Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
ETag
Link
CF-RAY
X-XSS-Protection
Expect-CT
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
CF-Cache-Status
X-Timer
X-Request-Id
X-FRAME-OPTIONS
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Xss-Protection
X-AspNet-Version
X-Download-Options
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
Alt-Svc
X-Check
X-Cacheable
X-Generator
Content-Security-Policy-Report-Only
X-Cache-Status
CF-Ray
X-Request-ID
X-AspNetMvc-Version
X-Permitted-Cross-Domain-Policies
X-DNS-Prefetch-Control
X-Template
X-Language
X-Iinfo
Status
Content-Encoding
Timing-Allow-Origin
X-Buckets
X-Content-Security-Policy
Upgrade
X-CDN
Xkey
X-Turbo-Charged-By
X-Kinja-Server-Push
Keep-Alive
Access-Control-Expose-Headers
P3p
X-Backend
X-Pass-Why
X-Cache-Group
X-AH-Environment
X-Age
Access-Control-Max-Age
X-Drupal-Dynamic-Cache
X-Ua-Compatible
X-Pingback
X-Server
X-Proxy-Cache
X-Via
Grace
X-Amz-Id-2
X-Amz-Request-Id
X-Hacker
WPE-Backend
X-Robots-Tag
X-Server-Powered-By
X-Nginx-Cache-Status
X-Varnish-Cache
X-Page-Speed
X-UA-Device
EagleId
Request-Context
X-Envoy-Upstream-Service-Time
Cf-Railgun
X-Amz-Version-Id
X-LiteSpeed-Cache
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Swift-SaveTime
X-Swift-CacheTime
X-Device
X-OneAgent-JS-Injection
X-WebKit-CSP
Allow
Ali-Swift-Global-Savetime
Server-Timing
X-Type
X-CST
X-Ac
X-Node
X-Rq
X-Host
Feature-Policy
Content-Location
X-Server-Id
X-Response-Time
X-Cnection
Report-To
X-Backend-Server
X-Iejgwucgyu
X-Application-Context
Surrogate-Control
EagleEye-TraceId
X-Cloud-Trace-Context
X-ORACLE-DMS-ECID
X-Url
X-Readtime
X-Origin-Cache
X-Rack-Cache
Request-Id
X-Country
X-FTR-Request-ID
X-Cache-Lookup
X-Clacks-Overhead
X-Country-Code
Rating
NEL
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Upstream-Env
X-Instart-Request-ID
Pinterest-Generated-By
X-Dns-Prefetch-Control
X-Ruxit-JS-Agent
X-Mod-Pagespeed
X-Vhost
X-DynaTrace
X-Px
X-Origin-Upstream-Status
X-DataDome
Edge-Control
X-Goog-Hash
X-Server-Name
Verso
X-ESI
Accept-CH
X-Dispatcher
X-HW
Charset
X-GitHub-Request-Id
X-VARITI-CCR
PB-PID
Arc-Version
X-Mobile-Rewrite
PB-RID
MS-Author-Via
X-MS-InvokeApp
X-Cached
X-DataStream-Cache-Status
X-Kinja
X-Kinja-Server
X-Use-Magma
X-GoogleNews-Bot
X-Kinja-Revision
X-Kinja-Build
X-Exp-Id
X-Exp-Variant
X-Cdn-Fetch
X-Version
AR-ATIME
AR-PoweredBy
AR-CACHE
X-ORACLE-DMS-RID
X-Powered-By-Plesk
X-Recruiting
Content-MD5
Public-Key-Pins
X-D2id
Service-Worker-Allowed
X-PC
X-TtlSet
Accept-CH-Lifetime
X-Vname
X-Navigation-Version
X-Abt-Application-Version
AR-Request-ID
X-TTL
RTSS
Ar-Sid
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Server-ID
X-Ser
X-Trace
X-Forwarded-Proto
SPRequestGuid
X-Varnish-TTL
X-Client-IP
X-Vcap-Request-Id
X-DynaTrace-JS-Agent
X-Amz-Server-Side-Encryption
X-SharePointHealthScore
X-FTR-Realm
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-FTR-Balancer
X-FTR-Backend-Server
X-Goog-Metageneration
X-FTR-Backend
X-Country-Code-Real
X-FTR-DC
X-FTR-Cache-Status
X-Amz-Rid
X-Goog-Generation
X-Fastly-Request-ID
X-Oracle-Dms-Rid
X-FTR-Expires
S
Arr-Disable-Session-Affinity
X-Amz-Meta-S3cmd-Attrs
Nginx-Cache
X-VCache
X-Debug
X-Shield-Request-Id
X-XRDS-Location
TCN
X-Dw-Request-Base-Id
X-Upstream-Proxy
Pinterest-Version
X-Pinterest-Rid
X-Hits
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
SPRequestDuration
SPIisLatency
X-Id
Front-End-Https
X-Akam-SW-Version
DynaTrace
X-SERVER
Access-Control-Request-Method
X-Goog-Storage-Class
X-FTR-Cache-Host
X-Ttl
X-T
X-B3-TraceId
X-Powered-CMS
X-Aspnet-Version
Realpath
X-NF-Request-ID
X-Acc-Meta-Resource-Type
Paypal-Debug-Id
Tracecode
X-Amzn-Trace-Id
X-MSEdge-Ref
X-Varnish-Age
X-Forwarded-For
X-N
X-Content-Type
Fastcgi-Cache
Alternate-Protocol
X-Mrf-Section-Lastmod
Mrf-Cache-Status
MRF-Tech
X-Mrf-Item-Lastmod
X-B3-TraceId-Primal
X-RateLimit-Remaining
X-Upstream
X-Accel-Buffering
X-Frontend
X-Logged-In
X-PressLabs-Stats
Fusion-Content-Id
Fusion-Component-Id
Fusion-Template-Id
X-Content-Digest
X-HS-Content-Id
Fusion-Content-Source
Fusion-Source
X-HS-Hub-Id
Display
X-Sol
X-Middleton-Display
X-Litespeed-Cache
Response
X-Middleton-Response
X-Hostname
AMP-Access-Control-Allow-Source-Origin
X-Srv
X-Kinsta-Cache
X-Fastcgi-Cache
X-Cache-Key
Server-Name
X-Pad
X-Accel-Expires
MicrosoftSharePointTeamServices
X-Content-Options
X-User-Agent
X-B3-Traceid
Refresh
X-DIS-Request-ID
X-Analytics
Backend-Timing
Host
X-Correlation-Id
X-Revision
X-Rid
X-LB-Cache
X-IPLB-Instance
X-Debug-Info
X-Grace
X-Cdn
X-Activity-Id
X-Az
X-Amz-Apigw-Id
X-AppVersion
X-Amzn-RequestId
FilterID
X-B
Accept-Charset
X-CF-Powered-By
X-Cache-Hit
X-DataStream-MidMile-RTT
X-DataStream-Origin-MEX-Latency
Powered-By-ChinaCache
X-B3-Sampled
X-FastCGI-Cache
X-Cache-2
Surrogate-Key
ServerID
X-Page-Id
X-Whom
Server-Info
X-PHP-Backend
X-Webkit-CSP
X-Varnish-Backend
TP-L2-Cache
TP-Cache
X-Ruxit-Js-Agent
X-Content-Security-Policy-Report-Only
X-Amz-Replication-Status
VIX-Pulpo-Upstream-Status
X-F-Cache
VIX-Pulpo-Node
Host-Header
X-TT
MS-CV
Source
X-Akamai-Edgescape
X-Request-Received
X-Request-Processing-Time
X-Origin-Server
X-Framework
X-Cluster
X-App-Environment
X-Tumblr-User
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-RateLimit-Limit
X-Cache-Action
X-UA-Device-Type
X-FW-Hash
X-Content-Powered-By
X-FW-Serve
X-FW-Static
X-Mobile
X-Platform-Server
X-FW-Type
X-Instance
X-FW-Server
X-Handled-By
X-Varnish-Grace
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Drupal-Cache-Tags
X-Request-Guid
Cache-Status
Access-Control-Allow-Method
X-Cached-By
X-Geo-Country
X-Zen-Fury
X-SS-Set-Cookie
X-Magnolia-Registration
X-Wix-Server-Artifact-Id
X-FB-Debug
X-Shard
X-Ezoic-Cdn
X-ATG-Version
X-GUploader-UploadID
X-Cache-TTL
Edge-Cache-Tag
X-Forwarded-Host
From-Origin
X-App-Server
CACHE
DC
X-Varnish-Server
X-Cache-Age
PageSpeed
Cleartype
X-Node-Name
X-Varnish-Hostname
Cache-Tags
X-AOL-HN
X-Cache-Control
X-BCube-Filmed-By
Payment
X-Region
X-Generated-By
X-Seen-By
Filters
X-RequestSource
X-Response-Served-From
X-Signature
X-B-Cache
X-WebKit-CSP-Report-Only
X-GeoIP
X-TX-ID
Healthy
X-Adobe-Content
X-Adobe-Loc
Country
X-UUID
X-TT-TIMESTAMP
Cache-Tv-Group
X-Redis-Cache
X-RTag
X-VG-WebCache
Server-Node
GEO-INFO
Ms-Operation-Id
NGB
X-FW-Dynamic
X-Tumblr-Pixel-2
Webserver
X-Tumblr-Pixel-1
Upgrade-Insecure-Requests
X-Via-JSL
ServedBy
X-Jobs
Retry-After
X-Drupal-Cache-Contexts
Actual-Object-TTL
X-Storage
X-Content-Age
X-Cacheable-TTL
Liferay-Portal
X-XRDS-LOCATION
X-Locale
X-Varnish-Hits
X-Cache-Rule
X-Contextid
X-Rendered-As
X-Oneagent-Js-Injection
HitType
X-Varnish-IP
X-Cache-TTL-Remaining
Fastly-Restarts
Frame-Options
X-Guploader-Uploadid
X-Wix-Request-Id
ViewerVersion
Powered
S-Cnection
X-WA-Info
Viewport
X-Real-IP
Content-Script-Type
Content-Style-Type
X-BACKEND-TTL
X-Cache-Server
X-Yottaa-Metrics
X-NewRelic-App-Data
X-Yottaa-Optimizations
Datacenter
X-TA-CDN-Provider
X-Upgrade-Enabled
X-Esi
X-Cache-Config
NtCoent-Length
X-Mode
X-RemovedCookies
X-ProcessESI
Eomportal-Instance
Xserver
X-Varnish-Cache-Hits
X-Endurance-Cache-Level
X-Time
X-Akamai-Transformed
X-Cache-Var
X-Detected-As
X-Cache-Var-Map
Machine
X-RN-RSRV
X-Routing-Service
X-Zipkin-Id
Cache-Key
Load-Balancing
X-Proxied
X-Proto
X-Hl-Ver
X-ES-SERVER
X-Is-Bot
Meta-Geo
X-Path-Route
X-Device-Type
Cache-Hits
X-S
X-Proxy
X-Backend-Name
X-AWS-Id
X-Origin-Host
L5d-Success-Class
Mail-Subject
X-Access
X-FC-Vary-Parameters
X-Origin-Hint
Access-Control-Request-Headers
X-Environment-Context
X-FW-Version
X-Format
X-Hosted-By
TWC-Locale-Group
Webcakes-Region
X-L-Path
X-Cache-Enabled
X-LJ-Flow-ID
X-Section
X-VWS-Id
X-Status
Property-Id
Webcakes-App-Name
Vix-Hermes-Req-Id
We-Hiring
Webcakes-App-Version
OT-Force-Account-Verify
X-Viewer-Country
TWC-Device-Class
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Privacy
TWC-Connection-Speed
X-VG-TLSProxy
X-EIG-Tracking-Id
S-Rt
X-Birta-Served
X-Debug-Cache
Azure-SlotName
Origin-Edge-Control
Origin-Cache-Control
X-GRACE
Now
X-Akamai-Request-ID
DB-Nickname
Azure-RegionName
Azure-SiteName
Azure-Version
X-Birta-Cache-Post
Azure-InstanceId
X-Cache-NE
X-Via-Fastly
X-Web-Node
X-Tb
X-Origin-Response-Time
X-TNCMS
X-ServerID
X-Time-Microsecs
X-Loop
Decoy-Debug-Key
X-Labrador-Cache-Channel
Mn-Server-Ip
X-From
Decoy-Debug-TTL
X-IP
Decoy-Debug-Status
X-Via-CDN
X-Timing-Wait
X-Xfnlog-Site
X-Varnish-Cacheable
X-Trace-Id
Selected-FE
X-ProxyCache-Status
X-NCache
Served-By
X-JoinUs
X-BYPASS-REASON
X-CCM
X-OCL
X-ProxyCache-Key
X-Human
X-PCL
X-Proxy-Build
Cache-Tag
X-Tumblr-Pixel-3
X-Internal-Host
X-Www-Served-By
X-Grey
X-Site-Version
X-MP-GENERATED-AT
X-Cache-Category-Id
X-Generated
User-Agent
Uber-Trace-Id
NGX
X-FB-TRIP-ID
X-Cache-Operation
AsisCache
X-CDN-Cache
X-Dynatrace-Js-Agent
X-EdgeConnect-Cache-Status
X-Rocket-Nginx-Bypass
X-Vgn-Hpd-Reason
LB
X-Newrelic-App-Data
X-VC-Cache
X-Rule
X-NWS-LOG-UUID
X-R9-Blue-Green-Version
X-UA
X-Cluster-Node
Rt-Fastcgi-Cache
X-Sucuri-ID
X-App-Name
X-RCS-CacheZone
Nel
X-Cache-Remote
Hostname
X-ApacheServer
X-PERF
X-UnsetCookies
Release
Pagespeed
X-Agile-Id
X-Agile-Age
X-Agile
X-Varnish-Ttl
X-TIME
X-Datadome
X-Source
X-Ua
Cache-Name
X-Nginx-Cache
X-B3-Spanid
X-App-Version
X-Edge-Location
X-APP-VERSION
X-CACHE-KEY
X-Edge-IP
X-Pubstack
X-Request-Time
X-Protected-By
X-Cdn-Forward
Fastcgi-Useragent
Warning
X-Ocache
X-OVcl-Cache
X-OVcl
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
Section-Io-Cache
X-ElasticPress-Search
Ec-Rule-Version
X-Debug-Cache-Store
X-ARC
X-Secret
X-ScT
X-Application
X-B-Cookie
X-Debug-Log
X-Up
Thinkindot-CacheControl-Type
X-Irp-Debug
Server-Cache-Control
X-Cache-ASPX
X-Region-Sid
Fly-Request-Id
Fly-Cache
X-Twitter-Response-Tags
X-Server-Group
X-BB-ID
X-Debug-Cookies
Thinkindot-Control
X-Rewrite-Enabled
X-A-Ccd
X-A
X-A-Dam
X-A-Dcw
Ajk
Cache-Prefix
Www
Thinkindot-CacheControl
X-IN-APIGATEWAY
BehaviorPad-Version
X-Platform
Arc-Country
X-A-Dgt
X-A-Wwc
X-Origin-TTL
Server-Surrogate-Control
X-IN-WAF
UCS
X-Rojux
X-Hp-Webp
X-Trv-Group
X-Origin
X-Accel-Expires-Debug
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Request-UUID
X-Aed
X-S-Cookie
Origin
Request-EU
Request-Time
X-VCT
X-External-Request-Id
X-SRCache-Key
X-Connection-Hash
Meta-Geo-Continent
X-Nginx-Cache-Key
X-Developer
X-G
X-Cache-Expires
X-CF-Lambda-Version
X-Date
X-Core-Value
X-VG-WebServer
Xc-Version
Magicmarker
Rendered-Blocks
X-D
X-Developers
X-Logtrace-Id
X-Matched-Rule
On-Server
X-Mobile-URL
MD5-Digest
X-DPWN-IS-SECURE
Request-Country
X-Gannett-Site-Version
X-CF-Lambda-Fn
X-Origin-CC
X-Debug-Cache-Fetch
X-Transaction
X-NU-AKA-ACS-Version
X-Generated-In
X-Thinkindot-L3
Node
X-Destination
X-Hit
X-Cache-Grace
N-Cache
X-NX-Host
X-NodeID
X-Debug-Cache-Expiry
X-Varnish-Authentication
X-Var-Ttl
SRV
X-Instart-Isnd
Cross-Origin-Window-Policy
X-Processor
X-PAYTM-SRV-ID
X-Cache-Backend
X-GZip
X-Real-Ip
RNT-Time
Proxy-Connection
Pramga
X-Policy
Pagetype
Server-Int
X-Info
X-Proxy-Cache-Status
RNT-Machine
Powered-By
Server-Host
X-Crawler
X-Distil-CS
X-Distributor
X-Dispatcher-Server
X-Device-Os
X-Cms-Context
X-CUA
X-Hnp-Log
X-Epic-Correlation-Id
X-Hash
X-Geo-Header
X-Gen-Mode
X-Page-Type
X-Eu-Site
X-F5-Cache
X-CGP
X-Cache-Miss-From
X-Amzn-Remapped-Date
X-PHP-Host
X-Amzn-Remapped-Connection
X-Amz-Meta-Cache-Control
User-Cache-Control
Web-Mar-Node
X-BBXSRF
X-Block-Status
X-Cache-Id
X-Cache-Info
X-Cache-Host
X-Cache-FS-Status
X-C
X-Cache-Debug
True-Client-Country-4JS
X-ServiceProvider
Apple-News-Services-Request-Url
X-Li-Pop
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
AKAMAI
Apple-News-Services-Handled
X-Skip-Cache
Backend
X-No-Session
X-LAGOON
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-From
X-SN
X-Request-URI
X-Sedo-Request-Id
X-Varnish-Url
X-Proxy-Upstream
X-LI-UUID
X-TT-LOGID
X-Webstats-RespID
X-Wikidot-Backend
X-Sf
X-Sucuri-Cache
X-Swa-Ws
X-Location
X-Wikidot-Static-Cache
X-Key
CDCHOST
X-RateLimit-Remaining-Second
X-Rebelmouse-Cache-Control
X-RateLimit-Limit-Second
X-Origin-Date
Content-Disposition
X-Ah-Environment
IsBot
Memcached
X-SIPLIST1
X-Origin-Expires
Lfy
Kp-EeAlive
Heartbleed
HA-Ipaddr
Fastly-Soc-X-Request-Id
X-Node-Id
Fastly-SIE
Fastly-Backend-Name
X-Qloud-Router
Fastly-SWR
X-Li-Fabric
X-Rebelmouse-Surrogate-Control
Ha-Gx-Prefs
X-LI-Proto
X-Reboot
Country-Code
X-Refresh
X-FireWall-Port
X-Thanos
X-Cdn-Srv
X-TrackingId
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Core-Mission
X-Fastly-Cache
X-Gateway-Cache-Key
X-Fetched-On
X-Gateway-Cache-Status
X-Gateway-Skip-Cache
X-GeoIP-City
X-Generated-On
X-MSEdge-Flight
X-MSEdge-Features
X-Micro-Cache
X-Variation
X-Servername
X-Via-Edge
X-Via-SSL
X-User
X-Server-IP
X-Backend-Host
X-Auto-Login
X-Backend-State
X-Backend-Url
SD-X-WS
X-Planisys-CDN-TTL
X-S-Maxage
X-Planisys-CDN-Cache
Adler-Geo
X-Alternate-Cache-Key
X-Planisys-CDN-Rules
X-Amzn-Remapped-Content-Length
X-Bip
Fastly-SSL
X-GeoIP-Country-Code
X-ShardId
X-Cache-Bucket
Pragrma
X-ShopId
X-Level-Front-Cache
Platform
Is-Eu
HTTPS
X-Shopify-Stage
X-Passed-To-DLL
X-Passed-To
X-Actual-URL
X-WPE-Loopback-Upstream-Addr
X-RateLimit-Reset
X-Owner
X-Passed-To-BeforeDispatch
X-Returned-From-PostProcessResponse
X-Stale
X-Server-By
X-Returned-From
X-Server-Time
X-Svr
X-Original-Request
X-Passed-To-PostProcessResponse
X-Varnish-Beresp-Ttl
X-Returned-From-BeforeDispatch
X-Returned-From-DLL
X-Unique-ID
X-Croise-Owner
Server-ID
X-HS-Cache-Config
X-VServer
X-Dc
Host-ID
X-Microcachable
X-Nc
Cteonnt-Length
Cdn-Request-Time
Cdn-Host
X-Edge-Server
X-NC
REQUESTUUID
X-Org
X-Parent-Response-Time
Viewtype
X-CDN-Forward
VivaBuild
X-Pjax-Url
X-Aicache-OS
FNAC-ModuleRouting
ServerName
X-Load-Cache
DSUID
X-FPC
Gh-Request-Id
X-V
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
X-Oss-Server-Time
SID
X-Oss-Object-Type
X-Oss-Storage-Class
X-Ua-Device
Mime-Version
X-CSRF-TOKEN
MIME-Version
X-Apm-Svc-Key
X-Sn-Servicetimems
X-Cdn-Origin
X-Apm-Inst-Hash
V-Age
X-Gdpr
X-Req
X-Apm-App-Name
Time
X-From-Cache
ProcessTime
Memory
X-ND-Cache
X-Geo
X-Exp-Se
Odigeo-Trace-Id
X-Servedbyhost
PICS-Label
Rt-Proxy-Cache
Cache
X-Served-From
X-HTML-Minification-Powered-By
X-Wa
X-Tb-Optimization-Total-Bytes-Saved
Public-Key-Pins-Report-Only
CF-IPCountry
X-Fstrz
X-DC
X-Optimization
AR-SID
X-GEO
X-Cache-HT
X-Lb-Id
X-Response-By
Resin-Trace
X-Newrelic-Synthetics
X-B3-Parentspanid
X-Git-Hash
Cdn
Cf-Ipcountry
Fastcgi-X-Cache-Version
X-Varnish-Beresp-TTL
X-Webkit-Csp
HostName
Wxu-Next-Commit
GMS-Ver
Wxu-Next-Hostname
Wxu-Next-Region
X-Atg-Version
Proxy-Firewall
XServer
X-WR-MODIFICATION
Processtime
X-APP
X-Release
X-Amz-Meta-Surrogate-Control
X-Fastly-Backend-Reqs
WZWS-RAY
X-Ratelimit-Remaining
X-TH-Server
X-WebServer
X-We-Are-Hiring
X-Ratelimit-Limit
X-UE-Client-Country
X-Daa-Tunnel
X-LB-ID
X-Clientip
Mobile-Detection-Method
Countrycode
GW-Server
X-CACHE-AGE
X-CLOUD-TRACE-CONTEXT
X-Phone
X-Vcl-Version
X-Hyper-Cache
SS
CF-Cached-On
X-URL
Ohc-File-Size
X-Vcache
X-HS-Status
X-Nananana
X-Instart-Info
X-NGINX-Cache
X-Fastly-Country-Code
X-Backend-TTL
X-WA
X-Check-Cacheable
Backend-Name
X-PF-Uncompressing
Pics-Label
X-ID
FSS-Proxy
X-HS-Combine-CSS
FSS-Cache
X-Ratelimit-Reset
Lb
X-Host-Name
225prxHost
219prxHost
189phosttRef
286prxHost
188prxHost
352pxline
Xxline
409pxxline
355prline
X-CSRF-Token
178proxuri
X-ServedByHost
X-Worker
DataCenter
Amp-Access-Control-Allow-Source-Origin
X-Upstream-HT
X-Upstream-CT
X-Be
X-Zone
X-B3-SpanId
X-Server-W
GeoIp-Country-Code
URI
Geoip-Latitude
X-IPS-LoggedIn
SN
X-SERVER-NAME
X-VHOST
Ohc-Cache-HIT
X-SRV
X-GZIP
X-Dynatrace
X-Request-Start
X-BE
X-Fpc
X-Render-Time
X-UCC
Geoip-City
X-Gen-Id
Serverid
X-Varnish-Action
X-VCL-Version
Who
X-LiteSpeed-Cache-Control
Esi-Enabled
X-CS
X-UPSTREAM-Address
X-NGENIX-Cache
Version
X-Unique-Id
X-Html-Edge-Cache
X-Cache-URL
X-PJAX-URL
WP-Super-Cache
CDN
FastCGI-Cache
X-FORWARDED-FOR
Dynatrace
X-HostName
X-Pf-Uncompressing
X-Contensis-Viewer-Groups
X-Fastly-Cache-Hits
GeoIP-Latitude
GeoIP-Country-Code
RequestUuid
GeoIP-City
X-GDPR
X-AssetVersion
Cneonction
X-Cdn-Cache
X-Cache-Ttl
X-Request-Url
RequestId
X-NWS-UUID-VERIFY
X-ServerName
X-Via-Ucdn
X-Store
Accept-Ch
X-Via-NSCOPI
Server-Id
X-Servedby
A
X-LiteSpeed-Tag
X-ZONE
X-Pc-Hit
X-Akamai-SSL-Client-Sid
X-Pc-Appver
X-Pc-Key
X-Generation-Time
X-HTML-Edge-Cache
Ohc-Response-Time
Frontcache
X-RequestId
X-Reqid
X-EC-Lua
Get-Access-Time
X-Dw-Trace-Id
X-Cdn-Request-ID
NnCoection
X-Serial
X-Port
Is-Session-Tracking
IBM-Web2-Location