Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Accept-Ranges
Pragma
X-Powered-By
Link
ETag
CF-RAY
Expect-CT
Via
X-Cache
X-XSS-Protection
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-UA-Compatible
X-Cache-Hits
X-Xss-Protection
X-Amz-Cf-Id
X-Served-By
P3P
Referrer-Policy
X-Varnish
X-Request-Id
X-Timer
CF-Cache-Status
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
P3p
CF-Ray
X-Drupal-Cache
X-Amz-Cf-Pop
X-Check
X-Adblock-Key
Alt-Svc
X-Cacheable
X-Generator
Content-Security-Policy-Report-Only
X-Cache-Status
X-DNS-Prefetch-Control
X-AspNetMvc-Version
Status
X-Template
X-Language
Timing-Allow-Origin
X-Permitted-Cross-Domain-Policies
Content-Encoding
X-Iinfo
X-Buckets
X-Content-Security-Policy
X-Turbo-Charged-By
X-Kinja-Server-Push
Upgrade
X-CDN
X-Request-ID
X-Type
Xkey
Keep-Alive
Access-Control-Expose-Headers
Access-Control-Max-Age
WPE-Backend
X-Pass-Why
X-AH-Environment
X-Backend
X-Cache-Group
X-Server
X-Age
X-Drupal-Dynamic-Cache
X-Pingback
X-Via
X-Nginx-Cache-Status
Grace
X-Amz-Id-2
X-Amz-Request-Id
X-Server-Powered-By
EagleId
X-Hacker
X-UA-Device
X-Robots-Tag
X-LiteSpeed-Cache
X-Varnish-Cache
X-Page-Speed
X-Proxy-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Request-Context
Cf-Railgun
X-Envoy-Upstream-Service-Time
Ali-Swift-Global-Savetime
X-Ua-Compatible
X-Ac
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-WebKit-CSP
X-Cache-Lookup
X-Amz-Version-Id
Content-Location
Surrogate-Control
X-Server-Id
X-Cnection
X-Node
X-OneAgent-JS-Injection
X-Host
X-Readtime
EagleEye-TraceId
Report-To
X-Rq
X-Response-Time
Server-Timing
Feature-Policy
X-Application-Context
X-Rack-Cache
X-CST
X-Backend-Server
X-ORACLE-DMS-ECID
X-Iejgwucgyu
X-Cloud-Trace-Context
Request-Id
X-Instart-Request-ID
X-Clacks-Overhead
NEL
Edge-Control
X-DynaTrace
X-Url
Rating
Allow
X-Country
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Varnish-TTL
X-Origin-Cache
X-FTR-Request-ID
X-Country-Code
X-Px
X-Trace
X-Server-ID
X-Vhost
X-B3-TraceId
X-Server-Name
X-GitHub-Request-Id
X-ORACLE-DMS-RID
X-DataDome
X-VARITI-CCR
X-Ruxit-JS-Agent
RTSS
X-ESI
X-Cached
X-Goog-Hash
X-MS-InvokeApp
Accept-CH
Charset
Pinterest-Generated-By
X-TTL
SPRequestGuid
X-Mod-Pagespeed
Verso
Public-Key-Pins
X-PC
X-Vname
X-F-Cache
X-TtlSet
X-Cdn-Fetch
X-Exp-Variant
X-Kinja
X-Exp-Id
X-GoogleNews-Bot
X-Kinja-Build
X-Use-Magma
X-Kinja-Revision
X-Kinja-Server
X-Mobile-Rewrite
PB-RID
Arc-Version
PB-PID
X-Dispatcher
X-Version
X-D2id
X-Cdn
X-T
X-SharePointHealthScore
X-Powered-By-Plesk
X-Abt-Application-Version
X-DIS-Request-ID
X-Powered-CMS
Accept-CH-Lifetime
X-Fastly-Request-ID
X-Ser
X-DynaTrace-JS-Agent
X-Origin-Upstream-Status
X-Upstream-Env
Pinterest-Version
X-Pinterest-Rid
X-B
X-Forwarded-Proto
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Shield-Request-Id
X-Amz-Rid
X-Navigation-Version
MS-Author-Via
Realpath
X-Recruiting
X-Client-IP
DynaTrace
X-HW
SPRequestDuration
SPIisLatency
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Vcap-Request-Id
X-Upstream
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Generation
Nginx-Cache
Content-MD5
X-Accel-Buffering
X-Wix-Server-Artifact-Id
X-Amz-Meta-S3cmd-Attrs
AR-CACHE
AR-ATIME
AR-PoweredBy
X-Ttl
Arr-Disable-Session-Affinity
Edge-Cache-Tag
X-Debug
X-Hits
X-Varnish-Age
X-N
MRF-Tech
Mrf-Cache-Status
X-Goog-Storage-Class
X-B3-TraceId-Primal
X-Oracle-Dms-Rid
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
X-Aspnet-Version
X-NF-Request-ID
X-MSEdge-Ref
X-Via-JSL
X-Dw-Request-Base-Id
X-Acc-Meta-Resource-Type
Access-Control-Request-Method
TCN
X-Id
X-XRDS-Location
S
X-ATG-Version
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-DC
X-FTR-Realm
X-FTR-Backend
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-Expires
Service-Worker-Allowed
X-NewRelic-App-Data
X-Logged-In
X-Oneagent-Js-Injection
Alternate-Protocol
X-Forwarded-For
X-HS-Hub-Id
X-HS-Content-Id
X-Kinsta-Cache
Surrogate-Key
X-Frontend
Tracecode
X-Cache-Key
X-PressLabs-Stats
Rt-Fastcgi-Cache
AMP-Access-Control-Allow-Source-Origin
X-Content-Digest
X-FastCGI-Cache
X-Pad
X-FTR-Cache-Host
X-Grace
Fastly-Restarts
MicrosoftSharePointTeamServices
X-RateLimit-Remaining
Server-Name
X-CF-Powered-By
X-Amzn-Trace-Id
X-Edge-Location
X-Analytics
Backend-Timing
X-Content-Options
X-Ruxit-Js-Agent
TP-Cache
TP-L2-Cache
FilterID
Host
X-Cache-2
X-User-Agent
X-Rid
Fastcgi-Cache
Ar-Sid
X-Magnolia-Registration
X-Whom
X-B3-Sampled
X-Debug-Info
ServerID
X-Revision
X-IPLB-Instance
Eomportal-Instance
X-Page-Id
X-Mobile
X-Hostname
X-Request-Received
X-Request-Processing-Time
X-Srv
X-NWS-LOG-UUID
AR-Request-ID
X-Akam-SW-Version
Paypal-Debug-Id
X-VCache
X-AOL-HN
Front-End-Https
X-URL
Refresh
Retry-After
X-B-Cache
X-Content-Powered-By
X-Litespeed-Cache
X-Signature
X-GUploader-UploadID
X-Request-Guid
Source
X-Device-Type
X-Cache-Action
X-Cluster
X-Framework
X-LB-Cache
X-Handled-By
Cleartype
X-SS-Set-Cookie
X-Varnish-Hostname
X-App-Environment
X-BCube-Filmed-By
X-Instance
X-Cache-Control
X-FB-Debug
X-Tumblr-User
X-Tumblr-Pixel-0
X-WA-Info
X-Tumblr-Pixel
X-Varnish-Grace
X-Cache-Hit
X-Akamai-Edgescape
X-Platform-Server
X-Fastcgi-Cache
X-Content-Security-Policy-Report-Only
X-HS-Cache-Config
Webserver
X-Zen-Fury
X-Esi
Display
X-XRDS-LOCATION
X-Middleton-Display
X-Correlation-Id
X-Sol
X-Az
X-Varnish-Backend
X-Content-Type
X-Activity-Id
X-AppVersion
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Webkit-CSP
Healthy
X-Cache-Server
X-Cache-Rule
X-TA-CDN-Provider
X-Middleton-Response
Response
X-Wix-Request-Id
X-Drupal-Cache-Tags
X-Seen-By
ViewerVersion
X-Daa-Tunnel
X-Varnish-Server
X-TT
Upgrade-Insecure-Requests
X-Generated-By
X-Cached-By
X-App-Server
X-Drupal-Cache-Contexts
X-Geo-Country
X-Origin-Server
Cache-Status
X-Cache-Age
Accept-Charset
S-Cnection
X-CACHE-GROUP
Server-Node
X-DataStream-Cache-Status
X-Amz-Apigw-Id
X-Amz-Replication-Status
X-Amzn-RequestId
X-Accel-Expires
Payment
X-UA-Device-Type
X-S
X-Response-Served-From
X-Contextid
Access-Control-Allow-Method
X-Locale
X-Servedby
X-Cacheable-TTL
X-Adobe-Loc
GEO-INFO
X-Adobe-Content
X-UUID
NGB
X-Edge-Cache
X-Edge-Cache-Key
X-Jobs
X-RequestSource
X-Cache-NE
Viewport
Actual-Object-TTL
Filters
ServedBy
X-Status
X-Varnish-IP
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
X-TT-TIMESTAMP
X-Varnish-Hits
X-TX-ID
X-Amz-Server-Side-Encryption
Server-Info
X-FW-Type
X-FW-Server
AsisCache
Cache-Tv-Group
X-FW-Serve
X-FW-Hash
X-FW-Static
X-Storage
X-GeoIP
X-WebKit-CSP-Report-Only
X-PHP-Backend
X-WPE-Loopback-Upstream-Addr
X-Dns-Prefetch-Control
MS-CV
HostName
X-Cache-Remote
X-Node-Name
X-Rendered-As
X-Cache-TTL-Remaining
X-Croise-Owner
Cache
X-App-Version
Host-Header
From-Origin
SRV
X-Region
X-Vg-Webcache
X-Cache-Operation
X-Redis-Cache
X-Hyper-Cache
X-APP-VERSION
Served-By
X-Dynatrace-Js-Agent
Liferay-Portal
Public-Key-Pins-Report-Only
Cache-Tag
DC
X-HS-Combine-CSS
X-Mode
X-Loop
X-Is-Bot
X-Agile
X-Webstats-RespID
X-TNCMS
X-Timing-Wait
X-Generated
Meta-Geo
Machine
X-Human
X-Hosted-By
X-Detected-As
X-Cache-Var-Map
X-IP
X-RN-RSRV
X-Proxy-Build
X-Site-Version
X-Agile-Age
X-Cache-Var
X-Agile-Id
X-Path-Route
Selected-FE
X-Forwarded-Host
Cache-Name
Xserver
Powered-By-ChinaCache
X-Original-Request
X-Pc-Hit
X-Pc-Appver
X-NGENIX-Cache
X-Environment-Context
X-Akamai-Transformed
X-Internal-Host
X-Grey
X-JoinUs
X-L-Path
X-Labrador-Cache-Channel
X-Endurance-Cache-Level
X-Pc-Key
X-CDN-Cache
Now
X-Web-Node
Origin-Edge-Control
X-Via-Fastly
X-Upgrade-Enabled
X-BYPASS-REASON
X-ProxyCache-Status
X-ProxyCache-Key
X-Request-Time
X-Cache-Category-Id
Origin-Cache-Control
DB-Nickname
X-Birta-Served
X-FC-Vary-Parameters
X-Birta-Cache-Post
S-Rt
X-Origin
X-Vgn-Hpd-Reason
X-VG-TLSProxy
X-Viewer-Country
X-Akamai-Request-ID
X-Origin-Response-Time
X-Upstream-HT
X-Upstream-CT
X-Origin-Host
X-Proxy
X-ServerID
X-Tumblr-Pixel-3
X-NCache
X-Pubstack
X-UA
X-B3-Spanid
X-Origin-CC
X-ProcessESI
X-RemovedCookies
X-Rule
X-OCL
X-Ocache
X-Backend-Name
X-Cache-Config
X-Guploader-Uploadid
X-CCM
X-Tb
X-Time-Microsecs
Azure-SlotName
Azure-Version
Mn-Server-Ip
X-Format
Azure-SiteName
Azure-RegionName
X-Via-CDN
X-Www-Served-By
X-Xfnlog-Site
Azure-InstanceId
Fastcgi-X-Cache-Version
X-PCL
Fastcgi-Useragent
X-BACKEND-TTL
Cache-Tags
Fastcgi-X-Cache
Webcakes-App-Name
TWC-Locale-Group
Webcakes-App-Version
TWC-Privacy
Webcakes-Region
X-Section
X-Origin-Hint
X-Access
TWC-GeoIP-LatLong
Pagespeed
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Routing-Service
X-Proxied
X-Zipkin-Id
TWC-Device-Class
TWC-Connection-Speed
Property-Id
TWC-GeoIP-Country
X-Newrelic-App-Data
HitType
X-App-Name
X-Parent-Response-Time
X-Kong-Upstream-Latency
X-Protected-By
X-Kong-Proxy-Latency
Cache-Key
Datacenter
Content-Style-Type
User-Cache-Control
Content-Script-Type
X-TIME
Vix-Hermes-Req-Id
X-Edge-IP
X-Nginx-Cache
X-Cache-TTL
OT-Force-Account-Verify
X-CACHE-KEY
X-Alternate-Cache-Key
X-ShardId
X-ShopId
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Ezoic-Cdn
X-Shopify-Stage
X-RTag
X-Correlation-ID
Ms-Operation-Id
X-Akamai-Request-ID2
Time
X-Cdn-Forward
X-PERF
X-Real-IP
X-RateLimit-Limit
X-FB-TRIP-ID
X-ApacheServer
X-Cache-Backend
X-Pc-Date
X-Pc-Host
X-OVcl-Cache
X-OVcl
L5d-Success-Class
Accept-Language
NtCoent-Length
X-Mrs-Age
X-Unique-Id-Primal
X-Mrs-Cache-Hits
X-Mrs-Cache
X-Mshield-Cache-Status
X-Webkit-Csp
AR-SID
X-Content-Age
X-Front
X-Real-Ip
Country
Load-Balancing
LB
X-Proto
X-Debug-Cache
X-Amz-Meta-Surrogate-Control
X-Ratelimit-Limit
X-Varnish-Cacheable
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
Section-Io-Cache
X-CDN-Forward
Ohc-File-Size
Fusion-Component-Id
Fusion-Content-Id
Fusion-Source
Fusion-Content-Source
Fusion-Template-Id
X-Hit
X-Sucuri-ID
X-Unique-ID
WZWS-RAY
X-Nc
X-Hl-Ver
X-MP-GENERATED-AT
X-Trace-Id
Mail-Subject
We-Hiring
X-GRACE
Version
Warning
X-Time
X-EdgeConnect-Cache-Status
User-Agent
X-CLOUD-TRACE-CONTEXT
X-Geo
RNT-Machine
SS
Server-ID
SD-X-WS
RNT-Time
Resin-Trace
Rt-Proxy-Cache
Rendered-Blocks
Platform
Powered-By
PFcat
X-Destination
X-Developer
X-Date
X-D
X-Connection-Hash
V-Age
X-Crawler
Release
X-CUA
X-CF-Lambda-Version
X-A
X-Cache-Id
X-B-Cookie
X-BB-ID
X-Cache-URL
X-Auto-Login
X-CF-Lambda-Fn
X-Application
X-Cache-Host
X-Cache-FS-Status
X-Cache-Bucket
Meta-Geo-Continent
X-Cache-Debug
X-Bip
X-Cache-Expires
X-Cache-Enabled
Memcached
X-Device-Os
X-A-Dam
X-A-Dcw
X-A-Ccd
Www
Is-Eu
VivaBuild
X-A-Dgt
X-A-Wwc
Mobile-Detection-Method
X-Aed
Node
X-Actual-URL
X-Accel-Expires-Debug
MD5-Digest
Viewtype
X-Via-SSL
X-Request-UUID
X-Twitter-Response-Tags
X-Response-By
X-Returned-From
X-TT-LOGID
X-Returned-From-BeforeDispatch
X-UE-Client-Country
X-User
X-Rebelmouse-Cache-Control
X-RCS-CacheZone
X-Rebelmouse-Surrogate-Control
X-Region-Sid
X-Release
X-Var-Ttl
X-Trv-Group
X-Transaction
X-Server-Time
X-Server-By
X-SRCache-Key
X-Store
X-Thanos
X-Swa-Ws
X-Served-From
X-ScT
X-Returned-From-PostProcessResponse
X-Returned-From-DLL
X-Rewrite-Enabled
X-Rojux
X-S-Maxage
X-S-Cookie
X-Variation
X-Qloud-Router
X-Li-Pop
X-Li-Fabric
X-LI-Proto
X-LI-UUID
X-Node-Id
X-Logtrace-Id
X-Layer
X-Goog-Meta-Goog-Reserved-File-Mtime
X-DPWN-IS-SECURE
X-Dispatcher-Server
X-External-Request-Id
X-From
X-Generated-In
X-G
X-NU-AKA-ACS-Version
Xc-Version
X-Passed-To-PostProcessResponse
X-Passed-To-DLL
X-Varnish-Action
X-PAYTM-SRV-ID
X-PHP-Host
IBM-Web2-Location
X-Passed-To-BeforeDispatch
X-Passed-To
X-WebServer
X-Org
X-We-Are-Hiring
X-Via-Edge
X-P-T
X-VG-WebServer
X-Died
Request-Time
Fastly-SWR
Arc-Country
Fly-Cache
Fly-Request-Id
Ajk
X-Ua
Access-Control-Request-Headers
Adler-Geo
Fastly-Backend-Name
X-Datadome
BehaviorPad-Version
Frame-Options
Fastly-SIE
Cache-Prefix
Ec-Rule-Version
X-Microcachable
X-Via-NSCOPI
X-C
X-Rocket-Nginx-Bypass
Pagetype
X-Clientip
X-UnsetCookies
X-Origin-Date
X-Amz-Meta-Cache-Control
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
Content-Disposition
Cache-Cookie-Set-From
Backend
X-Thinkindot-L3
AKAMAI
X-Backend-State
X-Cache-CFC
X-Distributor
X-Info
X-Key
X-IN-WAF
X-IN-SSL-APIGATEWAY
X-Hnp-Log
X-IN-APIGATEWAY
X-Proxy-Upstream
X-Proxy-Cache-Status
X-Nginx-Cache-Key
X-Origin-Expires
X-Phone
X-Matched-Rule
X-Location
X-Reboot
X-Hash
X-Sf
X-Fetched-On
X-F5-Cache
X-Stale
X-SVT-ORM-RULES
Country-Code
X-Fstrz
X-FW-Version
X-GeoIP-Country-Code
X-Request-Start
X-Gen-Mode
X-Server-Group
X-Server-IP
X-SVT-ORM-VERSION
X-Block-Status
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
Thinkindot-Control
True-Client-Country-4JS
Kp-EeAlive
Server-Int
Countrycode
On-Server
Origin
Fastly-SSL
Server-Host
Esi-Enabled
Magicmarker
Heartbleed
GW-Server
GMS-Ver
Proxy-Connection
Web-Mar-Node
Pramga
X-NODE
X-Dc
X-ElasticPress-Search
X-Request-URI
X-Secret
X-Eu-Site
X-SIPLIST1
X-ServiceProvider
X-Svr
HA-Geocountry
HA-Geocity
HA-Cloudapp
X-Fastly-Cache
X-Gannett-Site-Version
HA-Georegion
X-Micro-Cache
X-MI-In-Market
HA-Ipaddr
HA-Servedtime
X-No-Session
HA-Urlpath
X-Page-Type
X-Policy
HA-Host
MI-API
MI-Cache
MI-Cache-Age
HA-Geolon
Ha-Gx-Prefs
IsBot
X-Irp-Debug
HA-Geolat
X-Epic-Correlation-Id
X-V
Backend-Name
X-Core-Mission
X-Core-Value
X-Backend-Url
Decoy-Debug-Key
Decoy-Debug-Status
Decoy-Debug-TTL
Who
X-Backend-Host
X-Up
X-CGP
X-MSEdge-Flight
X-MSEdge-Features
X-Distil-CS
X-Be
X-DC
X-Debug-Cache-Expiry
Pragrma
X-Debug-Cache-Fetch
CDCHOST
X-Sn-Servicetimems
Apple-News-Services-Host
X-Wikidot-Backend
X-Platform
Apple-News-Services-Handled
X-Debug-Cache-Store
X-Developers
REQUESTUUID
X-Refresh
X-Debug-Log
X-Origin-TTL
X-NX-Host
Fastly-Soc-X-Request-Id
Apple-News-Services-Request-Url
X-Wikidot-Static-Cache
Apple-News-Services-Parsed-Url
X-Cdn-Origin
X-CACHE-AGE
X-Debug-Cookies
PageSpeed
X-COUNTRY
ServerName
X-Generated-On
X-Urbn-Context-Path
X-Servername
X-NC
Lfy
X-Urbn-Site-Id
X-Planisys-CDN-TTL
X-Level-Front-Cache
X-Instart-Info
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Instance-Name
Request-Country
Locale
Request-EU
Uber-Trace-Id
UCS
X-Cache-Info
Ohc-Response-Time
X-Pjax-Url
Host-ID
X-Cdn-Srv
X-VarnPar1
X-NWS-UUID-VERIFY
RequestId
X-PARISIEN-Cache-Rendered
X-Server-Cache
X-VarnCache
Group
V-Cache
X-Req
X-GeoIP-City
X-VCT
X-ARC
MIME-Version
X-Newrelic-Synthetics
X-B3-Traceid
Cteonnt-Length
HitInfo
Cache-Provider
Memory
Cdn
X-CMS-Context
X-BBXSRF
Mime-Version
X-Powered-By-ANYU
X-Gdpr
PICS-Label
X-EIG-Tracking-Id
X-Servedbyhost
X-Ratelimit-Remaining
Nel
X-TWH-CORRELATION-ID
X-LAGOON
CF-IPCountry
X-WR-MODIFICATION
X-StackifyID
X-Wa
X-Aicache-OS
NGX
CDN
GeoIP-Latitude
X-HTML-Minification-Powered-By
GeoIP-Country-Code
X-Load-Cache
X-Fastly-Country-Code
X-Fastly-Backend-Reqs
XServer
X-FireWall-Port
X-Cluster-Node
X-CSRF-TOKEN
Cf-Ipcountry
X-Varnish-Cache-Hits
X-WA
X-UPSTREAM-Address
FSS-Cache
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
FSS-Proxy
X-Generation-Time
X-Sentry-ID
X-NodeID
X-Sedo-Request-Id
Amp-Access-Control-Allow-Source-Origin
X-Cache-Miss-From
X-Check-Cacheable
X-Flog
GeoIp-Country-Code
Processtime
X-Hello
X-VServer
Geoip-Latitude
X-ABtesting
X-Csrf-Token
SN
X-Source
X-Unique-Id
X-HOST
X-Cache-Grace
CACHE
X-Varnish-Beresp-TTL
X-Cache-ASPX
X-APP
X-CDN-Pop
X-CDN-Pop-IP
Server-Surrogate-Control
Server-Cache-Control
X-Varnish-Authentication
WP-Super-Cache
X-Oss-Storage-Class
X-GZip
X-ServedByHost
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-RCS-Backend
X-Nananana
URI
X-Dynatrace
X-DataStream-MidMile-RTT
X-IPS-LoggedIn
X-CSRF-Token
TSSecure
X-DataStream-Origin-MEX-Latency
X-SRV
X-Skip-Cache
Pics-Label
X-Worker
Cdn-Request-Time
X-VC-Cache
X-Varnish-Url
X-GDPR
X-FORWARDED-FOR
X-Edge-Server
Cdn-Host
X-MServer
X-ID
DataCenter
X-ND-Cache
X-VG-WebCache
A
X-Instart-Isnd
X-HS-Status
X-BE
X-From-Cache
X-GoCache-CacheStatus
PageType
X-Fastly-Cache-Hits
Is-Session-Tracking
X-Sucuri-Cache
X-B3-SpanId
Get-Access-Time
X-Backend-TTL
X-Swift-Error
Dynatrace
X-Port
Hostname
X-PJAX-URL
Proxy-Firewall
HTTPS
X-AWS-Id
X-SplitTest
X-LJ-Flow-ID
X-VWS-Id
X-Pf-Uncompressing
X-Amzn-Remapped-Date
X-Amzn-Remapped-Connection
X-Server-W
X-Bug-Bounty
Powered
X-Gen-Id
Odigeo-Trace-Id
X-GZIP
Requestid
FastCGI-Cache
X-NGINX-Cache
X-Cache-Ttl
X-Owner
X-ORIG-AKA-EDGE
X-VarnPar2
X-SN
X-Fe
X-Pc-Subdomain
Cache-Hits
X-Amz-Meta-S3b-Last-Modified
Serverid
X-Alicdn-Da-Ups-Status
X-PAGE-TYPE
X-Varnish-URL
X-LiteSpeed-Cache-Control
X-PF-Uncompressing
X-RequestId
RequestUuid
X-RAMCache
X-Dw-Trace-Id
X-VC
X-Serial
X-GEO
X-ServerName
X-HostName
T-Server
X-SB
WebServer
X-ORIG-AKA-COUNTRY-CODE
Xet-Cookie
X-Ms-Version
X-Developed-By
SID
X-HTML-Edge-Cache
Correlation-Id
NnCoection
X-Akamai-ERPolicy
X-Ms-Blob-Type
X-Akamai-SSL-Client-Sid
X-CS
X-Ms-Lease-Status
X-Ms-Request-Id
X-LiteSpeed-Tag
X-Akamai-ERRuleID
Location