Threat Level: green Handler on Duty: Manuel Humberto Santander Pelaez

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
CF-RAY
CF-Cache-Status
Link
X-Powered-By
X-XSS-Protection
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Alt-Svc
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
Content-Security-Policy-Report-Only
X-Generator
X-Cacheable
X-Cache-Status
X-Permitted-Cross-Domain-Policies
X-Xss-Protection
Timing-Allow-Origin
X-Template
X-DNS-Prefetch-Control
X-Language
X-Request-ID
X-Iinfo
Status
X-Content-Security-Policy
X-AspNetMvc-Version
Content-Encoding
X-Buckets
X-Kinja-Server-Push
Xkey
Upgrade
X-Via
Access-Control-Expose-Headers
X-Turbo-Charged-By
Keep-Alive
Access-Control-Max-Age
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Pass-Why
P3p
EagleId
X-Age
X-Backend
X-Envoy-Upstream-Service-Time
X-Robots-Tag
X-Amz-Request-Id
X-Amz-Id-2
X-Page-Speed
X-Ua-Compatible
X-CDN
X-Pingback
X-Server-Powered-By
X-Proxy-Cache
X-Hacker
X-UA-Device
X-AH-Environment
X-Server
Request-Context
X-Nginx-Cache-Status
Grace
X-Swift-SaveTime
X-Swift-CacheTime
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-Cdn
X-LiteSpeed-Cache
Cf-Railgun
X-Amz-Version-Id
Server-Timing
Feature-Policy
X-WebKit-CSP
X-Device
X-Server-Id
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-OneAgent-JS-Injection
X-Rq
X-Ac
X-Cnection
X-Cloud-Trace-Context
Report-To
EagleEye-TraceId
X-Response-Time
X-Backend-Server
X-Host
Request-Id
X-Node
Content-Location
X-Dns-Prefetch-Control
X-Origin-Cache
X-Readtime
X-Vhost
X-Application-Context
X-Cache-Lookup
X-ORACLE-DMS-ECID
X-Dispatcher
X-ORACLE-DMS-RID
NEL
X-Ruxit-JS-Agent
X-DataDome
X-Origin-Upstream-Status
X-Rack-Cache
Surrogate-Control
X-HW
Allow
Rating
X-Country-Code
X-Clacks-Overhead
X-FTR-Request-ID
X-Country
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Url
X-DynaTrace
Fusion-Source
Fusion-Component-Id
X-Instart-Request-ID
Fusion-Content-Source
Fusion-Content-Id
Fusion-Template-Id
X-TTL
X-Goog-Hash
X-MS-InvokeApp
X-Varnish-TTL
X-TtlSet
X-PC
X-Vname
X-Ah-Environment
Verso
X-Powered-By-Plesk
RTSS
Public-Key-Pins
Edge-Control
Pinterest-Generated-By
X-Px
X-Mod-Pagespeed
X-CST
X-VARITI-CCR
X-Recruiting
X-Middleton-Display
Response
X-Sol
X-Middleton-Response
Display
X-D2id
X-Kinja-Server
X-Use-Magma
X-GoogleNews-Bot
X-Kinja
X-Kinja-Build
X-Exp-Variant
X-Cdn-Fetch
X-Kinja-Revision
Service-Worker-Allowed
X-Exp-Id
X-B3-TraceId
SPRequestGuid
X-SharePointHealthScore
X-Vcap-Request-Id
X-Version
X-Akam-SW-Version
Accept-CH
TCN
X-Abt-Application-Version
X-GitHub-Request-Id
MS-Author-Via
X-Navigation-Version
X-Powered-CMS
SPIisLatency
SPRequestDuration
Accept-Ch-Lifetime
X-ESI
X-Server-Name
X-Shard
Fastly-Restarts
Charset
X-Amz-Server-Side-Encryption
X-RateLimit-Remaining
X-Upstream
X-Trace
Nginx-Cache
AR-ATIME
X-Forwarded-Proto
X-Debug
X-Amz-Rid
AR-PoweredBy
AR-CACHE
Ar-Sid
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Realpath
X-Aspnetmvc-Version
X-XRDS-Location
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Ezoic-Cdn
Front-End-Https
X-Cached
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-NF-Request-ID
X-Goog-Stored-Content-Encoding
AR-Request-ID
X-MSEdge-Ref
Pagespeed
X-Shield-Request-Id
Access-Control-Request-Method
X-B3-TraceId-Primal
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
Mrf-Cache-Status
MRF-Tech
Arr-Disable-Session-Affinity
X-FTR-Cache-Status
X-FTR-Expires
X-Country-Code-Real
Content-MD5
X-VCache
Paypal-Debug-Id
MicrosoftSharePointTeamServices
X-Id
X-Goog-Storage-Class
X-Amz-Meta-S3cmd-Attrs
X-FTR-Realm
X-FTR-Balancer
X-FTR-DC
X-FTR-Backend-Server
X-FTR-Backend
S
ServerID
X-T
X-Fastly-Request-ID
DynaTrace
X-Via-JSL
X-Varnish-Age
X-Client-IP
X-Content-Type
X-Ser
X-Hits
X-DynaTrace-JS-Agent
X-Correlation-Id
X-Dw-Request-Base-Id
X-Grace
X-Amzn-Trace-Id
X-Accel-Expires
X-Server-ID
X-FastCGI-Cache
Fastcgi-Cache
X-SERVER
X-Content-Digest
X-Vcache
X-Frontend
Powered
X-N
X-DIS-Request-ID
X-FTR-Cache-Host
AMP-Access-Control-Allow-Source-Origin
PB-PID
X-Mobile-Rewrite
Arc-Version
PB-RID
X-Forwarded-For
Edge-Cache-Tag
Server-Name
X-HS-Hub-Id
X-HS-Content-Id
X-Logged-In
X-RateLimit-Limit
X-GUploader-UploadID
TP-Cache
TP-L2-Cache
X-Microsite
X-Request-Handler-Origin-Region
Accept-Ch
X-B3-Sampled
X-Request-Received
X-Request-Processing-Time
X-Cache-Age
X-Kinsta-Cache
X-Type
X-Zen-Fury
X-Analytics
X-AppVersion
X-Az
Backend-Timing
X-Activity-Id
X-Fastcgi-Cache
X-Rid
X-IPLB-Instance
X-User-Agent
X-Revision
X-LB-Cache
Pinterest-Version
X-Pinterest-Rid
Retry-After
Healthy
FilterID
X-Node-Name
X-Whom
X-Time
X-Cache-Hit
X-B3-Traceid
X-Srv
X-NWS-LOG-UUID
Server-Node
X-F-Cache
Accept-Charset
X-Cache-2
Alternate-Protocol
X-Erf-Bev-Bev-Is-Generated
X-Cache-Rule
X-Erf-Bev-Bev
X-Hp-Webp
X-Kong-Upstream-Latency
X-Esi
X-Kong-Proxy-Latency
X-Amzn-RequestId
X-Amz-Apigw-Id
Cache-Status
Cache-Tag
X-TA-CDN-Provider
X-Akamai-Edgescape
X-Content-Options
Refresh
Surrogate-Key
X-Content-Security-Policy-Report-Only
X-AOL-HN
X-Instance
VIX-Pulpo-Upstream-Status
X-Forwarded-Host
VIX-Pulpo-Node
X-Content-Powered-By
X-Debug-Info
Access-Control-Allow-Method
X-Webkit-CSP
DC
Tracecode
X-Tumblr-User
X-Cluster
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Jobs
MS-CV
X-Varnish-Grace
X-Page-Id
Fastcgi-Useragent
X-PHP-Backend
X-FB-Debug
X-Request-Guid
X-FW-Serve
Source
X-FW-Server
X-FW-Hash
X-Framework
X-FW-Static
X-FW-Type
X-App-Environment
Frame-Options
X-B
X-App-Server
X-Cache-Operation
X-Hostname
X-Mobile-URL
Actual-Object-TTL
Host
X-Cache-Key
X-Seen-By
X-Geo-Country
X-Cache-Control
Cleartype
X-Signature
X-B-Cache
X-Cache-TTL
X-Acc-Meta-Resource-Type
X-BCube-Filmed-By
X-Host-Name
X-Cached-By
X-Git-Hash
X-Pad
X-Amz-Replication-Status
NR-ENABLED
Upgrade-Insecure-Requests
X-TT
X-Varnish-Backend
X-Response-Served-From
NGB
Accept-CH-Lifetime
X-Adobe-Loc
X-Adobe-Content
X-WebKit-CSP-Report-Only
X-TT-TIMESTAMP
X-Mobile
Liferay-Portal
X-RemovedCookies
X-ProcessESI
WPE-Backend
Payment
Cache-Tv-Group
X-RTag
X-ATG-Version
Webserver
X-Tumblr-Pixel-1
X-TX-ID
X-Tumblr-Pixel-2
X-Handled-By
Ms-Operation-Id
Eomportal-Instance
From-Origin
GEO-INFO
X-Cache-Remote
X-Drupal-Cache-Tags
X-Status
Filters
X-Cacheable-TTL
X-RequestSource
X-GeoIP
X-Cache-TTL-Remaining
X-UA-Device-Type
X-FW-Dynamic
X-Daa-Tunnel
X-EdgeConnect-Cache-Status
X-WA-Info
X-Origin-Server
X-Cache-Action
X-Content-Age
X-Presslabs-Stats
X-Wix-Request-Id
X-Hyper-Cache
X-Storage
X-Edge-Location
Datacenter
Viewport
X-Contextid
Xserver
X-Region
Version
X-Ratelimit-Reset
X-CF-Powered-By
X-Varnish-Hostname
X-PressLabs-Stats
X-HS-Cache-Config
X-Accel-Buffering
X-Element-Page-Cache
Cache
Host-Header
PageSpeed
X-Akamai-Transformed
X-Cache-NE
Ohc-File-Size
X-Cache-Var-Map
X-RN-RSRV
Meta-Geo
X-Path-Route
X-ES-SERVER
Load-Balancing
X-Cache-Var
S-Cnection
X-IP
X-Varnish-Server
X-Cache-Server
X-Yottaa-Optimizations
Cache-Tags
X-Yottaa-Metrics
X-Via-Fastly
X-CS
X-Viewer-Country
X-Cache-Config
X-Origin-Response-Time
X-Proto
X-TNCMS
X-Section
X-Loop
X-Time-Microsecs
X-NCache
X-Tumblr-Pixel-3
Decoy-Debug-Key
X-Proxy
Vix-Hermes-Req-Id
Decoy-Debug-Status
X-Access
X-Akamai-Request-ID
X-ApacheServer
Ec-Rule-Version
Cache-Name
Decoy-Debug-TTL
X-PERF
X-NewRelic-App-Data
Azure-SlotName
X-Format
X-Origin
Azure-Version
X-From
Azure-InstanceId
X-Labrador-Cache-Channel
Cache-Key
X-Rule
X-OCL
X-Backend-TTL
Azure-SiteName
Azure-RegionName
DB-Nickname
X-Web-Node
X-Cache-Time
Cache-Hits
X-CCM
X-R9-Blue-Green-Version
X-Upstream-CT
X-Cache-Grace
X-Akamai-Request-ID2
X-PCL
X-Cache-Enabled
X-Upstream-HT
X-FC-Vary-Parameters
X-Xfnlog-Site
S-Rt
Rt-Fastcgi-Cache
X-Drupal-Cache-Contexts
X-Upgrade-Enabled
X-Cluster-Node
Selected-Fe
X-Generated
X-JoinUs
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Locale
X-Hit
X-Human
X-Hosted-By
X-Proxy-Build
Webcakes-Region
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Locale-Group
TWC-Privacy
TWC-Device-Class
TWC-Connection-Speed
Mn-Server-Ip
X-Www-Served-By
Property-Id
X-Upstream-Proxy
X-Timing-Wait
Webcakes-App-Name
X-Varnish-Cache-Hits
Country
X-Site-Version
X-Backend-Name
Webcakes-App-Version
X-Origin-Hint
X-FireWall-Port
X-UnsetCookies
X-EIG-Tracking-Id
X-Cache-Host
X-Debug-Cache
Release
Server-Info
Ohc-Cache-HIT
Time
X-Trace-Id
X-Ua
X-Ttl
X-Device-Type
X-FW-Version
X-Vgn-Hpd-Reason
X-S
X-Rendered-As
X-Varnish-Hits
Now
X-VCT
X-OVcl-Cache
DSUID
X-OVcl
Hostname
X-APP-VERSION
X-Real-IP
X-NGENIX-Cache
X-SS-Set-Cookie
OT-Force-Account-Verify
X-Pubstack
Fastcgi-X-Cache-Version
X-HS-Combine-CSS
X-Redis-Cache
Access-Control-Request-Headers
X-VG-TLSProxy
L5d-Success-Class
Origin-Cache-Control
Origin-Edge-Control
X-Litespeed-Cache
ServedBy
Origin
X-VG-WebCache
X-DataStream-Cache-Status
Cteonnt-Length
Accept-Language
Fastly-SSL
X-XRDS-LOCATION
X-NC
X-FB-TRIP-ID
X-Parent-Response-Time
X-Sorting-Hat-PodId
X-ShardId
X-Sorting-Hat-ShopId
X-Shopify-Stage
X-Tb
X-ShopId
NtCoent-Length
X-B3-Spanid
X-Origin-CC
X-Origin-TTL
X-Alternate-Cache-Key
Machine
SRV
X-UUID
X-CSRF-TOKEN
X-Cluster-Name
X-Tt-Trace-Tag
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
X-GoCache-CacheStatus
X-Rocket-Nginx-Bypass
X-Environment-Context
X-L-Path
X-Load-Cache
X-ServerID
IBM-Web2-Location
X-ECACHE
X-GEO
X-App-Version
X-No-Session
X-B3-Parentspanid
NGX
X-Nginx-Cache
X-Uri
Nel
X-Is-Bot
X-Magnolia-Registration
CF-IPCountry
X-Soup
X-Endurance-Cache-Level
X-Amzn-Remapped-Content-Length
X-CACHE-KEY
Mime-Version
Akamai-GRN
ServerName
X-Node-Id
MD5-Digest
GEO-REGION-INFO
Fly-Request-Id
Memcached
Mobile-Detection-Method
Rt-Proxy-Cache
T-Server
Rendered-Blocks
Odigeo-Trace-Id
Node
Meta-Geo-Continent
Cross-Origin-Window-Policy
BehaviorPad-Version
Apple-News-Services-Parsed-Url
Viewtype
AsisCache
Apple-News-Services-Request-Url
Cache-Prefix
Apple-News-Services-Host
A
Arc-Country
Content-Style-Type
Content-Script-Type
Apple-News-Services-Handled
Fly-Cache
X-B-Cookie
X-Rewrite-Enabled
X-Rojux
X-S-Cookie
X-ScT
X-Request-UUID
X-Region-Sid
X-G
X-Instart-Info
X-PAYTM-SRV-ID
X-Server-Time
X-SRCache-Key
X-Vtex-Remote-Cache
X-Worker
Xc-Version
X-Vtex-Processado-Em
X-VG-WebServer
X-Transaction
X-Trv-Group
X-Twitter-Response-Tags
X-External-Request-Id
X-DPWN-IS-SECURE
X-A-Wwc
X-Accel-Expires-Debug
X-Aed
X-A-Dgt
X-A-Dcw
X-A
X-A-Ccd
X-A-Dam
X-Application
X-ARC
X-Destination
X-Detected-As
X-Developer
X-Date
X-D
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Connection-Hash
VivaBuild
X-AIR-PT
Proxy-Connection
Backend-Name
X-Oneagent-Js-Injection
X-Mode
X-Cache-Bucket
X-Developers
X-S-Maxage
X-SIPLIST1
Request-Time
X-Generated-By
X-Origin-Date
X-Azure-Ref-OriginShield
Request-Country
X-Fastly-Cache
IsBot
X-Azure-Ref
Fastly-Soc-X-Request-Id
Locale
X-Origin-Expires
N-Cache
X-Cdn-Srv
X-Up
Section-Io-Cache
X-Urbn-Context-Path
X-Urbn-Site-Id
X-VC-Cache
X-MServer
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Hl-Ver
Request-EU
X-Cms-Context
X-Trafficlayer-App-Name
X-VWS-Id
X-AWS-Id
User-Cache-Control
X-Trafficlayer-App-Scope
X-LJ-Flow-ID
X-Cache-Info
X-C
X-Block-Status
X-Cdn-Origin
W
Thinkindot-CacheControl-Type
Thinkindot-Control
Thinkindot-CacheControl
Server-Int
RNT-Machine
RNT-Time
True-Client-Country-4JS
Uber-Trace-Id
X-Auto-Login
X-Backend-Host
X-App-Name
We-Hiring
Mail-Subject
X-Backend-Url
X-Dc
X-ServiceProvider
X-Skip-Cache
X-Release
X-Reboot
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Sn-Servicetimems
X-Thinkindot-L3
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-We-Are-Hiring
X-WADP-Cache
X-TrackingId
X-VServer
X-Policy
X-Nginx-Cache-Key
X-Distributor
X-Edge-Server
X-Distil-CS
X-Core-Mission
X-Clientip
X-Compress-Hint
X-ElasticPress-Search
X-Gen-Mode
X-Matched-Rule
X-Method
X-Location
X-Hnp-Log
X-Generation-Time
X-Geo-Header
X-Clara-WADP
X-GDPR
Countrycode
Fastly-SWR
Esi-Enabled
L
Magicmarker
CDCHOST
Content-Disposition
AKAMAI
Cdn-Host
Cdn-Request-Time
Gh-Request-Id
Fastly-SIE
X-Request-Time
X-Microcachable
X-MSEdge-Features
X-MSEdge-Flight
X-PHP-Host
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Qloud-Router
X-LI-UUID
Adler-Geo
X-Old-Content-Length
X-Internal-Host
X-Fetched-On
X-Generated-On
X-Epic-Correlation-Id
X-Device-Os
X-B3-SpanId
X-GeoIP-City
X-IN-APIGATEWAY
X-Li-Pop
X-Li-Fabric
X-Level-Front-Cache
X-IN-APIGATEWAYSSL
X-LI-Proto
X-Request-URI
X-Eu-Site
X-Generated-In
X-Irp-Debug
X-Debug-Log
X-Debug-Cookies
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-NX-Host
X-Proxy-Cache-Status
X-Has-Esi
X-Is-Gdpr
X-JWT-State
X-Var-Ttl
X-ProxyCache-Status
X-Proxy-Upstream
X-ProxyCache-Key
X-Debug-Cache-Expiry
X-CUA
X-Server-IP
X-Servername
X-Service
X-SayCDN-TTL
X-Say-TTL
X-UA
X-Say-Cacheable
X-Swa-Ws
X-Thanos
X-BYPASS-REASON
X-CGP
HA-Ipaddr
Ha-Gx-Prefs
X-Variation
X-WebServer
X-Request-Start
X-Platform-Server
X-Bip
Web-Mar-Node
X-BBXSRF
PFcat
V-Age
X-Cache-Id
Memory
X-Cache-FS-Status
Srv
X-Guploader-Uploadid
Platform
Pramga
X-Backend-State
Heartbleed
Is-Eu
X-Amz-Meta-Cache-Control
Served-By
Pagetype
X-Via-CDN
X-Owner
X-Info
X-SD-PageType
X-Org
Kp-EeAlive
Server-Host
Cache-Provider
SD-X-WS
X-Key
X-Reqid
X-User
X-Webstats-RespID
Resin-Trace
Server-ID
X-Hash
Wxu-Next-Hostname
Wxu-Next-Commit
Wxu-Next-Region
X-Dispatch
X-Cdn-Forward
X-Flog
X-ABtesting
X-Dispatcher-Server
X-FPC
X-Wa
X-COUNTRY
X-Hello
X-NWS-UUID-VERIFY
X-Geo
SS
X-URL
X-Servedbyhost
X-Lb-Id
X-DataStream-Origin-MEX-Latency
X-DataStream-MidMile-RTT
X-DC
X-Unique-ID
REQUESTUUID
X-Cache-URL
X-Svr
X-Response-By
X-RateLimit-Reset
X-Zipkin-Id
X-Ratelimit-Limit
X-IPS-LoggedIn
X-Routing-Service
X-Be
X-Proxied
X-Nc
Cache-Cookie-Set-Lfrom
Country-Code
Cache-Cookie-Set-From
Cache-Cookie-Set-Idcheck
X-Instart-Isnd
X-Scheme
X-Processor
XServer
X-CDN-Forward
X-Page-Type
X-VCL-Version
X-Dynatrace-Js-Agent
X-Datadome
UCS
X-Cache-Backend
CACHE
X-MP-GENERATED-AT
X-NodeID
X-Varnish-Beresp-Ttl
X-SRV
X-Oss-Object-Type
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-ZONE
X-Pjax-Url
Powered-By-ChinaCache
X-Oss-Storage-Class
PICS-Label
Ajk
X-SN
X-Logtrace-Id
X-Ruxit-Js-Agent
Group
X-HTML-Minification-Powered-By
X-Oracle-Dms-Rid
X-Server-W
ProcessTime
Dynatrace
Proxy-Firewall
X-Newrelic-Synthetics
X-Webkit-Csp
Cache-Host
X-Ftr-Request-Id
Powered-By
X-HS-Status
X-Tb-Optimization-Total-Bytes-Saved
X-EC-Lua
X-Dynatrace
SN
X-Grey
Ttl
X-Cache-Category-Id
X-Pf-Uncompressing
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-Source
X-GRACE
X-Zone
X-Ms-Version
X-Via-Ucdn
X-Ms-Request-Id
X-Ratelimit-Remaining
X-Session-Fingerprint
X-APP
X-TH-Server
Geoip-Latitude
X-FORWARDED-FOR
Fastly-Backend-Name
Geoip-City
GeoIp-Country-Code
X-Varnish-Beresp-TTL
X-LiteSpeed-Cache-Control
GeoIP-City
Lfy
MIME-Version
GeoIP-Country-Code
X-Sucuri-Id
GeoIP-Latitude
X-PF-Uncompressing
X-Cache-Debug
X-Check-Cacheable
X-NODE
X-Agile-Id
X-Agile-Age
X-Agile
X-Ftr-Cache-Host
GW-Server
X-BC
X-LAGOON
X-Fastly-Country-Code
Cdn
X-Tt-Trace-Host
X-7Graus-Varnish-Cache-Control
Environment
LB
X-7Graus-Varnish-XKeys
X-Bc
X-RCS-CacheZone
X-Varnish-Url
X-Sedo-Request-Id
Pics-Label
X-Aicache-OS
X-Logging-Id
X-Secret
CF-Cached-On
X-Gannett-Site-Version
X-Edge
X-Cache-Miss-From
X-Cache-Ttl
M-TraceId
WZWS-RAY
WWW
X-PJAX-URL
X-CSRF-Token
X-Ftr-Dc
X-Ftr-Realm
X-Ftr-Backend
X-Ftr-Backend-Server
X-Unique-Id
X-Ftr-Balancer
On-Server
X-CDN-Cache
X-Varnish-Cacheable
X-Mid
X-Core-Value
X-Cache-Tag
Ohc-Response-Time
Requestid
X-Akamai-SSL-Client-Sid
X-Sucuri-ID
Cf-Ipcountry
Cdnsip
X-Varnish-Ttl
Cdncip
DataCenter
User-Agent
X-MCACHE
X-GeoIP-Country-Code
X-Fastly-Backend-Reqs
X-UPSTREAM-Address
X-Vcl-Version
X-AK-Request-ID
Amp-Access-Control-Allow-Source-Origin
X-Vdms-Version
X-TT-LOGID
Inserted-Into-Cache-At
X-Litespeed-Cache-Control
CDN
X-Swift-Error
X-NGINX-Cache
Lb
X-BE
X-NU-AKA-ACS-Version
X-Sigma-Backend
X-Action
SID
X-Fstrz
X-DSS
X-RSL
X-DB
URI
X-Proxy-Cacherz
Xkeyrz
X-Sigma
X-Rocket-Build-Number
X-Sucuri-Cache
X-RPM
X-RPS
X-DI
X-DW
X-SERVER-NAME
HostName
Who
X-Render-Time
Host-ID
RequestUuid
X-Crawler
X-Correlation-ID
Server-Id
Get-Access-Time
Pragrma
Is-Session-Tracking
X-Page-Impression-Id
X-Refresh
X-Fpc
X-Shopify-Generated-Cart-Token
X-WR-MODIFICATION
X-Planisys-CDN-Rules
Warning
X-Via-NSCOPI
X-ServedByHost
X-WA
Xkeypdq
X-Fastly-Cache-Hits
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
X-LB-ID
X-Flow-Id
X-Zalando-Child-Request-Id
X-TIME
X-VC
X-Nananana
X-FE
X-Cdn-Request-ID
X-MID
X-Micro-Cache
X-SB
Correlation-Id
FNAC-ModuleRouting
X-Cf-Powered-By
X-Gen-Id
X-Akamai-ERRuleID
X-LiteSpeed-Tag
TTL
X-Trafficlayer-App-Version
X-Akamai-ERPolicy
X-MiniProfiler-Ids
X-Bug-Bounty
X-Fe
X-ServerName
HitType
X-ECache
X-Request-URL
Processtime
X-Via-SSL
X-Via-Edge
X-Gdpr
V-Cache
Xet-Cookie
X-Dw-Trace-Id
Cneonction
X-Served-From
X-Newrelic-App-Data
RequestId