Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
Last-Modified
Accept-Ranges
X-Content-Type-Options
Pragma
X-Powered-By
CF-RAY
ETag
Link
Expect-CT
Via
X-XSS-Protection
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Id
X-Served-By
Referrer-Policy
X-Xss-Protection
X-Varnish
X-Request-Id
X-Timer
CF-Cache-Status
X-AspNet-Version
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Runtime
X-Download-Options
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Cacheable
Alt-Svc
X-Generator
X-Check
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Cache-Status
X-AspNetMvc-Version
X-DNS-Prefetch-Control
Status
Timing-Allow-Origin
X-Template
X-Language
X-Permitted-Cross-Domain-Policies
X-FRAME-OPTIONS
X-Iinfo
Content-Encoding
X-CDN
X-Content-Security-Policy
X-Buckets
X-Turbo-Charged-By
X-Type
Upgrade
WPE-Backend
X-Pass-Why
X-Request-ID
Keep-Alive
X-Cache-Group
X-AH-Environment
Xkey
X-Backend
Access-Control-Max-Age
X-Age
Access-Control-Expose-Headers
X-Via
EagleId
X-Drupal-Dynamic-Cache
X-Nginx-Cache-Status
X-Server-Powered-By
X-Amz-Request-Id
X-Amz-Id-2
X-Pingback
X-Server
X-Swift-CacheTime
X-Swift-SaveTime
X-Hacker
Grace
X-UA-Device
Ali-Swift-Global-Savetime
X-Varnish-Cache
X-Robots-Tag
P3p
Cf-Railgun
X-Proxy-Cache
X-Envoy-Upstream-Service-Time
X-Ua-Compatible
X-Page-Speed
X-LiteSpeed-Cache
Request-Context
X-Device
X-Ac
Content-Location
X-Kinja-Server-Push
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Lookup
X-Amz-Version-Id
X-Response-Time
X-OneAgent-JS-Injection
X-Host
X-Backend-Server
Surrogate-Control
X-Cnection
X-Rq
X-Readtime
X-Server-Id
X-Rack-Cache
Server-Timing
Report-To
X-Node
X-Cloud-Trace-Context
EagleEye-TraceId
X-WebKit-CSP
X-Application-Context
Request-Id
Feature-Policy
X-ORACLE-DMS-ECID
X-Instart-Request-ID
X-Iejgwucgyu
X-Clacks-Overhead
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Edge-Control
X-CST
Pinterest-Generated-By
X-Country
NEL
X-Px
X-Url
Rating
X-Server-Name
X-Country-Code
X-Ruxit-JS-Agent
X-DataDome
X-TTL
X-Origin-Cache
X-Varnish-TTL
X-DynaTrace
X-MS-InvokeApp
Allow
X-Vhost
X-PC
X-Cached
X-Vname
X-TtlSet
X-FTR-Request-ID
RTSS
X-ESI
X-Goog-Hash
X-Powered-CMS
Charset
X-Powered-By-Plesk
X-DynaTrace-JS-Agent
X-VARITI-CCR
X-Server-ID
Accept-CH
X-Dispatcher
Public-Key-Pins
X-D2id
X-GitHub-Request-Id
X-Mod-Pagespeed
X-Oracle-Dms-Rid
Arc-Version
PB-RID
PB-PID
X-Mobile-Rewrite
X-F-Cache
X-Trace
X-Kinja-Build
X-Kinja
X-Exp-Variant
X-GoogleNews-Bot
X-Kinja-Revision
X-Cdn-Fetch
X-Kinja-Server
X-Exp-Id
X-Version
MS-Author-Via
Content-MD5
SPRequestGuid
Verso
X-SharePointHealthScore
X-T
X-Recruiting
Nginx-Cache
X-Abt-Application-Version
X-Client-IP
X-Shield-Request-Id
SPRequestDuration
SPIisLatency
X-Forwarded-Proto
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
Accept-CH-Lifetime
X-N
X-HW
X-DIS-Request-ID
X-B3-TraceId
X-Navigation-Version
X-Dw-Request-Base-Id
X-Amz-Rid
Pinterest-Version
X-Upstream-Env
X-Pinterest-Rid
X-Webkit-Csp
X-Origin-Upstream-Status
Fastly-Restarts
X-Upstream
X-XRDS-Location
X-SRCache-Fetch-Status
X-SRCache-Store-Status
AR-PoweredBy
AR-ATIME
AR-CACHE
X-B
X-Fastly-Request-ID
Paypal-Debug-Id
X-ORACLE-DMS-RID
X-Hits
X-Wix-Server-Artifact-Id
X-Amz-Meta-S3cmd-Attrs
X-Accel-Buffering
TCN
Realpath
DynaTrace
Arr-Disable-Session-Affinity
X-Content-Options
X-Pad
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-NF-Request-ID
Service-Worker-Allowed
X-Content-Digest
X-Id
X-Goog-Storage-Class
Tracecode
X-Ser
Access-Control-Request-Method
X-Acc-Meta-Resource-Type
X-Varnish-Age
S
Front-End-Https
X-Amz-Cf-Pop
X-Debug
X-Mrf-Item-Lastmod
Mrf-Cache-Status
MRF-Tech
X-Mrf-Section-Lastmod
X-Middleton-Display
Display
X-Sol
X-Vcap-Request-Id
X-RateLimit-Remaining
X-FastCGI-Cache
X-Kinsta-Cache
X-PressLabs-Stats
X-MSEdge-Ref
X-FTR-DC
X-Country-Code-Real
X-IPLB-Instance
X-FTR-Cache-Status
X-FTR-Realm
X-FTR-Balancer
X-FTR-Backend-Server
X-Frontend
X-FTR-Backend
X-FTR-Expires
X-Cache-Hit
X-ATG-Version
Surrogate-Key
Powered-By-ChinaCache
X-Geo-Segment
X-HS-Hub-Id
X-Forwarded-For
X-HS-Content-Id
X-Zen-Fury
X-Grace
Fastcgi-Cache
X-Middleton-Response
Response
X-NewRelic-App-Data
Rt-Fastcgi-Cache
X-CF-Powered-By
Server-Name
X-Logged-In
X-Oneagent-Js-Injection
X-Analytics
Backend-Timing
X-Litespeed-Cache
X-Mobile
X-Debug-Info
Host
X-SS-Set-Cookie
X-Akam-SW-Version
X-Revision
X-Rid
X-FTR-Cache-Host
FilterID
X-Amzn-Trace-Id
X-Request-Received
X-Request-Processing-Time
X-Edge-Location
TP-Cache
TP-L2-Cache
X-User-Agent
AMP-Access-Control-Allow-Source-Origin
X-TA-CDN-Provider
MicrosoftSharePointTeamServices
Cache-Status
X-Ttl
Edge-Cache-Tag
X-Cached-By
X-Cache-Key
X-Accel-Expires
X-SERVER
X-Drupal-Cache-Tags
Refresh
X-Magnolia-Registration
Host-Header
Ar-Sid
X-GUploader-UploadID
X-Cache-Rule
Liferay-Portal
ServerID
X-Varnish-Backend
X-Webkit-CSP
X-Node-Name
X-AOL-HN
X-Akamai-Edgescape
X-Framework
X-Newrelic-App-Data
X-Platform-Server
X-FB-Debug
X-HS-Cache-Config
X-Whom
Cache-Tag
DC
X-B3-Sampled
X-Tumblr-Pixel-0
X-Cluster
X-Tumblr-User
X-Varnish-Hostname
X-Tumblr-Pixel
X-Content-Security-Policy-Report-Only
X-Cache-Control
X-Cache-2
X-B-Cache
X-Signature
X-Instance
X-Page-Id
X-Device-Type
X-App-Environment
X-Request-Guid
X-LB-Cache
Public-Key-Pins-Report-Only
Cleartype
Accept-Charset
X-BCube-Filmed-By
X-Handled-By
X-Srv
X-Az
X-AppVersion
X-Activity-Id
Eomportal-Instance
X-WPE-Loopback-Upstream-Addr
X-B3-TraceId-Primal
X-Generated-By
X-TT
AR-Request-ID
X-Fastcgi-Cache
X-Use-Magma
Upgrade-Insecure-Requests
X-App-Version
X-Cache-Action
X-Cache-Server
X-Seen-By
X-Wix-Request-Id
MS-CV
X-Drupal-Cache-Contexts
X-Via-JSL
ViewerVersion
X-NWS-LOG-UUID
X-Correlation-Id
X-App-Server
X-Esi
Source
X-Amz-Replication-Status
Retry-After
X-VCache
X-Content-Powered-By
HostName
Alternate-Protocol
X-URL
X-Varnish-Server
Server-Node
X-WA-Info
X-Adobe-Content
X-Adobe-Loc
X-Cache-NE
SRV
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
X-Response-Served-From
X-Hostname
Actual-Object-TTL
X-Cache-TTL-Remaining
X-FW-Serve
X-FW-Server
X-WebKit-CSP-Report-Only
X-FW-Static
X-Jobs
X-FW-Hash
X-Status
X-UUID
X-GeoIP
X-Locale
X-FW-Type
X-Amzn-RequestId
X-RequestSource
X-Amz-Apigw-Id
X-Edge-Cache
X-Edge-Cache-Key
Webserver
AsisCache
Payment
X-Varnish-Grace
CACHE
AR-SID
GEO-INFO
ServedBy
X-Servedby
X-Contextid
X-Geo-Country
X-Yottaa-Metrics
X-Varnish-Hits
Viewport
X-Yottaa-Optimizations
X-HS-Combine-CSS
X-S
X-TX-ID
X-Varnish-IP
X-Dns-Prefetch-Control
X-TT-TIMESTAMP
X-Vg-Webcache
Pagespeed
Country
X-Origin-Server
PageSpeed
X-Cache-Operation
X-Correlation-ID
X-RateLimit-Limit
X-Sucuri-ID
X-Cacheable-TTL
X-Daa-Tunnel
Served-By
Server-Info
Datacenter
X-Region
X-Hyper-Cache
X-Cache-Age
X-Real-IP
X-Akamai-Request-ID2
From-Origin
X-Amz-Server-Side-Encryption
X-Forwarded-Host
Content-Script-Type
Content-Style-Type
X-Mode
HitType
X-Ezoic-Cdn
HitInfo
Cache
X-DataStream-Cache-Status
X-XRDS-LOCATION
X-Detected-As
X-Cache-Var-Map
X-Cache-Var
Azure-RegionName
X-Hit
X-Proxied
X-Routing-Service
X-Rocket-Nginx-Bypass
X-Akamai-Transformed
X-JoinUs
X-Rule
X-RN-RSRV
X-Section
X-ServerID
X-Rendered-As
Fastcgi-X-Cache
X-Access
X-Format
Access-Control-Allow-Method
Azure-InstanceId
X-App-Name
X-Amz-Meta-Surrogate-Control
Azure-Version
Machine
X-Proxy
Meta-Geo
Fastcgi-X-Cache-Version
Azure-SlotName
Azure-SiteName
X-Generated
X-TIME
S-Cnection
X-Zipkin-Id
X-Tb
X-Is-Bot
X-Site-Version
X-Upgrade-Enabled
TWC-Device-Class
TWC-Connection-Speed
TWC-GeoIP-LatLong
TWC-Privacy
X-Request-Time
TWC-Locale-Group
X-Ocache
TWC-GeoIP-Country
Now
LB
L5d-Success-Class
X-Origin-Hint
Fastcgi-Useragent
X-Origin
X-Cache-Config
OT-Force-Account-Verify
Webcakes-App-Name
Mn-Server-Ip
Property-Id
Webcakes-Region
X-L-Path
X-TWH-CORRELATION-ID
Webcakes-App-Version
Healthy
X-Environment-Context
X-Hosted-By
X-Grey
X-Content-Type
X-Cache-Category-Id
X-CDN-Cache
X-NGENIX-Cache
DB-Nickname
X-Source
X-Agile
X-VG-TLSProxy
X-Agile-Age
X-Agile-Id
X-Human
X-EIG-Tracking-Id
X-OCL
X-FC-Vary-Parameters
X-Loop
Cache-Name
X-Viewer-Country
X-Via-Fastly
X-Birta-Cache-Post
X-PCL
X-Birta-Served
X-Upstream-HT
X-Upstream-CT
X-Distil-CS
Xserver
X-TNCMS
S-Rt
X-LJ-Flow-ID
X-ProxyCache-Status
X-IP
X-SplitTest
X-RemovedCookies
X-AWS-Id
X-Cluster-Node
X-BYPASS-REASON
X-VWS-Id
X-ProxyCache-Key
X-Xfnlog-Site
X-Pc-Hit
IBM-Web2-Location
X-OVcl
X-Pc-Appver
X-ProcessESI
X-Pc-Key
X-OVcl-Cache
X-CCM
X-Original-Request
X-Timing-Wait
X-Ms-Lease-Status
X-Labrador-Cache-Channel
X-Ms-Request-Id
X-Cache-Enabled
X-Ms-Blob-Type
Selected-FE
X-Microcachable
Accept-Language
X-Www-Served-By
X-Ms-Version
X-Pubstack
X-Proxy-Build
X-ShopId
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-ShardId
Access-Control-Request-Headers
X-Alternate-Cache-Key
X-Shopify-Stage
X-NodeID
X-GRACE
X-Path-Route
X-RTag
X-Port
X-Web-Node
X-Transaction
X-Guploader-Uploadid
X-Twitter-Response-Tags
Cache-Hits
X-Via-CDN
X-Connection-Hash
X-HOST
X-Unique-ID
Ms-Operation-Id
X-Cache-Remote
User-Agent
X-MP-GENERATED-AT
Time
Origin-Edge-Control
Origin-Cache-Control
Backend
NtCoent-Length
X-UA
X-Origin-CC
X-Geo
X-Varnish-Cacheable
X-Nginx-Cache
X-Varnish-Cache-Hits
X-Debug-Cache
X-Edge-IP
X-Cdn-Forward
We-Hiring
X-Cache-TTL
Mail-Subject
X-Sucuri-Cache
X-NODE
X-CACHE-KEY
X-Real-Ip
X-Pc-Date
X-Pc-Host
X-APP-VERSION
X-NCache
X-Internal-Host
X-Tumblr-Pixel-3
NGB
Fastly-SSL
X-Proto
X-Csrf-Token
X-Mrs-Age
X-Mrs-Cache
X-Mshield-Cache-Status
X-CACHE-GROUP
Filters
X-Mrs-Cache-Hits
X-Newrelic-Synthetics
X-Ruxit-Js-Agent
Warning
X-ApacheServer
X-PERF
X-Ratelimit-Limit
X-Vgn-Hpd-Reason
X-Ua
Locale
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Storage
X-Akamai-Request-ID
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-Webstats-RespID
Cache-Key
X-Time-Microsecs
X-CDN-Forward
X-C
X-EdgeConnect-Cache-Status
X-Backend-Name
X-ElasticPress-Search
X-Dc
X-Nc
X-Dynatrace-Js-Agent
X-Endurance-Cache-Level
X-CACHE-AGE
User-Cache-Control
WZWS-RAY
X-Powered-By-ANYU
X-Cache-Bucket
Resin-Trace
Origin
X-Generated-In
Rendered-Blocks
X-Logtrace-Id
X-Irp-Debug
Rt-Proxy-Cache
X-Distributor
X-Died
Server-Host
Server-Int
X-DPWN-IS-SECURE
X-Epic-Correlation-Id
X-Gannett-Site-Version
X-GeoIP-Country-Code
Odigeo-Trace-Id
Section-Io-Cache
X-Cache-Srv
X-Matched-Rule
HA-Geolon
HA-Geolat
HA-Georegion
Ha-Gx-Prefs
HA-Host
HA-Geocountry
HA-Geocity
FSS-Proxy
FSS-Cache
X-Org
GMS-Ver
HA-Cloudapp
HA-Ipaddr
HA-Servedtime
X-MSEdge-Flight
Meta-Geo-Continent
X-MSEdge-Features
Mobile-Detection-Method
X-CF-Lambda-Fn
MD5-Digest
Magicmarker
HA-Urlpath
X-NU-AKA-ACS-Version
IsBot
X-Nginx-Cache-Key
NodeID
Thinkindot-CacheControl-Type
X-Amz-Meta-Cache-Control
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Application
X-Fastly-Cache
X-Hl-Ver
X-F5-Cache
Fly-Request-Id
X-Accel-Expires-Debug
X-Date
X-Aed
X-D
X-Hash
X-Core-Mission
X-Backend-TTL
X-G
X-BB-ID
X-From
X-Croise-Owner
X-BBXSRF
X-B-Cookie
X-Backend-Host
X-Fetched-On
X-A-Wwc
X-A-Dgt
X-Developers
X-IN-SSL-APIGATEWAY
UCS
V-Age
TSSecure
Thinkindot-Control
X-IN-WAF
Thinkindot-CacheControl
X-Backend-Url
X-External-Request-Id
Viewtype
VivaBuild
X-Destination
X-A-Ccd
X-A-Dam
X-A-Dcw
X-CGP
X-CF-Lambda-Version
X-IN-APIGATEWAY
Www
X-A
X-Developer
SN
X-Platform
Fly-Cache
X-S-Cookie
X-Secret
X-Server-By
X-Server-Time
X-Rojux
X-Rewrite-Enabled
Apple-News-Services-Handled
Apple-News-Services-Host
Ajk
Cache-Tags
X-Region-Sid
X-SIPLIST1
X-SRCache-Key
X-Via-SSL
X-Via-Edge
X-Wikidot-Backend
X-Wikidot-Static-Cache
Xc-Version
X-VG-WebServer
X-Up
X-Store
X-Thinkindot-L3
X-Trv-Group
X-UE-Client-Country
Apple-News-Services-Parsed-Url
X-ScT
X-Eu-Site
Cache-Prefix
X-Phone
Apple-News-Services-Request-Url
Ec-Rule-Version
Content-Disposition
BehaviorPad-Version
X-PAYTM-SRV-ID
Arc-Country
X-TT-LOGID
Countrycode
Memcached
X-UnsetCookies
X-GeoIP-City
X-User
GW-Server
X-Backend-State
X-Auto-Login
X-ABtesting
AKAMAI
X-Server-IP
X-Sn-Servicetimems
X-No-Session
X-Cache-CFC
X-Hello
Country-Code
X-Cache-Expires
X-Worker
X-Flog
X-Core-Value
Frame-Options
X-Debug-Cookies
X-Dispatcher-Server
X-Debug-Log
X-We-Are-Hiring
X-Fstrz
X-Cdn-Origin
X-Cache-URL
X-Cache-Host
X-Owner
X-VServer
X-FW-Version
X-Clientip
Backend-Name
X-Swa-Ws
Pramga
RNT-Machine
X-Redis-Cache
RNT-Time
Release
X-Cache-Backend
X-Release
Server-ID
X-Response-By
X-Location
X-Reboot
X-Request-Start
X-NX-Host
Heartbleed
Cache-Cookie-Set-Lfrom
X-Layer
X-S-Maxage
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-From
X-Key
X-Varnish-Beresp-Ttl
X-NC
X-BB-IP
X-Datadome
X-B3-Spanid
X-Li-Pop
X-WebServer
X-Passed-To-BeforeDispatch
X-LI-Proto
Decoy-Debug-Key
X-ServiceProvider
X-V
X-Rebelmouse-Cache-Control
Fastly-Soc-X-Request-Id
X-Request-URI
Decoy-Debug-TTL
X-LI-UUID
X-Node-Id
X-Rebelmouse-Surrogate-Control
Decoy-Debug-Status
X-Passed-To
X-Gen-Mode
X-Thanos
X-Returned-From-PostProcessResponse
X-Returned-From-DLL
X-Trace-Id
X-RCS-CacheZone
X-Stale
X-Sentry-ID
X-MI-In-Market
X-Sf
X-Hnp-Log
X-Returned-From-BeforeDispatch
X-Returned-From
X-VCT
X-Policy
X-Passed-To-PostProcessResponse
X-Passed-To-DLL
X-Served-From
X-Varnish-Action
X-Instance-Name
X-Request-UUID
X-Var-Ttl
X-Variation
X-Li-Fabric
X-Cache-Debug
MI-Cache
MI-Cache-Age
Kp-EeAlive
X-Bip
X-Block-Status
Platform
X-Actual-URL
Request-Country
Request-EU
Uber-Trace-Id
Web-Mar-Node
Pragrma
X-Cache-Id
Is-Eu
CDCHOST
X-CUA
Adler-Geo
X-Device-Os
Esi-Enabled
X-Crawler
Fastly-Backend-Name
Fastly-SWR
Fastly-SIE
Pagetype
X-Via-NSCOPI
X-PHP-Backend
Proxy-Connection
REQUESTUUID
X-DC
X-UA-Device-Type
True-Client-Country-4JS
X-Info
X-Ms-Lease-State
X-P-T
On-Server
X-Qloud-Router
Amp-Access-Control-Allow-Source-Origin
RequestId
Cteonnt-Length
MI-API
HTTPS
X-SN
ProcessTime
Powered-By
X-Page-Type
X-Pjax-Url
X-Ckpd-Fst-Backend
X-Be
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-CLOUD-TRACE-CONTEXT
MIME-Version
X-Req
X-Servername
Cdn
X-Refresh
X-NWS-UUID-VERIFY
X-Oracle-Dms-Ecid
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-Origin-TTL
X-Oss-Object-Type
X-Origin-Response-Time
X-SVT-ORM-RULES
X-Oss-Storage-Class
X-SVT-ORM-VERSION
X-Oss-Request-Id
X-GZip
X-MServer
Memory
Version
X-Content-Age
X-Parent-Response-Time
X-Cache-FS-Status
CF-IPCountry
Mime-Version
V-Cache
Who
Group
X-Unique-Id-Primal
X-Aicache-OS
X-Time
X-ND-Cache
X-Servedbyhost
X-Varnish-Url
X-Vcache
X-COUNTRY
Fusion-Source
X-Pf-Uncompressing
X-Generation-Time
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
Fusion-Content-Source
Fusion-Template-Id
X-Wa
X-Varnish-Beresp-TTL
SS
X-FireWall-Port
Fusion-Component-Id
GeoIP-Country-Code
Fusion-Content-Id
X-GEO
X-Cache-Info
Cdn-Host
X-Unique-Id
X-Edge-Server
X-Fastly-Cache-Hits
X-SRV
Cdn-Request-Time
CDN
GeoIP-Latitude
PageType
Get-Access-Time
Is-Session-Tracking
X-Qnm-Cache
X-M-Reqid
X-M-Log
XServer
X-CS
X-EC-Security-Audit
X-Protected-By
Geoip-Latitude
GeoIp-Country-Code
X-B3-Traceid
T-Server
X-WA
X-APP
X-Server-W
Load-Balancing
X-Surge-Debug
Serverid
NGX
X-Server-Group
X-Ratelimit-Remaining
ServerName
SD-X-WS
X-Requestid
X-HTML-Minification-Powered-By
X-Check-Cacheable
X-Origin-Expires
X-Origin-Date
Nel
A
X-ID
X-CSRF-Token
Cf-Ipcountry
X-Nananana
X-SERVER-NAME
X-RequestId
X-ServedByHost
DataCenter
X-StackifyID
X-ARC
X-HS-Status
X-Alicdn-Da-Ups-Status
X-Skip-Cache
Processtime
X-FORWARDED-FOR
Hostname
X-Gdpr
URI
PICS-Label
X-Fastly-Country-Code
X-GZIP
X-UPSTREAM-Address
X-Feature
X-NGINX-Cache
X-Proxy-Server
X-Load-Cache
X-PF-Uncompressing
X-ServerName
WP-Super-Cache
X-B3-SpanId
Cache-Provider
Lfy
X-Fe
X-PAGE-TYPE
Cneonction
X-BE
X-Origin-Host
X-VG-WebCache
X-Cdn-Srv
X-DataStream-MidMile-RTT
X-DataStream-Origin-MEX-Latency
X-PHP-Host
Node
Powered
X-Atg-Version
X-Proxy-Upstream
X-Proxy-Cache-Status
X-Content-Encoded-By
RequestUuid
X-IPS-LoggedIn
X-PJAX-URL
Https
Requestid
VIX-Pulpo-Node
X-HTML-Edge-Cache
VIX-Pulpo-Upstream-Status
Vix-Hermes-Req-Id
X-VC
X-Distil-Cs
X-Fastly-Backend-Reqs
X-From-Cache
Sid
X-Cache-Ttl
X-SB
N-Cache
X-Akamai-SSL-Client-Sid
X-CSRF-TOKEN
X-Grace-Duration
X-Serial
X-GDPR
Xet-Cookie
X-RAMCache
Host-ID
X-WR-MODIFICATION
X-Dw-Trace-Id
X-Gen-Id
Build-Number
Cdn-Src-Port
PFcat
SID