Threat Level: green Handler on Duty: Manuel Humberto Santander Pelaez

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
CF-RAY
CF-Cache-Status
Link
X-Powered-By
X-XSS-Protection
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Alt-Svc
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
Content-Security-Policy-Report-Only
X-Generator
X-Cacheable
X-Xss-Protection
X-Cache-Status
X-Permitted-Cross-Domain-Policies
X-Request-ID
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Template
X-Language
X-Iinfo
Status
X-Content-Security-Policy
Content-Encoding
X-AspNetMvc-Version
X-Buckets
X-Kinja-Server-Push
Xkey
Upgrade
X-Via
Access-Control-Expose-Headers
X-Turbo-Charged-By
Keep-Alive
Access-Control-Max-Age
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Pass-Why
P3p
EagleId
X-Age
X-Backend
X-Envoy-Upstream-Service-Time
X-Robots-Tag
X-Ua-Compatible
X-Amz-Id-2
X-Amz-Request-Id
X-Page-Speed
X-Pingback
X-CDN
X-Server-Powered-By
X-AH-Environment
X-Proxy-Cache
X-Hacker
X-UA-Device
X-Server
Request-Context
X-Nginx-Cache-Status
Grace
X-Swift-CacheTime
X-Swift-SaveTime
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-Cdn
X-LiteSpeed-Cache
Cf-Railgun
X-Amz-Version-Id
Server-Timing
Feature-Policy
X-Server-Id
X-WebKit-CSP
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-OneAgent-JS-Injection
X-Rq
X-Ac
X-Cnection
X-Cloud-Trace-Context
Report-To
EagleEye-TraceId
X-Response-Time
X-Host
X-Backend-Server
X-Node
Request-Id
Content-Location
X-Origin-Cache
X-Readtime
X-Vhost
X-Application-Context
X-Dns-Prefetch-Control
X-Cache-Lookup
X-ORACLE-DMS-ECID
X-Dispatcher
X-ORACLE-DMS-RID
NEL
X-Origin-Upstream-Status
X-DataDome
X-Rack-Cache
Surrogate-Control
X-Ruxit-JS-Agent
X-HW
Allow
Rating
X-Country-Code
X-FTR-Request-ID
X-Clacks-Overhead
X-Country
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Url
X-DynaTrace
X-TTL
X-Instart-Request-ID
Fusion-Template-Id
Fusion-Source
Fusion-Content-Id
Fusion-Component-Id
Fusion-Content-Source
X-MS-InvokeApp
X-Goog-Hash
X-PC
X-TtlSet
X-Vname
X-Varnish-TTL
X-Powered-By-Plesk
Verso
RTSS
Public-Key-Pins
Pinterest-Generated-By
X-CST
X-Px
Edge-Control
X-Mod-Pagespeed
X-Recruiting
X-VARITI-CCR
Display
X-Middleton-Display
X-Sol
X-Middleton-Response
Response
X-Ah-Environment
X-B3-TraceId
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Exp-Id
X-Kinja
X-GoogleNews-Bot
X-Exp-Variant
X-Kinja-Build
X-Cdn-Fetch
X-D2id
Service-Worker-Allowed
Accept-CH
X-SharePointHealthScore
SPRequestGuid
X-Vcap-Request-Id
X-Version
X-Akam-SW-Version
X-ESI
X-Server-Name
MS-Author-Via
X-GitHub-Request-Id
X-Abt-Application-Version
X-Navigation-Version
X-Powered-CMS
SPRequestDuration
SPIisLatency
Accept-Ch-Lifetime
TCN
X-Shard
X-RateLimit-Remaining
Charset
X-Upstream
AR-CACHE
AR-PoweredBy
Ar-Sid
Fastly-Restarts
AR-ATIME
X-Amz-Server-Side-Encryption
X-Trace
Nginx-Cache
Realpath
X-Amz-Rid
X-Aspnetmvc-Version
X-Forwarded-Proto
X-Debug
X-TEC-API-ROOT
X-TEC-API-VERSION
X-SRCache-Fetch-Status
X-TEC-API-ORIGIN
X-SRCache-Store-Status
X-XRDS-Location
X-Ezoic-Cdn
Front-End-Https
X-Cached
AR-Request-ID
X-NF-Request-ID
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
X-Shield-Request-Id
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-MSEdge-Ref
Pagespeed
Access-Control-Request-Method
Arr-Disable-Session-Affinity
X-FTR-Expires
X-FTR-Cache-Status
X-Country-Code-Real
Paypal-Debug-Id
Content-MD5
X-VCache
MicrosoftSharePointTeamServices
X-Id
X-Goog-Storage-Class
X-FTR-Realm
X-FTR-DC
X-T
X-FTR-Backend
X-FTR-Backend-Server
X-FTR-Balancer
X-Amz-Meta-S3cmd-Attrs
ServerID
S
X-Fastly-Request-ID
X-Via-JSL
DynaTrace
X-Varnish-Age
X-Client-IP
X-Content-Type
X-Hits
X-Dw-Request-Base-Id
X-Ser
X-DynaTrace-JS-Agent
X-SERVER
X-Vcache
X-Amzn-Trace-Id
X-Correlation-Id
X-Accel-Expires
X-Grace
Fastcgi-Cache
X-Content-Digest
X-Frontend
Powered
X-N
X-FTR-Cache-Host
Arc-Version
X-DIS-Request-ID
PB-PID
X-Mobile-Rewrite
PB-RID
X-Forwarded-For
Server-Name
X-Logged-In
X-RateLimit-Limit
X-Fastcgi-Cache
X-HS-Content-Id
X-HS-Hub-Id
Edge-Cache-Tag
AMP-Access-Control-Allow-Source-Origin
X-FastCGI-Cache
X-Server-ID
TP-Cache
TP-L2-Cache
X-B3-Sampled
X-Microsite
X-Request-Handler-Origin-Region
X-Request-Processing-Time
X-Request-Received
X-Cache-Age
X-Zen-Fury
X-Kinsta-Cache
X-AppVersion
X-Activity-Id
X-Az
X-Type
X-Rid
X-Revision
X-User-Agent
Backend-Timing
X-IPLB-Instance
X-Analytics
Pinterest-Version
X-Pinterest-Rid
X-LB-Cache
X-GUploader-UploadID
Healthy
Accept-Ch
FilterID
X-Whom
Retry-After
X-Time
X-Node-Name
X-Cache-Hit
X-Srv
X-NWS-LOG-UUID
X-F-Cache
Server-Node
Accept-Charset
X-Cache-2
Alternate-Protocol
X-B3-Traceid
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Cache-Rule
Cache-Status
X-Amzn-RequestId
X-Hp-Webp
X-Amz-Apigw-Id
X-Erf-Bev-Bev-Is-Generated
X-Content-Options
X-Erf-Bev-Bev
Surrogate-Key
X-Akamai-Edgescape
Cache-Tag
Refresh
DC
X-Content-Security-Policy-Report-Only
X-AOL-HN
X-Instance
X-Forwarded-Host
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Content-Powered-By
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel
X-Debug-Info
Access-Control-Allow-Method
X-Cluster
X-Varnish-Grace
X-Framework
X-TA-CDN-Provider
MS-CV
X-Jobs
X-PHP-Backend
X-App-Environment
X-Request-Guid
X-FB-Debug
Fastcgi-Useragent
Source
X-Page-Id
Tracecode
X-FW-Serve
X-FW-Hash
X-FW-Type
X-FW-Server
X-FW-Static
X-App-Server
Frame-Options
X-B
X-Esi
X-Cache-Operation
Host
X-Mobile-URL
Actual-Object-TTL
X-Cache-TTL
X-Acc-Meta-Resource-Type
X-Cache-Key
X-Hostname
X-Seen-By
Cleartype
X-Geo-Country
X-Signature
X-B-Cache
X-Cache-Control
X-Cached-By
X-BCube-Filmed-By
X-Host-Name
X-Git-Hash
X-Amz-Replication-Status
Accept-CH-Lifetime
X-TT
X-Mobile
X-Pad
Upgrade-Insecure-Requests
X-Varnish-Backend
NGB
NR-ENABLED
X-Response-Served-From
X-Adobe-Content
X-Adobe-Loc
X-TT-TIMESTAMP
WPE-Backend
Liferay-Portal
X-WebKit-CSP-Report-Only
Eomportal-Instance
Ms-Operation-Id
X-RemovedCookies
Payment
X-Handled-By
X-RTag
X-Status
From-Origin
Filters
GEO-INFO
X-ProcessESI
Cache-Tv-Group
X-ATG-Version
X-Drupal-Cache-Tags
X-TX-ID
Webserver
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
X-Cache-Remote
X-GeoIP
X-UA-Device-Type
X-RequestSource
X-Cacheable-TTL
X-FW-Dynamic
X-WA-Info
X-Cache-TTL-Remaining
X-Origin-Server
X-Daa-Tunnel
X-Webkit-CSP
X-EdgeConnect-Cache-Status
X-Content-Age
Xserver
X-Cache-Action
X-Edge-Location
X-Storage
X-Hyper-Cache
Viewport
X-Wix-Request-Id
X-Ratelimit-Reset
X-Contextid
X-Presslabs-Stats
Datacenter
X-PressLabs-Stats
X-Region
Version
X-CF-Powered-By
X-Accel-Buffering
X-Varnish-Hostname
PageSpeed
X-Oneagent-Js-Injection
Ohc-File-Size
X-HS-Cache-Config
Cache
Host-Header
X-Akamai-Transformed
Meta-Geo
X-Element-Page-Cache
X-Path-Route
Load-Balancing
X-ES-SERVER
X-RN-RSRV
X-Cache-Var
X-Varnish-Server
X-Cache-Var-Map
X-Cache-NE
X-Yottaa-Optimizations
X-Yottaa-Metrics
S-Cnection
X-Cache-Server
X-IP
Cache-Name
X-Upstream-Proxy
X-From
Cache-Tags
X-Via-Fastly
X-Tumblr-Pixel-3
X-TNCMS
X-Time-Microsecs
X-Origin-Response-Time
X-Loop
X-Viewer-Country
X-PERF
X-R9-Blue-Green-Version
X-NCache
X-Section
X-Cache-Config
Ec-Rule-Version
Rt-Fastcgi-Cache
Decoy-Debug-TTL
Decoy-Debug-Status
Cache-Hits
Decoy-Debug-Key
X-Access
X-Akamai-Request-ID
X-Proto
X-Cache-Enabled
X-CS
X-Cluster-Node
X-ApacheServer
X-Proxy
X-Akamai-Request-ID2
Vix-Hermes-Req-Id
X-NewRelic-App-Data
X-Human
X-Labrador-Cache-Channel
X-Hit
X-FC-Vary-Parameters
X-Format
X-OCL
X-Origin
S-Rt
X-Rule
X-Proxy-Build
X-PCL
Azure-InstanceId
Azure-RegionName
X-Cache-Grace
X-Cache-Time
DB-Nickname
X-Backend-TTL
Selected-Fe
X-CCM
Cache-Key
Azure-SiteName
Azure-SlotName
Azure-Version
X-Drupal-Cache-Contexts
X-Trace-Id
X-Timing-Wait
TWC-GeoIP-LatLong
TWC-GeoIP-Country
X-Upgrade-Enabled
TWC-Device-Class
TWC-Locale-Group
TWC-Privacy
Webcakes-Region
Ohc-Cache-HIT
Webcakes-App-Version
Webcakes-App-Name
TWC-Connection-Speed
X-Origin-Hint
X-Web-Node
X-Upstream-HT
X-Varnish-Cache-Hits
X-Upstream-CT
X-Www-Served-By
X-Xfnlog-Site
Mn-Server-Ip
Property-Id
Country
X-Debug-Cache
X-UnsetCookies
X-EIG-Tracking-Id
X-Cache-Host
X-Generated
X-Site-Version
X-JoinUs
X-Hosted-By
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Backend-Name
X-Locale
Server-Info
X-FireWall-Port
X-Device-Type
Release
Time
X-VCT
X-FW-Version
X-Vgn-Hpd-Reason
DSUID
X-Ua
X-Varnish-Hits
X-S
Now
X-Rendered-As
X-OVcl
X-OVcl-Cache
Hostname
X-Real-IP
OT-Force-Account-Verify
X-Litespeed-Cache
Fastcgi-X-Cache-Version
X-Pubstack
ServedBy
X-NGENIX-Cache
Access-Control-Request-Headers
X-Redis-Cache
X-DataStream-Cache-Status
Origin-Cache-Control
Origin-Edge-Control
X-VG-TLSProxy
X-XRDS-LOCATION
X-SS-Set-Cookie
L5d-Success-Class
Cteonnt-Length
Accept-Language
X-VG-WebCache
X-HS-Combine-CSS
NtCoent-Length
X-Webkit-Csp
Origin
X-FB-TRIP-ID
X-Sorting-Hat-ShopId
X-ShopId
X-Shopify-Stage
X-ShardId
X-Sorting-Hat-PodId
X-Alternate-Cache-Key
X-APP-VERSION
Fastly-SSL
SRV
X-App-Version
X-Tb
Machine
X-Origin-TTL
X-Parent-Response-Time
X-Origin-CC
X-CSRF-TOKEN
X-UUID
X-Tt-Trace-Tag
X-Cluster-Name
X-Ttl
X-GEO
X-Load-Cache
X-Environment-Context
X-GoCache-CacheStatus
X-L-Path
X-No-Session
X-NC
X-ECACHE
X-Rocket-Nginx-Bypass
IBM-Web2-Location
Nel
X-ServerID
X-B3-Spanid
X-Soup
X-Guploader-Uploadid
Mime-Version
X-Nginx-Cache
X-B3-Parentspanid
NGX
X-Uri
X-CACHE-KEY
X-Amzn-Remapped-Content-Length
X-Is-Bot
X-Endurance-Cache-Level
X-Magnolia-Registration
Proxy-Connection
ServerName
Akamai-GRN
X-Mode
Apple-News-Services-Handled
X-Worker
X-Vtex-Remote-Cache
A
X-Vtex-Processado-Em
X-VG-WebServer
X-CF-Lambda-Version
Apple-News-Services-Host
X-CF-Lambda-Fn
X-MServer
Xc-Version
X-Application
X-Accel-Expires-Debug
X-AIR-PT
X-D
X-Node-Id
X-Aed
X-ARC
X-A-Wwc
X-B-Cookie
X-A-Dam
Fly-Request-Id
GEO-REGION-INFO
X-DPWN-IS-SECURE
X-External-Request-Id
Fly-Cache
X-Rojux
X-Connection-Hash
T-Server
Cross-Origin-Window-Policy
Rt-Proxy-Cache
MD5-Digest
X-Rewrite-Enabled
Node
Odigeo-Trace-Id
Rendered-Blocks
X-Instart-Info
Mobile-Detection-Method
X-Region-Sid
Memcached
X-G
Meta-Geo-Continent
X-Request-UUID
Content-Style-Type
Viewtype
Apple-News-Services-Request-Url
X-PAYTM-SRV-ID
X-Destination
X-Detected-As
X-SRCache-Key
Apple-News-Services-Parsed-Url
X-Date
X-Trv-Group
X-A-Dcw
X-Transaction
Arc-Country
AsisCache
VivaBuild
X-S-Cookie
Cache-Prefix
Content-Script-Type
X-Developer
X-A
X-Server-Time
X-ScT
X-A-Ccd
BehaviorPad-Version
X-Twitter-Response-Tags
X-A-Dgt
Request-Time
X-B3-SpanId
X-Generated-By
X-Ruxit-Js-Agent
X-LJ-Flow-ID
X-Tec-Api-Origin
Backend-Name
X-VWS-Id
X-AWS-Id
X-Tec-Api-Version
X-Tec-Api-Root
Fastly-Soc-X-Request-Id
X-Fastly-Cache
Cdn-Host
X-Origin-Expires
X-Release
We-Hiring
Mail-Subject
X-Edge-Server
X-Origin-Date
X-Cms-Context
Request-EU
Request-Country
X-Azure-Ref-OriginShield
X-Azure-Ref
Section-Io-Cache
X-Cache-Bucket
X-Cdn-Srv
Locale
X-Developers
CF-IPCountry
X-S-Maxage
N-Cache
IsBot
Cdn-Request-Time
X-Urbn-Site-Id
X-VC-Cache
X-SVT-ORM-RULES
X-SIPLIST1
X-Dc
X-Up
X-Urbn-Context-Path
X-SVT-ORM-VERSION
X-Hl-Ver
User-Cache-Control
X-Request-Time
X-Cdn-Forward
X-WADP-Cache
X-Cdn-Origin
X-Cache-Info
X-VServer
X-Clara-WADP
X-Clientip
X-Compress-Hint
X-We-Are-Hiring
X-Core-Mission
X-BBXSRF
X-App-Name
X-Var-Ttl
X-Auto-Login
W
Uber-Trace-Id
Thinkindot-Control
True-Client-Country-4JS
X-CUA
X-Backend-Host
X-Bip
X-Block-Status
X-UA
X-Wikidot-Backend
X-Backend-Url
X-Wikidot-Static-Cache
X-C
X-Distil-CS
X-Nginx-Cache-Key
X-Sn-Servicetimems
X-Policy
X-Method
X-Matched-Rule
X-Location
Thinkindot-CacheControl-Type
X-Qloud-Router
X-Skip-Cache
X-Reboot
X-Service
X-ServiceProvider
X-Rebelmouse-Surrogate-Control
X-RateLimit-Limit-Second
X-Rebelmouse-Cache-Control
X-Level-Front-Cache
X-IN-APIGATEWAYSSL
X-ElasticPress-Search
X-Thanos
X-Thinkindot-L3
X-Distributor
X-TrackingId
X-Server-IP
X-GDPR
X-Gen-Mode
X-Hnp-Log
X-IN-APIGATEWAY
X-Geo-Header
X-Generation-Time
X-Swa-Ws
X-Generated-On
X-Device-Os
X-RateLimit-Remaining-Second
AKAMAI
Thinkindot-CacheControl
Esi-Enabled
Fastly-SIE
RNT-Time
RNT-Machine
Pramga
CDCHOST
Content-Disposition
Fastly-SWR
Countrycode
L
Gh-Request-Id
Magicmarker
Heartbleed
Server-Int
X-Microcachable
X-Debug-Cookies
X-Debug-Cache-Store
X-MSEdge-Flight
X-MSEdge-Features
X-LI-UUID
X-Epic-Correlation-Id
X-Li-Pop
Cache-Provider
X-Eu-Site
X-GeoIP-City
X-Generated-In
X-Internal-Host
X-Hash
X-Fetched-On
X-Li-Fabric
X-Debug-Log
X-LI-Proto
X-Org
Server-Host
Served-By
Adler-Geo
Wxu-Next-Commit
Wxu-Next-Hostname
Pagetype
Kp-EeAlive
X-WebServer
X-Via-CDN
X-Variation
Ha-Gx-Prefs
HA-Ipaddr
X-SayCDN-TTL
X-Say-TTL
X-Debug-Cache-Expiry
X-PHP-Host
X-Owner
X-Irp-Debug
X-Old-Content-Length
X-CGP
X-Platform-Server
X-Request-URI
X-Say-Cacheable
X-Request-Start
Wxu-Next-Region
X-BYPASS-REASON
X-Debug-Cache-Fetch
X-Dispatch
X-Is-Gdpr
X-JWT-State
X-Has-Esi
X-Webstats-RespID
Memory
V-Age
Server-ID
Web-Mar-Node
X-Backend-State
X-Amz-Meta-Cache-Control
Platform
X-Cache-FS-Status
X-Cache-Id
X-User
PFcat
Is-Eu
X-Proxy-Upstream
X-NX-Host
X-Proxy-Cache-Status
X-ProxyCache-Status
X-ProxyCache-Key
X-Reqid
Srv
X-COUNTRY
X-Servername
X-Flog
X-SD-PageType
X-Hello
X-Dispatcher-Server
SD-X-WS
X-Key
X-ABtesting
Resin-Trace
X-Info
X-Unique-ID
X-FPC
X-Nc
SS
X-URL
X-Lb-Id
X-Trafficlayer-App-Scope
X-NWS-UUID-VERIFY
X-Trafficlayer-App-Name
X-DataStream-MidMile-RTT
X-DataStream-Origin-MEX-Latency
X-Wa
X-Response-By
X-Geo
REQUESTUUID
X-Ratelimit-Limit
X-Proxied
X-Zipkin-Id
X-Be
X-RateLimit-Reset
X-IPS-LoggedIn
X-Routing-Service
X-DC
Country-Code
X-Servedbyhost
X-Svr
Cache-Cookie-Set-Idcheck
X-Cache-URL
Cache-Cookie-Set-From
Cache-Cookie-Set-Lfrom
X-Page-Type
X-Instart-Isnd
X-Dynatrace-Js-Agent
X-Datadome
X-Scheme
UCS
X-Cache-Backend
X-Processor
CACHE
X-MP-GENERATED-AT
X-VCL-Version
X-NodeID
X-Pjax-Url
X-SRV
XServer
Ajk
Powered-By-ChinaCache
X-SN
X-Logtrace-Id
Group
X-Oracle-Dms-Rid
X-Varnish-Beresp-Ttl
X-Oss-Storage-Class
Dynatrace
X-Oss-Server-Time
X-CDN-Forward
X-Oss-Request-Id
Proxy-Firewall
X-Oss-Hash-Crc64ecma
X-HTML-Minification-Powered-By
ProcessTime
X-Oss-Object-Type
X-Server-W
Cache-Host
PICS-Label
SN
X-ZONE
X-Tb-Optimization-Total-Bytes-Saved
X-HS-Status
Powered-By
X-Ftr-Request-Id
X-Zone
X-Dynatrace
X-Cache-Category-Id
X-Newrelic-Synthetics
X-Grey
X-Varnish-Beresp-Grace
X-Source
X-Varnish-Beresp-Status
X-EC-Lua
X-GRACE
X-Ms-Version
X-Ms-Request-Id
X-Pf-Uncompressing
X-Via-Ucdn
Ttl
X-Ratelimit-Remaining
GeoIp-Country-Code
Geoip-Latitude
Fastly-Backend-Name
Geoip-City
X-APP
X-FORWARDED-FOR
X-TH-Server
X-LiteSpeed-Cache-Control
X-Varnish-Beresp-TTL
X-Sucuri-Id
X-Session-Fingerprint
GeoIP-Country-Code
X-PF-Uncompressing
GeoIP-City
GeoIP-Latitude
Lfy
X-NODE
GW-Server
X-Ftr-Cache-Host
X-Agile-Id
X-Agile-Age
X-Agile
X-Cache-Debug
Cdn
MIME-Version
X-Check-Cacheable
LB
X-Tt-Trace-Host
X-LAGOON
X-Fastly-Country-Code
Pics-Label
Environment
X-RCS-CacheZone
Amp-Access-Control-Allow-Source-Origin
X-Bc
X-Aicache-OS
CF-Cached-On
X-Gannett-Site-Version
X-Logging-Id
X-7Graus-Varnish-Cache-Control
X-Edge
X-Secret
X-7Graus-Varnish-XKeys
X-Varnish-Url
X-BC
X-Cache-Miss-From
M-TraceId
WWW
Cf-Ipcountry
WZWS-RAY
X-Sedo-Request-Id
X-Ftr-Backend-Server
X-Ftr-Backend
X-Ftr-Balancer
X-Ftr-Dc
X-Ftr-Realm
X-CSRF-Token
Requestid
X-Vcl-Version
X-Mid
X-CDN-Cache
Ohc-Response-Time
X-Varnish-Cacheable
On-Server
X-PJAX-URL
X-Akamai-SSL-Client-Sid
X-Varnish-Ttl
X-MCACHE
X-Core-Value
X-GeoIP-Country-Code
X-UPSTREAM-Address
X-Fastly-Backend-Reqs
X-Cache-Ttl
User-Agent
DataCenter
X-Cache-Tag
Inserted-Into-Cache-At
Cdncip
X-Sucuri-ID
X-AK-Request-ID
X-Litespeed-Cache-Control
Cdnsip
Lb
X-NGINX-Cache
Tcn
X-Unique-Id
X-NU-AKA-ACS-Version
X-TT-LOGID
X-DB
X-DI
X-Action
X-Sucuri-Cache
SID
CDN
X-DSS
X-RSL
URI
X-Vdms-Version
Xkeyrz
X-RPS
X-Proxy-Cacherz
X-BE
X-DW
X-RPM
HostName
Who
X-ServedByHost
X-Sigma
X-Rocket-Build-Number
RequestUuid
X-Swift-Error
Host-ID
X-Crawler
X-Fstrz
X-WA
X-Sigma-Backend
X-Render-Time
X-Correlation-ID
Is-Session-Tracking
X-Shopify-Generated-Cart-Token
X-Planisys-CDN-Cache
Pragrma
X-Planisys-CDN-Rules
Get-Access-Time
X-Planisys-CDN-TTL
X-Fastly-Cache-Hits
Xkeypdq
X-Flow-Id
X-WR-MODIFICATION
X-LB-ID
Warning
X-Page-Impression-Id
X-Fpc
X-Zalando-Child-Request-Id
Server-Id
X-TIME
X-FE
X-Micro-Cache
X-Refresh
X-Cdn-Request-ID
X-Via-NSCOPI
X-SB
FNAC-ModuleRouting
X-MID
X-HostName
X-VC
Correlation-Id
X-ServerName
X-Nananana
X-Cf-Powered-By
TTL
X-Trafficlayer-App-Version
X-Served-From
X-Via-Edge
X-Fe
X-LiteSpeed-Tag
X-Gen-Id
Processtime
X-MiniProfiler-Ids
X-Newrelic-App-Data
Cneonction
X-Dw-Trace-Id
X-Gdpr
X-Bug-Bounty
HitType
V-Cache
X-Request-URL
X-ECache
Xet-Cookie
X-Via-SSL
RequestId