Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
CF-Cache-Status
Pragma
Link
CF-RAY
X-Powered-By
ETag
Expect-CT
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Xss-Protection
X-Varnish
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
Alt-Svc
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-FRAME-OPTIONS
X-Drupal-Cache
X-Adblock-Key
X-Request-ID
X-Check
X-Generator
Content-Security-Policy-Report-Only
X-Cache-Status
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-Template
X-Language
X-AspNetMvc-Version
Status
X-Content-Security-Policy
X-Buckets
Content-Encoding
Access-Control-Expose-Headers
X-CDN
Upgrade
Xkey
Access-Control-Max-Age
Keep-Alive
X-Drupal-Dynamic-Cache
X-Kinja-Server-Push
CF-Ray
X-Turbo-Charged-By
X-AH-Environment
X-Via
X-Ua-Compatible
X-Age
X-Cache-Group
X-Pass-Why
X-Backend
X-Envoy-Upstream-Service-Time
EagleId
X-Server
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Page-Speed
X-Pingback
X-Server-Powered-By
X-UA-Device
X-Proxy-Cache
X-Swift-CacheTime
X-Swift-SaveTime
X-Hacker
X-Nginx-Cache-Status
Ali-Swift-Global-Savetime
Request-Context
X-Varnish-Cache
Grace
Server-Timing
Feature-Policy
Cf-Railgun
X-Amz-Version-Id
X-LiteSpeed-Cache
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-WebKit-CSP
X-Rq
X-Server-Id
Report-To
EagleEye-TraceId
X-Response-Time
X-Ac
X-Host
X-OneAgent-JS-Injection
X-Ws-Request-Id
Request-Id
X-Cnection
X-Backend-Server
X-Node
X-DataDome
Content-Location
X-Origin-Cache
X-Cache-Lookup
X-Dns-Prefetch-Control
X-Cloud-Trace-Context
NEL
X-Readtime
X-Vhost
P3p
X-Application-Context
X-HW
X-Dispatcher
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Cdn
Allow
X-Clacks-Overhead
X-Rack-Cache
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Origin-Upstream-Status
Surrogate-Control
X-DynaTrace
Rating
X-Country
Fusion-Source
Fusion-Template-Id
Fusion-Content-Id
Fusion-Component-Id
Fusion-Content-Source
X-FTR-Request-ID
X-Akam-SW-Version
X-Country-Code
X-Goog-Hash
X-Varnish-TTL
X-Instart-Request-ID
Pinterest-Generated-By
Edge-Control
X-Ruxit-JS-Agent
X-Vname
X-TtlSet
X-PC
X-B3-TraceId
X-Mod-Pagespeed
X-MS-InvokeApp
X-Url
Verso
SPRequestGuid
X-Powered-By-Plesk
Accept-Ch
X-D2id
X-ESI
X-Trace
X-VARITI-CCR
X-SharePointHealthScore
X-Server-Name
Service-Worker-Allowed
X-Sol
X-GitHub-Request-Id
Response
Pagespeed
X-Middleton-Response
Display
X-Middleton-Display
Content-MD5
X-Exp-Variant
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Kinja-Build
X-Kinja
X-Exp-Id
X-GoogleNews-Bot
X-Cdn-Fetch
RTSS
X-TTL
SPRequestDuration
SPIisLatency
X-Navigation-Version
X-Powered-CMS
X-Abt-Application-Version
X-Debug
Accept-Ch-Lifetime
X-Vcache
X-Forwarded-Proto
X-Amz-Server-Side-Encryption
X-Upstream
Charset
X-Cached
Public-Key-Pins
X-Vcap-Request-Id
MS-Author-Via
X-CST
DynaTrace
X-NF-Request-ID
X-Version
X-Amz-Rid
Realpath
Edge-Cache-Tag
X-Px
MicrosoftSharePointTeamServices
X-Shard
Arr-Disable-Session-Affinity
X-DynaTrace-JS-Agent
TCN
X-Trafficlayer-App-Name
X-Trafficlayer-App-Scope
X-Ezoic-Cdn
Access-Control-Request-Method
X-Shield-Request-Id
X-MSEdge-Ref
X-Pinterest-Rid
X-XRDS-Location
Pinterest-Version
X-Server-ID
X-Ser
X-Fastly-Request-ID
X-SRCache-Store-Status
S
X-SRCache-Fetch-Status
Fastly-Restarts
X-Accel-Expires
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-DIS-Request-ID
X-Goog-Metageneration
X-Client-IP
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Generation
Front-End-Https
X-Recruiting
X-Amz-Meta-S3cmd-Attrs
X-T
X-Id
X-Goog-Storage-Class
X-Element-Page-Cache
X-Varnish-Age
Nginx-Cache
X-Webapp-Samesite-None-Activated-N
Cache-Tag
Mrf-Cache-Status
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-DC
X-FTR-Realm
X-FTR-Backend-Server
X-FTR-Backend
X-B3-TraceId-Primal
X-Mrf-Section-Lastmod
X-Country-Code-Real
MRF-Tech
X-Mrf-Item-Lastmod
X-Amzn-Trace-Id
X-FTR-Expires
X-Dw-Request-Base-Id
X-Fastcgi-Cache
Fastcgi-Cache
X-Frontend
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Content-Id
X-Content-Digest
NR-ENABLED
Powered
X-Ttl
X-Hits
X-Kinsta-Cache
Alternate-Protocol
X-Hp-Webp
X-Correlation-Id
X-Aspnetmvc-Version
X-Webkit-Csp
X-FTR-Cache-Host
X-Request-Received
X-Request-Processing-Time
ServerID
X-N
X-Content-Type
Server-Name
X-HS-Combine-CSS
X-Microsite
X-RateLimit-Remaining
X-Request-Handler-Origin-Region
X-Cache-Hit
PB-RID
PB-PID
X-Mobile-Rewrite
Arc-Version
X-Rid
X-Node-Name
TP-L2-Cache
X-User-Agent
TP-Cache
Healthy
X-Revision
X-Akamai-Edgescape
X-Analytics
Backend-Timing
X-Grace
X-Content-Security-Policy-Report-Only
X-Forwarded-For
X-Zen-Fury
AMP-Access-Control-Allow-Source-Origin
Server-Node
X-Logged-In
X-Pad
X-LB-Cache
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Mobile-URL
X-AppVersion
X-Activity-Id
X-Az
X-Varnish-Grace
X-Oneagent-Js-Injection
X-NWS-LOG-UUID
Cache-Status
X-Cached-By
Accept-CH
Accept-CH-Lifetime
X-B3-Sampled
X-IPLB-Instance
X-Content-Options
X-F-Cache
Refresh
X-Ruxit-Js-Agent
Retry-After
Upgrade-Insecure-Requests
X-Type
X-Geo-Country
X-GUploader-UploadID
X-FastCGI-Cache
X-Varnish-Backend
FilterID
X-Tumblr-User
X-App-Environment
X-Srv
X-Tumblr-Pixel-0
X-Tumblr-Pixel
Paypal-Debug-Id
Source
X-FB-Debug
X-Instance
AR-PoweredBy
AR-CACHE
AR-ATIME
X-Framework
X-PHP-Backend
DC
Access-Control-Allow-Method
X-Cluster
X-Request-Guid
X-Jobs
X-Debug-Info
X-Page-Id
Accept-Charset
Actual-Object-TTL
X-WebKit-CSP-Report-Only
Host
X-AOL-HN
X-Cache-2
X-B
X-ATG-Version
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Cache-Age
Cache
X-TT
X-Seen-By
Fastcgi-Useragent
Ar-Sid
X-PressLabs-Stats
X-Git-Hash
X-Via-JSL
MS-CV
X-Cache-Key
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Content-Powered-By
X-Cache-TTL
X-B-Cache
X-Signature
X-Amz-Replication-Status
X-Whom
X-TA-CDN-Provider
Host-Header
X-UA
X-Daa-Tunnel
X-Cache-Control
X-Wix-Request-Id
X-Cache-Enabled
Surrogate-Key
NGB
X-Response-Served-From
X-Host-Name
X-Origin-Server
X-RequestSource
X-Mobile
X-GeoIP
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
Cache-Tv-Group
WPE-Backend
X-Hyper-Cache
X-Region
AR-Request-ID
X-TX-ID
Frame-Options
X-FW-Type
X-FW-Hash
Payment
Cleartype
Filters
X-Handled-By
X-FW-Serve
Eomportal-Instance
X-FW-Server
X-FW-Static
X-Cache-Action
X-Drupal-Cache-Tags
Xserver
X-Litespeed-Cache
X-EdgeConnect-Cache-Status
X-Cacheable-TTL
X-Adobe-Content
X-SERVER
X-Adobe-Loc
X-Cache-NE
Webserver
X-ATS-Timestamp
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Datacenter
X-Cache-Operation
X-Cache-Rule
X-Esi
X-Hostname
From-Origin
X-NewRelic-App-Data
X-Akamai-Transformed
X-Load-Cache
X-RemovedCookies
X-UA-Device-Type
X-ProcessESI
X-Edge-Location
X-Cache-TTL-Remaining
X-Forwarded-Host
Ms-Operation-Id
X-RTag
Liferay-Portal
X-Cache-Server
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Varnish-Server
X-Varnish-Hostname
X-Status
X-Contextid
X-App-Server
X-Oss-Server-Time
X-Rule
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Oss-Request-Id
X-Oss-Storage-Class
X-ORACLE-APMCS-REQUEST-ID
X-ORACLE-APMCS-TAG
X-VCache
X-Time
Country
Odigeo-Trace-Id
X-Upgrade-Enabled
X-Path-Route
X-Cache-Var-Map
X-BCube-Filmed-By
X-RN-RSRV
X-ES-SERVER
Meta-Geo
X-TT-TIMESTAMP
Load-Balancing
X-UUID
X-Cache-Var
DSUID
X-Xfnlog-Site
X-Cache-Config
X-CCM
X-Debug-Cache
X-R9-Blue-Green-Version
X-Viewer-Country
TWC-Privacy
TWC-Locale-Group
TWC-Device-Class
Release
TWC-GeoIP-LatLong
TWC-Connection-Speed
TWC-GeoIP-Country
Webcakes-App-Name
Webcakes-App-Version
Mn-Server-Ip
X-PCL
X-Origin-Hint
X-OCL
X-Pubstack
Webcakes-Region
X-VCT
Cache-Tags
X-Rocket-Nginx-Bypass
X-From
Property-Id
X-Timing-Wait
X-EIG-Tracking-Id
X-Via-Fastly
X-Soup
Selected-Fe
S-Rt
X-Akamai-Request-ID2
X-Akamai-Request-ID
Azure-InstanceId
Azure-RegionName
Cache-Name
X-NWS-UUID-VERIFY
X-Cache-Host
X-Vgn-Hpd-Reason
X-TNCMS
Azure-SiteName
Azure-SlotName
Azure-Version
Tracecode
Fastly-SSL
X-Hosted-By
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Origin-Response-Time
X-Human
X-IP
X-Loop
DB-Nickname
X-Redis-Cache
NGX
X-FW-Dynamic
X-Web-Node
X-Proxy-Build
X-Real-IP
X-Proxy
X-Proto
L5d-Success-Class
X-FC-Vary-Parameters
X-Drupal-Cache-Contexts
S-Cnection
X-Access
X-Content-Age
X-Format
X-Generated
X-Locale
X-Section
X-Site-Version
Viewport
X-XRDS-LOCATION
X-Backend-Name
X-Varnish-Cache-Hits
X-Www-Served-By
Server-Info
Decoy-Debug-Key
X-Cache-Time
X-Origin
X-Labrador-Cache-Channel
X-FireWall-Port
Decoy-Debug-Status
X-ServerID
Origin-Cache-Control
Origin-Edge-Control
Ec-Rule-Version
Decoy-Debug-TTL
X-ProxyCache-Key
X-ProxyCache-Status
X-ApacheServer
X-Is-Bot
X-BYPASS-REASON
X-PERF
Uber-Trace-Id
X-Rendered-As
X-JoinUs
X-Cluster-Name
X-Time-Microsecs
Version
X-Varnish-Hits
X-Accel-Buffering
X-Generated-By
X-Cache-Backend
X-Storage
X-Guploader-Uploadid
X-Info
X-PHP-Host
X-Amzn-Remapped-Content-Length
X-App-Version
X-Origin-TTL
X-URL
X-Origin-CC
Akamai-GRN
Rt-Fastcgi-Cache
X-SaId
X-Nginx-Cache-Key
Time
X-WA-Info
X-CF-Powered-By
Cache-Key
Cteonnt-Length
X-Geo
X-No-Session
X-RateLimit-Limit
Origin
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
X-L-Path
X-MServer
X-Environment-Context
X-Cache-Remote
X-Tb
Vix-Hermes-Req-Id
Accept-Language
Cache-Hits
GEO-INFO
X-FB-TRIP-ID
X-GoCache-CacheStatus
X-NCache
X-CACHE-KEY
X-Presslabs-Stats
Access-Control-Request-Headers
X-Trace-Id
X-Say-TTL
X-Say-Cacheable
X-B3-SpanId
X-SayCDN-TTL
X-Hit
Srv
X-Backend-TTL
X-Unique-Id
X-Device-Type
X-B3-Traceid
X-SS-Set-Cookie
X-CS
X-APP-VERSION
X-EC-Lua
X-ShopId
X-ShardId
X-Alternate-Cache-Key
X-Shopify-Generated-Cart-Token
X-Shopify-Stage
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Tumblr-Pixel-3
X-CDN-Forward
X-CSRF-TOKEN
X-Dc
X-OVcl-Cache
X-OVcl
User-Cache-Control
X-RCS-CacheZone
X-Parent-Response-Time
X-Cluster-Node
NtCoent-Length
X-Source
X-S
ServedBy
X-Detected-As
VivaBuild
Apple-News-Services-Parsed-Url
X-Destination
Apple-News-Services-Host
X-A-Ccd
X-A
Apple-News-Services-Request-Url
X-Application
X-Connection-Hash
X-AIR-PT
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-ARC
X-B-Cookie
Apple-News-Services-Handled
X-D
X-A-Dgt
X-A-Dcw
X-A-Dam
X-A-Wwc
X-Accel-Expires-Debug
Viewtype
X-Aed
X-Date
X-PAYTM-SRV-ID
X-Service
X-Server-Time
X-Session-Fingerprint
X-SIPLIST1
X-SRCache-Key
X-ScT
X-S-Cookie
X-Region-Sid
X-DPWN-IS-SECURE
X-Request-UUID
X-Rewrite-Enabled
X-Rojux
X-Svr
MD5-Digest
X-Vtex-Processado-Em
Fastcgi-X-Cache-Version
X-Vtex-Remote-Cache
Machine
Xc-Version
X-VG-WebServer
X-VG-WebCache
OT-Force-Account-Verify
X-Transaction
X-Trv-Group
X-Twitter-Response-Tags
X-Vdms-Version
Meta-Geo-Continent
Cross-Origin-Window-Policy
BehaviorPad-Version
X-Hl-Ver
Server-Host
X-Ah-Environment
Content-Style-Type
T-Server
AsisCache
X-External-Request-Id
Mime-Version
X-G
Arc-Country
Request-EU
Rt-Proxy-Cache
Content-Script-Type
Node
X-Processor
Rendered-Blocks
Mobile-Detection-Method
IsBot
Request-Country
X-Endurance-Cache-Level
X-Magnolia-Registration
X-Cache-Grace
ServerName
Web-Mar-Node
Thinkindot-Control
Served-By
Server-Int
Thinkindot-CacheControl-Type
Wxu-Next-Commit
X-Matched-Rule
X-Ms-Version
X-NX-Host
X-Ms-Request-Id
X-Location
X-Instart-Isnd
X-Level-Front-Cache
X-Proxy-Cache-Status
X-Proxy-Upstream
X-Via-NSCOPI
X-Webstats-RespID
X-Thinkindot-L3
X-Reboot
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-Core-Value
X-CUA
X-Cache-Info
X-Cache-Bucket
Wxu-Next-Region
X-Block-Status
X-Debug-Cookies
X-Debug-Log
X-Hash
X-Hnp-Log
X-Generated-On
X-Gen-Mode
X-Dispatch
Wxu-Next-Hostname
Thinkindot-CacheControl
X-Upstream-Ct
Proxy-Connection
X-Nc
X-Upstream-Ht
CDCHOST
X-SRV
X-Uri
Now
X-Eu-Site
X-Fastly-Cache
X-Distil-CS
X-Developers
X-Generated-In
X-GeoIP-City
X-Has-Esi
X-Varnish-Beresp-Grace
X-Geo-Header
X-Generation-Time
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Status
X-FW-Version
X-Debug-Cache-Store
X-Cache-Debug
X-Cache-URL
X-Cdn-Srv
X-C
X-Bip
X-B3-Parentspanid
X-Backend-State
X-BBXSRF
X-CGP
X-Clara-WADP
Mail-Subject
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
We-Hiring
X-Core-Mission
X-Clientip
X-Cms-Context
X-Compress-Hint
X-Irp-Debug
X-Key
X-TrackingId
X-Up
X-User
X-Thanos
X-Swa-Ws
X-Sucuri-Cache
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-VC-Cache
X-VG-TLSProxy
X-Dispatcher-Server
X-Request-URI
X-ND-Cache
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-VServer
X-WADP-Cache
X-We-Are-Hiring
X-Skip-Cache
X-Sigma-Backend
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Origin-Expires
X-Origin-Date
X-Azure-Ref-OriginShield
X-Logging-Id
X-Method
X-Policy
X-Qloud-Router
X-Server-IP
X-TIME
X-Sigma
X-Scheme
X-Rocket-Build-Number
X-Release
X-Reqid
X-Is-Gdpr
X-JWT-State
Kp-EeAlive
L
Magicmarker
Esi-Enabled
Fastly-Soc-X-Request-Id
IBM-Web2-Location
Ha-Gx-Prefs
Cache-Host
Heartbleed
Memcached
Countrycode
RNT-Machine
RNT-Time
AKAMAI
Section-Io-Cache
Pramga
PFcat
W
Content-Disposition
X-Azure-Ref
Gh-Request-Id
HA-Ipaddr
X-Agile-Age
X-App-Name
X-Agile
X-Agile-Id
X-Auto-Login
Cache-Provider
X-GRACE
X-Via-CDN
X-S-Maxage
X-WebServer
X-ServiceProvider
X-SD-PageType
X-Request-Start
X-NodeID
X-MSEdge-Features
X-Internal-Host
X-Platform-Server
X-MSEdge-Flight
X-Variation
Cdncip
X-LI-UUID
X-Cache-FS-Status
X-Cache-Id
X-Urbn-Site-Id
Adler-Geo
Is-Eu
SD-X-WS
Platform
X-Urbn-Context-Path
X-Distributor
X-Amz-Meta-Cache-Control
X-Old-Content-Length
X-Li-Pop
Locale
X-Epic-Correlation-Id
X-Li-Fabric
X-Owner
Cdnsip
X-AK-Request-ID
True-Client-Country-4JS
X-Cdn-Forward
X-LI-Proto
V-Age
X-Trafficlayer-App-Version
Server-ID
X-Servername
Hostname
Powered-By-ChinaCache
X-NC
Environment
X-Sucuri-Id
X-UnsetCookies
GEO-REGION-INFO
X-7Graus-Varnish-Cache-Control
X-Be
FNAC-ModuleRouting
X-Served-From
Locid
X-Req
X-7Graus-Varnish-XKeys
X-Lb-Id
X-B3-Spanid
X-Nginx-Cache
CF-IPCountry
X-HTML-Minification-Powered-By
X-Refresh
Geo-Info
X-Newrelic-Synthetics
X-Gamma-Serve
X-Servedbyhost
X-FPC
A
X-VHOST
X-Developer
X-Zone
X-Render-Time
X-Device-Os
X-Cdn-Origin
ProcessTime
X-Sn-Servicetimems
X-Microcachable
X-Edge-O15-RID
Tcn
X-Webkit-CSP
X-IPS-LoggedIn
X-Correlation-ID
X-Tb-Optimization-Total-Bytes-Saved
X-Node-Id
X-NU-AKA-ACS-Version
X-Sucuri-ID
X-Mode
X-GeoIP-Country-Code
X-Pjax-Url
Memory
X-MP-GENERATED-AT
X-Ratelimit-Remaining
X-AWS-Id
X-LJ-Flow-ID
X-VWS-Id
X-FORWARDED-FOR
Request-Time
X-COUNTRY
X-Pf-Uncompressing
Gannett-Cam-Experience-Id
Cf-Ipcountry
Resin-Trace
X-Zipkin-Id
X-Routing-Service
X-VCL-Version
Amp-Access-Control-Allow-Source-Origin
X-Proxied
Pics-Label
TTL
X-DC
XServer
CF-Cached-On
X-Unique-ID
GeoIP-Latitude
GeoIp-Country-Code
X-Pod
GeoIP-Country-Code
Group
Geoip-Latitude
X-Bc
X-Via-Edge
X-Via-SSL
X-CSRF-Token
X-ZONE
M-TraceId
Geoip-City
X-Instart-Info
GeoIP-City
MIME-Version
Cache-Cookie-Set-From
Cache-Cookie-Set-Idcheck
PICS-Label
X-ECACHE
Cache-Cookie-Set-Lfrom
X-ElasticPress-Search
X-Backend-Url
Cdn
Host-ID
X-Backend-Host
HostName
X-Vcl-Version
X-Var-Ttl
X-CLOUD-TRACE-CONTEXT
X-Cdn-Request-ID
X-Ratelimit-Limit
X-APP
X-Request-Time
X-PF-Uncompressing
Ttl
Backend-Name
X-Swift-Error
X-NGENIX-Cache
Ohc-Cache-HIT
Ohc-File-Size
X-TH-Server
REQUESTUUID
Pagetype
N-Cache
HitType
Lfy
X-BC
X-Check-Cacheable
URI
Fly-Cache
Cache-Prefix
X-NGINX-Cache
Fly-Request-Id
X-PJAX-URL
X-Fstrz
X-UPSTREAM-Address
On-Server
Powered-By
X-Fastly-Country-Code
X-Worker
User-Agent
X-Via-Ucdn
X-GEO
X-HostName
Pragrma
Media-Length
X-ServedByHost
X-Cache-Miss-From
X-WR-MODIFICATION
X-Sedo-Request-Id
X-Cache-Tag
CDN
X-Tt-Trace-Tag
X-LiteSpeed-Cache-Control
SRV
X-Server-W
X-WA
X-HS-Status
X-Aicache-OS
Who
X-Fetched-On
X-Ftr-Cache-Host
AR-SID
X-BE
X-Tt-Trace-Host
X-Fpc
X-Rebelmouse-Surrogate-Control
Fastly-SIE
X-Wa
X-Rebelmouse-Cache-Control
Fastly-SWR
X-Upstream-CT
X-Hp-Ccpa-Warning
X-Upstream-HT
FSS-Proxy
X-LB-ID
X-Varnish-Cacheable
X-LAGOON
X-Varnish-URL
X-Dynatrace-Js-Agent
FSS-Cache
UCS
X-Cf-Powered-By
X-Store
X-ServerName
X-Fastly-Backend-Reqs
Debug
X-NYM-Debug-Backend
X-TT-LOGID
Processtime
X-Cache-Tags
X-Ua
X-Varnish-Authentication
X-Contensis-Viewer-Groups
X-Cache-ASPX
Country-Code
Server-Id
X-Protected-By
Server-Cache-Control
Server-Surrogate-Control
X-GDPR
X-Akamai-ERRuleID
X-Varnish-Beresp-TTL
X-Akamai-ERPolicy
X-BACKEND-TTL
DataCenter
X-Fastly-Cache-Hits
WP-Super-Cache
Xet-Cookie
X-Amzn-Remapped-Date
Thinkindot-Cache-Type
Location
X-Dw-Trace-Id
SID
X-VC
X-Gen-Id
X-Amzn-Remapped-Connection
Application
X-Nananana
X-SN
X-Request-Url
X-Li-Proto
NnCoection
Cdn-Host
Cdn-Request-Time
X-Edge-Server
Cneonction
Product
XxX-Cache-Status
X-SB