Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
CF-Cache-Status
Pragma
Link
CF-RAY
X-Powered-By
ETag
Expect-CT
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Xss-Protection
X-Varnish
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
Alt-Svc
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-FRAME-OPTIONS
X-Drupal-Cache
X-Adblock-Key
X-Request-ID
X-Check
X-Generator
Content-Security-Policy-Report-Only
X-Cache-Status
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-Template
X-Language
X-AspNetMvc-Version
Status
X-Content-Security-Policy
X-Buckets
Content-Encoding
Access-Control-Expose-Headers
X-CDN
Upgrade
Xkey
Access-Control-Max-Age
Keep-Alive
X-Drupal-Dynamic-Cache
X-Kinja-Server-Push
CF-Ray
X-Turbo-Charged-By
X-AH-Environment
X-Via
X-Age
X-Ua-Compatible
X-Cache-Group
X-Pass-Why
X-Backend
X-Envoy-Upstream-Service-Time
EagleId
X-Server
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Page-Speed
X-Server-Powered-By
X-Pingback
X-UA-Device
X-Proxy-Cache
X-Swift-SaveTime
X-Swift-CacheTime
X-Hacker
X-Nginx-Cache-Status
Ali-Swift-Global-Savetime
Request-Context
X-Varnish-Cache
Grace
Server-Timing
Feature-Policy
Cf-Railgun
X-Amz-Version-Id
X-LiteSpeed-Cache
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
X-Rq
X-Server-Id
Report-To
X-WebKit-CSP
EagleEye-TraceId
X-Response-Time
X-Ac
X-Host
X-OneAgent-JS-Injection
Request-Id
X-Ws-Request-Id
X-Cnection
X-Backend-Server
X-Node
X-DataDome
Content-Location
X-Origin-Cache
X-Cache-Lookup
X-Dns-Prefetch-Control
X-Cloud-Trace-Context
NEL
X-Readtime
X-Vhost
P3p
X-Application-Context
X-HW
X-Dispatcher
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Cdn
Allow
X-Clacks-Overhead
X-Rack-Cache
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Surrogate-Control
X-Origin-Upstream-Status
X-DynaTrace
Rating
X-Country
Fusion-Component-Id
Fusion-Content-Id
Fusion-Source
Fusion-Content-Source
Fusion-Template-Id
X-FTR-Request-ID
X-Akam-SW-Version
X-Country-Code
X-Goog-Hash
X-Instart-Request-ID
Pinterest-Generated-By
Edge-Control
X-Ruxit-JS-Agent
X-Vname
X-TtlSet
X-PC
X-Varnish-TTL
X-Mod-Pagespeed
X-MS-InvokeApp
X-Url
Verso
X-B3-TraceId
SPRequestGuid
X-Powered-By-Plesk
X-D2id
X-ESI
Accept-Ch
X-Trace
X-VARITI-CCR
X-SharePointHealthScore
X-Server-Name
Response
X-Middleton-Response
X-Sol
Pagespeed
X-GitHub-Request-Id
Service-Worker-Allowed
Display
X-Middleton-Display
X-Use-Magma
X-Kinja
X-GoogleNews-Bot
X-Kinja-Revision
Content-MD5
X-Exp-Id
X-Cdn-Fetch
X-Kinja-Server
X-Exp-Variant
X-Kinja-Build
RTSS
X-TTL
X-Navigation-Version
SPRequestDuration
SPIisLatency
X-Powered-CMS
X-Abt-Application-Version
X-Vcache
X-Debug
X-Amz-Server-Side-Encryption
X-Upstream
X-Forwarded-Proto
Charset
Public-Key-Pins
X-Vcap-Request-Id
X-Cached
MS-Author-Via
X-CST
DynaTrace
Accept-Ch-Lifetime
X-NF-Request-ID
X-Version
X-Amz-Rid
Realpath
Edge-Cache-Tag
X-Px
MicrosoftSharePointTeamServices
X-Shard
X-DynaTrace-JS-Agent
Arr-Disable-Session-Affinity
TCN
X-Ezoic-Cdn
X-Trafficlayer-App-Scope
X-Trafficlayer-App-Name
X-Shield-Request-Id
Access-Control-Request-Method
X-MSEdge-Ref
X-Pinterest-Rid
Pinterest-Version
X-Server-ID
X-Ser
X-SRCache-Fetch-Status
X-Fastly-Request-ID
X-SRCache-Store-Status
S
Fastly-Restarts
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Accel-Expires
X-DIS-Request-ID
X-XRDS-Location
X-Client-IP
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Metageneration
Front-End-Https
X-Recruiting
X-Amz-Meta-S3cmd-Attrs
X-Aspnet-Version
X-Goog-Storage-Class
X-T
X-Id
X-Element-Page-Cache
X-Varnish-Age
Nginx-Cache
X-Webapp-Samesite-None-Activated-N
X-FTR-Realm
X-FTR-DC
X-FTR-Backend
X-Country-Code-Real
Cache-Tag
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-Backend-Server
MRF-Tech
X-B3-TraceId-Primal
X-Mrf-Section-Lastmod
Mrf-Cache-Status
X-Mrf-Item-Lastmod
X-Amzn-Trace-Id
X-FTR-Expires
X-Dw-Request-Base-Id
X-Fastcgi-Cache
Fastcgi-Cache
X-HS-Content-Id
X-HS-Cache-Config
X-Frontend
X-HS-Hub-Id
X-Content-Digest
NR-ENABLED
Powered
X-Ttl
X-Hits
X-Correlation-Id
X-Kinsta-Cache
X-Hp-Webp
Alternate-Protocol
X-FTR-Cache-Host
X-Aspnetmvc-Version
X-Webkit-Csp
X-Request-Received
X-Request-Processing-Time
ServerID
X-N
Server-Name
X-HS-Combine-CSS
X-Content-Type
X-Request-Handler-Origin-Region
X-Microsite
X-Cache-Hit
X-Grace
PB-RID
Accept-CH
PB-PID
Arc-Version
X-Mobile-Rewrite
Accept-CH-Lifetime
TP-L2-Cache
X-Rid
TP-Cache
X-User-Agent
X-Node-Name
Healthy
X-Revision
X-Akamai-Edgescape
X-RateLimit-Remaining
X-Analytics
X-Content-Security-Policy-Report-Only
Backend-Timing
X-Forwarded-For
X-Zen-Fury
AMP-Access-Control-Allow-Source-Origin
X-Logged-In
X-Pad
X-LB-Cache
Server-Node
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Mobile-URL
X-Activity-Id
X-Az
X-AppVersion
X-Varnish-Grace
X-Oneagent-Js-Injection
Cache-Status
X-NWS-LOG-UUID
X-Cached-By
X-B3-Sampled
X-IPLB-Instance
X-Content-Options
X-F-Cache
Refresh
X-Ruxit-Js-Agent
Retry-After
X-Geo-Country
X-Type
Upgrade-Insecure-Requests
X-GUploader-UploadID
X-FastCGI-Cache
X-Varnish-Backend
FilterID
X-Tumblr-Pixel-0
X-Tumblr-User
Paypal-Debug-Id
X-App-Environment
X-Srv
X-Tumblr-Pixel
AR-CACHE
AR-PoweredBy
AR-ATIME
X-FB-Debug
X-Instance
Source
DC
Access-Control-Allow-Method
X-Cluster
X-Framework
X-Debug-Info
X-PHP-Backend
Actual-Object-TTL
Accept-Charset
Host
X-Page-Id
X-Request-Guid
X-Jobs
X-WebKit-CSP-Report-Only
X-AOL-HN
X-B
X-Cache-2
X-ATG-Version
X-Cache-Key
X-Erf-Bev-Bev-Is-Generated
X-Cache-Age
X-Erf-Bev-Bev
Cache
X-TT
X-Seen-By
Fastcgi-Useragent
Ar-Sid
MS-CV
X-Git-Hash
X-Via-JSL
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Content-Powered-By
X-Cache-TTL
X-PressLabs-Stats
X-B-Cache
X-Amz-Replication-Status
X-Whom
X-Signature
Host-Header
X-Daa-Tunnel
X-UA
X-Cache-Control
X-Wix-Request-Id
X-Cache-Enabled
X-Response-Served-From
Surrogate-Key
NGB
X-Origin-Server
X-Host-Name
X-Mobile
X-RequestSource
X-TA-CDN-Provider
X-GeoIP
Cache-Tv-Group
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
WPE-Backend
AR-Request-ID
Payment
X-Region
X-Hyper-Cache
Cleartype
X-Handled-By
X-TX-ID
Frame-Options
Eomportal-Instance
Filters
X-Cacheable-TTL
X-FW-Type
Xserver
X-EdgeConnect-Cache-Status
X-Cache-Action
X-FW-Hash
X-FW-Serve
X-FW-Server
X-FW-Static
X-Drupal-Cache-Tags
X-Litespeed-Cache
X-SERVER
X-Cache-NE
X-Adobe-Loc
X-Adobe-Content
X-ATS-Timestamp
Webserver
X-Kong-Proxy-Latency
X-Esi
X-Cache-Operation
Datacenter
X-Cache-Rule
X-Kong-Upstream-Latency
X-Hostname
From-Origin
X-Load-Cache
X-NewRelic-App-Data
X-Akamai-Transformed
X-ProcessESI
X-RemovedCookies
X-UA-Device-Type
X-Edge-Location
X-Cache-TTL-Remaining
X-RTag
Ms-Operation-Id
X-Forwarded-Host
Liferay-Portal
X-Cache-Server
X-XRDS-LOCATION
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Varnish-Hostname
X-Status
X-Varnish-Server
X-Rule
X-Oss-Storage-Class
X-App-Server
X-Oss-Server-Time
X-Contextid
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Oss-Request-Id
X-ORACLE-APMCS-REQUEST-ID
X-ORACLE-APMCS-TAG
Odigeo-Trace-Id
Country
X-Upgrade-Enabled
X-Cache-Var
Meta-Geo
X-UUID
X-Path-Route
X-RN-RSRV
Load-Balancing
X-TT-TIMESTAMP
X-BCube-Filmed-By
X-ES-SERVER
X-Cache-Var-Map
DSUID
X-Time
X-Xfnlog-Site
X-OCL
Cache-Tags
Mn-Server-Ip
Property-Id
X-Origin-Hint
X-Debug-Cache
X-Viewer-Country
X-R9-Blue-Green-Version
X-Pubstack
Release
TWC-Connection-Speed
Webcakes-App-Name
Webcakes-App-Version
Webcakes-Region
TWC-Privacy
TWC-Locale-Group
TWC-Device-Class
TWC-GeoIP-Country
TWC-GeoIP-LatLong
X-Rocket-Nginx-Bypass
X-PCL
X-From
X-CCM
X-VCT
X-Cache-Config
X-EIG-Tracking-Id
Azure-Version
X-Goog-Meta-Goog-Reserved-File-Mtime
Azure-SlotName
Azure-SiteName
X-Timing-Wait
X-FC-Vary-Parameters
X-Origin-Response-Time
Azure-RegionName
Cache-Name
X-IP
S-Rt
Selected-Fe
X-Human
X-Hosted-By
Tracecode
NGX
DB-Nickname
L5d-Success-Class
X-Drupal-Cache-Contexts
X-Cache-Host
X-Loop
Azure-InstanceId
X-Akamai-Request-ID2
X-Proxy
X-Real-IP
X-Web-Node
X-Redis-Cache
X-Soup
X-Proto
X-Proxy-Build
X-Via-Fastly
X-Akamai-Request-ID
X-Vgn-Hpd-Reason
X-TNCMS
X-Section
X-Site-Version
Viewport
X-NWS-UUID-VERIFY
X-Origin
X-Cache-Time
X-Format
S-Cnection
X-Access
X-FW-Dynamic
Decoy-Debug-TTL
Server-Info
Origin-Edge-Control
X-Www-Served-By
X-Generated
X-ServerID
X-Backend-Name
X-Labrador-Cache-Channel
Fastly-SSL
X-FireWall-Port
X-Varnish-Cache-Hits
Ec-Rule-Version
Origin-Cache-Control
Decoy-Debug-Status
X-Locale
Decoy-Debug-Key
X-Time-Microsecs
X-BYPASS-REASON
X-Cluster-Name
X-PERF
X-Content-Age
Version
Uber-Trace-Id
X-ProxyCache-Status
X-ProxyCache-Key
X-Is-Bot
X-Rendered-As
X-ApacheServer
X-JoinUs
X-Storage
X-VCache
X-Varnish-Hits
X-Cache-Backend
X-Generated-By
X-Accel-Buffering
X-Info
X-Guploader-Uploadid
X-PHP-Host
X-B3-Traceid
X-Amzn-Remapped-Content-Length
X-URL
X-Origin-TTL
X-Origin-CC
Akamai-GRN
Rt-Fastcgi-Cache
X-Geo
X-Presslabs-Stats
X-SaId
X-WA-Info
X-Nginx-Cache-Key
X-Webkit-CSP
X-CF-Powered-By
GEO-INFO
Cache-Key
Time
Cteonnt-Length
X-App-Version
X-No-Session
X-MServer
Origin
X-Tec-Api-Root
X-L-Path
X-Tec-Api-Version
X-Environment-Context
X-Tec-Api-Origin
X-Unique-Id
X-RateLimit-Limit
X-Cache-Remote
Cache-Hits
X-GoCache-CacheStatus
X-Tb
Accept-Language
Vix-Hermes-Req-Id
X-FB-TRIP-ID
Access-Control-Request-Headers
X-APP-VERSION
X-NCache
X-SayCDN-TTL
X-Say-Cacheable
X-Trace-Id
X-Say-TTL
X-Hit
X-Backend-TTL
X-SS-Set-Cookie
X-Device-Type
X-Alternate-Cache-Key
X-CS
X-EC-Lua
X-ShardId
Srv
X-B3-SpanId
X-Sorting-Hat-ShopId
X-ShopId
X-Shopify-Stage
X-Tumblr-Pixel-3
X-Shopify-Generated-Cart-Token
X-Sorting-Hat-PodId
X-CDN-Forward
X-CACHE-KEY
X-Dc
X-OVcl-Cache
X-OVcl
User-Cache-Control
X-RCS-CacheZone
X-TIME
X-S
X-Parent-Response-Time
NtCoent-Length
X-Source
X-Cluster-Node
ServedBy
AsisCache
BehaviorPad-Version
Arc-Country
Content-Style-Type
T-Server
Viewtype
X-Processor
X-Hl-Ver
Content-Script-Type
X-Region-Sid
X-CF-Lambda-Fn
Xc-Version
Request-Country
Rendered-Blocks
X-Ah-Environment
Apple-News-Services-Request-Url
X-Transaction
Rt-Proxy-Cache
X-VG-WebServer
X-VG-WebCache
X-Application
X-Vdms-Version
X-Vtex-Processado-Em
X-AIR-PT
Request-EU
X-PAYTM-SRV-ID
X-Vtex-Remote-Cache
OT-Force-Account-Verify
X-Connection-Hash
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Handled
Server-Host
X-Twitter-Response-Tags
X-CF-Lambda-Version
X-Date
X-Svr
X-A
X-SRCache-Key
X-B-Cookie
X-Destination
Mobile-Detection-Method
Meta-Geo-Continent
X-A-Ccd
X-A-Dam
Machine
X-A-Wwc
MD5-Digest
X-D
X-Accel-Expires-Debug
X-A-Dcw
X-A-Dgt
Cross-Origin-Window-Policy
X-Detected-As
X-Rojux
X-S-Cookie
X-G
Fastcgi-X-Cache-Version
X-Rewrite-Enabled
X-ARC
VivaBuild
X-Request-UUID
X-Session-Fingerprint
X-External-Request-Id
X-Aed
Mime-Version
X-Server-Time
X-Service
Node
X-ScT
X-DPWN-IS-SECURE
X-Trv-Group
X-Magnolia-Registration
X-Endurance-Cache-Level
X-CSRF-TOKEN
ServerName
X-Cache-Grace
X-Generated-On
X-Reboot
X-SIPLIST1
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Hnp-Log
CDCHOST
Thinkindot-CacheControl-Type
X-Hash
Thinkindot-Control
Proxy-Connection
X-Debug-Log
X-Dispatch
Wxu-Next-Commit
Wxu-Next-Hostname
X-Upstream-Ct
X-Debug-Cookies
X-Gen-Mode
Web-Mar-Node
IsBot
X-Upstream-Ht
Wxu-Next-Region
X-IN-APIGATEWAY
X-NX-Host
X-Level-Front-Cache
X-Core-Value
X-Proxy-Upstream
X-Location
X-Via-NSCOPI
X-Cache-Bucket
X-Ms-Request-Id
X-Ms-Version
X-Matched-Rule
X-Webstats-RespID
X-Cache-Info
X-Thinkindot-L3
Thinkindot-CacheControl
X-Proxy-Cache-Status
X-IN-APIGATEWAYSSL
X-Block-Status
X-CUA
X-Instart-Isnd
Served-By
X-SRV
X-Uri
Now
X-Azure-Ref-OriginShield
X-Compress-Hint
X-Cdn-Srv
X-BBXSRF
X-Azure-Ref
X-Bip
X-C
X-Cache-Debug
X-Auto-Login
X-Backend-State
X-Clientip
X-Clara-WADP
X-CGP
X-B3-Parentspanid
X-Cms-Context
X-Logging-Id
X-Sigma
X-Server-IP
X-Sigma-Backend
X-Skip-Cache
X-Sucuri-Cache
X-Scheme
X-Rocket-Build-Number
X-Dispatcher-Server
X-Qloud-Router
X-Release
X-Wikidot-Static-Cache
X-Reqid
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-User
X-Up
X-VC-Cache
X-VServer
X-VG-TLSProxy
X-WADP-Cache
X-We-Are-Hiring
X-Swa-Ws
X-Thanos
X-Wikidot-Backend
X-TrackingId
X-Request-URI
X-ND-Cache
X-Generated-In
X-FW-Version
X-Generation-Time
X-Geo-Header
X-GeoIP-City
X-Fastly-Cache
X-Eu-Site
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Developers
X-Distil-CS
X-Has-Esi
X-Irp-Debug
X-Planisys-CDN-Cache
X-App-Name
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Policy
X-Origin-Expires
X-Origin-Date
X-Is-Gdpr
X-JWT-State
X-Key
X-Method
X-Debug-Cache-Expiry
X-Cache-URL
IBM-Web2-Location
Heartbleed
HA-Ipaddr
Ha-Gx-Prefs
Kp-EeAlive
L
PFcat
Memcached
Magicmarker
Gh-Request-Id
Esi-Enabled
X-Varnish-Beresp-Status
X-Varnish-Beresp-Ttl
We-Hiring
Mail-Subject
X-Varnish-Beresp-Grace
AKAMAI
Countrycode
Content-Disposition
Cache-Host
Pramga
Fastly-Soc-X-Request-Id
RNT-Machine
W
Server-Int
X-Agile-Id
RNT-Time
Section-Io-Cache
X-Agile
X-Agile-Age
X-Nc
X-Via-CDN
Cache-Provider
X-Amz-Meta-Cache-Control
X-Cache-FS-Status
SD-X-WS
Adler-Geo
Is-Eu
Platform
Cdnsip
X-Internal-Host
X-MSEdge-Flight
X-ServiceProvider
X-NodeID
X-MSEdge-Features
X-Urbn-Context-Path
X-Cache-Id
X-AK-Request-ID
X-Urbn-Site-Id
Cdncip
True-Client-Country-4JS
X-Core-Mission
X-SD-PageType
X-Li-Pop
X-Variation
X-LI-UUID
X-Old-Content-Length
X-Request-Start
X-S-Maxage
X-Platform-Server
X-Owner
X-WebServer
Locale
X-Li-Fabric
X-Distributor
X-Epic-Correlation-Id
X-Cdn-Forward
X-NC
X-Trafficlayer-App-Version
V-Age
X-LI-Proto
Server-ID
X-B3-Spanid
Powered-By-ChinaCache
X-Servername
Hostname
X-UnsetCookies
Environment
X-GRACE
X-Req
FNAC-ModuleRouting
Locid
X-Be
X-Served-From
GEO-REGION-INFO
X-7Graus-Varnish-Cache-Control
X-Lb-Id
X-7Graus-Varnish-XKeys
CF-IPCountry
X-HTML-Minification-Powered-By
X-Nginx-Cache
X-Gamma-Serve
X-Refresh
X-Newrelic-Synthetics
X-FPC
X-Sucuri-Id
A
X-Developer
X-VHOST
X-Ratelimit-Remaining
X-Zone
Tcn
X-Servedbyhost
Geo-Info
X-Sucuri-ID
X-Cdn-Origin
X-Device-Os
X-Render-Time
X-Microcachable
X-Edge-O15-RID
ProcessTime
X-Sn-Servicetimems
X-IPS-LoggedIn
X-Tb-Optimization-Total-Bytes-Saved
X-NU-AKA-ACS-Version
X-Node-Id
X-Mode
X-Pjax-Url
X-GeoIP-Country-Code
X-MP-GENERATED-AT
X-FORWARDED-FOR
X-LJ-Flow-ID
X-VWS-Id
X-AWS-Id
X-Pf-Uncompressing
Request-Time
Memory
Gannett-Cam-Experience-Id
X-COUNTRY
X-Correlation-ID
X-Proxied
X-VCL-Version
X-Routing-Service
X-Zipkin-Id
Amp-Access-Control-Allow-Source-Origin
Resin-Trace
Cf-Ipcountry
TTL
Geoip-Latitude
X-DC
GeoIp-Country-Code
CF-Cached-On
XServer
X-CSRF-Token
Group
PICS-Label
Pics-Label
X-Bc
X-Pod
X-Instart-Info
Cache-Cookie-Set-From
X-ECACHE
Geoip-City
X-ElasticPress-Search
M-TraceId
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
X-Via-Edge
X-Via-SSL
GeoIP-Latitude
GeoIP-Country-Code
X-ZONE
GeoIP-City
MIME-Version
X-Ratelimit-Limit
X-Unique-ID
X-Backend-Host
HostName
Cdn
X-Vcl-Version
X-Var-Ttl
Host-ID
X-Backend-Url
X-CLOUD-TRACE-CONTEXT
X-APP
X-Request-Time
Backend-Name
Ttl
X-Cdn-Request-ID
X-NGENIX-Cache
X-Swift-Error
X-Check-Cacheable
X-PF-Uncompressing
Ohc-File-Size
Pagetype
X-BC
X-TH-Server
HitType
REQUESTUUID
Ohc-Cache-HIT
Lfy
N-Cache
X-Fstrz
Cache-Prefix
X-NGINX-Cache
Fly-Cache
X-PJAX-URL
Fly-Request-Id
URI
X-UPSTREAM-Address
Powered-By
X-ServedByHost
X-Via-Ucdn
User-Agent
SRV
X-Fastly-Country-Code
On-Server
X-Worker
X-Varnish-Ttl
X-HostName
Media-Length
X-Tt-Trace-Tag
X-Cache-Miss-From
CDN
X-Sedo-Request-Id
X-WR-MODIFICATION
X-Cache-Tag
Pragrma
X-LiteSpeed-Cache-Control
X-WA
X-GEO
X-Fetched-On
X-HS-Status
X-Server-W
X-Aicache-OS
Who
AR-SID
Fastly-SIE
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
Fastly-SWR
X-Tt-Trace-Host
X-BE
X-Wa
X-Upstream-CT
X-Upstream-HT
X-Hp-Ccpa-Warning
FSS-Cache
FSS-Proxy
X-Fpc
X-Varnish-URL
X-LB-ID
X-LAGOON
UCS
X-Dynatrace-Js-Agent
X-Varnish-Cacheable
X-Cf-Powered-By
Processtime
Debug
X-Fastly-Backend-Reqs
X-Cache-Tags
X-Store
X-NYM-Debug-Backend
X-ServerName
X-TT-LOGID
X-Ftr-Cache-Host
X-Ua
Server-Id
X-Akamai-ERPolicy
X-Akamai-ERRuleID
Server-Cache-Control
X-Protected-By
X-GDPR
Country-Code
X-Varnish-Beresp-TTL
Server-Surrogate-Control
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Varnish-Authentication
DataCenter
X-BACKEND-TTL
X-VC
X-SB
X-Apw-Access-Token
X-Apw-Hits
Xet-Cookie
WP-Super-Cache
X-Amzn-Remapped-Date
Location
X-Apw-Access-Object
X-Amzn-Remapped-Connection
X-Apw-Access-Action
XxX-Cache-Status
X-Gen-Id
SID
Cdn-Host
X-SN
X-Fastly-Cache-Hits
Product
Application
Cdn-Request-Time
NnCoection
Thinkindot-Cache-Type
Cneonction
X-Request-Url
X-Li-Proto
X-Edge-Server
X-Nananana
X-Dw-Trace-Id