Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
CF-RAY
CF-Cache-Status
Pragma
Link
X-Powered-By
ETag
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-Cache-Hits
X-UA-Compatible
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Xss-Protection
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Download-Options
Alt-Svc
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-FRAME-OPTIONS
X-Drupal-Cache
X-Adblock-Key
X-Check
Content-Security-Policy-Report-Only
X-Generator
X-Cache-Status
X-Cacheable
X-Permitted-Cross-Domain-Policies
X-Request-ID
Timing-Allow-Origin
X-Template
X-Language
X-Iinfo
X-DNS-Prefetch-Control
X-Content-Security-Policy
Status
Content-Encoding
X-Buckets
X-AspNetMvc-Version
X-Ua-Compatible
Upgrade
Access-Control-Expose-Headers
X-Kinja-Server-Push
Xkey
Access-Control-Max-Age
X-CDN
Keep-Alive
X-Turbo-Charged-By
X-Via
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Age
X-Pass-Why
X-Envoy-Upstream-Service-Time
X-Backend
EagleId
X-Robots-Tag
X-Amz-Id-2
X-Amz-Request-Id
X-Page-Speed
X-Pingback
X-Server-Powered-By
X-UA-Device
X-AH-Environment
X-Swift-CacheTime
X-Swift-SaveTime
X-Proxy-Cache
X-Hacker
X-Server
X-Nginx-Cache-Status
Ali-Swift-Global-Savetime
Request-Context
Grace
X-Varnish-Cache
Server-Timing
Feature-Policy
Cf-Railgun
X-Amz-Version-Id
X-Dns-Prefetch-Control
X-LiteSpeed-Cache
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Rq
X-Ac
Report-To
EagleEye-TraceId
X-Server-Id
X-Response-Time
X-WebKit-CSP
X-OneAgent-JS-Injection
X-Cdn
Request-Id
X-Cnection
X-Host
X-Backend-Server
Content-Location
X-Cloud-Trace-Context
X-DataDome
X-Node
X-Readtime
X-Origin-Cache
X-Cache-Lookup
X-Vhost
NEL
X-Application-Context
X-Dispatcher
X-ORACLE-DMS-ECID
X-HW
Allow
X-ORACLE-DMS-RID
X-Clacks-Overhead
X-Rack-Cache
X-Origin-Upstream-Status
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Country
Surrogate-Control
Rating
X-DynaTrace
Pinterest-Generated-By
X-FTR-Request-ID
X-Country-Code
X-Goog-Hash
Fusion-Component-Id
Fusion-Template-Id
Fusion-Content-Source
Fusion-Content-Id
Fusion-Source
X-MS-InvokeApp
X-Akam-SW-Version
X-Varnish-TTL
X-TtlSet
X-Vname
X-PC
Accept-Ch
X-Url
X-Instart-Request-ID
X-B3-TraceId
X-Ruxit-JS-Agent
X-Aspnetmvc-Version
X-Powered-By-Plesk
Edge-Control
Verso
X-Ws-Request-Id
SPRequestGuid
X-Mod-Pagespeed
X-Sol
X-Middleton-Response
Response
X-Middleton-Display
Display
X-SharePointHealthScore
X-Ah-Environment
X-Kinja
X-Kinja-Build
X-Kinja-Revision
X-Exp-Variant
X-Cdn-Fetch
X-Exp-Id
X-Use-Magma
X-GoogleNews-Bot
X-Kinja-Server
X-D2id
X-VARITI-CCR
X-Trace
Accept-Ch-Lifetime
X-ESI
RTSS
X-Server-Name
Service-Worker-Allowed
SPIisLatency
SPRequestDuration
X-GitHub-Request-Id
X-Server-ID
X-CST
X-Powered-CMS
X-Vcap-Request-Id
X-Debug
X-Navigation-Version
X-Abt-Application-Version
Public-Key-Pins
X-Px
Pagespeed
Content-MD5
X-Amz-Server-Side-Encryption
MS-Author-Via
X-Version
X-Upstream
X-TTL
Charset
X-Amz-Rid
X-NF-Request-ID
Realpath
X-Forwarded-Proto
X-Recruiting
DynaTrace
X-Shard
X-Cached
Fastly-Restarts
X-Vcache
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
Pinterest-Version
X-Pinterest-Rid
MicrosoftSharePointTeamServices
TCN
X-Ezoic-Cdn
X-SERVER
Nginx-Cache
Access-Control-Request-Method
X-MSEdge-Ref
X-Shield-Request-Id
Arr-Disable-Session-Affinity
X-DynaTrace-JS-Agent
Edge-Cache-Tag
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-XRDS-Location
X-SRCache-Store-Status
X-SRCache-Fetch-Status
S
Front-End-Https
X-Fastly-Request-ID
X-Ser
X-Amz-Meta-S3cmd-Attrs
X-Accel-Expires
X-DIS-Request-ID
X-Goog-Storage-Class
X-Id
X-Element-Page-Cache
X-T
X-Varnish-Age
X-Ttl
X-Client-IP
X-FTR-DC
X-FTR-Cache-Status
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Backend
X-RateLimit-Remaining
X-FTR-Balancer
X-FTR-Realm
MRF-Tech
X-Mrf-Item-Lastmod
Mrf-Cache-Status
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
X-FTR-Expires
X-Amzn-Trace-Id
X-Webkit-Csp
X-Dw-Request-Base-Id
X-Fastcgi-Cache
NR-ENABLED
Fastcgi-Cache
X-HS-Hub-Id
X-HS-Content-Id
X-Frontend
Ar-Sid
AR-CACHE
AR-ATIME
AR-PoweredBy
Powered
X-Content-Digest
X-Hits
X-Forwarded-For
X-Correlation-Id
X-Grace
ServerID
X-Trafficlayer-App-Scope
X-Trafficlayer-App-Name
X-Kinsta-Cache
X-FTR-Cache-Host
Cache-Tag
X-Litespeed-Cache
X-Cache-Hit
X-Oneagent-Js-Injection
TP-Cache
TP-L2-Cache
AMP-Access-Control-Allow-Source-Origin
X-Node-Name
X-Content-Type
PB-PID
PB-RID
X-HS-Cache-Config
X-Request-Received
X-Srv
X-Request-Processing-Time
Arc-Version
X-N
X-Mobile-Rewrite
X-Zen-Fury
X-Request-Handler-Origin-Region
X-Microsite
X-Via-JSL
Alternate-Protocol
Server-Name
X-Hp-Webp
AR-Request-ID
X-User-Agent
Server-Node
X-Rid
Paypal-Debug-Id
X-LB-Cache
Healthy
X-Revision
Backend-Timing
X-Analytics
X-Logged-In
Retry-After
Cache-Status
X-Az
X-Activity-Id
X-AppVersion
X-Ruxit-Js-Agent
X-IPLB-Instance
X-FastCGI-Cache
X-Content-Security-Policy-Report-Only
X-Akamai-Edgescape
X-Webapp-Samesite-None-Activated-N
X-Type
X-Amz-Apigw-Id
X-Amzn-RequestId
X-NWS-LOG-UUID
X-Cached-By
X-GUploader-UploadID
X-Cache-Age
FilterID
X-Varnish-Grace
X-Pad
X-HS-Combine-CSS
X-B3-Sampled
X-Webkit-CSP
X-F-Cache
Refresh
X-Content-Options
X-Tumblr-Pixel
X-Instance
X-Tumblr-User
X-Debug-Info
Accept-Charset
X-Seen-By
X-Mobile-URL
X-Tumblr-Pixel-0
Source
X-B
X-Cluster
X-Whom
DC
X-Geo-Country
Access-Control-Allow-Method
Actual-Object-TTL
X-Framework
X-App-Environment
X-Request-Guid
X-FB-Debug
X-PHP-Backend
X-Page-Id
X-Jobs
X-AOL-HN
Host
X-VCache
X-Erf-Bev-Bev
X-PressLabs-Stats
X-Erf-Bev-Bev-Is-Generated
X-Cache-Key
X-Content-Powered-By
MS-CV
Upgrade-Insecure-Requests
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
Fastcgi-Useragent
X-Cache-2
X-WebKit-CSP-Report-Only
X-Varnish-Backend
X-ATG-Version
X-Time
X-Host-Name
X-TA-CDN-Provider
X-Git-Hash
X-Cache-Control
X-Forwarded-Host
X-TT
X-Cache-Rule
X-Cache-Operation
X-Cache-TTL
Surrogate-Key
X-Amz-Replication-Status
Frame-Options
X-FW-Type
X-FW-Static
X-Esi
X-FW-Serve
X-FW-Hash
X-Daa-Tunnel
X-FW-Server
X-Kong-Proxy-Latency
Cache
X-Wix-Request-Id
X-Kong-Upstream-Latency
Tracecode
X-Mobile
Xserver
NGB
X-Response-Served-From
X-Origin-Server
X-UA-Device-Type
X-B-Cache
X-Signature
X-Tumblr-Pixel-2
X-App-Server
X-ProcessESI
X-RemovedCookies
WPE-Backend
Host-Header
X-Tumblr-Pixel-1
X-Region
X-RateLimit-Limit
X-Cache-NE
Webserver
Cleartype
From-Origin
X-TX-ID
X-Cacheable-TTL
Payment
X-Handled-By
X-GeoIP
X-RequestSource
X-Drupal-Cache-Tags
X-Hyper-Cache
X-Cache-Action
Eomportal-Instance
Cache-Tv-Group
X-Adobe-Content
X-Adobe-Loc
Filters
Ms-Operation-Id
X-RTag
X-Cache-Enabled
X-EdgeConnect-Cache-Status
Accept-CH-Lifetime
Datacenter
Accept-CH
X-Cache-TTL-Remaining
X-Status
X-NewRelic-App-Data
X-Akamai-Transformed
X-Contextid
X-UA
X-Cache-Server
Liferay-Portal
X-BCube-Filmed-By
X-TT-TIMESTAMP
X-Hostname
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Edge-Location
X-XRDS-LOCATION
X-FW-Dynamic
Odigeo-Trace-Id
X-Load-Cache
X-App-Version
Version
X-IP
Server-Info
X-Varnish-Hostname
X-Cache-Var-Map
X-ES-SERVER
X-Cache-Var
Meta-Geo
X-RN-RSRV
Load-Balancing
X-Path-Route
X-Viewer-Country
X-Varnish-Server
X-Xfnlog-Site
X-OCL
X-Cache-Config
X-PCL
X-Content-Age
Cache-Tags
DB-Nickname
Country
X-Via-Fastly
X-CCM
X-Info
X-Rule
X-Pubstack
X-Debug-Cache
X-Web-Node
Property-Id
X-Origin-Hint
Origin-Cache-Control
Mn-Server-Ip
Origin-Edge-Control
L5d-Success-Class
Azure-Version
Azure-InstanceId
X-TNCMS
Azure-RegionName
Azure-SlotName
Cache-Name
Release
X-Origin-Response-Time
TWC-GeoIP-Country
X-EIG-Tracking-Id
X-Drupal-Cache-Contexts
X-Cache-Time
X-Cache-Host
X-FC-Vary-Parameters
X-From
X-Labrador-Cache-Channel
X-Human
X-Hosted-By
X-Loop
X-Akamai-Request-ID
Webcakes-Region
X-Proto
TWC-Device-Class
TWC-Connection-Speed
X-Origin
TWC-GeoIP-LatLong
TWC-Locale-Group
Webcakes-App-Version
Webcakes-App-Name
TWC-Privacy
S-Rt
Azure-SiteName
X-Proxy
X-UUID
X-ServerID
X-Real-IP
X-R9-Blue-Green-Version
X-Varnish-Cache-Hits
GEO-INFO
Viewport
X-Section
X-Vgn-Hpd-Reason
S-Cnection
Ec-Rule-Version
X-WA-Info
X-Locale
X-Upgrade-Enabled
X-Soup
X-ApacheServer
X-Format
X-FireWall-Port
X-Generated
X-Goog-Meta-Goog-Reserved-File-Mtime
X-JoinUs
X-Timing-Wait
X-Www-Served-By
X-Akamai-Request-ID2
DSUID
X-Backend-Name
X-Cluster-Name
X-Access
Selected-Fe
X-Proxy-Build
X-VCT
X-Rendered-As
X-Site-Version
X-Redis-Cache
X-PERF
Fastly-SSL
X-Time-Microsecs
X-Cache-Grace
Decoy-Debug-Key
X-Varnish-Hits
Decoy-Debug-Status
Decoy-Debug-TTL
X-Rocket-Nginx-Bypass
Rt-Fastcgi-Cache
Cache-Key
X-Storage
X-NWS-UUID-VERIFY
X-Origin-TTL
X-Origin-CC
NGX
Vix-Hermes-Req-Id
X-Cache-Remote
Cache-Hits
Cteonnt-Length
X-Guploader-Uploadid
X-B3-SpanId
X-Is-Bot
X-Hit
X-GoCache-CacheStatus
X-NCache
X-ProxyCache-Status
X-BYPASS-REASON
Uber-Trace-Id
X-Backend-TTL
Time
X-ProxyCache-Key
X-Trace-Id
X-CF-Powered-By
X-SS-Set-Cookie
X-Device-Type
X-CS
Origin
Hostname
X-Cache-Backend
X-PHP-Host
Mime-Version
X-UnsetCookies
X-Tumblr-Pixel-3
X-Generated-By
X-Amzn-Remapped-Content-Length
X-OVcl
X-OVcl-Cache
X-Cluster-Node
Accept-Language
X-S
Akamai-GRN
X-ATS-Timestamp
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-Oss-Storage-Class
X-Via-CDN
X-Oss-Object-Type
X-Cdn-Forward
X-Nginx-Cache-Key
Fastcgi-X-Cache-Version
X-FB-TRIP-ID
X-Accel-Buffering
X-Uri
Now
X-L-Path
X-Environment-Context
X-FW-Version
X-B3-Traceid
X-URL
X-Tb
OT-Force-Account-Verify
X-No-Session
X-MServer
User-Cache-Control
X-ORACLE-APMCS-TAG
X-ORACLE-APMCS-REQUEST-ID
ServedBy
ServerName
X-Tec-Api-Version
Content-Style-Type
Cross-Origin-Window-Policy
X-B-Cookie
X-ARC
X-Application
Content-Script-Type
X-CF-Lambda-Version
X-D
X-Date
X-Connection-Hash
X-AIR-PT
X-CF-Lambda-Fn
Access-Control-Request-Headers
X-A-Wwc
Rt-Proxy-Cache
Machine
T-Server
Viewtype
MD5-Digest
Meta-Geo-Continent
Node
Rendered-Blocks
Request-Country
Request-EU
VivaBuild
X-Tec-Api-Origin
X-Tec-Api-Root
X-A-Dgt
X-Destination
X-Accel-Expires-Debug
X-A-Dcw
X-A-Dam
IsBot
X-A
X-A-Ccd
X-Aed
X-Detected-As
X-Server-Time
X-Session-Fingerprint
X-SIPLIST1
Apple-News-Services-Handled
X-ScT
X-NC
X-Rewrite-Enabled
X-Rojux
X-S-Cookie
Apple-News-Services-Host
X-SRCache-Key
X-Svr
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
A
Xc-Version
X-VG-WebServer
X-VG-WebCache
X-Transaction
X-Trv-Group
X-Twitter-Response-Tags
X-Request-UUID
X-SayCDN-TTL
X-G
X-Hl-Ver
BehaviorPad-Version
AsisCache
X-External-Request-Id
X-DPWN-IS-SECURE
X-CACHE-KEY
Mobile-Detection-Method
X-Developer
X-Presslabs-Stats
Arc-Country
Apple-News-Services-Request-Url
X-Processor
X-CSRF-TOKEN
X-Say-TTL
X-Region-Sid
Apple-News-Services-Parsed-Url
X-PAYTM-SRV-ID
X-Say-Cacheable
X-Endurance-Cache-Level
CDCHOST
Cache-Host
X-Cdn-Origin
X-Ms-Version
X-Node-Id
X-Ms-Request-Id
X-Location
X-Instart-Isnd
X-NX-Host
X-Proxy-Cache-Status
X-Sn-Servicetimems
X-WADP-Cache
X-S-Maxage
X-Request-URI
X-Proxy-Upstream
X-Hnp-Log
X-Gen-Mode
X-Block-Status
X-Cache-Bucket
Web-Mar-Node
Server-Int
RNT-Time
X-Cache-Debug
X-Cache-Info
X-Debug-Log
X-Debug-Cookies
X-Cms-Context
X-Clara-WADP
RNT-Machine
X-Device-Os
We-Hiring
X-Shopify-Stage
X-ShopId
X-ShardId
X-Alternate-Cache-Key
X-Sorting-Hat-PodId
Mail-Subject
X-Sorting-Hat-ShopId
X-Sucuri-Id
NtCoent-Length
X-Varnish-Beresp-Ttl
Proxy-Connection
X-Nc
X-Varnish-Beresp-Status
X-B3-Parentspanid
X-Varnish-Beresp-Grace
X-Internal-Host
X-Backend-State
X-BBXSRF
X-IN-APIGATEWAYSSL
X-Hash
X-Bip
X-GeoIP-City
X-Has-Esi
X-IN-APIGATEWAY
X-Irp-Debug
X-Li-Fabric
X-Li-Pop
X-LI-UUID
X-Key
X-Auto-Login
X-Is-Gdpr
X-JWT-State
X-Azure-Ref
X-Azure-Ref-OriginShield
X-Cache-FS-Status
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Developers
X-CUA
X-Core-Mission
X-CGP
X-Clientip
X-Compress-Hint
X-Dispatch
X-Dispatcher-Server
X-Fastly-Cache
X-Cache-Id
X-Generated-In
X-Eu-Site
X-Epic-Correlation-Id
X-Distil-CS
X-Cache-URL
X-Distributor
X-Cdn-Srv
X-Origin-Expires
X-VServer
X-We-Are-Hiring
X-WebServer
X-Webstats-RespID
X-VG-TLSProxy
X-VC-Cache
X-TrackingId
X-Up
X-User
X-Variation
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Level-Front-Cache
X-Matched-Rule
X-Reboot
X-Thinkindot-L3
X-Generated-On
Thinkindot-Control
Server-Host
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-Thanos
X-Swa-Ws
Adler-Geo
X-Policy
X-Qloud-Router
X-RateLimit-Limit-Second
X-Owner
X-Origin-Date
X-Magnolia-Registration
X-Method
X-Old-Content-Length
X-RateLimit-Remaining-Second
X-Release
X-Service
X-Skip-Cache
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Server-IP
X-SD-PageType
X-Reqid
X-Request-Start
X-Scheme
X-Logging-Id
X-Platform-Server
SD-X-WS
Pramga
Platform
PFcat
Section-Io-Cache
Served-By
Wxu-Next-Hostname
Wxu-Next-Commit
W
True-Client-Country-4JS
Memcached
Magicmarker
Gh-Request-Id
Fastly-Soc-X-Request-Id
Esi-Enabled
Countrycode
Ha-Gx-Prefs
HA-Ipaddr
L
Kp-EeAlive
Is-Eu
Wxu-Next-Region
IBM-Web2-Location
X-Agile-Id
X-Agile
X-Amz-Meta-Cache-Control
X-Agile-Age
X-App-Name
Cache-Provider
X-Parent-Response-Time
X-C
X-Generation-Time
X-MSEdge-Features
X-LI-Proto
X-Geo-Header
X-7Graus-Varnish-XKeys
X-NodeID
X-Urbn-Site-Id
X-Urbn-Context-Path
AKAMAI
Content-Disposition
Heartbleed
Locale
X-Lb-Id
X-7Graus-Varnish-Cache-Control
X-MSEdge-Flight
X-SaId
V-Age
X-APP-VERSION
Server-ID
X-Dc
X-ServiceProvider
Tcn
X-Core-Value
X-Geo
PageSpeed
Request-Time
X-GEO
X-Servername
X-Vdms-Version
Environment
X-GRACE
CF-IPCountry
Srv
X-NGENIX-Cache
X-ECACHE
X-Newrelic-Synthetics
GEO-REGION-INFO
X-Sucuri-Cache
X-FPC
X-Pjax-Url
X-EC-Lua
Cdncip
Cdnsip
X-Sigma
X-Sigma-Backend
X-AK-Request-ID
X-Be
X-Rocket-Build-Number
X-Shopify-Generated-Cart-Token
X-ElasticPress-Search
X-Instart-Info
Group
X-Unique-ID
X-Datadome
X-Planisys-CDN-Rules
X-Nginx-Cache
X-Servedbyhost
Ohc-File-Size
Ohc-Cache-HIT
X-Backend-Url
X-Tb-Optimization-Total-Bytes-Saved
X-Backend-Host
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
X-VHOST
X-CDN-Forward
SRV
X-Upstream-Ht
Backend-Name
X-Via-NSCOPI
X-Var-Ttl
X-Microcachable
Powered-By-ChinaCache
X-Upstream-Ct
Resin-Trace
X-B3-Spanid
X-Source
X-Unique-Id
X-ND-Cache
N-Cache
Memory
X-DC
X-IPS-LoggedIn
X-Zone
X-RCS-CacheZone
Pagetype
Cache-Prefix
Fly-Cache
Fly-Request-Id
CF-Cached-On
X-Trafficlayer-App-Version
X-Oracle-Dms-Rid
Lfy
X-Upstream-HT
X-Upstream-CT
X-Ua
X-VWS-Id
X-AWS-Id
X-LJ-Flow-ID
X-VCL-Version
Cdn
X-Worker
X-Dynatrace
X-Req
X-Check-Cacheable
Gannett-Cam-Experience-Id
Locid
X-COUNTRY
X-Via-Ucdn
X-Served-From
X-Correlation-ID
Cf-Ipcountry
Amp-Access-Control-Allow-Source-Origin
FNAC-ModuleRouting
X-Ratelimit-Reset
Pics-Label
TTL
X-Refresh
X-Gamma-Serve
X-Server-W
X-Ratelimit-Remaining
X-Pf-Uncompressing
X-CSRF-Token
X-Sedo-Request-Id
Geoip-City
Geoip-Latitude
GeoIp-Country-Code
X-Wa
X-Fetched-On
X-Cache-Miss-From
GeoIP-City
Fastly-SWR
GeoIP-Country-Code
GeoIP-Latitude
X-Rebelmouse-Surrogate-Control
X-Pod
Fastly-SIE
Geo-Info
X-Rebelmouse-Cache-Control
X-Upstream-Proxy
X-PF-Uncompressing
Ttl
M-TraceId
REQUESTUUID
PICS-Label
X-Via-Edge
X-Via-SSL
X-Tt-Trace-Tag
X-Sucuri-ID
X-Bc
XServer
X-Vcl-Version
X-Render-Time
X-TIME
X-APP
X-HS-Status
X-ZONE
X-CLOUD-TRACE-CONTEXT
ProcessTime
X-Fstrz
X-NU-AKA-ACS-Version
X-GDPR
X-LiteSpeed-Cache-Control
X-SRV
X-HTML-Minification-Powered-By
X-HostName
Cache-Cookie-Set-Idcheck
X-Edge-Server
Cdn-Request-Time
Cache-Cookie-Set-From
X-GeoIP-Country-Code
Cache-Cookie-Set-Lfrom
Cdn-Host
X-Mode
X-Ratelimit-Limit
X-Aicache-OS
X-Fastly-Country-Code
X-SN
X-Dynatrace-Js-Agent
X-Hello
X-Flog
SS
On-Server
Pragrma
X-Response-By
X-Org
User-Agent
X-Cache-Tag
X-ServedByHost
X-ABtesting
X-Swift-Error
MIME-Version
X-WR-MODIFICATION
X-BC
HitType
URI
X-FORWARDED-FOR
Host-ID
X-NGINX-Cache
HostName
X-WA
Who
X-BE
X-MP-GENERATED-AT
X-TT-LOGID
Requestid
X-RateLimit-Reset
CACHE
X-UPSTREAM-Address
X-PJAX-URL
Country-Code
X-RPM
X-RPS
X-Page-Type
X-Edge-O15-RID
SN
X-DW
X-DB
X-DI
X-DSS
X-Action
X-RSL
X-Cache-Ttl
X-Fastly-Backend-Reqs
Dynatrace
X-LAGOON
X-Cdn-Request-ID
X-Varnish-URL
X-Varnish-Cacheable
X-Fpc
X-ServerName
X-Cf-Powered-By
RequestUuid
DataCenter
Lb
Is-Session-Tracking
LB
X-Varnish-Beresp-TTL
Get-Access-Time
Server-Id
X-Edge
UCS
Debug
CDN
X-Proxied
X-Tt-Trace-Host
X-Zipkin-Id
X-Routing-Service
X-TH-Server
X-Ftr-Cache-Host
Powered-By
X-VC
X-Protected-By
X-SB
X-Gen-Id
X-Nananana
X-MID
X-MCACHE
X-Request-Time
RequestId
Media-Length
Product
X-Request-Url
V-Cache
NnCoection
SID
X-Dw-Trace-Id
X-LB-ID
Thinkindot-Cache-Type
X-Amzn-Remapped-Date
X-Amzn-Remapped-Connection
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-Li-Proto
X-LiteSpeed-Tag
X-Fastly-Cache-Hits
Correlation-Id
Proxy-Firewall
X-Mid
Warning
Xet-Cookie
Application