Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Accept-Ranges
Pragma
X-Powered-By
Link
ETag
CF-RAY
Expect-CT
Via
X-XSS-Protection
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Id
X-Served-By
P3P
X-Xss-Protection
Referrer-Policy
X-Varnish
X-Timer
X-Request-Id
CF-Cache-Status
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
P3p
X-Drupal-Cache
X-Check
X-Amz-Cf-Pop
X-Adblock-Key
Alt-Svc
X-Cacheable
X-Generator
Content-Security-Policy-Report-Only
CF-Ray
X-Cache-Status
X-AspNetMvc-Version
X-DNS-Prefetch-Control
Status
X-Template
X-Language
Timing-Allow-Origin
X-Permitted-Cross-Domain-Policies
Content-Encoding
X-Iinfo
X-Buckets
X-Content-Security-Policy
X-Request-ID
X-Turbo-Charged-By
Upgrade
X-Kinja-Server-Push
X-CDN
X-Type
Xkey
Keep-Alive
Access-Control-Expose-Headers
WPE-Backend
Access-Control-Max-Age
X-Pass-Why
X-AH-Environment
X-Backend
X-Cache-Group
X-Server
X-Age
X-Drupal-Dynamic-Cache
X-Pingback
X-Via
X-Nginx-Cache-Status
X-Amz-Request-Id
X-Amz-Id-2
Grace
X-Server-Powered-By
EagleId
X-Hacker
X-UA-Device
X-Robots-Tag
X-LiteSpeed-Cache
X-Varnish-Cache
X-Page-Speed
X-Swift-SaveTime
X-Swift-CacheTime
X-Proxy-Cache
Cf-Railgun
Request-Context
X-Envoy-Upstream-Service-Time
Ali-Swift-Global-Savetime
X-Ua-Compatible
X-Ac
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-WebKit-CSP
X-Device
X-Cache-Lookup
X-Server-Id
Content-Location
X-Amz-Version-Id
Surrogate-Control
X-Node
X-Host
X-Cnection
X-Readtime
X-OneAgent-JS-Injection
Report-To
EagleEye-TraceId
X-Rq
X-Response-Time
Server-Timing
Feature-Policy
X-CST
X-Rack-Cache
X-Application-Context
X-Backend-Server
X-ORACLE-DMS-ECID
X-Iejgwucgyu
Request-Id
X-Cloud-Trace-Context
X-Instart-Request-ID
X-Clacks-Overhead
X-Url
NEL
Edge-Control
X-DynaTrace
Rating
Allow
X-Country
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Varnish-TTL
X-Origin-Cache
X-FTR-Request-ID
X-Country-Code
X-Trace
X-DataDome
X-Server-Name
X-Px
X-Vhost
X-ESI
X-B3-TraceId
X-GitHub-Request-Id
X-VARITI-CCR
RTSS
X-MS-InvokeApp
X-Cached
X-ORACLE-DMS-RID
Accept-CH
X-Goog-Hash
X-Ruxit-JS-Agent
Charset
SPRequestGuid
X-Vname
X-PC
X-TtlSet
X-Mod-Pagespeed
Public-Key-Pins
X-Server-ID
X-F-Cache
Verso
X-D2id
X-Kinja-Build
X-Kinja-Revision
X-Cdn-Fetch
X-Use-Magma
X-Kinja
X-Exp-Variant
X-Kinja-Server
X-Exp-Id
X-GoogleNews-Bot
Pinterest-Generated-By
PB-RID
X-Mobile-Rewrite
Arc-Version
PB-PID
X-Dispatcher
X-Version
X-T
X-SharePointHealthScore
X-TTL
X-Powered-By-Plesk
X-Cdn
X-Abt-Application-Version
Accept-CH-Lifetime
X-DIS-Request-ID
X-Powered-CMS
X-Fastly-Request-ID
X-Ser
X-DynaTrace-JS-Agent
Pinterest-Version
X-Pinterest-Rid
X-Upstream-Env
X-Navigation-Version
X-Origin-Upstream-Status
X-B
X-Shield-Request-Id
X-Forwarded-Proto
X-Amz-Rid
X-Recruiting
MS-Author-Via
X-SRCache-Fetch-Status
X-SRCache-Store-Status
DynaTrace
X-Client-IP
Realpath
X-HW
SPIisLatency
SPRequestDuration
X-Ttl
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Upstream
X-Vcap-Request-Id
Content-MD5
Nginx-Cache
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Accel-Buffering
X-Wix-Server-Artifact-Id
X-Amz-Meta-S3cmd-Attrs
AR-CACHE
AR-PoweredBy
AR-ATIME
X-Oracle-Dms-Rid
Edge-Cache-Tag
X-N
Arr-Disable-Session-Affinity
X-Hits
X-Varnish-Age
X-Debug
X-Oneagent-Js-Injection
X-Goog-Storage-Class
MRF-Tech
X-Mrf-Item-Lastmod
X-NF-Request-ID
Mrf-Cache-Status
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
TCN
Access-Control-Request-Method
X-Acc-Meta-Resource-Type
X-MSEdge-Ref
X-Dw-Request-Base-Id
X-NewRelic-App-Data
X-Aspnet-Version
X-Id
X-ATG-Version
S
X-Via-JSL
X-FTR-Balancer
X-FTR-Backend
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Backend-Server
X-FTR-DC
X-FTR-Realm
Service-Worker-Allowed
X-Logged-In
X-XRDS-Location
X-FTR-Expires
Alternate-Protocol
X-Dns-Prefetch-Control
X-HS-Hub-Id
X-HS-Content-Id
X-Forwarded-For
X-Cache-Key
X-PressLabs-Stats
X-Frontend
Tracecode
Rt-Fastcgi-Cache
Surrogate-Key
X-Content-Digest
X-Kinsta-Cache
X-FastCGI-Cache
AMP-Access-Control-Allow-Source-Origin
X-Ruxit-Js-Agent
X-Pad
Fastly-Restarts
MicrosoftSharePointTeamServices
X-Grace
X-FTR-Cache-Host
X-Litespeed-Cache
X-RateLimit-Remaining
X-Content-Options
Ar-Sid
X-Edge-Location
Fastcgi-Cache
X-Amzn-Trace-Id
Server-Name
X-CF-Powered-By
X-Analytics
Backend-Timing
FilterID
Host
TP-L2-Cache
TP-Cache
X-Rid
X-Debug-Info
X-User-Agent
X-Magnolia-Registration
X-Cache-2
X-Hostname
ServerID
X-Whom
X-IPLB-Instance
X-B3-Sampled
X-Revision
Eomportal-Instance
X-Page-Id
X-Request-Processing-Time
X-Request-Received
X-Mobile
Paypal-Debug-Id
X-NWS-LOG-UUID
AR-Request-ID
X-Srv
Front-End-Https
X-AOL-HN
X-Akam-SW-Version
X-VCache
X-Content-Powered-By
Retry-After
X-HS-Cache-Config
X-Signature
Refresh
X-B-Cache
X-Correlation-Id
X-Handled-By
X-LB-Cache
X-Device-Type
X-Cluster
Source
X-Cache-Hit
X-WA-Info
X-Request-Guid
X-Framework
X-FB-Debug
X-Cache-Action
X-App-Environment
Cleartype
X-Cache-Control
X-Instance
X-SS-Set-Cookie
X-Varnish-Grace
X-Tumblr-Pixel
X-BCube-Filmed-By
X-Tumblr-User
X-Platform-Server
X-Tumblr-Pixel-0
X-Varnish-Hostname
X-Content-Security-Policy-Report-Only
X-Akamai-Edgescape
X-GUploader-UploadID
X-XRDS-LOCATION
Webserver
X-Fastcgi-Cache
X-Varnish-Backend
X-Zen-Fury
X-TA-CDN-Provider
X-Activity-Id
X-AppVersion
X-Middleton-Display
X-Az
Display
X-Sol
X-Daa-Tunnel
VIX-Pulpo-Node
X-Content-Type
X-Cache-Server
VIX-Pulpo-Upstream-Status
X-Cache-Rule
Healthy
X-Varnish-Server
X-Middleton-Response
X-Drupal-Cache-Contexts
X-Drupal-Cache-Tags
X-Cache-Age
Response
X-Wix-Request-Id
X-Seen-By
ViewerVersion
X-Cached-By
X-Generated-By
X-App-Server
S-Cnection
X-Geo-Country
Server-Node
X-URL
Cache-Status
X-TT
X-Origin-Server
X-Accel-Expires
X-Amz-Replication-Status
Upgrade-Insecure-Requests
X-Amz-Apigw-Id
X-DataStream-Cache-Status
X-Amzn-RequestId
Payment
X-CACHE-GROUP
Filters
X-UA-Device-Type
NGB
X-S
X-Response-Served-From
X-Cacheable-TTL
GEO-INFO
X-Locale
ServedBy
X-Cache-NE
Viewport
X-RequestSource
Actual-Object-TTL
X-Esi
X-Edge-Cache
X-Status
X-Servedby
X-Edge-Cache-Key
X-Contextid
X-Tumblr-Pixel-1
X-Tumblr-Pixel-2
X-Jobs
Accept-Charset
X-Node-Name
X-Varnish-IP
X-UUID
X-FW-Type
X-TT-TIMESTAMP
X-FW-Static
X-Varnish-Hits
X-Amz-Server-Side-Encryption
X-WPE-Loopback-Upstream-Addr
AsisCache
X-FW-Server
Access-Control-Allow-Method
X-TX-ID
X-FW-Serve
X-FW-Hash
X-Adobe-Content
X-GeoIP
X-Adobe-Loc
X-WebKit-CSP-Report-Only
Server-Info
X-Storage
Host-Header
X-PHP-Backend
HostName
Cache
MS-CV
Cache-Tv-Group
X-Rendered-As
X-Cache-TTL-Remaining
SRV
X-APP-VERSION
X-Cache-Remote
From-Origin
X-Croise-Owner
X-Hyper-Cache
X-Cache-Operation
X-Region
X-Vg-Webcache
X-App-Version
X-Redis-Cache
X-Webkit-CSP
Cache-Tag
Served-By
Public-Key-Pins-Report-Only
DC
Liferay-Portal
X-Forwarded-Host
X-UA
X-HS-Combine-CSS
X-Dynatrace-Js-Agent
X-Mode
X-TIME
X-Guploader-Uploadid
X-IP
X-Human
X-Is-Bot
X-Loop
X-Upgrade-Enabled
X-Webstats-RespID
X-NGENIX-Cache
X-Hosted-By
X-Generated
X-Agile-Age
X-Agile
Selected-FE
X-Agile-Id
Meta-Geo
X-Cache-Var-Map
X-Cache-Var
Machine
X-Detected-As
X-Path-Route
X-TNCMS
X-Timing-Wait
X-Site-Version
X-Proxy-Build
X-RN-RSRV
X-NCache
X-Original-Request
X-Yottaa-Optimizations
X-Vgn-Hpd-Reason
X-Upstream-HT
X-Pc-Hit
X-Akamai-Transformed
X-Pc-Appver
X-Request-Time
X-Labrador-Cache-Channel
X-Internal-Host
X-Cache-Category-Id
Now
Origin-Cache-Control
Origin-Edge-Control
X-CDN-Cache
X-Environment-Context
X-JoinUs
X-Endurance-Cache-Level
X-Grey
X-L-Path
X-Yottaa-Metrics
X-Via-Fastly
X-Web-Node
X-B3-Spanid
X-Upstream-CT
X-Pc-Key
X-BYPASS-REASON
X-Tumblr-Pixel-3
X-VG-TLSProxy
X-RemovedCookies
X-Birta-Served
X-Pubstack
X-FC-Vary-Parameters
X-Time-Microsecs
Cache-Name
Powered-By-ChinaCache
DB-Nickname
X-ProxyCache-Key
X-Format
X-Birta-Cache-Post
X-OCL
S-Rt
X-Origin-Host
X-Viewer-Country
X-ProxyCache-Status
X-PCL
X-Proxy
X-ProcessESI
X-Access
Fastcgi-Useragent
Fastcgi-X-Cache
X-Cache-Config
X-Akamai-Request-ID
X-Origin
X-Backend-Name
X-Rule
X-Section
Fastcgi-X-Cache-Version
X-Xfnlog-Site
Datacenter
X-Origin-CC
X-Via-CDN
X-Www-Served-By
Cache-Tags
X-Tb
X-CCM
X-Origin-Response-Time
X-Ocache
Pagespeed
X-Routing-Service
X-Origin-Hint
Azure-InstanceId
Webcakes-App-Name
Webcakes-App-Version
Webcakes-Region
Mn-Server-Ip
Azure-RegionName
TWC-Privacy
X-ServerID
Azure-SiteName
X-Zipkin-Id
Azure-Version
Azure-SlotName
X-Proxied
TWC-Device-Class
Property-Id
TWC-Locale-Group
Xserver
TWC-Connection-Speed
TWC-GeoIP-Country
TWC-GeoIP-LatLong
HitType
X-BACKEND-TTL
Cache-Key
X-App-Name
Content-Style-Type
Content-Script-Type
X-Protected-By
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Akamai-Request-ID2
OT-Force-Account-Verify
X-ShopId
X-Shopify-Stage
X-Alternate-Cache-Key
X-Cache-TTL
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
User-Cache-Control
Vix-Hermes-Req-Id
X-CLOUD-TRACE-CONTEXT
X-Parent-Response-Time
X-Edge-IP
X-ShardId
X-Ezoic-Cdn
X-Nginx-Cache
X-OVcl-Cache
X-OVcl
X-CACHE-KEY
L5d-Success-Class
Ms-Operation-Id
NtCoent-Length
X-RTag
Time
Accept-Language
X-Pc-Date
X-Pc-Host
X-Real-Ip
X-PERF
X-Cache-Backend
X-ApacheServer
X-Real-IP
X-RateLimit-Limit
X-Mrs-Age
LB
X-Mrs-Cache
X-Mshield-Cache-Status
X-Newrelic-App-Data
X-Amz-Meta-Surrogate-Control
X-Mrs-Cache-Hits
X-Unique-Id-Primal
X-FB-TRIP-ID
X-Proto
X-Cdn-Forward
X-Ratelimit-Limit
AR-SID
X-Webkit-Csp
X-Front
X-Correlation-ID
X-CDN-Forward
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
X-Content-Age
X-Varnish-Cacheable
X-Debug-Cache
Section-Io-Cache
Country
X-Hit
X-Nc
Load-Balancing
X-Sucuri-ID
WZWS-RAY
Fusion-Content-Id
Fusion-Source
Fusion-Component-Id
Fusion-Template-Id
Fusion-Content-Source
X-Trace-Id
Ohc-File-Size
X-MP-GENERATED-AT
X-Unique-ID
X-Microcachable
X-Hl-Ver
X-Varnish-Beresp-Ttl
X-Dc
Version
Mail-Subject
We-Hiring
Access-Control-Request-Headers
X-GRACE
X-EdgeConnect-Cache-Status
Warning
X-C
X-Twitter-Response-Tags
X-Cache-Enabled
X-Transaction
X-Connection-Hash
Is-Eu
X-Accel-Expires-Debug
Mobile-Detection-Method
IBM-Web2-Location
X-Aed
X-Actual-URL
X-UE-Client-Country
X-A-Dcw
X-A-Dgt
X-A-Dam
Platform
X-SRCache-Key
X-Trv-Group
X-A-Wwc
X-Thanos
X-Swa-Ws
Release
V-Age
X-Store
Server-Host
Memcached
SD-X-WS
Thinkindot-Control
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
SS
Meta-Geo-Continent
Server-ID
X-Application
MD5-Digest
Node
VivaBuild
X-Thinkindot-L3
Www
Powered-By
X-A
Viewtype
Rendered-Blocks
Rt-Proxy-Cache
RNT-Time
RNT-Machine
Resin-Trace
X-A-Ccd
X-DPWN-IS-SECURE
X-Rojux
X-S-Cookie
X-Rewrite-Enabled
X-Passed-To
X-Passed-To-DLL
X-Passed-To-BeforeDispatch
X-ScT
X-Org
X-Matched-Rule
X-Logtrace-Id
X-Server-By
X-Served-From
X-NU-AKA-ACS-Version
X-Node-Id
X-Passed-To-PostProcessResponse
X-PAYTM-SRV-ID
X-Release
X-Region-Sid
X-Request-UUID
X-Response-By
X-Returned-From-BeforeDispatch
X-Returned-From
X-Reboot
X-Rebelmouse-Surrogate-Control
X-Returned-From-PostProcessResponse
X-PHP-Host
X-Qloud-Router
X-RCS-CacheZone
X-Rebelmouse-Cache-Control
X-Layer
X-Server-Time
X-Cache-Id
X-Cache-Host
X-Cache-URL
X-CF-Lambda-Fn
X-Crawler
X-CF-Lambda-Version
X-Cache-Expires
X-Cache-Debug
X-Backend-State
X-B-Cookie
X-BB-ID
X-Bip
X-Cache-Bucket
X-D
X-Date
X-From
X-Fetched-On
X-FW-Version
X-G
X-GeoIP-Country-Code
X-Generated-In
X-External-Request-Id
Frame-Options
X-Developer
X-Destination
X-Device-Os
X-Died
X-Dispatcher-Server
X-Auto-Login
Fly-Cache
Ajk
Adler-Geo
X-User
Arc-Country
BehaviorPad-Version
Fastly-Backend-Name
Ec-Rule-Version
Cache-Prefix
X-Var-Ttl
X-Varnish-Action
X-WebServer
Xc-Version
Fly-Request-Id
User-Agent
X-We-Are-Hiring
X-VG-WebServer
X-Via-Edge
X-Via-SSL
Fastly-SIE
X-Variation
X-Returned-From-DLL
Fastly-SWR
X-Geo
X-Block-Status
X-Cache-FS-Status
X-Secret
X-CGP
X-CUA
Request-Time
X-Clientip
X-UnsetCookies
GMS-Ver
HA-Cloudapp
HA-Geocity
HA-Geocountry
HA-Geolat
X-Via-NSCOPI
X-Rocket-Nginx-Bypass
X-IN-WAF
GW-Server
Heartbleed
X-IN-SSL-APIGATEWAY
X-No-Session
X-TT-LOGID
X-Gen-Mode
X-Li-Fabric
X-Gannett-Site-Version
X-Li-Pop
X-Key
X-P-T
X-IN-APIGATEWAY
X-Hnp-Log
X-Server-IP
X-Hash
X-ServiceProvider
X-LI-Proto
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Location
X-MI-In-Market
X-Server-Group
X-Epic-Correlation-Id
X-Eu-Site
X-Sf
X-F5-Cache
X-LI-UUID
Web-Mar-Node
X-S-Maxage
Decoy-Debug-Key
Countrycode
Country-Code
Proxy-Connection
X-Proxy-Cache-Status
MI-Cache
MI-Cache-Age
On-Server
Origin
Pramga
Backend
X-Info
Content-Disposition
X-SVT-ORM-VERSION
HA-Host
X-SVT-ORM-RULES
AKAMAI
X-Stale
X-Request-Start
Kp-EeAlive
HA-Ipaddr
HA-Geolon
Esi-Enabled
HA-Urlpath
HA-Servedtime
HA-Georegion
Ha-Gx-Prefs
MI-API
Decoy-Debug-Status
Decoy-Debug-TTL
X-Proxy-Upstream
True-Client-Country-4JS
X-Be
X-Phone
X-Distributor
X-Origin-Date
X-Origin-Expires
X-Time
IsBot
X-Up
X-Nginx-Cache-Key
X-Fstrz
X-Distil-CS
Pragrma
Backend-Name
X-Backend-Host
X-Amz-Meta-Cache-Control
X-Request-URI
X-Backend-Url
PFcat
Apple-News-Services-Handled
X-Policy
X-ElasticPress-Search
X-Planisys-CDN-Cache
X-Irp-Debug
X-Page-Type
X-Planisys-CDN-TTL
X-Platform
Server-Int
Apple-News-Services-Host
Magicmarker
Fastly-SSL
X-V
REQUESTUUID
X-Core-Value
Who
X-SIPLIST1
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Cache-Cookie-Set-From
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
X-Planisys-CDN-Rules
Pagetype
X-NODE
X-Origin-TTL
X-Refresh
X-NX-Host
X-Cdn-Origin
X-Wikidot-Static-Cache
Request-EU
Request-Country
X-Debug-Cookies
X-Wikidot-Backend
X-Urbn-Context-Path
X-Urbn-Site-Id
UCS
Uber-Trace-Id
X-Sn-Servicetimems
X-Instance-Name
X-Debug-Log
X-MSEdge-Flight
Locale
X-Servername
Fastly-Soc-X-Request-Id
X-Cache-CFC
X-MSEdge-Features
X-Core-Mission
CDCHOST
X-Developers
X-Fastly-Cache
X-Ua
X-Debug-Cache-Store
RequestId
X-NWS-UUID-VERIFY
X-Debug-Cache-Fetch
X-Micro-Cache
X-Debug-Cache-Expiry
PageSpeed
X-Newrelic-Synthetics
Group
V-Cache
X-Instart-Info
X-GeoIP-City
X-Generated-On
X-COUNTRY
X-DC
X-NC
X-Svr
X-VCT
X-Level-Front-Cache
X-Pjax-Url
HitInfo
ServerName
X-Req
Host-ID
X-VarnPar1
Lfy
X-VarnCache
X-PARISIEN-Cache-Rendered
MIME-Version
X-CACHE-AGE
X-Cache-Info
X-Cdn-Srv
Ohc-Response-Time
X-Server-Cache
X-ARC
X-BBXSRF
Mime-Version
X-Powered-By-ANYU
X-Datadome
Cache-Provider
X-Gdpr
PICS-Label
X-B3-Traceid
Memory
X-EIG-Tracking-Id
Cdn
Cteonnt-Length
X-CMS-Context
X-TWH-CORRELATION-ID
X-Servedbyhost
X-Ratelimit-Remaining
CF-IPCountry
X-LAGOON
Nel
NGX
X-Fastly-Country-Code
X-Cluster-Node
X-Aicache-OS
X-WR-MODIFICATION
CDN
X-StackifyID
X-Wa
XServer
X-Load-Cache
X-NodeID
X-WA
FSS-Cache
X-Sentry-ID
Geoip-Latitude
FSS-Proxy
GeoIp-Country-Code
X-HTML-Minification-Powered-By
X-UPSTREAM-Address
X-VServer
GeoIP-Latitude
X-Fastly-Backend-Reqs
GeoIP-Country-Code
X-Flog
X-Hello
X-ABtesting
X-Check-Cacheable
X-Varnish-Beresp-TTL
Cf-Ipcountry
X-Source
X-CSRF-TOKEN
SN
X-Unique-Id
CACHE
X-Varnish-Cache-Hits
X-GZip
Amp-Access-Control-Allow-Source-Origin
X-FireWall-Port
Processtime
X-CSRF-Token
X-Generation-Time
X-APP
X-Csrf-Token
X-Sedo-Request-Id
X-RateLimit-Limit-Second
X-Cache-Miss-From
X-RateLimit-Remaining-Second
X-HOST
WP-Super-Cache
X-ServedByHost
X-Nananana
TSSecure
X-Worker
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-DataStream-Origin-MEX-Latency
X-CDN-Pop-IP
X-MServer
URI
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Storage-Class
X-Cache-Grace
X-CDN-Pop
X-DataStream-MidMile-RTT
PageType
A
X-Edge-Server
Server-Surrogate-Control
Cdn-Request-Time
Cdn-Host
Server-Cache-Control
X-Dynatrace
X-Varnish-Authentication
X-Cache-ASPX
X-SRV
X-Skip-Cache
Pics-Label
X-VC-Cache
X-VG-WebCache
X-FORWARDED-FOR
X-GDPR
X-RCS-Backend
X-IPS-LoggedIn
X-SplitTest
X-AWS-Id
X-VWS-Id
X-ID
DataCenter
X-LJ-Flow-ID
X-Sucuri-Cache
X-HS-Status
HTTPS
X-Port
Hostname
X-B3-SpanId
X-Fastly-Cache-Hits
Odigeo-Trace-Id
X-Varnish-Url
X-Instart-Isnd
X-ND-Cache
X-Backend-TTL
Cache-Hits
X-BE
X-Swift-Error
X-Owner
X-Pf-Uncompressing
X-PJAX-URL
X-From-Cache
X-GoCache-CacheStatus
Get-Access-Time
Dynatrace
Is-Session-Tracking
X-NGINX-Cache
X-GZIP
Proxy-Firewall
X-Ms-Lease-Status
X-Ms-Request-Id
X-Bug-Bounty
X-Ms-Blob-Type
X-Gen-Id
X-Amzn-Remapped-Connection
X-SN
X-Amzn-Remapped-Date
X-Ms-Version
Powered
X-Cache-Ttl
X-ORIG-AKA-EDGE
X-Server-W
ProcessTime
Requestid
X-VarnPar2
X-Amz-Meta-S3b-Last-Modified
Serverid
X-Akamai-SSL-Client-Sid
X-PAGE-TYPE
Correlation-Id
X-Alicdn-Da-Ups-Status
X-Varnish-URL
X-LiteSpeed-Cache-Control
X-Ms-Lease-State
X-VC
X-ServerName
X-Serial
T-Server
X-GEO
RequestUuid
X-ORIG-AKA-COUNTRY-CODE
X-SB
X-RAMCache
WebServer
X-Fe
NnCoection
Xet-Cookie
X-Akamai-ERPolicy
X-LiteSpeed-Tag
Location
X-Akamai-ERRuleID
X-Cache-Srv
X-Developed-By
NodeID
SID
X-CS
X-HTML-Edge-Cache
X-Dw-Trace-Id