Threat Level: green Handler on Duty: Russell Eubanks

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Pragma
Last-Modified
Accept-Ranges
Strict-Transport-Security
X-Content-Type-Options
X-Powered-By
CF-RAY
ETag
Link
Expect-CT
Via
X-XSS-Protection
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-UA-Compatible
P3P
X-Cache-Hits
X-Served-By
X-Varnish
X-Amz-Cf-Id
X-Xss-Protection
Referrer-Policy
X-Request-Id
X-Timer
X-AspNet-Version
CF-Cache-Status
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Runtime
Access-Control-Allow-Credentials
X-Download-Options
X-Drupal-Cache
X-Cacheable
Content-Security-Policy-Report-Only
X-Generator
Alt-Svc
Status
X-AspNetMvc-Version
X-Cache-Status
X-DNS-Prefetch-Control
X-Check
P3p
X-Iinfo
X-Adblock-Key
X-FRAME-OPTIONS
X-CDN
Timing-Allow-Origin
X-Content-Security-Policy
X-Permitted-Cross-Domain-Policies
X-Turbo-Charged-By
Content-Encoding
X-Template
X-Language
Keep-Alive
X-Type
X-AH-Environment
X-Via
X-Cache-Group
X-Backend
X-Request-ID
WPE-Backend
X-Pass-Why
X-Buckets
X-Age
X-Server
X-Nginx-Cache-Status
Access-Control-Max-Age
X-Server-Powered-By
X-Pingback
Xkey
X-Varnish-Cache
Grace
X-Drupal-Dynamic-Cache
Upgrade
Access-Control-Expose-Headers
X-Hacker
X-UA-Device
X-Amz-Request-Id
Cf-Railgun
X-Page-Speed
X-Amz-Id-2
X-Proxy-Cache
X-Robots-Tag
X-Ua-Compatible
EagleId
X-Envoy-Upstream-Service-Time
Request-Context
X-Node
X-LiteSpeed-Cache
X-Swift-SaveTime
X-Swift-CacheTime
X-Ac
X-Device
Ali-Swift-Global-Savetime
X-Host
X-Cnection
Content-Location
X-Amz-Version-Id
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-WebKit-CSP
X-Server-Id
Surrogate-Control
X-Backend-Server
X-Cache-Lookup
X-Rack-Cache
X-OneAgent-JS-Injection
X-Response-Time
X-Px
X-Instart-Request-ID
X-CST
Request-Id
Server-Timing
X-Readtime
X-Rq
X-Clacks-Overhead
Pinterest-Generated-By
X-Url
Permitted-Cross-Domain-Policies
X-HeyJason
X-Do-Not-Hack
EagleEye-TraceId
Edge-Control
X-Application-Context
X-Country
X-Cloud-Trace-Context
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-MS-InvokeApp
Report-To
X-Server-Name
Charset
X-DynaTrace-JS-Agent
X-ESI
SPRequestGuid
X-Country-Code
Allow
X-DataDome
X-SharePointHealthScore
Rating
X-Varnish-TTL
X-PC
X-Vname
X-TtlSet
X-Cached
X-Ruxit-JS-Agent
X-Powered-CMS
X-Powered-By-Plesk
X-Recruiting
X-DynaTrace
X-CF-Powered-By
X-FTR-Request-ID
X-Vhost
NEL
X-D2id
X-ORACLE-DMS-RID
X-ORACLE-DMS-ECID
X-Exp-Variant
X-Exp-Id
X-Geo-Segment
X-Kinja-Build
X-Kinja
X-Kinja-Server
X-Cdn-Fetch
X-Kinja-Revision
Public-Key-Pins
Pinterest-Version
X-Pinterest-Rid
X-F-Cache
X-Upstream-Env
X-TTL
X-Version
X-T
Cartoon
X-GoogleNews-Bot
X-VARITI-CCR
SPIisLatency
X-Dw-Request-Base-Id
SPRequestDuration
X-N
X-Mod-Pagespeed
X-Ttl
X-Abt-Application-Version
RTSS
Content-MD5
Feature-Policy
MS-Author-Via
Verso
Nginx-Cache
X-GitHub-Request-Id
X-Dispatcher
X-Goog-Hash
X-Navigation-Version
X-Client-IP
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Amz-Rid
MicrosoftSharePointTeamServices
X-Forwarded-Proto
Realpath
X-Hits
AR-PoweredBy
AR-CACHE
X-Shield-Request-Id
AR-ATIME
X-Origin-Cache
X-Cdn
X-Trace
Paypal-Debug-Id
DynaTrace
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Content-Options
X-Id
X-Zen-Fury
X-Content-Digest
X-Server-ID
X-Kinsta-Cache
TCN
X-B
X-Grace
Arr-Disable-Session-Affinity
Alternate-Protocol
X-Varnish-Age
AR-SID
X-Cache-Key
X-Sol
Fastcgi-Cache
X-Upstream
Mrf-Cache-Status
MRF-Tech
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
X-Acc-Meta-Resource-Type
Access-Control-Request-Method
X-Pad
X-Ser
PB-PID
X-Mobile-Rewrite
PB-RID
Display
X-Middleton-Display
X-Fastly-Request-ID
X-FastCGI-Cache
X-NF-Request-ID
X-Nf-Srv-Version
X-Via-JSL
X-DIS-Request-ID
X-User-Agent
X-Middleton-Response
X-Vcap-Request-Id
Response
Pagespeed
X-Forwarded-For
X-MSEdge-Ref
Eomportal-Instance
Arc-Version
X-PressLabs-Stats
Rt-Fastcgi-Cache
X-Frontend
Front-End-Https
X-Cache-Rule
X-Cache-Hit
X-SS-Set-Cookie
X-Logged-In
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Metageneration
X-Goog-Generation
X-IPLB-Instance
Server-Name
X-Whom
Host
X-Hostname
S
X-VCache
Surrogate-Key
Tracecode
X-Country-Code-Real
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Realm
X-FTR-DC
X-FTR-Expires
X-FTR-Balancer
X-FTR-Cache-Status
X-XRDS-LOCATION
X-Request-Received
X-Request-Processing-Time
X-Analytics
Backend-Timing
Cache-Status
X-HS-Content-Id
X-Debug
X-Instance
X-Magnolia-Registration
TP-L2-Cache
TP-Cache
X-AOL-HN
X-XRDS-Location
X-Contextid
X-Rid
X-HW
FilterID
X-Az
X-AppVersion
X-Proxied
X-Litespeed-Cache
Refresh
ServerID
X-Activity-Id
X-Srv
Public-Key-Pins-Report-Only
X-Wix-Server-Artifact-Id
HitInfo
Cleartype
HitType
Server-Info
X-UUID
X-B3-Traceid
X-WPE-Loopback-Upstream-Addr
AMP-Access-Control-Allow-Source-Origin
X-FTR-Cache-Host
X-Content-Security-Policy-Report-Only
X-Varnish-Backend
X-APP-VERSION
X-Mobile
X-Varnish-Server
Liferay-Portal
Service-Worker-Allowed
X-Origin-Upstream-Status
Served-By
Accept-Charset
X-Cache-Control
X-Revision
Source
X-Amzn-Trace-Id
X-TT
X-App-Environment
X-Newrelic-App-Data
X-Correlation-Id
Server-Node
X-BCube-Filmed-By
X-Hail-Hydra
X-Tumblr-User
Host-Header
Retry-After
X-Tumblr-Pixel-0
X-Handled-By
X-Request-Guid
X-Cache-Server
X-Geo-Country
X-Framework
X-Device-Type
X-Page-Id
MS-CV
X-PC-Hit
X-PC-Key
X-Tumblr-Pixel
X-PC-AppVer
X-PHP-Backend
X-Varnish-Hostname
DC
X-B-Cache
X-Cache-Config
X-Signature
X-Cache-Operation
X-RateLimit-Remaining
X-FB-Debug
X-Cache-2
Powered-By-ChinaCache
X-Origin-Server
X-ATG-Version
X-Origin
Viewport
S-Cnection
X-NWS-LOG-UUID
Edge-Cache-Tag
X-HS-Cache-Config
X-NewRelic-App-Data
X-Cache-Action
X-URL
X-TT-TIMESTAMP
X-Debug-Info
X-Ocache
Fastly-Restarts
X-PC-Date
X-Sucuri-ID
X-PC-Host
X-Cached-By
X-Hyper-Cache
X-Webkit-Csp
X-WA-Info
X-B3-Sampled
Actual-Object-TTL
NGB
X-LB-Cache
X-Akam-SW-Version
X-Content-Powered-By
X-Drupal-Cache-Tags
X-Oneagent-Js-Injection
X-Microcachable
X-ADI-VCache
X-Shield-Cache-Expires
X-Accel-Expires
Upgrade-Insecure-Requests
X-Generated-By
X-Cache-NE
SRV
Filters
AsisCache
X-App-Server
X-Distil-CS
X-WebKit-CSP-Report-Only
ServedBy
X-FW-Type
X-FW-Static
X-RequestSource
X-Tumblr-Pixel-1
X-FW-Hash
X-Tumblr-Pixel-2
X-FW-Serve
X-RTag
X-FW-Server
X-Cluster
X-Yottaa-Metrics
Content-Style-Type
X-Locale
X-GeoIP
Content-Script-Type
X-Internal-Host
X-Cacheable-TTL
X-Yottaa-Optimizations
X-Seen-By
X-Wix-Request-Id
X-S
X-Jobs
X-Node-Name
X-Geo
X-Varnish-Hits
X-Accel-Buffering
X-Amz-Server-Side-Encryption
X-Cache-Age
Cache
X-ServedBy
X-TX-ID
Datacenter
From-Origin
X-Varnish-Grace
X-GUploader-UploadID
X-Varnish-Cache-Hits
X-RateLimit-Limit
X-Adobe-Loc
X-Adobe-Content
X-Akamai-Edgescape
X-Platform-Server
X-Vg-Webcache
X-Varnish-IP
X-GZip
X-UA
X-Dns-Prefetch-Control
X-Sucuri-Cache
X-Cache-TTL-Remaining
X-CLOUD-TRACE-CONTEXT
X-Real-IP
X-HS-Combine-CSS
Cache-Tag
X-CDN-Forward
X-Edge-Cache
X-Edge-Cache-Key
X-Storage
X-Akamai-Transformed
X-Drupal-Cache-Contexts
X-Mode
X-Cache-Remote
X-Region
X-Source
X-Distributor
X-Amz-Replication-Status
X-Amzn-RequestId
X-ProcessESI
X-Path-Route
X-RemovedCookies
X-Rendered-As
X-RN-RSRV
X-MP-GENERATED-AT
X-Is-Bot
X-Amz-Apigw-Id
Load-Balancing
Machine
X-Detected-As
X-Proxy
Meta-Geo
Ohc-File-Size
ServerName
Fastly-SSL
X-PERF
X-Agile
X-Kinja-Server-Push
X-Guploader-Uploadid
X-Time-Microsecs
Cache-Key
X-Agile-Id
X-CDN-Cache
X-BB-IP
X-ApacheServer
X-Akamai-Request-ID
GEO-INFO
HostName
X-Agile-Age
Mn-Server-Ip
X-TWH-CORRELATION-ID
X-Upgrade-Enabled
X-Grey
Backend
X-Daa-Tunnel
X-NodeID
X-FC-Vary-Parameters
X-Amz-Meta-Surrogate-Control
X-Backend-Name
X-Cache-Var-Map
X-Cache-Var
X-Cache-Category-Id
X-Proto
S-Rt
Azure-RegionName
X-Cluster-Node
X-EIG-Tracking-Id
Azure-InstanceId
X-ServerID
X-Viewer-Country
X-Pubstack
X-Webstats-RespID
Azure-Version
X-Original-Request
Azure-SlotName
X-Varnish-Cacheable
Azure-SiteName
Webcakes-App-Version
Webcakes-App-Name
X-AWS-Id
X-Birta-Cache-Post
TWC-Privacy
X-App-Name
TWC-GeoIP-LatLong
TWC-Connection-Speed
TWC-Device-Class
X-Birta-Served
TWC-Locale-Group
X-Access
Selected-FE
TWC-GeoIP-Country
Webcakes-Region
X-Format
X-Section
X-SplitTest
X-Timing-Wait
X-Routing-Service
X-ProxyCache-Status
X-Proxy-Build
X-ProxyCache-Key
X-Via-Fastly
X-VWS-Id
Healthy
X-Hosted-By
X-JoinUs
Access-Control-Allow-Method
X-Zipkin-Id
X-Web-Node
X-Www-Served-By
X-Port
X-PCL
Property-Id
X-Generation-Time
X-IP
X-Edge-Location
X-Debug-Cache
X-Cache-HT
X-CCM-LastModified
X-LJ-Flow-ID
X-Meta-Tbi-Cache-Vertical
X-OVcl
X-OVcl-Cache
X-Origin-Hint
X-Optimization
X-NCache
X-OCL
X-BYPASS-REASON
X-Human
L5d-Success-Class
Countrycode
Cache-Name
Now
LB
DB-Nickname
User-Agent
Fastcgi-Useragent
X-Instance-Name
X-TNCMS
X-Loop
X-Site-Version
X-Labrador-Cache-Channel
X-Dc
User-Cache-Control
Country
X-CCM
X-Xfnlog-Site
Payment
X-Generated
Cache-Hits
X-Tb
Ec-Rule-Version
X-Tumblr-Pixel-3
RATING
X-Origin-CC
X-DataStream-Cache-Status
X-Request-Time
X-Surge-Debug
X-Newrelic-Synthetics
X-Ezoic-Cdn
X-Time
X-Unique-ID
X-Hit
X-Cache-Bucket
WP-Super-Cache
X-TA-CDN-Provider
X-Nc
X-B3-TraceId
X-Oracle-Dms-Ecid
X-Oracle-Dms-Rid
X-Cache-Enabled
X-B3-Spanid
X-Nginx-Cache
X-Real-Ip
X-Feature
X-Render-Type
Origin-Edge-Control
Origin-Cache-Control
X-UA-Device-Type
X-Correlation-ID
RequestId
X-L-Path
X-Environment-Context
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-Ruxit-Js-Agent
X-NU-AKA-ACS-Version
NODE
Xserver
X-Skip-Cache
X-Esi
X-Status
X-HS-Hub-Id
X-Content-Type
X-NGENIX-Cache
Apicache-Version
X-EdgeConnect-Cache-Status
Apicache-Store
Access-Control-Request-Headers
X-Be
X-Servedby
Ws
X-ElasticPress-Search
X-WR-MODIFICATION
X-CACHE-AGE
X-Cache-Backend
Warning
X-Vgn-Hpd-Reason
IBM-Web2-Location
Time
X-BBXSRF
X-CF-Lambda-Version
X-IN-APIGATEWAY
X-Connection-Hash
X-CF-Lambda-Fn
X-A-Wwc
Resin-Trace
BehaviorPad-Version
Cache-Prefix
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
Apple-News-Services-Host
Meta-Geo-Continent
Memcached
Fly-Cache
Fastly-Soc-X-Request-Id
Fastcgi-X-Cache
Fly-Request-Id
GMS-Ver
MD5-Digest
Host-ID
AKAMAI
Ajk
X-D
X-A-Dgt
X-A-Dcw
X-Accel-Expires-Debug
X-Application
X-B-Cookie
X-ARC
X-A-Dam
X-A-Ccd
T-Server
Sta2Tusw
Viewtype
VivaBuild
X-A
Www
X-BB-ID
X-Via-Edge
X-SVT-ORM-RULES
X-Date
X-From
X-G
X-SVT-ORM-VERSION
X-Transaction
X-Developer
X-Region-Sid
X-Twitter-Response-Tags
X-Trv-Group
X-SRCache-Key
X-Haproxy-Hostname
X-Server-Time
X-Server-By
X-No-Session
Fastcgi-X-Cache-Version
X-S-Cookie
X-Rojux
X-ND-Cache
X-Generated-In
X-Rewrite-Enabled
X-Haproxy-Ip
X-Died
X-PAYTM-SRV-ID
X-IN-WAF
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
X-Via-CDN
X-VG-WebServer
X-Planisys-CDN-Rules
X-IN-SSL-APIGATEWAY
X-User
Xc-Version
X-Fastcgi-Cache
X-Logtrace-Id
X-Wix-Route-ID
X-We-Are-Hiring
X-Public
X-Destination
Webserver
X-GoCache-CacheStatus
NGX
Fastly-SIE
IsBot
X-NX-Host
X-Rebelmouse-Cache-Control
X-Phone
Server-Int
Request-Time
Rendered-Blocks
Release
Fastly-SWR
X-Rebelmouse-Surrogate-Control
X-Forwarded-Host
X-Cdn-Origin
X-Hl-Ver
X-Upstream-HT
X-Cache-Host
X-Var-Ttl
X-Core-Value
X-Debug-Cookies
X-Via-NSCOPI
X-Debug-Log
X-CS
X-Cache-Expires
X-Upstream-CT
X-SIPLIST1
V-Age
UCS
Uber-Trace-Id
X-Sn-Servicetimems
X-Fastly-Cache
X-Up
X-Auto-Login
X-Trace-Id
X-F5-Cache
X-ScT
Origin
X-Cache-Ttl
X-C
X-Webkit-CSP
X-Croise-Owner
X-Servername
X-DPWN-IS-SECURE
Thinkindot-Control
X-Developers
X-Stale
X-ServiceProvider
OT-Force-Account-Verify
Who
Thinkindot-CacheControl-Type
X-UE-Client-Country
Cache-Cookie-Set-From
X-Server-IP
Cache-Cookie-Set-Idcheck
Proxy-Connection
X-Cache-Id
X-Eu-Site
Backend-Name
X-Crawler
X-Edge-IP
X-Epic-Correlation-Id
Server-Host
Thinkindot-CacheControl
X-Clientip
X-Bip
X-UnsetCookies
X-TT-LOGID
X-Cdn-Srv
X-Backend-Url
X-Bug-Bounty
X-Cache-CFC
X-V
X-Varnish-HitMiss
X-Cache-Debug
X-Cache-Control-Set-By
X-Backend-TTL
X-Backend-State
X-Thanos
X-Amz-Meta-Cache-Control
X-Actual-URL
X-CGP
X-Amz-Meta-S3cmd-Attrs
X-Wikidot-Static-Cache
X-Backend-Host
X-Passed-To-BeforeDispatch
X-Thinkindot-L3
X-Wikidot-Backend
Pramga
X-FireWall-Port
Content-Disposition
X-MI-In-Market
Heartbleed
Decoy-Debug-Key
X-Matched-Rule
X-Node-Id
Decoy-Debug-Status
X-Location
X-Platform
HTTPS
HA-Urlpath
HA-Servedtime
HA-Geolat
HA-Geocountry
HA-Geocity
HA-Cloudapp
HA-Geolon
HA-Georegion
HA-Ipaddr
HA-Host
Ha-Gx-Prefs
X-Reboot
Decoy-Debug-TTL
Odigeo-Trace-Id
X-GeoIP-Country-Code
Cache-Cookie-Set-Lfrom
MI-Cache-Age
Ohc-Response-Time
On-Server
Powered-By
X-Frame-Option
X-Fstrz
X-GeoIP-City
X-Passed-To
MI-Cache
X-Passed-To-DLL
X-Passed-To-PostProcessResponse
X-Returned-From
X-Request-URI
X-Returned-From-BeforeDispatch
X-Returned-From-DLL
X-HCF
X-Rocket-Nginx-Bypass
X-Returned-From-PostProcessResponse
GW-Server
Cneonction
X-Dispatcher-Server
X-Device-Os
X-Info
X-Env
X-Cache-Time
X-RCS-CacheZone
X-Server-Group
Fastly-Backend-Name
X-Content-Age
X-MSEdge-Features
X-MSEdge-Flight
X-Ckpd-Fst-Backend
X-VServer
X-Release
X-Response-By
X-Hash
X-Fetched-On
X-Core-Mission
Adler-Geo
X-Ver
Is-Eu
CDCHOST
Platform
REQUESTUUID
X-Cache-Srv
Pragrma
PFcat
Esi-Enabled
X-Worker
X-WebServer
Country-Code
Mime-Version
NnCoection
MI-API
X-Served-From
X-Shopify-Stage
X-Origin-Date
Server-ID
X-Sorting-Hat-FeatureSet
X-Gen-Mode
X-Alternate-Cache-Key
X-Origin-Expires
X-ShopId
Kp-EeAlive
X-Varnish-Beresp-Ttl
X-ShardId
X-S-Maxage
X-Varnish-Id
X-Block-Status
X-Hnp-Log
X-Sorting-Hat-PodId
X-Sorting-Hat-Section
X-Sorting-Hat-PrivacyLevel
Web-Mar-Node
X-Sorting-Hat-ShopId
X-Sorting-Hat-ShopId-Cached
X-Cache-URL
X-TIME
Request-Country
X-Refresh
Request-EU
Httpd-Identifier
X-Sorting-Hat-PodId-Cached
Dnion-Transfer-Encoding
X-Page-Type
X-Req
X-Pjax-Url
X-Svr
NtCoent-Length
X-P-T
Cache-Provider
X-App-Version
X-Gannett-Site-Version
Processtime
X-Secret
X-StackifyID
X-Cache-ASPX
Drupal-Pagecache-Memcache
X-Origin-TTL
Version
X-EC-Security-Audit
X-Pf-Uncompressing
X-Amz-Meta-S3b-Last-Modified
X-Csrf-Token
X-Oss-Object-Type
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
X-Oss-Request-Id
Ar-Sid
X-Amz-Meta-Sha256
X-Wix-Petri-Ex
Accept-Ch
Memory
Pagetype
SN
Dont-Set-Cookie
WebServer
X-Varnish-Url
X-Ua
X-LiteSpeed-Cache-Control
X-NC
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-From-Cache
X-GRACE
X-CSRF-Token
Geoip-Latitude
Geoip-City
GeoIp-Country-Code
X-Rule
Arc-Country
Cteonnt-Length
FSS-Proxy
X-Yottaa-Sig
FSS-Cache
X-Cache-Handler
PageType
X-Varnish-Beresp-TTL
X-Irp-Debug
Brightspot-Id
PICS-Label
Cdn
X-Load-Cache
X-LB-CacheStatus
X-Cdn-Forward
X-Request-Start
X-LB-Node
CF-IPCountry
X-Ratelimit-Remaining
If-Modified-Since
COMMERCE-SERVER-SOFTWARE
X-Redis-Cache
Sid
MIME-Version
X-ROOTCache
Edgecast
X-COUNTRY
X-SERVER-NAME
X-Sf
PROCESSING-IP
X-Fastly-Backend-Reqs
X-Request-UUID
BORDER-IP
X-DC
RNT-Time
X-Tid
RNT-Machine
X-Endurance-Cache-Level
X-Requestid
X-GDPR
X-Ratelimit-Limit
XServer
X-Varnish-Action
X-Servedbyhost
X-ServedByHost
X-TId
X-B3-SpanId
X-RequestId
X-Layer
X-Nananana
X-Rocket-Nginx-Serving-Static
Cache-Tags
X-Resolver-IP
X-BE
Powered
Cf-Ipcountry
Frame-Options
Pics-Label
X-Cache-TTL
X-DataStream-Origin-MEX-Latency
X-DataStream-MidMile-RTT
Amp-Access-Control-Allow-Source-Origin
NodeID
Node
X-Fastly-Cache-Hits
CACHE
X-Atg-Version
CDN
X-Tec-Api-Root
X-Tec-Api-Origin
X-Tec-Api-Version
X-UPSTREAM-Address
X-Key
GeoIP-City
GeoIP-Latitude
X-Gdpr
X-Owner
GeoIP-Country-Code
Mail-Subject
We-Hiring
PageSpeed
X-Varnish-URL
X-Shard
X-VG-WebCache
Hostname
X-Server-W
X-Dynatrace-Js-Agent
X-Varnish-Ttl
X-HTML-Minification-Powered-By
X-Use-Magma
X-Dynatrace
X-Alicdn-Da-Ups-Status
Lfy
X-Ms-Lease-Status
X-Aicache-OS
X-Ms-Blob-Type
Accept-CH
X-Sentry-ID
X-Ms-Request-Id
X-Ms-Version
Web-Mar-Region
X-GZIP
ProcessTime
X-Flog
X-VG-TLSProxy
X-PF-Uncompressing
X-ABtesting
WZWS-RAY
Dynatrace
URI
Cdn-Request-Time
X-Powered-By-ANYU
X-GEO
X-Edge-Server
True-Client-Country-4JS
Cdn-Host
X-Swa-Ws
X-NGINX-Cache
X-Dw-Trace-Id
Xet-Cookie
DataCenter
Rt-Proxy-Cache
X-Org
X-Policy
X-Ms-Lease-State
X-Front
X-PJAX-URL
GEO-REGION-INFO
Group
X-PAGE-TYPE
Max-Age
X-Oa-Upstreams
X-NWS-UUID-VERIFY
V-Cache
Get-Access-Time
Is-Session-Tracking
X-Check-Cacheable
X-Cookie
X-CDN-Pop
X-Vcache
X-CDN-Pop-IP
X-Unique-Id
N-Cache
X-Mem
X-M-Log
X-Trv-Request-Id
Requestid
X-Varnish-Info
X-M-Reqid
X-VC
RequestUuid
X-SB
X-Qnm-Cache
X-Varnish-ID
X-External-Request-Id
X-Response-Served-From
X-VID
X-Amzn-Remapped-Date
X-Powered-By-Defense
X-RSL
X-Remote-IP
X-Amzn-Remapped-Connection
X-DI
X-RAMCache
X-Acquia-Application-UUID
WS
X-Akamai-ERPolicy
X-Akamai-ERRuleID
CF-Cached-On
X-Hello
SID
X-Acquia-Application-Trace
X-Fe
X-DSS
X-DW
X-RPM
X-Litespeed-Tag
X-DB
X-Proxy-Server
X-Litespeed-Cache-Control
X-Cache-FS-Status
X-RPS