date
X-Origin-Expires
X-Page-Type
X-Time
X-Varnish-Ttl
X-Endurance-Cache-Level
X-Edge-IP
X-Newrelic-Synthetics
X-Surge-Debug
X-Server-W
X-Varnish-HitMiss
X-Cache-Control-Set-By
X-HCF
X-CLOUD-TRACE-CONTEXT
Geoip-Latitude
X-COUNTRY
GeoIp-Country-Code
X-Guploader-Uploadid
Hostname
X-Nc
X-Aed
WWW-Authenticate
X-Server-Group
Processtime
X-Oracle-Dms-Ecid
X-Ms-Lease-State
Geoip-City
Pramga
SD-X-WS
MS-CV
X-Cdn-Forward
TSSecure
X-Wix-Route-ID
X-CSRF-Token
X-Varnish-Url
A
X-Wa
PICS-Label
X-Aicache-OS
Dont-Set-Cookie
X-GRACE
X-Varnish-URL
X-Varnish-Beresp-TTL
X-DataStream-MidMile-RTT
Cdn-Request-Time
X-DataStream-Origin-MEX-Latency
X-Flog
X-Hello
X-ABtesting
X-Gdpr
X-From-Cache
X-Edge-Server
X-Akamai-Request-ID2
Cdn-Host
Node
Cdn
X-Nananana
X-WA
X-Geo
CACHE
Lfy
Lb
X-UPSTREAM-Address
X-Auto-Login
Ms-Operation-Id
X-RTag
X-Use-Magma
DataCenter
Mime-Version
FSS-Proxy
COMMERCE-SERVER-SOFTWARE
X-Optimization
GeoIP-Latitude
X-Cache-HT
GeoIP-Country-Code
X-Env
FSS-Cache
Is-Session-Tracking
Get-Access-Time
X-Ratelimit-Limit
X-Load-Cache
X-Fastly-Backend-Reqs
Who
X-EC-Security-Audit
X-Wix-Petri-Ex
GeoIP-City
PageType
X-APP
X-Sentry-ID
X-SRV
X-WR-MODIFICATION
X-PAGE-TYPE
X-Cache-FS-Status
X-Unique-Id
X-CACHE-KEY
X-Gen-Id
Rt-Proxy-Cache
X-Via-NSCOPI
X-Ver
X-Check-Cacheable
X-Meta-Tbi-Cache-Vertical
Ws
X-GDPR
X-Cache-Id
X-Served-From
X-Cookie
X-Ibm-Trace
X-Dynatrace-Js-Agent
Httpd-Identifier
X-NGINX-Cache
X-FORWARDED-FOR
X-MP-GENERATED-AT
X-Cache-Info
X-Bip
Memcached
X-Thanos
Ohc-File-Size
X-Swift-Error
X-Path-Route
Pics-Label
X-SVT-ORM-VERSION
X-Proxy-Server
X-PJAX-URL
Powered-By
X-SVT-ORM-RULES
X-Request-Start
URI
X-Be
Version
X-Fastly-Cache-Hits
Memory
X-HS-Status
X-B3-SpanId
V-Cache
Group
X-RateLimit-Reset
X-Dw-Trace-Id
X-Cache-Ttl
X-Fe
X-LiteSpeed-Cache-Control
X-CDN-Pop-IP
X-Shard
X-CDN-Pop
Requestid
Cf-Ipcountry
X-ServedByHost
X-P-T
Apicache-Version
Apicache-Store
X-ID
Amp-Access-Control-Allow-Source-Origin
X-GZIP
NX-Cache
X-SB
X-PF-Uncompressing
AGE-Hash
Xet-Cookie
Ohc-Response-Time
Fastly-Soc-X-Request-Id
UCS
X-VC
GW-Server
X-Bug-Bounty
Serverid
CDN-Node
X-Akamai-ERRuleID
X-Akamai-ERPolicy
X-Varnish-Info
X-Ratelimit-Remaining
X-CacheKey
If-Modified-Since
CDN-Cache-Hit
N-Cache
Https
X-Micro-Cache
X-Info
CDN-Cache
X-StackifyID
X-Distil-Cs
X-User
X-BE
RequestUuid
X-Cache-Handler
X-RequestId
X-BBXSRF
X-SD-PageType
X-RAMCache
X-Litespeed-Cache-Control
X-Flags
X-ServerName
X-Route-Name
X-Providence-Cookie
X-Is-Crawler
X-Grace-Duration