Threat Level: green Handler on Duty: Jim Clausing

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Accept-Ranges
Cf-Request-Id
CF-Cache-Status
Pragma
X-Powered-By
ETag
Link
Expect-CT
X-XSS-Protection
Via
CF-RAY
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-UA-Compatible
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
Alt-Svc
X-Served-By
CF-Ray
X-Xss-Protection
X-Timer
X-Varnish
X-Download-Options
Access-Control-Allow-Methods
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Permitted-Cross-Domain-Policies
X-Cache-Status
X-Generator
X-Cacheable
P3p
X-Request-ID
X-Kinja-Server-Push
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-Content-Security-Policy
Status
X-AspNetMvc-Version
Upgrade
Content-Encoding
X-Template
X-CDN
X-Language
Access-Control-Max-Age
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
X-Envoy-Upstream-Service-Time
Keep-Alive
X-Via
X-Ws-Request-Id
X-Age
Feature-Policy
X-Backend
X-AH-Environment
X-Buckets
X-Hacker
X-Cache-Group
X-Robots-Tag
X-Server
X-Amz-Request-Id
EagleId
X-Amz-Id-2
X-UA-Device
X-Proxy-Cache
X-Turbo-Charged-By
X-Server-Powered-By
X-Dns-Prefetch-Control
Request-Context
Server-Timing
Host-Header
X-Nginx-Cache-Status
Grace
Report-To
Xkey
X-Page-Speed
X-Rq
X-OneAgent-JS-Injection
X-Varnish-Cache
X-Pingback
Cf-Bgj
X-LiteSpeed-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Cf-Railgun
Ali-Swift-Global-Savetime
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-WebKit-CSP
X-Amz-Version-Id
X-Vhost
NEL
X-Host
X-Dispatcher
X-Device
X-Backend-Server
X-Node
Surrogate-Control
X-Ruxit-JS-Agent
X-Cache-Lookup
X-Origin-Cache
X-Response-Time
Content-Location
X-Akam-SW-Version
Request-Id
X-Ac
X-ASPNET-VERSION
X-Country
X-Server-Id
X-Mod-Pagespeed
X-HW
EagleEye-TraceId
Rating
X-Readtime
Accept-CH
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
Accept-CH-Lifetime
Akamai-Age-Ms
X-Cloud-Trace-Context
Pinterest-Generated-By
X-Application-Context
X-DataDome
Edge-Control
X-Country-Code
X-Origin-Upstream-Status
X-Vname
X-TtlSet
X-PC
X-Url
X-Varnish-TTL
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Fusion-Content-Id
Fusion-Template-Id
Fusion-Component-Id
Fusion-Source
Fusion-Deployment-Id
Fusion-Content-Source
X-Cnection
X-D2id
X-ESI
X-GitHub-Request-Id
X-MS-InvokeApp
X-Clacks-Overhead
X-Content-Type
X-Server-Name
X-Abt-Application-Version
X-Navigation-Version
X-FTR-Request-ID
Allow
X-Vcap-Request-Id
X-Trace
Pinterest-Version
X-Pinterest-Rid
Verso
X-Sol
Response
X-Middleton-Display
X-Middleton-Response
Pagespeed
Display
X-B3-TraceId
X-Px
X-Cached
X-Server-ID
X-DynaTrace
X-Element-Page-Cache
X-Rack-Cache
Accept-Ch
X-Fastly-Request-ID
Service-Worker-Allowed
X-TTL
X-Cache-TTL
MS-Author-Via
Arr-Disable-Session-Affinity
X-Client-IP
X-Powered-By-Plesk
Accept-Ch-Lifetime
X-Version
X-Upstream
X-Forwarded-Proto
X-T
Content-MD5
X-NF-Request-ID
X-Dw-Request-Base-Id
X-Debug
AR-PoweredBy
AR-CACHE
AR-ATIME
AR-Request-ID
Fastly-Restarts
Ar-Sid
SPRequestGuid
X-SharePointHealthScore
X-VARITI-CCR
X-XRDS-Location
X-Jurisdiction
X-Kinja
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Kinja-Build
X-GoogleNews-Bot
X-Cdn-Fetch
X-Exp-Id
X-Exp-Variant
TP-L2-Cache
TP-Cache
Access-Control-Request-Method
X-Content-Digest
X-Goog-Hash
X-Powered-CMS
X-Release
X-Edge
X-NWS-LOG-UUID
X-MSEdge-Ref
TCN
RTSS
X-PressLabs-Stats
Cache-Tag
S
SPIisLatency
Fastcgi-Cache
X-Webkit-CSP
SPRequestDuration
X-Amz-Rid
X-Request-Received
X-Ttl
X-Request-Processing-Time
X-Yandex-Sdch-Disable
Public-Key-Pins
X-Ezoic-Cdn
X-Accel-Expires
X-MCACHE
X-Mid
X-Ratelimit-Remaining
Server-Node
X-Pinterest-Direct
X-Node-Name
X-Cache-Key
X-Logged-In
X-Cache-Hit
X-FastCGI-Cache
ServerID
X-Amzn-Trace-Id
Front-End-Https
X-Request-Handler-Origin-Region
X-Microsite
Alternate-Protocol
X-Ser
X-CST
X-Recruiting
X-Page-Id
X-Origin-Server
X-Kinsta-Cache
X-B
X-Ratelimit-Limit
Host
X-ECACHE
X-Hostname
Accept-Charset
X-Mobile-URL
X-FTR-Expires
X-FTR-DC
X-FTR-Realm
X-FireWall-Port
X-FTR-Cache-Status
X-FTR-Balancer
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Backend
X-Forwarded-For
Nginx-Cache
X-Varnish-Age
X-Seen-By
X-Id
Realpath
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Load-Cache
X-Content-Security-Policy-Report-Only
Filterid
Mrf-Cache-Status
X-DIS-Request-ID
MRF-Tech
X-B3-TraceId-Primal
X-Jobs
X-Content-Options
X-Shield-Request-Id
X-Activity-Id
X-AppVersion
X-Daa-Tunnel
X-Az
X-Type
X-LB-Cache
X-Git-Hash
X-F-Cache
X-Varnish-Backend
X-App-Environment
Paypal-Debug-Id
X-Request-Guid
X-Varnish-Grace
X-Rid
Edge-Cache-Tag
X-Zen-Fury
X-N
X-Correlation-ID
Fastcgi-Useragent
X-Hits
X-FB-Debug
X-Grace
X-Proxy
X-Fastcgi-Cache
X-App-Server
AMP-Access-Control-Allow-Source-Origin
X-Mg-S
DC
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
DynaTrace
X-Content-Powered-By
Cache-Tags
X-Akamai-Edgescape
Content-Disposition
Access-Control-Allow-Method
X-Upgrade-Enabled
X-WebKit-CSP-Report-Only
X-Cache-Rule
X-Amz-Server-Side-Encryption
X-Cache-Operation
X-Geo-Country
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Endurance-Cache-Level
Cleartype
X-Wix-Request-Id
X-Cached-By
MicrosoftSharePointTeamServices
X-VCache
X-HP-Webp
X-Response-Served-From
X-Accel-Buffering
X-Original-Request-Id
X-Host-Name
X-Hp-Webp
Refresh
X-IPLB-Instance
X-B3-Sampled
NGB
X-Rule
Healthy
Payment
MS-CV
X-User-Agent
X-Ua
X-AOL-HN
X-Distributor
X-FW-Serve
X-FW-Hash
X-FW-Dynamic
X-Cache-Time
X-HS-Hub-Id
X-HS-Cache-Config
X-FW-Type
X-HS-Combine-CSS
X-FW-Static
X-FW-Server
X-B-Cache
X-HS-Content-Id
X-UUID
X-HTML-Minification-Powered-By
X-Signature
X-Cacheable-TTL
X-Region
X-Amz-Apigw-Id
X-Rendered-As
Datacenter
X-Whom
X-Is-Bot
X-Amzn-RequestId
X-Instance
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-Goog-Generation
X-Amz-Meta-S3cmd-Attrs
X-Tumblr-Pixel-0
X-Goog-Metageneration
X-Tumblr-User
X-GUploader-UploadID
X-Tumblr-Pixel-2
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
Countrycode
Arc-Version
PB-RID
PB-PID
Powered
X-Mobile
X-Debug-Info
X-Frontend
X-App-Version
X-Varnish-Server
X-XRDS-LOCATION
Surrogate-Key
X-PHP-Backend
X-DynaTrace-JS-Agent
Powered-By-ChinaCache
X-Backend-Name
S-Cnection
X-Tec-Api-Origin
X-Tec-Api-Version
X-Oneagent-Js-Injection
X-Tec-Api-Root
X-Azure-Ref
X-NewRelic-App-Data
X-Respond-Thread
X-Cache-Server
X-Via-JSL
Cache
X-WA-Info
X-Protected-By
X-Cache-Age
X-Time
X-Hyper-Cache
Liferay-Portal
X-Litespeed-Cache
X-Cache-Control
Viewport
Referer-Policy
X-FTR-Cache-Host
X-Cache-Expired-At
Retry-After
X-Proxy-Cache-Status
X-CSRF-Token
X-FB-TRIP-ID
X-EdgeConnect-Cache-Status
Webserver
X-Acc-Debug-Context
X-RemovedCookies
From-Origin
X-Cache-Var-Map
X-ProcessESI
Filters
X-ES-SERVER
X-Cache-Var
Meta-Geo
X-Debug-Cache
X-RN-RSRV
X-R9-Blue-Green-Version
X-Source
X-Mode
Section-Io-Cache
X-Sucuri-ID
Eomportal-Instance
X-Locale
X-From
X-Device-Type
X-Qloud-Router
X-AWS-Id
X-ProxyCache-Key
X-ProxyCache-Status
X-PCL
X-OCL
X-LJ-Flow-ID
X-Ratelimit-Reset
X-BYPASS-REASON
Mn-Server-Ip
X-VWS-Id
X-GeoIP
Ms-Operation-Id
X-Time-Microsecs
X-Site-Version
X-Cache-Host
X-Via-Fastly
X-Server-W
X-RTag
X-FW-Version
Cross-Origin-Window-Policy
Cache-Tv-Group
X-Hl-Ver
Charset
X-Handled-By
Ec-Rule-Version
X-Human
X-TNCMS
Webcakes-App-Name
Webcakes-App-Version
X-Xfnlog-Site
Selected-Fe
TWC-Privacy
TWC-Locale-Group
TWC-Device-Class
TWC-GeoIP-Country
TWC-GeoIP-LatLong
X-Cache-Action
X-Cluster
TWC-Connection-Speed
X-Zipkin-Id
X-Origin-Hint
X-Loop
X-Timing-Wait
Property-Id
X-Proxy-Build
X-Routing-Service
X-Proxied
X-Framework
Webcakes-Region
X-Ua-Device
X-Hosted-By
X-JoinUs
X-Generated-By
X-L-Path
X-Environment-Context
X-BCube-Filmed-By
X-Be
X-NYM-Debug-Backend
X-Proto
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Real-IP
X-Status
X-ServerID
X-Amzn-Remapped-Content-Length
X-SaId
X-PHP-Host
X-Labrador-Cache-Channel
DB-Nickname
X-Amz-Replication-Status
X-Section
X-Access
Uber-Trace-Id
X-Redis-Cache
X-TA-CDN-Provider
X-Revision
X-Format
X-Cache-TTL-Remaining
X-Varnish-Cache-Hits
FSS-Cache
X-Detected-As
X-No-Session
Frame-Options
X-Air-Hostname
Version
X-Cache-PHP
X-ATG-Version
X-NWS-UUID-VERIFY
X-Drupal-Cache-Contexts
X-Sucuri-Cache
X-Origin
X-CACHE-AGE
X-NCache
X-Contextid
CF-Cached-On
X-EIG-Tracking-Id
Server-Name
X-Drupal-Cache-Tags
X-URL
X-IPS-LoggedIn
X-EC-Lua
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Cache-Enabled
GEO-INFO
OT-Force-Account-Verify
X-Unique-Id
X-Akamai-Transformed
X-Instart-Request-ID
X-IP
X-Bc-Bl
X-Vgn-Hpd-Cached
X-Cache-Backend
X-Vgn-Hpd-Variations-Key
X-GoCache-CacheStatus
Now
X-Tumblr-Pixel-3
X-Backend-Host
X-TT
Time
X-Adobe-Loc
X-Adobe-Content
X-Ruxit-Js-Agent
Azure-SlotName
X-RCS-CacheZone
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
X-Oss-Object-Type
Azure-SiteName
Azure-RegionName
X-Oss-Storage-Class
Azure-InstanceId
Azure-Version
X-Oss-Request-Id
Access-Control-Request-Headers
X-AIR-PT
X-Correlation-Id
X-NGENIX-Cache
X-TIME
HostName
X-Cdn
Node
X-S-Cookie
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-Rewrite-Enabled
X-Rojux
X-CCM
X-Connection-Hash
X-Cache-2
X-Application
X-Generation-Time
VIX-Pulpo-Node
Surrogated-Key
SD-X-WS
Meta-Geo-Continent
Mobile-Detection-Method
Rendered-Blocks
VIX-Pulpo-Upstream-Status
X-A
X-Accel-Expires-Debug
X-Adobe-Source
X-Aed
X-A-Wwc
X-A-Dgt
X-A-Ccd
X-A-Dam
X-A-Dcw
MD5-Digest
Machine
X-Minions-Version
Apple-News-Services-Handled
Apple-News-Services-Host
X-B-Cookie
X-Cache-NE
X-Processor
X-PBS-Appsvrname
X-PAYTM-SRV-ID
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
DCR-Processing-Time-Ms
Fastcgi-X-Cache-Version
Host-ID
DCR-Decision-By
CloudFront-Viewer-Country
X-G
X-ARC
X-Request-UUID
X-S
X-Transaction
X-Vtex-Processado-Em
X-Trv-Group
X-ScT
X-Up
X-Twitter-Response-Tags
X-VG-WebCache
X-VG-WebServer
X-Vdms-Version
X-D
X-Vdms-Path
X-Date
X-Vtex-Remote-Cache
Xc-Version
X-Destination
X-Worker
X-External-Request-Id
X-APP-VERSION
X-Cdn-Forward
X-CDN-Forward
X-CUA
X-Agile
X-Agile-Age
X-Generated-On
X-OVcl
X-OVcl-Cache
X-Microcachable
Adler-Geo
X-Method
X-Agile-Id
X-VG-TLSProxy
CDN-EdgeStorageId
Fastly-SIE
Platform
X-Hash
We-Hiring
Fastly-SSL
Fastly-SWR
Is-Eu
Mail-Subject
NM-Fastcgi-Cache
Wxu-Next-Commit
X-Level-Front-Cache
X-Owner
CDN-CachedAt
CDN-Cache
CDN-PullZone
CDN-RequestCountryCode
Wxu-Next-Hostname
CDN-Uid
CDN-RequestId
Wxu-Next-Region
X-Alternate-Cache-Key
X-Varnishpool
X-TX-ID
X-Shopify-Stage
X-Core-Value
X-Storefront-Renderer-Rendered
X-Bip
X-Cache-Bucket
X-Thanos
X-Storage
X-Cache-Grace
X-SN
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Skip-Cache
X-Varnish-Beresp-Grace
X-Soup
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Status
X-Reqid
X-Req
X-Platform
X-DPWN-IS-SECURE
X-Servername
X-Forwarded-Host
X-PERF
X-ApacheServer
X-Dispatcher-Server
X-Envoy-Decorator-Operation
X-Pubstack
X-Variation
X-Edge-Location
X-Backend-TTL
X-Rebelmouse-Surrogate-Control
X-ShopId
X-Rebelmouse-Cache-Control
X-ShardId
X-UA
X-Cdn-Srv
PFcat
Pagetype
X-WADP-Cache
X-Clientip
X-Cache-Tags
X-HN
X-Cache-Config
X-Auto-Login
X-Gamma-Serve
X-Clara-WADP
X-Fastly-Backend
L5d-Success-Class
X-Backend-State
X-Fastly-Cache
X-Webstats-RespID
Rt-Fastcgi-Cache
X-Fmm-Version
X-Cache-Date
Ufe-Result
X-Cache-NGX
Country-Code
CacheControlHeader
Cache-Status
X-Render-Time
C-Via
X-Li-Pop
X-Li-Fabric
X-Viewer-Country
X-Request-Start
X-Cluster-Name
X-Eu-Site
L
AKAMAI
X-Micro-Cache
X-Cms-Context
X-Varnish-Cacheable
X-Policy
X-Proxy-Upstream
X-Varnish-Ttl
X-LI-UUID
X-Csrf-Jwt
X-VarnishDD-TTL
X-Core-Mission
X-HS-Content-Campaign-Id
Fastly-Drupal-HTML
Gh-Request-Id
Group
HA-Ipaddr
Ha-Gx-Prefs
Decoy-Debug-TTL
Fastly-Backend-Name
X-CGP
Decoy-Debug-Status
Decoy-Debug-Key
X-ECache
X-Cache-Id
X-Request-Host
X-Slack-Backend
X-Esi-Check
X-SayCDN-TTL
X-Cache-URL
X-Say-TTL
X-Say-Cacheable
X-Content-Age
X-VHOST
X-Developers
X-Web-Node
X-Has-Esi
X-Wikidot-Backend
UCS
X-JWT-State
X-Is-Gdpr
X-CS
Memcached
X-Irp-Debug
X-Gzip
X-Geo-Header
Backend
X-Location
Akamai-GRN
X-Old-Content-Length
X-Amz-Meta-Cb-Modifiedtime
X-Ms-Version
X-Wikidot-Static-Cache
Country
Origin
X-Ms-Request-Id
X-NC
X-Refresh
X-Wa
X-Esi
X-Dc
X-Mvc-Supplant-Cachable
X-PF-Uncompressing
M-TraceId
Nel
FSS-Proxy
X-Aicache-OS
X-LB-ID
X-NODE
X-Platform-Server
X-Via-Popn
Arc-Country
X-Via-Poph
Geo-Info
X-Unique-ID
X-BC
X-ZONE
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Varnish-CookieHashed-On
X-DefHash
X-DefElseHash
X-LAGOON
X-B3-Spanid
Upgrade-Insecure-Requests
Viewtype
Actual-Object-TTL
X-ORACLE-APMCS-REQUEST-ID
X-RateLimit-Remaining
VivaBuild
X-Branch-Name
NGX
X-RunCloud-Cache
X-Via-Ucdn
X-LI-Proto
X-Servedbyhost
X-UPSTREAM-Address
Srv
X-Mvc-Supplant-OutputCached
X-Cache-Debug
X-Session-Fingerprint
X-Providence-Cookie
Cdn-Host
X-Is-Crawler
X-Request-Time
X-Zone
X-Bc
X-Aspnet-Duration-Ms
X-Flags
X-Route-Name
X-Edge-Server
Cdn-Request-Time
X-SERVER
CACHE
X-Nginx-Cache
Memory
X-Vgn-Hpd-Ssi
X-Srv
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Ftr-Cache-Host
X-Varnish-Hostname
Xserver
X-Geo
X-DC
X-Nc
X-LiteSpeed-Cache-Control
X-APP
NtCoent-Length
X-HS-Status
Sid
X-CF-Powered-By
X-Action
X-Mobile-Rewrite
X-FPC
X-DB
X-Cs
X-Epic-Correlation-Id
WWW-Authenticate
X-DI
X-DSS
X-RPS
X-RPM
X-RSL
X-B3-Traceid
X-FC-Vary-Parameters
X-DW
X-Page-View
X-Akamai-Request-ID2
X-Cluster-Node
X-MP-GENERATED-AT
X-Hit
X-NGINX-Cache
Server-Info
X-GEO
X-Via-Popv
GeoIP-Country-Code
X-Oss-Cdn-Auth
ProcessTime
GeoIP-Latitude
X-Check-Cacheable
X-Vcache
X-VCL-Version
Geoip-Latitude
X-NU-AKA-ACS-Version
GeoIp-Country-Code
Apigw-Requestid
SRV
X-CSRF-TOKEN
User-Agent
X-Vcl-Version
Processtime
XServer
X-SERVER-NAME
Hostname
X-Fpc
X-FORWARDED-FOR
X-Webkit-CSP-Report-Only
X-Sql-Duration-Ms
X-Sql-Count
X-UnsetCookies
Origin-Cache-Control
Origin-Edge-Control
X-Via-CDN
Cdn
Edge-Copy-Time
X-Dynatrace-Js-Agent
W
X-Via-Edge
X-Via-SSL
WebServer
X-HOST
X-Presslabs-Stats
SID
Accept-Language
S-Rt
X-Envoy-Upstream-Healthchecked-Cluster
CF-IPCountry
Esi-Enabled
X-Key
X-Dispatch
X-Svr
X-Tb
On-Server
X-We-Are-Hiring
X-HITS
LB
X-Cache-Hm
X-Www-Served-By
X-Cache-Hfrom
Proxy-Firewall
Request-ID
HitType
T-Server
X-Pjax-Url
Cache-Hits
N-Cache
X-Fastly-Country-Code
ServedBy
X-S-Maxage
A
X-SRV
X-App
X-COUNTRY
X-CACHE-KEY
Ohc-File-Size
Server-Host
Fastcgi-Cache-TTL
X-Pass-Why
X-MSEdge-Features
Lb
X-MSEdge-Flight
Cteonnt-Length
CDN
X-Geo-Region
X-Generated
X-Cache-Remote
Amp-Access-Control-Allow-Source-Origin
X-RAMCache
BehaviorPad-Version
X-Path-Route
Magicmarker
Powered-By
X-Amzn-Remapped-Connection
Pics-Label
X-Newrelic-App-Data
X-Amzn-Remapped-Date
WZWS-RAY
X-TrackingId
X-Instart-Info
Xet-Cookie
X-VC
X-SB
X-Newrelic-Synthetics
X-ServedByHost
X-StackifyID
X-Varnish-Hits
X-Li-Proto
X-Datadome
X-Dynatrace
X-Akamai-Pragma-Client-IP
X-TH-Server
Server-Ttl
X-Served-From
X-B3-SpanId
X-Info
Cache-Key
X-Client-Ip
Dnion-Transfer-Encoding
Cache-Provider
X-Via-NSCOPI
X-Via-PopV
X-Via-PopN
X-Via-PopH
X-Origin-Response-Time
X-Lb-Id
X-LiteSpeed-Tag
Content-Script-Type
Content-Style-Type
X-Batcache
Ohc-Cache-HIT
Protected
X-Cache-Tag
X-Planisys-CDN-Rules
X-Agile-Brick-Ok
X-Uri
X-Region-Sid
Cf-Alt-Svc
User-Cache-Control
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
X-Tt-Logid
X-TT-LOGID
X-WA
Tcn
X-Vgn-Hpd-Reason
X-DevSite-Last-Modified
X-Pad
Odigeo-Trace-Id
Inserted-Into-Cache-At
X-Pf-Uncompressing
X-Yottaa-OS
X-Tid
Who
X-HostName
X-RateLimit-Limit
X-Selected-Name
X-Selected-Scheme
Load-Balancing
X-Selected-Host-Header
CountryCode
X-Apw-Hits
X-Apw-Access-Token
X-Apw-Access-Object
X-Apw-Access-Action
X-Varnish-Beresp-TTL
X-Request-URL
Source
Ssr
X-Snapshot-Date
PICS-Label
X-C
Vha6-Origin
X-Compress-Hint
X-Developer
AsisCache
X-Nananana
X-Akamai-ERRuleID
GEO-REGION-INFO
X-Proxy-Cachei7
X-Akamai-ERPolicy
X-Dw-Trace-Id
X-Fastly-Cache-Hits
X-Magnolia-Registration
X-Parent-Response-Time
Pragrma
X-PJAX-URL
X-Origin-TTL
Mime-Version
X-Origin-CC
Cneonction
X-MiniProfiler-Ids
X-SRCache-Key