Threat Level: green Handler on Duty: Jim Clausing

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
Last-Modified
X-Content-Type-Options
Accept-Ranges
Pragma
X-Powered-By
CF-RAY
Link
ETag
Expect-CT
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Id
X-Served-By
Referrer-Policy
X-Varnish
X-Request-Id
X-Xss-Protection
X-Timer
CF-Cache-Status
X-AspNet-Version
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Runtime
X-Download-Options
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Cacheable
Alt-Svc
X-Check
X-Generator
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Cache-Status
X-AspNetMvc-Version
Status
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Template
X-Language
X-Permitted-Cross-Domain-Policies
Content-Encoding
X-Iinfo
X-FRAME-OPTIONS
X-Content-Security-Policy
X-CDN
X-Buckets
X-Turbo-Charged-By
X-Request-ID
Upgrade
X-Type
WPE-Backend
X-Pass-Why
Keep-Alive
X-Cache-Group
X-AH-Environment
Xkey
CF-Ray
X-Backend
Access-Control-Max-Age
P3p
X-Age
Access-Control-Expose-Headers
X-Via
X-Drupal-Dynamic-Cache
EagleId
X-Nginx-Cache-Status
X-Pingback
X-Amz-Request-Id
X-Amz-Id-2
X-Server-Powered-By
X-Server
X-Hacker
Grace
X-UA-Device
X-Swift-SaveTime
X-Swift-CacheTime
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-Kinja-Server-Push
X-Robots-Tag
Cf-Railgun
X-Proxy-Cache
X-Envoy-Upstream-Service-Time
X-LiteSpeed-Cache
X-Page-Speed
X-Ua-Compatible
Request-Context
X-Device
X-Ac
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
Content-Location
X-Cache-Lookup
X-Amz-Version-Id
X-Host
X-Response-Time
Surrogate-Control
X-OneAgent-JS-Injection
X-WebKit-CSP
X-Rq
X-Cnection
X-Node
X-Backend-Server
X-Server-Id
X-Readtime
Server-Timing
X-Rack-Cache
Report-To
Request-Id
EagleEye-TraceId
X-Application-Context
X-Cloud-Trace-Context
Feature-Policy
X-ORACLE-DMS-ECID
X-Instart-Request-ID
X-CST
X-Iejgwucgyu
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Clacks-Overhead
Edge-Control
NEL
X-Url
Rating
X-Country
X-Server-Name
X-Px
X-Varnish-TTL
X-TTL
X-DataDome
X-MS-InvokeApp
Allow
Pinterest-Generated-By
X-Country-Code
X-DynaTrace
X-Origin-Cache
X-Vhost
X-Vname
X-TtlSet
X-PC
X-Cached
X-FTR-Request-ID
X-ESI
RTSS
X-Goog-Hash
X-Ruxit-JS-Agent
Charset
SPRequestGuid
X-VARITI-CCR
X-Trace
X-Oracle-Dms-Rid
X-Powered-By-Plesk
X-Powered-CMS
Accept-CH
X-GitHub-Request-Id
X-SharePointHealthScore
X-Dispatcher
Public-Key-Pins
X-D2id
X-T
X-Mod-Pagespeed
X-Server-ID
X-DynaTrace-JS-Agent
Arc-Version
X-Mobile-Rewrite
PB-RID
PB-PID
X-F-Cache
Content-MD5
X-Cdn-Fetch
Verso
X-Kinja-Server
X-Kinja-Revision
X-Exp-Id
X-GoogleNews-Bot
X-Kinja-Build
X-Exp-Variant
X-Kinja
X-B3-TraceId
MS-Author-Via
X-Version
SPIisLatency
SPRequestDuration
X-Shield-Request-Id
X-Recruiting
X-Abt-Application-Version
X-Dns-Prefetch-Control
Nginx-Cache
X-Client-IP
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Forwarded-Proto
X-HW
Accept-CH-Lifetime
X-N
X-DIS-Request-ID
X-Navigation-Version
AR-ATIME
AR-CACHE
AR-PoweredBy
X-Pinterest-Rid
X-Upstream-Env
Pinterest-Version
X-Amz-Rid
X-B
X-Upstream
X-Dw-Request-Base-Id
X-Fastly-Request-ID
DynaTrace
X-Origin-Upstream-Status
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Ser
X-Amz-Meta-S3cmd-Attrs
Fastly-Restarts
X-Hits
TCN
Realpath
X-ORACLE-DMS-RID
X-XRDS-Location
Paypal-Debug-Id
X-Wix-Server-Artifact-Id
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Accel-Buffering
X-Content-Options
Arr-Disable-Session-Affinity
Service-Worker-Allowed
X-NF-Request-ID
X-Pad
X-Acc-Meta-Resource-Type
X-Goog-Storage-Class
Tracecode
Access-Control-Request-Method
S
X-Content-Digest
X-Id
X-Varnish-Age
X-Debug
Front-End-Https
Mrf-Cache-Status
X-Mrf-Section-Lastmod
MRF-Tech
X-Mrf-Item-Lastmod
X-Vcap-Request-Id
X-MSEdge-Ref
X-Webkit-Csp
X-Oneagent-Js-Injection
X-Frontend
X-ATG-Version
X-IPLB-Instance
X-FTR-Expires
X-FTR-Realm
X-FTR-Backend
X-PressLabs-Stats
X-FTR-DC
X-FTR-Backend-Server
X-FTR-Balancer
X-Country-Code-Real
X-FTR-Cache-Status
X-Kinsta-Cache
Edge-Cache-Tag
X-Use-Magma
X-RateLimit-Remaining
X-Logged-In
X-HS-Hub-Id
X-Middleton-Display
X-Sol
Display
X-HS-Content-Id
X-Cache-Hit
Surrogate-Key
X-Amz-Cf-Pop
MicrosoftSharePointTeamServices
X-Forwarded-For
Rt-Fastcgi-Cache
Fastcgi-Cache
X-Request-Received
X-Request-Processing-Time
Powered-By-ChinaCache
X-Zen-Fury
X-Edge-Location
Ar-Sid
Server-Name
Backend-Timing
X-Grace
X-Analytics
X-Fastcgi-Cache
X-Debug-Info
X-Amzn-Trace-Id
X-Rid
X-B3-TraceId-Primal
X-User-Agent
X-Revision
Host
FilterID
TP-L2-Cache
TP-Cache
X-FTR-Cache-Host
Response
X-Middleton-Response
X-Litespeed-Cache
X-CF-Powered-By
X-Akam-SW-Version
X-NewRelic-App-Data
X-FastCGI-Cache
X-HS-Cache-Config
X-Cache-Key
X-Mobile
AMP-Access-Control-Allow-Source-Origin
X-SS-Set-Cookie
X-Drupal-Cache-Tags
X-Magnolia-Registration
AR-Request-ID
X-TA-CDN-Provider
Cache-Status
X-Accel-Expires
Refresh
X-Ruxit-Js-Agent
X-Cached-By
Host-Header
X-Ttl
X-Newrelic-App-Data
X-SERVER
X-B3-Sampled
ServerID
X-AOL-HN
X-Varnish-Backend
X-Node-Name
X-Content-Security-Policy-Report-Only
X-Instance
X-Tumblr-Pixel-0
X-Tumblr-User
X-Cluster
X-Tumblr-Pixel
X-FB-Debug
X-Akamai-Edgescape
X-Cache-Control
Eomportal-Instance
X-B-Cache
X-Cache-2
X-Whom
X-Platform-Server
X-Webkit-CSP
X-Signature
X-LB-Cache
X-App-Environment
X-Varnish-Hostname
X-BCube-Filmed-By
X-Page-Id
X-Framework
X-Device-Type
X-Srv
Cache-Tag
X-Generated-By
X-NWS-LOG-UUID
X-Handled-By
Cleartype
X-Request-Guid
X-GUploader-UploadID
X-Cache-Rule
X-Az
DC
X-Drupal-Cache-Contexts
X-Activity-Id
X-AppVersion
Liferay-Portal
X-VCache
X-Cache-Action
X-App-Server
X-Via-JSL
X-WPE-Loopback-Upstream-Addr
X-Cache-Server
X-App-Version
Source
X-Content-Powered-By
Public-Key-Pins-Report-Only
Retry-After
Alternate-Protocol
MS-CV
X-Correlation-Id
X-Hostname
X-HS-Combine-CSS
X-TT
X-Varnish-Grace
HostName
X-Amz-Replication-Status
Accept-Charset
X-Geo-Country
X-Varnish-Server
X-WA-Info
X-Geo-Segment
X-Wix-Request-Id
X-Seen-By
Server-Node
ViewerVersion
X-Esi
Webserver
Upgrade-Insecure-Requests
X-Daa-Tunnel
X-WebKit-CSP-Report-Only
X-Tumblr-Pixel-2
X-Cache-NE
X-Response-Served-From
X-Tumblr-Pixel-1
AsisCache
X-Amzn-RequestId
Pagespeed
X-Amz-Apigw-Id
SRV
Actual-Object-TTL
X-Locale
X-GeoIP
GEO-INFO
X-URL
X-RequestSource
X-Varnish-Hits
Cache
X-Jobs
ServedBy
X-FW-Serve
X-Yottaa-Metrics
X-Contextid
X-Yottaa-Optimizations
X-UUID
X-S
X-Edge-Cache-Key
X-Edge-Cache
X-Servedby
X-FW-Hash
Payment
X-FW-Static
X-FW-Type
Viewport
X-FW-Server
X-Status
X-TX-ID
AR-SID
X-Varnish-IP
X-Adobe-Loc
X-Adobe-Content
X-Origin-Server
X-TT-TIMESTAMP
X-Cacheable-TTL
X-XRDS-LOCATION
X-Cache-TTL-Remaining
S-Cnection
X-Vg-Webcache
X-Correlation-ID
X-Cache-Age
X-Hyper-Cache
X-Forwarded-Host
X-Amz-Server-Side-Encryption
Datacenter
X-Cache-Operation
Server-Info
X-RateLimit-Limit
Served-By
X-Region
X-Sucuri-ID
X-Akamai-Request-ID2
X-Mode
Country
Access-Control-Allow-Method
Healthy
X-CLOUD-TRACE-CONTEXT
X-Ezoic-Cdn
From-Origin
X-Guploader-Uploadid
X-TIME
X-DataStream-Cache-Status
Machine
X-Upgrade-Enabled
Fastcgi-X-Cache-Version
X-Zipkin-Id
Meta-Geo
X-Content-Type
X-Detected-As
X-RN-RSRV
X-L-Path
X-Cache-Var-Map
X-Ocache
X-JoinUs
X-Is-Bot
X-Generated
X-Environment-Context
X-Path-Route
X-Proxied
X-Site-Version
X-Cache-Var
X-Rule
X-Routing-Service
X-Proxy
X-Rendered-As
X-Cache-Config
Fastcgi-X-Cache
X-Agile-Age
X-Agile-Id
X-Amz-Meta-Surrogate-Control
X-Birta-Cache-Post
X-Agile
X-Access
DB-Nickname
Fastcgi-Useragent
L5d-Success-Class
Now
X-Birta-Served
X-Cache-Category-Id
X-NGENIX-Cache
X-Request-Time
X-Section
X-Viewer-Country
X-Hosted-By
X-Grey
CACHE
X-CDN-Cache
X-EIG-Tracking-Id
X-Format
X-Real-IP
X-Human
X-Akamai-Transformed
Xserver
X-FC-Vary-Parameters
X-Via-CDN
X-CCM
OT-Force-Account-Verify
Cache-Name
X-TNCMS
X-Labrador-Cache-Channel
X-Tb
Property-Id
X-Loop
TWC-Connection-Speed
Webcakes-App-Name
Webcakes-App-Version
Webcakes-Region
X-Via-Fastly
TWC-Privacy
TWC-Locale-Group
X-Microcachable
TWC-Device-Class
TWC-GeoIP-Country
TWC-GeoIP-LatLong
S-Rt
X-Hit
X-Pc-Appver
X-ServerID
X-OCL
X-Pc-Hit
X-Origin-Hint
X-PCL
X-Pc-Key
HitInfo
HitType
X-Cluster-Node
X-OVcl
X-Upstream-HT
X-ProxyCache-Key
X-ProcessESI
X-VG-TLSProxy
X-Web-Node
X-Xfnlog-Site
X-OVcl-Cache
X-Real-Ip
X-BYPASS-REASON
X-ProxyCache-Status
Accept-Language
X-VWS-Id
X-Upstream-CT
X-LJ-Flow-ID
X-RemovedCookies
X-AWS-Id
X-SplitTest
Azure-InstanceId
X-IP
X-Pubstack
X-Origin
X-Original-Request
Azure-Version
Azure-SlotName
Azure-RegionName
Azure-SiteName
X-Alternate-Cache-Key
X-Proxy-Build
X-ShardId
LB
Selected-FE
X-ShopId
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Timing-Wait
X-Www-Served-By
Mn-Server-Ip
Origin-Cache-Control
Origin-Edge-Control
X-Cdn
X-Rocket-Nginx-Bypass
X-App-Name
X-Cache-Enabled
X-TWH-CORRELATION-ID
Ms-Operation-Id
X-RTag
X-Connection-Hash
X-Transaction
X-UA
X-Twitter-Response-Tags
X-Source
X-Cdn-Forward
Content-Script-Type
NGB
Content-Style-Type
X-Geo
X-GRACE
Access-Control-Request-Headers
IBM-Web2-Location
Filters
Cache-Hits
X-NodeID
Time
X-Cache-Remote
X-Origin-CC
X-Port
X-Pc-Host
X-Unique-ID
X-Pc-Date
X-Internal-Host
X-Nginx-Cache
X-NCache
NtCoent-Length
X-Cache-TTL
PageSpeed
X-Ms-Blob-Type
X-Ms-Lease-Status
X-Ms-Request-Id
X-Ms-Version
X-Tumblr-Pixel-3
X-MP-GENERATED-AT
X-Proto
We-Hiring
X-Edge-IP
X-Distil-CS
Mail-Subject
Backend
X-UA-Device-Type
X-Varnish-Cacheable
X-Storage
X-Debug-Cache
X-CACHE-KEY
X-Vgn-Hpd-Reason
X-Time-Microsecs
X-Dynatrace-Js-Agent
X-PHP-Backend
X-Webstats-RespID
X-Backend-Name
Cache-Tags
X-APP-VERSION
X-Akamai-Request-ID
X-Ratelimit-Limit
X-Csrf-Token
X-CACHE-GROUP
X-Varnish-Cache-Hits
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Dc
Locale
X-Endurance-Cache-Level
X-Varnish-Beresp-Grace
X-Nc
X-Ua
X-Varnish-Beresp-Status
Warning
User-Agent
X-Sucuri-Cache
X-EdgeConnect-Cache-Status
X-ApacheServer
X-PERF
X-Mrs-Age
X-Mrs-Cache-Hits
X-B3-Spanid
Fastly-SSL
X-ElasticPress-Search
X-Mshield-Cache-Status
X-Mrs-Cache
X-Redis-Cache
X-C
X-CF-Lambda-Fn
X-Cdn-Origin
X-Died
X-CF-Lambda-Version
X-CGP
HA-Geolon
Ha-Gx-Prefs
HA-Georegion
X-IN-WAF
X-Cache-Bucket
HA-Ipaddr
X-Hash
X-Region-Sid
X-Cache-Host
HA-Servedtime
HA-Urlpath
HA-Host
X-Debug-Cookies
Fly-Cache
Fly-Request-Id
X-Developer
FSS-Cache
Ec-Rule-Version
Content-Disposition
BehaviorPad-Version
Cache-Prefix
X-Rewrite-Enabled
FSS-Proxy
GMS-Ver
X-BBXSRF
HA-Geolat
X-Date
HA-Geocountry
X-Debug-Log
X-Destination
HA-Cloudapp
HA-Geocity
X-D
X-Backend-Url
Arc-Country
Viewtype
V-Age
VivaBuild
X-G
Odigeo-Trace-Id
X-From
X-A
UCS
Powered-By
Rendered-Blocks
Rt-Proxy-Cache
X-IN-APIGATEWAY
X-IN-SSL-APIGATEWAY
X-Generated-In
TSSecure
SN
Server-Host
X-Fetched-On
X-A-Ccd
X-B-Cookie
X-DPWN-IS-SECURE
X-Application
X-Backend-Host
Mobile-Detection-Method
Meta-Geo-Continent
X-BB-ID
Resin-Trace
X-Eu-Site
X-Amz-Meta-Cache-Control
X-External-Request-Id
X-A-Dam
X-F5-Cache
X-A-Dcw
X-A-Dgt
X-Aed
X-Accel-Expires-Debug
X-A-Wwc
MD5-Digest
X-Store
X-PAYTM-SRV-ID
X-Irp-Debug
X-Sn-Servicetimems
X-Croise-Owner
X-Server-By
X-Logtrace-Id
Xc-Version
X-SRCache-Key
X-Cache-Backend
X-UE-Client-Country
X-Trv-Group
X-GeoIP-Country-Code
X-VG-WebServer
X-Via-SSL
X-Via-Edge
X-ScT
X-Server-Time
X-NX-Host
X-S-Cookie
X-NU-AKA-ACS-Version
X-Rojux
Ajk
X-Org
X-Origin-Response-Time
X-CACHE-AGE
Cache-Key
X-User
X-Flog
X-Location
X-ABtesting
X-Qloud-Router
X-Var-Ttl
X-V
X-UnsetCookies
Www
Thinkindot-Control
X-Trace-Id
Server-ID
X-Thinkindot-L3
RNT-Time
RNT-Machine
X-Response-By
X-GeoIP-City
X-Request-Start
AKAMAI
Thinkindot-CacheControl
X-Request-URI
X-FW-Version
X-Rebelmouse-Cache-Control
X-Release
X-Cache-Id
X-Worker
X-Wikidot-Static-Cache
X-Cache-URL
X-Matched-Rule
X-Rebelmouse-Surrogate-Control
X-Core-Value
X-Reboot
X-Clientip
X-Hello
X-Wikidot-Backend
X-No-Session
X-Epic-Correlation-Id
X-Auto-Login
X-VServer
X-Dispatcher-Server
X-Developers
X-Platform
X-Hl-Ver
X-Backend-State
X-We-Are-Hiring
X-Owner
Thinkindot-CacheControl-Type
Heartbleed
X-Key
Decoy-Debug-TTL
X-SIPLIST1
GW-Server
X-ServiceProvider
X-Layer
Decoy-Debug-Status
Country-Code
Countrycode
X-S-Maxage
IsBot
Memcached
Decoy-Debug-Key
X-Server-IP
Fastly-Soc-X-Request-Id
Pramga
Release
Fastly-SWR
Apple-News-Services-Handled
Frame-Options
Fastly-SIE
Apple-News-Services-Host
Apple-News-Services-Request-Url
Origin
Apple-News-Services-Parsed-Url
X-Newrelic-Synthetics
X-Policy
Fastly-Backend-Name
X-CUA
X-Core-Mission
Esi-Enabled
X-MServer
X-MI-In-Market
X-Nginx-Cache-Key
X-Crawler
Cache-Cookie-Set-Lfrom
X-Passed-To-BeforeDispatch
X-Passed-To
X-RCS-CacheZone
X-Fastly-Cache
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Passed-To-DLL
X-Powered-By-ANYU
X-Passed-To-PostProcessResponse
X-Gen-Mode
X-Gannett-Site-Version
X-P-T
Backend-Name
X-Via-NSCOPI
X-Device-Os
X-Secret
X-Info
Cache-Cookie-Set-Idcheck
X-Distributor
Adler-Geo
Cache-Cookie-Set-From
X-Phone
X-Node-Id
X-Block-Status
X-LI-UUID
True-Client-Country-4JS
X-SVT-ORM-VERSION
On-Server
Uber-Trace-Id
X-SVT-ORM-RULES
MI-Cache-Age
X-Up
X-Returned-From
User-Cache-Control
Platform
X-Request-UUID
X-Swa-Ws
Request-Country
X-Thanos
Request-EU
Section-Io-Cache
X-Li-Pop
X-Li-Fabric
Pragrma
Server-Int
Web-Mar-Node
MI-Cache
X-Returned-From-DLL
X-WebServer
X-Sf
X-Instance-Name
X-Bip
X-LI-Proto
X-Cache-Expires
X-Cache-Debug
X-Served-From
X-Returned-From-PostProcessResponse
X-Hnp-Log
Is-Eu
X-Varnish-Action
X-Variation
X-Returned-From-BeforeDispatch
WZWS-RAY
X-VCT
X-Stale
Kp-EeAlive
X-Actual-URL
Magicmarker
X-Sentry-ID
Version
X-Varnish-Beresp-Ttl
X-Datadome
X-NC
X-MSEdge-Features
X-Fstrz
X-MSEdge-Flight
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Oss-Request-Id
X-SN
X-Oss-Storage-Class
X-TT-LOGID
CDCHOST
REQUESTUUID
Proxy-Connection
X-NWS-UUID-VERIFY
X-Cache-CFC
X-CDN-Forward
X-Page-Type
X-Backend-TTL
X-Cache-FS-Status
X-DC
X-Refresh
RequestId
X-HOST
Amp-Access-Control-Allow-Source-Origin
X-NODE
MI-API
HTTPS
Pagetype
X-Kong-Proxy-Latency
V-Cache
X-Kong-Upstream-Latency
Group
X-Cache-Srv
X-Req
X-Unique-Id-Primal
X-Pjax-Url
X-Be
Who
X-Servername
NodeID
Cteonnt-Length
X-Ms-Lease-State
X-Parent-Response-Time
MIME-Version
Fusion-Source
X-Origin-TTL
X-GZip
X-Oracle-Dms-Ecid
Fusion-Content-Source
Memory
Fusion-Template-Id
ProcessTime
Cdn
Fusion-Component-Id
Fusion-Content-Id
Mime-Version
X-Time
X-BB-IP
Cdn-Host
X-Protected-By
X-Ckpd-Fst-Backend
X-Edge-Server
X-Aicache-OS
Cdn-Request-Time
SS
X-ND-Cache
CF-IPCountry
X-Servedbyhost
X-Server-Group
X-Content-Age
PageType
X-Varnish-Beresp-TTL
SD-X-WS
X-COUNTRY
X-Wa
GeoIP-Country-Code
GeoIP-Latitude
CDN
X-SRV
X-APP
A
X-Ratelimit-Remaining
X-Varnish-Url
Is-Session-Tracking
X-Origin-Date
Get-Access-Time
X-Origin-Expires
X-Unique-Id
XServer
X-WA
GeoIp-Country-Code
X-B3-Traceid
Geoip-Latitude
X-Origin-Host
X-Pf-Uncompressing
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Generation-Time
X-Fastly-Country-Code
X-CSRF-Token
Serverid
PICS-Label
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Requestid
X-Cache-Info
X-Gdpr
X-Fastly-Cache-Hits
X-StackifyID
X-FireWall-Port
Processtime
Node
X-PHP-Host
Cf-Ipcountry
X-Nananana
Nel
X-GEO
X-CS
X-EC-Security-Audit
X-Proxy-Upstream
X-ServedByHost
X-Proxy-Cache-Status
X-ID
X-Load-Cache
X-Check-Cacheable
X-Vcache
X-RequestId
X-HS-Status
Vix-Hermes-Req-Id
DataCenter
X-SERVER-NAME
WP-Super-Cache
Cache-Tv-Group
NGX
T-Server
URI
X-Server-W
X-Surge-Debug
X-FORWARDED-FOR
Hostname
X-Qnm-Cache
X-M-Reqid
X-WR-MODIFICATION
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
X-HTML-Minification-Powered-By
X-M-Log
X-BACKEND-TTL
X-NGINX-Cache
X-Feature
X-UPSTREAM-Address
X-GZIP
X-VG-WebCache
Cache-Provider
X-PF-Uncompressing
Request-Time
X-HTML-Edge-Cache
Load-Balancing
X-B3-SpanId
PFcat
X-Micro-Cache
X-Amz-Meta-S3b-Last-Modified
Host-ID
X-Alicdn-Da-Ups-Status
X-ServerName
X-DataStream-MidMile-RTT
X-Fastly-Backend-Reqs
X-DataStream-Origin-MEX-Latency
ServerName
X-BE
X-Fe
X-Atg-Version
X-Debug-Cache-Expiry
Https
X-Debug-Cache-Fetch
X-Skip-Cache
X-Debug-Cache-Store
X-Front
X-PJAX-URL
RequestUuid
Requestid
X-IPS-LoggedIn
X-ARC
X-Akamai-SSL-Client-Sid
X-GDPR
X-VarnPar1
X-VarnCache
X-Svr
X-PARISIEN-Cache-Rendered
X-VC
X-Proxy-Server
X-SB
N-Cache
X-From-Cache
WebServer
X-Cache-Ttl
X-Distil-Cs
X-PAGE-TYPE
Build-Number
X-Instart-Info
X-Swift-Error
X-Gen-Id
Cdn-Src-Port
X-Dw-Trace-Id
SID
X-RAMCache
X-Grace-Duration