Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
CF-RAY
ETag
Link
Expect-CT
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Xss-Protection
X-Varnish
X-Request-Id
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Adblock-Key
X-Check
Alt-Svc
X-Cacheable
X-Generator
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-Cache-Status
X-AspNetMvc-Version
X-Permitted-Cross-Domain-Policies
X-Template
X-Iinfo
X-Language
Status
Timing-Allow-Origin
X-Buckets
X-FRAME-OPTIONS
X-Content-Security-Policy
Content-Encoding
X-Kinja-Server-Push
Xkey
X-CDN
X-Turbo-Charged-By
Upgrade
X-Type
Keep-Alive
Access-Control-Expose-Headers
WPE-Backend
X-Pass-Why
X-AH-Environment
X-Backend
Access-Control-Max-Age
X-Age
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Server
X-Proxy-Cache
X-Via
X-Request-ID
Grace
X-Pingback
X-Nginx-Cache-Status
X-Server-Powered-By
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Hacker
X-Varnish-Cache
X-UA-Device
X-Page-Speed
EagleId
Request-Context
X-LiteSpeed-Cache
X-Envoy-Upstream-Service-Time
Cf-Railgun
X-CST
X-Ua-Compatible
X-Swift-CacheTime
X-Swift-SaveTime
X-Server-Id
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Ali-Swift-Global-Savetime
X-Device
X-WebKit-CSP
X-Amz-Version-Id
Server-Timing
X-Ac
X-Node
Allow
X-OneAgent-JS-Injection
X-Response-Time
Feature-Policy
X-Rq
X-Cnection
X-Iejgwucgyu
Content-Location
X-Cache-Lookup
X-Backend-Server
Report-To
EagleEye-TraceId
Surrogate-Control
X-Readtime
X-Host
X-Application-Context
Request-Id
X-ORACLE-DMS-ECID
P3p
X-Rack-Cache
X-Url
X-Origin-Cache
X-Clacks-Overhead
NEL
X-Country
X-FTR-Request-ID
Rating
X-Country-Code
X-Cloud-Trace-Context
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-DataDome
X-Ruxit-JS-Agent
X-Cdn
X-Px
X-Instart-Request-ID
X-Mod-Pagespeed
Charset
X-Vhost
X-MS-InvokeApp
X-VARITI-CCR
Accept-CH
Edge-Control
X-Goog-Hash
Verso
X-GitHub-Request-Id
X-TtlSet
X-PC
X-Vname
PB-PID
Arc-Version
X-Mobile-Rewrite
PB-RID
X-ESI
X-Server-Name
X-Upstream-Env
X-Version
X-DynaTrace
Pinterest-Generated-By
X-TTL
X-B3-TraceId
X-Powered-By-Plesk
X-D2id
X-Origin-Upstream-Status
X-Kinja-Revision
X-Kinja
X-Use-Magma
X-GoogleNews-Bot
X-Kinja-Server
X-Cached
X-Kinja-Build
X-Exp-Variant
X-Exp-Id
X-Cdn-Fetch
X-ORACLE-DMS-RID
X-Dispatcher
SPRequestGuid
X-Varnish-TTL
X-Recruiting
X-SharePointHealthScore
X-Abt-Application-Version
MS-Author-Via
X-Powered-CMS
Accept-CH-Lifetime
RTSS
X-Navigation-Version
X-T
X-Shield-Request-Id
Content-MD5
AR-PoweredBy
AR-CACHE
AR-ATIME
Public-Key-Pins
X-DynaTrace-JS-Agent
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Trace
X-Forwarded-Proto
X-Client-IP
Arr-Disable-Session-Affinity
X-Fastly-Request-ID
X-Amz-Rid
X-HW
X-Accel-Buffering
X-Wix-Server-Artifact-Id
SPIisLatency
SPRequestDuration
Realpath
X-DIS-Request-ID
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Metageneration
Service-Worker-Allowed
X-Goog-Stored-Content-Encoding
X-Amz-Meta-S3cmd-Attrs
X-Oracle-Dms-Rid
X-Upstream
X-F-Cache
Paypal-Debug-Id
AR-Request-ID
X-B
Front-End-Https
X-Ser
X-Pinterest-Rid
Pinterest-Version
X-FTR-Backend-Server
X-FTR-DC
X-FTR-Cache-Status
X-Country-Code-Real
X-FTR-Realm
X-FTR-Backend
X-Via-JSL
X-FTR-Balancer
X-FTR-Expires
X-Id
X-XRDS-Location
X-Dw-Request-Base-Id
Ar-Sid
X-Vcap-Request-Id
X-Dns-Prefetch-Control
X-Varnish-Age
X-Debug
X-Goog-Storage-Class
X-Acc-Meta-Resource-Type
X-MSEdge-Ref
X-Kinsta-Cache
X-Ttl
X-N
Nginx-Cache
X-Hits
X-NF-Request-ID
X-FTR-Cache-Host
S
X-NewRelic-App-Data
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-DataStream-Cache-Status
X-Logged-In
X-Akam-SW-Version
MRF-Tech
Mrf-Cache-Status
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
X-Mrf-Item-Lastmod
X-Forwarded-For
Tracecode
Alternate-Protocol
X-Frontend
X-HS-Content-Id
X-HS-Hub-Id
X-PressLabs-Stats
X-User-Agent
X-Grace
X-Amzn-Trace-Id
X-Server-ID
AMP-Access-Control-Allow-Source-Origin
X-Content-Digest
X-CACHE-GROUP
X-Content-Options
Server-Name
TCN
X-FastCGI-Cache
Refresh
Powered-By-ChinaCache
X-Pad
DynaTrace
Access-Control-Request-Method
Display
X-Middleton-Display
X-Content-Type
X-Sol
Backend-Timing
X-Analytics
MicrosoftSharePointTeamServices
Fastcgi-Cache
Accept-Charset
X-LB-Cache
X-Activity-Id
X-Zen-Fury
X-Az
X-AppVersion
X-IPLB-Instance
X-Debug-Info
FilterID
X-Rid
Host
X-Page-Id
X-CF-Powered-By
X-Cache-Key
X-Middleton-Response
Response
MS-CV
ServerID
X-Fastcgi-Cache
X-Cache-Hit
X-VCache
X-Magnolia-Registration
TP-L2-Cache
Cache-Status
X-RateLimit-Remaining
X-Hostname
TP-Cache
X-Srv
X-Seen-By
X-Content-Powered-By
X-ATG-Version
X-Mobile
X-Revision
X-WA-Info
X-Cached-By
Surrogate-Key
X-Varnish-Backend
X-Request-Received
X-B3-Sampled
X-GUploader-UploadID
X-Request-Processing-Time
Host-Header
X-SS-Set-Cookie
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Whom
Server-Info
X-Cluster
X-B-Cache
X-Signature
X-Instance
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-0
X-Drupal-Cache-Tags
X-Platform-Server
X-Content-Security-Policy-Report-Only
X-Cache-Action
X-Handled-By
ViewerVersion
X-Wix-Request-Id
Source
Cleartype
X-Framework
X-Request-Guid
X-Origin-Server
X-TT
DC
X-PHP-Backend
X-Cache-Age
X-Akamai-Edgescape
X-TA-CDN-Provider
X-App-Environment
Rt-Fastcgi-Cache
X-Amzn-RequestId
X-Amz-Apigw-Id
Fusion-Template-Id
Fusion-Content-Source
Fusion-Source
Fusion-Content-Id
Fusion-Component-Id
X-Real-IP
X-BCube-Filmed-By
X-Generated-By
X-Geo-Country
X-App-Server
X-Cache-Control
X-FW-Server
X-FW-Serve
X-FW-Type
X-FW-Hash
X-FW-Static
X-AOL-HN
X-Varnish-Server
X-Edge-Location
Server-Node
X-Oneagent-Js-Injection
X-Cache-Rule
X-NWS-LOG-UUID
X-XRDS-LOCATION
X-Varnish-Hostname
X-Ruxit-Js-Agent
Retry-After
X-Correlation-Id
X-Amz-Server-Side-Encryption
Payment
X-Cache-2
X-Varnish-Grace
Eomportal-Instance
X-FB-Debug
X-Amz-Replication-Status
Access-Control-Allow-Method
X-Response-Served-From
X-TT-TIMESTAMP
Webserver
AsisCache
Actual-Object-TTL
X-Tumblr-Pixel-1
X-Tumblr-Pixel-2
ServedBy
X-Cacheable-TTL
X-Cache-Config
Healthy
X-Upstream-Proxy
Filters
GEO-INFO
X-RTag
Ms-Operation-Id
X-WebKit-CSP-Report-Only
NGB
X-Varnish-Hits
X-Drupal-Cache-Contexts
X-Jobs
X-TX-ID
Content-Script-Type
Content-Style-Type
X-Region
X-UUID
Viewport
X-Adobe-Content
X-Contextid
X-UA-Device-Type
Upgrade-Insecure-Requests
X-VG-WebCache
X-Adobe-Loc
X-RequestSource
X-Ezoic-Cdn
From-Origin
X-Rendered-As
Cache-Tv-Group
X-Locale
Country
HitType
X-Varnish-IP
X-Accel-Expires
X-Device-Type
X-Cache-TTL
Fastcgi-Useragent
X-Cache-TTL-Remaining
X-BACKEND-TTL
X-FW-Dynamic
X-Cache-Server
X-Servedby
X-WPE-Loopback-Upstream-Addr
Edge-Cache-Tag
Pagespeed
X-Content-Age
X-Cache-Remote
Cache-Tags
Cache
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Upgrade-Enabled
X-Cache-Operation
X-Redis-Cache
X-APP-VERSION
X-RateLimit-Limit
X-Source
X-Hit
Datacenter
Fastly-Restarts
X-Storage
X-CACHE-KEY
X-Esi
X-DataStream-Origin-MEX-Latency
X-DataStream-MidMile-RTT
X-GeoIP
X-Mode
Served-By
Cache-Tag
X-Pubstack
Load-Balancing
X-Tb
X-RN-RSRV
X-Path-Route
X-Hl-Ver
X-Time-Microsecs
X-Internal-Host
X-NCache
Meta-Geo
X-Backend-Name
X-Akamai-Request-ID
SRV
Vix-Hermes-Req-Id
Machine
X-Cache-Var
X-NGENIX-Cache
X-Is-Bot
X-JoinUs
X-Cache-Var-Map
X-Origin-Response-Time
X-Detected-As
X-CDN-Cache
X-Agile
X-Agile-Age
X-Www-Served-By
X-Varnish-Cacheable
X-Timing-Wait
X-Agile-Id
X-L-Path
X-Varnish-Cache-Hits
X-Origin-Host
X-TNCMS
X-Loop
X-Labrador-Cache-Channel
X-Hosted-By
X-Proxy
X-Birta-Cache-Post
X-Birta-Served
Selected-FE
Origin-Edge-Control
Cache-Key
X-Edge-IP
X-Environment-Context
X-ServerID
X-Generated
X-Rule
X-Proxy-Build
X-FC-Vary-Parameters
X-Status
Origin-Cache-Control
X-S
Webcakes-App-Name
TWC-Privacy
Webcakes-App-Version
Webcakes-Region
X-ApacheServer
TWC-Locale-Group
TWC-GeoIP-LatLong
S-Rt
Property-Id
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-Country
X-Cache-Category-Id
X-Cache-Enabled
X-RemovedCookies
X-ProcessESI
X-VG-TLSProxy
X-Via-Fastly
X-Web-Node
X-PERF
X-Origin-Hint
X-Daa-Tunnel
X-Format
X-Grey
X-IP
Now
X-Viewer-Country
X-Guploader-Uploadid
X-MP-GENERATED-AT
Access-Control-Request-Headers
X-Human
X-Section
Public-Key-Pins-Report-Only
X-PCL
X-GEO
X-OCL
NtCoent-Length
X-App-Version
X-Access
Azure-SlotName
Cache-Name
X-Microcachable
Azure-SiteName
Azure-InstanceId
Azure-RegionName
X-CCM
Fastcgi-X-Cache-Version
Azure-Version
X-BYPASS-REASON
Xserver
X-App-Name
X-Proxied
X-Routing-Service
X-Site-Version
X-Xfnlog-Site
X-Zipkin-Id
DB-Nickname
X-ProxyCache-Key
X-ProxyCache-Status
X-Debug-Cache
Mail-Subject
We-Hiring
X-Akamai-Transformed
User-Agent
Liferay-Portal
Cache-Hits
X-Original-Request
X-Pc-Appver
X-Protected-By
X-Pc-Hit
X-Pc-Key
S-Cnection
X-EdgeConnect-Cache-Status
X-Cache-NE
X-Node-Name
X-ES-SERVER
X-Nginx-Cache
LB
X-Sucuri-ID
X-Origin
X-FW-Version
X-Ocache
CACHE
X-Request-Time
User-Cache-Control
X-Proto
X-Cdn-Forward
PageSpeed
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Trace-Id
Powered
X-UA
X-Ua
X-GRACE
X-Forwarded-Host
X-Webstats-RespID
Ohc-File-Size
X-Tumblr-Pixel-3
X-Varnish-Ttl
X-Unique-ID
X-Endurance-Cache-Level
L5d-Success-Class
X-LJ-Flow-ID
X-AWS-Id
X-VWS-Id
X-Correlation-ID
X-FB-TRIP-ID
Section-Io-Cache
Frame-Options
X-Nc
X-Origin-CC
X-Cluster-Node
X-V
X-Time
X-Varnish-Beresp-Status
X-URL
OT-Force-Account-Verify
X-Varnish-Beresp-Grace
X-OVcl-Cache
X-OVcl
X-Origin-TTL
X-Webkit-Csp
AR-SID
X-EIG-Tracking-Id
X-ElasticPress-Search
X-R9-Blue-Green-Version
X-Cache-Backend
Nel
Decoy-Debug-Status
X-From
Decoy-Debug-TTL
Decoy-Debug-Key
IBM-Web2-Location
X-Li-Pop
X-VG-WebServer
X-LI-Proto
X-We-Are-Hiring
BehaviorPad-Version
X-DPWN-IS-SECURE
Arc-Country
X-Info
X-Fetched-On
X-IN-WAF
X-IN-APIGATEWAY
X-Li-Fabric
X-LI-UUID
X-Generated-In
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Distil-CS
X-External-Request-Id
Ec-Rule-Version
X-ARC
X-Application
Mobile-Detection-Method
X-Auto-Login
Meta-Geo-Continent
MD5-Digest
Memcached
X-B-Cookie
X-Amz-Meta-Cache-Control
Node
Www
VivaBuild
Viewtype
Rendered-Blocks
Powered-By
On-Server
X-Aed
X-Accel-Expires-Debug
X-BB-ID
X-Cache-FS-Status
Fastly-SWR
Fly-Cache
Fly-Request-Id
Fastly-SIE
X-Date
Cache-Prefix
X-Destination
Country-Code
X-Connection-Hash
GMS-Ver
X-Cache-Info
X-Cache-Host
X-Cache-Grace
X-Cache-URL
X-Cdn-Srv
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-Developer
X-Irp-Debug
X-Server-By
X-Transaction
X-Parent-Response-Time
Xc-Version
X-Wikidot-Static-Cache
X-Rebelmouse-Cache-Control
X-Twitter-Response-Tags
X-TT-LOGID
X-User
X-Wikidot-Backend
X-PAYTM-SRV-ID
X-Reboot
X-Rebelmouse-Surrogate-Control
X-ServiceProvider
X-Region-Sid
X-UE-Client-Country
X-Server-Group
X-Rocket-Nginx-Bypass
X-Request-UUID
X-ScT
X-Trv-Group
X-S-Cookie
X-Node-Id
X-Micro-Cache
X-Rewrite-Enabled
X-SRCache-Key
X-NU-AKA-ACS-Version
X-Rojux
X-Origin-Expires
X-Origin-Date
X-Dc
X-Varnish-Beresp-Ttl
X-Vgn-Hpd-Reason
X-Cache-Expires
X-Cache-Debug
X-Cache-Bucket
X-Server-IP
X-C
X-Returned-From-PostProcessResponse
X-S-Maxage
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Thinkindot-Control
X-Cache-Id
X-Block-Status
Who
X-A-Dam
X-Returned-From-BeforeDispatch
X-Swa-Ws
X-Stale
X-Alternate-Cache-Key
X-A-Dgt
X-A-Dcw
X-A-Ccd
X-Returned-From
X-Backend-Url
X-Returned-From-DLL
X-Backend-Host
X-A-Wwc
X-Secret
X-Actual-URL
X-Bip
X-Crawler
X-GeoIP-Country-Code
X-Hash
X-Hnp-Log
X-ShopId
X-Passed-To
X-Passed-To-BeforeDispatch
X-Gannett-Site-Version
X-Gen-Mode
X-Passed-To-DLL
X-Generated-On
X-Shopify-Stage
X-NX-Host
X-Level-Front-Cache
X-SIPLIST1
X-Location
X-Sorting-Hat-PodId
X-Logtrace-Id
X-Matched-Rule
X-Nginx-Cache-Key
X-Var-Ttl
X-Sorting-Hat-ShopId
X-LAGOON
X-G
X-Fastly-Cache
X-Platform
X-D
SD-X-WS
X-Debug-Cookies
X-Policy
X-Proxy-Cache-Status
X-Clientip
X-Varnish-Action
X-Core-Mission
X-Proxy-Upstream
X-Backend-State
X-Debug-Log
X-Epic-Correlation-Id
X-Thinkindot-L3
X-Eu-Site
X-Passed-To-PostProcessResponse
X-Thanos
X-Distributor
Server-Host
X-Response-By
X-ShardId
X-PHP-Host
X-CGP
X-A
Lfy
IsBot
Backend
Magicmarker
Ajk
Origin
Request-Time
Proxy-Connection
X-Upstream-HT
X-Upstream-CT
Fastly-Backend-Name
Fastly-Soc-X-Request-Id
Content-Disposition
Countrycode
CDCHOST
HA-Ipaddr
Ha-Gx-Prefs
X-HS-Cache-Config
Mn-Server-Ip
X-Via-CDN
Warning
X-Pc-Host
X-Sucuri-Cache
X-Pc-Date
X-Pc-Subdomain
X-TIME
Cache-Cookie-Set-From
X-Developers
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-Idcheck
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Qloud-Router
X-Dispatcher-Server
X-Sf
X-CUA
X-Croise-Owner
Server-Cache-Control
X-Request-URI
X-Debug-Cache-Expiry
X-TrackingId
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Svr
Apple-News-Services-Host
X-Instart-Isnd
Fastly-SSL
X-Core-Value
X-Varnish-Authentication
X-MSEdge-Features
X-Variation
X-MSEdge-Flight
X-Up
Adler-Geo
Apple-News-Services-Handled
X-No-Session
Apple-News-Services-Parsed-Url
X-Fstrz
X-SERVER
X-UnsetCookies
AKAMAI
Apple-News-Services-Request-Url
X-F5-Cache
Heartbleed
X-Cache-ASPX
Platform
True-Client-Country-4JS
X-Amz-Meta-Surrogate-Control
Server-Int
Server-Surrogate-Control
Pramga
SS
Is-Eu
Resin-Trace
Web-Mar-Node
GW-Server
Release
Kp-EeAlive
SID
X-IN-SSL-APIGATEWAY
X-Server-Time
RNT-Time
REQUESTUUID
RNT-Machine
X-Server-Cache
X-Key
X-Device-Os
Pagetype
X-FireWall-Port
NGX
X-Be
X-Cache-Miss-From
Server-ID
Hostname
X-Varnish-Url
X-Servername
X-Generation-Time
X-Sedo-Request-Id
X-Page-Type
X-SN
X-Owner
X-Pjax-Url
Fastcgi-X-Cache
X-B3-Traceid
RequestId
Odigeo-Trace-Id
X-Via-NSCOPI
X-Died
X-Edge-Cache
X-Edge-Cache-Key
X-CDN-Forward
X-Newrelic-App-Data
X-Refresh
HostName
Version
MIME-Version
HTTPS
X-NC
X-B3-SpanId
Cteonnt-Length
X-Servedbyhost
PFcat
X-Edge-Server
Cdn-Request-Time
Cdn-Host
X-From-Cache
X-Oss-Object-Type
X-Oss-Storage-Class
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-FPC
X-Oss-Request-Id
Time
Cdn
ProcessTime
Mime-Version
PICS-Label
X-Store
Esi-Enabled
X-Req
X-Cache-CFC
FastCGI-Cache
X-Mobile-URL
MI-API
MI-Cache-Age
MI-Cache
X-CSRF-TOKEN
X-MI-In-Market
X-RCS-CacheZone
X-Layer
X-Hyper-Cache
X-GZip
CF-IPCountry
Memory
HA-Geolat
HA-Urlpath
HA-Geocountry
HA-Servedtime
HA-Georegion
X-RequestId
HA-Host
X-IPS-LoggedIn
HA-Geocity
Cross-Origin-Window-Policy
X-Amzn-Remapped-Date
X-Webkit-CSP
X-Amzn-Remapped-Connection
X-NodeID
HA-Cloudapp
Processtime
HA-Geolon
X-Load-Cache
X-CLOUD-TRACE-CONTEXT
X-Wa
X-VServer
X-HS-Combine-CSS
X-Dynatrace-Js-Agent
X-Ratelimit-Remaining
CDN
X-Real-Ip
X-Varnish-Beresp-TTL
Backend-Name
X-Lb-Id
X-Skip-Cache
Cf-Ipcountry
X-HTML-Minification-Powered-By
X-Newrelic-Synthetics
XServer
X-Geo
X-CMS-Context
X-Ratelimit-Limit
X-DC
X-Pf-Uncompressing
X-Aicache-OS
Uber-Trace-Id
X-Unique-Id-Primal
X-Mrs-Age
X-WR-MODIFICATION
Ohc-Cache-HIT
X-Mshield-Cache-Status
X-Mrs-Cache-Hits
X-B3-Spanid
X-Mrs-Cache
X-Instart-Info
X-VC-Cache
X-PF-Uncompressing
Ohc-Response-Time
X-Cms-Context
X-Tb-Optimization-Total-Bytes-Saved
X-Phone
X-WebServer
X-Atg-Version
X-WA
X-Request-Start
X-Gateway-Cache-Status
URI
X-Release
X-Gateway-Skip-Cache
X-Gateway-Cache-Key
N-Cache
GeoIP-Country-Code
X-Fastly-Country-Code
X-UCC
Amp-Access-Control-Allow-Source-Origin
T-Server
GeoIP-Latitude
X-Nananana
X-FORWARDED-FOR
Accept-Ch-Lifetime
X-Processor
X-Server-W
Pics-Label
X-LB-ID
X-Oracle-Dms-Ecid
X-Shard
X-BBXSRF
X-COUNTRY
X-MServer
X-Hp-Webp
X-APP
X-Served-From
X-CSRF-Token
X-GoCache-CacheStatus
X-Datadome
Rt-Proxy-Cache
X-Unique-Id
X-Worker
X-SRV
X-ND-Cache
X-LiteSpeed-Cache-Control
X-VHOST
X-ServedByHost
A
X-SERVER-NAME
X-VCT
Host-ID
X-Amzn-Remapped-Content-Length
X-UPSTREAM-Address
X-CACHE-AGE
X-Geo-Header
X-GeoIP-City
DataCenter
X-Fastly-Cache-Hits
X-HS-Status
X-Check-Cacheable
X-Requestid
UCS
X-Cdn-Origin
X-Optimization
X-GZIP
V-Age
X-Cache-HT
X-Sn-Servicetimems
X-NGINX-Cache
Request-EU
Dnion-Transfer-Encoding
X-Varnish-URL
X-ID
X-Vcache
Geoip-Latitude
Request-Country
Proxy-Firewall
X-BE
X-SVT-ORM-RULES
Cneonction
X-SVT-ORM-VERSION
X-Backend-TTL
X-Fastly-Backend-Reqs
X-Csrf-Token
X-P-T
X-PJAX-URL
WZWS-RAY
X-ServerName
X-Fpc
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
Pragrma
FSS-Cache
FSS-Proxy
X-PAGE-TYPE
X-Git-Hash
GeoIp-Country-Code
Requestid
Is-Session-Tracking
Get-Access-Time
X-Port
WP-Super-Cache
X-NWS-UUID-VERIFY
Serverid
X-Dw-Trace-Id
X-HostName
RequestUuid
X-Org
Cache-Provider
ServerName
X-Gen-Id
X-StackifyID
X-LiteSpeed-Tag
X-Fe
Server-Id
X-Html-Edge-Cache
355prline
409pxxline
X-RCS-Backend
X-GDPR
X-Via-SSL
X-Via-Edge
Xxline
352pxline
225prxHost
Inserted-Into-Cache-At
178proxuri
X-Request-Url
X-RAMCache
X-CS
188prxHost
DSUID
219prxHost
189phosttRef
286prxHost