Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
CF-RAY
ETag
Link
Expect-CT
Via
X-XSS-Protection
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Xss-Protection
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Request-Id
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Adblock-Key
X-Check
Alt-Svc
X-Cacheable
X-Generator
Content-Security-Policy-Report-Only
X-AspNetMvc-Version
X-Cache-Status
X-DNS-Prefetch-Control
X-Permitted-Cross-Domain-Policies
X-Template
X-Iinfo
X-Language
Status
Timing-Allow-Origin
X-Buckets
X-FRAME-OPTIONS
X-Content-Security-Policy
Content-Encoding
X-Kinja-Server-Push
Xkey
X-CDN
X-Turbo-Charged-By
Upgrade
X-Type
Keep-Alive
Access-Control-Expose-Headers
X-Request-ID
WPE-Backend
X-Pass-Why
X-AH-Environment
X-Backend
Access-Control-Max-Age
X-Age
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Server
X-Proxy-Cache
X-Via
Grace
X-Pingback
X-Nginx-Cache-Status
X-Server-Powered-By
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Hacker
X-Varnish-Cache
X-UA-Device
X-Page-Speed
EagleId
Request-Context
X-LiteSpeed-Cache
X-Envoy-Upstream-Service-Time
Cf-Railgun
X-CST
X-Ua-Compatible
X-Swift-SaveTime
X-Swift-CacheTime
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Ali-Swift-Global-Savetime
X-Server-Id
X-Device
X-Amz-Version-Id
X-WebKit-CSP
Server-Timing
X-Ac
X-Node
Allow
X-OneAgent-JS-Injection
Feature-Policy
X-Response-Time
X-Rq
X-Cnection
X-Iejgwucgyu
Content-Location
X-Backend-Server
X-Cache-Lookup
Report-To
EagleEye-TraceId
Surrogate-Control
X-Host
X-Readtime
X-Application-Context
Request-Id
X-ORACLE-DMS-ECID
P3p
X-Rack-Cache
X-Url
X-Origin-Cache
X-Clacks-Overhead
X-Country
NEL
X-FTR-Request-ID
Rating
X-Cloud-Trace-Context
X-Country-Code
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-DataDome
X-Ruxit-JS-Agent
X-Cdn
X-Px
X-Instart-Request-ID
X-Mod-Pagespeed
Charset
X-Vhost
X-VARITI-CCR
X-MS-InvokeApp
Accept-CH
Pinterest-Generated-By
X-Goog-Hash
Edge-Control
Verso
X-GitHub-Request-Id
X-Upstream-Env
X-PC
X-TtlSet
X-Vname
X-Server-Name
X-ESI
X-Mobile-Rewrite
Arc-Version
PB-PID
PB-RID
X-Version
X-DynaTrace
X-Origin-Upstream-Status
X-Powered-By-Plesk
X-Dns-Prefetch-Control
X-D2id
X-Kinja-Revision
X-Exp-Variant
X-GoogleNews-Bot
X-Kinja
X-Kinja-Build
X-Cdn-Fetch
X-Kinja-Server
X-Use-Magma
X-Exp-Id
X-Cached
X-B3-TraceId
X-TTL
X-Dispatcher
SPRequestGuid
X-Recruiting
X-Varnish-TTL
X-SharePointHealthScore
MS-Author-Via
X-Abt-Application-Version
X-ORACLE-DMS-RID
X-Powered-CMS
Accept-CH-Lifetime
RTSS
X-Navigation-Version
Content-MD5
AR-PoweredBy
AR-ATIME
AR-CACHE
X-Shield-Request-Id
X-T
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Public-Key-Pins
X-DynaTrace-JS-Agent
X-Trace
X-Forwarded-Proto
X-Client-IP
Arr-Disable-Session-Affinity
X-Amz-Rid
X-HW
X-Fastly-Request-ID
X-Accel-Buffering
X-Wix-Server-Artifact-Id
SPIisLatency
SPRequestDuration
Realpath
X-Oracle-Dms-Rid
X-DIS-Request-ID
Service-Worker-Allowed
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Metageneration
X-Amz-Meta-S3cmd-Attrs
AR-Request-ID
Paypal-Debug-Id
Front-End-Https
X-Upstream
X-Ser
X-B
X-FTR-DC
X-FTR-Cache-Status
X-FTR-Realm
X-Country-Code-Real
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Balancer
X-Pinterest-Rid
Pinterest-Version
X-FTR-Expires
X-Ttl
X-F-Cache
X-Id
X-Via-JSL
X-Dw-Request-Base-Id
X-Vcap-Request-Id
Ar-Sid
X-Debug
X-Varnish-Age
X-XRDS-Location
X-Goog-Storage-Class
X-Acc-Meta-Resource-Type
X-Kinsta-Cache
X-MSEdge-Ref
Nginx-Cache
X-N
X-Server-ID
X-Hits
X-NF-Request-ID
X-FTR-Cache-Host
X-DataStream-Cache-Status
S
X-NewRelic-App-Data
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Logged-In
X-Akam-SW-Version
X-B3-TraceId-Primal
MRF-Tech
X-Mrf-Section-Lastmod
Mrf-Cache-Status
X-Mrf-Item-Lastmod
X-Forwarded-For
Tracecode
Alternate-Protocol
X-Frontend
X-Grace
X-User-Agent
X-HS-Hub-Id
X-PressLabs-Stats
X-HS-Content-Id
X-Amzn-Trace-Id
AMP-Access-Control-Allow-Source-Origin
TCN
Server-Name
X-Content-Options
X-Content-Digest
X-CACHE-GROUP
Refresh
X-FastCGI-Cache
Powered-By-ChinaCache
Display
X-Sol
X-Content-Type
X-Middleton-Display
Access-Control-Request-Method
X-Pad
DynaTrace
MicrosoftSharePointTeamServices
Backend-Timing
X-Analytics
X-CF-Powered-By
Accept-Charset
X-LB-Cache
X-Debug-Info
X-Rid
X-IPLB-Instance
X-Az
X-Zen-Fury
X-Activity-Id
FilterID
X-AppVersion
Host
Response
X-Middleton-Response
Fastcgi-Cache
X-Page-Id
X-Cache-Key
X-VCache
X-Fastcgi-Cache
ServerID
MS-CV
X-Hostname
Cache-Status
X-Cache-Hit
TP-Cache
TP-L2-Cache
X-Magnolia-Registration
X-Srv
X-Seen-By
X-Content-Powered-By
X-RateLimit-Remaining
X-ATG-Version
X-Mobile
X-Revision
X-Cached-By
X-WA-Info
X-Varnish-Backend
X-GUploader-UploadID
X-Request-Processing-Time
Host-Header
X-Request-Received
X-Whom
Surrogate-Key
X-B3-Sampled
X-SS-Set-Cookie
X-Instance
VIX-Pulpo-Node
Server-Info
VIX-Pulpo-Upstream-Status
X-Cluster
X-Cache-Action
DC
X-Platform-Server
Source
X-Request-Guid
X-Handled-By
X-Tumblr-Pixel
X-Tumblr-User
X-Drupal-Cache-Tags
X-Tumblr-Pixel-0
X-Content-Security-Policy-Report-Only
X-B-Cache
X-Signature
Cleartype
X-Real-IP
X-Wix-Request-Id
X-PHP-Backend
ViewerVersion
X-Framework
X-TT
X-Origin-Server
X-Akamai-Edgescape
Fusion-Template-Id
Fusion-Source
Fusion-Content-Source
Fusion-Component-Id
X-Amzn-RequestId
Fusion-Content-Id
X-Cache-Age
X-Amz-Apigw-Id
X-App-Environment
X-XRDS-LOCATION
X-Geo-Country
Rt-Fastcgi-Cache
X-App-Server
X-FW-Serve
X-FW-Static
X-FW-Hash
X-Generated-By
X-FW-Type
X-FW-Server
X-AOL-HN
X-BCube-Filmed-By
X-Varnish-Server
X-Cache-Control
Server-Node
X-Oneagent-Js-Injection
X-Edge-Location
X-TA-CDN-Provider
X-NWS-LOG-UUID
X-Cache-Rule
X-Varnish-Hostname
Retry-After
X-Ruxit-Js-Agent
X-Upstream-Proxy
Payment
X-Correlation-Id
X-Amz-Server-Side-Encryption
X-Varnish-Grace
X-Cache-2
X-Amz-Replication-Status
Access-Control-Allow-Method
X-FB-Debug
Eomportal-Instance
X-Response-Served-From
X-TT-TIMESTAMP
Pagespeed
ServedBy
GEO-INFO
X-Ezoic-Cdn
X-Cache-Config
X-Cacheable-TTL
AsisCache
X-Tumblr-Pixel-1
X-UA-Device-Type
Webserver
X-Varnish-Hits
X-Tumblr-Pixel-2
Actual-Object-TTL
Filters
Content-Script-Type
Healthy
Content-Style-Type
Ms-Operation-Id
X-Contextid
NGB
X-TX-ID
X-Drupal-Cache-Contexts
X-Region
X-WebKit-CSP-Report-Only
X-RTag
X-Jobs
X-UUID
X-Varnish-IP
X-VG-WebCache
Upgrade-Insecure-Requests
X-Adobe-Loc
Viewport
X-Adobe-Content
X-Rendered-As
X-Locale
From-Origin
Country
Cache-Tv-Group
X-RequestSource
X-Cache-TTL
HitType
X-Accel-Expires
Fastcgi-Useragent
X-Cache-TTL-Remaining
X-Device-Type
X-BACKEND-TTL
X-FW-Dynamic
X-Cache-Server
X-Servedby
Edge-Cache-Tag
X-Content-Age
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-WPE-Loopback-Upstream-Addr
Cache
Cache-Tags
X-Cache-Remote
X-Redis-Cache
X-Upgrade-Enabled
X-APP-VERSION
X-Cache-Operation
X-Source
Datacenter
X-Hit
X-DataStream-Origin-MEX-Latency
X-Storage
X-DataStream-MidMile-RTT
X-Esi
Fastly-Restarts
X-CACHE-KEY
X-GeoIP
X-RateLimit-Limit
X-Mode
NtCoent-Length
Cache-Tag
X-S
Served-By
Xserver
X-Agile
X-Labrador-Cache-Channel
X-Path-Route
Vix-Hermes-Req-Id
X-Agile-Id
X-Hl-Ver
X-Time-Microsecs
Meta-Geo
X-Loop
X-Detected-As
X-Agile-Age
X-Akamai-Request-ID
X-Is-Bot
X-TNCMS
X-Backend-Name
X-Cache-Var-Map
X-JoinUs
X-Internal-Host
X-Pubstack
Load-Balancing
X-Origin-Response-Time
X-RN-RSRV
Machine
X-Cache-Var
X-NGENIX-Cache
X-Edge-IP
X-Timing-Wait
X-Status
Cache-Key
X-Origin-Host
X-FC-Vary-Parameters
X-Environment-Context
X-Varnish-Cacheable
Selected-FE
X-L-Path
X-ProxyCache-Key
X-ProxyCache-Status
X-Hosted-By
X-Cache-Category-Id
X-Proxy-Build
X-NCache
X-BYPASS-REASON
X-Proxy
X-Birta-Cache-Post
X-Rule
X-Tb
Now
X-Grey
Origin-Cache-Control
X-Www-Served-By
X-Birta-Served
X-ServerID
X-CDN-Cache
X-Generated
Origin-Edge-Control
X-Varnish-Cache-Hits
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Locale-Group
Webcakes-App-Version
Webcakes-App-Name
TWC-Device-Class
SRV
X-Microcachable
X-IP
S-Rt
Property-Id
Webcakes-Region
TWC-Connection-Speed
X-Web-Node
X-ProcessESI
X-Format
X-PERF
X-Origin-Hint
X-Guploader-Uploadid
X-RemovedCookies
X-Cache-Enabled
X-ApacheServer
X-Viewer-Country
X-Via-Fastly
X-VG-TLSProxy
Cache-Name
TWC-Privacy
X-Access
DB-Nickname
Access-Control-Request-Headers
Azure-InstanceId
Azure-RegionName
X-Section
X-CCM
X-OCL
X-MP-GENERATED-AT
X-PCL
X-Human
Public-Key-Pins-Report-Only
X-Akamai-Transformed
Azure-SlotName
Azure-SiteName
Azure-Version
Fastcgi-X-Cache-Version
Mail-Subject
X-App-Name
User-Agent
X-Routing-Service
X-Debug-Cache
X-Xfnlog-Site
X-Proxied
X-App-Version
X-Site-Version
We-Hiring
X-Zipkin-Id
Cache-Hits
X-Daa-Tunnel
X-ES-SERVER
Liferay-Portal
X-GEO
X-Node-Name
S-Cnection
X-Protected-By
LB
X-Original-Request
X-Origin
X-EdgeConnect-Cache-Status
X-FW-Version
X-Sucuri-ID
X-Pc-Key
X-Cache-NE
X-Pc-Hit
X-Pc-Appver
X-Nginx-Cache
X-Cdn-Forward
X-Proto
CACHE
X-Ocache
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Trace-Id
User-Cache-Control
X-Request-Time
Powered
X-VWS-Id
X-Ua
X-AWS-Id
X-Forwarded-Host
X-LJ-Flow-ID
X-UA
X-Tumblr-Pixel-3
X-Endurance-Cache-Level
X-GRACE
X-Nc
X-Varnish-Ttl
Ohc-File-Size
L5d-Success-Class
Frame-Options
X-Cluster-Node
Section-Io-Cache
X-Webstats-RespID
X-Correlation-ID
X-FB-TRIP-ID
X-V
X-Origin-CC
X-Time
X-Unique-ID
PageSpeed
OT-Force-Account-Verify
X-EIG-Tracking-Id
X-URL
X-OVcl
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
X-OVcl-Cache
X-Webkit-Csp
X-B3-Traceid
X-Origin-TTL
AR-SID
X-From
X-ElasticPress-Search
Nel
Decoy-Debug-TTL
Decoy-Debug-Key
X-Cache-Backend
Decoy-Debug-Status
X-R9-Blue-Green-Version
X-Rocket-Nginx-Bypass
Fastly-SIE
X-Connection-Hash
X-Developer
X-Destination
Fastly-SWR
Fly-Request-Id
GMS-Ver
X-UE-Client-Country
X-Twitter-Response-Tags
X-Node-Id
X-User
Ec-Rule-Version
Fly-Cache
X-NU-AKA-ACS-Version
X-Date
X-VG-WebServer
X-Wikidot-Static-Cache
Cache-Prefix
X-IN-APIGATEWAY
X-IN-WAF
X-Info
X-External-Request-Id
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Generated-In
X-Fetched-On
BehaviorPad-Version
X-Irp-Debug
X-DPWN-IS-SECURE
X-Origin-Date
X-Wikidot-Backend
X-LI-Proto
X-We-Are-Hiring
X-Li-Pop
X-Li-Fabric
X-Distil-CS
Country-Code
Xc-Version
X-LI-UUID
X-PAYTM-SRV-ID
X-Request-UUID
X-Amz-Meta-Cache-Control
X-Response-By
X-Aed
Rendered-Blocks
Powered-By
X-Application
X-Auto-Login
X-Reboot
X-Region-Sid
X-ARC
X-Accel-Expires-Debug
X-ServiceProvider
X-S-Maxage
Viewtype
X-S-Cookie
X-Rojux
X-Rewrite-Enabled
X-ScT
VivaBuild
Www
X-Server-Group
X-Server-By
SD-X-WS
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Trv-Group
X-PHP-Host
X-Transaction
X-Cache-Info
X-Cache-Id
Arc-Country
X-Cache-URL
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-Cdn-Srv
X-TT-LOGID
X-Cache-Host
X-Cache-Grace
Mobile-Detection-Method
X-Backend-State
Node
On-Server
X-B-Cookie
X-BB-ID
X-SRCache-Key
X-Cache-FS-Status
MD5-Digest
Memcached
Meta-Geo-Continent
X-Origin-Expires
IBM-Web2-Location
X-Dc
X-Proxy-Cache-Status
X-Sorting-Hat-PodId
X-Backend-Url
X-Proxy-Upstream
X-Backend-Host
X-SIPLIST1
X-RateLimit-Remaining-Second
X-Sorting-Hat-ShopId
X-RateLimit-Limit-Second
X-Stale
X-Cache-Bucket
X-Cache-Debug
X-Cache-Expires
X-C
X-Block-Status
X-Bip
Thinkindot-CacheControl
X-Policy
X-Request-URI
X-Shopify-Stage
Who
X-Secret
X-Server-IP
X-A
X-Returned-From-BeforeDispatch
X-Returned-From-DLL
Thinkindot-CacheControl-Type
Thinkindot-Control
True-Client-Country-4JS
X-A-Ccd
X-A-Dcw
X-ShardId
X-Alternate-Cache-Key
X-ShopId
X-Actual-URL
X-Returned-From
X-A-Dgt
X-A-Wwc
X-Sf
X-Svr
X-Swa-Ws
X-Dispatcher-Server
X-Returned-From-PostProcessResponse
X-Level-Front-Cache
X-Distributor
X-Location
X-Vgn-Hpd-Reason
X-Debug-Log
X-Matched-Rule
X-Logtrace-Id
X-LAGOON
X-Hnp-Log
X-Generated-On
X-Gen-Mode
X-G
X-Fastly-Cache
X-GeoIP-Country-Code
X-Epic-Correlation-Id
X-Eu-Site
X-Hash
X-Debug-Cookies
X-Micro-Cache
X-Passed-To-BeforeDispatch
X-Passed-To
X-CGP
X-Passed-To-DLL
X-Passed-To-PostProcessResponse
X-Thanos
X-Platform
X-Thinkindot-L3
X-Clientip
X-NX-Host
X-Var-Ttl
X-Variation
X-Varnish-Action
X-D
X-CUA
X-Core-Mission
X-Crawler
X-Nginx-Cache-Key
X-Gannett-Site-Version
X-A-Dam
Origin
Countrycode
Magicmarker
Content-Disposition
Platform
Request-Time
Proxy-Connection
Lfy
Fastly-Backend-Name
HA-Ipaddr
Adler-Geo
Ha-Gx-Prefs
Is-Eu
Fastly-SSL
Fastly-Soc-X-Request-Id
IsBot
Backend
CDCHOST
Mn-Server-Ip
X-Varnish-Beresp-Ttl
Ajk
X-Via-CDN
Server-Host
X-Parent-Response-Time
X-Sucuri-Cache
X-TIME
Warning
X-HS-Cache-Config
Hostname
X-Debug-Cache-Expiry
X-TrackingId
Cache-Cookie-Set-From
X-F5-Cache
X-Debug-Cache-Fetch
X-MSEdge-Features
X-Croise-Owner
GW-Server
X-No-Session
X-MSEdge-Flight
X-Instart-Isnd
X-Debug-Cache-Store
Cache-Cookie-Set-Idcheck
X-Developers
X-Device-Os
X-Fstrz
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Handled
Cache-Cookie-Set-Lfrom
AKAMAI
X-Core-Value
X-FireWall-Port
Apple-News-Services-Request-Url
X-Qloud-Router
X-Up
SID
X-Cache-ASPX
Server-Cache-Control
SS
RNT-Time
Pramga
X-Amz-Meta-Surrogate-Control
Release
RNT-Machine
X-Varnish-Authentication
Web-Mar-Node
Server-Surrogate-Control
X-SERVER
Server-Int
X-UnsetCookies
Heartbleed
X-Pc-Subdomain
X-Pc-Host
X-Pc-Date
X-Upstream-HT
X-Upstream-CT
REQUESTUUID
Server-ID
Resin-Trace
Pagetype
Kp-EeAlive
X-Owner
X-SN
NGX
X-Page-Type
X-Server-Time
X-Varnish-Url
X-Key
X-Be
X-Server-Cache
X-Pjax-Url
X-Sedo-Request-Id
X-Servername
Odigeo-Trace-Id
X-IN-SSL-APIGATEWAY
X-Cache-Miss-From
X-Generation-Time
X-Via-NSCOPI
Fastcgi-X-Cache
HTTPS
X-Died
X-Refresh
X-Newrelic-App-Data
X-Edge-Server
X-Oss-Storage-Class
X-Oss-Request-Id
X-Oss-Object-Type
Cdn-Request-Time
RequestId
X-From-Cache
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
Cdn-Host
X-Edge-Cache-Key
X-Edge-Cache
X-CDN-Forward
MIME-Version
Version
HostName
X-B3-SpanId
X-NC
Mime-Version
X-Servedbyhost
X-FPC
PFcat
ProcessTime
Cdn
Time
Cteonnt-Length
PICS-Label
X-Req
X-Mobile-URL
X-Ratelimit-Remaining
FastCGI-Cache
X-Cache-CFC
X-NodeID
X-Amzn-Remapped-Date
X-VServer
X-CSRF-TOKEN
Cross-Origin-Window-Policy
Esi-Enabled
X-Store
X-Amzn-Remapped-Connection
X-GZip
X-Load-Cache
X-MI-In-Market
MI-API
MI-Cache
Memory
MI-Cache-Age
X-RCS-CacheZone
X-Hyper-Cache
X-Layer
X-Webkit-CSP
X-HS-Combine-CSS
Processtime
X-CLOUD-TRACE-CONTEXT
CF-IPCountry
X-Geo
X-Ratelimit-Limit
X-Wa
HA-Host
HA-Geocity
HA-Geocountry
HA-Geolat
X-Dynatrace-Js-Agent
HA-Cloudapp
X-IPS-LoggedIn
X-Skip-Cache
HA-Geolon
Cf-Ipcountry
HA-Georegion
HA-Urlpath
X-RequestId
HA-Servedtime
X-Varnish-Beresp-TTL
Uber-Trace-Id
X-Lb-Id
X-HTML-Minification-Powered-By
Ohc-Cache-HIT
CDN
Backend-Name
X-Pf-Uncompressing
X-B3-Spanid
X-Newrelic-Synthetics
X-DC
X-VC-Cache
X-Cms-Context
X-Aicache-OS
X-Real-Ip
X-CMS-Context
X-Fastly-Country-Code
XServer
X-UCC
X-WA
N-Cache
X-Gateway-Skip-Cache
X-Gateway-Cache-Key
X-Gateway-Cache-Status
X-Mrs-Age
X-Unique-Id-Primal
X-Mshield-Cache-Status
X-Mrs-Cache-Hits
X-Atg-Version
X-PF-Uncompressing
X-Instart-Info
X-Tb-Optimization-Total-Bytes-Saved
X-WR-MODIFICATION
X-Mrs-Cache
X-Phone
X-WebServer
Ohc-Response-Time
X-Shard
Amp-Access-Control-Allow-Source-Origin
X-Request-Start
Accept-Ch-Lifetime
X-Release
T-Server
X-Nananana
X-Processor
URI
X-LB-ID
GeoIP-Country-Code
X-Server-W
X-Oracle-Dms-Ecid
GeoIP-Latitude
X-BBXSRF
X-Hp-Webp
Pics-Label
X-Unique-Id
X-CSRF-Token
X-COUNTRY
X-MServer
X-Worker
X-Datadome
X-FORWARDED-FOR
X-ServedByHost
X-APP
X-SRV
X-VCT
A
X-LiteSpeed-Cache-Control
Host-ID
X-Amzn-Remapped-Content-Length
X-ND-Cache
X-Geo-Header
X-GeoIP-City
Rt-Proxy-Cache
X-GoCache-CacheStatus
X-VHOST
X-Served-From
X-SERVER-NAME
UCS
X-HS-Status
DataCenter
X-CACHE-AGE
X-Check-Cacheable
X-Fastly-Cache-Hits
X-GZIP
X-Cache-HT
X-Optimization
X-UPSTREAM-Address
Request-EU
Request-Country
X-Requestid
X-NGINX-Cache
X-Cdn-Origin
Geoip-Latitude
Dnion-Transfer-Encoding
Cneonction
X-Sn-Servicetimems
Pragrma
FSS-Proxy
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-ID
X-Planisys-CDN-TTL
X-Fpc
FSS-Cache
X-Vcache
V-Age
X-BE
X-Fastly-Backend-Reqs
X-Backend-TTL
X-PAGE-TYPE
WZWS-RAY
Proxy-Firewall
X-Varnish-URL
X-Git-Hash
X-Dw-Trace-Id
X-SVT-ORM-RULES
Requestid
X-ServerName
X-Org
X-Port
X-Csrf-Token
X-PJAX-URL
X-SVT-ORM-VERSION
GeoIp-Country-Code
WP-Super-Cache
Serverid
X-Gen-Id
X-Via-Edge
Cache-Provider
X-Via-SSL
X-LiteSpeed-Tag
X-HostName
RequestUuid
Get-Access-Time
X-P-T
Server-Id
Is-Session-Tracking
X-NWS-UUID-VERIFY
188prxHost
X-Html-Edge-Cache
189phosttRef
178proxuri
DSUID
219prxHost
X-StackifyID
X-HTML-Edge-Cache
X-Fe
355prline
X-Request-Url
Inserted-Into-Cache-At
X-CS
X-RAMCache
Xxline
409pxxline
286prxHost
352pxline
ServerName
225prxHost