Threat Level: green Handler on Duty: Jim Clausing

SANS ISC: HTTP Header Usage Statistics - SANS Internet Storm Center HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
Last-Modified
X-Content-Type-Options
Accept-Ranges
Pragma
X-Powered-By
CF-RAY
Link
ETag
Expect-CT
Via
X-XSS-Protection
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Id
X-Served-By
Referrer-Policy
X-Varnish
X-Xss-Protection
X-Request-Id
X-Timer
CF-Cache-Status
X-AspNet-Version
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Runtime
X-Download-Options
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Cacheable
Alt-Svc
X-Check
X-Generator
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Cache-Status
X-AspNetMvc-Version
Status
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Template
X-Language
X-Permitted-Cross-Domain-Policies
Content-Encoding
X-Iinfo
X-FRAME-OPTIONS
X-Content-Security-Policy
X-CDN
X-Buckets
X-Turbo-Charged-By
P3p
X-Request-ID
Upgrade
X-Type
WPE-Backend
X-Pass-Why
Keep-Alive
X-AH-Environment
Xkey
X-Cache-Group
CF-Ray
X-Backend
Access-Control-Max-Age
X-Age
Access-Control-Expose-Headers
X-Via
X-Drupal-Dynamic-Cache
EagleId
X-Nginx-Cache-Status
X-Pingback
X-Amz-Id-2
X-Amz-Request-Id
X-Server-Powered-By
X-Server
X-Hacker
Grace
X-UA-Device
X-Swift-SaveTime
X-Swift-CacheTime
X-Varnish-Cache
Ali-Swift-Global-Savetime
X-Kinja-Server-Push
X-Robots-Tag
Cf-Railgun
X-Proxy-Cache
X-Envoy-Upstream-Service-Time
X-Page-Speed
X-LiteSpeed-Cache
X-Ua-Compatible
Request-Context
X-Device
X-Ac
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Content-Location
X-Cache-Lookup
X-Amz-Version-Id
X-Host
X-Response-Time
Surrogate-Control
X-OneAgent-JS-Injection
X-WebKit-CSP
X-Rq
X-Cnection
X-Node
X-Server-Id
X-Backend-Server
X-Readtime
Server-Timing
X-Rack-Cache
Report-To
Request-Id
EagleEye-TraceId
X-Application-Context
X-Cloud-Trace-Context
Feature-Policy
X-ORACLE-DMS-ECID
X-Instart-Request-ID
X-CST
X-Iejgwucgyu
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Clacks-Overhead
Edge-Control
NEL
X-Url
X-Country
Rating
X-Server-Name
X-Px
X-DataDome
X-MS-InvokeApp
X-TTL
X-Varnish-TTL
Allow
Pinterest-Generated-By
X-Country-Code
X-DynaTrace
X-Origin-Cache
X-Vhost
X-PC
X-Vname
X-TtlSet
X-Cached
X-FTR-Request-ID
X-ESI
RTSS
X-Ruxit-JS-Agent
X-Goog-Hash
Charset
SPRequestGuid
X-VARITI-CCR
X-Trace
X-Oracle-Dms-Rid
X-Powered-By-Plesk
X-Powered-CMS
X-DynaTrace-JS-Agent
Accept-CH
X-SharePointHealthScore
X-GitHub-Request-Id
X-Dispatcher
Public-Key-Pins
X-D2id
X-T
X-Mod-Pagespeed
X-Server-ID
PB-RID
X-Mobile-Rewrite
PB-PID
Arc-Version
X-F-Cache
Content-MD5
X-Exp-Id
X-GoogleNews-Bot
X-Cdn-Fetch
X-Exp-Variant
X-Kinja-Build
X-Kinja-Server
X-Kinja-Revision
X-Kinja
Verso
X-B3-TraceId
MS-Author-Via
X-Version
SPIisLatency
SPRequestDuration
X-Shield-Request-Id
X-Recruiting
X-Abt-Application-Version
X-Dns-Prefetch-Control
Nginx-Cache
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Client-IP
X-Forwarded-Proto
Accept-CH-Lifetime
X-HW
X-N
X-DIS-Request-ID
X-Navigation-Version
AR-PoweredBy
AR-CACHE
AR-ATIME
X-Upstream-Env
X-Pinterest-Rid
Pinterest-Version
X-Amz-Rid
X-B
X-Upstream
X-Dw-Request-Base-Id
X-Fastly-Request-ID
DynaTrace
X-Origin-Upstream-Status
X-SRCache-Store-Status
X-XRDS-Location
X-SRCache-Fetch-Status
X-Ser
X-Amz-Meta-S3cmd-Attrs
Fastly-Restarts
X-Hits
TCN
X-ORACLE-DMS-RID
Realpath
Paypal-Debug-Id
X-Wix-Server-Artifact-Id
X-Accel-Buffering
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Metageneration
X-Content-Options
Arr-Disable-Session-Affinity
Service-Worker-Allowed
X-NF-Request-ID
X-Pad
X-Acc-Meta-Resource-Type
X-Goog-Storage-Class
Tracecode
Access-Control-Request-Method
S
X-Id
X-Content-Digest
X-Litespeed-Cache
X-Debug
X-Varnish-Age
Front-End-Https
Mrf-Cache-Status
MRF-Tech
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
X-Vcap-Request-Id
X-MSEdge-Ref
X-Webkit-Csp
X-Oneagent-Js-Injection
X-Frontend
X-RateLimit-Remaining
X-IPLB-Instance
X-FTR-Backend-Server
X-FTR-Backend
X-PressLabs-Stats
X-FTR-Balancer
X-FTR-Expires
X-FTR-Realm
X-ATG-Version
X-FTR-DC
X-FTR-Cache-Status
X-Country-Code-Real
X-Kinsta-Cache
Edge-Cache-Tag
X-Use-Magma
X-Logged-In
Display
X-Sol
X-HS-Hub-Id
X-HS-Content-Id
X-Middleton-Display
X-Cache-Hit
Surrogate-Key
X-Amz-Cf-Pop
X-Forwarded-For
MicrosoftSharePointTeamServices
Rt-Fastcgi-Cache
Fastcgi-Cache
Powered-By-ChinaCache
X-Request-Received
X-Request-Processing-Time
X-Zen-Fury
X-Edge-Location
X-FastCGI-Cache
Ar-Sid
X-Grace
Server-Name
Backend-Timing
X-Analytics
X-Rid
X-Debug-Info
X-Amzn-Trace-Id
X-B3-TraceId-Primal
X-User-Agent
Host
X-Revision
X-FTR-Cache-Host
FilterID
TP-Cache
TP-L2-Cache
X-Middleton-Response
Response
X-Akam-SW-Version
X-CF-Powered-By
X-NewRelic-App-Data
X-HS-Cache-Config
X-Cache-Key
X-Mobile
AMP-Access-Control-Allow-Source-Origin
X-SS-Set-Cookie
X-Fastcgi-Cache
X-Drupal-Cache-Tags
X-Magnolia-Registration
X-TA-CDN-Provider
AR-Request-ID
X-Accel-Expires
Cache-Status
Refresh
X-Cached-By
Host-Header
X-Newrelic-App-Data
X-Ttl
X-SERVER
X-B3-Sampled
ServerID
X-Varnish-Backend
X-Node-Name
X-AOL-HN
X-GUploader-UploadID
X-Content-Security-Policy-Report-Only
X-Tumblr-User
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Instance
X-B-Cache
X-Webkit-CSP
X-Cache-Control
X-Whom
X-Signature
X-Akamai-Edgescape
X-Platform-Server
X-FB-Debug
Eomportal-Instance
X-Cache-2
X-BCube-Filmed-By
X-App-Environment
X-Cluster
X-Framework
X-Page-Id
X-Device-Type
X-NWS-LOG-UUID
X-LB-Cache
Cache-Tag
X-Varnish-Hostname
X-Generated-By
X-Srv
X-Handled-By
Cleartype
X-Request-Guid
X-Cache-Rule
X-Az
X-Activity-Id
DC
X-Drupal-Cache-Contexts
Liferay-Portal
X-AppVersion
X-Ruxit-Js-Agent
X-VCache
X-Cache-Action
X-Via-JSL
X-WPE-Loopback-Upstream-Addr
X-App-Server
X-Cache-Server
Source
Public-Key-Pins-Report-Only
X-Content-Powered-By
Alternate-Protocol
Retry-After
MS-CV
X-Hostname
X-HS-Combine-CSS
X-Seen-By
X-Varnish-Grace
X-Amz-Replication-Status
X-TT
X-Wix-Request-Id
X-App-Version
X-WA-Info
X-Geo-Country
ViewerVersion
X-Geo-Segment
Accept-Charset
X-CACHE-GROUP
X-Varnish-Server
Server-Node
X-Correlation-Id
X-Esi
HostName
X-Daa-Tunnel
Webserver
Upgrade-Insecure-Requests
X-Response-Served-From
X-Tumblr-Pixel-2
X-Cache-NE
AsisCache
X-Tumblr-Pixel-1
X-WebKit-CSP-Report-Only
SRV
X-GeoIP
X-Amz-Apigw-Id
X-Locale
X-Amzn-RequestId
Pagespeed
X-RequestSource
Actual-Object-TTL
GEO-INFO
X-URL
ServedBy
X-Jobs
X-S
X-Servedby
Payment
X-Edge-Cache
Viewport
X-Contextid
X-FW-Serve
X-FW-Hash
X-FW-Server
X-FW-Type
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Edge-Cache-Key
X-FW-Static
X-Varnish-Hits
X-UUID
X-Status
X-TX-ID
AR-SID
X-Varnish-IP
X-Adobe-Content
X-Correlation-ID
X-Adobe-Loc
Cache
X-Origin-Server
X-TT-TIMESTAMP
X-Cacheable-TTL
X-Vg-Webcache
X-Cache-TTL-Remaining
S-Cnection
X-Cache-Age
X-Hyper-Cache
X-Forwarded-Host
X-Amz-Server-Side-Encryption
X-Cache-Operation
Server-Info
X-RateLimit-Limit
X-Region
Served-By
Datacenter
X-Sucuri-ID
X-Akamai-Request-ID2
X-Mode
X-XRDS-LOCATION
CACHE
Access-Control-Allow-Method
Country
X-Real-IP
From-Origin
Healthy
X-CLOUD-TRACE-CONTEXT
X-Ezoic-Cdn
X-TIME
X-DataStream-Cache-Status
X-Content-Type
X-Rule
X-Routing-Service
X-RN-RSRV
X-Generated
X-Cache-Var
X-Rendered-As
X-Cache-Var-Map
X-Environment-Context
X-Proxied
Meta-Geo
Machine
X-Zipkin-Id
X-Cache-Config
X-L-Path
X-Is-Bot
X-Proxy
X-Detected-As
X-Path-Route
X-Ocache
X-Site-Version
Fastcgi-X-Cache-Version
X-Cache-Category-Id
X-Section
X-Upgrade-Enabled
X-Viewer-Country
X-Human
X-Birta-Served
X-Format
X-Request-Time
X-Grey
X-EIG-Tracking-Id
X-Akamai-Transformed
X-CDN-Cache
L5d-Success-Class
Fastcgi-X-Cache
X-JoinUs
Now
X-Birta-Cache-Post
X-Amz-Meta-Surrogate-Control
X-Access
Fastcgi-Useragent
DB-Nickname
Webcakes-Region
Webcakes-App-Version
Webcakes-App-Name
X-Agile
X-Agile-Age
X-CCM
X-Agile-Id
TWC-Privacy
TWC-Locale-Group
S-Rt
Property-Id
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-LatLong
TWC-GeoIP-Country
X-FC-Vary-Parameters
X-Hit
X-ServerID
X-PCL
X-Tb
X-TNCMS
X-Via-CDN
X-Via-Fastly
X-Pc-Hit
X-Pc-Appver
X-Labrador-Cache-Channel
X-Hosted-By
X-Loop
X-Microcachable
X-Origin-Hint
X-OCL
Cache-Name
X-Pc-Key
HitInfo
HitType
X-ProxyCache-Status
X-Xfnlog-Site
X-SplitTest
X-ProxyCache-Key
X-Web-Node
X-Pubstack
X-RemovedCookies
X-LJ-Flow-ID
X-Upstream-CT
X-Upstream-HT
X-VWS-Id
X-VG-TLSProxy
X-ProcessESI
X-AWS-Id
X-Cluster-Node
Azure-InstanceId
X-OVcl
X-Original-Request
X-IP
X-Origin
Azure-RegionName
Azure-SiteName
Accept-Language
X-BYPASS-REASON
OT-Force-Account-Verify
X-OVcl-Cache
Azure-Version
Azure-SlotName
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Proxy-Build
X-NGENIX-Cache
X-Alternate-Cache-Key
X-Sorting-Hat-ShopId
X-ShardId
X-ShopId
X-Www-Served-By
Mn-Server-Ip
LB
X-Timing-Wait
Selected-FE
Xserver
X-Cdn
X-Guploader-Uploadid
Origin-Cache-Control
Origin-Edge-Control
X-App-Name
X-Rocket-Nginx-Bypass
X-TWH-CORRELATION-ID
X-Transaction
X-Twitter-Response-Tags
X-Connection-Hash
X-Cache-Enabled
Ms-Operation-Id
X-UA
X-RTag
NGB
X-Source
Content-Script-Type
Content-Style-Type
X-GRACE
IBM-Web2-Location
Access-Control-Request-Headers
X-Real-Ip
X-Geo
X-Unique-ID
Filters
Time
Cache-Hits
X-NodeID
X-Origin-CC
X-Cache-Remote
X-Internal-Host
X-NCache
NtCoent-Length
X-Port
X-Pc-Date
X-Pc-Host
X-Cdn-Forward
PageSpeed
X-Cache-TTL
X-Ms-Version
X-Ms-Request-Id
X-Ms-Lease-Status
X-Ms-Blob-Type
X-Tumblr-Pixel-3
X-MP-GENERATED-AT
X-Distil-CS
X-Nginx-Cache
We-Hiring
Mail-Subject
X-Edge-IP
X-Proto
X-APP-VERSION
X-UA-Device-Type
Backend
X-Debug-Cache
X-Varnish-Cacheable
X-CACHE-KEY
X-Vgn-Hpd-Reason
X-Storage
X-Time-Microsecs
X-PHP-Backend
X-Csrf-Token
Cache-Tags
X-Webstats-RespID
X-Backend-Name
X-Akamai-Request-ID
X-Ratelimit-Limit
X-Varnish-Cache-Hits
Locale
X-Dc
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Ua
X-Varnish-Beresp-Grace
X-Endurance-Cache-Level
X-Varnish-Beresp-Status
Warning
X-Sucuri-Cache
User-Agent
X-ApacheServer
X-PERF
X-Mshield-Cache-Status
X-Mrs-Cache-Hits
X-ElasticPress-Search
X-Mrs-Cache
X-B3-Spanid
Fastly-SSL
X-Mrs-Age
X-C
X-Redis-Cache
X-EdgeConnect-Cache-Status
HA-Urlpath
HA-Servedtime
X-B-Cookie
HA-Ipaddr
X-A
VivaBuild
Odigeo-Trace-Id
SN
X-Org
HA-Host
TSSecure
Meta-Geo-Continent
Arc-Country
Viewtype
V-Age
X-Backend-Host
Mobile-Detection-Method
X-PAYTM-SRV-ID
Cache-Prefix
BehaviorPad-Version
UCS
Content-Disposition
Server-Host
X-Accel-Expires-Debug
X-A-Wwc
X-Aed
Ajk
Powered-By
FSS-Proxy
X-A-Dgt
X-A-Dcw
Fly-Request-Id
Fly-Cache
X-A-Ccd
X-NX-Host
FSS-Cache
X-A-Dam
X-Amz-Meta-Cache-Control
GMS-Ver
HA-Georegion
HA-Geolon
Ec-Rule-Version
Rt-Proxy-Cache
Ha-Gx-Prefs
Rendered-Blocks
X-Application
HA-Geolat
X-NU-AKA-ACS-Version
HA-Cloudapp
Resin-Trace
HA-Geocity
HA-Geocountry
X-Region-Sid
X-CF-Lambda-Fn
X-Debug-Log
X-IN-WAF
X-Destination
X-Developer
X-G
X-Generated-In
X-Debug-Cookies
X-Date
X-Sn-Servicetimems
X-D
X-SRCache-Key
Xc-Version
X-Hash
X-Died
X-Nc
X-F5-Cache
X-External-Request-Id
X-Irp-Debug
Cache-Key
X-Croise-Owner
X-Eu-Site
X-DPWN-IS-SECURE
X-Via-Edge
X-Via-SSL
X-VG-WebServer
X-From
X-Trv-Group
MD5-Digest
X-Store
X-Cache-Bucket
X-Logtrace-Id
X-Cache-Host
X-BBXSRF
X-Rewrite-Enabled
X-ScT
X-S-Cookie
X-Rojux
X-IN-SSL-APIGATEWAY
X-Cdn-Origin
X-Cache-Backend
X-CGP
X-Server-Time
X-Server-By
X-IN-APIGATEWAY
X-Backend-Url
X-BB-ID
X-CF-Lambda-Version
X-NC
X-Origin-Response-Time
X-CACHE-AGE
Origin
Memcached
X-Flog
X-Dispatcher-Server
X-Backend-State
X-Key
Pramga
X-Owner
X-Layer
X-Fetched-On
Release
Thinkindot-CacheControl-Type
X-Matched-Rule
Thinkindot-CacheControl
X-Cache-Id
Thinkindot-Control
X-ABtesting
Www
X-Core-Value
X-Clientip
X-Hello
X-No-Session
X-GeoIP-City
X-Location
X-FW-Version
X-Developers
RNT-Machine
X-Hl-Ver
RNT-Time
X-GeoIP-Country-Code
X-Auto-Login
X-Response-By
X-Thinkindot-L3
X-CDN-Forward
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-Worker
X-UE-Client-Country
Decoy-Debug-Key
X-UnsetCookies
Countrycode
Country-Code
Apple-News-Services-Handled
AKAMAI
X-Wikidot-Static-Cache
X-ServiceProvider
X-Request-Start
X-Request-URI
X-Server-IP
X-Reboot
X-Rebelmouse-Surrogate-Control
X-SIPLIST1
X-Platform
X-Qloud-Router
X-Rebelmouse-Cache-Control
Decoy-Debug-Status
X-Trace-Id
Heartbleed
X-Var-Ttl
GW-Server
X-VServer
Fastly-SWR
X-We-Are-Hiring
Fastly-SIE
X-User
Decoy-Debug-TTL
X-Wikidot-Backend
IsBot
X-V
Fastly-Soc-X-Request-Id
X-Varnish-Beresp-Ttl
X-Newrelic-Synthetics
X-Epic-Correlation-Id
X-Li-Pop
X-WebServer
X-Fastly-Cache
X-Gen-Mode
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Info
X-Dynatrace-Js-Agent
X-LI-UUID
X-MServer
X-Secret
X-LI-Proto
X-Cache-URL
X-Served-From
X-Sentry-ID
X-Core-Mission
X-Distributor
X-SVT-ORM-VERSION
X-Instance-Name
X-SVT-ORM-RULES
X-VCT
X-Varnish-Action
X-Swa-Ws
X-Device-Os
X-Cache-Expires
X-Stale
X-Gannett-Site-Version
X-Crawler
X-Sf
X-Li-Fabric
X-CUA
X-Up
X-Variation
X-Thanos
X-Release
Esi-Enabled
Section-Io-Cache
Fastly-Backend-Name
X-Node-Id
Request-EU
Server-ID
Server-Int
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
X-Passed-To-PostProcessResponse
X-Nginx-Cache-Key
Request-Country
Frame-Options
MI-Cache-Age
Is-Eu
MI-Cache
Kp-EeAlive
X-P-T
X-Passed-To
On-Server
X-Passed-To-DLL
Pragrma
X-Passed-To-BeforeDispatch
Platform
True-Client-Country-4JS
Cache-Cookie-Set-From
X-Request-UUID
X-Returned-From
X-Via-NSCOPI
Magicmarker
X-MI-In-Market
X-Returned-From-BeforeDispatch
X-Returned-From-DLL
X-S-Maxage
X-Returned-From-PostProcessResponse
X-Block-Status
X-Bip
X-Hnp-Log
X-Actual-URL
Web-Mar-Node
User-Cache-Control
Backend-Name
Uber-Trace-Id
WZWS-RAY
Adler-Geo
X-RCS-CacheZone
X-Powered-By-ANYU
X-Policy
X-Phone
X-Cache-Debug
Version
X-Datadome
X-NWS-UUID-VERIFY
X-MSEdge-Flight
X-MSEdge-Features
X-TT-LOGID
Proxy-Connection
Pagetype
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
REQUESTUUID
CDCHOST
X-Oss-Request-Id
X-Cache-CFC
X-Fstrz
X-Oss-Storage-Class
X-Oss-Server-Time
X-DC
X-Refresh
X-Cache-FS-Status
RequestId
Amp-Access-Control-Allow-Source-Origin
X-NODE
X-Backend-TTL
HTTPS
X-HOST
MI-API
X-SN
X-Page-Type
X-Pjax-Url
V-Cache
X-Req
X-Unique-Id-Primal
MIME-Version
X-Parent-Response-Time
Group
X-Kong-Proxy-Latency
X-Be
X-Kong-Upstream-Latency
X-Cache-Srv
Who
X-Ms-Lease-State
Cteonnt-Length
X-Servername
NodeID
X-Origin-TTL
X-GZip
Fusion-Source
X-Oracle-Dms-Ecid
Fusion-Template-Id
Fusion-Content-Source
Memory
ProcessTime
Fusion-Content-Id
Fusion-Component-Id
Cdn
X-BB-IP
X-Time
Mime-Version
X-Edge-Server
X-Ckpd-Fst-Backend
Cdn-Host
X-Protected-By
SS
X-Servedbyhost
CF-IPCountry
Cdn-Request-Time
X-Content-Age
X-Aicache-OS
X-ND-Cache
X-Server-Group
X-Wa
X-COUNTRY
SD-X-WS
GeoIP-Country-Code
X-Varnish-Beresp-TTL
CDN
PageType
XServer
X-APP
A
GeoIP-Latitude
X-SRV
X-Origin-Expires
X-Origin-Date
Get-Access-Time
Is-Session-Tracking
X-Varnish-Url
Geoip-Latitude
X-Pf-Uncompressing
X-B3-Traceid
X-Origin-Host
VIX-Pulpo-Upstream-Status
GeoIp-Country-Code
VIX-Pulpo-Node
X-RateLimit-Limit-Second
PICS-Label
X-Generation-Time
X-Cache-Info
Serverid
X-RateLimit-Remaining-Second
X-Unique-Id
X-WA
X-Gdpr
X-Fastly-Country-Code
X-FireWall-Port
X-Fastly-Cache-Hits
X-StackifyID
X-Requestid
X-CSRF-Token
X-Ratelimit-Remaining
Processtime
X-PHP-Host
Node
X-Nananana
Nel
X-GEO
DataCenter
Cf-Ipcountry
X-EC-Security-Audit
X-CS
X-ID
X-Load-Cache
X-Proxy-Cache-Status
X-Proxy-Upstream
Hostname
X-Check-Cacheable
Vix-Hermes-Req-Id
X-Vcache
X-HS-Status
X-RequestId
X-ServedByHost
X-SERVER-NAME
X-NGINX-Cache
Cache-Tv-Group
T-Server
X-Server-W
URI
NGX
X-Surge-Debug
X-FORWARDED-FOR
WP-Super-Cache
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
Cache-Provider
X-Planisys-CDN-TTL
X-GZIP
X-BACKEND-TTL
X-UPSTREAM-Address
X-Feature
X-M-Reqid
X-M-Log
X-Qnm-Cache
X-HTML-Minification-Powered-By
X-WR-MODIFICATION
X-PF-Uncompressing
Request-Time
X-HTML-Edge-Cache
X-B3-SpanId
Load-Balancing
X-DataStream-Origin-MEX-Latency
Host-ID
PFcat
X-Fastly-Backend-Reqs
X-ServerName
X-DataStream-MidMile-RTT
X-VG-WebCache
X-Micro-Cache
X-Alicdn-Da-Ups-Status
ServerName
X-Fe
X-BE
X-Amz-Meta-S3b-Last-Modified
X-Atg-Version
X-ARC
X-Debug-Cache-Expiry
X-IPS-LoggedIn
X-Front
Https
Requestid
X-Skip-Cache
X-PJAX-URL
X-Debug-Cache-Fetch
X-Debug-Cache-Store
RequestUuid
X-Akamai-SSL-Client-Sid
X-GDPR
X-PAGE-TYPE
X-Svr
X-VarnPar1
X-VC
X-Cache-Ttl
N-Cache
X-Proxy-Server
WebServer
X-SB
X-PARISIEN-Cache-Rendered
X-VarnCache
X-From-Cache
X-Distil-Cs
X-Instart-Info
X-Swift-Error
X-Gen-Id
X-RAMCache
X-Grace-Duration
X-Dw-Trace-Id
Cdn-Src-Port
Build-Number
SID