Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Accept-Ranges
Pragma
X-Powered-By
Link
ETag
CF-RAY
Expect-CT
Via
X-Cache
X-XSS-Protection
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-UA-Compatible
X-Cache-Hits
X-Xss-Protection
X-Amz-Cf-Id
X-Served-By
P3P
Referrer-Policy
X-Varnish
X-Timer
X-Request-Id
CF-Cache-Status
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
P3p
CF-Ray
X-Drupal-Cache
X-Amz-Cf-Pop
X-Check
X-Adblock-Key
Alt-Svc
X-Cacheable
X-Generator
Content-Security-Policy-Report-Only
X-Cache-Status
X-DNS-Prefetch-Control
X-AspNetMvc-Version
Status
X-Template
X-Language
Timing-Allow-Origin
Content-Encoding
X-Permitted-Cross-Domain-Policies
X-Iinfo
X-Buckets
X-Content-Security-Policy
X-Request-ID
X-Turbo-Charged-By
X-Kinja-Server-Push
Upgrade
X-CDN
X-Type
Xkey
Keep-Alive
Access-Control-Expose-Headers
Access-Control-Max-Age
WPE-Backend
X-Pass-Why
X-AH-Environment
X-Backend
X-Cache-Group
X-Server
X-Age
X-Drupal-Dynamic-Cache
X-Pingback
X-Via
X-Nginx-Cache-Status
Grace
X-Amz-Request-Id
X-Amz-Id-2
X-Server-Powered-By
EagleId
X-Hacker
X-UA-Device
X-Robots-Tag
X-LiteSpeed-Cache
X-Varnish-Cache
X-Page-Speed
X-Proxy-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Cf-Railgun
Request-Context
X-Envoy-Upstream-Service-Time
Ali-Swift-Global-Savetime
X-Ua-Compatible
X-Ac
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-WebKit-CSP
X-Device
X-Cache-Lookup
Content-Location
X-Amz-Version-Id
X-Server-Id
Surrogate-Control
X-OneAgent-JS-Injection
X-Cnection
X-Node
X-Host
X-Readtime
Report-To
EagleEye-TraceId
X-Rq
X-Response-Time
Server-Timing
Feature-Policy
X-CST
X-Rack-Cache
X-Application-Context
X-Backend-Server
X-ORACLE-DMS-ECID
X-Iejgwucgyu
X-Cloud-Trace-Context
Request-Id
X-Instart-Request-ID
X-Clacks-Overhead
NEL
Edge-Control
X-Url
X-DynaTrace
Rating
Allow
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Varnish-TTL
X-Country
X-Origin-Cache
X-FTR-Request-ID
X-Country-Code
X-B3-TraceId
X-Cdn
X-Trace
X-Px
X-DataDome
X-Vhost
X-Server-Name
X-GitHub-Request-Id
X-Server-ID
X-VARITI-CCR
X-ESI
X-MS-InvokeApp
X-ORACLE-DMS-RID
RTSS
Accept-CH
X-Cached
X-Goog-Hash
Charset
X-TTL
X-Ruxit-JS-Agent
SPRequestGuid
Pinterest-Generated-By
X-Mod-Pagespeed
X-PC
X-TtlSet
X-Vname
Public-Key-Pins
X-F-Cache
Verso
X-D2id
X-Exp-Variant
X-Kinja-Build
X-Kinja-Server
X-GoogleNews-Bot
X-Kinja-Revision
X-Kinja
X-Exp-Id
X-Use-Magma
X-Cdn-Fetch
Arc-Version
PB-PID
X-Mobile-Rewrite
PB-RID
X-Dispatcher
X-Version
X-T
X-SharePointHealthScore
X-Powered-By-Plesk
Accept-CH-Lifetime
X-DIS-Request-ID
X-Abt-Application-Version
X-Powered-CMS
X-Fastly-Request-ID
X-Ser
X-Origin-Upstream-Status
X-Pinterest-Rid
X-Upstream-Env
Pinterest-Version
X-Navigation-Version
X-DynaTrace-JS-Agent
X-B
X-Shield-Request-Id
X-Forwarded-Proto
X-SRCache-Fetch-Status
X-Amz-Rid
X-SRCache-Store-Status
X-Recruiting
MS-Author-Via
Realpath
X-Client-IP
DynaTrace
X-HW
SPIisLatency
SPRequestDuration
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Upstream
X-Vcap-Request-Id
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Metageneration
Content-MD5
Nginx-Cache
X-Accel-Buffering
X-Wix-Server-Artifact-Id
X-Amz-Meta-S3cmd-Attrs
AR-PoweredBy
AR-CACHE
AR-ATIME
X-Oracle-Dms-Rid
Arr-Disable-Session-Affinity
Edge-Cache-Tag
X-Hits
X-Debug
X-N
X-Varnish-Age
X-Ttl
X-B3-TraceId-Primal
X-Mrf-Item-Lastmod
Mrf-Cache-Status
MRF-Tech
X-Goog-Storage-Class
X-Mrf-Section-Lastmod
X-MSEdge-Ref
X-NF-Request-ID
X-Dw-Request-Base-Id
X-Acc-Meta-Resource-Type
Access-Control-Request-Method
TCN
X-Id
X-Via-JSL
X-Aspnet-Version
S
X-ATG-Version
X-FTR-Cache-Status
X-FTR-Balancer
X-FTR-DC
X-FTR-Realm
X-FTR-Backend
X-Country-Code-Real
X-FTR-Backend-Server
Service-Worker-Allowed
X-NewRelic-App-Data
X-XRDS-Location
X-FTR-Expires
X-Logged-In
Alternate-Protocol
X-HS-Hub-Id
X-HS-Content-Id
X-Cache-Key
X-Oneagent-Js-Injection
Tracecode
X-Kinsta-Cache
X-Frontend
Surrogate-Key
Rt-Fastcgi-Cache
X-PressLabs-Stats
AMP-Access-Control-Allow-Source-Origin
X-Content-Digest
X-FastCGI-Cache
X-Forwarded-For
X-Pad
X-Grace
X-Ruxit-Js-Agent
X-FTR-Cache-Host
MicrosoftSharePointTeamServices
Fastly-Restarts
Server-Name
X-CF-Powered-By
X-Amzn-Trace-Id
X-RateLimit-Remaining
X-Edge-Location
X-Content-Options
X-Analytics
Backend-Timing
Host
FilterID
TP-L2-Cache
TP-Cache
X-Rid
X-Cache-2
Fastcgi-Cache
X-User-Agent
X-Magnolia-Registration
Ar-Sid
X-Debug-Info
ServerID
X-B3-Sampled
X-Whom
X-IPLB-Instance
X-Revision
Eomportal-Instance
X-Page-Id
X-Hostname
X-Mobile
X-Request-Received
X-Request-Processing-Time
AR-Request-ID
X-NWS-LOG-UUID
Paypal-Debug-Id
X-Srv
Front-End-Https
X-Akam-SW-Version
X-AOL-HN
X-VCache
Retry-After
X-Content-Powered-By
Refresh
X-B-Cache
X-Signature
X-Device-Type
X-Handled-By
X-Cluster
X-Cache-Action
Source
X-LB-Cache
X-Framework
X-Request-Guid
X-App-Environment
X-Varnish-Hostname
X-FB-Debug
X-URL
X-SS-Set-Cookie
Cleartype
X-WA-Info
X-BCube-Filmed-By
X-Tumblr-Pixel-0
X-Instance
X-Cache-Hit
X-Tumblr-Pixel
X-Cache-Control
X-Tumblr-User
X-XRDS-LOCATION
X-Varnish-Grace
X-Akamai-Edgescape
X-HS-Cache-Config
X-GUploader-UploadID
X-Litespeed-Cache
X-Content-Security-Policy-Report-Only
X-Platform-Server
X-Correlation-Id
Webserver
X-Activity-Id
X-AppVersion
X-Zen-Fury
X-Fastcgi-Cache
X-Az
X-Varnish-Backend
X-TA-CDN-Provider
X-Sol
Display
X-Middleton-Display
X-Content-Type
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Esi
Healthy
X-Cache-Server
X-Cache-Rule
X-Drupal-Cache-Tags
X-Middleton-Response
X-Varnish-Server
Response
X-Daa-Tunnel
X-Seen-By
X-Wix-Request-Id
ViewerVersion
X-TT
Upgrade-Insecure-Requests
X-Generated-By
X-Drupal-Cache-Contexts
X-Cached-By
X-App-Server
X-Geo-Country
X-Origin-Server
X-Cache-Age
Cache-Status
S-Cnection
Server-Node
X-Amz-Replication-Status
X-Accel-Expires
X-DataStream-Cache-Status
X-Amzn-RequestId
X-Amz-Apigw-Id
Accept-Charset
Payment
X-S
X-Response-Served-From
NGB
Filters
X-UA-Device-Type
X-CACHE-GROUP
X-Cacheable-TTL
X-Adobe-Loc
X-Edge-Cache
GEO-INFO
X-Edge-Cache-Key
X-Adobe-Content
X-Contextid
X-Locale
X-Servedby
X-RequestSource
X-Varnish-IP
Viewport
Actual-Object-TTL
Access-Control-Allow-Method
X-Status
ServedBy
X-Cache-NE
X-Jobs
X-UUID
X-FW-Static
X-TT-TIMESTAMP
X-FW-Type
X-Tumblr-Pixel-1
X-FW-Server
X-TX-ID
X-Varnish-Hits
X-FW-Hash
X-FW-Serve
X-Tumblr-Pixel-2
AsisCache
Server-Info
X-Amz-Server-Side-Encryption
X-Storage
X-WebKit-CSP-Report-Only
X-WPE-Loopback-Upstream-Addr
X-GeoIP
X-PHP-Backend
X-Node-Name
HostName
Cache-Tv-Group
MS-CV
Cache
X-Cache-Remote
X-Cache-TTL-Remaining
X-Rendered-As
Host-Header
X-Dns-Prefetch-Control
X-Croise-Owner
SRV
From-Origin
X-Region
X-App-Version
X-Dynatrace-Js-Agent
X-Cache-Operation
X-Hyper-Cache
X-APP-VERSION
X-Vg-Webcache
X-Redis-Cache
X-Webkit-CSP
Cache-Tag
Served-By
X-UA
Liferay-Portal
Public-Key-Pins-Report-Only
X-HS-Combine-CSS
DC
X-Forwarded-Host
X-Guploader-Uploadid
X-Mode
X-TIME
X-Akamai-Transformed
X-Timing-Wait
X-IP
Selected-FE
X-Loop
X-Upgrade-Enabled
X-RN-RSRV
X-Site-Version
X-NGENIX-Cache
X-TNCMS
X-Webstats-RespID
X-Cache-Var-Map
X-Generated
Powered-By-ChinaCache
X-Detected-As
X-Path-Route
X-Is-Bot
X-Cache-Var
Meta-Geo
X-Agile-Id
Machine
X-Agile-Age
X-Agile
X-Hosted-By
X-Human
X-Proxy-Build
Origin-Edge-Control
Now
Cache-Name
X-Cache-Category-Id
X-Vgn-Hpd-Reason
X-Request-Time
X-ProxyCache-Status
X-Upstream-HT
X-Upstream-CT
X-Labrador-Cache-Channel
X-Original-Request
X-NCache
X-Via-Fastly
X-ProxyCache-Key
X-Web-Node
X-L-Path
X-CDN-Cache
X-JoinUs
X-Pc-Appver
X-Environment-Context
X-Grey
X-Pc-Hit
X-Internal-Host
X-Pc-Key
X-BYPASS-REASON
Origin-Cache-Control
X-Endurance-Cache-Level
X-B3-Spanid
X-FC-Vary-Parameters
X-Origin
X-Origin-Host
X-Birta-Served
X-Akamai-Request-ID
S-Rt
X-Origin-Response-Time
X-Birta-Cache-Post
X-Proxy
X-Tumblr-Pixel-3
X-VG-TLSProxy
X-Viewer-Country
X-Time-Microsecs
X-ServerID
X-Pubstack
X-RemovedCookies
DB-Nickname
X-ProcessESI
X-BACKEND-TTL
Fastcgi-Useragent
Fastcgi-X-Cache
Cache-Tags
X-Origin-CC
X-Format
Azure-Version
Fastcgi-X-Cache-Version
X-OCL
X-Yottaa-Optimizations
X-Yottaa-Metrics
Pagespeed
Mn-Server-Ip
X-CCM
X-Ocache
X-Cache-Config
Azure-SiteName
Azure-SlotName
Azure-RegionName
X-Via-CDN
X-Www-Served-By
X-Xfnlog-Site
X-Tb
X-Rule
X-PCL
X-Backend-Name
Azure-InstanceId
Webcakes-App-Name
X-Access
Webcakes-App-Version
Webcakes-Region
Property-Id
TWC-Device-Class
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Locale-Group
TWC-Privacy
TWC-Connection-Speed
HitType
X-Origin-Hint
X-Routing-Service
X-Section
X-Zipkin-Id
X-App-Name
X-Proxied
Xserver
Content-Script-Type
Content-Style-Type
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Protected-By
Cache-Key
X-Parent-Response-Time
User-Cache-Control
X-Edge-IP
Datacenter
Vix-Hermes-Req-Id
X-Nginx-Cache
X-Newrelic-App-Data
OT-Force-Account-Verify
X-Sorting-Hat-ShopId
X-Cache-TTL
X-Sorting-Hat-PodId
X-Shopify-Stage
X-Ezoic-Cdn
X-ShopId
X-Alternate-Cache-Key
X-ShardId
X-Real-Ip
X-Akamai-Request-ID2
Ms-Operation-Id
AR-SID
X-RTag
Time
X-CACHE-KEY
X-OVcl
NtCoent-Length
X-OVcl-Cache
X-Ratelimit-Limit
X-Pc-Host
X-Pc-Date
X-Correlation-ID
X-Cdn-Forward
X-Cache-Backend
X-ApacheServer
X-PERF
X-FB-TRIP-ID
L5d-Success-Class
X-Mrs-Cache
X-Mshield-Cache-Status
X-Mrs-Cache-Hits
Accept-Language
X-Mrs-Age
X-Unique-Id-Primal
Country
LB
X-Webkit-Csp
X-Content-Age
X-Front
X-Proto
X-RateLimit-Limit
X-Real-IP
X-Amz-Meta-Surrogate-Control
Load-Balancing
X-CDN-Forward
X-Debug-Cache
X-Varnish-Cacheable
X-Varnish-Beresp-Grace
Section-Io-Cache
X-Varnish-Beresp-Status
X-COUNTRY
Fusion-Source
X-Nc
Fusion-Template-Id
X-Varnish-Beresp-Ttl
Fusion-Component-Id
X-Sucuri-ID
X-Hit
Fusion-Content-Id
Fusion-Content-Source
WZWS-RAY
Ohc-File-Size
X-Hl-Ver
X-MP-GENERATED-AT
X-Unique-ID
Mail-Subject
We-Hiring
X-Trace-Id
Version
Warning
X-Microcachable
User-Agent
X-GRACE
X-EdgeConnect-Cache-Status
X-Geo
Access-Control-Request-Headers
X-C
X-Connection-Hash
Resin-Trace
X-Crawler
Rendered-Blocks
Request-Time
RNT-Time
SS
Thinkindot-CacheControl
Server-ID
Server-Host
Release
Rt-Proxy-Cache
RNT-Machine
Platform
Memcached
X-Destination
MD5-Digest
X-Developer
X-Device-Os
Is-Eu
Meta-Geo-Continent
Mobile-Detection-Method
X-CUA
Thinkindot-CacheControl-Type
X-D
Node
X-Date
Powered-By
V-Age
X-Actual-URL
X-Cache-Debug
X-Accel-Expires-Debug
X-A-Wwc
X-Cache-Expires
X-Cache-Enabled
X-Aed
X-Cache-Bucket
X-Bip
X-B-Cookie
X-Auto-Login
X-Died
X-Application
X-Cache-FS-Status
X-Cache-Host
X-A
X-A-Ccd
Www
VivaBuild
X-BB-ID
Viewtype
X-A-Dam
X-CF-Lambda-Version
X-A-Dgt
X-Cache-Id
X-Cache-URL
X-CF-Lambda-Fn
X-A-Dcw
Thinkindot-Control
X-LI-UUID
X-Response-By
X-Request-UUID
X-Release
X-Returned-From
X-Returned-From-BeforeDispatch
X-Trv-Group
X-Returned-From-DLL
X-Region-Sid
X-Reboot
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-User
X-UE-Client-Country
X-TT-LOGID
X-Twitter-Response-Tags
X-Returned-From-PostProcessResponse
X-Rewrite-Enabled
X-Thanos
X-Thinkindot-L3
X-SRCache-Key
X-VG-WebServer
X-Store
X-Swa-Ws
X-Via-Edge
X-Transaction
X-Server-Time
X-S-Cookie
X-Rojux
X-S-Maxage
X-ScT
X-Server-By
X-Served-From
X-RCS-CacheZone
X-Qloud-Router
X-Varnish-Action
X-Li-Fabric
X-Layer
X-Li-Pop
X-LI-Proto
X-Logtrace-Id
X-Variation
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Generated-In
X-External-Request-Id
X-DPWN-IS-SECURE
X-Fetched-On
X-From
X-G
X-FW-Version
Xc-Version
X-Matched-Rule
X-We-Are-Hiring
X-PAYTM-SRV-ID
X-Passed-To-PostProcessResponse
X-Var-Ttl
X-Via-SSL
IBM-Web2-Location
X-PHP-Host
X-Passed-To-DLL
X-Passed-To-BeforeDispatch
X-NU-AKA-ACS-Version
X-Node-Id
X-Org
X-P-T
X-WebServer
X-Passed-To
X-Dispatcher-Server
SD-X-WS
Fastly-SWR
X-CLOUD-TRACE-CONTEXT
Fastly-Backend-Name
Arc-Country
Fly-Cache
Ajk
Frame-Options
Adler-Geo
Fly-Request-Id
Ec-Rule-Version
Fastly-SIE
X-Via-NSCOPI
BehaviorPad-Version
Cache-Prefix
X-Dc
X-Rocket-Nginx-Bypass
Content-Disposition
Web-Mar-Node
X-F5-Cache
X-Distributor
X-Clientip
AKAMAI
Cache-Cookie-Set-Lfrom
X-Fstrz
Cache-Cookie-Set-From
Backend
X-Backend-State
Cache-Cookie-Set-Idcheck
X-Cache-CFC
X-Block-Status
X-Amz-Meta-Cache-Control
X-GeoIP-Country-Code
X-Server-Group
X-Server-IP
X-Request-Start
X-Proxy-Upstream
X-Proxy-Cache-Status
X-ServiceProvider
X-Sf
X-UnsetCookies
PFcat
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Stale
X-Origin-Expires
X-Origin-Date
X-IN-APIGATEWAY
X-IN-SSL-APIGATEWAY
X-Hnp-Log
X-Hash
Country-Code
X-IN-WAF
X-Info
X-Nginx-Cache-Key
X-No-Session
X-MI-In-Market
X-Location
X-Key
X-Gen-Mode
X-Phone
On-Server
GMS-Ver
Origin
Proxy-Connection
Server-Int
Fastly-SSL
MI-Cache-Age
MI-Cache
Countrycode
Kp-EeAlive
GW-Server
MI-API
Heartbleed
Esi-Enabled
Pramga
Magicmarker
Decoy-Debug-Key
Decoy-Debug-Status
Decoy-Debug-TTL
True-Client-Country-4JS
X-ElasticPress-Search
X-Be
Pagetype
X-Up
X-Distil-CS
X-Epic-Correlation-Id
HA-Host
HA-Geolat
X-SIPLIST1
X-Eu-Site
HA-Georegion
X-Fastly-Cache
HA-Servedtime
Ha-Gx-Prefs
HA-Ipaddr
X-V
X-Gannett-Site-Version
HA-Urlpath
X-Irp-Debug
X-MSEdge-Flight
X-Policy
X-MSEdge-Features
HA-Geolon
X-Request-URI
HA-Geocountry
HA-Geocity
HA-Cloudapp
IsBot
X-Secret
REQUESTUUID
X-Core-Value
X-Backend-Url
Who
X-Page-Type
X-Time
Backend-Name
X-Core-Mission
X-CGP
X-Backend-Host
X-NODE
Pragrma
CDCHOST
Fastly-Soc-X-Request-Id
X-Refresh
X-Platform
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
X-Wikidot-Backend
X-Developers
Apple-News-Services-Handled
X-Debug-Cookies
X-Micro-Cache
X-Debug-Log
X-Svr
X-NX-Host
X-Origin-TTL
X-Sn-Servicetimems
X-Cdn-Origin
X-Wikidot-Static-Cache
X-Ua
X-DC
X-Instance-Name
UCS
Uber-Trace-Id
X-Servername
X-Planisys-CDN-Cache
Locale
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-Debug-Cache-Store
RequestId
Request-Country
Request-EU
X-Urbn-Context-Path
X-CACHE-AGE
X-Generated-On
X-Planisys-CDN-Rules
X-Level-Front-Cache
X-Planisys-CDN-TTL
X-Urbn-Site-Id
PageSpeed
X-NC
X-NWS-UUID-VERIFY
X-Instart-Info
Lfy
ServerName
Group
V-Cache
Ohc-Response-Time
X-Cdn-Srv
X-Req
X-Cache-Info
Host-ID
X-GeoIP-City
X-Pjax-Url
X-VCT
X-Server-Cache
X-VarnCache
X-PARISIEN-Cache-Rendered
X-VarnPar1
X-Newrelic-Synthetics
MIME-Version
HitInfo
X-ARC
Memory
X-Ratelimit-Remaining
Cteonnt-Length
X-Datadome
X-BBXSRF
PICS-Label
Cdn
Mime-Version
Cache-Provider
X-Powered-By-ANYU
X-CMS-Context
X-Gdpr
X-EIG-Tracking-Id
X-TWH-CORRELATION-ID
X-Servedbyhost
X-WR-MODIFICATION
Nel
X-StackifyID
X-LAGOON
X-Aicache-OS
CF-IPCountry
NGX
X-Wa
X-Load-Cache
CDN
X-HTML-Minification-Powered-By
XServer
X-Cluster-Node
X-B3-Traceid
GeoIP-Country-Code
X-Fastly-Country-Code
GeoIP-Latitude
Cf-Ipcountry
X-WA
X-Fastly-Backend-Reqs
FSS-Proxy
GeoIp-Country-Code
X-CSRF-TOKEN
Geoip-Latitude
X-FireWall-Port
FSS-Cache
X-NodeID
X-Sentry-ID
X-Varnish-Cache-Hits
X-Check-Cacheable
X-RateLimit-Limit-Second
X-UPSTREAM-Address
X-ABtesting
X-Flog
X-Generation-Time
X-RateLimit-Remaining-Second
X-Hello
X-VServer
X-Unique-Id
X-Cache-Miss-From
X-Sedo-Request-Id
Processtime
SN
X-Source
X-FORWARDED-FOR
X-Varnish-Beresp-TTL
Amp-Access-Control-Allow-Source-Origin
X-SRV
X-Csrf-Token
X-GZip
X-Cache-Grace
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-ServedByHost
X-HOST
X-Oss-Request-Id
X-APP
X-Oss-Server-Time
X-CSRF-Token
CACHE
WP-Super-Cache
X-CDN-Pop
X-DataStream-MidMile-RTT
X-DataStream-Origin-MEX-Latency
Server-Cache-Control
X-CDN-Pop-IP
X-Varnish-Authentication
TSSecure
Server-Surrogate-Control
X-Cache-ASPX
DataCenter
Cdn-Request-Time
X-RCS-Backend
X-Nananana
Cdn-Host
X-Edge-Server
X-IPS-LoggedIn
X-MServer
X-Worker
X-VG-WebCache
X-Dynatrace
X-Skip-Cache
A
URI
X-VC-Cache
Pics-Label
X-HS-Status
X-Varnish-Url
X-GDPR
X-ID
PageType
X-ND-Cache
X-Sucuri-Cache
X-Instart-Isnd
X-SplitTest
X-Port
X-Fastly-Cache-Hits
X-From-Cache
Get-Access-Time
HTTPS
Is-Session-Tracking
X-PJAX-URL
X-VWS-Id
X-AWS-Id
X-GoCache-CacheStatus
X-B3-SpanId
X-LJ-Flow-ID
X-BE
X-Swift-Error
X-Backend-TTL
Hostname
Dynatrace
X-Pf-Uncompressing
Proxy-Firewall
Odigeo-Trace-Id
X-Bug-Bounty
X-Server-W
Cache-Hits
X-Owner
X-GZIP
Powered
X-Gen-Id
X-SN
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
FastCGI-Cache
X-ORIG-AKA-EDGE
X-Cache-Ttl
X-NGINX-Cache
X-VarnPar2
Requestid
X-Ms-Version
Serverid
X-Amz-Meta-S3b-Last-Modified
X-Pc-Subdomain
X-Ms-Lease-Status
X-Ms-Request-Id
X-Ms-Blob-Type
X-Akamai-SSL-Client-Sid
X-Varnish-URL
X-Alicdn-Da-Ups-Status
X-PAGE-TYPE
X-Dw-Trace-Id
X-LiteSpeed-Cache-Control
X-ORIG-AKA-COUNTRY-CODE
RequestUuid
T-Server
X-ServerName
X-VC
X-SB
X-Serial
X-RAMCache
WebServer
X-Fe
X-GEO
X-HostName
ProcessTime
Correlation-Id
X-PF-Uncompressing
X-RequestId
X-Requestid
X-FE
Xet-Cookie
SID
NnCoection
X-HTML-Edge-Cache
NodeID
X-Ms-Lease-State
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-Developed-By
X-CS
Location
X-LiteSpeed-Tag