Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Pragma
Last-Modified
Accept-Ranges
Strict-Transport-Security
X-Content-Type-Options
X-Powered-By
CF-RAY
ETag
Link
Expect-CT
Via
X-XSS-Protection
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-UA-Compatible
P3P
X-Cache-Hits
X-Served-By
X-Varnish
X-Amz-Cf-Id
X-Xss-Protection
Referrer-Policy
X-Request-Id
X-Timer
X-AspNet-Version
CF-Cache-Status
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Runtime
Access-Control-Allow-Credentials
X-Download-Options
X-Drupal-Cache
X-Cacheable
Content-Security-Policy-Report-Only
X-Generator
Alt-Svc
Status
X-AspNetMvc-Version
X-Cache-Status
X-DNS-Prefetch-Control
X-Check
X-Iinfo
X-FRAME-OPTIONS
X-Adblock-Key
X-CDN
Timing-Allow-Origin
X-Content-Security-Policy
X-Permitted-Cross-Domain-Policies
X-Turbo-Charged-By
P3p
Content-Encoding
X-Template
X-Language
Keep-Alive
X-Type
X-AH-Environment
CF-Ray
X-Via
X-Request-ID
X-Cache-Group
X-Backend
WPE-Backend
X-Pass-Why
X-Age
X-Buckets
X-Server
X-Nginx-Cache-Status
Access-Control-Max-Age
X-Server-Powered-By
X-Pingback
Xkey
X-Varnish-Cache
Grace
X-Drupal-Dynamic-Cache
Upgrade
Access-Control-Expose-Headers
X-Hacker
X-UA-Device
X-Amz-Request-Id
X-Page-Speed
Cf-Railgun
X-Amz-Id-2
X-Proxy-Cache
X-Robots-Tag
EagleId
X-Envoy-Upstream-Service-Time
X-LiteSpeed-Cache
Request-Context
X-Node
X-Ac
X-Device
X-Swift-CacheTime
X-Swift-SaveTime
X-Cnection
X-Host
Ali-Swift-Global-Savetime
Content-Location
X-Amz-Version-Id
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-WebKit-CSP
X-Server-Id
Surrogate-Control
X-Backend-Server
X-Cache-Lookup
X-OneAgent-JS-Injection
X-Rack-Cache
X-Response-Time
X-Px
X-Instart-Request-ID
Request-Id
Server-Timing
X-Readtime
X-Rq
X-CST
X-Clacks-Overhead
Permitted-Cross-Domain-Policies
X-HeyJason
X-Do-Not-Hack
Pinterest-Generated-By
X-Ua-Compatible
X-Url
EagleEye-TraceId
Edge-Control
X-Cloud-Trace-Context
X-Application-Context
X-Country
X-MS-InvokeApp
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Report-To
X-Server-Name
X-DynaTrace-JS-Agent
Charset
SPRequestGuid
X-Country-Code
Allow
X-ESI
X-SharePointHealthScore
X-DataDome
Rating
X-Varnish-TTL
X-Ruxit-JS-Agent
X-TtlSet
X-Vname
X-PC
X-Cached
X-Powered-CMS
X-TTL
X-Powered-By-Plesk
X-Recruiting
X-CF-Powered-By
X-DynaTrace
X-FTR-Request-ID
X-Vhost
NEL
X-D2id
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
Public-Key-Pins
X-Pinterest-Rid
X-Upstream-Env
Pinterest-Version
X-Exp-Id
X-Cdn-Fetch
X-F-Cache
X-Exp-Variant
X-Geo-Segment
X-Kinja-Server
X-Kinja-Build
X-Kinja-Revision
X-Kinja
X-Version
X-VARITI-CCR
X-N
X-T
Cartoon
SPRequestDuration
SPIisLatency
X-GoogleNews-Bot
X-Dw-Request-Base-Id
X-Mod-Pagespeed
MS-Author-Via
X-Abt-Application-Version
Content-MD5
RTSS
Nginx-Cache
Feature-Policy
Verso
X-GitHub-Request-Id
X-Dispatcher
X-Navigation-Version
MicrosoftSharePointTeamServices
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Goog-Hash
AR-CACHE
AR-ATIME
AR-PoweredBy
X-Client-IP
X-Amz-Rid
X-Hits
X-Forwarded-Proto
X-Shield-Request-Id
Realpath
X-Cdn
X-Ttl
X-Origin-Cache
X-Trace
Paypal-Debug-Id
X-Server-ID
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Content-Options
X-Id
X-Content-Digest
X-Zen-Fury
X-Kinsta-Cache
X-Grace
DynaTrace
TCN
X-B
Arr-Disable-Session-Affinity
AR-SID
Alternate-Protocol
X-Varnish-Age
X-Cache-Key
X-Sol
Fastcgi-Cache
X-Upstream
MRF-Tech
Mrf-Cache-Status
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
Access-Control-Request-Method
X-Ser
Display
X-Middleton-Display
X-FastCGI-Cache
X-Pad
X-Fastly-Request-ID
X-Acc-Meta-Resource-Type
PB-PID
PB-RID
X-Mobile-Rewrite
X-Nf-Srv-Version
X-NF-Request-ID
X-Via-JSL
X-DIS-Request-ID
Response
X-Middleton-Response
X-User-Agent
X-Vcap-Request-Id
Pagespeed
X-Forwarded-For
X-MSEdge-Ref
Front-End-Https
Rt-Fastcgi-Cache
Eomportal-Instance
X-Frontend
X-PressLabs-Stats
X-Cache-Rule
X-IPLB-Instance
X-SS-Set-Cookie
Arc-Version
X-Logged-In
X-Cache-Hit
Server-Name
X-VCache
X-Whom
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Storage-Class
X-Hostname
X-XRDS-LOCATION
Host
Tracecode
S
Surrogate-Key
X-FTR-Balancer
X-FTR-Expires
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Backend
X-FTR-DC
X-FTR-Backend-Server
X-FTR-Realm
X-Request-Processing-Time
X-Request-Received
Cache-Status
Backend-Timing
X-Analytics
X-Debug
X-HS-Content-Id
X-Instance
TP-L2-Cache
Refresh
X-AOL-HN
TP-Cache
X-Contextid
X-Magnolia-Registration
X-Proxied
X-Az
X-AppVersion
X-Rid
X-Activity-Id
FilterID
ServerID
Public-Key-Pins-Report-Only
X-Wix-Server-Artifact-Id
X-Srv
X-XRDS-Location
X-UUID
HitType
HitInfo
Server-Info
X-B3-Traceid
X-HW
X-WPE-Loopback-Upstream-Addr
Cleartype
X-Newrelic-App-Data
Liferay-Portal
X-APP-VERSION
X-Content-Security-Policy-Report-Only
X-Varnish-Server
X-Mobile
Service-Worker-Allowed
X-FTR-Cache-Host
AMP-Access-Control-Allow-Source-Origin
X-Varnish-Backend
Served-By
X-Cache-Control
X-Revision
Source
X-Cache-Server
X-Geo-Country
X-Litespeed-Cache
Server-Node
Retry-After
X-TT
X-Amzn-Trace-Id
X-Request-Guid
Host-Header
X-PC-AppVer
X-PC-Hit
X-PC-Key
X-PHP-Backend
X-App-Environment
X-Hail-Hydra
X-BCube-Filmed-By
X-Tumblr-User
X-Tumblr-Pixel
X-Handled-By
X-Origin-Upstream-Status
MS-CV
Accept-Charset
X-Varnish-Hostname
X-NWS-LOG-UUID
X-Device-Type
X-Tumblr-Pixel-0
X-RateLimit-Remaining
X-Origin
X-Correlation-Id
X-Framework
X-Cache-Config
DC
X-Cache-2
X-B-Cache
X-Signature
X-URL
X-Cache-Operation
Edge-Cache-Tag
X-Page-Id
X-HS-Cache-Config
S-Cnection
Powered-By-ChinaCache
X-FB-Debug
X-Origin-Server
Fastly-Restarts
X-Cache-Action
X-TT-TIMESTAMP
X-ATG-Version
X-Sucuri-ID
X-Debug-Info
X-Ocache
Viewport
X-PC-Date
X-PC-Host
Actual-Object-TTL
X-Webkit-Csp
X-B3-Sampled
X-Hyper-Cache
X-WA-Info
X-ADI-VCache
X-Shield-Cache-Expires
NGB
X-Cached-By
X-Content-Powered-By
X-Microcachable
X-Accel-Expires
X-Drupal-Cache-Tags
X-Akam-SW-Version
X-NewRelic-App-Data
X-LB-Cache
Upgrade-Insecure-Requests
AsisCache
SRV
Filters
X-Cache-NE
X-Generated-By
X-App-Server
ServedBy
X-Tumblr-Pixel-2
X-WebKit-CSP-Report-Only
X-FW-Serve
X-Distil-CS
X-Tumblr-Pixel-1
X-FW-Server
X-S
X-RTag
X-Yottaa-Metrics
X-FW-Type
X-Yottaa-Optimizations
X-Internal-Host
X-FW-Hash
X-FW-Static
X-RequestSource
Cache
X-Locale
X-Seen-By
Content-Style-Type
X-Cacheable-TTL
X-GeoIP
Content-Script-Type
X-Wix-Request-Id
X-TX-ID
X-Cluster
X-Accel-Buffering
X-Amz-Server-Side-Encryption
X-Jobs
X-Varnish-Hits
X-Node-Name
From-Origin
X-Geo
X-ServedBy
X-Cache-Age
X-Adobe-Content
X-GUploader-UploadID
X-Varnish-IP
X-Varnish-Grace
X-Varnish-Cache-Hits
X-Adobe-Loc
X-Akamai-Edgescape
X-Sucuri-Cache
X-UA
X-RateLimit-Limit
X-Dns-Prefetch-Control
Datacenter
X-HS-Combine-CSS
X-GZip
X-Platform-Server
X-CDN-Forward
X-Oneagent-Js-Injection
X-Vg-Webcache
X-Cache-TTL-Remaining
X-Edge-Cache
X-Edge-Cache-Key
X-Storage
X-Cache-Remote
Cache-Tag
X-Mode
X-Akamai-Transformed
X-Real-IP
X-Region
X-Drupal-Cache-Contexts
X-Daa-Tunnel
X-Amz-Replication-Status
X-Source
HostName
X-Distributor
X-Kinja-Server-Push
Meta-Geo
X-Detected-As
X-Cache-Var
X-Cache-Var-Map
Load-Balancing
Machine
X-MP-GENERATED-AT
X-Is-Bot
X-RN-RSRV
X-Rendered-As
X-RemovedCookies
X-ProcessESI
X-Path-Route
X-Amz-Apigw-Id
ServerName
X-Amzn-RequestId
X-NCache
X-Agile
Fastly-SSL
X-Agile-Age
X-Agile-Id
Cache-Key
X-CDN-Cache
X-ApacheServer
X-Webstats-RespID
GEO-INFO
X-Upgrade-Enabled
X-BB-IP
X-Cache-Category-Id
X-PERF
X-Time-Microsecs
X-NodeID
Mn-Server-Ip
X-Proxy
X-Grey
X-OCL
X-Akamai-Request-ID
X-TWH-CORRELATION-ID
X-PCL
Backend
X-Cache-HT
Azure-RegionName
Cache-Name
Azure-InstanceId
Azure-SiteName
Azure-Version
X-Cluster-Node
Azure-SlotName
X-Web-Node
X-Amz-Meta-Surrogate-Control
X-EIG-Tracking-Id
X-OVcl
X-OVcl-Cache
X-Proto
X-Pubstack
X-Original-Request
X-Optimization
S-Rt
X-Human
X-Instance-Name
Ohc-File-Size
X-Via-Fastly
X-ServerID
X-FC-Vary-Parameters
X-Viewer-Country
X-Edge-Location
TWC-Connection-Speed
Webcakes-Region
User-Cache-Control
Webcakes-App-Name
TWC-Privacy
TWC-Locale-Group
TWC-GeoIP-Country
TWC-GeoIP-LatLong
X-Access
Webcakes-App-Version
TWC-Device-Class
X-Xfnlog-Site
X-ProxyCache-Status
X-Varnish-Cacheable
Property-Id
X-ProxyCache-Key
X-BYPASS-REASON
X-Port
X-Format
X-IP
X-Hosted-By
X-LJ-Flow-ID
X-Meta-Tbi-Cache-Vertical
X-Origin-Hint
X-Routing-Service
X-Section
X-Birta-Served
X-Www-Served-By
X-Birta-Cache-Post
X-AWS-Id
X-App-Name
X-Generation-Time
X-CCM
X-SplitTest
X-Site-Version
X-Zipkin-Id
X-Debug-Cache
X-CCM-LastModified
X-VWS-Id
L5d-Success-Class
LB
DB-Nickname
X-CLOUD-TRACE-CONTEXT
Country
Healthy
X-Backend-Name
X-Request-Time
X-TNCMS
Cache-Hits
Now
Fastcgi-Useragent
X-JoinUs
Access-Control-Allow-Method
X-Labrador-Cache-Channel
User-Agent
X-Loop
X-Guploader-Uploadid
X-Generated
RATING
X-Timing-Wait
X-Proxy-Build
X-Surge-Debug
Countrycode
Selected-FE
X-Tumblr-Pixel-3
X-Dc
Payment
X-Tb
X-Esi
X-Cache-Bucket
Ec-Rule-Version
X-Ezoic-Cdn
X-Hit
X-Origin-CC
X-Time
X-Render-Type
X-TA-CDN-Provider
X-Cache-Enabled
X-Oracle-Dms-Rid
WP-Super-Cache
X-Oracle-Dms-Ecid
X-DataStream-Cache-Status
X-Unique-ID
X-Newrelic-Synthetics
X-Feature
X-Real-Ip
X-Nginx-Cache
X-B3-Spanid
Origin-Edge-Control
Origin-Cache-Control
X-Nc
X-Correlation-ID
X-L-Path
X-Environment-Context
X-UA-Device-Type
RequestId
X-Varnish-Beresp-Status
NODE
X-Varnish-Beresp-Grace
X-B3-TraceId
X-NU-AKA-ACS-Version
X-Skip-Cache
X-NGENIX-Cache
X-Be
X-CACHE-AGE
X-Servedby
Access-Control-Request-Headers
Xserver
X-WR-MODIFICATION
X-Status
X-Content-Type
X-ElasticPress-Search
X-Vgn-Hpd-Reason
X-EdgeConnect-Cache-Status
X-Cache-Backend
Webserver
Warning
Time
X-Upstream-CT
Ws
X-Upstream-HT
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
Apple-News-Services-Host
X-A-Dam
MD5-Digest
GMS-Ver
Ajk
Host-ID
Fly-Cache
AKAMAI
Fastcgi-X-Cache-Version
Fastly-Soc-X-Request-Id
X-A
Cache-Prefix
BehaviorPad-Version
Resin-Trace
T-Server
Fastcgi-X-Cache
Fly-Request-Id
Meta-Geo-Continent
Apple-News-Services-Request-Url
Sta2Tusw
X-A-Ccd
Www
VivaBuild
Viewtype
Memcached
X-Destination
X-Rojux
X-Rewrite-Enabled
X-S-Cookie
X-Server-By
X-Server-Time
X-Region-Sid
X-Public
X-PAYTM-SRV-ID
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-SRCache-Key
X-SVT-ORM-RULES
X-Via-Edge
X-Via-CDN
X-We-Are-Hiring
X-Wix-Route-ID
Xc-Version
X-VG-WebServer
X-User
X-SVT-ORM-VERSION
X-Transaction
X-Trv-Group
X-Twitter-Response-Tags
X-No-Session
X-ND-Cache
X-BBXSRF
X-BB-ID
X-Cache-Host
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-B-Cookie
X-ARC
X-A-Dgt
X-A-Wwc
X-Amz-Meta-Cache-Control
X-Application
X-Connection-Hash
X-D
X-Generated-In
X-G
X-Haproxy-Hostname
X-Haproxy-Ip
X-Logtrace-Id
X-From
X-Fastly-Cache
X-Date
X-Developer
X-Died
X-DPWN-IS-SECURE
X-A-Dcw
X-Accel-Expires-Debug
Apicache-Store
Apicache-Version
X-GoCache-CacheStatus
IBM-Web2-Location
X-Webkit-CSP
X-Ruxit-Js-Agent
X-IN-WAF
X-IN-SSL-APIGATEWAY
X-Cache-Id
X-Core-Value
X-Cdn-Origin
X-Cache-Time
X-Cache-Expires
X-IN-APIGATEWAY
Uber-Trace-Id
Release
Origin
Odigeo-Trace-Id
NGX
Rendered-Blocks
Request-Time
UCS
X-CS
Server-Int
V-Age
X-Wikidot-Static-Cache
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Up
X-Phone
X-Request-URI
X-ScT
X-Sn-Servicetimems
X-SIPLIST1
X-Trace-Id
X-Var-Ttl
X-NX-Host
X-F5-Cache
IsBot
X-Debug-Log
X-Wikidot-Backend
X-FireWall-Port
X-Fstrz
X-Frame-Option
X-Forwarded-Host
X-Debug-Cookies
X-Cache-CFC
Fastly-SIE
Fastly-SWR
X-C
X-Backend-TTL
X-Backend-Host
X-Hl-Ver
X-Backend-Url
X-Backend-State
X-Block-Status
CDCHOST
Cache-Cookie-Set-Lfrom
X-Cdn-Srv
X-UE-Client-Country
X-Cache-Debug
X-Bug-Bounty
X-Thinkindot-L3
X-Amz-Meta-S3cmd-Attrs
Content-Disposition
Who
X-Returned-From-PostProcessResponse
Web-Mar-Node
X-Served-From
X-Server-Group
X-TT-LOGID
Decoy-Debug-TTL
X-Returned-From-DLL
X-Returned-From
X-Actual-URL
X-Location
Decoy-Debug-Status
X-Returned-From-BeforeDispatch
X-Auto-Login
X-CGP
X-WebServer
Adler-Geo
X-Passed-To
X-Passed-To-BeforeDispatch
X-Passed-To-PostProcessResponse
X-Passed-To-DLL
X-Gen-Mode
X-VServer
X-MI-In-Market
X-Matched-Rule
X-Hnp-Log
X-Node-Id
X-GeoIP-City
X-GeoIP-Country-Code
X-Eu-Site
X-Epic-Correlation-Id
Cache-Cookie-Set-From
X-Reboot
X-Croise-Owner
Cache-Cookie-Set-Idcheck
Esi-Enabled
X-Content-Age
OT-Force-Account-Verify
X-UnsetCookies
X-Edge-IP
X-Env
Backend-Name
X-Dispatcher-Server
X-V
X-Developers
Cneonction
Decoy-Debug-Key
Ohc-Response-Time
X-Cache-Ttl
HA-Georegion
Ha-Gx-Prefs
On-Server
HA-Geolon
HA-Geocountry
Pragrma
Powered-By
HA-Geolat
X-Via-NSCOPI
HA-Host
Httpd-Identifier
HTTPS
Is-Eu
X-Rocket-Nginx-Bypass
MI-Cache
Heartbleed
HA-Ipaddr
HA-Servedtime
MI-Cache-Age
HA-Urlpath
Pramga
Platform
X-Stale
Proxy-Connection
Fastly-Backend-Name
X-Servername
X-Server-IP
Thinkindot-Control
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
Server-Host
X-ServiceProvider
HA-Cloudapp
HA-Geocity
GW-Server
X-HS-Hub-Id
X-TIME
X-Sorting-Hat-Section
X-Device-Os
X-Hash
X-Worker
X-Origin-Date
X-RCS-CacheZone
X-Varnish-Id
X-Thanos
X-Sorting-Hat-ShopId-Cached
X-Sorting-Hat-ShopId
X-Ver
X-Fetched-On
X-MSEdge-Features
X-Varnish-Beresp-Ttl
X-Origin-Expires
X-Sorting-Hat-PrivacyLevel
X-MSEdge-Flight
X-Varnish-HitMiss
X-Sorting-Hat-FeatureSet
Kp-EeAlive
X-Platform
PFcat
X-Shopify-Stage
X-Clientip
X-Crawler
X-ShopId
REQUESTUUID
X-ShardId
X-Alternate-Cache-Key
X-Response-By
Request-EU
X-HCF
Request-Country
X-Cache-Srv
X-Sorting-Hat-PodId
X-Release
X-S-Maxage
X-Core-Mission
X-Sorting-Hat-PodId-Cached
NtCoent-Length
X-Cache-Control-Set-By
X-Bip
X-Ckpd-Fst-Backend
NnCoection
X-StackifyID
Drupal-Pagecache-Memcache
X-Info
Server-ID
X-Secret
X-Page-Type
X-Cache-URL
MI-API
Country-Code
Mime-Version
X-Svr
X-Gannett-Site-Version
X-Fastcgi-Cache
X-Refresh
X-P-T
X-Req
Cache-Provider
X-Amz-Meta-S3b-Last-Modified
Dnion-Transfer-Encoding
Processtime
X-COUNTRY
X-Pf-Uncompressing
X-Pjax-Url
Version
X-Origin-TTL
X-Cache-ASPX
Accept-Ch
Pagetype
X-Amz-Meta-Sha256
Ar-Sid
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Object-Type
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-EC-Security-Audit
WebServer
X-Csrf-Token
Memory
X-Kong-Upstream-Latency
X-App-Version
X-RateLimit-Limit-Second
X-Kong-Proxy-Latency
X-RateLimit-Remaining-Second
X-Yottaa-Sig
Cteonnt-Length
FSS-Cache
Geoip-Latitude
GeoIp-Country-Code
SN
Geoip-City
X-NC
FSS-Proxy
Arc-Country
X-CSRF-Token
X-Varnish-Url
X-LiteSpeed-Cache-Control
X-From-Cache
Brightspot-Id
X-Irp-Debug
X-Wix-Petri-Ex
Dont-Set-Cookie
X-LB-CacheStatus
X-Ua
X-Rule
PageType
PICS-Label
X-LB-Node
COMMERCE-SERVER-SOFTWARE
X-Cache-Handler
X-Varnish-Beresp-TTL
If-Modified-Since
X-Request-Start
Sid
CF-IPCountry
X-DC
X-Redis-Cache
X-ROOTCache
X-Load-Cache
Cdn
X-Ratelimit-Remaining
MIME-Version
Edgecast
X-Request-UUID
X-SERVER-NAME
X-Cdn-Forward
X-Fastly-Backend-Reqs
PROCESSING-IP
BORDER-IP
X-GRACE
X-Endurance-Cache-Level
X-Varnish-Action
X-Tid
X-Ratelimit-Limit
X-GDPR
X-TId
X-Sf
X-ServedByHost
X-Layer
XServer
X-Servedbyhost
X-Requestid
RNT-Machine
RNT-Time
X-RequestId
X-Atg-Version
X-Dynatrace
Frame-Options
X-Resolver-IP
X-Rocket-Nginx-Serving-Static
X-B3-SpanId
X-Nananana
Powered
X-Cache-TTL
X-Fastly-Cache-Hits
X-BE
Cache-Tags
Cf-Ipcountry
Pics-Label
Amp-Access-Control-Allow-Source-Origin
NodeID
CACHE
CDN
X-DataStream-MidMile-RTT
X-DataStream-Origin-MEX-Latency
X-Owner
X-Key
X-Tec-Api-Root
X-Tec-Api-Origin
Node
X-Tec-Api-Version
Dynatrace
X-Server-W
Mail-Subject
We-Hiring
X-HTML-Minification-Powered-By
X-Gdpr
PageSpeed
Web-Mar-Region
GeoIP-Latitude
X-VG-WebCache
GeoIP-City
X-Shard
GeoIP-Country-Code
X-Varnish-Ttl
X-Dynatrace-Js-Agent
X-Use-Magma
X-Varnish-URL
X-ABtesting
Lfy
X-UPSTREAM-Address
X-Flog
X-Sentry-ID
X-Ms-Blob-Type
X-Ms-Request-Id
X-Ms-Lease-Status
X-GZIP
DataCenter
ProcessTime
Hostname
X-Ms-Version
Accept-CH
X-Powered-By-ANYU
WZWS-RAY
Max-Age
URI
X-CDN-Pop
X-PF-Uncompressing
X-GEO
X-Aicache-OS
X-CDN-Pop-IP
Get-Access-Time
Is-Session-Tracking
X-NWS-UUID-VERIFY
Xet-Cookie
X-NGINX-Cache
X-Dw-Trace-Id
X-Alicdn-Da-Ups-Status
X-VG-TLSProxy
Cdn-Request-Time
X-PJAX-URL
Cdn-Host
X-Edge-Server
X-PAGE-TYPE
X-Mem
X-Trv-Request-Id
X-Check-Cacheable
X-Oa-Upstreams
X-Cookie
X-Unique-Id
Requestid
X-Cache-FS-Status
X-Ms-Lease-State
X-Remote-IP
True-Client-Country-4JS
X-Powered-By-Defense
RequestUuid
X-Varnish-ID
X-Policy
X-Swa-Ws
X-Front
GEO-REGION-INFO
X-DW
Rt-Proxy-Cache
X-Org
X-RPS
X-DSS
X-VID
X-RSL
CF-Cached-On
X-RPM
X-Hello
X-Proxy-Server
X-RAMCache
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Akamai-ERRuleID
X-Akamai-ERPolicy
Magicmarker
WS
SID
X-DB
X-Litespeed-Cache-Control
X-Litespeed-Tag
X-Fe
X-DI