Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
CF-RAY
ETag
Link
Expect-CT
Via
X-XSS-Protection
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Xss-Protection
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Request-Id
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Adblock-Key
X-Check
Alt-Svc
X-Cacheable
X-Generator
Content-Security-Policy-Report-Only
X-AspNetMvc-Version
X-Cache-Status
X-DNS-Prefetch-Control
X-Permitted-Cross-Domain-Policies
X-Template
X-Iinfo
X-Language
Status
Timing-Allow-Origin
X-Buckets
X-FRAME-OPTIONS
X-Content-Security-Policy
Content-Encoding
X-Kinja-Server-Push
Xkey
X-CDN
X-Turbo-Charged-By
Upgrade
X-Type
Keep-Alive
Access-Control-Expose-Headers
X-Request-ID
WPE-Backend
X-Pass-Why
X-AH-Environment
X-Backend
Access-Control-Max-Age
X-Age
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Server
X-Proxy-Cache
X-Via
Grace
X-Pingback
X-Nginx-Cache-Status
X-Server-Powered-By
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Hacker
X-Varnish-Cache
X-UA-Device
X-Page-Speed
EagleId
Request-Context
X-LiteSpeed-Cache
X-Envoy-Upstream-Service-Time
Cf-Railgun
X-CST
X-Ua-Compatible
X-Swift-CacheTime
X-Swift-SaveTime
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Server-Id
Ali-Swift-Global-Savetime
X-Device
X-Amz-Version-Id
X-WebKit-CSP
Server-Timing
X-Ac
X-Node
Allow
X-OneAgent-JS-Injection
Feature-Policy
X-Response-Time
X-Rq
X-Cnection
X-Iejgwucgyu
Content-Location
X-Backend-Server
X-Cache-Lookup
Report-To
EagleEye-TraceId
Surrogate-Control
X-Host
X-Readtime
X-Application-Context
Request-Id
X-ORACLE-DMS-ECID
P3p
X-Rack-Cache
X-Url
X-Origin-Cache
X-Clacks-Overhead
X-Country
NEL
X-FTR-Request-ID
Rating
X-Cloud-Trace-Context
X-Country-Code
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-DataDome
X-Ruxit-JS-Agent
X-Cdn
X-Px
X-Instart-Request-ID
X-Mod-Pagespeed
Charset
X-Vhost
X-VARITI-CCR
X-MS-InvokeApp
Accept-CH
Pinterest-Generated-By
X-Goog-Hash
Edge-Control
Verso
X-GitHub-Request-Id
X-Upstream-Env
X-PC
X-TtlSet
X-Vname
X-Server-Name
Arc-Version
X-ESI
X-Mobile-Rewrite
PB-PID
PB-RID
X-Version
X-DynaTrace
X-Origin-Upstream-Status
X-Powered-By-Plesk
X-Dns-Prefetch-Control
X-D2id
X-Kinja-Revision
X-Exp-Variant
X-Kinja
X-GoogleNews-Bot
X-Cdn-Fetch
X-Kinja-Server
X-Exp-Id
X-Use-Magma
X-Kinja-Build
X-Cached
X-B3-TraceId
X-TTL
X-Dispatcher
X-Recruiting
SPRequestGuid
X-Varnish-TTL
X-SharePointHealthScore
X-Abt-Application-Version
MS-Author-Via
X-ORACLE-DMS-RID
X-Powered-CMS
Accept-CH-Lifetime
RTSS
X-Navigation-Version
Content-MD5
AR-PoweredBy
AR-ATIME
AR-CACHE
X-Shield-Request-Id
X-T
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Public-Key-Pins
X-DynaTrace-JS-Agent
X-Trace
X-Forwarded-Proto
X-Client-IP
X-Amz-Rid
Arr-Disable-Session-Affinity
X-HW
X-Fastly-Request-ID
X-Accel-Buffering
X-Wix-Server-Artifact-Id
Realpath
SPIisLatency
SPRequestDuration
X-Oracle-Dms-Rid
X-DIS-Request-ID
Service-Worker-Allowed
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Metageneration
X-Amz-Meta-S3cmd-Attrs
AR-Request-ID
Paypal-Debug-Id
Front-End-Https
X-Upstream
X-Ser
X-B
X-FTR-DC
X-FTR-Cache-Status
X-FTR-Realm
X-Country-Code-Real
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Balancer
X-Pinterest-Rid
Pinterest-Version
X-FTR-Expires
X-Ttl
X-F-Cache
X-Id
X-Via-JSL
X-Dw-Request-Base-Id
X-Vcap-Request-Id
Ar-Sid
X-Debug
X-Varnish-Age
X-XRDS-Location
X-Goog-Storage-Class
X-Acc-Meta-Resource-Type
X-Kinsta-Cache
X-MSEdge-Ref
Nginx-Cache
X-N
X-Server-ID
X-Hits
X-NF-Request-ID
X-FTR-Cache-Host
S
X-DataStream-Cache-Status
X-NewRelic-App-Data
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Logged-In
X-Akam-SW-Version
X-B3-TraceId-Primal
MRF-Tech
X-Mrf-Section-Lastmod
Mrf-Cache-Status
X-Mrf-Item-Lastmod
X-Forwarded-For
Tracecode
Alternate-Protocol
X-Frontend
X-Grace
X-User-Agent
X-HS-Hub-Id
X-PressLabs-Stats
X-HS-Content-Id
X-Amzn-Trace-Id
AMP-Access-Control-Allow-Source-Origin
TCN
Server-Name
X-Content-Options
X-Content-Digest
X-CACHE-GROUP
Refresh
X-FastCGI-Cache
Powered-By-ChinaCache
Display
X-Sol
X-Content-Type
X-Middleton-Display
Access-Control-Request-Method
X-Pad
DynaTrace
MicrosoftSharePointTeamServices
Backend-Timing
X-Analytics
X-CF-Powered-By
Accept-Charset
X-LB-Cache
X-Debug-Info
X-Rid
X-IPLB-Instance
X-Az
X-Zen-Fury
X-Activity-Id
FilterID
X-AppVersion
Host
Response
X-Middleton-Response
X-Page-Id
Fastcgi-Cache
X-Cache-Key
X-VCache
ServerID
X-Fastcgi-Cache
MS-CV
X-Cache-Hit
X-Hostname
Cache-Status
X-Magnolia-Registration
X-Srv
TP-Cache
TP-L2-Cache
X-Seen-By
X-Content-Powered-By
X-RateLimit-Remaining
X-Mobile
X-ATG-Version
X-Revision
X-Cached-By
X-WA-Info
X-Varnish-Backend
X-Request-Processing-Time
X-Request-Received
X-GUploader-UploadID
Host-Header
Surrogate-Key
X-Whom
X-B3-Sampled
Server-Info
X-Instance
VIX-Pulpo-Node
X-SS-Set-Cookie
VIX-Pulpo-Upstream-Status
X-Cluster
X-Cache-Action
DC
X-Platform-Server
Source
X-Request-Guid
X-Handled-By
X-Tumblr-Pixel
X-Tumblr-User
X-Drupal-Cache-Tags
X-Tumblr-Pixel-0
X-Content-Security-Policy-Report-Only
X-B-Cache
X-Signature
Cleartype
X-Real-IP
X-Wix-Request-Id
X-PHP-Backend
ViewerVersion
X-Framework
X-TT
X-Origin-Server
X-Akamai-Edgescape
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Cache-Age
Fusion-Source
Fusion-Content-Source
Fusion-Component-Id
Fusion-Template-Id
Fusion-Content-Id
X-App-Environment
X-XRDS-LOCATION
X-Geo-Country
Rt-Fastcgi-Cache
X-App-Server
X-FW-Serve
X-FW-Hash
X-FW-Static
X-Generated-By
X-FW-Type
X-FW-Server
X-Varnish-Server
X-AOL-HN
X-BCube-Filmed-By
X-Cache-Control
Server-Node
X-Oneagent-Js-Injection
X-Edge-Location
X-TA-CDN-Provider
X-NWS-LOG-UUID
X-Cache-Rule
X-Varnish-Hostname
Retry-After
X-Ruxit-Js-Agent
X-Upstream-Proxy
Payment
X-Correlation-Id
X-Amz-Server-Side-Encryption
X-Varnish-Grace
X-Cache-2
X-Amz-Replication-Status
Access-Control-Allow-Method
X-FB-Debug
Eomportal-Instance
X-Response-Served-From
X-TT-TIMESTAMP
Pagespeed
ServedBy
GEO-INFO
X-Ezoic-Cdn
X-Cache-Config
X-Cacheable-TTL
AsisCache
X-Tumblr-Pixel-1
X-UA-Device-Type
Webserver
X-Varnish-Hits
X-Tumblr-Pixel-2
Actual-Object-TTL
Filters
Content-Script-Type
Healthy
Content-Style-Type
Ms-Operation-Id
X-Contextid
NGB
X-TX-ID
X-Drupal-Cache-Contexts
X-Region
X-WebKit-CSP-Report-Only
X-RTag
X-Jobs
X-UUID
X-Varnish-IP
X-VG-WebCache
Upgrade-Insecure-Requests
X-Adobe-Loc
Viewport
X-Adobe-Content
X-Rendered-As
X-Locale
From-Origin
Country
Cache-Tv-Group
X-RequestSource
X-Cache-TTL
HitType
X-Accel-Expires
Fastcgi-Useragent
X-Cache-TTL-Remaining
X-Device-Type
X-BACKEND-TTL
X-FW-Dynamic
X-Cache-Server
X-Servedby
Edge-Cache-Tag
X-Kong-Proxy-Latency
X-Content-Age
X-Kong-Upstream-Latency
Cache
Cache-Tags
X-WPE-Loopback-Upstream-Addr
X-Cache-Remote
X-Redis-Cache
X-Upgrade-Enabled
X-Cache-Operation
X-Source
X-APP-VERSION
Datacenter
X-Hit
X-DataStream-MidMile-RTT
X-DataStream-Origin-MEX-Latency
X-Storage
Fastly-Restarts
X-Esi
X-CACHE-KEY
X-GeoIP
X-RateLimit-Limit
X-Mode
NtCoent-Length
Cache-Tag
Served-By
X-S
Meta-Geo
X-Origin-Response-Time
X-TNCMS
Vix-Hermes-Req-Id
X-Time-Microsecs
X-Hl-Ver
Xserver
Machine
X-RN-RSRV
X-Detected-As
X-Agile-Id
X-Labrador-Cache-Channel
X-Cache-Var
X-Path-Route
X-Agile
X-Loop
X-Akamai-Request-ID
X-JoinUs
X-Is-Bot
X-Internal-Host
X-Pubstack
X-NGENIX-Cache
Load-Balancing
X-Cache-Var-Map
X-Backend-Name
X-Agile-Age
Cache-Key
X-Edge-IP
X-Timing-Wait
X-Environment-Context
X-FC-Vary-Parameters
X-Varnish-Cacheable
X-Status
X-Rule
X-Proxy
X-Proxy-Build
X-Cache-Category-Id
X-L-Path
X-BYPASS-REASON
X-NCache
X-Origin-Host
X-Birta-Served
X-Birta-Cache-Post
X-ProxyCache-Key
X-ProxyCache-Status
X-Tb
Origin-Cache-Control
Now
X-Grey
X-Www-Served-By
Selected-FE
X-Hosted-By
X-ServerID
X-CDN-Cache
X-Generated
Origin-Edge-Control
X-Varnish-Cache-Hits
TWC-GeoIP-LatLong
X-Guploader-Uploadid
TWC-Privacy
Webcakes-App-Name
TWC-GeoIP-Country
TWC-Device-Class
S-Rt
X-Microcachable
Property-Id
SRV
TWC-Connection-Speed
Webcakes-App-Version
X-Web-Node
X-Format
X-RemovedCookies
X-ProcessESI
X-PERF
X-Origin-Hint
X-Cache-Enabled
X-VG-TLSProxy
Cache-Name
X-Viewer-Country
X-ApacheServer
X-Via-Fastly
Webcakes-Region
TWC-Locale-Group
X-IP
X-Access
X-CCM
X-Akamai-Transformed
Public-Key-Pins-Report-Only
X-Section
X-PCL
Access-Control-Request-Headers
X-OCL
DB-Nickname
Fastcgi-X-Cache-Version
X-MP-GENERATED-AT
X-Human
User-Agent
X-Debug-Cache
X-App-Version
X-Proxied
We-Hiring
X-Routing-Service
X-Site-Version
X-App-Name
X-Zipkin-Id
Azure-RegionName
X-Xfnlog-Site
Azure-SiteName
Azure-SlotName
Azure-Version
Mail-Subject
Azure-InstanceId
Cache-Hits
X-Daa-Tunnel
X-ES-SERVER
Liferay-Portal
X-GEO
X-Node-Name
X-Protected-By
LB
S-Cnection
X-Sucuri-ID
X-Origin
X-Original-Request
X-FW-Version
X-EdgeConnect-Cache-Status
X-Pc-Appver
X-Nginx-Cache
X-Cache-NE
X-Pc-Key
X-Pc-Hit
X-Cdn-Forward
CACHE
X-Proto
X-Ocache
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Request-Time
X-Trace-Id
User-Cache-Control
Powered
X-Ua
X-UA
X-GRACE
X-Nc
X-Forwarded-Host
X-AWS-Id
X-VWS-Id
X-Endurance-Cache-Level
X-LJ-Flow-ID
X-Tumblr-Pixel-3
X-Varnish-Ttl
L5d-Success-Class
Ohc-File-Size
X-Cluster-Node
Frame-Options
X-Webstats-RespID
X-Correlation-ID
Section-Io-Cache
X-FB-TRIP-ID
X-V
X-Origin-CC
X-Unique-ID
X-Time
PageSpeed
OT-Force-Account-Verify
X-URL
X-Varnish-Beresp-Grace
X-OVcl-Cache
X-OVcl
X-Varnish-Beresp-Status
X-EIG-Tracking-Id
X-Webkit-Csp
X-B3-Traceid
AR-SID
X-Origin-TTL
Nel
Decoy-Debug-Key
Decoy-Debug-TTL
X-Cache-Backend
Decoy-Debug-Status
X-ElasticPress-Search
X-From
X-Rocket-Nginx-Bypass
X-R9-Blue-Green-Version
Fastly-SIE
X-Developer
X-Connection-Hash
X-NU-AKA-ACS-Version
Fastly-SWR
X-Destination
Fly-Cache
X-User
X-Node-Id
X-UE-Client-Country
GMS-Ver
X-We-Are-Hiring
X-Twitter-Response-Tags
Fly-Request-Id
X-Date
X-VG-WebServer
X-Wikidot-Static-Cache
Cache-Prefix
X-IN-APIGATEWAY
X-IN-WAF
X-Info
X-External-Request-Id
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Generated-In
X-Fetched-On
BehaviorPad-Version
X-Irp-Debug
X-DPWN-IS-SECURE
X-Origin-Date
X-Wikidot-Backend
X-LI-Proto
X-LI-UUID
X-Li-Pop
X-Li-Fabric
X-Distil-CS
Country-Code
Xc-Version
Ec-Rule-Version
X-PHP-Host
X-Response-By
X-Request-UUID
X-Amz-Meta-Cache-Control
X-Aed
Rendered-Blocks
Powered-By
X-Application
X-Reboot
X-Auto-Login
X-Region-Sid
X-ARC
X-Accel-Expires-Debug
X-ServiceProvider
X-S-Maxage
X-ScT
X-S-Cookie
X-Rojux
X-Rewrite-Enabled
Viewtype
VivaBuild
Www
X-Server-Group
X-Server-By
SD-X-WS
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
Arc-Country
X-PAYTM-SRV-ID
X-Transaction
X-Cache-Info
X-Cache-Id
X-Cache-URL
X-Trv-Group
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-Cdn-Srv
X-TT-LOGID
X-Cache-Host
X-Cache-Grace
Mobile-Detection-Method
X-Backend-State
Node
On-Server
X-B-Cookie
X-BB-ID
X-SRCache-Key
X-Cache-FS-Status
MD5-Digest
Memcached
Meta-Geo-Continent
X-Origin-Expires
IBM-Web2-Location
X-Dc
X-RateLimit-Limit-Second
X-Proxy-Upstream
X-Proxy-Cache-Status
X-RateLimit-Remaining-Second
X-Backend-Host
X-Request-URI
X-SIPLIST1
X-Sorting-Hat-PodId
X-Backend-Url
X-Stale
X-Cache-Bucket
X-Cache-Debug
X-Cache-Expires
X-C
X-Block-Status
X-Bip
X-Svr
Thinkindot-CacheControl
X-Sorting-Hat-ShopId
X-Shopify-Stage
Who
X-Returned-From-BeforeDispatch
X-Server-IP
X-A
X-Secret
X-Returned-From-DLL
Thinkindot-CacheControl-Type
Thinkindot-Control
True-Client-Country-4JS
X-A-Ccd
X-A-Dcw
X-Returned-From
X-Alternate-Cache-Key
X-ShopId
X-Actual-URL
X-ShardId
X-A-Dgt
X-A-Wwc
X-Sf
X-Policy
X-Swa-Ws
X-Dispatcher-Server
X-Returned-From-PostProcessResponse
X-Level-Front-Cache
X-Distributor
X-Location
X-Logtrace-Id
X-Debug-Log
X-Micro-Cache
X-Matched-Rule
X-LAGOON
X-Hnp-Log
X-Generated-On
X-Gen-Mode
X-G
X-Fastly-Cache
X-GeoIP-Country-Code
X-Epic-Correlation-Id
X-Eu-Site
X-Hash
X-Debug-Cookies
X-Vgn-Hpd-Reason
X-Passed-To-BeforeDispatch
X-Passed-To
X-CGP
X-Passed-To-DLL
X-Passed-To-PostProcessResponse
X-Thanos
X-Thinkindot-L3
X-Platform
X-Clientip
X-NX-Host
X-Var-Ttl
X-Variation
X-Varnish-Action
X-D
X-CUA
X-Core-Mission
X-Crawler
X-Nginx-Cache-Key
X-Gannett-Site-Version
X-A-Dam
Origin
Magicmarker
Lfy
Countrycode
Content-Disposition
Proxy-Connection
CDCHOST
Fastly-Backend-Name
Fastly-Soc-X-Request-Id
Adler-Geo
Ha-Gx-Prefs
HA-Ipaddr
Is-Eu
Fastly-SSL
IsBot
Request-Time
Platform
X-Via-CDN
Ajk
X-Varnish-Beresp-Ttl
Mn-Server-Ip
Backend
Server-Host
Hostname
Warning
X-HS-Cache-Config
X-Sucuri-Cache
X-Parent-Response-Time
AKAMAI
X-Debug-Cache-Store
X-Debug-Cache-Expiry
GW-Server
X-Croise-Owner
X-No-Session
Apple-News-Services-Handled
X-Debug-Cache-Fetch
Apple-News-Services-Parsed-Url
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
X-FireWall-Port
Cache-Cookie-Set-From
X-F5-Cache
X-Core-Value
X-TrackingId
X-Developers
X-Instart-Isnd
X-Device-Os
Apple-News-Services-Request-Url
X-Fstrz
Apple-News-Services-Host
X-Qloud-Router
X-Cache-ASPX
RNT-Machine
RNT-Time
Server-Cache-Control
SID
X-TIME
X-Amz-Meta-Surrogate-Control
X-Varnish-Authentication
Release
SS
Pramga
Heartbleed
Web-Mar-Node
Server-Int
Server-Surrogate-Control
X-SERVER
X-UnsetCookies
X-Up
X-Pc-Subdomain
X-Pc-Host
X-Upstream-HT
X-Pc-Date
X-Upstream-CT
Resin-Trace
Server-ID
REQUESTUUID
Pagetype
X-SN
X-Owner
X-MSEdge-Features
X-MSEdge-Flight
X-Page-Type
X-Server-Time
Kp-EeAlive
NGX
X-Varnish-Url
X-Key
X-Be
X-Server-Cache
X-Pjax-Url
X-Servername
X-Sedo-Request-Id
Odigeo-Trace-Id
X-IN-SSL-APIGATEWAY
X-Cache-Miss-From
X-Generation-Time
X-Newrelic-App-Data
Fastcgi-X-Cache
X-Died
X-Via-NSCOPI
HTTPS
X-Refresh
Cdn-Host
Cdn-Request-Time
X-Edge-Server
RequestId
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Request-Id
X-From-Cache
X-CDN-Forward
X-Edge-Cache
X-Edge-Cache-Key
Version
MIME-Version
Mime-Version
HostName
X-B3-SpanId
X-NC
ProcessTime
X-FPC
Cdn
X-Servedbyhost
PFcat
Time
Cteonnt-Length
PICS-Label
X-Mobile-URL
X-Ratelimit-Remaining
X-Req
FastCGI-Cache
X-CSRF-TOKEN
X-VServer
Esi-Enabled
X-Cache-CFC
X-NodeID
Cross-Origin-Window-Policy
X-Amzn-Remapped-Date
X-Store
X-Amzn-Remapped-Connection
X-Load-Cache
X-GZip
Memory
MI-Cache
X-RCS-CacheZone
Processtime
X-Hyper-Cache
MI-API
X-Layer
X-MI-In-Market
MI-Cache-Age
X-HS-Combine-CSS
X-Webkit-CSP
CF-IPCountry
X-CLOUD-TRACE-CONTEXT
X-Geo
X-Ratelimit-Limit
X-Wa
HA-Host
HA-Geocity
HA-Geocountry
HA-Geolat
X-Dynatrace-Js-Agent
HA-Cloudapp
X-IPS-LoggedIn
X-Skip-Cache
HA-Geolon
Cf-Ipcountry
X-RequestId
HA-Servedtime
HA-Urlpath
HA-Georegion
X-Varnish-Beresp-TTL
X-HTML-Minification-Powered-By
Uber-Trace-Id
X-Lb-Id
CDN
Ohc-Cache-HIT
X-Pf-Uncompressing
X-B3-Spanid
Backend-Name
X-VC-Cache
X-DC
X-Newrelic-Synthetics
X-Aicache-OS
X-Fastly-Country-Code
X-Cms-Context
X-Real-Ip
X-CMS-Context
XServer
X-UCC
N-Cache
X-Gateway-Cache-Key
X-Gateway-Cache-Status
X-WA
X-Gateway-Skip-Cache
X-Mrs-Age
X-Unique-Id-Primal
X-Mshield-Cache-Status
X-Mrs-Cache-Hits
X-Atg-Version
X-PF-Uncompressing
X-Instart-Info
X-Tb-Optimization-Total-Bytes-Saved
X-WR-MODIFICATION
X-Mrs-Cache
X-Phone
X-WebServer
Ohc-Response-Time
X-Shard
Amp-Access-Control-Allow-Source-Origin
X-Processor
X-Nananana
X-LB-ID
URI
Accept-Ch-Lifetime
X-Request-Start
GeoIP-Country-Code
T-Server
X-Release
X-BBXSRF
Pics-Label
GeoIP-Latitude
X-Hp-Webp
X-Oracle-Dms-Ecid
X-Server-W
X-Unique-Id
X-COUNTRY
X-MServer
X-CSRF-Token
X-APP
X-ServedByHost
X-Worker
X-FORWARDED-FOR
X-Datadome
X-SRV
X-VCT
X-Amzn-Remapped-Content-Length
X-GeoIP-City
Rt-Proxy-Cache
X-ND-Cache
X-Geo-Header
X-LiteSpeed-Cache-Control
Host-ID
A
X-VHOST
X-GoCache-CacheStatus
X-Served-From
X-SERVER-NAME
UCS
DataCenter
X-HS-Status
X-Check-Cacheable
X-CACHE-AGE
X-Requestid
X-GZIP
Request-EU
X-UPSTREAM-Address
X-Optimization
X-Cache-HT
Request-Country
X-Fastly-Cache-Hits
X-NGINX-Cache
Dnion-Transfer-Encoding
Geoip-Latitude
X-Cdn-Origin
Cneonction
X-BE
X-Fpc
FSS-Cache
FSS-Proxy
X-Planisys-CDN-TTL
X-Sn-Servicetimems
X-Fastly-Backend-Reqs
X-ID
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Vcache
V-Age
X-Backend-TTL
X-Git-Hash
WZWS-RAY
X-Varnish-URL
Proxy-Firewall
X-PAGE-TYPE
X-Dw-Trace-Id
Requestid
GeoIp-Country-Code
X-ServerName
Pragrma
X-Org
X-SVT-ORM-RULES
X-Csrf-Token
X-SVT-ORM-VERSION
X-Port
X-PJAX-URL
WP-Super-Cache
Serverid
Cache-Provider
X-Via-SSL
X-Via-Edge
X-Gen-Id
X-LiteSpeed-Tag
X-HostName
RequestUuid
Get-Access-Time
X-P-T
Server-Id
Is-Session-Tracking
X-NWS-UUID-VERIFY
188prxHost
X-Html-Edge-Cache
189phosttRef
178proxuri
DSUID
219prxHost
X-StackifyID
X-HTML-Edge-Cache
X-Fe
355prline
X-Request-Url
Inserted-Into-Cache-At
X-CS
X-RAMCache
Xxline
409pxxline
286prxHost
352pxline
ServerName
225prxHost