Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Accept-Ranges
Pragma
X-Powered-By
Link
ETag
CF-RAY
Expect-CT
Via
X-Cache
X-XSS-Protection
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Id
X-Xss-Protection
X-Served-By
P3P
Referrer-Policy
X-Varnish
X-Timer
X-Request-Id
CF-Cache-Status
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
P3p
X-Drupal-Cache
X-Amz-Cf-Pop
X-Check
X-Adblock-Key
Alt-Svc
X-Cacheable
X-Generator
CF-Ray
Content-Security-Policy-Report-Only
X-Cache-Status
X-DNS-Prefetch-Control
X-AspNetMvc-Version
Status
X-Template
X-Language
Timing-Allow-Origin
Content-Encoding
X-Permitted-Cross-Domain-Policies
X-Iinfo
X-Request-ID
X-Buckets
X-Content-Security-Policy
X-Turbo-Charged-By
Upgrade
X-Kinja-Server-Push
X-CDN
X-Type
Xkey
Keep-Alive
Access-Control-Expose-Headers
Access-Control-Max-Age
WPE-Backend
X-Pass-Why
X-AH-Environment
X-Backend
X-Cache-Group
X-Server
X-Age
X-Drupal-Dynamic-Cache
X-Pingback
X-Via
X-Nginx-Cache-Status
Grace
X-Amz-Request-Id
X-Amz-Id-2
X-Server-Powered-By
EagleId
X-Hacker
X-UA-Device
X-Robots-Tag
X-LiteSpeed-Cache
X-Varnish-Cache
X-Page-Speed
X-Swift-SaveTime
X-Swift-CacheTime
X-Proxy-Cache
Cf-Railgun
Request-Context
X-Envoy-Upstream-Service-Time
Ali-Swift-Global-Savetime
X-Ua-Compatible
X-Ac
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-WebKit-CSP
X-Device
X-Cache-Lookup
X-Server-Id
Content-Location
X-Amz-Version-Id
Surrogate-Control
X-Cnection
X-Node
X-OneAgent-JS-Injection
X-Host
X-Readtime
Report-To
EagleEye-TraceId
X-Rq
X-Response-Time
Server-Timing
Feature-Policy
X-CST
X-Rack-Cache
X-Application-Context
X-Backend-Server
X-ORACLE-DMS-ECID
X-Iejgwucgyu
X-Cloud-Trace-Context
Request-Id
X-Instart-Request-ID
X-Clacks-Overhead
NEL
X-Url
Edge-Control
X-DynaTrace
Rating
Allow
X-Country
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Varnish-TTL
X-Origin-Cache
X-FTR-Request-ID
X-Country-Code
X-Cdn
X-B3-TraceId
X-Trace
X-Px
X-DataDome
X-Vhost
X-Server-Name
X-ESI
X-GitHub-Request-Id
X-ORACLE-DMS-RID
X-VARITI-CCR
RTSS
X-MS-InvokeApp
Accept-CH
X-Cached
X-Ruxit-JS-Agent
X-Goog-Hash
Charset
X-Server-ID
SPRequestGuid
X-TTL
X-Mod-Pagespeed
Pinterest-Generated-By
X-Vname
X-PC
X-TtlSet
Verso
X-D2id
X-F-Cache
Public-Key-Pins
X-Kinja-Build
X-Kinja
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-GoogleNews-Bot
X-Cdn-Fetch
X-Exp-Id
X-Exp-Variant
PB-PID
Arc-Version
X-Mobile-Rewrite
PB-RID
X-Dispatcher
X-Version
X-SharePointHealthScore
X-T
X-Powered-By-Plesk
Accept-CH-Lifetime
X-Abt-Application-Version
X-DIS-Request-ID
X-Powered-CMS
X-Fastly-Request-ID
X-Ser
X-DynaTrace-JS-Agent
X-Origin-Upstream-Status
Pinterest-Version
X-Upstream-Env
X-Pinterest-Rid
X-Navigation-Version
X-B
X-Shield-Request-Id
X-Forwarded-Proto
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Amz-Rid
X-Recruiting
MS-Author-Via
DynaTrace
X-Client-IP
Realpath
X-HW
SPIisLatency
SPRequestDuration
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Upstream
Nginx-Cache
X-Vcap-Request-Id
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Length
Content-MD5
X-Wix-Server-Artifact-Id
X-Accel-Buffering
X-Amz-Meta-S3cmd-Attrs
AR-PoweredBy
AR-CACHE
AR-ATIME
Edge-Cache-Tag
X-Ttl
Arr-Disable-Session-Affinity
X-N
X-Hits
X-Varnish-Age
X-Debug
X-Mrf-Item-Lastmod
X-B3-TraceId-Primal
X-Mrf-Section-Lastmod
X-Oracle-Dms-Rid
X-Goog-Storage-Class
Mrf-Cache-Status
MRF-Tech
X-Aspnet-Version
X-NF-Request-ID
X-MSEdge-Ref
TCN
X-Acc-Meta-Resource-Type
Access-Control-Request-Method
X-Dw-Request-Base-Id
X-Id
X-Via-JSL
X-NewRelic-App-Data
S
X-XRDS-Location
X-ATG-Version
X-FTR-Cache-Status
X-Country-Code-Real
X-FTR-Balancer
X-FTR-DC
X-FTR-Backend-Server
X-FTR-Realm
X-FTR-Backend
Service-Worker-Allowed
X-Logged-In
X-FTR-Expires
X-Oneagent-Js-Injection
Alternate-Protocol
X-HS-Content-Id
Tracecode
X-HS-Hub-Id
Surrogate-Key
X-PressLabs-Stats
X-Kinsta-Cache
Rt-Fastcgi-Cache
X-Frontend
X-Content-Digest
AMP-Access-Control-Allow-Source-Origin
X-Forwarded-For
X-FastCGI-Cache
X-Pad
X-Cache-Key
Fastly-Restarts
MicrosoftSharePointTeamServices
X-FTR-Cache-Host
X-RateLimit-Remaining
X-CF-Powered-By
X-Content-Options
Server-Name
X-Ruxit-Js-Agent
X-Amzn-Trace-Id
X-Edge-Location
Fastcgi-Cache
X-Analytics
Backend-Timing
Ar-Sid
X-Grace
FilterID
TP-Cache
Host
TP-L2-Cache
X-User-Agent
X-Rid
X-Cache-2
X-Magnolia-Registration
X-Debug-Info
X-Whom
ServerID
X-B3-Sampled
X-IPLB-Instance
X-Revision
X-Hostname
Eomportal-Instance
X-Mobile
X-Page-Id
X-Request-Received
X-Request-Processing-Time
X-Srv
AR-Request-ID
X-NWS-LOG-UUID
Paypal-Debug-Id
X-AOL-HN
X-Akam-SW-Version
Front-End-Https
X-VCache
X-Content-Powered-By
Retry-After
X-Litespeed-Cache
X-B-Cache
X-Signature
Refresh
X-Device-Type
X-Cache-Action
X-Handled-By
X-Correlation-Id
X-Cluster
X-Framework
Source
X-FB-Debug
X-HS-Cache-Config
X-App-Environment
Cleartype
X-LB-Cache
X-Cache-Control
X-SS-Set-Cookie
X-WA-Info
X-Varnish-Hostname
X-Tumblr-User
X-BCube-Filmed-By
X-Tumblr-Pixel-0
X-Platform-Server
X-Instance
X-Tumblr-Pixel
X-Akamai-Edgescape
X-Request-Guid
X-Cache-Hit
X-Content-Security-Policy-Report-Only
X-Varnish-Grace
X-Fastcgi-Cache
X-TA-CDN-Provider
Webserver
X-GUploader-UploadID
X-Zen-Fury
X-AppVersion
X-Sol
X-Az
X-Varnish-Backend
X-Activity-Id
X-Middleton-Display
Display
X-XRDS-LOCATION
X-Content-Type
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
Healthy
X-Cache-Server
X-Cache-Rule
X-Daa-Tunnel
X-Varnish-Server
X-Middleton-Response
Response
X-Drupal-Cache-Tags
X-Seen-By
ViewerVersion
X-Drupal-Cache-Contexts
X-Wix-Request-Id
X-Cache-Age
X-URL
X-Cached-By
Upgrade-Insecure-Requests
X-TT
X-Generated-By
X-App-Server
X-Geo-Country
Server-Node
S-Cnection
X-Origin-Server
Cache-Status
X-DataStream-Cache-Status
X-Amz-Replication-Status
X-CACHE-GROUP
X-Amz-Apigw-Id
X-Accel-Expires
X-Amzn-RequestId
X-Esi
Payment
Accept-Charset
X-UA-Device-Type
NGB
GEO-INFO
Filters
X-Response-Served-From
X-Adobe-Loc
X-Edge-Cache
X-Edge-Cache-Key
X-S
X-Adobe-Content
X-Status
X-Cacheable-TTL
X-Servedby
X-UUID
X-Varnish-IP
Access-Control-Allow-Method
X-RequestSource
X-Locale
Viewport
X-Cache-NE
X-Contextid
X-Jobs
Actual-Object-TTL
ServedBy
X-FW-Static
X-FW-Server
X-FW-Serve
X-TT-TIMESTAMP
X-Tumblr-Pixel-1
X-Varnish-Hits
X-TX-ID
X-Tumblr-Pixel-2
X-FW-Hash
X-FW-Type
AsisCache
X-Amz-Server-Side-Encryption
X-Node-Name
Server-Info
X-WebKit-CSP-Report-Only
X-GeoIP
X-Storage
X-WPE-Loopback-Upstream-Addr
HostName
X-Dns-Prefetch-Control
Cache-Tv-Group
X-PHP-Backend
Cache
MS-CV
X-Cache-TTL-Remaining
X-Croise-Owner
Host-Header
X-Cache-Remote
X-App-Version
SRV
From-Origin
X-Rendered-As
X-Region
X-Cache-Operation
X-Hyper-Cache
X-Vg-Webcache
X-Webkit-CSP
X-Redis-Cache
Served-By
X-APP-VERSION
Cache-Tag
Liferay-Portal
Public-Key-Pins-Report-Only
X-Guploader-Uploadid
X-Dynatrace-Js-Agent
DC
X-Forwarded-Host
X-HS-Combine-CSS
X-Mode
X-CACHE-KEY
Meta-Geo
Machine
X-Upgrade-Enabled
Pagespeed
X-Proxy-Build
X-RN-RSRV
X-NGENIX-Cache
X-Endurance-Cache-Level
X-Webstats-RespID
X-Akamai-Transformed
X-Is-Bot
X-Generated
X-Cache-Var
X-Cache-Var-Map
X-Detected-As
X-Timing-Wait
Selected-FE
X-Hosted-By
X-Site-Version
X-Request-Time
X-Human
X-Path-Route
X-Agile-Age
X-Cache-Category-Id
X-Agile
X-BYPASS-REASON
X-NCache
X-Environment-Context
Cache-Name
X-Labrador-Cache-Channel
X-JoinUs
X-Internal-Host
X-Grey
X-L-Path
X-Loop
X-VG-TLSProxy
Powered-By-ChinaCache
Origin-Edge-Control
X-ProxyCache-Key
X-ProxyCache-Status
X-Agile-Id
X-Upstream-HT
Xserver
X-Upstream-CT
Now
X-B3-Spanid
X-Vgn-Hpd-Reason
X-Origin
X-Web-Node
Origin-Cache-Control
X-Original-Request
X-Via-Fastly
X-TNCMS
X-Akamai-Request-ID
X-Time-Microsecs
X-Origin-Host
X-RemovedCookies
X-Birta-Cache-Post
X-CDN-Cache
X-FC-Vary-Parameters
X-Origin-Response-Time
X-Pc-Appver
X-Pc-Hit
X-Birta-Served
X-ServerID
X-Tumblr-Pixel-3
X-Viewer-Country
X-OCL
X-ProcessESI
X-Yottaa-Metrics
X-Format
X-PCL
X-Proxy
X-Tb
DB-Nickname
X-Pc-Key
X-UA
X-Yottaa-Optimizations
X-Access
Mn-Server-Ip
X-Rule
X-Xfnlog-Site
X-Origin-CC
X-Www-Served-By
X-Pubstack
X-Via-CDN
X-Section
X-Ocache
X-Backend-Name
X-Cache-Config
X-CCM
X-IP
X-App-Name
S-Rt
Azure-Version
Cache-Tags
Azure-SiteName
Azure-RegionName
X-BACKEND-TTL
Azure-InstanceId
Fastcgi-Useragent
Azure-SlotName
Fastcgi-X-Cache
Fastcgi-X-Cache-Version
Webcakes-Region
Webcakes-App-Version
TWC-Privacy
X-Origin-Hint
HitType
X-Routing-Service
X-Proxied
Datacenter
TWC-Locale-Group
Webcakes-App-Name
TWC-Connection-Speed
Property-Id
TWC-Device-Class
TWC-GeoIP-Country
X-Zipkin-Id
TWC-GeoIP-LatLong
Cache-Key
X-TIME
Content-Script-Type
X-Kong-Upstream-Latency
X-Protected-By
Content-Style-Type
X-Kong-Proxy-Latency
X-Nginx-Cache
User-Cache-Control
X-Edge-IP
X-Akamai-Request-ID2
Vix-Hermes-Req-Id
OT-Force-Account-Verify
X-Parent-Response-Time
X-Shopify-Stage
X-Cache-TTL
X-ShardId
X-Ezoic-Cdn
X-Sorting-Hat-ShopId
X-Alternate-Cache-Key
X-ShopId
X-Sorting-Hat-PodId
X-Cdn-Forward
NtCoent-Length
X-OVcl
X-OVcl-Cache
X-RTag
Ms-Operation-Id
L5d-Success-Class
X-Real-Ip
X-RateLimit-Limit
Time
X-PERF
Accept-Language
X-ApacheServer
X-Newrelic-App-Data
X-Pc-Date
X-Pc-Host
X-Cache-Backend
X-FB-TRIP-ID
X-Unique-Id-Primal
X-Mrs-Cache
X-Mrs-Age
X-Front
X-Mrs-Cache-Hits
X-Mshield-Cache-Status
AR-SID
X-Webkit-Csp
X-Amz-Meta-Surrogate-Control
X-GRACE
X-Correlation-ID
X-Real-IP
LB
Section-Io-Cache
X-Content-Age
Country
X-Proto
X-Varnish-Cacheable
X-Nc
X-Ratelimit-Limit
X-Debug-Cache
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
Load-Balancing
X-CDN-Forward
X-Sucuri-ID
Ohc-File-Size
X-Varnish-Beresp-Ttl
X-Hit
X-Unique-ID
Fusion-Template-Id
Fusion-Content-Source
Fusion-Content-Id
Fusion-Source
Fusion-Component-Id
X-Hl-Ver
X-Trace-Id
X-MP-GENERATED-AT
WZWS-RAY
Mail-Subject
Warning
Version
X-Microcachable
We-Hiring
X-Time
X-CLOUD-TRACE-CONTEXT
User-Agent
X-EdgeConnect-Cache-Status
X-Dc
Access-Control-Request-Headers
X-C
X-CUA
X-CF-Lambda-Fn
Is-Eu
X-D
Meta-Geo-Continent
X-Crawler
X-Connection-Hash
X-CF-Lambda-Version
MD5-Digest
X-B-Cookie
RNT-Time
X-A-Dam
Rt-Proxy-Cache
X-A-Ccd
RNT-Machine
Resin-Trace
X-A-Dgt
X-Date
Request-Time
X-A
Www
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
Server-ID
Thinkindot-Control
V-Age
VivaBuild
Server-Host
Viewtype
X-A-Wwc
X-Accel-Expires-Debug
X-Cache-Debug
X-Cache-Bucket
X-Bip
X-BB-ID
X-Cache-Enabled
X-Cache-Expires
X-Cache-Id
X-Cache-Host
X-Cache-FS-Status
Mobile-Detection-Method
Node
Rendered-Blocks
X-Aed
X-Actual-URL
Release
X-Application
Platform
Powered-By
X-Auto-Login
X-Cache-URL
X-Qloud-Router
X-Server-By
X-Served-From
X-ScT
X-Server-Time
X-SRCache-Key
X-Swa-Ws
X-Store
X-S-Maxage
X-S-Cookie
X-Returned-From-BeforeDispatch
X-Returned-From
X-Returned-From-DLL
X-Returned-From-PostProcessResponse
X-Rojux
X-Rewrite-Enabled
X-Thanos
X-Thinkindot-L3
X-Via-Edge
X-VG-WebServer
X-Varnish-Action
X-Via-SSL
X-We-Are-Hiring
Xc-Version
X-WebServer
X-Variation
X-Var-Ttl
X-Trv-Group
X-Transaction
X-TT-LOGID
X-Twitter-Response-Tags
X-User
X-UE-Client-Country
X-Request-UUID
X-Release
X-Generated-In
X-G
X-FW-Version
X-GeoIP-Country-Code
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Logtrace-Id
X-Layer
X-From
X-Fetched-On
X-Device-Os
X-Developer
X-Died
X-Dispatcher-Server
X-External-Request-Id
X-DPWN-IS-SECURE
X-Matched-Rule
X-Node-Id
IBM-Web2-Location
X-PHP-Host
X-RCS-CacheZone
X-Rebelmouse-Cache-Control
X-Region-Sid
X-Rebelmouse-Surrogate-Control
X-PAYTM-SRV-ID
X-Passed-To-PostProcessResponse
X-Org
X-NU-AKA-ACS-Version
X-P-T
X-Passed-To
X-Passed-To-DLL
X-Passed-To-BeforeDispatch
X-Destination
X-A-Dcw
Fastly-Backend-Name
Arc-Country
Ec-Rule-Version
Adler-Geo
X-Ua
Fastly-SIE
Fastly-SWR
Cache-Prefix
Frame-Options
Fly-Request-Id
Fly-Cache
BehaviorPad-Version
Ajk
X-Via-NSCOPI
X-Geo
X-Fstrz
Backend
X-Gannett-Site-Version
X-F5-Cache
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
X-Gen-Mode
X-Eu-Site
Cache-Cookie-Set-From
X-Epic-Correlation-Id
X-Block-Status
X-Hash
AKAMAI
X-CGP
X-Clientip
X-Distributor
X-Amz-Meta-Cache-Control
X-Backend-State
X-Cache-CFC
X-IN-APIGATEWAY
X-Rocket-Nginx-Bypass
X-Secret
X-Response-By
X-Request-Start
X-Proxy-Upstream
X-Reboot
X-Server-Group
X-Server-IP
X-Up
PFcat
X-UnsetCookies
X-Stale
X-ServiceProvider
X-Sf
X-Proxy-Cache-Status
X-Phone
X-Li-Fabric
X-Li-Pop
X-Key
X-Info
X-IN-SSL-APIGATEWAY
X-IN-WAF
X-LI-UUID
X-MI-In-Market
X-Origin-Expires
HA-Geocity
X-Origin-Date
X-No-Session
X-Nginx-Cache-Key
X-Hnp-Log
X-LI-Proto
MI-Cache
MI-Cache-Age
MI-API
Memcached
Magicmarker
On-Server
Origin
Esi-Enabled
Server-Int
SD-X-WS
Proxy-Connection
Pramga
Kp-EeAlive
GW-Server
HA-Georegion
Ha-Gx-Prefs
HA-Geolon
HA-Geolat
HA-Geocountry
HA-Host
HA-Ipaddr
HA-Cloudapp
Heartbleed
HA-Urlpath
HA-Servedtime
SS
GMS-Ver
Decoy-Debug-Key
Country-Code
Countrycode
True-Client-Country-4JS
Content-Disposition
Decoy-Debug-Status
Web-Mar-Node
Decoy-Debug-TTL
X-Be
X-NODE
Apple-News-Services-Handled
X-MSEdge-Flight
X-Backend-Host
X-MSEdge-Features
X-Location
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Pragrma
X-Backend-Url
X-Irp-Debug
X-Request-URI
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
Who
X-V
X-SIPLIST1
Backend-Name
Apple-News-Services-Request-Url
X-Policy
IsBot
X-Fastly-Cache
X-Page-Type
X-Platform
X-ElasticPress-Search
REQUESTUUID
Fastly-SSL
X-Distil-CS
X-Core-Mission
X-Core-Value
Pagetype
X-Refresh
Locale
X-Planisys-CDN-TTL
X-Origin-TTL
X-NX-Host
X-Developers
X-Debug-Log
X-Debug-Cookies
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
UCS
X-Cdn-Origin
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Svr
X-Micro-Cache
X-Wikidot-Static-Cache
X-Urbn-Context-Path
X-Urbn-Site-Id
CDCHOST
X-Wikidot-Backend
X-Sn-Servicetimems
Uber-Trace-Id
Request-EU
X-Instance-Name
Fastly-Soc-X-Request-Id
Request-Country
X-Level-Front-Cache
X-COUNTRY
X-Servername
X-Generated-On
X-Instart-Info
X-DC
RequestId
X-NWS-UUID-VERIFY
Group
X-Newrelic-Synthetics
V-Cache
X-Pjax-Url
X-GeoIP-City
X-VCT
Lfy
X-PARISIEN-Cache-Rendered
X-VarnPar1
Host-ID
X-VarnCache
ServerName
PageSpeed
X-Cdn-Srv
X-Cache-Info
HitInfo
Ohc-Response-Time
X-CACHE-AGE
X-Server-Cache
X-Req
X-NC
X-ARC
Mime-Version
X-Datadome
MIME-Version
X-BBXSRF
Cdn
Cache-Provider
X-Powered-By-ANYU
Cteonnt-Length
Memory
X-EIG-Tracking-Id
X-Gdpr
PICS-Label
X-CMS-Context
X-TWH-CORRELATION-ID
X-Servedbyhost
X-Ratelimit-Remaining
Nel
X-LAGOON
X-WR-MODIFICATION
X-Aicache-OS
X-Wa
NGX
X-StackifyID
X-Load-Cache
CF-IPCountry
X-Cluster-Node
X-B3-Traceid
GeoIP-Country-Code
X-Fastly-Country-Code
GeoIP-Latitude
CDN
Cf-Ipcountry
XServer
X-Sentry-ID
FSS-Cache
X-Fastly-Backend-Reqs
FSS-Proxy
X-CSRF-TOKEN
X-NodeID
X-HTML-Minification-Powered-By
X-Check-Cacheable
X-UPSTREAM-Address
Geoip-Latitude
X-Flog
X-ABtesting
GeoIp-Country-Code
X-Hello
X-FireWall-Port
X-VServer
X-WA
X-Varnish-Cache-Hits
Processtime
X-Generation-Time
X-RateLimit-Remaining-Second
Amp-Access-Control-Allow-Source-Origin
X-Varnish-Beresp-TTL
X-RateLimit-Limit-Second
SN
X-Source
X-Csrf-Token
X-Unique-Id
X-HOST
X-APP
X-Cache-Miss-From
X-FORWARDED-FOR
X-GZip
X-Sedo-Request-Id
X-CSRF-Token
CACHE
X-Oss-Server-Time
X-Oss-Storage-Class
TSSecure
X-Nananana
X-Oss-Request-Id
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-CDN-Pop
WP-Super-Cache
X-Cache-Grace
X-ServedByHost
X-CDN-Pop-IP
X-Edge-Server
Cdn-Request-Time
X-DataStream-MidMile-RTT
X-GDPR
X-Dynatrace
X-Cache-ASPX
X-MServer
Pics-Label
Server-Cache-Control
Server-Surrogate-Control
X-Worker
X-Varnish-Authentication
X-DataStream-Origin-MEX-Latency
Cdn-Host
X-SRV
X-RCS-Backend
URI
A
X-VC-Cache
X-IPS-LoggedIn
X-VG-WebCache
X-Skip-Cache
X-ID
DataCenter
PageType
X-HS-Status
X-Sucuri-Cache
X-Varnish-Url
X-Fastly-Cache-Hits
X-SplitTest
X-Port
X-Instart-Isnd
X-ND-Cache
HTTPS
X-VWS-Id
X-LJ-Flow-ID
X-AWS-Id
X-B3-SpanId
X-BE
X-Swift-Error
Get-Access-Time
X-PJAX-URL
Is-Session-Tracking
X-From-Cache
Dynatrace
Hostname
Odigeo-Trace-Id
X-Backend-TTL
X-Gen-Id
X-GoCache-CacheStatus
X-Bug-Bounty
X-GZIP
X-SN
Cache-Hits
X-Amzn-Remapped-Connection
X-Owner
X-Server-W
X-Pf-Uncompressing
Proxy-Firewall
X-Amzn-Remapped-Date
X-ORIG-AKA-EDGE
X-VarnPar2
X-NGINX-Cache
X-Cache-Ttl
Powered
Requestid
X-Amz-Meta-S3b-Last-Modified
X-Ms-Request-Id
X-Ms-Version
Serverid
X-Ms-Lease-Status
X-Ms-Blob-Type
X-Akamai-SSL-Client-Sid
X-PAGE-TYPE
RequestUuid
X-Varnish-URL
X-Alicdn-Da-Ups-Status
X-GEO
X-VC
X-Fe
X-RAMCache
X-SB
X-LiteSpeed-Cache-Control
T-Server
X-ORIG-AKA-COUNTRY-CODE
X-ServerName
WebServer
X-Serial
ProcessTime
Xet-Cookie
X-Akamai-ERRuleID
NodeID
X-RequestId
X-Developed-By
Correlation-Id
X-PF-Uncompressing
X-LiteSpeed-Tag
X-CS
X-HTML-Edge-Cache
X-Ms-Lease-State
NnCoection
SID
Location
X-Akamai-ERPolicy
X-Dw-Trace-Id