Threat Level: green Handler on Duty: Jim Clausing

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Accept-Ranges
Cf-Request-Id
CF-Cache-Status
Pragma
X-Powered-By
ETag
Link
Expect-CT
X-XSS-Protection
Via
CF-RAY
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-UA-Compatible
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
Alt-Svc
X-Served-By
CF-Ray
X-Xss-Protection
X-Timer
X-Varnish
X-Download-Options
Access-Control-Allow-Methods
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Permitted-Cross-Domain-Policies
X-Cache-Status
X-Generator
X-Cacheable
P3p
X-Request-ID
X-Kinja-Server-Push
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-Content-Security-Policy
Status
X-AspNetMvc-Version
Upgrade
Content-Encoding
X-CDN
X-Template
X-Language
Access-Control-Max-Age
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
X-Envoy-Upstream-Service-Time
Keep-Alive
X-Via
X-Ws-Request-Id
X-Age
Feature-Policy
X-Backend
X-AH-Environment
X-Buckets
X-Hacker
X-Robots-Tag
X-Server
X-UA-Device
X-Amz-Request-Id
EagleId
X-Cache-Group
X-Amz-Id-2
X-Proxy-Cache
X-Turbo-Charged-By
X-Server-Powered-By
X-Dns-Prefetch-Control
Request-Context
Server-Timing
Host-Header
X-Nginx-Cache-Status
Grace
Report-To
Xkey
X-Page-Speed
X-Rq
X-OneAgent-JS-Injection
X-Varnish-Cache
X-Pingback
Cf-Bgj
X-LiteSpeed-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Cf-Railgun
Ali-Swift-Global-Savetime
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-WebKit-CSP
X-Amz-Version-Id
X-Vhost
NEL
X-Host
X-Dispatcher
X-Device
X-Backend-Server
X-Node
Surrogate-Control
X-Ruxit-JS-Agent
X-Cache-Lookup
X-Origin-Cache
X-Response-Time
Content-Location
X-Akam-SW-Version
Request-Id
X-Ac
X-ASPNET-VERSION
X-Country
X-Server-Id
X-Mod-Pagespeed
X-HW
Rating
EagleEye-TraceId
X-Readtime
X-ORACLE-DMS-ECID
Accept-CH
Accept-CH-Lifetime
Akamai-Age-Ms
X-Cloud-Trace-Context
X-ORACLE-DMS-RID
Pinterest-Generated-By
X-Application-Context
X-DataDome
Edge-Control
X-Country-Code
X-Origin-Upstream-Status
X-Url
X-PC
X-TtlSet
X-Vname
X-Varnish-TTL
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Fusion-Content-Id
Fusion-Template-Id
Fusion-Component-Id
Fusion-Source
Fusion-Deployment-Id
Fusion-Content-Source
X-Cnection
X-D2id
X-ESI
X-GitHub-Request-Id
X-MS-InvokeApp
X-Clacks-Overhead
X-Content-Type
X-Server-Name
X-Abt-Application-Version
X-Navigation-Version
X-FTR-Request-ID
Allow
X-Vcap-Request-Id
X-Pinterest-Rid
Pinterest-Version
X-Trace
Verso
X-Middleton-Display
Response
Display
X-Middleton-Response
Pagespeed
X-Sol
X-Px
X-B3-TraceId
X-Server-ID
X-Cached
X-Element-Page-Cache
Accept-Ch
X-Rack-Cache
X-Fastly-Request-ID
X-DynaTrace
Service-Worker-Allowed
X-Client-IP
X-Cache-TTL
MS-Author-Via
Arr-Disable-Session-Affinity
X-Powered-By-Plesk
X-Version
Accept-Ch-Lifetime
X-Upstream
X-Forwarded-Proto
X-T
Content-MD5
X-NF-Request-ID
X-Dw-Request-Base-Id
X-TTL
X-Debug
Fastly-Restarts
Ar-Sid
AR-CACHE
AR-ATIME
AR-Request-ID
AR-PoweredBy
SPRequestGuid
X-SharePointHealthScore
X-VARITI-CCR
X-Jurisdiction
X-Cdn-Fetch
X-Kinja-Build
X-Kinja-Server
X-Exp-Id
X-GoogleNews-Bot
X-Exp-Variant
X-Use-Magma
X-Kinja
X-Kinja-Revision
TP-L2-Cache
TP-Cache
Access-Control-Request-Method
X-Content-Digest
X-XRDS-Location
X-Powered-CMS
X-Goog-Hash
X-Release
X-Edge
X-NWS-LOG-UUID
X-Ttl
X-MSEdge-Ref
X-PressLabs-Stats
TCN
RTSS
S
Cache-Tag
SPIisLatency
Fastcgi-Cache
SPRequestDuration
X-Webkit-CSP
X-FastCGI-Cache
X-Amz-Rid
X-Request-Processing-Time
X-Request-Received
X-Yandex-Sdch-Disable
Public-Key-Pins
X-Accel-Expires
X-Ezoic-Cdn
X-Mid
X-MCACHE
X-Ratelimit-Remaining
Server-Node
X-Pinterest-Direct
X-Node-Name
X-Cache-Key
X-Logged-In
X-Cache-Hit
ServerID
X-Amzn-Trace-Id
Front-End-Https
X-Request-Handler-Origin-Region
X-Microsite
Alternate-Protocol
X-Ser
X-CST
X-Recruiting
X-ECACHE
X-Page-Id
X-Origin-Server
X-Kinsta-Cache
X-B
X-Ratelimit-Limit
Host
X-Hostname
X-Mobile-URL
Accept-Charset
X-FTR-Backend
X-FTR-Realm
X-FTR-DC
X-FTR-Backend-Server
X-Country-Code-Real
X-FireWall-Port
X-FTR-Balancer
X-FTR-Expires
X-FTR-Cache-Status
X-Forwarded-For
Nginx-Cache
X-Seen-By
X-Varnish-Age
Realpath
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Content-Security-Policy-Report-Only
X-Load-Cache
MRF-Tech
Filterid
X-DIS-Request-ID
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Jobs
X-Content-Options
X-Id
X-Shield-Request-Id
X-Az
X-AppVersion
X-Activity-Id
X-Daa-Tunnel
X-Type
X-Git-Hash
X-F-Cache
X-Varnish-Backend
X-LB-Cache
X-App-Environment
Paypal-Debug-Id
X-Request-Guid
Edge-Cache-Tag
X-Varnish-Grace
X-N
X-Rid
X-Correlation-ID
X-Zen-Fury
Fastcgi-Useragent
X-Hits
X-FB-Debug
X-Grace
X-Proxy
AMP-Access-Control-Allow-Source-Origin
X-App-Server
X-Mg-S
DC
DynaTrace
Cache-Tags
X-Content-Powered-By
Access-Control-Allow-Method
Content-Disposition
X-Upgrade-Enabled
X-Akamai-Edgescape
X-Cache-Rule
X-WebKit-CSP-Report-Only
X-Cache-Operation
X-Amz-Server-Side-Encryption
X-Kong-Proxy-Latency
X-Endurance-Cache-Level
X-Kong-Upstream-Latency
X-Geo-Country
Cleartype
X-Wix-Request-Id
X-Cached-By
X-TEC-API-VERSION
X-VCache
X-TEC-API-ROOT
X-TEC-API-ORIGIN
MicrosoftSharePointTeamServices
X-Fastcgi-Cache
X-Accel-Buffering
X-Original-Request-Id
X-Response-Served-From
X-HP-Webp
X-IPLB-Instance
X-Host-Name
Refresh
X-Hp-Webp
X-XRDS-LOCATION
NGB
X-B3-Sampled
X-User-Agent
MS-CV
X-AOL-HN
X-Distributor
Healthy
X-Rule
Payment
X-UUID
X-FW-Type
X-Cacheable-TTL
X-HS-Cache-Config
X-FW-Dynamic
X-FW-Server
X-FW-Hash
X-FW-Serve
X-FW-Static
X-HTML-Minification-Powered-By
X-HS-Hub-Id
X-Signature
X-HS-Content-Id
X-HS-Combine-CSS
X-Cache-Time
X-B-Cache
X-Amz-Apigw-Id
X-Region
X-Rendered-As
X-Whom
X-Amzn-RequestId
X-Is-Bot
Datacenter
X-Instance
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-GUploader-UploadID
X-Goog-Metageneration
X-Amz-Meta-S3cmd-Attrs
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Tumblr-Pixel-2
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-Tumblr-User
Countrycode
X-Ua
X-Tec-Api-Origin
X-Tec-Api-Version
X-Debug-Info
PB-RID
PB-PID
X-Tec-Api-Root
X-Mobile
Arc-Version
Powered
X-Varnish-Server
X-Frontend
X-DynaTrace-JS-Agent
X-PHP-Backend
Cache
Surrogate-Key
X-Cache-Age
Powered-By-ChinaCache
X-App-Version
X-Backend-Name
X-NewRelic-App-Data
S-Cnection
X-Oneagent-Js-Injection
X-Azure-Ref
X-Cache-Server
X-Respond-Thread
X-Via-JSL
X-Protected-By
X-WA-Info
X-Hyper-Cache
X-FTR-Cache-Host
Liferay-Portal
X-Cache-Control
X-Litespeed-Cache
Referer-Policy
Viewport
Webserver
Retry-After
X-Cache-Expired-At
X-Proxy-Cache-Status
X-Time
X-CSRF-Token
X-EdgeConnect-Cache-Status
X-Acc-Debug-Context
X-FB-TRIP-ID
X-R9-Blue-Green-Version
X-RN-RSRV
X-RemovedCookies
X-ES-SERVER
Filters
X-Mode
X-ProcessESI
X-Cache-Var
From-Origin
Meta-Geo
X-Debug-Cache
X-Cache-Var-Map
X-Source
X-Locale
X-Qloud-Router
Eomportal-Instance
Section-Io-Cache
X-Device-Type
X-From
X-Sucuri-ID
X-Time-Microsecs
X-PCL
Ms-Operation-Id
X-VWS-Id
X-Via-Fastly
X-Cache-Host
X-ProxyCache-Status
X-ProxyCache-Key
X-Site-Version
X-RTag
X-Ratelimit-Reset
X-LJ-Flow-ID
X-GeoIP
X-OCL
X-BYPASS-REASON
X-Server-W
X-AWS-Id
Mn-Server-Ip
Property-Id
Selected-Fe
TWC-Device-Class
Cross-Origin-Window-Policy
TWC-Privacy
Webcakes-App-Name
Webcakes-App-Version
Webcakes-Region
X-Xfnlog-Site
TWC-Locale-Group
TWC-GeoIP-LatLong
Ec-Rule-Version
Charset
Cache-Tv-Group
TWC-GeoIP-Country
X-Handled-By
X-Proxied
X-Human
X-TNCMS
X-Timing-Wait
X-Routing-Service
X-Origin-Hint
X-Loop
X-FW-Version
X-Hl-Ver
TWC-Connection-Speed
X-Cluster
X-Proxy-Build
X-Zipkin-Id
X-Cache-Action
X-Framework
X-PHP-Host
X-Status
X-Real-IP
DB-Nickname
X-Proto
X-Yottaa-Metrics
X-ServerID
X-Yottaa-Optimizations
X-NYM-Debug-Backend
X-Generated-By
X-Environment-Context
X-Amzn-Remapped-Content-Length
X-BCube-Filmed-By
X-JoinUs
X-Hosted-By
X-L-Path
X-Be
X-Labrador-Cache-Channel
X-SaId
X-Redis-Cache
Uber-Trace-Id
X-Format
X-Section
X-Revision
X-Amz-Replication-Status
X-Access
X-Cache-TTL-Remaining
X-Varnish-Cache-Hits
X-TA-CDN-Provider
X-Detected-As
Frame-Options
X-No-Session
X-Air-Hostname
Version
FSS-Cache
X-Cache-PHP
X-NWS-UUID-VERIFY
X-ATG-Version
X-Drupal-Cache-Contexts
X-NCache
X-Sucuri-Cache
X-Origin
CF-Cached-On
X-Contextid
X-EIG-Tracking-Id
X-URL
X-Drupal-Cache-Tags
Server-Name
X-IPS-LoggedIn
X-EC-Lua
GEO-INFO
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Unique-Id
X-CACHE-AGE
X-Cache-Enabled
OT-Force-Account-Verify
X-Bc-Bl
X-Akamai-Transformed
X-Vgn-Hpd-Variations-Key
X-IP
X-Instart-Request-ID
X-Cache-Backend
X-Vgn-Hpd-Cached
X-GoCache-CacheStatus
Now
X-Backend-Host
X-Tumblr-Pixel-3
X-TIME
X-TT
X-APP-VERSION
Time
X-Adobe-Content
X-Adobe-Loc
X-Ruxit-Js-Agent
X-RCS-CacheZone
X-Oss-Storage-Class
Azure-SiteName
Azure-SlotName
Azure-Version
Azure-RegionName
Azure-InstanceId
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-UA
Access-Control-Request-Headers
X-CDN-Forward
X-NGENIX-Cache
X-Correlation-Id
X-AIR-PT
X-Cdn
Node
X-Twitter-Response-Tags
X-Date
X-D
Meta-Geo-Continent
X-Up
X-Generation-Time
X-Destination
X-Rewrite-Enabled
X-S-Cookie
X-Adobe-Source
Apple-News-Services-Handled
X-Transaction
X-Trv-Group
CloudFront-Viewer-Country
X-Aed
X-Cache-NE
X-External-Request-Id
X-VG-WebServer
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-Vtex-Processado-Em
X-S
X-B-Cookie
X-ARC
X-Vdms-Version
X-Vdms-Path
X-VG-WebCache
X-Rojux
X-Application
X-G
X-A-Wwc
X-Accel-Expires-Debug
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Request-UUID
X-Connection-Hash
MD5-Digest
Mobile-Detection-Method
VIX-Pulpo-Upstream-Status
Machine
Host-ID
Xc-Version
SD-X-WS
Surrogated-Key
VIX-Pulpo-Node
X-Processor
X-Worker
X-CCM
X-A-Dcw
X-A-Dam
X-Minions-Version
X-A-Dgt
DCR-Decision-By
DCR-Processing-Time-Ms
X-A-Ccd
Fastcgi-X-Cache-Version
X-ScT
X-Cache-2
X-Vtex-Remote-Cache
X-A
X-PAYTM-SRV-ID
X-PBS-Appsvrname
Rendered-Blocks
X-Cache-Bucket
X-Cache-Grace
Adler-Geo
X-Bip
X-Backend-TTL
HostName
CDN-RequestCountryCode
Wxu-Next-Hostname
Fastly-SWR
Fastly-SSL
Fastly-SIE
Wxu-Next-Commit
We-Hiring
Mail-Subject
Platform
Is-Eu
Wxu-Next-Region
X-Agile
CDN-Cache
X-Agile-Age
X-Agile-Id
X-Alternate-Cache-Key
CDN-CachedAt
CDN-EdgeStorageId
CDN-Uid
CDN-RequestId
CDN-PullZone
X-ApacheServer
X-CUA
X-OVcl
X-Storage
X-OVcl-Cache
X-Owner
X-Platform
X-PERF
X-Storefront-Renderer-Rendered
X-Thanos
X-Generated-On
NM-Fastcgi-Cache
X-Variation
X-Level-Front-Cache
X-Microcachable
X-Method
X-Soup
X-Sorting-Hat-ShopId
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Req
X-Reqid
X-Servername
X-ShardId
X-Pubstack
X-ShopId
X-TX-ID
X-Sorting-Hat-PodId
X-SN
X-Skip-Cache
X-Shopify-Stage
X-Varnishpool
X-Hash
X-Envoy-Decorator-Operation
X-Forwarded-Host
X-VG-TLSProxy
X-DPWN-IS-SECURE
X-Core-Value
X-Dispatcher-Server
X-Varnish-Beresp-Ttl
X-Edge-Location
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
X-Proxy-Upstream
X-Csrf-Jwt
X-VarnishDD-TTL
X-Webstats-RespID
Ufe-Result
X-Policy
Rt-Fastcgi-Cache
X-Cdn-Srv
X-Core-Mission
X-Clara-WADP
X-Clientip
Pagetype
PFcat
X-Request-Start
X-Render-Time
X-Cms-Context
X-CGP
X-WADP-Cache
X-Varnish-Cacheable
X-Auto-Login
X-Micro-Cache
X-Fmm-Version
X-LI-UUID
X-Li-Pop
X-HS-Content-Campaign-Id
X-Cluster-Name
X-Li-Fabric
X-Viewer-Country
X-Fastly-Cache
X-Cache-Config
X-Cache-Date
X-HN
X-Gamma-Serve
X-Eu-Site
X-Backend-State
X-Fastly-Backend
X-Cache-NGX
X-Cache-Tags
Decoy-Debug-Key
Country-Code
Decoy-Debug-TTL
Fastly-Backend-Name
Fastly-Drupal-HTML
X-Varnish-Ttl
CacheControlHeader
AKAMAI
X-NC
C-Via
Cache-Status
Gh-Request-Id
Decoy-Debug-Status
Ha-Gx-Prefs
L5d-Success-Class
HA-Ipaddr
Group
L
X-Cdn-Forward
X-Dc
X-Is-Gdpr
X-Web-Node
X-Irp-Debug
X-Has-Esi
X-Content-Age
X-Cache-URL
X-Developers
X-Esi-Check
X-Geo-Header
X-JWT-State
X-Old-Content-Length
Origin
X-Slack-Backend
X-Say-Cacheable
X-Say-TTL
X-SayCDN-TTL
X-Request-Host
X-Wikidot-Static-Cache
X-Ms-Request-Id
X-Ms-Version
X-VHOST
X-Wikidot-Backend
X-Cache-Id
X-Location
X-Gzip
Country
X-Amz-Meta-Cb-Modifiedtime
Akamai-GRN
Backend
UCS
Memcached
X-PF-Uncompressing
M-TraceId
X-Refresh
X-Mvc-Supplant-Cachable
X-Esi
X-Wa
X-CS
Nel
X-Aicache-OS
X-ZONE
FSS-Proxy
X-BC
X-NODE
X-Platform-Server
X-B3-Spanid
X-LB-ID
Arc-Country
X-CACHE-GROUP
X-ECache
X-LAGOON
X-DefHash
X-Via-Poph
X-DefElseHash
X-Via-Popn
X-Varnish-Remaining-TTL
Viewtype
X-RateLimit-Remaining
VivaBuild
Upgrade-Insecure-Requests
Actual-Object-TTL
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-ORACLE-APMCS-REQUEST-ID
X-Via-Ucdn
NGX
X-Servedbyhost
X-UPSTREAM-Address
X-Branch-Name
X-RunCloud-Cache
Srv
Geo-Info
X-Unique-ID
X-Mvc-Supplant-OutputCached
X-Ua-Device
X-LI-Proto
X-Cache-Debug
X-Session-Fingerprint
X-Srv
X-Providence-Cookie
X-Flags
Cdn-Host
X-Route-Name
X-Edge-Server
X-Is-Crawler
Cdn-Request-Time
X-Aspnet-Duration-Ms
X-Request-Time
X-SERVER
X-Debug-Cache-Fetch
X-Vgn-Hpd-Ssi
X-Debug-Cache-Store
Memory
X-Bc
X-Zone
X-Varnish-Hostname
Sid
X-Cs
X-Nginx-Cache
X-NGINX-Cache
X-APP
X-LiteSpeed-Cache-Control
X-FPC
X-HS-Status
X-Action
X-Mobile-Rewrite
Xserver
X-GEO
X-Geo
CACHE
X-Ftr-Cache-Host
X-Page-View
X-B3-Traceid
X-Akamai-Request-ID2
X-CF-Powered-By
X-FC-Vary-Parameters
X-Cluster-Node
NtCoent-Length
X-DSS
X-RSL
X-RPS
X-MP-GENERATED-AT
X-DI
X-Epic-Correlation-Id
X-DB
X-RPM
WWW-Authenticate
X-DW
X-DC
X-Hit
Server-Info
X-Nc
GeoIp-Country-Code
X-Check-Cacheable
X-Oss-Cdn-Auth
X-Via-Popv
Geoip-Latitude
Hostname
X-Vcache
XServer
X-NU-AKA-ACS-Version
Processtime
GeoIP-Latitude
GeoIP-Country-Code
Apigw-Requestid
ProcessTime
X-VCL-Version
User-Agent
X-CSRF-TOKEN
SRV
X-Vcl-Version
X-SERVER-NAME
X-FORWARDED-FOR
X-Webkit-CSP-Report-Only
X-Via-CDN
Origin-Cache-Control
X-UnsetCookies
X-Via-Edge
Origin-Edge-Control
Edge-Copy-Time
X-Sql-Duration-Ms
X-Sql-Count
X-Fpc
X-Dynatrace-Js-Agent
X-Via-SSL
W
X-HOST
X-We-Are-Hiring
Accept-Language
X-Envoy-Upstream-Healthchecked-Cluster
S-Rt
X-Key
X-Svr
Esi-Enabled
On-Server
X-Tb
Cdn
X-Dispatch
CF-IPCountry
X-Dynatrace
SID
X-HITS
X-Cache-Hfrom
X-Cache-Hm
X-Www-Served-By
Proxy-Firewall
LB
HitType
WebServer
X-Fastly-Country-Code
Cache-Hits
Lb
ServedBy
T-Server
CDN
N-Cache
X-S-Maxage
A
X-App
X-COUNTRY
X-CACHE-KEY
X-Cache-Remote
X-RAMCache
Fastcgi-Cache-TTL
X-Generated
X-Pjax-Url
Server-Host
Cteonnt-Length
Ohc-File-Size
Amp-Access-Control-Allow-Source-Origin
X-Geo-Region
X-MSEdge-Flight
X-Pass-Why
BehaviorPad-Version
X-MSEdge-Features
X-Oracle-Dms-Rid
X-Path-Route
X-SRV
X-Presslabs-Stats
WZWS-RAY
Pics-Label
X-Newrelic-App-Data
X-TrackingId
X-Li-Proto
X-Instart-Info
Magicmarker
X-Amzn-Remapped-Connection
Powered-By
X-Amzn-Remapped-Date
Xet-Cookie
X-VC
X-Varnish-Hits
X-SB
X-Newrelic-Synthetics
X-ServedByHost
X-Datadome
Server-Ttl
Cache-Key
X-Served-From
X-TH-Server
X-Akamai-Pragma-Client-IP
X-Info
X-Via-PopH
X-Via-PopN
X-Via-PopV
X-Lb-Id
X-StackifyID
X-LiteSpeed-Tag
X-B3-SpanId
X-Origin-Response-Time
X-Batcache
Ohc-Cache-HIT
X-Via-NSCOPI
Protected
Cache-Provider
Dnion-Transfer-Encoding
Content-Style-Type
Content-Script-Type
X-Cache-Tag
X-TT-LOGID
X-Tt-Logid
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
User-Cache-Control
X-WA
X-ID
X-Agile-Brick-Ok
X-Uri
Cf-Alt-Svc
X-Region-Sid
X-Vgn-Hpd-Reason
Tcn
X-HostName
X-PJAX-URL
X-Tid
X-Pf-Uncompressing
Odigeo-Trace-Id
X-Yottaa-OS
X-RateLimit-Limit
X-DevSite-Last-Modified
X-Pad
Who
Inserted-Into-Cache-At
Ssr
CountryCode
Load-Balancing
X-Selected-Scheme
X-Selected-Name
X-Selected-Host-Header
Tracecode
X-Apw-Access-Action
Lfy
Source
X-Men
X-Snapshot-Date
X-Request-URL
X-Varnish-Beresp-TTL
Cneonction
X-Apw-Access-Object
X-Apw-Access-Token
X-Apw-Hits
X-SRCache-Key
Pragrma
X-Fastly-Cache-Hits
X-Proxy-Cachei7
Mime-Version
X-MiniProfiler-Ids
X-Developer
X-Compress-Hint
Vha6-Origin
X-Dw-Trace-Id
X-C
AsisCache
X-Parent-Response-Time
GEO-REGION-INFO
X-Nananana
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-Origin-CC
X-Origin-TTL
X-Magnolia-Registration
PICS-Label