Threat Level: green Handler on Duty: Russ McRee

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
CF-RAY
ETag
Link
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Request-Id
X-Xss-Protection
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Adblock-Key
X-Check
Alt-Svc
X-Cacheable
X-Generator
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-Cache-Status
X-AspNetMvc-Version
X-Permitted-Cross-Domain-Policies
X-Iinfo
X-Template
X-Language
Status
Timing-Allow-Origin
X-Buckets
X-Content-Security-Policy
Content-Encoding
X-CDN
X-Kinja-Server-Push
Xkey
X-Turbo-Charged-By
Upgrade
X-Type
Access-Control-Expose-Headers
Keep-Alive
X-Request-ID
WPE-Backend
X-Pass-Why
Access-Control-Max-Age
X-Backend
X-AH-Environment
CF-Ray
X-Cache-Group
X-Age
X-Drupal-Dynamic-Cache
X-Server
X-Ua-Compatible
X-Via
X-Proxy-Cache
Grace
X-Pingback
X-Nginx-Cache-Status
X-Server-Powered-By
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Hacker
X-UA-Device
X-Varnish-Cache
EagleId
X-Page-Speed
Request-Context
X-LiteSpeed-Cache
Cf-Railgun
X-Envoy-Upstream-Service-Time
X-CST
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Server-Id
X-Device
X-Amz-Version-Id
X-Ac
Server-Timing
X-Node
X-OneAgent-JS-Injection
X-Iejgwucgyu
Feature-Policy
X-Cnection
X-Response-Time
Allow
X-Rq
Content-Location
X-Cache-Lookup
X-Backend-Server
Report-To
EagleEye-TraceId
Surrogate-Control
X-Readtime
X-Host
X-Application-Context
Request-Id
X-Url
X-ORACLE-DMS-ECID
X-Rack-Cache
X-Origin-Cache
X-Clacks-Overhead
X-Country
NEL
X-FTR-Request-ID
Rating
X-Country-Code
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-DataDome
X-Cloud-Trace-Context
X-Instart-Request-ID
X-Px
X-Vhost
X-MS-InvokeApp
X-Mod-Pagespeed
X-VARITI-CCR
X-Ruxit-JS-Agent
Charset
Accept-CH
Edge-Control
X-Goog-Hash
X-GitHub-Request-Id
X-Varnish-TTL
Verso
X-Mobile-Rewrite
PB-PID
PB-RID
Arc-Version
X-ESI
X-TTL
X-DynaTrace
X-Version
X-PC
X-Vname
X-TtlSet
X-Server-Name
X-B3-TraceId
X-Cdn
X-D2id
X-Powered-By-Plesk
Pinterest-Generated-By
X-Kinja-Server
X-Use-Magma
X-Kinja
X-GoogleNews-Bot
X-Exp-Id
X-Cdn-Fetch
X-Exp-Variant
X-Kinja-Build
X-Kinja-Revision
X-Cached
SPRequestGuid
X-Upstream-Env
X-Dispatcher
X-Origin-Upstream-Status
X-Powered-CMS
X-SharePointHealthScore
X-Abt-Application-Version
X-ORACLE-DMS-RID
X-T
MS-Author-Via
Accept-CH-Lifetime
X-Recruiting
RTSS
X-Trace
X-Navigation-Version
Public-Key-Pins
X-Shield-Request-Id
AR-ATIME
AR-PoweredBy
AR-CACHE
Content-MD5
X-SRCache-Fetch-Status
X-SRCache-Store-Status
SPIisLatency
SPRequestDuration
X-Fastly-Request-ID
X-Amz-Rid
X-HW
X-DIS-Request-ID
X-Client-IP
Realpath
Arr-Disable-Session-Affinity
X-Forwarded-Proto
X-Oracle-Dms-Rid
X-Accel-Buffering
X-Wix-Server-Artifact-Id
X-F-Cache
X-B
X-Server-ID
X-DynaTrace-JS-Agent
X-Upstream
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Metageneration
X-Ser
X-Via-JSL
X-Amz-Meta-S3cmd-Attrs
Service-Worker-Allowed
Pinterest-Version
X-Pinterest-Rid
X-Dw-Request-Base-Id
X-Id
X-FTR-Backend
X-FTR-Realm
X-FTR-DC
X-FTR-Cache-Status
X-FTR-Balancer
X-Country-Code-Real
X-FTR-Backend-Server
X-FTR-Expires
X-Vcap-Request-Id
AR-Request-ID
Paypal-Debug-Id
Front-End-Https
X-Varnish-Age
X-Dns-Prefetch-Control
X-Debug
X-Goog-Storage-Class
X-Acc-Meta-Resource-Type
Nginx-Cache
Ar-Sid
X-MSEdge-Ref
X-TEC-API-ROOT
X-TEC-API-VERSION
X-N
X-TEC-API-ORIGIN
X-Hits
X-Kinsta-Cache
X-NF-Request-ID
X-NewRelic-App-Data
X-FTR-Cache-Host
X-Logged-In
X-Ttl
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
S
X-XRDS-Location
X-Akam-SW-Version
X-Forwarded-For
X-HS-Content-Id
X-Frontend
X-HS-Hub-Id
X-Grace
X-PressLabs-Stats
AMP-Access-Control-Allow-Source-Origin
X-User-Agent
Alternate-Protocol
Tracecode
X-DataStream-Cache-Status
X-Cache-Key
DynaTrace
X-Amzn-Trace-Id
X-TA-CDN-Provider
X-CACHE-GROUP
X-Pad
X-FastCGI-Cache
Server-Name
X-Content-Digest
Refresh
X-Content-Options
X-Analytics
Backend-Timing
Fastcgi-Cache
Accept-Charset
X-Az
X-Activity-Id
Powered-By-ChinaCache
X-AppVersion
X-LB-Cache
X-Rid
X-Page-Id
MicrosoftSharePointTeamServices
X-Zen-Fury
X-Sol
FilterID
X-Content-Type
X-IPLB-Instance
MS-CV
Display
Host
X-Middleton-Display
Access-Control-Request-Method
X-Debug-Info
X-CF-Powered-By
TCN
ServerID
X-Magnolia-Registration
TP-L2-Cache
TP-Cache
X-Middleton-Response
X-XRDS-LOCATION
Response
Cache-Status
X-ATG-Version
X-Cache-Hit
X-Mobile
X-Ruxit-Js-Agent
X-Fastcgi-Cache
X-Content-Powered-By
X-Srv
Surrogate-Key
X-VCache
X-Seen-By
X-WA-Info
X-Hostname
X-B3-Sampled
X-RateLimit-Remaining
Rt-Fastcgi-Cache
X-Cached-By
X-Revision
X-Request-Processing-Time
X-Request-Received
X-Varnish-Backend
X-GUploader-UploadID
X-Cache-Action
X-Cache-Age
X-B-Cache
X-SS-Set-Cookie
X-Signature
X-Cluster
X-Tumblr-Pixel
X-Instance
X-Tumblr-User
X-Tumblr-Pixel-0
Cleartype
X-PHP-Backend
Source
X-Whom
X-Content-Security-Policy-Report-Only
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Request-Guid
X-Drupal-Cache-Tags
X-TT
X-Platform-Server
X-Akamai-Edgescape
X-Framework
X-Edge-Location
X-Handled-By
X-Origin-Server
X-App-Environment
Host-Header
X-Wix-Request-Id
ViewerVersion
Server-Info
X-Cache-Control
X-BCube-Filmed-By
DC
X-NWS-LOG-UUID
X-Cache-Rule
X-Generated-By
X-AOL-HN
X-Amzn-RequestId
X-App-Server
X-Amz-Apigw-Id
X-Varnish-Hostname
X-Cache-2
X-Geo-Country
X-Oneagent-Js-Injection
Retry-After
X-FW-Static
X-FW-Hash
X-FW-Serve
X-FW-Server
X-FW-Type
Server-Node
X-Varnish-Server
Eomportal-Instance
X-Correlation-Id
X-Real-IP
Fusion-Content-Id
Fusion-Source
Fusion-Component-Id
Fusion-Template-Id
Fusion-Content-Source
X-FB-Debug
Payment
X-Device-Type
Webserver
Access-Control-Allow-Method
X-Response-Served-From
Actual-Object-TTL
X-Tumblr-Pixel-1
X-Tumblr-Pixel-2
X-Varnish-Hits
X-Region
NGB
Content-Script-Type
X-RTag
ServedBy
Content-Style-Type
Ms-Operation-Id
GEO-INFO
X-Cacheable-TTL
Filters
X-Amz-Server-Side-Encryption
X-Jobs
X-UUID
X-Varnish-Grace
X-TT-TIMESTAMP
X-Varnish-IP
Healthy
Viewport
Upgrade-Insecure-Requests
X-Servedby
X-WebKit-CSP-Report-Only
X-Adobe-Content
X-Adobe-Loc
X-Contextid
AsisCache
Edge-Cache-Tag
X-Drupal-Cache-Contexts
X-TX-ID
X-Locale
X-Rendered-As
Country
Cache
X-Amz-Replication-Status
X-Accel-Expires
Cache-Tv-Group
X-UA-Device-Type
From-Origin
X-Cache-Config
X-RequestSource
X-WPE-Loopback-Upstream-Addr
X-Cache-TTL-Remaining
X-BACKEND-TTL
HitType
X-Cache-Server
X-Ezoic-Cdn
X-Cache-Remote
X-VG-WebCache
X-Cache-Operation
X-Cache-TTL
X-Kong-Upstream-Latency
Pagespeed
X-Kong-Proxy-Latency
Fastly-Restarts
Fastcgi-Useragent
X-APP-VERSION
X-Content-Age
X-Upgrade-Enabled
X-Storage
X-Hit
X-FW-Dynamic
X-Redis-Cache
X-S
Cache-Tags
X-Esi
X-Mode
Datacenter
X-RateLimit-Limit
Cache-Tag
X-Daa-Tunnel
NtCoent-Length
X-App-Version
X-Source
Served-By
Load-Balancing
X-Cache-NE
SRV
X-RN-RSRV
X-Backend-Name
X-Hl-Ver
X-Generated
X-Rule
X-Internal-Host
X-Cache-Var
X-JoinUs
Machine
X-Is-Bot
X-NGENIX-Cache
X-NCache
Origin-Cache-Control
X-Path-Route
X-Detected-As
Meta-Geo
Origin-Edge-Control
X-Cache-Var-Map
X-L-Path
X-Akamai-Request-ID
X-Origin-Response-Time
X-Edge-IP
X-Hosted-By
X-Www-Served-By
X-Grey
X-CDN-Cache
X-FC-Vary-Parameters
X-Environment-Context
X-Timing-Wait
X-Proxy-Build
X-Agile-Id
X-GeoIP
X-Agile-Age
X-Agile
Now
X-Proxy
X-ProxyCache-Key
X-ProxyCache-Status
X-Cache-Category-Id
X-Web-Node
X-Loop
X-TNCMS
X-BYPASS-REASON
X-ServerID
X-Tb
X-Labrador-Cache-Channel
Selected-FE
X-Status
X-Human
X-IP
X-Birta-Served
X-Birta-Cache-Post
Cache-Name
Vix-Hermes-Req-Id
X-Pc-Appver
X-Pc-Key
X-Varnish-Cacheable
X-Via-Fastly
X-Time-Microsecs
X-RemovedCookies
X-ProcessESI
X-Pubstack
X-Pc-Hit
X-Origin-Host
Xserver
X-ApacheServer
S-Rt
DB-Nickname
X-Debug-Cache
X-Guploader-Uploadid
X-Viewer-Country
X-Akamai-Transformed
X-Site-Version
X-Varnish-Cache-Hits
Cache-Key
X-PERF
X-VG-TLSProxy
Azure-SiteName
X-CCM
X-MP-GENERATED-AT
We-Hiring
X-Zipkin-Id
X-PCL
Azure-RegionName
Azure-InstanceId
X-Proxied
X-Xfnlog-Site
Azure-SlotName
Azure-Version
X-OCL
X-Original-Request
X-Routing-Service
Mail-Subject
X-Format
Webcakes-App-Version
Webcakes-Region
TWC-Privacy
TWC-Device-Class
X-Origin
Property-Id
X-Section
X-Access
X-Origin-Hint
X-Cache-Enabled
Webcakes-App-Name
TWC-Connection-Speed
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-GeoIP-Country
Public-Key-Pins-Report-Only
X-App-Name
Fastcgi-X-Cache-Version
X-UA
Access-Control-Request-Headers
X-Ocache
X-Microcachable
X-Sucuri-ID
Liferay-Portal
User-Cache-Control
X-Upstream-Proxy
X-Protected-By
X-Request-Time
S-Cnection
X-Nginx-Cache
X-Cdn-Forward
X-EdgeConnect-Cache-Status
X-DataStream-MidMile-RTT
X-CACHE-KEY
X-DataStream-Origin-MEX-Latency
X-Tumblr-Pixel-3
X-Webstats-RespID
X-FW-Version
User-Agent
X-GEO
X-Origin-CC
X-GRACE
X-Proto
X-FB-TRIP-ID
LB
X-Trace-Id
PageSpeed
Ohc-File-Size
Cache-Hits
X-Nc
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Node-Name
X-Varnish-Beresp-Status
X-Correlation-ID
X-Upstream-HT
X-Upstream-CT
Powered
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Ttl
X-ES-SERVER
X-Endurance-Cache-Level
X-Forwarded-Host
Frame-Options
X-Pc-Host
X-Cache-Backend
X-Pc-Date
X-OVcl-Cache
X-TIME
L5d-Success-Class
X-OVcl
X-Rocket-Nginx-Bypass
X-Ua
X-Edge-Cache
Section-Io-Cache
X-Origin-TTL
X-Parent-Response-Time
IBM-Web2-Location
X-ElasticPress-Search
X-Edge-Cache-Key
AR-SID
X-V
X-Vgn-Hpd-Reason
X-Pc-Subdomain
OT-Force-Account-Verify
X-Time
X-Unique-ID
HostName
X-Server-Cache
Nel
X-Dynatrace-Js-Agent
X-Cache-URL
X-Cdn-Srv
X-Cache-Info
X-Cache-Id
X-Li-Fabric
MD5-Digest
X-CF-Lambda-Fn
Resin-Trace
X-Developer
X-Died
X-Destination
X-Date
X-CF-Lambda-Version
X-Connection-Hash
Memcached
X-Cache-Host
X-Cache-Bucket
Mobile-Detection-Method
Node
X-BB-ID
X-Aed
X-B-Cookie
X-LI-UUID
X-LI-Proto
X-Li-Pop
Meta-Geo-Continent
X-Accel-Expires-Debug
Powered-By
X-Cache-FS-Status
X-Distil-CS
GMS-Ver
Country-Code
Cache-Prefix
X-From
X-ARC
X-IN-WAF
X-IN-SSL-APIGATEWAY
X-Generated-In
Viewtype
X-Application
BehaviorPad-Version
Arc-Country
X-IN-APIGATEWAY
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Fetched-On
X-Info
Www
X-Auto-Login
Fly-Cache
X-Irp-Debug
Fly-Request-Id
X-Micro-Cache
VivaBuild
X-Amz-Meta-Cache-Control
X-External-Request-Id
Ec-Rule-Version
Fastly-SIE
X-DPWN-IS-SECURE
Fastly-SWR
Rendered-Blocks
X-PHP-Host
X-Region-Sid
X-TT-LOGID
X-Request-UUID
X-Trv-Group
X-Reboot
X-Twitter-Response-Tags
X-User
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Transaction
X-Rewrite-Enabled
X-Server-Group
X-SRCache-Key
CACHE
X-Server-By
X-ScT
X-Rojux
X-S-Cookie
X-S-Maxage
X-VG-WebServer
X-UE-Client-Country
X-Origin-Expires
X-We-Are-Hiring
X-Origin-Date
Fastcgi-X-Cache
X-PAYTM-SRV-ID
X-NU-AKA-ACS-Version
Xc-Version
X-AWS-Id
X-R9-Blue-Green-Version
X-VWS-Id
X-LJ-Flow-ID
X-Dc
X-Thanos
X-Swa-Ws
X-Wikidot-Static-Cache
X-Cache-Expires
X-Sorting-Hat-PodId
X-SIPLIST1
Thinkindot-CacheControl-Type
X-Sorting-Hat-ShopId
Thinkindot-Control
X-Cache-Debug
X-Stale
X-Svr
X-Bip
X-Alternate-Cache-Key
X-Shopify-Stage
X-A-Dcw
X-Var-Ttl
X-Variation
X-Varnish-Action
X-Actual-URL
X-A-Dam
X-A-Ccd
X-A-Wwc
X-Block-Status
X-Thinkindot-L3
X-Backend-Url
X-A
X-Backend-Host
X-Wikidot-Backend
X-Debug-Log
X-Proxy-Upstream
X-Hnp-Log
X-Proxy-Cache-Status
Thinkindot-CacheControl
X-Hash
X-RateLimit-Limit-Second
X-Gen-Mode
X-Generated-On
X-RateLimit-Remaining-Second
X-Passed-To-PostProcessResponse
X-Level-Front-Cache
X-Nginx-Cache-Key
X-Location
X-Logtrace-Id
X-Node-Id
X-NX-Host
X-Passed-To-DLL
X-Passed-To-BeforeDispatch
X-Passed-To
X-G
X-FireWall-Port
X-CUA
X-D
X-Server-IP
X-Crawler
X-Core-Mission
X-ShardId
X-ServiceProvider
X-Server-Time
X-Debug-Cookies
X-Matched-Rule
X-Returned-From
X-Fastly-Cache
X-Response-By
X-Returned-From-BeforeDispatch
X-Returned-From-DLL
X-Dispatcher-Server
X-Distributor
X-Returned-From-PostProcessResponse
X-ShopId
X-A-Dgt
IsBot
Is-Eu
Fastly-Backend-Name
Lfy
Magicmarker
Platform
Origin
Decoy-Debug-TTL
Decoy-Debug-Key
X-Via-NSCOPI
Mn-Server-Ip
X-Via-CDN
Adler-Geo
Ajk
Content-Disposition
Backend
Request-Time
Decoy-Debug-Status
SD-X-WS
Server-Host
X-Sucuri-Cache
X-HS-Cache-Config
Warning
Web-Mar-Node
X-Fstrz
Countrycode
Server-Int
X-Gannett-Site-Version
HA-Ipaddr
X-Request-URI
Fastly-Soc-X-Request-Id
Who
GW-Server
X-Device-Os
Fastly-SSL
X-Epic-Correlation-Id
Cache-Cookie-Set-Lfrom
X-Eu-Site
Ha-Gx-Prefs
Cache-Cookie-Set-From
X-SERVER
X-UnsetCookies
X-No-Session
True-Client-Country-4JS
X-Platform
X-Qloud-Router
SS
X-Policy
X-Varnish-Authentication
X-Cluster-Node
Server-Surrogate-Control
X-C
X-GeoIP-Country-Code
AKAMAI
X-Instart-Isnd
X-Secret
X-Key
X-Generation-Time
Cache-Cookie-Set-Idcheck
Kp-EeAlive
RNT-Machine
On-Server
X-CGP
X-Clientip
X-Sf
X-Cache-Grace
X-Cache-ASPX
RNT-Time
Pagetype
X-Croise-Owner
X-Backend-State
Heartbleed
Server-Cache-Control
Pramga
X-Core-Value
Release
Proxy-Connection
REQUESTUUID
CDCHOST
X-MSEdge-Features
X-Amz-Meta-Surrogate-Control
Version
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-MSEdge-Flight
X-Debug-Cache-Expiry
X-Developers
X-Up
X-F5-Cache
Server-ID
X-LAGOON
X-CLOUD-TRACE-CONTEXT
Apple-News-Services-Request-Url
X-TrackingId
NGX
Apple-News-Services-Host
Apple-News-Services-Handled
X-Pjax-Url
Apple-News-Services-Parsed-Url
X-Page-Type
X-Cache-Miss-From
X-Varnish-Url
PFcat
X-Servername
X-Sedo-Request-Id
X-EIG-Tracking-Id
X-Be
X-Ratelimit-Remaining
RequestId
X-Refresh
X-B3-Traceid
X-CDN-Forward
X-Newrelic-App-Data
X-Store
Esi-Enabled
X-Cache-CFC
MI-Cache-Age
X-Layer
SID
MI-API
X-RCS-CacheZone
X-MI-In-Market
MI-Cache
X-B3-SpanId
X-URL
X-Oss-Storage-Class
X-Oss-Server-Time
X-SN
Time
X-Oss-Request-Id
Cdn
X-IPS-LoggedIn
X-Oss-Object-Type
X-From-Cache
X-RequestId
X-Owner
MIME-Version
X-Oss-Hash-Crc64ecma
X-NC
HA-Geolon
HA-Geolat
HA-Georegion
HA-Servedtime
Mime-Version
PICS-Label
HA-Urlpath
HA-Host
Odigeo-Trace-Id
HA-Cloudapp
HA-Geocountry
HA-Geocity
X-Mrs-Age
X-Unique-Id-Primal
X-Real-Ip
X-Mrs-Cache-Hits
X-Mrs-Cache
X-Mshield-Cache-Status
X-Geo
X-Ratelimit-Limit
X-FPC
Cteonnt-Length
FastCGI-Cache
X-Hyper-Cache
HTTPS
Backend-Name
X-Servedbyhost
CF-IPCountry
X-CMS-Context
Cdn-Request-Time
Cdn-Host
X-Webkit-Csp
Processtime
X-Varnish-Ttl
X-Edge-Server
X-Webkit-CSP
X-Req
Memory
X-WebServer
X-Instart-Info
X-CSRF-TOKEN
X-Phone
X-B3-Spanid
Hostname
Cf-Ipcountry
X-Aicache-OS
Ohc-Response-Time
X-Wa
X-Request-Start
CDN
X-WR-MODIFICATION
X-Mobile-URL
X-Release
X-Amzn-Remapped-Date
X-Pf-Uncompressing
X-Amzn-Remapped-Connection
X-Newrelic-Synthetics
X-DC
X-HS-Combine-CSS
GeoIP-Country-Code
ProcessTime
X-Load-Cache
X-GZip
GeoIP-Latitude
X-VServer
Cross-Origin-Window-Policy
XServer
X-NODE
X-WA
X-NodeID
X-Lb-Id
X-HTML-Minification-Powered-By
X-Atg-Version
X-Server-W
Rt-Proxy-Cache
X-PF-Uncompressing
X-Fastly-Country-Code
X-Served-From
X-Skip-Cache
X-Varnish-Beresp-TTL
X-ND-Cache
X-Unique-Id
X-FORWARDED-FOR
X-GoCache-CacheStatus
T-Server
URI
Accept-Ch-Lifetime
X-Nananana
Ohc-Cache-HIT
X-Oracle-Dms-Ecid
X-CSRF-Token
X-VC-Cache
X-Tb-Optimization-Total-Bytes-Saved
V-Age
X-Cms-Context
X-COUNTRY
X-ServedByHost
X-MServer
X-LB-ID
X-Cdn-Origin
X-Sn-Servicetimems
X-Gateway-Cache-Status
X-Gateway-Skip-Cache
X-APP
X-Gateway-Cache-Key
N-Cache
Pics-Label
Uber-Trace-Id
X-Worker
X-Datadome
X-SVT-ORM-VERSION
Proxy-Firewall
X-SRV
X-SVT-ORM-RULES
X-UPSTREAM-Address
X-LiteSpeed-Cache-Control
X-P-T
A
Is-Session-Tracking
Get-Access-Time
X-UCC
X-Fastly-Cache-Hits
X-SERVER-NAME
Amp-Access-Control-Allow-Source-Origin
X-Processor
X-CACHE-AGE
X-Check-Cacheable
ServerName
X-HS-Status
DataCenter
X-Hp-Webp
X-Requestid
X-RCS-Backend
X-BBXSRF
X-GZIP
X-NGINX-Cache
X-ID
X-BE
Dnion-Transfer-Encoding
X-PAGE-TYPE
X-Optimization
X-HostName
Geoip-Latitude
X-Cache-HT
X-Vg-Webcache
X-Backend-TTL
WZWS-RAY
X-Varnish-URL
X-PJAX-URL
GeoIp-Country-Code
X-Org
X-Csrf-Token
X-Port
X-Fe
X-GDPR
Cneonction
Requestid
X-StackifyID
X-NWS-UUID-VERIFY
Serverid
X-Via-SSL
X-ServerName
X-LiteSpeed-Tag
X-Via-Edge
X-Git-Hash
X-VCT
X-Geo-Header
X-Amzn-Remapped-Content-Length
Cache-Provider
X-Dw-Trace-Id
Host-ID
X-GeoIP-City
Server-Id
RequestUuid
WP-Super-Cache
Xxline
409pxxline
355prline
X-RAMCache
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Instance-Name
X-Request-Url
352pxline
178proxuri
188prxHost
189phosttRef
225prxHost
DSUID
Correlation-Id
X-Gdpr
286prxHost
Pragrma
X-CS
219prxHost