Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Accept-Ranges
Cf-Request-Id
CF-Cache-Status
Pragma
X-Powered-By
ETag
Link
Expect-CT
X-XSS-Protection
Via
Age
CF-RAY
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-UA-Compatible
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
Alt-Svc
X-Served-By
CF-Ray
X-Xss-Protection
X-Timer
X-Varnish
X-Download-Options
Access-Control-Allow-Methods
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Permitted-Cross-Domain-Policies
X-Cache-Status
X-Generator
X-Request-ID
P3p
X-Cacheable
X-Kinja-Server-Push
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-Content-Security-Policy
Status
X-AspNetMvc-Version
Upgrade
Content-Encoding
X-CDN
X-Template
X-Language
Access-Control-Max-Age
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
X-Envoy-Upstream-Service-Time
Keep-Alive
X-Via
X-Ws-Request-Id
Feature-Policy
X-Age
X-Backend
X-Dns-Prefetch-Control
X-Buckets
X-Hacker
X-AH-Environment
X-Cache-Group
X-Robots-Tag
X-Server
X-UA-Device
X-Amz-Request-Id
EagleId
X-Amz-Id-2
X-Proxy-Cache
X-Turbo-Charged-By
X-Server-Powered-By
Request-Context
Server-Timing
Host-Header
X-Nginx-Cache-Status
Grace
Report-To
Xkey
X-Page-Speed
X-Rq
Cf-Bgj
X-Varnish-Cache
X-OneAgent-JS-Injection
X-Pingback
X-LiteSpeed-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Cf-Railgun
Ali-Swift-Global-Savetime
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-WebKit-CSP
X-Amz-Version-Id
X-Vhost
X-Host
X-Dispatcher
NEL
X-Device
X-Backend-Server
X-Node
X-Cache-Lookup
Surrogate-Control
X-Ruxit-JS-Agent
X-Origin-Cache
X-Response-Time
Content-Location
X-Akam-SW-Version
Request-Id
X-ASPNET-VERSION
X-Ac
X-Country
X-Server-Id
X-Mod-Pagespeed
EagleEye-TraceId
X-HW
Rating
Accept-CH-Lifetime
X-Readtime
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
Accept-CH
X-Cloud-Trace-Context
Pinterest-Generated-By
X-Application-Context
Edge-Control
X-Country-Code
X-Url
X-DataDome
X-Origin-Upstream-Status
X-PC
X-Vname
X-TtlSet
X-Varnish-TTL
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Fusion-Content-Id
Fusion-Content-Source
Fusion-Deployment-Id
Fusion-Template-Id
Fusion-Source
Fusion-Component-Id
X-Cnection
Akamai-Age-Ms
X-D2id
X-GitHub-Request-Id
X-ESI
X-MS-InvokeApp
X-Clacks-Overhead
X-Content-Type
X-Server-Name
X-Abt-Application-Version
X-Navigation-Version
X-FTR-Request-ID
Allow
Pinterest-Version
X-Pinterest-Rid
X-Vcap-Request-Id
X-Trace
Verso
Display
X-Middleton-Display
X-Middleton-Response
Response
X-Sol
Pagespeed
X-Server-ID
X-Px
Accept-Ch
X-B3-TraceId
X-DynaTrace
X-Cached
X-Element-Page-Cache
X-Rack-Cache
X-Fastly-Request-ID
Service-Worker-Allowed
X-Client-IP
X-Cache-TTL
X-TTL
MS-Author-Via
Arr-Disable-Session-Affinity
X-Version
X-Powered-By-Plesk
X-Upstream
X-Forwarded-Proto
Content-MD5
X-Dw-Request-Base-Id
X-T
X-Webkit-CSP
X-NF-Request-ID
AR-ATIME
AR-PoweredBy
Ar-Sid
AR-CACHE
AR-Request-ID
Fastly-Restarts
X-Debug
SPRequestGuid
X-SharePointHealthScore
X-VARITI-CCR
Accept-Ch-Lifetime
X-Jurisdiction
X-XRDS-Location
X-Exp-Id
X-GoogleNews-Bot
X-Kinja-Server
X-Use-Magma
X-Kinja
X-Kinja-Build
X-Exp-Variant
X-Cdn-Fetch
X-Kinja-Revision
TP-Cache
TP-L2-Cache
X-Content-Digest
Access-Control-Request-Method
X-Powered-CMS
X-Goog-Hash
X-NWS-LOG-UUID
X-MSEdge-Ref
X-Edge
X-Release
X-PressLabs-Stats
TCN
X-FastCGI-Cache
X-Ttl
RTSS
S
Cache-Tag
SPIisLatency
SPRequestDuration
X-Amz-Rid
Fastcgi-Cache
X-Request-Processing-Time
X-Request-Received
X-Yandex-Sdch-Disable
Public-Key-Pins
X-Ezoic-Cdn
X-Pinterest-Direct
X-Accel-Expires
X-Node-Name
Server-Node
X-MCACHE
X-Mid
X-Cache-Key
X-Ratelimit-Remaining
X-Cache-Hit
X-Logged-In
X-Amzn-Trace-Id
ServerID
Front-End-Https
X-CST
X-Request-Handler-Origin-Region
X-Microsite
Alternate-Protocol
X-Ser
X-Page-Id
X-Recruiting
X-Origin-Server
X-Kinsta-Cache
X-B
X-Ratelimit-Limit
Host
Accept-Charset
X-ECACHE
X-Hostname
X-Mobile-URL
X-FireWall-Port
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-Expires
X-Country-Code-Real
X-FTR-DC
X-FTR-Realm
X-FTR-Backend
X-FTR-Backend-Server
Nginx-Cache
X-Varnish-Age
X-Seen-By
X-Forwarded-For
X-Content-Security-Policy-Report-Only
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Filterid
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-Load-Cache
X-DIS-Request-ID
Realpath
X-Jobs
X-Daa-Tunnel
X-Content-Options
X-Shield-Request-Id
X-Az
X-AppVersion
X-Activity-Id
X-Id
X-Git-Hash
X-Type
X-Varnish-Backend
X-F-Cache
X-LB-Cache
X-App-Environment
X-Varnish-Grace
X-Request-Guid
Paypal-Debug-Id
Edge-Cache-Tag
X-N
X-Rid
X-Zen-Fury
X-Hits
Fastcgi-Useragent
X-Correlation-ID
X-FB-Debug
X-Grace
X-Mg-S
X-Proxy
X-App-Server
DynaTrace
Cache-Tags
Access-Control-Allow-Method
X-Upgrade-Enabled
DC
Content-Disposition
X-Content-Powered-By
X-WebKit-CSP-Report-Only
X-Amz-Server-Side-Encryption
X-Akamai-Edgescape
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Cache-Operation
AMP-Access-Control-Allow-Source-Origin
X-Cache-Rule
X-Geo-Country
Cleartype
X-Endurance-Cache-Level
MicrosoftSharePointTeamServices
X-Wix-Request-Id
X-HP-Webp
X-Cached-By
X-VCache
X-Original-Request-Id
X-Host-Name
X-Accel-Buffering
X-Response-Served-From
NGB
Refresh
X-B3-Sampled
X-IPLB-Instance
X-AOL-HN
Payment
X-Rule
X-Cacheable-TTL
X-Distributor
Healthy
MS-CV
X-User-Agent
X-UUID
X-HTML-Minification-Powered-By
X-Is-Bot
X-Rendered-As
X-FW-Type
X-FW-Dynamic
X-FW-Serve
X-FW-Server
X-Ua
X-FW-Hash
X-FW-Static
X-HS-Content-Id
X-Cache-Time
X-HS-Hub-Id
X-Amz-Apigw-Id
X-Amzn-RequestId
X-HS-Combine-CSS
X-Signature
X-HS-Cache-Config
X-B-Cache
Datacenter
X-Region
X-Whom
X-Hp-Webp
X-Instance
X-Amz-Meta-S3cmd-Attrs
X-Goog-Stored-Content-Encoding
X-Tumblr-Pixel
X-GUploader-UploadID
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Tumblr-User
X-Fastcgi-Cache
X-Goog-Stored-Content-Length
X-Tumblr-Pixel-2
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Metageneration
Countrycode
X-Debug-Info
X-Mobile
X-XRDS-LOCATION
PB-RID
PB-PID
Arc-Version
X-Varnish-Server
Powered
X-Frontend
X-Cache-Age
X-App-Version
Powered-By-ChinaCache
X-Oneagent-Js-Injection
X-PHP-Backend
X-Tec-Api-Root
X-Tec-Api-Version
X-Tec-Api-Origin
Surrogate-Key
S-Cnection
X-Respond-Thread
X-Backend-Name
X-NewRelic-App-Data
X-Azure-Ref
X-Cache-Server
X-Via-JSL
X-Protected-By
Cache
X-Litespeed-Cache
X-DynaTrace-JS-Agent
X-WA-Info
X-Hyper-Cache
Liferay-Portal
X-FTR-Cache-Host
Viewport
X-Time
X-Cache-Control
X-Cache-Expired-At
Referer-Policy
X-Acc-Debug-Context
X-Proxy-Cache-Status
Retry-After
X-CSRF-Token
X-EdgeConnect-Cache-Status
X-FB-TRIP-ID
Filters
X-Cache-Var-Map
X-RemovedCookies
X-ProcessESI
X-Cache-Var
Meta-Geo
X-Debug-Cache
X-ES-SERVER
X-R9-Blue-Green-Version
X-RN-RSRV
X-Source
X-Sucuri-ID
Webserver
X-Mode
Eomportal-Instance
X-Qloud-Router
X-Locale
X-Device-Type
From-Origin
X-From
Section-Io-Cache
X-AWS-Id
X-OCL
X-LJ-Flow-ID
X-Xfnlog-Site
X-VWS-Id
X-GeoIP
Ms-Operation-Id
Mn-Server-Ip
X-Via-Fastly
X-Site-Version
X-BYPASS-REASON
X-Server-W
X-RTag
X-Ratelimit-Reset
X-ProxyCache-Status
X-Time-Microsecs
X-PCL
X-Real-IP
X-Cache-Host
X-ProxyCache-Key
Cross-Origin-Window-Policy
Charset
Cache-Tv-Group
X-Handled-By
Ec-Rule-Version
X-Hl-Ver
X-Human
X-TNCMS
X-Zipkin-Id
Webcakes-App-Name
Webcakes-App-Version
Webcakes-Region
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-Device-Class
Selected-Fe
TWC-GeoIP-Country
X-Cache-Action
X-Proxied
X-Origin-Hint
X-Cluster
X-Loop
X-Framework
TWC-Connection-Speed
X-Timing-Wait
X-Proxy-Build
Property-Id
X-Routing-Service
X-FW-Version
TWC-Privacy
X-Generated-By
X-Hosted-By
X-JoinUs
X-Environment-Context
X-Detected-As
X-BCube-Filmed-By
X-Be
X-L-Path
X-Labrador-Cache-Channel
X-ServerID
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-SaId
X-Proto
X-NYM-Debug-Backend
X-PHP-Host
X-Amzn-Remapped-Content-Length
X-Status
DB-Nickname
X-Amz-Replication-Status
X-Format
Uber-Trace-Id
X-Section
X-Redis-Cache
X-Cache-TTL-Remaining
X-Revision
X-Access
X-Varnish-Cache-Hits
FSS-Cache
X-NWS-UUID-VERIFY
Frame-Options
Version
X-Air-Hostname
X-No-Session
Nel
X-ATG-Version
X-Cache-PHP
X-Drupal-Cache-Contexts
X-TA-CDN-Provider
X-Sucuri-Cache
X-NCache
X-Contextid
X-Origin
GEO-INFO
X-EIG-Tracking-Id
X-Unique-Id
X-Drupal-Cache-Tags
CF-Cached-On
Server-Name
X-EC-Lua
X-IPS-LoggedIn
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-IP
X-Cache-Enabled
OT-Force-Account-Verify
X-Vgn-Hpd-Cached
X-Bc-Bl
X-Vgn-Hpd-Variations-Key
X-Akamai-Transformed
X-CACHE-AGE
Time
X-Cache-Backend
X-GoCache-CacheStatus
Now
X-Backend-Host
X-Tumblr-Pixel-3
X-Adobe-Loc
X-CDN-Forward
X-Oss-Storage-Class
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
X-Adobe-Content
X-Oss-Server-Time
X-Ruxit-Js-Agent
X-TT
X-Correlation-Id
X-AIR-PT
X-Cdn
Azure-Version
Azure-SlotName
Azure-RegionName
Azure-SiteName
X-URL
Azure-InstanceId
X-Instart-Request-ID
X-TIME
X-RCS-CacheZone
Access-Control-Request-Headers
Node
X-APP-VERSION
X-Vdms-Version
X-Vdms-Path
Fastcgi-X-Cache-Version
Apple-News-Services-Handled
X-NGENIX-Cache
Apple-News-Services-Parsed-Url
X-Cache-NE
X-B-Cookie
Apple-News-Services-Host
DCR-Decision-By
X-CF-Lambda-Version
X-Connection-Hash
X-Twitter-Response-Tags
X-CF-Lambda-Fn
X-CCM
DCR-Processing-Time-Ms
CloudFront-Viewer-Country
Apple-News-Services-Request-Url
X-Application
Meta-Geo-Continent
X-Cache-2
X-A
X-A-Ccd
Mobile-Detection-Method
Rendered-Blocks
Surrogated-Key
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-A-Dam
X-A-Dcw
X-Adobe-Source
X-Aed
SD-X-WS
X-ARC
Machine
X-Accel-Expires-Debug
MD5-Digest
X-A-Dgt
X-A-Wwc
Host-ID
X-Up
X-Worker
X-Vtex-Remote-Cache
X-Generation-Time
X-Vtex-Processado-Em
X-Rewrite-Enabled
X-G
X-VG-WebCache
X-Minions-Version
X-PAYTM-SRV-ID
X-PBS-Appsvrname
X-Processor
X-D
X-VG-WebServer
X-External-Request-Id
X-Request-UUID
X-ScT
X-Destination
X-Trv-Group
X-Transaction
X-S-Cookie
X-Date
Xc-Version
X-Rojux
X-S
X-UA
CDN-RequestId
X-Platform
X-Rebelmouse-Cache-Control
Ufe-Result
CDN-RequestCountryCode
X-Skip-Cache
Platform
X-Pubstack
CDN-EdgeStorageId
X-SN
CDN-PullZone
X-Shopify-Stage
Fastly-SWR
X-PERF
Fastly-SSL
Fastly-SIE
X-ShopId
Is-Eu
X-Reqid
X-ShardId
CDN-Uid
X-Rebelmouse-Surrogate-Control
X-Req
Mail-Subject
NM-Fastcgi-Cache
X-OVcl-Cache
X-Storefront-Renderer-Rendered
X-Forwarded-Host
X-Varnishpool
X-Cache-Grace
X-Cache-Bucket
X-Backend-TTL
X-Bip
X-Thanos
X-Envoy-Decorator-Operation
X-Servername
X-Core-Value
X-CUA
X-Variation
X-Dispatcher-Server
X-Edge-Location
X-DPWN-IS-SECURE
X-VG-TLSProxy
X-Storage
X-Owner
X-OVcl
X-Microcachable
X-Sorting-Hat-PodId
Wxu-Next-Region
Wxu-Next-Commit
Wxu-Next-Hostname
X-Method
X-Sorting-Hat-ShopId
X-Soup
X-Generated-On
X-Hash
CDN-CachedAt
X-Level-Front-Cache
X-ApacheServer
We-Hiring
X-Alternate-Cache-Key
X-Varnish-Ttl
X-NC
CDN-Cache
Adler-Geo
X-TX-ID
HostName
X-ECache
X-CGP
X-Cdn-Srv
X-Ms-Version
X-Cache-Tags
X-Core-Mission
X-Clara-WADP
X-Cluster-Name
X-Clientip
X-Cache-NGX
X-Cms-Context
X-Cache-Date
X-Auto-Login
X-Agile-Id
X-Agile-Age
X-Agile
X-Backend-State
X-Varnish-Beresp-Ttl
X-Csrf-Jwt
X-Cache-Config
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
X-Fastly-Cache
X-Proxy-Upstream
X-Policy
X-Ms-Request-Id
X-Micro-Cache
X-Render-Time
X-Webstats-RespID
X-Viewer-Country
X-VarnishDD-TTL
X-Varnish-Cacheable
X-LI-UUID
X-Li-Pop
Rt-Fastcgi-Cache
X-Fmm-Version
X-WADP-Cache
X-Fastly-Backend
X-Gamma-Serve
X-VHOST
X-Li-Fabric
X-HS-Content-Campaign-Id
X-HN
X-Eu-Site
X-Request-Start
AKAMAI
Gh-Request-Id
Group
Decoy-Debug-TTL
CacheControlHeader
Origin
Pagetype
Fastly-Backend-Name
PFcat
Fastly-Drupal-HTML
Decoy-Debug-Status
Decoy-Debug-Key
Country-Code
Cache-Status
L
L5d-Success-Class
C-Via
Ha-Gx-Prefs
HA-Ipaddr
X-Gzip
X-Content-Age
X-Geo-Header
Akamai-GRN
X-Web-Node
X-Has-Esi
Memcached
X-Cache-URL
X-Wikidot-Static-Cache
X-Esi-Check
X-Cache-Id
X-Wikidot-Backend
X-Developers
X-Amz-Meta-Cb-Modifiedtime
X-Slack-Backend
X-Esi
X-Old-Content-Length
X-Say-Cacheable
X-Location
X-Say-TTL
X-Request-Host
X-JWT-State
UCS
Backend
Country
X-Irp-Debug
X-Is-Gdpr
X-SayCDN-TTL
X-Cdn-Forward
X-CS
X-PF-Uncompressing
X-Wa
X-Refresh
FSS-Proxy
M-TraceId
X-Mvc-Supplant-Cachable
X-NODE
X-Dc
X-Platform-Server
X-Aicache-OS
X-LB-ID
X-Ah-Environment
X-RateLimit-Remaining
Arc-Country
X-Via-Poph
X-Via-Popn
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-LAGOON
X-DefHash
X-DefElseHash
Upgrade-Insecure-Requests
X-Varnish-CookieHashed-On
X-UPSTREAM-Address
X-B3-Spanid
X-BC
X-Branch-Name
Viewtype
VivaBuild
X-ZONE
NGX
X-RunCloud-Cache
Actual-Object-TTL
X-Session-Fingerprint
X-Cache-Debug
X-LI-Proto
X-Servedbyhost
X-ORACLE-APMCS-REQUEST-ID
X-Ua-Device
X-Via-Ucdn
Srv
Cdn-Host
Cdn-Request-Time
X-Mvc-Supplant-OutputCached
X-Route-Name
X-Flags
CACHE
X-Zone
X-Edge-Server
X-Is-Crawler
X-Aspnet-Duration-Ms
X-Providence-Cookie
X-Bc
X-SERVER
X-Unique-ID
Geo-Info
X-Debug-Cache-Store
X-Request-Time
X-Debug-Cache-Fetch
Memory
X-Nginx-Cache
X-Vgn-Hpd-Ssi
X-Srv
X-DC
Xserver
X-HS-Status
X-APP
X-Action
X-Varnish-Hostname
X-GEO
X-FPC
WWW-Authenticate
X-DB
X-Page-View
X-RPS
X-RSL
X-RPM
X-DW
X-DSS
X-DI
X-Ftr-Cache-Host
X-LiteSpeed-Cache-Control
X-CF-Powered-By
X-Akamai-Request-ID2
Sid
X-B3-Traceid
X-Cs
X-Geo
X-NGINX-Cache
NtCoent-Length
X-Cluster-Node
X-Epic-Correlation-Id
X-Oss-Cdn-Auth
X-MP-GENERATED-AT
X-Check-Cacheable
X-Via-Popv
X-Vcache
X-FC-Vary-Parameters
Hostname
X-Mobile-Rewrite
X-Hit
Geoip-Latitude
X-Dynatrace-Js-Agent
Server-Info
GeoIP-Country-Code
X-NU-AKA-ACS-Version
GeoIP-Latitude
GeoIp-Country-Code
X-Nc
X-VCL-Version
ProcessTime
X-CSRF-TOKEN
User-Agent
SRV
X-Datadome
X-SERVER-NAME
Apigw-Requestid
Processtime
XServer
X-Webkit-CSP-Report-Only
X-FORWARDED-FOR
X-Vcl-Version
X-Sql-Count
X-Via-CDN
X-Sql-Duration-Ms
X-UnsetCookies
X-Via-SSL
Edge-Copy-Time
X-Via-Edge
X-Fpc
W
WebServer
SID
X-HOST
S-Rt
On-Server
X-We-Are-Hiring
X-Envoy-Upstream-Healthchecked-Cluster
X-Svr
X-Key
Origin-Cache-Control
Esi-Enabled
Accept-Language
Origin-Edge-Control
LB
Amp-Access-Control-Allow-Source-Origin
X-HITS
X-Fastly-Country-Code
X-Cache-Hm
Cdn
X-Www-Served-By
X-Cache-Hfrom
X-Tb
X-Dispatch
CF-IPCountry
Proxy-Firewall
N-Cache
T-Server
X-Pjax-Url
Cache-Hits
ServedBy
A
X-SRV
Ohc-File-Size
X-S-Maxage
X-CACHE-KEY
X-COUNTRY
HitType
X-MSEdge-Features
X-Cache-Remote
Lb
CDN
X-Pass-Why
Cteonnt-Length
X-Geo-Region
X-MSEdge-Flight
Server-Host
X-App
X-Presslabs-Stats
Magicmarker
Fastcgi-Cache-TTL
Pics-Label
X-Instart-Info
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
X-RAMCache
BehaviorPad-Version
Powered-By
X-Newrelic-App-Data
X-Generated
WZWS-RAY
X-TrackingId
X-Li-Proto
X-SB
X-Path-Route
X-Newrelic-Synthetics
X-Varnish-Hits
X-VC
X-ServedByHost
X-Dynatrace
X-Pinterest-Sli-Response-Type
Cache-Key
X-Akamai-Pragma-Client-IP
X-Served-From
X-Pinterest-Sli-Endpoint-Name
X-Pinterest-Sli-Latency-Threshold
X-B3-SpanId
Ohc-Cache-HIT
X-TH-Server
Xet-Cookie
X-Info
X-StackifyID
X-Cache-Tag
X-Via-PopV
Cache-Provider
X-Via-PopN
Server-Ttl
Dnion-Transfer-Encoding
X-Via-NSCOPI
X-Via-PopH
X-LiteSpeed-Tag
Protected
X-Batcache
X-Lb-Id
X-Origin-Response-Time
User-Cache-Control
X-Tt-Logid
X-WA
X-Uri
X-ID
Content-Style-Type
X-Agile-Brick-Ok
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
Cf-Alt-Svc
X-TT-LOGID
Content-Script-Type
X-Vgn-Hpd-Reason
Tcn
X-Pad
X-Tid
X-Region-Sid
Who
X-Pf-Uncompressing
Inserted-Into-Cache-At
X-Varnish-Beresp-TTL
Ssr
X-RateLimit-Limit
X-Yottaa-OS
X-HostName
CountryCode
X-Selected-Scheme
Tracecode
X-Selected-Name
X-Selected-Host-Header
X-Snapshot-Date
X-Cache-Spec
Source
D-Cc-Upstream
Lfy
X-Cc-Req-Id
X-Request-URL
X-Cc-Via
X-Men
X-Apw-Hits
X-Scheme
X-Proxy-Cachei7
X-Dw-Trace-Id
X-MiniProfiler-Ids
Vha6-Origin
X-Nananana
Cneonction
X-DevSite-Last-Modified
Mime-Version
X-C
X-Apw-Access-Action
X-Apw-Access-Object
PICS-Label
X-PJAX-URL
X-Magnolia-Registration
Pragrma
X-Apw-Access-Token