Threat Level: green Handler on Duty: Manuel Humberto Santander Pelaez

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
CF-RAY
CF-Cache-Status
Link
X-Powered-By
X-XSS-Protection
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Alt-Svc
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
Content-Security-Policy-Report-Only
X-Generator
X-Cacheable
X-Cache-Status
X-Permitted-Cross-Domain-Policies
X-Xss-Protection
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Template
X-Language
X-Request-ID
X-Iinfo
Status
X-AspNetMvc-Version
X-Content-Security-Policy
Content-Encoding
X-Buckets
X-Kinja-Server-Push
Xkey
Upgrade
X-Via
Access-Control-Expose-Headers
X-Turbo-Charged-By
Keep-Alive
Access-Control-Max-Age
X-Cache-Group
X-Drupal-Dynamic-Cache
X-Pass-Why
P3p
X-Age
EagleId
X-Backend
X-Robots-Tag
X-Envoy-Upstream-Service-Time
X-Amz-Id-2
X-Amz-Request-Id
X-Page-Speed
X-Ua-Compatible
X-Pingback
X-Server-Powered-By
X-AH-Environment
X-Proxy-Cache
X-Hacker
X-CDN
X-UA-Device
X-Server
Request-Context
X-Nginx-Cache-Status
Grace
X-Swift-SaveTime
X-Swift-CacheTime
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-Cdn
X-LiteSpeed-Cache
Cf-Railgun
X-Amz-Version-Id
X-Server-Id
X-WebKit-CSP
Feature-Policy
Server-Timing
X-Device
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
X-Rq
X-Ac
X-Cnection
X-Cloud-Trace-Context
Report-To
X-Host
X-Response-Time
EagleEye-TraceId
X-Node
X-Backend-Server
Content-Location
Request-Id
X-Origin-Cache
X-Readtime
X-Vhost
X-Application-Context
X-Cache-Lookup
X-Dns-Prefetch-Control
X-ORACLE-DMS-ECID
X-Dispatcher
NEL
X-Origin-Upstream-Status
X-ORACLE-DMS-RID
X-Rack-Cache
X-Ruxit-JS-Agent
Surrogate-Control
X-DataDome
Allow
X-HW
Rating
X-Country-Code
X-FTR-Request-ID
X-Clacks-Overhead
X-TTL
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-DynaTrace
X-Country
X-Url
X-Instart-Request-ID
Fusion-Content-Source
Fusion-Source
Fusion-Template-Id
Fusion-Content-Id
Fusion-Component-Id
X-Goog-Hash
X-MS-InvokeApp
X-Varnish-TTL
X-Vname
X-TtlSet
X-PC
Verso
RTSS
X-Powered-By-Plesk
X-CST
Public-Key-Pins
X-Px
Edge-Control
X-Recruiting
X-VARITI-CCR
X-Mod-Pagespeed
Pinterest-Generated-By
X-Sol
Response
X-Middleton-Display
Display
X-Middleton-Response
Service-Worker-Allowed
X-Kinja
X-GoogleNews-Bot
X-Kinja-Revision
X-Use-Magma
X-Kinja-Server
X-Kinja-Build
X-D2id
X-Cdn-Fetch
X-Exp-Id
X-Exp-Variant
Accept-CH
X-Ah-Environment
X-B3-TraceId
X-Vcap-Request-Id
X-Version
SPRequestGuid
X-SharePointHealthScore
X-Akam-SW-Version
MS-Author-Via
TCN
X-Abt-Application-Version
X-GitHub-Request-Id
X-Navigation-Version
X-RateLimit-Remaining
X-Powered-CMS
Accept-Ch-Lifetime
SPRequestDuration
SPIisLatency
X-Shard
X-Server-Name
AR-CACHE
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Upstream
X-TEC-API-VERSION
Ar-Sid
AR-ATIME
AR-PoweredBy
X-Amz-Server-Side-Encryption
Fastly-Restarts
X-Forwarded-Proto
Charset
X-XRDS-Location
X-Trace
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Amz-Rid
Nginx-Cache
Realpath
X-Debug
X-ESI
X-Aspnetmvc-Version
Front-End-Https
AR-Request-ID
X-Ezoic-Cdn
X-Cached
X-Shield-Request-Id
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-NF-Request-ID
X-MSEdge-Ref
Mrf-Cache-Status
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
MRF-Tech
X-B3-TraceId-Primal
Access-Control-Request-Method
Pagespeed
Arr-Disable-Session-Affinity
X-FTR-Cache-Status
X-FTR-Expires
X-Country-Code-Real
Paypal-Debug-Id
Content-MD5
X-Id
DynaTrace
ServerID
X-FTR-DC
X-FTR-Backend-Server
MicrosoftSharePointTeamServices
X-FTR-Backend
X-FTR-Balancer
X-FTR-Realm
X-Goog-Storage-Class
X-T
X-Amz-Meta-S3cmd-Attrs
X-Fastly-Request-ID
S
X-Vcache
X-Via-JSL
X-Client-IP
X-Varnish-Age
X-DynaTrace-JS-Agent
X-Content-Type
X-VCache
X-Hits
X-Dw-Request-Base-Id
X-Amzn-Trace-Id
X-Correlation-Id
X-FastCGI-Cache
X-Grace
X-Accel-Expires
Fastcgi-Cache
X-RateLimit-Limit
X-Frontend
X-Content-Digest
X-SERVER
X-Ser
Powered
X-FTR-Cache-Host
X-N
X-Mobile-Rewrite
PB-PID
PB-RID
Arc-Version
X-DIS-Request-ID
AMP-Access-Control-Allow-Source-Origin
X-Logged-In
Server-Name
X-Forwarded-For
X-HS-Content-Id
X-HS-Hub-Id
X-B3-Sampled
TP-Cache
TP-L2-Cache
Edge-Cache-Tag
X-Esi
X-GUploader-UploadID
X-Microsite
X-Request-Handler-Origin-Region
X-Zen-Fury
X-Request-Received
X-Request-Processing-Time
X-Cache-Age
X-Type
X-Kinsta-Cache
X-IPLB-Instance
X-Az
X-Rid
X-Activity-Id
X-User-Agent
Backend-Timing
X-Analytics
X-AppVersion
X-Fastcgi-Cache
X-LB-Cache
X-Revision
Healthy
FilterID
X-B3-Traceid
X-Whom
X-Node-Name
X-Time
Retry-After
Accept-Ch
Pinterest-Version
X-Pinterest-Rid
X-Cache-Hit
X-Srv
X-F-Cache
X-NWS-LOG-UUID
Accept-Charset
X-Cache-2
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Alternate-Protocol
Server-Node
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Cache-Rule
Cache-Status
X-AOL-HN
X-Content-Options
X-Content-Powered-By
Surrogate-Key
Refresh
X-Akamai-Edgescape
DC
X-Hp-Webp
X-Content-Security-Policy-Report-Only
X-Server-ID
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Debug-Info
X-Instance
X-Forwarded-Host
X-Tumblr-Pixel
X-Jobs
X-Tumblr-Pixel-0
Access-Control-Allow-Method
X-Tumblr-User
X-PHP-Backend
X-Page-Id
X-FW-Type
X-Framework
X-FW-Hash
X-FW-Server
X-FW-Static
X-Cluster
X-FW-Serve
Cache-Tag
X-FB-Debug
X-B
X-App-Environment
Source
X-Request-Guid
X-Varnish-Grace
X-Acc-Meta-Resource-Type
MS-CV
Frame-Options
Fastcgi-Useragent
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-TA-CDN-Provider
X-App-Server
Tracecode
X-Hostname
Host
X-Cache-Key
X-Cache-Operation
Actual-Object-TTL
Cleartype
X-Mobile-URL
X-Signature
X-B-Cache
X-Cached-By
X-Seen-By
X-BCube-Filmed-By
X-Cache-Control
X-Geo-Country
X-Cache-TTL
X-Amz-Replication-Status
X-Host-Name
X-Varnish-Backend
X-Pad
X-TT
NGB
X-Response-Served-From
X-Mobile
X-Git-Hash
Upgrade-Insecure-Requests
X-Adobe-Content
X-Adobe-Loc
Accept-CH-Lifetime
Liferay-Portal
X-TT-TIMESTAMP
Payment
X-WebKit-CSP-Report-Only
X-ATG-Version
Cache-Tv-Group
X-RemovedCookies
Eomportal-Instance
Filters
X-ProcessESI
WPE-Backend
X-Status
X-Handled-By
X-RTag
X-Tumblr-Pixel-1
X-Cache-Remote
Webserver
From-Origin
Ms-Operation-Id
X-Tumblr-Pixel-2
X-Cacheable-TTL
X-TX-ID
X-GeoIP
X-FW-Dynamic
GEO-INFO
X-RequestSource
X-Drupal-Cache-Tags
X-Cache-TTL-Remaining
X-UA-Device-Type
X-WA-Info
X-Origin-Server
X-Ratelimit-Reset
NR-ENABLED
X-Content-Age
Xserver
X-Daa-Tunnel
X-Cache-Action
Datacenter
X-Edge-Location
X-Webkit-CSP
X-Storage
Viewport
X-PressLabs-Stats
X-EdgeConnect-Cache-Status
X-Varnish-Hostname
Version
X-Hyper-Cache
X-Wix-Request-Id
X-Accel-Buffering
X-Contextid
X-CF-Powered-By
X-Region
X-Presslabs-Stats
X-DataStream-Cache-Status
Cache
X-Upstream-Proxy
Host-Header
X-Akamai-Transformed
PageSpeed
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Varnish-Server
Load-Balancing
X-RN-RSRV
Meta-Geo
X-Cache-Var-Map
X-ES-SERVER
X-Cache-Var
X-Path-Route
X-IP
X-Cache-NE
S-Cnection
Cache-Name
Cache-Tags
Decoy-Debug-TTL
Cache-Hits
Decoy-Debug-Status
Decoy-Debug-Key
Rt-Fastcgi-Cache
Ec-Rule-Version
DB-Nickname
X-Access
X-Proxy
X-Cache-Config
X-Origin
X-NCache
X-Loop
X-Labrador-Cache-Channel
X-Viewer-Country
X-HS-Cache-Config
X-Cache-Enabled
X-Upgrade-Enabled
X-Time-Microsecs
X-TNCMS
X-Tumblr-Pixel-3
X-Section
X-Cache-Time
X-CS
X-Origin-Response-Time
X-Proto
X-Via-Fastly
X-From
Vix-Hermes-Req-Id
X-ApacheServer
X-Akamai-Request-ID
X-Akamai-Request-ID2
X-PERF
Ohc-File-Size
X-Ua
X-Web-Node
Webcakes-App-Name
X-Proxy-Build
X-Rule
X-Cache-Grace
X-Xfnlog-Site
X-Cache-Host
Azure-RegionName
Country
Cache-Key
X-UnsetCookies
Azure-Version
Azure-SlotName
Azure-SiteName
TWC-GeoIP-LatLong
X-Trace-Id
X-Timing-Wait
X-CCM
TWC-Locale-Group
TWC-Privacy
X-EIG-Tracking-Id
X-Format
X-PCL
X-OCL
X-Backend-TTL
X-R9-Blue-Green-Version
X-JoinUs
X-FC-Vary-Parameters
S-Rt
X-Hit
TWC-GeoIP-Country
Webcakes-Region
TWC-Connection-Speed
Selected-Fe
Mn-Server-Ip
TWC-Device-Class
X-Upstream-CT
X-Upstream-HT
X-Origin-Hint
X-Varnish-Cache-Hits
Webcakes-App-Version
X-Cluster-Node
Property-Id
X-Cache-Server
Azure-InstanceId
X-Site-Version
X-S
X-Debug-Cache
X-Drupal-Cache-Contexts
X-FireWall-Port
X-Backend-Name
X-Locale
X-Hosted-By
X-Human
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Varnish-Hits
X-Www-Served-By
X-Generated
X-Device-Type
Server-Info
X-FW-Version
Now
X-Rendered-As
Release
DSUID
X-VCT
Time
OT-Force-Account-Verify
X-APP-VERSION
X-Vgn-Hpd-Reason
Hostname
SRV
Ohc-Cache-HIT
X-Element-Page-Cache
X-OVcl
X-NewRelic-App-Data
X-OVcl-Cache
X-Real-IP
Cteonnt-Length
ServedBy
X-VG-TLSProxy
Fastcgi-X-Cache-Version
X-Redis-Cache
X-Litespeed-Cache
Access-Control-Request-Headers
Origin-Edge-Control
X-VG-WebCache
X-Pubstack
Origin-Cache-Control
X-ShardId
Accept-Language
X-CSRF-TOKEN
X-FB-TRIP-ID
X-Sorting-Hat-PodId
X-ShopId
X-Sorting-Hat-ShopId
X-B3-Spanid
X-Alternate-Cache-Key
X-Shopify-Stage
L5d-Success-Class
Origin
Machine
X-NC
X-Tb
X-GEO
X-SS-Set-Cookie
X-NGENIX-Cache
Fastly-SSL
X-Nginx-Cache
NtCoent-Length
X-No-Session
X-Environment-Context
X-Cluster-Name
X-Tt-Trace-Tag
X-L-Path
X-HS-Combine-CSS
X-UUID
X-Parent-Response-Time
X-COUNTRY
X-Origin-TTL
X-Origin-CC
X-B3-Parentspanid
X-GoCache-CacheStatus
X-ECACHE
X-Load-Cache
IBM-Web2-Location
X-LJ-Flow-ID
X-App-Version
X-ServerID
X-Mode
X-VWS-Id
X-AWS-Id
X-Rocket-Nginx-Bypass
X-URL
X-Amzn-Remapped-Content-Length
X-Generated-By
X-Magnolia-Registration
X-Endurance-Cache-Level
Odigeo-Trace-Id
X-DataStream-Origin-MEX-Latency
X-Uri
Nel
X-DataStream-MidMile-RTT
X-Is-Bot
NGX
Akamai-GRN
X-Soup
CF-IPCountry
X-CACHE-KEY
X-Request-Time
X-XRDS-LOCATION
A
Fly-Cache
X-MServer
X-Node-Id
Cross-Origin-Window-Policy
Fly-Request-Id
Content-Style-Type
Arc-Country
AsisCache
BehaviorPad-Version
Cache-Prefix
Cdn-Request-Time
Apple-News-Services-Request-Url
Cdn-Host
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Content-Script-Type
Apple-News-Services-Handled
X-AIR-PT
X-Region-Sid
X-PAYTM-SRV-ID
X-Request-UUID
X-Rewrite-Enabled
X-Rojux
X-Instart-Info
X-G
X-Developer
X-Detected-As
X-DPWN-IS-SECURE
X-Edge-Server
X-External-Request-Id
X-S-Cookie
X-S-Maxage
X-Vtex-Processado-Em
X-VG-WebServer
X-Vtex-Remote-Cache
X-Worker
Xc-Version
X-Twitter-Response-Tags
X-Trv-Group
X-ScT
X-Server-Time
X-SRCache-Key
X-Transaction
X-Destination
X-Date
T-Server
Rt-Proxy-Cache
Viewtype
VivaBuild
X-A
Rendered-Blocks
Node
MD5-Digest
Memcached
Meta-Geo-Continent
Mobile-Detection-Method
X-A-Ccd
X-A-Dam
X-CF-Lambda-Fn
X-B-Cookie
X-CF-Lambda-Version
X-Connection-Hash
X-D
X-ARC
X-Application
X-A-Dcw
X-A-Dgt
X-A-Wwc
X-Aed
GEO-REGION-INFO
X-Accel-Expires-Debug
Mail-Subject
Proxy-Connection
We-Hiring
Backend-Name
X-Oneagent-Js-Injection
Mime-Version
ServerName
X-Origin-Date
X-Cache-Bucket
N-Cache
X-Azure-Ref
X-Hl-Ver
X-Developers
X-VC-Cache
X-Up
X-Cms-Context
X-Urbn-Site-Id
X-Fastly-Cache
Fastly-Soc-X-Request-Id
X-Urbn-Context-Path
IsBot
X-Distributor
X-Origin-Expires
X-Cdn-Srv
Locale
X-Azure-Ref-OriginShield
X-Release
Request-Time
Section-Io-Cache
X-SIPLIST1
Request-Country
Request-EU
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
User-Cache-Control
Uber-Trace-Id
X-Clientip
X-Clara-WADP
X-Cdn-Origin
Thinkindot-Control
X-VServer
X-CUA
X-Core-Mission
Thinkindot-CacheControl-Type
X-Compress-Hint
V-Age
True-Client-Country-4JS
X-Cache-Info
X-WebServer
X-ABtesting
X-Backend-Url
X-Amz-Meta-Cache-Control
X-We-Are-Hiring
X-App-Name
X-Auto-Login
X-BBXSRF
X-Bip
X-Cache-FS-Status
X-Cache-Id
X-WADP-Cache
X-Wikidot-Static-Cache
X-C
X-Wikidot-Backend
X-Block-Status
W
X-GDPR
X-TrackingId
X-Platform-Server
X-Policy
X-RateLimit-Limit-Second
X-PHP-Host
X-Owner
X-Nginx-Cache-Key
X-Old-Content-Length
X-Org
X-RateLimit-Remaining-Second
X-Rebelmouse-Cache-Control
X-Thanos
X-ServiceProvider
X-Skip-Cache
X-Sn-Servicetimems
X-Request-URI
X-Request-Start
X-Rebelmouse-Surrogate-Control
X-Reboot
X-Thinkindot-L3
X-Method
X-Matched-Rule
X-Flog
Thinkindot-CacheControl
X-Gen-Mode
X-Generated-On
X-Fetched-On
X-Epic-Correlation-Id
X-Distil-CS
X-Variation
X-ElasticPress-Search
X-Generation-Time
X-Geo-Header
X-LI-Proto
X-LI-UUID
X-Location
X-Li-Pop
X-Li-Fabric
X-Hello
X-Hnp-Log
X-Level-Front-Cache
X-Device-Os
X-Backend-Host
Is-Eu
Fastly-SWR
L
Magicmarker
RNT-Machine
Platform
Fastly-SIE
Esi-Enabled
AKAMAI
Adler-Geo
CDCHOST
Content-Disposition
Countrycode
RNT-Time
Gh-Request-Id
Server-Int
Server-ID
X-Oracle-Dms-Rid
X-ProxyCache-Key
X-BYPASS-REASON
X-ProxyCache-Status
X-Microcachable
X-Debug-Cache-Fetch
X-Debug-Cookies
X-Debug-Log
X-Debug-Cache-Expiry
X-Debug-Cache-Store
HA-Ipaddr
Kp-EeAlive
X-GeoIP-City
X-Irp-Debug
Heartbleed
X-Internal-Host
Ha-Gx-Prefs
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Dispatcher-Server
Server-Host
X-Proxy-Cache-Status
X-Via-CDN
X-Hash
X-Generated-In
Served-By
X-Eu-Site
SD-X-WS
X-Dispatch
X-Qloud-Router
X-Proxy-Upstream
X-Servername
X-B3-SpanId
X-CGP
X-SayCDN-TTL
PFcat
X-Backend-State
Pagetype
Wxu-Next-Region
X-Say-TTL
X-SD-PageType
X-Guploader-Uploadid
Web-Mar-Node
X-NX-Host
X-Webstats-RespID
SS
X-Server-IP
Pramga
Wxu-Next-Hostname
X-Swa-Ws
X-Say-Cacheable
Wxu-Next-Commit
X-DC
X-Dc
X-MSEdge-Flight
X-User
Resin-Trace
X-Key
Memory
X-MSEdge-Features
X-Var-Ttl
X-Reqid
X-Service
X-Cdn-Forward
X-Routing-Service
X-Proxied
X-Zipkin-Id
Cache-Provider
X-JWT-State
X-Unique-ID
X-FPC
X-Wa
X-Has-Esi
X-Is-Gdpr
X-Response-By
X-UA
X-IPS-LoggedIn
Cache-Cookie-Set-From
Cache-Cookie-Set-Idcheck
Srv
Cache-Cookie-Set-Lfrom
X-Ttl
X-Servedbyhost
Country-Code
REQUESTUUID
X-RateLimit-Reset
X-Page-Type
X-NWS-UUID-VERIFY
X-Info
X-Tec-Api-Root
X-Tec-Api-Origin
X-Tec-Api-Version
X-MP-GENERATED-AT
X-Lb-Id
X-Nc
UCS
X-Geo
X-Be
X-Ratelimit-Limit
X-Cache-URL
X-Cache-Backend
Powered-By-ChinaCache
X-Svr
X-VCL-Version
X-Datadome
X-Processor
ProcessTime
Ajk
X-Instart-Isnd
X-Logtrace-Id
X-CDN-Forward
X-HTML-Minification-Powered-By
CACHE
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Object-Type
Proxy-Firewall
X-Varnish-Beresp-Ttl
X-Scheme
XServer
X-Trafficlayer-App-Scope
X-SRV
X-Trafficlayer-App-Name
PICS-Label
X-NodeID
X-Tb-Optimization-Total-Bytes-Saved
X-SN
X-HS-Status
X-Pjax-Url
X-Ruxit-Js-Agent
X-ZONE
Dynatrace
X-Grey
X-Cache-Category-Id
SN
Powered-By
X-FORWARDED-FOR
X-Zone
X-Dynatrace-Js-Agent
X-Webkit-Csp
Group
X-Ftr-Request-Id
X-Varnish-Beresp-Status
X-Dynatrace
X-Varnish-Beresp-Grace
X-TH-Server
X-Pf-Uncompressing
Fastly-Backend-Name
Ttl
X-Server-W
Cache-Host
X-Source
X-GRACE
GeoIP-Latitude
GeoIP-Country-Code
X-Newrelic-Synthetics
GeoIP-City
MIME-Version
X-EC-Lua
X-Ms-Version
X-Via-Ucdn
X-Ms-Request-Id
LB
X-LiteSpeed-Cache-Control
X-RCS-CacheZone
X-APP
GeoIp-Country-Code
X-PF-Uncompressing
Geoip-Latitude
Geoip-City
X-LAGOON
X-Bc
GW-Server
X-NODE
X-Varnish-Beresp-TTL
X-Check-Cacheable
Cdn
Lfy
CF-Cached-On
X-Ftr-Cache-Host
X-Cache-Ttl
X-Session-Fingerprint
X-Varnish-Url
Environment
X-Sucuri-Id
X-Fastly-Country-Code
X-Secret
X-Gannett-Site-Version
X-Agile
WZWS-RAY
X-Cache-Debug
X-Agile-Id
X-Agile-Age
X-Ratelimit-Remaining
X-Tt-Trace-Host
X-BC
X-Aicache-OS
Pics-Label
X-Varnish-Cacheable
X-PJAX-URL
X-CDN-Cache
On-Server
X-Edge
X-SERVER-NAME
X-GeoIP-Country-Code
User-Agent
X-Logging-Id
X-Akamai-SSL-Client-Sid
X-7Graus-Varnish-Cache-Control
X-7Graus-Varnish-XKeys
WWW
X-Ftr-Realm
X-Ftr-Backend-Server
X-Ftr-Backend
X-Ftr-Balancer
X-Ftr-Dc
X-Mid
X-Cache-Miss-From
X-Sedo-Request-Id
M-TraceId
Requestid
Inserted-Into-Cache-At
Ohc-Response-Time
Cf-Ipcountry
X-Vcl-Version
X-Fastly-Backend-Reqs
X-NU-AKA-ACS-Version
X-Varnish-Ttl
X-BE
X-Cache-Tag
X-CSRF-Token
X-MCACHE
SID
Amp-Access-Control-Allow-Source-Origin
X-Render-Time
X-Crawler
X-Core-Value
Who
X-Litespeed-Cache-Control
X-Sucuri-ID
X-UPSTREAM-Address
X-LB-ID
DataCenter
Lb
X-Unique-Id
URI
X-RSL
X-RPS
X-DW
Cdncip
Cdnsip
X-Newrelic-App-Data
X-AK-Request-ID
X-DSS
X-RPM
X-DI
Xkeyrz
X-Action
X-Proxy-Cacherz
X-DB
HostName
Is-Session-Tracking
X-Sucuri-Cache
Get-Access-Time
RequestUuid
X-TT-LOGID
X-Vdms-Version
Host-ID
X-Micro-Cache
CDN
Warning
X-FE
X-WR-MODIFICATION
X-Correlation-ID
X-NGINX-Cache
Xkeypdq
X-Nananana
X-Rocket-Build-Number
X-WA
X-ServedByHost
X-Sigma-Backend
X-Flow-Id
X-Sigma
X-Via-Edge
X-Via-SSL
X-Page-Impression-Id
X-Fpc
X-Zalando-Child-Request-Id
X-Fastly-Cache-Hits
X-Fstrz
X-Served-From
X-Swift-Error
Cneonction
X-TIME
X-Shopify-Generated-Cart-Token
X-Planisys-CDN-TTL
X-MID
X-Cdn-Request-ID
Pragrma
Correlation-Id
X-SB
X-Planisys-CDN-Cache
FNAC-ModuleRouting
X-VC
X-Planisys-CDN-Rules
X-Cf-Powered-By
X-LiteSpeed-Tag
X-Gen-Id
Server-Id
HitType
Processtime
X-ECache
X-Request-URL
X-Fe
X-Amzn-Remapped-Date
X-Amzn-Remapped-Connection
X-Bug-Bounty
X-ServerName
V-Cache
Xet-Cookie
X-Gdpr
X-Dw-Trace-Id
X-MiniProfiler-Ids
RequestId