Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
Last-Modified
Accept-Ranges
X-Content-Type-Options
Pragma
X-Powered-By
CF-RAY
ETag
Link
Expect-CT
Via
X-XSS-Protection
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Id
X-Served-By
Referrer-Policy
X-Xss-Protection
X-Varnish
X-Request-Id
X-Timer
CF-Cache-Status
X-AspNet-Version
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Runtime
X-Download-Options
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Cacheable
Alt-Svc
X-Generator
X-Check
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Cache-Status
X-AspNetMvc-Version
X-DNS-Prefetch-Control
Status
Timing-Allow-Origin
X-Template
X-Language
X-Permitted-Cross-Domain-Policies
X-FRAME-OPTIONS
X-Iinfo
Content-Encoding
X-CDN
X-Content-Security-Policy
X-Buckets
X-Turbo-Charged-By
X-Type
Upgrade
WPE-Backend
X-Pass-Why
X-Request-ID
Keep-Alive
X-Cache-Group
X-AH-Environment
Xkey
X-Backend
Access-Control-Max-Age
X-Age
Access-Control-Expose-Headers
X-Via
EagleId
X-Drupal-Dynamic-Cache
X-Nginx-Cache-Status
X-Server-Powered-By
X-Amz-Id-2
X-Amz-Request-Id
X-Pingback
X-Server
X-Swift-CacheTime
X-Swift-SaveTime
X-Hacker
Grace
X-UA-Device
Ali-Swift-Global-Savetime
X-Varnish-Cache
X-Robots-Tag
P3p
Cf-Railgun
X-Proxy-Cache
X-Envoy-Upstream-Service-Time
X-Page-Speed
X-LiteSpeed-Cache
Request-Context
X-Device
X-Ac
X-Kinja-Server-Push
Content-Location
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Lookup
X-Amz-Version-Id
X-Response-Time
X-OneAgent-JS-Injection
X-Host
X-Backend-Server
Surrogate-Control
X-Cnection
X-Rq
X-Readtime
X-Rack-Cache
Server-Timing
X-WebKit-CSP
Report-To
X-Server-Id
X-Node
X-Cloud-Trace-Context
EagleEye-TraceId
X-Application-Context
Request-Id
X-ORACLE-DMS-ECID
Feature-Policy
X-Instart-Request-ID
X-Ua-Compatible
X-Iejgwucgyu
X-Clacks-Overhead
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Edge-Control
X-CST
Pinterest-Generated-By
X-Country
NEL
X-Px
X-Url
X-TTL
Rating
X-Server-Name
X-Country-Code
X-Ruxit-JS-Agent
X-DataDome
X-Origin-Cache
X-Varnish-TTL
X-DynaTrace
X-MS-InvokeApp
Allow
X-Vhost
X-TtlSet
X-PC
X-Vname
X-Cached
X-FTR-Request-ID
RTSS
X-ESI
X-Server-ID
X-Powered-CMS
X-Goog-Hash
Charset
X-Powered-By-Plesk
X-DynaTrace-JS-Agent
X-VARITI-CCR
Accept-CH
X-Dispatcher
X-D2id
Public-Key-Pins
X-GitHub-Request-Id
X-Mod-Pagespeed
X-Oracle-Dms-Rid
Arc-Version
X-Mobile-Rewrite
PB-PID
PB-RID
X-F-Cache
X-Trace
X-Kinja-Server
X-Kinja
X-Exp-Id
X-Kinja-Build
X-Kinja-Revision
X-Cdn-Fetch
X-Exp-Variant
X-GoogleNews-Bot
MS-Author-Via
X-Version
Content-MD5
SPRequestGuid
Verso
X-SharePointHealthScore
X-T
X-Recruiting
Nginx-Cache
X-Abt-Application-Version
X-Shield-Request-Id
X-Client-IP
SPRequestDuration
SPIisLatency
X-Forwarded-Proto
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
Accept-CH-Lifetime
X-HW
X-N
X-DIS-Request-ID
X-Navigation-Version
X-B3-TraceId
X-Dw-Request-Base-Id
X-Amz-Rid
X-Upstream-Env
Pinterest-Version
X-Pinterest-Rid
X-Origin-Upstream-Status
Fastly-Restarts
X-Upstream
X-XRDS-Location
X-SRCache-Store-Status
X-SRCache-Fetch-Status
AR-CACHE
X-B
AR-ATIME
AR-PoweredBy
X-Fastly-Request-ID
Paypal-Debug-Id
X-ORACLE-DMS-RID
X-Hits
X-Wix-Server-Artifact-Id
X-Accel-Buffering
X-Amz-Meta-S3cmd-Attrs
TCN
Realpath
DynaTrace
Arr-Disable-Session-Affinity
X-Content-Options
X-Pad
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Webkit-Csp
X-NF-Request-ID
Service-Worker-Allowed
X-Content-Digest
X-Id
X-Goog-Storage-Class
X-Ser
Tracecode
Access-Control-Request-Method
X-Acc-Meta-Resource-Type
X-Varnish-Age
S
Front-End-Https
X-Debug
X-Amz-Cf-Pop
MRF-Tech
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
Mrf-Cache-Status
X-Middleton-Display
X-Sol
Display
X-Vcap-Request-Id
X-FastCGI-Cache
X-Kinsta-Cache
X-MSEdge-Ref
X-PressLabs-Stats
X-FTR-Cache-Status
X-Country-Code-Real
X-FTR-Expires
X-FTR-DC
X-FTR-Balancer
X-IPLB-Instance
X-Frontend
X-FTR-Realm
X-FTR-Backend-Server
X-FTR-Backend
X-RateLimit-Remaining
X-Cache-Hit
X-ATG-Version
Surrogate-Key
Powered-By-ChinaCache
X-Geo-Segment
X-HS-Content-Id
X-Forwarded-For
X-HS-Hub-Id
X-Zen-Fury
Fastcgi-Cache
X-Grace
X-Middleton-Response
Response
X-NewRelic-App-Data
Server-Name
X-CF-Powered-By
Rt-Fastcgi-Cache
X-Logged-In
X-Oneagent-Js-Injection
X-Mobile
X-Litespeed-Cache
X-Analytics
Backend-Timing
AMP-Access-Control-Allow-Source-Origin
X-Debug-Info
X-Revision
Host
X-SS-Set-Cookie
TP-Cache
X-Akam-SW-Version
TP-L2-Cache
X-Rid
X-FTR-Cache-Host
X-Amzn-Trace-Id
FilterID
X-Request-Received
X-Request-Processing-Time
X-Edge-Location
X-User-Agent
X-Cache-Key
X-TA-CDN-Provider
MicrosoftSharePointTeamServices
Cache-Status
X-Cached-By
Edge-Cache-Tag
X-Accel-Expires
X-SERVER
Ar-Sid
X-Magnolia-Registration
Refresh
Host-Header
X-Drupal-Cache-Tags
X-GUploader-UploadID
X-Cache-Rule
Liferay-Portal
X-Webkit-CSP
ServerID
X-Varnish-Backend
X-Node-Name
X-Framework
X-Platform-Server
X-Newrelic-App-Data
X-FB-Debug
X-AOL-HN
X-Akamai-Edgescape
X-Whom
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-User
Cache-Tag
X-Varnish-Hostname
X-HS-Cache-Config
X-Cluster
DC
X-B3-Sampled
X-Signature
X-Content-Security-Policy-Report-Only
X-Instance
X-Cache-Control
Public-Key-Pins-Report-Only
X-B-Cache
X-Cache-2
X-Page-Id
X-Device-Type
X-BCube-Filmed-By
X-App-Environment
X-Request-Guid
X-LB-Cache
Cleartype
X-Ttl
X-Handled-By
Accept-Charset
X-Srv
X-Az
X-AppVersion
X-Activity-Id
Eomportal-Instance
X-WPE-Loopback-Upstream-Addr
X-B3-TraceId-Primal
X-Generated-By
X-TT
AR-Request-ID
X-Fastcgi-Cache
Upgrade-Insecure-Requests
X-Use-Magma
X-Cache-Action
X-App-Version
X-Cache-Server
X-Seen-By
MS-CV
X-Wix-Request-Id
ViewerVersion
X-Via-JSL
X-Drupal-Cache-Contexts
X-NWS-LOG-UUID
X-App-Server
X-Correlation-Id
Source
X-Amz-Replication-Status
X-Esi
X-VCache
Retry-After
X-Content-Powered-By
HostName
X-URL
Alternate-Protocol
Server-Node
X-Varnish-Server
SRV
X-Tumblr-Pixel-1
X-Adobe-Content
X-Cache-NE
X-Tumblr-Pixel-2
Webserver
X-WA-Info
X-Response-Served-From
X-Adobe-Loc
Actual-Object-TTL
X-Hostname
X-Cache-TTL-Remaining
X-GeoIP
X-FW-Type
X-Jobs
X-Locale
X-UUID
X-Status
X-FW-Static
X-FW-Server
X-WebKit-CSP-Report-Only
X-FW-Hash
X-FW-Serve
X-RequestSource
X-Edge-Cache
X-Edge-Cache-Key
Payment
X-Amzn-RequestId
AsisCache
X-Amz-Apigw-Id
X-Varnish-Grace
AR-SID
CACHE
X-Contextid
X-Servedby
X-HS-Combine-CSS
X-Geo-Country
ServedBy
Viewport
X-Yottaa-Optimizations
GEO-INFO
X-Yottaa-Metrics
X-Varnish-Hits
X-S
X-TX-ID
X-Varnish-IP
X-Dns-Prefetch-Control
X-TT-TIMESTAMP
Pagespeed
X-Origin-Server
Country
X-Correlation-ID
X-Cache-Operation
PageSpeed
X-Vg-Webcache
X-Sucuri-ID
X-Cacheable-TTL
X-RateLimit-Limit
Server-Info
X-Daa-Tunnel
Served-By
Datacenter
X-Region
X-Hyper-Cache
X-Real-IP
From-Origin
X-Cache-Age
X-Akamai-Request-ID2
X-Amz-Server-Side-Encryption
X-Mode
Content-Script-Type
Content-Style-Type
X-Forwarded-Host
HitType
HitInfo
X-Ezoic-Cdn
X-DataStream-Cache-Status
X-XRDS-LOCATION
Cache
Azure-RegionName
Azure-Version
Azure-InstanceId
X-Amz-Meta-Surrogate-Control
X-App-Name
Access-Control-Allow-Method
Meta-Geo
X-Section
X-Rendered-As
Azure-SiteName
X-Routing-Service
X-ServerID
X-RN-RSRV
X-Rule
X-Rocket-Nginx-Bypass
X-Cache-Var
Fastcgi-X-Cache
X-Format
X-Is-Bot
X-Proxy
Fastcgi-X-Cache-Version
Azure-SlotName
X-Generated
X-Access
X-Proxied
Machine
X-Akamai-Transformed
X-Cache-Var-Map
X-Detected-As
X-JoinUs
X-Hit
X-TIME
S-Cnection
X-Upgrade-Enabled
X-Zipkin-Id
X-Site-Version
X-Tb
TWC-Device-Class
TWC-Connection-Speed
TWC-GeoIP-LatLong
Webcakes-App-Name
X-NGENIX-Cache
TWC-Privacy
TWC-Locale-Group
TWC-GeoIP-Country
Now
LB
X-Origin
Fastcgi-Useragent
DB-Nickname
X-Ocache
X-Cache-Config
OT-Force-Account-Verify
Webcakes-App-Version
Mn-Server-Ip
Property-Id
X-Source
Healthy
X-L-Path
X-Request-Time
X-Environment-Context
X-Content-Type
X-Hosted-By
X-Grey
X-Cache-Category-Id
X-CDN-Cache
X-TWH-CORRELATION-ID
Webcakes-Region
X-Origin-Hint
X-Agile
X-VG-TLSProxy
X-Agile-Id
X-Agile-Age
S-Rt
X-Human
L5d-Success-Class
X-Loop
X-FC-Vary-Parameters
X-OCL
X-EIG-Tracking-Id
Cache-Name
X-Viewer-Country
X-TNCMS
X-Birta-Served
X-Via-Fastly
X-Upstream-HT
Xserver
X-Upstream-CT
X-PCL
X-Birta-Cache-Post
X-Distil-CS
X-ProxyCache-Key
X-AWS-Id
X-LJ-Flow-ID
X-VWS-Id
X-Cluster-Node
X-Xfnlog-Site
X-OVcl
X-RemovedCookies
X-ProxyCache-Status
X-IP
X-ProcessESI
X-BYPASS-REASON
X-Labrador-Cache-Channel
X-OVcl-Cache
IBM-Web2-Location
X-Original-Request
X-CCM
X-SplitTest
X-Pc-Appver
X-Pc-Key
X-Pc-Hit
X-Ms-Version
X-Www-Served-By
X-Ms-Request-Id
X-Ms-Lease-Status
X-Pubstack
Accept-Language
X-Timing-Wait
X-Proxy-Build
X-Cache-Enabled
X-Microcachable
Selected-FE
X-Ms-Blob-Type
X-Shopify-Stage
X-Sorting-Hat-ShopId
X-ShardId
Access-Control-Request-Headers
X-Alternate-Cache-Key
X-ShopId
X-Sorting-Hat-PodId
X-NodeID
X-Path-Route
X-GRACE
X-RTag
X-Web-Node
X-Port
Cache-Hits
X-Via-CDN
X-Twitter-Response-Tags
X-Connection-Hash
X-Transaction
X-Guploader-Uploadid
X-HOST
Ms-Operation-Id
User-Agent
X-MP-GENERATED-AT
X-Cache-Remote
Origin-Edge-Control
Origin-Cache-Control
Time
Backend
X-UA
NtCoent-Length
X-Varnish-Cacheable
X-Unique-ID
X-Geo
X-Origin-CC
X-Nginx-Cache
X-Debug-Cache
X-Edge-IP
X-Varnish-Cache-Hits
X-Cdn-Forward
Mail-Subject
We-Hiring
X-NODE
X-Cache-TTL
X-Sucuri-Cache
X-Real-Ip
X-Pc-Host
X-NCache
X-Pc-Date
X-Internal-Host
X-APP-VERSION
X-Tumblr-Pixel-3
X-Ratelimit-Limit
Fastly-SSL
NGB
X-Newrelic-Synthetics
X-Proto
X-Mrs-Cache
X-Mrs-Cache-Hits
Filters
X-CACHE-GROUP
X-Mrs-Age
X-Ruxit-Js-Agent
X-Mshield-Cache-Status
X-ApacheServer
Warning
X-PERF
X-Vgn-Hpd-Reason
X-Ua
X-Csrf-Token
Locale
X-Storage
X-Urbn-Context-Path
X-Urbn-Site-Id
X-CACHE-KEY
X-Akamai-Request-ID
X-Varnish-Beresp-Grace
X-Time-Microsecs
X-Varnish-Beresp-Status
X-CDN-Forward
X-C
Cache-Key
X-Webstats-RespID
X-EdgeConnect-Cache-Status
X-Nc
X-Backend-Name
X-ElasticPress-Search
X-Dynatrace-Js-Agent
X-Dc
X-CACHE-AGE
X-Powered-By-ANYU
X-Endurance-Cache-Level
WZWS-RAY
User-Cache-Control
Ec-Rule-Version
Thinkindot-CacheControl-Type
Content-Disposition
Thinkindot-CacheControl
Section-Io-Cache
X-IN-WAF
Server-Host
SN
Server-Int
Fly-Cache
X-Irp-Debug
X-MSEdge-Features
Mobile-Detection-Method
X-Matched-Rule
NodeID
X-MSEdge-Flight
Meta-Geo-Continent
IsBot
X-Nginx-Cache-Key
Magicmarker
MD5-Digest
Odigeo-Trace-Id
Origin
FSS-Proxy
FSS-Cache
Fly-Request-Id
Resin-Trace
Rendered-Blocks
Thinkindot-Control
X-NU-AKA-ACS-Version
X-Logtrace-Id
GMS-Ver
X-Org
Rt-Proxy-Cache
X-Accel-Expires-Debug
X-CF-Lambda-Fn
X-G
X-CF-Lambda-Version
X-From
X-Core-Mission
X-Cache-Srv
X-Gannett-Site-Version
X-BBXSRF
X-GeoIP-Country-Code
X-Generated-In
X-Cache-Bucket
X-Croise-Owner
X-Fetched-On
X-Developers
X-Developer
X-Died
X-Distributor
X-DPWN-IS-SECURE
X-Destination
X-Date
X-Fastly-Cache
X-D
X-F5-Cache
X-External-Request-Id
X-BB-ID
X-Backend-Url
X-A
Www
X-A-Ccd
X-A-Dam
X-A-Dcw
X-IN-APIGATEWAY
VivaBuild
X-IN-SSL-APIGATEWAY
UCS
V-Age
Viewtype
X-A-Dgt
X-A-Wwc
X-B-Cookie
X-Backend-Host
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Backend-TTL
X-Hash
X-Application
X-PAYTM-SRV-ID
X-Aed
X-Hl-Ver
X-Amz-Meta-Cache-Control
TSSecure
Cache-Prefix
X-Phone
X-Rewrite-Enabled
X-S-Cookie
X-ScT
X-Server-By
X-Secret
X-Region-Sid
Cache-Tags
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Apple-News-Services-Host
Apple-News-Services-Handled
Ajk
X-Server-Time
X-SIPLIST1
X-Via-SSL
X-Via-Edge
X-Wikidot-Backend
X-Wikidot-Static-Cache
Xc-Version
X-VG-WebServer
X-Up
X-Store
X-SRCache-Key
X-Thinkindot-L3
X-Trv-Group
X-UE-Client-Country
Arc-Country
X-Rojux
X-Epic-Correlation-Id
BehaviorPad-Version
X-Platform
X-Auto-Login
Frame-Options
X-Hello
Cache-Cookie-Set-Lfrom
X-TT-LOGID
X-User
X-UnsetCookies
X-S-Maxage
X-Swa-Ws
Cache-Cookie-Set-Idcheck
HA-Cloudapp
X-Server-IP
Backend-Name
X-Owner
X-Sn-Servicetimems
X-ABtesting
X-GeoIP-City
X-NX-Host
GW-Server
X-Cache-CFC
X-Worker
Countrycode
X-Flog
X-Core-Value
Country-Code
X-Debug-Cookies
X-Dispatcher-Server
X-Eu-Site
X-Debug-Log
X-Fstrz
X-Clientip
X-Cache-URL
X-Cache-Host
X-Cache-Expires
X-Cdn-Origin
X-VServer
X-FW-Version
X-CGP
X-We-Are-Hiring
HA-Geocity
Cache-Cookie-Set-From
X-Layer
HA-Servedtime
HA-Geolon
X-Key
X-Location
X-Request-Start
X-Release
Release
HA-Ipaddr
Ha-Gx-Prefs
HA-Geocountry
AKAMAI
Pramga
HA-Host
Memcached
RNT-Machine
RNT-Time
X-Cache-Backend
X-Redis-Cache
Heartbleed
HA-Georegion
HA-Geolat
Server-ID
X-Reboot
HA-Urlpath
X-No-Session
X-Response-By
X-BB-IP
X-Datadome
X-B3-Spanid
X-Varnish-Beresp-Ttl
X-NC
X-RCS-CacheZone
X-Policy
X-Rebelmouse-Cache-Control
X-MI-In-Market
Decoy-Debug-Key
X-V
X-Node-Id
Fastly-Soc-X-Request-Id
X-ServiceProvider
X-Request-URI
X-Rebelmouse-Surrogate-Control
Decoy-Debug-Status
Decoy-Debug-TTL
X-WebServer
X-LI-Proto
X-Returned-From
X-Sf
X-Request-UUID
X-Stale
X-Hnp-Log
X-Returned-From-BeforeDispatch
X-Instance-Name
X-Returned-From-PostProcessResponse
X-Returned-From-DLL
X-Sentry-ID
X-Served-From
X-Thanos
X-Trace-Id
X-Passed-To-BeforeDispatch
X-VCT
X-LI-UUID
X-Gen-Mode
X-Passed-To-DLL
X-Varnish-Action
X-Variation
X-Li-Fabric
X-Passed-To
X-Li-Pop
X-Var-Ttl
X-Passed-To-PostProcessResponse
X-Cache-Debug
Pragrma
Platform
MI-Cache
Request-Country
Request-EU
X-Actual-URL
Web-Mar-Node
Uber-Trace-Id
Kp-EeAlive
Is-Eu
CDCHOST
Adler-Geo
X-Device-Os
Esi-Enabled
Fastly-Backend-Name
Fastly-SWR
Fastly-SIE
X-Backend-State
MI-Cache-Age
X-Bip
X-Block-Status
X-Crawler
X-CUA
X-Cache-Id
Pagetype
X-Info
True-Client-Country-4JS
Proxy-Connection
On-Server
X-UA-Device-Type
X-Via-NSCOPI
X-DC
X-PHP-Backend
X-Ms-Lease-State
REQUESTUUID
X-Qloud-Router
X-P-T
Cteonnt-Length
MI-API
HTTPS
RequestId
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Powered-By
X-Pjax-Url
ProcessTime
X-SN
X-Page-Type
X-Ckpd-Fst-Backend
X-Servername
X-Be
MIME-Version
X-CLOUD-TRACE-CONTEXT
X-Refresh
Cdn
X-Req
X-NWS-UUID-VERIFY
X-Oracle-Dms-Ecid
X-Oss-Request-Id
X-Origin-Response-Time
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Origin-TTL
X-MServer
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-GZip
Memory
X-Oss-Storage-Class
Amp-Access-Control-Allow-Source-Origin
Version
X-Content-Age
X-Parent-Response-Time
CF-IPCountry
X-Cache-FS-Status
Mime-Version
Who
X-Aicache-OS
Group
X-Unique-Id-Primal
V-Cache
X-ND-Cache
X-Servedbyhost
X-Varnish-Url
X-Time
X-Vcache
Fusion-Source
X-RateLimit-Remaining-Second
X-Generation-Time
X-Pf-Uncompressing
X-RateLimit-Limit-Second
X-COUNTRY
X-Unique-Id
Fusion-Content-Source
Fusion-Component-Id
Fusion-Content-Id
Fusion-Template-Id
GeoIP-Country-Code
SS
X-Wa
X-FireWall-Port
X-Varnish-Beresp-TTL
X-GEO
Cdn-Host
GeoIP-Latitude
Cdn-Request-Time
X-Fastly-Cache-Hits
X-Cache-Info
CDN
X-Edge-Server
X-SRV
X-Ratelimit-Remaining
PageType
Is-Session-Tracking
Get-Access-Time
X-Qnm-Cache
XServer
X-M-Reqid
X-M-Log
X-Protected-By
GeoIp-Country-Code
Geoip-Latitude
X-CS
X-EC-Security-Audit
X-B3-Traceid
Load-Balancing
X-APP
Serverid
T-Server
X-Server-Group
X-Server-W
X-Surge-Debug
X-WA
NGX
ServerName
SD-X-WS
X-Requestid
X-HTML-Minification-Powered-By
X-Check-Cacheable
X-CSRF-Token
X-Origin-Expires
X-Origin-Date
Nel
Cf-Ipcountry
A
X-ID
X-Nananana
X-ARC
DataCenter
X-ServedByHost
X-StackifyID
X-SERVER-NAME
X-RequestId
X-Alicdn-Da-Ups-Status
X-Skip-Cache
PICS-Label
X-HS-Status
X-FORWARDED-FOR
Processtime
Hostname
URI
X-GZIP
X-Gdpr
X-Fastly-Country-Code
X-VG-WebCache
X-Load-Cache
X-Proxy-Server
X-NGINX-Cache
X-UPSTREAM-Address
X-PF-Uncompressing
X-Feature
X-B3-SpanId
WP-Super-Cache
X-DataStream-Origin-MEX-Latency
Cneonction
Cache-Provider
X-ServerName
X-Origin-Host
X-DataStream-MidMile-RTT
Powered
X-PAGE-TYPE
X-Fe
Node
X-BE
X-PHP-Host
Lfy
X-Cdn-Srv
X-Atg-Version
Requestid
X-IPS-LoggedIn
X-PJAX-URL
Https
RequestUuid
X-Proxy-Cache-Status
VIX-Pulpo-Upstream-Status
X-Proxy-Upstream
X-HTML-Edge-Cache
X-Content-Encoded-By
VIX-Pulpo-Node
X-Distil-Cs
Vix-Hermes-Req-Id
X-From-Cache
Sid
X-SB
X-Cache-Ttl
N-Cache
X-Fastly-Backend-Reqs
X-VC
X-GDPR
X-Akamai-SSL-Client-Sid
SID
X-Serial
PFcat
Host-ID
Xet-Cookie
X-CSRF-TOKEN
X-WR-MODIFICATION
X-Dw-Trace-Id
Cdn-Src-Port
X-RAMCache
X-Gen-Id
X-Grace-Duration
Build-Number