Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
CF-RAY
ETag
Link
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Request-Id
X-Xss-Protection
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Adblock-Key
X-Check
Alt-Svc
X-Cacheable
X-Generator
Content-Security-Policy-Report-Only
X-Cache-Status
X-AspNetMvc-Version
X-DNS-Prefetch-Control
X-Permitted-Cross-Domain-Policies
X-Iinfo
X-Template
X-Language
Status
Timing-Allow-Origin
X-Buckets
X-Content-Security-Policy
Content-Encoding
X-Kinja-Server-Push
Xkey
X-Turbo-Charged-By
Upgrade
X-CDN
X-Type
Keep-Alive
Access-Control-Expose-Headers
WPE-Backend
X-Pass-Why
X-AH-Environment
Access-Control-Max-Age
X-Backend
X-Age
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Server
X-Request-ID
X-Proxy-Cache
X-Via
Grace
X-Pingback
X-Nginx-Cache-Status
X-Server-Powered-By
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Hacker
X-Varnish-Cache
X-UA-Device
X-Page-Speed
EagleId
Request-Context
X-LiteSpeed-Cache
Cf-Railgun
X-Envoy-Upstream-Service-Time
X-Ua-Compatible
X-CST
X-Swift-SaveTime
X-Swift-CacheTime
X-Server-Id
Ali-Swift-Global-Savetime
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
X-WebKit-CSP
X-Amz-Version-Id
Server-Timing
X-Ac
X-Node
Allow
X-OneAgent-JS-Injection
Feature-Policy
X-Response-Time
X-Iejgwucgyu
X-Cnection
X-Rq
Content-Location
X-Cache-Lookup
X-Backend-Server
Report-To
EagleEye-TraceId
Surrogate-Control
X-Readtime
X-Host
X-Application-Context
Request-Id
P3p
X-Url
X-ORACLE-DMS-ECID
X-Rack-Cache
X-Cdn
X-Origin-Cache
X-Clacks-Overhead
NEL
X-FTR-Request-ID
Rating
X-Country
X-Country-Code
X-Cloud-Trace-Context
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-DataDome
X-Ruxit-JS-Agent
X-Instart-Request-ID
X-Px
X-Vhost
X-Mod-Pagespeed
Charset
X-MS-InvokeApp
X-VARITI-CCR
Pinterest-Generated-By
Accept-CH
Edge-Control
X-Goog-Hash
X-GitHub-Request-Id
Verso
Arc-Version
PB-PID
PB-RID
X-Mobile-Rewrite
X-PC
X-TtlSet
X-Vname
X-TTL
X-Server-Name
X-Version
X-DynaTrace
X-Dns-Prefetch-Control
X-Upstream-Env
X-Powered-By-Plesk
X-B3-TraceId
X-ESI
X-D2id
X-Cdn-Fetch
X-Kinja-Build
X-Kinja
X-GoogleNews-Bot
X-Exp-Variant
X-Use-Magma
X-Exp-Id
X-Kinja-Server
X-Kinja-Revision
X-Cached
X-Varnish-TTL
X-Origin-Upstream-Status
X-Dispatcher
SPRequestGuid
X-ORACLE-DMS-RID
X-Powered-CMS
X-Abt-Application-Version
X-Recruiting
X-SharePointHealthScore
MS-Author-Via
X-T
Accept-CH-Lifetime
RTSS
X-Navigation-Version
X-Shield-Request-Id
Public-Key-Pins
Content-MD5
X-Trace
AR-CACHE
AR-ATIME
AR-PoweredBy
X-DynaTrace-JS-Agent
X-Client-IP
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Amz-Rid
X-Fastly-Request-ID
X-Wix-Server-Artifact-Id
X-Forwarded-Proto
X-Accel-Buffering
Arr-Disable-Session-Affinity
X-HW
SPIisLatency
SPRequestDuration
Realpath
X-DIS-Request-ID
X-Oracle-Dms-Rid
X-B
X-Upstream
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Length
Service-Worker-Allowed
X-F-Cache
X-Amz-Meta-S3cmd-Attrs
X-Via-JSL
Pinterest-Version
X-Pinterest-Rid
Paypal-Debug-Id
X-Ser
Front-End-Https
X-FTR-Backend-Server
AR-Request-ID
X-FTR-Realm
X-FTR-Backend
X-FTR-Cache-Status
X-FTR-DC
X-Country-Code-Real
X-FTR-Balancer
X-FTR-Expires
X-Id
X-Dw-Request-Base-Id
X-XRDS-Location
X-Vcap-Request-Id
X-Varnish-Age
X-Debug
X-Acc-Meta-Resource-Type
X-Goog-Storage-Class
X-MSEdge-Ref
X-Kinsta-Cache
Nginx-Cache
X-Hits
X-N
X-NF-Request-ID
X-Ttl
Ar-Sid
X-FTR-Cache-Host
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Logged-In
MRF-Tech
Mrf-Cache-Status
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
X-DataStream-Cache-Status
S
X-Akam-SW-Version
X-NewRelic-App-Data
X-Frontend
X-Server-ID
Alternate-Protocol
X-PressLabs-Stats
X-HS-Content-Id
Tracecode
X-User-Agent
X-HS-Hub-Id
X-Grace
X-Amzn-Trace-Id
X-Forwarded-For
X-CACHE-GROUP
X-FastCGI-Cache
AMP-Access-Control-Allow-Source-Origin
Server-Name
X-Content-Digest
DynaTrace
X-Content-Options
Refresh
X-Pad
Powered-By-ChinaCache
X-Content-Type
TCN
X-Analytics
Backend-Timing
X-Cache-Key
X-Middleton-Display
X-Sol
Display
FilterID
X-CF-Powered-By
Accept-Charset
X-LB-Cache
X-Debug-Info
X-Rid
X-IPLB-Instance
MicrosoftSharePointTeamServices
Access-Control-Request-Method
X-AppVersion
X-Az
X-Zen-Fury
X-Activity-Id
Fastcgi-Cache
Host
X-Page-Id
MS-CV
Response
ServerID
X-Middleton-Response
TP-L2-Cache
TP-Cache
Cache-Status
X-Magnolia-Registration
X-RateLimit-Remaining
X-Cache-Hit
X-Hostname
X-Content-Powered-By
X-Seen-By
X-Fastcgi-Cache
X-TA-CDN-Provider
X-VCache
X-Mobile
X-WA-Info
X-GUploader-UploadID
Surrogate-Key
X-Srv
X-ATG-Version
X-Cached-By
X-B3-Sampled
X-Revision
X-Request-Received
X-Request-Processing-Time
X-Varnish-Backend
X-SS-Set-Cookie
Host-Header
Rt-Fastcgi-Cache
X-Signature
X-Instance
X-Cache-Action
X-Whom
X-B-Cache
X-Platform-Server
VIX-Pulpo-Upstream-Status
X-Cluster
VIX-Pulpo-Node
X-Tumblr-Pixel
X-PHP-Backend
X-Content-Security-Policy-Report-Only
X-Tumblr-Pixel-0
X-Tumblr-User
X-Handled-By
X-Wix-Request-Id
ViewerVersion
X-Request-Guid
X-Cache-Age
X-Drupal-Cache-Tags
Source
Cleartype
Server-Info
X-App-Environment
X-Origin-Server
X-Framework
X-Akamai-Edgescape
X-TT
DC
X-Amz-Apigw-Id
X-Cache-Control
X-Amzn-RequestId
X-Generated-By
X-BCube-Filmed-By
X-Edge-Location
X-Geo-Country
X-Oneagent-Js-Injection
X-App-Server
X-FW-Serve
X-FW-Hash
X-FW-Static
X-FW-Type
X-FW-Server
Fusion-Source
Fusion-Template-Id
X-Varnish-Server
X-Cache-Rule
Server-Node
Fusion-Content-Id
Fusion-Content-Source
Fusion-Component-Id
X-AOL-HN
X-XRDS-LOCATION
X-Ruxit-Js-Agent
X-Real-IP
X-NWS-LOG-UUID
X-Varnish-Hostname
Retry-After
X-Cache-2
Eomportal-Instance
X-Correlation-Id
Payment
X-FB-Debug
X-Amz-Server-Side-Encryption
Webserver
X-Varnish-Grace
Actual-Object-TTL
X-TT-TIMESTAMP
X-Response-Served-From
X-Varnish-Hits
Access-Control-Allow-Method
X-Cacheable-TTL
ServedBy
GEO-INFO
AsisCache
X-Amz-Replication-Status
Filters
NGB
X-UUID
X-Jobs
X-TX-ID
X-Region
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
X-Varnish-IP
X-Drupal-Cache-Contexts
X-WebKit-CSP-Report-Only
X-Adobe-Loc
X-Servedby
X-RTag
X-Cache-Config
X-Adobe-Content
Ms-Operation-Id
X-Contextid
X-RequestSource
Upgrade-Insecure-Requests
Content-Script-Type
X-Rendered-As
Content-Style-Type
Cache-Tv-Group
Healthy
Viewport
X-Locale
X-Accel-Expires
From-Origin
Country
X-Ezoic-Cdn
X-Device-Type
X-WPE-Loopback-Upstream-Addr
X-UA-Device-Type
HitType
X-VG-WebCache
X-Esi
Cache
X-Cache-TTL-Remaining
X-BACKEND-TTL
X-Cache-Server
X-FW-Dynamic
X-Cache-Remote
Fastcgi-Useragent
X-Cache-TTL
Edge-Cache-Tag
X-Cache-Operation
Pagespeed
X-Upstream-Proxy
X-Content-Age
X-APP-VERSION
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Fastly-Restarts
Cache-Tags
X-Hit
X-Redis-Cache
X-Upgrade-Enabled
X-RateLimit-Limit
X-Source
X-Storage
X-S
Datacenter
X-Mode
Served-By
Cache-Tag
X-DataStream-MidMile-RTT
X-DataStream-Origin-MEX-Latency
X-Labrador-Cache-Channel
SRV
X-Akamai-Request-ID
X-Origin-Response-Time
X-NGENIX-Cache
Origin-Edge-Control
X-NCache
X-Detected-As
X-Tb
X-Generated
Meta-Geo
X-Internal-Host
Machine
X-GeoIP
Load-Balancing
X-Is-Bot
X-Cache-Var
X-Path-Route
X-RN-RSRV
X-Time-Microsecs
X-Cache-Var-Map
Origin-Cache-Control
X-JoinUs
X-CACHE-KEY
X-Hosted-By
X-L-Path
X-Loop
X-TNCMS
X-Rule
Cache-Key
Vix-Hermes-Req-Id
X-Agile
X-Cache-Category-Id
X-Environment-Context
X-CDN-Cache
X-Birta-Served
X-Birta-Cache-Post
X-Agile-Age
X-Agile-Id
X-Grey
X-Varnish-Cacheable
X-Status
X-Akamai-Transformed
NtCoent-Length
X-Www-Served-By
X-Pubstack
X-Web-Node
Webcakes-App-Name
X-IP
TWC-Privacy
TWC-Locale-Group
X-OCL
Webcakes-App-Version
Webcakes-Region
X-Origin-Host
X-Origin-Hint
TWC-GeoIP-LatLong
TWC-Device-Class
S-Rt
X-Viewer-Country
Property-Id
X-FC-Vary-Parameters
Cache-Name
X-Human
X-Daa-Tunnel
TWC-Connection-Speed
X-Pc-Appver
TWC-GeoIP-Country
X-Pc-Key
X-Format
X-BYPASS-REASON
X-RemovedCookies
X-Pc-Hit
X-Varnish-Cache-Hits
X-ServerID
X-Via-Fastly
X-Edge-IP
X-Cache-Enabled
X-ProxyCache-Key
X-ProxyCache-Status
X-PCL
X-ApacheServer
X-ProcessESI
Now
X-Proxy
X-PERF
X-CCM
X-Access
X-Backend-Name
X-Hl-Ver
X-VG-TLSProxy
Public-Key-Pins-Report-Only
Fastcgi-X-Cache-Version
X-App-Version
Azure-SlotName
Azure-RegionName
Azure-InstanceId
X-Section
X-Site-Version
Azure-Version
Azure-SiteName
X-MP-GENERATED-AT
DB-Nickname
X-Xfnlog-Site
X-Routing-Service
X-App-Name
X-Proxy-Build
X-Proxied
X-GEO
X-Timing-Wait
Access-Control-Request-Headers
X-Zipkin-Id
Selected-FE
X-Debug-Cache
X-Cache-NE
Xserver
X-Microcachable
X-Origin
X-Original-Request
We-Hiring
Mail-Subject
S-Cnection
Liferay-Portal
X-Guploader-Uploadid
X-EdgeConnect-Cache-Status
X-Sucuri-ID
User-Cache-Control
User-Agent
X-Ocache
X-Protected-By
Cache-Hits
X-FW-Version
X-Nginx-Cache
X-Request-Time
X-ES-SERVER
X-Node-Name
LB
X-Cdn-Forward
X-GRACE
AR-SID
X-UA
X-Yottaa-Optimizations
X-Yottaa-Metrics
PageSpeed
X-Proto
Ohc-File-Size
X-Trace-Id
X-Webstats-RespID
X-Tumblr-Pixel-3
Powered
X-Correlation-ID
X-FB-TRIP-ID
X-Ua
X-Forwarded-Host
X-Origin-CC
X-Endurance-Cache-Level
X-Webkit-Csp
X-Unique-ID
L5d-Success-Class
Section-Io-Cache
X-Time
CACHE
Frame-Options
X-Varnish-Beresp-Status
X-Nc
X-Varnish-Beresp-Grace
X-V
X-Pc-Host
X-Pc-Date
X-OVcl-Cache
X-OVcl
X-Parent-Response-Time
IBM-Web2-Location
X-Pc-Subdomain
X-AWS-Id
OT-Force-Account-Verify
X-Varnish-Beresp-Ttl
X-Origin-TTL
X-VWS-Id
Nel
X-LJ-Flow-ID
X-Cache-Backend
X-ElasticPress-Search
X-R9-Blue-Green-Version
X-Cluster-Node
X-Upstream-CT
X-Upstream-HT
X-Varnish-Ttl
X-Rocket-Nginx-Bypass
X-Amz-Meta-Cache-Control
X-Accel-Expires-Debug
X-Reboot
X-Application
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Aed
Arc-Country
X-IN-WAF
X-NU-AKA-ACS-Version
Powered-By
GMS-Ver
Rendered-Blocks
Fly-Request-Id
X-Origin-Expires
X-Origin-Date
X-Micro-Cache
Node
X-LI-Proto
X-Li-Pop
Memcached
Meta-Geo-Continent
X-LI-UUID
Mobile-Detection-Method
X-Li-Fabric
Fly-Cache
Fastly-SWR
BehaviorPad-Version
Cache-Prefix
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Generated-In
Viewtype
X-PAYTM-SRV-ID
Www
VivaBuild
X-Hnp-Log
Decoy-Debug-Key
X-IN-APIGATEWAY
Fastly-SIE
X-IN-SSL-APIGATEWAY
Resin-Trace
Ec-Rule-Version
Decoy-Debug-Status
Decoy-Debug-TTL
X-PHP-Host
X-External-Request-Id
X-ARC
X-Cache-URL
X-User
X-ServiceProvider
X-Server-Group
X-Date
X-Cache-Info
X-Cache-Host
X-VG-WebServer
X-Fetched-On
X-Cache-Id
X-S-Cookie
X-Cdn-Srv
X-CF-Lambda-Fn
X-Transaction
X-Trv-Group
X-Connection-Hash
X-From
X-ScT
X-S-Maxage
X-CF-Lambda-Version
X-UE-Client-Country
X-Server-By
X-Twitter-Response-Tags
X-TT-LOGID
X-Destination
X-Cache-FS-Status
X-Cache-Bucket
X-Gen-Mode
X-Block-Status
X-Vgn-Hpd-Reason
X-We-Are-Hiring
X-Developer
X-Wikidot-Backend
Xc-Version
X-Wikidot-Static-Cache
X-Rewrite-Enabled
MD5-Digest
X-Request-UUID
X-Region-Sid
X-BB-ID
X-B-Cookie
X-SRCache-Key
X-DPWN-IS-SECURE
X-Rojux
X-Newrelic-App-Data
X-EIG-Tracking-Id
Request-Time
Platform
X-Distributor
X-Fastly-Cache
X-Irp-Debug
Origin
X-Epic-Correlation-Id
X-LAGOON
Proxy-Connection
X-D
X-Core-Mission
X-Level-Front-Cache
X-FireWall-Port
X-Info
X-Distil-CS
X-CUA
True-Client-Country-4JS
X-Cache-Debug
X-Gannett-Site-Version
X-Cache-Expires
X-A-Wwc
X-A-Dgt
X-Actual-URL
X-Alternate-Cache-Key
X-Backend-Host
X-Auto-Login
X-Backend-State
X-Backend-Url
X-C
X-A-Dcw
X-A-Dam
Thinkindot-CacheControl-Type
Thinkindot-Control
Thinkindot-CacheControl
X-GeoIP-Country-Code
SD-X-WS
X-Generated-On
X-G
X-A-Ccd
X-A
Who
Web-Mar-Node
X-Clientip
CDCHOST
Adler-Geo
Ajk
X-Passed-To-BeforeDispatch
X-Passed-To-DLL
X-Var-Ttl
X-Passed-To-PostProcessResponse
X-TIME
Backend
X-Secret
On-Server
X-Thinkindot-L3
X-TrackingId
X-Passed-To
X-Variation
X-Varnish-Action
X-Returned-From-BeforeDispatch
X-Returned-From
X-Node-Id
X-Returned-From-PostProcessResponse
X-Cache-Grace
X-Returned-From-DLL
X-Response-By
X-Request-URI
Magicmarker
X-SERVER
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Server-Cache
Content-Disposition
X-Server-IP
X-Matched-Rule
X-Stale
X-Shopify-Stage
X-ShopId
X-Svr
X-ShardId
X-SIPLIST1
X-Logtrace-Id
Is-Eu
IsBot
X-Sorting-Hat-PodId
X-Location
X-Sorting-Hat-ShopId
Fastly-Soc-X-Request-Id
X-Nginx-Cache-Key
Countrycode
X-Sf
X-Swa-Ws
Fastly-Backend-Name
Country-Code
Warning
X-Sucuri-Cache
X-Croise-Owner
X-Eu-Site
X-Crawler
X-Thanos
X-Core-Value
X-Via-NSCOPI
X-Dispatcher-Server
Fastcgi-X-Cache
X-Debug-Log
X-Debug-Cookies
X-Up
X-UnsetCookies
X-CGP
X-Via-CDN
X-F5-Cache
X-Device-Os
X-Developers
X-Fstrz
X-Proxy-Upstream
X-NX-Host
GW-Server
X-No-Session
Fastly-SSL
RNT-Machine
X-Hash
Server-Host
RNT-Time
Pramga
X-MSEdge-Flight
Mn-Server-Ip
Heartbleed
Lfy
HA-Ipaddr
Pagetype
X-MSEdge-Features
Ha-Gx-Prefs
X-Bip
Server-Int
X-Platform
AKAMAI
Apple-News-Services-Host
X-Policy
X-Proxy-Cache-Status
X-Amz-Meta-Surrogate-Control
X-Qloud-Router
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
X-Generation-Time
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-From
Cache-Cookie-Set-Idcheck
Apple-News-Services-Request-Url
X-HS-Cache-Config
HostName
X-Dc
X-Page-Type
X-Varnish-Url
X-Instart-Isnd
X-Varnish-Authentication
X-Key
Server-Cache-Control
Server-ID
Server-Surrogate-Control
SS
REQUESTUUID
Release
X-Died
NGX
X-Edge-Cache-Key
X-Cache-ASPX
X-Edge-Cache
X-Debug-Cache-Store
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
X-Be
X-B3-Traceid
X-Sedo-Request-Id
X-Server-Time
X-Servername
X-Cache-Miss-From
SID
Kp-EeAlive
X-CDN-Forward
X-Owner
Version
RequestId
X-Pjax-Url
MIME-Version
X-NC
X-Refresh
X-SN
Odigeo-Trace-Id
PFcat
X-URL
X-B3-SpanId
X-From-Cache
X-Oss-Object-Type
X-Oss-Storage-Class
X-Oss-Request-Id
X-Oss-Server-Time
Esi-Enabled
X-FPC
HTTPS
X-Cache-CFC
X-Oss-Hash-Crc64ecma
X-Store
Cteonnt-Length
X-Servedbyhost
Time
Hostname
X-Layer
MI-API
X-MI-In-Market
MI-Cache-Age
X-Edge-Server
PICS-Label
Cdn-Host
Cdn-Request-Time
X-RCS-CacheZone
MI-Cache
FastCGI-Cache
X-RequestId
X-CSRF-TOKEN
X-IPS-LoggedIn
HA-Servedtime
HA-Geocountry
HA-Georegion
HA-Geocity
HA-Urlpath
HA-Cloudapp
Cdn
HA-Host
HA-Geolon
HA-Geolat
Mime-Version
X-Real-Ip
CF-IPCountry
X-Req
X-Webkit-CSP
X-COUNTRY
ProcessTime
X-CLOUD-TRACE-CONTEXT
X-Dynatrace-Js-Agent
X-Load-Cache
X-Mobile-URL
X-Wa
X-Hyper-Cache
X-Amzn-Remapped-Date
Backend-Name
Memory
X-Amzn-Remapped-Connection
CDN
X-DC
X-GZip
X-Ratelimit-Remaining
Processtime
X-VServer
Cross-Origin-Window-Policy
X-CMS-Context
X-Atg-Version
X-NodeID
X-Mrs-Age
X-Unique-Id-Primal
X-Mrs-Cache-Hits
X-Mshield-Cache-Status
X-Mrs-Cache
XServer
X-Geo
Ohc-Response-Time
X-Ratelimit-Limit
Cf-Ipcountry
X-Pf-Uncompressing
X-Instart-Info
X-FORWARDED-FOR
X-WR-MODIFICATION
X-Skip-Cache
X-HTML-Minification-Powered-By
X-Aicache-OS
X-WebServer
X-Phone
X-Lb-Id
X-Newrelic-Synthetics
X-HS-Combine-CSS
X-B3-Spanid
X-Varnish-Beresp-TTL
X-Fastly-Country-Code
GeoIP-Country-Code
X-Request-Start
Ohc-Cache-HIT
X-Release
X-PF-Uncompressing
X-VC-Cache
GeoIP-Latitude
URI
X-Nananana
Uber-Trace-Id
X-Server-W
X-WA
Accept-Ch-Lifetime
T-Server
X-Tb-Optimization-Total-Bytes-Saved
X-Cms-Context
Amp-Access-Control-Allow-Source-Origin
X-SRV
X-Gateway-Cache-Key
X-Gateway-Skip-Cache
X-Oracle-Dms-Ecid
X-Gateway-Cache-Status
N-Cache
X-UCC
X-GoCache-CacheStatus
X-ND-Cache
X-Served-From
X-LB-ID
Pics-Label
Rt-Proxy-Cache
X-MServer
X-Worker
X-CSRF-Token
X-Datadome
X-Processor
X-Unique-Id
X-APP
X-BBXSRF
X-Hp-Webp
X-ServedByHost
A
X-LiteSpeed-Cache-Control
X-SERVER-NAME
DataCenter
X-CACHE-AGE
X-Fastly-Cache-Hits
V-Age
X-Cdn-Origin
X-Sn-Servicetimems
X-UPSTREAM-Address
X-Shard
X-Optimization
X-Cache-HT
X-Requestid
X-GZIP
X-Check-Cacheable
X-SVT-ORM-VERSION
X-HS-Status
Proxy-Firewall
X-SVT-ORM-RULES
X-VCT
X-NGINX-Cache
Get-Access-Time
X-P-T
Geoip-Latitude
Dnion-Transfer-Encoding
Cneonction
Host-ID
X-GeoIP-City
X-ID
X-Vcache
Is-Session-Tracking
X-BE
X-Amzn-Remapped-Content-Length
X-Geo-Header
X-Backend-TTL
X-ServerName
GeoIp-Country-Code
X-Varnish-URL
X-PAGE-TYPE
X-PJAX-URL
Requestid
UCS
ServerName
X-Csrf-Token
X-Port
Serverid
X-NWS-UUID-VERIFY
Request-EU
Cache-Provider
Request-Country
X-Git-Hash
X-RCS-Backend
X-HostName
WP-Super-Cache
Server-Id
RequestUuid
X-Dw-Trace-Id
X-LiteSpeed-Tag
X-GDPR
X-StackifyID
X-Fe
X-Cache-Ttl
X-Vg-Webcache
Inserted-Into-Cache-At
X-Html-Edge-Cache
X-Gen-Id
409pxxline
X-Fastly-Backend-Reqs
Pragrma
X-Fpc
355prline
X-Request-Url
225prxHost
178proxuri
DSUID
X-CS
Xxline
188prxHost
WZWS-RAY
286prxHost
X-RAMCache
219prxHost
189phosttRef
352pxline