Threat Level: green Handler on Duty: Manuel Humberto Santander Pelaez

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
CF-RAY
CF-Cache-Status
Link
X-Powered-By
X-XSS-Protection
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Alt-Svc
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
Content-Security-Policy-Report-Only
X-Generator
X-Cacheable
X-Cache-Status
X-Permitted-Cross-Domain-Policies
X-Xss-Protection
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Template
X-Language
X-Request-ID
X-Iinfo
Status
X-Content-Security-Policy
Content-Encoding
X-AspNetMvc-Version
X-Buckets
X-Kinja-Server-Push
Xkey
Upgrade
X-Via
Access-Control-Expose-Headers
X-Turbo-Charged-By
Keep-Alive
Access-Control-Max-Age
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Pass-Why
P3p
X-Age
EagleId
X-Backend
X-Robots-Tag
X-Envoy-Upstream-Service-Time
X-Amz-Id-2
X-Amz-Request-Id
X-Page-Speed
X-Ua-Compatible
X-Pingback
X-Server-Powered-By
X-Proxy-Cache
X-CDN
X-Hacker
X-UA-Device
X-AH-Environment
Request-Context
X-Nginx-Cache-Status
Grace
X-Server
X-Swift-SaveTime
X-Swift-CacheTime
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-Cdn
X-LiteSpeed-Cache
Cf-Railgun
X-Amz-Version-Id
X-Server-Id
X-WebKit-CSP
Feature-Policy
Server-Timing
X-Device
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
X-Rq
X-Ac
X-Cnection
X-Cloud-Trace-Context
Report-To
X-Host
X-Response-Time
EagleEye-TraceId
X-Node
X-Backend-Server
Content-Location
Request-Id
X-Origin-Cache
X-Readtime
X-Vhost
X-Application-Context
X-Cache-Lookup
X-Dns-Prefetch-Control
X-ORACLE-DMS-ECID
X-Dispatcher
NEL
X-Origin-Upstream-Status
X-ORACLE-DMS-RID
X-Rack-Cache
X-Ruxit-JS-Agent
Surrogate-Control
X-DataDome
Allow
X-HW
Rating
X-Country-Code
X-FTR-Request-ID
X-Country
X-Clacks-Overhead
X-Url
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-TTL
X-DynaTrace
X-Instart-Request-ID
Fusion-Content-Source
Fusion-Source
Fusion-Template-Id
Fusion-Content-Id
Fusion-Component-Id
X-Goog-Hash
X-MS-InvokeApp
X-Varnish-TTL
X-Vname
X-TtlSet
X-PC
X-Ah-Environment
Verso
RTSS
X-Powered-By-Plesk
X-CST
X-Aspnetmvc-Version
Public-Key-Pins
X-Px
X-Recruiting
Edge-Control
X-Mod-Pagespeed
X-VARITI-CCR
Pinterest-Generated-By
Response
X-Middleton-Response
Display
X-Middleton-Display
X-Sol
Service-Worker-Allowed
X-Exp-Id
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Kinja-Build
X-Kinja
X-Exp-Variant
X-GoogleNews-Bot
X-Cdn-Fetch
X-D2id
Accept-CH
X-B3-TraceId
X-Vcap-Request-Id
X-Version
SPRequestGuid
X-SharePointHealthScore
X-Akam-SW-Version
MS-Author-Via
TCN
X-Abt-Application-Version
X-Powered-CMS
X-GitHub-Request-Id
X-RateLimit-Remaining
X-Navigation-Version
SPIisLatency
SPRequestDuration
X-Shard
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Upstream
AR-ATIME
AR-CACHE
X-Server-Name
AR-PoweredBy
Accept-Ch-Lifetime
Ar-Sid
Charset
X-Amz-Server-Side-Encryption
X-Forwarded-Proto
Fastly-Restarts
X-Trace
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-XRDS-Location
X-Amz-Rid
Nginx-Cache
Realpath
X-Debug
X-ESI
AR-Request-ID
Front-End-Https
X-Ezoic-Cdn
X-Cached
X-Shield-Request-Id
X-NF-Request-ID
Mrf-Cache-Status
X-Mrf-Item-Lastmod
MRF-Tech
X-B3-TraceId-Primal
X-Mrf-Section-Lastmod
X-Goog-Stored-Content-Length
X-MSEdge-Ref
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Encoding
Access-Control-Request-Method
Arr-Disable-Session-Affinity
X-Country-Code-Real
X-FTR-Expires
X-FTR-Cache-Status
X-SERVER
Paypal-Debug-Id
Content-MD5
Pagespeed
X-Id
ServerID
X-FTR-Balancer
X-FTR-Backend-Server
MicrosoftSharePointTeamServices
X-FTR-Backend
X-FTR-Realm
X-FTR-DC
X-Goog-Storage-Class
X-Amz-Meta-S3cmd-Attrs
DynaTrace
X-T
X-VCache
S
X-Fastly-Request-ID
X-Via-JSL
X-Client-IP
X-Varnish-Age
X-DynaTrace-JS-Agent
X-Content-Type
X-Vcache
X-Hits
X-Dw-Request-Base-Id
X-Amzn-Trace-Id
X-Correlation-Id
X-FastCGI-Cache
X-Grace
X-Accel-Expires
Fastcgi-Cache
X-Ser
X-Frontend
X-Content-Digest
Powered
X-RateLimit-Limit
X-FTR-Cache-Host
PB-RID
PB-PID
X-Mobile-Rewrite
X-N
Arc-Version
X-DIS-Request-ID
AMP-Access-Control-Allow-Source-Origin
Server-Name
X-Logged-In
X-Forwarded-For
X-HS-Content-Id
X-HS-Hub-Id
X-B3-Sampled
Edge-Cache-Tag
TP-L2-Cache
TP-Cache
X-Esi
X-GUploader-UploadID
X-Request-Handler-Origin-Region
X-Microsite
X-Zen-Fury
X-Request-Received
X-Request-Processing-Time
X-Type
X-Cache-Age
X-Rid
X-User-Agent
X-Activity-Id
X-Kinsta-Cache
X-AppVersion
X-Az
X-Analytics
Backend-Timing
X-Revision
X-LB-Cache
X-IPLB-Instance
X-Fastcgi-Cache
FilterID
X-B3-Traceid
Healthy
X-Whom
X-Node-Name
Accept-Ch
Retry-After
Pinterest-Version
X-Time
X-Pinterest-Rid
X-Cache-Hit
X-Srv
X-F-Cache
X-NWS-LOG-UUID
Accept-Charset
X-Cache-2
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Alternate-Protocol
Server-Node
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Cache-Rule
Cache-Status
X-AOL-HN
X-Content-Options
Surrogate-Key
X-Akamai-Edgescape
DC
X-Content-Security-Policy-Report-Only
X-Content-Powered-By
X-Hp-Webp
X-Server-ID
X-Instance
VIX-Pulpo-Upstream-Status
X-Debug-Info
VIX-Pulpo-Node
X-Tumblr-Pixel
X-Tumblr-Pixel-0
Access-Control-Allow-Method
Refresh
X-Tumblr-User
X-Forwarded-Host
X-Jobs
X-FW-Static
X-FW-Type
X-Page-Id
X-FW-Server
X-FW-Serve
X-Cluster
X-Framework
X-Varnish-Grace
X-FW-Hash
MS-CV
X-Acc-Meta-Resource-Type
X-B
X-App-Environment
Source
X-FB-Debug
Cache-Tag
X-PHP-Backend
X-Request-Guid
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-App-Server
Frame-Options
Fastcgi-Useragent
X-TA-CDN-Provider
Tracecode
Host
X-Hostname
X-Cache-Key
X-Cache-Operation
Actual-Object-TTL
X-Mobile-URL
X-B-Cache
X-Signature
Cleartype
X-Cached-By
X-Seen-By
X-Geo-Country
X-BCube-Filmed-By
X-Cache-Control
Accept-CH-Lifetime
X-Varnish-Backend
X-Host-Name
X-Cache-TTL
X-Amz-Replication-Status
X-TT
X-Pad
X-Mobile
NGB
X-Git-Hash
Upgrade-Insecure-Requests
X-Response-Served-From
Liferay-Portal
X-Adobe-Content
X-Adobe-Loc
Payment
X-TT-TIMESTAMP
X-WebKit-CSP-Report-Only
WPE-Backend
Cache-Tv-Group
Eomportal-Instance
Filters
X-Status
X-ATG-Version
Ms-Operation-Id
X-RTag
From-Origin
X-Tumblr-Pixel-2
X-Cache-Remote
X-TX-ID
Webserver
X-Tumblr-Pixel-1
X-Handled-By
X-Cacheable-TTL
X-RemovedCookies
X-UA-Device-Type
X-RequestSource
GEO-INFO
X-ProcessESI
X-FW-Dynamic
X-GeoIP
X-Drupal-Cache-Tags
X-WA-Info
X-Cache-TTL-Remaining
Xserver
X-Origin-Server
X-PressLabs-Stats
X-Ratelimit-Reset
NR-ENABLED
X-Daa-Tunnel
X-Content-Age
X-Cache-Action
X-Webkit-CSP
X-Edge-Location
Datacenter
X-Storage
PageSpeed
X-EdgeConnect-Cache-Status
X-Varnish-Hostname
Viewport
Version
X-Hyper-Cache
X-Accel-Buffering
X-Wix-Request-Id
X-Contextid
X-CF-Powered-By
X-Region
X-DataStream-Cache-Status
Cache
X-Upstream-Proxy
Host-Header
X-Presslabs-Stats
X-Ua
X-Akamai-Transformed
X-Yottaa-Metrics
X-Yottaa-Optimizations
Meta-Geo
X-Cache-Var-Map
X-ES-SERVER
X-Varnish-Server
X-RN-RSRV
X-Cache-Var
X-Path-Route
Load-Balancing
S-Cnection
Ohc-File-Size
X-IP
X-Cache-NE
Cache-Name
X-HS-Cache-Config
Cache-Tags
X-TNCMS
X-Origin
X-Viewer-Country
Rt-Fastcgi-Cache
X-Loop
X-Labrador-Cache-Channel
X-Cache-Enabled
X-Cache-Config
X-Time-Microsecs
X-Section
X-Upgrade-Enabled
X-Tumblr-Pixel-3
X-Proto
Vix-Hermes-Req-Id
Decoy-Debug-TTL
X-Proxy
X-Access
Decoy-Debug-Status
Cache-Hits
X-Akamai-Request-ID
X-PERF
X-ApacheServer
X-Akamai-Request-ID2
DB-Nickname
X-Origin-Response-Time
X-From
Ec-Rule-Version
Decoy-Debug-Key
X-CS
Cache-Key
Azure-SlotName
Azure-SiteName
Azure-Version
Azure-RegionName
Country
X-Cache-Time
X-Xfnlog-Site
Azure-InstanceId
X-Web-Node
X-Origin-Hint
X-OCL
X-Hit
X-JoinUs
X-NCache
X-Via-Fastly
X-PCL
X-Timing-Wait
X-Rule
X-R9-Blue-Green-Version
X-Trace-Id
X-UnsetCookies
X-Varnish-Cache-Hits
X-Upstream-HT
X-Upstream-CT
X-Format
X-FC-Vary-Parameters
TWC-GeoIP-LatLong
TWC-Locale-Group
TWC-Privacy
TWC-GeoIP-Country
TWC-Device-Class
S-Rt
Selected-Fe
TWC-Connection-Speed
Webcakes-App-Name
Webcakes-App-Version
X-CCM
X-Cluster-Node
X-EIG-Tracking-Id
X-Proxy-Build
X-Cache-Host
Webcakes-Region
X-Backend-TTL
Mn-Server-Ip
Property-Id
X-Debug-Cache
X-Generated
X-Human
X-FireWall-Port
X-Site-Version
X-Hosted-By
X-S
X-Locale
X-Drupal-Cache-Contexts
X-Varnish-Hits
X-Cache-Server
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Backend-Name
X-Cache-Grace
X-Device-Type
Server-Info
X-FW-Version
X-Rendered-As
X-VCT
Release
Now
DSUID
X-Www-Served-By
Time
Ohc-Cache-HIT
OT-Force-Account-Verify
X-Vgn-Hpd-Reason
SRV
X-Element-Page-Cache
Hostname
X-OVcl
X-NewRelic-App-Data
X-OVcl-Cache
Cteonnt-Length
X-VG-TLSProxy
ServedBy
X-Real-IP
Fastcgi-X-Cache-Version
X-APP-VERSION
X-Pubstack
Access-Control-Request-Headers
Origin-Cache-Control
X-VG-WebCache
X-Litespeed-Cache
X-Redis-Cache
Origin-Edge-Control
X-FB-TRIP-ID
X-Alternate-Cache-Key
X-ShardId
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-CSRF-TOKEN
X-ShopId
Origin
Accept-Language
L5d-Success-Class
X-NC
X-Tb
Machine
X-GEO
X-SS-Set-Cookie
Fastly-SSL
X-NGENIX-Cache
NtCoent-Length
X-Nginx-Cache
X-HS-Combine-CSS
X-B3-Spanid
X-L-Path
X-Tt-Trace-Tag
X-App-Version
X-No-Session
X-Cluster-Name
X-Environment-Context
X-UUID
X-Parent-Response-Time
X-GoCache-CacheStatus
IBM-Web2-Location
X-Load-Cache
X-ECACHE
X-Rocket-Nginx-Bypass
X-LJ-Flow-ID
X-Origin-TTL
X-ServerID
X-VWS-Id
X-AWS-Id
X-Origin-CC
X-Mode
X-B3-Parentspanid
X-Generated-By
Odigeo-Trace-Id
X-Magnolia-Registration
X-Endurance-Cache-Level
X-Amzn-Remapped-Content-Length
X-DataStream-Origin-MEX-Latency
X-DataStream-MidMile-RTT
Nel
X-Soup
X-Uri
Mail-Subject
NGX
X-Is-Bot
Mime-Version
Akamai-GRN
We-Hiring
X-XRDS-LOCATION
CF-IPCountry
X-CACHE-KEY
X-Request-Time
X-Application
Request-Time
X-Node-Id
X-Aed
BehaviorPad-Version
AsisCache
X-MServer
Proxy-Connection
X-Region-Sid
X-CF-Lambda-Version
Apple-News-Services-Handled
X-ARC
A
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Arc-Country
X-AIR-PT
X-PAYTM-SRV-ID
Apple-News-Services-Request-Url
X-Instart-Info
X-Edge-Server
X-A-Dam
X-A-Dcw
Rendered-Blocks
X-A-Ccd
X-A
X-Destination
X-Detected-As
X-Trv-Group
X-Transaction
X-Twitter-Response-Tags
Node
X-Developer
X-VG-WebServer
Rt-Proxy-Cache
Viewtype
T-Server
VivaBuild
X-Worker
Xc-Version
X-Connection-Hash
X-D
X-CF-Lambda-Fn
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
X-Date
Mobile-Detection-Method
Meta-Geo-Continent
Content-Style-Type
X-S-Maxage
X-G
X-B-Cookie
Cross-Origin-Window-Policy
X-S-Cookie
X-Rojux
Cdn-Request-Time
Cdn-Host
Content-Script-Type
X-Request-UUID
X-Rewrite-Enabled
X-Accel-Expires-Debug
X-ScT
X-A-Wwc
X-SRCache-Key
MD5-Digest
Memcached
X-A-Dgt
X-DPWN-IS-SECURE
X-External-Request-Id
Fly-Cache
Fly-Request-Id
X-Server-Time
GEO-REGION-INFO
Cache-Prefix
ServerName
Backend-Name
X-Oneagent-Js-Injection
X-Release
X-Azure-Ref-OriginShield
X-Origin-Date
X-Origin-Expires
N-Cache
X-Hl-Ver
Section-Io-Cache
X-Developers
X-Urbn-Context-Path
X-Cdn-Srv
X-Up
Fastly-Soc-X-Request-Id
X-B3-SpanId
X-Cache-Bucket
X-Distributor
X-Fastly-Cache
IsBot
X-SIPLIST1
X-Urbn-Site-Id
X-Azure-Ref
X-Cms-Context
Locale
Request-Country
Request-EU
User-Cache-Control
Uber-Trace-Id
X-C
Platform
X-Thanos
X-SVT-ORM-RULES
X-Distil-CS
Is-Eu
X-Bip
Magicmarker
X-SVT-ORM-VERSION
X-TrackingId
X-Thinkindot-L3
X-Block-Status
X-Device-Os
RNT-Time
True-Client-Country-4JS
X-Compress-Hint
Thinkindot-Control
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
V-Age
X-Wikidot-Backend
X-Clara-WADP
X-Clientip
W
X-Wikidot-Static-Cache
X-Cache-FS-Status
X-WebServer
X-VServer
X-DC
X-Skip-Cache
RNT-Machine
X-VC-Cache
X-WADP-Cache
X-We-Are-Hiring
X-Core-Mission
X-CUA
Server-Int
Server-ID
X-Variation
X-Cache-Id
X-Policy
X-Auto-Login
X-Hnp-Log
X-Platform-Server
X-IN-APIGATEWAY
Adler-Geo
X-Amz-Meta-Cache-Control
X-Rebelmouse-Cache-Control
X-Via-CDN
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-PHP-Host
X-Owner
X-LI-Proto
X-Li-Pop
X-LI-UUID
X-Nginx-Cache-Key
X-Matched-Rule
X-Li-Fabric
X-Level-Front-Cache
X-IN-APIGATEWAYSSL
X-Org
X-Old-Content-Length
X-App-Name
X-ElasticPress-Search
X-Rebelmouse-Surrogate-Control
Fastly-SIE
Fastly-SWR
X-Cache-Info
Esi-Enabled
X-Backend-Host
X-Backend-Url
X-BBXSRF
Gh-Request-Id
X-Epic-Correlation-Id
X-ServiceProvider
X-Fetched-On
X-Location
X-Generation-Time
Countrycode
CDCHOST
X-GDPR
X-Request-Start
X-Reboot
X-Generated-On
X-Request-URI
Content-Disposition
X-Gen-Mode
X-Oracle-Dms-Rid
X-BYPASS-REASON
X-ProxyCache-Status
X-Microcachable
X-ProxyCache-Key
X-Cdn-Origin
X-NX-Host
X-Say-Cacheable
X-Say-TTL
X-Reqid
X-Qloud-Router
X-Proxy-Cache-Status
X-Proxy-Upstream
X-SayCDN-TTL
X-SD-PageType
X-User
X-Webstats-RespID
X-Swa-Ws
X-Sn-Servicetimems
X-Server-IP
X-Servername
X-Method
X-Irp-Debug
X-Debug-Log
X-Dispatch
X-Debug-Cookies
X-Debug-Cache-Store
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
X-Dispatcher-Server
X-Eu-Site
X-Hello
X-Internal-Host
X-Hash
X-Geo-Header
X-Flog
X-Generated-In
X-CGP
X-ABtesting
Pagetype
Pramga
Served-By
Server-Host
L
Kp-EeAlive
AKAMAI
Ha-Gx-Prefs
HA-Ipaddr
Heartbleed
Web-Mar-Node
SD-X-WS
Wxu-Next-Hostname
Wxu-Next-Region
X-Backend-State
X-Guploader-Uploadid
Wxu-Next-Commit
X-Key
X-MSEdge-Features
SS
X-MSEdge-Flight
X-Var-Ttl
Resin-Trace
Memory
PFcat
X-GeoIP-City
X-Routing-Service
X-Cdn-Forward
X-Proxied
X-Zipkin-Id
X-JWT-State
X-Is-Gdpr
X-Response-By
X-Service
X-Dc
X-Wa
X-FPC
Cache-Provider
X-Has-Esi
X-Unique-ID
X-COUNTRY
X-IPS-LoggedIn
Cache-Cookie-Set-From
Cache-Cookie-Set-Idcheck
X-URL
X-Ttl
X-Servedbyhost
Cache-Cookie-Set-Lfrom
Srv
Country-Code
X-NWS-UUID-VERIFY
REQUESTUUID
X-Info
X-Lb-Id
X-Page-Type
X-RateLimit-Reset
X-Tec-Api-Origin
X-Tec-Api-Root
X-MP-GENERATED-AT
X-Tec-Api-Version
X-UA
UCS
X-Nc
X-Geo
X-VCL-Version
X-Cache-URL
X-Cache-Backend
X-Svr
Powered-By-ChinaCache
X-Ratelimit-Limit
X-Be
X-Datadome
X-Logtrace-Id
ProcessTime
X-Processor
X-CDN-Forward
Ajk
X-Instart-Isnd
CACHE
X-HTML-Minification-Powered-By
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Storage-Class
X-Oss-Object-Type
X-HS-Status
X-Pjax-Url
Proxy-Firewall
X-SRV
X-Scheme
PICS-Label
X-Varnish-Beresp-Ttl
X-NodeID
X-SN
X-Tb-Optimization-Total-Bytes-Saved
X-Ruxit-Js-Agent
X-Cache-Category-Id
Powered-By
X-Grey
SN
X-ZONE
Dynatrace
X-Dynatrace-Js-Agent
X-Webkit-Csp
Group
X-Zone
X-Ftr-Request-Id
X-Trafficlayer-App-Name
XServer
X-Trafficlayer-App-Scope
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-Dynatrace
GeoIP-Latitude
X-TH-Server
X-Server-W
Fastly-Backend-Name
Ttl
Cache-Host
GeoIP-Country-Code
GeoIP-City
X-Source
X-GRACE
X-Newrelic-Synthetics
X-Pf-Uncompressing
X-LiteSpeed-Cache-Control
X-EC-Lua
X-Ms-Request-Id
X-FORWARDED-FOR
X-Ms-Version
X-Via-Ucdn
X-RCS-CacheZone
X-Varnish-Beresp-TTL
X-Sucuri-Id
GW-Server
X-Bc
X-LAGOON
MIME-Version
X-PF-Uncompressing
X-APP
LB
Cdn
X-NODE
X-Check-Cacheable
X-Cache-Ttl
Environment
X-Session-Fingerprint
Geoip-City
X-Gannett-Site-Version
X-Secret
CF-Cached-On
X-Ftr-Cache-Host
Geoip-Latitude
GeoIp-Country-Code
Lfy
X-Varnish-Url
X-Fastly-Country-Code
X-Cache-Debug
X-Tt-Trace-Host
X-Agile-Age
WZWS-RAY
X-Agile
X-Ratelimit-Remaining
X-Agile-Id
X-BC
X-Varnish-Cacheable
X-CDN-Cache
X-Edge
On-Server
X-Aicache-OS
Pics-Label
X-SERVER-NAME
X-Logging-Id
X-Akamai-SSL-Client-Sid
User-Agent
X-PJAX-URL
X-GeoIP-Country-Code
X-7Graus-Varnish-XKeys
X-7Graus-Varnish-Cache-Control
WWW
X-Ftr-Balancer
X-Ftr-Dc
X-Ftr-Backend-Server
X-Ftr-Realm
X-Ftr-Backend
Requestid
X-Cache-Miss-From
M-TraceId
X-Mid
Inserted-Into-Cache-At
X-Sedo-Request-Id
X-BE
Ohc-Response-Time
Cf-Ipcountry
X-NU-AKA-ACS-Version
X-MCACHE
SID
X-Cache-Tag
X-Vcl-Version
X-CSRF-Token
X-UPSTREAM-Address
X-Fastly-Backend-Reqs
X-Varnish-Ttl
Amp-Access-Control-Allow-Source-Origin
X-Litespeed-Cache-Control
X-Crawler
X-Render-Time
X-Core-Value
Who
Lb
DataCenter
X-Unique-Id
Cdnsip
X-LB-ID
Cdncip
X-Newrelic-App-Data
X-AK-Request-ID
RequestUuid
X-DW
X-DI
X-DB
Xkeyrz
X-Proxy-Cacherz
URI
X-DSS
X-Action
X-RPM
X-RPS
X-RSL
X-Sucuri-ID
HostName
X-TT-LOGID
Is-Session-Tracking
Warning
X-WR-MODIFICATION
X-Vdms-Version
X-Sucuri-Cache
Host-ID
Get-Access-Time
X-Micro-Cache
X-FE
CDN
X-Correlation-ID
X-NGINX-Cache
X-Served-From
Xkeypdq
X-WA
X-Rocket-Build-Number
X-ServedByHost
X-Nananana
X-Zalando-Child-Request-Id
X-Via-SSL
X-Via-Edge
X-Sigma
X-Fastly-Cache-Hits
X-Fpc
X-Flow-Id
X-Page-Impression-Id
X-Sigma-Backend
X-Fstrz
X-Swift-Error
X-Shopify-Generated-Cart-Token
X-TIME
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
Pragrma
X-LiteSpeed-Tag
Cneonction
X-Planisys-CDN-Rules
X-Cdn-Request-ID
X-SB
FNAC-ModuleRouting
X-MID
X-VC
Correlation-Id
X-Cf-Powered-By
Server-Id
V-Cache
X-Gen-Id
X-Dw-Trace-Id
X-ServerName
X-MiniProfiler-Ids
X-Bug-Bounty
X-Gdpr
HitType
X-Request-URL
X-Fe
Xet-Cookie
Processtime
RequestId
X-Amzn-Remapped-Connection
X-ECache
X-Amzn-Remapped-Date