Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Pragma
Accept-Ranges
Last-Modified
Strict-Transport-Security
X-Content-Type-Options
X-Powered-By
CF-RAY
ETag
Link
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Access-Control-Allow-Origin
Content-Security-Policy
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Served-By
X-Varnish
X-Amz-Cf-Id
Referrer-Policy
X-Request-Id
X-Timer
X-AspNet-Version
CF-Cache-Status
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Runtime
Access-Control-Allow-Credentials
X-Download-Options
X-Drupal-Cache
X-Cacheable
Alt-Svc
X-Generator
Content-Security-Policy-Report-Only
X-Xss-Protection
X-AspNetMvc-Version
Status
Timing-Allow-Origin
X-Check
X-Cache-Status
X-Adblock-Key
X-Iinfo
X-DNS-Prefetch-Control
X-Permitted-Cross-Domain-Policies
X-Content-Security-Policy
Content-Encoding
X-CDN
X-Template
X-Language
X-Turbo-Charged-By
X-Request-ID
Keep-Alive
X-Type
X-Buckets
EagleId
Xkey
X-Backend
X-AH-Environment
X-Via
WPE-Backend
X-Age
X-Pass-Why
Access-Control-Max-Age
X-Server
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Cache-Group
X-Pingback
X-Varnish-Cache
Upgrade
X-Nginx-Cache-Status
X-Server-Powered-By
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Grace
X-Hacker
X-UA-Device
Cf-Railgun
P3p
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-LiteSpeed-Cache
X-Ua-Compatible
X-Proxy-Cache
X-Envoy-Upstream-Service-Time
X-Page-Speed
Request-Context
X-CST
X-Node
X-Device
X-Host
X-Ac
X-Cache-Lookup
Content-Location
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cnection
Surrogate-Control
X-Amz-Version-Id
X-Server-Id
X-WebKit-CSP
X-Rack-Cache
X-Backend-Server
X-Response-Time
X-Rq
X-Px
X-Readtime
X-Application-Context
Pinterest-Generated-By
Allow
X-Cloud-Trace-Context
X-Instart-Request-ID
EagleEye-TraceId
X-Dns-Prefetch-Control
X-OneAgent-JS-Injection
X-Clacks-Overhead
Server-Timing
X-Do-Not-Hack
X-HeyJason
Permitted-Cross-Domain-Policies
X-Url
Request-Id
X-Country
Report-To
Rating
X-TTL
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Country-Code
Charset
X-Varnish-TTL
Edge-Control
X-ESI
X-ORACLE-DMS-ECID
X-Vname
X-PC
X-TtlSet
X-Server-Name
X-Powered-CMS
X-FTR-Request-ID
X-CF-Powered-By
X-DataDome
X-ORACLE-DMS-RID
Feature-Policy
X-Origin-Cache
X-MS-InvokeApp
X-Goog-Hash
X-DynaTrace-JS-Agent
X-Cached
NEL
Public-Key-Pins
X-Recruiting
X-Vhost
X-DynaTrace
X-VARITI-CCR
X-Cdn-Fetch
X-Exp-Id
X-Kinja-Server
X-Exp-Variant
X-Kinja-Revision
X-GoogleNews-Bot
X-Geo-Segment
X-Kinja-Build
X-Kinja
X-F-Cache
X-Version
AR-PoweredBy
AR-ATIME
AR-CACHE
X-Powered-By-Plesk
X-Mod-Pagespeed
X-Upstream-Env
X-Pinterest-Rid
Pinterest-Version
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-T
PB-RID
PB-PID
X-Mobile-Rewrite
Arc-Version
Content-MD5
X-Client-IP
Verso
X-D2id
X-Abt-Application-Version
RTSS
X-N
X-Dispatcher
SPRequestGuid
X-Amz-Rid
X-SharePointHealthScore
X-Cdn
X-GitHub-Request-Id
X-Ruxit-JS-Agent
X-Server-ID
Nginx-Cache
X-Forwarded-Proto
X-Hits
X-Navigation-Version
X-Dw-Request-Base-Id
Paypal-Debug-Id
X-B
X-Upstream
Realpath
X-Pad
X-Grace
X-Varnish-Age
X-TEC-API-ROOT
X-Content-Digest
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Shield-Request-Id
Arr-Disable-Session-Affinity
X-Id
MS-Author-Via
X-Content-Options
X-FastCGI-Cache
X-Cache-Hit
X-Ttl
TCN
X-Logged-In
X-NWS-LOG-UUID
X-Goog-Metageneration
Access-Control-Request-Method
X-Kinsta-Cache
DynaTrace
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
SPRequestDuration
SPIisLatency
S
X-Acc-Meta-Resource-Type
X-XRDS-Location
MRF-Tech
Mrf-Cache-Status
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
X-Trace
X-Origin-Upstream-Status
X-VCache
X-Vcap-Request-Id
X-MSEdge-Ref
X-DIS-Request-ID
X-HW
Cleartype
X-IPLB-Instance
Eomportal-Instance
Surrogate-Key
X-Fastly-Request-ID
X-Country-Code-Real
X-Cache-Rule
X-FTR-Backend
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-DC
X-FTR-Realm
X-Via-JSL
Cache-Status
X-FTR-Cache-Status
X-Frontend
X-Zen-Fury
Service-Worker-Allowed
X-FTR-Expires
X-PressLabs-Stats
X-NF-Request-ID
X-HS-Hub-Id
X-HS-Content-Id
Front-End-Https
X-CACHE-GROUP
X-SS-Set-Cookie
Server-Name
X-Forwarded-For
X-User-Agent
AR-SID
Tracecode
X-Oneagent-Js-Injection
X-Varnish-Backend
X-Request-Received
X-Request-Processing-Time
X-Cache-2
X-Hostname
Fastcgi-Cache
X-Analytics
Host
Rt-Fastcgi-Cache
Backend-Timing
X-Wix-Server-Artifact-Id
X-AOL-HN
Viewport
TP-Cache
Public-Key-Pins-Report-Only
FilterID
TP-L2-Cache
X-Whom
X-Revision
Alternate-Protocol
X-Content-Powered-By
X-FTR-Cache-Host
X-Srv
X-Proxied
X-Rid
X-Middleton-Display
X-Sol
Display
Response
X-Middleton-Response
X-Debug-Info
AMP-Access-Control-Allow-Source-Origin
ServerID
X-AppVersion
X-Activity-Id
X-Az
X-Debug
X-URL
X-Ser
X-Akam-SW-Version
X-Contextid
X-Cached-By
X-Daa-Tunnel
X-Cache-Control
X-Cache-Server
X-Magnolia-Registration
X-WPE-Loopback-Upstream-Addr
X-Mobile
X-Cache-Key
Ar-Sid
HitType
X-RateLimit-Remaining
HitInfo
Server-Info
Accept-Charset
X-B3-Traceid
Refresh
X-Page-Id
Cache-Tag
X-FB-Debug
X-Amz-Meta-S3cmd-Attrs
MicrosoftSharePointTeamServices
X-Instance
X-Framework
AR-Request-ID
X-Varnish-Grace
X-Geo-Country
Retry-After
X-PHP-Backend
X-Content-Security-Policy-Report-Only
X-Varnish-Hostname
X-Cache-Operation
X-Generated-By
X-Signature
X-B-Cache
Host-Header
X-App-Environment
X-Webkit-Csp
X-BCube-Filmed-By
X-TT
Upgrade-Insecure-Requests
X-Newrelic-App-Data
X-Request-Guid
X-LB-Cache
X-Origin-Server
Server-Node
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-XRDS-LOCATION
X-App-Server
X-Tumblr-User
X-Accel-Expires
X-Handled-By
Source
X-Cache-Age
X-Device-Type
X-Platform-Server
Accept-CH
X-Hyper-Cache
X-Akamai-Edgescape
Liferay-Portal
DC
X-Webkit-CSP
X-WA-Info
Powered-By-ChinaCache
X-GUploader-UploadID
X-TT-TIMESTAMP
X-NewRelic-App-Data
X-APP-VERSION
X-Cache-Action
X-Correlation-Id
X-Amzn-Trace-Id
Fastly-Restarts
X-Fastcgi-Cache
X-Node-Name
X-B3-Sampled
X-Drupal-Cache-Tags
X-Port
X-Cluster
Webserver
X-TA-CDN-Provider
X-Varnish-Server
X-ATG-Version
X-Accel-Buffering
NGB
X-Edge-Location
X-Cacheable-TTL
X-S
Filters
X-GeoIP
X-Locale
X-Wix-Request-Id
X-WebKit-CSP-Report-Only
X-Seen-By
Actual-Object-TTL
X-Jobs
ServedBy
X-FW-Static
X-FW-Type
X-Tumblr-Pixel-2
X-Varnish-Hits
X-RequestSource
X-FW-Hash
X-FW-Server
X-Tumblr-Pixel-1
AsisCache
X-Amz-Replication-Status
X-FW-Serve
X-Source
GEO-INFO
X-Region
X-UA
X-Distil-CS
X-Cache-TTL-Remaining
MS-CV
Cache
X-UA-Device-Type
X-RTag
S-Cnection
X-Edge-Cache
X-Edge-Cache-Key
X-Adobe-Loc
X-Wix-Petri-Ex
X-Adobe-Content
X-Servedby
Content-Style-Type
Content-Script-Type
X-Cache-Config
Served-By
X-Cache-Remote
Country
X-Oracle-Dms-Rid
PageSpeed
X-Correlation-ID
X-Vg-Webcache
X-Guploader-Uploadid
HostName
X-Ocache
X-Dynatrace-Js-Agent
X-Sucuri-ID
X-Unique-ID
Datacenter
X-Amz-Server-Side-Encryption
X-TX-ID
X-Drupal-Cache-Contexts
X-Status
X-RateLimit-Limit
X-Varnish-IP
X-GZip
X-Ruxit-Js-Agent
IBM-Web2-Location
Healthy
X-Microcachable
X-UUID
X-Esi
X-Internal-Host
X-DataStream-Cache-Status
X-Ezoic-Cdn
X-Akamai-Transformed
X-Cache-Category-Id
X-Detected-As
X-CCM
X-Rendered-As
X-App-Name
X-RN-RSRV
X-Agile
X-Real-IP
Load-Balancing
X-Vgn-Hpd-Reason
Access-Control-Allow-Method
Machine
Meta-Geo
X-Agile-Id
X-Agile-Age
X-Mode
User-Cache-Control
X-Akamai-Request-ID
X-BYPASS-REASON
X-Is-Bot
X-ProxyCache-Key
X-IP
X-JoinUs
X-Grey
X-ProxyCache-Status
X-Generated
X-ServerID
Mn-Server-Ip
X-OVcl
X-CDN-Forward
X-Time-Microsecs
User-Agent
X-TNCMS
X-Origin
X-Xfnlog-Site
X-OVcl-Cache
X-Backend-Name
X-Instance-Name
X-NGENIX-Cache
X-Loop
X-Debug-Cache
X-Varnish-Cacheable
X-Varnish-Cache-Hits
DB-Nickname
Backend
Cache-Name
Cache-Key
X-Content-Type
X-BB-IP
X-FC-Vary-Parameters
X-Hosted-By
X-Tb
X-Human
X-Upgrade-Enabled
L5d-Success-Class
ServerName
X-ApacheServer
X-PERF
S-Rt
Now
X-OCL
Ohc-File-Size
X-Rocket-Nginx-Bypass
X-PCL
Payment
X-NodeID
X-Viewer-Country
X-RemovedCookies
X-Original-Request
X-Site-Version
Azure-Version
X-ProcessESI
X-NCache
Azure-SlotName
Azure-SiteName
X-Distributor
X-CDN-Cache
Azure-RegionName
Azure-InstanceId
X-Yottaa-Metrics
X-Web-Node
X-Via-Fastly
X-Yottaa-Optimizations
X-EIG-Tracking-Id
X-Zipkin-Id
Webcakes-Region
TWC-GeoIP-LatLong
X-Access
TWC-GeoIP-Country
Webcakes-App-Version
X-Routing-Service
TWC-Connection-Speed
Selected-FE
Webcakes-App-Name
Access-Control-Request-Headers
Property-Id
X-Section
X-LJ-Flow-ID
X-VWS-Id
TWC-Device-Class
X-TWH-CORRELATION-ID
X-Origin-Hint
TWC-Privacy
TWC-Locale-Group
X-Www-Served-By
X-SplitTest
X-AWS-Id
X-Timing-Wait
X-Proxy-Build
X-Proxy
X-Origin-CC
X-Format
X-Amz-Meta-Surrogate-Control
X-Pubstack
Dont-Set-Cookie
X-PC-Key
Xserver
X-PC-Hit
X-PC-AppVer
Ms-Operation-Id
X-Storage
X-Cache-Backend
X-PC-Host
X-Environment-Context
X-Oracle-Dms-Ecid
X-L-Path
X-PC-Date
SRV
X-Transaction
X-Connection-Hash
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Object-Type
X-Twitter-Response-Tags
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
Cteonnt-Length
X-Path-Route
WZWS-RAY
LB
X-Time
X-Webstats-RespID
X-Hit
Edge-Cache-Tag
X-HS-Cache-Config
X-Sucuri-Cache
X-Labrador-Cache-Channel
X-Generation-Time
X-M-Log
X-M-Reqid
X-B3-Spanid
X-Qnm-Cache
X-Cache-HT
X-Optimization
X-Proto
Countrycode
X-Amz-Apigw-Id
X-Amzn-RequestId
X-SERVER-NAME
X-Ah-Environment
Pagespeed
X-V
X-Cache-Ttl
X-Release
X-Newrelic-Synthetics
X-Birta-Cache-Post
X-Birta-Served
X-Real-Ip
X-Meta-Tbi-Cache-Vertical
X-Tumblr-Pixel-3
X-Varnish-Beresp-Status
NnCoection
NODE
X-Varnish-Beresp-Grace
XServer
X-Cache-Enabled
X-MP-GENERATED-AT
X-C
Fastly-SSL
X-Rule
X-EdgeConnect-Cache-Status
NtCoent-Length
X-Cache-NE
Apicache-Store
Apicache-Version
From-Origin
Cache-Hits
X-A-Dam
X-A-Ccd
X-A-Dcw
X-A-Dgt
X-A-Wwc
X-A
Www
Viewtype
VivaBuild
Warning
Web-Mar-Node
X-Accel-Expires-Debug
X-Alternate-Cache-Key
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-D
X-Destination
X-Developer
X-Cache-URL
X-Block-Status
X-Application
X-ARC
X-B-Cookie
X-BB-ID
V-Age
True-Client-Country-4JS
Host-ID
GMS-Ver
Httpd-Identifier
Kp-EeAlive
MD5-Digest
Fly-Request-Id
Fly-Cache
Decoy-Debug-Key
Decoy-Debug-Status
Decoy-Debug-TTL
Ec-Rule-Version
Meta-Geo-Continent
MI-Cache
T-Server
Server-ID
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Thinkindot-Control
Server-Host
Resin-Trace
MI-Cache-Age
Rendered-Blocks
Request-Country
Request-EU
X-Died
X-Dispatcher-Server
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-SRCache-Key
X-Thinkindot-L3
X-Trv-Group
X-Shopify-Stage
X-ShopId
X-Server-Time
X-ServiceProvider
X-Sf
X-ShardId
X-TT-LOGID
X-UE-Client-Country
X-WebServer
X-We-Are-Hiring
X-Wix-Route-ID
X-Worker
Xc-Version
X-Via-SSL
X-Via-Edge
X-Upstream-CT
X-Upstream-HT
X-VG-WebServer
X-Via-CDN
X-Server-By
X-ScT
X-Generated-In
X-Gen-Mode
X-Hl-Ver
X-Hnp-Log
X-Matched-Rule
X-G
X-From
X-DPWN-IS-SECURE
X-Edge-Server
X-Env
X-Fetched-On
X-MI-In-Market
X-NU-AKA-ACS-Version
X-Rewrite-Enabled
X-Response-By
X-Rojux
X-S-Cookie
X-S-Maxage
X-Region-Sid
X-Planisys-CDN-TTL
X-Org
X-PAYTM-SRV-ID
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
Cneonction
X-Date
Cache-Prefix
X-NC
X-Varnish-Beresp-Ttl
Cdn-Host
BehaviorPad-Version
Ws
X-SERVER
Cdn-Request-Time
X-Dc
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Release
Pragrma
X-Amz-Meta-Cache-Control
X-SIPLIST1
Proxy-Connection
X-Atg-Version
X-Fstrz
On-Server
Odigeo-Trace-Id
Origin-Cache-Control
Origin-Edge-Control
X-GeoIP-City
PFcat
Platform
RNT-Time
X-IN-WAF
X-IN-SSL-APIGATEWAY
Uber-Trace-Id
X-Logtrace-Id
X-No-Session
X-Origin-Expires
X-Origin-TTL
X-RCS-CacheZone
X-IN-APIGATEWAY
NGX
RNT-Machine
X-GeoIP-Country-Code
X-Hash
Server-Int
X-Redis-Cache
SN
X-Server-IP
X-Backend-Host
X-Cache-Host
Apple-News-Services-Parsed-Url
X-CS
X-Crawler
X-Origin-Date
X-Cache-CFC
X-Content-Age
Apple-News-Services-Request-Url
Country-Code
Accept-CH-Lifetime
CDCHOST
X-Request-URI
Fastly-Backend-Name
X-Device-Os
X-Cache-Bucket
Apple-News-Services-Handled
Ajk
IsBot
X-Response-Served-From
Apple-News-Services-Host
X-Backend-Url
X-Backend-State
X-VServer
MI-API
Is-Eu
Adler-Geo
X-ElasticPress-Search
X-ServedBy
ProcessTime
X-Nc
X-Fastly-Cache
X-CGP
Time
X-Developers
X-Epic-Correlation-Id
X-FireWall-Port
X-Ckpd-Fst-Backend
X-Clientip
X-HCF
X-Eu-Site
X-F5-Cache
X-Core-Mission
X-Croise-Owner
X-Core-Value
X-Server-Group
Fastly-SWR
Get-Access-Time
Is-Session-Tracking
Fastly-SIE
Cache-Tags
X-VG-TLSProxy
X-Wikidot-Backend
X-Wikidot-Static-Cache
WWW-Authenticate
X-Cdn-Origin
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Sn-Servicetimems
X-Powered-By-ANYU
X-NX-Host
X-Debug-Cookies
X-Debug-Log
X-Forwarded-Host
X-Ver
X-Varnish-HitMiss
X-Reboot
X-Returned-From
X-Returned-From-BeforeDispatch
X-Platform
X-Phone
X-Passed-To-BeforeDispatch
X-Passed-To-DLL
X-Passed-To-PostProcessResponse
X-Returned-From-DLL
X-Returned-From-PostProcessResponse
X-Trace-Id
X-UnsetCookies
X-Up
X-Swa-Ws
X-SVT-ORM-VERSION
X-Cdn-Srv
X-Skip-Cache
X-SVT-ORM-RULES
X-Passed-To
X-Node-Id
HA-Geolat
HA-Geocountry
HA-Geocity
HA-Geolon
HA-Georegion
Ha-Gx-Prefs
X-Backend-TTL
X-Actual-URL
Request-Time
Esi-Enabled
Backend-Name
Content-Disposition
Who
Frame-Options
HA-Cloudapp
AKAMAI
Origin
X-Cache-Expires
X-Cache-FS-Status
HA-Servedtime
X-Cache-Control-Set-By
HA-Host
Heartbleed
HA-Urlpath
X-Cache-ASPX
X-Cache-Srv
HTTPS
HA-Ipaddr
X-Cache-TTL
X-HS-Combine-CSS
X-Refresh
X-GoCache-CacheStatus
X-Stale
X-Location
RequestId
X-Alicdn-Da-Ups-Status
X-Owner
X-Key
X-Var-Ttl
X-Nginx-Cache
X-App-Version
X-From-Cache
Dnion-Transfer-Encoding
X-Ms-Version
X-Ms-Request-Id
X-Ms-Lease-Status
NodeID
X-Ms-Blob-Type
X-CUA
Powered-By
MIME-Version
X-Req
X-P-T
X-Pjax-Url
X-MSEdge-Flight
X-MSEdge-Features
X-Servername
Fastly-Soc-X-Request-Id
X-Geo
We-Hiring
X-Edge-IP
Mail-Subject
X-Csrf-Token
X-Pf-Uncompressing
X-Pc-Hit
X-Pc-Key
X-Pc-Appver
X-Info
Ohc-Response-Time
X-TIME
X-Cdn-Forward
X-B3-TraceId
X-Request-Time
X-NWS-UUID-VERIFY
X-Micro-Cache
X-BBXSRF
Section-Io-Cache
X-Pc-Date
X-GRACE
X-Pc-Host
WP-Super-Cache
X-Page-Type
CF-IPCountry
X-External-Request-Id
X-Cache-Time
X-Litespeed-Cache
Dynatrace
X-WR-MODIFICATION
X-Varnish-Url
PICS-Label
X-CSRF-Token
X-COUNTRY
X-Servedbyhost
Magicmarker
Cdn
X-Varnish-Action
X-DC
X-User
PageType
Mime-Version
Geoip-Latitude
GeoIp-Country-Code
Geoip-City
X-Ua
X-Aicache-OS
X-LiteSpeed-Cache-Control
X-Request-UUID
X-CCM-LastModified
CDN
X-GEO
X-Variation
FastCGI-Cache
X-Varnish-Beresp-TTL
X-Irp-Debug
X-Ibm-Trace
X-Cache-Handler
GW-Server
Pagetype
UCS
Processtime
X-Dynatrace
Arc-Country
Sid
X-Gdpr
Version
X-Fastly-Backend-Reqs
X-GDPR
X-HTML-Minification-Powered-By
CACHE
COMMERCE-SERVER-SOFTWARE
X-Cache-Id
X-Layer
X-FW-Version
X-Varnish-Id
Cartoon
Rt-Proxy-Cache
X-TId
X-Server-W
X-Nananana
X-Nginx-Cache-Key
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Wa
X-CACHE-KEY
X-Bip
X-Thanos
X-Shard
Memcached
X-Load-Cache
GeoIP-City
GeoIP-Latitude
GeoIP-Country-Code
If-Modified-Since
X-BE
X-StackifyID
DataCenter
X-UPSTREAM-Address
Hostname
Node
Memory
X-ServedByHost
X-Ig-Deployment-Stage
X-Varnish-URL
X-Sentry-ID
X-Via-NSCOPI
Lb
X-Secret
X-Varnish-Ttl
RATING
Pics-Label
X-Akamai-Request-ID2
X-Gannett-Site-Version
X-NGINX-Cache
X-Cache-Var-Map
X-Cache-Var
X-Auto-Login
Sta2Tusw
X-FORWARDED-FOR
X-PAGE-TYPE
URI
X-Be
X-Proxy-Server
X-Datadome
X-Gen-Id
Cf-Ipcountry
X-SRV
X-Fastly-Cache-Hits
X-DataStream-MidMile-RTT
Mobile-Detection-Method
X-Tid
X-Cluster-Node
X-DataStream-Origin-MEX-Latency
SD-X-WS
X-Frame-Option
OT-Force-Account-Verify
Srv
X-APP
X-VCT
X-Nf-Srv-Version
X-Ratelimit-Remaining
Fastcgi-X-Cache
Fastcgi-Useragent
Fastcgi-X-Cache-Version
Xet-Cookie
X-ID
X-PJAX-URL
X-WA
X-PF-Uncompressing
X-GZIP
X-Ratelimit-Limit
X-Check-Cacheable
X-EC-Security-Audit
Powered
X-Mrs-Cache
X-Mrs-Cache-Hits
X-Mshield-Cache-Status
Cache-Provider
Group
X-Litespeed-Cache-Control
X-Dw-Trace-Id
V-Cache
X-CacheKey
X-Mrs-Age
X-SB
X-Feature
X-Store
X-B3-SpanId
X-VC
X-Policy
X-CACHE-AGE
Serverid
N-Cache
X-Endurance-Cache-Level
X-Fe
AGE-Hash
X-Bug-Bounty
X-CDN-Pop-IP
X-CDN-Pop
Pramga
X-Akamai-ERRuleID
REQUESTUUID
X-Akamai-ERPolicy
X-Distil-Cs
X-Hail-Hydra
X-RAMCache
X-Ratelimit-Reset
X-RateLimit-Reset
X-ServerName
X-Unique-Id
X-VG-WebCache
X-Public
X-Surge-Debug
X-Cookie
X-Haproxy-Ip
X-Haproxy-Hostname
X-Grace-Duration
X-Request-Start
Requestid
X-Varnish-ID
X-SD-PageType