Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
CF-Cache-Status
Pragma
Link
X-Powered-By
ETag
CF-RAY
Expect-CT
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Xss-Protection
X-Varnish
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
Alt-Svc
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-FRAME-OPTIONS
X-Drupal-Cache
X-Request-ID
X-Adblock-Key
X-Check
X-Generator
Content-Security-Policy-Report-Only
X-Cache-Status
CF-Ray
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-Template
X-Language
X-AspNetMvc-Version
Status
X-Content-Security-Policy
X-Buckets
Content-Encoding
Access-Control-Expose-Headers
X-CDN
Upgrade
Xkey
Access-Control-Max-Age
Keep-Alive
X-Drupal-Dynamic-Cache
X-Kinja-Server-Push
X-Turbo-Charged-By
X-AH-Environment
X-Via
X-Age
X-Cache-Group
X-Pass-Why
X-Backend
X-Ua-Compatible
X-Envoy-Upstream-Service-Time
EagleId
X-Server
X-Robots-Tag
X-Amz-Request-Id
X-Amz-Id-2
X-Page-Speed
X-Pingback
X-Server-Powered-By
X-UA-Device
X-Proxy-Cache
X-Swift-CacheTime
X-Swift-SaveTime
X-Hacker
X-Nginx-Cache-Status
Ali-Swift-Global-Savetime
Request-Context
X-Varnish-Cache
Grace
Server-Timing
Feature-Policy
Cf-Railgun
X-Amz-Version-Id
X-LiteSpeed-Cache
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-WebKit-CSP
X-Rq
Report-To
X-Server-Id
EagleEye-TraceId
X-Ac
X-Response-Time
X-Host
X-OneAgent-JS-Injection
Request-Id
X-Cnection
X-Backend-Server
X-Node
X-DataDome
X-Ws-Request-Id
Content-Location
X-Origin-Cache
X-Cache-Lookup
X-Cloud-Trace-Context
X-Readtime
NEL
X-Dns-Prefetch-Control
X-Vhost
X-Application-Context
X-Dispatcher
X-ORACLE-DMS-ECID
X-HW
X-ORACLE-DMS-RID
P3p
X-Cdn
Allow
X-Clacks-Overhead
X-Rack-Cache
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Origin-Upstream-Status
Surrogate-Control
X-DynaTrace
X-Country
Rating
Fusion-Component-Id
Fusion-Content-Id
Fusion-Template-Id
Fusion-Content-Source
Fusion-Source
X-FTR-Request-ID
X-Akam-SW-Version
X-Country-Code
X-Goog-Hash
X-Ruxit-JS-Agent
X-Varnish-TTL
X-Instart-Request-ID
Pinterest-Generated-By
X-Vname
X-PC
X-TtlSet
Edge-Control
X-Url
X-MS-InvokeApp
X-Mod-Pagespeed
X-B3-TraceId
Verso
SPRequestGuid
X-Powered-By-Plesk
Accept-Ch
X-ESI
X-D2id
X-Trace
X-SharePointHealthScore
X-VARITI-CCR
Pagespeed
X-Server-Name
X-Sol
X-Middleton-Response
Response
Service-Worker-Allowed
Display
X-Middleton-Display
X-GitHub-Request-Id
X-Exp-Id
X-Exp-Variant
X-Cdn-Fetch
X-Kinja-Build
X-GoogleNews-Bot
X-Kinja-Revision
X-Use-Magma
X-Kinja
X-Kinja-Server
RTSS
Content-MD5
SPRequestDuration
SPIisLatency
X-Server-ID
X-Navigation-Version
X-TTL
X-Powered-CMS
X-Abt-Application-Version
X-Debug
X-Vcache
X-Amz-Server-Side-Encryption
X-Forwarded-Proto
X-Upstream
Charset
X-Vcap-Request-Id
Public-Key-Pins
Accept-Ch-Lifetime
X-Cached
MS-Author-Via
DynaTrace
X-NF-Request-ID
X-CST
X-Version
X-Amz-Rid
Edge-Cache-Tag
Realpath
X-Px
MicrosoftSharePointTeamServices
X-Shard
TCN
Arr-Disable-Session-Affinity
X-Trafficlayer-App-Name
X-Ezoic-Cdn
X-Trafficlayer-App-Scope
X-XRDS-Location
Access-Control-Request-Method
X-DynaTrace-JS-Agent
X-Pinterest-Rid
Pinterest-Version
X-MSEdge-Ref
X-Shield-Request-Id
X-Ser
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Fastly-Restarts
X-Fastly-Request-ID
S
X-Accel-Expires
X-DIS-Request-ID
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Metageneration
X-TEC-API-ORIGIN
X-TEC-API-ROOT
Front-End-Https
X-Recruiting
X-TEC-API-VERSION
X-Client-IP
X-Amz-Meta-S3cmd-Attrs
X-T
X-Id
X-Goog-Storage-Class
X-Element-Page-Cache
Nginx-Cache
X-Varnish-Age
Mrf-Cache-Status
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-DC
X-FTR-Realm
X-FTR-Backend-Server
X-FTR-Backend
X-B3-TraceId-Primal
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
MRF-Tech
X-Country-Code-Real
Cache-Tag
X-FTR-Expires
X-Amzn-Trace-Id
X-Dw-Request-Base-Id
X-Webapp-Samesite-None-Activated-N
X-Ttl
Fastcgi-Cache
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Cache-Config
X-Frontend
X-Content-Digest
NR-ENABLED
Powered
X-Hits
X-Correlation-Id
X-Kinsta-Cache
Alternate-Protocol
X-Hp-Webp
X-FTR-Cache-Host
X-Fastcgi-Cache
X-Request-Processing-Time
ServerID
X-Request-Received
X-RateLimit-Remaining
X-Content-Type
X-HS-Combine-CSS
X-Aspnetmvc-Version
X-N
Server-Name
X-Request-Handler-Origin-Region
X-Cache-Hit
X-Microsite
X-Webkit-Csp
PB-PID
PB-RID
X-Node-Name
TP-L2-Cache
Arc-Version
X-Mobile-Rewrite
TP-Cache
X-User-Agent
X-Grace
X-Rid
Healthy
X-Revision
X-Analytics
X-Akamai-Edgescape
X-Forwarded-For
Backend-Timing
AMP-Access-Control-Allow-Source-Origin
X-Content-Security-Policy-Report-Only
X-Zen-Fury
Accept-CH
Accept-CH-Lifetime
X-Logged-In
X-FastCGI-Cache
Server-Node
X-LB-Cache
X-Pad
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Mobile-URL
X-AppVersion
X-Az
X-Activity-Id
X-GUploader-UploadID
X-NWS-LOG-UUID
X-Varnish-Grace
X-Cached-By
Cache-Status
X-B3-Sampled
X-Oneagent-Js-Injection
X-IPLB-Instance
X-Content-Options
Retry-After
X-F-Cache
Refresh
X-Type
AR-CACHE
AR-ATIME
Upgrade-Insecure-Requests
AR-PoweredBy
X-Geo-Country
X-Srv
X-Ruxit-Js-Agent
FilterID
X-Varnish-Backend
X-Tumblr-Pixel
X-App-Environment
Paypal-Debug-Id
X-Tumblr-User
X-Tumblr-Pixel-0
Source
X-Instance
X-FB-Debug
X-Framework
Access-Control-Allow-Method
X-Debug-Info
X-Cluster
X-Request-Guid
DC
X-PHP-Backend
X-Jobs
X-Page-Id
Host
Accept-Charset
Actual-Object-TTL
X-WebKit-CSP-Report-Only
X-AOL-HN
X-B
X-Cache-2
X-Litespeed-Cache
X-Cache-Age
Ar-Sid
X-ATG-Version
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
Cache
X-Seen-By
X-TT
X-Via-JSL
Fastcgi-Useragent
X-Cache-Key
MS-CV
X-Git-Hash
X-Content-Powered-By
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Cache-TTL
X-PressLabs-Stats
X-Whom
X-B-Cache
X-Signature
X-Amz-Replication-Status
X-UA
X-Cache-Control
X-TA-CDN-Provider
X-Daa-Tunnel
Host-Header
X-Wix-Request-Id
AR-Request-ID
Surrogate-Key
X-Response-Served-From
NGB
X-Host-Name
X-Origin-Server
X-Cache-Enabled
X-Mobile
X-RequestSource
X-GeoIP
X-Tumblr-Pixel-2
Frame-Options
X-Tumblr-Pixel-1
WPE-Backend
Cache-Tv-Group
X-FW-Static
X-TX-ID
X-FW-Server
X-FW-Serve
X-FW-Type
X-Handled-By
X-FW-Hash
X-Region
Cleartype
Eomportal-Instance
Filters
X-Hyper-Cache
Payment
X-Cache-Action
X-Cacheable-TTL
X-Drupal-Cache-Tags
X-EdgeConnect-Cache-Status
X-Adobe-Loc
X-Cache-NE
X-Adobe-Content
X-Cache-Operation
X-Kong-Upstream-Latency
X-Cache-Rule
Webserver
X-Kong-Proxy-Latency
Xserver
X-Hostname
X-SERVER
X-NewRelic-App-Data
From-Origin
X-ATS-Timestamp
X-RemovedCookies
X-ProcessESI
X-Load-Cache
Datacenter
X-Akamai-Transformed
X-Esi
X-UA-Device-Type
X-Forwarded-Host
X-RTag
Ms-Operation-Id
X-Edge-Location
X-Cache-TTL-Remaining
X-Cache-Server
Liferay-Portal
X-Time
X-App-Server
X-Status
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Contextid
X-Varnish-Server
X-Varnish-Hostname
X-Rule
X-Oss-Storage-Class
X-Oss-Server-Time
X-Oss-Request-Id
X-VCache
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
Country
Odigeo-Trace-Id
X-BCube-Filmed-By
X-TT-TIMESTAMP
X-ORACLE-APMCS-TAG
X-ORACLE-APMCS-REQUEST-ID
X-Upgrade-Enabled
X-RN-RSRV
X-Path-Route
X-Cache-Var
X-ES-SERVER
X-UUID
Meta-Geo
Tracecode
X-Cache-Var-Map
Load-Balancing
X-Xfnlog-Site
DSUID
X-Origin-Hint
Webcakes-App-Name
Webcakes-App-Version
Webcakes-Region
X-Cache-Config
TWC-Privacy
TWC-Locale-Group
X-OCL
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Device-Class
X-VCT
X-Pubstack
Release
X-PCL
Mn-Server-Ip
X-R9-Blue-Green-Version
X-Rocket-Nginx-Bypass
TWC-Connection-Speed
X-CCM
X-Debug-Cache
Cache-Tags
Property-Id
Azure-SlotName
Azure-SiteName
Azure-Version
X-FW-Dynamic
Cache-Name
Azure-RegionName
Azure-InstanceId
X-NWS-UUID-VERIFY
X-IP
X-Human
X-Hosted-By
DB-Nickname
X-FC-Vary-Parameters
X-Akamai-Request-ID2
X-Akamai-Request-ID
S-Rt
Selected-Fe
X-Cache-Host
NGX
Fastly-SSL
X-EIG-Tracking-Id
L5d-Success-Class
X-Drupal-Cache-Contexts
X-Loop
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Web-Node
X-Soup
X-Real-IP
X-Vgn-Hpd-Reason
X-Via-Fastly
X-Viewer-Country
X-Proxy
X-Proxy-Build
X-Timing-Wait
X-Origin-Response-Time
X-Proto
X-From
X-TNCMS
X-Varnish-Cache-Hits
X-Redis-Cache
X-Cache-Time
X-Content-Age
Origin-Edge-Control
X-Www-Served-By
X-Access
S-Cnection
Version
Origin-Cache-Control
Ec-Rule-Version
X-Backend-Name
Decoy-Debug-Status
X-Section
Decoy-Debug-TTL
Server-Info
Viewport
X-Locale
X-Labrador-Cache-Channel
X-Generated
X-ServerID
Decoy-Debug-Key
X-Origin
X-Site-Version
X-FireWall-Port
X-Format
X-Cluster-Name
X-JoinUs
X-Is-Bot
X-Rendered-As
X-Time-Microsecs
X-ApacheServer
X-PERF
X-ProxyCache-Key
X-BYPASS-REASON
X-ProxyCache-Status
Uber-Trace-Id
X-Varnish-Hits
X-XRDS-LOCATION
X-Storage
X-Tec-Api-Version
X-Info
X-Tec-Api-Root
X-Accel-Buffering
X-Cache-Backend
X-Generated-By
X-Tec-Api-Origin
X-PHP-Host
X-Origin-TTL
X-Origin-CC
X-B3-Traceid
X-Amzn-Remapped-Content-Length
Akamai-GRN
Rt-Fastcgi-Cache
X-App-Version
X-WA-Info
Time
X-URL
X-RateLimit-Limit
X-CF-Powered-By
X-Nginx-Cache-Key
Cache-Key
X-Presslabs-Stats
X-SaId
Cteonnt-Length
X-Geo
X-No-Session
X-MServer
X-Cache-Remote
X-Environment-Context
GEO-INFO
Origin
X-L-Path
Vix-Hermes-Req-Id
X-Guploader-Uploadid
Cache-Hits
X-GoCache-CacheStatus
Accept-Language
X-NCache
X-Tb
X-FB-TRIP-ID
Access-Control-Request-Headers
X-Hit
X-Trace-Id
X-Say-TTL
X-Say-Cacheable
X-Backend-TTL
X-SS-Set-Cookie
Srv
X-SayCDN-TTL
X-CACHE-KEY
X-APP-VERSION
X-Unique-Id
X-B3-SpanId
X-Device-Type
X-CS
X-Tumblr-Pixel-3
X-CDN-Forward
X-Alternate-Cache-Key
X-Sorting-Hat-PodId
X-ShardId
X-Sorting-Hat-ShopId
X-Shopify-Generated-Cart-Token
X-ShopId
X-Shopify-Stage
X-OVcl-Cache
X-CSRF-TOKEN
X-OVcl
X-EC-Lua
X-Cluster-Node
NtCoent-Length
User-Cache-Control
X-Parent-Response-Time
X-S
ServedBy
X-B-Cookie
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Apple-News-Services-Host
X-ARC
Apple-News-Services-Handled
X-AIR-PT
X-Application
Arc-Country
Cross-Origin-Window-Policy
X-CF-Lambda-Version
Content-Script-Type
Mobile-Detection-Method
X-CF-Lambda-Fn
Node
AsisCache
Rendered-Blocks
BehaviorPad-Version
X-Aed
Request-Country
X-A-Ccd
X-A
MD5-Digest
X-Accel-Expires-Debug
X-A-Wwc
Fastcgi-X-Cache-Version
X-A-Dcw
X-A-Dgt
Meta-Geo-Continent
IsBot
Server-Host
Rt-Proxy-Cache
Request-EU
T-Server
Viewtype
X-RCS-CacheZone
Machine
VivaBuild
X-A-Dam
Xc-Version
X-Transaction
OT-Force-Account-Verify
X-Svr
X-SRCache-Key
Content-Style-Type
X-Trv-Group
X-VG-WebServer
X-VG-WebCache
X-Vdms-Version
X-Connection-Hash
X-SIPLIST1
X-Session-Fingerprint
X-Rewrite-Enabled
X-Cache-Grace
X-Request-UUID
X-Processor
X-Rojux
X-PAYTM-SRV-ID
X-Service
X-Server-Time
X-ScT
X-S-Cookie
X-Vtex-Processado-Em
X-Twitter-Response-Tags
X-External-Request-Id
X-G
X-Detected-As
X-D
X-Vtex-Remote-Cache
X-DPWN-IS-SECURE
X-Hl-Ver
X-Destination
X-Region-Sid
X-Date
X-Dc
X-Source
ServerName
X-Endurance-Cache-Level
X-Magnolia-Registration
X-Block-Status
X-Debug-Log
X-Debug-Cookies
X-Ms-Request-Id
X-NX-Host
X-Proxy-Upstream
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Reboot
X-Proxy-Cache-Status
X-Core-Value
X-Ms-Version
X-Cache-Info
X-CUA
X-Cache-Bucket
Thinkindot-CacheControl-Type
X-Level-Front-Cache
Wxu-Next-Region
Wxu-Next-Hostname
Wxu-Next-Commit
X-Instart-Isnd
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-Hash
X-Generated-On
Web-Mar-Node
X-Webstats-RespID
X-Hnp-Log
Server-Int
X-Dispatch
Thinkindot-Control
X-Thinkindot-L3
X-Gen-Mode
X-Location
X-Matched-Rule
Served-By
Thinkindot-CacheControl
X-Uri
Proxy-Connection
X-Ah-Environment
CDCHOST
Mime-Version
Now
X-B3-Parentspanid
X-BBXSRF
X-Geo-Header
X-Sucuri-Cache
X-Backend-State
X-Azure-Ref-OriginShield
X-GeoIP-City
X-Bip
We-Hiring
X-Skip-Cache
X-Sigma-Backend
X-Generation-Time
X-Cache-Debug
X-C
Mail-Subject
X-Azure-Ref
X-Has-Esi
X-TrackingId
X-Thanos
X-Origin-Expires
X-Request-URI
X-Policy
X-Up
X-Swa-Ws
X-Agile
X-SVT-ORM-RULES
X-Auto-Login
X-SVT-ORM-VERSION
X-App-Name
X-Agile-Age
X-Agile-Id
X-Cache-URL
X-Generated-In
X-Release
X-Varnish-Beresp-Grace
X-Developers
X-FW-Version
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Status
X-Dispatcher-Server
X-Distil-CS
X-Rocket-Build-Number
X-Fastly-Cache
X-Eu-Site
X-Scheme
X-Server-IP
X-Reqid
Content-Disposition
X-Debug-Cache-Store
X-Clara-WADP
X-Clientip
X-Sigma
X-CGP
X-Cdn-Srv
Esi-Enabled
X-Cms-Context
X-Compress-Hint
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
X-Upstream-Ct
X-Upstream-Ht
X-Core-Mission
X-User
X-Qloud-Router
RNT-Time
RNT-Machine
X-We-Are-Hiring
IBM-Web2-Location
Heartbleed
HA-Ipaddr
X-Key
Memcached
Section-Io-Cache
Ha-Gx-Prefs
Countrycode
AKAMAI
PFcat
Cache-Host
X-Via-NSCOPI
Magicmarker
X-Planisys-CDN-TTL
X-Wikidot-Static-Cache
X-Wikidot-Backend
Pramga
Kp-EeAlive
L
X-Nc
X-WADP-Cache
X-Origin-Date
X-JWT-State
X-Planisys-CDN-Cache
X-Is-Gdpr
Fastly-Soc-X-Request-Id
X-VC-Cache
X-Irp-Debug
X-VG-TLSProxy
Gh-Request-Id
X-Logging-Id
W
X-Planisys-CDN-Rules
X-Method
X-VServer
X-Via-CDN
Cache-Provider
X-SRV
X-ND-Cache
X-Old-Content-Length
Locale
X-SD-PageType
X-Distributor
X-ServiceProvider
Is-Eu
X-Request-Start
X-NodeID
Cdncip
X-Epic-Correlation-Id
X-TIME
X-S-Maxage
Platform
X-Amz-Meta-Cache-Control
SD-X-WS
X-Li-Fabric
X-Li-Pop
X-AK-Request-ID
True-Client-Country-4JS
X-Urbn-Site-Id
X-Internal-Host
X-Urbn-Context-Path
X-Platform-Server
Adler-Geo
X-WebServer
X-Owner
X-LI-UUID
X-Cache-FS-Status
Cdnsip
X-Variation
X-Cache-Id
X-GRACE
X-MSEdge-Flight
X-LI-Proto
V-Age
X-NC
X-MSEdge-Features
X-Cdn-Forward
Hostname
X-B3-Spanid
X-Servername
Server-ID
X-UnsetCookies
Powered-By-ChinaCache
X-Trafficlayer-App-Version
Environment
X-Lb-Id
X-Be
GEO-REGION-INFO
X-7Graus-Varnish-Cache-Control
X-7Graus-Varnish-XKeys
CF-IPCountry
X-Sucuri-Id
FNAC-ModuleRouting
X-Req
X-Newrelic-Synthetics
Locid
X-Served-From
X-Nginx-Cache
X-HTML-Minification-Powered-By
X-Refresh
X-Gamma-Serve
A
Geo-Info
X-Developer
X-Servedbyhost
X-FPC
X-Cdn-Origin
X-VHOST
X-Device-Os
X-Microcachable
X-Sn-Servicetimems
X-Edge-O15-RID
X-Render-Time
ProcessTime
Tcn
X-Sucuri-ID
X-Node-Id
X-IPS-LoggedIn
X-Webkit-CSP
X-NU-AKA-ACS-Version
X-Tb-Optimization-Total-Bytes-Saved
Memory
X-Zone
X-GeoIP-Country-Code
X-Mode
X-MP-GENERATED-AT
X-AWS-Id
X-Pjax-Url
X-VWS-Id
X-LJ-Flow-ID
Request-Time
X-Ratelimit-Remaining
X-FORWARDED-FOR
X-Pf-Uncompressing
X-DC
X-VCL-Version
XServer
Gannett-Cam-Experience-Id
X-COUNTRY
Resin-Trace
X-ZONE
X-Correlation-ID
Pics-Label
TTL
X-Zipkin-Id
X-Routing-Service
X-Proxied
Cf-Ipcountry
Group
Geoip-Latitude
GeoIp-Country-Code
Amp-Access-Control-Allow-Source-Origin
MIME-Version
CF-Cached-On
X-Unique-ID
X-ECACHE
GeoIP-Country-Code
Geoip-City
X-Pod
X-ElasticPress-Search
GeoIP-Latitude
PICS-Label
X-Instart-Info
X-Backend-Url
X-Var-Ttl
X-Via-SSL
X-Backend-Host
M-TraceId
X-Bc
Cache-Cookie-Set-Idcheck
X-CSRF-Token
X-Via-Edge
Cache-Cookie-Set-From
GeoIP-City
Cache-Cookie-Set-Lfrom
Cdn
Ttl
Host-ID
Backend-Name
X-NGENIX-Cache
HostName
Ohc-Cache-HIT
Ohc-File-Size
X-CLOUD-TRACE-CONTEXT
X-Cdn-Request-ID
N-Cache
X-APP
REQUESTUUID
Pagetype
X-BC
Lfy
X-Vcl-Version
X-Check-Cacheable
X-Request-Time
X-Ratelimit-Limit
X-PF-Uncompressing
X-Swift-Error
Fly-Request-Id
X-NGINX-Cache
Cache-Prefix
X-TH-Server
X-Fstrz
HitType
X-PJAX-URL
Fly-Cache
URI
X-Via-Ucdn
X-Worker
X-Fastly-Country-Code
X-UPSTREAM-Address
X-Dynatrace-Js-Agent
X-Cache-Miss-From
X-Cache-Tag
Pragrma
X-GEO
Powered-By
On-Server
User-Agent
X-Tt-Trace-Tag
X-Sedo-Request-Id
X-HostName
X-LiteSpeed-Cache-Control
X-WR-MODIFICATION
X-HS-Status
X-Server-W
Media-Length
X-Fetched-On
X-ServedByHost
CDN
SRV
X-Aicache-OS
X-WA
X-Rebelmouse-Surrogate-Control
X-Upstream-HT
X-Wa
Fastly-SWR
X-Upstream-CT
X-Rebelmouse-Cache-Control
Who
Fastly-SIE
AR-SID
X-BE
X-Tt-Trace-Host
X-Fpc
X-Hp-Ccpa-Warning
X-Varnish-URL
X-Varnish-Cacheable
X-LB-ID
UCS
FSS-Cache
X-LAGOON
FSS-Proxy
X-TT-LOGID
X-Cf-Powered-By
DataCenter
Processtime
Server-Id
X-ServerName
X-Cache-Tags
X-Store
Debug
X-Fastly-Backend-Reqs
X-GDPR
X-NYM-Debug-Backend
X-Ftr-Cache-Host
X-Ua
Cdn-Request-Time
X-Cache-ASPX
Cdn-Host
X-Varnish-Beresp-TTL
X-Contensis-Viewer-Groups
Country-Code
X-Edge-Server
X-Akamai-ERPolicy
X-Varnish-Authentication
Server-Cache-Control
X-Akamai-ERRuleID
Server-Surrogate-Control
X-Protected-By
X-SN
X-BACKEND-TTL
Location
Cneonction
X-VC
Xet-Cookie
X-SB
WP-Super-Cache
X-Nananana
XxX-Cache-Status
NnCoection
X-Amzn-Remapped-Connection
X-Action
X-Flog
X-ABtesting
Warning
X-RateLimit-Reset
SS
X-DB
X-DI
X-RPS
X-RPM
X-RSL
X-DW
X-DSS
Requestid
X-Hello
SID
X-LiteSpeed-Tag
X-Gen-Id
X-Fastly-Cache-Hits
Product
Application
X-Li-Proto
Thinkindot-Cache-Type
LB
X-Amzn-Remapped-Date
Is-Session-Tracking
X-Dw-Trace-Id
Get-Access-Time
X-Request-Url