Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Accept-Ranges
Pragma
X-Powered-By
Link
ETag
CF-RAY
Expect-CT
Via
X-Cache
X-XSS-Protection
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Id
X-Xss-Protection
X-Served-By
P3P
Referrer-Policy
X-Varnish
X-Timer
CF-Cache-Status
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-AspNet-Version
X-Download-Options
X-Runtime
Access-Control-Allow-Credentials
P3p
X-Drupal-Cache
X-Check
X-Adblock-Key
Alt-Svc
X-Cacheable
X-Amz-Cf-Pop
X-Generator
CF-Ray
Content-Security-Policy-Report-Only
X-Cache-Status
X-AspNetMvc-Version
X-DNS-Prefetch-Control
Status
X-Request-ID
X-Template
X-Language
Timing-Allow-Origin
Content-Encoding
X-Permitted-Cross-Domain-Policies
X-Iinfo
X-Buckets
X-Content-Security-Policy
X-Turbo-Charged-By
Upgrade
X-Kinja-Server-Push
X-CDN
X-Type
Xkey
Keep-Alive
Access-Control-Expose-Headers
Access-Control-Max-Age
WPE-Backend
X-Pass-Why
X-AH-Environment
X-Backend
X-Cache-Group
X-Server
X-Age
X-Drupal-Dynamic-Cache
X-Pingback
X-Via
X-Nginx-Cache-Status
X-Amz-Request-Id
X-Amz-Id-2
Grace
X-Server-Powered-By
X-Hacker
EagleId
X-UA-Device
X-Robots-Tag
X-LiteSpeed-Cache
X-Varnish-Cache
X-Page-Speed
X-Swift-SaveTime
X-Swift-CacheTime
X-Proxy-Cache
Cf-Railgun
X-Envoy-Upstream-Service-Time
Request-Context
Ali-Swift-Global-Savetime
X-Ua-Compatible
X-Ac
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
X-WebKit-CSP
X-Cache-Lookup
Content-Location
X-Server-Id
X-Amz-Version-Id
Surrogate-Control
X-Host
X-Cnection
X-Node
Report-To
X-Readtime
X-OneAgent-JS-Injection
EagleEye-TraceId
X-Rq
Server-Timing
X-Response-Time
Feature-Policy
X-CST
X-Rack-Cache
X-Application-Context
X-Backend-Server
X-ORACLE-DMS-ECID
X-Iejgwucgyu
Request-Id
X-Cloud-Trace-Context
X-Instart-Request-ID
X-Clacks-Overhead
X-Url
NEL
Edge-Control
X-DynaTrace
Rating
Allow
X-EdgeConnect-MidMile-RTT
X-Country
X-EdgeConnect-Origin-MEX-Latency
X-Varnish-TTL
X-Origin-Cache
X-FTR-Request-ID
X-Country-Code
X-Trace
X-DataDome
X-Server-Name
X-Px
X-Vhost
X-B3-TraceId
X-GitHub-Request-Id
X-ORACLE-DMS-RID
X-VARITI-CCR
RTSS
X-MS-InvokeApp
X-Cached
X-Ruxit-JS-Agent
X-ESI
Accept-CH
X-Goog-Hash
Charset
SPRequestGuid
X-Server-ID
X-TtlSet
X-PC
X-Vname
Pinterest-Generated-By
X-Mod-Pagespeed
Public-Key-Pins
Verso
X-F-Cache
X-D2id
X-Kinja-Build
X-Exp-Variant
X-Kinja
X-Exp-Id
X-Use-Magma
X-Kinja-Revision
X-Kinja-Server
X-GoogleNews-Bot
X-Cdn-Fetch
X-Dispatcher
PB-RID
X-Mobile-Rewrite
Arc-Version
PB-PID
X-Version
X-SharePointHealthScore
X-Cdn
X-T
X-Powered-By-Plesk
X-TTL
Accept-CH-Lifetime
X-Abt-Application-Version
X-DIS-Request-ID
X-Powered-CMS
X-DynaTrace-JS-Agent
X-Ser
X-Fastly-Request-ID
Pinterest-Version
X-Pinterest-Rid
X-Upstream-Env
X-Origin-Upstream-Status
X-Navigation-Version
X-Shield-Request-Id
X-B
X-Forwarded-Proto
X-Client-IP
X-Recruiting
X-Amz-Rid
X-SRCache-Store-Status
DynaTrace
MS-Author-Via
X-SRCache-Fetch-Status
X-Ttl
X-HW
SPRequestDuration
SPIisLatency
Realpath
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Upstream
X-Vcap-Request-Id
Content-MD5
Nginx-Cache
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Wix-Server-Artifact-Id
X-Accel-Buffering
X-Amz-Meta-S3cmd-Attrs
AR-PoweredBy
AR-CACHE
AR-ATIME
Edge-Cache-Tag
X-Oneagent-Js-Injection
Arr-Disable-Session-Affinity
X-Hits
X-N
X-Varnish-Age
X-Debug
X-Oracle-Dms-Rid
TCN
X-Goog-Storage-Class
X-Aspnet-Version
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
X-NF-Request-ID
X-MSEdge-Ref
Access-Control-Request-Method
X-Acc-Meta-Resource-Type
X-Dw-Request-Base-Id
X-Id
S
X-ATG-Version
X-XRDS-Location
X-Via-JSL
X-FTR-Realm
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Backend
X-FTR-DC
X-FTR-Balancer
X-FTR-Backend-Server
Service-Worker-Allowed
X-NewRelic-App-Data
X-FTR-Expires
X-Logged-In
X-Dns-Prefetch-Control
Alternate-Protocol
X-FastCGI-Cache
X-Forwarded-For
Tracecode
Rt-Fastcgi-Cache
X-HS-Hub-Id
X-HS-Content-Id
X-Frontend
X-PressLabs-Stats
Surrogate-Key
X-Content-Digest
X-Kinsta-Cache
X-Cache-Key
AMP-Access-Control-Allow-Source-Origin
X-Pad
Fastly-Restarts
MicrosoftSharePointTeamServices
X-RateLimit-Remaining
X-FTR-Cache-Host
X-Grace
X-Content-Options
X-Ruxit-Js-Agent
Server-Name
X-Edge-Location
X-Amzn-Trace-Id
X-CF-Powered-By
Backend-Timing
X-Analytics
FilterID
Host
TP-Cache
TP-L2-Cache
X-Rid
X-Whom
X-User-Agent
X-Hostname
Fastcgi-Cache
X-Debug-Info
X-Magnolia-Registration
X-IPLB-Instance
X-Cache-2
ServerID
X-Revision
Ar-Sid
X-B3-Sampled
Eomportal-Instance
X-Page-Id
X-Request-Received
X-Request-Processing-Time
Paypal-Debug-Id
X-Mobile
X-Srv
X-NWS-LOG-UUID
AR-Request-ID
X-Akam-SW-Version
Front-End-Https
X-AOL-HN
X-VCache
X-HS-Cache-Config
Retry-After
X-Content-Powered-By
X-B-Cache
X-Signature
X-GUploader-UploadID
X-Litespeed-Cache
X-Cluster
X-FB-Debug
X-SS-Set-Cookie
X-LB-Cache
X-Handled-By
X-Cache-Action
Source
X-Varnish-Grace
X-Instance
X-Cache-Hit
X-App-Environment
X-WA-Info
X-Request-Guid
X-Cache-Control
X-Device-Type
Refresh
X-Framework
X-Tumblr-Pixel
X-BCube-Filmed-By
X-Varnish-Hostname
X-Tumblr-Pixel-0
X-Platform-Server
X-Tumblr-User
X-Akamai-Edgescape
Cleartype
X-Content-Security-Policy-Report-Only
Webserver
X-Correlation-Id
X-Zen-Fury
Display
X-Middleton-Display
X-Varnish-Backend
X-Sol
X-XRDS-LOCATION
X-AppVersion
X-Esi
X-Activity-Id
X-Az
X-Daa-Tunnel
X-Content-Type
X-Fastcgi-Cache
VIX-Pulpo-Node
X-Cache-Server
VIX-Pulpo-Upstream-Status
Healthy
X-Cache-Rule
X-Varnish-Server
X-Wix-Request-Id
X-Drupal-Cache-Contexts
X-Drupal-Cache-Tags
X-Seen-By
ViewerVersion
Response
X-Middleton-Response
X-URL
X-Generated-By
X-Geo-Country
X-Cached-By
S-Cnection
X-App-Server
Cache-Status
Server-Node
X-TT
X-Origin-Server
X-Amz-Replication-Status
X-CACHE-GROUP
X-Accel-Expires
Upgrade-Insecure-Requests
X-DataStream-Cache-Status
X-Cache-Age
X-Amz-Apigw-Id
X-Amzn-RequestId
Payment
X-RequestSource
NGB
GEO-INFO
X-TA-CDN-Provider
X-Response-Served-From
Filters
X-UA-Device-Type
X-S
X-Varnish-IP
Actual-Object-TTL
ServedBy
X-Cache-NE
X-Edge-Cache-Key
X-Edge-Cache
X-Cacheable-TTL
X-Status
Accept-Charset
X-FW-Server
X-FW-Static
X-FW-Type
X-Locale
X-FW-Serve
X-Contextid
Access-Control-Allow-Method
X-FW-Hash
X-Jobs
X-Tumblr-Pixel-2
X-Node-Name
X-Servedby
X-TT-TIMESTAMP
X-Tumblr-Pixel-1
X-Varnish-Hits
X-WPE-Loopback-Upstream-Addr
X-TX-ID
X-GeoIP
X-Amz-Server-Side-Encryption
X-UUID
AsisCache
X-Adobe-Content
X-WebKit-CSP-Report-Only
Server-Info
HostName
X-Adobe-Loc
Host-Header
Viewport
X-Storage
Cache
X-APP-VERSION
X-PHP-Backend
X-Cache-TTL-Remaining
SRV
X-Cache-Remote
Cache-Tv-Group
X-Rendered-As
MS-CV
X-Vg-Webcache
From-Origin
X-Croise-Owner
X-Hyper-Cache
X-Region
X-Cache-Operation
X-Webkit-CSP
X-HS-Combine-CSS
Cache-Tag
Served-By
X-Redis-Cache
Liferay-Portal
DC
Public-Key-Pins-Report-Only
X-App-Version
X-Forwarded-Host
X-Mode
X-Timing-Wait
X-Yottaa-Optimizations
Xserver
X-Yottaa-Metrics
X-TNCMS
X-Upgrade-Enabled
X-RN-RSRV
X-Path-Route
X-Agile-Id
X-Cache-Var
X-Human
X-Hosted-By
X-Agile-Age
X-Cache-Var-Map
X-Is-Bot
Machine
X-IP
X-Detected-As
Meta-Geo
X-Loop
X-NGENIX-Cache
X-Proxy-Build
Selected-FE
X-Webstats-RespID
X-Generated
Fastcgi-Useragent
X-Endurance-Cache-Level
X-Agile
X-Akamai-Transformed
X-Request-Time
Fastcgi-X-Cache
Fastcgi-X-Cache-Version
Origin-Cache-Control
Property-Id
Origin-Edge-Control
TWC-Device-Class
TWC-Connection-Speed
Now
X-ProxyCache-Status
X-L-Path
X-JoinUs
X-Labrador-Cache-Channel
X-NCache
X-Origin-Hint
X-BYPASS-REASON
X-Cache-Category-Id
X-Grey
X-Format
X-Environment-Context
X-Internal-Host
X-CDN-Cache
X-Original-Request
Webcakes-Region
X-Via-Fastly
X-Web-Node
X-Vgn-Hpd-Reason
X-Upstream-HT
X-Upstream-CT
TWC-Locale-Group
TWC-Privacy
Webcakes-App-Version
Webcakes-App-Name
Cache-Name
X-ProxyCache-Key
TWC-GeoIP-Country
TWC-GeoIP-LatLong
Powered-By-ChinaCache
X-B3-Spanid
X-UA
DB-Nickname
Cache-Tags
S-Rt
X-FC-Vary-Parameters
X-Section
X-Tumblr-Pixel-3
X-Access
X-Viewer-Country
X-Time-Microsecs
X-Pubstack
X-VG-TLSProxy
X-Pc-Appver
X-Origin-Host
X-Pc-Hit
X-Pc-Key
X-Proxy
X-PCL
X-OCL
X-Akamai-Request-ID
X-Origin
X-Origin-Response-Time
X-Newrelic-App-Data
X-RemovedCookies
X-ProcessESI
X-ServerID
X-Birta-Cache-Post
Datacenter
X-Birta-Served
X-Tb
X-Ocache
X-Site-Version
X-CCM
X-Cache-Config
X-Rule
X-Backend-Name
X-Xfnlog-Site
Azure-SiteName
Azure-RegionName
Azure-InstanceId
Azure-Version
Azure-SlotName
Mn-Server-Ip
HitType
X-Zipkin-Id
X-Akamai-Request-ID2
X-Proxied
X-Via-CDN
X-Origin-CC
X-Guploader-Uploadid
X-Routing-Service
Pagespeed
X-TIME
X-CLOUD-TRACE-CONTEXT
X-Cache-TTL
OT-Force-Account-Verify
X-App-Name
Cache-Key
X-Parent-Response-Time
X-Www-Served-By
X-Shopify-Stage
X-ShopId
X-ShardId
X-BACKEND-TTL
X-Alternate-Cache-Key
X-Nginx-Cache
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
User-Cache-Control
X-Protected-By
X-Dynatrace-Js-Agent
X-Kong-Proxy-Latency
X-Edge-IP
X-CACHE-KEY
Content-Style-Type
Content-Script-Type
X-Kong-Upstream-Latency
AR-SID
Vix-Hermes-Req-Id
X-RateLimit-Limit
X-Ezoic-Cdn
X-OVcl
X-Correlation-ID
X-OVcl-Cache
Accept-Language
L5d-Success-Class
NtCoent-Length
Time
X-RTag
Ms-Operation-Id
X-Real-IP
X-Pc-Date
X-ApacheServer
X-PERF
X-Pc-Host
X-Cache-Backend
X-Real-Ip
LB
X-Webkit-Csp
X-Amz-Meta-Surrogate-Control
X-Cdn-Forward
X-Front
X-Proto
X-FB-TRIP-ID
X-Mrs-Cache-Hits
X-Mshield-Cache-Status
X-Mrs-Age
X-Unique-Id-Primal
X-Mrs-Cache
Section-Io-Cache
X-Content-Age
X-Hit
X-Varnish-Cacheable
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-Debug-Cache
X-CDN-Forward
Country
X-Sucuri-ID
X-Nc
Load-Balancing
WZWS-RAY
X-Unique-ID
X-Ratelimit-Limit
Fusion-Component-Id
Fusion-Template-Id
Fusion-Content-Id
Fusion-Content-Source
Fusion-Source
X-GRACE
Ohc-File-Size
X-Microcachable
X-C
X-MP-GENERATED-AT
X-Time
X-Hl-Ver
We-Hiring
Access-Control-Request-Headers
X-Varnish-Beresp-Ttl
Mail-Subject
X-EdgeConnect-Cache-Status
X-Twitter-Response-Tags
X-Connection-Hash
Warning
Version
X-Trace-Id
X-Cache-Enabled
X-Transaction
X-Clientip
X-Crawler
X-Cache-Host
X-CUA
X-Cache-Expires
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-Cache-Id
X-Cache-FS-Status
X-Cache-URL
X-Backend-State
RNT-Time
RNT-Machine
Resin-Trace
Rt-Proxy-Cache
SD-X-WS
SS
Server-ID
Server-Host
Rendered-Blocks
Release
Memcached
MD5-Digest
Is-Eu
Meta-Geo-Continent
Mobile-Detection-Method
Powered-By
Platform
Node
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-Aed
X-Actual-URL
X-Accel-Expires-Debug
X-Application
X-Auto-Login
X-Cache-Bucket
X-BB-ID
X-B-Cookie
X-A-Wwc
X-A-Dgt
Viewtype
V-Age
Thinkindot-Control
Www
X-A
X-A-Dcw
X-A-Dam
X-A-Ccd
X-Cache-Debug
X-Org
X-Returned-From-PostProcessResponse
X-Returned-From-DLL
X-Returned-From-BeforeDispatch
X-Rewrite-Enabled
X-Rojux
X-S-Maxage
X-S-Cookie
X-Returned-From
X-Response-By
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Reboot
X-Region-Sid
X-Request-UUID
X-Release
X-ScT
X-Server-By
X-Via-Edge
X-VG-WebServer
X-Variation
X-Via-SSL
X-We-Are-Hiring
Xc-Version
X-WebServer
X-Var-Ttl
X-UE-Client-Country
X-SRCache-Key
X-Server-Time
X-Store
X-Swa-Ws
X-Trv-Group
X-Thinkindot-L3
X-RCS-CacheZone
X-Qloud-Router
X-From
X-Fetched-On
X-F5-Cache
X-FW-Version
X-G
X-GeoIP-Country-Code
X-Generated-In
X-External-Request-Id
X-DPWN-IS-SECURE
X-Destination
X-Date
X-Developer
X-Device-Os
X-Dispatcher-Server
X-Died
X-Layer
X-Li-Fabric
X-Passed-To-BeforeDispatch
X-Passed-To
X-Passed-To-DLL
X-Passed-To-PostProcessResponse
X-PHP-Host
X-PAYTM-SRV-ID
IBM-Web2-Location
X-NU-AKA-ACS-Version
X-LI-Proto
X-Li-Pop
X-LI-UUID
X-Logtrace-Id
X-Node-Id
X-Matched-Rule
X-D
VivaBuild
Ec-Rule-Version
Fly-Cache
Ajk
Fastly-SWR
Fastly-Backend-Name
X-Ua
Adler-Geo
Fastly-SIE
Fly-Request-Id
Frame-Options
Countrycode
BehaviorPad-Version
Cache-Prefix
Arc-Country
X-Dc
X-Epic-Correlation-Id
User-Agent
X-Gannett-Site-Version
X-Eu-Site
X-CGP
X-Block-Status
Apple-News-Services-Request-Url
Backend
Backend-Name
X-Amz-Meta-Cache-Control
Apple-News-Services-Parsed-Url
X-Bip
Apple-News-Services-Handled
Apple-News-Services-Host
X-Gen-Mode
X-IN-APIGATEWAY
X-Thanos
X-UnsetCookies
X-Stale
X-Sf
X-ServiceProvider
X-User
X-Varnish-Action
X-P-T
X-TT-LOGID
X-Goog-Meta-Goog-Reserved-File-Mtime
Request-Time
X-Via-NSCOPI
X-Server-IP
X-Server-Group
X-Info
X-Key
X-IN-WAF
X-IN-SSL-APIGATEWAY
X-Hnp-Log
X-MI-In-Market
X-Proxy-Cache-Status
X-Secret
X-Served-From
X-Rocket-Nginx-Bypass
HA-Host
X-Proxy-Upstream
X-Hash
X-Location
HA-Geolon
MI-Cache
MI-Cache-Age
Kp-EeAlive
Esi-Enabled
HA-Urlpath
True-Client-Country-4JS
Heartbleed
HA-Geocity
On-Server
HA-Cloudapp
Ha-Gx-Prefs
Proxy-Connection
HA-Georegion
Origin
MI-API
GW-Server
Web-Mar-Node
Decoy-Debug-Key
Pragrma
Pramga
Content-Disposition
Country-Code
Decoy-Debug-Status
Decoy-Debug-TTL
GMS-Ver
HA-Geocountry
HA-Servedtime
HA-Ipaddr
HA-Geolat
X-NODE
X-Geo
X-Planisys-CDN-Cache
X-Page-Type
X-No-Session
X-Irp-Debug
X-Instance-Name
CDCHOST
X-Planisys-CDN-TTL
X-Request-Start
X-Policy
X-Platform
X-Request-URI
X-V
X-Fstrz
X-MSEdge-Features
X-Distributor
X-Cache-CFC
Server-Int
X-MSEdge-Flight
X-Nginx-Cache-Key
X-Up
PFcat
X-Phone
X-Origin-Expires
X-Origin-Date
Magicmarker
Fastly-SSL
IsBot
X-Urbn-Context-Path
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
Locale
X-Urbn-Site-Id
X-Wikidot-Backend
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-From
X-Wikidot-Static-Cache
X-SIPLIST1
X-Planisys-CDN-Rules
X-Backend-Url
Fastly-Soc-X-Request-Id
X-Core-Value
X-Developers
AKAMAI
X-Backend-Host
Who
UCS
Uber-Trace-Id
Request-EU
X-Distil-CS
Request-Country
X-Be
X-DC
Pagetype
X-ElasticPress-Search
X-Origin-TTL
X-Servername
X-NWS-UUID-VERIFY
X-Debug-Log
X-Refresh
X-Sn-Servicetimems
X-Cdn-Origin
PageSpeed
X-CACHE-AGE
REQUESTUUID
X-Fastly-Cache
X-Debug-Cookies
X-Core-Mission
X-NX-Host
Group
V-Cache
X-NC
X-Micro-Cache
X-GeoIP-City
X-COUNTRY
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-VCT
X-Debug-Cache-Store
HitInfo
X-VarnPar1
X-Req
Host-ID
X-VarnCache
X-Svr
X-PARISIEN-Cache-Rendered
X-Instart-Info
RequestId
X-Newrelic-Synthetics
Lfy
MIME-Version
X-Pjax-Url
X-Generated-On
X-Level-Front-Cache
X-BBXSRF
X-Cache-Info
ServerName
Ohc-Response-Time
X-Cdn-Srv
X-Server-Cache
X-Powered-By-ANYU
X-Datadome
X-ARC
X-B3-Traceid
Cache-Provider
X-EIG-Tracking-Id
X-Gdpr
Mime-Version
PICS-Label
Memory
Cdn
Cteonnt-Length
X-TWH-CORRELATION-ID
X-CMS-Context
X-Servedbyhost
CF-IPCountry
Nel
X-StackifyID
X-Cluster-Node
X-Wa
X-LAGOON
X-WR-MODIFICATION
NGX
CDN
X-Aicache-OS
X-Fastly-Country-Code
X-Load-Cache
X-HTML-Minification-Powered-By
FSS-Proxy
X-NodeID
X-Sentry-ID
GeoIP-Latitude
FSS-Cache
GeoIP-Country-Code
X-Ratelimit-Remaining
X-CSRF-TOKEN
X-Flog
X-Hello
X-VServer
X-ABtesting
XServer
X-Check-Cacheable
Geoip-Latitude
X-Fastly-Backend-Reqs
GeoIp-Country-Code
X-Varnish-Beresp-TTL
X-WA
SN
Cf-Ipcountry
X-GZip
Amp-Access-Control-Allow-Source-Origin
X-UPSTREAM-Address
Processtime
X-Source
X-FireWall-Port
X-APP
X-Csrf-Token
X-CSRF-Token
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Unique-Id
X-Generation-Time
X-HOST
TSSecure
X-Varnish-Cache-Hits
CACHE
X-MServer
WP-Super-Cache
X-Oss-Server-Time
X-Oss-Request-Id
X-Sedo-Request-Id
X-Oss-Object-Type
X-Oss-Storage-Class
X-CDN-Pop-IP
X-ServedByHost
X-CDN-Pop
X-Worker
X-Oss-Hash-Crc64ecma
X-Cache-Miss-From
X-DataStream-MidMile-RTT
X-DataStream-Origin-MEX-Latency
PageType
A
X-Dynatrace
Cdn-Host
X-Edge-Server
URI
X-Cache-Grace
X-Nananana
Cdn-Request-Time
X-SRV
Pics-Label
X-Cache-ASPX
X-VC-Cache
Server-Surrogate-Control
X-Skip-Cache
Server-Cache-Control
X-Varnish-Authentication
X-FORWARDED-FOR
X-GDPR
DataCenter
X-ID
X-AWS-Id
X-SplitTest
X-VWS-Id
X-LJ-Flow-ID
HTTPS
X-Port
X-Fastly-Cache-Hits
X-Sucuri-Cache
X-HS-Status
X-IPS-LoggedIn
X-RCS-Backend
X-BE
X-Backend-TTL
Odigeo-Trace-Id
X-VG-WebCache
X-B3-SpanId
X-Varnish-Url
Cache-Hits
X-Swift-Error
Hostname
X-PJAX-URL
X-Instart-Isnd
X-From-Cache
Dynatrace
X-Owner
X-ND-Cache
Is-Session-Tracking
X-Bug-Bounty
X-Pf-Uncompressing
Get-Access-Time
X-Gen-Id
Requestid
X-Ms-Request-Id
X-GZIP
X-Ms-Version
X-SN
X-Ms-Blob-Type
X-Ms-Lease-Status
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
FastCGI-Cache
X-GoCache-CacheStatus
ProcessTime
X-NGINX-Cache
X-VarnPar2
Proxy-Firewall
X-Cache-Ttl
X-ORIG-AKA-EDGE
X-Server-W
X-Akamai-SSL-Client-Sid
X-Amz-Meta-S3b-Last-Modified
Serverid
X-Ms-Lease-State
RequestUuid
X-SB
X-LiteSpeed-Cache-Control
X-ServerName
X-Varnish-URL
T-Server
X-VC
X-PAGE-TYPE
WebServer
X-ORIG-AKA-COUNTRY-CODE
X-Fe
X-GEO
X-Serial
X-RAMCache
X-Alicdn-Da-Ups-Status
NodeID
Correlation-Id
Powered
Xet-Cookie
X-LiteSpeed-Tag
X-Dw-Trace-Id
X-Akamai-ERRuleID
X-CS
Location
X-Akamai-ERPolicy
NnCoection
X-HTML-Edge-Cache
X-Developed-By
X-Cache-Srv
SID