Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Accept-Ranges
Pragma
X-Powered-By
Link
ETag
CF-RAY
Expect-CT
Via
X-XSS-Protection
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Id
X-Served-By
P3P
X-Xss-Protection
Referrer-Policy
X-Varnish
X-Timer
X-Request-Id
CF-Cache-Status
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
P3p
CF-Ray
X-Drupal-Cache
X-Check
X-Amz-Cf-Pop
X-Adblock-Key
Alt-Svc
X-Cacheable
X-Generator
Content-Security-Policy-Report-Only
X-Cache-Status
X-AspNetMvc-Version
X-DNS-Prefetch-Control
Status
X-Template
X-Language
Timing-Allow-Origin
X-Permitted-Cross-Domain-Policies
Content-Encoding
X-Iinfo
X-Buckets
X-Content-Security-Policy
X-Request-ID
X-Turbo-Charged-By
Upgrade
X-Kinja-Server-Push
X-CDN
X-Type
Xkey
Keep-Alive
Access-Control-Expose-Headers
WPE-Backend
Access-Control-Max-Age
X-Pass-Why
X-AH-Environment
X-Backend
X-Cache-Group
X-Server
X-Age
X-Drupal-Dynamic-Cache
X-Pingback
X-Via
X-Nginx-Cache-Status
X-Amz-Id-2
X-Amz-Request-Id
Grace
X-Server-Powered-By
EagleId
X-Hacker
X-UA-Device
X-Robots-Tag
X-LiteSpeed-Cache
X-Varnish-Cache
X-Page-Speed
X-Swift-SaveTime
X-Swift-CacheTime
X-Proxy-Cache
Cf-Railgun
Request-Context
X-Envoy-Upstream-Service-Time
Ali-Swift-Global-Savetime
X-Ua-Compatible
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Ac
X-WebKit-CSP
X-Device
X-Cache-Lookup
X-Server-Id
Content-Location
X-Amz-Version-Id
Surrogate-Control
X-Host
X-Node
X-Cnection
X-Readtime
Report-To
X-OneAgent-JS-Injection
EagleEye-TraceId
X-Rq
X-Response-Time
Server-Timing
Feature-Policy
X-CST
X-Rack-Cache
X-Application-Context
X-Backend-Server
X-ORACLE-DMS-ECID
X-Iejgwucgyu
Request-Id
X-Cloud-Trace-Context
X-Instart-Request-ID
X-Clacks-Overhead
X-Url
NEL
Edge-Control
X-DynaTrace
Rating
Allow
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Country
X-Varnish-TTL
X-Origin-Cache
X-FTR-Request-ID
X-Country-Code
X-Trace
X-DataDome
X-Server-Name
X-Px
X-Vhost
X-ESI
X-B3-TraceId
X-GitHub-Request-Id
X-VARITI-CCR
X-MS-InvokeApp
RTSS
X-Cached
Accept-CH
X-ORACLE-DMS-RID
X-Goog-Hash
X-Ruxit-JS-Agent
Charset
SPRequestGuid
X-Vname
X-TtlSet
X-PC
X-Mod-Pagespeed
X-F-Cache
X-Server-ID
Verso
X-D2id
Public-Key-Pins
X-Kinja
X-GoogleNews-Bot
X-Kinja-Build
X-Kinja-Revision
X-Exp-Variant
X-Use-Magma
X-Kinja-Server
X-Cdn-Fetch
X-Exp-Id
Pinterest-Generated-By
X-Dispatcher
X-Mobile-Rewrite
PB-PID
PB-RID
Arc-Version
X-Version
X-SharePointHealthScore
X-T
X-TTL
X-Powered-By-Plesk
X-Cdn
X-Abt-Application-Version
Accept-CH-Lifetime
X-DIS-Request-ID
X-Powered-CMS
X-Fastly-Request-ID
X-Ser
X-DynaTrace-JS-Agent
Pinterest-Version
X-Pinterest-Rid
X-Upstream-Env
X-Navigation-Version
X-Origin-Upstream-Status
X-Shield-Request-Id
X-B
X-Forwarded-Proto
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Recruiting
X-Amz-Rid
MS-Author-Via
DynaTrace
X-Client-IP
Realpath
X-HW
SPIisLatency
SPRequestDuration
X-Ttl
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Vcap-Request-Id
X-Upstream
Nginx-Cache
X-Goog-Metageneration
Content-MD5
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Wix-Server-Artifact-Id
X-Accel-Buffering
X-Amz-Meta-S3cmd-Attrs
AR-PoweredBy
AR-CACHE
AR-ATIME
X-Oracle-Dms-Rid
Edge-Cache-Tag
X-N
Arr-Disable-Session-Affinity
X-Hits
X-Varnish-Age
X-Debug
X-Oneagent-Js-Injection
X-Goog-Storage-Class
X-B3-TraceId-Primal
X-NF-Request-ID
Mrf-Cache-Status
X-Mrf-Section-Lastmod
MRF-Tech
X-Mrf-Item-Lastmod
X-MSEdge-Ref
TCN
X-Dw-Request-Base-Id
X-Acc-Meta-Resource-Type
Access-Control-Request-Method
X-NewRelic-App-Data
X-Aspnet-Version
X-Id
X-Via-JSL
X-ATG-Version
S
X-FTR-Balancer
X-FTR-DC
X-FTR-Realm
X-Country-Code-Real
X-FTR-Backend
X-FTR-Backend-Server
X-FTR-Cache-Status
Service-Worker-Allowed
X-FTR-Expires
X-Logged-In
X-Dns-Prefetch-Control
Alternate-Protocol
X-XRDS-Location
X-PressLabs-Stats
Tracecode
X-Forwarded-For
X-Cache-Key
X-HS-Hub-Id
X-HS-Content-Id
Rt-Fastcgi-Cache
Surrogate-Key
X-Frontend
X-Kinsta-Cache
X-Content-Digest
X-FastCGI-Cache
AMP-Access-Control-Allow-Source-Origin
X-Pad
X-Ruxit-Js-Agent
MicrosoftSharePointTeamServices
Fastly-Restarts
X-FTR-Cache-Host
X-Grace
X-RateLimit-Remaining
X-Litespeed-Cache
X-Content-Options
Ar-Sid
Fastcgi-Cache
X-Edge-Location
Server-Name
X-CF-Powered-By
X-Analytics
Backend-Timing
X-Amzn-Trace-Id
Host
FilterID
TP-L2-Cache
TP-Cache
X-Rid
X-Debug-Info
X-User-Agent
X-Magnolia-Registration
X-Whom
X-Hostname
ServerID
X-B3-Sampled
X-IPLB-Instance
X-Revision
X-Cache-2
Eomportal-Instance
X-Page-Id
X-Request-Received
X-Request-Processing-Time
X-Mobile
Paypal-Debug-Id
X-NWS-LOG-UUID
AR-Request-ID
X-Srv
X-XRDS-LOCATION
X-Akam-SW-Version
X-AOL-HN
X-VCache
Front-End-Https
X-Content-Powered-By
Retry-After
X-B-Cache
X-Signature
X-Correlation-Id
Refresh
X-HS-Cache-Config
X-Cluster
X-Cache-Action
X-Device-Type
X-LB-Cache
X-Handled-By
Source
Cleartype
X-App-Environment
X-FB-Debug
X-Framework
X-WA-Info
X-Instance
X-Request-Guid
X-SS-Set-Cookie
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel
X-Cache-Control
X-BCube-Filmed-By
X-Varnish-Grace
X-Platform-Server
X-Cache-Hit
X-Varnish-Hostname
X-Content-Security-Policy-Report-Only
X-GUploader-UploadID
X-Akamai-Edgescape
Webserver
X-Fastcgi-Cache
X-Middleton-Display
X-Zen-Fury
X-TA-CDN-Provider
X-Varnish-Backend
X-Sol
Display
X-AppVersion
X-Activity-Id
X-Az
X-Daa-Tunnel
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Cache-Server
Healthy
X-Cache-Rule
X-Content-Type
Response
X-Varnish-Server
X-Middleton-Response
X-Drupal-Cache-Contexts
X-Cache-Age
X-Drupal-Cache-Tags
X-Cached-By
X-Seen-By
ViewerVersion
X-Wix-Request-Id
X-App-Server
X-Geo-Country
X-Generated-By
X-URL
X-TT
Server-Node
S-Cnection
Cache-Status
X-Origin-Server
X-Accel-Expires
Upgrade-Insecure-Requests
X-DataStream-Cache-Status
X-Amz-Replication-Status
X-Amzn-RequestId
X-Amz-Apigw-Id
Payment
Accept-Charset
X-Response-Served-From
NGB
X-CACHE-GROUP
Filters
GEO-INFO
X-Cacheable-TTL
X-UA-Device-Type
X-Locale
Viewport
X-RequestSource
X-Edge-Cache-Key
X-Status
X-Contextid
ServedBy
X-Servedby
X-Edge-Cache
Actual-Object-TTL
X-Esi
X-S
X-Cache-NE
X-Jobs
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
X-Node-Name
Access-Control-Allow-Method
X-Varnish-Hits
X-UUID
X-FW-Hash
X-FW-Serve
X-FW-Server
X-FW-Type
X-FW-Static
X-Varnish-IP
AsisCache
X-GeoIP
X-WebKit-CSP-Report-Only
X-Adobe-Content
X-Adobe-Loc
X-Amz-Server-Side-Encryption
X-TT-TIMESTAMP
X-WPE-Loopback-Upstream-Addr
X-TX-ID
Server-Info
X-Storage
Host-Header
X-PHP-Backend
HostName
Cache
X-Cache-TTL-Remaining
X-Rendered-As
MS-CV
Cache-Tv-Group
SRV
X-Cache-Remote
X-APP-VERSION
From-Origin
X-Croise-Owner
X-Hyper-Cache
X-Cache-Operation
X-Region
X-Vg-Webcache
X-App-Version
X-Webkit-CSP
X-Redis-Cache
Served-By
Cache-Tag
Liferay-Portal
DC
X-Forwarded-Host
X-HS-Combine-CSS
Public-Key-Pins-Report-Only
X-UA
X-Mode
X-TIME
Pagespeed
X-Dynatrace-Js-Agent
X-Guploader-Uploadid
X-Path-Route
X-IP
X-Human
X-Hosted-By
X-Timing-Wait
X-Is-Bot
X-Loop
X-Akamai-Transformed
X-Webstats-RespID
X-NGENIX-Cache
X-Generated
X-Site-Version
X-Proxy-Build
X-Detected-As
X-Cache-Var
X-Agile-Id
X-Agile-Age
X-Agile
Meta-Geo
Selected-FE
X-Upgrade-Enabled
Powered-By-ChinaCache
X-RN-RSRV
X-TNCMS
X-Cache-Var-Map
Machine
Origin-Cache-Control
X-Pc-Hit
X-Pc-Appver
X-Request-Time
X-NCache
X-Pc-Key
Origin-Edge-Control
X-Vgn-Hpd-Reason
X-B3-Spanid
X-Web-Node
X-Environment-Context
X-Original-Request
X-Internal-Host
X-L-Path
X-JoinUs
Cache-Name
X-CDN-Cache
X-Format
X-Cache-Category-Id
S-Rt
Now
X-BYPASS-REASON
X-Grey
X-Labrador-Cache-Channel
X-FC-Vary-Parameters
X-ProcessESI
X-Origin
X-Via-Fastly
X-Proxy
X-VG-TLSProxy
X-ProxyCache-Key
X-Tumblr-Pixel-3
X-Upstream-HT
X-Upstream-CT
X-RemovedCookies
X-Pubstack
X-ProxyCache-Status
X-Akamai-Request-ID
Cache-Tags
X-Access
X-Endurance-Cache-Level
X-Cache-Config
DB-Nickname
X-Origin-Response-Time
Fastcgi-X-Cache
Datacenter
X-Birta-Served
X-Section
X-Backend-Name
X-Birta-Cache-Post
Fastcgi-X-Cache-Version
Fastcgi-Useragent
X-ServerID
X-CCM
X-Rule
X-Time-Microsecs
X-OCL
X-Origin-CC
X-PCL
X-Origin-Host
X-Via-CDN
X-Ocache
X-Tb
X-Www-Served-By
X-Yottaa-Metrics
X-Viewer-Country
X-Yottaa-Optimizations
Azure-RegionName
X-Routing-Service
Azure-InstanceId
Webcakes-App-Name
Webcakes-App-Version
Webcakes-Region
Mn-Server-Ip
X-Zipkin-Id
X-Proxied
Azure-SiteName
TWC-Privacy
Azure-Version
X-Origin-Hint
Azure-SlotName
TWC-Device-Class
Property-Id
Xserver
TWC-Connection-Speed
TWC-Locale-Group
TWC-GeoIP-Country
TWC-GeoIP-LatLong
X-App-Name
X-Xfnlog-Site
X-BACKEND-TTL
X-Kong-Proxy-Latency
X-Nginx-Cache
Content-Script-Type
X-Protected-By
Cache-Key
Content-Style-Type
X-Kong-Upstream-Latency
HitType
X-Akamai-Request-ID2
OT-Force-Account-Verify
X-Cache-TTL
X-Edge-IP
X-CLOUD-TRACE-CONTEXT
X-Parent-Response-Time
Vix-Hermes-Req-Id
User-Cache-Control
X-ShopId
X-Alternate-Cache-Key
X-ShardId
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Ezoic-Cdn
X-OVcl-Cache
X-OVcl
X-RateLimit-Limit
X-CACHE-KEY
X-RTag
Time
Ms-Operation-Id
L5d-Success-Class
NtCoent-Length
X-Pc-Host
X-Pc-Date
X-Real-Ip
Accept-Language
X-Cache-Backend
X-ApacheServer
X-PERF
X-Real-IP
X-Amz-Meta-Surrogate-Control
LB
X-Newrelic-App-Data
X-Proto
X-FB-TRIP-ID
X-Mrs-Age
X-Unique-Id-Primal
X-Cdn-Forward
X-Mrs-Cache-Hits
X-Mrs-Cache
X-Mshield-Cache-Status
X-Webkit-Csp
X-Front
AR-SID
X-Correlation-ID
X-CDN-Forward
X-Varnish-Beresp-Status
X-Varnish-Cacheable
X-Varnish-Beresp-Grace
Section-Io-Cache
X-Content-Age
X-Hit
X-Debug-Cache
Country
X-Ratelimit-Limit
X-Nc
Load-Balancing
WZWS-RAY
X-Trace-Id
Fusion-Template-Id
X-Sucuri-ID
Fusion-Source
Fusion-Component-Id
Fusion-Content-Source
Fusion-Content-Id
X-Varnish-Beresp-Ttl
X-MP-GENERATED-AT
Ohc-File-Size
X-Microcachable
X-Hl-Ver
Version
X-Unique-ID
We-Hiring
Mail-Subject
X-Dc
Access-Control-Request-Headers
X-GRACE
X-EdgeConnect-Cache-Status
Warning
X-Cache-Enabled
X-C
X-Transaction
X-Connection-Hash
X-Twitter-Response-Tags
X-Cache-Expires
X-Cache-Debug
X-Cache-Host
X-Cache-URL
X-We-Are-Hiring
X-Backend-State
X-Cache-FS-Status
X-Via-SSL
X-CF-Lambda-Fn
Xc-Version
X-Cache-Bucket
X-Bip
X-CF-Lambda-Version
X-Auto-Login
SD-X-WS
Rt-Proxy-Cache
Resin-Trace
Server-Host
SS
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
Rendered-Blocks
Release
Memcached
MD5-Digest
Meta-Geo-Continent
Mobile-Detection-Method
Powered-By
Node
Thinkindot-Control
V-Age
X-Accel-Expires-Debug
X-A-Wwc
X-Actual-URL
X-Aed
X-Via-Edge
X-Application
X-A-Dgt
X-A-Dcw
VivaBuild
Viewtype
Www
X-A
X-A-Dam
X-A-Ccd
X-B-Cookie
X-Fetched-On
X-Rebelmouse-Cache-Control
X-Qloud-Router
X-Rebelmouse-Surrogate-Control
X-Swa-Ws
X-Store
X-Reboot
X-Thanos
X-PAYTM-SRV-ID
X-Passed-To
X-Org
X-Passed-To-BeforeDispatch
X-Passed-To-DLL
X-Thinkindot-L3
X-Passed-To-PostProcessResponse
X-SRCache-Key
X-Server-Time
X-S-Cookie
X-S-Maxage
X-Rojux
X-Rewrite-Enabled
X-Returned-From-DLL
X-Returned-From-BeforeDispatch
X-Returned-From
X-Response-By
X-ScT
X-Server-By
X-Region-Sid
X-Release
X-Request-UUID
IBM-Web2-Location
X-Trv-Group
X-External-Request-Id
X-VG-WebServer
X-Returned-From-PostProcessResponse
X-Varnish-Action
X-FW-Version
X-From
X-DPWN-IS-SECURE
X-Died
X-D
X-CUA
X-Date
X-Destination
X-Developer
X-G
X-Generated-In
X-Logtrace-Id
X-User
X-Matched-Rule
X-Node-Id
X-NU-AKA-ACS-Version
X-UE-Client-Country
X-LI-UUID
X-LI-Proto
X-Var-Ttl
X-GeoIP-Country-Code
X-Layer
X-Li-Fabric
X-Li-Pop
X-Crawler
X-BB-ID
Fly-Cache
Fly-Request-Id
Frame-Options
Fastly-SWR
BehaviorPad-Version
Ec-Rule-Version
Fastly-SIE
Cache-Prefix
Ajk
Arc-Country
User-Agent
X-Geo
X-Served-From
X-Server-Group
X-Server-IP
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Clientip
X-CGP
True-Client-Country-4JS
Content-Disposition
Server-ID
X-IN-APIGATEWAY
X-WebServer
X-Secret
X-Hash
Country-Code
X-Via-NSCOPI
Countrycode
X-Variation
X-Gannett-Site-Version
Adler-Geo
X-Device-Os
AKAMAI
X-Amz-Meta-Cache-Control
X-Epic-Correlation-Id
X-Dispatcher-Server
X-SVT-ORM-VERSION
X-Eu-Site
X-F5-Cache
Backend
X-Sf
X-UnsetCookies
X-Cache-Id
X-SVT-ORM-RULES
X-Stale
Request-Time
RNT-Time
X-No-Session
HA-Geocountry
HA-Geolat
RNT-Machine
HA-Geocity
X-Proxy-Upstream
X-Proxy-Cache-Status
Is-Eu
X-TT-LOGID
HA-Ipaddr
HA-Georegion
HA-Host
HA-Servedtime
HA-Urlpath
HA-Geolon
Heartbleed
Ha-Gx-Prefs
X-P-T
X-Key
Fastly-Backend-Name
X-Rocket-Nginx-Bypass
GMS-Ver
X-Info
X-IN-SSL-APIGATEWAY
X-IN-WAF
X-PHP-Host
Pramga
X-Request-Start
HA-Cloudapp
Origin
X-RCS-CacheZone
X-Location
Platform
GW-Server
X-Be
X-Core-Value
X-SIPLIST1
X-Gen-Mode
X-Time
X-Irp-Debug
X-Hnp-Log
X-ServiceProvider
X-MI-In-Market
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Platform
X-Distil-CS
X-ElasticPress-Search
Apple-News-Services-Request-Url
Backend-Name
Who
Web-Mar-Node
On-Server
Apple-News-Services-Parsed-Url
MI-Cache
Apple-News-Services-Handled
Apple-News-Services-Host
X-Origin-Expires
Pragrma
REQUESTUUID
X-Origin-Date
Proxy-Connection
Esi-Enabled
Decoy-Debug-TTL
Decoy-Debug-Key
X-Nginx-Cache-Key
Decoy-Debug-Status
X-Distributor
MI-Cache-Age
X-Block-Status
Magicmarker
MI-API
IsBot
Fastly-SSL
Cache-Cookie-Set-Lfrom
PFcat
Cache-Cookie-Set-From
Cache-Cookie-Set-Idcheck
Kp-EeAlive
X-Up
X-Cache-CFC
X-Backend-Host
X-Phone
X-Backend-Url
Server-Int
Pagetype
X-NODE
Request-Country
X-Origin-TTL
X-Policy
Fastly-Soc-X-Request-Id
X-Request-URI
Locale
X-Refresh
X-NX-Host
X-Servername
X-Debug-Cookies
X-Debug-Log
X-Developers
X-Core-Mission
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Wikidot-Backend
X-Cdn-Origin
X-V
X-Page-Type
X-Fastly-Cache
Uber-Trace-Id
X-MSEdge-Flight
X-Instance-Name
UCS
X-MSEdge-Features
X-Fstrz
X-Sn-Servicetimems
X-Wikidot-Static-Cache
Request-EU
X-Ua
X-Debug-Cache-Expiry
CDCHOST
X-Debug-Cache-Store
X-Svr
RequestId
X-NWS-UUID-VERIFY
X-Debug-Cache-Fetch
X-Micro-Cache
X-Newrelic-Synthetics
Group
V-Cache
X-Generated-On
X-VCT
X-Req
X-GeoIP-City
X-Level-Front-Cache
X-Pjax-Url
X-Instart-Info
X-COUNTRY
X-DC
X-NC
HitInfo
Host-ID
Lfy
X-VarnPar1
X-PARISIEN-Cache-Rendered
X-VarnCache
ServerName
PageSpeed
Ohc-Response-Time
X-Server-Cache
X-CACHE-AGE
X-Cdn-Srv
X-Cache-Info
MIME-Version
X-ARC
X-BBXSRF
X-Datadome
Mime-Version
X-Powered-By-ANYU
X-Gdpr
X-EIG-Tracking-Id
PICS-Label
Cache-Provider
X-B3-Traceid
Memory
Cteonnt-Length
Cdn
X-TWH-CORRELATION-ID
X-CMS-Context
X-Ratelimit-Remaining
CF-IPCountry
Nel
X-Servedbyhost
X-Fastly-Country-Code
X-LAGOON
X-Aicache-OS
NGX
X-Cluster-Node
X-WR-MODIFICATION
X-Wa
X-StackifyID
X-Load-Cache
X-WA
XServer
X-NodeID
Geoip-Latitude
FSS-Proxy
FSS-Cache
GeoIp-Country-Code
CDN
X-Sentry-ID
X-Flog
GeoIP-Country-Code
X-ABtesting
GeoIP-Latitude
X-Fastly-Backend-Reqs
X-UPSTREAM-Address
X-Hello
X-HTML-Minification-Powered-By
X-VServer
Cf-Ipcountry
X-Varnish-Beresp-TTL
X-Check-Cacheable
SN
X-Source
X-FireWall-Port
CACHE
X-CSRF-TOKEN
X-CSRF-Token
X-Unique-Id
X-RateLimit-Remaining-Second
X-Generation-Time
Amp-Access-Control-Allow-Source-Origin
Processtime
X-GZip
X-APP
X-Varnish-Cache-Hits
X-RateLimit-Limit-Second
X-Csrf-Token
X-Oss-Hash-Crc64ecma
X-Sedo-Request-Id
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Storage-Class
TSSecure
X-Oss-Object-Type
X-Nananana
X-Cache-Miss-From
X-ServedByHost
WP-Super-Cache
X-HOST
X-CDN-Pop-IP
X-Cache-Grace
X-CDN-Pop
URI
X-MServer
X-Worker
X-DataStream-Origin-MEX-Latency
X-DataStream-MidMile-RTT
X-Cache-ASPX
Cdn-Host
X-Varnish-Authentication
X-Dynatrace
PageType
Cdn-Request-Time
Server-Surrogate-Control
Server-Cache-Control
X-Edge-Server
A
X-SRV
X-Skip-Cache
Pics-Label
X-VC-Cache
X-FORWARDED-FOR
X-RCS-Backend
X-IPS-LoggedIn
X-VG-WebCache
X-GDPR
X-ID
X-LJ-Flow-ID
X-VWS-Id
DataCenter
X-SplitTest
X-AWS-Id
HTTPS
X-Port
X-Sucuri-Cache
X-HS-Status
X-Instart-Isnd
X-Fastly-Cache-Hits
X-Backend-TTL
X-B3-SpanId
X-Varnish-Url
Odigeo-Trace-Id
X-ND-Cache
Hostname
X-Swift-Error
Cache-Hits
X-BE
Dynatrace
Is-Session-Tracking
X-PJAX-URL
X-From-Cache
X-Pf-Uncompressing
Get-Access-Time
X-Owner
X-GoCache-CacheStatus
X-Bug-Bounty
X-Gen-Id
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
X-Ms-Blob-Type
X-Ms-Version
X-Ms-Lease-Status
X-Ms-Request-Id
X-SN
X-GZIP
Requestid
X-Server-W
Powered
X-NGINX-Cache
X-Cache-Ttl
X-VarnPar2
X-ORIG-AKA-EDGE
ProcessTime
Proxy-Firewall
X-Akamai-SSL-Client-Sid
Serverid
X-Amz-Meta-S3b-Last-Modified
RequestUuid
X-Varnish-URL
X-Alicdn-Da-Ups-Status
X-LiteSpeed-Cache-Control
X-VC
X-Serial
X-RAMCache
Correlation-Id
X-ORIG-AKA-COUNTRY-CODE
X-Ms-Lease-State
X-SB
T-Server
X-Fe
X-ServerName
X-PAGE-TYPE
WebServer
X-GEO
Xet-Cookie
SID
X-LiteSpeed-Tag
X-Dw-Trace-Id
X-CS
X-HTML-Edge-Cache
Location
X-Developed-By
X-Cache-Srv
X-Akamai-ERPolicy
NodeID
X-Akamai-ERRuleID
NnCoection