Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
Last-Modified
X-Content-Type-Options
Accept-Ranges
Pragma
X-Powered-By
CF-RAY
Link
ETag
Expect-CT
Via
X-XSS-Protection
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Id
X-Served-By
Referrer-Policy
X-Varnish
X-Xss-Protection
X-Request-Id
X-Timer
CF-Cache-Status
X-AspNet-Version
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Runtime
X-Download-Options
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Cacheable
Alt-Svc
X-Check
X-Generator
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Cache-Status
X-AspNetMvc-Version
Status
X-DNS-Prefetch-Control
X-Template
Timing-Allow-Origin
X-Language
X-Permitted-Cross-Domain-Policies
X-FRAME-OPTIONS
Content-Encoding
X-Iinfo
X-Content-Security-Policy
X-CDN
X-Buckets
X-Turbo-Charged-By
X-Request-ID
Upgrade
X-Type
WPE-Backend
Keep-Alive
X-Pass-Why
X-Cache-Group
CF-Ray
X-AH-Environment
Xkey
P3p
X-Backend
Access-Control-Max-Age
X-Age
Access-Control-Expose-Headers
X-Via
X-Drupal-Dynamic-Cache
EagleId
X-Pingback
X-Nginx-Cache-Status
X-Amz-Id-2
X-Amz-Request-Id
X-Server-Powered-By
X-Server
X-Kinja-Server-Push
X-Hacker
Grace
X-UA-Device
X-Swift-CacheTime
X-Swift-SaveTime
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-Robots-Tag
Cf-Railgun
X-Proxy-Cache
X-Envoy-Upstream-Service-Time
X-LiteSpeed-Cache
X-Page-Speed
X-Ua-Compatible
Request-Context
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Ac
Content-Location
X-Cache-Lookup
X-Amz-Version-Id
X-Response-Time
X-Host
Surrogate-Control
X-OneAgent-JS-Injection
X-Rq
X-Cnection
X-WebKit-CSP
X-Node
X-Backend-Server
Server-Timing
X-Server-Id
X-Readtime
Report-To
X-Rack-Cache
Request-Id
EagleEye-TraceId
X-Application-Context
Feature-Policy
X-Cloud-Trace-Context
X-ORACLE-DMS-ECID
X-Instart-Request-ID
X-CST
X-Iejgwucgyu
Edge-Control
X-EdgeConnect-Origin-MEX-Latency
X-Clacks-Overhead
X-EdgeConnect-MidMile-RTT
NEL
Rating
X-Country
X-Url
X-Server-Name
X-TTL
X-Varnish-TTL
X-DynaTrace
X-MS-InvokeApp
Allow
X-Px
X-Country-Code
Pinterest-Generated-By
X-Origin-Cache
X-DataDome
X-Vhost
X-Vname
X-PC
X-TtlSet
X-Cached
X-FTR-Request-ID
X-Ruxit-JS-Agent
RTSS
X-Trace
X-Goog-Hash
SPRequestGuid
X-ESI
X-VARITI-CCR
Charset
X-Powered-By-Plesk
X-SharePointHealthScore
X-DynaTrace-JS-Agent
X-Dispatcher
X-GitHub-Request-Id
X-T
X-Server-ID
X-Powered-CMS
Public-Key-Pins
Accept-CH
X-Mod-Pagespeed
X-F-Cache
Arc-Version
PB-PID
X-Mobile-Rewrite
PB-RID
X-D2id
Verso
X-Exp-Variant
Content-MD5
X-GoogleNews-Bot
X-Exp-Id
X-Kinja
X-Cdn-Fetch
X-Kinja-Server
X-Kinja-Revision
X-Kinja-Build
X-B3-TraceId
X-Version
SPIisLatency
SPRequestDuration
MS-Author-Via
X-Shield-Request-Id
X-Recruiting
X-Dns-Prefetch-Control
X-Oracle-Dms-Rid
X-Abt-Application-Version
X-ORACLE-DMS-RID
Nginx-Cache
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Forwarded-Proto
X-Client-IP
X-HW
X-DIS-Request-ID
X-N
Accept-CH-Lifetime
AR-PoweredBy
AR-CACHE
AR-ATIME
Pinterest-Version
X-Pinterest-Rid
X-Upstream-Env
X-B
X-Amz-Rid
X-Navigation-Version
DynaTrace
X-Upstream
X-Fastly-Request-ID
X-Origin-Upstream-Status
X-Dw-Request-Base-Id
X-Ser
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Amz-Meta-S3cmd-Attrs
Fastly-Restarts
X-Hits
TCN
Realpath
Paypal-Debug-Id
X-Wix-Server-Artifact-Id
X-Goog-Stored-Content-Encoding
X-XRDS-Location
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Accel-Buffering
X-Content-Options
Arr-Disable-Session-Affinity
Service-Worker-Allowed
X-NF-Request-ID
X-Pad
X-Acc-Meta-Resource-Type
X-Goog-Storage-Class
Tracecode
S
Access-Control-Request-Method
X-Id
X-Content-Digest
X-Debug
X-Varnish-Age
X-Use-Magma
Front-End-Https
X-Oneagent-Js-Injection
X-Vcap-Request-Id
MRF-Tech
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
Mrf-Cache-Status
Edge-Cache-Tag
X-MSEdge-Ref
X-Frontend
X-ATG-Version
X-FTR-Expires
X-PressLabs-Stats
X-FTR-Realm
X-IPLB-Instance
X-RateLimit-Remaining
X-FTR-DC
X-FTR-Backend
X-Country-Code-Real
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Cache-Status
X-Kinsta-Cache
X-Logged-In
X-Amz-Cf-Pop
MicrosoftSharePointTeamServices
X-HS-Content-Id
X-HS-Hub-Id
Surrogate-Key
X-Cache-Hit
Rt-Fastcgi-Cache
X-Forwarded-For
X-Webkit-CSP
X-Request-Processing-Time
X-B3-TraceId-Primal
Fastcgi-Cache
X-Request-Received
X-Middleton-Display
X-Sol
Display
X-Zen-Fury
X-Edge-Location
X-Webkit-Csp
Powered-By-ChinaCache
Backend-Timing
X-Analytics
X-Litespeed-Cache
X-Rid
X-Debug-Info
X-Amzn-Trace-Id
Server-Name
X-FastCGI-Cache
Host
X-User-Agent
X-Revision
X-FTR-Cache-Host
TP-Cache
TP-L2-Cache
FilterID
X-Cache-Key
X-HS-Cache-Config
X-Newrelic-App-Data
X-Akam-SW-Version
X-CF-Powered-By
AMP-Access-Control-Allow-Source-Origin
Ar-Sid
X-Fastcgi-Cache
Response
X-Middleton-Response
X-TA-CDN-Provider
AR-Request-ID
X-Grace
X-Drupal-Cache-Tags
X-SS-Set-Cookie
X-Mobile
X-Magnolia-Registration
X-SERVER
Refresh
Cache-Status
X-Accel-Expires
X-Cached-By
Host-Header
X-GUploader-UploadID
X-B3-Sampled
ServerID
X-AOL-HN
X-Varnish-Backend
X-Node-Name
X-VCache
X-NWS-LOG-UUID
X-Content-Security-Policy-Report-Only
X-Tumblr-User
X-Tumblr-Pixel-0
X-Cluster
X-Tumblr-Pixel
X-Instance
X-Whom
X-NewRelic-App-Data
X-FB-Debug
X-Akamai-Edgescape
X-Cache-Control
X-Platform-Server
X-Signature
X-B-Cache
Eomportal-Instance
X-Cache-2
X-Framework
X-LB-Cache
X-BCube-Filmed-By
X-Ruxit-Js-Agent
X-Esi
X-App-Environment
X-Page-Id
X-Generated-By
X-Device-Type
X-Varnish-Hostname
X-Drupal-Cache-Contexts
Cleartype
X-Handled-By
X-Via-JSL
X-Request-Guid
X-Srv
X-Cache-Rule
X-Cache-Action
Cache-Tag
DC
X-App-Server
Liferay-Portal
X-Activity-Id
X-Az
X-AppVersion
X-Ttl
Alternate-Protocol
Source
X-Cache-Server
X-WPE-Loopback-Upstream-Addr
X-Content-Powered-By
Retry-After
X-Hostname
X-HS-Combine-CSS
X-App-Version
X-Varnish-Grace
X-WA-Info
MS-CV
HostName
Public-Key-Pins-Report-Only
X-Geo-Country
X-Varnish-Server
X-Amz-Replication-Status
X-Wix-Request-Id
X-TT
X-Seen-By
X-Daa-Tunnel
Server-Node
ViewerVersion
AR-SID
Accept-Charset
Pagespeed
Webserver
X-URL
X-Correlation-Id
Upgrade-Insecure-Requests
AsisCache
X-Tumblr-Pixel-1
X-Tumblr-Pixel-2
X-WebKit-CSP-Report-Only
X-Response-Served-From
X-Cache-NE
X-Amzn-RequestId
X-Locale
Actual-Object-TTL
SRV
X-Amz-Apigw-Id
X-GeoIP
GEO-INFO
X-RequestSource
X-Varnish-Hits
ServedBy
X-Jobs
X-Correlation-ID
X-Servedby
X-Yottaa-Metrics
X-Contextid
X-Yottaa-Optimizations
X-S
Payment
Viewport
X-UUID
X-Edge-Cache-Key
X-FW-Serve
X-FW-Server
X-FW-Type
X-Status
X-FW-Hash
X-FW-Static
X-Edge-Cache
X-Varnish-IP
X-TX-ID
X-XRDS-LOCATION
X-Adobe-Loc
X-Adobe-Content
X-Cacheable-TTL
X-TT-TIMESTAMP
Cache
X-Origin-Server
X-Cache-TTL-Remaining
X-Vg-Webcache
S-Cnection
X-Geo-Segment
X-Hyper-Cache
X-Amz-Server-Side-Encryption
X-Forwarded-Host
X-Cache-Operation
Server-Info
X-RateLimit-Limit
Datacenter
X-Cache-Age
Served-By
X-Real-IP
X-Region
X-Akamai-Request-ID2
X-Mode
X-CLOUD-TRACE-CONTEXT
Access-Control-Allow-Method
X-DataStream-Cache-Status
X-Sucuri-ID
Healthy
X-GRACE
CACHE
X-Content-Type
Country
X-Akamai-Transformed
X-Cache-Config
X-Zipkin-Id
X-L-Path
From-Origin
X-Routing-Service
Fastcgi-X-Cache-Version
X-Rule
X-Rendered-As
Fastcgi-Useragent
X-RN-RSRV
X-Ocache
Fastcgi-X-Cache
X-JoinUs
X-Generated
Machine
X-Environment-Context
X-Proxied
X-Site-Version
X-Is-Bot
X-Cache-Var-Map
X-Cache-Var
X-Path-Route
X-Detected-As
X-Proxy
Meta-Geo
X-Access
X-Birta-Cache-Post
X-Amz-Meta-Surrogate-Control
X-Request-Time
X-Section
X-Agile-Id
X-Agile-Age
X-Agile
X-CDN-Cache
X-Hosted-By
X-Via-CDN
X-Viewer-Country
Now
L5d-Success-Class
DB-Nickname
X-Birta-Served
X-Human
X-Upgrade-Enabled
X-Format
S-Rt
Property-Id
Webcakes-App-Version
Webcakes-App-Name
OT-Force-Account-Verify
TWC-Connection-Speed
TWC-GeoIP-Country
TWC-Locale-Group
Webcakes-Region
TWC-Device-Class
TWC-Privacy
TWC-GeoIP-LatLong
Cache-Name
X-Web-Node
X-Origin-Hint
X-NGENIX-Cache
X-OCL
X-Via-Fastly
X-Labrador-Cache-Channel
X-Pc-Appver
X-Pc-Hit
X-Pc-Key
X-PCL
X-Grey
X-Hit
X-EIG-Tracking-Id
X-ServerID
Xserver
X-CCM
X-Cache-Category-Id
X-Loop
X-TNCMS
X-Tb
X-FC-Vary-Parameters
Origin-Edge-Control
HitInfo
X-Origin
X-Original-Request
X-ProxyCache-Key
X-Pubstack
Origin-Cache-Control
X-ProxyCache-Status
X-Xfnlog-Site
X-IP
X-BYPASS-REASON
X-VG-TLSProxy
HitType
Azure-RegionName
Azure-InstanceId
X-Cdn
Azure-SlotName
Azure-SiteName
Azure-Version
X-Ezoic-Cdn
X-ShopId
X-Timing-Wait
X-Alternate-Cache-Key
X-Shopify-Stage
X-Sorting-Hat-ShopId
X-ShardId
X-ProcessESI
X-Cluster-Node
X-Geo
Accept-Language
X-Upstream-CT
X-Proxy-Build
X-RemovedCookies
X-Sorting-Hat-PodId
Mn-Server-Ip
LB
X-Upstream-HT
X-Www-Served-By
Selected-FE
X-Microcachable
X-App-Name
X-OVcl-Cache
X-OVcl
X-Transaction
X-Rocket-Nginx-Bypass
NGB
X-TWH-CORRELATION-ID
X-Connection-Hash
X-Twitter-Response-Tags
X-RTag
X-TIME
X-Cache-Enabled
Ms-Operation-Id
X-Cache-Remote
Filters
X-SplitTest
X-LJ-Flow-ID
X-AWS-Id
X-VWS-Id
X-UA
Access-Control-Request-Headers
X-Real-Ip
IBM-Web2-Location
Time
X-Internal-Host
X-NodeID
X-Pc-Host
X-Unique-ID
Content-Script-Type
X-UA-Device-Type
X-Tumblr-Pixel-3
X-Pc-Date
Content-Style-Type
X-Guploader-Uploadid
X-NCache
X-Origin-CC
X-Nginx-Cache
X-Proto
X-Source
Cache-Hits
Mail-Subject
We-Hiring
X-Cdn-Forward
X-Port
X-PHP-Backend
X-MP-GENERATED-AT
X-Ms-Blob-Type
X-Storage
X-Edge-IP
X-Ms-Lease-Status
X-Ms-Version
X-Ms-Request-Id
X-Vgn-Hpd-Reason
NtCoent-Length
Backend
X-Datadome
X-Cache-TTL
X-Debug-Cache
X-Time-Microsecs
X-Varnish-Cacheable
X-Distil-CS
X-Akamai-Request-ID
X-Webstats-RespID
X-APP-VERSION
Cache-Tags
X-Backend-Name
X-CACHE-GROUP
X-CACHE-KEY
X-Csrf-Token
X-CACHE-AGE
X-Ua
X-Endurance-Cache-Level
X-Varnish-Beresp-Status
Locale
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Varnish-Beresp-Grace
X-Ratelimit-Limit
PageSpeed
X-Origin-Response-Time
X-B3-Spanid
X-Redis-Cache
Warning
X-EdgeConnect-Cache-Status
User-Agent
X-Varnish-Cache-Hits
X-Croise-Owner
X-ApacheServer
X-PERF
X-C
X-NC
X-Via-SSL
V-Age
Viewtype
GMS-Ver
X-We-Are-Hiring
X-IN-APIGATEWAY
HA-Cloudapp
UCS
Xc-Version
FSS-Proxy
VivaBuild
Ec-Rule-Version
X-A-Dcw
Content-Disposition
X-A-Dam
Fly-Cache
FSS-Cache
Fly-Request-Id
X-A-Ccd
HA-Geocity
HA-Geocountry
HA-Ipaddr
Meta-Geo-Continent
Rt-Proxy-Cache
HA-Host
Resin-Trace
HA-Servedtime
MD5-Digest
HA-Urlpath
Rendered-Blocks
SN
Ha-Gx-Prefs
HA-Geolat
Mobile-Detection-Method
TSSecure
X-Irp-Debug
X-IN-WAF
Odigeo-Trace-Id
HA-Georegion
HA-Geolon
Powered-By
X-Hash
X-Debug-Log
X-Debug-Cookies
X-Destination
Cache-Prefix
X-Region-Sid
X-Rewrite-Enabled
X-Rojux
X-CGP
X-CF-Lambda-Version
X-S-Cookie
X-D
X-Date
X-Developer
X-PAYTM-SRV-ID
X-ElasticPress-Search
X-Org
X-Eu-Site
X-External-Request-Id
X-NX-Host
X-DPWN-IS-SECURE
X-F5-Cache
X-Generated-In
X-Died
X-G
X-From
X-ScT
X-Server-By
X-VG-WebServer
X-NU-AKA-ACS-Version
X-BB-ID
X-Logtrace-Id
X-BBXSRF
X-B-Cookie
X-Application
X-Via-Edge
X-A-Wwc
X-Accel-Expires-Debug
X-Aed
X-Amz-Meta-Cache-Control
X-Cache-Bucket
X-Cache-Host
X-SRCache-Key
X-CF-Lambda-Fn
X-Sn-Servicetimems
X-Server-Time
X-GeoIP-Country-Code
X-Cdn-Origin
X-Store
X-Cache-URL
X-IN-SSL-APIGATEWAY
X-UE-Client-Country
X-Trv-Group
X-A-Dgt
X-A
X-Mrs-Cache
X-Mrs-Age
Fastly-SSL
X-Mrs-Cache-Hits
X-Mshield-Cache-Status
X-Varnish-Beresp-Ttl
X-CDN-Forward
Ajk
Arc-Country
BehaviorPad-Version
X-Cache-Backend
Version
X-Sucuri-Cache
X-Dc
Cache-Key
X-Hl-Ver
X-Fetched-On
X-Layer
X-Flog
X-Key
X-GeoIP-City
X-Hello
X-Core-Value
X-Backend-Host
X-Backend-State
X-Auto-Login
X-ABtesting
Www
X-Backend-Url
X-Dynatrace-Js-Agent
X-Developers
X-Dispatcher-Server
X-Location
X-Clientip
X-Cache-Id
X-Epic-Correlation-Id
X-Oss-Hash-Crc64ecma
X-Var-Ttl
X-Via-NSCOPI
X-V
X-User
X-Trace-Id
X-UnsetCookies
X-VServer
X-Wikidot-Backend
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
Fastly-SWR
Fastly-SIE
X-Wikidot-Static-Cache
Country-Code
X-SIPLIST1
X-S-Maxage
X-Qloud-Router
X-Oss-Object-Type
X-Platform
Server-ID
X-No-Session
X-DC
X-Release
X-Request-Start
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Request-Id
X-Response-By
X-Request-URI
X-Nc
X-MServer
RNT-Time
Apple-News-Services-Parsed-Url
Server-Host
Heartbleed
Frame-Options
Origin
IsBot
Apple-News-Services-Handled
Countrycode
Apple-News-Services-Request-Url
Fastly-Soc-X-Request-Id
Apple-News-Services-Host
RNT-Machine
GW-Server
Memcached
Release
AKAMAI
Pramga
Section-Io-Cache
X-Powered-By-ANYU
X-NWS-UUID-VERIFY
WZWS-RAY
X-Passed-To
X-Passed-To-BeforeDispatch
X-Policy
Server-Int
X-Returned-From
X-Reboot
X-RCS-CacheZone
X-Passed-To-PostProcessResponse
X-Phone
X-Passed-To-DLL
X-Node-Id
X-Instance-Name
Magicmarker
X-Li-Fabric
X-Hnp-Log
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Gannett-Site-Version
X-Gen-Mode
X-Li-Pop
X-LI-Proto
X-Nginx-Cache-Key
X-Returned-From-BeforeDispatch
X-Newrelic-Synthetics
Cache-Cookie-Set-Idcheck
X-Matched-Rule
X-LI-UUID
Kp-EeAlive
X-P-T
X-Served-From
X-Worker
Decoy-Debug-Key
Adler-Geo
Decoy-Debug-Status
Decoy-Debug-TTL
Esi-Enabled
X-WebServer
Backend-Name
Is-Eu
Cache-Cookie-Set-From
Cache-Cookie-Set-Lfrom
X-Variation
X-Info
X-Cache-FS-Status
Platform
Uber-Trace-Id
Fastly-Backend-Name
X-VCT
X-Server-IP
X-ServiceProvider
X-Sf
X-FW-Version
X-Sentry-ID
X-Returned-From-PostProcessResponse
X-Secret
X-Stale
X-SVT-ORM-RULES
X-TT-LOGID
X-Up
X-Varnish-Action
X-Thinkindot-L3
X-Thanos
X-SVT-ORM-VERSION
X-Swa-Ws
X-Returned-From-DLL
X-Request-UUID
X-Cache-Expires
Request-Country
X-Cache-Debug
X-Fastly-Cache
X-Bip
X-Core-Mission
X-Crawler
Pragrma
X-Device-Os
X-Distributor
X-CUA
On-Server
Request-EU
X-Block-Status
Web-Mar-Node
User-Cache-Control
Thinkindot-CacheControl-Type
True-Client-Country-4JS
Thinkindot-Control
Pagetype
Thinkindot-CacheControl
X-Actual-URL
X-Parent-Response-Time
X-MSEdge-Flight
X-Owner
Group
V-Cache
Proxy-Connection
X-MSEdge-Features
X-HOST
X-Unique-Id-Primal
X-Cache-CFC
X-Fstrz
X-Refresh
CDCHOST
X-NODE
MI-Cache-Age
MI-Cache
X-MI-In-Market
X-Time
X-Backend-TTL
REQUESTUUID
Cteonnt-Length
X-Page-Type
Who
MIME-Version
MI-API
X-Req
X-Pjax-Url
X-SN
Fusion-Source
X-Servername
HTTPS
RequestId
X-Cache-Srv
X-Kong-Proxy-Latency
Fusion-Template-Id
X-Be
X-Kong-Upstream-Latency
Fusion-Component-Id
Fusion-Content-Source
Fusion-Content-Id
Amp-Access-Control-Allow-Source-Origin
X-Oracle-Dms-Ecid
X-Ms-Lease-State
NodeID
X-Origin-TTL
Memory
X-GZip
X-Edge-Server
ProcessTime
X-B3-Traceid
Cdn-Request-Time
Cdn-Host
X-Servedbyhost
X-Server-Group
Cdn
CF-IPCountry
X-Protected-By
X-Aicache-OS
X-Content-Age
SS
SD-X-WS
Mime-Version
X-BB-IP
X-ND-Cache
X-Ckpd-Fst-Backend
X-COUNTRY
X-Wa
CDN
GeoIP-Country-Code
A
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-SRV
X-Origin-Date
X-Origin-Expires
GeoIP-Latitude
PageType
X-Origin-Host
X-Varnish-Beresp-TTL
Get-Access-Time
Is-Session-Tracking
XServer
X-APP
X-Pf-Uncompressing
X-StackifyID
X-Varnish-Url
X-Fastly-Country-Code
GeoIp-Country-Code
Geoip-Latitude
X-Unique-Id
Serverid
Processtime
X-Cache-Info
X-WA
Node
X-Requestid
PICS-Label
X-PHP-Host
X-Gdpr
X-CSRF-Token
X-Ratelimit-Remaining
X-RateLimit-Limit-Second
X-Proxy-Upstream
X-Generation-Time
X-Proxy-Cache-Status
X-RateLimit-Remaining-Second
Vix-Hermes-Req-Id
X-Fastly-Cache-Hits
X-Nananana
Nel
Cache-Tv-Group
X-Load-Cache
X-FireWall-Port
X-ID
X-RequestId
X-UPSTREAM-Address
X-Check-Cacheable
X-ServedByHost
Cf-Ipcountry
X-SERVER-NAME
DataCenter
URI
Cache-Provider
X-EC-Security-Audit
X-CS
X-Server-W
X-HS-Status
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-FORWARDED-FOR
Hostname
X-NGINX-Cache
X-GZIP
WP-Super-Cache
Request-Time
X-BACKEND-TTL
X-GEO
X-Micro-Cache
X-BE
X-Fastly-Backend-Reqs
NGX
PFcat
T-Server
X-Surge-Debug
X-WR-MODIFICATION
X-B3-SpanId
X-Front
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Fe
X-HTML-Minification-Powered-By
X-HTML-Edge-Cache
X-VG-WebCache
X-Debug-Cache-Expiry
Requestid
X-DataStream-MidMile-RTT
Host-ID
X-DataStream-Origin-MEX-Latency
Https
X-Cache-Ttl
X-Atg-Version
X-FB-TRIP-ID
X-PF-Uncompressing
X-M-Log
X-Svr
X-PJAX-URL
X-Qnm-Cache
ServerName
X-VarnPar1
X-VarnCache
X-PARISIEN-Cache-Rendered
X-ServerName
X-IPS-LoggedIn
X-GDPR
RequestUuid
X-M-Reqid
X-Swift-Error
X-Amz-Meta-S3b-Last-Modified
X-Akamai-SSL-Client-Sid
X-Vcache
X-Cdn-Srv
X-VarnPar2
X-Instart-Info
Ohc-Response-Time
Ohc-File-Size
Lfy
N-Cache
X-Alicdn-Da-Ups-Status
WebServer
X-Distil-Cs
X-SB
X-PAGE-TYPE
X-VC
X-From-Cache
Load-Balancing
X-Generated-On
Build-Number
X-Skip-Cache
X-Level-Front-Cache
Pics-Label
X-Serial
X-ARC
X-Grace-Duration
X-Gen-Id
X-RAMCache
X-Dw-Trace-Id
Cdn-Src-Port
SID