Threat Level: green Handler on Duty: Russell Eubanks

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Pragma
Last-Modified
Accept-Ranges
Strict-Transport-Security
X-Content-Type-Options
X-Powered-By
CF-RAY
ETag
Link
Expect-CT
Via
X-XSS-Protection
X-Cache
Age
Access-Control-Allow-Origin
Content-Security-Policy
Content-Language
X-UA-Compatible
P3P
X-Cache-Hits
X-Served-By
X-Varnish
X-Amz-Cf-Id
X-Xss-Protection
Referrer-Policy
X-Request-Id
X-Timer
X-AspNet-Version
CF-Cache-Status
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Runtime
Access-Control-Allow-Credentials
X-Download-Options
X-Drupal-Cache
X-Cacheable
Content-Security-Policy-Report-Only
X-Generator
Alt-Svc
Status
X-AspNetMvc-Version
X-Cache-Status
X-DNS-Prefetch-Control
X-Check
P3p
X-Iinfo
X-Adblock-Key
X-FRAME-OPTIONS
X-CDN
Timing-Allow-Origin
X-Content-Security-Policy
X-Permitted-Cross-Domain-Policies
X-Turbo-Charged-By
Content-Encoding
X-Template
X-Language
Keep-Alive
X-Type
X-AH-Environment
X-Via
X-Cache-Group
X-Backend
X-Request-ID
WPE-Backend
X-Pass-Why
X-Buckets
X-Age
X-Server
X-Nginx-Cache-Status
Access-Control-Max-Age
X-Server-Powered-By
X-Pingback
Xkey
X-Varnish-Cache
Grace
X-Drupal-Dynamic-Cache
Upgrade
Access-Control-Expose-Headers
X-Hacker
X-UA-Device
X-Amz-Request-Id
Cf-Railgun
X-Page-Speed
X-Amz-Id-2
X-Proxy-Cache
X-Robots-Tag
EagleId
X-Envoy-Upstream-Service-Time
Request-Context
X-Node
X-Swift-CacheTime
X-Swift-SaveTime
X-LiteSpeed-Cache
X-Ac
X-Device
Ali-Swift-Global-Savetime
X-Cnection
X-Host
X-Amz-Version-Id
Content-Location
X-WebKit-CSP
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Server-Id
Surrogate-Control
X-Backend-Server
X-OneAgent-JS-Injection
X-Cache-Lookup
X-Rack-Cache
X-Response-Time
X-Px
X-Instart-Request-ID
X-CST
Server-Timing
Request-Id
X-Readtime
X-Rq
X-Url
X-Clacks-Overhead
Pinterest-Generated-By
Permitted-Cross-Domain-Policies
X-HeyJason
X-Do-Not-Hack
EagleEye-TraceId
X-Ua-Compatible
Edge-Control
X-Country
X-Application-Context
X-Cloud-Trace-Context
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-MS-InvokeApp
Report-To
Charset
X-DynaTrace-JS-Agent
X-Server-Name
SPRequestGuid
X-Country-Code
Allow
X-ESI
X-DataDome
X-SharePointHealthScore
Rating
X-Varnish-TTL
X-Ruxit-JS-Agent
X-Vname
X-PC
X-TtlSet
X-Cached
X-Powered-CMS
X-Powered-By-Plesk
X-Recruiting
X-DynaTrace
X-CF-Powered-By
X-FTR-Request-ID
X-Vhost
NEL
X-D2id
X-TTL
X-Pinterest-Rid
Public-Key-Pins
Pinterest-Version
X-Upstream-Env
X-F-Cache
X-Geo-Segment
X-Kinja-Server
X-Kinja-Build
X-Cdn-Fetch
X-Exp-Id
X-Kinja
X-Exp-Variant
X-Kinja-Revision
X-Version
X-T
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
Cartoon
X-VARITI-CCR
X-GoogleNews-Bot
X-N
SPRequestDuration
SPIisLatency
X-Dw-Request-Base-Id
X-Mod-Pagespeed
X-Ttl
X-Abt-Application-Version
RTSS
Content-MD5
Verso
Feature-Policy
Nginx-Cache
MS-Author-Via
X-GitHub-Request-Id
X-Dispatcher
X-Goog-Hash
X-Navigation-Version
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Amz-Rid
X-Client-IP
X-Forwarded-Proto
X-Hits
MicrosoftSharePointTeamServices
Realpath
AR-CACHE
AR-ATIME
X-Shield-Request-Id
AR-PoweredBy
X-Origin-Cache
X-Cdn
X-Trace
Paypal-Debug-Id
X-TEC-API-VERSION
X-TEC-API-ROOT
DynaTrace
X-TEC-API-ORIGIN
X-Content-Options
X-Grace
X-Content-Digest
X-Id
X-Zen-Fury
X-Server-ID
X-Kinsta-Cache
X-B
TCN
Arr-Disable-Session-Affinity
Alternate-Protocol
X-Varnish-Age
X-Cache-Key
AR-SID
Fastcgi-Cache
X-Sol
X-Upstream
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
MRF-Tech
Mrf-Cache-Status
X-Acc-Meta-Resource-Type
Access-Control-Request-Method
X-FastCGI-Cache
X-Pad
Display
PB-PID
X-Middleton-Display
PB-RID
X-Mobile-Rewrite
X-Ser
X-Fastly-Request-ID
X-NF-Request-ID
X-Nf-Srv-Version
X-Via-JSL
X-DIS-Request-ID
X-Vcap-Request-Id
X-User-Agent
X-Middleton-Response
X-Litespeed-Cache
Pagespeed
Response
X-MSEdge-Ref
X-Forwarded-For
Rt-Fastcgi-Cache
Eomportal-Instance
Arc-Version
X-Cache-Rule
X-Frontend
Front-End-Https
X-PressLabs-Stats
X-Cache-Hit
X-SS-Set-Cookie
X-Goog-Stored-Content-Encoding
X-Logged-In
X-Goog-Storage-Class
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Length
X-IPLB-Instance
X-Hostname
Server-Name
Host
X-Whom
X-VCache
Surrogate-Key
Tracecode
S
X-FTR-DC
X-FTR-Cache-Status
X-FTR-Backend-Server
X-FTR-Balancer
X-Country-Code-Real
X-FTR-Backend
X-FTR-Expires
X-FTR-Realm
X-XRDS-LOCATION
X-Request-Processing-Time
X-Request-Received
Backend-Timing
X-Analytics
TP-Cache
TP-L2-Cache
Cache-Status
X-Debug
X-Instance
X-Magnolia-Registration
X-AOL-HN
X-Contextid
X-HS-Content-Id
Refresh
X-Az
ServerID
X-AppVersion
X-Proxied
X-XRDS-Location
X-Activity-Id
X-B3-Traceid
X-Rid
FilterID
Public-Key-Pins-Report-Only
X-HW
X-Srv
X-Wix-Server-Artifact-Id
Cleartype
HitInfo
HitType
Server-Info
X-UUID
X-WPE-Loopback-Upstream-Addr
X-APP-VERSION
AMP-Access-Control-Allow-Source-Origin
X-FTR-Cache-Host
X-Content-Security-Policy-Report-Only
X-Varnish-Backend
X-Newrelic-App-Data
Service-Worker-Allowed
X-Mobile
X-Origin-Upstream-Status
X-Varnish-Server
Liferay-Portal
X-Cache-Control
Accept-Charset
Served-By
X-Revision
X-Cache-Server
X-Amzn-Trace-Id
Server-Node
X-TT
X-BCube-Filmed-By
X-Geo-Country
X-Hail-Hydra
X-PC-AppVer
X-PC-Hit
X-PC-Key
X-Request-Guid
X-PHP-Backend
Host-Header
X-Page-Id
Retry-After
MS-CV
Source
X-Framework
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-User
X-App-Environment
X-Varnish-Hostname
DC
X-Handled-By
X-Cache-Config
X-Device-Type
X-Cache-Operation
X-FB-Debug
Powered-By-ChinaCache
X-B-Cache
X-Signature
X-Cache-2
X-Origin-Server
X-RateLimit-Remaining
X-Correlation-Id
Viewport
X-Origin
S-Cnection
X-NWS-LOG-UUID
X-Debug-Info
X-ATG-Version
X-Cache-Action
X-TT-TIMESTAMP
Fastly-Restarts
X-Ocache
X-HS-Cache-Config
Edge-Cache-Tag
X-PC-Date
X-PC-Host
X-Sucuri-ID
X-B3-Sampled
X-Cached-By
Actual-Object-TTL
X-WA-Info
X-Hyper-Cache
X-NewRelic-App-Data
NGB
X-LB-Cache
X-Drupal-Cache-Tags
X-Microcachable
X-Akam-SW-Version
X-Content-Powered-By
X-Shield-Cache-Expires
X-ADI-VCache
X-Accel-Expires
Upgrade-Insecure-Requests
AsisCache
X-Cache-NE
X-Generated-By
Filters
SRV
X-App-Server
X-WebKit-CSP-Report-Only
X-Distil-CS
X-Tumblr-Pixel-2
ServedBy
X-Tumblr-Pixel-1
X-FW-Serve
X-FW-Hash
X-FW-Static
X-FW-Server
X-FW-Type
X-Locale
X-RTag
X-Internal-Host
X-Yottaa-Optimizations
X-Cluster
X-Yottaa-Metrics
X-URL
X-Cacheable-TTL
Content-Style-Type
X-S
X-Seen-By
X-GUploader-UploadID
Content-Script-Type
X-RequestSource
X-Wix-Request-Id
X-ServedBy
X-Jobs
X-Cache-Age
X-Geo
Cache
X-Accel-Buffering
X-Amz-Server-Side-Encryption
X-Varnish-Hits
X-GeoIP
X-TX-ID
From-Origin
X-Node-Name
Datacenter
X-Varnish-Grace
X-Platform-Server
X-Varnish-Cache-Hits
X-Adobe-Loc
X-RateLimit-Limit
X-Adobe-Content
X-Vg-Webcache
X-CDN-Forward
X-GZip
X-Varnish-IP
X-Akamai-Edgescape
X-Dns-Prefetch-Control
X-UA
X-Sucuri-Cache
X-CLOUD-TRACE-CONTEXT
X-Cache-TTL-Remaining
X-HS-Combine-CSS
Cache-Tag
X-Real-IP
X-Edge-Cache-Key
X-Storage
X-Edge-Cache
X-Oneagent-Js-Injection
X-Akamai-Transformed
X-Webkit-Csp
X-Mode
X-Drupal-Cache-Contexts
X-Region
X-Cache-Remote
X-Amz-Replication-Status
X-Source
X-Distributor
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
Machine
X-MP-GENERATED-AT
X-Path-Route
X-RemovedCookies
X-ProcessESI
X-Rendered-As
X-RN-RSRV
X-Proxy
X-Amz-Apigw-Id
X-Amzn-RequestId
Load-Balancing
X-Detected-As
X-Is-Bot
Meta-Geo
Fastly-SSL
X-NCache
X-ApacheServer
X-Time-Microsecs
X-Akamai-Request-ID
X-Agile-Age
X-Agile-Id
X-Upgrade-Enabled
ServerName
X-PERF
X-Webstats-RespID
Cache-Key
X-FC-Vary-Parameters
X-CDN-Cache
HostName
X-Kinja-Server-Push
X-Agile
Ohc-File-Size
X-Backend-Name
Azure-RegionName
Azure-InstanceId
User-Agent
X-Cache-Category-Id
X-OCL
X-NodeID
X-Varnish-Cacheable
X-Viewer-Country
X-OVcl
X-OVcl-Cache
X-Pubstack
X-PCL
X-TWH-CORRELATION-ID
X-Web-Node
Backend
S-Rt
GEO-INFO
Azure-Version
Azure-SlotName
X-Amz-Meta-Surrogate-Control
X-BB-IP
X-Grey
X-Cache-Var-Map
X-Cache-Var
Azure-SiteName
Mn-Server-Ip
X-Daa-Tunnel
X-Human
Countrycode
X-Instance-Name
X-Generation-Time
X-IP
X-Proto
X-LJ-Flow-ID
X-Format
X-Edge-Location
X-App-Name
X-Access
Now
X-AWS-Id
X-Birta-Cache-Post
X-Cluster-Node
LB
X-Birta-Served
X-Original-Request
X-Meta-Tbi-Cache-Vertical
X-ServerID
X-Section
X-SplitTest
X-Zipkin-Id
X-VWS-Id
X-Via-Fastly
X-Routing-Service
X-Site-Version
X-Hosted-By
X-Port
X-JoinUs
Webcakes-Region
X-Www-Served-By
X-Origin-Hint
Webcakes-App-Version
User-Cache-Control
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Locale-Group
TWC-Privacy
X-Timing-Wait
Webcakes-App-Name
Access-Control-Allow-Method
TWC-Device-Class
X-ProxyCache-Status
X-ProxyCache-Key
X-Proxy-Build
X-TNCMS
X-Debug-Cache
Healthy
X-Cache-HT
X-CCM-LastModified
X-Loop
X-Optimization
X-BYPASS-REASON
L5d-Success-Class
DB-Nickname
TWC-Connection-Speed
Fastcgi-Useragent
Property-Id
Cache-Name
Selected-FE
X-EIG-Tracking-Id
Country
X-Labrador-Cache-Channel
X-Tb
Payment
X-CCM
X-Xfnlog-Site
X-Generated
X-Esi
X-Tumblr-Pixel-3
X-Dc
Cache-Hits
Ec-Rule-Version
X-Guploader-Uploadid
X-Request-Time
RATING
X-Newrelic-Synthetics
X-Surge-Debug
X-Ezoic-Cdn
X-Time
X-Hit
X-Unique-ID
X-DataStream-Cache-Status
X-Cache-Bucket
X-Origin-CC
WP-Super-Cache
X-B3-Spanid
X-Correlation-ID
X-TA-CDN-Provider
X-Nginx-Cache
X-Feature
Origin-Cache-Control
Origin-Edge-Control
X-Render-Type
X-Real-Ip
X-Cache-Enabled
X-Nc
NODE
X-L-Path
X-Environment-Context
X-Varnish-Beresp-Status
X-UA-Device-Type
X-NU-AKA-ACS-Version
X-Varnish-Beresp-Grace
RequestId
X-Skip-Cache
Xserver
X-Status
X-B3-TraceId
X-Content-Type
X-NGENIX-Cache
Apicache-Store
Apicache-Version
X-HS-Hub-Id
X-Be
Ws
Access-Control-Request-Headers
X-Servedby
X-ElasticPress-Search
X-Cache-Backend
X-EdgeConnect-Cache-Status
X-CACHE-AGE
X-WR-MODIFICATION
IBM-Web2-Location
Warning
X-Vgn-Hpd-Reason
Apple-News-Services-Host
T-Server
X-Date
Resin-Trace
X-ARC
X-Application
AKAMAI
Ajk
Sta2Tusw
X-Destination
X-BB-ID
X-CF-Lambda-Version
X-Connection-Hash
X-A
X-BBXSRF
Apple-News-Services-Request-Url
X-CF-Lambda-Fn
X-A-Dam
X-A-Dcw
X-A-Dgt
X-B-Cookie
Apple-News-Services-Parsed-Url
X-Accel-Expires-Debug
X-A-Ccd
X-D
X-A-Wwc
Www
VivaBuild
Viewtype
Apple-News-Services-Handled
Memcached
Fly-Request-Id
GMS-Ver
X-SRCache-Key
X-SVT-ORM-RULES
Fly-Cache
X-SVT-ORM-VERSION
X-Server-Time
X-Server-By
X-S-Cookie
X-Developer
Webserver
Time
Host-ID
X-Transaction
X-Trv-Group
X-We-Are-Hiring
Fastly-Soc-X-Request-Id
Fastcgi-X-Cache-Version
X-Wix-Route-ID
Xc-Version
X-Via-Edge
X-Via-CDN
X-Upstream-CT
X-Twitter-Response-Tags
X-Upstream-HT
X-User
X-VG-WebServer
Cache-Prefix
X-Rojux
X-Haproxy-Ip
X-Haproxy-Hostname
Fastcgi-X-Cache
X-IN-APIGATEWAY
X-Rewrite-Enabled
X-Generated-In
X-G
BehaviorPad-Version
X-Died
X-Fastly-Cache
Meta-Geo-Continent
X-From
X-IN-WAF
X-IN-SSL-APIGATEWAY
MD5-Digest
X-Planisys-CDN-Cache
X-Logtrace-Id
X-Planisys-CDN-TTL
X-Region-Sid
X-PAYTM-SRV-ID
X-ND-Cache
X-No-Session
X-Public
X-Planisys-CDN-Rules
X-GoCache-CacheStatus
Release
IsBot
NGX
Fastly-SWR
Rendered-Blocks
Origin
Fastly-SIE
X-Hl-Ver
X-SIPLIST1
X-ScT
X-Rocket-Nginx-Bypass
X-Rebelmouse-Surrogate-Control
X-Sn-Servicetimems
X-Trace-Id
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-Via-NSCOPI
X-Up
X-Rebelmouse-Cache-Control
X-Phone
X-Amz-Meta-Cache-Control
UCS
Uber-Trace-Id
Server-Int
X-Auto-Login
X-Cache-Host
X-Forwarded-Host
X-F5-Cache
X-Core-Value
X-Cdn-Origin
Request-Time
V-Age
X-Croise-Owner
X-Webkit-CSP
X-Cache-Ttl
X-C
X-Backend-Url
X-Cache-CFC
X-Bip
X-Cache-Control-Set-By
X-Cache-Expires
X-Thinkindot-L3
X-Cache-Id
X-TT-LOGID
X-Backend-TTL
X-Backend-Host
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-UE-Client-Country
On-Server
Thinkindot-Control
Who
X-Thanos
X-V
X-Node-Id
X-Varnish-HitMiss
X-Backend-State
X-ServiceProvider
X-Request-URI
X-HCF
X-GeoIP-Country-Code
X-Fstrz
X-Frame-Option
X-Reboot
X-Platform
X-NX-Host
X-MI-In-Market
X-Matched-Rule
X-Location
X-FireWall-Port
X-Epic-Correlation-Id
X-CS
X-Servername
X-Clientip
Ohc-Response-Time
X-Debug-Cookies
X-Debug-Log
X-Edge-IP
X-DPWN-IS-SECURE
X-Developers
X-Server-Group
X-Cdn-Srv
X-Var-Ttl
Backend-Name
Decoy-Debug-Key
Odigeo-Trace-Id
MI-Cache-Age
MI-Cache
Cache-Cookie-Set-From
Cache-Cookie-Set-Idcheck
Decoy-Debug-Status
Content-Disposition
Decoy-Debug-TTL
Cache-Cookie-Set-Lfrom
HTTPS
Cneonction
X-Ckpd-Fst-Backend
HA-Georegion
HA-Geolon
HA-Geocountry
HA-Geolat
X-Crawler
Httpd-Identifier
X-Content-Age
X-Cache-Debug
Heartbleed
HA-Servedtime
HA-Urlpath
HA-Host
X-Server-IP
X-CGP
X-Cache-Time
X-Stale
Ha-Gx-Prefs
X-Ruxit-Js-Agent
X-Passed-To-PostProcessResponse
X-Passed-To-DLL
X-Info
X-RCS-CacheZone
X-Hnp-Log
X-Passed-To-BeforeDispatch
X-Passed-To
Esi-Enabled
X-MSEdge-Flight
X-MSEdge-Features
Fastly-Backend-Name
X-Returned-From
X-GeoIP-City
X-Bug-Bounty
CDCHOST
GW-Server
HA-Cloudapp
X-Env
X-Eu-Site
X-Returned-From-BeforeDispatch
X-Gen-Mode
X-Returned-From-DLL
X-Returned-From-PostProcessResponse
HA-Geocity
HA-Ipaddr
X-Worker
X-Ver
X-VServer
X-Block-Status
X-Actual-URL
X-Varnish-Id
PFcat
X-Cache-Srv
Web-Mar-Node
X-Fetched-On
X-Response-By
X-Core-Mission
OT-Force-Account-Verify
X-Amz-Meta-S3cmd-Attrs
Server-Host
Pramga
X-UnsetCookies
Powered-By
Platform
Is-Eu
Proxy-Connection
Pragrma
Adler-Geo
REQUESTUUID
X-Release
X-Sorting-Hat-ShopId
X-Sorting-Hat-Section
X-Alternate-Cache-Key
X-TIME
Request-EU
Server-ID
X-Origin-Expires
X-Refresh
X-Origin-Date
X-Sorting-Hat-ShopId-Cached
Request-Country
MI-API
X-Served-From
X-S-Maxage
X-ShopId
X-Cache-URL
Country-Code
X-Hash
X-ShardId
X-Shopify-Stage
X-Device-Os
X-Sorting-Hat-PodId-Cached
X-Sorting-Hat-PrivacyLevel
X-Sorting-Hat-FeatureSet
X-Sorting-Hat-PodId
Cache-Provider
X-WebServer
X-Dispatcher-Server
Dnion-Transfer-Encoding
NnCoection
X-Varnish-Beresp-Ttl
Kp-EeAlive
X-Page-Type
Mime-Version
X-Fastcgi-Cache
X-P-T
X-Svr
X-Req
NtCoent-Length
Drupal-Pagecache-Memcache
X-Cache-ASPX
X-StackifyID
X-Gannett-Site-Version
X-Pjax-Url
X-Pf-Uncompressing
X-Secret
X-Origin-TTL
X-EC-Security-Audit
Processtime
X-SERVER-NAME
Accept-Ch
X-Amz-Meta-S3b-Last-Modified
X-Oss-Storage-Class
X-Oss-Object-Type
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
Version
X-Csrf-Token
X-Wix-Petri-Ex
X-NC
Ar-Sid
Memory
X-Amz-Meta-Sha256
SN
Pagetype
Dont-Set-Cookie
X-Varnish-Url
X-Rule
WebServer
X-App-Version
Geoip-City
X-CSRF-Token
X-RateLimit-Remaining-Second
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-From-Cache
X-RateLimit-Limit-Second
Geoip-Latitude
X-LiteSpeed-Cache-Control
GeoIp-Country-Code
X-Ua
Cteonnt-Length
X-Yottaa-Sig
FSS-Proxy
PICS-Label
Arc-Country
X-Cache-Handler
FSS-Cache
X-Load-Cache
X-Varnish-Beresp-TTL
Brightspot-Id
CF-IPCountry
PageType
X-Irp-Debug
MIME-Version
Cdn
X-LB-CacheStatus
X-LB-Node
X-Request-Start
X-DC
X-Ratelimit-Remaining
X-Redis-Cache
Sid
X-ROOTCache
Edgecast
COMMERCE-SERVER-SOFTWARE
X-COUNTRY
If-Modified-Since
X-Fastly-Backend-Reqs
X-Sf
X-Request-UUID
X-Endurance-Cache-Level
X-GRACE
BORDER-IP
PROCESSING-IP
X-Cdn-Forward
X-Requestid
X-Tid
RNT-Machine
RNT-Time
XServer
X-Ratelimit-Limit
X-Servedbyhost
X-ServedByHost
X-TId
X-Varnish-Action
X-GDPR
X-RequestId
X-Layer
Powered
X-Atg-Version
X-Rocket-Nginx-Serving-Static
X-Resolver-IP
Cache-Tags
X-B3-SpanId
X-Nananana
X-Cache-TTL
Frame-Options
X-BE
X-DataStream-MidMile-RTT
X-DataStream-Origin-MEX-Latency
X-Fastly-Cache-Hits
CDN
Amp-Access-Control-Allow-Source-Origin
Pics-Label
Cf-Ipcountry
NodeID
CACHE
X-Gdpr
X-Tec-Api-Root
Node
X-Tec-Api-Origin
X-Tec-Api-Version
X-UPSTREAM-Address
X-Owner
X-Key
Mail-Subject
We-Hiring
PageSpeed
X-HTML-Minification-Powered-By
X-Dynatrace-Js-Agent
Hostname
X-Shard
GeoIP-Latitude
X-Server-W
X-VG-WebCache
GeoIP-City
X-Varnish-URL
GeoIP-Country-Code
X-Varnish-Ttl
X-Dynatrace
X-Use-Magma
X-Alicdn-Da-Ups-Status
Lfy
X-Aicache-OS
X-Ms-Version
X-Ms-Blob-Type
Web-Mar-Region
X-Sentry-ID
X-Ms-Lease-Status
X-Ms-Request-Id
ProcessTime
X-GZIP
X-VG-TLSProxy
X-Flog
X-ABtesting
Accept-CH
WZWS-RAY
Dynatrace
URI
X-PF-Uncompressing
X-Powered-By-ANYU
X-PJAX-URL
Cdn-Host
X-GEO
Cdn-Request-Time
X-Edge-Server
True-Client-Country-4JS
X-Front
X-NGINX-Cache
X-Dw-Trace-Id
DataCenter
Xet-Cookie
X-Swa-Ws
GEO-REGION-INFO
Rt-Proxy-Cache
X-CDN-Pop-IP
X-Org
X-Oa-Upstreams
Is-Session-Tracking
Max-Age
X-Ms-Lease-State
Get-Access-Time
X-Policy
Group
V-Cache
X-Check-Cacheable
X-CDN-Pop
X-Vcache
X-Cookie
X-PAGE-TYPE
X-NWS-UUID-VERIFY
X-Unique-Id
X-Varnish-Info
X-Mem
Requestid
X-Trv-Request-Id
RequestUuid
N-Cache
X-Varnish-ID
X-VID
X-External-Request-Id
X-Response-Served-From
X-RSL
X-Amzn-Remapped-Date
X-RPS
X-Amzn-Remapped-Connection
X-M-Reqid
X-SB
X-M-Log
X-VC
X-Qnm-Cache
X-Litespeed-Cache-Control
X-Proxy-Server
X-Litespeed-Tag
X-Remote-IP
SID
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Hello
X-Akamai-ERRuleID
X-Akamai-ERPolicy
X-Powered-By-Defense
X-RAMCache
X-DI
X-DSS
X-DW
X-DB
CF-Cached-On
X-Cache-FS-Status
WS
X-Fe
X-RPM