Threat Level: green Handler on Duty: Russell Eubanks

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Pragma
Last-Modified
Accept-Ranges
Strict-Transport-Security
X-Content-Type-Options
X-Powered-By
CF-RAY
ETag
Link
Expect-CT
Via
X-XSS-Protection
X-Cache
Age
Access-Control-Allow-Origin
Content-Security-Policy
Content-Language
X-UA-Compatible
P3P
X-Cache-Hits
X-Served-By
X-Varnish
X-Amz-Cf-Id
X-Xss-Protection
Referrer-Policy
X-Request-Id
X-Timer
X-AspNet-Version
CF-Cache-Status
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Runtime
Access-Control-Allow-Credentials
X-Download-Options
X-Drupal-Cache
X-Cacheable
Content-Security-Policy-Report-Only
X-Generator
Alt-Svc
Status
X-AspNetMvc-Version
X-Cache-Status
X-DNS-Prefetch-Control
X-Check
P3p
X-Iinfo
X-Adblock-Key
X-FRAME-OPTIONS
X-CDN
Timing-Allow-Origin
X-Content-Security-Policy
X-Permitted-Cross-Domain-Policies
X-Turbo-Charged-By
Content-Encoding
X-Template
X-Language
Keep-Alive
X-Type
X-AH-Environment
X-Via
X-Cache-Group
X-Request-ID
X-Backend
WPE-Backend
X-Pass-Why
X-Buckets
X-Age
X-Server
X-Nginx-Cache-Status
Access-Control-Max-Age
X-Server-Powered-By
X-Pingback
Xkey
X-Varnish-Cache
Grace
X-Drupal-Dynamic-Cache
Upgrade
Access-Control-Expose-Headers
X-Hacker
X-UA-Device
X-Amz-Request-Id
Cf-Railgun
X-Page-Speed
X-Amz-Id-2
X-Proxy-Cache
X-Robots-Tag
EagleId
X-Envoy-Upstream-Service-Time
Request-Context
X-Node
X-LiteSpeed-Cache
X-Swift-SaveTime
X-Swift-CacheTime
X-Ac
X-Device
Ali-Swift-Global-Savetime
X-Host
X-Cnection
Content-Location
X-Amz-Version-Id
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-WebKit-CSP
X-Server-Id
Surrogate-Control
X-Backend-Server
X-Cache-Lookup
X-OneAgent-JS-Injection
X-Rack-Cache
X-Response-Time
X-Px
X-Instart-Request-ID
X-CST
Server-Timing
Request-Id
X-Readtime
X-Rq
X-Clacks-Overhead
Pinterest-Generated-By
X-Url
X-Do-Not-Hack
Permitted-Cross-Domain-Policies
X-HeyJason
EagleEye-TraceId
X-Ua-Compatible
Edge-Control
X-Application-Context
X-Country
X-Cloud-Trace-Context
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-MS-InvokeApp
Report-To
X-Server-Name
Charset
X-DynaTrace-JS-Agent
X-ESI
SPRequestGuid
X-Country-Code
Allow
X-DataDome
X-SharePointHealthScore
Rating
X-Varnish-TTL
X-Ruxit-JS-Agent
X-PC
X-TtlSet
X-Vname
X-Cached
X-Powered-CMS
X-Powered-By-Plesk
X-DynaTrace
X-Recruiting
X-CF-Powered-By
X-FTR-Request-ID
X-Vhost
NEL
X-D2id
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Pinterest-Rid
X-Upstream-Env
X-Kinja-Server
X-Kinja-Build
X-Exp-Variant
X-Kinja-Revision
X-Exp-Id
X-Cdn-Fetch
X-Geo-Segment
X-Kinja
Pinterest-Version
Public-Key-Pins
X-F-Cache
X-TTL
X-Version
X-T
Cartoon
X-GoogleNews-Bot
X-VARITI-CCR
X-N
SPRequestDuration
X-Dw-Request-Base-Id
SPIisLatency
X-Mod-Pagespeed
X-Ttl
X-Abt-Application-Version
RTSS
Content-MD5
Verso
Feature-Policy
MS-Author-Via
Nginx-Cache
X-Dispatcher
X-GitHub-Request-Id
X-Goog-Hash
X-Navigation-Version
X-Client-IP
X-Amz-Rid
MicrosoftSharePointTeamServices
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Realpath
X-Hits
X-Forwarded-Proto
AR-CACHE
AR-ATIME
X-Shield-Request-Id
AR-PoweredBy
X-Origin-Cache
X-Cdn
X-Trace
Paypal-Debug-Id
DynaTrace
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Content-Options
X-Id
X-Content-Digest
X-Zen-Fury
X-Grace
X-Server-ID
TCN
X-Kinsta-Cache
X-B
Arr-Disable-Session-Affinity
Alternate-Protocol
X-Cache-Key
AR-SID
X-Varnish-Age
X-Sol
Fastcgi-Cache
X-Upstream
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
Mrf-Cache-Status
MRF-Tech
X-Acc-Meta-Resource-Type
X-FastCGI-Cache
Access-Control-Request-Method
X-Pad
X-Ser
X-Mobile-Rewrite
PB-PID
Display
PB-RID
X-Middleton-Display
X-Fastly-Request-ID
X-Nf-Srv-Version
X-NF-Request-ID
X-Via-JSL
X-User-Agent
X-DIS-Request-ID
X-Middleton-Response
Response
Pagespeed
X-Vcap-Request-Id
X-Forwarded-For
X-MSEdge-Ref
Rt-Fastcgi-Cache
Eomportal-Instance
Arc-Version
X-PressLabs-Stats
Front-End-Https
X-Cache-Rule
X-Frontend
X-Cache-Hit
X-Logged-In
X-SS-Set-Cookie
X-IPLB-Instance
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
Server-Name
X-Hostname
Host
X-Whom
Surrogate-Key
S
Tracecode
X-VCache
X-FTR-Backend-Server
X-FTR-Expires
X-Country-Code-Real
X-FTR-Backend
X-FTR-Balancer
X-FTR-Cache-Status
X-XRDS-LOCATION
X-FTR-DC
X-FTR-Realm
X-Request-Received
X-Request-Processing-Time
X-Analytics
Backend-Timing
X-Debug
Cache-Status
X-Magnolia-Registration
X-HS-Content-Id
TP-Cache
X-AOL-HN
TP-L2-Cache
X-Instance
X-Contextid
Refresh
X-Rid
X-Proxied
X-Litespeed-Cache
X-B3-Traceid
X-Az
X-Activity-Id
X-AppVersion
X-XRDS-Location
X-HW
FilterID
ServerID
X-Srv
Public-Key-Pins-Report-Only
X-Wix-Server-Artifact-Id
HitInfo
Server-Info
HitType
Cleartype
X-UUID
X-WPE-Loopback-Upstream-Addr
X-APP-VERSION
AMP-Access-Control-Allow-Source-Origin
X-Content-Security-Policy-Report-Only
X-FTR-Cache-Host
X-Varnish-Backend
X-Mobile
X-Origin-Upstream-Status
Service-Worker-Allowed
X-Varnish-Server
Liferay-Portal
X-Newrelic-App-Data
X-Cache-Control
Served-By
X-Revision
X-TT
Source
X-Cache-Server
X-Amzn-Trace-Id
Server-Node
X-Tumblr-Pixel
X-Request-Guid
X-PC-Key
X-PC-Hit
X-PC-AppVer
X-Tumblr-Pixel-0
X-Tumblr-User
X-BCube-Filmed-By
X-Geo-Country
X-App-Environment
X-Hail-Hydra
X-Device-Type
X-Handled-By
Retry-After
X-Framework
MS-CV
X-Page-Id
Host-Header
Accept-Charset
X-PHP-Backend
DC
X-Cache-Config
X-Varnish-Hostname
X-Cache-Operation
X-Cache-2
Powered-By-ChinaCache
X-Signature
X-RateLimit-Remaining
X-B-Cache
X-Origin-Server
X-Origin
X-Correlation-Id
S-Cnection
X-FB-Debug
Viewport
X-URL
X-NWS-LOG-UUID
X-HS-Cache-Config
Edge-Cache-Tag
X-ATG-Version
X-Debug-Info
X-Cache-Action
X-TT-TIMESTAMP
Fastly-Restarts
X-Ocache
X-PC-Date
X-PC-Host
X-Cached-By
X-Sucuri-ID
Actual-Object-TTL
X-B3-Sampled
X-Hyper-Cache
X-WA-Info
NGB
X-NewRelic-App-Data
X-Content-Powered-By
X-Akam-SW-Version
X-Shield-Cache-Expires
X-ADI-VCache
X-Drupal-Cache-Tags
X-Microcachable
X-LB-Cache
X-Accel-Expires
X-Generated-By
AsisCache
Filters
X-Cache-NE
Upgrade-Insecure-Requests
SRV
X-Tumblr-Pixel-2
ServedBy
X-WebKit-CSP-Report-Only
X-Distil-CS
X-Tumblr-Pixel-1
X-FW-Static
X-RequestSource
X-FW-Type
X-FW-Server
X-FW-Serve
X-RTag
X-FW-Hash
X-Locale
X-Internal-Host
X-App-Server
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Cacheable-TTL
Content-Script-Type
Content-Style-Type
X-GeoIP
X-S
X-Cluster
X-Wix-Request-Id
X-Seen-By
X-Node-Name
X-ServedBy
X-Amz-Server-Side-Encryption
X-Jobs
X-GUploader-UploadID
X-Cache-Age
X-Geo
Cache
X-TX-ID
X-Varnish-Hits
X-Accel-Buffering
From-Origin
X-UA
X-Varnish-Grace
X-Platform-Server
X-RateLimit-Limit
X-Varnish-Cache-Hits
Datacenter
X-GZip
X-Adobe-Loc
X-Akamai-Edgescape
X-Adobe-Content
X-Vg-Webcache
X-CDN-Forward
X-Varnish-IP
X-Dns-Prefetch-Control
X-Sucuri-Cache
X-CLOUD-TRACE-CONTEXT
X-HS-Combine-CSS
Cache-Tag
X-Real-IP
X-Cache-TTL-Remaining
X-Edge-Cache-Key
X-Edge-Cache
X-Storage
X-Oneagent-Js-Injection
X-Akamai-Transformed
X-Webkit-Csp
X-Mode
X-Drupal-Cache-Contexts
X-Region
X-Cache-Remote
X-Source
X-Distributor
X-Amz-Replication-Status
X-Proxy
X-Path-Route
Meta-Geo
X-Amz-Apigw-Id
X-RN-RSRV
X-Is-Bot
X-Detected-As
X-Amzn-RequestId
X-MP-GENERATED-AT
X-RemovedCookies
X-ProcessESI
Load-Balancing
Machine
X-Rendered-As
ServerName
Fastly-SSL
X-NCache
Ohc-File-Size
X-Upgrade-Enabled
X-BB-IP
X-Webstats-RespID
X-PERF
GEO-INFO
X-ApacheServer
X-Backend-Name
X-TWH-CORRELATION-ID
X-Agile
X-Agile-Id
X-CDN-Cache
X-Akamai-Request-ID
Cache-Key
X-Time-Microsecs
X-Agile-Age
Mn-Server-Ip
X-Kinja-Server-Push
X-Cluster-Node
X-Pubstack
X-EIG-Tracking-Id
X-Varnish-Cacheable
S-Rt
X-Web-Node
X-Viewer-Country
X-FC-Vary-Parameters
X-NodeID
Azure-Version
X-OCL
X-ServerID
Azure-SlotName
Azure-SiteName
Azure-InstanceId
Azure-RegionName
X-Human
X-Grey
X-Daa-Tunnel
X-Cache-Category-Id
X-OVcl
X-Amz-Meta-Surrogate-Control
X-Original-Request
X-PCL
HostName
X-Cache-Var-Map
X-OVcl-Cache
X-Cache-Var
X-Debug-Cache
X-Edge-Location
Now
LB
X-Cache-HT
L5d-Success-Class
X-Routing-Service
X-Origin-Hint
X-BYPASS-REASON
X-Optimization
X-Birta-Served
X-Birta-Cache-Post
X-AWS-Id
TWC-Privacy
TWC-Locale-Group
TWC-GeoIP-LatLong
Webcakes-App-Name
Webcakes-App-Version
X-Access
Webcakes-Region
X-Port
X-Section
X-App-Name
X-ProxyCache-Key
X-ProxyCache-Status
TWC-Connection-Speed
TWC-GeoIP-Country
TWC-Device-Class
Property-Id
Cache-Name
User-Agent
X-Instance-Name
X-Www-Served-By
X-Generation-Time
Backend
X-VWS-Id
X-Zipkin-Id
X-Via-Fastly
X-Format
X-IP
X-CCM-LastModified
X-Proto
X-Meta-Tbi-Cache-Vertical
X-Site-Version
X-SplitTest
X-LJ-Flow-ID
X-JoinUs
Healthy
DB-Nickname
X-Hosted-By
User-Cache-Control
Access-Control-Allow-Method
X-Webkit-CSP
Fastcgi-Useragent
X-Labrador-Cache-Channel
X-TNCMS
X-Loop
Country
X-Tb
Selected-FE
X-CCM
X-Proxy-Build
Countrycode
X-Timing-Wait
X-Xfnlog-Site
Payment
X-Tumblr-Pixel-3
X-Dc
Cache-Hits
X-Request-Time
Ec-Rule-Version
X-Guploader-Uploadid
RATING
X-Newrelic-Synthetics
X-Generated
X-Surge-Debug
X-Origin-CC
X-Ezoic-Cdn
X-Unique-ID
X-Cache-Bucket
WP-Super-Cache
X-TA-CDN-Provider
X-Correlation-ID
X-DataStream-Cache-Status
X-Time
X-Hit
X-B3-Spanid
X-Oracle-Dms-Ecid
X-Cache-Enabled
X-Oracle-Dms-Rid
X-Real-Ip
Origin-Edge-Control
Origin-Cache-Control
X-Feature
X-Render-Type
X-Nginx-Cache
X-Nc
NODE
X-Varnish-Beresp-Status
RequestId
X-Varnish-Beresp-Grace
X-L-Path
X-Environment-Context
X-UA-Device-Type
X-NU-AKA-ACS-Version
X-B3-TraceId
X-Esi
X-Be
X-Skip-Cache
X-HS-Hub-Id
X-Content-Type
X-WR-MODIFICATION
Apicache-Version
Apicache-Store
X-NGENIX-Cache
X-Status
Access-Control-Request-Headers
Ws
X-ElasticPress-Search
X-Servedby
X-Cache-Backend
Xserver
X-Vgn-Hpd-Reason
Warning
X-CACHE-AGE
X-D
X-Application
X-We-Are-Hiring
X-IN-SSL-APIGATEWAY
X-Date
X-ARC
X-Accel-Expires-Debug
X-Via-CDN
X-Connection-Hash
X-CF-Lambda-Fn
X-Wix-Route-ID
X-CF-Lambda-Version
X-BBXSRF
Xc-Version
X-BB-ID
X-B-Cookie
X-A-Wwc
Fastcgi-X-Cache
Resin-Trace
BehaviorPad-Version
Sta2Tusw
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Cache-Prefix
Meta-Geo-Continent
GMS-Ver
Fly-Request-Id
Fastly-Soc-X-Request-Id
Host-ID
Memcached
MD5-Digest
Apple-News-Services-Host
Apple-News-Services-Handled
X-A
IBM-Web2-Location
X-A-Ccd
X-A-Dam
X-A-Dgt
X-A-Dcw
Www
Fastcgi-X-Cache-Version
Ajk
AKAMAI
T-Server
Viewtype
VivaBuild
Fly-Cache
X-Via-Edge
X-Planisys-CDN-TTL
X-Public
Time
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Region-Sid
X-Rewrite-Enabled
X-Died
X-Server-Time
X-Server-By
X-S-Cookie
X-Fastly-Cache
X-PAYTM-SRV-ID
X-ND-Cache
X-Logtrace-Id
X-IN-WAF
X-IN-APIGATEWAY
X-No-Session
X-Haproxy-Ip
X-From
X-G
X-Generated-In
X-Haproxy-Hostname
X-SRCache-Key
X-Rojux
X-Trv-Group
X-Destination
X-Developer
X-Twitter-Response-Tags
X-Upstream-CT
X-SVT-ORM-RULES
X-Upstream-HT
X-Transaction
X-EdgeConnect-Cache-Status
X-SVT-ORM-VERSION
X-User
X-VG-WebServer
Webserver
X-GoCache-CacheStatus
Fastly-SIE
Release
X-NX-Host
Request-Time
Origin
X-Var-Ttl
NGX
IsBot
X-Hl-Ver
X-Wikidot-Backend
Fastly-SWR
X-CS
X-Debug-Cookies
X-Core-Value
X-Debug-Log
X-Up
X-ScT
X-Trace-Id
X-Rocket-Nginx-Bypass
X-F5-Cache
X-Cache-Expires
X-Sn-Servicetimems
X-SIPLIST1
X-Amz-Meta-Cache-Control
X-Cache-Host
X-Rebelmouse-Surrogate-Control
X-Phone
X-Forwarded-Host
X-Wikidot-Static-Cache
Uber-Trace-Id
UCS
X-Rebelmouse-Cache-Control
X-Cdn-Origin
V-Age
Server-Int
Rendered-Blocks
X-Croise-Owner
X-C
X-MI-In-Market
Thinkindot-Control
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-Matched-Rule
Who
X-HCF
X-Location
Backend-Name
Server-Host
X-Passed-To-PostProcessResponse
Pramga
Powered-By
X-Platform
X-Cache-Id
Cache-Cookie-Set-Idcheck
X-Passed-To
X-Passed-To-BeforeDispatch
Cache-Cookie-Set-From
X-Passed-To-DLL
X-GeoIP-Country-Code
X-GeoIP-City
X-Cache-Ttl
X-Backend-Url
X-Backend-TTL
X-Backend-State
X-Bug-Bounty
X-Cache-CFC
X-Cdn-Srv
X-CGP
X-Cache-Debug
X-Cache-Control-Set-By
X-Backend-Host
X-Auto-Login
X-Eu-Site
X-FireWall-Port
X-Frame-Option
X-Fstrz
X-Epic-Correlation-Id
X-Edge-IP
X-Developers
X-Amz-Meta-S3cmd-Attrs
X-DPWN-IS-SECURE
X-Actual-URL
X-Reboot
Proxy-Connection
Cache-Cookie-Set-Lfrom
HA-Servedtime
HA-Ipaddr
HA-Host
HA-Urlpath
Heartbleed
X-Varnish-HitMiss
X-TIME
X-TT-LOGID
Decoy-Debug-Key
Ha-Gx-Prefs
HA-Georegion
GW-Server
Decoy-Debug-Status
X-UnsetCookies
X-V
HA-Cloudapp
HA-Geocity
HA-Geolon
HA-Geolat
HA-Geocountry
X-Thinkindot-L3
HTTPS
MI-Cache
X-Returned-From
X-Returned-From-BeforeDispatch
X-Via-NSCOPI
MI-Cache-Age
X-Request-URI
On-Server
Ohc-Response-Time
Odigeo-Trace-Id
X-Returned-From-PostProcessResponse
X-Returned-From-DLL
X-ServiceProvider
Content-Disposition
X-Stale
X-Server-IP
X-Servername
Decoy-Debug-TTL
X-Server-Group
X-Cache-Time
X-WebServer
X-Varnish-Id
X-Worker
X-Clientip
X-Ckpd-Fst-Backend
X-Content-Age
X-VServer
X-Gen-Mode
X-MSEdge-Flight
X-Node-Id
X-UE-Client-Country
Fastly-Backend-Name
X-MSEdge-Features
X-Thanos
X-Device-Os
X-Dispatcher-Server
X-Ruxit-Js-Agent
X-Hnp-Log
X-Crawler
X-Env
X-Block-Status
Pragrma
Platform
Is-Eu
Web-Mar-Node
CDCHOST
Httpd-Identifier
X-Bip
Esi-Enabled
REQUESTUUID
OT-Force-Account-Verify
Adler-Geo
Cneonction
NnCoection
X-Info
MI-API
X-RCS-CacheZone
X-Release
X-Ver
X-Refresh
Cache-Provider
X-Response-By
PFcat
X-Cache-Srv
X-Served-From
X-Core-Mission
Country-Code
X-Hash
Kp-EeAlive
X-Fetched-On
Dnion-Transfer-Encoding
X-Varnish-Beresp-Ttl
X-Fastcgi-Cache
X-Origin-Date
X-Origin-Expires
X-S-Maxage
X-Alternate-Cache-Key
X-Sorting-Hat-ShopId
X-Cache-URL
X-Svr
X-Req
Request-Country
Server-ID
X-Page-Type
NtCoent-Length
X-P-T
Request-EU
X-Sorting-Hat-PodId-Cached
X-ShardId
X-Sorting-Hat-ShopId-Cached
X-Sorting-Hat-PodId
Mime-Version
X-Shopify-Stage
X-Sorting-Hat-Section
X-Sorting-Hat-PrivacyLevel
X-ShopId
X-Sorting-Hat-FeatureSet
X-Gannett-Site-Version
X-StackifyID
X-Pjax-Url
X-Pf-Uncompressing
Processtime
Drupal-Pagecache-Memcache
X-Secret
X-Cache-ASPX
X-Origin-TTL
X-EC-Security-Audit
Accept-Ch
X-Amz-Meta-S3b-Last-Modified
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-Oss-Storage-Class
X-Oss-Object-Type
Pagetype
Memory
X-Amz-Meta-Sha256
Version
X-NC
Ar-Sid
X-Csrf-Token
X-Wix-Petri-Ex
Geoip-Latitude
WebServer
SN
Dont-Set-Cookie
Geoip-City
GeoIp-Country-Code
X-App-Version
X-Rule
X-CSRF-Token
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-LiteSpeed-Cache-Control
X-Varnish-Url
X-From-Cache
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
Cteonnt-Length
FSS-Proxy
X-Cache-Handler
FSS-Cache
X-Yottaa-Sig
PICS-Label
Arc-Country
X-Load-Cache
X-Varnish-Beresp-TTL
X-Irp-Debug
PageType
X-Ua
CF-IPCountry
Brightspot-Id
MIME-Version
Cdn
X-Request-Start
X-LB-Node
X-LB-CacheStatus
X-Ratelimit-Remaining
XServer
X-DC
If-Modified-Since
X-Redis-Cache
Edgecast
COMMERCE-SERVER-SOFTWARE
X-ROOTCache
Sid
X-COUNTRY
X-SERVER-NAME
BORDER-IP
PROCESSING-IP
X-Fastly-Backend-Reqs
X-Request-UUID
X-Cdn-Forward
X-Sf
X-GRACE
X-Endurance-Cache-Level
RNT-Machine
X-Requestid
X-Tid
RNT-Time
X-Ratelimit-Limit
X-Servedbyhost
X-Varnish-Action
X-ServedByHost
X-TId
X-GDPR
Powered
X-RequestId
X-Layer
X-Nananana
X-Resolver-IP
X-B3-SpanId
X-Rocket-Nginx-Serving-Static
Cache-Tags
X-Atg-Version
X-Cache-TTL
Frame-Options
X-DataStream-MidMile-RTT
X-BE
X-DataStream-Origin-MEX-Latency
Pics-Label
Amp-Access-Control-Allow-Source-Origin
CDN
Cf-Ipcountry
NodeID
X-Fastly-Cache-Hits
CACHE
X-Gdpr
X-Tec-Api-Version
X-Tec-Api-Root
Node
X-Tec-Api-Origin
Mail-Subject
X-Owner
X-Varnish-URL
X-Key
We-Hiring
X-UPSTREAM-Address
PageSpeed
GeoIP-Latitude
X-Server-W
Hostname
X-HTML-Minification-Powered-By
X-Shard
X-Dynatrace-Js-Agent
GeoIP-Country-Code
X-VG-WebCache
GeoIP-City
X-Varnish-Ttl
X-Dynatrace
X-Use-Magma
X-Alicdn-Da-Ups-Status
Web-Mar-Region
X-Ms-Request-Id
X-Aicache-OS
Lfy
X-Ms-Blob-Type
X-Ms-Lease-Status
X-Ms-Version
X-Sentry-ID
X-GZIP
DataCenter
ProcessTime
Accept-CH
X-ABtesting
X-VG-TLSProxy
WZWS-RAY
X-Flog
X-NGINX-Cache
Dynatrace
X-Powered-By-ANYU
Cdn-Host
X-Swa-Ws
X-Edge-Server
True-Client-Country-4JS
Cdn-Request-Time
X-PF-Uncompressing
X-GEO
URI
X-Dw-Trace-Id
Xet-Cookie
X-Oa-Upstreams
Get-Access-Time
Is-Session-Tracking
X-CDN-Pop
X-Vcache
X-Check-Cacheable
Rt-Proxy-Cache
X-Org
GEO-REGION-INFO
X-PAGE-TYPE
X-Ms-Lease-State
X-Front
X-CDN-Pop-IP
X-PJAX-URL
X-Cookie
V-Cache
Group
Max-Age
X-Unique-Id
X-Qnm-Cache
X-Policy
X-M-Reqid
X-M-Log
X-NWS-UUID-VERIFY
N-Cache
X-Mem
X-SB
X-Trv-Request-Id
X-Varnish-Info
X-VC
RequestUuid
X-Varnish-ID
Requestid
X-Amzn-Remapped-Date
X-Powered-By-Defense
X-VID
CF-Cached-On
CountryCode
X-Hello
X-Acquia-Application-Trace
X-Amzn-Remapped-Connection
X-DW
X-Litespeed-Tag
X-Proxy-Server
X-Litespeed-Cache-Control
X-Fe
WS
X-Cache-FS-Status
SID
X-RAMCache
X-Akamai-ERRuleID
X-Remote-IP
X-Acquia-Application-UUID
X-RPM
X-RPS
X-Akamai-ERPolicy
X-DSS
X-DB
X-DI
X-RSL