Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
CF-RAY
ETag
Link
Expect-CT
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Xss-Protection
X-Varnish
X-Request-Id
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Adblock-Key
X-Check
Alt-Svc
X-Cacheable
X-Generator
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-Cache-Status
X-AspNetMvc-Version
X-Permitted-Cross-Domain-Policies
X-Template
X-Iinfo
X-Language
Status
Timing-Allow-Origin
X-Buckets
X-Content-Security-Policy
Content-Encoding
X-CDN
X-Kinja-Server-Push
Xkey
X-Turbo-Charged-By
Upgrade
X-Type
Keep-Alive
Access-Control-Expose-Headers
X-Request-ID
WPE-Backend
X-Pass-Why
Access-Control-Max-Age
X-Backend
X-AH-Environment
CF-Ray
X-Cache-Group
X-Age
X-Drupal-Dynamic-Cache
X-Server
X-Ua-Compatible
X-Via
X-Proxy-Cache
Grace
X-Pingback
X-Nginx-Cache-Status
X-Server-Powered-By
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Hacker
X-UA-Device
X-Varnish-Cache
X-Page-Speed
EagleId
Request-Context
X-LiteSpeed-Cache
P3p
Cf-Railgun
X-Envoy-Upstream-Service-Time
X-CST
X-Swift-SaveTime
X-Swift-CacheTime
X-WebKit-CSP
Ali-Swift-Global-Savetime
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-Server-Id
X-Amz-Version-Id
X-Ac
X-Node
Server-Timing
X-OneAgent-JS-Injection
Feature-Policy
Allow
X-Cnection
X-Response-Time
X-Iejgwucgyu
X-Rq
Content-Location
X-Backend-Server
X-Cache-Lookup
Report-To
EagleEye-TraceId
Surrogate-Control
X-Readtime
X-Application-Context
X-Host
Request-Id
X-Url
X-ORACLE-DMS-ECID
X-Rack-Cache
X-Origin-Cache
X-Clacks-Overhead
X-Country
NEL
X-FTR-Request-ID
Rating
X-Country-Code
X-Cloud-Trace-Context
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-DataDome
X-Instart-Request-ID
X-Px
X-Ruxit-JS-Agent
X-Vhost
X-MS-InvokeApp
X-Mod-Pagespeed
Charset
X-VARITI-CCR
Accept-CH
Edge-Control
Pinterest-Generated-By
X-Goog-Hash
X-GitHub-Request-Id
Verso
PB-PID
Arc-Version
X-Mobile-Rewrite
PB-RID
X-ESI
X-DynaTrace
X-Vname
X-Version
X-PC
X-TtlSet
X-Server-Name
X-Varnish-TTL
X-TTL
X-Cdn
X-Powered-By-Plesk
X-D2id
X-Exp-Variant
X-Cdn-Fetch
X-Kinja-Server
X-Use-Magma
X-Exp-Id
X-GoogleNews-Bot
X-Kinja
X-Kinja-Build
X-Kinja-Revision
X-Cached
X-Upstream-Env
X-B3-TraceId
X-Origin-Upstream-Status
SPRequestGuid
X-Dispatcher
X-Powered-CMS
X-SharePointHealthScore
X-Abt-Application-Version
X-Recruiting
MS-Author-Via
X-T
Accept-CH-Lifetime
RTSS
X-Navigation-Version
Public-Key-Pins
X-Shield-Request-Id
X-ORACLE-DMS-RID
X-Oracle-Dms-Rid
X-Trace
Content-MD5
AR-PoweredBy
AR-CACHE
AR-ATIME
X-Amz-Rid
X-SRCache-Fetch-Status
X-Client-IP
X-SRCache-Store-Status
SPIisLatency
SPRequestDuration
X-HW
X-Fastly-Request-ID
X-Forwarded-Proto
X-DIS-Request-ID
X-Wix-Server-Artifact-Id
X-Accel-Buffering
Arr-Disable-Session-Affinity
Realpath
X-Server-ID
X-B
X-DynaTrace-JS-Agent
X-F-Cache
X-Upstream
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Amz-Meta-S3cmd-Attrs
X-Ser
Service-Worker-Allowed
X-Via-JSL
Pinterest-Version
X-Pinterest-Rid
X-FTR-Cache-Status
X-FTR-DC
X-FTR-Balancer
X-Country-Code-Real
X-Id
X-FTR-Realm
X-FTR-Backend-Server
X-FTR-Backend
X-Dw-Request-Base-Id
Front-End-Https
X-FTR-Expires
AR-Request-ID
Paypal-Debug-Id
X-Vcap-Request-Id
X-Varnish-Age
X-Dns-Prefetch-Control
X-Debug
X-Goog-Storage-Class
X-Ttl
Ar-Sid
X-Acc-Meta-Resource-Type
Nginx-Cache
X-N
X-MSEdge-Ref
X-Hits
X-Kinsta-Cache
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-NF-Request-ID
X-NewRelic-App-Data
X-FTR-Cache-Host
X-Logged-In
Mrf-Cache-Status
X-Mrf-Item-Lastmod
X-B3-TraceId-Primal
MRF-Tech
S
X-Mrf-Section-Lastmod
X-XRDS-Location
X-Akam-SW-Version
X-Forwarded-For
X-Grace
X-Frontend
X-PressLabs-Stats
X-HS-Hub-Id
X-HS-Content-Id
X-DataStream-Cache-Status
X-User-Agent
Alternate-Protocol
Tracecode
X-Amzn-Trace-Id
AMP-Access-Control-Allow-Source-Origin
X-CACHE-GROUP
DynaTrace
Server-Name
X-Content-Digest
X-Pad
Refresh
X-Cache-Key
X-Content-Options
MicrosoftSharePointTeamServices
Powered-By-ChinaCache
X-Analytics
X-TA-CDN-Provider
Backend-Timing
Accept-Charset
X-Content-Type
Fastcgi-Cache
X-Zen-Fury
X-AppVersion
X-Az
X-LB-Cache
X-Activity-Id
X-Fastcgi-Cache
TCN
X-Page-Id
X-IPLB-Instance
Host
FilterID
X-Rid
X-Middleton-Display
X-FastCGI-Cache
Display
X-Sol
X-Debug-Info
Access-Control-Request-Method
MS-CV
X-CF-Powered-By
ServerID
X-Magnolia-Registration
Cache-Status
TP-Cache
X-Middleton-Response
X-XRDS-LOCATION
Response
TP-L2-Cache
X-Cache-Hit
X-ATG-Version
X-Mobile
X-Content-Powered-By
X-Seen-By
X-Srv
X-WA-Info
Surrogate-Key
X-Hostname
X-VCache
X-B3-Sampled
X-Revision
X-Cached-By
Rt-Fastcgi-Cache
X-Request-Processing-Time
X-Request-Received
X-Varnish-Backend
X-SS-Set-Cookie
X-Cluster
X-Signature
X-Cache-Action
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-RateLimit-Remaining
X-B-Cache
X-Tumblr-User
X-Tumblr-Pixel-0
X-Content-Security-Policy-Report-Only
X-Tumblr-Pixel
X-Instance
X-Cache-Age
Source
X-Whom
X-PHP-Backend
Cleartype
X-Drupal-Cache-Tags
X-Framework
ViewerVersion
X-TT
X-Handled-By
X-Akamai-Edgescape
X-Platform-Server
Host-Header
X-Request-Guid
X-Wix-Request-Id
X-App-Environment
X-Origin-Server
X-Ruxit-Js-Agent
X-Edge-Location
Server-Info
X-GUploader-UploadID
X-Cache-Control
X-BCube-Filmed-By
DC
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Generated-By
X-Geo-Country
X-FW-Server
X-Real-IP
X-FW-Hash
X-App-Server
X-Cache-Rule
X-FW-Serve
X-NWS-LOG-UUID
X-FW-Static
X-FW-Type
X-AOL-HN
X-Varnish-Hostname
X-Oneagent-Js-Injection
X-Varnish-Server
Retry-After
Server-Node
X-Cache-2
Fusion-Template-Id
Fusion-Source
Fusion-Content-Id
Fusion-Content-Source
Fusion-Component-Id
X-Correlation-Id
Eomportal-Instance
X-FB-Debug
Cache
Payment
Webserver
X-WPE-Loopback-Upstream-Addr
X-TT-TIMESTAMP
X-Amz-Server-Side-Encryption
X-Varnish-Grace
X-Response-Served-From
Actual-Object-TTL
Access-Control-Allow-Method
X-Varnish-Hits
ServedBy
AsisCache
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
X-Device-Type
GEO-INFO
X-TX-ID
Filters
X-Cacheable-TTL
Ms-Operation-Id
X-WebKit-CSP-Report-Only
NGB
X-Region
X-Jobs
Content-Style-Type
X-UUID
Content-Script-Type
X-RTag
Viewport
X-Contextid
X-Adobe-Loc
X-Adobe-Content
X-Amz-Replication-Status
Healthy
X-Varnish-IP
X-Servedby
X-Cache-Config
X-Drupal-Cache-Contexts
X-Locale
X-RequestSource
X-Rendered-As
Country
Upgrade-Insecure-Requests
Cache-Tv-Group
X-UA-Device-Type
From-Origin
X-Accel-Expires
X-Cache-TTL-Remaining
Edge-Cache-Tag
HitType
X-Ezoic-Cdn
X-BACKEND-TTL
X-Cache-Server
X-Cache-Remote
X-Cache-TTL
X-VG-WebCache
Fastcgi-Useragent
X-Cache-Operation
Pagespeed
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Fastly-Restarts
X-FW-Dynamic
X-Content-Age
Cache-Tags
X-APP-VERSION
X-Hit
X-Upgrade-Enabled
X-Storage
X-Redis-Cache
X-S
X-Esi
X-Guploader-Uploadid
Datacenter
X-Mode
X-Source
Cache-Tag
X-App-Version
Served-By
NtCoent-Length
X-Upstream-Proxy
X-Generated
X-Cache-Var
X-Hl-Ver
X-Detected-As
X-Path-Route
X-RN-RSRV
Origin-Cache-Control
Origin-Edge-Control
X-Rule
X-GeoIP
X-Cache-Var-Map
Load-Balancing
X-Origin-Response-Time
X-NCache
X-Akamai-Request-ID
X-NGENIX-Cache
X-JoinUs
X-Is-Bot
Machine
X-Internal-Host
Xserver
X-Backend-Name
SRV
Meta-Geo
X-Environment-Context
X-Edge-IP
X-FC-Vary-Parameters
X-Grey
X-L-Path
X-Hosted-By
X-CDN-Cache
X-Cache-Category-Id
X-Agile
Selected-FE
X-Agile-Age
X-Agile-Id
X-BYPASS-REASON
X-Birta-Served
X-Labrador-Cache-Channel
X-Loop
X-TNCMS
X-Timing-Wait
X-Web-Node
X-Www-Served-By
X-Tb
Vix-Hermes-Req-Id
X-Time-Microsecs
X-Pubstack
X-Proxy
X-Origin-Host
X-Proxy-Build
X-ProxyCache-Key
X-ProxyCache-Status
Now
X-Birta-Cache-Post
X-Akamai-Transformed
TWC-Device-Class
TWC-Connection-Speed
X-Origin-Hint
TWC-GeoIP-Country
Cache-Key
X-Pc-Appver
X-Varnish-Cache-Hits
X-Varnish-Cacheable
X-IP
Property-Id
X-ApacheServer
Cache-Name
X-RateLimit-Limit
X-Pc-Hit
TWC-GeoIP-LatLong
X-RemovedCookies
Webcakes-App-Version
Webcakes-Region
X-ServerID
X-Cache-NE
X-Status
X-Pc-Key
X-Via-Fastly
TWC-Locale-Group
X-ProcessESI
X-PERF
Webcakes-App-Name
TWC-Privacy
X-Viewer-Country
X-CCM
X-Human
X-Format
X-Debug-Cache
S-Rt
DB-Nickname
X-PCL
X-Daa-Tunnel
Fastcgi-X-Cache-Version
X-OCL
X-Site-Version
X-Access
X-Proxied
We-Hiring
X-Section
X-Routing-Service
X-DataStream-MidMile-RTT
X-Cache-Enabled
X-DataStream-Origin-MEX-Latency
X-MP-GENERATED-AT
X-CACHE-KEY
Azure-Version
Public-Key-Pins-Report-Only
X-VG-TLSProxy
X-Zipkin-Id
Azure-SlotName
Azure-SiteName
X-Xfnlog-Site
Mail-Subject
Azure-InstanceId
Azure-RegionName
X-Original-Request
X-App-Name
X-Origin
Access-Control-Request-Headers
X-UA
X-Microcachable
X-Sucuri-ID
S-Cnection
X-Cdn-Forward
X-Ocache
User-Cache-Control
X-Protected-By
X-EdgeConnect-Cache-Status
Liferay-Portal
X-Nginx-Cache
X-Request-Time
X-FW-Version
User-Agent
LB
X-Tumblr-Pixel-3
X-Webstats-RespID
X-GEO
X-Proto
Cache-Hits
X-Yottaa-Metrics
Ohc-File-Size
X-Yottaa-Optimizations
X-Node-Name
X-GRACE
X-FB-TRIP-ID
X-Origin-CC
X-ES-SERVER
PageSpeed
X-Trace-Id
X-Nc
Powered
X-Correlation-ID
X-Endurance-Cache-Level
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
Frame-Options
X-Pc-Host
X-Forwarded-Host
X-Pc-Date
X-Parent-Response-Time
X-Upstream-HT
X-Upstream-CT
X-Time
L5d-Success-Class
X-Pc-Subdomain
IBM-Web2-Location
X-OVcl
X-OVcl-Cache
X-V
X-Unique-ID
X-ElasticPress-Search
X-Cache-Backend
X-B3-Traceid
AR-SID
X-Rocket-Nginx-Bypass
X-Ua
X-Origin-TTL
Section-Io-Cache
X-Varnish-Beresp-Ttl
OT-Force-Account-Verify
X-VWS-Id
X-LJ-Flow-ID
X-Vgn-Hpd-Reason
X-AWS-Id
Nel
X-R9-Blue-Green-Version
Decoy-Debug-TTL
Decoy-Debug-Status
Decoy-Debug-Key
Country-Code
Fly-Request-Id
Www
X-TIME
X-Accel-Expires-Debug
Memcached
X-Cache-Host
MD5-Digest
Viewtype
Resin-Trace
Mobile-Detection-Method
Meta-Geo-Continent
Node
Powered-By
Rendered-Blocks
GMS-Ver
X-Aed
X-Cache-Bucket
X-Block-Status
Fastly-SWR
Fastly-SIE
Ec-Rule-Version
X-BB-ID
X-B-Cookie
Fly-Cache
X-Amz-Meta-Cache-Control
X-Application
X-ARC
X-Auto-Login
X-Cache-FS-Status
X-External-Request-Id
X-Rewrite-Enabled
X-Request-UUID
X-Rojux
X-S-Cookie
X-ScT
X-S-Maxage
X-Region-Sid
X-Reboot
X-PAYTM-SRV-ID
X-Origin-Expires
X-PHP-Host
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Server-By
X-Server-Group
X-VG-WebServer
X-User
X-We-Are-Hiring
X-Wikidot-Backend
Xc-Version
X-Wikidot-Static-Cache
X-UE-Client-Country
X-Twitter-Response-Tags
X-SRCache-Key
X-ServiceProvider
X-Transaction
X-Trv-Group
X-TT-LOGID
X-Origin-Date
X-NU-AKA-ACS-Version
X-Developer
X-Destination
X-Distil-CS
X-DPWN-IS-SECURE
X-Fetched-On
Cache-Prefix
X-Date
X-Connection-Hash
X-Cache-URL
X-Cache-Info
X-Cdn-Srv
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-From
X-Gen-Mode
X-Li-Fabric
X-Irp-Debug
X-Li-Pop
X-LI-Proto
X-Micro-Cache
X-LI-UUID
X-Info
X-IN-WAF
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Generated-In
X-Hnp-Log
X-IN-APIGATEWAY
X-IN-SSL-APIGATEWAY
X-Cache-Id
VivaBuild
Arc-Country
BehaviorPad-Version
Fastcgi-X-Cache
X-Server-Cache
X-Edge-Cache-Key
X-Edge-Cache
X-Cluster-Node
X-Dynatrace-Js-Agent
X-Dc
X-Dispatcher-Server
X-Distributor
X-Debug-Log
X-D
X-CUA
X-Fastly-Cache
X-Debug-Cookies
X-FireWall-Port
X-Crawler
X-Level-Front-Cache
X-Generated-On
Mn-Server-Ip
X-G
X-Hash
X-Cache-Expires
X-A-Wwc
X-Actual-URL
X-Alternate-Cache-Key
X-A-Dgt
X-A-Dcw
X-A-Ccd
X-A-Dam
X-Backend-Host
X-Backend-Url
X-Cache-Grace
X-Clientip
X-Location
X-Cache-Debug
X-Bip
X-C
X-Core-Mission
X-Node-Id
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-ShopId
X-ShardId
X-Server-IP
X-Sf
X-Stale
X-Svr
X-Var-Ttl
X-Variation
X-Varnish-Action
X-Via-NSCOPI
X-Thinkindot-L3
X-Swa-Ws
X-Thanos
X-Returned-From-PostProcessResponse
X-Returned-From-DLL
X-Passed-To
X-Passed-To-BeforeDispatch
X-Passed-To-DLL
X-NX-Host
X-A
X-Matched-Rule
X-Nginx-Cache-Key
X-Passed-To-PostProcessResponse
X-Proxy-Cache-Status
X-Response-By
X-Returned-From
X-Returned-From-BeforeDispatch
X-Request-URI
X-RateLimit-Remaining-Second
X-Proxy-Upstream
X-RateLimit-Limit-Second
X-Logtrace-Id
X-Policy
Origin
Magicmarker
Lfy
Platform
Proxy-Connection
SD-X-WS
Request-Time
Is-Eu
Adler-Geo
CDCHOST
Countrycode
Content-Disposition
Backend
Fastly-Backend-Name
Ajk
Fastly-Soc-X-Request-Id
Server-Host
On-Server
Thinkindot-CacheControl
True-Client-Country-4JS
Thinkindot-CacheControl-Type
Who
Web-Mar-Node
Thinkindot-Control
X-Via-CDN
X-Sucuri-Cache
Warning
Pramga
GW-Server
X-Eu-Site
Heartbleed
X-Generation-Time
Release
Ha-Gx-Prefs
X-Died
HA-Ipaddr
Cache-Cookie-Set-Lfrom
IsBot
X-Fstrz
X-Instart-Isnd
X-GeoIP-Country-Code
Pagetype
X-LAGOON
X-No-Session
SS
X-Platform
X-Qloud-Router
X-CGP
X-Backend-State
X-Device-Os
X-Gannett-Site-Version
X-Key
X-Secret
X-F5-Cache
AKAMAI
Cache-Cookie-Set-Idcheck
X-SERVER
X-Developers
Fastly-SSL
X-Epic-Correlation-Id
X-UnsetCookies
Cache-Cookie-Set-From
X-Varnish-Authentication
Server-Surrogate-Control
X-Cache-ASPX
Server-Int
X-Core-Value
Server-Cache-Control
RNT-Time
RNT-Machine
X-SIPLIST1
X-Croise-Owner
X-HS-Cache-Config
HostName
X-Ratelimit-Remaining
X-Debug-Cache-Expiry
X-MSEdge-Features
Apple-News-Services-Host
X-Page-Type
Server-ID
X-Server-Time
X-MSEdge-Flight
CACHE
X-Debug-Cache-Store
Apple-News-Services-Handled
X-Debug-Cache-Fetch
Apple-News-Services-Parsed-Url
X-Amz-Meta-Surrogate-Control
X-TrackingId
X-Varnish-Url
Apple-News-Services-Request-Url
X-Up
REQUESTUUID
X-EIG-Tracking-Id
Kp-EeAlive
X-Be
Version
X-Sedo-Request-Id
X-Cache-Miss-From
X-Pjax-Url
NGX
X-Servername
X-Refresh
PFcat
RequestId
SID
X-Varnish-Ttl
X-Newrelic-App-Data
Esi-Enabled
X-Cache-CFC
X-Store
X-SN
X-Owner
Time
X-CDN-Forward
X-URL
X-RCS-CacheZone
MI-Cache-Age
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
MI-Cache
Odigeo-Trace-Id
MIME-Version
X-Layer
X-Oss-Request-Id
X-MI-In-Market
X-From-Cache
X-Oss-Server-Time
MI-API
X-Oss-Storage-Class
X-NC
X-B3-SpanId
X-Ratelimit-Limit
Cdn
X-IPS-LoggedIn
X-RequestId
X-FPC
Mime-Version
PICS-Label
Cteonnt-Length
Hostname
X-Geo
HA-Geolat
HA-Host
HA-Geolon
HA-Cloudapp
HTTPS
HA-Geocity
HA-Geocountry
HA-Georegion
HA-Servedtime
HA-Urlpath
FastCGI-Cache
X-Hyper-Cache
X-Unique-Id-Primal
X-Servedbyhost
X-Mrs-Cache-Hits
X-Mrs-Age
X-Mrs-Cache
Backend-Name
X-Mshield-Cache-Status
X-CMS-Context
X-Webkit-CSP
X-Webkit-Csp
Processtime
X-Edge-Server
Cdn-Request-Time
X-Real-Ip
Cdn-Host
X-Load-Cache
Memory
X-CSRF-TOKEN
X-Req
X-CLOUD-TRACE-CONTEXT
CF-IPCountry
Cf-Ipcountry
X-B3-Spanid
X-Amzn-Remapped-Date
Ohc-Response-Time
X-Phone
ProcessTime
X-Wa
X-WebServer
X-Instart-Info
X-Mobile-URL
X-Amzn-Remapped-Connection
CDN
X-VServer
X-NodeID
X-Pf-Uncompressing
Cross-Origin-Window-Policy
GeoIP-Country-Code
X-DC
X-Request-Start
X-Varnish-Beresp-TTL
X-GZip
X-HS-Combine-CSS
X-HTML-Minification-Powered-By
GeoIP-Latitude
X-Release
X-Lb-Id
X-WR-MODIFICATION
X-Aicache-OS
X-Newrelic-Synthetics
XServer
X-Fastly-Country-Code
X-PF-Uncompressing
X-Skip-Cache
X-Atg-Version
X-WA
X-HOST
URI
X-Server-W
Ohc-Cache-HIT
Rt-Proxy-Cache
T-Server
X-ND-Cache
X-FORWARDED-FOR
X-Served-From
Accept-Ch-Lifetime
X-VC-Cache
X-Unique-Id
Amp-Access-Control-Allow-Source-Origin
X-Tb-Optimization-Total-Bytes-Saved
X-Cms-Context
X-Nananana
X-Oracle-Dms-Ecid
X-GoCache-CacheStatus
X-APP
Uber-Trace-Id
X-ServedByHost
X-LB-ID
X-CSRF-Token
X-Gateway-Skip-Cache
N-Cache
X-COUNTRY
X-MServer
X-UCC
X-Gateway-Cache-Status
X-Gateway-Cache-Key
V-Age
X-Sn-Servicetimems
X-Datadome
Pics-Label
X-Worker
X-Cdn-Origin
X-SRV
X-Fastly-Cache-Hits
Proxy-Firewall
X-HS-Status
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-LiteSpeed-Cache-Control
X-UPSTREAM-Address
A
X-Processor
X-SERVER-NAME
X-BBXSRF
X-Hp-Webp
Get-Access-Time
DataCenter
X-CACHE-AGE
Is-Session-Tracking
X-P-T
Cneonction
X-Check-Cacheable
X-Requestid
ServerName
X-GZIP
X-NGINX-Cache
X-RCS-Backend
X-HostName
Geoip-Latitude
X-BE
X-ID
X-Vcache
X-Cache-HT
Dnion-Transfer-Encoding
X-Optimization
X-Vg-Webcache
X-Shard
X-Backend-TTL
X-Fe
X-Csrf-Token
X-GDPR
X-Varnish-URL
GeoIp-Country-Code
X-PJAX-URL
X-StackifyID
X-Geo-Header
Requestid
X-GeoIP-City
X-VCT
X-ServerName
X-Amzn-Remapped-Content-Length
X-PAGE-TYPE
X-Port
WP-Super-Cache
Host-ID
Serverid
X-NWS-UUID-VERIFY
Server-Id
Inserted-Into-Cache-At
X-Org
WZWS-RAY
UCS
X-Fastly-Backend-Reqs
X-LiteSpeed-Tag
Cache-Provider
RequestUuid
X-Git-Hash
X-Dw-Trace-Id
X-RAMCache
352pxline
188prxHost
189phosttRef
178proxuri
DSUID
X-Via-Edge
X-Via-SSL
219prxHost
225prxHost
Xxline
X-Request-Url
409pxxline
355prline
286prxHost
X-CS