Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
CF-Cache-Status
Pragma
Link
CF-RAY
X-Powered-By
ETag
Expect-CT
Via
X-XSS-Protection
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Xss-Protection
Referrer-Policy
X-Served-By
X-Varnish
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
Alt-Svc
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Request-ID
X-Check
X-Generator
Content-Security-Policy-Report-Only
X-Cache-Status
X-Permitted-Cross-Domain-Policies
X-Cacheable
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Iinfo
X-Template
X-Language
X-AspNetMvc-Version
Status
X-Content-Security-Policy
X-Buckets
Content-Encoding
Access-Control-Expose-Headers
X-CDN
Upgrade
Xkey
Access-Control-Max-Age
Keep-Alive
X-Drupal-Dynamic-Cache
X-Kinja-Server-Push
CF-Ray
X-Turbo-Charged-By
X-AH-Environment
X-Via
X-Ua-Compatible
X-Age
X-Cache-Group
X-Pass-Why
X-Backend
X-Envoy-Upstream-Service-Time
EagleId
X-Server
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Page-Speed
X-Server-Powered-By
X-Pingback
X-UA-Device
X-Proxy-Cache
X-Swift-CacheTime
X-Swift-SaveTime
X-Hacker
X-Nginx-Cache-Status
Ali-Swift-Global-Savetime
Request-Context
X-Varnish-Cache
Grace
Server-Timing
Feature-Policy
Cf-Railgun
P3p
X-Amz-Version-Id
X-LiteSpeed-Cache
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-WebKit-CSP
X-Rq
X-Server-Id
Report-To
X-Dns-Prefetch-Control
EagleEye-TraceId
X-Response-Time
X-Ac
X-Host
X-OneAgent-JS-Injection
Request-Id
X-Cnection
X-Ws-Request-Id
X-Backend-Server
X-Node
X-DataDome
Content-Location
X-Origin-Cache
X-Cache-Lookup
X-Cloud-Trace-Context
X-Readtime
NEL
X-Vhost
X-Application-Context
X-HW
X-ORACLE-DMS-ECID
X-Dispatcher
X-ORACLE-DMS-RID
X-Cdn
Allow
X-Clacks-Overhead
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Rack-Cache
X-Origin-Upstream-Status
Surrogate-Control
X-DynaTrace
X-Country
Rating
Fusion-Content-Source
Fusion-Template-Id
Fusion-Source
Fusion-Content-Id
Fusion-Component-Id
X-Akam-SW-Version
X-FTR-Request-ID
X-Country-Code
X-Goog-Hash
X-Varnish-TTL
X-Instart-Request-ID
Pinterest-Generated-By
X-TtlSet
X-Vname
X-PC
Edge-Control
X-Mod-Pagespeed
X-B3-TraceId
X-MS-InvokeApp
X-Ruxit-JS-Agent
X-Url
Verso
SPRequestGuid
Accept-Ch
X-Powered-By-Plesk
X-D2id
X-ESI
X-Trace
X-VARITI-CCR
X-SharePointHealthScore
X-GitHub-Request-Id
Pagespeed
Response
X-Middleton-Response
X-Sol
Service-Worker-Allowed
X-Server-Name
X-Middleton-Display
Display
Content-MD5
X-Exp-Id
X-Cdn-Fetch
X-GoogleNews-Bot
X-Kinja-Server
X-Kinja
X-Kinja-Build
X-Kinja-Revision
X-Use-Magma
RTSS
X-Exp-Variant
SPRequestDuration
SPIisLatency
X-Navigation-Version
X-Powered-CMS
X-TTL
X-Vcache
X-Debug
X-Abt-Application-Version
Accept-Ch-Lifetime
X-Forwarded-Proto
X-Amz-Server-Side-Encryption
X-Upstream
Charset
X-Vcap-Request-Id
X-Cached
Public-Key-Pins
X-CST
MS-Author-Via
DynaTrace
X-NF-Request-ID
X-Version
X-Amz-Rid
Realpath
Edge-Cache-Tag
X-Px
MicrosoftSharePointTeamServices
X-Shard
Arr-Disable-Session-Affinity
X-DynaTrace-JS-Agent
X-Trafficlayer-App-Scope
X-Trafficlayer-App-Name
X-Ezoic-Cdn
X-Shield-Request-Id
Access-Control-Request-Method
X-MSEdge-Ref
X-Server-ID
X-Pinterest-Rid
Pinterest-Version
TCN
X-Ser
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Fastly-Request-ID
S
Fastly-Restarts
X-Accel-Expires
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-DIS-Request-ID
X-XRDS-Location
X-Goog-Metageneration
X-Client-IP
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Generation
Front-End-Https
X-Amz-Meta-S3cmd-Attrs
X-Recruiting
X-T
X-Goog-Storage-Class
X-Id
X-Element-Page-Cache
Nginx-Cache
X-Varnish-Age
X-Webapp-Samesite-None-Activated-N
X-Mrf-Item-Lastmod
Mrf-Cache-Status
Cache-Tag
MRF-Tech
X-B3-TraceId-Primal
X-Mrf-Section-Lastmod
X-FTR-Backend-Server
X-FTR-DC
X-FTR-Balancer
X-FTR-Backend
X-FTR-Realm
X-Country-Code-Real
X-FTR-Cache-Status
X-Amzn-Trace-Id
X-Dw-Request-Base-Id
X-FTR-Expires
X-Ttl
Fastcgi-Cache
X-Fastcgi-Cache
X-HS-Cache-Config
X-HS-Content-Id
X-Frontend
X-HS-Hub-Id
NR-ENABLED
X-Content-Digest
Powered
X-Hits
X-Correlation-Id
X-Kinsta-Cache
X-Hp-Webp
Alternate-Protocol
X-FTR-Cache-Host
X-Oneagent-Js-Injection
X-Aspnetmvc-Version
X-Webkit-Csp
X-Request-Received
X-Request-Processing-Time
X-N
ServerID
Server-Name
X-HS-Combine-CSS
X-Microsite
X-RateLimit-Remaining
X-Content-Type
X-Request-Handler-Origin-Region
X-Cache-Hit
X-Grace
PB-RID
PB-PID
TP-Cache
Arc-Version
X-Rid
TP-L2-Cache
X-Mobile-Rewrite
X-Node-Name
X-User-Agent
X-Akamai-Edgescape
Healthy
X-Revision
X-Analytics
Backend-Timing
X-Content-Security-Policy-Report-Only
X-Ruxit-Js-Agent
X-Zen-Fury
X-Forwarded-For
AMP-Access-Control-Allow-Source-Origin
X-Logged-In
Server-Node
X-Pad
X-LB-Cache
X-Amz-Apigw-Id
X-Mobile-URL
X-Amzn-RequestId
X-Az
X-Activity-Id
X-AppVersion
X-Varnish-Grace
Cache-Status
Accept-CH-Lifetime
X-NWS-LOG-UUID
X-Cached-By
Accept-CH
X-B3-Sampled
Refresh
X-Content-Options
X-IPLB-Instance
X-F-Cache
Retry-After
X-Type
Upgrade-Insecure-Requests
X-GUploader-UploadID
X-FastCGI-Cache
X-Geo-Country
X-Varnish-Backend
FilterID
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-App-Environment
X-Srv
Paypal-Debug-Id
X-Tumblr-User
Source
AR-PoweredBy
AR-CACHE
AR-ATIME
X-Framework
X-Jobs
X-FB-Debug
X-Instance
DC
Accept-Charset
X-Cluster
X-PHP-Backend
X-Page-Id
X-Debug-Info
Actual-Object-TTL
X-WebKit-CSP-Report-Only
X-Request-Guid
Host
X-AOL-HN
Access-Control-Allow-Method
X-Cache-2
X-B
X-ATG-Version
X-Erf-Bev-Bev-Is-Generated
Cache
X-Erf-Bev-Bev
X-Cache-Age
X-Cache-Key
X-TT
X-PressLabs-Stats
X-Seen-By
Ar-Sid
MS-CV
X-Via-JSL
X-Git-Hash
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Content-Powered-By
Fastcgi-Useragent
X-Cache-TTL
X-Whom
X-Amz-Replication-Status
X-B-Cache
X-TA-CDN-Provider
X-Signature
Host-Header
X-UA
X-Cache-Control
X-Daa-Tunnel
NGB
Surrogate-Key
X-Cache-Enabled
X-Wix-Request-Id
X-Response-Served-From
X-Host-Name
X-Mobile
X-Origin-Server
X-RequestSource
X-Tumblr-Pixel-1
WPE-Backend
X-GeoIP
Cache-Tv-Group
X-Tumblr-Pixel-2
X-Hyper-Cache
Cleartype
X-Region
Eomportal-Instance
Filters
AR-Request-ID
X-Litespeed-Cache
Frame-Options
X-FW-Static
X-FW-Hash
X-Handled-By
Payment
X-FW-Server
X-Cache-Action
X-TX-ID
X-EdgeConnect-Cache-Status
Xserver
X-FW-Serve
X-FW-Type
X-Cacheable-TTL
X-Cache-NE
X-Adobe-Loc
X-SERVER
X-Adobe-Content
X-Drupal-Cache-Tags
X-ATS-Timestamp
Webserver
X-Esi
Datacenter
X-Cache-Operation
X-Cache-Rule
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
From-Origin
X-Akamai-Transformed
X-NewRelic-App-Data
X-Load-Cache
X-UA-Device-Type
X-ProcessESI
X-RemovedCookies
X-Hostname
X-RTag
X-Edge-Location
X-Forwarded-Host
X-Cache-TTL-Remaining
Ms-Operation-Id
X-Cache-Server
Liferay-Portal
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Varnish-Hostname
X-Varnish-Server
X-Status
X-Contextid
X-Rule
X-App-Server
X-XRDS-LOCATION
X-Oss-Object-Type
X-ORACLE-APMCS-TAG
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-Oss-Storage-Class
X-ORACLE-APMCS-REQUEST-ID
Odigeo-Trace-Id
Country
X-Upgrade-Enabled
X-BCube-Filmed-By
X-Cache-Var
X-Path-Route
X-RN-RSRV
X-Cache-Var-Map
Meta-Geo
X-ES-SERVER
X-UUID
Load-Balancing
X-TT-TIMESTAMP
X-Xfnlog-Site
X-Time
DSUID
X-Rocket-Nginx-Bypass
X-VCT
Webcakes-App-Version
X-R9-Blue-Green-Version
Webcakes-Region
X-PCL
X-From
X-OCL
X-Origin-Hint
Webcakes-App-Name
X-Pubstack
TWC-GeoIP-Country
TWC-Locale-Group
TWC-GeoIP-LatLong
X-CCM
Mn-Server-Ip
TWC-Privacy
X-Debug-Cache
TWC-Device-Class
X-Viewer-Country
TWC-Connection-Speed
Release
Cache-Tags
Property-Id
DB-Nickname
Azure-InstanceId
Azure-RegionName
X-Real-IP
Selected-Fe
X-Proxy
X-Proxy-Build
X-Cache-Host
Azure-SiteName
Azure-SlotName
X-Vgn-Hpd-Reason
L5d-Success-Class
X-Timing-Wait
X-Via-Fastly
Cache-Name
Azure-Version
NGX
Tracecode
X-EIG-Tracking-Id
X-Cache-Config
X-Redis-Cache
X-Akamai-Request-ID2
X-Goog-Meta-Goog-Reserved-File-Mtime
X-IP
X-Human
X-Content-Age
X-Section
X-FC-Vary-Parameters
X-Generated
X-FW-Dynamic
X-Format
X-Soup
X-Site-Version
X-Backend-Name
X-Locale
Viewport
Fastly-SSL
X-Proto
S-Rt
S-Cnection
X-Origin-Response-Time
X-Akamai-Request-ID
X-Access
X-Hosted-By
Decoy-Debug-TTL
Origin-Edge-Control
Origin-Cache-Control
X-NWS-UUID-VERIFY
X-FireWall-Port
X-Labrador-Cache-Channel
X-ServerID
X-Origin
Server-Info
X-Www-Served-By
X-Cache-Time
X-Drupal-Cache-Contexts
Decoy-Debug-Key
X-Varnish-Cache-Hits
Decoy-Debug-Status
X-Web-Node
X-JoinUs
X-Rendered-As
X-Is-Bot
X-BYPASS-REASON
X-ProxyCache-Key
X-ApacheServer
Version
X-Cluster-Name
X-ProxyCache-Status
X-PERF
Uber-Trace-Id
X-TNCMS
X-Loop
X-Time-Microsecs
X-Cache-Backend
X-Generated-By
X-VCache
X-Varnish-Hits
Ec-Rule-Version
X-Accel-Buffering
X-Storage
X-Guploader-Uploadid
X-Info
X-PHP-Host
X-App-Version
Akamai-GRN
X-Amzn-Remapped-Content-Length
X-URL
X-Origin-CC
X-Origin-TTL
X-SaId
X-WA-Info
X-Nginx-Cache-Key
Rt-Fastcgi-Cache
X-Geo
Cache-Key
X-CF-Powered-By
Cteonnt-Length
X-RateLimit-Limit
X-No-Session
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
Origin
X-Environment-Context
X-L-Path
Time
X-MServer
GEO-INFO
X-Cache-Remote
X-FB-TRIP-ID
X-Tb
Vix-Hermes-Req-Id
Cache-Hits
Accept-Language
Access-Control-Request-Headers
X-Presslabs-Stats
X-NCache
X-Trace-Id
X-B3-SpanId
X-GoCache-CacheStatus
X-Hit
X-SayCDN-TTL
X-Say-Cacheable
Srv
X-Backend-TTL
X-Say-TTL
X-Unique-Id
X-B3-Traceid
X-Device-Type
X-Sorting-Hat-PodId
X-ShardId
X-ShopId
X-CS
X-Shopify-Stage
X-Sorting-Hat-ShopId
X-Shopify-Generated-Cart-Token
X-EC-Lua
X-Alternate-Cache-Key
X-Tumblr-Pixel-3
X-APP-VERSION
X-SS-Set-Cookie
X-CDN-Forward
User-Cache-Control
X-OVcl
X-Dc
X-CACHE-KEY
X-RCS-CacheZone
X-OVcl-Cache
ServedBy
NtCoent-Length
X-Cluster-Node
X-Parent-Response-Time
X-Source
X-S
Apple-News-Services-Parsed-Url
T-Server
X-Vtex-Processado-Em
Apple-News-Services-Host
Xc-Version
X-D
IsBot
X-Date
Apple-News-Services-Handled
X-Connection-Hash
X-Vtex-Remote-Cache
X-Application
X-A-Dam
X-A-Dcw
X-A-Dgt
X-A-Ccd
X-A
VivaBuild
Viewtype
X-A-Wwc
X-Accel-Expires-Debug
X-B-Cookie
X-CF-Lambda-Fn
X-ARC
X-Destination
X-Aed
X-AIR-PT
X-CF-Lambda-Version
X-Vdms-Version
Node
X-Session-Fingerprint
X-TIME
X-Service
X-Server-Time
X-SIPLIST1
X-SRCache-Key
Request-Country
X-Detected-As
X-Svr
Rendered-Blocks
Fastcgi-X-Cache-Version
Mobile-Detection-Method
X-PAYTM-SRV-ID
Content-Style-Type
X-Region-Sid
Meta-Geo-Continent
MD5-Digest
Content-Script-Type
X-Request-UUID
X-Rewrite-Enabled
X-ScT
X-S-Cookie
X-Rojux
X-Processor
Request-EU
Machine
AsisCache
X-DPWN-IS-SECURE
X-Ah-Environment
X-Hl-Ver
Arc-Country
X-G
X-VG-WebServer
Mime-Version
X-External-Request-Id
X-VG-WebCache
Cross-Origin-Window-Policy
BehaviorPad-Version
Server-Host
X-Transaction
Apple-News-Services-Request-Url
X-Trv-Group
X-Twitter-Response-Tags
Rt-Proxy-Cache
OT-Force-Account-Verify
X-Cache-Grace
X-CSRF-TOKEN
X-Endurance-Cache-Level
X-Magnolia-Registration
ServerName
Server-Int
Thinkindot-Control
Thinkindot-CacheControl-Type
Web-Mar-Node
X-Ms-Request-Id
X-Ms-Version
X-NX-Host
X-Matched-Rule
X-Level-Front-Cache
X-IN-APIGATEWAYSSL
X-Instart-Isnd
X-Proxy-Cache-Status
X-Proxy-Upstream
X-Via-NSCOPI
X-Webstats-RespID
X-Thinkindot-L3
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-IN-APIGATEWAY
X-Hnp-Log
X-Cache-Info
X-Core-Value
X-Cache-Bucket
X-Block-Status
Wxu-Next-Hostname
Wxu-Next-Region
X-CUA
X-Debug-Cookies
X-Generated-On
X-Hash
X-Gen-Mode
X-Dispatch
X-Debug-Log
Wxu-Next-Commit
Thinkindot-CacheControl
X-Upstream-Ct
Proxy-Connection
CDCHOST
X-Upstream-Ht
X-Uri
Now
X-SRV
X-Nc
X-Azure-Ref
X-Distil-CS
X-Developers
X-Azure-Ref-OriginShield
X-Debug-Cache-Store
X-Eu-Site
X-Debug-Cache-Fetch
X-Fastly-Cache
X-Varnish-Beresp-Grace
X-App-Name
X-Generated-In
X-Auto-Login
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Status
X-Debug-Cache-Expiry
Mail-Subject
X-Cache-URL
X-Cdn-Srv
X-Cache-Debug
X-C
X-BBXSRF
X-Bip
X-CGP
X-Clara-WADP
We-Hiring
X-Backend-State
X-Generation-Time
X-Core-Mission
X-Cms-Context
X-Compress-Hint
X-B3-Parentspanid
X-GeoIP-City
X-SVT-ORM-VERSION
X-Swa-Ws
X-Thanos
X-SVT-ORM-RULES
X-Sucuri-Cache
X-Sigma
X-Sigma-Backend
X-TrackingId
X-VC-Cache
X-Dispatcher-Server
X-Request-URI
X-ND-Cache
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-VG-TLSProxy
X-WADP-Cache
X-Scheme
X-Rocket-Build-Number
X-Method
X-Origin-Date
X-Origin-Expires
X-Logging-Id
X-Location
X-Agile-Id
X-Key
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Release
X-Reqid
X-Reboot
X-Qloud-Router
X-Planisys-CDN-TTL
X-Policy
X-Geo-Header
X-Irp-Debug
Pramga
Gh-Request-Id
RNT-Machine
Served-By
AKAMAI
Cache-Host
PFcat
Ha-Gx-Prefs
L
Magicmarker
Kp-EeAlive
Esi-Enabled
HA-Ipaddr
Heartbleed
W
RNT-Time
X-Agile-Age
X-Agile
Fastly-Soc-X-Request-Id
X-Via-CDN
Cache-Provider
X-VServer
X-Is-Gdpr
X-Urbn-Site-Id
X-User
X-JWT-State
X-We-Are-Hiring
SD-X-WS
X-Cache-Id
X-Distributor
X-Cache-FS-Status
Section-Io-Cache
X-Urbn-Context-Path
X-Amz-Meta-Cache-Control
X-FW-Version
X-MSEdge-Features
X-AK-Request-ID
Content-Disposition
X-ServiceProvider
Countrycode
X-Server-IP
Locale
Memcached
X-Skip-Cache
X-MSEdge-Flight
X-Epic-Correlation-Id
X-NodeID
IBM-Web2-Location
Cdnsip
Cdncip
X-Up
X-Has-Esi
X-Request-Start
True-Client-Country-4JS
X-Clientip
X-S-Maxage
X-WebServer
X-SD-PageType
X-Old-Content-Length
X-Owner
X-Cdn-Forward
X-Li-Pop
X-LI-UUID
V-Age
X-Internal-Host
X-Platform-Server
X-Trafficlayer-App-Version
X-Li-Fabric
Is-Eu
Platform
Server-ID
Adler-Geo
X-Variation
X-LI-Proto
X-NC
Hostname
Powered-By-ChinaCache
X-Sucuri-Id
X-GRACE
Environment
X-UnsetCookies
FNAC-ModuleRouting
X-Req
X-Servername
Tcn
X-7Graus-Varnish-Cache-Control
X-Served-From
GEO-REGION-INFO
X-Be
X-7Graus-Varnish-XKeys
Locid
X-Lb-Id
X-B3-Spanid
X-Nginx-Cache
CF-IPCountry
X-Gamma-Serve
X-Newrelic-Synthetics
X-HTML-Minification-Powered-By
Geo-Info
X-Refresh
X-FPC
X-Developer
A
X-VHOST
X-Zone
X-Cdn-Origin
X-Device-Os
X-Render-Time
X-Edge-O15-RID
X-Sn-Servicetimems
ProcessTime
X-Microcachable
X-Servedbyhost
X-IPS-LoggedIn
X-Webkit-CSP
X-Tb-Optimization-Total-Bytes-Saved
X-Node-Id
X-Sucuri-ID
X-NU-AKA-ACS-Version
X-MP-GENERATED-AT
X-Pjax-Url
X-Mode
X-GeoIP-Country-Code
X-Ratelimit-Remaining
X-LJ-Flow-ID
Memory
Request-Time
X-AWS-Id
X-VWS-Id
X-FORWARDED-FOR
Gannett-Cam-Experience-Id
X-Pf-Uncompressing
X-COUNTRY
X-Correlation-ID
Resin-Trace
X-VCL-Version
X-Zipkin-Id
Pics-Label
TTL
X-Routing-Service
Amp-Access-Control-Allow-Source-Origin
Cf-Ipcountry
X-DC
X-Proxied
XServer
CF-Cached-On
X-Unique-ID
Group
Geoip-Latitude
X-Bc
GeoIp-Country-Code
X-CSRF-Token
X-Pod
Cache-Cookie-Set-Lfrom
X-ElasticPress-Search
X-ECACHE
X-ZONE
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-From
M-TraceId
Geoip-City
X-Instart-Info
GeoIP-Latitude
X-Via-Edge
GeoIP-Country-Code
PICS-Label
X-Via-SSL
MIME-Version
GeoIP-City
X-Backend-Url
Cdn
HostName
Host-ID
X-Var-Ttl
X-Backend-Host
X-Vcl-Version
X-CLOUD-TRACE-CONTEXT
X-APP
X-Request-Time
X-Ratelimit-Limit
Ttl
X-Cdn-Request-ID
Backend-Name
X-NGENIX-Cache
X-Swift-Error
X-BC
N-Cache
X-Check-Cacheable
REQUESTUUID
Pagetype
Lfy
X-PF-Uncompressing
HitType
Ohc-File-Size
Ohc-Cache-HIT
X-NGINX-Cache
X-TH-Server
X-Fstrz
Fly-Request-Id
X-HostName
X-PJAX-URL
Cache-Prefix
Fly-Cache
X-UPSTREAM-Address
URI
X-Fastly-Country-Code
X-Worker
X-Via-Ucdn
User-Agent
Powered-By
On-Server
X-ServedByHost
Pragrma
X-Cache-Miss-From
CDN
X-Cache-Tag
X-Tt-Trace-Tag
Media-Length
X-Sedo-Request-Id
X-WR-MODIFICATION
SRV
X-LiteSpeed-Cache-Control
X-Server-W
X-HS-Status
X-Fetched-On
Who
X-WA
X-Aicache-OS
X-GEO
AR-SID
X-Tt-Trace-Host
X-BE
X-Rebelmouse-Cache-Control
X-Wa
X-Rebelmouse-Surrogate-Control
Fastly-SWR
Fastly-SIE
X-Upstream-HT
X-Upstream-CT
X-Hp-Ccpa-Warning
FSS-Proxy
UCS
X-Dynatrace-Js-Agent
X-Varnish-Cacheable
FSS-Cache
X-Varnish-URL
X-LB-ID
X-LAGOON
X-Fpc
X-Cf-Powered-By
X-Store
X-Fastly-Backend-Reqs
X-ServerName
Processtime
Debug
X-TT-LOGID
X-Ftr-Cache-Host
X-NYM-Debug-Backend
X-Ua
X-Cache-Tags
Server-Id
Server-Cache-Control
X-Varnish-Authentication
X-Contensis-Viewer-Groups
X-Cache-ASPX
Server-Surrogate-Control
Country-Code
X-Protected-By
X-Varnish-Beresp-TTL
X-Akamai-ERPolicy
X-GDPR
X-Akamai-ERRuleID
X-BACKEND-TTL
DataCenter
WP-Super-Cache
X-VC
X-SB
Xet-Cookie
X-Request-Url
Location
Product
X-SN
Thinkindot-Cache-Type
X-Fastly-Cache-Hits
X-Gen-Id
X-Nananana
X-Li-Proto
Application
NnCoection
SID
Cdn-Host
Cdn-Request-Time
X-Amzn-Remapped-Date
X-Edge-Server
Cneonction
X-Amzn-Remapped-Connection
XxX-Cache-Status
X-Dw-Trace-Id