Threat Level: green Handler on Duty: Rob VandenBrink

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Pragma
Accept-Ranges
Last-Modified
Strict-Transport-Security
X-Content-Type-Options
X-Powered-By
CF-RAY
ETag
Link
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Access-Control-Allow-Origin
Content-Security-Policy
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Served-By
X-Varnish
X-Amz-Cf-Id
Referrer-Policy
X-Request-Id
X-Timer
X-AspNet-Version
CF-Cache-Status
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Runtime
Access-Control-Allow-Credentials
X-Download-Options
X-Drupal-Cache
X-Cacheable
X-Generator
Alt-Svc
Content-Security-Policy-Report-Only
X-Xss-Protection
X-AspNetMvc-Version
Status
X-Check
Timing-Allow-Origin
X-Cache-Status
X-Adblock-Key
X-DNS-Prefetch-Control
X-Iinfo
X-Permitted-Cross-Domain-Policies
X-Content-Security-Policy
X-Template
Content-Encoding
X-CDN
X-Language
X-Turbo-Charged-By
X-Request-ID
P3p
Keep-Alive
X-Buckets
X-Type
X-AH-Environment
X-Via
EagleId
Xkey
X-Backend
WPE-Backend
X-Age
X-Pass-Why
Access-Control-Max-Age
X-Cache-Group
X-Server
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Varnish-Cache
X-Pingback
X-Nginx-Cache-Status
Upgrade
X-Server-Powered-By
X-Drupal-Dynamic-Cache
Grace
Access-Control-Expose-Headers
X-Hacker
X-UA-Device
Cf-Railgun
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Ua-Compatible
X-LiteSpeed-Cache
X-Proxy-Cache
X-Envoy-Upstream-Service-Time
X-Page-Speed
Request-Context
X-CST
X-Node
X-Ac
X-Cache-Lookup
X-Device
Content-Location
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cnection
X-WebKit-CSP
X-Amz-Version-Id
X-Host
Surrogate-Control
X-Backend-Server
X-Rack-Cache
X-Response-Time
X-Px
X-Rq
X-Readtime
Allow
Pinterest-Generated-By
X-Application-Context
X-Server-Id
X-Url
X-Instart-Request-ID
X-Clacks-Overhead
EagleEye-TraceId
Request-Id
Server-Timing
X-Country
X-OneAgent-JS-Injection
X-HeyJason
Permitted-Cross-Domain-Policies
X-Do-Not-Hack
Report-To
Rating
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Server-ID
X-Country-Code
X-Cloud-Trace-Context
Edge-Control
X-Varnish-TTL
Charset
X-ESI
X-Powered-CMS
X-Vname
X-TtlSet
X-PC
X-TTL
X-FTR-Request-ID
X-Server-Name
X-CF-Powered-By
X-MS-InvokeApp
X-Cached
X-DataDome
X-Goog-Hash
NEL
X-DynaTrace-JS-Agent
X-Vhost
Feature-Policy
X-Recruiting
Public-Key-Pins
X-Origin-Cache
X-Powered-By-Plesk
X-Dns-Prefetch-Control
X-Geo-Segment
X-Kinja-Server
X-GoogleNews-Bot
X-Kinja-Revision
X-Kinja-Build
X-Kinja
X-Exp-Id
X-Cdn-Fetch
X-Exp-Variant
X-VARITI-CCR
X-F-Cache
X-T
X-DynaTrace
X-Mod-Pagespeed
X-Version
X-D2id
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Upstream-Env
Pinterest-Version
X-Pinterest-Rid
Verso
X-Abt-Application-Version
X-Client-IP
X-Dispatcher
SPRequestGuid
X-SharePointHealthScore
X-SRCache-Store-Status
PB-PID
X-SRCache-Fetch-Status
PB-RID
X-Mobile-Rewrite
Arc-Version
X-N
Content-MD5
X-Cdn
RTSS
X-Forwarded-Proto
X-Amz-Rid
X-Hits
X-GitHub-Request-Id
X-Navigation-Version
AR-PoweredBy
AR-ATIME
X-Dw-Request-Base-Id
Nginx-Cache
AR-CACHE
X-Ttl
Realpath
X-B
Paypal-Debug-Id
X-Oneagent-Js-Injection
X-Content-Digest
X-Upstream
X-Pad
X-Grace
X-TEC-API-ORIGIN
X-Content-Options
X-TEC-API-VERSION
X-TEC-API-ROOT
SPIisLatency
SPRequestDuration
X-Ruxit-JS-Agent
X-Id
X-Shield-Request-Id
X-Varnish-Age
X-Kinsta-Cache
X-Goog-Generation
X-Goog-Metageneration
Arr-Disable-Session-Affinity
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-NWS-LOG-UUID
X-Goog-Stored-Content-Encoding
MS-Author-Via
Access-Control-Request-Method
X-Acc-Meta-Resource-Type
TCN
X-Cache-Hit
X-Logged-In
X-Mrf-Item-Lastmod
MRF-Tech
X-Mrf-Section-Lastmod
Mrf-Cache-Status
DynaTrace
S
X-Trace
X-Vcap-Request-Id
X-Zen-Fury
X-Origin-Upstream-Status
X-HW
X-MSEdge-Ref
Front-End-Https
X-DIS-Request-ID
Cleartype
Eomportal-Instance
X-Frontend
X-FTR-Expires
X-FTR-Realm
Surrogate-Key
X-Country-Code-Real
X-FTR-Backend
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-DC
X-FTR-Cache-Status
X-HS-Hub-Id
X-HS-Content-Id
X-Cache-Rule
X-PressLabs-Stats
X-VCache
X-Via-JSL
X-Fastly-Request-ID
X-NF-Request-ID
X-User-Agent
X-XRDS-Location
X-Request-Received
X-Request-Processing-Time
Service-Worker-Allowed
Cache-Status
Tracecode
X-Forwarded-For
AR-SID
Alternate-Protocol
X-Hostname
X-IPLB-Instance
Fastcgi-Cache
Server-Name
X-Fastcgi-Cache
X-Sol
X-Middleton-Display
Display
X-Varnish-Backend
X-Analytics
Backend-Timing
Host
X-FastCGI-Cache
Rt-Fastcgi-Cache
FilterID
Viewport
X-AOL-HN
MicrosoftSharePointTeamServices
TP-Cache
Public-Key-Pins-Report-Only
TP-L2-Cache
X-AppVersion
X-Az
X-Activity-Id
X-FTR-Cache-Host
X-Middleton-Response
X-Ser
Response
X-Whom
X-Cache-2
X-Rid
X-XRDS-LOCATION
X-Wix-Server-Artifact-Id
X-SS-Set-Cookie
X-Proxied
X-Revision
ServerID
X-Contextid
X-Srv
X-Content-Powered-By
X-HOST
X-Debug
X-Magnolia-Registration
X-Cache-Control
AMP-Access-Control-Allow-Source-Origin
X-Cached-By
X-Debug-Info
Powered-By-ChinaCache
Refresh
X-B3-Traceid
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
X-Ruxit-Js-Agent
X-Cache-Server
X-Cache-Key
X-Mobile
X-Akam-SW-Version
X-Instance
X-Daa-Tunnel
Server-Info
X-Webkit-Csp
HitInfo
HitType
Accept-Charset
X-Page-Id
X-FB-Debug
X-WPE-Loopback-Upstream-Addr
X-Cache-Age
X-Framework
X-Generated-By
X-LB-Cache
X-Content-Security-Policy-Report-Only
X-App-Server
X-B-Cache
X-App-Environment
X-Signature
X-Request-Guid
X-TT
Retry-After
Cache-Tag
X-Geo-Country
X-BCube-Filmed-By
X-Varnish-Hostname
X-RateLimit-Remaining
X-ATG-Version
X-Tumblr-Pixel-0
X-Origin-Server
X-Handled-By
Source
X-Cache-Operation
X-Tumblr-Pixel
Host-Header
Server-Node
X-PHP-Backend
X-Tumblr-User
X-Device-Type
X-NewRelic-App-Data
X-Varnish-Grace
X-Hyper-Cache
X-APP-VERSION
Upgrade-Insecure-Requests
DC
X-Accel-Expires
X-Amzn-Trace-Id
X-CLOUD-TRACE-CONTEXT
X-Platform-Server
X-Drupal-Cache-Tags
X-WA-Info
X-GUploader-UploadID
X-Newrelic-App-Data
X-Varnish-Server
X-TT-TIMESTAMP
X-Akamai-Edgescape
X-Cache-Action
MS-CV
X-URL
NGB
X-PC-Key
X-PC-AppVer
X-PC-Hit
Webserver
X-B3-Sampled
Pagespeed
X-Locale
Filters
X-WebKit-CSP-Report-Only
X-Jobs
X-Cluster
X-GeoIP
X-Cacheable-TTL
Actual-Object-TTL
X-Node-Name
X-S
ServedBy
X-Source
X-PC-Date
AsisCache
X-PC-Host
X-Accel-Buffering
X-Tumblr-Pixel-1
X-FW-Type
X-FW-Static
X-Seen-By
X-RequestSource
X-RTag
X-FW-Hash
X-Correlation-ID
X-Wix-Petri-Ex
X-FW-Serve
Liferay-Portal
Fastly-Restarts
X-Tumblr-Pixel-2
X-FW-Server
X-Wix-Request-Id
S-Cnection
X-Varnish-Hits
X-Port
Served-By
X-Edge-Location
X-Cache-Config
X-Distil-CS
Datacenter
X-Amz-Meta-S3cmd-Attrs
X-Correlation-Id
X-Amz-Replication-Status
X-Cache-TTL-Remaining
X-UA
X-Vg-Webcache
X-Region
GEO-INFO
Country
Cache
Ohc-File-Size
X-TA-CDN-Provider
X-Ocache
Cartoon
X-Guploader-Uploadid
Content-Script-Type
X-Drupal-Cache-Contexts
Content-Style-Type
X-Dynatrace-Js-Agent
HostName
X-Edge-Cache-Key
X-Cache-Remote
X-UA-Device-Type
X-Sucuri-ID
X-Edge-Cache
X-GZip
X-Internal-Host
X-RateLimit-Limit
Ar-Sid
X-ServedBy
X-UUID
X-Esi
X-Adobe-Content
X-Microcachable
X-Adobe-Loc
X-Real-IP
AR-Request-ID
X-Status
X-Akamai-Transformed
X-Proxy
X-Varnish-IP
X-Yottaa-Optimizations
X-Cache-Ttl
X-Yottaa-Metrics
X-DataStream-Cache-Status
X-Unique-ID
Xserver
X-Detected-As
X-Akamai-Request-ID
Access-Control-Allow-Method
X-App-Name
X-IP
X-Rendered-As
X-Path-Route
Meta-Geo
X-JoinUs
Load-Balancing
Machine
X-RN-RSRV
X-Is-Bot
X-Generated
X-Ezoic-Cdn
User-Agent
Healthy
Mn-Server-Ip
X-Proxy-Build
X-Amz-Server-Side-Encryption
X-Agile-Id
X-Agile-Age
X-Agile
Selected-FE
X-Timing-Wait
X-Loop
X-OVcl
X-OVcl-Cache
X-Grey
X-Cache-Category-Id
X-Mode
X-Backend-Name
X-TNCMS
X-Web-Node
IBM-Web2-Location
X-Varnish-Cacheable
X-Varnish-Cache-Hits
Payment
Backend
X-Origin
X-ProxyCache-Key
X-BYPASS-REASON
X-ServerID
S-Rt
ServerName
X-FC-Vary-Parameters
X-Hosted-By
X-Human
X-Debug-Cache
X-Tb
User-Cache-Control
X-BB-IP
X-Time-Microsecs
X-ProxyCache-Status
X-Upgrade-Enabled
Azure-RegionName
Azure-SiteName
Now
X-Site-Version
X-Content-Type
X-CDN-Cache
Azure-SlotName
Azure-Version
DB-Nickname
L5d-Success-Class
X-ApacheServer
Cache-Key
SRV
X-Distributor
Azure-InstanceId
X-NCache
X-NodeID
Cache-Name
X-PERF
X-ProcessESI
X-Instance-Name
X-Original-Request
X-EIG-Tracking-Id
X-RemovedCookies
X-CDN-Forward
Webcakes-App-Version
TWC-Privacy
Webcakes-App-Name
TWC-GeoIP-LatLong
TWC-GeoIP-Country
Property-Id
TWC-Connection-Speed
TWC-Device-Class
Webcakes-Region
X-Routing-Service
X-Access
X-Origin-Hint
X-OCL
X-LJ-Flow-ID
X-AWS-Id
X-Section
X-SplitTest
X-TWH-CORRELATION-ID
X-PCL
X-TX-ID
TWC-Locale-Group
X-VWS-Id
X-Vgn-Hpd-Reason
X-Viewer-Country
Dont-Set-Cookie
X-Zipkin-Id
X-Www-Served-By
X-Time
X-Pubstack
X-Via-Fastly
X-Format
X-Amz-Meta-Surrogate-Control
X-Origin-CC
X-MP-GENERATED-AT
X-Xfnlog-Site
LB
X-NGENIX-Cache
X-CCM
X-Litespeed-Cache
X-Rocket-Nginx-Bypass
X-Storage
X-Nc
Cache-Hits
Countrycode
X-HS-Cache-Config
X-Webstats-RespID
Edge-Cache-Tag
X-Generation-Time
X-Proto
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Sucuri-Cache
X-B3-Spanid
X-Geo
X-Newrelic-Synthetics
X-Cache-HT
X-Optimization
Access-Control-Request-Headers
X-Labrador-Cache-Channel
Apicache-Version
Apicache-Store
X-Cache-NE
X-Dc
Accept-CH
X-Cache-Backend
WZWS-RAY
X-SERVER-NAME
X-Meta-Tbi-Cache-Vertical
X-Environment-Context
X-Birta-Served
X-Birta-Cache-Post
X-L-Path
X-Tumblr-Pixel-3
X-Twitter-Response-Tags
X-Transaction
X-Connection-Hash
Fastly-SSL
X-Webkit-CSP
X-Oss-Request-Id
X-Servedby
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
X-Oss-Object-Type
X-Real-Ip
Ec-Rule-Version
From-Origin
X-CACHE-GROUP
Ws
X-Hit
NnCoection
X-Qnm-Cache
X-M-Log
X-M-Reqid
PageSpeed
X-EdgeConnect-Cache-Status
X-Alicdn-Da-Ups-Status
X-Rule
X-Varnish-Beresp-Grace
Cteonnt-Length
NODE
X-Varnish-Beresp-Status
Ms-Operation-Id
X-SERVER
X-Cache-Enabled
Country-Code
X-UE-Client-Country
X-Trv-Group
Cneonction
X-D
X-CF-Lambda-Version
X-Date
X-CF-Lambda-Fn
Fastly-Soc-X-Request-Id
Fly-Request-Id
Fly-Cache
X-TT-LOGID
X-Developer
X-From
X-Fetched-On
X-G
X-We-Are-Hiring
X-Generated-In
X-Via-Edge
X-Via-CDN
BehaviorPad-Version
X-Destination
X-Thinkindot-L3
X-Died
V-Age
Cache-Prefix
Host-ID
Resin-Trace
Warning
VivaBuild
Www
X-A
X-A-Dam
X-A-Ccd
Server-Host
SN
Thinkindot-Control
Viewtype
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-SRCache-Key
T-Server
Rendered-Blocks
X-SVT-ORM-RULES
MD5-Digest
X-Application
X-ARC
X-B-Cookie
X-BBXSRF
X-BB-ID
Meta-Geo-Continent
MI-Cache
X-SVT-ORM-VERSION
X-A-Dcw
X-A-Dgt
X-A-Wwc
MI-Cache-Age
X-Accel-Expires-Debug
GMS-Ver
X-VG-WebServer
X-Upstream-CT
X-Matched-Rule
X-Upstream-HT
X-S-Cookie
X-Planisys-CDN-Cache
X-Region-Sid
X-Rojux
X-Wix-Route-ID
Xc-Version
X-Rewrite-Enabled
X-Planisys-CDN-Rules
X-PAYTM-SRV-ID
X-ScT
X-MI-In-Market
X-Hl-Ver
X-Org
X-NU-AKA-ACS-Version
X-Hash
X-Planisys-CDN-TTL
X-Response-By
X-Server-Time
X-Server-By
X-V
X-HS-Combine-CSS
ProcessTime
X-C
X-Clientip
Decoy-Debug-TTL
Decoy-Debug-Status
Decoy-Debug-Key
X-Backend-State
X-Core-Mission
X-ServiceProvider
X-Crawler
X-Req
Origin-Cache-Control
X-Cache-URL
X-Nf-Srv-Version
X-Backend-Url
NGX
X-Cache-Bucket
Origin-Edge-Control
PFcat
X-P-T
Proxy-Connection
X-Dispatcher-Server
X-CS
X-Release
Release
Apple-News-Services-Parsed-Url
X-Server-IP
X-IN-WAF
Server-Int
Server-ID
X-Node-Id
X-IN-SSL-APIGATEWAY
X-IN-APIGATEWAY
X-SIPLIST1
Uber-Trace-Id
X-WebServer
X-GeoIP-Country-Code
X-GeoIP-City
X-Logtrace-Id
X-Edge-IP
Apple-News-Services-Request-Url
Apple-News-Services-Host
X-S-Maxage
X-Backend-Host
X-No-Session
X-Ver
Apple-News-Services-Handled
Ajk
IsBot
X-RCS-CacheZone
X-Nginx-Cache
X-ElasticPress-Search
X-CCM-LastModified
X-Rebelmouse-Cache-Control
X-Alternate-Cache-Key
X-Returned-From
X-Returned-From-DLL
Web-Mar-Node
X-Returned-From-PostProcessResponse
X-Server-Group
Who
X-Returned-From-BeforeDispatch
X-Rebelmouse-Surrogate-Control
X-Reboot
X-Request-URI
X-Sf
X-Actual-URL
X-Passed-To-BeforeDispatch
X-Sorting-Hat-PodId
X-Env
X-Info
X-Device-Os
X-Developers
X-Debug-Cookies
X-Debug-Log
X-ShopId
X-Epic-Correlation-Id
X-Eu-Site
X-Hnp-Log
X-HCF
X-Shopify-Stage
X-Gen-Mode
X-Sn-Servicetimems
X-F5-Cache
X-Fastly-Cache
X-Forwarded-Host
X-NX-Host
X-Core-Value
X-Cache-Control-Set-By
X-Cache-Expires
X-Cache-Srv
X-Cache-ASPX
X-Block-Status
X-Sorting-Hat-ShopId
X-Platform
X-Backend-TTL
X-Cdn-Origin
X-Phone
X-CGP
X-Origin-Expires
X-Origin-Date
X-Passed-To
X-Passed-To-DLL
X-Cdn-Srv
X-Passed-To-PostProcessResponse
X-ShardId
Origin
X-Trace-Id
X-Cache-Host
Fastly-SWR
Fastly-SIE
X-Edge-Server
X-UnsetCookies
X-Cache-CFC
HA-Cloudapp
HA-Geolat
HA-Geolon
HA-Geocountry
Pragrma
X-Amz-Meta-Cache-Control
HA-Geocity
Cache-Tags
X-Up
X-DPWN-IS-SECURE
X-VServer
X-App-Version
X-Wikidot-Backend
X-Worker
X-Wikidot-Static-Cache
Time
Adler-Geo
Backend-Name
X-Varnish-HitMiss
AKAMAI
X-VG-TLSProxy
X-Origin-TTL
Platform
Content-Disposition
X-Swa-Ws
MI-API
Request-EU
Cdn-Request-Time
True-Client-Country-4JS
RNT-Time
Ohc-Response-Time
Powered-By
Request-Country
RNT-Machine
On-Server
HA-Georegion
Request-Time
HA-Ipaddr
HA-Servedtime
HA-Host
Ha-Gx-Prefs
Odigeo-Trace-Id
HA-Urlpath
Heartbleed
Cdn-Host
Kp-EeAlive
HTTPS
Httpd-Identifier
Is-Eu
Mime-Version
X-GoCache-CacheStatus
X-Location
X-Fstrz
X-Cache-Time
X-Skip-Cache
RequestId
X-Stale
X-FireWall-Port
X-Var-Ttl
CDCHOST
X-Content-Age
Fastly-Backend-Name
X-Refresh
X-User
X-Croise-Owner
X-Ms-Blob-Type
NtCoent-Length
X-Ms-Version
XServer
X-Ms-Lease-Status
Dnion-Transfer-Encoding
X-Ms-Request-Id
Cdn
Esi-Enabled
X-Ckpd-Fst-Backend
X-From-Cache
X-Micro-Cache
X-Redis-Cache
X-Servername
X-Varnish-Beresp-Ttl
X-Pjax-Url
X-CSRF-Token
X-B3-TraceId
X-WR-MODIFICATION
X-Cdn-Forward
X-MSEdge-Flight
X-Pf-Uncompressing
X-MSEdge-Features
X-Cache-FS-Status
X-Via-SSL
GW-Server
UCS
X-GRACE
WP-Super-Cache
X-TIME
Dynatrace
X-Powered-By-ANYU
WWW-Authenticate
X-Cache-Handler
X-Varnish-Url
Get-Access-Time
CF-IPCountry
Is-Session-Tracking
X-Varnish-Beresp-TTL
X-COUNTRY
X-Request-Time
X-Varnish-Id
X-Key
PICS-Label
X-Owner
Rt-Proxy-Cache
Frame-Options
X-Csrf-Token
X-NWS-UUID-VERIFY
Memcached
X-GDPR
NodeID
X-Bip
X-Aicache-OS
X-Kong-Upstream-Latency
X-Ua
X-Hail-Hydra
PageType
X-CUA
X-Kong-Proxy-Latency
X-Thanos
X-Atg-Version
X-Cache-Id
X-Response-Served-From
Mail-Subject
X-External-Request-Id
X-Page-Type
We-Hiring
GeoIp-Country-Code
Memory
Geoip-City
X-Be
Geoip-Latitude
FastCGI-Cache
X-NC
X-Cache-TTL
X-Cluster-Node
X-Via-NSCOPI
MIME-Version
X-LiteSpeed-Cache-Control
X-Dynatrace
Section-Io-Cache
Sta2Tusw
X-DataStream-Origin-MEX-Latency
X-DataStream-MidMile-RTT
CACHE
X-ServedByHost
X-Auto-Login
Version
X-Nananana
X-DC
X-TId
Magicmarker
X-Fastly-Backend-Reqs
X-UPSTREAM-Address
If-Modified-Since
X-Varnish-Action
X-Servedbyhost
X-StackifyID
X-CACHE-KEY
X-Frame-Option
X-Tid
X-Load-Cache
Node
GeoIP-Country-Code
X-Request-UUID
GeoIP-City
X-BE
GeoIP-Latitude
Pagetype
Processtime
COMMERCE-SERVER-SOFTWARE
X-GEO
X-Variation
X-PAGE-TYPE
X-Sentry-ID
X-Ig-Deployment-Stage
X-EC-Security-Audit
X-Shard
X-Irp-Debug
X-Pc-Hit
X-Pc-Key
X-ADI-VCache
RATING
URI
X-Server-W
X-Varnish-Ttl
Pramga
X-Shield-Cache-Expires
X-Proxy-Server
Pics-Label
X-Pc-Appver
X-Bug-Bounty
X-Pc-Host
V-Cache
Group
CDN
X-Pc-Date
Sid
X-FORWARDED-FOR
X-Public
Arc-Country
X-Wa
X-Haproxy-Ip
X-Haproxy-Hostname
X-Varnish-URL
X-Gdpr
X-Ibm-Trace
X-Datadome
X-Vcache
Srv
Cache-Cookie-Set-From
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
X-HTML-Minification-Powered-By
Cf-Ipcountry
X-SRV
Cache-Provider
X-ND-Cache
X-Surge-Debug
X-Endurance-Cache-Level
X-Cache-Debug
X-Layer
X-Fastly-Cache-Hits
X-Ratelimit-Remaining
X-FW-Version
Fastcgi-Useragent
OT-Force-Account-Verify
X-RateLimit-Limit-Second
X-Nginx-Cache-Key
X-RateLimit-Remaining-Second
X-Sorting-Hat-PodId-Cached
X-Sorting-Hat-FeatureSet
REQUESTUUID
X-PF-Uncompressing
DataCenter
X-PJAX-URL
X-ID
Accept-Ch
X-Sorting-Hat-PrivacyLevel
X-Gen-Id
GEO-REGION-INFO
X-Sorting-Hat-Section
X-Sorting-Hat-ShopId-Cached
X-Ratelimit-Limit
X-GZIP
X-B3-SpanId
X-Dw-Trace-Id
Fastcgi-X-Cache
X-Ms-Lease-State
X-Feature
X-RequestId
X-Cache-Var-Map
X-Cache-Var
Fastcgi-X-Cache-Version
N-Cache
X-APP
X-CacheKey
Powered
X-Litespeed-Cache-Control
Serverid
Hostname
X-Distil-Cs
Lb
X-CDN-Pop
X-CDN-Pop-IP
X-Policy
X-SB
X-Front
X-VC
X-RAMCache
X-Varnish-Info
X-NGINX-Cache
Xet-Cookie
X-Gannett-Site-Version
X-Secret
X-WA
X-Grace-Duration
X-ServerName
X-Served-From
X-Requestid
X-Amzn-Remapped-Connection
X-Cookie
X-HS-Status
X-Amzn-Remapped-Date
X-Unique-Id
X-VG-WebCache
X-Varnish-ID
Requestid
X-Fe
X-Akamai-ERRuleID
X-Akamai-ERPolicy
X-Request-Start