Threat Level: green Handler on Duty: Rob VandenBrink

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
CF-RAY
ETag
Link
Expect-CT
Via
X-XSS-Protection
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Xss-Protection
X-Varnish
X-Request-Id
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Adblock-Key
X-Check
Alt-Svc
X-Cacheable
X-Generator
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-Cache-Status
X-AspNetMvc-Version
X-Permitted-Cross-Domain-Policies
X-Template
X-Iinfo
X-Language
Status
Timing-Allow-Origin
X-Buckets
X-Content-Security-Policy
Content-Encoding
X-CDN
X-Kinja-Server-Push
Xkey
X-Turbo-Charged-By
Upgrade
X-Type
X-Request-ID
Keep-Alive
Access-Control-Expose-Headers
WPE-Backend
X-Pass-Why
Access-Control-Max-Age
X-Backend
X-AH-Environment
X-Ua-Compatible
X-Age
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Server
X-Via
X-Proxy-Cache
Grace
X-Pingback
X-Nginx-Cache-Status
X-Server-Powered-By
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Hacker
X-UA-Device
X-Varnish-Cache
X-Page-Speed
EagleId
Request-Context
P3p
X-LiteSpeed-Cache
Cf-Railgun
X-Envoy-Upstream-Service-Time
X-CST
X-Swift-CacheTime
X-Swift-SaveTime
X-WebKit-CSP
Ali-Swift-Global-Savetime
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-Server-Id
X-Amz-Version-Id
X-Ac
Server-Timing
X-Node
X-OneAgent-JS-Injection
Allow
Feature-Policy
X-Cnection
X-Iejgwucgyu
X-Response-Time
X-Rq
Content-Location
X-Cache-Lookup
X-Backend-Server
Report-To
EagleEye-TraceId
Surrogate-Control
X-Readtime
X-Host
X-Application-Context
Request-Id
X-ORACLE-DMS-ECID
X-Url
X-Rack-Cache
X-Origin-Cache
X-Clacks-Overhead
X-Country
NEL
X-FTR-Request-ID
Rating
X-Country-Code
X-Cloud-Trace-Context
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-DataDome
X-Instart-Request-ID
X-Ruxit-JS-Agent
X-Px
X-Vhost
X-Mod-Pagespeed
X-MS-InvokeApp
Charset
X-VARITI-CCR
Accept-CH
Edge-Control
X-Goog-Hash
Verso
X-GitHub-Request-Id
Pinterest-Generated-By
PB-RID
X-Mobile-Rewrite
Arc-Version
PB-PID
X-Vname
X-TtlSet
X-PC
X-Version
X-Server-Name
X-Cdn
X-Varnish-TTL
X-B3-TraceId
X-Powered-By-Plesk
X-ESI
X-D2id
X-DynaTrace
X-Exp-Variant
X-Cached
X-Exp-Id
X-Kinja
X-Cdn-Fetch
X-GoogleNews-Bot
X-Kinja-Server
X-TTL
X-Use-Magma
X-Kinja-Revision
X-Kinja-Build
X-Upstream-Env
X-Origin-Upstream-Status
X-Dispatcher
X-ORACLE-DMS-RID
SPRequestGuid
X-Powered-CMS
X-SharePointHealthScore
X-Abt-Application-Version
MS-Author-Via
X-Recruiting
RTSS
X-T
Accept-CH-Lifetime
X-Navigation-Version
Public-Key-Pins
X-Shield-Request-Id
Content-MD5
X-Trace
AR-PoweredBy
AR-CACHE
AR-ATIME
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Amz-Rid
X-Client-IP
SPRequestDuration
X-HW
SPIisLatency
X-Fastly-Request-ID
X-Forwarded-Proto
X-Wix-Server-Artifact-Id
X-Accel-Buffering
Arr-Disable-Session-Affinity
X-DIS-Request-ID
Realpath
X-DynaTrace-JS-Agent
X-Server-ID
X-B
X-Oracle-Dms-Rid
X-F-Cache
X-Upstream
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Amz-Meta-S3cmd-Attrs
Service-Worker-Allowed
X-Ser
X-Via-JSL
Pinterest-Version
X-Pinterest-Rid
X-FTR-Backend-Server
Paypal-Debug-Id
X-FTR-Backend
X-FTR-Balancer
X-Id
X-FTR-Cache-Status
Front-End-Https
X-FTR-Realm
X-Country-Code-Real
X-FTR-DC
AR-Request-ID
X-FTR-Expires
X-Dw-Request-Base-Id
X-Dns-Prefetch-Control
X-Ttl
X-Vcap-Request-Id
X-Varnish-Age
X-Debug
X-Acc-Meta-Resource-Type
X-Goog-Storage-Class
X-MSEdge-Ref
Nginx-Cache
X-Kinsta-Cache
X-N
X-XRDS-Location
X-Hits
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-NF-Request-ID
X-FTR-Cache-Host
Ar-Sid
X-Logged-In
S
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
X-Akam-SW-Version
X-NewRelic-App-Data
X-DataStream-Cache-Status
X-Forwarded-For
X-Frontend
X-PressLabs-Stats
Alternate-Protocol
X-User-Agent
X-HS-Hub-Id
X-HS-Content-Id
Tracecode
X-Grace
X-CACHE-GROUP
X-Amzn-Trace-Id
X-FastCGI-Cache
AMP-Access-Control-Allow-Source-Origin
Server-Name
X-Content-Digest
X-Pad
Refresh
X-Content-Options
Powered-By-ChinaCache
X-Cache-Key
DynaTrace
Backend-Timing
X-Analytics
X-Content-Type
MicrosoftSharePointTeamServices
X-Zen-Fury
X-LB-Cache
TCN
Accept-Charset
FilterID
X-Sol
Display
X-Debug-Info
X-AppVersion
X-Middleton-Display
X-Az
X-Activity-Id
Host
X-Rid
X-IPLB-Instance
Access-Control-Request-Method
X-Page-Id
MS-CV
X-CF-Powered-By
X-TA-CDN-Provider
ServerID
X-Magnolia-Registration
Fastcgi-Cache
X-Middleton-Response
Cache-Status
Response
TP-Cache
TP-L2-Cache
X-Cache-Hit
X-Content-Powered-By
X-Hostname
X-Mobile
X-ATG-Version
X-Seen-By
X-RateLimit-Remaining
X-Srv
X-WA-Info
X-Fastcgi-Cache
Surrogate-Key
X-VCache
X-GUploader-UploadID
X-Revision
X-B3-Sampled
X-Cached-By
X-Varnish-Backend
X-Request-Received
X-Request-Processing-Time
Rt-Fastcgi-Cache
X-SS-Set-Cookie
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-B-Cache
X-Signature
X-Cluster
X-Instance
X-Cache-Action
X-Tumblr-Pixel
Host-Header
X-Tumblr-Pixel-0
X-Tumblr-User
X-Content-Security-Policy-Report-Only
X-Drupal-Cache-Tags
X-Platform-Server
X-Whom
X-Wix-Request-Id
X-Cache-Age
Cleartype
Source
ViewerVersion
X-Request-Guid
X-PHP-Backend
X-XRDS-LOCATION
X-Framework
X-Handled-By
X-TT
X-Akamai-Edgescape
X-App-Environment
X-Origin-Server
Server-Info
X-Edge-Location
X-Cache-Control
DC
X-Real-IP
X-BCube-Filmed-By
X-Amz-Apigw-Id
X-Oneagent-Js-Injection
X-Generated-By
X-Amzn-RequestId
X-App-Server
X-Cache-Rule
X-Geo-Country
X-FW-Hash
X-FW-Static
X-FW-Server
X-FW-Serve
X-FW-Type
X-NWS-LOG-UUID
X-AOL-HN
Server-Node
Fusion-Template-Id
X-Ruxit-Js-Agent
Fusion-Component-Id
X-Varnish-Hostname
Fusion-Content-Id
Fusion-Source
Fusion-Content-Source
X-Varnish-Server
Retry-After
X-Cache-2
Eomportal-Instance
X-Correlation-Id
X-FB-Debug
Cache
Payment
X-Amz-Server-Side-Encryption
X-Varnish-Grace
Webserver
X-Response-Served-From
Actual-Object-TTL
X-TT-TIMESTAMP
Access-Control-Allow-Method
X-Tumblr-Pixel-2
X-Varnish-Hits
GEO-INFO
AsisCache
X-Tumblr-Pixel-1
X-WPE-Loopback-Upstream-Addr
ServedBy
X-UUID
X-RTag
Ms-Operation-Id
X-TX-ID
Filters
X-Drupal-Cache-Contexts
X-Jobs
Healthy
NGB
X-Device-Type
X-Cacheable-TTL
X-Region
Content-Style-Type
Content-Script-Type
X-WebKit-CSP-Report-Only
X-Contextid
X-Adobe-Loc
Upgrade-Insecure-Requests
Viewport
X-Adobe-Content
X-Amz-Replication-Status
X-Servedby
X-Varnish-IP
X-Cache-Config
Country
X-Rendered-As
X-RequestSource
X-Locale
X-Esi
From-Origin
Cache-Tv-Group
X-Accel-Expires
X-UA-Device-Type
HitType
X-Ezoic-Cdn
Edge-Cache-Tag
X-BACKEND-TTL
X-Cache-TTL-Remaining
X-VG-WebCache
X-Cache-TTL
X-Cache-Server
X-Cache-Remote
X-FW-Dynamic
Fastcgi-Useragent
X-Cache-Operation
Pagespeed
X-Content-Age
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Fastly-Restarts
X-Hit
Cache-Tags
X-Upgrade-Enabled
X-Redis-Cache
X-APP-VERSION
X-Storage
X-Source
X-S
X-RateLimit-Limit
X-Upstream-Proxy
Datacenter
X-App-Version
X-Mode
Served-By
Cache-Tag
X-Generated
X-Backend-Name
X-Internal-Host
X-Cache-Var
X-Detected-As
X-Tb
X-Akamai-Request-ID
X-Cache-Var-Map
X-Origin-Response-Time
X-Hl-Ver
X-Is-Bot
X-NCache
Machine
Load-Balancing
Vix-Hermes-Req-Id
SRV
Meta-Geo
Origin-Edge-Control
Origin-Cache-Control
X-JoinUs
X-Rule
NtCoent-Length
X-Daa-Tunnel
X-Path-Route
X-RN-RSRV
X-Akamai-Transformed
X-NGENIX-Cache
X-GeoIP
X-Varnish-Cache-Hits
X-Edge-IP
X-Environment-Context
X-FC-Vary-Parameters
X-Birta-Cache-Post
X-Agile
Cache-Key
Selected-FE
Now
X-Agile-Age
X-Agile-Id
X-Www-Served-By
X-Cache-Category-Id
X-BYPASS-REASON
X-Birta-Served
X-CDN-Cache
X-Grey
X-Pubstack
X-CACHE-KEY
X-Timing-Wait
X-Time-Microsecs
X-Origin-Host
X-ServerID
X-ProxyCache-Status
X-Web-Node
X-Hosted-By
X-ProxyCache-Key
X-Proxy-Build
X-Proxy
X-Labrador-Cache-Channel
X-L-Path
X-Loop
Xserver
X-TNCMS
X-Varnish-Cacheable
TWC-Privacy
Webcakes-Region
Webcakes-App-Version
Webcakes-App-Name
TWC-GeoIP-Country
X-Pc-Hit
X-PERF
Property-Id
TWC-Connection-Speed
TWC-Device-Class
Cache-Name
TWC-GeoIP-LatLong
TWC-Locale-Group
X-ApacheServer
X-Status
X-PCL
X-DataStream-Origin-MEX-Latency
X-Format
X-Viewer-Country
X-DataStream-MidMile-RTT
X-Pc-Key
X-Via-Fastly
X-IP
X-Pc-Appver
X-Origin-Hint
X-OCL
S-Rt
X-ProcessESI
Public-Key-Pins-Report-Only
X-Access
X-Section
X-Debug-Cache
X-RemovedCookies
X-Site-Version
X-CCM
X-Human
X-Cache-Enabled
X-VG-TLSProxy
X-Cache-NE
Azure-Version
Azure-SlotName
Azure-SiteName
Azure-InstanceId
DB-Nickname
Azure-RegionName
Fastcgi-X-Cache-Version
X-Zipkin-Id
X-Xfnlog-Site
X-Proxied
X-MP-GENERATED-AT
X-App-Name
We-Hiring
Mail-Subject
X-Routing-Service
X-Microcachable
Access-Control-Request-Headers
X-Origin
X-Original-Request
X-Ocache
X-GEO
User-Cache-Control
X-EdgeConnect-Cache-Status
X-Guploader-Uploadid
S-Cnection
X-Sucuri-ID
Liferay-Portal
X-Protected-By
X-Request-Time
X-Nginx-Cache
X-Cdn-Forward
AR-SID
X-FW-Version
User-Agent
X-UA
Cache-Hits
X-GRACE
X-Node-Name
X-Tumblr-Pixel-3
X-ES-SERVER
X-Proto
X-Webstats-RespID
PageSpeed
X-Yottaa-Metrics
X-Yottaa-Optimizations
Ohc-File-Size
LB
X-Correlation-ID
X-Time
X-FB-TRIP-ID
X-Trace-Id
Powered
X-Origin-CC
X-Ua
X-Unique-ID
X-Forwarded-Host
X-Endurance-Cache-Level
L5d-Success-Class
X-Nc
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
Frame-Options
Section-Io-Cache
X-Upstream-HT
X-Upstream-CT
X-Parent-Response-Time
X-Pc-Subdomain
X-V
IBM-Web2-Location
X-Pc-Host
X-OVcl-Cache
X-OVcl
X-Pc-Date
X-Origin-TTL
X-Cache-Backend
X-Rocket-Nginx-Bypass
X-ElasticPress-Search
X-VWS-Id
X-Varnish-Beresp-Ttl
Nel
X-AWS-Id
X-LJ-Flow-ID
OT-Force-Account-Verify
X-R9-Blue-Green-Version
X-Vgn-Hpd-Reason
X-Cluster-Node
Mobile-Detection-Method
Node
Meta-Geo-Continent
Powered-By
Memcached
Decoy-Debug-Key
X-Rojux
BehaviorPad-Version
Cache-Prefix
Arc-Country
X-S-Cookie
X-ScT
X-S-Maxage
Country-Code
Decoy-Debug-Status
Fly-Cache
Fly-Request-Id
GMS-Ver
Fastly-SWR
Fastly-SIE
Decoy-Debug-TTL
Ec-Rule-Version
MD5-Digest
X-Block-Status
X-Gen-Mode
X-From
X-Generated-In
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Hnp-Log
X-Fetched-On
X-External-Request-Id
X-Destination
X-Date
X-Developer
X-Distil-CS
X-DPWN-IS-SECURE
X-IN-APIGATEWAY
X-IN-SSL-APIGATEWAY
X-NU-AKA-ACS-Version
X-Micro-Cache
X-Origin-Date
X-Origin-Expires
X-PAYTM-SRV-ID
X-LI-UUID
X-LI-Proto
X-Info
X-IN-WAF
X-Irp-Debug
X-Li-Fabric
X-Li-Pop
X-Connection-Hash
X-Rebelmouse-Cache-Control
X-Amz-Meta-Cache-Control
X-Aed
X-Reboot
X-Application
X-ARC
X-Accel-Expires-Debug
Www
X-Request-UUID
Resin-Trace
X-Region-Sid
Viewtype
VivaBuild
X-Auto-Login
X-B-Cookie
X-Rebelmouse-Surrogate-Control
X-Cache-URL
X-Cdn-Srv
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Cache-Info
X-Cache-Id
X-Server-By
X-BB-ID
X-Cache-Bucket
X-Cache-FS-Status
X-Cache-Host
Rendered-Blocks
X-Rewrite-Enabled
X-Twitter-Response-Tags
X-User
X-UE-Client-Country
X-ServiceProvider
X-Trv-Group
X-Transaction
X-Server-Cache
X-SRCache-Key
X-TT-LOGID
X-We-Are-Hiring
X-Server-Group
X-VG-WebServer
X-Wikidot-Backend
X-PHP-Host
Xc-Version
X-Wikidot-Static-Cache
Fastcgi-X-Cache
X-Sucuri-Cache
X-Newrelic-App-Data
X-Distributor
X-Edge-Cache
X-Request-URI
Thinkindot-CacheControl
Thinkindot-Control
Thinkindot-CacheControl-Type
True-Client-Country-4JS
X-Dispatcher-Server
SD-X-WS
X-Response-By
X-FireWall-Port
Proxy-Connection
X-G
Platform
X-Gannett-Site-Version
Request-Time
X-RateLimit-Limit-Second
X-Epic-Correlation-Id
Server-Host
Web-Mar-Node
X-Eu-Site
X-RateLimit-Remaining-Second
X-Fastly-Cache
X-Edge-Cache-Key
X-A-Dam
X-C
X-Core-Mission
X-Crawler
X-Bip
X-Backend-State
X-Backend-Url
X-Thinkindot-L3
X-Cache-Debug
X-Clientip
X-CGP
X-Cache-Grace
X-Thanos
X-Cache-Expires
X-Backend-Host
X-CUA
X-Swa-Ws
X-A-Dcw
X-A-Ccd
X-A
X-Svr
X-A-Dgt
X-A-Wwc
X-Alternate-Cache-Key
X-D
X-Debug-Cookies
X-Actual-URL
X-Debug-Log
Who
Origin
X-Shopify-Stage
X-SIPLIST1
X-Proxy-Cache-Status
Countrycode
X-ShopId
CDCHOST
Content-Disposition
Fastly-Backend-Name
X-Sorting-Hat-PodId
X-Stale
X-Matched-Rule
X-Returned-From-DLL
On-Server
Fastly-Soc-X-Request-Id
X-Sorting-Hat-ShopId
X-ShardId
X-Nginx-Cache-Key
X-Passed-To-BeforeDispatch
Adler-Geo
X-Passed-To-DLL
X-Server-IP
X-Passed-To-PostProcessResponse
X-Secret
Ajk
X-Passed-To
X-Sf
X-Node-Id
Backend
X-NX-Host
X-Platform
X-Policy
X-Logtrace-Id
X-Returned-From-PostProcessResponse
X-Proxy-Upstream
X-SERVER
Magicmarker
Lfy
X-Returned-From-BeforeDispatch
X-Location
X-Returned-From
X-Var-Ttl
X-Generated-On
X-Varnish-Action
X-GeoIP-Country-Code
X-Hash
X-Variation
Is-Eu
IsBot
HA-Ipaddr
Ha-Gx-Prefs
HostName
X-LAGOON
X-Level-Front-Cache
Warning
Mn-Server-Ip
X-UnsetCookies
X-Up
X-Generation-Time
X-Fstrz
X-Device-Os
X-Varnish-Authentication
X-Qloud-Router
X-Developers
X-MSEdge-Features
X-Debug-Cache-Expiry
X-No-Session
X-MSEdge-Flight
X-Key
X-Instart-Isnd
X-Croise-Owner
X-F5-Cache
X-Core-Value
X-Debug-Cache-Fetch
X-Died
X-Debug-Cache-Store
X-Amz-Meta-Surrogate-Control
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
X-EIG-Tracking-Id
Cache-Cookie-Set-From
Cache-Cookie-Set-Idcheck
Apple-News-Services-Host
Heartbleed
RNT-Machine
Server-Cache-Control
Server-Int
Server-Surrogate-Control
SS
RNT-Time
Release
Fastly-SSL
Cache-Cookie-Set-Lfrom
GW-Server
X-Via-NSCOPI
X-Via-CDN
X-Cache-ASPX
AKAMAI
Apple-News-Services-Handled
Pramga
Pagetype
X-TrackingId
CACHE
X-Dc
X-HS-Cache-Config
X-Page-Type
X-Server-Time
X-TIME
NGX
Kp-EeAlive
X-Varnish-Url
Server-ID
X-Sedo-Request-Id
X-Cache-Miss-From
REQUESTUUID
X-Pjax-Url
Version
X-B3-Traceid
X-Servername
SID
PFcat
X-Varnish-Ttl
X-NC
MIME-Version
X-Be
RequestId
X-Dynatrace-Js-Agent
X-Refresh
X-Owner
FastCGI-Cache
X-SN
X-B3-SpanId
X-CDN-Forward
X-URL
X-Cache-CFC
Esi-Enabled
X-Store
Odigeo-Trace-Id
X-From-Cache
X-Oss-Request-Id
X-MI-In-Market
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
Time
X-Oss-Object-Type
X-Oss-Storage-Class
MI-Cache-Age
X-Layer
X-FPC
MI-API
MI-Cache
X-RCS-CacheZone
X-Ratelimit-Remaining
PICS-Label
X-RequestId
HA-Cloudapp
X-Servedbyhost
HTTPS
HA-Urlpath
HA-Geocountry
HA-Geocity
Cteonnt-Length
HA-Geolat
HA-Geolon
HA-Servedtime
HA-Host
HA-Georegion
X-IPS-LoggedIn
Cdn
X-Edge-Server
X-CSRF-TOKEN
Cdn-Request-Time
Cdn-Host
Mime-Version
X-Hyper-Cache
CF-IPCountry
Hostname
X-Webkit-Csp
X-Req
Backend-Name
X-Webkit-CSP
X-CLOUD-TRACE-CONTEXT
X-Unique-Id-Primal
ProcessTime
X-Mshield-Cache-Status
X-Mrs-Cache-Hits
X-Mrs-Cache
X-Mrs-Age
X-Ratelimit-Limit
X-Wa
X-CMS-Context
Memory
X-Geo
CDN
X-Load-Cache
Processtime
X-DC
X-Mobile-URL
X-Datadome
X-Amzn-Remapped-Date
X-Amzn-Remapped-Connection
X-Instart-Info
X-Real-Ip
X-WebServer
Cf-Ipcountry
Ohc-Response-Time
X-NodeID
X-VServer
Cross-Origin-Window-Policy
X-Phone
X-WR-MODIFICATION
GeoIP-Country-Code
X-Newrelic-Synthetics
X-Aicache-OS
X-HS-Combine-CSS
X-Request-Start
X-Pf-Uncompressing
X-GZip
X-B3-Spanid
XServer
X-Varnish-Beresp-TTL
X-PF-Uncompressing
X-Fastly-Country-Code
X-Lb-Id
GeoIP-Latitude
X-Skip-Cache
X-Release
X-HTML-Minification-Powered-By
X-Atg-Version
URI
Ohc-Cache-HIT
Accept-Ch-Lifetime
X-VC-Cache
X-FORWARDED-FOR
X-WA
T-Server
X-Server-W
Amp-Access-Control-Allow-Source-Origin
Rt-Proxy-Cache
X-Oracle-Dms-Ecid
X-ND-Cache
X-APP
Uber-Trace-Id
X-Cms-Context
X-Served-From
X-Nananana
X-Tb-Optimization-Total-Bytes-Saved
X-LB-ID
X-GoCache-CacheStatus
X-MServer
X-Gateway-Skip-Cache
X-Gateway-Cache-Status
X-Gateway-Cache-Key
X-UCC
N-Cache
X-COUNTRY
X-ServedByHost
X-SRV
Pics-Label
X-Worker
X-Unique-Id
X-CSRF-Token
X-LiteSpeed-Cache-Control
V-Age
X-Processor
X-UPSTREAM-Address
X-Dynatrace
A
X-Fastly-Cache-Hits
X-Sn-Servicetimems
X-Cdn-Origin
X-GZIP
X-SERVER-NAME
X-SVT-ORM-RULES
X-CACHE-AGE
X-BBXSRF
Proxy-Firewall
X-SVT-ORM-VERSION
DataCenter
X-Hp-Webp
X-BE
X-Cache-HT
X-Requestid
X-Optimization
X-Check-Cacheable
Is-Session-Tracking
X-P-T
Get-Access-Time
X-HS-Status
X-NGINX-Cache
Dnion-Transfer-Encoding
Geoip-Latitude
Requestid
X-Vcache
Cneonction
X-ID
ServerName
Dynatrace
X-VCT
X-Backend-TTL
X-Vg-Webcache
X-Shard
X-Varnish-URL
X-RCS-Backend
X-ServerName
X-Csrf-Token
RequestUuid
X-Fe
X-GDPR
X-GeoIP-City
X-Geo-Header
X-Amzn-Remapped-Content-Length
Host-ID
GeoIp-Country-Code
X-PAGE-TYPE
X-Port
X-PJAX-URL
WP-Super-Cache
X-NWS-UUID-VERIFY
Serverid
Cache-Provider
X-HostName
X-Git-Hash
X-StackifyID
X-LiteSpeed-Tag
X-Dw-Trace-Id
Server-Id
UCS
Inserted-Into-Cache-At
Lb
X-RAMCache
X-Fastly-Backend-Reqs
409pxxline
Request-EU
178proxuri
Request-Country
188prxHost
225prxHost
189phosttRef
219prxHost
X-CS
Xxline
DSUID
X-Request-Url
WZWS-RAY
355prline
352pxline
286prxHost
X-Org