Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
Last-Modified
X-Content-Type-Options
Accept-Ranges
Pragma
X-Powered-By
CF-RAY
Link
ETag
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Id
X-Served-By
Referrer-Policy
X-Varnish
X-Request-Id
X-Timer
CF-Cache-Status
X-AspNet-Version
Access-Control-Allow-Headers
X-Xss-Protection
Access-Control-Allow-Methods
X-Runtime
X-Download-Options
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Cacheable
Alt-Svc
X-Check
X-Generator
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Cache-Status
X-AspNetMvc-Version
Status
X-DNS-Prefetch-Control
X-Template
Timing-Allow-Origin
X-Language
X-Permitted-Cross-Domain-Policies
X-FRAME-OPTIONS
Content-Encoding
X-Iinfo
X-Content-Security-Policy
X-CDN
X-Buckets
X-Turbo-Charged-By
X-Request-ID
Upgrade
X-Type
WPE-Backend
Keep-Alive
X-Pass-Why
X-Cache-Group
CF-Ray
X-AH-Environment
Xkey
P3p
X-Backend
Access-Control-Max-Age
X-Age
Access-Control-Expose-Headers
X-Via
X-Drupal-Dynamic-Cache
EagleId
X-Pingback
X-Nginx-Cache-Status
X-Amz-Request-Id
X-Amz-Id-2
X-Server-Powered-By
X-Server
X-Kinja-Server-Push
X-Hacker
Grace
X-UA-Device
X-Swift-SaveTime
X-Swift-CacheTime
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-Robots-Tag
Cf-Railgun
X-Proxy-Cache
X-Envoy-Upstream-Service-Time
X-LiteSpeed-Cache
X-Page-Speed
X-Ua-Compatible
Request-Context
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Ac
Content-Location
X-Cache-Lookup
X-Amz-Version-Id
X-WebKit-CSP
X-Response-Time
X-Host
Surrogate-Control
X-OneAgent-JS-Injection
X-Rq
X-Cnection
X-Node
X-Backend-Server
Server-Timing
X-Readtime
Report-To
X-Rack-Cache
X-Server-Id
Request-Id
EagleEye-TraceId
X-Application-Context
Feature-Policy
X-Cloud-Trace-Context
X-ORACLE-DMS-ECID
X-Instart-Request-ID
X-CST
X-Iejgwucgyu
X-EdgeConnect-Origin-MEX-Latency
Edge-Control
X-EdgeConnect-MidMile-RTT
X-Clacks-Overhead
NEL
Rating
X-Country
X-Url
X-Server-Name
X-Varnish-TTL
X-DynaTrace
X-MS-InvokeApp
Allow
X-Px
X-Country-Code
X-TTL
Pinterest-Generated-By
X-Origin-Cache
X-DataDome
X-Vhost
X-Vname
X-TtlSet
X-PC
X-Cached
X-FTR-Request-ID
X-ESI
X-Server-ID
RTSS
X-Ruxit-JS-Agent
SPRequestGuid
X-Trace
X-Goog-Hash
Charset
X-VARITI-CCR
X-Powered-By-Plesk
X-SharePointHealthScore
Accept-CH
X-GitHub-Request-Id
X-DynaTrace-JS-Agent
X-T
X-Dispatcher
X-Powered-CMS
Public-Key-Pins
X-D2id
X-Mod-Pagespeed
X-B3-TraceId
Arc-Version
PB-PID
X-Mobile-Rewrite
PB-RID
X-F-Cache
Verso
X-Oracle-Dms-Rid
Content-MD5
X-Exp-Variant
X-Kinja-Build
X-Kinja-Revision
X-Cdn-Fetch
X-Kinja
X-Exp-Id
X-GoogleNews-Bot
X-Kinja-Server
X-Version
SPRequestDuration
SPIisLatency
MS-Author-Via
X-Shield-Request-Id
X-Recruiting
X-Dns-Prefetch-Control
X-Abt-Application-Version
Nginx-Cache
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Forwarded-Proto
X-Client-IP
Accept-CH-Lifetime
X-HW
X-DIS-Request-ID
X-N
X-Navigation-Version
Pinterest-Version
X-Pinterest-Rid
X-Upstream-Env
AR-CACHE
AR-ATIME
AR-PoweredBy
X-B
X-Amz-Rid
X-ORACLE-DMS-RID
X-Fastly-Request-ID
X-Upstream
DynaTrace
X-Origin-Upstream-Status
X-Dw-Request-Base-Id
X-Ser
X-SRCache-Fetch-Status
X-Amz-Meta-S3cmd-Attrs
X-SRCache-Store-Status
X-Hits
Fastly-Restarts
TCN
Realpath
Paypal-Debug-Id
X-Goog-Generation
X-Goog-Metageneration
X-Wix-Server-Artifact-Id
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-XRDS-Location
X-Accel-Buffering
X-Content-Options
Arr-Disable-Session-Affinity
Service-Worker-Allowed
X-NF-Request-ID
X-Pad
X-Acc-Meta-Resource-Type
X-Goog-Storage-Class
Tracecode
S
Access-Control-Request-Method
X-Content-Digest
X-Id
X-Debug
X-Varnish-Age
X-Use-Magma
Front-End-Https
X-Oneagent-Js-Injection
X-Vcap-Request-Id
MRF-Tech
Mrf-Cache-Status
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
X-MSEdge-Ref
Edge-Cache-Tag
X-Frontend
X-IPLB-Instance
X-FTR-DC
X-FTR-Cache-Status
X-FTR-Expires
X-FTR-Realm
X-FTR-Balancer
X-FTR-Backend-Server
X-RateLimit-Remaining
X-Country-Code-Real
X-FTR-Backend
X-PressLabs-Stats
X-Kinsta-Cache
X-Logged-In
X-ATG-Version
MicrosoftSharePointTeamServices
X-Amz-Cf-Pop
X-HS-Hub-Id
X-HS-Content-Id
Surrogate-Key
X-Cache-Hit
Rt-Fastcgi-Cache
X-B3-TraceId-Primal
X-Forwarded-For
X-Request-Received
X-Request-Processing-Time
Fastcgi-Cache
X-FastCGI-Cache
X-Middleton-Display
Display
X-Sol
Powered-By-ChinaCache
X-Edge-Location
X-Webkit-Csp
X-Zen-Fury
X-Analytics
X-Litespeed-Cache
Backend-Timing
X-Rid
X-Debug-Info
Server-Name
X-Amzn-Trace-Id
X-Revision
X-User-Agent
X-Grace
Host
TP-L2-Cache
X-FTR-Cache-Host
TP-Cache
FilterID
X-HS-Cache-Config
X-Cache-Key
X-Akam-SW-Version
AMP-Access-Control-Allow-Source-Origin
X-CF-Powered-By
X-Newrelic-App-Data
Response
X-Middleton-Response
X-TA-CDN-Provider
AR-Request-ID
X-SS-Set-Cookie
X-Drupal-Cache-Tags
X-Mobile
X-Magnolia-Registration
Ar-Sid
X-SERVER
X-Ttl
X-Fastcgi-Cache
Refresh
Cache-Status
X-Accel-Expires
X-Cached-By
X-GUploader-UploadID
Host-Header
X-B3-Sampled
X-Varnish-Backend
ServerID
X-AOL-HN
X-Webkit-CSP
X-VCache
X-Node-Name
X-NWS-LOG-UUID
X-Content-Security-Policy-Report-Only
X-Instance
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-NewRelic-App-Data
X-Tumblr-User
X-FB-Debug
Eomportal-Instance
X-Cluster
X-Whom
X-Platform-Server
X-Akamai-Edgescape
X-Cache-Control
X-B-Cache
X-Cache-2
X-Signature
X-Varnish-Hostname
X-BCube-Filmed-By
X-Device-Type
X-Page-Id
X-Generated-By
X-App-Environment
X-LB-Cache
X-Framework
X-Ruxit-Js-Agent
X-Drupal-Cache-Contexts
X-Handled-By
Cleartype
X-Via-JSL
X-Srv
X-Request-Guid
X-AppVersion
X-Activity-Id
X-Cache-Rule
X-Az
Cache-Tag
X-Cache-Action
DC
X-App-Server
Liferay-Portal
Alternate-Protocol
Source
X-Cache-Server
X-WPE-Loopback-Upstream-Addr
X-Content-Powered-By
Retry-After
MS-CV
X-Hostname
X-HS-Combine-CSS
AR-SID
X-WA-Info
X-Varnish-Grace
HostName
X-Geo-Country
Public-Key-Pins-Report-Only
X-Varnish-Server
X-Esi
X-Amz-Replication-Status
X-Daa-Tunnel
X-Wix-Request-Id
X-Seen-By
X-TT
ViewerVersion
X-App-Version
Server-Node
Pagespeed
Webserver
Accept-Charset
X-URL
X-Correlation-Id
Upgrade-Insecure-Requests
X-Response-Served-From
AsisCache
X-Tumblr-Pixel-1
X-Tumblr-Pixel-2
X-WebKit-CSP-Report-Only
X-Cache-NE
X-Amzn-RequestId
X-Amz-Apigw-Id
X-GeoIP
Actual-Object-TTL
SRV
GEO-INFO
X-RequestSource
ServedBy
X-Locale
X-Jobs
X-Varnish-Hits
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-UUID
X-Servedby
X-FW-Static
Viewport
X-Edge-Cache-Key
X-Edge-Cache
X-FW-Hash
X-FW-Serve
X-Contextid
X-FW-Server
X-FW-Type
Payment
X-Correlation-ID
X-S
X-Status
X-Varnish-IP
X-TX-ID
X-Adobe-Loc
X-Adobe-Content
X-XRDS-LOCATION
X-Cacheable-TTL
X-TT-TIMESTAMP
X-Origin-Server
X-Vg-Webcache
X-Cache-TTL-Remaining
X-Geo-Segment
S-Cnection
X-Hyper-Cache
Cache
X-Amz-Server-Side-Encryption
X-Cache-Operation
X-Forwarded-Host
Server-Info
Datacenter
X-RateLimit-Limit
Served-By
X-Real-IP
X-Region
CACHE
X-Cache-Age
X-Akamai-Request-ID2
X-Mode
Access-Control-Allow-Method
X-CLOUD-TRACE-CONTEXT
X-DataStream-Cache-Status
X-Sucuri-ID
Healthy
X-Akamai-Transformed
X-Content-Type
Country
Machine
X-Detected-As
X-Is-Bot
Fastcgi-Useragent
Fastcgi-X-Cache-Version
Fastcgi-X-Cache
X-L-Path
X-JoinUs
X-Rule
X-Cache-Var-Map
X-RN-RSRV
X-Cache-Config
X-Environment-Context
Meta-Geo
X-Rendered-As
X-Cache-Var
X-Generated
X-Routing-Service
X-Zipkin-Id
From-Origin
X-Ocache
X-Upgrade-Enabled
X-Proxied
X-Path-Route
X-Proxy
X-Birta-Cache-Post
X-Birta-Served
X-Format
X-Amz-Meta-Surrogate-Control
X-Hosted-By
X-Agile-Age
L5d-Success-Class
DB-Nickname
X-Via-CDN
Now
X-Viewer-Country
X-Human
X-Agile
X-Access
X-Agile-Id
X-CDN-Cache
X-Request-Time
X-NGENIX-Cache
X-Section
X-Pc-Key
OT-Force-Account-Verify
Xserver
X-Ezoic-Cdn
X-Via-Fastly
X-Web-Node
Property-Id
X-Tb
S-Rt
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Privacy
Webcakes-App-Name
Cache-Name
TWC-Connection-Speed
Webcakes-App-Version
Webcakes-Region
X-Origin-Hint
X-Loop
X-FC-Vary-Parameters
X-PCL
X-Labrador-Cache-Channel
X-Grey
X-TNCMS
X-Pc-Hit
X-Hit
X-Pc-Appver
X-OCL
X-CCM
TWC-Device-Class
X-Cache-Category-Id
X-ServerID
X-EIG-Tracking-Id
X-OVcl-Cache
Origin-Edge-Control
X-Microcachable
X-VG-TLSProxy
X-ProxyCache-Status
X-ProcessESI
Origin-Cache-Control
X-Origin
X-Pubstack
X-Xfnlog-Site
X-Upstream-CT
X-Upstream-HT
X-BYPASS-REASON
X-IP
X-RemovedCookies
X-Original-Request
X-Site-Version
X-ProxyCache-Key
HitInfo
X-OVcl
HitType
Azure-SlotName
Azure-InstanceId
Azure-Version
Azure-SiteName
X-Cdn
Azure-RegionName
X-Geo
X-ShopId
X-ShardId
X-Www-Served-By
X-Alternate-Cache-Key
X-Cluster-Node
X-Timing-Wait
Accept-Language
Mn-Server-Ip
X-Sorting-Hat-ShopId
X-Proxy-Build
LB
Selected-FE
X-Sorting-Hat-PodId
X-Shopify-Stage
NGB
Ms-Operation-Id
X-RTag
X-App-Name
X-GRACE
X-Rocket-Nginx-Bypass
X-Twitter-Response-Tags
Filters
X-Connection-Hash
X-Transaction
X-TWH-CORRELATION-ID
X-Cache-Enabled
X-TIME
X-LJ-Flow-ID
X-Cache-Remote
X-SplitTest
X-VWS-Id
X-AWS-Id
X-Real-Ip
Access-Control-Request-Headers
X-UA
Time
X-Internal-Host
X-NCache
IBM-Web2-Location
X-Guploader-Uploadid
X-NodeID
Content-Style-Type
X-Tumblr-Pixel-3
X-Pc-Host
X-Unique-ID
X-Pc-Date
X-UA-Device-Type
Content-Script-Type
X-APP-VERSION
X-Nginx-Cache
X-Proto
Cache-Hits
X-Origin-CC
X-Source
Mail-Subject
X-Cdn-Forward
X-PHP-Backend
We-Hiring
X-Port
X-MP-GENERATED-AT
NtCoent-Length
X-Ms-Request-Id
X-Ms-Blob-Type
X-Storage
X-Vgn-Hpd-Reason
X-Ms-Version
X-Ms-Lease-Status
X-Edge-IP
Backend
X-Cache-TTL
X-Time-Microsecs
X-Datadome
X-Debug-Cache
X-Distil-CS
X-Akamai-Request-ID
X-Webstats-RespID
X-Backend-Name
X-Varnish-Cacheable
Cache-Tags
X-Oracle-Dms-Ecid
X-CACHE-GROUP
X-CACHE-KEY
X-CACHE-AGE
X-Csrf-Token
X-Endurance-Cache-Level
X-Ua
X-Varnish-Beresp-Grace
PageSpeed
Locale
X-Urbn-Site-Id
X-Urbn-Context-Path
X-Varnish-Beresp-Status
X-Origin-Response-Time
X-Ratelimit-Limit
X-Redis-Cache
X-B3-Spanid
Warning
X-EdgeConnect-Cache-Status
X-Varnish-Cache-Hits
User-Agent
X-Croise-Owner
X-C
X-PERF
X-NC
X-ApacheServer
SN
TSSecure
X-VG-WebServer
V-Age
X-Via-SSL
X-Via-Edge
UCS
VivaBuild
X-A-Ccd
X-SRCache-Key
X-A-Dam
X-A-Dcw
X-A
X-Store
X-We-Are-Hiring
X-UE-Client-Country
X-Trv-Group
Viewtype
Xc-Version
HA-Geocountry
HA-Geocity
HA-Geolat
HA-Geolon
HA-Georegion
HA-Cloudapp
GMS-Ver
Fly-Cache
Ec-Rule-Version
Fly-Request-Id
FSS-Cache
FSS-Proxy
Ha-Gx-Prefs
HA-Host
Powered-By
Odigeo-Trace-Id
Rendered-Blocks
Resin-Trace
Rt-Proxy-Cache
Mobile-Detection-Method
Meta-Geo-Continent
HA-Ipaddr
HA-Servedtime
HA-Urlpath
MD5-Digest
Server-Host
X-Sn-Servicetimems
X-Generated-In
X-GeoIP-Country-Code
X-G
X-From
X-Fetched-On
X-Hash
X-CF-Lambda-Version
X-Irp-Debug
X-IN-WAF
X-IN-SSL-APIGATEWAY
X-IN-APIGATEWAY
X-F5-Cache
X-CGP
X-Destination
X-Debug-Log
X-Developer
Content-Disposition
X-DPWN-IS-SECURE
X-ElasticPress-Search
X-Debug-Cookies
X-D
X-External-Request-Id
X-Date
X-Eu-Site
X-Logtrace-Id
X-CF-Lambda-Fn
X-Application
X-Amz-Meta-Cache-Control
X-B-Cookie
X-BB-ID
X-ScT
X-Server-By
X-Aed
X-A-Wwc
X-Died
X-Server-Time
X-Accel-Expires-Debug
X-S-Cookie
X-Rojux
X-PAYTM-SRV-ID
X-Cdn-Origin
X-Org
X-NX-Host
X-NU-AKA-ACS-Version
X-Cache-URL
X-Cache-Host
X-Rewrite-Enabled
X-BBXSRF
X-Region-Sid
X-Cache-Bucket
Fastly-SSL
X-A-Dgt
BehaviorPad-Version
X-Mrs-Cache-Hits
X-Varnish-Beresp-Ttl
X-Mrs-Cache
Ajk
Arc-Country
X-Cache-Backend
Cache-Prefix
X-Mrs-Age
X-Mshield-Cache-Status
Version
X-Sucuri-Cache
Cache-Key
X-Dc
X-CDN-Forward
X-Response-By
X-Qloud-Router
X-Reboot
X-ABtesting
X-Oss-Object-Type
X-Request-Start
X-Release
X-Request-URI
X-S-Maxage
Thinkindot-CacheControl
Server-ID
X-ServiceProvider
RNT-Time
Thinkindot-CacheControl-Type
X-Flog
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Storage-Class
X-Platform
Www
X-No-Session
X-Key
X-Hl-Ver
X-Layer
X-Core-Value
X-Clientip
X-Hello
X-Developers
X-FW-Version
X-Epic-Correlation-Id
X-Dispatcher-Server
X-GeoIP-City
X-Location
X-Nc
X-Backend-Url
X-Oss-Hash-Crc64ecma
X-Backend-State
X-Backend-Host
X-DC
RNT-Machine
X-Dynatrace-Js-Agent
X-Matched-Rule
X-Cache-Id
X-MServer
X-Auto-Login
Thinkindot-Control
Apple-News-Services-Request-Url
Memcached
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-VServer
X-Via-NSCOPI
Frame-Options
X-User
X-Var-Ttl
GW-Server
IsBot
Fastly-SWR
Fastly-SIE
Country-Code
Apple-News-Services-Handled
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Heartbleed
X-SIPLIST1
X-UnsetCookies
X-V
X-Rebelmouse-Cache-Control
X-Thinkindot-L3
Pramga
X-Rebelmouse-Surrogate-Control
Decoy-Debug-TTL
Countrycode
Decoy-Debug-Key
Decoy-Debug-Status
X-Trace-Id
Release
Fastly-Soc-X-Request-Id
Origin
X-Powered-By-ANYU
X-NWS-UUID-VERIFY
Section-Io-Cache
WZWS-RAY
X-Hnp-Log
X-Gannett-Site-Version
Platform
Uber-Trace-Id
X-LI-UUID
X-Variation
X-Gen-Mode
X-Info
X-Instance-Name
X-Li-Fabric
X-Li-Pop
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Cache-FS-Status
Is-Eu
X-MI-In-Market
X-LI-Proto
X-Passed-To-PostProcessResponse
X-Thanos
X-Swa-Ws
X-TT-LOGID
X-Returned-From-PostProcessResponse
X-Returned-From-BeforeDispatch
X-Returned-From-DLL
X-Secret
X-Sentry-ID
X-Stale
X-Sf
X-SVT-ORM-RULES
X-Server-IP
X-Served-From
X-SVT-ORM-VERSION
X-Returned-From
X-Up
X-Passed-To-BeforeDispatch
X-Passed-To-DLL
X-Passed-To
X-P-T
X-Newrelic-Synthetics
Backend-Name
Adler-Geo
X-Worker
X-VCT
X-Request-UUID
X-WebServer
X-RCS-CacheZone
X-Phone
X-Policy
X-Node-Id
X-Nginx-Cache-Key
Web-Mar-Node
Pagetype
User-Cache-Control
True-Client-Country-4JS
Server-Int
Cache-Cookie-Set-From
X-Bip
X-Core-Mission
X-Crawler
X-Cache-Expires
X-Cache-Debug
X-Block-Status
Request-EU
Request-Country
Magicmarker
MI-Cache
Kp-EeAlive
Cache-Cookie-Set-Idcheck
AKAMAI
MI-Cache-Age
Fastly-Backend-Name
Cache-Cookie-Set-Lfrom
Pragrma
On-Server
Esi-Enabled
X-CUA
X-Actual-URL
X-Fastly-Cache
X-Distributor
X-Device-Os
X-Parent-Response-Time
X-Varnish-Action
X-Fstrz
CDCHOST
X-Cache-CFC
Proxy-Connection
X-Unique-Id-Primal
X-Refresh
X-HOST
X-NODE
X-MSEdge-Flight
X-Owner
V-Cache
X-MSEdge-Features
MI-API
Group
X-Time
MIME-Version
REQUESTUUID
Cteonnt-Length
X-Page-Type
Who
X-Pjax-Url
HTTPS
X-SN
X-Req
RequestId
X-Backend-TTL
Fusion-Source
X-Servername
Fusion-Template-Id
X-Kong-Upstream-Latency
Fusion-Component-Id
X-Be
Fusion-Content-Id
X-Kong-Proxy-Latency
X-Cache-Srv
Fusion-Content-Source
Amp-Access-Control-Allow-Source-Origin
X-GZip
NodeID
X-Ms-Lease-State
Memory
X-Origin-TTL
ProcessTime
X-Edge-Server
Cdn-Request-Time
Cdn-Host
Cdn
X-Servedbyhost
X-Server-Group
CF-IPCountry
Mime-Version
SS
X-Protected-By
X-Content-Age
X-Aicache-OS
SD-X-WS
X-BB-IP
X-Wa
X-Ckpd-Fst-Backend
X-COUNTRY
X-ND-Cache
CDN
GeoIP-Country-Code
A
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
GeoIP-Latitude
X-Origin-Date
X-Origin-Expires
X-SRV
X-Varnish-Beresp-TTL
PageType
X-Origin-Host
Is-Session-Tracking
Get-Access-Time
XServer
X-B3-Traceid
X-Pf-Uncompressing
X-StackifyID
X-APP
PICS-Label
X-Varnish-Url
GeoIp-Country-Code
Serverid
X-Unique-Id
X-Fastly-Country-Code
Geoip-Latitude
Processtime
Node
X-Cache-Info
X-Requestid
X-WA
X-Gdpr
X-PHP-Host
X-CSRF-Token
X-Ratelimit-Remaining
Vix-Hermes-Req-Id
X-Generation-Time
X-Fastly-Cache-Hits
X-RateLimit-Remaining-Second
X-Proxy-Cache-Status
X-RateLimit-Limit-Second
X-Proxy-Upstream
X-Nananana
Nel
Cache-Tv-Group
X-Check-Cacheable
X-FireWall-Port
X-ID
X-Load-Cache
Cf-Ipcountry
X-RequestId
X-UPSTREAM-Address
DataCenter
X-ServedByHost
X-SERVER-NAME
X-BACKEND-TTL
X-Atg-Version
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
X-CS
URI
X-HS-Status
Cache-Provider
X-Server-W
X-Planisys-CDN-Rules
X-EC-Security-Audit
Hostname
X-FORWARDED-FOR
Request-Time
WP-Super-Cache
X-GZIP
X-NGINX-Cache
X-GEO
X-Micro-Cache
T-Server
X-Surge-Debug
PFcat
NGX
X-WR-MODIFICATION
X-Fastly-Backend-Reqs
X-BE
Host-ID
X-Front
X-B3-SpanId
X-HTML-Edge-Cache
X-DataStream-MidMile-RTT
X-HTML-Minification-Powered-By
X-Debug-Cache-Expiry
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-VG-WebCache
X-DataStream-Origin-MEX-Latency
X-Fe
Requestid
Https
X-Cache-Ttl
X-Svr
RequestUuid
X-VarnCache
X-VarnPar1
X-PARISIEN-Cache-Rendered
X-M-Reqid
X-PF-Uncompressing
X-Qnm-Cache
X-GDPR
X-M-Log
X-ServerName
X-FB-TRIP-ID
X-IPS-LoggedIn
X-PJAX-URL
X-Vcache
X-Akamai-SSL-Client-Sid
X-Swift-Error
X-Amz-Meta-S3b-Last-Modified
Ohc-File-Size
Lfy
X-VarnPar2
X-Level-Front-Cache
X-Cdn-Srv
Ohc-Response-Time
X-Instart-Info
X-Generated-On
X-Distil-Cs
X-SB
X-From-Cache
WebServer
X-VC
X-Alicdn-Da-Ups-Status
ServerName
N-Cache
X-PAGE-TYPE
Load-Balancing
Build-Number
X-Serial
X-Dw-Trace-Id
Cdn-Src-Port
X-ARC
X-Grace-Duration
SID
X-Skip-Cache
X-RAMCache
X-Gen-Id
Pics-Label