Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Accept-Ranges
Pragma
X-Powered-By
Link
ETag
CF-RAY
Expect-CT
Via
X-XSS-Protection
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Id
X-Served-By
P3P
Referrer-Policy
X-Varnish
X-Xss-Protection
X-Timer
CF-Cache-Status
X-Request-Id
Access-Control-Allow-Headers
X-AspNet-Version
Access-Control-Allow-Methods
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
P3p
X-Drupal-Cache
X-Check
X-Adblock-Key
Alt-Svc
X-Cacheable
X-Generator
CF-Ray
Content-Security-Policy-Report-Only
X-Amz-Cf-Pop
X-Cache-Status
X-AspNetMvc-Version
Status
X-DNS-Prefetch-Control
X-Request-ID
X-Template
X-Language
Timing-Allow-Origin
Content-Encoding
X-Permitted-Cross-Domain-Policies
X-Iinfo
X-Buckets
X-Content-Security-Policy
X-Turbo-Charged-By
Upgrade
X-Kinja-Server-Push
X-CDN
X-Type
Xkey
Keep-Alive
Access-Control-Expose-Headers
WPE-Backend
X-Pass-Why
Access-Control-Max-Age
X-AH-Environment
X-Backend
X-Cache-Group
X-Server
X-Age
X-Drupal-Dynamic-Cache
X-Pingback
X-Via
X-Nginx-Cache-Status
X-Amz-Request-Id
X-Amz-Id-2
Grace
X-Server-Powered-By
X-Hacker
EagleId
X-UA-Device
X-Robots-Tag
X-LiteSpeed-Cache
X-Varnish-Cache
X-Page-Speed
X-Swift-SaveTime
X-Swift-CacheTime
X-Proxy-Cache
Cf-Railgun
X-Envoy-Upstream-Service-Time
Request-Context
Ali-Swift-Global-Savetime
X-Ua-Compatible
X-Ac
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-WebKit-CSP
X-Cache-Lookup
Content-Location
X-Server-Id
X-Amz-Version-Id
Surrogate-Control
X-Host
X-Node
X-Cnection
X-Readtime
Report-To
EagleEye-TraceId
X-Rq
Server-Timing
X-Response-Time
X-OneAgent-JS-Injection
X-CST
Feature-Policy
X-Rack-Cache
X-Backend-Server
X-ORACLE-DMS-ECID
X-Application-Context
X-Iejgwucgyu
Request-Id
X-Instart-Request-ID
X-Cloud-Trace-Context
X-Clacks-Overhead
NEL
X-Url
Edge-Control
X-Cdn
X-DynaTrace
Allow
Rating
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Country
X-Varnish-TTL
X-Origin-Cache
X-FTR-Request-ID
X-Country-Code
X-B3-TraceId
X-Trace
X-Server-Name
X-DataDome
X-Px
X-Vhost
X-ESI
X-GitHub-Request-Id
RTSS
X-MS-InvokeApp
X-VARITI-CCR
X-Cached
X-Ruxit-JS-Agent
Accept-CH
X-Goog-Hash
SPRequestGuid
X-ORACLE-DMS-RID
Charset
X-Server-ID
X-Vname
X-TtlSet
X-PC
Pinterest-Generated-By
X-D2id
X-Mod-Pagespeed
Public-Key-Pins
X-Exp-Variant
X-Exp-Id
X-Cdn-Fetch
Verso
X-GoogleNews-Bot
X-Kinja
X-Use-Magma
X-Kinja-Server
X-Kinja-Revision
X-Kinja-Build
X-Dispatcher
X-F-Cache
PB-PID
X-Mobile-Rewrite
Arc-Version
PB-RID
X-SharePointHealthScore
X-TTL
X-T
X-Version
X-Powered-By-Plesk
X-DynaTrace-JS-Agent
X-Abt-Application-Version
Accept-CH-Lifetime
X-DIS-Request-ID
X-Powered-CMS
X-Dns-Prefetch-Control
X-Ser
X-Fastly-Request-ID
Pinterest-Version
X-Upstream-Env
X-Pinterest-Rid
X-Origin-Upstream-Status
X-Navigation-Version
X-Shield-Request-Id
X-B
X-Forwarded-Proto
X-Recruiting
X-Client-IP
MS-Author-Via
DynaTrace
X-Amz-Rid
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Realpath
X-HW
SPIisLatency
SPRequestDuration
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Oneagent-Js-Injection
Content-MD5
X-Upstream
X-Ttl
Nginx-Cache
X-Vcap-Request-Id
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Wix-Server-Artifact-Id
X-Accel-Buffering
X-Amz-Meta-S3cmd-Attrs
Edge-Cache-Tag
AR-ATIME
AR-PoweredBy
AR-CACHE
X-Oracle-Dms-Rid
X-N
X-Hits
Arr-Disable-Session-Affinity
X-Varnish-Age
X-Debug
TCN
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
X-Mrf-Item-Lastmod
Mrf-Cache-Status
X-NF-Request-ID
MRF-Tech
Access-Control-Request-Method
X-Goog-Storage-Class
X-MSEdge-Ref
X-Acc-Meta-Resource-Type
X-Dw-Request-Base-Id
X-NewRelic-App-Data
X-XRDS-Location
X-ATG-Version
X-Id
S
X-Via-JSL
Service-Worker-Allowed
X-FTR-Backend
X-Country-Code-Real
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Realm
X-FTR-DC
X-FTR-Cache-Status
X-Logged-In
X-FTR-Expires
Tracecode
Alternate-Protocol
X-HS-Content-Id
X-HS-Hub-Id
X-PressLabs-Stats
Rt-Fastcgi-Cache
X-Frontend
X-Forwarded-For
X-Content-Digest
X-Kinsta-Cache
Surrogate-Key
X-RateLimit-Remaining
Fastly-Restarts
X-Pad
X-FastCGI-Cache
MicrosoftSharePointTeamServices
AMP-Access-Control-Allow-Source-Origin
X-Cache-Key
Ar-Sid
X-FTR-Cache-Host
X-Content-Options
X-Grace
X-Ruxit-Js-Agent
X-Edge-Location
Server-Name
X-Amzn-Trace-Id
Fastcgi-Cache
Backend-Timing
X-Analytics
FilterID
X-CF-Powered-By
Host
X-Rid
TP-L2-Cache
TP-Cache
X-User-Agent
X-Hostname
X-Debug-Info
X-Whom
X-IPLB-Instance
X-B3-Sampled
ServerID
X-Magnolia-Registration
X-Revision
X-Cache-2
Eomportal-Instance
X-Request-Processing-Time
X-Request-Received
Paypal-Debug-Id
X-Page-Id
X-NWS-LOG-UUID
X-Mobile
AR-Request-ID
X-Srv
X-HS-Cache-Config
X-Akam-SW-Version
Front-End-Https
X-AOL-HN
X-VCache
X-Content-Powered-By
Retry-After
X-Litespeed-Cache
X-Signature
X-B-Cache
X-Cache-Hit
Source
X-FB-Debug
X-Varnish-Grace
X-LB-Cache
X-SS-Set-Cookie
X-App-Environment
Cleartype
X-Request-Guid
X-Cache-Action
X-Device-Type
X-Cluster
X-Instance
X-Cache-Control
Refresh
X-Tumblr-Pixel-0
X-Platform-Server
X-Tumblr-User
X-WA-Info
X-Varnish-Hostname
X-Handled-By
X-Tumblr-Pixel
X-Correlation-Id
X-Framework
X-BCube-Filmed-By
X-Content-Security-Policy-Report-Only
X-Fastcgi-Cache
X-Akamai-Edgescape
Webserver
X-GUploader-UploadID
X-Zen-Fury
X-Varnish-Backend
X-Daa-Tunnel
Display
X-Middleton-Display
X-Sol
X-Cache-Server
X-XRDS-LOCATION
X-AppVersion
X-Activity-Id
X-Az
Healthy
X-Varnish-Server
VIX-Pulpo-Upstream-Status
X-Content-Type
X-TA-CDN-Provider
X-Cache-Rule
X-Drupal-Cache-Tags
X-Drupal-Cache-Contexts
VIX-Pulpo-Node
Response
X-Geo-Country
X-URL
X-Generated-By
X-Middleton-Response
ViewerVersion
X-Wix-Request-Id
X-Seen-By
S-Cnection
X-Cached-By
X-App-Server
Server-Node
X-Cache-Age
Cache-Status
X-Origin-Server
X-Accel-Expires
X-DataStream-Cache-Status
X-Amz-Replication-Status
X-CACHE-GROUP
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Node-Name
X-TT
X-Esi
Upgrade-Insecure-Requests
Filters
GEO-INFO
NGB
X-RequestSource
X-Response-Served-From
X-S
Payment
X-Locale
X-Cacheable-TTL
X-UA-Device-Type
X-WPE-Loopback-Upstream-Addr
X-Varnish-IP
Viewport
X-Cache-NE
X-FW-Serve
X-FW-Type
X-FW-Static
X-FW-Server
X-Jobs
HostName
X-Servedby
X-Tumblr-Pixel-2
X-Contextid
Actual-Object-TTL
X-Tumblr-Pixel-1
X-Edge-Cache
X-Edge-Cache-Key
X-FW-Hash
X-GeoIP
Host-Header
ServedBy
AsisCache
X-TX-ID
X-TT-TIMESTAMP
Access-Control-Allow-Method
X-Status
X-Amz-Server-Side-Encryption
X-Varnish-Hits
X-WebKit-CSP-Report-Only
X-UUID
Accept-Charset
Server-Info
Cache
X-Storage
X-Adobe-Content
X-Adobe-Loc
X-Webkit-Csp
X-PHP-Backend
X-Vg-Webcache
SRV
X-Hyper-Cache
X-Cache-TTL-Remaining
X-CLOUD-TRACE-CONTEXT
X-Rendered-As
X-Cache-Remote
MS-CV
X-Croise-Owner
X-HS-Combine-CSS
Cache-Tv-Group
From-Origin
X-App-Version
X-APP-VERSION
X-Cache-Operation
X-Webkit-CSP
X-Region
Cache-Tag
DC
X-Forwarded-Host
Public-Key-Pins-Report-Only
X-Redis-Cache
Served-By
X-Mode
Liferay-Portal
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Guploader-Uploadid
X-CACHE-KEY
Machine
Fastcgi-Useragent
Fastcgi-X-Cache-Version
X-Endurance-Cache-Level
Fastcgi-X-Cache
X-Agile
Meta-Geo
X-Agile-Id
X-Akamai-Request-ID2
X-Agile-Age
Selected-FE
X-Generated
X-Is-Bot
X-Proxy-Build
X-IP
Xserver
X-NGENIX-Cache
X-Webstats-RespID
X-Upgrade-Enabled
X-TNCMS
X-Timing-Wait
X-Site-Version
X-RN-RSRV
X-Human
X-Loop
X-Cache-Var-Map
X-Detected-As
X-Path-Route
X-Cache-Var
X-Request-Time
X-Origin-Hint
X-ProxyCache-Status
X-ProxyCache-Key
TWC-GeoIP-LatLong
TWC-Locale-Group
TWC-Connection-Speed
X-Pc-Key
X-Pc-Hit
X-Pc-Appver
X-Proxied
Now
TWC-Device-Class
S-Rt
Property-Id
TWC-GeoIP-Country
X-Labrador-Cache-Channel
X-Grey
X-Hosted-By
X-Internal-Host
X-Format
X-Environment-Context
X-BYPASS-REASON
X-Cache-Category-Id
X-CDN-Cache
X-Routing-Service
X-JoinUs
Webcakes-App-Version
X-NCache
Cache-Name
Webcakes-Region
X-Zipkin-Id
X-L-Path
X-Vgn-Hpd-Reason
X-Via-Fastly
Webcakes-App-Name
TWC-Privacy
Pagespeed
Powered-By-ChinaCache
X-Akamai-Transformed
X-PCL
X-Original-Request
X-ProcessESI
X-RemovedCookies
X-Access
Origin-Cache-Control
X-OCL
Datacenter
X-Birta-Served
X-UA
X-Section
X-Birta-Cache-Post
Origin-Edge-Control
X-Proxy
X-Viewer-Country
X-Upstream-HT
X-Web-Node
Cache-Tags
X-Upstream-CT
DB-Nickname
X-Tumblr-Pixel-3
X-Time-Microsecs
X-Origin
X-Cache-Config
X-Origin-Response-Time
X-ServerID
X-B3-Spanid
X-Backend-Name
X-Akamai-Request-ID
X-CCM
X-Ocache
X-Xfnlog-Site
X-Rule
X-Via-CDN
X-FC-Vary-Parameters
X-Origin-CC
X-Www-Served-By
X-Origin-Host
Azure-Version
Mn-Server-Ip
X-Tb
Azure-SlotName
Azure-SiteName
HitType
X-RateLimit-Limit
Azure-RegionName
X-VG-TLSProxy
Azure-InstanceId
X-TIME
X-Pubstack
OT-Force-Account-Verify
Accept-Language
X-Alternate-Cache-Key
X-ShopId
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-App-Name
X-ShardId
X-Shopify-Stage
Cache-Key
X-Cache-TTL
X-Nginx-Cache
X-Parent-Response-Time
X-Ezoic-Cdn
X-Protected-By
User-Cache-Control
Vix-Hermes-Req-Id
X-OVcl
X-Edge-IP
X-OVcl-Cache
X-Real-Ip
Content-Script-Type
Content-Style-Type
L5d-Success-Class
X-BACKEND-TTL
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
LB
NtCoent-Length
Time
X-Newrelic-App-Data
Ms-Operation-Id
X-PERF
X-Cache-Backend
X-RTag
X-Amz-Meta-Surrogate-Control
X-ApacheServer
X-Proto
X-Pc-Host
X-Pc-Date
X-Front
X-Real-IP
X-Correlation-ID
X-Mshield-Cache-Status
X-Mrs-Age
X-Unique-Id-Primal
X-Mrs-Cache
X-Mrs-Cache-Hits
X-Nc
X-FB-TRIP-ID
X-Cdn-Forward
X-Hit
X-Dynatrace-Js-Agent
X-Varnish-Cacheable
X-CDN-Forward
X-Content-Age
Section-Io-Cache
X-Sucuri-ID
X-Debug-Cache
X-Unique-ID
AR-SID
WZWS-RAY
X-Microcachable
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-GRACE
Country
Access-Control-Request-Headers
X-C
X-Trace-Id
X-Dc
X-Time
Load-Balancing
Fusion-Source
Fusion-Content-Id
Version
Fusion-Content-Source
Fusion-Template-Id
Fusion-Component-Id
X-Cache-Enabled
X-MP-GENERATED-AT
X-EdgeConnect-Cache-Status
X-Connection-Hash
X-Transaction
X-Twitter-Response-Tags
Ohc-File-Size
We-Hiring
Warning
Mail-Subject
X-Cache-Host
X-Cache-Debug
X-Cache-FS-Status
Meta-Geo-Continent
Memcached
Resin-Trace
X-Cache-URL
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Clientip
RNT-Time
Rt-Proxy-Cache
X-Cache-Id
Rendered-Blocks
Powered-By
RNT-Machine
Release
Server-ID
X-Bip
X-BB-ID
Locale
X-A-Dcw
X-A-Dam
MD5-Digest
X-Backend-State
X-Application
X-Accel-Expires-Debug
X-Auto-Login
X-B-Cookie
X-A-Dgt
X-A-Ccd
Is-Eu
Mobile-Detection-Method
SS
X-Aed
X-Cache-Bucket
Server-Host
V-Age
Platform
Node
X-A
VivaBuild
Viewtype
SD-X-WS
X-LI-UUID
X-Served-From
X-ScT
X-Server-By
X-Server-Time
X-Store
X-SRCache-Key
X-S-Maxage
X-S-Cookie
X-Region-Sid
X-Reboot
X-Release
X-Response-By
X-Rojux
X-Rewrite-Enabled
X-Thanos
X-Trv-Group
X-Via-Edge
X-VG-WebServer
X-Via-SSL
X-We-Are-Hiring
Xc-Version
X-WebServer
X-Varnish-Action
X-Variation
X-Urbn-Context-Path
X-UE-Client-Country
X-Urbn-Site-Id
X-User
X-Var-Ttl
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-External-Request-Id
X-DPWN-IS-SECURE
X-F5-Cache
X-Fetched-On
X-FW-Version
X-From
X-Dispatcher-Server
X-Died
X-D
X-CUA
X-Date
X-Destination
X-Device-Os
X-Developer
X-G
X-Generated-In
X-Org
X-NU-AKA-ACS-Version
X-PAYTM-SRV-ID
X-PHP-Host
X-RCS-CacheZone
X-Qloud-Router
X-Logtrace-Id
Frame-Options
X-Layer
X-GeoIP-Country-Code
X-Li-Fabric
X-Li-Pop
X-LI-Proto
X-Crawler
X-A-Wwc
X-Hl-Ver
Ajk
Cache-Prefix
Countrycode
Fly-Cache
Ec-Rule-Version
Fastly-SIE
Fastly-SWR
BehaviorPad-Version
Adler-Geo
Arc-Country
Fly-Request-Id
X-Ua
X-Ratelimit-Limit
X-Varnish-Beresp-Ttl
X-Rocket-Nginx-Bypass
X-Cache-Expires
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
X-Returned-From
X-Amz-Meta-Cache-Control
Www
Thinkindot-Control
X-Returned-From-BeforeDispatch
Web-Mar-Node
AKAMAI
Who
X-Returned-From-PostProcessResponse
X-Returned-From-DLL
Apple-News-Services-Handled
X-Location
X-Actual-URL
X-Block-Status
X-Hash
X-Passed-To
X-Matched-Rule
X-Hnp-Log
User-Agent
X-Gen-Mode
X-Passed-To-BeforeDispatch
X-Eu-Site
X-Swa-Ws
X-Epic-Correlation-Id
X-Passed-To-PostProcessResponse
X-Passed-To-DLL
X-Proxy-Cache-Status
X-Proxy-Upstream
X-Request-Start
X-Info
X-Key
Apple-News-Services-Request-Url
X-Request-UUID
X-V
X-IN-WAF
X-CGP
X-Via-NSCOPI
X-IN-APIGATEWAY
X-IN-SSL-APIGATEWAY
X-UnsetCookies
UCS
HA-Urlpath
Heartbleed
HA-Servedtime
HA-Ipaddr
HA-Host
X-Sf
IBM-Web2-Location
MI-Cache
X-Thinkindot-L3
Fastly-Backend-Name
Kp-EeAlive
Ha-Gx-Prefs
HA-Georegion
GMS-Ver
X-Server-Group
X-Server-IP
X-ServiceProvider
GW-Server
HA-Cloudapp
HA-Geolon
HA-Geolat
HA-Geocountry
HA-Geocity
MI-Cache-Age
MI-API
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Request-EU
Request-Country
Esi-Enabled
Country-Code
Content-Disposition
True-Client-Country-4JS
Uber-Trace-Id
Backend
Backend-Name
X-MI-In-Market
Proxy-Connection
Decoy-Debug-Key
X-No-Session
Pramga
X-Node-Id
Origin
Decoy-Debug-TTL
Pragrma
Decoy-Debug-Status
X-Be
X-NODE
X-Instance-Name
X-SIPLIST1
X-Irp-Debug
X-Core-Value
X-Wikidot-Static-Cache
X-Wikidot-Backend
IsBot
X-Gannett-Site-Version
X-Secret
X-TT-LOGID
X-Backend-Host
X-Phone
X-P-T
X-Backend-Url
X-Nginx-Cache-Key
X-Request-URI
X-SVT-ORM-VERSION
CDCHOST
On-Server
Fastly-Soc-X-Request-Id
X-Stale
X-SVT-ORM-RULES
REQUESTUUID
Cache-Cookie-Set-From
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Distil-CS
Cache-Cookie-Set-Lfrom
Request-Time
X-Developers
X-NWS-UUID-VERIFY
Fastly-SSL
X-Platform
Cache-Cookie-Set-Idcheck
X-Policy
X-Cache-CFC
Server-Int
Group
X-Geo
V-Cache
X-Sn-Servicetimems
HitInfo
X-Refresh
X-Origin-TTL
X-VCT
X-NX-Host
X-Core-Mission
X-Origin-Expires
X-Distributor
X-Up
X-Debug-Cookies
X-Cdn-Origin
X-Origin-Date
X-MSEdge-Features
X-Fstrz
X-MSEdge-Flight
X-Debug-Log
PFcat
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-GeoIP-City
X-Page-Type
X-Planisys-CDN-TTL
X-ElasticPress-Search
Magicmarker
Pagetype
RequestId
X-DC
X-COUNTRY
X-Servername
X-Fastly-Cache
X-VarnPar1
X-Debug-Cache-Store
X-VarnCache
X-PARISIEN-Cache-Rendered
X-Debug-Cache-Fetch
X-Svr
X-Debug-Cache-Expiry
X-Req
Host-ID
X-Pjax-Url
X-Micro-Cache
X-Newrelic-Synthetics
PageSpeed
X-Generated-On
X-Level-Front-Cache
X-Instart-Info
X-BBXSRF
X-NC
X-CACHE-AGE
X-EIG-Tracking-Id
X-Powered-By-ANYU
ServerName
Lfy
Mime-Version
X-Datadome
MIME-Version
X-Cache-Info
Ohc-Response-Time
Cache-Provider
X-Cdn-Srv
X-Server-Cache
Cdn
X-ARC
Cteonnt-Length
Memory
PICS-Label
X-Gdpr
X-TWH-CORRELATION-ID
X-Servedbyhost
X-Cluster-Node
X-CMS-Context
Nel
X-StackifyID
CF-IPCountry
X-Sentry-ID
X-NodeID
FSS-Proxy
X-Fastly-Country-Code
X-LAGOON
X-Wa
X-Aicache-OS
FSS-Cache
X-Load-Cache
Amp-Access-Control-Allow-Source-Origin
X-VServer
NGX
X-Flog
X-WR-MODIFICATION
CDN
X-ABtesting
GeoIP-Country-Code
X-Hello
GeoIP-Latitude
X-Varnish-Beresp-TTL
X-B3-Traceid
SN
X-CSRF-TOKEN
X-HTML-Minification-Powered-By
GeoIp-Country-Code
XServer
X-Fastly-Backend-Reqs
Geoip-Latitude
X-Check-Cacheable
X-WA
X-GZip
X-UPSTREAM-Address
Cf-Ipcountry
TSSecure
Processtime
X-APP
X-Source
X-CSRF-Token
X-Csrf-Token
X-DataStream-MidMile-RTT
X-Worker
X-DataStream-Origin-MEX-Latency
X-FireWall-Port
X-MServer
X-HOST
PageType
CACHE
X-Ratelimit-Remaining
X-Unique-Id
WP-Super-Cache
X-CDN-Pop-IP
X-RateLimit-Limit-Second
X-Generation-Time
X-Cache-Miss-From
X-CDN-Pop
X-Varnish-Cache-Hits
A
X-Sedo-Request-Id
X-ServedByHost
X-RateLimit-Remaining-Second
X-VWS-Id
X-AWS-Id
X-Oss-Request-Id
X-Oss-Storage-Class
X-Dynatrace
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Edge-Server
Cdn-Host
X-Nananana
X-Oss-Server-Time
X-SplitTest
Cdn-Request-Time
X-LJ-Flow-ID
X-GDPR
Pics-Label
X-SRV
X-Port
X-FORWARDED-FOR
X-Cache-Grace
HTTPS
URI
X-VC-Cache
X-Skip-Cache
DataCenter
X-ID
Cache-Hits
Odigeo-Trace-Id
X-Cache-ASPX
X-Sucuri-Cache
X-IPS-LoggedIn
X-Varnish-Authentication
X-Backend-TTL
Server-Surrogate-Control
Server-Cache-Control
X-HS-Status
X-RCS-Backend
X-Owner
X-Fastly-Cache-Hits
X-B3-SpanId
X-Swift-Error
X-BE
X-Ms-Request-Id
X-Ms-Lease-Status
X-Ms-Blob-Type
X-Ms-Version
X-PJAX-URL
Dynatrace
X-Varnish-Url
Hostname
ProcessTime
X-ND-Cache
X-Instart-Isnd
X-Bug-Bounty
X-Gen-Id
X-From-Cache
X-VG-WebCache
X-Amzn-Remapped-Connection
X-SN
X-Amzn-Remapped-Date
X-GZIP
X-Server-W
X-GoCache-CacheStatus
Requestid
X-Cache-Ttl
X-VarnPar2
Get-Access-Time
X-ORIG-AKA-EDGE
X-Pf-Uncompressing
X-NGINX-Cache
Is-Session-Tracking
X-Ms-Lease-State
X-Akamai-SSL-Client-Sid
Serverid
X-Amz-Meta-S3b-Last-Modified
X-LiteSpeed-Cache-Control
X-Alicdn-Da-Ups-Status
Proxy-Firewall
X-GEO
X-PAGE-TYPE
X-Cache-Srv
X-Varnish-URL
X-ServerName
X-Fe
X-ORIG-AKA-COUNTRY-CODE
T-Server
RequestUuid
X-SB
WebServer
X-RAMCache
X-VC
X-Serial
X-PF-Uncompressing
X-Dw-Trace-Id
Xet-Cookie
X-HTML-Edge-Cache
Location
Powered
X-LiteSpeed-Tag
X-Akamai-ERRuleID
X-Akamai-ERPolicy
SID
X-Developed-By
NnCoection
NodeID
X-CS