Threat Level: green Handler on Duty: Manuel Humberto Santander Pelaez

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
CF-RAY
CF-Cache-Status
Link
X-Powered-By
X-XSS-Protection
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Alt-Svc
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
Content-Security-Policy-Report-Only
X-Generator
X-Cacheable
X-Cache-Status
X-Permitted-Cross-Domain-Policies
X-Xss-Protection
X-Request-ID
Timing-Allow-Origin
X-Template
X-Language
X-DNS-Prefetch-Control
X-Iinfo
Status
X-AspNetMvc-Version
X-Content-Security-Policy
Content-Encoding
X-Buckets
X-Kinja-Server-Push
Xkey
Upgrade
X-Via
X-Turbo-Charged-By
Access-Control-Expose-Headers
Keep-Alive
Access-Control-Max-Age
X-Cache-Group
X-Drupal-Dynamic-Cache
X-Pass-Why
P3p
X-Age
EagleId
X-Backend
X-Robots-Tag
X-Envoy-Upstream-Service-Time
X-Amz-Request-Id
X-Amz-Id-2
X-Page-Speed
X-CDN
X-Ua-Compatible
X-Pingback
X-Server-Powered-By
X-AH-Environment
X-Proxy-Cache
X-Hacker
X-UA-Device
X-Server
Request-Context
X-Nginx-Cache-Status
Grace
X-Swift-SaveTime
X-Swift-CacheTime
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-Cdn
X-LiteSpeed-Cache
Cf-Railgun
X-Amz-Version-Id
X-Server-Id
X-WebKit-CSP
Feature-Policy
Server-Timing
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-OneAgent-JS-Injection
X-Rq
X-Ac
X-Cnection
X-Cloud-Trace-Context
Report-To
X-Host
X-Response-Time
EagleEye-TraceId
X-Node
X-Backend-Server
X-Dns-Prefetch-Control
Content-Location
Request-Id
X-Origin-Cache
X-Readtime
X-Vhost
X-Application-Context
X-Cache-Lookup
X-ORACLE-DMS-ECID
X-Dispatcher
NEL
X-Origin-Upstream-Status
X-ORACLE-DMS-RID
X-Rack-Cache
X-Ruxit-JS-Agent
Surrogate-Control
X-DataDome
Allow
X-HW
Rating
X-Country-Code
X-FTR-Request-ID
X-Country
X-Clacks-Overhead
X-TTL
X-EdgeConnect-Origin-MEX-Latency
X-DynaTrace
X-Url
X-EdgeConnect-MidMile-RTT
Fusion-Content-Source
Fusion-Component-Id
X-Instart-Request-ID
Fusion-Source
Fusion-Content-Id
Fusion-Template-Id
X-Goog-Hash
X-MS-InvokeApp
X-Varnish-TTL
X-Vname
X-TtlSet
X-PC
Verso
RTSS
X-CST
X-Powered-By-Plesk
Public-Key-Pins
X-Px
X-Recruiting
Edge-Control
X-VARITI-CCR
X-Mod-Pagespeed
Pinterest-Generated-By
Response
X-Sol
X-Middleton-Display
Display
X-Middleton-Response
Service-Worker-Allowed
X-D2id
X-Exp-Variant
X-GoogleNews-Bot
X-Cdn-Fetch
X-Kinja-Server
X-Use-Magma
X-Kinja-Revision
X-Kinja-Build
X-Kinja
X-Exp-Id
Accept-CH
X-Ah-Environment
X-B3-TraceId
X-Vcap-Request-Id
X-Version
SPRequestGuid
X-SharePointHealthScore
X-Akam-SW-Version
MS-Author-Via
TCN
X-Navigation-Version
X-Abt-Application-Version
X-GitHub-Request-Id
Accept-Ch-Lifetime
X-RateLimit-Remaining
X-Powered-CMS
SPIisLatency
X-Shard
SPRequestDuration
X-Server-Name
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Upstream
AR-ATIME
X-Forwarded-Proto
Ar-Sid
Fastly-Restarts
X-Amz-Server-Side-Encryption
AR-CACHE
Charset
AR-PoweredBy
X-Trace
X-XRDS-Location
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Amz-Rid
Nginx-Cache
Realpath
X-Debug
X-ESI
X-Aspnetmvc-Version
Front-End-Https
X-Cached
X-Ezoic-Cdn
AR-Request-ID
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-NF-Request-ID
X-Goog-Generation
X-Shield-Request-Id
X-Goog-Stored-Content-Encoding
X-Mrf-Section-Lastmod
Mrf-Cache-Status
X-Mrf-Item-Lastmod
X-B3-TraceId-Primal
MRF-Tech
X-MSEdge-Ref
Access-Control-Request-Method
Pagespeed
Arr-Disable-Session-Affinity
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Expires
Paypal-Debug-Id
Content-MD5
X-Id
ServerID
DynaTrace
X-FTR-DC
X-FTR-Backend-Server
X-FTR-Realm
X-FTR-Balancer
X-FTR-Backend
X-Goog-Storage-Class
MicrosoftSharePointTeamServices
X-Amz-Meta-S3cmd-Attrs
X-T
S
X-Fastly-Request-ID
X-Vcache
X-Via-JSL
X-Client-IP
X-Varnish-Age
X-DynaTrace-JS-Agent
X-VCache
X-Content-Type
X-Hits
X-Dw-Request-Base-Id
X-Amzn-Trace-Id
X-Correlation-Id
X-FastCGI-Cache
X-Grace
Fastcgi-Cache
X-Accel-Expires
X-Ser
X-Frontend
X-Content-Digest
X-RateLimit-Limit
X-SERVER
Powered
X-FTR-Cache-Host
X-N
Arc-Version
PB-PID
PB-RID
X-Mobile-Rewrite
X-DIS-Request-ID
AMP-Access-Control-Allow-Source-Origin
X-Logged-In
Server-Name
X-HS-Hub-Id
X-HS-Content-Id
X-Forwarded-For
X-B3-Sampled
Edge-Cache-Tag
TP-Cache
TP-L2-Cache
X-GUploader-UploadID
X-Esi
X-Microsite
X-Request-Handler-Origin-Region
X-Zen-Fury
X-Request-Processing-Time
X-Request-Received
X-Type
X-Cache-Age
Backend-Timing
X-AppVersion
X-Az
X-Rid
X-Kinsta-Cache
X-Activity-Id
X-Analytics
X-IPLB-Instance
X-Fastcgi-Cache
X-Revision
X-User-Agent
X-LB-Cache
FilterID
X-B3-Traceid
Healthy
X-Node-Name
X-Whom
Retry-After
X-Pinterest-Rid
Accept-Ch
Pinterest-Version
X-Cache-Hit
X-F-Cache
X-NWS-LOG-UUID
X-Time
X-Cache-2
Accept-Charset
X-Srv
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Server-Node
Alternate-Protocol
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Cache-Rule
Cache-Status
X-AOL-HN
X-Content-Powered-By
X-Content-Options
Surrogate-Key
Refresh
X-Hp-Webp
DC
X-Content-Security-Policy-Report-Only
X-Server-ID
X-Forwarded-Host
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Debug-Info
X-Akamai-Edgescape
X-Instance
X-Tumblr-Pixel
X-Tumblr-Pixel-0
Access-Control-Allow-Method
X-Tumblr-User
X-Cluster
X-FW-Type
X-Framework
X-FW-Static
X-Jobs
X-Page-Id
X-FW-Server
X-FW-Hash
X-Varnish-Grace
X-FW-Serve
X-PHP-Backend
X-FB-Debug
X-Request-Guid
MS-CV
X-Acc-Meta-Resource-Type
Cache-Tag
X-B
Source
X-App-Server
Fastcgi-Useragent
Frame-Options
X-TA-CDN-Provider
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-App-Environment
Tracecode
X-Hostname
Host
X-Cache-Key
X-Cache-Operation
Actual-Object-TTL
X-Mobile-URL
Cleartype
X-B-Cache
X-Signature
X-Cached-By
X-Seen-By
X-BCube-Filmed-By
X-Geo-Country
X-Cache-Control
X-Amz-Replication-Status
X-Host-Name
X-Varnish-Backend
X-TT
X-Pad
X-Mobile
X-Git-Hash
NGB
X-Response-Served-From
Upgrade-Insecure-Requests
Liferay-Portal
Accept-CH-Lifetime
X-Adobe-Loc
X-Adobe-Content
X-Cache-TTL
X-TT-TIMESTAMP
X-WebKit-CSP-Report-Only
Payment
X-Status
X-ATG-Version
WPE-Backend
Filters
Cache-Tv-Group
X-ProcessESI
Eomportal-Instance
X-RemovedCookies
From-Origin
X-Tumblr-Pixel-1
X-Tumblr-Pixel-2
Ms-Operation-Id
X-Cache-Remote
X-Cacheable-TTL
Webserver
X-Handled-By
X-TX-ID
X-RTag
X-FW-Dynamic
X-Cache-TTL-Remaining
X-WA-Info
X-Drupal-Cache-Tags
GEO-INFO
X-UA-Device-Type
X-GeoIP
X-RequestSource
X-Origin-Server
X-Ratelimit-Reset
X-PressLabs-Stats
NR-ENABLED
X-Daa-Tunnel
X-Content-Age
Xserver
X-Cache-Action
X-Webkit-CSP
Datacenter
X-Edge-Location
X-Storage
Viewport
X-EdgeConnect-Cache-Status
X-Varnish-Hostname
X-Hyper-Cache
Version
X-Wix-Request-Id
X-Accel-Buffering
X-Contextid
X-CF-Powered-By
X-Region
X-DataStream-Cache-Status
Cache
X-Upstream-Proxy
Host-Header
X-Presslabs-Stats
PageSpeed
X-Akamai-Transformed
X-Ua
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-RN-RSRV
Meta-Geo
Load-Balancing
X-ES-SERVER
X-Varnish-Server
X-Cache-Var-Map
X-Path-Route
X-Cache-Var
S-Cnection
X-Cache-NE
X-IP
Ohc-File-Size
Cache-Tags
X-HS-Cache-Config
Cache-Name
X-Access
Decoy-Debug-Key
Decoy-Debug-Status
DB-Nickname
X-Akamai-Request-ID
X-Time-Microsecs
X-CS
X-NCache
X-Viewer-Country
X-Via-Fastly
X-Section
Cache-Hits
X-Proxy
X-Origin-Response-Time
X-Origin
X-PERF
X-Proto
X-From
Decoy-Debug-TTL
X-Cache-Server
X-Cache-Time
Vix-Hermes-Req-Id
X-Cache-Enabled
X-Cache-Config
Ec-Rule-Version
X-TNCMS
X-Labrador-Cache-Channel
X-Upgrade-Enabled
X-Tumblr-Pixel-3
X-Loop
Rt-Fastcgi-Cache
X-ApacheServer
Selected-Fe
Azure-Version
Cache-Key
Country
Azure-SlotName
Azure-SiteName
Azure-InstanceId
Azure-RegionName
S-Rt
X-Backend-TTL
X-Upstream-HT
X-Web-Node
X-Upstream-CT
X-R9-Blue-Green-Version
X-Trace-Id
X-Rule
X-Xfnlog-Site
X-EIG-Tracking-Id
X-JoinUs
X-Hit
X-Format
X-FC-Vary-Parameters
X-PCL
X-OCL
X-Cluster-Node
X-Proxy-Build
X-Akamai-Request-ID2
X-CCM
X-Cache-Grace
X-Timing-Wait
X-Site-Version
X-Origin-Hint
X-Cache-Host
X-Drupal-Cache-Contexts
X-Locale
X-Hosted-By
Webcakes-App-Version
X-Human
Webcakes-Region
X-FireWall-Port
X-Backend-Name
X-Www-Served-By
TWC-GeoIP-LatLong
Webcakes-App-Name
TWC-GeoIP-Country
X-S
TWC-Device-Class
X-Generated
X-UnsetCookies
TWC-Locale-Group
Mn-Server-Ip
TWC-Connection-Speed
X-Varnish-Hits
X-Varnish-Cache-Hits
TWC-Privacy
X-Goog-Meta-Goog-Reserved-File-Mtime
Property-Id
Server-Info
X-Debug-Cache
X-FW-Version
X-Device-Type
Now
X-Rendered-As
Time
Ohc-Cache-HIT
OT-Force-Account-Verify
Release
X-VCT
X-APP-VERSION
DSUID
SRV
X-Element-Page-Cache
X-Vgn-Hpd-Reason
Hostname
X-OVcl
X-NewRelic-App-Data
X-OVcl-Cache
X-VG-TLSProxy
Cteonnt-Length
X-Real-IP
ServedBy
X-Redis-Cache
Fastcgi-X-Cache-Version
X-VG-WebCache
Origin-Cache-Control
Origin-Edge-Control
X-Pubstack
Access-Control-Request-Headers
X-Litespeed-Cache
X-ShopId
X-ShardId
X-FB-TRIP-ID
X-Sorting-Hat-PodId
X-B3-Spanid
X-Shopify-Stage
X-Sorting-Hat-ShopId
X-Alternate-Cache-Key
X-CSRF-TOKEN
Origin
L5d-Success-Class
Accept-Language
X-GEO
X-Tb
X-NC
Machine
X-NGENIX-Cache
X-SS-Set-Cookie
Fastly-SSL
X-Nginx-Cache
NtCoent-Length
X-HS-Combine-CSS
X-Environment-Context
X-No-Session
X-Cluster-Name
X-L-Path
X-Tt-Trace-Tag
X-UUID
X-Parent-Response-Time
X-Origin-TTL
X-Origin-CC
X-Load-Cache
IBM-Web2-Location
X-ECACHE
X-B3-Parentspanid
X-GoCache-CacheStatus
X-Mode
X-App-Version
X-Rocket-Nginx-Bypass
X-ServerID
X-Magnolia-Registration
X-Endurance-Cache-Level
Odigeo-Trace-Id
X-Amzn-Remapped-Content-Length
X-DataStream-Origin-MEX-Latency
Nel
X-Uri
X-LJ-Flow-ID
X-DataStream-MidMile-RTT
X-AWS-Id
X-Soup
X-VWS-Id
X-Generated-By
We-Hiring
Akamai-GRN
NGX
Mail-Subject
X-Is-Bot
X-Request-Time
X-XRDS-LOCATION
CF-IPCountry
X-CACHE-KEY
Content-Style-Type
Cross-Origin-Window-Policy
Fly-Cache
MD5-Digest
Fly-Request-Id
GEO-REGION-INFO
X-Node-Id
Memcached
A
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
Apple-News-Services-Host
Arc-Country
AsisCache
Cdn-Request-Time
Cdn-Host
Cache-Prefix
BehaviorPad-Version
Content-Script-Type
X-CF-Lambda-Fn
X-Request-UUID
X-Region-Sid
X-Rewrite-Enabled
X-Rojux
X-S-Cookie
X-PAYTM-SRV-ID
X-Instart-Info
X-DPWN-IS-SECURE
X-Edge-Server
X-External-Request-Id
X-G
X-S-Maxage
X-ScT
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
X-Worker
Xc-Version
X-VG-WebServer
X-Twitter-Response-Tags
X-Server-Time
X-SRCache-Key
X-Transaction
X-Trv-Group
X-Developer
X-Detected-As
X-A
VivaBuild
X-A-Ccd
X-A-Dam
X-A-Dcw
Viewtype
T-Server
Mobile-Detection-Method
Node
Rendered-Blocks
Rt-Proxy-Cache
X-A-Dgt
X-A-Wwc
X-Connection-Hash
X-D
X-Date
X-Destination
X-CF-Lambda-Version
X-B-Cookie
X-Accel-Expires-Debug
X-Aed
X-AIR-PT
X-ARC
Meta-Geo-Continent
X-Application
Proxy-Connection
Request-Time
Backend-Name
X-Oneagent-Js-Injection
ServerName
Mime-Version
Request-EU
X-VC-Cache
Fastly-Soc-X-Request-Id
Section-Io-Cache
X-Cdn-Srv
X-Urbn-Context-Path
X-Up
X-Cms-Context
X-Fastly-Cache
N-Cache
IsBot
X-Developers
Locale
X-Azure-Ref-OriginShield
X-Distributor
X-Cache-Bucket
X-Release
X-Urbn-Site-Id
Request-Country
X-Hl-Ver
X-SIPLIST1
X-SVT-ORM-VERSION
X-Origin-Date
X-Azure-Ref
X-SVT-ORM-RULES
X-Origin-Expires
X-MServer
User-Cache-Control
Uber-Trace-Id
X-Amz-Meta-Cache-Control
X-Backend-Url
X-WADP-Cache
RNT-Machine
X-We-Are-Hiring
X-Compress-Hint
RNT-Time
X-Core-Mission
X-Thinkindot-L3
X-Rebelmouse-Cache-Control
X-Auto-Login
X-Variation
Platform
X-RateLimit-Remaining-Second
X-Backend-Host
X-Device-Os
X-PHP-Host
X-App-Name
X-WebServer
X-VServer
X-Cache-Info
V-Age
X-Wikidot-Static-Cache
X-Cdn-Origin
X-Cache-Id
W
X-Bip
X-C
X-Policy
X-Wikidot-Backend
X-Cache-FS-Status
Magicmarker
True-Client-Country-4JS
Server-Int
X-RateLimit-Limit-Second
Server-ID
X-Clara-WADP
X-Clientip
X-Platform-Server
X-ABtesting
X-BBXSRF
Thinkindot-Control
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-Block-Status
X-Reboot
X-IN-APIGATEWAYSSL
AKAMAI
Adler-Geo
X-Owner
X-Level-Front-Cache
X-IN-APIGATEWAY
X-Hnp-Log
X-Rebelmouse-Surrogate-Control
CDCHOST
X-Generation-Time
X-Geo-Header
X-Hello
X-Li-Fabric
X-Li-Pop
X-Org
X-Old-Content-Length
X-ServiceProvider
X-Skip-Cache
X-Sn-Servicetimems
X-TrackingId
X-Nginx-Cache-Key
X-LI-UUID
X-LI-Proto
X-Location
X-Matched-Rule
X-Method
X-Gen-Mode
X-Generated-On
Is-Eu
X-Request-Start
Fastly-SWR
X-Request-URI
X-Via-CDN
X-Thanos
X-ElasticPress-Search
X-Epic-Correlation-Id
Gh-Request-Id
Esi-Enabled
Fastly-SIE
X-Fetched-On
X-GDPR
L
X-Flog
Content-Disposition
Countrycode
X-Distil-CS
X-ProxyCache-Key
X-BYPASS-REASON
X-ProxyCache-Status
X-Oracle-Dms-Rid
X-Microcachable
X-NX-Host
X-Debug-Cookies
X-User
X-Backend-State
X-Debug-Log
X-CUA
X-GeoIP-City
X-CGP
X-Generated-In
X-Internal-Host
X-Irp-Debug
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-Eu-Site
X-Debug-Cache-Store
Web-Mar-Node
X-Proxy-Upstream
Heartbleed
X-SD-PageType
X-SayCDN-TTL
X-Qloud-Router
X-Say-Cacheable
Pramga
PFcat
X-Swa-Ws
SD-X-WS
HA-Ipaddr
X-Proxy-Cache-Status
X-Reqid
X-Webstats-RespID
Ha-Gx-Prefs
X-Say-TTL
X-Servername
X-Server-IP
X-Guploader-Uploadid
X-B3-SpanId
X-DC
X-Dc
Kp-EeAlive
X-Hash
X-Service
X-Dispatcher-Server
X-Dispatch
Memory
Pagetype
SS
X-MSEdge-Features
X-MSEdge-Flight
Wxu-Next-Hostname
Wxu-Next-Region
Server-Host
Wxu-Next-Commit
Resin-Trace
X-Key
Served-By
X-Cdn-Forward
X-Routing-Service
X-Zipkin-Id
X-Proxied
X-JWT-State
X-Has-Esi
X-Wa
X-Is-Gdpr
X-FPC
X-Response-By
Cache-Provider
X-Var-Ttl
X-COUNTRY
X-Unique-ID
X-IPS-LoggedIn
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-From
REQUESTUUID
X-Ttl
Srv
X-URL
Country-Code
X-Servedbyhost
X-NWS-UUID-VERIFY
X-Info
X-Page-Type
X-Tec-Api-Root
X-MP-GENERATED-AT
X-Tec-Api-Version
X-Tec-Api-Origin
X-RateLimit-Reset
X-Nc
X-UA
UCS
X-Lb-Id
X-Geo
Powered-By-ChinaCache
X-VCL-Version
X-Svr
X-Cache-Backend
X-SRV
X-Cache-URL
X-Ratelimit-Limit
X-Be
X-Datadome
X-CDN-Forward
Ajk
ProcessTime
X-Logtrace-Id
X-Processor
X-HTML-Minification-Powered-By
CACHE
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
Proxy-Firewall
X-HS-Status
X-Instart-Isnd
X-Scheme
X-Varnish-Beresp-Ttl
X-Oss-Storage-Class
X-Oss-Server-Time
X-Trafficlayer-App-Name
X-Trafficlayer-App-Scope
XServer
X-NodeID
X-Pjax-Url
X-SN
X-Tb-Optimization-Total-Bytes-Saved
PICS-Label
X-Ruxit-Js-Agent
SN
Powered-By
Dynatrace
X-ZONE
X-Grey
X-FORWARDED-FOR
X-Cache-Category-Id
X-Webkit-Csp
X-Zone
Group
X-Dynatrace-Js-Agent
X-Ftr-Request-Id
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
X-Dynatrace
Ttl
Cache-Host
X-TH-Server
X-Server-W
Fastly-Backend-Name
X-Pf-Uncompressing
X-Source
X-GRACE
X-Newrelic-Synthetics
GeoIP-Country-Code
GeoIP-Latitude
GeoIP-City
X-Cache-Ttl
MIME-Version
X-LiteSpeed-Cache-Control
X-EC-Lua
X-Via-Ucdn
LB
X-Ms-Version
X-Ms-Request-Id
X-RCS-CacheZone
X-PF-Uncompressing
X-APP
X-LAGOON
GW-Server
X-Bc
X-Varnish-Beresp-TTL
X-NODE
X-Check-Cacheable
X-Secret
X-Fastly-Country-Code
Cdn
X-Ftr-Cache-Host
Environment
Geoip-Latitude
Geoip-City
X-Sucuri-Id
GeoIp-Country-Code
X-Varnish-Url
Lfy
X-Session-Fingerprint
X-Gannett-Site-Version
CF-Cached-On
X-Tt-Trace-Host
WZWS-RAY
X-Ratelimit-Remaining
X-Agile-Id
X-Agile-Age
X-Cache-Debug
X-Agile
X-BC
X-CDN-Cache
Pics-Label
X-PJAX-URL
On-Server
X-Aicache-OS
X-Edge
X-Varnish-Cacheable
X-SERVER-NAME
X-7Graus-Varnish-XKeys
X-7Graus-Varnish-Cache-Control
X-GeoIP-Country-Code
WWW
X-Akamai-SSL-Client-Sid
X-Logging-Id
User-Agent
X-Ftr-Balancer
X-Ftr-Realm
X-Ftr-Backend-Server
X-Ftr-Dc
X-Ftr-Backend
X-Sedo-Request-Id
X-Cache-Miss-From
Requestid
Inserted-Into-Cache-At
X-Mid
M-TraceId
Ohc-Response-Time
Cf-Ipcountry
X-Vcl-Version
X-Varnish-Ttl
X-BE
X-Fastly-Backend-Reqs
X-MCACHE
SID
X-Cache-Tag
X-CSRF-Token
X-NU-AKA-ACS-Version
Amp-Access-Control-Allow-Source-Origin
X-Render-Time
Who
X-Core-Value
X-Sucuri-ID
X-LB-ID
X-UPSTREAM-Address
X-Crawler
X-Litespeed-Cache-Control
Lb
X-Unique-Id
DataCenter
X-DW
X-Newrelic-App-Data
X-DSS
URI
X-DB
X-DI
X-RPM
X-Action
X-Proxy-Cacherz
X-RPS
X-AK-Request-ID
Cdncip
Cdnsip
Xkeyrz
X-RSL
X-TIME
HostName
RequestUuid
X-FE
X-Micro-Cache
X-Vdms-Version
X-Sucuri-Cache
X-TT-LOGID
Warning
X-WR-MODIFICATION
Host-ID
CDN
Get-Access-Time
Is-Session-Tracking
X-Correlation-ID
X-NGINX-Cache
X-Fstrz
X-Sigma
X-Rocket-Build-Number
X-Sigma-Backend
X-Zalando-Child-Request-Id
X-Served-From
X-Nananana
X-Flow-Id
X-Fpc
Xkeypdq
X-Page-Impression-Id
X-Fastly-Cache-Hits
X-Via-SSL
X-ServedByHost
X-WA
X-Via-Edge
X-Swift-Error
FNAC-ModuleRouting
X-Cdn-Request-ID
Pragrma
Correlation-Id
X-MID
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Shopify-Generated-Cart-Token
X-Planisys-CDN-Cache
X-SB
Cneonction
X-LiteSpeed-Tag
X-VC
X-Cf-Powered-By
X-Request-URL
X-Fe
X-Gen-Id
Server-Id
Xet-Cookie
X-Amzn-Remapped-Date
X-Amzn-Remapped-Connection
X-MiniProfiler-Ids
V-Cache
X-Gdpr
X-ServerName
X-Bug-Bounty
RequestId
X-ECache
HitType
X-Dw-Trace-Id
Processtime