Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
CF-RAY
ETag
Link
Expect-CT
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Xss-Protection
X-Varnish
X-Request-Id
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Adblock-Key
X-Check
Alt-Svc
X-Cacheable
X-Generator
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-Cache-Status
X-AspNetMvc-Version
X-Permitted-Cross-Domain-Policies
X-Iinfo
X-Template
X-Language
Status
Timing-Allow-Origin
X-Buckets
X-Content-Security-Policy
Content-Encoding
X-CDN
X-Kinja-Server-Push
Xkey
X-Turbo-Charged-By
Upgrade
X-Type
Keep-Alive
Access-Control-Expose-Headers
X-Request-ID
WPE-Backend
X-Pass-Why
Access-Control-Max-Age
X-Backend
X-AH-Environment
CF-Ray
X-Cache-Group
X-Age
X-Drupal-Dynamic-Cache
X-Server
X-Ua-Compatible
X-Via
X-Proxy-Cache
Grace
X-Pingback
X-Nginx-Cache-Status
X-Server-Powered-By
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Hacker
X-UA-Device
X-Varnish-Cache
X-Page-Speed
EagleId
Request-Context
X-LiteSpeed-Cache
Cf-Railgun
X-Envoy-Upstream-Service-Time
X-CST
X-Swift-CacheTime
X-Swift-SaveTime
X-WebKit-CSP
Ali-Swift-Global-Savetime
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
X-Server-Id
X-Amz-Version-Id
X-Ac
Server-Timing
X-OneAgent-JS-Injection
X-Node
Allow
Feature-Policy
X-Iejgwucgyu
X-Cnection
X-Response-Time
X-Rq
Content-Location
X-Backend-Server
X-Cache-Lookup
Report-To
EagleEye-TraceId
Surrogate-Control
X-Readtime
X-Host
X-Application-Context
Request-Id
X-Url
X-ORACLE-DMS-ECID
P3p
X-Rack-Cache
X-Origin-Cache
X-Clacks-Overhead
X-Country
NEL
X-FTR-Request-ID
Rating
X-Country-Code
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-DataDome
X-Cloud-Trace-Context
X-Instart-Request-ID
X-Px
X-Ruxit-JS-Agent
X-Vhost
X-MS-InvokeApp
X-Mod-Pagespeed
Charset
X-VARITI-CCR
Edge-Control
Accept-CH
X-Goog-Hash
Pinterest-Generated-By
X-GitHub-Request-Id
Verso
X-Mobile-Rewrite
Arc-Version
X-TTL
PB-PID
PB-RID
X-ESI
X-DynaTrace
X-Vname
X-TtlSet
X-PC
X-Version
X-Server-Name
X-Varnish-TTL
X-B3-TraceId
X-Cdn
X-Powered-By-Plesk
X-D2id
X-Exp-Variant
X-Use-Magma
X-Kinja-Build
X-Cdn-Fetch
X-GoogleNews-Bot
X-Kinja
X-Kinja-Revision
X-Kinja-Server
X-Exp-Id
X-Cached
X-Upstream-Env
X-Origin-Upstream-Status
X-Dispatcher
SPRequestGuid
X-SharePointHealthScore
X-Powered-CMS
X-Abt-Application-Version
X-ORACLE-DMS-RID
MS-Author-Via
X-Recruiting
X-T
Accept-CH-Lifetime
RTSS
X-Navigation-Version
Public-Key-Pins
X-Shield-Request-Id
X-Trace
AR-ATIME
AR-PoweredBy
Content-MD5
AR-CACHE
X-Amz-Rid
X-Client-IP
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Fastly-Request-ID
X-HW
SPRequestDuration
SPIisLatency
X-Forwarded-Proto
X-DIS-Request-ID
Arr-Disable-Session-Affinity
X-Wix-Server-Artifact-Id
Realpath
X-Accel-Buffering
X-Oracle-Dms-Rid
X-Server-ID
X-DynaTrace-JS-Agent
X-B
X-F-Cache
X-Upstream
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Amz-Meta-S3cmd-Attrs
Service-Worker-Allowed
X-Ser
X-Via-JSL
X-Pinterest-Rid
Pinterest-Version
X-FTR-Balancer
X-FTR-DC
X-FTR-Backend-Server
X-FTR-Backend
X-Id
X-Country-Code-Real
X-FTR-Realm
X-FTR-Cache-Status
X-Dw-Request-Base-Id
Paypal-Debug-Id
X-FTR-Expires
AR-Request-ID
Front-End-Https
X-Vcap-Request-Id
X-Varnish-Age
X-Dns-Prefetch-Control
X-Debug
X-Goog-Storage-Class
X-Acc-Meta-Resource-Type
Ar-Sid
X-MSEdge-Ref
Nginx-Cache
X-N
X-Hits
X-Kinsta-Cache
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-NF-Request-ID
X-NewRelic-App-Data
X-FTR-Cache-Host
X-Logged-In
X-Mrf-Section-Lastmod
S
X-Mrf-Item-Lastmod
MRF-Tech
Mrf-Cache-Status
X-Ttl
X-B3-TraceId-Primal
X-Akam-SW-Version
X-XRDS-Location
X-Grace
X-Forwarded-For
X-Frontend
X-PressLabs-Stats
X-DataStream-Cache-Status
X-User-Agent
X-HS-Content-Id
X-HS-Hub-Id
Tracecode
Alternate-Protocol
X-Amzn-Trace-Id
AMP-Access-Control-Allow-Source-Origin
DynaTrace
X-CACHE-GROUP
Server-Name
X-FastCGI-Cache
X-Pad
X-Content-Digest
Refresh
X-Cache-Key
X-Content-Options
X-Analytics
X-TA-CDN-Provider
Powered-By-ChinaCache
Backend-Timing
MicrosoftSharePointTeamServices
X-Content-Type
Fastcgi-Cache
Accept-Charset
X-LB-Cache
X-Az
X-Activity-Id
X-Zen-Fury
X-AppVersion
X-IPLB-Instance
FilterID
TCN
X-Page-Id
Host
X-Rid
X-Middleton-Display
X-Debug-Info
X-Sol
Display
X-CF-Powered-By
MS-CV
Access-Control-Request-Method
ServerID
X-Magnolia-Registration
TP-L2-Cache
TP-Cache
Cache-Status
X-Middleton-Response
X-XRDS-LOCATION
Response
X-Cache-Hit
X-Fastcgi-Cache
X-ATG-Version
X-Content-Powered-By
X-Mobile
X-Seen-By
X-Srv
X-WA-Info
Surrogate-Key
X-Hostname
X-RateLimit-Remaining
X-VCache
X-B3-Sampled
X-Revision
Rt-Fastcgi-Cache
X-Cached-By
X-Varnish-Backend
X-Request-Received
X-Request-Processing-Time
X-GUploader-UploadID
X-SS-Set-Cookie
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Signature
X-Cluster
X-Cache-Action
X-B-Cache
X-Instance
X-Cache-Age
X-Content-Security-Policy-Report-Only
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-0
X-PHP-Backend
X-Drupal-Cache-Tags
Source
X-Whom
X-Request-Guid
Cleartype
X-Handled-By
X-Framework
Host-Header
X-TT
X-Akamai-Edgescape
X-Platform-Server
X-App-Environment
X-Origin-Server
X-Wix-Request-Id
ViewerVersion
X-Ruxit-Js-Agent
X-Edge-Location
Server-Info
X-Cache-Control
X-BCube-Filmed-By
DC
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Generated-By
X-App-Server
X-Geo-Country
X-FW-Type
X-FW-Hash
X-FW-Static
X-FW-Serve
X-FW-Server
X-NWS-LOG-UUID
X-Real-IP
X-Cache-Rule
X-Varnish-Hostname
X-Oneagent-Js-Injection
X-AOL-HN
Server-Node
X-Varnish-Server
Retry-After
Fusion-Content-Id
Fusion-Component-Id
Fusion-Template-Id
Fusion-Content-Source
Fusion-Source
X-Cache-2
Eomportal-Instance
X-Correlation-Id
X-FB-Debug
Payment
Webserver
X-WPE-Loopback-Upstream-Addr
X-Amz-Server-Side-Encryption
X-Response-Served-From
X-TT-TIMESTAMP
Actual-Object-TTL
X-Varnish-Grace
Access-Control-Allow-Method
X-Device-Type
AsisCache
X-Varnish-Hits
X-Tumblr-Pixel-1
ServedBy
X-Tumblr-Pixel-2
GEO-INFO
NGB
Content-Style-Type
X-RTag
X-WebKit-CSP-Report-Only
Ms-Operation-Id
Content-Script-Type
X-Cacheable-TTL
X-Region
X-UUID
Filters
X-Jobs
X-Adobe-Content
X-Amz-Replication-Status
X-Varnish-IP
Viewport
X-Adobe-Loc
X-Servedby
Cache
Healthy
X-Contextid
Upgrade-Insecure-Requests
X-Locale
Country
X-Rendered-As
X-Drupal-Cache-Contexts
X-TX-ID
X-Cache-Config
X-RequestSource
X-UA-Device-Type
Cache-Tv-Group
From-Origin
X-Accel-Expires
Edge-Cache-Tag
HitType
X-Ezoic-Cdn
X-BACKEND-TTL
X-Cache-TTL-Remaining
X-Cache-Remote
X-Cache-Server
X-VG-WebCache
X-Cache-TTL
Fastcgi-Useragent
Pagespeed
X-Cache-Operation
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-FW-Dynamic
X-Content-Age
Fastly-Restarts
X-APP-VERSION
Cache-Tags
X-Hit
X-Upgrade-Enabled
X-Storage
X-Redis-Cache
X-S
X-Esi
Datacenter
X-Mode
X-Source
Cache-Tag
X-App-Version
X-RateLimit-Limit
Served-By
X-Upstream-Proxy
NtCoent-Length
Machine
X-NCache
X-Detected-As
Origin-Cache-Control
X-NGENIX-Cache
X-JoinUs
X-Is-Bot
X-Generated
X-Hl-Ver
X-Internal-Host
X-Akamai-Request-ID
X-Cache-Var-Map
X-Backend-Name
X-Rule
X-GeoIP
Load-Balancing
Origin-Edge-Control
X-RN-RSRV
X-Path-Route
SRV
X-Cache-Var
X-Origin-Response-Time
Xserver
Meta-Geo
X-Edge-IP
X-CDN-Cache
X-Environment-Context
X-FC-Vary-Parameters
X-Hosted-By
X-Grey
X-Cache-Category-Id
X-BYPASS-REASON
X-Agile
Selected-FE
X-Agile-Age
X-Agile-Id
X-Birta-Served
X-Birta-Cache-Post
X-Labrador-Cache-Channel
X-Loop
X-TNCMS
X-Timing-Wait
X-Web-Node
X-Www-Served-By
X-Tb
Vix-Hermes-Req-Id
X-ServerID
X-Pubstack
X-Proxy
X-Origin-Host
X-Proxy-Build
X-ProxyCache-Key
X-ProxyCache-Status
Now
X-L-Path
X-Akamai-Transformed
TWC-Locale-Group
TWC-Privacy
Webcakes-App-Name
Webcakes-App-Version
TWC-GeoIP-LatLong
Webcakes-Region
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-Country
Property-Id
X-PERF
X-Viewer-Country
X-Via-Fastly
X-IP
X-Origin-Hint
X-Pc-Appver
X-ApacheServer
X-Pc-Key
X-Pc-Hit
Cache-Name
X-ProcessESI
X-Time-Microsecs
X-Status
X-Cache-NE
X-Varnish-Cacheable
X-Varnish-Cache-Hits
X-RemovedCookies
X-Site-Version
X-Debug-Cache
X-DataStream-MidMile-RTT
S-Rt
Cache-Key
X-Format
X-DataStream-Origin-MEX-Latency
X-Guploader-Uploadid
Azure-SlotName
Azure-Version
Azure-SiteName
Azure-RegionName
Azure-InstanceId
X-Daa-Tunnel
X-Human
Fastcgi-X-Cache-Version
DB-Nickname
We-Hiring
X-Section
X-Access
X-Cache-Enabled
X-OCL
X-CCM
X-PCL
X-Routing-Service
X-Zipkin-Id
X-Proxied
X-CACHE-KEY
X-Xfnlog-Site
X-MP-GENERATED-AT
X-VG-TLSProxy
Mail-Subject
X-App-Name
Public-Key-Pins-Report-Only
X-Original-Request
Access-Control-Request-Headers
X-Origin
X-Microcachable
X-UA
X-Sucuri-ID
X-Ocache
X-EdgeConnect-Cache-Status
X-Protected-By
Liferay-Portal
User-Cache-Control
X-Request-Time
X-Nginx-Cache
S-Cnection
X-GEO
X-Cdn-Forward
X-FW-Version
User-Agent
LB
X-Tumblr-Pixel-3
X-Webstats-RespID
Cache-Hits
X-Proto
Ohc-File-Size
X-GRACE
X-Node-Name
X-FB-TRIP-ID
X-Nc
X-Trace-Id
X-Yottaa-Optimizations
X-ES-SERVER
PageSpeed
X-Origin-CC
X-Yottaa-Metrics
Powered
X-Correlation-ID
X-Endurance-Cache-Level
X-Varnish-Beresp-Grace
X-Forwarded-Host
X-Varnish-Beresp-Status
Frame-Options
X-Upstream-HT
X-Parent-Response-Time
X-Upstream-CT
X-Pc-Host
X-Pc-Date
L5d-Success-Class
X-Time
Section-Io-Cache
X-OVcl
X-OVcl-Cache
X-Pc-Subdomain
IBM-Web2-Location
X-ElasticPress-Search
X-Unique-ID
X-Cache-Backend
X-Ua
X-Origin-TTL
X-V
AR-SID
X-Rocket-Nginx-Bypass
OT-Force-Account-Verify
X-Varnish-Beresp-Ttl
X-AWS-Id
X-Vgn-Hpd-Reason
Nel
X-LJ-Flow-ID
X-VWS-Id
X-R9-Blue-Green-Version
Xc-Version
Rendered-Blocks
Fly-Request-Id
Fly-Cache
GMS-Ver
MD5-Digest
Memcached
Fastly-SWR
Fastly-SIE
BehaviorPad-Version
Cache-Prefix
Country-Code
Ec-Rule-Version
Meta-Geo-Continent
Mobile-Detection-Method
X-Amz-Meta-Cache-Control
X-Aed
X-Application
X-ARC
X-Auto-Login
X-Accel-Expires-Debug
Www
Node
Powered-By
Resin-Trace
Viewtype
X-B-Cookie
X-Cache-URL
X-Li-Pop
X-Li-Fabric
X-LI-Proto
X-LI-UUID
X-NU-AKA-ACS-Version
X-Micro-Cache
X-Irp-Debug
X-ServiceProvider
X-Transaction
X-IN-APIGATEWAY
X-SRCache-Key
X-IN-SSL-APIGATEWAY
X-Info
X-IN-WAF
X-Origin-Date
X-Origin-Expires
X-Rojux
X-Rewrite-Enabled
X-S-Cookie
X-S-Maxage
X-Server-By
X-ScT
X-Request-UUID
X-Region-Sid
X-PHP-Host
X-PAYTM-SRV-ID
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Reboot
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Generated-In
X-VG-WebServer
X-Cache-Info
X-User
X-UE-Client-Country
X-Cdn-Srv
X-Server-Group
X-Cache-Id
X-Cache-Host
X-Cache-Bucket
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-We-Are-Hiring
X-Cache-FS-Status
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-External-Request-Id
X-Twitter-Response-Tags
X-Fetched-On
X-TT-LOGID
X-From
X-Trv-Group
X-DPWN-IS-SECURE
X-Distil-CS
X-Date
X-Connection-Hash
X-Destination
X-Developer
Arc-Country
X-BB-ID
VivaBuild
X-Edge-Cache-Key
X-Edge-Cache
X-Server-Cache
Fastcgi-X-Cache
X-TIME
CACHE
HostName
X-Dynatrace-Js-Agent
X-Cluster-Node
X-Dc
X-Passed-To
X-Node-Id
X-Passed-To-BeforeDispatch
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-G
X-NX-Host
True-Client-Country-4JS
Thinkindot-Control
X-Passed-To-DLL
X-Debug-Log
X-Proxy-Upstream
X-Fastly-Cache
X-RateLimit-Limit-Second
Request-Time
X-Proxy-Cache-Status
X-FireWall-Port
Server-Host
X-Gen-Mode
SD-X-WS
X-Passed-To-PostProcessResponse
X-A
X-Backend-Url
X-Bip
X-Backend-Host
X-Level-Front-Cache
Mn-Server-Ip
X-Block-Status
X-C
X-Cache-Expires
X-Cache-Debug
X-Hash
X-Hnp-Log
X-Location
X-Alternate-Cache-Key
X-A-Dam
X-A-Dcw
X-A-Ccd
X-RateLimit-Remaining-Second
X-Nginx-Cache-Key
X-A-Dgt
X-A-Wwc
X-Logtrace-Id
X-Matched-Rule
X-Actual-URL
X-Generated-On
Who
X-Clientip
X-Thinkindot-L3
X-Thanos
X-CUA
X-Via-NSCOPI
Fastly-Soc-X-Request-Id
X-Swa-Ws
X-Svr
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Cache-Grace
X-Stale
Fastly-Backend-Name
X-D
X-Variation
Content-Disposition
X-Varnish-Action
Adler-Geo
Backend
Countrycode
X-Var-Ttl
Decoy-Debug-TTL
Decoy-Debug-Status
Decoy-Debug-Key
X-Debug-Cookies
Is-Eu
On-Server
Origin
X-Returned-From-DLL
X-Returned-From-PostProcessResponse
X-Dispatcher-Server
X-Returned-From-BeforeDispatch
X-Returned-From
X-Request-URI
X-Distributor
Platform
X-Response-By
X-Crawler
X-Core-Mission
Ajk
Magicmarker
Lfy
X-SIPLIST1
IsBot
X-Shopify-Stage
X-ShopId
X-Server-IP
X-ShardId
X-Sucuri-Cache
X-Via-CDN
Warning
X-Device-Os
X-Died
X-Fstrz
X-Generation-Time
X-Developers
AKAMAI
X-CGP
X-Sf
X-Epic-Correlation-Id
X-Eu-Site
X-Backend-State
HA-Ipaddr
Ha-Gx-Prefs
X-Varnish-Authentication
X-UnsetCookies
X-Gannett-Site-Version
X-GeoIP-Country-Code
X-MSEdge-Flight
X-MSEdge-Features
X-Key
X-No-Session
X-Secret
X-Qloud-Router
X-Policy
X-Platform
X-Instart-Isnd
X-F5-Cache
Release
X-SERVER
RNT-Machine
RNT-Time
Fastly-SSL
GW-Server
Heartbleed
Pagetype
X-Cache-ASPX
Pramga
Proxy-Connection
CDCHOST
Server-Cache-Control
SS
Server-Surrogate-Control
X-Core-Value
X-Croise-Owner
Web-Mar-Node
Cache-Cookie-Set-From
Cache-Cookie-Set-Idcheck
Server-Int
Cache-Cookie-Set-Lfrom
X-HS-Cache-Config
Server-ID
X-LAGOON
REQUESTUUID
X-TrackingId
X-Debug-Cache-Expiry
X-Amz-Meta-Surrogate-Control
X-Debug-Cache-Store
Apple-News-Services-Host
Apple-News-Services-Handled
X-EIG-Tracking-Id
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
X-Server-Time
X-Debug-Cache-Fetch
X-Up
X-CLOUD-TRACE-CONTEXT
Version
X-Page-Type
NGX
Kp-EeAlive
X-Sedo-Request-Id
X-Varnish-Url
X-Cache-Miss-From
X-Pjax-Url
X-Be
PFcat
RequestId
X-B3-Traceid
X-Servername
X-CDN-Forward
X-Ratelimit-Remaining
X-Varnish-Ttl
SID
X-Newrelic-App-Data
X-Refresh
X-Owner
X-B3-SpanId
X-Store
Esi-Enabled
X-SN
X-Cache-CFC
X-URL
Time
X-RCS-CacheZone
X-Layer
MI-API
Odigeo-Trace-Id
MI-Cache
MIME-Version
X-From-Cache
MI-Cache-Age
X-Oss-Storage-Class
X-Oss-Server-Time
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-MI-In-Market
X-Oss-Request-Id
Cdn
X-NC
X-IPS-LoggedIn
X-RequestId
PICS-Label
Cteonnt-Length
Mime-Version
X-FPC
HA-Geocountry
HA-Georegion
HA-Geolat
HA-Geocity
HA-Geolon
X-Litespeed-Cache
HA-Host
HTTPS
HA-Cloudapp
HA-Servedtime
HA-Urlpath
FastCGI-Cache
X-Ratelimit-Limit
Cdn-Host
X-Unique-Id-Primal
X-Mshield-Cache-Status
X-Edge-Server
X-Mrs-Cache
X-Mrs-Age
Backend-Name
X-Servedbyhost
X-Mrs-Cache-Hits
Cdn-Request-Time
X-Hyper-Cache
Hostname
CF-IPCountry
X-Geo
Processtime
X-Webkit-Csp
X-Req
X-Load-Cache
X-CSRF-TOKEN
X-Real-Ip
Memory
X-CMS-Context
X-Webkit-CSP
ProcessTime
X-WebServer
Cf-Ipcountry
X-Wa
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
Ohc-Response-Time
X-Mobile-URL
X-Phone
X-Instart-Info
X-B3-Spanid
CDN
X-WR-MODIFICATION
X-NodeID
X-DC
X-Request-Start
X-Pf-Uncompressing
X-HS-Combine-CSS
X-Varnish-Beresp-TTL
Cross-Origin-Window-Policy
X-VServer
X-GZip
GeoIP-Country-Code
X-Release
X-Newrelic-Synthetics
X-Lb-Id
GeoIP-Latitude
X-NODE
X-Aicache-OS
X-HTML-Minification-Powered-By
XServer
X-Skip-Cache
X-Fastly-Country-Code
X-PF-Uncompressing
X-Atg-Version
X-WA
X-Server-W
Ohc-Cache-HIT
URI
X-ND-Cache
Accept-Ch-Lifetime
X-VC-Cache
X-Served-From
Rt-Proxy-Cache
X-FORWARDED-FOR
T-Server
Amp-Access-Control-Allow-Source-Origin
X-Unique-Id
X-Oracle-Dms-Ecid
Uber-Trace-Id
X-Cms-Context
X-Tb-Optimization-Total-Bytes-Saved
X-GoCache-CacheStatus
X-Nananana
X-APP
N-Cache
X-Gateway-Cache-Key
X-ServedByHost
X-MServer
X-UCC
X-Gateway-Cache-Status
X-Gateway-Skip-Cache
X-COUNTRY
X-CSRF-Token
X-LB-ID
X-Cdn-Origin
X-SRV
X-Datadome
X-Worker
V-Age
X-Sn-Servicetimems
Pics-Label
X-SVT-ORM-VERSION
X-HS-Status
X-SVT-ORM-RULES
A
X-Fastly-Cache-Hits
X-UPSTREAM-Address
X-Processor
Proxy-Firewall
X-LiteSpeed-Cache-Control
X-SERVER-NAME
X-BBXSRF
DataCenter
X-Hp-Webp
Get-Access-Time
Is-Session-Tracking
X-CACHE-AGE
X-P-T
X-GZIP
X-Requestid
ServerName
X-Check-Cacheable
Cneonction
X-NGINX-Cache
X-Optimization
X-Cache-HT
Geoip-Latitude
X-PAGE-TYPE
X-Varnish-URL
X-Vcache
X-RCS-Backend
X-ID
Dnion-Transfer-Encoding
X-BE
X-HostName
X-Vg-Webcache
X-Shard
X-Backend-TTL
X-GDPR
Requestid
X-StackifyID
GeoIp-Country-Code
X-Amzn-Remapped-Content-Length
X-ServerName
Host-ID
X-PJAX-URL
X-Geo-Header
X-Port
WP-Super-Cache
X-Csrf-Token
X-VCT
X-GeoIP-City
X-Fe
Serverid
X-NWS-UUID-VERIFY
UCS
X-Git-Hash
Cache-Provider
X-Org
Inserted-Into-Cache-At
Server-Id
X-Dw-Trace-Id
WZWS-RAY
RequestUuid
X-LiteSpeed-Tag
188prxHost
178proxuri
DSUID
219prxHost
X-Fastly-Backend-Reqs
286prxHost
225prxHost
189phosttRef
409pxxline
352pxline
X-Via-Edge
X-Via-SSL
X-CS
X-Request-Url
355prline
Xxline
X-RAMCache