Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Accept-Ranges
Pragma
X-Powered-By
Link
ETag
CF-RAY
Expect-CT
Via
X-Cache
X-XSS-Protection
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Id
X-Xss-Protection
X-Served-By
P3P
Referrer-Policy
X-Varnish
X-Timer
CF-Cache-Status
X-Request-Id
Access-Control-Allow-Headers
X-AspNet-Version
Access-Control-Allow-Methods
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
P3p
X-Drupal-Cache
X-Check
X-Adblock-Key
Alt-Svc
X-Cacheable
X-Generator
CF-Ray
Content-Security-Policy-Report-Only
X-Amz-Cf-Pop
X-Cache-Status
X-Request-ID
X-AspNetMvc-Version
Status
X-DNS-Prefetch-Control
X-Template
X-Language
Timing-Allow-Origin
Content-Encoding
X-Permitted-Cross-Domain-Policies
X-Iinfo
X-Buckets
X-Content-Security-Policy
X-Turbo-Charged-By
Upgrade
X-Kinja-Server-Push
X-CDN
X-Type
Xkey
Keep-Alive
Access-Control-Expose-Headers
WPE-Backend
X-AH-Environment
X-Pass-Why
Access-Control-Max-Age
X-Backend
X-Cache-Group
X-Server
X-Age
X-Drupal-Dynamic-Cache
X-Pingback
X-Via
X-Nginx-Cache-Status
X-Amz-Id-2
X-Amz-Request-Id
Grace
X-Server-Powered-By
X-Hacker
EagleId
X-UA-Device
X-Robots-Tag
X-LiteSpeed-Cache
X-Varnish-Cache
X-Page-Speed
X-Swift-CacheTime
X-Swift-SaveTime
X-Proxy-Cache
Cf-Railgun
X-Envoy-Upstream-Service-Time
Request-Context
Ali-Swift-Global-Savetime
X-Ua-Compatible
X-Ac
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-WebKit-CSP
X-Cache-Lookup
Content-Location
X-Amz-Version-Id
X-Server-Id
Surrogate-Control
X-Host
X-Node
X-Cnection
X-Readtime
Report-To
EagleEye-TraceId
X-Rq
Server-Timing
X-Response-Time
X-OneAgent-JS-Injection
X-CST
Feature-Policy
X-Rack-Cache
X-Backend-Server
X-ORACLE-DMS-ECID
X-Application-Context
X-Iejgwucgyu
Request-Id
X-Instart-Request-ID
X-Cloud-Trace-Context
X-Clacks-Overhead
NEL
X-Url
Edge-Control
X-DynaTrace
Allow
Rating
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Country
X-Varnish-TTL
X-Origin-Cache
X-FTR-Request-ID
X-Country-Code
X-Cdn
X-B3-TraceId
X-Trace
X-Server-Name
X-Px
X-DataDome
X-Vhost
X-ESI
X-GitHub-Request-Id
X-ORACLE-DMS-RID
X-MS-InvokeApp
X-VARITI-CCR
RTSS
X-Cached
X-Ruxit-JS-Agent
Accept-CH
X-Goog-Hash
SPRequestGuid
Charset
X-Server-ID
Pinterest-Generated-By
X-Vname
X-TtlSet
X-PC
X-Mod-Pagespeed
Public-Key-Pins
X-D2id
X-F-Cache
Verso
X-Dispatcher
X-Cdn-Fetch
X-GoogleNews-Bot
X-Kinja-Revision
X-Kinja-Server
X-Kinja-Build
X-Kinja
X-Exp-Variant
X-Use-Magma
X-Exp-Id
PB-PID
PB-RID
X-Mobile-Rewrite
Arc-Version
X-SharePointHealthScore
X-TTL
X-T
X-Version
X-Powered-By-Plesk
X-DynaTrace-JS-Agent
X-Abt-Application-Version
Accept-CH-Lifetime
X-DIS-Request-ID
X-Powered-CMS
X-Dns-Prefetch-Control
X-Ser
X-Fastly-Request-ID
X-Pinterest-Rid
Pinterest-Version
X-Upstream-Env
X-Origin-Upstream-Status
X-Navigation-Version
X-Forwarded-Proto
X-Shield-Request-Id
X-B
X-Recruiting
X-Client-IP
DynaTrace
MS-Author-Via
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Amz-Rid
Realpath
X-HW
SPIisLatency
SPRequestDuration
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Oneagent-Js-Injection
Content-MD5
X-Upstream
X-Ttl
Nginx-Cache
X-Vcap-Request-Id
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Accel-Buffering
X-Wix-Server-Artifact-Id
X-Amz-Meta-S3cmd-Attrs
AR-CACHE
AR-PoweredBy
Edge-Cache-Tag
AR-ATIME
X-N
X-Hits
Arr-Disable-Session-Affinity
X-Varnish-Age
X-Debug
TCN
X-Oracle-Dms-Rid
Mrf-Cache-Status
X-Mrf-Section-Lastmod
X-NF-Request-ID
X-Mrf-Item-Lastmod
X-B3-TraceId-Primal
MRF-Tech
Access-Control-Request-Method
X-Goog-Storage-Class
X-MSEdge-Ref
X-Acc-Meta-Resource-Type
X-Dw-Request-Base-Id
X-NewRelic-App-Data
X-XRDS-Location
X-Id
S
X-ATG-Version
X-Via-JSL
X-FTR-Balancer
X-FTR-Realm
X-FTR-Cache-Status
Service-Worker-Allowed
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Backend
X-FTR-DC
X-Logged-In
X-FTR-Expires
Tracecode
Alternate-Protocol
Rt-Fastcgi-Cache
X-HS-Hub-Id
X-PressLabs-Stats
X-HS-Content-Id
X-Frontend
X-Content-Digest
X-Kinsta-Cache
Surrogate-Key
X-RateLimit-Remaining
Fastly-Restarts
X-Forwarded-For
AMP-Access-Control-Allow-Source-Origin
X-Pad
X-FastCGI-Cache
MicrosoftSharePointTeamServices
X-Cache-Key
X-Content-Options
Ar-Sid
X-FTR-Cache-Host
Server-Name
X-Ruxit-Js-Agent
X-Amzn-Trace-Id
X-Edge-Location
Fastcgi-Cache
Backend-Timing
X-Analytics
Host
X-CF-Powered-By
FilterID
X-Grace
TP-L2-Cache
TP-Cache
X-Rid
X-Debug-Info
X-Hostname
X-User-Agent
X-IPLB-Instance
ServerID
X-B3-Sampled
X-Whom
X-Magnolia-Registration
X-Cache-2
X-Revision
Eomportal-Instance
X-Request-Received
X-Request-Processing-Time
Paypal-Debug-Id
X-NWS-LOG-UUID
X-Mobile
X-Page-Id
AR-Request-ID
X-Srv
X-HS-Cache-Config
Front-End-Https
X-Akam-SW-Version
X-AOL-HN
X-Content-Powered-By
X-VCache
Retry-After
X-Signature
X-B-Cache
X-Litespeed-Cache
X-FB-Debug
X-Device-Type
X-Cluster
X-LB-Cache
X-Handled-By
X-SS-Set-Cookie
X-Cache-Hit
X-App-Environment
Refresh
Source
X-WA-Info
X-Cache-Control
Cleartype
X-Cache-Action
X-Correlation-Id
X-BCube-Filmed-By
X-Instance
X-Varnish-Hostname
X-Tumblr-User
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Varnish-Grace
X-Platform-Server
X-Framework
X-Request-Guid
X-Fastcgi-Cache
X-Content-Security-Policy-Report-Only
X-Akamai-Edgescape
Webserver
X-Zen-Fury
X-GUploader-UploadID
X-Varnish-Backend
Display
X-Sol
X-Daa-Tunnel
X-Middleton-Display
X-Cache-Server
X-XRDS-LOCATION
X-AppVersion
X-Activity-Id
X-Az
X-Content-Type
X-Varnish-Server
Healthy
X-Drupal-Cache-Tags
X-TA-CDN-Provider
VIX-Pulpo-Upstream-Status
X-Drupal-Cache-Contexts
X-Cache-Rule
VIX-Pulpo-Node
X-Generated-By
X-Wix-Request-Id
X-Geo-Country
X-URL
X-Seen-By
ViewerVersion
X-Cached-By
X-Middleton-Response
S-Cnection
Response
X-App-Server
X-Cache-Age
Server-Node
Cache-Status
X-Origin-Server
X-CACHE-GROUP
X-Accel-Expires
X-Amz-Replication-Status
X-DataStream-Cache-Status
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Node-Name
X-TT
X-Esi
Upgrade-Insecure-Requests
GEO-INFO
X-Response-Served-From
NGB
Payment
Filters
X-RequestSource
X-S
X-UA-Device-Type
Viewport
X-Cacheable-TTL
X-Cache-NE
X-Edge-Cache
X-Edge-Cache-Key
Actual-Object-TTL
X-Varnish-IP
X-Locale
X-Tumblr-Pixel-1
X-FW-Serve
HostName
X-FW-Static
X-FW-Type
X-WPE-Loopback-Upstream-Addr
X-Jobs
X-FW-Hash
X-FW-Server
X-Tumblr-Pixel-2
ServedBy
X-GeoIP
Host-Header
X-TT-TIMESTAMP
X-TX-ID
X-Status
Access-Control-Allow-Method
X-Servedby
X-Amz-Server-Side-Encryption
X-Varnish-Hits
AsisCache
X-Contextid
X-UUID
X-WebKit-CSP-Report-Only
Accept-Charset
Server-Info
X-Storage
Cache
X-Adobe-Loc
X-Adobe-Content
X-Vg-Webcache
SRV
X-PHP-Backend
X-Cache-TTL-Remaining
X-CLOUD-TRACE-CONTEXT
X-Hyper-Cache
X-Cache-Remote
X-Croise-Owner
MS-CV
From-Origin
Cache-Tv-Group
X-HS-Combine-CSS
X-Rendered-As
X-APP-VERSION
X-Cache-Operation
X-App-Version
X-Webkit-CSP
X-Region
DC
Cache-Tag
X-Forwarded-Host
Public-Key-Pins-Report-Only
Served-By
X-Redis-Cache
Liferay-Portal
X-Mode
X-Yottaa-Metrics
X-CACHE-KEY
X-Yottaa-Optimizations
X-Guploader-Uploadid
X-Path-Route
Fastcgi-X-Cache
Fastcgi-Useragent
X-Cache-Var-Map
Selected-FE
X-Is-Bot
X-Endurance-Cache-Level
X-RN-RSRV
X-NGENIX-Cache
Machine
Meta-Geo
Fastcgi-X-Cache-Version
X-Proxy-Build
X-Hosted-By
X-Human
X-Request-Time
X-Upgrade-Enabled
X-Timing-Wait
X-Akamai-Request-ID2
X-Site-Version
X-Webstats-RespID
X-Generated
X-Cache-Var
X-Detected-As
Xserver
TWC-GeoIP-Country
TWC-Device-Class
X-Routing-Service
X-BYPASS-REASON
X-CDN-Cache
X-Environment-Context
TWC-GeoIP-LatLong
X-Loop
Now
Property-Id
Origin-Edge-Control
X-Format
TWC-Locale-Group
X-Cache-Category-Id
TWC-Connection-Speed
X-Grey
Origin-Cache-Control
X-Agile-Id
X-Zipkin-Id
X-Original-Request
X-Origin-Hint
X-Agile
Webcakes-App-Version
Cache-Name
Webcakes-Region
X-Proxied
X-ProxyCache-Status
X-Agile-Age
X-Internal-Host
Webcakes-App-Name
X-TNCMS
X-ProxyCache-Key
X-NCache
X-L-Path
X-Via-Fastly
X-Vgn-Hpd-Reason
X-JoinUs
X-Labrador-Cache-Channel
TWC-Privacy
Powered-By-ChinaCache
X-Akamai-Transformed
X-OCL
Pagespeed
X-Pc-Appver
X-Pc-Hit
X-UA
X-FC-Vary-Parameters
X-Access
Datacenter
X-Birta-Cache-Post
X-Birta-Served
X-Pc-Key
X-PCL
X-Viewer-Country
X-Tumblr-Pixel-3
X-Upstream-CT
X-Upstream-HT
X-Web-Node
X-Time-Microsecs
X-Section
X-ProcessESI
X-Proxy
X-Pubstack
X-RemovedCookies
S-Rt
X-Origin-Host
DB-Nickname
Cache-Tags
X-Backend-Name
X-Via-CDN
X-Xfnlog-Site
X-Rule
X-Origin-CC
X-CCM
X-IP
X-Cache-Config
X-Ocache
X-B3-Spanid
X-Www-Served-By
X-Akamai-Request-ID
X-ServerID
X-Origin
X-Origin-Response-Time
X-VG-TLSProxy
X-Tb
Azure-RegionName
Mn-Server-Ip
X-RateLimit-Limit
Azure-SiteName
Azure-InstanceId
Azure-SlotName
HitType
Azure-Version
X-TIME
OT-Force-Account-Verify
X-ShardId
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Shopify-Stage
X-ShopId
X-App-Name
Accept-Language
X-Alternate-Cache-Key
X-Nginx-Cache
X-Cache-TTL
Cache-Key
X-Ezoic-Cdn
X-Parent-Response-Time
X-Protected-By
X-Edge-IP
X-OVcl
X-OVcl-Cache
Vix-Hermes-Req-Id
User-Cache-Control
X-Real-Ip
Content-Style-Type
Content-Script-Type
L5d-Success-Class
X-BACKEND-TTL
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Time
NtCoent-Length
LB
X-Newrelic-App-Data
X-Amz-Meta-Surrogate-Control
X-RTag
X-ApacheServer
X-PERF
Ms-Operation-Id
X-Cache-Backend
X-Webkit-Csp
X-Proto
X-Front
X-Correlation-ID
X-Pc-Host
X-Real-IP
X-Pc-Date
X-GRACE
X-Unique-Id-Primal
X-Mrs-Age
X-Mrs-Cache-Hits
X-Mrs-Cache
X-Mshield-Cache-Status
X-Nc
X-Cdn-Forward
X-FB-TRIP-ID
X-Hit
X-Dynatrace-Js-Agent
X-Varnish-Cacheable
X-CDN-Forward
X-Varnish-Beresp-Status
X-Content-Age
X-Debug-Cache
X-Varnish-Beresp-Grace
Section-Io-Cache
X-Sucuri-ID
AR-SID
X-Unique-ID
X-Microcachable
WZWS-RAY
X-Time
Version
X-Trace-Id
X-C
Fusion-Template-Id
X-Dc
Fusion-Content-Id
Fusion-Component-Id
Country
Fusion-Content-Source
Fusion-Source
Access-Control-Request-Headers
Load-Balancing
X-Cache-Enabled
X-Connection-Hash
X-Varnish-Beresp-Ttl
Ohc-File-Size
X-EdgeConnect-Cache-Status
X-Transaction
X-MP-GENERATED-AT
X-Twitter-Response-Tags
We-Hiring
Mail-Subject
Warning
X-D
X-CF-Lambda-Fn
Viewtype
X-Cache-Id
X-Cache-URL
X-A
X-BB-ID
X-B-Cookie
VivaBuild
X-Clientip
X-Crawler
X-CUA
MD5-Digest
Platform
X-A-Ccd
X-Bip
X-CF-Lambda-Version
X-A-Dam
Server-Host
Memcached
Powered-By
X-Accel-Expires-Debug
Is-Eu
Rt-Proxy-Cache
RNT-Time
X-A-Wwc
Locale
X-Actual-URL
X-Auto-Login
X-Application
X-Aed
X-Cache-Debug
X-Cache-Bucket
Mobile-Detection-Method
Node
Rendered-Blocks
Release
Server-ID
X-A-Dgt
Meta-Geo-Continent
V-Age
RNT-Machine
X-Cache-Host
Resin-Trace
X-Cache-FS-Status
X-Passed-To-BeforeDispatch
X-ScT
X-S-Maxage
X-Served-From
X-Server-By
X-SRCache-Key
X-Server-Time
X-S-Cookie
X-Rojux
X-Returned-From
X-Release
X-Returned-From-BeforeDispatch
X-Returned-From-DLL
X-Rewrite-Enabled
X-Returned-From-PostProcessResponse
X-Store
X-Thanos
X-Via-Edge
X-VG-WebServer
X-Via-SSL
X-We-Are-Hiring
Xc-Version
X-WebServer
X-Varnish-Action
X-Variation
X-UE-Client-Country
X-Trv-Group
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Var-Ttl
X-User
X-Region-Sid
X-Reboot
X-From
X-Fetched-On
X-FW-Version
X-G
X-GeoIP-Country-Code
X-Generated-In
X-F5-Cache
X-External-Request-Id
X-Developer
X-Destination
X-Device-Os
X-Died
X-DPWN-IS-SECURE
X-Dispatcher-Server
X-Layer
X-Logtrace-Id
X-PHP-Host
X-PAYTM-SRV-ID
X-Qloud-Router
X-RCS-CacheZone
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Passed-To-PostProcessResponse
X-Passed-To-DLL
X-NU-AKA-ACS-Version
X-Node-Id
X-Org
X-Passed-To
IBM-Web2-Location
X-Date
X-A-Dcw
X-Ua
Ec-Rule-Version
Fastly-SIE
X-Ratelimit-Limit
Frame-Options
Fastly-SWR
Fly-Cache
Fly-Request-Id
Countrycode
X-Hl-Ver
Arc-Country
BehaviorPad-Version
Ajk
Adler-Geo
Cache-Prefix
Fastly-Backend-Name
X-Rocket-Nginx-Bypass
X-Li-Fabric
X-Li-Pop
X-IN-APIGATEWAY
X-IN-WAF
X-IN-SSL-APIGATEWAY
X-Info
X-Key
X-Hash
X-Backend-State
X-Amz-Meta-Cache-Control
AKAMAI
Apple-News-Services-Handled
X-Block-Status
X-CGP
X-Gen-Mode
X-Eu-Site
X-Epic-Correlation-Id
User-Agent
X-Hnp-Log
X-No-Session
Origin
Thinkindot-CacheControl
X-V
X-UnsetCookies
X-SVT-ORM-VERSION
Thinkindot-CacheControl-Type
Thinkindot-Control
X-Swa-Ws
X-Thinkindot-L3
X-Matched-Rule
X-Cache-Expires
Www
X-SVT-ORM-RULES
X-Stale
Apple-News-Services-Host
X-Proxy-Cache-Status
X-MI-In-Market
X-Location
X-LI-UUID
X-Proxy-Upstream
X-Request-Start
X-ServiceProvider
X-Sf
X-Server-Group
X-Response-By
X-Request-UUID
X-LI-Proto
X-Server-IP
SS
GW-Server
Esi-Enabled
Pragrma
HA-Cloudapp
HA-Geocity
True-Client-Country-4JS
HA-Geolat
HA-Geocountry
On-Server
Pramga
Proxy-Connection
Decoy-Debug-Key
Content-Disposition
Country-Code
SD-X-WS
Decoy-Debug-Status
Request-EU
Decoy-Debug-TTL
Request-Country
GMS-Ver
HA-Georegion
HA-Geolon
Uber-Trace-Id
HA-Host
MI-Cache-Age
Ha-Gx-Prefs
MI-Cache
MI-API
Backend-Name
HA-Urlpath
HA-Ipaddr
UCS
Kp-EeAlive
Heartbleed
Apple-News-Services-Request-Url
Backend
Apple-News-Services-Parsed-Url
Web-Mar-Node
Who
HA-Servedtime
X-Be
X-NODE
REQUESTUUID
X-Instance-Name
X-Irp-Debug
X-Secret
Fastly-Soc-X-Request-Id
Cache-Cookie-Set-Idcheck
X-Wikidot-Backend
IsBot
X-NWS-UUID-VERIFY
X-Policy
X-Platform
X-Gannett-Site-Version
X-Wikidot-Static-Cache
X-Core-Value
X-Request-URI
X-Via-NSCOPI
X-SIPLIST1
Cache-Cookie-Set-From
X-Distil-CS
X-TT-LOGID
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Phone
X-P-T
X-Developers
Cache-Cookie-Set-Lfrom
X-Nginx-Cache-Key
CDCHOST
Server-Int
X-Backend-Url
X-Backend-Host
X-Cache-CFC
Request-Time
X-Geo
V-Cache
Group
X-Debug-Cookies
X-Debug-Log
X-Origin-Date
X-Sn-Servicetimems
X-Up
X-Refresh
PFcat
X-VCT
X-Cdn-Origin
HitInfo
X-Origin-Expires
X-GeoIP-City
X-Fstrz
X-Core-Mission
X-Distributor
X-Origin-TTL
Magicmarker
Fastly-SSL
X-MSEdge-Features
X-ElasticPress-Search
X-MSEdge-Flight
X-NX-Host
X-Page-Type
X-Planisys-CDN-Cache
X-Servername
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-COUNTRY
X-Fastly-Cache
X-DC
RequestId
Pagetype
X-VarnPar1
X-Newrelic-Synthetics
X-Debug-Cache-Fetch
X-VarnCache
Host-ID
X-Pjax-Url
X-Debug-Cache-Expiry
X-Micro-Cache
X-Svr
X-Req
X-PARISIEN-Cache-Rendered
X-Debug-Cache-Store
PageSpeed
X-Level-Front-Cache
X-Generated-On
X-Instart-Info
X-NC
X-CACHE-AGE
X-BBXSRF
X-Powered-By-ANYU
X-EIG-Tracking-Id
ServerName
Lfy
MIME-Version
X-Datadome
Mime-Version
X-Server-Cache
X-Cache-Info
Ohc-Response-Time
Cache-Provider
X-Cdn-Srv
Cdn
X-ARC
Cteonnt-Length
X-Gdpr
PICS-Label
Memory
X-TWH-CORRELATION-ID
X-Servedbyhost
X-Cluster-Node
Nel
X-CMS-Context
X-StackifyID
X-Wa
CF-IPCountry
X-Aicache-OS
FSS-Proxy
X-LAGOON
FSS-Cache
X-NodeID
X-Sentry-ID
X-Fastly-Country-Code
X-Load-Cache
X-HTML-Minification-Powered-By
CDN
X-Flog
NGX
X-Hello
X-WR-MODIFICATION
GeoIP-Latitude
X-VServer
GeoIP-Country-Code
X-ABtesting
X-B3-Traceid
X-Fastly-Backend-Reqs
XServer
GeoIp-Country-Code
SN
X-CSRF-TOKEN
Geoip-Latitude
X-Check-Cacheable
X-Varnish-Beresp-TTL
X-WA
X-UPSTREAM-Address
X-GZip
Cf-Ipcountry
Processtime
X-APP
X-Source
Amp-Access-Control-Allow-Source-Origin
TSSecure
X-Csrf-Token
X-CSRF-Token
X-Worker
X-DataStream-Origin-MEX-Latency
X-FORWARDED-FOR
X-MServer
X-DataStream-MidMile-RTT
X-HOST
X-FireWall-Port
X-Unique-Id
CACHE
X-Ratelimit-Remaining
PageType
X-Sedo-Request-Id
A
X-ServedByHost
WP-Super-Cache
X-CDN-Pop-IP
X-CDN-Pop
X-RateLimit-Remaining-Second
X-Cache-Miss-From
X-RateLimit-Limit-Second
X-Generation-Time
X-Varnish-Cache-Hits
Pics-Label
X-GDPR
X-Dynatrace
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
X-Nananana
X-AWS-Id
X-LJ-Flow-ID
X-SplitTest
X-VWS-Id
X-Oss-Object-Type
X-Edge-Server
Cdn-Request-Time
Cdn-Host
X-Port
X-SRV
X-VC-Cache
HTTPS
X-Cache-Grace
URI
X-Skip-Cache
X-ID
DataCenter
X-Backend-TTL
X-Sucuri-Cache
Server-Cache-Control
X-IPS-LoggedIn
Server-Surrogate-Control
X-Cache-ASPX
Odigeo-Trace-Id
X-Varnish-Authentication
Cache-Hits
X-RCS-Backend
X-Fastly-Cache-Hits
X-HS-Status
X-B3-SpanId
X-Owner
X-Ms-Blob-Type
X-Ms-Request-Id
X-Ms-Version
X-Swift-Error
X-BE
X-Ms-Lease-Status
Hostname
X-Varnish-Url
X-PJAX-URL
Dynatrace
ProcessTime
X-Gen-Id
X-Bug-Bounty
X-VG-WebCache
X-SN
X-Amzn-Remapped-Connection
X-GZIP
X-Instart-Isnd
X-Amzn-Remapped-Date
X-From-Cache
X-ND-Cache
X-ORIG-AKA-EDGE
Is-Session-Tracking
Requestid
X-Pf-Uncompressing
X-Server-W
X-NGINX-Cache
X-Ms-Lease-State
X-Cache-Ttl
X-GoCache-CacheStatus
X-VarnPar2
Get-Access-Time
X-Akamai-SSL-Client-Sid
X-Amz-Meta-S3b-Last-Modified
Serverid
X-Alicdn-Da-Ups-Status
X-LiteSpeed-Cache-Control
X-PAGE-TYPE
X-Varnish-URL
Proxy-Firewall
X-GEO
X-RAMCache
X-Fe
WebServer
X-Serial
X-ServerName
X-VC
X-SB
RequestUuid
X-Cache-Srv
T-Server
X-ORIG-AKA-COUNTRY-CODE
X-PF-Uncompressing
SID
Xet-Cookie
X-HTML-Edge-Cache
Powered
NodeID
X-Akamai-ERPolicy
X-CS
X-Developed-By
Location
X-Akamai-ERRuleID
NnCoection
X-Dw-Trace-Id
X-LiteSpeed-Tag