Threat Level: green Handler on Duty: Manuel Humberto Santander Pelaez

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
CF-RAY
CF-Cache-Status
Link
X-Powered-By
X-XSS-Protection
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Alt-Svc
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
Content-Security-Policy-Report-Only
X-Generator
X-Cacheable
X-Cache-Status
X-Permitted-Cross-Domain-Policies
X-Xss-Protection
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Template
X-Language
X-Request-ID
X-Iinfo
Status
X-AspNetMvc-Version
X-Content-Security-Policy
Content-Encoding
X-Buckets
X-Kinja-Server-Push
Xkey
Upgrade
X-Via
X-Turbo-Charged-By
Access-Control-Expose-Headers
Keep-Alive
Access-Control-Max-Age
X-Cache-Group
X-Drupal-Dynamic-Cache
X-Pass-Why
P3p
X-Age
EagleId
X-Backend
X-Robots-Tag
X-Envoy-Upstream-Service-Time
X-Amz-Request-Id
X-Amz-Id-2
X-Page-Speed
X-Ua-Compatible
X-CDN
X-Pingback
X-Server-Powered-By
X-Proxy-Cache
X-Hacker
X-UA-Device
X-Server
X-AH-Environment
Request-Context
X-Nginx-Cache-Status
Grace
X-Swift-SaveTime
X-Swift-CacheTime
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-Cdn
X-LiteSpeed-Cache
Cf-Railgun
X-Amz-Version-Id
X-Server-Id
X-WebKit-CSP
Feature-Policy
Server-Timing
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-OneAgent-JS-Injection
X-Rq
X-Ac
X-Cnection
X-Cloud-Trace-Context
Report-To
X-Host
X-Response-Time
X-Backend-Server
EagleEye-TraceId
X-Node
Content-Location
Request-Id
X-Origin-Cache
X-Readtime
X-Vhost
X-Application-Context
X-Cache-Lookup
X-Dns-Prefetch-Control
X-ORACLE-DMS-ECID
X-Dispatcher
NEL
X-Origin-Upstream-Status
X-Rack-Cache
X-Ruxit-JS-Agent
Surrogate-Control
X-DataDome
X-ORACLE-DMS-RID
Allow
X-HW
Rating
X-Country-Code
X-FTR-Request-ID
X-Country
X-Clacks-Overhead
X-Url
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-TTL
X-DynaTrace
Fusion-Source
Fusion-Content-Id
Fusion-Component-Id
Fusion-Content-Source
Fusion-Template-Id
X-Instart-Request-ID
X-Goog-Hash
X-MS-InvokeApp
X-Varnish-TTL
X-PC
X-Vname
X-TtlSet
X-Ah-Environment
Verso
RTSS
X-Powered-By-Plesk
X-CST
Public-Key-Pins
X-Px
Edge-Control
X-Recruiting
X-Mod-Pagespeed
X-VARITI-CCR
Pinterest-Generated-By
Display
X-Sol
Response
X-Middleton-Response
Service-Worker-Allowed
X-Middleton-Display
X-D2id
X-Exp-Variant
X-Kinja
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-GoogleNews-Bot
X-Kinja-Build
X-Cdn-Fetch
X-Exp-Id
X-Vcap-Request-Id
X-Version
Accept-CH
SPRequestGuid
X-SharePointHealthScore
X-Akam-SW-Version
X-B3-TraceId
MS-Author-Via
TCN
X-Navigation-Version
X-Abt-Application-Version
Accept-Ch-Lifetime
X-GitHub-Request-Id
X-Powered-CMS
X-RateLimit-Remaining
X-Shard
SPRequestDuration
SPIisLatency
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Upstream
X-Server-Name
X-Amz-Server-Side-Encryption
AR-PoweredBy
Fastly-Restarts
Ar-Sid
AR-CACHE
AR-ATIME
X-Forwarded-Proto
Charset
X-Trace
X-XRDS-Location
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Amz-Rid
Nginx-Cache
X-Debug
Realpath
X-ESI
X-Aspnetmvc-Version
Front-End-Https
AR-Request-ID
X-Ezoic-Cdn
X-Cached
X-Shield-Request-Id
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-NF-Request-ID
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
Mrf-Cache-Status
MRF-Tech
X-MSEdge-Ref
X-B3-TraceId-Primal
Access-Control-Request-Method
Pagespeed
Arr-Disable-Session-Affinity
X-FTR-Cache-Status
X-FTR-Expires
X-Country-Code-Real
Paypal-Debug-Id
Content-MD5
DynaTrace
ServerID
X-Id
X-FTR-DC
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Balancer
X-FTR-Realm
X-Goog-Storage-Class
MicrosoftSharePointTeamServices
X-Amz-Meta-S3cmd-Attrs
S
X-T
X-Vcache
X-Fastly-Request-ID
X-Via-JSL
X-Client-IP
X-Varnish-Age
X-DynaTrace-JS-Agent
X-Content-Type
X-VCache
X-Hits
X-Dw-Request-Base-Id
X-Amzn-Trace-Id
X-Correlation-Id
X-FastCGI-Cache
X-Grace
Fastcgi-Cache
X-Accel-Expires
X-SERVER
X-Ser
X-Content-Digest
X-RateLimit-Limit
X-Frontend
Powered
X-FTR-Cache-Host
X-N
PB-PID
Arc-Version
PB-RID
X-Mobile-Rewrite
X-DIS-Request-ID
AMP-Access-Control-Allow-Source-Origin
Server-Name
X-Logged-In
X-Forwarded-For
X-HS-Content-Id
X-HS-Hub-Id
X-B3-Traceid
X-B3-Sampled
Edge-Cache-Tag
TP-L2-Cache
TP-Cache
Accept-Ch
X-GUploader-UploadID
X-Esi
X-Microsite
X-Request-Handler-Origin-Region
X-Zen-Fury
X-Request-Received
X-Request-Processing-Time
X-Type
X-Cache-Age
Backend-Timing
X-Analytics
X-Kinsta-Cache
X-Activity-Id
X-Fastcgi-Cache
X-AppVersion
X-Az
X-IPLB-Instance
X-User-Agent
X-Rid
X-LB-Cache
X-Revision
FilterID
Healthy
X-Node-Name
Retry-After
X-Whom
X-Time
X-F-Cache
Pinterest-Version
X-Cache-Hit
X-Pinterest-Rid
X-Srv
X-NWS-LOG-UUID
Accept-Charset
X-Cache-2
X-Kong-Proxy-Latency
Alternate-Protocol
Server-Node
X-Kong-Upstream-Latency
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Cache-Rule
Cache-Status
X-AOL-HN
X-Content-Options
X-Content-Powered-By
X-Hp-Webp
Surrogate-Key
X-Content-Security-Policy-Report-Only
Refresh
X-Debug-Info
X-Instance
X-Akamai-Edgescape
X-Forwarded-Host
X-Server-ID
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
Access-Control-Allow-Method
DC
X-FW-Serve
X-FW-Server
X-FW-Hash
X-Varnish-Grace
X-Tumblr-Pixel-0
X-Cluster
X-FW-Type
X-Tumblr-Pixel
X-FW-Static
X-Page-Id
X-Jobs
X-Tumblr-User
Cache-Tag
X-Request-Guid
X-FB-Debug
X-Acc-Meta-Resource-Type
X-PHP-Backend
X-B
MS-CV
X-Framework
Source
Frame-Options
X-TA-CDN-Provider
X-Erf-Bev-Bev
Fastcgi-Useragent
X-App-Environment
X-Erf-Bev-Bev-Is-Generated
Tracecode
X-App-Server
X-Hostname
Host
X-Cache-Operation
X-Cache-Key
Actual-Object-TTL
Cleartype
X-Mobile-URL
X-Signature
X-B-Cache
X-Seen-By
X-Cached-By
X-BCube-Filmed-By
X-Geo-Country
X-Cache-Control
X-Host-Name
X-Varnish-Backend
X-Amz-Replication-Status
X-TT
X-Pad
NGB
Upgrade-Insecure-Requests
X-Response-Served-From
X-Adobe-Loc
X-Adobe-Content
X-Mobile
Accept-CH-Lifetime
Liferay-Portal
X-Git-Hash
X-Cache-TTL
X-TT-TIMESTAMP
Payment
X-WebKit-CSP-Report-Only
X-ATG-Version
X-RemovedCookies
X-ProcessESI
Cache-Tv-Group
X-Status
X-Tumblr-Pixel-1
X-TX-ID
X-Cache-Remote
Eomportal-Instance
Webserver
WPE-Backend
X-Tumblr-Pixel-2
X-Cacheable-TTL
X-Handled-By
Ms-Operation-Id
From-Origin
Filters
X-RTag
X-FW-Dynamic
X-Cache-TTL-Remaining
X-UA-Device-Type
X-Drupal-Cache-Tags
X-WA-Info
GEO-INFO
X-RequestSource
X-GeoIP
Xserver
X-Ratelimit-Reset
X-PressLabs-Stats
X-Origin-Server
X-Content-Age
X-Daa-Tunnel
NR-ENABLED
X-Cache-Action
Datacenter
X-Webkit-CSP
X-Storage
X-Edge-Location
Viewport
X-EdgeConnect-Cache-Status
X-Varnish-Hostname
Version
X-Hyper-Cache
X-Wix-Request-Id
X-Accel-Buffering
X-Contextid
X-CF-Powered-By
X-Region
X-DataStream-Cache-Status
Cache
X-Upstream-Proxy
Host-Header
X-Presslabs-Stats
PageSpeed
X-Ua
X-Akamai-Transformed
Meta-Geo
X-Cache-Var
X-Yottaa-Optimizations
X-Cache-Var-Map
X-Yottaa-Metrics
X-ES-SERVER
Load-Balancing
X-RN-RSRV
X-Path-Route
X-IP
S-Cnection
X-Cache-NE
X-Varnish-Server
X-HS-Cache-Config
Cache-Tags
Decoy-Debug-Key
Decoy-Debug-Status
Vix-Hermes-Req-Id
Decoy-Debug-TTL
DB-Nickname
Cache-Name
Ec-Rule-Version
X-Akamai-Request-ID
X-Upgrade-Enabled
X-Loop
X-Labrador-Cache-Channel
X-Tumblr-Pixel-3
X-From
X-Cache-Time
X-Proxy
X-Proto
X-Viewer-Country
X-Origin-Response-Time
X-Via-Fastly
X-Origin
X-PERF
X-NCache
X-Time-Microsecs
X-TNCMS
X-Cache-Config
Ohc-File-Size
X-ApacheServer
X-Section
X-CS
X-Access
Cache-Hits
S-Rt
X-OCL
Cache-Key
Rt-Fastcgi-Cache
X-FC-Vary-Parameters
Azure-Version
Azure-SiteName
X-Cache-Server
X-PCL
Azure-InstanceId
X-Hit
X-JoinUs
X-Format
Azure-RegionName
X-CCM
Azure-SlotName
X-Web-Node
X-Upstream-HT
X-Cache-Enabled
X-Upstream-CT
X-Cache-Grace
Country
X-Backend-TTL
X-Xfnlog-Site
X-Rule
X-Akamai-Request-ID2
X-FireWall-Port
X-Cache-Host
X-Timing-Wait
X-Generated
X-Cluster-Node
Webcakes-App-Name
X-S
X-Backend-Name
Webcakes-App-Version
X-EIG-Tracking-Id
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Hosted-By
TWC-Connection-Speed
Selected-Fe
X-Varnish-Hits
X-Origin-Hint
TWC-Device-Class
Webcakes-Region
TWC-GeoIP-Country
X-Varnish-Cache-Hits
Mn-Server-Ip
X-Drupal-Cache-Contexts
TWC-Locale-Group
X-UnsetCookies
TWC-GeoIP-LatLong
X-Proxy-Build
X-R9-Blue-Green-Version
TWC-Privacy
Property-Id
X-Debug-Cache
Server-Info
X-Human
X-FW-Version
X-Www-Served-By
X-Trace-Id
X-Rendered-As
Now
X-Device-Type
X-Locale
X-Site-Version
Time
OT-Force-Account-Verify
X-VCT
X-APP-VERSION
Release
DSUID
Ohc-Cache-HIT
SRV
X-Element-Page-Cache
Hostname
X-NewRelic-App-Data
X-Vgn-Hpd-Reason
X-OVcl
X-OVcl-Cache
X-Real-IP
X-VG-TLSProxy
X-Redis-Cache
Cteonnt-Length
Fastcgi-X-Cache-Version
X-VG-WebCache
Access-Control-Request-Headers
ServedBy
X-Litespeed-Cache
X-Pubstack
Origin-Edge-Control
Origin-Cache-Control
X-FB-TRIP-ID
X-B3-Spanid
X-CSRF-TOKEN
L5d-Success-Class
Accept-Language
Origin
X-Shopify-Stage
Machine
X-ShopId
X-ShardId
X-Alternate-Cache-Key
X-Tb
X-NC
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-GEO
X-NGENIX-Cache
X-SS-Set-Cookie
Fastly-SSL
X-Oracle-Dms-Rid
X-HS-Combine-CSS
X-Nginx-Cache
NtCoent-Length
X-Environment-Context
X-Cluster-Name
X-Tt-Trace-Tag
X-L-Path
X-UUID
X-Parent-Response-Time
X-No-Session
X-Origin-CC
X-Origin-TTL
X-B3-Parentspanid
IBM-Web2-Location
X-GoCache-CacheStatus
X-Load-Cache
X-ECACHE
X-ServerID
X-Mode
X-App-Version
X-Rocket-Nginx-Bypass
X-Endurance-Cache-Level
X-Magnolia-Registration
Odigeo-Trace-Id
X-Ttl
X-Amzn-Remapped-Content-Length
X-Uri
X-DataStream-Origin-MEX-Latency
Nel
X-LJ-Flow-ID
X-AWS-Id
X-VWS-Id
X-DataStream-MidMile-RTT
We-Hiring
X-Generated-By
X-Is-Bot
NGX
X-Soup
Mail-Subject
Akamai-GRN
X-XRDS-LOCATION
X-CACHE-KEY
Mime-Version
X-Request-Time
CF-IPCountry
Content-Style-Type
BehaviorPad-Version
X-Vtex-Remote-Cache
Xc-Version
Content-Script-Type
Cache-Prefix
X-Worker
X-Vtex-Processado-Em
Cdn-Host
X-S-Maxage
Cdn-Request-Time
X-ScT
X-Server-Time
X-Twitter-Response-Tags
A
X-Trv-Group
X-Transaction
X-SRCache-Key
Apple-News-Services-Handled
Apple-News-Services-Host
Arc-Country
AsisCache
X-VG-WebServer
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
X-Node-Id
MD5-Digest
X-AIR-PT
X-Application
X-Instart-Info
X-G
X-Aed
X-Accel-Expires-Debug
X-A-Dam
X-A-Dcw
X-A-Wwc
X-ARC
X-B-Cookie
X-D
X-DPWN-IS-SECURE
X-Date
X-Destination
X-Connection-Hash
X-Edge-Server
X-CF-Lambda-Fn
X-External-Request-Id
X-CF-Lambda-Version
X-A-Ccd
X-A
X-Developer
X-Detected-As
Memcached
X-Rewrite-Enabled
GEO-REGION-INFO
Fly-Request-Id
X-Rojux
Cross-Origin-Window-Policy
Fly-Cache
X-Request-UUID
X-Region-Sid
X-PAYTM-SRV-ID
T-Server
Viewtype
VivaBuild
Rt-Proxy-Cache
Rendered-Blocks
Meta-Geo-Continent
Mobile-Detection-Method
Node
X-S-Cookie
X-A-Dgt
Request-Time
Backend-Name
X-Oneagent-Js-Injection
ServerName
X-Distributor
X-Fastly-Cache
Fastly-Soc-X-Request-Id
Section-Io-Cache
X-Origin-Expires
X-Origin-Date
X-Developers
X-Hl-Ver
X-Cdn-Srv
X-Azure-Ref
Request-Country
Request-EU
X-Azure-Ref-OriginShield
N-Cache
IsBot
Locale
X-Cache-Bucket
X-Cms-Context
X-MServer
Proxy-Connection
X-SVT-ORM-VERSION
X-Urbn-Site-Id
X-SVT-ORM-RULES
X-VC-Cache
X-SIPLIST1
X-Urbn-Context-Path
X-Up
User-Cache-Control
Uber-Trace-Id
X-Compress-Hint
X-Core-Mission
X-WADP-Cache
X-Cache-FS-Status
X-C
X-Cache-Id
X-Clara-WADP
X-Clientip
X-Variation
X-Block-Status
X-Cache-Info
X-Cdn-Origin
X-VServer
X-Backend-Host
X-Wikidot-Static-Cache
X-Wikidot-Backend
Thinkindot-Control
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
Server-ID
Server-Int
True-Client-Country-4JS
V-Age
X-Auto-Login
X-WebServer
X-We-Are-Hiring
X-App-Name
X-Amz-Meta-Cache-Control
W
X-ABtesting
X-Backend-Url
X-Epic-Correlation-Id
X-Org
X-Sn-Servicetimems
X-Skip-Cache
X-Old-Content-Length
X-Nginx-Cache-Key
X-Matched-Rule
X-Method
X-PHP-Host
X-Platform-Server
X-Release
X-Request-Start
X-Request-URI
X-Reboot
X-Rebelmouse-Surrogate-Control
X-Policy
X-Rebelmouse-Cache-Control
X-Location
X-LI-UUID
X-TrackingId
X-GDPR
X-Gen-Mode
X-Flog
X-Fetched-On
X-ElasticPress-Search
X-ServiceProvider
X-Generation-Time
X-Geo-Header
X-Li-Fabric
X-Li-Pop
X-LI-Proto
X-IN-APIGATEWAYSSL
X-Hnp-Log
X-Hello
X-Thinkindot-L3
X-Distil-CS
X-IN-APIGATEWAY
Esi-Enabled
Countrycode
X-Via-CDN
AKAMAI
Magicmarker
Fastly-SIE
Gh-Request-Id
Platform
Fastly-SWR
Adler-Geo
Content-Disposition
RNT-Time
RNT-Machine
Is-Eu
CDCHOST
L
X-BYPASS-REASON
X-Microcachable
X-DC
X-ProxyCache-Status
X-ProxyCache-Key
X-Device-Os
X-User
X-Servername
X-Debug-Cookies
Ha-Gx-Prefs
X-Thanos
X-CUA
X-Debug-Cache-Fetch
X-SD-PageType
X-CGP
X-Debug-Cache-Store
HA-Ipaddr
X-Debug-Log
X-Generated-In
X-RateLimit-Remaining-Second
X-Level-Front-Cache
X-B3-SpanId
X-RateLimit-Limit-Second
X-Proxy-Upstream
X-Owner
X-Proxy-Cache-Status
X-NX-Host
SD-X-WS
X-Irp-Debug
X-Say-Cacheable
X-Say-TTL
X-SayCDN-TTL
X-Generated-On
X-GeoIP-City
X-Internal-Host
X-Reqid
X-Eu-Site
X-Debug-Cache-Expiry
X-BBXSRF
X-Backend-State
X-Guploader-Uploadid
PFcat
X-Bip
Web-Mar-Node
Pagetype
Kp-EeAlive
Wxu-Next-Commit
X-Server-IP
X-Webstats-RespID
X-Swa-Ws
X-Dispatch
Wxu-Next-Region
Wxu-Next-Hostname
Served-By
X-Dispatcher-Server
X-Hash
Heartbleed
Resin-Trace
SS
X-Qloud-Router
Pramga
X-MSEdge-Flight
X-Key
Memory
Server-Host
X-MSEdge-Features
X-Cdn-Forward
X-Zipkin-Id
X-Proxied
X-Routing-Service
X-FPC
X-Var-Ttl
X-Response-By
X-COUNTRY
X-Service
X-JWT-State
X-Is-Gdpr
X-Has-Esi
X-Dc
X-Wa
X-Unique-ID
X-Dynatrace
X-IPS-LoggedIn
X-Servedbyhost
Cache-Provider
Country-Code
Srv
Cache-Cookie-Set-From
X-URL
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-Idcheck
X-Page-Type
X-NWS-UUID-VERIFY
REQUESTUUID
X-Tec-Api-Origin
X-Info
X-RateLimit-Reset
X-Tec-Api-Root
X-Tec-Api-Version
X-MP-GENERATED-AT
UCS
X-Nc
X-UA
X-Lb-Id
X-Geo
X-Ratelimit-Limit
X-VCL-Version
Powered-By-ChinaCache
X-Svr
X-Cache-URL
X-Be
X-Datadome
X-Cache-Backend
ProcessTime
X-Logtrace-Id
Ajk
X-Processor
X-HTML-Minification-Powered-By
X-CDN-Forward
CACHE
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Request-Id
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
Proxy-Firewall
X-HS-Status
X-Scheme
X-Instart-Isnd
X-SRV
X-Trafficlayer-App-Name
X-Trafficlayer-App-Scope
X-Tb-Optimization-Total-Bytes-Saved
X-Pjax-Url
X-SN
X-Varnish-Beresp-Ttl
PICS-Label
X-Ruxit-Js-Agent
SN
X-Cache-Category-Id
X-Grey
Powered-By
X-NodeID
Dynatrace
X-ZONE
X-Webkit-Csp
X-Zone
X-Dynatrace-Js-Agent
XServer
X-Ftr-Request-Id
Group
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
Fastly-Backend-Name
X-TH-Server
Ttl
X-Pf-Uncompressing
X-Server-W
X-Source
X-GRACE
GeoIP-Country-Code
Cache-Host
GeoIP-Latitude
GeoIP-City
X-EC-Lua
X-Newrelic-Synthetics
X-Cache-Ttl
X-LiteSpeed-Cache-Control
X-FORWARDED-FOR
X-RCS-CacheZone
X-PF-Uncompressing
X-LAGOON
X-Sucuri-Id
MIME-Version
X-APP
X-Ms-Request-Id
LB
X-Bc
GW-Server
X-Ms-Version
X-Via-Ucdn
X-NODE
X-Check-Cacheable
X-Varnish-Beresp-TTL
X-Ftr-Cache-Host
X-Gannett-Site-Version
CF-Cached-On
X-Varnish-Url
GeoIp-Country-Code
Cdn
X-Secret
Geoip-Latitude
Environment
Geoip-City
X-Session-Fingerprint
X-Cache-Debug
X-Ratelimit-Remaining
WZWS-RAY
X-Tt-Trace-Host
X-Fastly-Country-Code
Lfy
X-BC
Pics-Label
X-Aicache-OS
X-Varnish-Cacheable
X-Agile-Age
X-Agile
On-Server
X-Edge
X-CDN-Cache
X-Agile-Id
X-SERVER-NAME
User-Agent
X-GeoIP-Country-Code
X-Akamai-SSL-Client-Sid
X-PJAX-URL
X-7Graus-Varnish-Cache-Control
X-7Graus-Varnish-XKeys
WWW
X-Ftr-Backend-Server
X-Ftr-Dc
X-Ftr-Balancer
X-Ftr-Realm
X-Ftr-Backend
X-Mid
Requestid
X-Cache-Miss-From
X-Logging-Id
M-TraceId
X-Sedo-Request-Id
Ohc-Response-Time
Inserted-Into-Cache-At
Cf-Ipcountry
X-Fastly-Backend-Reqs
X-Cache-Tag
SID
X-BE
X-Varnish-Ttl
X-NU-AKA-ACS-Version
X-CSRF-Token
X-MCACHE
X-Vcl-Version
Amp-Access-Control-Allow-Source-Origin
X-Litespeed-Cache-Control
X-Render-Time
X-Crawler
X-Core-Value
Who
X-UPSTREAM-Address
DataCenter
Lb
X-Unique-Id
X-Proxy-Cacherz
X-Newrelic-App-Data
X-LB-ID
Xkeyrz
X-Action
X-RSL
X-RPS
Cdncip
Cdnsip
X-AK-Request-ID
X-RPM
X-DW
X-DB
X-DI
X-DSS
URI
X-Sucuri-ID
HostName
X-WR-MODIFICATION
RequestUuid
X-Vdms-Version
X-Micro-Cache
CDN
Host-ID
X-TT-LOGID
X-FE
Is-Session-Tracking
Warning
Get-Access-Time
X-Correlation-ID
X-NGINX-Cache
X-Flow-Id
X-Sigma
X-Rocket-Build-Number
X-Via-SSL
X-Via-Edge
X-Fastly-Cache-Hits
X-Page-Impression-Id
X-Zalando-Child-Request-Id
X-ServedByHost
X-Sigma-Backend
X-Sucuri-Cache
X-Nananana
Xkeypdq
X-Fstrz
X-WA
X-Fpc
X-Served-From
X-Swift-Error
X-Cdn-Request-ID
X-Planisys-CDN-Cache
X-LiteSpeed-Tag
Pragrma
Cneonction
X-Planisys-CDN-TTL
FNAC-ModuleRouting
X-MID
X-SB
X-Planisys-CDN-Rules
X-TIME
X-VC
Correlation-Id
X-Cf-Powered-By
X-Shopify-Generated-Cart-Token
Server-Id
X-Gen-Id
X-Amzn-Remapped-Date
X-ECache
HitType
Processtime
X-Request-URL
X-Amzn-Remapped-Connection
X-Fe
X-Bug-Bounty
X-ServerName
V-Cache
Xet-Cookie
X-Gdpr
X-Dw-Trace-Id
X-MiniProfiler-Ids
RequestId