Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Accept-Ranges
Pragma
X-Powered-By
Link
ETag
CF-RAY
Expect-CT
Via
X-XSS-Protection
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Id
X-Served-By
Referrer-Policy
P3P
X-Varnish
X-Xss-Protection
X-Timer
CF-Cache-Status
X-Request-Id
Access-Control-Allow-Headers
X-AspNet-Version
Access-Control-Allow-Methods
P3p
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Check
X-Adblock-Key
Alt-Svc
X-Cacheable
X-Generator
CF-Ray
Content-Security-Policy-Report-Only
X-Amz-Cf-Pop
X-Cache-Status
X-AspNetMvc-Version
Status
X-DNS-Prefetch-Control
X-Request-ID
X-Template
X-Language
Timing-Allow-Origin
Content-Encoding
X-Permitted-Cross-Domain-Policies
X-Iinfo
X-Buckets
X-Content-Security-Policy
X-Turbo-Charged-By
Upgrade
X-Kinja-Server-Push
X-CDN
X-Type
Xkey
Keep-Alive
Access-Control-Expose-Headers
WPE-Backend
X-Pass-Why
Access-Control-Max-Age
X-AH-Environment
X-Backend
X-Cache-Group
X-Server
X-Age
X-Drupal-Dynamic-Cache
X-Pingback
X-Via
X-Nginx-Cache-Status
X-Amz-Request-Id
X-Amz-Id-2
Grace
X-Server-Powered-By
X-Hacker
EagleId
X-UA-Device
X-Robots-Tag
X-LiteSpeed-Cache
X-Varnish-Cache
X-Page-Speed
X-Swift-SaveTime
X-Swift-CacheTime
X-Proxy-Cache
Cf-Railgun
X-Envoy-Upstream-Service-Time
Request-Context
Ali-Swift-Global-Savetime
X-Ua-Compatible
X-Ac
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-WebKit-CSP
X-Cache-Lookup
Content-Location
X-Amz-Version-Id
Surrogate-Control
X-Host
X-Node
X-Cnection
X-Server-Id
X-Readtime
Report-To
EagleEye-TraceId
X-Rq
Server-Timing
X-Response-Time
X-OneAgent-JS-Injection
Feature-Policy
X-CST
X-Rack-Cache
X-Backend-Server
X-ORACLE-DMS-ECID
X-Application-Context
X-Iejgwucgyu
Request-Id
X-Instart-Request-ID
X-Cloud-Trace-Context
X-Clacks-Overhead
NEL
X-Url
Edge-Control
X-DynaTrace
Allow
Rating
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Country
X-Varnish-TTL
X-Origin-Cache
X-FTR-Request-ID
X-Country-Code
X-Cdn
X-B3-TraceId
X-Server-Name
X-Trace
X-Px
X-Vhost
X-DataDome
X-Server-ID
X-ESI
X-GitHub-Request-Id
RTSS
X-VARITI-CCR
X-MS-InvokeApp
X-Cached
X-Ruxit-JS-Agent
Accept-CH
X-Goog-Hash
X-ORACLE-DMS-RID
SPRequestGuid
Charset
X-TtlSet
X-Vname
X-PC
Pinterest-Generated-By
X-Mod-Pagespeed
X-F-Cache
X-D2id
Public-Key-Pins
Verso
X-Dispatcher
X-Use-Magma
X-Kinja-Server
X-Kinja-Revision
X-Exp-Id
X-Cdn-Fetch
X-Exp-Variant
X-Kinja-Build
X-GoogleNews-Bot
X-Kinja
X-Mobile-Rewrite
PB-RID
PB-PID
Arc-Version
X-SharePointHealthScore
X-TTL
X-T
X-Version
X-Powered-By-Plesk
Accept-CH-Lifetime
X-Abt-Application-Version
X-DIS-Request-ID
X-Powered-CMS
X-Dns-Prefetch-Control
X-DynaTrace-JS-Agent
X-Ser
X-Fastly-Request-ID
X-Pinterest-Rid
X-Upstream-Env
Pinterest-Version
X-Origin-Upstream-Status
X-Navigation-Version
X-Forwarded-Proto
X-B
X-Shield-Request-Id
X-Recruiting
X-Client-IP
DynaTrace
MS-Author-Via
X-Amz-Rid
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Realpath
X-HW
SPRequestDuration
SPIisLatency
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Oneagent-Js-Injection
Content-MD5
X-Upstream
X-Ttl
Nginx-Cache
X-Vcap-Request-Id
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Generation
X-Accel-Buffering
X-Wix-Server-Artifact-Id
X-Oracle-Dms-Rid
X-Amz-Meta-S3cmd-Attrs
AR-CACHE
AR-ATIME
AR-PoweredBy
Edge-Cache-Tag
X-N
X-Hits
Arr-Disable-Session-Affinity
X-Varnish-Age
X-Debug
TCN
X-NF-Request-ID
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
X-Mrf-Item-Lastmod
Access-Control-Request-Method
X-Goog-Storage-Class
X-MSEdge-Ref
X-Acc-Meta-Resource-Type
X-Dw-Request-Base-Id
X-NewRelic-App-Data
X-ATG-Version
S
X-Id
X-Via-JSL
Service-Worker-Allowed
X-FTR-Cache-Status
X-FTR-Realm
X-FTR-DC
X-FTR-Balancer
X-Country-Code-Real
X-FTR-Backend
X-FTR-Backend-Server
X-Logged-In
X-FTR-Expires
X-XRDS-Location
Tracecode
Alternate-Protocol
Rt-Fastcgi-Cache
X-PressLabs-Stats
X-Content-Digest
X-Forwarded-For
X-HS-Hub-Id
X-HS-Content-Id
X-Frontend
X-Kinsta-Cache
Surrogate-Key
Fastly-Restarts
X-FastCGI-Cache
X-Pad
MicrosoftSharePointTeamServices
X-RateLimit-Remaining
AMP-Access-Control-Allow-Source-Origin
X-Cache-Key
X-Content-Options
Ar-Sid
X-FTR-Cache-Host
X-Grace
Server-Name
X-Ruxit-Js-Agent
X-Edge-Location
X-Amzn-Trace-Id
Backend-Timing
X-Analytics
Fastcgi-Cache
FilterID
Host
X-CF-Powered-By
X-User-Agent
X-Rid
X-IPLB-Instance
TP-L2-Cache
X-Debug-Info
X-Hostname
TP-Cache
ServerID
X-Magnolia-Registration
X-B3-Sampled
X-Cache-2
X-Whom
X-Revision
Eomportal-Instance
X-Request-Processing-Time
X-Request-Received
Paypal-Debug-Id
X-Page-Id
X-NWS-LOG-UUID
X-Mobile
AR-Request-ID
X-Srv
Front-End-Https
X-HS-Cache-Config
X-Akam-SW-Version
X-AOL-HN
X-Content-Powered-By
Retry-After
X-Litespeed-Cache
X-Signature
X-B-Cache
X-Cache-Hit
X-Varnish-Grace
X-Cluster
X-FB-Debug
X-LB-Cache
X-Device-Type
Source
Refresh
X-Handled-By
Cleartype
X-Instance
X-Request-Guid
X-WA-Info
X-Cache-Action
X-App-Environment
X-XRDS-LOCATION
X-Cache-Control
X-Tumblr-User
X-Tumblr-Pixel-0
X-Varnish-Hostname
X-Tumblr-Pixel
X-VCache
X-Correlation-Id
X-Platform-Server
X-Framework
X-BCube-Filmed-By
X-Content-Security-Policy-Report-Only
X-Akamai-Edgescape
X-SS-Set-Cookie
X-Fastcgi-Cache
X-Zen-Fury
X-GUploader-UploadID
Webserver
X-Varnish-Backend
Display
X-Daa-Tunnel
X-Middleton-Display
X-Sol
X-Cache-Server
X-Activity-Id
X-AppVersion
X-Az
X-Content-Type
Healthy
X-TA-CDN-Provider
X-Cache-Rule
VIX-Pulpo-Node
X-Varnish-Server
VIX-Pulpo-Upstream-Status
X-Drupal-Cache-Contexts
X-Drupal-Cache-Tags
X-Generated-By
Response
X-Middleton-Response
X-Seen-By
ViewerVersion
X-Wix-Request-Id
X-URL
X-Cached-By
S-Cnection
X-Cache-Age
X-Geo-Country
X-App-Server
Server-Node
Cache-Status
X-Amz-Replication-Status
X-CACHE-GROUP
X-Origin-Server
X-DataStream-Cache-Status
X-Accel-Expires
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Esi
X-TT
Upgrade-Insecure-Requests
X-Node-Name
NGB
X-Response-Served-From
X-S
Payment
GEO-INFO
X-RequestSource
Filters
X-Locale
X-UA-Device-Type
X-Edge-Cache-Key
X-Varnish-IP
X-Edge-Cache
Viewport
X-WPE-Loopback-Upstream-Addr
Actual-Object-TTL
X-Cacheable-TTL
X-Cache-NE
X-FW-Server
X-FW-Static
X-Servedby
X-Jobs
X-FW-Serve
X-FW-Type
X-Tumblr-Pixel-1
X-GeoIP
X-Tumblr-Pixel-2
ServedBy
X-Contextid
X-FW-Hash
HostName
Host-Header
X-Status
X-TX-ID
AsisCache
X-Varnish-Hits
Accept-Charset
Access-Control-Allow-Method
X-Amz-Server-Side-Encryption
X-WebKit-CSP-Report-Only
X-TT-TIMESTAMP
X-UUID
Server-Info
Cache
X-Storage
X-Adobe-Content
X-Adobe-Loc
X-Vg-Webcache
SRV
X-PHP-Backend
X-Rendered-As
X-Hyper-Cache
X-CLOUD-TRACE-CONTEXT
X-Cache-TTL-Remaining
X-Cache-Remote
From-Origin
MS-CV
X-Croise-Owner
X-HS-Combine-CSS
X-APP-VERSION
X-App-Version
Cache-Tv-Group
X-Cache-Operation
X-Webkit-CSP
X-Region
Cache-Tag
DC
Public-Key-Pins-Report-Only
Served-By
X-Forwarded-Host
X-Redis-Cache
Liferay-Portal
X-Mode
X-Yottaa-Optimizations
X-CACHE-KEY
X-Yottaa-Metrics
X-UA
X-Guploader-Uploadid
X-Loop
X-Detected-As
X-Generated
X-Site-Version
X-Timing-Wait
X-Request-Time
X-Upgrade-Enabled
X-TNCMS
X-RN-RSRV
X-Endurance-Cache-Level
Machine
Fastcgi-X-Cache-Version
Fastcgi-X-Cache
Meta-Geo
Selected-FE
X-Cache-Var-Map
X-Is-Bot
X-Hosted-By
X-NGENIX-Cache
X-Path-Route
X-Webstats-RespID
X-Agile-Id
X-Proxy-Build
X-Agile-Age
X-Agile
Xserver
X-Cache-Var
X-Internal-Host
Cache-Name
X-ProxyCache-Status
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-Country
X-Zipkin-Id
X-Human
Property-Id
Origin-Edge-Control
X-Original-Request
X-Proxied
Fastcgi-Useragent
X-Via-Fastly
X-ProxyCache-Key
Origin-Cache-Control
Now
TWC-GeoIP-LatLong
X-IP
X-CDN-Cache
Webcakes-App-Version
X-L-Path
X-NCache
X-Pc-Key
X-Akamai-Request-ID2
X-Origin-Hint
X-Routing-Service
X-JoinUs
X-Pc-Appver
X-Pc-Hit
TWC-Locale-Group
X-BYPASS-REASON
Webcakes-Region
Webcakes-App-Name
X-Environment-Context
X-Format
X-Vgn-Hpd-Reason
TWC-Privacy
X-Akamai-Transformed
Pagespeed
Powered-By-ChinaCache
X-Grey
X-Birta-Cache-Post
X-Origin-Host
X-OCL
S-Rt
X-Upstream-CT
X-Birta-Served
X-Tumblr-Pixel-3
X-Section
X-Access
Datacenter
X-Cache-Category-Id
X-ProcessESI
X-Proxy
X-Pubstack
X-Upstream-HT
X-RemovedCookies
X-PCL
X-Viewer-Country
X-Labrador-Cache-Channel
DB-Nickname
Cache-Tags
X-FC-Vary-Parameters
X-Web-Node
X-Cache-Config
X-Rule
X-Origin
X-Backend-Name
X-VG-TLSProxy
X-ServerID
X-B3-Spanid
X-CCM
X-Www-Served-By
X-Time-Microsecs
X-Via-CDN
X-Ocache
X-Xfnlog-Site
X-Origin-CC
X-Origin-Response-Time
HitType
X-Tb
Azure-InstanceId
X-Akamai-Request-ID
Azure-SlotName
Azure-SiteName
Mn-Server-Ip
Azure-Version
Azure-RegionName
X-TIME
OT-Force-Account-Verify
X-ShopId
X-Sorting-Hat-ShopId
X-App-Name
X-Shopify-Stage
X-Sorting-Hat-PodId
X-ShardId
X-Alternate-Cache-Key
Cache-Key
Accept-Language
X-Nginx-Cache
X-Cache-TTL
X-Parent-Response-Time
X-Ezoic-Cdn
X-RateLimit-Limit
User-Cache-Control
Vix-Hermes-Req-Id
X-OVcl
X-OVcl-Cache
X-Real-Ip
X-Protected-By
X-Edge-IP
Content-Style-Type
Content-Script-Type
X-Dynatrace-Js-Agent
L5d-Success-Class
X-BACKEND-TTL
X-Kong-Proxy-Latency
Time
NtCoent-Length
LB
X-Kong-Upstream-Latency
X-Newrelic-App-Data
X-Cache-Backend
X-RTag
X-PERF
X-Amz-Meta-Surrogate-Control
Ms-Operation-Id
X-ApacheServer
X-Webkit-Csp
X-Proto
X-Pc-Date
X-Front
X-Pc-Host
X-Correlation-ID
X-Real-IP
X-Mrs-Age
X-Unique-Id-Primal
X-Mrs-Cache
X-Mrs-Cache-Hits
X-Mshield-Cache-Status
X-Nc
X-FB-TRIP-ID
X-Cdn-Forward
X-CDN-Forward
X-Varnish-Cacheable
X-Hit
Section-Io-Cache
X-Content-Age
X-Varnish-Beresp-Grace
X-Debug-Cache
X-Varnish-Beresp-Status
X-Sucuri-ID
X-Unique-ID
WZWS-RAY
AR-SID
X-Microcachable
X-Ratelimit-Limit
X-GRACE
Version
Fusion-Component-Id
Access-Control-Request-Headers
Country
X-C
Load-Balancing
X-Time
X-Trace-Id
X-Dc
Fusion-Content-Source
Fusion-Source
Fusion-Template-Id
Fusion-Content-Id
X-Twitter-Response-Tags
Ohc-File-Size
X-EdgeConnect-Cache-Status
X-Connection-Hash
X-Transaction
X-Cache-Enabled
We-Hiring
Warning
X-MP-GENERATED-AT
Mail-Subject
X-Application
X-CF-Lambda-Fn
X-Aed
MD5-Digest
X-Auto-Login
VivaBuild
X-D
V-Age
X-BB-ID
Viewtype
X-Actual-URL
X-Accel-Expires-Debug
X-A
X-Crawler
X-A-Ccd
X-CUA
Is-Eu
X-A-Wwc
X-A-Dam
SS
X-CF-Lambda-Version
X-Clientip
X-A-Dcw
X-Cache-Host
RNT-Time
Mobile-Detection-Method
Rt-Proxy-Cache
Platform
RNT-Machine
Resin-Trace
Node
X-Cache-Bucket
Rendered-Blocks
X-Bip
SD-X-WS
Meta-Geo-Continent
Powered-By
X-Date
Server-ID
Release
X-B-Cookie
Memcached
X-Cache-Debug
Server-Host
X-Cache-FS-Status
X-Backend-State
X-Cache-Id
X-Org
X-Rojux
X-Rewrite-Enabled
X-Returned-From-PostProcessResponse
X-S-Cookie
X-S-Maxage
X-Served-From
X-ScT
X-Returned-From-DLL
X-Returned-From-BeforeDispatch
X-Region-Sid
X-Reboot
X-Release
X-Request-UUID
X-Returned-From
X-Response-By
X-Server-By
X-Server-Time
X-Via-Edge
X-VG-WebServer
X-Via-SSL
X-We-Are-Hiring
Xc-Version
X-WebServer
X-Varnish-Action
X-Variation
X-Store
X-SRCache-Key
X-Thanos
X-Trv-Group
X-Var-Ttl
X-UE-Client-Country
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-FW-Version
X-From
X-G
X-Generated-In
X-Layer
X-GeoIP-Country-Code
X-Fetched-On
X-F5-Cache
X-Device-Os
X-Developer
X-Died
X-Dispatcher-Server
X-External-Request-Id
X-DPWN-IS-SECURE
X-Li-Fabric
X-Li-Pop
X-Passed-To-PostProcessResponse
X-Passed-To-DLL
X-PAYTM-SRV-ID
X-PHP-Host
X-RCS-CacheZone
X-Qloud-Router
X-Passed-To-BeforeDispatch
X-Passed-To
X-LI-UUID
X-LI-Proto
X-Logtrace-Id
X-Node-Id
IBM-Web2-Location
X-NU-AKA-ACS-Version
X-Destination
X-A-Dgt
Fastly-SIE
Fastly-Backend-Name
Fastly-SWR
Fly-Cache
Fly-Request-Id
Ec-Rule-Version
Countrycode
Ajk
X-Hl-Ver
Arc-Country
BehaviorPad-Version
Cache-Prefix
Frame-Options
Adler-Geo
X-Rocket-Nginx-Bypass
X-Varnish-Beresp-Ttl
GMS-Ver
X-V
X-Matched-Rule
X-Block-Status
X-MI-In-Market
X-Proxy-Upstream
X-Cache-URL
X-Via-NSCOPI
X-Urbn-Site-Id
HA-Cloudapp
X-Request-Start
X-Urbn-Context-Path
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
HA-Geocountry
Apple-News-Services-Host
Apple-News-Services-Handled
X-No-Session
HA-Geocity
X-Amz-Meta-Cache-Control
AKAMAI
X-Proxy-Cache-Status
X-Server-Group
X-IN-WAF
X-IN-SSL-APIGATEWAY
X-IN-APIGATEWAY
X-Hnp-Log
X-Info
X-Key
Www
Thinkindot-Control
X-Location
Thinkindot-CacheControl-Type
X-Hash
X-Eu-Site
X-Epic-Correlation-Id
User-Agent
Backend
Origin
Thinkindot-CacheControl
X-Swa-Ws
X-Gen-Mode
X-Thinkindot-L3
X-CGP
X-User
MI-API
MI-Cache
Request-Country
MI-Cache-Age
Request-EU
X-SVT-ORM-VERSION
Ha-Gx-Prefs
Esi-Enabled
X-Sf
X-Cache-Expires
Heartbleed
Backend-Name
Proxy-Connection
Pramga
Pragrma
HA-Servedtime
HA-Urlpath
X-SVT-ORM-RULES
HA-Ipaddr
X-Stale
On-Server
Decoy-Debug-TTL
HA-Host
HA-Geolon
X-UnsetCookies
Web-Mar-Node
True-Client-Country-4JS
GW-Server
Uber-Trace-Id
Content-Disposition
Kp-EeAlive
UCS
Who
Country-Code
Decoy-Debug-Status
HA-Geolat
Decoy-Debug-Key
HA-Georegion
X-ServiceProvider
Locale
X-Be
X-NODE
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-From
X-Secret
X-Irp-Debug
Cache-Cookie-Set-Lfrom
X-Server-IP
X-Instance-Name
X-SIPLIST1
X-Gannett-Site-Version
X-Wikidot-Static-Cache
X-Nginx-Cache-Key
X-Policy
X-Goog-Meta-Goog-Reserved-File-Mtime
CDCHOST
REQUESTUUID
X-P-T
X-Request-URI
X-Core-Value
X-Phone
Fastly-SSL
X-Platform
X-Distil-CS
Server-Int
IsBot
Request-Time
X-Cache-CFC
Fastly-Soc-X-Request-Id
X-Wikidot-Backend
X-NWS-UUID-VERIFY
X-Developers
X-Geo
Group
V-Cache
X-Ua
X-VCT
X-Sn-Servicetimems
X-Refresh
HitInfo
X-Origin-TTL
X-NX-Host
X-Fstrz
X-Origin-Date
X-Cdn-Origin
X-MSEdge-Flight
X-Debug-Cookies
X-Origin-Expires
X-TT-LOGID
PFcat
X-Backend-Host
X-Backend-Url
X-Up
X-Debug-Log
X-MSEdge-Features
Magicmarker
X-GeoIP-City
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-ElasticPress-Search
X-Distributor
X-Page-Type
X-Core-Mission
Pagetype
RequestId
X-COUNTRY
X-Servername
X-DC
X-Fastly-Cache
X-Debug-Cache-Store
X-PARISIEN-Cache-Rendered
X-Svr
X-VarnPar1
X-VarnCache
X-Newrelic-Synthetics
Host-ID
X-Pjax-Url
X-Micro-Cache
X-Req
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
PageSpeed
X-Level-Front-Cache
X-Instart-Info
X-Generated-On
X-NC
X-CACHE-AGE
X-BBXSRF
X-Powered-By-ANYU
X-EIG-Tracking-Id
Lfy
ServerName
MIME-Version
X-Datadome
Mime-Version
X-Server-Cache
X-Cache-Info
Ohc-Response-Time
Cache-Provider
X-Cdn-Srv
Cdn
X-ARC
Cteonnt-Length
Memory
X-Gdpr
PICS-Label
X-TWH-CORRELATION-ID
X-Cluster-Node
Nel
X-Servedbyhost
X-CMS-Context
X-StackifyID
CF-IPCountry
Amp-Access-Control-Allow-Source-Origin
X-Fastly-Country-Code
FSS-Cache
X-NodeID
X-Sentry-ID
X-LAGOON
X-Aicache-OS
X-Wa
FSS-Proxy
X-Load-Cache
X-Flog
X-Hello
GeoIP-Latitude
X-HTML-Minification-Powered-By
NGX
X-ABtesting
X-Varnish-Beresp-TTL
GeoIP-Country-Code
CDN
X-WR-MODIFICATION
X-VServer
X-B3-Traceid
SN
XServer
X-Fastly-Backend-Reqs
GeoIp-Country-Code
Geoip-Latitude
X-CSRF-TOKEN
X-WA
X-Ratelimit-Remaining
X-Check-Cacheable
X-GZip
X-UPSTREAM-Address
Processtime
Cf-Ipcountry
TSSecure
X-Source
X-APP
X-CSRF-Token
X-Csrf-Token
X-FireWall-Port
X-DataStream-MidMile-RTT
X-MServer
X-Worker
X-DataStream-Origin-MEX-Latency
X-HOST
X-Unique-Id
PageType
CACHE
X-Varnish-Cache-Hits
X-ServedByHost
X-Generation-Time
X-RateLimit-Limit-Second
A
X-Cache-Miss-From
X-CDN-Pop-IP
X-CDN-Pop
X-RateLimit-Remaining-Second
X-Sedo-Request-Id
WP-Super-Cache
X-VWS-Id
X-Oss-Server-Time
X-Nananana
X-Dynatrace
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-LJ-Flow-ID
X-Oss-Request-Id
X-Oss-Storage-Class
X-GDPR
Cdn-Host
Cdn-Request-Time
X-Edge-Server
X-AWS-Id
X-SplitTest
X-SRV
X-Port
HTTPS
X-Cache-Grace
X-FORWARDED-FOR
X-Skip-Cache
Pics-Label
X-VC-Cache
DataCenter
X-ID
Cache-Hits
X-Sucuri-Cache
X-Backend-TTL
Server-Cache-Control
X-Cache-ASPX
X-Varnish-Authentication
Server-Surrogate-Control
URI
X-IPS-LoggedIn
Odigeo-Trace-Id
X-Owner
X-Fastly-Cache-Hits
X-HS-Status
X-B3-SpanId
X-RCS-Backend
X-Swift-Error
X-Ms-Version
X-Ms-Lease-Status
X-BE
X-Ms-Request-Id
X-Ms-Blob-Type
X-PJAX-URL
X-Varnish-Url
Dynatrace
Hostname
ProcessTime
X-From-Cache
X-Instart-Isnd
X-Gen-Id
X-ND-Cache
X-Bug-Bounty
X-VG-WebCache
X-SN
X-Amzn-Remapped-Connection
X-GZIP
X-Amzn-Remapped-Date
X-VarnPar2
X-NGINX-Cache
Get-Access-Time
X-Pf-Uncompressing
X-Vcache
X-Server-W
X-Cache-Ttl
X-Ms-Lease-State
X-GoCache-CacheStatus
Is-Session-Tracking
X-ServerName
Requestid
X-ORIG-AKA-EDGE
X-Akamai-SSL-Client-Sid
Serverid
X-Amz-Meta-S3b-Last-Modified
RequestUuid
T-Server
X-LiteSpeed-Cache-Control
X-PAGE-TYPE
X-SB
X-Varnish-URL
X-Alicdn-Da-Ups-Status
WebServer
X-RAMCache
X-Cache-Srv
X-Serial
Proxy-Firewall
X-ORIG-AKA-COUNTRY-CODE
X-Fe
X-GEO
X-VC
Xet-Cookie
X-PF-Uncompressing
X-LiteSpeed-Tag
Powered
X-Dw-Trace-Id
X-Akamai-ERRuleID
X-CS
Location
X-Akamai-ERPolicy
NnCoection
X-Developed-By
SID
X-HTML-Edge-Cache
NodeID