Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Accept-Ranges
Pragma
X-Powered-By
Link
ETag
CF-RAY
Expect-CT
Via
X-XSS-Protection
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Id
X-Served-By
P3P
Referrer-Policy
X-Varnish
X-Xss-Protection
X-Timer
CF-Cache-Status
X-Request-Id
Access-Control-Allow-Headers
X-AspNet-Version
Access-Control-Allow-Methods
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
P3p
CF-Ray
X-Drupal-Cache
X-Check
X-Adblock-Key
Alt-Svc
X-Cacheable
X-Generator
Content-Security-Policy-Report-Only
X-Amz-Cf-Pop
X-Cache-Status
X-Request-ID
X-AspNetMvc-Version
Status
X-DNS-Prefetch-Control
X-Template
X-Language
Timing-Allow-Origin
Content-Encoding
X-Permitted-Cross-Domain-Policies
X-Iinfo
X-Buckets
X-Content-Security-Policy
X-Turbo-Charged-By
Upgrade
X-Kinja-Server-Push
X-CDN
X-Type
Xkey
Keep-Alive
Access-Control-Expose-Headers
WPE-Backend
X-Pass-Why
X-AH-Environment
Access-Control-Max-Age
X-Backend
X-Cache-Group
X-Server
X-Age
X-Drupal-Dynamic-Cache
X-Pingback
X-Via
X-Nginx-Cache-Status
X-Amz-Request-Id
X-Amz-Id-2
Grace
X-Server-Powered-By
X-Hacker
EagleId
X-UA-Device
X-Robots-Tag
X-LiteSpeed-Cache
X-Varnish-Cache
X-Page-Speed
X-Swift-CacheTime
X-Swift-SaveTime
X-Proxy-Cache
Cf-Railgun
X-Envoy-Upstream-Service-Time
Request-Context
Ali-Swift-Global-Savetime
X-Ua-Compatible
X-Ac
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-WebKit-CSP
X-Cache-Lookup
Content-Location
X-Amz-Version-Id
Surrogate-Control
X-Server-Id
X-Cnection
X-Host
X-Readtime
Report-To
X-Node
X-Rq
EagleEye-TraceId
Server-Timing
X-Response-Time
X-CST
X-OneAgent-JS-Injection
Feature-Policy
X-Rack-Cache
X-Backend-Server
X-ORACLE-DMS-ECID
X-Application-Context
X-Iejgwucgyu
Request-Id
X-Cloud-Trace-Context
X-Instart-Request-ID
X-Clacks-Overhead
X-Url
Edge-Control
X-DynaTrace
NEL
Allow
Rating
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Country
X-Varnish-TTL
X-Origin-Cache
X-FTR-Request-ID
X-Country-Code
X-Server-Name
X-Trace
X-B3-TraceId
X-DataDome
X-Px
X-Cdn
X-Vhost
X-ESI
X-GitHub-Request-Id
X-MS-InvokeApp
RTSS
X-Ruxit-JS-Agent
X-VARITI-CCR
X-Cached
X-Server-ID
X-ORACLE-DMS-RID
Accept-CH
SPRequestGuid
X-Goog-Hash
Charset
X-TtlSet
X-PC
X-Vname
Pinterest-Generated-By
X-Mod-Pagespeed
X-F-Cache
Public-Key-Pins
X-D2id
Verso
X-Dispatcher
X-GoogleNews-Bot
X-Kinja-Build
X-Exp-Id
X-Cdn-Fetch
X-Kinja-Revision
X-Exp-Variant
X-Kinja
X-Kinja-Server
X-Use-Magma
X-SharePointHealthScore
PB-RID
PB-PID
X-Mobile-Rewrite
Arc-Version
X-T
X-Version
X-TTL
X-Powered-By-Plesk
X-DynaTrace-JS-Agent
X-Abt-Application-Version
Accept-CH-Lifetime
X-Powered-CMS
X-DIS-Request-ID
X-Ser
X-Fastly-Request-ID
X-Dns-Prefetch-Control
X-Pinterest-Rid
Pinterest-Version
X-Upstream-Env
X-Navigation-Version
X-Origin-Upstream-Status
X-B
X-Shield-Request-Id
X-Recruiting
X-Forwarded-Proto
X-Oneagent-Js-Injection
MS-Author-Via
X-Client-IP
DynaTrace
X-Amz-Rid
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Realpath
X-HW
SPRequestDuration
SPIisLatency
X-Ttl
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
Content-MD5
X-Upstream
Nginx-Cache
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Vcap-Request-Id
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Wix-Server-Artifact-Id
X-Accel-Buffering
X-Amz-Meta-S3cmd-Attrs
Edge-Cache-Tag
AR-CACHE
AR-PoweredBy
AR-ATIME
X-N
X-Oracle-Dms-Rid
X-Hits
Arr-Disable-Session-Affinity
TCN
X-Varnish-Age
X-Debug
X-NF-Request-ID
Access-Control-Request-Method
X-Mrf-Item-Lastmod
X-B3-TraceId-Primal
X-NewRelic-App-Data
MRF-Tech
Mrf-Cache-Status
X-Mrf-Section-Lastmod
X-Goog-Storage-Class
X-MSEdge-Ref
X-Acc-Meta-Resource-Type
X-Dw-Request-Base-Id
S
X-ATG-Version
X-Id
Service-Worker-Allowed
X-FTR-Backend-Server
X-FTR-Cache-Status
X-FTR-Backend
X-FTR-Balancer
X-FTR-Realm
X-Via-JSL
X-FTR-DC
X-Country-Code-Real
X-XRDS-Location
X-FTR-Expires
X-Logged-In
X-FastCGI-Cache
Tracecode
Rt-Fastcgi-Cache
X-PressLabs-Stats
X-HS-Content-Id
X-HS-Hub-Id
X-Forwarded-For
X-Content-Digest
X-Frontend
Alternate-Protocol
X-Kinsta-Cache
Surrogate-Key
X-Pad
X-Cache-Key
Fastly-Restarts
X-RateLimit-Remaining
AMP-Access-Control-Allow-Source-Origin
MicrosoftSharePointTeamServices
X-Content-Options
X-Litespeed-Cache
X-FTR-Cache-Host
X-Grace
Ar-Sid
Server-Name
X-Edge-Location
X-Amzn-Trace-Id
Fastcgi-Cache
X-Analytics
Backend-Timing
Host
FilterID
X-CF-Powered-By
X-Ruxit-Js-Agent
X-Rid
TP-Cache
TP-L2-Cache
X-IPLB-Instance
X-User-Agent
X-Debug-Info
X-Magnolia-Registration
ServerID
X-Hostname
X-Whom
X-Revision
X-B3-Sampled
X-Cache-2
Eomportal-Instance
X-Request-Received
Paypal-Debug-Id
X-Request-Processing-Time
X-NWS-LOG-UUID
X-Page-Id
X-Mobile
AR-Request-ID
X-Srv
X-HS-Cache-Config
Front-End-Https
X-Akam-SW-Version
X-AOL-HN
X-GUploader-UploadID
X-Content-Powered-By
X-VCache
Retry-After
X-Cache-Hit
X-B-Cache
X-Varnish-Grace
X-Signature
X-SS-Set-Cookie
X-Handled-By
X-Device-Type
X-FB-Debug
X-Cluster
Source
X-LB-Cache
X-Cache-Control
X-Request-Guid
X-Cache-Action
X-App-Environment
Cleartype
Refresh
X-WA-Info
X-Instance
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-0
X-Varnish-Hostname
X-BCube-Filmed-By
X-Framework
X-Platform-Server
X-Content-Security-Policy-Report-Only
X-Zen-Fury
X-Akamai-Edgescape
X-Correlation-Id
X-XRDS-LOCATION
Webserver
X-Varnish-Backend
X-TA-CDN-Provider
X-Middleton-Display
Display
X-Sol
X-Daa-Tunnel
X-Cache-Server
X-AppVersion
X-Az
X-Activity-Id
X-Drupal-Cache-Tags
X-Webkit-CSP
X-Varnish-Server
X-Drupal-Cache-Contexts
X-Cache-Rule
X-Content-Type
Healthy
X-Geo-Country
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Fastcgi-Cache
X-Wix-Request-Id
X-Generated-By
X-Middleton-Response
Response
X-Seen-By
X-Cache-Age
ViewerVersion
X-Cached-By
S-Cnection
X-App-Server
Server-Node
Cache-Status
X-URL
X-Accel-Expires
X-DataStream-Cache-Status
X-Origin-Server
X-Node-Name
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Amz-Replication-Status
Upgrade-Insecure-Requests
X-TT
Payment
Filters
X-CACHE-GROUP
X-S
X-Response-Served-From
X-RequestSource
GEO-INFO
NGB
X-WPE-Loopback-Upstream-Addr
Host-Header
X-Cacheable-TTL
X-Locale
X-UA-Device-Type
X-Esi
Actual-Object-TTL
Viewport
X-Edge-Cache-Key
X-Varnish-IP
X-Edge-Cache
X-Cache-NE
ServedBy
X-Jobs
X-Servedby
X-Tumblr-Pixel-1
X-FW-Type
X-FW-Static
X-Contextid
X-FW-Hash
X-FW-Serve
X-FW-Server
X-Tumblr-Pixel-2
X-GeoIP
X-Status
AsisCache
X-Varnish-Hits
HostName
X-TX-ID
X-Amz-Server-Side-Encryption
X-TT-TIMESTAMP
Access-Control-Allow-Method
X-WebKit-CSP-Report-Only
X-UUID
Accept-Charset
X-APP-VERSION
Server-Info
X-Storage
X-Adobe-Content
X-Adobe-Loc
X-Vg-Webcache
SRV
X-Hyper-Cache
X-Cache-TTL-Remaining
X-PHP-Backend
X-Rendered-As
MS-CV
X-HS-Combine-CSS
X-Cache-Remote
Cache
From-Origin
X-CLOUD-TRACE-CONTEXT
X-Croise-Owner
X-Cache-Operation
Cache-Tv-Group
DC
Cache-Tag
X-Region
Public-Key-Pins-Report-Only
X-Forwarded-Host
Liferay-Portal
Served-By
X-Redis-Cache
X-Mode
X-UA
X-App-Version
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-TIME
X-Hosted-By
X-TNCMS
X-Timing-Wait
X-NGENIX-Cache
X-Human
X-Akamai-Request-ID2
X-Agile-Id
Meta-Geo
X-Agile
X-Path-Route
X-Upgrade-Enabled
Pagespeed
X-Generated
X-Cache-Var
X-Cache-Var-Map
X-IP
X-Proxy-Build
Fastcgi-X-Cache
Fastcgi-Useragent
X-Loop
X-RN-RSRV
X-Request-Time
Selected-FE
Fastcgi-X-Cache-Version
X-Agile-Age
X-Detected-As
Machine
X-Webstats-RespID
X-Is-Bot
X-Site-Version
TWC-Privacy
Origin-Cache-Control
TWC-Connection-Speed
TWC-Device-Class
Webcakes-App-Name
S-Rt
Property-Id
TWC-Locale-Group
TWC-GeoIP-LatLong
Origin-Edge-Control
Now
X-ProxyCache-Key
X-Grey
X-Format
X-ProxyCache-Status
X-CDN-Cache
X-Origin-Hint
X-JoinUs
X-Pc-Key
X-Via-Fastly
X-Routing-Service
X-Zipkin-Id
X-Original-Request
X-Pc-Hit
X-BYPASS-REASON
X-Proxied
X-Internal-Host
Webcakes-Region
X-Vgn-Hpd-Reason
Cache-Name
X-Pc-Appver
X-NCache
X-Labrador-Cache-Channel
X-Cache-Category-Id
Webcakes-App-Version
TWC-GeoIP-Country
Powered-By-ChinaCache
X-Akamai-Transformed
X-Endurance-Cache-Level
X-PCL
X-ProcessESI
X-Pubstack
X-RemovedCookies
X-OCL
X-Access
X-FC-Vary-Parameters
X-Birta-Cache-Post
Datacenter
X-Birta-Served
X-Environment-Context
DB-Nickname
X-L-Path
X-Proxy
X-Tumblr-Pixel-3
X-Viewer-Country
X-Upstream-HT
X-Upstream-CT
X-Web-Node
Cache-Tags
X-Section
X-Www-Served-By
X-Cache-Config
X-Origin-Host
X-Time-Microsecs
X-Akamai-Request-ID
X-Xfnlog-Site
X-Backend-Name
X-VG-TLSProxy
X-Origin-Response-Time
X-ServerID
X-Via-CDN
X-Origin-CC
X-Rule
X-Origin
X-Ocache
X-B3-Spanid
X-Tb
Xserver
X-CCM
Azure-InstanceId
Azure-SiteName
Azure-RegionName
Azure-Version
Mn-Server-Ip
Azure-SlotName
OT-Force-Account-Verify
HitType
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-App-Name
X-ShardId
X-ShopId
X-Alternate-Cache-Key
X-Shopify-Stage
Accept-Language
X-Cache-TTL
X-RateLimit-Limit
X-Ezoic-Cdn
X-Real-IP
X-OVcl-Cache
X-Protected-By
X-OVcl
X-Parent-Response-Time
L5d-Success-Class
X-Edge-IP
X-Nginx-Cache
X-Guploader-Uploadid
X-NODE
User-Cache-Control
Vix-Hermes-Req-Id
Cache-Key
Content-Style-Type
X-CACHE-KEY
Content-Script-Type
NtCoent-Length
X-Kong-Upstream-Latency
Time
LB
X-Kong-Proxy-Latency
X-Correlation-ID
X-BACKEND-TTL
X-Amz-Meta-Surrogate-Control
Ms-Operation-Id
X-Proto
X-RTag
X-CDN-Forward
X-Cache-Backend
X-Real-Ip
X-Newrelic-App-Data
AR-SID
X-PERF
X-ApacheServer
X-Pc-Date
X-Pc-Host
X-Front
X-Webkit-Csp
X-Mshield-Cache-Status
X-Unique-Id-Primal
X-Mrs-Cache-Hits
X-Mrs-Age
X-Mrs-Cache
X-Nc
X-Hit
X-Sucuri-ID
X-Varnish-Cacheable
X-FB-TRIP-ID
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
X-Debug-Cache
Section-Io-Cache
X-Dynatrace-Js-Agent
X-Microcachable
WZWS-RAY
X-Content-Age
X-Dc
X-Unique-ID
Access-Control-Request-Headers
X-Connection-Hash
X-Ratelimit-Limit
Country
X-Cdn-Forward
X-Cache-Enabled
X-Twitter-Response-Tags
Fusion-Content-Source
Fusion-Source
Fusion-Component-Id
Version
X-C
Fusion-Template-Id
Fusion-Content-Id
X-Transaction
X-MP-GENERATED-AT
X-Trace-Id
X-GRACE
X-EdgeConnect-Cache-Status
Warning
Load-Balancing
We-Hiring
Mail-Subject
X-Destination
X-Developer
Frame-Options
Fly-Cache
X-Device-Os
Fastly-SWR
X-Date
Fly-Request-Id
X-D
X-Crawler
X-Clientip
X-CF-Lambda-Version
X-Cache-URL
X-Died
X-CF-Lambda-Fn
X-CUA
X-Cache-Id
Ec-Rule-Version
X-FW-Version
X-From
BehaviorPad-Version
Arc-Country
X-G
Ajk
X-GeoIP-Country-Code
X-Generated-In
X-Fetched-On
X-F5-Cache
X-Cache-Host
X-Dispatcher-Server
Fastly-Backend-Name
Countrycode
X-DPWN-IS-SECURE
X-External-Request-Id
Cache-Prefix
Fastly-SIE
X-Cache-Debug
X-A-Dam
X-A-Ccd
Resin-Trace
RNT-Machine
X-A-Dcw
X-A-Dgt
X-A-Wwc
Release
Rendered-Blocks
RNT-Time
Rt-Proxy-Cache
VivaBuild
Viewtype
V-Age
Uber-Trace-Id
SS
X-A
SD-X-WS
Server-Host
Server-ID
X-Accel-Expires-Debug
Powered-By
X-BB-ID
X-Backend-State
Locale
X-B-Cookie
Is-Eu
IBM-Web2-Location
X-Rewrite-Enabled
X-Cache-Bucket
X-Bip
MD5-Digest
Memcached
X-Aed
X-Actual-URL
Platform
X-Application
Node
X-Auto-Login
Meta-Geo-Continent
Mobile-Detection-Method
X-Cache-FS-Status
Adler-Geo
X-RCS-CacheZone
X-Qloud-Router
X-Trv-Group
X-Via-Edge
Xc-Version
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-UE-Client-Country
X-Server-Time
X-Passed-To-PostProcessResponse
Ohc-File-Size
X-VG-WebServer
X-PAYTM-SRV-ID
X-User
X-PHP-Host
X-Urbn-Context-Path
X-Reboot
X-Region-Sid
X-We-Are-Hiring
X-Returned-From
X-Response-By
X-Returned-From-BeforeDispatch
X-SRCache-Key
X-Returned-From-PostProcessResponse
X-Returned-From-DLL
X-Rojux
X-Request-UUID
X-Release
UCS
X-Thanos
X-S-Cookie
X-Via-SSL
X-Store
X-Passed-To-DLL
X-S-Maxage
X-Var-Ttl
X-LI-UUID
X-Urbn-Site-Id
X-Server-By
X-Served-From
X-LI-Proto
X-ScT
X-Hl-Ver
X-Layer
X-Li-Fabric
X-Variation
X-Li-Pop
X-Logtrace-Id
X-Rocket-Nginx-Bypass
X-Varnish-Action
X-Node-Id
X-Org
X-Passed-To
X-Passed-To-BeforeDispatch
X-WebServer
X-NU-AKA-ACS-Version
Www
X-Request-Start
X-Info
X-SVT-ORM-VERSION
X-Swa-Ws
X-Hash
X-Gen-Mode
Web-Mar-Node
X-Stale
X-IN-SSL-APIGATEWAY
X-IN-WAF
X-SVT-ORM-RULES
X-IN-APIGATEWAY
X-Via-NSCOPI
X-Matched-Rule
X-UnsetCookies
X-Proxy-Cache-Status
X-Block-Status
X-No-Session
X-Server-IP
X-Cache-Expires
X-Hnp-Log
X-Sf
X-Proxy-Upstream
X-CGP
X-Epic-Correlation-Id
X-Eu-Site
X-Amz-Meta-Cache-Control
X-Server-Group
X-Location
X-Thinkindot-L3
X-Key
Who
HA-Geolat
HA-Geolon
AKAMAI
HA-Geocity
HA-Cloudapp
HA-Georegion
Ha-Gx-Prefs
HA-Urlpath
HA-Servedtime
HA-Ipaddr
HA-Host
GW-Server
GMS-Ver
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Handled
X-Geo
Apple-News-Services-Request-Url
Backend
Esi-Enabled
Country-Code
Content-Disposition
Backend-Name
Heartbleed
HA-Geocountry
Thinkindot-CacheControl
Request-EU
Origin
Request-Country
Thinkindot-CacheControl-Type
Pragrma
Pramga
Thinkindot-Control
Kp-EeAlive
User-Agent
X-Be
X-NWS-UUID-VERIFY
X-Varnish-Beresp-Ttl
Cache-Cookie-Set-Idcheck
X-Platform
Cache-Cookie-Set-Lfrom
X-Distil-CS
Decoy-Debug-Key
CDCHOST
X-Phone
REQUESTUUID
X-Nginx-Cache-Key
X-Instance-Name
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Wikidot-Backend
X-Irp-Debug
X-Gannett-Site-Version
Cache-Cookie-Set-From
Server-Int
X-Wikidot-Static-Cache
X-P-T
X-Developers
MI-Cache
X-Time
X-TT-LOGID
True-Client-Country-4JS
MI-API
MI-Cache-Age
X-Backend-Host
On-Server
Proxy-Connection
X-Backend-Url
X-Cache-CFC
X-SIPLIST1
Decoy-Debug-TTL
X-Request-URI
X-Secret
X-Policy
IsBot
Fastly-SSL
X-V
X-ServiceProvider
Decoy-Debug-Status
Fastly-Soc-X-Request-Id
X-MI-In-Market
X-Core-Value
Group
V-Cache
X-MSEdge-Features
X-MSEdge-Flight
X-Debug-Cookies
HitInfo
X-Refresh
X-Debug-Log
X-Origin-TTL
X-NX-Host
X-Origin-Expires
Request-Time
X-ElasticPress-Search
X-VCT
X-Servername
X-Distributor
Magicmarker
X-Up
X-Origin-Date
X-GeoIP-City
X-Core-Mission
X-Sn-Servicetimems
X-Cdn-Origin
X-Fstrz
Pagetype
Nel
X-Ua
X-Fastly-Cache
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
X-Page-Type
PFcat
X-Planisys-CDN-Rules
RequestId
X-DC
X-NC
X-Req
X-Pjax-Url
X-COUNTRY
X-BBXSRF
X-EIG-Tracking-Id
X-Micro-Cache
Host-ID
X-Newrelic-Synthetics
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-VarnCache
X-Svr
X-PARISIEN-Cache-Rendered
X-Debug-Cache-Store
X-VarnPar1
PageSpeed
X-Powered-By-ANYU
X-Generated-On
X-Instart-Info
MIME-Version
X-CACHE-AGE
X-Level-Front-Cache
X-HOST
ServerName
Lfy
X-Datadome
Mime-Version
X-Cdn-Srv
PICS-Label
Cache-Provider
X-Gdpr
X-Cache-Info
X-Server-Cache
Ohc-Response-Time
Cdn
Cteonnt-Length
X-TWH-CORRELATION-ID
Memory
X-ARC
X-Cluster-Node
X-Servedbyhost
CF-IPCountry
X-CMS-Context
X-StackifyID
FSS-Proxy
X-Sentry-ID
X-Aicache-OS
X-NodeID
FSS-Cache
CDN
X-WR-MODIFICATION
X-Varnish-Beresp-TTL
X-Wa
X-VServer
X-Flog
XServer
GeoIp-Country-Code
X-Fastly-Country-Code
X-Hello
CACHE
Geoip-Latitude
X-ABtesting
X-LAGOON
X-Load-Cache
X-WA
SN
NGX
X-HTML-Minification-Powered-By
X-B3-Traceid
X-Fastly-Backend-Reqs
GeoIP-Latitude
GeoIP-Country-Code
X-UPSTREAM-Address
X-GZip
X-CSRF-TOKEN
X-Check-Cacheable
TSSecure
X-APP
X-Source
X-CSRF-Token
Processtime
X-Worker
Amp-Access-Control-Allow-Source-Origin
X-MServer
X-Unique-Id
X-Csrf-Token
X-ServedByHost
Cf-Ipcountry
X-DataStream-Origin-MEX-Latency
X-FireWall-Port
A
X-DataStream-MidMile-RTT
X-Varnish-Cache-Hits
X-VWS-Id
X-SplitTest
X-AWS-Id
X-Ratelimit-Remaining
PageType
X-LJ-Flow-ID
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
WP-Super-Cache
X-Oss-Object-Type
X-Oss-Storage-Class
X-CDN-Pop
X-Generation-Time
X-Cache-Miss-From
X-Port
X-RateLimit-Limit-Second
X-Sedo-Request-Id
X-RateLimit-Remaining-Second
X-CDN-Pop-IP
X-Edge-Server
Cdn-Host
HTTPS
Cdn-Request-Time
X-Dynatrace
X-Nananana
URI
Cache-Hits
X-SRV
X-Backend-TTL
Pics-Label
Odigeo-Trace-Id
X-VC-Cache
X-Skip-Cache
X-FORWARDED-FOR
X-Sucuri-Cache
X-GDPR
X-Cache-Grace
X-ID
DataCenter
Server-Surrogate-Control
X-Cache-ASPX
Server-Cache-Control
X-Owner
X-IPS-LoggedIn
X-Varnish-Authentication
X-Ms-Version
X-Ms-Lease-Status
X-Ms-Request-Id
X-Ms-Blob-Type
Hostname
ProcessTime
X-Fastly-Cache-Hits
X-HS-Status
X-B3-SpanId
X-RCS-Backend
X-Swift-Error
X-BE
X-SN
Dynatrace
X-Varnish-Url
X-PJAX-URL
X-NGINX-Cache
X-Instart-Isnd
X-VG-WebCache
X-From-Cache
X-Bug-Bounty
X-Pf-Uncompressing
X-Amzn-Remapped-Date
X-ND-Cache
X-Gen-Id
X-GZIP
X-Amzn-Remapped-Connection
Is-Session-Tracking
X-Ms-Lease-State
X-PAGE-TYPE
X-ORIG-AKA-EDGE
X-Cache-Ttl
X-Fe
Get-Access-Time
X-VarnPar2
X-Server-W
X-GoCache-CacheStatus
Requestid
X-Cache-Srv
Serverid
X-Akamai-SSL-Client-Sid
X-Amz-Meta-S3b-Last-Modified
X-LiteSpeed-Cache-Control
X-Varnish-URL
X-Alicdn-Da-Ups-Status
X-SB
X-RAMCache
X-Serial
Proxy-Firewall
X-ServerName
WebServer
X-VC
NodeID
X-ORIG-AKA-COUNTRY-CODE
T-Server
RequestUuid
Xet-Cookie
X-LiteSpeed-Tag
X-Akamai-ERRuleID
X-HTML-Edge-Cache
SID
X-RequestId
NnCoection
X-Akamai-ERPolicy
X-Developed-By
X-CS
Location
X-Dw-Trace-Id