Threat Level: green Handler on Duty: Russ McRee

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
CF-RAY
ETag
Link
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Request-Id
X-Xss-Protection
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Adblock-Key
X-Check
Alt-Svc
X-Cacheable
X-Generator
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-Cache-Status
X-AspNetMvc-Version
X-Permitted-Cross-Domain-Policies
X-Iinfo
X-Template
Status
X-Language
Timing-Allow-Origin
X-Buckets
X-Content-Security-Policy
Content-Encoding
X-CDN
X-Kinja-Server-Push
Xkey
X-Ua-Compatible
X-Turbo-Charged-By
Upgrade
X-Type
Access-Control-Expose-Headers
Keep-Alive
WPE-Backend
X-Pass-Why
Access-Control-Max-Age
X-Backend
X-AH-Environment
CF-Ray
X-Cache-Group
X-Age
X-Drupal-Dynamic-Cache
X-Server
X-Via
X-Request-ID
X-Proxy-Cache
Grace
X-Pingback
X-Nginx-Cache-Status
X-Server-Powered-By
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Hacker
X-UA-Device
X-Varnish-Cache
X-Page-Speed
EagleId
Request-Context
X-LiteSpeed-Cache
Cf-Railgun
X-Envoy-Upstream-Service-Time
X-CST
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Server-Id
X-Device
X-Amz-Version-Id
X-Ac
X-Node
Server-Timing
X-OneAgent-JS-Injection
Feature-Policy
X-Iejgwucgyu
X-Cnection
X-Response-Time
Allow
X-Rq
Content-Location
X-Backend-Server
X-Cache-Lookup
Report-To
EagleEye-TraceId
Surrogate-Control
X-Readtime
X-Host
X-Application-Context
Request-Id
X-Url
X-ORACLE-DMS-ECID
X-Rack-Cache
X-Origin-Cache
X-Clacks-Overhead
X-Country
NEL
X-FTR-Request-ID
Rating
X-Country-Code
X-Cloud-Trace-Context
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-DataDome
X-Instart-Request-ID
X-Px
X-Vhost
X-MS-InvokeApp
X-Mod-Pagespeed
Charset
X-Ruxit-JS-Agent
X-VARITI-CCR
Edge-Control
Accept-CH
X-Goog-Hash
X-GitHub-Request-Id
X-Mobile-Rewrite
PB-RID
PB-PID
Arc-Version
Verso
X-TTL
X-ESI
X-DynaTrace
X-Version
X-PC
X-Vname
X-TtlSet
X-Varnish-TTL
X-Server-Name
X-B3-TraceId
X-Cdn
X-Powered-By-Plesk
X-D2id
Pinterest-Generated-By
X-Exp-Variant
X-Cdn-Fetch
X-Exp-Id
X-Kinja
X-GoogleNews-Bot
X-Kinja-Build
X-Kinja-Server
X-Use-Magma
X-Kinja-Revision
X-Cached
SPRequestGuid
X-Origin-Upstream-Status
X-Dispatcher
X-Upstream-Env
X-Powered-CMS
X-SharePointHealthScore
X-Abt-Application-Version
X-T
MS-Author-Via
X-Recruiting
Accept-CH-Lifetime
RTSS
X-Trace
X-Navigation-Version
Public-Key-Pins
X-Shield-Request-Id
X-Oracle-Dms-Rid
X-ORACLE-DMS-RID
Content-MD5
AR-CACHE
AR-PoweredBy
AR-ATIME
X-SRCache-Fetch-Status
SPIisLatency
X-Amz-Rid
X-SRCache-Store-Status
SPRequestDuration
X-HW
X-Fastly-Request-ID
X-DIS-Request-ID
X-Client-IP
Realpath
Arr-Disable-Session-Affinity
X-Accel-Buffering
X-Wix-Server-Artifact-Id
X-Forwarded-Proto
X-F-Cache
X-B
X-Server-ID
X-Upstream
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Metageneration
X-DynaTrace-JS-Agent
X-Amz-Meta-S3cmd-Attrs
X-Ser
X-Via-JSL
Service-Worker-Allowed
Pinterest-Version
X-Pinterest-Rid
X-Id
X-Dw-Request-Base-Id
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-DC
X-Country-Code-Real
X-FTR-Realm
X-FTR-Expires
Front-End-Https
X-Vcap-Request-Id
AR-Request-ID
Paypal-Debug-Id
X-Varnish-Age
X-Dns-Prefetch-Control
X-Debug
X-Goog-Storage-Class
X-Acc-Meta-Resource-Type
Nginx-Cache
X-MSEdge-Ref
Ar-Sid
X-N
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Hits
X-Kinsta-Cache
X-NF-Request-ID
X-NewRelic-App-Data
X-Logged-In
X-FTR-Cache-Host
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
X-Ttl
S
X-XRDS-Location
X-Akam-SW-Version
X-Forwarded-For
X-Frontend
X-HS-Hub-Id
X-HS-Content-Id
X-Grace
Alternate-Protocol
X-PressLabs-Stats
X-User-Agent
AMP-Access-Control-Allow-Source-Origin
Tracecode
DynaTrace
X-Amzn-Trace-Id
X-Cache-Key
X-DataStream-Cache-Status
X-TA-CDN-Provider
X-CACHE-GROUP
Server-Name
X-Pad
X-Content-Digest
Refresh
X-Content-Options
Backend-Timing
X-Analytics
Accept-Charset
Fastcgi-Cache
X-Activity-Id
X-Az
Powered-By-ChinaCache
X-AppVersion
MicrosoftSharePointTeamServices
FilterID
X-Page-Id
Access-Control-Request-Method
X-LB-Cache
X-Zen-Fury
X-Rid
Display
MS-CV
Host
X-Sol
X-Middleton-Display
X-Content-Type
X-IPLB-Instance
X-Debug-Info
X-Fastcgi-Cache
X-FastCGI-Cache
X-CF-Powered-By
TCN
ServerID
X-Magnolia-Registration
TP-Cache
TP-L2-Cache
X-XRDS-LOCATION
Response
X-Middleton-Response
Cache-Status
X-ATG-Version
X-Cache-Hit
X-Mobile
X-Content-Powered-By
X-Ruxit-Js-Agent
X-Srv
Surrogate-Key
X-VCache
X-Seen-By
X-WA-Info
X-B3-Sampled
X-Hostname
Rt-Fastcgi-Cache
X-Revision
X-Cached-By
X-Request-Processing-Time
X-Request-Received
X-Varnish-Backend
X-RateLimit-Remaining
X-Cache-Age
X-SS-Set-Cookie
X-Signature
X-B-Cache
X-Cache-Action
X-Cluster
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Instance
X-Tumblr-Pixel-0
X-Tumblr-User
X-Content-Security-Policy-Report-Only
X-Tumblr-Pixel
X-Request-Guid
Source
Cleartype
X-Whom
X-PHP-Backend
X-Akamai-Edgescape
X-Platform-Server
X-Drupal-Cache-Tags
X-Framework
X-TT
X-Handled-By
X-Edge-Location
X-Origin-Server
Server-Info
X-App-Environment
ViewerVersion
X-Wix-Request-Id
Host-Header
X-GUploader-UploadID
X-Cache-Control
X-BCube-Filmed-By
X-Generated-By
DC
X-Amz-Apigw-Id
X-Cache-Rule
X-NWS-LOG-UUID
X-Amzn-RequestId
X-AOL-HN
X-Varnish-Hostname
X-App-Server
X-Cache-2
X-Geo-Country
X-Oneagent-Js-Injection
X-FW-Serve
X-FW-Hash
X-FW-Server
X-FW-Type
X-FW-Static
Retry-After
X-Varnish-Server
Server-Node
Eomportal-Instance
X-Correlation-Id
X-Real-IP
Fusion-Source
Fusion-Template-Id
Fusion-Content-Source
Fusion-Component-Id
Fusion-Content-Id
X-FB-Debug
Payment
X-Device-Type
Cache
Webserver
X-Response-Served-From
Actual-Object-TTL
X-Amz-Server-Side-Encryption
Access-Control-Allow-Method
X-Tumblr-Pixel-2
ServedBy
X-Tumblr-Pixel-1
X-Varnish-Hits
AsisCache
X-TT-TIMESTAMP
Filters
GEO-INFO
Ms-Operation-Id
X-Region
X-Jobs
X-WebKit-CSP-Report-Only
Content-Style-Type
X-TX-ID
X-Cacheable-TTL
X-RTag
Content-Script-Type
NGB
X-UUID
X-Varnish-Grace
Edge-Cache-Tag
X-Contextid
Healthy
X-Varnish-IP
X-Adobe-Content
X-Adobe-Loc
Upgrade-Insecure-Requests
X-Amz-Replication-Status
X-Servedby
Viewport
Country
X-Locale
X-Rendered-As
X-Drupal-Cache-Contexts
X-Accel-Expires
Cache-Tv-Group
X-Cache-Config
X-UA-Device-Type
X-RequestSource
From-Origin
X-WPE-Loopback-Upstream-Addr
HitType
X-Cache-TTL-Remaining
X-BACKEND-TTL
X-Ezoic-Cdn
X-Cache-Server
X-Cache-Remote
X-VG-WebCache
X-Cache-Operation
X-Cache-TTL
X-Kong-Upstream-Latency
Pagespeed
X-Kong-Proxy-Latency
Fastly-Restarts
Fastcgi-Useragent
X-Content-Age
X-Storage
Cache-Tags
X-FW-Dynamic
X-App-Version
X-Upgrade-Enabled
X-Hit
X-Redis-Cache
X-S
X-Esi
X-Guploader-Uploadid
X-APP-VERSION
Datacenter
X-Mode
X-Daa-Tunnel
Cache-Tag
NtCoent-Length
X-Source
Served-By
SRV
Load-Balancing
Origin-Edge-Control
Origin-Cache-Control
X-Cache-NE
Machine
Meta-Geo
X-Cache-Var-Map
X-Path-Route
X-Rule
X-Generated
X-Detected-As
X-NGENIX-Cache
X-NCache
X-Hl-Ver
X-Is-Bot
X-JoinUs
X-Internal-Host
X-RN-RSRV
X-Cache-Var
X-Backend-Name
X-Www-Served-By
X-GeoIP
X-Akamai-Request-ID
X-Web-Node
X-TNCMS
X-Hosted-By
X-Origin-Host
X-Origin-Response-Time
X-Birta-Cache-Post
X-Agile-Id
X-Agile-Age
X-L-Path
X-Labrador-Cache-Channel
X-Proxy-Build
X-Loop
X-Agile
X-Time-Microsecs
X-ProxyCache-Status
Now
X-FC-Vary-Parameters
X-Environment-Context
X-Edge-IP
X-CDN-Cache
X-Cache-Category-Id
X-BYPASS-REASON
X-Proxy
X-Birta-Served
X-ServerID
X-Tb
X-Grey
Vix-Hermes-Req-Id
X-ProxyCache-Key
X-Pubstack
X-Timing-Wait
Selected-FE
X-Status
Xserver
X-RemovedCookies
X-Human
X-ProcessESI
X-PERF
X-ApacheServer
X-Varnish-Cacheable
X-Viewer-Country
Cache-Key
X-Via-Fastly
Cache-Name
X-RateLimit-Limit
X-Pc-Appver
X-IP
X-Pc-Key
X-Pc-Hit
X-Akamai-Transformed
X-Varnish-Cache-Hits
DB-Nickname
X-OCL
X-CCM
S-Rt
X-PCL
X-Site-Version
X-Debug-Cache
Public-Key-Pins-Report-Only
X-Proxied
X-MP-GENERATED-AT
X-Original-Request
X-Routing-Service
We-Hiring
X-VG-TLSProxy
X-Xfnlog-Site
Azure-SlotName
X-Format
X-Zipkin-Id
Azure-SiteName
Azure-Version
Azure-RegionName
Mail-Subject
Azure-InstanceId
Webcakes-App-Version
Webcakes-App-Name
TWC-Privacy
Webcakes-Region
X-Access
X-Cache-Enabled
X-Origin
TWC-Locale-Group
X-Section
X-Origin-Hint
TWC-GeoIP-LatLong
Property-Id
X-App-Name
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-Country
Fastcgi-X-Cache-Version
X-UA
X-Ocache
User-Cache-Control
Access-Control-Request-Headers
S-Cnection
X-Sucuri-ID
X-Cdn-Forward
X-Microcachable
Liferay-Portal
X-Protected-By
X-Upstream-Proxy
X-Request-Time
X-EdgeConnect-Cache-Status
X-Nginx-Cache
X-CACHE-KEY
X-Tumblr-Pixel-3
X-DataStream-MidMile-RTT
X-Webstats-RespID
X-DataStream-Origin-MEX-Latency
X-FW-Version
User-Agent
X-Proto
X-FB-TRIP-ID
X-Origin-CC
X-GRACE
X-Yottaa-Metrics
X-Trace-Id
X-Dynatrace-Js-Agent
X-Yottaa-Optimizations
LB
PageSpeed
X-GEO
X-Node-Name
Ohc-File-Size
X-Nc
Cache-Hits
X-Varnish-Beresp-Grace
X-Upstream-HT
X-Upstream-CT
X-Correlation-ID
X-Varnish-Beresp-Status
Powered
X-ES-SERVER
X-Varnish-Beresp-Ttl
X-Forwarded-Host
X-Endurance-Cache-Level
Frame-Options
X-Cache-Backend
X-ElasticPress-Search
X-OVcl-Cache
X-OVcl
L5d-Success-Class
X-TIME
X-Ua
AR-SID
X-Edge-Cache
X-Edge-Cache-Key
X-Rocket-Nginx-Bypass
X-Pc-Date
X-V
X-Pc-Host
Section-Io-Cache
IBM-Web2-Location
X-Origin-TTL
X-Vgn-Hpd-Reason
X-Parent-Response-Time
Nel
X-Server-Cache
X-Unique-ID
OT-Force-Account-Verify
X-Time
X-Amz-Meta-Cache-Control
X-Cache-FS-Status
X-ARC
X-Cache-Bucket
X-Application
X-Block-Status
X-We-Are-Hiring
X-B-Cookie
X-Auto-Login
X-BB-ID
X-Cache-Host
Xc-Version
Rendered-Blocks
Fly-Cache
Fastly-SWR
Fly-Request-Id
GMS-Ver
MD5-Digest
Fastly-SIE
Ec-Rule-Version
Country-Code
Decoy-Debug-Key
Decoy-Debug-Status
Decoy-Debug-TTL
Memcached
Meta-Geo-Continent
VivaBuild
Www
X-Origin-Date
X-PAYTM-SRV-ID
Viewtype
Resin-Trace
Mobile-Detection-Method
Node
Powered-By
X-VG-WebServer
X-Accel-Expires-Debug
X-TT-LOGID
X-From
X-Fetched-On
X-Li-Fabric
X-Gen-Mode
X-Generated-In
X-External-Request-Id
X-Li-Pop
X-PHP-Host
X-Rojux
X-Distil-CS
X-DPWN-IS-SECURE
X-LI-Proto
X-Irp-Debug
Cache-Prefix
X-Region-Sid
X-Request-UUID
X-Reboot
X-IN-WAF
X-Rebelmouse-Cache-Control
X-Rewrite-Enabled
X-IN-SSL-APIGATEWAY
X-Info
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Hnp-Log
X-IN-APIGATEWAY
X-Died
X-S-Cookie
X-Trv-Group
X-Rebelmouse-Surrogate-Control
X-Transaction
X-SRCache-Key
X-Micro-Cache
X-Twitter-Response-Tags
X-UE-Client-Country
X-User
X-Cache-Info
X-Cache-URL
X-NU-AKA-ACS-Version
X-Cdn-Srv
X-CF-Lambda-Fn
X-Origin-Expires
X-Date
X-S-Maxage
X-Destination
X-LI-UUID
X-Developer
X-ScT
X-Server-By
X-CF-Lambda-Version
X-Connection-Hash
X-ServiceProvider
X-Server-Group
X-Cache-Id
X-Aed
Fastcgi-X-Cache
BehaviorPad-Version
X-Pc-Subdomain
Arc-Country
X-AWS-Id
X-VWS-Id
X-R9-Blue-Green-Version
X-LJ-Flow-ID
X-Dc
X-Cache-Grace
X-Sorting-Hat-ShopId
X-Cache-Debug
X-Cache-Expires
X-Sorting-Hat-PodId
X-Shopify-Stage
X-Sf
X-Core-Mission
X-Crawler
X-ShardId
X-ShopId
X-Stale
Mn-Server-Ip
X-SIPLIST1
X-Svr
X-A-Dcw
X-A-Dgt
X-A-Wwc
X-A-Dam
X-A-Ccd
Web-Mar-Node
X-A
X-Actual-URL
HostName
X-CUA
X-Backend-Url
X-Swa-Ws
X-Thanos
X-Thinkindot-L3
X-Alternate-Cache-Key
X-Bip
X-Debug-Cookies
X-Location
X-Logtrace-Id
X-Matched-Rule
X-Proxy-Cache-Status
X-Proxy-Upstream
X-RateLimit-Remaining-Second
X-Level-Front-Cache
X-RateLimit-Limit-Second
X-Policy
X-Nginx-Cache-Key
X-Passed-To-BeforeDispatch
X-Passed-To
Content-Disposition
X-Passed-To-DLL
X-Passed-To-PostProcessResponse
X-Node-Id
X-NX-Host
X-Request-URI
X-Hash
X-Dispatcher-Server
X-Via-NSCOPI
X-Distributor
X-Via-CDN
X-Server-IP
X-Server-Time
X-Var-Ttl
X-Debug-Log
X-Fastly-Cache
X-FireWall-Port
X-Generated-On
X-Returned-From
X-Response-By
X-Returned-From-BeforeDispatch
X-Returned-From-DLL
X-Returned-From-PostProcessResponse
X-G
X-D
X-Backend-Host
Magicmarker
X-Wikidot-Static-Cache
Lfy
SD-X-WS
X-Wikidot-Backend
Proxy-Connection
Ajk
Fastly-Backend-Name
Request-Time
Backend
Adler-Geo
Platform
Server-Host
Origin
On-Server
X-Varnish-Action
Is-Eu
X-Variation
True-Client-Country-4JS
Thinkindot-Control
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
IsBot
X-Sucuri-Cache
X-Ratelimit-Remaining
X-HS-Cache-Config
Warning
Ha-Gx-Prefs
X-Core-Value
X-Instart-Isnd
X-Croise-Owner
X-Gannett-Site-Version
X-Eu-Site
X-Epic-Correlation-Id
X-Secret
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-Idcheck
X-Fstrz
Kp-EeAlive
HA-Ipaddr
X-Generation-Time
X-CGP
X-Device-Os
Heartbleed
X-GeoIP-Country-Code
X-C
AKAMAI
X-Platform
RNT-Time
RNT-Machine
X-Backend-State
CDCHOST
Server-Cache-Control
Fastly-SSL
SS
X-UnsetCookies
X-Varnish-Authentication
Server-Surrogate-Control
Server-Int
Pagetype
X-No-Session
Cache-Cookie-Set-From
Who
X-LAGOON
X-SERVER
X-Key
X-Clientip
Pramga
Fastly-Soc-X-Request-Id
X-Cache-ASPX
GW-Server
Countrycode
X-Qloud-Router
Release
X-Cluster-Node
X-MSEdge-Flight
CACHE
X-Debug-Cache-Fetch
X-Up
X-MSEdge-Features
Server-ID
X-Amz-Meta-Surrogate-Control
X-Page-Type
X-Varnish-Url
X-Debug-Cache-Store
X-Debug-Cache-Expiry
Version
REQUESTUUID
X-F5-Cache
X-Developers
Apple-News-Services-Request-Url
X-TrackingId
PFcat
X-Cache-Miss-From
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
X-Pjax-Url
X-Sedo-Request-Id
NGX
X-Servername
Apple-News-Services-Host
X-EIG-Tracking-Id
X-Be
X-B3-Traceid
RequestId
X-Refresh
X-Store
Esi-Enabled
X-Newrelic-App-Data
X-Varnish-Ttl
X-Cache-CFC
MI-Cache-Age
MI-API
MI-Cache
X-MI-In-Market
X-Layer
X-RCS-CacheZone
SID
X-URL
X-Geo
X-CDN-Forward
X-Ratelimit-Limit
X-SN
X-Oss-Storage-Class
Time
X-Owner
X-RequestId
X-Oss-Object-Type
X-Oss-Server-Time
MIME-Version
X-From-Cache
X-IPS-LoggedIn
Cdn
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
X-B3-SpanId
X-NC
HA-Georegion
HA-Geolon
Mime-Version
HA-Geocity
HA-Cloudapp
HA-Geocountry
HA-Geolat
Odigeo-Trace-Id
HA-Host
PICS-Label
HA-Urlpath
HA-Servedtime
X-Unique-Id-Primal
X-Mrs-Cache
X-Real-Ip
X-Mrs-Cache-Hits
X-Mshield-Cache-Status
X-Mrs-Age
Cteonnt-Length
X-Hyper-Cache
X-FPC
FastCGI-Cache
HTTPS
Backend-Name
X-CMS-Context
X-Servedbyhost
Hostname
X-Webkit-CSP
X-Edge-Server
Cdn-Request-Time
X-Webkit-Csp
Processtime
X-Req
Cdn-Host
Cf-Ipcountry
CF-IPCountry
X-CLOUD-TRACE-CONTEXT
X-B3-Spanid
X-CSRF-TOKEN
X-Phone
Memory
X-WebServer
X-Instart-Info
Ohc-Response-Time
X-Aicache-OS
X-Wa
X-Request-Start
CDN
X-WR-MODIFICATION
X-Mobile-URL
X-Release
X-Pf-Uncompressing
X-Amzn-Remapped-Connection
X-HS-Combine-CSS
X-Amzn-Remapped-Date
X-Newrelic-Synthetics
GeoIP-Country-Code
X-DC
ProcessTime
X-NodeID
X-VServer
Cross-Origin-Window-Policy
GeoIP-Latitude
X-GZip
X-Load-Cache
XServer
X-Lb-Id
X-Atg-Version
X-HTML-Minification-Powered-By
X-WA
X-Skip-Cache
X-Fastly-Country-Code
X-ND-Cache
Rt-Proxy-Cache
X-Served-From
X-Varnish-Beresp-TTL
X-PF-Uncompressing
X-Unique-Id
X-Server-W
X-FORWARDED-FOR
X-GoCache-CacheStatus
Accept-Ch-Lifetime
T-Server
X-Nananana
URI
Ohc-Cache-HIT
X-Oracle-Dms-Ecid
X-VC-Cache
X-Tb-Optimization-Total-Bytes-Saved
X-ServedByHost
X-CSRF-Token
X-COUNTRY
X-Cdn-Origin
X-Sn-Servicetimems
X-LB-ID
X-MServer
X-Cms-Context
V-Age
Uber-Trace-Id
X-Gateway-Cache-Key
X-Gateway-Cache-Status
X-Gateway-Skip-Cache
N-Cache
X-UCC
Proxy-Firewall
X-SRV
Pics-Label
X-Worker
X-Datadome
X-APP
X-SVT-ORM-VERSION
X-UPSTREAM-Address
X-SVT-ORM-RULES
X-P-T
Is-Session-Tracking
Get-Access-Time
A
X-LiteSpeed-Cache-Control
X-Fastly-Cache-Hits
X-SERVER-NAME
Amp-Access-Control-Allow-Source-Origin
X-CACHE-AGE
ServerName
DataCenter
X-Check-Cacheable
X-Processor
X-HS-Status
X-RCS-Backend
X-Requestid
X-Hp-Webp
X-BBXSRF
X-GZIP
X-NGINX-Cache
X-HostName
X-BE
X-Optimization
X-ID
X-Cache-HT
Dnion-Transfer-Encoding
Geoip-Latitude
X-Backend-TTL
X-Vg-Webcache
X-Port
X-PAGE-TYPE
WZWS-RAY
X-PJAX-URL
GeoIp-Country-Code
X-Org
Requestid
X-StackifyID
X-GDPR
Cneonction
X-Fe
X-Csrf-Token
X-Varnish-URL
Serverid
X-NWS-UUID-VERIFY
X-GeoIP-City
X-VCT
X-Dw-Trace-Id
Server-Id
X-ServerName
X-Geo-Header
X-LiteSpeed-Tag
Cache-Provider
X-Via-Edge
X-Via-SSL
WP-Super-Cache
X-Git-Hash
Host-ID
RequestUuid
X-Amzn-Remapped-Content-Length
X-RAMCache
Pragrma
X-Instance-Name
225prxHost
286prxHost
352pxline
219prxHost
189phosttRef
DSUID
178proxuri
188prxHost
355prline
409pxxline
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Request-Url
X-Gdpr
Correlation-Id
Xxline
X-CS