Threat Level: green Handler on Duty: Manuel Humberto Santander Pelaez

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
CF-RAY
CF-Cache-Status
Link
X-Powered-By
X-XSS-Protection
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Alt-Svc
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
Content-Security-Policy-Report-Only
X-Generator
X-Cacheable
X-Cache-Status
X-Permitted-Cross-Domain-Policies
X-Xss-Protection
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Template
X-Language
X-Request-ID
X-Iinfo
Status
X-Content-Security-Policy
Content-Encoding
X-AspNetMvc-Version
X-Buckets
X-Kinja-Server-Push
Xkey
Upgrade
X-Via
Access-Control-Expose-Headers
X-Turbo-Charged-By
Keep-Alive
Access-Control-Max-Age
X-Cache-Group
X-Drupal-Dynamic-Cache
X-Pass-Why
P3p
X-Age
EagleId
X-Backend
X-Robots-Tag
X-Envoy-Upstream-Service-Time
X-Amz-Id-2
X-Amz-Request-Id
X-Page-Speed
X-Ua-Compatible
X-Pingback
X-Server-Powered-By
X-Proxy-Cache
X-Hacker
X-CDN
X-UA-Device
X-AH-Environment
Request-Context
X-Nginx-Cache-Status
Grace
X-Server
X-Swift-SaveTime
X-Swift-CacheTime
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-Cdn
X-LiteSpeed-Cache
Cf-Railgun
X-Amz-Version-Id
X-Server-Id
X-WebKit-CSP
Feature-Policy
Server-Timing
X-Device
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
X-Rq
X-Ac
X-Cnection
X-Cloud-Trace-Context
Report-To
X-Host
X-Response-Time
EagleEye-TraceId
X-Node
X-Backend-Server
Content-Location
Request-Id
X-Origin-Cache
X-Readtime
X-Vhost
X-Application-Context
X-Cache-Lookup
X-Dns-Prefetch-Control
X-ORACLE-DMS-ECID
X-Dispatcher
NEL
X-Origin-Upstream-Status
X-ORACLE-DMS-RID
X-Rack-Cache
X-Ruxit-JS-Agent
Surrogate-Control
X-DataDome
Allow
X-HW
Rating
X-Country-Code
X-FTR-Request-ID
X-Country
X-Clacks-Overhead
X-TTL
X-Url
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-DynaTrace
X-Instart-Request-ID
Fusion-Content-Source
Fusion-Content-Id
Fusion-Source
Fusion-Component-Id
Fusion-Template-Id
X-Goog-Hash
X-MS-InvokeApp
X-Varnish-TTL
X-TtlSet
X-Vname
X-PC
X-Ah-Environment
Verso
RTSS
X-Powered-By-Plesk
X-CST
X-Aspnetmvc-Version
Public-Key-Pins
X-Px
Edge-Control
X-Recruiting
X-VARITI-CCR
X-Mod-Pagespeed
Pinterest-Generated-By
X-Sol
Response
Display
X-Middleton-Display
X-Middleton-Response
Service-Worker-Allowed
X-D2id
X-Kinja-Revision
X-Use-Magma
X-Kinja-Server
X-Kinja-Build
X-Exp-Variant
X-Cdn-Fetch
X-GoogleNews-Bot
X-Exp-Id
X-Kinja
Accept-CH
X-B3-TraceId
X-Vcap-Request-Id
X-Version
SPRequestGuid
X-SharePointHealthScore
X-Akam-SW-Version
MS-Author-Via
TCN
X-Navigation-Version
X-Abt-Application-Version
X-GitHub-Request-Id
X-Powered-CMS
X-RateLimit-Remaining
SPRequestDuration
SPIisLatency
X-Shard
X-TEC-API-ORIGIN
X-Server-Name
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Upstream
AR-CACHE
Accept-Ch-Lifetime
Ar-Sid
AR-ATIME
AR-PoweredBy
Charset
Fastly-Restarts
X-Forwarded-Proto
X-Amz-Server-Side-Encryption
X-XRDS-Location
X-Trace
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Amz-Rid
Realpath
Nginx-Cache
X-Debug
X-ESI
Front-End-Https
AR-Request-ID
X-Ezoic-Cdn
X-Cached
X-Shield-Request-Id
X-Goog-Stored-Content-Length
X-Goog-Generation
X-NF-Request-ID
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Mrf-Item-Lastmod
MRF-Tech
X-MSEdge-Ref
Access-Control-Request-Method
Arr-Disable-Session-Affinity
X-SERVER
X-Country-Code-Real
X-FTR-Expires
X-FTR-Cache-Status
Paypal-Debug-Id
Content-MD5
Pagespeed
X-Id
ServerID
MicrosoftSharePointTeamServices
X-FTR-Backend-Server
X-FTR-Realm
DynaTrace
X-FTR-DC
X-FTR-Backend
X-FTR-Balancer
X-Goog-Storage-Class
X-VCache
X-T
X-Amz-Meta-S3cmd-Attrs
S
X-Fastly-Request-ID
X-Via-JSL
X-Client-IP
X-Varnish-Age
X-DynaTrace-JS-Agent
X-Content-Type
X-Vcache
X-Hits
X-Dw-Request-Base-Id
X-Amzn-Trace-Id
X-Correlation-Id
X-FastCGI-Cache
X-Grace
Fastcgi-Cache
X-Accel-Expires
X-Ser
X-Frontend
X-Content-Digest
Powered
X-RateLimit-Limit
X-FTR-Cache-Host
X-N
Arc-Version
X-Mobile-Rewrite
PB-RID
PB-PID
X-DIS-Request-ID
AMP-Access-Control-Allow-Source-Origin
Server-Name
X-Logged-In
X-Forwarded-For
X-HS-Content-Id
X-HS-Hub-Id
X-B3-Sampled
Edge-Cache-Tag
TP-L2-Cache
TP-Cache
X-Esi
X-GUploader-UploadID
X-Microsite
X-Request-Handler-Origin-Region
X-Zen-Fury
X-Request-Received
X-Request-Processing-Time
X-Cache-Age
X-Type
X-Analytics
X-Activity-Id
X-AppVersion
X-Kinsta-Cache
X-IPLB-Instance
X-Rid
X-Az
Backend-Timing
X-User-Agent
X-Revision
X-Fastcgi-Cache
X-LB-Cache
FilterID
Healthy
X-B3-Traceid
X-Whom
X-Node-Name
X-Time
Accept-Ch
X-Pinterest-Rid
Pinterest-Version
Retry-After
X-Cache-Hit
X-Srv
X-F-Cache
X-NWS-LOG-UUID
X-Cache-2
Accept-Charset
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Alternate-Protocol
Server-Node
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Cache-Rule
Cache-Status
X-AOL-HN
X-Content-Options
Surrogate-Key
X-Content-Powered-By
X-Hp-Webp
X-Content-Security-Policy-Report-Only
DC
Refresh
X-Akamai-Edgescape
X-Instance
X-Forwarded-Host
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Debug-Info
X-Server-ID
Access-Control-Allow-Method
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Tumblr-User
X-Jobs
X-FW-Static
X-FW-Server
X-FW-Serve
X-FW-Hash
X-Cluster
X-Varnish-Grace
X-FW-Type
X-Framework
X-Page-Id
X-PHP-Backend
X-Request-Guid
X-B
X-App-Environment
X-Acc-Meta-Resource-Type
Source
X-FB-Debug
MS-CV
Cache-Tag
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-App-Server
X-TA-CDN-Provider
Frame-Options
Fastcgi-Useragent
Tracecode
X-Hostname
Host
X-Cache-Key
X-Cache-Operation
Actual-Object-TTL
X-Mobile-URL
Accept-CH-Lifetime
Cleartype
X-B-Cache
X-Signature
X-Cached-By
X-Seen-By
X-Geo-Country
X-Cache-Control
X-BCube-Filmed-By
X-Amz-Replication-Status
X-Host-Name
X-Cache-TTL
X-Varnish-Backend
X-TT
X-Pad
X-Mobile
NGB
Upgrade-Insecure-Requests
X-Response-Served-From
X-Git-Hash
X-Adobe-Loc
X-Adobe-Content
Liferay-Portal
X-TT-TIMESTAMP
X-WebKit-CSP-Report-Only
Payment
Filters
Cache-Tv-Group
Eomportal-Instance
WPE-Backend
X-ATG-Version
X-Status
X-RemovedCookies
X-ProcessESI
From-Origin
X-TX-ID
X-RTag
X-Cache-Remote
X-Tumblr-Pixel-2
Webserver
Ms-Operation-Id
X-Cacheable-TTL
X-Handled-By
X-Tumblr-Pixel-1
X-Drupal-Cache-Tags
X-FW-Dynamic
X-RequestSource
X-UA-Device-Type
GEO-INFO
X-GeoIP
X-Cache-TTL-Remaining
X-WA-Info
Xserver
X-Origin-Server
X-PressLabs-Stats
X-Ratelimit-Reset
NR-ENABLED
X-Daa-Tunnel
X-Content-Age
X-Cache-Action
X-Edge-Location
X-Webkit-CSP
Datacenter
X-Storage
Viewport
PageSpeed
X-EdgeConnect-Cache-Status
X-Varnish-Hostname
Version
X-Hyper-Cache
X-Accel-Buffering
X-Contextid
X-Wix-Request-Id
X-CF-Powered-By
X-Region
X-DataStream-Cache-Status
Cache
X-Upstream-Proxy
Host-Header
X-Ua
X-Akamai-Transformed
X-Presslabs-Stats
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-ES-SERVER
X-Varnish-Server
X-Cache-Var
X-Cache-Var-Map
Meta-Geo
X-RN-RSRV
X-Path-Route
Load-Balancing
X-Cache-NE
X-IP
Ohc-File-Size
S-Cnection
Cache-Name
X-HS-Cache-Config
Cache-Tags
X-Origin
X-NCache
X-Cache-Enabled
Rt-Fastcgi-Cache
X-CS
Cache-Hits
X-From
X-Loop
X-Labrador-Cache-Channel
X-Cache-Config
X-Viewer-Country
X-Access
X-Tumblr-Pixel-3
Ec-Rule-Version
X-Upgrade-Enabled
X-Section
X-Akamai-Request-ID
X-Time-Microsecs
X-Akamai-Request-ID2
X-ApacheServer
X-Origin-Response-Time
X-Cache-Time
X-PERF
X-Proto
Decoy-Debug-Key
DB-Nickname
X-TNCMS
X-Via-Fastly
X-Proxy
Decoy-Debug-Status
Decoy-Debug-TTL
Vix-Hermes-Req-Id
Azure-SlotName
Azure-SiteName
Country
Mn-Server-Ip
Cache-Key
Azure-Version
X-Proxy-Build
X-Backend-TTL
X-OCL
X-JoinUs
X-Origin-Hint
X-Xfnlog-Site
X-Web-Node
Azure-RegionName
X-Hit
X-Format
X-Cache-Grace
X-Cache-Host
X-R9-Blue-Green-Version
X-CCM
X-Cluster-Node
X-FC-Vary-Parameters
X-EIG-Tracking-Id
X-PCL
X-Varnish-Cache-Hits
TWC-GeoIP-LatLong
TWC-Locale-Group
TWC-Privacy
TWC-GeoIP-Country
TWC-Device-Class
Selected-Fe
TWC-Connection-Speed
Webcakes-App-Name
Webcakes-App-Version
X-UnsetCookies
X-Upstream-CT
X-Upstream-HT
X-Trace-Id
X-Timing-Wait
X-Rule
Webcakes-Region
S-Rt
Property-Id
X-Cache-Server
Azure-InstanceId
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Hosted-By
X-FireWall-Port
X-Debug-Cache
X-Human
X-Generated
X-S
X-Drupal-Cache-Contexts
X-Varnish-Hits
X-Site-Version
X-Backend-Name
X-Locale
X-Www-Served-By
Server-Info
X-Device-Type
X-FW-Version
Release
X-Rendered-As
X-VCT
Now
DSUID
Time
OT-Force-Account-Verify
Ohc-Cache-HIT
SRV
X-Vgn-Hpd-Reason
X-Element-Page-Cache
Hostname
X-OVcl
X-NewRelic-App-Data
X-OVcl-Cache
X-VG-TLSProxy
Cteonnt-Length
ServedBy
X-Real-IP
Fastcgi-X-Cache-Version
X-Redis-Cache
Access-Control-Request-Headers
X-APP-VERSION
Origin-Cache-Control
X-Litespeed-Cache
X-VG-WebCache
X-Pubstack
Origin-Edge-Control
X-FB-TRIP-ID
X-Alternate-Cache-Key
X-ShardId
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Shopify-Stage
X-CSRF-TOKEN
X-ShopId
L5d-Success-Class
Origin
Accept-Language
X-Tb
X-NC
X-GEO
Machine
X-NGENIX-Cache
X-SS-Set-Cookie
NtCoent-Length
Fastly-SSL
X-App-Version
X-HS-Combine-CSS
X-Nginx-Cache
X-B3-Spanid
X-Cluster-Name
X-L-Path
X-No-Session
X-Tt-Trace-Tag
X-Environment-Context
X-UUID
X-Parent-Response-Time
X-Load-Cache
X-B3-Parentspanid
IBM-Web2-Location
X-GoCache-CacheStatus
X-ECACHE
X-ServerID
X-LJ-Flow-ID
X-Mode
X-Origin-TTL
X-VWS-Id
X-Origin-CC
X-AWS-Id
X-Rocket-Nginx-Bypass
X-Magnolia-Registration
X-Generated-By
X-Endurance-Cache-Level
Odigeo-Trace-Id
X-Amzn-Remapped-Content-Length
Nel
X-DataStream-Origin-MEX-Latency
X-DataStream-MidMile-RTT
X-Uri
X-Soup
NGX
Mail-Subject
We-Hiring
Mime-Version
Akamai-GRN
X-Is-Bot
X-CACHE-KEY
X-Request-Time
X-XRDS-LOCATION
CF-IPCountry
X-Transaction
T-Server
X-Application
X-Date
X-Developer
Request-Time
X-D
X-Edge-Server
X-DPWN-IS-SECURE
Fly-Cache
A
X-External-Request-Id
Fly-Request-Id
X-Node-Id
GEO-REGION-INFO
X-Destination
X-Vtex-Processado-Em
X-Detected-As
X-B-Cookie
X-ARC
Xc-Version
Proxy-Connection
X-Vtex-Remote-Cache
X-Instart-Info
X-MServer
X-G
X-VG-WebServer
Apple-News-Services-Host
X-ScT
X-S-Maxage
X-Server-Time
Cross-Origin-Window-Policy
Cache-Prefix
X-S-Cookie
X-Rojux
BehaviorPad-Version
Rendered-Blocks
X-Request-UUID
X-Rewrite-Enabled
X-CF-Lambda-Version
Cdn-Host
Rt-Proxy-Cache
Content-Script-Type
Content-Style-Type
X-Trv-Group
X-CF-Lambda-Fn
X-Twitter-Response-Tags
VivaBuild
Viewtype
X-SRCache-Key
Cdn-Request-Time
X-Region-Sid
X-A
Apple-News-Services-Handled
X-Connection-Hash
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
X-A-Ccd
Mobile-Detection-Method
Meta-Geo-Continent
X-AIR-PT
MD5-Digest
Memcached
X-Aed
X-PAYTM-SRV-ID
X-Worker
X-A-Wwc
AsisCache
X-A-Dgt
X-A-Dcw
X-A-Dam
X-Accel-Expires-Debug
Arc-Country
Node
X-Oneagent-Js-Injection
ServerName
Backend-Name
X-B3-SpanId
X-Cache-Bucket
X-Cms-Context
X-Developers
X-Distributor
X-Cdn-Srv
Fastly-Soc-X-Request-Id
X-VC-Cache
Request-Country
X-SIPLIST1
IsBot
Request-EU
Locale
X-Origin-Date
X-Urbn-Site-Id
X-Release
N-Cache
X-Origin-Expires
X-Urbn-Context-Path
X-Azure-Ref
X-Hl-Ver
Section-Io-Cache
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Up
X-Azure-Ref-OriginShield
X-Fastly-Cache
User-Cache-Control
Uber-Trace-Id
True-Client-Country-4JS
X-Cache-Id
X-Cache-Info
W
V-Age
X-Cache-FS-Status
X-Block-Status
X-Bip
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-C
X-BBXSRF
X-Backend-Url
X-Amz-Meta-Cache-Control
Thinkindot-Control
X-App-Name
X-Auto-Login
X-Backend-Host
X-Cdn-Origin
X-IN-APIGATEWAYSSL
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Reboot
X-Policy
X-Platform-Server
X-Old-Content-Length
X-Nginx-Cache-Key
X-Org
X-Owner
X-PHP-Host
X-Request-Start
X-Request-URI
X-TrackingId
X-Thinkindot-L3
X-Variation
X-VServer
X-WADP-Cache
X-Thanos
X-WebServer
X-Wikidot-Static-Cache
X-ServiceProvider
X-Wikidot-Backend
X-Skip-Cache
X-Sn-Servicetimems
X-Method
X-Matched-Rule
X-Fetched-On
X-Epic-Correlation-Id
X-Flog
X-GDPR
X-Gen-Mode
X-ElasticPress-Search
X-Distil-CS
X-Compress-Hint
X-Clientip
X-Core-Mission
X-CUA
X-Device-Os
X-Generated-On
X-Generation-Time
X-Li-Pop
X-Li-Fabric
X-LI-Proto
X-LI-UUID
X-Location
X-Level-Front-Cache
X-We-Are-Hiring
X-Geo-Header
X-Hello
X-Hnp-Log
X-IN-APIGATEWAY
X-Clara-WADP
X-ABtesting
CDCHOST
Content-Disposition
Adler-Geo
Countrycode
Platform
AKAMAI
Magicmarker
L
Is-Eu
X-DC
RNT-Machine
Gh-Request-Id
X-Via-CDN
Fastly-SWR
Server-ID
Esi-Enabled
Fastly-SIE
Server-Int
RNT-Time
X-Oracle-Dms-Rid
X-ProxyCache-Key
X-ProxyCache-Status
X-Microcachable
X-BYPASS-REASON
X-Internal-Host
X-Say-TTL
X-Guploader-Uploadid
X-SayCDN-TTL
X-CGP
X-SD-PageType
X-Debug-Cookies
X-Eu-Site
X-Proxy-Cache-Status
X-Proxy-Upstream
X-NX-Host
X-Generated-In
X-Irp-Debug
X-Hash
X-GeoIP-City
X-Qloud-Router
X-Dispatcher-Server
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-Servername
X-Debug-Log
X-Dispatch
X-Reqid
X-Say-Cacheable
X-Server-IP
PFcat
X-Swa-Ws
Pagetype
X-Webstats-RespID
Kp-EeAlive
Wxu-Next-Region
Wxu-Next-Hostname
Served-By
Server-Host
SD-X-WS
Web-Mar-Node
Wxu-Next-Commit
Heartbleed
Pramga
Ha-Gx-Prefs
X-Backend-State
HA-Ipaddr
X-User
X-Var-Ttl
SS
X-MSEdge-Flight
X-Service
X-MSEdge-Features
X-Key
Memory
Resin-Trace
X-Routing-Service
X-Cdn-Forward
X-Zipkin-Id
X-Proxied
X-Response-By
X-COUNTRY
X-Wa
X-Dc
X-Unique-ID
X-Has-Esi
Cache-Provider
X-JWT-State
X-Is-Gdpr
X-FPC
X-IPS-LoggedIn
X-Servedbyhost
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-Idcheck
Srv
X-URL
Country-Code
Cache-Cookie-Set-From
X-Ttl
X-NWS-UUID-VERIFY
X-Lb-Id
X-Info
REQUESTUUID
X-Page-Type
X-Tec-Api-Version
X-RateLimit-Reset
X-Tec-Api-Root
X-Tec-Api-Origin
X-MP-GENERATED-AT
X-Nc
UCS
X-UA
X-Geo
X-Svr
X-Ratelimit-Limit
X-Cache-Backend
X-VCL-Version
X-Cache-URL
Powered-By-ChinaCache
X-Be
X-Datadome
X-Logtrace-Id
X-Instart-Isnd
X-Processor
ProcessTime
X-CDN-Forward
Ajk
X-HTML-Minification-Powered-By
CACHE
X-Oss-Object-Type
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
Proxy-Firewall
X-HS-Status
X-Oss-Storage-Class
X-Oss-Request-Id
X-Pjax-Url
X-Scheme
X-Trafficlayer-App-Name
X-Trafficlayer-App-Scope
X-SRV
X-Varnish-Beresp-Ttl
PICS-Label
X-NodeID
X-SN
X-Tb-Optimization-Total-Bytes-Saved
X-Ruxit-Js-Agent
X-Grey
X-ZONE
Dynatrace
X-Cache-Category-Id
Powered-By
SN
X-Dynatrace-Js-Agent
X-Zone
X-Webkit-Csp
Group
XServer
X-Ftr-Request-Id
X-Dynatrace
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
X-TH-Server
X-Server-W
GeoIP-City
GeoIP-Latitude
Fastly-Backend-Name
Cache-Host
GeoIP-Country-Code
Ttl
X-GRACE
X-Source
X-Newrelic-Synthetics
X-Pf-Uncompressing
X-LiteSpeed-Cache-Control
X-EC-Lua
X-Ms-Version
X-PF-Uncompressing
X-Ms-Request-Id
X-Via-Ucdn
X-FORWARDED-FOR
X-RCS-CacheZone
X-Sucuri-Id
X-Varnish-Beresp-TTL
X-APP
X-Bc
LB
MIME-Version
GW-Server
Cdn
X-LAGOON
X-NODE
X-Check-Cacheable
Geoip-Latitude
X-Session-Fingerprint
GeoIp-Country-Code
Geoip-City
X-Gannett-Site-Version
Environment
Lfy
X-Varnish-Url
X-Secret
X-Ftr-Cache-Host
CF-Cached-On
X-Cache-Ttl
X-Tt-Trace-Host
X-Fastly-Country-Code
X-Cache-Debug
WZWS-RAY
X-Agile
X-Ratelimit-Remaining
X-Agile-Age
X-Agile-Id
X-BC
On-Server
Pics-Label
X-Varnish-Cacheable
X-CDN-Cache
X-Edge
X-Aicache-OS
X-SERVER-NAME
X-PJAX-URL
X-7Graus-Varnish-Cache-Control
X-Logging-Id
X-Akamai-SSL-Client-Sid
X-7Graus-Varnish-XKeys
X-GeoIP-Country-Code
WWW
User-Agent
X-Ftr-Realm
X-Ftr-Backend
X-Ftr-Balancer
X-Ftr-Dc
X-Ftr-Backend-Server
Inserted-Into-Cache-At
M-TraceId
X-BE
Requestid
X-Mid
X-Sedo-Request-Id
X-Cache-Miss-From
Ohc-Response-Time
Cf-Ipcountry
X-Fastly-Backend-Reqs
SID
X-CSRF-Token
X-NU-AKA-ACS-Version
X-Varnish-Ttl
X-MCACHE
X-Vcl-Version
X-Cache-Tag
X-UPSTREAM-Address
Amp-Access-Control-Allow-Source-Origin
X-Render-Time
Who
X-Core-Value
X-Litespeed-Cache-Control
X-Crawler
DataCenter
Lb
X-Unique-Id
URI
X-Action
X-AK-Request-ID
X-RSL
Cdnsip
Cdncip
X-LB-ID
X-RPS
X-RPM
X-DSS
X-DW
Xkeyrz
X-Proxy-Cacherz
X-DB
X-Newrelic-App-Data
X-DI
RequestUuid
HostName
X-Sucuri-ID
Warning
Host-ID
X-TT-LOGID
X-FE
X-Vdms-Version
X-Micro-Cache
Get-Access-Time
X-WR-MODIFICATION
CDN
X-Sucuri-Cache
Is-Session-Tracking
X-NGINX-Cache
X-Correlation-ID
X-Fstrz
X-Sigma
X-Sigma-Backend
X-Rocket-Build-Number
X-Nananana
X-Fpc
X-WA
Xkeypdq
X-Via-Edge
X-Fastly-Cache-Hits
X-Via-SSL
X-ServedByHost
X-Served-From
X-Zalando-Child-Request-Id
X-Flow-Id
X-Page-Impression-Id
X-Swift-Error
Cneonction
X-Cdn-Request-ID
FNAC-ModuleRouting
Pragrma
X-LiteSpeed-Tag
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Shopify-Generated-Cart-Token
Correlation-Id
X-MID
X-VC
X-SB
X-Planisys-CDN-Cache
X-TIME
X-Cf-Powered-By
Server-Id
X-Amzn-Remapped-Date
X-Gen-Id
X-Request-URL
X-ServerName
X-Bug-Bounty
V-Cache
X-Gdpr
X-Dw-Trace-Id
HitType
X-ECache
X-Fe
X-Amzn-Remapped-Connection
Xet-Cookie
X-MiniProfiler-Ids
Processtime
RequestId