Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Accept-Ranges
Pragma
X-Powered-By
Link
ETag
CF-RAY
Expect-CT
Via
X-Cache
X-XSS-Protection
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-UA-Compatible
X-Cache-Hits
X-Xss-Protection
X-Amz-Cf-Id
X-Served-By
P3P
Referrer-Policy
X-Varnish
X-Request-Id
X-Timer
CF-Cache-Status
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Amz-Cf-Pop
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
P3p
X-Drupal-Cache
X-Check
X-Adblock-Key
X-Cacheable
Alt-Svc
Content-Security-Policy-Report-Only
X-Generator
CF-Ray
X-Cache-Status
X-DNS-Prefetch-Control
X-AspNetMvc-Version
Status
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-Permitted-Cross-Domain-Policies
Content-Encoding
X-Buckets
X-Content-Security-Policy
X-Turbo-Charged-By
X-Kinja-Server-Push
Upgrade
X-Request-ID
X-CDN
Xkey
X-Type
Keep-Alive
Access-Control-Expose-Headers
Access-Control-Max-Age
WPE-Backend
X-Pass-Why
X-AH-Environment
X-Backend
X-Cache-Group
X-Server
X-Age
X-Drupal-Dynamic-Cache
X-Via
X-Pingback
Grace
X-Nginx-Cache-Status
X-Amz-Request-Id
X-Amz-Id-2
X-Server-Powered-By
EagleId
X-Hacker
X-UA-Device
X-Robots-Tag
X-LiteSpeed-Cache
X-Varnish-Cache
X-Page-Speed
X-Proxy-Cache
Request-Context
X-Swift-CacheTime
X-Swift-SaveTime
Cf-Railgun
X-Envoy-Upstream-Service-Time
Ali-Swift-Global-Savetime
X-Ua-Compatible
X-WebKit-CSP
X-Ac
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
X-Cache-Lookup
X-Server-Id
X-Amz-Version-Id
X-Cnection
X-Node
Content-Location
Surrogate-Control
X-OneAgent-JS-Injection
X-Readtime
EagleEye-TraceId
X-CST
Report-To
X-Host
X-Response-Time
X-Rq
Feature-Policy
Server-Timing
X-Iejgwucgyu
X-Backend-Server
X-Application-Context
X-ORACLE-DMS-ECID
X-Rack-Cache
Request-Id
X-Instart-Request-ID
Allow
X-Cloud-Trace-Context
X-Clacks-Overhead
X-Url
NEL
X-Cdn
Rating
X-DynaTrace
X-Country
Edge-Control
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Origin-Cache
X-Varnish-TTL
X-FTR-Request-ID
X-Country-Code
X-B3-TraceId
X-Px
X-DataDome
X-ORACLE-DMS-RID
X-Server-ID
X-GitHub-Request-Id
X-Ruxit-JS-Agent
X-ESI
X-Vhost
X-Trace
X-VARITI-CCR
Accept-CH
X-Goog-Hash
Charset
X-Server-Name
X-Cached
RTSS
X-MS-InvokeApp
Pinterest-Generated-By
X-TTL
X-Mod-Pagespeed
Verso
PB-RID
PB-PID
Arc-Version
X-Mobile-Rewrite
Public-Key-Pins
X-D2id
X-Kinja-Revision
X-Use-Magma
X-Kinja-Server
X-GoogleNews-Bot
X-Exp-Variant
X-Exp-Id
X-Kinja-Build
X-Kinja
X-Cdn-Fetch
X-Version
X-F-Cache
SPRequestGuid
X-PC
X-Vname
X-TtlSet
X-Dispatcher
X-DynaTrace-JS-Agent
X-T
X-DIS-Request-ID
X-Powered-By-Plesk
Accept-CH-Lifetime
X-Abt-Application-Version
X-Powered-CMS
X-SharePointHealthScore
X-Origin-Upstream-Status
X-Fastly-Request-ID
X-Ser
X-Pinterest-Rid
X-Navigation-Version
Pinterest-Version
X-Upstream-Env
X-B
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Client-IP
Realpath
X-Shield-Request-Id
X-Amz-Rid
MS-Author-Via
X-Forwarded-Proto
X-Recruiting
X-HW
X-Upstream
SPIisLatency
SPRequestDuration
X-Vcap-Request-Id
DynaTrace
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Wix-Server-Artifact-Id
X-Accel-Buffering
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
Nginx-Cache
X-Amz-Meta-S3cmd-Attrs
Arr-Disable-Session-Affinity
X-XRDS-Location
X-Varnish-Age
Content-MD5
AR-ATIME
AR-CACHE
AR-PoweredBy
X-Debug
X-Mrf-Item-Lastmod
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Mrf-Section-Lastmod
X-Via-JSL
X-Dw-Request-Base-Id
X-Hits
X-Ttl
X-Goog-Storage-Class
X-MSEdge-Ref
X-Id
X-NewRelic-App-Data
X-Acc-Meta-Resource-Type
X-Oracle-Dms-Rid
X-N
X-Aspnet-Version
X-NF-Request-ID
X-FTR-Backend-Server
X-FTR-Cache-Status
X-FTR-Realm
X-FTR-Balancer
X-FTR-Backend
X-FTR-DC
X-Country-Code-Real
Service-Worker-Allowed
X-FTR-Expires
Access-Control-Request-Method
S
X-ATG-Version
Edge-Cache-Tag
Alternate-Protocol
TCN
X-Logged-In
AMP-Access-Control-Allow-Source-Origin
X-Kinsta-Cache
X-PressLabs-Stats
X-HS-Hub-Id
X-Oneagent-Js-Injection
X-HS-Content-Id
X-Frontend
X-Forwarded-For
Surrogate-Key
Rt-Fastcgi-Cache
X-RateLimit-Remaining
X-FTR-Cache-Host
X-Content-Digest
Tracecode
X-FastCGI-Cache
X-Pad
Fastcgi-Cache
X-CF-Powered-By
X-Cache-Key
X-TA-CDN-Provider
Server-Name
Fastly-Restarts
X-Amzn-Trace-Id
MicrosoftSharePointTeamServices
X-Analytics
Backend-Timing
X-User-Agent
TP-Cache
TP-L2-Cache
Host
X-Cache-2
X-Edge-Location
FilterID
X-Rid
X-Debug-Info
X-Magnolia-Registration
Ar-Sid
ServerID
X-B3-Sampled
X-Whom
X-Page-Id
X-Mobile
X-Grace
X-Content-Options
X-Revision
X-IPLB-Instance
Eomportal-Instance
Front-End-Https
Paypal-Debug-Id
X-Srv
X-Hostname
X-Akam-SW-Version
AR-Request-ID
X-NWS-LOG-UUID
Refresh
X-LB-Cache
X-Ruxit-Js-Agent
X-VCache
X-Request-Received
X-Request-Processing-Time
Retry-After
X-Content-Powered-By
X-Activity-Id
X-Signature
X-Az
X-B-Cache
X-AppVersion
X-Fastcgi-Cache
X-SS-Set-Cookie
X-Cache-Action
X-Cluster
X-Framework
X-URL
Cleartype
X-Varnish-Hostname
Source
X-Handled-By
X-App-Environment
X-Platform-Server
X-Tumblr-User
X-Cache-Control
X-Tumblr-Pixel
X-Request-Guid
X-Tumblr-Pixel-0
X-BCube-Filmed-By
X-Device-Type
X-Instance
X-FB-Debug
X-WA-Info
X-Content-Security-Policy-Report-Only
X-Akamai-Edgescape
X-Litespeed-Cache
X-AOL-HN
VIX-Pulpo-Upstream-Status
Webserver
VIX-Pulpo-Node
X-Content-Type
X-Cache-Hit
X-Zen-Fury
X-Varnish-Grace
X-Correlation-Id
Display
X-Middleton-Display
X-Sol
Accept-Charset
X-Cache-Rule
X-Varnish-Backend
X-GUploader-UploadID
Healthy
X-Seen-By
X-Wix-Request-Id
ViewerVersion
X-TT
X-Origin-Server
X-Drupal-Cache-Tags
X-Middleton-Response
X-Cache-Age
X-Cache-Server
Response
X-Daa-Tunnel
Cache-Status
Upgrade-Insecure-Requests
MS-CV
X-DataStream-Cache-Status
X-Varnish-Server
X-Cached-By
X-Drupal-Cache-Contexts
X-App-Server
X-Generated-By
X-Amz-Replication-Status
X-Amz-Apigw-Id
Payment
X-Geo-Country
X-Amzn-RequestId
X-Storage
Server-Node
X-PHP-Backend
X-Response-Served-From
NGB
X-CACHE-GROUP
X-UA-Device-Type
Filters
Access-Control-Allow-Method
X-Cacheable-TTL
X-Amz-Server-Side-Encryption
X-HS-Cache-Config
X-S
GEO-INFO
X-FW-Type
X-Varnish-IP
X-Edge-Cache
X-RequestSource
ServedBy
X-Jobs
X-Edge-Cache-Key
X-FW-Server
X-Cache-NE
X-Adobe-Content
X-TT-TIMESTAMP
Viewport
X-Servedby
X-Adobe-Loc
Actual-Object-TTL
X-Contextid
X-FW-Hash
X-FW-Serve
X-FW-Static
X-Esi
X-Tumblr-Pixel-1
X-Varnish-Hits
X-Tumblr-Pixel-2
X-UUID
X-Locale
X-TX-ID
Cache-Tv-Group
X-WPE-Loopback-Upstream-Addr
AsisCache
S-Cnection
X-WebKit-CSP-Report-Only
X-Accel-Expires
X-Cache-Remote
Server-Info
X-Cache-TTL-Remaining
X-Status
X-XRDS-LOCATION
From-Origin
X-Rendered-As
X-GeoIP
Host-Header
X-Dns-Prefetch-Control
X-Cache-Operation
Cache
X-Region
X-App-Version
HostName
X-Croise-Owner
SRV
X-APP-VERSION
X-Redis-Cache
X-Guploader-Uploadid
X-CACHE-KEY
Served-By
X-Webkit-CSP
X-Node-Name
X-BACKEND-TTL
X-Hyper-Cache
Content-Script-Type
Content-Style-Type
DC
Liferay-Portal
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Public-Key-Pins-Report-Only
X-Upgrade-Enabled
Xserver
X-Vg-Webcache
X-Cache-Config
X-Cache-Category-Id
X-Cache-Var-Map
X-Timing-Wait
X-RN-RSRV
X-Hosted-By
X-Is-Bot
X-RTag
Machine
X-Parent-Response-Time
X-Site-Version
X-Cache-Var
X-Webstats-RespID
X-Detected-As
X-NGENIX-Cache
X-Proxy-Build
Selected-FE
X-Mode
Ms-Operation-Id
X-Generated
X-Grey
Meta-Geo
Cache-Tag
X-Path-Route
X-CDN-Cache
X-Labrador-Cache-Channel
X-NCache
X-Via-Fastly
X-Environment-Context
X-JoinUs
X-Loop
X-Internal-Host
Now
X-Upstream-CT
X-ProxyCache-Key
X-ProxyCache-Status
Origin-Cache-Control
Origin-Edge-Control
X-Agile
X-Akamai-Transformed
X-Agile-Age
X-Agile-Id
X-Original-Request
X-L-Path
X-Upstream-HT
X-BYPASS-REASON
Cache-Name
X-Human
X-Request-Time
X-TNCMS
X-Akamai-Request-ID
X-Origin-Response-Time
X-Edge-IP
Azure-InstanceId
Cache-Key
X-Birta-Cache-Post
DB-Nickname
User-Cache-Control
Azure-Version
Azure-SlotName
X-Birta-Served
Azure-RegionName
Azure-SiteName
X-Format
X-Protected-By
X-Time-Microsecs
X-GRACE
X-Pc-Appver
X-Proxy
X-ProcessESI
X-Web-Node
X-RemovedCookies
X-Pc-Hit
X-Pc-Key
X-Origin-Host
X-ServerID
X-Origin-CC
X-Viewer-Country
X-IP
X-Tumblr-Pixel-3
X-Backend-Name
TWC-GeoIP-Country
TWC-GeoIP-LatLong
Fastcgi-X-Cache
TWC-Privacy
Fastcgi-X-Cache-Version
TWC-Device-Class
X-Access
S-Rt
Fastcgi-Useragent
X-PCL
Webcakes-Region
TWC-Connection-Speed
X-Pubstack
Property-Id
Cache-Tags
X-CCM
X-Origin-Hint
TWC-Locale-Group
X-Origin
X-OCL
X-Ocache
X-FC-Vary-Parameters
Webcakes-App-Name
Webcakes-App-Version
X-Www-Served-By
X-Xfnlog-Site
X-Section
X-Rule
X-VG-TLSProxy
HitType
X-Forwarded-Host
X-App-Name
X-Vgn-Hpd-Reason
X-Proxied
X-Zipkin-Id
X-B3-Spanid
Vix-Hermes-Req-Id
X-Tb
X-Routing-Service
Pagespeed
Powered-By-ChinaCache
X-FB-TRIP-ID
Load-Balancing
X-RateLimit-Limit
Mn-Server-Ip
X-Endurance-Cache-Level
X-Cache-TTL
X-ApacheServer
Country
X-PERF
X-Nginx-Cache
Datacenter
X-Content-Age
X-Cache-Backend
X-TIME
X-Via-CDN
X-Mrs-Cache
X-Mrs-Age
X-Mrs-Cache-Hits
X-Mshield-Cache-Status
X-Unique-Id-Primal
OT-Force-Account-Verify
X-Ezoic-Cdn
Time
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Sorting-Hat-ShopId
X-Alternate-Cache-Key
X-Shopify-Stage
X-ShopId
X-UA
X-ShardId
X-Cdn-Forward
X-Sorting-Hat-PodId
Fusion-Content-Id
Fusion-Content-Source
Fusion-Source
Fusion-Template-Id
X-CLOUD-TRACE-CONTEXT
Fusion-Component-Id
X-Real-IP
Ohc-File-Size
X-Varnish-Cacheable
X-OVcl-Cache
X-OVcl
X-Debug-Cache
AR-SID
X-Ua
X-Sucuri-ID
LB
X-Pc-Date
X-Pc-Host
X-Nc
X-Varnish-Beresp-Ttl
X-Real-Ip
L5d-Success-Class
X-Correlation-ID
X-Varnish-Beresp-Grace
X-HS-Combine-CSS
X-Hl-Ver
X-Varnish-Beresp-Status
NtCoent-Length
Mail-Subject
X-MP-GENERATED-AT
We-Hiring
X-CDN-Forward
Section-Io-Cache
X-Amz-Meta-Surrogate-Control
X-Unique-ID
X-Proto
X-Time
X-Trace-Id
User-Agent
X-Akamai-Request-ID2
X-Hit
X-Front
X-Cache-Enabled
Pagetype
Access-Control-Request-Headers
X-EdgeConnect-Cache-Status
Version
X-C
X-Ratelimit-Limit
Accept-Language
X-Microcachable
X-Newrelic-App-Data
X-Dynatrace-Js-Agent
Warning
X-Rocket-Nginx-Bypass
X-Auto-Login
Xc-Version
X-Cache-Host
X-Application
X-B-Cookie
X-Cache-Expires
X-Bip
X-Cache-Bucket
X-Cache-Debug
X-BB-ID
X-Cache-Id
X-Connection-Hash
X-Developer
X-Destination
X-Device-Os
X-Died
X-Dispatcher-Server
X-Date
X-D
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-Aed
X-Crawler
X-CUA
X-Cache-URL
X-A-Wwc
Rendered-Blocks
Release
Powered-By
Request-Time
Resin-Trace
RNT-Time
RNT-Machine
Platform
PFcat
MD5-Digest
Is-Eu
Memcached
Meta-Geo-Continent
Node
Mobile-Detection-Method
Rt-Proxy-Cache
Server-Host
X-A-Dam
X-A-Ccd
X-A
X-A-Dcw
X-A-Dgt
X-Accel-Expires-Debug
X-Server-IP
Www
VivaBuild
Thinkindot-CacheControl
Server-ID
Thinkindot-CacheControl-Type
Thinkindot-Control
Viewtype
V-Age
X-Actual-URL
X-From
X-Request-UUID
X-Region-Sid
X-Twitter-Response-Tags
X-Served-From
X-TT-LOGID
X-Returned-From
X-Reboot
X-Rebelmouse-Surrogate-Control
X-Qloud-Router
X-UE-Client-Country
IBM-Web2-Location
X-RCS-CacheZone
X-Rebelmouse-Cache-Control
X-Server-Time
X-Returned-From-BeforeDispatch
X-Trv-Group
X-Swa-Ws
X-S-Cookie
X-Svr
X-Store
X-SRCache-Key
X-S-Maxage
X-Thanos
X-Thinkindot-L3
X-Transaction
X-Returned-From-DLL
X-Returned-From-PostProcessResponse
X-Rewrite-Enabled
X-Rojux
X-PHP-Host
X-PAYTM-SRV-ID
X-VG-WebServer
X-We-Are-Hiring
X-Generated-On
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Level-Front-Cache
X-Layer
X-Generated-In
X-G
X-Fetched-On
X-External-Request-Id
X-ScT
X-FW-Version
X-WebServer
X-Server-By
X-Li-Fabric
X-Varnish-Action
X-User
X-NU-AKA-ACS-Version
X-Passed-To
X-Passed-To-BeforeDispatch
X-Passed-To-PostProcessResponse
X-Passed-To-DLL
X-Var-Ttl
X-Matched-Rule
X-Variation
X-Li-Pop
X-LI-Proto
X-LI-UUID
X-Logtrace-Id
X-DPWN-IS-SECURE
X-Cache-FS-Status
Fastly-Backend-Name
Adler-Geo
Fastly-SWR
Frame-Options
BehaviorPad-Version
Ec-Rule-Version
Ajk
Fly-Cache
Fly-Request-Id
Arc-Country
Cache-Prefix
Fastly-SIE
X-Distil-CS
X-Gannett-Site-Version
X-Gen-Mode
X-ElasticPress-Search
X-F5-Cache
X-Epic-Correlation-Id
Ohc-Response-Time
Backend
Cache-Cookie-Set-Lfrom
X-Block-Status
X-Backend-Url
X-Backend-Host
X-Amz-Meta-Cache-Control
Cache-Cookie-Set-Idcheck
X-Cache-CFC
X-Clientip
X-GeoIP-Country-Code
Backend-Name
Cache-Cookie-Set-From
AKAMAI
X-Hash
X-Secret
X-Server-Group
X-Response-By
X-Request-Start
X-Proxy-Upstream
X-Release
X-ServiceProvider
X-Sf
X-UnsetCookies
X-Via-NSCOPI
X-Geo
X-SVT-ORM-VERSION
X-Stale
X-SVT-ORM-RULES
X-Proxy-Cache-Status
X-P-T
X-Info
X-Instart-Info
X-IN-WAF
X-IN-SSL-APIGATEWAY
X-Hnp-Log
X-IN-APIGATEWAY
X-Server-Cache
X-Location
X-No-Session
X-Node-Id
X-Nginx-Cache-Key
X-MSEdge-Flight
X-MI-In-Market
X-MSEdge-Features
Content-Disposition
X-Phone
SS
Country-Code
Web-Mar-Node
Who
Heartbleed
MI-API
True-Client-Country-4JS
Pramga
Proxy-Connection
Origin
MI-Cache-Age
MI-Cache
Server-Int
Esi-Enabled
Kp-EeAlive
GW-Server
GMS-Ver
SD-X-WS
Decoy-Debug-TTL
Lfy
Magicmarker
Decoy-Debug-Status
Countrycode
Decoy-Debug-Key
X-Dc
X-Be
X-Key
X-Micro-Cache
HA-Cloudapp
HA-Geolon
X-Fstrz
REQUESTUUID
HA-Geocity
HA-Geolat
HA-Geocountry
X-Irp-Debug
X-Platform
HA-Urlpath
X-Request-URI
HA-Ipaddr
X-V
X-Wikidot-Backend
X-ARC
X-Wikidot-Static-Cache
HA-Host
X-Policy
X-Origin-Expires
X-Origin-Date
Ha-Gx-Prefs
X-Origin-TTL
On-Server
X-Eu-Site
X-Page-Type
HA-Georegion
HA-Servedtime
X-Core-Mission
Apple-News-Services-Handled
Apple-News-Services-Host
ServerName
X-Debug-Cache-Expiry
X-Debug-Cache-Store
X-Debug-Cache-Fetch
Apple-News-Services-Parsed-Url
X-Cdn-Srv
Fastly-Soc-X-Request-Id
X-Backend-State
CDCHOST
Fastly-SSL
Apple-News-Services-Request-Url
X-Cache-Info
X-Developers
X-CGP
X-Distributor
X-NODE
X-Debug-Cookies
X-Core-Value
X-Cdn-Origin
WZWS-RAY
X-NX-Host
X-Up
X-Debug-Log
IsBot
X-SIPLIST1
X-Sn-Servicetimems
X-Servername
X-Fastly-Cache
Nel
PageSpeed
RequestId
X-Refresh
X-Org
X-CMS-Context
X-COUNTRY
X-DC
X-Pjax-Url
X-Via-Edge
X-Via-SSL
Cteonnt-Length
X-NC
X-CACHE-AGE
Mime-Version
Cdn
X-VarnPar1
X-VarnCache
X-PARISIEN-Cache-Rendered
Pragrma
X-LAGOON
X-Datadome
X-Newrelic-Synthetics
MIME-Version
X-Urbn-Site-Id
X-Planisys-CDN-Rules
Uber-Trace-Id
UCS
X-Planisys-CDN-TTL
Locale
X-Planisys-CDN-Cache
X-Urbn-Context-Path
X-Instance-Name
Memory
Request-Country
Request-EU
X-Servedbyhost
X-NWS-UUID-VERIFY
X-Req
Host-ID
NGX
Group
V-Cache
X-VCT
Cache-Provider
X-GeoIP-City
PICS-Label
X-Wa
X-Generation-Time
X-RateLimit-Limit-Second
X-FireWall-Port
X-Webkit-Csp
X-RateLimit-Remaining-Second
X-Varnish-Cache-Hits
X-CSRF-TOKEN
X-Gdpr
GeoIP-Country-Code
X-BBXSRF
GeoIP-Latitude
X-HTML-Minification-Powered-By
CF-IPCountry
X-Powered-By-ANYU
HitInfo
X-Aicache-OS
X-WR-MODIFICATION
X-Ratelimit-Remaining
X-B3-Traceid
X-Load-Cache
X-StackifyID
X-UPSTREAM-Address
Server-Cache-Control
X-Fastly-Country-Code
X-Cache-ASPX
CDN
X-Varnish-Authentication
Server-Surrogate-Control
X-Cache-Grace
X-Sedo-Request-Id
X-Cache-Miss-From
Cf-Ipcountry
X-DataStream-MidMile-RTT
X-IPS-LoggedIn
X-DataStream-Origin-MEX-Latency
XServer
X-EIG-Tracking-Id
Geoip-Latitude
GeoIp-Country-Code
X-Varnish-Url
X-VG-WebCache
X-Check-Cacheable
X-ND-Cache
X-TWH-CORRELATION-ID
X-Source
X-Instart-Isnd
X-Sucuri-Cache
Pics-Label
X-Varnish-Beresp-TTL
URI
X-Fastly-Backend-Reqs
X-HOST
X-FORWARDED-FOR
X-RCS-Backend
X-WA
X-From-Cache
CACHE
X-Unique-Id
Proxy-Firewall
Get-Access-Time
Is-Session-Tracking
X-APP
X-CDN-Pop
X-CDN-Pop-IP
FSS-Proxy
FSS-Cache
Processtime
X-GoCache-CacheStatus
X-NodeID
X-Fastly-Cache-Hits
X-Dynatrace
X-Sentry-ID
Powered
X-SRV
X-R9-Blue-Green-Version
X-Csrf-Token
X-FW-Dynamic
X-VC-Cache
X-Cluster-Node
WP-Super-Cache
X-Server-W
X-Flog
X-Hello
X-GDPR
X-Skip-Cache
X-GEO
X-VServer
X-ServedByHost
X-ABtesting
X-ID
DataCenter
X-Pc-Subdomain
X-Oss-Server-Time
X-Oss-Object-Type
X-Oss-Request-Id
X-CSRF-Token
X-Oss-Storage-Class
X-Nananana
X-RequestId
SN
X-Oss-Hash-Crc64ecma
Amp-Access-Control-Allow-Source-Origin
X-GZip
X-B3-SpanId
X-HS-Status
X-PF-Uncompressing
X-Fe
X-BE
TSSecure
X-TrackingId
Dynatrace
Hostname
X-Pf-Uncompressing
X-PJAX-URL
X-Worker
X-Swift-Error
X-Amzn-Remapped-Connection
X-Bug-Bounty
X-Edge-Server
X-Gen-Id
X-Amzn-Remapped-Date
X-GZIP
Cache-Hits
X-Backend-TTL
X-MServer
Cdn-Request-Time
Cdn-Host
ProcessTime
X-LiteSpeed-Cache-Control
X-Cache-Ttl
Requestid
A
X-NGINX-Cache
X-ORIG-AKA-EDGE
Serverid
X-SB
X-LiteSpeed-Tag
DSUID
X-RAMCache
X-Port
X-HostName
X-ServerName
X-VarnPar2
X-VC
X-ORIG-AKA-COUNTRY-CODE
X-Alicdn-Da-Ups-Status
X-Varnish-URL
X-PAGE-TYPE
RequestUuid
T-Server
X-SN
188prxHost
178proxuri
SID
Xxline
409pxxline
352pxline
355prline
286prxHost
225prxHost
219prxHost
189phosttRef
NnCoection
Location
X-Akamai-ERRuleID
X-CS
X-Developed-By
X-Dw-Trace-Id
X-Akamai-ERPolicy
X-Serial
Cneonction
Correlation-Id
HTTPS
Xet-Cookie
X-Tb-Optimization-Total-Bytes-Saved