Threat Level: green Handler on Duty: Manuel Humberto Santander Pelaez

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
CF-RAY
CF-Cache-Status
Link
X-Powered-By
ETag
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Alt-Svc
Access-Control-Allow-Credentials
X-Runtime
X-Xss-Protection
X-Drupal-Cache
X-Adblock-Key
X-Check
Content-Security-Policy-Report-Only
X-Cacheable
X-Generator
X-Cache-Status
X-Permitted-Cross-Domain-Policies
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Template
X-Language
X-Request-ID
X-Iinfo
Status
X-Content-Security-Policy
Content-Encoding
X-AspNetMvc-Version
X-Buckets
X-Kinja-Server-Push
Xkey
Upgrade
P3p
X-Via
Access-Control-Expose-Headers
X-Turbo-Charged-By
Keep-Alive
Access-Control-Max-Age
X-Cache-Group
X-Drupal-Dynamic-Cache
X-Pass-Why
X-Age
EagleId
X-Backend
X-Robots-Tag
X-Envoy-Upstream-Service-Time
X-Amz-Id-2
X-Amz-Request-Id
X-Page-Speed
X-CDN
X-Ua-Compatible
X-Pingback
X-Server-Powered-By
X-AH-Environment
X-Proxy-Cache
X-Hacker
X-UA-Device
X-Server
Request-Context
X-Nginx-Cache-Status
Grace
X-Swift-SaveTime
X-Swift-CacheTime
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-Cdn
X-LiteSpeed-Cache
Cf-Railgun
X-Amz-Version-Id
X-Server-Id
X-WebKit-CSP
Feature-Policy
Server-Timing
X-Device
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
X-Rq
X-Ac
X-Cnection
X-Cloud-Trace-Context
Report-To
X-Host
X-Response-Time
EagleEye-TraceId
X-Node
X-Backend-Server
Content-Location
Request-Id
X-Origin-Cache
X-Readtime
X-Vhost
X-Application-Context
X-Cache-Lookup
X-Dns-Prefetch-Control
X-ORACLE-DMS-ECID
X-Dispatcher
NEL
X-Origin-Upstream-Status
X-ORACLE-DMS-RID
X-Rack-Cache
X-Ruxit-JS-Agent
Surrogate-Control
X-DataDome
Allow
X-HW
Rating
X-Country-Code
X-FTR-Request-ID
X-Country
X-Clacks-Overhead
X-Url
X-TTL
X-DynaTrace
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Instart-Request-ID
Fusion-Template-Id
Fusion-Component-Id
Fusion-Content-Id
Fusion-Content-Source
Fusion-Source
X-Goog-Hash
X-MS-InvokeApp
X-Varnish-TTL
X-TtlSet
X-Vname
X-PC
Verso
RTSS
X-Aspnetmvc-Version
X-CST
X-Powered-By-Plesk
Public-Key-Pins
X-Px
Edge-Control
X-Recruiting
X-VARITI-CCR
X-Mod-Pagespeed
Pinterest-Generated-By
X-Sol
X-Middleton-Response
X-Middleton-Display
Response
Display
Service-Worker-Allowed
X-D2id
X-Kinja-Server
X-GoogleNews-Bot
X-Use-Magma
X-Kinja-Build
X-Exp-Variant
X-Exp-Id
X-Cdn-Fetch
X-Kinja
X-Kinja-Revision
Accept-CH
X-Ah-Environment
X-Vcap-Request-Id
X-Version
SPRequestGuid
X-SharePointHealthScore
X-B3-TraceId
X-Akam-SW-Version
MS-Author-Via
TCN
X-Navigation-Version
X-Abt-Application-Version
X-GitHub-Request-Id
X-RateLimit-Remaining
X-Powered-CMS
SPIisLatency
SPRequestDuration
X-Shard
X-Server-Name
X-Upstream
AR-ATIME
Ar-Sid
Accept-Ch-Lifetime
AR-CACHE
AR-PoweredBy
X-ESI
Charset
X-Amz-Server-Side-Encryption
Fastly-Restarts
X-Forwarded-Proto
X-XRDS-Location
X-Trace
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Amz-Rid
Nginx-Cache
Realpath
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Debug
Front-End-Https
AR-Request-ID
X-Cached
X-Ezoic-Cdn
X-Shield-Request-Id
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-NF-Request-ID
X-Goog-Generation
X-Goog-Metageneration
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
X-MSEdge-Ref
Access-Control-Request-Method
Pagespeed
Arr-Disable-Session-Affinity
X-FTR-Cache-Status
X-Country-Code-Real
X-FTR-Expires
Paypal-Debug-Id
Content-MD5
X-Id
ServerID
DynaTrace
X-FTR-Realm
X-FTR-DC
MicrosoftSharePointTeamServices
X-FTR-Balancer
X-FTR-Backend
X-FTR-Backend-Server
X-Goog-Storage-Class
X-VCache
X-T
X-Amz-Meta-S3cmd-Attrs
X-Fastly-Request-ID
S
X-Via-JSL
X-Client-IP
X-Varnish-Age
X-Content-Type
X-Hits
X-Vcache
X-Dw-Request-Base-Id
X-DynaTrace-JS-Agent
X-Amzn-Trace-Id
X-Correlation-Id
X-FastCGI-Cache
X-Grace
X-Accel-Expires
Fastcgi-Cache
X-RateLimit-Limit
X-Ser
X-SERVER
X-Frontend
X-Content-Digest
Powered
X-FTR-Cache-Host
X-N
Arc-Version
PB-PID
PB-RID
X-Mobile-Rewrite
X-DIS-Request-ID
AMP-Access-Control-Allow-Source-Origin
Server-Name
X-Logged-In
X-Forwarded-For
X-B3-Traceid
X-HS-Content-Id
X-HS-Hub-Id
X-B3-Sampled
Edge-Cache-Tag
TP-L2-Cache
TP-Cache
X-GUploader-UploadID
X-Microsite
X-Request-Handler-Origin-Region
X-Zen-Fury
X-Request-Received
X-Request-Processing-Time
X-Cache-Age
X-Type
X-User-Agent
X-Activity-Id
X-Rid
X-Kinsta-Cache
X-IPLB-Instance
X-AppVersion
X-Analytics
Backend-Timing
X-Az
X-Fastcgi-Cache
X-Revision
X-LB-Cache
FilterID
Healthy
X-Whom
X-Node-Name
Pinterest-Version
X-Esi
X-Time
Accept-Ch
X-Pinterest-Rid
Retry-After
X-Srv
X-Cache-Hit
X-F-Cache
X-NWS-LOG-UUID
Accept-Charset
X-Cache-2
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Alternate-Protocol
Server-Node
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Cache-Rule
Cache-Status
X-AOL-HN
X-Content-Options
X-Content-Powered-By
Surrogate-Key
X-Akamai-Edgescape
Refresh
DC
X-Hp-Webp
VIX-Pulpo-Upstream-Status
X-Content-Security-Policy-Report-Only
X-Debug-Info
VIX-Pulpo-Node
X-Server-ID
X-Forwarded-Host
X-Instance
Access-Control-Allow-Method
X-Tumblr-Pixel
X-Jobs
X-Tumblr-Pixel-0
X-Tumblr-User
X-Page-Id
X-FW-Type
X-Varnish-Grace
X-FW-Hash
X-Framework
X-FW-Serve
X-PHP-Backend
X-FW-Static
X-FW-Server
X-Acc-Meta-Resource-Type
X-App-Environment
Cache-Tag
Source
X-Request-Guid
X-B
MS-CV
X-Cluster
Frame-Options
X-FB-Debug
X-TA-CDN-Provider
X-Erf-Bev-Bev
X-App-Server
X-Erf-Bev-Bev-Is-Generated
Fastcgi-Useragent
Tracecode
Host
X-Hostname
X-Cache-Key
X-Cache-Operation
Actual-Object-TTL
Cleartype
X-Mobile-URL
Accept-CH-Lifetime
X-Signature
X-B-Cache
X-Cached-By
X-Seen-By
X-Geo-Country
X-BCube-Filmed-By
X-Cache-Control
X-Host-Name
X-Varnish-Backend
X-Amz-Replication-Status
X-Cache-TTL
X-TT
X-Pad
X-Mobile
Upgrade-Insecure-Requests
X-Response-Served-From
X-Git-Hash
NGB
X-Adobe-Content
X-Adobe-Loc
Liferay-Portal
Payment
X-TT-TIMESTAMP
Filters
Cache-Tv-Group
WPE-Backend
X-ProcessESI
X-RemovedCookies
Eomportal-Instance
X-WebKit-CSP-Report-Only
X-Status
X-Tumblr-Pixel-1
X-TX-ID
X-Tumblr-Pixel-2
X-RTag
X-Handled-By
X-ATG-Version
From-Origin
Ms-Operation-Id
Webserver
X-Cacheable-TTL
X-Cache-Remote
X-GeoIP
X-FW-Dynamic
GEO-INFO
X-RequestSource
X-Drupal-Cache-Tags
X-UA-Device-Type
X-Cache-TTL-Remaining
X-WA-Info
X-Origin-Server
X-Ratelimit-Reset
NR-ENABLED
X-Content-Age
X-Cache-Action
Xserver
X-Daa-Tunnel
X-Webkit-CSP
X-Edge-Location
X-Storage
X-PressLabs-Stats
Viewport
Datacenter
X-EdgeConnect-Cache-Status
X-Varnish-Hostname
Version
X-Hyper-Cache
X-Accel-Buffering
X-Wix-Request-Id
X-Contextid
X-CF-Powered-By
X-Region
X-Presslabs-Stats
X-DataStream-Cache-Status
Cache
X-Upstream-Proxy
Host-Header
PageSpeed
X-Akamai-Transformed
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-ES-SERVER
Ohc-File-Size
X-Path-Route
X-Cache-Var-Map
Meta-Geo
Load-Balancing
X-RN-RSRV
X-Cache-Var
X-IP
X-Varnish-Server
S-Cnection
X-Cache-NE
X-HS-Cache-Config
Cache-Tags
Cache-Name
X-Upgrade-Enabled
X-NCache
X-Loop
X-Cache-Enabled
X-Access
X-Section
X-Akamai-Request-ID2
DB-Nickname
Cache-Hits
X-Viewer-Country
X-Akamai-Request-ID
X-Labrador-Cache-Channel
X-Via-Fastly
X-Cache-Config
X-Tumblr-Pixel-3
X-Proto
Rt-Fastcgi-Cache
X-PERF
X-CS
X-Ua
X-Proxy
Decoy-Debug-Key
X-Cache-Server
X-Time-Microsecs
Vix-Hermes-Req-Id
Decoy-Debug-TTL
Decoy-Debug-Status
X-TNCMS
X-Origin
Ec-Rule-Version
X-From
X-Origin-Response-Time
X-Cache-Time
X-ApacheServer
Azure-SiteName
Azure-SlotName
TWC-Connection-Speed
Webcakes-App-Name
Azure-InstanceId
TWC-Privacy
TWC-Locale-Group
Webcakes-App-Version
TWC-GeoIP-LatLong
Azure-RegionName
TWC-GeoIP-Country
Webcakes-Region
TWC-Device-Class
X-Cache-Host
Mn-Server-Ip
X-UnsetCookies
X-Trace-Id
X-FC-Vary-Parameters
X-R9-Blue-Green-Version
X-Timing-Wait
X-Upstream-CT
X-Upstream-HT
X-Xfnlog-Site
X-Web-Node
Property-Id
X-Varnish-Cache-Hits
S-Rt
X-Rule
X-Proxy-Build
X-EIG-Tracking-Id
Azure-Version
X-OCL
X-Backend-TTL
Selected-Fe
X-JoinUs
X-Hit
X-Cache-Grace
X-Format
X-Cluster-Node
Cache-Key
X-PCL
X-CCM
X-Origin-Hint
Country
X-Generated
X-Drupal-Cache-Contexts
X-Www-Served-By
X-Varnish-Hits
X-S
X-Locale
X-Human
X-Debug-Cache
X-FireWall-Port
X-Site-Version
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Backend-Name
X-FW-Version
Server-Info
X-Hosted-By
X-Device-Type
Now
X-VCT
X-Rendered-As
Release
DSUID
X-NewRelic-App-Data
Ohc-Cache-HIT
Time
OT-Force-Account-Verify
X-APP-VERSION
X-Element-Page-Cache
SRV
X-Vgn-Hpd-Reason
Hostname
X-OVcl-Cache
X-OVcl
Cteonnt-Length
X-VG-TLSProxy
X-Real-IP
ServedBy
X-Redis-Cache
Fastcgi-X-Cache-Version
X-Litespeed-Cache
X-Pubstack
X-VG-WebCache
Origin-Cache-Control
Access-Control-Request-Headers
Origin-Edge-Control
X-B3-Spanid
X-CSRF-TOKEN
X-FB-TRIP-ID
X-Alternate-Cache-Key
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
Accept-Language
X-ShardId
X-Shopify-Stage
X-ShopId
Origin
L5d-Success-Class
X-Tb
X-NC
X-GEO
Machine
X-SS-Set-Cookie
X-NGENIX-Cache
Fastly-SSL
X-HS-Combine-CSS
NtCoent-Length
X-Cluster-Name
X-No-Session
X-Environment-Context
X-Tt-Trace-Tag
X-L-Path
X-UUID
X-Nginx-Cache
X-Origin-CC
X-Parent-Response-Time
X-Origin-TTL
X-B3-Parentspanid
X-Load-Cache
X-ECACHE
X-GoCache-CacheStatus
IBM-Web2-Location
X-Rocket-Nginx-Bypass
X-AWS-Id
X-LJ-Flow-ID
X-ServerID
X-Mode
X-VWS-Id
X-App-Version
X-Amzn-Remapped-Content-Length
Odigeo-Trace-Id
X-Generated-By
X-Endurance-Cache-Level
X-Magnolia-Registration
X-Uri
X-Soup
X-DataStream-MidMile-RTT
Nel
X-DataStream-Origin-MEX-Latency
Akamai-GRN
We-Hiring
NGX
Mail-Subject
X-Is-Bot
X-XRDS-LOCATION
X-Request-Time
CF-IPCountry
X-CACHE-KEY
Apple-News-Services-Host
Cache-Prefix
Mobile-Detection-Method
Rendered-Blocks
Node
Rt-Proxy-Cache
A
X-A-Ccd
X-A
VivaBuild
T-Server
Viewtype
X-Node-Id
Cdn-Host
Fly-Cache
BehaviorPad-Version
GEO-REGION-INFO
Arc-Country
AsisCache
Content-Style-Type
X-MServer
Fly-Request-Id
Proxy-Connection
Request-Time
Meta-Geo-Continent
Cross-Origin-Window-Policy
Apple-News-Services-Request-Url
Memcached
Cdn-Request-Time
Content-Script-Type
MD5-Digest
Apple-News-Services-Parsed-Url
X-CF-Lambda-Version
X-Region-Sid
X-PAYTM-SRV-ID
X-Request-UUID
X-Rewrite-Enabled
X-Rojux
X-Instart-Info
X-G
X-Developer
X-Detected-As
X-A-Dam
X-Edge-Server
X-External-Request-Id
X-S-Cookie
X-S-Maxage
X-Vtex-Processado-Em
X-VG-WebServer
X-Vtex-Remote-Cache
X-Worker
Xc-Version
X-Twitter-Response-Tags
X-Trv-Group
X-ScT
X-Server-Time
X-SRCache-Key
X-Transaction
X-Destination
X-DPWN-IS-SECURE
X-Application
X-ARC
X-Date
X-CF-Lambda-Fn
X-AIR-PT
X-Aed
X-A-Dcw
X-A-Dgt
X-A-Wwc
X-Accel-Expires-Debug
Apple-News-Services-Handled
X-B-Cookie
X-Connection-Hash
X-D
ServerName
X-Oneagent-Js-Injection
Mime-Version
Backend-Name
X-Distributor
X-SVT-ORM-VERSION
X-Developers
X-Urbn-Site-Id
IsBot
Locale
X-VC-Cache
X-SVT-ORM-RULES
X-Urbn-Context-Path
X-Up
X-SIPLIST1
N-Cache
X-Release
X-Cdn-Srv
X-Origin-Expires
X-Fastly-Cache
X-Origin-Date
X-Cache-Bucket
Fastly-Soc-X-Request-Id
Request-EU
X-Hl-Ver
Request-Country
X-Azure-Ref
X-Cms-Context
Section-Io-Cache
X-Azure-Ref-OriginShield
X-Tec-Api-Origin
Uber-Trace-Id
User-Cache-Control
X-Tec-Api-Root
X-Tec-Api-Version
X-Geo-Header
X-Generation-Time
Server-Int
Server-ID
X-GDPR
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-Generated-On
Thinkindot-Control
V-Age
X-Gen-Mode
True-Client-Country-4JS
X-Hnp-Log
X-LI-UUID
X-LI-Proto
X-Location
X-Matched-Rule
Platform
X-Li-Pop
X-Level-Front-Cache
X-IN-APIGATEWAY
W
X-IN-APIGATEWAYSSL
RNT-Time
RNT-Machine
X-Hello
X-Epic-Correlation-Id
X-Bip
X-Block-Status
X-Compress-Hint
X-BBXSRF
X-Backend-Url
X-C
X-Clientip
X-Cache-Info
X-Cdn-Origin
X-Cache-Id
X-Cache-FS-Status
X-Clara-WADP
X-Core-Mission
X-Backend-Host
X-Distil-CS
X-Via-CDN
X-ElasticPress-Search
X-Method
X-Fetched-On
X-ABtesting
X-Device-Os
X-CUA
X-Auto-Login
X-App-Name
X-Amz-Meta-Cache-Control
X-Flog
X-Li-Fabric
Esi-Enabled
Countrycode
X-Thanos
X-Thinkindot-L3
X-Sn-Servicetimems
Fastly-SIE
Gh-Request-Id
X-ServiceProvider
X-Nginx-Cache-Key
X-Skip-Cache
Content-Disposition
X-TrackingId
X-Wikidot-Backend
X-Wikidot-Static-Cache
Adler-Geo
AKAMAI
X-WebServer
X-We-Are-Hiring
CDCHOST
X-Variation
X-VServer
X-WADP-Cache
X-Request-URI
Fastly-SWR
X-Reboot
X-Request-Start
L
Is-Eu
X-Rebelmouse-Surrogate-Control
X-RateLimit-Remaining-Second
X-Rebelmouse-Cache-Control
X-Policy
X-RateLimit-Limit-Second
X-Old-Content-Length
X-Platform-Server
X-Org
Magicmarker
X-Owner
X-PHP-Host
X-BYPASS-REASON
X-ProxyCache-Status
X-ProxyCache-Key
X-Microcachable
X-Oracle-Dms-Rid
X-Webstats-RespID
X-CGP
X-Debug-Cache-Expiry
X-Internal-Host
X-Irp-Debug
X-Qloud-Router
X-Proxy-Upstream
X-User
X-Proxy-Cache-Status
X-Debug-Log
X-SD-PageType
X-Server-IP
X-Guploader-Uploadid
X-SayCDN-TTL
X-Say-TTL
X-Say-Cacheable
X-Reqid
X-Generated-In
X-Servername
X-Eu-Site
X-Debug-Cookies
X-Swa-Ws
X-Debug-Cache-Store
X-B3-SpanId
X-Dispatch
X-GeoIP-City
X-Hash
X-Dispatcher-Server
X-Debug-Cache-Fetch
X-NX-Host
SS
Server-Host
Web-Mar-Node
Wxu-Next-Commit
Wxu-Next-Hostname
Heartbleed
SD-X-WS
Ha-Gx-Prefs
HA-Ipaddr
Kp-EeAlive
Pagetype
Pramga
Wxu-Next-Region
Served-By
X-Backend-State
X-Dc
X-DC
Resin-Trace
X-Service
X-MSEdge-Flight
Memory
PFcat
X-Var-Ttl
X-MSEdge-Features
X-Key
X-Zipkin-Id
X-Cdn-Forward
X-Routing-Service
X-Proxied
X-Is-Gdpr
X-FPC
X-COUNTRY
X-Response-By
X-Unique-ID
Cache-Provider
X-Wa
X-Has-Esi
X-JWT-State
X-UA
X-IPS-LoggedIn
Srv
Cache-Cookie-Set-Lfrom
REQUESTUUID
X-Servedbyhost
Country-Code
X-URL
X-Ttl
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-From
X-NWS-UUID-VERIFY
X-RateLimit-Reset
X-Page-Type
X-Info
X-Lb-Id
X-MP-GENERATED-AT
UCS
X-Nc
X-Be
X-Geo
X-Cache-URL
X-Cache-Backend
X-VCL-Version
X-Dynatrace-Js-Agent
Powered-By-ChinaCache
X-Ratelimit-Limit
X-Svr
X-Datadome
Ajk
ProcessTime
X-CDN-Forward
X-Instart-Isnd
X-Logtrace-Id
X-Processor
X-HTML-Minification-Powered-By
CACHE
X-Oss-Request-Id
X-Oss-Object-Type
X-Oss-Storage-Class
X-Varnish-Beresp-Ttl
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
X-HS-Status
Proxy-Firewall
X-Scheme
X-Trafficlayer-App-Name
X-SRV
XServer
X-Trafficlayer-App-Scope
X-Pjax-Url
X-SN
PICS-Label
X-NodeID
X-Tb-Optimization-Total-Bytes-Saved
X-Ruxit-Js-Agent
X-Cache-Category-Id
X-ZONE
SN
Dynatrace
X-Grey
Powered-By
X-Zone
X-Webkit-Csp
Group
X-Ftr-Request-Id
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-Dynatrace
X-Server-W
Fastly-Backend-Name
X-TH-Server
X-Pf-Uncompressing
Cache-Host
Ttl
X-GRACE
X-Source
GeoIP-City
GeoIP-Country-Code
GeoIP-Latitude
X-Newrelic-Synthetics
X-LiteSpeed-Cache-Control
MIME-Version
X-EC-Lua
X-Ms-Request-Id
X-Ms-Version
X-FORWARDED-FOR
X-Via-Ucdn
LB
X-RCS-CacheZone
X-APP
Geoip-Latitude
X-LAGOON
GeoIp-Country-Code
X-Bc
Geoip-City
X-PF-Uncompressing
GW-Server
X-Check-Cacheable
X-Varnish-Beresp-TTL
X-NODE
Cdn
X-Fastly-Country-Code
X-Gannett-Site-Version
X-Varnish-Url
X-Sucuri-Id
X-Ftr-Cache-Host
Environment
X-Secret
Lfy
X-Cache-Ttl
X-Session-Fingerprint
CF-Cached-On
X-Agile
X-Agile-Age
X-Cache-Debug
X-Tt-Trace-Host
WZWS-RAY
X-Agile-Id
X-Ratelimit-Remaining
X-BC
Pics-Label
X-Edge
X-CDN-Cache
X-Aicache-OS
X-PJAX-URL
X-Varnish-Cacheable
On-Server
X-SERVER-NAME
Requestid
X-Logging-Id
X-7Graus-Varnish-XKeys
User-Agent
X-Akamai-SSL-Client-Sid
WWW
X-GeoIP-Country-Code
X-7Graus-Varnish-Cache-Control
X-Ftr-Backend-Server
X-Ftr-Dc
X-Ftr-Realm
X-Ftr-Backend
X-Ftr-Balancer
X-Sedo-Request-Id
X-Mid
X-Cache-Miss-From
Inserted-Into-Cache-At
M-TraceId
Ohc-Response-Time
DataCenter
Cf-Ipcountry
X-Vcl-Version
X-Varnish-Ttl
SID
X-MCACHE
X-CSRF-Token
X-Cache-Tag
X-NU-AKA-ACS-Version
X-BE
X-Fastly-Backend-Reqs
Amp-Access-Control-Allow-Source-Origin
X-Crawler
X-Sucuri-ID
Who
X-RPM
X-RSL
X-DI
X-Render-Time
X-DSS
X-DW
X-UPSTREAM-Address
X-DB
X-RPS
X-Litespeed-Cache-Control
X-Action
X-Core-Value
X-Unique-Id
Lb
Cdncip
Cdnsip
X-AK-Request-ID
X-LB-ID
Xkeyrz
URI
X-Proxy-Cacherz
X-NGINX-Cache
HostName
X-Vdms-Version
CDN
Host-ID
X-Sucuri-Cache
RequestUuid
X-WR-MODIFICATION
X-FE
Warning
Is-Session-Tracking
X-Micro-Cache
Get-Access-Time
X-TT-LOGID
X-Correlation-ID
X-Via-SSL
Xkeypdq
X-WA
X-Nananana
X-ServedByHost
X-Via-Edge
X-Flow-Id
X-Sigma-Backend
X-Fastly-Cache-Hits
X-Sigma
X-Fpc
X-Rocket-Build-Number
X-Fstrz
X-Page-Impression-Id
X-Served-From
X-Zalando-Child-Request-Id
X-Swift-Error
X-Newrelic-App-Data
X-Planisys-CDN-TTL
X-Shopify-Generated-Cart-Token
X-Planisys-CDN-Rules
X-LiteSpeed-Tag
Pragrma
X-Planisys-CDN-Cache
X-TIME
Correlation-Id
FNAC-ModuleRouting
X-VC
X-Cdn-Request-ID
Cneonction
X-MID
X-SB
X-Cf-Powered-By
X-Gen-Id
X-Fe
Server-Id
X-Request-URL
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
HitType
X-Dw-Trace-Id
X-Gdpr
V-Cache
Xet-Cookie
X-MiniProfiler-Ids
X-ServerName
X-ECache
X-Bug-Bounty
RequestId
Processtime