Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Accept-Ranges
Pragma
X-Powered-By
Link
ETag
CF-RAY
Expect-CT
Via
X-Cache
X-XSS-Protection
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Id
X-Xss-Protection
X-Served-By
P3P
Referrer-Policy
X-Varnish
X-Timer
X-Request-Id
CF-Cache-Status
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
P3p
X-Drupal-Cache
X-Check
X-Adblock-Key
Alt-Svc
X-Cacheable
X-Amz-Cf-Pop
X-Generator
CF-Ray
Content-Security-Policy-Report-Only
X-Cache-Status
X-AspNetMvc-Version
X-DNS-Prefetch-Control
Status
X-Template
X-Language
Timing-Allow-Origin
Content-Encoding
X-Permitted-Cross-Domain-Policies
X-Iinfo
X-Request-ID
X-Buckets
X-Content-Security-Policy
X-Turbo-Charged-By
Upgrade
X-Kinja-Server-Push
X-CDN
X-Type
Xkey
Keep-Alive
Access-Control-Expose-Headers
WPE-Backend
Access-Control-Max-Age
X-Pass-Why
X-AH-Environment
X-Backend
X-Cache-Group
X-Server
X-Age
X-Drupal-Dynamic-Cache
X-Pingback
X-Via
X-Nginx-Cache-Status
X-Amz-Id-2
X-Amz-Request-Id
Grace
X-Server-Powered-By
X-Hacker
EagleId
X-UA-Device
X-Robots-Tag
X-LiteSpeed-Cache
X-Varnish-Cache
X-Page-Speed
X-Swift-CacheTime
X-Swift-SaveTime
X-Proxy-Cache
Cf-Railgun
Request-Context
X-Envoy-Upstream-Service-Time
Ali-Swift-Global-Savetime
X-Ua-Compatible
X-Ac
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-WebKit-CSP
X-Cache-Lookup
Content-Location
X-Server-Id
X-Amz-Version-Id
Surrogate-Control
X-Host
X-Cnection
X-Node
X-Readtime
Report-To
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Rq
Server-Timing
X-Response-Time
Feature-Policy
X-CST
X-Rack-Cache
X-Backend-Server
X-Application-Context
X-ORACLE-DMS-ECID
X-Iejgwucgyu
Request-Id
X-Cloud-Trace-Context
X-Instart-Request-ID
X-Clacks-Overhead
NEL
Edge-Control
X-DynaTrace
Allow
Rating
X-Url
X-Country
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Varnish-TTL
X-Origin-Cache
X-FTR-Request-ID
X-Country-Code
X-Trace
X-DataDome
X-Server-Name
X-Px
X-Vhost
X-B3-TraceId
X-ESI
X-GitHub-Request-Id
X-ORACLE-DMS-RID
X-VARITI-CCR
X-MS-InvokeApp
RTSS
X-Ruxit-JS-Agent
X-Cached
Accept-CH
X-Goog-Hash
Charset
SPRequestGuid
X-Server-ID
X-PC
X-TtlSet
X-Vname
X-Mod-Pagespeed
X-D2id
Public-Key-Pins
X-F-Cache
Verso
Pinterest-Generated-By
X-Kinja-Revision
X-Use-Magma
X-Kinja-Build
X-Kinja-Server
X-GoogleNews-Bot
X-Cdn-Fetch
X-Exp-Id
X-Exp-Variant
X-Kinja
X-Dispatcher
PB-RID
X-Mobile-Rewrite
Arc-Version
PB-PID
X-TTL
X-SharePointHealthScore
X-Version
X-T
X-Cdn
X-Powered-By-Plesk
X-Abt-Application-Version
Accept-CH-Lifetime
X-DIS-Request-ID
X-Powered-CMS
X-DynaTrace-JS-Agent
X-Ser
X-Fastly-Request-ID
X-Pinterest-Rid
X-Upstream-Env
Pinterest-Version
X-Origin-Upstream-Status
X-Navigation-Version
X-Shield-Request-Id
X-B
X-Forwarded-Proto
X-Client-IP
X-Recruiting
MS-Author-Via
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Amz-Rid
DynaTrace
Realpath
X-HW
SPRequestDuration
SPIisLatency
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Upstream
X-Vcap-Request-Id
Content-MD5
X-Ttl
Nginx-Cache
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Accel-Buffering
X-Wix-Server-Artifact-Id
X-Amz-Meta-S3cmd-Attrs
AR-PoweredBy
AR-CACHE
AR-ATIME
Edge-Cache-Tag
X-Oneagent-Js-Injection
X-N
Arr-Disable-Session-Affinity
X-Hits
X-Varnish-Age
X-Debug
X-Oracle-Dms-Rid
TCN
X-B3-TraceId-Primal
X-Aspnet-Version
MRF-Tech
X-Mrf-Item-Lastmod
Mrf-Cache-Status
X-Goog-Storage-Class
X-Mrf-Section-Lastmod
X-NF-Request-ID
X-MSEdge-Ref
Access-Control-Request-Method
X-Acc-Meta-Resource-Type
X-NewRelic-App-Data
X-Dw-Request-Base-Id
X-Id
X-XRDS-Location
S
X-ATG-Version
X-Via-JSL
X-FTR-Realm
X-FTR-Cache-Status
X-FTR-Balancer
X-FTR-DC
X-Country-Code-Real
X-FTR-Backend-Server
X-FTR-Backend
Service-Worker-Allowed
X-Logged-In
X-FTR-Expires
X-Dns-Prefetch-Control
Alternate-Protocol
X-HS-Content-Id
Tracecode
Rt-Fastcgi-Cache
X-HS-Hub-Id
X-Forwarded-For
X-PressLabs-Stats
X-Frontend
X-Kinsta-Cache
X-Content-Digest
Surrogate-Key
AMP-Access-Control-Allow-Source-Origin
X-FastCGI-Cache
X-Pad
Fastly-Restarts
MicrosoftSharePointTeamServices
X-RateLimit-Remaining
X-Cache-Key
X-FTR-Cache-Host
X-Content-Options
X-Ruxit-Js-Agent
X-Edge-Location
Server-Name
Fastcgi-Cache
Ar-Sid
X-CF-Powered-By
X-Amzn-Trace-Id
Backend-Timing
X-Analytics
FilterID
X-Grace
Host
TP-Cache
TP-L2-Cache
X-Rid
X-Hostname
X-Whom
X-User-Agent
X-Debug-Info
X-Magnolia-Registration
X-IPLB-Instance
ServerID
X-Cache-2
X-Revision
X-B3-Sampled
Eomportal-Instance
X-Request-Received
X-Request-Processing-Time
X-Page-Id
X-Mobile
Paypal-Debug-Id
X-NWS-LOG-UUID
AR-Request-ID
X-Srv
Front-End-Https
X-Akam-SW-Version
X-AOL-HN
X-VCache
X-Content-Powered-By
X-URL
X-HS-Cache-Config
Retry-After
X-Litespeed-Cache
X-B-Cache
X-Signature
X-Cluster
X-SS-Set-Cookie
Source
Refresh
X-Device-Type
X-Cache-Action
X-Handled-By
X-LB-Cache
X-FB-Debug
X-WA-Info
Cleartype
X-Correlation-Id
X-Request-Guid
X-Cache-Hit
X-App-Environment
X-Framework
X-Cache-Control
X-Varnish-Grace
X-Instance
X-Varnish-Hostname
X-Tumblr-User
X-Platform-Server
X-BCube-Filmed-By
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Fastcgi-Cache
X-Content-Security-Policy-Report-Only
X-Akamai-Edgescape
X-GUploader-UploadID
Webserver
X-Zen-Fury
X-Varnish-Backend
X-Middleton-Display
Display
X-Sol
X-Az
X-XRDS-LOCATION
X-AppVersion
X-Activity-Id
X-Daa-Tunnel
X-Content-Type
X-Cache-Server
Healthy
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Cache-Rule
X-Varnish-Server
X-Wix-Request-Id
X-Drupal-Cache-Tags
Response
ViewerVersion
X-Middleton-Response
X-Seen-By
X-Drupal-Cache-Contexts
X-Generated-By
X-Cache-Age
X-Cached-By
X-Geo-Country
X-App-Server
S-Cnection
Server-Node
Cache-Status
X-TT
X-Origin-Server
X-Accel-Expires
X-Amz-Replication-Status
X-DataStream-Cache-Status
X-CACHE-GROUP
Upgrade-Insecure-Requests
X-Esi
X-Amzn-RequestId
X-Amz-Apigw-Id
Payment
X-S
X-RequestSource
X-UA-Device-Type
GEO-INFO
NGB
X-TA-CDN-Provider
Filters
X-Response-Served-From
X-Node-Name
X-Locale
X-Cacheable-TTL
X-Edge-Cache
X-Contextid
X-Varnish-IP
X-Cache-NE
ServedBy
Viewport
Accept-Charset
X-Status
Actual-Object-TTL
X-Servedby
X-Edge-Cache-Key
X-FW-Static
X-Jobs
X-TT-TIMESTAMP
X-Varnish-Hits
Access-Control-Allow-Method
X-FW-Type
X-FW-Server
X-FW-Hash
X-FW-Serve
X-Tumblr-Pixel-1
X-Tumblr-Pixel-2
AsisCache
X-UUID
X-GeoIP
X-Amz-Server-Side-Encryption
X-TX-ID
X-Adobe-Loc
Server-Info
X-Adobe-Content
X-WebKit-CSP-Report-Only
HostName
X-WPE-Loopback-Upstream-Addr
Host-Header
X-Storage
Cache
X-PHP-Backend
X-Rendered-As
Cache-Tv-Group
X-Cache-TTL-Remaining
X-Cache-Remote
SRV
MS-CV
X-Croise-Owner
From-Origin
X-Vg-Webcache
X-Hyper-Cache
X-Cache-Operation
X-App-Version
X-Region
X-APP-VERSION
X-Webkit-CSP
X-HS-Combine-CSS
X-Redis-Cache
Served-By
Cache-Tag
Public-Key-Pins-Report-Only
Liferay-Portal
DC
X-Forwarded-Host
X-Guploader-Uploadid
X-CACHE-KEY
X-Mode
X-Upgrade-Enabled
Fastcgi-X-Cache
Fastcgi-X-Cache-Version
X-Agile-Age
X-Request-Time
X-TNCMS
Fastcgi-Useragent
X-Webstats-RespID
Meta-Geo
X-RN-RSRV
X-Akamai-Transformed
X-Endurance-Cache-Level
X-Site-Version
Selected-FE
X-Agile-Id
X-Timing-Wait
X-Agile
Machine
X-Proxy-Build
X-Cache-Var-Map
X-Cache-Var
X-Loop
X-NGENIX-Cache
X-Detected-As
X-Is-Bot
X-Generated
X-Hosted-By
X-Human
X-IP
X-Path-Route
Pagespeed
X-Yottaa-Metrics
X-Yottaa-Optimizations
Xserver
TWC-GeoIP-Country
TWC-Device-Class
X-ProxyCache-Status
TWC-GeoIP-LatLong
X-JoinUs
TWC-Connection-Speed
Cache-Name
Property-Id
X-Environment-Context
X-ProxyCache-Key
X-Grey
Now
Origin-Cache-Control
X-L-Path
Origin-Edge-Control
X-Internal-Host
X-CDN-Cache
X-Origin-Hint
X-Cache-Category-Id
X-Vgn-Hpd-Reason
X-BYPASS-REASON
X-Original-Request
X-Upstream-HT
X-Upstream-CT
X-Pc-Hit
X-NCache
X-Via-Fastly
X-Web-Node
X-Pc-Key
TWC-Privacy
Webcakes-App-Name
Webcakes-App-Version
X-Labrador-Cache-Channel
Webcakes-Region
X-Format
X-Pc-Appver
TWC-Locale-Group
X-B3-Spanid
Powered-By-ChinaCache
X-PCL
X-ProcessESI
X-Akamai-Request-ID
X-Viewer-Country
X-Pubstack
X-Proxy
X-Access
X-Section
X-Tumblr-Pixel-3
X-FC-Vary-Parameters
X-Time-Microsecs
X-RemovedCookies
S-Rt
X-UA
X-Origin-Host
X-VG-TLSProxy
X-Birta-Served
X-OCL
X-Origin-Response-Time
X-Birta-Cache-Post
DB-Nickname
Cache-Tags
X-Origin
Datacenter
X-Cache-Config
X-Via-CDN
X-Rule
X-Backend-Name
X-CCM
X-Www-Served-By
Azure-RegionName
X-Xfnlog-Site
Mn-Server-Ip
X-Origin-CC
X-ServerID
X-Tb
Azure-SlotName
Azure-Version
Azure-SiteName
Azure-InstanceId
X-Ocache
X-Routing-Service
X-Zipkin-Id
X-Akamai-Request-ID2
HitType
X-Proxied
X-CLOUD-TRACE-CONTEXT
X-TIME
Cache-Key
X-Parent-Response-Time
X-App-Name
OT-Force-Account-Verify
X-Nginx-Cache
X-Sorting-Hat-ShopId
X-BACKEND-TTL
X-Cache-TTL
X-Protected-By
X-ShardId
X-Alternate-Cache-Key
X-Sorting-Hat-PodId
X-Shopify-Stage
X-ShopId
X-Edge-IP
Content-Style-Type
X-RateLimit-Limit
User-Cache-Control
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Vix-Hermes-Req-Id
X-Dynatrace-Js-Agent
Content-Script-Type
X-Ezoic-Cdn
Accept-Language
X-OVcl-Cache
X-OVcl
L5d-Success-Class
Time
X-Real-IP
NtCoent-Length
X-Pc-Host
X-Pc-Date
Ms-Operation-Id
X-RTag
X-ApacheServer
X-Newrelic-App-Data
X-PERF
X-Cache-Backend
LB
X-Cdn-Forward
X-Real-Ip
X-Amz-Meta-Surrogate-Control
X-Front
X-Webkit-Csp
AR-SID
X-Proto
X-Correlation-ID
X-GRACE
X-Mrs-Cache
X-Unique-Id-Primal
X-Mshield-Cache-Status
X-Mrs-Cache-Hits
X-Mrs-Age
X-FB-TRIP-ID
X-Nc
X-Content-Age
Section-Io-Cache
X-Varnish-Cacheable
X-CDN-Forward
X-Varnish-Beresp-Grace
X-Debug-Cache
X-Varnish-Beresp-Status
X-Hit
X-Sucuri-ID
Country
Load-Balancing
WZWS-RAY
X-Unique-ID
X-Ratelimit-Limit
Fusion-Source
Fusion-Template-Id
X-Microcachable
Ohc-File-Size
Fusion-Content-Source
Fusion-Component-Id
X-Trace-Id
Fusion-Content-Id
X-Time
X-Hl-Ver
Version
X-MP-GENERATED-AT
X-C
Mail-Subject
Access-Control-Request-Headers
X-Dc
X-EdgeConnect-Cache-Status
X-Varnish-Beresp-Ttl
We-Hiring
X-Transaction
X-Twitter-Response-Tags
X-Connection-Hash
Warning
X-Cache-Enabled
Meta-Geo-Continent
Mobile-Detection-Method
X-Date
Memcached
MD5-Digest
X-CUA
Is-Eu
X-Crawler
X-Clientip
X-D
X-CF-Lambda-Version
X-Cache-URL
X-Auto-Login
Thinkindot-Control
V-Age
Viewtype
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
Server-ID
SS
X-B-Cookie
VivaBuild
X-Application
X-A-Dcw
X-A-Dgt
X-Accel-Expires-Debug
X-A-Dam
X-A-Ccd
Www
X-Aed
X-Actual-URL
Server-Host
X-Backend-State
Resin-Trace
X-A-Wwc
X-Cache-Id
RNT-Machine
Rendered-Blocks
Release
X-CF-Lambda-Fn
Platform
Powered-By
RNT-Time
X-Cache-Host
X-Bip
X-BB-ID
SD-X-WS
Rt-Proxy-Cache
X-Cache-Bucket
X-Cache-FS-Status
X-Cache-Expires
X-Cache-Debug
Node
X-Passed-To-BeforeDispatch
X-S-Maxage
X-S-Cookie
X-Rojux
X-ScT
X-Served-From
X-Server-Time
X-Server-By
X-Rewrite-Enabled
X-Returned-From-PostProcessResponse
X-Request-UUID
X-Release
X-Region-Sid
X-Response-By
X-Returned-From
X-Returned-From-DLL
X-Returned-From-BeforeDispatch
X-SRCache-Key
X-Store
X-Via-Edge
X-VG-WebServer
X-Varnish-Action
X-Via-SSL
X-We-Are-Hiring
Xc-Version
X-WebServer
X-Variation
X-Var-Ttl
X-Thanos
X-Swa-Ws
X-Thinkindot-L3
X-Trv-Group
X-User
X-UE-Client-Country
X-Reboot
X-Rebelmouse-Surrogate-Control
X-G
X-FW-Version
X-From
X-Generated-In
X-GeoIP-Country-Code
X-Li-Fabric
X-Layer
X-Fetched-On
X-F5-Cache
X-Device-Os
X-Developer
X-Died
X-Dispatcher-Server
X-External-Request-Id
X-DPWN-IS-SECURE
X-Li-Pop
X-LI-Proto
X-PAYTM-SRV-ID
X-Passed-To-PostProcessResponse
X-Passed-To-DLL
X-PHP-Host
X-Qloud-Router
X-Rebelmouse-Cache-Control
X-RCS-CacheZone
IBM-Web2-Location
X-Passed-To
X-Logtrace-Id
X-LI-UUID
X-Matched-Rule
X-Node-Id
X-Org
X-NU-AKA-ACS-Version
X-Destination
X-A
Fastly-Backend-Name
Ec-Rule-Version
Fastly-SIE
Fly-Cache
Fly-Request-Id
Countrycode
Cache-Prefix
Adler-Geo
User-Agent
Ajk
Arc-Country
BehaviorPad-Version
Frame-Options
Fastly-SWR
X-Ua
X-Info
Backend-Name
HA-Urlpath
Backend
X-IN-WAF
Apple-News-Services-Request-Url
X-IN-SSL-APIGATEWAY
HA-Servedtime
X-Key
Decoy-Debug-Key
Decoy-Debug-Status
Decoy-Debug-TTL
HA-Ipaddr
X-Location
X-Amz-Meta-Cache-Control
Content-Disposition
Country-Code
X-Block-Status
Apple-News-Services-Parsed-Url
X-TT-LOGID
X-CGP
Request-Time
X-Gannett-Site-Version
Heartbleed
X-Epic-Correlation-Id
X-P-T
X-Eu-Site
X-Gen-Mode
X-Hash
AKAMAI
Apple-News-Services-Handled
Apple-News-Services-Host
Kp-EeAlive
X-Request-Start
X-Hnp-Log
X-IN-APIGATEWAY
On-Server
MI-API
X-Server-IP
X-Proxy-Cache-Status
X-Proxy-Upstream
HA-Geocity
HA-Cloudapp
X-ServiceProvider
GMS-Ver
GW-Server
X-Server-Group
HA-Geocountry
HA-Georegion
X-Secret
Origin
HA-Geolon
Pragrma
HA-Geolat
Proxy-Connection
Pramga
X-Sf
X-Stale
MI-Cache
X-MI-In-Market
X-No-Session
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Via-NSCOPI
Web-Mar-Node
MI-Cache-Age
Esi-Enabled
X-UnsetCookies
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Rocket-Nginx-Bypass
Ha-Gx-Prefs
True-Client-Country-4JS
HA-Host
Who
X-NODE
X-Geo
X-Be
Cache-Cookie-Set-From
Cache-Cookie-Set-Idcheck
CDCHOST
X-Wikidot-Static-Cache
X-Wikidot-Backend
Request-EU
X-Irp-Debug
Locale
PFcat
X-Backend-Url
X-Backend-Host
X-Instance-Name
Fastly-Soc-X-Request-Id
REQUESTUUID
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
X-SIPLIST1
X-Page-Type
X-Platform
X-Urbn-Context-Path
X-V
X-Policy
UCS
Uber-Trace-Id
X-Urbn-Site-Id
Cache-Cookie-Set-Lfrom
Request-Country
X-MSEdge-Flight
X-Distributor
X-Developers
X-Distil-CS
X-MSEdge-Features
X-Nginx-Cache-Key
X-Origin-Expires
IsBot
X-Fstrz
X-Phone
X-Cache-CFC
X-Origin-Date
Fastly-SSL
Server-Int
Magicmarker
X-Up
X-Request-URI
X-Core-Value
Pagetype
X-NX-Host
X-Servername
X-Origin-TTL
X-Debug-Cookies
X-NWS-UUID-VERIFY
X-Core-Mission
X-Refresh
X-Sn-Servicetimems
X-Debug-Log
X-Fastly-Cache
X-ElasticPress-Search
X-Cdn-Origin
V-Cache
Group
RequestId
X-COUNTRY
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Svr
X-Debug-Cache-Expiry
X-Micro-Cache
X-GeoIP-City
X-DC
X-VCT
HitInfo
X-Generated-On
X-VarnPar1
Host-ID
X-Req
X-Level-Front-Cache
X-Instart-Info
X-Pjax-Url
X-VarnCache
X-PARISIEN-Cache-Rendered
PageSpeed
X-Newrelic-Synthetics
ServerName
X-NC
Lfy
X-CACHE-AGE
X-Server-Cache
X-Cdn-Srv
Ohc-Response-Time
X-Cache-Info
X-BBXSRF
MIME-Version
Mime-Version
X-Powered-By-ANYU
X-Datadome
X-ARC
Cache-Provider
X-B3-Traceid
X-EIG-Tracking-Id
Cdn
Memory
Cteonnt-Length
PICS-Label
X-Gdpr
X-TWH-CORRELATION-ID
X-Servedbyhost
X-CMS-Context
Nel
X-LAGOON
X-Cluster-Node
X-Wa
X-WR-MODIFICATION
CF-IPCountry
NGX
X-StackifyID
X-Fastly-Country-Code
X-Aicache-OS
X-Load-Cache
X-HTML-Minification-Powered-By
X-NodeID
GeoIP-Country-Code
FSS-Proxy
X-Sentry-ID
CDN
FSS-Cache
GeoIP-Latitude
X-Ratelimit-Remaining
GeoIp-Country-Code
Geoip-Latitude
X-Flog
X-Hello
X-VServer
X-CSRF-TOKEN
X-ABtesting
X-Fastly-Backend-Reqs
XServer
X-Varnish-Beresp-TTL
X-Check-Cacheable
Cf-Ipcountry
X-WA
SN
X-UPSTREAM-Address
Processtime
X-APP
X-FireWall-Port
X-GZip
X-Source
Amp-Access-Control-Allow-Source-Origin
X-Csrf-Token
X-CSRF-Token
X-RateLimit-Limit-Second
X-HOST
X-RateLimit-Remaining-Second
TSSecure
X-Varnish-Cache-Hits
X-Unique-Id
X-Generation-Time
CACHE
X-DataStream-Origin-MEX-Latency
X-Oss-Object-Type
X-ServedByHost
X-CDN-Pop
X-MServer
X-Sedo-Request-Id
X-Worker
WP-Super-Cache
X-DataStream-MidMile-RTT
X-CDN-Pop-IP
X-Cache-Miss-From
X-Oss-Hash-Crc64ecma
X-Oss-Storage-Class
X-Oss-Server-Time
X-Oss-Request-Id
X-Dynatrace
PageType
X-Edge-Server
URI
Cdn-Request-Time
X-Nananana
A
Cdn-Host
X-Cache-Grace
X-GDPR
Pics-Label
X-SRV
X-Varnish-Authentication
X-Skip-Cache
X-Cache-ASPX
X-FORWARDED-FOR
Server-Cache-Control
Server-Surrogate-Control
X-VC-Cache
X-SplitTest
X-ID
X-AWS-Id
X-VWS-Id
X-LJ-Flow-ID
DataCenter
X-IPS-LoggedIn
X-HS-Status
X-Sucuri-Cache
X-Port
HTTPS
X-RCS-Backend
X-VG-WebCache
Odigeo-Trace-Id
X-B3-SpanId
X-Backend-TTL
X-Varnish-Url
X-Fastly-Cache-Hits
Cache-Hits
X-BE
X-Swift-Error
X-ND-Cache
X-PJAX-URL
X-From-Cache
Dynatrace
X-Owner
Hostname
X-Instart-Isnd
X-Ms-Lease-Status
Get-Access-Time
X-Gen-Id
X-Ms-Request-Id
X-Pf-Uncompressing
X-SN
X-Ms-Version
X-Ms-Blob-Type
X-Amzn-Remapped-Date
X-Amzn-Remapped-Connection
X-GZIP
Is-Session-Tracking
X-Bug-Bounty
ProcessTime
X-Server-W
X-Cache-Ttl
X-GoCache-CacheStatus
X-NGINX-Cache
X-ORIG-AKA-EDGE
X-VarnPar2
Proxy-Firewall
Requestid
X-Amz-Meta-S3b-Last-Modified
X-Akamai-SSL-Client-Sid
Serverid
X-Alicdn-Da-Ups-Status
X-Varnish-URL
X-PAGE-TYPE
X-LiteSpeed-Cache-Control
X-Serial
Powered
X-ServerName
X-GEO
X-Ms-Lease-State
WebServer
X-Fe
X-RAMCache
T-Server
X-ORIG-AKA-COUNTRY-CODE
X-VC
RequestUuid
X-SB
X-PF-Uncompressing
Xet-Cookie
Correlation-Id
X-LiteSpeed-Tag
NnCoection
X-HTML-Edge-Cache
SID
X-Cache-Srv
NodeID
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-Developed-By
X-CS
Location
X-Dw-Trace-Id