Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Accept-Ranges
Pragma
X-Powered-By
Link
ETag
CF-RAY
Expect-CT
Via
X-Cache
X-XSS-Protection
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-UA-Compatible
X-Cache-Hits
X-Xss-Protection
X-Amz-Cf-Id
X-Served-By
Referrer-Policy
P3P
X-Varnish
X-Request-Id
X-Timer
CF-Cache-Status
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Amz-Cf-Pop
X-Download-Options
P3p
X-Runtime
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Check
X-Adblock-Key
X-Cacheable
Alt-Svc
Content-Security-Policy-Report-Only
X-Generator
CF-Ray
X-Cache-Status
X-DNS-Prefetch-Control
X-AspNetMvc-Version
Status
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-Permitted-Cross-Domain-Policies
Content-Encoding
X-Buckets
X-Content-Security-Policy
X-Turbo-Charged-By
X-Kinja-Server-Push
Upgrade
X-CDN
Xkey
X-Type
Keep-Alive
Access-Control-Expose-Headers
X-Request-ID
Access-Control-Max-Age
WPE-Backend
X-Pass-Why
X-AH-Environment
X-Backend
X-Cache-Group
X-Server
X-Age
X-Drupal-Dynamic-Cache
X-Via
X-Pingback
X-Nginx-Cache-Status
Grace
X-Server-Powered-By
X-Amz-Id-2
X-Amz-Request-Id
EagleId
X-Hacker
X-UA-Device
X-Robots-Tag
X-LiteSpeed-Cache
X-Varnish-Cache
X-Page-Speed
X-Proxy-Cache
Request-Context
X-Swift-SaveTime
X-Swift-CacheTime
Cf-Railgun
X-Envoy-Upstream-Service-Time
Ali-Swift-Global-Savetime
X-Ua-Compatible
X-WebKit-CSP
X-Ac
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
X-Cache-Lookup
X-Amz-Version-Id
X-Server-Id
X-Cnection
X-OneAgent-JS-Injection
X-Node
Content-Location
Surrogate-Control
X-CST
X-Readtime
EagleEye-TraceId
Report-To
X-Host
X-Response-Time
X-Rq
Feature-Policy
Server-Timing
X-Iejgwucgyu
X-Backend-Server
X-Application-Context
X-Rack-Cache
X-ORACLE-DMS-ECID
Request-Id
X-Instart-Request-ID
X-Cloud-Trace-Context
Allow
X-Url
X-Clacks-Overhead
NEL
Rating
X-DynaTrace
X-Country
Edge-Control
X-Origin-Cache
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-FTR-Request-ID
X-Varnish-TTL
X-Country-Code
X-Cdn
X-Px
X-B3-TraceId
X-Server-ID
X-DataDome
X-Ruxit-JS-Agent
X-GitHub-Request-Id
X-ORACLE-DMS-RID
X-Vhost
X-Trace
X-VARITI-CCR
Accept-CH
X-Goog-Hash
Charset
X-ESI
X-Cached
X-Server-Name
RTSS
Pinterest-Generated-By
X-MS-InvokeApp
X-Mod-Pagespeed
Verso
PB-RID
Arc-Version
PB-PID
X-Mobile-Rewrite
Public-Key-Pins
X-TTL
X-D2id
X-Use-Magma
X-Exp-Variant
X-Exp-Id
X-Version
X-GoogleNews-Bot
X-Kinja-Server
X-Kinja-Revision
X-Kinja-Build
X-Kinja
X-Cdn-Fetch
X-F-Cache
SPRequestGuid
X-PC
X-TtlSet
X-Vname
X-Dispatcher
X-DynaTrace-JS-Agent
X-DIS-Request-ID
X-Powered-By-Plesk
X-T
Accept-CH-Lifetime
X-Abt-Application-Version
X-Powered-CMS
X-SharePointHealthScore
X-Fastly-Request-ID
X-Origin-Upstream-Status
X-Ser
X-Navigation-Version
X-Pinterest-Rid
Pinterest-Version
X-Upstream-Env
X-SRCache-Fetch-Status
X-B
X-SRCache-Store-Status
X-Amz-Rid
X-Client-IP
X-Shield-Request-Id
Realpath
X-Forwarded-Proto
MS-Author-Via
X-Recruiting
X-HW
X-Upstream
X-Vcap-Request-Id
SPRequestDuration
SPIisLatency
DynaTrace
X-TEC-API-ORIGIN
X-Accel-Buffering
X-Wix-Server-Artifact-Id
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-XRDS-Location
X-Amz-Meta-S3cmd-Attrs
Nginx-Cache
Arr-Disable-Session-Affinity
X-Varnish-Age
AR-PoweredBy
AR-CACHE
AR-ATIME
Content-MD5
X-Ttl
X-Debug
X-Mrf-Section-Lastmod
Mrf-Cache-Status
MRF-Tech
X-Mrf-Item-Lastmod
X-B3-TraceId-Primal
X-Via-JSL
X-Dw-Request-Base-Id
X-Hits
X-Goog-Storage-Class
X-Oracle-Dms-Rid
X-Aspnet-Version
X-MSEdge-Ref
X-Id
X-Acc-Meta-Resource-Type
X-NF-Request-ID
X-FTR-DC
X-FTR-Backend
X-FTR-Realm
X-Country-Code-Real
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-Backend-Server
X-N
Service-Worker-Allowed
X-FTR-Expires
S
X-NewRelic-App-Data
Access-Control-Request-Method
Edge-Cache-Tag
X-ATG-Version
Alternate-Protocol
X-FastCGI-Cache
X-Logged-In
AMP-Access-Control-Allow-Source-Origin
X-Kinsta-Cache
TCN
X-PressLabs-Stats
X-HS-Hub-Id
X-HS-Content-Id
X-Frontend
Surrogate-Key
X-Forwarded-For
Rt-Fastcgi-Cache
X-FTR-Cache-Host
X-RateLimit-Remaining
X-Content-Digest
X-Cache-Key
Tracecode
X-TA-CDN-Provider
X-CF-Powered-By
X-Pad
Server-Name
X-Oneagent-Js-Injection
X-Amzn-Trace-Id
Fastcgi-Cache
X-Analytics
Backend-Timing
X-User-Agent
Fastly-Restarts
MicrosoftSharePointTeamServices
TP-L2-Cache
TP-Cache
X-Cache-2
Host
FilterID
X-Edge-Location
X-Magnolia-Registration
X-Rid
X-Debug-Info
X-Grace
X-B3-Sampled
ServerID
Ar-Sid
X-Whom
X-Mobile
X-Page-Id
X-Revision
X-Content-Options
X-IPLB-Instance
Eomportal-Instance
Front-End-Https
X-Hostname
X-Srv
X-Akam-SW-Version
AR-Request-ID
Paypal-Debug-Id
X-NWS-LOG-UUID
Refresh
X-LB-Cache
X-VCache
X-AppVersion
X-Az
Retry-After
X-Activity-Id
X-Content-Powered-By
X-Signature
X-Litespeed-Cache
X-Request-Processing-Time
X-Request-Received
X-GUploader-UploadID
X-B-Cache
X-SS-Set-Cookie
X-Cluster
X-Cache-Action
X-Framework
X-Handled-By
X-App-Environment
X-Varnish-Hostname
Source
X-Platform-Server
X-Request-Guid
X-Cache-Control
X-Tumblr-Pixel-0
X-Tumblr-Pixel
Cleartype
X-Tumblr-User
X-BCube-Filmed-By
X-FB-Debug
X-Instance
X-Akamai-Edgescape
X-WA-Info
X-Device-Type
X-Content-Security-Policy-Report-Only
X-Content-Type
X-AOL-HN
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
Webserver
X-Zen-Fury
X-Ruxit-Js-Agent
X-Cache-Hit
X-Varnish-Grace
Accept-Charset
Display
X-Sol
X-Middleton-Display
X-Cache-Rule
X-Varnish-Backend
X-Esi
Healthy
X-Seen-By
ViewerVersion
X-Wix-Request-Id
X-TT
X-Correlation-Id
X-URL
X-Fastcgi-Cache
X-Origin-Server
X-Drupal-Cache-Tags
Cache-Status
Response
X-Middleton-Response
X-Cache-Server
Upgrade-Insecure-Requests
X-DataStream-Cache-Status
MS-CV
X-Daa-Tunnel
X-Cached-By
X-Varnish-Server
X-CACHE-GROUP
X-Cache-Age
X-Amz-Apigw-Id
X-Drupal-Cache-Contexts
X-Amz-Replication-Status
X-Geo-Country
X-Generated-By
X-Amzn-RequestId
X-App-Server
X-Storage
X-PHP-Backend
Payment
Server-Node
NGB
X-UA-Device-Type
X-Response-Served-From
Filters
Access-Control-Allow-Method
X-Adobe-Content
X-Amz-Server-Side-Encryption
X-Adobe-Loc
GEO-INFO
X-Cacheable-TTL
X-Edge-Cache
X-RequestSource
X-Edge-Cache-Key
X-TT-TIMESTAMP
X-Cache-NE
X-S
X-Servedby
X-Contextid
X-UUID
X-FW-Server
X-FW-Serve
X-FW-Static
X-Jobs
ServedBy
Actual-Object-TTL
X-Varnish-IP
X-FW-Type
X-FW-Hash
X-TX-ID
X-WPE-Loopback-Upstream-Addr
X-Tumblr-Pixel-1
X-Accel-Expires
X-Tumblr-Pixel-2
Viewport
Server-Info
X-Varnish-Hits
X-Locale
X-Cache-Remote
AsisCache
Cache-Tv-Group
X-HS-Cache-Config
X-WebKit-CSP-Report-Only
X-Cache-TTL-Remaining
S-Cnection
X-Status
From-Origin
X-Dns-Prefetch-Control
X-Rendered-As
X-GeoIP
Host-Header
X-Cache-Operation
Cache
X-Region
X-APP-VERSION
X-XRDS-LOCATION
X-App-Version
X-Croise-Owner
SRV
HostName
X-Webkit-CSP
X-Redis-Cache
Served-By
Content-Script-Type
X-BACKEND-TTL
Content-Style-Type
X-Hyper-Cache
X-Node-Name
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Liferay-Portal
DC
X-CACHE-KEY
Public-Key-Pins-Report-Only
Cache-Tag
X-Cache-Config
Ms-Operation-Id
X-Upgrade-Enabled
X-RTag
Xserver
X-Vg-Webcache
X-Grey
Machine
X-NGENIX-Cache
Meta-Geo
X-Hosted-By
X-RN-RSRV
X-Webstats-RespID
X-Generated
X-Proxy-Build
X-Mode
X-Cache-Category-Id
X-Cache-Var
Selected-FE
X-Detected-As
X-Cache-Var-Map
X-Is-Bot
X-Parent-Response-Time
X-Timing-Wait
X-Path-Route
X-BYPASS-REASON
X-CDN-Cache
X-Agile-Id
X-Internal-Host
X-Agile-Age
X-Human
X-Agile
X-Environment-Context
X-Akamai-Request-ID
Now
X-Labrador-Cache-Channel
X-Loop
X-NCache
X-L-Path
Cache-Name
X-JoinUs
X-Edge-IP
X-Akamai-Transformed
X-ProxyCache-Status
X-Via-Fastly
X-Upstream-CT
X-Upstream-HT
X-TNCMS
Origin-Edge-Control
Origin-Cache-Control
X-Request-Time
X-Original-Request
X-Web-Node
X-ProxyCache-Key
X-Origin-Response-Time
X-Tumblr-Pixel-3
User-Cache-Control
X-Format
X-Birta-Served
Azure-SlotName
Azure-Version
Cache-Key
Azure-SiteName
Azure-RegionName
DB-Nickname
Azure-InstanceId
X-Birta-Cache-Post
X-Time-Microsecs
X-Pc-Key
X-Proxy
X-Protected-By
X-IP
X-ProcessESI
X-RemovedCookies
X-Pc-Appver
X-Pc-Hit
X-Origin-Host
X-Viewer-Country
X-Origin
X-ServerID
TWC-GeoIP-Country
TWC-Privacy
Fastcgi-Useragent
TWC-Locale-Group
TWC-GeoIP-LatLong
X-Xfnlog-Site
Webcakes-Region
Webcakes-App-Name
Property-Id
Cache-Tags
S-Rt
X-Access
TWC-Connection-Speed
Fastcgi-X-Cache-Version
TWC-Device-Class
Webcakes-App-Version
X-VG-TLSProxy
Fastcgi-X-Cache
X-FC-Vary-Parameters
Powered-By-ChinaCache
X-Tb
Load-Balancing
X-Origin-CC
X-Site-Version
X-Section
X-Ocache
X-B3-Spanid
X-Pubstack
X-CCM
X-Rule
X-Origin-Hint
X-OCL
X-Guploader-Uploadid
X-Backend-Name
X-PCL
X-Routing-Service
X-App-Name
X-Proxied
HitType
X-Forwarded-Host
X-Zipkin-Id
Vix-Hermes-Req-Id
X-Vgn-Hpd-Reason
X-Www-Served-By
X-FB-TRIP-ID
X-ApacheServer
X-PERF
Mn-Server-Ip
Country
X-RateLimit-Limit
Pagespeed
X-Cdn-Forward
X-GRACE
X-Via-CDN
X-Nginx-Cache
X-Endurance-Cache-Level
X-Cache-TTL
X-Cache-Backend
X-Content-Age
X-Correlation-ID
Datacenter
X-TIME
X-Unique-Id-Primal
X-Mrs-Age
X-Mrs-Cache-Hits
X-Mrs-Cache
X-Mshield-Cache-Status
OT-Force-Account-Verify
X-Real-IP
Time
Fusion-Template-Id
Fusion-Source
Fusion-Content-Source
Fusion-Content-Id
Fusion-Component-Id
AR-SID
X-Ezoic-Cdn
X-Alternate-Cache-Key
X-Yottaa-Metrics
X-Sorting-Hat-ShopId
Ohc-File-Size
X-Yottaa-Optimizations
X-Sorting-Hat-PodId
X-Shopify-Stage
X-ShopId
X-ShardId
X-Ua
X-Varnish-Cacheable
X-Debug-Cache
X-Varnish-Beresp-Ttl
X-UA
X-OVcl-Cache
X-OVcl
NtCoent-Length
X-Newrelic-App-Data
X-Sucuri-ID
X-Pc-Host
X-Pc-Date
LB
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-Hl-Ver
L5d-Success-Class
X-Unique-ID
We-Hiring
X-MP-GENERATED-AT
Mail-Subject
X-Time
X-Real-Ip
Section-Io-Cache
X-HS-Combine-CSS
User-Agent
X-Hit
X-Amz-Meta-Surrogate-Control
X-Trace-Id
X-Proto
X-Nc
X-Akamai-Request-ID2
X-Front
X-Cache-Enabled
Access-Control-Request-Headers
X-Dynatrace-Js-Agent
Pagetype
X-Ratelimit-Limit
X-C
X-CDN-Forward
X-EdgeConnect-Cache-Status
X-CLOUD-TRACE-CONTEXT
Warning
X-Microcachable
X-Rocket-Nginx-Bypass
Version
Accept-Language
X-Cache-Bucket
X-Bip
X-Destination
X-BB-ID
X-Cache-Debug
X-B-Cookie
X-Actual-URL
X-Developer
X-Aed
X-Application
X-Auto-Login
X-Cache-FS-Status
X-Cache-Host
X-Date
Xc-Version
X-CUA
X-D
X-Crawler
X-Connection-Hash
X-Cache-URL
X-CF-Lambda-Fn
X-Accel-Expires-Debug
X-CF-Lambda-Version
X-Cache-Id
X-A-Wwc
Release
Powered-By
Rendered-Blocks
Request-Time
RNT-Machine
Resin-Trace
Platform
PFcat
MD5-Digest
Is-Eu
Memcached
Meta-Geo-Continent
Node
Mobile-Detection-Method
RNT-Time
Rt-Proxy-Cache
X-A
Www
X-A-Ccd
X-A-Dam
X-A-Dgt
X-A-Dcw
VivaBuild
Viewtype
Server-ID
Server-Host
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
V-Age
Thinkindot-Control
X-Device-Os
X-Dispatcher-Server
X-Transaction
X-Trv-Group
X-Request-UUID
X-Thinkindot-L3
X-Returned-From
X-Thanos
X-Region-Sid
X-TT-LOGID
X-RCS-CacheZone
X-Qloud-Router
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
IBM-Web2-Location
X-Reboot
X-Returned-From-BeforeDispatch
X-Returned-From-DLL
X-SRCache-Key
X-Store
X-Server-Time
X-Server-IP
X-Server-By
X-ScT
X-S-Maxage
X-Svr
X-Returned-From-PostProcessResponse
X-Swa-Ws
X-Rewrite-Enabled
X-Rojux
X-S-Cookie
X-PHP-Host
X-PAYTM-SRV-ID
X-Var-Ttl
X-Fetched-On
X-From
X-FW-Version
X-Generated-In
X-G
X-Variation
X-VG-WebServer
X-We-Are-Hiring
X-WebServer
X-Served-From
X-DPWN-IS-SECURE
X-External-Request-Id
X-UE-Client-Country
X-Goog-Meta-Goog-Reserved-File-Mtime
X-NU-AKA-ACS-Version
X-Matched-Rule
X-Passed-To
X-Passed-To-BeforeDispatch
X-Passed-To-PostProcessResponse
X-Passed-To-DLL
X-Logtrace-Id
X-LI-UUID
X-Layer
X-Twitter-Response-Tags
X-Li-Fabric
X-Li-Pop
X-LI-Proto
X-Died
X-Cache-Expires
Fly-Cache
Adler-Geo
Ec-Rule-Version
Fastly-SWR
Arc-Country
BehaviorPad-Version
Fly-Request-Id
Fastly-Backend-Name
Frame-Options
Fastly-SIE
X-Server-Cache
Ajk
Cache-Prefix
X-Sf
Ohc-Response-Time
X-ServiceProvider
X-Response-By
X-Secret
X-Server-Group
X-Clientip
X-Block-Status
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
X-Stale
Content-Disposition
Cache-Cookie-Set-From
Backend-Name
X-ElasticPress-Search
X-MI-In-Market
X-Backend-Host
Backend
X-Cache-CFC
X-Release
X-IN-WAF
X-Info
X-IN-SSL-APIGATEWAY
X-IN-APIGATEWAY
X-Hash
X-Hnp-Log
X-Node-Id
X-Instart-Info
X-MSEdge-Features
X-Location
X-MSEdge-Flight
X-Nginx-Cache-Key
X-No-Session
X-Level-Front-Cache
X-Origin-Date
X-GeoIP-Country-Code
X-Epic-Correlation-Id
X-Proxy-Cache-Status
X-Proxy-Upstream
X-Distributor
Country-Code
X-Distil-CS
X-F5-Cache
X-Phone
X-Generated-On
X-Origin-Expires
X-Gen-Mode
X-P-T
X-Fstrz
X-Gannett-Site-Version
X-Request-Start
X-Backend-Url
Pramga
Magicmarker
X-Amz-Meta-Cache-Control
Proxy-Connection
X-Via-NSCOPI
X-User
Server-Int
SD-X-WS
X-ARC
Origin
Lfy
Kp-EeAlive
Heartbleed
MI-API
MI-Cache
GMS-Ver
GW-Server
MI-Cache-Age
SS
X-Varnish-Action
Decoy-Debug-TTL
Decoy-Debug-Status
True-Client-Country-4JS
Decoy-Debug-Key
Countrycode
Web-Mar-Node
Esi-Enabled
X-UnsetCookies
Who
X-NODE
X-SVT-ORM-RULES
X-Eu-Site
Apple-News-Services-Request-Url
X-Wikidot-Static-Cache
HA-Geolat
X-Key
HA-Geolon
IsBot
X-SVT-ORM-VERSION
HA-Geocountry
X-Origin-TTL
X-Irp-Debug
CDCHOST
HA-Cloudapp
X-Wikidot-Backend
X-Page-Type
HA-Georegion
X-Fastly-Cache
X-Platform
X-Request-URI
On-Server
X-Policy
X-Up
X-Cdn-Srv
X-SIPLIST1
Fastly-Soc-X-Request-Id
Fastly-SSL
X-CGP
X-Cache-Info
X-Backend-State
ServerName
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Handled
AKAMAI
X-Developers
X-Micro-Cache
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-Debug-Cache-Store
HA-Servedtime
HA-Geocity
HA-Urlpath
Ha-Gx-Prefs
HA-Ipaddr
X-Core-Mission
X-V
HA-Host
X-Core-Value
X-DC
X-Be
PageSpeed
X-NX-Host
X-Sn-Servicetimems
X-Debug-Cookies
X-CACHE-AGE
X-Servername
X-Debug-Log
REQUESTUUID
X-Geo
X-Cdn-Origin
WZWS-RAY
X-Dc
X-COUNTRY
X-CMS-Context
X-NC
X-Refresh
RequestId
X-Org
X-Via-Edge
X-Pjax-Url
X-Via-SSL
MIME-Version
Cteonnt-Length
X-LAGOON
X-Datadome
X-Newrelic-Synthetics
X-VarnCache
X-VarnPar1
X-PARISIEN-Cache-Rendered
X-Servedbyhost
Pragrma
X-Req
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
UCS
Cdn
X-Urbn-Site-Id
Memory
Locale
NGX
X-Instance-Name
Request-Country
X-Urbn-Context-Path
X-Planisys-CDN-Cache
Request-EU
Uber-Trace-Id
Mime-Version
X-NWS-UUID-VERIFY
Host-ID
Group
V-Cache
X-VCT
PICS-Label
Cache-Provider
X-CSRF-TOKEN
X-GeoIP-City
X-Wa
X-Gdpr
X-Webkit-Csp
X-FireWall-Port
X-Generation-Time
X-RateLimit-Remaining-Second
Nel
X-RateLimit-Limit-Second
CF-IPCountry
GeoIP-Country-Code
X-Varnish-Cache-Hits
GeoIP-Latitude
X-HTML-Minification-Powered-By
X-WR-MODIFICATION
CDN
X-BBXSRF
X-B3-Traceid
X-Ratelimit-Remaining
HitInfo
X-UPSTREAM-Address
X-Powered-By-ANYU
X-Aicache-OS
X-Cache-Miss-From
X-Cache-Grace
X-DataStream-MidMile-RTT
X-Varnish-Authentication
X-DataStream-Origin-MEX-Latency
Server-Cache-Control
X-Sedo-Request-Id
X-Cache-ASPX
Server-Surrogate-Control
X-Load-Cache
X-Fastly-Country-Code
XServer
X-StackifyID
X-IPS-LoggedIn
Cf-Ipcountry
X-VG-WebCache
X-Varnish-Url
X-Source
X-EIG-Tracking-Id
X-Instart-Isnd
GeoIp-Country-Code
X-ND-Cache
Geoip-Latitude
X-Sucuri-Cache
X-Check-Cacheable
X-Fastly-Backend-Reqs
X-From-Cache
X-HOST
X-RCS-Backend
X-FORWARDED-FOR
URI
X-TWH-CORRELATION-ID
CACHE
Is-Session-Tracking
X-GEO
Proxy-Firewall
Get-Access-Time
X-APP
Pics-Label
X-CDN-Pop
X-CDN-Pop-IP
X-WA
X-Fastly-Cache-Hits
X-Oracle-Dms-Ecid
X-Unique-Id
FSS-Cache
X-GoCache-CacheStatus
X-Varnish-Beresp-TTL
FSS-Proxy
Powered
X-Dynatrace
X-R9-Blue-Green-Version
X-FW-Dynamic
X-SRV
X-Skip-Cache
X-Sentry-ID
X-Server-W
X-NodeID
X-VC-Cache
DataCenter
X-ID
SN
X-Cluster-Node
X-ABtesting
X-Csrf-Token
X-GDPR
X-Hello
X-RequestId
X-Flog
X-ServedByHost
X-HS-Status
Processtime
X-VServer
X-Pc-Subdomain
WP-Super-Cache
X-Nananana
X-BE
Amp-Access-Control-Allow-Source-Origin
X-Oss-Request-Id
X-Oss-Server-Time
X-CSRF-Token
X-Oss-Storage-Class
X-Oss-Object-Type
X-PF-Uncompressing
X-Oss-Hash-Crc64ecma
X-B3-SpanId
Dynatrace
X-Fe
X-PJAX-URL
X-GZip
Hostname
X-TrackingId
X-Pf-Uncompressing
X-GZIP
FastCGI-Cache
X-Worker
X-Backend-TTL
X-Amzn-Remapped-Date
TSSecure
ProcessTime
Requestid
X-Bug-Bounty
Cache-Hits
X-Gen-Id
X-Amzn-Remapped-Connection
X-Atg-Version
X-Edge-Server
X-NGINX-Cache
X-Cache-Ttl
X-Swift-Error
X-LiteSpeed-Cache-Control
X-MServer
Cdn-Request-Time
X-ORIG-AKA-EDGE
Cdn-Host
Serverid
X-LiteSpeed-Tag
X-HostName
RequestUuid
A
X-ServerName
X-Tb-Optimization-Total-Bytes-Saved
X-VC
X-Alicdn-Da-Ups-Status
T-Server
X-ORIG-AKA-COUNTRY-CODE
X-Varnish-URL
X-SB
X-RAMCache
X-PAGE-TYPE
X-ES-SERVER
189phosttRef
219prxHost
Xxline
225prxHost
286prxHost
355prline
188prxHost
X-LJ-Flow-ID
X-SN
X-AWS-Id
SID
X-Owner
X-VWS-Id
409pxxline
352pxline
Correlation-Id
X-VarnPar2
NnCoection
X-Port
Location
X-Developed-By
X-CS
X-Serial
Xet-Cookie
Cneonction
DSUID
X-Akamai-ERPolicy
X-Dw-Trace-Id
X-Akamai-ERRuleID
178proxuri