Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
CF-RAY
ETag
Link
Expect-CT
Via
X-XSS-Protection
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Xss-Protection
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Request-Id
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Adblock-Key
X-Check
Alt-Svc
X-Cacheable
X-Generator
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-Cache-Status
X-AspNetMvc-Version
X-Permitted-Cross-Domain-Policies
X-Iinfo
X-Template
X-Language
Status
Timing-Allow-Origin
X-Buckets
X-Content-Security-Policy
Content-Encoding
X-CDN
X-Kinja-Server-Push
Xkey
X-Turbo-Charged-By
Upgrade
X-Type
Keep-Alive
Access-Control-Expose-Headers
WPE-Backend
X-Pass-Why
Access-Control-Max-Age
X-Backend
X-AH-Environment
CF-Ray
X-Cache-Group
X-Age
X-Drupal-Dynamic-Cache
X-Server
X-Ua-Compatible
X-Via
X-Proxy-Cache
X-Request-ID
Grace
X-Pingback
X-Nginx-Cache-Status
X-Server-Powered-By
X-Robots-Tag
X-Amz-Id-2
X-Amz-Request-Id
X-Hacker
X-UA-Device
X-Varnish-Cache
X-Page-Speed
EagleId
Request-Context
X-LiteSpeed-Cache
P3p
Cf-Railgun
X-Envoy-Upstream-Service-Time
X-CST
X-Swift-SaveTime
X-Swift-CacheTime
X-WebKit-CSP
Ali-Swift-Global-Savetime
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-Server-Id
X-Amz-Version-Id
X-Ac
X-Node
Server-Timing
X-OneAgent-JS-Injection
Feature-Policy
Allow
X-Iejgwucgyu
X-Cnection
X-Response-Time
X-Rq
Content-Location
X-Backend-Server
X-Cache-Lookup
Report-To
EagleEye-TraceId
Surrogate-Control
X-Readtime
X-Host
X-Application-Context
Request-Id
X-Url
X-ORACLE-DMS-ECID
X-Rack-Cache
X-Origin-Cache
X-Clacks-Overhead
X-Country
NEL
X-FTR-Request-ID
Rating
X-Country-Code
X-Cloud-Trace-Context
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-DataDome
X-Instart-Request-ID
X-Px
X-Ruxit-JS-Agent
X-Vhost
X-Mod-Pagespeed
X-MS-InvokeApp
Charset
X-VARITI-CCR
Accept-CH
Edge-Control
Pinterest-Generated-By
X-Goog-Hash
X-GitHub-Request-Id
Verso
PB-RID
X-Mobile-Rewrite
Arc-Version
PB-PID
X-TTL
X-ESI
X-DynaTrace
X-PC
X-Version
X-Vname
X-TtlSet
X-Server-Name
X-B3-TraceId
X-Powered-By-Plesk
X-Cdn
X-D2id
X-Varnish-TTL
X-Kinja-Server
X-Exp-Variant
X-Exp-Id
X-Kinja-Revision
X-Kinja-Build
X-GoogleNews-Bot
X-Kinja
X-Cdn-Fetch
X-Use-Magma
X-Cached
X-Upstream-Env
X-Origin-Upstream-Status
SPRequestGuid
X-Dispatcher
X-SharePointHealthScore
X-Powered-CMS
X-Abt-Application-Version
MS-Author-Via
X-Recruiting
X-T
Accept-CH-Lifetime
RTSS
X-Navigation-Version
Public-Key-Pins
X-Shield-Request-Id
X-Oracle-Dms-Rid
X-ORACLE-DMS-RID
X-Trace
Content-MD5
AR-CACHE
AR-PoweredBy
AR-ATIME
X-Client-IP
X-Amz-Rid
X-SRCache-Store-Status
X-SRCache-Fetch-Status
SPRequestDuration
SPIisLatency
X-Fastly-Request-ID
X-HW
X-Forwarded-Proto
X-DIS-Request-ID
X-Accel-Buffering
X-Wix-Server-Artifact-Id
Arr-Disable-Session-Affinity
Realpath
X-Server-ID
X-B
X-F-Cache
X-Upstream
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Amz-Meta-S3cmd-Attrs
X-DynaTrace-JS-Agent
X-Ser
Service-Worker-Allowed
X-Via-JSL
Pinterest-Version
X-Pinterest-Rid
X-FTR-Backend
X-Country-Code-Real
X-Id
X-FTR-Realm
X-FTR-DC
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Cache-Status
Front-End-Https
X-Dw-Request-Base-Id
X-FTR-Expires
Paypal-Debug-Id
AR-Request-ID
X-Vcap-Request-Id
X-Varnish-Age
X-Dns-Prefetch-Control
X-Debug
X-Goog-Storage-Class
X-Acc-Meta-Resource-Type
Ar-Sid
X-MSEdge-Ref
X-N
Nginx-Cache
X-Kinsta-Cache
X-Hits
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-NF-Request-ID
X-NewRelic-App-Data
X-FTR-Cache-Host
X-Logged-In
X-Ttl
S
MRF-Tech
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Mrf-Item-Lastmod
X-Akam-SW-Version
X-XRDS-Location
X-Forwarded-For
X-Grace
X-Frontend
X-PressLabs-Stats
X-HS-Hub-Id
X-HS-Content-Id
X-User-Agent
X-DataStream-Cache-Status
Alternate-Protocol
Tracecode
X-Amzn-Trace-Id
X-CACHE-GROUP
DynaTrace
Server-Name
X-Pad
AMP-Access-Control-Allow-Source-Origin
X-Content-Digest
Refresh
X-Content-Options
MicrosoftSharePointTeamServices
X-TA-CDN-Provider
X-Analytics
Backend-Timing
Powered-By-ChinaCache
Accept-Charset
X-Zen-Fury
Fastcgi-Cache
X-Content-Type
X-Az
X-Activity-Id
X-AppVersion
X-Fastcgi-Cache
X-LB-Cache
FilterID
TCN
X-IPLB-Instance
X-Rid
Host
X-Page-Id
X-FastCGI-Cache
Display
Access-Control-Request-Method
X-Middleton-Display
X-Debug-Info
X-Sol
X-Cache-Key
MS-CV
X-CF-Powered-By
ServerID
X-Magnolia-Registration
Cache-Status
TP-Cache
TP-L2-Cache
X-XRDS-LOCATION
X-Middleton-Response
Response
X-Cache-Hit
X-ATG-Version
X-Content-Powered-By
X-Mobile
X-Seen-By
X-Srv
Surrogate-Key
X-Hostname
X-WA-Info
X-B3-Sampled
X-Revision
X-Cached-By
Rt-Fastcgi-Cache
X-Request-Received
X-Varnish-Backend
X-Request-Processing-Time
X-SS-Set-Cookie
X-Signature
X-RateLimit-Remaining
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Cluster
X-Cache-Action
X-B-Cache
X-Tumblr-Pixel
X-Content-Security-Policy-Report-Only
X-Tumblr-Pixel-0
X-Tumblr-User
X-Instance
X-Cache-Age
X-Drupal-Cache-Tags
Cleartype
X-PHP-Backend
X-Request-Guid
X-Whom
Source
X-VCache
X-Akamai-Edgescape
X-TT
X-Wix-Request-Id
X-Platform-Server
ViewerVersion
Host-Header
X-Framework
X-Handled-By
X-App-Environment
X-Edge-Location
Server-Info
X-Ruxit-Js-Agent
X-Origin-Server
X-GUploader-UploadID
X-Cache-Control
X-BCube-Filmed-By
DC
X-Generated-By
X-Amz-Apigw-Id
X-Amzn-RequestId
X-App-Server
X-Geo-Country
X-Real-IP
X-FW-Type
X-Cache-Rule
X-NWS-LOG-UUID
X-FW-Hash
X-FW-Server
X-FW-Static
X-FW-Serve
X-Varnish-Hostname
X-Oneagent-Js-Injection
X-AOL-HN
Server-Node
X-Varnish-Server
Retry-After
X-Cache-2
Fusion-Source
Fusion-Content-Id
Fusion-Template-Id
Fusion-Component-Id
Fusion-Content-Source
X-Correlation-Id
Eomportal-Instance
X-FB-Debug
Cache
Payment
X-WPE-Loopback-Upstream-Addr
Webserver
Access-Control-Allow-Method
X-Response-Served-From
X-Amz-Server-Side-Encryption
Actual-Object-TTL
X-Varnish-Grace
X-TT-TIMESTAMP
X-Varnish-Hits
X-Tumblr-Pixel-1
AsisCache
X-Tumblr-Pixel-2
X-Device-Type
ServedBy
X-RTag
NGB
Ms-Operation-Id
GEO-INFO
X-TX-ID
X-Region
X-Cacheable-TTL
X-WebKit-CSP-Report-Only
X-Jobs
Content-Style-Type
Content-Script-Type
X-UUID
Filters
X-Contextid
X-Varnish-IP
X-Adobe-Loc
Viewport
Upgrade-Insecure-Requests
X-Amz-Replication-Status
X-Servedby
Healthy
X-Adobe-Content
X-Drupal-Cache-Contexts
X-Cache-Config
X-Locale
X-Rendered-As
X-RequestSource
Country
X-UA-Device-Type
Cache-Tv-Group
From-Origin
X-Accel-Expires
X-Cache-TTL-Remaining
Edge-Cache-Tag
HitType
X-Ezoic-Cdn
X-BACKEND-TTL
Pagespeed
X-Cache-Server
X-Cache-Remote
X-VG-WebCache
X-Cache-TTL
Fastcgi-Useragent
X-Cache-Operation
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Fastly-Restarts
X-FW-Dynamic
X-Content-Age
Cache-Tags
X-Upgrade-Enabled
X-Hit
X-Redis-Cache
X-Storage
X-App-Version
X-S
X-Guploader-Uploadid
X-CACHE-KEY
X-Esi
Datacenter
X-APP-VERSION
X-Source
X-Mode
Cache-Tag
Served-By
X-Upstream-Proxy
NtCoent-Length
Origin-Edge-Control
SRV
X-Path-Route
Load-Balancing
X-Rule
X-RN-RSRV
X-Hl-Ver
X-GeoIP
X-NGENIX-Cache
X-Is-Bot
X-JoinUs
X-NCache
Machine
X-Origin-Response-Time
X-Cache-Var
X-Internal-Host
Origin-Cache-Control
X-Backend-Name
X-Cache-Var-Map
X-Detected-As
Meta-Geo
X-Generated
Xserver
X-Akamai-Request-ID
X-Cache-Category-Id
X-TNCMS
X-Web-Node
X-Timing-Wait
X-Time-Microsecs
X-Pubstack
X-ServerID
X-Www-Served-By
Vix-Hermes-Req-Id
X-L-Path
X-Hosted-By
X-Labrador-Cache-Channel
X-Loop
X-Tb
X-Origin-Host
X-ProxyCache-Status
X-Grey
X-Birta-Served
X-BYPASS-REASON
X-Birta-Cache-Post
X-Agile-Id
X-Agile
X-Agile-Age
X-CDN-Cache
X-Edge-IP
X-Proxy-Build
X-ProxyCache-Key
X-Proxy
X-FC-Vary-Parameters
X-Environment-Context
Selected-FE
Now
X-Akamai-Transformed
Webcakes-App-Name
Webcakes-App-Version
X-Cache-NE
TWC-Privacy
Webcakes-Region
TWC-Locale-Group
TWC-Connection-Speed
Property-Id
TWC-Device-Class
TWC-GeoIP-Country
TWC-GeoIP-LatLong
X-ApacheServer
X-IP
X-Via-Fastly
X-Status
X-Viewer-Country
Cache-Key
X-Varnish-Cacheable
X-RemovedCookies
X-ProcessESI
X-Origin-Hint
X-Pc-Appver
X-Pc-Hit
X-PERF
X-RateLimit-Limit
X-Pc-Key
X-Varnish-Cache-Hits
Cache-Name
Azure-SiteName
Azure-RegionName
Azure-SlotName
Azure-Version
Azure-InstanceId
X-OCL
X-Format
X-Site-Version
X-Debug-Cache
X-Daa-Tunnel
X-PCL
X-CCM
Fastcgi-X-Cache-Version
DB-Nickname
S-Rt
X-Routing-Service
X-DataStream-MidMile-RTT
X-Human
X-VG-TLSProxy
X-MP-GENERATED-AT
X-Xfnlog-Site
X-Proxied
X-Zipkin-Id
Public-Key-Pins-Report-Only
Mail-Subject
X-Access
X-DataStream-Origin-MEX-Latency
X-Section
We-Hiring
X-Cache-Enabled
X-App-Name
X-Original-Request
X-Origin
Access-Control-Request-Headers
X-UA
X-Microcachable
X-Sucuri-ID
User-Cache-Control
X-Ocache
S-Cnection
X-Cdn-Forward
X-EdgeConnect-Cache-Status
X-Protected-By
Liferay-Portal
X-GEO
X-Nginx-Cache
X-Request-Time
X-FW-Version
User-Agent
LB
X-Webstats-RespID
X-Tumblr-Pixel-3
Cache-Hits
X-Proto
X-GRACE
X-Yottaa-Optimizations
X-FB-TRIP-ID
Ohc-File-Size
X-Node-Name
X-Yottaa-Metrics
X-Trace-Id
X-Origin-CC
X-Nc
X-ES-SERVER
Powered
X-Correlation-ID
X-Time
X-Dynatrace-Js-Agent
X-Endurance-Cache-Level
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-Unique-ID
X-Forwarded-Host
X-Pc-Host
Frame-Options
X-Parent-Response-Time
X-Upstream-CT
X-Pc-Date
X-Upstream-HT
PageSpeed
X-Pc-Subdomain
L5d-Success-Class
X-V
X-OVcl-Cache
Section-Io-Cache
X-OVcl
IBM-Web2-Location
X-Cache-Backend
X-ElasticPress-Search
X-Origin-TTL
X-Ua
AR-SID
X-Rocket-Nginx-Bypass
OT-Force-Account-Verify
X-Varnish-Beresp-Ttl
Nel
X-Vgn-Hpd-Reason
X-LJ-Flow-ID
X-VWS-Id
X-AWS-Id
X-R9-Blue-Green-Version
X-Cache-Bucket
X-Block-Status
X-BB-ID
Resin-Trace
Fly-Cache
Fastly-SWR
Fly-Request-Id
GMS-Ver
Memcached
MD5-Digest
Fastly-SIE
Ec-Rule-Version
Country-Code
Cache-Prefix
Decoy-Debug-Key
Decoy-Debug-Status
Decoy-Debug-TTL
Meta-Geo-Continent
Mobile-Detection-Method
X-Aed
X-Accel-Expires-Debug
X-Amz-Meta-Cache-Control
X-ARC
X-Auto-Login
Www
VivaBuild
Powered-By
Node
Rendered-Blocks
Xc-Version
Viewtype
X-B-Cookie
X-Distil-CS
X-NU-AKA-ACS-Version
X-Micro-Cache
X-Origin-Date
X-Origin-Expires
X-PHP-Host
X-PAYTM-SRV-ID
X-TT-LOGID
X-LI-UUID
X-Irp-Debug
X-Info
X-Li-Fabric
X-Li-Pop
X-LI-Proto
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-S-Maxage
X-SRCache-Key
X-ScT
X-Server-By
X-Server-Group
X-S-Cookie
X-Rojux
X-Trv-Group
X-Reboot
X-Region-Sid
X-Request-UUID
X-Rewrite-Enabled
X-IN-WAF
X-IN-SSL-APIGATEWAY
X-CF-Lambda-Version
X-Wikidot-Backend
X-Date
X-Destination
X-We-Are-Hiring
X-Developer
X-CF-Lambda-Fn
X-Cdn-Srv
X-Cache-Id
X-Cache-Host
X-Cache-Info
X-Cache-URL
X-Wikidot-Static-Cache
X-ServiceProvider
X-DPWN-IS-SECURE
X-Generated-In
X-UE-Client-Country
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Hnp-Log
X-IN-APIGATEWAY
X-User
BehaviorPad-Version
X-VG-WebServer
X-External-Request-Id
X-Fetched-On
X-From
X-Gen-Mode
X-Cache-FS-Status
X-Application
Arc-Country
X-Varnish-Ttl
X-Server-Cache
X-Edge-Cache-Key
Fastcgi-X-Cache
X-Edge-Cache
X-Cluster-Node
X-Dc
X-ShopId
X-Backend-Url
X-C
X-ShardId
X-Shopify-Stage
X-Bip
X-Cache-Expires
X-Via-NSCOPI
X-Clientip
Mn-Server-Ip
X-Server-IP
X-Sf
X-Cache-Grace
X-Cache-Debug
X-Sorting-Hat-PodId
X-A-Dam
X-A-Dcw
X-A-Dgt
X-A-Ccd
X-A
X-Transaction
X-Thinkindot-L3
X-A-Wwc
X-Thanos
X-Sorting-Hat-ShopId
X-Returned-From-PostProcessResponse
X-SIPLIST1
X-Stale
X-Svr
X-Swa-Ws
X-Alternate-Cache-Key
X-Backend-Host
X-CUA
X-Policy
X-Passed-To-PostProcessResponse
X-Passed-To-DLL
X-Proxy-Cache-Status
X-Proxy-Upstream
X-Generated-On
X-Hash
X-Passed-To-BeforeDispatch
X-Passed-To
X-Location
X-Logtrace-Id
X-Matched-Rule
X-Nginx-Cache-Key
X-Node-Id
X-NX-Host
X-Level-Front-Cache
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Returned-From-DLL
X-Debug-Cookies
X-Debug-Log
X-D
Who
X-Core-Mission
X-Crawler
X-Returned-From-BeforeDispatch
X-Returned-From
X-Fastly-Cache
X-FireWall-Port
X-G
X-Request-URI
X-Distributor
X-Dispatcher-Server
X-Response-By
X-Connection-Hash
X-Actual-URL
X-Varnish-Action
Countrycode
Web-Mar-Node
Magicmarker
SD-X-WS
X-Variation
On-Server
Origin
Platform
CDCHOST
Content-Disposition
Backend
Request-Time
Lfy
Server-Host
Thinkindot-Control
Thinkindot-CacheControl-Type
True-Client-Country-4JS
Fastly-Soc-X-Request-Id
Fastly-Backend-Name
X-Twitter-Response-Tags
Thinkindot-CacheControl
Adler-Geo
Ajk
Is-Eu
Proxy-Connection
X-Var-Ttl
IsBot
Warning
X-Via-CDN
X-Sucuri-Cache
Heartbleed
GW-Server
X-MSEdge-Features
X-F5-Cache
X-Epic-Correlation-Id
Server-Surrogate-Control
Server-Cache-Control
X-Died
X-Instart-Isnd
X-MSEdge-Flight
Server-Int
X-Fstrz
X-Gannett-Site-Version
Fastly-SSL
X-Platform
X-UnsetCookies
X-Secret
Cache-Cookie-Set-From
SS
X-Qloud-Router
X-Device-Os
X-GeoIP-Country-Code
X-LAGOON
X-Generation-Time
X-Eu-Site
X-Developers
Pagetype
X-TIME
X-Varnish-Authentication
Pramga
X-Cache-ASPX
Cache-Cookie-Set-Lfrom
X-SERVER
Release
X-No-Session
Cache-Cookie-Set-Idcheck
Ha-Gx-Prefs
X-Core-Value
X-Backend-State
X-CGP
AKAMAI
RNT-Time
RNT-Machine
X-Key
HA-Ipaddr
X-Croise-Owner
HostName
X-TrackingId
X-Page-Type
X-Up
CACHE
X-Amz-Meta-Surrogate-Control
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
X-Server-Time
Apple-News-Services-Host
X-Varnish-Url
Apple-News-Services-Handled
X-Ratelimit-Remaining
X-EIG-Tracking-Id
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
REQUESTUUID
Server-ID
X-Debug-Cache-Store
X-HS-Cache-Config
X-Sedo-Request-Id
NGX
X-Pjax-Url
X-Cache-Miss-From
Version
X-Be
Kp-EeAlive
X-B3-Traceid
PFcat
X-Refresh
RequestId
X-Newrelic-App-Data
X-Servername
SID
X-Store
X-Cache-CFC
Esi-Enabled
X-Owner
X-SN
Time
X-CDN-Forward
X-URL
X-RCS-CacheZone
MI-Cache-Age
MIME-Version
MI-Cache
X-Oss-Object-Type
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-Layer
X-MI-In-Market
Odigeo-Trace-Id
X-Oss-Storage-Class
X-Oss-Request-Id
X-From-Cache
MI-API
X-NC
X-B3-SpanId
Cdn
X-FPC
X-RequestId
Mime-Version
PICS-Label
X-IPS-LoggedIn
Cteonnt-Length
X-Ratelimit-Limit
Hostname
HA-Georegion
HA-Servedtime
HA-Urlpath
HTTPS
HA-Geolon
HA-Geolat
HA-Geocity
HA-Geocountry
HA-Cloudapp
HA-Host
X-Hyper-Cache
FastCGI-Cache
X-Mrs-Cache-Hits
X-Mshield-Cache-Status
Backend-Name
X-Unique-Id-Primal
X-Servedbyhost
Cdn-Host
X-Mrs-Age
Cdn-Request-Time
X-Edge-Server
X-Mrs-Cache
X-CSRF-TOKEN
X-Geo
X-Req
X-Load-Cache
X-Real-Ip
X-Webkit-Csp
X-Webkit-CSP
X-CMS-Context
Memory
CF-IPCountry
X-CLOUD-TRACE-CONTEXT
ProcessTime
Cf-Ipcountry
X-B3-Spanid
Processtime
X-WebServer
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
X-Wa
X-Mobile-URL
X-Instart-Info
X-Phone
Ohc-Response-Time
CDN
X-Newrelic-Synthetics
Cross-Origin-Window-Policy
X-GZip
X-VServer
GeoIP-Country-Code
X-Request-Start
X-DC
X-Varnish-Beresp-TTL
X-NodeID
Amp-Access-Control-Allow-Source-Origin
X-HS-Combine-CSS
X-WR-MODIFICATION
X-PF-Uncompressing
X-Aicache-OS
X-Pf-Uncompressing
X-HTML-Minification-Powered-By
GeoIP-Latitude
X-Release
X-Lb-Id
XServer
X-Atg-Version
X-WA
X-Fastly-Country-Code
X-Skip-Cache
URI
X-Server-W
Ohc-Cache-HIT
T-Server
X-Served-From
X-FORWARDED-FOR
X-Nananana
X-VC-Cache
X-ND-Cache
Accept-Ch-Lifetime
Rt-Proxy-Cache
Uber-Trace-Id
X-Tb-Optimization-Total-Bytes-Saved
X-ServedByHost
X-Oracle-Dms-Ecid
X-Cms-Context
X-GoCache-CacheStatus
X-APP
X-COUNTRY
N-Cache
X-LB-ID
X-Unique-Id
X-Gateway-Skip-Cache
X-UCC
X-MServer
X-Gateway-Cache-Status
X-Gateway-Cache-Key
X-Worker
X-Vcache
X-Cdn-Origin
X-Sn-Servicetimems
X-Datadome
V-Age
X-CSRF-Token
X-SRV
Pics-Label
Proxy-Firewall
X-Fastly-Cache-Hits
X-SVT-ORM-RULES
A
X-SVT-ORM-VERSION
X-UPSTREAM-Address
X-LiteSpeed-Cache-Control
X-Processor
X-SERVER-NAME
X-CACHE-AGE
DataCenter
X-Hp-Webp
X-HS-Status
Is-Session-Tracking
X-BBXSRF
X-P-T
Get-Access-Time
X-Requestid
X-GZIP
X-Check-Cacheable
ServerName
Cneonction
X-NGINX-Cache
X-Optimization
X-Cache-HT
Geoip-Latitude
Dnion-Transfer-Encoding
X-ServerName
X-RCS-Backend
X-HostName
X-ID
X-BE
X-Backend-TTL
X-Vg-Webcache
X-GeoIP-City
X-PAGE-TYPE
X-VCT
X-GDPR
X-Shard
X-Varnish-URL
X-Geo-Header
X-Amzn-Remapped-Content-Length
GeoIp-Country-Code
X-StackifyID
X-Csrf-Token
Host-ID
X-Fe
X-PJAX-URL
X-Port
Requestid
Serverid
X-NWS-UUID-VERIFY
Cache-Provider
X-Org
WP-Super-Cache
X-LiteSpeed-Tag
RequestUuid
X-Fastly-Backend-Reqs
UCS
Inserted-Into-Cache-At
X-Git-Hash
WZWS-RAY
Server-Id
X-Dw-Trace-Id
X-CS
Xxline
X-Request-Url
225prxHost
219prxHost
286prxHost
178proxuri
X-RAMCache
189phosttRef
409pxxline
DSUID
X-Via-SSL
188prxHost
352pxline
355prline
X-Via-Edge