Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
Last-Modified
X-Content-Type-Options
Accept-Ranges
Pragma
X-Powered-By
CF-RAY
Link
ETag
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Id
X-Served-By
Referrer-Policy
X-Varnish
X-Request-Id
X-Timer
CF-Cache-Status
X-AspNet-Version
Access-Control-Allow-Headers
X-Xss-Protection
Access-Control-Allow-Methods
X-Runtime
X-Download-Options
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Cacheable
Alt-Svc
X-Check
X-Generator
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Cache-Status
X-AspNetMvc-Version
Status
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Template
X-Language
X-Permitted-Cross-Domain-Policies
X-FRAME-OPTIONS
Content-Encoding
X-Iinfo
X-Content-Security-Policy
X-CDN
X-Buckets
X-Turbo-Charged-By
X-Request-ID
Upgrade
X-Type
WPE-Backend
Keep-Alive
X-Pass-Why
X-Cache-Group
X-AH-Environment
CF-Ray
Xkey
P3p
X-Backend
Access-Control-Max-Age
X-Age
Access-Control-Expose-Headers
X-Via
X-Drupal-Dynamic-Cache
EagleId
X-Nginx-Cache-Status
X-Pingback
X-Amz-Id-2
X-Amz-Request-Id
X-Server-Powered-By
X-Server
X-Hacker
Grace
X-UA-Device
X-Swift-SaveTime
X-Swift-CacheTime
X-Kinja-Server-Push
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-Robots-Tag
Cf-Railgun
X-Proxy-Cache
X-Envoy-Upstream-Service-Time
X-LiteSpeed-Cache
X-Ua-Compatible
X-Page-Speed
Request-Context
X-Device
X-Ac
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Content-Location
X-Cache-Lookup
X-Amz-Version-Id
X-WebKit-CSP
X-Response-Time
X-Host
Surrogate-Control
X-Rq
X-OneAgent-JS-Injection
X-Cnection
X-Node
X-Backend-Server
X-Readtime
Server-Timing
X-Rack-Cache
Report-To
X-Server-Id
Request-Id
EagleEye-TraceId
X-Application-Context
Feature-Policy
X-Cloud-Trace-Context
X-ORACLE-DMS-ECID
X-Instart-Request-ID
X-CST
X-Iejgwucgyu
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Clacks-Overhead
Edge-Control
NEL
Rating
X-Country
X-Url
X-Server-Name
X-Varnish-TTL
X-Px
X-MS-InvokeApp
Allow
X-Country-Code
Pinterest-Generated-By
X-DynaTrace
X-TTL
X-Origin-Cache
X-DataDome
X-Vhost
X-TtlSet
X-Vname
X-PC
X-Cached
X-FTR-Request-ID
X-Server-ID
X-ESI
RTSS
X-Ruxit-JS-Agent
X-Goog-Hash
SPRequestGuid
Charset
X-Trace
X-VARITI-CCR
X-Powered-By-Plesk
X-Powered-CMS
X-Oracle-Dms-Rid
X-SharePointHealthScore
X-DynaTrace-JS-Agent
Accept-CH
X-GitHub-Request-Id
X-Dispatcher
X-T
Public-Key-Pins
X-D2id
X-Mod-Pagespeed
X-Mobile-Rewrite
PB-RID
Arc-Version
PB-PID
X-F-Cache
Content-MD5
Verso
X-GoogleNews-Bot
X-Exp-Variant
X-Exp-Id
X-Kinja
X-Cdn-Fetch
X-Kinja-Build
X-B3-TraceId
X-Kinja-Server
X-Kinja-Revision
MS-Author-Via
X-Version
SPIisLatency
SPRequestDuration
X-Shield-Request-Id
X-Recruiting
X-Dns-Prefetch-Control
X-Abt-Application-Version
Nginx-Cache
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Client-IP
X-Forwarded-Proto
X-HW
Accept-CH-Lifetime
X-DIS-Request-ID
X-N
X-Navigation-Version
AR-PoweredBy
AR-CACHE
AR-ATIME
X-Pinterest-Rid
Pinterest-Version
X-Upstream-Env
X-Amz-Rid
X-B
X-Upstream
X-Fastly-Request-ID
X-Dw-Request-Base-Id
DynaTrace
X-Origin-Upstream-Status
X-Ser
X-ORACLE-DMS-RID
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Amz-Meta-S3cmd-Attrs
X-XRDS-Location
Fastly-Restarts
X-Hits
TCN
Realpath
Paypal-Debug-Id
X-Wix-Server-Artifact-Id
X-Accel-Buffering
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Metageneration
X-Content-Options
Arr-Disable-Session-Affinity
Service-Worker-Allowed
X-NF-Request-ID
X-Pad
X-Acc-Meta-Resource-Type
X-Goog-Storage-Class
Tracecode
Access-Control-Request-Method
S
X-Content-Digest
X-Id
X-Debug
X-Varnish-Age
Front-End-Https
X-Oneagent-Js-Injection
Mrf-Cache-Status
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
MRF-Tech
X-Vcap-Request-Id
X-MSEdge-Ref
X-Use-Magma
X-Frontend
X-RateLimit-Remaining
X-IPLB-Instance
Edge-Cache-Tag
X-FTR-DC
X-FTR-Expires
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Backend
X-FTR-Realm
X-PressLabs-Stats
X-Kinsta-Cache
X-Amz-Cf-Pop
X-Logged-In
X-ATG-Version
X-HS-Content-Id
X-HS-Hub-Id
MicrosoftSharePointTeamServices
X-Cache-Hit
Surrogate-Key
X-Middleton-Display
Display
X-Sol
X-Forwarded-For
Rt-Fastcgi-Cache
X-FastCGI-Cache
Fastcgi-Cache
X-Request-Processing-Time
X-Request-Received
Powered-By-ChinaCache
X-Zen-Fury
X-B3-TraceId-Primal
X-Edge-Location
X-Analytics
Backend-Timing
X-Webkit-Csp
X-Litespeed-Cache
Server-Name
X-Rid
X-Amzn-Trace-Id
X-Debug-Info
X-User-Agent
X-Revision
X-Grace
Host
TP-L2-Cache
TP-Cache
X-FTR-Cache-Host
FilterID
X-CF-Powered-By
X-Cache-Key
X-Akam-SW-Version
AMP-Access-Control-Allow-Source-Origin
X-Newrelic-App-Data
Response
X-Middleton-Response
X-HS-Cache-Config
Ar-Sid
X-TA-CDN-Provider
X-Mobile
X-Drupal-Cache-Tags
AR-Request-ID
X-SS-Set-Cookie
X-Magnolia-Registration
X-Accel-Expires
X-SERVER
Cache-Status
X-Ttl
Refresh
X-Fastcgi-Cache
X-Cached-By
Host-Header
X-GUploader-UploadID
X-B3-Sampled
X-NewRelic-App-Data
X-AOL-HN
X-Varnish-Backend
ServerID
X-Webkit-CSP
X-Node-Name
X-Content-Security-Policy-Report-Only
X-Tumblr-Pixel
X-Cluster
X-FB-Debug
X-Instance
X-Tumblr-User
X-NWS-LOG-UUID
X-Tumblr-Pixel-0
X-Cache-2
X-Cache-Control
X-Akamai-Edgescape
X-B-Cache
X-Whom
X-Platform-Server
Eomportal-Instance
X-Signature
X-Framework
X-Device-Type
X-Page-Id
X-App-Environment
X-Ruxit-Js-Agent
X-VCache
X-Varnish-Hostname
X-LB-Cache
X-BCube-Filmed-By
X-Generated-By
X-Handled-By
Cleartype
X-Srv
X-Request-Guid
Cache-Tag
X-Activity-Id
X-AppVersion
X-Drupal-Cache-Contexts
X-Cache-Rule
X-Az
Liferay-Portal
DC
X-Cache-Action
X-Via-JSL
X-App-Server
X-WPE-Loopback-Upstream-Addr
X-Cache-Server
Source
X-Content-Powered-By
Alternate-Protocol
Retry-After
MS-CV
Public-Key-Pins-Report-Only
X-Hostname
X-HS-Combine-CSS
X-Varnish-Grace
X-Geo-Country
X-WA-Info
HostName
X-Seen-By
X-Esi
X-Varnish-Server
X-Amz-Replication-Status
X-TT
X-Wix-Request-Id
ViewerVersion
AR-SID
X-App-Version
Server-Node
Accept-Charset
Webserver
X-URL
X-Daa-Tunnel
Upgrade-Insecure-Requests
X-Correlation-Id
X-Response-Served-From
X-Geo-Segment
AsisCache
X-Tumblr-Pixel-2
X-WebKit-CSP-Report-Only
X-Cache-NE
X-Tumblr-Pixel-1
X-Amzn-RequestId
X-GeoIP
SRV
Actual-Object-TTL
X-Amz-Apigw-Id
X-RequestSource
Pagespeed
GEO-INFO
ServedBy
X-Locale
X-Jobs
X-Correlation-ID
X-Servedby
Viewport
X-Yottaa-Metrics
X-FW-Static
X-Varnish-Hits
X-UUID
X-Contextid
X-Edge-Cache
X-FW-Serve
X-FW-Server
X-FW-Type
Payment
X-FW-Hash
X-Yottaa-Optimizations
X-Edge-Cache-Key
X-Status
X-S
X-Varnish-IP
X-TX-ID
X-Adobe-Content
X-Adobe-Loc
X-Cacheable-TTL
X-Origin-Server
X-TT-TIMESTAMP
X-Vg-Webcache
X-Cache-TTL-Remaining
Cache
S-Cnection
X-Hyper-Cache
X-Forwarded-Host
X-Amz-Server-Side-Encryption
X-Cache-Operation
X-RateLimit-Limit
Datacenter
Server-Info
X-XRDS-LOCATION
CACHE
X-Real-IP
X-Region
Served-By
X-Cache-Age
X-Sucuri-ID
X-Akamai-Request-ID2
X-Mode
X-CLOUD-TRACE-CONTEXT
Access-Control-Allow-Method
Country
Healthy
X-Content-Type
From-Origin
X-DataStream-Cache-Status
X-Cache-Var
X-Zipkin-Id
X-Upgrade-Enabled
X-Is-Bot
X-Environment-Context
X-Detected-As
X-Cache-Var-Map
X-Generated
X-JoinUs
X-Cache-Config
X-L-Path
X-Ocache
X-Proxied
Machine
X-Proxy
X-Rendered-As
Fastcgi-X-Cache
Fastcgi-X-Cache-Version
X-Ezoic-Cdn
Meta-Geo
X-Path-Route
X-Routing-Service
X-RN-RSRV
X-Rule
X-Access
X-Format
X-Grey
X-EIG-Tracking-Id
X-Request-Time
DB-Nickname
X-Akamai-Transformed
X-Agile
X-CDN-Cache
X-Via-CDN
X-NGENIX-Cache
X-Viewer-Country
X-Birta-Cache-Post
Fastcgi-Useragent
X-Agile-Age
X-Birta-Served
Now
X-Amz-Meta-Surrogate-Control
X-Human
X-Section
X-Cache-Category-Id
L5d-Success-Class
X-Agile-Id
X-Hosted-By
TWC-Locale-Group
Property-Id
S-Rt
X-Tb
OT-Force-Account-Verify
Cache-Name
X-TNCMS
TWC-Connection-Speed
TWC-Device-Class
Webcakes-App-Name
Webcakes-App-Version
TWC-Privacy
TWC-GeoIP-LatLong
TWC-GeoIP-Country
Webcakes-Region
X-FC-Vary-Parameters
X-Origin-Hint
X-Microcachable
X-Loop
X-Pc-Appver
X-Pc-Hit
X-ServerID
X-PCL
X-Pc-Key
X-Labrador-Cache-Channel
X-OCL
X-Via-Fastly
X-Hit
Xserver
X-CCM
X-ProcessESI
X-BYPASS-REASON
X-ProxyCache-Key
X-Pubstack
X-RemovedCookies
X-Cluster-Node
HitType
X-ProxyCache-Status
X-OVcl-Cache
X-AWS-Id
X-Site-Version
X-LJ-Flow-ID
X-Origin
HitInfo
X-IP
X-OVcl
X-Original-Request
X-SplitTest
X-Cdn
X-Xfnlog-Site
X-Upstream-HT
Azure-SlotName
Azure-SiteName
Azure-RegionName
Azure-Version
X-Upstream-CT
X-Web-Node
X-VG-TLSProxy
X-VWS-Id
Azure-InstanceId
Origin-Cache-Control
Origin-Edge-Control
X-Proxy-Build
X-Alternate-Cache-Key
X-Sorting-Hat-PodId
X-TIME
X-Www-Served-By
X-ShardId
X-ShopId
LB
X-Shopify-Stage
X-Sorting-Hat-ShopId
X-Timing-Wait
Selected-FE
Mn-Server-Ip
Accept-Language
X-App-Name
X-Twitter-Response-Tags
Ms-Operation-Id
X-Transaction
X-Connection-Hash
X-Rocket-Nginx-Bypass
X-RTag
X-Geo
X-GRACE
X-Cache-Enabled
NGB
X-TWH-CORRELATION-ID
Access-Control-Request-Headers
X-Source
Content-Script-Type
IBM-Web2-Location
Content-Style-Type
Filters
X-Unique-ID
X-Cdn-Forward
Time
X-NodeID
Cache-Hits
X-Guploader-Uploadid
X-NCache
X-Internal-Host
X-Cache-Remote
X-Real-Ip
X-Tumblr-Pixel-3
X-Port
X-APP-VERSION
X-Nginx-Cache
X-Pc-Date
X-Pc-Host
X-Ms-Lease-Status
X-Ms-Blob-Type
NtCoent-Length
X-Cache-TTL
X-Ms-Version
X-Ms-Request-Id
X-MP-GENERATED-AT
Mail-Subject
X-UA
X-Origin-CC
X-Proto
We-Hiring
X-UA-Device-Type
X-Edge-IP
X-Datadome
PageSpeed
X-Distil-CS
X-Storage
Backend
X-Debug-Cache
X-Vgn-Hpd-Reason
X-PHP-Backend
X-Ua
X-Time-Microsecs
X-Varnish-Cacheable
X-Oracle-Dms-Ecid
X-Webstats-RespID
Cache-Tags
X-Backend-Name
X-CACHE-GROUP
X-Akamai-Request-ID
X-CACHE-KEY
X-Csrf-Token
X-CACHE-AGE
Locale
X-Urbn-Context-Path
X-Urbn-Site-Id
User-Agent
X-Endurance-Cache-Level
X-Varnish-Cache-Hits
X-Ratelimit-Limit
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
X-EdgeConnect-Cache-Status
Warning
X-PERF
X-ApacheServer
X-B3-Spanid
X-Sucuri-Cache
X-Origin-Response-Time
X-C
X-Redis-Cache
Fastly-SSL
X-Mrs-Age
X-ElasticPress-Search
X-Mrs-Cache
X-NC
X-Mrs-Cache-Hits
X-Mshield-Cache-Status
VivaBuild
X-A
X-A-Ccd
Viewtype
X-A-Dam
SN
Server-Host
X-A-Dcw
TSSecure
UCS
V-Age
X-Accel-Expires-Debug
X-Backend-Host
X-Backend-Url
X-BB-ID
X-BBXSRF
X-B-Cookie
X-Application
X-A-Wwc
Rt-Proxy-Cache
X-Aed
X-Amz-Meta-Cache-Control
X-A-Dgt
Powered-By
HA-Geocity
HA-Geocountry
HA-Geolat
HA-Geolon
HA-Cloudapp
GMS-Ver
Fly-Cache
Fly-Request-Id
FSS-Cache
FSS-Proxy
HA-Georegion
Ha-Gx-Prefs
Mobile-Detection-Method
Odigeo-Trace-Id
X-Cache-Bucket
Rendered-Blocks
Meta-Geo-Continent
MD5-Digest
HA-Host
HA-Ipaddr
HA-Servedtime
HA-Urlpath
Resin-Trace
X-CF-Lambda-Version
X-Region-Sid
X-Rewrite-Enabled
X-Rojux
X-S-Cookie
X-PAYTM-SRV-ID
X-Org
X-Irp-Debug
X-Logtrace-Id
X-NU-AKA-ACS-Version
X-NX-Host
X-ScT
X-Server-By
X-VG-WebServer
X-Via-Edge
X-Via-SSL
Xc-Version
X-UE-Client-Country
X-Trv-Group
X-Server-Time
X-Sn-Servicetimems
X-SRCache-Key
X-Store
X-IN-WAF
X-IN-SSL-APIGATEWAY
X-Debug-Cookies
X-Debug-Log
X-Destination
X-Died
X-Date
X-D
X-Cdn-Origin
X-CF-Lambda-Fn
Ec-Rule-Version
X-CGP
X-DPWN-IS-SECURE
X-Eu-Site
X-Generated-In
X-GeoIP-Country-Code
X-Hash
X-IN-APIGATEWAY
X-G
X-From
X-External-Request-Id
X-F5-Cache
X-Fetched-On
X-Cache-Host
X-Developer
BehaviorPad-Version
X-Varnish-Beresp-Ttl
Cache-Prefix
Ajk
Content-Disposition
Arc-Country
X-Cache-Backend
X-Croise-Owner
Cache-Key
X-Dc
X-FW-Version
X-GeoIP-City
X-Layer
X-Location
Decoy-Debug-Key
X-Key
X-DC
X-Hello
X-Hl-Ver
X-Nc
X-Developers
X-Dynatrace-Js-Agent
X-ABtesting
Www
Thinkindot-Control
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-Auto-Login
X-Backend-State
X-Dispatcher-Server
X-Epic-Correlation-Id
X-Core-Value
X-Clientip
X-Cache-Id
X-Flog
X-Qloud-Router
X-V
X-Var-Ttl
X-UnsetCookies
X-Trace-Id
X-Thinkindot-L3
X-Via-NSCOPI
X-VServer
X-Cache-URL
X-We-Are-Hiring
X-Worker
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-SIPLIST1
X-ServiceProvider
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
Server-ID
X-Platform
X-No-Session
X-Reboot
X-Release
X-S-Maxage
X-Server-IP
X-Response-By
X-Request-URI
X-Request-Start
X-MServer
X-Matched-Rule
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Fastly-SWR
Pramga
Fastly-Soc-X-Request-Id
Decoy-Debug-Status
Origin
Memcached
Decoy-Debug-TTL
Countrycode
GW-Server
Release
Apple-News-Services-Host
Frame-Options
Heartbleed
Apple-News-Services-Handled
Country-Code
RNT-Time
RNT-Machine
IsBot
Fastly-SIE
Is-Eu
X-Hnp-Log
MI-Cache-Age
X-Newrelic-Synthetics
X-Up
Esi-Enabled
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Fastly-Cache
X-Distributor
X-Device-Os
Pragrma
Pagetype
Platform
X-RCS-CacheZone
X-Gannett-Site-Version
On-Server
Fastly-Backend-Name
X-Gen-Mode
Adler-Geo
X-Oss-Storage-Class
X-Policy
X-Oss-Server-Time
X-Oss-Request-Id
X-Node-Id
X-Owner
X-P-T
X-Passed-To-PostProcessResponse
X-Phone
X-Passed-To-DLL
X-Passed-To-BeforeDispatch
X-Passed-To
Kp-EeAlive
X-Nginx-Cache-Key
X-Oss-Hash-Crc64ecma
X-Li-Fabric
X-Instance-Name
X-Info
X-WebServer
X-Li-Pop
X-LI-Proto
Magicmarker
X-Powered-By-ANYU
X-MI-In-Market
X-Oss-Object-Type
X-LI-UUID
MI-Cache
AKAMAI
X-Sentry-ID
X-Cache-Debug
X-Secret
X-Served-From
X-VCT
Cache-Cookie-Set-Idcheck
X-Request-UUID
X-Cache-Expires
Cache-Cookie-Set-From
X-Returned-From-PostProcessResponse
X-Returned-From
X-Returned-From-BeforeDispatch
X-Returned-From-DLL
Backend-Name
Request-EU
X-Block-Status
X-Bip
X-Actual-URL
Cache-Cookie-Set-Lfrom
X-Crawler
X-Thanos
True-Client-Country-4JS
X-User
Server-Int
Section-Io-Cache
X-CUA
X-Core-Mission
X-Swa-Ws
WZWS-RAY
X-Variation
X-Sf
X-Stale
Web-Mar-Node
Uber-Trace-Id
User-Cache-Control
Request-Country
Version
X-CDN-Forward
X-NWS-UUID-VERIFY
X-MSEdge-Flight
X-Varnish-Action
X-Cache-FS-Status
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
CDCHOST
Proxy-Connection
X-Fstrz
X-NODE
X-MSEdge-Features
MI-API
X-Refresh
X-TT-LOGID
X-HOST
X-Cache-CFC
V-Cache
X-Page-Type
Group
X-Parent-Response-Time
X-SN
MIME-Version
X-Unique-Id-Primal
X-Backend-TTL
REQUESTUUID
Cteonnt-Length
RequestId
X-Kong-Upstream-Latency
X-Pjax-Url
X-Req
Who
HTTPS
X-Kong-Proxy-Latency
X-Servername
X-Cache-Srv
Fusion-Source
X-Be
X-Ms-Lease-State
X-Time
NodeID
X-GZip
Fusion-Content-Id
Fusion-Content-Source
Amp-Access-Control-Allow-Source-Origin
Fusion-Component-Id
Fusion-Template-Id
X-Origin-TTL
Memory
ProcessTime
Cdn
Cdn-Host
X-Edge-Server
Cdn-Request-Time
X-Servedbyhost
X-BB-IP
CF-IPCountry
SS
X-Aicache-OS
X-Server-Group
Mime-Version
X-Ckpd-Fst-Backend
X-Protected-By
X-ND-Cache
X-Content-Age
X-Wa
X-COUNTRY
SD-X-WS
GeoIP-Country-Code
CDN
A
GeoIP-Latitude
X-APP
X-SRV
X-Varnish-Beresp-TTL
PageType
Is-Session-Tracking
X-Origin-Date
X-Origin-Expires
Get-Access-Time
XServer
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Pf-Uncompressing
X-Varnish-Url
X-Origin-Host
X-B3-Traceid
PICS-Label
Geoip-Latitude
Serverid
X-Unique-Id
GeoIp-Country-Code
X-Fastly-Country-Code
X-Gdpr
X-WA
X-Requestid
X-StackifyID
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Cache-Info
X-Generation-Time
X-Ratelimit-Remaining
X-CSRF-Token
Processtime
X-FireWall-Port
X-PHP-Host
Node
X-Fastly-Cache-Hits
X-Nananana
Nel
X-Proxy-Upstream
X-Proxy-Cache-Status
X-Load-Cache
X-ID
Vix-Hermes-Req-Id
X-RequestId
X-EC-Security-Audit
X-CS
Cf-Ipcountry
DataCenter
URI
X-SERVER-NAME
Cache-Tv-Group
X-Check-Cacheable
X-GEO
X-Atg-Version
X-Server-W
X-HS-Status
X-ServedByHost
Hostname
X-FORWARDED-FOR
X-Surge-Debug
X-BACKEND-TTL
NGX
X-NGINX-Cache
X-GZIP
T-Server
X-UPSTREAM-Address
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
Cache-Provider
X-Planisys-CDN-TTL
X-Vcache
X-HTML-Minification-Powered-By
X-BE
Request-Time
X-HTML-Edge-Cache
X-Fastly-Backend-Reqs
WP-Super-Cache
X-WR-MODIFICATION
X-B3-SpanId
X-M-Reqid
X-M-Log
X-Qnm-Cache
X-Micro-Cache
X-DataStream-Origin-MEX-Latency
PFcat
Host-ID
X-DataStream-MidMile-RTT
X-VG-WebCache
X-Fe
Requestid
Https
X-PF-Uncompressing
X-Amz-Meta-S3b-Last-Modified
ServerName
RequestUuid
X-ServerName
X-Debug-Cache-Expiry
X-Alicdn-Da-Ups-Status
Load-Balancing
X-Debug-Cache-Fetch
X-IPS-LoggedIn
X-PJAX-URL
X-Debug-Cache-Store
X-Front
X-Akamai-SSL-Client-Sid
N-Cache
X-SB
X-Distil-Cs
X-VC
X-VarnPar1
X-Svr
X-GDPR
X-PARISIEN-Cache-Rendered
X-VarnCache
X-PAGE-TYPE
X-Cache-Ttl
WebServer
X-Skip-Cache
X-From-Cache
X-ARC
X-FB-TRIP-ID
X-RAMCache
X-Instart-Info
X-Swift-Error
X-VarnPar2
Cdn-Src-Port
SID
X-Proxy-Server
X-Grace-Duration
X-Feature
X-Gen-Id
X-Dw-Trace-Id
Build-Number