Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
Last-Modified
X-Content-Type-Options
Accept-Ranges
Pragma
X-Powered-By
CF-RAY
Link
ETag
Expect-CT
Via
X-XSS-Protection
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Id
X-Served-By
Referrer-Policy
X-Varnish
X-Xss-Protection
X-Timer
X-Request-Id
CF-Cache-Status
X-AspNet-Version
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Runtime
X-Download-Options
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Cacheable
Alt-Svc
X-Check
X-Generator
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Cache-Status
X-AspNetMvc-Version
Status
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Template
X-Language
X-Permitted-Cross-Domain-Policies
Content-Encoding
X-Request-ID
X-Iinfo
X-FRAME-OPTIONS
X-Content-Security-Policy
X-CDN
X-Buckets
X-Turbo-Charged-By
X-Type
Upgrade
WPE-Backend
X-Pass-Why
Keep-Alive
X-Cache-Group
X-AH-Environment
Xkey
X-Backend
Access-Control-Max-Age
P3p
X-Age
Access-Control-Expose-Headers
X-Via
EagleId
X-Drupal-Dynamic-Cache
X-Nginx-Cache-Status
X-Pingback
X-Amz-Request-Id
X-Amz-Id-2
X-Server-Powered-By
X-Server
X-Hacker
X-Swift-SaveTime
X-Swift-CacheTime
Grace
X-UA-Device
Ali-Swift-Global-Savetime
X-Varnish-Cache
X-Robots-Tag
X-Kinja-Server-Push
Cf-Railgun
X-Proxy-Cache
X-Envoy-Upstream-Service-Time
X-LiteSpeed-Cache
X-Page-Speed
Request-Context
X-Device
X-Ac
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
Content-Location
X-Cache-Lookup
X-Amz-Version-Id
X-WebKit-CSP
X-Host
X-Response-Time
Surrogate-Control
X-OneAgent-JS-Injection
X-Rq
X-Cnection
X-Backend-Server
X-Node
X-Server-Id
X-Readtime
Server-Timing
X-Rack-Cache
Report-To
EagleEye-TraceId
X-Application-Context
Request-Id
X-Cloud-Trace-Context
Feature-Policy
X-ORACLE-DMS-ECID
X-CST
X-Instart-Request-ID
X-Iejgwucgyu
X-Ua-Compatible
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Clacks-Overhead
Edge-Control
NEL
Rating
X-Country
X-Url
X-Server-Name
X-Px
Pinterest-Generated-By
Allow
X-Country-Code
X-DataDome
X-Varnish-TTL
X-MS-InvokeApp
X-DynaTrace
X-Origin-Cache
X-TTL
X-Vhost
X-Vname
X-PC
X-TtlSet
X-Cached
X-FTR-Request-ID
X-ESI
RTSS
X-Ruxit-JS-Agent
X-Goog-Hash
Charset
X-VARITI-CCR
X-Powered-CMS
X-Trace
SPRequestGuid
X-Powered-By-Plesk
X-DynaTrace-JS-Agent
Accept-CH
X-GitHub-Request-Id
X-Dispatcher
Public-Key-Pins
X-D2id
X-SharePointHealthScore
X-Mod-Pagespeed
X-Server-ID
X-T
X-Mobile-Rewrite
Arc-Version
PB-PID
PB-RID
X-F-Cache
X-Oracle-Dms-Rid
Content-MD5
X-Exp-Variant
X-Exp-Id
X-Cdn-Fetch
X-Kinja
X-GoogleNews-Bot
X-Kinja-Server
Verso
X-Kinja-Revision
X-Kinja-Build
MS-Author-Via
X-Version
X-B3-TraceId
SPIisLatency
SPRequestDuration
X-Recruiting
X-Shield-Request-Id
X-Abt-Application-Version
Nginx-Cache
X-Dns-Prefetch-Control
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Client-IP
X-Forwarded-Proto
X-HW
Accept-CH-Lifetime
X-DIS-Request-ID
X-Navigation-Version
X-N
AR-CACHE
AR-PoweredBy
AR-ATIME
Pinterest-Version
X-Pinterest-Rid
X-Upstream-Env
X-Amz-Rid
X-B
X-Dw-Request-Base-Id
X-Upstream
X-ORACLE-DMS-RID
X-Origin-Upstream-Status
X-Fastly-Request-ID
DynaTrace
X-XRDS-Location
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Amz-Meta-S3cmd-Attrs
Fastly-Restarts
X-Ser
X-Hits
Paypal-Debug-Id
TCN
X-Wix-Server-Artifact-Id
X-Accel-Buffering
Realpath
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Content-Options
Arr-Disable-Session-Affinity
X-Pad
X-NF-Request-ID
Service-Worker-Allowed
X-Acc-Meta-Resource-Type
X-Goog-Storage-Class
Tracecode
Access-Control-Request-Method
X-Content-Digest
X-Id
S
Front-End-Https
X-Varnish-Age
X-Debug
Mrf-Cache-Status
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
MRF-Tech
X-MSEdge-Ref
X-Amz-Cf-Pop
X-Vcap-Request-Id
X-Oneagent-Js-Injection
X-Frontend
X-IPLB-Instance
X-FTR-Backend-Server
X-FTR-Realm
X-Country-Code-Real
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-Backend
X-FTR-DC
X-PressLabs-Stats
X-ATG-Version
X-FTR-Expires
X-Kinsta-Cache
X-RateLimit-Remaining
X-Middleton-Display
Display
X-Sol
X-Logged-In
X-Cache-Hit
Edge-Cache-Tag
X-HS-Content-Id
X-HS-Hub-Id
Surrogate-Key
X-FastCGI-Cache
X-Forwarded-For
Rt-Fastcgi-Cache
Fastcgi-Cache
X-Use-Magma
Powered-By-ChinaCache
MicrosoftSharePointTeamServices
X-Zen-Fury
X-Request-Processing-Time
X-Request-Received
X-Edge-Location
X-Grace
Backend-Timing
Server-Name
X-Analytics
X-Amzn-Trace-Id
X-Debug-Info
X-Rid
Response
X-Middleton-Response
X-Ttl
X-Revision
Host
FilterID
TP-L2-Cache
X-User-Agent
TP-Cache
X-Akam-SW-Version
X-FTR-Cache-Host
X-Litespeed-Cache
X-CF-Powered-By
X-NewRelic-App-Data
X-Webkit-Csp
X-B3-TraceId-Primal
X-Mobile
X-Cache-Key
X-SS-Set-Cookie
AMP-Access-Control-Allow-Source-Origin
Ar-Sid
X-HS-Cache-Config
X-Drupal-Cache-Tags
X-Accel-Expires
X-Magnolia-Registration
X-TA-CDN-Provider
Cache-Status
Refresh
X-Cached-By
AR-Request-ID
Host-Header
X-Newrelic-App-Data
X-SERVER
X-Fastcgi-Cache
ServerID
X-B3-Sampled
X-Varnish-Backend
X-Node-Name
X-GUploader-UploadID
X-AOL-HN
X-Content-Security-Policy-Report-Only
X-Cluster
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Instance
X-FB-Debug
X-Signature
X-Webkit-CSP
X-Cache-Control
X-B-Cache
X-Akamai-Edgescape
X-Platform-Server
X-Page-Id
X-Framework
X-Device-Type
X-LB-Cache
X-App-Environment
X-Varnish-Hostname
Cache-Tag
X-BCube-Filmed-By
X-Whom
Eomportal-Instance
X-Srv
X-Handled-By
Cleartype
X-Cache-2
X-Cache-Rule
X-Generated-By
X-Request-Guid
DC
Liferay-Portal
X-NWS-LOG-UUID
X-Activity-Id
X-Az
X-AppVersion
X-Ruxit-Js-Agent
X-WPE-Loopback-Upstream-Addr
X-Drupal-Cache-Contexts
X-Cache-Action
X-Geo-Segment
Public-Key-Pins-Report-Only
X-App-Server
X-VCache
X-Cache-Server
X-Content-Powered-By
X-Via-JSL
Source
Retry-After
X-Correlation-Id
MS-CV
Accept-Charset
Alternate-Protocol
X-Wix-Request-Id
X-TT
X-Seen-By
X-Amz-Replication-Status
X-HS-Combine-CSS
ViewerVersion
X-App-Version
X-Hostname
X-Varnish-Grace
X-Varnish-Server
X-Geo-Country
X-WA-Info
AR-SID
Webserver
Server-Node
X-Esi
HostName
Upgrade-Insecure-Requests
X-Cache-NE
X-Response-Served-From
X-WebKit-CSP-Report-Only
X-Tumblr-Pixel-2
AsisCache
X-Tumblr-Pixel-1
X-Locale
X-Amz-Apigw-Id
SRV
X-GeoIP
X-Amzn-RequestId
Actual-Object-TTL
X-RequestSource
GEO-INFO
X-URL
X-Daa-Tunnel
X-Varnish-Hits
ServedBy
X-Jobs
X-Yottaa-Optimizations
X-UUID
Payment
X-Yottaa-Metrics
Viewport
X-Servedby
X-FW-Server
X-FW-Static
X-FW-Hash
X-Edge-Cache-Key
X-Contextid
X-Edge-Cache
X-FW-Type
X-FW-Serve
X-S
X-Status
X-TX-ID
Pagespeed
X-Varnish-IP
X-Adobe-Loc
Cache
X-Adobe-Content
X-Cache-TTL-Remaining
X-TT-TIMESTAMP
X-Origin-Server
X-Vg-Webcache
X-Cacheable-TTL
X-Forwarded-Host
X-Correlation-ID
X-Cache-Age
X-Cache-Operation
S-Cnection
X-Hyper-Cache
Datacenter
X-Amz-Server-Side-Encryption
X-RateLimit-Limit
Server-Info
Served-By
X-Region
X-Sucuri-ID
X-XRDS-LOCATION
X-Akamai-Request-ID2
Country
CACHE
X-TIME
X-Mode
X-Real-IP
Access-Control-Allow-Method
From-Origin
X-CLOUD-TRACE-CONTEXT
Healthy
X-Microcachable
X-Path-Route
X-L-Path
X-Ocache
X-JoinUs
X-Cache-Config
X-Generated
X-Detected-As
X-Environment-Context
X-Is-Bot
X-Cache-Var
X-Cache-Var-Map
X-Proxy
X-Ezoic-Cdn
X-Site-Version
Machine
Meta-Geo
Fastcgi-X-Cache-Version
X-Upgrade-Enabled
X-Content-Type
X-DataStream-Cache-Status
X-Zipkin-Id
Fastcgi-X-Cache
X-Proxied
X-Rule
X-Rendered-As
X-RN-RSRV
X-Routing-Service
X-CDN-Cache
Fastcgi-Useragent
X-Akamai-Transformed
X-Access
X-Agile
L5d-Success-Class
Now
X-Amz-Meta-Surrogate-Control
X-Agile-Id
X-Birta-Served
X-Birta-Cache-Post
X-Agile-Age
X-Hosted-By
X-Viewer-Country
X-EIG-Tracking-Id
X-Format
X-NGENIX-Cache
X-Section
X-Request-Time
Property-Id
TWC-Device-Class
TWC-Connection-Speed
X-ServerID
OT-Force-Account-Verify
X-Via-Fastly
Cache-Name
X-Human
X-Labrador-Cache-Channel
S-Rt
DB-Nickname
X-TNCMS
TWC-GeoIP-Country
X-Tb
TWC-GeoIP-LatLong
X-Loop
X-OCL
X-Origin-Hint
X-Hit
X-Cache-Category-Id
X-FC-Vary-Parameters
X-Grey
X-Pc-Appver
X-Pc-Hit
TWC-Privacy
TWC-Locale-Group
Webcakes-App-Name
Webcakes-App-Version
X-Pc-Key
Webcakes-Region
X-PCL
X-CCM
X-Cluster-Node
X-IP
Accept-Language
X-SplitTest
HitType
X-AWS-Id
X-LJ-Flow-ID
X-RemovedCookies
X-ProcessESI
X-OVcl-Cache
X-Original-Request
X-Origin
X-Pubstack
X-OVcl
HitInfo
X-VWS-Id
X-VG-TLSProxy
X-Web-Node
X-Xfnlog-Site
X-Via-CDN
Azure-InstanceId
Azure-RegionName
Azure-Version
X-Upstream-HT
X-Upstream-CT
Azure-SlotName
Azure-SiteName
X-BYPASS-REASON
X-Alternate-Cache-Key
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Timing-Wait
X-Www-Served-By
X-Shopify-Stage
X-ShopId
X-ProxyCache-Status
X-ShardId
X-ProxyCache-Key
X-Proxy-Build
Mn-Server-Ip
Selected-FE
LB
PageSpeed
Xserver
Cache-Hits
X-Rocket-Nginx-Bypass
Content-Style-Type
X-App-Name
Origin-Cache-Control
Content-Script-Type
Origin-Edge-Control
X-Cdn
X-Source
X-Cache-Enabled
X-Guploader-Uploadid
X-Transaction
X-UA
X-Connection-Hash
X-TWH-CORRELATION-ID
X-RTag
X-Twitter-Response-Tags
IBM-Web2-Location
Access-Control-Request-Headers
X-Unique-ID
X-GRACE
Ms-Operation-Id
X-Ms-Request-Id
X-NodeID
X-Ms-Lease-Status
NGB
X-Real-Ip
X-Ms-Version
X-Ms-Blob-Type
Time
X-Cache-Remote
X-Geo
X-Origin-CC
X-Port
NtCoent-Length
Filters
X-Nginx-Cache
X-MP-GENERATED-AT
X-NCache
X-Pc-Host
X-Distil-CS
X-Pc-Date
X-Internal-Host
X-Cdn-Forward
X-Edge-IP
X-Tumblr-Pixel-3
Mail-Subject
Backend
X-APP-VERSION
We-Hiring
X-Varnish-Cacheable
X-Cache-TTL
X-Debug-Cache
X-Proto
X-CACHE-KEY
X-Storage
X-Vgn-Hpd-Reason
X-Time-Microsecs
X-UA-Device-Type
X-Webstats-RespID
Cache-Tags
X-Ratelimit-Limit
X-PHP-Backend
X-Backend-Name
X-Varnish-Cache-Hits
X-Varnish-Beresp-Grace
User-Agent
X-CACHE-GROUP
X-Sucuri-Cache
X-Varnish-Beresp-Status
X-Akamai-Request-ID
X-Urbn-Site-Id
Locale
X-EdgeConnect-Cache-Status
X-Dc
X-Urbn-Context-Path
X-Ua
X-Mrs-Age
X-PERF
X-ApacheServer
X-Mrs-Cache-Hits
X-Mrs-Cache
X-Mshield-Cache-Status
X-Csrf-Token
Fastly-SSL
X-ElasticPress-Search
Warning
X-Newrelic-Synthetics
X-B3-Spanid
X-C
X-Varnish-Beresp-Ttl
X-A
X-A-Ccd
X-A-Dcw
X-A-Dgt
TSSecure
VivaBuild
X-A-Dam
X-ScT
Viewtype
V-Age
X-Cdn-Origin
X-GeoIP-Country-Code
UCS
X-Hash
X-Cache-Host
X-Generated-In
Rt-Proxy-Cache
HA-Geocity
HA-Cloudapp
HA-Geocountry
HA-Geolat
HA-Geolon
GMS-Ver
FSS-Proxy
Ec-Rule-Version
Fly-Cache
Fly-Request-Id
FSS-Cache
HA-Georegion
Ha-Gx-Prefs
Odigeo-Trace-Id
Mobile-Detection-Method
Rendered-Blocks
Resin-Trace
Server-Host
Meta-Geo-Continent
MD5-Digest
HA-Host
HA-Ipaddr
HA-Servedtime
HA-Urlpath
SN
X-CF-Lambda-Fn
X-Via-SSL
X-Via-Edge
X-IN-SSL-APIGATEWAY
X-NX-Host
X-Org
X-Died
X-Developer
X-Destination
X-Date
X-BB-ID
X-G
X-CF-Lambda-Version
X-Backend-Host
Content-Disposition
X-Backend-Url
X-PAYTM-SRV-ID
X-Fetched-On
X-Region-Sid
X-CGP
Xc-Version
X-D
X-Eu-Site
X-External-Request-Id
X-Debug-Log
X-BBXSRF
X-From
X-Irp-Debug
X-S-Cookie
X-F5-Cache
X-Application
X-Rojux
X-Amz-Meta-Cache-Control
X-Aed
X-A-Wwc
X-Accel-Expires-Debug
X-Server-By
X-Server-Time
X-Sn-Servicetimems
X-Logtrace-Id
X-UE-Client-Country
X-Debug-Cookies
X-VG-WebServer
X-NU-AKA-ACS-Version
X-IN-APIGATEWAY
X-Trv-Group
X-Store
X-IN-WAF
X-Rewrite-Enabled
X-SRCache-Key
X-B-Cookie
X-Cache-Bucket
Cache-Key
X-Endurance-Cache-Level
BehaviorPad-Version
X-Nc
Cache-Prefix
Arc-Country
X-Redis-Cache
Ajk
X-Cache-Backend
X-CACHE-AGE
Thinkindot-Control
X-CDN-Forward
Www
Thinkindot-CacheControl-Type
X-Owner
X-Platform
X-Response-By
X-Request-Start
Release
Pramga
X-S-Maxage
X-Reboot
X-Rebelmouse-Surrogate-Control
X-No-Session
X-Qloud-Router
Server-ID
X-Rebelmouse-Cache-Control
Thinkindot-CacheControl
X-Matched-Rule
X-Cache-URL
X-Epic-Correlation-Id
X-Cache-Id
X-Flog
X-DPWN-IS-SECURE
X-Dispatcher-Server
X-Core-Value
X-Clientip
X-Developers
X-FW-Version
X-NC
X-Key
X-Layer
X-Location
Origin
X-Auto-Login
X-Backend-State
X-GeoIP-City
X-Hello
X-Hl-Ver
X-ABtesting
X-Release
X-Wikidot-Backend
X-User
Heartbleed
Fastly-SWR
Fastly-Soc-X-Request-Id
X-Trace-Id
X-UnsetCookies
Fastly-SIE
X-V
X-Var-Ttl
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
GW-Server
Apple-News-Services-Host
X-We-Are-Hiring
Frame-Options
AKAMAI
Apple-News-Services-Handled
X-Thinkindot-L3
IsBot
X-ServiceProvider
Countrycode
Decoy-Debug-Key
X-Dynatrace-Js-Agent
Decoy-Debug-Status
Decoy-Debug-TTL
X-Server-IP
Powered-By
Memcached
Country-Code
X-SIPLIST1
X-Worker
X-Wikidot-Static-Cache
X-Powered-By-ANYU
User-Cache-Control
WZWS-RAY
X-Info
X-VCT
X-VServer
X-Hnp-Log
X-Distributor
X-Fastly-Cache
X-Varnish-Action
X-Gannett-Site-Version
X-Gen-Mode
X-CUA
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Croise-Owner
X-Nginx-Cache-Key
X-Crawler
X-Request-URI
X-Stale
X-Swa-Ws
X-RCS-CacheZone
X-Thanos
X-Request-UUID
X-Returned-From
X-Returned-From-PostProcessResponse
X-Secret
X-Sf
X-Returned-From-DLL
X-Returned-From-BeforeDispatch
X-Policy
X-Up
X-MI-In-Market
X-Sentry-ID
X-LI-UUID
X-Li-Pop
X-Variation
X-Li-Fabric
X-Node-Id
X-P-T
X-Passed-To-PostProcessResponse
X-Phone
X-Passed-To-DLL
X-Passed-To-BeforeDispatch
X-Passed-To
X-Instance-Name
X-LI-Proto
Web-Mar-Node
Kp-EeAlive
Cache-Cookie-Set-Lfrom
X-Origin-Response-Time
Cache-Cookie-Set-Idcheck
Uber-Trace-Id
Fastly-Backend-Name
Esi-Enabled
X-Bip
X-Block-Status
Magicmarker
MI-Cache
MI-Cache-Age
True-Client-Country-4JS
Cache-Cookie-Set-From
Pragrma
Request-Country
Platform
On-Server
Backend-Name
Request-EU
RNT-Machine
Adler-Geo
X-Core-Mission
Server-Int
Section-Io-Cache
RNT-Time
X-Cache-Debug
X-Actual-URL
X-Cache-Expires
Is-Eu
X-Datadome
X-SVT-ORM-VERSION
X-Via-NSCOPI
X-WebServer
X-Cache-CFC
Pagetype
X-MSEdge-Flight
CDCHOST
X-MServer
X-SN
X-MSEdge-Features
X-TT-LOGID
Proxy-Connection
X-SVT-ORM-RULES
X-Fstrz
X-Served-From
X-Device-Os
REQUESTUUID
X-Backend-TTL
Version
X-Cache-Srv
X-Oss-Storage-Class
X-NODE
X-Oss-Request-Id
RequestId
X-Oss-Server-Time
X-Refresh
X-NWS-UUID-VERIFY
X-DC
HTTPS
MI-API
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-HOST
Amp-Access-Control-Allow-Source-Origin
X-Page-Type
X-Ms-Lease-State
X-Req
X-Be
X-Kong-Proxy-Latency
X-Cache-FS-Status
NodeID
Cteonnt-Length
X-Pjax-Url
X-Kong-Upstream-Latency
MIME-Version
X-Unique-Id-Primal
X-Servername
Group
V-Cache
X-Parent-Response-Time
ProcessTime
Who
X-GZip
X-Origin-TTL
X-Oracle-Dms-Ecid
X-BB-IP
Fusion-Source
Cdn
Fusion-Content-Source
Fusion-Content-Id
Fusion-Template-Id
Memory
Fusion-Component-Id
X-Ckpd-Fst-Backend
Mime-Version
X-Aicache-OS
CF-IPCountry
X-Servedbyhost
SS
X-ND-Cache
Cdn-Host
Cdn-Request-Time
X-Edge-Server
X-Protected-By
X-Time
X-Content-Age
X-Server-Group
X-COUNTRY
SD-X-WS
X-Wa
PageType
GeoIP-Country-Code
XServer
CDN
GeoIP-Latitude
X-Varnish-Url
X-SRV
X-Varnish-Beresp-TTL
X-Ratelimit-Remaining
X-APP
Is-Session-Tracking
Get-Access-Time
A
X-Origin-Expires
X-Generation-Time
X-Origin-Date
GeoIp-Country-Code
X-RateLimit-Remaining-Second
X-WA
X-B3-Traceid
X-Pf-Uncompressing
X-RateLimit-Limit-Second
Geoip-Latitude
X-CSRF-Token
X-FireWall-Port
Serverid
X-StackifyID
X-Fastly-Cache-Hits
PICS-Label
X-Cache-Info
X-Unique-Id
X-Vcache
X-Origin-Host
X-GEO
X-Requestid
X-Fastly-Country-Code
X-Gdpr
X-Nananana
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-EC-Security-Audit
X-CS
Processtime
Nel
X-ID
Node
X-Load-Cache
Cf-Ipcountry
X-PHP-Host
Hostname
X-Proxy-Cache-Status
X-RequestId
X-Proxy-Upstream
X-Server-W
X-ServedByHost
T-Server
NGX
X-SERVER-NAME
DataCenter
X-Surge-Debug
X-Check-Cacheable
X-Qnm-Cache
X-M-Reqid
X-M-Log
X-HTML-Minification-Powered-By
Vix-Hermes-Req-Id
URI
X-FORWARDED-FOR
Load-Balancing
X-Feature
X-UPSTREAM-Address
X-PF-Uncompressing
X-NGINX-Cache
Cache-Tv-Group
X-GZIP
X-HS-Status
WP-Super-Cache
ServerName
Cache-Provider
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-B3-SpanId
X-WR-MODIFICATION
X-BACKEND-TTL
X-ServerName
X-VG-WebCache
X-Fastly-Backend-Reqs
X-DataStream-MidMile-RTT
Request-Time
X-Alicdn-Da-Ups-Status
X-DataStream-Origin-MEX-Latency
X-ARC
X-Skip-Cache
X-Fe
X-BE
X-Atg-Version
X-Proxy-Server
PFcat
Https
X-PAGE-TYPE
Host-ID
X-Micro-Cache
X-PJAX-URL
X-HTML-Edge-Cache
Requestid
X-IPS-LoggedIn
RequestUuid
X-Akamai-SSL-Client-Sid
X-VC
X-SB
N-Cache
X-Debug-Cache-Expiry
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-From-Cache
X-Distil-Cs
X-Amz-Meta-S3b-Last-Modified
X-Cache-Ttl
X-GDPR
Sid
X-Swift-Error
Cdn-Src-Port
X-Gen-Id
X-Grace-Duration
X-RAMCache
X-Dw-Trace-Id
Build-Number
X-CSRF-TOKEN