Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
CF-RAY
ETag
Link
Expect-CT
Via
X-XSS-Protection
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Xss-Protection
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Request-Id
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Adblock-Key
X-Check
Alt-Svc
X-Cacheable
X-Generator
Content-Security-Policy-Report-Only
X-AspNetMvc-Version
X-Cache-Status
X-DNS-Prefetch-Control
X-Permitted-Cross-Domain-Policies
X-Template
X-Iinfo
X-Language
Status
Timing-Allow-Origin
X-Buckets
X-FRAME-OPTIONS
X-Content-Security-Policy
Content-Encoding
X-Kinja-Server-Push
Xkey
X-CDN
X-Turbo-Charged-By
Upgrade
X-Type
Keep-Alive
Access-Control-Expose-Headers
WPE-Backend
X-Pass-Why
X-AH-Environment
X-Backend
Access-Control-Max-Age
X-Age
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Server
X-Proxy-Cache
X-Via
X-Request-ID
Grace
X-Pingback
X-Nginx-Cache-Status
X-Server-Powered-By
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Hacker
X-Varnish-Cache
X-UA-Device
X-Page-Speed
EagleId
Request-Context
X-Envoy-Upstream-Service-Time
Cf-Railgun
X-LiteSpeed-Cache
X-CST
X-Ua-Compatible
X-Swift-CacheTime
X-Swift-SaveTime
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Ali-Swift-Global-Savetime
X-Server-Id
X-Device
X-Amz-Version-Id
X-WebKit-CSP
Server-Timing
X-Ac
X-Node
Allow
X-OneAgent-JS-Injection
Feature-Policy
X-Response-Time
X-Rq
X-Cnection
X-Iejgwucgyu
Content-Location
X-Backend-Server
X-Cache-Lookup
Report-To
EagleEye-TraceId
Surrogate-Control
X-Host
X-Readtime
X-Application-Context
Request-Id
X-ORACLE-DMS-ECID
P3p
X-Rack-Cache
X-Url
X-Origin-Cache
X-Clacks-Overhead
X-Country
NEL
X-FTR-Request-ID
Rating
X-Country-Code
X-Cloud-Trace-Context
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-DataDome
X-Ruxit-JS-Agent
X-Cdn
X-Px
X-Instart-Request-ID
X-Mod-Pagespeed
Charset
X-Vhost
X-VARITI-CCR
X-MS-InvokeApp
Accept-CH
Pinterest-Generated-By
X-Goog-Hash
Edge-Control
Verso
X-GitHub-Request-Id
X-TtlSet
X-PC
X-Upstream-Env
X-Vname
X-Server-Name
PB-RID
PB-PID
Arc-Version
X-Mobile-Rewrite
X-ESI
X-Version
X-DynaTrace
X-Origin-Upstream-Status
X-Powered-By-Plesk
X-Dns-Prefetch-Control
X-D2id
X-GoogleNews-Bot
X-Use-Magma
X-Kinja
X-Kinja-Revision
X-Cdn-Fetch
X-Kinja-Build
X-Exp-Variant
X-Exp-Id
X-Kinja-Server
X-Cached
X-B3-TraceId
X-ORACLE-DMS-RID
X-Dispatcher
X-TTL
SPRequestGuid
X-Recruiting
X-Varnish-TTL
X-SharePointHealthScore
X-Abt-Application-Version
MS-Author-Via
X-Powered-CMS
Accept-CH-Lifetime
RTSS
X-Navigation-Version
Content-MD5
AR-PoweredBy
AR-CACHE
AR-ATIME
X-T
X-Shield-Request-Id
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Public-Key-Pins
X-Trace
X-DynaTrace-JS-Agent
X-Forwarded-Proto
X-Client-IP
Arr-Disable-Session-Affinity
X-Amz-Rid
X-HW
X-Fastly-Request-ID
X-Wix-Server-Artifact-Id
X-Accel-Buffering
SPRequestDuration
SPIisLatency
Realpath
X-DIS-Request-ID
Service-Worker-Allowed
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Length
Paypal-Debug-Id
AR-Request-ID
X-Amz-Meta-S3cmd-Attrs
X-Oracle-Dms-Rid
Front-End-Https
X-Upstream
X-Ser
X-B
X-FTR-Backend
X-FTR-DC
X-Country-Code-Real
X-FTR-Realm
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Cache-Status
X-Ttl
Pinterest-Version
X-FTR-Expires
X-Pinterest-Rid
X-F-Cache
X-Id
X-XRDS-Location
X-Via-JSL
X-Dw-Request-Base-Id
X-Vcap-Request-Id
Ar-Sid
X-Debug
X-Varnish-Age
X-Goog-Storage-Class
X-Acc-Meta-Resource-Type
X-MSEdge-Ref
X-Kinsta-Cache
X-N
X-Server-ID
Nginx-Cache
X-Hits
X-NF-Request-ID
X-DataStream-Cache-Status
X-FTR-Cache-Host
S
X-NewRelic-App-Data
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Logged-In
X-TEC-API-VERSION
X-Akam-SW-Version
MRF-Tech
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Mrf-Item-Lastmod
X-Forwarded-For
Tracecode
Alternate-Protocol
X-Frontend
X-Grace
X-User-Agent
X-PressLabs-Stats
X-HS-Hub-Id
X-HS-Content-Id
X-Amzn-Trace-Id
X-FastCGI-Cache
AMP-Access-Control-Allow-Source-Origin
TCN
Server-Name
X-Content-Options
X-Content-Digest
X-CACHE-GROUP
Refresh
Powered-By-ChinaCache
Display
X-Middleton-Display
X-Sol
X-Content-Type
Access-Control-Request-Method
X-Pad
DynaTrace
X-Analytics
MicrosoftSharePointTeamServices
Backend-Timing
X-CF-Powered-By
X-LB-Cache
FilterID
X-Debug-Info
X-Zen-Fury
X-AppVersion
X-Activity-Id
X-Az
X-IPLB-Instance
X-Rid
X-Page-Id
Response
Host
X-Middleton-Response
Fastcgi-Cache
Accept-Charset
X-Cache-Key
X-VCache
ServerID
MS-CV
X-Hostname
Cache-Status
X-Cache-Hit
TP-L2-Cache
X-Magnolia-Registration
X-RateLimit-Remaining
TP-Cache
X-Srv
X-Seen-By
X-Content-Powered-By
X-GUploader-UploadID
X-Fastcgi-Cache
X-ATG-Version
X-Mobile
X-Revision
X-Cached-By
X-WA-Info
X-Varnish-Backend
X-Request-Processing-Time
X-Request-Received
Host-Header
Surrogate-Key
X-Whom
X-B3-Sampled
X-Instance
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-SS-Set-Cookie
Server-Info
X-Cache-Action
X-Cluster
X-Platform-Server
X-Request-Guid
X-Tumblr-Pixel-0
X-Handled-By
X-Drupal-Cache-Tags
DC
Source
X-Content-Security-Policy-Report-Only
X-Tumblr-User
X-Tumblr-Pixel
X-Wix-Request-Id
X-Signature
X-PHP-Backend
X-B-Cache
X-Real-IP
Cleartype
ViewerVersion
X-Framework
X-Akamai-Edgescape
X-TT
X-Origin-Server
Fusion-Template-Id
X-Amzn-RequestId
X-Amz-Apigw-Id
Fusion-Component-Id
Fusion-Content-Id
Fusion-Content-Source
Fusion-Source
X-Cache-Age
X-App-Environment
Rt-Fastcgi-Cache
X-Geo-Country
X-App-Server
X-FW-Type
X-Generated-By
X-FW-Server
X-FW-Static
X-FW-Serve
X-FW-Hash
X-AOL-HN
X-Varnish-Server
X-BCube-Filmed-By
X-Cache-Control
Server-Node
X-Oneagent-Js-Injection
X-Edge-Location
X-TA-CDN-Provider
X-Varnish-Hostname
X-NWS-LOG-UUID
X-XRDS-LOCATION
X-Cache-Rule
Retry-After
X-Ruxit-Js-Agent
X-Upstream-Proxy
Payment
X-Correlation-Id
X-Varnish-Grace
X-Amz-Server-Side-Encryption
X-Cache-2
Access-Control-Allow-Method
X-Amz-Replication-Status
X-TT-TIMESTAMP
X-FB-Debug
X-Response-Served-From
Eomportal-Instance
X-Cacheable-TTL
X-Cache-Config
ServedBy
GEO-INFO
X-Varnish-Hits
X-Tumblr-Pixel-1
AsisCache
X-UA-Device-Type
Webserver
X-Tumblr-Pixel-2
X-Ezoic-Cdn
Actual-Object-TTL
Content-Style-Type
Filters
Content-Script-Type
X-Contextid
X-TX-ID
X-UUID
X-WebKit-CSP-Report-Only
X-RTag
X-Region
NGB
X-Drupal-Cache-Contexts
X-Jobs
Ms-Operation-Id
Healthy
X-Adobe-Loc
X-Adobe-Content
Upgrade-Insecure-Requests
X-Varnish-IP
X-VG-WebCache
Viewport
Cache-Tv-Group
Country
X-Locale
X-Rendered-As
X-RequestSource
X-Cache-TTL
From-Origin
HitType
X-Accel-Expires
Fastcgi-Useragent
X-Cache-TTL-Remaining
X-Device-Type
Pagespeed
X-BACKEND-TTL
X-FW-Dynamic
X-Cache-Server
Edge-Cache-Tag
X-Servedby
X-Content-Age
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Cache-Tags
X-WPE-Loopback-Upstream-Addr
X-Cache-Remote
X-Redis-Cache
X-Upgrade-Enabled
X-APP-VERSION
X-Cache-Operation
X-Source
Datacenter
Cache
X-DataStream-Origin-MEX-Latency
X-RateLimit-Limit
X-DataStream-MidMile-RTT
X-Hit
X-Storage
X-Esi
X-CACHE-KEY
Fastly-Restarts
X-GeoIP
X-Mode
Cache-Tag
NtCoent-Length
Served-By
X-S
X-Cache-Var-Map
X-TNCMS
X-Is-Bot
X-Hl-Ver
X-Detected-As
X-JoinUs
Meta-Geo
Machine
Load-Balancing
X-Labrador-Cache-Channel
X-Agile
X-NGENIX-Cache
X-Internal-Host
X-Agile-Age
X-RN-RSRV
X-Pubstack
X-Agile-Id
Vix-Hermes-Req-Id
X-Origin-Response-Time
X-Cache-Var
X-Backend-Name
X-Loop
X-Akamai-Request-ID
X-Path-Route
X-Time-Microsecs
Cache-Key
X-Hosted-By
X-Proxy
X-Status
X-BYPASS-REASON
X-Www-Served-By
X-Birta-Served
X-L-Path
X-Tb
X-FC-Vary-Parameters
Selected-FE
X-Edge-IP
X-Rule
X-Birta-Cache-Post
X-Environment-Context
X-ServerID
Origin-Edge-Control
X-Timing-Wait
Now
X-Grey
X-ProxyCache-Key
X-CDN-Cache
X-Generated
X-NCache
X-Origin-Host
X-Cache-Category-Id
X-ProxyCache-Status
X-Proxy-Build
Origin-Cache-Control
X-Varnish-Cache-Hits
Webcakes-App-Name
TWC-Privacy
Webcakes-App-Version
TWC-Locale-Group
Webcakes-Region
X-ApacheServer
TWC-GeoIP-Country
SRV
Property-Id
TWC-Connection-Speed
TWC-Device-Class
X-Cache-Enabled
TWC-GeoIP-LatLong
X-Format
X-Viewer-Country
X-Via-Fastly
S-Rt
X-Microcachable
X-IP
X-VG-TLSProxy
X-Varnish-Cacheable
X-Origin-Hint
X-PERF
X-ProcessESI
X-RemovedCookies
Cache-Name
X-Web-Node
Access-Control-Request-Headers
X-PCL
Azure-InstanceId
Azure-RegionName
Public-Key-Pins-Report-Only
X-Access
X-OCL
X-CCM
X-Akamai-Transformed
X-Human
X-MP-GENERATED-AT
Azure-SiteName
X-Section
Fastcgi-X-Cache-Version
DB-Nickname
Azure-SlotName
Azure-Version
X-GEO
User-Agent
X-Proxied
We-Hiring
X-App-Version
Cache-Hits
X-App-Name
X-Routing-Service
X-Zipkin-Id
X-Xfnlog-Site
X-Site-Version
X-Debug-Cache
Mail-Subject
Xserver
X-Daa-Tunnel
X-ES-SERVER
Liferay-Portal
CACHE
X-Node-Name
X-EdgeConnect-Cache-Status
S-Cnection
X-Protected-By
LB
X-FW-Version
X-Original-Request
X-Origin
X-Sucuri-ID
X-Cache-NE
X-Pc-Key
X-Pc-Hit
X-Pc-Appver
X-Guploader-Uploadid
X-Proto
X-Ocache
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Nginx-Cache
PageSpeed
User-Cache-Control
X-Trace-Id
Powered
X-Cdn-Forward
X-AWS-Id
X-Ua
X-UA
X-Request-Time
X-Forwarded-Host
X-LJ-Flow-ID
X-VWS-Id
X-Tumblr-Pixel-3
X-Endurance-Cache-Level
X-GRACE
L5d-Success-Class
X-Varnish-Ttl
Ohc-File-Size
X-Unique-ID
X-Webstats-RespID
Frame-Options
Section-Io-Cache
X-Cluster-Node
X-Correlation-ID
X-V
X-FB-TRIP-ID
X-Nc
X-Time
X-Origin-CC
OT-Force-Account-Verify
X-EIG-Tracking-Id
X-URL
X-OVcl
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-OVcl-Cache
X-Webkit-Csp
X-B3-Traceid
X-Origin-TTL
AR-SID
X-Cache-Backend
Decoy-Debug-TTL
X-ElasticPress-Search
Decoy-Debug-Key
Decoy-Debug-Status
Nel
X-From
X-Rocket-Nginx-Bypass
X-R9-Blue-Green-Version
Viewtype
Arc-Country
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Generated-In
X-IN-APIGATEWAY
X-Fetched-On
SD-X-WS
VivaBuild
X-Irp-Debug
X-Info
X-Accel-Expires-Debug
Www
X-IN-WAF
Rendered-Blocks
Country-Code
X-Cache-URL
On-Server
X-Cache-Info
X-Cdn-Srv
X-CF-Lambda-Fn
X-B-Cookie
X-Connection-Hash
X-CF-Lambda-Version
X-Cache-Id
X-Cache-Host
Meta-Geo-Continent
X-BB-ID
Mobile-Detection-Method
Memcached
Node
X-Cache-Grace
X-Cache-FS-Status
MD5-Digest
X-Auto-Login
GMS-Ver
X-Amz-Meta-Cache-Control
X-Backend-State
Ec-Rule-Version
X-Distil-CS
X-Aed
X-External-Request-Id
Cache-Prefix
X-DPWN-IS-SECURE
X-Developer
X-Destination
X-ARC
Fly-Request-Id
X-Date
X-Application
Powered-By
Fastly-SIE
Fastly-SWR
Fly-Cache
BehaviorPad-Version
Xc-Version
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-ServiceProvider
X-Reboot
X-SRCache-Key
X-VG-WebServer
X-Wikidot-Backend
X-We-Are-Hiring
X-Twitter-Response-Tags
X-Parent-Response-Time
X-Region-Sid
X-Request-UUID
X-User
X-S-Cookie
X-Rojux
X-Rewrite-Enabled
X-S-Maxage
X-ScT
X-Response-By
X-Server-Group
X-Server-By
X-Wikidot-Static-Cache
X-UE-Client-Country
X-PAYTM-SRV-ID
X-Origin-Date
X-TT-LOGID
X-NU-AKA-ACS-Version
X-Origin-Expires
X-Node-Id
X-Trv-Group
X-Transaction
X-PHP-Host
X-Dc
IBM-Web2-Location
X-Thinkindot-L3
X-Block-Status
X-Cache-Bucket
X-C
Who
True-Client-Country-4JS
Thinkindot-Control
Thinkindot-CacheControl-Type
X-Secret
X-A-Ccd
X-Cache-Expires
X-Server-IP
X-Cache-Debug
X-Sf
X-Stale
X-A-Wwc
X-CGP
X-A-Dgt
X-Thanos
X-Alternate-Cache-Key
X-Swa-Ws
X-Actual-URL
X-Svr
X-Sorting-Hat-ShopId
X-Backend-Host
X-ShardId
X-Bip
X-A-Dcw
X-ShopId
X-Backend-Url
X-Sorting-Hat-PodId
X-SIPLIST1
X-Shopify-Stage
X-A-Dam
X-Var-Ttl
X-Policy
Thinkindot-CacheControl
X-Platform
X-LAGOON
X-Level-Front-Cache
X-Hnp-Log
X-Vgn-Hpd-Reason
X-Varnish-Action
X-Generated-On
X-GeoIP-Country-Code
X-Hash
X-Passed-To-PostProcessResponse
X-Li-Fabric
X-Location
X-LI-UUID
X-Logtrace-Id
X-Matched-Rule
X-Micro-Cache
X-NX-Host
X-LI-Proto
X-Passed-To-DLL
X-Passed-To-BeforeDispatch
X-Li-Pop
X-Passed-To
X-Gen-Mode
X-Gannett-Site-Version
X-Nginx-Cache-Key
X-Returned-From-BeforeDispatch
X-Returned-From
X-Debug-Cookies
X-Debug-Log
X-Returned-From-DLL
X-D
X-Returned-From-PostProcessResponse
X-Core-Mission
X-Crawler
X-CUA
X-Request-URI
X-Variation
X-Fastly-Cache
X-Proxy-Upstream
X-Proxy-Cache-Status
X-G
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Dispatcher-Server
X-Distributor
X-Epic-Correlation-Id
X-Eu-Site
X-Clientip
X-A
Countrycode
X-Via-CDN
Is-Eu
Ha-Gx-Prefs
Platform
Request-Time
Ajk
Proxy-Connection
Mn-Server-Ip
IsBot
Adler-Geo
Lfy
CDCHOST
Origin
HA-Ipaddr
Magicmarker
Content-Disposition
Fastly-Backend-Name
Fastly-SSL
Fastly-Soc-X-Request-Id
Server-Host
X-Varnish-Beresp-Ttl
Backend
Warning
X-TIME
X-Sucuri-Cache
Hostname
X-HS-Cache-Config
Cache-Cookie-Set-From
X-SERVER
X-F5-Cache
X-Core-Value
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-Debug-Cache-Store
X-Developers
X-Device-Os
X-MSEdge-Features
X-Croise-Owner
X-Instart-Isnd
Cache-Cookie-Set-Lfrom
X-No-Session
X-MSEdge-Flight
GW-Server
Cache-Cookie-Set-Idcheck
X-Cache-ASPX
RNT-Time
X-Varnish-Authentication
RNT-Machine
Resin-Trace
AKAMAI
Server-Cache-Control
Web-Mar-Node
Server-Surrogate-Control
Server-Int
X-UnsetCookies
X-Up
Apple-News-Services-Handled
Release
SID
X-Fstrz
X-FireWall-Port
Heartbleed
X-Qloud-Router
Apple-News-Services-Request-Url
SS
Apple-News-Services-Host
Pramga
X-Amz-Meta-Surrogate-Control
Apple-News-Services-Parsed-Url
X-TrackingId
X-Upstream-HT
X-Pc-Date
X-Upstream-CT
X-Pc-Host
X-Pc-Subdomain
Pagetype
X-SN
NGX
X-Owner
Kp-EeAlive
REQUESTUUID
X-Key
X-Page-Type
X-Server-Time
X-Be
X-Varnish-Url
X-Servername
Odigeo-Trace-Id
X-Server-Cache
X-Pjax-Url
X-Sedo-Request-Id
X-IN-SSL-APIGATEWAY
Server-ID
X-Cache-Miss-From
X-Generation-Time
X-CDN-Forward
Fastcgi-X-Cache
X-Refresh
X-Via-NSCOPI
X-Newrelic-App-Data
X-Died
HTTPS
MIME-Version
X-NC
X-Oss-Storage-Class
Cdn-Host
Cdn-Request-Time
X-Oss-Server-Time
X-Oss-Request-Id
X-From-Cache
X-Oss-Hash-Crc64ecma
RequestId
X-Edge-Server
X-Oss-Object-Type
X-B3-SpanId
X-Edge-Cache
X-Edge-Cache-Key
X-Servedbyhost
Version
HostName
ProcessTime
PFcat
X-FPC
Cteonnt-Length
Time
X-Req
Mime-Version
X-Mobile-URL
PICS-Label
Cdn
X-CSRF-TOKEN
FastCGI-Cache
X-Amzn-Remapped-Date
Cross-Origin-Window-Policy
X-Cache-CFC
Esi-Enabled
X-Amzn-Remapped-Connection
X-VServer
X-NodeID
X-Store
CF-IPCountry
X-Load-Cache
X-GZip
X-Litespeed-Cache
MI-API
X-Layer
X-RCS-CacheZone
Memory
X-Webkit-CSP
X-MI-In-Market
MI-Cache-Age
MI-Cache
X-HS-Combine-CSS
X-Hyper-Cache
Processtime
X-CLOUD-TRACE-CONTEXT
X-Dynatrace-Js-Agent
X-Wa
HA-Servedtime
HA-Cloudapp
HA-Georegion
HA-Geolon
HA-Geolat
X-RequestId
HA-Geocountry
HA-Geocity
X-Skip-Cache
X-IPS-LoggedIn
HA-Urlpath
HA-Host
X-Ratelimit-Remaining
CDN
X-Varnish-Beresp-TTL
X-HTML-Minification-Powered-By
X-Lb-Id
Uber-Trace-Id
Cf-Ipcountry
XServer
Ohc-Cache-HIT
X-DC
X-Aicache-OS
X-VC-Cache
X-Ratelimit-Limit
X-Pf-Uncompressing
X-Newrelic-Synthetics
X-Geo
Backend-Name
X-Fastly-Country-Code
X-Real-Ip
X-Cms-Context
X-B3-Spanid
X-CMS-Context
X-Gateway-Skip-Cache
N-Cache
X-WA
X-UCC
X-Gateway-Cache-Key
X-Gateway-Cache-Status
X-Mrs-Cache-Hits
X-Instart-Info
X-Mrs-Cache
X-PF-Uncompressing
X-Mshield-Cache-Status
X-Mrs-Age
X-Tb-Optimization-Total-Bytes-Saved
X-Atg-Version
X-Unique-Id-Primal
X-WR-MODIFICATION
X-Phone
X-WebServer
X-Shard
Ohc-Response-Time
Amp-Access-Control-Allow-Source-Origin
X-Nananana
URI
X-Release
X-Request-Start
GeoIP-Country-Code
T-Server
X-LB-ID
Accept-Ch-Lifetime
X-Processor
X-Server-W
GeoIP-Latitude
X-Hp-Webp
Pics-Label
X-Oracle-Dms-Ecid
X-BBXSRF
X-MServer
X-COUNTRY
X-Worker
X-Datadome
X-APP
X-SRV
X-LiteSpeed-Cache-Control
X-FORWARDED-FOR
X-Unique-Id
X-CSRF-Token
X-VCT
X-Served-From
Host-ID
X-Amzn-Remapped-Content-Length
Rt-Proxy-Cache
X-Geo-Header
X-ServedByHost
X-GeoIP-City
X-VHOST
X-ND-Cache
X-GoCache-CacheStatus
A
X-SERVER-NAME
UCS
DataCenter
X-HS-Status
X-CACHE-AGE
X-NGINX-Cache
Request-EU
X-GZIP
Request-Country
X-Requestid
X-Check-Cacheable
X-UPSTREAM-Address
X-Cache-HT
X-Fastly-Cache-Hits
X-Optimization
Cneonction
X-Cdn-Origin
Geoip-Latitude
V-Age
Dnion-Transfer-Encoding
X-BE
X-ID
X-Vcache
X-Planisys-CDN-Cache
Pragrma
X-Fpc
FSS-Cache
FSS-Proxy
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Sn-Servicetimems
X-Backend-TTL
Proxy-Firewall
X-Org
X-ServerName
X-SVT-ORM-RULES
WZWS-RAY
X-Git-Hash
X-SVT-ORM-VERSION
X-Fastly-Backend-Reqs
X-PAGE-TYPE
X-Varnish-URL
X-Port
Requestid
X-Csrf-Token
X-Dw-Trace-Id
WP-Super-Cache
X-PJAX-URL
Server-Id
GeoIp-Country-Code
Serverid
X-Gen-Id
Get-Access-Time
X-HostName
X-LiteSpeed-Tag
X-Html-Edge-Cache
Cache-Provider
X-Via-Edge
Is-Session-Tracking
RequestUuid
X-Via-SSL
X-P-T
X-NWS-UUID-VERIFY
Xxline
DSUID
X-CS
X-Request-Url
355prline
225prxHost
286prxHost
219prxHost
189phosttRef
188prxHost
352pxline
X-RAMCache
178proxuri
ServerName
Inserted-Into-Cache-At
X-Fe
X-StackifyID
409pxxline