Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
CF-RAY
ETag
Link
Expect-CT
Via
X-XSS-Protection
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Xss-Protection
X-Varnish
X-Request-Id
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Adblock-Key
X-Check
Alt-Svc
X-Cacheable
X-Generator
Content-Security-Policy-Report-Only
X-AspNetMvc-Version
X-Cache-Status
X-DNS-Prefetch-Control
X-Permitted-Cross-Domain-Policies
X-Iinfo
X-Template
X-Language
Status
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Buckets
X-Content-Security-Policy
Content-Encoding
X-Kinja-Server-Push
Xkey
X-Turbo-Charged-By
X-CDN
Upgrade
X-Type
Keep-Alive
Access-Control-Expose-Headers
WPE-Backend
X-Pass-Why
X-AH-Environment
X-Backend
Access-Control-Max-Age
X-Age
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Server
X-Proxy-Cache
X-Request-ID
X-Via
Grace
X-Pingback
X-Nginx-Cache-Status
X-Server-Powered-By
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Hacker
X-Varnish-Cache
X-UA-Device
X-Page-Speed
EagleId
Request-Context
X-LiteSpeed-Cache
X-Envoy-Upstream-Service-Time
Cf-Railgun
X-Ua-Compatible
X-CST
X-Swift-CacheTime
X-Swift-SaveTime
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Ali-Swift-Global-Savetime
X-Server-Id
X-Device
X-Amz-Version-Id
X-WebKit-CSP
Server-Timing
X-Ac
Allow
X-Node
X-OneAgent-JS-Injection
X-Response-Time
Feature-Policy
X-Rq
X-Cnection
X-Iejgwucgyu
Content-Location
X-Backend-Server
Report-To
X-Cache-Lookup
EagleEye-TraceId
Surrogate-Control
X-Host
X-Readtime
X-Application-Context
Request-Id
P3p
X-ORACLE-DMS-ECID
X-Rack-Cache
X-Url
X-Origin-Cache
X-Clacks-Overhead
X-Country
NEL
X-FTR-Request-ID
Rating
X-Country-Code
X-Cloud-Trace-Context
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-DataDome
X-Cdn
X-Ruxit-JS-Agent
X-Px
X-Instart-Request-ID
X-Mod-Pagespeed
Charset
X-Vhost
X-VARITI-CCR
X-MS-InvokeApp
Pinterest-Generated-By
Accept-CH
X-Goog-Hash
Edge-Control
X-Upstream-Env
Verso
X-PC
X-Vname
X-TtlSet
X-GitHub-Request-Id
PB-RID
PB-PID
Arc-Version
X-Mobile-Rewrite
X-Server-Name
X-ESI
X-Version
X-Dns-Prefetch-Control
X-DynaTrace
X-Powered-By-Plesk
X-Origin-Upstream-Status
X-D2id
X-TTL
X-Kinja-Build
X-Use-Magma
X-GoogleNews-Bot
X-Cdn-Fetch
X-Kinja
X-Exp-Id
X-Exp-Variant
X-Kinja-Server
X-Kinja-Revision
X-Cached
X-Dispatcher
X-B3-TraceId
SPRequestGuid
X-Recruiting
X-Varnish-TTL
X-SharePointHealthScore
MS-Author-Via
X-Abt-Application-Version
X-Powered-CMS
Accept-CH-Lifetime
X-Navigation-Version
Content-MD5
X-ORACLE-DMS-RID
RTSS
AR-PoweredBy
AR-CACHE
AR-ATIME
X-Shield-Request-Id
X-T
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Trace
X-Forwarded-Proto
X-DynaTrace-JS-Agent
Public-Key-Pins
X-Client-IP
X-Amz-Rid
Arr-Disable-Session-Affinity
X-Oracle-Dms-Rid
X-HW
X-Wix-Server-Artifact-Id
X-Accel-Buffering
X-Fastly-Request-ID
SPIisLatency
SPRequestDuration
Realpath
X-DIS-Request-ID
Service-Worker-Allowed
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
AR-Request-ID
Paypal-Debug-Id
X-Amz-Meta-S3cmd-Attrs
Front-End-Https
X-Upstream
X-Ser
X-FTR-DC
X-FTR-Cache-Status
X-Country-Code-Real
X-FTR-Backend
X-FTR-Balancer
X-FTR-Realm
X-FTR-Backend-Server
X-B
X-FTR-Expires
Pinterest-Version
X-Pinterest-Rid
X-Id
X-Via-JSL
X-F-Cache
X-XRDS-Location
X-Ttl
X-Dw-Request-Base-Id
X-Debug
Ar-Sid
X-Vcap-Request-Id
X-Server-ID
X-Goog-Storage-Class
X-Varnish-Age
X-Acc-Meta-Resource-Type
X-MSEdge-Ref
X-N
X-Kinsta-Cache
Nginx-Cache
X-Hits
X-NF-Request-ID
X-DataStream-Cache-Status
S
X-FTR-Cache-Host
X-Logged-In
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Akam-SW-Version
X-TEC-API-ORIGIN
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
X-Forwarded-For
X-NewRelic-App-Data
X-Grace
Tracecode
Alternate-Protocol
X-FastCGI-Cache
X-Frontend
X-User-Agent
X-HS-Content-Id
X-HS-Hub-Id
X-PressLabs-Stats
X-Amzn-Trace-Id
X-CACHE-GROUP
TCN
AMP-Access-Control-Allow-Source-Origin
X-Content-Options
Server-Name
X-Content-Digest
X-Sol
Refresh
X-Middleton-Display
Display
Powered-By-ChinaCache
X-Content-Type
X-Pad
Access-Control-Request-Method
X-Cache-Key
X-Page-Id
MicrosoftSharePointTeamServices
X-Analytics
Backend-Timing
X-Middleton-Response
X-Zen-Fury
DynaTrace
Response
X-Debug-Info
X-Az
X-IPLB-Instance
X-Rid
X-LB-Cache
X-AppVersion
X-Activity-Id
X-CF-Powered-By
Accept-Charset
FilterID
Host
X-VCache
Fastcgi-Cache
X-Hostname
MS-CV
ServerID
Cache-Status
X-Cache-Hit
TP-Cache
TP-L2-Cache
X-GUploader-UploadID
X-Magnolia-Registration
X-RateLimit-Remaining
X-Seen-By
X-Srv
X-Content-Powered-By
X-Mobile
X-Revision
X-Cached-By
X-Fastcgi-Cache
X-WA-Info
X-Varnish-Backend
X-ATG-Version
Host-Header
X-Request-Processing-Time
X-Whom
X-Real-IP
X-Request-Received
Surrogate-Key
Server-Info
VIX-Pulpo-Upstream-Status
X-Instance
VIX-Pulpo-Node
X-B3-Sampled
X-SS-Set-Cookie
X-Cache-Action
X-Cluster
DC
X-Drupal-Cache-Tags
Source
X-Request-Guid
X-Tumblr-User
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Handled-By
X-Content-Security-Policy-Report-Only
X-Platform-Server
X-B-Cache
X-Signature
X-Wix-Request-Id
X-PHP-Backend
ViewerVersion
Cleartype
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Framework
X-Akamai-Edgescape
X-TT
X-Origin-Server
Fusion-Component-Id
Fusion-Content-Source
Fusion-Source
Fusion-Content-Id
Fusion-Template-Id
X-App-Environment
X-Cache-Age
X-Geo-Country
X-App-Server
X-Generated-By
X-FW-Type
X-FW-Hash
X-FW-Static
X-FW-Server
X-FW-Serve
Rt-Fastcgi-Cache
X-Oneagent-Js-Injection
X-Varnish-Server
X-BCube-Filmed-By
X-AOL-HN
X-Cache-Control
Server-Node
X-XRDS-LOCATION
X-Edge-Location
X-Ruxit-Js-Agent
X-Upstream-Proxy
X-Cache-Rule
X-NWS-LOG-UUID
X-Varnish-Hostname
Retry-After
Payment
X-Amz-Server-Side-Encryption
X-Varnish-Grace
X-TA-CDN-Provider
X-Correlation-Id
X-Cache-2
X-Amz-Replication-Status
Access-Control-Allow-Method
X-FB-Debug
X-Response-Served-From
X-Ezoic-Cdn
X-TT-TIMESTAMP
X-Rendered-As
AsisCache
X-Varnish-Hits
X-Cache-Config
X-Cacheable-TTL
ServedBy
Eomportal-Instance
X-Tumblr-Pixel-2
Actual-Object-TTL
X-UA-Device-Type
X-Tumblr-Pixel-1
GEO-INFO
Webserver
X-Contextid
Content-Style-Type
X-Drupal-Cache-Contexts
Healthy
X-Region
Content-Script-Type
NGB
X-Jobs
X-WebKit-CSP-Report-Only
X-RTag
X-TX-ID
Ms-Operation-Id
X-UUID
Filters
X-VG-WebCache
X-Adobe-Content
X-Adobe-Loc
HitType
X-Varnish-IP
Upgrade-Insecure-Requests
X-Locale
From-Origin
X-Cache-TTL
X-Accel-Expires
Viewport
Country
X-RequestSource
Cache-Tv-Group
Fastcgi-Useragent
X-Cache-TTL-Remaining
X-BACKEND-TTL
X-Device-Type
X-FW-Dynamic
Pagespeed
X-Cache-Server
X-Content-Age
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Edge-Cache-Tag
X-Servedby
X-WPE-Loopback-Upstream-Addr
Cache-Tags
X-APP-VERSION
X-Cache-Remote
X-Redis-Cache
X-Upgrade-Enabled
X-Source
X-Esi
X-Cache-Operation
X-Hit
X-DataStream-Origin-MEX-Latency
X-DataStream-MidMile-RTT
X-RateLimit-Limit
Cache
X-Storage
Datacenter
X-GeoIP
Fastly-Restarts
NtCoent-Length
X-Mode
Cache-Tag
X-Hl-Ver
X-Internal-Host
Load-Balancing
X-JoinUs
X-S
X-Agile
X-Agile-Age
Vix-Hermes-Req-Id
Meta-Geo
Machine
Served-By
X-Agile-Id
X-Cache-Var
X-Cache-Var-Map
X-Labrador-Cache-Channel
X-Backend-Name
X-Akamai-Request-ID
X-Detected-As
X-Is-Bot
X-Time-Microsecs
X-Origin-Response-Time
X-RN-RSRV
X-TNCMS
X-Loop
X-Path-Route
X-Pubstack
X-Cache-Category-Id
X-BYPASS-REASON
X-ProxyCache-Key
X-Proxy
X-Birta-Served
X-ProxyCache-Status
X-L-Path
X-Tb
X-Varnish-Cacheable
X-Www-Served-By
X-ServerID
X-Rule
X-Varnish-Cache-Hits
S-Rt
X-Birta-Cache-Post
X-Status
X-Generated
X-IP
Now
X-Grey
X-NCache
X-Microcachable
X-Hosted-By
Origin-Cache-Control
Cache-Key
X-Origin-Host
X-FC-Vary-Parameters
Origin-Edge-Control
X-Edge-IP
X-CDN-Cache
X-Environment-Context
TWC-GeoIP-LatLong
TWC-Locale-Group
TWC-Privacy
Webcakes-App-Name
TWC-GeoIP-Country
Property-Id
TWC-Device-Class
SRV
TWC-Connection-Speed
Cache-Name
X-Web-Node
X-RemovedCookies
Webcakes-App-Version
X-Cache-Enabled
X-PERF
X-Origin-Hint
X-CACHE-KEY
X-Format
X-ApacheServer
X-ProcessESI
Webcakes-Region
X-Viewer-Country
X-Via-Fastly
X-VG-TLSProxy
X-NGENIX-Cache
X-MP-GENERATED-AT
X-OCL
X-CCM
X-ES-SERVER
Public-Key-Pins-Report-Only
X-PCL
X-Section
X-Access
X-Human
Azure-RegionName
Azure-SlotName
Azure-InstanceId
Access-Control-Request-Headers
X-Akamai-Transformed
User-Agent
Azure-Version
Azure-SiteName
Fastcgi-X-Cache-Version
Cache-Hits
DB-Nickname
X-Site-Version
We-Hiring
X-GEO
X-Routing-Service
X-Proxy-Build
X-Timing-Wait
X-Proxied
CACHE
X-App-Name
X-Xfnlog-Site
Selected-FE
X-Debug-Cache
Mail-Subject
X-Zipkin-Id
Liferay-Portal
Xserver
X-Daa-Tunnel
X-Node-Name
X-EdgeConnect-Cache-Status
LB
X-FW-Version
S-Cnection
X-Protected-By
X-App-Version
X-Original-Request
X-Origin
X-Sucuri-ID
X-Pc-Hit
X-Pc-Appver
X-Pc-Key
X-Proto
X-Cache-NE
PageSpeed
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Ocache
X-Nginx-Cache
X-AWS-Id
X-LJ-Flow-ID
X-VWS-Id
X-UA
X-Trace-Id
Powered
User-Cache-Control
X-Request-Time
X-Varnish-Ttl
X-Forwarded-Host
X-Cluster-Node
X-Guploader-Uploadid
X-Endurance-Cache-Level
X-Tumblr-Pixel-3
X-Cdn-Forward
Ohc-File-Size
L5d-Success-Class
X-Correlation-ID
X-Ua
Section-Io-Cache
X-Unique-ID
X-Webstats-RespID
Frame-Options
X-FB-TRIP-ID
X-V
X-URL
X-EIG-Tracking-Id
X-Origin-CC
X-Nc
OT-Force-Account-Verify
X-GRACE
X-B3-Traceid
AR-SID
X-Webkit-Csp
X-OVcl-Cache
X-Varnish-Beresp-Grace
X-OVcl
X-Varnish-Beresp-Status
X-Time
Nel
X-Origin-TTL
Decoy-Debug-Key
X-ElasticPress-Search
Decoy-Debug-TTL
X-From
Decoy-Debug-Status
X-Cache-Backend
X-Connection-Hash
X-UE-Client-Country
X-Twitter-Response-Tags
X-TT-LOGID
Powered-By
X-S-Cookie
SD-X-WS
X-Transaction
X-ScT
X-S-Maxage
X-Trv-Group
X-Date
X-Cache-URL
Fastly-SIE
X-B-Cookie
Fastly-SWR
VivaBuild
X-Backend-State
Ec-Rule-Version
Cache-Prefix
Country-Code
X-BB-ID
Fly-Cache
Fly-Request-Id
X-Aed
X-Accel-Expires-Debug
X-ServiceProvider
X-Server-Group
X-Amz-Meta-Cache-Control
X-Application
X-SRCache-Key
X-ARC
GMS-Ver
X-Rocket-Nginx-Bypass
X-Destination
X-Rewrite-Enabled
X-Server-By
Www
X-Cache-Info
Mobile-Detection-Method
Node
On-Server
X-CF-Lambda-Fn
X-Cdn-Srv
Meta-Geo-Continent
X-Cache-Id
X-Cache-Grace
Viewtype
BehaviorPad-Version
X-Cache-FS-Status
X-Cache-Host
X-Rojux
Memcached
MD5-Digest
Arc-Country
X-CF-Lambda-Version
X-External-Request-Id
X-Wikidot-Static-Cache
X-Rebelmouse-Surrogate-Control
Rendered-Blocks
X-LI-UUID
X-LI-Proto
X-Rebelmouse-Cache-Control
X-We-Are-Hiring
X-Origin-Expires
X-Origin-Date
X-NU-AKA-ACS-Version
X-VG-WebServer
X-Li-Pop
X-Li-Fabric
X-IN-APIGATEWAY
X-IN-WAF
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Request-UUID
X-Generated-In
X-Info
X-Region-Sid
X-Varnish-Beresp-Ttl
X-Reboot
Xc-Version
X-Irp-Debug
X-R9-Blue-Green-Version
X-Wikidot-Backend
X-Response-By
X-Fetched-On
X-DPWN-IS-SECURE
X-Distil-CS
X-User
X-Developer
X-PAYTM-SRV-ID
X-PHP-Host
X-Parent-Response-Time
X-TIME
IBM-Web2-Location
X-LAGOON
Who
X-Policy
X-Eu-Site
X-Passed-To-BeforeDispatch
X-Epic-Correlation-Id
X-Debug-Cookies
X-Fastly-Cache
X-A-Dam
X-A-Dcw
X-A-Ccd
X-A
X-A-Wwc
X-Distributor
X-A-Dgt
True-Client-Country-4JS
X-CGP
X-Dispatcher-Server
X-Passed-To-DLL
X-Generated-On
X-GeoIP-Country-Code
Request-Time
Server-Host
Thinkindot-CacheControl
Thinkindot-Control
X-Level-Front-Cache
X-Request-URI
Thinkindot-CacheControl-Type
X-Hash
X-Hnp-Log
X-G
X-Actual-URL
X-Gannett-Site-Version
X-C
X-Block-Status
X-Core-Mission
X-Backend-Url
X-Debug-Log
X-Cache-Bucket
X-Nginx-Cache-Key
X-Passed-To-PostProcessResponse
X-Passed-To
X-NX-Host
X-Returned-From-DLL
X-Cache-Expires
X-Node-Id
X-CUA
X-Micro-Cache
X-Returned-From-PostProcessResponse
X-Location
X-Platform
X-Alternate-Cache-Key
X-RateLimit-Remaining-Second
X-Returned-From-BeforeDispatch
X-Auto-Login
X-Logtrace-Id
X-D
X-Backend-Host
X-Matched-Rule
X-Returned-From
X-RateLimit-Limit-Second
X-Gen-Mode
X-Variation
X-Var-Ttl
X-SIPLIST1
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
Fastly-SSL
X-Shopify-Stage
X-ShopId
X-Server-IP
HA-Ipaddr
Ha-Gx-Prefs
X-ShardId
Fastly-Soc-X-Request-Id
Fastly-Backend-Name
Ajk
X-Thinkindot-L3
Adler-Geo
X-Via-CDN
Mn-Server-Ip
Backend
X-Swa-Ws
X-Stale
X-Svr
Content-Disposition
CDCHOST
Is-Eu
X-Sf
X-Secret
X-Vgn-Hpd-Reason
SID
Origin
Platform
X-Newrelic-App-Data
Magicmarker
X-SERVER
Proxy-Connection
IsBot
Lfy
Warning
X-HS-Cache-Config
X-MSEdge-Flight
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-TrackingId
X-Croise-Owner
X-Crawler
X-No-Session
Release
X-Proxy-Upstream
X-Proxy-Cache-Status
X-Qloud-Router
X-Core-Value
X-Instart-Isnd
X-Thanos
X-Sucuri-Cache
X-Fstrz
X-Device-Os
X-Varnish-Action
X-F5-Cache
X-Developers
SS
X-Up
X-UnsetCookies
X-Varnish-Authentication
X-Owner
X-FireWall-Port
X-MSEdge-Features
X-Debug-Cache-Store
Web-Mar-Node
NGX
Heartbleed
X-Amz-Meta-Surrogate-Control
GW-Server
X-Clientip
Server-Int
RNT-Machine
Resin-Trace
RNT-Time
Pramga
Server-Cache-Control
X-Bip
Server-Surrogate-Control
Countrycode
Cache-Cookie-Set-From
Cache-Cookie-Set-Idcheck
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
AKAMAI
Apple-News-Services-Handled
X-Cache-Debug
Apple-News-Services-Request-Url
Cache-Cookie-Set-Lfrom
X-Cache-ASPX
X-Dc
X-Pc-Host
X-Pc-Date
X-Pc-Subdomain
Hostname
Odigeo-Trace-Id
X-Key
Server-ID
X-SN
REQUESTUUID
Pagetype
X-Upstream-CT
X-Page-Type
X-Server-Time
X-Varnish-Url
X-Upstream-HT
Kp-EeAlive
X-Be
X-Sedo-Request-Id
X-Server-Cache
X-IN-SSL-APIGATEWAY
X-Cache-Miss-From
X-Servername
X-CDN-Forward
X-Refresh
X-Generation-Time
HTTPS
X-Pjax-Url
X-NC
MIME-Version
Cdn-Request-Time
X-Oss-Request-Id
X-Died
Cdn-Host
X-Oss-Object-Type
X-Edge-Server
X-Oss-Storage-Class
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-Via-NSCOPI
X-B3-SpanId
Fastcgi-X-Cache
X-From-Cache
RequestId
HostName
X-Servedbyhost
X-FPC
Version
X-Edge-Cache
X-Edge-Cache-Key
PICS-Label
PFcat
X-Mobile-URL
ProcessTime
X-Req
Cteonnt-Length
FastCGI-Cache
X-CSRF-TOKEN
Cdn
Time
Cross-Origin-Window-Policy
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
X-VServer
X-NodeID
Mime-Version
X-GZip
CF-IPCountry
X-Cache-CFC
X-Webkit-CSP
Esi-Enabled
Processtime
X-Store
X-HS-Combine-CSS
X-Load-Cache
X-CLOUD-TRACE-CONTEXT
X-Wa
MI-API
Memory
MI-Cache
MI-Cache-Age
X-Skip-Cache
X-Layer
X-RCS-CacheZone
X-MI-In-Market
X-Dynatrace-Js-Agent
X-Ratelimit-Remaining
CDN
X-DC
X-Hyper-Cache
HA-Cloudapp
HA-Host
HA-Georegion
HA-Geolon
HA-Geocountry
HA-Geocity
HA-Geolat
HA-Urlpath
HA-Servedtime
X-Lb-Id
Uber-Trace-Id
X-RequestId
X-IPS-LoggedIn
X-Atg-Version
Ohc-Cache-HIT
XServer
X-Ratelimit-Limit
X-Pf-Uncompressing
X-HTML-Minification-Powered-By
X-Varnish-Beresp-TTL
X-Geo
X-Aicache-OS
Cf-Ipcountry
X-VC-Cache
X-Cms-Context
Backend-Name
X-Newrelic-Synthetics
X-Gateway-Skip-Cache
N-Cache
X-CMS-Context
X-Fastly-Country-Code
X-Gateway-Cache-Status
X-Gateway-Cache-Key
X-UCC
X-B3-Spanid
X-Shard
X-PF-Uncompressing
X-Tb-Optimization-Total-Bytes-Saved
X-Instart-Info
X-Real-Ip
X-WR-MODIFICATION
X-WA
X-Mrs-Cache
Amp-Access-Control-Allow-Source-Origin
X-Mrs-Age
X-Unique-Id-Primal
X-Mrs-Cache-Hits
X-Mshield-Cache-Status
X-Nananana
X-LB-ID
X-Phone
Ohc-Response-Time
Accept-Ch-Lifetime
T-Server
X-WebServer
X-Processor
X-BBXSRF
X-Hp-Webp
GeoIP-Country-Code
X-Release
X-Oracle-Dms-Ecid
X-Request-Start
URI
X-MServer
X-COUNTRY
X-Server-W
Pics-Label
GeoIP-Latitude
X-APP
X-Unique-Id
X-SRV
DataCenter
X-CSRF-Token
X-Worker
X-FORWARDED-FOR
X-Datadome
X-VCT
Host-ID
A
X-Geo-Header
X-Amzn-Remapped-Content-Length
X-VHOST
X-GeoIP-City
X-LiteSpeed-Cache-Control
X-ServedByHost
X-SERVER-NAME
X-ND-Cache
X-Check-Cacheable
X-HS-Status
Rt-Proxy-Cache
X-Served-From
X-NGINX-Cache
UCS
X-GoCache-CacheStatus
X-CACHE-AGE
X-GZIP
X-Cache-HT
X-Optimization
X-UPSTREAM-Address
Request-EU
X-Requestid
X-Fastly-Cache-Hits
Request-Country
Dnion-Transfer-Encoding
Geoip-Latitude
FSS-Proxy
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Fpc
FSS-Cache
Pragrma
X-BE
X-Planisys-CDN-TTL
X-ID
X-Vcache
X-Backend-TTL
X-Cdn-Origin
V-Age
X-Org
X-Csrf-Token
X-Git-Hash
X-Varnish-URL
X-PAGE-TYPE
X-Sn-Servicetimems
X-Fastly-Backend-Reqs
X-Dw-Trace-Id
X-Port
Cneonction
WP-Super-Cache
WZWS-RAY
Requestid
X-PJAX-URL
GeoIp-Country-Code
X-ServerName
Serverid
Cache-Provider
X-HostName
X-SVT-ORM-RULES
Proxy-Firewall
X-Via-Edge
X-Via-SSL
Server-Id
X-SVT-ORM-VERSION
RequestUuid
X-Gen-Id
X-Html-Edge-Cache
X-NWS-UUID-VERIFY
Inserted-Into-Cache-At
Xxline
178proxuri
188prxHost
189phosttRef
DSUID
Get-Access-Time
X-P-T
X-Fe
Is-Session-Tracking
219prxHost
225prxHost
X-Request-Url
X-CS
X-LiteSpeed-Tag
409pxxline
355prline
286prxHost
352pxline
X-RAMCache