Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
CF-RAY
ETag
Link
Expect-CT
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Xss-Protection
X-Varnish
X-Request-Id
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Adblock-Key
X-Check
Alt-Svc
X-Cacheable
X-Generator
Content-Security-Policy-Report-Only
X-AspNetMvc-Version
X-Cache-Status
X-DNS-Prefetch-Control
X-Permitted-Cross-Domain-Policies
X-Template
X-Iinfo
X-Language
Status
Timing-Allow-Origin
X-Buckets
X-FRAME-OPTIONS
X-Content-Security-Policy
Content-Encoding
X-Kinja-Server-Push
Xkey
X-CDN
X-Turbo-Charged-By
Upgrade
X-Type
Keep-Alive
Access-Control-Expose-Headers
WPE-Backend
X-Pass-Why
X-AH-Environment
X-Backend
Access-Control-Max-Age
X-Age
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Server
X-Proxy-Cache
X-Via
X-Request-ID
Grace
X-Pingback
X-Nginx-Cache-Status
X-Server-Powered-By
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Hacker
X-Varnish-Cache
X-UA-Device
X-Page-Speed
EagleId
Request-Context
X-LiteSpeed-Cache
X-Envoy-Upstream-Service-Time
Cf-Railgun
X-CST
X-Ua-Compatible
X-Swift-CacheTime
X-Swift-SaveTime
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
Ali-Swift-Global-Savetime
X-Server-Id
X-Device
X-Amz-Version-Id
X-WebKit-CSP
Server-Timing
X-Ac
X-Node
Allow
X-OneAgent-JS-Injection
X-Response-Time
Feature-Policy
X-Rq
X-Cnection
X-Iejgwucgyu
Content-Location
X-Backend-Server
X-Cache-Lookup
Report-To
EagleEye-TraceId
Surrogate-Control
X-Host
X-Readtime
X-Application-Context
Request-Id
X-ORACLE-DMS-ECID
P3p
X-Rack-Cache
X-Url
X-Origin-Cache
X-Clacks-Overhead
NEL
X-Country
X-FTR-Request-ID
Rating
X-Country-Code
X-Cloud-Trace-Context
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-DataDome
X-Ruxit-JS-Agent
X-Cdn
X-Px
X-Instart-Request-ID
X-Mod-Pagespeed
Charset
X-Vhost
X-VARITI-CCR
X-MS-InvokeApp
Accept-CH
Pinterest-Generated-By
Edge-Control
X-Goog-Hash
Verso
X-GitHub-Request-Id
X-Upstream-Env
X-Vname
X-PC
X-TtlSet
X-Server-Name
Arc-Version
PB-PID
PB-RID
X-Mobile-Rewrite
X-ESI
X-Version
X-DynaTrace
X-Origin-Upstream-Status
X-Dns-Prefetch-Control
X-Powered-By-Plesk
X-D2id
X-Kinja-Build
X-Kinja
X-Exp-Id
X-Cdn-Fetch
X-Kinja-Revision
X-Kinja-Server
X-Exp-Variant
X-GoogleNews-Bot
X-Use-Magma
X-Cached
X-B3-TraceId
X-ORACLE-DMS-RID
X-TTL
X-Dispatcher
SPRequestGuid
X-Recruiting
X-Varnish-TTL
X-SharePointHealthScore
X-Abt-Application-Version
MS-Author-Via
X-Powered-CMS
Accept-CH-Lifetime
X-Navigation-Version
RTSS
Content-MD5
AR-PoweredBy
AR-ATIME
AR-CACHE
X-T
X-Shield-Request-Id
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Public-Key-Pins
X-Trace
X-DynaTrace-JS-Agent
X-Forwarded-Proto
X-Client-IP
Arr-Disable-Session-Affinity
X-Fastly-Request-ID
X-Amz-Rid
X-HW
X-Wix-Server-Artifact-Id
X-Accel-Buffering
SPRequestDuration
SPIisLatency
Realpath
X-DIS-Request-ID
Service-Worker-Allowed
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Amz-Meta-S3cmd-Attrs
AR-Request-ID
Paypal-Debug-Id
X-Oracle-Dms-Rid
Front-End-Https
X-Upstream
X-Ser
X-FTR-Backend-Server
X-FTR-Cache-Status
X-FTR-Backend
X-FTR-DC
X-B
X-Pinterest-Rid
X-FTR-Realm
Pinterest-Version
X-Country-Code-Real
X-FTR-Balancer
X-FTR-Expires
X-F-Cache
X-Ttl
X-Id
X-Via-JSL
X-XRDS-Location
X-Dw-Request-Base-Id
Ar-Sid
X-Vcap-Request-Id
X-Varnish-Age
X-Debug
X-Goog-Storage-Class
X-Acc-Meta-Resource-Type
X-MSEdge-Ref
X-Kinsta-Cache
Nginx-Cache
X-N
X-Server-ID
X-Hits
X-DataStream-Cache-Status
X-NF-Request-ID
S
X-FTR-Cache-Host
X-NewRelic-App-Data
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Akam-SW-Version
X-Logged-In
X-B3-TraceId-Primal
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
MRF-Tech
Mrf-Cache-Status
X-Forwarded-For
Tracecode
Alternate-Protocol
X-Frontend
X-User-Agent
X-PressLabs-Stats
X-HS-Content-Id
X-HS-Hub-Id
X-Grace
X-Amzn-Trace-Id
X-FastCGI-Cache
AMP-Access-Control-Allow-Source-Origin
TCN
X-Content-Options
X-Content-Digest
Server-Name
X-CACHE-GROUP
Refresh
Powered-By-ChinaCache
X-Middleton-Display
X-Sol
Display
X-Content-Type
Access-Control-Request-Method
X-Pad
DynaTrace
X-Analytics
Backend-Timing
MicrosoftSharePointTeamServices
Accept-Charset
X-LB-Cache
X-CF-Powered-By
X-Activity-Id
X-Rid
X-AppVersion
X-Debug-Info
X-Az
X-IPLB-Instance
FilterID
X-Zen-Fury
X-Page-Id
Host
Fastcgi-Cache
X-Middleton-Response
Response
X-Cache-Key
X-VCache
ServerID
MS-CV
X-Hostname
X-Cache-Hit
Cache-Status
TP-L2-Cache
X-Magnolia-Registration
TP-Cache
X-RateLimit-Remaining
X-Srv
X-Seen-By
X-Content-Powered-By
X-GUploader-UploadID
X-ATG-Version
X-Mobile
X-Fastcgi-Cache
X-Revision
X-Cached-By
X-WA-Info
X-Varnish-Backend
Host-Header
X-Request-Received
X-Request-Processing-Time
Surrogate-Key
X-B3-Sampled
X-Whom
Server-Info
VIX-Pulpo-Node
X-Instance
X-SS-Set-Cookie
VIX-Pulpo-Upstream-Status
X-Cluster
X-Platform-Server
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-0
X-Drupal-Cache-Tags
Source
DC
X-Cache-Action
X-Content-Security-Policy-Report-Only
X-Handled-By
X-Request-Guid
X-B-Cache
Cleartype
X-Signature
X-Wix-Request-Id
X-PHP-Backend
ViewerVersion
X-Real-IP
X-TT
X-Akamai-Edgescape
X-Framework
X-Origin-Server
X-Amzn-RequestId
Fusion-Content-Source
Fusion-Source
Fusion-Template-Id
Fusion-Component-Id
Fusion-Content-Id
X-Cache-Age
X-Amz-Apigw-Id
X-App-Environment
Rt-Fastcgi-Cache
X-Geo-Country
X-App-Server
X-FW-Static
X-FW-Serve
X-FW-Hash
X-FW-Type
X-FW-Server
X-Generated-By
X-BCube-Filmed-By
X-AOL-HN
X-Varnish-Server
X-Cache-Control
Server-Node
X-Oneagent-Js-Injection
X-Edge-Location
X-TA-CDN-Provider
X-Cache-Rule
X-NWS-LOG-UUID
X-XRDS-LOCATION
X-Varnish-Hostname
Retry-After
X-Ruxit-Js-Agent
X-Upstream-Proxy
Payment
X-Correlation-Id
X-Amz-Server-Side-Encryption
X-Varnish-Grace
X-Cache-2
X-Amz-Replication-Status
Access-Control-Allow-Method
X-TT-TIMESTAMP
X-Response-Served-From
X-FB-Debug
Eomportal-Instance
X-Tumblr-Pixel-2
X-Cacheable-TTL
X-Tumblr-Pixel-1
X-Cache-Config
Actual-Object-TTL
ServedBy
AsisCache
X-Ezoic-Cdn
Webserver
Ms-Operation-Id
X-UUID
NGB
X-WebKit-CSP-Report-Only
X-Varnish-Hits
Filters
Content-Script-Type
X-Contextid
X-Jobs
X-RTag
Healthy
X-Drupal-Cache-Contexts
X-UA-Device-Type
Content-Style-Type
X-Region
GEO-INFO
X-TX-ID
X-Adobe-Content
X-VG-WebCache
X-Adobe-Loc
Upgrade-Insecure-Requests
Viewport
Cache-Tv-Group
X-RequestSource
X-Rendered-As
X-Cache-TTL
HitType
From-Origin
X-Locale
X-Accel-Expires
Country
X-Varnish-IP
Fastcgi-Useragent
X-Cache-TTL-Remaining
X-Device-Type
X-BACKEND-TTL
Pagespeed
X-FW-Dynamic
X-Cache-Server
X-Content-Age
Edge-Cache-Tag
X-Servedby
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-WPE-Loopback-Upstream-Addr
Cache-Tags
X-Cache-Remote
X-Redis-Cache
X-Upgrade-Enabled
X-Cache-Operation
X-APP-VERSION
X-Source
Datacenter
X-RateLimit-Limit
Cache
X-Hit
X-DataStream-MidMile-RTT
X-DataStream-Origin-MEX-Latency
X-Storage
X-CACHE-KEY
Fastly-Restarts
X-Esi
X-GeoIP
X-Mode
NtCoent-Length
Cache-Tag
Served-By
X-Path-Route
X-Cache-Var-Map
X-Detected-As
X-Is-Bot
X-Origin-Response-Time
X-Cache-Var
X-Pubstack
X-TNCMS
X-Loop
X-Time-Microsecs
X-RN-RSRV
X-NGENIX-Cache
X-Internal-Host
X-JoinUs
X-Agile-Id
X-Akamai-Request-ID
X-Backend-Name
X-Agile
Vix-Hermes-Req-Id
Machine
Meta-Geo
Load-Balancing
X-Agile-Age
X-Hl-Ver
X-Varnish-Cache-Hits
X-Rule
Selected-FE
X-NCache
X-Environment-Context
X-ServerID
X-Tb
X-Hosted-By
X-Timing-Wait
X-Varnish-Cacheable
Origin-Edge-Control
Cache-Key
X-Proxy-Build
X-Birta-Served
X-Edge-IP
X-FC-Vary-Parameters
X-Labrador-Cache-Channel
X-L-Path
X-Status
X-CDN-Cache
X-Proxy
X-Origin-Host
X-Www-Served-By
X-Birta-Cache-Post
X-Generated
Origin-Cache-Control
Webcakes-App-Name
TWC-Privacy
Webcakes-App-Version
Webcakes-Region
X-ApacheServer
TWC-Locale-Group
TWC-GeoIP-LatLong
SRV
Property-Id
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-Country
X-Cache-Category-Id
X-Cache-Enabled
X-Web-Node
X-Viewer-Country
S-Rt
X-Microcachable
X-IP
X-Via-Fastly
X-VG-TLSProxy
X-Grey
X-Format
X-Origin-Hint
X-ProcessESI
X-RemovedCookies
Now
X-PERF
X-S
Access-Control-Request-Headers
X-CCM
Azure-InstanceId
X-Section
X-Human
X-OCL
Public-Key-Pins-Report-Only
X-PCL
X-MP-GENERATED-AT
X-GEO
Azure-Version
Azure-SlotName
Azure-SiteName
Azure-RegionName
X-Access
Cache-Name
Fastcgi-X-Cache-Version
X-BYPASS-REASON
X-App-Version
X-App-Name
X-ProxyCache-Key
X-Xfnlog-Site
X-Zipkin-Id
Cache-Hits
X-Site-Version
X-ProxyCache-Status
X-Proxied
X-Akamai-Transformed
Xserver
X-Routing-Service
User-Agent
DB-Nickname
X-Debug-Cache
Liferay-Portal
Mail-Subject
X-Daa-Tunnel
We-Hiring
CACHE
X-ES-SERVER
X-Node-Name
X-EdgeConnect-Cache-Status
LB
X-Protected-By
S-Cnection
X-Original-Request
X-FW-Version
X-Nginx-Cache
X-Sucuri-ID
X-Pc-Appver
X-Cache-NE
X-Pc-Key
X-Pc-Hit
X-Origin
X-Guploader-Uploadid
X-Proto
X-Ocache
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Request-Time
PageSpeed
X-Trace-Id
User-Cache-Control
X-Cdn-Forward
Powered
X-Ua
X-LJ-Flow-ID
X-AWS-Id
X-Forwarded-Host
X-UA
X-VWS-Id
X-GRACE
X-Tumblr-Pixel-3
Ohc-File-Size
X-Varnish-Ttl
L5d-Success-Class
X-Endurance-Cache-Level
X-Unique-ID
X-Webstats-RespID
Frame-Options
X-Cluster-Node
Section-Io-Cache
X-Correlation-ID
X-Nc
X-FB-TRIP-ID
X-V
X-Time
X-Origin-CC
OT-Force-Account-Verify
X-URL
X-EIG-Tracking-Id
X-Varnish-Beresp-Status
X-OVcl
X-OVcl-Cache
X-Varnish-Beresp-Grace
X-Origin-TTL
AR-SID
X-Webkit-Csp
X-B3-Traceid
X-ElasticPress-Search
Decoy-Debug-Status
Nel
X-Cache-Backend
X-From
Decoy-Debug-Key
Decoy-Debug-TTL
X-R9-Blue-Green-Version
X-B-Cookie
X-LI-Proto
X-Li-Fabric
X-BB-ID
X-Li-Pop
X-Backend-State
X-LI-UUID
X-Goog-Meta-Goog-Reserved-File-Mtime
X-CF-Lambda-Fn
X-CF-Lambda-Version
Cache-Prefix
X-Destination
X-Distil-CS
X-Developer
X-Date
Country-Code
Fastly-SIE
X-Connection-Hash
Fly-Cache
Fly-Request-Id
Ec-Rule-Version
BehaviorPad-Version
GMS-Ver
X-Generated-In
X-Cache-Grace
X-Node-Id
X-IN-APIGATEWAY
X-Info
X-IN-WAF
X-Cache-Host
X-Fetched-On
Arc-Country
X-Cdn-Srv
X-Cache-URL
X-Cache-Info
X-External-Request-Id
X-Irp-Debug
Meta-Geo-Continent
X-Response-By
X-Request-UUID
Node
On-Server
X-Rewrite-Enabled
X-Aed
X-NU-AKA-ACS-Version
Fastly-SWR
VivaBuild
X-VG-WebServer
Www
X-Reboot
X-Region-Sid
X-Parent-Response-Time
X-Rojux
Powered-By
X-TT-LOGID
X-User
X-Twitter-Response-Tags
X-UE-Client-Country
X-ServiceProvider
X-Server-Group
X-Accel-Expires-Debug
X-S-Cookie
X-ScT
X-Server-By
X-SRCache-Key
X-Rebelmouse-Surrogate-Control
X-Trv-Group
X-Transaction
Memcached
X-We-Are-Hiring
Rendered-Blocks
X-PAYTM-SRV-ID
X-Wikidot-Backend
X-Wikidot-Static-Cache
Xc-Version
X-Auto-Login
X-Origin-Date
X-Origin-Expires
MD5-Digest
SD-X-WS
X-ARC
X-Amz-Meta-Cache-Control
Mobile-Detection-Method
X-Application
X-Rebelmouse-Cache-Control
Viewtype
X-Dc
X-Rocket-Nginx-Bypass
IBM-Web2-Location
X-Cache-Debug
Thinkindot-CacheControl-Type
X-A-Dcw
X-Block-Status
X-CGP
X-A-Dam
X-Cache-Expires
X-Backend-Host
X-A
X-A-Ccd
X-Backend-Url
X-Bip
Server-Host
X-C
Thinkindot-Control
X-Cache-Id
X-A-Wwc
X-Alternate-Cache-Key
X-Actual-URL
X-A-Dgt
X-Cache-FS-Status
Thinkindot-CacheControl
X-Cache-Bucket
X-PHP-Host
X-Returned-From-DLL
X-Returned-From-BeforeDispatch
X-Returned-From-PostProcessResponse
X-S-Maxage
X-Secret
X-Returned-From
X-Proxy-Upstream
X-Passed-To-PostProcessResponse
X-Passed-To-DLL
X-Platform
X-Policy
X-Proxy-Cache-Status
X-Server-IP
X-ShardId
X-Thinkindot-L3
X-Thanos
X-Var-Ttl
X-Varnish-Action
X-Vgn-Hpd-Reason
X-Swa-Ws
X-Stale
X-Shopify-Stage
X-ShopId
X-SIPLIST1
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Passed-To-BeforeDispatch
X-Passed-To
X-Eu-Site
X-Epic-Correlation-Id
X-Fastly-Cache
X-G
X-Gannett-Site-Version
X-DPWN-IS-SECURE
X-Distributor
X-Crawler
X-Core-Mission
X-D
X-Debug-Cookies
X-Debug-Log
X-Gen-Mode
X-Generated-On
X-Matched-Rule
X-Logtrace-Id
X-Micro-Cache
X-Nginx-Cache-Key
X-NX-Host
X-Location
X-Level-Front-Cache
X-GeoIP-Country-Code
X-Hash
X-Hnp-Log
X-LAGOON
X-Clientip
Who
Request-Time
HA-Ipaddr
Lfy
Fastly-Backend-Name
Origin
IsBot
Content-Disposition
Countrycode
Backend
Proxy-Connection
Ha-Gx-Prefs
Ajk
Fastly-SSL
CDCHOST
X-Varnish-Beresp-Ttl
Magicmarker
Mn-Server-Ip
Fastly-Soc-X-Request-Id
X-Via-CDN
X-HS-Cache-Config
X-TIME
Warning
X-Sucuri-Cache
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
X-Core-Value
SID
GW-Server
X-Debug-Cache-Store
X-No-Session
X-Croise-Owner
X-CUA
X-Dispatcher-Server
X-Fstrz
AKAMAI
Apple-News-Services-Handled
Adler-Geo
X-Instart-Isnd
X-MSEdge-Flight
X-MSEdge-Features
X-SERVER
X-F5-Cache
Apple-News-Services-Host
X-Developers
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
X-Request-URI
Cache-Cookie-Set-From
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
X-Qloud-Router
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
Platform
Release
Hostname
X-UnsetCookies
X-Amz-Meta-Surrogate-Control
X-Sf
Web-Mar-Node
X-Svr
X-TrackingId
Server-Surrogate-Control
Server-Int
SS
True-Client-Country-4JS
Resin-Trace
X-Up
Pramga
X-Variation
Server-Cache-Control
Heartbleed
Is-Eu
X-Varnish-Authentication
X-Cache-ASPX
X-Pc-Subdomain
X-Pc-Date
X-Upstream-CT
X-Pc-Host
X-Upstream-HT
REQUESTUUID
X-Server-Time
X-SN
X-Key
NGX
RNT-Time
X-Owner
RNT-Machine
X-FireWall-Port
X-Device-Os
Pagetype
Kp-EeAlive
X-Be
Odigeo-Trace-Id
X-Servername
X-Cache-Miss-From
X-Server-Cache
X-IN-SSL-APIGATEWAY
X-Pjax-Url
Server-ID
X-Page-Type
X-Varnish-Url
X-Sedo-Request-Id
X-Generation-Time
X-CDN-Forward
X-Newrelic-App-Data
HTTPS
X-Died
X-Refresh
X-Via-NSCOPI
Fastcgi-X-Cache
Cdn-Host
RequestId
X-NC
Cdn-Request-Time
MIME-Version
X-Edge-Server
X-B3-SpanId
X-Edge-Cache-Key
X-Edge-Cache
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-From-Cache
Version
X-Oss-Request-Id
X-Oss-Storage-Class
X-Servedbyhost
X-Oss-Server-Time
HostName
X-FPC
ProcessTime
PFcat
Time
Cteonnt-Length
Mime-Version
Cdn
PICS-Label
X-Req
X-Mobile-URL
FastCGI-Cache
Esi-Enabled
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
X-Cache-CFC
X-Store
X-NodeID
Cross-Origin-Window-Policy
X-CSRF-TOKEN
X-Load-Cache
CF-IPCountry
X-GZip
X-VServer
Memory
X-Layer
MI-API
X-MI-In-Market
Processtime
MI-Cache-Age
MI-Cache
X-HS-Combine-CSS
X-Hyper-Cache
X-Webkit-CSP
X-RCS-CacheZone
X-CLOUD-TRACE-CONTEXT
HA-Geolat
HA-Geolon
HA-Urlpath
HA-Host
HA-Georegion
X-Wa
HA-Geocountry
X-Dynatrace-Js-Agent
X-IPS-LoggedIn
X-RequestId
HA-Servedtime
HA-Geocity
HA-Cloudapp
X-Skip-Cache
X-Ratelimit-Remaining
X-Varnish-Beresp-TTL
X-HTML-Minification-Powered-By
X-Lb-Id
Uber-Trace-Id
Cf-Ipcountry
CDN
Ohc-Cache-HIT
X-Ratelimit-Limit
X-Geo
X-Pf-Uncompressing
X-VC-Cache
X-DC
X-Newrelic-Synthetics
XServer
X-Aicache-OS
Backend-Name
X-CMS-Context
X-Fastly-Country-Code
X-Cms-Context
X-Real-Ip
X-B3-Spanid
N-Cache
X-WA
X-UCC
X-Mrs-Cache-Hits
X-Instart-Info
X-Atg-Version
X-Mshield-Cache-Status
X-Mrs-Cache
X-Mrs-Age
X-Unique-Id-Primal
X-Tb-Optimization-Total-Bytes-Saved
X-WR-MODIFICATION
X-PF-Uncompressing
X-Gateway-Cache-Key
X-Gateway-Cache-Status
Ohc-Response-Time
X-WebServer
X-Phone
X-Gateway-Skip-Cache
X-Shard
Amp-Access-Control-Allow-Source-Origin
Accept-Ch-Lifetime
X-Processor
URI
X-Request-Start
X-LB-ID
T-Server
GeoIP-Country-Code
X-Nananana
X-Release
GeoIP-Latitude
X-Oracle-Dms-Ecid
Pics-Label
X-Hp-Webp
X-BBXSRF
X-Server-W
X-MServer
X-COUNTRY
X-APP
X-Datadome
X-CSRF-Token
X-SRV
X-Unique-Id
X-FORWARDED-FOR
X-Worker
X-VCT
Host-ID
X-LiteSpeed-Cache-Control
X-GoCache-CacheStatus
X-Served-From
X-ND-Cache
A
X-GeoIP-City
Rt-Proxy-Cache
X-Amzn-Remapped-Content-Length
X-ServedByHost
X-VHOST
X-Geo-Header
X-SERVER-NAME
UCS
X-Check-Cacheable
X-HS-Status
X-CACHE-AGE
DataCenter
Request-EU
X-GZIP
X-UPSTREAM-Address
X-Optimization
Request-Country
X-Requestid
X-Cache-HT
X-Fastly-Cache-Hits
X-NGINX-Cache
Geoip-Latitude
X-Vcache
X-Varnish-URL
X-Planisys-CDN-Cache
X-Cdn-Origin
Dnion-Transfer-Encoding
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-ID
V-Age
X-Sn-Servicetimems
Cneonction
FSS-Cache
Pragrma
X-Fpc
FSS-Proxy
X-BE
X-Backend-TTL
X-Git-Hash
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-PAGE-TYPE
Proxy-Firewall
X-ServerName
X-PJAX-URL
WP-Super-Cache
X-Dw-Trace-Id
X-Csrf-Token
X-Org
Requestid
WZWS-RAY
GeoIp-Country-Code
X-Fastly-Backend-Reqs
X-Port
Serverid
X-HostName
Cache-Provider
Server-Id
X-P-T
X-Via-SSL
RequestUuid
X-LiteSpeed-Tag
X-Via-Edge
Get-Access-Time
X-Html-Edge-Cache
Is-Session-Tracking
X-Gen-Id
X-NWS-UUID-VERIFY
X-StackifyID
219prxHost
355prline
352pxline
286prxHost
409pxxline
X-CS
X-Request-Url
Xxline
225prxHost
ServerName
DSUID
X-RAMCache
X-Fe
178proxuri
189phosttRef
188prxHost
Inserted-Into-Cache-At