Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
CF-RAY
CF-Cache-Status
Pragma
Link
X-Powered-By
ETag
Expect-CT
Via
X-XSS-Protection
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Xss-Protection
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
Alt-Svc
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-FRAME-OPTIONS
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Request-ID
Content-Security-Policy-Report-Only
X-Generator
X-Cache-Status
X-Cacheable
X-Permitted-Cross-Domain-Policies
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Template
X-Iinfo
X-Language
X-AspNetMvc-Version
Status
X-Content-Security-Policy
X-Buckets
Content-Encoding
Access-Control-Expose-Headers
Upgrade
X-CDN
Xkey
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Drupal-Dynamic-Cache
X-Turbo-Charged-By
X-Via
X-AH-Environment
X-Cache-Group
X-Age
X-Ua-Compatible
X-Pass-Why
X-Backend
X-Envoy-Upstream-Service-Time
EagleId
X-Server
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Page-Speed
X-Pingback
X-Server-Powered-By
X-UA-Device
X-Proxy-Cache
X-Swift-SaveTime
X-Swift-CacheTime
X-Hacker
Ali-Swift-Global-Savetime
X-Nginx-Cache-Status
Request-Context
Grace
X-Varnish-Cache
Server-Timing
Feature-Policy
Cf-Railgun
X-Amz-Version-Id
X-Device
X-LiteSpeed-Cache
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Rq
X-WebKit-CSP
Report-To
EagleEye-TraceId
X-Ac
X-Server-Id
X-Response-Time
X-Host
Request-Id
X-Cnection
X-OneAgent-JS-Injection
X-Backend-Server
X-DataDome
X-Node
Content-Location
X-Origin-Cache
X-Cloud-Trace-Context
X-Dns-Prefetch-Control
X-Readtime
X-Cache-Lookup
X-Cdn
NEL
X-Vhost
X-Ws-Request-Id
X-Application-Context
X-Dispatcher
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-HW
Allow
X-Clacks-Overhead
X-Rack-Cache
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Origin-Upstream-Status
X-DynaTrace
Surrogate-Control
Rating
X-FTR-Request-ID
X-Country
X-Country-Code
Fusion-Source
Fusion-Template-Id
Fusion-Component-Id
Fusion-Content-Source
Fusion-Content-Id
X-Akam-SW-Version
X-Goog-Hash
Pinterest-Generated-By
X-Varnish-TTL
X-PC
X-Vname
X-Instart-Request-ID
X-TtlSet
X-MS-InvokeApp
Edge-Control
X-B3-TraceId
X-Url
X-Ruxit-JS-Agent
X-Mod-Pagespeed
Verso
SPRequestGuid
X-Powered-By-Plesk
X-D2id
X-Trace
X-SharePointHealthScore
X-Middleton-Response
X-Sol
Pagespeed
Response
Accept-Ch
Display
X-Middleton-Display
X-VARITI-CCR
RTSS
X-Exp-Id
X-GoogleNews-Bot
X-Exp-Variant
Service-Worker-Allowed
X-Cdn-Fetch
X-Kinja
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Server-Name
X-Kinja-Build
X-GitHub-Request-Id
X-Server-ID
X-ESI
SPIisLatency
SPRequestDuration
Content-MD5
X-Navigation-Version
X-Vcache
X-Powered-CMS
X-Abt-Application-Version
X-Debug
X-TTL
X-Vcap-Request-Id
X-Amz-Server-Side-Encryption
Public-Key-Pins
X-CST
Charset
MS-Author-Via
X-Upstream
X-Forwarded-Proto
X-Cached
Accept-Ch-Lifetime
X-NF-Request-ID
X-Amz-Rid
X-Px
Realpath
X-Version
DynaTrace
Edge-Cache-Tag
MicrosoftSharePointTeamServices
X-Shard
Arr-Disable-Session-Affinity
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
Fastly-Restarts
Pinterest-Version
X-Pinterest-Rid
X-Ezoic-Cdn
X-Shield-Request-Id
X-Ser
Access-Control-Request-Method
TCN
X-MSEdge-Ref
X-DynaTrace-JS-Agent
X-SRCache-Store-Status
X-SRCache-Fetch-Status
S
X-Fastly-Request-ID
X-Recruiting
X-XRDS-Location
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Accel-Expires
X-DIS-Request-ID
X-Trafficlayer-App-Name
X-Trafficlayer-App-Scope
Front-End-Https
Nginx-Cache
X-Amz-Meta-S3cmd-Attrs
X-Client-IP
X-Goog-Storage-Class
X-Id
X-T
X-Varnish-Age
X-Element-Page-Cache
X-B3-TraceId-Primal
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
MRF-Tech
Mrf-Cache-Status
X-FTR-DC
X-FTR-Cache-Status
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-Realm
X-FTR-Backend
X-Country-Code-Real
X-FTR-Expires
X-Amzn-Trace-Id
X-Webkit-Csp
X-Ttl
X-Dw-Request-Base-Id
Cache-Tag
Fastcgi-Cache
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
X-Fastcgi-Cache
X-Frontend
X-Webapp-Samesite-None-Activated-N
X-Content-Digest
NR-ENABLED
Powered
X-RateLimit-Remaining
X-Hits
X-Correlation-Id
X-Kinsta-Cache
X-Litespeed-Cache
X-Oneagent-Js-Injection
X-FTR-Cache-Host
Alternate-Protocol
X-Grace
ServerID
X-Aspnetmvc-Version
X-Hp-Webp
X-N
X-Cache-Hit
X-Request-Processing-Time
X-Request-Received
TP-L2-Cache
TP-Cache
X-Node-Name
X-Microsite
PB-PID
X-Request-Handler-Origin-Region
PB-RID
X-HS-Combine-CSS
X-Mobile-Rewrite
Server-Name
Arc-Version
AMP-Access-Control-Allow-Source-Origin
Accept-CH
X-Rid
Healthy
X-Zen-Fury
X-User-Agent
Accept-CH-Lifetime
X-Revision
X-Content-Type
X-Ruxit-Js-Agent
Backend-Timing
X-Analytics
X-Akamai-Edgescape
X-Content-Security-Policy-Report-Only
Server-Node
X-Logged-In
X-LB-Cache
AR-CACHE
AR-PoweredBy
AR-ATIME
X-Az
X-Activity-Id
Cache-Status
X-Forwarded-For
X-AppVersion
X-Pad
Ar-Sid
X-Amz-Apigw-Id
X-Amzn-RequestId
X-NWS-LOG-UUID
X-IPLB-Instance
X-Cached-By
Retry-After
X-Varnish-Grace
X-Mobile-URL
X-Type
X-FastCGI-Cache
X-B3-Sampled
X-Srv
X-GUploader-UploadID
Paypal-Debug-Id
X-Content-Options
Refresh
X-F-Cache
FilterID
X-Via-JSL
Upgrade-Insecure-Requests
X-Geo-Country
X-App-Environment
X-Tumblr-Pixel-0
X-Varnish-Backend
X-Tumblr-User
X-Tumblr-Pixel
Accept-Charset
X-Debug-Info
X-FB-Debug
X-Instance
Source
X-Jobs
Host
X-Framework
X-Cache-Age
Access-Control-Allow-Method
Actual-Object-TTL
X-PHP-Backend
DC
X-Request-Guid
X-B
X-Cluster
X-Page-Id
X-AOL-HN
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-WebKit-CSP-Report-Only
X-Seen-By
X-ATG-Version
X-Cache-Key
AR-Request-ID
MS-CV
Fastcgi-Useragent
X-TT
X-Content-Powered-By
X-PressLabs-Stats
X-Cache-TTL
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Whom
X-Git-Hash
X-Cache-2
Cache
X-Esi
X-UA
X-TA-CDN-Provider
X-Amz-Replication-Status
X-Cache-Control
X-Host-Name
X-B-Cache
Surrogate-Key
X-Wix-Request-Id
X-Signature
Host-Header
X-Response-Served-From
Frame-Options
NGB
X-Daa-Tunnel
X-Mobile
X-Kong-Proxy-Latency
X-Origin-Server
X-Cache-Rule
X-Cache-Operation
X-FW-Type
X-Kong-Upstream-Latency
X-FW-Server
X-FW-Static
X-GeoIP
X-RequestSource
X-FW-Hash
X-FW-Serve
Cache-Tv-Group
X-Drupal-Cache-Tags
X-Tumblr-Pixel-2
WPE-Backend
X-Tumblr-Pixel-1
X-Cache-Enabled
Cleartype
X-Cache-NE
Webserver
X-TX-ID
Payment
X-Region
X-Hyper-Cache
X-Handled-By
Eomportal-Instance
Filters
X-Cacheable-TTL
X-Cache-Action
X-Adobe-Content
Xserver
X-Adobe-Loc
X-SERVER
X-UA-Device-Type
From-Origin
X-Forwarded-Host
X-EdgeConnect-Cache-Status
X-ProcessESI
X-RemovedCookies
X-Time
X-Load-Cache
Datacenter
Ms-Operation-Id
X-RTag
X-Akamai-Transformed
X-Cache-TTL-Remaining
X-App-Server
X-NewRelic-App-Data
X-Cache-Server
X-Edge-Location
X-Hostname
Liferay-Portal
X-Status
Tracecode
X-Contextid
X-XRDS-LOCATION
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-ATS-Timestamp
X-Varnish-Hostname
X-Varnish-Server
X-BCube-Filmed-By
X-TT-TIMESTAMP
Odigeo-Trace-Id
X-Rule
Country
X-RN-RSRV
X-ES-SERVER
Load-Balancing
X-Cache-Var-Map
Meta-Geo
X-Path-Route
X-Cache-Var
X-FW-Dynamic
Release
X-Viewer-Country
X-Debug-Cache
X-VCT
DSUID
X-Xfnlog-Site
X-Upgrade-Enabled
X-RateLimit-Limit
Server-Info
TWC-GeoIP-LatLong
X-CCM
X-OCL
TWC-Locale-Group
X-EIG-Tracking-Id
Webcakes-Region
Webcakes-App-Name
TWC-Privacy
Webcakes-App-Version
TWC-GeoIP-Country
X-Cache-Config
X-Cache-Host
X-R9-Blue-Green-Version
TWC-Connection-Speed
X-Via-Fastly
Property-Id
DB-Nickname
Cache-Tags
X-Varnish-Cache-Hits
TWC-Device-Class
X-Pubstack
X-PCL
Version
X-Rocket-Nginx-Bypass
X-Soup
X-Origin-Hint
Mn-Server-Ip
Azure-SiteName
Azure-RegionName
Azure-SlotName
Azure-Version
X-FC-Vary-Parameters
Azure-InstanceId
X-From
X-Oss-Hash-Crc64ecma
X-IP
X-Human
Origin-Cache-Control
Cache-Name
X-NWS-UUID-VERIFY
Selected-Fe
S-Rt
NGX
Origin-Edge-Control
L5d-Success-Class
Fastly-SSL
X-Drupal-Cache-Contexts
X-Cache-Time
X-Akamai-Request-ID2
X-Akamai-Request-ID
X-Labrador-Cache-Channel
X-Hosted-By
X-Oss-Storage-Class
X-Redis-Cache
X-Proxy
X-Proto
X-Real-IP
X-ServerID
X-Web-Node
X-UUID
X-TNCMS
X-Timing-Wait
X-Oss-Server-Time
X-Proxy-Build
X-Origin-Response-Time
X-Oss-Object-Type
X-Origin
X-Oss-Request-Id
X-Loop
X-Access
Viewport
X-Vgn-Hpd-Reason
X-Www-Served-By
X-JoinUs
S-Cnection
X-Site-Version
X-ApacheServer
X-Locale
X-Format
X-FireWall-Port
X-PERF
X-Generated
X-Content-Age
X-Backend-Name
X-Section
X-Cluster-Name
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Rendered-As
Decoy-Debug-TTL
Ec-Rule-Version
Decoy-Debug-Status
Decoy-Debug-Key
X-VCache
X-Info
X-Time-Microsecs
X-Varnish-Hits
X-Is-Bot
X-ORACLE-APMCS-TAG
X-ORACLE-APMCS-REQUEST-ID
X-Storage
X-ProxyCache-Status
Uber-Trace-Id
X-Guploader-Uploadid
X-ProxyCache-Key
X-BYPASS-REASON
Rt-Fastcgi-Cache
X-Origin-TTL
X-Origin-CC
X-URL
X-Cache-Backend
X-Generated-By
X-App-Version
X-PHP-Host
Cteonnt-Length
Cache-Key
X-Amzn-Remapped-Content-Length
X-WA-Info
X-Accel-Buffering
Akamai-GRN
Time
X-SS-Set-Cookie
Vix-Hermes-Req-Id
Cache-Hits
X-GoCache-CacheStatus
X-NCache
X-CF-Powered-By
X-Hit
X-Nginx-Cache-Key
X-Backend-TTL
X-Trace-Id
Origin
X-SaId
X-Cache-Remote
X-FB-TRIP-ID
Accept-Language
X-No-Session
GEO-INFO
X-Environment-Context
X-MServer
X-L-Path
X-Presslabs-Stats
X-Device-Type
X-B3-SpanId
X-CS
X-Cache-Grace
X-Tumblr-Pixel-3
X-Geo
X-B3-Traceid
X-Tb
Access-Control-Request-Headers
X-APP-VERSION
X-SayCDN-TTL
X-OVcl
X-Say-TTL
X-OVcl-Cache
X-Say-Cacheable
X-S
Srv
X-Cluster-Node
X-CACHE-KEY
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
X-Uri
X-CDN-Forward
User-Cache-Control
X-Via-CDN
Fastcgi-X-Cache-Version
X-Rewrite-Enabled
X-Connection-Hash
X-D
MD5-Digest
X-AIR-PT
X-CF-Lambda-Fn
X-Aed
We-Hiring
X-Application
X-ARC
Machine
X-CF-Lambda-Version
X-B-Cookie
Meta-Geo-Continent
Mail-Subject
X-S-Cookie
X-Alternate-Cache-Key
AsisCache
BehaviorPad-Version
VivaBuild
Node
Arc-Country
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Viewtype
T-Server
Request-EU
Content-Style-Type
Cross-Origin-Window-Policy
Content-Script-Type
Request-Country
Server-Host
Rendered-Blocks
Apple-News-Services-Host
Apple-News-Services-Handled
X-ShardId
X-ShopId
X-A-Dcw
Rt-Proxy-Cache
ServedBy
X-A-Wwc
X-A-Dgt
X-Shopify-Stage
X-ScT
Mobile-Detection-Method
X-A
X-A-Ccd
X-A-Dam
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Accel-Expires-Debug
X-Request-UUID
X-G
X-Unique-Id
X-CSRF-TOKEN
X-External-Request-Id
X-Trv-Group
X-Svr
X-DPWN-IS-SECURE
X-PAYTM-SRV-ID
X-Service
Xc-Version
X-Transaction
X-Ah-Environment
X-Rojux
NtCoent-Length
X-Hl-Ver
X-Region-Sid
X-Processor
X-Vtex-Processado-Em
X-EC-Lua
X-VG-WebServer
X-VG-WebCache
X-Date
X-Twitter-Response-Tags
IsBot
X-Server-Time
X-Session-Fingerprint
X-Vtex-Remote-Cache
X-Detected-As
X-Destination
X-SRCache-Key
Mime-Version
X-SIPLIST1
X-Dc
ServerName
OT-Force-Account-Verify
Now
X-Proxy-Upstream
X-Proxy-Cache-Status
Wxu-Next-Hostname
X-Ms-Request-Id
X-Ms-Version
Kp-EeAlive
X-RateLimit-Remaining-Second
X-Reboot
Thinkindot-Control
Thinkindot-CacheControl
Served-By
X-Thinkindot-L3
RNT-Time
X-NX-Host
RNT-Machine
Wxu-Next-Commit
Web-Mar-Node
Server-Int
X-Level-Front-Cache
X-Endurance-Cache-Level
X-Dispatcher-Server
X-Cache-Info
X-Request-URI
X-Cache-Debug
X-Gen-Mode
X-Dispatch
X-Clara-WADP
X-CUA
X-Debug-Cookies
X-Debug-Log
X-Core-Value
X-Cms-Context
X-RateLimit-Limit-Second
X-Cache-Bucket
X-Block-Status
X-Reqid
X-WADP-Cache
X-S-Maxage
X-Location
X-User
Wxu-Next-Region
X-Instart-Isnd
X-IN-APIGATEWAYSSL
X-Generated-On
X-Webstats-RespID
X-Hash
X-Hnp-Log
X-IN-APIGATEWAY
X-Matched-Rule
Thinkindot-CacheControl-Type
CDCHOST
X-Varnish-Beresp-Ttl
X-Shopify-Generated-Cart-Token
X-UnsetCookies
Proxy-Connection
Cache-Host
X-Varnish-Beresp-Status
Hostname
X-Varnish-Beresp-Grace
X-Nc
X-FW-Version
X-B3-Parentspanid
X-SVT-ORM-RULES
X-Distributor
X-Distil-CS
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-Debug-Cache-Store
X-Developers
X-Thanos
X-Swa-Ws
X-SVT-ORM-VERSION
X-Compress-Hint
X-Backend-State
X-BBXSRF
X-Bip
X-Variation
X-VC-Cache
X-Auto-Login
X-Azure-Ref
X-Azure-Ref-OriginShield
X-C
X-Cache-FS-Status
X-TrackingId
X-Clientip
X-Sucuri-Cache
X-CGP
X-Cache-URL
X-Cache-Id
X-Up
X-Core-Mission
X-Skip-Cache
X-Scheme
Ha-Gx-Prefs
X-Rocket-Build-Number
X-Method
X-Magnolia-Registration
X-Li-Pop
X-LI-UUID
X-Logging-Id
X-Old-Content-Length
X-Origin-Date
X-Request-Start
X-Qloud-Router
X-Release
X-Policy
X-Platform-Server
X-Origin-Expires
X-Owner
X-Li-Fabric
X-SD-PageType
X-Sigma
X-Parent-Response-Time
X-Generated-In
X-Sigma-Backend
X-Fastly-Cache
X-Eu-Site
X-VG-TLSProxy
X-Generation-Time
X-Geo-Header
X-Is-Gdpr
X-JWT-State
X-Key
X-Irp-Debug
X-Server-IP
X-GeoIP-City
X-Has-Esi
X-Epic-Correlation-Id
X-Cdn-Srv
Countrycode
X-App-Name
Section-Io-Cache
SD-X-WS
Esi-Enabled
True-Client-Country-4JS
X-Wikidot-Static-Cache
AKAMAI
X-WebServer
X-Wikidot-Backend
W
X-Vdms-Version
Fastly-Soc-X-Request-Id
Is-Eu
Gh-Request-Id
IBM-Web2-Location
Heartbleed
HA-Ipaddr
L
Magicmarker
Pramga
Platform
PFcat
Memcached
Adler-Geo
Content-Disposition
X-Agile-Age
X-We-Are-Hiring
X-VServer
X-Agile-Id
X-Agile
X-Amz-Meta-Cache-Control
Cache-Provider
V-Age
X-ServiceProvider
X-NodeID
X-Urbn-Site-Id
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
Cdncip
X-Planisys-CDN-Cache
X-Urbn-Context-Path
X-Internal-Host
X-MSEdge-Features
Locale
X-7Graus-Varnish-Cache-Control
X-MSEdge-Flight
X-7Graus-Varnish-XKeys
Cdnsip
X-AK-Request-ID
X-LI-Proto
X-RCS-CacheZone
X-NC
X-Cdn-Forward
Server-ID
X-Source
Tcn
X-Via-NSCOPI
X-Upstream-Ht
Powered-By-ChinaCache
X-Upstream-Ct
X-COUNTRY
X-SRV
X-ND-Cache
X-Developer
A
X-Sucuri-Id
X-GRACE
X-Servername
X-Trafficlayer-App-Version
X-Sn-Servicetimems
X-Be
X-B3-Spanid
X-Cdn-Origin
GEO-REGION-INFO
X-Device-Os
X-Nginx-Cache
CF-IPCountry
Environment
X-TIME
X-FPC
Geo-Info
X-Lb-Id
X-Node-Id
X-Req
Locid
X-FORWARDED-FOR
X-VHOST
X-Zone
X-Microcachable
FNAC-ModuleRouting
X-Served-From
X-Gamma-Serve
X-Servedbyhost
X-Webkit-CSP
X-Newrelic-Synthetics
X-Refresh
Request-Time
ProcessTime
X-Sucuri-ID
X-Pjax-Url
X-Tb-Optimization-Total-Bytes-Saved
X-HTML-Minification-Powered-By
Resin-Trace
X-IPS-LoggedIn
X-AWS-Id
CF-Cached-On
X-Pf-Uncompressing
X-Render-Time
X-LJ-Flow-ID
Memory
X-VWS-Id
X-ECACHE
X-ElasticPress-Search
X-Instart-Info
X-VCL-Version
X-NU-AKA-ACS-Version
Group
X-Edge-O15-RID
Gannett-Cam-Experience-Id
X-Unique-ID
Cf-Ipcountry
X-Correlation-ID
TTL
X-Var-Ttl
Pics-Label
XServer
X-GeoIP-Country-Code
X-NGENIX-Cache
Geoip-City
X-DC
X-Backend-Host
GeoIp-Country-Code
X-Ratelimit-Remaining
X-Backend-Url
Amp-Access-Control-Allow-Source-Origin
Geoip-Latitude
X-CSRF-Token
X-Pod
Backend-Name
MIME-Version
X-Bc
X-Mode
X-MP-GENERATED-AT
X-Via-Edge
Cdn
X-Via-SSL
Lfy
GeoIP-City
GeoIP-Latitude
REQUESTUUID
Pagetype
GeoIP-Country-Code
PICS-Label
N-Cache
X-ZONE
X-Vcl-Version
X-GEO
Ttl
Cache-Prefix
X-APP
X-Check-Cacheable
Fly-Request-Id
Fly-Cache
M-TraceId
X-CLOUD-TRACE-CONTEXT
Host-ID
X-Worker
Ohc-Cache-HIT
X-Via-Ucdn
HostName
Ohc-File-Size
X-Fstrz
X-Zipkin-Id
X-Proxied
X-Routing-Service
X-Cache-Miss-From
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-Idcheck
X-HostName
X-PF-Uncompressing
X-Sedo-Request-Id
HitType
Cache-Cookie-Set-From
X-Swift-Error
X-Ratelimit-Limit
X-Upstream-CT
X-Cdn-Request-ID
X-BC
X-LiteSpeed-Cache-Control
X-PJAX-URL
X-Upstream-HT
X-HS-Status
X-Fastly-Country-Code
X-Server-W
X-Fetched-On
SRV
X-Dynatrace-Js-Agent
X-TH-Server
X-Rebelmouse-Surrogate-Control
User-Agent
X-ServedByHost
Fastly-SWR
URI
Fastly-SIE
On-Server
Pragrma
X-Rebelmouse-Cache-Control
X-Cache-Tag
X-Wa
X-NGINX-Cache
Powered-By
X-WR-MODIFICATION
X-UPSTREAM-Address
X-Aicache-OS
X-Tt-Trace-Tag
X-Request-Time
CDN
Who
X-TT-LOGID
X-WA
CACHE
X-RateLimit-Reset
X-GDPR
Media-Length
X-LB-ID
X-BE
Dynatrace
X-Fastly-Backend-Reqs
X-Edge-Server
X-Fpc
X-ServerName
X-Varnish-Cacheable
Cdn-Request-Time
Cdn-Host
X-LAGOON
X-Varnish-URL
DataCenter
X-Cf-Powered-By
FSS-Cache
FSS-Proxy
Is-Session-Tracking
Get-Access-Time
LB
X-Hello
Debug
X-Flog
Server-Id
SS
X-ABtesting
X-SN
X-Ftr-Cache-Host
X-Ua
X-Response-By
X-RPS
X-Org
SN
X-Tt-Trace-Host
X-Gen-Id
X-Protected-By
X-RSL
X-Varnish-Beresp-TTL
X-RPM
AR-SID
X-DB
X-DSS
X-DI
X-Action
X-DW
X-VC
Warning
Xet-Cookie
X-LiteSpeed-Tag
X-SB
XxX-Cache-Status
UCS
X-Li-Proto
Requestid
Cneonction
SID
X-Fastly-Cache-Hits
Product
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-Request-Url
X-Amzn-Remapped-Connection
Thinkindot-Cache-Type
RequestId
X-Amzn-Remapped-Date
NnCoection
Application
X-Dw-Trace-Id
X-Nananana