Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
CF-RAY
CF-Cache-Status
Pragma
Link
X-Powered-By
ETag
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Xss-Protection
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Download-Options
Alt-Svc
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-FRAME-OPTIONS
X-Drupal-Cache
X-Adblock-Key
X-Check
Content-Security-Policy-Report-Only
X-Generator
X-Cache-Status
X-Cacheable
X-Permitted-Cross-Domain-Policies
X-Request-ID
Timing-Allow-Origin
X-Template
X-Language
X-Iinfo
X-DNS-Prefetch-Control
X-Content-Security-Policy
Status
Content-Encoding
X-Buckets
X-AspNetMvc-Version
X-Ua-Compatible
Upgrade
Access-Control-Expose-Headers
X-Kinja-Server-Push
Xkey
Access-Control-Max-Age
X-CDN
Keep-Alive
X-Turbo-Charged-By
X-Via
X-Drupal-Dynamic-Cache
X-Cache-Group
X-Age
X-Pass-Why
X-Envoy-Upstream-Service-Time
X-Backend
EagleId
X-Robots-Tag
X-Amz-Id-2
X-Amz-Request-Id
X-Page-Speed
X-Pingback
X-Server-Powered-By
X-UA-Device
X-AH-Environment
X-Swift-SaveTime
X-Swift-CacheTime
X-Proxy-Cache
X-Hacker
X-Server
Ali-Swift-Global-Savetime
X-Nginx-Cache-Status
Request-Context
Grace
X-Varnish-Cache
Server-Timing
Feature-Policy
Cf-Railgun
X-Amz-Version-Id
X-Dns-Prefetch-Control
X-LiteSpeed-Cache
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Rq
X-Ac
EagleEye-TraceId
Report-To
X-Server-Id
X-Response-Time
X-WebKit-CSP
X-OneAgent-JS-Injection
X-Cdn
Request-Id
X-Cnection
X-Host
X-Backend-Server
Content-Location
X-Cloud-Trace-Context
X-DataDome
X-Node
X-Readtime
X-Origin-Cache
X-Cache-Lookup
X-Vhost
NEL
X-Application-Context
X-Dispatcher
X-ORACLE-DMS-ECID
X-HW
Allow
X-ORACLE-DMS-RID
X-Clacks-Overhead
X-Rack-Cache
X-Origin-Upstream-Status
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Country
Surrogate-Control
Rating
X-DynaTrace
Pinterest-Generated-By
X-FTR-Request-ID
X-Country-Code
X-Goog-Hash
Fusion-Component-Id
Fusion-Template-Id
Fusion-Content-Source
Fusion-Content-Id
Fusion-Source
X-MS-InvokeApp
X-Akam-SW-Version
X-Varnish-TTL
X-TtlSet
X-Vname
X-PC
Accept-Ch
X-Instart-Request-ID
X-Url
X-B3-TraceId
X-Ruxit-JS-Agent
X-Aspnetmvc-Version
X-Powered-By-Plesk
Verso
Edge-Control
SPRequestGuid
X-Ws-Request-Id
X-Mod-Pagespeed
X-Sol
X-Middleton-Response
Response
X-Middleton-Display
Display
X-SharePointHealthScore
X-Ah-Environment
X-D2id
X-VARITI-CCR
X-Kinja-Revision
X-Use-Magma
X-Kinja-Build
X-GoogleNews-Bot
X-Cdn-Fetch
X-Exp-Id
X-Exp-Variant
X-Kinja
X-Kinja-Server
X-Trace
Accept-Ch-Lifetime
RTSS
X-ESI
SPIisLatency
SPRequestDuration
X-GitHub-Request-Id
X-Server-Name
Service-Worker-Allowed
X-Server-ID
X-CST
X-Vcap-Request-Id
X-Powered-CMS
X-Debug
X-Navigation-Version
Public-Key-Pins
X-Abt-Application-Version
X-Px
Pagespeed
Content-MD5
X-Amz-Server-Side-Encryption
MS-Author-Via
X-Version
Charset
X-Upstream
X-TTL
X-Amz-Rid
Realpath
X-NF-Request-ID
X-Forwarded-Proto
DynaTrace
X-Recruiting
X-Shard
X-Cached
Fastly-Restarts
X-Vcache
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
Pinterest-Version
X-Pinterest-Rid
MicrosoftSharePointTeamServices
TCN
X-Ezoic-Cdn
X-SERVER
Nginx-Cache
Access-Control-Request-Method
Arr-Disable-Session-Affinity
X-Shield-Request-Id
X-MSEdge-Ref
X-DynaTrace-JS-Agent
Edge-Cache-Tag
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-XRDS-Location
X-SRCache-Store-Status
X-SRCache-Fetch-Status
S
X-Fastly-Request-ID
Front-End-Https
X-Ser
X-Amz-Meta-S3cmd-Attrs
X-Accel-Expires
X-Goog-Storage-Class
X-DIS-Request-ID
X-Id
X-Element-Page-Cache
X-T
X-Varnish-Age
X-Client-IP
X-RateLimit-Remaining
X-Ttl
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
MRF-Tech
X-B3-TraceId-Primal
X-Country-Code-Real
X-FTR-Backend
X-FTR-DC
X-FTR-Realm
Mrf-Cache-Status
X-FTR-Cache-Status
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-Expires
X-Amzn-Trace-Id
X-Webkit-Csp
X-Dw-Request-Base-Id
NR-ENABLED
X-Fastcgi-Cache
Fastcgi-Cache
X-HS-Hub-Id
X-HS-Content-Id
Ar-Sid
AR-PoweredBy
X-Frontend
AR-ATIME
AR-CACHE
Powered
X-Content-Digest
X-Hits
X-Forwarded-For
X-Grace
X-Correlation-Id
ServerID
X-Trafficlayer-App-Scope
X-Trafficlayer-App-Name
X-Kinsta-Cache
X-FTR-Cache-Host
Cache-Tag
X-Litespeed-Cache
X-Cache-Hit
X-Oneagent-Js-Injection
AMP-Access-Control-Allow-Source-Origin
TP-Cache
X-Node-Name
TP-L2-Cache
X-Content-Type
X-HS-Cache-Config
PB-RID
X-Srv
PB-PID
X-Request-Received
X-Request-Processing-Time
X-Mobile-Rewrite
Arc-Version
X-Zen-Fury
X-Request-Handler-Origin-Region
X-N
X-Microsite
Alternate-Protocol
X-Via-JSL
Server-Name
X-Hp-Webp
Paypal-Debug-Id
AR-Request-ID
Server-Node
X-Revision
X-Rid
X-User-Agent
Backend-Timing
Healthy
X-LB-Cache
X-Analytics
X-Logged-In
Cache-Status
Retry-After
X-Az
X-Activity-Id
X-AppVersion
X-Ruxit-Js-Agent
X-Content-Security-Policy-Report-Only
X-Akamai-Edgescape
X-FastCGI-Cache
X-Webapp-Samesite-None-Activated-N
X-IPLB-Instance
X-Type
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Cached-By
X-NWS-LOG-UUID
X-GUploader-UploadID
X-Cache-Age
FilterID
X-Pad
X-Varnish-Grace
X-HS-Combine-CSS
X-B3-Sampled
X-Webkit-CSP
Refresh
X-Tumblr-Pixel
Accept-Charset
X-Mobile-URL
X-F-Cache
X-Tumblr-User
X-Content-Options
X-Tumblr-Pixel-0
X-Framework
X-Instance
X-Debug-Info
X-Whom
X-B
X-Jobs
X-Page-Id
Actual-Object-TTL
X-App-Environment
Source
X-Seen-By
DC
X-Cluster
X-AOL-HN
X-PHP-Backend
X-FB-Debug
X-Request-Guid
Host
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
Access-Control-Allow-Method
X-VCache
X-PressLabs-Stats
X-Geo-Country
X-Cache-Key
MS-CV
X-Content-Powered-By
Upgrade-Insecure-Requests
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-WebKit-CSP-Report-Only
X-Cache-2
X-TA-CDN-Provider
X-Time
X-ATG-Version
X-Varnish-Backend
X-Host-Name
Fastcgi-Useragent
X-Git-Hash
X-Cache-Control
X-Forwarded-Host
X-TT
X-Cache-TTL
X-Cache-Rule
Surrogate-Key
X-Cache-Operation
X-Amz-Replication-Status
Frame-Options
X-Daa-Tunnel
X-Esi
Cache
X-FW-Hash
X-FW-Type
X-FW-Static
X-FW-Serve
X-FW-Server
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Tracecode
X-Mobile
X-Wix-Request-Id
X-Response-Served-From
Xserver
NGB
X-Origin-Server
X-UA-Device-Type
WPE-Backend
X-Tumblr-Pixel-2
X-RemovedCookies
X-ProcessESI
X-Signature
X-Tumblr-Pixel-1
X-App-Server
X-B-Cache
Cleartype
Host-Header
X-Region
X-RequestSource
X-Hyper-Cache
X-Cache-NE
X-GeoIP
X-RateLimit-Limit
Eomportal-Instance
Webserver
X-Cache-Action
X-TX-ID
From-Origin
X-Cacheable-TTL
X-Drupal-Cache-Tags
X-Adobe-Content
Payment
X-Adobe-Loc
X-Handled-By
Filters
Cache-Tv-Group
Ms-Operation-Id
X-RTag
X-EdgeConnect-Cache-Status
Accept-CH-Lifetime
X-Cache-Enabled
Datacenter
Accept-CH
X-Cache-TTL-Remaining
X-Akamai-Transformed
X-Status
X-Contextid
X-NewRelic-App-Data
X-UA
X-Cache-Server
Liferay-Portal
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-TT-TIMESTAMP
X-Hostname
X-Edge-Location
X-BCube-Filmed-By
Odigeo-Trace-Id
X-Load-Cache
X-FW-Dynamic
X-XRDS-LOCATION
X-IP
Version
X-App-Version
X-Varnish-Hostname
Server-Info
X-Path-Route
Meta-Geo
Load-Balancing
X-ES-SERVER
X-RN-RSRV
X-Cache-Var
X-Cache-Var-Map
X-Xfnlog-Site
X-Viewer-Country
X-Varnish-Server
X-Content-Age
X-Info
X-Rule
X-OCL
Cache-Tags
X-Via-Fastly
X-PCL
X-Pubstack
X-Debug-Cache
Country
X-CCM
DB-Nickname
Azure-SiteName
Origin-Edge-Control
X-Origin-Hint
Azure-RegionName
Azure-InstanceId
Release
Property-Id
Origin-Cache-Control
Azure-SlotName
X-UUID
X-Proxy
Cache-Name
L5d-Success-Class
Mn-Server-Ip
Azure-Version
X-Real-IP
TWC-GeoIP-Country
Webcakes-Region
Webcakes-App-Version
Webcakes-App-Name
TWC-Privacy
X-R9-Blue-Green-Version
X-Varnish-Cache-Hits
X-Cache-Host
X-Human
X-Cache-Time
GEO-INFO
X-Cache-Config
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-Device-Class
TWC-Connection-Speed
X-Origin
X-ServerID
X-EIG-Tracking-Id
X-From
X-Format
X-Generated
X-Cluster-Name
X-Drupal-Cache-Contexts
X-FC-Vary-Parameters
X-FireWall-Port
X-Hosted-By
X-Akamai-Request-ID
X-Goog-Meta-Goog-Reserved-File-Mtime
X-JoinUs
Selected-Fe
S-Rt
S-Cnection
X-Labrador-Cache-Channel
Viewport
DSUID
X-ApacheServer
X-Akamai-Request-ID2
X-Origin-Response-Time
X-Access
X-Backend-Name
X-Proto
X-WA-Info
X-Redis-Cache
X-VCT
X-Timing-Wait
X-Proxy-Build
X-Rendered-As
X-Web-Node
X-PERF
X-Locale
X-Www-Served-By
X-Site-Version
X-Vgn-Hpd-Reason
X-Section
X-Upgrade-Enabled
Decoy-Debug-Status
Fastly-SSL
X-Cache-Grace
Decoy-Debug-TTL
X-Time-Microsecs
X-Soup
Decoy-Debug-Key
X-Varnish-Hits
X-Loop
X-Rocket-Nginx-Bypass
X-TNCMS
Cache-Key
Ec-Rule-Version
X-NWS-UUID-VERIFY
Rt-Fastcgi-Cache
X-Origin-TTL
X-Origin-CC
X-Storage
NGX
X-Cache-Remote
Vix-Hermes-Req-Id
Cache-Hits
Cteonnt-Length
X-Guploader-Uploadid
X-Is-Bot
X-Hit
X-B3-SpanId
X-NCache
X-Backend-TTL
X-BYPASS-REASON
X-ProxyCache-Key
X-ProxyCache-Status
X-Trace-Id
X-CF-Powered-By
X-GoCache-CacheStatus
Uber-Trace-Id
Origin
Hostname
X-Device-Type
X-CS
X-Tumblr-Pixel-3
X-Cache-Backend
Mime-Version
X-UnsetCookies
Time
X-SS-Set-Cookie
X-PHP-Host
X-Generated-By
X-OVcl-Cache
X-OVcl
X-Amzn-Remapped-Content-Length
X-S
Akamai-GRN
X-Cluster-Node
Accept-Language
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
X-Oss-Storage-Class
X-Via-CDN
X-ATS-Timestamp
X-Oss-Object-Type
X-Cdn-Forward
Fastcgi-X-Cache-Version
X-Nginx-Cache-Key
X-FB-TRIP-ID
X-Accel-Buffering
X-Uri
Now
X-L-Path
X-Environment-Context
X-URL
X-FW-Version
X-Tb
X-No-Session
X-B3-Traceid
X-ORACLE-APMCS-TAG
ServerName
User-Cache-Control
X-ORACLE-APMCS-REQUEST-ID
X-MServer
ServedBy
X-Tec-Api-Version
X-Aed
X-AIR-PT
X-Accel-Expires-Debug
X-A-Wwc
X-A-Dam
X-A-Dcw
X-A-Dgt
X-Application
X-B-Cookie
BehaviorPad-Version
OT-Force-Account-Verify
X-Svr
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-Tec-Api-Root
Content-Script-Type
A
X-ARC
X-A-Ccd
Request-Country
Request-EU
Machine
IsBot
Rendered-Blocks
Node
Xc-Version
Meta-Geo-Continent
Mobile-Detection-Method
Rt-Proxy-Cache
Cross-Origin-Window-Policy
VivaBuild
Content-Style-Type
X-A
Viewtype
X-Tec-Api-Origin
Access-Control-Request-Headers
X-Vtex-Remote-Cache
T-Server
X-D
X-Connection-Hash
X-CSRF-TOKEN
Apple-News-Services-Host
Apple-News-Services-Handled
X-Region-Sid
X-Processor
X-PAYTM-SRV-ID
X-Date
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
X-Request-UUID
X-Rewrite-Enabled
X-Session-Fingerprint
X-SIPLIST1
X-SRCache-Key
X-Server-Time
X-ScT
X-Rojux
X-S-Cookie
X-NC
X-Transaction
Arc-Country
X-Destination
X-Detected-As
X-Developer
MD5-Digest
X-CACHE-KEY
X-Vtex-Processado-Em
X-Presslabs-Stats
X-Trv-Group
X-VG-WebServer
AsisCache
X-G
X-DPWN-IS-SECURE
X-Hl-Ver
X-VG-WebCache
X-Twitter-Response-Tags
X-External-Request-Id
X-SayCDN-TTL
X-Say-TTL
X-Endurance-Cache-Level
X-Say-Cacheable
CDCHOST
Cache-Host
X-Cache-Info
X-Ms-Version
X-NX-Host
X-Ms-Request-Id
X-Instart-Isnd
X-Hnp-Log
X-Proxy-Cache-Status
X-Proxy-Upstream
X-WADP-Cache
X-Sn-Servicetimems
X-S-Maxage
X-Request-URI
X-Gen-Mode
X-Debug-Log
X-Block-Status
Web-Mar-Node
Server-Int
RNT-Time
X-Cache-Bucket
X-Cache-Debug
X-Debug-Cookies
X-Cms-Context
X-Clara-WADP
X-Cdn-Origin
RNT-Machine
X-Device-Os
X-ShopId
We-Hiring
X-ShardId
X-Shopify-Stage
X-Alternate-Cache-Key
X-Sorting-Hat-PodId
Mail-Subject
X-Sorting-Hat-ShopId
X-Varnish-Beresp-Ttl
Proxy-Connection
X-Sucuri-Id
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-B3-Parentspanid
NtCoent-Length
X-BBXSRF
X-Reqid
Wxu-Next-Commit
X-Release
X-RateLimit-Remaining-Second
X-Backend-State
X-SD-PageType
X-Service
W
X-RateLimit-Limit-Second
X-Bip
X-Azure-Ref-OriginShield
X-IN-APIGATEWAYSSL
X-App-Name
X-Amz-Meta-Cache-Control
X-Agile
X-Agile-Id
X-Qloud-Router
X-Auto-Login
X-Agile-Age
X-Scheme
X-Azure-Ref
X-Request-Start
Wxu-Next-Hostname
X-Cache-FS-Status
X-Magnolia-Registration
X-Logging-Id
X-Location
X-Distributor
X-Distil-CS
X-Dispatch
X-Dispatcher-Server
X-Epic-Correlation-Id
X-Eu-Site
X-Hash
X-Irp-Debug
X-IN-APIGATEWAY
X-GeoIP-City
X-Generated-In
X-Fastly-Cache
X-Key
X-Method
X-Developers
X-Policy
X-Compress-Hint
X-Owner
X-CGP
X-Cdn-Srv
X-Cache-Id
X-Cache-URL
X-Core-Mission
X-CUA
X-Debug-Cache-Store
X-Old-Content-Length
X-Node-Id
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-Origin-Expires
X-Origin-Date
True-Client-Country-4JS
Wxu-Next-Region
HA-Ipaddr
Ha-Gx-Prefs
Gh-Request-Id
X-Webstats-RespID
Kp-EeAlive
L
PFcat
X-VC-Cache
X-VG-TLSProxy
Magicmarker
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Generated-On
X-Level-Front-Cache
X-Matched-Rule
X-Thinkindot-L3
Thinkindot-Control
Thinkindot-CacheControl-Type
Fastly-Soc-X-Request-Id
Esi-Enabled
Server-Host
Thinkindot-CacheControl
Pramga
X-WebServer
X-SVT-ORM-VERSION
X-Thanos
X-Nc
X-SVT-ORM-RULES
SD-X-WS
X-TrackingId
X-Swa-Ws
Cache-Provider
X-Parent-Response-Time
X-SaId
X-MSEdge-Flight
X-Is-Gdpr
X-NodeID
X-MSEdge-Features
Adler-Geo
X-Urbn-Context-Path
Section-Io-Cache
Countrycode
Heartbleed
X-Internal-Host
X-Server-IP
X-C
X-Li-Pop
X-Li-Fabric
X-Lb-Id
X-Has-Esi
X-JWT-State
X-Reboot
X-Geo-Header
AKAMAI
X-LI-UUID
V-Age
X-Generation-Time
Served-By
X-Variation
Locale
X-Skip-Cache
Memcached
IBM-Web2-Location
X-VServer
Is-Eu
X-User
X-We-Are-Hiring
X-Clientip
X-Up
X-Platform-Server
X-Urbn-Site-Id
Platform
X-APP-VERSION
X-Dc
X-ServiceProvider
Content-Disposition
Server-ID
X-7Graus-Varnish-Cache-Control
X-LI-Proto
X-7Graus-Varnish-XKeys
X-Core-Value
PageSpeed
X-Geo
Request-Time
X-GEO
X-Vdms-Version
X-Servername
X-GRACE
Environment
Tcn
X-ECACHE
Srv
CF-IPCountry
X-NGENIX-Cache
X-Sucuri-Cache
X-Newrelic-Synthetics
X-EC-Lua
X-Pjax-Url
GEO-REGION-INFO
X-FPC
X-Shopify-Generated-Cart-Token
X-ElasticPress-Search
X-Instart-Info
X-Sigma
X-Sigma-Backend
Cdncip
X-Rocket-Build-Number
Cdnsip
X-Be
X-AK-Request-ID
Group
X-Unique-ID
X-Datadome
X-Nginx-Cache
X-Servedbyhost
X-VHOST
X-Backend-Host
X-Planisys-CDN-Cache
X-Tb-Optimization-Total-Bytes-Saved
X-Backend-Url
Ohc-Cache-HIT
Ohc-File-Size
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
SRV
X-CDN-Forward
X-Var-Ttl
X-Upstream-Ct
X-Microcachable
Resin-Trace
X-Upstream-Ht
Powered-By-ChinaCache
Backend-Name
X-Via-NSCOPI
X-B3-Spanid
X-Source
X-ND-Cache
X-Unique-Id
N-Cache
X-Zone
X-DC
X-IPS-LoggedIn
Pagetype
X-Oracle-Dms-Rid
Memory
Fly-Request-Id
CF-Cached-On
Cache-Prefix
X-RCS-CacheZone
Lfy
Fly-Cache
X-Trafficlayer-App-Version
X-Upstream-HT
X-Upstream-CT
X-Ua
X-VCL-Version
X-AWS-Id
X-VWS-Id
X-Worker
X-LJ-Flow-ID
Cdn
X-Dynatrace
X-Via-Ucdn
X-COUNTRY
X-Check-Cacheable
Locid
Gannett-Cam-Experience-Id
X-Req
X-Served-From
Cf-Ipcountry
X-Correlation-ID
Amp-Access-Control-Allow-Source-Origin
X-Refresh
TTL
X-Gamma-Serve
FNAC-ModuleRouting
Pics-Label
X-Ratelimit-Reset
X-Ratelimit-Remaining
X-Server-W
Geo-Info
Fastly-SIE
X-Rebelmouse-Surrogate-Control
X-Pod
X-Cache-Miss-From
Fastly-SWR
X-Rebelmouse-Cache-Control
GeoIP-Latitude
GeoIP-City
X-CSRF-Token
X-Wa
GeoIP-Country-Code
X-Sedo-Request-Id
X-Pf-Uncompressing
X-Fetched-On
X-Upstream-Proxy
REQUESTUUID
GeoIp-Country-Code
Geoip-Latitude
X-PF-Uncompressing
Ttl
M-TraceId
Geoip-City
PICS-Label
X-Via-SSL
X-Via-Edge
X-Bc
X-Sucuri-ID
X-Tt-Trace-Tag
XServer
X-APP
X-ZONE
X-Vcl-Version
X-HS-Status
X-Render-Time
X-TIME
X-CLOUD-TRACE-CONTEXT
X-LiteSpeed-Cache-Control
X-GDPR
ProcessTime
X-Fstrz
X-SRV
X-HTML-Minification-Powered-By
X-Edge-Server
X-Mode
Cdn-Host
X-GeoIP-Country-Code
X-NU-AKA-ACS-Version
Cdn-Request-Time
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-From
X-Ratelimit-Limit
X-SN
X-Fastly-Country-Code
X-Aicache-OS
X-HostName
X-Dynatrace-Js-Agent
X-Hello
X-Flog
SS
On-Server
X-Response-By
X-Cache-Tag
User-Agent
X-ABtesting
X-Org
Pragrma
X-Swift-Error
MIME-Version
X-NGINX-Cache
X-ServedByHost
URI
Host-ID
HitType
X-BC
X-WR-MODIFICATION
X-FORWARDED-FOR
Requestid
X-WA
X-MP-GENERATED-AT
Who
X-TT-LOGID
X-BE
HostName
X-RateLimit-Reset
CACHE
X-RSL
X-RPS
X-Action
SN
X-Cache-Ttl
Country-Code
X-Fastly-Backend-Reqs
X-DB
X-UPSTREAM-Address
X-PJAX-URL
X-Page-Type
X-Edge-O15-RID
X-DW
X-RPM
X-DSS
X-DI
Dynatrace
RequestUuid
X-Fpc
X-LAGOON
X-Varnish-URL
X-Varnish-Cacheable
X-Cf-Powered-By
X-Cdn-Request-ID
Lb
DataCenter
X-Routing-Service
X-Varnish-Beresp-TTL
UCS
X-Tt-Trace-Host
Server-Id
Is-Session-Tracking
Get-Access-Time
X-Proxied
CDN
LB
X-Zipkin-Id
X-ServerName
Debug
X-Edge
X-Ftr-Cache-Host
X-MCACHE
X-Protected-By
X-Gen-Id
X-Nananana
X-TH-Server
Powered-By
X-Request-Time
X-VC
X-MID
X-SB
Media-Length
X-Request-Url
Product
NnCoection
X-Mid
Proxy-Firewall
Warning
X-LiteSpeed-Tag
X-Akamai-ERPolicy
X-LB-ID
RequestId
Correlation-Id
Xet-Cookie
X-Akamai-ERRuleID
X-Amzn-Remapped-Connection
X-Li-Proto
SID
X-Fastly-Cache-Hits
Thinkindot-Cache-Type
V-Cache
X-Amzn-Remapped-Date
X-Dw-Trace-Id
Application