Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
CF-Cache-Status
Pragma
Link
CF-RAY
X-Powered-By
ETag
Expect-CT
Via
X-XSS-Protection
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Xss-Protection
Referrer-Policy
X-Served-By
X-Varnish
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
Alt-Svc
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Request-ID
X-Check
X-Generator
Content-Security-Policy-Report-Only
X-Cache-Status
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-Template
X-Language
X-AspNetMvc-Version
Status
X-Content-Security-Policy
X-Buckets
Content-Encoding
Access-Control-Expose-Headers
X-CDN
Upgrade
Xkey
Access-Control-Max-Age
Keep-Alive
X-Drupal-Dynamic-Cache
X-Kinja-Server-Push
CF-Ray
X-Turbo-Charged-By
X-AH-Environment
X-Via
X-Ua-Compatible
X-Age
X-Cache-Group
X-Pass-Why
X-Backend
X-Envoy-Upstream-Service-Time
EagleId
X-Server
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Page-Speed
X-Pingback
X-Server-Powered-By
X-UA-Device
X-Proxy-Cache
X-Swift-CacheTime
X-Swift-SaveTime
X-Hacker
X-Nginx-Cache-Status
Ali-Swift-Global-Savetime
Request-Context
X-Varnish-Cache
Grace
Server-Timing
Feature-Policy
Cf-Railgun
X-Amz-Version-Id
X-LiteSpeed-Cache
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-WebKit-CSP
X-Rq
X-Server-Id
Report-To
EagleEye-TraceId
X-Response-Time
X-Ac
X-Host
X-OneAgent-JS-Injection
Request-Id
X-Ws-Request-Id
X-Cnection
X-Backend-Server
X-Node
X-DataDome
Content-Location
X-Origin-Cache
X-Cache-Lookup
X-Dns-Prefetch-Control
NEL
X-Cloud-Trace-Context
X-Readtime
X-Vhost
P3p
X-Application-Context
X-HW
X-Dispatcher
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Cdn
Allow
X-Clacks-Overhead
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Rack-Cache
Surrogate-Control
X-Origin-Upstream-Status
X-DynaTrace
X-Country
Rating
Fusion-Content-Id
Fusion-Template-Id
Fusion-Component-Id
Fusion-Source
Fusion-Content-Source
X-Akam-SW-Version
X-FTR-Request-ID
X-Country-Code
X-Goog-Hash
X-Instart-Request-ID
Pinterest-Generated-By
X-Varnish-TTL
X-Ruxit-JS-Agent
Edge-Control
X-Vname
X-PC
X-TtlSet
X-Mod-Pagespeed
X-B3-TraceId
X-MS-InvokeApp
X-Url
Verso
SPRequestGuid
Accept-Ch
X-Powered-By-Plesk
X-D2id
X-ESI
X-Trace
X-VARITI-CCR
X-SharePointHealthScore
X-Server-Name
Service-Worker-Allowed
Pagespeed
X-GitHub-Request-Id
X-Middleton-Response
Response
X-Sol
Display
X-Middleton-Display
Content-MD5
X-GoogleNews-Bot
X-Exp-Id
X-Exp-Variant
X-Kinja
X-Use-Magma
X-Kinja-Revision
X-Kinja-Build
X-Cdn-Fetch
X-Kinja-Server
RTSS
X-TTL
X-Navigation-Version
SPRequestDuration
SPIisLatency
X-Powered-CMS
X-Abt-Application-Version
X-Debug
Accept-Ch-Lifetime
X-Vcache
X-Forwarded-Proto
X-Amz-Server-Side-Encryption
X-Upstream
Charset
Public-Key-Pins
MS-Author-Via
X-Vcap-Request-Id
X-Cached
X-NF-Request-ID
DynaTrace
X-CST
X-Amz-Rid
X-Version
Edge-Cache-Tag
Realpath
X-Px
MicrosoftSharePointTeamServices
Arr-Disable-Session-Affinity
X-Shard
X-DynaTrace-JS-Agent
TCN
X-Trafficlayer-App-Name
X-Trafficlayer-App-Scope
X-Ezoic-Cdn
Access-Control-Request-Method
X-Shield-Request-Id
X-Server-ID
Pinterest-Version
X-Pinterest-Rid
X-MSEdge-Ref
X-Ser
X-XRDS-Location
S
X-SRCache-Fetch-Status
X-Fastly-Request-ID
X-SRCache-Store-Status
Fastly-Restarts
X-Accel-Expires
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-DIS-Request-ID
X-Goog-Metageneration
Front-End-Https
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Client-IP
X-Recruiting
X-Amz-Meta-S3cmd-Attrs
X-Id
X-T
X-Goog-Storage-Class
X-Element-Page-Cache
X-Varnish-Age
X-Webapp-Samesite-None-Activated-N
Nginx-Cache
MRF-Tech
X-Mrf-Section-Lastmod
Mrf-Cache-Status
X-Mrf-Item-Lastmod
X-B3-TraceId-Primal
Cache-Tag
X-FTR-DC
X-FTR-Backend
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-Cache-Status
X-Country-Code-Real
X-FTR-Realm
X-Amzn-Trace-Id
X-FTR-Expires
X-Dw-Request-Base-Id
X-Fastcgi-Cache
Fastcgi-Cache
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Cache-Config
X-Frontend
X-Content-Digest
NR-ENABLED
Powered
X-Ttl
X-Hits
X-Kinsta-Cache
X-Hp-Webp
Alternate-Protocol
X-Correlation-Id
X-Aspnetmvc-Version
X-Webkit-Csp
X-FTR-Cache-Host
X-Request-Received
X-Request-Processing-Time
ServerID
X-N
Server-Name
X-HS-Combine-CSS
X-Microsite
X-Content-Type
X-Request-Handler-Origin-Region
X-RateLimit-Remaining
PB-RID
PB-PID
X-Cache-Hit
Arc-Version
X-Mobile-Rewrite
TP-L2-Cache
TP-Cache
X-User-Agent
X-Rid
Healthy
X-Node-Name
X-Akamai-Edgescape
X-Grace
X-Revision
X-Content-Security-Policy-Report-Only
Backend-Timing
X-Analytics
X-Forwarded-For
X-Zen-Fury
AMP-Access-Control-Allow-Source-Origin
X-Logged-In
Server-Node
X-Pad
X-LB-Cache
X-Amz-Apigw-Id
X-Mobile-URL
X-Amzn-RequestId
X-Activity-Id
X-Az
X-AppVersion
X-Oneagent-Js-Injection
X-NWS-LOG-UUID
Cache-Status
Accept-CH-Lifetime
Accept-CH
X-Varnish-Grace
X-Cached-By
X-B3-Sampled
X-IPLB-Instance
X-Content-Options
X-F-Cache
Refresh
X-Ruxit-Js-Agent
Upgrade-Insecure-Requests
X-Type
Retry-After
X-GUploader-UploadID
X-Geo-Country
X-FastCGI-Cache
FilterID
X-Varnish-Backend
X-Srv
Paypal-Debug-Id
X-Tumblr-Pixel-0
X-Tumblr-User
X-Instance
X-FB-Debug
X-Tumblr-Pixel
AR-ATIME
AR-CACHE
AR-PoweredBy
X-Framework
X-App-Environment
Source
Access-Control-Allow-Method
X-Debug-Info
DC
X-Jobs
X-WebKit-CSP-Report-Only
X-Cluster
Host
Accept-Charset
X-AOL-HN
X-PHP-Backend
Actual-Object-TTL
X-Cache-2
X-Request-Guid
X-Page-Id
X-B
X-ATG-Version
Cache
X-Cache-Age
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-TT
X-Seen-By
Fastcgi-Useragent
Ar-Sid
X-PressLabs-Stats
X-Via-JSL
MS-CV
X-Cache-Key
X-Git-Hash
VIX-Pulpo-Node
X-Content-Powered-By
VIX-Pulpo-Upstream-Status
X-Cache-TTL
X-Whom
X-B-Cache
X-Signature
X-TA-CDN-Provider
X-Amz-Replication-Status
X-UA
X-Daa-Tunnel
X-Wix-Request-Id
X-Cache-Control
Host-Header
NGB
Surrogate-Key
X-Response-Served-From
X-Mobile
X-Host-Name
X-Cache-Enabled
X-Origin-Server
X-RequestSource
Cache-Tv-Group
X-GeoIP
WPE-Backend
X-TX-ID
Frame-Options
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
X-FW-Server
X-Hyper-Cache
X-FW-Serve
X-Region
X-FW-Hash
Payment
Cleartype
X-FW-Type
X-FW-Static
AR-Request-ID
Filters
Eomportal-Instance
X-Drupal-Cache-Tags
Xserver
X-Litespeed-Cache
X-Handled-By
X-Cache-Action
X-Adobe-Loc
X-Cacheable-TTL
X-Cache-NE
X-EdgeConnect-Cache-Status
X-Adobe-Content
X-SERVER
Webserver
X-Cache-Operation
X-ATS-Timestamp
X-Kong-Proxy-Latency
X-Cache-Rule
X-Esi
X-Kong-Upstream-Latency
Datacenter
X-Hostname
From-Origin
X-NewRelic-App-Data
X-Akamai-Transformed
X-Load-Cache
X-RemovedCookies
X-UA-Device-Type
X-ProcessESI
X-Edge-Location
Ms-Operation-Id
X-Forwarded-Host
X-RTag
X-Cache-TTL-Remaining
Liferay-Portal
X-Cache-Server
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Varnish-Server
X-Varnish-Hostname
X-Status
X-Oss-Storage-Class
X-App-Server
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Contextid
X-ORACLE-APMCS-REQUEST-ID
X-VCache
X-ORACLE-APMCS-TAG
Country
X-Time
Odigeo-Trace-Id
X-Rule
X-Upgrade-Enabled
X-TT-TIMESTAMP
Meta-Geo
X-UUID
X-Path-Route
X-Cache-Var-Map
X-Cache-Var
X-BCube-Filmed-By
X-RN-RSRV
X-ES-SERVER
Load-Balancing
X-Xfnlog-Site
DSUID
TWC-Privacy
Webcakes-App-Name
Webcakes-App-Version
TWC-Locale-Group
TWC-Device-Class
TWC-Connection-Speed
TWC-GeoIP-Country
Release
TWC-GeoIP-LatLong
Webcakes-Region
Cache-Tags
X-Pubstack
X-R9-Blue-Green-Version
Mn-Server-Ip
X-Viewer-Country
X-Origin-Hint
X-VCT
X-CCM
X-From
X-Cache-Config
Property-Id
Selected-Fe
Tracecode
X-Akamai-Request-ID
X-Akamai-Request-ID2
X-Drupal-Cache-Contexts
X-Debug-Cache
NGX
L5d-Success-Class
Azure-SiteName
Azure-RegionName
Azure-SlotName
Azure-Version
Fastly-SSL
Cache-Name
X-FW-Dynamic
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Vgn-Hpd-Reason
X-TNCMS
X-Via-Fastly
DB-Nickname
X-EIG-Tracking-Id
X-Cache-Host
X-Soup
X-Rocket-Nginx-Bypass
X-OCL
X-Loop
X-Origin-Response-Time
X-PCL
X-Proxy-Build
X-Proto
Azure-InstanceId
X-Timing-Wait
X-NWS-UUID-VERIFY
X-Backend-Name
X-Access
X-Www-Served-By
X-Web-Node
X-Varnish-Cache-Hits
X-ServerID
S-Cnection
Viewport
X-Labrador-Cache-Channel
X-Origin
X-Cache-Time
S-Rt
X-XRDS-LOCATION
Ec-Rule-Version
X-Format
X-Proxy
X-Hosted-By
X-Human
X-Real-IP
X-FC-Vary-Parameters
X-Section
X-Redis-Cache
X-Content-Age
X-Locale
X-PERF
X-Generated
X-Cluster-Name
Version
X-ApacheServer
Origin-Cache-Control
X-Time-Microsecs
X-Site-Version
Origin-Edge-Control
X-FireWall-Port
Decoy-Debug-TTL
X-ProxyCache-Status
X-ProxyCache-Key
X-BYPASS-REASON
Decoy-Debug-Status
Decoy-Debug-Key
X-JoinUs
X-IP
Uber-Trace-Id
Server-Info
X-Cache-Backend
X-Storage
X-Varnish-Hits
X-Accel-Buffering
X-Is-Bot
X-Rendered-As
X-Generated-By
X-Guploader-Uploadid
X-PHP-Host
X-Amzn-Remapped-Content-Length
X-Info
X-App-Version
X-Origin-TTL
X-Origin-CC
X-URL
Akamai-GRN
Rt-Fastcgi-Cache
X-SaId
X-Nginx-Cache-Key
X-WA-Info
Time
X-CF-Powered-By
Cache-Key
X-Geo
Cteonnt-Length
X-No-Session
X-RateLimit-Limit
X-MServer
X-Tec-Api-Origin
X-Environment-Context
X-L-Path
Origin
X-Tec-Api-Version
X-Tec-Api-Root
X-Tb
GEO-INFO
X-GoCache-CacheStatus
X-FB-TRIP-ID
X-Cache-Remote
Cache-Hits
Vix-Hermes-Req-Id
Accept-Language
X-CACHE-KEY
X-Presslabs-Stats
Access-Control-Request-Headers
X-Hit
X-Trace-Id
Srv
X-Backend-TTL
X-B3-SpanId
X-NCache
X-Say-TTL
X-Say-Cacheable
X-SayCDN-TTL
X-Unique-Id
X-SS-Set-Cookie
X-B3-Traceid
X-Device-Type
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Shopify-Generated-Cart-Token
X-ShopId
X-CS
X-APP-VERSION
X-Tumblr-Pixel-3
X-EC-Lua
X-ShardId
X-Alternate-Cache-Key
X-CDN-Forward
X-RCS-CacheZone
X-CSRF-TOKEN
X-Parent-Response-Time
ServedBy
X-Cluster-Node
X-Dc
NtCoent-Length
X-Source
X-S
IsBot
X-A-Dgt
X-A-Wwc
X-Accel-Expires-Debug
X-Aed
User-Cache-Control
X-AIR-PT
Fastcgi-X-Cache-Version
X-CF-Lambda-Fn
X-CF-Lambda-Version
Cross-Origin-Window-Policy
Content-Script-Type
X-Transaction
X-B-Cookie
OT-Force-Account-Verify
Machine
X-Application
X-ARC
X-Svr
Meta-Geo-Continent
Apple-News-Services-Handled
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Request-EU
X-Connection-Hash
Viewtype
VivaBuild
Server-Host
Rt-Proxy-Cache
Arc-Country
AsisCache
X-A-Dam
Mobile-Detection-Method
T-Server
MD5-Digest
Node
X-A-Ccd
Request-Country
BehaviorPad-Version
Rendered-Blocks
X-A
X-A-Dcw
X-Service
X-Region-Sid
X-SRCache-Key
X-Vtex-Remote-Cache
X-Ah-Environment
X-Request-UUID
X-Rewrite-Enabled
X-G
X-Hl-Ver
X-Rojux
X-Vtex-Processado-Em
Content-Style-Type
X-OVcl-Cache
X-OVcl
X-Vdms-Version
X-Twitter-Response-Tags
X-VG-WebCache
X-Processor
X-Trv-Group
X-VG-WebServer
X-External-Request-Id
Xc-Version
X-Detected-As
X-ScT
X-Date
X-Server-Time
X-DPWN-IS-SECURE
X-Destination
X-S-Cookie
X-PAYTM-SRV-ID
Mime-Version
X-D
X-SIPLIST1
X-Session-Fingerprint
ServerName
X-Endurance-Cache-Level
X-Cache-Grace
X-Magnolia-Registration
X-Proxy-Cache-Status
X-Location
X-Via-NSCOPI
X-Level-Front-Cache
X-Cache-Bucket
X-Debug-Cookies
X-Ms-Version
X-Ms-Request-Id
X-Thinkindot-L3
X-CUA
X-NX-Host
X-Matched-Rule
X-Debug-Log
Wxu-Next-Hostname
Wxu-Next-Commit
X-Core-Value
Wxu-Next-Region
X-IN-APIGATEWAY
X-Generated-On
X-Hash
X-Dispatch
X-IN-APIGATEWAYSSL
X-Reboot
Thinkindot-CacheControl
X-Proxy-Upstream
Served-By
Thinkindot-CacheControl-Type
Thinkindot-Control
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Instart-Isnd
Server-Int
X-Upstream-Ct
CDCHOST
X-Upstream-Ht
X-Nc
Proxy-Connection
Now
X-SRV
X-Uri
X-Developers
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Distil-CS
X-Varnish-Beresp-Ttl
X-Gen-Mode
X-Generated-In
X-Generation-Time
X-Varnish-Beresp-Grace
X-FW-Version
X-Eu-Site
X-Varnish-Beresp-Status
X-Debug-Cache-Expiry
X-Core-Mission
X-B3-Parentspanid
X-Bip
X-Block-Status
X-Azure-Ref-OriginShield
X-Azure-Ref
X-Agile-Id
X-App-Name
X-Auto-Login
X-C
X-Cache-Debug
X-Cms-Context
X-Compress-Hint
Mail-Subject
X-Clientip
X-CGP
X-Cache-Info
We-Hiring
X-Geo-Header
X-Has-Esi
X-SVT-ORM-VERSION
X-Swa-Ws
X-Thanos
X-SVT-ORM-RULES
X-TIME
X-Sigma-Backend
X-Skip-Cache
X-Sucuri-Cache
X-Up
X-User
X-Dispatcher-Server
X-Request-URI
X-ND-Cache
X-Webstats-RespID
X-VServer
X-VC-Cache
X-VG-TLSProxy
X-Sigma
X-Server-IP
X-Method
X-Origin-Date
X-Origin-Expires
X-Logging-Id
X-JWT-State
X-Agile-Age
X-Hnp-Log
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Release
X-Rocket-Build-Number
X-Scheme
Countrycode
X-Qloud-Router
X-Planisys-CDN-TTL
X-Policy
X-GeoIP-City
X-Is-Gdpr
IBM-Web2-Location
Heartbleed
RNT-Machine
Gh-Request-Id
W
Fastly-Soc-X-Request-Id
X-Agile
Kp-EeAlive
Magicmarker
Ha-Gx-Prefs
PFcat
Cache-Host
AKAMAI
RNT-Time
Content-Disposition
Esi-Enabled
Pramga
HA-Ipaddr
Section-Io-Cache
Web-Mar-Node
L
X-GRACE
X-Via-CDN
X-Key
X-MSEdge-Features
X-Irp-Debug
X-Internal-Host
X-MSEdge-Flight
X-NodeID
X-ServiceProvider
Cdncip
Memcached
X-Reqid
X-TrackingId
X-LI-UUID
X-Old-Content-Length
X-Li-Pop
X-Li-Fabric
X-Epic-Correlation-Id
X-Owner
X-Platform-Server
X-WebServer
X-Variation
X-S-Maxage
X-Request-Start
X-Distributor
Cdnsip
X-Wikidot-Backend
X-We-Are-Hiring
X-WADP-Cache
X-Urbn-Site-Id
X-Wikidot-Static-Cache
Adler-Geo
X-Cache-Id
X-Cache-FS-Status
Platform
Is-Eu
X-Urbn-Context-Path
Locale
X-AK-Request-ID
X-Backend-State
X-Cache-URL
X-BBXSRF
X-Clara-WADP
X-Cdn-Srv
X-Fastly-Cache
True-Client-Country-4JS
X-Cdn-Forward
Cache-Provider
X-Amz-Meta-Cache-Control
X-LI-Proto
X-Trafficlayer-App-Version
X-SD-PageType
SD-X-WS
Server-ID
V-Age
X-NC
Hostname
X-Servername
Powered-By-ChinaCache
Environment
X-Sucuri-Id
X-UnsetCookies
Locid
X-7Graus-Varnish-XKeys
FNAC-ModuleRouting
X-Be
X-Served-From
X-7Graus-Varnish-Cache-Control
X-Req
X-Lb-Id
GEO-REGION-INFO
CF-IPCountry
X-Nginx-Cache
X-B3-Spanid
X-Gamma-Serve
X-Newrelic-Synthetics
Geo-Info
X-HTML-Minification-Powered-By
X-Refresh
A
X-Developer
X-Servedbyhost
X-VHOST
X-FPC
X-Edge-O15-RID
X-Zone
X-Microcachable
X-Sn-Servicetimems
X-Render-Time
X-Cdn-Origin
Tcn
ProcessTime
X-Device-Os
X-Webkit-CSP
X-IPS-LoggedIn
X-Tb-Optimization-Total-Bytes-Saved
X-Correlation-ID
X-Node-Id
X-Sucuri-ID
X-GeoIP-Country-Code
X-Pjax-Url
X-Mode
X-MP-GENERATED-AT
X-NU-AKA-ACS-Version
X-Ratelimit-Remaining
X-VWS-Id
X-LJ-Flow-ID
Request-Time
Memory
X-AWS-Id
X-FORWARDED-FOR
X-Pf-Uncompressing
X-COUNTRY
Gannett-Cam-Experience-Id
X-VCL-Version
X-Zipkin-Id
TTL
Amp-Access-Control-Allow-Source-Origin
Resin-Trace
X-DC
Cf-Ipcountry
X-Proxied
X-Routing-Service
Pics-Label
X-Unique-ID
XServer
CF-Cached-On
Group
X-Pod
GeoIP-Latitude
GeoIP-Country-Code
Geoip-Latitude
GeoIp-Country-Code
X-ECACHE
X-Instart-Info
PICS-Label
X-Bc
X-ElasticPress-Search
X-CSRF-Token
X-ZONE
Geoip-City
MIME-Version
M-TraceId
GeoIP-City
X-Via-Edge
X-Via-SSL
X-Backend-Host
Cdn
X-Backend-Url
Host-ID
Cache-Cookie-Set-Lfrom
X-Var-Ttl
Cache-Cookie-Set-Idcheck
HostName
Cache-Cookie-Set-From
X-CLOUD-TRACE-CONTEXT
X-Request-Time
Ttl
X-Vcl-Version
Backend-Name
X-Ratelimit-Limit
X-APP
X-PF-Uncompressing
X-Swift-Error
X-NGENIX-Cache
N-Cache
Pagetype
Lfy
HitType
X-Cdn-Request-ID
X-TH-Server
X-BC
REQUESTUUID
X-Check-Cacheable
Ohc-Cache-HIT
X-NGINX-Cache
Cache-Prefix
Fly-Request-Id
X-PJAX-URL
X-Fstrz
Ohc-File-Size
Fly-Cache
URI
X-UPSTREAM-Address
Powered-By
On-Server
X-Fastly-Country-Code
X-Via-Ucdn
User-Agent
X-Worker
X-HostName
X-Cache-Miss-From
CDN
X-Sedo-Request-Id
X-ServedByHost
X-Cache-Tag
X-WR-MODIFICATION
Pragrma
X-GEO
X-LiteSpeed-Cache-Control
SRV
X-Fetched-On
X-Server-W
X-Aicache-OS
X-HS-Status
Who
Media-Length
X-WA
X-Tt-Trace-Tag
AR-SID
X-Ftr-Cache-Host
X-Rebelmouse-Cache-Control
X-Wa
X-Rebelmouse-Surrogate-Control
X-Fpc
Fastly-SWR
X-BE
Fastly-SIE
X-Upstream-HT
X-Upstream-CT
X-Hp-Ccpa-Warning
FSS-Proxy
X-Tt-Trace-Host
UCS
FSS-Cache
X-LB-ID
X-Varnish-URL
X-Varnish-Cacheable
X-LAGOON
X-Dynatrace-Js-Agent
X-Cf-Powered-By
Debug
X-Store
X-Fastly-Backend-Reqs
X-Cache-Tags
X-TT-LOGID
X-ServerName
X-NYM-Debug-Backend
Processtime
X-Ua
X-Varnish-Beresp-TTL
X-GDPR
Server-Id
X-Protected-By
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-Contensis-Viewer-Groups
X-Varnish-Authentication
Server-Surrogate-Control
X-Cache-ASPX
Server-Cache-Control
Country-Code
X-BACKEND-TTL
DataCenter
Cdn-Host
Location
WP-Super-Cache
Cdn-Request-Time
X-SB
X-VC
Xet-Cookie
X-Nananana
X-Request-Url
X-Li-Proto
Thinkindot-Cache-Type
SID
X-Gen-Id
X-Fastly-Cache-Hits
Product
X-Dw-Trace-Id
X-Amzn-Remapped-Date
X-Edge-Server
XxX-Cache-Status
Application
NnCoection
X-Amzn-Remapped-Connection
X-SN
Cneonction