Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Accept-Ranges
Pragma
X-Powered-By
Link
ETag
CF-RAY
Expect-CT
Via
X-Cache
X-XSS-Protection
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-UA-Compatible
X-Cache-Hits
X-Xss-Protection
X-Amz-Cf-Id
X-Served-By
P3P
Referrer-Policy
X-Varnish
X-Request-Id
X-Timer
CF-Cache-Status
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
P3p
CF-Ray
X-Drupal-Cache
X-Amz-Cf-Pop
X-Check
X-Adblock-Key
Alt-Svc
X-Cacheable
X-Generator
Content-Security-Policy-Report-Only
X-Cache-Status
X-DNS-Prefetch-Control
X-AspNetMvc-Version
Status
X-Template
X-Language
Timing-Allow-Origin
Content-Encoding
X-Permitted-Cross-Domain-Policies
X-Iinfo
X-Buckets
X-Content-Security-Policy
X-Turbo-Charged-By
X-Kinja-Server-Push
Upgrade
X-CDN
X-Request-ID
X-Type
Xkey
Keep-Alive
Access-Control-Expose-Headers
Access-Control-Max-Age
WPE-Backend
X-Pass-Why
X-AH-Environment
X-Backend
X-Cache-Group
X-Server
X-Age
X-Drupal-Dynamic-Cache
X-Pingback
X-Via
X-Nginx-Cache-Status
Grace
X-Amz-Request-Id
X-Amz-Id-2
X-Server-Powered-By
EagleId
X-Hacker
X-UA-Device
X-Robots-Tag
X-LiteSpeed-Cache
X-Varnish-Cache
X-Page-Speed
X-Proxy-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Request-Context
Cf-Railgun
X-Envoy-Upstream-Service-Time
Ali-Swift-Global-Savetime
X-Ua-Compatible
X-Ac
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-WebKit-CSP
X-Device
X-Cache-Lookup
X-Amz-Version-Id
Content-Location
Surrogate-Control
X-Server-Id
X-Cnection
X-Node
X-OneAgent-JS-Injection
X-Host
X-Readtime
EagleEye-TraceId
Report-To
X-Rq
X-Response-Time
Server-Timing
Feature-Policy
X-Application-Context
X-Rack-Cache
X-CST
X-Backend-Server
X-ORACLE-DMS-ECID
X-Iejgwucgyu
X-Cloud-Trace-Context
Request-Id
X-Instart-Request-ID
X-Clacks-Overhead
NEL
Edge-Control
X-DynaTrace
X-Url
Rating
Allow
X-Country
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Varnish-TTL
X-Origin-Cache
X-FTR-Request-ID
X-Country-Code
X-B3-TraceId
X-Trace
X-Px
X-Server-ID
X-DataDome
X-Vhost
X-ESI
X-GitHub-Request-Id
X-Server-Name
X-ORACLE-DMS-RID
X-VARITI-CCR
X-Ruxit-JS-Agent
Accept-CH
RTSS
X-Cached
X-Goog-Hash
X-MS-InvokeApp
Charset
X-TTL
SPRequestGuid
X-Mod-Pagespeed
Pinterest-Generated-By
X-PC
X-TtlSet
X-Vname
X-D2id
Verso
Public-Key-Pins
X-F-Cache
X-GoogleNews-Bot
X-Kinja-Build
X-Exp-Variant
X-Exp-Id
X-Cdn-Fetch
X-Kinja-Revision
X-Kinja
X-Kinja-Server
X-Use-Magma
X-Mobile-Rewrite
PB-RID
PB-PID
Arc-Version
X-Version
X-Dispatcher
X-Cdn
X-T
X-SharePointHealthScore
X-Powered-By-Plesk
Accept-CH-Lifetime
X-DIS-Request-ID
X-Abt-Application-Version
X-Powered-CMS
X-Fastly-Request-ID
X-Ser
X-DynaTrace-JS-Agent
X-Origin-Upstream-Status
Pinterest-Version
X-Pinterest-Rid
X-Upstream-Env
X-Navigation-Version
X-B
X-Shield-Request-Id
X-Forwarded-Proto
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Amz-Rid
MS-Author-Via
Realpath
X-Recruiting
X-Client-IP
DynaTrace
X-HW
SPRequestDuration
SPIisLatency
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Upstream
X-Vcap-Request-Id
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Stored-Content-Length
Nginx-Cache
Content-MD5
X-Accel-Buffering
X-Wix-Server-Artifact-Id
X-Amz-Meta-S3cmd-Attrs
AR-CACHE
AR-PoweredBy
AR-ATIME
X-Ttl
Arr-Disable-Session-Affinity
Edge-Cache-Tag
X-Hits
X-Debug
X-Varnish-Age
X-N
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
X-Oracle-Dms-Rid
X-Goog-Storage-Class
X-Aspnet-Version
X-MSEdge-Ref
X-NF-Request-ID
X-Dw-Request-Base-Id
X-Via-JSL
X-Acc-Meta-Resource-Type
Access-Control-Request-Method
X-Id
TCN
X-XRDS-Location
S
X-NewRelic-App-Data
X-ATG-Version
X-FTR-Balancer
X-FTR-DC
X-FTR-Realm
X-FTR-Cache-Status
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Backend
Service-Worker-Allowed
X-FTR-Expires
X-Logged-In
X-Oneagent-Js-Injection
Alternate-Protocol
X-Forwarded-For
X-HS-Content-Id
X-HS-Hub-Id
Surrogate-Key
X-Frontend
X-Kinsta-Cache
Tracecode
X-PressLabs-Stats
Rt-Fastcgi-Cache
AMP-Access-Control-Allow-Source-Origin
X-Content-Digest
X-FastCGI-Cache
X-Cache-Key
X-Pad
X-FTR-Cache-Host
X-Grace
MicrosoftSharePointTeamServices
Fastly-Restarts
X-RateLimit-Remaining
Server-Name
X-CF-Powered-By
X-Edge-Location
Fastcgi-Cache
X-Amzn-Trace-Id
X-Analytics
X-Content-Options
Backend-Timing
X-Ruxit-Js-Agent
TP-Cache
TP-L2-Cache
Ar-Sid
FilterID
Host
X-Cache-2
X-Rid
X-User-Agent
X-Magnolia-Registration
X-Whom
ServerID
X-B3-Sampled
X-Debug-Info
X-IPLB-Instance
X-Revision
Eomportal-Instance
X-Page-Id
X-Mobile
X-Hostname
X-Request-Processing-Time
X-Request-Received
X-Srv
X-NWS-LOG-UUID
AR-Request-ID
X-Akam-SW-Version
Paypal-Debug-Id
X-VCache
X-URL
Front-End-Https
X-AOL-HN
Retry-After
Refresh
X-Content-Powered-By
X-Litespeed-Cache
X-LB-Cache
X-Signature
X-B-Cache
X-Cluster
X-Framework
X-Handled-By
X-Device-Type
X-Cache-Action
X-Request-Guid
Source
X-SS-Set-Cookie
X-FB-Debug
X-App-Environment
Cleartype
X-Varnish-Hostname
X-Tumblr-User
X-WA-Info
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Instance
X-Cache-Control
X-BCube-Filmed-By
X-Akamai-Edgescape
X-Correlation-Id
X-Varnish-Grace
X-Cache-Hit
X-Fastcgi-Cache
X-Platform-Server
X-Content-Security-Policy-Report-Only
X-HS-Cache-Config
X-GUploader-UploadID
Webserver
X-AppVersion
X-Az
X-Activity-Id
X-Zen-Fury
Display
X-Sol
X-XRDS-LOCATION
X-Middleton-Display
X-Content-Type
X-Varnish-Backend
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
Healthy
X-Cache-Server
X-Cache-Rule
X-TA-CDN-Provider
X-Middleton-Response
Response
X-Cache-Age
ViewerVersion
X-Varnish-Server
X-Wix-Request-Id
X-Seen-By
X-Drupal-Cache-Tags
X-Daa-Tunnel
X-TT
Upgrade-Insecure-Requests
X-Generated-By
X-Cached-By
X-Drupal-Cache-Contexts
X-App-Server
X-Origin-Server
X-Geo-Country
Cache-Status
Accept-Charset
X-CACHE-GROUP
Server-Node
X-DataStream-Cache-Status
S-Cnection
X-Amz-Replication-Status
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Accel-Expires
X-Esi
Payment
NGB
X-S
Filters
X-UA-Device-Type
X-Response-Served-From
X-Edge-Cache
X-Edge-Cache-Key
X-Locale
X-Contextid
X-Cacheable-TTL
GEO-INFO
X-Adobe-Content
X-Adobe-Loc
Access-Control-Allow-Method
X-Servedby
X-Cache-NE
Viewport
ServedBy
Actual-Object-TTL
X-Jobs
X-Varnish-IP
X-Status
X-UUID
X-RequestSource
X-Varnish-Hits
X-TT-TIMESTAMP
X-Tumblr-Pixel-1
X-TX-ID
X-FW-Type
X-FW-Serve
X-Tumblr-Pixel-2
X-FW-Static
X-FW-Hash
X-FW-Server
X-Amz-Server-Side-Encryption
X-Storage
AsisCache
Cache-Tv-Group
Server-Info
X-WebKit-CSP-Report-Only
X-GeoIP
X-WPE-Loopback-Upstream-Addr
X-PHP-Backend
MS-CV
X-Dns-Prefetch-Control
X-Cache-Remote
X-Node-Name
HostName
X-Rendered-As
X-Cache-TTL-Remaining
Cache
X-App-Version
X-Croise-Owner
Host-Header
From-Origin
X-Region
SRV
X-Vg-Webcache
X-Cache-Operation
X-Hyper-Cache
X-Webkit-CSP
X-Redis-Cache
X-APP-VERSION
Served-By
X-Guploader-Uploadid
Liferay-Portal
X-Dynatrace-Js-Agent
Cache-Tag
Public-Key-Pins-Report-Only
DC
X-HS-Combine-CSS
X-Mode
X-BACKEND-TTL
X-CACHE-KEY
Selected-FE
X-Hosted-By
X-Upgrade-Enabled
X-Forwarded-Host
X-Timing-Wait
X-Akamai-Transformed
X-Site-Version
X-Is-Bot
X-TNCMS
X-Human
X-Cache-Var-Map
X-Agile-Age
X-IP
X-Path-Route
Pagespeed
X-Proxy-Build
Machine
X-Cache-Var
Meta-Geo
X-Agile-Id
X-Agile
X-Webstats-RespID
X-Generated
X-RN-RSRV
X-Loop
X-Detected-As
X-NGENIX-Cache
X-Upstream-CT
Xserver
X-Original-Request
X-NCache
X-Request-Time
X-ProxyCache-Status
X-ProxyCache-Key
X-Environment-Context
Origin-Edge-Control
X-Endurance-Cache-Level
X-Grey
Origin-Cache-Control
X-Internal-Host
X-CDN-Cache
X-Vgn-Hpd-Reason
X-JoinUs
X-Web-Node
X-L-Path
X-Pc-Key
Now
X-Pc-Appver
X-Cache-Category-Id
X-BYPASS-REASON
X-Via-Fastly
X-Labrador-Cache-Channel
X-Pc-Hit
Cache-Name
X-Upstream-HT
Powered-By-ChinaCache
X-Origin-Host
X-ProcessESI
X-Viewer-Country
X-B3-Spanid
X-Pubstack
X-ServerID
X-Akamai-Request-ID
X-Birta-Served
X-RemovedCookies
X-UA
X-Time-Microsecs
S-Rt
X-Origin
DB-Nickname
X-Tumblr-Pixel-3
X-VG-TLSProxy
X-Birta-Cache-Post
X-Origin-Response-Time
X-Proxy
X-FC-Vary-Parameters
Cache-Tags
Fastcgi-X-Cache
Fastcgi-X-Cache-Version
X-PCL
Fastcgi-Useragent
X-Www-Served-By
X-Backend-Name
X-OCL
Azure-Version
X-Format
Azure-RegionName
X-Cache-Config
Azure-InstanceId
X-Rule
Azure-SiteName
X-Xfnlog-Site
X-Tb
X-Ocache
X-Origin-CC
X-CCM
Mn-Server-Ip
Azure-SlotName
X-App-Name
X-Zipkin-Id
X-Origin-Hint
X-Via-CDN
X-Parent-Response-Time
X-Section
TWC-Locale-Group
TWC-Privacy
Webcakes-App-Version
X-Kong-Upstream-Latency
Property-Id
X-Access
TWC-Connection-Speed
X-Yottaa-Metrics
X-Yottaa-Optimizations
Content-Script-Type
Content-Style-Type
X-Routing-Service
X-Proxied
X-Kong-Proxy-Latency
Webcakes-App-Name
TWC-GeoIP-LatLong
TWC-Device-Class
TWC-GeoIP-Country
Webcakes-Region
HitType
X-Protected-By
Cache-Key
Datacenter
X-TIME
User-Cache-Control
X-Edge-IP
Vix-Hermes-Req-Id
X-Cache-TTL
OT-Force-Account-Verify
X-Nginx-Cache
X-Sorting-Hat-ShopId
X-Shopify-Stage
Ms-Operation-Id
X-RTag
X-ShardId
X-ShopId
X-Sorting-Hat-PodId
X-Alternate-Cache-Key
X-Akamai-Request-ID2
X-Ezoic-Cdn
Time
X-Cdn-Forward
X-Real-IP
X-OVcl
X-OVcl-Cache
X-RateLimit-Limit
X-FB-TRIP-ID
X-Cache-Backend
X-PERF
X-ApacheServer
X-Pc-Host
X-Pc-Date
NtCoent-Length
X-Newrelic-App-Data
X-Mrs-Cache
X-Unique-Id-Primal
X-Mshield-Cache-Status
X-Mrs-Cache-Hits
X-Mrs-Age
L5d-Success-Class
Accept-Language
X-Front
X-Webkit-Csp
X-Content-Age
AR-SID
X-Real-Ip
X-Correlation-ID
Country
Load-Balancing
LB
X-Proto
X-Debug-Cache
X-Amz-Meta-Surrogate-Control
X-Ratelimit-Limit
X-Varnish-Cacheable
X-Varnish-Beresp-Grace
X-Nc
Section-Io-Cache
X-Varnish-Beresp-Status
X-Varnish-Beresp-Ttl
Ohc-File-Size
X-CDN-Forward
Fusion-Source
Fusion-Component-Id
Fusion-Content-Source
Fusion-Content-Id
Fusion-Template-Id
X-Hit
WZWS-RAY
X-Unique-ID
X-Sucuri-ID
X-Hl-Ver
X-MP-GENERATED-AT
Mail-Subject
We-Hiring
X-Trace-Id
X-GRACE
Warning
X-Time
Version
X-CLOUD-TRACE-CONTEXT
User-Agent
X-Microcachable
X-EdgeConnect-Cache-Status
X-C
X-Geo
BehaviorPad-Version
Fly-Request-Id
X-Passed-To-DLL
X-BB-ID
Arc-Country
Frame-Options
X-Bip
X-Actual-URL
Rt-Proxy-Cache
X-Passed-To-BeforeDispatch
Adler-Geo
Ajk
SD-X-WS
Server-Host
X-FW-Version
X-Auto-Login
X-Application
Cache-Prefix
X-PAYTM-SRV-ID
X-G
X-Passed-To-PostProcessResponse
Ec-Rule-Version
X-Generated-In
Fastly-SWR
X-B-Cookie
X-Aed
Fastly-SIE
Fastly-Backend-Name
Server-ID
Fly-Cache
X-Node-Id
V-Age
Mobile-Detection-Method
Node
X-LI-Proto
Viewtype
Meta-Geo-Continent
VivaBuild
MD5-Digest
Memcached
X-LI-UUID
PFcat
X-Li-Pop
Thinkindot-CacheControl
Release
Rendered-Blocks
Thinkindot-CacheControl-Type
Thinkindot-Control
X-Layer
Platform
Powered-By
X-Li-Fabric
Request-Time
X-Goog-Meta-Goog-Reserved-File-Mtime
X-NU-AKA-ACS-Version
X-A-Dcw
X-A-Dam
X-A-Ccd
X-Org
X-A-Dgt
X-Passed-To
X-P-T
X-A-Wwc
RNT-Time
X-A
Is-Eu
SS
X-Logtrace-Id
Access-Control-Request-Headers
IBM-Web2-Location
Resin-Trace
RNT-Machine
Www
X-Matched-Rule
X-Accel-Expires-Debug
X-Cache-Host
X-Transaction
X-Thinkindot-L3
X-Thanos
X-Trv-Group
X-Dc
X-UE-Client-Country
X-Twitter-Response-Tags
X-TT-LOGID
X-Swa-Ws
X-Ua
X-CF-Lambda-Version
X-Server-Time
X-CF-Lambda-Fn
X-SRCache-Key
X-Connection-Hash
X-Crawler
X-Store
X-CUA
X-D
Xc-Version
X-WebServer
X-We-Are-Hiring
X-Developer
X-Device-Os
X-DPWN-IS-SECURE
X-Dispatcher-Server
X-Died
X-Via-NSCOPI
X-Destination
X-Var-Ttl
X-Date
X-User
X-Variation
X-Varnish-Action
X-External-Request-Id
X-VG-WebServer
X-From
X-Fetched-On
X-Cache-Debug
X-Server-By
X-Cache-FS-Status
X-Request-UUID
X-Response-By
X-RCS-CacheZone
X-Returned-From
X-Release
X-Cache-Enabled
X-Rebelmouse-Cache-Control
X-Cache-Expires
X-Rebelmouse-Surrogate-Control
X-Reboot
X-Region-Sid
X-Qloud-Router
X-Returned-From-DLL
X-Returned-From-BeforeDispatch
X-S-Maxage
X-Cache-Id
X-PHP-Host
X-ScT
X-Served-From
X-Cache-URL
X-Returned-From-PostProcessResponse
X-Cache-Bucket
X-Rewrite-Enabled
X-Rojux
X-S-Cookie
Pagetype
X-Rocket-Nginx-Bypass
X-Cache-CFC
X-Fstrz
X-Backend-State
X-IN-SSL-APIGATEWAY
X-Distributor
X-Hnp-Log
X-F5-Cache
X-GeoIP-Country-Code
X-Clientip
X-Block-Status
Web-Mar-Node
X-Hash
X-Amz-Meta-Cache-Control
X-Gen-Mode
X-IN-APIGATEWAY
Server-Int
True-Client-Country-4JS
Cache-Cookie-Set-From
X-IN-WAF
Cache-Cookie-Set-Lfrom
Backend
AKAMAI
X-Phone
Content-Disposition
Country-Code
Decoy-Debug-TTL
Decoy-Debug-Status
Decoy-Debug-Key
Countrycode
X-Proxy-Cache-Status
X-Proxy-Upstream
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-UnsetCookies
X-Via-Edge
X-Via-SSL
X-Stale
X-Sf
X-Request-Start
X-Server-Group
X-Server-IP
X-ServiceProvider
Esi-Enabled
Cache-Cookie-Set-Idcheck
MI-Cache
MI-Cache-Age
MI-API
Fastly-SSL
Magicmarker
On-Server
X-Info
X-Key
Proxy-Connection
Pramga
Origin
Kp-EeAlive
X-Location
X-Nginx-Cache-Key
X-No-Session
X-Origin-Date
X-Origin-Expires
GW-Server
GMS-Ver
X-MI-In-Market
Heartbleed
X-ElasticPress-Search
X-NODE
X-Be
X-Eu-Site
X-Svr
X-Irp-Debug
X-MSEdge-Features
X-V
Backend-Name
X-Distil-CS
Who
X-MSEdge-Flight
X-Secret
X-Epic-Correlation-Id
X-Page-Type
X-Gannett-Site-Version
X-Micro-Cache
X-Policy
X-Fastly-Cache
X-SIPLIST1
X-Request-URI
X-Up
X-Core-Mission
HA-Geolon
HA-Georegion
HA-Geolat
IsBot
HA-Geocity
Ha-Gx-Prefs
REQUESTUUID
HA-Urlpath
HA-Servedtime
HA-Ipaddr
HA-Host
HA-Cloudapp
HA-Geocountry
X-CGP
X-Core-Value
X-Backend-Url
X-Backend-Host
Apple-News-Services-Handled
Apple-News-Services-Host
X-Wikidot-Backend
X-Sn-Servicetimems
X-Wikidot-Static-Cache
X-Platform
X-Refresh
Apple-News-Services-Parsed-Url
X-Debug-Cache-Store
X-Debug-Cache-Fetch
CDCHOST
X-Developers
X-Origin-TTL
Fastly-Soc-X-Request-Id
Apple-News-Services-Request-Url
X-NX-Host
X-Debug-Cache-Expiry
X-Cdn-Origin
X-Level-Front-Cache
X-Generated-On
Pragrma
X-Debug-Cookies
X-Debug-Log
X-COUNTRY
X-Servername
X-Instart-Info
X-Planisys-CDN-Cache
UCS
X-Planisys-CDN-Rules
X-Urbn-Context-Path
X-DC
Uber-Trace-Id
X-Planisys-CDN-TTL
X-Urbn-Site-Id
ServerName
Request-Country
X-Instance-Name
Request-EU
RequestId
Locale
Lfy
Ohc-Response-Time
X-Cache-Info
X-VarnCache
X-Pjax-Url
X-VarnPar1
X-PARISIEN-Cache-Rendered
Host-ID
X-NWS-UUID-VERIFY
X-Cdn-Srv
X-Server-Cache
V-Cache
PageSpeed
Group
X-Req
X-NC
X-CACHE-AGE
X-GeoIP-City
X-ARC
X-VCT
X-Newrelic-Synthetics
MIME-Version
X-Datadome
HitInfo
Cteonnt-Length
Cdn
Memory
Cache-Provider
Mime-Version
X-CMS-Context
X-BBXSRF
X-Powered-By-ANYU
PICS-Label
X-Gdpr
X-EIG-Tracking-Id
X-Ratelimit-Remaining
X-Servedbyhost
X-LAGOON
X-TWH-CORRELATION-ID
Nel
X-WR-MODIFICATION
X-Aicache-OS
NGX
X-Wa
CF-IPCountry
X-HTML-Minification-Powered-By
X-StackifyID
GeoIP-Latitude
GeoIP-Country-Code
X-B3-Traceid
X-Load-Cache
CDN
X-Fastly-Country-Code
Cf-Ipcountry
X-FireWall-Port
X-Fastly-Backend-Reqs
X-UPSTREAM-Address
X-CSRF-TOKEN
XServer
X-Cluster-Node
X-Varnish-Cache-Hits
X-WA
X-RateLimit-Limit-Second
X-Generation-Time
X-Sentry-ID
X-RateLimit-Remaining-Second
FSS-Cache
FSS-Proxy
X-NodeID
X-Cache-Miss-From
GeoIp-Country-Code
X-Sedo-Request-Id
Processtime
X-Hello
X-ABtesting
X-Check-Cacheable
X-VServer
X-Flog
Geoip-Latitude
Amp-Access-Control-Allow-Source-Origin
X-Csrf-Token
SN
X-HOST
X-Cache-Grace
X-Unique-Id
X-Source
CACHE
X-Varnish-Beresp-TTL
X-Oss-Hash-Crc64ecma
X-Varnish-Authentication
Server-Surrogate-Control
X-Oss-Object-Type
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Request-Id
X-Cache-ASPX
X-CDN-Pop-IP
Server-Cache-Control
X-CDN-Pop
X-APP
X-ServedByHost
X-GZip
WP-Super-Cache
X-CSRF-Token
X-GDPR
X-Nananana
X-IPS-LoggedIn
X-Dynatrace
URI
Pics-Label
X-RCS-Backend
X-DataStream-MidMile-RTT
X-DataStream-Origin-MEX-Latency
TSSecure
X-SRV
X-Skip-Cache
Cdn-Request-Time
X-Worker
X-Varnish-Url
X-Edge-Server
X-FORWARDED-FOR
Cdn-Host
X-MServer
X-VC-Cache
X-ID
DataCenter
X-VG-WebCache
X-Fastly-Cache-Hits
X-HS-Status
X-ND-Cache
X-Instart-Isnd
A
Is-Session-Tracking
Get-Access-Time
X-GoCache-CacheStatus
X-From-Cache
X-B3-SpanId
PageType
X-Sucuri-Cache
X-Swift-Error
X-BE
Hostname
X-PJAX-URL
Proxy-Firewall
HTTPS
X-Port
Dynatrace
X-LJ-Flow-ID
X-VWS-Id
X-SplitTest
X-AWS-Id
X-Bug-Bounty
X-GZIP
X-Backend-TTL
X-Pf-Uncompressing
X-Server-W
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
Odigeo-Trace-Id
X-Gen-Id
Powered
X-Owner
X-NGINX-Cache
X-Cache-Ttl
X-VarnPar2
X-SN
Requestid
X-Fe
X-ORIG-AKA-EDGE
X-Amz-Meta-S3b-Last-Modified
Cache-Hits
X-Pc-Subdomain
Serverid
X-PF-Uncompressing
X-GEO
X-LiteSpeed-Cache-Control
X-Varnish-URL
X-SB
X-VC
X-Alicdn-Da-Ups-Status
X-PAGE-TYPE
RequestUuid
X-RAMCache
X-ServerName
X-ORIG-AKA-COUNTRY-CODE
WebServer
X-Serial
X-HostName
X-Dw-Trace-Id
X-RequestId
T-Server
X-Akamai-SSL-Client-Sid
Correlation-Id
X-App
NnCoection
X-FW-Dynamic
X-R9-Blue-Green-Version
Xet-Cookie
X-Developed-By
SID
X-CS
Location
X-HTML-Edge-Cache
X-Akamai-ERRuleID
X-Ms-Version
X-Akamai-ERPolicy
X-Ms-Blob-Type
X-Ms-Lease-Status
X-Ms-Request-Id
X-LiteSpeed-Tag