Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
CF-RAY
CF-Cache-Status
Pragma
Link
X-Powered-By
ETag
Expect-CT
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Xss-Protection
X-Varnish
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
Alt-Svc
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-FRAME-OPTIONS
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Request-ID
X-Generator
Content-Security-Policy-Report-Only
X-Cache-Status
X-Cacheable
X-Permitted-Cross-Domain-Policies
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-Template
X-Language
X-AspNetMvc-Version
Status
X-Content-Security-Policy
X-Buckets
Content-Encoding
Access-Control-Expose-Headers
Upgrade
X-CDN
Xkey
Access-Control-Max-Age
Keep-Alive
X-Drupal-Dynamic-Cache
X-Kinja-Server-Push
X-Turbo-Charged-By
X-Via
X-AH-Environment
X-Cache-Group
X-Age
X-Pass-Why
X-Backend
X-Ua-Compatible
X-Envoy-Upstream-Service-Time
EagleId
X-Server
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Page-Speed
X-Pingback
X-Server-Powered-By
X-UA-Device
X-Proxy-Cache
X-Swift-SaveTime
X-Swift-CacheTime
X-Hacker
X-Nginx-Cache-Status
Ali-Swift-Global-Savetime
Request-Context
Grace
X-Varnish-Cache
Server-Timing
Feature-Policy
Cf-Railgun
X-Amz-Version-Id
X-LiteSpeed-Cache
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-WebKit-CSP
X-Rq
X-Server-Id
Report-To
EagleEye-TraceId
X-Ac
X-Response-Time
X-OneAgent-JS-Injection
X-Host
Request-Id
X-Cnection
X-Backend-Server
X-DataDome
X-Node
Content-Location
X-Origin-Cache
X-Cloud-Trace-Context
X-Ws-Request-Id
X-Readtime
X-Cache-Lookup
NEL
X-Dns-Prefetch-Control
X-Cdn
X-Vhost
X-Application-Context
X-ORACLE-DMS-ECID
X-Dispatcher
X-ORACLE-DMS-RID
X-HW
Allow
X-Clacks-Overhead
X-Rack-Cache
X-EdgeConnect-Origin-MEX-Latency
X-Origin-Upstream-Status
X-EdgeConnect-MidMile-RTT
Surrogate-Control
X-DynaTrace
Rating
X-Country
X-FTR-Request-ID
Fusion-Content-Source
Fusion-Source
Fusion-Content-Id
Fusion-Template-Id
Fusion-Component-Id
X-Akam-SW-Version
X-Country-Code
X-Goog-Hash
Pinterest-Generated-By
X-Varnish-TTL
X-Ruxit-JS-Agent
X-Instart-Request-ID
X-TtlSet
X-Vname
X-PC
Edge-Control
X-MS-InvokeApp
X-Mod-Pagespeed
X-Url
Verso
SPRequestGuid
X-Powered-By-Plesk
X-B3-TraceId
X-D2id
Pagespeed
X-Sol
X-Trace
Response
X-Middleton-Response
X-SharePointHealthScore
X-Middleton-Display
Display
X-VARITI-CCR
Service-Worker-Allowed
RTSS
X-TTL
X-Use-Magma
X-Kinja-Revision
X-Kinja-Server
X-Kinja-Build
X-Exp-Variant
X-Exp-Id
X-Cdn-Fetch
X-GoogleNews-Bot
X-Kinja
X-GitHub-Request-Id
Content-MD5
X-Server-Name
SPIisLatency
SPRequestDuration
X-Navigation-Version
X-ESI
X-Vcache
Accept-Ch
X-Powered-CMS
X-Abt-Application-Version
X-Debug
X-Amz-Server-Side-Encryption
X-Vcap-Request-Id
Charset
X-Upstream
X-Forwarded-Proto
X-CST
Public-Key-Pins
MS-Author-Via
X-Cached
X-NF-Request-ID
X-Amz-Rid
X-Version
X-Server-ID
Realpath
Edge-Cache-Tag
DynaTrace
X-Px
MicrosoftSharePointTeamServices
X-Shard
TCN
Arr-Disable-Session-Affinity
Accept-Ch-Lifetime
X-Ezoic-Cdn
X-XRDS-Location
Pinterest-Version
X-Pinterest-Rid
X-MSEdge-Ref
X-Shield-Request-Id
Fastly-Restarts
X-DynaTrace-JS-Agent
Access-Control-Request-Method
X-Ser
X-SRCache-Store-Status
X-Trafficlayer-App-Name
X-SRCache-Fetch-Status
X-Trafficlayer-App-Scope
X-Fastly-Request-ID
S
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Accel-Expires
X-Recruiting
X-DIS-Request-ID
Front-End-Https
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Generation
X-Client-IP
X-Amz-Meta-S3cmd-Attrs
Nginx-Cache
X-Id
X-T
X-Goog-Storage-Class
X-Varnish-Age
X-Element-Page-Cache
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-FTR-DC
X-FTR-Balancer
X-Country-Code-Real
X-FTR-Realm
X-FTR-Cache-Status
X-FTR-Backend
X-FTR-Backend-Server
X-FTR-Expires
X-Amzn-Trace-Id
Cache-Tag
X-Dw-Request-Base-Id
X-Webapp-Samesite-None-Activated-N
Fastcgi-Cache
X-HS-Hub-Id
X-HS-Content-Id
Accept-CH
X-HS-Cache-Config
X-Content-Digest
X-Frontend
NR-ENABLED
X-Hits
Accept-CH-Lifetime
Powered
X-Correlation-Id
X-Kinsta-Cache
X-Ttl
X-Hp-Webp
X-FTR-Cache-Host
Alternate-Protocol
X-RateLimit-Remaining
X-Fastcgi-Cache
ServerID
X-Request-Received
X-Request-Processing-Time
X-Cache-Hit
X-Grace
X-N
X-Aspnetmvc-Version
X-HS-Combine-CSS
X-Request-Handler-Origin-Region
Server-Name
X-Microsite
PB-RID
X-Node-Name
X-Webkit-Csp
PB-PID
X-Content-Type
TP-Cache
TP-L2-Cache
Arc-Version
X-Mobile-Rewrite
AMP-Access-Control-Allow-Source-Origin
X-User-Agent
X-Rid
Healthy
X-Zen-Fury
X-Analytics
Backend-Timing
X-Akamai-Edgescape
X-Revision
X-Content-Security-Policy-Report-Only
X-Logged-In
Server-Node
X-FastCGI-Cache
X-Pad
X-LB-Cache
X-Forwarded-For
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Activity-Id
X-AppVersion
X-Az
X-Mobile-URL
Cache-Status
X-Varnish-Grace
X-Cached-By
X-GUploader-UploadID
AR-ATIME
X-IPLB-Instance
AR-PoweredBy
AR-CACHE
X-NWS-LOG-UUID
X-B3-Sampled
X-Oneagent-Js-Injection
Retry-After
X-Type
X-Content-Options
Refresh
X-F-Cache
X-Geo-Country
Upgrade-Insecure-Requests
Paypal-Debug-Id
X-Ruxit-Js-Agent
X-Litespeed-Cache
Ar-Sid
X-Srv
X-App-Environment
X-Tumblr-User
X-Tumblr-Pixel
X-Instance
X-Tumblr-Pixel-0
X-PHP-Backend
Source
X-Varnish-Backend
DC
X-Request-Guid
X-Debug-Info
X-Framework
Host
Actual-Object-TTL
Access-Control-Allow-Method
Accept-Charset
X-Page-Id
X-Jobs
X-FB-Debug
X-B
X-AOL-HN
X-Cache-Key
X-Cluster
FilterID
X-Cache-Age
X-WebKit-CSP-Report-Only
X-Via-JSL
X-Seen-By
X-ATG-Version
X-Erf-Bev-Bev
X-Cache-2
X-Erf-Bev-Bev-Is-Generated
X-Esi
X-TT
Fastcgi-Useragent
X-Git-Hash
Cache
X-Content-Powered-By
MS-CV
X-Cache-TTL
VIX-Pulpo-Upstream-Status
X-PressLabs-Stats
VIX-Pulpo-Node
X-Whom
AR-Request-ID
X-UA
X-Amz-Replication-Status
X-Cache-Control
X-Signature
X-B-Cache
Host-Header
X-Wix-Request-Id
Surrogate-Key
X-Host-Name
NGB
X-Response-Served-From
X-Daa-Tunnel
X-TA-CDN-Provider
X-RequestSource
Frame-Options
X-Cache-Enabled
X-Origin-Server
X-FW-Serve
X-FW-Server
X-FW-Type
X-FW-Static
X-FW-Hash
Cache-Tv-Group
X-Mobile
X-EdgeConnect-Cache-Status
X-TX-ID
X-GeoIP
WPE-Backend
X-Tumblr-Pixel-1
Filters
X-Tumblr-Pixel-2
Eomportal-Instance
X-Region
Payment
X-Cache-Rule
X-Drupal-Cache-Tags
X-Hyper-Cache
X-Handled-By
X-Cache-Operation
X-Cache-Action
X-Cacheable-TTL
X-Adobe-Content
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Cleartype
X-Adobe-Loc
X-Cache-NE
Webserver
Xserver
X-Hostname
From-Origin
X-SERVER
X-ProcessESI
X-RemovedCookies
X-UA-Device-Type
X-Akamai-Transformed
X-Load-Cache
X-Forwarded-Host
X-NewRelic-App-Data
Datacenter
X-Cache-TTL-Remaining
X-RTag
Ms-Operation-Id
X-ATS-Timestamp
X-Edge-Location
X-Time
X-Cache-Server
Liferay-Portal
X-App-Server
X-Contextid
X-Status
X-Varnish-Hostname
X-Yottaa-Optimizations
X-B3-Traceid
X-Yottaa-Metrics
X-Varnish-Server
X-Rule
Tracecode
Country
X-BCube-Filmed-By
Odigeo-Trace-Id
X-TT-TIMESTAMP
X-URL
X-Upgrade-Enabled
X-Cache-Var-Map
Load-Balancing
X-Cache-Var
Meta-Geo
X-ES-SERVER
X-Oss-Hash-Crc64ecma
X-Path-Route
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Object-Type
X-Oss-Storage-Class
X-RN-RSRV
X-Xfnlog-Site
X-UUID
X-Viewer-Country
X-ORACLE-APMCS-REQUEST-ID
X-Debug-Cache
X-ORACLE-APMCS-TAG
TWC-Locale-Group
X-Via-Fastly
TWC-Privacy
Webcakes-App-Version
Webcakes-Region
DSUID
TWC-GeoIP-LatLong
X-VCT
Webcakes-App-Name
X-Pubstack
TWC-Connection-Speed
DB-Nickname
TWC-GeoIP-Country
Property-Id
X-OCL
X-Origin-Hint
X-CCM
X-FW-Dynamic
Cache-Tags
Mn-Server-Ip
X-PCL
TWC-Device-Class
X-Origin
X-Labrador-Cache-Channel
X-Origin-Response-Time
S-Rt
Server-Info
X-Redis-Cache
Azure-RegionName
X-Cache-Host
Azure-Version
X-Rocket-Nginx-Bypass
Azure-SlotName
X-Cache-Time
X-Cache-Config
X-Drupal-Cache-Contexts
X-EIG-Tracking-Id
X-Web-Node
Fastly-SSL
X-IP
X-From
Azure-SiteName
X-Varnish-Cache-Hits
X-R9-Blue-Green-Version
X-Akamai-Request-ID
NGX
X-Akamai-Request-ID2
Release
Azure-InstanceId
Ec-Rule-Version
Origin-Edge-Control
Origin-Cache-Control
X-Soup
X-Proxy
X-Real-IP
Decoy-Debug-TTL
L5d-Success-Class
X-Proto
X-FC-Vary-Parameters
X-Hosted-By
X-Loop
X-Format
X-TNCMS
X-Site-Version
X-Access
X-Locale
X-Rendered-As
X-Human
X-PERF
X-ApacheServer
X-Section
S-Cnection
Decoy-Debug-Status
Cache-Name
X-NWS-UUID-VERIFY
Decoy-Debug-Key
X-ServerID
X-FireWall-Port
X-Is-Bot
X-Time-Microsecs
Version
Viewport
X-Www-Served-By
X-Content-Age
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Proxy-Build
Selected-Fe
X-Timing-Wait
X-Varnish-Hits
Uber-Trace-Id
X-Storage
X-Info
X-Vgn-Hpd-Reason
X-Cluster-Name
X-Backend-Name
X-XRDS-LOCATION
X-Generated
X-BYPASS-REASON
X-ProxyCache-Key
X-ProxyCache-Status
X-JoinUs
X-RateLimit-Limit
X-VCache
X-Cache-Backend
X-Generated-By
X-Origin-TTL
X-Accel-Buffering
X-Origin-CC
X-PHP-Host
Rt-Fastcgi-Cache
X-Amzn-Remapped-Content-Length
Akamai-GRN
Cteonnt-Length
Cache-Key
Time
X-WA-Info
X-Presslabs-Stats
X-Nginx-Cache-Key
X-APP-VERSION
X-App-Version
Cache-Hits
Origin
X-No-Session
GEO-INFO
X-GoCache-CacheStatus
X-Geo
X-Guploader-Uploadid
Vix-Hermes-Req-Id
X-SaId
X-Tec-Api-Root
X-SS-Set-Cookie
X-Tec-Api-Origin
X-Environment-Context
X-L-Path
X-MServer
X-Cache-Remote
X-CF-Powered-By
X-NCache
X-Tec-Api-Version
Accept-Language
X-Unique-Id
X-Trace-Id
X-Backend-TTL
X-FB-TRIP-ID
X-CDN-Forward
X-Hit
X-Tb
Srv
Access-Control-Request-Headers
X-SayCDN-TTL
X-Say-Cacheable
X-Say-TTL
X-Tumblr-Pixel-3
X-Device-Type
X-CS
X-OVcl-Cache
X-CSRF-TOKEN
X-OVcl
X-S
X-Cache-Grace
X-B3-SpanId
User-Cache-Control
X-EC-Lua
X-Shopify-Stage
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-ShopId
ServedBy
X-Alternate-Cache-Key
X-ShardId
X-Shopify-Generated-Cart-Token
Meta-Geo-Continent
Apple-News-Services-Host
BehaviorPad-Version
Machine
Content-Script-Type
Content-Style-Type
Cross-Origin-Window-Policy
IsBot
AsisCache
Arc-Country
MD5-Digest
Fastcgi-X-Cache-Version
Mobile-Detection-Method
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Apple-News-Services-Handled
X-A-Dam
X-Rewrite-Enabled
X-Request-UUID
X-Rojux
X-S-Cookie
X-ScT
X-Region-Sid
X-Processor
X-External-Request-Id
X-G
X-Hl-Ver
X-PAYTM-SRV-ID
X-Server-Time
X-Session-Fingerprint
X-VG-WebServer
X-VG-WebCache
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-Twitter-Response-Tags
X-Trv-Group
X-SIPLIST1
X-SRCache-Key
X-Svr
X-Transaction
X-DPWN-IS-SECURE
X-Detected-As
VivaBuild
Viewtype
X-A
X-A-Ccd
X-A-Dcw
T-Server
Server-Host
Rendered-Blocks
Request-Country
Request-EU
Rt-Proxy-Cache
X-A-Dgt
X-A-Wwc
X-Connection-Hash
X-CF-Lambda-Version
X-D
X-Date
X-Destination
X-CF-Lambda-Fn
X-B-Cookie
X-Accel-Expires-Debug
X-Aed
X-AIR-PT
X-ARC
Node
X-Application
X-Cluster-Node
X-CACHE-KEY
NtCoent-Length
X-Uri
OT-Force-Account-Verify
X-Parent-Response-Time
X-Reboot
X-RateLimit-Remaining-Second
Wxu-Next-Region
Wxu-Next-Hostname
Wxu-Next-Commit
X-Webstats-RespID
X-RateLimit-Limit-Second
X-Ms-Version
X-Location
X-Level-Front-Cache
CDCHOST
X-Endurance-Cache-Level
X-Ms-Request-Id
X-WADP-Cache
Web-Mar-Node
X-Thinkindot-L3
X-Service
RNT-Time
RNT-Machine
X-Vdms-Version
Served-By
Server-Int
Thinkindot-Control
X-Request-URI
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-Ah-Environment
X-Block-Status
X-Matched-Rule
X-Cache-Info
X-Hnp-Log
X-Generated-On
X-Cms-Context
X-Clara-WADP
We-Hiring
X-CUA
X-Core-Value
X-Gen-Mode
X-Cache-Bucket
Mail-Subject
X-Dispatcher-Server
X-Dispatch
X-RCS-CacheZone
X-Via-CDN
Mime-Version
X-B3-Parentspanid
X-Dc
X-FW-Version
ServerName
X-NC
True-Client-Country-4JS
X-Scheme
X-Developers
X-Fastly-Cache
X-Skip-Cache
Section-Io-Cache
X-Generation-Time
X-Geo-Header
X-S-Maxage
X-Has-Esi
X-Compress-Hint
X-Logging-Id
X-App-Name
X-Is-Gdpr
X-Method
X-C
X-Azure-Ref
X-BBXSRF
X-Backend-State
X-Azure-Ref-OriginShield
X-Cache-Id
X-Agile-Id
X-JWT-State
W
X-Release
X-Cdn-Srv
X-Instart-Isnd
X-Agile-Age
X-Agile
X-Cache-URL
X-Reqid
X-Sucuri-Cache
X-NX-Host
Proxy-Connection
X-IN-APIGATEWAYSSL
Esi-Enabled
Fastly-Soc-X-Request-Id
X-Wikidot-Backend
IBM-Web2-Location
X-VServer
X-We-Are-Hiring
Now
X-IN-APIGATEWAY
Cache-Host
AKAMAI
X-Debug-Log
X-Debug-Cookies
Adler-Geo
X-Magnolia-Registration
X-Hash
Content-Disposition
X-Cache-Debug
Is-Eu
X-Wikidot-Static-Cache
X-VG-TLSProxy
X-User
X-SVT-ORM-VERSION
Memcached
X-Proxy-Cache-Status
X-Up
X-Proxy-Upstream
X-Variation
Magicmarker
L
Kp-EeAlive
X-SVT-ORM-RULES
Platform
X-VC-Cache
X-Source
X-SRV
X-Internal-Host
X-Distil-CS
X-Sigma
X-Eu-Site
X-Rocket-Build-Number
X-Generated-In
X-Epic-Correlation-Id
X-Via-NSCOPI
X-Origin-Expires
X-Planisys-CDN-Cache
X-Debug-Cache-Store
X-Planisys-CDN-Rules
X-Origin-Date
X-Key
X-Policy
X-Planisys-CDN-TTL
X-Irp-Debug
X-GeoIP-City
X-Auto-Login
Gh-Request-Id
Countrycode
Ha-Gx-Prefs
X-Qloud-Router
X-Owner
X-Platform-Server
X-Thanos
X-Urbn-Site-Id
X-Swa-Ws
X-Sigma-Backend
X-ServiceProvider
X-Urbn-Context-Path
X-SD-PageType
X-Server-IP
X-WebServer
X-Old-Content-Length
X-Core-Mission
X-Clientip
X-LI-UUID
X-Debug-Cache-Expiry
X-Li-Fabric
X-Li-Pop
X-CGP
X-Bip
HA-Ipaddr
X-NodeID
PFcat
X-MSEdge-Features
X-TrackingId
X-Debug-Cache-Fetch
X-MSEdge-Flight
X-Amz-Meta-Cache-Control
X-AK-Request-ID
Cdncip
X-Upstream-Ct
X-Upstream-Ht
Cdnsip
X-Varnish-Beresp-Status
Pramga
SD-X-WS
Locale
Heartbleed
X-Varnish-Beresp-Grace
X-Cache-FS-Status
X-Varnish-Beresp-Ttl
X-B3-Spanid
X-Distributor
X-UnsetCookies
Hostname
Cache-Provider
X-Nc
X-LI-Proto
X-ND-Cache
Powered-By-ChinaCache
V-Age
X-Request-Start
X-7Graus-Varnish-Cache-Control
X-7Graus-Varnish-XKeys
X-Servername
CF-IPCountry
Server-ID
X-TIME
X-Trafficlayer-App-Version
GEO-REGION-INFO
X-GRACE
X-Cdn-Forward
Environment
X-COUNTRY
X-Developer
X-Req
X-FPC
A
X-Be
Locid
X-Newrelic-Synthetics
X-Nginx-Cache
X-Sn-Servicetimems
Geo-Info
X-Device-Os
X-Sucuri-Id
X-Servedbyhost
X-Lb-Id
X-Cdn-Origin
X-Served-From
FNAC-ModuleRouting
X-Zone
X-Sucuri-ID
X-Node-Id
X-HTML-Minification-Powered-By
X-Refresh
X-Microcachable
X-Gamma-Serve
X-VHOST
X-FORWARDED-FOR
Tcn
ProcessTime
X-Webkit-CSP
X-IPS-LoggedIn
X-Tb-Optimization-Total-Bytes-Saved
X-Render-Time
Memory
X-VCL-Version
X-NU-AKA-ACS-Version
X-VWS-Id
Request-Time
X-Pf-Uncompressing
X-LJ-Flow-ID
X-AWS-Id
XServer
X-Pjax-Url
Resin-Trace
X-GeoIP-Country-Code
X-DC
X-MP-GENERATED-AT
X-Mode
Gannett-Cam-Experience-Id
CF-Cached-On
X-Edge-O15-RID
X-Correlation-ID
Amp-Access-Control-Allow-Source-Origin
X-ECACHE
Geoip-Latitude
GeoIp-Country-Code
MIME-Version
Geoip-City
Group
X-Instart-Info
PICS-Label
X-ElasticPress-Search
X-Ratelimit-Remaining
GeoIP-Country-Code
GeoIP-Latitude
Pics-Label
TTL
Cf-Ipcountry
X-Backend-Url
X-Backend-Host
X-Pod
X-Bc
X-Var-Ttl
Ttl
X-Zipkin-Id
X-Routing-Service
X-Proxied
X-NGENIX-Cache
Backend-Name
GeoIP-City
X-Via-SSL
X-Via-Edge
X-APP
Host-ID
X-CSRF-Token
X-Unique-ID
X-ZONE
Lfy
N-Cache
Cache-Cookie-Set-From
Cache-Cookie-Set-Idcheck
REQUESTUUID
Cache-Cookie-Set-Lfrom
Pagetype
Cdn
HostName
M-TraceId
X-CLOUD-TRACE-CONTEXT
Ohc-Cache-HIT
Ohc-File-Size
X-Vcl-Version
X-Check-Cacheable
X-PJAX-URL
Fly-Cache
Cache-Prefix
Fly-Request-Id
X-Fstrz
X-GEO
X-BC
HitType
X-Cdn-Request-ID
X-PF-Uncompressing
X-Via-Ucdn
X-Worker
X-Ratelimit-Limit
X-Request-Time
X-Swift-Error
X-Cache-Miss-From
X-Sedo-Request-Id
X-Fastly-Country-Code
X-TH-Server
X-NGINX-Cache
X-Dynatrace-Js-Agent
X-Server-W
Pragrma
On-Server
X-HS-Status
User-Agent
X-Aicache-OS
URI
X-Fetched-On
X-Tt-Trace-Tag
X-HostName
X-Upstream-HT
X-LiteSpeed-Cache-Control
X-Upstream-CT
Powered-By
X-ServedByHost
CDN
X-UPSTREAM-Address
Fastly-SIE
X-Cache-Tag
X-WR-MODIFICATION
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
Fastly-SWR
X-Wa
SRV
X-WA
X-BE
Media-Length
Who
AR-SID
X-SERVER-NAME
X-TT-LOGID
X-LB-ID
X-Varnish-URL
X-LAGOON
X-Tt-Trace-Host
FSS-Proxy
X-Varnish-Cacheable
FSS-Cache
X-Fpc
X-Fastly-Backend-Reqs
X-GDPR
DataCenter
X-Cf-Powered-By
Dynatrace
CACHE
X-ServerName
X-Edge-Server
Debug
Cdn-Request-Time
X-Hp-Ccpa-Warning
Server-Id
UCS
Cdn-Host
X-Ftr-Cache-Host
X-Ua
X-RateLimit-Reset
X-Cache-Tags
X-Akamai-ERPolicy
X-Flog
Is-Session-Tracking
X-ABtesting
X-Protected-By
Filterid
LB
Get-Access-Time
X-Gen-Id
SS
X-SN
X-Hello
X-Akamai-ERRuleID
X-Varnish-Beresp-TTL
WP-Super-Cache
X-Store
Processtime
X-SB
XxX-Cache-Status
NnCoection
X-VC
X-RPS
Country-Code
Cneonction
X-Nananana
Xet-Cookie
X-RPM
Application
X-DI
X-Dw-Trace-Id
X-Response-By
X-DB
X-LiteSpeed-Tag
X-DSS
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
X-DW
Thinkindot-Cache-Type
X-Li-Proto
Product
SN
X-Request-Url
X-RSL
Requestid
X-Fastly-Cache-Hits
X-Action
Warning
SID
X-Org