Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
CF-RAY
ETag
Link
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Xss-Protection
X-Request-Id
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Adblock-Key
X-Check
Alt-Svc
X-Cacheable
X-Generator
Content-Security-Policy-Report-Only
X-AspNetMvc-Version
X-Cache-Status
X-Permitted-Cross-Domain-Policies
X-Iinfo
X-Template
X-DNS-Prefetch-Control
X-Language
Status
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Buckets
X-Content-Security-Policy
Content-Encoding
X-Request-ID
X-Kinja-Server-Push
Xkey
X-Turbo-Charged-By
Upgrade
X-CDN
X-Type
Keep-Alive
Access-Control-Expose-Headers
WPE-Backend
X-Pass-Why
X-AH-Environment
X-Backend
Access-Control-Max-Age
X-Age
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Server
X-Proxy-Cache
X-Via
X-Pingback
Grace
X-Nginx-Cache-Status
X-Server-Powered-By
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Hacker
X-Varnish-Cache
X-Page-Speed
X-UA-Device
EagleId
Request-Context
P3p
X-LiteSpeed-Cache
X-Envoy-Upstream-Service-Time
Cf-Railgun
X-CST
X-Swift-SaveTime
X-Swift-CacheTime
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Amz-Version-Id
X-Device
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Server-Id
Server-Timing
Allow
X-Ac
X-Node
X-OneAgent-JS-Injection
Feature-Policy
X-Rq
X-Response-Time
X-Cnection
X-Iejgwucgyu
Content-Location
X-Backend-Server
Report-To
EagleEye-TraceId
X-Host
Surrogate-Control
X-Cache-Lookup
X-Readtime
X-Application-Context
Request-Id
X-Dns-Prefetch-Control
X-ORACLE-DMS-ECID
X-Url
X-Rack-Cache
X-Ua-Compatible
X-Origin-Cache
X-Clacks-Overhead
X-Country
NEL
X-FTR-Request-ID
Rating
X-Country-Code
X-Cloud-Trace-Context
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Cdn
X-DataDome
X-Ruxit-JS-Agent
X-Px
X-Mod-Pagespeed
X-Instart-Request-ID
X-Vhost
Charset
X-VARITI-CCR
X-MS-InvokeApp
Accept-CH
X-Goog-Hash
Edge-Control
X-Upstream-Env
X-Vname
X-PC
Verso
X-TtlSet
X-GitHub-Request-Id
X-Server-Name
Pinterest-Generated-By
X-ESI
Arc-Version
X-Mobile-Rewrite
PB-RID
PB-PID
X-Version
X-DynaTrace
X-Origin-Upstream-Status
X-Powered-By-Plesk
X-D2id
X-Exp-Id
X-Cdn-Fetch
X-Exp-Variant
X-Kinja
X-Use-Magma
X-Kinja-Revision
X-Kinja-Build
X-GoogleNews-Bot
X-Kinja-Server
X-TTL
X-Cached
X-Dispatcher
X-B3-TraceId
X-Recruiting
SPRequestGuid
MS-Author-Via
X-SharePointHealthScore
X-Abt-Application-Version
X-Varnish-TTL
Content-MD5
X-Navigation-Version
Accept-CH-Lifetime
AR-ATIME
AR-CACHE
AR-PoweredBy
RTSS
X-Powered-CMS
X-ORACLE-DMS-RID
X-Shield-Request-Id
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Forwarded-Proto
X-Trace
X-HW
X-T
X-Client-IP
Public-Key-Pins
X-Amz-Rid
X-Oracle-Dms-Rid
Arr-Disable-Session-Affinity
X-Fastly-Request-ID
X-Wix-Server-Artifact-Id
X-Accel-Buffering
X-DynaTrace-JS-Agent
SPIisLatency
SPRequestDuration
Realpath
AR-Request-ID
Service-Worker-Allowed
X-Server-ID
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Metageneration
X-DIS-Request-ID
Paypal-Debug-Id
X-Amz-Meta-S3cmd-Attrs
Front-End-Https
X-FTR-DC
X-FTR-Cache-Status
X-FTR-Backend-Server
X-FTR-Backend
X-Country-Code-Real
X-FTR-Balancer
X-FTR-Realm
X-FTR-Expires
X-Ser
X-Upstream
Pinterest-Version
X-Pinterest-Rid
X-XRDS-Location
X-B
Ar-Sid
X-DataStream-Cache-Status
X-Via-JSL
X-Debug
X-Ttl
X-Id
X-Dw-Request-Base-Id
X-Goog-Storage-Class
X-Vcap-Request-Id
X-F-Cache
X-Kinsta-Cache
X-N
X-Acc-Meta-Resource-Type
X-Varnish-Age
X-MSEdge-Ref
X-NF-Request-ID
Nginx-Cache
X-Hits
S
X-FTR-Cache-Host
X-Akam-SW-Version
X-Logged-In
X-NewRelic-App-Data
MRF-Tech
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
X-Forwarded-For
Mrf-Cache-Status
X-B3-TraceId-Primal
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Grace
Tracecode
Alternate-Protocol
X-FastCGI-Cache
X-Amzn-Trace-Id
X-Frontend
TCN
X-User-Agent
X-PressLabs-Stats
X-HS-Hub-Id
X-HS-Content-Id
X-Content-Options
X-CACHE-GROUP
AMP-Access-Control-Allow-Source-Origin
Server-Name
Display
X-Middleton-Display
X-Sol
Powered-By-ChinaCache
X-Content-Type
X-Content-Digest
Refresh
Access-Control-Request-Method
X-VCache
Response
X-Middleton-Response
X-Pad
X-Cache-Key
X-Page-Id
Backend-Timing
MicrosoftSharePointTeamServices
X-Analytics
Accept-Charset
FilterID
X-AppVersion
X-Zen-Fury
X-LB-Cache
X-Activity-Id
X-Az
Host
X-Debug-Info
X-GUploader-UploadID
X-IPLB-Instance
X-Rid
X-CF-Powered-By
DynaTrace
Fastcgi-Cache
X-Hostname
X-Cache-Hit
MS-CV
Cache-Status
X-Seen-By
ServerID
TP-Cache
TP-L2-Cache
X-RateLimit-Remaining
X-Magnolia-Registration
X-Content-Powered-By
X-Srv
X-Revision
X-Mobile
X-Cached-By
X-Whom
Server-Info
X-Fastcgi-Cache
X-Real-IP
Fusion-Content-Source
Fusion-Template-Id
Host-Header
Fusion-Component-Id
X-Varnish-Backend
Fusion-Content-Id
Fusion-Source
X-Request-Processing-Time
X-PHP-Backend
X-Request-Received
X-ATG-Version
X-Amz-Apigw-Id
X-Amzn-RequestId
VIX-Pulpo-Upstream-Status
X-Cluster
VIX-Pulpo-Node
X-WA-Info
X-SS-Set-Cookie
X-Instance
X-Handled-By
Source
X-Request-Guid
DC
Surrogate-Key
X-Drupal-Cache-Tags
X-Content-Security-Policy-Report-Only
X-Cache-Action
X-B3-Sampled
X-Platform-Server
X-Wix-Request-Id
ViewerVersion
X-Upstream-Proxy
Cleartype
X-TT
X-Tumblr-Pixel
X-Framework
X-Tumblr-User
X-Origin-Server
X-Tumblr-Pixel-0
X-B-Cache
X-App-Environment
X-Signature
X-Akamai-Edgescape
X-Geo-Country
X-App-Server
X-FW-Server
X-Cache-Age
X-FW-Static
X-FW-Hash
X-FW-Serve
X-FW-Type
X-Varnish-Server
X-Generated-By
X-AOL-HN
X-Oneagent-Js-Injection
Server-Node
X-BCube-Filmed-By
X-Cache-Control
X-XRDS-LOCATION
X-Ruxit-Js-Agent
Rt-Fastcgi-Cache
X-Edge-Location
X-Varnish-Grace
X-Varnish-Hostname
X-Amz-Server-Side-Encryption
Retry-After
Payment
X-Ezoic-Cdn
X-Cache-2
X-NWS-LOG-UUID
X-Cache-Rule
X-Amz-Replication-Status
Access-Control-Allow-Method
X-FB-Debug
X-UA-Device-Type
X-Accel-Expires
X-TT-TIMESTAMP
X-Correlation-Id
X-Response-Served-From
X-Rendered-As
ServedBy
GEO-INFO
X-Region
X-Cache-TTL
X-Cacheable-TTL
HitType
Ms-Operation-Id
NGB
X-WebKit-CSP-Report-Only
Filters
Content-Script-Type
Content-Style-Type
AsisCache
Actual-Object-TTL
Webserver
X-TX-ID
X-Contextid
X-Drupal-Cache-Contexts
X-Jobs
X-RTag
Pagespeed
X-UUID
X-Cache-Config
Fastcgi-Useragent
X-Varnish-Hits
Healthy
X-Locale
X-Tumblr-Pixel-2
Upgrade-Insecure-Requests
X-Varnish-IP
Viewport
X-Adobe-Loc
X-VG-WebCache
X-Tumblr-Pixel-1
X-Adobe-Content
From-Origin
X-RequestSource
Eomportal-Instance
Country
Cache-Tv-Group
X-Cache-TTL-Remaining
X-FW-Dynamic
X-Kong-Proxy-Latency
X-BACKEND-TTL
X-Kong-Upstream-Latency
X-Device-Type
X-Content-Age
Cache-Tags
X-WPE-Loopback-Upstream-Addr
X-Redis-Cache
Edge-Cache-Tag
X-Cache-Server
X-Source
X-APP-VERSION
X-DataStream-MidMile-RTT
X-DataStream-Origin-MEX-Latency
X-Upgrade-Enabled
X-Cache-Remote
X-TA-CDN-Provider
CACHE
X-Esi
X-Servedby
X-GeoIP
Datacenter
NtCoent-Length
X-Hit
X-Storage
X-Cache-Operation
X-RateLimit-Limit
X-Mode
User-Agent
Machine
X-Path-Route
X-ES-SERVER
Load-Balancing
Meta-Geo
X-Origin-Response-Time
X-Labrador-Cache-Channel
X-IP
Vix-Hermes-Req-Id
X-Hl-Ver
X-Is-Bot
Fastly-Restarts
X-JoinUs
X-Loop
X-Detected-As
X-Agile-Age
X-TNCMS
X-Cache-Var
X-Agile-Id
Cache-Tag
X-Akamai-Request-ID
X-Time-Microsecs
X-Cache-Var-Map
X-RN-RSRV
X-Hosted-By
X-Agile
X-Status
X-Birta-Cache-Post
Cache-Key
X-BYPASS-REASON
X-Birta-Served
X-Cache-Category-Id
X-L-Path
X-Generated
Served-By
X-Grey
X-FC-Vary-Parameters
X-CDN-Cache
X-Environment-Context
S-Rt
Selected-FE
X-Www-Served-By
X-Pubstack
X-ProxyCache-Key
X-ServerID
X-Web-Node
X-Varnish-Cacheable
X-Timing-Wait
X-Viewer-Country
X-Tb
X-Proxy-Build
X-ProxyCache-Status
X-Microcachable
X-S
Origin-Edge-Control
Origin-Cache-Control
X-Backend-Name
X-Origin-Host
TWC-Connection-Speed
Webcakes-App-Name
TWC-Device-Class
X-Node-Name
Webcakes-Region
Property-Id
Webcakes-App-Version
Now
TWC-Locale-Group
TWC-Privacy
TWC-GeoIP-LatLong
X-Edge-IP
X-Origin-Hint
X-NCache
X-ApacheServer
TWC-GeoIP-Country
X-ProcessESI
X-Proxy
X-VG-TLSProxy
X-Via-Fastly
X-Rule
X-RemovedCookies
X-Varnish-Cache-Hits
X-Format
X-EdgeConnect-Cache-Status
X-PERF
Cache-Hits
X-CCM
X-OCL
Azure-RegionName
X-PCL
X-Cache-Enabled
Public-Key-Pins-Report-Only
X-Akamai-Transformed
X-Debug-Cache
X-Section
Liferay-Portal
Azure-InstanceId
Access-Control-Request-Headers
Azure-Version
Azure-SlotName
Azure-SiteName
X-Access
Cache-Name
X-Internal-Host
X-Human
We-Hiring
X-App-Name
X-Site-Version
X-Proxied
X-Routing-Service
X-Xfnlog-Site
X-Zipkin-Id
X-GEO
X-CACHE-KEY
DB-Nickname
Cache
Mail-Subject
Fastcgi-X-Cache-Version
Xserver
SRV
X-MP-GENERATED-AT
X-FW-Version
X-Protected-By
S-Cnection
X-Proto
X-NGENIX-Cache
X-AWS-Id
X-VWS-Id
X-LJ-Flow-ID
X-Cluster-Node
X-Yottaa-Metrics
X-Yottaa-Optimizations
LB
X-Origin
X-Original-Request
X-App-Version
X-Sucuri-ID
PageSpeed
Powered
X-Trace-Id
X-Nginx-Cache
X-UA
X-Forwarded-Host
X-Endurance-Cache-Level
X-Cache-NE
L5d-Success-Class
X-Varnish-Ttl
X-EIG-Tracking-Id
User-Cache-Control
X-Request-Time
X-Pc-Hit
X-Ocache
X-Pc-Appver
X-Pc-Key
Frame-Options
Section-Io-Cache
X-Daa-Tunnel
X-Correlation-ID
X-Ua
X-FB-TRIP-ID
X-Cdn-Forward
X-Tumblr-Pixel-3
Ohc-File-Size
X-Unique-ID
X-V
OT-Force-Account-Verify
AR-SID
X-Nc
X-GRACE
X-Webstats-RespID
X-Webkit-Csp
X-B3-Traceid
X-OVcl
X-Origin-CC
X-Guploader-Uploadid
X-OVcl-Cache
Decoy-Debug-Status
X-From
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
Nel
Decoy-Debug-Key
X-Origin-TTL
Decoy-Debug-TTL
X-Time
X-Via-CDN
X-Node-Id
X-We-Are-Hiring
Xc-Version
X-Wikidot-Backend
GMS-Ver
X-Wikidot-Static-Cache
Fastly-SIE
Ec-Rule-Version
Arc-Country
BehaviorPad-Version
Cache-Prefix
X-VG-WebServer
X-Rojux
X-Vgn-Hpd-Reason
Fly-Request-Id
Fly-Cache
Fastly-SWR
X-Rocket-Nginx-Bypass
Mn-Server-Ip
Viewtype
X-Developer
X-Destination
X-Distil-CS
X-DPWN-IS-SECURE
X-External-Request-Id
X-Date
X-Connection-Hash
X-Twitter-Response-Tags
X-Cache-Id
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-TT-LOGID
X-Fetched-On
X-Generated-In
X-Li-Fabric
X-Irp-Debug
X-Li-Pop
X-LI-Proto
X-LI-UUID
X-Transaction
X-Info
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Trv-Group
X-IN-APIGATEWAY
X-IN-WAF
X-Cache-Host
X-Cache-Grace
SD-X-WS
Rendered-Blocks
SID
X-Response-By
X-NU-AKA-ACS-Version
Powered-By
X-User
X-Rewrite-Enabled
Meta-Geo-Continent
Mobile-Detection-Method
Node
On-Server
VivaBuild
Www
X-Backend-State
X-B-Cookie
X-BB-ID
X-Cache-Backend
X-Cache-FS-Status
X-ARC
X-Application
X-Accel-Expires-Debug
X-Aed
X-Amz-Meta-Cache-Control
X-UE-Client-Country
MD5-Digest
Country-Code
X-Rebelmouse-Surrogate-Control
X-Region-Sid
X-SRCache-Key
X-ServiceProvider
X-Rebelmouse-Cache-Control
X-Server-Group
X-S-Maxage
X-PAYTM-SRV-ID
X-S-Cookie
X-PHP-Host
X-Reboot
X-ScT
X-Request-UUID
X-Server-By
X-ElasticPress-Search
X-Origin-Expires
X-Origin-Date
X-Varnish-Beresp-Ttl
Hostname
X-TIME
X-Parent-Response-Time
X-A-Dcw
X-A-Dgt
X-Alternate-Cache-Key
X-A-Wwc
X-Actual-URL
X-Instart-Isnd
X-Sorting-Hat-PodId
X-Epic-Correlation-Id
Server-Host
X-Secret
X-LAGOON
Request-Time
Proxy-Connection
X-FireWall-Port
SS
Thinkindot-CacheControl
Who
X-A
X-A-Ccd
X-RateLimit-Remaining-Second
True-Client-Country-4JS
Thinkindot-CacheControl-Type
Thinkindot-Control
X-A-Dam
X-SN
X-CUA
X-D
X-Proxy-Cache-Status
X-Crawler
X-Core-Mission
X-Shopify-Stage
X-Proxy-Upstream
X-Debug-Cookies
X-Debug-Log
X-Hnp-Log
X-Distributor
X-Dispatcher-Server
X-Matched-Rule
X-Policy
X-Platform
X-Clientip
X-CGP
X-Stale
X-Bip
X-Block-Status
X-R9-Blue-Green-Version
Platform
X-SIPLIST1
X-Auto-Login
X-C
X-Returned-From-BeforeDispatch
X-ShardId
X-ShopId
X-Eu-Site
X-Cache-Info
X-Cache-Expires
X-Sf
X-RateLimit-Limit-Second
X-Hash
X-Gannett-Site-Version
Ha-Gx-Prefs
Ajk
X-Svr
X-Nginx-Cache-Key
HA-Ipaddr
Adler-Geo
X-Generated-On
X-G
IsBot
X-Passed-To-BeforeDispatch
X-Variation
X-Gen-Mode
X-Sorting-Hat-ShopId
Content-Disposition
X-Passed-To-DLL
CDCHOST
X-Passed-To
Backend
Countrycode
X-Passed-To-PostProcessResponse
X-Thanos
X-Request-URI
Fastly-SSL
Fastly-Soc-X-Request-Id
Fastly-Backend-Name
X-Logtrace-Id
Is-Eu
X-GeoIP-Country-Code
X-Returned-From-DLL
X-Returned-From-PostProcessResponse
NGX
X-Thinkindot-L3
X-Returned-From
X-NX-Host
Origin
X-Var-Ttl
Odigeo-Trace-Id
X-Level-Front-Cache
X-Owner
X-Server-IP
X-SERVER
Magicmarker
Memcached
X-Swa-Ws
Warning
X-HS-Cache-Config
Apple-News-Services-Request-Url
X-No-Session
X-Cdn-Srv
X-Cache-URL
X-Debug-Cache-Fetch
Apple-News-Services-Parsed-Url
X-Amz-Meta-Surrogate-Control
X-Qloud-Router
X-Debug-Cache-Store
X-Debug-Cache-Expiry
X-Core-Value
Pramga
X-Developers
AKAMAI
X-Croise-Owner
Apple-News-Services-Handled
X-Device-Os
Apple-News-Services-Host
X-Backend-Host
Server-Surrogate-Control
Server-Int
X-Micro-Cache
X-Fastly-Cache
Lfy
X-Key
Server-Cache-Control
X-Up
Pagetype
X-MSEdge-Flight
Release
X-MSEdge-Features
RNT-Time
RNT-Machine
Cache-Cookie-Set-From
Web-Mar-Node
X-Cache-Bucket
X-Cache-ASPX
X-Cache-Debug
Cache-Cookie-Set-Lfrom
X-Location
X-TrackingId
X-Backend-Url
X-Varnish-Action
Heartbleed
Cache-Cookie-Set-Idcheck
X-Varnish-Authentication
X-Fstrz
X-F5-Cache
IBM-Web2-Location
X-Sedo-Request-Id
Server-ID
GW-Server
X-Varnish-Url
X-Dc
HTTPS
X-Page-Type
Kp-EeAlive
X-Sucuri-Cache
X-UnsetCookies
X-Cache-Miss-From
Resin-Trace
X-Server-Time
X-Edge-Server
MIME-Version
Cdn-Request-Time
X-Servername
X-Pc-Date
X-Pc-Host
X-Pc-Subdomain
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
X-Pjax-Url
X-Oss-Storage-Class
Cdn-Host
X-Oss-Server-Time
X-Be
X-CDN-Forward
REQUESTUUID
X-Newrelic-App-Data
X-NC
X-B3-SpanId
X-Server-Cache
X-IN-SSL-APIGATEWAY
X-Upstream-HT
X-Upstream-CT
X-Refresh
X-FPC
X-Mobile-URL
X-Via-NSCOPI
X-Ua-Device
X-Generation-Time
X-URL
X-Servedbyhost
X-Load-Cache
X-From-Cache
HostName
ProcessTime
X-Amzn-Remapped-Connection
X-NodeID
X-Amzn-Remapped-Date
X-Died
X-VServer
X-Req
Cross-Origin-Window-Policy
RequestId
PICS-Label
FastCGI-Cache
Cteonnt-Length
Fastcgi-X-Cache
X-Skip-Cache
Version
X-CSRF-TOKEN
Uber-Trace-Id
Cdn
X-GZip
CF-IPCountry
Time
PFcat
X-HS-Combine-CSS
Processtime
Memory
X-Webkit-CSP
Ohc-Cache-HIT
X-RCS-CacheZone
Mime-Version
X-CLOUD-TRACE-CONTEXT
X-Dynatrace-Js-Agent
X-HTML-Minification-Powered-By
X-VC-Cache
X-Shard
X-Wa
X-Edge-Cache-Key
X-Ratelimit-Remaining
X-Edge-Cache
CDN
X-DC
Esi-Enabled
X-Cms-Context
X-Lb-Id
X-Atg-Version
X-Layer
X-Cache-CFC
X-Store
XServer
X-UCC
X-Gateway-Skip-Cache
X-Gateway-Cache-Status
X-Gateway-Cache-Key
N-Cache
X-Pf-Uncompressing
MI-Cache
MI-Cache-Age
X-MI-In-Market
MI-API
X-Aicache-OS
X-Geo
X-Varnish-Beresp-TTL
X-Ratelimit-Limit
Cf-Ipcountry
HA-Georegion
HA-Host
HA-Servedtime
HA-Urlpath
HA-Geolon
HA-Geolat
X-Newrelic-Synthetics
HA-Cloudapp
HA-Geocity
X-IPS-LoggedIn
HA-Geocountry
X-RequestId
X-LB-ID
X-WR-MODIFICATION
X-Hyper-Cache
X-Tb-Optimization-Total-Bytes-Saved
X-Processor
X-Real-Ip
X-PF-Uncompressing
X-Fastly-Country-Code
X-WA
Backend-Name
X-BBXSRF
X-Hp-Webp
Amp-Access-Control-Allow-Source-Origin
URI
Accept-Ch-Lifetime
T-Server
X-Nananana
X-CMS-Context
X-SRV
X-Instart-Info
X-Oracle-Dms-Ecid
X-VCT
X-B3-Spanid
Pics-Label
X-APP
X-Geo-Header
X-Phone
X-Amzn-Remapped-Content-Length
Host-ID
X-GeoIP-City
X-MServer
X-COUNTRY
X-WebServer
X-Mrs-Cache
X-Mrs-Age
X-Unique-Id-Primal
X-Mrs-Cache-Hits
X-ID
X-Mshield-Cache-Status
X-Datadome
DataCenter
X-CSRF-Token
X-FORWARDED-FOR
UCS
X-Worker
GeoIP-Country-Code
X-Unique-Id
X-Release
Ohc-Response-Time
X-Request-Start
X-Server-W
GeoIP-Latitude
X-GZIP
X-VHOST
X-HS-Status
X-ServedByHost
Request-Country
A
Request-EU
X-SERVER-NAME
X-CACHE-AGE
FSS-Proxy
Pragrma
WZWS-RAY
FSS-Cache
X-NGINX-Cache
X-LiteSpeed-Cache-Control
X-Optimization
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-GoCache-CacheStatus
X-Cache-HT
Serverid
X-Requestid
X-Org
X-Fpc
X-Via-SSL
X-Via-Edge
X-Check-Cacheable
WP-Super-Cache
X-Fastly-Cache-Hits
X-Port
X-UPSTREAM-Address
Dnion-Transfer-Encoding
X-BE
X-Vcache
Geoip-Latitude
Rt-Proxy-Cache
X-ND-Cache
X-Served-From
X-Backend-TTL
X-ServerName
GeoIp-Country-Code
X-Gen-Id
X-Dw-Trace-Id
X-Fastly-Backend-Reqs
X-PAGE-TYPE
X-Varnish-URL
X-Git-Hash
Cneonction
X-Csrf-Token
Requestid
X-PJAX-URL
Server-Id
X-HostName
RequestUuid
X-Html-Edge-Cache
Cache-Provider
Lb
X-NWS-UUID-VERIFY
X-CS
X-Request-Url
X-Gdpr
X-LiteSpeed-Tag
V-Age
Inserted-Into-Cache-At
X-RAMCache
X-Cdn-Origin
X-Sn-Servicetimems