Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
Last-Modified
X-Content-Type-Options
Accept-Ranges
Pragma
X-Powered-By
CF-RAY
Link
ETag
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Id
X-Served-By
Referrer-Policy
X-Varnish
X-Request-Id
X-Timer
CF-Cache-Status
X-AspNet-Version
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Xss-Protection
X-Runtime
X-Download-Options
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Cacheable
Alt-Svc
X-Check
X-Generator
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Cache-Status
X-AspNetMvc-Version
Status
X-DNS-Prefetch-Control
X-Template
Timing-Allow-Origin
X-Language
X-Permitted-Cross-Domain-Policies
Content-Encoding
X-Iinfo
X-FRAME-OPTIONS
X-Content-Security-Policy
X-CDN
X-Buckets
X-Turbo-Charged-By
P3p
X-Request-ID
Upgrade
X-Type
WPE-Backend
Keep-Alive
X-Pass-Why
X-Cache-Group
X-AH-Environment
Xkey
CF-Ray
X-Backend
Access-Control-Max-Age
X-Age
Access-Control-Expose-Headers
X-Via
X-Drupal-Dynamic-Cache
EagleId
X-Pingback
X-Nginx-Cache-Status
X-Amz-Request-Id
X-Amz-Id-2
X-Server-Powered-By
X-Server
X-Hacker
Grace
X-UA-Device
X-Kinja-Server-Push
X-Swift-SaveTime
X-Swift-CacheTime
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-Robots-Tag
Cf-Railgun
X-Proxy-Cache
X-Envoy-Upstream-Service-Time
X-LiteSpeed-Cache
X-Page-Speed
X-Ua-Compatible
Request-Context
X-Device
X-Ac
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
Content-Location
X-Cache-Lookup
X-Amz-Version-Id
X-Host
X-Response-Time
Surrogate-Control
X-OneAgent-JS-Injection
X-Rq
X-Cnection
X-Node
X-Backend-Server
X-Server-Id
X-WebKit-CSP
Server-Timing
X-Readtime
Report-To
X-Rack-Cache
Request-Id
EagleEye-TraceId
X-Application-Context
X-Cloud-Trace-Context
Feature-Policy
X-ORACLE-DMS-ECID
X-Instart-Request-ID
X-CST
X-Iejgwucgyu
Edge-Control
X-Clacks-Overhead
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
NEL
Rating
X-Url
X-Country
X-Server-Name
X-Varnish-TTL
X-MS-InvokeApp
X-DynaTrace
X-TTL
X-DataDome
Allow
X-Country-Code
X-Px
Pinterest-Generated-By
X-Origin-Cache
X-Vhost
X-TtlSet
X-Vname
X-PC
X-Cached
X-FTR-Request-ID
X-ESI
RTSS
X-Ruxit-JS-Agent
X-Goog-Hash
SPRequestGuid
X-Trace
X-VARITI-CCR
Charset
X-Powered-By-Plesk
X-SharePointHealthScore
X-GitHub-Request-Id
Accept-CH
X-Powered-CMS
X-Dispatcher
X-T
Public-Key-Pins
X-D2id
X-Mod-Pagespeed
X-DynaTrace-JS-Agent
X-Server-ID
PB-PID
X-Mobile-Rewrite
PB-RID
Arc-Version
X-F-Cache
Verso
X-B3-TraceId
X-Kinja-Revision
X-Kinja
X-Kinja-Build
X-Exp-Id
X-Kinja-Server
X-Exp-Variant
X-GoogleNews-Bot
X-Cdn-Fetch
Content-MD5
X-Version
MS-Author-Via
X-Oracle-Dms-Rid
SPRequestDuration
SPIisLatency
X-Shield-Request-Id
X-Recruiting
X-Abt-Application-Version
X-Dns-Prefetch-Control
Nginx-Cache
X-TEC-API-ROOT
X-Forwarded-Proto
X-TEC-API-VERSION
X-Client-IP
X-TEC-API-ORIGIN
Accept-CH-Lifetime
X-HW
X-ORACLE-DMS-RID
X-DIS-Request-ID
X-N
X-Navigation-Version
X-Upstream-Env
X-Pinterest-Rid
Pinterest-Version
AR-PoweredBy
AR-ATIME
AR-CACHE
X-B
X-Amz-Rid
X-Fastly-Request-ID
X-Upstream
X-Origin-Upstream-Status
DynaTrace
X-Dw-Request-Base-Id
X-Ser
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Amz-Meta-S3cmd-Attrs
Fastly-Restarts
X-Hits
Realpath
TCN
X-Wix-Server-Artifact-Id
X-Accel-Buffering
Paypal-Debug-Id
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Content-Options
X-Webkit-Csp
Arr-Disable-Session-Affinity
X-XRDS-Location
Service-Worker-Allowed
X-NF-Request-ID
X-Pad
X-Acc-Meta-Resource-Type
X-Goog-Storage-Class
Tracecode
S
Access-Control-Request-Method
X-Content-Digest
X-Id
X-Debug
X-Varnish-Age
Front-End-Https
X-Mrf-Item-Lastmod
MRF-Tech
X-Mrf-Section-Lastmod
Mrf-Cache-Status
X-Vcap-Request-Id
X-Use-Magma
X-MSEdge-Ref
Edge-Cache-Tag
X-Oneagent-Js-Injection
X-Frontend
X-ATG-Version
X-FTR-Realm
X-IPLB-Instance
X-PressLabs-Stats
X-FTR-Backend-Server
X-FTR-DC
X-FTR-Balancer
X-FTR-Backend
X-FTR-Cache-Status
X-Country-Code-Real
X-FTR-Expires
X-Kinsta-Cache
X-Logged-In
X-RateLimit-Remaining
MicrosoftSharePointTeamServices
X-HS-Hub-Id
X-HS-Content-Id
Surrogate-Key
X-Amz-Cf-Pop
X-Cache-Hit
X-Forwarded-For
X-Sol
Display
Rt-Fastcgi-Cache
X-Middleton-Display
Fastcgi-Cache
X-Request-Processing-Time
X-Request-Received
X-B3-TraceId-Primal
Powered-By-ChinaCache
X-Edge-Location
X-Zen-Fury
X-Grace
X-Analytics
Backend-Timing
Server-Name
X-Rid
X-Debug-Info
X-Amzn-Trace-Id
X-Revision
Host
X-User-Agent
X-Fastcgi-Cache
TP-L2-Cache
TP-Cache
X-FTR-Cache-Host
FilterID
X-CF-Powered-By
X-Litespeed-Cache
X-HS-Cache-Config
X-Akam-SW-Version
X-Middleton-Response
Response
X-FastCGI-Cache
X-Cache-Key
AMP-Access-Control-Allow-Source-Origin
X-Mobile
X-Drupal-Cache-Tags
Ar-Sid
X-NewRelic-App-Data
X-SS-Set-Cookie
X-Ruxit-Js-Agent
AR-Request-ID
X-TA-CDN-Provider
X-Magnolia-Registration
Refresh
X-Accel-Expires
Cache-Status
X-Cached-By
Host-Header
X-SERVER
X-Newrelic-App-Data
X-Ttl
ServerID
X-B3-Sampled
X-Varnish-Backend
X-AOL-HN
X-Node-Name
X-Content-Security-Policy-Report-Only
X-Whom
X-Tumblr-Pixel
Eomportal-Instance
X-Cluster
X-Instance
X-Tumblr-User
X-FB-Debug
X-NWS-LOG-UUID
X-Tumblr-Pixel-0
X-Cache-2
X-Signature
X-Cache-Control
X-B-Cache
X-Platform-Server
X-Akamai-Edgescape
X-Webkit-CSP
X-BCube-Filmed-By
X-App-Environment
X-Device-Type
X-VCache
X-Framework
X-Varnish-Hostname
X-Page-Id
X-LB-Cache
X-Handled-By
X-Srv
Cleartype
X-Generated-By
X-Via-JSL
X-Request-Guid
X-Drupal-Cache-Contexts
X-GUploader-UploadID
X-AppVersion
X-Cache-Rule
Cache-Tag
X-Activity-Id
X-Az
X-Cache-Action
DC
Liferay-Portal
X-App-Server
X-WPE-Loopback-Upstream-Addr
X-Cache-Server
Source
Alternate-Protocol
X-Content-Powered-By
Retry-After
X-Hostname
MS-CV
X-Correlation-Id
X-HS-Combine-CSS
Public-Key-Pins-Report-Only
X-Varnish-Grace
X-WA-Info
HostName
X-App-Version
X-Geo-Country
X-Varnish-Server
AR-SID
X-TT
X-Seen-By
X-Amz-Replication-Status
X-Wix-Request-Id
ViewerVersion
Server-Node
Accept-Charset
Pagespeed
X-Esi
Webserver
X-Daa-Tunnel
Upgrade-Insecure-Requests
X-Cache-NE
X-Response-Served-From
X-WebKit-CSP-Report-Only
X-XRDS-LOCATION
AsisCache
X-Tumblr-Pixel-1
X-Tumblr-Pixel-2
X-Locale
X-GeoIP
Actual-Object-TTL
X-Amz-Apigw-Id
X-Amzn-RequestId
SRV
X-RequestSource
GEO-INFO
X-URL
ServedBy
X-Jobs
X-Varnish-Hits
X-S
X-Servedby
Viewport
Payment
X-Contextid
X-FW-Server
X-FW-Static
X-FW-Hash
X-FW-Type
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Geo-Segment
X-FW-Serve
X-Status
X-Edge-Cache-Key
X-UUID
X-Edge-Cache
Cache
X-Varnish-IP
X-TX-ID
X-Adobe-Content
X-Adobe-Loc
X-Cacheable-TTL
X-TT-TIMESTAMP
X-Origin-Server
X-Cache-TTL-Remaining
S-Cnection
X-Vg-Webcache
X-Cache-Age
X-Hyper-Cache
X-Correlation-ID
X-Forwarded-Host
X-Amz-Server-Side-Encryption
Server-Info
X-Cache-Operation
Datacenter
X-RateLimit-Limit
X-Region
Served-By
X-Akamai-Request-ID2
X-DataStream-Cache-Status
X-Sucuri-ID
Access-Control-Allow-Method
X-Mode
Healthy
X-Content-Type
Country
X-CLOUD-TRACE-CONTEXT
X-Guploader-Uploadid
X-Akamai-Transformed
From-Origin
X-Cache-Var-Map
X-Upgrade-Enabled
X-Cache-Var
X-Proxy
X-Rule
X-Site-Version
X-Detected-As
X-Environment-Context
X-Cache-Config
X-JoinUs
Meta-Geo
Machine
Fastcgi-X-Cache-Version
Fastcgi-X-Cache
X-L-Path
X-Rendered-As
X-Generated
X-Is-Bot
X-RN-RSRV
X-Ocache
X-Path-Route
X-Agile-Age
X-Viewer-Country
X-Birta-Served
X-Hosted-By
X-Human
X-Via-CDN
X-Section
X-EIG-Tracking-Id
X-CDN-Cache
X-Request-Time
X-NGENIX-Cache
X-Access
Now
Fastcgi-Useragent
X-Agile
X-Agile-Id
X-Birta-Cache-Post
X-Format
DB-Nickname
L5d-Success-Class
CACHE
X-Ezoic-Cdn
X-Real-IP
Xserver
X-OCL
X-Origin-Hint
X-TIME
X-Pc-Appver
Webcakes-Region
X-Cache-Category-Id
X-Amz-Meta-Surrogate-Control
X-Labrador-Cache-Channel
X-FC-Vary-Parameters
X-Real-Ip
X-Grey
X-Hit
X-Pc-Hit
X-CCM
X-Loop
X-PCL
TWC-Device-Class
X-TNCMS
X-Tb
TWC-Connection-Speed
X-Via-Fastly
OT-Force-Account-Verify
Property-Id
X-ServerID
TWC-GeoIP-Country
TWC-Privacy
Webcakes-App-Name
Webcakes-App-Version
X-Pc-Key
TWC-Locale-Group
Cache-Name
TWC-GeoIP-LatLong
S-Rt
X-BYPASS-REASON
X-Microcachable
X-Routing-Service
X-RemovedCookies
X-Pubstack
X-Upstream-CT
X-Upstream-HT
X-Web-Node
X-Zipkin-Id
X-VG-TLSProxy
X-ProxyCache-Status
X-ProxyCache-Key
X-Origin
HitType
X-IP
X-Original-Request
X-OVcl
X-Proxied
X-ProcessESI
X-OVcl-Cache
X-Cluster-Node
X-Xfnlog-Site
Azure-Version
Azure-SlotName
Azure-SiteName
Azure-RegionName
HitInfo
Azure-InstanceId
LB
X-Shopify-Stage
X-ShardId
X-Alternate-Cache-Key
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Timing-Wait
Mn-Server-Ip
X-Www-Served-By
X-ShopId
Selected-FE
X-Proxy-Build
Origin-Cache-Control
Origin-Edge-Control
Accept-Language
X-Cdn
NGB
X-TWH-CORRELATION-ID
X-App-Name
X-Cdn-Forward
X-Transaction
X-Geo
X-Connection-Hash
Ms-Operation-Id
X-RTag
X-Rocket-Nginx-Bypass
X-Twitter-Response-Tags
Filters
X-Cache-Enabled
X-UA
X-GRACE
X-Cache-Remote
X-AWS-Id
X-VWS-Id
X-SplitTest
X-LJ-Flow-ID
IBM-Web2-Location
Content-Style-Type
Time
Content-Script-Type
Access-Control-Request-Headers
X-NCache
X-Internal-Host
X-NodeID
X-Pc-Host
X-Nginx-Cache
X-Pc-Date
X-Tumblr-Pixel-3
X-Source
Cache-Hits
NtCoent-Length
X-Unique-ID
X-Origin-CC
X-UA-Device-Type
X-Proto
X-Cache-TTL
X-MP-GENERATED-AT
Mail-Subject
We-Hiring
X-Port
X-Ms-Request-Id
X-APP-VERSION
X-Ms-Lease-Status
X-CACHE-KEY
X-Ms-Version
X-Ms-Blob-Type
X-Edge-IP
Backend
X-Storage
X-Distil-CS
X-PHP-Backend
X-Vgn-Hpd-Reason
X-Debug-Cache
X-Varnish-Cacheable
X-Time-Microsecs
X-Webstats-RespID
X-Dynatrace-Js-Agent
X-Backend-Name
Cache-Tags
X-Akamai-Request-ID
PageSpeed
X-Ratelimit-Limit
X-CACHE-GROUP
X-Endurance-Cache-Level
X-Csrf-Token
X-Urbn-Context-Path
X-Dc
Locale
X-Urbn-Site-Id
X-Ua
X-Nc
X-Redis-Cache
X-Varnish-Cache-Hits
X-Varnish-Beresp-Grace
User-Agent
X-Varnish-Beresp-Status
X-EdgeConnect-Cache-Status
Warning
X-B3-Spanid
X-Origin-Response-Time
X-ApacheServer
X-Croise-Owner
X-PERF
X-Mrs-Cache
X-Mrs-Cache-Hits
X-Mshield-Cache-Status
Fastly-SSL
X-Mrs-Age
X-ElasticPress-Search
X-C
SN
HA-Geocountry
HA-Geolat
X-From
X-NX-Host
HA-Cloudapp
X-Org
Server-Host
HA-Geocity
HA-Geolon
HA-Urlpath
HA-Servedtime
MD5-Digest
X-F5-Cache
UCS
HA-Ipaddr
HA-Host
Ajk
X-Fetched-On
HA-Georegion
Ha-Gx-Prefs
TSSecure
X-PAYTM-SRV-ID
Rt-Proxy-Cache
Rendered-Blocks
Content-Disposition
Mobile-Detection-Method
Cache-Prefix
Fly-Cache
X-Trv-Group
X-IN-SSL-APIGATEWAY
X-External-Request-Id
Powered-By
Ec-Rule-Version
X-Hash
Odigeo-Trace-Id
X-IN-APIGATEWAY
Fly-Request-Id
X-IN-WAF
X-Generated-In
Meta-Geo-Continent
Resin-Trace
X-Irp-Debug
X-Logtrace-Id
GMS-Ver
FSS-Proxy
X-Server-Time
FSS-Cache
X-GeoIP-Country-Code
BehaviorPad-Version
X-NU-AKA-ACS-Version
Arc-Country
X-G
X-A-Dcw
X-Via-Edge
X-B-Cookie
X-Cache-Bucket
X-Store
X-Application
X-Died
X-Sn-Servicetimems
Cache-Key
X-Amz-Meta-Cache-Control
Xc-Version
X-Sucuri-Cache
X-UE-Client-Country
X-Developer
X-BBXSRF
X-BB-ID
X-SRCache-Key
X-S-Cookie
X-Rojux
X-Via-SSL
X-Debug-Log
X-Rewrite-Enabled
X-Destination
X-Aed
X-DPWN-IS-SECURE
X-Cache-Backend
X-CF-Lambda-Version
X-Server-By
X-CF-Lambda-Fn
X-CGP
X-Region-Sid
V-Age
Viewtype
VivaBuild
X-Eu-Site
X-A
X-Cdn-Origin
X-Date
X-Debug-Cookies
X-VG-WebServer
X-Accel-Expires-Debug
X-A-Wwc
X-A-Dgt
X-A-Ccd
X-A-Dam
X-Cache-Host
X-D
X-ScT
X-CACHE-AGE
X-Cache-Id
Thinkindot-CacheControl
X-Flog
IsBot
X-FW-Version
Thinkindot-CacheControl-Type
Thinkindot-Control
X-Key
X-Layer
X-Clientip
Www
X-Epic-Correlation-Id
Server-ID
X-ABtesting
X-Hello
Pramga
X-Hl-Ver
X-Backend-State
X-Backend-Url
Release
X-Backend-Host
Memcached
X-Dispatcher-Server
X-Auto-Login
X-GeoIP-City
X-Developers
Apple-News-Services-Request-Url
X-Reboot
X-Rebelmouse-Surrogate-Control
X-Release
X-Request-Start
X-Request-URI
X-Trace-Id
X-Rebelmouse-Cache-Control
Apple-News-Services-Host
Apple-News-Services-Handled
AKAMAI
X-Platform
X-Response-By
X-We-Are-Hiring
X-Via-NSCOPI
X-VServer
X-SIPLIST1
X-ServiceProvider
X-Var-Ttl
X-User
X-Wikidot-Backend
X-UnsetCookies
X-Cache-URL
X-Wikidot-Static-Cache
X-S-Maxage
Apple-News-Services-Parsed-Url
X-Thinkindot-L3
GW-Server
Frame-Options
Countrycode
Decoy-Debug-TTL
X-Matched-Rule
Country-Code
Decoy-Debug-Key
Decoy-Debug-Status
Fastly-SIE
X-Location
Fastly-SWR
X-MServer
X-No-Session
Fastly-Soc-X-Request-Id
Heartbleed
Version
X-Device-Os
X-Instance-Name
X-SVT-ORM-RULES
X-Info
X-Stale
X-Secret
X-Returned-From-PostProcessResponse
X-LI-UUID
X-Served-From
X-Crawler
X-Server-IP
X-V
X-Li-Pop
X-Core-Value
X-CUA
X-Variation
X-Worker
X-WebServer
X-LI-Proto
X-VCT
X-Varnish-Action
X-Sf
X-Sentry-ID
X-Up
X-MI-In-Market
X-Phone
X-Policy
X-Powered-By-ANYU
X-Qloud-Router
X-Passed-To-PostProcessResponse
X-Passed-To-DLL
X-Gannett-Site-Version
X-Gen-Mode
X-P-T
X-Passed-To
X-Passed-To-BeforeDispatch
X-Fastly-Cache
X-RCS-CacheZone
X-Returned-From
X-Node-Id
X-Distributor
X-Core-Mission
X-Returned-From-BeforeDispatch
X-Hnp-Log
X-Request-UUID
X-Li-Fabric
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Thanos
X-Swa-Ws
X-SVT-ORM-VERSION
X-Returned-From-DLL
Request-Country
Origin
On-Server
MI-Cache-Age
MI-Cache
Platform
Pragrma
Section-Io-Cache
RNT-Time
RNT-Machine
Request-EU
Magicmarker
Kp-EeAlive
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Storage-Class
X-NWS-UUID-VERIFY
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
Is-Eu
Fastly-Backend-Name
Backend-Name
Adler-Geo
Server-Int
Esi-Enabled
WZWS-RAY
Web-Mar-Node
X-Actual-URL
X-Bip
X-Cache-Expires
X-Cache-Debug
User-Cache-Control
X-Block-Status
True-Client-Country-4JS
Uber-Trace-Id
X-Parent-Response-Time
X-Datadome
X-NC
X-Varnish-Beresp-Ttl
X-Nginx-Cache-Key
Cache-Cookie-Set-Idcheck
CDCHOST
Cache-Cookie-Set-From
X-MSEdge-Flight
X-MSEdge-Features
X-Cache-FS-Status
X-Cache-CFC
X-Refresh
X-Newrelic-Synthetics
X-TT-LOGID
X-Owner
REQUESTUUID
X-Fstrz
Cache-Cookie-Set-Lfrom
Proxy-Connection
MI-API
X-CDN-Forward
X-NODE
X-HOST
Cteonnt-Length
RequestId
X-Unique-Id-Primal
X-DC
X-Page-Type
Amp-Access-Control-Allow-Source-Origin
Group
V-Cache
HTTPS
Pagetype
X-Pjax-Url
X-Be
X-Backend-TTL
Who
X-SN
X-Req
X-Cache-Srv
X-Servername
Fusion-Source
MIME-Version
X-Ms-Lease-State
X-GZip
Fusion-Component-Id
X-Time
X-Kong-Upstream-Latency
NodeID
Fusion-Content-Source
X-Kong-Proxy-Latency
Fusion-Content-Id
Fusion-Template-Id
X-Oracle-Dms-Ecid
Memory
Cdn
ProcessTime
Mime-Version
X-Origin-TTL
Cdn-Request-Time
X-Edge-Server
Cdn-Host
X-BB-IP
X-Content-Age
X-Protected-By
SS
X-Server-Group
SD-X-WS
X-Aicache-OS
X-Ckpd-Fst-Backend
X-ND-Cache
CF-IPCountry
X-Servedbyhost
X-Varnish-Beresp-TTL
PageType
X-COUNTRY
A
GeoIP-Country-Code
X-Wa
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Origin-Date
X-Origin-Expires
X-SRV
GeoIP-Latitude
CDN
X-Origin-Host
Get-Access-Time
X-Ratelimit-Remaining
X-APP
Is-Session-Tracking
X-Unique-Id
XServer
X-Varnish-Url
Geoip-Latitude
X-WA
GeoIp-Country-Code
X-Fastly-Country-Code
X-Pf-Uncompressing
X-StackifyID
X-B3-Traceid
X-CSRF-Token
PICS-Label
X-Cache-Info
Serverid
Processtime
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Generation-Time
X-PHP-Host
Node
X-Requestid
X-Gdpr
Vix-Hermes-Req-Id
X-Fastly-Cache-Hits
X-FireWall-Port
Cf-Ipcountry
X-Proxy-Cache-Status
X-Proxy-Upstream
X-Check-Cacheable
X-Nananana
Nel
Cache-Tv-Group
X-Load-Cache
X-ID
X-ServedByHost
X-UPSTREAM-Address
X-EC-Security-Audit
X-CS
X-RequestId
URI
DataCenter
X-SERVER-NAME
X-BACKEND-TTL
X-GEO
X-HS-Status
X-Planisys-CDN-TTL
Cache-Provider
X-Server-W
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-FORWARDED-FOR
X-WR-MODIFICATION
Hostname
X-VG-WebCache
X-Fastly-Backend-Reqs
T-Server
X-Surge-Debug
X-NGINX-Cache
NGX
X-GZIP
Request-Time
X-Vcache
X-Micro-Cache
Host-ID
PFcat
X-HTML-Minification-Powered-By
WP-Super-Cache
X-Qnm-Cache
X-Front
X-B3-SpanId
X-M-Reqid
X-M-Log
X-PF-Uncompressing
X-Debug-Cache-Store
X-DataStream-MidMile-RTT
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-HTML-Edge-Cache
X-DataStream-Origin-MEX-Latency
X-Fe
X-BE
X-ServerName
X-Atg-Version
ServerName
Https
Requestid
RequestUuid
X-IPS-LoggedIn
Load-Balancing
X-GDPR
X-PJAX-URL
X-FB-TRIP-ID
X-Alicdn-Da-Ups-Status
X-PARISIEN-Cache-Rendered
X-VarnPar1
X-VarnCache
X-Svr
X-Akamai-SSL-Client-Sid
X-Amz-Meta-S3b-Last-Modified
Lfy
Ohc-File-Size
X-Skip-Cache
X-Cdn-Srv
X-ARC
N-Cache
X-VC
X-From-Cache
X-Serial
X-VarnPar2
X-Swift-Error
X-Cache-Ttl
X-Level-Front-Cache
X-PAGE-TYPE
Ohc-Response-Time
WebServer
X-Generated-On
X-Distil-Cs
X-SB
X-Instart-Info
Pics-Label
X-Gen-Id
X-Dw-Trace-Id
Build-Number
Cdn-Src-Port
X-RAMCache
X-Grace-Duration
X-Proxy-Server
X-Feature
SID