Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Pragma
X-Powered-By
Link
ETag
CF-RAY
Expect-CT
Via
X-XSS-Protection
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Id
X-Served-By
P3P
Referrer-Policy
X-Varnish
X-Xss-Protection
X-Timer
CF-Cache-Status
X-Request-Id
Access-Control-Allow-Headers
X-AspNet-Version
Access-Control-Allow-Methods
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
P3p
X-Drupal-Cache
X-Check
X-Adblock-Key
Alt-Svc
X-Cacheable
X-Generator
CF-Ray
Content-Security-Policy-Report-Only
X-Cache-Status
X-Request-ID
X-AspNetMvc-Version
Status
X-Amz-Cf-Pop
X-DNS-Prefetch-Control
X-Template
X-Language
Timing-Allow-Origin
Content-Encoding
X-Permitted-Cross-Domain-Policies
X-Iinfo
X-Buckets
X-Content-Security-Policy
X-Turbo-Charged-By
Upgrade
X-Kinja-Server-Push
X-CDN
X-Type
Xkey
Keep-Alive
Access-Control-Expose-Headers
WPE-Backend
X-Pass-Why
X-AH-Environment
Access-Control-Max-Age
X-Backend
X-Cache-Group
X-Server
X-Age
X-Drupal-Dynamic-Cache
X-Pingback
X-Via
X-Nginx-Cache-Status
X-Amz-Request-Id
X-Amz-Id-2
X-Server-Powered-By
Grace
X-Hacker
EagleId
X-UA-Device
X-Robots-Tag
X-LiteSpeed-Cache
X-Varnish-Cache
X-Page-Speed
X-Swift-SaveTime
X-Swift-CacheTime
X-Proxy-Cache
Cf-Railgun
X-Envoy-Upstream-Service-Time
Request-Context
Ali-Swift-Global-Savetime
X-Ua-Compatible
X-Styx-Req-Id
X-Ac
X-Pantheon-Styx-Hostname
X-Device
X-WebKit-CSP
X-Cache-Lookup
Content-Location
X-Amz-Version-Id
Surrogate-Control
X-Cnection
X-Host
X-Server-Id
Report-To
X-Readtime
X-Node
X-Rq
EagleEye-TraceId
Server-Timing
X-Response-Time
X-CST
Feature-Policy
X-OneAgent-JS-Injection
X-Rack-Cache
X-Backend-Server
X-ORACLE-DMS-ECID
X-Application-Context
X-Iejgwucgyu
Request-Id
X-Instart-Request-ID
X-Cloud-Trace-Context
X-Clacks-Overhead
Edge-Control
X-Url
X-DynaTrace
NEL
Allow
Rating
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Country
X-Varnish-TTL
X-Origin-Cache
X-FTR-Request-ID
X-Country-Code
X-Cdn
X-Trace
X-Server-Name
X-Px
X-B3-TraceId
X-DataDome
X-Vhost
X-Server-ID
X-ESI
X-GitHub-Request-Id
X-MS-InvokeApp
RTSS
X-VARITI-CCR
X-Cached
X-Ruxit-JS-Agent
Accept-CH
SPRequestGuid
X-Goog-Hash
X-ORACLE-DMS-RID
Charset
X-TtlSet
X-PC
X-Vname
Pinterest-Generated-By
X-F-Cache
X-D2id
Public-Key-Pins
X-Mod-Pagespeed
X-Dispatcher
X-GoogleNews-Bot
X-Exp-Variant
X-Exp-Id
X-Kinja
X-Kinja-Build
X-Use-Magma
X-Kinja-Server
X-Kinja-Revision
X-Cdn-Fetch
Verso
X-SharePointHealthScore
PB-RID
X-Mobile-Rewrite
Arc-Version
PB-PID
X-TTL
X-T
X-DynaTrace-JS-Agent
X-Version
X-Powered-By-Plesk
X-Abt-Application-Version
Accept-CH-Lifetime
X-Powered-CMS
X-DIS-Request-ID
X-Dns-Prefetch-Control
X-Ser
X-Fastly-Request-ID
Pinterest-Version
X-Pinterest-Rid
X-Upstream-Env
X-Oneagent-Js-Injection
X-Origin-Upstream-Status
X-Navigation-Version
X-Shield-Request-Id
X-Forwarded-Proto
X-B
X-Recruiting
DynaTrace
X-Client-IP
MS-Author-Via
X-Amz-Rid
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Realpath
X-HW
SPIisLatency
SPRequestDuration
Content-MD5
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Upstream
Nginx-Cache
X-Ttl
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Vcap-Request-Id
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
Edge-Cache-Tag
X-Amz-Meta-S3cmd-Attrs
X-Oracle-Dms-Rid
AR-PoweredBy
AR-CACHE
AR-ATIME
X-Accel-Buffering
X-Wix-Server-Artifact-Id
X-N
X-Hits
TCN
Arr-Disable-Session-Affinity
X-Varnish-Age
X-Debug
X-NF-Request-ID
X-Goog-Storage-Class
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
Access-Control-Request-Method
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Acc-Meta-Resource-Type
X-MSEdge-Ref
X-Dw-Request-Base-Id
X-NewRelic-App-Data
S
X-ATG-Version
X-Id
Service-Worker-Allowed
X-FTR-Backend-Server
X-FTR-Realm
X-FTR-Cache-Status
X-FTR-Balancer
X-Country-Code-Real
X-FTR-DC
X-FTR-Backend
X-Via-JSL
X-Logged-In
X-FTR-Expires
X-XRDS-Location
Tracecode
X-FastCGI-Cache
X-Forwarded-For
X-HS-Content-Id
X-PressLabs-Stats
X-Content-Digest
X-HS-Hub-Id
Rt-Fastcgi-Cache
X-Frontend
Alternate-Protocol
X-Kinsta-Cache
Surrogate-Key
X-Pad
Fastly-Restarts
X-Cache-Key
MicrosoftSharePointTeamServices
AMP-Access-Control-Allow-Source-Origin
X-Content-Options
X-RateLimit-Remaining
X-FTR-Cache-Host
X-Grace
X-Edge-Location
X-Ruxit-Js-Agent
Server-Name
X-Amzn-Trace-Id
Fastcgi-Cache
Ar-Sid
Backend-Timing
X-Analytics
FilterID
X-CF-Powered-By
Host
X-Rid
X-IPLB-Instance
TP-Cache
X-Debug-Info
TP-L2-Cache
X-User-Agent
X-Hostname
X-Revision
X-Magnolia-Registration
X-Whom
ServerID
Eomportal-Instance
X-Request-Processing-Time
X-Request-Received
X-B3-Sampled
Paypal-Debug-Id
X-Cache-2
X-NWS-LOG-UUID
X-Page-Id
X-HS-Cache-Config
X-Mobile
AR-Request-ID
X-Srv
X-Akam-SW-Version
Front-End-Https
X-AOL-HN
X-Content-Powered-By
X-Cache-Hit
Retry-After
X-VCache
X-GUploader-UploadID
X-Signature
X-Litespeed-Cache
X-B-Cache
X-Varnish-Grace
X-LB-Cache
X-SS-Set-Cookie
X-FB-Debug
Source
X-Cluster
X-Handled-By
X-Device-Type
X-WA-Info
X-Instance
X-Correlation-Id
X-Cache-Control
Cleartype
X-XRDS-LOCATION
Refresh
X-Cache-Action
X-App-Environment
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Request-Guid
X-Platform-Server
X-BCube-Filmed-By
X-Tumblr-User
X-Framework
X-Varnish-Hostname
X-Zen-Fury
X-Content-Security-Policy-Report-Only
X-TA-CDN-Provider
X-Akamai-Edgescape
Webserver
X-Varnish-Backend
X-Webkit-CSP
X-Daa-Tunnel
Display
X-Sol
X-Middleton-Display
X-Cache-Server
X-Fastcgi-Cache
X-Drupal-Cache-Tags
X-Varnish-Server
X-Activity-Id
X-Drupal-Cache-Contexts
X-Az
X-AppVersion
Healthy
X-Content-Type
X-Geo-Country
VIX-Pulpo-Node
X-Generated-By
VIX-Pulpo-Upstream-Status
X-URL
X-Cache-Rule
X-Middleton-Response
Response
X-Cached-By
X-Cache-Age
S-Cnection
X-Wix-Request-Id
X-App-Server
ViewerVersion
Server-Node
X-Seen-By
X-Accel-Expires
Cache-Status
X-Node-Name
X-CACHE-GROUP
X-DataStream-Cache-Status
X-Amzn-RequestId
X-Amz-Replication-Status
X-Amz-Apigw-Id
X-Esi
X-Origin-Server
X-TT
X-WPE-Loopback-Upstream-Addr
X-Response-Served-From
X-S
GEO-INFO
NGB
Filters
X-Cacheable-TTL
X-Locale
Host-Header
Payment
Upgrade-Insecure-Requests
X-UA-Device-Type
HostName
X-Varnish-IP
X-Cache-NE
X-GeoIP
X-RequestSource
Actual-Object-TTL
Viewport
X-Edge-Cache-Key
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
X-Servedby
X-Edge-Cache
ServedBy
X-Contextid
X-FW-Server
X-FW-Hash
X-FW-Static
X-FW-Type
X-Varnish-Hits
X-Jobs
AsisCache
X-FW-Serve
X-UUID
X-Status
Access-Control-Allow-Method
X-WebKit-CSP-Report-Only
X-Amz-Server-Side-Encryption
X-TT-TIMESTAMP
X-TX-ID
Server-Info
Accept-Charset
X-Adobe-Loc
X-Adobe-Content
X-Storage
X-HS-Combine-CSS
X-Hyper-Cache
SRV
X-APP-VERSION
Cache
X-Cache-TTL-Remaining
X-CLOUD-TRACE-CONTEXT
X-Rendered-As
X-Vg-Webcache
X-PHP-Backend
X-Cache-Remote
From-Origin
X-Croise-Owner
MS-CV
Cache-Tag
DC
X-Cache-Operation
Cache-Tv-Group
X-Region
X-Forwarded-Host
Public-Key-Pins-Report-Only
Served-By
X-App-Version
Liferay-Portal
X-Redis-Cache
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-UA
X-Mode
X-NGENIX-Cache
X-Request-Time
X-Human
X-Agile
X-RN-RSRV
X-Akamai-Request-ID2
X-TNCMS
X-Loop
X-Path-Route
X-Agile-Id
X-Agile-Age
X-Hosted-By
X-Upgrade-Enabled
Meta-Geo
X-Akamai-Transformed
X-Endurance-Cache-Level
Selected-FE
X-IP
X-Cache-Var
X-Cache-Var-Map
X-Is-Bot
Machine
X-TIME
X-Proxy-Build
X-Detected-As
X-Webstats-RespID
X-Generated
X-Site-Version
X-Timing-Wait
X-BYPASS-REASON
X-Format
X-Cache-Category-Id
X-CDN-Cache
X-Environment-Context
X-Vgn-Hpd-Reason
X-JoinUs
X-ProxyCache-Status
X-ProxyCache-Key
X-Pc-Key
X-Grey
Origin-Edge-Control
Origin-Cache-Control
Now
X-NCache
X-Labrador-Cache-Channel
X-L-Path
X-Pc-Hit
X-Via-Fastly
Cache-Name
X-Original-Request
X-Pc-Appver
X-Internal-Host
Xserver
Webcakes-App-Name
Webcakes-App-Version
TWC-GeoIP-Country
TWC-Locale-Group
Webcakes-Region
S-Rt
Property-Id
TWC-Device-Class
TWC-Privacy
TWC-Connection-Speed
X-VG-TLSProxy
X-Pubstack
X-Proxy
DB-Nickname
X-PCL
X-RemovedCookies
X-Web-Node
X-OCL
X-ProcessESI
X-Tumblr-Pixel-3
X-Section
X-FC-Vary-Parameters
X-Birta-Served
X-Birta-Cache-Post
X-Upstream-CT
X-Upstream-HT
X-Origin-Hint
X-Viewer-Country
X-Access
TWC-GeoIP-LatLong
Datacenter
Powered-By-ChinaCache
X-Time-Microsecs
X-Rule
X-Via-CDN
Fastcgi-Useragent
X-Cache-Config
X-Www-Served-By
X-Akamai-Request-ID
X-Origin-Host
X-Origin-Response-Time
Pagespeed
Fastcgi-X-Cache-Version
Cache-Tags
X-Backend-Name
X-Ocache
X-Origin
X-Origin-CC
Fastcgi-X-Cache
X-CCM
X-ServerID
X-Proxied
X-Routing-Service
X-Tb
X-Zipkin-Id
X-Xfnlog-Site
Mn-Server-Ip
OT-Force-Account-Verify
X-Shopify-Stage
X-Sorting-Hat-PodId
X-B3-Spanid
Azure-RegionName
X-ShopId
X-ShardId
Azure-SlotName
Azure-SiteName
Azure-InstanceId
Azure-Version
X-Sorting-Hat-ShopId
HitType
X-Alternate-Cache-Key
X-Parent-Response-Time
X-Guploader-Uploadid
X-Cache-TTL
X-NODE
Accept-Language
X-Nginx-Cache
X-OVcl-Cache
X-CACHE-KEY
X-OVcl
X-RateLimit-Limit
X-Ezoic-Cdn
X-App-Name
L5d-Success-Class
X-Protected-By
User-Cache-Control
NtCoent-Length
Vix-Hermes-Req-Id
X-Edge-IP
Cache-Key
X-Real-IP
Content-Script-Type
Content-Style-Type
LB
Time
X-Newrelic-App-Data
X-Amz-Meta-Surrogate-Control
X-Real-Ip
X-BACKEND-TTL
AR-SID
X-Proto
X-Cache-Backend
X-Webkit-Csp
X-Kong-Upstream-Latency
X-RTag
X-Pc-Host
Ms-Operation-Id
X-Pc-Date
X-Kong-Proxy-Latency
X-Correlation-ID
X-ApacheServer
X-PERF
X-Front
X-Cdn-Forward
X-Nc
X-Hit
X-CDN-Forward
X-Unique-Id-Primal
X-Mshield-Cache-Status
X-Mrs-Age
X-Mrs-Cache
X-Mrs-Cache-Hits
Section-Io-Cache
X-Sucuri-ID
X-Varnish-Beresp-Grace
X-Varnish-Cacheable
X-FB-TRIP-ID
X-Varnish-Beresp-Status
X-Debug-Cache
X-Microcachable
WZWS-RAY
X-Ratelimit-Limit
X-Dc
Access-Control-Request-Headers
X-GRACE
X-Content-Age
X-Transaction
X-Cache-Enabled
X-Unique-ID
X-Connection-Hash
Version
X-C
X-Twitter-Response-Tags
Fusion-Content-Id
Fusion-Component-Id
Fusion-Source
Fusion-Content-Source
X-EdgeConnect-Cache-Status
X-Trace-Id
Fusion-Template-Id
Warning
X-MP-GENERATED-AT
X-User
Locale
X-BB-ID
X-Application
X-Cache-Bucket
X-Cache-Debug
X-Via-Edge
X-Cache-FS-Status
IBM-Web2-Location
Is-Eu
X-Aed
X-Backend-State
X-Bip
X-Auto-Login
X-B-Cookie
MD5-Digest
X-A-Wwc
X-Variation
X-A-Dam
X-A-Dcw
SS
Server-ID
X-Varnish-Action
X-A-Ccd
X-A
V-Age
X-Var-Ttl
UCS
Uber-Trace-Id
VivaBuild
Viewtype
Server-Host
SD-X-WS
Node
X-VG-WebServer
Mobile-Detection-Method
X-Accel-Expires-Debug
X-Actual-URL
Meta-Geo-Continent
Platform
Powered-By
Resin-Trace
Rt-Proxy-Cache
Rendered-Blocks
X-A-Dgt
Release
X-Cache-Host
Memcached
X-LI-UUID
X-RCS-CacheZone
X-PHP-Host
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Region-Sid
X-Reboot
X-PAYTM-SRV-ID
X-Passed-To-PostProcessResponse
X-Thanos
X-Org
X-Store
X-Passed-To
X-Passed-To-DLL
X-Passed-To-BeforeDispatch
X-Release
X-Request-UUID
X-ScT
X-S-Maxage
X-Served-From
X-SRCache-Key
X-Server-Time
X-Server-By
X-S-Cookie
X-Rojux
X-Returned-From
X-Response-By
X-Returned-From-BeforeDispatch
X-Returned-From-DLL
X-Rewrite-Enabled
X-Returned-From-PostProcessResponse
X-NU-AKA-ACS-Version
X-Node-Id
X-Developer
X-Destination
X-Device-Os
X-Died
X-DPWN-IS-SECURE
X-Dispatcher-Server
X-Date
X-D
X-Cache-URL
X-Urbn-Site-Id
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-CUA
X-Crawler
X-External-Request-Id
X-Urbn-Context-Path
X-Li-Pop
X-Li-Fabric
X-LI-Proto
X-Via-SSL
X-Trv-Group
X-Logtrace-Id
X-Layer
X-UE-Client-Country
X-From
X-Fetched-On
X-FW-Version
X-G
X-GeoIP-Country-Code
X-Generated-In
X-Cache-Id
Fastly-SWR
Ohc-File-Size
We-Hiring
Fastly-SIE
X-WebServer
Load-Balancing
Fly-Request-Id
Fly-Cache
X-We-Are-Hiring
Country
Mail-Subject
Cache-Prefix
Fastly-Backend-Name
Adler-Geo
Frame-Options
Arc-Country
BehaviorPad-Version
Xc-Version
Ec-Rule-Version
Ajk
X-Rocket-Nginx-Bypass
X-Hl-Ver
X-Varnish-Beresp-Ttl
X-NWS-UUID-VERIFY
X-Swa-Ws
X-SVT-ORM-VERSION
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Thinkindot-Control
Apple-News-Services-Handled
AKAMAI
Www
Who
Web-Mar-Node
X-Thinkindot-L3
X-No-Session
X-Clientip
X-CGP
X-Hash
X-Hnp-Log
X-Gen-Mode
X-UnsetCookies
X-Epic-Correlation-Id
X-Eu-Site
X-F5-Cache
X-IN-APIGATEWAY
X-IN-SSL-APIGATEWAY
X-Location
X-Matched-Rule
Thinkindot-CacheControl-Type
X-Key
X-Block-Status
X-IN-WAF
X-Cache-Expires
X-Info
X-Amz-Meta-Cache-Control
Apple-News-Services-Request-Url
HA-Urlpath
HA-Servedtime
HA-Ipaddr
HA-Host
Heartbleed
X-Server-IP
Countrycode
Esi-Enabled
Kp-EeAlive
Thinkindot-CacheControl
Ha-Gx-Prefs
HA-Georegion
GW-Server
GMS-Ver
X-Via-NSCOPI
X-Sf
HA-Cloudapp
HA-Geocity
HA-Geolon
HA-Geolat
HA-Geocountry
X-Request-Start
X-Server-Group
X-Time
Pragrma
Backend-Name
Pramga
X-Proxy-Cache-Status
X-Qloud-Router
Request-Country
Request-EU
X-SVT-ORM-RULES
X-Stale
X-Proxy-Upstream
RNT-Time
Backend
RNT-Machine
Country-Code
Content-Disposition
User-Agent
Group
X-Be
X-Geo
V-Cache
X-Fstrz
X-Gannett-Site-Version
X-P-T
X-Distributor
X-Up
X-Distil-CS
HitInfo
X-Policy
X-Dynatrace-Js-Agent
X-Secret
X-Request-URI
X-Irp-Debug
X-Instance-Name
X-Goog-Meta-Goog-Reserved-File-Mtime
X-TT-LOGID
X-Platform
X-GeoIP-City
Proxy-Connection
REQUESTUUID
CDCHOST
MI-Cache-Age
Origin
Decoy-Debug-Status
X-ServiceProvider
X-Wikidot-Static-Cache
X-Wikidot-Backend
MI-API
X-Core-Value
MI-Cache
On-Server
X-MI-In-Market
X-Backend-Url
X-Developers
X-Backend-Host
Decoy-Debug-Key
X-VCT
Fastly-Soc-X-Request-Id
Decoy-Debug-TTL
True-Client-Country-4JS
X-Ua
X-Origin-TTL
X-Nginx-Cache-Key
X-NX-Host
X-Origin-Date
X-Phone
IsBot
X-Sn-Servicetimems
X-Servername
X-SIPLIST1
Fastly-SSL
X-Refresh
Cache-Cookie-Set-From
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
Server-Int
X-Origin-Expires
Request-Time
Nel
X-Cache-CFC
X-Cdn-Origin
X-Debug-Log
X-Debug-Cookies
X-ElasticPress-Search
X-V
X-Fastly-Cache
Pagetype
X-Planisys-CDN-TTL
X-COUNTRY
X-Core-Mission
X-Page-Type
X-DC
Magicmarker
X-Planisys-CDN-Rules
PFcat
X-Planisys-CDN-Cache
RequestId
X-MSEdge-Flight
X-MSEdge-Features
X-Req
X-Pjax-Url
Host-ID
X-BBXSRF
X-EIG-Tracking-Id
X-Powered-By-ANYU
PageSpeed
X-NC
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Micro-Cache
X-PARISIEN-Cache-Rendered
X-Svr
X-VarnCache
X-CACHE-AGE
X-VarnPar1
X-HOST
X-Level-Front-Cache
X-Newrelic-Synthetics
X-Generated-On
Mime-Version
MIME-Version
X-Datadome
X-Instart-Info
Lfy
Cache-Provider
ServerName
Cdn
X-TWH-CORRELATION-ID
PICS-Label
X-Server-Cache
X-Gdpr
X-Cdn-Srv
X-Cache-Info
Ohc-Response-Time
Cteonnt-Length
X-Cluster-Node
X-ARC
Memory
X-Servedbyhost
CF-IPCountry
X-CMS-Context
FSS-Cache
X-Sentry-ID
X-StackifyID
FSS-Proxy
X-NodeID
X-Wa
X-VServer
X-ABtesting
X-Fastly-Country-Code
X-Aicache-OS
X-Hello
X-Flog
X-WR-MODIFICATION
SN
X-LAGOON
X-Varnish-Beresp-TTL
Geoip-Latitude
GeoIp-Country-Code
CDN
X-Load-Cache
X-Ratelimit-Remaining
X-WA
X-B3-Traceid
NGX
X-Fastly-Backend-Reqs
X-GZip
GeoIP-Country-Code
GeoIP-Latitude
XServer
CACHE
X-UPSTREAM-Address
X-CSRF-Token
X-CSRF-TOKEN
X-HTML-Minification-Powered-By
TSSecure
X-Check-Cacheable
X-Unique-Id
X-APP
X-Worker
Processtime
Amp-Access-Control-Allow-Source-Origin
X-MServer
X-Source
X-Csrf-Token
A
X-ServedByHost
Cf-Ipcountry
X-DataStream-MidMile-RTT
X-DataStream-Origin-MEX-Latency
PageType
X-VWS-Id
X-LJ-Flow-ID
X-AWS-Id
X-SplitTest
X-CDN-Pop
WP-Super-Cache
X-CDN-Pop-IP
X-Oss-Server-Time
X-FireWall-Port
X-Port
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
X-Oss-Object-Type
X-Varnish-Cache-Hits
X-Oss-Storage-Class
X-Edge-Server
X-RateLimit-Remaining-Second
X-Dynatrace
X-Nananana
X-Generation-Time
HTTPS
Cdn-Host
Cdn-Request-Time
X-RateLimit-Limit-Second
X-SRV
Cache-Hits
X-VC-Cache
X-FORWARDED-FOR
X-Cache-Miss-From
X-Sedo-Request-Id
Pics-Label
X-Skip-Cache
X-Sucuri-Cache
X-Backend-TTL
URI
Odigeo-Trace-Id
X-GDPR
DataCenter
X-ID
X-Owner
X-Cache-Grace
X-Ms-Blob-Type
X-Ms-Request-Id
X-Ms-Lease-Status
X-Ms-Version
Server-Surrogate-Control
Server-Cache-Control
X-Fastly-Cache-Hits
X-VG-WebCache
X-B3-SpanId
X-HS-Status
X-Varnish-Authentication
X-Cache-ASPX
ProcessTime
X-BE
X-Swift-Error
X-PJAX-URL
X-Gen-Id
Hostname
X-RCS-Backend
X-SN
X-IPS-LoggedIn
Dynatrace
X-From-Cache
X-Bug-Bounty
X-Varnish-Url
X-Amzn-Remapped-Date
X-Amzn-Remapped-Connection
X-GZIP
X-ORIG-AKA-EDGE
X-Cache-Ttl
X-NGINX-Cache
X-Instart-Isnd
X-GoCache-CacheStatus
X-PAGE-TYPE
Requestid
X-Ms-Lease-State
X-ND-Cache
X-VarnPar2
X-Cache-Srv
X-Fe
Serverid
X-Akamai-SSL-Client-Sid
X-Amz-Meta-S3b-Last-Modified
X-ServerName
WebServer
X-Serial
X-Varnish-URL
Is-Session-Tracking
X-LiteSpeed-Cache-Control
X-Server-W
X-Pf-Uncompressing
X-ORIG-AKA-COUNTRY-CODE
NodeID
RequestUuid
X-Alicdn-Da-Ups-Status
X-VC
Get-Access-Time
T-Server
X-RAMCache
X-SB
Xet-Cookie
Proxy-Firewall
X-LiteSpeed-Tag
X-HTML-Edge-Cache
NnCoection
SID
X-RequestId
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-Developed-By
X-CS
Location
X-Dw-Trace-Id