Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Pragma
Accept-Ranges
Last-Modified
Strict-Transport-Security
X-Content-Type-Options
X-Powered-By
CF-RAY
ETag
Link
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Access-Control-Allow-Origin
Content-Security-Policy
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Served-By
X-Varnish
X-Amz-Cf-Id
Referrer-Policy
X-Request-Id
X-Timer
X-AspNet-Version
CF-Cache-Status
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Runtime
Access-Control-Allow-Credentials
X-Download-Options
X-Drupal-Cache
X-Cacheable
Alt-Svc
X-Generator
Content-Security-Policy-Report-Only
X-Xss-Protection
X-AspNetMvc-Version
Status
Timing-Allow-Origin
X-Check
X-Cache-Status
X-Adblock-Key
X-Iinfo
X-DNS-Prefetch-Control
X-Permitted-Cross-Domain-Policies
X-Content-Security-Policy
X-Template
X-CDN
Content-Encoding
X-Language
X-Turbo-Charged-By
X-Request-ID
Keep-Alive
X-Buckets
X-Type
EagleId
X-Via
Xkey
X-Backend
X-AH-Environment
WPE-Backend
X-Age
X-Pass-Why
Access-Control-Max-Age
X-Server
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Cache-Group
X-Varnish-Cache
X-Pingback
Upgrade
X-Nginx-Cache-Status
X-Server-Powered-By
X-Drupal-Dynamic-Cache
Grace
Access-Control-Expose-Headers
X-Hacker
P3p
X-UA-Device
Cf-Railgun
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Ua-Compatible
X-LiteSpeed-Cache
X-Proxy-Cache
X-Envoy-Upstream-Service-Time
X-Page-Speed
Request-Context
X-CST
X-Node
X-Cache-Lookup
X-Device
X-Ac
Content-Location
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Cnection
X-Host
X-Amz-Version-Id
Surrogate-Control
X-WebKit-CSP
X-Backend-Server
X-Rack-Cache
X-Response-Time
X-Rq
X-Px
X-Readtime
X-Server-Id
X-Application-Context
X-Dns-Prefetch-Control
Allow
Pinterest-Generated-By
X-Instart-Request-ID
EagleEye-TraceId
X-Clacks-Overhead
X-OneAgent-JS-Injection
X-Url
Request-Id
Server-Timing
X-Country
X-Cloud-Trace-Context
X-HeyJason
X-Do-Not-Hack
Permitted-Cross-Domain-Policies
X-TTL
Report-To
Rating
X-Country-Code
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Varnish-TTL
Charset
Edge-Control
X-ESI
X-Powered-CMS
X-Server-ID
X-PC
X-Vname
X-TtlSet
X-FTR-Request-ID
X-Server-Name
X-CF-Powered-By
X-DataDome
Feature-Policy
X-MS-InvokeApp
X-Cached
X-Goog-Hash
X-DynaTrace-JS-Agent
NEL
X-Origin-Cache
X-Vhost
X-Recruiting
Public-Key-Pins
X-Geo-Segment
X-Exp-Variant
X-Cdn-Fetch
X-GoogleNews-Bot
X-Exp-Id
X-Kinja
X-Kinja-Server
X-Kinja-Revision
X-Kinja-Build
X-VARITI-CCR
X-F-Cache
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Powered-By-Plesk
X-DynaTrace
X-Version
X-Mod-Pagespeed
X-T
X-Upstream-Env
X-D2id
Pinterest-Version
X-Pinterest-Rid
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Client-IP
Verso
Content-MD5
Arc-Version
PB-PID
PB-RID
X-Mobile-Rewrite
X-Abt-Application-Version
X-Dispatcher
AR-PoweredBy
X-N
AR-ATIME
RTSS
SPRequestGuid
AR-CACHE
X-Cdn
X-SharePointHealthScore
X-Amz-Rid
X-Forwarded-Proto
X-Hits
X-GitHub-Request-Id
X-Navigation-Version
Nginx-Cache
X-Dw-Request-Base-Id
X-Ruxit-JS-Agent
X-B
Realpath
Paypal-Debug-Id
X-Upstream
X-Grace
X-Pad
X-Content-Digest
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Shield-Request-Id
X-Content-Options
X-Varnish-Age
X-Id
Arr-Disable-Session-Affinity
SPRequestDuration
SPIisLatency
X-Kinsta-Cache
X-Cache-Hit
X-NWS-LOG-UUID
MS-Author-Via
TCN
Access-Control-Request-Method
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Logged-In
X-Acc-Meta-Resource-Type
S
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
MRF-Tech
Mrf-Cache-Status
DynaTrace
X-Trace
X-XRDS-Location
X-Ttl
X-Origin-Upstream-Status
X-Vcap-Request-Id
X-VCache
X-MSEdge-Ref
X-HW
X-Zen-Fury
X-DIS-Request-ID
Front-End-Https
Cleartype
X-Oneagent-Js-Injection
Eomportal-Instance
X-FTR-Balancer
X-FTR-Cache-Status
X-Country-Code-Real
Surrogate-Key
X-FTR-Backend
X-FTR-DC
X-HS-Content-Id
X-FTR-Backend-Server
X-FTR-Realm
X-HS-Hub-Id
X-FTR-Expires
X-Cache-Rule
X-Frontend
X-PressLabs-Stats
X-Fastly-Request-ID
X-Via-JSL
X-FastCGI-Cache
Service-Worker-Allowed
X-NF-Request-ID
Cache-Status
X-User-Agent
X-IPLB-Instance
X-Forwarded-For
Server-Name
Tracecode
X-Request-Processing-Time
X-Request-Received
X-Hostname
Fastcgi-Cache
X-SS-Set-Cookie
X-Varnish-Backend
Alternate-Protocol
X-Analytics
Backend-Timing
Host
X-Cache-2
Display
X-Middleton-Display
X-Sol
FilterID
X-Wix-Server-Artifact-Id
Rt-Fastcgi-Cache
X-AOL-HN
Viewport
X-Whom
TP-L2-Cache
Public-Key-Pins-Report-Only
TP-Cache
X-FTR-Cache-Host
X-Revision
Response
X-Rid
X-Proxied
X-Middleton-Response
X-Activity-Id
X-AppVersion
X-Az
X-Content-Powered-By
X-Fastcgi-Cache
X-Srv
ServerID
AR-SID
X-Ser
X-Debug
X-Debug-Info
X-Contextid
X-Cache-Control
AMP-Access-Control-Allow-Source-Origin
X-Magnolia-Registration
MicrosoftSharePointTeamServices
X-Cached-By
X-Daa-Tunnel
Refresh
X-Cache-Server
X-Mobile
X-Akam-SW-Version
X-B3-Traceid
X-Instance
X-WPE-Loopback-Upstream-Addr
Server-Info
HitType
HitInfo
X-Webkit-Csp
Powered-By-ChinaCache
X-Page-Id
Accept-Charset
Cache-Tag
X-FB-Debug
X-App-Server
X-Generated-By
X-Framework
X-Cache-Key
X-Cache-Age
Retry-After
X-URL
X-Content-Security-Policy-Report-Only
X-XRDS-LOCATION
X-Geo-Country
X-PHP-Backend
X-Varnish-Hostname
X-LB-Cache
X-Signature
X-Request-Guid
X-TT
X-B-Cache
Host-Header
X-App-Environment
X-BCube-Filmed-By
X-Cache-Operation
X-Varnish-Grace
X-RateLimit-Remaining
X-Tumblr-Pixel-0
X-Tumblr-Pixel
Source
X-Handled-By
X-Tumblr-User
Server-Node
X-Origin-Server
X-Device-Type
Ar-Sid
X-Newrelic-App-Data
Upgrade-Insecure-Requests
X-Hyper-Cache
X-Accel-Expires
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-Platform-Server
DC
X-WA-Info
X-APP-VERSION
X-NewRelic-App-Data
X-CACHE-GROUP
X-Akamai-Edgescape
X-Amzn-Trace-Id
X-GUploader-UploadID
X-Drupal-Cache-Tags
X-TT-TIMESTAMP
Liferay-Portal
X-Cache-Action
X-ATG-Version
X-Amz-Meta-S3cmd-Attrs
X-Varnish-Server
X-Ruxit-Js-Agent
Fastly-Restarts
Webserver
X-Edge-Location
X-Cluster
X-Port
X-B3-Sampled
X-Accel-Buffering
X-Node-Name
NGB
X-Cacheable-TTL
X-Correlation-ID
X-S
Filters
X-Seen-By
X-Locale
X-Wix-Petri-Ex
X-WebKit-CSP-Report-Only
AR-Request-ID
X-GeoIP
X-Wix-Request-Id
X-Source
Actual-Object-TTL
ServedBy
X-Jobs
X-Tumblr-Pixel-2
X-Varnish-Hits
X-FW-Server
X-FW-Serve
X-Tumblr-Pixel-1
X-FW-Hash
X-RequestSource
X-FW-Static
X-FW-Type
AsisCache
MS-CV
X-RTag
S-Cnection
X-Amz-Replication-Status
GEO-INFO
X-Region
X-Distil-CS
X-UA
X-Cache-TTL-Remaining
X-Correlation-Id
Served-By
HostName
Cache
X-Webkit-CSP
X-Cache-Config
X-UA-Device-Type
X-Edge-Cache-Key
Country
X-Vg-Webcache
X-Edge-Cache
X-Cache-Remote
X-TA-CDN-Provider
Content-Script-Type
X-PC-AppVer
X-PC-Hit
X-PC-Key
X-Guploader-Uploadid
Content-Style-Type
Accept-CH
X-Dynatrace-Js-Agent
Ohc-File-Size
X-Sucuri-ID
X-Adobe-Loc
X-Ocache
X-Adobe-Content
X-PC-Host
X-PC-Date
Datacenter
X-Drupal-Cache-Contexts
X-GZip
X-HOST
X-Internal-Host
X-RateLimit-Limit
X-Microcachable
X-Esi
X-UUID
X-Varnish-IP
X-Unique-ID
Pagespeed
X-Status
X-DataStream-Cache-Status
X-Ezoic-Cdn
X-Akamai-Transformed
X-Amz-Server-Side-Encryption
X-Real-IP
X-TX-ID
X-Detected-As
X-Agile
X-Grey
X-Generated
X-RN-RSRV
X-BYPASS-REASON
X-ProxyCache-Status
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-ProxyCache-Key
X-Cache-Category-Id
X-Akamai-Request-ID
X-Rendered-As
X-Path-Route
X-App-Name
IBM-Web2-Location
Machine
Load-Balancing
Meta-Geo
X-Is-Bot
X-Agile-Age
User-Cache-Control
X-IP
X-Agile-Id
X-Web-Node
Access-Control-Allow-Method
X-JoinUs
Healthy
X-Backend-Name
Selected-FE
X-Mode
X-Instance-Name
X-Debug-Cache
X-Proxy-Build
X-Loop
X-Origin
X-Timing-Wait
X-CCM
Mn-Server-Ip
X-OVcl-Cache
X-OVcl
X-Vgn-Hpd-Reason
X-Xfnlog-Site
X-Proxy
X-TNCMS
X-ServerID
X-CDN-Forward
DB-Nickname
Cache-Name
X-BB-IP
X-PCL
L5d-Success-Class
X-Varnish-Cacheable
X-Varnish-Cache-Hits
X-NodeID
X-Tb
X-OCL
Backend
X-Upgrade-Enabled
X-Time-Microsecs
ServerName
X-Viewer-Country
X-Human
X-Hosted-By
X-Content-Type
X-FC-Vary-Parameters
S-Rt
Payment
Now
Azure-SiteName
Azure-RegionName
Azure-InstanceId
X-ApacheServer
Azure-SlotName
X-Via-Fastly
User-Agent
Azure-Version
X-Site-Version
X-RemovedCookies
Cache-Key
Xserver
X-PERF
X-Cache-Ttl
X-CDN-Cache
X-Distributor
X-EIG-Tracking-Id
X-Original-Request
X-ProcessESI
X-NCache
TWC-Locale-Group
TWC-Privacy
TWC-GeoIP-LatLong
TWC-Connection-Speed
Property-Id
X-Zipkin-Id
TWC-GeoIP-Country
Webcakes-App-Name
X-Routing-Service
X-AWS-Id
X-NGENIX-Cache
X-Access
Webcakes-App-Version
Webcakes-Region
X-Time
TWC-Device-Class
X-TWH-CORRELATION-ID
X-Section
X-Www-Served-By
X-SplitTest
X-Origin-Hint
Dont-Set-Cookie
X-VWS-Id
X-LJ-Flow-ID
LB
X-Servedby
X-Origin-CC
X-Rocket-Nginx-Bypass
X-Pubstack
X-Amz-Meta-Surrogate-Control
X-Format
PageSpeed
SRV
Access-Control-Request-Headers
X-Storage
X-ServedBy
X-L-Path
WZWS-RAY
X-Cache-Backend
X-Environment-Context
X-Sucuri-Cache
Countrycode
X-Webstats-RespID
X-HS-Cache-Config
Edge-Cache-Tag
X-Cache-HT
X-Generation-Time
X-Labrador-Cache-Channel
X-Oss-Server-Time
X-Optimization
X-Proto
X-Oss-Hash-Crc64ecma
X-MP-GENERATED-AT
X-Oss-Object-Type
X-B3-Spanid
X-Oss-Request-Id
X-Oss-Storage-Class
X-Connection-Hash
X-Amz-Apigw-Id
X-Twitter-Response-Tags
X-Transaction
X-Amzn-RequestId
Cache-Hits
Cteonnt-Length
X-Ah-Environment
X-Nc
X-SERVER-NAME
Apicache-Version
Apicache-Store
Ms-Operation-Id
X-Newrelic-Synthetics
X-M-Log
X-M-Reqid
X-Qnm-Cache
X-Birta-Served
X-CLOUD-TRACE-CONTEXT
X-Birta-Cache-Post
X-Cache-NE
X-Hit
X-Meta-Tbi-Cache-Vertical
X-Real-Ip
X-Tumblr-Pixel-3
Fastly-SSL
NnCoection
From-Origin
X-Dc
Cartoon
X-Geo
Ec-Rule-Version
X-Varnish-Beresp-Status
Ws
X-Varnish-Beresp-Grace
X-EdgeConnect-Cache-Status
X-Cache-Enabled
NODE
X-SERVER
X-Upstream-CT
X-Release
X-Upstream-HT
X-V
Meta-Geo-Continent
X-A-Wwc
X-A-Dcw
MD5-Digest
Country-Code
X-A-Dgt
Kp-EeAlive
X-BB-ID
X-Block-Status
Cneonction
X-CF-Lambda-Fn
X-B-Cookie
Httpd-Identifier
X-Alternate-Cache-Key
X-Application
MI-Cache
X-ARC
X-Accel-Expires-Debug
Www
Host-ID
Thinkindot-Control
V-Age
Viewtype
X-CF-Lambda-Version
Thinkindot-CacheControl
T-Server
Resin-Trace
Server-Host
Server-ID
SN
GMS-Ver
Fly-Request-Id
Web-Mar-Node
Request-EU
X-A
X-A-Ccd
MI-Cache-Age
Warning
VivaBuild
Fly-Cache
Request-Country
Rendered-Blocks
X-A-Dam
X-Env
X-ShopId
X-ShardId
X-Shopify-Stage
X-Sorting-Hat-PodId
X-SRCache-Key
X-Sorting-Hat-ShopId
X-Sf
X-Server-Time
X-S-Cookie
X-Rule
X-S-Maxage
X-ScT
X-Server-By
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-WebServer
X-We-Are-Hiring
X-Wix-Route-ID
X-Worker
Xc-Version
X-Via-Edge
X-Via-CDN
X-Trv-Group
X-Thinkindot-L3
X-TT-LOGID
X-UE-Client-Country
X-VG-WebServer
X-Rojux
X-Rewrite-Enabled
X-From
X-Fetched-On
X-G
X-Gen-Mode
X-Hl-Ver
X-Generated-In
Cache-Prefix
X-DPWN-IS-SECURE
X-Destination
X-Date
X-Developer
X-Died
X-Dispatcher-Server
X-Hnp-Log
X-Matched-Rule
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-RCS-CacheZone
X-Region-Sid
X-Response-By
X-Planisys-CDN-Cache
X-PAYTM-SRV-ID
X-NU-AKA-ACS-Version
X-MI-In-Market
X-Org
X-Origin-Date
X-Origin-Expires
X-D
Thinkindot-CacheControl-Type
X-Alicdn-Da-Ups-Status
BehaviorPad-Version
XServer
ProcessTime
X-C
X-Varnish-Beresp-Ttl
X-GeoIP-Country-Code
NGX
X-Hash
Server-Int
Uber-Trace-Id
X-VServer
X-No-Session
X-Request-URI
X-Node-Id
X-Amz-Meta-Cache-Control
RNT-Machine
Proxy-Connection
Pragrma
Platform
PFcat
Origin-Cache-Control
Release
Origin-Edge-Control
Odigeo-Trace-Id
X-Logtrace-Id
RNT-Time
X-Backend-Url
X-SIPLIST1
X-Device-Os
X-Origin-TTL
X-IN-APIGATEWAY
X-ServiceProvider
X-Edge-IP
X-GeoIP-City
X-Fstrz
X-Server-IP
X-Edge-Server
X-IN-SSL-APIGATEWAY
X-CS
X-Cache-CFC
X-Cache-Bucket
X-Cache-URL
X-Backend-State
X-P-T
X-Cache-Host
X-Crawler
X-Content-Age
X-Clientip
X-IN-WAF
X-Backend-Host
True-Client-Country-4JS
Apple-News-Services-Host
Apple-News-Services-Handled
Cdn-Request-Time
Is-Eu
Decoy-Debug-Key
Decoy-Debug-TTL
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Fastly-Soc-X-Request-Id
Fastly-Backend-Name
IsBot
Decoy-Debug-Status
CDCHOST
MI-API
Adler-Geo
Ajk
Cdn-Host
X-ElasticPress-Search
X-HS-Combine-CSS
X-CGP
Backend-Name
X-Backend-TTL
X-Ckpd-Fst-Backend
X-Core-Mission
HA-Cloudapp
Fastly-SWR
X-Cdn-Srv
X-Cache-Srv
X-Cache-Control-Set-By
X-Cache-ASPX
X-Passed-To
X-Cache-Expires
X-Rebelmouse-Cache-Control
X-Passed-To-BeforeDispatch
X-Core-Value
X-Info
X-Cdn-Origin
X-Croise-Owner
X-App-Version
X-Forwarded-Host
X-Reboot
X-Rebelmouse-Surrogate-Control
X-Epic-Correlation-Id
X-Eu-Site
X-F5-Cache
X-FireWall-Port
X-Returned-From
X-Sn-Servicetimems
Content-Disposition
X-NX-Host
Esi-Enabled
X-Server-Group
X-Fastly-Cache
X-Debug-Cookies
X-Debug-Log
X-Developers
Cache-Tags
X-Swa-Ws
Fastly-SIE
X-Platform
On-Server
HA-Geocity
HA-Ipaddr
X-Ver
X-VG-TLSProxy
X-Varnish-HitMiss
HA-Host
HA-Geolon
X-Returned-From-DLL
HA-Georegion
Ha-Gx-Prefs
HA-Servedtime
X-HCF
X-Wikidot-Static-Cache
Powered-By
AKAMAI
X-Returned-From-BeforeDispatch
Origin
HTTPS
HA-Urlpath
Heartbleed
X-Wikidot-Backend
Request-Time
X-Passed-To-PostProcessResponse
X-Phone
X-UnsetCookies
X-Passed-To-DLL
X-Redis-Cache
Who
HA-Geocountry
X-Trace-Id
X-Up
X-Actual-URL
HA-Geolat
Time
X-Returned-From-PostProcessResponse
NtCoent-Length
X-Atg-Version
X-From-Cache
X-Ms-Version
X-Var-Ttl
X-GoCache-CacheStatus
X-Req
X-Cache-FS-Status
X-Refresh
X-BBXSRF
X-Ms-Request-Id
RequestId
X-Ms-Blob-Type
X-Via-SSL
X-Stale
Ohc-Response-Time
X-Ms-Lease-Status
X-Location
X-Skip-Cache
X-Nginx-Cache
Dnion-Transfer-Encoding
X-Micro-Cache
X-Cache-Time
X-Powered-By-ANYU
Get-Access-Time
WWW-Authenticate
X-MSEdge-Flight
X-Pjax-Url
Is-Session-Tracking
X-Servername
X-MSEdge-Features
X-WR-MODIFICATION
Frame-Options
Mime-Version
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Cdn-Forward
X-B3-TraceId
X-Csrf-Token
X-Response-Served-From
X-Pf-Uncompressing
X-CCM-LastModified
X-Key
X-Owner
Cdn
X-User
X-GRACE
NodeID
X-NC
X-Request-Time
X-CUA
X-TIME
Dynatrace
X-Litespeed-Cache
WP-Super-Cache
X-COUNTRY
X-Varnish-Url
CF-IPCountry
Mail-Subject
X-Page-Type
We-Hiring
X-Cache-TTL
PICS-Label
GW-Server
MIME-Version
UCS
X-CSRF-Token
X-External-Request-Id
X-NWS-UUID-VERIFY
X-Cache-Handler
X-LiteSpeed-Cache-Control
PageType
Section-Io-Cache
X-Ua
X-DC
X-GDPR
Geoip-City
Geoip-Latitude
X-Aicache-OS
GeoIp-Country-Code
X-Nf-Srv-Version
FastCGI-Cache
X-Varnish-Id
Magicmarker
X-Cache-Id
Version
X-Servedbyhost
Rt-Proxy-Cache
X-Varnish-Action
X-Varnish-Beresp-TTL
X-Dynatrace
X-Pc-Key
X-Bip
X-Thanos
Memcached
X-Pc-Appver
X-Pc-Hit
CACHE
Memory
X-Request-UUID
X-Fastly-Backend-Reqs
X-Pc-Host
X-Nananana
X-Pc-Date
X-TId
X-Via-NSCOPI
X-Variation
X-ServedByHost
If-Modified-Since
X-GEO
CDN
X-Be
X-StackifyID
Processtime
X-Server-W
X-CACHE-KEY
COMMERCE-SERVER-SOFTWARE
X-Ibm-Trace
Pagetype
X-Irp-Debug
X-Load-Cache
X-Cluster-Node
Sta2Tusw
Node
GeoIP-Latitude
X-BE
X-UPSTREAM-Address
X-Auto-Login
X-Wa
X-DataStream-MidMile-RTT
GeoIP-City
X-Gdpr
X-DataStream-Origin-MEX-Latency
GeoIP-Country-Code
Sid
Arc-Country
X-Hail-Hydra
X-Frame-Option
X-Shard
X-HTML-Minification-Powered-By
X-Tid
X-Sentry-ID
Accept-CH-Lifetime
X-Ig-Deployment-Stage
X-Varnish-Ttl
Pics-Label
DataCenter
RATING
X-FW-Version
X-Proxy-Server
X-Layer
X-PAGE-TYPE
URI
X-RateLimit-Remaining-Second
X-Varnish-URL
X-Nginx-Cache-Key
X-RateLimit-Limit-Second
X-FORWARDED-FOR
X-Datadome
Srv
X-Fastly-Cache-Hits
Cf-Ipcountry
X-EC-Security-Audit
X-SRV
X-NGINX-Cache
X-Gen-Id
X-Bug-Bounty
Pramga
X-Ratelimit-Remaining
V-Cache
Group
X-PF-Uncompressing
X-Haproxy-Ip
X-Haproxy-Hostname
X-Shield-Cache-Expires
X-Endurance-Cache-Level
X-PJAX-URL
X-Public
X-ID
X-Surge-Debug
Cache-Provider
X-Gannett-Site-Version
X-Akamai-Request-ID2
X-ADI-VCache
X-Secret
X-GZIP
X-Ratelimit-Limit
X-Feature
Cache-Cookie-Set-From
X-Dw-Trace-Id
X-APP
X-Litespeed-Cache-Control
Cache-Cookie-Set-Idcheck
X-CacheKey
X-B3-SpanId
X-Cache-Debug
X-ND-Cache
Cache-Cookie-Set-Lfrom
Hostname
Xet-Cookie
Serverid
X-Ms-Lease-State
X-Sorting-Hat-ShopId-Cached
X-Distil-Cs
X-CDN-Pop
Lb
X-RequestId
X-Sorting-Hat-Section
X-Sorting-Hat-PrivacyLevel
X-Sorting-Hat-PodId-Cached
X-Sorting-Hat-FeatureSet
X-CDN-Pop-IP
Mobile-Detection-Method
SD-X-WS
X-Akamai-ERRuleID
X-Fe
OT-Force-Account-Verify
X-Akamai-ERPolicy
X-RAMCache
X-Cache-Var-Map
X-Cache-Var
X-VCT
X-SD-PageType
X-Grace-Duration
X-Cookie
X-WA
X-Store
X-Request-Start
X-Varnish-ID
GEO-REGION-INFO
Accept-Ch
N-Cache
Requestid
X-VG-WebCache
X-ServerName
REQUESTUUID
X-Unique-Id