Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Accept-Ranges
Pragma
X-Powered-By
Link
ETag
CF-RAY
Expect-CT
Via
X-Cache
X-XSS-Protection
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Id
X-Xss-Protection
X-Served-By
P3P
Referrer-Policy
X-Varnish
X-Timer
X-Request-Id
CF-Cache-Status
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
P3p
X-Drupal-Cache
X-Check
X-Adblock-Key
Alt-Svc
X-Cacheable
X-Amz-Cf-Pop
X-Generator
CF-Ray
Content-Security-Policy-Report-Only
X-Cache-Status
X-AspNetMvc-Version
X-DNS-Prefetch-Control
Status
X-Template
X-Language
Timing-Allow-Origin
Content-Encoding
X-Permitted-Cross-Domain-Policies
X-Iinfo
X-Request-ID
X-Buckets
X-Content-Security-Policy
X-Turbo-Charged-By
Upgrade
X-Kinja-Server-Push
X-CDN
X-Type
Xkey
Keep-Alive
Access-Control-Expose-Headers
WPE-Backend
Access-Control-Max-Age
X-Pass-Why
X-AH-Environment
X-Backend
X-Cache-Group
X-Server
X-Age
X-Drupal-Dynamic-Cache
X-Pingback
X-Via
X-Nginx-Cache-Status
X-Amz-Request-Id
X-Amz-Id-2
Grace
X-Server-Powered-By
X-Hacker
EagleId
X-UA-Device
X-Robots-Tag
X-LiteSpeed-Cache
X-Varnish-Cache
X-Page-Speed
X-Swift-SaveTime
X-Swift-CacheTime
X-Proxy-Cache
Cf-Railgun
Request-Context
X-Envoy-Upstream-Service-Time
Ali-Swift-Global-Savetime
X-Ua-Compatible
X-Ac
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-WebKit-CSP
X-Cache-Lookup
Content-Location
X-Amz-Version-Id
X-Server-Id
Surrogate-Control
X-Host
X-Cnection
X-Node
X-Readtime
Report-To
X-OneAgent-JS-Injection
EagleEye-TraceId
X-Rq
Server-Timing
X-Response-Time
Feature-Policy
X-CST
X-Rack-Cache
X-Application-Context
X-Backend-Server
X-ORACLE-DMS-ECID
X-Iejgwucgyu
Request-Id
X-Cloud-Trace-Context
X-Instart-Request-ID
X-Clacks-Overhead
X-Url
NEL
Edge-Control
X-DynaTrace
Rating
Allow
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Country
X-Varnish-TTL
X-Origin-Cache
X-FTR-Request-ID
X-Country-Code
X-Trace
X-Server-Name
X-Px
X-DataDome
X-Vhost
X-B3-TraceId
X-ESI
X-GitHub-Request-Id
X-VARITI-CCR
RTSS
X-MS-InvokeApp
X-Cached
X-Ruxit-JS-Agent
Accept-CH
X-Goog-Hash
X-ORACLE-DMS-RID
Charset
SPRequestGuid
X-Server-ID
X-PC
X-Vname
X-TtlSet
Pinterest-Generated-By
X-Mod-Pagespeed
X-F-Cache
Verso
Public-Key-Pins
X-D2id
X-Kinja-Build
X-Cdn-Fetch
X-Use-Magma
X-Kinja-Server
X-Exp-Variant
X-GoogleNews-Bot
X-Kinja
X-Kinja-Revision
X-Exp-Id
X-Dispatcher
PB-RID
Arc-Version
X-Mobile-Rewrite
PB-PID
X-Version
X-SharePointHealthScore
X-Cdn
X-T
X-Powered-By-Plesk
X-TTL
X-Abt-Application-Version
Accept-CH-Lifetime
X-DIS-Request-ID
X-Powered-CMS
X-DynaTrace-JS-Agent
X-Fastly-Request-ID
X-Ser
Pinterest-Version
X-Upstream-Env
X-Pinterest-Rid
X-Origin-Upstream-Status
X-Navigation-Version
X-Forwarded-Proto
X-B
X-Shield-Request-Id
X-Client-IP
X-Recruiting
MS-Author-Via
X-Amz-Rid
X-SRCache-Fetch-Status
DynaTrace
X-SRCache-Store-Status
X-Ttl
X-HW
SPIisLatency
Realpath
SPRequestDuration
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Upstream
Content-MD5
X-Vcap-Request-Id
Nginx-Cache
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Accel-Buffering
X-Wix-Server-Artifact-Id
X-Oracle-Dms-Rid
X-Amz-Meta-S3cmd-Attrs
AR-PoweredBy
AR-CACHE
AR-ATIME
Edge-Cache-Tag
Arr-Disable-Session-Affinity
X-Oneagent-Js-Injection
X-Hits
X-N
X-Varnish-Age
X-Debug
TCN
X-Aspnet-Version
X-Goog-Storage-Class
MRF-Tech
X-Mrf-Section-Lastmod
Mrf-Cache-Status
X-Mrf-Item-Lastmod
X-B3-TraceId-Primal
X-NF-Request-ID
X-MSEdge-Ref
Access-Control-Request-Method
X-Acc-Meta-Resource-Type
X-Dw-Request-Base-Id
X-Id
X-XRDS-Location
S
X-Via-JSL
X-Country-Code-Real
X-FTR-Realm
X-FTR-DC
X-FTR-Cache-Status
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-Backend
Service-Worker-Allowed
X-NewRelic-App-Data
X-ATG-Version
X-FTR-Expires
X-Logged-In
X-Dns-Prefetch-Control
X-FastCGI-Cache
Alternate-Protocol
X-HS-Content-Id
X-HS-Hub-Id
Tracecode
Rt-Fastcgi-Cache
X-Forwarded-For
X-PressLabs-Stats
X-Frontend
Surrogate-Key
X-Content-Digest
X-Kinsta-Cache
X-Cache-Key
AMP-Access-Control-Allow-Source-Origin
X-Pad
Fastly-Restarts
MicrosoftSharePointTeamServices
X-RateLimit-Remaining
X-FTR-Cache-Host
X-Grace
X-Content-Options
X-Ruxit-Js-Agent
X-Edge-Location
Server-Name
X-Amzn-Trace-Id
X-CF-Powered-By
Backend-Timing
X-Analytics
FilterID
Host
TP-L2-Cache
TP-Cache
X-Rid
X-Debug-Info
X-User-Agent
X-Hostname
Fastcgi-Cache
X-Whom
X-Magnolia-Registration
X-IPLB-Instance
ServerID
X-Cache-2
Ar-Sid
X-B3-Sampled
X-Revision
Eomportal-Instance
X-Page-Id
X-Request-Received
X-Request-Processing-Time
X-Mobile
Paypal-Debug-Id
X-NWS-LOG-UUID
X-Srv
AR-Request-ID
Front-End-Https
X-Akam-SW-Version
X-AOL-HN
X-VCache
X-HS-Cache-Config
Retry-After
X-Content-Powered-By
X-GUploader-UploadID
X-Signature
X-B-Cache
X-Litespeed-Cache
X-Cache-Action
X-Cluster
X-SS-Set-Cookie
Source
X-Handled-By
X-FB-Debug
X-LB-Cache
Refresh
X-WA-Info
X-Varnish-Grace
X-Cache-Control
X-Request-Guid
X-Device-Type
X-Instance
X-App-Environment
X-Cache-Hit
Cleartype
X-Framework
X-Varnish-Hostname
X-BCube-Filmed-By
X-Platform-Server
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel
X-Akamai-Edgescape
X-Content-Security-Policy-Report-Only
Webserver
X-Correlation-Id
X-Zen-Fury
Display
X-Middleton-Display
X-Varnish-Backend
X-Sol
X-AppVersion
X-Activity-Id
X-Az
X-XRDS-LOCATION
X-Daa-Tunnel
X-Content-Type
Healthy
X-Cache-Server
X-Fastcgi-Cache
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Cache-Rule
X-Varnish-Server
Response
X-Middleton-Response
X-Wix-Request-Id
X-Drupal-Cache-Contexts
X-Drupal-Cache-Tags
X-Seen-By
ViewerVersion
X-URL
X-Cached-By
X-Geo-Country
X-Generated-By
S-Cnection
X-App-Server
Server-Node
Cache-Status
X-TT
X-DataStream-Cache-Status
X-Origin-Server
X-CACHE-GROUP
X-Accel-Expires
Upgrade-Insecure-Requests
X-Amz-Replication-Status
X-Cache-Age
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Esi
Payment
X-RequestSource
NGB
Filters
GEO-INFO
X-Response-Served-From
X-UA-Device-Type
X-TA-CDN-Provider
X-S
X-Edge-Cache-Key
X-Edge-Cache
X-Cacheable-TTL
X-Cache-NE
Actual-Object-TTL
Accept-Charset
X-Status
X-Servedby
X-Contextid
ServedBy
X-Varnish-IP
X-Jobs
X-FW-Type
X-FW-Server
X-Tumblr-Pixel-1
X-Tumblr-Pixel-2
Access-Control-Allow-Method
X-TT-TIMESTAMP
X-FW-Serve
X-FW-Static
X-Node-Name
X-FW-Hash
X-Locale
Viewport
X-Varnish-Hits
X-Amz-Server-Side-Encryption
X-TX-ID
X-UUID
AsisCache
X-GeoIP
X-WPE-Loopback-Upstream-Addr
X-Adobe-Content
X-Adobe-Loc
Server-Info
HostName
X-WebKit-CSP-Report-Only
Host-Header
X-Storage
Cache
X-APP-VERSION
X-PHP-Backend
SRV
X-Rendered-As
X-Cache-TTL-Remaining
Cache-Tv-Group
X-Cache-Remote
MS-CV
X-Vg-Webcache
X-Croise-Owner
X-Hyper-Cache
From-Origin
X-Cache-Operation
X-Region
X-Webkit-CSP
X-Redis-Cache
X-HS-Combine-CSS
Served-By
Cache-Tag
X-App-Version
DC
Liferay-Portal
Public-Key-Pins-Report-Only
X-Forwarded-Host
X-Mode
Xserver
Meta-Geo
X-Path-Route
X-Yottaa-Optimizations
Machine
Fastcgi-X-Cache-Version
X-NGENIX-Cache
X-Yottaa-Metrics
X-IP
X-Endurance-Cache-Level
Fastcgi-X-Cache
X-Proxy-Build
X-Akamai-Transformed
X-Human
Selected-FE
X-Hosted-By
X-Loop
Fastcgi-Useragent
X-Webstats-RespID
X-Timing-Wait
X-Agile
X-Detected-As
X-Generated
X-Upgrade-Enabled
X-Is-Bot
X-Cache-Var-Map
X-Request-Time
X-RN-RSRV
X-Agile-Id
X-Cache-Var
X-Agile-Age
X-TNCMS
TWC-Device-Class
TWC-Connection-Speed
X-Format
Webcakes-Region
Now
X-Cache-Category-Id
X-BYPASS-REASON
X-CDN-Cache
Origin-Cache-Control
X-Environment-Context
Property-Id
Origin-Edge-Control
Webcakes-App-Version
X-Internal-Host
X-Pc-Key
TWC-GeoIP-LatLong
X-Pc-Hit
X-Pc-Appver
Cache-Name
X-Upstream-HT
X-Web-Node
X-Via-Fastly
X-Vgn-Hpd-Reason
TWC-Locale-Group
TWC-Privacy
X-Original-Request
X-ProxyCache-Status
X-Labrador-Cache-Channel
X-L-Path
X-ProxyCache-Key
Webcakes-App-Name
X-NCache
X-Origin-Hint
X-Grey
X-Upstream-CT
X-JoinUs
TWC-GeoIP-Country
Powered-By-ChinaCache
X-B3-Spanid
X-Origin-Host
X-ProcessESI
X-OCL
X-PCL
X-UA
X-Access
X-FC-Vary-Parameters
X-Proxy
X-Pubstack
X-Origin
X-Origin-Response-Time
X-VG-TLSProxy
X-Viewer-Country
X-Tumblr-Pixel-3
X-RemovedCookies
X-Section
X-Time-Microsecs
S-Rt
X-Akamai-Request-ID
DB-Nickname
Cache-Tags
X-Birta-Cache-Post
Azure-SlotName
Azure-Version
X-Birta-Served
Azure-SiteName
Azure-InstanceId
X-Www-Served-By
Datacenter
X-Xfnlog-Site
X-Backend-Name
Azure-RegionName
Mn-Server-Ip
X-Cache-Config
X-Newrelic-App-Data
X-Ocache
X-Tb
X-ServerID
X-Site-Version
X-CCM
X-Rule
X-Origin-CC
X-Guploader-Uploadid
X-Routing-Service
X-Proxied
X-Akamai-Request-ID2
X-Via-CDN
X-Zipkin-Id
HitType
Pagespeed
X-CLOUD-TRACE-CONTEXT
X-TIME
X-Cache-TTL
X-App-Name
X-Parent-Response-Time
OT-Force-Account-Verify
Cache-Key
X-ShopId
X-ShardId
X-BACKEND-TTL
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Nginx-Cache
X-Alternate-Cache-Key
X-Sorting-Hat-ShopId
User-Cache-Control
X-CACHE-KEY
Vix-Hermes-Req-Id
AR-SID
X-Edge-IP
X-Dynatrace-Js-Agent
Content-Script-Type
Content-Style-Type
X-Protected-By
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Ezoic-Cdn
X-RateLimit-Limit
X-Correlation-ID
X-OVcl-Cache
X-OVcl
Accept-Language
L5d-Success-Class
NtCoent-Length
Time
X-Pc-Date
X-Pc-Host
X-RTag
Ms-Operation-Id
X-Real-IP
X-Cache-Backend
X-ApacheServer
X-PERF
X-Real-Ip
X-Cdn-Forward
X-Amz-Meta-Surrogate-Control
X-Webkit-Csp
LB
X-Front
X-Proto
X-FB-TRIP-ID
X-Unique-Id-Primal
X-Mrs-Cache-Hits
X-Mrs-Age
X-Mrs-Cache
X-Mshield-Cache-Status
Section-Io-Cache
X-Content-Age
X-CDN-Forward
X-Varnish-Beresp-Status
X-Hit
X-Varnish-Beresp-Grace
X-Debug-Cache
X-Varnish-Cacheable
X-Nc
Country
X-Sucuri-ID
WZWS-RAY
X-Unique-ID
Load-Balancing
X-Ratelimit-Limit
X-GRACE
Fusion-Template-Id
Fusion-Component-Id
Fusion-Content-Id
Fusion-Content-Source
Fusion-Source
Ohc-File-Size
X-Microcachable
X-MP-GENERATED-AT
Version
X-Hl-Ver
X-Time
X-C
We-Hiring
Mail-Subject
Access-Control-Request-Headers
X-Varnish-Beresp-Ttl
X-EdgeConnect-Cache-Status
X-Connection-Hash
X-Trace-Id
Warning
X-Cache-Enabled
X-Transaction
X-Twitter-Response-Tags
X-Device-Os
X-Dispatcher-Server
X-Died
X-Developer
VivaBuild
X-F5-Cache
X-G
X-FW-Version
X-From
Countrycode
Cache-Prefix
BehaviorPad-Version
X-GeoIP-Country-Code
X-Generated-In
Arc-Country
X-Fetched-On
X-External-Request-Id
Fly-Request-Id
Frame-Options
X-DPWN-IS-SECURE
Fly-Cache
Fastly-SWR
Ec-Rule-Version
Fastly-Backend-Name
Fastly-SIE
Viewtype
X-CUA
X-A-Wwc
X-A-Dgt
MD5-Digest
Rendered-Blocks
Release
X-Cache-Bucket
X-A-Dcw
RNT-Machine
X-Cache-Debug
Resin-Trace
X-A-Dam
Ajk
Memcached
X-Accel-Expires-Debug
X-Application
Platform
X-Auto-Login
Mobile-Detection-Method
Node
Powered-By
X-Backend-State
Meta-Geo-Continent
X-Actual-URL
X-Aed
X-BB-ID
Is-Eu
IBM-Web2-Location
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
SS
X-A-Ccd
Server-ID
X-B-Cookie
X-D
Www
X-A
X-Date
Thinkindot-Control
Server-Host
SD-X-WS
X-Cache-Id
X-Cache-URL
X-Cache-Host
X-Cache-FS-Status
X-Cache-Expires
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Crawler
X-Clientip
Rt-Proxy-Cache
RNT-Time
X-Destination
X-Qloud-Router
X-Rewrite-Enabled
X-Returned-From-PostProcessResponse
Adler-Geo
X-Rojux
X-S-Cookie
X-ScT
X-S-Maxage
X-Returned-From-BeforeDispatch
X-Returned-From
X-Reboot
V-Age
X-Region-Sid
X-Release
X-Response-By
X-Request-UUID
X-Server-By
X-Server-Time
X-VG-WebServer
X-Variation
X-Var-Ttl
X-Via-Edge
X-Via-SSL
X-WebServer
X-We-Are-Hiring
X-UE-Client-Country
X-Trv-Group
Xc-Version
X-SRCache-Key
X-Store
X-Ua
X-Thinkindot-L3
X-Swa-Ws
X-Rebelmouse-Surrogate-Control
X-Returned-From-DLL
X-Layer
X-Node-Id
X-LI-UUID
X-Org
X-Matched-Rule
X-Rebelmouse-Cache-Control
X-LI-Proto
X-Li-Pop
X-Logtrace-Id
X-Li-Fabric
X-Passed-To
X-NU-AKA-ACS-Version
X-Passed-To-BeforeDispatch
X-Passed-To-PostProcessResponse
X-Passed-To-DLL
X-PHP-Host
X-RCS-CacheZone
X-PAYTM-SRV-ID
X-Dc
X-Thanos
X-Hnp-Log
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-IN-APIGATEWAY
X-Hash
X-Gannett-Site-Version
X-Varnish-Action
X-IN-WAF
X-IN-SSL-APIGATEWAY
X-Info
X-Gen-Mode
X-Via-NSCOPI
X-UnsetCookies
X-User
X-Key
X-Amz-Meta-Cache-Control
X-Epic-Correlation-Id
X-Rocket-Nginx-Bypass
X-Block-Status
X-Goog-Meta-Goog-Reserved-File-Mtime
X-P-T
X-TT-LOGID
X-Proxy-Upstream
X-Proxy-Cache-Status
X-CGP
X-Bip
X-Eu-Site
X-Server-IP
X-ServiceProvider
X-Sf
X-Location
X-Server-Group
X-Served-From
Request-Time
X-MI-In-Market
X-Secret
X-Stale
Web-Mar-Node
MI-API
Apple-News-Services-Parsed-Url
Kp-EeAlive
HA-Geolat
MI-Cache
HA-Geocity
MI-Cache-Age
HA-Geocountry
Apple-News-Services-Handled
HA-Geolon
HA-Ipaddr
Apple-News-Services-Host
HA-Host
HA-Georegion
HA-Servedtime
Heartbleed
HA-Urlpath
HA-Cloudapp
On-Server
Decoy-Debug-Key
Country-Code
Content-Disposition
True-Client-Country-4JS
Esi-Enabled
Decoy-Debug-Status
User-Agent
Decoy-Debug-TTL
Backend-Name
Backend
GW-Server
Apple-News-Services-Request-Url
Origin
Pragrma
Pramga
GMS-Ver
Proxy-Connection
Ha-Gx-Prefs
X-Geo
X-NODE
X-Platform
CDCHOST
X-Policy
X-Wikidot-Static-Cache
X-Planisys-CDN-TTL
Cache-Cookie-Set-From
X-Page-Type
X-No-Session
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Request-Start
X-Urbn-Context-Path
X-Urbn-Site-Id
AKAMAI
Cache-Cookie-Set-Idcheck
X-Instance-Name
X-Irp-Debug
X-Request-URI
X-SIPLIST1
X-Wikidot-Backend
X-V
X-Developers
Who
X-Nginx-Cache-Key
X-MSEdge-Flight
X-Backend-Host
X-Backend-Url
Fastly-Soc-X-Request-Id
PFcat
X-Origin-Date
Request-EU
X-Phone
Request-Country
X-Up
X-Origin-Expires
X-MSEdge-Features
Locale
Uber-Trace-Id
X-Distil-CS
UCS
X-Cache-CFC
Server-Int
X-Distributor
X-Core-Value
IsBot
X-Fstrz
Cache-Cookie-Set-Lfrom
Fastly-SSL
Magicmarker
X-Be
Pagetype
X-DC
X-NWS-UUID-VERIFY
PageSpeed
X-Core-Mission
X-Origin-TTL
X-Fastly-Cache
X-Sn-Servicetimems
X-Servername
X-Refresh
X-CACHE-AGE
X-Debug-Cookies
X-ElasticPress-Search
REQUESTUUID
X-Debug-Log
X-Cdn-Origin
X-NX-Host
V-Cache
Group
X-Debug-Cache-Expiry
X-Debug-Cache-Store
X-GeoIP-City
X-VCT
X-COUNTRY
X-Debug-Cache-Fetch
X-Micro-Cache
X-NC
HitInfo
X-Req
Host-ID
RequestId
X-Instart-Info
X-PARISIEN-Cache-Rendered
X-VarnPar1
X-VarnCache
X-Svr
X-Newrelic-Synthetics
X-Pjax-Url
X-Level-Front-Cache
X-Generated-On
Lfy
MIME-Version
X-Server-Cache
X-Cache-Info
X-Cdn-Srv
Ohc-Response-Time
X-BBXSRF
ServerName
X-Datadome
X-Powered-By-ANYU
X-ARC
X-B3-Traceid
Cache-Provider
X-EIG-Tracking-Id
X-Gdpr
Mime-Version
PICS-Label
Memory
Cteonnt-Length
Cdn
X-TWH-CORRELATION-ID
X-CMS-Context
X-Servedbyhost
Nel
CF-IPCountry
X-StackifyID
X-LAGOON
X-Wa
X-Cluster-Node
X-WR-MODIFICATION
X-Aicache-OS
X-Fastly-Country-Code
NGX
CDN
X-Load-Cache
FSS-Cache
X-Sentry-ID
X-HTML-Minification-Powered-By
GeoIP-Country-Code
FSS-Proxy
GeoIP-Latitude
X-NodeID
X-Ratelimit-Remaining
X-Check-Cacheable
X-ABtesting
GeoIp-Country-Code
XServer
X-CSRF-TOKEN
X-VServer
X-Fastly-Backend-Reqs
X-Flog
X-Hello
Geoip-Latitude
X-Varnish-Beresp-TTL
X-WA
SN
X-Source
Amp-Access-Control-Allow-Source-Origin
X-UPSTREAM-Address
X-FireWall-Port
Cf-Ipcountry
X-APP
Processtime
X-GZip
X-Csrf-Token
X-Generation-Time
X-HOST
X-Varnish-Cache-Hits
X-Unique-Id
TSSecure
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-CSRF-Token
CACHE
X-Oracle-Dms-Ecid
X-DataStream-MidMile-RTT
X-Oss-Storage-Class
X-MServer
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Sedo-Request-Id
X-ServedByHost
WP-Super-Cache
X-DataStream-Origin-MEX-Latency
X-CDN-Pop
X-CDN-Pop-IP
X-Cache-Miss-From
X-Worker
A
X-Dynatrace
URI
X-Cache-Grace
X-Edge-Server
PageType
Cdn-Request-Time
X-Nananana
Cdn-Host
X-SRV
X-GDPR
Server-Cache-Control
Pics-Label
X-Varnish-Authentication
X-Cache-ASPX
Server-Surrogate-Control
X-FORWARDED-FOR
X-VC-Cache
X-Skip-Cache
X-SplitTest
DataCenter
X-AWS-Id
X-ID
X-LJ-Flow-ID
X-VWS-Id
X-RCS-Backend
X-IPS-LoggedIn
X-Fastly-Cache-Hits
HTTPS
X-HS-Status
X-Sucuri-Cache
X-Port
X-BE
X-Varnish-Url
Odigeo-Trace-Id
X-Backend-TTL
X-VG-WebCache
X-B3-SpanId
Cache-Hits
X-Swift-Error
X-PJAX-URL
X-Owner
X-From-Cache
X-Instart-Isnd
Dynatrace
X-ND-Cache
X-Pf-Uncompressing
Hostname
X-Ms-Blob-Type
X-Ms-Lease-Status
Requestid
Get-Access-Time
X-Ms-Request-Id
Is-Session-Tracking
X-Ms-Version
X-GZIP
X-SN
X-Gen-Id
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
X-Bug-Bounty
X-Atg-Version
FastCGI-Cache
Proxy-Firewall
X-Server-W
X-VarnPar2
ProcessTime
X-GoCache-CacheStatus
X-NGINX-Cache
X-Cache-Ttl
X-ORIG-AKA-EDGE
Serverid
X-Amz-Meta-S3b-Last-Modified
X-Akamai-SSL-Client-Sid
X-RAMCache
X-Alicdn-Da-Ups-Status
X-Ms-Lease-State
X-PAGE-TYPE
X-Varnish-URL
X-Fe
X-LiteSpeed-Cache-Control
T-Server
X-ServerName
X-VC
WebServer
RequestUuid
X-SB
X-GEO
X-Serial
X-ORIG-AKA-COUNTRY-CODE
Correlation-Id
Xet-Cookie
X-LiteSpeed-Tag
Powered
X-CS
NnCoection
X-Cache-Srv
SID
X-HTML-Edge-Cache
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-Developed-By
Location
NodeID
X-Dw-Trace-Id