Threat Level: green Handler on Duty: Manuel Humberto Santander Pelaez

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
CF-RAY
CF-Cache-Status
Link
X-Powered-By
X-XSS-Protection
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Alt-Svc
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
Content-Security-Policy-Report-Only
X-Generator
X-Cacheable
X-Cache-Status
X-Permitted-Cross-Domain-Policies
X-Xss-Protection
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Template
X-Language
X-Request-ID
X-Iinfo
Status
X-Content-Security-Policy
X-AspNetMvc-Version
Content-Encoding
X-Buckets
X-Kinja-Server-Push
Xkey
Upgrade
X-Via
Access-Control-Expose-Headers
X-Turbo-Charged-By
Keep-Alive
Access-Control-Max-Age
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Pass-Why
P3p
X-Age
EagleId
X-Backend
X-Envoy-Upstream-Service-Time
X-Robots-Tag
X-Amz-Request-Id
X-Amz-Id-2
X-Page-Speed
X-Ua-Compatible
X-Pingback
X-Server-Powered-By
X-AH-Environment
X-Proxy-Cache
X-CDN
X-UA-Device
X-Hacker
X-Server
Request-Context
X-Nginx-Cache-Status
Grace
X-Swift-SaveTime
X-Swift-CacheTime
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-Cdn
Cf-Railgun
X-LiteSpeed-Cache
X-Amz-Version-Id
Server-Timing
Feature-Policy
X-WebKit-CSP
X-Device
X-Server-Id
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-OneAgent-JS-Injection
X-Rq
X-Ac
X-Cnection
X-Cloud-Trace-Context
Report-To
EagleEye-TraceId
X-Response-Time
X-Host
X-Backend-Server
Request-Id
X-Node
Content-Location
X-Origin-Cache
X-Readtime
X-Vhost
X-Application-Context
X-Cache-Lookup
X-Dns-Prefetch-Control
X-ORACLE-DMS-ECID
X-Dispatcher
X-ORACLE-DMS-RID
NEL
X-Ruxit-JS-Agent
X-DataDome
X-Origin-Upstream-Status
X-Rack-Cache
Surrogate-Control
X-HW
Allow
Rating
X-Country-Code
X-Clacks-Overhead
X-FTR-Request-ID
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-DynaTrace
X-Country
X-Url
X-Instart-Request-ID
Fusion-Content-Source
Fusion-Template-Id
Fusion-Component-Id
Fusion-Content-Id
Fusion-Source
X-TTL
X-MS-InvokeApp
X-Goog-Hash
X-Varnish-TTL
X-Vname
X-TtlSet
X-PC
X-Powered-By-Plesk
Verso
RTSS
Pinterest-Generated-By
Public-Key-Pins
X-Px
Edge-Control
X-CST
X-Mod-Pagespeed
X-VARITI-CCR
X-Recruiting
Response
X-Middleton-Response
X-Sol
Display
X-Middleton-Display
X-B3-TraceId
X-Cdn-Fetch
X-Kinja-Build
X-Kinja-Revision
X-Use-Magma
X-Kinja
X-Exp-Variant
X-GoogleNews-Bot
X-Exp-Id
X-Kinja-Server
X-D2id
Service-Worker-Allowed
Accept-CH
X-Ah-Environment
SPRequestGuid
X-SharePointHealthScore
X-Vcap-Request-Id
X-Version
X-Akam-SW-Version
X-Server-Name
MS-Author-Via
X-GitHub-Request-Id
TCN
SPRequestDuration
SPIisLatency
X-Abt-Application-Version
X-Navigation-Version
X-Powered-CMS
X-ESI
X-Shard
Accept-Ch-Lifetime
X-Upstream
Fastly-Restarts
Charset
X-RateLimit-Remaining
X-Amz-Server-Side-Encryption
X-Trace
AR-PoweredBy
AR-ATIME
Ar-Sid
AR-CACHE
Nginx-Cache
X-Amz-Rid
Realpath
X-Forwarded-Proto
X-Debug
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Aspnetmvc-Version
X-XRDS-Location
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Ezoic-Cdn
Front-End-Https
X-Cached
X-NF-Request-ID
AR-Request-ID
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Length
Pagespeed
X-MSEdge-Ref
X-Shield-Request-Id
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
MRF-Tech
X-Mrf-Item-Lastmod
Mrf-Cache-Status
Access-Control-Request-Method
Arr-Disable-Session-Affinity
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Expires
Content-MD5
X-VCache
Paypal-Debug-Id
MicrosoftSharePointTeamServices
X-Id
X-Goog-Storage-Class
X-T
X-FTR-Backend
X-FTR-Backend-Server
X-FTR-DC
X-FTR-Realm
X-Amz-Meta-S3cmd-Attrs
X-FTR-Balancer
S
ServerID
X-Fastly-Request-ID
DynaTrace
X-Via-JSL
X-Varnish-Age
X-Client-IP
X-Server-ID
X-Content-Type
X-Ser
X-Dw-Request-Base-Id
X-Hits
X-DynaTrace-JS-Agent
X-Correlation-Id
X-Amzn-Trace-Id
X-Grace
X-Accel-Expires
X-FastCGI-Cache
Fastcgi-Cache
X-Frontend
X-Vcache
X-Content-Digest
Powered
X-SERVER
X-N
X-DIS-Request-ID
X-FTR-Cache-Host
AMP-Access-Control-Allow-Source-Origin
PB-RID
Arc-Version
PB-PID
X-Mobile-Rewrite
Edge-Cache-Tag
Server-Name
X-Logged-In
X-HS-Content-Id
X-HS-Hub-Id
X-RateLimit-Limit
X-Forwarded-For
TP-Cache
TP-L2-Cache
X-GUploader-UploadID
X-Request-Handler-Origin-Region
X-Microsite
X-B3-Sampled
X-Request-Received
X-Request-Processing-Time
X-Pinterest-Rid
Pinterest-Version
X-Cache-Age
X-Zen-Fury
X-Kinsta-Cache
X-Activity-Id
X-AppVersion
X-Az
X-Type
X-Revision
X-IPLB-Instance
Backend-Timing
X-Analytics
X-User-Agent
X-Rid
X-LB-Cache
X-Fastcgi-Cache
Healthy
FilterID
X-Whom
Retry-After
X-Time
X-Node-Name
X-Cache-Hit
Accept-Ch
X-Srv
X-NWS-LOG-UUID
Server-Node
X-F-Cache
Accept-Charset
Alternate-Protocol
X-Cache-2
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Erf-Bev-Bev-Is-Generated
X-Esi
X-Erf-Bev-Bev
X-Cache-Rule
X-Hp-Webp
Cache-Status
X-Amzn-RequestId
X-B3-Traceid
X-Amz-Apigw-Id
X-Akamai-Edgescape
Cache-Tag
X-Content-Options
Surrogate-Key
X-TA-CDN-Provider
Refresh
DC
X-Content-Security-Policy-Report-Only
X-Content-Powered-By
X-Instance
X-Forwarded-Host
X-AOL-HN
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Tumblr-User
X-Webkit-CSP
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Debug-Info
Access-Control-Allow-Method
Tracecode
X-Varnish-Grace
X-PHP-Backend
MS-CV
X-Framework
X-Cluster
X-Jobs
X-Request-Guid
Fastcgi-Useragent
X-App-Environment
X-FB-Debug
Source
X-Page-Id
X-FW-Hash
X-FW-Serve
X-FW-Static
X-FW-Server
X-FW-Type
X-App-Server
X-B
Frame-Options
X-Cache-Operation
X-Cache-Key
X-Hostname
X-Mobile-URL
Actual-Object-TTL
Host
X-Cache-TTL
X-Seen-By
X-Geo-Country
Accept-CH-Lifetime
X-Cache-Control
Cleartype
X-Signature
X-B-Cache
X-Acc-Meta-Resource-Type
X-BCube-Filmed-By
X-Cached-By
X-Host-Name
X-Pad
X-Git-Hash
NR-ENABLED
Upgrade-Insecure-Requests
X-TT
X-Amz-Replication-Status
X-Varnish-Backend
X-Mobile
NGB
X-Response-Served-From
X-Adobe-Loc
X-Adobe-Content
WPE-Backend
X-WebKit-CSP-Report-Only
X-TT-TIMESTAMP
X-ProcessESI
X-Handled-By
Cache-Tv-Group
X-RemovedCookies
Eomportal-Instance
X-RTag
Ms-Operation-Id
Payment
GEO-INFO
Filters
Liferay-Portal
From-Origin
X-Tumblr-Pixel-1
X-ATG-Version
Webserver
X-Drupal-Cache-Tags
X-TX-ID
X-Tumblr-Pixel-2
X-Cacheable-TTL
X-UA-Device-Type
X-Litespeed-Cache
X-Cache-Remote
X-GeoIP
X-RequestSource
X-Status
X-FW-Dynamic
X-Cache-TTL-Remaining
X-Presslabs-Stats
X-Origin-Server
X-Daa-Tunnel
X-EdgeConnect-Cache-Status
X-WA-Info
X-Cache-Action
X-Content-Age
X-Edge-Location
X-Wix-Request-Id
X-Storage
X-Hyper-Cache
Viewport
X-Contextid
Datacenter
X-Region
Version
X-CF-Powered-By
X-Ratelimit-Reset
X-HS-Cache-Config
Xserver
X-Varnish-Hostname
X-Accel-Buffering
X-Element-Page-Cache
Ohc-File-Size
Cache
X-Akamai-Transformed
Host-Header
PageSpeed
X-PressLabs-Stats
X-Cache-NE
X-Cache-Var-Map
X-ES-SERVER
X-Path-Route
X-RN-RSRV
X-Cache-Var
Meta-Geo
X-Cache-Server
X-Varnish-Server
Load-Balancing
X-Yottaa-Optimizations
S-Cnection
X-Yottaa-Metrics
X-IP
Cache-Tags
Cache-Name
Ec-Rule-Version
X-CS
Decoy-Debug-TTL
Decoy-Debug-Key
X-Cache-Enabled
X-Cluster-Node
Decoy-Debug-Status
Rt-Fastcgi-Cache
Vix-Hermes-Req-Id
X-Access
X-Akamai-Request-ID
X-ApacheServer
X-Viewer-Country
X-Cache-Config
X-Via-Fastly
X-Akamai-Request-ID2
X-Proxy
X-Proto
X-PERF
X-Loop
X-Tumblr-Pixel-3
X-R9-Blue-Green-Version
X-TNCMS
X-Origin-Response-Time
X-Time-Microsecs
Cache-Hits
X-NCache
X-Section
Azure-InstanceId
Mn-Server-Ip
Azure-RegionName
S-Rt
Cache-Key
Country
Azure-Version
Azure-SlotName
Selected-Fe
Azure-SiteName
X-Xfnlog-Site
X-Cache-Time
X-OCL
X-Upstream-CT
X-Upstream-HT
X-Labrador-Cache-Channel
X-Origin
X-PCL
X-Rule
X-Trace-Id
X-Proxy-Build
X-Upgrade-Enabled
X-Human
X-From
X-Timing-Wait
X-Cache-Grace
X-Backend-TTL
X-Web-Node
X-NewRelic-App-Data
X-CCM
X-Format
X-FC-Vary-Parameters
X-Drupal-Cache-Contexts
X-Www-Served-By
DB-Nickname
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Device-Class
TWC-Privacy
Webcakes-App-Name
X-Varnish-Cache-Hits
Ohc-Cache-HIT
Webcakes-Region
Webcakes-App-Version
TWC-Connection-Speed
X-Origin-Hint
Property-Id
X-EIG-Tracking-Id
X-Generated
X-Site-Version
X-Debug-Cache
X-Backend-Name
X-Cache-Host
X-Upstream-Proxy
X-Hit
X-Goog-Meta-Goog-Reserved-File-Mtime
X-UnsetCookies
X-Locale
X-JoinUs
X-Hosted-By
X-FireWall-Port
Server-Info
X-Device-Type
Release
X-Vgn-Hpd-Reason
X-VCT
Time
X-Ttl
DSUID
X-Varnish-Hits
X-Rendered-As
X-S
X-FW-Version
Now
X-OVcl-Cache
X-OVcl
X-Ua
X-APP-VERSION
X-Real-IP
Hostname
X-NGENIX-Cache
X-Pubstack
OT-Force-Account-Verify
X-HS-Combine-CSS
X-SS-Set-Cookie
ServedBy
Origin-Edge-Control
Access-Control-Request-Headers
Fastcgi-X-Cache-Version
Origin-Cache-Control
X-Redis-Cache
L5d-Success-Class
X-VG-TLSProxy
Cteonnt-Length
X-VG-WebCache
X-DataStream-Cache-Status
Accept-Language
Origin
X-ShardId
X-Alternate-Cache-Key
X-ShopId
X-XRDS-LOCATION
X-FB-TRIP-ID
Fastly-SSL
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-NC
X-Origin-TTL
X-Tb
NtCoent-Length
X-Parent-Response-Time
Machine
X-B3-Spanid
X-Origin-CC
X-CSRF-TOKEN
X-UUID
SRV
X-Cluster-Name
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
X-Tt-Trace-Tag
X-GoCache-CacheStatus
X-Load-Cache
X-Environment-Context
X-COUNTRY
X-L-Path
X-Rocket-Nginx-Bypass
X-No-Session
X-ECACHE
X-ServerID
IBM-Web2-Location
X-URL
X-Soup
X-App-Version
X-GEO
X-Uri
NGX
X-B3-Parentspanid
X-Nginx-Cache
X-Is-Bot
Nel
X-Amzn-Remapped-Content-Length
CF-IPCountry
X-Endurance-Cache-Level
Proxy-Connection
X-Magnolia-Registration
X-CACHE-KEY
ServerName
Akamai-GRN
X-CF-Lambda-Version
X-Developer
X-DPWN-IS-SECURE
X-External-Request-Id
X-PAYTM-SRV-ID
X-Instart-Info
X-G
X-D
X-Detected-As
X-Destination
X-Date
X-Region-Sid
Apple-News-Services-Handled
A
X-Connection-Hash
X-ScT
X-VG-WebServer
X-Twitter-Response-Tags
X-Trv-Group
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-Worker
X-Node-Id
X-Transaction
X-Rojux
X-Rewrite-Enabled
X-S-Cookie
Apple-News-Services-Host
X-SRCache-Key
X-Server-Time
X-Request-UUID
Apple-News-Services-Parsed-Url
Cache-Prefix
Node
Content-Script-Type
Odigeo-Trace-Id
BehaviorPad-Version
Rt-Proxy-Cache
Rendered-Blocks
Content-Style-Type
Mobile-Detection-Method
GEO-REGION-INFO
Fly-Request-Id
Fly-Cache
MD5-Digest
Memcached
X-MServer
Meta-Geo-Continent
T-Server
Viewtype
X-AIR-PT
X-Aed
X-Accel-Expires-Debug
Cross-Origin-Window-Policy
X-Application
X-B-Cookie
X-ARC
Apple-News-Services-Request-Url
X-A-Wwc
X-A-Ccd
X-A
VivaBuild
X-A-Dam
AsisCache
X-A-Dgt
X-A-Dcw
X-CF-Lambda-Fn
Arc-Country
X-Generated-By
Request-Time
Backend-Name
X-Oneagent-Js-Injection
X-UA
X-Dc
X-Mode
Mime-Version
Locale
Request-Country
Request-EU
X-SIPLIST1
X-S-Maxage
X-Trafficlayer-App-Name
We-Hiring
X-Origin-Expires
X-Origin-Date
X-Cdn-Srv
Mail-Subject
X-Cache-Bucket
X-Azure-Ref-OriginShield
X-Cms-Context
X-Release
X-SVT-ORM-RULES
X-Developers
X-Urbn-Site-Id
X-VC-Cache
N-Cache
IsBot
X-Fastly-Cache
X-Urbn-Context-Path
X-Up
X-Azure-Ref
X-SVT-ORM-VERSION
Fastly-Soc-X-Request-Id
X-Hl-Ver
X-Trafficlayer-App-Scope
Section-Io-Cache
X-AWS-Id
X-VWS-Id
User-Cache-Control
X-LJ-Flow-ID
X-Device-Os
X-Core-Mission
X-Clientip
X-Compress-Hint
X-Clara-WADP
X-Backend-Url
X-App-Name
X-Auto-Login
W
Uber-Trace-Id
Thinkindot-Control
True-Client-Country-4JS
X-Backend-Host
X-Distil-CS
X-C
X-Cache-Info
X-Block-Status
X-Bip
X-BBXSRF
X-Cdn-Origin
X-Level-Front-Cache
X-Skip-Cache
X-Sn-Servicetimems
X-Swa-Ws
X-ServiceProvider
X-Service
X-Rebelmouse-Surrogate-Control
X-Reboot
X-Server-IP
X-Thanos
X-Thinkindot-L3
X-Wikidot-Static-Cache
X-CUA
X-Var-Ttl
X-Wikidot-Backend
X-We-Are-Hiring
X-TrackingId
X-VServer
X-WADP-Cache
X-Rebelmouse-Cache-Control
X-RateLimit-Remaining-Second
X-Geo-Header
X-Hnp-Log
X-IN-APIGATEWAY
X-Generation-Time
X-Gen-Mode
X-Edge-Server
X-ElasticPress-Search
X-GDPR
X-IN-APIGATEWAYSSL
Thinkindot-CacheControl-Type
X-Policy
X-Qloud-Router
X-RateLimit-Limit-Second
X-Nginx-Cache-Key
X-Method
X-Location
X-Matched-Rule
X-Distributor
X-Generated-On
Cdn-Host
RNT-Machine
Gh-Request-Id
Thinkindot-CacheControl
Heartbleed
Content-Disposition
L
Pramga
Cdn-Request-Time
RNT-Time
Magicmarker
CDCHOST
Fastly-SIE
Fastly-SWR
Esi-Enabled
Server-Int
Countrycode
AKAMAI
X-Microcachable
X-Request-Time
X-PHP-Host
Cache-Provider
X-Proxy-Upstream
X-Request-Start
X-ProxyCache-Key
X-Reqid
X-Platform-Server
X-ProxyCache-Status
X-MSEdge-Flight
X-User
X-Internal-Host
X-Webstats-RespID
X-GeoIP-City
X-Li-Fabric
X-Li-Pop
X-Request-URI
X-MSEdge-Features
X-LI-UUID
X-LI-Proto
X-Owner
X-Say-Cacheable
HA-Ipaddr
Kp-EeAlive
Pagetype
Ha-Gx-Prefs
Srv
X-Via-CDN
X-WebServer
Served-By
Server-Host
X-BYPASS-REASON
X-CGP
Wxu-Next-Region
Wxu-Next-Hostname
X-Debug-Cache-Expiry
Wxu-Next-Commit
X-B3-SpanId
X-Debug-Cache-Fetch
X-Irp-Debug
X-Servername
Adler-Geo
X-SayCDN-TTL
X-Say-TTL
X-NX-Host
X-Guploader-Uploadid
X-Hash
X-Generated-In
X-Variation
X-Debug-Cache-Store
X-Debug-Cookies
X-Debug-Log
X-Eu-Site
X-Dispatch
X-Proxy-Cache-Status
X-Old-Content-Length
Web-Mar-Node
X-Backend-State
X-Has-Esi
X-Amz-Meta-Cache-Control
Is-Eu
Memory
X-Is-Gdpr
X-Cache-FS-Status
X-Cache-Id
PFcat
X-JWT-State
Platform
X-Epic-Correlation-Id
V-Age
X-Fetched-On
Server-ID
Resin-Trace
X-Dispatcher-Server
X-Info
X-SD-PageType
X-Key
X-Org
SD-X-WS
X-Cdn-Forward
X-NWS-UUID-VERIFY
X-ABtesting
X-FPC
X-Flog
X-Wa
X-Hello
X-Geo
SS
X-Servedbyhost
REQUESTUUID
X-Lb-Id
X-DataStream-Origin-MEX-Latency
XServer
X-DataStream-MidMile-RTT
X-Be
X-Unique-ID
X-Svr
X-Response-By
X-Cache-URL
X-Ratelimit-Limit
X-DC
X-Zipkin-Id
X-RateLimit-Reset
X-Routing-Service
X-Proxied
X-IPS-LoggedIn
Country-Code
X-Instart-Isnd
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-From
X-Nc
X-Cache-Backend
X-VCL-Version
X-CDN-Forward
X-Scheme
X-Page-Type
X-Processor
X-Dynatrace-Js-Agent
X-Datadome
X-NodeID
UCS
CACHE
X-MP-GENERATED-AT
X-Varnish-Beresp-Ttl
Group
X-SRV
X-Oss-Request-Id
X-Pjax-Url
X-Oss-Hash-Crc64ecma
Powered-By-ChinaCache
X-ZONE
X-Logtrace-Id
X-SN
X-Oss-Object-Type
X-Oss-Server-Time
Ajk
PICS-Label
X-Oss-Storage-Class
X-Ruxit-Js-Agent
Cache-Host
X-Server-W
X-Oracle-Dms-Rid
X-Newrelic-Synthetics
ProcessTime
Dynatrace
X-HTML-Minification-Powered-By
Proxy-Firewall
X-FORWARDED-FOR
X-Webkit-Csp
X-Ftr-Request-Id
X-HS-Status
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
Powered-By
X-Tb-Optimization-Total-Bytes-Saved
X-Dynatrace
X-EC-Lua
X-Ms-Version
X-Grey
Ttl
X-Ms-Request-Id
X-Pf-Uncompressing
X-Via-Ucdn
SN
X-Cache-Category-Id
X-Source
X-GRACE
X-Zone
GeoIp-Country-Code
Geoip-City
Geoip-Latitude
X-Ratelimit-Remaining
MIME-Version
Lfy
X-Session-Fingerprint
X-TH-Server
Fastly-Backend-Name
X-APP
X-Varnish-Beresp-TTL
X-LiteSpeed-Cache-Control
X-PF-Uncompressing
X-Cache-Debug
GeoIP-Latitude
GeoIP-Country-Code
GeoIP-City
X-Agile-Age
X-Agile
X-Agile-Id
X-Check-Cacheable
X-NODE
X-Ftr-Cache-Host
GW-Server
X-Sucuri-Id
X-BC
LB
Environment
Cdn
X-Logging-Id
X-Fastly-Country-Code
X-7Graus-Varnish-Cache-Control
X-LAGOON
X-Tt-Trace-Host
X-7Graus-Varnish-XKeys
X-RCS-CacheZone
X-Bc
X-Sedo-Request-Id
X-Gannett-Site-Version
Pics-Label
X-Cache-Miss-From
CF-Cached-On
X-Varnish-Url
X-Aicache-OS
X-Edge
X-Secret
X-PJAX-URL
M-TraceId
X-Sucuri-ID
WWW
WZWS-RAY
X-Ftr-Balancer
X-Ftr-Backend-Server
X-Ftr-Backend
X-CSRF-Token
X-Ftr-Realm
X-Unique-Id
X-Ftr-Dc
On-Server
X-Varnish-Cacheable
X-CDN-Cache
X-Core-Value
Ohc-Response-Time
X-Mid
X-Cache-Tag
Requestid
X-Akamai-SSL-Client-Sid
Cf-Ipcountry
Cdncip
User-Agent
Cdnsip
X-Varnish-Ttl
CDN
X-MCACHE
X-Cache-Ttl
X-Fastly-Backend-Reqs
X-GeoIP-Country-Code
X-UPSTREAM-Address
DataCenter
X-AK-Request-ID
X-Vcl-Version
Amp-Access-Control-Allow-Source-Origin
Inserted-Into-Cache-At
X-Litespeed-Cache-Control
X-Vdms-Version
X-TT-LOGID
X-Sucuri-Cache
X-NGINX-Cache
Lb
X-Swift-Error
X-NU-AKA-ACS-Version
X-DSS
X-Sigma-Backend
SID
X-DB
X-Action
X-DI
URI
Xkeyrz
X-Proxy-Cacherz
X-BE
X-Rocket-Build-Number
X-Sigma
X-Fstrz
X-RSL
X-DW
X-RPS
X-RPM
HostName
Pragrma
RequestUuid
X-Planisys-CDN-TTL
X-Crawler
X-Shopify-Generated-Cart-Token
Host-ID
X-Planisys-CDN-Rules
Who
X-LB-ID
X-Render-Time
X-Planisys-CDN-Cache
X-Correlation-ID
Get-Access-Time
Is-Session-Tracking
X-Page-Impression-Id
X-Via-NSCOPI
X-Fastly-Cache-Hits
X-Flow-Id
Warning
X-Fpc
X-Refresh
X-Zalando-Child-Request-Id
X-WR-MODIFICATION
Server-Id
X-ServedByHost
X-WA
Xkeypdq
X-Nananana
X-Trafficlayer-App-Version
X-FE
FNAC-ModuleRouting
X-SB
X-MID
X-TIME
X-VC
Correlation-Id
X-Cdn-Request-ID
X-Micro-Cache
X-Cf-Powered-By
X-Akamai-ERRuleID
X-LiteSpeed-Tag
TTL
X-Gen-Id
X-Akamai-ERPolicy
X-MiniProfiler-Ids
X-Bug-Bounty
X-ServerName
X-Fe
HitType
X-Request-URL
Processtime
X-ECache
X-Via-SSL
X-Via-Edge
X-Gdpr
V-Cache
Xet-Cookie
X-Dw-Trace-Id
Cneonction
X-Served-From
X-Newrelic-App-Data
RequestId