Threat Level: green Handler on Duty: Jim Clausing

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
Last-Modified
X-Content-Type-Options
Accept-Ranges
Pragma
X-Powered-By
CF-RAY
Link
ETag
Expect-CT
Via
X-XSS-Protection
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Id
X-Served-By
Referrer-Policy
X-Varnish
X-Xss-Protection
X-Request-Id
X-Timer
CF-Cache-Status
X-AspNet-Version
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Runtime
X-Download-Options
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Cacheable
Alt-Svc
X-Check
X-Generator
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Cache-Status
X-AspNetMvc-Version
Status
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Template
X-Language
X-Permitted-Cross-Domain-Policies
Content-Encoding
X-Iinfo
X-FRAME-OPTIONS
X-Content-Security-Policy
X-CDN
X-Buckets
X-Turbo-Charged-By
X-Request-ID
Upgrade
X-Type
WPE-Backend
X-Pass-Why
Keep-Alive
X-AH-Environment
Xkey
X-Cache-Group
CF-Ray
X-Backend
Access-Control-Max-Age
P3p
X-Age
Access-Control-Expose-Headers
X-Via
X-Drupal-Dynamic-Cache
EagleId
X-Nginx-Cache-Status
X-Pingback
X-Amz-Request-Id
X-Amz-Id-2
X-Server-Powered-By
X-Server
X-Hacker
Grace
X-UA-Device
X-Swift-CacheTime
X-Swift-SaveTime
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-Kinja-Server-Push
X-Robots-Tag
Cf-Railgun
X-Proxy-Cache
X-Envoy-Upstream-Service-Time
X-LiteSpeed-Cache
X-Page-Speed
X-Ua-Compatible
Request-Context
X-Device
X-Ac
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Content-Location
X-Cache-Lookup
X-Amz-Version-Id
X-Host
X-Response-Time
Surrogate-Control
X-OneAgent-JS-Injection
X-WebKit-CSP
X-Rq
X-Cnection
X-Node
X-Backend-Server
X-Server-Id
X-Readtime
Server-Timing
X-Rack-Cache
Report-To
Request-Id
EagleEye-TraceId
X-Application-Context
X-Cloud-Trace-Context
Feature-Policy
X-ORACLE-DMS-ECID
X-Instart-Request-ID
X-CST
X-Iejgwucgyu
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Clacks-Overhead
Edge-Control
NEL
X-Url
Rating
X-Country
X-Server-Name
X-Px
X-DataDome
X-TTL
X-Varnish-TTL
X-MS-InvokeApp
Allow
Pinterest-Generated-By
X-Country-Code
X-DynaTrace
X-Origin-Cache
X-Vhost
X-Vname
X-PC
X-TtlSet
X-Cached
X-FTR-Request-ID
X-ESI
RTSS
X-Ruxit-JS-Agent
X-Goog-Hash
Charset
SPRequestGuid
X-VARITI-CCR
X-Trace
X-Oracle-Dms-Rid
X-Powered-By-Plesk
X-Powered-CMS
X-DynaTrace-JS-Agent
Accept-CH
X-SharePointHealthScore
X-GitHub-Request-Id
X-Dispatcher
Public-Key-Pins
X-D2id
X-T
X-Mod-Pagespeed
X-Server-ID
Arc-Version
X-Mobile-Rewrite
PB-PID
PB-RID
X-F-Cache
Content-MD5
Verso
X-Exp-Variant
X-Cdn-Fetch
X-Exp-Id
X-GoogleNews-Bot
X-Kinja
X-Kinja-Build
X-Kinja-Revision
X-Kinja-Server
X-B3-TraceId
MS-Author-Via
X-Version
SPRequestDuration
SPIisLatency
X-Shield-Request-Id
X-Recruiting
X-Abt-Application-Version
X-Dns-Prefetch-Control
Nginx-Cache
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Client-IP
X-Forwarded-Proto
X-HW
Accept-CH-Lifetime
X-N
X-DIS-Request-ID
X-Navigation-Version
AR-PoweredBy
AR-CACHE
AR-ATIME
X-Upstream-Env
X-Pinterest-Rid
Pinterest-Version
X-Amz-Rid
X-B
X-Upstream
X-Dw-Request-Base-Id
X-Fastly-Request-ID
X-Origin-Upstream-Status
DynaTrace
X-SRCache-Fetch-Status
X-XRDS-Location
X-SRCache-Store-Status
X-Ser
X-Amz-Meta-S3cmd-Attrs
Fastly-Restarts
X-Hits
TCN
Realpath
X-ORACLE-DMS-RID
Paypal-Debug-Id
X-Wix-Server-Artifact-Id
X-Accel-Buffering
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Content-Options
Arr-Disable-Session-Affinity
Service-Worker-Allowed
X-NF-Request-ID
X-Pad
X-Acc-Meta-Resource-Type
X-Goog-Storage-Class
Tracecode
Access-Control-Request-Method
S
X-Id
X-Content-Digest
X-Debug
X-Varnish-Age
Front-End-Https
MRF-Tech
Mrf-Cache-Status
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
X-Vcap-Request-Id
X-MSEdge-Ref
X-Oneagent-Js-Injection
X-Webkit-Csp
X-RateLimit-Remaining
X-Frontend
X-ATG-Version
X-IPLB-Instance
X-PressLabs-Stats
X-FTR-DC
X-FTR-Backend
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-Realm
X-FTR-Expires
X-Kinsta-Cache
Edge-Cache-Tag
X-Use-Magma
X-Logged-In
X-HS-Hub-Id
X-HS-Content-Id
X-Middleton-Display
Display
X-Sol
X-Cache-Hit
Surrogate-Key
X-Amz-Cf-Pop
MicrosoftSharePointTeamServices
X-Forwarded-For
Rt-Fastcgi-Cache
Fastcgi-Cache
X-Request-Received
X-Request-Processing-Time
Powered-By-ChinaCache
X-Edge-Location
X-Zen-Fury
X-FastCGI-Cache
X-Grace
Ar-Sid
Server-Name
X-Analytics
Backend-Timing
X-Amzn-Trace-Id
X-B3-TraceId-Primal
X-Rid
X-Debug-Info
Host
X-User-Agent
X-Revision
TP-L2-Cache
TP-Cache
X-FTR-Cache-Host
FilterID
Response
X-Middleton-Response
X-CF-Powered-By
X-Akam-SW-Version
X-Litespeed-Cache
X-NewRelic-App-Data
X-HS-Cache-Config
X-Mobile
X-Cache-Key
AMP-Access-Control-Allow-Source-Origin
X-Fastcgi-Cache
X-SS-Set-Cookie
X-Drupal-Cache-Tags
AR-Request-ID
X-TA-CDN-Provider
X-Magnolia-Registration
Cache-Status
X-Accel-Expires
Refresh
X-Cached-By
Host-Header
X-SERVER
X-Ttl
X-Newrelic-App-Data
X-B3-Sampled
ServerID
X-AOL-HN
X-Varnish-Backend
X-GUploader-UploadID
X-Node-Name
X-Content-Security-Policy-Report-Only
X-Cluster
X-Tumblr-Pixel
X-FB-Debug
X-Instance
X-Tumblr-Pixel-0
X-Tumblr-User
X-B-Cache
X-Webkit-CSP
X-Akamai-Edgescape
X-Cache-2
Eomportal-Instance
X-Whom
X-Cache-Control
X-Signature
X-Platform-Server
X-LB-Cache
X-Page-Id
X-Varnish-Hostname
X-Framework
X-NWS-LOG-UUID
X-BCube-Filmed-By
X-App-Environment
X-Device-Type
Cache-Tag
X-Generated-By
X-Srv
Cleartype
X-Handled-By
X-Request-Guid
X-Cache-Rule
X-Activity-Id
X-AppVersion
X-Az
DC
Liferay-Portal
X-Drupal-Cache-Contexts
X-Ruxit-Js-Agent
X-VCache
X-Cache-Action
X-Via-JSL
X-WPE-Loopback-Upstream-Addr
X-App-Server
X-Cache-Server
Source
Public-Key-Pins-Report-Only
X-Content-Powered-By
Retry-After
Alternate-Protocol
MS-CV
X-Hostname
X-HS-Combine-CSS
X-Amz-Replication-Status
X-Seen-By
X-TT
X-Varnish-Grace
HostName
X-Wix-Request-Id
X-App-Version
Accept-Charset
ViewerVersion
X-WA-Info
X-Geo-Segment
X-CACHE-GROUP
X-Varnish-Server
X-Geo-Country
Server-Node
X-Correlation-Id
X-Esi
Webserver
X-Daa-Tunnel
Upgrade-Insecure-Requests
AsisCache
X-Response-Served-From
X-Cache-NE
X-Tumblr-Pixel-1
X-Tumblr-Pixel-2
X-WebKit-CSP-Report-Only
X-Locale
Pagespeed
Actual-Object-TTL
X-Amz-Apigw-Id
X-Amzn-RequestId
X-GeoIP
SRV
X-URL
GEO-INFO
X-RequestSource
X-Varnish-Hits
X-Jobs
ServedBy
X-S
X-Servedby
X-FW-Serve
X-Contextid
X-FW-Server
X-FW-Hash
Payment
X-UUID
X-Yottaa-Metrics
Viewport
X-FW-Static
X-Edge-Cache-Key
X-Edge-Cache
X-FW-Type
X-Yottaa-Optimizations
X-Status
X-Varnish-IP
AR-SID
X-TX-ID
X-Adobe-Loc
X-Correlation-ID
X-Adobe-Content
Cache
X-Cacheable-TTL
X-Origin-Server
X-TT-TIMESTAMP
X-Vg-Webcache
X-Cache-TTL-Remaining
S-Cnection
X-Hyper-Cache
X-Cache-Age
X-Forwarded-Host
X-Amz-Server-Side-Encryption
X-Cache-Operation
Server-Info
X-RateLimit-Limit
Served-By
Datacenter
X-Region
X-Sucuri-ID
X-Mode
X-XRDS-LOCATION
X-Akamai-Request-ID2
X-Real-IP
CACHE
Access-Control-Allow-Method
Country
X-TIME
From-Origin
X-CLOUD-TRACE-CONTEXT
Healthy
X-Ezoic-Cdn
X-DataStream-Cache-Status
X-Content-Type
Fastcgi-X-Cache
X-Environment-Context
X-Zipkin-Id
X-Proxied
X-Generated
X-Rendered-As
X-JoinUs
X-Proxy
X-L-Path
X-Cache-Var
Meta-Geo
Machine
X-Rule
X-Is-Bot
X-Upgrade-Enabled
X-Site-Version
X-Cache-Config
X-Routing-Service
Fastcgi-X-Cache-Version
X-Detected-As
X-RN-RSRV
X-Ocache
X-Cache-Var-Map
X-Path-Route
X-Birta-Cache-Post
X-Grey
X-Hosted-By
X-Human
X-Section
X-CDN-Cache
X-Request-Time
X-NGENIX-Cache
X-Format
X-EIG-Tracking-Id
X-Viewer-Country
X-Cache-Category-Id
X-Access
Now
L5d-Success-Class
X-Agile
X-Agile-Age
X-Birta-Served
X-Amz-Meta-Surrogate-Control
X-Agile-Id
Fastcgi-Useragent
DB-Nickname
X-Akamai-Transformed
X-Tb
X-Origin-Hint
X-CCM
X-TNCMS
Webcakes-App-Version
X-Via-Fastly
Webcakes-Region
X-Pc-Appver
Property-Id
Cache-Name
TWC-Device-Class
TWC-Connection-Speed
S-Rt
OT-Force-Account-Verify
X-ServerID
TWC-GeoIP-Country
TWC-Privacy
TWC-Locale-Group
TWC-GeoIP-LatLong
X-OCL
Webcakes-App-Name
X-Loop
X-PCL
X-Hit
X-Pc-Key
X-Labrador-Cache-Channel
X-Pc-Hit
X-FC-Vary-Parameters
X-Microcachable
X-Via-CDN
X-Original-Request
X-OVcl-Cache
X-AWS-Id
HitType
X-Pubstack
X-IP
X-OVcl
X-RemovedCookies
Accept-Language
X-LJ-Flow-ID
HitInfo
Azure-Version
X-ProcessESI
X-Cluster-Node
X-Upstream-CT
X-Upstream-HT
X-Web-Node
X-Origin
X-VG-TLSProxy
X-Xfnlog-Site
X-ProxyCache-Key
Azure-SlotName
X-ProxyCache-Status
X-SplitTest
Azure-SiteName
Azure-RegionName
X-BYPASS-REASON
Azure-InstanceId
X-VWS-Id
X-Alternate-Cache-Key
X-Proxy-Build
Selected-FE
X-Sorting-Hat-ShopId
X-ShopId
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Timing-Wait
X-ShardId
X-Www-Served-By
Mn-Server-Ip
LB
Origin-Edge-Control
Origin-Cache-Control
Xserver
X-Guploader-Uploadid
X-Cdn
X-Rocket-Nginx-Bypass
X-App-Name
X-RTag
X-Cache-Enabled
X-Twitter-Response-Tags
X-Connection-Hash
Ms-Operation-Id
X-UA
X-TWH-CORRELATION-ID
X-Transaction
Content-Style-Type
X-Source
Content-Script-Type
NGB
X-GRACE
X-Unique-ID
X-Geo
X-Real-Ip
IBM-Web2-Location
Access-Control-Request-Headers
X-NodeID
Filters
Cache-Hits
Time
X-Origin-CC
X-Cache-Remote
X-Internal-Host
X-Port
X-Pc-Date
X-NCache
X-Pc-Host
NtCoent-Length
X-Tumblr-Pixel-3
X-Ms-Request-Id
X-Ms-Lease-Status
PageSpeed
X-Ms-Blob-Type
X-Ms-Version
X-Cache-TTL
X-Cdn-Forward
X-MP-GENERATED-AT
We-Hiring
X-Nginx-Cache
X-Edge-IP
X-Proto
Mail-Subject
X-Distil-CS
X-APP-VERSION
X-UA-Device-Type
Backend
X-Storage
X-Debug-Cache
X-CACHE-KEY
X-Varnish-Cacheable
X-Vgn-Hpd-Reason
X-Time-Microsecs
X-PHP-Backend
X-Csrf-Token
X-Webstats-RespID
X-Backend-Name
Cache-Tags
X-Akamai-Request-ID
X-Ratelimit-Limit
Locale
X-Varnish-Cache-Hits
X-Urbn-Site-Id
X-Urbn-Context-Path
X-Endurance-Cache-Level
X-Varnish-Beresp-Status
X-Ua
X-Varnish-Beresp-Grace
User-Agent
Warning
X-EdgeConnect-Cache-Status
X-Sucuri-Cache
X-PERF
X-ApacheServer
Fastly-SSL
X-B3-Spanid
X-Mrs-Cache
X-Mrs-Cache-Hits
X-Mrs-Age
X-Mshield-Cache-Status
X-ElasticPress-Search
X-C
X-Redis-Cache
X-Dc
X-Date
Server-Host
UCS
X-D
V-Age
SN
X-Developer
TSSecure
X-Via-SSL
X-DPWN-IS-SECURE
X-A
X-A-Ccd
Content-Disposition
X-Died
VivaBuild
Rt-Proxy-Cache
X-Via-Edge
Viewtype
Xc-Version
Resin-Trace
HA-Geocity
HA-Cloudapp
HA-Geocountry
HA-Geolat
HA-Geolon
GMS-Ver
FSS-Proxy
Ec-Rule-Version
Fly-Cache
Fly-Request-Id
FSS-Cache
HA-Georegion
Ha-Gx-Prefs
Odigeo-Trace-Id
Mobile-Detection-Method
Powered-By
X-Debug-Log
X-A-Dam
Meta-Geo-Continent
MD5-Digest
HA-Host
HA-Ipaddr
HA-Servedtime
HA-Urlpath
X-Destination
X-VG-WebServer
X-Hash
X-CF-Lambda-Version
X-Org
X-NX-Host
X-Backend-Host
X-GeoIP-Country-Code
X-PAYTM-SRV-ID
X-G
X-B-Cookie
X-Region-Sid
X-Generated-In
X-NU-AKA-ACS-Version
X-Logtrace-Id
X-Cache-Host
X-Cdn-Origin
X-Irp-Debug
X-CF-Lambda-Fn
X-Cache-Bucket
X-BBXSRF
X-IN-APIGATEWAY
X-IN-SSL-APIGATEWAY
X-Backend-Url
X-BB-ID
X-Rewrite-Enabled
X-Application
X-External-Request-Id
X-CGP
X-Aed
X-Trv-Group
X-Store
X-Accel-Expires-Debug
X-Eu-Site
X-IN-WAF
X-UE-Client-Country
X-A-Dgt
X-A-Wwc
X-SRCache-Key
X-Sn-Servicetimems
X-Debug-Cookies
X-Rojux
X-Fetched-On
X-From
X-Amz-Meta-Cache-Control
X-S-Cookie
X-Server-Time
X-Server-By
X-ScT
X-F5-Cache
X-A-Dcw
Rendered-Blocks
X-Cache-Backend
Cache-Prefix
BehaviorPad-Version
Arc-Country
Ajk
Cache-Key
X-Croise-Owner
X-Nc
X-Origin-Response-Time
X-CACHE-AGE
X-NC
Origin
X-Matched-Rule
RNT-Machine
RNT-Time
Server-ID
X-Request-URI
X-Response-By
X-Developers
X-Request-Start
X-Cache-URL
Release
X-S-Maxage
Pramga
X-Cache-Id
X-Release
X-FW-Version
X-GeoIP-City
X-Hello
Thinkindot-CacheControl
X-Backend-State
Www
X-Layer
X-Owner
X-ABtesting
X-Location
X-Auto-Login
X-No-Session
X-Key
X-Platform
X-Hl-Ver
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Server-IP
Thinkindot-CacheControl-Type
X-Qloud-Router
Thinkindot-Control
X-Reboot
X-Varnish-Beresp-Ttl
X-Var-Ttl
X-Core-Value
X-Dispatcher-Server
Frame-Options
GW-Server
X-ServiceProvider
Apple-News-Services-Handled
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
X-Wikidot-Backend
Fastly-SWR
Decoy-Debug-Key
Countrycode
Country-Code
X-We-Are-Hiring
Decoy-Debug-Status
Decoy-Debug-TTL
Fastly-Soc-X-Request-Id
Fastly-SIE
X-VServer
AKAMAI
Apple-News-Services-Request-Url
X-Wikidot-Static-Cache
Memcached
X-V
X-CDN-Forward
X-Worker
X-Flog
X-SIPLIST1
X-Clientip
X-Epic-Correlation-Id
X-Trace-Id
Heartbleed
X-UnsetCookies
X-User
IsBot
X-Thinkindot-L3
X-Newrelic-Synthetics
X-LI-UUID
X-Gannett-Site-Version
X-Instance-Name
X-WebServer
X-Distributor
X-Hnp-Log
X-Fastly-Cache
X-Li-Pop
X-Li-Fabric
X-Info
X-LI-Proto
X-Gen-Mode
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Request-UUID
X-Sf
X-Stale
X-Served-From
X-Sentry-ID
X-MServer
X-Secret
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Varnish-Action
X-VCT
X-Variation
X-Up
X-Swa-Ws
X-Thanos
X-Returned-From-PostProcessResponse
X-Returned-From-DLL
X-Passed-To-BeforeDispatch
X-Passed-To-DLL
X-Passed-To
X-P-T
X-Nginx-Cache-Key
X-Node-Id
X-Passed-To-PostProcessResponse
X-Via-NSCOPI
X-Returned-From
X-Returned-From-BeforeDispatch
X-RCS-CacheZone
X-Powered-By-ANYU
X-Phone
X-Policy
X-MI-In-Market
X-Device-Os
Server-Int
True-Client-Country-4JS
Section-Io-Cache
Request-EU
X-DC
Request-Country
Uber-Trace-Id
User-Cache-Control
X-Block-Status
X-Cache-Debug
X-Bip
X-Actual-URL
WZWS-RAY
Pragrma
Platform
Cache-Cookie-Set-From
Backend-Name
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
Esi-Enabled
Fastly-Backend-Name
Adler-Geo
Is-Eu
MI-Cache-Age
On-Server
MI-Cache
Magicmarker
Kp-EeAlive
X-Cache-Expires
Web-Mar-Node
X-Dynatrace-Js-Agent
X-Core-Mission
X-CUA
X-Crawler
X-NWS-UUID-VERIFY
X-Datadome
Version
Pagetype
X-MSEdge-Features
X-MSEdge-Flight
CDCHOST
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
X-Oss-Object-Type
X-TT-LOGID
X-Oss-Server-Time
Proxy-Connection
X-Oss-Storage-Class
REQUESTUUID
X-Fstrz
X-Cache-CFC
X-Page-Type
X-Refresh
Amp-Access-Control-Allow-Source-Origin
RequestId
X-Cache-FS-Status
X-Backend-TTL
X-SN
MI-API
HTTPS
X-NODE
X-HOST
X-Req
X-Cache-Srv
Group
X-Be
X-Pjax-Url
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
MIME-Version
X-Parent-Response-Time
V-Cache
X-Unique-Id-Primal
Cteonnt-Length
Who
X-Servername
NodeID
X-Ms-Lease-State
X-GZip
Fusion-Source
X-Origin-TTL
X-Oracle-Dms-Ecid
ProcessTime
Memory
Fusion-Template-Id
Fusion-Component-Id
Fusion-Content-Source
Fusion-Content-Id
Cdn
X-BB-IP
X-Time
Mime-Version
X-Edge-Server
X-Protected-By
CF-IPCountry
X-Ckpd-Fst-Backend
X-Servedbyhost
Cdn-Host
Cdn-Request-Time
SS
X-Content-Age
X-Aicache-OS
X-ND-Cache
X-Server-Group
X-COUNTRY
X-Wa
SD-X-WS
X-Varnish-Beresp-TTL
CDN
GeoIP-Country-Code
PageType
XServer
X-APP
GeoIP-Latitude
X-SRV
A
Is-Session-Tracking
Get-Access-Time
X-Varnish-Url
X-Origin-Expires
X-Origin-Date
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-B3-Traceid
GeoIp-Country-Code
X-Pf-Uncompressing
X-Origin-Host
Geoip-Latitude
X-RateLimit-Remaining-Second
X-Generation-Time
X-RateLimit-Limit-Second
X-Fastly-Country-Code
X-Cache-Info
X-Unique-Id
PICS-Label
Serverid
X-WA
X-StackifyID
X-Requestid
X-FireWall-Port
X-Fastly-Cache-Hits
X-Gdpr
Processtime
X-Ratelimit-Remaining
X-CSRF-Token
DataCenter
X-PHP-Host
Node
X-GEO
Nel
X-Nananana
X-Proxy-Cache-Status
Cf-Ipcountry
X-Load-Cache
X-CS
X-ID
X-EC-Security-Audit
X-Proxy-Upstream
X-Vcache
Vix-Hermes-Req-Id
X-Check-Cacheable
X-RequestId
X-HS-Status
X-SERVER-NAME
X-ServedByHost
X-NGINX-Cache
Cache-Tv-Group
URI
X-Surge-Debug
T-Server
X-Server-W
NGX
X-FORWARDED-FOR
WP-Super-Cache
Hostname
X-Qnm-Cache
X-Feature
X-Planisys-CDN-Rules
X-BACKEND-TTL
X-WR-MODIFICATION
X-Planisys-CDN-Cache
X-HTML-Minification-Powered-By
Cache-Provider
X-M-Log
X-Planisys-CDN-TTL
X-UPSTREAM-Address
X-GZIP
X-M-Reqid
Request-Time
X-HTML-Edge-Cache
X-Fastly-Backend-Reqs
X-PF-Uncompressing
Load-Balancing
X-B3-SpanId
PFcat
X-Micro-Cache
ServerName
Host-ID
X-DataStream-MidMile-RTT
X-DataStream-Origin-MEX-Latency
X-BE
X-Fe
X-Alicdn-Da-Ups-Status
X-ServerName
X-VG-WebCache
X-Amz-Meta-S3b-Last-Modified
X-Atg-Version
X-Front
X-ARC
X-Debug-Cache-Expiry
X-Skip-Cache
X-Debug-Cache-Fetch
X-Debug-Cache-Store
Https
X-PJAX-URL
RequestUuid
X-IPS-LoggedIn
Requestid
X-Akamai-SSL-Client-Sid
X-Distil-Cs
X-VarnPar1
X-VarnCache
X-PARISIEN-Cache-Rendered
X-GDPR
WebServer
X-Svr
X-PAGE-TYPE
X-Proxy-Server
X-Cache-Ttl
N-Cache
X-From-Cache
X-SB
X-VC
X-Instart-Info
X-RAMCache
X-Swift-Error
Cdn-Src-Port
X-Grace-Duration
X-Gen-Id
SID
X-Dw-Trace-Id
Build-Number