Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Accept-Ranges
Pragma
X-Powered-By
Link
ETag
CF-RAY
Expect-CT
Via
X-XSS-Protection
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Id
X-Served-By
P3P
Referrer-Policy
X-Varnish
X-Xss-Protection
X-Timer
CF-Cache-Status
X-Request-Id
Access-Control-Allow-Headers
X-AspNet-Version
Access-Control-Allow-Methods
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
P3p
CF-Ray
X-Drupal-Cache
X-Check
X-Adblock-Key
Alt-Svc
X-Cacheable
X-Generator
Content-Security-Policy-Report-Only
X-Amz-Cf-Pop
X-Cache-Status
X-Request-ID
X-AspNetMvc-Version
Status
X-DNS-Prefetch-Control
X-Template
X-Language
Timing-Allow-Origin
Content-Encoding
X-Permitted-Cross-Domain-Policies
X-Iinfo
X-Buckets
X-Content-Security-Policy
X-Turbo-Charged-By
Upgrade
X-Kinja-Server-Push
X-CDN
X-Type
Xkey
Keep-Alive
Access-Control-Expose-Headers
WPE-Backend
X-Pass-Why
X-AH-Environment
Access-Control-Max-Age
X-Backend
X-Cache-Group
X-Server
X-Age
X-Drupal-Dynamic-Cache
X-Pingback
X-Via
X-Nginx-Cache-Status
X-Amz-Id-2
X-Amz-Request-Id
Grace
X-Server-Powered-By
X-Hacker
EagleId
X-UA-Device
X-Robots-Tag
X-LiteSpeed-Cache
X-Varnish-Cache
X-Page-Speed
X-Swift-CacheTime
X-Swift-SaveTime
X-Proxy-Cache
Cf-Railgun
X-Envoy-Upstream-Service-Time
Request-Context
Ali-Swift-Global-Savetime
X-Ua-Compatible
X-Ac
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-WebKit-CSP
X-Cache-Lookup
Content-Location
X-Amz-Version-Id
X-Server-Id
Surrogate-Control
X-Host
X-Node
X-Cnection
Report-To
X-Readtime
X-Rq
EagleEye-TraceId
Server-Timing
X-Response-Time
X-OneAgent-JS-Injection
Feature-Policy
X-CST
X-Rack-Cache
X-Backend-Server
X-ORACLE-DMS-ECID
X-Application-Context
X-Iejgwucgyu
Request-Id
X-Instart-Request-ID
X-Cloud-Trace-Context
X-Clacks-Overhead
X-Url
NEL
Edge-Control
X-DynaTrace
Rating
Allow
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Country
X-Varnish-TTL
X-Origin-Cache
X-FTR-Request-ID
X-Country-Code
X-Cdn
X-Trace
X-B3-TraceId
X-Server-Name
X-Px
X-DataDome
X-Vhost
X-GitHub-Request-Id
X-ORACLE-DMS-RID
RTSS
X-MS-InvokeApp
X-VARITI-CCR
X-Cached
X-ESI
X-Ruxit-JS-Agent
Accept-CH
X-Goog-Hash
SPRequestGuid
Charset
X-Server-ID
X-Vname
X-TtlSet
X-PC
Pinterest-Generated-By
X-Mod-Pagespeed
Public-Key-Pins
X-D2id
X-F-Cache
Verso
X-Kinja-Build
X-Use-Magma
X-Kinja-Revision
X-Kinja
X-Kinja-Server
X-Exp-Variant
X-GoogleNews-Bot
X-Cdn-Fetch
X-Dispatcher
X-Exp-Id
PB-PID
X-Mobile-Rewrite
Arc-Version
PB-RID
X-SharePointHealthScore
X-T
X-Version
X-Powered-By-Plesk
X-DynaTrace-JS-Agent
X-TTL
X-Abt-Application-Version
Accept-CH-Lifetime
X-Powered-CMS
X-DIS-Request-ID
X-Dns-Prefetch-Control
X-Ser
X-Fastly-Request-ID
Pinterest-Version
X-Pinterest-Rid
X-Upstream-Env
X-Navigation-Version
X-Origin-Upstream-Status
X-Forwarded-Proto
X-Shield-Request-Id
X-B
X-Recruiting
X-Client-IP
DynaTrace
MS-Author-Via
X-Amz-Rid
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Ttl
X-HW
SPRequestDuration
SPIisLatency
Realpath
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Oneagent-Js-Injection
Content-MD5
X-Upstream
Nginx-Cache
X-Vcap-Request-Id
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Wix-Server-Artifact-Id
X-Accel-Buffering
X-Amz-Meta-S3cmd-Attrs
AR-ATIME
AR-CACHE
AR-PoweredBy
Edge-Cache-Tag
X-N
X-Hits
Arr-Disable-Session-Affinity
X-Debug
TCN
X-Varnish-Age
X-Oracle-Dms-Rid
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-NF-Request-ID
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
Access-Control-Request-Method
X-Goog-Storage-Class
X-MSEdge-Ref
X-Acc-Meta-Resource-Type
X-Dw-Request-Base-Id
S
X-Id
X-ATG-Version
X-XRDS-Location
X-Via-JSL
X-Country-Code-Real
X-FTR-DC
Service-Worker-Allowed
X-FTR-Backend
X-FTR-Realm
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Cache-Status
X-NewRelic-App-Data
X-Logged-In
X-FTR-Expires
X-FastCGI-Cache
Tracecode
Alternate-Protocol
X-HS-Content-Id
X-Forwarded-For
Rt-Fastcgi-Cache
X-HS-Hub-Id
X-PressLabs-Stats
X-Frontend
X-Content-Digest
X-Kinsta-Cache
Surrogate-Key
X-Pad
X-RateLimit-Remaining
X-Cache-Key
AMP-Access-Control-Allow-Source-Origin
Fastly-Restarts
MicrosoftSharePointTeamServices
X-Content-Options
X-FTR-Cache-Host
X-Grace
X-Ruxit-Js-Agent
X-Edge-Location
Server-Name
X-Amzn-Trace-Id
Ar-Sid
Fastcgi-Cache
X-Analytics
Backend-Timing
FilterID
X-CF-Powered-By
Host
TP-Cache
TP-L2-Cache
X-Rid
X-User-Agent
X-Debug-Info
X-Hostname
X-IPLB-Instance
X-B3-Sampled
X-Whom
X-Magnolia-Registration
ServerID
X-Revision
X-Cache-2
Eomportal-Instance
X-Request-Received
X-Request-Processing-Time
Paypal-Debug-Id
X-Page-Id
X-NWS-LOG-UUID
AR-Request-ID
X-Srv
X-Mobile
X-HS-Cache-Config
Front-End-Https
X-Akam-SW-Version
X-AOL-HN
X-VCache
Retry-After
X-Content-Powered-By
X-Varnish-Grace
X-B-Cache
X-Cache-Hit
X-GUploader-UploadID
X-Signature
X-Litespeed-Cache
X-Cluster
Source
X-FB-Debug
X-LB-Cache
X-Handled-By
X-SS-Set-Cookie
X-Device-Type
X-Cache-Action
X-Instance
X-App-Environment
X-Cache-Control
X-WA-Info
X-Request-Guid
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel
X-BCube-Filmed-By
X-Varnish-Hostname
X-Platform-Server
Refresh
Cleartype
X-Framework
X-Content-Security-Policy-Report-Only
X-Akamai-Edgescape
Webserver
X-Zen-Fury
X-Correlation-Id
X-Varnish-Backend
X-Sol
Display
X-Middleton-Display
X-Esi
X-Daa-Tunnel
X-XRDS-LOCATION
X-Activity-Id
X-Az
X-Cache-Server
X-AppVersion
X-Fastcgi-Cache
X-Content-Type
X-Varnish-Server
Healthy
VIX-Pulpo-Node
X-Drupal-Cache-Tags
VIX-Pulpo-Upstream-Status
X-Cache-Rule
X-Drupal-Cache-Contexts
X-TA-CDN-Provider
X-Seen-By
X-Wix-Request-Id
X-Generated-By
Response
X-Geo-Country
X-URL
X-Middleton-Response
ViewerVersion
S-Cnection
X-Cached-By
X-App-Server
Server-Node
Cache-Status
X-Origin-Server
X-Amz-Replication-Status
X-CACHE-GROUP
X-Accel-Expires
X-Amzn-RequestId
X-Amz-Apigw-Id
Upgrade-Insecure-Requests
X-Cache-Age
X-TT
X-DataStream-Cache-Status
Payment
X-Node-Name
Filters
X-RequestSource
X-Response-Served-From
GEO-INFO
NGB
X-S
X-UA-Device-Type
X-Edge-Cache
X-Cacheable-TTL
X-WPE-Loopback-Upstream-Addr
X-Cache-NE
X-Edge-Cache-Key
X-Varnish-IP
Actual-Object-TTL
X-Jobs
HostName
X-FW-Type
X-Tumblr-Pixel-2
X-FW-Hash
ServedBy
Host-Header
X-FW-Static
X-Tumblr-Pixel-1
X-Locale
X-GeoIP
X-FW-Serve
X-FW-Server
X-Contextid
X-Status
X-Servedby
Viewport
X-TX-ID
X-TT-TIMESTAMP
AsisCache
Access-Control-Allow-Method
X-Amz-Server-Side-Encryption
Accept-Charset
X-UUID
X-WebKit-CSP-Report-Only
X-Varnish-Hits
Server-Info
Cache
X-Storage
X-Adobe-Loc
X-Adobe-Content
X-APP-VERSION
X-Vg-Webcache
SRV
X-PHP-Backend
X-CLOUD-TRACE-CONTEXT
X-Hyper-Cache
X-Cache-TTL-Remaining
X-Rendered-As
X-Cache-Remote
MS-CV
X-Croise-Owner
Cache-Tv-Group
X-HS-Combine-CSS
From-Origin
X-Cache-Operation
X-Webkit-CSP
X-Region
Cache-Tag
DC
X-Forwarded-Host
Public-Key-Pins-Report-Only
Served-By
X-Mode
X-App-Version
X-Redis-Cache
Liferay-Portal
X-Yottaa-Metrics
X-Yottaa-Optimizations
Fastcgi-X-Cache-Version
Fastcgi-Useragent
Fastcgi-X-Cache
Machine
X-Endurance-Cache-Level
Xserver
Selected-FE
Meta-Geo
X-Human
X-IP
X-Request-Time
X-Generated
X-Detected-As
X-Is-Bot
X-Loop
X-Proxy-Build
X-Path-Route
X-Webstats-RespID
X-NGENIX-Cache
X-Upgrade-Enabled
X-Hosted-By
X-Agile-Age
X-Agile-Id
X-Cache-Var-Map
X-Akamai-Request-ID2
X-Timing-Wait
X-TNCMS
X-Cache-Var
X-Agile
X-RN-RSRV
X-ProxyCache-Key
Cache-Name
X-Zipkin-Id
TWC-Connection-Speed
X-ProxyCache-Status
Property-Id
Origin-Edge-Control
Origin-Cache-Control
Now
TWC-Device-Class
X-Vgn-Hpd-Reason
X-Via-Fastly
X-Routing-Service
S-Rt
TWC-Locale-Group
X-Environment-Context
X-Format
X-Grey
X-CDN-Cache
Webcakes-App-Name
Webcakes-Region
X-BYPASS-REASON
X-Cache-Category-Id
X-Internal-Host
X-JoinUs
X-Original-Request
X-Proxied
TWC-GeoIP-LatLong
X-Origin-Hint
Webcakes-App-Version
X-L-Path
X-Labrador-Cache-Channel
X-NCache
TWC-GeoIP-Country
TWC-Privacy
X-Akamai-Transformed
Powered-By-ChinaCache
X-Time-Microsecs
X-Web-Node
X-FC-Vary-Parameters
X-UA
DB-Nickname
X-Upstream-HT
X-Tumblr-Pixel-3
X-Access
Datacenter
X-Viewer-Country
X-Upstream-CT
Cache-Tags
X-Section
X-Pc-Appver
X-Origin-Host
X-Pc-Hit
X-Pc-Key
X-Proxy
X-PCL
X-OCL
X-Pubstack
X-Birta-Cache-Post
X-Cache-Config
X-ServerID
X-Backend-Name
X-Origin-Response-Time
X-Xfnlog-Site
X-ProcessESI
X-CCM
X-RemovedCookies
X-Site-Version
X-VG-TLSProxy
X-Origin
X-Akamai-Request-ID
X-Rule
X-B3-Spanid
X-Ocache
X-Birta-Served
HitType
Azure-SlotName
X-Via-CDN
Azure-InstanceId
Azure-SiteName
Azure-RegionName
X-Newrelic-App-Data
Mn-Server-Ip
X-Tb
X-Origin-CC
Azure-Version
X-RateLimit-Limit
OT-Force-Account-Verify
X-TIME
Accept-Language
X-ShopId
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Shopify-Stage
X-ShardId
X-App-Name
X-Www-Served-By
X-Alternate-Cache-Key
X-Ezoic-Cdn
Cache-Key
X-Cache-TTL
Pagespeed
X-Nginx-Cache
X-Guploader-Uploadid
X-CACHE-KEY
X-Parent-Response-Time
Vix-Hermes-Req-Id
X-Protected-By
X-OVcl
X-Edge-IP
User-Cache-Control
X-OVcl-Cache
Content-Style-Type
L5d-Success-Class
Content-Script-Type
X-Correlation-ID
X-BACKEND-TTL
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Real-IP
Time
NtCoent-Length
X-Real-Ip
X-RTag
X-Amz-Meta-Surrogate-Control
X-Cache-Backend
LB
X-ApacheServer
X-PERF
Ms-Operation-Id
X-Proto
X-Front
AR-SID
X-Webkit-Csp
X-Mshield-Cache-Status
X-Mrs-Cache-Hits
X-Mrs-Cache
X-Unique-Id-Primal
X-Pc-Host
X-Mrs-Age
X-Pc-Date
X-FB-TRIP-ID
X-Cdn-Forward
X-Dynatrace-Js-Agent
X-Hit
X-CDN-Forward
X-Nc
Section-Io-Cache
X-Content-Age
X-Debug-Cache
X-Varnish-Cacheable
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-Sucuri-ID
WZWS-RAY
X-Unique-ID
X-Microcachable
X-GRACE
Fusion-Content-Id
Fusion-Component-Id
Country
X-C
Fusion-Content-Source
X-Time
Fusion-Source
Access-Control-Request-Headers
Load-Balancing
Fusion-Template-Id
Ohc-File-Size
X-EdgeConnect-Cache-Status
X-Cache-Enabled
X-MP-GENERATED-AT
X-Transaction
X-Connection-Hash
X-Twitter-Response-Tags
X-Varnish-Beresp-Ttl
Mail-Subject
Version
Warning
We-Hiring
X-Cache-Host
X-Cache-FS-Status
X-Cache-Bucket
X-Crawler
X-CUA
X-CF-Lambda-Version
X-Cache-Id
X-CF-Lambda-Fn
X-Cache-Debug
X-Cache-URL
X-Clientip
X-B-Cookie
Resin-Trace
Rendered-Blocks
Release
RNT-Machine
RNT-Time
Server-Host
SD-X-WS
Rt-Proxy-Cache
Powered-By
Platform
MD5-Digest
Locale
Is-Eu
Memcached
Meta-Geo-Continent
Node
Mobile-Detection-Method
Server-ID
SS
X-Actual-URL
X-Accel-Expires-Debug
X-A-Wwc
X-Aed
X-Application
X-Backend-State
X-D
X-Auto-Login
X-A-Dgt
X-A-Dcw
V-Age
UCS
Uber-Trace-Id
Viewtype
VivaBuild
X-A-Ccd
X-A
X-BB-ID
X-Node-Id
X-Rewrite-Enabled
X-Returned-From-PostProcessResponse
X-Returned-From-DLL
X-Rojux
X-S-Cookie
X-ScT
X-S-Maxage
X-Returned-From-BeforeDispatch
X-Returned-From
X-Reboot
X-Rebelmouse-Surrogate-Control
X-Region-Sid
X-Release
X-Response-By
X-Request-UUID
X-Server-By
X-Server-Time
X-Via-Edge
X-VG-WebServer
X-Via-SSL
X-We-Are-Hiring
Xc-Version
X-WebServer
X-Variation
X-Var-Ttl
X-Store
X-SRCache-Key
X-Trv-Group
X-UE-Client-Country
X-Urbn-Site-Id
X-Urbn-Context-Path
X-Rebelmouse-Cache-Control
X-RCS-CacheZone
X-From
X-Fetched-On
X-FW-Version
X-G
X-GeoIP-Country-Code
X-Generated-In
X-F5-Cache
X-External-Request-Id
X-Developer
X-Destination
X-Device-Os
X-Died
X-DPWN-IS-SECURE
X-Dispatcher-Server
X-Layer
X-Li-Fabric
X-Passed-To-DLL
X-Passed-To-BeforeDispatch
X-Passed-To-PostProcessResponse
X-PAYTM-SRV-ID
X-Qloud-Router
X-PHP-Host
X-Passed-To
X-Org
X-LI-Proto
X-Li-Pop
X-LI-UUID
X-Logtrace-Id
X-NU-AKA-ACS-Version
IBM-Web2-Location
X-Date
X-A-Dam
Fastly-Backend-Name
Ec-Rule-Version
Countrycode
Fastly-SIE
Fastly-SWR
Fly-Request-Id
Fly-Cache
Cache-Prefix
BehaviorPad-Version
X-Hl-Ver
X-Ratelimit-Limit
X-Ua
X-Trace-Id
Adler-Geo
Arc-Country
Ajk
Frame-Options
X-Dc
X-Rocket-Nginx-Bypass
X-IN-WAF
X-IN-SSL-APIGATEWAY
X-IN-APIGATEWAY
X-Info
X-Hnp-Log
X-Key
X-Proxy-Cache-Status
X-MI-In-Market
X-Location
X-Hash
X-Gen-Mode
HA-Georegion
X-Geo
Ha-Gx-Prefs
X-Amz-Meta-Cache-Control
X-Bip
X-Block-Status
X-Eu-Site
X-Epic-Correlation-Id
X-CGP
HA-Geolon
X-Proxy-Upstream
HA-Geolat
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
Origin
X-Via-NSCOPI
Thinkindot-Control
Www
X-Thinkindot-L3
X-Swa-Ws
X-Matched-Rule
X-Cache-Expires
X-Varnish-Action
X-V
HA-Geocity
X-Server-IP
X-Served-From
HA-Geocountry
X-ServiceProvider
X-Sf
X-User
X-UnsetCookies
X-Thanos
X-Stale
HA-Host
X-Server-Group
MI-Cache
True-Client-Country-4JS
Heartbleed
MI-Cache-Age
On-Server
MI-API
Country-Code
Web-Mar-Node
HA-Servedtime
HA-Cloudapp
Content-Disposition
Decoy-Debug-Key
GMS-Ver
Request-Country
Request-EU
Esi-Enabled
GW-Server
Kp-EeAlive
Proxy-Connection
Decoy-Debug-Status
Decoy-Debug-TTL
Pragrma
Pramga
Backend-Name
HA-Urlpath
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
Apple-News-Services-Host
Backend
HA-Ipaddr
X-NODE
AKAMAI
X-Instance-Name
X-Irp-Debug
CDCHOST
X-TT-LOGID
Cache-Cookie-Set-Idcheck
X-Backend-Url
IsBot
X-Policy
X-SIPLIST1
X-Gannett-Site-Version
X-Core-Value
X-Wikidot-Static-Cache
X-NWS-UUID-VERIFY
X-No-Session
X-Wikidot-Backend
X-Secret
X-Nginx-Cache-Key
X-Platform
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-From
Who
X-Backend-Host
X-Request-Start
X-SVT-ORM-VERSION
X-P-T
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Developers
X-SVT-ORM-RULES
X-Distil-CS
Fastly-Soc-X-Request-Id
X-Request-URI
Request-Time
X-Phone
Fastly-SSL
Server-Int
X-Cache-CFC
User-Agent
PageSpeed
V-Cache
X-Be
Group
X-DC
X-Servername
X-Debug-Log
X-CACHE-AGE
X-VCT
X-Debug-Cookies
HitInfo
X-Refresh
X-Planisys-CDN-TTL
X-GeoIP-City
X-MSEdge-Features
X-Origin-Date
X-Origin-TTL
Magicmarker
X-Core-Mission
X-Fstrz
X-ElasticPress-Search
X-Distributor
X-Up
X-Cdn-Origin
X-Planisys-CDN-Cache
X-Page-Type
X-NX-Host
REQUESTUUID
X-Planisys-CDN-Rules
X-MSEdge-Flight
PFcat
X-Sn-Servicetimems
X-Origin-Expires
Pagetype
X-NC
X-COUNTRY
X-Fastly-Cache
X-VarnPar1
RequestId
X-Micro-Cache
X-Debug-Cache-Expiry
Host-ID
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-PARISIEN-Cache-Rendered
X-VarnCache
X-Newrelic-Synthetics
X-Req
X-BBXSRF
MIME-Version
X-Pjax-Url
X-Svr
X-Instart-Info
X-EIG-Tracking-Id
X-Powered-By-ANYU
X-Generated-On
Lfy
X-Level-Front-Cache
X-Datadome
X-Cdn-Srv
Ohc-Response-Time
ServerName
Cache-Provider
X-Cache-Info
X-Server-Cache
PICS-Label
Mime-Version
X-Gdpr
X-ARC
Cteonnt-Length
Cdn
Memory
X-TWH-CORRELATION-ID
X-Servedbyhost
X-Cluster-Node
X-CMS-Context
Nel
CF-IPCountry
X-Wa
X-NodeID
X-WR-MODIFICATION
CDN
X-LAGOON
X-StackifyID
FSS-Cache
X-Sentry-ID
X-Fastly-Country-Code
FSS-Proxy
X-Aicache-OS
X-Load-Cache
X-VServer
X-Flog
GeoIP-Country-Code
X-ABtesting
X-HTML-Minification-Powered-By
NGX
X-Hello
GeoIP-Latitude
X-B3-Traceid
X-CSRF-TOKEN
SN
XServer
GeoIp-Country-Code
X-Fastly-Backend-Reqs
Geoip-Latitude
X-UPSTREAM-Address
X-Varnish-Beresp-TTL
X-GZip
X-WA
X-APP
X-Check-Cacheable
X-Source
TSSecure
Amp-Access-Control-Allow-Source-Origin
Processtime
X-Csrf-Token
X-CSRF-Token
X-MServer
X-DataStream-MidMile-RTT
X-HOST
Cf-Ipcountry
X-DataStream-Origin-MEX-Latency
X-FireWall-Port
X-Worker
X-Unique-Id
X-Ratelimit-Remaining
CACHE
PageType
WP-Super-Cache
X-ServedByHost
X-Sedo-Request-Id
X-RateLimit-Remaining-Second
A
X-CDN-Pop
X-Cache-Miss-From
X-Generation-Time
X-CDN-Pop-IP
X-RateLimit-Limit-Second
X-Varnish-Cache-Hits
X-VWS-Id
X-Dynatrace
X-Oss-Storage-Class
Cdn-Host
X-Edge-Server
Cdn-Request-Time
X-AWS-Id
X-SplitTest
X-LJ-Flow-ID
X-Oss-Server-Time
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Nananana
X-Oss-Request-Id
X-SRV
X-Port
Pics-Label
X-Cache-Grace
X-VC-Cache
X-Skip-Cache
X-FORWARDED-FOR
HTTPS
URI
X-GDPR
X-ID
DataCenter
X-Backend-TTL
X-Cache-ASPX
X-Sucuri-Cache
X-IPS-LoggedIn
Odigeo-Trace-Id
X-Varnish-Authentication
Server-Surrogate-Control
Server-Cache-Control
Cache-Hits
X-BE
X-HS-Status
X-B3-SpanId
X-Owner
X-RCS-Backend
X-Fastly-Cache-Hits
X-Swift-Error
X-Ms-Lease-Status
X-Ms-Request-Id
X-Ms-Blob-Type
X-Ms-Version
X-Varnish-Url
Dynatrace
Hostname
X-PJAX-URL
ProcessTime
X-Bug-Bounty
X-SN
X-Gen-Id
Requestid
X-Amzn-Remapped-Connection
X-VG-WebCache
X-From-Cache
X-Instart-Isnd
X-GZIP
X-ND-Cache
X-Amzn-Remapped-Date
X-Pf-Uncompressing
X-NGINX-Cache
Is-Session-Tracking
X-Cache-Ttl
X-VarnPar2
X-ORIG-AKA-EDGE
X-GoCache-CacheStatus
Get-Access-Time
X-Ms-Lease-State
X-Server-W
Serverid
X-Amz-Meta-S3b-Last-Modified
X-Akamai-SSL-Client-Sid
Proxy-Firewall
X-LiteSpeed-Cache-Control
X-PAGE-TYPE
X-Alicdn-Da-Ups-Status
X-Varnish-URL
WebServer
X-Fe
X-SB
X-Serial
X-ServerName
X-Cache-Srv
X-VC
X-RAMCache
X-ORIG-AKA-COUNTRY-CODE
RequestUuid
T-Server
X-HTML-Edge-Cache
SID
Xet-Cookie
X-Developed-By
NodeID
X-CS
X-Dw-Trace-Id
Location
X-Akamai-ERRuleID
X-Akamai-ERPolicy
NnCoection
X-LiteSpeed-Tag