Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Accept-Ranges
Cf-Request-Id
CF-Cache-Status
Pragma
X-Powered-By
ETag
Link
Expect-CT
X-XSS-Protection
Via
Age
CF-RAY
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-UA-Compatible
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
Alt-Svc
X-Served-By
CF-Ray
X-Xss-Protection
X-Timer
X-Varnish
X-Download-Options
Access-Control-Allow-Methods
Access-Control-Allow-Headers
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Permitted-Cross-Domain-Policies
X-Cache-Status
X-Generator
X-Request-ID
X-Cacheable
P3p
X-Kinja-Server-Push
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-Content-Security-Policy
Status
X-AspNetMvc-Version
Upgrade
Content-Encoding
X-CDN
X-Template
X-Language
X-Drupal-Dynamic-Cache
Access-Control-Max-Age
Access-Control-Expose-Headers
X-Envoy-Upstream-Service-Time
Keep-Alive
X-Via
X-Ws-Request-Id
Feature-Policy
X-Age
X-Backend
X-AH-Environment
X-Hacker
X-Buckets
X-Cache-Group
X-Robots-Tag
X-Server
X-UA-Device
X-Amz-Request-Id
EagleId
X-Amz-Id-2
X-Proxy-Cache
X-Turbo-Charged-By
X-Server-Powered-By
X-Dns-Prefetch-Control
Request-Context
Server-Timing
Host-Header
X-Nginx-Cache-Status
Grace
Xkey
Report-To
X-Page-Speed
X-Rq
X-OneAgent-JS-Injection
X-Pingback
Cf-Bgj
X-Varnish-Cache
X-LiteSpeed-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Cf-Railgun
Ali-Swift-Global-Savetime
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Amz-Version-Id
NEL
X-Vhost
X-Host
X-WebKit-CSP
X-Dispatcher
X-Device
X-Backend-Server
X-Node
Surrogate-Control
X-Ruxit-JS-Agent
X-Cache-Lookup
X-Response-Time
X-Origin-Cache
Content-Location
X-Akam-SW-Version
Request-Id
X-Ac
X-ASPNET-VERSION
X-Server-Id
X-Country
X-Mod-Pagespeed
EagleEye-TraceId
X-HW
Rating
X-Readtime
Accept-CH
Accept-CH-Lifetime
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Cloud-Trace-Context
Pinterest-Generated-By
X-Application-Context
X-DataDome
Edge-Control
X-Country-Code
X-Url
X-Origin-Upstream-Status
X-PC
X-Vname
X-TtlSet
X-Varnish-TTL
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Fusion-Content-Source
Fusion-Source
Fusion-Component-Id
Fusion-Template-Id
Fusion-Deployment-Id
Fusion-Content-Id
X-Cnection
X-D2id
Akamai-Age-Ms
X-ESI
X-GitHub-Request-Id
X-MS-InvokeApp
X-Content-Type
X-Clacks-Overhead
X-Server-Name
Allow
X-Abt-Application-Version
X-Navigation-Version
X-FTR-Request-ID
X-Pinterest-Rid
Pinterest-Version
X-Vcap-Request-Id
X-Trace
Verso
X-Sol
X-Middleton-Response
X-Middleton-Display
Response
Pagespeed
Display
X-B3-TraceId
X-Px
X-Server-ID
X-DynaTrace
X-Cached
X-Element-Page-Cache
X-Rack-Cache
Accept-Ch
X-Fastly-Request-ID
X-Webkit-CSP
Service-Worker-Allowed
X-Client-IP
X-Cache-TTL
MS-Author-Via
Arr-Disable-Session-Affinity
X-Powered-By-Plesk
X-Upstream
X-Version
Accept-Ch-Lifetime
Content-MD5
X-T
X-Forwarded-Proto
X-Dw-Request-Base-Id
X-TTL
X-NF-Request-ID
AR-CACHE
Ar-Sid
AR-ATIME
AR-PoweredBy
AR-Request-ID
X-SharePointHealthScore
SPRequestGuid
X-Debug
Fastly-Restarts
X-VARITI-CCR
X-Jurisdiction
X-Exp-Variant
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Cdn-Fetch
X-Kinja
X-Exp-Id
X-GoogleNews-Bot
X-Kinja-Build
TP-Cache
TP-L2-Cache
Access-Control-Request-Method
X-XRDS-Location
X-Powered-CMS
X-Content-Digest
X-Release
X-Goog-Hash
X-Edge
X-NWS-LOG-UUID
X-MSEdge-Ref
X-Ttl
TCN
S
SPRequestDuration
SPIisLatency
X-PressLabs-Stats
RTSS
Cache-Tag
Fastcgi-Cache
X-Request-Received
X-Request-Processing-Time
X-FastCGI-Cache
X-Amz-Rid
X-Pinterest-Direct
X-Yandex-Sdch-Disable
Public-Key-Pins
X-Ezoic-Cdn
Server-Node
X-Mid
X-MCACHE
X-Cache-Key
X-Node-Name
X-Accel-Expires
X-Ratelimit-Remaining
X-CST
X-Logged-In
X-Cache-Hit
X-Amzn-Trace-Id
Front-End-Https
ServerID
X-Microsite
X-Request-Handler-Origin-Region
X-Ser
Alternate-Protocol
X-Recruiting
X-Page-Id
X-Origin-Server
X-Kinsta-Cache
X-B
Host
X-Ratelimit-Limit
Accept-Charset
X-Hostname
X-Mobile-URL
X-FTR-Backend-Server
X-FTR-DC
X-FTR-Cache-Status
X-FTR-Backend
X-FTR-Expires
X-FTR-Realm
X-Country-Code-Real
X-FTR-Balancer
X-ECACHE
X-Varnish-Age
X-FireWall-Port
Nginx-Cache
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Seen-By
X-Forwarded-For
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
X-DIS-Request-ID
X-Content-Security-Policy-Report-Only
X-Id
Filterid
X-Load-Cache
Realpath
X-Jobs
X-Content-Options
X-Shield-Request-Id
X-Daa-Tunnel
X-Type
X-Varnish-Backend
X-LB-Cache
X-F-Cache
X-Git-Hash
X-N
X-Request-Guid
X-Activity-Id
X-AppVersion
X-Az
X-Varnish-Grace
X-Rid
X-App-Environment
Paypal-Debug-Id
Edge-Cache-Tag
X-Correlation-ID
X-Zen-Fury
Fastcgi-Useragent
X-Hits
X-Grace
X-Proxy
X-FB-Debug
X-Mg-S
DynaTrace
Access-Control-Allow-Method
X-App-Server
Cache-Tags
X-Upgrade-Enabled
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Content-Powered-By
Content-Disposition
DC
X-Amz-Server-Side-Encryption
X-HP-Webp
X-Kong-Proxy-Latency
X-Cache-Operation
X-Kong-Upstream-Latency
X-Cache-Rule
AMP-Access-Control-Allow-Source-Origin
MicrosoftSharePointTeamServices
X-Akamai-Edgescape
X-Geo-Country
Cleartype
X-WebKit-CSP-Report-Only
X-Wix-Request-Id
X-Fastcgi-Cache
X-Endurance-Cache-Level
X-VCache
X-Cached-By
X-Original-Request-Id
X-Response-Served-From
X-Accel-Buffering
X-Host-Name
X-IPLB-Instance
X-B3-Sampled
X-Ua
NGB
Refresh
X-Distributor
Healthy
Payment
X-HTML-Minification-Powered-By
X-User-Agent
X-Cacheable-TTL
X-AOL-HN
X-UUID
X-Region
X-B-Cache
X-Is-Bot
X-FW-Server
MS-CV
X-FW-Serve
X-FW-Dynamic
X-Signature
X-FW-Static
X-FW-Type
X-FW-Hash
X-Rendered-As
X-Cache-Time
Datacenter
X-HS-Cache-Config
X-Amz-Apigw-Id
X-HS-Hub-Id
X-Amzn-RequestId
X-HS-Content-Id
X-HS-Combine-CSS
X-Instance
X-Rule
X-Whom
X-Tumblr-Pixel-1
Countrycode
X-Tumblr-Pixel-2
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-User
X-Amz-Meta-S3cmd-Attrs
X-Goog-Storage-Class
X-Goog-Metageneration
X-Goog-Generation
X-Debug-Info
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Hp-Webp
PB-PID
X-App-Version
Powered-By-ChinaCache
PB-RID
Arc-Version
X-Mobile
X-Frontend
X-Varnish-Server
X-XRDS-LOCATION
Powered
X-Backend-Name
X-PHP-Backend
Surrogate-Key
S-Cnection
X-NewRelic-App-Data
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
X-Respond-Thread
X-Oneagent-Js-Injection
X-Cache-Server
X-Protected-By
Cache
X-Azure-Ref
X-Via-JSL
X-DynaTrace-JS-Agent
Liferay-Portal
X-Cache-Age
X-WA-Info
X-Hyper-Cache
X-Time
X-Cache-Expired-At
X-Litespeed-Cache
Viewport
X-Proxy-Cache-Status
X-FTR-Cache-Host
Referer-Policy
X-Cache-Control
X-Acc-Debug-Context
Retry-After
X-CSRF-Token
X-FB-TRIP-ID
X-EdgeConnect-Cache-Status
Filters
Meta-Geo
X-RN-RSRV
X-Cache-Var-Map
X-Debug-Cache
X-ES-SERVER
X-Mode
X-Sucuri-ID
X-Cache-Var
X-Qloud-Router
X-R9-Blue-Green-Version
Section-Io-Cache
Webserver
X-Source
X-Locale
X-Device-Type
X-RemovedCookies
X-ProcessESI
X-From
X-Via-Fastly
X-GeoIP
X-Real-IP
Eomportal-Instance
X-VWS-Id
X-Xfnlog-Site
X-ProxyCache-Key
X-ProxyCache-Status
X-Ratelimit-Reset
Mn-Server-Ip
X-BYPASS-REASON
X-AWS-Id
X-Cache-Host
X-LJ-Flow-ID
X-Hl-Ver
X-Loop
X-PCL
Selected-Fe
Cache-Tv-Group
X-Handled-By
X-OCL
Ec-Rule-Version
X-Server-W
X-Proxy-Build
X-Routing-Service
X-Cluster
X-Zipkin-Id
X-Proxied
X-Site-Version
Cross-Origin-Window-Policy
X-TNCMS
X-Timing-Wait
X-Time-Microsecs
Charset
X-Amz-Replication-Status
Webcakes-Region
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Framework
X-ServerID
X-FW-Version
X-Human
X-NYM-Debug-Backend
X-Origin-Hint
X-JoinUs
X-SaId
X-Cache-Action
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Device-Class
TWC-Connection-Speed
TWC-Locale-Group
Webcakes-App-Name
X-Be
X-BCube-Filmed-By
Webcakes-App-Version
Property-Id
TWC-Privacy
From-Origin
Ms-Operation-Id
X-Status
X-PHP-Host
X-Section
X-Access
X-Hosted-By
X-RTag
X-L-Path
X-Cache-TTL-Remaining
X-Format
X-Environment-Context
X-Proto
X-Labrador-Cache-Channel
DB-Nickname
X-Amzn-Remapped-Content-Length
X-Generated-By
FSS-Cache
Uber-Trace-Id
X-Varnish-Cache-Hits
X-Detected-As
X-Air-Hostname
Version
X-Redis-Cache
X-Revision
X-No-Session
Frame-Options
X-Cache-PHP
X-ATG-Version
X-NWS-UUID-VERIFY
X-Drupal-Cache-Contexts
X-Sucuri-Cache
X-Contextid
X-CACHE-AGE
X-TA-CDN-Provider
X-Drupal-Cache-Tags
X-EIG-Tracking-Id
X-Origin
X-NCache
CF-Cached-On
Server-Name
X-EC-Lua
GEO-INFO
X-Unique-Id
X-IPS-LoggedIn
X-Tt-Trace-Host
X-URL
OT-Force-Account-Verify
X-Tt-Trace-Tag
X-Akamai-Transformed
X-Bc-Bl
X-IP
X-Vgn-Hpd-Variations-Key
X-Vgn-Hpd-Cached
X-Cache-Enabled
X-Cache-Backend
X-GoCache-CacheStatus
X-Adobe-Content
X-Adobe-Loc
X-AIR-PT
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Request-Id
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
Time
X-Backend-Host
X-TT
Now
X-ECache
X-CDN-Forward
X-Ruxit-Js-Agent
X-Tumblr-Pixel-3
X-Correlation-Id
X-RCS-CacheZone
Access-Control-Request-Headers
Azure-RegionName
Azure-InstanceId
Azure-SiteName
Azure-Version
X-Cdn
X-Cache-2
X-TIME
Azure-SlotName
X-Instart-Request-ID
Apple-News-Services-Parsed-Url
Xc-Version
Apple-News-Services-Host
Apple-News-Services-Handled
X-Rojux
X-D
Apple-News-Services-Request-Url
DCR-Processing-Time-Ms
DCR-Decision-By
CloudFront-Viewer-Country
X-Request-UUID
X-Cache-NE
X-ScT
Fastcgi-X-Cache-Version
X-Connection-Hash
X-CF-Lambda-Version
X-PBS-Appsvrname
X-Vtex-Processado-Em
X-S
X-Vtex-Remote-Cache
X-S-Cookie
X-CCM
X-CF-Lambda-Fn
X-Worker
X-VG-WebServer
Host-ID
X-A-Dam
X-A-Dcw
X-Twitter-Response-Tags
X-A-Ccd
X-A
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-A-Dgt
X-Vdms-Path
X-Date
X-Aed
X-Application
X-Adobe-Source
X-Destination
X-A-Wwc
X-Accel-Expires-Debug
X-External-Request-Id
X-Vdms-Version
Machine
MD5-Digest
X-PAYTM-SRV-ID
X-Processor
X-Up
X-Transaction
X-VG-WebCache
X-Minions-Version
Meta-Geo-Continent
SD-X-WS
Surrogated-Key
X-Trv-Group
X-G
Rendered-Blocks
Mobile-Detection-Method
X-Rewrite-Enabled
X-B-Cookie
X-ARC
X-NGENIX-Cache
X-APP-VERSION
Node
X-Hash
X-Generation-Time
X-Forwarded-Host
X-Backend-TTL
Adler-Geo
X-ApacheServer
X-Alternate-Cache-Key
X-Microcachable
Fastly-SIE
X-Method
Wxu-Next-Commit
Wxu-Next-Region
Wxu-Next-Hostname
X-Envoy-Decorator-Operation
X-DPWN-IS-SECURE
CDN-EdgeStorageId
CDN-CachedAt
CDN-PullZone
CDN-RequestCountryCode
CDN-Uid
CDN-RequestId
CDN-Cache
X-Cache-Grace
X-Dispatcher-Server
X-Owner
X-CUA
X-Bip
X-Cache-Bucket
X-Core-Value
X-Edge-Location
We-Hiring
X-Soup
NM-Fastcgi-Cache
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Skip-Cache
X-PERF
X-Storefront-Renderer-Rendered
X-Thanos
Is-Eu
Mail-Subject
HostName
X-VG-TLSProxy
X-Variation
X-Varnishpool
X-Shopify-Stage
X-SN
X-ShopId
X-Rebelmouse-Cache-Control
Platform
Fastly-SWR
X-Req
X-Rebelmouse-Surrogate-Control
X-ShardId
X-Servername
X-UA
X-TX-ID
X-Backend-State
Rt-Fastcgi-Cache
Origin
X-Cache-Tags
Ufe-Result
X-Varnish-Ttl
X-Cache-Date
X-Auto-Login
X-Cache-NGX
PFcat
X-Cache-Config
X-Eu-Site
X-Proxy-Upstream
X-Pubstack
X-Policy
X-Platform
X-OVcl-Cache
X-Reqid
X-Request-Start
X-Ms-Request-Id
X-Ms-Version
X-VarnishDD-TTL
X-Varnish-Cacheable
X-Storage
X-OVcl
X-Li-Pop
X-Core-Mission
X-Csrf-Jwt
X-Cms-Context
X-Cluster-Name
X-Clientip
L5d-Success-Class
X-Fastly-Backend
X-Level-Front-Cache
X-Li-Fabric
X-HN
X-Generated-On
X-Gamma-Serve
X-CGP
X-LI-UUID
Ha-Gx-Prefs
X-NC
Group
Fastly-Drupal-HTML
Gh-Request-Id
Country-Code
HA-Ipaddr
L
AKAMAI
C-Via
Cache-Status
CacheControlHeader
Fastly-SSL
X-Cdn-Forward
X-Varnish-Beresp-Status
X-Amz-Meta-Cb-Modifiedtime
X-VHOST
X-Agile-Id
X-Agile-Age
X-Varnish-Beresp-Grace
X-JWT-State
X-Agile
Country
X-Fmm-Version
X-Developers
X-Micro-Cache
X-Location
X-Content-Age
X-Render-Time
X-Fastly-Cache
X-Clara-WADP
X-Has-Esi
X-Is-Gdpr
X-Geo-Header
X-WADP-Cache
Fastly-Backend-Name
Pagetype
X-Viewer-Country
X-Webstats-RespID
UCS
X-Varnish-Beresp-Ttl
X-CS
X-Say-Cacheable
X-Cdn-Srv
X-Cache-URL
X-Cache-Id
X-Say-TTL
X-Wikidot-Backend
X-Gzip
X-PF-Uncompressing
X-Old-Content-Length
Akamai-GRN
X-Esi-Check
Backend
X-Wikidot-Static-Cache
X-HS-Content-Campaign-Id
X-Request-Host
Memcached
X-SayCDN-TTL
X-Web-Node
Decoy-Debug-Status
FSS-Proxy
Decoy-Debug-TTL
Decoy-Debug-Key
X-Slack-Backend
X-Esi
X-Wa
X-Irp-Debug
X-Dc
Nel
M-TraceId
X-Aicache-OS
X-Platform-Server
X-Refresh
X-Mvc-Supplant-Cachable
X-LB-ID
X-NODE
X-DefElseHash
X-Varnish-CookieINHashed-On
Upgrade-Insecure-Requests
X-Varnish-CookieHashed-On
X-Varnish-Remaining-TTL
X-DefHash
X-Via-Popn
X-Via-Poph
X-UPSTREAM-Address
X-ZONE
X-BC
X-LAGOON
X-Branch-Name
X-RateLimit-Remaining
Arc-Country
X-LI-Proto
X-B3-Spanid
X-Aspnet-Duration-Ms
X-Session-Fingerprint
X-Cache-Debug
VivaBuild
X-Servedbyhost
X-Route-Name
X-Flags
X-Is-Crawler
X-Providence-Cookie
Viewtype
Geo-Info
X-Unique-ID
X-Via-Ucdn
X-RunCloud-Cache
Actual-Object-TTL
X-ORACLE-APMCS-REQUEST-ID
NGX
X-Ua-Device
Srv
Cdn-Request-Time
X-Request-Time
X-Zone
CACHE
X-Edge-Server
Cdn-Host
X-Mvc-Supplant-OutputCached
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Bc
X-Nginx-Cache
X-SERVER
Memory
Xserver
X-Varnish-Hostname
X-HS-Status
X-Ftr-Cache-Host
X-Srv
X-Vgn-Hpd-Ssi
X-Page-View
X-DC
X-Action
X-APP
X-GEO
X-Akamai-Request-ID2
X-Check-Cacheable
X-Cs
X-LiteSpeed-Cache-Control
X-CF-Powered-By
X-B3-Traceid
X-DSS
X-DI
X-DW
X-RPM
X-RPS
X-Via-Popv
X-DB
Sid
X-RSL
X-FPC
X-MP-GENERATED-AT
WWW-Authenticate
X-NGINX-Cache
X-Nc
X-Geo
X-Oss-Cdn-Auth
ProcessTime
GeoIP-Country-Code
SRV
X-NU-AKA-ACS-Version
GeoIP-Latitude
X-Epic-Correlation-Id
NtCoent-Length
X-Cluster-Node
Hostname
X-Webkit-CSP-Report-Only
X-FC-Vary-Parameters
X-Mobile-Rewrite
X-Vcache
X-Hit
Server-Info
X-Dynatrace-Js-Agent
X-VCL-Version
Geoip-Latitude
GeoIp-Country-Code
X-CSRF-TOKEN
User-Agent
X-Sql-Duration-Ms
X-SERVER-NAME
Processtime
X-Via-SSL
Apigw-Requestid
X-Fpc
Edge-Copy-Time
X-UnsetCookies
X-Via-CDN
XServer
X-Via-Edge
W
X-Sql-Count
X-FORWARDED-FOR
X-We-Are-Hiring
On-Server
X-Vcl-Version
X-HOST
SID
LB
WebServer
Origin-Edge-Control
S-Rt
X-Www-Served-By
X-Svr
X-Fastly-Country-Code
X-Key
X-Envoy-Upstream-Healthchecked-Cluster
Accept-Language
Esi-Enabled
Origin-Cache-Control
X-Presslabs-Stats
X-HITS
X-S-Maxage
Ohc-File-Size
Amp-Access-Control-Allow-Source-Origin
T-Server
X-Cache-Hfrom
X-Pjax-Url
Cache-Hits
Cdn
X-Cache-Hm
X-Dispatch
ServedBy
X-Pinterest-Sli-Response-Type
X-Pinterest-Sli-Endpoint-Name
X-Tb
CF-IPCountry
X-Pinterest-Sli-Latency-Threshold
X-SRV
Proxy-Firewall
X-Cache-Remote
N-Cache
A
Server-Host
X-CACHE-KEY
HitType
X-COUNTRY
Magicmarker
X-MSEdge-Features
Pics-Label
X-Geo-Region
Cteonnt-Length
CDN
X-MSEdge-Flight
X-Pass-Why
Lb
X-App
X-SB
X-VC
X-Amzn-Remapped-Date
X-Amzn-Remapped-Connection
X-Generated
BehaviorPad-Version
X-Varnish-Hits
X-RAMCache
X-Newrelic-App-Data
Fastcgi-Cache-TTL
X-Instart-Info
WZWS-RAY
Powered-By
Ohc-Cache-HIT
X-Path-Route
X-ServedByHost
X-Newrelic-Synthetics
X-Li-Proto
X-TrackingId
X-Datadome
X-Xrds-Location
X-Dynatrace
X-Cache-Tag
X-Info
X-Served-From
Cache-Key
X-Akamai-Pragma-Client-IP
X-TH-Server
Xet-Cookie
X-StackifyID
Protected
X-B3-SpanId
Server-Ttl
X-Lb-Id
X-LiteSpeed-Tag
Cache-Provider
X-Batcache
Dnion-Transfer-Encoding
X-Via-PopN
X-Via-NSCOPI
X-Via-PopV
X-Via-PopH
Content-Script-Type
Content-Style-Type
X-TT-LOGID
X-Agile-Brick-Ok
X-WA
Cf-Alt-Svc
X-Origin-Response-Time
User-Cache-Control
Tracecode
X-Tt-Logid
X-Varnish-Beresp-TTL
Ssr
X-Uri
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
X-Vgn-Hpd-Reason
Tcn
X-Cc-Via
X-Scheme
Who
X-Region-Sid
Lfy
X-Yottaa-OS
D-Cc-Upstream
Inserted-Into-Cache-At
X-Pf-Uncompressing
X-Tid
X-Pad
X-Cache-Spec
X-HostName
X-RateLimit-Limit
X-Cc-Req-Id
X-Selected-Host-Header
CountryCode
X-Selected-Name
X-Selected-Scheme
X-Snapshot-Date
X-Proxy-Cachei7
Vha6-Origin
X-Nananana
Source
X-DevSite-Last-Modified
X-Request-URL
Cneonction
X-Men
X-Dw-Trace-Id
X-C
X-Magnolia-Registration
Pragrma
X-PJAX-URL
Mime-Version
X-Apw-Access-Action
X-MiniProfiler-Ids
X-Apw-Hits
X-Apw-Access-Token
X-Apw-Access-Object
PICS-Label