Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Accept-Ranges
Pragma
X-Powered-By
CF-RAY
Link
ETag
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Id
X-Served-By
Referrer-Policy
X-Varnish
X-Request-Id
X-Timer
CF-Cache-Status
X-AspNet-Version
Access-Control-Allow-Headers
X-Xss-Protection
Access-Control-Allow-Methods
X-Runtime
X-Download-Options
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Cacheable
Alt-Svc
X-Check
X-Generator
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Cache-Status
X-AspNetMvc-Version
Status
X-DNS-Prefetch-Control
X-Template
X-Language
Timing-Allow-Origin
X-Permitted-Cross-Domain-Policies
X-FRAME-OPTIONS
Content-Encoding
X-Iinfo
X-Content-Security-Policy
X-CDN
X-Buckets
X-Turbo-Charged-By
X-Request-ID
Upgrade
X-Type
WPE-Backend
Keep-Alive
X-Pass-Why
CF-Ray
X-Cache-Group
X-AH-Environment
Xkey
P3p
X-Backend
Access-Control-Max-Age
X-Age
Access-Control-Expose-Headers
X-Via
X-Drupal-Dynamic-Cache
EagleId
X-Pingback
X-Nginx-Cache-Status
X-Amz-Id-2
X-Amz-Request-Id
X-Kinja-Server-Push
X-Server-Powered-By
X-Server
X-Hacker
Grace
X-UA-Device
X-Swift-CacheTime
X-Swift-SaveTime
X-Varnish-Cache
X-Robots-Tag
Ali-Swift-Global-Savetime
Cf-Railgun
X-Proxy-Cache
X-Envoy-Upstream-Service-Time
X-LiteSpeed-Cache
X-Page-Speed
X-Ua-Compatible
Request-Context
X-Device
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Ac
Content-Location
X-Cache-Lookup
X-Amz-Version-Id
X-WebKit-CSP
X-Response-Time
X-Host
Surrogate-Control
X-OneAgent-JS-Injection
X-Rq
X-Cnection
X-Node
Server-Timing
X-Backend-Server
Report-To
X-Readtime
X-Rack-Cache
X-Server-Id
Request-Id
EagleEye-TraceId
X-Application-Context
Feature-Policy
X-Cloud-Trace-Context
X-ORACLE-DMS-ECID
X-Instart-Request-ID
X-CST
X-Iejgwucgyu
Edge-Control
X-Clacks-Overhead
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
NEL
X-TTL
Rating
X-Country
X-DynaTrace
X-Varnish-TTL
X-MS-InvokeApp
X-Url
X-Server-Name
Allow
X-Px
X-Country-Code
X-Origin-Cache
Pinterest-Generated-By
X-DataDome
X-Vhost
X-PC
X-Vname
X-TtlSet
X-Cached
X-FTR-Request-ID
X-Ruxit-JS-Agent
RTSS
X-ESI
X-Server-ID
SPRequestGuid
X-Trace
X-Goog-Hash
X-VARITI-CCR
Charset
X-SharePointHealthScore
X-Powered-By-Plesk
X-GitHub-Request-Id
X-T
Accept-CH
X-DynaTrace-JS-Agent
X-Dispatcher
X-Powered-CMS
X-B3-TraceId
Public-Key-Pins
X-Mod-Pagespeed
X-D2id
PB-PID
X-Mobile-Rewrite
Arc-Version
PB-RID
X-F-Cache
X-Kinja-Server
X-Kinja-Build
X-Exp-Variant
X-Exp-Id
X-Kinja
X-Cdn-Fetch
X-GoogleNews-Bot
Verso
X-Kinja-Revision
Content-MD5
X-Version
SPIisLatency
SPRequestDuration
X-Shield-Request-Id
MS-Author-Via
X-Recruiting
X-Dns-Prefetch-Control
X-Abt-Application-Version
X-Oracle-Dms-Rid
X-ORACLE-DMS-RID
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Forwarded-Proto
Nginx-Cache
Accept-CH-Lifetime
X-Client-IP
X-HW
X-DIS-Request-ID
X-N
X-Navigation-Version
Pinterest-Version
X-Upstream-Env
X-Pinterest-Rid
AR-PoweredBy
AR-ATIME
AR-CACHE
X-B
X-Amz-Rid
X-Fastly-Request-ID
DynaTrace
X-Origin-Upstream-Status
X-Upstream
X-Ser
X-Dw-Request-Base-Id
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Amz-Meta-S3cmd-Attrs
X-Hits
TCN
Fastly-Restarts
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Goog-Generation
Realpath
X-XRDS-Location
X-Wix-Server-Artifact-Id
X-Accel-Buffering
Paypal-Debug-Id
X-Content-Options
Arr-Disable-Session-Affinity
Service-Worker-Allowed
X-NF-Request-ID
X-Acc-Meta-Resource-Type
X-Pad
X-Goog-Storage-Class
S
Tracecode
X-Use-Magma
Access-Control-Request-Method
X-Content-Digest
X-Id
X-Debug
X-Varnish-Age
Edge-Cache-Tag
X-Vcap-Request-Id
X-Oneagent-Js-Injection
Front-End-Https
X-MSEdge-Ref
Mrf-Cache-Status
X-Mrf-Item-Lastmod
MRF-Tech
X-Mrf-Section-Lastmod
X-Frontend
X-IPLB-Instance
X-FTR-Realm
X-Country-Code-Real
X-FTR-Balancer
X-FTR-Backend
X-FTR-Cache-Status
X-FTR-DC
X-FTR-Backend-Server
X-PressLabs-Stats
X-FTR-Expires
X-Kinsta-Cache
X-RateLimit-Remaining
MicrosoftSharePointTeamServices
X-Logged-In
X-ATG-Version
X-B3-TraceId-Primal
X-HS-Content-Id
X-HS-Hub-Id
Rt-Fastcgi-Cache
Surrogate-Key
X-Request-Processing-Time
X-Request-Received
X-Cache-Hit
X-Forwarded-For
Fastcgi-Cache
X-Amz-Cf-Pop
X-FastCGI-Cache
X-Zen-Fury
X-Sol
X-Middleton-Display
Display
X-Edge-Location
AMP-Access-Control-Allow-Source-Origin
X-Litespeed-Cache
Backend-Timing
X-Analytics
X-Amzn-Trace-Id
Powered-By-ChinaCache
X-Rid
X-HS-Cache-Config
X-Debug-Info
X-User-Agent
Server-Name
X-Revision
Host
X-Newrelic-App-Data
TP-Cache
TP-L2-Cache
X-FTR-Cache-Host
FilterID
X-Cache-Key
X-Akam-SW-Version
X-CF-Powered-By
AR-Request-ID
Response
X-TA-CDN-Provider
X-Middleton-Response
X-Drupal-Cache-Tags
X-Magnolia-Registration
X-Grace
X-SS-Set-Cookie
Ar-Sid
X-SERVER
X-Mobile
X-Fastcgi-Cache
Refresh
Cache-Status
X-VCache
X-Cached-By
X-Accel-Expires
X-B3-Sampled
X-GUploader-UploadID
Host-Header
X-NWS-LOG-UUID
X-AOL-HN
X-Webkit-CSP
ServerID
X-Varnish-Backend
X-Node-Name
Eomportal-Instance
X-Content-Security-Policy-Report-Only
X-Whom
X-Signature
X-Cache-2
X-Instance
X-Cluster
X-FB-Debug
X-Via-JSL
X-Tumblr-User
X-B-Cache
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-NewRelic-App-Data
X-Akamai-Edgescape
X-Platform-Server
X-Device-Type
X-Webkit-Csp
X-Cache-Control
X-Generated-By
X-Ruxit-Js-Agent
X-Page-Id
X-LB-Cache
X-Varnish-Hostname
X-Drupal-Cache-Contexts
X-BCube-Filmed-By
X-Handled-By
X-App-Environment
X-Framework
Cleartype
X-Srv
X-Request-Guid
X-URL
X-Cache-Rule
X-Cache-Action
X-Az
Cache-Tag
X-AppVersion
X-App-Server
X-Activity-Id
Alternate-Protocol
DC
Source
Liferay-Portal
Retry-After
X-Content-Powered-By
X-Hostname
X-Cache-Server
X-HS-Combine-CSS
X-Varnish-Grace
AR-SID
X-WA-Info
X-WPE-Loopback-Upstream-Addr
MS-CV
X-Daa-Tunnel
X-Geo-Country
HostName
X-Varnish-Server
X-Esi
X-Amz-Replication-Status
Public-Key-Pins-Report-Only
Server-Node
X-Seen-By
X-App-Version
X-Wix-Request-Id
X-TT
ViewerVersion
Webserver
X-Correlation-Id
X-Response-Served-From
X-Tumblr-Pixel-1
X-Cache-NE
Pagespeed
X-WebKit-CSP-Report-Only
Accept-Charset
AsisCache
X-Tumblr-Pixel-2
X-GeoIP
Actual-Object-TTL
X-Amzn-RequestId
X-Amz-Apigw-Id
SRV
Upgrade-Insecure-Requests
GEO-INFO
X-RequestSource
X-Locale
X-Jobs
ServedBy
X-Varnish-Hits
X-Ttl
X-FW-Server
X-Servedby
Payment
X-Yottaa-Metrics
X-UUID
X-FW-Hash
X-FW-Serve
X-Contextid
X-Correlation-ID
X-FW-Type
X-FW-Static
X-S
X-Yottaa-Optimizations
X-Edge-Cache
X-Edge-Cache-Key
X-TX-ID
Viewport
X-Status
X-Varnish-IP
X-XRDS-LOCATION
X-Adobe-Loc
X-Adobe-Content
X-Cacheable-TTL
X-TT-TIMESTAMP
S-Cnection
X-Origin-Server
X-Vg-Webcache
X-Cache-TTL-Remaining
X-Hyper-Cache
Cache
X-Cache-Operation
X-Amz-Server-Side-Encryption
X-Forwarded-Host
Server-Info
X-Real-IP
Datacenter
X-RateLimit-Limit
X-Geo-Segment
Served-By
X-Cache-Age
X-Region
X-Akamai-Request-ID2
Access-Control-Allow-Method
X-CLOUD-TRACE-CONTEXT
X-DataStream-Cache-Status
X-Mode
Healthy
X-Content-Type
X-Sucuri-ID
X-GRACE
CACHE
X-Akamai-Transformed
X-Proxy
Meta-Geo
X-Detected-As
X-Environment-Context
X-L-Path
X-JoinUs
X-Ezoic-Cdn
X-Ocache
X-Path-Route
X-Is-Bot
X-Generated
Fastcgi-X-Cache-Version
Fastcgi-X-Cache
X-Proxied
Fastcgi-Useragent
Machine
X-Rule
X-Cache-Var
X-Routing-Service
X-Zipkin-Id
X-Site-Version
X-Cache-Var-Map
X-RN-RSRV
X-Cache-Config
X-Rendered-As
X-Upgrade-Enabled
DB-Nickname
Country
X-TNCMS
X-Loop
X-Birta-Served
X-Birta-Cache-Post
X-CDN-Cache
X-Amz-Meta-Surrogate-Control
X-Viewer-Country
X-Hosted-By
L5d-Success-Class
From-Origin
X-Section
X-Agile-Id
X-Format
Now
X-Agile
X-NGENIX-Cache
X-Agile-Age
X-Human
X-Access
X-Request-Time
X-OCL
TWC-Device-Class
TWC-Connection-Speed
X-Via-Fastly
X-FC-Vary-Parameters
Cache-Name
X-Grey
X-Hit
X-Origin-Hint
X-Labrador-Cache-Channel
Origin-Cache-Control
Origin-Edge-Control
S-Rt
Webcakes-App-Version
Webcakes-App-Name
X-Tb
X-PCL
Webcakes-Region
Xserver
OT-Force-Account-Verify
Property-Id
X-CCM
X-ServerID
X-Geo
X-Cache-Category-Id
X-Pc-Key
X-Pc-Hit
TWC-GeoIP-Country
X-Pc-Appver
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-Privacy
HitInfo
X-Original-Request
HitType
X-EIG-Tracking-Id
X-Cdn
X-Pubstack
X-VG-TLSProxy
Azure-Version
X-Origin
X-BYPASS-REASON
X-Upstream-CT
X-OVcl-Cache
Accept-Language
X-ProcessESI
X-ProxyCache-Key
X-ProxyCache-Status
X-RemovedCookies
X-OVcl
X-Upstream-HT
Azure-InstanceId
Azure-RegionName
Azure-SiteName
X-IP
X-Xfnlog-Site
Azure-SlotName
NGB
X-Web-Node
Selected-FE
X-Alternate-Cache-Key
X-Microcachable
X-ShardId
Mn-Server-Ip
X-Sorting-Hat-PodId
X-Timing-Wait
X-ShopId
X-Proxy-Build
LB
X-Www-Served-By
X-Shopify-Stage
X-Via-CDN
X-Sorting-Hat-ShopId
X-Cluster-Node
Filters
X-App-Name
X-TWH-CORRELATION-ID
X-UA-Device-Type
X-Cache-Remote
Ms-Operation-Id
X-Connection-Hash
X-Transaction
X-Twitter-Response-Tags
X-Rocket-Nginx-Bypass
X-RTag
X-Cache-Enabled
X-NCache
X-Internal-Host
X-Tumblr-Pixel-3
X-UA
Time
X-Pc-Date
X-Pc-Host
X-Cache-TTL
Access-Control-Request-Headers
IBM-Web2-Location
X-Guploader-Uploadid
X-PHP-Backend
X-APP-VERSION
X-LJ-Flow-ID
X-SplitTest
X-TIME
X-Nginx-Cache
X-VWS-Id
X-Proto
X-Origin-CC
X-Unique-ID
X-AWS-Id
Content-Script-Type
Content-Style-Type
Cache-Hits
X-NodeID
Mail-Subject
We-Hiring
X-Storage
NtCoent-Length
X-Vgn-Hpd-Reason
X-MP-GENERATED-AT
X-Port
X-Time-Microsecs
X-Real-Ip
X-Edge-IP
X-Source
X-Datadome
Backend
X-Akamai-Request-ID
X-Webstats-RespID
X-Backend-Name
Cache-Tags
X-Debug-Cache
X-Ms-Blob-Type
X-Varnish-Cacheable
X-Ms-Request-Id
X-Ms-Lease-Status
X-Ms-Version
X-Cdn-Forward
X-Csrf-Token
X-Distil-CS
X-CACHE-KEY
X-CACHE-GROUP
X-Oracle-Dms-Ecid
X-Endurance-Cache-Level
Locale
X-Urbn-Site-Id
X-Origin-Response-Time
X-CACHE-AGE
X-Urbn-Context-Path
X-Redis-Cache
X-Ua
X-CDN-Forward
X-B3-Spanid
X-Ratelimit-Limit
X-Croise-Owner
PageSpeed
Warning
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
X-EdgeConnect-Cache-Status
User-Agent
X-NC
X-NWS-UUID-VERIFY
X-A-Ccd
X-A
X-A-Dam
X-A-Dcw
X-A-Wwc
X-A-Dgt
VivaBuild
Viewtype
Server-Host
Rt-Proxy-Cache
TSSecure
UCS
V-Age
X-Accel-Expires-Debug
X-Eu-Site
X-Oss-Hash-Crc64ecma
X-BB-ID
X-F5-Cache
X-Fetched-On
X-From
X-External-Request-Id
X-B-Cookie
X-ApacheServer
X-Aed
X-Amz-Meta-Cache-Control
X-Application
X-Oss-Server-Time
Resin-Trace
Rendered-Blocks
Country-Code
HA-Geocountry
Content-Disposition
HA-Geolat
HA-Geolon
HA-Geocity
HA-Cloudapp
Fastly-SIE
Fly-Cache
Fly-Request-Id
Ec-Rule-Version
GMS-Ver
Cache-Prefix
HA-Georegion
Meta-Geo-Continent
MD5-Digest
Mobile-Detection-Method
Ajk
Powered-By
HA-Urlpath
HA-Servedtime
HA-Host
Ha-Gx-Prefs
BehaviorPad-Version
HA-Ipaddr
Arc-Country
X-BBXSRF
X-Oss-Storage-Class
X-Varnish-Cache-Hits
X-DPWN-IS-SECURE
Xc-Version
X-Died
X-Varnish-Beresp-Ttl
X-ScT
X-We-Are-Hiring
X-C
X-Via-Edge
X-Server-By
X-Via-SSL
X-Generated-In
X-GeoIP-Country-Code
X-S-Cookie
X-IN-APIGATEWAY
X-Debug-Cookies
X-Rebelmouse-Cache-Control
X-Rojux
X-Rewrite-Enabled
X-Region-Sid
X-Debug-Log
X-Hash
Fastly-SWR
X-PERF
X-Developer
X-D
X-Destination
X-VG-WebServer
X-PAYTM-SRV-ID
X-NX-Host
X-Cache-Host
X-Oss-Object-Type
X-Cache-URL
X-Oss-Request-Id
X-Irp-Debug
X-NU-AKA-ACS-Version
X-Cache-Bucket
X-Logtrace-Id
X-Sn-Servicetimems
X-ElasticPress-Search
X-SRCache-Key
X-Cdn-Origin
X-Date
X-Server-Time
X-IN-SSL-APIGATEWAY
X-Trv-Group
X-UE-Client-Country
X-G
X-CGP
X-Org
X-CF-Lambda-Fn
X-Cache-Backend
X-IN-WAF
X-Store
X-CF-Lambda-Version
X-Rebelmouse-Surrogate-Control
Fastly-SSL
X-Dc
Version
Pagetype
Cache-Key
X-Developers
X-Dispatcher-Server
X-Key
X-Core-Value
X-Clientip
X-Flog
X-FW-Version
X-Hello
X-GeoIP-City
X-Info
X-DC
X-Hl-Ver
X-Cache-FS-Status
Uber-Trace-Id
Section-Io-Cache
User-Cache-Control
Thinkindot-Control
Thinkindot-CacheControl-Type
Www
X-ABtesting
X-Backend-Url
X-Layer
X-Backend-State
X-Backend-Host
X-Auto-Login
X-Cache-Id
X-Location
X-UnsetCookies
X-User
X-Dynatrace-Js-Agent
X-Thinkindot-L3
X-ServiceProvider
X-SIPLIST1
X-V
X-Var-Ttl
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-VServer
X-Via-NSCOPI
X-Variation
X-S-Maxage
X-Parent-Response-Time
X-Nc
Fastly-Soc-X-Request-Id
X-No-Session
X-MServer
X-Matched-Rule
X-Platform
X-Qloud-Router
X-Request-URI
X-Response-By
X-Release
X-Time
X-Reboot
Thinkindot-CacheControl
X-Epic-Correlation-Id
Countrycode
Memcached
Platform
Apple-News-Services-Handled
Decoy-Debug-Key
Decoy-Debug-TTL
GW-Server
Pramga
Apple-News-Services-Host
Adler-Geo
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Heartbleed
Is-Eu
Backend-Name
IsBot
Release
RNT-Machine
Decoy-Debug-Status
AKAMAI
Origin
Server-ID
WZWS-RAY
FSS-Proxy
RNT-Time
X-Powered-By-ANYU
SN
FSS-Cache
Frame-Options
X-Mrs-Cache-Hits
X-Mrs-Cache
X-Mshield-Cache-Status
X-Mrs-Age
X-P-T
X-Gen-Mode
Kp-EeAlive
X-Phone
X-Goog-Meta-Goog-Reserved-File-Mtime
V-Cache
X-Policy
X-Hnp-Log
X-LI-UUID
X-Li-Fabric
X-LI-Proto
X-Li-Pop
MI-Cache
X-MI-In-Market
Group
X-Nginx-Cache-Key
X-Instance-Name
Magicmarker
Cache-Cookie-Set-Idcheck
X-VCT
X-WebServer
Esi-Enabled
X-Varnish-Action
X-Up
X-Trace-Id
X-TT-LOGID
X-Worker
Fastly-Backend-Name
X-Passed-To
X-Passed-To-BeforeDispatch
X-Node-Id
X-Passed-To-PostProcessResponse
On-Server
X-Actual-URL
X-Swa-Ws
X-Returned-From
X-Gannett-Site-Version
X-Stale
Cache-Cookie-Set-From
X-SVT-ORM-RULES
X-RCS-CacheZone
X-Request-Start
Cache-Cookie-Set-Lfrom
X-Secret
X-Returned-From-DLL
X-Returned-From-BeforeDispatch
X-Sf
X-Returned-From-PostProcessResponse
X-Sentry-ID
X-Server-IP
X-SVT-ORM-VERSION
MI-Cache-Age
X-Sucuri-Cache
X-CUA
X-Device-Os
X-Distributor
Web-Mar-Node
X-Passed-To-DLL
Pragrma
X-Core-Mission
X-Block-Status
Request-EU
Request-Country
X-Cache-Debug
X-Cache-Expires
X-Fastly-Cache
X-Crawler
X-Request-UUID
Odigeo-Trace-Id
True-Client-Country-4JS
Server-Int
X-Refresh
X-Cache-CFC
X-MSEdge-Flight
X-MSEdge-Features
X-NODE
X-Fstrz
REQUESTUUID
X-Thanos
X-Served-From
MI-API
X-Newrelic-Synthetics
X-HOST
X-Unique-Id-Primal
X-Bip
CDCHOST
Proxy-Connection
X-Owner
X-Servername
Who
Fusion-Source
X-Page-Type
MIME-Version
Cteonnt-Length
HTTPS
RequestId
Fusion-Content-Id
Fusion-Component-Id
Fusion-Template-Id
Fusion-Content-Source
X-Req
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Be
X-Backend-TTL
X-Pjax-Url
X-SN
X-Cache-Srv
X-GZip
NodeID
X-Ms-Lease-State
Memory
Cdn-Request-Time
Cdn-Host
X-Origin-TTL
X-Edge-Server
X-Server-Group
Cdn
ProcessTime
X-Servedbyhost
SD-X-WS
Amp-Access-Control-Allow-Source-Origin
CF-IPCountry
X-Content-Age
X-Wa
VIX-Pulpo-Upstream-Status
X-Protected-By
Mime-Version
SS
VIX-Pulpo-Node
A
X-Aicache-OS
X-COUNTRY
GeoIP-Country-Code
X-Ckpd-Fst-Backend
X-Origin-Expires
X-ND-Cache
X-BB-IP
X-Origin-Host
X-Origin-Date
CDN
X-SERVER-NAME
GeoIP-Latitude
X-SRV
X-Varnish-Beresp-TTL
X-StackifyID
Get-Access-Time
Is-Session-Tracking
XServer
X-Pf-Uncompressing
X-APP
X-Fastly-Country-Code
PageType
X-B3-Traceid
Processtime
Geoip-Latitude
PICS-Label
GeoIp-Country-Code
Node
X-Unique-Id
Serverid
X-PHP-Host
Cache-Tv-Group
Vix-Hermes-Req-Id
X-Proxy-Cache-Status
X-Gdpr
X-Cache-Info
X-Varnish-Url
X-Proxy-Upstream
X-Requestid
X-Ratelimit-Remaining
X-CSRF-Token
X-WA
X-Load-Cache
Nel
X-Nananana
X-BACKEND-TTL
X-RateLimit-Remaining-Second
X-Generation-Time
X-Fastly-Cache-Hits
X-ID
X-RateLimit-Limit-Second
Cache-Provider
X-ServedByHost
DataCenter
X-FireWall-Port
Cf-Ipcountry
X-Planisys-CDN-Cache
X-RequestId
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Atg-Version
X-Check-Cacheable
X-UPSTREAM-Address
Request-Time
URI
X-HS-Status
X-FORWARDED-FOR
Hostname
X-Fastly-Backend-Reqs
X-CS
X-NGINX-Cache
X-Front
X-Micro-Cache
X-Server-W
PFcat
X-GZIP
WP-Super-Cache
X-EC-Security-Audit
Host-ID
X-Debug-Cache-Expiry
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-BE
X-WR-MODIFICATION
X-FB-TRIP-ID
X-B3-SpanId
X-DataStream-MidMile-RTT
T-Server
X-DataStream-Origin-MEX-Latency
NGX
Https
X-VG-WebCache
Requestid
X-PARISIEN-Cache-Rendered
X-VarnPar1
X-HTML-Edge-Cache
X-Fe
X-Surge-Debug
X-GDPR
X-VarnCache
Ohc-File-Size
X-Swift-Error
X-GEO
Lfy
X-Cdn-Srv
Ohc-Response-Time
ServerName
X-PJAX-URL
X-IPS-LoggedIn
X-HTML-Minification-Powered-By
X-Svr
X-Instart-Info
RequestUuid
X-Amz-Meta-S3b-Last-Modified
X-Akamai-SSL-Client-Sid
Pics-Label
X-ServerName
X-VarnPar2
X-RAMCache
X-Cache-Ttl
N-Cache
X-Distil-Cs
X-Generated-On
X-PF-Uncompressing
X-PAGE-TYPE
X-From-Cache
X-Level-Front-Cache
WebServer
X-Qnm-Cache
X-M-Log
X-M-Reqid
X-Akamai-ERRuleID
X-Akamai-ERPolicy
X-Serial
NnCoection
Cdn-Src-Port
X-SB
X-VC
X-Gen-Id
X-Dw-Trace-Id
Build-Number
X-Alicdn-Da-Ups-Status
SID