Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
CF-RAY
ETag
Link
Expect-CT
Via
X-XSS-Protection
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Xss-Protection
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Request-Id
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Adblock-Key
X-Check
Alt-Svc
X-Cacheable
X-Generator
Content-Security-Policy-Report-Only
X-AspNetMvc-Version
X-Cache-Status
X-DNS-Prefetch-Control
X-Permitted-Cross-Domain-Policies
X-Iinfo
X-Template
X-Language
Status
Timing-Allow-Origin
X-Buckets
X-FRAME-OPTIONS
X-Content-Security-Policy
Content-Encoding
X-Kinja-Server-Push
Xkey
X-Turbo-Charged-By
X-CDN
Upgrade
X-Type
Keep-Alive
Access-Control-Expose-Headers
WPE-Backend
X-Pass-Why
X-AH-Environment
X-Backend
Access-Control-Max-Age
P3p
X-Age
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Server
X-Proxy-Cache
X-Via
X-Request-ID
Grace
X-Pingback
X-Nginx-Cache-Status
X-Server-Powered-By
X-Robots-Tag
X-Amz-Request-Id
X-Amz-Id-2
X-Hacker
X-Varnish-Cache
X-Page-Speed
X-UA-Device
EagleId
Request-Context
X-LiteSpeed-Cache
X-Envoy-Upstream-Service-Time
Cf-Railgun
X-CST
X-Ua-Compatible
X-Swift-CacheTime
X-Swift-SaveTime
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Ali-Swift-Global-Savetime
X-Amz-Version-Id
X-Device
X-WebKit-CSP
X-Server-Id
Server-Timing
Allow
X-Ac
X-Node
Feature-Policy
X-Response-Time
X-Rq
X-OneAgent-JS-Injection
X-Cnection
X-Iejgwucgyu
Content-Location
X-Backend-Server
Report-To
X-Cache-Lookup
EagleEye-TraceId
X-Host
Surrogate-Control
X-Readtime
X-Application-Context
Request-Id
X-ORACLE-DMS-ECID
X-Rack-Cache
X-Url
X-Origin-Cache
X-Clacks-Overhead
X-Country
NEL
X-FTR-Request-ID
Rating
X-Cloud-Trace-Context
X-Country-Code
X-Dns-Prefetch-Control
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-DataDome
X-Cdn
X-Px
X-Ruxit-JS-Agent
X-Mod-Pagespeed
X-Instart-Request-ID
X-Vhost
Charset
X-VARITI-CCR
X-MS-InvokeApp
Accept-CH
X-Goog-Hash
Edge-Control
Verso
X-Upstream-Env
X-GitHub-Request-Id
X-PC
X-TtlSet
X-Vname
Pinterest-Generated-By
X-ESI
X-Server-Name
Arc-Version
PB-RID
PB-PID
X-Mobile-Rewrite
X-Version
X-DynaTrace
X-Powered-By-Plesk
X-B3-TraceId
X-D2id
X-Kinja-Build
X-Kinja-Revision
X-Kinja-Server
X-Kinja
X-Exp-Variant
X-Exp-Id
X-Cdn-Fetch
X-Use-Magma
X-GoogleNews-Bot
X-Origin-Upstream-Status
X-Cached
X-Dispatcher
X-TTL
X-Recruiting
SPRequestGuid
MS-Author-Via
X-SharePointHealthScore
X-ORACLE-DMS-RID
X-Abt-Application-Version
Accept-CH-Lifetime
X-Navigation-Version
X-Varnish-TTL
Content-MD5
RTSS
X-Powered-CMS
AR-CACHE
AR-PoweredBy
AR-ATIME
X-Shield-Request-Id
X-T
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Server-ID
X-Forwarded-Proto
X-Trace
X-Client-IP
Public-Key-Pins
X-Amz-Rid
Arr-Disable-Session-Affinity
X-HW
X-Fastly-Request-ID
X-Wix-Server-Artifact-Id
X-Accel-Buffering
X-DynaTrace-JS-Agent
X-Oracle-Dms-Rid
SPIisLatency
SPRequestDuration
Realpath
X-DIS-Request-ID
Service-Worker-Allowed
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Length
AR-Request-ID
X-Goog-Stored-Content-Encoding
Paypal-Debug-Id
X-Amz-Meta-S3cmd-Attrs
Front-End-Https
X-Ser
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-Cache-Status
X-FTR-DC
X-FTR-Realm
X-FTR-Backend
X-Country-Code-Real
X-Upstream
X-Ttl
X-FTR-Expires
X-B
X-Pinterest-Rid
X-Id
Pinterest-Version
X-Via-JSL
X-F-Cache
Ar-Sid
X-Dw-Request-Base-Id
X-Debug
X-Vcap-Request-Id
X-Goog-Storage-Class
X-DataStream-Cache-Status
X-XRDS-Location
X-Varnish-Age
X-Acc-Meta-Resource-Type
X-Kinsta-Cache
X-MSEdge-Ref
X-N
Nginx-Cache
X-Hits
X-NF-Request-ID
S
X-FTR-Cache-Host
X-NewRelic-App-Data
X-Logged-In
X-Akam-SW-Version
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Mrf-Item-Lastmod
X-Forwarded-For
X-Mrf-Section-Lastmod
Tracecode
Alternate-Protocol
X-User-Agent
X-Grace
X-Frontend
X-Amzn-Trace-Id
X-PressLabs-Stats
X-HS-Content-Id
X-HS-Hub-Id
X-FastCGI-Cache
TCN
Server-Name
X-Content-Digest
X-Middleton-Display
X-Sol
Display
X-Content-Options
X-CACHE-GROUP
AMP-Access-Control-Allow-Source-Origin
Refresh
X-Content-Type
Powered-By-ChinaCache
Access-Control-Request-Method
X-Pad
X-Middleton-Response
Response
Backend-Timing
X-Analytics
MicrosoftSharePointTeamServices
X-Page-Id
DynaTrace
Accept-Charset
FilterID
X-CF-Powered-By
X-Zen-Fury
X-LB-Cache
X-AppVersion
X-Activity-Id
X-Az
X-IPLB-Instance
Host
Fastcgi-Cache
X-Rid
X-Debug-Info
ServerID
X-Hostname
MS-CV
Cache-Status
X-VCache
X-Cache-Hit
X-Srv
X-Cache-Key
X-Seen-By
X-Magnolia-Registration
TP-L2-Cache
TP-Cache
X-Oneagent-Js-Injection
X-Content-Powered-By
X-GUploader-UploadID
X-ATG-Version
X-RateLimit-Remaining
X-Fastcgi-Cache
X-Mobile
X-Revision
X-Cached-By
X-Varnish-Backend
X-Real-IP
X-WA-Info
X-Whom
X-Request-Processing-Time
X-Request-Received
Host-Header
Server-Info
Surrogate-Key
VIX-Pulpo-Node
X-B3-Sampled
X-Instance
VIX-Pulpo-Upstream-Status
X-Cluster
X-Cache-Action
Fusion-Source
Fusion-Template-Id
X-Request-Guid
Fusion-Content-Source
Fusion-Content-Id
DC
Source
X-Content-Security-Policy-Report-Only
X-PHP-Backend
Fusion-Component-Id
X-Drupal-Cache-Tags
X-Handled-By
ViewerVersion
X-Ruxit-Js-Agent
X-Tumblr-Pixel
X-Wix-Request-Id
X-Amz-Apigw-Id
X-Tumblr-User
Cleartype
X-Tumblr-Pixel-0
X-Amzn-RequestId
X-B-Cache
X-Akamai-Edgescape
X-Framework
X-Platform-Server
X-TT
X-Signature
X-SS-Set-Cookie
X-Origin-Server
X-Cache-Age
X-App-Environment
X-XRDS-LOCATION
X-App-Server
X-FW-Type
X-FW-Hash
X-FW-Serve
X-FW-Server
X-FW-Static
X-AOL-HN
X-Geo-Country
X-Generated-By
Rt-Fastcgi-Cache
X-Varnish-Server
X-Cache-Control
Server-Node
X-BCube-Filmed-By
X-Upstream-Proxy
X-Edge-Location
X-Varnish-Hostname
X-NWS-LOG-UUID
Retry-After
X-Cache-Rule
Payment
Pagespeed
X-Varnish-Grace
X-Correlation-Id
X-Amz-Server-Side-Encryption
X-Cache-2
Access-Control-Allow-Method
X-Amz-Replication-Status
X-Ezoic-Cdn
X-Response-Served-From
X-Rendered-As
X-TA-CDN-Provider
X-UA-Device-Type
X-FB-Debug
X-Cache-Config
Actual-Object-TTL
ServedBy
GEO-INFO
X-TT-TIMESTAMP
X-Varnish-Hits
Healthy
X-Contextid
X-Cacheable-TTL
Eomportal-Instance
Ms-Operation-Id
X-Jobs
X-Region
X-TX-ID
X-Tumblr-Pixel-1
X-RTag
Filters
NGB
Content-Style-Type
X-Tumblr-Pixel-2
X-WebKit-CSP-Report-Only
Content-Script-Type
X-Cache-TTL
X-VG-WebCache
HitType
X-Drupal-Cache-Contexts
AsisCache
Webserver
Viewport
X-UUID
X-Adobe-Content
X-Adobe-Loc
X-Varnish-IP
Upgrade-Insecure-Requests
X-RequestSource
From-Origin
X-Locale
Country
X-Accel-Expires
Cache-Tv-Group
Fastcgi-Useragent
X-Cache-TTL-Remaining
X-FW-Dynamic
X-BACKEND-TTL
X-Device-Type
X-Cache-Server
X-Content-Age
X-WPE-Loopback-Upstream-Addr
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Cache-Tags
Edge-Cache-Tag
X-CACHE-KEY
X-Servedby
X-Redis-Cache
X-Cache-Remote
X-Upgrade-Enabled
X-DataStream-MidMile-RTT
X-DataStream-Origin-MEX-Latency
X-Source
Datacenter
Cache
X-Cache-Operation
X-Hit
X-Storage
X-Esi
X-GeoIP
X-APP-VERSION
X-RateLimit-Limit
Fastly-Restarts
X-Mode
NtCoent-Length
Cache-Tag
X-Cache-Var
X-Cache-Var-Map
X-JoinUs
X-Backend-Name
X-RN-RSRV
Served-By
X-Is-Bot
Xserver
X-Hl-Ver
X-S
X-Internal-Host
X-Detected-As
X-TNCMS
X-Agile-Id
Machine
X-Loop
X-Path-Route
Load-Balancing
X-Pubstack
X-Agile-Age
X-Agile
Vix-Hermes-Req-Id
Meta-Geo
X-Timing-Wait
X-Time-Microsecs
X-Varnish-Cache-Hits
X-ProxyCache-Key
X-CDN-Cache
X-BYPASS-REASON
X-Akamai-Request-ID
X-Edge-IP
X-Environment-Context
X-Generated
X-FC-Vary-Parameters
X-Hosted-By
Selected-FE
Cache-Key
X-Status
X-ProxyCache-Status
X-Proxy-Build
Now
Origin-Edge-Control
Origin-Cache-Control
X-ServerID
X-Tb
X-Microcachable
X-Varnish-Cacheable
X-NCache
X-Labrador-Cache-Channel
X-Www-Served-By
X-Origin-Response-Time
X-App-Version
X-L-Path
X-Origin-Host
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Privacy
X-PERF
X-IP
TWC-Locale-Group
TWC-Connection-Speed
X-Proxy
Cache-Name
X-ProcessESI
X-VG-TLSProxy
Webcakes-App-Name
S-Rt
Property-Id
TWC-Device-Class
X-RemovedCookies
X-Format
X-Rule
Webcakes-App-Version
X-Birta-Cache-Post
X-Via-Fastly
X-Birta-Served
X-Cache-Category-Id
X-Origin-Hint
Webcakes-Region
X-Grey
X-ApacheServer
X-Viewer-Country
User-Agent
X-CCM
X-OCL
X-Cache-Enabled
SRV
X-ES-SERVER
X-EdgeConnect-Cache-Status
X-Access
X-Web-Node
Public-Key-Pins-Report-Only
Fastcgi-X-Cache-Version
X-Section
Azure-SlotName
Azure-RegionName
Azure-InstanceId
X-Akamai-Transformed
Access-Control-Request-Headers
Azure-Version
Azure-SiteName
Cache-Hits
DB-Nickname
X-PCL
X-Xfnlog-Site
X-Site-Version
X-Zipkin-Id
X-Debug-Cache
X-App-Name
X-Routing-Service
X-GEO
Mail-Subject
X-MP-GENERATED-AT
X-Proxied
We-Hiring
X-Human
Liferay-Portal
X-Node-Name
X-NGENIX-Cache
CACHE
X-Varnish-Ttl
LB
S-Cnection
X-Protected-By
X-FW-Version
X-Guploader-Uploadid
X-Sucuri-ID
X-Origin
X-Nginx-Cache
X-Original-Request
X-Proto
X-Daa-Tunnel
X-Cache-NE
X-Cdn-Forward
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Ocache
X-Pc-Hit
X-Pc-Key
X-Pc-Appver
X-AWS-Id
X-LJ-Flow-ID
X-VWS-Id
X-Trace-Id
Powered
X-Request-Time
User-Cache-Control
X-Forwarded-Host
X-Cluster-Node
X-Ua
X-Endurance-Cache-Level
L5d-Success-Class
X-UA
X-Nc
X-GRACE
Section-Io-Cache
Frame-Options
Ohc-File-Size
X-Time
X-Tumblr-Pixel-3
X-Unique-ID
X-Correlation-ID
X-V
X-FB-TRIP-ID
X-EIG-Tracking-Id
X-Webstats-RespID
OT-Force-Account-Verify
X-Origin-CC
PageSpeed
X-URL
X-OVcl
X-OVcl-Cache
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
X-Webkit-Csp
AR-SID
X-Origin-TTL
Decoy-Debug-TTL
Decoy-Debug-Key
X-From
Decoy-Debug-Status
Nel
X-ElasticPress-Search
Hostname
X-Cache-Backend
Fly-Request-Id
X-Li-Fabric
X-NU-AKA-ACS-Version
X-S-Cookie
X-Irp-Debug
X-LI-Proto
X-ScT
X-Li-Pop
Fastly-SIE
Country-Code
Fastly-SWR
Fly-Cache
Ec-Rule-Version
X-S-Maxage
X-IN-APIGATEWAY
X-Fetched-On
X-Developer
X-Generated-In
X-External-Request-Id
X-Server-By
X-Server-Group
X-DPWN-IS-SECURE
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Destination
X-Date
X-IN-WAF
X-Info
X-Origin-Expires
Cache-Prefix
Arc-Country
BehaviorPad-Version
X-Origin-Date
X-Rocket-Nginx-Bypass
Www
VivaBuild
Viewtype
MD5-Digest
X-Accel-Expires-Debug
X-Aed
X-ARC
X-Application
X-Amz-Meta-Cache-Control
SD-X-WS
Rendered-Blocks
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Reboot
Mobile-Detection-Method
Node
X-Node-Id
Powered-By
On-Server
X-Region-Sid
X-Auto-Login
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-PHP-Host
X-Cache-Id
X-PAYTM-SRV-ID
X-Connection-Hash
X-Rojux
Meta-Geo-Continent
GMS-Ver
X-Cache-Host
X-Cache-Grace
X-BB-ID
X-Backend-State
X-B-Cookie
X-Distil-CS
X-Cache-FS-Status
X-Rewrite-Enabled
X-Response-By
X-Request-UUID
X-LI-UUID
Xc-Version
X-We-Are-Hiring
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-UE-Client-Country
X-VG-WebServer
X-R9-Blue-Green-Version
X-Twitter-Response-Tags
X-Trv-Group
X-Transaction
X-Parent-Response-Time
X-SRCache-Key
X-ServiceProvider
X-Via-CDN
Mn-Server-Ip
X-A-Wwc
X-Variation
X-A-Dgt
X-A-Dcw
X-A-Ccd
X-A-Dam
X-Actual-URL
X-Varnish-Action
X-Level-Front-Cache
X-Vgn-Hpd-Reason
X-Varnish-Beresp-Ttl
X-Alternate-Cache-Key
X-Var-Ttl
X-LAGOON
Who
X-Micro-Cache
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Server-Host
X-Proxy-Upstream
Proxy-Connection
Request-Time
Thinkindot-Control
X-Matched-Rule
X-Location
X-Platform
X-User
X-Policy
True-Client-Country-4JS
X-Logtrace-Id
X-Proxy-Cache-Status
X-Bip
X-C
X-Eu-Site
X-Passed-To-DLL
X-Epic-Correlation-Id
X-Distributor
X-Debug-Log
X-Dispatcher-Server
X-Passed-To-BeforeDispatch
X-Passed-To
X-GeoIP-Country-Code
X-Hash
X-Generated-On
X-Gen-Mode
X-G
X-Gannett-Site-Version
X-Debug-Cookies
X-D
X-Hnp-Log
X-Cache-Info
X-Nginx-Cache-Key
X-NX-Host
X-Cache-Debug
X-Cache-Expires
X-Cache-URL
X-Cdn-Srv
X-Crawler
X-CUA
X-Core-Mission
X-Passed-To-PostProcessResponse
X-CGP
X-Clientip
X-Block-Status
X-A
X-Secret
X-ShopId
Is-Eu
X-Sorting-Hat-ShopId
IsBot
Backend
Magicmarker
X-Svr
X-ShardId
X-Request-URI
HA-Ipaddr
X-Returned-From
X-Returned-From-BeforeDispatch
X-Shopify-Stage
X-Returned-From-DLL
X-Returned-From-PostProcessResponse
X-Swa-Ws
X-Thanos
Ha-Gx-Prefs
CDCHOST
X-Thinkindot-L3
Memcached
X-RateLimit-Remaining-Second
X-Stale
Adler-Geo
X-Sf
Fastly-Soc-X-Request-Id
X-RateLimit-Limit-Second
X-Sorting-Hat-PodId
Ajk
Origin
X-TT-LOGID
Platform
X-SIPLIST1
X-Dc
Fastly-Backend-Name
Fastly-SSL
Countrycode
Warning
IBM-Web2-Location
X-Debug-Cache-Fetch
Pramga
Content-Disposition
X-Debug-Cache-Store
X-Core-Value
X-Croise-Owner
X-FireWall-Port
X-Debug-Cache-Expiry
Cache-Cookie-Set-From
AKAMAI
Apple-News-Services-Handled
Apple-News-Services-Host
X-Instart-Isnd
X-SERVER
X-No-Session
X-MSEdge-Flight
X-MSEdge-Features
Apple-News-Services-Parsed-Url
X-Fstrz
X-Developers
X-SN
X-Owner
X-Device-Os
Cache-Cookie-Set-Idcheck
Apple-News-Services-Request-Url
X-Fastly-Cache
Cache-Cookie-Set-Lfrom
SS
Resin-Trace
Lfy
X-Up
X-Server-IP
Heartbleed
X-Amz-Meta-Surrogate-Control
X-Sucuri-Cache
SID
X-TrackingId
X-UnsetCookies
RNT-Time
RNT-Machine
Server-Cache-Control
Server-Int
NGX
Server-Surrogate-Control
X-Varnish-Authentication
Web-Mar-Node
GW-Server
X-Cache-Bucket
Release
X-Qloud-Router
X-Backend-Url
X-Cache-ASPX
X-Backend-Host
X-HS-Cache-Config
X-Page-Type
X-Varnish-Url
Server-ID
REQUESTUUID
X-Key
Kp-EeAlive
X-Server-Time
Odigeo-Trace-Id
X-F5-Cache
Pagetype
X-Pc-Subdomain
X-Pc-Host
X-Be
X-Pc-Date
X-Upstream-CT
X-TIME
X-Pjax-Url
X-Sedo-Request-Id
X-Upstream-HT
X-Cache-Miss-From
X-B3-Traceid
X-Servername
X-IN-SSL-APIGATEWAY
HTTPS
X-Server-Cache
X-Refresh
X-Oss-Storage-Class
Cdn-Host
X-Edge-Server
Cdn-Request-Time
X-Generation-Time
X-Oss-Server-Time
X-Oss-Object-Type
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-Newrelic-App-Data
ProcessTime
X-From-Cache
X-Via-NSCOPI
X-Died
Fastcgi-X-Cache
X-CDN-Forward
MIME-Version
RequestId
X-Ua-Device
X-Dynatrace-Js-Agent
Mime-Version
X-NC
X-B3-SpanId
X-Req
X-Servedbyhost
Cdn
X-Mobile-URL
Version
X-Edge-Cache-Key
X-Edge-Cache
X-NodeID
X-VServer
X-Amzn-Remapped-Date
PFcat
X-CSRF-TOKEN
X-FPC
Cross-Origin-Window-Policy
X-Amzn-Remapped-Connection
HostName
X-Load-Cache
Cteonnt-Length
X-Ratelimit-Remaining
FastCGI-Cache
Time
PICS-Label
X-GZip
X-HS-Combine-CSS
X-Cache-CFC
X-Webkit-CSP
Esi-Enabled
X-Store
CF-IPCountry
X-CLOUD-TRACE-CONTEXT
Uber-Trace-Id
X-MI-In-Market
Cf-Ipcountry
MI-API
MI-Cache-Age
X-RCS-CacheZone
Memory
X-Layer
MI-Cache
X-Wa
X-Skip-Cache
Ohc-Cache-HIT
X-Varnish-Beresp-TTL
Processtime
X-Ratelimit-Limit
HA-Servedtime
HA-Urlpath
HA-Geocity
X-VC-Cache
HA-Georegion
HA-Geolon
HA-Geocountry
HA-Geolat
HA-Cloudapp
X-Newrelic-Synthetics
X-Aicache-OS
HA-Host
X-RequestId
X-Lb-Id
X-HTML-Minification-Powered-By
X-IPS-LoggedIn
Amp-Access-Control-Allow-Source-Origin
CDN
X-Hyper-Cache
X-DC
X-Geo
X-Cms-Context
X-Shard
X-Pf-Uncompressing
N-Cache
X-PF-Uncompressing
Backend-Name
X-Fastly-Country-Code
X-UCC
XServer
X-B3-Spanid
X-CMS-Context
X-Gateway-Skip-Cache
X-WA
X-Gateway-Cache-Key
X-Gateway-Cache-Status
X-Atg-Version
X-Real-Ip
X-Instart-Info
X-LB-ID
X-Tb-Optimization-Total-Bytes-Saved
X-WR-MODIFICATION
X-Processor
X-Mrs-Age
X-Mrs-Cache-Hits
X-Unique-Id-Primal
X-Mrs-Cache
X-Mshield-Cache-Status
Accept-Ch-Lifetime
X-Nananana
URI
T-Server
X-Hp-Webp
X-BBXSRF
X-Phone
X-WebServer
Ohc-Response-Time
X-Oracle-Dms-Ecid
X-Request-Start
Pics-Label
GeoIP-Country-Code
X-Release
GeoIP-Latitude
X-COUNTRY
X-MServer
X-Vcache
X-Server-W
X-APP
X-VCT
X-GeoIP-City
X-Unique-Id
X-Datadome
X-Worker
X-CSRF-Token
X-SRV
X-FORWARDED-FOR
Host-ID
X-Amzn-Remapped-Content-Length
X-Geo-Header
X-VHOST
UCS
X-ServedByHost
A
X-SERVER-NAME
X-GoCache-CacheStatus
X-Served-From
X-HS-Status
Rt-Proxy-Cache
X-CACHE-AGE
X-GZIP
X-LiteSpeed-Cache-Control
X-ND-Cache
DataCenter
Request-Country
Request-EU
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Requestid
X-Optimization
X-Fpc
X-UPSTREAM-Address
FSS-Cache
FSS-Proxy
X-Cache-HT
X-Fastly-Cache-Hits
Pragrma
X-Planisys-CDN-Cache
X-Check-Cacheable
WP-Super-Cache
X-NGINX-Cache
X-ID
X-BE
X-ServerName
Dnion-Transfer-Encoding
WZWS-RAY
X-Org
Geoip-Latitude
X-Backend-TTL
Requestid
X-Git-Hash
X-Sn-Servicetimems
X-Fastly-Backend-Reqs
X-Varnish-URL
X-Csrf-Token
X-Via-SSL
X-PAGE-TYPE
X-Html-Edge-Cache
X-Port
Cneonction
X-PJAX-URL
X-Via-Edge
GeoIp-Country-Code
X-Cdn-Origin
V-Age
X-Dw-Trace-Id
Serverid
RequestUuid
Cache-Provider
Server-Id
X-SVT-ORM-RULES
Proxy-Firewall
X-HostName
X-Gen-Id
X-SVT-ORM-VERSION
X-NWS-UUID-VERIFY
DSUID
Inserted-Into-Cache-At
225prxHost
X-P-T
355prline
352pxline
409pxxline
X-Fe
X-Request-Url
Xxline
X-CS
286prxHost
178proxuri
Is-Session-Tracking
X-RAMCache
188prxHost
189phosttRef
219prxHost
X-LiteSpeed-Tag
Get-Access-Time