Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Accept-Ranges
Pragma
X-Powered-By
Link
ETag
CF-RAY
Expect-CT
Via
X-Cache
X-XSS-Protection
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-UA-Compatible
X-Cache-Hits
X-Xss-Protection
X-Amz-Cf-Id
X-Served-By
P3P
Referrer-Policy
X-Varnish
X-Request-Id
X-Timer
CF-Cache-Status
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Amz-Cf-Pop
X-Download-Options
Access-Control-Allow-Credentials
X-Runtime
P3p
X-Drupal-Cache
X-Check
X-Adblock-Key
Alt-Svc
X-Cacheable
Content-Security-Policy-Report-Only
X-Generator
CF-Ray
X-Cache-Status
X-DNS-Prefetch-Control
X-AspNetMvc-Version
Status
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-Permitted-Cross-Domain-Policies
Content-Encoding
X-Buckets
X-Content-Security-Policy
X-Turbo-Charged-By
X-Kinja-Server-Push
Upgrade
X-CDN
Xkey
X-Type
Keep-Alive
Access-Control-Expose-Headers
Access-Control-Max-Age
WPE-Backend
X-Pass-Why
X-Request-ID
X-AH-Environment
X-Backend
X-Cache-Group
X-Server
X-Age
X-Drupal-Dynamic-Cache
X-Via
X-Pingback
Grace
X-Nginx-Cache-Status
X-Amz-Id-2
X-Amz-Request-Id
EagleId
X-Server-Powered-By
X-Hacker
X-UA-Device
X-Robots-Tag
X-LiteSpeed-Cache
X-Varnish-Cache
X-Page-Speed
X-Proxy-Cache
Request-Context
X-Swift-SaveTime
X-Swift-CacheTime
Cf-Railgun
X-Envoy-Upstream-Service-Time
Ali-Swift-Global-Savetime
X-Ua-Compatible
X-WebKit-CSP
X-Ac
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-Cache-Lookup
X-Server-Id
X-Amz-Version-Id
X-OneAgent-JS-Injection
X-Cnection
X-Node
Content-Location
Surrogate-Control
X-Readtime
EagleEye-TraceId
X-CST
Report-To
X-Host
X-Response-Time
X-Rq
Feature-Policy
Server-Timing
X-Iejgwucgyu
X-Backend-Server
X-Application-Context
X-ORACLE-DMS-ECID
X-Rack-Cache
Request-Id
X-Cloud-Trace-Context
X-Instart-Request-ID
Allow
X-Clacks-Overhead
NEL
X-Url
Rating
X-DynaTrace
Edge-Control
X-Country
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Origin-Cache
X-Varnish-TTL
X-FTR-Request-ID
X-Country-Code
X-B3-TraceId
X-ORACLE-DMS-RID
X-Px
X-Cdn
X-Ruxit-JS-Agent
X-DataDome
X-Server-ID
X-GitHub-Request-Id
X-Vhost
X-ESI
X-Trace
X-VARITI-CCR
Accept-CH
X-TTL
X-Goog-Hash
Charset
X-Server-Name
X-Cached
RTSS
X-MS-InvokeApp
Pinterest-Generated-By
X-Mod-Pagespeed
Verso
Arc-Version
X-Mobile-Rewrite
PB-RID
PB-PID
Public-Key-Pins
X-D2id
X-Cdn-Fetch
X-Exp-Variant
X-GoogleNews-Bot
X-Kinja-Build
X-Use-Magma
X-Kinja-Server
X-Kinja-Revision
X-Kinja
X-Exp-Id
X-Version
X-F-Cache
SPRequestGuid
X-PC
X-TtlSet
X-Vname
X-Dispatcher
X-DynaTrace-JS-Agent
X-T
X-Powered-By-Plesk
X-DIS-Request-ID
Accept-CH-Lifetime
X-Abt-Application-Version
X-SharePointHealthScore
X-Powered-CMS
X-Fastly-Request-ID
X-Origin-Upstream-Status
X-Ser
X-Pinterest-Rid
Pinterest-Version
X-Upstream-Env
X-Navigation-Version
X-B
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Amz-Rid
X-Client-IP
X-Shield-Request-Id
Realpath
X-Forwarded-Proto
MS-Author-Via
X-Recruiting
X-HW
SPRequestDuration
X-Upstream
SPIisLatency
DynaTrace
X-Vcap-Request-Id
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Accel-Buffering
X-Wix-Server-Artifact-Id
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Amz-Meta-S3cmd-Attrs
Nginx-Cache
Arr-Disable-Session-Affinity
X-XRDS-Location
X-Varnish-Age
AR-PoweredBy
AR-CACHE
AR-ATIME
Content-MD5
X-Debug
MRF-Tech
X-Via-JSL
X-B3-TraceId-Primal
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
Mrf-Cache-Status
X-Dw-Request-Base-Id
X-Hits
X-Goog-Storage-Class
X-Id
X-MSEdge-Ref
X-NewRelic-App-Data
X-Acc-Meta-Resource-Type
X-N
X-NF-Request-ID
X-Aspnet-Version
X-FTR-Realm
X-FTR-DC
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-Backend-Server
X-FTR-Backend
X-Country-Code-Real
Service-Worker-Allowed
X-FTR-Expires
S
X-Ttl
X-ATG-Version
Access-Control-Request-Method
Edge-Cache-Tag
X-Logged-In
TCN
Alternate-Protocol
AMP-Access-Control-Allow-Source-Origin
X-Oracle-Dms-Rid
X-PressLabs-Stats
X-Kinsta-Cache
X-HS-Content-Id
X-HS-Hub-Id
X-Frontend
X-FastCGI-Cache
Surrogate-Key
X-RateLimit-Remaining
Rt-Fastcgi-Cache
X-Forwarded-For
X-Content-Digest
X-FTR-Cache-Host
Tracecode
X-Pad
X-Cache-Key
Fastcgi-Cache
X-CF-Powered-By
X-TA-CDN-Provider
Ar-Sid
Server-Name
MicrosoftSharePointTeamServices
Fastly-Restarts
Backend-Timing
X-User-Agent
X-Analytics
X-Amzn-Trace-Id
Host
TP-L2-Cache
TP-Cache
FilterID
X-Cache-2
X-Magnolia-Registration
X-Rid
X-Oneagent-Js-Injection
X-Edge-Location
X-Debug-Info
ServerID
X-B3-Sampled
X-Whom
X-Page-Id
X-Mobile
X-Grace
X-Content-Options
X-IPLB-Instance
X-Revision
Eomportal-Instance
Front-End-Https
X-Srv
Paypal-Debug-Id
X-Hostname
X-Akam-SW-Version
AR-Request-ID
X-NWS-LOG-UUID
Refresh
X-LB-Cache
X-VCache
X-Request-Processing-Time
X-Request-Received
Retry-After
X-Content-Powered-By
X-Activity-Id
X-Signature
X-Az
X-AppVersion
X-B-Cache
X-Cache-Action
X-SS-Set-Cookie
X-Cluster
X-Framework
X-Varnish-Hostname
X-URL
X-Handled-By
Cleartype
Source
X-Tumblr-Pixel-0
X-Request-Guid
X-Tumblr-Pixel
X-Tumblr-User
X-Platform-Server
X-App-Environment
X-FB-Debug
X-Device-Type
X-WA-Info
X-Instance
X-Akamai-Edgescape
X-Cache-Control
X-BCube-Filmed-By
X-Litespeed-Cache
X-GUploader-UploadID
X-Content-Security-Policy-Report-Only
X-AOL-HN
Webserver
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Correlation-Id
X-Zen-Fury
X-Content-Type
X-Cache-Hit
X-Varnish-Grace
X-Middleton-Display
X-Sol
Display
X-Fastcgi-Cache
Accept-Charset
X-Varnish-Backend
X-Ruxit-Js-Agent
X-Cache-Rule
Healthy
ViewerVersion
X-Seen-By
X-Wix-Request-Id
X-TT
X-Drupal-Cache-Tags
X-Origin-Server
X-Cache-Age
Response
X-Cache-Server
X-Middleton-Response
X-Daa-Tunnel
X-DataStream-Cache-Status
Upgrade-Insecure-Requests
MS-CV
Cache-Status
X-Varnish-Server
X-Cached-By
X-App-Server
X-Amz-Replication-Status
X-Generated-By
X-Drupal-Cache-Contexts
Payment
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Geo-Country
X-PHP-Backend
X-Storage
Server-Node
NGB
X-UA-Device-Type
X-CACHE-GROUP
Filters
X-Response-Served-From
GEO-INFO
X-HS-Cache-Config
X-S
X-Adobe-Loc
X-Amz-Server-Side-Encryption
X-Adobe-Content
Access-Control-Allow-Method
X-Cacheable-TTL
X-TT-TIMESTAMP
X-FW-Serve
X-Esi
X-RequestSource
X-Contextid
Actual-Object-TTL
Viewport
X-FW-Server
ServedBy
X-FW-Type
X-UUID
X-Servedby
X-FW-Static
X-Edge-Cache
X-Jobs
X-Cache-NE
X-FW-Hash
X-Edge-Cache-Key
X-Varnish-IP
X-Locale
X-Tumblr-Pixel-1
X-Varnish-Hits
X-Tumblr-Pixel-2
Cache-Tv-Group
AsisCache
X-Accel-Expires
X-TX-ID
X-WPE-Loopback-Upstream-Addr
Server-Info
S-Cnection
X-WebKit-CSP-Report-Only
X-Cache-Remote
X-Cache-TTL-Remaining
X-Status
X-XRDS-LOCATION
From-Origin
X-Rendered-As
Host-Header
X-GeoIP
X-Dns-Prefetch-Control
X-Cache-Operation
X-Region
X-App-Version
X-Croise-Owner
Cache
SRV
X-APP-VERSION
HostName
X-Redis-Cache
X-CACHE-KEY
Served-By
X-Webkit-CSP
X-Node-Name
X-BACKEND-TTL
X-Hyper-Cache
Content-Style-Type
DC
Content-Script-Type
Liferay-Portal
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Guploader-Uploadid
X-Upgrade-Enabled
X-Vg-Webcache
Public-Key-Pins-Report-Only
X-Cache-Config
X-RN-RSRV
X-Is-Bot
X-Cache-Var-Map
X-Webstats-RespID
X-Cache-Var
X-Cache-Category-Id
Ms-Operation-Id
X-Site-Version
X-Timing-Wait
X-Path-Route
X-Grey
X-Akamai-Transformed
X-Hosted-By
X-RTag
Selected-FE
X-Mode
X-Generated
X-NGENIX-Cache
Meta-Geo
X-Detected-As
X-Proxy-Build
Cache-Tag
Machine
X-Environment-Context
X-CDN-Cache
X-TNCMS
X-L-Path
X-Internal-Host
X-Agile-Id
X-Akamai-Request-ID
Origin-Cache-Control
Origin-Edge-Control
X-Agile
X-Agile-Age
X-Human
X-Request-Time
X-Labrador-Cache-Channel
X-Loop
X-Parent-Response-Time
X-JoinUs
Cache-Name
X-Original-Request
X-Origin-Response-Time
X-NCache
X-Birta-Served
Cache-Key
Azure-Version
X-Birta-Cache-Post
DB-Nickname
Now
X-Upstream-CT
Azure-SlotName
Azure-SiteName
X-Format
X-Edge-IP
X-BYPASS-REASON
Azure-InstanceId
Azure-RegionName
X-Upstream-HT
X-IP
X-Pc-Key
X-Origin-Host
X-Origin-CC
X-GRACE
X-ServerID
X-Pc-Appver
X-B3-Spanid
X-Time-Microsecs
X-ProcessESI
X-Proxy
X-ProxyCache-Key
X-ProxyCache-Status
X-RemovedCookies
X-Tumblr-Pixel-3
X-Pc-Hit
X-Protected-By
X-Origin
X-Via-Fastly
X-Web-Node
X-Pubstack
X-Backend-Name
Fastcgi-X-Cache-Version
S-Rt
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-Privacy
User-Cache-Control
Webcakes-App-Name
TWC-GeoIP-Country
TWC-Device-Class
Fastcgi-X-Cache
X-Access
Webcakes-Region
TWC-Connection-Speed
Property-Id
Cache-Tags
X-FC-Vary-Parameters
Xserver
X-Tb
X-Origin-Hint
X-Viewer-Country
Webcakes-App-Version
Fastcgi-Useragent
X-Section
X-Rule
X-Www-Served-By
X-VG-TLSProxy
X-Ocache
Vix-Hermes-Req-Id
X-OCL
X-Forwarded-Host
X-Vgn-Hpd-Reason
X-PCL
X-Zipkin-Id
X-App-Name
X-Routing-Service
X-Proxied
Pagespeed
Powered-By-ChinaCache
HitType
X-RateLimit-Limit
Load-Balancing
X-Xfnlog-Site
X-FB-TRIP-ID
X-CCM
Mn-Server-Ip
X-Cache-TTL
X-PERF
X-ApacheServer
X-Nginx-Cache
X-Cache-Backend
X-Endurance-Cache-Level
X-Content-Age
X-TIME
Datacenter
Country
X-Real-IP
X-Via-CDN
X-Mrs-Cache-Hits
X-Mrs-Age
X-Unique-Id-Primal
X-Mrs-Cache
X-Mshield-Cache-Status
X-Ezoic-Cdn
Time
OT-Force-Account-Verify
X-UA
X-Cdn-Forward
Fusion-Content-Source
Fusion-Template-Id
Fusion-Source
Fusion-Content-Id
Fusion-Component-Id
X-Yottaa-Optimizations
Ohc-File-Size
X-Yottaa-Metrics
X-Alternate-Cache-Key
X-ShardId
X-Varnish-Cacheable
X-ShopId
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Shopify-Stage
X-OVcl-Cache
X-OVcl
X-Ua
X-Debug-Cache
X-Sucuri-ID
LB
X-Pc-Date
X-Pc-Host
X-Nc
X-Correlation-ID
L5d-Success-Class
X-Varnish-Beresp-Ttl
X-CDN-Forward
X-Hl-Ver
X-HS-Combine-CSS
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-Unique-ID
X-MP-GENERATED-AT
NtCoent-Length
Section-Io-Cache
We-Hiring
Mail-Subject
X-Proto
X-Amz-Meta-Surrogate-Control
X-Hit
User-Agent
X-Trace-Id
X-Time
X-Akamai-Request-ID2
X-Real-Ip
X-Front
Pagetype
AR-SID
X-Cache-Enabled
Access-Control-Request-Headers
X-C
Version
X-Dynatrace-Js-Agent
X-Newrelic-App-Data
X-Microcachable
Accept-Language
X-Rocket-Nginx-Bypass
X-EdgeConnect-Cache-Status
Warning
X-Ratelimit-Limit
Mobile-Detection-Method
Thinkindot-CacheControl-Type
X-Destination
Thinkindot-Control
X-Developer
X-Date
X-D
X-Crawler
PFcat
Node
X-CUA
X-A-Dam
Thinkindot-CacheControl
X-Device-Os
X-Dispatcher-Server
X-A
Viewtype
Is-Eu
X-DPWN-IS-SECURE
MD5-Digest
VivaBuild
Meta-Geo-Continent
X-Connection-Hash
X-Died
X-A-Ccd
Memcached
V-Age
X-CF-Lambda-Version
Server-Host
X-Application
Rendered-Blocks
Release
X-Auto-Login
X-A-Dcw
Request-Time
X-Aed
X-Accel-Expires-Debug
X-A-Wwc
Resin-Trace
X-Actual-URL
Rt-Proxy-Cache
X-B-Cookie
X-BB-ID
X-Cache-Host
Platform
X-Cache-Id
X-Cache-URL
X-CF-Lambda-Fn
Powered-By
X-External-Request-Id
X-Cache-Bucket
X-Bip
X-Cache-Debug
X-Cache-Expires
Www
X-A-Dgt
X-Qloud-Router
X-Server-Time
X-Server-IP
X-SRCache-Key
X-Store
X-Swa-Ws
X-Svr
X-Server-By
X-Served-From
X-Rewrite-Enabled
X-Returned-From-PostProcessResponse
X-Rojux
X-S-Cookie
X-ScT
X-S-Maxage
X-Thanos
X-Thinkindot-L3
X-Varnish-Action
X-Variation
X-VG-WebServer
X-We-Are-Hiring
Xc-Version
X-WebServer
X-Var-Ttl
X-User
X-Trv-Group
X-Transaction
X-TT-LOGID
X-Twitter-Response-Tags
X-UE-Client-Country
X-Returned-From-DLL
X-Returned-From-BeforeDispatch
X-Li-Pop
X-Li-Fabric
X-LI-Proto
X-LI-UUID
X-Matched-Rule
X-Logtrace-Id
X-Level-Front-Cache
X-Layer
X-FW-Version
X-From
X-G
X-Generated-In
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Generated-On
X-NU-AKA-ACS-Version
X-P-T
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Reboot
X-Region-Sid
X-Returned-From
X-Request-UUID
IBM-Web2-Location
X-PHP-Host
X-Passed-To-BeforeDispatch
X-Passed-To
X-Passed-To-DLL
X-Passed-To-PostProcessResponse
X-PAYTM-SRV-ID
X-Fetched-On
X-Cache-FS-Status
Fly-Request-Id
Arc-Country
X-CLOUD-TRACE-CONTEXT
Fly-Cache
Frame-Options
BehaviorPad-Version
Ec-Rule-Version
Ajk
Adler-Geo
Fastly-SWR
Cache-Prefix
Fastly-SIE
X-Cache-CFC
Cache-Cookie-Set-From
Cache-Cookie-Set-Idcheck
Decoy-Debug-Key
Decoy-Debug-Status
Backend
Decoy-Debug-TTL
Backend-Name
X-Proxy-Upstream
Cache-Cookie-Set-Lfrom
Content-Disposition
X-RCS-CacheZone
X-Request-Start
X-Response-By
X-Backend-Host
Countrycode
X-Backend-Url
Country-Code
X-Amz-Meta-Cache-Control
X-Clientip
X-Server-Cache
X-Gannett-Site-Version
X-Location
X-MI-In-Market
X-F5-Cache
X-Instart-Info
X-Info
X-IN-APIGATEWAY
X-Hash
X-IN-SSL-APIGATEWAY
X-GeoIP-Country-Code
X-IN-WAF
X-ElasticPress-Search
X-Epic-Correlation-Id
X-Origin-Expires
X-Origin-Date
Ohc-Response-Time
X-Phone
AKAMAI
X-Node-Id
X-No-Session
X-MSEdge-Flight
X-MSEdge-Features
X-Distributor
X-Distil-CS
X-Nginx-Cache-Key
X-Proxy-Cache-Status
X-Release
RNT-Time
RNT-Machine
SD-X-WS
Proxy-Connection
Server-Int
Server-ID
X-Via-NSCOPI
Lfy
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
Magicmarker
X-Stale
GW-Server
X-UnsetCookies
SS
Fastly-Backend-Name
Origin
Heartbleed
Who
X-Secret
X-Server-Group
X-ServiceProvider
MI-API
Pramga
MI-Cache
MI-Cache-Age
X-Sf
GMS-Ver
X-Be
HA-Servedtime
HA-Ipaddr
IsBot
X-Micro-Cache
X-Wikidot-Static-Cache
HA-Geolon
X-Developers
X-ARC
On-Server
HA-Geolat
HA-Georegion
Kp-EeAlive
HA-Host
X-Key
HA-Geocountry
X-Wikidot-Backend
X-Fastly-Cache
Ha-Gx-Prefs
X-Eu-Site
X-Gen-Mode
X-Irp-Debug
X-Fstrz
X-Core-Value
X-Block-Status
X-SIPLIST1
REQUESTUUID
X-Dc
X-Cache-Info
Apple-News-Services-Request-Url
X-Backend-State
ServerName
Fastly-Soc-X-Request-Id
Web-Mar-Node
X-Request-URI
True-Client-Country-4JS
Fastly-SSL
X-Hnp-Log
Apple-News-Services-Parsed-Url
X-Cdn-Srv
X-Debug-Cache-Expiry
HA-Geocity
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Origin-TTL
HA-Urlpath
HA-Cloudapp
X-Up
Apple-News-Services-Handled
Apple-News-Services-Host
X-CGP
X-Platform
Esi-Enabled
X-Core-Mission
X-V
X-NODE
X-Policy
X-Debug-Cookies
X-Page-Type
X-Debug-Log
CDCHOST
WZWS-RAY
X-Geo
X-Sn-Servicetimems
X-Servername
X-NX-Host
X-Cdn-Origin
PageSpeed
RequestId
X-Refresh
X-Pjax-Url
X-Org
X-DC
X-COUNTRY
X-Via-SSL
X-CMS-Context
X-Via-Edge
Cteonnt-Length
X-CACHE-AGE
X-NC
MIME-Version
X-LAGOON
X-PARISIEN-Cache-Rendered
Pragrma
X-VarnPar1
X-VarnCache
X-Datadome
X-Newrelic-Synthetics
Cdn
X-Planisys-CDN-Rules
X-Instance-Name
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
Locale
X-Servedbyhost
Request-Country
X-Urbn-Context-Path
X-Urbn-Site-Id
Memory
Request-EU
Uber-Trace-Id
UCS
Mime-Version
X-NWS-UUID-VERIFY
X-Req
Host-ID
NGX
Group
V-Cache
X-GeoIP-City
X-VCT
Cache-Provider
PICS-Label
X-Wa
X-CSRF-TOKEN
Nel
X-Generation-Time
X-Webkit-Csp
X-RateLimit-Limit-Second
X-FireWall-Port
X-Varnish-Cache-Hits
X-RateLimit-Remaining-Second
X-Gdpr
CF-IPCountry
X-HTML-Minification-Powered-By
GeoIP-Country-Code
X-BBXSRF
GeoIP-Latitude
HitInfo
X-Powered-By-ANYU
X-WR-MODIFICATION
X-Aicache-OS
X-Load-Cache
XServer
X-B3-Traceid
X-Ratelimit-Remaining
Server-Cache-Control
X-DataStream-MidMile-RTT
X-StackifyID
X-Sedo-Request-Id
X-Cache-ASPX
Server-Surrogate-Control
CDN
X-Cache-Miss-From
X-Fastly-Country-Code
X-UPSTREAM-Address
X-Cache-Grace
X-DataStream-Origin-MEX-Latency
X-Varnish-Authentication
Cf-Ipcountry
X-IPS-LoggedIn
X-VG-WebCache
X-EIG-Tracking-Id
CACHE
GeoIp-Country-Code
Geoip-Latitude
X-Check-Cacheable
X-ND-Cache
X-Instart-Isnd
X-Varnish-Url
X-Source
X-TWH-CORRELATION-ID
X-Sucuri-Cache
X-RCS-Backend
X-Fastly-Backend-Reqs
Pics-Label
URI
X-WA
X-Varnish-Beresp-TTL
X-HOST
X-FORWARDED-FOR
X-Fastly-Cache-Hits
X-APP
X-From-Cache
Is-Session-Tracking
Get-Access-Time
X-CDN-Pop
X-CDN-Pop-IP
X-GEO
X-Unique-Id
Processtime
X-Dynatrace
FSS-Cache
Proxy-Firewall
X-GoCache-CacheStatus
Powered
FSS-Proxy
X-Sentry-ID
X-NodeID
X-Csrf-Token
X-FW-Dynamic
X-SRV
X-R9-Blue-Green-Version
X-Skip-Cache
X-Flog
X-Cluster-Node
X-Hello
X-VC-Cache
X-Server-W
X-GDPR
X-ABtesting
X-VServer
WP-Super-Cache
X-ID
DataCenter
SN
X-Oss-Hash-Crc64ecma
X-CSRF-Token
X-RequestId
X-Oss-Object-Type
X-Oss-Server-Time
X-ServedByHost
X-Oss-Request-Id
X-Pc-Subdomain
X-Oss-Storage-Class
X-Nananana
Amp-Access-Control-Allow-Source-Origin
Hostname
X-B3-SpanId
X-GZip
X-Fe
X-HS-Status
X-PF-Uncompressing
X-BE
X-TrackingId
X-Worker
Dynatrace
TSSecure
X-Pf-Uncompressing
X-PJAX-URL
X-Swift-Error
X-Bug-Bounty
X-Backend-TTL
X-Edge-Server
X-MServer
Cache-Hits
Cdn-Host
X-Amzn-Remapped-Date
X-Amzn-Remapped-Connection
X-GZIP
X-Gen-Id
Cdn-Request-Time
X-NGINX-Cache
Requestid
X-PAGE-TYPE
X-ORIG-AKA-EDGE
ProcessTime
X-Varnish-URL
A
X-Cache-Ttl
X-LiteSpeed-Cache-Control
Serverid
X-ORIG-AKA-COUNTRY-CODE
X-HostName
X-Tb-Optimization-Total-Bytes-Saved
X-ServerName
X-RAMCache
DSUID
X-LiteSpeed-Tag
RequestUuid
X-Port
X-VarnPar2
X-SB
X-VC
T-Server
X-Alicdn-Da-Ups-Status
Xxline
189phosttRef
188prxHost
219prxHost
352pxline
SID
X-SN
409pxxline
355prline
286prxHost
178proxuri
225prxHost
X-Serial
X-CS
X-Developed-By
X-Dw-Trace-Id
Location
Xet-Cookie
X-Akamai-ERRuleID
HTTPS
NnCoection
X-Akamai-ERPolicy
Correlation-Id
Cneonction