Threat Level: green Handler on Duty: Rob VandenBrink

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
CF-RAY
ETag
Link
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Request-Id
X-Xss-Protection
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Adblock-Key
X-Check
Alt-Svc
X-Cacheable
X-Generator
Content-Security-Policy-Report-Only
X-Cache-Status
X-AspNetMvc-Version
X-DNS-Prefetch-Control
X-Permitted-Cross-Domain-Policies
X-Template
X-Iinfo
X-Language
Status
Timing-Allow-Origin
X-Buckets
X-Content-Security-Policy
Content-Encoding
X-CDN
X-Kinja-Server-Push
Xkey
X-Turbo-Charged-By
Upgrade
X-Type
Keep-Alive
Access-Control-Expose-Headers
WPE-Backend
X-Pass-Why
Access-Control-Max-Age
X-Backend
X-AH-Environment
X-Ua-Compatible
X-Age
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Server
X-Request-ID
X-Via
X-Proxy-Cache
Grace
X-Pingback
X-Nginx-Cache-Status
X-Server-Powered-By
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Hacker
X-UA-Device
X-Varnish-Cache
X-Page-Speed
EagleId
Request-Context
P3p
X-LiteSpeed-Cache
Cf-Railgun
X-Envoy-Upstream-Service-Time
X-CST
X-Swift-SaveTime
X-Swift-CacheTime
X-WebKit-CSP
Ali-Swift-Global-Savetime
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
X-Server-Id
X-Amz-Version-Id
X-Ac
Server-Timing
X-Node
X-OneAgent-JS-Injection
Allow
Feature-Policy
X-Cnection
X-Iejgwucgyu
X-Response-Time
X-Rq
Content-Location
X-Cache-Lookup
X-Backend-Server
Report-To
EagleEye-TraceId
Surrogate-Control
X-Readtime
X-Host
X-Application-Context
Request-Id
X-ORACLE-DMS-ECID
X-Url
X-Rack-Cache
X-Origin-Cache
X-Clacks-Overhead
X-Country
NEL
X-FTR-Request-ID
Rating
X-Country-Code
X-Cloud-Trace-Context
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-DataDome
X-Instart-Request-ID
X-Ruxit-JS-Agent
X-Px
X-Vhost
X-MS-InvokeApp
X-Mod-Pagespeed
Charset
X-VARITI-CCR
Accept-CH
Edge-Control
X-Goog-Hash
Verso
X-GitHub-Request-Id
Pinterest-Generated-By
PB-PID
PB-RID
Arc-Version
X-Mobile-Rewrite
X-ESI
X-PC
X-TtlSet
X-Vname
X-Version
X-Dns-Prefetch-Control
X-DynaTrace
X-Server-Name
X-Cdn
X-Varnish-TTL
X-B3-TraceId
X-Powered-By-Plesk
X-D2id
X-Exp-Id
X-TTL
X-Exp-Variant
X-Kinja-Server
X-Kinja-Revision
X-Cdn-Fetch
X-Use-Magma
X-Kinja-Build
X-Kinja
X-Cached
X-GoogleNews-Bot
X-Upstream-Env
X-Origin-Upstream-Status
X-Dispatcher
X-ORACLE-DMS-RID
SPRequestGuid
X-SharePointHealthScore
X-Powered-CMS
X-Abt-Application-Version
X-Recruiting
MS-Author-Via
X-T
RTSS
Accept-CH-Lifetime
X-Navigation-Version
X-Shield-Request-Id
Public-Key-Pins
X-Trace
Content-MD5
AR-PoweredBy
AR-ATIME
AR-CACHE
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Client-IP
X-Amz-Rid
SPRequestDuration
SPIisLatency
X-HW
X-Fastly-Request-ID
X-Wix-Server-Artifact-Id
Arr-Disable-Session-Affinity
X-Accel-Buffering
X-Forwarded-Proto
X-DIS-Request-ID
Realpath
X-DynaTrace-JS-Agent
X-Server-ID
X-B
X-Oracle-Dms-Rid
X-F-Cache
X-Upstream
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Amz-Meta-S3cmd-Attrs
Service-Worker-Allowed
X-Via-JSL
X-Ser
X-Pinterest-Rid
Pinterest-Version
X-FTR-Backend
X-FTR-Realm
X-Country-Code-Real
X-FTR-DC
X-FTR-Balancer
Paypal-Debug-Id
X-FTR-Cache-Status
X-Id
Front-End-Https
X-FTR-Backend-Server
AR-Request-ID
X-FTR-Expires
X-Dw-Request-Base-Id
X-Ttl
X-Vcap-Request-Id
X-Varnish-Age
X-Debug
X-Acc-Meta-Resource-Type
X-Goog-Storage-Class
Ar-Sid
X-MSEdge-Ref
Nginx-Cache
X-XRDS-Location
X-Kinsta-Cache
X-Hits
X-N
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-NF-Request-ID
X-FTR-Cache-Host
X-NewRelic-App-Data
X-Logged-In
S
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
X-Akam-SW-Version
X-DataStream-Cache-Status
X-Forwarded-For
X-Frontend
X-PressLabs-Stats
Alternate-Protocol
X-User-Agent
X-HS-Content-Id
X-HS-Hub-Id
Tracecode
X-CACHE-GROUP
X-Amzn-Trace-Id
X-FastCGI-Cache
AMP-Access-Control-Allow-Source-Origin
X-Grace
Server-Name
DynaTrace
X-Content-Digest
X-Pad
X-Content-Options
Refresh
Powered-By-ChinaCache
Backend-Timing
X-Content-Type
X-Analytics
MicrosoftSharePointTeamServices
Accept-Charset
X-LB-Cache
X-Zen-Fury
TCN
X-Debug-Info
Display
X-Az
X-Sol
X-Middleton-Display
X-AppVersion
X-Activity-Id
Fastcgi-Cache
FilterID
X-Rid
Access-Control-Request-Method
Host
X-Page-Id
X-IPLB-Instance
MS-CV
X-CF-Powered-By
X-TA-CDN-Provider
ServerID
X-Cache-Key
X-Magnolia-Registration
Cache-Status
X-Middleton-Response
Response
TP-Cache
TP-L2-Cache
X-Cache-Hit
X-Content-Powered-By
X-Hostname
X-ATG-Version
X-Seen-By
X-Mobile
X-RateLimit-Remaining
X-Srv
X-WA-Info
X-Fastcgi-Cache
Surrogate-Key
X-GUploader-UploadID
X-Revision
X-B3-Sampled
X-Cached-By
X-Request-Received
X-Request-Processing-Time
X-Varnish-Backend
Rt-Fastcgi-Cache
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-SS-Set-Cookie
X-Cache-Action
X-Instance
X-B-Cache
X-Cluster
X-Signature
Host-Header
X-Tumblr-Pixel
X-Drupal-Cache-Tags
X-Content-Security-Policy-Report-Only
X-Platform-Server
X-Tumblr-Pixel-0
X-Tumblr-User
X-Request-Guid
X-Wix-Request-Id
X-XRDS-LOCATION
X-PHP-Backend
ViewerVersion
Cleartype
Source
X-Cache-Age
X-Whom
X-VCache
X-Handled-By
X-TT
X-Framework
X-Akamai-Edgescape
X-Origin-Server
X-App-Environment
Server-Info
X-Edge-Location
X-Cache-Control
DC
X-Real-IP
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Oneagent-Js-Injection
X-BCube-Filmed-By
X-Generated-By
X-Geo-Country
X-App-Server
X-FW-Server
X-FW-Static
X-FW-Type
X-Cache-Rule
X-NWS-LOG-UUID
X-FW-Serve
X-FW-Hash
X-AOL-HN
Server-Node
X-Varnish-Hostname
X-Ruxit-Js-Agent
X-Varnish-Server
Fusion-Source
Fusion-Content-Source
Fusion-Template-Id
Fusion-Content-Id
Fusion-Component-Id
Retry-After
X-Cache-2
Eomportal-Instance
X-Correlation-Id
Payment
X-FB-Debug
X-Amz-Server-Side-Encryption
X-Varnish-Grace
X-TT-TIMESTAMP
Actual-Object-TTL
X-Response-Served-From
Webserver
Access-Control-Allow-Method
X-Tumblr-Pixel-1
GEO-INFO
X-Varnish-Hits
X-Tumblr-Pixel-2
ServedBy
X-Cacheable-TTL
Healthy
Content-Style-Type
X-Region
X-Drupal-Cache-Contexts
Ms-Operation-Id
X-Amz-Replication-Status
Filters
NGB
X-RTag
AsisCache
X-Jobs
X-UUID
X-Device-Type
Content-Script-Type
X-TX-ID
X-WebKit-CSP-Report-Only
Viewport
X-Cache-Config
X-Varnish-IP
Cache
X-Adobe-Loc
Upgrade-Insecure-Requests
X-Contextid
X-Adobe-Content
X-Servedby
X-WPE-Loopback-Upstream-Addr
Country
X-Locale
X-RequestSource
X-Rendered-As
X-Accel-Expires
From-Origin
Cache-Tv-Group
X-UA-Device-Type
X-Ezoic-Cdn
HitType
Edge-Cache-Tag
X-BACKEND-TTL
X-Cache-TTL-Remaining
X-Cache-Server
X-Cache-TTL
Pagespeed
X-VG-WebCache
X-Cache-Remote
Fastcgi-Useragent
X-Cache-Operation
X-FW-Dynamic
X-Content-Age
X-Kong-Proxy-Latency
Fastly-Restarts
X-Kong-Upstream-Latency
X-Hit
X-Upgrade-Enabled
Cache-Tags
X-CACHE-KEY
X-Esi
X-Redis-Cache
X-APP-VERSION
X-Storage
X-Source
X-S
X-RateLimit-Limit
X-App-Version
X-Upstream-Proxy
Datacenter
X-Mode
Cache-Tag
Served-By
X-Detected-As
X-Internal-Host
Origin-Cache-Control
X-Akamai-Transformed
Meta-Geo
X-Cache-Var-Map
Origin-Edge-Control
X-RN-RSRV
X-NGENIX-Cache
X-JoinUs
X-Generated
X-Tb
X-Hl-Ver
Machine
X-Akamai-Request-ID
X-Path-Route
SRV
X-NCache
X-Origin-Response-Time
X-Cache-Var
X-Backend-Name
Load-Balancing
X-Daa-Tunnel
Vix-Hermes-Req-Id
X-GeoIP
NtCoent-Length
X-Is-Bot
Selected-FE
X-ProxyCache-Key
Now
X-Loop
X-Origin-Host
X-Proxy
Cache-Key
X-Proxy-Build
X-L-Path
X-Grey
X-Agile-Id
X-Agile-Age
X-Web-Node
X-Varnish-Cacheable
X-Www-Served-By
X-Labrador-Cache-Channel
X-Birta-Cache-Post
X-Time-Microsecs
X-Birta-Served
X-BYPASS-REASON
X-Agile
X-TNCMS
X-ServerID
X-Rule
X-Hosted-By
X-Pubstack
X-FC-Vary-Parameters
X-Timing-Wait
X-CDN-Cache
X-Edge-IP
X-Environment-Context
X-ProxyCache-Status
X-Cache-Category-Id
Xserver
X-Varnish-Cache-Hits
TWC-GeoIP-LatLong
TWC-GeoIP-Country
X-Viewer-Country
TWC-Device-Class
X-Via-Fastly
Cache-Name
X-Pc-Key
Webcakes-Region
Webcakes-App-Name
X-ApacheServer
TWC-Locale-Group
TWC-Privacy
X-Format
X-Status
X-ProcessESI
X-Origin-Hint
X-PERF
X-PCL
X-Pc-Hit
X-Pc-Appver
X-OCL
X-DataStream-MidMile-RTT
X-IP
Property-Id
TWC-Connection-Speed
X-DataStream-Origin-MEX-Latency
X-RemovedCookies
Webcakes-App-Version
X-Debug-Cache
X-VG-TLSProxy
X-Site-Version
X-Section
X-CCM
S-Rt
X-Human
X-Cache-Enabled
X-Cache-NE
X-Access
Azure-SlotName
Azure-Version
Azure-SiteName
Azure-RegionName
Azure-InstanceId
DB-Nickname
Fastcgi-X-Cache-Version
Public-Key-Pins-Report-Only
Mail-Subject
X-MP-GENERATED-AT
X-Proxied
X-Routing-Service
We-Hiring
X-Xfnlog-Site
X-Zipkin-Id
X-App-Name
X-Original-Request
Access-Control-Request-Headers
X-Microcachable
X-GRACE
X-Origin
X-Sucuri-ID
User-Cache-Control
X-EdgeConnect-Cache-Status
X-Ocache
S-Cnection
X-Guploader-Uploadid
X-GEO
X-Protected-By
Liferay-Portal
X-Request-Time
X-Cdn-Forward
X-Nginx-Cache
X-FW-Version
User-Agent
Cache-Hits
X-UA
LB
X-Node-Name
X-Proto
X-Tumblr-Pixel-3
X-Webstats-RespID
X-ES-SERVER
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-FB-TRIP-ID
X-Trace-Id
X-Correlation-ID
Ohc-File-Size
X-Origin-CC
X-Nc
X-Ua
Powered
X-Time
X-Unique-ID
X-Endurance-Cache-Level
X-Forwarded-Host
PageSpeed
L5d-Success-Class
Frame-Options
Section-Io-Cache
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
AR-SID
X-Upstream-CT
X-Parent-Response-Time
X-Upstream-HT
X-Pc-Subdomain
IBM-Web2-Location
X-OVcl-Cache
X-V
X-OVcl
X-Pc-Date
X-Pc-Host
X-Cache-Backend
X-Origin-TTL
X-VWS-Id
X-Rocket-Nginx-Bypass
X-AWS-Id
X-LJ-Flow-ID
X-Varnish-Beresp-Ttl
Nel
X-ElasticPress-Search
OT-Force-Account-Verify
X-R9-Blue-Green-Version
CACHE
X-Cluster-Node
X-Vgn-Hpd-Reason
Fly-Cache
X-Application
Fastly-SWR
X-Generated-In
X-NU-AKA-ACS-Version
X-Aed
X-Server-Cache
Www
Fly-Request-Id
X-Gen-Mode
X-Origin-Expires
X-Accel-Expires-Debug
X-Server-Group
X-Amz-Meta-Cache-Control
X-ARC
X-Origin-Date
X-Rewrite-Enabled
Cache-Prefix
X-Irp-Debug
Country-Code
Decoy-Debug-Key
Decoy-Debug-Status
X-Info
X-IN-WAF
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Hnp-Log
Arc-Country
X-IN-APIGATEWAY
X-IN-SSL-APIGATEWAY
X-Li-Fabric
X-Li-Pop
X-Rojux
X-Auto-Login
Fastly-SIE
GMS-Ver
X-Server-By
Ec-Rule-Version
X-ScT
X-LI-Proto
X-LI-UUID
Decoy-Debug-TTL
X-S-Cookie
X-Micro-Cache
X-PHP-Host
X-CF-Lambda-Fn
X-Date
X-CF-Lambda-Version
X-User
X-Transaction
Rendered-Blocks
X-Reboot
X-We-Are-Hiring
X-VG-WebServer
MD5-Digest
Memcached
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Twitter-Response-Tags
X-TT-LOGID
Node
BehaviorPad-Version
X-UE-Client-Country
Mobile-Detection-Method
Meta-Geo-Continent
Powered-By
X-Trv-Group
X-Connection-Hash
X-Destination
X-Wikidot-Backend
X-Request-UUID
X-External-Request-Id
X-SRCache-Key
X-BB-ID
X-Block-Status
X-Fetched-On
X-S-Maxage
X-From
X-PAYTM-SRV-ID
VivaBuild
Viewtype
X-Cache-FS-Status
X-Cache-Host
Xc-Version
X-Wikidot-Static-Cache
X-Distil-CS
X-Developer
X-DPWN-IS-SECURE
X-B-Cookie
X-Cache-Id
Resin-Trace
X-Cache-URL
X-Region-Sid
X-ServiceProvider
X-Sucuri-Cache
Fastcgi-X-Cache
SD-X-WS
X-Cache-Grace
X-Request-URI
Server-Host
X-ShardId
X-Cache-Info
X-Edge-Cache
X-C
Thinkindot-CacheControl
X-Cache-Bucket
X-Cache-Debug
X-Cache-Expires
X-ShopId
X-Shopify-Stage
X-RateLimit-Remaining-Second
X-CGP
Platform
X-Clientip
X-RateLimit-Limit-Second
Proxy-Connection
X-Var-Ttl
X-Cdn-Srv
Request-Time
X-Varnish-Action
X-Variation
Thinkindot-CacheControl-Type
True-Client-Country-4JS
X-Returned-From
X-Backend-Url
X-Actual-URL
X-A-Wwc
X-A-Dgt
X-Alternate-Cache-Key
X-Returned-From-BeforeDispatch
X-Returned-From-PostProcessResponse
X-Secret
X-Returned-From-DLL
X-Backend-Host
X-Backend-State
X-A-Dcw
X-A-Dam
X-Sf
X-SERVER
X-Bip
X-Edge-Cache-Key
Origin
X-Response-By
Web-Mar-Node
X-A-Ccd
X-A
X-Server-IP
Who
Thinkindot-Control
On-Server
X-Node-Id
X-NX-Host
X-Nginx-Cache-Key
Fastly-Soc-X-Request-Id
X-Matched-Rule
X-Passed-To
X-Passed-To-BeforeDispatch
X-Passed-To-PostProcessResponse
X-FireWall-Port
X-Passed-To-DLL
X-G
X-Gannett-Site-Version
Fastly-Backend-Name
X-Generated-On
CDCHOST
Content-Disposition
Ajk
X-GeoIP-Country-Code
Backend
Adler-Geo
Countrycode
X-Logtrace-Id
X-Location
X-Level-Front-Cache
X-LAGOON
X-Platform
X-Policy
X-Thanos
X-Thinkindot-L3
X-Swa-Ws
Magicmarker
X-Debug-Cookies
X-Sorting-Hat-ShopId
X-D
X-Core-Mission
X-SIPLIST1
X-Sorting-Hat-PodId
X-Crawler
X-CUA
X-Debug-Log
IsBot
Ha-Gx-Prefs
X-Distributor
X-Stale
X-Epic-Correlation-Id
X-Eu-Site
HA-Ipaddr
X-Svr
X-Proxy-Upstream
Is-Eu
X-Proxy-Cache-Status
X-Dispatcher-Server
X-Hash
Mn-Server-Ip
Warning
X-Dc
X-Fstrz
GW-Server
X-TrackingId
X-Generation-Time
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
Fastly-SSL
X-F5-Cache
Heartbleed
Lfy
X-Debug-Cache-Store
X-Developers
X-Device-Os
Cache-Cookie-Set-From
X-Died
X-Fastly-Cache
Apple-News-Services-Parsed-Url
X-MSEdge-Flight
X-MSEdge-Features
X-EIG-Tracking-Id
X-No-Session
X-Up
X-Qloud-Router
X-UnsetCookies
X-Varnish-Authentication
X-Via-CDN
Apple-News-Services-Handled
X-Debug-Cache-Fetch
X-Instart-Isnd
AKAMAI
X-Via-NSCOPI
X-Key
Apple-News-Services-Request-Url
Apple-News-Services-Host
Server-Cache-Control
X-Cache-ASPX
X-Debug-Cache-Expiry
Pagetype
X-Core-Value
Server-Surrogate-Control
Server-Int
SS
X-Amz-Meta-Surrogate-Control
Release
RNT-Machine
Pramga
X-Croise-Owner
RNT-Time
X-HS-Cache-Config
Server-ID
X-Page-Type
X-TIME
NGX
Kp-EeAlive
HostName
X-Server-Time
X-Varnish-Url
REQUESTUUID
X-Sedo-Request-Id
X-Cache-Miss-From
Version
X-B3-Traceid
X-Servername
X-Be
X-Pjax-Url
X-Varnish-Ttl
X-Newrelic-App-Data
SID
RequestId
PFcat
X-Refresh
X-Dynatrace-Js-Agent
X-Owner
X-SN
X-CDN-Forward
X-URL
X-Cache-CFC
MIME-Version
Odigeo-Trace-Id
X-Store
Esi-Enabled
X-From-Cache
X-NC
X-B3-SpanId
MI-Cache
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
MI-API
X-Oss-Storage-Class
MI-Cache-Age
Time
X-RCS-CacheZone
X-MI-In-Market
X-Layer
Hostname
Cteonnt-Length
X-RequestId
Mime-Version
Cdn
X-Ratelimit-Remaining
HTTPS
HA-Georegion
HA-Geolat
HA-Geocountry
HA-Geolon
X-Servedbyhost
HA-Host
HA-Cloudapp
HA-Geocity
X-IPS-LoggedIn
HA-Urlpath
X-FPC
HA-Servedtime
FastCGI-Cache
X-Edge-Server
Cdn-Request-Time
Cdn-Host
X-CSRF-TOKEN
PICS-Label
X-Hyper-Cache
Backend-Name
X-Webkit-Csp
X-Webkit-CSP
X-Req
X-Mrs-Age
X-Mrs-Cache-Hits
X-Unique-Id-Primal
ProcessTime
X-Mrs-Cache
CF-IPCountry
X-CLOUD-TRACE-CONTEXT
X-Mshield-Cache-Status
X-Wa
Memory
X-Ratelimit-Limit
X-CMS-Context
X-Geo
Processtime
X-Load-Cache
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
X-Instart-Info
Cf-Ipcountry
X-Mobile-URL
X-Real-Ip
CDN
X-B3-Spanid
X-DC
X-Phone
Ohc-Response-Time
X-NodeID
Cross-Origin-Window-Policy
X-VServer
X-WebServer
X-WR-MODIFICATION
X-Aicache-OS
X-HS-Combine-CSS
GeoIP-Country-Code
X-Pf-Uncompressing
X-GZip
X-Newrelic-Synthetics
X-Request-Start
XServer
X-Varnish-Beresp-TTL
GeoIP-Latitude
X-Skip-Cache
X-HTML-Minification-Powered-By
X-Fastly-Country-Code
X-Atg-Version
X-Lb-Id
X-PF-Uncompressing
X-Release
URI
Ohc-Cache-HIT
X-VC-Cache
X-Server-W
T-Server
Accept-Ch-Lifetime
X-FORWARDED-FOR
X-WA
Amp-Access-Control-Allow-Source-Origin
X-Oracle-Dms-Ecid
Uber-Trace-Id
X-LB-ID
X-Tb-Optimization-Total-Bytes-Saved
Rt-Proxy-Cache
X-Served-From
X-Nananana
X-ND-Cache
X-Cms-Context
Pics-Label
X-GoCache-CacheStatus
X-Gateway-Cache-Status
X-Gateway-Skip-Cache
X-Gateway-Cache-Key
X-COUNTRY
X-UCC
X-MServer
X-APP
N-Cache
X-Vcache
X-Worker
X-ServedByHost
X-CSRF-Token
X-Datadome
X-SRV
X-Unique-Id
X-Sn-Servicetimems
A
X-Processor
X-UPSTREAM-Address
X-Fastly-Cache-Hits
V-Age
X-LiteSpeed-Cache-Control
X-Cdn-Origin
X-GZIP
X-SERVER-NAME
X-BBXSRF
X-Hp-Webp
DataCenter
X-CACHE-AGE
X-SVT-ORM-RULES
Proxy-Firewall
X-SVT-ORM-VERSION
X-Cache-HT
X-Requestid
X-Optimization
X-Check-Cacheable
X-P-T
X-HS-Status
Is-Session-Tracking
Get-Access-Time
X-NGINX-Cache
Cneonction
X-BE
ServerName
X-ID
Dnion-Transfer-Encoding
Geoip-Latitude
X-Vg-Webcache
X-Backend-TTL
X-VCT
X-Shard
X-Varnish-URL
X-Port
X-Csrf-Token
X-RCS-Backend
X-GDPR
X-Fe
X-GeoIP-City
X-Geo-Header
X-Amzn-Remapped-Content-Length
Host-ID
GeoIp-Country-Code
X-PAGE-TYPE
X-ServerName
WP-Super-Cache
X-PJAX-URL
Requestid
Serverid
X-NWS-UUID-VERIFY
UCS
X-HostName
X-StackifyID
RequestUuid
X-Dw-Trace-Id
X-Git-Hash
Server-Id
X-LiteSpeed-Tag
Cache-Provider
X-RAMCache
X-Fpc
Request-EU
Inserted-Into-Cache-At
355prline
X-Fastly-Backend-Reqs
Request-Country
Xxline
178proxuri
188prxHost
X-CS
DSUID
X-Request-Url
189phosttRef
X-Org
WZWS-RAY
286prxHost
409pxxline
225prxHost
219prxHost
352pxline