Threat Level: green Handler on Duty: Manuel Humberto Santander Pelaez

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
CF-RAY
CF-Cache-Status
Link
X-Powered-By
X-XSS-Protection
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Alt-Svc
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
Content-Security-Policy-Report-Only
X-Cacheable
X-Generator
X-Cache-Status
X-Permitted-Cross-Domain-Policies
X-Xss-Protection
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Template
X-Language
X-Request-ID
X-Iinfo
Status
X-AspNetMvc-Version
X-Content-Security-Policy
Content-Encoding
X-Buckets
X-Kinja-Server-Push
Xkey
Upgrade
X-Via
Access-Control-Expose-Headers
X-Turbo-Charged-By
Keep-Alive
Access-Control-Max-Age
X-Cache-Group
X-Drupal-Dynamic-Cache
X-Pass-Why
P3p
X-Age
EagleId
X-Backend
X-Robots-Tag
X-Envoy-Upstream-Service-Time
X-Amz-Request-Id
X-Amz-Id-2
X-Page-Speed
X-Ua-Compatible
X-Pingback
X-Server-Powered-By
X-AH-Environment
X-Proxy-Cache
X-CDN
X-Hacker
X-UA-Device
X-Server
Request-Context
X-Nginx-Cache-Status
Grace
X-Swift-CacheTime
X-Swift-SaveTime
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-Cdn
Cf-Railgun
X-LiteSpeed-Cache
X-Amz-Version-Id
X-WebKit-CSP
Feature-Policy
Server-Timing
X-Server-Id
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-OneAgent-JS-Injection
X-Rq
X-Ac
X-Cnection
X-Cloud-Trace-Context
Report-To
X-Host
EagleEye-TraceId
X-Response-Time
X-Node
X-Backend-Server
Content-Location
Request-Id
X-Origin-Cache
X-Readtime
X-Vhost
X-Application-Context
X-Cache-Lookup
X-Dns-Prefetch-Control
X-ORACLE-DMS-ECID
X-Dispatcher
NEL
X-Origin-Upstream-Status
X-ORACLE-DMS-RID
X-Rack-Cache
X-Ruxit-JS-Agent
Surrogate-Control
X-DataDome
Allow
X-HW
Rating
X-Country-Code
X-FTR-Request-ID
X-Clacks-Overhead
X-TTL
X-DynaTrace
X-Country
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Url
X-Instart-Request-ID
Fusion-Template-Id
Fusion-Source
Fusion-Content-Id
Fusion-Component-Id
Fusion-Content-Source
X-MS-InvokeApp
X-Goog-Hash
X-Varnish-TTL
X-Vname
X-PC
X-TtlSet
RTSS
Verso
X-CST
X-Powered-By-Plesk
Public-Key-Pins
X-Px
X-Recruiting
Edge-Control
X-VARITI-CCR
X-Mod-Pagespeed
Pinterest-Generated-By
Response
Display
X-Middleton-Response
X-Middleton-Display
X-Sol
Service-Worker-Allowed
X-D2id
X-Kinja-Build
Accept-CH
X-Kinja
X-Kinja-Server
X-Cdn-Fetch
X-Exp-Id
X-Kinja-Revision
X-GoogleNews-Bot
X-Exp-Variant
X-Use-Magma
X-Ah-Environment
X-B3-TraceId
X-Vcap-Request-Id
X-Version
SPRequestGuid
X-SharePointHealthScore
X-Akam-SW-Version
MS-Author-Via
X-Abt-Application-Version
X-Navigation-Version
TCN
X-RateLimit-Remaining
X-GitHub-Request-Id
X-Powered-CMS
SPRequestDuration
SPIisLatency
X-Shard
X-Server-Name
X-Upstream
Accept-Ch-Lifetime
AR-PoweredBy
Ar-Sid
AR-ATIME
AR-CACHE
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Amz-Server-Side-Encryption
Charset
Fastly-Restarts
X-Forwarded-Proto
X-Trace
X-XRDS-Location
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Realpath
Nginx-Cache
X-Amz-Rid
X-Debug
X-ESI
X-Aspnetmvc-Version
Front-End-Https
X-Cached
X-Ezoic-Cdn
AR-Request-ID
X-Shield-Request-Id
X-NF-Request-ID
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
X-MSEdge-Ref
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Metageneration
Pagespeed
Access-Control-Request-Method
Arr-Disable-Session-Affinity
X-FTR-Cache-Status
X-FTR-Expires
X-Country-Code-Real
Paypal-Debug-Id
Content-MD5
DynaTrace
X-Id
X-FTR-Realm
ServerID
X-FTR-DC
X-FTR-Balancer
X-FTR-Backend
MicrosoftSharePointTeamServices
X-FTR-Backend-Server
X-Goog-Storage-Class
X-T
X-Amz-Meta-S3cmd-Attrs
X-Fastly-Request-ID
X-Vcache
S
X-Via-JSL
X-Client-IP
X-Varnish-Age
X-DynaTrace-JS-Agent
X-Content-Type
X-VCache
X-Hits
X-Dw-Request-Base-Id
X-Amzn-Trace-Id
X-Correlation-Id
X-FastCGI-Cache
Fastcgi-Cache
X-RateLimit-Limit
X-Accel-Expires
X-SERVER
X-Content-Digest
X-Ser
X-Grace
X-Frontend
X-FTR-Cache-Host
Powered
X-N
X-Mobile-Rewrite
Arc-Version
PB-RID
PB-PID
AMP-Access-Control-Allow-Source-Origin
Server-Name
X-DIS-Request-ID
X-Logged-In
X-HS-Content-Id
X-HS-Hub-Id
X-Forwarded-For
X-B3-Sampled
Edge-Cache-Tag
TP-L2-Cache
TP-Cache
X-Server-ID
X-Microsite
X-Request-Handler-Origin-Region
X-Esi
X-GUploader-UploadID
X-Zen-Fury
X-Request-Processing-Time
X-Request-Received
X-Type
Backend-Timing
X-Az
X-Activity-Id
X-Cache-Age
X-IPLB-Instance
X-AppVersion
X-Analytics
X-Fastcgi-Cache
X-User-Agent
X-Rid
X-Revision
X-B3-Traceid
X-Kinsta-Cache
Healthy
FilterID
X-LB-Cache
X-Node-Name
X-Whom
Accept-Ch
X-Time
Retry-After
X-Pinterest-Rid
Pinterest-Version
X-Cache-Hit
X-Srv
X-F-Cache
X-NWS-LOG-UUID
X-Cache-2
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Accept-Charset
Alternate-Protocol
Server-Node
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Cache-Rule
Cache-Status
X-AOL-HN
X-Content-Options
Surrogate-Key
Refresh
X-Akamai-Edgescape
X-Content-Powered-By
DC
X-Hp-Webp
X-Debug-Info
X-Instance
X-Content-Security-Policy-Report-Only
X-Forwarded-Host
X-PHP-Backend
X-Tumblr-Pixel-0
X-FW-Static
X-Tumblr-User
VIX-Pulpo-Upstream-Status
X-FW-Server
X-Varnish-Grace
VIX-Pulpo-Node
X-FW-Hash
X-Tumblr-Pixel
X-FW-Type
X-FW-Serve
X-App-Environment
X-B
X-Request-Guid
X-Framework
X-Acc-Meta-Resource-Type
Access-Control-Allow-Method
X-Jobs
Cache-Tag
X-Page-Id
MS-CV
Frame-Options
Source
X-Erf-Bev-Bev
Fastcgi-Useragent
X-TA-CDN-Provider
X-Cluster
X-Erf-Bev-Bev-Is-Generated
X-App-Server
Tracecode
X-FB-Debug
X-Hostname
Host
X-Cache-Key
X-Cache-Operation
Accept-CH-Lifetime
X-Mobile-URL
Actual-Object-TTL
X-Cached-By
Cleartype
X-Signature
X-B-Cache
X-Seen-By
X-Cache-Control
X-Geo-Country
X-BCube-Filmed-By
X-Host-Name
X-Amz-Replication-Status
X-Cache-TTL
X-Varnish-Backend
X-Pad
X-TT
X-Mobile
X-Response-Served-From
X-Git-Hash
NGB
X-Adobe-Loc
X-Adobe-Content
Upgrade-Insecure-Requests
Liferay-Portal
X-TT-TIMESTAMP
Cache-Tv-Group
Payment
X-RemovedCookies
X-ProcessESI
Eomportal-Instance
X-Status
WPE-Backend
Filters
From-Origin
X-TX-ID
X-ATG-Version
X-Handled-By
Ms-Operation-Id
X-Cache-Remote
X-RTag
X-Cacheable-TTL
X-WebKit-CSP-Report-Only
X-UA-Device-Type
X-Tumblr-Pixel-1
X-FW-Dynamic
X-RequestSource
X-GeoIP
X-Tumblr-Pixel-2
GEO-INFO
Webserver
X-Cache-TTL-Remaining
X-Drupal-Cache-Tags
X-WA-Info
X-Origin-Server
X-Ratelimit-Reset
X-Litespeed-Cache
NR-ENABLED
Xserver
X-Content-Age
X-Cache-Action
X-Daa-Tunnel
X-Webkit-CSP
X-Edge-Location
Datacenter
X-Storage
X-PressLabs-Stats
Viewport
X-Varnish-Hostname
X-EdgeConnect-Cache-Status
Version
X-Accel-Buffering
X-Hyper-Cache
X-Wix-Request-Id
X-Contextid
X-CF-Powered-By
X-Presslabs-Stats
X-DataStream-Cache-Status
X-Region
Cache
X-Upstream-Proxy
Host-Header
PageSpeed
X-Akamai-Transformed
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Cache-Var-Map
X-Cache-Var
X-RN-RSRV
X-Path-Route
Meta-Geo
Load-Balancing
X-ES-SERVER
X-Cache-NE
X-Varnish-Server
X-IP
S-Cnection
Ohc-File-Size
X-HS-Cache-Config
Cache-Tags
Cache-Name
X-ApacheServer
X-From
X-Tumblr-Pixel-3
Cache-Hits
X-Section
X-Time-Microsecs
X-Upgrade-Enabled
Ec-Rule-Version
X-Akamai-Request-ID
X-Via-Fastly
X-Akamai-Request-ID2
X-Viewer-Country
X-Access
Decoy-Debug-TTL
Decoy-Debug-Status
X-NCache
X-Ua
X-Origin
X-Cache-Time
DB-Nickname
Rt-Fastcgi-Cache
X-Labrador-Cache-Channel
X-Origin-Response-Time
X-Cache-Server
X-Cache-Enabled
X-PERF
Decoy-Debug-Key
X-Trace-Id
TWC-GeoIP-LatLong
TWC-Device-Class
Property-Id
Mn-Server-Ip
TWC-Locale-Group
TWC-GeoIP-Country
TWC-Privacy
S-Rt
Vix-Hermes-Req-Id
Webcakes-Region
X-TNCMS
Webcakes-App-Name
X-Format
Webcakes-App-Version
Azure-Version
X-Proto
X-Cache-Grace
X-Proxy
X-R9-Blue-Green-Version
X-EIG-Tracking-Id
X-PCL
X-Origin-Hint
X-Loop
X-CCM
X-CS
X-OCL
X-Cache-Host
TWC-Connection-Speed
Cache-Key
Azure-InstanceId
Azure-RegionName
X-Varnish-Cache-Hits
X-Upstream-HT
X-Upstream-CT
Azure-SiteName
Azure-SlotName
X-Cache-Config
X-Xfnlog-Site
X-Backend-TTL
X-Web-Node
Country
X-UnsetCookies
X-S
X-Hit
X-Drupal-Cache-Contexts
X-Locale
X-Cluster-Node
X-Debug-Cache
X-Human
X-Www-Served-By
X-Rule
X-Varnish-Hits
X-Site-Version
X-FireWall-Port
X-FC-Vary-Parameters
Server-Info
X-Hosted-By
X-FW-Version
X-Timing-Wait
X-Proxy-Build
X-VCT
X-Rendered-As
Selected-Fe
X-JoinUs
X-Device-Type
Release
DSUID
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Backend-Name
Time
X-Generated
OT-Force-Account-Verify
Now
Ohc-Cache-HIT
X-APP-VERSION
SRV
X-OVcl
Hostname
X-NewRelic-App-Data
X-OVcl-Cache
ServedBy
X-VG-TLSProxy
Cteonnt-Length
X-Element-Page-Cache
X-Vgn-Hpd-Reason
X-Redis-Cache
Fastcgi-X-Cache-Version
X-Real-IP
Access-Control-Request-Headers
Origin-Cache-Control
X-VG-WebCache
Origin-Edge-Control
X-Pubstack
X-B3-Spanid
X-FB-TRIP-ID
X-CSRF-TOKEN
Accept-Language
Origin
X-ShopId
X-Sorting-Hat-ShopId
X-Shopify-Stage
X-Tb
X-Sorting-Hat-PodId
X-Alternate-Cache-Key
X-NC
X-GEO
L5d-Success-Class
Machine
X-ShardId
X-NGENIX-Cache
X-SS-Set-Cookie
Fastly-SSL
X-HS-Combine-CSS
NtCoent-Length
X-Environment-Context
X-No-Session
X-L-Path
X-Tt-Trace-Tag
X-Nginx-Cache
X-UUID
X-Origin-CC
X-Origin-TTL
X-Parent-Response-Time
X-ECACHE
X-Load-Cache
X-GoCache-CacheStatus
X-Cluster-Name
X-B3-Parentspanid
IBM-Web2-Location
X-COUNTRY
X-LJ-Flow-ID
X-Mode
X-AWS-Id
X-App-Version
X-VWS-Id
Odigeo-Trace-Id
X-ServerID
X-Rocket-Nginx-Bypass
X-Generated-By
X-Amzn-Remapped-Content-Length
X-Endurance-Cache-Level
X-DataStream-Origin-MEX-Latency
X-Uri
X-Soup
X-URL
Nel
X-DataStream-MidMile-RTT
We-Hiring
Akamai-GRN
NGX
X-Magnolia-Registration
X-Is-Bot
Mail-Subject
X-CACHE-KEY
X-Request-Time
X-XRDS-LOCATION
Arc-Country
Memcached
Mobile-Detection-Method
Meta-Geo-Continent
X-ScT
X-Server-Time
Rendered-Blocks
T-Server
Viewtype
X-S-Cookie
Rt-Proxy-Cache
X-Vtex-Remote-Cache
AsisCache
X-S-Maxage
X-DPWN-IS-SECURE
Node
MD5-Digest
Fly-Cache
Cdn-Request-Time
X-Twitter-Response-Tags
X-MServer
Content-Script-Type
Content-Style-Type
X-Node-Id
X-VG-WebServer
X-Trv-Group
X-Transaction
Cache-Prefix
BehaviorPad-Version
VivaBuild
X-Vtex-Processado-Em
GEO-REGION-INFO
Cdn-Host
Fly-Request-Id
Proxy-Connection
X-SRCache-Key
X-A-Ccd
Xc-Version
X-G
Apple-News-Services-Parsed-Url
X-Worker
X-Instart-Info
X-A
X-B-Cookie
X-PAYTM-SRV-ID
X-CF-Lambda-Fn
A
X-Connection-Hash
X-D
X-Date
X-Edge-Server
Apple-News-Services-Host
X-CF-Lambda-Version
X-External-Request-Id
CF-IPCountry
X-ARC
X-Developer
X-A-Dcw
X-A-Dgt
X-Rewrite-Enabled
X-Rojux
Apple-News-Services-Handled
Cross-Origin-Window-Policy
X-A-Dam
X-Request-UUID
Apple-News-Services-Request-Url
X-AIR-PT
X-Application
X-Detected-As
X-Aed
X-Accel-Expires-Debug
X-A-Wwc
X-Region-Sid
X-Destination
Backend-Name
X-Oneagent-Js-Injection
ServerName
Mime-Version
Request-Country
X-Cache-Bucket
X-Azure-Ref-OriginShield
X-Release
Section-Io-Cache
X-Hl-Ver
X-Fastly-Cache
X-Distributor
X-Developers
X-Cms-Context
X-Cdn-Srv
Request-EU
N-Cache
X-Up
X-Urbn-Context-Path
X-Urbn-Site-Id
X-VC-Cache
X-SVT-ORM-VERSION
IsBot
X-SIPLIST1
Locale
X-SVT-ORM-RULES
Fastly-Soc-X-Request-Id
X-Azure-Ref
Request-Time
Uber-Trace-Id
User-Cache-Control
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-Matched-Rule
X-Method
Thinkindot-Control
X-Location
X-Li-Pop
W
X-LI-Proto
V-Age
X-LI-UUID
True-Client-Country-4JS
X-Li-Fabric
X-Origin-Date
X-Org
X-Origin-Expires
X-Owner
X-PHP-Host
Adler-Geo
RNT-Machine
Server-Int
X-Device-Os
Server-ID
X-Nginx-Cache-Key
RNT-Time
Platform
X-Compress-Hint
X-Flog
X-Fetched-On
X-C
X-Block-Status
X-GDPR
X-Clara-WADP
X-Cache-FS-Status
X-Cdn-Origin
X-ElasticPress-Search
X-Epic-Correlation-Id
X-Cache-Info
X-Cache-Id
X-BBXSRF
X-Backend-Url
X-Hnp-Log
X-Hello
X-ABtesting
X-Via-CDN
X-Platform-Server
X-Amz-Meta-Cache-Control
X-App-Name
X-Gen-Mode
X-Backend-Host
X-Generated-On
X-Generation-Time
X-Geo-Header
X-Level-Front-Cache
X-Old-Content-Length
X-Request-URI
CDCHOST
X-Variation
L
X-WADP-Cache
X-VServer
Content-Disposition
X-Thinkindot-L3
Esi-Enabled
Fastly-SIE
X-Sn-Servicetimems
Fastly-SWR
X-ServiceProvider
X-Skip-Cache
X-We-Are-Hiring
Is-Eu
X-RateLimit-Remaining-Second
X-Wikidot-Backend
X-RateLimit-Limit-Second
X-Wikidot-Static-Cache
X-CUA
AKAMAI
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
Magicmarker
X-Reboot
X-Oracle-Dms-Rid
X-Microcachable
X-Dispatch
X-GeoIP-City
Countrycode
X-Webstats-RespID
X-Distil-CS
X-WebServer
X-Guploader-Uploadid
X-Thanos
X-Clientip
X-TrackingId
X-Backend-State
X-Auto-Login
X-IN-APIGATEWAY
X-User
X-Bip
X-Swa-Ws
Wxu-Next-Region
Server-Host
Served-By
X-Request-Start
Kp-EeAlive
Heartbleed
SS
X-Core-Mission
SD-X-WS
Pramga
Pagetype
X-Qloud-Router
X-Dispatcher-Server
X-Reqid
X-Say-TTL
X-Say-Cacheable
Wxu-Next-Hostname
Wxu-Next-Commit
X-Policy
X-Internal-Host
X-IN-APIGATEWAYSSL
X-B3-SpanId
Web-Mar-Node
Gh-Request-Id
X-Servername
X-SayCDN-TTL
X-SD-PageType
X-Server-IP
X-ProxyCache-Key
X-DC
X-BYPASS-REASON
X-ProxyCache-Status
X-Debug-Log
X-Debug-Cookies
X-MSEdge-Flight
X-Proxy-Upstream
X-Dc
X-Service
X-Var-Ttl
X-Proxy-Cache-Status
X-Debug-Cache-Store
X-Generated-In
X-Hash
X-Irp-Debug
X-MSEdge-Features
X-Eu-Site
X-NX-Host
HA-Ipaddr
Ha-Gx-Prefs
X-Debug-Cache-Fetch
X-CGP
Memory
PFcat
X-Debug-Cache-Expiry
Resin-Trace
X-Routing-Service
X-Zipkin-Id
X-Cdn-Forward
X-Proxied
X-Wa
X-FPC
X-Response-By
X-Has-Esi
X-JWT-State
X-Is-Gdpr
X-Key
Cache-Provider
X-Unique-ID
X-UA
X-IPS-LoggedIn
Cache-Cookie-Set-Idcheck
Country-Code
Cache-Cookie-Set-Lfrom
X-Ttl
REQUESTUUID
Cache-Cookie-Set-From
X-Servedbyhost
Srv
X-NWS-UUID-VERIFY
X-RateLimit-Reset
X-Info
X-Page-Type
X-MP-GENERATED-AT
X-Tec-Api-Root
X-Tec-Api-Version
X-Tec-Api-Origin
X-Lb-Id
UCS
X-Nc
X-Be
X-Geo
Powered-By-ChinaCache
X-Ratelimit-Limit
X-VCL-Version
X-Cache-URL
X-Svr
X-Cache-Backend
X-Datadome
X-Processor
X-Logtrace-Id
Ajk
ProcessTime
X-Instart-Isnd
X-CDN-Forward
CACHE
X-HTML-Minification-Powered-By
X-HS-Status
Proxy-Firewall
X-Varnish-Beresp-Ttl
X-Scheme
XServer
X-Trafficlayer-App-Scope
X-SRV
X-Trafficlayer-App-Name
X-Tb-Optimization-Total-Bytes-Saved
PICS-Label
X-Oss-Object-Type
X-NodeID
X-Pjax-Url
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-Oss-Storage-Class
X-Ruxit-Js-Agent
Dynatrace
X-Cache-Category-Id
SN
Powered-By
X-ZONE
X-Grey
X-SN
X-Zone
X-Webkit-Csp
X-FORWARDED-FOR
X-Dynatrace-Js-Agent
X-Ftr-Request-Id
X-Varnish-Beresp-Status
Group
X-Dynatrace
X-Varnish-Beresp-Grace
Fastly-Backend-Name
Ttl
X-Pf-Uncompressing
X-Server-W
Cache-Host
X-TH-Server
X-Source
X-GRACE
GeoIP-Country-Code
GeoIP-City
GeoIP-Latitude
X-Newrelic-Synthetics
X-LiteSpeed-Cache-Control
MIME-Version
X-EC-Lua
X-Via-Ucdn
LB
X-Ms-Request-Id
X-Ms-Version
X-RCS-CacheZone
X-Bc
X-LAGOON
X-APP
Geoip-Latitude
X-PF-Uncompressing
Geoip-City
GW-Server
GeoIp-Country-Code
X-Varnish-Beresp-TTL
X-NODE
X-Sucuri-Id
X-Fastly-Country-Code
Cdn
X-Session-Fingerprint
X-Varnish-Url
CF-Cached-On
Lfy
X-Cache-Ttl
X-Gannett-Site-Version
X-Secret
X-Ftr-Cache-Host
X-Check-Cacheable
WZWS-RAY
Environment
X-Tt-Trace-Host
X-Agile
X-Agile-Age
X-Agile-Id
X-Ratelimit-Remaining
X-BC
Pics-Label
X-Cache-Debug
X-Edge
X-PJAX-URL
X-Aicache-OS
On-Server
X-CDN-Cache
X-Varnish-Cacheable
X-SERVER-NAME
X-7Graus-Varnish-Cache-Control
X-Logging-Id
User-Agent
X-7Graus-Varnish-XKeys
X-GeoIP-Country-Code
WWW
X-Akamai-SSL-Client-Sid
X-Ftr-Dc
X-Ftr-Balancer
X-Ftr-Realm
X-Ftr-Backend
X-Ftr-Backend-Server
M-TraceId
Requestid
X-Cache-Miss-From
Ohc-Response-Time
X-Sedo-Request-Id
X-Mid
Inserted-Into-Cache-At
Cf-Ipcountry
X-MCACHE
X-Varnish-Ttl
X-CSRF-Token
SID
X-Cache-Tag
X-BE
X-NU-AKA-ACS-Version
X-Vcl-Version
X-Fastly-Backend-Reqs
Amp-Access-Control-Allow-Source-Origin
X-Crawler
X-Litespeed-Cache-Control
Who
X-Core-Value
X-UPSTREAM-Address
X-Render-Time
X-Sucuri-ID
Lb
DataCenter
X-Unique-Id
X-AK-Request-ID
Cdncip
Cdnsip
X-DW
X-Action
X-DI
X-DB
X-DSS
URI
X-Proxy-Cacherz
Xkeyrz
X-RSL
X-RPS
X-RPM
X-LB-ID
HostName
RequestUuid
Get-Access-Time
X-Vdms-Version
X-Sucuri-Cache
X-TT-LOGID
Is-Session-Tracking
CDN
X-Newrelic-App-Data
X-FE
Warning
X-Micro-Cache
Host-ID
X-WR-MODIFICATION
X-NGINX-Cache
X-Correlation-ID
X-Page-Impression-Id
X-WA
X-Via-SSL
X-Zalando-Child-Request-Id
X-ServedByHost
Xkeypdq
X-Fastly-Cache-Hits
X-Nananana
X-Flow-Id
X-Via-Edge
X-Fstrz
X-Fpc
X-Served-From
X-Swift-Error
X-TIME
X-Sigma-Backend
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
X-LiteSpeed-Tag
X-Sigma
Pragrma
X-Rocket-Build-Number
Cneonction
Correlation-Id
X-MID
X-SB
FNAC-ModuleRouting
X-Cdn-Request-ID
X-VC
X-Cf-Powered-By
X-Gen-Id
X-ECache
Server-Id
X-ServerName
X-Shopify-Generated-Cart-Token
Processtime
X-Bug-Bounty
HitType
V-Cache
X-Fe
X-Amzn-Remapped-Date
Xet-Cookie
X-Amzn-Remapped-Connection
RequestId
X-Dw-Trace-Id
X-Gdpr
X-Request-URL
X-MiniProfiler-Ids