Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Accept-Ranges
Pragma
X-Powered-By
Link
ETag
CF-RAY
Expect-CT
Via
X-XSS-Protection
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Id
X-Served-By
P3P
Referrer-Policy
X-Varnish
X-Xss-Protection
X-Timer
CF-Cache-Status
X-Request-Id
Access-Control-Allow-Headers
X-AspNet-Version
Access-Control-Allow-Methods
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
P3p
X-Drupal-Cache
X-Check
X-Adblock-Key
Alt-Svc
X-Cacheable
X-Generator
CF-Ray
Content-Security-Policy-Report-Only
X-Amz-Cf-Pop
X-Cache-Status
X-AspNetMvc-Version
Status
X-DNS-Prefetch-Control
X-Request-ID
X-Template
X-Language
Timing-Allow-Origin
Content-Encoding
X-Permitted-Cross-Domain-Policies
X-Iinfo
X-Buckets
X-Content-Security-Policy
X-Turbo-Charged-By
Upgrade
X-Kinja-Server-Push
X-CDN
X-Type
Xkey
Keep-Alive
Access-Control-Expose-Headers
WPE-Backend
X-Pass-Why
Access-Control-Max-Age
X-AH-Environment
X-Backend
X-Cache-Group
X-Server
X-Age
X-Drupal-Dynamic-Cache
X-Ua-Compatible
X-Pingback
X-Via
X-Nginx-Cache-Status
X-Amz-Id-2
X-Amz-Request-Id
Grace
X-Server-Powered-By
X-Hacker
EagleId
X-UA-Device
X-Robots-Tag
X-LiteSpeed-Cache
X-Varnish-Cache
X-Page-Speed
X-Swift-SaveTime
X-Swift-CacheTime
X-Proxy-Cache
Cf-Railgun
X-Envoy-Upstream-Service-Time
Request-Context
Ali-Swift-Global-Savetime
X-Ac
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-WebKit-CSP
X-Cache-Lookup
Content-Location
X-Amz-Version-Id
X-Server-Id
Surrogate-Control
X-Host
X-Node
X-Cnection
X-Readtime
Report-To
EagleEye-TraceId
X-Rq
Server-Timing
X-Response-Time
X-OneAgent-JS-Injection
Feature-Policy
X-CST
X-Rack-Cache
X-ORACLE-DMS-ECID
X-Backend-Server
X-Application-Context
X-Iejgwucgyu
Request-Id
X-Instart-Request-ID
X-Cloud-Trace-Context
X-Clacks-Overhead
NEL
X-Url
Edge-Control
X-DynaTrace
Allow
Rating
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Country
X-Varnish-TTL
X-Origin-Cache
X-FTR-Request-ID
X-Country-Code
X-Cdn
X-B3-TraceId
X-Trace
X-Server-Name
X-Px
X-Vhost
X-DataDome
X-ESI
X-GitHub-Request-Id
RTSS
X-VARITI-CCR
X-MS-InvokeApp
X-Cached
X-Ruxit-JS-Agent
Accept-CH
X-Goog-Hash
X-ORACLE-DMS-RID
SPRequestGuid
Charset
X-Server-ID
X-PC
X-Vname
X-TtlSet
Pinterest-Generated-By
X-Mod-Pagespeed
X-D2id
X-F-Cache
Public-Key-Pins
Verso
X-Kinja-Revision
X-Kinja-Build
X-Kinja-Server
X-Use-Magma
X-Dispatcher
X-Exp-Id
X-Kinja
X-Exp-Variant
X-Cdn-Fetch
X-GoogleNews-Bot
X-Mobile-Rewrite
PB-RID
PB-PID
Arc-Version
X-SharePointHealthScore
X-T
X-Version
X-Powered-By-Plesk
X-DynaTrace-JS-Agent
X-TTL
X-Abt-Application-Version
Accept-CH-Lifetime
X-DIS-Request-ID
X-Powered-CMS
X-Dns-Prefetch-Control
X-Ser
X-Fastly-Request-ID
Pinterest-Version
X-Pinterest-Rid
X-Upstream-Env
X-Origin-Upstream-Status
X-Navigation-Version
X-Forwarded-Proto
X-Shield-Request-Id
X-B
X-Recruiting
X-Client-IP
DynaTrace
MS-Author-Via
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Amz-Rid
X-Ttl
Realpath
X-HW
SPRequestDuration
SPIisLatency
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Oneagent-Js-Injection
Content-MD5
X-Upstream
Nginx-Cache
X-Vcap-Request-Id
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Wix-Server-Artifact-Id
X-Accel-Buffering
X-Oracle-Dms-Rid
X-Amz-Meta-S3cmd-Attrs
AR-CACHE
Edge-Cache-Tag
AR-PoweredBy
AR-ATIME
X-N
X-Hits
Arr-Disable-Session-Affinity
X-Varnish-Age
X-Debug
TCN
X-Mrf-Item-Lastmod
MRF-Tech
Mrf-Cache-Status
X-NF-Request-ID
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
Access-Control-Request-Method
X-Goog-Storage-Class
X-Acc-Meta-Resource-Type
X-MSEdge-Ref
X-Dw-Request-Base-Id
X-NewRelic-App-Data
X-XRDS-Location
X-ATG-Version
S
X-Id
X-Via-JSL
Service-Worker-Allowed
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Realm
X-FTR-DC
X-FTR-Balancer
X-FTR-Backend
X-FTR-Backend-Server
X-Logged-In
X-FTR-Expires
Tracecode
Alternate-Protocol
X-HS-Content-Id
X-HS-Hub-Id
Rt-Fastcgi-Cache
X-PressLabs-Stats
X-Frontend
X-Forwarded-For
X-Content-Digest
X-Kinsta-Cache
Surrogate-Key
X-RateLimit-Remaining
Fastly-Restarts
X-Pad
X-FastCGI-Cache
MicrosoftSharePointTeamServices
X-Cache-Key
AMP-Access-Control-Allow-Source-Origin
X-Content-Options
Ar-Sid
X-FTR-Cache-Host
X-Grace
Server-Name
X-Edge-Location
X-Ruxit-Js-Agent
X-Amzn-Trace-Id
Backend-Timing
X-Analytics
Fastcgi-Cache
FilterID
Host
X-CF-Powered-By
TP-Cache
X-Rid
TP-L2-Cache
X-User-Agent
X-Hostname
X-IPLB-Instance
X-Debug-Info
ServerID
X-Whom
X-Magnolia-Registration
X-B3-Sampled
X-Revision
X-Cache-2
Eomportal-Instance
X-Request-Received
X-Request-Processing-Time
Paypal-Debug-Id
X-Page-Id
X-NWS-LOG-UUID
X-Mobile
AR-Request-ID
X-Srv
X-HS-Cache-Config
Front-End-Https
X-Akam-SW-Version
X-AOL-HN
X-Content-Powered-By
Retry-After
X-Litespeed-Cache
X-Signature
X-B-Cache
X-Cache-Hit
Source
X-FB-Debug
X-Handled-By
X-Cluster
X-Varnish-Grace
X-Device-Type
X-LB-Cache
X-Instance
X-Cache-Action
Refresh
Cleartype
X-Cache-Control
X-App-Environment
X-Request-Guid
X-WA-Info
X-BCube-Filmed-By
X-Correlation-Id
X-Tumblr-User
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-VCache
X-Varnish-Hostname
X-Framework
X-Platform-Server
X-Content-Security-Policy-Report-Only
X-Fastcgi-Cache
X-SS-Set-Cookie
X-Akamai-Edgescape
X-GUploader-UploadID
Webserver
X-Zen-Fury
X-Varnish-Backend
X-Middleton-Display
X-Sol
X-Daa-Tunnel
Display
X-XRDS-LOCATION
X-Cache-Server
X-AppVersion
X-Activity-Id
X-Az
X-Varnish-Server
Healthy
X-Content-Type
VIX-Pulpo-Upstream-Status
X-TA-CDN-Provider
X-Cache-Rule
VIX-Pulpo-Node
X-Drupal-Cache-Tags
X-Drupal-Cache-Contexts
X-Middleton-Response
X-Generated-By
Response
ViewerVersion
X-URL
X-Seen-By
X-Wix-Request-Id
X-Cached-By
S-Cnection
X-Geo-Country
X-Cache-Age
X-App-Server
Server-Node
Cache-Status
X-Origin-Server
X-Amz-Replication-Status
X-DataStream-Cache-Status
X-Accel-Expires
X-CACHE-GROUP
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Node-Name
X-Esi
Upgrade-Insecure-Requests
X-TT
GEO-INFO
NGB
X-RequestSource
Payment
X-Response-Served-From
Filters
X-S
X-UA-Device-Type
X-Locale
X-WPE-Loopback-Upstream-Addr
X-Edge-Cache-Key
X-Edge-Cache
Actual-Object-TTL
X-Cacheable-TTL
Viewport
X-Cache-NE
X-Varnish-IP
X-Tumblr-Pixel-1
X-FW-Static
X-FW-Server
X-FW-Serve
X-FW-Hash
X-FW-Type
X-Jobs
ServedBy
X-GeoIP
X-Contextid
X-Servedby
X-Tumblr-Pixel-2
HostName
Host-Header
X-Status
X-TX-ID
X-Varnish-Hits
AsisCache
X-WebKit-CSP-Report-Only
X-TT-TIMESTAMP
Access-Control-Allow-Method
Accept-Charset
X-Amz-Server-Side-Encryption
X-UUID
Server-Info
Cache
X-Storage
X-Adobe-Loc
X-Adobe-Content
X-Vg-Webcache
X-PHP-Backend
SRV
X-Rendered-As
X-Hyper-Cache
X-CLOUD-TRACE-CONTEXT
X-Cache-TTL-Remaining
X-Cache-Remote
From-Origin
MS-CV
X-Croise-Owner
X-HS-Combine-CSS
Cache-Tv-Group
X-App-Version
X-APP-VERSION
X-Cache-Operation
X-Webkit-CSP
X-Region
DC
Cache-Tag
X-Redis-Cache
Served-By
Public-Key-Pins-Report-Only
X-Forwarded-Host
X-Mode
Liferay-Portal
X-CACHE-KEY
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-UA
X-Guploader-Uploadid
X-Detected-As
X-Generated
X-Hosted-By
X-Upgrade-Enabled
X-Agile-Id
X-Timing-Wait
X-Site-Version
X-RN-RSRV
X-TNCMS
X-Endurance-Cache-Level
Machine
Fastcgi-X-Cache-Version
Fastcgi-X-Cache
Meta-Geo
Selected-FE
X-NGENIX-Cache
X-Human
X-Is-Bot
X-Request-Time
X-Loop
X-Webstats-RespID
X-Agile
X-Path-Route
X-Proxy-Build
X-Agile-Age
X-Cache-Var
Xserver
X-Cache-Var-Map
Cache-Name
X-ProxyCache-Key
X-Via-Fastly
TWC-Connection-Speed
TWC-Device-Class
X-Zipkin-Id
X-Internal-Host
S-Rt
TWC-GeoIP-Country
Property-Id
X-Pc-Key
X-Pc-Hit
Fastcgi-Useragent
X-Proxied
Now
Origin-Edge-Control
Origin-Cache-Control
TWC-GeoIP-LatLong
X-Pc-Appver
X-CDN-Cache
X-L-Path
Webcakes-App-Version
X-Labrador-Cache-Channel
X-ProxyCache-Status
X-NCache
X-BYPASS-REASON
X-Routing-Service
X-JoinUs
X-Akamai-Request-ID2
TWC-Privacy
X-Vgn-Hpd-Reason
X-IP
Webcakes-Region
Webcakes-App-Name
X-Environment-Context
X-Format
X-Original-Request
X-Origin-Hint
TWC-Locale-Group
Powered-By-ChinaCache
X-Akamai-Transformed
Pagespeed
X-RemovedCookies
X-Pubstack
X-Cache-Category-Id
X-Proxy
X-Upstream-HT
X-Viewer-Country
X-Section
X-Upstream-CT
DB-Nickname
X-Tumblr-Pixel-3
Cache-Tags
X-OCL
X-FC-Vary-Parameters
X-Birta-Cache-Post
X-Grey
X-Birta-Served
Datacenter
X-Access
X-ProcessESI
X-PCL
X-Origin-Host
X-Cache-Config
X-B3-Spanid
X-Backend-Name
X-Origin-CC
X-Ocache
X-Rule
X-Via-CDN
X-ServerID
X-Origin
X-CCM
X-Xfnlog-Site
X-Web-Node
X-Www-Served-By
X-VG-TLSProxy
X-Time-Microsecs
X-RateLimit-Limit
X-Origin-Response-Time
X-Tb
X-Akamai-Request-ID
Azure-SlotName
Azure-InstanceId
HitType
Azure-RegionName
Azure-SiteName
Mn-Server-Ip
Azure-Version
OT-Force-Account-Verify
X-TIME
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-App-Name
X-Alternate-Cache-Key
X-ShopId
X-ShardId
Cache-Key
X-Cache-TTL
Accept-Language
X-Nginx-Cache
X-Parent-Response-Time
X-Protected-By
X-Ezoic-Cdn
X-Real-Ip
X-Edge-IP
Vix-Hermes-Req-Id
X-OVcl
User-Cache-Control
X-OVcl-Cache
Content-Script-Type
L5d-Success-Class
Content-Style-Type
X-BACKEND-TTL
X-Kong-Proxy-Latency
Time
NtCoent-Length
LB
X-Kong-Upstream-Latency
X-Newrelic-App-Data
X-Cache-Backend
X-Amz-Meta-Surrogate-Control
X-RTag
Ms-Operation-Id
X-PERF
X-ApacheServer
X-Pc-Date
X-Webkit-Csp
X-Proto
X-Front
X-Pc-Host
X-Real-IP
X-Correlation-ID
X-Mrs-Age
X-Mshield-Cache-Status
X-Mrs-Cache
X-Unique-Id-Primal
X-Mrs-Cache-Hits
X-Nc
X-FB-TRIP-ID
X-Cdn-Forward
X-Dynatrace-Js-Agent
X-Hit
X-CDN-Forward
X-Varnish-Cacheable
X-Content-Age
X-Debug-Cache
X-Varnish-Beresp-Status
Section-Io-Cache
X-Varnish-Beresp-Grace
X-Sucuri-ID
WZWS-RAY
X-Unique-ID
AR-SID
X-Microcachable
X-GRACE
X-Trace-Id
Load-Balancing
Country
Access-Control-Request-Headers
X-C
Version
Fusion-Content-Source
Fusion-Content-Id
Fusion-Source
Fusion-Template-Id
X-Dc
X-Time
Fusion-Component-Id
X-Twitter-Response-Tags
X-EdgeConnect-Cache-Status
X-MP-GENERATED-AT
X-Connection-Hash
X-Cache-Enabled
X-Transaction
Ohc-File-Size
Mail-Subject
We-Hiring
Warning
Server-Host
X-Date
X-Accel-Expires-Debug
X-Actual-URL
X-Cache-Id
VivaBuild
X-D
X-A-Wwc
X-CF-Lambda-Fn
X-CUA
SS
X-A-Dam
X-Crawler
X-A-Ccd
V-Age
Server-ID
Is-Eu
X-A-Dcw
X-A
X-Clientip
X-Aed
X-CF-Lambda-Version
MD5-Digest
X-Cache-Bucket
X-Bip
Rendered-Blocks
X-Cache-Debug
X-Cache-FS-Status
X-BB-ID
Release
Platform
Viewtype
X-Backend-State
Node
Mobile-Detection-Method
Resin-Trace
X-Destination
Powered-By
SD-X-WS
X-B-Cookie
X-Auto-Login
X-Cache-Host
Memcached
RNT-Machine
RNT-Time
Meta-Geo-Continent
Rt-Proxy-Cache
X-Application
X-NU-AKA-ACS-Version
X-Rojux
X-Rewrite-Enabled
X-S-Cookie
X-S-Maxage
X-Served-From
X-ScT
X-Returned-From-PostProcessResponse
X-Returned-From-DLL
X-Release
X-Region-Sid
X-Request-UUID
X-Response-By
X-Returned-From-BeforeDispatch
X-Returned-From
X-Server-By
X-Server-Time
X-Via-Edge
X-VG-WebServer
X-Via-SSL
X-We-Are-Hiring
Xc-Version
X-WebServer
X-Varnish-Action
X-Variation
X-Store
X-SRCache-Key
X-Thanos
X-Trv-Group
X-Var-Ttl
X-UE-Client-Country
X-Reboot
X-Rebelmouse-Surrogate-Control
X-G
X-FW-Version
X-Generated-In
X-GeoIP-Country-Code
X-Li-Fabric
X-Layer
X-From
X-Fetched-On
X-Died
X-Device-Os
X-Dispatcher-Server
X-DPWN-IS-SECURE
X-F5-Cache
X-External-Request-Id
X-Li-Pop
X-LI-Proto
X-PAYTM-SRV-ID
X-Passed-To-PostProcessResponse
X-PHP-Host
X-Qloud-Router
X-Rebelmouse-Cache-Control
X-RCS-CacheZone
X-Passed-To-DLL
X-Passed-To-BeforeDispatch
X-Logtrace-Id
X-LI-UUID
X-Node-Id
IBM-Web2-Location
X-Passed-To
X-Org
X-Developer
X-A-Dgt
Fly-Cache
Fastly-SWR
Adler-Geo
Ec-Rule-Version
Countrycode
Fly-Request-Id
Frame-Options
X-Ratelimit-Limit
Ajk
X-Hl-Ver
Fastly-SIE
Fastly-Backend-Name
Arc-Country
Cache-Prefix
BehaviorPad-Version
X-Rocket-Nginx-Bypass
X-Varnish-Beresp-Ttl
X-Cache-URL
Thinkindot-CacheControl
X-Block-Status
X-V
Origin
X-Via-NSCOPI
Thinkindot-Control
Apple-News-Services-Handled
Apple-News-Services-Host
X-Swa-Ws
X-Hnp-Log
AKAMAI
X-Amz-Meta-Cache-Control
X-User
Www
X-Cache-Expires
X-Matched-Rule
Thinkindot-CacheControl-Type
X-UnsetCookies
X-MI-In-Market
X-Location
X-No-Session
X-Eu-Site
X-Epic-Correlation-Id
X-Key
X-Gen-Mode
X-Hash
X-IN-APIGATEWAY
X-IN-SSL-APIGATEWAY
X-IN-WAF
X-Info
X-Proxy-Cache-Status
X-Proxy-Upstream
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
Apple-News-Services-Request-Url
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Stale
X-Sf
X-Request-Start
User-Agent
X-Server-Group
X-ServiceProvider
X-CGP
Apple-News-Services-Parsed-Url
Pragrma
Backend
Ha-Gx-Prefs
On-Server
Pramga
Proxy-Connection
Request-EU
Request-Country
Esi-Enabled
HA-Host
MI-Cache-Age
HA-Servedtime
HA-Urlpath
Heartbleed
Kp-EeAlive
Locale
MI-Cache
MI-API
HA-Ipaddr
HA-Georegion
HA-Geolon
GW-Server
X-Thinkindot-L3
True-Client-Country-4JS
HA-Cloudapp
Uber-Trace-Id
UCS
Who
Web-Mar-Node
GMS-Ver
Backend-Name
HA-Geocity
HA-Geocountry
Decoy-Debug-TTL
HA-Geolat
Decoy-Debug-Key
Decoy-Debug-Status
Country-Code
Content-Disposition
X-NODE
X-Be
X-Policy
X-Irp-Debug
X-Platform
X-Instance-Name
Request-Time
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
Fastly-SSL
X-Core-Value
X-Gannett-Site-Version
X-SIPLIST1
X-Secret
Cache-Cookie-Set-From
IsBot
X-Wikidot-Static-Cache
X-Request-URI
X-Nginx-Cache-Key
X-P-T
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Cache-CFC
X-Wikidot-Backend
Server-Int
X-Phone
X-Server-IP
X-Developers
X-NWS-UUID-VERIFY
REQUESTUUID
Fastly-Soc-X-Request-Id
X-Distil-CS
CDCHOST
X-Ua
X-Geo
Group
V-Cache
X-Backend-Host
X-Backend-Url
X-Refresh
X-Page-Type
X-Planisys-CDN-Cache
HitInfo
X-Cdn-Origin
X-Origin-Date
X-Sn-Servicetimems
X-ElasticPress-Search
X-Debug-Log
X-VCT
X-Debug-Cookies
X-Origin-TTL
X-Distributor
X-Core-Mission
X-Fstrz
X-Origin-Expires
X-MSEdge-Flight
X-MSEdge-Features
X-Planisys-CDN-Rules
X-TT-LOGID
PFcat
X-GeoIP-City
X-Planisys-CDN-TTL
X-Up
X-NX-Host
Magicmarker
Pagetype
X-Servername
X-Fastly-Cache
RequestId
X-DC
X-COUNTRY
X-Svr
X-Pjax-Url
X-Newrelic-Synthetics
X-Debug-Cache-Store
X-VarnCache
X-Debug-Cache-Fetch
Host-ID
X-Micro-Cache
X-Debug-Cache-Expiry
X-VarnPar1
X-PARISIEN-Cache-Rendered
X-Req
PageSpeed
X-Instart-Info
X-CACHE-AGE
X-NC
X-BBXSRF
X-Level-Front-Cache
X-Generated-On
X-Powered-By-ANYU
X-EIG-Tracking-Id
Lfy
ServerName
X-Datadome
Mime-Version
MIME-Version
X-Cdn-Srv
Ohc-Response-Time
X-Server-Cache
Cache-Provider
X-Cache-Info
Cdn
X-ARC
Cteonnt-Length
PICS-Label
Memory
X-Gdpr
X-TWH-CORRELATION-ID
X-Cluster-Node
Nel
X-CMS-Context
X-Servedbyhost
X-StackifyID
CF-IPCountry
X-Sentry-ID
X-Wa
Amp-Access-Control-Allow-Source-Origin
X-Aicache-OS
X-LAGOON
FSS-Cache
X-Fastly-Country-Code
FSS-Proxy
X-NodeID
X-Load-Cache
X-ABtesting
GeoIP-Country-Code
NGX
GeoIP-Latitude
X-Flog
X-Varnish-Beresp-TTL
X-VServer
X-Hello
CDN
X-HTML-Minification-Powered-By
X-WR-MODIFICATION
X-B3-Traceid
X-Fastly-Backend-Reqs
SN
GeoIp-Country-Code
X-CSRF-TOKEN
Geoip-Latitude
X-WA
XServer
X-Check-Cacheable
X-UPSTREAM-Address
X-GZip
TSSecure
Processtime
Cf-Ipcountry
X-APP
X-Source
X-Csrf-Token
X-CSRF-Token
X-MServer
X-HOST
X-DataStream-Origin-MEX-Latency
X-DataStream-MidMile-RTT
X-FireWall-Port
X-Worker
CACHE
X-Unique-Id
PageType
X-Ratelimit-Remaining
X-ServedByHost
X-Sedo-Request-Id
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-CDN-Pop-IP
A
WP-Super-Cache
X-Varnish-Cache-Hits
X-CDN-Pop
X-Cache-Miss-From
X-Generation-Time
Pics-Label
X-GDPR
Cdn-Host
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
X-Oss-Server-Time
X-Nananana
X-VWS-Id
X-SplitTest
X-Dynatrace
X-Oss-Storage-Class
X-Oss-Object-Type
X-AWS-Id
X-LJ-Flow-ID
Cdn-Request-Time
X-Edge-Server
X-Port
X-SRV
X-Cache-Grace
X-Skip-Cache
X-VC-Cache
HTTPS
X-FORWARDED-FOR
RATING
X-ID
DataCenter
Cache-Hits
X-Backend-TTL
Server-Cache-Control
X-Varnish-Authentication
Odigeo-Trace-Id
X-Sucuri-Cache
X-Cache-ASPX
X-IPS-LoggedIn
URI
Server-Surrogate-Control
X-Fastly-Cache-Hits
X-RCS-Backend
X-HS-Status
X-B3-SpanId
X-Owner
X-Ms-Lease-Status
X-Ms-Version
X-Ms-Request-Id
X-BE
X-Swift-Error
X-Ms-Blob-Type
Hostname
X-PJAX-URL
Dynatrace
X-Varnish-Url
ProcessTime
X-VG-WebCache
X-SN
X-Gen-Id
X-From-Cache
X-Bug-Bounty
X-ND-Cache
X-Amzn-Remapped-Connection
X-GZIP
X-Amzn-Remapped-Date
X-Instart-Isnd
X-Ms-Lease-State
X-GoCache-CacheStatus
X-NGINX-Cache
X-ORIG-AKA-EDGE
X-ServerName
Requestid
X-Pf-Uncompressing
Get-Access-Time
Is-Session-Tracking
X-VarnPar2
X-Vcache
X-Cache-Ttl
X-Server-W
X-Amz-Meta-S3b-Last-Modified
X-Akamai-SSL-Client-Sid
Serverid
X-PAGE-TYPE
Proxy-Firewall
X-Alicdn-Da-Ups-Status
X-Varnish-URL
X-LiteSpeed-Cache-Control
X-GEO
X-VC
RequestUuid
X-SB
X-Serial
X-RAMCache
X-Fe
WebServer
T-Server
X-ORIG-AKA-COUNTRY-CODE
X-Cache-Srv
X-Akamai-ERRuleID
X-Developed-By
Xet-Cookie
X-Akamai-ERPolicy
X-PF-Uncompressing
Powered
X-LiteSpeed-Tag
Location
NodeID
X-Dw-Trace-Id
NnCoection
X-CS
X-HTML-Edge-Cache
SID