Threat Level: green Handler on Duty: Russell Eubanks

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Pragma
Last-Modified
Accept-Ranges
Strict-Transport-Security
X-Content-Type-Options
X-Powered-By
CF-RAY
ETag
Link
Expect-CT
Via
X-XSS-Protection
X-Cache
Age
Access-Control-Allow-Origin
Content-Security-Policy
Content-Language
X-UA-Compatible
P3P
X-Cache-Hits
X-Served-By
X-Varnish
X-Amz-Cf-Id
X-Xss-Protection
Referrer-Policy
X-Request-Id
X-Timer
X-AspNet-Version
CF-Cache-Status
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Runtime
Access-Control-Allow-Credentials
X-Download-Options
X-Drupal-Cache
X-Cacheable
Content-Security-Policy-Report-Only
X-Generator
Alt-Svc
Status
X-AspNetMvc-Version
X-Cache-Status
X-DNS-Prefetch-Control
X-Check
P3p
X-Iinfo
X-Adblock-Key
X-FRAME-OPTIONS
X-CDN
Timing-Allow-Origin
X-Content-Security-Policy
X-Permitted-Cross-Domain-Policies
X-Turbo-Charged-By
Content-Encoding
X-Template
X-Language
Keep-Alive
X-Type
X-AH-Environment
X-Via
X-Cache-Group
X-Backend
X-Request-ID
WPE-Backend
X-Pass-Why
X-Buckets
X-Age
X-Server
X-Nginx-Cache-Status
Access-Control-Max-Age
X-Server-Powered-By
X-Pingback
Xkey
X-Varnish-Cache
Grace
X-Drupal-Dynamic-Cache
Upgrade
Access-Control-Expose-Headers
X-Hacker
X-UA-Device
X-Amz-Request-Id
Cf-Railgun
X-Page-Speed
X-Amz-Id-2
X-Proxy-Cache
X-Robots-Tag
EagleId
X-Envoy-Upstream-Service-Time
Request-Context
X-Node
X-Swift-SaveTime
X-Swift-CacheTime
X-Ac
X-LiteSpeed-Cache
X-Device
Ali-Swift-Global-Savetime
X-Host
X-Cnection
Content-Location
X-Amz-Version-Id
X-WebKit-CSP
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Server-Id
Surrogate-Control
X-Backend-Server
X-OneAgent-JS-Injection
X-Cache-Lookup
X-Rack-Cache
X-Response-Time
X-Px
X-Instart-Request-ID
X-CST
Server-Timing
Request-Id
X-Readtime
X-Rq
X-Url
X-Clacks-Overhead
Pinterest-Generated-By
X-Do-Not-Hack
Permitted-Cross-Domain-Policies
X-HeyJason
EagleEye-TraceId
X-Ua-Compatible
Edge-Control
X-Application-Context
X-Country
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Cloud-Trace-Context
X-MS-InvokeApp
Report-To
X-Server-Name
Charset
X-DynaTrace-JS-Agent
X-ESI
SPRequestGuid
X-Country-Code
Allow
X-DataDome
X-SharePointHealthScore
Rating
X-Varnish-TTL
X-Ruxit-JS-Agent
X-Vname
X-PC
X-TtlSet
X-Cached
X-Powered-CMS
X-Powered-By-Plesk
X-DynaTrace
X-Recruiting
X-CF-Powered-By
X-FTR-Request-ID
X-Vhost
NEL
X-D2id
X-Kinja
X-Kinja-Revision
X-Exp-Id
X-Cdn-Fetch
X-Kinja-Server
X-Exp-Variant
X-Geo-Segment
X-Kinja-Build
Pinterest-Version
Public-Key-Pins
X-Upstream-Env
X-Pinterest-Rid
X-F-Cache
X-Ttl
X-Version
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-T
Cartoon
X-GoogleNews-Bot
X-VARITI-CCR
X-N
X-Dw-Request-Base-Id
SPIisLatency
SPRequestDuration
X-TTL
X-Mod-Pagespeed
X-Abt-Application-Version
RTSS
Content-MD5
Verso
Feature-Policy
MS-Author-Via
Nginx-Cache
X-GitHub-Request-Id
X-Dispatcher
X-Goog-Hash
X-Navigation-Version
X-Client-IP
X-Amz-Rid
X-SRCache-Store-Status
X-SRCache-Fetch-Status
MicrosoftSharePointTeamServices
X-Hits
X-Forwarded-Proto
Realpath
X-Shield-Request-Id
AR-PoweredBy
AR-CACHE
X-Origin-Cache
AR-ATIME
X-Cdn
X-Trace
Paypal-Debug-Id
DynaTrace
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Content-Options
X-Id
X-Grace
X-Content-Digest
X-Zen-Fury
X-Server-ID
X-Kinsta-Cache
TCN
X-B
Arr-Disable-Session-Affinity
Alternate-Protocol
X-Varnish-Age
X-Cache-Key
AR-SID
Fastcgi-Cache
X-Sol
X-Upstream
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
MRF-Tech
Mrf-Cache-Status
X-Acc-Meta-Resource-Type
Access-Control-Request-Method
X-FastCGI-Cache
X-Pad
PB-PID
X-Mobile-Rewrite
PB-RID
X-Middleton-Display
Display
X-Fastly-Request-ID
X-Ser
X-Nf-Srv-Version
X-NF-Request-ID
X-Via-JSL
X-Litespeed-Cache
X-Vcap-Request-Id
X-User-Agent
X-DIS-Request-ID
Response
Pagespeed
X-Middleton-Response
X-Forwarded-For
X-MSEdge-Ref
Eomportal-Instance
Arc-Version
Rt-Fastcgi-Cache
X-Cache-Rule
X-Frontend
X-PressLabs-Stats
Front-End-Https
X-Cache-Hit
X-Logged-In
X-SS-Set-Cookie
X-Goog-Metageneration
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-IPLB-Instance
Server-Name
Host
X-Whom
X-Hostname
Surrogate-Key
S
X-VCache
Tracecode
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Realm
X-FTR-DC
X-FTR-Expires
X-FTR-Balancer
X-FTR-Backend
X-FTR-Cache-Status
X-XRDS-LOCATION
X-Request-Processing-Time
X-Request-Received
Backend-Timing
X-Analytics
X-Debug
Cache-Status
X-HS-Content-Id
X-Magnolia-Registration
X-AOL-HN
X-Instance
X-XRDS-Location
X-Rid
Refresh
X-Contextid
X-Activity-Id
X-HW
X-AppVersion
X-Az
X-B3-Traceid
TP-L2-Cache
FilterID
ServerID
TP-Cache
X-Proxied
X-Srv
Public-Key-Pins-Report-Only
X-Wix-Server-Artifact-Id
Cleartype
HitType
HitInfo
Server-Info
X-UUID
X-WPE-Loopback-Upstream-Addr
X-APP-VERSION
X-FTR-Cache-Host
X-Content-Security-Policy-Report-Only
X-Varnish-Backend
X-Mobile
X-Varnish-Server
X-Origin-Upstream-Status
Liferay-Portal
Service-Worker-Allowed
X-Cache-Control
Accept-Charset
Served-By
AMP-Access-Control-Allow-Source-Origin
X-Revision
X-TT
X-Cache-Server
Source
X-Newrelic-App-Data
X-PC-Hit
X-PC-Key
X-Request-Guid
X-Hail-Hydra
X-Geo-Country
Server-Node
X-Amzn-Trace-Id
X-App-Environment
X-Tumblr-Pixel
X-PC-AppVer
X-Tumblr-Pixel-0
X-Tumblr-User
Host-Header
X-BCube-Filmed-By
Retry-After
X-Framework
MS-CV
X-Device-Type
X-Page-Id
X-PHP-Backend
X-Handled-By
X-Varnish-Hostname
DC
X-B-Cache
X-Cache-Operation
X-Cache-Config
X-Signature
X-FB-Debug
X-Cache-2
X-RateLimit-Remaining
Powered-By-ChinaCache
X-Origin-Server
X-ATG-Version
X-Correlation-Id
S-Cnection
X-Origin
Viewport
Edge-Cache-Tag
X-HS-Cache-Config
X-NewRelic-App-Data
X-NWS-LOG-UUID
X-Debug-Info
X-Cache-Action
X-TT-TIMESTAMP
Fastly-Restarts
X-Ocache
X-PC-Host
X-PC-Date
X-Sucuri-ID
X-B3-Sampled
X-Hyper-Cache
X-WA-Info
X-Cached-By
Actual-Object-TTL
NGB
X-LB-Cache
X-Content-Powered-By
X-Akam-SW-Version
X-Microcachable
X-Drupal-Cache-Tags
X-ADI-VCache
X-Shield-Cache-Expires
X-Accel-Expires
X-CLOUD-TRACE-CONTEXT
X-Generated-By
Upgrade-Insecure-Requests
X-Cache-NE
SRV
AsisCache
Filters
X-Cache-Age
X-App-Server
X-Distil-CS
X-Tumblr-Pixel-1
X-Tumblr-Pixel-2
ServedBy
X-WebKit-CSP-Report-Only
X-FW-Serve
X-FW-Hash
X-FW-Server
X-Locale
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-RTag
X-RequestSource
X-Internal-Host
X-FW-Type
X-FW-Static
X-URL
X-Cluster
Content-Script-Type
X-GeoIP
Content-Style-Type
X-Cacheable-TTL
X-GUploader-UploadID
X-Jobs
X-S
X-Seen-By
X-Wix-Request-Id
X-Node-Name
X-ServedBy
Cache
X-Varnish-Hits
X-Accel-Buffering
X-Amz-Server-Side-Encryption
X-Geo
X-TX-ID
From-Origin
Datacenter
X-UA
X-Varnish-Grace
X-RateLimit-Limit
X-Platform-Server
X-Varnish-Cache-Hits
X-GZip
X-Akamai-Edgescape
X-CDN-Forward
X-Adobe-Loc
X-Adobe-Content
X-Varnish-IP
X-Vg-Webcache
X-Sucuri-Cache
X-Dns-Prefetch-Control
Cache-Tag
X-Real-IP
X-Cache-TTL-Remaining
X-HS-Combine-CSS
X-Edge-Cache-Key
X-Edge-Cache
X-Storage
X-Oneagent-Js-Injection
X-Webkit-Csp
X-Akamai-Transformed
X-Mode
X-Drupal-Cache-Contexts
X-Region
X-Cache-Remote
X-Source
X-Amz-Replication-Status
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-Distributor
X-Proxy
X-RemovedCookies
Meta-Geo
X-Rendered-As
Load-Balancing
X-Detected-As
X-ProcessESI
Machine
X-RN-RSRV
X-Is-Bot
X-Path-Route
X-MP-GENERATED-AT
X-Amz-Apigw-Id
X-Amzn-RequestId
X-NCache
Fastly-SSL
Ohc-File-Size
ServerName
X-FC-Vary-Parameters
X-TWH-CORRELATION-ID
X-Backend-Name
X-ApacheServer
Mn-Server-Ip
X-PERF
X-Webstats-RespID
X-Akamai-Request-ID
GEO-INFO
Cache-Key
X-Kinja-Server-Push
X-BB-IP
X-Time-Microsecs
X-Cluster-Node
X-EIG-Tracking-Id
X-Cache-Var-Map
X-Amz-Meta-Surrogate-Control
Azure-SlotName
Azure-Version
Azure-SiteName
Azure-RegionName
User-Agent
Azure-InstanceId
X-Cache-Var
X-CDN-Cache
X-Human
S-Rt
X-OVcl
X-Varnish-Cacheable
X-Original-Request
X-Pubstack
X-Viewer-Country
X-Upgrade-Enabled
X-OCL
Backend
X-Proto
X-Web-Node
X-OVcl-Cache
X-PCL
Webcakes-App-Version
Webcakes-App-Name
X-Proxy-Build
X-NodeID
Webcakes-Region
X-Access
X-Optimization
X-ProxyCache-Status
X-Hosted-By
TWC-Privacy
X-SplitTest
TWC-Locale-Group
X-Generation-Time
TWC-Device-Class
TWC-Connection-Speed
Selected-FE
TWC-GeoIP-Country
X-Format
X-ServerID
X-LJ-Flow-ID
X-VWS-Id
TWC-GeoIP-LatLong
Access-Control-Allow-Method
X-Site-Version
X-BYPASS-REASON
X-Timing-Wait
X-Birta-Served
X-Birta-Cache-Post
X-Edge-Location
X-Cache-Category-Id
X-Cache-HT
X-CCM-LastModified
X-Routing-Service
X-Debug-Cache
X-Section
X-Port
X-Via-Fastly
X-Origin-Hint
X-IP
X-ProxyCache-Key
Healthy
X-Zipkin-Id
X-Meta-Tbi-Cache-Vertical
X-AWS-Id
X-App-Name
X-Www-Served-By
X-Grey
X-Instance-Name
Now
Cache-Name
X-Dc
LB
L5d-Success-Class
X-Daa-Tunnel
Property-Id
Countrycode
X-Agile-Age
X-Agile
X-Agile-Id
X-Loop
X-JoinUs
X-TNCMS
HostName
DB-Nickname
User-Cache-Control
Fastcgi-Useragent
Country
X-Labrador-Cache-Channel
X-Tb
X-Generated
Payment
X-Xfnlog-Site
X-CCM
Cache-Hits
X-Tumblr-Pixel-3
Ec-Rule-Version
X-Guploader-Uploadid
X-Newrelic-Synthetics
RATING
X-Request-Time
X-Surge-Debug
X-Origin-CC
X-Unique-ID
X-Hit
X-DataStream-Cache-Status
WP-Super-Cache
X-Ezoic-Cdn
X-Cache-Bucket
X-TA-CDN-Provider
X-Time
X-Correlation-ID
X-B3-Spanid
X-Cache-Enabled
X-Real-Ip
X-Render-Type
X-Feature
Origin-Cache-Control
X-Nc
X-Nginx-Cache
Origin-Edge-Control
NODE
X-UA-Device-Type
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
RequestId
X-NU-AKA-ACS-Version
X-L-Path
X-Environment-Context
X-Esi
X-B3-TraceId
X-HS-Hub-Id
X-Be
X-Skip-Cache
X-Content-Type
X-Status
X-NGENIX-Cache
Apicache-Version
X-WR-MODIFICATION
Apicache-Store
Access-Control-Request-Headers
Ws
X-ElasticPress-Search
X-Cache-Backend
X-EdgeConnect-Cache-Status
X-Servedby
Xserver
Warning
X-Vgn-Hpd-Reason
IBM-Web2-Location
X-A-Dcw
Apple-News-Services-Handled
Ajk
Www
AKAMAI
X-A
X-A-Ccd
X-A-Dam
Apple-News-Services-Request-Url
GMS-Ver
Host-ID
MD5-Digest
Memcached
X-A-Dgt
Fly-Request-Id
Fastly-Soc-X-Request-Id
Fly-Cache
Fastcgi-X-Cache-Version
Fastcgi-X-Cache
Cache-Prefix
Apple-News-Services-Host
T-Server
Viewtype
Apple-News-Services-Parsed-Url
Sta2Tusw
Meta-Geo-Continent
Resin-Trace
BehaviorPad-Version
VivaBuild
X-Developer
X-Server-By
X-S-Cookie
X-Server-Time
X-SRCache-Key
X-SVT-ORM-RULES
X-Rojux
X-Rewrite-Enabled
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Public
X-Region-Sid
X-SVT-ORM-VERSION
X-Transaction
X-Via-Edge
X-Via-CDN
X-We-Are-Hiring
X-Wix-Route-ID
Xc-Version
X-VG-WebServer
X-User
X-Trv-Group
X-Twitter-Response-Tags
X-Upstream-CT
X-Upstream-HT
X-Planisys-CDN-Cache
X-PAYTM-SRV-ID
X-Connection-Hash
X-CF-Lambda-Version
X-D
X-Date
X-Destination
X-CF-Lambda-Fn
X-BBXSRF
X-Accel-Expires-Debug
X-Application
X-ARC
X-BB-ID
X-Died
X-Fastly-Cache
X-IN-WAF
X-IN-SSL-APIGATEWAY
X-Logtrace-Id
X-ND-Cache
X-No-Session
X-IN-APIGATEWAY
X-Haproxy-Ip
X-From
X-G
X-Generated-In
X-Haproxy-Hostname
X-A-Wwc
X-B-Cookie
Time
Webserver
X-GoCache-CacheStatus
X-F5-Cache
X-Auto-Login
X-Cdn-Origin
X-Hl-Ver
Origin
X-Rocket-Nginx-Bypass
X-CS
Server-Int
X-ScT
X-Rebelmouse-Cache-Control
IsBot
X-NX-Host
Fastly-SIE
X-Forwarded-Host
Fastly-SWR
X-Cache-Expires
NGX
X-Phone
X-Rebelmouse-Surrogate-Control
UCS
X-Var-Ttl
X-Debug-Log
X-Croise-Owner
X-Debug-Cookies
X-Via-NSCOPI
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-Core-Value
X-Up
Uber-Trace-Id
X-Sn-Servicetimems
Request-Time
Release
Rendered-Blocks
X-Trace-Id
X-SIPLIST1
X-C
X-Webkit-CSP
X-Cache-Host
X-CGP
X-Crawler
X-Clientip
X-Cdn-Srv
X-Cache-Id
X-Backend-State
Who
X-Actual-URL
X-Amz-Meta-Cache-Control
V-Age
Thinkindot-Control
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-Amz-Meta-S3cmd-Attrs
X-Backend-Host
X-Cache-CFC
X-Cache-Control-Set-By
X-Bug-Bounty
X-Bip
X-Backend-TTL
X-Backend-Url
X-Cache-Debug
X-GeoIP-Country-Code
X-Returned-From-PostProcessResponse
X-Server-Group
X-Server-IP
X-Returned-From-DLL
X-Returned-From-BeforeDispatch
X-Reboot
X-Request-URI
X-Returned-From
X-Servername
X-ServiceProvider
X-UnsetCookies
X-V
X-Varnish-HitMiss
X-TT-LOGID
X-Thinkindot-L3
X-Stale
X-Thanos
X-Platform
X-Passed-To-PostProcessResponse
X-CACHE-AGE
X-FireWall-Port
X-Fstrz
X-Eu-Site
X-Epic-Correlation-Id
X-DPWN-IS-SECURE
X-Edge-IP
X-GeoIP-City
X-HCF
X-Passed-To
X-Passed-To-BeforeDispatch
X-Passed-To-DLL
X-Node-Id
X-MI-In-Market
X-TIME
X-Location
X-Developers
X-Matched-Rule
HA-Geocity
HA-Geocountry
MI-Cache-Age
Ohc-Response-Time
HA-Cloudapp
OT-Force-Account-Verify
HTTPS
On-Server
MI-Cache
HA-Geolat
HA-Servedtime
HA-Urlpath
Heartbleed
HA-Ipaddr
HA-Host
HA-Geolon
HA-Georegion
Ha-Gx-Prefs
Backend-Name
GW-Server
Pramga
Powered-By
Cache-Cookie-Set-Lfrom
Proxy-Connection
Decoy-Debug-Key
Decoy-Debug-TTL
Decoy-Debug-Status
Server-Host
Content-Disposition
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-From
Cneonction
X-RCS-CacheZone
Esi-Enabled
Adler-Geo
Country-Code
X-Gen-Mode
X-Cache-Srv
X-Hnp-Log
Httpd-Identifier
X-Content-Age
X-Cache-Ttl
X-Device-Os
X-Ckpd-Fst-Backend
X-Dispatcher-Server
X-MSEdge-Features
CDCHOST
X-WebServer
X-Frame-Option
X-MSEdge-Flight
X-Info
X-VServer
X-Varnish-Id
Fastly-Backend-Name
X-Env
X-Worker
PFcat
X-Ruxit-Js-Agent
X-UE-Client-Country
REQUESTUUID
X-Ver
Pragrma
X-Block-Status
Odigeo-Trace-Id
Web-Mar-Node
X-Response-By
Platform
X-Fetched-On
X-Core-Mission
X-Release
X-Hash
Is-Eu
X-Cache-Time
NnCoection
X-Shopify-Stage
X-Refresh
X-ShopId
X-Cache-URL
X-Served-From
X-Sorting-Hat-Section
Cache-Provider
X-Sorting-Hat-ShopId
X-Sorting-Hat-PrivacyLevel
X-ShardId
X-Sorting-Hat-PodId
X-Sorting-Hat-PodId-Cached
X-Sorting-Hat-ShopId-Cached
X-Sorting-Hat-FeatureSet
X-S-Maxage
Request-Country
Server-ID
Request-EU
MI-API
X-Alternate-Cache-Key
Kp-EeAlive
X-Origin-Expires
X-Origin-Date
Dnion-Transfer-Encoding
X-Pjax-Url
Mime-Version
NtCoent-Length
X-P-T
X-Req
X-Page-Type
X-Svr
X-Fastcgi-Cache
X-Varnish-Beresp-Ttl
Drupal-Pagecache-Memcache
X-Pf-Uncompressing
Processtime
X-Secret
X-Cache-ASPX
X-Gannett-Site-Version
X-StackifyID
X-Origin-TTL
X-EC-Security-Audit
Accept-Ch
X-Amz-Meta-S3b-Last-Modified
X-Oss-Server-Time
Pagetype
X-Oss-Request-Id
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
Version
X-NC
X-Amz-Meta-Sha256
SN
Memory
Ar-Sid
X-Wix-Petri-Ex
X-Csrf-Token
Dont-Set-Cookie
WebServer
GeoIp-Country-Code
Geoip-City
X-Rule
X-App-Version
Geoip-Latitude
X-From-Cache
X-Kong-Upstream-Latency
X-Varnish-Beresp-TTL
X-LiteSpeed-Cache-Control
X-Varnish-Url
X-RateLimit-Remaining-Second
X-Kong-Proxy-Latency
X-CSRF-Token
X-RateLimit-Limit-Second
PICS-Label
Arc-Country
Cteonnt-Length
FSS-Cache
X-Yottaa-Sig
X-Cache-Handler
X-Load-Cache
FSS-Proxy
PageType
CF-IPCountry
X-Irp-Debug
X-Ua
Brightspot-Id
MIME-Version
Cdn
X-LB-Node
X-LB-CacheStatus
X-Request-Start
X-Ratelimit-Remaining
X-ROOTCache
XServer
COMMERCE-SERVER-SOFTWARE
Edgecast
If-Modified-Since
X-Redis-Cache
Sid
X-COUNTRY
X-SERVER-NAME
PROCESSING-IP
BORDER-IP
X-Endurance-Cache-Level
X-Sf
X-GRACE
X-Cdn-Forward
X-Fastly-Backend-Reqs
X-Request-UUID
X-DC
RNT-Machine
RNT-Time
X-Tid
X-Requestid
X-Ratelimit-Limit
X-Servedbyhost
X-ServedByHost
X-Varnish-Action
X-GDPR
X-TId
Amp-Access-Control-Allow-Source-Origin
X-RequestId
X-Layer
Powered
X-Cache-TTL
X-Nananana
X-Resolver-IP
Cache-Tags
X-Rocket-Nginx-Serving-Static
X-B3-SpanId
Frame-Options
X-DataStream-Origin-MEX-Latency
X-BE
X-DataStream-MidMile-RTT
CDN
Cf-Ipcountry
Pics-Label
NodeID
X-Fastly-Cache-Hits
X-Atg-Version
CACHE
X-Gdpr
Hostname
X-Tec-Api-Origin
X-Tec-Api-Root
Node
X-Tec-Api-Version
X-Owner
X-Varnish-URL
X-UPSTREAM-Address
Mail-Subject
X-Key
We-Hiring
PageSpeed
X-HTML-Minification-Powered-By
GeoIP-Latitude
GeoIP-Country-Code
X-Server-W
GeoIP-City
X-Dynatrace-Js-Agent
X-Varnish-Ttl
X-VG-WebCache
X-Shard
X-Alicdn-Da-Ups-Status
X-Use-Magma
X-Dynatrace
X-Aicache-OS
Web-Mar-Region
Lfy
X-Ms-Lease-Status
X-Ms-Request-Id
X-Ms-Version
X-Sentry-ID
X-Ms-Blob-Type
X-GZIP
ProcessTime
WZWS-RAY
X-ABtesting
X-Flog
Accept-CH
X-VG-TLSProxy
Dynatrace
Cdn-Host
X-Powered-By-ANYU
X-PF-Uncompressing
X-GEO
Cdn-Request-Time
URI
True-Client-Country-4JS
X-Front
X-Edge-Server
X-Swa-Ws
Xet-Cookie
DataCenter
X-NGINX-Cache
X-Dw-Trace-Id
Rt-Proxy-Cache
X-Org
GEO-REGION-INFO
Group
X-Policy
X-Ms-Lease-State
X-Oa-Upstreams
Get-Access-Time
X-PJAX-URL
V-Cache
X-CDN-Pop-IP
Max-Age
X-CDN-Pop
Is-Session-Tracking
X-PAGE-TYPE
X-Cookie
X-Check-Cacheable
X-Vcache
X-Unique-Id
X-Trv-Request-Id
X-NWS-UUID-VERIFY
N-Cache
X-Mem
X-M-Reqid
X-M-Log
X-Varnish-Info
X-VC
RequestUuid
X-SB
Requestid
X-Varnish-ID
X-Qnm-Cache
X-VID
X-Amzn-Remapped-Date
X-Cache-FS-Status
X-Amzn-Remapped-Connection
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-RSL
X-DI
WS
X-Fe
X-Remote-IP
X-Hello
X-RAMCache
SID
X-Litespeed-Tag
CF-Cached-On
X-Litespeed-Cache-Control
X-Akamai-ERRuleID
X-DW
X-Proxy-Server
X-RPM
X-DSS
X-Powered-By-Defense
X-Akamai-ERPolicy
X-DB
X-RPS