Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
CF-RAY
CF-Cache-Status
Pragma
Link
X-Powered-By
ETag
Expect-CT
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Xss-Protection
X-Varnish
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
Alt-Svc
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Request-ID
Content-Security-Policy-Report-Only
X-Generator
X-Cache-Status
X-Cacheable
X-Permitted-Cross-Domain-Policies
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Template
X-Iinfo
X-Language
X-AspNetMvc-Version
X-Content-Security-Policy
Status
X-Buckets
Content-Encoding
Access-Control-Expose-Headers
Upgrade
X-CDN
Xkey
X-Kinja-Server-Push
Access-Control-Max-Age
Keep-Alive
X-Drupal-Dynamic-Cache
X-Turbo-Charged-By
X-Via
X-Ua-Compatible
X-Cache-Group
X-Age
X-Pass-Why
X-Envoy-Upstream-Service-Time
X-Backend
EagleId
X-AH-Environment
X-Server
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Page-Speed
X-Pingback
X-Server-Powered-By
X-UA-Device
X-Swift-CacheTime
X-Swift-SaveTime
X-Proxy-Cache
X-Hacker
Ali-Swift-Global-Savetime
X-Nginx-Cache-Status
Request-Context
Grace
X-Varnish-Cache
Server-Timing
Feature-Policy
Cf-Railgun
X-Amz-Version-Id
X-Device
X-LiteSpeed-Cache
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Rq
X-WebKit-CSP
Report-To
X-Ac
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Response-Time
X-Server-Id
X-Host
Request-Id
X-Cnection
X-Backend-Server
X-DataDome
Content-Location
X-Node
X-Cloud-Trace-Context
X-Dns-Prefetch-Control
X-Origin-Cache
X-Readtime
X-Cache-Lookup
NEL
X-Vhost
P3p
X-Application-Context
X-Dispatcher
X-ORACLE-DMS-ECID
X-HW
X-Cdn
Allow
X-ORACLE-DMS-RID
X-Clacks-Overhead
X-Ws-Request-Id
X-Rack-Cache
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Origin-Upstream-Status
Surrogate-Control
X-Country
Rating
X-DynaTrace
X-FTR-Request-ID
X-Country-Code
X-Goog-Hash
Fusion-Content-Id
Fusion-Source
Fusion-Template-Id
Fusion-Component-Id
Fusion-Content-Source
X-Akam-SW-Version
Pinterest-Generated-By
X-PC
X-Vname
X-TtlSet
X-Ruxit-JS-Agent
X-MS-InvokeApp
X-Instart-Request-ID
X-Url
X-Varnish-TTL
Edge-Control
Verso
X-Mod-Pagespeed
X-Powered-By-Plesk
SPRequestGuid
Accept-Ch
X-B3-TraceId
X-D2id
X-Middleton-Response
X-Trace
X-Sol
Pagespeed
Response
X-Middleton-Display
Display
X-SharePointHealthScore
X-VARITI-CCR
RTSS
X-Kinja-Revision
X-Kinja-Server
X-Cdn-Fetch
X-Kinja-Build
X-Use-Magma
X-Exp-Variant
X-Kinja
X-GoogleNews-Bot
X-Exp-Id
Service-Worker-Allowed
X-Server-Name
X-Server-ID
X-GitHub-Request-Id
X-ESI
SPRequestDuration
SPIisLatency
X-Vcache
X-Navigation-Version
X-Powered-CMS
Content-MD5
X-Debug
X-Abt-Application-Version
X-Vcap-Request-Id
X-CST
Accept-Ch-Lifetime
X-Amz-Server-Side-Encryption
Public-Key-Pins
MS-Author-Via
Charset
X-Upstream
X-Forwarded-Proto
X-TTL
X-Version
X-Px
X-Amz-Rid
X-NF-Request-ID
X-Cached
DynaTrace
Realpath
X-Shard
TCN
Fastly-Restarts
Edge-Cache-Tag
MicrosoftSharePointTeamServices
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
Arr-Disable-Session-Affinity
X-Ezoic-Cdn
X-Recruiting
X-MSEdge-Ref
Access-Control-Request-Method
X-Shield-Request-Id
Pinterest-Version
X-Pinterest-Rid
X-DynaTrace-JS-Agent
X-Ser
X-SRCache-Fetch-Status
X-SRCache-Store-Status
S
X-Fastly-Request-ID
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Encoding
Nginx-Cache
X-XRDS-Location
Front-End-Https
X-Accel-Expires
X-DIS-Request-ID
X-Amz-Meta-S3cmd-Attrs
X-Client-IP
X-Goog-Storage-Class
X-Ttl
X-Id
X-Element-Page-Cache
X-Varnish-Age
X-Trafficlayer-App-Scope
X-Trafficlayer-App-Name
X-T
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Mrf-Item-Lastmod
MRF-Tech
X-Mrf-Section-Lastmod
X-FTR-Cache-Status
X-FTR-DC
X-FTR-Balancer
X-FTR-Backend
X-FTR-Realm
X-Country-Code-Real
X-FTR-Backend-Server
X-Webkit-Csp
X-FTR-Expires
X-Amzn-Trace-Id
X-Dw-Request-Base-Id
Fastcgi-Cache
X-Fastcgi-Cache
NR-ENABLED
X-HS-Content-Id
Cache-Tag
X-HS-Hub-Id
X-Content-Digest
X-Frontend
X-Hits
Powered
X-Correlation-Id
X-RateLimit-Remaining
X-Kinsta-Cache
X-HS-Cache-Config
X-Litespeed-Cache
X-Grace
X-FTR-Cache-Host
ServerID
X-Webapp-Samesite-None-Activated-N
X-Aspnetmvc-Version
Alternate-Protocol
TP-L2-Cache
TP-Cache
X-Hp-Webp
X-Cache-Hit
X-Node-Name
X-Request-Received
X-Request-Processing-Time
X-Forwarded-For
X-N
PB-PID
X-Ah-Environment
PB-RID
X-Microsite
X-Request-Handler-Origin-Region
Ar-Sid
X-Mobile-Rewrite
AR-PoweredBy
AR-CACHE
AR-ATIME
Arc-Version
AMP-Access-Control-Allow-Source-Origin
Server-Name
X-Zen-Fury
X-Content-Type
X-Rid
X-User-Agent
Healthy
X-Analytics
Backend-Timing
X-Revision
Server-Node
X-Content-Security-Policy-Report-Only
X-LB-Cache
X-Akamai-Edgescape
X-Logged-In
Cache-Status
X-Activity-Id
X-Az
X-AppVersion
X-HS-Combine-CSS
X-Srv
Retry-After
X-IPLB-Instance
X-FastCGI-Cache
X-Cached-By
X-Oneagent-Js-Injection
X-Amzn-RequestId
X-Amz-Apigw-Id
X-NWS-LOG-UUID
X-Pad
Accept-CH
X-Via-JSL
Accept-CH-Lifetime
X-Type
Paypal-Debug-Id
X-Varnish-Grace
X-GUploader-UploadID
X-Ruxit-Js-Agent
X-Mobile-URL
X-B3-Sampled
FilterID
Refresh
X-Content-Options
X-F-Cache
AR-Request-ID
X-Cache-Age
X-Geo-Country
X-Instance
X-Tumblr-User
X-Tumblr-Pixel-0
Accept-Charset
X-Tumblr-Pixel
X-Debug-Info
X-FB-Debug
Access-Control-Allow-Method
X-Jobs
X-Page-Id
X-Request-Guid
X-Cluster
X-App-Environment
Source
X-AOL-HN
Host
Upgrade-Insecure-Requests
Actual-Object-TTL
X-Framework
X-PHP-Backend
X-Varnish-Backend
X-B
X-Erf-Bev-Bev
X-Seen-By
DC
X-Erf-Bev-Bev-Is-Generated
X-WebKit-CSP-Report-Only
X-Cache-Key
X-ATG-Version
Fastcgi-Useragent
MS-CV
X-Content-Powered-By
X-Whom
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-PressLabs-Stats
X-TT
X-Git-Hash
X-Cache-2
X-Host-Name
X-Cache-Control
X-Esi
X-Amz-Replication-Status
Cache
X-Cache-TTL
Surrogate-Key
X-Wix-Request-Id
X-TA-CDN-Provider
X-Cache-Rule
X-Cache-Operation
Frame-Options
X-Signature
X-B-Cache
X-FW-Type
X-Kong-Upstream-Latency
NGB
X-Kong-Proxy-Latency
X-FW-Static
X-FW-Server
X-FW-Hash
X-FW-Serve
X-Response-Served-From
Host-Header
X-Daa-Tunnel
X-Forwarded-Host
X-UA
Xserver
X-Time
X-Origin-Server
X-Tumblr-Pixel-1
Cache-Tv-Group
X-Tumblr-Pixel-2
Eomportal-Instance
X-Region
X-Mobile
X-TX-ID
X-Cache-NE
X-Cache-Action
Payment
Webserver
WPE-Backend
X-Hyper-Cache
X-Drupal-Cache-Tags
X-RequestSource
Cleartype
Filters
X-GeoIP
X-Adobe-Loc
X-Cacheable-TTL
X-Handled-By
From-Origin
X-Adobe-Content
X-Cache-Enabled
X-UA-Device-Type
X-SERVER
X-ProcessESI
X-RemovedCookies
X-App-Server
X-EdgeConnect-Cache-Status
X-RTag
Datacenter
Ms-Operation-Id
Tracecode
X-Cache-TTL-Remaining
X-NewRelic-App-Data
X-Akamai-Transformed
X-Hostname
X-Load-Cache
X-Status
X-Cache-Server
X-Contextid
X-Edge-Location
Liferay-Portal
X-B3-Traceid
X-Yottaa-Metrics
X-XRDS-LOCATION
X-Yottaa-Optimizations
X-BCube-Filmed-By
X-TT-TIMESTAMP
X-Varnish-Hostname
Odigeo-Trace-Id
X-Varnish-Server
Server-Info
X-FW-Dynamic
X-Rule
X-RateLimit-Limit
X-Cache-Var
X-Cache-Var-Map
X-Path-Route
X-ES-SERVER
X-RN-RSRV
Load-Balancing
Meta-Geo
Country
X-Viewer-Country
X-Xfnlog-Site
X-CCM
X-IP
X-Rocket-Nginx-Bypass
X-Cache-Config
X-Debug-Cache
X-OCL
X-PCL
Version
X-Via-Fastly
DB-Nickname
X-UUID
Cache-Tags
Webcakes-App-Name
Webcakes-Region
X-Akamai-Request-ID
Webcakes-App-Version
X-Redis-Cache
X-EIG-Tracking-Id
X-Drupal-Cache-Contexts
X-Cache-Time
X-Cache-Host
TWC-GeoIP-Country
Azure-Version
Azure-SlotName
Azure-SiteName
Cache-Name
Property-Id
L5d-Success-Class
Mn-Server-Ip
Azure-RegionName
Azure-InstanceId
TWC-GeoIP-LatLong
TWC-Locale-Group
Fastly-SSL
TWC-Device-Class
S-Rt
TWC-Connection-Speed
TWC-Privacy
X-FC-Vary-Parameters
X-R9-Blue-Green-Version
X-Origin-CC
X-Pubstack
X-Proto
X-Origin-Hint
X-Origin-Response-Time
X-Origin-TTL
X-Real-IP
X-ATS-Timestamp
X-Web-Node
X-Varnish-Cache-Hits
X-Upgrade-Enabled
X-ServerID
X-TNCMS
X-Origin
X-Proxy
X-Loop
X-Info
X-Hosted-By
X-Labrador-Cache-Channel
X-From
X-Goog-Meta-Goog-Reserved-File-Mtime
Release
X-Timing-Wait
S-Cnection
X-VCT
X-Format
X-Www-Served-By
Origin-Cache-Control
Origin-Edge-Control
X-Human
X-Generated
X-Rendered-As
Viewport
X-FireWall-Port
X-PERF
X-Backend-Name
X-Akamai-Request-ID2
X-Proxy-Build
X-JoinUs
X-Access
X-Content-Age
X-Cluster-Name
Selected-Fe
X-Section
X-ApacheServer
Decoy-Debug-TTL
Decoy-Debug-Key
DSUID
Decoy-Debug-Status
Ec-Rule-Version
X-Vgn-Hpd-Reason
NGX
X-Soup
X-Varnish-Hits
X-VCache
X-Time-Microsecs
X-NWS-UUID-VERIFY
X-Locale
X-Site-Version
X-Storage
X-Is-Bot
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
X-Oss-Storage-Class
Rt-Fastcgi-Cache
X-Guploader-Uploadid
X-Oss-Object-Type
X-ProxyCache-Key
Uber-Trace-Id
X-ProxyCache-Status
X-BYPASS-REASON
Cache-Key
X-WA-Info
Cteonnt-Length
GEO-INFO
X-PHP-Host
Vix-Hermes-Req-Id
X-Cache-Backend
X-GoCache-CacheStatus
X-Generated-By
X-ORACLE-APMCS-REQUEST-ID
X-ORACLE-APMCS-TAG
X-SS-Set-Cookie
X-App-Version
X-Hit
Cache-Hits
X-Amzn-Remapped-Content-Length
X-NCache
X-Cache-Grace
Time
X-Backend-TTL
Akamai-GRN
X-Cache-Remote
X-Accel-Buffering
Origin
X-Device-Type
X-Trace-Id
X-Nginx-Cache-Key
X-CS
X-APP-VERSION
X-Presslabs-Stats
X-Tumblr-Pixel-3
X-FB-TRIP-ID
Accept-Language
X-Environment-Context
X-OVcl-Cache
X-No-Session
X-OVcl
X-L-Path
X-S
X-CF-Powered-By
X-SaId
Mime-Version
X-Tb
X-MServer
Hostname
Access-Control-Request-Headers
X-Uri
X-B3-SpanId
X-Cluster-Node
X-URL
X-Say-Cacheable
X-Say-TTL
X-Via-CDN
X-SayCDN-TTL
X-UnsetCookies
Fastcgi-X-Cache-Version
X-Tec-Api-Version
X-Tec-Api-Root
X-CACHE-KEY
X-Tec-Api-Origin
X-Geo
Now
ServerName
User-Cache-Control
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
X-VG-WebServer
Content-Script-Type
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Apple-News-Services-Host
Apple-News-Services-Handled
X-VG-WebCache
Arc-Country
AsisCache
IsBot
Machine
Cross-Origin-Window-Policy
Content-Style-Type
BehaviorPad-Version
Xc-Version
Request-Country
X-Connection-Hash
Viewtype
X-CF-Lambda-Version
VivaBuild
X-A
X-D
X-Date
X-DPWN-IS-SECURE
X-Detected-As
T-Server
X-Destination
X-CF-Lambda-Fn
X-B-Cookie
X-A-Dgt
X-A-Ccd
X-A-Dam
X-A-Dcw
X-A-Wwc
X-Accel-Expires-Debug
X-ARC
X-Application
X-AIR-PT
X-Aed
X-External-Request-Id
X-G
Node
X-SRCache-Key
X-SIPLIST1
X-Session-Fingerprint
X-Svr
X-Transaction
Meta-Geo-Continent
Mobile-Detection-Method
X-Twitter-Response-Tags
X-Trv-Group
X-Server-Time
X-ScT
X-Region-Sid
X-Processor
X-PAYTM-SRV-ID
X-Hl-Ver
X-Request-UUID
Request-EU
Rendered-Blocks
X-S-Cookie
X-Rojux
X-Rewrite-Enabled
MD5-Digest
Rt-Proxy-Cache
X-FW-Version
X-Endurance-Cache-Level
X-CSRF-TOKEN
X-Cache-Bucket
X-Block-Status
X-Cache-Debug
X-Clara-WADP
X-Cms-Context
Web-Mar-Node
X-Cache-Info
Thinkindot-CacheControl
RNT-Time
RNT-Machine
Server-Host
Server-Int
Thinkindot-CacheControl-Type
X-Cdn-Forward
Thinkindot-Control
X-Core-Value
X-S-Maxage
X-Request-URI
X-Reboot
X-NC
X-Service
X-WADP-Cache
X-Thinkindot-L3
X-Proxy-Upstream
X-Proxy-Cache-Status
X-Debug-Log
X-Debug-Cookies
X-Gen-Mode
X-Location
X-NX-Host
X-Matched-Rule
CDCHOST
X-Hnp-Log
We-Hiring
Mail-Subject
Proxy-Connection
OT-Force-Account-Verify
X-B3-Parentspanid
NtCoent-Length
X-BBXSRF
X-RateLimit-Limit-Second
X-C
X-RateLimit-Remaining-Second
X-Backend-State
X-Release
Wxu-Next-Commit
X-Cache-FS-Status
X-Cache-Id
X-Origin-Expires
X-Shopify-Stage
X-CGP
X-Cdn-Srv
X-Cache-URL
X-Policy
X-Platform-Server
X-Azure-Ref-OriginShield
X-Azure-Ref
X-Server-IP
X-Scheme
X-Unique-Id
Wxu-Next-Region
X-ShardId
X-7Graus-Varnish-Cache-Control
X-ShopId
X-Alternate-Cache-Key
X-Amz-Meta-Cache-Control
X-Auto-Login
X-Reqid
X-Origin-Date
X-Request-Start
Wxu-Next-Hostname
X-App-Name
X-7Graus-Varnish-XKeys
X-Clientip
X-JWT-State
X-Generated-In
X-Generated-On
X-Key
X-Level-Front-Cache
X-Eu-Site
X-Fastly-Cache
X-Li-Fabric
X-Generation-Time
X-Geo-Header
X-IN-APIGATEWAYSSL
X-Irp-Debug
X-Instart-Isnd
X-IN-APIGATEWAY
X-Is-Gdpr
X-GeoIP-City
X-Has-Esi
X-Hash
X-Epic-Correlation-Id
X-Li-Pop
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Ms-Version
X-Debug-Cache-Expiry
X-CUA
W
X-Compress-Hint
X-Core-Mission
X-Ms-Request-Id
X-Developers
X-Distributor
X-Magnolia-Registration
X-LI-UUID
X-Distil-CS
X-Dispatcher-Server
X-Method
X-Dispatch
X-Old-Content-Length
X-SD-PageType
Platform
X-Up
HA-Ipaddr
PFcat
IBM-Web2-Location
Ha-Gx-Prefs
X-TrackingId
X-Varnish-Beresp-Grace
X-We-Are-Hiring
Gh-Request-Id
X-Webstats-RespID
Is-Eu
X-User
Magicmarker
X-VServer
L
X-Skip-Cache
X-VG-TLSProxy
Kp-EeAlive
X-Variation
X-VC-Cache
X-WebServer
Memcached
X-Varnish-Beresp-Status
X-SVT-ORM-VERSION
Countrycode
X-SVT-ORM-RULES
Esi-Enabled
AKAMAI
Adler-Geo
Content-Disposition
Cache-Host
X-Sorting-Hat-PodId
True-Client-Country-4JS
X-Sorting-Hat-ShopId
SD-X-WS
Fastly-Soc-X-Request-Id
X-Wikidot-Backend
X-Wikidot-Static-Cache
ServedBy
X-Varnish-Beresp-Ttl
Served-By
Section-Io-Cache
X-Nc
Srv
Cache-Provider
X-Parent-Response-Time
X-MSEdge-Flight
X-LI-Proto
X-MSEdge-Features
X-Developer
X-Dc
X-CDN-Forward
X-Logging-Id
Heartbleed
Locale
Pramga
X-Urbn-Context-Path
X-Bip
X-ServiceProvider
X-Internal-Host
X-Thanos
X-Agile-Age
X-Agile-Id
X-Swa-Ws
X-Agile
X-Qloud-Router
V-Age
X-Owner
A
X-Urbn-Site-Id
X-Vdms-Version
X-Sucuri-Cache
Server-ID
X-Sn-Servicetimems
X-AK-Request-ID
X-Shopify-Generated-Cart-Token
X-Sigma
X-Sigma-Backend
X-Rocket-Build-Number
Cdnsip
X-B3-Spanid
X-Cdn-Origin
Cdncip
X-NodeID
X-Planisys-CDN-Rules
X-Node-Id
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
X-Sucuri-Id
X-Servername
X-Device-Os
X-GRACE
X-Upstream-Ht
X-Upstream-Ct
X-Via-NSCOPI
GEO-REGION-INFO
Powered-By-ChinaCache
X-Lb-Id
Environment
X-EC-Lua
X-RCS-CacheZone
CF-IPCountry
X-Source
X-Be
X-FPC
X-ND-Cache
X-Nginx-Cache
X-VHOST
X-Trafficlayer-App-Version
X-Zone
Tcn
X-Newrelic-Synthetics
X-Microcachable
Resin-Trace
Request-Time
X-Servedbyhost
X-Webkit-CSP
X-Pjax-Url
Locid
X-Tb-Optimization-Total-Bytes-Saved
X-Req
X-Ratelimit-Remaining
X-ElasticPress-Search
X-Served-From
X-Instart-Info
FNAC-ModuleRouting
X-NGENIX-Cache
Geo-Info
X-Gamma-Serve
X-ECACHE
X-Oracle-Dms-Rid
X-SRV
Group
X-Backend-Host
X-Sucuri-ID
X-Pf-Uncompressing
X-TIME
X-Refresh
X-Backend-Url
X-Dynatrace
X-VCL-Version
X-DC
Memory
X-Var-Ttl
X-COUNTRY
X-IPS-LoggedIn
CF-Cached-On
X-VWS-Id
X-GEO
X-AWS-Id
Gannett-Cam-Experience-Id
ProcessTime
Backend-Name
X-LJ-Flow-ID
X-Unique-ID
X-Correlation-ID
Cf-Ipcountry
TTL
Amp-Access-Control-Allow-Source-Origin
X-HTML-Minification-Powered-By
X-Render-Time
N-Cache
X-CSRF-Token
X-Pod
Fly-Request-Id
SRV
GeoIp-Country-Code
X-NU-AKA-ACS-Version
Fly-Cache
PICS-Label
Pagetype
Pics-Label
Geoip-Latitude
Geoip-City
X-FORWARDED-FOR
X-Check-Cacheable
Lfy
Cache-Prefix
GeoIP-Latitude
X-GeoIP-Country-Code
GeoIP-Country-Code
X-Bc
X-Worker
REQUESTUUID
X-Via-SSL
X-Via-Edge
GeoIP-City
XServer
Ohc-Cache-HIT
Ohc-File-Size
X-Upstream-CT
X-Via-Ucdn
Cdn
X-Upstream-HT
X-Vcl-Version
M-TraceId
X-APP
X-Sedo-Request-Id
X-Cache-Miss-From
Ttl
X-Mode
X-Ratelimit-Limit
X-CLOUD-TRACE-CONTEXT
X-Fetched-On
X-Server-W
X-Fstrz
X-ZONE
X-MP-GENERATED-AT
MIME-Version
X-PF-Uncompressing
Fastly-SIE
Fastly-SWR
HitType
X-LiteSpeed-Cache-Control
X-Rebelmouse-Cache-Control
X-Fastly-Country-Code
X-Wa
X-Rebelmouse-Surrogate-Control
HostName
X-HS-Status
Host-ID
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-From
X-Dynatrace-Js-Agent
On-Server
X-ServedByHost
User-Agent
Pragrma
X-Swift-Error
X-Zipkin-Id
X-HostName
X-BC
X-Proxied
X-Varnish-Ttl
X-Routing-Service
X-NGINX-Cache
X-Cache-Tag
X-PJAX-URL
X-GDPR
URI
X-Tt-Trace-Tag
X-Aicache-OS
X-Ua
X-WR-MODIFICATION
X-Cdn-Request-ID
Who
X-TT-LOGID
Cdn-Host
Cdn-Request-Time
X-TH-Server
X-Edge-Server
X-WA
CACHE
X-RateLimit-Reset
X-Flog
X-ABtesting
X-UPSTREAM-Address
X-Edge-O15-RID
X-SN
X-Cache-Ttl
Powered-By
X-BE
X-Cf-Powered-By
X-Hello
CDN
X-Fastly-Backend-Reqs
Dynatrace
X-DW
X-DB
X-DI
X-Varnish-URL
X-RSL
X-RPS
X-Action
SS
Media-Length
X-RPM
X-LAGOON
X-Org
X-Fpc
X-Varnish-Cacheable
X-DSS
X-Response-By
DataCenter
X-Request-Time
Debug
X-ServerName
Server-Id
Get-Access-Time
Is-Session-Tracking
SN
X-Ratelimit-Reset
X-Upstream-Proxy
LB
X-LB-ID
X-Ftr-Cache-Host
X-Gen-Id
X-Protected-By
Requestid
X-Varnish-Beresp-TTL
Cneonction
Lb
X-Amzn-Remapped-Date
NnCoection
X-Li-Proto
X-Dw-Trace-Id
X-Varnish-Info
XxX-Cache-Status
RequestUuid
X-Amzn-Remapped-Connection
X-Nananana
RequestId
X-Fastly-Cache-Hits
Correlation-Id
Warning
X-LiteSpeed-Tag
SID
Application
Product
X-Page-Type
X-Akamai-ERPolicy
X-Request-Url
Thinkindot-Cache-Type
Country-Code
X-Akamai-ERRuleID