Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
Last-Modified
X-Content-Type-Options
Accept-Ranges
Pragma
X-Powered-By
CF-RAY
Link
ETag
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Id
X-Served-By
Referrer-Policy
X-Varnish
X-Request-Id
X-Timer
CF-Cache-Status
X-AspNet-Version
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Xss-Protection
X-Runtime
X-Download-Options
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Cacheable
Alt-Svc
X-Check
X-Generator
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Cache-Status
X-AspNetMvc-Version
Status
X-DNS-Prefetch-Control
X-Template
Timing-Allow-Origin
X-Language
X-Permitted-Cross-Domain-Policies
Content-Encoding
X-Iinfo
X-FRAME-OPTIONS
X-Content-Security-Policy
X-CDN
X-Buckets
X-Turbo-Charged-By
X-Request-ID
Upgrade
X-Type
WPE-Backend
Keep-Alive
X-Pass-Why
X-Cache-Group
X-AH-Environment
Xkey
CF-Ray
X-Backend
Access-Control-Max-Age
P3p
X-Age
Access-Control-Expose-Headers
X-Via
X-Ua-Compatible
X-Drupal-Dynamic-Cache
EagleId
X-Pingback
X-Nginx-Cache-Status
X-Amz-Request-Id
X-Amz-Id-2
X-Server-Powered-By
X-Kinja-Server-Push
X-Server
X-Hacker
Grace
X-UA-Device
X-Swift-CacheTime
X-Swift-SaveTime
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-Robots-Tag
Cf-Railgun
X-Proxy-Cache
X-Envoy-Upstream-Service-Time
X-Page-Speed
X-LiteSpeed-Cache
Request-Context
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Ac
Content-Location
X-Cache-Lookup
X-Amz-Version-Id
X-WebKit-CSP
X-Host
X-Response-Time
Surrogate-Control
X-OneAgent-JS-Injection
X-Rq
X-Cnection
X-Node
X-Server-Id
X-Backend-Server
Server-Timing
X-Readtime
Report-To
X-Rack-Cache
Request-Id
EagleEye-TraceId
X-Application-Context
Feature-Policy
X-ORACLE-DMS-ECID
X-Cloud-Trace-Context
X-Instart-Request-ID
X-CST
X-Iejgwucgyu
Edge-Control
X-EdgeConnect-MidMile-RTT
X-Clacks-Overhead
X-EdgeConnect-Origin-MEX-Latency
NEL
Rating
X-Country
X-Server-Name
X-Url
X-DynaTrace
X-Varnish-TTL
X-MS-InvokeApp
X-TTL
X-DataDome
Allow
X-Px
X-Country-Code
X-Origin-Cache
Pinterest-Generated-By
X-Vhost
X-TtlSet
X-Vname
X-PC
X-Cached
X-FTR-Request-ID
X-Ruxit-JS-Agent
X-ESI
RTSS
X-Trace
X-Goog-Hash
SPRequestGuid
Charset
X-VARITI-CCR
X-Powered-By-Plesk
X-SharePointHealthScore
X-GitHub-Request-Id
Accept-CH
X-DynaTrace-JS-Agent
X-Dispatcher
X-T
X-Powered-CMS
Public-Key-Pins
X-D2id
X-Mod-Pagespeed
X-B3-TraceId
X-Server-ID
Arc-Version
PB-PID
PB-RID
X-Mobile-Rewrite
X-F-Cache
Verso
X-Cdn-Fetch
X-Kinja-Revision
X-Exp-Variant
X-Kinja-Build
X-Exp-Id
X-Kinja-Server
X-GoogleNews-Bot
X-Kinja
Content-MD5
X-Version
MS-Author-Via
SPIisLatency
SPRequestDuration
X-Shield-Request-Id
X-Recruiting
X-ORACLE-DMS-RID
X-Abt-Application-Version
X-Dns-Prefetch-Control
X-Oracle-Dms-Rid
Nginx-Cache
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Client-IP
X-Forwarded-Proto
Accept-CH-Lifetime
X-HW
X-DIS-Request-ID
X-N
X-Navigation-Version
Pinterest-Version
X-Upstream-Env
X-Pinterest-Rid
AR-PoweredBy
AR-ATIME
AR-CACHE
X-B
X-Amz-Rid
X-Fastly-Request-ID
X-Origin-Upstream-Status
DynaTrace
X-Upstream
X-Ser
X-Dw-Request-Base-Id
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Amz-Meta-S3cmd-Attrs
X-Hits
Fastly-Restarts
TCN
Realpath
X-XRDS-Location
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Wix-Server-Artifact-Id
X-Accel-Buffering
Paypal-Debug-Id
X-Content-Options
Arr-Disable-Session-Affinity
X-NF-Request-ID
Service-Worker-Allowed
X-Pad
X-Acc-Meta-Resource-Type
X-Goog-Storage-Class
Tracecode
S
Access-Control-Request-Method
X-Content-Digest
X-Id
X-Use-Magma
X-Varnish-Age
X-Litespeed-Cache
X-Debug
X-Vcap-Request-Id
Edge-Cache-Tag
Front-End-Https
X-Mrf-Section-Lastmod
MRF-Tech
Mrf-Cache-Status
X-Mrf-Item-Lastmod
X-MSEdge-Ref
X-Oneagent-Js-Injection
X-ATG-Version
X-Frontend
X-IPLB-Instance
X-Country-Code-Real
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-DC
X-FTR-Realm
X-PressLabs-Stats
X-FTR-Cache-Status
X-FTR-Backend
X-FTR-Expires
X-Kinsta-Cache
X-RateLimit-Remaining
X-Logged-In
X-HS-Content-Id
X-HS-Hub-Id
MicrosoftSharePointTeamServices
Surrogate-Key
X-Forwarded-For
X-Cache-Hit
Rt-Fastcgi-Cache
X-Amz-Cf-Pop
X-B3-TraceId-Primal
Fastcgi-Cache
X-Request-Processing-Time
X-Request-Received
X-Sol
Display
X-Middleton-Display
X-FastCGI-Cache
X-Edge-Location
X-Zen-Fury
Backend-Timing
X-Analytics
Server-Name
X-Rid
Powered-By-ChinaCache
X-Debug-Info
X-Webkit-Csp
X-Amzn-Trace-Id
Host
X-Revision
X-User-Agent
X-FTR-Cache-Host
X-HS-Cache-Config
FilterID
Ar-Sid
TP-L2-Cache
TP-Cache
AMP-Access-Control-Allow-Source-Origin
X-Akam-SW-Version
X-CF-Powered-By
X-Middleton-Response
Response
X-Grace
X-Cache-Key
X-Fastcgi-Cache
AR-Request-ID
X-NewRelic-App-Data
X-Drupal-Cache-Tags
X-SS-Set-Cookie
X-Mobile
X-Magnolia-Registration
X-TA-CDN-Provider
Refresh
Cache-Status
X-Cached-By
X-Accel-Expires
X-B3-Sampled
X-SERVER
X-Newrelic-App-Data
X-Ttl
Host-Header
ServerID
X-AOL-HN
X-NWS-LOG-UUID
X-Varnish-Backend
X-Node-Name
X-GUploader-UploadID
X-VCache
X-Whom
X-Content-Security-Policy-Report-Only
Eomportal-Instance
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel
X-Instance
X-Cluster
X-FB-Debug
X-B-Cache
X-Signature
X-Cache-2
X-Cache-Control
X-Akamai-Edgescape
X-Webkit-CSP
X-LB-Cache
X-Page-Id
X-Device-Type
X-Generated-By
X-Varnish-Hostname
X-Platform-Server
X-Framework
X-Via-JSL
Cleartype
X-BCube-Filmed-By
X-Srv
X-Drupal-Cache-Contexts
X-Handled-By
X-App-Environment
X-Request-Guid
X-Cache-Rule
X-Cache-Action
X-Az
X-Activity-Id
X-AppVersion
X-Ruxit-Js-Agent
Cache-Tag
X-App-Server
X-URL
Alternate-Protocol
DC
Source
X-Cache-Server
Liferay-Portal
X-Content-Powered-By
X-Hostname
Retry-After
X-HS-Combine-CSS
X-WPE-Loopback-Upstream-Addr
MS-CV
X-Varnish-Grace
X-WA-Info
X-Geo-Country
X-Varnish-Server
X-Daa-Tunnel
Pagespeed
X-App-Version
Public-Key-Pins-Report-Only
X-Amz-Replication-Status
Server-Node
X-TT
X-Seen-By
X-Wix-Request-Id
HostName
ViewerVersion
X-Correlation-Id
X-Esi
Webserver
Accept-Charset
AR-SID
X-Response-Served-From
X-Cache-NE
X-Tumblr-Pixel-2
AsisCache
X-Tumblr-Pixel-1
X-WebKit-CSP-Report-Only
Upgrade-Insecure-Requests
SRV
Actual-Object-TTL
X-GeoIP
X-Locale
X-Amzn-RequestId
X-RequestSource
GEO-INFO
X-Amz-Apigw-Id
X-Varnish-Hits
X-Jobs
ServedBy
X-FW-Static
X-FW-Type
Viewport
X-FW-Hash
X-Contextid
Payment
X-Edge-Cache
X-Edge-Cache-Key
X-FW-Serve
X-FW-Server
X-UUID
X-S
X-Servedby
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Status
X-CLOUD-TRACE-CONTEXT
X-TX-ID
X-Varnish-IP
X-Correlation-ID
X-Cacheable-TTL
X-Adobe-Loc
X-Adobe-Content
X-TT-TIMESTAMP
X-Origin-Server
X-Vg-Webcache
S-Cnection
X-Cache-TTL-Remaining
X-XRDS-LOCATION
X-Hyper-Cache
X-Cache-Age
Cache
X-Geo-Segment
X-Amz-Server-Side-Encryption
X-Cache-Operation
X-Forwarded-Host
Server-Info
Datacenter
X-Real-IP
X-RateLimit-Limit
Served-By
X-Region
X-Akamai-Request-ID2
Access-Control-Allow-Method
X-Mode
X-DataStream-Cache-Status
Healthy
CACHE
X-Content-Type
X-Sucuri-ID
X-Akamai-Transformed
X-Ezoic-Cdn
X-Generated
X-Cache-Var-Map
X-Site-Version
X-Detected-As
X-Rule
X-Routing-Service
X-JoinUs
X-Cache-Var
X-Is-Bot
X-Upgrade-Enabled
X-Path-Route
X-Cache-Config
Country
X-RN-RSRV
X-Ocache
Fastcgi-X-Cache
Fastcgi-Useragent
X-Proxied
Fastcgi-X-Cache-Version
X-Zipkin-Id
X-Rendered-As
Meta-Geo
X-Proxy
Machine
From-Origin
X-L-Path
X-Environment-Context
X-Section
X-Human
X-Hosted-By
X-Format
X-Birta-Served
X-NGENIX-Cache
X-Access
Now
X-Amz-Meta-Surrogate-Control
X-Birta-Cache-Post
X-Viewer-Country
DB-Nickname
L5d-Success-Class
X-GRACE
Webcakes-App-Version
Webcakes-App-Name
TWC-Privacy
Webcakes-Region
X-Agile
X-Agile-Id
X-Agile-Age
X-Via-Fastly
TWC-Locale-Group
TWC-GeoIP-LatLong
OT-Force-Account-Verify
X-Tb
X-Request-Time
Cache-Name
Property-Id
S-Rt
TWC-GeoIP-Country
TWC-Device-Class
TWC-Connection-Speed
X-Pc-Key
X-PCL
X-OCL
X-Hit
X-Origin-Hint
X-CCM
X-CDN-Cache
X-TNCMS
X-Loop
X-Labrador-Cache-Channel
X-FC-Vary-Parameters
X-Pc-Appver
X-Pc-Hit
X-Grey
X-ProxyCache-Status
X-ServerID
X-IP
X-RemovedCookies
X-ProxyCache-Key
X-Original-Request
X-Cache-Category-Id
X-BYPASS-REASON
Azure-Version
X-OVcl-Cache
X-OVcl
X-Origin
X-ProcessESI
X-EIG-Tracking-Id
X-Pubstack
Origin-Edge-Control
Azure-RegionName
Origin-Cache-Control
Azure-InstanceId
X-Upstream-CT
X-Xfnlog-Site
Azure-SiteName
X-Web-Node
X-Upstream-HT
X-VG-TLSProxy
Azure-SlotName
X-Proxy-Build
X-Alternate-Cache-Key
X-Via-CDN
NGB
Accept-Language
X-Timing-Wait
X-Sorting-Hat-ShopId
Selected-FE
X-Www-Served-By
X-ShardId
X-ShopId
X-Shopify-Stage
X-Sorting-Hat-PodId
HitInfo
HitType
X-Microcachable
LB
Mn-Server-Ip
X-Cluster-Node
X-Geo
Xserver
X-App-Name
X-TIME
X-Guploader-Uploadid
Filters
X-Cdn
Ms-Operation-Id
X-RTag
X-TWH-CORRELATION-ID
X-Rocket-Nginx-Bypass
X-UA
X-Transaction
X-Twitter-Response-Tags
X-Connection-Hash
X-Cache-Remote
X-Cache-Enabled
X-Internal-Host
X-NCache
X-UA-Device-Type
Time
X-Tumblr-Pixel-3
X-Unique-ID
X-Pc-Host
IBM-Web2-Location
X-Pc-Date
Access-Control-Request-Headers
X-Cache-TTL
X-LJ-Flow-ID
Content-Script-Type
Content-Style-Type
X-VWS-Id
X-SplitTest
X-AWS-Id
X-Origin-CC
X-Real-Ip
X-Proto
X-NodeID
X-PHP-Backend
We-Hiring
X-CACHE-KEY
Mail-Subject
X-APP-VERSION
X-Nginx-Cache
Cache-Hits
X-Vgn-Hpd-Reason
X-MP-GENERATED-AT
X-Storage
X-Port
X-Source
X-Time-Microsecs
X-Edge-IP
X-Cdn-Forward
NtCoent-Length
Backend
X-Debug-Cache
X-Varnish-Cacheable
X-Akamai-Request-ID
X-Distil-CS
X-Webstats-RespID
X-Ms-Blob-Type
X-Ms-Lease-Status
X-Ms-Request-Id
X-Ms-Version
X-Backend-Name
Cache-Tags
X-Csrf-Token
X-Endurance-Cache-Level
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
X-Redis-Cache
X-Ratelimit-Limit
X-CACHE-GROUP
X-B3-Spanid
X-Origin-Response-Time
X-Urbn-Site-Id
Locale
X-Urbn-Context-Path
X-Dc
X-Croise-Owner
X-Ua
Warning
User-Agent
X-EdgeConnect-Cache-Status
X-CDN-Forward
X-ApacheServer
X-Varnish-Beresp-Ttl
X-PERF
X-Varnish-Cache-Hits
X-C
Powered-By
Server-Host
Viewtype
V-Age
UCS
Rendered-Blocks
Resin-Trace
TSSecure
Rt-Proxy-Cache
HA-Geolat
Fly-Cache
Ec-Rule-Version
Fly-Request-Id
X-Rewrite-Enabled
GMS-Ver
Content-Disposition
X-Rojux
Ajk
Arc-Country
BehaviorPad-Version
Cache-Prefix
HA-Cloudapp
HA-Geocity
HA-Servedtime
HA-Urlpath
MD5-Digest
Meta-Geo-Continent
HA-Ipaddr
HA-Host
HA-Geocountry
VivaBuild
HA-Georegion
Ha-Gx-Prefs
Mobile-Detection-Method
X-A-Wwc
X-External-Request-Id
X-F5-Cache
X-Fetched-On
X-From
X-Eu-Site
X-ElasticPress-Search
X-Developer
X-Died
X-DPWN-IS-SECURE
X-PAYTM-SRV-ID
X-G
X-Generated-In
X-Org
X-Logtrace-Id
X-NX-Host
X-NU-AKA-ACS-Version
X-Irp-Debug
X-IN-WAF
X-GeoIP-Country-Code
X-Hash
X-IN-APIGATEWAY
X-IN-SSL-APIGATEWAY
X-Destination
X-Debug-Log
X-Aed
X-Region-Sid
X-Application
X-B-Cookie
X-Accel-Expires-Debug
X-S-Cookie
X-A-Ccd
X-A-Dam
X-A-Dcw
X-A-Dgt
X-BB-ID
X-BBXSRF
X-CGP
X-D
X-Date
X-Debug-Cookies
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-Cache-Bucket
X-Cache-URL
X-Cdn-Origin
X-A
HA-Geolon
X-SRCache-Key
X-Cache-Backend
X-We-Are-Hiring
Cache-Key
Xc-Version
X-Server-By
X-Server-Time
X-Mrs-Age
X-Store
X-VG-WebServer
X-Via-Edge
X-Mshield-Cache-Status
X-Mrs-Cache-Hits
X-Trv-Group
X-Mrs-Cache
X-ScT
Fastly-SSL
X-Via-SSL
X-Nc
X-Sn-Servicetimems
X-NC
Version
X-NWS-UUID-VERIFY
X-CACHE-AGE
X-Backend-Host
X-ABtesting
X-Backend-State
X-Auto-Login
X-Release
X-S-Maxage
X-Amz-Meta-Cache-Control
X-Layer
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Thinkindot-Control
X-Request-Start
X-Request-URI
Server-ID
SN
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Oss-Server-Time
X-Oss-Storage-Class
X-Rebelmouse-Surrogate-Control
Www
X-Reboot
X-Oss-Request-Id
X-Thinkindot-L3
X-Rebelmouse-Cache-Control
X-Cache-Id
X-Wikidot-Backend
X-Flog
X-Wikidot-Static-Cache
X-Var-Ttl
X-Dispatcher-Server
X-Epic-Correlation-Id
X-FW-Version
X-VServer
X-Via-NSCOPI
X-Key
X-Hl-Ver
X-Hello
X-GeoIP-City
PageSpeed
X-Developers
X-V
X-Qloud-Router
Fastly-SIE
X-Matched-Rule
X-Cache-Host
Fastly-SWR
X-Location
Country-Code
X-UE-Client-Country
X-Core-Value
X-User
X-Clientip
X-Platform
X-UnsetCookies
X-Backend-Url
X-Trace-Id
Fastly-Soc-X-Request-Id
X-SIPLIST1
X-ServiceProvider
Decoy-Debug-TTL
Decoy-Debug-Status
Frame-Options
FSS-Proxy
Memcached
IsBot
Heartbleed
GW-Server
Decoy-Debug-Key
Countrycode
X-Powered-By-ANYU
WZWS-RAY
User-Cache-Control
Section-Io-Cache
AKAMAI
Apple-News-Services-Handled
X-No-Session
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-MServer
FSS-Cache
X-Response-By
Pramga
RNT-Machine
Release
RNT-Time
Origin
Pagetype
X-Sucuri-Cache
X-Passed-To-PostProcessResponse
X-Fastly-Cache
X-Passed-To-DLL
X-WebServer
Cache-Cookie-Set-Idcheck
True-Client-Country-4JS
Cache-Cookie-Set-Lfrom
X-Dynatrace-Js-Agent
X-Device-Os
Esi-Enabled
Adler-Geo
Pragrma
Cache-Cookie-Set-From
X-Worker
X-Server-IP
X-Gen-Mode
X-P-T
X-Hnp-Log
X-Thanos
X-Secret
X-Varnish-Action
Server-Int
X-Request-UUID
X-Instance-Name
X-MI-In-Market
Request-EU
X-Sentry-ID
MI-Cache
X-Gannett-Site-Version
X-Passed-To-BeforeDispatch
Request-Country
X-Passed-To
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Served-From
Backend-Name
X-Bip
X-RCS-CacheZone
Is-Eu
X-TT-LOGID
X-Block-Status
X-SVT-ORM-RULES
Fastly-Backend-Name
X-Cache-Debug
X-Nginx-Cache-Key
X-SVT-ORM-VERSION
X-Returned-From-DLL
Platform
X-Returned-From-BeforeDispatch
Uber-Trace-Id
X-Actual-URL
MI-Cache-Age
X-Swa-Ws
X-Info
Kp-EeAlive
Magicmarker
X-VCT
X-Cache-Expires
X-Crawler
X-Sf
X-Core-Mission
X-Phone
X-CUA
Web-Mar-Node
X-Up
X-Parent-Response-Time
Odigeo-Trace-Id
On-Server
X-Stale
X-Policy
X-Returned-From-PostProcessResponse
X-Variation
X-Node-Id
X-Returned-From
X-Datadome
X-Li-Fabric
X-LI-UUID
X-LI-Proto
X-MSEdge-Flight
X-Li-Pop
X-MSEdge-Features
X-Cache-FS-Status
MI-API
Proxy-Connection
Group
V-Cache
CDCHOST
X-Newrelic-Synthetics
REQUESTUUID
X-Distributor
X-Fstrz
X-Cache-CFC
X-Refresh
X-Unique-Id-Primal
X-Page-Type
Who
X-Owner
RequestId
X-HOST
X-NODE
X-DC
HTTPS
Cteonnt-Length
X-Time
MIME-Version
X-Pjax-Url
Fusion-Source
X-Req
X-Be
X-Servername
Fusion-Content-Source
Fusion-Content-Id
X-Backend-TTL
X-Kong-Proxy-Latency
Fusion-Component-Id
X-Kong-Upstream-Latency
Fusion-Template-Id
X-SN
X-GZip
X-Cache-Srv
Amp-Access-Control-Allow-Source-Origin
X-Oracle-Dms-Ecid
X-Origin-TTL
NodeID
Memory
X-Ms-Lease-State
Cdn-Host
X-Edge-Server
Cdn-Request-Time
Cdn
X-Servedbyhost
X-Server-Group
ProcessTime
Mime-Version
X-Content-Age
CF-IPCountry
SS
X-Protected-By
SD-X-WS
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Aicache-OS
X-BB-IP
X-Wa
X-ND-Cache
A
X-Ckpd-Fst-Backend
X-COUNTRY
CDN
X-Origin-Expires
X-Origin-Date
GeoIP-Country-Code
X-Origin-Host
XServer
X-SRV
GeoIP-Latitude
PageType
X-Varnish-Beresp-TTL
X-StackifyID
Is-Session-Tracking
Get-Access-Time
GeoIp-Country-Code
X-B3-Traceid
X-APP
X-Pf-Uncompressing
Geoip-Latitude
Processtime
X-Fastly-Country-Code
X-Varnish-Url
Serverid
X-Cache-Info
X-Unique-Id
X-PHP-Host
PICS-Label
Node
Cache-Tv-Group
Vix-Hermes-Req-Id
X-WA
X-Requestid
X-Gdpr
X-Proxy-Upstream
X-Load-Cache
X-Proxy-Cache-Status
X-Ratelimit-Remaining
X-CSRF-Token
X-RateLimit-Remaining-Second
X-Generation-Time
X-RateLimit-Limit-Second
X-Fastly-Cache-Hits
X-Nananana
Nel
X-BACKEND-TTL
X-ID
Cf-Ipcountry
X-FireWall-Port
Hostname
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
DataCenter
X-RequestId
Cache-Provider
X-SERVER-NAME
X-ServedByHost
X-Check-Cacheable
X-Planisys-CDN-Rules
X-HS-Status
URI
WP-Super-Cache
X-EC-Security-Audit
X-CS
X-UPSTREAM-Address
X-NGINX-Cache
X-Server-W
Request-Time
X-FORWARDED-FOR
PFcat
X-Micro-Cache
Host-ID
X-Fastly-Backend-Reqs
X-GZIP
X-Front
X-GEO
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
X-Debug-Cache-Store
T-Server
X-WR-MODIFICATION
X-Surge-Debug
NGX
X-FB-TRIP-ID
X-B3-SpanId
X-VarnCache
X-VarnPar1
X-DataStream-MidMile-RTT
X-DataStream-Origin-MEX-Latency
X-GDPR
X-PARISIEN-Cache-Rendered
X-BE
ServerName
X-Fe
X-HTML-Edge-Cache
X-VG-WebCache
X-HTML-Minification-Powered-By
X-Swift-Error
X-Atg-Version
Https
X-ServerName
X-M-Reqid
X-Qnm-Cache
X-Svr
Requestid
X-M-Log
X-Generated-On
X-Instart-Info
X-Level-Front-Cache
X-IPS-LoggedIn
X-PJAX-URL
X-Cdn-Srv
X-PF-Uncompressing
Ohc-File-Size
RequestUuid
Ohc-Response-Time
Lfy
X-Vcache
X-Akamai-SSL-Client-Sid
X-Amz-Meta-S3b-Last-Modified
X-VarnPar2
X-SB
X-Cache-Ttl
X-From-Cache
Pics-Label
X-RAMCache
X-PAGE-TYPE
X-VC
WebServer
X-Alicdn-Da-Ups-Status
N-Cache
X-Distil-Cs
Load-Balancing
X-ARC
X-Serial
X-Akamai-ERRuleID
Cdn-Src-Port
X-Akamai-ERPolicy
X-Grace-Duration
X-Gen-Id
SID
X-Skip-Cache
Build-Number
X-Dw-Trace-Id