Threat Level: green Handler on Duty: Russ McRee

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
CF-RAY
ETag
Link
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Request-Id
X-Xss-Protection
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Adblock-Key
X-Check
Alt-Svc
X-Cacheable
X-Generator
Content-Security-Policy-Report-Only
X-Cache-Status
X-DNS-Prefetch-Control
X-AspNetMvc-Version
X-Permitted-Cross-Domain-Policies
X-Iinfo
X-Template
X-Language
Status
Timing-Allow-Origin
X-Buckets
X-Content-Security-Policy
Content-Encoding
X-CDN
X-Kinja-Server-Push
Xkey
X-Turbo-Charged-By
Upgrade
X-Type
Access-Control-Expose-Headers
Keep-Alive
WPE-Backend
X-Pass-Why
Access-Control-Max-Age
X-Backend
X-AH-Environment
CF-Ray
X-Age
X-Drupal-Dynamic-Cache
X-Server
X-Ua-Compatible
X-Cache-Group
X-Via
X-Request-ID
X-Proxy-Cache
Grace
X-Pingback
X-Nginx-Cache-Status
X-Server-Powered-By
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Hacker
X-UA-Device
X-Varnish-Cache
X-Page-Speed
EagleId
Request-Context
X-LiteSpeed-Cache
Cf-Railgun
X-Envoy-Upstream-Service-Time
X-CST
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Server-Id
X-Device
X-Amz-Version-Id
X-Ac
X-Node
Server-Timing
X-OneAgent-JS-Injection
Feature-Policy
X-Iejgwucgyu
X-Response-Time
X-Cnection
Allow
X-Rq
Content-Location
X-Cache-Lookup
X-Backend-Server
Report-To
EagleEye-TraceId
Surrogate-Control
X-Readtime
X-Host
X-Application-Context
Request-Id
X-Url
X-ORACLE-DMS-ECID
X-Rack-Cache
X-Origin-Cache
X-Clacks-Overhead
X-Country
NEL
X-FTR-Request-ID
Rating
X-Country-Code
X-Cloud-Trace-Context
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-DataDome
X-Instart-Request-ID
X-Px
X-Vhost
X-MS-InvokeApp
X-Mod-Pagespeed
Charset
X-Ruxit-JS-Agent
X-VARITI-CCR
Edge-Control
Accept-CH
X-Goog-Hash
X-GitHub-Request-Id
PB-RID
Arc-Version
PB-PID
X-Mobile-Rewrite
Verso
X-Varnish-TTL
X-ESI
X-TTL
X-DynaTrace
X-Version
X-Server-Name
X-PC
X-TtlSet
X-Vname
X-Dns-Prefetch-Control
X-Cdn
X-Powered-By-Plesk
X-D2id
Pinterest-Generated-By
X-Exp-Variant
X-Exp-Id
X-Cdn-Fetch
X-Kinja-Build
X-GoogleNews-Bot
X-Kinja-Revision
X-Kinja
X-Kinja-Server
X-Use-Magma
X-Cached
X-B3-TraceId
SPRequestGuid
X-Dispatcher
X-Upstream-Env
X-Origin-Upstream-Status
X-Powered-CMS
X-SharePointHealthScore
X-Abt-Application-Version
MS-Author-Via
X-T
X-Recruiting
Accept-CH-Lifetime
RTSS
X-Trace
X-Navigation-Version
Public-Key-Pins
X-Shield-Request-Id
X-Oracle-Dms-Rid
X-ORACLE-DMS-RID
Content-MD5
AR-ATIME
AR-PoweredBy
AR-CACHE
SPIisLatency
X-SRCache-Store-Status
X-SRCache-Fetch-Status
SPRequestDuration
X-Amz-Rid
X-Fastly-Request-ID
X-HW
X-DIS-Request-ID
X-Client-IP
Arr-Disable-Session-Affinity
Realpath
X-Forwarded-Proto
X-Wix-Server-Artifact-Id
X-Accel-Buffering
X-F-Cache
X-Server-ID
X-B
X-DynaTrace-JS-Agent
X-Upstream
X-Goog-Stored-Content-Length
X-Amz-Meta-S3cmd-Attrs
X-Ser
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Via-JSL
X-Pinterest-Rid
Pinterest-Version
Service-Worker-Allowed
X-CACHE-GROUP
X-Id
X-Dw-Request-Base-Id
X-FTR-DC
X-FTR-Cache-Status
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Backend
X-FTR-Realm
X-FTR-Balancer
X-FTR-Expires
Front-End-Https
AR-Request-ID
X-Vcap-Request-Id
Paypal-Debug-Id
X-Varnish-Age
X-Aspnet-Version
X-Debug
X-Goog-Storage-Class
X-Acc-Meta-Resource-Type
Nginx-Cache
X-MSEdge-Ref
Ar-Sid
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Hits
X-N
X-Kinsta-Cache
X-NF-Request-ID
X-XRDS-Location
X-NewRelic-App-Data
X-FTR-Cache-Host
X-Logged-In
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Ttl
S
X-Akam-SW-Version
X-Forwarded-For
X-HS-Content-Id
X-Frontend
X-HS-Hub-Id
Alternate-Protocol
X-PressLabs-Stats
AMP-Access-Control-Allow-Source-Origin
X-User-Agent
X-Grace
Tracecode
X-DataStream-Cache-Status
X-Cache-Key
X-Amzn-Trace-Id
DynaTrace
X-TA-CDN-Provider
X-FastCGI-Cache
X-Pad
Server-Name
X-Content-Digest
Refresh
X-Content-Options
Backend-Timing
X-Analytics
Accept-Charset
Fastcgi-Cache
Powered-By-ChinaCache
MicrosoftSharePointTeamServices
X-Az
X-Zen-Fury
X-Activity-Id
X-Rid
X-AppVersion
Access-Control-Request-Method
FilterID
X-Debug-Info
X-Middleton-Display
Display
X-Page-Id
X-Sol
X-IPLB-Instance
X-LB-Cache
Host
X-CF-Powered-By
MS-CV
X-Content-Type
TCN
ServerID
X-Magnolia-Registration
TP-L2-Cache
TP-Cache
X-Middleton-Response
Response
Cache-Status
X-Cache-Hit
X-Mobile
X-Content-Powered-By
X-Ruxit-Js-Agent
X-Fastcgi-Cache
X-Srv
Surrogate-Key
X-ATG-Version
X-Seen-By
X-WA-Info
X-VCache
X-Hostname
X-B3-Sampled
X-RateLimit-Remaining
Rt-Fastcgi-Cache
X-XRDS-LOCATION
X-Cached-By
X-Revision
X-Request-Received
X-Request-Processing-Time
X-Varnish-Backend
X-GUploader-UploadID
X-Cache-Age
VIX-Pulpo-Upstream-Status
X-Cache-Action
VIX-Pulpo-Node
X-SS-Set-Cookie
X-Content-Security-Policy-Report-Only
X-Instance
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel
X-Signature
X-Request-Guid
X-Whom
X-PHP-Backend
X-Cluster
Source
X-B-Cache
Cleartype
X-TT
X-Drupal-Cache-Tags
X-Edge-Location
X-Platform-Server
X-Akamai-Edgescape
X-Handled-By
X-Framework
X-Origin-Server
X-App-Environment
X-Wix-Request-Id
ViewerVersion
Host-Header
Server-Info
X-Cache-Control
X-BCube-Filmed-By
X-NWS-LOG-UUID
DC
X-Generated-By
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Cache-Rule
X-Cache-2
X-AOL-HN
X-App-Server
X-Varnish-Hostname
X-Oneagent-Js-Injection
X-Geo-Country
Retry-After
X-FW-Hash
X-FW-Server
X-FW-Static
X-FW-Type
X-FW-Serve
Server-Node
Eomportal-Instance
X-Varnish-Server
X-Real-IP
X-Correlation-Id
Fusion-Component-Id
Fusion-Content-Id
Fusion-Content-Source
Fusion-Template-Id
Fusion-Source
Payment
X-Device-Type
Webserver
Actual-Object-TTL
X-FB-Debug
X-Response-Served-From
X-Amz-Server-Side-Encryption
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
Access-Control-Allow-Method
ServedBy
X-TT-TIMESTAMP
AsisCache
X-Varnish-Hits
Content-Style-Type
Content-Script-Type
Filters
X-Cacheable-TTL
X-WebKit-CSP-Report-Only
X-UUID
GEO-INFO
X-TX-ID
NGB
X-Varnish-Grace
Upgrade-Insecure-Requests
X-Amz-Replication-Status
Viewport
X-Adobe-Content
X-Adobe-Loc
X-Servedby
Edge-Cache-Tag
X-Varnish-IP
X-Contextid
Ms-Operation-Id
X-Region
X-RTag
Healthy
Country
X-Drupal-Cache-Contexts
X-Locale
X-Jobs
X-Accel-Expires
Cache
Cache-Tv-Group
X-Cache-Config
X-UA-Device-Type
X-Rendered-As
From-Origin
X-RequestSource
X-WPE-Loopback-Upstream-Addr
X-Cache-TTL-Remaining
X-BACKEND-TTL
HitType
X-Cache-Server
X-Ezoic-Cdn
X-Aspnetmvc-Version
X-Cache-Remote
X-VG-WebCache
X-Cache-TTL
X-Cache-Operation
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Pagespeed
Fastly-Restarts
X-APP-VERSION
Fastcgi-Useragent
X-Content-Age
X-Storage
X-FW-Dynamic
X-Upgrade-Enabled
X-Redis-Cache
Cache-Tags
X-S
X-Hit
X-Esi
X-Mode
X-Daa-Tunnel
X-App-Version
X-RateLimit-Limit
Cache-Tag
NtCoent-Length
X-Source
Served-By
Machine
Load-Balancing
X-Path-Route
X-Hl-Ver
X-Cache-NE
Meta-Geo
Origin-Cache-Control
X-Rule
X-RN-RSRV
Origin-Edge-Control
X-Detected-As
X-Is-Bot
X-Internal-Host
X-Backend-Name
X-Cache-Var
X-Cache-Var-Map
X-NCache
X-FC-Vary-Parameters
X-Edge-IP
X-Environment-Context
X-Cache-Category-Id
X-Grey
Datacenter
X-Akamai-Request-ID
X-ServerID
X-ProxyCache-Key
X-Tb
X-Agile-Age
X-Time-Microsecs
X-CDN-Cache
X-Agile
X-Proxy
X-Pubstack
X-ProxyCache-Status
X-Proxy-Build
SRV
X-Agile-Id
X-Timing-Wait
X-Labrador-Cache-Channel
X-Origin-Response-Time
X-L-Path
X-Birta-Served
X-JoinUs
X-Birta-Cache-Post
Vix-Hermes-Req-Id
Now
X-Web-Node
X-Origin-Host
X-Www-Served-By
X-BYPASS-REASON
Selected-FE
X-Status
X-ProcessESI
X-PERF
Cache-Key
X-GeoIP
X-TNCMS
X-RemovedCookies
X-Pc-Key
X-Pc-Hit
X-Human
X-Hosted-By
X-IP
X-Loop
X-ApacheServer
X-Pc-Appver
Cache-Name
X-Varnish-Cacheable
X-Viewer-Country
X-Via-Fastly
X-OCL
X-NGENIX-Cache
DB-Nickname
X-PCL
X-CCM
X-Guploader-Uploadid
X-Akamai-Transformed
X-Generated
X-Debug-Cache
X-Varnish-Cache-Hits
X-Site-Version
S-Rt
X-Original-Request
We-Hiring
X-MP-GENERATED-AT
Azure-SlotName
Azure-Version
Azure-SiteName
Azure-RegionName
Public-Key-Pins-Report-Only
X-Format
X-Zipkin-Id
X-Routing-Service
X-Proxied
Mail-Subject
X-VG-TLSProxy
Azure-InstanceId
X-Xfnlog-Site
Webcakes-App-Name
X-Section
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Locale-Group
TWC-Privacy
Webcakes-Region
X-Origin
TWC-Device-Class
Property-Id
X-Origin-Hint
Webcakes-App-Version
X-Access
TWC-Connection-Speed
X-Cache-Enabled
X-App-Name
Xserver
X-UA
X-Ocache
Fastcgi-X-Cache-Version
User-Cache-Control
X-Sucuri-ID
Access-Control-Request-Headers
X-Microcachable
S-Cnection
Liferay-Portal
X-Protected-By
X-Upstream-Proxy
X-Request-Time
X-Cdn-Forward
X-CACHE-KEY
X-DataStream-MidMile-RTT
X-DataStream-Origin-MEX-Latency
X-EdgeConnect-Cache-Status
X-Nginx-Cache
X-Tumblr-Pixel-3
X-FW-Version
X-Webstats-RespID
X-GEO
User-Agent
X-Proto
X-Origin-CC
X-FB-TRIP-ID
X-GRACE
X-Yottaa-Metrics
PageSpeed
X-Trace-Id
X-Yottaa-Optimizations
LB
Cache-Hits
Ohc-File-Size
X-Node-Name
X-Correlation-ID
X-Upstream-CT
X-Upstream-HT
X-Varnish-Beresp-Ttl
Powered
X-ES-SERVER
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
X-Endurance-Cache-Level
X-Forwarded-Host
X-Nc
Frame-Options
X-Cache-Backend
X-Pc-Date
X-ElasticPress-Search
X-Pc-Host
L5d-Success-Class
X-B3-Traceid
X-OVcl
X-OVcl-Cache
X-Unique-ID
X-TIME
Section-Io-Cache
X-V
X-Parent-Response-Time
X-Ua
X-Edge-Cache
X-Origin-TTL
AR-SID
X-Edge-Cache-Key
IBM-Web2-Location
X-Rocket-Nginx-Bypass
X-Vgn-Hpd-Reason
X-Time
X-Pc-Subdomain
OT-Force-Account-Verify
X-Server-Cache
Nel
HostName
X-Dynatrace-Js-Agent
X-Info
X-IN-WAF
X-Li-Pop
X-Generated-In
X-IN-APIGATEWAY
X-Irp-Debug
X-Hnp-Log
Arc-Country
X-IN-SSL-APIGATEWAY
X-Li-Fabric
Fly-Cache
X-Cache-Bucket
Mobile-Detection-Method
Node
X-Block-Status
X-BB-ID
X-Cache-FS-Status
Meta-Geo-Continent
X-Cache-Id
X-Cache-Host
MD5-Digest
Memcached
X-B-Cookie
Powered-By
Resin-Trace
X-Accel-Expires-Debug
Www
VivaBuild
Viewtype
Rendered-Blocks
X-Aed
X-Auto-Login
X-ARC
X-Application
X-Amz-Meta-Cache-Control
X-Cache-Info
X-Cdn-Srv
Decoy-Debug-TTL
Decoy-Debug-Status
Ec-Rule-Version
X-External-Request-Id
Fastly-SIE
Decoy-Debug-Key
Country-Code
X-Gen-Mode
X-From
Cache-Prefix
X-Fetched-On
X-DPWN-IS-SECURE
Fastly-SWR
X-Date
X-Connection-Hash
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-Destination
X-Developer
X-LI-Proto
Fly-Request-Id
GMS-Ver
X-Distil-CS
BehaviorPad-Version
Fastcgi-X-Cache
X-Trv-Group
X-Reboot
X-Region-Sid
X-Transaction
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-PHP-Host
X-User
X-ServiceProvider
X-TT-LOGID
X-Request-UUID
X-Rewrite-Enabled
X-ScT
X-Server-By
CACHE
X-Server-Group
X-S-Maxage
X-SRCache-Key
X-Rojux
X-LI-UUID
X-S-Cookie
X-PAYTM-SRV-ID
X-Twitter-Response-Tags
X-We-Are-Hiring
X-Origin-Date
X-Origin-Expires
Xc-Version
X-NU-AKA-ACS-Version
X-Micro-Cache
X-VG-WebServer
X-AWS-Id
X-R9-Blue-Green-Version
X-LJ-Flow-ID
X-VWS-Id
X-Cache-Grace
X-Sf
Web-Mar-Node
X-Cache-Debug
X-Stale
Thinkindot-Control
True-Client-Country-4JS
X-SIPLIST1
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Cache-Expires
X-Bip
X-A-Dgt
X-A-Dcw
X-A-Dam
X-UE-Client-Country
X-Var-Ttl
X-Actual-URL
X-Variation
X-A-Ccd
X-A
X-Thanos
X-Swa-Ws
X-Varnish-Action
X-Thinkindot-L3
X-Backend-Host
X-Backend-Url
X-Svr
X-Debug-Cookies
X-Passed-To-DLL
X-Generated-On
X-Goog-Meta-Goog-Reserved-File-Mtime
Thinkindot-CacheControl-Type
X-Passed-To-PostProcessResponse
X-FireWall-Port
X-Policy
X-G
X-Passed-To-BeforeDispatch
X-Passed-To
X-Level-Front-Cache
X-Logtrace-Id
X-Location
X-Matched-Rule
X-Nginx-Cache-Key
X-NX-Host
X-Node-Id
X-Proxy-Cache-Status
X-Proxy-Upstream
X-Debug-Log
X-Died
X-Dispatcher-Server
X-D
X-CUA
X-Server-IP
X-Cache-URL
X-Crawler
X-Returned-From-PostProcessResponse
X-Returned-From-DLL
X-Fastly-Cache
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Request-URI
X-Returned-From
X-Distributor
X-Returned-From-BeforeDispatch
X-Server-Time
X-A-Wwc
Origin
On-Server
Thinkindot-CacheControl
Proxy-Connection
Ajk
Request-Time
Content-Disposition
Fastly-Backend-Name
Is-Eu
X-Via-NSCOPI
IsBot
Lfy
Magicmarker
Adler-Geo
Platform
Server-Host
SD-X-WS
Mn-Server-Ip
X-Via-CDN
X-HS-Cache-Config
X-Sucuri-Cache
Warning
X-LAGOON
GW-Server
HA-Ipaddr
X-Key
X-Dc
X-Croise-Owner
X-ShardId
X-SERVER
Ha-Gx-Prefs
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Shopify-Stage
Fastly-SSL
X-Device-Os
X-ShopId
X-No-Session
X-Secret
Backend
Cache-Cookie-Set-From
X-Response-By
AKAMAI
X-Generation-Time
X-Hash
X-GeoIP-Country-Code
X-Gannett-Site-Version
X-Cluster-Node
X-Instart-Isnd
X-Qloud-Router
X-Eu-Site
Cache-Cookie-Set-Lfrom
X-Platform
Cache-Cookie-Set-Idcheck
X-Fstrz
X-Epic-Correlation-Id
X-UnsetCookies
Pagetype
X-Core-Value
Pramga
X-Cache-ASPX
X-Clientip
Who
X-C
X-Alternate-Cache-Key
Release
Server-Surrogate-Control
SS
Server-Int
Server-Cache-Control
RNT-Machine
RNT-Time
Fastly-Soc-X-Request-Id
X-Backend-State
Heartbleed
X-CGP
Countrycode
X-Core-Mission
CDCHOST
X-Varnish-Authentication
Kp-EeAlive
REQUESTUUID
X-Debug-Cache-Store
X-Page-Type
X-Debug-Cache-Fetch
X-Up
X-Debug-Cache-Expiry
X-MSEdge-Flight
X-MSEdge-Features
X-F5-Cache
X-Developers
X-Varnish-Url
Server-ID
Version
X-Amz-Meta-Surrogate-Control
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-Pjax-Url
Apple-News-Services-Handled
X-Servername
PFcat
NGX
X-Sedo-Request-Id
X-Cache-Miss-From
X-TrackingId
Apple-News-Services-Request-Url
X-Be
X-EIG-Tracking-Id
X-Refresh
X-Ratelimit-Remaining
RequestId
X-CDN-Forward
X-Store
X-Newrelic-App-Data
Esi-Enabled
X-Cache-CFC
X-NC
MIME-Version
MI-Cache-Age
X-Layer
MI-API
MI-Cache
SID
X-MI-In-Market
X-RCS-CacheZone
X-URL
X-B3-SpanId
X-Oss-Server-Time
X-IPS-LoggedIn
X-From-Cache
Time
X-Oss-Storage-Class
X-SN
X-Owner
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
Odigeo-Trace-Id
HA-Host
HA-Georegion
HA-Geolat
HA-Geolon
HA-Cloudapp
HA-Geocity
HA-Urlpath
X-RequestId
PICS-Label
HA-Geocountry
HA-Servedtime
X-Mshield-Cache-Status
X-Mrs-Age
X-Mrs-Cache
X-Mrs-Cache-Hits
X-Real-Ip
Cdn
X-Geo
X-Unique-Id-Primal
X-Ratelimit-Limit
Cteonnt-Length
X-Servedbyhost
X-Hyper-Cache
X-FPC
Mime-Version
FastCGI-Cache
X-CMS-Context
HTTPS
Backend-Name
CF-IPCountry
X-Webkit-Csp
X-CSRF-TOKEN
X-Webkit-CSP
Cdn-Request-Time
X-Edge-Server
Cdn-Host
Processtime
X-Req
X-Varnish-Ttl
X-CLOUD-TRACE-CONTEXT
X-Instart-Info
X-Wa
CDN
Memory
X-WebServer
X-Phone
X-B3-Spanid
Cf-Ipcountry
Hostname
X-DC
Ohc-Response-Time
X-Request-Start
X-WR-MODIFICATION
X-Atg-Version
XServer
GeoIP-Country-Code
X-Amzn-Remapped-Date
X-Load-Cache
X-Pf-Uncompressing
X-Newrelic-Synthetics
X-Release
X-HS-Combine-CSS
X-Amzn-Remapped-Connection
X-Mobile-URL
X-Aicache-OS
ProcessTime
Cross-Origin-Window-Policy
GeoIP-Latitude
X-VServer
X-NodeID
X-GZip
X-Lb-Id
X-HTML-Minification-Powered-By
X-Served-From
X-WA
X-Fastly-Country-Code
X-Server-W
X-Skip-Cache
X-Varnish-Beresp-TTL
Rt-Proxy-Cache
X-ND-Cache
X-PF-Uncompressing
Accept-Ch-Lifetime
T-Server
X-FORWARDED-FOR
X-GoCache-CacheStatus
URI
X-Unique-Id
Ohc-Cache-HIT
X-Oracle-Dms-Ecid
X-Nananana
X-Tb-Optimization-Total-Bytes-Saved
X-VC-Cache
X-Sn-Servicetimems
X-Cms-Context
V-Age
X-COUNTRY
X-MServer
X-Cdn-Origin
X-LB-ID
X-CSRF-Token
X-ServedByHost
X-APP
Pics-Label
DataCenter
N-Cache
X-Datadome
Uber-Trace-Id
X-Gateway-Cache-Key
X-Gateway-Skip-Cache
X-Gateway-Cache-Status
Proxy-Firewall
X-UCC
X-Worker
X-SRV
X-UPSTREAM-Address
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-LiteSpeed-Cache-Control
A
X-Fastly-Cache-Hits
Get-Access-Time
Is-Session-Tracking
X-P-T
Amp-Access-Control-Allow-Source-Origin
X-SERVER-NAME
ServerName
X-NGINX-Cache
X-Processor
X-HS-Status
X-Requestid
X-Check-Cacheable
X-CACHE-AGE
X-GZIP
X-RCS-Backend
X-BBXSRF
X-Hp-Webp
Geoip-Latitude
X-BE
X-Cache-HT
X-ID
X-HostName
Dnion-Transfer-Encoding
X-Optimization
X-Backend-TTL
X-Vg-Webcache
X-PJAX-URL
X-Org
X-Port
X-Varnish-URL
WZWS-RAY
X-Fe
X-GDPR
X-Csrf-Token
X-StackifyID
Cneonction
Requestid
GeoIp-Country-Code
X-PAGE-TYPE
Serverid
X-NWS-UUID-VERIFY
Host-ID
X-Git-Hash
Cache-Provider
X-VCT
X-Amzn-Remapped-Content-Length
X-Geo-Header
Server-Id
X-Via-SSL
WP-Super-Cache
X-Dw-Trace-Id
RequestUuid
X-ServerName
X-Via-Edge
X-LiteSpeed-Tag
225prxHost
X-RAMCache
189phosttRef
219prxHost
188prxHost
DSUID
X-Fastly-Backend-Reqs
X-GeoIP-City
286prxHost
178proxuri
355prline
X-Planisys-CDN-Cache
Pragrma
X-Instance-Name
X-CS
X-Planisys-CDN-Rules
X-Request-Url
X-Gdpr
352pxline
X-Planisys-CDN-TTL
409pxxline
Xxline
Correlation-Id