Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
Last-Modified
X-Content-Type-Options
Accept-Ranges
Pragma
X-Powered-By
CF-RAY
Link
ETag
Expect-CT
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Id
X-Served-By
Referrer-Policy
X-Varnish
X-Xss-Protection
X-Timer
X-Request-Id
CF-Cache-Status
X-AspNet-Version
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Runtime
X-Download-Options
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Cacheable
Alt-Svc
X-Check
X-Generator
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Cache-Status
X-AspNetMvc-Version
Status
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Template
X-Language
X-Permitted-Cross-Domain-Policies
Content-Encoding
X-Request-ID
X-Iinfo
X-FRAME-OPTIONS
X-Content-Security-Policy
X-CDN
X-Buckets
X-Turbo-Charged-By
X-Type
Upgrade
WPE-Backend
X-Pass-Why
Keep-Alive
X-Cache-Group
X-AH-Environment
Xkey
X-Backend
P3p
Access-Control-Max-Age
X-Age
Access-Control-Expose-Headers
X-Via
EagleId
X-Drupal-Dynamic-Cache
X-Nginx-Cache-Status
X-Pingback
X-Amz-Id-2
X-Amz-Request-Id
X-Server-Powered-By
X-Server
X-Hacker
X-Swift-CacheTime
X-Swift-SaveTime
Grace
X-UA-Device
Ali-Swift-Global-Savetime
X-Varnish-Cache
X-Robots-Tag
X-Kinja-Server-Push
Cf-Railgun
X-Proxy-Cache
X-Envoy-Upstream-Service-Time
X-LiteSpeed-Cache
X-Page-Speed
Request-Context
X-Device
X-Ac
Content-Location
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Cache-Lookup
X-Amz-Version-Id
X-WebKit-CSP
X-Response-Time
Surrogate-Control
X-Host
X-OneAgent-JS-Injection
X-Rq
X-Cnection
X-Backend-Server
X-Readtime
Server-Timing
X-Node
X-Rack-Cache
Report-To
X-Server-Id
EagleEye-TraceId
Request-Id
X-Application-Context
X-Cloud-Trace-Context
Feature-Policy
X-ORACLE-DMS-ECID
X-CST
X-Instart-Request-ID
X-Iejgwucgyu
X-Ua-Compatible
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Clacks-Overhead
Edge-Control
NEL
X-Country
Rating
X-Url
X-Server-Name
X-Px
Pinterest-Generated-By
Allow
X-Country-Code
X-TTL
X-DataDome
X-Varnish-TTL
X-MS-InvokeApp
X-DynaTrace
X-Origin-Cache
X-Vhost
X-PC
X-Vname
X-TtlSet
X-Cached
X-FTR-Request-ID
X-ESI
RTSS
X-Ruxit-JS-Agent
X-Server-ID
X-Goog-Hash
X-VARITI-CCR
Charset
SPRequestGuid
X-Powered-CMS
X-Powered-By-Plesk
X-Trace
X-DynaTrace-JS-Agent
Accept-CH
X-Dispatcher
X-GitHub-Request-Id
X-SharePointHealthScore
Public-Key-Pins
X-D2id
X-T
X-Mod-Pagespeed
PB-PID
X-Oracle-Dms-Rid
X-F-Cache
Arc-Version
PB-RID
X-Mobile-Rewrite
X-Kinja
Content-MD5
X-Exp-Variant
X-Kinja-Revision
X-Kinja-Build
X-Cdn-Fetch
X-Kinja-Server
X-Exp-Id
X-GoogleNews-Bot
Verso
MS-Author-Via
X-Version
X-B3-TraceId
SPRequestDuration
SPIisLatency
X-Recruiting
X-Shield-Request-Id
X-Abt-Application-Version
Nginx-Cache
X-Dns-Prefetch-Control
X-Client-IP
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-HW
X-Forwarded-Proto
Accept-CH-Lifetime
X-DIS-Request-ID
X-Navigation-Version
X-N
AR-ATIME
AR-PoweredBy
X-Pinterest-Rid
X-Upstream-Env
Pinterest-Version
AR-CACHE
X-Amz-Rid
X-B
X-Dw-Request-Base-Id
X-Origin-Upstream-Status
X-Upstream
X-ORACLE-DMS-RID
X-Fastly-Request-ID
X-XRDS-Location
DynaTrace
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Fastly-Restarts
X-Ser
X-Amz-Meta-S3cmd-Attrs
X-Hits
Paypal-Debug-Id
TCN
Realpath
X-Wix-Server-Artifact-Id
X-Accel-Buffering
X-Content-Options
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Stored-Content-Length
Arr-Disable-Session-Affinity
X-Pad
Service-Worker-Allowed
X-NF-Request-ID
X-Goog-Storage-Class
X-Acc-Meta-Resource-Type
Tracecode
Access-Control-Request-Method
X-Content-Digest
S
X-Id
X-Varnish-Age
Front-End-Https
X-Debug
Mrf-Cache-Status
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
MRF-Tech
X-Amz-Cf-Pop
X-MSEdge-Ref
X-Vcap-Request-Id
X-Oneagent-Js-Injection
X-IPLB-Instance
X-FTR-Cache-Status
X-FTR-DC
X-FTR-Balancer
X-Country-Code-Real
X-FTR-Expires
X-Frontend
X-FTR-Backend-Server
X-FTR-Backend
X-PressLabs-Stats
X-FTR-Realm
X-ATG-Version
X-Kinsta-Cache
X-RateLimit-Remaining
X-Middleton-Display
X-Sol
Display
X-Cache-Hit
X-Logged-In
Edge-Cache-Tag
Surrogate-Key
X-HS-Hub-Id
X-HS-Content-Id
X-Forwarded-For
X-FastCGI-Cache
Rt-Fastcgi-Cache
Fastcgi-Cache
X-Use-Magma
Powered-By-ChinaCache
MicrosoftSharePointTeamServices
X-Request-Processing-Time
X-Request-Received
X-Zen-Fury
X-Edge-Location
X-Grace
Server-Name
Backend-Timing
X-Analytics
X-Rid
Host
X-Middleton-Response
X-Revision
Response
X-Debug-Info
X-Amzn-Trace-Id
X-FTR-Cache-Host
TP-Cache
X-User-Agent
TP-L2-Cache
FilterID
X-Akam-SW-Version
X-Litespeed-Cache
X-CF-Powered-By
X-Webkit-Csp
X-Mobile
X-NewRelic-App-Data
X-B3-TraceId-Primal
X-Cache-Key
X-SS-Set-Cookie
AMP-Access-Control-Allow-Source-Origin
Ar-Sid
X-HS-Cache-Config
X-Drupal-Cache-Tags
X-Accel-Expires
X-TA-CDN-Provider
X-Magnolia-Registration
Cache-Status
Refresh
X-Cached-By
Host-Header
AR-Request-ID
X-Ttl
X-SERVER
X-Newrelic-App-Data
X-Fastcgi-Cache
ServerID
X-Varnish-Backend
X-B3-Sampled
X-Node-Name
X-AOL-HN
X-GUploader-UploadID
X-Tumblr-Pixel
X-Cluster
X-Content-Security-Policy-Report-Only
X-Tumblr-User
X-Tumblr-Pixel-0
X-FB-Debug
X-Cache-Control
X-B-Cache
X-Akamai-Edgescape
X-Cache-2
X-Platform-Server
X-Instance
X-Webkit-CSP
X-Signature
X-Whom
Eomportal-Instance
X-BCube-Filmed-By
X-Varnish-Hostname
X-LB-Cache
X-Framework
X-Device-Type
X-Page-Id
Cache-Tag
X-App-Environment
X-Handled-By
X-Cache-Rule
Cleartype
DC
X-Srv
Liferay-Portal
X-Request-Guid
X-Generated-By
X-NWS-LOG-UUID
X-AppVersion
X-Activity-Id
X-Ruxit-Js-Agent
X-Az
X-WPE-Loopback-Upstream-Addr
X-Drupal-Cache-Contexts
X-Cache-Action
X-Geo-Segment
Public-Key-Pins-Report-Only
X-App-Server
X-VCache
X-Cache-Server
X-Via-JSL
Source
X-Content-Powered-By
Retry-After
X-Correlation-Id
MS-CV
Accept-Charset
X-TT
X-Wix-Request-Id
X-Seen-By
ViewerVersion
X-App-Version
X-Hostname
Alternate-Protocol
HostName
X-HS-Combine-CSS
X-Amz-Replication-Status
X-Varnish-Grace
X-Geo-Country
X-Varnish-Server
X-WA-Info
Webserver
X-Esi
AR-SID
Server-Node
Upgrade-Insecure-Requests
X-Response-Served-From
X-Cache-NE
X-Tumblr-Pixel-1
X-Tumblr-Pixel-2
Actual-Object-TTL
SRV
X-Locale
X-GeoIP
X-WebKit-CSP-Report-Only
X-Amzn-RequestId
X-Amz-Apigw-Id
X-URL
GEO-INFO
AsisCache
X-RequestSource
X-Jobs
X-Daa-Tunnel
X-Varnish-Hits
X-S
X-FW-Type
X-Edge-Cache-Key
X-Servedby
ServedBy
X-UUID
X-Contextid
X-FW-Static
Payment
X-Edge-Cache
Viewport
X-FW-Serve
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-FW-Server
X-FW-Hash
X-Status
Pagespeed
X-Varnish-IP
X-TX-ID
Cache
X-Adobe-Loc
X-Adobe-Content
X-Cache-TTL-Remaining
X-Vg-Webcache
X-Cacheable-TTL
X-TT-TIMESTAMP
X-Origin-Server
X-Correlation-ID
X-Forwarded-Host
X-Cache-Operation
X-Cache-Age
X-Hyper-Cache
S-Cnection
Datacenter
Server-Info
X-RateLimit-Limit
X-Amz-Server-Side-Encryption
Served-By
X-Sucuri-ID
X-Region
X-Akamai-Request-ID2
X-Mode
Country
CACHE
X-TIME
X-XRDS-LOCATION
X-Real-IP
From-Origin
Access-Control-Allow-Method
X-CLOUD-TRACE-CONTEXT
Healthy
X-Cache-Var-Map
X-Cache-Var
X-JoinUs
Fastcgi-X-Cache-Version
X-Rule
Meta-Geo
X-Site-Version
Fastcgi-X-Cache
X-Path-Route
X-Detected-As
Machine
X-Rendered-As
X-RN-RSRV
X-Proxy
X-Proxied
X-Routing-Service
X-Upgrade-Enabled
X-Ocache
X-Is-Bot
X-Generated
X-Zipkin-Id
X-Content-Type
X-DataStream-Cache-Status
X-Ezoic-Cdn
X-Environment-Context
X-Microcachable
X-L-Path
X-Akamai-Transformed
X-Access
X-Section
Fastcgi-Useragent
DB-Nickname
X-Agile-Age
X-Request-Time
X-Agile
X-Amz-Meta-Surrogate-Control
X-CDN-Cache
X-Agile-Id
X-Hosted-By
X-Grey
X-Format
Now
X-NGENIX-Cache
L5d-Success-Class
X-Cache-Config
X-Cache-Category-Id
TWC-Connection-Speed
TWC-Locale-Group
TWC-Privacy
Property-Id
TWC-GeoIP-LatLong
Cache-Name
OT-Force-Account-Verify
TWC-Device-Class
Webcakes-App-Name
X-Hit
X-TNCMS
X-Tb
X-ServerID
X-PCL
X-Via-Fastly
X-Viewer-Country
X-Labrador-Cache-Channel
X-Human
S-Rt
X-Pc-Key
X-Pc-Hit
X-EIG-Tracking-Id
X-Birta-Served
X-Birta-Cache-Post
Webcakes-Region
X-FC-Vary-Parameters
X-Loop
X-Pc-Appver
X-Origin-Hint
X-OCL
Webcakes-App-Version
TWC-GeoIP-Country
Xserver
X-CCM
X-VG-TLSProxy
X-Cluster-Node
HitType
X-BYPASS-REASON
X-VWS-Id
Accept-Language
X-Xfnlog-Site
X-Web-Node
HitInfo
X-IP
X-RemovedCookies
X-ProcessESI
X-ProxyCache-Status
X-ProxyCache-Key
X-OVcl-Cache
X-OVcl
X-SplitTest
X-LJ-Flow-ID
X-Origin
X-Original-Request
X-Via-CDN
X-AWS-Id
Azure-RegionName
Azure-SlotName
Azure-SiteName
Azure-InstanceId
Azure-Version
X-Proxy-Build
X-Www-Served-By
X-Timing-Wait
X-Upstream-CT
X-Upstream-HT
LB
Selected-FE
Mn-Server-Ip
X-Pubstack
X-ShardId
X-Rocket-Nginx-Bypass
X-ShopId
X-Shopify-Stage
X-Alternate-Cache-Key
X-Sorting-Hat-PodId
PageSpeed
X-Sorting-Hat-ShopId
Cache-Hits
Content-Style-Type
Content-Script-Type
X-App-Name
X-Cdn
X-Cache-Enabled
Origin-Edge-Control
X-Source
X-Guploader-Uploadid
Origin-Cache-Control
X-Twitter-Response-Tags
X-Transaction
X-Connection-Hash
X-TWH-CORRELATION-ID
X-RTag
X-UA
Access-Control-Request-Headers
IBM-Web2-Location
Ms-Operation-Id
X-GRACE
NGB
X-Ms-Blob-Type
X-NodeID
X-Ms-Version
X-Real-Ip
X-Ms-Lease-Status
X-Ms-Request-Id
X-Port
X-Origin-CC
X-Cache-Remote
X-Unique-ID
X-Nginx-Cache
Filters
NtCoent-Length
X-Pc-Date
X-MP-GENERATED-AT
X-Distil-CS
X-NCache
X-NODE
X-HOST
X-Internal-Host
X-Geo
X-Pc-Host
Time
X-Edge-IP
X-Cdn-Forward
X-Tumblr-Pixel-3
We-Hiring
X-APP-VERSION
Mail-Subject
Backend
X-Cache-TTL
X-Proto
X-Varnish-Cacheable
X-Debug-Cache
X-CACHE-KEY
X-Vgn-Hpd-Reason
X-Storage
X-Time-Microsecs
X-UA-Device-Type
X-Webstats-RespID
X-Backend-Name
X-PHP-Backend
X-Ratelimit-Limit
X-Akamai-Request-ID
X-Varnish-Cache-Hits
X-Varnish-Beresp-Grace
X-Sucuri-Cache
Cache-Tags
X-Varnish-Beresp-Status
X-CACHE-GROUP
User-Agent
X-Urbn-Site-Id
Locale
X-EdgeConnect-Cache-Status
X-Urbn-Context-Path
X-Ua
X-Nc
X-Csrf-Token
X-Dc
Fastly-SSL
Warning
X-B3-Spanid
X-Mrs-Cache
X-Mrs-Age
X-PERF
X-ApacheServer
X-Mrs-Cache-Hits
X-Newrelic-Synthetics
X-Mshield-Cache-Status
X-ElasticPress-Search
X-Varnish-Beresp-Ttl
X-Endurance-Cache-Level
X-C
X-Cache-Host
Content-Disposition
X-BB-ID
Fly-Cache
Fly-Request-Id
X-B-Cookie
X-External-Request-Id
X-Backend-Host
Ec-Rule-Version
X-BBXSRF
X-Backend-Url
X-Cache-Bucket
X-Eu-Site
Ajk
X-Died
X-D
Arc-Country
X-Destination
X-Date
BehaviorPad-Version
X-CGP
X-Redis-Cache
X-Developer
X-CF-Lambda-Version
FSS-Cache
Cache-Prefix
X-DPWN-IS-SECURE
X-CF-Lambda-Fn
HA-Geocountry
X-A
VivaBuild
Mobile-Detection-Method
Meta-Geo-Continent
X-A-Ccd
X-A-Dcw
MD5-Digest
X-A-Dam
Viewtype
V-Age
Rendered-Blocks
Server-Host
Rt-Proxy-Cache
SN
TSSecure
Odigeo-Trace-Id
UCS
X-A-Dgt
X-A-Wwc
HA-Geocity
X-F5-Cache
HA-Geolat
HA-Cloudapp
X-Amz-Meta-Cache-Control
X-Application
GMS-Ver
HA-Geolon
HA-Georegion
HA-Urlpath
X-Aed
X-Accel-Expires-Debug
HA-Servedtime
HA-Ipaddr
Ha-Gx-Prefs
HA-Host
FSS-Proxy
X-Fetched-On
X-IN-APIGATEWAY
X-IN-SSL-APIGATEWAY
X-Via-SSL
X-S-Cookie
X-Rojux
X-Rewrite-Enabled
X-Hash
X-VG-WebServer
Resin-Trace
X-IN-WAF
X-Irp-Debug
X-Server-By
X-Org
X-NU-AKA-ACS-Version
X-Server-Time
X-Via-Edge
X-ScT
X-Store
X-PAYTM-SRV-ID
X-SRCache-Key
X-GeoIP-Country-Code
X-Cache-Backend
X-UE-Client-Country
X-Generated-In
X-Trv-Group
X-From
X-Logtrace-Id
X-Region-Sid
Xc-Version
X-G
X-CACHE-AGE
X-Worker
X-VServer
Www
X-Location
X-Sn-Servicetimems
X-NX-Host
RNT-Machine
RNT-Time
X-SIPLIST1
X-ABtesting
Server-ID
Thinkindot-Control
X-Wikidot-Static-Cache
X-Matched-Rule
X-Wikidot-Backend
X-Thinkindot-L3
Thinkindot-CacheControl-Type
X-No-Session
Powered-By
Thinkindot-CacheControl
X-We-Are-Hiring
X-Auto-Login
X-Debug-Cookies
X-Debug-Log
X-Release
X-Request-Start
X-Response-By
X-Core-Value
X-Qloud-Router
X-Rebelmouse-Cache-Control
X-Developers
X-Reboot
X-Trace-Id
X-Epic-Correlation-Id
X-Flog
X-FW-Version
X-Dispatcher-Server
X-Clientip
X-GeoIP-City
X-Key
X-Rebelmouse-Surrogate-Control
X-Owner
X-User
X-UnsetCookies
X-Layer
X-Server-IP
X-S-Maxage
X-Backend-State
X-Cdn-Origin
X-Hello
X-Cache-URL
X-Cache-Id
X-Platform
X-Hl-Ver
X-Var-Ttl
Cache-Key
Fastly-SWR
Fastly-Soc-X-Request-Id
Frame-Options
GW-Server
IsBot
Heartbleed
Fastly-SIE
Countrycode
Apple-News-Services-Handled
AKAMAI
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
X-Dynatrace-Js-Agent
Apple-News-Services-Request-Url
Memcached
Country-Code
Pramga
Release
X-CDN-Forward
Origin
WZWS-RAY
X-Powered-By-ANYU
Section-Io-Cache
Cache-Cookie-Set-Lfrom
Request-EU
Request-Country
X-Up
X-Device-Os
Adler-Geo
Backend-Name
Server-Int
X-Crawler
X-Core-Mission
X-Request-UUID
X-Croise-Owner
X-Returned-From
Cache-Cookie-Set-Idcheck
X-Request-URI
X-CUA
X-RCS-CacheZone
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Node-Id
X-Gannett-Site-Version
X-Nginx-Cache-Key
X-LI-UUID
X-Li-Pop
X-Info
X-LI-Proto
X-Origin-Response-Time
X-P-T
X-Phone
X-Distributor
X-Returned-From-BeforeDispatch
X-Passed-To-PostProcessResponse
X-Fastly-Cache
X-Passed-To
X-Passed-To-BeforeDispatch
X-Passed-To-DLL
X-WebServer
Cache-Cookie-Set-From
X-Returned-From-DLL
Platform
X-Actual-URL
X-VCT
X-Served-From
Pragrma
X-Sentry-ID
X-Varnish-Action
Is-Eu
X-Stale
X-V
X-Variation
Uber-Trace-Id
Kp-EeAlive
Magicmarker
X-Swa-Ws
X-ServiceProvider
Decoy-Debug-Key
X-Bip
Decoy-Debug-Status
Decoy-Debug-TTL
X-Cache-Expires
X-Cache-Debug
X-Returned-From-PostProcessResponse
Fastly-Backend-Name
X-Thanos
Esi-Enabled
X-Secret
X-Li-Fabric
X-NC
User-Cache-Control
X-Datadome
X-Hnp-Log
X-MI-In-Market
X-MSEdge-Flight
MI-Cache
X-MSEdge-Features
Web-Mar-Node
X-Instance-Name
REQUESTUUID
MI-Cache-Age
X-SN
X-Via-NSCOPI
X-Policy
X-Sf
X-Backend-TTL
X-Fstrz
X-SVT-ORM-VERSION
True-Client-Country-4JS
X-Block-Status
X-Gen-Mode
X-MServer
X-SVT-ORM-RULES
On-Server
X-TT-LOGID
X-Cache-CFC
Version
Pagetype
X-Oss-Storage-Class
X-Oss-Request-Id
HTTPS
Proxy-Connection
CDCHOST
X-Oss-Hash-Crc64ecma
X-NWS-UUID-VERIFY
X-Oss-Server-Time
X-Refresh
X-Oss-Object-Type
X-Cache-Srv
X-DC
RequestId
Amp-Access-Control-Allow-Source-Origin
MI-API
X-Page-Type
X-Req
X-Be
X-Kong-Proxy-Latency
X-Pjax-Url
NodeID
X-Ms-Lease-State
X-Cache-FS-Status
Cteonnt-Length
X-Kong-Upstream-Latency
X-Parent-Response-Time
X-Servername
Group
V-Cache
MIME-Version
ProcessTime
X-GZip
X-Origin-TTL
X-Unique-Id-Primal
Who
Cdn
X-Oracle-Dms-Ecid
X-BB-IP
Fusion-Source
Memory
Mime-Version
Fusion-Content-Source
X-Ckpd-Fst-Backend
Fusion-Component-Id
Fusion-Template-Id
Fusion-Content-Id
SS
CF-IPCountry
X-Servedbyhost
X-ND-Cache
X-Protected-By
X-Time
X-Aicache-OS
X-Edge-Server
X-Server-Group
Cdn-Request-Time
X-COUNTRY
Cdn-Host
X-Content-Age
X-Wa
GeoIP-Country-Code
SD-X-WS
PageType
X-Varnish-Url
GeoIP-Latitude
CDN
X-SRV
X-Varnish-Beresp-TTL
Is-Session-Tracking
A
X-Ratelimit-Remaining
Get-Access-Time
X-APP
X-Unique-Id
XServer
X-Origin-Date
Geoip-Latitude
X-WA
X-B3-Traceid
X-Origin-Expires
X-Pf-Uncompressing
GeoIp-Country-Code
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Generation-Time
X-Fastly-Cache-Hits
X-CSRF-Token
X-FireWall-Port
X-StackifyID
Serverid
PICS-Label
X-Cache-Info
X-GEO
X-Vcache
X-Nananana
X-Gdpr
X-Origin-Host
X-Fastly-Country-Code
X-Requestid
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-CS
X-EC-Security-Audit
Processtime
Nel
X-Load-Cache
X-ServedByHost
X-PHP-Host
Cf-Ipcountry
Node
X-ID
X-Proxy-Cache-Status
X-Server-W
T-Server
X-SERVER-NAME
NGX
X-Surge-Debug
DataCenter
X-Proxy-Upstream
X-RequestId
X-M-Reqid
X-Qnm-Cache
X-M-Log
X-Check-Cacheable
Vix-Hermes-Req-Id
URI
X-HTML-Minification-Powered-By
Hostname
X-FORWARDED-FOR
X-PF-Uncompressing
X-Feature
X-NGINX-Cache
Load-Balancing
X-UPSTREAM-Address
Cache-Tv-Group
X-GZIP
X-HS-Status
ServerName
WP-Super-Cache
X-Planisys-CDN-TTL
Cache-Provider
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-WR-MODIFICATION
X-B3-SpanId
X-BACKEND-TTL
X-BE
X-Alicdn-Da-Ups-Status
X-ARC
X-ServerName
X-VG-WebCache
X-Fastly-Backend-Reqs
X-Skip-Cache
X-DataStream-Origin-MEX-Latency
X-Fe
Request-Time
X-DataStream-MidMile-RTT
X-Atg-Version
PFcat
Host-ID
X-Micro-Cache
X-PAGE-TYPE
RequestUuid
X-Proxy-Server
Https
X-HTML-Edge-Cache
X-IPS-LoggedIn
Requestid
X-PJAX-URL
X-Akamai-SSL-Client-Sid
N-Cache
X-VC
X-SB
X-Amz-Meta-S3b-Last-Modified
X-Distil-Cs
X-From-Cache
X-Cache-Ttl
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Debug-Cache-Expiry
Sid
X-GDPR
X-Gen-Id
Cdn-Src-Port
Build-Number
X-CSRF-TOKEN
X-Dw-Trace-Id
X-RAMCache
X-Grace-Duration