Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-Powered-By
Pragma
CF-Cache-Status
Link
ETag
Expect-CT
Via
CF-RAY
Age
X-Cache
X-XSS-Protection
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-Xss-Protection
Referrer-Policy
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
P3P
X-UA-Compatible
X-Served-By
CF-Ray
Alt-Svc
X-Varnish
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-FRAME-OPTIONS
X-Drupal-Cache
X-Check
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Cacheable
X-Permitted-Cross-Domain-Policies
X-Generator
X-Cache-Status
P3p
X-DNS-Prefetch-Control
X-Ua-Compatible
Timing-Allow-Origin
X-Iinfo
X-Template
X-Language
Status
Upgrade
X-AspNetMvc-Version
X-CDN
X-Content-Security-Policy
X-Buckets
Content-Encoding
Access-Control-Expose-Headers
X-Kinja-Server-Push
X-Request-ID
Access-Control-Max-Age
Keep-Alive
X-Via
X-Envoy-Upstream-Service-Time
X-AH-Environment
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Pass-Why
X-Ws-Request-Id
X-Backend
X-Age
X-Server
X-Proxy-Cache
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
Xkey
EagleId
X-Page-Speed
Feature-Policy
X-Hacker
Request-Context
X-Server-Powered-By
X-Pingback
Server-Timing
X-Nginx-Cache-Status
Grace
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-UA-Device
X-Varnish-Cache
X-Amz-Version-Id
Report-To
Cf-Railgun
X-OneAgent-JS-Injection
X-Rq
X-LiteSpeed-Cache
X-Device
X-Origin-Cache
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
CONTENT-SECURITY-POLICY
X-Server-Id
X-Vhost
X-Host
EagleEye-TraceId
X-Dns-Prefetch-Control
X-Backend-Server
X-Node
X-Response-Time
X-Dispatcher
NEL
X-WebKit-CSP
X-Ac
X-Cache-Lookup
X-Origin-Upstream-Status
Request-Id
Surrogate-Control
X-Readtime
X-DataDome
Fusion-Source
Fusion-Content-Source
Fusion-Content-Id
X-Application-Context
Fusion-Template-Id
Fusion-Component-Id
Content-Location
X-ORACLE-DMS-ECID
X-HW
X-ORACLE-DMS-RID
X-Ruxit-JS-Agent
X-Cnection
X-Mod-Pagespeed
X-Country
X-Akam-SW-Version
Edge-Control
Rating
X-Rack-Cache
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Url
X-Clacks-Overhead
RTSS
X-Cloud-Trace-Context
Fusion-Deployment-Id
X-Goog-Hash
X-FTR-Request-ID
X-Country-Code
X-TtlSet
X-PC
X-Vname
X-DynaTrace
Allow
X-ASPNET-VERSION
X-Varnish-TTL
Verso
X-GitHub-Request-Id
Service-Worker-Allowed
X-MS-InvokeApp
X-Instart-Request-ID
Accept-CH
X-D2id
X-Cdn-Fetch
X-GoogleNews-Bot
X-Use-Magma
X-Kinja-Server
X-Kinja
X-Exp-Variant
X-Kinja-Build
X-Exp-Id
X-Kinja-Revision
X-Server-Name
X-Powered-By-Plesk
Pinterest-Generated-By
SPRequestGuid
Content-MD5
X-Forwarded-Proto
X-Cached
X-Navigation-Version
X-Amz-Server-Side-Encryption
Accept-CH-Lifetime
X-Trace
TCN
X-SharePointHealthScore
X-Amz-Rid
X-Abt-Application-Version
Public-Key-Pins
X-Fastly-Request-ID
X-Vcap-Request-Id
Nginx-Cache
X-ESI
X-MSEdge-Ref
X-Debug
SPRequestDuration
SPIisLatency
X-Ttl
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
Arr-Disable-Session-Affinity
X-VARITI-CCR
X-DynaTrace-JS-Agent
Charset
X-B3-TraceId
X-Vcache
NR-ENABLED
X-Accel-Expires
X-Cache-TTL
Pagespeed
X-Middleton-Response
X-Middleton-Display
Display
Response
MS-Author-Via
X-NF-Request-ID
X-Sol
X-Server-ID
X-Px
X-Content-Type
Realpath
X-Client-IP
WPE-Backend
Cache-Tag
Access-Control-Request-Method
S
X-Pinterest-Rid
Pinterest-Version
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Ser
X-Id
X-Grace
X-Powered-CMS
Edge-Cache-Tag
X-Shield-Request-Id
X-Hp-Webp
X-Jurisdiction
X-Webkit-Csp
Front-End-Https
X-T
X-Upstream
X-Amz-Meta-S3cmd-Attrs
X-Hits
X-Element-Page-Cache
AR-Request-ID
AR-ATIME
AR-PoweredBy
X-Dw-Request-Base-Id
X-Content-Digest
DynaTrace
X-Version
X-Node-Name
X-Fastcgi-Cache
X-Cache-Hit
X-Recruiting
Fastcgi-Cache
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
AMP-Access-Control-Allow-Source-Origin
ServerID
X-Mobile-URL
X-Request-Received
X-Request-Processing-Time
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Correlation-Id
X-Goog-Metageneration
X-GUploader-UploadID
X-Goog-Generation
X-FTR-Backend-Server
X-FTR-Backend
X-Country-Code-Real
Server-Node
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-Realm
X-FTR-DC
AR-CACHE
Ar-Sid
X-HS-Content-Id
X-HS-Hub-Id
X-Frontend
X-HS-Cache-Config
Accept-Ch
Powered
X-FTR-Expires
PB-RID
X-DIS-Request-ID
PB-PID
TP-L2-Cache
TP-Cache
X-Ezoic-Cdn
X-Shard
Upgrade-Insecure-Requests
Arc-Version
X-Mobile-Rewrite
X-Forwarded-For
Host-Header
Refresh
X-HS-Combine-CSS
X-TTL
Alternate-Protocol
Server-Name
X-XRDS-Location
X-Geo-Country
Fastly-Restarts
X-FastCGI-Cache
X-N
X-Amzn-Trace-Id
X-Request-Handler-Origin-Region
X-Microsite
Accept-Ch-Lifetime
X-NWS-LOG-UUID
X-LB-Cache
X-Rid
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Akamai-Edgescape
X-Page-Id
X-FTR-Cache-Host
X-User-Agent
X-B
X-F-Cache
Backend-Timing
X-ATS-Timestamp
X-Content-Security-Policy-Report-Only
X-Logged-In
X-Varnish-Age
X-Cache-Key
X-Aspnetmvc-Version
MicrosoftSharePointTeamServices
X-XRDS-LOCATION
X-Amzn-Requestid
X-Kinsta-Cache
X-Zen-Fury
Healthy
X-Revision
X-Cache-Age
X-Presslabs-Stats
X-ORACLE-APMCS-TAG
X-ORACLE-APMCS-REQUEST-ID
Paypal-Debug-Id
X-Origin-Server
X-Varnish-Backend
X-Varnish-Grace
X-Hostname
X-Jobs
X-Request-Guid
Fastcgi-Useragent
X-Git-Hash
X-Instance
X-App-Environment
X-Via-JSL
X-Tumblr-Pixel
X-Esi
X-Tumblr-Pixel-0
X-Tumblr-User
X-ATG-Version
X-B3-Sampled
X-Amz-Replication-Status
X-Type
X-TT
Actual-Object-TTL
X-B-Cache
X-Seen-By
Section-Io-Cache
X-Signature
X-WebKit-CSP-Report-Only
X-AOL-HN
X-Debug-Info
X-Cache-Action
X-FB-Debug
X-Whom
Host
Frame-Options
X-Cluster
Cache-Status
X-Contextid
X-Endurance-Cache-Level
Access-Control-Allow-Method
Source
X-Cache-Operation
X-Cache-Rule
X-Content-Options
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Host-Name
X-Content-Powered-By
Trailer
Accept-Charset
DC
Tracecode
X-SERVER
X-APP-VERSION
X-Activity-Id
X-Az
X-AppVersion
X-Upgrade-Enabled
X-IPLB-Instance
X-Daa-Tunnel
X-FireWall-Port
From-Origin
X-Amz-Apigw-Id
X-RateLimit-Remaining
Retry-After
X-Tt-Trace-Host
X-Tt-Trace-Tag
Liferay-Portal
X-Response-Served-From
X-Framework
NGB
X-Accel-Buffering
X-PHP-Backend
X-WA-Info
X-ProcessESI
X-RemovedCookies
X-FW-Server
X-UUID
X-FW-Static
X-FW-Type
X-TIME
X-Tumblr-Pixel-1
X-Tumblr-Pixel-2
X-FW-Serve
X-FW-Hash
Surrogate-Key
Payment
X-Time-Microsecs
X-Cacheable-TTL
X-Rendered-As
X-CST
X-Is-Bot
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
Eomportal-Instance
X-GeoIP
X-Region
X-Adobe-Loc
X-L-Path
X-RequestSource
X-Environment-Context
Filters
X-Wix-Request-Id
X-Adobe-Content
X-Mobile
X-Cache-NE
Srv
X-Varnish-Server
Filterid
X-Unique-Id
X-Proxy
X-Handled-By
GEO-INFO
X-UA-Device-Type
X-NGENIX-Cache
X-Cache-Control
X-Cache-Server
X-Origin-Response-Time
X-EdgeConnect-Cache-Status
Datacenter
Nel
X-Varnish-Hostname
X-Cache-TTL-Remaining
X-Cached-By
X-URL
X-Cache-Time
X-Akamai-Transformed
X-Webkit-CSP
X-B3-Traceid
Odigeo-Trace-Id
X-Rule
X-Mode
X-Backend-Name
X-Pinterest-Direct
MS-CV
Xserver
Cache-Tags
X-Litespeed-Cache
X-FW-Dynamic
S-Cnection
Version
X-Ruxit-Js-Agent
X-Yottaa-Optimizations
X-Status
X-Yottaa-Metrics
X-Locale
X-Site-Version
X-Path-Route
X-IP
X-Cache-Var-Map
X-Dc
X-Cache-Var
X-CCM
X-ES-SERVER
Meta-Geo
X-Srv
Azure-SlotName
Azure-Version
DB-Nickname
Azure-SiteName
Country
Azure-RegionName
Webserver
Cross-Origin-Window-Policy
Node
Azure-InstanceId
Ec-Rule-Version
S-Rt
X-Redis-Cache
X-RN-RSRV
X-Via-Fastly
X-Www-Served-By
X-Pubstack
X-PERF
X-Cache-Enabled
X-FC-Vary-Parameters
X-MP-GENERATED-AT
X-Amzn-Remapped-Content-Length
X-ApacheServer
Cache-Tv-Group
Akamai-GRN
Server-Info
Cache-Hits
Content-Disposition
X-Cache-2
X-Say-TTL
X-Web-Node
Property-Id
X-TX-ID
X-TNCMS
X-SayCDN-TTL
Decoy-Debug-Key
Decoy-Debug-Status
X-Akamai-Request-ID2
X-Adobe-Source
X-Forwarded-Host
X-Detected-As
X-Cache-NGX
Origin-Edge-Control
Origin-Cache-Control
Decoy-Debug-TTL
NGX
X-NCache
X-Loop
ServedBy
X-Say-Cacheable
TWC-Locale-Group
X-Origin-Hint
TWC-GeoIP-LatLong
TWC-Privacy
X-Human
Webcakes-Region
Webcakes-App-Version
Webcakes-App-Name
TWC-Device-Class
TWC-GeoIP-Country
TWC-Connection-Speed
X-Real-IP
X-R9-Blue-Green-Version
Now
X-Hl-Ver
Cache-Key
Cleartype
X-Proxied
X-LJ-Flow-ID
X-AWS-Id
X-Ua-Device
X-NYM-Debug-Backend
X-No-Session
X-Access
X-Hosted-By
X-Device-Type
X-RCS-CacheZone
X-Zipkin-Id
X-Cache-Status-Check
X-VWS-Id
Section-Io-Id
Section-Io-Origin-Status
X-Microcachable
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
X-Format
X-Section
X-Backend-TTL
X-Cache-Config
X-Routing-Service
X-BYPASS-REASON
X-HTML-Minification-Powered-By
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-ShopId
X-Shopify-Stage
X-FB-TRIP-ID
X-ProxyCache-Status
X-ProxyCache-Key
X-EIG-Tracking-Id
X-Alternate-Cache-Key
X-ServerID
X-Xfnlog-Site
X-Viewer-Country
X-ShardId
X-Proxy-Cache-Status
X-Proxy-Build
X-Origin
Selected-Fe
X-Timing-Wait
Access-Control-Request-Headers
Mn-Server-Ip
X-Shopify-Generated-Cart-Token
X-Vgn-Hpd-Reason
X-Content-Age
OT-Force-Account-Verify
X-BCube-Filmed-By
X-Generated
X-EC-Lua
X-SaId
X-VCache
X-JoinUs
X-Tb
X-Soup
X-Debug-Cache
X-Proto
X-Cdn
X-Request-Time
X-From
X-Cache-Remote
Accept-Language
X-Drupal-Cache-Tags
X-CF-Powered-By
X-MCACHE
X-Edge
X-NC
X-UA
X-Generated-By
X-Pad
X-Akamai-Request-ID
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Storage-Class
X-ECACHE
X-NewRelic-App-Data
X-COUNTRY
X-Varnish-Hits
Cf-Ipcountry
Uber-Trace-Id
X-VCT
Time
X-Old-Content-Length
X-IPS-LoggedIn
X-RateLimit-Limit
X-Azure-Ref
X-Source
X-Cache-Grace
Cache-Name
X-Mid
X-CS
X-Geo
X-FORWARDED-FOR
X-RTag
Ms-Operation-Id
Cache
X-APP
X-CDN-Forward
X-Uri
X-GoCache-CacheStatus
X-NWS-UUID-VERIFY
X-Magnolia-Registration
Proxy-Connection
User-Agent
X-CLOUD-TRACE-CONTEXT
X-Sucuri-ID
X-OCL
X-PCL
X-Info
X-FW-Version
X-Tumblr-Pixel-3
X-Drupal-Cache-Contexts
X-Qloud-Router
Countrycode
X-Edge-Location
FilterID
X-Varnish-Cache-Hits
VivaBuild
SD-X-WS
Arc-Country
AKAMAI
Memcached
ServerName
True-Client-Country-4JS
Viewtype
X-A-Dam
Request-EU
Apple-News-Services-Request-Url
Apple-News-Services-Handled
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Request-Country
Rendered-Blocks
X-A
GEO-REGION-INFO
Fastcgi-X-Cache-Version
BehaviorPad-Version
Machine
MD5-Digest
Mobile-Detection-Method
Meta-Geo-Continent
X-A-Ccd
AsisCache
X-ARC
X-Rocket-Nginx-Bypass
X-Rewrite-Enabled
X-Rojux
X-S
X-S-Cookie
X-Request-UUID
X-Request-URI
X-PAYTM-SRV-ID
X-Micro-Cache
X-Processor
X-Reboot
X-Region-Sid
X-ScT
X-Served-From
X-VG-WebServer
X-VG-WebCache
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-Vdms-Version
X-Twitter-Response-Tags
X-Session-Fingerprint
X-SRCache-Key
X-Transaction
X-Trv-Group
X-Level-Front-Cache
X-JWT-State
X-Cdn-Srv
X-Cache-Bucket
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Connection-Hash
X-B-Cookie
X-Application
X-A-Dgt
X-A-Wwc
X-Accel-Expires-Debug
X-Aed
X-D
X-Date
X-GeoIP-Country-Code
X-Geo-Header
X-Has-Esi
X-Instart-Info
X-Is-Gdpr
X-Generated-On
X-G
X-Destination
X-Developer
X-DPWN-IS-SECURE
X-External-Request-Id
X-A-Dcw
T-Server
X-UnsetCookies
X-Cluster-Node
User-Cache-Control
X-Newrelic-Synthetics
X-PHP-Host
X-Labrador-Cache-Channel
On-Server
X-Bc-Bl
X-Scheme
X-Contensis-Viewer-Groups
X-Ms-Version
X-Core-Value
X-NodeID
Web-Mar-Node
X-Cms-Context
X-ServiceProvider
X-Cdn-Origin
Locale
X-Servername
X-Server-W
X-Request-Host
X-Ms-Request-Id
X-Clara-WADP
X-Cache-URL
X-Logging-Id
Server-Surrogate-Control
X-Generation-Time
X-Hnp-Log
X-Gen-Mode
Thinkindot-CacheControl
X-Fastly-Cache
Thinkindot-Control
Thinkindot-CacheControl-Type
Server-Host
Server-Cache-Control
X-Webstats-RespID
X-Skip-Cache
X-Matched-Rule
X-Developers
X-DevSite-Last-Modified
Viewport
X-Dispatch
X-Vdms-Path
X-Sn-Servicetimems
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-From
X-WADP-Cache
Cache-Cookie-Set-Lfrom
X-VServer
X-Varnish-Authentication
X-Cache-ASPX
X-VG-TLSProxy
X-We-Are-Hiring
X-Auto-Login
X-Bip
Heartbleed
N-Cache
X-Backend-State
X-Block-Status
X-Wikidot-Backend
X-Wikidot-Static-Cache
Content-Script-Type
X-Cache-Info
X-Thanos
X-Thinkindot-L3
X-Fmm-Version
X-BBXSRF
X-Swa-Ws
X-Agile-Age
Gh-Request-Id
X-Trace-Id
X-TrackingId
X-Urbn-Site-Id
Content-Style-Type
X-Agile
X-Urbn-Context-Path
X-Oneagent-Js-Injection
X-Agile-Id
X-Backend-Host
X-Hyper-Cache
X-Cluster-Name
X-Clientip
X-C
X-Cache-PHP
X-Rebelmouse-Cache-Control
X-Variation
X-Varnish-Cacheable
X-TT-TIMESTAMP
X-Device-Os
X-SN
X-Storage
X-VC-Cache
Wxu-Next-Region
Wxu-Next-Commit
Group
Cache-Host
X-WebServer
Wxu-Next-Hostname
X-Slack-Backend
X-SIPLIST1
X-LAGOON
X-Nginx-Cache-Key
X-Irp-Debug
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-Var-Ttl
X-Owner
X-Sigma
X-Sigma-Backend
X-Rocket-Build-Number
X-Req
X-Rebelmouse-Surrogate-Control
X-Gamma-Serve
X-Distil-CS
Locid
W
We-Hiring
Mail-Subject
RNT-Time
Rt-Fastcgi-Cache
Kp-EeAlive
IsBot
FNAC-ModuleRouting
Fastly-SWR
Fastly-SIE
Vix-Hermes-Req-Id
Is-Eu
RNT-Machine
CDCHOST
X-App-Name
Platform
Adler-Geo
X-Nginx-Cache
X-B3-Spanid
X-S-Maxage
Ha-Gx-Prefs
HA-Ipaddr
X-Eu-Site
X-Epic-Correlation-Id
X-Proxy-Upstream
X-Origin-Date
X-Origin-Expires
X-Platform-Server
X-Generated-In
X-Fetched-On
X-Hash
X-Distributor
X-Li-Fabric
X-Li-Pop
X-LI-Proto
X-Response-By
L5d-Success-Class
X-LI-UUID
Request-Time
V-Age
X-Core-Mission
X-Trafficlayer-App-Version
Sever-Int
X-CGP
Country-Code
Server-Hostname
X-Trafficlayer-App-Scope
X-Trafficlayer-App-Name
X-Cache-Tags
X-Cache-FS-Status
Fastly-Drupal-HTML
Server-Ext
X-Protected-By
X-PressLabs-Stats
Proxy-Firewall
X-RateLimit-Remaining-Second
Server-ID
X-CSRF-Token
X-Parent-Response-Time
X-Refresh
NM-Fastcgi-Cache
X-RateLimit-Limit-Second
X-Hit
X-CUA
CF-Cached-On
Pagetype
X-Dispatcher-Server
X-GeoIP-City
XServer
M-TraceId
A
X-RESPONSE-TIME
X-FPC
X-Method
X-GEO
X-CACHE-KEY
X-Worker
X-App-Server
X-Instart-Isnd
Magicmarker
X-Debug-Cookies
X-Cache-Expired-At
X-NX-Host
X-Debug-Log
X-Varnish-Beresp-Status
X-SRV
X-TA-CDN-Provider
HostName
X-Varnish-Beresp-Grace
X-Amzn-RequestId
X-Envoy-Upstream-Healthchecked-Cluster
X-OVcl-Cache
X-SS-Set-Cookie
X-Branch-Name
Geoip-City
Geoip-Latitude
X-OVcl
X-Via-PopH
X-Via-PopV
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
Mime-Version
X-Request-Start
X-Node-Id
X-Be
X-Wa
GeoIp-Country-Code
X-Policy
PFcat
X-MSEdge-Flight
X-MSEdge-Features
X-Varnish-URL
Origin
X-Varnish-Beresp-Ttl
X-Varnish-Ttl
X-Nc
X-Tec-Api-Version
X-Tec-Api-Root
Esi-Enabled
X-Planisys-CDN-Cache
X-Tec-Api-Origin
PICS-Label
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
Powered-By-ChinaCache
Who
Pramga
X-Lb-Id
Cteonnt-Length
X-Ratelimit-Remaining
X-Via-Ucdn
X-Reqid
X-C-Key
X-C-Zone
X-Service
Memory
Cloudfront-Viewer-Country
X-Load-Cache
X-SERVER-NAME
X-Pjax-Url
X-Country-IP
X-ND-Cache
X-Time
Dt-Cache-Category
HitType
X-HS-Status
Geo-Info
X-ECache
X-VCL-Version
Environment
UCS
X-Newrelic-App-Data
X-Servedbyhost
X-Azure-Ref-OriginShield
X-BACKEND-TTL
X-Myra-Origin2
Product
SRV
X-NGINX-Cache
X-Bc
X-Zone
TTL
X-ZONE
X-Referer
X-Wix-Viewer-Type
Ttl
X-BC
X-Correlation-ID
X-CSRF-TOKEN
X-Cache-Metadata
NtCoent-Length
X-Vcl-Version
X-Server-IP
X-DC
X-Cdn-Forward
X-ServedByHost
FSS-Cache
Resin-Trace
X-Cache-Host
X-Up
Fastly-Backend-Name
X-Ratelimit-Limit
Cdn
Release
X-PJAX-URL
X-Fastly-Country-Code
C-Via
X-Origin-CC
X-Origin-TTL
X-Ua
LB
X-Pf-Uncompressing
Pragrma
X-TT-LOGID
X-Swift-Error
X-Server-Time
X-Cache-Backend
Hostname
X-Location
Cdn-Host
Sid
Cdn-Request-Time
X-Edge-Server
X-AIR-PT
X-UPSTREAM-Address
CACHE
X-App-Version
X-AK-Request-ID
X-Node-ID
Cdnsip
Cdncip
My-App
X-SVT-ORM-VERSION
X-Sucuri-Cache
X-SVT-ORM-RULES
Lb
X-Tb-Optimization-Total-Bytes-Saved
X-NU-AKA-ACS-Version
X-Mvc-Supplant-Cachable
Warning
X-WPE-Loopback-Upstream-Addr
MIME-Version
Load-Balancing
Dnion-Transfer-Encoding
Fastly-SSL
X-WA
X-Configured-By
X-Mvc-Supplant-OutputCached
X-Fastly-Backend-Reqs
GeoIP-Country-Code
X-Varnish-Beresp-TTL
X-Air-Hostname
CDN
X-Varnish-Url
X-BE
GeoIP-City
X-Powered-Y
X-RAMCache
X-Svr
Processtime
X-User
GeoIP-Latitude
CF-IPCountry
Ohc-File-Size
Lfy
X-Cache-Id
X-Esi-Check
X-Fastly-Request-Id
Host-ID
X-Gzip
X-VarnishDD-TTL
Ohc-Cache-HIT
DSUID
X-SD-PageType
X-B3-SpanId
Cneonction
Pics-Label
X-Fpc
RequestId
X-MID
X-Apw-Access-Object
X-Apw-Access-Action
X-TH-Server
X-Apw-Access-Token
X-Apw-Hits
X-Cache-Debug
X-LiteSpeed-Cache-Control
X-Via-NSCOPI
X-Envoy-Decorator-Operation
L
X-Compress-Hint
X-DB
X-Amzn-Remapped-Date
X-Zalando-Child-Request-Id
X-Amzn-Remapped-Connection
IBM-Web2-Location
X-Nananana
X-ElasticPress-Query
X-Page-Impression-Id
Requestid
X-RPM
X-DW
X-RPS
Xet-Cookie
X-Flow-Id
X-Check-Cacheable
X-DSS
X-ElasticPress-Search
X-RSL
X-DI
X-Agile-Brick-Ok
X-B3-Parentspanid
X-Action
WZWS-RAY
X-Debug-Revision
X-Unique-ID
X-Debug-Controller
X-Aicache-OS
X-Sucuri-Id
X-Request-Url
DataCenter
CloudFront-Viewer-Country
Server-Id
Server-Int
X-Fastly-Cache-Hits
X-LB-ID
X-Request-URL
X-Cache-Tag
X-Akamai-ERRuleID
URI
X-Dw-Trace-Id
X-MiniProfiler-Ids
X-Ocache
X-Akamai-ERPolicy