Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
Last-Modified
X-Content-Type-Options
Accept-Ranges
Pragma
X-Powered-By
CF-RAY
Link
ETag
Expect-CT
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-UA-Compatible
P3P
X-Cache-Hits
X-Amz-Cf-Id
X-Served-By
Referrer-Policy
X-Varnish
X-Xss-Protection
X-Timer
CF-Cache-Status
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Runtime
X-Download-Options
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Drupal-Cache
X-Cacheable
Alt-Svc
X-Check
X-Generator
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Cache-Status
X-AspNetMvc-Version
Status
X-DNS-Prefetch-Control
X-Request-ID
Timing-Allow-Origin
X-Template
X-Language
X-Permitted-Cross-Domain-Policies
Content-Encoding
X-Iinfo
X-Content-Security-Policy
X-CDN
X-Buckets
X-Turbo-Charged-By
P3p
X-Type
Upgrade
WPE-Backend
X-Pass-Why
Keep-Alive
X-Cache-Group
X-AH-Environment
Xkey
X-Backend
Access-Control-Max-Age
X-Age
Access-Control-Expose-Headers
X-Via
EagleId
X-Drupal-Dynamic-Cache
X-Nginx-Cache-Status
X-Pingback
X-Amz-Id-2
X-Amz-Request-Id
X-Server-Powered-By
X-Server
X-Hacker
X-Swift-CacheTime
X-Swift-SaveTime
X-UA-Device
Grace
Ali-Swift-Global-Savetime
X-Varnish-Cache
X-Robots-Tag
X-Kinja-Server-Push
Cf-Railgun
X-Proxy-Cache
X-Envoy-Upstream-Service-Time
X-Page-Speed
X-LiteSpeed-Cache
Request-Context
X-Device
X-Ac
X-Pantheon-Styx-Hostname
Content-Location
X-Styx-Req-Id
X-Cache-Lookup
X-Amz-Version-Id
X-WebKit-CSP
X-Host
X-Response-Time
Surrogate-Control
X-OneAgent-JS-Injection
X-Rq
X-Cnection
X-Backend-Server
X-Node
X-Server-Id
X-Readtime
Server-Timing
X-Rack-Cache
Report-To
EagleEye-TraceId
X-Application-Context
Request-Id
Feature-Policy
X-ORACLE-DMS-ECID
X-Cloud-Trace-Context
X-CST
X-Instart-Request-ID
X-Iejgwucgyu
X-Ua-Compatible
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Clacks-Overhead
Edge-Control
NEL
Rating
X-Url
X-Country
X-Server-Name
Pinterest-Generated-By
X-Px
Allow
X-Country-Code
X-DataDome
X-Varnish-TTL
X-MS-InvokeApp
X-DynaTrace
X-Origin-Cache
X-TTL
X-Vhost
X-Vname
X-TtlSet
X-PC
X-Cached
X-FTR-Request-ID
X-ESI
RTSS
X-Ruxit-JS-Agent
X-Goog-Hash
Charset
X-Powered-CMS
X-VARITI-CCR
X-Trace
X-Powered-By-Plesk
SPRequestGuid
Accept-CH
X-DynaTrace-JS-Agent
X-GitHub-Request-Id
X-Dispatcher
Public-Key-Pins
X-D2id
X-SharePointHealthScore
X-Server-ID
X-T
PB-RID
Arc-Version
X-Mod-Pagespeed
X-Mobile-Rewrite
PB-PID
X-Oracle-Dms-Rid
X-F-Cache
Content-MD5
X-GoogleNews-Bot
X-Exp-Variant
X-Cdn-Fetch
X-Exp-Id
X-Kinja-Build
X-Kinja
X-Kinja-Server
Verso
X-Kinja-Revision
MS-Author-Via
X-Version
X-B3-TraceId
X-Recruiting
SPIisLatency
X-Shield-Request-Id
SPRequestDuration
X-Abt-Application-Version
Nginx-Cache
X-Dns-Prefetch-Control
X-Client-IP
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Forwarded-Proto
X-HW
Accept-CH-Lifetime
X-DIS-Request-ID
X-Navigation-Version
X-N
AR-ATIME
AR-PoweredBy
X-Upstream-Env
AR-CACHE
X-Pinterest-Rid
X-Amz-Rid
Pinterest-Version
X-B
X-Dw-Request-Base-Id
X-XRDS-Location
X-Upstream
X-ORACLE-DMS-RID
X-Origin-Upstream-Status
X-Fastly-Request-ID
DynaTrace
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Fastly-Restarts
X-Amz-Meta-S3cmd-Attrs
X-Ser
X-Hits
Paypal-Debug-Id
TCN
X-Wix-Server-Artifact-Id
Realpath
X-Accel-Buffering
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Content-Options
Arr-Disable-Session-Affinity
X-Pad
X-NF-Request-ID
Service-Worker-Allowed
X-Acc-Meta-Resource-Type
X-Goog-Storage-Class
Tracecode
Access-Control-Request-Method
X-Content-Digest
S
X-Id
Front-End-Https
X-Varnish-Age
X-Litespeed-Cache
X-Debug
X-Mrf-Section-Lastmod
Mrf-Cache-Status
MRF-Tech
X-Mrf-Item-Lastmod
X-Amz-Cf-Pop
X-MSEdge-Ref
X-Vcap-Request-Id
X-Oneagent-Js-Injection
X-Frontend
X-IPLB-Instance
X-FTR-Realm
X-Country-Code-Real
X-FTR-Expires
X-PressLabs-Stats
X-FTR-Backend
X-FTR-Cache-Status
X-ATG-Version
X-FTR-Balancer
X-FTR-DC
X-FTR-Backend-Server
X-Kinsta-Cache
X-Middleton-Display
X-RateLimit-Remaining
X-Sol
Display
X-Logged-In
X-Cache-Hit
Edge-Cache-Tag
X-HS-Content-Id
X-HS-Hub-Id
Surrogate-Key
X-FastCGI-Cache
X-Forwarded-For
Fastcgi-Cache
Rt-Fastcgi-Cache
X-Use-Magma
Powered-By-ChinaCache
X-Request-Received
X-Request-Processing-Time
X-Zen-Fury
MicrosoftSharePointTeamServices
X-Edge-Location
X-Analytics
Backend-Timing
X-Grace
Server-Name
Ar-Sid
X-Amzn-Trace-Id
X-Rid
X-Middleton-Response
X-Ttl
FilterID
X-Debug-Info
X-Revision
Response
Host
TP-L2-Cache
X-User-Agent
TP-Cache
X-Akam-SW-Version
X-FTR-Cache-Host
X-CF-Powered-By
X-Webkit-Csp
X-NewRelic-App-Data
X-Mobile
X-B3-TraceId-Primal
X-Cache-Key
X-SS-Set-Cookie
X-HS-Cache-Config
X-Drupal-Cache-Tags
X-TA-CDN-Provider
X-Accel-Expires
X-Magnolia-Registration
Cache-Status
X-Cached-By
Refresh
AMP-Access-Control-Allow-Source-Origin
AR-Request-ID
Host-Header
X-SERVER
X-Newrelic-App-Data
X-Fastcgi-Cache
ServerID
X-B3-Sampled
X-Varnish-Backend
X-GUploader-UploadID
X-Node-Name
X-AOL-HN
X-Content-Security-Policy-Report-Only
X-FB-Debug
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel
X-Instance
X-Cluster
X-B-Cache
X-Webkit-CSP
X-Cache-Control
X-Akamai-Edgescape
X-Signature
X-App-Environment
Cache-Tag
X-LB-Cache
X-Page-Id
X-Platform-Server
X-Framework
X-Device-Type
Eomportal-Instance
X-BCube-Filmed-By
X-Whom
X-Handled-By
X-Generated-By
X-Cache-2
Cleartype
X-Varnish-Hostname
X-Srv
X-Cache-Rule
X-Request-Guid
DC
X-NWS-LOG-UUID
Liferay-Portal
X-AppVersion
X-Activity-Id
X-Ruxit-Js-Agent
X-Az
X-Drupal-Cache-Contexts
X-WPE-Loopback-Upstream-Addr
X-Geo-Segment
Public-Key-Pins-Report-Only
X-Cache-Action
X-App-Server
X-VCache
X-Cache-Server
Source
X-Content-Powered-By
X-Via-JSL
MS-CV
Retry-After
Accept-Charset
X-Wix-Request-Id
Alternate-Protocol
X-TT
X-Seen-By
X-HS-Combine-CSS
X-Hostname
ViewerVersion
X-App-Version
X-Amz-Replication-Status
X-Varnish-Grace
X-Varnish-Server
X-WA-Info
Webserver
X-Correlation-Id
Server-Node
X-Geo-Country
X-Esi
Upgrade-Insecure-Requests
HostName
AsisCache
X-Cache-NE
X-Response-Served-From
X-WebKit-CSP-Report-Only
X-Tumblr-Pixel-1
X-Tumblr-Pixel-2
SRV
X-Amzn-RequestId
Actual-Object-TTL
X-Locale
X-Amz-Apigw-Id
X-GeoIP
X-RequestSource
X-URL
ServedBy
X-Daa-Tunnel
X-Jobs
GEO-INFO
X-Yottaa-Metrics
X-Yottaa-Optimizations
Viewport
X-Varnish-Hits
X-FW-Type
X-FW-Hash
X-FW-Serve
X-Edge-Cache-Key
X-Edge-Cache
X-Contextid
Payment
X-FW-Server
X-UUID
X-Servedby
X-FW-Static
X-Status
X-TX-ID
X-S
Pagespeed
AR-SID
X-CLOUD-TRACE-CONTEXT
Cache
X-Varnish-IP
X-Adobe-Loc
X-Adobe-Content
X-Correlation-ID
X-TT-TIMESTAMP
X-Cacheable-TTL
X-Origin-Server
X-Vg-Webcache
X-Cache-TTL-Remaining
X-Forwarded-Host
X-Cache-Operation
S-Cnection
X-Cache-Age
X-Hyper-Cache
X-Amz-Server-Side-Encryption
Datacenter
Server-Info
Served-By
X-Region
X-Sucuri-ID
Country
X-TIME
X-Mode
CACHE
X-Akamai-Request-ID2
X-RateLimit-Limit
X-Real-IP
From-Origin
Access-Control-Allow-Method
Healthy
X-Rendered-As
X-Is-Bot
X-Routing-Service
X-RN-RSRV
X-Content-Type
X-Proxied
X-Path-Route
X-Cache-Var
X-Cache-Config
X-Generated
X-Ezoic-Cdn
X-Rule
X-Proxy
X-Zipkin-Id
Machine
X-Cache-Var-Map
Fastcgi-X-Cache
Fastcgi-X-Cache-Version
X-Microcachable
X-Upgrade-Enabled
X-Site-Version
Meta-Geo
X-DataStream-Cache-Status
X-Ocache
X-Detected-As
X-JoinUs
X-Environment-Context
X-EIG-Tracking-Id
X-L-Path
X-CDN-Cache
X-NGENIX-Cache
X-Format
X-Hosted-By
X-Section
L5d-Success-Class
X-Viewer-Country
Now
X-Access
Fastcgi-Useragent
X-Birta-Served
X-Amz-Meta-Surrogate-Control
X-Birta-Cache-Post
TWC-GeoIP-Country
TWC-GeoIP-LatLong
X-Agile-Age
X-CCM
OT-Force-Account-Verify
Property-Id
TWC-Device-Class
TWC-Locale-Group
X-FC-Vary-Parameters
DB-Nickname
Webcakes-App-Version
Webcakes-Region
X-Cache-Category-Id
Webcakes-App-Name
TWC-Privacy
X-Agile-Id
X-Agile
X-Origin-Hint
X-Pc-Appver
S-Rt
X-Tb
X-Pc-Hit
X-Pc-Key
X-Human
X-PCL
TWC-Connection-Speed
X-Via-Fastly
X-Grey
X-Akamai-Transformed
X-Hit
X-Loop
X-TNCMS
X-OCL
Azure-Version
Azure-SiteName
Azure-SlotName
X-Xfnlog-Site
Azure-RegionName
X-VWS-Id
X-Upstream-CT
X-Upstream-HT
X-SplitTest
Azure-InstanceId
Cache-Name
X-Web-Node
X-Pubstack
X-Original-Request
X-OVcl
X-Cluster-Node
X-Via-CDN
X-IP
X-LJ-Flow-ID
X-OVcl-Cache
X-ProcessESI
X-RemovedCookies
X-ServerID
X-VG-TLSProxy
X-Labrador-Cache-Channel
Accept-Language
X-AWS-Id
X-Www-Served-By
X-ShardId
X-Alternate-Cache-Key
X-Proxy-Build
X-Origin
X-Request-Time
X-ShopId
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Shopify-Stage
X-Timing-Wait
Mn-Server-Ip
LB
Selected-FE
Xserver
Cache-Hits
HitType
HitInfo
X-Rocket-Nginx-Bypass
PageSpeed
X-ProxyCache-Status
Content-Style-Type
Origin-Cache-Control
X-Source
X-App-Name
Origin-Edge-Control
X-BYPASS-REASON
X-ProxyCache-Key
Content-Script-Type
X-Cache-Enabled
X-Cdn
X-XRDS-LOCATION
X-Guploader-Uploadid
X-TWH-CORRELATION-ID
X-UA
X-Transaction
X-Twitter-Response-Tags
X-RTag
X-Connection-Hash
IBM-Web2-Location
Access-Control-Request-Headers
X-Unique-ID
X-GRACE
Ms-Operation-Id
X-Real-Ip
NGB
X-Ms-Request-Id
X-Ms-Lease-Status
X-Ms-Version
X-Ms-Blob-Type
X-Port
X-Geo
X-Origin-CC
Time
NtCoent-Length
X-NodeID
X-Cache-Remote
Filters
X-Pc-Host
X-MP-GENERATED-AT
X-Pc-Date
X-Distil-CS
X-NCache
X-Internal-Host
X-Tumblr-Pixel-3
X-Edge-IP
X-Cdn-Forward
X-Nginx-Cache
We-Hiring
Mail-Subject
Backend
X-APP-VERSION
X-Varnish-Cacheable
X-Cache-TTL
X-Proto
X-Debug-Cache
X-CACHE-KEY
X-Storage
X-Ratelimit-Limit
X-Vgn-Hpd-Reason
X-Time-Microsecs
X-UA-Device-Type
X-Webstats-RespID
X-PHP-Backend
X-Backend-Name
Cache-Tags
X-Varnish-Beresp-Status
X-Csrf-Token
X-Varnish-Beresp-Grace
X-Varnish-Cache-Hits
X-Sucuri-Cache
X-CACHE-GROUP
X-Akamai-Request-ID
User-Agent
X-Dc
X-EdgeConnect-Cache-Status
Locale
X-Urbn-Site-Id
X-Urbn-Context-Path
X-ApacheServer
X-Mrs-Cache
X-Mrs-Cache-Hits
X-Mshield-Cache-Status
X-PERF
X-Mrs-Age
X-Ua
Fastly-SSL
Warning
X-ElasticPress-Search
X-Newrelic-Synthetics
X-B3-Spanid
X-Varnish-Beresp-Ttl
X-C
HA-Urlpath
HA-Geolon
V-Age
X-A-Dgt
Viewtype
X-A
X-A-Dcw
Mobile-Detection-Method
Meta-Geo-Continent
MD5-Digest
HA-Geolat
Server-Host
FSS-Proxy
FSS-Cache
Fly-Request-Id
HA-Georegion
Rt-Proxy-Cache
GMS-Ver
Resin-Trace
X-A-Ccd
HA-Geocity
HA-Cloudapp
Fly-Cache
VivaBuild
X-A-Dam
HA-Geocountry
TSSecure
UCS
HA-Servedtime
HA-Ipaddr
Content-Disposition
Ec-Rule-Version
SN
Ha-Gx-Prefs
HA-Host
Rendered-Blocks
X-PAYTM-SRV-ID
X-Org
X-NX-Host
Cache-Prefix
X-Region-Sid
X-Rewrite-Enabled
X-NU-AKA-ACS-Version
X-Logtrace-Id
X-IN-APIGATEWAY
X-Hash
X-IN-SSL-APIGATEWAY
X-IN-WAF
X-Irp-Debug
X-Rojux
X-S-Cookie
X-VG-WebServer
X-UE-Client-Country
X-Via-Edge
X-Via-SSL
Xc-Version
X-Trv-Group
X-Store
X-Server-By
X-ScT
X-Server-Time
X-Sn-Servicetimems
X-SRCache-Key
X-GeoIP-Country-Code
X-Generated-In
X-Cache-Bucket
X-BBXSRF
X-Cdn-Origin
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-BB-ID
X-Backend-Url
X-Aed
X-Accel-Expires-Debug
X-Application
X-B-Cookie
X-Backend-Host
X-CGP
X-D
X-F5-Cache
X-External-Request-Id
X-Fetched-On
X-From
X-G
X-Eu-Site
X-Died
X-Debug-Cookies
X-Date
X-Debug-Log
X-Destination
X-Developer
X-A-Wwc
Cache-Key
Arc-Country
X-Nc
BehaviorPad-Version
X-Cache-Backend
X-Endurance-Cache-Level
Ajk
X-Redis-Cache
X-CACHE-AGE
Server-ID
Thinkindot-Control
X-Dynatrace-Js-Agent
X-Owner
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-CDN-Forward
X-User
X-V
Origin
Odigeo-Trace-Id
Release
X-UnsetCookies
X-Thinkindot-L3
X-Trace-Id
X-No-Session
X-Developers
X-Core-Value
X-ServiceProvider
X-Backend-State
X-Auto-Login
X-Cache-Host
X-Response-By
X-Request-Start
X-Release
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Reboot
X-Amz-Meta-Cache-Control
X-Qloud-Router
X-Hello
X-Server-IP
X-Var-Ttl
X-Clientip
Www
Amp-Access-Control-Allow-Source-Origin
X-Cache-URL
X-ABtesting
X-Platform
X-SIPLIST1
Pramga
Apple-News-Services-Parsed-Url
GW-Server
Apple-News-Services-Request-Url
X-NC
Apple-News-Services-Host
AKAMAI
X-Worker
Powered-By
X-FW-Version
Frame-Options
Fastly-SWR
Decoy-Debug-Key
Countrycode
Country-Code
X-Hl-Ver
Decoy-Debug-Status
Decoy-Debug-TTL
Fastly-Soc-X-Request-Id
Fastly-SIE
X-GeoIP-City
X-Wikidot-Static-Cache
Apple-News-Services-Handled
X-Layer
IsBot
X-Epic-Correlation-Id
X-Key
X-Flog
Memcached
X-We-Are-Hiring
X-Matched-Rule
X-Location
X-DPWN-IS-SECURE
X-Wikidot-Backend
Heartbleed
WZWS-RAY
User-Cache-Control
X-Powered-By-ANYU
X-Cache-Id
X-MI-In-Market
X-Fastly-Cache
X-RCS-CacheZone
X-Cache-Expires
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Cache-Debug
X-Dispatcher-Server
X-Hnp-Log
X-Nginx-Cache-Key
X-Core-Mission
X-Passed-To-BeforeDispatch
X-Distributor
X-Instance-Name
X-P-T
X-Crawler
X-Passed-To
X-Node-Id
X-Passed-To-DLL
X-Croise-Owner
X-Info
X-Gen-Mode
X-Phone
X-Gannett-Site-Version
X-Passed-To-PostProcessResponse
X-Policy
Web-Mar-Node
Request-Country
Esi-Enabled
X-Up
On-Server
X-Block-Status
Request-EU
RNT-Time
RNT-Machine
Cache-Cookie-Set-Idcheck
Fastly-Backend-Name
X-Varnish-Action
X-VServer
Magicmarker
Kp-EeAlive
Backend-Name
Cache-Cookie-Set-From
MI-Cache-Age
MI-Cache
X-VCT
Section-Io-Cache
X-Thanos
X-Returned-From-DLL
X-Actual-URL
X-Returned-From-PostProcessResponse
X-S-Maxage
X-Returned-From-BeforeDispatch
X-Returned-From
X-Bip
X-Request-URI
X-Request-UUID
X-Swa-Ws
X-Secret
X-Sentry-ID
X-Origin-Response-Time
Server-Int
True-Client-Country-4JS
X-Stale
X-Sf
Uber-Trace-Id
Cache-Cookie-Set-Lfrom
X-Datadome
X-Via-NSCOPI
X-SVT-ORM-RULES
X-MServer
X-SVT-ORM-VERSION
X-MSEdge-Flight
X-MSEdge-Features
X-TT-LOGID
X-SN
X-Served-From
X-Variation
X-LI-UUID
X-Li-Fabric
CDCHOST
X-LI-Proto
X-WebServer
X-Li-Pop
Proxy-Connection
Pragrma
Platform
X-CUA
Pagetype
X-Backend-TTL
X-Device-Os
X-Fstrz
REQUESTUUID
Is-Eu
Adler-Geo
Version
X-HOST
MI-API
X-DC
X-Refresh
X-Cache-Srv
X-Cache-CFC
X-NWS-UUID-VERIFY
X-Oss-Storage-Class
RequestId
X-NODE
X-Oss-Object-Type
HTTPS
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
X-Page-Type
X-Pjax-Url
X-Req
Cteonnt-Length
X-Be
NodeID
X-Kong-Proxy-Latency
X-Ms-Lease-State
X-Kong-Upstream-Latency
MIME-Version
X-Cache-FS-Status
X-Parent-Response-Time
X-Unique-Id-Primal
X-Servername
V-Cache
Group
ProcessTime
Who
X-GZip
X-Origin-TTL
X-Oracle-Dms-Ecid
X-BB-IP
Fusion-Source
Cdn
Fusion-Component-Id
Fusion-Content-Source
Fusion-Template-Id
Memory
Fusion-Content-Id
X-Ckpd-Fst-Backend
Mime-Version
X-Servedbyhost
SS
CF-IPCountry
X-Aicache-OS
Cdn-Host
X-ND-Cache
Cdn-Request-Time
X-Edge-Server
X-Time
X-Protected-By
X-Server-Group
X-Content-Age
X-COUNTRY
PageType
GeoIP-Country-Code
X-Wa
XServer
CDN
SD-X-WS
X-SRV
GeoIP-Latitude
X-Varnish-Url
X-Varnish-Beresp-TTL
Get-Access-Time
A
X-Ratelimit-Remaining
Is-Session-Tracking
X-APP
GeoIp-Country-Code
X-Generation-Time
Geoip-Latitude
X-Origin-Date
X-WA
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Origin-Expires
X-Pf-Uncompressing
X-B3-Traceid
X-StackifyID
Serverid
X-Fastly-Cache-Hits
X-Cache-Info
X-Unique-Id
PICS-Label
X-FireWall-Port
X-Origin-Host
X-GEO
X-Vcache
X-Fastly-Country-Code
X-Gdpr
X-Requestid
VIX-Pulpo-Node
X-CSRF-Token
VIX-Pulpo-Upstream-Status
X-Nananana
X-CS
X-EC-Security-Audit
Nel
Processtime
Cf-Ipcountry
Node
X-ID
X-Load-Cache
X-ServedByHost
X-RequestId
Hostname
X-Proxy-Cache-Status
X-Proxy-Upstream
X-Server-W
DataCenter
X-SERVER-NAME
X-Surge-Debug
X-PHP-Host
NGX
T-Server
X-Check-Cacheable
X-M-Log
X-M-Reqid
X-Qnm-Cache
Vix-Hermes-Req-Id
URI
X-HTML-Minification-Powered-By
X-NGINX-Cache
X-FORWARDED-FOR
Cache-Tv-Group
X-UPSTREAM-Address
X-PF-Uncompressing
X-Feature
Load-Balancing
X-GZIP
X-HS-Status
ServerName
WP-Super-Cache
Cache-Provider
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
X-BACKEND-TTL
X-B3-SpanId
X-WR-MODIFICATION
X-DataStream-Origin-MEX-Latency
Request-Time
X-DataStream-MidMile-RTT
X-Fastly-Backend-Reqs
X-Alicdn-Da-Ups-Status
X-VG-WebCache
X-ARC
X-ServerName
X-Skip-Cache
X-BE
X-Fe
X-Atg-Version
X-IPS-LoggedIn
X-HTML-Edge-Cache
X-Micro-Cache
Https
Requestid
X-Proxy-Server
PFcat
RequestUuid
Host-ID
X-PJAX-URL
X-Akamai-SSL-Client-Sid
X-Debug-Cache-Store
X-From-Cache
X-Cache-Ttl
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
N-Cache
X-VC
X-PAGE-TYPE
X-Amz-Meta-S3b-Last-Modified
X-SB
X-Distil-Cs
X-Swift-Error
Sid
X-GDPR
Build-Number
X-Grace-Duration
X-Dw-Trace-Id
X-Gen-Id
X-CSRF-TOKEN
Cdn-Src-Port
X-RAMCache