Threat Level: green Handler on Duty: Bojan Zdrnja

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Pragma
Accept-Ranges
Last-Modified
Strict-Transport-Security
X-Content-Type-Options
X-Powered-By
CF-RAY
ETag
Link
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Access-Control-Allow-Origin
Content-Security-Policy
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Served-By
X-Varnish
X-Amz-Cf-Id
Referrer-Policy
X-Request-Id
X-Timer
X-AspNet-Version
CF-Cache-Status
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Runtime
Access-Control-Allow-Credentials
X-Download-Options
X-Drupal-Cache
X-Cacheable
Alt-Svc
X-Generator
Content-Security-Policy-Report-Only
X-Xss-Protection
X-AspNetMvc-Version
Status
X-Check
X-Cache-Status
Timing-Allow-Origin
X-Adblock-Key
X-DNS-Prefetch-Control
X-Iinfo
X-Permitted-Cross-Domain-Policies
X-Content-Security-Policy
X-CDN
X-Template
Content-Encoding
X-Language
X-Turbo-Charged-By
X-Request-ID
X-Buckets
Keep-Alive
P3p
X-Type
X-Via
Xkey
X-AH-Environment
EagleId
X-Backend
WPE-Backend
X-Age
X-Pass-Why
Access-Control-Max-Age
X-Cache-Group
X-Server
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Varnish-Cache
X-Pingback
X-Nginx-Cache-Status
Upgrade
X-Server-Powered-By
X-Drupal-Dynamic-Cache
Grace
Access-Control-Expose-Headers
X-Hacker
X-UA-Device
Cf-Railgun
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Ua-Compatible
X-Proxy-Cache
X-Envoy-Upstream-Service-Time
X-LiteSpeed-Cache
X-Page-Speed
Request-Context
X-CST
X-Node
X-Ac
X-Device
X-Cache-Lookup
Content-Location
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Cnection
X-WebKit-CSP
X-Host
X-Amz-Version-Id
Surrogate-Control
X-Backend-Server
X-Rack-Cache
X-Response-Time
X-Px
X-Rq
X-Readtime
Allow
Pinterest-Generated-By
X-Application-Context
X-Url
X-Instart-Request-ID
X-Clacks-Overhead
X-Server-Id
Request-Id
EagleEye-TraceId
Server-Timing
X-OneAgent-JS-Injection
X-Country
X-HeyJason
X-Do-Not-Hack
Permitted-Cross-Domain-Policies
X-Server-ID
Rating
Report-To
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Country-Code
X-Cloud-Trace-Context
Edge-Control
Charset
X-Varnish-TTL
X-ESI
X-Powered-CMS
X-Vname
X-TtlSet
X-PC
X-FTR-Request-ID
X-Server-Name
X-MS-InvokeApp
X-DataDome
X-CF-Powered-By
X-Cached
X-Goog-Hash
X-Vhost
X-TTL
NEL
Feature-Policy
X-Recruiting
Public-Key-Pins
X-DynaTrace-JS-Agent
X-Origin-Cache
X-Powered-By-Plesk
X-Geo-Segment
X-Exp-Variant
X-GoogleNews-Bot
X-Cdn-Fetch
X-Exp-Id
X-Kinja-Build
X-Kinja-Revision
X-Kinja
X-Kinja-Server
X-VARITI-CCR
X-F-Cache
X-T
X-DynaTrace
X-Dns-Prefetch-Control
X-Mod-Pagespeed
X-Version
X-D2id
Pinterest-Version
X-Pinterest-Rid
X-Upstream-Env
X-Client-IP
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
SPRequestGuid
Verso
X-Dispatcher
X-SharePointHealthScore
X-Abt-Application-Version
X-Ttl
X-SRCache-Store-Status
X-SRCache-Fetch-Status
PB-PID
PB-RID
X-Mobile-Rewrite
Arc-Version
X-N
Content-MD5
X-Forwarded-Proto
RTSS
X-Amz-Rid
X-Cdn
X-Hits
X-GitHub-Request-Id
X-Navigation-Version
AR-ATIME
AR-PoweredBy
X-Dw-Request-Base-Id
Nginx-Cache
AR-CACHE
Realpath
X-B
Paypal-Debug-Id
X-Content-Digest
X-Ruxit-JS-Agent
X-Upstream
X-Grace
X-Pad
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Content-Options
SPRequestDuration
SPIisLatency
X-Id
X-Shield-Request-Id
X-Varnish-Age
X-Kinsta-Cache
Arr-Disable-Session-Affinity
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-NWS-LOG-UUID
Access-Control-Request-Method
X-Acc-Meta-Resource-Type
MS-Author-Via
TCN
X-Oneagent-Js-Injection
X-Cache-Hit
X-Mrf-Item-Lastmod
Mrf-Cache-Status
MRF-Tech
X-Mrf-Section-Lastmod
X-Logged-In
DynaTrace
X-Trace
S
X-Vcap-Request-Id
X-Zen-Fury
X-HW
X-Origin-Upstream-Status
X-XRDS-Location
X-MSEdge-Ref
Front-End-Https
X-VCache
Cleartype
X-DIS-Request-ID
Eomportal-Instance
X-Frontend
X-FTR-DC
X-FTR-Cache-Status
X-FTR-Expires
X-FTR-Backend
X-HS-Hub-Id
X-HS-Content-Id
X-FTR-Balancer
X-FTR-Realm
X-Country-Code-Real
X-FTR-Backend-Server
Surrogate-Key
X-Via-JSL
X-Cache-Rule
X-PressLabs-Stats
X-Fastly-Request-ID
X-User-Agent
X-NF-Request-ID
X-Request-Processing-Time
X-Forwarded-For
X-Request-Received
Service-Worker-Allowed
Cache-Status
Fastcgi-Cache
Tracecode
Alternate-Protocol
X-IPLB-Instance
Server-Name
X-Sol
X-Middleton-Display
X-Hostname
Display
X-FastCGI-Cache
Host
X-Analytics
Backend-Timing
X-Varnish-Backend
MicrosoftSharePointTeamServices
Rt-Fastcgi-Cache
X-AOL-HN
FilterID
X-Fastcgi-Cache
Viewport
AR-SID
X-Middleton-Response
Response
X-Cache-2
TP-Cache
TP-L2-Cache
X-Az
X-Activity-Id
X-Wix-Server-Artifact-Id
X-AppVersion
X-Oracle-Dms-Rid
X-Ser
X-FTR-Cache-Host
Public-Key-Pins-Report-Only
X-Oracle-Dms-Ecid
X-Proxied
X-Rid
X-Whom
ServerID
X-Revision
X-SS-Set-Cookie
X-Contextid
X-Srv
X-Content-Powered-By
X-Cache-Control
X-Debug
X-Magnolia-Registration
X-Cached-By
Refresh
Powered-By-ChinaCache
X-Debug-Info
X-Cache-Key
AMP-Access-Control-Allow-Source-Origin
X-B3-Traceid
X-Cache-Server
X-Mobile
X-Instance
X-Akam-SW-Version
X-XRDS-LOCATION
Server-Info
HitInfo
HitType
X-Page-Id
Accept-Charset
X-Cache-Age
X-WPE-Loopback-Upstream-Addr
X-NewRelic-App-Data
X-Ruxit-Js-Agent
X-FB-Debug
X-Daa-Tunnel
X-Framework
X-Generated-By
X-LB-Cache
Cache-Tag
X-Content-Security-Policy-Report-Only
X-App-Server
Retry-After
X-Geo-Country
X-TT
X-B-Cache
X-PHP-Backend
X-BCube-Filmed-By
X-Request-Guid
X-Signature
X-Webkit-Csp
X-Varnish-Hostname
X-App-Environment
X-Tumblr-User
X-Tumblr-Pixel-0
X-ATG-Version
Host-Header
X-Tumblr-Pixel
X-Handled-By
X-Origin-Server
Source
X-Device-Type
X-Cache-Operation
Server-Node
X-RateLimit-Remaining
X-Varnish-Grace
X-Hyper-Cache
DC
Upgrade-Insecure-Requests
X-Amzn-Trace-Id
X-Drupal-Cache-Tags
X-APP-VERSION
X-Accel-Expires
X-WA-Info
X-CLOUD-TRACE-CONTEXT
X-Platform-Server
X-Varnish-Server
X-GUploader-UploadID
X-HOST
X-TT-TIMESTAMP
X-Newrelic-App-Data
X-Akamai-Edgescape
X-Cache-Action
MS-CV
X-B3-Sampled
X-PC-Key
X-PC-Hit
X-PC-AppVer
NGB
Webserver
X-Correlation-ID
X-Locale
X-Cluster
X-Litespeed-Cache
X-WebKit-CSP-Report-Only
X-Jobs
X-GeoIP
X-Accel-Buffering
X-Cacheable-TTL
Filters
X-Wix-Petri-Ex
Actual-Object-TTL
X-S
X-PC-Date
X-PC-Host
X-Wix-Request-Id
X-Dynatrace-Js-Agent
X-Seen-By
ServedBy
X-Node-Name
X-FW-Type
X-Source
X-Tumblr-Pixel-1
AsisCache
X-FW-Server
X-FW-Serve
X-FW-Static
X-FW-Hash
X-URL
X-Tumblr-Pixel-2
X-RequestSource
X-RTag
Pagespeed
Liferay-Portal
Served-By
X-Varnish-Hits
S-Cnection
X-Port
X-Edge-Location
Fastly-Restarts
Cartoon
X-Cache-Config
X-Distil-CS
X-UA
Datacenter
X-Cache-TTL-Remaining
X-Guploader-Uploadid
Ar-Sid
X-Amz-Replication-Status
X-TA-CDN-Provider
X-Amz-Meta-S3cmd-Attrs
X-Region
X-Ocache
X-Vg-Webcache
GEO-INFO
Cache
Ohc-File-Size
X-Correlation-Id
Content-Script-Type
Content-Style-Type
X-Drupal-Cache-Contexts
Country
X-Sucuri-ID
X-ServedBy
X-UUID
X-UA-Device-Type
X-Cache-Remote
X-GZip
X-Internal-Host
X-Edge-Cache
X-Edge-Cache-Key
X-RateLimit-Limit
HostName
X-Microcachable
X-Adobe-Content
X-Adobe-Loc
X-Status
X-Akamai-Transformed
X-Yottaa-Optimizations
X-Esi
X-Yottaa-Metrics
X-Varnish-IP
X-Real-IP
X-Proxy
X-DataStream-Cache-Status
User-Agent
AR-Request-ID
Machine
X-RN-RSRV
Access-Control-Allow-Method
Meta-Geo
Load-Balancing
X-Akamai-Request-ID
X-Rendered-As
X-Path-Route
X-IP
X-Generated
X-Detected-As
X-Is-Bot
X-JoinUs
X-Proxy-Build
X-Grey
Selected-FE
X-Agile-Id
X-TNCMS
X-Timing-Wait
User-Cache-Control
Xserver
Healthy
X-Agile
X-App-Name
X-OVcl-Cache
X-OVcl
X-Mode
X-Web-Node
X-Agile-Age
X-Cache-Category-Id
X-Ezoic-Cdn
Mn-Server-Ip
X-Loop
X-Backend-Name
S-Rt
ServerName
X-Unique-ID
Backend
X-Human
X-Time-Microsecs
X-ServerID
X-Hosted-By
X-Varnish-Cache-Hits
X-ProxyCache-Key
X-Amz-Server-Side-Encryption
X-ProxyCache-Status
X-FC-Vary-Parameters
X-Instance-Name
X-BYPASS-REASON
X-Debug-Cache
X-BB-IP
X-Cache-Ttl
X-TX-ID
Azure-InstanceId
X-Site-Version
Azure-RegionName
X-Upgrade-Enabled
DB-Nickname
X-Varnish-Cacheable
Azure-SiteName
Azure-Version
IBM-Web2-Location
Azure-SlotName
X-Tb
X-PERF
X-EIG-Tracking-Id
X-NCache
X-Distributor
X-Content-Type
X-ApacheServer
X-CDN-Cache
X-NodeID
X-Origin
X-ProcessESI
X-RemovedCookies
Now
Payment
X-Original-Request
X-Viewer-Country
Cache-Name
SRV
LB
X-Time
Property-Id
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-Country
X-Via-Fastly
X-Xfnlog-Site
X-Www-Served-By
TWC-GeoIP-LatLong
X-TWH-CORRELATION-ID
Webcakes-App-Version
X-CCM
X-Origin-Hint
X-OCL
X-PCL
X-Routing-Service
Webcakes-App-Name
X-Zipkin-Id
Webcakes-Region
TWC-Privacy
TWC-Locale-Group
Cache-Key
Dont-Set-Cookie
L5d-Success-Class
X-Access
X-SplitTest
X-LJ-Flow-ID
X-Pubstack
X-Section
X-VWS-Id
X-Vgn-Hpd-Reason
X-AWS-Id
X-Origin-CC
X-Amz-Meta-Surrogate-Control
X-MP-GENERATED-AT
X-Format
X-CDN-Forward
X-NGENIX-Cache
X-Storage
X-HS-Cache-Config
X-Webstats-RespID
Countrycode
Cache-Hits
X-Rocket-Nginx-Bypass
Edge-Cache-Tag
X-Newrelic-Synthetics
X-Generation-Time
X-Proto
X-Geo
X-Amzn-RequestId
X-Amz-Apigw-Id
Access-Control-Request-Headers
X-Optimization
X-Sucuri-Cache
X-Cache-HT
X-Dc
X-Cache-NE
X-B3-Spanid
X-Nc
Apicache-Version
X-Labrador-Cache-Channel
Apicache-Store
X-Cache-Backend
X-Birta-Served
X-Meta-Tbi-Cache-Vertical
X-Birta-Cache-Post
X-Tumblr-Pixel-3
X-L-Path
X-Environment-Context
Accept-CH
Fastly-SSL
X-Twitter-Response-Tags
X-Rule
X-Connection-Hash
X-Transaction
X-Real-Ip
WZWS-RAY
PageSpeed
X-SERVER-NAME
X-Oss-Object-Type
Ec-Rule-Version
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Storage-Class
X-Webkit-CSP
X-Oss-Hash-Crc64ecma
From-Origin
X-Servedby
Ws
X-Hit
NnCoection
X-CACHE-GROUP
X-Varnish-Beresp-Status
X-EdgeConnect-Cache-Status
X-Nf-Srv-Version
X-Ah-Environment
X-Alicdn-Da-Ups-Status
Cteonnt-Length
X-Varnish-Beresp-Grace
X-Upstream-CT
X-Qnm-Cache
X-M-Reqid
X-Upstream-HT
X-M-Log
X-Cache-Enabled
NODE
X-Planisys-CDN-Rules
X-Via-CDN
Thinkindot-CacheControl-Type
X-Planisys-CDN-TTL
Thinkindot-CacheControl
X-VG-WebServer
Country-Code
X-Developer
X-Died
X-Destination
X-Date
ProcessTime
X-UE-Client-Country
X-Region-Sid
Cneonction
X-B-Cookie
X-ARC
X-A
Www
X-BB-ID
X-Application
BehaviorPad-Version
X-A-Dcw
X-A-Dam
X-A-Dgt
X-A-Wwc
X-Accel-Expires-Debug
X-BBXSRF
Cache-Prefix
Thinkindot-Control
V-Age
T-Server
X-We-Are-Hiring
X-Via-Edge
X-Wix-Route-ID
Viewtype
X-CF-Lambda-Fn
Warning
X-CF-Lambda-Version
VivaBuild
Xc-Version
X-D
X-Fetched-On
SN
X-Matched-Rule
X-ScT
GMS-Ver
Rendered-Blocks
Fly-Request-Id
Fastly-Soc-X-Request-Id
X-S-Cookie
Fly-Cache
X-Planisys-CDN-Cache
X-MI-In-Market
MI-Cache
Meta-Geo-Continent
X-PAYTM-SRV-ID
MD5-Digest
X-App-Version
MI-Cache-Age
X-Server-By
X-Server-Time
X-NU-AKA-ACS-Version
X-SRCache-Key
X-Rojux
X-Rewrite-Enabled
X-Hash
X-TT-LOGID
Ms-Operation-Id
X-Generated-In
X-Response-By
X-A-Ccd
X-From
X-G
X-Thinkindot-L3
X-Trv-Group
Resin-Trace
Server-Host
Host-ID
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-SERVER
X-Hl-Ver
X-V
X-HS-Combine-CSS
X-C
IsBot
Httpd-Identifier
Kp-EeAlive
X-Org
Request-Country
Request-EU
Server-ID
Server-Int
Release
Proxy-Connection
NGX
Origin-Cache-Control
Origin-Edge-Control
PFcat
Web-Mar-Node
X-RCS-CacheZone
X-Logtrace-Id
X-SIPLIST1
X-Shopify-Stage
X-ShopId
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-IN-SSL-APIGATEWAY
X-IN-WAF
X-Info
X-No-Session
X-ShardId
X-P-T
X-Server-IP
X-S-Maxage
X-Origin-Expires
X-ServiceProvider
X-Node-Id
X-Sf
X-Origin-Date
X-IN-APIGATEWAY
X-Hnp-Log
X-Clientip
X-Worker
X-Core-Mission
X-Crawler
X-Cache-URL
X-Cache-Bucket
X-Backend-Host
X-Backend-Url
X-Block-Status
X-CS
X-WebServer
X-Gen-Mode
X-GeoIP-City
X-Release
X-Env
X-Edge-IP
X-Req
X-Ver
X-Dispatcher-Server
X-Alternate-Cache-Key
Uber-Trace-Id
Decoy-Debug-Status
Decoy-Debug-Key
Decoy-Debug-TTL
X-CCM-LastModified
Ajk
X-ElasticPress-Search
X-Content-Age
X-Edge-Server
X-F5-Cache
Time
X-Core-Value
X-Developers
X-Device-Os
X-Debug-Log
X-Cdn-Srv
X-Debug-Cookies
X-DPWN-IS-SECURE
X-Cache-Time
X-Backend-State
X-Backend-TTL
Adler-Geo
X-Amz-Meta-Cache-Control
AKAMAI
X-Actual-URL
X-Cache-ASPX
X-Cache-CFC
X-Cache-Srv
X-Fastly-Cache
X-Cache-Host
X-Cache-Expires
X-Cache-Control-Set-By
X-Cdn-Origin
X-Forwarded-Host
X-Returned-From-DLL
X-Returned-From-PostProcessResponse
X-Returned-From-BeforeDispatch
X-Returned-From
XServer
X-Request-URI
X-Server-Group
X-Sn-Servicetimems
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Varnish-HitMiss
X-UnsetCookies
X-Swa-Ws
X-Trace-Id
X-GoCache-CacheStatus
X-Refresh
X-Origin-TTL
X-Passed-To
X-NX-Host
X-HCF
X-Fstrz
X-GeoIP-Country-Code
X-Passed-To-BeforeDispatch
X-Passed-To-DLL
X-Rebelmouse-Surrogate-Control
X-Reboot
X-Rebelmouse-Cache-Control
Heartbleed
X-Passed-To-PostProcessResponse
Apple-News-Services-Handled
X-Phone
RNT-Time
RNT-Machine
Fastly-Backend-Name
Request-Time
Content-Disposition
True-Client-Country-4JS
CDCHOST
Cdn-Host
Cdn-Request-Time
Fastly-SIE
Fastly-SWR
Ohc-Response-Time
Apple-News-Services-Host
Is-Eu
HTTPS
On-Server
Origin
Pragrma
Powered-By
Platform
Cache-Tags
Odigeo-Trace-Id
Who
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Backend-Name
RequestId
X-Var-Ttl
X-Skip-Cache
X-Stale
HA-Ipaddr
X-Epic-Correlation-Id
X-User
X-Up
Ha-Gx-Prefs
HA-Cloudapp
X-Platform
X-Location
HA-Geocity
HA-Geocountry
HA-Georegion
HA-Geolon
HA-Geolat
X-Eu-Site
HA-Host
X-Nginx-Cache
X-Ckpd-Fst-Backend
X-CGP
HA-Servedtime
MI-API
HA-Urlpath
X-VServer
Esi-Enabled
X-VG-TLSProxy
X-Ms-Request-Id
X-B3-TraceId
X-Ms-Lease-Status
X-Croise-Owner
X-Ms-Blob-Type
X-Ms-Version
Mime-Version
X-From-Cache
X-Redis-Cache
NtCoent-Length
X-FireWall-Port
X-Cdn-Forward
Dnion-Transfer-Encoding
X-Pjax-Url
X-Micro-Cache
Cdn
X-WR-MODIFICATION
GW-Server
WP-Super-Cache
UCS
X-Servername
X-Varnish-Beresp-Ttl
X-CSRF-Token
X-TIME
X-Pf-Uncompressing
X-Cache-FS-Status
X-MSEdge-Flight
X-Via-SSL
X-MSEdge-Features
X-Varnish-Beresp-TTL
X-GRACE
X-Varnish-Url
X-Cache-Handler
X-Hail-Hydra
Dynatrace
Is-Session-Tracking
X-Request-Time
X-Varnish-Id
Get-Access-Time
WWW-Authenticate
X-Powered-By-ANYU
X-Csrf-Token
CF-IPCountry
X-COUNTRY
PageType
Memcached
X-Bip
X-Owner
X-Aicache-OS
X-Key
X-Thanos
PICS-Label
Rt-Proxy-Cache
X-Page-Type
X-GDPR
X-Be
Frame-Options
X-Cache-TTL
X-NWS-UUID-VERIFY
X-NC
X-Kong-Proxy-Latency
X-Ua
X-Kong-Upstream-Latency
X-CUA
NodeID
X-Cache-Id
Memory
X-Cluster-Node
X-Atg-Version
Geoip-Latitude
GeoIp-Country-Code
Geoip-City
MIME-Version
X-Response-Served-From
Mail-Subject
X-Via-NSCOPI
We-Hiring
X-External-Request-Id
FastCGI-Cache
X-DataStream-Origin-MEX-Latency
X-Auto-Login
X-DataStream-MidMile-RTT
X-Dynatrace
X-LiteSpeed-Cache-Control
Sta2Tusw
X-ServedByHost
CACHE
Section-Io-Cache
X-UPSTREAM-Address
Version
X-TId
If-Modified-Since
X-Servedbyhost
X-StackifyID
X-Fastly-Backend-Reqs
X-Nananana
X-DC
X-Frame-Option
X-Varnish-Action
Magicmarker
Node
X-Load-Cache
GeoIP-Country-Code
X-Tid
GeoIP-City
X-CACHE-KEY
GeoIP-Latitude
X-BE
X-EC-Security-Audit
X-ADI-VCache
X-Request-UUID
X-Shield-Cache-Expires
Processtime
X-Bug-Bounty
Pramga
X-Sentry-ID
COMMERCE-SERVER-SOFTWARE
Pics-Label
Pagetype
X-GEO
X-Ig-Deployment-Stage
X-Variation
CDN
X-Public
X-Pc-Appver
X-Pc-Hit
RATING
URI
X-PAGE-TYPE
X-Pc-Key
X-Haproxy-Hostname
X-Server-W
X-Varnish-Ttl
X-Haproxy-Ip
X-Irp-Debug
X-Gdpr
X-Ibm-Trace
X-Shard
X-Proxy-Server
X-Pc-Host
V-Cache
X-Pc-Date
Group
X-Surge-Debug
X-FORWARDED-FOR
X-Endurance-Cache-Level
Cache-Cookie-Set-From
Arc-Country
X-Wa
Cache-Provider
Cache-Cookie-Set-Lfrom
X-Varnish-URL
X-Cache-Debug
X-Ratelimit-Remaining
Cache-Cookie-Set-Idcheck
X-ND-Cache
Cf-Ipcountry
X-Datadome
OT-Force-Account-Verify
Fastcgi-Useragent
Srv
X-SRV
X-HTML-Minification-Powered-By
Sid
REQUESTUUID
X-FW-Version
X-Sorting-Hat-PodId-Cached
X-Sorting-Hat-PrivacyLevel
X-Layer
X-PF-Uncompressing
Accept-Ch
X-Fastly-Cache-Hits
X-Sorting-Hat-Section
X-Sorting-Hat-FeatureSet
X-Sorting-Hat-ShopId-Cached
X-Ratelimit-Limit
X-Cache-Var-Map
X-Cache-Var
X-Nginx-Cache-Key
X-ID
X-RateLimit-Remaining-Second
X-Ms-Lease-State
Powered
GEO-REGION-INFO
X-Gen-Id
Fastcgi-X-Cache-Version
Hostname
X-PJAX-URL
X-RateLimit-Limit-Second
Fastcgi-X-Cache
DataCenter
X-GZIP
Amp-Access-Control-Allow-Source-Origin
X-APP
X-Policy
X-Vcache
X-Front
X-Feature
X-Dw-Trace-Id
X-RequestId
N-Cache
X-CacheKey
X-Litespeed-Cache-Control
X-B3-SpanId
Serverid
X-Unique-Id
X-NGINX-Cache
X-SB
X-Varnish-Info
X-Distil-Cs
X-Requestid
X-CDN-Pop
X-Served-From
X-VC
X-CDN-Pop-IP
X-RAMCache
Xet-Cookie
X-Cookie
X-VG-WebCache
X-Amz-Meta-Sha256
X-WA
SID
X-Grace-Duration
X-Amz-Meta-S3b-Last-Modified
X-Akamai-ERPolicy
X-Svr
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
X-HS-Status
Requestid
X-ServerName
X-Akamai-ERRuleID
X-Fe
X-Request-Start
X-Varnish-ID