Threat Level: green Handler on Duty: Rob VandenBrink

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
CF-RAY
ETag
Link
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Request-Id
X-Xss-Protection
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Adblock-Key
X-Check
Alt-Svc
X-Cacheable
X-Generator
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-Cache-Status
X-AspNetMvc-Version
X-Permitted-Cross-Domain-Policies
X-Template
X-Iinfo
X-Language
Status
Timing-Allow-Origin
X-Buckets
X-Content-Security-Policy
Content-Encoding
X-Kinja-Server-Push
Xkey
X-CDN
X-Turbo-Charged-By
Upgrade
X-Type
Keep-Alive
Access-Control-Expose-Headers
WPE-Backend
X-Pass-Why
Access-Control-Max-Age
X-Backend
X-AH-Environment
X-Ua-Compatible
X-Age
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Server
X-Request-ID
X-Via
X-Proxy-Cache
Grace
X-Pingback
X-Nginx-Cache-Status
X-Server-Powered-By
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Hacker
X-UA-Device
X-Varnish-Cache
X-Page-Speed
EagleId
Request-Context
X-LiteSpeed-Cache
Cf-Railgun
X-Envoy-Upstream-Service-Time
X-CST
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Server-Id
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-WebKit-CSP
X-Device
X-Amz-Version-Id
X-Ac
Server-Timing
X-Node
X-OneAgent-JS-Injection
Allow
Feature-Policy
X-Cnection
X-Iejgwucgyu
X-Response-Time
X-Rq
Content-Location
X-Cache-Lookup
X-Backend-Server
Report-To
EagleEye-TraceId
Surrogate-Control
X-Readtime
X-Host
X-Application-Context
Request-Id
P3p
X-Url
X-ORACLE-DMS-ECID
X-Rack-Cache
X-Origin-Cache
X-Clacks-Overhead
X-Country
NEL
X-FTR-Request-ID
Rating
X-Country-Code
X-Cloud-Trace-Context
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-DataDome
X-Cdn
X-Instart-Request-ID
X-Ruxit-JS-Agent
X-Px
X-Vhost
X-MS-InvokeApp
X-Mod-Pagespeed
Charset
X-VARITI-CCR
Accept-CH
Edge-Control
X-Goog-Hash
Pinterest-Generated-By
X-GitHub-Request-Id
Verso
Arc-Version
PB-PID
X-Mobile-Rewrite
PB-RID
X-Vname
X-ESI
X-TtlSet
X-PC
X-Server-Name
X-DynaTrace
X-TTL
X-Version
X-Powered-By-Plesk
X-B3-TraceId
X-D2id
X-Exp-Id
X-Cdn-Fetch
X-Kinja
X-Kinja-Revision
X-Kinja-Build
X-GoogleNews-Bot
X-Kinja-Server
X-Exp-Variant
X-Use-Magma
X-Varnish-TTL
X-Upstream-Env
X-Cached
X-Origin-Upstream-Status
SPRequestGuid
X-Dispatcher
X-SharePointHealthScore
X-Powered-CMS
X-Abt-Application-Version
X-Recruiting
MS-Author-Via
X-T
X-ORACLE-DMS-RID
RTSS
Accept-CH-Lifetime
X-Navigation-Version
X-Shield-Request-Id
Public-Key-Pins
Content-MD5
X-Trace
AR-CACHE
AR-PoweredBy
AR-ATIME
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Client-IP
X-Amz-Rid
SPIisLatency
SPRequestDuration
X-HW
X-Fastly-Request-ID
Arr-Disable-Session-Affinity
X-Accel-Buffering
X-Wix-Server-Artifact-Id
X-Oracle-Dms-Rid
X-Forwarded-Proto
Realpath
X-DIS-Request-ID
X-DynaTrace-JS-Agent
X-B
X-F-Cache
X-Upstream
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Amz-Meta-S3cmd-Attrs
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
Service-Worker-Allowed
X-Ser
X-Via-JSL
X-Pinterest-Rid
Pinterest-Version
Paypal-Debug-Id
X-Id
Front-End-Https
AR-Request-ID
X-FTR-Balancer
X-FTR-Backend
X-FTR-Cache-Status
X-FTR-DC
X-FTR-Realm
X-Country-Code-Real
X-FTR-Backend-Server
X-Dns-Prefetch-Control
X-FTR-Expires
X-Dw-Request-Base-Id
X-Server-ID
X-Varnish-Age
X-Vcap-Request-Id
X-Debug
X-Acc-Meta-Resource-Type
X-Goog-Storage-Class
X-MSEdge-Ref
Ar-Sid
X-Kinsta-Cache
Nginx-Cache
X-N
X-Hits
X-XRDS-Location
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-NF-Request-ID
X-Ttl
X-NewRelic-App-Data
X-FTR-Cache-Host
X-Logged-In
S
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
X-Akam-SW-Version
X-DataStream-Cache-Status
X-Frontend
X-Forwarded-For
X-PressLabs-Stats
X-HS-Hub-Id
X-User-Agent
X-HS-Content-Id
Alternate-Protocol
Tracecode
X-Grace
X-CACHE-GROUP
X-Amzn-Trace-Id
Server-Name
DynaTrace
X-Pad
AMP-Access-Control-Allow-Source-Origin
X-Content-Digest
Refresh
X-Content-Options
X-FastCGI-Cache
Powered-By-ChinaCache
Backend-Timing
MicrosoftSharePointTeamServices
X-Analytics
X-Content-Type
Accept-Charset
X-LB-Cache
Fastcgi-Cache
X-Zen-Fury
X-Activity-Id
TCN
X-Debug-Info
X-AppVersion
X-Az
FilterID
Host
X-Rid
Access-Control-Request-Method
X-Sol
Display
X-Middleton-Display
X-IPLB-Instance
MS-CV
X-TA-CDN-Provider
X-Page-Id
X-CF-Powered-By
X-Cache-Key
ServerID
X-Magnolia-Registration
X-Fastcgi-Cache
Cache-Status
TP-Cache
TP-L2-Cache
X-Middleton-Response
Response
X-Cache-Hit
X-Hostname
X-Content-Powered-By
X-Mobile
X-Seen-By
X-Srv
X-RateLimit-Remaining
X-ATG-Version
X-WA-Info
Surrogate-Key
X-VCache
X-B3-Sampled
X-Revision
X-Request-Processing-Time
X-Cached-By
X-Varnish-Backend
X-Request-Received
Rt-Fastcgi-Cache
VIX-Pulpo-Upstream-Status
X-SS-Set-Cookie
VIX-Pulpo-Node
X-B-Cache
X-Cache-Action
X-Signature
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-User
X-Platform-Server
X-Drupal-Cache-Tags
X-GUploader-UploadID
X-Instance
X-Content-Security-Policy-Report-Only
X-Cluster
X-Wix-Request-Id
X-Whom
ViewerVersion
Cleartype
Host-Header
X-XRDS-LOCATION
X-Cache-Age
X-Akamai-Edgescape
X-TT
X-Framework
Source
X-PHP-Backend
X-Origin-Server
Server-Info
X-App-Environment
X-Handled-By
X-Edge-Location
X-Request-Guid
DC
X-Cache-Control
X-Oneagent-Js-Injection
X-Generated-By
X-Amzn-RequestId
X-BCube-Filmed-By
X-Amz-Apigw-Id
X-App-Server
X-Cache-Rule
X-Geo-Country
X-FW-Static
X-FW-Server
X-FW-Type
X-FW-Hash
Server-Node
X-FW-Serve
X-NWS-LOG-UUID
X-AOL-HN
Fusion-Content-Source
Fusion-Content-Id
Fusion-Component-Id
X-Real-IP
X-Varnish-Hostname
X-Ruxit-Js-Agent
Fusion-Source
X-Varnish-Server
Fusion-Template-Id
Retry-After
X-Cache-2
Eomportal-Instance
X-Correlation-Id
X-FB-Debug
Payment
X-Amz-Server-Side-Encryption
Webserver
X-TT-TIMESTAMP
Access-Control-Allow-Method
X-Response-Served-From
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
AsisCache
GEO-INFO
X-Varnish-Hits
NGB
Ms-Operation-Id
X-Drupal-Cache-Contexts
ServedBy
X-Jobs
X-TX-ID
X-UUID
X-RTag
X-Region
Content-Script-Type
Filters
X-WebKit-CSP-Report-Only
Actual-Object-TTL
Content-Style-Type
X-Varnish-Grace
X-Amz-Replication-Status
X-Adobe-Loc
Upgrade-Insecure-Requests
X-Adobe-Content
Viewport
X-Cacheable-TTL
Healthy
X-Varnish-IP
X-Device-Type
X-Cache-Config
Cache
X-Contextid
Country
X-WPE-Loopback-Upstream-Addr
X-Servedby
X-RequestSource
X-UA-Device-Type
Cache-Tv-Group
X-Accel-Expires
X-Locale
From-Origin
HitType
X-Rendered-As
X-Ezoic-Cdn
X-Cache-TTL-Remaining
Edge-Cache-Tag
X-BACKEND-TTL
X-Cache-TTL
X-Cache-Server
X-Cache-Remote
X-VG-WebCache
Pagespeed
Fastcgi-Useragent
X-Cache-Operation
X-FW-Dynamic
X-Content-Age
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Fastly-Restarts
X-Hit
Cache-Tags
X-Upgrade-Enabled
X-Esi
X-CACHE-KEY
X-APP-VERSION
X-Redis-Cache
X-Storage
X-Source
X-RateLimit-Limit
X-S
X-Upstream-Proxy
Datacenter
X-App-Version
X-Mode
Served-By
Cache-Tag
X-GeoIP
X-Backend-Name
X-Tb
X-NCache
X-Path-Route
X-Cache-Var
X-NGENIX-Cache
X-JoinUs
X-Is-Bot
X-Hl-Ver
X-Detected-As
X-Cache-Var-Map
X-Internal-Host
X-Origin-Response-Time
X-RN-RSRV
Load-Balancing
Vix-Hermes-Req-Id
Machine
Meta-Geo
X-Akamai-Request-ID
SRV
X-Daa-Tunnel
X-L-Path
Selected-FE
X-Proxy
X-Edge-IP
X-Environment-Context
X-Generated
X-Varnish-Cache-Hits
X-Grey
X-Time-Microsecs
X-Varnish-Cacheable
X-Proxy-Build
X-ProxyCache-Key
X-Birta-Cache-Post
X-Birta-Served
X-BYPASS-REASON
X-ProxyCache-Status
Cache-Key
X-Cache-Category-Id
X-Www-Served-By
X-Timing-Wait
X-ServerID
X-Rule
X-Labrador-Cache-Channel
Now
Xserver
X-Guploader-Uploadid
X-Akamai-Transformed
NtCoent-Length
Webcakes-Region
Webcakes-App-Version
Webcakes-App-Name
X-RemovedCookies
X-ProcessESI
X-Agile-Age
X-Agile
TWC-Privacy
TWC-Locale-Group
Cache-Name
Property-Id
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-LatLong
TWC-GeoIP-Country
X-Agile-Id
X-ApacheServer
X-CDN-Cache
X-Format
X-Loop
X-PERF
X-Viewer-Country
X-Via-Fastly
X-Hosted-By
X-DataStream-MidMile-RTT
X-Origin-Hint
X-Origin-Host
X-Status
X-TNCMS
X-DataStream-Origin-MEX-Latency
X-Web-Node
X-Pc-Key
Public-Key-Pins-Report-Only
Origin-Cache-Control
X-Access
X-CCM
X-Cache-Enabled
X-OCL
X-PCL
X-Pc-Appver
X-Pc-Hit
Origin-Edge-Control
Azure-SlotName
Azure-Version
X-Section
Azure-RegionName
X-Cache-NE
Azure-InstanceId
DB-Nickname
Azure-SiteName
Fastcgi-X-Cache-Version
X-Zipkin-Id
We-Hiring
X-Pubstack
X-Site-Version
X-App-Name
X-Routing-Service
X-FC-Vary-Parameters
X-MP-GENERATED-AT
S-Rt
X-Human
X-Proxied
X-Xfnlog-Site
Mail-Subject
X-Debug-Cache
X-VG-TLSProxy
X-Origin
Access-Control-Request-Headers
X-IP
X-Microcachable
X-Original-Request
X-Ocache
X-GEO
X-Sucuri-ID
S-Cnection
X-EdgeConnect-Cache-Status
X-Protected-By
Liferay-Portal
X-Nginx-Cache
User-Cache-Control
X-Cdn-Forward
X-Request-Time
User-Agent
X-FW-Version
Cache-Hits
X-UA
X-Node-Name
LB
X-GRACE
X-Webstats-RespID
X-Tumblr-Pixel-3
X-ES-SERVER
X-Yottaa-Metrics
X-Proto
X-Yottaa-Optimizations
X-FB-TRIP-ID
X-Correlation-ID
X-Time
X-Trace-Id
Powered
X-Origin-CC
X-Ua
Ohc-File-Size
X-Nc
X-Unique-ID
PageSpeed
X-Endurance-Cache-Level
X-Forwarded-Host
L5d-Success-Class
Section-Io-Cache
Frame-Options
X-Webkit-Csp
X-Upstream-HT
X-Upstream-CT
AR-SID
X-Parent-Response-Time
X-OVcl
X-Varnish-Beresp-Status
X-V
X-Varnish-Beresp-Grace
X-OVcl-Cache
IBM-Web2-Location
X-LJ-Flow-ID
X-AWS-Id
X-ElasticPress-Search
X-Origin-TTL
X-Rocket-Nginx-Bypass
Nel
X-VWS-Id
X-Pc-Host
X-Pc-Date
X-Pc-Subdomain
X-R9-Blue-Green-Version
CACHE
OT-Force-Account-Verify
X-Cache-Backend
X-Cluster-Node
X-Vgn-Hpd-Reason
X-Varnish-Beresp-Ttl
Powered-By
Decoy-Debug-Key
Cache-Prefix
BehaviorPad-Version
Node
Country-Code
Decoy-Debug-Status
Decoy-Debug-TTL
Fastly-SIE
VivaBuild
Www
Viewtype
Fly-Cache
Fly-Request-Id
Meta-Geo-Continent
GMS-Ver
X-Accel-Expires-Debug
Fastly-SWR
Ec-Rule-Version
X-ARC
Mobile-Detection-Method
X-Application
Resin-Trace
X-Aed
Rendered-Blocks
X-Destination
X-Rewrite-Enabled
X-Request-UUID
X-Rojux
X-S-Cookie
X-S-Maxage
X-Region-Sid
X-Rebelmouse-Surrogate-Control
X-Origin-Expires
X-Origin-Date
X-PAYTM-SRV-ID
X-PHP-Host
X-Rebelmouse-Cache-Control
X-ScT
X-Server-By
X-User
X-UE-Client-Country
X-VG-WebServer
X-We-Are-Hiring
Xc-Version
X-Twitter-Response-Tags
X-TT-LOGID
X-ServiceProvider
X-Server-Group
X-SRCache-Key
X-Transaction
X-Trv-Group
X-NU-AKA-ACS-Version
X-Micro-Cache
X-CF-Lambda-Fn
X-Cdn-Srv
X-CF-Lambda-Version
X-Connection-Hash
X-Date
X-Cache-URL
X-Cache-Info
X-BB-ID
X-B-Cookie
X-Cache-FS-Status
X-Cache-Host
X-Cache-Id
Arc-Country
X-Developer
X-IN-APIGATEWAY
X-Goog-Meta-Goog-Reserved-File-Mtime
X-IN-SSL-APIGATEWAY
X-IN-WAF
X-Info
X-Generated-In
X-From
X-Distil-CS
X-DPWN-IS-SECURE
X-External-Request-Id
X-Fetched-On
X-Auto-Login
MD5-Digest
X-Server-Cache
X-Varnish-Ttl
X-Sucuri-Cache
Fastcgi-X-Cache
X-Crawler
X-CUA
X-D
X-Debug-Cookies
X-Core-Mission
Thinkindot-CacheControl-Type
X-Cache-Grace
X-CGP
X-Clientip
X-Debug-Log
X-Dispatcher-Server
X-Gannett-Site-Version
X-Gen-Mode
X-Generated-On
X-G
X-Fastly-Cache
Adler-Geo
X-Epic-Correlation-Id
X-Eu-Site
X-Cache-Expires
X-Cache-Debug
X-A-Wwc
True-Client-Country-4JS
X-Alternate-Cache-Key
X-A-Dgt
X-A-Dcw
X-A
X-A-Ccd
X-A-Dam
X-Amz-Meta-Cache-Control
X-SERVER
X-C
X-GeoIP-Country-Code
X-Cache-Bucket
X-Block-Status
Thinkindot-Control
X-Backend-Host
X-Backend-Url
X-Bip
Who
X-Hash
X-ShopId
X-Shopify-Stage
X-SIPLIST1
X-Sorting-Hat-PodId
X-ShardId
X-Sf
X-Secret
X-Edge-Cache
X-Server-IP
X-Sorting-Hat-ShopId
X-Edge-Cache-Key
X-Variation
X-Varnish-Action
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Var-Ttl
X-Thinkindot-L3
X-Svr
X-Swa-Ws
X-Thanos
X-Request-URI
X-Reboot
X-Li-Fabric
X-Li-Pop
X-LI-Proto
X-LI-UUID
X-Level-Front-Cache
X-LAGOON
X-Hnp-Log
X-Dc
X-Irp-Debug
X-Logtrace-Id
X-Matched-Rule
X-Proxy-Upstream
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Proxy-Cache-Status
X-Policy
X-Nginx-Cache-Key
X-NX-Host
X-Platform
Thinkindot-CacheControl
X-Distributor
Memcached
Lfy
Ajk
Origin
Proxy-Connection
Platform
IsBot
Is-Eu
Content-Disposition
CDCHOST
Countrycode
Backend
Ha-Gx-Prefs
Fastly-Soc-X-Request-Id
Request-Time
HA-Ipaddr
Server-Host
Warning
Mn-Server-Ip
X-EIG-Tracking-Id
X-F5-Cache
X-Up
X-Died
X-UnsetCookies
X-FireWall-Port
Heartbleed
Server-Int
X-Fstrz
X-Device-Os
X-Developers
Web-Mar-Node
Server-Surrogate-Control
X-Croise-Owner
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
X-Returned-From-PostProcessResponse
AKAMAI
X-Debug-Cache-Store
X-Returned-From-DLL
X-Passed-To-PostProcessResponse
Apple-News-Services-Host
X-MSEdge-Flight
X-MSEdge-Features
Apple-News-Services-Handled
X-No-Session
X-Node-Id
Fastly-Backend-Name
X-Qloud-Router
Apple-News-Services-Parsed-Url
X-Varnish-Authentication
X-Location
X-Passed-To-BeforeDispatch
X-Generation-Time
X-Passed-To-DLL
X-Passed-To
RNT-Time
GW-Server
RNT-Machine
X-Instart-Isnd
X-Core-Value
Magicmarker
Cache-Cookie-Set-Lfrom
SD-X-WS
X-Backend-State
Pramga
X-Cache-ASPX
X-Response-By
On-Server
Server-Cache-Control
X-Returned-From-BeforeDispatch
X-Returned-From
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-From
X-Stale
X-Actual-URL
Apple-News-Services-Request-Url
X-Amz-Meta-Surrogate-Control
Release
X-HS-Cache-Config
X-Via-NSCOPI
X-Key
Pagetype
Fastly-SSL
X-Varnish-Url
Server-ID
X-Page-Type
HostName
X-Via-CDN
X-Server-Time
NGX
X-TIME
Kp-EeAlive
X-TrackingId
REQUESTUUID
SS
X-Pjax-Url
X-Cache-Miss-From
X-Be
X-B3-Traceid
Version
X-Sedo-Request-Id
X-Newrelic-App-Data
SID
X-Servername
RequestId
PFcat
X-Owner
X-SN
X-Refresh
X-Dynatrace-Js-Agent
X-URL
X-CDN-Forward
Esi-Enabled
X-Cache-CFC
MIME-Version
X-From-Cache
Odigeo-Trace-Id
X-Store
X-NC
X-B3-SpanId
MI-Cache
MI-Cache-Age
X-MI-In-Market
X-Oss-Server-Time
X-Oss-Storage-Class
X-RCS-CacheZone
MI-API
X-Layer
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
Hostname
Cteonnt-Length
Time
X-FPC
Mime-Version
HA-Urlpath
HA-Servedtime
X-Servedbyhost
X-RequestId
Cdn
HTTPS
HA-Host
X-Ratelimit-Remaining
HA-Geocountry
HA-Geocity
HA-Cloudapp
HA-Geolat
HA-Geolon
HA-Georegion
X-IPS-LoggedIn
FastCGI-Cache
PICS-Label
X-Edge-Server
Cdn-Request-Time
X-CSRF-TOKEN
Cdn-Host
X-Hyper-Cache
Backend-Name
X-Req
X-Webkit-CSP
X-Real-Ip
X-Mshield-Cache-Status
X-CLOUD-TRACE-CONTEXT
X-Unique-Id-Primal
X-Mrs-Cache-Hits
X-Mrs-Cache
X-Mrs-Age
CF-IPCountry
ProcessTime
X-CMS-Context
X-Ratelimit-Limit
X-Geo
Processtime
X-Load-Cache
X-Instart-Info
Memory
X-Wa
X-Mobile-URL
Cf-Ipcountry
X-B3-Spanid
X-GZip
CDN
X-DC
X-Phone
X-Amzn-Remapped-Date
Cross-Origin-Window-Policy
Ohc-Response-Time
X-WebServer
X-Amzn-Remapped-Connection
X-Varnish-Beresp-TTL
X-WR-MODIFICATION
X-NodeID
GeoIP-Country-Code
X-Aicache-OS
X-VServer
X-HS-Combine-CSS
X-Pf-Uncompressing
X-Request-Start
X-Newrelic-Synthetics
XServer
Amp-Access-Control-Allow-Source-Origin
GeoIP-Latitude
X-Fastly-Country-Code
X-Lb-Id
X-PF-Uncompressing
X-Release
X-Skip-Cache
X-Atg-Version
URI
X-HTML-Minification-Powered-By
X-FORWARDED-FOR
Accept-Ch-Lifetime
T-Server
X-Server-W
X-WA
X-VC-Cache
Ohc-Cache-HIT
X-Cms-Context
X-Served-From
X-Oracle-Dms-Ecid
Uber-Trace-Id
X-Nananana
X-Tb-Optimization-Total-Bytes-Saved
Rt-Proxy-Cache
X-ND-Cache
X-MServer
X-APP
X-LB-ID
X-COUNTRY
Pics-Label
X-UCC
X-GoCache-CacheStatus
X-Gateway-Skip-Cache
N-Cache
X-Gateway-Cache-Status
X-Gateway-Cache-Key
X-Worker
X-CSRF-Token
X-Datadome
X-ServedByHost
X-Unique-Id
X-SRV
X-Processor
A
V-Age
X-UPSTREAM-Address
X-Sn-Servicetimems
X-LiteSpeed-Cache-Control
X-Fastly-Cache-Hits
X-Cdn-Origin
X-SERVER-NAME
Proxy-Firewall
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Hp-Webp
X-BBXSRF
DataCenter
X-CACHE-AGE
X-P-T
Get-Access-Time
X-Optimization
X-Cache-HT
X-Requestid
X-GZIP
Is-Session-Tracking
X-HS-Status
X-Check-Cacheable
X-NGINX-Cache
Geoip-Latitude
ServerName
Dnion-Transfer-Encoding
X-BE
X-Vcache
X-ID
Cneonction
X-Backend-TTL
X-Vg-Webcache
X-VCT
X-Shard
Host-ID
X-GeoIP-City
X-RCS-Backend
X-Varnish-URL
X-Fe
GeoIp-Country-Code
X-Csrf-Token
X-Geo-Header
X-ServerName
X-Port
X-PJAX-URL
Requestid
X-Amzn-Remapped-Content-Length
X-GDPR
X-PAGE-TYPE
Serverid
X-NWS-UUID-VERIFY
Cache-Provider
X-LiteSpeed-Tag
X-Git-Hash
X-HostName
RequestUuid
UCS
Server-Id
X-StackifyID
X-Dw-Trace-Id
WP-Super-Cache
X-Fastly-Backend-Reqs
X-Fpc
Inserted-Into-Cache-At
Request-EU
Request-Country
178proxuri
X-RAMCache
X-CS
409pxxline
DSUID
X-Org
Xxline
X-Request-Url
355prline
352pxline
189phosttRef
188prxHost
219prxHost
225prxHost
286prxHost
WZWS-RAY