Threat Level: green Handler on Duty: Jim Clausing

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Accept-Ranges
Cf-Request-Id
CF-Cache-Status
Pragma
X-Powered-By
ETag
Link
Expect-CT
X-XSS-Protection
Via
Age
CF-RAY
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-UA-Compatible
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-Xss-Protection
Alt-Svc
X-Served-By
CF-Ray
X-Timer
X-Varnish
X-Download-Options
Access-Control-Allow-Methods
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Permitted-Cross-Domain-Policies
P3p
X-Cache-Status
X-Generator
X-Request-ID
X-Cacheable
X-Kinja-Server-Push
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-Content-Security-Policy
Status
X-AspNetMvc-Version
Upgrade
Content-Encoding
X-Template
X-Language
X-CDN
Access-Control-Max-Age
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
X-Envoy-Upstream-Service-Time
Keep-Alive
X-Via
X-Ws-Request-Id
X-Age
Feature-Policy
X-Buckets
X-Backend
X-AH-Environment
X-Hacker
X-UA-Device
X-Cache-Group
X-Robots-Tag
X-Server
EagleId
X-Amz-Request-Id
X-Amz-Id-2
X-Proxy-Cache
X-Dns-Prefetch-Control
X-Turbo-Charged-By
X-Server-Powered-By
Request-Context
Server-Timing
Host-Header
Grace
X-Nginx-Cache-Status
Xkey
Report-To
X-Page-Speed
X-Rq
Cf-Bgj
X-Varnish-Cache
X-OneAgent-JS-Injection
X-Pingback
X-LiteSpeed-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
Cf-Railgun
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-WebKit-CSP
X-Amz-Version-Id
X-Vhost
NEL
X-Host
X-Dispatcher
X-Device
X-Backend-Server
X-Node
X-Cache-Lookup
Surrogate-Control
X-Ruxit-JS-Agent
X-Origin-Cache
X-Response-Time
Content-Location
X-Akam-SW-Version
Request-Id
X-ASPNET-VERSION
X-Ac
X-Country
X-Server-Id
X-Mod-Pagespeed
X-HW
Rating
EagleEye-TraceId
Akamai-Age-Ms
X-ORACLE-DMS-ECID
X-Readtime
X-ORACLE-DMS-RID
Accept-CH
Accept-CH-Lifetime
X-Cloud-Trace-Context
Pinterest-Generated-By
X-Application-Context
Edge-Control
X-DataDome
X-Origin-Upstream-Status
X-Country-Code
X-Vname
X-PC
X-TtlSet
X-Varnish-TTL
Fusion-Deployment-Id
Fusion-Source
Fusion-Template-Id
Fusion-Content-Id
Fusion-Component-Id
Fusion-Content-Source
X-Url
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Cnection
X-D2id
X-ESI
X-GitHub-Request-Id
X-MS-InvokeApp
X-Clacks-Overhead
X-Server-Name
X-Content-Type
X-Abt-Application-Version
X-Navigation-Version
X-FTR-Request-ID
X-Vcap-Request-Id
Verso
Pinterest-Version
X-Pinterest-Rid
X-Trace
Allow
X-Server-ID
Display
X-Middleton-Response
X-Sol
X-Middleton-Display
Response
Pagespeed
X-Px
Accept-Ch
X-Cached
X-DynaTrace
X-Element-Page-Cache
X-Rack-Cache
X-Fastly-Request-ID
X-B3-TraceId
Service-Worker-Allowed
X-TTL
X-Client-IP
Accept-Ch-Lifetime
X-Cache-TTL
X-Powered-By-Plesk
X-Version
MS-Author-Via
Arr-Disable-Session-Affinity
X-Upstream
X-Forwarded-Proto
X-T
Content-MD5
X-NF-Request-ID
X-Dw-Request-Base-Id
X-Debug
Fastly-Restarts
AR-CACHE
AR-ATIME
AR-PoweredBy
AR-Request-ID
X-SharePointHealthScore
SPRequestGuid
Ar-Sid
X-VARITI-CCR
X-Jurisdiction
X-XRDS-Location
X-Kinja-Build
X-Kinja-Server
X-Use-Magma
X-Kinja-Revision
X-Kinja
X-Exp-Variant
X-GoogleNews-Bot
X-Cdn-Fetch
X-Exp-Id
TP-Cache
TP-L2-Cache
Access-Control-Request-Method
X-Content-Digest
X-Powered-CMS
X-Goog-Hash
X-PressLabs-Stats
X-NWS-LOG-UUID
X-Edge
X-Release
X-MSEdge-Ref
TCN
X-Webkit-CSP
X-FastCGI-Cache
RTSS
Cache-Tag
Fastcgi-Cache
SPIisLatency
SPRequestDuration
S
X-Amz-Rid
X-Request-Processing-Time
X-Request-Received
Public-Key-Pins
X-Yandex-Sdch-Disable
X-Accel-Expires
X-Ttl
X-MCACHE
X-Mid
X-Ezoic-Cdn
X-Ratelimit-Remaining
Server-Node
X-Cache-Hit
X-Node-Name
X-Logged-In
X-Cache-Key
ServerID
X-Amzn-Trace-Id
X-Pinterest-Direct
Front-End-Https
Alternate-Protocol
X-Request-Handler-Origin-Region
X-Microsite
X-ECACHE
X-Ser
X-Recruiting
X-Origin-Server
X-Page-Id
X-Kinsta-Cache
X-B
X-Ratelimit-Limit
X-CST
X-Hostname
Host
X-Mobile-URL
Accept-Charset
X-FTR-Expires
X-FireWall-Port
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-Realm
X-FTR-DC
X-FTR-Backend
X-Country-Code-Real
X-FTR-Cache-Status
X-Forwarded-For
X-Seen-By
Nginx-Cache
Realpath
X-Content-Security-Policy-Report-Only
X-Varnish-Age
X-SRCache-Fetch-Status
X-Correlation-ID
X-SRCache-Store-Status
Filterid
X-B3-TraceId-Primal
X-Load-Cache
Mrf-Cache-Status
MRF-Tech
X-DIS-Request-ID
X-Jobs
X-Content-Options
X-Id
X-Daa-Tunnel
X-AppVersion
X-Az
X-Activity-Id
X-Shield-Request-Id
X-Type
X-Varnish-Backend
X-F-Cache
Paypal-Debug-Id
X-LB-Cache
X-Git-Hash
X-App-Environment
X-N
X-Request-Guid
X-Rid
X-Varnish-Grace
Edge-Cache-Tag
X-Zen-Fury
Fastcgi-Useragent
X-FB-Debug
X-Hits
X-Grace
X-Proxy
X-App-Server
AMP-Access-Control-Allow-Source-Origin
DC
Content-Disposition
Cache-Tags
X-Content-Powered-By
X-Akamai-Edgescape
DynaTrace
X-Amz-Server-Side-Encryption
X-WebKit-CSP-Report-Only
Access-Control-Allow-Method
X-Cache-Operation
X-Mg-S
X-Cache-Rule
X-Upgrade-Enabled
X-Endurance-Cache-Level
X-Kong-Proxy-Latency
X-Geo-Country
X-Kong-Upstream-Latency
X-Wix-Request-Id
Cleartype
MicrosoftSharePointTeamServices
X-VCache
X-Hp-Webp
X-Cached-By
X-Original-Request-Id
X-TEC-API-ORIGIN
X-Response-Served-From
X-Accel-Buffering
X-TEC-API-ROOT
X-TEC-API-VERSION
X-IPLB-Instance
Refresh
X-B3-Sampled
NGB
X-Host-Name
X-AOL-HN
X-Amzn-RequestId
X-User-Agent
X-Amz-Apigw-Id
X-Rule
X-Distributor
MS-CV
Payment
Healthy
X-Region
X-FW-Serve
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Combine-CSS
X-FW-Type
X-FW-Static
X-FW-Server
X-HS-Cache-Config
X-Cache-Time
X-HTML-Minification-Powered-By
X-UUID
X-HP-Webp
X-Cacheable-TTL
X-B-Cache
X-Signature
X-FW-Hash
X-FW-Dynamic
X-Amz-Meta-S3cmd-Attrs
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Tumblr-Pixel-2
X-Tumblr-User
X-Rendered-As
X-Is-Bot
X-Instance
Powered
X-Tec-Api-Version
X-GUploader-UploadID
X-Goog-Storage-Class
Datacenter
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Whom
X-Goog-Stored-Content-Length
X-Goog-Generation
Countrycode
PB-PID
PB-RID
Arc-Version
X-XRDS-LOCATION
X-Varnish-Server
X-Mobile
X-Debug-Info
X-Frontend
X-Ua
X-App-Version
X-Cache-Age
X-Fastcgi-Cache
X-PHP-Backend
X-Oneagent-Js-Injection
Surrogate-Key
X-DynaTrace-JS-Agent
X-NewRelic-App-Data
X-Backend-Name
Cache
S-Cnection
X-Azure-Ref
Powered-By-ChinaCache
X-FTR-Cache-Host
X-Via-JSL
X-Cache-Server
X-Respond-Thread
X-WA-Info
X-Litespeed-Cache
X-Protected-By
Webserver
X-Hyper-Cache
X-Cache-Control
Referer-Policy
Retry-After
Liferay-Portal
Viewport
X-Proxy-Cache-Status
X-Cache-Expired-At
X-Time
X-URL
From-Origin
X-FB-TRIP-ID
Meta-Geo
X-RN-RSRV
Filters
X-Source
X-Cache-Var
X-R9-Blue-Green-Version
X-ProcessESI
X-Acc-Debug-Context
X-Debug-Cache
X-Cache-Var-Map
X-EdgeConnect-Cache-Status
X-ES-SERVER
X-Mode
X-RemovedCookies
X-From
Eomportal-Instance
X-Locale
X-GeoIP
X-Device-Type
X-Sucuri-ID
X-Qloud-Router
Section-Io-Cache
X-VWS-Id
X-Via-Fastly
X-Ratelimit-Reset
X-Cache-Host
X-Handled-By
X-BYPASS-REASON
Cache-Tv-Group
X-ProxyCache-Status
X-ProxyCache-Key
X-Site-Version
X-LJ-Flow-ID
X-OCL
X-Server-W
X-RTag
X-AWS-Id
X-Time-Microsecs
Mn-Server-Ip
Ms-Operation-Id
X-PCL
Property-Id
DB-Nickname
X-Hl-Ver
Charset
Ec-Rule-Version
Cross-Origin-Window-Policy
TWC-Locale-Group
X-Framework
X-Zipkin-Id
Webcakes-App-Name
TWC-Privacy
X-NYM-Debug-Backend
X-Cluster
Webcakes-App-Version
X-Be
X-Cache-Action
X-Amzn-Remapped-Content-Length
X-Xfnlog-Site
X-Proxied
X-FW-Version
X-Proxy-Build
TWC-Device-Class
TWC-GeoIP-Country
X-TNCMS
X-Human
TWC-Connection-Speed
X-Timing-Wait
X-Origin-Hint
X-Routing-Service
X-Loop
X-ServerID
TWC-GeoIP-LatLong
Selected-Fe
Webcakes-Region
X-CSRF-Token
X-BCube-Filmed-By
X-SaId
X-Section
X-Proto
X-PHP-Host
X-JoinUs
X-L-Path
X-Labrador-Cache-Channel
X-Status
X-Amz-Replication-Status
X-Generated-By
X-Format
X-Real-IP
X-Environment-Context
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Hosted-By
X-Access
X-Redis-Cache
X-Revision
X-Varnish-Cache-Hits
Uber-Trace-Id
X-TA-CDN-Provider
X-Cache-TTL-Remaining
X-Detected-As
X-NWS-UUID-VERIFY
FSS-Cache
X-Air-Hostname
X-No-Session
X-ATG-Version
X-Cache-PHP
Frame-Options
X-Drupal-Cache-Contexts
X-Origin
Version
X-NCache
CF-Cached-On
X-Contextid
X-Sucuri-Cache
X-EIG-Tracking-Id
Server-Name
X-EC-Lua
X-Drupal-Cache-Tags
X-IPS-LoggedIn
X-Tt-Trace-Tag
X-Tt-Trace-Host
GEO-INFO
X-Cache-Enabled
X-Unique-Id
X-Vgn-Hpd-Variations-Key
X-Vgn-Hpd-Cached
X-Instart-Request-ID
X-Bc-Bl
Now
OT-Force-Account-Verify
X-TIME
X-IP
X-Tumblr-Pixel-3
X-Akamai-Transformed
X-CACHE-AGE
X-Cache-Backend
Time
X-GoCache-CacheStatus
X-Backend-Host
X-Ruxit-Js-Agent
X-UA
X-TT
X-Adobe-Loc
X-Adobe-Content
X-RCS-CacheZone
X-Cdn
Node
Access-Control-Request-Headers
X-Oss-Storage-Class
X-Oss-Object-Type
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
Azure-SiteName
Azure-RegionName
X-NGENIX-Cache
Azure-SlotName
Azure-Version
Azure-InstanceId
X-CDN-Forward
X-APP-VERSION
X-AIR-PT
X-ARC
X-Application
X-CCM
Fastcgi-X-Cache-Version
X-G
VIX-Pulpo-Node
X-CF-Lambda-Version
X-Worker
X-PAYTM-SRV-ID
Xc-Version
Apple-News-Services-Host
Apple-News-Services-Handled
CloudFront-Viewer-Country
X-External-Request-Id
DCR-Decision-By
X-Minions-Version
X-B-Cookie
X-Vdms-Path
X-CF-Lambda-Fn
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
DCR-Processing-Time-Ms
X-Generation-Time
X-Aed
X-A-Ccd
X-VG-WebCache
X-A
X-Destination
Mobile-Detection-Method
Meta-Geo-Continent
MD5-Digest
X-A-Dam
X-VG-WebServer
X-Date
X-D
X-Up
SD-X-WS
Surrogated-Key
VIX-Pulpo-Upstream-Status
X-Vdms-Version
X-Twitter-Response-Tags
Rendered-Blocks
X-Transaction
X-Trv-Group
X-Connection-Hash
Machine
Host-ID
X-Cache-2
X-Vtex-Processado-Em
X-Accel-Expires-Debug
X-Adobe-Source
X-Processor
X-Vtex-Remote-Cache
X-Cache-NE
X-PBS-Appsvrname
X-A-Wwc
X-S-Cookie
X-A-Dcw
X-ScT
X-A-Dgt
X-S
X-Request-UUID
X-Rewrite-Enabled
X-Rojux
AKAMAI
Adler-Geo
X-Cms-Context
X-Core-Value
Fastly-SSL
X-Agile
Is-Eu
X-Agile-Age
X-Agile-Id
Fastly-SWR
X-Alternate-Cache-Key
Mail-Subject
NM-Fastcgi-Cache
Wxu-Next-Commit
We-Hiring
Wxu-Next-Hostname
Platform
Wxu-Next-Region
X-CUA
Fastly-SIE
CDN-EdgeStorageId
CDN-PullZone
CDN-CachedAt
CDN-Cache
X-Cache-Grace
CDN-RequestCountryCode
CDN-RequestId
X-Backend-TTL
X-ApacheServer
X-Bip
X-Cache-Bucket
CDN-Uid
CacheControlHeader
X-Varnish-Beresp-Ttl
X-Reqid
X-Level-Front-Cache
X-Req
X-Rebelmouse-Surrogate-Control
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-Platform
X-ShardId
X-Servername
X-Rebelmouse-Cache-Control
X-Varnish-Ttl
X-OVcl-Cache
X-Owner
X-PERF
HostName
X-TX-ID
X-OVcl
X-Pubstack
X-Method
X-Microcachable
X-ShopId
X-Hash
X-Thanos
X-Envoy-Decorator-Operation
X-Storefront-Renderer-Rendered
X-Storage
X-Variation
X-Edge-Location
X-Varnishpool
X-Dispatcher-Server
X-DPWN-IS-SECURE
X-Shopify-Stage
X-VG-TLSProxy
X-SN
X-Skip-Cache
X-Generated-On
X-Sorting-Hat-PodId
X-Soup
X-Sorting-Hat-ShopId
X-Forwarded-Host
X-Cdn-Forward
X-Viewer-Country
X-VarnishDD-TTL
X-Policy
X-Proxy-Upstream
X-Varnish-Cacheable
X-Request-Start
X-Render-Time
X-Micro-Cache
X-Fmm-Version
X-Fastly-Cache
X-Gamma-Serve
X-Cdn-Srv
X-Cache-Tags
X-Geo-Header
X-Fastly-Backend
X-CGP
X-Core-Mission
X-Developers
X-Cluster-Name
X-Clientip
X-Eu-Site
X-Clara-WADP
X-Cache-NGX
X-Has-Esi
X-LI-UUID
X-Li-Pop
X-Location
X-Csrf-Jwt
X-Webstats-RespID
X-Auto-Login
X-Cache-Config
X-Li-Fabric
X-HS-Content-Campaign-Id
X-HN
X-Is-Gdpr
Ufe-Result
X-Cache-Date
X-JWT-State
X-WADP-Cache
X-Backend-State
Gh-Request-Id
Group
Ha-Gx-Prefs
HA-Ipaddr
Decoy-Debug-Key
Cache-Status
Fastly-Drupal-HTML
X-VHOST
Decoy-Debug-TTL
Decoy-Debug-Status
Fastly-Backend-Name
L
L5d-Success-Class
Rt-Fastcgi-Cache
PFcat
Pagetype
C-Via
Country
X-NC
X-Cache-URL
Backend
Akamai-GRN
X-Gzip
X-Esi-Check
X-Irp-Debug
X-Say-TTL
X-Wikidot-Static-Cache
X-Wikidot-Backend
Origin
X-Ms-Request-Id
X-Ms-Version
X-Web-Node
X-Slack-Backend
X-Esi
X-Request-Host
X-Say-Cacheable
X-SayCDN-TTL
X-Old-Content-Length
X-Dc
UCS
X-Cache-Id
M-TraceId
X-Amz-Meta-Cb-Modifiedtime
Memcached
Country-Code
X-CS
Nel
X-Mvc-Supplant-Cachable
X-Content-Age
X-ZONE
X-PF-Uncompressing
X-Refresh
X-BC
X-Wa
X-NODE
FSS-Proxy
Arc-Country
X-Aicache-OS
X-Correlation-Id
X-B3-Spanid
X-Platform-Server
X-RateLimit-Remaining
Actual-Object-TTL
X-ORACLE-APMCS-REQUEST-ID
VivaBuild
X-Via-Poph
X-Via-Popn
X-LB-ID
Viewtype
X-LAGOON
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-RunCloud-Cache
NGX
X-Via-Ucdn
X-B3-Traceid
X-DefElseHash
X-DefHash
Geo-Info
X-Unique-ID
Upgrade-Insecure-Requests
Srv
X-LI-Proto
X-Servedbyhost
X-Branch-Name
X-UPSTREAM-Address
Cdn-Request-Time
Cdn-Host
X-Mvc-Supplant-OutputCached
X-Edge-Server
X-Cache-Debug
X-Session-Fingerprint
X-ECache
X-SERVER
X-Vgn-Hpd-Ssi
Memory
X-Srv
X-Request-Time
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Aspnet-Duration-Ms
X-Providence-Cookie
X-Is-Crawler
X-Flags
X-Bc
X-Zone
X-Route-Name
X-NGINX-Cache
X-Action
X-APP
X-LiteSpeed-Cache-Control
Sid
X-FPC
X-Mobile-Rewrite
CACHE
X-Geo
X-Varnish-Hostname
X-FC-Vary-Parameters
X-Akamai-Request-ID2
X-DI
X-DSS
X-DW
X-RPM
X-DB
X-RSL
X-Cluster-Node
X-RPS
X-CF-Powered-By
WWW-Authenticate
X-Nginx-Cache
X-HS-Status
X-DC
X-Epic-Correlation-Id
X-MP-GENERATED-AT
NtCoent-Length
X-Cs
Server-Info
X-CSRF-TOKEN
X-Nc
X-GEO
X-Hit
GeoIp-Country-Code
Geoip-Latitude
Xserver
X-Oss-Cdn-Auth
X-Via-Popv
XServer
X-Vcache
Hostname
ProcessTime
X-Ftr-Cache-Host
X-Page-View
X-Check-Cacheable
Apigw-Requestid
User-Agent
GeoIP-Country-Code
X-NU-AKA-ACS-Version
GeoIP-Latitude
Processtime
X-SERVER-NAME
X-VCL-Version
X-Vcl-Version
X-FORWARDED-FOR
X-Webkit-CSP-Report-Only
Origin-Cache-Control
SRV
Origin-Edge-Control
X-Dynatrace-Js-Agent
X-HOST
Edge-Copy-Time
Accept-Language
X-Dispatch
X-Fpc
X-Tb
X-UnsetCookies
X-Key
X-Via-CDN
W
Esi-Enabled
X-Envoy-Upstream-Healthchecked-Cluster
X-Via-SSL
CF-IPCountry
X-Via-Edge
X-HITS
X-Sql-Duration-Ms
SID
X-Sql-Count
X-Svr
On-Server
Proxy-Firewall
Cdn
X-We-Are-Hiring
X-Cache-Hm
S-Rt
X-Cache-Hfrom
HitType
X-Www-Served-By
A
Lb
X-Fastly-Country-Code
CDN
X-CACHE-KEY
X-COUNTRY
X-App
LB
T-Server
Amp-Access-Control-Allow-Source-Origin
X-Geo-Region
Fastcgi-Cache-TTL
BehaviorPad-Version
Cteonnt-Length
Cache-Hits
N-Cache
X-RAMCache
X-Pass-Why
ServedBy
X-Generated
Ohc-File-Size
X-Path-Route
X-S-Maxage
X-SRV
WebServer
X-MSEdge-Features
X-Instart-Info
X-MSEdge-Flight
Server-Host
X-Amzn-Remapped-Date
X-TrackingId
X-Pjax-Url
X-Amzn-Remapped-Connection
X-Newrelic-App-Data
Powered-By
X-Cache-Remote
Xet-Cookie
Pics-Label
WZWS-RAY
X-Li-Proto
X-ServedByHost
Magicmarker
X-Newrelic-Synthetics
X-Datadome
X-Dynatrace
X-Served-From
X-VC
X-StackifyID
X-Lb-Id
X-TH-Server
Cache-Key
X-Akamai-Pragma-Client-IP
X-SB
X-Varnish-Hits
Ohc-Cache-HIT
X-Origin-Response-Time
X-Via-NSCOPI
Cache-Provider
X-Info
X-Via-PopV
X-Via-PopH
Server-Ttl
X-Batcache
X-Via-PopN
Dnion-Transfer-Encoding
Content-Style-Type
Content-Script-Type
X-LiteSpeed-Tag
X-Presslabs-Stats
X-Cache-Tag
User-Cache-Control
X-Planisys-CDN-Rules
Cf-Alt-Svc
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
X-Tt-Logid
X-WA
X-Agile-Brick-Ok
X-Region-Sid
X-TT-LOGID
X-ID
X-B3-SpanId
Tcn
Protected
X-Vgn-Hpd-Reason
X-PJAX-URL
Odigeo-Trace-Id
X-Pad
X-HostName
X-Yottaa-OS
X-DevSite-Last-Modified
X-Tid
X-RateLimit-Limit
X-Uri
X-Pf-Uncompressing
Who
Inserted-Into-Cache-At
X-Selected-Scheme
Load-Balancing
X-Selected-Host-Header
CountryCode
X-Selected-Name
Ssr
X-Apw-Access-Action
X-Developer
X-Request-URL
X-Varnish-Beresp-TTL
X-Origin-CC
X-Apw-Access-Token
X-Apw-Hits
PICS-Label
X-Apw-Access-Object
X-Proxy-Cachei7
X-SRCache-Key
Mime-Version
X-C
Vha6-Origin
X-MiniProfiler-Ids
X-Nananana
X-Compress-Hint
X-Origin-TTL
X-Akamai-ERPolicy
X-Magnolia-Registration
X-Dw-Trace-Id
Cneonction
GEO-REGION-INFO
Pragrma
X-Fastly-Cache-Hits
AsisCache
X-Parent-Response-Time
X-Akamai-ERRuleID