Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
CF-RAY
CF-Cache-Status
Link
X-Powered-By
ETag
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Alt-Svc
Access-Control-Allow-Credentials
X-Xss-Protection
X-Runtime
X-FRAME-OPTIONS
X-Drupal-Cache
X-Adblock-Key
X-Check
Content-Security-Policy-Report-Only
X-Generator
X-Cacheable
X-Cache-Status
X-Permitted-Cross-Domain-Policies
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Template
X-Language
X-Iinfo
X-Content-Security-Policy
Status
Content-Encoding
X-AspNetMvc-Version
X-Request-ID
X-Buckets
X-Kinja-Server-Push
Upgrade
Xkey
X-Via
Access-Control-Expose-Headers
X-Turbo-Charged-By
Access-Control-Max-Age
Keep-Alive
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Pass-Why
EagleId
X-Age
X-Backend
X-Envoy-Upstream-Service-Time
X-Robots-Tag
X-Amz-Request-Id
X-Amz-Id-2
X-Page-Speed
X-Pingback
X-Server-Powered-By
X-Server
X-AH-Environment
X-UA-Device
X-Proxy-Cache
X-Hacker
X-CDN
Request-Context
X-Swift-SaveTime
X-Swift-CacheTime
X-Nginx-Cache-Status
Grace
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-Cdn
P3p
Cf-Railgun
X-LiteSpeed-Cache
Server-Timing
X-Ua-Compatible
Feature-Policy
X-Amz-Version-Id
X-Device
X-Server-Id
X-WebKit-CSP
X-OneAgent-JS-Injection
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Rq
X-Ac
EagleEye-TraceId
X-Cnection
Report-To
X-Cloud-Trace-Context
Request-Id
X-Backend-Server
X-Response-Time
X-Node
Content-Location
X-Host
X-Readtime
X-Origin-Cache
X-Vhost
X-Cache-Lookup
X-Application-Context
X-DataDome
X-ORACLE-DMS-ECID
X-Dispatcher
X-Ruxit-JS-Agent
NEL
X-ORACLE-DMS-RID
X-Rack-Cache
X-Origin-Upstream-Status
X-HW
Surrogate-Control
X-Dns-Prefetch-Control
X-Clacks-Overhead
Rating
X-Country-Code
Allow
X-Country
X-Url
X-EdgeConnect-MidMile-RTT
X-FTR-Request-ID
X-EdgeConnect-Origin-MEX-Latency
X-DynaTrace
X-MS-InvokeApp
X-Goog-Hash
X-Instart-Request-ID
Fusion-Component-Id
Fusion-Template-Id
Fusion-Source
Fusion-Content-Id
Fusion-Content-Source
X-TTL
X-TtlSet
X-PC
X-Vname
X-Varnish-TTL
X-B3-TraceId
Pinterest-Generated-By
Verso
X-Powered-By-Plesk
X-Px
Public-Key-Pins
RTSS
Edge-Control
X-Mod-Pagespeed
X-ESI
SPRequestGuid
X-Ah-Environment
Display
X-Middleton-Response
Response
X-Middleton-Display
X-Sol
X-VARITI-CCR
X-SharePointHealthScore
X-Akam-SW-Version
X-Kinja
X-Kinja-Server
X-Kinja-Build
X-Kinja-Revision
X-Use-Magma
X-D2id
X-Exp-Id
X-Cdn-Fetch
X-Exp-Variant
X-GoogleNews-Bot
Accept-Ch-Lifetime
X-Recruiting
Service-Worker-Allowed
SPIisLatency
SPRequestDuration
X-Vcap-Request-Id
X-CST
X-Server-Name
X-Version
X-GitHub-Request-Id
X-Powered-CMS
MS-Author-Via
X-Navigation-Version
TCN
X-Abt-Application-Version
X-Trace
Charset
X-Debug
X-Amz-Server-Side-Encryption
X-Shard
Fastly-Restarts
X-Amz-Rid
X-Aspnetmvc-Version
Nginx-Cache
Realpath
X-Upstream
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
AR-PoweredBy
AR-CACHE
Ar-Sid
Accept-CH
AR-ATIME
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-NF-Request-ID
X-RateLimit-Remaining
X-Forwarded-Proto
X-Ezoic-Cdn
Front-End-Https
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Goog-Generation
X-MSEdge-Ref
Access-Control-Request-Method
DynaTrace
X-Cached
Arr-Disable-Session-Affinity
Content-MD5
Pagespeed
X-Shield-Request-Id
AR-Request-ID
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
MicrosoftSharePointTeamServices
X-FTR-Cache-Status
X-FTR-Expires
X-Country-Code-Real
X-XRDS-Location
X-Amz-Meta-S3cmd-Attrs
S
X-Goog-Storage-Class
X-Ser
X-VCache
X-Fastly-Request-ID
X-T
X-Id
X-FTR-Backend-Server
X-FTR-DC
X-FTR-Realm
X-FTR-Balancer
X-FTR-Backend
Paypal-Debug-Id
X-Varnish-Age
X-DynaTrace-JS-Agent
Accept-Ch
ServerID
X-Via-JSL
X-Fastcgi-Cache
X-Grace
X-Accel-Expires
X-Correlation-Id
X-Content-Type
X-Client-IP
Edge-Cache-Tag
X-Dw-Request-Base-Id
X-Forwarded-For
Fastcgi-Cache
X-Amzn-Trace-Id
X-Hits
X-Frontend
X-Content-Digest
X-Vcache
X-DIS-Request-ID
Powered
X-N
AMP-Access-Control-Allow-Source-Origin
Pinterest-Version
X-Pinterest-Rid
X-HS-Hub-Id
X-HS-Content-Id
PB-RID
X-Mobile-Rewrite
PB-PID
Arc-Version
X-FTR-Cache-Host
X-Logged-In
Server-Name
X-Server-ID
TP-Cache
TP-L2-Cache
X-Request-Received
X-Cache-Hit
X-Request-Processing-Time
X-Kinsta-Cache
X-Microsite
X-Request-Handler-Origin-Region
X-Zen-Fury
X-Activity-Id
X-AppVersion
X-Time
X-Az
X-Rid
X-LB-Cache
X-GUploader-UploadID
X-User-Agent
X-IPLB-Instance
X-Revision
X-Cache-Age
X-Type
Healthy
Retry-After
X-Whom
Backend-Timing
X-Analytics
X-Node-Name
X-FastCGI-Cache
Server-Node
X-B3-Sampled
FilterID
X-RateLimit-Limit
X-NWS-LOG-UUID
X-Srv
X-Hp-Webp
Cache-Tag
Alternate-Protocol
X-F-Cache
Accept-Charset
X-SERVER
NR-ENABLED
X-Akamai-Edgescape
X-Content-Security-Policy-Report-Only
X-Erf-Bev-Bev
X-Webkit-CSP
X-Erf-Bev-Bev-Is-Generated
X-Content-Options
X-Cache-Rule
Cache-Status
MS-CV
DC
VIX-Pulpo-Node
X-Amz-Apigw-Id
X-Content-Powered-By
X-Amzn-RequestId
VIX-Pulpo-Upstream-Status
X-AOL-HN
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-User
X-Instance
X-Framework
X-Cluster
X-FB-Debug
Access-Control-Allow-Method
Refresh
Tracecode
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Source
X-App-Environment
X-Varnish-Grace
X-Jobs
X-Cache-2
X-Debug-Info
X-B
X-PHP-Backend
X-Page-Id
X-Forwarded-Host
Actual-Object-TTL
X-Seen-By
X-Cache-TTL
X-Request-Guid
X-Mobile-URL
Surrogate-Key
X-Cache-Operation
X-App-Server
Host
Frame-Options
X-Geo-Country
Fastcgi-Useragent
X-FW-Static
X-Cache-Control
X-FW-Type
X-FW-Server
X-FW-Serve
X-FW-Hash
X-TA-CDN-Provider
X-Cached-By
X-Pad
X-Host-Name
X-Hostname
Cleartype
X-Element-Page-Cache
X-Cache-Key
X-Signature
X-B-Cache
Upgrade-Insecure-Requests
X-Git-Hash
X-WebKit-CSP-Report-Only
X-Mobile
X-ATG-Version
X-BCube-Filmed-By
X-Response-Served-From
X-Varnish-Backend
X-HS-Cache-Config
NGB
Xserver
X-UA-Device-Type
WPE-Backend
Ms-Operation-Id
X-RTag
X-RemovedCookies
X-GeoIP
X-ProcessESI
Eomportal-Instance
Cache-Tv-Group
X-Amz-Replication-Status
Filters
X-Tumblr-Pixel-2
X-EdgeConnect-Cache-Status
X-Daa-Tunnel
X-Origin-Server
X-Handled-By
X-TT
X-Tumblr-Pixel-1
Webserver
X-TX-ID
X-Litespeed-Cache
From-Origin
X-Adobe-Content
X-Cacheable-TTL
X-Drupal-Cache-Tags
GEO-INFO
X-Adobe-Loc
X-RequestSource
Payment
X-Presslabs-Stats
X-TT-TIMESTAMP
X-Cache-TTL-Remaining
Cache
X-Wix-Request-Id
X-XRDS-LOCATION
X-Cache-Remote
X-Status
Datacenter
X-Esi
Liferay-Portal
X-FW-Dynamic
X-WA-Info
X-Hyper-Cache
X-Region
X-Contextid
Version
X-Ratelimit-Reset
X-Cache-Action
X-Edge-Location
X-Ttl
X-Acc-Meta-Resource-Type
Viewport
X-Content-Age
X-CF-Powered-By
X-Cache-NE
X-B3-Traceid
X-HS-Combine-CSS
X-Akamai-Transformed
PageSpeed
X-Storage
X-Varnish-Hostname
X-Cache-Server
Accept-CH-Lifetime
X-Varnish-Server
Load-Balancing
X-Cache-Var-Map
X-RN-RSRV
X-ES-SERVER
Meta-Geo
X-Cache-Var
X-Path-Route
X-Viewer-Country
X-Cache-Grace
Host-Header
X-IP
X-Cache-Enabled
Country
X-Cache-Config
X-Xfnlog-Site
Cache-Tags
X-PressLabs-Stats
X-Proxy
Ohc-File-Size
X-Via-Fastly
X-Accel-Buffering
X-CCM
Cache-Hits
X-Yottaa-Metrics
X-Labrador-Cache-Channel
X-OCL
X-NCache
Cache-Name
X-Yottaa-Optimizations
X-TNCMS
DB-Nickname
X-Device-Type
X-Loop
X-Tumblr-Pixel-3
Release
X-UnsetCookies
X-Proto
X-Cache-Host
X-PCL
X-Akamai-Request-ID2
X-Debug-Cache
Vix-Hermes-Req-Id
X-Cache-Time
Rt-Fastcgi-Cache
X-Human
X-JoinUs
Ec-Rule-Version
X-Hosted-By
X-Goog-Meta-Goog-Reserved-File-Mtime
S-Rt
Property-Id
DSUID
Decoy-Debug-TTL
X-R9-Blue-Green-Version
X-Rule
X-Origin-Hint
X-Origin
Decoy-Debug-Status
Decoy-Debug-Key
Selected-Fe
TWC-Connection-Speed
X-FC-Vary-Parameters
Webcakes-Region
X-EIG-Tracking-Id
X-Backend-Name
X-CS
X-Backend-TTL
Webcakes-App-Version
Webcakes-App-Name
TWC-GeoIP-Country
TWC-Device-Class
TWC-GeoIP-LatLong
TWC-Locale-Group
X-From
TWC-Privacy
X-Time-Microsecs
X-Proxy-Build
X-Varnish-Cache-Hits
X-Upgrade-Enabled
X-Timing-Wait
X-Varnish-Hits
S-Cnection
X-Www-Served-By
X-Web-Node
X-Vgn-Hpd-Reason
X-Trace-Id
X-NewRelic-App-Data
X-Site-Version
X-ApacheServer
X-Origin-Response-Time
X-Locale
X-Generated
X-VCT
Mn-Server-Ip
X-FireWall-Port
X-PERF
Cache-Key
Azure-SiteName
Azure-RegionName
Azure-InstanceId
Azure-SlotName
Azure-Version
X-Cluster-Node
X-Drupal-Cache-Contexts
X-Akamai-Request-ID
X-OVcl-Cache
X-Ua
X-Real-IP
X-Pubstack
X-OVcl
X-Access
X-Hit
X-Section
Origin-Edge-Control
Origin-Cache-Control
X-Format
X-Rendered-As
X-S
Time
X-Trafficlayer-App-Name
X-Trafficlayer-App-Scope
Ohc-Cache-HIT
Server-Info
L5d-Success-Class
X-Redis-Cache
X-NGENIX-Cache
X-Origin-CC
X-FW-Version
Now
X-Origin-TTL
Fastcgi-X-Cache-Version
Fastly-SSL
X-SS-Set-Cookie
OT-Force-Account-Verify
ServedBy
X-Upstream-CT
X-Cluster-Name
Origin
Hostname
X-ServerID
X-Upstream-HT
Cteonnt-Length
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-ShardId
X-ShopId
X-Shopify-Stage
X-Load-Cache
X-App-Version
X-Alternate-Cache-Key
X-APP-VERSION
X-UUID
Access-Control-Request-Headers
Mime-Version
X-FB-TRIP-ID
X-Soup
X-GoCache-CacheStatus
X-Webkit-Csp
X-Rocket-Nginx-Bypass
X-CACHE-KEY
X-Parent-Response-Time
X-VG-WebCache
Accept-Language
NGX
X-Is-Bot
NtCoent-Length
X-VG-TLSProxy
Machine
Odigeo-Trace-Id
X-Uri
Nel
X-Info
X-Upstream-Proxy
X-B3-SpanId
IBM-Web2-Location
X-Guploader-Uploadid
X-CSRF-TOKEN
X-Geo
X-ProxyCache-Key
X-ECACHE
X-MServer
X-No-Session
X-Tb
X-Environment-Context
X-BYPASS-REASON
X-ProxyCache-Status
X-L-Path
X-Node-Id
Srv
X-Tt-Trace-Tag
X-UA
X-Nc
X-Oneagent-Js-Injection
X-PHP-Host
A
X-Cms-Context
X-Request-UUID
Uber-Trace-Id
X-Connection-Hash
X-Twitter-Response-Tags
X-CF-Lambda-Version
X-Trv-Group
X-Transaction
X-SRCache-Key
X-D
X-CF-Lambda-Fn
Arc-Country
VivaBuild
Viewtype
X-S-Cookie
MD5-Digest
X-Server-Time
X-A
X-A-Dcw
X-A-Dam
X-A-Ccd
Memcached
Meta-Geo-Continent
Rendered-Blocks
Request-Country
Request-EU
Rt-Proxy-Cache
ServerName
T-Server
Mobile-Detection-Method
Node
X-ScT
X-A-Dgt
X-A-Wwc
Cache-Prefix
X-B-Cookie
X-ARC
Content-Script-Type
BehaviorPad-Version
AsisCache
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Content-Style-Type
X-Application
X-Accel-Expires-Debug
Fly-Cache
Fly-Request-Id
GEO-REGION-INFO
X-Aed
X-Rojux
X-Rewrite-Enabled
Cross-Origin-Window-Policy
X-AIR-PT
Apple-News-Services-Handled
X-Date
X-Developer
X-External-Request-Id
X-Detected-As
X-PAYTM-SRV-ID
X-G
X-Tec-Api-Version
X-Vtex-Remote-Cache
X-VG-WebServer
X-DPWN-IS-SECURE
X-Hl-Ver
X-Instart-Info
X-Vtex-Processado-Em
X-Destination
X-Region-Sid
X-Tec-Api-Origin
Request-Time
X-Tec-Api-Root
Proxy-Connection
Xc-Version
CF-IPCountry
X-B3-Parentspanid
Backend-Name
X-Endurance-Cache-Level
User-Cache-Control
X-ElasticPress-Search
X-Request-URI
X-Sn-Servicetimems
X-SVT-ORM-RULES
X-Generated-By
X-Amzn-Remapped-Content-Length
X-Cache-Info
X-Proxy-Cache-Status
IsBot
X-SIPLIST1
X-Debug-Log
X-Block-Status
X-Hnp-Log
X-Worker
X-Cache-Bucket
X-JWT-State
X-Is-Gdpr
X-WADP-Cache
X-NX-Host
X-Gen-Mode
X-S-Maxage
X-Debug-Cookies
X-Proxy-Upstream
X-Device-Os
N-Cache
X-Cdn-Origin
X-Clara-WADP
X-SVT-ORM-VERSION
X-Cdn-Srv
X-Has-Esi
X-Nginx-Cache
Mail-Subject
X-Via-CDN
We-Hiring
X-Cdn-Forward
Server-Host
Server-Int
X-GeoIP-City
X-Generated-In
Served-By
X-Generated-On
RNT-Time
X-Fetched-On
X-Geo-Header
Section-Io-Cache
Thinkindot-CacheControl
X-Release
Web-Mar-Node
True-Client-Country-4JS
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-Request-Start
Thinkindot-Control
Thinkindot-CacheControl-Type
X-Irp-Debug
X-Hash
X-Reqid
X-Bip
X-Origin-Expires
X-Owner
X-Platform-Server
X-Developers
X-Origin-Date
X-Dispatch
X-Old-Content-Length
X-RateLimit-Limit-Second
X-Clientip
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
X-Policy
X-Debug-Cache-Store
X-Generation-Time
X-Compress-Hint
X-CUA
X-Matched-Rule
X-Dispatcher-Server
X-Backend-Url
X-Li-Fabric
X-BBXSRF
X-Backend-Host
X-Auto-Login
X-Amz-Meta-Cache-Control
X-Level-Front-Cache
X-Distributor
X-Li-Pop
X-Location
X-Reboot
X-Magnolia-Registration
X-Cache-Id
X-LI-UUID
RNT-Machine
X-Cache-FS-Status
X-Fastly-Cache
X-TrackingId
CDCHOST
X-WebServer
X-We-Are-Hiring
AKAMAI
Adler-Geo
X-Webstats-RespID
X-NC
X-Service
Fastly-Soc-X-Request-Id
X-Skip-Cache
Countrycode
X-VServer
X-Swa-Ws
X-User
X-Var-Ttl
X-Variation
X-VC-Cache
X-Urbn-Site-Id
X-Urbn-Context-Path
X-Thanos
X-Thinkindot-L3
X-RateLimit-Remaining-Second
X-Up
Gh-Request-Id
Content-Disposition
X-SayCDN-TTL
Kp-EeAlive
Platform
PFcat
X-Svr
Locale
Pagetype
X-Server-IP
Heartbleed
Is-Eu
X-Say-TTL
Pramga
X-Say-Cacheable
Resin-Trace
X-Nginx-Cache-Key
X-Cache-URL
Magicmarker
X-Instart-Isnd
X-SD-PageType
SD-X-WS
X-Distil-CS
X-Method
X-NWS-UUID-VERIFY
X-Epic-Correlation-Id
X-B3-Spanid
X-Rebelmouse-Surrogate-Control
X-CGP
X-Core-Mission
Akamai-GRN
X-Key
Wxu-Next-Region
Ha-Gx-Prefs
Esi-Enabled
Fastly-SIE
X-Wikidot-Static-Cache
X-ServiceProvider
Wxu-Next-Hostname
X-Lb-Id
Fastly-SWR
X-Wikidot-Backend
X-Qloud-Router
HA-Ipaddr
X-Rebelmouse-Cache-Control
X-Eu-Site
X-C
X-LI-Proto
L
V-Age
X-Azure-Ref
X-Azure-Ref-OriginShield
Wxu-Next-Commit
X-Microcachable
X-Dc
SRV
X-Scheme
X-MSEdge-Features
X-MSEdge-Flight
X-Internal-Host
X-Cache-Backend
Memory
Cache-Provider
Server-ID
X-Backend-State
X-App-Name
X-Servername
W
X-Processor
X-FPC
X-DC
X-Ratelimit-Limit
X-Be
REQUESTUUID
Cdn-Request-Time
X-GEO
Cdn-Host
X-Edge-Server
X-AWS-Id
X-VWS-Id
Group
X-LJ-Flow-ID
X-GDPR
X-NodeID
X-Pjax-Url
X-Servedbyhost
Cache-Host
X-Wa
X-Hello
X-Org
X-Flog
X-Mode
X-ABtesting
X-Datadome
X-Request-Time
X-Server-W
SS
X-SRV
X-Ms-Request-Id
X-Ms-Version
X-Response-By
X-CDN-Forward
X-IPS-LoggedIn
X-Oss-Request-Id
X-VCL-Version
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Varnish-Beresp-Grace
X-SN
X-Oss-Server-Time
X-Oss-Storage-Class
X-Varnish-Beresp-Ttl
X-Unique-ID
X-Page-Type
X-Varnish-Beresp-Status
Country-Code
X-Webapp-Samesite-None-Activated-N
X-Ruxit-Js-Agent
X-Ratelimit-Remaining
X-Session-Fingerprint
Lfy
X-Via-Ucdn
Cache-Cookie-Set-From
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
X-Oracle-Dms-Rid
X-EC-Lua
X-Cache-Debug
X-Ftr-Request-Id
X-Zone
X-Dynatrace
Ttl
X-Tb-Optimization-Total-Bytes-Saved
X-Agile-Age
X-Agile-Id
X-Agile
X-HS-Status
UCS
X-URL
X-Routing-Service
PICS-Label
X-Zipkin-Id
X-Proxied
X-COUNTRY
X-GRACE
SN
Powered-By-ChinaCache
X-7Graus-Varnish-XKeys
X-7Graus-Varnish-Cache-Control
GeoIp-Country-Code
GeoIP-Latitude
GeoIP-City
X-PF-Uncompressing
X-Fastly-Country-Code
Environment
Ajk
GeoIP-Country-Code
Geoip-City
Geoip-Latitude
X-Pf-Uncompressing
X-Sedo-Request-Id
X-Logtrace-Id
X-Logging-Id
X-Cache-Miss-From
Proxy-Firewall
X-Unique-Id
X-Dynatrace-Js-Agent
X-Source
X-Sucuri-Id
X-Varnish-Beresp-TTL
X-CSRF-Token
X-ZONE
X-Newrelic-Synthetics
X-MP-GENERATED-AT
X-Sucuri-ID
XServer
X-Grey
X-APP
Cdn
ProcessTime
Powered-By
X-Ftr-Cache-Host
X-Cache-Category-Id
X-CLOUD-TRACE-CONTEXT
X-Bc
X-RateLimit-Reset
X-Core-Value
M-TraceId
Pics-Label
X-HTML-Minification-Powered-By
X-Tt-Trace-Host
X-LiteSpeed-Cache-Control
X-Vcl-Version
X-Aicache-OS
X-TH-Server
X-Vdms-Version
X-Check-Cacheable
CF-Cached-On
Fastly-Backend-Name
X-Edge
Cdnsip
WWW
Cdncip
X-AK-Request-ID
X-Sucuri-Cache
X-DataStream-Cache-Status
Cf-Ipcountry
X-Ftr-Dc
X-Ftr-Realm
X-Ftr-Balancer
X-Ftr-Backend-Server
X-Ftr-Backend
X-Planisys-CDN-Rules
X-Mid
X-Rocket-Build-Number
X-Shopify-Generated-Cart-Token
X-Planisys-CDN-TTL
Requestid
Pragrma
X-Planisys-CDN-Cache
X-Sigma
X-Sigma-Backend
X-Fstrz
CACHE
MIME-Version
HostName
X-ServedByHost
X-MCACHE
GW-Server
X-FORWARDED-FOR
X-Fastly-Backend-Reqs
X-Via-NSCOPI
X-Varnish-Ttl
X-Swift-Error
X-RCS-CacheZone
X-LAGOON
X-Cache-Tag
Amp-Access-Control-Allow-Source-Origin
X-TT-LOGID
X-UPSTREAM-Address
X-Secret
X-BC
X-NGINX-Cache
LB
X-WA
X-SaId
X-ORACLE-APMCS-REQUEST-ID
X-ORACLE-APMCS-TAG
X-Gannett-Site-Version
Lb
X-DI
X-DSS
X-DB
X-RPM
X-Action
X-PJAX-URL
X-Varnish-Url
TTL
X-ND-Cache
X-BE
URI
X-RSL
X-Litespeed-Cache-Control
X-RPS
X-DW
Ohc-Response-Time
X-DataStream-MidMile-RTT
X-DataStream-Origin-MEX-Latency
X-Cache-Ttl
X-Upstream-Ct
X-Upstream-Ht
Dynatrace
X-Varnish-Cacheable
Host-ID
X-Trafficlayer-App-Version
X-CDN-Cache
RequestUuid
X-Refresh
On-Server
DataCenter
X-Correlation-ID
Xkeyrz
X-Served-From
Is-Session-Tracking
CDN
Xkeypdq
User-Agent
X-Fpc
X-Fastly-Cache-Hits
Server-Id
X-WR-MODIFICATION
X-Flow-Id
Get-Access-Time
X-Via-SSL
X-Zalando-Child-Request-Id
X-Via-Edge
X-Page-Impression-Id
X-GeoIP-Country-Code
X-Proxy-Cacherz
WZWS-RAY
X-Nananana
X-Req
Warning
X-Pod
X-Dw-Trace-Id
Inserted-Into-Cache-At
X-Gamma-Serve
Locid
X-SB
X-MID
Gannett-Cam-Experience-Id
X-VC
Correlation-Id
X-Cf-Powered-By
X-Gdpr
X-Newrelic-App-Data
Xet-Cookie
RequestId
Thinkindot-Cache-Type
V-Cache
FNAC-ModuleRouting
X-ECache
X-Bug-Bounty
X-Li-Proto
X-LB-ID
Processtime
HitType
X-ServerName
X-Gen-Id
X-LiteSpeed-Tag
X-MiniProfiler-Ids
X-Akamai-ERPolicy
X-Amzn-Remapped-Date
X-Amzn-Remapped-Connection
X-Akamai-ERRuleID
Cneonction