Threat Level: green Handler on Duty: Russ McRee

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
CF-RAY
ETag
Link
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Request-Id
X-Xss-Protection
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Adblock-Key
X-Check
Alt-Svc
X-Cacheable
X-Generator
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-Cache-Status
X-AspNetMvc-Version
X-Permitted-Cross-Domain-Policies
X-Iinfo
X-Template
X-Language
Status
Timing-Allow-Origin
X-Buckets
X-Content-Security-Policy
Content-Encoding
X-CDN
X-Kinja-Server-Push
Xkey
X-Turbo-Charged-By
Upgrade
X-Type
Keep-Alive
Access-Control-Expose-Headers
X-Request-ID
WPE-Backend
X-Pass-Why
Access-Control-Max-Age
X-Backend
X-AH-Environment
CF-Ray
X-Cache-Group
X-Age
X-Drupal-Dynamic-Cache
X-Server
X-Ua-Compatible
X-Via
X-Proxy-Cache
Grace
X-Pingback
X-Nginx-Cache-Status
X-Server-Powered-By
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Hacker
X-UA-Device
X-Varnish-Cache
EagleId
X-Page-Speed
Request-Context
X-LiteSpeed-Cache
Cf-Railgun
X-Envoy-Upstream-Service-Time
X-CST
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Server-Id
X-Device
X-Amz-Version-Id
X-Ac
X-Node
Server-Timing
X-OneAgent-JS-Injection
Feature-Policy
X-Cnection
X-Iejgwucgyu
X-Response-Time
Allow
X-Rq
Content-Location
X-Cache-Lookup
X-Backend-Server
Report-To
EagleEye-TraceId
X-Readtime
Surrogate-Control
X-Host
X-Application-Context
Request-Id
X-Url
X-ORACLE-DMS-ECID
X-Rack-Cache
X-Origin-Cache
X-Clacks-Overhead
X-Country
NEL
X-FTR-Request-ID
Rating
X-Country-Code
X-Cloud-Trace-Context
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-DataDome
X-Instart-Request-ID
X-Px
X-Vhost
X-MS-InvokeApp
Charset
X-Mod-Pagespeed
X-Ruxit-JS-Agent
X-VARITI-CCR
Edge-Control
Accept-CH
X-Goog-Hash
X-GitHub-Request-Id
X-Mobile-Rewrite
PB-RID
PB-PID
Arc-Version
Verso
X-Varnish-TTL
X-ESI
X-DynaTrace
X-Version
X-PC
X-TtlSet
X-Vname
X-Server-Name
X-TTL
X-Cdn
X-Powered-By-Plesk
X-D2id
Pinterest-Generated-By
X-Cdn-Fetch
X-Kinja-Server
X-Exp-Variant
X-Exp-Id
X-Kinja
X-GoogleNews-Bot
X-Kinja-Build
X-Kinja-Revision
X-Use-Magma
X-Cached
X-B3-TraceId
SPRequestGuid
X-Origin-Upstream-Status
X-Upstream-Env
X-Dispatcher
X-Powered-CMS
X-SharePointHealthScore
X-Abt-Application-Version
X-T
MS-Author-Via
X-Recruiting
Accept-CH-Lifetime
RTSS
X-Navigation-Version
Public-Key-Pins
X-Trace
X-Shield-Request-Id
X-Oracle-Dms-Rid
X-ORACLE-DMS-RID
Content-MD5
AR-PoweredBy
AR-CACHE
AR-ATIME
SPRequestDuration
X-Amz-Rid
X-SRCache-Fetch-Status
SPIisLatency
X-SRCache-Store-Status
X-Fastly-Request-ID
X-HW
X-DIS-Request-ID
X-Client-IP
Realpath
Arr-Disable-Session-Affinity
X-Accel-Buffering
X-Wix-Server-Artifact-Id
X-Forwarded-Proto
X-F-Cache
X-B
X-Server-ID
X-DynaTrace-JS-Agent
X-Upstream
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Ser
X-Amz-Meta-S3cmd-Attrs
Service-Worker-Allowed
X-Via-JSL
Pinterest-Version
X-Pinterest-Rid
X-Id
X-Dw-Request-Base-Id
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-DC
X-Country-Code-Real
X-FTR-Realm
X-FTR-Expires
X-Vcap-Request-Id
Front-End-Https
Paypal-Debug-Id
AR-Request-ID
X-Varnish-Age
X-Dns-Prefetch-Control
X-Debug
X-Goog-Storage-Class
X-Ttl
X-Acc-Meta-Resource-Type
Nginx-Cache
Ar-Sid
X-MSEdge-Ref
X-N
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Kinsta-Cache
X-Hits
X-NF-Request-ID
X-NewRelic-App-Data
X-Logged-In
X-FTR-Cache-Host
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
S
X-XRDS-Location
X-Akam-SW-Version
X-Forwarded-For
X-Frontend
X-HS-Content-Id
X-HS-Hub-Id
X-Grace
Alternate-Protocol
X-PressLabs-Stats
X-User-Agent
AMP-Access-Control-Allow-Source-Origin
Tracecode
X-Amzn-Trace-Id
X-Cache-Key
X-DataStream-Cache-Status
DynaTrace
X-TA-CDN-Provider
X-CACHE-GROUP
Server-Name
X-Pad
X-Content-Digest
Refresh
X-Content-Options
X-Analytics
Backend-Timing
Accept-Charset
Fastcgi-Cache
X-Activity-Id
Powered-By-ChinaCache
X-Az
MicrosoftSharePointTeamServices
X-AppVersion
X-Rid
X-Page-Id
FilterID
X-LB-Cache
X-Zen-Fury
MS-CV
Display
Host
X-Middleton-Display
X-Sol
X-Content-Type
X-IPLB-Instance
X-Debug-Info
Access-Control-Request-Method
X-FastCGI-Cache
X-Fastcgi-Cache
X-CF-Powered-By
TCN
X-Magnolia-Registration
ServerID
TP-L2-Cache
TP-Cache
Response
X-Middleton-Response
X-XRDS-LOCATION
Cache-Status
X-ATG-Version
X-Cache-Hit
X-Mobile
X-Ruxit-Js-Agent
X-Content-Powered-By
X-Srv
Surrogate-Key
X-Seen-By
X-VCache
X-WA-Info
X-Hostname
X-B3-Sampled
Rt-Fastcgi-Cache
X-Revision
X-Cached-By
X-Request-Processing-Time
X-Request-Received
X-Varnish-Backend
X-RateLimit-Remaining
X-Cache-Age
X-SS-Set-Cookie
X-Signature
X-B-Cache
X-Cache-Action
X-Cluster
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Instance
X-Tumblr-Pixel-0
X-Tumblr-User
X-Content-Security-Policy-Report-Only
X-Tumblr-Pixel
Cleartype
Source
X-Whom
X-PHP-Backend
X-Drupal-Cache-Tags
X-Akamai-Edgescape
X-Platform-Server
X-Framework
X-TT
X-Handled-By
X-Edge-Location
X-Request-Guid
X-Origin-Server
Server-Info
X-App-Environment
ViewerVersion
X-Wix-Request-Id
Host-Header
X-GUploader-UploadID
X-Cache-Control
X-BCube-Filmed-By
X-Generated-By
DC
X-Amz-Apigw-Id
X-Cache-Rule
X-NWS-LOG-UUID
X-Amzn-RequestId
X-AOL-HN
X-Varnish-Hostname
X-Geo-Country
X-Oneagent-Js-Injection
X-Cache-2
Retry-After
X-App-Server
X-FW-Static
X-FW-Type
X-FW-Serve
X-FW-Server
X-FW-Hash
X-Varnish-Server
Server-Node
Eomportal-Instance
X-Correlation-Id
X-Real-IP
Fusion-Content-Source
Fusion-Content-Id
Fusion-Component-Id
Fusion-Template-Id
Fusion-Source
X-FB-Debug
Payment
X-Device-Type
Webserver
Cache
X-Response-Served-From
X-Amz-Server-Side-Encryption
Actual-Object-TTL
Access-Control-Allow-Method
X-Tumblr-Pixel-2
X-Varnish-Hits
X-TT-TIMESTAMP
X-Tumblr-Pixel-1
AsisCache
ServedBy
GEO-INFO
Content-Script-Type
X-Cacheable-TTL
Content-Style-Type
X-Region
Filters
X-WebKit-CSP-Report-Only
NGB
X-RTag
Ms-Operation-Id
X-Varnish-Grace
X-Jobs
Healthy
X-Amz-Replication-Status
Viewport
X-Adobe-Loc
X-Servedby
X-Adobe-Content
Edge-Cache-Tag
X-TX-ID
X-UUID
X-Varnish-IP
X-Contextid
X-Rendered-As
Country
X-Drupal-Cache-Contexts
X-Locale
X-Accel-Expires
X-Cache-Config
Upgrade-Insecure-Requests
Cache-Tv-Group
X-UA-Device-Type
From-Origin
X-RequestSource
X-WPE-Loopback-Upstream-Addr
X-Cache-TTL-Remaining
HitType
X-BACKEND-TTL
X-Ezoic-Cdn
X-Cache-Server
X-Cache-Remote
X-VG-WebCache
X-Cache-TTL
X-Cache-Operation
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Pagespeed
Fastly-Restarts
Fastcgi-Useragent
X-Storage
X-APP-VERSION
Cache-Tags
X-Content-Age
X-Upgrade-Enabled
X-Hit
X-FW-Dynamic
X-Redis-Cache
X-S
X-Esi
X-Guploader-Uploadid
Datacenter
X-Mode
X-App-Version
NtCoent-Length
Cache-Tag
X-Daa-Tunnel
Served-By
X-Source
Meta-Geo
Machine
Origin-Cache-Control
Load-Balancing
X-Cache-NE
Origin-Edge-Control
X-Cache-Var
X-Path-Route
X-Detected-As
X-NGENIX-Cache
X-Generated
X-Rule
X-RN-RSRV
X-NCache
X-Cache-Var-Map
X-Is-Bot
X-Internal-Host
X-JoinUs
X-Hl-Ver
SRV
X-Backend-Name
X-Grey
X-TNCMS
X-Timing-Wait
X-Origin-Host
X-Www-Served-By
X-Origin-Response-Time
X-Loop
X-Labrador-Cache-Channel
X-Time-Microsecs
X-Akamai-Request-ID
X-L-Path
X-GeoIP
X-Web-Node
X-Pubstack
X-Birta-Served
Now
X-BYPASS-REASON
X-Birta-Cache-Post
X-Agile-Id
Vix-Hermes-Req-Id
X-Agile
X-Agile-Age
X-Cache-Category-Id
X-Hosted-By
X-Proxy-Build
X-ProxyCache-Status
X-Proxy
X-FC-Vary-Parameters
X-Environment-Context
X-CDN-Cache
X-Edge-IP
X-ProxyCache-Key
X-Tb
Selected-FE
X-Status
Xserver
X-ServerID
X-RemovedCookies
X-Varnish-Cacheable
X-Via-Fastly
Cache-Name
X-ProcessESI
X-PERF
X-IP
X-RateLimit-Limit
X-Human
X-Pc-Appver
X-ApacheServer
X-Pc-Key
X-Pc-Hit
Cache-Key
X-Viewer-Country
X-Akamai-Transformed
X-Site-Version
X-CCM
X-PCL
X-OCL
X-Debug-Cache
X-Varnish-Cache-Hits
DB-Nickname
S-Rt
X-Proxied
X-Zipkin-Id
X-Xfnlog-Site
X-Original-Request
X-Format
We-Hiring
X-Routing-Service
Public-Key-Pins-Report-Only
Mail-Subject
X-MP-GENERATED-AT
X-VG-TLSProxy
X-Cache-Enabled
Azure-SlotName
X-Access
X-Origin-Hint
Azure-SiteName
X-Section
Azure-RegionName
X-Origin
Webcakes-App-Name
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Device-Class
Property-Id
TWC-Privacy
Azure-InstanceId
Webcakes-App-Version
Azure-Version
Webcakes-Region
TWC-Connection-Speed
X-UA
Fastcgi-X-Cache-Version
X-Ocache
X-Sucuri-ID
S-Cnection
Access-Control-Request-Headers
User-Cache-Control
X-Cdn-Forward
X-Microcachable
X-App-Name
Liferay-Portal
X-Upstream-Proxy
X-Protected-By
X-EdgeConnect-Cache-Status
X-Request-Time
X-Nginx-Cache
X-CACHE-KEY
X-DataStream-Origin-MEX-Latency
X-Tumblr-Pixel-3
X-FW-Version
X-DataStream-MidMile-RTT
X-Webstats-RespID
User-Agent
X-GRACE
X-Origin-CC
X-FB-TRIP-ID
X-Proto
X-Yottaa-Optimizations
X-Yottaa-Metrics
PageSpeed
X-Trace-Id
LB
X-Node-Name
X-Nc
Cache-Hits
Ohc-File-Size
X-GEO
Powered
X-Varnish-Beresp-Status
X-Upstream-HT
X-Correlation-ID
X-Upstream-CT
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Ttl
X-ES-SERVER
X-Endurance-Cache-Level
X-Forwarded-Host
X-ElasticPress-Search
Frame-Options
X-Cache-Backend
X-OVcl-Cache
L5d-Success-Class
X-TIME
X-OVcl
X-V
X-Rocket-Nginx-Bypass
IBM-Web2-Location
X-Ua
X-Origin-TTL
X-Pc-Date
X-Pc-Host
X-Edge-Cache-Key
X-Edge-Cache
AR-SID
X-Vgn-Hpd-Reason
X-B3-Traceid
X-Parent-Response-Time
Section-Io-Cache
X-Time
X-Server-Cache
Nel
X-Unique-ID
OT-Force-Account-Verify
X-Dynatrace-Js-Agent
X-Gen-Mode
X-Generated-In
Country-Code
X-From
Fastly-SIE
Ec-Rule-Version
Decoy-Debug-TTL
Decoy-Debug-Status
Decoy-Debug-Key
X-Irp-Debug
X-Info
X-IN-WAF
Fastly-SWR
X-Li-Fabric
X-Li-Pop
X-IN-SSL-APIGATEWAY
X-IN-APIGATEWAY
X-Goog-Meta-Goog-Reserved-File-Mtime
BehaviorPad-Version
X-Hnp-Log
Arc-Country
Cache-Prefix
X-DPWN-IS-SECURE
Powered-By
X-BB-ID
X-B-Cookie
X-Auto-Login
X-Block-Status
X-Cache-Bucket
Mobile-Detection-Method
Node
X-Cache-FS-Status
Rendered-Blocks
X-ARC
Www
VivaBuild
Viewtype
X-Accel-Expires-Debug
X-Aed
X-Application
X-Amz-Meta-Cache-Control
Resin-Trace
X-Cache-Host
X-Cache-Id
X-Distil-CS
X-Died
X-Developer
X-Destination
X-LI-UUID
X-External-Request-Id
Fly-Request-Id
X-Fetched-On
GMS-Ver
X-Date
X-Connection-Hash
X-Cache-URL
Meta-Geo-Continent
X-Cache-Info
Memcached
MD5-Digest
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-Cdn-Srv
Fly-Cache
X-LI-Proto
X-Server-Group
X-UE-Client-Country
X-Server-By
X-Twitter-Response-Tags
X-ScT
X-User
X-VG-WebServer
X-We-Are-Hiring
Xc-Version
X-PAYTM-SRV-ID
X-ServiceProvider
X-PHP-Host
X-S-Maxage
X-TT-LOGID
X-Rebelmouse-Surrogate-Control
X-SRCache-Key
X-Reboot
X-Region-Sid
X-Request-UUID
X-Rewrite-Enabled
X-Rebelmouse-Cache-Control
X-Trv-Group
X-S-Cookie
X-Rojux
X-Transaction
X-Pc-Subdomain
Fastcgi-X-Cache
X-Micro-Cache
X-Origin-Date
X-Origin-Expires
X-NU-AKA-ACS-Version
X-VWS-Id
X-R9-Blue-Green-Version
X-LJ-Flow-ID
X-Dc
X-AWS-Id
X-Bip
X-Node-Id
X-Backend-Url
X-Backend-Host
X-Sorting-Hat-PodId
X-Cache-Debug
X-Thinkindot-L3
X-Shopify-Stage
X-Cache-Expires
X-Matched-Rule
X-Cache-Grace
X-Thanos
X-Logtrace-Id
X-A-Ccd
X-A-Dam
X-A-Dcw
X-A
X-Returned-From-BeforeDispatch
X-Svr
X-Returned-From-DLL
Web-Mar-Node
X-A-Dgt
X-A-Wwc
X-Sorting-Hat-ShopId
X-Request-URI
X-Returned-From-PostProcessResponse
X-Response-By
X-Alternate-Cache-Key
X-Returned-From
X-Swa-Ws
X-Stale
X-RateLimit-Limit-Second
X-Server-IP
X-Variation
X-Varnish-Action
X-Var-Ttl
X-Fastly-Cache
True-Client-Country-4JS
X-ShardId
X-Passed-To-DLL
X-FireWall-Port
X-Wikidot-Static-Cache
X-Generated-On
X-Passed-To-PostProcessResponse
X-Sf
X-Hash
X-Server-Time
X-G
X-Distributor
X-Passed-To-BeforeDispatch
X-Passed-To
X-Crawler
X-CUA
X-Level-Front-Cache
X-NX-Host
X-Wikidot-Backend
X-Proxy-Upstream
X-D
X-Proxy-Cache-Status
X-Policy
X-Dispatcher-Server
X-ShopId
X-Location
X-Debug-Cookies
X-Debug-Log
X-RateLimit-Remaining-Second
X-Actual-URL
Platform
X-Via-NSCOPI
Mn-Server-Ip
Request-Time
Fastly-Backend-Name
X-Via-CDN
Origin
On-Server
Is-Eu
Ajk
Lfy
Magicmarker
HostName
SD-X-WS
Proxy-Connection
Adler-Geo
Thinkindot-Control
Content-Disposition
Thinkindot-CacheControl
Backend
Server-Host
Thinkindot-CacheControl-Type
X-HS-Cache-Config
X-Sucuri-Cache
X-Ratelimit-Remaining
Warning
X-Croise-Owner
X-No-Session
HA-Ipaddr
Fastly-Soc-X-Request-Id
X-Nginx-Cache-Key
Heartbleed
CDCHOST
AKAMAI
Countrycode
X-Device-Os
X-Gannett-Site-Version
X-Eu-Site
GW-Server
X-LAGOON
X-Fstrz
X-Key
X-Epic-Correlation-Id
X-Core-Mission
X-Instart-Isnd
X-GeoIP-Country-Code
Who
X-C
X-Clientip
X-Generation-Time
Ha-Gx-Prefs
X-CGP
X-Backend-State
X-Qloud-Router
Pramga
X-Platform
X-Cache-ASPX
RNT-Machine
X-SIPLIST1
X-Secret
SS
Server-Surrogate-Control
Server-Cache-Control
RNT-Time
Pagetype
Release
X-Varnish-Authentication
Kp-EeAlive
IsBot
X-UnsetCookies
X-Cluster-Node
X-SERVER
Server-ID
X-F5-Cache
Cache-Cookie-Set-Lfrom
CACHE
X-Varnish-Url
Version
Server-Int
Cache-Cookie-Set-From
Fastly-SSL
X-Debug-Cache-Fetch
X-Developers
X-Debug-Cache-Store
X-Page-Type
X-Core-Value
X-Amz-Meta-Surrogate-Control
X-Up
X-Debug-Cache-Expiry
REQUESTUUID
Cache-Cookie-Set-Idcheck
X-Servername
X-Pjax-Url
X-MSEdge-Features
X-MSEdge-Flight
Apple-News-Services-Handled
Apple-News-Services-Request-Url
PFcat
NGX
X-TrackingId
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
X-Be
X-Sedo-Request-Id
X-EIG-Tracking-Id
X-Refresh
RequestId
X-Cache-Miss-From
X-Newrelic-App-Data
Esi-Enabled
X-Cache-CFC
X-Store
SID
X-RCS-CacheZone
MI-Cache-Age
MI-Cache
MI-API
X-MI-In-Market
X-Layer
X-CDN-Forward
X-Ratelimit-Limit
X-URL
X-Geo
Time
X-RequestId
Cdn
X-IPS-LoggedIn
X-From-Cache
X-Oss-Storage-Class
X-SN
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-Owner
MIME-Version
X-Oss-Object-Type
X-Oss-Request-Id
X-B3-SpanId
X-NC
Odigeo-Trace-Id
HA-Cloudapp
HA-Geolon
HA-Urlpath
HA-Host
HA-Geocountry
HA-Servedtime
HA-Georegion
Mime-Version
HA-Geocity
HA-Geolat
PICS-Label
X-Mrs-Age
X-Mrs-Cache-Hits
X-Mshield-Cache-Status
X-Mrs-Cache
X-Real-Ip
X-Unique-Id-Primal
X-Hyper-Cache
Cteonnt-Length
X-FPC
FastCGI-Cache
Backend-Name
X-CMS-Context
X-Servedbyhost
HTTPS
Hostname
X-Edge-Server
Cf-Ipcountry
Cdn-Host
Cdn-Request-Time
X-Varnish-Ttl
X-Req
X-Webkit-Csp
Processtime
X-Webkit-CSP
X-B3-Spanid
X-CLOUD-TRACE-CONTEXT
CF-IPCountry
Memory
X-Instart-Info
X-WebServer
X-Phone
X-CSRF-TOKEN
X-Aicache-OS
Ohc-Response-Time
X-Request-Start
X-Wa
CDN
X-WR-MODIFICATION
GeoIP-Country-Code
X-Release
X-Pf-Uncompressing
X-DC
X-Amzn-Remapped-Connection
X-HS-Combine-CSS
X-Mobile-URL
X-Amzn-Remapped-Date
ProcessTime
X-Newrelic-Synthetics
X-NodeID
X-Load-Cache
X-VServer
X-GZip
Cross-Origin-Window-Policy
GeoIP-Latitude
XServer
X-WA
X-Lb-Id
X-Atg-Version
X-HTML-Minification-Powered-By
X-Served-From
X-ND-Cache
X-Varnish-Beresp-TTL
Rt-Proxy-Cache
X-Unique-Id
X-Skip-Cache
X-Fastly-Country-Code
X-Server-W
X-PF-Uncompressing
X-GoCache-CacheStatus
X-FORWARDED-FOR
URI
T-Server
X-Nananana
Accept-Ch-Lifetime
Ohc-Cache-HIT
X-Oracle-Dms-Ecid
X-Tb-Optimization-Total-Bytes-Saved
X-CSRF-Token
X-VC-Cache
X-ServedByHost
X-COUNTRY
X-Cms-Context
X-Cdn-Origin
X-Sn-Servicetimems
V-Age
X-LB-ID
X-MServer
X-UPSTREAM-Address
Pics-Label
X-Gateway-Cache-Key
Proxy-Firewall
N-Cache
Uber-Trace-Id
X-APP
X-Gateway-Skip-Cache
X-Gateway-Cache-Status
X-SVT-ORM-RULES
X-UCC
X-Datadome
X-SRV
X-SVT-ORM-VERSION
X-Worker
X-LiteSpeed-Cache-Control
X-P-T
Get-Access-Time
Is-Session-Tracking
A
X-Fastly-Cache-Hits
X-SERVER-NAME
Amp-Access-Control-Allow-Source-Origin
X-HS-Status
X-CACHE-AGE
X-Processor
DataCenter
ServerName
X-Check-Cacheable
X-Hp-Webp
X-RCS-Backend
X-BBXSRF
X-Requestid
X-GZIP
X-NGINX-Cache
X-HostName
Geoip-Latitude
X-BE
X-Optimization
X-Cache-HT
X-ID
Dnion-Transfer-Encoding
X-Vg-Webcache
X-Backend-TTL
GeoIp-Country-Code
X-PAGE-TYPE
X-Port
X-PJAX-URL
X-Varnish-URL
X-GDPR
WZWS-RAY
X-StackifyID
X-Csrf-Token
X-Org
Cneonction
X-Fe
Requestid
X-NWS-UUID-VERIFY
Serverid
X-Via-SSL
X-LiteSpeed-Tag
X-Dw-Trace-Id
X-ServerName
Server-Id
WP-Super-Cache
X-Git-Hash
X-VCT
Host-ID
X-Amzn-Remapped-Content-Length
Cache-Provider
RequestUuid
X-GeoIP-City
X-Via-Edge
X-Geo-Header
X-Planisys-CDN-Rules
X-RAMCache
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
Correlation-Id
286prxHost
225prxHost
219prxHost
352pxline
355prline
Pragrma
409pxxline
189phosttRef
188prxHost
X-Gdpr
Xxline
X-Request-Url
X-CS
178proxuri
DSUID
X-Instance-Name