Threat Level: green Handler on Duty: Manuel Humberto Santander Pelaez

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
CF-RAY
CF-Cache-Status
Link
X-Powered-By
ETag
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Alt-Svc
Access-Control-Allow-Credentials
X-Runtime
X-Xss-Protection
X-FRAME-OPTIONS
X-Drupal-Cache
X-Adblock-Key
X-Check
Content-Security-Policy-Report-Only
X-Generator
X-Cacheable
X-Cache-Status
X-Permitted-Cross-Domain-Policies
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Template
X-Language
X-Iinfo
X-Content-Security-Policy
Content-Encoding
Status
X-AspNetMvc-Version
X-Buckets
X-Kinja-Server-Push
Xkey
Upgrade
X-Request-ID
X-Via
Access-Control-Expose-Headers
X-Turbo-Charged-By
Access-Control-Max-Age
Keep-Alive
X-Drupal-Dynamic-Cache
X-Pass-Why
X-Cache-Group
X-Age
EagleId
X-Backend
X-Envoy-Upstream-Service-Time
X-Robots-Tag
X-CDN
X-Amz-Id-2
X-Amz-Request-Id
X-Page-Speed
X-Ua-Compatible
X-Pingback
X-Server-Powered-By
X-AH-Environment
X-Server
X-Proxy-Cache
X-UA-Device
X-Hacker
Request-Context
X-Nginx-Cache-Status
X-Swift-CacheTime
X-Swift-SaveTime
Grace
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-Cdn
P3p
Cf-Railgun
X-LiteSpeed-Cache
Server-Timing
Feature-Policy
X-Amz-Version-Id
X-Device
X-Server-Id
X-OneAgent-JS-Injection
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-WebKit-CSP
X-Rq
X-Ac
EagleEye-TraceId
X-Cnection
Report-To
X-Cloud-Trace-Context
Request-Id
X-Backend-Server
X-Response-Time
X-Host
Content-Location
X-Node
X-Readtime
X-Origin-Cache
X-Vhost
X-Cache-Lookup
X-Application-Context
X-DataDome
X-ORACLE-DMS-ECID
X-Dispatcher
X-Ruxit-JS-Agent
NEL
X-ORACLE-DMS-RID
X-Rack-Cache
X-Origin-Upstream-Status
X-HW
Surrogate-Control
Rating
X-Country-Code
X-Clacks-Overhead
Allow
X-Dns-Prefetch-Control
X-Country
X-Url
X-FTR-Request-ID
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-DynaTrace
X-MS-InvokeApp
X-Instart-Request-ID
Fusion-Component-Id
Fusion-Template-Id
Fusion-Source
Fusion-Content-Source
Fusion-Content-Id
X-Goog-Hash
X-PC
X-Vname
X-TtlSet
X-Varnish-TTL
X-B3-TraceId
X-TTL
Pinterest-Generated-By
Verso
X-Powered-By-Plesk
X-Px
Public-Key-Pins
RTSS
X-ESI
Edge-Control
X-Mod-Pagespeed
SPRequestGuid
X-VARITI-CCR
X-Middleton-Display
Display
Response
X-Sol
X-Middleton-Response
X-D2id
X-Exp-Id
X-Exp-Variant
X-Kinja
X-GoogleNews-Bot
X-Cdn-Fetch
X-Kinja-Server
X-Use-Magma
Accept-Ch-Lifetime
X-Kinja-Build
X-Kinja-Revision
X-SharePointHealthScore
X-Akam-SW-Version
X-Ah-Environment
X-Recruiting
X-CST
Service-Worker-Allowed
X-Vcap-Request-Id
SPRequestDuration
SPIisLatency
X-Server-Name
X-Version
X-GitHub-Request-Id
TCN
X-Powered-CMS
X-Navigation-Version
MS-Author-Via
X-Abt-Application-Version
X-Trace
X-Debug
Charset
X-Shard
Realpath
Nginx-Cache
Fastly-Restarts
X-Amz-Server-Side-Encryption
X-Amz-Rid
X-Upstream
AR-ATIME
AR-CACHE
AR-PoweredBy
Ar-Sid
X-Aspnetmvc-Version
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Forwarded-Proto
Accept-CH
X-NF-Request-ID
X-Ezoic-Cdn
X-RateLimit-Remaining
Front-End-Https
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Goog-Stored-Content-Length
X-Cached
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-MSEdge-Ref
DynaTrace
Access-Control-Request-Method
Arr-Disable-Session-Affinity
Pagespeed
Content-MD5
X-Shield-Request-Id
X-VCache
AR-Request-ID
X-Mrf-Section-Lastmod
Mrf-Cache-Status
MRF-Tech
X-Mrf-Item-Lastmod
X-B3-TraceId-Primal
MicrosoftSharePointTeamServices
X-FTR-Expires
X-FTR-Cache-Status
X-Country-Code-Real
X-DynaTrace-JS-Agent
S
X-T
X-Amz-Meta-S3cmd-Attrs
X-Fastly-Request-ID
X-Goog-Storage-Class
Accept-Ch
X-Ser
X-FTR-Backend
X-FTR-Balancer
X-FTR-Realm
X-Id
X-FTR-Backend-Server
X-FTR-DC
Paypal-Debug-Id
X-Varnish-Age
ServerID
X-XRDS-Location
X-Via-JSL
X-Grace
X-Accel-Expires
X-Content-Type
X-Client-IP
X-Correlation-Id
X-Dw-Request-Base-Id
X-Forwarded-For
Edge-Cache-Tag
Fastcgi-Cache
X-Hits
X-Amzn-Trace-Id
X-Content-Digest
X-Frontend
X-DIS-Request-ID
Powered
AMP-Access-Control-Allow-Source-Origin
X-N
X-Fastcgi-Cache
Arc-Version
X-Mobile-Rewrite
X-Pinterest-Rid
X-FTR-Cache-Host
PB-RID
Pinterest-Version
PB-PID
X-HS-Hub-Id
X-HS-Content-Id
X-Logged-In
Server-Name
TP-Cache
TP-L2-Cache
X-FastCGI-Cache
X-Vcache
X-Request-Processing-Time
X-Request-Received
X-Kinsta-Cache
X-Cache-Hit
X-Request-Handler-Origin-Region
X-Server-ID
X-Microsite
X-Webkit-CSP
X-Zen-Fury
X-Time
X-AppVersion
X-Az
X-Activity-Id
X-LB-Cache
X-IPLB-Instance
X-Rid
Healthy
X-Type
X-Revision
X-GUploader-UploadID
X-Cache-Age
X-User-Agent
Retry-After
X-Whom
X-Srv
Backend-Timing
X-Analytics
X-B3-Sampled
X-Node-Name
Server-Node
FilterID
X-NWS-LOG-UUID
Alternate-Protocol
X-Hp-Webp
Cache-Tag
X-RateLimit-Limit
Accept-Charset
X-F-Cache
X-Akamai-Edgescape
X-Content-Security-Policy-Report-Only
Cache-Status
X-SERVER
NR-ENABLED
X-Cache-Rule
X-Content-Options
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Content-Powered-By
DC
X-AOL-HN
X-FB-Debug
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Amz-Apigw-Id
X-Cache-2
X-Amzn-RequestId
X-Cluster
X-Tumblr-User
MS-CV
X-Tumblr-Pixel
X-Tumblr-Pixel-0
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
Refresh
Access-Control-Allow-Method
X-Varnish-Grace
X-Jobs
X-App-Environment
X-Instance
X-B
X-Framework
Tracecode
X-Debug-Info
X-Page-Id
X-PHP-Backend
Source
X-Forwarded-Host
X-Cache-TTL
X-Seen-By
X-Request-Guid
Actual-Object-TTL
Surrogate-Key
Host
X-Mobile-URL
X-App-Server
X-Cache-Operation
Fastcgi-Useragent
X-Cache-Key
X-Geo-Country
Frame-Options
X-FW-Static
X-FW-Serve
X-FW-Hash
X-FW-Type
X-FW-Server
X-Cache-Control
X-Pad
X-Cached-By
X-XRDS-LOCATION
X-Host-Name
Cleartype
X-Hostname
X-TA-CDN-Provider
X-Element-Page-Cache
X-Signature
X-B-Cache
X-Git-Hash
Upgrade-Insecure-Requests
X-BCube-Filmed-By
X-Mobile
X-WebKit-CSP-Report-Only
X-Varnish-Backend
X-Response-Served-From
X-ATG-Version
NGB
X-HS-Cache-Config
X-RemovedCookies
X-UA-Device-Type
X-ProcessESI
X-GeoIP
Eomportal-Instance
Filters
Webserver
WPE-Backend
X-Amz-Replication-Status
X-Tumblr-Pixel-2
X-Presslabs-Stats
X-RTag
Ms-Operation-Id
X-Tumblr-Pixel-1
X-Daa-Tunnel
X-Handled-By
X-TT
Cache-Tv-Group
GEO-INFO
X-Drupal-Cache-Tags
X-Origin-Server
X-EdgeConnect-Cache-Status
X-Adobe-Content
X-Cacheable-TTL
X-Ttl
X-Adobe-Loc
Payment
From-Origin
Xserver
X-RequestSource
X-TX-ID
X-TT-TIMESTAMP
X-Wix-Request-Id
X-Cache-TTL-Remaining
Datacenter
X-Litespeed-Cache
X-Cache-Remote
X-Status
X-FW-Dynamic
Liferay-Portal
X-WA-Info
X-Esi
X-Hyper-Cache
X-Cache-Action
X-Region
X-Contextid
X-Acc-Meta-Resource-Type
Cache
Version
X-Edge-Location
X-Content-Age
Viewport
X-Ratelimit-Reset
X-CF-Powered-By
X-Cache-NE
X-Akamai-Transformed
X-Varnish-Hostname
X-HS-Combine-CSS
X-Storage
X-Cache-Server
X-B3-Traceid
PageSpeed
X-Varnish-Server
X-Path-Route
X-Cache-Var-Map
X-ES-SERVER
Load-Balancing
Meta-Geo
Host-Header
X-RN-RSRV
X-Cache-Var
X-Cache-Enabled
Accept-CH-Lifetime
X-Accel-Buffering
X-IP
X-Xfnlog-Site
Ohc-File-Size
X-Viewer-Country
X-Via-Fastly
X-Proxy
Country
X-NCache
X-Cache-Config
DB-Nickname
X-TNCMS
Cache-Name
X-UnsetCookies
X-Tumblr-Pixel-3
Rt-Fastcgi-Cache
X-Debug-Cache
X-Proto
X-Cache-Time
Release
X-Device-Type
X-CCM
X-Loop
Cache-Tags
DSUID
Property-Id
Ec-Rule-Version
Webcakes-App-Version
X-Human
X-Hosted-By
X-From
X-Origin-Hint
X-Cache-Grace
X-OCL
X-Labrador-Cache-Channel
X-Cache-Host
X-FC-Vary-Parameters
X-Akamai-Request-ID2
X-Varnish-Cache-Hits
X-Www-Served-By
X-Vgn-Hpd-Reason
Cache-Hits
X-CS
X-EIG-Tracking-Id
Vix-Hermes-Req-Id
X-Upgrade-Enabled
X-PCL
X-Yottaa-Metrics
TWC-Locale-Group
TWC-Privacy
X-Yottaa-Optimizations
TWC-GeoIP-LatLong
TWC-GeoIP-Country
Selected-Fe
TWC-Connection-Speed
TWC-Device-Class
X-Origin
Webcakes-Region
X-Rule
X-Timing-Wait
X-JoinUs
X-R9-Blue-Green-Version
X-Proxy-Build
X-Backend-Name
X-Backend-TTL
S-Rt
Webcakes-App-Name
X-NewRelic-App-Data
X-Generated
X-Locale
X-Origin-Response-Time
X-PressLabs-Stats
X-Drupal-Cache-Contexts
X-Akamai-Request-ID
X-Cluster-Node
X-Web-Node
Mn-Server-Ip
X-Varnish-Hits
Decoy-Debug-Status
Decoy-Debug-TTL
X-Goog-Meta-Goog-Reserved-File-Mtime
Decoy-Debug-Key
X-VCT
X-Trace-Id
X-Time-Microsecs
X-Site-Version
S-Cnection
X-FireWall-Port
Azure-SiteName
Azure-SlotName
Azure-RegionName
Azure-InstanceId
Azure-Version
X-Section
X-Access
X-Hit
X-PERF
X-ApacheServer
X-Format
X-Rendered-As
X-OVcl
X-OVcl-Cache
X-Real-IP
X-S
Origin-Cache-Control
Origin-Edge-Control
Ohc-Cache-HIT
Cache-Key
Time
Server-Info
X-Pubstack
X-NGENIX-Cache
L5d-Success-Class
X-Redis-Cache
X-Trafficlayer-App-Name
X-Tec-Api-Root
X-Tec-Api-Version
X-Trafficlayer-App-Scope
X-APP-VERSION
X-Tec-Api-Origin
Now
X-FW-Version
Fastcgi-X-Cache-Version
X-Ua
OT-Force-Account-Verify
X-SS-Set-Cookie
Fastly-SSL
X-Upstream-HT
X-Upstream-CT
X-Origin-CC
X-Origin-TTL
X-Cluster-Name
X-ServerID
ServedBy
Access-Control-Request-Headers
Cteonnt-Length
X-Load-Cache
X-Shopify-Stage
X-UUID
X-Alternate-Cache-Key
Origin
X-FB-TRIP-ID
X-ShopId
X-ShardId
X-Sorting-Hat-PodId
Hostname
X-Sorting-Hat-ShopId
X-Soup
X-GoCache-CacheStatus
X-Parent-Response-Time
X-Rocket-Nginx-Bypass
Mime-Version
X-VG-WebCache
NtCoent-Length
X-Webkit-Csp
X-VG-TLSProxy
Accept-Language
Machine
X-Upstream-Proxy
X-Is-Bot
X-UA
Odigeo-Trace-Id
NGX
X-App-Version
X-Uri
IBM-Web2-Location
X-No-Session
X-Tb
Nel
X-Info
X-MServer
X-ECACHE
X-ProxyCache-Key
X-Environment-Context
X-ProxyCache-Status
X-Node-Id
X-L-Path
X-BYPASS-REASON
X-Guploader-Uploadid
X-CACHE-KEY
X-Geo
Uber-Trace-Id
Node
Mobile-Detection-Method
Meta-Geo-Continent
Apple-News-Services-Parsed-Url
BehaviorPad-Version
Proxy-Connection
GEO-REGION-INFO
Content-Style-Type
X-B3-Parentspanid
Apple-News-Services-Host
Cross-Origin-Window-Policy
Rendered-Blocks
Fly-Request-Id
Fly-Cache
Request-Time
CF-IPCountry
Cache-Prefix
AsisCache
Arc-Country
Memcached
A
MD5-Digest
Content-Script-Type
Apple-News-Services-Handled
Apple-News-Services-Request-Url
X-Accel-Expires-Debug
X-Hl-Ver
X-G
X-Instart-Info
X-B3-Spanid
X-Region-Sid
X-PAYTM-SRV-ID
X-External-Request-Id
Request-Country
X-Date
X-D
X-Destination
X-Detected-As
X-Developer
X-Request-UUID
X-Rewrite-Enabled
X-VG-WebServer
X-Twitter-Response-Tags
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-Trv-Group
X-Transaction
X-S-Cookie
X-Rojux
X-ScT
X-Server-Time
X-SRCache-Key
X-Connection-Hash
X-DPWN-IS-SECURE
X-A-Dam
X-A-Ccd
X-Cms-Context
X-A-Dgt
X-A-Wwc
X-A
VivaBuild
Rt-Proxy-Cache
Request-EU
ServerName
T-Server
Viewtype
X-Aed
X-A-Dcw
X-ARC
X-Application
X-AIR-PT
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-B-Cookie
X-Endurance-Cache-Level
X-Nc
Srv
Backend-Name
X-Tt-Trace-Tag
X-Oneagent-Js-Injection
X-Ratelimit-Limit
X-PHP-Host
X-JWT-State
X-Generated-By
X-WADP-Cache
X-Clara-WADP
X-Worker
IsBot
X-Is-Gdpr
X-Device-Os
X-SIPLIST1
X-Has-Esi
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
N-Cache
X-Cdn-Srv
X-S-Maxage
X-Cache-Bucket
X-CSRF-TOKEN
X-Amzn-Remapped-Content-Length
X-B3-SpanId
Mail-Subject
We-Hiring
X-NC
User-Cache-Control
X-Via-CDN
X-Dc
X-Service
X-Server-IP
X-Amz-Meta-Cache-Control
X-Reqid
X-Backend-Url
X-BBXSRF
X-Backend-Host
X-Release
X-Auto-Login
X-Request-Start
X-Thanos
Server-Host
X-Webstats-RespID
X-WebServer
Served-By
Section-Io-Cache
RNT-Machine
RNT-Time
X-We-Are-Hiring
X-Hash
X-TrackingId
X-Bip
X-Up
X-User
X-Variation
X-Var-Ttl
X-Skip-Cache
X-Platform-Server
X-Li-Fabric
X-Level-Front-Cache
X-Fastly-Cache
X-Distributor
X-Dispatcher-Server
X-Li-Pop
X-Dispatch
X-Irp-Debug
X-Fetched-On
X-GeoIP-City
X-IN-APIGATEWAY
X-Geo-Header
X-Generation-Time
X-IN-APIGATEWAYSSL
X-Generated-On
X-Developers
X-LI-UUID
X-Old-Content-Length
X-Clientip
X-Origin-Date
X-Origin-Expires
X-Cache-FS-Status
X-Owner
X-Nginx-Cache
X-Compress-Hint
X-Debug-Cache-Store
X-Location
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-CUA
X-Magnolia-Registration
X-Reboot
X-VC-Cache
Content-Disposition
Heartbleed
X-Cache-Info
Gh-Request-Id
X-NX-Host
AKAMAI
X-Proxy-Cache-Status
X-Request-URI
X-Proxy-Upstream
X-Block-Status
Is-Eu
X-Cdn-Origin
Adler-Geo
X-ElasticPress-Search
Pramga
X-Gen-Mode
Fastly-Soc-X-Request-Id
X-Hnp-Log
X-Debug-Log
X-Debug-Cookies
Pagetype
PFcat
X-Sn-Servicetimems
Platform
Countrycode
X-CACHE-GROUP
Akamai-GRN
X-NWS-UUID-VERIFY
X-Cdn-Forward
X-Matched-Rule
X-Thinkindot-L3
X-Swa-Ws
X-Key
X-Urbn-Context-Path
X-Nginx-Cache-Key
X-CGP
X-Svr
X-VServer
X-Urbn-Site-Id
X-Lb-Id
X-Eu-Site
X-Epic-Correlation-Id
X-SayCDN-TTL
X-Distil-CS
X-Say-TTL
X-Method
X-Policy
X-Say-Cacheable
X-RateLimit-Remaining-Second
X-Core-Mission
X-RateLimit-Limit-Second
X-Qloud-Router
True-Client-Country-4JS
Thinkindot-Control
X-Generated-In
Magicmarker
X-Wikidot-Backend
Kp-EeAlive
Wxu-Next-Region
Wxu-Next-Hostname
Server-Int
Locale
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Wxu-Next-Commit
Web-Mar-Node
SD-X-WS
X-Azure-Ref-OriginShield
X-SD-PageType
X-C
CDCHOST
Esi-Enabled
X-Wikidot-Static-Cache
X-Azure-Ref
L
Ha-Gx-Prefs
X-Cache-Id
HA-Ipaddr
SRV
X-Microcachable
Fastly-SWR
X-Internal-Host
X-Instart-Isnd
Fastly-SIE
V-Age
X-MSEdge-Features
X-MSEdge-Flight
X-Cache-URL
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-ServiceProvider
X-LI-Proto
Resin-Trace
X-Servername
W
X-Backend-State
X-App-Name
Memory
X-Scheme
Cache-Provider
X-FPC
Server-ID
X-Cache-Backend
X-GEO
X-Be
Cdn-Request-Time
REQUESTUUID
X-Processor
Cdn-Host
X-LJ-Flow-ID
X-Edge-Server
X-AWS-Id
X-VWS-Id
X-GDPR
Group
X-DC
X-Mode
X-Org
X-NodeID
X-Request-Time
X-Ratelimit-Remaining
SS
Cache-Host
X-Servedbyhost
X-Wa
X-Hello
X-Pjax-Url
X-ABtesting
X-Flog
X-Datadome
X-CDN-Forward
X-Response-By
X-Server-W
X-IPS-LoggedIn
X-Ms-Version
X-Ms-Request-Id
X-Oss-Storage-Class
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
Country-Code
X-Oss-Request-Id
X-Unique-ID
X-Oss-Server-Time
X-Webapp-Samesite-None-Activated-N
X-Varnish-Beresp-Status
X-Page-Type
Cache-Cookie-Set-Idcheck
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Ttl
Cache-Cookie-Set-Lfrom
X-VCL-Version
X-SN
Cache-Cookie-Set-From
X-Ruxit-Js-Agent
X-EC-Lua
Lfy
X-Via-Ucdn
PICS-Label
X-Session-Fingerprint
X-Oracle-Dms-Rid
X-Proxied
X-Zipkin-Id
X-Zone
X-Routing-Service
X-SRV
X-HS-Status
X-Cache-Debug
X-Ftr-Request-Id
X-Tb-Optimization-Total-Bytes-Saved
UCS
X-Dynatrace
Geoip-Latitude
X-CSRF-Token
Geoip-City
GeoIp-Country-Code
Powered-By-ChinaCache
X-URL
Ttl
X-Agile
X-Agile-Age
X-Pf-Uncompressing
X-COUNTRY
X-Agile-Id
X-GRACE
X-DataStream-Cache-Status
X-Logtrace-Id
XServer
X-7Graus-Varnish-Cache-Control
X-7Graus-Varnish-XKeys
SN
Ajk
X-Varnish-Beresp-TTL
X-MP-GENERATED-AT
X-RateLimit-Reset
X-Sucuri-ID
Environment
X-Fastly-Country-Code
X-Logging-Id
Proxy-Firewall
X-Cache-Miss-From
X-Sedo-Request-Id
X-Unique-Id
ProcessTime
X-Source
X-PF-Uncompressing
X-Grey
X-Newrelic-Synthetics
X-Cache-Category-Id
X-APP
Powered-By
GeoIP-City
X-ZONE
GeoIP-Country-Code
GeoIP-Latitude
X-Bc
X-NODE
X-HTML-Minification-Powered-By
CACHE
X-Ftr-Cache-Host
Cdn
X-Sucuri-Id
X-CLOUD-TRACE-CONTEXT
X-Core-Value
X-Check-Cacheable
X-Vcl-Version
X-Tt-Trace-Host
X-TH-Server
CF-Cached-On
Pics-Label
M-TraceId
X-Edge
X-DataStream-Origin-MEX-Latency
X-Vdms-Version
X-DataStream-MidMile-RTT
X-Aicache-OS
Fastly-Backend-Name
X-LiteSpeed-Cache-Control
MIME-Version
WWW
X-AK-Request-ID
Cdncip
Cdnsip
Cf-Ipcountry
X-Sucuri-Cache
X-Swift-Error
X-Ftr-Dc
X-Ftr-Realm
X-Dynatrace-Js-Agent
X-Ftr-Balancer
X-Ftr-Backend-Server
HostName
X-Ftr-Backend
X-Mid
X-RCS-CacheZone
X-Fastly-Backend-Reqs
X-Rocket-Build-Number
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Shopify-Generated-Cart-Token
X-Planisys-CDN-Cache
Pragrma
X-Sigma
X-Sigma-Backend
X-Fstrz
GW-Server
Requestid
X-MCACHE
LB
X-Varnish-Ttl
X-FORWARDED-FOR
X-ServedByHost
X-Cache-Tag
X-LAGOON
X-NGINX-Cache
X-Via-NSCOPI
Amp-Access-Control-Allow-Source-Origin
X-BC
X-ORACLE-APMCS-REQUEST-ID
X-Secret
X-SaId
X-WA
X-TT-LOGID
X-PJAX-URL
X-Litespeed-Cache-Control
X-ORACLE-APMCS-TAG
X-UPSTREAM-Address
X-Varnish-Url
X-Gannett-Site-Version
Ohc-Response-Time
Lb
X-Action
TTL
X-ND-Cache
X-DB
X-DSS
X-RPS
X-RSL
X-RPM
X-DW
X-CDN-Cache
X-DI
X-BE
X-Cache-Ttl
URI
X-Upstream-Ct
X-Upstream-Ht
Dynatrace
X-GeoIP-Country-Code
Host-ID
X-Varnish-Cacheable
CDN
On-Server
RequestUuid
X-WR-MODIFICATION
X-Refresh
WZWS-RAY
X-Trafficlayer-App-Version
Server-Id
X-Correlation-ID
DataCenter
X-Zalando-Child-Request-Id
X-Served-From
User-Agent
X-Fastly-Cache-Hits
Is-Session-Tracking
Get-Access-Time
X-Proxy-Cacherz
Inserted-Into-Cache-At
Xkeyrz
X-Page-Impression-Id
X-Fpc
X-Via-Edge
X-Via-SSL
Xkeypdq
X-Flow-Id
X-Req
X-Nananana
X-Gamma-Serve
X-VC
X-MID
X-Li-Proto
Warning
X-Dw-Trace-Id
X-Pod
X-SB
Gannett-Cam-Experience-Id
Locid
Correlation-Id
X-Akamai-SSL-Client-Sid
X-Cf-Powered-By
Thinkindot-Cache-Type
X-Akamai-ERRuleID
FNAC-ModuleRouting
X-Amzn-Remapped-Connection
X-Akamai-ERPolicy
X-Amzn-Remapped-Date
V-Cache
SID
Who
X-Request-URL
X-ServerName
X-Bug-Bounty
Processtime
X-ECache
HitType
X-Newrelic-App-Data
X-MiniProfiler-Ids
RequestId
X-LB-ID
X-Gen-Id
Xet-Cookie
X-Crawler
Cneonction
X-Gdpr
X-NU-AKA-ACS-Version
X-LiteSpeed-Tag