Threat Level: green Handler on Duty: Jim Clausing

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
Last-Modified
X-Content-Type-Options
Accept-Ranges
Pragma
X-Powered-By
CF-RAY
Link
ETag
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Id
X-Served-By
Referrer-Policy
X-Varnish
X-Request-Id
X-Timer
CF-Cache-Status
X-AspNet-Version
Access-Control-Allow-Headers
X-Xss-Protection
Access-Control-Allow-Methods
X-Runtime
X-Download-Options
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Cacheable
Alt-Svc
X-Check
X-Generator
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Cache-Status
X-AspNetMvc-Version
Status
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Template
X-Language
X-Permitted-Cross-Domain-Policies
X-FRAME-OPTIONS
Content-Encoding
X-Iinfo
X-Content-Security-Policy
X-Buckets
X-CDN
X-Turbo-Charged-By
X-Request-ID
Upgrade
X-Type
WPE-Backend
X-Pass-Why
Keep-Alive
X-Cache-Group
X-AH-Environment
Xkey
P3p
X-Backend
Access-Control-Max-Age
X-Age
Access-Control-Expose-Headers
X-Via
EagleId
X-Drupal-Dynamic-Cache
X-Nginx-Cache-Status
X-Pingback
X-Amz-Request-Id
X-Amz-Id-2
X-Server-Powered-By
X-Server
X-Hacker
X-Swift-SaveTime
X-Swift-CacheTime
Grace
X-UA-Device
Ali-Swift-Global-Savetime
X-Varnish-Cache
X-Robots-Tag
X-Kinja-Server-Push
Cf-Railgun
X-Proxy-Cache
X-Envoy-Upstream-Service-Time
X-LiteSpeed-Cache
X-Page-Speed
Request-Context
X-Device
X-Ac
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
Content-Location
X-Cache-Lookup
X-Amz-Version-Id
X-Response-Time
X-WebKit-CSP
X-Host
Surrogate-Control
X-Rq
X-Cnection
X-Backend-Server
X-Node
X-Server-Id
X-Readtime
X-OneAgent-JS-Injection
Server-Timing
X-Rack-Cache
Report-To
EagleEye-TraceId
Request-Id
X-Application-Context
X-Cloud-Trace-Context
Feature-Policy
X-ORACLE-DMS-ECID
X-Instart-Request-ID
X-Ua-Compatible
X-CST
X-Iejgwucgyu
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Clacks-Overhead
Edge-Control
NEL
Rating
X-Country
X-Server-Name
X-Px
Pinterest-Generated-By
X-DataDome
X-Url
X-Varnish-TTL
X-Country-Code
Allow
X-TTL
X-MS-InvokeApp
X-DynaTrace
X-Origin-Cache
X-Vhost
X-PC
X-Vname
X-TtlSet
X-Cached
X-FTR-Request-ID
RTSS
X-Goog-Hash
X-ESI
X-DynaTrace-JS-Agent
Charset
X-VARITI-CCR
X-Trace
X-Ruxit-JS-Agent
X-Powered-CMS
SPRequestGuid
X-Powered-By-Plesk
X-Server-ID
Accept-CH
X-GitHub-Request-Id
X-Dispatcher
Public-Key-Pins
X-D2id
X-SharePointHealthScore
X-T
X-Mod-Pagespeed
X-F-Cache
Arc-Version
PB-RID
PB-PID
X-Mobile-Rewrite
Content-MD5
X-Kinja-Revision
Verso
X-Kinja-Build
X-Kinja-Server
X-GoogleNews-Bot
X-Cdn-Fetch
X-Kinja
X-Exp-Id
X-Exp-Variant
X-Oracle-Dms-Rid
MS-Author-Via
X-B3-TraceId
X-Version
X-Recruiting
X-Shield-Request-Id
SPIisLatency
SPRequestDuration
X-Dns-Prefetch-Control
X-Abt-Application-Version
Nginx-Cache
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Client-IP
X-Forwarded-Proto
X-HW
Accept-CH-Lifetime
X-DIS-Request-ID
X-Navigation-Version
X-N
AR-ATIME
AR-CACHE
AR-PoweredBy
Pinterest-Version
X-Pinterest-Rid
X-Upstream-Env
X-ORACLE-DMS-RID
X-Amz-Rid
X-B
X-Dw-Request-Base-Id
X-Upstream
X-XRDS-Location
X-Origin-Upstream-Status
X-Fastly-Request-ID
DynaTrace
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Amz-Meta-S3cmd-Attrs
Fastly-Restarts
X-Ser
X-Hits
Paypal-Debug-Id
TCN
Realpath
X-Wix-Server-Artifact-Id
X-Accel-Buffering
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Oneagent-Js-Injection
X-Content-Options
Arr-Disable-Session-Affinity
X-Pad
Service-Worker-Allowed
X-NF-Request-ID
X-Acc-Meta-Resource-Type
X-Goog-Storage-Class
Tracecode
Access-Control-Request-Method
S
X-Content-Digest
X-Id
Front-End-Https
X-Varnish-Age
X-Debug
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
Mrf-Cache-Status
MRF-Tech
X-MSEdge-Ref
X-Vcap-Request-Id
X-Frontend
X-RateLimit-Remaining
X-ATG-Version
X-FTR-Backend
X-FTR-Realm
X-FTR-Backend-Server
X-FTR-Expires
X-FTR-Cache-Status
X-PressLabs-Stats
X-FTR-DC
X-IPLB-Instance
X-FTR-Balancer
X-Country-Code-Real
X-Kinsta-Cache
X-Amz-Cf-Pop
Edge-Cache-Tag
Display
X-Sol
X-Middleton-Display
X-Logged-In
X-Use-Magma
X-HS-Content-Id
X-Cache-Hit
X-HS-Hub-Id
Surrogate-Key
Fastcgi-Cache
Rt-Fastcgi-Cache
X-FastCGI-Cache
Powered-By-ChinaCache
MicrosoftSharePointTeamServices
X-Request-Received
X-Request-Processing-Time
X-Zen-Fury
X-Forwarded-For
X-Edge-Location
X-Analytics
Backend-Timing
Server-Name
X-Litespeed-Cache
X-Rid
X-Debug-Info
X-Amzn-Trace-Id
TP-Cache
TP-L2-Cache
Ar-Sid
X-Cdn
X-Webkit-Csp
X-Grace
X-B3-TraceId-Primal
X-User-Agent
X-Revision
FilterID
Host
X-FTR-Cache-Host
X-Middleton-Response
Response
X-CF-Powered-By
X-Akam-SW-Version
X-Cache-Key
AMP-Access-Control-Allow-Source-Origin
X-Newrelic-App-Data
X-Mobile
X-TA-CDN-Provider
X-HS-Cache-Config
X-SS-Set-Cookie
X-Ruxit-Js-Agent
X-Drupal-Cache-Tags
X-Accel-Expires
X-Magnolia-Registration
AR-Request-ID
X-Ttl
Cache-Status
X-SERVER
Refresh
X-Fastcgi-Cache
X-Cached-By
Host-Header
X-GUploader-UploadID
X-B3-Sampled
X-NewRelic-App-Data
X-Varnish-Backend
X-Webkit-CSP
ServerID
X-Node-Name
X-AOL-HN
X-Content-Security-Policy-Report-Only
X-BCube-Filmed-By
X-Tumblr-Pixel-0
X-Instance
X-Cluster
X-FB-Debug
X-Tumblr-User
X-Tumblr-Pixel
X-Signature
X-Cache-Control
X-Cache-2
X-Whom
X-B-Cache
X-Platform-Server
X-Akamai-Edgescape
X-Handled-By
X-Varnish-Hostname
Eomportal-Instance
X-Page-Id
X-Framework
X-LB-Cache
X-Esi
Cache-Tag
X-Device-Type
X-NWS-LOG-UUID
Cleartype
X-App-Environment
DC
X-Cache-Rule
X-Generated-By
X-Request-Guid
Liferay-Portal
X-URL
X-Az
X-Activity-Id
X-AppVersion
X-Drupal-Cache-Contexts
X-VCache
X-Cache-Action
X-WPE-Loopback-Upstream-Addr
X-Srv
X-App-Server
Public-Key-Pins-Report-Only
X-Cache-Server
X-Via-JSL
X-Content-Powered-By
Source
MS-CV
Retry-After
X-Geo-Segment
X-HS-Combine-CSS
Alternate-Protocol
X-Hostname
X-Amz-Replication-Status
X-Wix-Request-Id
X-Seen-By
X-TT
Accept-Charset
X-Varnish-Grace
ViewerVersion
HostName
X-WA-Info
X-Geo-Country
X-Varnish-Server
X-App-Version
Webserver
Server-Node
Upgrade-Insecure-Requests
X-Correlation-Id
X-Tumblr-Pixel-1
X-Cache-NE
X-WebKit-CSP-Report-Only
X-Response-Served-From
AsisCache
X-Daa-Tunnel
X-Tumblr-Pixel-2
X-Locale
X-GeoIP
SRV
Actual-Object-TTL
X-Amz-Apigw-Id
X-Amzn-RequestId
AR-SID
Pagespeed
ServedBy
GEO-INFO
X-Varnish-Hits
X-Yottaa-Metrics
X-RequestSource
X-FW-Type
X-Yottaa-Optimizations
X-S
X-Jobs
X-Edge-Cache-Key
X-FW-Static
X-Servedby
Viewport
X-UUID
X-Correlation-ID
X-Edge-Cache
X-Contextid
X-FW-Serve
X-FW-Server
Payment
X-FW-Hash
X-Status
X-Varnish-IP
X-TX-ID
X-Adobe-Loc
X-Adobe-Content
X-Cache-TTL-Remaining
X-Cacheable-TTL
X-Origin-Server
X-TT-TIMESTAMP
Cache
X-Vg-Webcache
X-Forwarded-Host
X-Hyper-Cache
S-Cnection
X-Cache-Operation
X-Amz-Server-Side-Encryption
Datacenter
Server-Info
CACHE
X-RateLimit-Limit
X-Sucuri-ID
Served-By
X-Region
X-Akamai-Request-ID2
X-Mode
X-TIME
Country
X-CLOUD-TRACE-CONTEXT
X-Cache-Age
Access-Control-Allow-Method
X-Real-IP
From-Origin
Healthy
X-Cache-Var
X-Proxy
X-Routing-Service
Machine
X-Rendered-As
X-Proxied
X-Cache-Config
Meta-Geo
X-RN-RSRV
X-Rule
Fastcgi-X-Cache-Version
X-Content-Type
X-Generated
X-Environment-Context
X-Detected-As
X-Cache-Var-Map
X-Is-Bot
X-JoinUs
X-Upgrade-Enabled
X-Site-Version
X-Ocache
X-L-Path
X-Zipkin-Id
X-Path-Route
Fastcgi-X-Cache
X-DataStream-Cache-Status
X-Ezoic-Cdn
X-EIG-Tracking-Id
X-CDN-Cache
Now
X-Cache-Category-Id
S-Rt
X-Request-Time
L5d-Success-Class
X-Grey
DB-Nickname
X-Hosted-By
X-Human
X-Labrador-Cache-Channel
Fastcgi-Useragent
X-NGENIX-Cache
X-Microcachable
X-Format
X-Section
X-Viewer-Country
X-Agile-Age
X-Agile
X-Access
X-Birta-Served
X-Agile-Id
X-Amz-Meta-Surrogate-Control
X-Akamai-Transformed
X-Birta-Cache-Post
X-Pc-Key
X-Pc-Hit
X-Pc-Appver
X-FC-Vary-Parameters
X-Loop
X-Via-CDN
Cache-Name
X-Hit
X-Tb
X-OCL
X-PCL
X-TNCMS
X-CCM
X-Via-Fastly
X-ServerID
TWC-Privacy
TWC-Connection-Speed
TWC-Device-Class
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-GeoIP-Country
Azure-Version
X-BYPASS-REASON
HitType
Webcakes-App-Version
X-Cluster-Node
HitInfo
Webcakes-App-Name
OT-Force-Account-Verify
Webcakes-Region
Property-Id
X-LJ-Flow-ID
X-Pubstack
X-RemovedCookies
X-Xfnlog-Site
X-Web-Node
X-ProxyCache-Key
Azure-SlotName
Accept-Language
X-VG-TLSProxy
X-VWS-Id
X-Upstream-HT
X-Upstream-CT
X-SplitTest
X-ProcessESI
X-ProxyCache-Status
X-AWS-Id
Azure-RegionName
Azure-InstanceId
X-IP
X-XRDS-LOCATION
X-Origin
X-OVcl-Cache
Azure-SiteName
X-OVcl
X-Origin-Hint
X-Original-Request
X-Sorting-Hat-ShopId
X-Timing-Wait
X-Sorting-Hat-PodId
Selected-FE
X-Www-Served-By
X-Proxy-Build
X-Alternate-Cache-Key
LB
X-ShopId
X-ShardId
X-Shopify-Stage
Origin-Edge-Control
Origin-Cache-Control
X-Rocket-Nginx-Bypass
Cache-Hits
Mn-Server-Ip
X-Twitter-Response-Tags
X-Transaction
X-Connection-Hash
X-GRACE
X-Cache-Enabled
X-RTag
X-App-Name
Ms-Operation-Id
Xserver
X-Real-Ip
Content-Style-Type
Content-Script-Type
X-TWH-CORRELATION-ID
X-Source
Access-Control-Request-Headers
IBM-Web2-Location
X-Geo
X-NodeID
X-UA
X-Unique-ID
NGB
PageSpeed
X-Ms-Lease-Status
X-Ms-Version
X-Ms-Blob-Type
X-Cache-Remote
X-Ms-Request-Id
X-Origin-CC
Filters
Time
X-Port
X-Guploader-Uploadid
X-NCache
X-Pc-Host
X-Nginx-Cache
X-APP-VERSION
X-Pc-Date
X-Internal-Host
X-MP-GENERATED-AT
X-Tumblr-Pixel-3
Mail-Subject
NtCoent-Length
X-Distil-CS
We-Hiring
X-Edge-IP
Backend
X-Cdn-Forward
X-Cache-TTL
X-Proto
X-Varnish-Cacheable
X-Debug-Cache
X-Storage
X-UA-Device-Type
X-Vgn-Hpd-Reason
X-Time-Microsecs
X-Ratelimit-Limit
X-PHP-Backend
X-Csrf-Token
X-CACHE-GROUP
X-Webstats-RespID
Cache-Tags
X-Backend-Name
X-CACHE-AGE
X-Ua
X-Akamai-Request-ID
X-CACHE-KEY
X-Urbn-Site-Id
X-Urbn-Context-Path
User-Agent
X-EdgeConnect-Cache-Status
X-Sucuri-Cache
X-Varnish-Cache-Hits
Locale
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
X-ApacheServer
Warning
X-PERF
X-Mrs-Cache
X-Mrs-Cache-Hits
X-Endurance-Cache-Level
Fastly-SSL
X-ElasticPress-Search
X-Mshield-Cache-Status
X-Mrs-Age
X-B3-Spanid
X-NC
X-C
Server-Host
FSS-Cache
X-A-Dcw
Rt-Proxy-Cache
GMS-Ver
FSS-Proxy
Resin-Trace
SN
HA-Host
V-Age
X-Aed
Fly-Cache
UCS
X-Accel-Expires-Debug
HA-Cloudapp
X-A-Dam
TSSecure
Fly-Request-Id
X-A
HA-Geolon
HA-Geolat
VivaBuild
X-A-Dgt
HA-Georegion
MD5-Digest
Meta-Geo-Continent
Odigeo-Trace-Id
HA-Geocountry
Powered-By
X-A-Wwc
Rendered-Blocks
X-A-Ccd
Ha-Gx-Prefs
Viewtype
HA-Urlpath
HA-Servedtime
HA-Ipaddr
HA-Geocity
X-Debug-Cookies
X-Org
X-NX-Host
X-PAYTM-SRV-ID
X-Region-Sid
X-Rewrite-Enabled
X-NU-AKA-ACS-Version
X-Logtrace-Id
X-IN-APIGATEWAY
X-Hash
X-IN-SSL-APIGATEWAY
X-IN-WAF
X-Irp-Debug
X-Rojux
X-S-Cookie
X-VG-WebServer
X-UE-Client-Country
X-Via-Edge
X-Via-SSL
Xc-Version
X-Trv-Group
X-Store
X-Server-By
X-ScT
X-Server-Time
X-Sn-Servicetimems
X-SRCache-Key
X-GeoIP-Country-Code
X-Generated-In
X-Cdn-Origin
X-Cache-Host
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-CGP
X-Cache-Bucket
X-BBXSRF
X-B-Cookie
X-Application
X-Backend-Host
X-Backend-Url
X-BB-ID
X-D
X-Date
X-F5-Cache
X-External-Request-Id
X-Fetched-On
X-From
X-G
X-Eu-Site
X-DPWN-IS-SECURE
X-Debug-Log
Ec-Rule-Version
X-Destination
X-Developer
X-Died
X-Amz-Meta-Cache-Control
Mobile-Detection-Method
X-CDN-Forward
Ajk
Cache-Prefix
X-Redis-Cache
BehaviorPad-Version
Arc-Country
X-Cache-Backend
Content-Disposition
X-Varnish-Beresp-Ttl
X-Dc
X-Newrelic-Synthetics
Cache-Key
X-Layer
Countrycode
X-Flog
X-Epic-Correlation-Id
X-Key
X-Hl-Ver
X-Dispatcher-Server
X-Hello
X-GeoIP-City
X-FW-Version
X-Clientip
X-Origin-Response-Time
Www
Thinkindot-Control
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-ABtesting
X-Auto-Login
X-Matched-Rule
X-Core-Value
X-Cache-URL
X-Cache-Id
X-Backend-State
X-Developers
X-Qloud-Router
X-Trace-Id
X-User
X-Thinkindot-L3
X-SIPLIST1
X-ServiceProvider
X-V
X-VServer
X-Worker
X-Nc
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-We-Are-Hiring
X-DC
X-Server-IP
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
Server-ID
X-Platform
X-Owner
X-Reboot
X-Release
X-S-Maxage
X-Response-By
X-Request-URI
X-Request-Start
X-No-Session
X-Location
Memcached
IsBot
Fastly-SIE
Country-Code
Decoy-Debug-TTL
Pramga
Origin
Decoy-Debug-Status
Heartbleed
AKAMAI
Fastly-Soc-X-Request-Id
Fastly-SWR
Frame-Options
GW-Server
Apple-News-Services-Request-Url
Apple-News-Services-Handled
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Release
Decoy-Debug-Key
RNT-Time
RNT-Machine
X-Datadome
X-Croise-Owner
X-MServer
X-Gannett-Site-Version
Backend-Name
X-Gen-Mode
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Passed-To-PostProcessResponse
X-Variation
X-Sentry-ID
X-Served-From
X-Via-NSCOPI
X-Distributor
X-Powered-By-ANYU
Uber-Trace-Id
X-Device-Os
Platform
X-Policy
On-Server
X-Phone
X-Var-Ttl
X-Fastly-Cache
Cache-Cookie-Set-Idcheck
Is-Eu
MI-Cache-Age
X-Hnp-Log
Adler-Geo
X-MI-In-Market
Esi-Enabled
Cache-Cookie-Set-From
X-LI-UUID
X-Nginx-Cache-Key
Magicmarker
X-P-T
Kp-EeAlive
Fastly-Backend-Name
X-Node-Id
X-LI-Proto
X-Li-Pop
X-Info
WZWS-RAY
MI-Cache
X-Secret
X-Instance-Name
User-Cache-Control
X-Li-Fabric
X-Passed-To
X-Passed-To-BeforeDispatch
X-Passed-To-DLL
X-Sf
Cache-Cookie-Set-Lfrom
X-Actual-URL
X-SVT-ORM-RULES
Request-EU
True-Client-Country-4JS
X-RCS-CacheZone
X-UnsetCookies
X-Returned-From-BeforeDispatch
X-Returned-From-DLL
X-VCT
X-Block-Status
X-Cache-Debug
X-Cache-Expires
Request-Country
X-Bip
X-Returned-From
X-Swa-Ws
X-Up
X-Returned-From-PostProcessResponse
X-SVT-ORM-VERSION
Server-Int
X-Request-UUID
X-Varnish-Action
Section-Io-Cache
X-Thanos
Web-Mar-Node
X-Core-Mission
X-Stale
Pragrma
Pagetype
Version
X-Oss-Storage-Class
X-WebServer
X-MSEdge-Features
X-Oss-Object-Type
X-NWS-UUID-VERIFY
X-MSEdge-Flight
X-Backend-TTL
X-Cache-CFC
X-Fstrz
CDCHOST
X-HOST
X-Crawler
X-CUA
X-Oss-Server-Time
X-SN
X-TT-LOGID
Proxy-Connection
X-NODE
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
REQUESTUUID
MIME-Version
Cteonnt-Length
HTTPS
X-Cache-Srv
RequestId
X-Cache-FS-Status
MI-API
X-Refresh
X-Page-Type
X-Req
NodeID
Group
V-Cache
X-Servername
X-Unique-Id-Primal
X-Kong-Proxy-Latency
X-Ms-Lease-State
X-Parent-Response-Time
X-Kong-Upstream-Latency
Who
ProcessTime
X-Be
X-Pjax-Url
X-Oracle-Dms-Ecid
Fusion-Source
Amp-Access-Control-Allow-Source-Origin
X-Origin-TTL
X-GZip
X-Dynatrace-Js-Agent
Fusion-Content-Source
Fusion-Template-Id
Fusion-Content-Id
Fusion-Component-Id
X-BB-IP
Memory
Cdn
CF-IPCountry
X-Ckpd-Fst-Backend
X-Servedbyhost
X-SRV
X-Time
X-Edge-Server
X-ND-Cache
X-Aicache-OS
X-Protected-By
Cdn-Request-Time
Mime-Version
Cdn-Host
X-Content-Age
SS
X-Server-Group
X-COUNTRY
X-Wa
GeoIP-Country-Code
CDN
SD-X-WS
XServer
X-Varnish-Beresp-TTL
PageType
Is-Session-Tracking
GeoIP-Latitude
X-Varnish-Url
A
Get-Access-Time
X-Origin-Date
X-Origin-Expires
X-APP
X-B3-Traceid
X-Pf-Uncompressing
X-StackifyID
PICS-Label
Geoip-Latitude
GeoIp-Country-Code
X-RateLimit-Remaining-Second
X-Unique-Id
Serverid
X-RateLimit-Limit-Second
X-Generation-Time
X-Origin-Host
X-WA
X-Fastly-Cache-Hits
X-Requestid
X-Fastly-Country-Code
X-Cache-Info
X-FireWall-Port
X-Gdpr
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-CSRF-Token
X-Ratelimit-Remaining
X-FORWARDED-FOR
X-GEO
Nel
X-PHP-Host
X-ID
X-EC-Security-Audit
Node
X-CS
X-Load-Cache
X-Nananana
Processtime
X-Vcache
X-RequestId
Cf-Ipcountry
X-Proxy-Cache-Status
X-SERVER-NAME
DataCenter
X-Proxy-Upstream
X-HS-Status
X-Server-W
NGX
Vix-Hermes-Req-Id
URI
X-Surge-Debug
X-ServedByHost
T-Server
Hostname
X-Check-Cacheable
X-Qnm-Cache
Cache-Tv-Group
X-HTML-Minification-Powered-By
X-GZIP
X-M-Log
X-M-Reqid
X-NGINX-Cache
X-UPSTREAM-Address
X-Feature
WP-Super-Cache
X-PF-Uncompressing
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
Cache-Provider
X-BACKEND-TTL
Load-Balancing
X-B3-SpanId
X-WR-MODIFICATION
X-Fastly-Backend-Reqs
Request-Time
X-DataStream-MidMile-RTT
X-DataStream-Origin-MEX-Latency
X-PJAX-URL
X-VG-WebCache
ServerName
X-Alicdn-Da-Ups-Status
X-Fe
X-BE
X-Atg-Version
Requestid
X-Skip-Cache
Https
X-ServerName
RequestUuid
Host-ID
X-ARC
X-Micro-Cache
X-IPS-LoggedIn
PFcat
X-HTML-Edge-Cache
X-Akamai-SSL-Client-Sid
X-Amz-Meta-S3b-Last-Modified
X-Debug-Cache-Store
X-Proxy-Server
X-Debug-Cache-Expiry
X-Distil-Cs
X-Debug-Cache-Fetch
X-Cache-Ttl
X-From-Cache
X-PAGE-TYPE
X-VC
N-Cache
X-SB
X-GDPR
Sid
X-Front
Cdn-Src-Port
X-Dw-Trace-Id
X-Grace-Duration
X-RAMCache
Build-Number
X-Gen-Id