Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
CF-RAY
CF-Cache-Status
Pragma
Link
X-Powered-By
ETag
Expect-CT
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Xss-Protection
X-Varnish
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
Alt-Svc
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Request-ID
X-Generator
Content-Security-Policy-Report-Only
X-Cache-Status
X-Cacheable
X-Permitted-Cross-Domain-Policies
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-Template
X-Language
X-AspNetMvc-Version
Status
X-Content-Security-Policy
X-Buckets
Content-Encoding
Access-Control-Expose-Headers
Upgrade
X-CDN
Xkey
Access-Control-Max-Age
Keep-Alive
X-Kinja-Server-Push
X-Drupal-Dynamic-Cache
X-Turbo-Charged-By
X-Via
X-AH-Environment
X-Ua-Compatible
X-Cache-Group
X-Age
X-Pass-Why
X-Backend
X-Envoy-Upstream-Service-Time
EagleId
X-Server
X-Amz-Id-2
X-Robots-Tag
X-Amz-Request-Id
X-Page-Speed
X-Pingback
X-Server-Powered-By
X-UA-Device
X-Proxy-Cache
X-Swift-CacheTime
X-Swift-SaveTime
X-Hacker
X-Nginx-Cache-Status
Ali-Swift-Global-Savetime
Request-Context
X-Varnish-Cache
Grace
Server-Timing
Feature-Policy
Cf-Railgun
X-Amz-Version-Id
X-LiteSpeed-Cache
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Rq
X-WebKit-CSP
Report-To
X-Server-Id
EagleEye-TraceId
X-Ac
X-Response-Time
X-Host
X-OneAgent-JS-Injection
Request-Id
X-Cnection
X-Backend-Server
X-DataDome
X-Node
Content-Location
X-Origin-Cache
X-Cloud-Trace-Context
X-Dns-Prefetch-Control
X-Readtime
X-Cache-Lookup
X-Cdn
NEL
X-Ws-Request-Id
X-Vhost
X-Application-Context
X-Dispatcher
X-ORACLE-DMS-ECID
X-HW
X-ORACLE-DMS-RID
P3p
Allow
X-Clacks-Overhead
X-Rack-Cache
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Origin-Upstream-Status
X-DynaTrace
Surrogate-Control
Rating
X-FTR-Request-ID
X-Country
Fusion-Component-Id
Fusion-Content-Id
Fusion-Source
Fusion-Content-Source
Fusion-Template-Id
X-Country-Code
X-Akam-SW-Version
X-Goog-Hash
Pinterest-Generated-By
X-Instart-Request-ID
X-TtlSet
X-Vname
X-PC
X-Ruxit-JS-Agent
X-Varnish-TTL
Edge-Control
X-MS-InvokeApp
X-B3-TraceId
X-Url
X-Mod-Pagespeed
SPRequestGuid
X-Powered-By-Plesk
Verso
X-D2id
X-Trace
X-SharePointHealthScore
Pagespeed
X-Sol
Response
X-Middleton-Response
X-VARITI-CCR
Display
X-Middleton-Display
X-Use-Magma
X-Cdn-Fetch
X-Server-Name
X-Exp-Variant
X-Kinja-Server
X-Kinja
X-Kinja-Build
X-GoogleNews-Bot
X-Kinja-Revision
X-Exp-Id
RTSS
X-GitHub-Request-Id
Service-Worker-Allowed
X-TTL
X-ESI
Content-MD5
Accept-Ch
SPIisLatency
SPRequestDuration
X-Navigation-Version
X-Powered-CMS
X-Vcache
X-Debug
X-Abt-Application-Version
X-Vcap-Request-Id
X-Amz-Server-Side-Encryption
Charset
X-CST
X-Server-ID
MS-Author-Via
Public-Key-Pins
X-Forwarded-Proto
DynaTrace
X-Upstream
X-Cached
X-NF-Request-ID
X-Amz-Rid
Realpath
X-Version
Edge-Cache-Tag
X-Px
Accept-Ch-Lifetime
MicrosoftSharePointTeamServices
X-Shard
Arr-Disable-Session-Affinity
TCN
X-Pinterest-Rid
X-Ezoic-Cdn
X-Shield-Request-Id
X-MSEdge-Ref
Pinterest-Version
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Ser
X-DynaTrace-JS-Agent
Access-Control-Request-Method
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Fastly-Restarts
X-Trafficlayer-App-Name
X-Trafficlayer-App-Scope
X-Fastly-Request-ID
S
X-Accel-Expires
X-XRDS-Location
X-Recruiting
X-DIS-Request-ID
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
Front-End-Https
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Amz-Meta-S3cmd-Attrs
Nginx-Cache
X-Client-IP
X-Goog-Storage-Class
X-T
X-Id
X-Varnish-Age
X-Element-Page-Cache
X-Mrf-Section-Lastmod
MRF-Tech
Mrf-Cache-Status
X-Mrf-Item-Lastmod
X-B3-TraceId-Primal
X-Country-Code-Real
X-FTR-Realm
X-FTR-DC
X-FTR-Cache-Status
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-Backend
X-Amzn-Trace-Id
X-FTR-Expires
X-Webkit-Csp
X-Dw-Request-Base-Id
Cache-Tag
X-Webapp-Samesite-None-Activated-N
Fastcgi-Cache
X-Fastcgi-Cache
X-Frontend
X-HS-Hub-Id
X-Content-Digest
X-HS-Content-Id
X-HS-Cache-Config
NR-ENABLED
Powered
X-Hits
X-Ttl
X-Kinsta-Cache
X-Correlation-Id
Accept-CH
X-FTR-Cache-Host
Alternate-Protocol
X-Hp-Webp
Accept-CH-Lifetime
X-RateLimit-Remaining
X-Aspnetmvc-Version
X-N
X-Request-Processing-Time
X-Request-Received
X-Grace
ServerID
X-Cache-Hit
TP-Cache
TP-L2-Cache
X-Node-Name
Server-Name
X-Microsite
X-Request-Handler-Origin-Region
PB-PID
PB-RID
X-HS-Combine-CSS
Arc-Version
X-Mobile-Rewrite
AMP-Access-Control-Allow-Source-Origin
X-Zen-Fury
X-Rid
X-Content-Type
Healthy
X-User-Agent
X-Akamai-Edgescape
X-Revision
X-Content-Security-Policy-Report-Only
X-Logged-In
Server-Node
X-LB-Cache
Backend-Timing
X-Analytics
X-Forwarded-For
X-Activity-Id
X-AppVersion
X-Amz-Apigw-Id
X-Az
X-Amzn-RequestId
Cache-Status
X-Pad
X-Oneagent-Js-Injection
X-Mobile-URL
AR-ATIME
AR-PoweredBy
AR-CACHE
X-IPLB-Instance
X-NWS-LOG-UUID
X-Varnish-Grace
X-Cached-By
Retry-After
X-Type
Refresh
X-Ruxit-Js-Agent
X-Content-Options
X-Litespeed-Cache
X-F-Cache
Ar-Sid
X-FastCGI-Cache
X-B3-Sampled
X-GUploader-UploadID
Paypal-Debug-Id
X-Geo-Country
FilterID
X-App-Environment
Upgrade-Insecure-Requests
X-Srv
X-FB-Debug
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel
X-Jobs
X-Debug-Info
X-Varnish-Backend
DC
X-Instance
X-PHP-Backend
X-Request-Guid
Accept-Charset
X-B
Source
X-AOL-HN
X-Framework
X-Cluster
Actual-Object-TTL
Host
Access-Control-Allow-Method
X-Cache-Age
X-Page-Id
X-Via-JSL
X-WebKit-CSP-Report-Only
X-ATG-Version
X-Seen-By
X-Cache-Key
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-TT
Fastcgi-Useragent
X-Cache-2
X-Git-Hash
MS-CV
X-Content-Powered-By
X-Cache-TTL
Cache
X-Whom
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
AR-Request-ID
X-PressLabs-Stats
X-Amz-Replication-Status
X-UA
X-Esi
X-Cache-Control
X-Signature
X-B-Cache
Host-Header
X-Wix-Request-Id
X-Host-Name
X-TA-CDN-Provider
NGB
X-Response-Served-From
Surrogate-Key
X-Daa-Tunnel
Frame-Options
X-Cache-Enabled
Cache-Tv-Group
X-Origin-Server
X-Mobile
X-GeoIP
X-Hyper-Cache
Eomportal-Instance
X-RequestSource
WPE-Backend
X-FW-Type
Filters
X-Drupal-Cache-Tags
X-FW-Static
X-Cache-Rule
X-Cache-Operation
X-Handled-By
X-Tumblr-Pixel-2
X-Cache-Action
X-FW-Hash
X-FW-Serve
X-Tumblr-Pixel-1
X-Cacheable-TTL
X-FW-Server
X-TX-ID
Cleartype
X-Region
X-Kong-Proxy-Latency
X-Adobe-Content
X-Adobe-Loc
X-Kong-Upstream-Latency
X-Cache-NE
X-EdgeConnect-Cache-Status
Xserver
Payment
X-SERVER
Webserver
From-Origin
X-ProcessESI
X-UA-Device-Type
X-RemovedCookies
X-Akamai-Transformed
Datacenter
X-Load-Cache
X-Hostname
X-Forwarded-Host
Ms-Operation-Id
X-NewRelic-App-Data
X-RTag
X-Cache-TTL-Remaining
X-App-Server
X-Cache-Server
X-Time
X-Edge-Location
X-Status
Liferay-Portal
X-Contextid
X-Yottaa-Optimizations
X-XRDS-LOCATION
X-Yottaa-Metrics
X-Varnish-Hostname
X-ATS-Timestamp
X-Varnish-Server
Tracecode
X-Rule
X-BCube-Filmed-By
Odigeo-Trace-Id
Country
X-TT-TIMESTAMP
Load-Balancing
X-Cache-Var-Map
X-Cache-Var
X-Upgrade-Enabled
Meta-Geo
X-ES-SERVER
X-RN-RSRV
X-Path-Route
X-Oss-Hash-Crc64ecma
DSUID
X-Debug-Cache
X-Oss-Storage-Class
X-Oss-Object-Type
X-Viewer-Country
X-Oss-Request-Id
X-Oss-Server-Time
X-Cache-Host
Version
X-Via-Fastly
X-UUID
X-Pubstack
DB-Nickname
X-Xfnlog-Site
Server-Info
X-ORACLE-APMCS-REQUEST-ID
Release
X-EIG-Tracking-Id
X-FW-Dynamic
X-CCM
X-ORACLE-APMCS-TAG
X-R9-Blue-Green-Version
Origin-Edge-Control
X-Soup
Webcakes-App-Version
Webcakes-Region
Property-Id
X-Redis-Cache
X-Cache-Config
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Device-Class
TWC-Connection-Speed
TWC-Locale-Group
X-Varnish-Cache-Hits
TWC-Privacy
S-Rt
X-VCT
Webcakes-App-Name
X-Akamai-Request-ID2
X-Origin-Hint
X-Cache-Time
Cache-Tags
Cache-Name
X-OCL
Fastly-SSL
X-From
X-Human
X-IP
X-Labrador-Cache-Channel
X-Hosted-By
X-Loop
Azure-SiteName
X-PCL
Azure-RegionName
X-TNCMS
Azure-InstanceId
X-Rocket-Nginx-Bypass
Azure-SlotName
NGX
Origin-Cache-Control
Azure-Version
X-Web-Node
X-Rendered-As
X-Www-Served-By
X-FireWall-Port
X-Generated
X-FC-Vary-Parameters
X-Content-Age
X-Locale
X-Origin
X-Proto
X-Origin-Response-Time
X-Drupal-Cache-Contexts
X-Akamai-Request-ID
X-ServerID
Ec-Rule-Version
X-Proxy
X-Real-IP
X-Site-Version
S-Cnection
Decoy-Debug-TTL
Decoy-Debug-Key
X-NWS-UUID-VERIFY
Decoy-Debug-Status
L5d-Success-Class
X-VCache
Viewport
X-PERF
X-ApacheServer
X-Is-Bot
X-Time-Microsecs
X-Varnish-Hits
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Vgn-Hpd-Reason
X-JoinUs
Mn-Server-Ip
X-Timing-Wait
Selected-Fe
X-Proxy-Build
X-Info
X-Section
X-Access
X-Storage
Uber-Trace-Id
X-Cluster-Name
X-Backend-Name
X-Format
X-ProxyCache-Status
X-ProxyCache-Key
X-BYPASS-REASON
X-Guploader-Uploadid
X-Origin-TTL
X-Origin-CC
X-Cache-Backend
X-Generated-By
Rt-Fastcgi-Cache
X-URL
X-RateLimit-Limit
X-PHP-Host
X-Accel-Buffering
X-Amzn-Remapped-Content-Length
Cteonnt-Length
Cache-Key
Akamai-GRN
Time
X-WA-Info
X-App-Version
X-Presslabs-Stats
X-SaId
GEO-INFO
X-Nginx-Cache-Key
Cache-Hits
X-GoCache-CacheStatus
X-CF-Powered-By
Origin
X-NCache
X-No-Session
Vix-Hermes-Req-Id
X-Geo
X-FB-TRIP-ID
X-Backend-TTL
X-Cache-Remote
X-Trace-Id
Accept-Language
X-Hit
X-L-Path
X-Environment-Context
X-SS-Set-Cookie
X-APP-VERSION
X-MServer
X-B3-Traceid
X-CS
X-Tb
Access-Control-Request-Headers
X-Say-TTL
X-Device-Type
X-SayCDN-TTL
X-Tumblr-Pixel-3
X-Say-Cacheable
X-Cache-Grace
X-OVcl-Cache
Srv
X-B3-SpanId
X-Unique-Id
X-OVcl
X-S
X-CDN-Forward
X-CACHE-KEY
User-Cache-Control
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
X-Cluster-Node
X-Uri
X-Shopify-Generated-Cart-Token
X-Shopify-Stage
X-ShopId
X-ShardId
ServedBy
X-Alternate-Cache-Key
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
OT-Force-Account-Verify
Meta-Geo-Continent
MD5-Digest
Mobile-Detection-Method
IsBot
Rendered-Blocks
Machine
Node
Arc-Country
AsisCache
X-ScT
X-Server-Time
X-Service
BehaviorPad-Version
Content-Script-Type
Xc-Version
Cross-Origin-Window-Policy
Content-Style-Type
Fastcgi-X-Cache-Version
VivaBuild
X-Svr
X-D
X-Date
X-SRCache-Key
X-Connection-Hash
X-CF-Lambda-Version
X-Application
X-B-Cookie
X-Transaction
X-CF-Lambda-Fn
X-Destination
X-Detected-As
X-Processor
X-Region-Sid
X-Request-UUID
X-Rewrite-Enabled
X-PAYTM-SRV-ID
X-Hl-Ver
X-DPWN-IS-SECURE
X-SIPLIST1
X-External-Request-Id
X-G
X-AIR-PT
X-Aed
Viewtype
X-S-Cookie
X-Rojux
X-Session-Fingerprint
T-Server
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Request-EU
Rt-Proxy-Cache
Server-Host
X-A
X-VG-WebServer
X-Trv-Group
X-A-Dgt
X-A-Wwc
X-Accel-Expires-Debug
X-A-Dcw
X-A-Dam
X-A-Ccd
X-VG-WebCache
X-Twitter-Response-Tags
Request-Country
X-ARC
X-EC-Lua
X-Dc
X-CSRF-TOKEN
X-Ah-Environment
ServerName
X-Via-CDN
Mime-Version
X-Level-Front-Cache
Server-Int
Thinkindot-CacheControl-Type
Web-Mar-Node
Thinkindot-Control
Thinkindot-CacheControl
X-Generated-On
X-Request-URI
X-Hash
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Status
X-Cache-Debug
X-Varnish-Beresp-Grace
X-Location
X-WADP-Cache
X-Dispatch
X-Hnp-Log
X-CUA
X-Dispatcher-Server
X-Endurance-Cache-Level
X-Gen-Mode
X-S-Maxage
X-Core-Value
X-Cms-Context
X-Block-Status
X-Instart-Isnd
X-Matched-Rule
X-Cache-Bucket
X-Cache-Info
X-Clara-WADP
X-Thinkindot-L3
X-Webstats-RespID
Served-By
X-Ms-Version
Apple-News-Services-Parsed-Url
X-Reboot
X-RateLimit-Remaining-Second
Mail-Subject
We-Hiring
Apple-News-Services-Request-Url
Apple-News-Services-Host
X-Vdms-Version
Cache-Host
Apple-News-Services-Handled
Proxy-Connection
X-Ms-Request-Id
X-RateLimit-Limit-Second
X-FW-Version
NtCoent-Length
X-SRV
X-B3-Parentspanid
X-VC-Cache
X-Amz-Meta-Cache-Control
Wxu-Next-Hostname
X-Variation
X-User
CDCHOST
X-Li-Fabric
X-VServer
X-We-Are-Hiring
Wxu-Next-Commit
X-Proxy-Upstream
Wxu-Next-Region
X-Proxy-Cache-Status
X-Is-Gdpr
True-Client-Country-4JS
X-Up
X-Platform-Server
X-Fastly-Cache
X-Skip-Cache
X-Epic-Correlation-Id
X-Server-IP
X-Has-Esi
X-Scheme
X-Generation-Time
X-Geo-Header
X-SD-PageType
X-Distributor
X-Owner
X-Cdn-Srv
X-Li-Pop
X-Cache-Id
X-Cache-FS-Status
X-Compress-Hint
X-Old-Content-Length
X-Release
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Swa-Ws
X-BBXSRF
X-JWT-State
IBM-Web2-Location
Pramga
Platform
Is-Eu
Esi-Enabled
Magicmarker
AKAMAI
X-NX-Host
X-Core-Mission
X-Debug-Cookies
X-IN-APIGATEWAY
X-GeoIP-City
X-Logging-Id
Heartbleed
Memcached
X-Origin-Date
Now
SD-X-WS
X-Origin-Expires
X-LI-UUID
Section-Io-Cache
Kp-EeAlive
Adler-Geo
X-Reqid
X-Debug-Log
RNT-Machine
X-Method
RNT-Time
PFcat
X-IN-APIGATEWAYSSL
Content-Disposition
X-UnsetCookies
Cache-Provider
Hostname
X-Nc
X-Parent-Response-Time
X-Magnolia-Registration
Cdnsip
X-Via-NSCOPI
X-Generated-In
X-WebServer
Cdncip
X-Planisys-CDN-Rules
X-TrackingId
X-Planisys-CDN-Cache
X-ServiceProvider
X-Key
X-Developers
X-Irp-Debug
X-Sucuri-Cache
X-Policy
X-Planisys-CDN-TTL
Fastly-Soc-X-Request-Id
L
X-NC
X-MSEdge-Features
X-Clientip
X-LI-Proto
X-Wikidot-Backend
X-Agile
X-Agile-Age
X-Debug-Cache-Expiry
X-Agile-Id
X-Wikidot-Static-Cache
X-Bip
V-Age
Gh-Request-Id
X-Request-Start
Countrycode
W
X-Qloud-Router
X-Auto-Login
X-NodeID
X-AK-Request-ID
X-MSEdge-Flight
X-Urbn-Context-Path
X-Backend-State
X-C
Locale
X-Cache-URL
X-Thanos
X-Urbn-Site-Id
X-Azure-Ref-OriginShield
X-Source
X-Debug-Cache-Fetch
X-VG-TLSProxy
X-App-Name
X-Azure-Ref
X-Debug-Cache-Store
X-Cdn-Forward
X-RCS-CacheZone
X-Internal-Host
X-7Graus-Varnish-Cache-Control
Powered-By-ChinaCache
X-7Graus-Varnish-XKeys
X-Rocket-Build-Number
Ha-Gx-Prefs
HA-Ipaddr
X-Distil-CS
X-CGP
X-Upstream-Ct
X-Sigma
X-ND-Cache
X-Eu-Site
Server-ID
X-Upstream-Ht
X-Sigma-Backend
X-TIME
X-B3-Spanid
X-Servername
Environment
X-GRACE
X-COUNTRY
X-Trafficlayer-App-Version
A
GEO-REGION-INFO
X-Be
X-Developer
CF-IPCountry
X-Nginx-Cache
X-FPC
X-Sn-Servicetimems
X-Device-Os
X-Sucuri-Id
X-Lb-Id
X-Cdn-Origin
X-Req
X-Gamma-Serve
Locid
X-Served-From
X-Node-Id
X-VHOST
X-Newrelic-Synthetics
X-Zone
ProcessTime
X-Microcachable
X-Refresh
Tcn
FNAC-ModuleRouting
X-FORWARDED-FOR
X-Servedbyhost
Geo-Info
X-HTML-Minification-Powered-By
X-Webkit-CSP
X-Edge-O15-RID
X-Sucuri-ID
Request-Time
Memory
X-Ratelimit-Remaining
X-Pjax-Url
X-Render-Time
X-IPS-LoggedIn
Resin-Trace
X-Tb-Optimization-Total-Bytes-Saved
X-Pf-Uncompressing
X-VWS-Id
X-LJ-Flow-ID
X-AWS-Id
X-NU-AKA-ACS-Version
X-VCL-Version
Gannett-Cam-Experience-Id
Cf-Ipcountry
X-Correlation-ID
CF-Cached-On
X-MP-GENERATED-AT
Amp-Access-Control-Allow-Source-Origin
X-GeoIP-Country-Code
X-DC
TTL
Geoip-Latitude
Group
GeoIp-Country-Code
Geoip-City
X-Instart-Info
XServer
X-ElasticPress-Search
X-ECACHE
X-CSRF-Token
X-Pod
Pics-Label
X-Backend-Host
X-Backend-Url
X-Var-Ttl
X-Mode
MIME-Version
X-NGENIX-Cache
GeoIP-City
Backend-Name
GeoIP-Country-Code
X-Via-SSL
PICS-Label
X-Via-Edge
M-TraceId
Cdn
GeoIP-Latitude
X-ZONE
X-Unique-ID
X-Vcl-Version
Pagetype
REQUESTUUID
N-Cache
Lfy
X-Bc
HostName
X-APP
X-Check-Cacheable
Ttl
X-CLOUD-TRACE-CONTEXT
Cache-Cookie-Set-From
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
X-Fstrz
Fly-Request-Id
X-Ratelimit-Limit
Host-ID
Fly-Cache
Cache-Prefix
X-Zipkin-Id
Ohc-File-Size
Ohc-Cache-HIT
X-Routing-Service
X-Proxied
X-BC
X-Cdn-Request-ID
HitType
X-GEO
X-Worker
X-Via-Ucdn
X-PF-Uncompressing
X-TH-Server
X-Sedo-Request-Id
X-Cache-Miss-From
X-Fastly-Country-Code
X-PJAX-URL
X-Swift-Error
X-Dynatrace-Js-Agent
X-LiteSpeed-Cache-Control
URI
On-Server
X-ServedByHost
User-Agent
X-HS-Status
X-Request-Time
Pragrma
X-Fetched-On
X-Server-W
X-HostName
X-Upstream-HT
X-Upstream-CT
SRV
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Tt-Trace-Tag
X-UPSTREAM-Address
Powered-By
X-Varnish-Ttl
Fastly-SIE
X-Cache-Tag
X-Wa
X-WR-MODIFICATION
Fastly-SWR
X-NGINX-Cache
X-WA
Media-Length
CDN
X-Aicache-OS
Who
X-BE
X-TT-LOGID
X-LAGOON
X-LB-ID
X-Fpc
X-Varnish-URL
X-Varnish-Cacheable
AR-SID
X-Fastly-Backend-Reqs
X-GDPR
DataCenter
X-Cf-Powered-By
Debug
Cdn-Host
Cdn-Request-Time
X-Edge-Server
Server-Id
X-Tt-Trace-Host
FSS-Proxy
FSS-Cache
X-Akamai-ERRuleID
CACHE
X-ServerName
X-Akamai-ERPolicy
X-RateLimit-Reset
X-Ftr-Cache-Host
X-Ua
X-SN
Get-Access-Time
X-ABtesting
LB
X-Hello
SS
UCS
X-Varnish-Beresp-TTL
X-Flog
X-Protected-By
X-Gen-Id
Is-Session-Tracking
X-Hp-Ccpa-Warning
WP-Super-Cache
X-Cache-Tags
X-SB
X-Nananana
XxX-Cache-Status
Cneonction
NnCoection
X-VC
Xet-Cookie
X-Org
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
X-DI
X-DB
X-DSS
X-DW
X-LiteSpeed-Tag
X-RPM
X-RPS
X-RSL
X-Action
X-Dw-Trace-Id
SID
X-Fastly-Cache-Hits
Application
Product
SN
X-Li-Proto
Warning
Requestid
X-Response-By
Thinkindot-Cache-Type
X-Request-Url