Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
CF-RAY
ETag
Link
Expect-CT
Via
X-XSS-Protection
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Xss-Protection
X-Varnish
X-Request-Id
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Adblock-Key
X-Check
Alt-Svc
X-Cacheable
X-Generator
Content-Security-Policy-Report-Only
X-AspNetMvc-Version
X-Cache-Status
X-DNS-Prefetch-Control
X-Permitted-Cross-Domain-Policies
X-Iinfo
X-Template
X-Language
Status
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Buckets
X-Content-Security-Policy
Content-Encoding
X-Kinja-Server-Push
Xkey
X-Turbo-Charged-By
X-CDN
Upgrade
X-Type
Keep-Alive
Access-Control-Expose-Headers
WPE-Backend
X-Pass-Why
X-AH-Environment
X-Backend
Access-Control-Max-Age
X-Age
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Server
X-Proxy-Cache
X-Request-ID
X-Via
Grace
X-Pingback
X-Nginx-Cache-Status
X-Server-Powered-By
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Hacker
X-Varnish-Cache
X-UA-Device
X-Page-Speed
EagleId
Request-Context
P3p
X-LiteSpeed-Cache
X-Envoy-Upstream-Service-Time
Cf-Railgun
X-Ua-Compatible
X-CST
X-Swift-SaveTime
X-Swift-CacheTime
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Ali-Swift-Global-Savetime
X-Device
X-Amz-Version-Id
X-Server-Id
X-WebKit-CSP
Server-Timing
X-Ac
Allow
X-Node
X-OneAgent-JS-Injection
X-Response-Time
Feature-Policy
X-Rq
X-Cnection
X-Iejgwucgyu
Content-Location
X-Backend-Server
X-Cache-Lookup
Report-To
EagleEye-TraceId
Surrogate-Control
X-Host
X-Readtime
X-Application-Context
Request-Id
X-ORACLE-DMS-ECID
X-Rack-Cache
X-Url
X-Origin-Cache
X-Clacks-Overhead
X-Country
NEL
X-FTR-Request-ID
Rating
X-Country-Code
X-Cloud-Trace-Context
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Cdn
X-Ruxit-JS-Agent
X-DataDome
X-Px
X-Instart-Request-ID
X-Mod-Pagespeed
Charset
X-Vhost
X-VARITI-CCR
X-MS-InvokeApp
Pinterest-Generated-By
Accept-CH
X-Goog-Hash
Edge-Control
Verso
X-GitHub-Request-Id
X-TtlSet
X-Vname
X-PC
X-Upstream-Env
PB-PID
PB-RID
Arc-Version
X-Mobile-Rewrite
X-Server-Name
X-Dns-Prefetch-Control
X-Version
X-Powered-By-Plesk
X-Origin-Upstream-Status
X-ESI
X-D2id
X-B3-TraceId
X-Cdn-Fetch
X-GoogleNews-Bot
X-Exp-Variant
X-Exp-Id
X-Kinja-Server
X-Kinja-Build
X-Use-Magma
X-Kinja
X-Kinja-Revision
X-Cached
X-DynaTrace
X-Dispatcher
X-ORACLE-DMS-RID
SPRequestGuid
X-TTL
X-Recruiting
X-SharePointHealthScore
X-Varnish-TTL
MS-Author-Via
X-Abt-Application-Version
X-Powered-CMS
X-Navigation-Version
Accept-CH-Lifetime
Content-MD5
RTSS
AR-ATIME
AR-PoweredBy
AR-CACHE
X-Shield-Request-Id
X-T
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Trace
Public-Key-Pins
X-Forwarded-Proto
X-Client-IP
X-DynaTrace-JS-Agent
Arr-Disable-Session-Affinity
X-Amz-Rid
X-Fastly-Request-ID
X-HW
X-Wix-Server-Artifact-Id
X-Accel-Buffering
SPRequestDuration
SPIisLatency
Realpath
X-Server-ID
X-DIS-Request-ID
X-Oracle-Dms-Rid
Service-Worker-Allowed
X-Goog-Stored-Content-Length
AR-Request-ID
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Amz-Meta-S3cmd-Attrs
Paypal-Debug-Id
X-Ttl
Front-End-Https
X-Upstream
X-FTR-Cache-Status
X-FTR-DC
X-FTR-Balancer
X-FTR-Backend
X-FTR-Realm
X-Country-Code-Real
X-FTR-Backend-Server
X-Ser
X-B
X-FTR-Expires
Pinterest-Version
X-Pinterest-Rid
X-Via-JSL
X-Id
X-F-Cache
X-XRDS-Location
X-Vcap-Request-Id
X-Dw-Request-Base-Id
X-Debug
X-Varnish-Age
X-Goog-Storage-Class
X-Acc-Meta-Resource-Type
X-MSEdge-Ref
X-Kinsta-Cache
X-N
X-DataStream-Cache-Status
X-Hits
Nginx-Cache
Ar-Sid
X-NF-Request-ID
X-FTR-Cache-Host
S
X-Logged-In
X-Akam-SW-Version
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Mrf-Section-Lastmod
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-Mrf-Item-Lastmod
X-Forwarded-For
X-NewRelic-App-Data
Tracecode
X-FastCGI-Cache
Alternate-Protocol
X-Frontend
X-User-Agent
X-PressLabs-Stats
X-HS-Hub-Id
X-HS-Content-Id
X-Amzn-Trace-Id
X-Grace
X-CACHE-GROUP
TCN
AMP-Access-Control-Allow-Source-Origin
Server-Name
X-Content-Options
X-Content-Digest
Powered-By-ChinaCache
X-Sol
X-Middleton-Display
Display
Refresh
X-Content-Type
Access-Control-Request-Method
X-Pad
X-Cache-Key
Backend-Timing
X-Page-Id
X-Analytics
MicrosoftSharePointTeamServices
Accept-Charset
X-LB-Cache
X-Zen-Fury
X-Middleton-Response
FilterID
Response
X-Activity-Id
X-Rid
X-IPLB-Instance
X-Debug-Info
X-CF-Powered-By
X-AppVersion
X-Az
Host
X-VCache
DynaTrace
ServerID
MS-CV
X-Hostname
X-Cache-Hit
Cache-Status
Fastcgi-Cache
X-Magnolia-Registration
X-GUploader-UploadID
TP-Cache
TP-L2-Cache
X-Srv
X-RateLimit-Remaining
X-Seen-By
X-Content-Powered-By
X-Mobile
X-ATG-Version
X-Revision
X-Cached-By
X-Fastcgi-Cache
X-WA-Info
Host-Header
X-Varnish-Backend
X-Whom
X-Real-IP
X-Request-Received
X-Request-Processing-Time
Server-Info
Surrogate-Key
X-B3-Sampled
X-Instance
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-SS-Set-Cookie
X-Cluster
X-Cache-Action
DC
X-Handled-By
X-Drupal-Cache-Tags
Source
X-Content-Security-Policy-Report-Only
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-0
X-Request-Guid
X-Platform-Server
ViewerVersion
X-B-Cache
X-Signature
X-Wix-Request-Id
Cleartype
X-PHP-Backend
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Framework
Fusion-Content-Id
Fusion-Component-Id
X-Origin-Server
X-Akamai-Edgescape
Fusion-Content-Source
X-TT
Fusion-Template-Id
Fusion-Source
X-Cache-Age
X-App-Environment
X-Geo-Country
X-App-Server
X-FW-Serve
X-FW-Server
X-FW-Type
X-FW-Hash
X-FW-Static
X-Generated-By
Rt-Fastcgi-Cache
X-Oneagent-Js-Injection
X-AOL-HN
X-Varnish-Server
X-BCube-Filmed-By
X-Cache-Control
Server-Node
X-XRDS-LOCATION
X-Edge-Location
X-Ruxit-Js-Agent
X-Upstream-Proxy
X-Varnish-Hostname
X-NWS-LOG-UUID
X-Cache-Rule
Retry-After
Payment
X-Varnish-Grace
X-Amz-Server-Side-Encryption
X-TA-CDN-Provider
X-Correlation-Id
Access-Control-Allow-Method
X-Amz-Replication-Status
X-Cache-2
X-Response-Served-From
X-Rendered-As
X-TT-TIMESTAMP
X-Ezoic-Cdn
X-FB-Debug
ServedBy
X-Cache-Config
X-UA-Device-Type
GEO-INFO
X-Tumblr-Pixel-1
X-Cacheable-TTL
X-Tumblr-Pixel-2
Eomportal-Instance
AsisCache
Actual-Object-TTL
X-Varnish-Hits
X-Jobs
NGB
Filters
X-Region
X-WebKit-CSP-Report-Only
Content-Style-Type
X-Contextid
Healthy
X-Drupal-Cache-Contexts
Webserver
X-TX-ID
Ms-Operation-Id
X-UUID
X-RTag
Content-Script-Type
HitType
Viewport
X-Adobe-Content
X-Adobe-Loc
X-VG-WebCache
Upgrade-Insecure-Requests
X-Varnish-IP
Country
X-Locale
X-RequestSource
X-Accel-Expires
Cache-Tv-Group
From-Origin
X-Cache-TTL
X-Esi
Fastcgi-Useragent
X-Cache-TTL-Remaining
Pagespeed
X-Device-Type
X-FW-Dynamic
X-Cache-Server
X-BACKEND-TTL
X-Content-Age
X-Kong-Upstream-Latency
Edge-Cache-Tag
X-Kong-Proxy-Latency
X-WPE-Loopback-Upstream-Addr
X-Servedby
Cache-Tags
Cache
X-Cache-Remote
X-Redis-Cache
X-Upgrade-Enabled
X-Source
X-DataStream-MidMile-RTT
X-Cache-Operation
X-DataStream-Origin-MEX-Latency
Datacenter
X-APP-VERSION
X-Hit
X-RateLimit-Limit
X-Storage
X-GeoIP
Fastly-Restarts
NtCoent-Length
X-Mode
Cache-Tag
Vix-Hermes-Req-Id
X-Cache-Var-Map
X-Origin-Response-Time
X-Cache-Var
X-Path-Route
X-Backend-Name
X-Loop
X-Labrador-Cache-Channel
X-Hl-Ver
X-Internal-Host
X-Is-Bot
X-JoinUs
X-Pubstack
X-RN-RSRV
X-Agile
Served-By
X-S
Machine
X-Agile-Age
X-TNCMS
X-Akamai-Request-ID
X-Agile-Id
X-Detected-As
X-Time-Microsecs
Load-Balancing
Meta-Geo
X-NCache
X-Birta-Cache-Post
X-Microcachable
X-Status
Cache-Key
X-Origin-Host
X-Proxy-Build
Now
X-Varnish-Cache-Hits
X-L-Path
X-Birta-Served
X-Environment-Context
X-Cache-Category-Id
X-Edge-IP
X-CDN-Cache
X-FC-Vary-Parameters
X-BYPASS-REASON
X-Hosted-By
X-Grey
X-Generated
X-ProxyCache-Key
X-Proxy
X-Timing-Wait
X-ProxyCache-Status
Origin-Edge-Control
X-Varnish-Cacheable
S-Rt
X-IP
X-Www-Served-By
Selected-FE
X-ServerID
X-Tb
Xserver
Origin-Cache-Control
X-Rule
TWC-Device-Class
TWC-Connection-Speed
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Locale-Group
Webcakes-App-Name
SRV
X-Cache-Enabled
X-ApacheServer
Webcakes-Region
Property-Id
Webcakes-App-Version
Cache-Name
X-CACHE-KEY
X-Format
X-RemovedCookies
X-ProcessESI
X-VG-TLSProxy
X-Via-Fastly
X-Web-Node
X-Viewer-Country
X-PERF
X-Origin-Hint
TWC-Privacy
X-Section
X-MP-GENERATED-AT
Azure-RegionName
Azure-InstanceId
X-App-Version
X-Human
X-Akamai-Transformed
X-ES-SERVER
User-Agent
X-Access
Public-Key-Pins-Report-Only
Access-Control-Request-Headers
X-OCL
X-PCL
X-NGENIX-Cache
Cache-Hits
DB-Nickname
Azure-Version
X-CCM
Azure-SiteName
Fastcgi-X-Cache-Version
Azure-SlotName
X-Zipkin-Id
X-Debug-Cache
We-Hiring
X-Proxied
X-App-Name
X-Site-Version
X-Xfnlog-Site
X-Routing-Service
Mail-Subject
X-GEO
Liferay-Portal
X-Node-Name
X-Daa-Tunnel
X-EdgeConnect-Cache-Status
X-FW-Version
S-Cnection
X-Protected-By
X-Original-Request
CACHE
X-Origin
X-Pc-Key
X-Pc-Appver
X-Sucuri-ID
X-Nginx-Cache
X-Pc-Hit
X-Cache-NE
X-Proto
LB
PageSpeed
X-Yottaa-Metrics
X-Yottaa-Optimizations
AR-SID
X-Ocache
X-Ua
X-VWS-Id
X-AWS-Id
X-LJ-Flow-ID
X-Cdn-Forward
X-Trace-Id
Powered
X-GRACE
User-Cache-Control
X-Request-Time
X-Varnish-Ttl
X-Endurance-Cache-Level
X-Forwarded-Host
X-Cluster-Node
X-Guploader-Uploadid
X-Correlation-ID
Ohc-File-Size
L5d-Success-Class
X-Tumblr-Pixel-3
X-UA
X-Webkit-CSP
Frame-Options
Section-Io-Cache
X-Webstats-RespID
X-Unique-ID
X-Time
X-FB-TRIP-ID
X-V
X-URL
X-EIG-Tracking-Id
X-Nc
X-Origin-CC
OT-Force-Account-Verify
X-Webkit-Csp
X-OVcl
X-OVcl-Cache
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-Origin-TTL
Nel
X-From
X-ElasticPress-Search
Decoy-Debug-Key
Decoy-Debug-Status
Decoy-Debug-TTL
X-Cache-Backend
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Generated-In
X-LI-Proto
X-IN-WAF
X-Info
X-Irp-Debug
X-Li-Fabric
X-Li-Pop
X-IN-APIGATEWAY
X-LI-UUID
X-Developer
Node
On-Server
X-Backend-State
X-B-Cookie
Mobile-Detection-Method
X-BB-ID
X-Cache-FS-Status
MD5-Digest
Memcached
Meta-Geo-Continent
X-Auto-Login
Powered-By
SD-X-WS
Www
VivaBuild
Viewtype
X-Accel-Expires-Debug
X-Aed
X-ARC
X-Application
X-Amz-Meta-Cache-Control
Rendered-Blocks
X-Cache-Grace
X-Cache-Host
X-Distil-CS
Ec-Rule-Version
Fastly-SIE
X-Destination
Country-Code
X-DPWN-IS-SECURE
X-Fetched-On
BehaviorPad-Version
X-External-Request-Id
Cache-Prefix
Fastly-SWR
Fly-Cache
X-Cdn-Srv
X-Cache-URL
X-Cache-Info
X-Cache-Id
X-CF-Lambda-Fn
X-CF-Lambda-Version
Fly-Request-Id
X-Date
GMS-Ver
X-Connection-Hash
Arc-Country
X-Node-Id
X-R9-Blue-Green-Version
X-Rewrite-Enabled
X-Varnish-Beresp-Ttl
X-SRCache-Key
X-VG-WebServer
X-Rojux
X-We-Are-Hiring
X-ScT
X-S-Maxage
X-S-Cookie
X-User
X-UE-Client-Country
X-Reboot
X-Response-By
X-Request-UUID
X-Region-Sid
X-Rebelmouse-Surrogate-Control
X-Transaction
X-Twitter-Response-Tags
X-Rebelmouse-Cache-Control
X-TT-LOGID
X-Trv-Group
X-Wikidot-Backend
X-Rocket-Nginx-Bypass
X-Origin-Expires
X-PAYTM-SRV-ID
X-Origin-Date
X-Server-Group
X-Server-By
X-NU-AKA-ACS-Version
X-PHP-Host
Xc-Version
X-ServiceProvider
X-Wikidot-Static-Cache
X-Newrelic-App-Data
IBM-Web2-Location
X-Parent-Response-Time
X-Cache-Bucket
X-C
X-A
X-Sf
X-Cache-Debug
X-Alternate-Cache-Key
X-Returned-From-DLL
X-Svr
X-Actual-URL
X-Secret
X-Returned-From
X-Returned-From-BeforeDispatch
X-A-Ccd
Who
X-Cache-Expires
X-Server-IP
X-ShopId
X-SIPLIST1
X-Sorting-Hat-PodId
X-Shopify-Stage
X-Backend-Host
X-A-Dgt
X-Swa-Ws
X-Backend-Url
X-Sorting-Hat-ShopId
X-Stale
X-A-Dam
X-A-Wwc
X-A-Dcw
X-Block-Status
X-ShardId
X-Bip
X-Returned-From-PostProcessResponse
X-Thinkindot-L3
X-Proxy-Upstream
X-Proxy-Cache-Status
X-Policy
X-LAGOON
X-RateLimit-Limit-Second
X-Hnp-Log
X-Generated-On
X-GeoIP-Country-Code
X-Vgn-Hpd-Reason
X-Hash
X-Level-Front-Cache
X-Platform
X-Location
X-Logtrace-Id
X-Matched-Rule
X-Micro-Cache
X-NX-Host
X-Passed-To
SID
X-Passed-To-PostProcessResponse
X-Passed-To-DLL
X-Passed-To-BeforeDispatch
X-RateLimit-Remaining-Second
X-Gen-Mode
X-Thanos
X-Debug-Cookies
X-Nginx-Cache-Key
X-Debug-Log
X-D
X-CUA
X-CGP
X-Clientip
X-Core-Mission
X-Crawler
X-Dispatcher-Server
X-Distributor
X-Varnish-Action
True-Client-Country-4JS
X-G
X-Gannett-Site-Version
X-Fastly-Cache
X-Eu-Site
X-Var-Ttl
X-Epic-Correlation-Id
X-Variation
X-Request-URI
Thinkindot-CacheControl
Magicmarker
Lfy
IsBot
Backend
Platform
Ajk
Proxy-Connection
CDCHOST
Is-Eu
Fastly-Soc-X-Request-Id
Ha-Gx-Prefs
Fastly-SSL
Fastly-Backend-Name
HA-Ipaddr
Content-Disposition
Countrycode
Request-Time
Origin
Thinkindot-CacheControl-Type
Adler-Geo
X-SERVER
Server-Host
Mn-Server-Ip
Thinkindot-Control
X-Via-CDN
Warning
X-HS-Cache-Config
X-Croise-Owner
X-Qloud-Router
GW-Server
X-Device-Os
X-Debug-Cache-Expiry
X-Owner
X-Debug-Cache-Store
X-No-Session
X-MSEdge-Flight
X-Debug-Cache-Fetch
X-MSEdge-Features
Cache-Cookie-Set-Lfrom
Apple-News-Services-Request-Url
X-FireWall-Port
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
AKAMAI
Apple-News-Services-Handled
X-UnsetCookies
X-Fstrz
X-F5-Cache
Cache-Cookie-Set-Idcheck
X-Instart-Isnd
Cache-Cookie-Set-From
X-SN
X-Sucuri-Cache
X-Developers
Pramga
X-Amz-Meta-Surrogate-Control
X-Up
X-TrackingId
Server-Surrogate-Control
X-Cache-ASPX
X-Varnish-Authentication
Release
X-Core-Value
Server-Int
Web-Mar-Node
Server-Cache-Control
RNT-Time
Resin-Trace
RNT-Machine
Heartbleed
NGX
SS
Hostname
X-Pc-Host
X-Dc
X-Pc-Date
X-Pc-Subdomain
X-Key
Kp-EeAlive
Odigeo-Trace-Id
Server-ID
X-Page-Type
X-Upstream-HT
X-Upstream-CT
Pagetype
X-Server-Time
X-TIME
X-Varnish-Url
X-Cache-Miss-From
X-Pjax-Url
X-IN-SSL-APIGATEWAY
REQUESTUUID
X-Servername
X-Server-Cache
X-Sedo-Request-Id
X-B3-Traceid
X-Be
HTTPS
X-Refresh
X-Generation-Time
MIME-Version
X-NC
X-Oss-Request-Id
Cdn-Host
X-Via-NSCOPI
Cdn-Request-Time
X-Edge-Server
FastCGI-Cache
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-Died
X-Oss-Storage-Class
X-Oss-Object-Type
X-B3-SpanId
Fastcgi-X-Cache
X-CDN-Forward
RequestId
HostName
X-From-Cache
ProcessTime
X-FPC
X-Servedbyhost
Version
X-Edge-Cache
X-Edge-Cache-Key
X-Req
PICS-Label
PFcat
X-Mobile-URL
Cteonnt-Length
Cdn
X-CSRF-TOKEN
Time
X-Amzn-Remapped-Connection
X-VServer
X-Amzn-Remapped-Date
X-NodeID
Cross-Origin-Window-Policy
CF-IPCountry
Mime-Version
X-Load-Cache
X-Store
X-Cache-CFC
Esi-Enabled
X-HS-Combine-CSS
X-CLOUD-TRACE-CONTEXT
X-GZip
MI-Cache-Age
X-Dynatrace-Js-Agent
X-Wa
X-Skip-Cache
Memory
X-MI-In-Market
MI-API
X-RCS-CacheZone
X-Layer
MI-Cache
X-DC
X-Ratelimit-Remaining
CDN
Processtime
HA-Geocountry
HA-Urlpath
HA-Host
HA-Georegion
HA-Geocity
HA-Geolat
HA-Geolon
HA-Cloudapp
HA-Servedtime
X-Datadome
Uber-Trace-Id
X-IPS-LoggedIn
X-RequestId
Ohc-Cache-HIT
X-Hyper-Cache
X-Newrelic-Synthetics
X-Geo
X-Lb-Id
X-Ratelimit-Limit
X-HTML-Minification-Powered-By
X-Aicache-OS
X-Varnish-Beresp-TTL
X-VC-Cache
Cf-Ipcountry
Backend-Name
X-Pf-Uncompressing
X-Cms-Context
XServer
X-Gateway-Cache-Key
X-Gateway-Cache-Status
X-Gateway-Skip-Cache
X-UCC
X-Atg-Version
X-PF-Uncompressing
X-CMS-Context
X-Fastly-Country-Code
N-Cache
X-B3-Spanid
X-Real-Ip
X-LB-ID
X-Instart-Info
X-WR-MODIFICATION
X-WA
X-Shard
X-Tb-Optimization-Total-Bytes-Saved
Amp-Access-Control-Allow-Source-Origin
X-Mrs-Age
X-Mrs-Cache-Hits
X-Unique-Id-Primal
X-Mshield-Cache-Status
X-Mrs-Cache
T-Server
X-Processor
Accept-Ch-Lifetime
X-Phone
URI
Ohc-Response-Time
X-Nananana
X-WebServer
X-Release
X-Request-Start
X-BBXSRF
X-Hp-Webp
GeoIP-Country-Code
X-Oracle-Dms-Ecid
X-COUNTRY
X-Server-W
GeoIP-Latitude
X-MServer
Pics-Label
X-APP
X-Worker
X-CSRF-Token
X-SRV
X-Unique-Id
X-FORWARDED-FOR
X-VCT
X-Amzn-Remapped-Content-Length
X-Geo-Header
X-GeoIP-City
Host-ID
A
X-ServedByHost
X-LiteSpeed-Cache-Control
X-VHOST
X-SERVER-NAME
X-Dynatrace
UCS
X-GoCache-CacheStatus
X-ND-Cache
Rt-Proxy-Cache
X-GZIP
X-CACHE-AGE
X-HS-Status
DataCenter
X-Served-From
X-Backend-TTL
X-UPSTREAM-Address
X-Fastly-Cache-Hits
X-Requestid
X-Cache-HT
X-BE
Request-Country
X-Check-Cacheable
X-Optimization
Request-EU
X-NGINX-Cache
Pragrma
X-Fpc
Geoip-Latitude
FSS-Proxy
Dnion-Transfer-Encoding
FSS-Cache
X-Planisys-CDN-TTL
X-Vcache
X-Dw-Trace-Id
WP-Super-Cache
X-ID
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Sn-Servicetimems
Dynatrace
X-PAGE-TYPE
WZWS-RAY
X-Varnish-URL
X-Git-Hash
X-ServerName
X-Fastly-Backend-Reqs
X-Cdn-Origin
V-Age
Requestid
GeoIp-Country-Code
X-Org
X-Csrf-Token
RequestUuid
Cneonction
X-Port
X-PJAX-URL
Serverid
X-Via-Edge
X-Via-SSL
X-SVT-ORM-VERSION
X-Gen-Id
Cache-Provider
X-Html-Edge-Cache
Proxy-Firewall
X-HostName
X-SVT-ORM-RULES
Server-Id
Lb
X-NWS-UUID-VERIFY
Inserted-Into-Cache-At
X-LiteSpeed-Tag
352pxline
X-Fe
286prxHost
355prline
409pxxline
X-Request-Url
X-P-T
Xxline
DSUID
225prxHost
188prxHost
Is-Session-Tracking
178proxuri
189phosttRef
Get-Access-Time
219prxHost
X-CS
X-RAMCache