Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Accept-Ranges
Pragma
X-Powered-By
Link
ETag
CF-RAY
Expect-CT
Via
X-Cache
X-XSS-Protection
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Id
X-Xss-Protection
X-Served-By
P3P
Referrer-Policy
X-Varnish
X-Timer
CF-Cache-Status
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
P3p
X-Drupal-Cache
X-Check
X-Adblock-Key
Alt-Svc
X-Cacheable
X-Amz-Cf-Pop
X-Generator
CF-Ray
Content-Security-Policy-Report-Only
X-Cache-Status
X-AspNetMvc-Version
X-DNS-Prefetch-Control
Status
X-Request-ID
X-Template
X-Language
Timing-Allow-Origin
Content-Encoding
X-Permitted-Cross-Domain-Policies
X-Iinfo
X-Buckets
X-Content-Security-Policy
X-Turbo-Charged-By
Upgrade
X-Kinja-Server-Push
X-CDN
X-Type
Xkey
Keep-Alive
Access-Control-Expose-Headers
Access-Control-Max-Age
WPE-Backend
X-Pass-Why
X-AH-Environment
X-Backend
X-Cache-Group
X-Server
X-Age
X-Drupal-Dynamic-Cache
X-Pingback
X-Via
X-Nginx-Cache-Status
X-Amz-Id-2
X-Amz-Request-Id
Grace
X-Server-Powered-By
X-Hacker
EagleId
X-UA-Device
X-Robots-Tag
X-LiteSpeed-Cache
X-Varnish-Cache
X-Page-Speed
X-Swift-SaveTime
X-Swift-CacheTime
X-Proxy-Cache
Cf-Railgun
Request-Context
X-Envoy-Upstream-Service-Time
Ali-Swift-Global-Savetime
X-Ua-Compatible
X-Ac
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-WebKit-CSP
X-Cache-Lookup
Content-Location
X-Amz-Version-Id
Surrogate-Control
X-Host
X-Cnection
X-Server-Id
X-Node
X-Readtime
Report-To
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Rq
Server-Timing
X-Response-Time
Feature-Policy
X-CST
X-Rack-Cache
X-Backend-Server
X-Application-Context
X-ORACLE-DMS-ECID
X-Iejgwucgyu
Request-Id
X-Cloud-Trace-Context
X-Instart-Request-ID
X-Clacks-Overhead
NEL
X-Url
Edge-Control
X-DynaTrace
Allow
Rating
X-Country
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Varnish-TTL
X-Origin-Cache
X-FTR-Request-ID
X-Country-Code
X-Trace
X-DataDome
X-Server-Name
X-Px
X-Server-ID
X-Vhost
X-B3-TraceId
X-ESI
X-GitHub-Request-Id
X-ORACLE-DMS-RID
X-VARITI-CCR
RTSS
X-MS-InvokeApp
X-Ruxit-JS-Agent
X-Cached
Accept-CH
X-Goog-Hash
Charset
SPRequestGuid
X-Vname
X-PC
X-TtlSet
X-D2id
X-Mod-Pagespeed
Public-Key-Pins
Verso
X-F-Cache
Pinterest-Generated-By
X-Cdn-Fetch
X-Kinja-Revision
X-Kinja-Server
X-Kinja
X-GoogleNews-Bot
X-Use-Magma
X-Exp-Id
X-Kinja-Build
X-Exp-Variant
X-Dispatcher
X-Mobile-Rewrite
Arc-Version
PB-RID
PB-PID
X-Version
X-SharePointHealthScore
X-T
X-Cdn
X-Powered-By-Plesk
X-TTL
X-Abt-Application-Version
Accept-CH-Lifetime
X-DIS-Request-ID
X-Powered-CMS
X-DynaTrace-JS-Agent
X-Ser
X-Fastly-Request-ID
Pinterest-Version
X-Upstream-Env
X-Pinterest-Rid
X-Origin-Upstream-Status
X-Navigation-Version
X-B
X-Forwarded-Proto
X-Shield-Request-Id
X-Client-IP
X-Recruiting
MS-Author-Via
X-Amz-Rid
X-SRCache-Store-Status
X-SRCache-Fetch-Status
DynaTrace
Realpath
X-Ttl
X-HW
SPIisLatency
SPRequestDuration
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Upstream
X-Vcap-Request-Id
Content-MD5
Nginx-Cache
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Wix-Server-Artifact-Id
X-Accel-Buffering
X-Amz-Meta-S3cmd-Attrs
AR-CACHE
AR-PoweredBy
AR-ATIME
Edge-Cache-Tag
X-Oneagent-Js-Injection
Arr-Disable-Session-Affinity
X-Hits
X-N
X-Varnish-Age
X-Debug
X-Oracle-Dms-Rid
TCN
MRF-Tech
X-Goog-Storage-Class
X-Aspnet-Version
Mrf-Cache-Status
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
X-B3-TraceId-Primal
X-NF-Request-ID
X-MSEdge-Ref
Access-Control-Request-Method
X-NewRelic-App-Data
X-Acc-Meta-Resource-Type
X-Dw-Request-Base-Id
X-Id
X-XRDS-Location
S
X-ATG-Version
X-Via-JSL
X-FTR-DC
X-FTR-Realm
X-FTR-Cache-Status
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Balancer
X-FTR-Backend
Service-Worker-Allowed
X-FTR-Expires
X-Logged-In
X-Dns-Prefetch-Control
X-FastCGI-Cache
Alternate-Protocol
X-PressLabs-Stats
Rt-Fastcgi-Cache
X-Forwarded-For
Tracecode
X-HS-Hub-Id
X-HS-Content-Id
Surrogate-Key
X-Frontend
X-Content-Digest
X-Kinsta-Cache
AMP-Access-Control-Allow-Source-Origin
X-Pad
Fastly-Restarts
X-RateLimit-Remaining
MicrosoftSharePointTeamServices
X-Cache-Key
X-FTR-Cache-Host
X-Content-Options
X-Ruxit-Js-Agent
X-Edge-Location
Server-Name
Fastcgi-Cache
X-Amzn-Trace-Id
Ar-Sid
X-CF-Powered-By
X-Analytics
Backend-Timing
Host
X-Grace
FilterID
TP-L2-Cache
TP-Cache
X-Rid
X-Whom
X-Hostname
X-Debug-Info
X-User-Agent
ServerID
X-Cache-2
X-Magnolia-Registration
X-IPLB-Instance
X-B3-Sampled
X-Revision
Eomportal-Instance
X-Page-Id
X-Request-Received
X-Request-Processing-Time
X-Mobile
Paypal-Debug-Id
X-NWS-LOG-UUID
X-Srv
AR-Request-ID
X-Akam-SW-Version
Front-End-Https
X-AOL-HN
X-VCache
X-HS-Cache-Config
X-Content-Powered-By
Retry-After
X-GUploader-UploadID
X-B-Cache
X-Signature
X-Litespeed-Cache
X-Device-Type
X-Cache-Action
X-FB-Debug
Source
Refresh
X-LB-Cache
X-SS-Set-Cookie
X-Handled-By
X-WA-Info
X-Request-Guid
X-Framework
X-Cache-Control
Cleartype
X-Varnish-Grace
X-Instance
X-Cluster
X-Tumblr-User
X-Correlation-Id
X-Cache-Hit
X-Platform-Server
X-App-Environment
X-Tumblr-Pixel
X-BCube-Filmed-By
X-Tumblr-Pixel-0
X-Varnish-Hostname
X-Akamai-Edgescape
X-Content-Security-Policy-Report-Only
Webserver
X-Zen-Fury
X-Middleton-Display
X-Sol
X-Varnish-Backend
Display
X-AppVersion
X-Az
X-Activity-Id
X-XRDS-LOCATION
X-Daa-Tunnel
X-Content-Type
X-Cache-Server
X-Fastcgi-Cache
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
Healthy
X-Cache-Rule
ViewerVersion
X-Drupal-Cache-Contexts
X-Varnish-Server
X-Drupal-Cache-Tags
X-Wix-Request-Id
X-Seen-By
X-Middleton-Response
Response
X-URL
X-Cached-By
X-Generated-By
X-Geo-Country
X-Cache-Age
S-Cnection
X-App-Server
Server-Node
Cache-Status
X-Origin-Server
X-TT
X-DataStream-Cache-Status
X-Accel-Expires
X-CACHE-GROUP
Upgrade-Insecure-Requests
X-Amzn-RequestId
X-Amz-Replication-Status
X-Amz-Apigw-Id
X-Esi
Payment
GEO-INFO
X-UA-Device-Type
X-S
NGB
X-RequestSource
X-TA-CDN-Provider
X-Response-Served-From
Filters
X-Node-Name
X-Cacheable-TTL
X-Locale
Accept-Charset
X-Cache-NE
X-Varnish-IP
X-Contextid
X-Edge-Cache
X-Edge-Cache-Key
Actual-Object-TTL
X-Servedby
ServedBy
Viewport
X-Status
Access-Control-Allow-Method
X-Tumblr-Pixel-2
X-FW-Serve
X-FW-Server
X-FW-Static
X-FW-Hash
X-Jobs
X-Tumblr-Pixel-1
X-Varnish-Hits
X-TT-TIMESTAMP
X-FW-Type
X-GeoIP
X-UUID
X-TX-ID
X-Adobe-Loc
Server-Info
X-Adobe-Content
X-WPE-Loopback-Upstream-Addr
X-Amz-Server-Side-Encryption
HostName
AsisCache
X-WebKit-CSP-Report-Only
X-Storage
Host-Header
Cache
X-PHP-Backend
Cache-Tv-Group
SRV
X-Rendered-As
X-Cache-TTL-Remaining
X-Cache-Remote
MS-CV
X-Croise-Owner
X-Vg-Webcache
From-Origin
X-Hyper-Cache
X-Cache-Operation
X-APP-VERSION
X-App-Version
X-Region
X-Webkit-CSP
X-HS-Combine-CSS
Cache-Tag
X-Redis-Cache
Served-By
Public-Key-Pins-Report-Only
DC
Liferay-Portal
X-Forwarded-Host
X-CACHE-KEY
X-Mode
Fastcgi-X-Cache
X-Agile-Age
Xserver
X-Yottaa-Metrics
X-Akamai-Transformed
X-Yottaa-Optimizations
X-Generated
X-Cache-Var-Map
X-Path-Route
X-Cache-Var
Fastcgi-Useragent
X-Proxy-Build
Meta-Geo
X-Endurance-Cache-Level
X-Is-Bot
X-Detected-As
X-Upgrade-Enabled
X-NGENIX-Cache
X-TNCMS
X-Timing-Wait
X-Human
X-Site-Version
X-Agile
X-Loop
X-RN-RSRV
Selected-FE
X-IP
X-Request-Time
X-Agile-Id
Fastcgi-X-Cache-Version
Machine
TWC-Locale-Group
TWC-Connection-Speed
Origin-Edge-Control
Origin-Cache-Control
Now
Property-Id
X-NCache
TWC-GeoIP-Country
TWC-Device-Class
TWC-GeoIP-LatLong
Webcakes-App-Name
X-Upstream-CT
X-Internal-Host
X-Upstream-HT
Webcakes-Region
X-Vgn-Hpd-Reason
X-Hosted-By
X-Grey
X-Cache-Category-Id
X-CDN-Cache
X-BYPASS-REASON
X-Format
X-Via-Fastly
X-Web-Node
X-Pc-Appver
X-Pc-Hit
X-Original-Request
X-Origin-Hint
X-JoinUs
X-Pc-Key
X-ProxyCache-Key
Webcakes-App-Version
X-Webstats-RespID
Cache-Name
X-ProxyCache-Status
X-Labrador-Cache-Channel
TWC-Privacy
Pagespeed
Powered-By-ChinaCache
X-UA
X-OCL
X-L-Path
X-FC-Vary-Parameters
X-Environment-Context
X-B3-Spanid
X-Access
X-Birta-Cache-Post
X-Birta-Served
X-Origin-Host
X-PCL
X-Tumblr-Pixel-3
X-Akamai-Request-ID
X-Origin-Response-Time
X-VG-TLSProxy
X-Time-Microsecs
X-Section
X-ProcessESI
X-Proxy
X-Pubstack
X-RemovedCookies
S-Rt
X-Origin
DB-Nickname
Cache-Tags
Azure-Version
Azure-SlotName
X-Rule
X-ServerID
X-Tb
X-Backend-Name
X-Cache-Config
X-CCM
Azure-SiteName
Azure-RegionName
X-Ocache
X-Origin-CC
X-Viewer-Country
X-Www-Served-By
X-Xfnlog-Site
Datacenter
Azure-InstanceId
X-Via-CDN
Mn-Server-Ip
X-Guploader-Uploadid
X-Akamai-Request-ID2
HitType
X-TIME
X-Proxied
X-CLOUD-TRACE-CONTEXT
X-Routing-Service
X-Zipkin-Id
Cache-Key
X-App-Name
X-Parent-Response-Time
OT-Force-Account-Verify
X-BACKEND-TTL
X-Sorting-Hat-PodId
X-Protected-By
X-Sorting-Hat-ShopId
X-Cache-TTL
X-Nginx-Cache
X-Shopify-Stage
X-ShopId
X-Alternate-Cache-Key
X-ShardId
Vix-Hermes-Req-Id
X-Kong-Proxy-Latency
Content-Script-Type
User-Cache-Control
Content-Style-Type
X-RateLimit-Limit
X-Edge-IP
X-Kong-Upstream-Latency
X-Dynatrace-Js-Agent
X-Ezoic-Cdn
X-OVcl-Cache
X-OVcl
Accept-Language
L5d-Success-Class
X-Real-IP
NtCoent-Length
X-Pc-Date
X-RTag
Time
X-Pc-Host
Ms-Operation-Id
X-Newrelic-App-Data
LB
X-Cache-Backend
X-PERF
X-Cdn-Forward
X-Real-Ip
X-ApacheServer
X-Front
AR-SID
X-Webkit-Csp
X-Proto
X-GRACE
X-Mrs-Age
X-FB-TRIP-ID
X-Correlation-ID
X-Mrs-Cache
X-Mshield-Cache-Status
X-Mrs-Cache-Hits
X-Unique-Id-Primal
X-Amz-Meta-Surrogate-Control
X-Nc
Section-Io-Cache
X-Varnish-Cacheable
X-Content-Age
X-Debug-Cache
X-Varnish-Beresp-Status
X-CDN-Forward
X-Varnish-Beresp-Grace
X-Hit
X-Sucuri-ID
Country
WZWS-RAY
Load-Balancing
X-Unique-ID
X-Ratelimit-Limit
Fusion-Component-Id
X-Microcachable
X-Trace-Id
Ohc-File-Size
Fusion-Content-Id
Fusion-Template-Id
Fusion-Content-Source
Fusion-Source
X-C
X-Time
X-MP-GENERATED-AT
Version
X-Hl-Ver
Mail-Subject
X-Varnish-Beresp-Ttl
We-Hiring
Access-Control-Request-Headers
X-Twitter-Response-Tags
Warning
X-Connection-Hash
X-Transaction
X-Generated-In
Countrycode
X-Application
Cache-Prefix
X-Auto-Login
X-GeoIP-Country-Code
X-G
Fastly-SIE
X-From
Fastly-Backend-Name
X-FW-Version
BehaviorPad-Version
Ec-Rule-Version
X-B-Cookie
Rendered-Blocks
RNT-Machine
X-ScT
X-Li-Pop
X-S-Maxage
RNT-Time
X-Rojux
X-S-Cookie
X-Li-Fabric
Adler-Geo
X-Aed
Arc-Country
Fastly-SWR
X-Actual-URL
X-Accel-Expires-Debug
Ajk
Resin-Trace
Release
Frame-Options
Is-Eu
X-Cache-URL
X-Cache-Id
IBM-Web2-Location
X-CF-Lambda-Fn
X-BB-ID
X-CF-Lambda-Version
X-Cache-Host
MD5-Digest
X-Cache-Bucket
Mobile-Detection-Method
Node
X-Cache-Debug
X-Cache-Expires
X-Cache-FS-Status
Meta-Geo-Continent
X-Clientip
X-Crawler
Platform
X-Backend-State
X-DPWN-IS-SECURE
X-External-Request-Id
Powered-By
Fly-Request-Id
X-Fetched-On
X-Dispatcher-Server
X-Died
X-D
X-CUA
X-Date
X-Destination
X-Device-Os
X-Developer
Fly-Cache
X-Via-SSL
X-Thanos
X-Release
X-Region-Sid
X-Swa-Ws
Thinkindot-Control
X-Ua
X-A-Dgt
X-Thinkindot-L3
X-Trv-Group
X-Rebelmouse-Surrogate-Control
Thinkindot-CacheControl-Type
X-User
X-UE-Client-Country
X-Reboot
X-Returned-From-DLL
X-WebServer
X-A-Dcw
X-A-Dam
VivaBuild
Viewtype
V-Age
X-Server-Time
Www
X-Returned-From
X-Response-By
X-SRCache-Key
X-A
X-A-Ccd
X-Request-UUID
Xc-Version
X-Returned-From-BeforeDispatch
X-Store
X-Server-By
X-We-Are-Hiring
X-EdgeConnect-Cache-Status
Server-ID
X-Returned-From-PostProcessResponse
X-Rewrite-Enabled
X-Node-Id
X-NU-AKA-ACS-Version
X-A-Wwc
X-Org
Server-Host
SD-X-WS
X-LI-Proto
X-Served-From
X-Bip
X-LI-UUID
Rt-Proxy-Cache
X-Matched-Rule
X-Logtrace-Id
X-Rebelmouse-Cache-Control
X-Passed-To
X-Qloud-Router
Thinkindot-CacheControl
X-Varnish-Action
X-Variation
X-RCS-CacheZone
X-Var-Ttl
X-Via-Edge
SS
X-Passed-To-DLL
X-Passed-To-BeforeDispatch
X-PHP-Host
X-Passed-To-PostProcessResponse
X-PAYTM-SRV-ID
X-VG-WebServer
X-Dc
X-Cache-Enabled
X-Amz-Meta-Cache-Control
X-IN-SSL-APIGATEWAY
X-Proxy-Upstream
X-UnsetCookies
X-TT-LOGID
X-Proxy-Cache-Status
X-Via-NSCOPI
X-MI-In-Market
X-No-Session
X-SVT-ORM-VERSION
X-Request-Start
X-Sf
X-ServiceProvider
X-Server-IP
X-Server-Group
X-Stale
X-SVT-ORM-RULES
X-P-T
X-Rocket-Nginx-Bypass
X-Location
X-Gannett-Site-Version
X-Gen-Mode
X-Hash
X-F5-Cache
X-Eu-Site
X-CGP
X-Epic-Correlation-Id
X-Hnp-Log
X-IN-APIGATEWAY
X-Layer
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Secret
X-Key
X-Info
Request-Time
X-IN-WAF
X-Block-Status
Who
HA-Geolat
HA-Geolon
HA-Geocountry
HA-Geocity
User-Agent
HA-Cloudapp
HA-Georegion
Ha-Gx-Prefs
HA-Urlpath
Heartbleed
Web-Mar-Node
HA-Ipaddr
HA-Host
GW-Server
GMS-Ver
Apple-News-Services-Host
Content-Disposition
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Backend-Name
Country-Code
Decoy-Debug-Key
Apple-News-Services-Handled
AKAMAI
Esi-Enabled
Decoy-Debug-TTL
Decoy-Debug-Status
Kp-EeAlive
HA-Servedtime
MI-Cache-Age
MI-API
On-Server
Pragrma
Origin
True-Client-Country-4JS
MI-Cache
Memcached
Proxy-Connection
X-Geo
X-NODE
X-Be
X-Distributor
X-Page-Type
X-Fstrz
X-MSEdge-Features
X-Cache-CFC
X-Nginx-Cache-Key
X-Origin-Expires
X-Up
PFcat
X-Origin-Date
X-Instance-Name
X-MSEdge-Flight
X-Planisys-CDN-Cache
X-Irp-Debug
Server-Int
Backend
Cache-Cookie-Set-From
X-SIPLIST1
X-Wikidot-Static-Cache
X-Urbn-Context-Path
X-V
X-Urbn-Site-Id
Cache-Cookie-Set-Idcheck
X-Request-URI
X-Policy
X-Platform
X-Wikidot-Backend
Magicmarker
Cache-Cookie-Set-Lfrom
Fastly-SSL
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Backend-Host
X-Backend-Url
Pramga
Uber-Trace-Id
X-Core-Value
REQUESTUUID
Request-Country
Locale
IsBot
CDCHOST
X-Developers
X-Distil-CS
UCS
Fastly-Soc-X-Request-Id
Request-EU
X-DC
Pagetype
X-Sn-Servicetimems
X-ElasticPress-Search
X-Debug-Log
X-Servername
X-Debug-Cookies
X-Refresh
X-Cdn-Origin
X-Origin-TTL
X-Phone
X-Core-Mission
X-NWS-UUID-VERIFY
X-NX-Host
X-Fastly-Cache
V-Cache
Group
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-Micro-Cache
X-GeoIP-City
X-COUNTRY
RequestId
X-Svr
X-VCT
X-Debug-Cache-Store
HitInfo
X-Req
X-PARISIEN-Cache-Rendered
Host-ID
X-VarnCache
X-Instart-Info
X-Level-Front-Cache
X-VarnPar1
X-Generated-On
X-Pjax-Url
X-Newrelic-Synthetics
PageSpeed
Lfy
X-CACHE-AGE
ServerName
X-NC
X-Cdn-Srv
X-Cache-Info
X-Server-Cache
X-BBXSRF
Ohc-Response-Time
MIME-Version
X-Datadome
X-Powered-By-ANYU
Cache-Provider
X-EIG-Tracking-Id
X-ARC
Mime-Version
X-B3-Traceid
Cdn
Cteonnt-Length
PICS-Label
X-Gdpr
Memory
X-TWH-CORRELATION-ID
X-CMS-Context
X-Servedbyhost
Nel
X-Cluster-Node
X-StackifyID
X-Wa
X-LAGOON
CF-IPCountry
X-WR-MODIFICATION
X-Fastly-Country-Code
X-Aicache-OS
NGX
X-Load-Cache
CDN
FSS-Cache
X-NodeID
X-HTML-Minification-Powered-By
GeoIP-Latitude
FSS-Proxy
X-Sentry-ID
GeoIP-Country-Code
X-Ratelimit-Remaining
X-CSRF-TOKEN
XServer
X-Hello
X-Flog
X-Fastly-Backend-Reqs
X-ABtesting
Geoip-Latitude
GeoIp-Country-Code
X-VServer
Cf-Ipcountry
X-Varnish-Beresp-TTL
X-Check-Cacheable
X-WA
SN
X-UPSTREAM-Address
X-GZip
Processtime
X-APP
X-FireWall-Port
X-Source
Amp-Access-Control-Allow-Source-Origin
X-Csrf-Token
X-Generation-Time
X-CSRF-Token
X-RateLimit-Limit-Second
TSSecure
X-Varnish-Cache-Hits
X-HOST
X-Unique-Id
X-RateLimit-Remaining-Second
CACHE
X-Cache-Miss-From
X-DataStream-MidMile-RTT
X-DataStream-Origin-MEX-Latency
WP-Super-Cache
X-Oss-Request-Id
X-Oss-Object-Type
X-Worker
X-Oss-Server-Time
X-Oss-Storage-Class
X-ServedByHost
X-CDN-Pop
X-Sedo-Request-Id
X-Oss-Hash-Crc64ecma
X-MServer
X-CDN-Pop-IP
X-Edge-Server
Pics-Label
X-Dynatrace
X-Cache-Grace
X-Nananana
URI
Cdn-Host
X-GDPR
A
PageType
Cdn-Request-Time
X-SRV
X-Cache-ASPX
X-Skip-Cache
X-VC-Cache
X-FORWARDED-FOR
Server-Cache-Control
Server-Surrogate-Control
X-Varnish-Authentication
X-VWS-Id
X-AWS-Id
X-SplitTest
DataCenter
X-LJ-Flow-ID
X-ID
X-RCS-Backend
X-Sucuri-Cache
HTTPS
X-Port
X-IPS-LoggedIn
X-Fastly-Cache-Hits
X-HS-Status
X-VG-WebCache
Odigeo-Trace-Id
X-Backend-TTL
X-Varnish-Url
X-B3-SpanId
X-Swift-Error
X-BE
Cache-Hits
X-ND-Cache
X-From-Cache
Hostname
X-PJAX-URL
X-Owner
Dynatrace
X-Pf-Uncompressing
Get-Access-Time
X-Ms-Version
X-Gen-Id
Is-Session-Tracking
X-Amzn-Remapped-Connection
X-Ms-Request-Id
X-SN
X-Ms-Blob-Type
X-GZIP
X-Bug-Bounty
X-Amzn-Remapped-Date
X-Instart-Isnd
X-Ms-Lease-Status
Proxy-Firewall
X-Cache-Ttl
X-ORIG-AKA-EDGE
X-NGINX-Cache
X-VarnPar2
X-Server-W
Requestid
ProcessTime
X-GoCache-CacheStatus
X-Amz-Meta-S3b-Last-Modified
Serverid
X-Akamai-SSL-Client-Sid
X-Alicdn-Da-Ups-Status
X-PAGE-TYPE
X-Varnish-URL
X-LiteSpeed-Cache-Control
T-Server
X-SB
WebServer
X-Fe
X-RAMCache
X-ServerName
X-Serial
RequestUuid
X-VC
X-Ms-Lease-State
X-ORIG-AKA-COUNTRY-CODE
X-GEO
X-PF-Uncompressing
X-HTML-Edge-Cache
Xet-Cookie
Powered
NodeID
SID
X-Akamai-ERRuleID
X-CS
X-Cache-Srv
X-Developed-By
Location
X-Dw-Trace-Id
NnCoection
X-Akamai-ERPolicy
X-LiteSpeed-Tag