Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
CF-RAY
CF-Cache-Status
Pragma
Link
X-Powered-By
ETag
Expect-CT
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Xss-Protection
X-Varnish
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
Alt-Svc
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-FRAME-OPTIONS
X-Drupal-Cache
X-Adblock-Key
X-Request-ID
X-Check
X-Generator
Content-Security-Policy-Report-Only
X-Cache-Status
X-Cacheable
X-Permitted-Cross-Domain-Policies
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Template
X-Iinfo
X-Language
X-AspNetMvc-Version
Status
X-Content-Security-Policy
X-Buckets
Content-Encoding
Access-Control-Expose-Headers
Upgrade
X-CDN
Xkey
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Drupal-Dynamic-Cache
X-Turbo-Charged-By
X-Via
X-AH-Environment
X-Cache-Group
X-Age
X-Ua-Compatible
X-Pass-Why
X-Backend
X-Envoy-Upstream-Service-Time
EagleId
X-Server
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Page-Speed
X-Pingback
X-Server-Powered-By
X-UA-Device
X-Swift-CacheTime
X-Swift-SaveTime
X-Proxy-Cache
X-Hacker
Ali-Swift-Global-Savetime
X-Nginx-Cache-Status
Request-Context
Grace
X-Varnish-Cache
Server-Timing
Feature-Policy
Cf-Railgun
X-Amz-Version-Id
X-Device
X-LiteSpeed-Cache
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Rq
X-WebKit-CSP
Report-To
EagleEye-TraceId
X-Ac
X-Server-Id
X-Response-Time
X-OneAgent-JS-Injection
Request-Id
X-Cnection
X-Host
X-Backend-Server
X-DataDome
X-Node
Content-Location
X-Origin-Cache
X-Cloud-Trace-Context
X-Readtime
X-Cache-Lookup
X-Cdn
NEL
X-Vhost
X-Ws-Request-Id
X-Application-Context
X-Dispatcher
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-HW
Allow
X-Dns-Prefetch-Control
X-Clacks-Overhead
X-Rack-Cache
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Origin-Upstream-Status
X-DynaTrace
Surrogate-Control
Rating
X-Country
X-FTR-Request-ID
X-Country-Code
Fusion-Template-Id
Fusion-Content-Source
Fusion-Source
Fusion-Component-Id
Fusion-Content-Id
X-Akam-SW-Version
X-Goog-Hash
Pinterest-Generated-By
X-TtlSet
X-Vname
X-Instart-Request-ID
X-PC
X-Ruxit-JS-Agent
X-MS-InvokeApp
X-Varnish-TTL
Edge-Control
X-Url
X-Mod-Pagespeed
Verso
X-B3-TraceId
SPRequestGuid
X-Powered-By-Plesk
X-D2id
X-Trace
X-SharePointHealthScore
Pagespeed
X-Sol
Response
X-Middleton-Response
X-VARITI-CCR
Display
X-Middleton-Display
RTSS
X-Kinja-Revision
X-Cdn-Fetch
X-Use-Magma
X-Kinja-Server
X-Server-Name
X-GoogleNews-Bot
X-Kinja
X-Kinja-Build
X-Exp-Variant
X-Exp-Id
X-GitHub-Request-Id
Service-Worker-Allowed
X-Server-ID
X-ESI
SPRequestDuration
SPIisLatency
Accept-Ch
X-TTL
Content-MD5
X-Navigation-Version
X-Vcache
X-Powered-CMS
X-Abt-Application-Version
X-Debug
X-Vcap-Request-Id
X-Amz-Server-Side-Encryption
Public-Key-Pins
X-CST
Charset
MS-Author-Via
X-Upstream
X-Forwarded-Proto
X-Cached
X-NF-Request-ID
X-Amz-Rid
X-Px
Realpath
X-Version
DynaTrace
Edge-Cache-Tag
MicrosoftSharePointTeamServices
X-Shard
Accept-Ch-Lifetime
TCN
Arr-Disable-Session-Affinity
X-TEC-API-VERSION
Fastly-Restarts
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Ezoic-Cdn
Pinterest-Version
X-Pinterest-Rid
X-Ser
X-Shield-Request-Id
X-MSEdge-Ref
Access-Control-Request-Method
X-DynaTrace-JS-Agent
X-SRCache-Store-Status
X-SRCache-Fetch-Status
S
X-Fastly-Request-ID
X-Recruiting
X-XRDS-Location
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-DIS-Request-ID
X-Trafficlayer-App-Scope
X-Trafficlayer-App-Name
X-Accel-Expires
Front-End-Https
Nginx-Cache
X-Amz-Meta-S3cmd-Attrs
X-Client-IP
X-Goog-Storage-Class
X-Id
X-T
X-Element-Page-Cache
X-Varnish-Age
MRF-Tech
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
Mrf-Cache-Status
X-B3-TraceId-Primal
X-FTR-Realm
X-FTR-DC
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Backend
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-Expires
X-Amzn-Trace-Id
X-Dw-Request-Base-Id
Cache-Tag
Fastcgi-Cache
X-Fastcgi-Cache
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
X-Webapp-Samesite-None-Activated-N
X-Frontend
X-Content-Digest
NR-ENABLED
Powered
X-Correlation-Id
X-Hits
X-Ttl
X-Kinsta-Cache
Accept-CH
X-Litespeed-Cache
X-RateLimit-Remaining
X-FTR-Cache-Host
Accept-CH-Lifetime
Alternate-Protocol
X-Grace
X-Aspnetmvc-Version
ServerID
X-Hp-Webp
X-Webkit-Csp
X-N
X-Request-Received
X-Cache-Hit
X-Request-Processing-Time
TP-Cache
X-Node-Name
TP-L2-Cache
PB-PID
PB-RID
X-Request-Handler-Origin-Region
X-Microsite
Arc-Version
Server-Name
X-HS-Combine-CSS
X-Mobile-Rewrite
X-Rid
AMP-Access-Control-Allow-Source-Origin
X-Zen-Fury
X-User-Agent
Healthy
X-Revision
X-Content-Type
Backend-Timing
X-Analytics
X-Akamai-Edgescape
X-Content-Security-Policy-Report-Only
Server-Node
X-Logged-In
X-LB-Cache
AR-CACHE
AR-ATIME
AR-PoweredBy
X-AppVersion
Cache-Status
X-Activity-Id
X-Az
X-Forwarded-For
X-Pad
X-Amzn-RequestId
Ar-Sid
X-Amz-Apigw-Id
X-NWS-LOG-UUID
X-Oneagent-Js-Injection
X-IPLB-Instance
X-Cached-By
X-Varnish-Grace
Retry-After
X-Mobile-URL
X-Type
X-FastCGI-Cache
X-Srv
X-B3-Sampled
X-Ruxit-Js-Agent
Paypal-Debug-Id
X-GUploader-UploadID
X-Content-Options
Refresh
X-F-Cache
X-Geo-Country
X-Via-JSL
Upgrade-Insecure-Requests
X-Varnish-Backend
X-Tumblr-Pixel
X-App-Environment
X-Tumblr-Pixel-0
X-Tumblr-User
Accept-Charset
X-FB-Debug
Host
X-Debug-Info
X-Instance
Source
X-B
X-Cluster
X-Jobs
X-AOL-HN
DC
Access-Control-Allow-Method
X-Page-Id
X-PHP-Backend
Actual-Object-TTL
X-Framework
X-Cache-Age
FilterID
X-Request-Guid
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-WebKit-CSP-Report-Only
X-Cache-Key
X-ATG-Version
X-Seen-By
AR-Request-ID
MS-CV
Fastcgi-Useragent
X-Content-Powered-By
X-TT
X-Cache-TTL
X-Git-Hash
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Whom
X-Cache-2
Cache
X-Esi
X-UA
X-PressLabs-Stats
X-Cache-Control
X-Amz-Replication-Status
X-TA-CDN-Provider
X-Host-Name
Surrogate-Key
X-Wix-Request-Id
X-Signature
X-B-Cache
Host-Header
Frame-Options
X-Response-Served-From
NGB
X-Mobile
X-Daa-Tunnel
X-Cache-Operation
X-GeoIP
X-Origin-Server
X-RequestSource
X-Cache-Rule
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-FW-Server
X-FW-Hash
X-FW-Static
X-Tumblr-Pixel-1
X-Tumblr-Pixel-2
WPE-Backend
X-Cache-Enabled
Cache-Tv-Group
X-FW-Type
X-FW-Serve
X-Drupal-Cache-Tags
Webserver
X-Cacheable-TTL
X-Cache-Action
X-Handled-By
Cleartype
X-TX-ID
Payment
Eomportal-Instance
X-Hyper-Cache
X-Region
Filters
X-Cache-NE
Xserver
X-Adobe-Loc
X-Adobe-Content
X-UA-Device-Type
X-SERVER
X-Forwarded-Host
From-Origin
X-EdgeConnect-Cache-Status
X-ProcessESI
X-RemovedCookies
X-Time
Datacenter
Ms-Operation-Id
X-RTag
X-Akamai-Transformed
X-Load-Cache
X-Hostname
X-Cache-TTL-Remaining
X-App-Server
X-NewRelic-App-Data
X-Cache-Server
X-Edge-Location
X-Status
Liferay-Portal
X-Contextid
Tracecode
X-XRDS-LOCATION
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-ATS-Timestamp
X-Varnish-Hostname
X-Varnish-Server
X-BCube-Filmed-By
X-Rule
X-TT-TIMESTAMP
Odigeo-Trace-Id
Country
Load-Balancing
X-Path-Route
Meta-Geo
X-ES-SERVER
X-Cache-Var
X-Cache-Var-Map
X-RN-RSRV
X-Debug-Cache
Server-Info
Release
X-Viewer-Country
X-Upgrade-Enabled
X-VCT
X-Xfnlog-Site
DSUID
Property-Id
X-Soup
X-OCL
X-Rocket-Nginx-Bypass
X-R9-Blue-Green-Version
TWC-Device-Class
X-Varnish-Cache-Hits
TWC-GeoIP-Country
TWC-GeoIP-LatLong
X-Origin-Hint
X-PCL
X-Via-Fastly
TWC-Connection-Speed
X-EIG-Tracking-Id
Webcakes-App-Version
Webcakes-Region
X-Pubstack
DB-Nickname
Cache-Tags
X-Cache-Config
X-Cache-Host
TWC-Locale-Group
TWC-Privacy
X-CCM
Webcakes-App-Name
Version
Mn-Server-Ip
X-FW-Dynamic
X-Hosted-By
X-NWS-UUID-VERIFY
X-From
X-Human
X-FC-Vary-Parameters
X-IP
X-Origin
X-Loop
L5d-Success-Class
X-Drupal-Cache-Contexts
X-Cache-Time
Origin-Edge-Control
Origin-Cache-Control
NGX
S-Rt
Selected-Fe
X-Akamai-Request-ID2
Cache-Name
X-Akamai-Request-ID
X-Origin-Response-Time
X-Labrador-Cache-Channel
X-TNCMS
X-Timing-Wait
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Storage-Class
X-Web-Node
X-UUID
X-Real-IP
X-ServerID
X-Proxy
X-Oss-Object-Type
X-Proxy-Build
X-Proto
X-Redis-Cache
X-Oss-Hash-Crc64ecma
X-Locale
X-Www-Served-By
X-Access
Viewport
X-JoinUs
X-Vgn-Hpd-Reason
S-Cnection
X-Backend-Name
X-Section
X-Generated
X-Rendered-As
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Format
X-PERF
X-Site-Version
X-Cluster-Name
X-RateLimit-Limit
X-ApacheServer
X-FireWall-Port
Decoy-Debug-Key
Decoy-Debug-Status
Decoy-Debug-TTL
Azure-Version
Azure-SlotName
Azure-InstanceId
Azure-SiteName
Ec-Rule-Version
Azure-RegionName
Fastly-SSL
X-VCache
X-Info
X-Content-Age
X-Varnish-Hits
X-Time-Microsecs
X-Is-Bot
X-ORACLE-APMCS-TAG
X-ORACLE-APMCS-REQUEST-ID
X-B3-Traceid
X-Storage
X-BYPASS-REASON
X-ProxyCache-Status
Uber-Trace-Id
X-ProxyCache-Key
X-Guploader-Uploadid
X-URL
Rt-Fastcgi-Cache
X-Origin-TTL
X-Origin-CC
X-Cache-Backend
X-Generated-By
X-PHP-Host
Cteonnt-Length
Cache-Key
X-Accel-Buffering
X-WA-Info
X-Webkit-CSP
X-Amzn-Remapped-Content-Length
X-Presslabs-Stats
Akamai-GRN
GEO-INFO
X-App-Version
X-SS-Set-Cookie
Time
Vix-Hermes-Req-Id
Cache-Hits
X-GoCache-CacheStatus
X-NCache
X-Nginx-Cache-Key
X-Hit
X-Backend-TTL
X-Trace-Id
X-CF-Powered-By
X-SaId
Origin
X-Cache-Remote
X-APP-VERSION
Accept-Language
X-FB-TRIP-ID
X-No-Session
X-Device-Type
X-MServer
X-Environment-Context
X-L-Path
X-Cache-Grace
X-CS
X-Tb
X-Tumblr-Pixel-3
X-Geo
Access-Control-Request-Headers
X-SayCDN-TTL
X-Say-TTL
X-OVcl
X-OVcl-Cache
X-Say-Cacheable
X-B3-SpanId
X-Unique-Id
X-S
X-Cluster-Node
X-CDN-Forward
X-Tec-Api-Version
User-Cache-Control
X-Tec-Api-Root
X-Tec-Api-Origin
X-CACHE-KEY
X-Uri
Srv
Fastcgi-X-Cache-Version
X-Via-CDN
X-Vtex-Remote-Cache
Xc-Version
Mobile-Detection-Method
MD5-Digest
Apple-News-Services-Handled
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-ShopId
X-ShardId
ServedBy
X-Alternate-Cache-Key
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Content-Script-Type
Content-Style-Type
Cross-Origin-Window-Policy
BehaviorPad-Version
AsisCache
Apple-News-Services-Request-Url
Arc-Country
Machine
X-Transaction
X-AIR-PT
X-Aed
X-Application
X-Region-Sid
X-Processor
X-Accel-Expires-Debug
X-A-Wwc
X-Rojux
X-Rewrite-Enabled
X-Request-UUID
X-A-Dgt
X-ARC
X-B-Cookie
X-Destination
X-Date
X-Detected-As
X-DPWN-IS-SECURE
X-External-Request-Id
X-D
X-Hl-Ver
X-PAYTM-SRV-ID
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Connection-Hash
X-A-Dcw
X-S-Cookie
Viewtype
T-Server
X-VG-WebServer
X-VG-WebCache
X-Twitter-Response-Tags
X-Vtex-Processado-Em
Server-Host
Rendered-Blocks
Request-Country
Request-EU
Rt-Proxy-Cache
VivaBuild
X-Trv-Group
X-Service
X-A-Dam
X-Server-Time
X-ScT
X-Session-Fingerprint
X-A-Ccd
X-G
X-Svr
X-SRCache-Key
X-A
Node
Meta-Geo-Continent
We-Hiring
X-EC-Lua
Mail-Subject
Mime-Version
X-CSRF-TOKEN
NtCoent-Length
X-Ah-Environment
ServerName
OT-Force-Account-Verify
X-Dc
Now
Hostname
RNT-Machine
X-Gen-Mode
X-Hnp-Log
X-Hash
X-Generated-On
X-IN-APIGATEWAYSSL
X-Ms-Request-Id
X-Ms-Version
X-NX-Host
X-Proxy-Cache-Status
X-Matched-Rule
X-Location
RNT-Time
X-Instart-Isnd
X-Level-Front-Cache
Kp-EeAlive
X-IN-APIGATEWAY
X-UnsetCookies
X-Cms-Context
Wxu-Next-Region
Wxu-Next-Hostname
Wxu-Next-Commit
X-Clara-WADP
X-FW-Version
X-Block-Status
X-Cache-Bucket
X-Cache-Debug
X-Cache-Info
Web-Mar-Node
X-Core-Value
X-Dispatch
X-Dispatcher-Server
X-Proxy-Upstream
Served-By
X-Debug-Log
X-Debug-Cookies
X-CUA
Thinkindot-Control
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-Endurance-Cache-Level
IsBot
Cache-Host
X-Varnish-Beresp-Grace
CDCHOST
X-S-Maxage
X-Request-URI
X-Varnish-Beresp-Status
X-Varnish-Beresp-Ttl
Proxy-Connection
X-Shopify-Generated-Cart-Token
X-SIPLIST1
X-Thinkindot-L3
X-User
X-Webstats-RespID
X-WADP-Cache
X-Reboot
X-Reqid
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-B3-Parentspanid
X-Debug-Cache-Expiry
X-Up
X-Compress-Hint
X-Debug-Cache-Fetch
X-BBXSRF
X-Backend-State
X-TrackingId
X-Swa-Ws
X-Auto-Login
X-SVT-ORM-VERSION
X-Azure-Ref
X-Thanos
X-Variation
X-Azure-Ref-OriginShield
X-Debug-Cache-Store
X-Bip
X-WebServer
X-Cdn-Srv
X-CGP
X-Cache-URL
X-Wikidot-Static-Cache
X-Cache-FS-Status
X-Cache-Id
X-We-Are-Hiring
X-Clientip
X-Wikidot-Backend
X-VG-TLSProxy
X-VServer
X-Vdms-Version
X-SVT-ORM-RULES
X-C
X-VC-Cache
X-Sigma
X-LI-UUID
X-Request-Start
X-Logging-Id
X-App-Name
X-Li-Pop
X-Key
X-Rocket-Build-Number
X-Li-Fabric
X-Magnolia-Registration
X-Method
X-Owner
X-Platform-Server
X-Policy
X-Origin-Expires
X-Origin-Date
X-Release
X-Old-Content-Length
X-JWT-State
X-Is-Gdpr
X-Epic-Correlation-Id
X-Eu-Site
X-Fastly-Cache
X-Qloud-Router
X-Sigma-Backend
X-Skip-Cache
X-Distil-CS
X-Distributor
X-Server-IP
X-SD-PageType
X-Has-Esi
X-Scheme
X-Irp-Debug
X-GeoIP-City
X-Geo-Header
X-Generated-In
X-Generation-Time
X-Sucuri-Cache
X-Developers
Pramga
Adler-Geo
Platform
PFcat
Memcached
Content-Disposition
SD-X-WS
True-Client-Country-4JS
X-NC
Server-Int
Section-Io-Cache
Magicmarker
X-Parent-Response-Time
Gh-Request-Id
Fastly-Soc-X-Request-Id
Esi-Enabled
Countrycode
Ha-Gx-Prefs
HA-Ipaddr
L
Is-Eu
IBM-Web2-Location
Heartbleed
W
AKAMAI
X-Agile-Age
X-Agile-Id
X-Amz-Meta-Cache-Control
X-Agile
X-Nc
Cache-Provider
Cdncip
X-NodeID
X-Urbn-Context-Path
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-7Graus-Varnish-XKeys
X-AK-Request-ID
Locale
X-Internal-Host
X-LI-Proto
X-7Graus-Varnish-Cache-Control
X-Planisys-CDN-TTL
X-Urbn-Site-Id
Cdnsip
X-ServiceProvider
V-Age
X-Core-Mission
X-Cdn-Forward
X-RCS-CacheZone
X-B3-Spanid
X-Via-NSCOPI
X-Upstream-Ht
X-MSEdge-Flight
X-Source
X-MSEdge-Features
Powered-By-ChinaCache
Server-ID
X-Upstream-Ct
X-COUNTRY
X-SRV
X-Developer
X-Servername
X-ND-Cache
A
X-GRACE
X-Be
X-Device-Os
X-Cdn-Origin
X-Sn-Servicetimems
GEO-REGION-INFO
X-Trafficlayer-App-Version
CF-IPCountry
Environment
X-Sucuri-Id
X-FPC
X-Lb-Id
X-Node-Id
X-TIME
X-Req
Locid
X-FORWARDED-FOR
X-VHOST
X-Nginx-Cache
X-Zone
Geo-Info
X-Sucuri-ID
X-Gamma-Serve
X-Servedbyhost
X-Served-From
X-Microcachable
Tcn
FNAC-ModuleRouting
X-Newrelic-Synthetics
ProcessTime
X-Refresh
Request-Time
X-HTML-Minification-Powered-By
Resin-Trace
X-Pjax-Url
X-Tb-Optimization-Total-Bytes-Saved
X-Ratelimit-Remaining
X-IPS-LoggedIn
X-VWS-Id
X-AWS-Id
Memory
X-Pf-Uncompressing
X-Render-Time
X-LJ-Flow-ID
X-ECACHE
X-ElasticPress-Search
X-VCL-Version
X-NU-AKA-ACS-Version
X-Edge-O15-RID
Group
Gannett-Cam-Experience-Id
X-Instart-Info
CF-Cached-On
X-Correlation-ID
Cf-Ipcountry
Amp-Access-Control-Allow-Source-Origin
TTL
XServer
X-GeoIP-Country-Code
X-NGENIX-Cache
X-Backend-Host
X-Backend-Url
X-Var-Ttl
X-DC
Geoip-Latitude
Geoip-City
GeoIp-Country-Code
X-CSRF-Token
Backend-Name
PICS-Label
X-Pod
Pics-Label
MIME-Version
X-MP-GENERATED-AT
X-Unique-ID
X-Bc
X-Mode
REQUESTUUID
X-Via-Edge
X-Via-SSL
Pagetype
Cdn
Lfy
N-Cache
GeoIP-Latitude
GeoIP-City
GeoIP-Country-Code
X-Vcl-Version
X-GEO
Fly-Request-Id
M-TraceId
Fly-Cache
X-ZONE
X-Check-Cacheable
X-APP
X-HOST
Ttl
Cache-Prefix
X-CLOUD-TRACE-CONTEXT
X-Worker
Ohc-File-Size
Ohc-Cache-HIT
X-Ratelimit-Limit
HostName
Host-ID
X-Via-Ucdn
X-Fstrz
X-Routing-Service
X-Proxied
X-Zipkin-Id
Cache-Cookie-Set-Lfrom
SRV
X-HS-Status
HitType
X-PF-Uncompressing
X-Cache-Miss-From
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-From
X-Sedo-Request-Id
X-Swift-Error
X-Upstream-HT
X-Fetched-On
X-Server-W
X-Upstream-CT
X-LiteSpeed-Cache-Control
X-Fastly-Country-Code
X-BC
X-PJAX-URL
X-Cdn-Request-ID
X-Dynatrace-Js-Agent
X-ServedByHost
X-NGINX-Cache
URI
Pragrma
On-Server
X-Cache-Tag
X-Wa
X-TH-Server
X-Rebelmouse-Surrogate-Control
Fastly-SWR
User-Agent
X-Rebelmouse-Cache-Control
Fastly-SIE
X-Varnish-Ttl
X-HostName
X-UPSTREAM-Address
X-Aicache-OS
Powered-By
X-WR-MODIFICATION
X-Tt-Trace-Tag
CDN
X-WA
X-Request-Time
X-TT-LOGID
Who
CACHE
X-RateLimit-Reset
X-LB-ID
X-GDPR
X-BE
Media-Length
Dynatrace
Cdn-Host
Cdn-Request-Time
X-Fastly-Backend-Reqs
X-Fpc
X-Varnish-URL
X-Edge-Server
X-LAGOON
X-Varnish-Cacheable
X-Cf-Powered-By
DataCenter
Debug
FSS-Cache
FSS-Proxy
X-ServerName
SS
X-Hello
X-SN
X-ABtesting
LB
Get-Access-Time
Is-Session-Tracking
Server-Id
X-Flog
X-Ua
X-Ftr-Cache-Host
Filterid
X-DI
X-DSS
X-DW
X-Org
X-Action
X-Protected-By
X-Tt-Trace-Host
AR-SID
X-Response-By
SN
X-DB
X-RPS
X-RSL
X-Varnish-Beresp-TTL
X-RPM
X-Gen-Id
Cneonction
X-Request-Url
XxX-Cache-Status
Requestid
X-Fastly-Cache-Hits
Warning
SID
Xet-Cookie
X-VC
X-SB
UCS
Thinkindot-Cache-Type
X-Amzn-Remapped-Date
X-Amzn-Remapped-Connection
Application
X-LiteSpeed-Tag
X-Akamai-ERRuleID
X-Akamai-ERPolicy
RequestId
X-Nananana
Product
X-Li-Proto
NnCoection
X-Dw-Trace-Id