Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Accept-Ranges
Pragma
X-Powered-By
Link
ETag
CF-RAY
Expect-CT
Via
X-Cache
X-XSS-Protection
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-UA-Compatible
X-Cache-Hits
X-Xss-Protection
X-Amz-Cf-Id
X-Served-By
P3P
Referrer-Policy
X-Varnish
X-Request-Id
X-Timer
CF-Cache-Status
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Amz-Cf-Pop
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
P3p
X-Drupal-Cache
X-Check
X-Adblock-Key
X-Cacheable
Alt-Svc
Content-Security-Policy-Report-Only
X-Generator
CF-Ray
X-Cache-Status
X-DNS-Prefetch-Control
X-AspNetMvc-Version
Status
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-Permitted-Cross-Domain-Policies
Content-Encoding
X-Buckets
X-Content-Security-Policy
X-Turbo-Charged-By
X-Kinja-Server-Push
Upgrade
X-CDN
X-Request-ID
Xkey
X-Type
Keep-Alive
Access-Control-Expose-Headers
Access-Control-Max-Age
WPE-Backend
X-Pass-Why
X-AH-Environment
X-Backend
X-Cache-Group
X-Server
X-Age
X-Drupal-Dynamic-Cache
X-Via
X-Pingback
X-Nginx-Cache-Status
Grace
X-Amz-Request-Id
X-Amz-Id-2
X-Server-Powered-By
EagleId
X-Hacker
X-UA-Device
X-Robots-Tag
X-Varnish-Cache
X-LiteSpeed-Cache
X-Page-Speed
X-Proxy-Cache
Request-Context
X-Swift-CacheTime
X-Swift-SaveTime
Cf-Railgun
X-Envoy-Upstream-Service-Time
Ali-Swift-Global-Savetime
X-Ua-Compatible
X-WebKit-CSP
X-Ac
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-Cache-Lookup
X-Server-Id
X-Amz-Version-Id
X-OneAgent-JS-Injection
X-Cnection
X-Node
Content-Location
Surrogate-Control
X-Readtime
EagleEye-TraceId
Report-To
X-CST
X-Host
X-Response-Time
X-Rq
Feature-Policy
Server-Timing
X-Iejgwucgyu
X-Backend-Server
X-Application-Context
X-ORACLE-DMS-ECID
X-Rack-Cache
Request-Id
X-Cloud-Trace-Context
X-Instart-Request-ID
Allow
X-Clacks-Overhead
NEL
X-Url
Rating
X-DynaTrace
Edge-Control
X-Country
X-Origin-Cache
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Varnish-TTL
X-FTR-Request-ID
X-Country-Code
X-B3-TraceId
X-Px
X-Cdn
X-Ruxit-JS-Agent
X-DataDome
X-ORACLE-DMS-RID
X-Server-ID
X-GitHub-Request-Id
X-Vhost
X-ESI
X-Trace
X-VARITI-CCR
Accept-CH
X-Goog-Hash
Charset
X-Server-Name
X-Cached
RTSS
X-MS-InvokeApp
Pinterest-Generated-By
X-Mod-Pagespeed
X-TTL
Verso
PB-PID
PB-RID
Arc-Version
X-Mobile-Rewrite
Public-Key-Pins
X-D2id
X-Kinja-Build
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Cdn-Fetch
X-Kinja
X-Exp-Id
X-GoogleNews-Bot
X-Exp-Variant
X-Version
X-F-Cache
SPRequestGuid
X-Vname
X-PC
X-TtlSet
X-Dispatcher
X-DynaTrace-JS-Agent
X-T
X-Powered-By-Plesk
X-DIS-Request-ID
Accept-CH-Lifetime
X-Abt-Application-Version
X-SharePointHealthScore
X-Powered-CMS
X-Origin-Upstream-Status
X-Fastly-Request-ID
X-Ser
Pinterest-Version
X-Navigation-Version
X-Upstream-Env
X-Pinterest-Rid
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-B
X-Client-IP
X-Amz-Rid
Realpath
X-Shield-Request-Id
MS-Author-Via
X-Recruiting
X-Forwarded-Proto
X-HW
X-Upstream
SPRequestDuration
SPIisLatency
DynaTrace
X-Vcap-Request-Id
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Wix-Server-Artifact-Id
X-Accel-Buffering
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-XRDS-Location
Nginx-Cache
X-Amz-Meta-S3cmd-Attrs
Arr-Disable-Session-Affinity
X-Varnish-Age
AR-PoweredBy
AR-CACHE
Content-MD5
AR-ATIME
X-Debug
X-B3-TraceId-Primal
X-Via-JSL
MRF-Tech
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
Mrf-Cache-Status
X-Dw-Request-Base-Id
X-Ttl
X-Hits
X-Goog-Storage-Class
X-MSEdge-Ref
X-Id
X-NewRelic-App-Data
X-Acc-Meta-Resource-Type
X-N
X-Aspnet-Version
X-NF-Request-ID
X-Oracle-Dms-Rid
X-FTR-DC
X-FTR-Cache-Status
X-FTR-Backend
X-Country-Code-Real
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-Realm
Service-Worker-Allowed
X-FTR-Expires
S
Access-Control-Request-Method
X-ATG-Version
Edge-Cache-Tag
Alternate-Protocol
X-Logged-In
TCN
X-Kinsta-Cache
AMP-Access-Control-Allow-Source-Origin
X-PressLabs-Stats
X-HS-Hub-Id
X-HS-Content-Id
X-Frontend
X-FastCGI-Cache
Surrogate-Key
X-Forwarded-For
X-RateLimit-Remaining
Rt-Fastcgi-Cache
X-FTR-Cache-Host
X-Content-Digest
Tracecode
X-Pad
X-Cache-Key
X-CF-Powered-By
Fastcgi-Cache
X-Litespeed-Cache
X-TA-CDN-Provider
Ar-Sid
Server-Name
MicrosoftSharePointTeamServices
Fastly-Restarts
X-Amzn-Trace-Id
X-Analytics
Backend-Timing
X-User-Agent
Host
X-Cache-2
X-Edge-Location
FilterID
TP-Cache
X-Magnolia-Registration
X-Rid
TP-L2-Cache
X-Oneagent-Js-Injection
X-Debug-Info
ServerID
X-B3-Sampled
X-Whom
X-Mobile
X-Page-Id
X-Grace
X-Content-Options
X-IPLB-Instance
X-Revision
Eomportal-Instance
X-Hostname
Front-End-Https
Paypal-Debug-Id
X-Srv
X-Akam-SW-Version
AR-Request-ID
X-NWS-LOG-UUID
X-LB-Cache
Refresh
X-VCache
X-Request-Processing-Time
X-Request-Received
X-Content-Powered-By
Retry-After
X-B-Cache
X-Az
X-Activity-Id
X-Signature
X-AppVersion
X-Cache-Action
X-Cluster
X-SS-Set-Cookie
X-Framework
Source
X-Varnish-Hostname
Cleartype
X-Handled-By
X-URL
X-Cache-Control
X-Tumblr-Pixel
X-Tumblr-User
X-App-Environment
X-Request-Guid
X-Tumblr-Pixel-0
X-Platform-Server
X-FB-Debug
X-Akamai-Edgescape
X-Device-Type
X-Instance
X-WA-Info
X-GUploader-UploadID
X-AOL-HN
X-Content-Security-Policy-Report-Only
X-BCube-Filmed-By
X-Content-Type
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
Webserver
X-Cache-Hit
X-Zen-Fury
X-Varnish-Grace
X-Fastcgi-Cache
Display
X-Middleton-Display
X-Sol
X-Ruxit-Js-Agent
Accept-Charset
X-Varnish-Backend
X-Cache-Rule
X-Correlation-Id
Healthy
X-Wix-Request-Id
X-Seen-By
ViewerVersion
X-TT
X-Cache-Age
X-Drupal-Cache-Tags
X-Origin-Server
X-Cache-Server
X-Middleton-Response
Response
X-Daa-Tunnel
Cache-Status
Upgrade-Insecure-Requests
X-DataStream-Cache-Status
MS-CV
X-Varnish-Server
X-Cached-By
X-App-Server
X-Generated-By
X-Drupal-Cache-Contexts
X-Amz-Replication-Status
X-Geo-Country
Payment
X-Storage
X-PHP-Backend
X-Amz-Apigw-Id
Server-Node
X-Amzn-RequestId
X-UA-Device-Type
X-CACHE-GROUP
X-Response-Served-From
NGB
Filters
X-HS-Cache-Config
GEO-INFO
Access-Control-Allow-Method
X-Amz-Server-Side-Encryption
X-Cacheable-TTL
X-S
X-UUID
X-Contextid
X-RequestSource
X-Servedby
X-Esi
ServedBy
Viewport
X-Adobe-Content
X-Adobe-Loc
X-Cache-NE
X-TT-TIMESTAMP
X-Jobs
X-FW-Server
X-FW-Hash
X-FW-Static
X-FW-Serve
X-FW-Type
X-Varnish-IP
X-Edge-Cache-Key
X-Edge-Cache
X-Locale
X-Varnish-Hits
Actual-Object-TTL
X-TX-ID
X-Tumblr-Pixel-1
X-Tumblr-Pixel-2
AsisCache
Cache-Tv-Group
X-WPE-Loopback-Upstream-Addr
X-Accel-Expires
Server-Info
X-WebKit-CSP-Report-Only
X-Cache-Remote
S-Cnection
X-Status
X-Cache-TTL-Remaining
From-Origin
X-Rendered-As
X-GeoIP
Host-Header
X-Dns-Prefetch-Control
X-Region
X-Cache-Operation
X-App-Version
X-Croise-Owner
Cache
SRV
X-APP-VERSION
X-Redis-Cache
X-XRDS-LOCATION
HostName
X-CACHE-KEY
X-Webkit-CSP
Served-By
X-Node-Name
X-BACKEND-TTL
X-Hyper-Cache
Content-Style-Type
Content-Script-Type
DC
Liferay-Portal
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Public-Key-Pins-Report-Only
X-Upgrade-Enabled
X-Guploader-Uploadid
Cache-Tag
X-Cache-Config
X-Vg-Webcache
X-NGENIX-Cache
X-RTag
X-Generated
X-RN-RSRV
Ms-Operation-Id
X-Hosted-By
X-Is-Bot
Selected-FE
X-Site-Version
X-Mode
Machine
X-Timing-Wait
X-Detected-As
X-Akamai-Transformed
X-Proxy-Build
X-Path-Route
Meta-Geo
X-Cache-Var-Map
X-Cache-Var
X-Webstats-RespID
X-L-Path
X-Labrador-Cache-Channel
X-Loop
X-NCache
X-Environment-Context
Cache-Name
X-Akamai-Request-ID
X-Upstream-CT
Now
X-BYPASS-REASON
X-Cache-Category-Id
X-Human
X-Grey
X-Upstream-HT
X-Via-Fastly
X-JoinUs
X-Internal-Host
X-Request-Time
X-Parent-Response-Time
X-Origin-Response-Time
X-Original-Request
X-ProxyCache-Key
X-TNCMS
X-ProxyCache-Status
Azure-RegionName
Azure-InstanceId
Azure-SiteName
Azure-SlotName
Azure-Version
X-Birta-Served
X-GRACE
X-CDN-Cache
X-RemovedCookies
X-Origin-CC
X-Origin
Cache-Key
X-Proxy
Origin-Edge-Control
Origin-Cache-Control
X-Agile
X-Pc-Hit
User-Cache-Control
X-Pc-Key
X-Agile-Age
DB-Nickname
X-Agile-Id
X-B3-Spanid
X-ProcessESI
X-Origin-Host
X-Birta-Cache-Post
X-IP
X-Protected-By
X-Time-Microsecs
X-Edge-IP
X-Viewer-Country
X-Pc-Appver
X-Tumblr-Pixel-3
X-Web-Node
X-Format
X-ServerID
X-Xfnlog-Site
X-PCL
X-Access
X-Www-Served-By
Webcakes-Region
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Locale-Group
TWC-Privacy
TWC-Device-Class
TWC-Connection-Speed
S-Rt
Webcakes-App-Name
Webcakes-App-Version
Property-Id
Fastcgi-X-Cache-Version
X-VG-TLSProxy
X-Rule
X-Origin-Hint
X-Ocache
Xserver
X-Pubstack
X-OCL
X-FC-Vary-Parameters
X-CCM
X-Tb
X-Section
Cache-Tags
Fastcgi-X-Cache
X-Backend-Name
Fastcgi-Useragent
X-Routing-Service
X-Forwarded-Host
X-Vgn-Hpd-Reason
HitType
Vix-Hermes-Req-Id
X-Zipkin-Id
X-Proxied
X-App-Name
Pagespeed
Powered-By-ChinaCache
Load-Balancing
X-FB-TRIP-ID
Mn-Server-Ip
X-Cache-TTL
X-Endurance-Cache-Level
Country
X-PERF
X-ApacheServer
Datacenter
X-Content-Age
X-Cache-Backend
X-TIME
X-RateLimit-Limit
X-Real-IP
X-Mrs-Age
X-Via-CDN
X-Mrs-Cache
X-Mrs-Cache-Hits
X-Unique-Id-Primal
X-Mshield-Cache-Status
X-Nginx-Cache
OT-Force-Account-Verify
Time
X-Ezoic-Cdn
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Shopify-Stage
X-Sorting-Hat-PodId
X-ShardId
X-UA
X-Cdn-Forward
X-Alternate-Cache-Key
X-ShopId
Fusion-Content-Source
X-Sorting-Hat-ShopId
Fusion-Source
Fusion-Template-Id
Fusion-Component-Id
Fusion-Content-Id
X-Correlation-ID
Ohc-File-Size
X-Varnish-Cacheable
X-Debug-Cache
X-OVcl-Cache
X-OVcl
X-Sucuri-ID
X-Ua
LB
X-Pc-Host
X-Pc-Date
L5d-Success-Class
NtCoent-Length
X-Varnish-Beresp-Ttl
X-CDN-Forward
X-Varnish-Beresp-Grace
X-Unique-ID
X-Varnish-Beresp-Status
X-Hl-Ver
X-HS-Combine-CSS
X-MP-GENERATED-AT
Section-Io-Cache
Mail-Subject
We-Hiring
X-Nc
X-Amz-Meta-Surrogate-Control
X-Hit
X-Ratelimit-Limit
X-Proto
X-Trace-Id
X-Akamai-Request-ID2
X-Front
X-Time
User-Agent
X-Real-Ip
X-Cache-Enabled
Pagetype
AR-SID
Access-Control-Request-Headers
X-C
Version
Accept-Language
X-Dynatrace-Js-Agent
Warning
X-Rocket-Nginx-Bypass
X-Newrelic-App-Data
X-Microcachable
X-EdgeConnect-Cache-Status
Node
X-CF-Lambda-Version
X-Cache-Id
X-CF-Lambda-Fn
X-Cache-URL
X-Cache-Debug
X-Cache-Expires
X-Date
Meta-Geo-Continent
X-Developer
X-Device-Os
X-Died
X-Dispatcher-Server
X-Destination
X-Cache-Bucket
X-Crawler
X-Connection-Hash
X-CUA
X-D
Mobile-Detection-Method
Is-Eu
X-Application
VivaBuild
Viewtype
RNT-Machine
Memcached
Www
Request-Time
Resin-Trace
RNT-Time
X-DPWN-IS-SECURE
Thinkindot-CacheControl-Type
MD5-Digest
Thinkindot-CacheControl
Thinkindot-Control
V-Age
Rt-Proxy-Cache
Server-Host
X-A
Rendered-Blocks
X-Aed
X-Actual-URL
PFcat
Server-ID
X-Auto-Login
X-BB-ID
X-B-Cookie
Platform
X-Accel-Expires-Debug
X-A-Dcw
X-A-Dam
X-A-Ccd
Release
X-A-Dgt
Powered-By
X-A-Wwc
X-Bip
X-Qloud-Router
X-Server-By
X-Served-From
X-Server-IP
X-Server-Time
X-Store
X-SRCache-Key
X-ScT
X-S-Maxage
X-Returned-From-DLL
X-Returned-From-BeforeDispatch
X-Returned-From-PostProcessResponse
X-Rewrite-Enabled
X-S-Cookie
X-Rojux
X-Svr
X-Swa-Ws
X-Varnish-Action
X-Variation
X-VG-WebServer
X-We-Are-Hiring
Xc-Version
X-WebServer
X-Var-Ttl
X-User
X-Thinkindot-L3
X-Thanos
X-Transaction
X-Trv-Group
X-Twitter-Response-Tags
X-TT-LOGID
X-Returned-From
X-Request-UUID
X-Li-Fabric
X-Level-Front-Cache
X-Li-Pop
X-LI-Proto
X-Logtrace-Id
X-LI-UUID
X-Layer
X-Goog-Meta-Goog-Reserved-File-Mtime
X-From
X-Fetched-On
X-FW-Version
X-G
X-Generated-On
X-Generated-In
X-Matched-Rule
X-NU-AKA-ACS-Version
X-RCS-CacheZone
IBM-Web2-Location
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Region-Sid
X-Reboot
X-PHP-Host
X-PAYTM-SRV-ID
X-Passed-To
X-P-T
X-Passed-To-BeforeDispatch
X-Passed-To-DLL
X-Passed-To-PostProcessResponse
X-External-Request-Id
X-Cache-FS-Status
Ajk
Fastly-SIE
X-CLOUD-TRACE-CONTEXT
Adler-Geo
Fastly-SWR
Frame-Options
Fly-Request-Id
Fly-Cache
Fastly-Backend-Name
Arc-Country
Cache-Prefix
Ec-Rule-Version
BehaviorPad-Version
X-Distil-CS
X-Backend-Host
X-Epic-Correlation-Id
Cache-Cookie-Set-Lfrom
X-F5-Cache
X-Gannett-Site-Version
X-Fstrz
Ohc-Response-Time
X-ElasticPress-Search
Cache-Cookie-Set-Idcheck
X-Gen-Mode
X-Block-Status
Backend
Backend-Name
X-Cache-Host
X-Clientip
X-Cache-CFC
Cache-Cookie-Set-From
AKAMAI
X-Backend-Url
X-Hash
X-Response-By
X-Secret
X-Server-Group
X-Request-Start
X-Release
X-Proxy-Cache-Status
X-Proxy-Upstream
X-ServiceProvider
X-Sf
X-UnsetCookies
X-Via-NSCOPI
X-UE-Client-Country
X-SVT-ORM-VERSION
X-Stale
X-SVT-ORM-RULES
X-Origin-Expires
X-Origin-Date
X-IN-WAF
X-Info
X-IN-SSL-APIGATEWAY
X-IN-APIGATEWAY
X-Amz-Meta-Cache-Control
X-Hnp-Log
X-Instart-Info
X-Location
X-No-Session
X-Node-Id
X-Nginx-Cache-Key
X-MSEdge-Flight
X-MI-In-Market
X-MSEdge-Features
X-GeoIP-Country-Code
X-Phone
MI-API
MI-Cache-Age
Magicmarker
Lfy
Esi-Enabled
Kp-EeAlive
True-Client-Country-4JS
SS
Server-Int
GMS-Ver
GW-Server
Proxy-Connection
Origin
Pramga
Web-Mar-Node
MI-Cache
Who
Decoy-Debug-Key
Countrycode
Heartbleed
Content-Disposition
Country-Code
Decoy-Debug-TTL
Decoy-Debug-Status
X-Dc
X-Be
HA-Geocountry
X-Key
X-Server-Cache
X-Up
X-Micro-Cache
X-V
REQUESTUUID
X-Wikidot-Static-Cache
X-ARC
X-Wikidot-Backend
HA-Cloudapp
HA-Geolat
HA-Geocity
X-Irp-Debug
HA-Georegion
X-Request-URI
HA-Host
HA-Servedtime
HA-Urlpath
IsBot
X-SIPLIST1
X-Fastly-Cache
Ha-Gx-Prefs
X-Origin-TTL
On-Server
X-Page-Type
X-Platform
X-Policy
HA-Geolon
HA-Ipaddr
Fastly-SSL
Fastly-Soc-X-Request-Id
X-Core-Value
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
ServerName
X-Developers
X-Debug-Cache-Store
X-Core-Mission
X-CGP
X-Cache-Info
Apple-News-Services-Request-Url
CDCHOST
Apple-News-Services-Parsed-Url
X-Cdn-Srv
Apple-News-Services-Handled
Apple-News-Services-Host
X-Distributor
X-Backend-State
X-Eu-Site
SD-X-WS
X-NODE
X-Cdn-Origin
X-Sn-Servicetimems
X-Debug-Log
X-Geo
X-Debug-Cookies
X-Servername
WZWS-RAY
X-NX-Host
PageSpeed
RequestId
X-Refresh
X-COUNTRY
X-Org
X-NC
X-Pjax-Url
X-DC
X-CMS-Context
X-Via-SSL
X-Via-Edge
Cteonnt-Length
MIME-Version
X-CACHE-AGE
X-PARISIEN-Cache-Rendered
X-Servedbyhost
X-LAGOON
X-VarnCache
X-VarnPar1
Pragrma
Cdn
X-Newrelic-Synthetics
X-Datadome
Request-EU
UCS
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
Uber-Trace-Id
X-Urbn-Context-Path
Memory
X-Req
X-Urbn-Site-Id
Locale
X-Planisys-CDN-Cache
Mime-Version
X-Instance-Name
Request-Country
X-NWS-UUID-VERIFY
Host-ID
NGX
V-Cache
Group
X-GeoIP-City
X-VCT
Cache-Provider
X-CSRF-TOKEN
PICS-Label
X-Wa
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Gdpr
X-Webkit-Csp
X-Generation-Time
X-FireWall-Port
Nel
X-Varnish-Cache-Hits
CF-IPCountry
GeoIP-Country-Code
X-HTML-Minification-Powered-By
GeoIP-Latitude
X-BBXSRF
HitInfo
X-Powered-By-ANYU
X-Aicache-OS
XServer
X-WR-MODIFICATION
CDN
X-Ratelimit-Remaining
X-B3-Traceid
X-Load-Cache
X-StackifyID
X-UPSTREAM-Address
X-DataStream-Origin-MEX-Latency
X-Varnish-Authentication
X-Sedo-Request-Id
X-Fastly-Country-Code
X-DataStream-MidMile-RTT
X-Cache-ASPX
Server-Surrogate-Control
X-Cache-Grace
Server-Cache-Control
X-Cache-Miss-From
Cf-Ipcountry
X-IPS-LoggedIn
X-VG-WebCache
Geoip-Latitude
GeoIp-Country-Code
CACHE
X-Varnish-Url
X-EIG-Tracking-Id
X-Check-Cacheable
X-TWH-CORRELATION-ID
X-Source
X-Instart-Isnd
X-ND-Cache
X-Sucuri-Cache
X-Fastly-Backend-Reqs
Pics-Label
X-Varnish-Beresp-TTL
X-HOST
X-RCS-Backend
X-FORWARDED-FOR
X-From-Cache
URI
Proxy-Firewall
Is-Session-Tracking
Get-Access-Time
X-WA
X-CDN-Pop-IP
X-CDN-Pop
X-APP
X-Fastly-Cache-Hits
X-GEO
X-Unique-Id
FSS-Cache
X-GoCache-CacheStatus
Powered
FSS-Proxy
Processtime
X-Dynatrace
X-Sentry-ID
X-NodeID
X-Csrf-Token
X-R9-Blue-Green-Version
X-FW-Dynamic
X-SRV
WP-Super-Cache
X-VC-Cache
X-ABtesting
X-Nananana
X-Skip-Cache
X-Flog
X-Cluster-Node
X-GDPR
X-Server-W
X-VServer
X-Hello
DataCenter
X-ID
X-ServedByHost
X-Oss-Request-Id
X-Oss-Server-Time
SN
X-Oss-Storage-Class
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Pc-Subdomain
Amp-Access-Control-Allow-Source-Origin
Hostname
X-PF-Uncompressing
X-HS-Status
X-GZip
X-B3-SpanId
X-CSRF-Token
X-Fe
X-RequestId
X-BE
TSSecure
X-Worker
Dynatrace
X-Pf-Uncompressing
X-PJAX-URL
X-TrackingId
X-Swift-Error
X-NGINX-Cache
Cdn-Request-Time
X-MServer
X-Bug-Bounty
Cache-Hits
X-Amzn-Remapped-Date
X-Backend-TTL
Cdn-Host
X-Gen-Id
X-Edge-Server
X-Amzn-Remapped-Connection
X-GZIP
X-LiteSpeed-Cache-Control
A
X-Cache-Ttl
X-ORIG-AKA-EDGE
Requestid
ProcessTime
Serverid
X-Tb-Optimization-Total-Bytes-Saved
X-LiteSpeed-Tag
X-ServerName
DSUID
X-Alicdn-Da-Ups-Status
X-Port
T-Server
X-ORIG-AKA-COUNTRY-CODE
X-PAGE-TYPE
X-HostName
X-SB
X-VC
X-RAMCache
RequestUuid
X-Varnish-URL
X-VarnPar2
286prxHost
225prxHost
189phosttRef
352pxline
219prxHost
355prline
X-SN
Xxline
X-Requestid
SID
409pxxline
188prxHost
NnCoection
HTTPS
Correlation-Id
X-Akamai-ERRuleID
Xet-Cookie
X-Serial
X-CS
Location
Cneonction
X-Akamai-ERPolicy
X-Dw-Trace-Id
X-Developed-By
178proxuri