Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
CF-RAY
ETag
Link
Expect-CT
Via
X-XSS-Protection
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Xss-Protection
X-Varnish
X-Request-Id
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Adblock-Key
X-Check
Alt-Svc
X-Cacheable
X-Generator
Content-Security-Policy-Report-Only
X-AspNetMvc-Version
X-Cache-Status
X-DNS-Prefetch-Control
X-Permitted-Cross-Domain-Policies
X-Iinfo
X-Template
X-Language
Status
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Buckets
X-Content-Security-Policy
Content-Encoding
X-Kinja-Server-Push
Xkey
X-Turbo-Charged-By
X-CDN
Upgrade
X-Type
Keep-Alive
Access-Control-Expose-Headers
WPE-Backend
X-Pass-Why
X-AH-Environment
X-Backend
Access-Control-Max-Age
X-Age
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Server
X-Proxy-Cache
X-Request-ID
X-Via
Grace
X-Pingback
X-Nginx-Cache-Status
X-Server-Powered-By
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Hacker
X-Varnish-Cache
X-UA-Device
X-Page-Speed
EagleId
Request-Context
X-LiteSpeed-Cache
X-Envoy-Upstream-Service-Time
Cf-Railgun
X-Ua-Compatible
X-CST
P3p
X-Swift-SaveTime
X-Swift-CacheTime
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Ali-Swift-Global-Savetime
X-Server-Id
X-Device
X-Amz-Version-Id
X-WebKit-CSP
Server-Timing
X-Ac
Allow
X-Node
X-OneAgent-JS-Injection
Feature-Policy
X-Response-Time
X-Rq
X-Cnection
X-Iejgwucgyu
Content-Location
X-Backend-Server
X-Cache-Lookup
Report-To
EagleEye-TraceId
Surrogate-Control
X-Host
X-Readtime
X-Application-Context
Request-Id
X-ORACLE-DMS-ECID
X-Rack-Cache
X-Url
X-Origin-Cache
X-Clacks-Overhead
NEL
X-FTR-Request-ID
X-Country
Rating
X-Country-Code
X-Cloud-Trace-Context
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-DataDome
X-Cdn
X-Ruxit-JS-Agent
X-Px
X-Instart-Request-ID
X-Mod-Pagespeed
Charset
X-Vhost
X-VARITI-CCR
X-MS-InvokeApp
Pinterest-Generated-By
Accept-CH
X-Goog-Hash
Edge-Control
X-GitHub-Request-Id
X-Upstream-Env
Verso
X-TtlSet
X-PC
X-Vname
PB-PID
X-Server-Name
X-Mobile-Rewrite
PB-RID
Arc-Version
X-Dns-Prefetch-Control
X-Version
X-DynaTrace
X-Origin-Upstream-Status
X-Powered-By-Plesk
X-D2id
X-ESI
X-B3-TraceId
X-Cdn-Fetch
X-TTL
X-Exp-Id
X-GoogleNews-Bot
X-Kinja
X-Kinja-Build
X-Kinja-Revision
X-Exp-Variant
X-Kinja-Server
X-Use-Magma
X-Cached
X-Dispatcher
SPRequestGuid
X-ORACLE-DMS-RID
X-Recruiting
X-SharePointHealthScore
X-Varnish-TTL
MS-Author-Via
X-Abt-Application-Version
X-Powered-CMS
Accept-CH-Lifetime
X-Navigation-Version
Content-MD5
RTSS
AR-PoweredBy
AR-CACHE
AR-ATIME
X-Shield-Request-Id
X-T
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Trace
Public-Key-Pins
X-Forwarded-Proto
X-DynaTrace-JS-Agent
X-Client-IP
X-Amz-Rid
Arr-Disable-Session-Affinity
X-HW
X-Fastly-Request-ID
X-Wix-Server-Artifact-Id
X-Accel-Buffering
SPIisLatency
SPRequestDuration
Realpath
X-DIS-Request-ID
X-Oracle-Dms-Rid
Service-Worker-Allowed
AR-Request-ID
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Amz-Meta-S3cmd-Attrs
Paypal-Debug-Id
Front-End-Https
X-Upstream
X-FTR-Backend-Server
X-FTR-Backend
X-Ser
X-FTR-Balancer
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Realm
X-FTR-DC
X-FTR-Expires
X-B
Pinterest-Version
X-Pinterest-Rid
X-Via-JSL
X-Id
X-F-Cache
X-XRDS-Location
X-Ttl
X-Vcap-Request-Id
X-Dw-Request-Base-Id
Ar-Sid
X-Debug
X-Server-ID
X-Goog-Storage-Class
X-Varnish-Age
X-Acc-Meta-Resource-Type
X-Kinsta-Cache
X-MSEdge-Ref
X-N
Nginx-Cache
X-Hits
X-DataStream-Cache-Status
X-NF-Request-ID
X-FTR-Cache-Host
S
X-Logged-In
X-Akam-SW-Version
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Mrf-Section-Lastmod
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-Mrf-Item-Lastmod
X-NewRelic-App-Data
X-Grace
Tracecode
X-FastCGI-Cache
X-Forwarded-For
Alternate-Protocol
X-Frontend
X-HS-Hub-Id
X-PressLabs-Stats
X-HS-Content-Id
X-User-Agent
X-Amzn-Trace-Id
X-CACHE-GROUP
TCN
AMP-Access-Control-Allow-Source-Origin
X-Content-Options
Server-Name
X-Content-Digest
Powered-By-ChinaCache
X-Middleton-Display
Display
Refresh
X-Sol
X-Content-Type
Access-Control-Request-Method
X-Pad
X-Cache-Key
Backend-Timing
MicrosoftSharePointTeamServices
X-Analytics
X-Middleton-Response
X-Zen-Fury
Accept-Charset
FilterID
DynaTrace
Response
X-Activity-Id
X-AppVersion
X-Debug-Info
X-Rid
X-LB-Cache
X-CF-Powered-By
X-Az
X-IPLB-Instance
X-Page-Id
Host
X-VCache
Fastcgi-Cache
ServerID
X-Hostname
MS-CV
X-Cache-Hit
Cache-Status
TP-Cache
X-GUploader-UploadID
TP-L2-Cache
X-Magnolia-Registration
X-RateLimit-Remaining
X-Srv
X-Seen-By
X-Content-Powered-By
X-Mobile
X-Revision
X-Cached-By
X-WA-Info
X-Fastcgi-Cache
X-ATG-Version
Host-Header
X-Varnish-Backend
X-Request-Received
X-Request-Processing-Time
X-Whom
Server-Info
Surrogate-Key
X-SS-Set-Cookie
X-Instance
X-B3-Sampled
X-Cache-Action
X-Platform-Server
X-Request-Guid
X-Tumblr-User
X-Tumblr-Pixel-0
DC
X-Tumblr-Pixel
Source
VIX-Pulpo-Upstream-Status
X-Drupal-Cache-Tags
X-Cluster
VIX-Pulpo-Node
X-Handled-By
X-PHP-Backend
X-Content-Security-Policy-Report-Only
X-Signature
Cleartype
ViewerVersion
X-Wix-Request-Id
X-B-Cache
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Real-IP
Fusion-Content-Source
Fusion-Component-Id
X-Akamai-Edgescape
X-Origin-Server
Fusion-Source
Fusion-Content-Id
Fusion-Template-Id
X-TT
X-Framework
X-Cache-Age
X-App-Environment
X-Geo-Country
X-App-Server
X-FW-Type
X-FW-Static
X-FW-Serve
X-FW-Server
X-FW-Hash
Rt-Fastcgi-Cache
X-Generated-By
X-Oneagent-Js-Injection
X-Varnish-Server
X-AOL-HN
X-BCube-Filmed-By
X-Cache-Control
Server-Node
X-XRDS-LOCATION
X-Edge-Location
X-Ruxit-Js-Agent
X-Upstream-Proxy
X-NWS-LOG-UUID
X-Cache-Rule
X-Varnish-Hostname
Retry-After
X-Varnish-Grace
X-Amz-Server-Side-Encryption
Payment
X-TA-CDN-Provider
X-Correlation-Id
Access-Control-Allow-Method
X-Amz-Replication-Status
X-Cache-2
X-Ezoic-Cdn
X-TT-TIMESTAMP
X-Rendered-As
X-Response-Served-From
X-FB-Debug
X-UA-Device-Type
X-Cacheable-TTL
Actual-Object-TTL
X-Tumblr-Pixel-2
X-Varnish-Hits
X-Tumblr-Pixel-1
AsisCache
Eomportal-Instance
ServedBy
GEO-INFO
Content-Script-Type
X-UUID
X-Drupal-Cache-Contexts
X-Jobs
NGB
Content-Style-Type
X-RTag
Ms-Operation-Id
X-TX-ID
Webserver
X-Contextid
X-Region
X-Cache-Config
Healthy
Filters
X-VG-WebCache
Upgrade-Insecure-Requests
HitType
X-Adobe-Loc
X-WebKit-CSP-Report-Only
Viewport
X-Varnish-IP
X-Adobe-Content
X-Cache-TTL
Country
X-Locale
X-SERVER
X-RequestSource
X-Accel-Expires
Cache-Tv-Group
From-Origin
Fastcgi-Useragent
X-Esi
X-Cache-TTL-Remaining
X-FW-Dynamic
Pagespeed
X-Device-Type
X-BACKEND-TTL
X-Cache-Server
X-Content-Age
X-Servedby
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Edge-Cache-Tag
Cache-Tags
X-WPE-Loopback-Upstream-Addr
X-Cache-Remote
X-APP-VERSION
X-Redis-Cache
X-Upgrade-Enabled
X-Source
X-DataStream-MidMile-RTT
X-DataStream-Origin-MEX-Latency
X-Cache-Operation
X-Hit
Cache
X-RateLimit-Limit
X-Storage
X-GeoIP
Datacenter
Fastly-Restarts
X-Mode
NtCoent-Length
Cache-Tag
X-Cache-Var-Map
X-Detected-As
X-Cache-Var
X-Is-Bot
X-Agile-Age
X-Internal-Host
X-Agile-Id
X-Akamai-Request-ID
X-Origin-Response-Time
X-RN-RSRV
X-Pubstack
X-S
Machine
Meta-Geo
X-Time-Microsecs
Served-By
X-Path-Route
X-Loop
X-TNCMS
Load-Balancing
X-Labrador-Cache-Channel
X-Agile
X-Birta-Served
X-Status
X-Birta-Cache-Post
Selected-FE
X-Varnish-Cache-Hits
Vix-Hermes-Req-Id
X-BYPASS-REASON
S-Rt
Origin-Edge-Control
Origin-Cache-Control
X-Grey
X-NCache
X-Varnish-Cacheable
X-ProxyCache-Key
X-Www-Served-By
X-Microcachable
X-Proxy-Build
X-Timing-Wait
X-ServerID
X-Cache-Category-Id
X-Origin-Host
X-Tb
X-Proxy
X-L-Path
X-Environment-Context
X-Edge-IP
X-CDN-Cache
X-ProxyCache-Status
X-FC-Vary-Parameters
X-IP
X-Hosted-By
Cache-Key
X-JoinUs
X-Generated
X-RemovedCookies
X-Rule
X-Viewer-Country
X-Web-Node
Cache-Name
SRV
X-Via-Fastly
Now
Property-Id
X-PERF
Webcakes-App-Version
Webcakes-App-Name
Webcakes-Region
X-Format
X-Cache-Enabled
X-ApacheServer
X-Origin-Hint
TWC-Privacy
TWC-GeoIP-Country
TWC-Device-Class
X-ProcessESI
TWC-GeoIP-LatLong
TWC-Locale-Group
TWC-Connection-Speed
X-VG-TLSProxy
X-CACHE-KEY
X-Hl-Ver
X-Human
X-CCM
X-Backend-Name
Public-Key-Pins-Report-Only
X-Access
X-MP-GENERATED-AT
X-NGENIX-Cache
X-ES-SERVER
Azure-SiteName
X-Section
User-Agent
X-OCL
X-PCL
X-Akamai-Transformed
CACHE
Azure-RegionName
Cache-Hits
DB-Nickname
Fastcgi-X-Cache-Version
Access-Control-Request-Headers
Azure-SlotName
Azure-InstanceId
Azure-Version
We-Hiring
X-Proxied
X-App-Name
X-GEO
X-Debug-Cache
X-Routing-Service
Mail-Subject
X-Xfnlog-Site
X-Site-Version
X-Zipkin-Id
Liferay-Portal
Xserver
X-Node-Name
X-EdgeConnect-Cache-Status
X-Daa-Tunnel
LB
X-App-Version
X-FW-Version
S-Cnection
X-Original-Request
X-Origin
X-Protected-By
X-Pc-Key
X-Sucuri-ID
X-Pc-Hit
X-Pc-Appver
PageSpeed
X-Nginx-Cache
X-Cache-NE
X-Proto
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Ocache
X-VWS-Id
X-Trace-Id
X-UA
X-LJ-Flow-ID
X-AWS-Id
X-Request-Time
Powered
User-Cache-Control
X-Varnish-Ttl
X-Forwarded-Host
X-Endurance-Cache-Level
X-Guploader-Uploadid
Ohc-File-Size
X-Correlation-ID
X-Tumblr-Pixel-3
L5d-Success-Class
X-Cluster-Node
X-Cdn-Forward
X-Ua
Section-Io-Cache
Frame-Options
X-Webstats-RespID
X-Unique-ID
X-V
X-FB-TRIP-ID
X-EIG-Tracking-Id
X-URL
X-Nc
X-Origin-CC
OT-Force-Account-Verify
AR-SID
X-GRACE
X-Webkit-Csp
X-OVcl-Cache
X-Time
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
X-OVcl
Nel
X-Origin-TTL
X-From
X-ElasticPress-Search
Decoy-Debug-TTL
Decoy-Debug-Key
Decoy-Debug-Status
X-Cache-Backend
X-Cdn-Srv
X-Transaction
X-TT-LOGID
X-Rewrite-Enabled
Arc-Country
X-Application
Fly-Request-Id
X-Backend-State
Fly-Cache
X-Cache-FS-Status
X-Trv-Group
X-CF-Lambda-Version
X-BB-ID
X-CF-Lambda-Fn
X-Cache-Info
Viewtype
X-ARC
X-Auto-Login
VivaBuild
GMS-Ver
X-User
X-Rojux
X-Cache-Host
X-Li-Fabric
X-Cache-URL
X-SRCache-Key
X-UE-Client-Country
X-Cache-Id
X-Cache-Grace
X-Twitter-Response-Tags
Www
Meta-Geo-Continent
Memcached
X-Origin-Date
X-Server-By
X-Node-Id
X-NU-AKA-ACS-Version
X-Origin-Expires
X-Fetched-On
Fastly-SIE
X-Wikidot-Static-Cache
Powered-By
MD5-Digest
X-Response-By
X-Region-Sid
Xc-Version
X-ScT
X-Goog-Meta-Goog-Reserved-File-Mtime
Node
On-Server
X-Info
X-IN-APIGATEWAY
X-Request-UUID
Mobile-Detection-Method
X-Varnish-Beresp-Ttl
X-LI-UUID
X-Generated-In
Ec-Rule-Version
X-Rebelmouse-Cache-Control
Country-Code
X-External-Request-Id
X-S-Cookie
SD-X-WS
X-Destination
X-Developer
X-Li-Pop
X-Reboot
X-Date
X-Aed
X-Connection-Hash
X-ServiceProvider
X-LI-Proto
BehaviorPad-Version
Fastly-SWR
X-IN-WAF
X-R9-Blue-Green-Version
X-Rebelmouse-Surrogate-Control
Rendered-Blocks
X-VG-WebServer
X-S-Maxage
X-Wikidot-Backend
X-We-Are-Hiring
X-PAYTM-SRV-ID
X-DPWN-IS-SECURE
X-PHP-Host
Cache-Prefix
X-B-Cookie
X-Server-Group
X-Accel-Expires-Debug
X-Amz-Meta-Cache-Control
X-Parent-Response-Time
IBM-Web2-Location
X-TIME
X-Newrelic-App-Data
X-A
X-A-Ccd
Platform
Request-Time
Proxy-Connection
Server-Host
True-Client-Country-4JS
X-Level-Front-Cache
Thinkindot-Control
Thinkindot-CacheControl-Type
Who
Thinkindot-CacheControl
X-A-Dam
X-Core-Mission
X-Epic-Correlation-Id
X-Eu-Site
X-Fastly-Cache
X-Returned-From-BeforeDispatch
X-Distributor
X-Distil-CS
X-Debug-Cookies
X-Debug-Log
X-Dispatcher-Server
X-Returned-From
X-LAGOON
X-Hash
X-Hnp-Log
X-Request-URI
X-GeoIP-Country-Code
X-Generated-On
X-G
X-Gannett-Site-Version
X-Gen-Mode
X-D
X-CUA
X-Backend-Url
X-Bip
X-Block-Status
X-Backend-Host
X-Alternate-Cache-Key
X-A-Dgt
X-A-Wwc
X-Actual-URL
X-C
X-Cache-Bucket
X-Clientip
X-Returned-From-DLL
X-Crawler
X-Returned-From-PostProcessResponse
X-CGP
X-Rocket-Nginx-Bypass
X-Cache-Debug
X-Cache-Expires
X-A-Dcw
Adler-Geo
CDCHOST
Content-Disposition
X-Proxy-Upstream
X-Vgn-Hpd-Reason
X-Passed-To-PostProcessResponse
X-Swa-Ws
Countrycode
X-Svr
X-Sorting-Hat-ShopId
X-Passed-To-DLL
Fastly-SSL
Fastly-Soc-X-Request-Id
X-Logtrace-Id
Fastly-Backend-Name
Backend
X-RateLimit-Limit-Second
X-Var-Ttl
Origin
X-Variation
X-Varnish-Action
X-Matched-Rule
X-Irp-Debug
X-Proxy-Cache-Status
X-Location
X-Via-CDN
Ajk
Mn-Server-Ip
X-Thanos
X-Thinkindot-L3
X-Sorting-Hat-PodId
X-Stale
SID
Magicmarker
X-Server-IP
HA-Ipaddr
X-Passed-To-BeforeDispatch
Lfy
IsBot
Is-Eu
X-Micro-Cache
X-NX-Host
X-Nginx-Cache-Key
X-Sf
X-Secret
X-ShardId
X-ShopId
X-SIPLIST1
X-Shopify-Stage
X-Passed-To
Ha-Gx-Prefs
X-RateLimit-Remaining-Second
X-HS-Cache-Config
Warning
X-Instart-Isnd
SS
X-Core-Value
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Croise-Owner
X-Debug-Cache-Expiry
X-MSEdge-Flight
X-SN
X-Qloud-Router
X-No-Session
X-F5-Cache
X-Fstrz
X-Platform
X-Device-Os
X-FireWall-Port
X-Sucuri-Cache
X-Owner
X-MSEdge-Features
X-Developers
X-Policy
X-UnsetCookies
Web-Mar-Node
GW-Server
Server-Surrogate-Control
X-Varnish-Authentication
Cache-Cookie-Set-Idcheck
Apple-News-Services-Request-Url
X-Amz-Meta-Surrogate-Control
Cache-Cookie-Set-From
Server-Int
Server-Cache-Control
Release
Pramga
NGX
Heartbleed
Resin-Trace
RNT-Time
RNT-Machine
Apple-News-Services-Parsed-Url
Cache-Cookie-Set-Lfrom
X-Cache-ASPX
X-Up
AKAMAI
X-TrackingId
Apple-News-Services-Handled
Apple-News-Services-Host
X-Dc
X-Pc-Host
X-Pc-Subdomain
X-Pc-Date
Hostname
X-Upstream-HT
X-Upstream-CT
Kp-EeAlive
X-Server-Time
X-Key
REQUESTUUID
Pagetype
Server-ID
X-Varnish-Url
X-Page-Type
Odigeo-Trace-Id
X-Be
X-IN-SSL-APIGATEWAY
X-Cache-Miss-From
X-Sedo-Request-Id
X-Servername
X-B3-Traceid
X-Server-Cache
X-CDN-Forward
X-Refresh
X-Generation-Time
X-Pjax-Url
HTTPS
MIME-Version
X-NC
X-Via-NSCOPI
X-Oss-Request-Id
X-Oss-Object-Type
X-Oss-Server-Time
X-Edge-Server
X-Oss-Storage-Class
Cdn-Host
Cdn-Request-Time
X-Oss-Hash-Crc64ecma
X-Died
Fastcgi-X-Cache
X-B3-SpanId
HostName
X-From-Cache
RequestId
X-FPC
X-Servedbyhost
Version
X-Edge-Cache
X-Edge-Cache-Key
ProcessTime
X-Req
PFcat
X-Mobile-URL
PICS-Label
Cteonnt-Length
FastCGI-Cache
Cross-Origin-Window-Policy
Cdn
Time
X-CSRF-TOKEN
X-NodeID
X-Amzn-Remapped-Date
X-VServer
X-Amzn-Remapped-Connection
Mime-Version
X-GZip
CF-IPCountry
X-Cache-CFC
X-COUNTRY
X-HS-Combine-CSS
Esi-Enabled
Processtime
X-Store
X-Webkit-CSP
X-CLOUD-TRACE-CONTEXT
X-Load-Cache
MI-Cache-Age
MI-API
Memory
MI-Cache
X-Wa
X-Skip-Cache
X-Layer
X-RCS-CacheZone
X-MI-In-Market
X-Dynatrace-Js-Agent
X-Ratelimit-Remaining
X-DC
CDN
X-Hyper-Cache
HA-Georegion
HA-Host
HA-Cloudapp
HA-Geolon
HA-Geocity
HA-Geolat
HA-Geocountry
HA-Servedtime
Uber-Trace-Id
X-Atg-Version
X-RequestId
X-IPS-LoggedIn
HA-Urlpath
XServer
Ohc-Cache-HIT
X-Lb-Id
X-Pf-Uncompressing
X-Varnish-Beresp-TTL
X-Aicache-OS
X-Ratelimit-Limit
X-HTML-Minification-Powered-By
X-Geo
Cf-Ipcountry
X-VC-Cache
X-Real-Ip
Backend-Name
X-Newrelic-Synthetics
X-Cms-Context
X-Gateway-Cache-Key
X-CMS-Context
X-Fastly-Country-Code
N-Cache
X-Gateway-Cache-Status
X-Gateway-Skip-Cache
X-UCC
X-B3-Spanid
X-Tb-Optimization-Total-Bytes-Saved
X-Shard
X-Instart-Info
X-PF-Uncompressing
X-WA
X-WR-MODIFICATION
X-FORWARDED-FOR
Amp-Access-Control-Allow-Source-Origin
X-Mrs-Age
X-Mrs-Cache-Hits
X-Unique-Id-Primal
X-Mshield-Cache-Status
X-Mrs-Cache
X-Nananana
X-LB-ID
T-Server
Accept-Ch-Lifetime
X-Phone
Ohc-Response-Time
X-Processor
X-WebServer
X-Hp-Webp
X-Request-Start
GeoIP-Country-Code
URI
X-Oracle-Dms-Ecid
X-Release
X-BBXSRF
Pics-Label
X-Server-W
X-MServer
GeoIP-Latitude
X-Datadome
X-Worker
X-APP
X-SRV
X-CSRF-Token
X-Unique-Id
DataCenter
X-VCT
X-Amzn-Remapped-Content-Length
X-GeoIP-City
A
X-VHOST
X-ServedByHost
Host-ID
X-LiteSpeed-Cache-Control
X-Geo-Header
X-SERVER-NAME
X-ND-Cache
X-HS-Status
X-Served-From
Rt-Proxy-Cache
X-Check-Cacheable
UCS
X-GoCache-CacheStatus
X-CACHE-AGE
X-GZIP
X-Optimization
X-UPSTREAM-Address
X-Cache-HT
Request-Country
Request-EU
X-Requestid
X-Fastly-Cache-Hits
X-NGINX-Cache
X-PJAX-URL
Geoip-Latitude
Dnion-Transfer-Encoding
FSS-Proxy
Pragrma
FSS-Cache
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-BE
X-Fpc
X-ID
X-Vcache
X-Backend-TTL
V-Age
X-PAGE-TYPE
X-Cdn-Origin
X-Varnish-URL
X-Port
X-Sn-Servicetimems
X-Csrf-Token
Cneonction
X-Org
X-Git-Hash
X-ServerName
Requestid
GeoIp-Country-Code
X-Fastly-Backend-Reqs
WZWS-RAY
X-Dw-Trace-Id
WP-Super-Cache
Serverid
Cache-Provider
X-HostName
X-SVT-ORM-RULES
Proxy-Firewall
X-Via-Edge
X-Via-SSL
Server-Id
X-SVT-ORM-VERSION
RequestUuid
X-Gen-Id
X-Html-Edge-Cache
X-NWS-UUID-VERIFY
Inserted-Into-Cache-At
Xxline
178proxuri
188prxHost
189phosttRef
DSUID
Get-Access-Time
X-P-T
X-Fe
Is-Session-Tracking
219prxHost
225prxHost
X-Request-Url
X-CS
X-LiteSpeed-Tag
409pxxline
355prline
286prxHost
352pxline
X-RAMCache