Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
ETag
CF-RAY
Link
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Request-Id
X-Xss-Protection
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Adblock-Key
X-Check
Alt-Svc
X-Cacheable
X-Generator
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-Cache-Status
X-AspNetMvc-Version
X-Permitted-Cross-Domain-Policies
X-Template
X-Iinfo
X-Language
Status
Timing-Allow-Origin
X-Buckets
X-FRAME-OPTIONS
X-Content-Security-Policy
Content-Encoding
X-Kinja-Server-Push
Xkey
X-Turbo-Charged-By
Upgrade
X-CDN
X-Type
Keep-Alive
Access-Control-Expose-Headers
X-Request-ID
WPE-Backend
X-Pass-Why
X-AH-Environment
X-Backend
Access-Control-Max-Age
CF-Ray
X-Age
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Server
X-Proxy-Cache
X-Via
Grace
X-Pingback
X-Nginx-Cache-Status
X-Server-Powered-By
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Hacker
X-Varnish-Cache
X-UA-Device
X-Page-Speed
EagleId
Request-Context
X-LiteSpeed-Cache
X-Envoy-Upstream-Service-Time
Cf-Railgun
X-Ua-Compatible
X-CST
X-Swift-CacheTime
X-Swift-SaveTime
X-Server-Id
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Ali-Swift-Global-Savetime
X-Device
X-WebKit-CSP
X-Amz-Version-Id
Server-Timing
X-Ac
X-Node
Allow
X-Response-Time
Feature-Policy
X-OneAgent-JS-Injection
X-Rq
X-Cnection
X-Iejgwucgyu
Content-Location
X-Backend-Server
X-Cache-Lookup
Report-To
EagleEye-TraceId
Surrogate-Control
X-Readtime
X-Host
X-Application-Context
Request-Id
X-ORACLE-DMS-ECID
P3p
X-Rack-Cache
X-Url
X-Origin-Cache
X-Cdn
X-Clacks-Overhead
X-Country
X-FTR-Request-ID
Rating
NEL
X-Country-Code
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Cloud-Trace-Context
X-DataDome
X-Px
X-Instart-Request-ID
X-Ruxit-JS-Agent
X-Mod-Pagespeed
Charset
X-Vhost
X-VARITI-CCR
X-MS-InvokeApp
Accept-CH
Edge-Control
X-Goog-Hash
Verso
X-GitHub-Request-Id
X-TtlSet
X-Vname
X-PC
PB-PID
Arc-Version
X-ESI
PB-RID
X-Mobile-Rewrite
X-Server-Name
X-Upstream-Env
X-Version
Pinterest-Generated-By
X-DynaTrace
X-TTL
X-B3-TraceId
X-Powered-By-Plesk
X-D2id
X-Kinja
X-Exp-Variant
X-Exp-Id
X-Cached
X-Cdn-Fetch
X-GoogleNews-Bot
X-Kinja-Build
X-Use-Magma
X-Kinja-Server
X-Kinja-Revision
X-Origin-Upstream-Status
X-Dispatcher
SPRequestGuid
X-Varnish-TTL
X-Recruiting
X-SharePointHealthScore
X-Abt-Application-Version
MS-Author-Via
X-ORACLE-DMS-RID
X-Powered-CMS
Accept-CH-Lifetime
RTSS
X-Navigation-Version
Content-MD5
X-T
X-Shield-Request-Id
AR-PoweredBy
AR-CACHE
AR-ATIME
Public-Key-Pins
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-DynaTrace-JS-Agent
X-Trace
X-Client-IP
X-Forwarded-Proto
X-Fastly-Request-ID
X-HW
Arr-Disable-Session-Affinity
X-Accel-Buffering
X-Wix-Server-Artifact-Id
X-Amz-Rid
Realpath
SPRequestDuration
SPIisLatency
X-Oracle-Dms-Rid
X-DIS-Request-ID
Service-Worker-Allowed
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Amz-Meta-S3cmd-Attrs
X-Upstream
X-F-Cache
X-B
Paypal-Debug-Id
AR-Request-ID
X-Ser
Front-End-Https
X-Pinterest-Rid
Pinterest-Version
X-FTR-Realm
X-FTR-Balancer
X-FTR-Cache-Status
X-Country-Code-Real
X-FTR-DC
X-FTR-Backend
X-FTR-Backend-Server
X-Via-JSL
X-FTR-Expires
X-Id
X-Dw-Request-Base-Id
X-Vcap-Request-Id
Ar-Sid
X-Dns-Prefetch-Control
X-Varnish-Age
X-Debug
X-Goog-Storage-Class
X-Acc-Meta-Resource-Type
X-XRDS-Location
X-Ttl
X-MSEdge-Ref
X-Kinsta-Cache
X-N
X-Hits
Nginx-Cache
X-NF-Request-ID
X-FTR-Cache-Host
S
X-NewRelic-App-Data
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Logged-In
X-DataStream-Cache-Status
X-Mrf-Item-Lastmod
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Akam-SW-Version
MRF-Tech
X-Mrf-Section-Lastmod
X-Forwarded-For
Alternate-Protocol
Tracecode
X-Frontend
X-Grace
X-User-Agent
X-HS-Content-Id
X-HS-Hub-Id
X-PressLabs-Stats
X-Amzn-Trace-Id
X-Server-ID
AMP-Access-Control-Allow-Source-Origin
Server-Name
X-Content-Digest
X-CACHE-GROUP
TCN
X-Content-Options
Refresh
Powered-By-ChinaCache
X-Content-Type
X-Pad
DynaTrace
X-Fastcgi-Cache
Access-Control-Request-Method
Display
X-Middleton-Display
X-Sol
MicrosoftSharePointTeamServices
X-Analytics
Backend-Timing
X-LB-Cache
Fastcgi-Cache
Accept-Charset
X-Az
X-AppVersion
X-Debug-Info
FilterID
X-Activity-Id
X-Rid
X-IPLB-Instance
X-Zen-Fury
X-Page-Id
Host
X-FastCGI-Cache
X-CF-Powered-By
X-Cache-Key
MS-CV
ServerID
X-Middleton-Response
Response
Cache-Status
X-Cache-Hit
X-Hostname
TP-L2-Cache
TP-Cache
X-RateLimit-Remaining
X-Magnolia-Registration
X-VCache
X-Srv
X-Oneagent-Js-Injection
X-Content-Powered-By
X-Seen-By
X-ATG-Version
X-Mobile
X-Revision
X-WA-Info
X-Cached-By
X-Varnish-Backend
Surrogate-Key
X-B3-Sampled
X-Request-Received
X-Whom
X-Request-Processing-Time
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-SS-Set-Cookie
Host-Header
X-B-Cache
X-Cache-Action
X-Signature
X-Instance
X-Cluster
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Handled-By
X-Content-Security-Policy-Report-Only
X-Drupal-Cache-Tags
X-Platform-Server
X-Tumblr-User
Source
X-Ruxit-Js-Agent
Cleartype
ViewerVersion
X-Wix-Request-Id
Server-Info
X-Framework
X-Request-Guid
X-Origin-Server
DC
X-PHP-Backend
X-TT
X-Cache-Age
X-Akamai-Edgescape
Rt-Fastcgi-Cache
X-TA-CDN-Provider
X-App-Environment
X-XRDS-LOCATION
X-Amzn-RequestId
X-GUploader-UploadID
X-Amz-Apigw-Id
Fusion-Component-Id
Fusion-Template-Id
Fusion-Content-Id
Fusion-Content-Source
Fusion-Source
X-Real-IP
X-Geo-Country
X-Generated-By
X-App-Server
X-BCube-Filmed-By
X-FW-Server
X-FW-Type
X-Cache-Control
X-FW-Hash
X-FW-Static
X-FW-Serve
X-Varnish-Server
X-Edge-Location
X-AOL-HN
Server-Node
X-Cache-Rule
X-NWS-LOG-UUID
X-Varnish-Hostname
Retry-After
X-Cache-2
X-Correlation-Id
X-Amz-Server-Side-Encryption
Payment
X-Varnish-Grace
X-Amz-Replication-Status
Eomportal-Instance
X-FB-Debug
Access-Control-Allow-Method
Webserver
X-Response-Served-From
X-TT-TIMESTAMP
Actual-Object-TTL
X-Cacheable-TTL
AsisCache
X-Tumblr-Pixel-1
GEO-INFO
X-Varnish-Hits
X-Tumblr-Pixel-2
ServedBy
X-TX-ID
X-Upstream-Proxy
X-Jobs
Healthy
Content-Script-Type
X-WebKit-CSP-Report-Only
X-RTag
X-UA-Device-Type
X-Region
X-Drupal-Cache-Contexts
Ms-Operation-Id
X-Cache-Config
Content-Style-Type
NGB
Filters
X-Varnish-IP
X-Contextid
Viewport
X-UUID
X-RequestSource
From-Origin
X-VG-WebCache
Cache-Tv-Group
Country
X-Rendered-As
Upgrade-Insecure-Requests
X-Adobe-Content
X-Locale
X-Adobe-Loc
X-Accel-Expires
X-Cache-TTL
X-Ezoic-Cdn
X-Device-Type
HitType
Fastcgi-Useragent
X-BACKEND-TTL
X-FW-Dynamic
X-Servedby
Cache
X-Cache-Server
X-Cache-TTL-Remaining
X-WPE-Loopback-Upstream-Addr
Pagespeed
Edge-Cache-Tag
X-Content-Age
X-Cache-Remote
X-Kong-Proxy-Latency
Cache-Tags
X-Kong-Upstream-Latency
X-Cache-Operation
X-Upgrade-Enabled
X-Redis-Cache
X-APP-VERSION
X-Source
X-Hit
X-RateLimit-Limit
Fastly-Restarts
X-CACHE-KEY
Datacenter
X-Storage
X-Esi
X-Guploader-Uploadid
X-Mode
X-DataStream-MidMile-RTT
X-GeoIP
X-DataStream-Origin-MEX-Latency
Served-By
X-S
Cache-Tag
Machine
SRV
Load-Balancing
X-Hl-Ver
Xserver
X-Time-Microsecs
X-Pubstack
X-Cache-Var
X-RN-RSRV
Meta-Geo
Vix-Hermes-Req-Id
X-NCache
X-Backend-Name
X-Labrador-Cache-Channel
X-Cache-Var-Map
X-JoinUs
X-Is-Bot
X-Detected-As
X-Internal-Host
X-Akamai-Request-ID
X-Path-Route
X-Origin-Response-Time
X-NGENIX-Cache
X-Agile
X-Www-Served-By
X-Agile-Id
X-Status
X-Varnish-Cacheable
X-Loop
X-Proxy
Cache-Key
X-Agile-Age
X-Hosted-By
X-L-Path
X-Environment-Context
X-FC-Vary-Parameters
X-Origin-Host
X-Edge-IP
X-CDN-Cache
X-Birta-Served
X-BYPASS-REASON
X-Cache-Category-Id
X-TNCMS
X-Generated
X-Grey
X-Tb
X-ProxyCache-Key
X-Proxy-Build
Now
X-ServerID
X-Rule
Selected-FE
Origin-Edge-Control
X-Birta-Cache-Post
X-ProxyCache-Status
X-Timing-Wait
Origin-Cache-Control
X-Varnish-Cache-Hits
TWC-GeoIP-Country
TWC-Device-Class
X-RemovedCookies
TWC-GeoIP-LatLong
X-Origin-Hint
TWC-Connection-Speed
X-IP
Property-Id
X-PERF
X-ProcessESI
Cache-Name
S-Rt
TWC-Privacy
TWC-Locale-Group
Webcakes-App-Version
X-Format
X-ApacheServer
X-Web-Node
Webcakes-Region
Webcakes-App-Name
X-Via-Fastly
X-Daa-Tunnel
X-Viewer-Country
NtCoent-Length
X-Cache-Enabled
X-OCL
X-CCM
X-MP-GENERATED-AT
X-App-Version
X-Access
X-Human
Public-Key-Pins-Report-Only
X-PCL
Azure-RegionName
Azure-SlotName
Azure-InstanceId
Access-Control-Request-Headers
X-VG-TLSProxy
X-Section
Azure-Version
Azure-SiteName
Fastcgi-X-Cache-Version
DB-Nickname
X-Microcachable
X-Site-Version
Mail-Subject
We-Hiring
X-Xfnlog-Site
X-Routing-Service
X-Debug-Cache
X-Zipkin-Id
X-Proxied
X-App-Name
X-Akamai-Transformed
User-Agent
Cache-Hits
Liferay-Portal
X-GEO
X-EdgeConnect-Cache-Status
X-Origin
X-Pc-Key
X-Protected-By
X-Original-Request
X-Pc-Hit
X-Pc-Appver
Nel
X-Cache-NE
S-Cnection
X-Node-Name
X-ES-SERVER
X-FW-Version
X-Nginx-Cache
LB
X-Sucuri-ID
X-Ocache
User-Cache-Control
X-Request-Time
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Proto
X-Cdn-Forward
X-Trace-Id
X-UA
X-Ua
Powered
X-GRACE
PageSpeed
X-Nc
X-Forwarded-Host
CACHE
X-Webstats-RespID
X-Tumblr-Pixel-3
Ohc-File-Size
X-Varnish-Ttl
X-Endurance-Cache-Level
X-LJ-Flow-ID
X-VWS-Id
X-AWS-Id
X-Correlation-ID
X-FB-TRIP-ID
L5d-Success-Class
Frame-Options
X-Origin-CC
Section-Io-Cache
X-Unique-ID
X-V
X-Cluster-Node
X-Time
OT-Force-Account-Verify
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
X-URL
X-OVcl
X-OVcl-Cache
AR-SID
X-Origin-TTL
X-Webkit-Csp
X-EIG-Tracking-Id
X-Cache-Backend
X-Rocket-Nginx-Bypass
X-ElasticPress-Search
X-R9-Blue-Green-Version
Decoy-Debug-Key
Decoy-Debug-TTL
IBM-Web2-Location
Decoy-Debug-Status
X-Distil-CS
Ec-Rule-Version
Country-Code
X-DPWN-IS-SECURE
X-External-Request-Id
Cache-Prefix
X-Developer
Fastly-SIE
Fly-Request-Id
X-Date
Fly-Cache
Fastly-SWR
X-Destination
X-Fetched-On
BehaviorPad-Version
X-Parent-Response-Time
X-Li-Fabric
X-Li-Pop
X-SRCache-Key
X-LI-UUID
X-LI-Proto
X-Irp-Debug
X-Info
Arc-Country
X-From
X-Generated-In
X-Goog-Meta-Goog-Reserved-File-Mtime
X-IN-WAF
GMS-Ver
X-Connection-Hash
X-Application
Powered-By
X-ARC
X-Auto-Login
On-Server
X-B-Cookie
X-Amz-Meta-Cache-Control
X-Aed
VivaBuild
Viewtype
Www
X-Accel-Expires-Debug
Rendered-Blocks
Node
Mobile-Detection-Method
X-Cache-Info
X-Cache-Id
X-Cache-URL
X-Cdn-Srv
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-Cache-Host
X-Cache-Grace
Meta-Geo-Continent
X-BB-ID
Memcached
MD5-Digest
X-Cache-FS-Status
X-Micro-Cache
X-IN-APIGATEWAY
X-VG-WebServer
X-Server-Group
X-Rojux
X-NU-AKA-ACS-Version
X-Node-Id
X-UE-Client-Country
X-Reboot
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Server-By
X-S-Cookie
X-S-Maxage
X-TT-LOGID
X-Wikidot-Static-Cache
Xc-Version
X-PHP-Host
X-ScT
X-We-Are-Hiring
X-Wikidot-Backend
X-PAYTM-SRV-ID
X-User
X-Twitter-Response-Tags
X-Rewrite-Enabled
X-Request-UUID
X-Region-Sid
X-ServiceProvider
X-Trv-Group
X-Transaction
X-Dc
X-Varnish-Beresp-Ttl
X-Vgn-Hpd-Reason
X-CGP
Thinkindot-CacheControl-Type
X-Clientip
Who
X-A
X-Cache-Expires
X-Varnish-Action
X-Cache-Debug
X-Proxy-Cache-Status
True-Client-Country-4JS
X-Returned-From
Thinkindot-Control
Thinkindot-CacheControl
X-C
X-Actual-URL
X-Backend-Url
X-Request-URI
SD-X-WS
X-Backend-Host
X-Alternate-Cache-Key
X-RateLimit-Remaining-Second
X-A-Dgt
X-A-Dcw
X-RateLimit-Limit-Second
X-Proxy-Upstream
X-A-Ccd
X-Block-Status
X-A-Dam
X-Bip
X-Cache-Bucket
X-Debug-Cookies
X-LAGOON
X-Variation
X-Level-Front-Cache
X-Sf
X-ShardId
X-Var-Ttl
X-Returned-From-DLL
X-Server-IP
X-Hash
X-Hnp-Log
X-Returned-From-PostProcessResponse
X-Returned-From-BeforeDispatch
X-Stale
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Location
X-Logtrace-Id
X-Shopify-Stage
X-Nginx-Cache-Key
X-Thanos
X-Svr
X-Swa-Ws
X-Thinkindot-L3
X-ShopId
X-GeoIP-Country-Code
X-Generated-On
X-Backend-State
X-Debug-Log
X-Response-By
X-Passed-To-PostProcessResponse
X-Dispatcher-Server
X-Matched-Rule
X-Platform
X-Crawler
X-CUA
X-D
X-Policy
X-Secret
X-Passed-To-DLL
X-NX-Host
X-G
X-Gannett-Site-Version
X-Gen-Mode
X-Origin-Date
X-Eu-Site
X-Passed-To-BeforeDispatch
X-Passed-To
X-Epic-Correlation-Id
X-Origin-Expires
X-Core-Mission
X-A-Wwc
Is-Eu
HA-Ipaddr
Ha-Gx-Prefs
Magicmarker
Origin
Proxy-Connection
Platform
Adler-Geo
Ajk
Content-Disposition
CDCHOST
Countrycode
Fastly-Backend-Name
Backend
Fastly-Soc-X-Request-Id
Request-Time
Lfy
X-Upstream-CT
X-Upstream-HT
Server-Host
X-Pc-Host
X-Pc-Subdomain
X-TIME
X-Pc-Date
Mn-Server-Ip
X-Via-CDN
X-HS-Cache-Config
Apple-News-Services-Request-Url
GW-Server
Apple-News-Services-Parsed-Url
Web-Mar-Node
AKAMAI
Apple-News-Services-Handled
Apple-News-Services-Host
X-Debug-Cache-Fetch
X-F5-Cache
X-Fastly-Cache
Server-Int
X-Distributor
Server-Surrogate-Control
X-Device-Os
X-Developers
X-Debug-Cache-Store
Server-Cache-Control
X-FireWall-Port
X-SIPLIST1
SS
X-Debug-Cache-Expiry
X-Instart-Isnd
Resin-Trace
X-Amz-Meta-Surrogate-Control
RNT-Machine
X-Varnish-Authentication
Fastly-SSL
Pramga
X-TrackingId
X-Qloud-Router
Release
X-SERVER
X-UnsetCookies
X-Cache-ASPX
X-No-Session
Heartbleed
IsBot
X-MSEdge-Features
X-MSEdge-Flight
RNT-Time
Warning
X-Sucuri-Cache
X-Server-Time
X-IN-SSL-APIGATEWAY
X-Key
SID
X-Fstrz
X-Up
Cache-Cookie-Set-Idcheck
X-Page-Type
X-Varnish-Url
X-Server-Cache
Cache-Cookie-Set-From
REQUESTUUID
X-Core-Value
Kp-EeAlive
Cache-Cookie-Set-Lfrom
Pagetype
X-Croise-Owner
Server-ID
X-Be
X-CLOUD-TRACE-CONTEXT
X-Sedo-Request-Id
X-Generation-Time
X-SN
NGX
X-Cache-Miss-From
X-Servername
X-Owner
X-Pjax-Url
Fastcgi-X-Cache
RequestId
X-Via-NSCOPI
X-B3-Traceid
Odigeo-Trace-Id
X-Died
X-Edge-Cache
HostName
Hostname
X-Edge-Cache-Key
X-Newrelic-App-Data
X-Refresh
HTTPS
X-From-Cache
Version
Cteonnt-Length
X-CDN-Forward
Cdn
X-Edge-Server
X-Oss-Storage-Class
X-Oss-Server-Time
X-Oss-Object-Type
PFcat
X-Oss-Hash-Crc64ecma
MIME-Version
X-Oss-Request-Id
Cdn-Request-Time
Cdn-Host
Mime-Version
X-B3-SpanId
X-NC
Time
X-FPC
X-Servedbyhost
ProcessTime
X-Req
X-Store
X-Cache-CFC
PICS-Label
Esi-Enabled
FastCGI-Cache
X-Mobile-URL
X-CSRF-TOKEN
X-Layer
X-RCS-CacheZone
X-MI-In-Market
MI-Cache
MI-API
MI-Cache-Age
X-GZip
X-Hyper-Cache
X-VServer
HA-Geocountry
HA-Geocity
HA-Geolat
HA-Cloudapp
X-NodeID
Cross-Origin-Window-Policy
HA-Geolon
X-RequestId
HA-Host
HA-Urlpath
X-Webkit-CSP
X-Amzn-Remapped-Date
X-Amzn-Remapped-Connection
X-IPS-LoggedIn
HA-Servedtime
Processtime
HA-Georegion
Memory
CF-IPCountry
X-Load-Cache
X-Wa
X-Geo
X-HS-Combine-CSS
X-Dynatrace-Js-Agent
X-Ratelimit-Remaining
X-Varnish-Beresp-TTL
X-Real-Ip
Backend-Name
X-HTML-Minification-Powered-By
Cf-Ipcountry
X-Lb-Id
X-Skip-Cache
X-Aicache-OS
CDN
X-CMS-Context
X-DC
X-Ratelimit-Limit
X-Pf-Uncompressing
X-Newrelic-Synthetics
X-B3-Spanid
X-Unique-Id-Primal
Ohc-Cache-HIT
X-Mshield-Cache-Status
Uber-Trace-Id
X-WR-MODIFICATION
X-Mrs-Age
X-Mrs-Cache-Hits
X-Mrs-Cache
X-Instart-Info
XServer
Ohc-Response-Time
X-PF-Uncompressing
X-WA
X-Phone
X-VC-Cache
X-Atg-Version
X-WebServer
X-Cms-Context
GeoIP-Country-Code
N-Cache
X-Tb-Optimization-Total-Bytes-Saved
X-UCC
X-Gateway-Cache-Status
URI
X-Release
X-Gateway-Skip-Cache
X-Fastly-Country-Code
X-Request-Start
X-Gateway-Cache-Key
Amp-Access-Control-Allow-Source-Origin
X-Nananana
GeoIP-Latitude
T-Server
X-FORWARDED-FOR
Accept-Ch-Lifetime
X-Server-W
X-Oracle-Dms-Ecid
X-LB-ID
Pics-Label
X-Processor
X-MServer
X-Unique-Id
X-APP
X-Hp-Webp
X-CSRF-Token
X-BBXSRF
X-COUNTRY
X-Shard
X-ServedByHost
X-GoCache-CacheStatus
X-Datadome
X-Served-From
X-Worker
X-SRV
X-ND-Cache
Rt-Proxy-Cache
X-VHOST
X-LiteSpeed-Cache-Control
A
X-SERVER-NAME
X-VCT
X-GeoIP-City
X-Amzn-Remapped-Content-Length
DataCenter
Host-ID
X-Geo-Header
X-Fastly-Cache-Hits
X-CACHE-AGE
X-UPSTREAM-Address
X-HS-Status
X-GZIP
X-Optimization
X-Requestid
V-Age
X-Cache-HT
X-Check-Cacheable
X-Cdn-Origin
UCS
X-Sn-Servicetimems
X-NGINX-Cache
Dnion-Transfer-Encoding
Geoip-Latitude
Request-Country
Request-EU
X-Vcache
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
Proxy-Firewall
X-ID
Cneonction
X-BE
X-Backend-TTL
Get-Access-Time
Requestid
Is-Session-Tracking
X-Git-Hash
X-Csrf-Token
X-P-T
X-Fastly-Backend-Reqs
X-ServerName
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
Pragrma
FSS-Proxy
X-Fpc
FSS-Cache
X-Varnish-URL
WZWS-RAY
X-PAGE-TYPE
X-Port
GeoIp-Country-Code
X-PJAX-URL
WP-Super-Cache
Serverid
X-NWS-UUID-VERIFY
Cache-Provider
X-LiteSpeed-Tag
X-Gen-Id
RequestUuid
X-Dw-Trace-Id
X-StackifyID
Server-Id
X-HostName
X-Fe
ServerName
X-Org
X-Html-Edge-Cache
X-Via-SSL
178proxuri
225prxHost
188prxHost
X-Via-Edge
189phosttRef
X-CS
219prxHost
352pxline
X-RCS-Backend
409pxxline
355prline
X-GDPR
X-RAMCache
Xxline
DSUID
286prxHost
Inserted-Into-Cache-At
X-Request-Url