Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
CF-RAY
ETag
Link
Expect-CT
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Xss-Protection
X-Varnish
X-Request-Id
CF-Cache-Status
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Adblock-Key
X-Check
Alt-Svc
X-Cacheable
X-Generator
Content-Security-Policy-Report-Only
X-DNS-Prefetch-Control
X-Cache-Status
X-AspNetMvc-Version
X-Permitted-Cross-Domain-Policies
X-Iinfo
X-Template
Status
X-Language
Timing-Allow-Origin
X-Buckets
X-Content-Security-Policy
Content-Encoding
X-CDN
X-Kinja-Server-Push
Xkey
X-Turbo-Charged-By
Upgrade
X-Type
Access-Control-Expose-Headers
Keep-Alive
WPE-Backend
X-Pass-Why
Access-Control-Max-Age
X-Backend
X-AH-Environment
CF-Ray
X-Cache-Group
X-Drupal-Dynamic-Cache
X-Age
X-Server
X-Ua-Compatible
X-Via
X-Request-ID
X-Proxy-Cache
Grace
X-Pingback
X-Nginx-Cache-Status
X-Amz-Id-2
X-Amz-Request-Id
X-Server-Powered-By
X-Robots-Tag
X-Hacker
X-UA-Device
X-Varnish-Cache
EagleId
X-Page-Speed
Request-Context
X-LiteSpeed-Cache
Cf-Railgun
X-Envoy-Upstream-Service-Time
X-Swift-SaveTime
X-Swift-CacheTime
X-CST
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Server-Id
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-Amz-Version-Id
X-Ac
X-OneAgent-JS-Injection
X-Node
Server-Timing
Feature-Policy
X-Cnection
X-Iejgwucgyu
X-Response-Time
X-Rq
Allow
X-Cache-Lookup
Content-Location
Report-To
X-Backend-Server
EagleEye-TraceId
X-Readtime
Surrogate-Control
X-Host
X-Application-Context
Request-Id
X-Url
X-ORACLE-DMS-ECID
X-Rack-Cache
P3p
X-Origin-Cache
X-Clacks-Overhead
X-Country
NEL
Rating
X-FTR-Request-ID
X-Cloud-Trace-Context
X-Country-Code
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-DataDome
X-Instart-Request-ID
X-Px
X-MS-InvokeApp
X-Vhost
Charset
X-Ruxit-JS-Agent
X-VARITI-CCR
X-Mod-Pagespeed
Edge-Control
Accept-CH
X-Varnish-TTL
X-Goog-Hash
X-GitHub-Request-Id
X-DynaTrace
Verso
X-ESI
Arc-Version
PB-PID
PB-RID
X-Mobile-Rewrite
X-Version
X-Server-Name
X-PC
X-Vname
X-TtlSet
Pinterest-Generated-By
X-Cdn
X-D2id
X-Powered-By-Plesk
X-Kinja-Build
X-Cdn-Fetch
X-Use-Magma
X-Kinja-Revision
X-Kinja
X-Exp-Variant
X-Kinja-Server
X-GoogleNews-Bot
X-Exp-Id
X-Cached
X-TTL
X-Origin-Upstream-Status
SPRequestGuid
X-B3-TraceId
X-Dispatcher
X-Upstream-Env
X-Powered-CMS
X-Abt-Application-Version
X-ORACLE-DMS-RID
X-SharePointHealthScore
X-T
RTSS
Accept-CH-Lifetime
MS-Author-Via
X-Trace
X-Recruiting
Public-Key-Pins
X-Navigation-Version
X-Shield-Request-Id
Content-MD5
AR-PoweredBy
AR-CACHE
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Amz-Rid
SPIisLatency
SPRequestDuration
AR-ATIME
X-DIS-Request-ID
X-HW
X-Fastly-Request-ID
X-Client-IP
Realpath
Arr-Disable-Session-Affinity
X-Oracle-Dms-Rid
X-Accel-Buffering
X-Wix-Server-Artifact-Id
X-F-Cache
X-Forwarded-Proto
X-B
X-DynaTrace-JS-Agent
X-Upstream
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Generation
X-Ser
X-Goog-Stored-Content-Length
X-Amz-Meta-S3cmd-Attrs
X-Via-JSL
X-Pinterest-Rid
Service-Worker-Allowed
Pinterest-Version
X-Ttl
X-Id
X-Dw-Request-Base-Id
X-FTR-Realm
X-Vcap-Request-Id
X-FTR-Backend-Server
X-FTR-Cache-Status
X-Country-Code-Real
X-FTR-Backend
X-FTR-Balancer
X-FTR-DC
X-FTR-Expires
X-Varnish-Age
Front-End-Https
Paypal-Debug-Id
AR-Request-ID
X-Dns-Prefetch-Control
X-Server-ID
Nginx-Cache
X-Goog-Storage-Class
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Acc-Meta-Resource-Type
X-Aspnet-Version
X-Debug
X-MSEdge-Ref
X-Hits
X-Kinsta-Cache
X-XRDS-Location
X-NF-Request-ID
Ar-Sid
X-N
X-NewRelic-App-Data
X-Logged-In
X-FTR-Cache-Host
X-Mrf-Item-Lastmod
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Mrf-Section-Lastmod
S
X-Frontend
X-Akam-SW-Version
X-Grace
X-HS-Hub-Id
X-HS-Content-Id
X-Forwarded-For
X-PressLabs-Stats
AMP-Access-Control-Allow-Source-Origin
Alternate-Protocol
X-User-Agent
X-Cache-Key
Tracecode
DynaTrace
X-DataStream-Cache-Status
X-Pad
X-TA-CDN-Provider
X-Amzn-Trace-Id
X-CACHE-GROUP
X-FastCGI-Cache
Server-Name
X-Content-Digest
Refresh
X-Analytics
Backend-Timing
X-Content-Options
MicrosoftSharePointTeamServices
Fastcgi-Cache
Accept-Charset
X-CF-Powered-By
X-Middleton-Display
X-Activity-Id
Access-Control-Request-Method
X-Sol
Display
X-Debug-Info
X-Az
X-AppVersion
FilterID
X-Rid
X-Page-Id
Powered-By-ChinaCache
Host
X-LB-Cache
MS-CV
X-IPLB-Instance
X-Zen-Fury
X-Content-Type
X-Magnolia-Registration
ServerID
TP-L2-Cache
TP-Cache
TCN
Response
X-Middleton-Response
Cache-Status
X-ATG-Version
X-Mobile
X-Cache-Hit
X-Content-Powered-By
Surrogate-Key
X-Hostname
X-Srv
X-VCache
X-Fastcgi-Cache
X-Ruxit-Js-Agent
Rt-Fastcgi-Cache
X-Seen-By
X-WA-Info
X-B3-Sampled
X-RateLimit-Remaining
X-XRDS-LOCATION
X-Cached-By
X-Varnish-Backend
X-Revision
X-Request-Received
X-Request-Processing-Time
X-GUploader-UploadID
X-Cache-Age
X-Signature
X-Cluster
X-B-Cache
X-Cache-Action
X-SS-Set-Cookie
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Content-Security-Policy-Report-Only
X-Edge-Location
X-Platform-Server
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Tumblr-User
X-Instance
Cleartype
Source
X-Whom
X-PHP-Backend
X-Framework
X-Akamai-Edgescape
X-TT
X-Handled-By
X-Request-Guid
X-Drupal-Cache-Tags
X-App-Environment
X-Origin-Server
X-Wix-Request-Id
X-Cache-Control
ViewerVersion
X-NWS-LOG-UUID
Host-Header
Server-Info
X-BCube-Filmed-By
X-Cache-Rule
X-AOL-HN
X-Cache-2
X-Generated-By
DC
Retry-After
X-Varnish-Hostname
X-App-Server
Eomportal-Instance
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Geo-Country
X-Varnish-Server
Server-Node
X-FW-Serve
X-FW-Hash
X-FW-Type
X-FW-Server
X-FW-Static
X-Correlation-Id
Fusion-Source
Fusion-Content-Id
Fusion-Template-Id
Fusion-Content-Source
Fusion-Component-Id
X-FB-Debug
X-Device-Type
Webserver
X-Real-IP
Payment
Actual-Object-TTL
Access-Control-Allow-Method
Edge-Cache-Tag
X-Response-Served-From
X-Amz-Server-Side-Encryption
ServedBy
X-Tumblr-Pixel-2
AsisCache
X-TT-TIMESTAMP
X-Tumblr-Pixel-1
X-Varnish-Grace
Filters
Content-Style-Type
X-WebKit-CSP-Report-Only
Content-Script-Type
X-Varnish-Hits
X-Cacheable-TTL
GEO-INFO
Ms-Operation-Id
NGB
X-RTag
X-Region
X-Contextid
Healthy
X-Drupal-Cache-Contexts
X-Adobe-Loc
X-Jobs
X-TX-ID
X-Amz-Replication-Status
Viewport
X-UUID
X-Servedby
X-Adobe-Content
From-Origin
Country
Cache
X-Locale
X-Rendered-As
X-Accel-Expires
Upgrade-Insecure-Requests
X-Varnish-IP
Cache-Tv-Group
X-UA-Device-Type
X-RequestSource
X-WPE-Loopback-Upstream-Addr
X-Cache-Config
X-Cache-TTL-Remaining
X-Cache-Server
X-BACKEND-TTL
X-Cache-Operation
HitType
X-VG-WebCache
X-Ezoic-Cdn
Pagespeed
X-APP-VERSION
X-Cache-Remote
Fastly-Restarts
X-Cache-TTL
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Storage
X-Oneagent-Js-Injection
X-S
X-Upgrade-Enabled
Fastcgi-Useragent
X-Content-Age
X-Hit
Cache-Tags
X-Redis-Cache
X-Daa-Tunnel
X-Esi
X-FW-Dynamic
Served-By
X-Cache-NE
Datacenter
Cache-Tag
X-RateLimit-Limit
X-Internal-Host
X-Is-Bot
X-Rule
X-Status
X-RN-RSRV
X-Cache-Var-Map
X-JoinUs
X-Hl-Ver
X-Cache-Var
X-Generated
X-Backend-Name
Origin-Cache-Control
X-NGENIX-Cache
X-Detected-As
Origin-Edge-Control
X-Mode
X-Path-Route
X-NCache
SRV
Load-Balancing
Machine
Meta-Geo
Selected-FE
Now
X-CDN-Cache
X-Agile
X-Birta-Served
X-Akamai-Request-ID
X-Birta-Cache-Post
X-Agile-Id
X-Cache-Category-Id
Cache-Key
X-Agile-Age
Vix-Hermes-Req-Id
X-Grey
X-Edge-IP
X-TNCMS
X-Origin-Host
X-Loop
X-Labrador-Cache-Channel
X-Proxy
X-Proxy-Build
X-Tb
X-Time-Microsecs
X-Pubstack
X-Timing-Wait
X-L-Path
X-Origin-Response-Time
X-Hosted-By
X-Web-Node
X-Www-Served-By
X-FC-Vary-Parameters
X-Environment-Context
X-Source
X-Human
X-ProcessESI
Cache-Name
X-ProxyCache-Status
X-RemovedCookies
X-PERF
X-ProxyCache-Key
X-IP
X-BYPASS-REASON
X-ServerID
X-Origin
X-OCL
X-Viewer-Country
X-Original-Request
X-Via-Fastly
X-ApacheServer
X-Pc-Key
X-Varnish-Cacheable
X-Pc-Hit
X-PCL
X-Pc-Appver
X-Guploader-Uploadid
Public-Key-Pins-Report-Only
X-Format
X-Varnish-Cache-Hits
X-VG-TLSProxy
X-Site-Version
DB-Nickname
X-Akamai-Transformed
X-CCM
X-GeoIP
X-Debug-Cache
X-Access
X-MP-GENERATED-AT
X-Section
Mail-Subject
We-Hiring
X-App-Version
Azure-RegionName
X-Xfnlog-Site
S-Rt
Azure-SiteName
Azure-InstanceId
Azure-SlotName
Azure-Version
TWC-Device-Class
TWC-Connection-Speed
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Privacy
TWC-Locale-Group
Webcakes-App-Name
Webcakes-App-Version
X-Origin-Hint
Webcakes-Region
Property-Id
NtCoent-Length
Xserver
User-Cache-Control
X-Cache-Enabled
X-Ocache
X-UA
S-Cnection
Fastcgi-X-Cache-Version
X-Zipkin-Id
X-Routing-Service
X-Request-Time
X-App-Name
X-Sucuri-ID
X-Proxied
Liferay-Portal
Access-Control-Request-Headers
X-Protected-By
X-Microcachable
X-Nginx-Cache
X-Cdn-Forward
X-B3-Traceid
X-EdgeConnect-Cache-Status
X-Webstats-RespID
X-Tumblr-Pixel-3
X-CACHE-KEY
X-FW-Version
X-GEO
X-FB-TRIP-ID
X-DataStream-MidMile-RTT
X-Origin-CC
User-Agent
X-DataStream-Origin-MEX-Latency
X-GRACE
X-Upstream-HT
X-Upstream-Proxy
X-Upstream-CT
AR-SID
X-Proto
PageSpeed
X-Trace-Id
X-Yottaa-Optimizations
LB
X-Yottaa-Metrics
X-TIME
X-Node-Name
X-Correlation-ID
Powered
Ohc-File-Size
X-Forwarded-Host
X-Varnish-Beresp-Grace
Cache-Hits
X-Nc
X-Varnish-Beresp-Status
X-Edge-Cache-Key
X-Pc-Host
X-Pc-Date
X-Endurance-Cache-Level
X-Edge-Cache
X-Cache-Backend
X-ES-SERVER
X-ElasticPress-Search
X-OVcl
X-OVcl-Cache
X-Unique-ID
Frame-Options
X-Vgn-Hpd-Reason
Section-Io-Cache
X-Origin-TTL
X-Ua
X-Rocket-Nginx-Bypass
X-Server-Cache
L5d-Success-Class
X-Dynatrace-Js-Agent
X-Varnish-Beresp-Ttl
IBM-Web2-Location
Fastcgi-X-Cache
Nel
X-V
HostName
X-Parent-Response-Time
OT-Force-Account-Verify
X-Twitter-Response-Tags
Node
X-Generated-In
X-Distil-CS
X-External-Request-Id
X-Connection-Hash
X-DPWN-IS-SECURE
GMS-Ver
X-Died
X-Destination
Meta-Geo-Continent
X-Goog-Meta-Goog-Reserved-File-Mtime
Memcached
X-Cache-Info
MD5-Digest
X-NU-AKA-ACS-Version
X-Date
Mobile-Detection-Method
X-Developer
X-Cdn-Srv
X-User
X-Cache-URL
X-UE-Client-Country
X-Gen-Mode
Decoy-Debug-Key
Decoy-Debug-Status
X-Fetched-On
Country-Code
Cache-Prefix
Rendered-Blocks
Decoy-Debug-TTL
Ec-Rule-Version
Fastly-SWR
Fly-Cache
X-ScT
Fastly-SIE
X-SRCache-Key
BehaviorPad-Version
X-Transaction
X-CF-Lambda-Version
Powered-By
X-Trv-Group
Fly-Request-Id
X-CF-Lambda-Fn
Resin-Trace
X-S-Cookie
Arc-Country
X-Info
X-From
X-Server-By
X-Server-Group
X-TT-LOGID
X-Hnp-Log
X-Reboot
X-Cache-Bucket
Xc-Version
X-Rebelmouse-Surrogate-Control
X-Region-Sid
X-ServiceProvider
X-We-Are-Hiring
X-Cache-Host
X-ARC
Www
X-IN-WAF
X-Request-UUID
X-B-Cookie
X-Application
X-Irp-Debug
X-Auto-Login
X-Amz-Meta-Cache-Control
X-PAYTM-SRV-ID
X-Accel-Expires-Debug
CACHE
X-Aed
X-Origin-Expires
X-Rebelmouse-Cache-Control
X-PHP-Host
X-Micro-Cache
X-Rewrite-Enabled
X-IN-APIGATEWAY
X-Block-Status
X-Origin-Date
X-BB-ID
X-Cache-Id
X-Pc-Subdomain
VivaBuild
X-Rojux
X-VG-WebServer
Viewtype
X-IN-SSL-APIGATEWAY
Mn-Server-Ip
X-Via-CDN
X-Dc
X-D
X-Backend-Host
X-Cache-Debug
X-Cache-Expires
X-Crawler
X-Secret
X-Backend-Url
On-Server
Platform
X-Bip
X-CUA
X-Stale
X-A-Wwc
SD-X-WS
X-Sf
X-Shopify-Stage
Web-Mar-Node
X-A
X-ShardId
Server-Host
Thinkindot-CacheControl-Type
X-ShopId
Thinkindot-Control
True-Client-Country-4JS
X-Server-IP
X-A-Ccd
X-A-Dam
X-Cache-Grace
X-Sorting-Hat-ShopId
X-Server-Time
X-Alternate-Cache-Key
X-Cache-FS-Status
X-Actual-URL
Thinkindot-CacheControl
Request-Time
X-Sorting-Hat-PodId
X-A-Dcw
X-A-Dgt
Proxy-Connection
Backend
X-LI-UUID
X-Response-By
X-Returned-From
X-Location
X-Wikidot-Backend
X-Via-NSCOPI
X-Wikidot-Static-Cache
X-Node-Id
X-Level-Front-Cache
X-Varnish-Action
Magicmarker
X-Var-Ttl
X-Li-Pop
X-Li-Fabric
X-Time
X-LI-Proto
X-Passed-To
X-RateLimit-Remaining-Second
X-Policy
X-Passed-To-PostProcessResponse
X-Passed-To-DLL
X-Platform
X-Request-URI
X-Returned-From-PostProcessResponse
X-Returned-From-DLL
X-Croise-Owner
X-Proxy-Cache-Status
X-RateLimit-Limit-Second
X-Passed-To-BeforeDispatch
X-Logtrace-Id
X-Matched-Rule
X-LAGOON
X-Proxy-Upstream
X-Hash
X-Variation
X-Swa-Ws
X-Fastly-Cache
X-Thanos
X-Thinkindot-L3
X-Returned-From-BeforeDispatch
Fastly-Backend-Name
X-Epic-Correlation-Id
X-Distributor
X-Debug-Cookies
Lfy
Is-Eu
X-Debug-Log
X-Dispatcher-Server
Content-Disposition
X-S-Maxage
Ajk
Adler-Geo
Warning
X-Gannett-Site-Version
X-G
X-NX-Host
X-GeoIP-Country-Code
X-Generated-On
X-Sucuri-Cache
X-HS-Cache-Config
X-R9-Blue-Green-Version
X-Debug-Cache-Expiry
X-Debug-Cache-Store
X-No-Session
X-Instart-Isnd
X-Key
X-Debug-Cache-Fetch
X-Fstrz
X-Generation-Time
X-Eu-Site
X-FireWall-Port
X-CGP
X-Device-Os
X-Clientip
X-Qloud-Router
X-Varnish-Authentication
Fastly-Soc-X-Request-Id
Countrycode
CDCHOST
AKAMAI
GW-Server
Ha-Gx-Prefs
X-Svr
Heartbleed
HA-Ipaddr
X-UnsetCookies
X-Up
Origin
X-SIPLIST1
X-Core-Mission
X-Nginx-Cache-Key
IsBot
X-SERVER
X-VWS-Id
X-Cache-ASPX
X-AWS-Id
Kp-EeAlive
X-LJ-Flow-ID
X-Amz-Meta-Surrogate-Control
X-Backend-State
Who
Version
Pramga
Release
RNT-Machine
Server-Cache-Control
RNT-Time
Pagetype
Server-Surrogate-Control
SS
X-C
Apple-News-Services-Request-Url
REQUESTUUID
Apple-News-Services-Parsed-Url
Server-Int
Apple-News-Services-Handled
Apple-News-Services-Host
X-MSEdge-Flight
X-F5-Cache
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-From
X-Core-Value
X-Developers
PFcat
X-Page-Type
Fastly-SSL
X-Servername
X-MSEdge-Features
X-Cluster-Node
Server-ID
NGX
X-Pjax-Url
X-Varnish-Url
X-Ratelimit-Remaining
RequestId
X-Refresh
X-Store
X-Sedo-Request-Id
X-TrackingId
Esi-Enabled
X-Cache-Miss-From
X-Be
X-CDN-Forward
Time
MI-API
X-Cache-CFC
X-EIG-Tracking-Id
X-Newrelic-App-Data
MI-Cache
X-Layer
MI-Cache-Age
X-RCS-CacheZone
X-MI-In-Market
MIME-Version
X-NC
X-Real-Ip
X-B3-SpanId
X-URL
HA-Urlpath
HA-Georegion
X-IPS-LoggedIn
X-Oss-Storage-Class
HA-Geolon
X-Oss-Server-Time
X-Oss-Object-Type
HA-Geolat
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
HA-Servedtime
HA-Host
HA-Geocity
X-Mshield-Cache-Status
X-Unique-Id-Primal
X-Mrs-Cache-Hits
X-Mrs-Cache
X-Mrs-Age
X-SN
HA-Cloudapp
HA-Geocountry
SID
Cteonnt-Length
X-From-Cache
X-Owner
X-Ratelimit-Limit
X-Geo
PICS-Label
X-Hyper-Cache
X-Servedbyhost
Odigeo-Trace-Id
X-RequestId
Mime-Version
Cdn
Backend-Name
X-CMS-Context
X-Litespeed-Cache
FastCGI-Cache
Memory
X-FPC
CF-IPCountry
X-Req
X-Webkit-Csp
X-Webkit-CSP
X-WebServer
X-Instart-Info
HTTPS
Processtime
X-B3-Spanid
X-CLOUD-TRACE-CONTEXT
CDN
X-CSRF-TOKEN
X-Edge-Server
X-Request-Start
Cdn-Host
Cdn-Request-Time
X-Phone
Hostname
X-Pf-Uncompressing
X-Release
X-Wa
Cf-Ipcountry
X-Aicache-OS
Ohc-Response-Time
XServer
X-WR-MODIFICATION
X-DC
GeoIP-Country-Code
X-Newrelic-Synthetics
X-Varnish-Beresp-TTL
X-Load-Cache
X-Amzn-Remapped-Connection
X-HS-Combine-CSS
GeoIP-Latitude
X-Mobile-URL
X-Amzn-Remapped-Date
X-Server-W
ProcessTime
X-ND-Cache
Cross-Origin-Window-Policy
X-VServer
X-Served-From
X-WA
URI
X-NodeID
X-GZip
Rt-Proxy-Cache
X-Atg-Version
X-Fastly-Country-Code
X-HTML-Minification-Powered-By
X-Lb-Id
X-Varnish-Ttl
X-FORWARDED-FOR
Accept-Ch-Lifetime
X-Unique-Id
X-Skip-Cache
X-GoCache-CacheStatus
T-Server
X-Nananana
X-PF-Uncompressing
X-Sn-Servicetimems
X-CSRF-Token
X-Cdn-Origin
X-Oracle-Dms-Ecid
V-Age
X-Tb-Optimization-Total-Bytes-Saved
Proxy-Firewall
X-SVT-ORM-RULES
X-COUNTRY
X-VC-Cache
X-LB-ID
X-MServer
X-SVT-ORM-VERSION
X-ServedByHost
Ohc-Cache-HIT
X-P-T
Pics-Label
X-Datadome
X-APP
X-Cms-Context
X-UPSTREAM-Address
X-SRV
Is-Session-Tracking
X-Worker
Get-Access-Time
X-Fastly-Cache-Hits
Uber-Trace-Id
N-Cache
X-UCC
A
X-LiteSpeed-Cache-Control
X-Check-Cacheable
ServerName
X-HS-Status
X-SERVER-NAME
Amp-Access-Control-Allow-Source-Origin
X-Gateway-Skip-Cache
X-CACHE-AGE
DataCenter
X-Gateway-Cache-Status
X-RCS-Backend
X-Requestid
X-Gateway-Cache-Key
X-GZIP
X-Processor
Geoip-Latitude
X-NGINX-Cache
X-BBXSRF
X-Hp-Webp
Dnion-Transfer-Encoding
X-Cache-HT
X-Varnish-URL
X-BE
X-Optimization
X-ID
X-Org
WZWS-RAY
X-StackifyID
GeoIp-Country-Code
X-Backend-TTL
X-Vg-Webcache
X-Port
X-Fe
X-GDPR
X-Via-Edge
WP-Super-Cache
X-Csrf-Token
X-PJAX-URL
X-Via-SSL
Server-Id
Cneonction
X-PAGE-TYPE
Cache-Provider
Requestid
Serverid
X-NWS-UUID-VERIFY
X-Planisys-CDN-Cache
Pragrma
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Git-Hash
X-HostName
X-LiteSpeed-Tag
X-ServerName
RequestUuid
X-Gdpr
X-Dw-Trace-Id
X-Instance-Name
X-Front
Xxline
X-PARISIEN-Cache-Rendered
219prxHost
189phosttRef
225prxHost
286prxHost
X-VCT
409pxxline
X-RAMCache
352pxline
188prxHost
X-Akamai-Request-ID2
355prline
X-VarnPar1
Accept-Language
X-CS
Correlation-Id
X-Request-Url
178proxuri
Request-EU
Request-Country
DSUID
X-VarnCache