Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
Last-Modified
X-Content-Type-Options
Accept-Ranges
Pragma
X-Powered-By
CF-RAY
Link
ETag
Expect-CT
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Id
X-Served-By
Referrer-Policy
X-Varnish
X-Timer
X-Xss-Protection
X-Request-Id
CF-Cache-Status
X-AspNet-Version
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Runtime
X-Download-Options
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Cacheable
Alt-Svc
X-Generator
X-Check
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Cache-Status
X-AspNetMvc-Version
Status
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Template
X-Language
X-Permitted-Cross-Domain-Policies
X-Request-ID
Content-Encoding
X-Iinfo
X-FRAME-OPTIONS
X-Content-Security-Policy
X-CDN
X-Buckets
X-Turbo-Charged-By
X-Type
Upgrade
WPE-Backend
X-Pass-Why
Keep-Alive
X-Cache-Group
X-AH-Environment
Xkey
X-Backend
P3p
Access-Control-Max-Age
X-Age
Access-Control-Expose-Headers
X-Via
EagleId
X-Drupal-Dynamic-Cache
X-Nginx-Cache-Status
X-Pingback
X-Amz-Id-2
X-Amz-Request-Id
X-Server-Powered-By
X-Server
X-Hacker
X-Swift-CacheTime
X-Swift-SaveTime
X-UA-Device
Grace
Ali-Swift-Global-Savetime
X-Varnish-Cache
X-Robots-Tag
Cf-Railgun
X-Proxy-Cache
X-Envoy-Upstream-Service-Time
X-Kinja-Server-Push
X-LiteSpeed-Cache
X-Page-Speed
Request-Context
X-Device
X-Ac
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Content-Location
X-Cache-Lookup
X-Amz-Version-Id
X-OneAgent-JS-Injection
X-Response-Time
X-Server-Id
Surrogate-Control
X-Host
X-WebKit-CSP
X-Rq
X-Cnection
X-Backend-Server
X-Readtime
Server-Timing
X-Rack-Cache
Report-To
X-Node
EagleEye-TraceId
X-Application-Context
Request-Id
X-Cloud-Trace-Context
Feature-Policy
X-ORACLE-DMS-ECID
X-Instart-Request-ID
X-CST
X-Iejgwucgyu
X-Ua-Compatible
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Clacks-Overhead
Edge-Control
NEL
X-Country
Rating
X-Url
Pinterest-Generated-By
X-Server-Name
X-Px
X-Country-Code
X-DataDome
X-TTL
Allow
X-Varnish-TTL
X-MS-InvokeApp
X-DynaTrace
X-Origin-Cache
X-Vhost
X-TtlSet
X-PC
X-Vname
X-Cached
X-Ruxit-JS-Agent
X-FTR-Request-ID
X-ESI
RTSS
X-Goog-Hash
Charset
X-Powered-CMS
X-VARITI-CCR
X-Powered-By-Plesk
X-DynaTrace-JS-Agent
SPRequestGuid
X-Trace
Accept-CH
X-Dispatcher
Public-Key-Pins
X-GitHub-Request-Id
X-D2id
X-Mod-Pagespeed
X-SharePointHealthScore
PB-PID
PB-RID
Arc-Version
X-Mobile-Rewrite
X-F-Cache
X-T
X-Oracle-Dms-Rid
X-Kinja-Server
X-Kinja-Build
X-Exp-Id
X-Cdn-Fetch
X-Exp-Variant
X-GoogleNews-Bot
X-Kinja
X-Kinja-Revision
Content-MD5
Verso
MS-Author-Via
X-Version
X-Recruiting
SPRequestDuration
SPIisLatency
X-Shield-Request-Id
X-B3-TraceId
X-Abt-Application-Version
Nginx-Cache
X-Server-ID
X-Dns-Prefetch-Control
X-Client-IP
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Forwarded-Proto
X-HW
Accept-CH-Lifetime
X-N
X-DIS-Request-ID
X-Navigation-Version
X-Pinterest-Rid
X-Amz-Rid
Pinterest-Version
X-Upstream-Env
AR-PoweredBy
AR-ATIME
AR-CACHE
X-Dw-Request-Base-Id
X-B
X-Upstream
X-ORACLE-DMS-RID
X-Origin-Upstream-Status
X-Fastly-Request-ID
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-XRDS-Location
Fastly-Restarts
Paypal-Debug-Id
DynaTrace
X-Amz-Meta-S3cmd-Attrs
X-Hits
X-Wix-Server-Artifact-Id
X-Accel-Buffering
Realpath
X-Ser
TCN
X-Content-Options
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
Arr-Disable-Session-Affinity
X-Pad
Service-Worker-Allowed
X-NF-Request-ID
X-Acc-Meta-Resource-Type
X-Goog-Storage-Class
X-Content-Digest
Tracecode
Access-Control-Request-Method
X-Id
S
Front-End-Https
X-Varnish-Age
X-Debug
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
Mrf-Cache-Status
MRF-Tech
X-Amz-Cf-Pop
X-MSEdge-Ref
X-Vcap-Request-Id
X-Frontend
X-PressLabs-Stats
X-Webkit-Csp
X-IPLB-Instance
X-Country-Code-Real
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-Realm
X-FTR-Cache-Status
X-FTR-Backend
X-FTR-Expires
X-FTR-DC
X-ATG-Version
X-Kinsta-Cache
X-FastCGI-Cache
Display
X-Middleton-Display
X-Sol
X-RateLimit-Remaining
X-Cache-Hit
X-HS-Hub-Id
X-HS-Content-Id
X-Logged-In
Surrogate-Key
X-Forwarded-For
Fastcgi-Cache
Edge-Cache-Tag
Rt-Fastcgi-Cache
X-Zen-Fury
Powered-By-ChinaCache
X-NewRelic-App-Data
X-Grace
X-Request-Received
X-Request-Processing-Time
Server-Name
MicrosoftSharePointTeamServices
X-Edge-Location
X-Analytics
Backend-Timing
Response
X-Debug-Info
X-Middleton-Response
X-Oneagent-Js-Injection
FilterID
X-Rid
X-Amzn-Trace-Id
X-Cache-Key
X-Use-Magma
X-User-Agent
Host
X-Revision
X-FTR-Cache-Host
TP-Cache
X-Akam-SW-Version
TP-L2-Cache
AMP-Access-Control-Allow-Source-Origin
X-CF-Powered-By
X-Litespeed-Cache
X-Mobile
X-SS-Set-Cookie
Ar-Sid
X-B3-TraceId-Primal
X-Drupal-Cache-Tags
X-HS-Cache-Config
X-TA-CDN-Provider
X-Magnolia-Registration
X-Cached-By
Cache-Status
Host-Header
Refresh
X-Accel-Expires
X-Ttl
X-SERVER
ServerID
AR-Request-ID
X-B3-Sampled
X-Varnish-Backend
X-Node-Name
X-Geo-Segment
X-GUploader-UploadID
Liferay-Portal
X-AOL-HN
X-Platform-Server
X-Content-Security-Policy-Report-Only
X-Tumblr-User
DC
X-Instance
X-Tumblr-Pixel-0
Cache-Tag
X-FB-Debug
X-Cluster
X-Tumblr-Pixel
X-Cache-Rule
X-Signature
X-Webkit-CSP
X-B-Cache
X-Akamai-Edgescape
X-Cache-Control
X-App-Environment
X-Framework
X-Cache-2
X-BCube-Filmed-By
X-Device-Type
X-Varnish-Hostname
X-LB-Cache
X-Page-Id
X-Handled-By
X-Srv
Cleartype
Eomportal-Instance
X-Whom
X-Newrelic-App-Data
X-Generated-By
X-Request-Guid
X-Fastcgi-Cache
X-WPE-Loopback-Upstream-Addr
X-AppVersion
X-Az
X-Activity-Id
X-NWS-LOG-UUID
Public-Key-Pins-Report-Only
X-Drupal-Cache-Contexts
X-Cache-Action
X-Cache-Server
X-App-Server
Accept-Charset
Source
X-Content-Powered-By
X-Via-JSL
X-Correlation-Id
Retry-After
X-VCache
MS-CV
X-TT
X-Wix-Request-Id
X-Seen-By
ViewerVersion
X-Amz-Replication-Status
X-App-Version
X-HS-Combine-CSS
Alternate-Protocol
X-Hostname
HostName
X-WA-Info
X-Varnish-Grace
AR-SID
X-Varnish-Server
Upgrade-Insecure-Requests
X-Ruxit-Js-Agent
X-Geo-Country
Server-Node
Webserver
X-Esi
X-Response-Served-From
X-WebKit-CSP-Report-Only
X-Tumblr-Pixel-2
X-Cache-NE
X-Tumblr-Pixel-1
AsisCache
X-Amzn-RequestId
X-Amz-Apigw-Id
Actual-Object-TTL
SRV
X-Locale
X-GeoIP
X-RequestSource
X-URL
GEO-INFO
X-Varnish-Hits
ServedBy
X-Jobs
Payment
Viewport
X-FW-Type
X-S
X-Servedby
X-FW-Server
X-FW-Static
X-FW-Serve
X-Edge-Cache
X-Contextid
X-Edge-Cache-Key
X-FW-Hash
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Status
X-UUID
X-Varnish-IP
X-TX-ID
X-Daa-Tunnel
X-Cache-TTL-Remaining
X-Adobe-Loc
X-Adobe-Content
X-TT-TIMESTAMP
Pagespeed
X-Origin-Server
X-Cacheable-TTL
Cache
X-Vg-Webcache
X-Correlation-ID
X-Cache-Operation
X-Forwarded-Host
X-Cache-Age
Datacenter
X-Hyper-Cache
CACHE
X-Amz-Server-Side-Encryption
Server-Info
X-Sucuri-ID
S-Cnection
X-RateLimit-Limit
Served-By
X-TIME
Country
X-Region
X-XRDS-LOCATION
X-Mode
X-Akamai-Request-ID2
X-Real-IP
PageSpeed
From-Origin
Access-Control-Allow-Method
X-CLOUD-TRACE-CONTEXT
X-Ezoic-Cdn
X-DataStream-Cache-Status
X-Amz-Meta-Surrogate-Control
X-Upgrade-Enabled
X-L-Path
X-Is-Bot
X-Cache-Var-Map
X-Environment-Context
X-Rule
X-Detected-As
X-Generated
X-Cache-Var
X-RN-RSRV
X-Routing-Service
X-Cache-Config
X-JoinUs
X-Site-Version
Meta-Geo
X-Path-Route
Fastcgi-X-Cache
X-Rendered-As
X-Proxied
X-Zipkin-Id
X-Ocache
Machine
Fastcgi-X-Cache-Version
X-Proxy
X-Akamai-Transformed
DB-Nickname
X-CDN-Cache
Now
Fastcgi-Useragent
X-Section
OT-Force-Account-Verify
X-Birta-Cache-Post
X-Agile
X-Microcachable
X-Agile-Age
X-Access
X-Viewer-Country
X-Birta-Served
X-Agile-Id
X-Content-Type
Healthy
X-Cache-Category-Id
X-EIG-Tracking-Id
X-NGENIX-Cache
X-Hosted-By
L5d-Success-Class
Xserver
X-Grey
HitInfo
HitType
X-Request-Time
X-Format
TWC-Locale-Group
TWC-Privacy
Webcakes-App-Version
X-Via-Fastly
X-Pc-Hit
Webcakes-App-Name
X-Pc-Appver
TWC-Device-Class
Property-Id
X-Tb
Cache-Name
S-Rt
TWC-Connection-Speed
X-Pc-Key
TWC-GeoIP-Country
TWC-GeoIP-LatLong
Webcakes-Region
X-Human
X-Loop
X-Hit
X-ServerID
X-FC-Vary-Parameters
X-CCM
X-TNCMS
X-Labrador-Cache-Channel
X-Origin-Hint
X-OVcl
X-Original-Request
X-Pubstack
X-OVcl-Cache
X-Cluster-Node
X-ProxyCache-Status
X-ProxyCache-Key
X-ProcessESI
X-PCL
X-OCL
X-LJ-Flow-ID
X-RemovedCookies
X-AWS-Id
X-Upstream-CT
X-IP
X-Origin
X-BYPASS-REASON
X-Upstream-HT
Azure-Version
Azure-SlotName
X-VG-TLSProxy
Azure-SiteName
X-Xfnlog-Site
Azure-InstanceId
Azure-RegionName
X-SplitTest
X-VWS-Id
Cache-Hits
X-Web-Node
X-Alternate-Cache-Key
LB
Accept-Language
Content-Style-Type
X-ShopId
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-ShardId
X-Rocket-Nginx-Bypass
X-Timing-Wait
Content-Script-Type
X-Proxy-Build
X-Source
X-Via-CDN
X-Www-Served-By
Mn-Server-Ip
Selected-FE
X-Cache-Enabled
X-Guploader-Uploadid
X-Cdn
X-App-Name
Access-Control-Request-Headers
IBM-Web2-Location
X-TWH-CORRELATION-ID
X-Ms-Version
X-Ms-Lease-Status
X-Ms-Request-Id
X-Twitter-Response-Tags
X-Ms-Blob-Type
X-Connection-Hash
X-UA
Origin-Edge-Control
X-RTag
Origin-Cache-Control
X-Transaction
X-NodeID
Time
Ms-Operation-Id
X-GRACE
X-Port
NtCoent-Length
X-Cache-Remote
X-NODE
X-HOST
X-Real-Ip
X-Distil-CS
X-Origin-CC
X-Nginx-Cache
X-MP-GENERATED-AT
NGB
X-Edge-IP
X-Cdn-Forward
X-Geo
X-Internal-Host
Filters
X-Pc-Date
Backend
X-Unique-ID
X-Pc-Host
X-NCache
X-Varnish-Cacheable
We-Hiring
Mail-Subject
X-Tumblr-Pixel-3
X-APP-VERSION
X-Cache-TTL
X-Debug-Cache
X-Proto
User-Agent
X-Storage
X-Vgn-Hpd-Reason
X-Time-Microsecs
X-Sucuri-Cache
X-Ratelimit-Limit
X-Webstats-RespID
X-Newrelic-Synthetics
X-UA-Device-Type
X-CACHE-GROUP
X-Varnish-Beresp-Grace
Cache-Tags
X-Backend-Name
X-Varnish-Beresp-Status
X-ApacheServer
X-Varnish-Cache-Hits
X-Mshield-Cache-Status
X-Dc
X-Mrs-Cache-Hits
X-Mrs-Cache
X-Mrs-Age
X-Urbn-Context-Path
X-Akamai-Request-ID
X-Urbn-Site-Id
X-PERF
Locale
X-Nc
Fastly-SSL
X-PHP-Backend
X-Csrf-Token
X-ElasticPress-Search
Warning
X-Ua
X-CACHE-KEY
X-B3-Spanid
X-EdgeConnect-Cache-Status
X-C
Cache-Key
X-Varnish-Beresp-Ttl
X-Cdn-Origin
Fly-Cache
Fly-Request-Id
X-CF-Lambda-Fn
FSS-Cache
X-CGP
X-CF-Lambda-Version
Ec-Rule-Version
FSS-Proxy
HA-Cloudapp
HA-Geocity
HA-Geocountry
X-BBXSRF
GMS-Ver
X-Cache-Host
X-Cache-Bucket
X-D
X-Debug-Cookies
X-Eu-Site
X-Epic-Correlation-Id
X-DPWN-IS-SECURE
Server-Host
X-F5-Cache
X-Fetched-On
Ajk
Arc-Country
X-Died
Content-Disposition
X-Debug-Log
HA-Geolat
X-Destination
X-Developer
BehaviorPad-Version
Cache-Prefix
X-Date
HA-Geolon
X-A-Dam
X-A-Ccd
X-A
Odigeo-Trace-Id
X-A-Dcw
Mobile-Detection-Method
X-A-Dgt
VivaBuild
Viewtype
Resin-Trace
SN
Rt-Proxy-Cache
TSSecure
Rendered-Blocks
V-Age
UCS
X-A-Wwc
X-Accel-Expires-Debug
HA-Servedtime
HA-Urlpath
X-BB-ID
HA-Ipaddr
HA-Host
HA-Georegion
Ha-Gx-Prefs
X-Backend-Url
X-Backend-Host
X-Aed
Meta-Geo-Continent
X-Amz-Meta-Cache-Control
MD5-Digest
X-B-Cookie
X-Application
X-Endurance-Cache-Level
X-External-Request-Id
X-PAYTM-SRV-ID
X-Platform
X-UE-Client-Country
X-Cache-Backend
X-Server-Time
X-NX-Host
X-Via-Edge
X-VG-WebServer
X-NU-AKA-ACS-Version
X-Trv-Group
X-Region-Sid
X-SRCache-Key
X-ScT
X-Sn-Servicetimems
X-Server-By
X-S-Cookie
X-Rojux
X-From
X-Store
X-Rewrite-Enabled
X-Via-SSL
X-Org
X-IN-WAF
X-Logtrace-Id
X-Dynatrace-Js-Agent
X-IN-APIGATEWAY
X-Hash
X-GeoIP-Country-Code
Xc-Version
X-G
X-Generated-In
X-Irp-Debug
X-IN-SSL-APIGATEWAY
X-CACHE-AGE
X-Worker
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-We-Are-Hiring
Server-ID
X-ServiceProvider
X-VServer
X-SIPLIST1
Www
X-Var-Ttl
X-V
X-User
X-UnsetCookies
X-Trace-Id
Thinkindot-CacheControl-Type
X-ABtesting
Thinkindot-CacheControl
X-Thinkindot-L3
Thinkindot-Control
X-Request-Start
X-Layer
X-Key
X-Location
X-Clientip
X-No-Session
X-Matched-Rule
X-Developers
X-Hl-Ver
X-FW-Version
X-Flog
X-Gannett-Site-Version
X-GeoIP-City
X-Hello
X-Cache-URL
X-Owner
X-Response-By
X-Request-URI
X-S-Maxage
X-Secret
X-Server-IP
X-Backend-State
X-Release
X-Redis-Cache
X-Qloud-Router
X-Cache-Id
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Reboot
X-Auto-Login
X-Dispatcher-Server
User-Cache-Control
AKAMAI
Apple-News-Services-Handled
Apple-News-Services-Host
WZWS-RAY
GW-Server
Decoy-Debug-Status
IsBot
Heartbleed
Frame-Options
Apple-News-Services-Parsed-Url
Country-Code
Countrycode
Decoy-Debug-Key
Decoy-Debug-TTL
Fastly-SIE
Apple-News-Services-Request-Url
Fastly-SWR
Fastly-Soc-X-Request-Id
Memcached
X-Powered-By-ANYU
Release
Pramga
RNT-Machine
Origin
RNT-Time
X-CDN-Forward
X-Li-Pop
X-LI-Proto
X-Li-Fabric
X-P-T
X-MI-In-Market
X-Passed-To
X-LI-UUID
X-Node-Id
X-Nginx-Cache-Key
X-Swa-Ws
X-Thanos
X-Device-Os
Backend-Name
X-Stale
X-Passed-To-BeforeDispatch
X-Distributor
Adler-Geo
X-Phone
X-Returned-From
X-Gen-Mode
X-Request-UUID
Section-Io-Cache
X-Policy
X-RCS-CacheZone
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Returned-From-BeforeDispatch
X-Passed-To-PostProcessResponse
X-Instance-Name
X-Served-From
X-Hnp-Log
X-Info
X-Passed-To-DLL
X-Returned-From-DLL
X-Returned-From-PostProcessResponse
X-Sentry-ID
X-Fastly-Cache
X-Core-Mission
Web-Mar-Node
X-Backend-TTL
Is-Eu
Pragrma
X-WebServer
X-Block-Status
X-Bip
Kp-EeAlive
X-CUA
MI-Cache
On-Server
MI-Cache-Age
Platform
X-Actual-URL
Magicmarker
Powered-By
X-Core-Value
Uber-Trace-Id
X-Variation
Esi-Enabled
X-Up
X-Crawler
Server-Int
X-Croise-Owner
X-Varnish-Action
Fastly-Backend-Name
X-Cache-Expires
X-Cache-Debug
Request-Country
True-Client-Country-4JS
Request-EU
X-Datadome
X-NC
X-MSEdge-Flight
Proxy-Connection
REQUESTUUID
Cache-Cookie-Set-From
X-VCT
X-Via-NSCOPI
X-Cache-Srv
CDCHOST
X-TT-LOGID
X-MSEdge-Features
X-Sf
X-Cache-CFC
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-Idcheck
X-Fstrz
Pagetype
X-Origin-Response-Time
X-MServer
X-SVT-ORM-RULES
X-DC
X-SN
X-SVT-ORM-VERSION
X-Refresh
X-Ms-Lease-State
MI-API
HTTPS
NodeID
RequestId
Version
X-Pjax-Url
X-Be
X-Oss-Storage-Class
X-Servername
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Req
X-NWS-UUID-VERIFY
X-Page-Type
X-Cache-FS-Status
X-Kong-Upstream-Latency
X-Parent-Response-Time
Cteonnt-Length
ProcessTime
X-Kong-Proxy-Latency
MIME-Version
X-BB-IP
X-Unique-Id-Primal
Group
X-Origin-TTL
Memory
X-GZip
V-Cache
Cdn
X-Oracle-Dms-Ecid
Who
Amp-Access-Control-Allow-Source-Origin
Mime-Version
X-Ckpd-Fst-Backend
Fusion-Source
Fusion-Component-Id
Fusion-Template-Id
Fusion-Content-Id
Fusion-Content-Source
X-Aicache-OS
CF-IPCountry
SS
X-Servedbyhost
X-ND-Cache
X-Content-Age
X-Protected-By
Cdn-Request-Time
Cdn-Host
X-COUNTRY
X-Edge-Server
X-Wa
X-Server-Group
PageType
X-Varnish-Url
X-Time
X-Unique-Id
SD-X-WS
X-APP
GeoIP-Country-Code
CDN
X-SRV
X-Vcache
X-Varnish-Beresp-TTL
X-Ratelimit-Remaining
GeoIP-Latitude
Geoip-Latitude
GeoIp-Country-Code
Is-Session-Tracking
X-Generation-Time
X-RateLimit-Remaining-Second
X-Pf-Uncompressing
Get-Access-Time
X-RateLimit-Limit-Second
XServer
X-GEO
X-Fastly-Cache-Hits
X-B3-Traceid
A
X-WA
X-FireWall-Port
X-Cache-Info
X-Origin-Expires
X-Origin-Date
X-CSRF-Token
Serverid
X-CS
PICS-Label
X-Gdpr
X-StackifyID
X-EC-Security-Audit
X-Requestid
X-Origin-Host
X-Fastly-Country-Code
Nel
T-Server
NGX
X-M-Log
VIX-Pulpo-Upstream-Status
X-ID
X-Surge-Debug
VIX-Pulpo-Node
X-Server-W
Cf-Ipcountry
X-Load-Cache
X-Qnm-Cache
X-M-Reqid
Processtime
X-Nananana
X-Check-Cacheable
X-RequestId
X-ServedByHost
DataCenter
Node
X-SERVER-NAME
X-PHP-Host
X-HTML-Minification-Powered-By
Load-Balancing
X-UPSTREAM-Address
X-Proxy-Upstream
X-Proxy-Cache-Status
ServerName
URI
X-FORWARDED-FOR
Hostname
WP-Super-Cache
X-PF-Uncompressing
Vix-Hermes-Req-Id
X-HS-Status
X-Feature
X-NGINX-Cache
X-VG-WebCache
X-GZIP
X-ARC
X-Skip-Cache
X-B3-SpanId
X-Planisys-CDN-TTL
X-ServerName
X-BE
X-Fe
X-Alicdn-Da-Ups-Status
Cache-Provider
X-Fastly-Backend-Reqs
X-DataStream-MidMile-RTT
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
Cache-Tv-Group
X-Proxy-Server
X-DataStream-Origin-MEX-Latency
X-Akamai-SSL-Client-Sid
X-Atg-Version
X-PAGE-TYPE
Request-Time
X-PJAX-URL
X-IPS-LoggedIn
RequestUuid
Requestid
X-HTML-Edge-Cache
X-BACKEND-TTL
X-WR-MODIFICATION
Https
Host-ID
X-Distil-Cs
N-Cache
X-VC
X-SB
X-From-Cache
PFcat
X-Micro-Cache
X-Cache-Ttl
X-SF
X-Gen-Id
X-CSRF-TOKEN
Cneonction
X-Cdn-Srv
X-RAMCache
Build-Number
Cdn-Src-Port
Powered
X-Dw-Trace-Id
X-Grace-Duration
Lfy