Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
CF-RAY
ETag
Link
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Request-Id
X-Xss-Protection
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Adblock-Key
X-Check
Alt-Svc
X-Cacheable
X-Generator
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-Cache-Status
X-AspNetMvc-Version
X-Permitted-Cross-Domain-Policies
X-Template
X-Iinfo
X-Language
Status
Timing-Allow-Origin
X-Buckets
X-Content-Security-Policy
Content-Encoding
X-Kinja-Server-Push
Xkey
X-CDN
X-Turbo-Charged-By
Upgrade
X-Type
Keep-Alive
Access-Control-Expose-Headers
WPE-Backend
X-Pass-Why
X-AH-Environment
X-Backend
Access-Control-Max-Age
X-Age
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Server
X-Request-ID
X-Via
X-Proxy-Cache
Grace
X-Pingback
X-Nginx-Cache-Status
X-Server-Powered-By
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Hacker
X-Varnish-Cache
X-UA-Device
X-Page-Speed
EagleId
Request-Context
X-LiteSpeed-Cache
Cf-Railgun
X-Envoy-Upstream-Service-Time
X-Ua-Compatible
X-CST
X-Swift-CacheTime
X-Swift-SaveTime
X-Server-Id
Ali-Swift-Global-Savetime
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
X-WebKit-CSP
X-Amz-Version-Id
X-Ac
Server-Timing
X-Node
X-OneAgent-JS-Injection
Allow
Feature-Policy
X-Response-Time
X-Iejgwucgyu
X-Cnection
X-Rq
Content-Location
X-Cache-Lookup
X-Backend-Server
Report-To
EagleEye-TraceId
Surrogate-Control
X-Readtime
X-Host
X-Application-Context
Request-Id
P3p
X-ORACLE-DMS-ECID
X-Url
X-Rack-Cache
X-Origin-Cache
X-Clacks-Overhead
X-Country
NEL
X-FTR-Request-ID
Rating
X-Country-Code
X-Cloud-Trace-Context
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-DataDome
X-Cdn
X-Ruxit-JS-Agent
X-Instart-Request-ID
X-Px
X-Vhost
X-Mod-Pagespeed
Charset
X-MS-InvokeApp
X-VARITI-CCR
Accept-CH
Edge-Control
Pinterest-Generated-By
X-Goog-Hash
Verso
X-GitHub-Request-Id
PB-PID
Arc-Version
PB-RID
X-Mobile-Rewrite
X-PC
X-TtlSet
X-Vname
X-TTL
X-Server-Name
X-Version
X-DynaTrace
X-Powered-By-Plesk
X-B3-TraceId
X-Upstream-Env
X-D2id
X-ESI
X-Cached
X-GoogleNews-Bot
X-Exp-Id
X-Kinja
X-Cdn-Fetch
X-Exp-Variant
X-Kinja-Server
X-Use-Magma
X-Kinja-Revision
X-Kinja-Build
X-Varnish-TTL
X-Origin-Upstream-Status
X-Dispatcher
X-ORACLE-DMS-RID
SPRequestGuid
X-SharePointHealthScore
X-Powered-CMS
X-Recruiting
X-Abt-Application-Version
MS-Author-Via
Accept-CH-Lifetime
RTSS
X-T
X-Navigation-Version
X-Shield-Request-Id
Public-Key-Pins
Content-MD5
X-Trace
AR-ATIME
AR-PoweredBy
AR-CACHE
X-SRCache-Fetch-Status
X-DynaTrace-JS-Agent
X-SRCache-Store-Status
X-Amz-Rid
X-Client-IP
X-Fastly-Request-ID
Arr-Disable-Session-Affinity
X-Forwarded-Proto
X-HW
X-Wix-Server-Artifact-Id
X-Accel-Buffering
SPRequestDuration
SPIisLatency
Realpath
X-DIS-Request-ID
X-Oracle-Dms-Rid
X-B
X-Upstream
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
Service-Worker-Allowed
X-Goog-Generation
X-Amz-Meta-S3cmd-Attrs
X-F-Cache
X-Ser
X-Via-JSL
Pinterest-Version
X-Pinterest-Rid
Paypal-Debug-Id
Front-End-Https
AR-Request-ID
X-FTR-Backend
X-Country-Code-Real
X-FTR-Backend-Server
X-FTR-Realm
X-FTR-Cache-Status
X-FTR-DC
X-FTR-Balancer
X-FTR-Expires
X-Id
X-Dns-Prefetch-Control
X-Dw-Request-Base-Id
X-XRDS-Location
X-Vcap-Request-Id
X-Varnish-Age
X-Debug
X-Goog-Storage-Class
X-Acc-Meta-Resource-Type
X-MSEdge-Ref
X-Kinsta-Cache
Nginx-Cache
X-N
X-Hits
X-NF-Request-ID
X-TEC-API-VERSION
Ar-Sid
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Ttl
X-FTR-Cache-Host
X-Logged-In
S
X-B3-TraceId-Primal
X-Mrf-Section-Lastmod
X-DataStream-Cache-Status
X-Mrf-Item-Lastmod
MRF-Tech
Mrf-Cache-Status
X-Akam-SW-Version
X-NewRelic-App-Data
X-Frontend
X-Server-ID
X-User-Agent
X-HS-Hub-Id
X-HS-Content-Id
Tracecode
Alternate-Protocol
X-PressLabs-Stats
X-Grace
X-Forwarded-For
X-Amzn-Trace-Id
X-CACHE-GROUP
X-FastCGI-Cache
AMP-Access-Control-Allow-Source-Origin
Server-Name
X-Content-Digest
X-Content-Options
X-Pad
DynaTrace
Refresh
Powered-By-ChinaCache
X-Content-Type
TCN
X-Cache-Key
X-Analytics
Backend-Timing
X-Middleton-Display
Accept-Charset
MicrosoftSharePointTeamServices
X-Sol
X-Zen-Fury
Display
X-Az
Access-Control-Request-Method
X-AppVersion
X-Debug-Info
X-LB-Cache
X-Activity-Id
FilterID
X-CF-Powered-By
X-Page-Id
X-Rid
Host
X-IPLB-Instance
MS-CV
ServerID
Response
X-Middleton-Response
Fastcgi-Cache
TP-Cache
Cache-Status
TP-L2-Cache
X-Magnolia-Registration
X-RateLimit-Remaining
X-Cache-Hit
X-Hostname
X-Content-Powered-By
X-Fastcgi-Cache
X-Seen-By
X-TA-CDN-Provider
X-Mobile
X-VCache
X-WA-Info
X-GUploader-UploadID
X-Revision
X-ATG-Version
X-Srv
Surrogate-Key
X-Cached-By
X-B3-Sampled
X-Varnish-Backend
X-Request-Processing-Time
X-Request-Received
X-SS-Set-Cookie
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Instance
Host-Header
Rt-Fastcgi-Cache
X-Cache-Action
X-Whom
X-Cluster
X-B-Cache
X-Signature
X-Content-Security-Policy-Report-Only
X-Drupal-Cache-Tags
X-Platform-Server
X-Handled-By
X-Tumblr-User
X-Wix-Request-Id
Cleartype
X-Tumblr-Pixel-0
ViewerVersion
Server-Info
X-PHP-Backend
X-Tumblr-Pixel
X-Request-Guid
X-Origin-Server
Source
X-Akamai-Edgescape
X-Cache-Age
X-TT
X-Framework
X-App-Environment
DC
X-Edge-Location
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Cache-Control
X-BCube-Filmed-By
X-Generated-By
X-Oneagent-Js-Injection
X-Geo-Country
X-App-Server
Fusion-Content-Source
X-FW-Type
Fusion-Source
Fusion-Template-Id
Fusion-Content-Id
Fusion-Component-Id
X-FW-Serve
X-FW-Server
X-FW-Static
X-FW-Hash
Server-Node
X-Cache-Rule
X-AOL-HN
X-XRDS-LOCATION
X-Varnish-Server
X-NWS-LOG-UUID
X-Ruxit-Js-Agent
X-Real-IP
X-Varnish-Hostname
Retry-After
X-Cache-2
X-Correlation-Id
Eomportal-Instance
Payment
X-Amz-Server-Side-Encryption
X-FB-Debug
X-Varnish-Grace
Webserver
Actual-Object-TTL
Access-Control-Allow-Method
X-Response-Served-From
X-TT-TIMESTAMP
AsisCache
X-Cacheable-TTL
X-Varnish-Hits
X-Tumblr-Pixel-1
X-Tumblr-Pixel-2
X-Amz-Replication-Status
ServedBy
NGB
Content-Style-Type
GEO-INFO
X-WebKit-CSP-Report-Only
Healthy
X-Cache-Config
X-UUID
X-Region
Ms-Operation-Id
X-Drupal-Cache-Contexts
X-TX-ID
X-RTag
Content-Script-Type
X-Adobe-Loc
X-Contextid
Upgrade-Insecure-Requests
X-Servedby
X-Varnish-IP
X-Adobe-Content
X-Jobs
Viewport
X-Rendered-As
X-UA-Device-Type
X-Accel-Expires
Filters
X-Locale
Country
Cache-Tv-Group
X-Device-Type
X-Ezoic-Cdn
From-Origin
X-Esi
HitType
X-RequestSource
X-WPE-Loopback-Upstream-Addr
X-VG-WebCache
Cache
X-BACKEND-TTL
X-Cache-TTL-Remaining
Edge-Cache-Tag
X-Cache-Server
X-FW-Dynamic
Fastcgi-Useragent
X-Cache-Remote
X-Cache-TTL
X-Cache-Operation
Pagespeed
X-Content-Age
X-Upstream-Proxy
X-APP-VERSION
Fastly-Restarts
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Cache-Tags
X-Hit
X-Redis-Cache
X-RateLimit-Limit
X-Upgrade-Enabled
X-Source
X-Storage
Datacenter
X-S
X-Mode
X-DataStream-MidMile-RTT
Served-By
Cache-Tag
X-DataStream-Origin-MEX-Latency
X-Cache-Var-Map
X-Is-Bot
X-Internal-Host
X-JoinUs
X-Labrador-Cache-Channel
X-GeoIP
Load-Balancing
Machine
X-NCache
Meta-Geo
X-NGENIX-Cache
Origin-Cache-Control
X-Backend-Name
X-Cache-Var
X-Origin-Response-Time
X-Path-Route
X-RN-RSRV
Vix-Hermes-Req-Id
X-Hl-Ver
X-Tb
X-Rule
X-Detected-As
X-Time-Microsecs
Origin-Edge-Control
X-Akamai-Request-ID
SRV
X-Generated
X-Birta-Cache-Post
X-Edge-IP
X-Grey
Cache-Key
X-Status
X-Agile
X-Agile-Age
X-Loop
X-L-Path
X-Agile-Id
X-Environment-Context
X-Cache-Category-Id
X-ServerID
X-Www-Served-By
X-Origin-Host
X-ProxyCache-Status
X-Varnish-Cacheable
X-TNCMS
X-FC-Vary-Parameters
X-Hosted-By
X-BYPASS-REASON
X-ProxyCache-Key
X-CDN-Cache
X-Proxy
X-Pubstack
X-Web-Node
X-Birta-Served
Now
X-Varnish-Cache-Hits
NtCoent-Length
X-Akamai-Transformed
X-CACHE-KEY
X-Viewer-Country
X-ApacheServer
S-Rt
X-Daa-Tunnel
X-RemovedCookies
X-Via-Fastly
Selected-FE
X-Timing-Wait
X-ProcessESI
Cache-Name
Xserver
X-Proxy-Build
X-IP
X-Human
X-Pc-Appver
X-Format
X-Pc-Key
X-Pc-Hit
X-OCL
X-PCL
X-PERF
Public-Key-Pins-Report-Only
TWC-GeoIP-Country
X-MP-GENERATED-AT
TWC-Connection-Speed
TWC-GeoIP-LatLong
X-Origin-Hint
X-App-Version
TWC-Privacy
X-Debug-Cache
Property-Id
X-CCM
X-Access
Webcakes-Region
X-Cache-Enabled
Webcakes-App-Name
Webcakes-App-Version
TWC-Locale-Group
TWC-Device-Class
Azure-SiteName
Fastcgi-X-Cache-Version
DB-Nickname
Azure-Version
X-VG-TLSProxy
Azure-SlotName
Azure-RegionName
Azure-InstanceId
X-Section
X-Site-Version
X-App-Name
X-Xfnlog-Site
X-Zipkin-Id
We-Hiring
X-Microcachable
X-Proxied
X-Routing-Service
X-GEO
Mail-Subject
X-Cache-NE
X-Original-Request
X-Origin
Access-Control-Request-Headers
X-EdgeConnect-Cache-Status
X-Guploader-Uploadid
X-Protected-By
S-Cnection
Liferay-Portal
User-Agent
X-Sucuri-ID
X-Ocache
User-Cache-Control
Cache-Hits
X-Nginx-Cache
X-Request-Time
X-FW-Version
X-ES-SERVER
AR-SID
LB
X-Cdn-Forward
X-Node-Name
X-Proto
X-Ua
X-GRACE
X-Yottaa-Optimizations
PageSpeed
X-Yottaa-Metrics
X-Trace-Id
X-Tumblr-Pixel-3
Powered
X-Correlation-ID
Ohc-File-Size
X-Webstats-RespID
X-UA
X-FB-TRIP-ID
X-Webkit-Csp
X-Unique-ID
X-Endurance-Cache-Level
X-Origin-CC
X-Forwarded-Host
L5d-Success-Class
Frame-Options
Section-Io-Cache
CACHE
X-Nc
X-Time
X-VWS-Id
X-Varnish-Beresp-Grace
X-AWS-Id
X-Varnish-Beresp-Status
X-LJ-Flow-ID
X-V
X-Pc-Date
X-Pc-Host
X-OVcl-Cache
X-Parent-Response-Time
IBM-Web2-Location
X-OVcl
X-Pc-Subdomain
Nel
X-Origin-TTL
X-Varnish-Beresp-Ttl
X-Cluster-Node
X-Upstream-CT
X-Upstream-HT
X-R9-Blue-Green-Version
X-Rocket-Nginx-Bypass
X-ElasticPress-Search
OT-Force-Account-Verify
X-Cache-Backend
X-Varnish-Ttl
Fastly-SIE
Ec-Rule-Version
Decoy-Debug-TTL
Fastly-SWR
X-User
Fly-Request-Id
X-VG-WebServer
X-Auto-Login
Fly-Cache
X-B-Cookie
X-Cache-Bucket
X-UE-Client-Country
X-Cache-FS-Status
Country-Code
X-Block-Status
X-We-Are-Hiring
Decoy-Debug-Key
X-BB-ID
Decoy-Debug-Status
MD5-Digest
Viewtype
Mobile-Detection-Method
VivaBuild
Node
X-Cache-Host
Resin-Trace
Powered-By
Xc-Version
X-Accel-Expires-Debug
X-Aed
Memcached
Rendered-Blocks
GMS-Ver
Meta-Geo-Continent
X-ARC
X-Wikidot-Static-Cache
X-Amz-Meta-Cache-Control
X-Application
X-Wikidot-Backend
X-CF-Lambda-Fn
X-Rebelmouse-Surrogate-Control
X-Reboot
X-Rebelmouse-Cache-Control
X-PHP-Host
X-PAYTM-SRV-ID
X-Region-Sid
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Gen-Mode
X-Rewrite-Enabled
X-Generated-In
X-Request-UUID
X-Origin-Expires
X-Hnp-Log
X-Li-Fabric
X-Li-Pop
X-IN-APIGATEWAY
X-IN-WAF
X-Info
X-LI-Proto
X-LI-UUID
X-Origin-Date
X-NU-AKA-ACS-Version
Cache-Prefix
X-Micro-Cache
X-Rojux
X-From
X-Irp-Debug
X-Transaction
X-SRCache-Key
X-CF-Lambda-Version
X-ServiceProvider
X-Cdn-Srv
X-Trv-Group
X-TT-LOGID
X-Cache-Id
X-Cache-Info
X-Cache-URL
X-Connection-Hash
X-Server-Group
X-DPWN-IS-SECURE
X-S-Maxage
X-External-Request-Id
X-S-Cookie
X-Fetched-On
X-Distil-CS
X-ScT
X-Date
X-Destination
X-Developer
X-Server-By
X-Twitter-Response-Tags
Www
BehaviorPad-Version
X-Vgn-Hpd-Reason
Arc-Country
X-Newrelic-App-Data
X-D
X-Core-Mission
X-CGP
X-C
X-Variation
X-SERVER
X-Debug-Cookies
X-Clientip
X-TrackingId
X-Swa-Ws
X-Epic-Correlation-Id
X-Eu-Site
X-Distributor
X-Thanos
X-Bip
X-Thinkindot-L3
X-Dispatcher-Server
X-Debug-Log
X-Backend-Url
X-A
X-A-Ccd
X-A-Dam
Who
Web-Mar-Node
True-Client-Country-4JS
On-Server
X-EIG-Tracking-Id
X-A-Dcw
X-A-Dgt
X-Backend-Host
X-Backend-State
X-Svr
X-Server-Cache
X-Alternate-Cache-Key
X-A-Wwc
X-TIME
X-Actual-URL
X-Varnish-Action
X-FireWall-Port
X-Passed-To
X-Passed-To-BeforeDispatch
X-Passed-To-DLL
X-Returned-From-PostProcessResponse
X-NX-Host
X-Logtrace-Id
X-Matched-Rule
X-Nginx-Cache-Key
X-Passed-To-PostProcessResponse
X-Returned-From-DLL
X-Proxy-Cache-Status
X-Proxy-Upstream
X-Request-URI
X-Policy
X-Platform
X-Returned-From-BeforeDispatch
X-Returned-From
X-Response-By
X-Location
X-Secret
X-Sorting-Hat-PodId
X-SIPLIST1
X-Generated-On
X-Sorting-Hat-ShopId
X-Gannett-Site-Version
X-Stale
Thinkindot-Control
X-G
X-GeoIP-Country-Code
X-Shopify-Stage
X-Server-IP
X-LAGOON
X-Level-Front-Cache
X-Sf
X-IN-SSL-APIGATEWAY
X-ShopId
X-Hash
X-ShardId
X-Fastly-Cache
X-Cache-Debug
Proxy-Connection
IsBot
Lfy
Is-Eu
HA-Ipaddr
Ha-Gx-Prefs
Fastly-Backend-Name
Thinkindot-CacheControl-Type
Magicmarker
Platform
Origin
CDCHOST
Content-Disposition
Backend
Countrycode
Fastly-Soc-X-Request-Id
Request-Time
X-Node-Id
Adler-Geo
SD-X-WS
X-Cache-Grace
Server-Host
Ajk
Thinkindot-CacheControl
X-HS-Cache-Config
X-Sucuri-Cache
Warning
AKAMAI
X-Developers
X-CUA
X-Croise-Owner
X-Debug-Cache-Expiry
X-MSEdge-Flight
X-F5-Cache
X-Debug-Cache-Store
X-MSEdge-Features
X-Fstrz
X-Key
GW-Server
Apple-News-Services-Host
Fastcgi-X-Cache
X-Instart-Isnd
Fastly-SSL
X-Crawler
X-Generation-Time
Apple-News-Services-Handled
Cache-Cookie-Set-From
Apple-News-Services-Request-Url
Heartbleed
Apple-News-Services-Parsed-Url
X-No-Session
X-Debug-Cache-Fetch
X-Cache-Expires
RNT-Time
X-Var-Ttl
X-RateLimit-Limit-Second
Server-Surrogate-Control
X-Amz-Meta-Surrogate-Control
X-RateLimit-Remaining-Second
Pramga
X-Varnish-Authentication
X-Via-CDN
Server-Int
Release
X-Cache-ASPX
X-Core-Value
X-Via-NSCOPI
X-Up
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
RNT-Machine
Server-Cache-Control
X-Qloud-Router
SS
HostName
X-Dc
Server-ID
Pagetype
X-Edge-Cache-Key
X-Page-Type
X-Varnish-Url
X-Device-Os
REQUESTUUID
X-Edge-Cache
X-Died
NGX
X-UnsetCookies
Mn-Server-Ip
Kp-EeAlive
SID
X-B3-Traceid
X-Servername
X-Cache-Miss-From
X-Server-Time
X-Sedo-Request-Id
X-CDN-Forward
X-Owner
Version
X-Be
X-Pjax-Url
RequestId
X-SN
X-NC
MIME-Version
Odigeo-Trace-Id
X-Refresh
PFcat
X-B3-SpanId
FastCGI-Cache
X-URL
X-From-Cache
Esi-Enabled
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Object-Type
X-Store
X-Cache-CFC
X-FPC
X-Servedbyhost
HTTPS
Cteonnt-Length
Time
Hostname
Cdn-Request-Time
MI-Cache-Age
MI-Cache
Cdn-Host
MI-API
PICS-Label
X-Layer
X-MI-In-Market
X-RCS-CacheZone
X-Edge-Server
X-RequestId
X-CSRF-TOKEN
X-Real-Ip
Cdn
HA-Urlpath
ProcessTime
HA-Geocity
HA-Cloudapp
X-IPS-LoggedIn
HA-Geolat
HA-Geocountry
HA-Servedtime
HA-Geolon
HA-Host
HA-Georegion
CF-IPCountry
Mime-Version
X-Req
X-Hyper-Cache
X-Webkit-CSP
X-CLOUD-TRACE-CONTEXT
Backend-Name
Memory
X-Wa
X-Dynatrace-Js-Agent
X-Amzn-Remapped-Connection
X-Load-Cache
X-Mobile-URL
X-Amzn-Remapped-Date
Processtime
CDN
X-DC
X-GZip
X-Ratelimit-Remaining
X-Unique-Id-Primal
X-CMS-Context
X-Mrs-Cache-Hits
X-Mshield-Cache-Status
X-NodeID
Cross-Origin-Window-Policy
X-VServer
X-Mrs-Age
X-Mrs-Cache
X-Atg-Version
Cf-Ipcountry
X-Geo
X-Pf-Uncompressing
X-HS-Combine-CSS
X-Ratelimit-Limit
X-FORWARDED-FOR
X-Instart-Info
X-HTML-Minification-Powered-By
X-Skip-Cache
X-Newrelic-Synthetics
Ohc-Response-Time
X-WebServer
X-Lb-Id
X-B3-Spanid
X-Aicache-OS
X-Phone
X-Varnish-Beresp-TTL
X-WR-MODIFICATION
XServer
GeoIP-Country-Code
X-Fastly-Country-Code
X-Request-Start
X-Release
X-PF-Uncompressing
GeoIP-Latitude
X-VC-Cache
URI
X-SRV
Uber-Trace-Id
Ohc-Cache-HIT
X-Tb-Optimization-Total-Bytes-Saved
Accept-Ch-Lifetime
X-WA
X-Nananana
X-Cms-Context
X-Server-W
T-Server
Amp-Access-Control-Allow-Source-Origin
X-Gateway-Cache-Key
N-Cache
X-UCC
X-Gateway-Skip-Cache
X-LB-ID
X-Oracle-Dms-Ecid
X-Gateway-Cache-Status
X-Served-From
X-MServer
X-COUNTRY
Rt-Proxy-Cache
X-GoCache-CacheStatus
X-ND-Cache
Pics-Label
X-Datadome
X-Unique-Id
X-CSRF-Token
X-Worker
X-APP
X-Processor
A
X-LiteSpeed-Cache-Control
X-ServedByHost
X-Hp-Webp
X-SERVER-NAME
X-CACHE-AGE
X-BBXSRF
X-UPSTREAM-Address
X-Sn-Servicetimems
DataCenter
V-Age
X-Cdn-Origin
X-Fastly-Cache-Hits
X-Shard
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-BE
X-HS-Status
X-Check-Cacheable
Proxy-Firewall
X-Cache-HT
X-Optimization
X-Requestid
X-GZIP
X-NGINX-Cache
X-VCT
Dnion-Transfer-Encoding
Geoip-Latitude
X-Amzn-Remapped-Content-Length
X-PJAX-URL
X-P-T
X-ID
X-Geo-Header
Host-ID
X-Vcache
X-GeoIP-City
Get-Access-Time
Is-Session-Tracking
Cneonction
X-Backend-TTL
X-Port
X-PAGE-TYPE
X-Varnish-URL
ServerName
X-ServerName
GeoIp-Country-Code
X-Csrf-Token
Requestid
X-NWS-UUID-VERIFY
Serverid
X-Git-Hash
Server-Id
UCS
X-RCS-Backend
Request-EU
X-Cache-Ttl
X-Fe
X-LiteSpeed-Tag
Request-Country
X-HostName
RequestUuid
X-Dw-Trace-Id
X-StackifyID
X-GDPR
Cache-Provider
WP-Super-Cache
X-Vg-Webcache
X-Fpc
Inserted-Into-Cache-At
X-Fastly-Backend-Reqs
Pragrma
X-Gen-Id
X-Html-Edge-Cache
Xxline
219prxHost
225prxHost
189phosttRef
188prxHost
DSUID
178proxuri
286prxHost
352pxline
X-CS
WZWS-RAY
X-Request-Url
409pxxline
355prline
X-RAMCache