Threat Level: green Handler on Duty: Rob VandenBrink

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
Last-Modified
Accept-Ranges
Pragma
X-Content-Type-Options
X-Powered-By
CF-RAY
ETag
Link
Expect-CT
Via
X-Cache
X-XSS-Protection
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Served-By
X-Amz-Cf-Id
X-Xss-Protection
X-Varnish
Referrer-Policy
X-Timer
CF-Cache-Status
X-FRAME-OPTIONS
Access-Control-Allow-Headers
X-AspNet-Version
Access-Control-Allow-Methods
X-Request-Id
X-Runtime
X-Download-Options
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Request-ID
X-Cacheable
Alt-Svc
X-Generator
Content-Security-Policy-Report-Only
X-Check
X-Adblock-Key
X-AspNetMvc-Version
Status
X-Cache-Status
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Template
X-Permitted-Cross-Domain-Policies
X-Language
X-Iinfo
Content-Encoding
X-Content-Security-Policy
X-Turbo-Charged-By
X-CDN
X-Buckets
X-Type
Keep-Alive
Xkey
X-AH-Environment
X-Cache-Group
WPE-Backend
X-Pass-Why
X-Backend
Access-Control-Max-Age
X-Age
Upgrade
CF-Ray
X-Server
X-POWERED-BY
Access-Control-Expose-Headers
EagleId
X-Via
X-Nginx-Cache-Status
X-Server-Powered-By
X-Drupal-Dynamic-Cache
X-Pingback
X-Varnish-Cache
X-Amz-Id-2
X-Amz-Request-Id
X-Hacker
Grace
X-UA-Device
X-Swift-CacheTime
X-Swift-SaveTime
X-Robots-Tag
Ali-Swift-Global-Savetime
P3p
Cf-Railgun
X-LiteSpeed-Cache
X-Proxy-Cache
X-Envoy-Upstream-Service-Time
X-Page-Speed
X-Ua-Compatible
Request-Context
Content-Location
X-Device
X-Ac
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cnection
X-Amz-Version-Id
X-Host
X-Server-Id
Surrogate-Control
X-Node
X-Cache-Lookup
X-Backend-Server
X-Rq
X-WebKit-CSP
X-Response-Time
X-Rack-Cache
X-Readtime
X-Application-Context
EagleEye-TraceId
X-OneAgent-JS-Injection
Server-Timing
X-Cloud-Trace-Context
Pinterest-Generated-By
X-CST
Report-To
X-Url
Request-Id
X-TTL
X-Instart-Request-ID
X-ORACLE-DMS-ECID
X-Country
X-Px
X-Clacks-Overhead
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Feature-Policy
Edge-Control
X-Country-Code
Rating
Allow
X-DataDome
NEL
X-Powered-CMS
X-PC
X-Vname
X-TtlSet
X-Dns-Prefetch-Control
X-FTR-Request-ID
X-Server-Name
X-Origin-Cache
Charset
X-ESI
X-DynaTrace
X-DynaTrace-JS-Agent
X-Cached
X-MS-InvokeApp
X-Vhost
X-Goog-Hash
X-GitHub-Request-Id
X-Recruiting
X-VARITI-CCR
X-Varnish-TTL
RTSS
X-F-Cache
X-Version
Content-MD5
X-Geo-Segment
X-GoogleNews-Bot
X-Kinja
X-Exp-Id
X-Kinja-Build
X-Kinja-Revision
X-Exp-Variant
X-Kinja-Server
X-Cdn-Fetch
X-Powered-By-Plesk
Accept-CH
Arc-Version
PB-RID
PB-PID
X-Mobile-Rewrite
Public-Key-Pins
X-D2id
X-Mod-Pagespeed
MS-Author-Via
Verso
X-Client-IP
X-Abt-Application-Version
X-Dispatcher
X-Upstream-Env
X-Pinterest-Rid
Pinterest-Version
SPRequestGuid
X-SRCache-Store-Status
X-Ruxit-JS-Agent
X-SRCache-Fetch-Status
X-ORACLE-DMS-RID
X-N
X-SharePointHealthScore
X-Amz-Rid
Nginx-Cache
Accept-CH-Lifetime
X-Navigation-Version
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Dw-Request-Base-Id
X-CF-Powered-By
X-Trace
X-Fastly-Request-ID
X-Forwarded-Proto
Paypal-Debug-Id
X-DIS-Request-ID
X-Origin-Upstream-Status
X-T
X-Hits
X-Upstream
X-Grace
DynaTrace
X-Varnish-Age
SPRequestDuration
SPIisLatency
Arr-Disable-Session-Affinity
TCN
X-Amz-Meta-S3cmd-Attrs
X-Id
X-Shield-Request-Id
AR-ATIME
AR-PoweredBy
X-Pad
AR-CACHE
X-Content-Options
X-Oracle-Dms-Rid
X-Content-Digest
Realpath
X-Cdn
X-NF-Request-ID
X-HW
Access-Control-Request-Method
Mrf-Cache-Status
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
MRF-Tech
X-Kinsta-Cache
X-IPLB-Instance
X-Acc-Meta-Resource-Type
X-Server-ID
X-Cache-Hit
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-FastCGI-Cache
X-B
X-Vcap-Request-Id
X-Debug
X-Logged-In
X-Wix-Server-Artifact-Id
X-XRDS-Location
X-SS-Set-Cookie
X-Ser
Service-Worker-Allowed
Tracecode
X-NewRelic-App-Data
S
X-MSEdge-Ref
Server-Name
Fastly-Restarts
X-PressLabs-Stats
X-FTR-DC
X-FTR-Realm
X-FTR-Cache-Status
X-FTR-Balancer
X-Frontend
X-Country-Code-Real
X-FTR-Backend
X-FTR-Backend-Server
X-Cache-Key
X-FTR-Expires
AMP-Access-Control-Allow-Source-Origin
X-Accel-Buffering
Rt-Fastcgi-Cache
Surrogate-Key
X-Forwarded-For
Fastcgi-Cache
AR-SID
X-Analytics
Backend-Timing
X-HS-Content-Id
X-HS-Hub-Id
X-Cache-Rule
Alternate-Protocol
Eomportal-Instance
Host
FilterID
Cleartype
X-Srv
TP-L2-Cache
Cache-Status
TP-Cache
X-Revision
X-Rid
Front-End-Https
Public-Key-Pins-Report-Only
X-FTR-Cache-Host
X-User-Agent
X-Debug-Info
X-Iejgwucgyu
X-Whom
X-Akam-SW-Version
ServerID
X-Mobile
Accept-Charset
X-AOL-HN
X-HeyJason
X-Varnish-Backend
X-Do-Not-Hack
Permitted-Cross-Domain-Policies
X-XRDS-LOCATION
X-Cache-2
X-GUploader-UploadID
X-Webkit-CSP
X-RateLimit-Remaining
X-TA-CDN-Provider
X-Request-Processing-Time
X-Request-Received
X-Zen-Fury
X-Via-JSL
X-Kinja-Server-Push
X-Content-Powered-By
X-Cached-By
X-NWS-LOG-UUID
X-WPE-Loopback-Upstream-Addr
X-VCache
X-Oneagent-Js-Injection
X-App-Environment
X-Ttl
X-Correlation-Id
X-Node-Name
X-Magnolia-Registration
Host-Header
X-Cluster
X-Page-Id
X-LB-Cache
Viewport
X-Cache-Control
X-Varnish-Hostname
Display
X-Tumblr-User
X-Akamai-Edgescape
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Request-Guid
X-TT
X-Middleton-Display
X-Sol
X-Signature
X-Framework
X-B3-Sampled
X-Content-Security-Policy-Report-Only
X-FB-Debug
X-B-Cache
X-Device-Type
X-Handled-By
Upgrade-Insecure-Requests
X-Platform-Server
X-Instance
Liferay-Portal
DC
Cache-Tag
X-BCube-Filmed-By
X-Amzn-Trace-Id
X-Cache-Server
MicrosoftSharePointTeamServices
X-Hostname
Server-Node
X-Origin-Server
X-TT-TIMESTAMP
X-Webkit-Csp
X-Accel-Expires
X-B3-Traceid
Retry-After
X-Fastcgi-Cache
X-Varnish-Server
Source
X-WA-Info
X-Servedby
X-Contextid
X-Distil-CS
HitType
X-Seen-By
Server-Info
HitInfo
X-Wix-Request-Id
X-Esi
X-Cache-Action
X-Edge-Location
X-Amz-Replication-Status
Content-Script-Type
Content-Style-Type
X-Cache-Operation
X-GeoIP
X-S
SRV
X-RequestSource
X-ATG-Version
X-Middleton-Response
X-Status
X-Tumblr-Pixel-1
X-Jobs
GEO-INFO
Response
User-Agent
Webserver
X-Tumblr-Pixel-2
X-Locale
X-WebKit-CSP-Report-Only
X-Generated-By
Actual-Object-TTL
X-FW-Serve
X-FW-Server
X-FW-Type
AsisCache
X-FW-Hash
X-Edge-Cache
X-FW-Static
X-Response-Served-From
X-Edge-Cache-Key
X-Region
X-Adobe-Content
X-Drupal-Cache-Tags
ServedBy
X-UUID
X-TX-ID
Refresh
X-Adobe-Loc
X-Varnish-Hits
X-Cache-NE
X-Yottaa-Optimizations
X-Yottaa-Metrics
Healthy
X-Port
X-Newrelic-App-Data
X-Geo-Country
X-Hyper-Cache
Payment
X-DataStream-Cache-Status
X-Cache-TTL-Remaining
X-APP-VERSION
S-Cnection
X-Content-Type
IBM-Web2-Location
X-Cache-Age
X-URL
X-Varnish-Grace
X-Amz-Server-Side-Encryption
Country
Edge-Cache-Tag
X-Daa-Tunnel
X-HS-Cache-Config
Filters
X-UA
Datacenter
Served-By
X-Activity-Id
HostName
X-AppVersion
Powered-By-ChinaCache
X-Az
NGB
X-Pc-Hit
X-Pc-Key
X-Pc-Appver
X-Sucuri-ID
X-Cache-Remote
X-HS-Combine-CSS
X-Varnish-IP
X-Cacheable-TTL
X-App-Server
X-Vg-Webcache
X-Mrs-Cache
X-Mshield-Cache-Status
X-Mrs-Cache-Hits
X-Mrs-Age
X-Mode
X-Akamai-Transformed
X-Cache-TTL
X-Rule
X-Cache-Var
X-Detected-As
Meta-Geo
Machine
X-RemovedCookies
X-Cache-Var-Map
X-CDN-Forward
X-Rendered-As
X-RN-RSRV
X-ProcessESI
X-Is-Bot
X-Proxied
Load-Balancing
X-FC-Vary-Parameters
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
TWC-Device-Class
TWC-Connection-Speed
X-PCL
X-Origin-Hint
Mn-Server-Ip
OT-Force-Account-Verify
X-Proxy
Property-Id
DB-Nickname
X-Tb
X-Cache-Category-Id
TWC-Privacy
X-Varnish-Cache-Hits
User-Cache-Control
Webcakes-App-Name
Webcakes-App-Version
X-Amz-Meta-Surrogate-Control
X-Hosted-By
TWC-Locale-Group
X-Grey
Backend
Cache-Name
X-OCL
X-Varnish-Cacheable
X-Rocket-Nginx-Bypass
Webcakes-Region
TWC-GeoIP-LatLong
TWC-GeoIP-Country
X-Origin
X-OVcl-Cache
X-Original-Request
Access-Control-Allow-Method
Azure-InstanceId
Azure-RegionName
Azure-SiteName
Azure-Version
X-ProxyCache-Key
X-Section
X-JoinUs
X-ServerID
X-Loop
X-Routing-Service
X-Generated
X-Format
X-Access
X-Human
X-Site-Version
X-CDN-Cache
X-ProxyCache-Status
ServerName
X-Hit
X-OVcl
X-BYPASS-REASON
X-TNCMS
X-Upgrade-Enabled
X-Zipkin-Id
X-EIG-Tracking-Id
Azure-SlotName
Selected-FE
X-Timing-Wait
X-SplitTest
X-Pubstack
X-PERF
X-Proxy-Build
Now
X-TWH-CORRELATION-ID
X-Www-Served-By
L5d-Success-Class
X-VWS-Id
X-Viewer-Country
X-Via-Fastly
X-Agile
X-Agile-Age
X-Debug-Cache
X-NGENIX-Cache
X-LJ-Flow-ID
X-L-Path
X-IP
X-Environment-Context
X-NodeID
X-Cache-Config
X-ApacheServer
X-Agile-Id
X-App-Name
X-AWS-Id
X-BB-IP
Fastcgi-X-Cache-Version
S-Rt
X-Upstream-HT
Access-Control-Request-Headers
Fastcgi-X-Cache
X-Upstream-CT
X-Source
Fastcgi-Useragent
Cache-Key
From-Origin
X-Drupal-Cache-Contexts
X-CCM
X-Origin-CC
X-Ocache
X-App-Version
X-Correlation-ID
X-Nginx-Cache
X-Amz-Apigw-Id
X-Xfnlog-Site
X-HOST
X-Amzn-RequestId
X-Unique-ID
Pagespeed
LB
X-Backend-Name
Cache
X-Forwarded-Host
Fastly-SSL
X-Akamai-Request-ID
X-Litespeed-Cache
NtCoent-Length
X-Storage
ViewerVersion
X-Ms-Lease-Status
X-Pc-Date
X-Pc-Host
X-Ms-Request-Id
X-RateLimit-Limit
X-Ms-Blob-Type
X-Ms-Version
X-Birta-Cache-Post
X-Birta-Served
X-Vgn-Hpd-Reason
X-Feature
X-M-Reqid
X-Qnm-Cache
X-M-Log
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-VG-TLSProxy
AR-Request-ID
X-Labrador-Cache-Channel
X-Real-Ip
X-NCache
X-Time-Microsecs
Ar-Sid
CACHE
X-Internal-Host
X-Cluster-Node
X-Microcachable
X-Guploader-Uploadid
X-Distributor
X-Release
Time
X-EdgeConnect-Cache-Status
PageSpeed
X-Real-IP
X-Ruxit-Js-Agent
X-B3-Spanid
WZWS-RAY
X-Powered-By-ANYU
Xserver
X-Cache-Enabled
X-B3-TraceId
X-Sucuri-Cache
X-Request-Time
X-SIPLIST1
Fly-Cache
Ec-Rule-Version
X-Rojux
Cache-Prefix
X-Rewrite-Enabled
Meta-Geo-Continent
X-Server-Time
IsBot
Fly-Request-Id
MD5-Digest
X-S-Cookie
X-ScT
X-Server-By
X-SRCache-Key
X-Via-CDN
X-VG-WebServer
X-UE-Client-Country
X-Via-Edge
X-Via-SSL
Xc-Version
X-WebServer
X-Twitter-Response-Tags
X-Trv-Group
Ajk
AKAMAI
Arc-Country
X-Web-Node
X-Request-UUID
X-Transaction
X-Store
BehaviorPad-Version
Rendered-Blocks
X-A-Dgt
X-Developer
X-A-Wwc
X-Destination
X-A-Dcw
X-A-Dam
X-DPWN-IS-SECURE
X-Dispatcher-Server
X-Died
X-Date
X-D
X-CF-Lambda-Fn
X-Cache-Bucket
X-BB-ID
X-B-Cookie
X-CF-Lambda-Version
X-Application
X-CUA
X-Accel-Expires-Debug
X-Connection-Hash
X-From
X-G
REQUESTUUID
X-Org
X-NU-AKA-ACS-Version
Server-Int
X-PAYTM-SRV-ID
X-ARC
X-Redis-Cache
Mobile-Detection-Method
NGX
X-No-Session
T-Server
X-A-Ccd
X-Generation-Time
X-Generated-In
X-Logtrace-Id
X-A
Viewtype
VivaBuild
Www
X-Region-Sid
V-Age
X-Varnish-Beresp-Ttl
X-NC
X-Newrelic-Synthetics
X-Cache-Backend
X-Sorting-Hat-ShopId
X-Shopify-Stage
X-FireWall-Port
X-SERVER-NAME
X-Dynatrace-Js-Agent
X-ShopId
X-Sorting-Hat-PodId
X-ShardId
X-Alternate-Cache-Key
X-Crawler
X-Cache-CFC
X-GeoIP-City
X-Gen-Mode
ProcessTime
X-External-Request-Id
X-Fastly-Cache
X-Block-Status
X-F5-Cache
X-CS
Server-Host
Origin-Cache-Control
Frame-Options
NodeID
Magicmarker
Origin-Edge-Control
Pragrma
Web-Mar-Node
SN
Release
X-Amz-Meta-Cache-Control
X-IN-APIGATEWAY
X-UnsetCookies
X-S-Maxage
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Varnish-Action
X-VCT
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-We-Are-Hiring
X-VServer
Backend-Name
X-Policy
X-IN-SSL-APIGATEWAY
GMS-Ver
X-Hnp-Log
X-Hash
X-IN-WAF
X-Irp-Debug
X-Origin-TTL
X-Node-Id
X-Layer
X-Phone
X-Endurance-Cache-Level
X-Webstats-RespID
X-C
X-ElasticPress-Search
X-Gannett-Site-Version
X-GeoIP-Country-Code
CDCHOST
X-Ezoic-Cdn
X-Eu-Site
X-Fetched-On
X-Hl-Ver
Apple-News-Services-Request-Url
X-Instance-Name
X-Key
Cneonction
Apple-News-Services-Handled
Apple-News-Services-Host
X-HTML-Minification-Powered-By
Apple-News-Services-Parsed-Url
X-Epic-Correlation-Id
X-Developers
X-Backend-Url
Countrycode
X-Cache-Expires
X-Backend-TTL
X-Backend-State
X-GZip
X-Backend-Host
X-Cache-Srv
X-Cache-URL
Country-Code
X-Croise-Owner
X-Core-Value
X-Core-Mission
X-CGP
X-Clientip
X-Location
X-MI-In-Market
X-Secret
X-Server-IP
X-Sf
X-Returned-From-PostProcessResponse
X-Returned-From-DLL
X-Returned-From
X-Returned-From-BeforeDispatch
X-Stale
X-Swa-Ws
X-Var-Ttl
X-Variation
X-Up
X-Tumblr-Pixel-3
X-Thinkindot-L3
X-TT-LOGID
X-Response-By
X-Request-URI
Pagetype
Adler-Geo
X-Owner
X-Nginx-Cache-Key
X-MSEdge-Flight
X-Actual-URL
X-MSEdge-Features
X-Passed-To
X-Passed-To-BeforeDispatch
X-Reboot
X-UA-Device-Type
X-RCS-CacheZone
X-Platform
X-Passed-To-DLL
X-Passed-To-PostProcessResponse
X-Matched-Rule
X-FW-Version
HA-Host
HA-Ipaddr
MI-API
Platform
MI-Cache
Ha-Gx-Prefs
HA-Servedtime
Uber-Trace-Id
Is-Eu
Thinkindot-Control
Esi-Enabled
Thinkindot-CacheControl-Type
HA-Urlpath
Heartbleed
HA-Georegion
HA-Geolon
Section-Io-Cache
Request-EU
Thinkindot-CacheControl
Origin
Odigeo-Trace-Id
MI-Cache-Age
Request-Country
Proxy-Connection
HA-Geolat
Kp-EeAlive
HA-Geocountry
HA-Cloudapp
HA-Geocity
X-Nc
X-CACHE-AGE
X-Amz-Cf-Pop
RNT-Time
X-Debug-Log
RNT-Machine
Cache-Tags
On-Server
Powered
X-Fstrz
HTTPS
Cache-Cookie-Set-From
X-Worker
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
Resin-Trace
X-Device-Os
X-Dc
X-TIME
X-Debug-Cookies
X-NWS-UUID-VERIFY
X-ServiceProvider
X-Sn-Servicetimems
X-Trace-Id
X-V
X-NX-Host
Content-Disposition
X-Ckpd-Fst-Backend
True-Client-Country-4JS
Decoy-Debug-Key
Fastly-Backend-Name
Server-ID
X-Cache-Host
X-Cdn-Origin
Decoy-Debug-Status
Decoy-Debug-TTL
X-Content-Age
X-COUNTRY
XServer
X-Rebelmouse-Surrogate-Control
X-Cdn-Srv
Fastly-SIE
X-Rebelmouse-Cache-Control
X-Surge-Debug
Fastly-SWR
X-Alicdn-Da-Ups-Status
Warning
X-Skip-Cache
X-Servername
X-Csrf-Token
Host-ID
RequestId
MIME-Version
X-Pf-Uncompressing
X-Ua
X-Req
X-Aed
X-Ratelimit-Limit
X-Edge-IP
X-GEO
PFcat
Request-Time
X-Proto
Pramga
Sid
Cteonnt-Length
TSSecure
Mail-Subject
We-Hiring
X-PHP-Backend
X-Refresh
X-Ms-Lease-State
CF-IPCountry
X-Pjax-Url
WP-Super-Cache
X-Hello
X-Flog
X-ABtesting
X-Page-Type
X-Cdn-Forward
X-Server-W
X-Varnish-Ttl
X-Geo
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
Cdn
X-Servedbyhost
X-Varnish-Url
X-Planisys-CDN-TTL
X-Atg-Version
CDN
X-DC
X-CLOUD-TRACE-CONTEXT
X-Time
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
GeoIp-Country-Code
X-Oss-Request-Id
X-Auto-Login
Mime-Version
Geoip-Latitude
X-Oss-Server-Time
X-Oss-Storage-Class
X-CSRF-Token
FSS-Proxy
X-Cache-ASPX
FSS-Cache
Dnion-Transfer-Encoding
X-Oracle-Dms-Ecid
X-GoCache-CacheStatus
X-DataStream-Origin-MEX-Latency
X-Unique-Id
Lfy
X-DataStream-MidMile-RTT
X-Akamai-Request-ID2
X-Aicache-OS
X-Varnish-Beresp-TTL
Rt-Proxy-Cache
X-Sentry-ID
A
PageType
X-WA
MS-CV
X-Datadome
X-EC-Security-Audit
X-GRACE
NnCoection
X-MP-GENERATED-AT
Memcached
X-Thanos
X-Origin-Expires
X-Served-From
X-Cache-Id
X-Origin-Date
X-Via-NSCOPI
X-Bip
X-Check-Cacheable
NODE
X-Ratelimit-Remaining
X-Varnish-HitMiss
X-CACHE-KEY
Node
X-Cache-Info
X-APP
X-Be
X-HCF
X-Wa
X-Cache-Control-Set-By
Hostname
SD-X-WS
X-Request-Start
X-Proxy-Server
X-Use-Magma
X-Nananana
X-Server-Group
WWW-Authenticate
X-UPSTREAM-Address
GeoIP-Country-Code
Memory
GeoIP-Latitude
X-NODE
X-Fastly-Cache-Hits
X-SRV
GeoIP-City
Geoip-City
GW-Server
UCS
DataCenter
X-PAGE-TYPE
X-ServedByHost
X-Cookie
PICS-Label
Cache-Hits
Processtime
X-Varnish-URL
X-Vcache
X-User
X-Wix-Route-ID
X-RTag
X-WR-MODIFICATION
X-From-Cache
X-Gen-Id
Accept-Language
X-HS-Status
X-GDPR
X-Load-Cache
Cdn-Request-Time
X-Gdpr
Cf-Ipcountry
Cdn-Host
X-Fastly-Backend-Reqs
X-PJAX-URL
X-Edge-Server
X-Goog-Meta-Goog-Reserved-File-Mtime
Amp-Access-Control-Allow-Source-Origin
X-FORWARDED-FOR
Ms-Operation-Id
X-Urbn-Context-Path
X-Urbn-Site-Id
X-LI-UUID
X-LI-Proto
Locale
Pics-Label
X-Swift-Error
COMMERCE-SERVER-SOFTWARE
X-Li-Fabric
X-Path-Route
X-BBXSRF
X-Cache-Ttl
X-Li-Pop
X-Cache-Debug
X-B3-SpanId
X-Info
Dont-Set-Cookie
X-Fe
Lb
X-Dw-Trace-Id
Get-Access-Time
X-VG-WebCache
X-Optimization
V-Cache
SS
X-RateLimit-Reset
Group
Is-Session-Tracking
X-PF-Uncompressing
Fastly-Soc-X-Request-Id
X-Cache-HT
X-CDN-Pop-IP
X-Env
X-CDN-Pop
X-Qloud-Router
X-ID
X-Content-Encoded-By
X-P-T
NX-Cache
X-Bug-Bounty
X-GZIP
Who
URI
Requestid
Serverid
X-NGINX-Cache
X-Cache-FS-Status
X-SN
AGE-Hash
CDN-Cache
CDN-Cache-Hit
CDN-Node
Xet-Cookie
X-CacheKey
X-ServerName
X-Ver
X-Varnish-Info
X-Akamai-SSL-Client-Sid
SID
X-Serial
X-CSRF-TOKEN
X-Ibm-Trace
X-VC
X-RequestId
X-Shard
X-SB
X-Meta-Tbi-Cache-Vertical
N-Cache
Ws
X-Litespeed-Cache-Control
X-Flags
X-Akamai-ERRuleID
Https
X-Akamai-ERPolicy
X-Route-Name
X-Is-Crawler
X-Providence-Cookie
X-Grace-Duration