Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
CF-Cache-Status
Pragma
Link
X-Powered-By
ETag
CF-RAY
Expect-CT
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Xss-Protection
X-Varnish
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
Alt-Svc
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-FRAME-OPTIONS
X-Drupal-Cache
X-Request-ID
X-Adblock-Key
X-Check
X-Generator
Content-Security-Policy-Report-Only
CF-Ray
X-Cache-Status
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-Template
X-Language
X-AspNetMvc-Version
Status
X-Content-Security-Policy
X-Buckets
Content-Encoding
Access-Control-Expose-Headers
X-CDN
Upgrade
Xkey
Access-Control-Max-Age
X-Drupal-Dynamic-Cache
Keep-Alive
X-Kinja-Server-Push
X-Turbo-Charged-By
X-AH-Environment
X-Ua-Compatible
X-Age
X-Cache-Group
X-Via
X-Pass-Why
X-Backend
X-Envoy-Upstream-Service-Time
EagleId
X-Server
X-Robots-Tag
X-Amz-Id-2
X-Amz-Request-Id
X-Server-Powered-By
X-Page-Speed
X-Pingback
X-UA-Device
X-Proxy-Cache
X-Swift-CacheTime
X-Swift-SaveTime
X-Hacker
X-Nginx-Cache-Status
Request-Context
Ali-Swift-Global-Savetime
X-Varnish-Cache
Grace
Server-Timing
Feature-Policy
Cf-Railgun
X-Amz-Version-Id
X-LiteSpeed-Cache
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-Rq
X-WebKit-CSP
X-Server-Id
Report-To
EagleEye-TraceId
X-Ws-Request-Id
X-Host
X-Response-Time
X-Ac
X-OneAgent-JS-Injection
Request-Id
X-Cnection
X-Backend-Server
Content-Location
X-DataDome
X-Origin-Cache
X-Node
X-Cache-Lookup
X-Dns-Prefetch-Control
NEL
X-Readtime
X-Cloud-Trace-Context
X-Vhost
P3p
X-HW
X-Dispatcher
X-Application-Context
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Cdn
Allow
X-Clacks-Overhead
Surrogate-Control
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Rack-Cache
X-Origin-Upstream-Status
X-DynaTrace
Rating
X-Country
Fusion-Content-Id
Fusion-Content-Source
Fusion-Source
Fusion-Template-Id
Fusion-Component-Id
X-Akam-SW-Version
X-FTR-Request-ID
X-Country-Code
X-Goog-Hash
X-Varnish-TTL
Pinterest-Generated-By
X-Instart-Request-ID
Edge-Control
X-Ruxit-JS-Agent
X-PC
X-TtlSet
X-Vname
X-B3-TraceId
X-Mod-Pagespeed
X-Url
Accept-Ch
X-MS-InvokeApp
Verso
SPRequestGuid
X-Powered-By-Plesk
X-D2id
X-TTL
X-Trace
X-ESI
X-VARITI-CCR
X-Server-Name
X-GitHub-Request-Id
Service-Worker-Allowed
X-SharePointHealthScore
Content-MD5
X-Sol
Pagespeed
X-Middleton-Response
Response
X-Kinja
X-GoogleNews-Bot
X-Kinja-Server
X-Use-Magma
X-Exp-Variant
X-Exp-Id
X-Kinja-Revision
X-Kinja-Build
X-Cdn-Fetch
Display
X-Middleton-Display
RTSS
Accept-Ch-Lifetime
X-Navigation-Version
SPIisLatency
SPRequestDuration
X-Vcache
X-Abt-Application-Version
X-Powered-CMS
X-Debug
X-Forwarded-Proto
X-Upstream
X-Cached
X-Amz-Server-Side-Encryption
X-Vcap-Request-Id
Public-Key-Pins
Charset
X-CST
MS-Author-Via
X-Version
DynaTrace
X-NF-Request-ID
X-Amz-Rid
Edge-Cache-Tag
Realpath
X-Px
X-DynaTrace-JS-Agent
MicrosoftSharePointTeamServices
Arr-Disable-Session-Affinity
X-Shard
TCN
X-Trafficlayer-App-Name
X-Trafficlayer-App-Scope
X-Ezoic-Cdn
X-Shield-Request-Id
X-Server-ID
X-MSEdge-Ref
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Fastly-Request-ID
X-Ser
Pinterest-Version
X-Pinterest-Rid
Access-Control-Request-Method
S
X-Accel-Expires
Fastly-Restarts
X-DIS-Request-ID
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-XRDS-Location
X-Client-IP
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Goog-Generation
Front-End-Https
X-Webapp-Samesite-None-Activated-N
X-Amz-Meta-S3cmd-Attrs
X-Recruiting
X-T
X-Id
X-Element-Page-Cache
X-Varnish-Age
X-Goog-Storage-Class
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-Realm
X-FTR-Backend
Cache-Tag
X-Country-Code-Real
X-FTR-DC
X-FTR-Backend-Server
X-Amzn-Trace-Id
Nginx-Cache
X-B3-TraceId-Primal
MRF-Tech
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
Mrf-Cache-Status
X-FTR-Expires
X-Dw-Request-Base-Id
Fastcgi-Cache
X-Content-Digest
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Cache-Config
X-Frontend
NR-ENABLED
Powered
X-Hits
X-Correlation-Id
X-Hp-Webp
X-Fastcgi-Cache
Alternate-Protocol
X-Kinsta-Cache
X-FTR-Cache-Host
X-Aspnetmvc-Version
X-Webkit-Csp
X-Content-Type
X-Request-Processing-Time
X-Request-Received
X-Ttl
ServerID
Server-Name
X-RateLimit-Remaining
X-Microsite
X-N
X-Request-Handler-Origin-Region
X-HS-Combine-CSS
TP-Cache
TP-L2-Cache
X-Cache-Hit
PB-PID
PB-RID
X-Grace
Arc-Version
X-Mobile-Rewrite
X-Rid
Healthy
X-Akamai-Edgescape
X-User-Agent
X-Node-Name
X-Analytics
Backend-Timing
X-Revision
X-Forwarded-For
X-Content-Security-Policy-Report-Only
X-Logged-In
X-Pad
X-Zen-Fury
AMP-Access-Control-Allow-Source-Origin
X-Mobile-URL
X-Amz-Apigw-Id
X-Amzn-RequestId
X-LB-Cache
Server-Node
X-Varnish-Grace
X-Oneagent-Js-Injection
X-AppVersion
X-Az
X-Activity-Id
Cache-Status
X-Cached-By
X-FastCGI-Cache
X-B3-Sampled
X-NWS-LOG-UUID
X-GUploader-UploadID
X-Content-Options
X-F-Cache
Refresh
X-Geo-Country
X-IPLB-Instance
X-Ruxit-Js-Agent
Upgrade-Insecure-Requests
X-Type
Retry-After
X-Varnish-Backend
X-Litespeed-Cache
X-Tumblr-Pixel-0
FilterID
X-Tumblr-Pixel
X-Tumblr-User
X-App-Environment
Accept-Charset
Host
X-Jobs
X-FB-Debug
Paypal-Debug-Id
X-Srv
X-Cache-2
Accept-CH-Lifetime
X-Page-Id
X-Cluster
X-PHP-Backend
X-Instance
X-Framework
X-B
X-AOL-HN
X-Debug-Info
DC
Actual-Object-TTL
X-Request-Guid
Access-Control-Allow-Method
Source
Accept-CH
X-WebKit-CSP-Report-Only
AR-PoweredBy
AR-CACHE
AR-ATIME
X-ATG-Version
Cache
X-TT
X-Erf-Bev-Bev
X-Cache-Age
X-Erf-Bev-Bev-Is-Generated
X-Seen-By
Fastcgi-Useragent
X-PressLabs-Stats
MS-CV
X-Git-Hash
X-Cache-Key
X-Content-Powered-By
X-Via-JSL
Ar-Sid
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
Host-Header
X-Amz-Replication-Status
X-B-Cache
X-Signature
X-Cache-TTL
X-Whom
X-Cache-Control
X-Wix-Request-Id
X-Daa-Tunnel
X-Cache-Enabled
X-Origin-Server
X-Response-Served-From
NGB
X-Mobile
Surrogate-Key
Xserver
X-UA
X-TA-CDN-Provider
X-ATS-Timestamp
X-RequestSource
X-Tumblr-Pixel-1
X-GeoIP
X-Host-Name
Cache-Tv-Group
X-Tumblr-Pixel-2
X-Cache-NE
Cleartype
X-FW-Type
X-FW-Server
X-FW-Serve
X-Handled-By
X-Hyper-Cache
WPE-Backend
Payment
X-FW-Hash
X-FW-Static
X-Cacheable-TTL
Eomportal-Instance
Datacenter
Filters
X-Region
X-Adobe-Loc
X-Adobe-Content
Frame-Options
X-Cache-Action
X-EdgeConnect-Cache-Status
X-SERVER
X-Drupal-Cache-Tags
X-TX-ID
Webserver
X-Esi
X-Load-Cache
X-Hostname
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Cache-Rule
X-Cache-Operation
X-Akamai-Transformed
AR-Request-ID
From-Origin
X-NewRelic-App-Data
X-ProcessESI
X-RemovedCookies
X-Edge-Location
X-Cache-TTL-Remaining
X-UA-Device-Type
Liferay-Portal
X-RTag
Ms-Operation-Id
X-Cache-Server
X-Varnish-Hostname
X-Forwarded-Host
X-Oss-Storage-Class
X-Oss-Server-Time
X-Oss-Object-Type
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-ORACLE-APMCS-REQUEST-ID
X-ORACLE-APMCS-TAG
X-XRDS-LOCATION
X-Varnish-Server
X-Rule
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Status
Country
X-Contextid
X-Upgrade-Enabled
Odigeo-Trace-Id
X-App-Server
X-UUID
X-BCube-Filmed-By
Load-Balancing
X-Cache-Var
X-Cache-Var-Map
X-Path-Route
X-RN-RSRV
Meta-Geo
X-ES-SERVER
X-TT-TIMESTAMP
DSUID
TWC-Privacy
TWC-Locale-Group
TWC-GeoIP-LatLong
Property-Id
Release
TWC-Connection-Speed
TWC-Device-Class
Webcakes-App-Name
TWC-GeoIP-Country
X-VCT
X-Origin-Hint
X-CCM
X-Debug-Cache
X-EIG-Tracking-Id
X-R9-Blue-Green-Version
X-Rocket-Nginx-Bypass
Webcakes-Region
X-From
DB-Nickname
Webcakes-App-Version
Mn-Server-Ip
X-Time
X-Cache-Config
X-Akamai-Request-ID
Selected-Fe
X-Cache-Host
X-Cache-Time
X-FireWall-Port
X-FC-Vary-Parameters
X-Drupal-Cache-Contexts
S-Rt
Origin-Edge-Control
Cache-Name
Azure-Version
Azure-SlotName
Cache-Tags
Fastly-SSL
Origin-Cache-Control
L5d-Success-Class
X-FW-Dynamic
X-Hosted-By
X-Soup
X-ServerID
X-Real-IP
X-Timing-Wait
X-TNCMS
X-Viewer-Country
X-Via-Fastly
X-Vgn-Hpd-Reason
X-Pubstack
X-Proxy-Build
X-Loop
X-IP
X-Human
X-OCL
X-Origin
X-Proxy
X-Proto
X-PCL
Azure-SiteName
X-Origin-Response-Time
Azure-RegionName
Azure-InstanceId
X-Redis-Cache
X-Generated
X-Is-Bot
X-JoinUs
X-Format
X-Goog-Meta-Goog-Reserved-File-Mtime
X-NWS-UUID-VERIFY
X-Akamai-Request-ID2
X-Access
X-Backend-Name
X-Cluster-Name
X-Content-Age
X-Labrador-Cache-Channel
X-Rendered-As
Uber-Trace-Id
X-BYPASS-REASON
X-ProxyCache-Key
X-ProxyCache-Status
X-Xfnlog-Site
X-Www-Served-By
Viewport
X-Section
X-Varnish-Hits
X-Web-Node
X-Locale
X-Site-Version
NGX
Ec-Rule-Version
X-Varnish-Cache-Hits
Server-Info
Decoy-Debug-Status
S-Cnection
X-Accel-Buffering
Decoy-Debug-Key
Version
Decoy-Debug-TTL
X-Time-Microsecs
X-Generated-By
Tracecode
X-Cache-Backend
X-PHP-Host
X-ApacheServer
X-PERF
X-Info
X-Amzn-Remapped-Content-Length
X-Storage
X-Origin-TTL
X-Origin-CC
X-SaId
X-App-Version
X-URL
X-VCache
Akamai-GRN
X-Geo
X-WA-Info
X-Nginx-Cache-Key
Rt-Fastcgi-Cache
X-CF-Powered-By
Cteonnt-Length
Time
X-MServer
X-Guploader-Uploadid
Cache-Key
X-No-Session
X-L-Path
Origin
X-Environment-Context
X-RateLimit-Limit
X-Cache-Remote
GEO-INFO
X-Tec-Api-Root
Accept-Language
X-Tb
X-FB-TRIP-ID
Access-Control-Request-Headers
X-Tec-Api-Origin
X-Tec-Api-Version
X-Presslabs-Stats
X-CACHE-KEY
X-GoCache-CacheStatus
X-SayCDN-TTL
X-NCache
X-B3-SpanId
X-Say-Cacheable
X-Say-TTL
X-Unique-Id
X-EC-Lua
X-Hit
X-Backend-TTL
Vix-Hermes-Req-Id
Cache-Hits
X-RCS-CacheZone
X-ShardId
X-Alternate-Cache-Key
X-Trace-Id
X-Sorting-Hat-PodId
X-ShopId
X-APP-VERSION
X-Shopify-Stage
X-Sorting-Hat-ShopId
X-Shopify-Generated-Cart-Token
X-Source
Srv
X-Device-Type
Mime-Version
X-CS
OT-Force-Account-Verify
X-Tumblr-Pixel-3
X-S
X-CDN-Forward
X-SS-Set-Cookie
X-TIME
X-OVcl
X-OVcl-Cache
X-Accel-Expires-Debug
Apple-News-Services-Host
Apple-News-Services-Request-Url
X-A-Wwc
Apple-News-Services-Parsed-Url
Machine
X-ARC
IsBot
Fastcgi-X-Cache-Version
Cross-Origin-Window-Policy
Content-Style-Type
BehaviorPad-Version
X-Application
AsisCache
X-Aed
X-AIR-PT
Apple-News-Services-Handled
Arc-Country
Meta-Geo-Continent
Rt-Proxy-Cache
Request-EU
Request-Country
X-Magnolia-Registration
Server-Host
T-Server
Viewtype
VivaBuild
X-A
X-Endurance-Cache-Level
X-A-Dam
MD5-Digest
X-A-Dcw
Mobile-Detection-Method
User-Cache-Control
X-A-Ccd
Rendered-Blocks
Node
X-A-Dgt
X-Destination
X-G
X-Service
X-PAYTM-SRV-ID
X-SRCache-Key
X-Twitter-Response-Tags
X-S-Cookie
X-Processor
X-VG-WebServer
X-Trv-Group
X-Hl-Ver
X-Cluster-Node
X-VG-WebCache
X-Svr
X-CSRF-TOKEN
X-Server-Time
X-Vdms-Version
Content-Script-Type
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
X-ScT
X-DPWN-IS-SECURE
X-External-Request-Id
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-Rojux
X-Upstream-Ht
X-Upstream-Ct
X-Ah-Environment
X-Connection-Hash
X-SIPLIST1
X-Session-Fingerprint
X-Rewrite-Enabled
X-B-Cookie
X-Detected-As
X-Region-Sid
X-Date
X-D
X-Transaction
Xc-Version
X-Request-UUID
X-Parent-Response-Time
ServerName
ServedBy
X-Dc
X-Matched-Rule
X-Location
X-Thinkindot-L3
X-Reboot
Thinkindot-CacheControl-Type
X-Dispatcher-Server
X-Webstats-RespID
Wxu-Next-Region
Wxu-Next-Hostname
X-Dispatch
X-CUA
X-Cache-Bucket
X-Core-Value
X-ND-Cache
Wxu-Next-Commit
X-Generated-On
X-Instart-Isnd
X-Via-NSCOPI
Server-Int
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-Hash
Thinkindot-Control
Thinkindot-CacheControl
X-Level-Front-Cache
Served-By
We-Hiring
Mail-Subject
X-Nc
Now
Proxy-Connection
X-SRV
NtCoent-Length
X-Uri
X-Cache-Debug
X-B3-Parentspanid
X-Azure-Ref-OriginShield
X-Cache-FS-Status
X-Ms-Version
X-Backend-State
X-Method
X-Bip
X-Block-Status
X-Logging-Id
X-BBXSRF
X-Ms-Request-Id
X-Azure-Ref
X-C
X-Amz-Meta-Cache-Control
X-Owner
X-Origin-Expires
X-Cache-Grace
X-Planisys-CDN-Cache
X-FW-Version
X-Planisys-CDN-Rules
X-Origin-Date
X-Old-Content-Length
X-Cache-Info
X-App-Name
X-Agile-Id
X-Agile-Age
X-NX-Host
X-Agile
X-Auto-Login
X-Li-Pop
X-Developers
X-Hnp-Log
X-Has-Esi
X-Varnish-Beresp-Grace
X-Debug-Log
X-Debug-Cache-Store
X-Debug-Cookies
X-GeoIP-City
X-Distil-CS
X-Eu-Site
X-Gen-Mode
X-Fastly-Cache
X-Epic-Correlation-Id
X-Generation-Time
X-Distributor
X-Geo-Header
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-CGP
X-Key
X-Clara-WADP
X-Li-Fabric
X-Cdn-Srv
X-Cache-URL
X-Platform-Server
X-Clientip
X-Cms-Context
X-Irp-Debug
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Status
X-Is-Gdpr
X-Core-Mission
X-Compress-Hint
X-JWT-State
X-LI-UUID
X-Planisys-CDN-TTL
X-VC-Cache
X-Variation
X-User
L
Cache-Host
IBM-Web2-Location
Is-Eu
Magicmarker
AKAMAI
X-SVT-ORM-VERSION
PFcat
X-Thanos
X-Up
Memcached
Adler-Geo
Heartbleed
HA-Ipaddr
Esi-Enabled
X-Wikidot-Backend
CDCHOST
Countrycode
Content-Disposition
X-Wikidot-Static-Cache
Fastly-Soc-X-Request-Id
X-WebServer
Gh-Request-Id
Ha-Gx-Prefs
X-VG-TLSProxy
X-VServer
X-We-Are-Hiring
X-WADP-Cache
X-SVT-ORM-RULES
X-TrackingId
X-Rocket-Build-Number
X-Request-URI
X-Request-Start
X-S-Maxage
X-Scheme
SD-X-WS
Platform
X-Reqid
X-Release
X-Proxy-Cache-Status
W
Web-Mar-Node
X-Proxy-Upstream
X-Qloud-Router
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-SD-PageType
Section-Io-Cache
X-Skip-Cache
X-Sigma
X-Sigma-Backend
Pramga
RNT-Time
X-Server-IP
RNT-Machine
X-Sucuri-Cache
Cache-Provider
X-LI-Proto
X-Trafficlayer-App-Version
X-Generated-In
X-Policy
Server-ID
X-Swa-Ws
X-Cache-Id
X-Internal-Host
Kp-EeAlive
X-Cdn-Forward
X-Via-CDN
X-Urbn-Site-Id
Cdnsip
X-ServiceProvider
Powered-By-ChinaCache
X-Urbn-Context-Path
X-NodeID
X-MSEdge-Flight
X-MSEdge-Features
V-Age
True-Client-Country-4JS
X-AK-Request-ID
Cdncip
Locale
Environment
X-B3-Traceid
X-Req
X-Served-From
Locid
X-Servername
X-Sucuri-Id
X-HTML-Minification-Powered-By
X-GRACE
X-NC
GEO-REGION-INFO
X-Lb-Id
FNAC-ModuleRouting
X-Gamma-Serve
X-Be
Hostname
X-Nginx-Cache
X-UnsetCookies
X-B3-Spanid
X-Newrelic-Synthetics
Geo-Info
X-Refresh
X-7Graus-Varnish-XKeys
X-7Graus-Varnish-Cache-Control
CF-IPCountry
X-IPS-LoggedIn
X-FPC
X-VHOST
X-Render-Time
X-NU-AKA-ACS-Version
X-Servedbyhost
X-Developer
X-Tb-Optimization-Total-Bytes-Saved
ProcessTime
Tcn
A
X-Edge-O15-RID
X-MP-GENERATED-AT
X-Mode
X-Webkit-CSP
X-Cdn-Origin
X-Sn-Servicetimems
X-GeoIP-Country-Code
X-Microcachable
X-Device-Os
X-Zone
X-Sucuri-ID
X-Pjax-Url
X-Node-Id
X-Ratelimit-Remaining
X-AWS-Id
X-DC
X-LJ-Flow-ID
X-FORWARDED-FOR
X-VWS-Id
X-Routing-Service
X-Proxied
X-Zipkin-Id
TTL
Memory
X-Pf-Uncompressing
Gannett-Cam-Experience-Id
X-COUNTRY
Request-Time
X-Correlation-ID
Cf-Ipcountry
Pics-Label
X-VCL-Version
Amp-Access-Control-Allow-Source-Origin
X-ZONE
CF-Cached-On
X-Unique-ID
X-CSRF-Token
Cache-Cookie-Set-Idcheck
X-Pod
Cache-Cookie-Set-Lfrom
Resin-Trace
GeoIp-Country-Code
Geoip-Latitude
GeoIP-Country-Code
Cache-Cookie-Set-From
GeoIP-Latitude
PICS-Label
M-TraceId
HostName
Group
X-Via-Edge
X-Via-SSL
Cdn
GeoIP-City
X-Bc
X-Request-Time
X-Ratelimit-Limit
X-ECACHE
Host-ID
XServer
X-NODE
X-ElasticPress-Search
X-Vcl-Version
Geoip-City
X-Cdn-Request-ID
X-Instart-Info
X-Swift-Error
MIME-Version
X-BC
X-CLOUD-TRACE-CONTEXT
X-Backend-Url
X-TH-Server
X-PF-Uncompressing
X-Backend-Host
Ttl
X-Var-Ttl
X-APP
HitType
X-Check-Cacheable
Backend-Name
Ohc-File-Size
Ohc-Cache-HIT
X-NGINX-Cache
Powered-By
X-NGENIX-Cache
URI
REQUESTUUID
Pagetype
Lfy
N-Cache
X-UPSTREAM-Address
X-Fastly-Country-Code
Fly-Cache
X-PJAX-URL
User-Agent
X-Fstrz
On-Server
Fly-Request-Id
Media-Length
Cache-Prefix
X-HostName
X-Worker
X-WR-MODIFICATION
X-Via-Ucdn
X-Aicache-OS
X-Cache-Tag
X-ServedByHost
X-Tt-Trace-Tag
X-LiteSpeed-Cache-Control
SRV
X-Tt-Trace-Host
X-HS-Status
X-Fetched-On
X-Hp-Ccpa-Warning
Who
X-Sedo-Request-Id
FSS-Cache
FSS-Proxy
Pragrma
CDN
X-WA
X-Cache-Miss-From
AR-SID
X-Fpc
X-BE
X-Server-W
UCS
X-NYM-Debug-Backend
X-GEO
Fastly-SWR
X-LAGOON
X-Varnish-Cacheable
Processtime
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-LB-ID
X-Cache-Tags
X-Wa
Fastly-SIE
X-Varnish-URL
X-Cf-Powered-By
X-Store
X-Fastly-Backend-Reqs
Debug
X-Contensis-Viewer-Groups
X-Varnish-Authentication
X-ServerName
X-Cache-ASPX
X-Upstream-CT
Server-Surrogate-Control
X-Upstream-HT
Server-Cache-Control
X-Ua
X-Ftr-Cache-Host
X-Akamai-ERRuleID
X-Apw-Access-Token
X-Apw-Hits
X-Apw-Access-Object
X-Akamai-ERPolicy
Location
X-TT-LOGID
Fastly-Backend-Name
X-Varnish-Beresp-TTL
X-Apw-Access-Action
Country-Code
X-Protected-By
X-BACKEND-TTL
WP-Super-Cache
X-VC
Xet-Cookie
X-Amzn-Remapped-Date
X-Fastly-Cache-Hits
Application
Product
Thinkindot-Cache-Type
X-Gen-Id
SID
X-Li-Proto
X-Dw-Trace-Id
Server-Id
X-Nananana
XxX-Cache-Status
Cneonction
X-Amzn-Remapped-Connection
NnCoection
X-Request-Url
X-GDPR
X-SB