Threat Level: green Handler on Duty: Rob VandenBrink

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Accept-Ranges
Pragma
X-Powered-By
CF-RAY
Link
ETag
Expect-CT
Via
X-Cache
X-XSS-Protection
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-Xss-Protection
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Id
X-Served-By
P3P
Referrer-Policy
X-Varnish
X-Request-Id
X-Timer
CF-Cache-Status
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Amz-Cf-Pop
X-AspNet-Version
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
P3p
X-Drupal-Cache
X-Check
X-Adblock-Key
X-Cacheable
Alt-Svc
Content-Security-Policy-Report-Only
X-Generator
X-Cache-Status
X-DNS-Prefetch-Control
X-AspNetMvc-Version
Status
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-Permitted-Cross-Domain-Policies
Content-Encoding
X-Buckets
X-Content-Security-Policy
X-Turbo-Charged-By
X-Kinja-Server-Push
X-CDN
Upgrade
Xkey
X-Type
Keep-Alive
Access-Control-Expose-Headers
Access-Control-Max-Age
WPE-Backend
X-Pass-Why
X-Request-ID
X-AH-Environment
X-Backend
X-Cache-Group
X-Server
CF-Ray
X-Drupal-Dynamic-Cache
X-Age
X-Ua-Compatible
X-Via
X-Pingback
Grace
X-Nginx-Cache-Status
X-Server-Powered-By
EagleId
X-Amz-Request-Id
X-Amz-Id-2
X-Hacker
X-UA-Device
X-Robots-Tag
X-Varnish-Cache
X-LiteSpeed-Cache
X-Page-Speed
X-Proxy-Cache
Request-Context
Cf-Railgun
X-Swift-SaveTime
X-Swift-CacheTime
X-Envoy-Upstream-Service-Time
Ali-Swift-Global-Savetime
X-WebKit-CSP
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Ac
X-Device
X-Cache-Lookup
X-CST
X-Amz-Version-Id
X-Cnection
X-Node
X-OneAgent-JS-Injection
X-Server-Id
X-Readtime
Content-Location
Surrogate-Control
EagleEye-TraceId
Report-To
X-Host
X-Response-Time
X-Rq
Feature-Policy
Server-Timing
X-Iejgwucgyu
X-Backend-Server
X-Application-Context
X-ORACLE-DMS-ECID
X-Rack-Cache
Allow
X-Url
Request-Id
X-Instart-Request-ID
X-Cloud-Trace-Context
X-Clacks-Overhead
NEL
Rating
X-Country
X-DynaTrace
X-Origin-Cache
Edge-Control
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-FTR-Request-ID
X-Varnish-TTL
X-Server-ID
X-Country-Code
X-Px
X-B3-TraceId
X-ORACLE-DMS-RID
X-Cdn
X-DataDome
X-Ruxit-JS-Agent
X-GitHub-Request-Id
X-Vhost
X-ESI
X-VARITI-CCR
X-Goog-Hash
Accept-CH
X-Trace
Charset
X-Server-Name
X-Cached
Pinterest-Generated-By
RTSS
X-TTL
X-Mod-Pagespeed
X-MS-InvokeApp
Verso
PB-RID
X-Mobile-Rewrite
PB-PID
Arc-Version
X-D2id
X-Kinja-Build
X-Kinja
X-Kinja-Server
X-Use-Magma
X-GoogleNews-Bot
X-Exp-Variant
X-Cdn-Fetch
X-Exp-Id
Public-Key-Pins
X-Kinja-Revision
X-Version
X-F-Cache
SPRequestGuid
X-Vname
X-PC
X-TtlSet
X-Dispatcher
X-Powered-By-Plesk
X-DynaTrace-JS-Agent
Accept-CH-Lifetime
X-DIS-Request-ID
X-Abt-Application-Version
X-T
X-Powered-CMS
X-SharePointHealthScore
X-Origin-Upstream-Status
X-Fastly-Request-ID
X-Ser
X-Navigation-Version
X-Pinterest-Rid
X-SRCache-Store-Status
Pinterest-Version
X-SRCache-Fetch-Status
X-Upstream-Env
X-B
X-Client-IP
Realpath
X-Amz-Rid
X-Recruiting
X-Shield-Request-Id
MS-Author-Via
X-Forwarded-Proto
X-HW
X-Upstream
X-Vcap-Request-Id
X-Accel-Buffering
X-Wix-Server-Artifact-Id
SPIisLatency
SPRequestDuration
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-XRDS-Location
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
DynaTrace
Arr-Disable-Session-Affinity
X-Amz-Meta-S3cmd-Attrs
Nginx-Cache
AR-ATIME
AR-PoweredBy
AR-CACHE
X-Varnish-Age
Content-MD5
X-Debug
X-Via-JSL
X-Dw-Request-Base-Id
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Mrf-Section-Lastmod
MRF-Tech
X-Mrf-Item-Lastmod
X-Goog-Storage-Class
X-Ttl
X-Id
X-Hits
X-MSEdge-Ref
X-Acc-Meta-Resource-Type
X-NewRelic-App-Data
X-Aspnet-Version
X-FTR-DC
X-FTR-Realm
X-FTR-Cache-Status
X-FTR-Backend-Server
X-FTR-Backend
X-Country-Code-Real
X-FTR-Balancer
X-NF-Request-ID
Service-Worker-Allowed
X-N
X-FTR-Expires
S
Access-Control-Request-Method
X-ATG-Version
X-Logged-In
AMP-Access-Control-Allow-Source-Origin
X-Kinsta-Cache
X-Oracle-Dms-Rid
Alternate-Protocol
X-PressLabs-Stats
X-HS-Hub-Id
Edge-Cache-Tag
X-HS-Content-Id
X-Frontend
TCN
X-FastCGI-Cache
X-Forwarded-For
Surrogate-Key
X-RateLimit-Remaining
X-FTR-Cache-Host
Rt-Fastcgi-Cache
X-Content-Digest
Fastcgi-Cache
X-Pad
Tracecode
X-CF-Powered-By
Ar-Sid
X-TA-CDN-Provider
Server-Name
X-User-Agent
X-Cache-Key
Backend-Timing
X-Amzn-Trace-Id
X-Analytics
TP-L2-Cache
Host
TP-Cache
MicrosoftSharePointTeamServices
X-Oneagent-Js-Injection
X-Magnolia-Registration
FilterID
X-Rid
X-Debug-Info
X-Cache-2
X-Edge-Location
ServerID
Fastly-Restarts
X-B3-Sampled
X-Mobile
Paypal-Debug-Id
X-Whom
X-Page-Id
Front-End-Https
AR-Request-ID
X-Revision
X-IPLB-Instance
X-Content-Options
Eomportal-Instance
X-Srv
X-Grace
X-Hostname
X-Akam-SW-Version
Refresh
X-LB-Cache
X-NWS-LOG-UUID
X-AppVersion
X-Az
X-Activity-Id
X-Content-Powered-By
X-GUploader-UploadID
X-VCache
Retry-After
X-B-Cache
X-Signature
X-Framework
X-SS-Set-Cookie
X-Cache-Action
Cleartype
X-Cluster
Source
X-Cache-Control
X-Varnish-Hostname
X-Request-Received
X-Handled-By
X-Request-Processing-Time
X-Tumblr-Pixel
X-Request-Guid
X-Tumblr-User
X-Tumblr-Pixel-0
X-Platform-Server
X-BCube-Filmed-By
X-App-Environment
X-WA-Info
X-Akamai-Edgescape
X-Instance
X-Content-Type
X-Litespeed-Cache
X-Zen-Fury
X-Device-Type
X-Content-Security-Policy-Report-Only
X-FB-Debug
Accept-Charset
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Correlation-Id
X-AOL-HN
Webserver
X-Sol
X-Cache-Hit
Display
X-Middleton-Display
X-Varnish-Backend
X-Ruxit-Js-Agent
X-Varnish-Grace
X-Cache-Rule
X-Fastcgi-Cache
X-Seen-By
X-Wix-Request-Id
ViewerVersion
X-TT
Healthy
Cache-Status
MS-CV
X-Origin-Server
X-Cache-Age
X-Cache-Server
X-Drupal-Cache-Tags
X-DataStream-Cache-Status
Response
X-Middleton-Response
Upgrade-Insecure-Requests
X-Cached-By
X-PHP-Backend
X-Daa-Tunnel
X-Storage
Payment
X-Varnish-Server
X-WPE-Loopback-Upstream-Addr
X-Amzn-RequestId
X-Geo-Country
X-Amz-Apigw-Id
X-Generated-By
X-Drupal-Cache-Contexts
X-Amz-Replication-Status
X-App-Server
X-UA-Device-Type
X-Response-Served-From
NGB
Filters
X-CACHE-GROUP
X-Adobe-Loc
GEO-INFO
X-Adobe-Content
Server-Node
Actual-Object-TTL
Access-Control-Allow-Method
Viewport
X-FW-Type
X-RequestSource
X-FW-Serve
X-Cache-NE
X-FW-Server
X-Cacheable-TTL
X-Edge-Cache-Key
X-Locale
ServedBy
X-Varnish-IP
X-Jobs
X-UUID
X-FW-Static
X-S
X-Servedby
X-FW-Hash
X-TT-TIMESTAMP
X-Contextid
X-Edge-Cache
X-Esi
X-Amz-Server-Side-Encryption
X-Varnish-Hits
X-Tumblr-Pixel-1
X-Accel-Expires
X-Tumblr-Pixel-2
X-TX-ID
Server-Info
X-Cache-Remote
Cache-Tv-Group
AsisCache
X-Cache-TTL-Remaining
X-WebKit-CSP-Report-Only
Cache
X-App-Version
X-Status
From-Origin
X-CACHE-KEY
Host-Header
X-HS-Cache-Config
S-Cnection
X-Rendered-As
X-Dns-Prefetch-Control
X-Cache-Operation
X-GeoIP
X-URL
X-Region
X-XRDS-LOCATION
SRV
X-GRACE
X-Croise-Owner
Content-Style-Type
DC
HostName
Content-Script-Type
X-BACKEND-TTL
X-Webkit-CSP
X-Redis-Cache
Served-By
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Ms-Operation-Id
X-RTag
Powered-By-ChinaCache
X-APP-VERSION
X-Upgrade-Enabled
Cache-Tag
Liferay-Portal
X-Cache-Config
Public-Key-Pins-Report-Only
X-Node-Name
Pagespeed
Xserver
X-Hyper-Cache
X-Site-Version
X-Proxy-Build
X-Detected-As
X-Cache-Var-Map
X-Cache-Var
X-Generated
X-Grey
X-NGENIX-Cache
X-Is-Bot
X-Cache-Category-Id
Selected-FE
Machine
Load-Balancing
X-Edge-IP
Meta-Geo
Origin-Cache-Control
X-Path-Route
Origin-Edge-Control
X-Protected-By
X-RN-RSRV
X-Timing-Wait
X-Parent-Response-Time
X-Webstats-RespID
X-Web-Node
X-Agile-Age
X-Akamai-Request-ID
X-BYPASS-REASON
X-Via-Fastly
X-Agile
X-Agile-Id
X-ProxyCache-Status
Cache-Name
Now
X-Mode
X-NCache
X-Original-Request
X-CDN-Cache
X-ProxyCache-Key
X-Origin-Response-Time
X-Request-Time
X-Upstream-CT
X-Human
X-Hosted-By
X-JoinUs
X-TNCMS
X-Loop
X-Labrador-Cache-Channel
X-Upstream-HT
X-Internal-Host
X-Akamai-Transformed
Azure-SiteName
User-Cache-Control
Azure-SlotName
Azure-Version
X-Origin-CC
Cache-Key
X-Rule
X-Time-Microsecs
X-ProcessESI
X-PCL
X-Tumblr-Pixel-3
Azure-RegionName
X-L-Path
X-Pc-Key
X-Birta-Served
X-OCL
X-Pc-Appver
X-Pc-Hit
X-Origin
X-ServerID
X-Origin-Host
X-Format
X-Birta-Cache-Post
X-Proxy
X-RemovedCookies
X-Environment-Context
Azure-InstanceId
DB-Nickname
X-FC-Vary-Parameters
X-CCM
X-Tb
TWC-Connection-Speed
Webcakes-App-Version
Webcakes-App-Name
Webcakes-Region
X-Access
X-Backend-Name
TWC-Privacy
TWC-Locale-Group
X-Origin-Hint
TWC-Device-Class
TWC-GeoIP-Country
TWC-GeoIP-LatLong
Property-Id
Fastcgi-X-Cache
Cache-Tags
X-Ocache
X-Www-Served-By
X-Xfnlog-Site
X-Pubstack
X-Section
X-VG-TLSProxy
Fastcgi-Useragent
X-Viewer-Country
Fastcgi-X-Cache-Version
Vix-Hermes-Req-Id
HitType
Country
X-App-Name
X-Cdn-Forward
X-Forwarded-Host
S-Rt
X-RateLimit-Limit
X-Guploader-Uploadid
X-Zipkin-Id
X-IP
X-Routing-Service
X-Proxied
X-B3-Spanid
X-Vgn-Hpd-Reason
X-ApacheServer
X-Vg-Webcache
X-PERF
X-Nginx-Cache
X-FB-TRIP-ID
X-Cache-TTL
X-Mrs-Cache-Hits
X-Content-Age
X-Mrs-Age
X-Mrs-Cache
X-Mshield-Cache-Status
X-Unique-Id-Primal
Mn-Server-Ip
Fusion-Source
Fusion-Template-Id
Datacenter
X-Cache-Backend
X-Via-CDN
Fusion-Component-Id
Fusion-Content-Source
Fusion-Content-Id
X-Endurance-Cache-Level
X-Ua
OT-Force-Account-Verify
X-TIME
X-Varnish-Cacheable
X-Real-IP
X-Sucuri-ID
X-Ezoic-Cdn
Time
X-Debug-Cache
Ohc-File-Size
X-Sorting-Hat-PodId
X-Yottaa-Metrics
X-Shopify-Stage
X-Sorting-Hat-ShopId
X-Varnish-Beresp-Ttl
X-Alternate-Cache-Key
X-Yottaa-Optimizations
X-ShardId
X-ShopId
X-Pc-Host
X-Pc-Date
X-OVcl
X-Hl-Ver
X-OVcl-Cache
X-Varnish-Beresp-Status
X-UA
NtCoent-Length
LB
X-Varnish-Beresp-Grace
X-Real-Ip
X-Nc
Mail-Subject
We-Hiring
X-Time
X-MP-GENERATED-AT
X-Correlation-ID
X-Unique-ID
L5d-Success-Class
X-Cache-Enabled
X-Hit
Section-Io-Cache
X-Trace-Id
Access-Control-Request-Headers
AR-SID
User-Agent
X-Proto
X-Microcachable
X-EdgeConnect-Cache-Status
Version
X-C
X-Amz-Meta-Surrogate-Control
X-Newrelic-App-Data
X-Rocket-Nginx-Bypass
X-Ratelimit-Limit
X-Dynatrace-Js-Agent
X-Server-Cache
Pagetype
X-CDN-Forward
Warning
X-Cache-URL
X-Cache-Expires
X-Cache-Bucket
X-Bip
X-Qloud-Router
X-Cache-Debug
X-Returned-From-BeforeDispatch
X-Cache-Host
X-Cache-FS-Status
X-Cache-Id
Fly-Request-Id
X-Date
X-Rojux
X-D
X-CUA
X-Crawler
X-S-Cookie
X-Destination
X-Device-Os
X-Developer
Cache-Prefix
X-S-Maxage
X-Connection-Hash
Ec-Rule-Version
X-BB-ID
Frame-Options
X-Rewrite-Enabled
X-Returned-From-PostProcessResponse
Fly-Cache
Fastly-SWR
Fastly-Backend-Name
Fastly-SIE
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-Returned-From-DLL
Magicmarker
X-A
Resin-Trace
RNT-Machine
RNT-Time
X-A-Ccd
Request-Time
Release
Rendered-Blocks
X-A-Dcw
X-A-Dam
Rt-Proxy-Cache
Www
Thinkindot-Control
Viewtype
V-Age
X-Reboot
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
Server-Host
Server-ID
X-Region-Sid
VivaBuild
X-A-Dgt
X-A-Wwc
Memcached
X-ARC
Meta-Geo-Continent
X-Application
MD5-Digest
X-Died
IBM-Web2-Location
Is-Eu
X-B-Cookie
X-Auto-Login
X-Amz-Meta-Cache-Control
X-RCS-CacheZone
Platform
Powered-By
X-Accel-Expires-Debug
X-Rebelmouse-Cache-Control
X-Request-UUID
PFcat
Mobile-Detection-Method
Node
X-Aed
X-Actual-URL
X-Returned-From
X-Served-From
X-Level-Front-Cache
Xc-Version
X-PAYTM-SRV-ID
X-Li-Fabric
X-Li-Pop
X-Twitter-Response-Tags
X-LI-Proto
X-HS-Combine-CSS
X-WebServer
X-Thanos
X-Swa-Ws
X-Thinkindot-L3
X-Transaction
X-TT-LOGID
BehaviorPad-Version
X-LI-UUID
X-Passed-To-PostProcessResponse
X-UE-Client-Country
X-User
X-Var-Ttl
X-Passed-To
X-NU-AKA-ACS-Version
X-Front
X-Akamai-Request-ID2
X-Passed-To-BeforeDispatch
X-Variation
X-Logtrace-Id
X-CLOUD-TRACE-CONTEXT
X-Matched-Rule
X-Passed-To-DLL
X-Varnish-Action
X-VG-WebServer
X-We-Are-Hiring
X-Trv-Group
X-From
X-Server-By
X-DPWN-IS-SECURE
X-Generated-In
Ohc-Response-Time
Adler-Geo
X-Server-IP
X-External-Request-Id
X-FW-Version
X-G
X-Server-Time
X-Generated-On
X-SRCache-Key
X-Svr
X-Rebelmouse-Surrogate-Control
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Dispatcher-Server
Ajk
X-Fetched-On
X-PHP-Host
Arc-Country
X-ScT
X-Store
X-MSEdge-Flight
Who
X-Distributor
X-Origin-Date
X-Distil-CS
X-Origin-Expires
X-Node-Id
Web-Mar-Node
X-Nginx-Cache-Key
X-No-Session
X-Proxy-Cache-Status
X-MSEdge-Features
X-Epic-Correlation-Id
X-Fstrz
X-GeoIP-Country-Code
X-Hnp-Log
X-Gen-Mode
X-IN-APIGATEWAY
X-Backend-Host
X-Backend-Url
X-Hash
X-Block-Status
X-Phone
X-IN-SSL-APIGATEWAY
X-IN-WAF
X-Cache-CFC
X-Clientip
X-Location
X-Proxy-Upstream
X-Layer
X-Irp-Debug
X-Info
X-Gannett-Site-Version
X-Instart-Info
X-MI-In-Market
X-Response-By
Country-Code
Content-Disposition
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-Idcheck
Countrycode
Decoy-Debug-Key
GMS-Ver
Esi-Enabled
Decoy-Debug-TTL
Decoy-Debug-Status
Backend-Name
AKAMAI
X-Wikidot-Backend
X-Wikidot-Static-Cache
Lfy
X-UnsetCookies
X-Stale
X-Sf
X-Secret
X-Server-Group
X-ElasticPress-Search
X-ServiceProvider
GW-Server
Cache-Cookie-Set-From
Server-Int
Heartbleed
MI-Cache-Age
SD-X-WS
MI-Cache
X-Release
Kp-EeAlive
MI-API
Proxy-Connection
X-Request-Start
True-Client-Country-4JS
Origin
X-Be
X-F5-Cache
Apple-News-Services-Request-Url
Backend
Apple-News-Services-Handled
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-Eu-Site
X-Policy
X-SIPLIST1
X-Via-NSCOPI
X-V
Accept-Language
X-Up
X-Page-Type
X-Origin-TTL
X-DC
X-Micro-Cache
Pramga
REQUESTUUID
SS
X-Cdn-Srv
X-Fastly-Cache
HA-Urlpath
X-Platform
HA-Georegion
Fastly-Soc-X-Request-Id
X-CGP
HA-Geocity
Ha-Gx-Prefs
Fastly-SSL
HA-Geolon
X-Backend-State
HA-Cloudapp
X-Cache-Info
HA-Geocountry
HA-Geolat
HA-Host
IsBot
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Developers
CDCHOST
X-Debug-Cache-Expiry
On-Server
HA-Ipaddr
X-Request-URI
X-Core-Mission
X-Core-Value
HA-Servedtime
X-NODE
X-CMS-Context
X-Debug-Log
X-P-T
X-Key
X-SVT-ORM-VERSION
X-Sn-Servicetimems
X-NX-Host
X-SVT-ORM-RULES
X-Servername
X-Geo
X-Debug-Cookies
X-Cdn-Origin
ServerName
X-Refresh
RequestId
Cteonnt-Length
X-COUNTRY
X-Pjax-Url
X-Dc
WZWS-RAY
X-LAGOON
Cdn
PageSpeed
X-Org
X-CACHE-AGE
X-NC
MIME-Version
X-Servedbyhost
NGX
X-Via-Edge
X-Via-SSL
X-Newrelic-Synthetics
X-Datadome
Memory
X-Req
Mime-Version
X-VarnCache
X-PARISIEN-Cache-Rendered
X-CSRF-TOKEN
Pragrma
X-VarnPar1
Locale
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-RateLimit-Limit-Second
Request-Country
X-RateLimit-Remaining-Second
X-Planisys-CDN-Cache
UCS
Uber-Trace-Id
X-Generation-Time
X-Wa
Request-EU
X-Urbn-Site-Id
X-Urbn-Context-Path
X-Instance-Name
X-Varnish-Cache-Hits
Host-ID
X-HTML-Minification-Powered-By
X-FireWall-Port
V-Cache
X-NWS-UUID-VERIFY
Group
Cache-Provider
X-Gdpr
GeoIP-Latitude
X-GeoIP-City
PICS-Label
X-VCT
GeoIP-Country-Code
X-Webkit-Csp
Nel
X-DataStream-MidMile-RTT
X-VG-WebCache
X-DataStream-Origin-MEX-Latency
X-WR-MODIFICATION
X-Cache-Grace
Server-Surrogate-Control
X-Cache-Miss-From
X-Varnish-Authentication
Server-Cache-Control
X-Cache-ASPX
X-Sedo-Request-Id
CF-IPCountry
Cf-Ipcountry
X-IPS-LoggedIn
X-BBXSRF
X-Ratelimit-Remaining
X-B3-Traceid
X-Source
X-Aicache-OS
X-Varnish-Url
CDN
X-Sucuri-Cache
X-StackifyID
XServer
X-ND-Cache
X-Powered-By-ANYU
HitInfo
X-Instart-Isnd
X-UPSTREAM-Address
X-Load-Cache
X-EIG-Tracking-Id
X-Fastly-Country-Code
Geoip-Latitude
Pics-Label
GeoIp-Country-Code
X-GEO
X-FW-Dynamic
X-Check-Cacheable
URI
X-APP
Powered
X-FORWARDED-FOR
X-HOST
X-RCS-Backend
X-From-Cache
X-R9-Blue-Green-Version
CACHE
X-Pc-Subdomain
X-CDN-Pop-IP
Is-Session-Tracking
Proxy-Firewall
Get-Access-Time
X-WA
X-CDN-Pop
X-Fastly-Backend-Reqs
X-Fastly-Cache-Hits
X-Unique-Id
X-TWH-CORRELATION-ID
X-GoCache-CacheStatus
X-RequestId
X-Varnish-Beresp-TTL
X-PF-Uncompressing
X-Nananana
X-Dynatrace
X-SRV
FSS-Cache
X-Server-W
X-VC-Cache
FSS-Proxy
X-B3-SpanId
X-Cluster-Node
X-Skip-Cache
X-ID
DataCenter
X-Sentry-ID
X-NodeID
X-ServedByHost
X-TrackingId
X-HS-Status
Amp-Access-Control-Allow-Source-Origin
X-CSRF-Token
X-Flog
Processtime
SN
X-VServer
X-ABtesting
X-Hello
ProcessTime
X-GDPR
WP-Super-Cache
Cache-Hits
X-BE
Hostname
X-Oss-Object-Type
X-Fe
X-Oss-Request-Id
Dynatrace
X-LiteSpeed-Cache-Control
X-Oss-Hash-Crc64ecma
X-Oss-Storage-Class
X-PJAX-URL
X-Oss-Server-Time
X-ES-SERVER
X-Csrf-Token
X-GZIP
X-GZip
X-Bug-Bounty
X-Amzn-Remapped-Date
X-Backend-TTL
X-Pf-Uncompressing
X-Gen-Id
X-Amzn-Remapped-Connection
X-Owner
X-NGINX-Cache
TSSecure
X-Cache-Ttl
Requestid
X-Worker
X-ORIG-AKA-EDGE
SID
X-SN
X-AWS-Id
X-LJ-Flow-ID
X-VWS-Id
Serverid
X-LiteSpeed-Tag
X-ServerName
X-Tb-Optimization-Total-Bytes-Saved
Cdn-Host
RequestUuid
T-Server
X-Alicdn-Da-Ups-Status
X-Swift-Error
X-VC
X-HostName
X-SB
Odigeo-Trace-Id
X-LB-ID
X-Varnish-URL
X-PAGE-TYPE
X-Edge-Server
X-MServer
Cdn-Request-Time
X-ORIG-AKA-COUNTRY-CODE
286prxHost
225prxHost
352pxline
355prline
409pxxline
219prxHost
Xxline
X-Dw-Trace-Id
X-Developed-By
X-RAMCache
A
X-CS
X-VarnPar2
Location
X-Serial
Xet-Cookie
178proxuri
188prxHost
DSUID
Cneonction
Correlation-Id
189phosttRef