Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
CF-RAY
CF-Cache-Status
Pragma
Link
X-Powered-By
ETag
Expect-CT
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Xss-Protection
X-Varnish
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
Alt-Svc
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Request-ID
Content-Security-Policy-Report-Only
X-Generator
X-Cache-Status
X-Cacheable
X-Permitted-Cross-Domain-Policies
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Template
X-Iinfo
X-Language
X-AspNetMvc-Version
X-Content-Security-Policy
Status
Content-Encoding
X-Buckets
Access-Control-Expose-Headers
Upgrade
X-CDN
Xkey
X-Kinja-Server-Push
Access-Control-Max-Age
Keep-Alive
X-Drupal-Dynamic-Cache
X-Turbo-Charged-By
X-Via
X-Ua-Compatible
X-Cache-Group
X-Age
X-Pass-Why
X-Envoy-Upstream-Service-Time
X-Backend
EagleId
X-AH-Environment
X-Server
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Page-Speed
X-Pingback
X-Server-Powered-By
X-UA-Device
X-Swift-CacheTime
X-Swift-SaveTime
X-Proxy-Cache
X-Hacker
Ali-Swift-Global-Savetime
X-Nginx-Cache-Status
Request-Context
Grace
X-Varnish-Cache
Server-Timing
Feature-Policy
Cf-Railgun
X-Amz-Version-Id
X-Device
X-LiteSpeed-Cache
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-WebKit-CSP
X-Rq
Report-To
X-Ac
EagleEye-TraceId
X-Response-Time
X-Server-Id
X-OneAgent-JS-Injection
X-Host
Request-Id
X-Cnection
X-Backend-Server
X-DataDome
Content-Location
X-Node
X-Cloud-Trace-Context
X-Origin-Cache
X-Readtime
X-Cache-Lookup
NEL
X-Vhost
P3p
X-Application-Context
X-Dispatcher
X-ORACLE-DMS-ECID
X-HW
X-Cdn
Allow
X-Dns-Prefetch-Control
X-ORACLE-DMS-RID
X-Clacks-Overhead
X-Rack-Cache
X-Ws-Request-Id
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Origin-Upstream-Status
Surrogate-Control
X-Country
Rating
X-DynaTrace
X-FTR-Request-ID
X-Country-Code
X-Goog-Hash
Fusion-Content-Source
Fusion-Template-Id
Fusion-Source
Fusion-Content-Id
Fusion-Component-Id
X-Akam-SW-Version
Pinterest-Generated-By
X-Varnish-TTL
X-Vname
X-PC
X-TtlSet
X-Instart-Request-ID
X-Ruxit-JS-Agent
X-MS-InvokeApp
X-Url
Edge-Control
Verso
X-Mod-Pagespeed
X-Powered-By-Plesk
SPRequestGuid
Accept-Ch
X-B3-TraceId
X-D2id
X-Trace
X-Sol
X-Middleton-Response
Pagespeed
Response
X-Middleton-Display
Display
X-SharePointHealthScore
RTSS
X-VARITI-CCR
X-Exp-Variant
X-Exp-Id
X-Kinja
X-Use-Magma
X-Kinja-Server
X-Kinja-Revision
X-Kinja-Build
X-GoogleNews-Bot
X-Cdn-Fetch
Service-Worker-Allowed
X-Server-Name
X-Server-ID
X-GitHub-Request-Id
X-Vcache
SPRequestDuration
SPIisLatency
X-Navigation-Version
X-Powered-CMS
Content-MD5
X-Debug
X-ESI
X-Abt-Application-Version
X-Vcap-Request-Id
X-CST
Accept-Ch-Lifetime
X-Amz-Server-Side-Encryption
Public-Key-Pins
Charset
MS-Author-Via
X-Upstream
X-Forwarded-Proto
X-TTL
X-Version
X-Px
X-NF-Request-ID
X-Cached
X-Amz-Rid
DynaTrace
Realpath
X-Shard
Edge-Cache-Tag
Fastly-Restarts
TCN
MicrosoftSharePointTeamServices
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
Arr-Disable-Session-Affinity
X-Ezoic-Cdn
X-Recruiting
X-MSEdge-Ref
Access-Control-Request-Method
X-Pinterest-Rid
Pinterest-Version
X-Shield-Request-Id
X-DynaTrace-JS-Agent
X-XRDS-Location
X-SRCache-Store-Status
X-Ser
X-SRCache-Fetch-Status
S
X-Fastly-Request-ID
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Metageneration
Nginx-Cache
Front-End-Https
X-Accel-Expires
X-DIS-Request-ID
X-Amz-Meta-S3cmd-Attrs
X-Goog-Storage-Class
X-Client-IP
X-Ttl
X-Id
X-Varnish-Age
X-Element-Page-Cache
X-Trafficlayer-App-Name
X-Trafficlayer-App-Scope
X-T
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
X-FTR-Realm
X-FTR-Cache-Status
X-FTR-DC
X-FTR-Backend
X-FTR-Backend-Server
X-FTR-Balancer
X-Country-Code-Real
X-FTR-Expires
X-Amzn-Trace-Id
X-Dw-Request-Base-Id
Fastcgi-Cache
X-RateLimit-Remaining
Cache-Tag
X-HS-Hub-Id
NR-ENABLED
X-HS-Content-Id
X-Content-Digest
X-Frontend
X-Hits
Powered
X-Correlation-Id
X-Kinsta-Cache
X-HS-Cache-Config
X-Litespeed-Cache
X-Fastcgi-Cache
X-Grace
X-FTR-Cache-Host
ServerID
X-Webapp-Samesite-None-Activated-N
X-Aspnetmvc-Version
X-Webkit-Csp
TP-Cache
Alternate-Protocol
TP-L2-Cache
X-Cache-Hit
X-Hp-Webp
X-Node-Name
X-Request-Processing-Time
X-Request-Received
X-Ah-Environment
X-Microsite
X-N
X-Request-Handler-Origin-Region
PB-RID
PB-PID
AR-CACHE
AR-ATIME
X-Mobile-Rewrite
Arc-Version
AR-PoweredBy
AMP-Access-Control-Allow-Source-Origin
Ar-Sid
Server-Name
X-Zen-Fury
X-Content-Type
X-Rid
X-Forwarded-For
X-User-Agent
Healthy
X-Revision
Server-Node
X-Analytics
Backend-Timing
X-FastCGI-Cache
X-Content-Security-Policy-Report-Only
X-LB-Cache
X-Akamai-Edgescape
X-Activity-Id
X-AppVersion
X-Az
X-HS-Combine-CSS
Cache-Status
X-Logged-In
Retry-After
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Oneagent-Js-Injection
X-IPLB-Instance
X-GUploader-UploadID
X-Cached-By
X-Pad
X-NWS-LOG-UUID
Accept-CH
X-Via-JSL
X-Type
Accept-CH-Lifetime
X-Srv
Paypal-Debug-Id
X-Varnish-Grace
X-Mobile-URL
X-Ruxit-Js-Agent
X-B3-Sampled
FilterID
X-F-Cache
Refresh
AR-Request-ID
X-Content-Options
X-Cache-Age
X-Geo-Country
X-Tumblr-Pixel-0
Accept-Charset
X-Tumblr-User
X-FB-Debug
X-Tumblr-Pixel
X-Instance
X-Debug-Info
X-Page-Id
Upgrade-Insecure-Requests
X-Cluster
X-Request-Guid
Access-Control-Allow-Method
X-AOL-HN
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
Actual-Object-TTL
Host
Source
X-Jobs
X-B
X-PHP-Backend
X-Esi
X-Framework
X-App-Environment
X-Varnish-Backend
DC
X-Seen-By
X-WebKit-CSP-Report-Only
X-PressLabs-Stats
X-ATG-Version
X-Cache-Key
MS-CV
Fastcgi-Useragent
X-Whom
X-Content-Powered-By
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-TT
X-Git-Hash
X-Cache-2
X-Host-Name
X-Cache-Control
Cache
X-Amz-Replication-Status
X-Cache-TTL
Surrogate-Key
X-Wix-Request-Id
X-TA-CDN-Provider
X-Cache-Operation
X-Cache-Rule
Frame-Options
X-Signature
X-B-Cache
X-FW-Serve
NGB
Host-Header
X-Daa-Tunnel
X-FW-Server
X-FW-Hash
X-Response-Served-From
X-FW-Type
X-FW-Static
X-Kong-Proxy-Latency
X-Forwarded-Host
X-Time
X-Kong-Upstream-Latency
Xserver
X-Origin-Server
X-UA
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
Cache-Tv-Group
X-Mobile
Cleartype
X-Hyper-Cache
X-Region
X-TX-ID
X-Cache-NE
WPE-Backend
Eomportal-Instance
Payment
Webserver
X-Cache-Action
Filters
X-Adobe-Loc
X-Drupal-Cache-Tags
X-GeoIP
X-Handled-By
X-Adobe-Content
X-Cacheable-TTL
X-RequestSource
X-SERVER
From-Origin
X-UA-Device-Type
X-Cache-Enabled
X-RemovedCookies
X-ProcessESI
X-EdgeConnect-Cache-Status
X-App-Server
X-RTag
Ms-Operation-Id
Datacenter
Tracecode
X-Cache-TTL-Remaining
X-Akamai-Transformed
X-NewRelic-App-Data
X-Load-Cache
X-Hostname
X-Status
X-Contextid
X-Cache-Server
Liferay-Portal
X-Yottaa-Optimizations
X-B3-Traceid
X-Edge-Location
X-Yottaa-Metrics
X-BCube-Filmed-By
X-TT-TIMESTAMP
X-RateLimit-Limit
X-Varnish-Hostname
Odigeo-Trace-Id
Server-Info
X-Rule
X-Varnish-Server
X-FW-Dynamic
Meta-Geo
X-ES-SERVER
X-Path-Route
X-Cache-Var-Map
Load-Balancing
X-RN-RSRV
X-Cache-Var
X-Viewer-Country
Country
X-Xfnlog-Site
X-UUID
X-OCL
X-IP
X-Rocket-Nginx-Bypass
DB-Nickname
Cache-Tags
X-Via-Fastly
X-PCL
X-Cache-Config
Version
X-CCM
L5d-Success-Class
X-Drupal-Cache-Contexts
X-Redis-Cache
X-Origin
X-ServerID
X-R9-Blue-Green-Version
X-Origin-Response-Time
Fastly-SSL
X-Proto
X-TNCMS
X-Info
X-FC-Vary-Parameters
S-Rt
X-From
Azure-SlotName
Azure-SiteName
X-Proxy
X-Origin-CC
Azure-Version
X-Debug-Cache
X-Hosted-By
Cache-Name
X-Akamai-Request-ID
X-Cache-Time
Azure-RegionName
X-ATS-Timestamp
X-Pubstack
Azure-InstanceId
X-Real-IP
X-Upgrade-Enabled
X-Loop
X-Web-Node
X-Origin-TTL
X-Labrador-Cache-Channel
Decoy-Debug-TTL
X-Rendered-As
Decoy-Debug-Key
Ec-Rule-Version
Decoy-Debug-Status
Mn-Server-Ip
X-Origin-Hint
X-Backend-Name
X-JoinUs
X-Generated
TWC-Locale-Group
X-ApacheServer
TWC-GeoIP-LatLong
TWC-Privacy
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Access
Webcakes-Region
Webcakes-App-Name
X-EIG-Tracking-Id
Viewport
X-Format
X-Cache-Host
S-Cnection
TWC-Connection-Speed
Property-Id
Origin-Edge-Control
Origin-Cache-Control
TWC-Device-Class
TWC-GeoIP-Country
X-FireWall-Port
X-Cluster-Name
X-Human
Webcakes-App-Version
X-Content-Age
X-Www-Served-By
X-Varnish-Cache-Hits
X-Section
X-XRDS-LOCATION
X-PERF
X-Proxy-Build
Selected-Fe
Release
NGX
X-Timing-Wait
X-Soup
X-Varnish-Hits
X-Vgn-Hpd-Reason
X-VCT
X-Time-Microsecs
X-VCache
X-Akamai-Request-ID2
X-NWS-UUID-VERIFY
X-Locale
DSUID
X-Site-Version
X-Storage
X-Oss-Storage-Class
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Is-Bot
Rt-Fastcgi-Cache
X-BYPASS-REASON
Cache-Key
X-ProxyCache-Key
X-ProxyCache-Status
Uber-Trace-Id
X-WA-Info
Cteonnt-Length
X-PHP-Host
Vix-Hermes-Req-Id
X-ORACLE-APMCS-TAG
X-ORACLE-APMCS-REQUEST-ID
X-GoCache-CacheStatus
X-Cache-Backend
X-NCache
X-Amzn-Remapped-Content-Length
X-Hit
Cache-Hits
X-Generated-By
X-App-Version
X-SS-Set-Cookie
X-Cache-Grace
X-Guploader-Uploadid
Akamai-GRN
Time
X-Cache-Remote
X-Backend-TTL
GEO-INFO
Origin
X-Accel-Buffering
X-APP-VERSION
X-CS
X-Trace-Id
X-Nginx-Cache-Key
X-Tumblr-Pixel-3
X-Device-Type
Accept-Language
X-No-Session
X-L-Path
X-OVcl-Cache
X-OVcl
X-Environment-Context
X-S
X-CF-Powered-By
X-Tb
X-FB-TRIP-ID
X-SaId
Hostname
X-MServer
X-Uri
X-URL
X-B3-SpanId
X-Cluster-Node
X-Say-Cacheable
X-Via-CDN
X-UnsetCookies
X-SayCDN-TTL
X-Say-TTL
Fastcgi-X-Cache-Version
Mime-Version
X-Presslabs-Stats
X-CACHE-KEY
X-Tec-Api-Root
X-Tec-Api-Origin
X-Tec-Api-Version
User-Cache-Control
ServerName
Now
Access-Control-Request-Headers
X-CSRF-TOKEN
X-Geo
Rt-Proxy-Cache
Request-EU
Rendered-Blocks
T-Server
Request-Country
X-A-Ccd
X-A-Dcw
X-A-Dgt
X-A-Dam
Node
VivaBuild
X-A
Viewtype
MD5-Digest
Arc-Country
AsisCache
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
Apple-News-Services-Host
BehaviorPad-Version
Content-Script-Type
X-A-Wwc
Meta-Geo-Continent
Machine
IsBot
Content-Style-Type
Cross-Origin-Window-Policy
Mobile-Detection-Method
X-Aed
X-Session-Fingerprint
X-SIPLIST1
X-SRCache-Key
X-Server-Time
X-ScT
X-Rewrite-Enabled
X-Rojux
X-S-Cookie
X-Svr
X-Transaction
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-VG-WebServer
X-VG-WebCache
X-Trv-Group
X-Twitter-Response-Tags
X-Request-UUID
X-Region-Sid
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Connection-Hash
X-B-Cookie
X-ARC
X-AIR-PT
X-Application
X-Date
X-Destination
X-Hl-Ver
X-PAYTM-SRV-ID
X-Processor
X-G
X-External-Request-Id
X-Detected-As
X-DPWN-IS-SECURE
X-Accel-Expires-Debug
X-D
X-FW-Version
X-Endurance-Cache-Level
X-Proxy-Cache-Status
X-NC
X-Cache-Debug
X-Proxy-Upstream
X-Cache-Bucket
Proxy-Connection
X-Request-URI
X-CDN-Forward
RNT-Time
X-Reboot
X-Cache-Info
X-S-Maxage
CDCHOST
X-Hnp-Log
X-Debug-Cookies
X-Debug-Log
OT-Force-Account-Verify
X-Gen-Mode
X-Core-Value
X-Cms-Context
X-NX-Host
X-Matched-Rule
X-Clara-WADP
X-Location
X-Block-Status
RNT-Machine
Mail-Subject
Thinkindot-CacheControl-Type
We-Hiring
Thinkindot-CacheControl
X-Thinkindot-L3
Server-Int
X-WADP-Cache
Srv
X-Service
Web-Mar-Node
Thinkindot-Control
X-B3-Parentspanid
X-Sorting-Hat-PodId
X-Shopify-Stage
X-Sorting-Hat-ShopId
X-ShardId
X-ShopId
NtCoent-Length
X-Alternate-Cache-Key
X-Debug-Cache-Expiry
X-Parent-Response-Time
X-7Graus-Varnish-Cache-Control
X-Distil-CS
X-Distributor
X-Epic-Correlation-Id
X-Developers
X-Core-Mission
X-Debug-Cache-Store
X-7Graus-Varnish-XKeys
X-Debug-Cache-Fetch
X-Cache-URL
X-Azure-Ref-OriginShield
X-Azure-Ref
X-C
X-Eu-Site
X-BBXSRF
X-Backend-State
X-Auto-Login
X-Cache-FS-Status
X-CGP
X-Clientip
X-Cdn-Srv
X-Amz-Meta-Cache-Control
X-Cache-Id
X-App-Name
X-Compress-Hint
X-Key
X-Server-IP
X-Skip-Cache
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-SD-PageType
X-Scheme
X-Policy
X-Release
X-Reqid
X-Request-Start
X-TrackingId
X-Unique-Id
X-We-Are-Hiring
X-WebServer
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-VServer
X-VG-TLSProxy
X-Up
X-User
X-Variation
X-VC-Cache
X-Platform-Server
X-Origin-Expires
X-IN-APIGATEWAYSSL
X-Irp-Debug
X-Is-Gdpr
X-JWT-State
X-IN-APIGATEWAY
X-Has-Esi
X-Generated-In
X-Generated-On
X-Generation-Time
X-Geo-Header
W
X-Level-Front-Cache
X-Ms-Request-Id
X-Ms-Version
X-Old-Content-Length
X-Origin-Date
X-Method
X-Magnolia-Registration
X-Li-Fabric
X-Li-Pop
X-LI-UUID
X-Fastly-Cache
X-GeoIP-City
PFcat
Memcached
Magicmarker
L
Platform
X-Varnish-Beresp-Ttl
ServedBy
Section-Io-Cache
SD-X-WS
X-Varnish-Beresp-Status
Kp-EeAlive
Is-Eu
Countrycode
Content-Disposition
Cache-Host
AKAMAI
Esi-Enabled
Fastly-Soc-X-Request-Id
IBM-Web2-Location
HA-Ipaddr
Ha-Gx-Prefs
Gh-Request-Id
Server-Host
Adler-Geo
X-Varnish-Beresp-Grace
True-Client-Country-4JS
X-Dc
X-Nc
Cache-Provider
X-MSEdge-Features
Locale
Wxu-Next-Region
X-CUA
X-Qloud-Router
X-RateLimit-Limit-Second
X-Webstats-RespID
Wxu-Next-Hostname
X-Developer
X-MSEdge-Flight
X-LI-Proto
X-Instart-Isnd
X-Swa-Ws
X-Hash
Heartbleed
X-Internal-Host
V-Age
X-Agile
X-Dispatch
X-Dispatcher-Server
X-Logging-Id
X-Owner
X-Cdn-Forward
X-Urbn-Site-Id
Pramga
X-Vdms-Version
A
X-RateLimit-Remaining-Second
X-Bip
X-Agile-Age
Wxu-Next-Commit
X-Thanos
Served-By
X-ServiceProvider
X-Urbn-Context-Path
X-Agile-Id
X-Shopify-Generated-Cart-Token
Server-ID
X-Sigma
X-AK-Request-ID
X-B3-Spanid
X-Sn-Servicetimems
X-Cdn-Origin
X-NodeID
Cdnsip
X-Sigma-Backend
Cdncip
X-Rocket-Build-Number
X-Sucuri-Cache
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Servername
X-Device-Os
X-Node-Id
CF-IPCountry
X-Sucuri-Id
X-EC-Lua
X-Planisys-CDN-TTL
X-GRACE
Powered-By-ChinaCache
GEO-REGION-INFO
X-Upstream-Ht
X-Via-NSCOPI
X-Upstream-Ct
X-RCS-CacheZone
Environment
X-FPC
X-ND-Cache
X-Lb-Id
X-Source
X-Nginx-Cache
X-Servedbyhost
X-Be
X-Trafficlayer-App-Version
X-VHOST
X-SRV
X-Zone
X-Microcachable
Tcn
Request-Time
X-Newrelic-Synthetics
X-Webkit-CSP
Geo-Info
Resin-Trace
X-Tb-Optimization-Total-Bytes-Saved
X-Req
Locid
X-Instart-Info
FNAC-ModuleRouting
X-NGENIX-Cache
X-Pjax-Url
X-ElasticPress-Search
X-Served-From
X-Oracle-Dms-Rid
X-Gamma-Serve
X-ECACHE
X-FORWARDED-FOR
X-Refresh
X-Backend-Url
X-Pf-Uncompressing
X-Sucuri-ID
X-TIME
Group
X-Backend-Host
X-VCL-Version
X-Dynatrace
X-IPS-LoggedIn
X-COUNTRY
Memory
X-GEO
X-Var-Ttl
ProcessTime
Gannett-Cam-Experience-Id
X-DC
CF-Cached-On
Backend-Name
X-Unique-ID
X-Correlation-ID
X-HTML-Minification-Powered-By
X-LJ-Flow-ID
X-Ratelimit-Remaining
N-Cache
X-VWS-Id
Amp-Access-Control-Allow-Source-Origin
X-AWS-Id
X-Render-Time
TTL
Pics-Label
Cf-Ipcountry
X-NU-AKA-ACS-Version
Lfy
Fly-Request-Id
Fly-Cache
X-Pod
PICS-Label
X-Check-Cacheable
Pagetype
Cache-Prefix
X-Bc
GeoIp-Country-Code
Geoip-City
GeoIP-Latitude
Geoip-Latitude
X-Via-SSL
REQUESTUUID
Ttl
X-GeoIP-Country-Code
GeoIP-Country-Code
X-Via-Edge
GeoIP-City
X-CSRF-Token
X-Worker
M-TraceId
Ohc-Cache-HIT
SRV
XServer
Ohc-File-Size
X-Via-Ucdn
Cdn
X-Sedo-Request-Id
X-Upstream-HT
X-Cache-Miss-From
X-Upstream-CT
X-APP
MIME-Version
X-Mode
X-CLOUD-TRACE-CONTEXT
X-Fstrz
X-Fetched-On
X-LiteSpeed-Cache-Control
X-Vcl-Version
X-Server-W
X-MP-GENERATED-AT
X-ZONE
X-Rebelmouse-Surrogate-Control
Fastly-SIE
X-Wa
Fastly-SWR
X-Rebelmouse-Cache-Control
X-Fastly-Country-Code
X-PF-Uncompressing
HitType
X-Ratelimit-Limit
HostName
X-HS-Status
Cache-Cookie-Set-Lfrom
Host-ID
Cache-Cookie-Set-From
Cache-Cookie-Set-Idcheck
X-Dynatrace-Js-Agent
User-Agent
Pragrma
On-Server
X-PJAX-URL
X-BC
X-Zipkin-Id
X-HostName
X-Routing-Service
X-Swift-Error
X-Proxied
X-GDPR
URI
X-Tt-Trace-Tag
X-Cache-Tag
X-NGINX-Cache
X-Cdn-Request-ID
X-ServedByHost
X-Ua
X-Aicache-OS
X-WR-MODIFICATION
X-Edge-Server
Who
X-WA
X-TT-LOGID
X-TH-Server
Cdn-Host
Cdn-Request-Time
X-RateLimit-Reset
CACHE
X-Fastly-Backend-Reqs
CDN
X-SN
X-BE
X-Cf-Powered-By
X-ABtesting
X-Edge-O15-RID
Powered-By
X-Cache-Ttl
X-Hello
X-UPSTREAM-Address
X-Flog
Dynatrace
X-Varnish-URL
X-LAGOON
X-Action
X-DB
X-Org
X-RSL
X-Varnish-Cacheable
Media-Length
X-DSS
X-DW
SS
X-LB-ID
X-Response-By
X-Fpc
X-DI
X-RPM
X-RPS
DataCenter
X-Request-Time
X-ServerName
Debug
X-Ratelimit-Reset
Server-Id
LB
Is-Session-Tracking
Get-Access-Time
X-Upstream-Proxy
SN
X-Ftr-Cache-Host
X-Protected-By
X-Gen-Id
Requestid
X-Varnish-Beresp-TTL
NnCoection
RequestId
Country-Code
FSS-Cache
FSS-Proxy
Cneonction
XxX-Cache-Status
Correlation-Id
X-Page-Type
X-Nananana
X-Request-Url
X-Amzn-Remapped-Date
X-Amzn-Remapped-Connection
SID
X-Dw-Trace-Id
Thinkindot-Cache-Type
RequestUuid
X-Akamai-ERRuleID
X-Fastly-Cache-Hits
X-LiteSpeed-Tag
X-Li-Proto
Product
Application
X-Akamai-ERPolicy
Lb
Warning