Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Pragma
Accept-Ranges
Last-Modified
Strict-Transport-Security
X-Content-Type-Options
X-Powered-By
CF-RAY
ETag
Link
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Access-Control-Allow-Origin
Content-Security-Policy
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Served-By
X-Varnish
X-Amz-Cf-Id
Referrer-Policy
X-Request-Id
X-Timer
X-AspNet-Version
CF-Cache-Status
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Runtime
Access-Control-Allow-Credentials
X-Download-Options
X-Drupal-Cache
X-Cacheable
Alt-Svc
X-Generator
X-Xss-Protection
Content-Security-Policy-Report-Only
X-AspNetMvc-Version
Status
Timing-Allow-Origin
X-Check
X-Cache-Status
X-Adblock-Key
X-Iinfo
X-DNS-Prefetch-Control
X-Content-Security-Policy
X-Permitted-Cross-Domain-Policies
Content-Encoding
X-CDN
X-Template
X-Language
X-Turbo-Charged-By
X-Request-ID
Keep-Alive
X-Type
X-Buckets
EagleId
Xkey
X-Backend
X-Via
X-AH-Environment
WPE-Backend
X-Age
X-Pass-Why
Access-Control-Max-Age
X-Server
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Cache-Group
X-Varnish-Cache
X-Pingback
Upgrade
X-Nginx-Cache-Status
X-Server-Powered-By
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Grace
X-Hacker
P3p
X-UA-Device
Cf-Railgun
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Ua-Compatible
X-LiteSpeed-Cache
X-Proxy-Cache
X-Envoy-Upstream-Service-Time
X-Page-Speed
Request-Context
X-CST
X-Node
X-Device
X-Host
X-Cache-Lookup
X-Ac
Content-Location
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Cnection
Surrogate-Control
X-Amz-Version-Id
X-Server-Id
X-WebKit-CSP
X-Backend-Server
X-Rack-Cache
X-Response-Time
X-Rq
X-Px
X-Readtime
X-Application-Context
Pinterest-Generated-By
X-Dns-Prefetch-Control
Allow
X-Cloud-Trace-Context
X-Instart-Request-ID
X-OneAgent-JS-Injection
EagleEye-TraceId
X-Clacks-Overhead
X-Url
Server-Timing
X-Do-Not-Hack
Permitted-Cross-Domain-Policies
X-HeyJason
Request-Id
X-Country
Report-To
Rating
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Country-Code
Charset
X-Varnish-TTL
Edge-Control
X-ESI
X-TTL
X-TtlSet
X-PC
X-Powered-CMS
X-Vname
X-Server-Name
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-FTR-Request-ID
X-DataDome
X-CF-Powered-By
Feature-Policy
X-MS-InvokeApp
X-Origin-Cache
X-Goog-Hash
X-Cached
X-DynaTrace-JS-Agent
NEL
Public-Key-Pins
X-Recruiting
X-Vhost
X-DynaTrace
X-VARITI-CCR
X-Exp-Variant
X-Kinja-Revision
X-Kinja-Server
X-Cdn-Fetch
X-Exp-Id
X-Kinja-Build
X-Kinja
X-GoogleNews-Bot
X-Geo-Segment
X-F-Cache
AR-PoweredBy
X-Version
AR-ATIME
X-Mod-Pagespeed
X-Powered-By-Plesk
AR-CACHE
X-Pinterest-Rid
X-Upstream-Env
Pinterest-Version
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-T
PB-PID
PB-RID
X-Mobile-Rewrite
Arc-Version
Content-MD5
X-D2id
X-Client-IP
Verso
X-Abt-Application-Version
RTSS
X-N
X-Dispatcher
X-Cdn
SPRequestGuid
X-Server-ID
X-Amz-Rid
X-SharePointHealthScore
X-GitHub-Request-Id
X-Ruxit-JS-Agent
X-Forwarded-Proto
X-Hits
Nginx-Cache
X-Navigation-Version
X-Dw-Request-Base-Id
X-Ttl
Paypal-Debug-Id
X-B
X-Upstream
Realpath
X-Pad
X-Grace
X-Varnish-Age
X-Content-Digest
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Shield-Request-Id
Arr-Disable-Session-Affinity
X-TEC-API-VERSION
X-Id
MS-Author-Via
X-Content-Options
X-Cache-Hit
TCN
X-Kinsta-Cache
X-Logged-In
Access-Control-Request-Method
X-XRDS-Location
X-Goog-Generation
X-NWS-LOG-UUID
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
SPIisLatency
SPRequestDuration
DynaTrace
S
X-Acc-Meta-Resource-Type
X-Trace
Mrf-Cache-Status
MRF-Tech
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
X-Origin-Upstream-Status
X-FastCGI-Cache
X-Vcap-Request-Id
X-VCache
X-MSEdge-Ref
X-DIS-Request-ID
X-HW
Cleartype
Eomportal-Instance
X-Via-JSL
Surrogate-Key
X-Cache-Rule
Cache-Status
X-Frontend
X-Fastly-Request-ID
X-Zen-Fury
X-IPLB-Instance
X-FTR-Backend
X-FTR-Cache-Status
X-FTR-DC
X-FTR-Expires
X-Country-Code-Real
X-FTR-Balancer
X-FTR-Realm
X-FTR-Backend-Server
X-HS-Hub-Id
X-HS-Content-Id
X-PressLabs-Stats
Front-End-Https
Service-Worker-Allowed
X-NF-Request-ID
X-SS-Set-Cookie
Server-Name
X-User-Agent
X-Webkit-Csp
X-Forwarded-For
Tracecode
X-Request-Received
X-Request-Processing-Time
X-Hostname
X-Varnish-Backend
Fastcgi-Cache
AR-SID
X-Cache-2
Host
Backend-Timing
X-Analytics
Rt-Fastcgi-Cache
X-Wix-Server-Artifact-Id
FilterID
Viewport
X-AOL-HN
TP-L2-Cache
X-Whom
TP-Cache
Public-Key-Pins-Report-Only
X-FTR-Cache-Host
X-Content-Powered-By
X-Revision
X-Srv
X-Rid
Alternate-Protocol
X-Proxied
X-Middleton-Display
Display
X-Sol
Response
X-Middleton-Response
X-Debug-Info
X-Activity-Id
ServerID
X-AppVersion
X-Az
X-Debug
X-Oneagent-Js-Injection
X-Ser
X-Cache-Control
X-Daa-Tunnel
AMP-Access-Control-Allow-Source-Origin
X-Cached-By
X-Magnolia-Registration
X-Contextid
X-Akam-SW-Version
X-Cache-Server
Ar-Sid
X-WPE-Loopback-Upstream-Addr
X-Mobile
X-Cache-Key
Refresh
Server-Info
Accept-Charset
HitType
MicrosoftSharePointTeamServices
HitInfo
X-RateLimit-Remaining
Cache-Tag
X-FB-Debug
X-Cache-Age
X-Framework
X-PHP-Backend
X-Varnish-Hostname
X-Page-Id
X-Content-Security-Policy-Report-Only
X-Generated-By
X-App-Server
X-Instance
X-URL
X-Cache-Operation
X-Varnish-Grace
Retry-After
Upgrade-Insecure-Requests
X-Geo-Country
X-TT
X-Signature
X-B-Cache
X-LB-Cache
X-Origin-Server
X-Fastcgi-Cache
Source
Server-Node
X-Tumblr-Pixel
X-Tumblr-User
X-BCube-Filmed-By
Host-Header
X-App-Environment
X-Tumblr-Pixel-0
AR-Request-ID
X-Amz-Meta-S3cmd-Attrs
X-Request-Guid
X-Handled-By
X-Accel-Expires
X-Device-Type
X-Newrelic-App-Data
X-Platform-Server
X-NewRelic-App-Data
X-B3-Traceid
X-Hyper-Cache
X-Akamai-Edgescape
Liferay-Portal
Powered-By-ChinaCache
DC
X-WA-Info
X-XRDS-LOCATION
X-Correlation-Id
X-TT-TIMESTAMP
Accept-CH
X-CACHE-GROUP
X-Cache-Action
X-Amzn-Trace-Id
Fastly-Restarts
X-Drupal-Cache-Tags
X-B3-Sampled
X-Node-Name
X-ATG-Version
Webserver
X-APP-VERSION
X-Port
X-Cluster
X-GUploader-UploadID
X-Varnish-Server
X-Accel-Buffering
NGB
X-Edge-Location
X-Seen-By
X-GeoIP
X-Cacheable-TTL
Filters
X-Wix-Request-Id
X-S
X-WebKit-CSP-Report-Only
X-Jobs
X-FW-Server
X-FW-Static
X-FW-Serve
X-FW-Hash
X-Tumblr-Pixel-2
X-Amz-Replication-Status
X-FW-Type
ServedBy
X-Source
AsisCache
X-RequestSource
X-Locale
X-Varnish-Hits
X-Tumblr-Pixel-1
Actual-Object-TTL
GEO-INFO
X-Guploader-Uploadid
X-Region
X-Distil-CS
MS-CV
X-Wix-Petri-Ex
X-RTag
X-Cache-TTL-Remaining
S-Cnection
X-UA-Device-Type
Cache
X-Edge-Cache
X-Webkit-CSP
X-Edge-Cache-Key
X-Adobe-Content
X-UA
X-Adobe-Loc
Content-Script-Type
X-Cache-Config
HostName
Content-Style-Type
Served-By
X-Cache-Remote
Country
X-Dynatrace-Js-Agent
X-TA-CDN-Provider
Datacenter
X-Vg-Webcache
X-Servedby
X-Unique-ID
PageSpeed
X-Ocache
X-Sucuri-ID
X-Ruxit-Js-Agent
X-Esi
X-Amz-Server-Side-Encryption
X-Status
X-Drupal-Cache-Contexts
X-Correlation-ID
X-Varnish-IP
X-RateLimit-Limit
X-Microcachable
X-TX-ID
X-GZip
X-UUID
X-DataStream-Cache-Status
X-Ezoic-Cdn
Healthy
Xserver
X-Akamai-Transformed
X-Internal-Host
IBM-Web2-Location
X-Mode
Ohc-File-Size
X-BYPASS-REASON
Machine
X-RN-RSRV
X-CCM
X-Is-Bot
X-Vgn-Hpd-Reason
Access-Control-Allow-Method
X-ProxyCache-Status
X-Akamai-Request-ID
X-App-Name
X-Cache-Category-Id
X-Rendered-As
X-JoinUs
X-ProxyCache-Key
Load-Balancing
Meta-Geo
X-Grey
X-Detected-As
X-Agile-Id
X-OVcl-Cache
X-OVcl
X-Origin
X-Generated
X-Agile-Age
Mn-Server-Ip
X-Agile
User-Agent
X-Time-Microsecs
X-Xfnlog-Site
Selected-FE
X-Backend-Name
X-Timing-Wait
X-ServerID
X-Debug-Cache
User-Cache-Control
X-NGENIX-Cache
X-Proxy-Build
X-ApacheServer
X-Tb
X-NodeID
X-TNCMS
X-Loop
Now
X-PERF
DB-Nickname
L5d-Success-Class
X-Rocket-Nginx-Bypass
Cache-Name
Cache-Key
X-Varnish-Cacheable
X-Instance-Name
X-OCL
X-Viewer-Country
ServerName
X-PCL
X-Upgrade-Enabled
Backend
X-Yottaa-Metrics
S-Rt
X-Content-Type
X-Distributor
X-PC-Hit
X-FC-Vary-Parameters
X-Yottaa-Optimizations
Azure-InstanceId
X-PC-Key
X-PC-AppVer
Azure-Version
Azure-SlotName
Azure-RegionName
Azure-SiteName
X-Human
X-Hosted-By
X-Via-Fastly
X-Varnish-Cache-Hits
X-EIG-Tracking-Id
X-BB-IP
X-ProcessESI
X-NCache
X-IP
Payment
X-RemovedCookies
TWC-Device-Class
X-Access
TWC-Connection-Speed
TWC-GeoIP-Country
TWC-Locale-Group
Webcakes-App-Name
Webcakes-App-Version
TWC-GeoIP-LatLong
TWC-Privacy
X-Routing-Service
X-CDN-Cache
X-TWH-CORRELATION-ID
X-Original-Request
X-Proxy
X-SplitTest
X-Section
X-Site-Version
X-Origin-Hint
X-LJ-Flow-ID
X-Zipkin-Id
Access-Control-Request-Headers
X-Www-Served-By
X-Web-Node
X-VWS-Id
X-AWS-Id
Webcakes-Region
Dont-Set-Cookie
Property-Id
X-PC-Date
X-PC-Host
X-Oracle-Dms-Rid
X-Amz-Meta-Surrogate-Control
X-Oracle-Dms-Ecid
X-Format
X-Origin-CC
X-Time
X-CDN-Forward
X-Storage
Ms-Operation-Id
X-Real-IP
X-Environment-Context
X-L-Path
X-Pubstack
LB
SRV
X-Path-Route
X-Cache-Backend
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Object-Type
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
Cteonnt-Length
X-Connection-Hash
X-Twitter-Response-Tags
WZWS-RAY
X-Transaction
X-Qnm-Cache
X-HS-Cache-Config
Edge-Cache-Tag
X-Sucuri-Cache
Countrycode
X-M-Log
X-M-Reqid
X-Ah-Environment
X-Labrador-Cache-Channel
X-Real-Ip
Pagespeed
X-Optimization
X-SERVER-NAME
X-Cache-HT
X-Proto
X-Generation-Time
X-Cache-Ttl
X-B3-Spanid
X-Amzn-RequestId
X-Webstats-RespID
X-Hit
X-Amz-Apigw-Id
X-V
X-Release
X-MP-GENERATED-AT
X-Birta-Served
X-Meta-Tbi-Cache-Vertical
X-Birta-Cache-Post
X-Tumblr-Pixel-3
X-Newrelic-Synthetics
X-Varnish-Beresp-Grace
Apicache-Store
X-Varnish-Beresp-Status
NnCoection
Apicache-Version
Cache-Hits
X-Nc
X-Cache-Enabled
ProcessTime
X-C
X-EdgeConnect-Cache-Status
X-Rule
X-Cache-NE
X-Varnish-Beresp-Ttl
X-SERVER
Fastly-SSL
X-App-Version
X-Dc
X-WebServer
X-A-Dcw
X-A-Wwc
X-A-Dam
X-A-Dgt
X-A-Ccd
X-Wix-Route-ID
X-Worker
Warning
Www
X-A
X-We-Are-Hiring
X-Accel-Expires-Debug
X-ARC
X-Upstream-HT
X-Upstream-CT
X-UE-Client-Country
X-TT-LOGID
X-Application
X-VG-WebServer
X-Alternate-Cache-Key
X-Via-SSL
X-Via-Edge
X-Via-CDN
VivaBuild
Viewtype
Kp-EeAlive
Host-ID
MD5-Digest
Meta-Geo-Continent
MI-Cache
GMS-Ver
Fly-Request-Id
Decoy-Debug-Status
Decoy-Debug-Key
Decoy-Debug-TTL
Ec-Rule-Version
Fly-Cache
MI-Cache-Age
Rendered-Blocks
Thinkindot-CacheControl
Xc-Version
Thinkindot-Control
True-Client-Country-4JS
V-Age
T-Server
Server-ID
Request-Country
Request-EU
Resin-Trace
Server-Host
X-B-Cookie
X-BB-ID
X-Org
X-Origin-Date
X-NU-AKA-ACS-Version
X-MI-In-Market
X-Matched-Rule
X-Origin-Expires
X-Date
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-PAYTM-SRV-ID
X-Destination
X-Hnp-Log
X-G
X-Dispatcher-Server
X-From
X-DPWN-IS-SECURE
X-Fetched-On
X-Died
X-Gen-Mode
X-Developer
X-Hl-Ver
Country-Code
X-Generated-In
X-RCS-CacheZone
X-Region-Sid
X-SRCache-Key
X-CF-Lambda-Fn
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Shopify-Stage
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Trv-Group
X-Block-Status
X-Cache-URL
X-Thinkindot-L3
X-ShopId
X-ShardId
X-S-Cookie
X-S-Maxage
X-D
X-Rojux
X-Rewrite-Enabled
X-ScT
X-Server-By
X-Sf
X-ServiceProvider
X-Server-Time
X-CF-Lambda-Version
X-Edge-Server
Thinkindot-CacheControl-Type
From-Origin
BehaviorPad-Version
Cache-Prefix
Cdn-Host
Cdn-Request-Time
Cneonction
NODE
Ws
X-ServedBy
NtCoent-Length
RNT-Time
RNT-Machine
X-Logtrace-Id
X-Origin-TTL
SN
Server-Int
X-No-Session
Ajk
Pragrma
Platform
PFcat
X-Server-IP
Release
Adler-Geo
X-IN-WAF
X-Response-By
X-Hash
X-Content-Age
X-Amz-Meta-Cache-Control
X-Crawler
Frame-Options
X-Clientip
X-Backend-Host
X-Cache-CFC
X-Cache-Host
X-Backend-Url
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-GeoIP-Country-Code
X-SIPLIST1
X-IN-APIGATEWAY
X-GeoIP-City
X-Fstrz
X-Device-Os
X-Env
Web-Mar-Node
X-IN-SSL-APIGATEWAY
Proxy-Connection
X-VServer
Apple-News-Services-Host
MI-API
CDCHOST
Origin-Edge-Control
Is-Eu
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
X-Request-URI
X-CS
Origin-Cache-Control
IsBot
Odigeo-Trace-Id
Httpd-Identifier
NGX
X-ElasticPress-Search
X-Core-Value
X-Developers
X-Cdn-Origin
WWW-Authenticate
X-Debug-Cookies
X-Debug-Log
X-Croise-Owner
X-Forwarded-Host
X-Ckpd-Fst-Backend
X-Cache-FS-Status
X-Rebelmouse-Surrogate-Control
X-Cache-Expires
X-Sn-Servicetimems
X-Cache-Bucket
X-Cache-Srv
X-CGP
X-Core-Mission
X-Powered-By-ANYU
X-Epic-Correlation-Id
X-Rebelmouse-Cache-Control
X-NX-Host
Fastly-SIE
X-Redis-Cache
X-UnsetCookies
X-Platform
X-Phone
X-Up
X-Trace-Id
X-Response-Served-From
X-Skip-Cache
X-Swa-Ws
XServer
X-Cache-ASPX
Content-Disposition
X-Ver
X-FireWall-Port
Get-Access-Time
X-Fastly-Cache
Is-Session-Tracking
X-F5-Cache
Fastly-SWR
Cache-Tags
X-VG-TLSProxy
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-B3-TraceId
X-Eu-Site
X-Node-Id
X-Alicdn-Da-Ups-Status
HA-Urlpath
Uber-Trace-Id
HA-Geolon
HTTPS
HA-Georegion
HA-Geolat
X-Nginx-Cache
HA-Geocountry
HA-Geocity
Fastly-Backend-Name
Esi-Enabled
Backend-Name
Heartbleed
HA-Cloudapp
X-Backend-State
Time
Ha-Gx-Prefs
HA-Host
HA-Ipaddr
Request-Time
X-Backend-TTL
Who
HA-Servedtime
AKAMAI
On-Server
Origin
X-Atg-Version
X-HS-Combine-CSS
X-NC
X-Server-Group
X-Varnish-HitMiss
X-Passed-To-BeforeDispatch
X-Passed-To
X-Passed-To-DLL
X-Passed-To-PostProcessResponse
Powered-By
X-Cdn-Forward
X-Returned-From-PostProcessResponse
X-HCF
X-Returned-From
X-Cache-TTL
X-Var-Ttl
X-Returned-From-DLL
X-Reboot
X-From-Cache
X-Refresh
RequestId
X-Actual-URL
X-Cdn-Srv
X-Returned-From-BeforeDispatch
X-Owner
X-Cache-Control-Set-By
Dnion-Transfer-Encoding
X-Ms-Lease-Status
X-P-T
X-Edge-IP
X-Ms-Version
X-Location
X-Ms-Request-Id
X-Geo
X-Key
NodeID
Fastly-Soc-X-Request-Id
X-Ms-Blob-Type
X-GoCache-CacheStatus
X-Stale
X-CUA
X-Req
Accept-CH-Lifetime
X-Csrf-Token
X-MSEdge-Flight
X-MSEdge-Features
X-Info
X-Pjax-Url
We-Hiring
Ohc-Response-Time
Mail-Subject
X-Servername
X-BBXSRF
X-Micro-Cache
MIME-Version
X-GRACE
X-Varnish-Url
X-Request-Time
X-Pf-Uncompressing
X-NWS-UUID-VERIFY
X-Cache-Time
Section-Io-Cache
X-Page-Type
X-WR-MODIFICATION
Dynatrace
WP-Super-Cache
X-Litespeed-Cache
X-Ua
X-Pc-Appver
X-COUNTRY
X-Pc-Hit
X-Pc-Key
Cdn
X-External-Request-Id
X-TIME
Mime-Version
X-Servedbyhost
X-Varnish-Action
CF-IPCountry
X-User
Magicmarker
PageType
X-Aicache-OS
X-Pc-Date
X-CSRF-Token
X-Pc-Host
PICS-Label
X-LiteSpeed-Cache-Control
X-CCM-LastModified
X-DC
X-Request-UUID
FastCGI-Cache
X-Cache-Handler
GeoIp-Country-Code
Geoip-City
GW-Server
UCS
X-GEO
X-Variation
Geoip-Latitude
CDN
X-GDPR
X-Dynatrace
X-Fastly-Backend-Reqs
X-Ibm-Trace
X-Irp-Debug
X-Varnish-Beresp-TTL
CACHE
Arc-Country
Sid
Version
X-Varnish-Id
Rt-Proxy-Cache
Cartoon
X-Server-W
X-Cache-Id
X-Shard
X-Gdpr
Pagetype
X-TId
Node
Processtime
GeoIP-Country-Code
GeoIP-Latitude
X-HTML-Minification-Powered-By
X-Thanos
X-Nananana
X-CACHE-KEY
X-Layer
X-FW-Version
X-Bip
GeoIP-City
Memcached
X-Load-Cache
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
COMMERCE-SERVER-SOFTWARE
X-Wa
X-BE
X-StackifyID
Memory
X-Nginx-Cache-Key
If-Modified-Since
X-ServedByHost
X-UPSTREAM-Address
X-Sentry-ID
X-Ig-Deployment-Stage
Pics-Label
X-Via-NSCOPI
X-Varnish-Ttl
RATING
DataCenter
Hostname
X-Gen-Id
X-Proxy-Server
URI
X-Akamai-Request-ID2
X-Be
X-Gannett-Site-Version
X-Varnish-URL
Sta2Tusw
X-Auto-Login
Cf-Ipcountry
X-FORWARDED-FOR
X-Secret
X-Datadome
X-Fastly-Cache-Hits
X-Cluster-Node
X-DataStream-Origin-MEX-Latency
X-NGINX-Cache
Srv
X-Cache-Var
X-Frame-Option
X-SRV
X-Tid
Lb
X-Cache-Var-Map
X-PAGE-TYPE
X-DataStream-MidMile-RTT
Mobile-Detection-Method
X-Nf-Srv-Version
X-PF-Uncompressing
X-Ratelimit-Remaining
OT-Force-Account-Verify
X-ID
SD-X-WS
X-VCT
X-Store
X-PJAX-URL
X-GZIP
X-Ratelimit-Limit
X-EC-Security-Audit
X-B3-SpanId
X-WA
Fastcgi-Useragent
X-Feature
X-APP
X-Dw-Trace-Id
Cache-Provider
Fastcgi-X-Cache
X-Litespeed-Cache-Control
Fastcgi-X-Cache-Version
X-CacheKey
Amp-Access-Control-Allow-Source-Origin
Xet-Cookie
Serverid
X-VC
X-Endurance-Cache-Level
X-Bug-Bounty
X-Hail-Hydra
X-CDN-Pop
Group
X-SB
V-Cache
X-Distil-Cs
X-Policy
X-CDN-Pop-IP
X-Akamai-ERPolicy
X-RAMCache
Pramga
X-Akamai-ERRuleID
X-Fe
Powered
X-Mrs-Cache-Hits
X-Mrs-Cache
X-Mrs-Age
X-Mshield-Cache-Status
REQUESTUUID
X-Ratelimit-Reset
X-SD-PageType
X-Check-Cacheable
X-Surge-Debug
X-Cookie
X-Public
X-Haproxy-Ip
X-Haproxy-Hostname
X-Unique-Id
X-VG-WebCache
X-Request-Start
Requestid
X-Varnish-ID
X-ServerName
X-Grace-Duration