Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
CF-RAY
CF-Cache-Status
Pragma
Link
X-Powered-By
ETag
Expect-CT
Via
X-XSS-Protection
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Xss-Protection
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
Alt-Svc
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-FRAME-OPTIONS
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Request-ID
X-Generator
Content-Security-Policy-Report-Only
X-Cache-Status
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-Template
X-Language
X-AspNetMvc-Version
Status
X-Content-Security-Policy
X-Buckets
Content-Encoding
Access-Control-Expose-Headers
X-CDN
Upgrade
Xkey
Access-Control-Max-Age
Keep-Alive
X-Drupal-Dynamic-Cache
X-Kinja-Server-Push
X-Turbo-Charged-By
X-Via
X-AH-Environment
X-Ua-Compatible
X-Cache-Group
X-Age
X-Pass-Why
X-Backend
X-Envoy-Upstream-Service-Time
EagleId
X-Server
X-Robots-Tag
X-Amz-Request-Id
X-Amz-Id-2
X-Page-Speed
X-Pingback
X-Server-Powered-By
X-UA-Device
X-Proxy-Cache
X-Swift-SaveTime
X-Swift-CacheTime
X-Hacker
X-Nginx-Cache-Status
Ali-Swift-Global-Savetime
Request-Context
Grace
X-Varnish-Cache
Server-Timing
Feature-Policy
Cf-Railgun
X-Amz-Version-Id
X-LiteSpeed-Cache
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-Rq
X-Server-Id
X-WebKit-CSP
Report-To
EagleEye-TraceId
X-Ac
X-Response-Time
X-Host
X-OneAgent-JS-Injection
Request-Id
X-Cnection
X-Backend-Server
X-DataDome
X-Node
Content-Location
X-Ws-Request-Id
X-Origin-Cache
X-Cache-Lookup
X-Dns-Prefetch-Control
X-Cloud-Trace-Context
X-Readtime
NEL
X-Vhost
P3p
X-Application-Context
X-Dispatcher
X-ORACLE-DMS-ECID
X-HW
X-ORACLE-DMS-RID
X-Cdn
Allow
X-Clacks-Overhead
X-Rack-Cache
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Origin-Upstream-Status
Surrogate-Control
X-DynaTrace
X-Country
Rating
X-FTR-Request-ID
Fusion-Component-Id
Fusion-Source
Fusion-Template-Id
Fusion-Content-Id
Fusion-Content-Source
X-Akam-SW-Version
X-Country-Code
X-Goog-Hash
Pinterest-Generated-By
X-Instart-Request-ID
X-Ruxit-JS-Agent
X-Vname
X-TtlSet
X-PC
Edge-Control
X-Varnish-TTL
X-MS-InvokeApp
X-Mod-Pagespeed
X-Url
Verso
SPRequestGuid
X-Powered-By-Plesk
X-B3-TraceId
X-D2id
X-Trace
X-ESI
X-SharePointHealthScore
X-VARITI-CCR
X-Middleton-Response
X-Sol
Response
Pagespeed
Display
X-Middleton-Display
Service-Worker-Allowed
X-GitHub-Request-Id
X-Server-Name
X-Cdn-Fetch
X-Kinja
X-GoogleNews-Bot
X-Exp-Variant
X-Kinja-Revision
X-Use-Magma
X-Kinja-Server
X-Exp-Id
X-Kinja-Build
RTSS
Content-MD5
X-TTL
Accept-Ch
SPIisLatency
SPRequestDuration
X-Navigation-Version
X-Powered-CMS
X-Vcache
X-Abt-Application-Version
X-Debug
X-Amz-Server-Side-Encryption
X-Forwarded-Proto
X-Vcap-Request-Id
Charset
X-Upstream
Public-Key-Pins
MS-Author-Via
X-CST
X-Cached
DynaTrace
X-NF-Request-ID
X-Version
X-Amz-Rid
Realpath
X-Px
Edge-Cache-Tag
MicrosoftSharePointTeamServices
Accept-Ch-Lifetime
X-Shard
TCN
Arr-Disable-Session-Affinity
X-Ezoic-Cdn
X-Server-ID
X-Trafficlayer-App-Scope
Pinterest-Version
X-Pinterest-Rid
X-Trafficlayer-App-Name
X-MSEdge-Ref
X-Shield-Request-Id
Access-Control-Request-Method
X-DynaTrace-JS-Agent
X-Ser
Fastly-Restarts
X-SRCache-Store-Status
S
X-SRCache-Fetch-Status
X-Fastly-Request-ID
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Accel-Expires
X-DIS-Request-ID
X-XRDS-Location
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Stored-Content-Length
Front-End-Https
X-Recruiting
X-Client-IP
X-Amz-Meta-S3cmd-Attrs
Nginx-Cache
X-Id
X-T
X-Goog-Storage-Class
X-Aspnet-Version
X-Element-Page-Cache
X-Varnish-Age
X-FTR-Backend-Server
X-FTR-Realm
X-FTR-DC
X-FTR-Cache-Status
X-FTR-Balancer
X-Country-Code-Real
X-FTR-Backend
X-B3-TraceId-Primal
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
MRF-Tech
Mrf-Cache-Status
X-Amzn-Trace-Id
X-FTR-Expires
Cache-Tag
X-Dw-Request-Base-Id
X-Webapp-Samesite-None-Activated-N
X-Fastcgi-Cache
Fastcgi-Cache
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
X-Frontend
X-Content-Digest
NR-ENABLED
Powered
X-Hits
X-Ttl
X-Correlation-Id
X-Kinsta-Cache
Accept-CH
Alternate-Protocol
X-FTR-Cache-Host
X-Hp-Webp
Accept-CH-Lifetime
X-Aspnetmvc-Version
X-Webkit-Csp
X-RateLimit-Remaining
X-Request-Processing-Time
X-Request-Received
ServerID
X-N
X-Cache-Hit
X-Grace
Server-Name
X-Request-Handler-Origin-Region
X-HS-Combine-CSS
X-Microsite
X-Content-Type
PB-PID
PB-RID
X-Node-Name
Arc-Version
TP-Cache
TP-L2-Cache
X-Mobile-Rewrite
X-User-Agent
X-Rid
Healthy
X-Revision
X-Akamai-Edgescape
X-Analytics
X-Zen-Fury
Backend-Timing
AMP-Access-Control-Allow-Source-Origin
X-Forwarded-For
X-Content-Security-Policy-Report-Only
X-Logged-In
X-Pad
X-LB-Cache
Server-Node
X-Amz-Apigw-Id
X-Amzn-RequestId
X-AppVersion
X-Az
X-Activity-Id
X-Mobile-URL
Cache-Status
X-Oneagent-Js-Injection
X-Cached-By
X-NWS-LOG-UUID
X-Varnish-Grace
X-IPLB-Instance
X-B3-Sampled
Retry-After
X-Content-Options
Refresh
X-Type
X-F-Cache
AR-PoweredBy
AR-CACHE
AR-ATIME
X-Ruxit-Js-Agent
X-GUploader-UploadID
X-Geo-Country
X-FastCGI-Cache
Upgrade-Insecure-Requests
X-Tumblr-Pixel
X-Srv
Paypal-Debug-Id
X-App-Environment
X-Tumblr-User
X-Varnish-Backend
X-Tumblr-Pixel-0
Source
X-Instance
X-FB-Debug
Host
DC
X-Cluster
X-Page-Id
X-PHP-Backend
Access-Control-Allow-Method
X-Framework
X-Debug-Info
X-B
Accept-Charset
X-Request-Guid
X-Jobs
Actual-Object-TTL
FilterID
X-WebKit-CSP-Report-Only
X-AOL-HN
Ar-Sid
X-Cache-Age
X-Cache-Key
X-ATG-Version
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
Cache
X-Via-JSL
X-Cache-2
X-Seen-By
X-TT
Fastcgi-Useragent
MS-CV
X-Content-Powered-By
X-Git-Hash
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Cache-TTL
X-Whom
X-PressLabs-Stats
X-Amz-Replication-Status
X-UA
X-B-Cache
X-Signature
Host-Header
X-Cache-Control
X-Wix-Request-Id
AR-Request-ID
X-Daa-Tunnel
Surrogate-Key
X-Host-Name
X-TA-CDN-Provider
X-Response-Served-From
NGB
X-Cache-Enabled
X-RequestSource
X-Origin-Server
X-GeoIP
X-Mobile
Cache-Tv-Group
X-Tumblr-Pixel-2
WPE-Backend
X-Tumblr-Pixel-1
Frame-Options
X-EdgeConnect-Cache-Status
X-Region
Filters
X-Handled-By
Payment
X-TX-ID
X-Drupal-Cache-Tags
Cleartype
X-Hyper-Cache
Eomportal-Instance
X-FW-Serve
X-FW-Hash
X-FW-Server
Xserver
X-Cache-Action
X-FW-Static
X-Litespeed-Cache
X-FW-Type
X-Cacheable-TTL
X-Adobe-Content
X-Adobe-Loc
Webserver
X-Cache-NE
X-Cache-Operation
X-Cache-Rule
X-SERVER
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Esi
From-Origin
X-Hostname
X-ProcessESI
X-UA-Device-Type
X-RemovedCookies
X-Akamai-Transformed
X-Load-Cache
X-Forwarded-Host
X-ATS-Timestamp
Datacenter
X-NewRelic-App-Data
Ms-Operation-Id
X-RTag
X-Cache-TTL-Remaining
X-Edge-Location
Liferay-Portal
X-Cache-Server
X-App-Server
X-Status
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-XRDS-LOCATION
X-Varnish-Hostname
X-Contextid
X-B3-Traceid
X-Varnish-Server
X-Time
X-Rule
X-Oss-Storage-Class
X-Oss-Server-Time
X-Oss-Object-Type
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
Country
Odigeo-Trace-Id
X-ORACLE-APMCS-TAG
X-BCube-Filmed-By
X-TT-TIMESTAMP
X-ORACLE-APMCS-REQUEST-ID
Tracecode
X-Cache-Var
X-Path-Route
Load-Balancing
X-ES-SERVER
Meta-Geo
X-RN-RSRV
X-Cache-Var-Map
X-Upgrade-Enabled
DSUID
X-Debug-Cache
X-UUID
X-Xfnlog-Site
X-Viewer-Country
Webcakes-App-Version
Property-Id
Cache-Tags
DB-Nickname
Webcakes-App-Name
TWC-Privacy
TWC-Device-Class
X-Pubstack
X-Cache-Config
TWC-GeoIP-Country
TWC-Locale-Group
X-CCM
Webcakes-Region
TWC-GeoIP-LatLong
X-R9-Blue-Green-Version
X-Rocket-Nginx-Bypass
TWC-Connection-Speed
X-PCL
X-Via-Fastly
Mn-Server-Ip
X-OCL
X-NWS-UUID-VERIFY
X-Origin-Hint
X-VCT
Release
X-Akamai-Request-ID
X-Proxy-Build
X-Origin
X-Akamai-Request-ID2
X-Proxy
X-Hosted-By
X-Labrador-Cache-Channel
Azure-Version
Cache-Name
X-IP
Azure-SlotName
Azure-SiteName
NGX
Azure-InstanceId
Azure-RegionName
X-Loop
X-Origin-Response-Time
X-Soup
X-Vgn-Hpd-Reason
X-EIG-Tracking-Id
X-Drupal-Cache-Contexts
X-FC-Vary-Parameters
X-Proto
X-From
Selected-Fe
X-Web-Node
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Redis-Cache
X-Timing-Wait
X-Cache-Time
X-Cache-Host
L5d-Success-Class
X-TNCMS
S-Rt
Server-Info
X-Human
X-Real-IP
X-Varnish-Cache-Hits
S-Cnection
X-Content-Age
X-Format
X-FireWall-Port
X-Site-Version
X-Locale
X-FW-Dynamic
X-Generated
X-Is-Bot
X-PERF
X-Www-Served-By
X-Backend-Name
X-ApacheServer
X-Access
X-Cluster-Name
X-Rendered-As
X-ServerID
X-Section
Viewport
Origin-Cache-Control
Origin-Edge-Control
Decoy-Debug-TTL
Decoy-Debug-Status
Decoy-Debug-Key
Fastly-SSL
Ec-Rule-Version
Version
X-ProxyCache-Status
X-VCache
X-BYPASS-REASON
X-JoinUs
X-ProxyCache-Key
X-Time-Microsecs
X-Varnish-Hits
Uber-Trace-Id
X-Storage
X-Info
X-Generated-By
X-Cache-Backend
X-Guploader-Uploadid
X-PHP-Host
X-Origin-TTL
X-Accel-Buffering
X-Origin-CC
X-URL
Rt-Fastcgi-Cache
X-Amzn-Remapped-Content-Length
Akamai-GRN
X-Presslabs-Stats
X-Webkit-CSP
Time
X-WA-Info
Cache-Key
X-RateLimit-Limit
X-Nginx-Cache-Key
Cteonnt-Length
X-App-Version
GEO-INFO
X-Tec-Api-Version
X-Tec-Api-Root
X-Geo
X-SaId
X-Tec-Api-Origin
X-CF-Powered-By
X-No-Session
Origin
X-GoCache-CacheStatus
X-Environment-Context
X-Cache-Remote
X-L-Path
X-MServer
Vix-Hermes-Req-Id
Cache-Hits
X-NCache
Accept-Language
X-FB-TRIP-ID
X-APP-VERSION
X-Unique-Id
X-Tb
X-Hit
X-Trace-Id
X-Backend-TTL
Access-Control-Request-Headers
X-SS-Set-Cookie
X-Say-Cacheable
X-Say-TTL
X-SayCDN-TTL
X-Device-Type
X-CS
X-Tumblr-Pixel-3
X-B3-SpanId
Srv
X-Sorting-Hat-ShopId
X-Alternate-Cache-Key
X-Shopify-Stage
X-CDN-Forward
X-Sorting-Hat-PodId
X-OVcl-Cache
X-OVcl
X-ShopId
X-ShardId
X-Shopify-Generated-Cart-Token
X-Cluster-Node
X-Cache-Grace
X-S
ServedBy
X-CACHE-KEY
User-Cache-Control
X-Parent-Response-Time
X-Dc
Mobile-Detection-Method
Request-Country
Rendered-Blocks
Node
Meta-Geo-Continent
Request-EU
Apple-News-Services-Parsed-Url
Arc-Country
AsisCache
Apple-News-Services-Request-Url
Apple-News-Services-Host
Apple-News-Services-Handled
BehaviorPad-Version
Content-Script-Type
Machine
Fastcgi-X-Cache-Version
Cross-Origin-Window-Policy
Content-Style-Type
MD5-Digest
X-ARC
X-S-Cookie
X-Rojux
X-ScT
X-Server-Time
X-Service
X-Rewrite-Enabled
X-Request-UUID
X-Hl-Ver
X-PAYTM-SRV-ID
X-Processor
X-Region-Sid
X-Session-Fingerprint
X-SRCache-Key
X-VG-WebServer
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-VG-WebCache
X-Vdms-Version
X-Svr
X-Transaction
X-Trv-Group
X-Twitter-Response-Tags
X-G
X-External-Request-Id
X-A-Dam
X-A-Dcw
X-A-Dgt
X-A-Wwc
X-A-Ccd
X-A
Server-Host
T-Server
Viewtype
VivaBuild
X-Accel-Expires-Debug
X-Aed
X-Date
X-Destination
X-Detected-As
X-DPWN-IS-SECURE
X-D
X-Connection-Hash
X-Application
X-B-Cookie
X-CF-Lambda-Fn
X-CF-Lambda-Version
Rt-Proxy-Cache
X-AIR-PT
Mime-Version
NtCoent-Length
X-EC-Lua
X-CSRF-TOKEN
X-Ah-Environment
OT-Force-Account-Verify
ServerName
X-Endurance-Cache-Level
X-RCS-CacheZone
Served-By
Thinkindot-CacheControl-Type
X-NX-Host
X-Ms-Version
X-CUA
X-Ms-Request-Id
X-Reboot
X-RateLimit-Remaining-Second
Thinkindot-CacheControl
X-Proxy-Upstream
X-RateLimit-Limit-Second
X-Cms-Context
X-Core-Value
X-Proxy-Cache-Status
X-Level-Front-Cache
X-Debug-Log
X-Debug-Cookies
X-Hash
X-Generated-On
Now
X-Dispatcher-Server
X-Dispatch
X-Gen-Mode
X-Hnp-Log
X-IN-APIGATEWAY
IsBot
X-Request-URI
X-Location
RNT-Time
RNT-Machine
X-IN-APIGATEWAYSSL
X-Instart-Isnd
X-Matched-Rule
Thinkindot-Control
Wxu-Next-Region
X-Cache-Debug
Wxu-Next-Hostname
Wxu-Next-Commit
We-Hiring
Web-Mar-Node
X-Thinkindot-L3
X-Cache-Bucket
X-WADP-Cache
X-Webstats-RespID
X-Block-Status
X-Uri
X-Source
Mail-Subject
X-Magnolia-Registration
X-Cache-Info
CDCHOST
Cache-Host
Proxy-Connection
X-Clara-WADP
X-SIPLIST1
X-Via-CDN
X-SRV
X-B3-Parentspanid
X-Azure-Ref
X-TIME
X-Azure-Ref-OriginShield
X-Compress-Hint
X-Cache-Id
X-Developers
X-Agile-Id
X-App-Name
X-Auto-Login
X-Backend-State
X-BBXSRF
X-Debug-Cache-Store
X-Distil-CS
X-Cdn-Srv
X-Cache-URL
X-Debug-Cache-Expiry
X-C
X-Bip
X-CGP
X-Clientip
X-Debug-Cache-Fetch
X-Key
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Swa-Ws
X-Thanos
X-Sucuri-Cache
X-Skip-Cache
X-Scheme
X-Server-IP
X-Sigma
X-Sigma-Backend
X-TrackingId
X-Up
X-WebServer
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Via-NSCOPI
X-We-Are-Hiring
X-VServer
X-User
X-Variation
X-VC-Cache
X-VG-TLSProxy
X-S-Maxage
X-Rocket-Build-Number
X-Irp-Debug
X-Is-Gdpr
X-JWT-State
X-Agile-Age
X-Has-Esi
X-GeoIP-City
X-Fastly-Cache
X-FW-Version
X-Generated-In
X-Geo-Header
X-Logging-Id
X-Method
X-Policy
X-Qloud-Router
X-Release
X-Reqid
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Origin-Date
X-Origin-Expires
X-Planisys-CDN-Cache
X-Eu-Site
X-Generation-Time
Memcached
X-Varnish-Beresp-Ttl
Magicmarker
L
Kp-EeAlive
X-Varnish-Beresp-Status
PFcat
Section-Io-Cache
Server-Int
X-Varnish-Beresp-Grace
Pramga
Platform
Is-Eu
IBM-Web2-Location
Content-Disposition
Countrycode
X-Agile
AKAMAI
Adler-Geo
Esi-Enabled
X-Upstream-Ct
HA-Ipaddr
Heartbleed
Ha-Gx-Prefs
Gh-Request-Id
Fastly-Soc-X-Request-Id
True-Client-Country-4JS
X-Upstream-Ht
W
X-Nc
Cache-Provider
X-Urbn-Context-Path
X-MSEdge-Features
Cdncip
X-Amz-Meta-Cache-Control
Locale
X-Urbn-Site-Id
X-MSEdge-Flight
X-Epic-Correlation-Id
X-AK-Request-ID
X-ServiceProvider
X-Platform-Server
X-Distributor
X-SD-PageType
X-Cache-FS-Status
X-Internal-Host
X-Request-Start
X-LI-UUID
X-ND-Cache
X-Owner
X-NodeID
X-Old-Content-Length
X-Core-Mission
X-Li-Pop
X-Li-Fabric
Cdnsip
X-NC
SD-X-WS
X-Cdn-Forward
Hostname
V-Age
X-UnsetCookies
X-LI-Proto
X-B3-Spanid
Server-ID
X-Trafficlayer-App-Version
X-7Graus-Varnish-XKeys
X-7Graus-Varnish-Cache-Control
X-Servername
Powered-By-ChinaCache
Environment
X-GRACE
Locid
X-Req
X-Lb-Id
X-Be
GEO-REGION-INFO
X-Nginx-Cache
CF-IPCountry
X-FPC
X-Sucuri-Id
X-Served-From
X-Newrelic-Synthetics
X-Developer
A
FNAC-ModuleRouting
X-Device-Os
X-Sn-Servicetimems
X-Cdn-Origin
X-HTML-Minification-Powered-By
X-Gamma-Serve
X-VHOST
X-Refresh
X-Zone
ProcessTime
X-Sucuri-ID
X-Microcachable
X-Node-Id
Tcn
Geo-Info
X-Servedbyhost
X-Render-Time
X-NU-AKA-ACS-Version
X-Tb-Optimization-Total-Bytes-Saved
X-Pjax-Url
X-Ratelimit-Remaining
Request-Time
X-IPS-LoggedIn
Memory
X-AWS-Id
X-Pf-Uncompressing
X-GeoIP-Country-Code
X-FORWARDED-FOR
X-VWS-Id
X-LJ-Flow-ID
X-Mode
X-MP-GENERATED-AT
Gannett-Cam-Experience-Id
X-VCL-Version
X-COUNTRY
Resin-Trace
X-Edge-O15-RID
Cf-Ipcountry
X-Correlation-ID
TTL
X-DC
Geoip-Latitude
XServer
GeoIp-Country-Code
Amp-Access-Control-Allow-Source-Origin
Group
X-CSRF-Token
CF-Cached-On
X-ElasticPress-Search
X-Pod
X-ECACHE
Pics-Label
Geoip-City
X-Bc
PICS-Label
X-Instart-Info
X-Zipkin-Id
MIME-Version
X-Proxied
X-Routing-Service
GeoIP-City
GeoIP-Latitude
GeoIP-Country-Code
X-Via-Edge
X-Var-Ttl
X-Via-SSL
X-Backend-Host
X-Backend-Url
Cdn
X-ZONE
X-Unique-ID
Cache-Cookie-Set-Idcheck
Ttl
Cache-Cookie-Set-From
Backend-Name
X-NGENIX-Cache
Host-ID
M-TraceId
Cache-Cookie-Set-Lfrom
HostName
X-Vcl-Version
X-CLOUD-TRACE-CONTEXT
X-APP
X-Ratelimit-Limit
REQUESTUUID
X-Check-Cacheable
Lfy
Pagetype
N-Cache
Ohc-File-Size
Ohc-Cache-HIT
X-Fstrz
HitType
X-Cdn-Request-ID
Fly-Request-Id
Fly-Cache
Cache-Prefix
X-BC
X-PF-Uncompressing
X-Swift-Error
X-Request-Time
X-Worker
X-Via-Ucdn
X-TH-Server
X-PJAX-URL
X-NGINX-Cache
X-Dynatrace-Js-Agent
X-Cache-Tag
X-Cache-Miss-From
X-GEO
X-Sedo-Request-Id
Pragrma
URI
SRV
On-Server
X-ServedByHost
X-Fastly-Country-Code
User-Agent
X-LiteSpeed-Cache-Control
X-HostName
X-Varnish-Ttl
X-UPSTREAM-Address
CDN
X-Aicache-OS
Powered-By
X-WR-MODIFICATION
X-Server-W
X-HS-Status
X-Fetched-On
X-Tt-Trace-Tag
X-Upstream-HT
Fastly-SWR
Fastly-SIE
X-WA
Media-Length
Who
X-Rebelmouse-Cache-Control
X-Wa
X-Upstream-CT
X-Rebelmouse-Surrogate-Control
AR-SID
X-BE
X-LAGOON
X-TT-LOGID
X-Varnish-URL
FSS-Proxy
X-LB-ID
X-Tt-Trace-Host
FSS-Cache
X-Fpc
X-Varnish-Cacheable
DataCenter
X-Cf-Powered-By
UCS
Debug
X-Hp-Ccpa-Warning
X-Fastly-Backend-Reqs
Server-Id
X-GDPR
X-ServerName
Filterid
X-Ua
X-Ftr-Cache-Host
X-Cache-Tags
X-Edge-Server
X-Store
X-Akamai-ERPolicy
Cdn-Host
X-SN
X-Varnish-Beresp-TTL
X-Akamai-ERRuleID
Cdn-Request-Time
X-Protected-By
X-NYM-Debug-Backend
Processtime
Cneonction
WP-Super-Cache
Xet-Cookie
XxX-Cache-Status
NnCoection
Country-Code
X-SB
X-Nananana
X-VC
X-RPS
X-DW
X-DSS
X-Flog
X-Hello
Is-Session-Tracking
LB
X-DI
Requestid
X-ABtesting
X-Action
Warning
SS
X-DB
X-LiteSpeed-Tag
Get-Access-Time
SID
X-Li-Proto
X-Gen-Id
X-Fastly-Cache-Hits
Product
Application
Thinkindot-Cache-Type
X-Dw-Trace-Id
X-RPM
X-RateLimit-Reset
X-RSL
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
X-Request-Url