Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
CF-RAY
ETag
Link
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Request-Id
X-Xss-Protection
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Adblock-Key
X-Check
Alt-Svc
X-Cacheable
X-Generator
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-Cache-Status
X-AspNetMvc-Version
X-Permitted-Cross-Domain-Policies
X-Template
X-Iinfo
X-Language
Status
Timing-Allow-Origin
X-Buckets
X-FRAME-OPTIONS
X-Content-Security-Policy
Content-Encoding
X-Kinja-Server-Push
Xkey
X-CDN
X-Turbo-Charged-By
Upgrade
X-Type
Keep-Alive
Access-Control-Expose-Headers
WPE-Backend
X-Pass-Why
X-AH-Environment
X-Backend
Access-Control-Max-Age
X-Age
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Server
X-Proxy-Cache
X-Via
X-Request-ID
Grace
X-Pingback
X-Nginx-Cache-Status
X-Server-Powered-By
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Hacker
X-Varnish-Cache
X-UA-Device
X-Page-Speed
EagleId
Request-Context
X-LiteSpeed-Cache
X-Envoy-Upstream-Service-Time
Cf-Railgun
X-CST
X-Ua-Compatible
X-Swift-SaveTime
X-Swift-CacheTime
X-Server-Id
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
Ali-Swift-Global-Savetime
X-Device
X-WebKit-CSP
X-Amz-Version-Id
Server-Timing
X-Ac
X-Node
Allow
X-OneAgent-JS-Injection
X-Response-Time
Feature-Policy
X-Rq
X-Cnection
X-Iejgwucgyu
Content-Location
X-Cache-Lookup
X-Backend-Server
Report-To
EagleEye-TraceId
Surrogate-Control
X-Readtime
X-Host
X-Application-Context
Request-Id
X-ORACLE-DMS-ECID
P3p
X-Rack-Cache
X-Url
X-Origin-Cache
X-Clacks-Overhead
X-Country
NEL
X-FTR-Request-ID
Rating
X-Country-Code
X-Cloud-Trace-Context
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-DataDome
X-Ruxit-JS-Agent
X-Cdn
X-Px
X-Instart-Request-ID
X-Mod-Pagespeed
Charset
X-Vhost
X-VARITI-CCR
X-MS-InvokeApp
Accept-CH
Edge-Control
X-Goog-Hash
Verso
X-GitHub-Request-Id
X-TtlSet
X-PC
X-Vname
PB-RID
X-Mobile-Rewrite
PB-PID
Arc-Version
X-ESI
X-Server-Name
X-Upstream-Env
X-Version
X-DynaTrace
Pinterest-Generated-By
X-TTL
X-Powered-By-Plesk
X-D2id
X-Origin-Upstream-Status
X-Kinja-Build
X-Kinja
X-Kinja-Revision
X-Cdn-Fetch
X-Kinja-Server
X-Use-Magma
X-GoogleNews-Bot
X-Exp-Id
X-Exp-Variant
X-Cached
X-B3-TraceId
X-ORACLE-DMS-RID
X-Dispatcher
SPRequestGuid
X-Varnish-TTL
X-Recruiting
X-SharePointHealthScore
X-Abt-Application-Version
MS-Author-Via
X-Powered-CMS
Accept-CH-Lifetime
RTSS
X-Navigation-Version
Content-MD5
X-T
X-Shield-Request-Id
AR-CACHE
AR-ATIME
AR-PoweredBy
Public-Key-Pins
X-DynaTrace-JS-Agent
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Trace
X-Client-IP
X-Forwarded-Proto
Arr-Disable-Session-Affinity
X-Amz-Rid
X-Fastly-Request-ID
X-HW
X-Accel-Buffering
X-Wix-Server-Artifact-Id
SPIisLatency
SPRequestDuration
Realpath
X-DIS-Request-ID
Service-Worker-Allowed
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Amz-Meta-S3cmd-Attrs
X-Upstream
X-Oracle-Dms-Rid
X-F-Cache
X-B
Paypal-Debug-Id
AR-Request-ID
X-Ser
Front-End-Https
Pinterest-Version
X-Pinterest-Rid
X-FTR-Cache-Status
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-DC
X-FTR-Realm
X-Country-Code-Real
X-Via-JSL
X-FTR-Expires
X-Id
X-XRDS-Location
X-Dw-Request-Base-Id
X-Vcap-Request-Id
Ar-Sid
X-Varnish-Age
X-Dns-Prefetch-Control
X-Debug
X-Goog-Storage-Class
X-Acc-Meta-Resource-Type
X-Ttl
X-MSEdge-Ref
X-Kinsta-Cache
X-N
X-Hits
Nginx-Cache
X-NF-Request-ID
X-FTR-Cache-Host
S
X-NewRelic-App-Data
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-DataStream-Cache-Status
X-Logged-In
X-Akam-SW-Version
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
X-Forwarded-For
Tracecode
Alternate-Protocol
X-Frontend
X-Grace
X-User-Agent
X-HS-Hub-Id
X-HS-Content-Id
X-PressLabs-Stats
X-Amzn-Trace-Id
X-Server-ID
AMP-Access-Control-Allow-Source-Origin
Server-Name
X-CACHE-GROUP
X-Content-Digest
X-Content-Options
TCN
X-FastCGI-Cache
Refresh
Powered-By-ChinaCache
X-Pad
X-Content-Type
DynaTrace
X-Sol
X-Middleton-Display
Access-Control-Request-Method
Display
X-Analytics
MicrosoftSharePointTeamServices
Backend-Timing
X-LB-Cache
Fastcgi-Cache
FilterID
X-Az
X-Rid
X-IPLB-Instance
X-Activity-Id
X-Debug-Info
X-Zen-Fury
X-AppVersion
X-Page-Id
Host
X-CF-Powered-By
Accept-Charset
X-Cache-Key
Response
X-Middleton-Response
MS-CV
ServerID
X-Fastcgi-Cache
X-Cache-Hit
Cache-Status
TP-L2-Cache
X-Magnolia-Registration
TP-Cache
X-Hostname
X-VCache
X-RateLimit-Remaining
X-Srv
X-Seen-By
X-Content-Powered-By
X-ATG-Version
X-Mobile
X-Revision
X-WA-Info
X-Cached-By
X-Varnish-Backend
Surrogate-Key
X-GUploader-UploadID
X-Request-Processing-Time
X-B3-Sampled
X-Request-Received
Host-Header
X-Whom
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-SS-Set-Cookie
X-B-Cache
X-Cache-Action
X-Signature
X-Cluster
X-Instance
X-Platform-Server
Server-Info
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-User
X-Content-Security-Policy-Report-Only
X-Handled-By
X-Drupal-Cache-Tags
X-Wix-Request-Id
ViewerVersion
Cleartype
Source
X-Request-Guid
X-Cache-Age
X-Origin-Server
X-Akamai-Edgescape
X-PHP-Backend
X-Framework
DC
X-TT
X-TA-CDN-Provider
Rt-Fastcgi-Cache
X-App-Environment
X-Amzn-RequestId
X-Amz-Apigw-Id
Fusion-Template-Id
Fusion-Source
Fusion-Component-Id
Fusion-Content-Id
Fusion-Content-Source
X-Real-IP
X-Geo-Country
X-App-Server
X-Generated-By
X-BCube-Filmed-By
X-Cache-Control
X-FW-Serve
X-FW-Type
X-FW-Static
X-FW-Hash
X-FW-Server
X-Varnish-Server
X-AOL-HN
X-Edge-Location
Server-Node
X-Oneagent-Js-Injection
X-Cache-Rule
X-NWS-LOG-UUID
X-Varnish-Hostname
X-XRDS-LOCATION
Retry-After
X-Ruxit-Js-Agent
X-Correlation-Id
X-Cache-2
Payment
X-Amz-Server-Side-Encryption
X-Varnish-Grace
Eomportal-Instance
X-FB-Debug
X-Amz-Replication-Status
Access-Control-Allow-Method
X-TT-TIMESTAMP
X-Response-Served-From
Webserver
X-Tumblr-Pixel-2
X-Varnish-Hits
X-Tumblr-Pixel-1
Actual-Object-TTL
X-Cache-Config
X-Cacheable-TTL
AsisCache
ServedBy
GEO-INFO
Content-Script-Type
X-Jobs
X-WebKit-CSP-Report-Only
Ms-Operation-Id
X-TX-ID
X-RTag
X-Region
X-UA-Device-Type
Healthy
Filters
X-Upstream-Proxy
NGB
X-Drupal-Cache-Contexts
Content-Style-Type
X-UUID
X-Varnish-IP
X-Contextid
X-Adobe-Content
Viewport
X-Adobe-Loc
Upgrade-Insecure-Requests
X-VG-WebCache
Cache-Tv-Group
Country
X-Rendered-As
X-Ezoic-Cdn
From-Origin
X-RequestSource
X-Locale
X-Accel-Expires
X-Device-Type
X-Cache-TTL
HitType
X-BACKEND-TTL
Fastcgi-Useragent
X-Cache-TTL-Remaining
X-FW-Dynamic
X-Cache-Server
X-Servedby
X-WPE-Loopback-Upstream-Addr
Edge-Cache-Tag
Pagespeed
X-Content-Age
Cache
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Cache-Tags
X-Cache-Remote
X-Cache-Operation
X-Upgrade-Enabled
X-Redis-Cache
X-APP-VERSION
X-Source
X-RateLimit-Limit
X-Hit
Fastly-Restarts
Datacenter
X-CACHE-KEY
X-Storage
X-Esi
X-DataStream-MidMile-RTT
X-Mode
X-DataStream-Origin-MEX-Latency
X-GeoIP
Cache-Tag
Served-By
X-S
Machine
Load-Balancing
Meta-Geo
X-Akamai-Request-ID
X-Cache-Var-Map
X-NCache
X-Labrador-Cache-Channel
X-JoinUs
X-Cache-Var
X-NGENIX-Cache
X-Is-Bot
X-Path-Route
X-Time-Microsecs
X-Origin-Response-Time
X-Detected-As
X-Hl-Ver
X-Tb
X-Internal-Host
X-Backend-Name
Vix-Hermes-Req-Id
SRV
X-RN-RSRV
X-Pubstack
X-ServerID
X-Timing-Wait
X-Status
X-Grey
X-Cache-Category-Id
X-Generated
X-Www-Served-By
X-Agile
X-Environment-Context
X-FC-Vary-Parameters
X-ProxyCache-Status
X-ProxyCache-Key
X-Proxy
X-Proxy-Build
X-Agile-Age
X-Loop
Selected-FE
X-TNCMS
Origin-Edge-Control
X-Rule
X-BYPASS-REASON
X-Birta-Served
X-CDN-Cache
X-Origin-Host
X-Edge-IP
Cache-Key
X-Agile-Id
Now
X-Hosted-By
X-Birta-Cache-Post
X-L-Path
Origin-Cache-Control
X-Varnish-Cache-Hits
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Locale-Group
TWC-Privacy
Webcakes-App-Version
Webcakes-App-Name
TWC-Device-Class
X-Via-Fastly
Property-Id
X-Varnish-Cacheable
S-Rt
X-VG-TLSProxy
Webcakes-Region
Cache-Name
TWC-Connection-Speed
X-Origin-Hint
X-Web-Node
X-ProcessESI
X-IP
X-Format
X-RemovedCookies
X-PERF
X-Daa-Tunnel
X-Cache-Enabled
X-ApacheServer
X-Viewer-Country
X-Human
X-Access
X-App-Version
NtCoent-Length
X-GEO
X-MP-GENERATED-AT
X-CCM
X-Microcachable
Public-Key-Pins-Report-Only
Azure-SiteName
Azure-SlotName
Azure-Version
Azure-RegionName
Azure-InstanceId
X-PCL
X-Guploader-Uploadid
X-OCL
DB-Nickname
Access-Control-Request-Headers
Fastcgi-X-Cache-Version
X-Section
X-Proxied
We-Hiring
X-Site-Version
X-App-Name
X-Zipkin-Id
Mail-Subject
X-Debug-Cache
X-Akamai-Transformed
Xserver
X-Xfnlog-Site
X-Routing-Service
User-Agent
Cache-Hits
X-Pc-Hit
X-EdgeConnect-Cache-Status
Liferay-Portal
X-Cache-NE
S-Cnection
X-Pc-Key
X-Original-Request
X-Origin
X-Protected-By
X-Pc-Appver
X-Sucuri-ID
X-ES-SERVER
X-Node-Name
LB
X-Nginx-Cache
X-FW-Version
X-Ocache
CACHE
User-Cache-Control
X-Request-Time
X-Proto
X-Yottaa-Metrics
X-Yottaa-Optimizations
PageSpeed
X-Cdn-Forward
X-Trace-Id
X-UA
X-Ua
Powered
X-Forwarded-Host
X-GRACE
X-Tumblr-Pixel-3
X-Endurance-Cache-Level
Ohc-File-Size
X-Varnish-Ttl
X-Webstats-RespID
X-Unique-ID
X-VWS-Id
X-AWS-Id
L5d-Success-Class
X-LJ-Flow-ID
Frame-Options
X-FB-TRIP-ID
X-Correlation-ID
Section-Io-Cache
X-Origin-CC
X-Nc
X-Time
X-Cluster-Node
X-V
X-Varnish-Beresp-Status
X-URL
X-Varnish-Beresp-Grace
OT-Force-Account-Verify
X-OVcl-Cache
X-OVcl
X-Webkit-Csp
AR-SID
X-B3-Traceid
X-Origin-TTL
X-EIG-Tracking-Id
X-ElasticPress-Search
X-Rocket-Nginx-Bypass
X-Cache-Backend
Nel
X-R9-Blue-Green-Version
Decoy-Debug-Status
Decoy-Debug-TTL
X-From
IBM-Web2-Location
Decoy-Debug-Key
Ec-Rule-Version
X-DPWN-IS-SECURE
Country-Code
X-External-Request-Id
Cache-Prefix
Fastly-SIE
X-Destination
X-Distil-CS
Fly-Cache
X-Fetched-On
Fly-Request-Id
X-Developer
Fastly-SWR
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Wikidot-Static-Cache
Xc-Version
X-Wikidot-Backend
X-We-Are-Hiring
X-VG-WebServer
X-Irp-Debug
X-IN-WAF
Arc-Country
X-Generated-In
GMS-Ver
X-IN-APIGATEWAY
BehaviorPad-Version
X-Date
X-Auto-Login
X-ARC
Powered-By
X-B-Cookie
On-Server
X-BB-ID
X-Application
X-Amz-Meta-Cache-Control
VivaBuild
Viewtype
Www
X-Accel-Expires-Debug
Rendered-Blocks
X-Aed
Node
Mobile-Detection-Method
X-Cache-URL
X-Cache-Info
X-Cdn-Srv
X-CF-Lambda-Fn
X-Connection-Hash
X-CF-Lambda-Version
X-Cache-Id
X-Cache-Host
Memcached
Meta-Geo-Continent
MD5-Digest
X-Cache-FS-Status
X-Cache-Grace
X-Micro-Cache
X-Info
X-PHP-Host
X-Parent-Response-Time
X-Rebelmouse-Cache-Control
X-ServiceProvider
X-PAYTM-SRV-ID
X-Origin-Expires
X-Trv-Group
X-Transaction
X-Origin-Date
X-Server-Group
X-Server-By
X-Request-UUID
X-S-Cookie
X-Rojux
X-Rewrite-Enabled
X-S-Maxage
X-ScT
X-Rebelmouse-Surrogate-Control
X-Reboot
X-Region-Sid
X-TT-LOGID
X-SRCache-Key
X-UE-Client-Country
X-User
X-NU-AKA-ACS-Version
X-Node-Id
X-Twitter-Response-Tags
X-Vgn-Hpd-Reason
X-Dc
X-Varnish-Beresp-Ttl
X-Cache-Bucket
Thinkindot-CacheControl-Type
X-C
X-Block-Status
X-Secret
X-Shopify-Stage
X-Cache-Debug
SD-X-WS
X-Backend-State
X-RateLimit-Remaining-Second
X-ShardId
X-Sf
X-LI-UUID
X-Bip
X-Cache-Expires
X-Server-IP
X-ShopId
X-Backend-Host
X-A
X-A-Ccd
X-A-Dam
X-A-Dgt
X-Varnish-Action
Who
Thinkindot-Control
True-Client-Country-4JS
X-Returned-From-PostProcessResponse
X-Returned-From-BeforeDispatch
X-A-Wwc
X-Actual-URL
X-Logtrace-Id
X-Var-Ttl
X-SIPLIST1
X-Backend-Url
X-Variation
X-Request-URI
X-Matched-Rule
X-Alternate-Cache-Key
X-Returned-From
X-Location
X-CGP
X-Gannett-Site-Version
X-Gen-Mode
X-Passed-To
X-Li-Pop
X-Passed-To-BeforeDispatch
X-G
X-LI-Proto
X-Passed-To-PostProcessResponse
X-Fastly-Cache
X-Passed-To-DLL
X-Generated-On
X-GeoIP-Country-Code
X-NX-Host
X-Returned-From-DLL
X-Level-Front-Cache
X-LAGOON
X-Thinkindot-L3
X-Li-Fabric
X-Thanos
X-Hash
X-Hnp-Log
X-Eu-Site
X-Swa-Ws
X-D
X-Sorting-Hat-ShopId
X-Debug-Cookies
X-Debug-Log
X-CUA
X-Crawler
X-Clientip
X-RateLimit-Limit-Second
X-Core-Mission
X-Nginx-Cache-Key
X-Proxy-Upstream
X-Distributor
X-Platform
X-Response-By
X-Epic-Correlation-Id
X-Svr
X-Policy
X-Dispatcher-Server
X-Proxy-Cache-Status
X-Stale
X-Sorting-Hat-PodId
X-A-Dcw
Lfy
IsBot
Is-Eu
Origin
Platform
Request-Time
X-Upstream-HT
Proxy-Connection
HA-Ipaddr
Adler-Geo
Countrycode
Content-Disposition
CDCHOST
Fastly-Backend-Name
Fastly-Soc-X-Request-Id
Ajk
Ha-Gx-Prefs
Backend
X-Upstream-CT
Magicmarker
Thinkindot-CacheControl
Server-Host
X-Pc-Subdomain
X-Pc-Host
X-HS-Cache-Config
Mn-Server-Ip
X-TIME
X-Pc-Date
Warning
X-Via-CDN
X-Sucuri-Cache
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-Debug-Cache-Store
Server-Surrogate-Control
GW-Server
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
X-Core-Value
Apple-News-Services-Handled
X-Croise-Owner
Apple-News-Services-Host
Cache-Cookie-Set-From
X-Fstrz
Cache-Cookie-Set-Lfrom
X-Up
X-Varnish-Authentication
SS
X-UnsetCookies
Release
X-Developers
X-Device-Os
X-FireWall-Port
Cache-Cookie-Set-Idcheck
AKAMAI
Web-Mar-Node
X-F5-Cache
X-MSEdge-Features
Fastly-SSL
X-SERVER
X-MSEdge-Flight
X-No-Session
RNT-Time
RNT-Machine
X-Cache-ASPX
Resin-Trace
Pramga
Server-Cache-Control
X-Amz-Meta-Surrogate-Control
X-TrackingId
X-Qloud-Router
Server-Int
X-Instart-Isnd
Heartbleed
X-IN-SSL-APIGATEWAY
X-Server-Time
SID
X-Server-Cache
X-Page-Type
X-Key
Pagetype
NGX
REQUESTUUID
Kp-EeAlive
Hostname
X-Be
X-Generation-Time
X-Varnish-Url
X-Servername
X-Owner
Server-ID
X-Sedo-Request-Id
X-Pjax-Url
X-Cache-Miss-From
X-SN
Fastcgi-X-Cache
RequestId
Odigeo-Trace-Id
X-Died
X-Via-NSCOPI
X-Edge-Cache
X-Edge-Cache-Key
X-CDN-Forward
X-Refresh
X-Newrelic-App-Data
MIME-Version
X-NC
Version
X-From-Cache
HostName
HTTPS
X-B3-SpanId
Cteonnt-Length
Cdn-Host
Cdn-Request-Time
X-Oss-Storage-Class
X-Oss-Request-Id
X-Edge-Server
X-Servedbyhost
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
PFcat
X-Oss-Server-Time
Time
X-FPC
ProcessTime
Cdn
Esi-Enabled
X-Req
PICS-Label
X-Store
X-CSRF-TOKEN
Mime-Version
X-Cache-CFC
FastCGI-Cache
MI-API
X-RCS-CacheZone
X-MI-In-Market
X-Mobile-URL
MI-Cache
X-Layer
MI-Cache-Age
X-Hyper-Cache
CF-IPCountry
X-GZip
X-Amzn-Remapped-Date
HA-Geocountry
X-RequestId
X-IPS-LoggedIn
HA-Geolon
HA-Urlpath
HA-Servedtime
HA-Geolat
HA-Host
HA-Georegion
Memory
Processtime
X-Amzn-Remapped-Connection
HA-Geocity
X-VServer
Cross-Origin-Window-Policy
X-Webkit-CSP
X-NodeID
HA-Cloudapp
X-Load-Cache
X-CLOUD-TRACE-CONTEXT
X-HS-Combine-CSS
X-Wa
CDN
X-Dynatrace-Js-Agent
X-Varnish-Beresp-TTL
X-Ratelimit-Remaining
X-Real-Ip
X-HTML-Minification-Powered-By
Cf-Ipcountry
X-Skip-Cache
X-Lb-Id
Backend-Name
XServer
X-Geo
X-Pf-Uncompressing
X-Ratelimit-Limit
X-Aicache-OS
X-DC
X-CMS-Context
X-Newrelic-Synthetics
X-B3-Spanid
X-Mshield-Cache-Status
X-WR-MODIFICATION
Uber-Trace-Id
Ohc-Cache-HIT
X-Mrs-Cache-Hits
X-Unique-Id-Primal
X-Mrs-Cache
X-Mrs-Age
X-VC-Cache
X-Instart-Info
Ohc-Response-Time
X-WebServer
X-WA
X-Atg-Version
X-Tb-Optimization-Total-Bytes-Saved
X-Cms-Context
X-Phone
X-PF-Uncompressing
URI
X-UCC
GeoIP-Country-Code
X-Gateway-Skip-Cache
X-Request-Start
X-Gateway-Cache-Key
X-Gateway-Cache-Status
X-Release
X-Fastly-Country-Code
N-Cache
Amp-Access-Control-Allow-Source-Origin
X-Nananana
T-Server
Accept-Ch-Lifetime
GeoIP-Latitude
X-FORWARDED-FOR
Pics-Label
X-Oracle-Dms-Ecid
X-Processor
X-LB-ID
X-Server-W
X-Shard
X-COUNTRY
X-MServer
X-APP
X-Hp-Webp
X-BBXSRF
X-CSRF-Token
X-Served-From
X-Worker
X-Datadome
X-ND-Cache
X-Unique-Id
Rt-Proxy-Cache
X-SRV
X-GoCache-CacheStatus
X-LiteSpeed-Cache-Control
A
X-VHOST
X-ServedByHost
X-SERVER-NAME
X-VCT
X-Amzn-Remapped-Content-Length
X-UPSTREAM-Address
DataCenter
X-Fastly-Cache-Hits
X-Geo-Header
Host-ID
X-GeoIP-City
X-CACHE-AGE
X-HS-Status
UCS
X-Requestid
X-Check-Cacheable
V-Age
X-GZIP
X-Cdn-Origin
X-Optimization
X-Cache-HT
X-Sn-Servicetimems
X-NGINX-Cache
Dnion-Transfer-Encoding
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
Cneonction
X-BE
X-ID
Request-EU
Request-Country
X-Vcache
Geoip-Latitude
Proxy-Firewall
X-Backend-TTL
X-Port
X-Fastly-Backend-Reqs
Requestid
X-Git-Hash
X-P-T
X-PJAX-URL
WP-Super-Cache
X-ServerName
X-Csrf-Token
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
Pragrma
FSS-Proxy
X-Fpc
FSS-Cache
Is-Session-Tracking
WZWS-RAY
Get-Access-Time
X-Varnish-URL
X-PAGE-TYPE
GeoIp-Country-Code
Server-Id
X-NWS-UUID-VERIFY
Serverid
X-Gen-Id
Cache-Provider
X-Fe
X-HostName
X-StackifyID
X-LiteSpeed-Tag
X-Org
ServerName
RequestUuid
X-Dw-Trace-Id
178proxuri
DSUID
X-Via-SSL
X-Via-Edge
X-RCS-Backend
X-Html-Edge-Cache
286prxHost
352pxline
Xxline
355prline
189phosttRef
X-GDPR
188prxHost
X-RAMCache
X-Request-Url
225prxHost
Inserted-Into-Cache-At
219prxHost
409pxxline
X-CS