Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Accept-Ranges
Pragma
X-Powered-By
Link
ETag
CF-RAY
Expect-CT
Via
X-XSS-Protection
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Id
X-Served-By
P3P
Referrer-Policy
X-Varnish
X-Xss-Protection
X-Timer
CF-Cache-Status
X-Request-Id
Access-Control-Allow-Headers
X-AspNet-Version
Access-Control-Allow-Methods
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
P3p
X-Drupal-Cache
X-Check
X-Adblock-Key
Alt-Svc
X-Cacheable
X-Generator
CF-Ray
Content-Security-Policy-Report-Only
X-Cache-Status
X-AspNetMvc-Version
Status
X-Amz-Cf-Pop
X-DNS-Prefetch-Control
X-Request-ID
X-Template
X-Language
Timing-Allow-Origin
Content-Encoding
X-Permitted-Cross-Domain-Policies
X-Iinfo
X-Buckets
X-Content-Security-Policy
X-Turbo-Charged-By
Upgrade
X-Kinja-Server-Push
X-CDN
X-Type
Xkey
Keep-Alive
Access-Control-Expose-Headers
WPE-Backend
X-Pass-Why
X-AH-Environment
Access-Control-Max-Age
X-Backend
X-Cache-Group
X-Server
X-Age
X-Drupal-Dynamic-Cache
X-Pingback
X-Via
X-Nginx-Cache-Status
X-Amz-Request-Id
X-Amz-Id-2
X-Server-Powered-By
Grace
X-Hacker
EagleId
X-UA-Device
X-Robots-Tag
X-LiteSpeed-Cache
X-Varnish-Cache
X-Page-Speed
X-Swift-CacheTime
X-Swift-SaveTime
X-Proxy-Cache
Cf-Railgun
X-Envoy-Upstream-Service-Time
Request-Context
Ali-Swift-Global-Savetime
X-Ua-Compatible
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Ac
X-Device
X-WebKit-CSP
X-Cache-Lookup
Content-Location
X-Amz-Version-Id
Surrogate-Control
X-Cnection
X-Server-Id
X-Host
X-Readtime
Report-To
X-Node
X-Rq
EagleEye-TraceId
Server-Timing
X-Response-Time
X-OneAgent-JS-Injection
X-CST
Feature-Policy
X-Rack-Cache
X-Backend-Server
X-ORACLE-DMS-ECID
X-Application-Context
X-Iejgwucgyu
Request-Id
X-Instart-Request-ID
X-Cloud-Trace-Context
X-Clacks-Overhead
Edge-Control
NEL
X-Url
X-DynaTrace
Allow
Rating
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Country
X-Varnish-TTL
X-Origin-Cache
X-FTR-Request-ID
X-Country-Code
X-B3-TraceId
X-Cdn
X-Trace
X-Server-Name
X-Px
X-Vhost
X-DataDome
X-ESI
X-Server-ID
X-GitHub-Request-Id
X-MS-InvokeApp
RTSS
X-Cached
X-VARITI-CCR
X-Ruxit-JS-Agent
Accept-CH
SPRequestGuid
X-Goog-Hash
X-ORACLE-DMS-RID
Charset
X-PC
X-Vname
X-TtlSet
X-TTL
Pinterest-Generated-By
X-Mod-Pagespeed
Public-Key-Pins
X-D2id
X-F-Cache
X-Dispatcher
X-GoogleNews-Bot
X-Kinja
X-Kinja-Build
X-Kinja-Revision
X-Cdn-Fetch
X-Exp-Variant
X-Use-Magma
Verso
X-Exp-Id
X-Kinja-Server
X-SharePointHealthScore
PB-RID
Arc-Version
X-Mobile-Rewrite
PB-PID
X-T
X-Version
X-Powered-By-Plesk
X-DynaTrace-JS-Agent
X-Abt-Application-Version
Accept-CH-Lifetime
X-Powered-CMS
X-DIS-Request-ID
X-Dns-Prefetch-Control
X-Ser
X-Fastly-Request-ID
Pinterest-Version
X-Upstream-Env
X-Pinterest-Rid
X-Navigation-Version
X-Origin-Upstream-Status
X-Shield-Request-Id
X-Forwarded-Proto
X-Recruiting
X-B
DynaTrace
MS-Author-Via
X-Client-IP
X-Amz-Rid
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-HW
SPIisLatency
SPRequestDuration
Realpath
Content-MD5
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Oneagent-Js-Injection
X-Upstream
Nginx-Cache
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Vcap-Request-Id
X-Goog-Metageneration
Edge-Cache-Tag
X-Amz-Meta-S3cmd-Attrs
AR-PoweredBy
AR-CACHE
X-Oracle-Dms-Rid
AR-ATIME
X-Wix-Server-Artifact-Id
X-Accel-Buffering
X-N
X-Ttl
X-Hits
TCN
Arr-Disable-Session-Affinity
X-Varnish-Age
X-Debug
X-NF-Request-ID
Access-Control-Request-Method
Mrf-Cache-Status
X-Goog-Storage-Class
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
X-B3-TraceId-Primal
MRF-Tech
X-Acc-Meta-Resource-Type
X-MSEdge-Ref
X-Dw-Request-Base-Id
X-NewRelic-App-Data
S
X-ATG-Version
X-Id
Service-Worker-Allowed
X-FTR-Balancer
X-Via-JSL
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-DC
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Realm
X-Logged-In
X-FTR-Expires
X-XRDS-Location
Tracecode
X-FastCGI-Cache
X-Forwarded-For
X-Content-Digest
X-PressLabs-Stats
X-HS-Content-Id
X-HS-Hub-Id
Rt-Fastcgi-Cache
X-Pad
Alternate-Protocol
X-Frontend
X-Kinsta-Cache
Surrogate-Key
Fastly-Restarts
X-Cache-Key
AMP-Access-Control-Allow-Source-Origin
MicrosoftSharePointTeamServices
X-Content-Options
X-RateLimit-Remaining
Ar-Sid
X-FTR-Cache-Host
X-Grace
X-Ruxit-Js-Agent
Server-Name
X-Edge-Location
X-Amzn-Trace-Id
Fastcgi-Cache
X-Analytics
Backend-Timing
FilterID
Host
X-CF-Powered-By
X-Rid
TP-L2-Cache
TP-Cache
X-IPLB-Instance
X-User-Agent
X-Debug-Info
X-Hostname
X-Magnolia-Registration
ServerID
X-Revision
X-Whom
X-B3-Sampled
Eomportal-Instance
X-Request-Received
X-Cache-2
Paypal-Debug-Id
X-Request-Processing-Time
X-NWS-LOG-UUID
X-Page-Id
X-HS-Cache-Config
X-Mobile
AR-Request-ID
X-Srv
X-Akam-SW-Version
Front-End-Https
X-AOL-HN
X-Content-Powered-By
Retry-After
X-VCache
X-Cache-Hit
X-Litespeed-Cache
X-GUploader-UploadID
X-B-Cache
X-Varnish-Grace
X-Signature
X-SS-Set-Cookie
X-LB-Cache
X-Handled-By
X-Device-Type
X-Cluster
Source
X-FB-Debug
X-Request-Guid
X-Correlation-Id
Refresh
Cleartype
X-Instance
X-Cache-Action
X-XRDS-LOCATION
X-Cache-Control
X-WA-Info
X-App-Environment
X-BCube-Filmed-By
X-Tumblr-User
X-Platform-Server
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Varnish-Hostname
X-Framework
X-Content-Security-Policy-Report-Only
X-Zen-Fury
X-Akamai-Edgescape
X-TA-CDN-Provider
Webserver
X-Varnish-Backend
X-Webkit-CSP
X-Daa-Tunnel
X-Middleton-Display
X-Sol
Display
X-Fastcgi-Cache
X-Cache-Server
X-Drupal-Cache-Tags
X-Varnish-Server
X-Activity-Id
X-Az
X-AppVersion
X-Drupal-Cache-Contexts
Healthy
X-Cache-Rule
X-Content-Type
VIX-Pulpo-Upstream-Status
X-Generated-By
X-Geo-Country
VIX-Pulpo-Node
X-URL
Response
X-Middleton-Response
Server-Node
X-Cache-Age
X-App-Server
X-Cached-By
S-Cnection
X-Wix-Request-Id
ViewerVersion
X-Seen-By
Cache-Status
X-Accel-Expires
X-Node-Name
X-CACHE-GROUP
X-DataStream-Cache-Status
X-Amz-Replication-Status
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Origin-Server
X-Esi
Upgrade-Insecure-Requests
X-TT
X-WPE-Loopback-Upstream-Addr
X-Response-Served-From
X-S
Filters
Payment
NGB
GEO-INFO
Host-Header
X-Cacheable-TTL
HostName
X-Locale
X-UA-Device-Type
X-Cache-NE
X-Varnish-IP
X-Edge-Cache-Key
Actual-Object-TTL
X-GeoIP
Viewport
X-RequestSource
X-Edge-Cache
ServedBy
X-Contextid
X-FW-Server
X-Tumblr-Pixel-1
X-Tumblr-Pixel-2
X-Servedby
X-Jobs
X-FW-Serve
X-FW-Type
X-FW-Hash
X-FW-Static
AsisCache
X-UUID
X-Varnish-Hits
X-Status
X-TT-TIMESTAMP
Access-Control-Allow-Method
X-Amz-Server-Side-Encryption
X-TX-ID
X-WebKit-CSP-Report-Only
Server-Info
X-Adobe-Loc
Accept-Charset
X-Adobe-Content
X-Storage
X-Hyper-Cache
X-HS-Combine-CSS
SRV
Cache
X-CLOUD-TRACE-CONTEXT
X-Cache-TTL-Remaining
X-Rendered-As
X-Vg-Webcache
X-PHP-Backend
X-Cache-Remote
X-Croise-Owner
From-Origin
MS-CV
X-App-Version
X-APP-VERSION
Cache-Tag
X-Cache-Operation
Cache-Tv-Group
DC
X-Region
Public-Key-Pins-Report-Only
X-Forwarded-Host
Served-By
X-Redis-Cache
Liferay-Portal
X-Yottaa-Metrics
X-Mode
X-Yottaa-Optimizations
X-UA
X-Akamai-Request-ID2
X-Agile-Id
Selected-FE
Meta-Geo
X-RN-RSRV
X-Agile
X-Agile-Age
X-Cache-Var-Map
X-Endurance-Cache-Level
X-Generated
X-Site-Version
X-Hosted-By
X-Akamai-Transformed
X-Cache-Var
X-Human
X-Detected-As
X-IP
Machine
X-Upgrade-Enabled
X-TNCMS
X-Webstats-RespID
X-Proxy-Build
X-Path-Route
X-Request-Time
X-NGENIX-Cache
X-Timing-Wait
X-Loop
X-TIME
X-Is-Bot
X-Pc-Appver
X-ProxyCache-Key
X-ProxyCache-Status
X-Environment-Context
X-Proxied
Now
X-Routing-Service
X-NCache
X-Pc-Key
S-Rt
Origin-Edge-Control
Origin-Cache-Control
X-Original-Request
X-BYPASS-REASON
X-Pc-Hit
X-Cache-Category-Id
Cache-Name
X-CDN-Cache
Xserver
X-JoinUs
X-Internal-Host
X-Via-Fastly
X-Vgn-Hpd-Reason
X-Zipkin-Id
X-L-Path
X-Labrador-Cache-Channel
X-Grey
X-Format
TWC-GeoIP-Country
X-ProcessESI
TWC-Locale-Group
TWC-Privacy
TWC-Device-Class
TWC-Connection-Speed
Property-Id
X-Viewer-Country
X-Upstream-HT
X-Upstream-CT
Webcakes-App-Name
X-RemovedCookies
X-Section
X-Web-Node
X-VG-TLSProxy
X-PCL
X-Tumblr-Pixel-3
X-Proxy
X-Birta-Served
X-Birta-Cache-Post
X-Access
Webcakes-Region
X-FC-Vary-Parameters
X-Pubstack
X-OCL
X-Origin-Hint
Webcakes-App-Version
TWC-GeoIP-LatLong
Datacenter
DB-Nickname
Powered-By-ChinaCache
X-Rule
Fastcgi-X-Cache-Version
X-ServerID
X-Akamai-Request-ID
X-Time-Microsecs
X-Origin-Host
X-Xfnlog-Site
X-Www-Served-By
Fastcgi-X-Cache
X-Via-CDN
X-Origin-Response-Time
X-Origin
X-Ocache
Fastcgi-Useragent
Pagespeed
Cache-Tags
X-Backend-Name
X-Cache-Config
X-Origin-CC
X-Tb
X-CCM
Azure-SiteName
OT-Force-Account-Verify
Azure-Version
Mn-Server-Ip
Azure-RegionName
Azure-SlotName
Azure-InstanceId
X-B3-Spanid
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Shopify-Stage
X-ShopId
X-Alternate-Cache-Key
X-ShardId
HitType
X-Parent-Response-Time
X-App-Name
X-NODE
Accept-Language
X-Guploader-Uploadid
X-Cache-TTL
X-Nginx-Cache
X-RateLimit-Limit
X-OVcl-Cache
X-Ezoic-Cdn
X-OVcl
X-CACHE-KEY
L5d-Success-Class
User-Cache-Control
X-Edge-IP
X-Protected-By
Vix-Hermes-Req-Id
NtCoent-Length
Cache-Key
X-Real-IP
Content-Style-Type
Content-Script-Type
Time
X-Newrelic-App-Data
X-Amz-Meta-Surrogate-Control
X-Real-Ip
LB
X-Proto
X-BACKEND-TTL
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Cache-Backend
X-Webkit-Csp
X-RTag
X-Pc-Date
X-Correlation-ID
X-Pc-Host
Ms-Operation-Id
X-ApacheServer
X-PERF
X-Front
X-Cdn-Forward
X-Nc
Section-Io-Cache
X-Mrs-Age
X-Mrs-Cache
X-Dynatrace-Js-Agent
X-Mrs-Cache-Hits
X-Mshield-Cache-Status
X-Hit
X-CDN-Forward
X-Unique-Id-Primal
X-Sucuri-ID
AR-SID
X-Varnish-Cacheable
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-FB-TRIP-ID
WZWS-RAY
X-Microcachable
X-Debug-Cache
X-Ratelimit-Limit
X-Content-Age
X-Dc
X-GRACE
Access-Control-Request-Headers
X-C
Version
X-Transaction
X-Twitter-Response-Tags
X-Cache-Enabled
X-Unique-ID
X-Connection-Hash
Fusion-Content-Id
X-Trace-Id
Fusion-Component-Id
X-EdgeConnect-Cache-Status
Fusion-Template-Id
Fusion-Content-Source
Fusion-Source
Country
Warning
X-MP-GENERATED-AT
X-CUA
X-Cache-Id
X-Date
X-D
X-Crawler
X-Cache-Bucket
X-Cache-FS-Status
Is-Eu
X-CF-Lambda-Fn
X-Cache-URL
Locale
X-Cache-Debug
X-Cache-Host
MD5-Digest
X-CF-Lambda-Version
X-Backend-State
SD-X-WS
X-Destination
X-A-Ccd
Rt-Proxy-Cache
RNT-Time
RNT-Machine
X-A-Dam
X-A
VivaBuild
SS
UCS
Uber-Trace-Id
Server-ID
V-Age
Server-Host
Viewtype
X-A-Dcw
X-A-Dgt
X-B-Cookie
X-Auto-Login
X-Application
Mobile-Detection-Method
X-BB-ID
Meta-Geo-Continent
X-Bip
X-Aed
Node
X-Actual-URL
Resin-Trace
X-A-Wwc
Rendered-Blocks
Release
Platform
Powered-By
Memcached
X-RCS-CacheZone
X-ScT
X-S-Maxage
X-S-Cookie
X-Served-From
X-Server-By
X-SRCache-Key
X-Server-Time
X-Rojux
X-Rewrite-Enabled
X-Response-By
X-Request-UUID
X-Returned-From
X-Returned-From-BeforeDispatch
X-Returned-From-PostProcessResponse
X-Returned-From-DLL
X-Store
X-Thanos
X-Via-Edge
X-VG-WebServer
X-Via-SSL
X-We-Are-Hiring
Xc-Version
X-WebServer
X-Varnish-Action
X-Variation
X-UE-Client-Country
X-Trv-Group
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Var-Ttl
X-User
X-Release
X-Region-Sid
X-GeoIP-Country-Code
X-Generated-In
X-G
X-Layer
X-Li-Fabric
X-LI-Proto
X-Li-Pop
X-FW-Version
X-From
X-Died
X-Device-Os
X-Dispatcher-Server
X-DPWN-IS-SECURE
X-Fetched-On
X-External-Request-Id
X-LI-UUID
X-Logtrace-Id
X-Qloud-Router
X-PHP-Host
IBM-Web2-Location
X-Rebelmouse-Cache-Control
X-Reboot
X-Rebelmouse-Surrogate-Control
X-PAYTM-SRV-ID
X-Passed-To-PostProcessResponse
X-NU-AKA-ACS-Version
X-Node-Id
X-Org
X-Passed-To
X-Passed-To-DLL
X-Passed-To-BeforeDispatch
X-Developer
X-Accel-Expires-Debug
Frame-Options
X-Rocket-Nginx-Bypass
Ajk
Adler-Geo
Fly-Request-Id
Cache-Prefix
Fastly-SWR
Fly-Cache
We-Hiring
Mail-Subject
Fastly-Backend-Name
Fastly-SIE
Ohc-File-Size
Arc-Country
Load-Balancing
BehaviorPad-Version
Ec-Rule-Version
X-Hl-Ver
X-NWS-UUID-VERIFY
X-Varnish-Beresp-Ttl
Who
X-Amz-Meta-Cache-Control
X-Proxy-Cache-Status
Web-Mar-Node
Backend
Apple-News-Services-Host
Apple-News-Services-Request-Url
Apple-News-Services-Handled
AKAMAI
Apple-News-Services-Parsed-Url
Www
X-Block-Status
X-Hash
X-Hnp-Log
X-IN-APIGATEWAY
X-IN-SSL-APIGATEWAY
X-Stale
X-Epic-Correlation-Id
X-Gen-Mode
X-F5-Cache
X-Eu-Site
X-IN-WAF
X-Info
X-Matched-Rule
X-Cache-Expires
X-No-Session
X-Location
X-CGP
X-Key
X-Core-Value
X-Clientip
X-Via-NSCOPI
Backend-Name
X-Swa-Ws
HA-Host
HA-Ipaddr
X-Proxy-Upstream
Ha-Gx-Prefs
X-Time
Origin
HA-Georegion
X-Thinkindot-L3
X-SVT-ORM-VERSION
HA-Servedtime
X-Sf
GMS-Ver
GW-Server
Heartbleed
Kp-EeAlive
X-SVT-ORM-RULES
X-Server-Group
X-Server-IP
HA-Urlpath
HA-Geolat
HA-Geolon
Content-Disposition
Country-Code
Pragrma
Esi-Enabled
HA-Cloudapp
Thinkindot-CacheControl
Thinkindot-Control
HA-Geocity
Thinkindot-CacheControl-Type
X-Request-Start
Countrycode
X-UnsetCookies
HA-Geocountry
Request-Country
Pramga
Request-EU
X-Be
V-Cache
Group
User-Agent
X-Geo
X-SIPLIST1
X-Gannett-Site-Version
True-Client-Country-4JS
On-Server
Proxy-Connection
X-GeoIP-City
X-Goog-Meta-Goog-Reserved-File-Mtime
Decoy-Debug-Status
X-VCT
X-Request-URI
X-P-T
X-TT-LOGID
X-Fstrz
X-Up
X-Policy
X-Platform
X-Phone
X-Wikidot-Backend
X-Wikidot-Static-Cache
MI-API
MI-Cache
MI-Cache-Age
X-Irp-Debug
Decoy-Debug-TTL
X-Secret
HitInfo
Decoy-Debug-Key
X-Nginx-Cache-Key
X-Instance-Name
X-Distributor
X-Backend-Url
X-Distil-CS
REQUESTUUID
X-Developers
X-ServiceProvider
X-Cache-CFC
Fastly-SSL
X-V
X-Backend-Host
Fastly-Soc-X-Request-Id
Server-Int
IsBot
Cache-Cookie-Set-Idcheck
CDCHOST
Cache-Cookie-Set-Lfrom
X-MI-In-Market
Cache-Cookie-Set-From
X-Ua
X-MSEdge-Features
X-NX-Host
Request-Time
X-Origin-Expires
X-Refresh
X-Cdn-Origin
X-Origin-TTL
X-Origin-Date
X-MSEdge-Flight
X-Sn-Servicetimems
X-Debug-Log
Magicmarker
X-ElasticPress-Search
X-Servername
X-Fastly-Cache
X-Core-Mission
X-Debug-Cookies
Pagetype
X-DC
RequestId
X-Planisys-CDN-Cache
X-Page-Type
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-COUNTRY
PFcat
X-Req
X-Pjax-Url
X-EIG-Tracking-Id
Host-ID
X-BBXSRF
PageSpeed
X-Powered-By-ANYU
X-Debug-Cache-Fetch
X-Svr
X-Debug-Cache-Store
X-PARISIEN-Cache-Rendered
X-CACHE-AGE
X-VarnCache
X-NC
X-Micro-Cache
X-Debug-Cache-Expiry
X-VarnPar1
X-Newrelic-Synthetics
X-HOST
X-Level-Front-Cache
X-Generated-On
X-Instart-Info
MIME-Version
X-Datadome
Mime-Version
Lfy
Cache-Provider
ServerName
Cdn
Ohc-Response-Time
X-Server-Cache
PICS-Label
X-Cache-Info
X-Gdpr
X-TWH-CORRELATION-ID
X-Cdn-Srv
Cteonnt-Length
X-Cluster-Node
Memory
X-ARC
Nel
X-Servedbyhost
CF-IPCountry
X-NodeID
X-CMS-Context
FSS-Cache
X-StackifyID
FSS-Proxy
X-Sentry-ID
X-Aicache-OS
X-Flog
X-Hello
X-Wa
X-VServer
X-Fastly-Country-Code
X-ABtesting
X-Load-Cache
X-LAGOON
X-WR-MODIFICATION
X-Varnish-Beresp-TTL
CDN
SN
Geoip-Latitude
GeoIp-Country-Code
X-Ratelimit-Remaining
X-GZip
XServer
NGX
X-HTML-Minification-Powered-By
X-Fastly-Backend-Reqs
X-WA
GeoIP-Latitude
GeoIP-Country-Code
CACHE
X-CSRF-TOKEN
TSSecure
X-UPSTREAM-Address
X-CSRF-Token
X-Check-Cacheable
X-Unique-Id
X-MServer
X-Source
Amp-Access-Control-Allow-Source-Origin
Processtime
X-Worker
X-APP
X-Csrf-Token
X-DataStream-Origin-MEX-Latency
A
Cf-Ipcountry
X-DataStream-MidMile-RTT
X-ServedByHost
X-VWS-Id
X-LJ-Flow-ID
X-SplitTest
PageType
X-AWS-Id
X-Varnish-Cache-Hits
X-Oss-Object-Type
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
WP-Super-Cache
X-CDN-Pop-IP
X-CDN-Pop
X-Port
X-Oss-Storage-Class
X-FireWall-Port
HTTPS
X-Edge-Server
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Cache-Miss-From
Cdn-Request-Time
X-Dynatrace
X-Nananana
X-Sedo-Request-Id
X-Generation-Time
Cdn-Host
X-SRV
Cache-Hits
X-VC-Cache
X-GDPR
URI
Odigeo-Trace-Id
X-Backend-TTL
Pics-Label
X-Sucuri-Cache
X-FORWARDED-FOR
X-Skip-Cache
X-ID
DataCenter
X-Owner
X-Cache-Grace
X-B3-Traceid
X-Ms-Lease-Status
X-Ms-Request-Id
X-Ms-Blob-Type
X-Ms-Version
X-IPS-LoggedIn
X-Varnish-Authentication
X-Cache-ASPX
Server-Surrogate-Control
X-VG-WebCache
Server-Cache-Control
X-Fastly-Cache-Hits
X-HS-Status
X-B3-SpanId
ProcessTime
X-BE
X-Swift-Error
X-SN
Dynatrace
X-RCS-Backend
Hostname
X-PJAX-URL
X-Gen-Id
X-Amzn-Remapped-Date
X-Varnish-Url
X-From-Cache
X-Bug-Bounty
X-GZIP
X-Amzn-Remapped-Connection
X-ND-Cache
X-ORIG-AKA-EDGE
X-GoCache-CacheStatus
X-Fe
X-Cache-Ttl
X-NGINX-Cache
X-Ms-Lease-State
X-VarnPar2
Requestid
X-Instart-Isnd
X-PAGE-TYPE
X-Cache-Srv
X-Akamai-SSL-Client-Sid
X-Amz-Meta-S3b-Last-Modified
Serverid
X-LiteSpeed-Cache-Control
X-RAMCache
X-Pf-Uncompressing
X-Varnish-URL
X-Alicdn-Da-Ups-Status
X-Server-W
WebServer
X-Serial
X-VC
X-SB
X-ServerName
T-Server
NodeID
X-ORIG-AKA-COUNTRY-CODE
Get-Access-Time
Is-Session-Tracking
RequestUuid
Lb
X-HTML-Edge-Cache
Proxy-Firewall
X-LiteSpeed-Tag
Xet-Cookie
SID
X-Akamai-ERPolicy
Location
X-CS
X-Developed-By
X-Dw-Trace-Id
X-Akamai-ERRuleID
X-RequestId
NnCoection