Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
CF-RAY
ETag
Link
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Request-Id
X-Xss-Protection
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Adblock-Key
X-Check
Alt-Svc
X-Cacheable
X-Generator
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-Cache-Status
X-AspNetMvc-Version
X-Permitted-Cross-Domain-Policies
X-Template
X-Iinfo
X-Language
Status
Timing-Allow-Origin
X-Buckets
X-Content-Security-Policy
Content-Encoding
X-Kinja-Server-Push
Xkey
X-Turbo-Charged-By
X-CDN
Upgrade
X-Type
Keep-Alive
Access-Control-Expose-Headers
WPE-Backend
X-Pass-Why
X-AH-Environment
X-Backend
Access-Control-Max-Age
X-Age
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Server
X-Request-ID
X-Proxy-Cache
X-Via
Grace
X-Pingback
X-Nginx-Cache-Status
X-Server-Powered-By
X-Robots-Tag
X-Amz-Request-Id
X-Amz-Id-2
X-Hacker
X-UA-Device
X-Varnish-Cache
X-Page-Speed
EagleId
Request-Context
X-LiteSpeed-Cache
Cf-Railgun
X-Envoy-Upstream-Service-Time
X-Ua-Compatible
X-CST
X-Swift-SaveTime
X-Swift-CacheTime
X-Server-Id
Ali-Swift-Global-Savetime
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
X-WebKit-CSP
X-Amz-Version-Id
Server-Timing
X-Ac
X-Node
X-OneAgent-JS-Injection
Allow
Feature-Policy
X-Response-Time
X-Rq
X-Cnection
X-Iejgwucgyu
Content-Location
X-Cache-Lookup
X-Backend-Server
Report-To
EagleEye-TraceId
Surrogate-Control
X-Readtime
X-Host
X-Application-Context
Request-Id
P3p
X-Url
X-ORACLE-DMS-ECID
X-Rack-Cache
X-Origin-Cache
X-Clacks-Overhead
X-Country
NEL
X-FTR-Request-ID
Rating
X-Country-Code
X-Cloud-Trace-Context
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Cdn
X-DataDome
X-Ruxit-JS-Agent
X-Px
X-Instart-Request-ID
X-Vhost
X-Mod-Pagespeed
Charset
X-MS-InvokeApp
X-VARITI-CCR
Accept-CH
Edge-Control
X-Goog-Hash
Verso
X-GitHub-Request-Id
X-PC
X-Vname
X-TtlSet
X-Server-Name
Arc-Version
X-Mobile-Rewrite
PB-RID
PB-PID
X-ESI
X-Version
X-DynaTrace
Pinterest-Generated-By
X-Powered-By-Plesk
X-D2id
X-B3-TraceId
X-TTL
X-Kinja
X-Kinja-Revision
X-GoogleNews-Bot
X-Kinja-Build
X-Kinja-Server
X-Cdn-Fetch
X-Use-Magma
X-Exp-Id
X-Cached
X-Exp-Variant
X-Upstream-Env
X-Origin-Upstream-Status
X-Dispatcher
SPRequestGuid
X-ORACLE-DMS-RID
X-Varnish-TTL
X-SharePointHealthScore
X-Abt-Application-Version
X-Recruiting
MS-Author-Via
X-Powered-CMS
Accept-CH-Lifetime
X-Navigation-Version
RTSS
Content-MD5
X-T
X-Shield-Request-Id
AR-PoweredBy
AR-CACHE
AR-ATIME
Public-Key-Pins
X-Trace
X-DynaTrace-JS-Agent
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Amz-Rid
X-Forwarded-Proto
X-Client-IP
X-HW
X-Fastly-Request-ID
Arr-Disable-Session-Affinity
X-Wix-Server-Artifact-Id
X-Accel-Buffering
SPRequestDuration
SPIisLatency
Realpath
X-DIS-Request-ID
X-Oracle-Dms-Rid
Service-Worker-Allowed
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Upstream
X-Goog-Generation
X-Amz-Meta-S3cmd-Attrs
X-F-Cache
X-B
X-Ser
AR-Request-ID
Front-End-Https
Paypal-Debug-Id
X-Via-JSL
X-FTR-Cache-Status
X-FTR-Realm
X-FTR-DC
X-FTR-Balancer
X-Country-Code-Real
X-FTR-Backend
X-FTR-Backend-Server
X-FTR-Expires
X-Dns-Prefetch-Control
Pinterest-Version
X-Pinterest-Rid
X-XRDS-Location
X-Dw-Request-Base-Id
X-Ttl
X-Id
X-Server-ID
X-Vcap-Request-Id
X-Varnish-Age
X-Debug
Ar-Sid
X-Acc-Meta-Resource-Type
X-Goog-Storage-Class
X-Kinsta-Cache
X-MSEdge-Ref
X-N
Nginx-Cache
X-Hits
X-NF-Request-ID
X-FTR-Cache-Host
S
X-Logged-In
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-NewRelic-App-Data
X-DataStream-Cache-Status
X-Akam-SW-Version
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
X-Frontend
X-Forwarded-For
Alternate-Protocol
X-User-Agent
Tracecode
X-Grace
X-PressLabs-Stats
X-HS-Hub-Id
X-HS-Content-Id
X-Amzn-Trace-Id
X-CACHE-GROUP
AMP-Access-Control-Allow-Source-Origin
Server-Name
X-Content-Options
X-Content-Digest
Refresh
TCN
Powered-By-ChinaCache
X-Pad
X-Content-Type
DynaTrace
X-FastCGI-Cache
X-Middleton-Display
Display
X-Sol
Backend-Timing
MicrosoftSharePointTeamServices
Access-Control-Request-Method
X-Analytics
Accept-Charset
X-Zen-Fury
X-LB-Cache
X-Activity-Id
X-AppVersion
X-Az
FilterID
X-Debug-Info
X-Page-Id
X-Fastcgi-Cache
Host
Fastcgi-Cache
X-CF-Powered-By
X-IPLB-Instance
X-Rid
X-Middleton-Response
Response
MS-CV
X-Cache-Key
ServerID
Cache-Status
TP-L2-Cache
TP-Cache
X-Cache-Hit
X-Magnolia-Registration
X-Hostname
X-RateLimit-Remaining
X-Content-Powered-By
X-Seen-By
X-Srv
X-ATG-Version
X-Mobile
X-WA-Info
X-Revision
X-VCache
X-GUploader-UploadID
X-Cached-By
X-B3-Sampled
X-Varnish-Backend
Surrogate-Key
Host-Header
VIX-Pulpo-Upstream-Status
X-Whom
VIX-Pulpo-Node
X-SS-Set-Cookie
X-TA-CDN-Provider
Server-Info
X-Request-Received
X-Cluster
X-Request-Processing-Time
X-Platform-Server
X-Signature
X-Drupal-Cache-Tags
X-Handled-By
X-B-Cache
X-Cache-Action
X-Content-Security-Policy-Report-Only
X-Instance
X-Request-Guid
Source
Cleartype
X-PHP-Backend
X-Wix-Request-Id
ViewerVersion
X-Tumblr-User
Rt-Fastcgi-Cache
X-Tumblr-Pixel
X-TT
X-Framework
X-Origin-Server
X-Cache-Age
X-Tumblr-Pixel-0
X-Akamai-Edgescape
X-App-Environment
DC
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Real-IP
X-BCube-Filmed-By
X-Generated-By
X-Geo-Country
X-Cache-Control
X-Oneagent-Js-Injection
X-App-Server
Fusion-Source
Fusion-Content-Source
Fusion-Content-Id
Fusion-Template-Id
Fusion-Component-Id
X-FW-Type
X-FW-Static
X-FW-Server
X-FW-Serve
X-Edge-Location
X-FW-Hash
X-Varnish-Server
Server-Node
X-AOL-HN
X-XRDS-LOCATION
X-Ruxit-Js-Agent
X-Cache-Rule
X-NWS-LOG-UUID
X-Varnish-Hostname
Retry-After
X-Correlation-Id
Payment
X-Cache-2
Eomportal-Instance
X-Amz-Server-Side-Encryption
X-Varnish-Grace
X-FB-Debug
Access-Control-Allow-Method
X-Amz-Replication-Status
Webserver
X-Response-Served-From
X-TT-TIMESTAMP
Actual-Object-TTL
X-Cacheable-TTL
X-Cache-Config
GEO-INFO
ServedBy
AsisCache
Filters
X-TX-ID
X-WebKit-CSP-Report-Only
X-Jobs
NGB
Ms-Operation-Id
Content-Style-Type
X-RTag
X-UUID
Healthy
Content-Script-Type
X-Varnish-Hits
X-Drupal-Cache-Contexts
Viewport
Upgrade-Insecure-Requests
X-UA-Device-Type
X-Region
X-Adobe-Content
X-Contextid
X-VG-WebCache
X-Tumblr-Pixel-2
X-Varnish-IP
X-Tumblr-Pixel-1
X-Adobe-Loc
X-Locale
From-Origin
X-Rendered-As
X-RequestSource
X-Ezoic-Cdn
Cache-Tv-Group
X-Accel-Expires
Country
X-Device-Type
HitType
X-Cache-TTL
X-Servedby
Pagespeed
X-WPE-Loopback-Upstream-Addr
X-Cache-TTL-Remaining
Fastcgi-Useragent
X-BACKEND-TTL
Edge-Cache-Tag
X-Cache-Server
X-FW-Dynamic
Cache
X-Cache-Remote
X-Content-Age
X-Upstream-Proxy
X-Kong-Proxy-Latency
Cache-Tags
X-Cache-Operation
X-Kong-Upstream-Latency
X-Upgrade-Enabled
X-Redis-Cache
X-Hit
X-Source
X-Esi
Fastly-Restarts
X-RateLimit-Limit
X-CACHE-KEY
X-APP-VERSION
Datacenter
X-Storage
X-S
X-Mode
Cache-Tag
X-GeoIP
Served-By
X-DataStream-Origin-MEX-Latency
X-DataStream-MidMile-RTT
X-Cache-Var-Map
X-Hl-Ver
Origin-Cache-Control
X-Cache-Var
X-Time-Microsecs
X-Generated
Vix-Hermes-Req-Id
X-Akamai-Request-ID
X-FC-Vary-Parameters
X-Tb
X-Detected-As
Machine
X-Origin-Response-Time
X-NGENIX-Cache
X-Labrador-Cache-Channel
X-Is-Bot
Load-Balancing
X-Path-Route
X-JoinUs
X-Rule
X-RN-RSRV
X-Pubstack
Meta-Geo
Origin-Edge-Control
X-App-Version
X-Agile
X-Cache-Category-Id
X-BYPASS-REASON
X-Agile-Age
X-Agile-Id
X-Daa-Tunnel
X-TNCMS
X-ProxyCache-Status
X-Loop
X-Www-Served-By
X-Backend-Name
X-Timing-Wait
X-ServerID
Selected-FE
SRV
X-Varnish-Cacheable
Cache-Key
X-ProxyCache-Key
X-Web-Node
X-Status
X-Birta-Served
X-Birta-Cache-Post
NtCoent-Length
X-Hosted-By
X-Origin-Host
Xserver
X-L-Path
X-Environment-Context
X-Grey
X-Proxy-Build
X-NCache
Webcakes-App-Version
Webcakes-App-Name
TWC-Connection-Speed
TWC-Device-Class
X-PCL
X-VG-TLSProxy
Webcakes-Region
X-Origin-Hint
Property-Id
TWC-Locale-Group
S-Rt
TWC-Privacy
X-ApacheServer
X-OCL
TWC-GeoIP-LatLong
Now
X-PERF
X-IP
X-Viewer-Country
X-Human
X-RemovedCookies
X-ProcessESI
TWC-GeoIP-Country
X-Proxy
X-CDN-Cache
X-Varnish-Cache-Hits
X-Cache-Enabled
X-Edge-IP
X-Site-Version
X-Microcachable
Public-Key-Pins-Report-Only
X-CCM
X-Format
X-Akamai-Transformed
Azure-RegionName
Azure-SiteName
Azure-InstanceId
Access-Control-Request-Headers
X-Debug-Cache
Azure-SlotName
Azure-Version
Fastcgi-X-Cache-Version
X-Internal-Host
Cache-Name
X-Via-Fastly
X-Access
X-App-Name
X-Proxied
We-Hiring
Mail-Subject
DB-Nickname
X-Zipkin-Id
X-Routing-Service
X-GEO
X-Xfnlog-Site
X-Section
X-Pc-Hit
X-Pc-Key
X-Pc-Appver
X-MP-GENERATED-AT
X-Cache-NE
Cache-Hits
X-Original-Request
User-Agent
X-Origin
X-EdgeConnect-Cache-Status
Liferay-Portal
S-Cnection
X-Protected-By
X-Guploader-Uploadid
X-ES-SERVER
X-Sucuri-ID
User-Cache-Control
X-Node-Name
X-Nginx-Cache
X-Cdn-Forward
X-FW-Version
X-Request-Time
X-Ocache
X-Ua
X-Proto
LB
X-Yottaa-Optimizations
X-GRACE
X-Yottaa-Metrics
X-Trace-Id
X-Varnish-Ttl
Powered
CACHE
Ohc-File-Size
X-Tumblr-Pixel-3
X-Correlation-ID
X-Webstats-RespID
X-Forwarded-Host
X-Endurance-Cache-Level
X-UA
X-VWS-Id
X-LJ-Flow-ID
X-Nc
L5d-Success-Class
X-AWS-Id
X-Unique-ID
X-FB-TRIP-ID
PageSpeed
Section-Io-Cache
X-Time
Frame-Options
X-Origin-CC
X-V
X-Cluster-Node
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
AR-SID
X-Webkit-Csp
OT-Force-Account-Verify
X-OVcl
X-OVcl-Cache
X-Origin-TTL
Nel
IBM-Web2-Location
X-EIG-Tracking-Id
X-Cache-Backend
X-Parent-Response-Time
X-R9-Blue-Green-Version
X-Rocket-Nginx-Bypass
X-Varnish-Beresp-Ttl
Decoy-Debug-Key
Decoy-Debug-Status
X-Fetched-On
Country-Code
X-From
Cache-Prefix
Decoy-Debug-TTL
Fastly-SWR
Fly-Cache
Fly-Request-Id
X-Gen-Mode
Fastly-SIE
X-External-Request-Id
Ec-Rule-Version
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Li-Pop
X-Li-Fabric
X-LI-Proto
X-LI-UUID
X-Region-Sid
X-Request-UUID
X-Irp-Debug
X-Server-By
Arc-Country
X-Generated-In
X-DPWN-IS-SECURE
X-Hnp-Log
X-IN-WAF
X-IN-APIGATEWAY
BehaviorPad-Version
X-Developer
Powered-By
X-B-Cookie
X-ARC
X-BB-ID
X-Block-Status
On-Server
X-Cache-Bucket
X-Application
Rendered-Blocks
VivaBuild
Viewtype
Www
X-Accel-Expires-Debug
X-Amz-Meta-Cache-Control
X-Aed
Node
Mobile-Detection-Method
X-Connection-Hash
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-Date
X-Destination
X-Distil-CS
X-Node-Id
X-Cache-URL
X-Cache-Info
X-Cache-Host
X-Cache-Grace
Meta-Geo-Continent
X-Cache-Id
MD5-Digest
Memcached
GMS-Ver
X-Info
X-VG-WebServer
X-User
X-UE-Client-Country
X-Twitter-Response-Tags
X-PHP-Host
X-We-Are-Hiring
X-Wikidot-Backend
X-S-Maxage
X-PAYTM-SRV-ID
X-NU-AKA-ACS-Version
X-Trv-Group
X-Rebelmouse-Cache-Control
X-ServiceProvider
X-Rebelmouse-Surrogate-Control
X-Server-Group
X-Upstream-CT
X-Upstream-HT
X-Transaction
X-ScT
X-SRCache-Key
X-S-Cookie
X-TT-LOGID
X-Rojux
X-Reboot
X-Origin-Date
Xc-Version
X-Origin-Expires
X-ElasticPress-Search
X-Wikidot-Static-Cache
X-Rewrite-Enabled
X-Pc-Host
X-Pc-Date
X-Pc-Subdomain
X-Vgn-Hpd-Reason
X-Backend-State
X-Shopify-Stage
X-SIPLIST1
X-Bip
True-Client-Country-4JS
X-RateLimit-Limit-Second
X-C
X-Sorting-Hat-PodId
X-Returned-From-DLL
X-Stale
X-Svr
X-Swa-Ws
X-Sorting-Hat-ShopId
X-Cache-FS-Status
X-Cache-Debug
X-RateLimit-Remaining-Second
X-Cache-Expires
X-Matched-Rule
X-Sf
X-A
X-A-Ccd
X-A-Dam
Who
Web-Mar-Node
X-NX-Host
X-Server-IP
X-Response-By
X-A-Dcw
X-A-Dgt
X-Proxy-Upstream
X-ShardId
X-ShopId
X-Alternate-Cache-Key
X-Secret
X-A-Wwc
X-Micro-Cache
X-Actual-URL
X-Auto-Login
X-CGP
X-Fastly-Cache
X-Platform
X-Level-Front-Cache
X-FireWall-Port
X-Varnish-Action
X-Policy
X-Var-Ttl
X-Variation
X-Eu-Site
X-LAGOON
X-G
X-GeoIP-Country-Code
X-Hash
X-Passed-To
X-Passed-To-BeforeDispatch
X-Generated-On
X-Gannett-Site-Version
X-Passed-To-PostProcessResponse
X-Passed-To-DLL
X-Proxy-Cache-Status
X-Epic-Correlation-Id
X-Core-Mission
X-Crawler
X-CUA
X-TrackingId
X-Clientip
X-Cdn-Srv
X-Thinkindot-L3
X-Returned-From-BeforeDispatch
X-D
X-Logtrace-Id
X-Returned-From-PostProcessResponse
SD-X-WS
X-Distributor
X-Dispatcher-Server
X-Request-URI
X-Debug-Cookies
X-Debug-Log
X-Returned-From
X-Thanos
Thinkindot-CacheControl
Countrycode
Magicmarker
Lfy
CDCHOST
Origin
Proxy-Connection
Platform
X-SERVER
IsBot
Ajk
Adler-Geo
Ha-Gx-Prefs
HA-Ipaddr
Is-Eu
Fastly-Backend-Name
Request-Time
Content-Disposition
Thinkindot-CacheControl-Type
Thinkindot-Control
Server-Host
Resin-Trace
Backend
X-HS-Cache-Config
X-Sucuri-Cache
Warning
X-Core-Value
Fastly-Soc-X-Request-Id
X-Qloud-Router
Heartbleed
X-Croise-Owner
Cache-Cookie-Set-From
SS
X-Server-Cache
X-Debug-Cache-Expiry
X-Location
Apple-News-Services-Request-Url
X-Device-Os
X-Key
X-MSEdge-Features
X-MSEdge-Flight
X-Nginx-Cache-Key
Server-Surrogate-Control
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-No-Session
Server-Int
X-Backend-Url
X-Backend-Host
RNT-Machine
Apple-News-Services-Host
X-Up
Pramga
X-Varnish-Authentication
Cache-Cookie-Set-Idcheck
X-Via-CDN
X-Amz-Meta-Surrogate-Control
X-Fstrz
Release
Pagetype
X-Cache-ASPX
AKAMAI
X-IN-SSL-APIGATEWAY
Apple-News-Services-Parsed-Url
Cache-Cookie-Set-Lfrom
Apple-News-Services-Handled
Server-Cache-Control
RNT-Time
Fastly-SSL
X-Instart-Isnd
Mn-Server-Ip
X-F5-Cache
X-Dc
Kp-EeAlive
X-TIME
X-UnsetCookies
X-Varnish-Url
REQUESTUUID
SID
Server-ID
GW-Server
NGX
X-Generation-Time
X-Developers
X-Page-Type
X-Server-Time
Fastcgi-X-Cache
X-Owner
X-SN
X-Via-NSCOPI
X-Servername
HostName
X-Pjax-Url
X-B3-Traceid
X-Died
X-Edge-Cache-Key
X-Be
X-Edge-Cache
X-Newrelic-App-Data
Odigeo-Trace-Id
X-Cache-Miss-From
X-Sedo-Request-Id
MIME-Version
RequestId
X-Refresh
Version
X-B3-SpanId
Hostname
X-CDN-Forward
X-URL
PFcat
HTTPS
X-NC
X-Servedbyhost
Cdn-Request-Time
X-Edge-Server
X-From-Cache
X-Oss-Storage-Class
X-Oss-Object-Type
X-Oss-Request-Id
Cdn-Host
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
Cteonnt-Length
ProcessTime
X-FPC
Esi-Enabled
X-Cache-CFC
X-Store
Cdn
Time
FastCGI-Cache
X-RCS-CacheZone
X-Layer
MI-Cache
MI-API
X-Req
MI-Cache-Age
PICS-Label
X-CSRF-TOKEN
X-MI-In-Market
Mime-Version
X-Webkit-CSP
X-IPS-LoggedIn
HA-Geolon
HA-Geocity
X-RequestId
HA-Urlpath
X-Amzn-Remapped-Date
X-Mobile-URL
HA-Cloudapp
HA-Georegion
HA-Host
HA-Geolat
HA-Geocountry
X-Amzn-Remapped-Connection
HA-Servedtime
X-CLOUD-TRACE-CONTEXT
X-Hyper-Cache
CF-IPCountry
X-Dynatrace-Js-Agent
X-NodeID
X-VServer
Cross-Origin-Window-Policy
Memory
X-Wa
X-Ratelimit-Remaining
X-Real-Ip
X-GZip
Processtime
X-DC
X-Load-Cache
Backend-Name
X-HS-Combine-CSS
CDN
X-HTML-Minification-Powered-By
Cf-Ipcountry
X-Varnish-Beresp-TTL
X-Newrelic-Synthetics
X-CMS-Context
X-Ratelimit-Limit
X-Lb-Id
X-Geo
X-Aicache-OS
X-Mrs-Cache-Hits
X-WR-MODIFICATION
X-Mrs-Cache
X-Mrs-Age
X-Unique-Id-Primal
X-Mshield-Cache-Status
X-Instart-Info
X-Skip-Cache
X-Pf-Uncompressing
Ohc-Cache-HIT
XServer
X-B3-Spanid
X-PF-Uncompressing
X-WebServer
X-Phone
X-VC-Cache
X-Atg-Version
Uber-Trace-Id
Ohc-Response-Time
X-Tb-Optimization-Total-Bytes-Saved
X-Release
URI
X-Fastly-Country-Code
X-WA
X-Request-Start
GeoIP-Country-Code
Amp-Access-Control-Allow-Source-Origin
X-Cms-Context
T-Server
X-Nananana
X-Gateway-Skip-Cache
Accept-Ch-Lifetime
X-Gateway-Cache-Key
GeoIP-Latitude
X-FORWARDED-FOR
X-UCC
X-Gateway-Cache-Status
X-Oracle-Dms-Ecid
X-Server-W
X-LB-ID
X-APP
Pics-Label
N-Cache
X-COUNTRY
X-MServer
X-Processor
X-Vcache
X-Datadome
X-GoCache-CacheStatus
X-Worker
X-BBXSRF
X-Hp-Webp
X-ID
X-SRV
X-Unique-Id
Rt-Proxy-Cache
X-CSRF-Token
X-Served-From
X-ND-Cache
X-Shard
A
X-LiteSpeed-Cache-Control
X-ServedByHost
X-SERVER-NAME
X-Fastly-Cache-Hits
X-GZIP
X-CACHE-AGE
DataCenter
X-UPSTREAM-Address
X-HS-Status
X-VCT
X-Amzn-Remapped-Content-Length
X-Sn-Servicetimems
X-GeoIP-City
X-Optimization
X-Cache-HT
X-Geo-Header
V-Age
X-Cdn-Origin
X-Requestid
Host-ID
X-Check-Cacheable
X-NGINX-Cache
WP-Super-Cache
Geoip-Latitude
Dnion-Transfer-Encoding
UCS
Proxy-Firewall
Cneonction
X-SVT-ORM-VERSION
X-BE
X-SVT-ORM-RULES
X-Backend-TTL
X-PAGE-TYPE
X-ServerName
X-Varnish-URL
Get-Access-Time
X-P-T
Is-Session-Tracking
GeoIp-Country-Code
Request-Country
X-Git-Hash
Requestid
X-Csrf-Token
X-PJAX-URL
Request-EU
X-Port
Serverid
X-NWS-UUID-VERIFY
X-Fe
FSS-Proxy
Pragrma
X-Gen-Id
FSS-Cache
X-Fpc
RequestUuid
X-Fastly-Backend-Reqs
Cache-Provider
X-StackifyID
Server-Id
ServerName
X-HostName
X-LiteSpeed-Tag
X-Dw-Trace-Id
Lb
Xxline
352pxline
355prline
409pxxline
X-Html-Edge-Cache
X-Planisys-CDN-TTL
X-Org
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
286prxHost
X-Request-Url
X-GDPR
X-RAMCache
DSUID
X-RCS-Backend
WZWS-RAY
178proxuri
188prxHost
219prxHost
Inserted-Into-Cache-At
X-CS
189phosttRef
225prxHost