Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
Last-Modified
X-Content-Type-Options
Accept-Ranges
Pragma
X-Powered-By
CF-RAY
Link
ETag
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Id
X-Served-By
Referrer-Policy
X-Varnish
X-Request-Id
X-Timer
CF-Cache-Status
X-AspNet-Version
Access-Control-Allow-Headers
X-Xss-Protection
Access-Control-Allow-Methods
X-Runtime
X-Download-Options
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Cacheable
Alt-Svc
X-Check
X-Generator
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Cache-Status
X-AspNetMvc-Version
Status
X-DNS-Prefetch-Control
X-Template
X-Language
Timing-Allow-Origin
X-Permitted-Cross-Domain-Policies
X-FRAME-OPTIONS
Content-Encoding
X-Iinfo
X-Content-Security-Policy
X-CDN
X-Buckets
X-Turbo-Charged-By
X-Request-ID
Upgrade
X-Type
WPE-Backend
Keep-Alive
X-Pass-Why
CF-Ray
X-Cache-Group
X-AH-Environment
Xkey
P3p
X-Backend
Access-Control-Max-Age
X-Age
Access-Control-Expose-Headers
X-Via
X-Drupal-Dynamic-Cache
EagleId
X-Pingback
X-Nginx-Cache-Status
X-Amz-Id-2
X-Amz-Request-Id
X-Kinja-Server-Push
X-Server-Powered-By
X-Server
X-Hacker
Grace
X-UA-Device
X-Swift-CacheTime
X-Swift-SaveTime
X-Varnish-Cache
X-Robots-Tag
Ali-Swift-Global-Savetime
Cf-Railgun
X-Proxy-Cache
X-Envoy-Upstream-Service-Time
X-LiteSpeed-Cache
X-Page-Speed
X-Ua-Compatible
Request-Context
X-Device
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Ac
Content-Location
X-Cache-Lookup
X-Amz-Version-Id
X-WebKit-CSP
X-Response-Time
Surrogate-Control
X-Host
X-OneAgent-JS-Injection
X-Rq
X-Cnection
X-Node
Server-Timing
X-Backend-Server
X-Server-Id
X-Readtime
Report-To
X-Rack-Cache
Request-Id
EagleEye-TraceId
X-Application-Context
Feature-Policy
X-Cloud-Trace-Context
X-ORACLE-DMS-ECID
X-Instart-Request-ID
X-CST
X-Iejgwucgyu
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Edge-Control
X-Clacks-Overhead
NEL
X-TTL
Rating
X-Country
X-Server-Name
X-DynaTrace
X-Varnish-TTL
X-MS-InvokeApp
X-DataDome
Allow
X-Px
X-Country-Code
X-Origin-Cache
Pinterest-Generated-By
X-Url
X-Vhost
X-PC
X-TtlSet
X-Vname
X-Cached
X-FTR-Request-ID
X-Ruxit-JS-Agent
RTSS
X-ESI
SPRequestGuid
X-Trace
X-Goog-Hash
X-VARITI-CCR
Charset
X-SharePointHealthScore
X-Powered-By-Plesk
Accept-CH
X-T
X-DynaTrace-JS-Agent
X-GitHub-Request-Id
X-Dispatcher
X-Server-ID
X-Powered-CMS
X-B3-TraceId
X-Mod-Pagespeed
Public-Key-Pins
X-D2id
PB-PID
Arc-Version
PB-RID
X-Mobile-Rewrite
X-F-Cache
X-Cdn-Fetch
X-Kinja-Revision
X-Kinja-Server
X-Kinja
X-Kinja-Build
X-GoogleNews-Bot
X-Exp-Id
X-Exp-Variant
Verso
Content-MD5
SPIisLatency
SPRequestDuration
X-Version
X-Shield-Request-Id
MS-Author-Via
X-Dns-Prefetch-Control
X-Recruiting
X-Oracle-Dms-Rid
X-Abt-Application-Version
X-ORACLE-DMS-RID
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
Nginx-Cache
X-Forwarded-Proto
Accept-CH-Lifetime
X-Client-IP
X-HW
X-DIS-Request-ID
X-N
X-Navigation-Version
Pinterest-Version
X-Pinterest-Rid
X-Upstream-Env
AR-CACHE
AR-PoweredBy
AR-ATIME
X-B
X-Amz-Rid
DynaTrace
X-Fastly-Request-ID
X-Origin-Upstream-Status
X-Upstream
X-Ser
X-Dw-Request-Base-Id
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Amz-Meta-S3cmd-Attrs
X-Hits
Realpath
TCN
Fastly-Restarts
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Wix-Server-Artifact-Id
X-XRDS-Location
X-Accel-Buffering
Paypal-Debug-Id
X-Content-Options
Arr-Disable-Session-Affinity
X-NF-Request-ID
Service-Worker-Allowed
X-Pad
X-Acc-Meta-Resource-Type
X-Goog-Storage-Class
S
Tracecode
Access-Control-Request-Method
X-Use-Magma
X-Content-Digest
X-Id
X-Debug
X-Varnish-Age
Edge-Cache-Tag
X-Oneagent-Js-Injection
X-Vcap-Request-Id
Front-End-Https
X-MSEdge-Ref
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
MRF-Tech
Mrf-Cache-Status
X-ATG-Version
X-Frontend
X-IPLB-Instance
X-PressLabs-Stats
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Cache-Status
X-RateLimit-Remaining
X-FTR-Realm
X-FTR-Balancer
X-FTR-DC
X-Country-Code-Real
X-FTR-Expires
X-Kinsta-Cache
MicrosoftSharePointTeamServices
X-Logged-In
X-B3-TraceId-Primal
X-HS-Content-Id
X-HS-Hub-Id
Rt-Fastcgi-Cache
Surrogate-Key
X-Forwarded-For
X-Request-Processing-Time
X-Cache-Hit
X-Request-Received
Fastcgi-Cache
X-Amz-Cf-Pop
X-Webkit-CSP
X-FastCGI-Cache
X-Middleton-Display
Display
X-Sol
X-Zen-Fury
X-Edge-Location
Backend-Timing
X-Litespeed-Cache
AMP-Access-Control-Allow-Source-Origin
X-Analytics
Powered-By-ChinaCache
X-Debug-Info
X-Rid
X-Amzn-Trace-Id
X-HS-Cache-Config
Server-Name
Host
X-User-Agent
X-Revision
TP-L2-Cache
TP-Cache
X-FTR-Cache-Host
X-Newrelic-App-Data
X-Cache-Key
FilterID
Ar-Sid
X-Akam-SW-Version
X-CF-Powered-By
X-Middleton-Response
Response
AR-Request-ID
X-TA-CDN-Provider
X-URL
X-Drupal-Cache-Tags
X-Grace
X-Magnolia-Registration
X-SS-Set-Cookie
X-Mobile
X-SERVER
X-Fastcgi-Cache
Refresh
Cache-Status
X-VCache
X-GUploader-UploadID
X-B3-Sampled
X-Cached-By
X-Accel-Expires
Host-Header
X-AOL-HN
X-NWS-LOG-UUID
X-Varnish-Backend
X-Node-Name
ServerID
X-Whom
X-Content-Security-Policy-Report-Only
X-Signature
X-NewRelic-App-Data
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Cluster
X-Tumblr-User
X-Instance
X-FB-Debug
X-Device-Type
Eomportal-Instance
X-B-Cache
X-Cache-2
X-Via-JSL
X-Webkit-Csp
X-Cache-Control
X-Platform-Server
X-Akamai-Edgescape
X-Varnish-Hostname
X-Page-Id
X-Ruxit-Js-Agent
X-Framework
X-BCube-Filmed-By
X-Generated-By
X-Drupal-Cache-Contexts
X-LB-Cache
X-Handled-By
X-App-Environment
Cleartype
X-Request-Guid
X-Cache-Rule
X-Srv
X-Cache-Action
X-App-Server
Cache-Tag
X-AppVersion
X-Az
X-Activity-Id
Alternate-Protocol
DC
Source
Liferay-Portal
X-Content-Powered-By
X-Cache-Server
X-Hostname
Retry-After
X-HS-Combine-CSS
X-Varnish-Grace
X-WPE-Loopback-Upstream-Addr
MS-CV
X-WA-Info
X-App-Version
X-Geo-Country
HostName
X-Varnish-Server
X-Daa-Tunnel
X-Esi
Server-Node
X-Amz-Replication-Status
Public-Key-Pins-Report-Only
X-Wix-Request-Id
X-TT
X-Seen-By
Pagespeed
AR-SID
ViewerVersion
Webserver
X-Correlation-Id
X-WebKit-CSP-Report-Only
X-Tumblr-Pixel-1
X-Tumblr-Pixel-2
AsisCache
X-Response-Served-From
X-Cache-NE
X-Amzn-RequestId
Actual-Object-TTL
X-Amz-Apigw-Id
X-GeoIP
SRV
Accept-Charset
Upgrade-Insecure-Requests
X-Locale
X-RequestSource
GEO-INFO
X-Ttl
ServedBy
X-Jobs
X-Varnish-Hits
X-Edge-Cache-Key
X-Edge-Cache
X-FW-Serve
X-Servedby
X-Contextid
X-FW-Hash
X-UUID
X-FW-Server
X-S
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-FW-Type
X-Correlation-ID
X-FW-Static
Payment
X-TX-ID
Viewport
X-Status
X-Varnish-IP
X-Adobe-Loc
X-Adobe-Content
X-Cacheable-TTL
X-XRDS-LOCATION
X-TT-TIMESTAMP
X-Origin-Server
S-Cnection
X-Hyper-Cache
X-Vg-Webcache
X-Cache-TTL-Remaining
X-Cache-Operation
X-Amz-Server-Side-Encryption
X-Forwarded-Host
Server-Info
X-Real-IP
Cache
X-Cache-Age
Served-By
X-Geo-Segment
Datacenter
X-Akamai-Request-ID2
X-Region
Access-Control-Allow-Method
CACHE
X-RateLimit-Limit
X-Mode
X-CLOUD-TRACE-CONTEXT
X-DataStream-Cache-Status
Healthy
X-Content-Type
X-GRACE
X-Sucuri-ID
X-Akamai-Transformed
X-Ezoic-Cdn
X-Environment-Context
X-Generated
X-Cache-Var
X-Cache-Var-Map
X-Detected-As
X-Upgrade-Enabled
Machine
Meta-Geo
X-Rule
X-Routing-Service
Fastcgi-X-Cache-Version
Fastcgi-X-Cache
X-Path-Route
X-RN-RSRV
X-Site-Version
Fastcgi-Useragent
X-Cache-Config
X-Rendered-As
X-Proxy
X-Proxied
X-JoinUs
X-Is-Bot
X-Zipkin-Id
X-L-Path
X-Ocache
Country
X-Amz-Meta-Surrogate-Control
X-Birta-Served
X-Birta-Cache-Post
X-Request-Time
X-TNCMS
X-Agile
X-NGENIX-Cache
L5d-Success-Class
Now
DB-Nickname
X-Section
X-Loop
X-Access
X-Agile-Age
X-Agile-Id
X-Hosted-By
From-Origin
X-CDN-Cache
X-Human
X-Format
X-Viewer-Country
X-Tb
TWC-Privacy
Origin-Edge-Control
Webcakes-Region
TWC-Locale-Group
X-Cache-Category-Id
Webcakes-App-Version
TWC-Device-Class
Origin-Cache-Control
Property-Id
X-OCL
X-Hit
X-ServerID
Cache-Name
TWC-GeoIP-Country
TWC-Connection-Speed
S-Rt
TWC-GeoIP-LatLong
Webcakes-App-Name
X-PCL
X-Origin-Hint
OT-Force-Account-Verify
X-Geo
X-Labrador-Cache-Channel
X-Pc-Hit
X-Pc-Key
X-CCM
X-Pc-Appver
X-Via-Fastly
X-Grey
X-EIG-Tracking-Id
X-ProxyCache-Status
X-BYPASS-REASON
X-IP
Accept-Language
HitInfo
X-Origin
X-VG-TLSProxy
X-RemovedCookies
X-Pubstack
HitType
X-Cdn
Azure-SlotName
X-Xfnlog-Site
X-OVcl-Cache
X-OVcl
X-ProcessESI
X-Web-Node
X-FC-Vary-Parameters
NGB
X-ProxyCache-Key
X-Original-Request
Azure-SiteName
Azure-Version
Azure-RegionName
X-Upstream-CT
X-Upstream-HT
Azure-InstanceId
X-Microcachable
X-Alternate-Cache-Key
X-Shopify-Stage
X-ShopId
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Via-CDN
X-ShardId
X-Www-Served-By
LB
Mn-Server-Ip
X-Cluster-Node
Filters
X-UA
X-App-Name
Xserver
X-TIME
X-Cache-Remote
X-TWH-CORRELATION-ID
X-Timing-Wait
X-Proxy-Build
X-UA-Device-Type
Selected-FE
X-Connection-Hash
X-Twitter-Response-Tags
Ms-Operation-Id
X-Transaction
X-RTag
X-Rocket-Nginx-Bypass
X-Cache-Enabled
X-NCache
X-Internal-Host
X-Tumblr-Pixel-3
Time
Access-Control-Request-Headers
X-Guploader-Uploadid
X-PHP-Backend
X-Pc-Host
X-Cache-TTL
X-Pc-Date
IBM-Web2-Location
X-NodeID
X-VWS-Id
X-Origin-CC
X-LJ-Flow-ID
X-Unique-ID
X-AWS-Id
X-SplitTest
X-Proto
Content-Script-Type
Cache-Hits
Content-Style-Type
We-Hiring
Mail-Subject
X-Nginx-Cache
X-Storage
X-Vgn-Hpd-Reason
NtCoent-Length
X-MP-GENERATED-AT
X-Port
X-Time-Microsecs
X-Real-Ip
X-Edge-IP
X-Source
X-Akamai-Request-ID
Backend
X-Webstats-RespID
X-Cdn-Forward
X-Varnish-Cacheable
X-Ms-Blob-Type
X-Backend-Name
X-APP-VERSION
Cache-Tags
X-Debug-Cache
X-Ms-Request-Id
X-Ms-Lease-Status
X-Ms-Version
X-CACHE-KEY
X-Csrf-Token
X-Ratelimit-Limit
X-Distil-CS
X-Endurance-Cache-Level
X-CACHE-GROUP
X-Origin-Response-Time
Locale
X-Urbn-Site-Id
X-Urbn-Context-Path
X-CACHE-AGE
X-Redis-Cache
X-B3-Spanid
X-CDN-Forward
Warning
X-Croise-Owner
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-EdgeConnect-Cache-Status
User-Agent
X-Ua
X-NC
X-A-Dcw
X-A-Dgt
X-Trv-Group
X-A-Dam
Xc-Version
X-A
V-Age
UCS
Viewtype
VivaBuild
X-UE-Client-Country
X-A-Ccd
X-A-Wwc
X-Amz-Meta-Cache-Control
X-Via-SSL
X-Via-Edge
X-B-Cookie
X-Application
X-Aed
X-Accel-Expires-Debug
X-Store
X-We-Are-Hiring
X-BB-ID
TSSecure
X-VG-WebServer
Resin-Trace
HA-Geocountry
HA-Geocity
Cache-Prefix
HA-Geolat
HA-Georegion
HA-Geolon
Content-Disposition
Country-Code
Ec-Rule-Version
Fastly-SWR
Fly-Cache
Fly-Request-Id
HA-Cloudapp
GMS-Ver
BehaviorPad-Version
Ha-Gx-Prefs
Mobile-Detection-Method
Meta-Geo-Continent
Powered-By
Rendered-Blocks
Rt-Proxy-Cache
X-SRCache-Key
Ajk
MD5-Digest
HA-Host
Arc-Country
HA-Ipaddr
HA-Servedtime
HA-Urlpath
Server-Host
X-Server-By
X-Generated-In
X-GeoIP-Country-Code
X-CF-Lambda-Version
X-G
X-Fetched-On
X-From
X-Varnish-Beresp-Ttl
X-Hash
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Storage-Class
X-F5-Cache
X-External-Request-Id
X-Destination
X-Developer
X-Debug-Log
X-Debug-Cookies
X-D
X-Date
X-CGP
X-Died
X-ElasticPress-Search
X-Eu-Site
X-ApacheServer
X-DPWN-IS-SECURE
X-C
X-Varnish-Cache-Hits
X-IN-APIGATEWAY
X-Cache-Host
X-S-Cookie
X-Cache-Backend
X-Cache-URL
X-Rewrite-Enabled
X-Rojux
X-Cache-Bucket
X-ScT
X-Server-Time
X-Sn-Servicetimems
X-NWS-UUID-VERIFY
X-BBXSRF
X-PERF
X-Cdn-Origin
Fastly-SIE
X-Logtrace-Id
X-NU-AKA-ACS-Version
X-Irp-Debug
X-IN-WAF
X-IN-SSL-APIGATEWAY
X-NX-Host
X-Org
X-Region-Sid
X-CF-Lambda-Fn
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-PAYTM-SRV-ID
PageSpeed
Fastly-SSL
X-Mrs-Cache-Hits
X-Mrs-Age
X-Mshield-Cache-Status
Pagetype
Cache-Key
Version
X-Dc
X-Mrs-Cache
X-Backend-Url
X-Location
X-Backend-State
X-Backend-Host
X-User
X-UnsetCookies
X-Trace-Id
X-Cache-Id
X-SIPLIST1
X-Dynatrace-Js-Agent
X-Cache-FS-Status
X-Thinkindot-L3
X-V
X-Var-Ttl
Uber-Trace-Id
X-Layer
Thinkindot-Control
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
Www
X-Wikidot-Static-Cache
X-ABtesting
X-Via-NSCOPI
X-VServer
X-Wikidot-Backend
X-Key
X-ServiceProvider
X-Platform
X-Flog
X-Qloud-Router
X-Parent-Response-Time
X-Epic-Correlation-Id
X-Hl-Ver
X-FW-Version
X-MServer
X-GeoIP-City
X-No-Session
Fastly-Soc-X-Request-Id
X-Reboot
X-Release
SN
X-DC
X-Matched-Rule
X-Nc
X-Core-Value
X-S-Maxage
X-Response-By
X-Request-Start
X-Dispatcher-Server
X-Request-URI
X-Developers
X-Hello
X-Variation
Apple-News-Services-Handled
Decoy-Debug-Key
Heartbleed
Platform
FSS-Proxy
Is-Eu
GW-Server
X-Powered-By-ANYU
Apple-News-Services-Request-Url
Backend-Name
Pramga
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Release
WZWS-RAY
FSS-Cache
Decoy-Debug-Status
Memcached
Section-Io-Cache
Decoy-Debug-TTL
AKAMAI
User-Cache-Control
IsBot
RNT-Time
RNT-Machine
Adler-Geo
Origin
Server-ID
X-Datadome
Cache-Cookie-Set-From
X-Policy
X-Fastly-Cache
X-Phone
X-SVT-ORM-RULES
Magicmarker
Kp-EeAlive
X-Device-Os
Cache-Cookie-Set-Idcheck
X-Distributor
Countrycode
X-Instance-Name
X-Info
X-MI-In-Market
X-Hnp-Log
Frame-Options
X-LI-UUID
X-Li-Pop
X-Li-Fabric
Esi-Enabled
X-Request-UUID
V-Cache
Group
X-SVT-ORM-VERSION
Cache-Cookie-Set-Lfrom
X-Gannett-Site-Version
X-Gen-Mode
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Nginx-Cache-Key
X-Stale
X-P-T
X-Core-Mission
X-Passed-To-DLL
X-Auto-Login
Request-Country
X-LI-Proto
X-Up
Pragrma
X-Block-Status
X-TT-LOGID
X-CUA
X-VCT
Request-EU
Fastly-Backend-Name
On-Server
True-Client-Country-4JS
Server-Int
X-Worker
Web-Mar-Node
X-Passed-To-BeforeDispatch
X-Passed-To
X-WebServer
Odigeo-Trace-Id
X-Passed-To-PostProcessResponse
X-Served-From
X-Server-IP
X-Sucuri-Cache
X-Unique-Id-Primal
X-Clientip
X-Actual-URL
X-Secret
X-Sentry-ID
X-Returned-From-PostProcessResponse
MI-Cache-Age
MI-Cache
X-Cache-Expires
X-Returned-From-DLL
X-Returned-From-BeforeDispatch
X-Returned-From
X-Sf
X-Swa-Ws
Who
X-Node-Id
X-Refresh
X-RCS-CacheZone
X-Thanos
X-MSEdge-Flight
X-Varnish-Action
X-NODE
X-MSEdge-Features
X-HOST
X-Newrelic-Synthetics
Proxy-Connection
REQUESTUUID
X-Cache-CFC
X-Fstrz
CDCHOST
X-Crawler
X-Cache-Debug
MI-API
X-Bip
X-Time
X-Owner
X-Page-Type
Fusion-Source
X-Servername
HTTPS
MIME-Version
RequestId
Cteonnt-Length
Fusion-Template-Id
Fusion-Content-Source
X-Be
Fusion-Content-Id
X-Req
Fusion-Component-Id
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Backend-TTL
X-Pjax-Url
X-SN
X-Oracle-Dms-Ecid
X-Cache-Srv
X-GZip
NodeID
Cdn-Host
X-Origin-TTL
X-Edge-Server
Cdn-Request-Time
Memory
X-Ms-Lease-State
X-Server-Group
Cdn
SD-X-WS
ProcessTime
X-Servedbyhost
Amp-Access-Control-Allow-Source-Origin
CF-IPCountry
X-Content-Age
X-Wa
X-Protected-By
SS
Mime-Version
X-Aicache-OS
VIX-Pulpo-Upstream-Status
A
VIX-Pulpo-Node
X-COUNTRY
CDN
X-Origin-Expires
X-Origin-Date
X-BB-IP
X-Origin-Host
X-Ckpd-Fst-Backend
X-ND-Cache
XServer
GeoIP-Country-Code
X-SRV
X-Varnish-Beresp-TTL
Is-Session-Tracking
Get-Access-Time
GeoIP-Latitude
X-StackifyID
X-Pf-Uncompressing
Geoip-Latitude
GeoIp-Country-Code
X-B3-Traceid
PageType
X-APP
Processtime
Serverid
Node
X-PHP-Host
X-Fastly-Country-Code
X-Unique-Id
PICS-Label
Cache-Tv-Group
X-Requestid
X-Gdpr
X-Varnish-Url
X-Cache-Info
Vix-Hermes-Req-Id
X-CSRF-Token
X-Ratelimit-Remaining
X-Proxy-Cache-Status
X-WA
DataCenter
X-Proxy-Upstream
X-Load-Cache
X-Nananana
Nel
X-ID
X-Generation-Time
X-RateLimit-Limit-Second
X-Fastly-Cache-Hits
X-RateLimit-Remaining-Second
X-BACKEND-TTL
Cf-Ipcountry
Cache-Provider
X-ServedByHost
X-Planisys-CDN-Cache
X-SERVER-NAME
X-RequestId
X-FireWall-Port
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-NGINX-Cache
URI
WP-Super-Cache
X-UPSTREAM-Address
X-Check-Cacheable
X-HS-Status
Request-Time
Hostname
X-FORWARDED-FOR
X-Front
X-CS
X-Fastly-Backend-Reqs
Host-ID
X-GZIP
PFcat
X-EC-Security-Audit
X-Server-W
X-Micro-Cache
X-WR-MODIFICATION
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-FB-TRIP-ID
X-B3-SpanId
X-HTML-Edge-Cache
X-VG-WebCache
X-Surge-Debug
X-Svr
NGX
X-VarnCache
X-VarnPar1
X-PARISIEN-Cache-Rendered
T-Server
X-BE
X-DataStream-MidMile-RTT
X-DataStream-Origin-MEX-Latency
X-GDPR
X-Fe
X-GEO
X-Swift-Error
X-Atg-Version
Ohc-File-Size
X-Generated-On
X-HTML-Minification-Powered-By
Ohc-Response-Time
ServerName
Lfy
Https
X-Cdn-Srv
X-PJAX-URL
Requestid
X-IPS-LoggedIn
X-Level-Front-Cache
X-Instart-Info
RequestUuid
X-Akamai-SSL-Client-Sid
X-Amz-Meta-S3b-Last-Modified
X-ServerName
X-VarnPar2
N-Cache
WebServer
X-Cache-Ttl
X-PAGE-TYPE
X-RAMCache
Pics-Label
X-Distil-Cs
X-PF-Uncompressing
X-From-Cache
X-M-Reqid
X-Qnm-Cache
X-M-Log
Build-Number
X-Serial
NnCoection
X-Akamai-ERPolicy
Cdn-Src-Port
X-Akamai-ERRuleID
X-Gen-Id
X-Alicdn-Da-Ups-Status
X-SB
X-VC
SID
X-Dw-Trace-Id