Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
CF-RAY
ETag
Link
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Request-Id
X-Xss-Protection
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Adblock-Key
X-Check
Alt-Svc
X-Cacheable
X-Generator
Content-Security-Policy-Report-Only
X-AspNetMvc-Version
X-Cache-Status
X-DNS-Prefetch-Control
X-Permitted-Cross-Domain-Policies
X-Iinfo
X-Template
X-Language
Status
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Buckets
X-Content-Security-Policy
Content-Encoding
X-Kinja-Server-Push
Xkey
X-Turbo-Charged-By
Upgrade
X-CDN
X-Type
Keep-Alive
Access-Control-Expose-Headers
WPE-Backend
X-Pass-Why
X-AH-Environment
X-Backend
Access-Control-Max-Age
X-Age
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Server
X-Proxy-Cache
X-Request-ID
X-Via
Grace
X-Pingback
X-Nginx-Cache-Status
X-Server-Powered-By
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Hacker
X-Varnish-Cache
X-Page-Speed
X-UA-Device
EagleId
Request-Context
P3p
X-LiteSpeed-Cache
X-Envoy-Upstream-Service-Time
Cf-Railgun
X-Ua-Compatible
X-CST
X-Swift-CacheTime
X-Swift-SaveTime
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
Ali-Swift-Global-Savetime
X-Amz-Version-Id
X-WebKit-CSP
X-Server-Id
Server-Timing
Allow
X-Ac
X-Node
X-OneAgent-JS-Injection
Feature-Policy
X-Response-Time
X-Rq
X-Cnection
X-Iejgwucgyu
Content-Location
X-Backend-Server
Report-To
X-Cache-Lookup
EagleEye-TraceId
Surrogate-Control
X-Host
X-Readtime
X-Application-Context
Request-Id
X-ORACLE-DMS-ECID
X-Url
X-Rack-Cache
X-Origin-Cache
X-Clacks-Overhead
X-Country
NEL
X-FTR-Request-ID
Rating
X-Dns-Prefetch-Control
X-Country-Code
X-Cloud-Trace-Context
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-DataDome
X-Cdn
X-Ruxit-JS-Agent
X-Px
X-Mod-Pagespeed
X-Instart-Request-ID
X-Vhost
Charset
X-VARITI-CCR
X-MS-InvokeApp
Accept-CH
X-Goog-Hash
Edge-Control
X-Upstream-Env
Verso
X-GitHub-Request-Id
X-TtlSet
X-Vname
X-PC
Pinterest-Generated-By
X-Server-Name
PB-PID
Arc-Version
PB-RID
X-Mobile-Rewrite
X-ESI
X-Version
X-DynaTrace
X-Powered-By-Plesk
X-D2id
X-Kinja-Build
X-GoogleNews-Bot
X-Use-Magma
X-Kinja
X-Kinja-Revision
X-Kinja-Server
X-Exp-Id
X-Exp-Variant
X-Cdn-Fetch
X-Origin-Upstream-Status
X-Cached
X-Dispatcher
X-B3-TraceId
X-ORACLE-DMS-RID
X-Recruiting
SPRequestGuid
MS-Author-Via
X-SharePointHealthScore
X-Abt-Application-Version
X-Varnish-TTL
X-Navigation-Version
Accept-CH-Lifetime
Content-MD5
X-TTL
RTSS
AR-ATIME
AR-CACHE
AR-PoweredBy
X-Powered-CMS
X-Shield-Request-Id
X-T
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Forwarded-Proto
X-Trace
Public-Key-Pins
X-Client-IP
Arr-Disable-Session-Affinity
X-HW
X-Amz-Rid
X-Fastly-Request-ID
X-Accel-Buffering
X-Wix-Server-Artifact-Id
X-DynaTrace-JS-Agent
X-Ttl
SPIisLatency
Realpath
SPRequestDuration
X-Server-ID
AR-Request-ID
Service-Worker-Allowed
X-Oracle-Dms-Rid
X-DIS-Request-ID
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
Paypal-Debug-Id
X-Amz-Meta-S3cmd-Attrs
Front-End-Https
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-DC
X-FTR-Realm
X-FTR-Backend-Server
X-FTR-Backend
X-Country-Code-Real
X-FTR-Expires
X-Upstream
X-Ser
X-Id
X-Pinterest-Rid
Pinterest-Version
X-Via-JSL
X-B
X-XRDS-Location
Ar-Sid
X-Dw-Request-Base-Id
X-F-Cache
X-Debug
X-Vcap-Request-Id
X-Goog-Storage-Class
X-DataStream-Cache-Status
X-Varnish-Age
X-Acc-Meta-Resource-Type
X-Kinsta-Cache
X-N
X-MSEdge-Ref
Nginx-Cache
X-Hits
X-NF-Request-ID
X-FTR-Cache-Host
S
X-Akam-SW-Version
X-FastCGI-Cache
X-NewRelic-App-Data
X-Logged-In
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Forwarded-For
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
Tracecode
X-Grace
Alternate-Protocol
X-Amzn-Trace-Id
X-User-Agent
X-Frontend
X-PressLabs-Stats
X-HS-Hub-Id
X-HS-Content-Id
TCN
X-CACHE-GROUP
AMP-Access-Control-Allow-Source-Origin
X-Content-Options
Server-Name
X-Sol
X-Middleton-Display
Display
Powered-By-ChinaCache
X-Content-Digest
X-Content-Type
Refresh
Access-Control-Request-Method
X-Pad
Response
X-Middleton-Response
X-Cache-Key
Backend-Timing
X-VCache
X-Page-Id
MicrosoftSharePointTeamServices
X-Analytics
FilterID
Accept-Charset
X-Zen-Fury
X-Az
X-LB-Cache
X-IPLB-Instance
X-AppVersion
X-Activity-Id
Host
X-Rid
DynaTrace
X-Debug-Info
X-GUploader-UploadID
Fastcgi-Cache
X-CF-Powered-By
X-Hostname
ServerID
MS-CV
Cache-Status
X-Cache-Hit
X-Srv
TP-Cache
TP-L2-Cache
X-Magnolia-Registration
X-Seen-By
X-RateLimit-Remaining
X-Content-Powered-By
X-Revision
X-ATG-Version
X-Mobile
X-Cached-By
X-Request-Processing-Time
X-Request-Received
Server-Info
X-Real-IP
X-Varnish-Backend
X-WA-Info
Host-Header
X-Whom
X-SS-Set-Cookie
X-Instance
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-PHP-Backend
Surrogate-Key
Fusion-Content-Id
Fusion-Content-Source
Fusion-Source
Fusion-Component-Id
Fusion-Template-Id
X-Amz-Apigw-Id
X-B3-Sampled
X-Amzn-RequestId
X-Cluster
X-Handled-By
X-Drupal-Cache-Tags
DC
Source
X-Content-Security-Policy-Report-Only
X-Request-Guid
X-Cache-Action
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel
ViewerVersion
Cleartype
X-Wix-Request-Id
X-Platform-Server
X-Signature
X-Origin-Server
X-B-Cache
X-Akamai-Edgescape
X-TT
X-Framework
X-App-Environment
X-Cache-Age
X-App-Server
X-Fastcgi-Cache
X-FW-Serve
X-FW-Server
X-FW-Type
X-Geo-Country
X-FW-Hash
X-FW-Static
X-Generated-By
X-AOL-HN
X-Upstream-Proxy
X-Varnish-Server
X-Oneagent-Js-Injection
X-BCube-Filmed-By
Rt-Fastcgi-Cache
Server-Node
X-Cache-Control
X-XRDS-LOCATION
X-Ruxit-Js-Agent
X-Edge-Location
X-NWS-LOG-UUID
X-Varnish-Hostname
Retry-After
X-Cache-Rule
Payment
X-Varnish-Grace
X-Amz-Server-Side-Encryption
X-Cache-2
Access-Control-Allow-Method
X-Amz-Replication-Status
X-Ezoic-Cdn
X-FB-Debug
X-Correlation-Id
X-Rendered-As
X-TT-TIMESTAMP
X-UA-Device-Type
X-Response-Served-From
X-Cacheable-TTL
Actual-Object-TTL
X-Accel-Expires
X-Cache-Config
ServedBy
Webserver
X-Region
X-Contextid
X-WebKit-CSP-Report-Only
X-Jobs
X-Drupal-Cache-Contexts
X-TX-ID
X-RTag
X-Varnish-Hits
NGB
Filters
Content-Style-Type
Content-Script-Type
Healthy
X-Tumblr-Pixel-2
X-UUID
X-Tumblr-Pixel-1
HitType
Ms-Operation-Id
GEO-INFO
X-Locale
X-VG-WebCache
Upgrade-Insecure-Requests
Viewport
X-Adobe-Content
X-Adobe-Loc
X-Cache-TTL
AsisCache
Eomportal-Instance
Cache-Tv-Group
X-Varnish-IP
Fastcgi-Useragent
Country
From-Origin
X-RequestSource
Pagespeed
X-Cache-TTL-Remaining
X-TA-CDN-Provider
X-FW-Dynamic
X-BACKEND-TTL
X-Device-Type
X-Cache-Server
X-Content-Age
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Cache-Tags
X-WPE-Loopback-Upstream-Addr
Edge-Cache-Tag
X-Redis-Cache
X-APP-VERSION
X-Cache-Remote
X-Source
X-Servedby
X-DataStream-MidMile-RTT
X-DataStream-Origin-MEX-Latency
X-Upgrade-Enabled
Datacenter
X-Esi
X-Cache-Operation
NtCoent-Length
X-Hit
X-GeoIP
X-Storage
X-RateLimit-Limit
CACHE
X-Mode
Cache
Fastly-Restarts
X-Detected-As
X-Cache-Var
X-Pubstack
X-Path-Route
X-IP
X-Is-Bot
X-Loop
X-Origin-Response-Time
X-JoinUs
X-Time-Microsecs
X-Agile-Id
X-TNCMS
X-Agile-Age
Vix-Hermes-Req-Id
Machine
X-Agile
Meta-Geo
X-Akamai-Request-ID
Served-By
X-Hl-Ver
X-ES-SERVER
X-RN-RSRV
X-Cache-Var-Map
X-Backend-Name
X-Internal-Host
Load-Balancing
Cache-Tag
X-Cache-Category-Id
X-Birta-Served
X-CDN-Cache
X-Edge-IP
X-FC-Vary-Parameters
X-Environment-Context
X-Birta-Cache-Post
Selected-FE
Now
Cache-Key
Origin-Cache-Control
Origin-Edge-Control
S-Rt
X-Generated
X-L-Path
X-Varnish-Cacheable
X-Timing-Wait
X-Web-Node
X-Www-Served-By
X-Hosted-By
X-Tb
X-ServerID
X-Microcachable
X-Labrador-Cache-Channel
X-NCache
X-Origin-Host
X-Proxy-Build
X-Status
X-Grey
User-Agent
X-Varnish-Cache-Hits
Webcakes-App-Version
Webcakes-App-Name
Webcakes-Region
X-BYPASS-REASON
X-ApacheServer
TWC-Locale-Group
TWC-Connection-Speed
Property-Id
TWC-Device-Class
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Privacy
X-Format
X-ProxyCache-Status
X-ProxyCache-Key
X-Proxy
X-RemovedCookies
X-Rule
X-VG-TLSProxy
X-Via-Fastly
X-ProcessESI
X-PERF
X-Viewer-Country
X-Origin-Hint
X-Section
X-Human
SRV
X-MP-GENERATED-AT
Public-Key-Pins-Report-Only
X-CCM
X-OCL
X-Access
X-PCL
X-S
X-CACHE-KEY
X-Debug-Cache
X-Cache-Enabled
Azure-SlotName
Cache-Hits
Cache-Name
Azure-SiteName
Azure-RegionName
Access-Control-Request-Headers
Azure-InstanceId
DB-Nickname
Azure-Version
Fastcgi-X-Cache-Version
X-Xfnlog-Site
X-Site-Version
Mail-Subject
X-App-Name
Liferay-Portal
X-EdgeConnect-Cache-Status
We-Hiring
X-Zipkin-Id
X-Proxied
X-Node-Name
X-Routing-Service
X-Akamai-Transformed
X-GEO
Xserver
X-NGENIX-Cache
X-FW-Version
LB
S-Cnection
X-Protected-By
X-App-Version
X-LJ-Flow-ID
X-AWS-Id
X-Nginx-Cache
X-VWS-Id
X-Proto
X-Original-Request
X-Yottaa-Metrics
X-Sucuri-ID
X-Yottaa-Optimizations
X-Origin
PageSpeed
X-Daa-Tunnel
X-Pc-Key
Powered
X-Pc-Hit
X-Ocache
X-UA
X-Cluster-Node
X-Pc-Appver
X-Trace-Id
X-Cache-NE
X-Forwarded-Host
X-Endurance-Cache-Level
X-Request-Time
X-Varnish-Ttl
User-Cache-Control
L5d-Success-Class
X-Correlation-ID
Frame-Options
Section-Io-Cache
X-EIG-Tracking-Id
X-Tumblr-Pixel-3
Ohc-File-Size
X-Ua
X-Cdn-Forward
X-FB-TRIP-ID
X-Unique-ID
X-V
OT-Force-Account-Verify
X-Webstats-RespID
X-Nc
X-Origin-CC
AR-SID
X-Webkit-Csp
X-GRACE
X-Varnish-Beresp-Grace
X-B3-Traceid
X-OVcl
X-Guploader-Uploadid
X-OVcl-Cache
X-Varnish-Beresp-Status
X-Time
Nel
X-Origin-TTL
Decoy-Debug-Status
Decoy-Debug-Key
Hostname
Decoy-Debug-TTL
X-From
X-ElasticPress-Search
X-Via-CDN
Mobile-Detection-Method
X-Aed
X-Wikidot-Static-Cache
On-Server
Arc-Country
Powered-By
Rendered-Blocks
Node
Fastly-SWR
MD5-Digest
X-Accel-Expires-Debug
Country-Code
Fly-Cache
Ec-Rule-Version
Fly-Request-Id
VivaBuild
Fastly-SIE
Meta-Geo-Continent
GMS-Ver
Xc-Version
Www
BehaviorPad-Version
Cache-Prefix
Viewtype
SID
X-CF-Lambda-Version
X-LI-Proto
X-Transaction
X-SRCache-Key
X-LI-UUID
X-NU-AKA-ACS-Version
X-Node-Id
X-Li-Pop
X-Li-Fabric
X-IN-WAF
X-IN-APIGATEWAY
X-Trv-Group
X-Info
X-Irp-Debug
X-Origin-Date
X-Origin-Expires
X-Rewrite-Enabled
X-Response-By
X-Rojux
X-S-Cookie
X-Server-By
X-ScT
X-Request-UUID
X-Region-Sid
X-PAYTM-SRV-ID
X-ServiceProvider
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Reboot
X-TT-LOGID
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Cache-Backend
X-BB-ID
X-Cache-Grace
X-Cache-Host
X-CF-Lambda-Fn
X-Cache-URL
X-We-Are-Hiring
X-Backend-State
X-ARC
X-Application
X-Auto-Login
X-Wikidot-Backend
X-B-Cookie
X-VG-WebServer
X-Server-Group
X-Fetched-On
X-External-Request-Id
X-UE-Client-Country
X-Generated-In
X-Twitter-Response-Tags
X-DPWN-IS-SECURE
X-Distil-CS
X-Date
X-Connection-Hash
X-Destination
X-User
X-Developer
X-Amz-Meta-Cache-Control
SD-X-WS
Mn-Server-Ip
X-R9-Blue-Green-Version
X-TIME
X-Core-Mission
X-Crawler
X-D
X-Clientip
X-CGP
X-Cache-FS-Status
X-Cache-Id
X-Cache-Info
X-Cdn-Srv
X-Debug-Cookies
X-Debug-Log
X-Gen-Mode
X-Generated-On
X-GeoIP-Country-Code
X-Hash
X-Gannett-Site-Version
X-G
X-Distributor
X-Epic-Correlation-Id
X-Eu-Site
X-Cache-Expires
X-Cache-Debug
X-A-Ccd
X-A-Dam
X-A-Dcw
X-A-Dgt
X-A
Who
Thinkindot-CacheControl-Type
Thinkindot-Control
True-Client-Country-4JS
X-A-Wwc
X-Actual-URL
X-Block-Status
X-C
X-Hnp-Log
X-Bip
X-Backend-Url
X-Alternate-Cache-Key
X-SERVER
X-Backend-Host
Thinkindot-CacheControl
X-Level-Front-Cache
X-ShardId
X-ShopId
X-Shopify-Stage
X-SIPLIST1
X-Sf
X-Server-IP
X-Rocket-Nginx-Bypass
X-S-Maxage
X-Secret
X-SN
X-Sorting-Hat-PodId
X-Var-Ttl
X-Varnish-Action
X-Parent-Response-Time
X-Vgn-Hpd-Reason
X-Thinkindot-L3
X-Thanos
X-Sorting-Hat-ShopId
X-Stale
X-Swa-Ws
X-Returned-From-PostProcessResponse
X-Returned-From-DLL
X-NX-Host
X-Owner
X-Passed-To
X-Passed-To-BeforeDispatch
X-Nginx-Cache-Key
X-Micro-Cache
SS
X-Location
X-Logtrace-Id
X-Passed-To-DLL
X-Passed-To-PostProcessResponse
X-Request-URI
X-Returned-From
X-Returned-From-BeforeDispatch
X-Proxy-Upstream
X-Proxy-Cache-Status
X-PHP-Host
X-Platform
X-Policy
X-LAGOON
X-Matched-Rule
IsBot
HA-Ipaddr
Magicmarker
Memcached
Proxy-Connection
Origin
Ha-Gx-Prefs
Fastly-SSL
Backend
Ajk
Content-Disposition
Countrycode
Fastly-Soc-X-Request-Id
Fastly-Backend-Name
Request-Time
CDCHOST
Server-Host
X-HS-Cache-Config
X-Dc
NGX
IBM-Web2-Location
Warning
X-Varnish-Beresp-Ttl
RNT-Time
GW-Server
X-No-Session
Server-Cache-Control
X-Fstrz
X-MSEdge-Flight
X-MSEdge-Features
X-Fastly-Cache
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
Lfy
X-Developers
X-Device-Os
Heartbleed
Is-Eu
X-Dispatcher-Server
X-FireWall-Port
X-RateLimit-Limit-Second
Adler-Geo
Server-Int
AKAMAI
Apple-News-Services-Handled
X-Svr
X-Varnish-Authentication
X-TrackingId
X-UnsetCookies
X-Up
X-Variation
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Cache-Cookie-Set-Lfrom
X-Instart-Isnd
X-RateLimit-Remaining-Second
X-CUA
Cache-Cookie-Set-Idcheck
Odigeo-Trace-Id
Apple-News-Services-Request-Url
Server-Surrogate-Control
Cache-Cookie-Set-From
X-Qloud-Router
X-Key
Platform
X-Cache-ASPX
RNT-Machine
Release
X-Cache-Bucket
X-Amz-Meta-Surrogate-Control
Pagetype
X-Croise-Owner
Web-Mar-Node
X-Core-Value
Pramga
X-Pc-Host
X-Pc-Date
X-Pc-Subdomain
X-Sucuri-Cache
X-Sedo-Request-Id
Kp-EeAlive
Resin-Trace
X-F5-Cache
X-Server-Time
REQUESTUUID
X-Cache-Miss-From
X-Be
X-Page-Type
Server-ID
X-Servername
X-Pjax-Url
HTTPS
X-Varnish-Url
X-Upstream-HT
X-Upstream-CT
X-CDN-Forward
X-Edge-Server
X-Server-Cache
X-Newrelic-App-Data
X-IN-SSL-APIGATEWAY
Cdn-Host
Cdn-Request-Time
MIME-Version
X-NC
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
X-Oss-Object-Type
X-Oss-Request-Id
X-Generation-Time
X-Via-NSCOPI
X-Refresh
X-B3-SpanId
X-Ua-Device
X-Died
X-URL
X-Req
Fastcgi-X-Cache
RequestId
X-FPC
X-Servedbyhost
X-Mobile-URL
X-From-Cache
ProcessTime
Version
X-Amzn-Remapped-Date
PICS-Label
X-VServer
X-Load-Cache
X-Amzn-Remapped-Connection
X-NodeID
Cross-Origin-Window-Policy
FastCGI-Cache
PFcat
Cdn
HostName
X-Edge-Cache
X-GZip
Mime-Version
CF-IPCountry
X-Edge-Cache-Key
Cteonnt-Length
Time
X-CSRF-TOKEN
X-HS-Combine-CSS
Processtime
X-Webkit-CSP
X-Skip-Cache
X-CLOUD-TRACE-CONTEXT
X-Store
X-RCS-CacheZone
Memory
Uber-Trace-Id
X-Dynatrace-Js-Agent
X-Cache-CFC
Esi-Enabled
X-Ratelimit-Remaining
CDN
Ohc-Cache-HIT
X-Varnish-Beresp-TTL
X-HTML-Minification-Powered-By
X-MI-In-Market
X-Wa
MI-Cache
MI-Cache-Age
MI-API
X-Layer
X-VC-Cache
X-Lb-Id
XServer
HA-Host
HA-Georegion
HA-Geolon
X-DC
X-Cms-Context
X-Geo
X-Ratelimit-Limit
HA-Urlpath
HA-Servedtime
Cf-Ipcountry
HA-Geolat
HA-Geocountry
HA-Geocity
HA-Cloudapp
X-IPS-LoggedIn
X-Aicache-OS
X-RequestId
X-Newrelic-Synthetics
X-Pf-Uncompressing
X-Shard
X-UCC
N-Cache
X-Hyper-Cache
X-Fastly-Country-Code
X-Gateway-Cache-Status
X-Atg-Version
X-Gateway-Skip-Cache
X-WA
X-Tb-Optimization-Total-Bytes-Saved
Backend-Name
X-Gateway-Cache-Key
URI
X-Nananana
X-LB-ID
X-Processor
X-Real-Ip
X-PF-Uncompressing
X-WR-MODIFICATION
X-CMS-Context
Amp-Access-Control-Allow-Source-Origin
X-BBXSRF
X-Hp-Webp
X-Instart-Info
X-B3-Spanid
Accept-Ch-Lifetime
T-Server
X-Mrs-Cache
X-Phone
X-Mrs-Cache-Hits
X-Oracle-Dms-Ecid
X-Mrs-Age
X-Mshield-Cache-Status
X-WebServer
X-Unique-Id-Primal
Ohc-Response-Time
X-COUNTRY
GeoIP-Country-Code
X-Release
X-MServer
X-Request-Start
Pics-Label
X-APP
X-VCT
X-Amzn-Remapped-Content-Length
X-Geo-Header
X-FORWARDED-FOR
X-Unique-Id
X-GeoIP-City
X-Datadome
X-SRV
GeoIP-Latitude
X-CSRF-Token
X-Server-W
Host-ID
X-Worker
X-ServedByHost
UCS
X-VHOST
A
X-SERVER-NAME
Request-Country
X-GZIP
X-CACHE-AGE
X-HS-Status
X-LiteSpeed-Cache-Control
DataCenter
Request-EU
FSS-Proxy
Pragrma
X-Requestid
FSS-Cache
X-Fpc
X-Cache-HT
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-GoCache-CacheStatus
X-ND-Cache
X-Optimization
X-Served-From
Rt-Proxy-Cache
WP-Super-Cache
X-Planisys-CDN-TTL
X-NGINX-Cache
Dnion-Transfer-Encoding
WZWS-RAY
X-Varnish-URL
X-Fastly-Cache-Hits
Geoip-Latitude
X-Org
X-ID
X-UPSTREAM-Address
X-Check-Cacheable
X-BE
X-Vcache
X-Backend-TTL
X-Via-SSL
X-Git-Hash
X-Fastly-Backend-Reqs
X-ServerName
X-Via-Edge
X-PAGE-TYPE
Cneonction
X-Port
GeoIp-Country-Code
X-Csrf-Token
Server-Id
Requestid
X-PJAX-URL
X-Dw-Trace-Id
Serverid
X-HostName
X-Sn-Servicetimems
X-Cdn-Origin
V-Age
Cache-Provider
X-Html-Edge-Cache
X-Gen-Id
RequestUuid
X-NWS-UUID-VERIFY
X-CS
X-Gdpr
X-Request-Url
Inserted-Into-Cache-At
409pxxline
Proxy-Firewall
178proxuri
X-LiteSpeed-Tag
188prxHost
189phosttRef
X-SVT-ORM-RULES
219prxHost
352pxline
286prxHost
355prline
225prxHost
X-RAMCache
X-SVT-ORM-VERSION
Xxline