Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
Last-Modified
X-Content-Type-Options
Accept-Ranges
Pragma
X-Powered-By
CF-RAY
Link
ETag
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Id
X-Served-By
Referrer-Policy
X-Varnish
X-Request-Id
X-Timer
CF-Cache-Status
X-AspNet-Version
Access-Control-Allow-Headers
X-Xss-Protection
Access-Control-Allow-Methods
X-Runtime
X-Download-Options
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Cacheable
Alt-Svc
X-Check
X-Generator
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Cache-Status
X-AspNetMvc-Version
Status
X-DNS-Prefetch-Control
X-Template
X-Language
Timing-Allow-Origin
X-Permitted-Cross-Domain-Policies
X-FRAME-OPTIONS
Content-Encoding
X-Iinfo
X-Content-Security-Policy
X-CDN
X-Buckets
X-Turbo-Charged-By
X-Request-ID
Upgrade
X-Type
WPE-Backend
Keep-Alive
X-Pass-Why
CF-Ray
X-Cache-Group
X-AH-Environment
Xkey
P3p
X-Backend
Access-Control-Max-Age
X-Age
Access-Control-Expose-Headers
X-Via
X-Drupal-Dynamic-Cache
EagleId
X-Pingback
X-Nginx-Cache-Status
X-Amz-Id-2
X-Amz-Request-Id
X-Kinja-Server-Push
X-Server-Powered-By
X-Server
X-Hacker
Grace
X-UA-Device
X-Swift-CacheTime
X-Swift-SaveTime
X-Varnish-Cache
X-Robots-Tag
Ali-Swift-Global-Savetime
Cf-Railgun
X-Proxy-Cache
X-Envoy-Upstream-Service-Time
X-LiteSpeed-Cache
X-Page-Speed
X-Ua-Compatible
Request-Context
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Ac
Content-Location
X-Cache-Lookup
X-Amz-Version-Id
X-WebKit-CSP
X-Response-Time
Surrogate-Control
X-Host
X-OneAgent-JS-Injection
X-Rq
X-Cnection
X-Node
Server-Timing
X-Backend-Server
X-Readtime
Report-To
X-Rack-Cache
X-Server-Id
Request-Id
EagleEye-TraceId
X-Application-Context
Feature-Policy
X-Cloud-Trace-Context
X-ORACLE-DMS-ECID
X-Instart-Request-ID
X-CST
X-Iejgwucgyu
Edge-Control
X-EdgeConnect-MidMile-RTT
X-Clacks-Overhead
X-EdgeConnect-Origin-MEX-Latency
NEL
Rating
X-Country
X-TTL
X-Server-Name
X-DynaTrace
X-Varnish-TTL
X-MS-InvokeApp
X-Url
Allow
X-Px
X-Country-Code
X-Origin-Cache
Pinterest-Generated-By
X-DataDome
X-Vhost
X-PC
X-Vname
X-TtlSet
X-Cached
X-FTR-Request-ID
X-Server-ID
X-Ruxit-JS-Agent
X-ESI
RTSS
SPRequestGuid
X-Trace
X-Goog-Hash
X-VARITI-CCR
Charset
X-SharePointHealthScore
X-Powered-By-Plesk
X-GitHub-Request-Id
X-T
Accept-CH
X-DynaTrace-JS-Agent
X-Dispatcher
X-B3-TraceId
X-Powered-CMS
Public-Key-Pins
X-Mod-Pagespeed
X-D2id
Arc-Version
PB-PID
X-Mobile-Rewrite
PB-RID
X-F-Cache
X-Cdn-Fetch
X-Exp-Variant
Verso
X-Kinja-Build
X-Kinja-Revision
X-Kinja
X-Exp-Id
X-GoogleNews-Bot
X-Kinja-Server
Content-MD5
SPIisLatency
SPRequestDuration
X-Version
X-Shield-Request-Id
MS-Author-Via
X-Dns-Prefetch-Control
X-Oracle-Dms-Rid
X-Recruiting
X-Abt-Application-Version
X-ORACLE-DMS-RID
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Forwarded-Proto
Nginx-Cache
Accept-CH-Lifetime
X-Client-IP
X-HW
X-DIS-Request-ID
X-N
X-Navigation-Version
Pinterest-Version
X-Upstream-Env
X-Pinterest-Rid
AR-PoweredBy
AR-ATIME
AR-CACHE
X-B
X-Amz-Rid
X-Fastly-Request-ID
DynaTrace
X-Origin-Upstream-Status
X-Upstream
X-Ser
X-Dw-Request-Base-Id
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Amz-Meta-S3cmd-Attrs
X-Hits
TCN
Realpath
Fastly-Restarts
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Goog-Generation
X-XRDS-Location
X-Wix-Server-Artifact-Id
X-Accel-Buffering
Paypal-Debug-Id
Arr-Disable-Session-Affinity
X-Content-Options
Service-Worker-Allowed
X-NF-Request-ID
X-Pad
X-Acc-Meta-Resource-Type
X-Goog-Storage-Class
S
Tracecode
X-Use-Magma
Access-Control-Request-Method
X-Content-Digest
X-Id
X-Debug
X-Varnish-Age
Edge-Cache-Tag
X-Vcap-Request-Id
X-Oneagent-Js-Injection
Front-End-Https
X-MSEdge-Ref
Mrf-Cache-Status
X-Mrf-Item-Lastmod
MRF-Tech
X-Mrf-Section-Lastmod
X-Frontend
X-IPLB-Instance
X-FTR-Realm
X-Country-Code-Real
X-FTR-Balancer
X-FTR-Backend
X-FTR-Cache-Status
X-FTR-DC
X-FTR-Backend-Server
X-PressLabs-Stats
X-RateLimit-Remaining
X-FTR-Expires
X-Kinsta-Cache
MicrosoftSharePointTeamServices
X-Logged-In
X-ATG-Version
X-B3-TraceId-Primal
X-HS-Content-Id
X-HS-Hub-Id
Rt-Fastcgi-Cache
Surrogate-Key
X-Request-Processing-Time
X-Request-Received
X-Cache-Hit
X-Forwarded-For
Fastcgi-Cache
X-Amz-Cf-Pop
X-FastCGI-Cache
X-Sol
Display
X-Middleton-Display
X-Zen-Fury
X-Edge-Location
AMP-Access-Control-Allow-Source-Origin
X-Litespeed-Cache
Backend-Timing
X-Analytics
X-Amzn-Trace-Id
X-Debug-Info
Powered-By-ChinaCache
X-Rid
X-HS-Cache-Config
Server-Name
Host
X-User-Agent
X-Revision
X-Newrelic-App-Data
X-FTR-Cache-Host
TP-L2-Cache
TP-Cache
FilterID
X-Cache-Key
X-Akam-SW-Version
X-CF-Powered-By
AR-Request-ID
Response
X-Middleton-Response
X-TA-CDN-Provider
X-Drupal-Cache-Tags
X-Magnolia-Registration
X-Grace
X-SS-Set-Cookie
Ar-Sid
X-Mobile
X-SERVER
X-Fastcgi-Cache
Refresh
Cache-Status
X-Accel-Expires
X-Cached-By
X-VCache
X-GUploader-UploadID
X-B3-Sampled
Host-Header
X-NWS-LOG-UUID
X-AOL-HN
ServerID
X-Webkit-CSP
X-Varnish-Backend
X-Node-Name
X-Whom
Eomportal-Instance
X-Content-Security-Policy-Report-Only
X-Tumblr-User
X-Via-JSL
X-Cache-2
X-Cluster
X-Instance
X-Signature
X-FB-Debug
X-Tumblr-Pixel-0
X-Device-Type
X-B-Cache
X-NewRelic-App-Data
X-Tumblr-Pixel
X-Cache-Control
X-Webkit-Csp
X-Platform-Server
X-Akamai-Edgescape
X-LB-Cache
X-Ruxit-Js-Agent
X-Page-Id
X-Varnish-Hostname
X-Drupal-Cache-Contexts
X-Framework
X-BCube-Filmed-By
X-Generated-By
Cleartype
X-Handled-By
X-App-Environment
X-Srv
X-Request-Guid
X-URL
X-Cache-Action
X-Cache-Rule
X-Activity-Id
Cache-Tag
X-AppVersion
X-App-Server
X-Az
Alternate-Protocol
DC
Liferay-Portal
Source
X-Ttl
X-Content-Powered-By
Retry-After
X-Hostname
X-Cache-Server
X-HS-Combine-CSS
X-WPE-Loopback-Upstream-Addr
AR-SID
X-WA-Info
X-Varnish-Grace
X-Daa-Tunnel
MS-CV
X-Geo-Country
HostName
X-Varnish-Server
X-Esi
X-Amz-Replication-Status
Public-Key-Pins-Report-Only
Server-Node
X-Seen-By
X-TT
X-App-Version
X-Wix-Request-Id
ViewerVersion
Webserver
X-Correlation-Id
X-Tumblr-Pixel-1
X-Response-Served-From
X-Cache-NE
X-WebKit-CSP-Report-Only
Pagespeed
Accept-Charset
AsisCache
X-Tumblr-Pixel-2
X-GeoIP
Actual-Object-TTL
X-Amzn-RequestId
X-Amz-Apigw-Id
SRV
Upgrade-Insecure-Requests
GEO-INFO
X-RequestSource
X-Jobs
ServedBy
X-Varnish-Hits
Viewport
X-Edge-Cache
X-UUID
Payment
X-S
X-Servedby
X-FW-Type
X-Locale
X-FW-Hash
X-FW-Serve
X-FW-Server
X-Edge-Cache-Key
X-Contextid
X-FW-Static
X-Correlation-ID
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-TX-ID
X-Status
X-Varnish-IP
X-Cacheable-TTL
X-Adobe-Loc
X-Adobe-Content
X-XRDS-LOCATION
X-TT-TIMESTAMP
S-Cnection
X-Origin-Server
X-Cache-TTL-Remaining
X-Hyper-Cache
X-Vg-Webcache
Cache
X-Amz-Server-Side-Encryption
X-Cache-Operation
Server-Info
X-Forwarded-Host
X-Real-IP
Datacenter
X-RateLimit-Limit
X-Cache-Age
X-Geo-Segment
Served-By
X-Region
X-Akamai-Request-ID2
Access-Control-Allow-Method
X-CLOUD-TRACE-CONTEXT
X-Mode
X-DataStream-Cache-Status
Healthy
X-Content-Type
X-GRACE
CACHE
X-Sucuri-ID
X-Akamai-Transformed
X-Ezoic-Cdn
Meta-Geo
X-Proxy
X-Detected-As
X-Environment-Context
X-JoinUs
X-L-Path
X-Ocache
X-Path-Route
X-Is-Bot
X-Generated
Fastcgi-X-Cache-Version
Fastcgi-X-Cache
X-Proxied
Fastcgi-Useragent
Machine
X-Rule
X-Cache-Var
X-Routing-Service
X-Cache-Var-Map
X-Zipkin-Id
X-Rendered-As
X-RN-RSRV
X-Cache-Config
X-Upgrade-Enabled
X-Viewer-Country
DB-Nickname
Country
X-NGENIX-Cache
X-TNCMS
X-Loop
X-Birta-Cache-Post
X-CDN-Cache
X-Birta-Served
X-Amz-Meta-Surrogate-Control
X-Format
X-Agile-Id
X-Section
X-Request-Time
Now
X-Agile-Age
From-Origin
X-Human
L5d-Success-Class
X-Agile
X-Access
X-Hosted-By
Origin-Edge-Control
TWC-Device-Class
TWC-Connection-Speed
X-OCL
X-FC-Vary-Parameters
Cache-Name
X-Grey
X-Hit
X-Origin-Hint
Origin-Cache-Control
X-Labrador-Cache-Channel
X-Via-Fastly
TWC-Locale-Group
Webcakes-App-Version
Webcakes-App-Name
X-Tb
X-PCL
Webcakes-Region
Xserver
OT-Force-Account-Verify
Property-Id
X-CCM
X-ServerID
X-Geo
X-Cache-Category-Id
X-Pc-Key
TWC-GeoIP-LatLong
X-Pc-Hit
X-Pc-Appver
TWC-Privacy
S-Rt
TWC-GeoIP-Country
HitInfo
X-Original-Request
HitType
X-EIG-Tracking-Id
X-Cdn
X-VG-TLSProxy
X-Pubstack
Azure-Version
X-Origin
Accept-Language
X-BYPASS-REASON
X-Upstream-CT
X-OVcl-Cache
X-ProcessESI
X-Site-Version
X-ProxyCache-Key
X-ProxyCache-Status
X-RemovedCookies
Azure-SlotName
X-OVcl
Azure-InstanceId
Azure-RegionName
Azure-SiteName
X-IP
X-Xfnlog-Site
NGB
X-Upstream-HT
X-Web-Node
Selected-FE
X-Alternate-Cache-Key
X-Microcachable
X-ShardId
Mn-Server-Ip
X-Sorting-Hat-PodId
X-Timing-Wait
X-ShopId
X-Proxy-Build
LB
X-Www-Served-By
X-Shopify-Stage
X-Via-CDN
X-Sorting-Hat-ShopId
X-Cluster-Node
Filters
X-App-Name
X-TWH-CORRELATION-ID
X-UA-Device-Type
X-Cache-Remote
Ms-Operation-Id
X-Connection-Hash
X-Transaction
X-Twitter-Response-Tags
X-Rocket-Nginx-Bypass
X-RTag
X-Cache-Enabled
X-NCache
X-Internal-Host
X-Tumblr-Pixel-3
X-UA
Time
X-Pc-Date
X-Pc-Host
X-Cache-TTL
X-Guploader-Uploadid
Access-Control-Request-Headers
X-PHP-Backend
IBM-Web2-Location
X-APP-VERSION
X-TIME
X-Unique-ID
X-Proto
X-VWS-Id
X-Nginx-Cache
X-SplitTest
X-LJ-Flow-ID
X-AWS-Id
X-NodeID
X-Origin-CC
Content-Script-Type
Content-Style-Type
Cache-Hits
Mail-Subject
We-Hiring
NtCoent-Length
X-Storage
X-Vgn-Hpd-Reason
X-Cdn-Forward
X-MP-GENERATED-AT
X-Datadome
X-Real-Ip
X-Time-Microsecs
X-Port
X-Edge-IP
X-Source
X-Webstats-RespID
X-Akamai-Request-ID
Backend
Cache-Tags
X-Varnish-Cacheable
X-Backend-Name
X-Ms-Blob-Type
X-Debug-Cache
X-Ms-Request-Id
X-Ms-Version
X-Ms-Lease-Status
X-CACHE-KEY
X-Distil-CS
X-Csrf-Token
X-Oracle-Dms-Ecid
X-Endurance-Cache-Level
X-CACHE-GROUP
X-Urbn-Site-Id
Locale
X-Urbn-Context-Path
X-CACHE-AGE
X-Origin-Response-Time
X-Ua
X-Redis-Cache
X-B3-Spanid
PageSpeed
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
X-Ratelimit-Limit
Warning
X-Croise-Owner
X-EdgeConnect-Cache-Status
User-Agent
X-NWS-UUID-VERIFY
X-NC
X-A-Wwc
X-A-Dam
X-Accel-Expires-Debug
X-A
X-BBXSRF
X-A-Ccd
X-A-Dcw
X-A-Dgt
X-Aed
X-External-Request-Id
X-BB-ID
X-From
X-F5-Cache
X-B-Cookie
VivaBuild
X-Fetched-On
X-ApacheServer
X-Amz-Meta-Cache-Control
X-Application
X-Eu-Site
TSSecure
HA-Geolon
HA-Geolat
Content-Disposition
Cache-Prefix
HA-Georegion
HA-Host
Ha-Gx-Prefs
Country-Code
HA-Geocountry
Fly-Request-Id
Fastly-SIE
Fly-Cache
Ec-Rule-Version
GMS-Ver
HA-Geocity
HA-Cloudapp
BehaviorPad-Version
HA-Ipaddr
Rt-Proxy-Cache
Resin-Trace
Rendered-Blocks
Server-Host
X-Cache-Bucket
V-Age
UCS
Powered-By
Ajk
HA-Servedtime
Arc-Country
HA-Urlpath
MD5-Digest
Mobile-Detection-Method
Meta-Geo-Continent
Viewtype
X-Cache-URL
X-Rebelmouse-Surrogate-Control
X-Region-Sid
X-Rebelmouse-Cache-Control
X-Debug-Cookies
X-IN-APIGATEWAY
X-Hash
X-Rewrite-Enabled
X-Rojux
X-Developer
X-D
X-Destination
X-CDN-Forward
X-Debug-Log
X-PAYTM-SRV-ID
X-Varnish-Beresp-Ttl
X-PERF
X-Irp-Debug
X-IN-WAF
X-Oss-Server-Time
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Oss-Storage-Class
X-IN-SSL-APIGATEWAY
X-Date
X-Org
X-NX-Host
X-NU-AKA-ACS-Version
X-Logtrace-Id
Fastly-SWR
X-S-Cookie
X-CF-Lambda-Version
X-Store
X-CGP
X-Server-Time
X-UE-Client-Country
X-Trv-Group
X-CF-Lambda-Fn
X-Cache-Backend
X-SRCache-Key
X-ElasticPress-Search
X-Cache-Host
X-Oss-Request-Id
X-Cdn-Origin
X-G
X-VG-WebServer
X-Varnish-Cache-Hits
X-DPWN-IS-SECURE
Xc-Version
X-Died
X-ScT
X-We-Are-Hiring
X-C
X-Via-Edge
X-Server-By
X-Via-SSL
X-Generated-In
X-GeoIP-Country-Code
X-Sn-Servicetimems
Fastly-SSL
Pagetype
Version
X-Mrs-Age
X-Mrs-Cache
X-Mshield-Cache-Status
X-Mrs-Cache-Hits
X-Dc
Cache-Key
X-Hl-Ver
X-Info
X-DC
X-Key
X-Developers
X-Dispatcher-Server
X-Hello
X-FW-Version
X-Flog
X-GeoIP-City
X-Clientip
Www
X-ABtesting
Section-Io-Cache
Uber-Trace-Id
User-Cache-Control
X-Auto-Login
X-Backend-Host
X-Cache-Id
X-Layer
X-Cache-FS-Status
X-Backend-Url
X-Backend-State
X-Core-Value
X-Location
X-Dynatrace-Js-Agent
X-UnsetCookies
X-Trace-Id
X-Thinkindot-L3
X-ServiceProvider
X-SIPLIST1
X-User
X-V
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-VServer
X-Via-NSCOPI
X-Var-Ttl
X-Variation
X-S-Maxage
X-Parent-Response-Time
Fastly-Soc-X-Request-Id
X-Platform
X-Nc
X-No-Session
X-Matched-Rule
X-MServer
X-Qloud-Router
X-Reboot
X-Request-URI
X-Response-By
X-Request-Start
X-Release
X-Time
Thinkindot-Control
X-Epic-Correlation-Id
AKAMAI
RNT-Time
RNT-Machine
GW-Server
Decoy-Debug-TTL
Server-ID
WZWS-RAY
X-Powered-By-ANYU
Decoy-Debug-Status
Decoy-Debug-Key
Release
Pramga
IsBot
Adler-Geo
Platform
Countrycode
Origin
FSS-Proxy
Backend-Name
SN
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
Heartbleed
Apple-News-Services-Host
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
Is-Eu
Apple-News-Services-Request-Url
Memcached
FSS-Cache
Frame-Options
X-Gannett-Site-Version
X-Returned-From-PostProcessResponse
Magicmarker
X-Gen-Mode
X-Served-From
MI-Cache-Age
Cache-Cookie-Set-Lfrom
X-Server-IP
X-P-T
X-Sf
X-RCS-CacheZone
X-Passed-To-BeforeDispatch
X-Fastly-Cache
X-Li-Pop
V-Cache
X-Request-UUID
X-Li-Fabric
X-Goog-Meta-Goog-Reserved-File-Mtime
Cache-Cookie-Set-From
Group
X-Nginx-Cache-Key
X-Instance-Name
X-SVT-ORM-RULES
True-Client-Country-4JS
X-Returned-From-DLL
X-Stale
MI-Cache
Odigeo-Trace-Id
X-Secret
X-Sentry-ID
X-Hnp-Log
X-LI-Proto
X-LI-UUID
Cache-Cookie-Set-Idcheck
X-MI-In-Market
X-Device-Os
X-Varnish-Action
X-SVT-ORM-VERSION
X-VCT
Server-Int
X-Bip
X-Block-Status
X-TT-LOGID
X-Up
X-Returned-From-BeforeDispatch
X-Cache-Debug
X-Passed-To-PostProcessResponse
X-WebServer
X-Actual-URL
X-Passed-To-DLL
X-Node-Id
X-Passed-To
Web-Mar-Node
On-Server
Esi-Enabled
X-Worker
Fastly-Backend-Name
X-Thanos
X-Cache-Expires
Kp-EeAlive
X-Returned-From
X-CUA
X-Sucuri-Cache
Request-Country
X-Phone
Request-EU
X-Crawler
X-Unique-Id-Primal
X-Distributor
X-Swa-Ws
Pragrma
X-Core-Mission
X-Policy
Proxy-Connection
X-MSEdge-Features
X-HOST
CDCHOST
Who
X-MSEdge-Flight
X-NODE
MI-API
X-Cache-CFC
X-Fstrz
X-Refresh
X-Newrelic-Synthetics
MIME-Version
X-Owner
X-Page-Type
Fusion-Source
REQUESTUUID
X-Servername
Cteonnt-Length
X-Pjax-Url
Fusion-Component-Id
RequestId
X-Req
Fusion-Template-Id
Fusion-Content-Source
HTTPS
Fusion-Content-Id
X-SN
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Backend-TTL
X-Be
X-GZip
X-Cache-Srv
X-Edge-Server
Cdn-Request-Time
X-Ms-Lease-State
Cdn-Host
NodeID
X-Origin-TTL
Memory
X-Server-Group
Cdn
CF-IPCountry
Amp-Access-Control-Allow-Source-Origin
ProcessTime
X-Servedbyhost
SD-X-WS
X-Content-Age
Mime-Version
VIX-Pulpo-Node
SS
X-Protected-By
VIX-Pulpo-Upstream-Status
X-Wa
X-COUNTRY
A
X-Aicache-OS
X-Origin-Expires
X-Origin-Date
GeoIP-Country-Code
X-Origin-Host
CDN
X-Ckpd-Fst-Backend
X-ND-Cache
X-BB-IP
X-SRV
GeoIP-Latitude
X-Varnish-Beresp-TTL
X-StackifyID
Get-Access-Time
Is-Session-Tracking
XServer
X-Fastly-Country-Code
X-APP
PageType
X-B3-Traceid
X-Pf-Uncompressing
Processtime
PICS-Label
X-PHP-Host
GeoIp-Country-Code
Geoip-Latitude
Node
Serverid
X-Unique-Id
Vix-Hermes-Req-Id
Cache-Tv-Group
X-Cache-Info
X-Proxy-Cache-Status
X-Gdpr
X-Proxy-Upstream
X-Varnish-Url
X-Requestid
X-Ratelimit-Remaining
X-CSRF-Token
X-WA
X-Load-Cache
X-Nananana
Nel
X-Generation-Time
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Fastly-Cache-Hits
X-ID
X-BACKEND-TTL
X-Planisys-CDN-Cache
X-ServedByHost
Cf-Ipcountry
Cache-Provider
DataCenter
X-FireWall-Port
X-SERVER-NAME
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-RequestId
X-Atg-Version
URI
WP-Super-Cache
X-Check-Cacheable
X-HS-Status
Request-Time
X-UPSTREAM-Address
X-FORWARDED-FOR
Hostname
X-CS
X-NGINX-Cache
X-Front
X-Fastly-Backend-Reqs
Host-ID
X-EC-Security-Audit
X-GZIP
PFcat
X-Micro-Cache
X-Server-W
X-BE
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-WR-MODIFICATION
X-B3-SpanId
X-FB-TRIP-ID
T-Server
NGX
X-DataStream-Origin-MEX-Latency
X-DataStream-MidMile-RTT
Https
X-GDPR
X-Fe
X-Svr
Requestid
X-HTML-Edge-Cache
X-VarnCache
X-Surge-Debug
X-PARISIEN-Cache-Rendered
X-VG-WebCache
X-VarnPar1
Ohc-File-Size
X-GEO
X-Swift-Error
X-IPS-LoggedIn
Lfy
Ohc-Response-Time
X-HTML-Minification-Powered-By
X-Cdn-Srv
X-PJAX-URL
X-Level-Front-Cache
RequestUuid
X-Instart-Info
X-Generated-On
X-Amz-Meta-S3b-Last-Modified
X-Akamai-SSL-Client-Sid
Pics-Label
X-ServerName
X-VarnPar2
X-Cache-Ttl
N-Cache
X-Distil-Cs
X-RAMCache
X-PF-Uncompressing
X-PAGE-TYPE
ServerName
X-From-Cache
WebServer
X-Qnm-Cache
X-M-Log
X-M-Reqid
X-Akamai-ERRuleID
X-Akamai-ERPolicy
X-Serial
NnCoection
Cdn-Src-Port
X-SB
X-VC
X-Gen-Id
X-Dw-Trace-Id
Build-Number
X-Alicdn-Da-Ups-Status
SID