Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
CF-RAY
CF-Cache-Status
Pragma
Link
X-Powered-By
ETag
Expect-CT
Via
X-XSS-Protection
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Xss-Protection
Referrer-Policy
X-Served-By
X-Varnish
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
Alt-Svc
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Request-ID
X-Generator
Content-Security-Policy-Report-Only
X-Cache-Status
X-Cacheable
X-Permitted-Cross-Domain-Policies
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-Template
X-Language
X-AspNetMvc-Version
Status
X-Content-Security-Policy
X-Buckets
Content-Encoding
Access-Control-Expose-Headers
Upgrade
X-CDN
Xkey
Access-Control-Max-Age
Keep-Alive
X-Drupal-Dynamic-Cache
X-Kinja-Server-Push
X-Turbo-Charged-By
X-Via
X-AH-Environment
X-Ua-Compatible
X-Cache-Group
X-Age
X-Pass-Why
X-Backend
X-Envoy-Upstream-Service-Time
EagleId
X-Server
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Page-Speed
X-Server-Powered-By
X-Pingback
X-UA-Device
X-Proxy-Cache
X-Swift-CacheTime
X-Swift-SaveTime
X-Hacker
X-Nginx-Cache-Status
Ali-Swift-Global-Savetime
Request-Context
Grace
X-Varnish-Cache
Server-Timing
Feature-Policy
Cf-Railgun
X-Amz-Version-Id
X-LiteSpeed-Cache
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Rq
X-WebKit-CSP
Report-To
X-Server-Id
EagleEye-TraceId
X-Ac
X-Response-Time
X-Host
Request-Id
X-Cnection
X-OneAgent-JS-Injection
X-Backend-Server
X-DataDome
X-Node
Content-Location
X-Origin-Cache
X-Cloud-Trace-Context
X-Dns-Prefetch-Control
X-Readtime
X-Cache-Lookup
X-Cdn
NEL
X-Ws-Request-Id
X-Vhost
X-Application-Context
X-ORACLE-DMS-ECID
X-Dispatcher
X-ORACLE-DMS-RID
X-HW
Allow
X-Clacks-Overhead
X-Rack-Cache
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Origin-Upstream-Status
X-DynaTrace
Surrogate-Control
Rating
X-Country
X-FTR-Request-ID
Fusion-Component-Id
Fusion-Content-Id
Fusion-Content-Source
Fusion-Source
Fusion-Template-Id
X-Country-Code
X-Akam-SW-Version
X-Goog-Hash
X-Varnish-TTL
Pinterest-Generated-By
X-Instart-Request-ID
X-Vname
X-TtlSet
X-PC
X-MS-InvokeApp
Edge-Control
X-B3-TraceId
X-Url
X-Ruxit-JS-Agent
X-Mod-Pagespeed
SPRequestGuid
Verso
X-Powered-By-Plesk
X-D2id
X-Trace
X-Sol
X-Middleton-Response
Response
Pagespeed
X-SharePointHealthScore
Accept-Ch
Display
X-Middleton-Display
X-VARITI-CCR
Service-Worker-Allowed
RTSS
X-Server-Name
X-GitHub-Request-Id
X-Exp-Variant
X-Exp-Id
X-Cdn-Fetch
X-Use-Magma
X-Kinja
X-GoogleNews-Bot
X-Kinja-Server
X-Kinja-Build
X-Kinja-Revision
X-ESI
Content-MD5
SPIisLatency
SPRequestDuration
X-Navigation-Version
X-Vcache
X-Debug
X-Powered-CMS
X-TTL
X-Abt-Application-Version
X-Vcap-Request-Id
X-Amz-Server-Side-Encryption
Charset
X-Server-ID
X-CST
Public-Key-Pins
X-Forwarded-Proto
MS-Author-Via
X-Cached
X-Upstream
DynaTrace
Accept-Ch-Lifetime
X-NF-Request-ID
X-Amz-Rid
X-Version
Realpath
Edge-Cache-Tag
X-Px
MicrosoftSharePointTeamServices
X-Shard
Arr-Disable-Session-Affinity
X-Ezoic-Cdn
X-Pinterest-Rid
X-Shield-Request-Id
Pinterest-Version
X-MSEdge-Ref
Fastly-Restarts
TCN
Access-Control-Request-Method
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Ser
X-TEC-API-ORIGIN
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-DynaTrace-JS-Agent
X-Trafficlayer-App-Name
X-Trafficlayer-App-Scope
X-Fastly-Request-ID
S
X-XRDS-Location
X-Recruiting
X-Accel-Expires
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-DIS-Request-ID
Front-End-Https
X-Client-IP
X-Amz-Meta-S3cmd-Attrs
Nginx-Cache
X-T
X-Id
X-Goog-Storage-Class
X-Varnish-Age
X-Element-Page-Cache
X-Mrf-Section-Lastmod
Mrf-Cache-Status
X-Mrf-Item-Lastmod
MRF-Tech
X-B3-TraceId-Primal
X-Country-Code-Real
X-FTR-DC
X-FTR-Realm
X-FTR-Backend
X-FTR-Cache-Status
X-FTR-Balancer
X-FTR-Backend-Server
X-Amzn-Trace-Id
X-FTR-Expires
X-Dw-Request-Base-Id
X-Webkit-Csp
Cache-Tag
X-Ttl
X-Webapp-Samesite-None-Activated-N
Fastcgi-Cache
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Hub-Id
X-Fastcgi-Cache
X-Frontend
NR-ENABLED
X-Content-Digest
Powered
X-Hits
X-Correlation-Id
X-Kinsta-Cache
X-RateLimit-Remaining
X-Oneagent-Js-Injection
X-FTR-Cache-Host
Alternate-Protocol
X-Hp-Webp
X-Aspnetmvc-Version
X-N
ServerID
X-Request-Received
X-Request-Processing-Time
X-Grace
X-Cache-Hit
X-Request-Handler-Origin-Region
Server-Name
X-Microsite
X-Node-Name
TP-Cache
TP-L2-Cache
X-HS-Combine-CSS
PB-PID
PB-RID
Accept-CH
Arc-Version
X-Mobile-Rewrite
X-Zen-Fury
AMP-Access-Control-Allow-Source-Origin
Accept-CH-Lifetime
X-Rid
Healthy
X-Content-Type
X-User-Agent
X-Revision
X-Ruxit-Js-Agent
X-Analytics
Backend-Timing
X-Akamai-Edgescape
X-Content-Security-Policy-Report-Only
Server-Node
X-Logged-In
X-LB-Cache
X-Activity-Id
X-AppVersion
Cache-Status
X-Forwarded-For
X-Az
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Pad
X-Cached-By
AR-PoweredBy
AR-ATIME
AR-CACHE
X-Mobile-URL
X-NWS-LOG-UUID
X-IPLB-Instance
X-Varnish-Grace
Retry-After
X-Type
X-B3-Sampled
Refresh
X-Litespeed-Cache
X-Content-Options
X-F-Cache
Ar-Sid
X-FastCGI-Cache
X-GUploader-UploadID
Paypal-Debug-Id
Upgrade-Insecure-Requests
FilterID
X-Geo-Country
X-Srv
X-App-Environment
X-Jobs
X-Tumblr-User
X-Tumblr-Pixel
X-Tumblr-Pixel-0
Host
X-Debug-Info
X-Instance
X-Varnish-Backend
Source
X-AOL-HN
X-FB-Debug
X-B
Accept-Charset
X-PHP-Backend
X-Framework
Actual-Object-TTL
X-Request-Guid
DC
X-Cluster
X-Page-Id
X-Via-JSL
Access-Control-Allow-Method
X-Cache-Age
X-WebKit-CSP-Report-Only
X-ATG-Version
X-Cache-Key
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Seen-By
X-TT
X-Cache-2
MS-CV
X-PressLabs-Stats
X-Git-Hash
Cache
X-Content-Powered-By
X-Cache-TTL
X-Whom
Fastcgi-Useragent
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
AR-Request-ID
X-UA
X-Amz-Replication-Status
X-Esi
X-Cache-Control
X-Host-Name
X-B-Cache
X-TA-CDN-Provider
X-Signature
Surrogate-Key
Host-Header
X-Wix-Request-Id
NGB
X-Response-Served-From
X-Daa-Tunnel
X-Origin-Server
Frame-Options
X-Cache-Enabled
X-RequestSource
X-GeoIP
X-Mobile
WPE-Backend
X-Cache-Action
Cache-Tv-Group
Filters
X-Cache-NE
X-FW-Hash
X-FW-Serve
X-Hyper-Cache
X-Drupal-Cache-Tags
Eomportal-Instance
X-FW-Type
X-Region
X-FW-Static
X-FW-Server
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
Cleartype
Xserver
X-TX-ID
X-Cache-Rule
X-Cache-Operation
X-Adobe-Content
X-Cacheable-TTL
X-Adobe-Loc
Payment
X-Kong-Upstream-Latency
X-EdgeConnect-Cache-Status
X-Handled-By
X-SERVER
X-Kong-Proxy-Latency
Webserver
From-Origin
X-RemovedCookies
X-ProcessESI
X-UA-Device-Type
X-Forwarded-Host
X-Akamai-Transformed
Datacenter
X-Load-Cache
X-RTag
Ms-Operation-Id
X-Cache-TTL-Remaining
X-NewRelic-App-Data
X-Hostname
X-App-Server
X-Cache-Server
X-Edge-Location
X-ATS-Timestamp
X-Time
X-Status
Liferay-Portal
X-Contextid
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Varnish-Hostname
X-XRDS-LOCATION
X-Varnish-Server
Tracecode
X-Rule
Odigeo-Trace-Id
Country
X-TT-TIMESTAMP
X-BCube-Filmed-By
X-ES-SERVER
Load-Balancing
X-RN-RSRV
Meta-Geo
X-Cache-Var
X-Path-Route
X-Cache-Var-Map
X-Upgrade-Enabled
X-Xfnlog-Site
X-Debug-Cache
X-Viewer-Country
DSUID
TWC-Device-Class
X-OCL
TWC-Connection-Speed
X-R9-Blue-Green-Version
X-Cache-Host
Webcakes-Region
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Storage-Class
TWC-Locale-Group
TWC-GeoIP-LatLong
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
Webcakes-App-Version
X-Origin-Hint
Webcakes-App-Name
TWC-Privacy
Server-Info
Mn-Server-Ip
Version
X-PCL
Property-Id
X-ORACLE-APMCS-TAG
X-Pubstack
Release
X-CCM
X-Varnish-Cache-Hits
Cache-Tags
X-ORACLE-APMCS-REQUEST-ID
X-Via-Fastly
DB-Nickname
X-EIG-Tracking-Id
X-VCT
TWC-GeoIP-Country
Azure-SlotName
Azure-SiteName
Azure-Version
Origin-Edge-Control
Cache-Name
Origin-Cache-Control
X-Origin
X-Akamai-Request-ID2
X-From
NGX
X-Cache-Time
X-UUID
X-Rocket-Nginx-Bypass
Azure-InstanceId
X-IP
X-Human
X-Redis-Cache
Azure-RegionName
X-FW-Dynamic
S-Rt
X-Site-Version
X-Content-Age
X-Drupal-Cache-Contexts
X-FireWall-Port
X-PERF
X-Www-Served-By
X-Cache-Config
X-Labrador-Cache-Channel
X-Origin-Response-Time
X-Format
L5d-Success-Class
X-Generated
X-Hosted-By
X-Section
X-Rendered-As
X-ApacheServer
X-Akamai-Request-ID
X-Locale
X-Soup
X-Proxy
X-Real-IP
X-Web-Node
X-ServerID
X-Access
S-Cnection
Decoy-Debug-Key
X-NWS-UUID-VERIFY
Decoy-Debug-Status
Fastly-SSL
Decoy-Debug-TTL
X-VCache
X-JoinUs
X-Proto
X-Is-Bot
X-Vgn-Hpd-Reason
X-FC-Vary-Parameters
Viewport
X-Varnish-Hits
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Timing-Wait
X-Loop
X-Info
Selected-Fe
X-Time-Microsecs
X-TNCMS
X-Proxy-Build
Ec-Rule-Version
X-Backend-Name
X-Cluster-Name
X-RateLimit-Limit
X-ProxyCache-Status
X-ProxyCache-Key
X-BYPASS-REASON
Uber-Trace-Id
X-Storage
X-Guploader-Uploadid
X-Cache-Backend
X-Origin-CC
X-Generated-By
X-Origin-TTL
X-App-Version
X-URL
X-Accel-Buffering
X-PHP-Host
Rt-Fastcgi-Cache
Cache-Key
Cteonnt-Length
Akamai-GRN
X-Amzn-Remapped-Content-Length
X-WA-Info
X-Nginx-Cache-Key
X-SaId
Origin
Cache-Hits
Time
X-NCache
X-Cache-Remote
Vix-Hermes-Req-Id
X-CF-Powered-By
X-No-Session
X-Hit
GEO-INFO
X-Backend-TTL
X-GoCache-CacheStatus
Accept-Language
X-L-Path
X-FB-TRIP-ID
X-Environment-Context
X-Trace-Id
X-Presslabs-Stats
X-SS-Set-Cookie
X-Geo
X-MServer
X-Tb
X-B3-SpanId
X-CS
Access-Control-Request-Headers
X-B3-Traceid
Srv
X-Device-Type
X-Tumblr-Pixel-3
X-Say-Cacheable
X-APP-VERSION
X-SayCDN-TTL
X-Cache-Grace
X-Say-TTL
X-OVcl
X-Unique-Id
X-OVcl-Cache
X-S
X-CDN-Forward
User-Cache-Control
X-Tec-Api-Root
X-Cluster-Node
X-Tec-Api-Origin
X-Tec-Api-Version
X-CACHE-KEY
X-Shopify-Generated-Cart-Token
X-Shopify-Stage
X-ShopId
X-ShardId
ServedBy
X-Alternate-Cache-Key
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Uri
Node
Arc-Country
AsisCache
Cross-Origin-Window-Policy
Content-Style-Type
Content-Script-Type
Meta-Geo-Continent
Machine
Mobile-Detection-Method
MD5-Digest
Apple-News-Services-Handled
Apple-News-Services-Host
IsBot
BehaviorPad-Version
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Fastcgi-X-Cache-Version
X-A-Dcw
X-Rojux
X-Rewrite-Enabled
X-S-Cookie
X-ScT
X-Server-Time
X-Request-UUID
X-Region-Sid
X-G
X-Hl-Ver
X-PAYTM-SRV-ID
X-Processor
X-Service
X-Session-Fingerprint
X-VG-WebServer
X-VG-WebCache
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-Twitter-Response-Tags
X-Trv-Group
X-SIPLIST1
X-SRCache-Key
X-Svr
X-Transaction
X-External-Request-Id
X-DPWN-IS-SECURE
X-A
VivaBuild
X-A-Ccd
X-A-Dam
X-A-Dgt
Viewtype
T-Server
Request-Country
Request-EU
Rt-Proxy-Cache
Server-Host
X-A-Wwc
X-Accel-Expires-Debug
X-D
X-Connection-Hash
X-Date
X-Destination
X-Detected-As
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-Aed
X-AIR-PT
X-Application
X-B-Cookie
Rendered-Blocks
X-ARC
Mime-Version
X-Ah-Environment
X-Dc
X-CSRF-TOKEN
X-EC-Lua
OT-Force-Account-Verify
ServerName
X-Via-CDN
Wxu-Next-Commit
X-Ms-Version
Wxu-Next-Hostname
Wxu-Next-Region
X-Cache-Debug
X-Endurance-Cache-Level
X-Ms-Request-Id
CDCHOST
X-Hnp-Log
X-Block-Status
X-Matched-Rule
Web-Mar-Node
X-S-Maxage
X-Vdms-Version
X-Webstats-RespID
X-Generated-On
X-Varnish-Beresp-Ttl
X-Gen-Mode
X-WADP-Cache
X-RateLimit-Remaining-Second
X-Varnish-Beresp-Status
Server-Int
X-RateLimit-Limit-Second
X-Varnish-Beresp-Grace
X-Request-URI
Cache-Host
X-Cache-Bucket
We-Hiring
X-Core-Value
Mail-Subject
Thinkindot-Control
X-Cms-Context
X-CUA
X-Level-Front-Cache
X-Dispatcher-Server
Thinkindot-CacheControl
X-Dispatch
X-Instart-Isnd
Thinkindot-CacheControl-Type
RNT-Time
X-Clara-WADP
X-Cache-Info
X-Hash
X-Thinkindot-L3
Proxy-Connection
RNT-Machine
X-Parent-Response-Time
NtCoent-Length
X-B3-Parentspanid
X-Nc
X-SRV
X-Scheme
X-Reqid
W
True-Client-Country-4JS
X-SD-PageType
X-Azure-Ref-OriginShield
X-Cache-URL
X-Location
X-Logging-Id
X-Cache-Id
X-C
X-Cache-FS-Status
X-Cdn-Srv
X-Compress-Hint
X-Generation-Time
X-Epic-Correlation-Id
X-Geo-Header
X-Distributor
X-Developers
X-BBXSRF
X-Method
X-Agile-Id
X-Qloud-Router
X-Agile-Age
X-Agile
X-Reboot
X-Amz-Meta-Cache-Control
X-Owner
X-Sucuri-Cache
X-Backend-State
X-Azure-Ref
X-Old-Content-Length
X-App-Name
X-Release
X-SVT-ORM-VERSION
PFcat
Fastly-Soc-X-Request-Id
X-Core-Mission
X-Debug-Cookies
Now
Heartbleed
Kp-EeAlive
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Debug-Log
X-GeoIP-City
X-Origin-Expires
X-Proxy-Cache-Status
X-Proxy-Upstream
X-RCS-CacheZone
X-Origin-Date
X-NX-Host
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
AKAMAI
L
Esi-Enabled
X-Fastly-Cache
X-Swa-Ws
X-VG-TLSProxy
X-VC-Cache
Pramga
SD-X-WS
X-SVT-ORM-RULES
Served-By
Magicmarker
X-UnsetCookies
Cache-Provider
X-Magnolia-Registration
X-Source
X-FW-Version
Hostname
X-Policy
X-JWT-State
X-Is-Gdpr
Gh-Request-Id
X-Li-Fabric
X-Li-Pop
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
Ha-Gx-Prefs
X-Planisys-CDN-Cache
X-Request-Start
X-TrackingId
X-WebServer
X-VServer
X-Via-NSCOPI
X-Thanos
X-Has-Esi
X-Rocket-Build-Number
X-Sigma
X-Sigma-Backend
HA-Ipaddr
X-Platform-Server
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Urbn-Site-Id
X-Urbn-Context-Path
X-Debug-Cache-Expiry
X-Skip-Cache
X-MSEdge-Flight
X-MSEdge-Features
X-CGP
X-User
X-Distil-CS
X-Eu-Site
X-Key
X-ServiceProvider
X-Auto-Login
X-LI-UUID
X-Server-IP
X-Irp-Debug
X-Generated-In
X-Up
X-Bip
X-We-Are-Hiring
X-Variation
X-NodeID
V-Age
Cdnsip
Content-Disposition
X-Upstream-Ht
Adler-Geo
X-AK-Request-ID
Memcached
X-Upstream-Ct
Cdncip
Is-Eu
IBM-Web2-Location
Section-Io-Cache
Platform
Locale
X-Cdn-Forward
Powered-By-ChinaCache
X-ND-Cache
X-LI-Proto
X-7Graus-Varnish-XKeys
X-7Graus-Varnish-Cache-Control
X-Internal-Host
Server-ID
X-NC
Countrycode
X-Clientip
X-TIME
X-COUNTRY
X-GRACE
X-Sucuri-Id
Environment
A
X-Be
X-Developer
Tcn
X-Servername
X-B3-Spanid
X-Trafficlayer-App-Version
GEO-REGION-INFO
CF-IPCountry
X-Nginx-Cache
Geo-Info
X-Lb-Id
X-Device-Os
X-Sn-Servicetimems
X-Req
Locid
X-Cdn-Origin
X-Served-From
X-Node-Id
X-Newrelic-Synthetics
FNAC-ModuleRouting
X-FPC
X-VHOST
X-Gamma-Serve
X-Refresh
X-FORWARDED-FOR
X-Zone
ProcessTime
X-Servedbyhost
X-Microcachable
X-Webkit-CSP
X-HTML-Minification-Powered-By
X-Edge-O15-RID
X-Sucuri-ID
X-Render-Time
Request-Time
X-Pjax-Url
X-IPS-LoggedIn
Memory
X-VWS-Id
X-Tb-Optimization-Total-Bytes-Saved
Resin-Trace
X-AWS-Id
X-LJ-Flow-ID
X-GeoIP-Country-Code
X-Pf-Uncompressing
X-VCL-Version
X-NU-AKA-ACS-Version
Gannett-Cam-Experience-Id
Cf-Ipcountry
CF-Cached-On
X-Correlation-ID
Amp-Access-Control-Allow-Source-Origin
Group
Pics-Label
X-DC
TTL
X-Instart-Info
XServer
X-ECACHE
X-Ratelimit-Remaining
X-Mode
X-ElasticPress-Search
X-MP-GENERATED-AT
X-Unique-ID
X-Var-Ttl
X-Backend-Host
Geoip-City
X-Pod
X-Backend-Url
GeoIp-Country-Code
Geoip-Latitude
X-CSRF-Token
MIME-Version
X-NGENIX-Cache
GeoIP-City
GeoIP-Country-Code
GeoIP-Latitude
Cdn
X-Via-Edge
Backend-Name
M-TraceId
PICS-Label
X-Via-SSL
X-ZONE
Ttl
X-Vcl-Version
HostName
Host-ID
X-Routing-Service
X-Proxied
X-Bc
X-Zipkin-Id
X-APP
Lfy
X-Check-Cacheable
N-Cache
Pagetype
REQUESTUUID
X-CLOUD-TRACE-CONTEXT
Cache-Prefix
Cache-Cookie-Set-From
Fly-Request-Id
Cache-Cookie-Set-Idcheck
X-Fstrz
Cache-Cookie-Set-Lfrom
Fly-Cache
Ohc-Cache-HIT
Ohc-File-Size
X-Via-Ucdn
X-Cdn-Request-ID
X-GEO
HitType
X-BC
X-PF-Uncompressing
X-Worker
X-Ratelimit-Limit
X-Sedo-Request-Id
X-Cache-Miss-From
X-HostName
X-PJAX-URL
X-Fastly-Country-Code
X-HS-Status
X-LiteSpeed-Cache-Control
X-Swift-Error
X-Dynatrace-Js-Agent
URI
User-Agent
X-Fetched-On
X-TH-Server
On-Server
X-Request-Time
Pragrma
X-Cache-Tag
X-Server-W
X-Upstream-CT
X-Upstream-HT
X-Rebelmouse-Cache-Control
X-ServedByHost
X-WR-MODIFICATION
Fastly-SIE
Fastly-SWR
X-Wa
X-Rebelmouse-Surrogate-Control
X-UPSTREAM-Address
X-Tt-Trace-Tag
X-NGINX-Cache
Powered-By
SRV
X-Aicache-OS
Who
X-WA
Media-Length
CDN
X-BE
X-TT-LOGID
X-Fastly-Backend-Reqs
X-GDPR
X-Fpc
X-LAGOON
AR-SID
X-LB-ID
X-Varnish-Cacheable
X-Varnish-URL
X-Cf-Powered-By
DataCenter
X-Edge-Server
Debug
Server-Id
X-ServerName
X-Tt-Trace-Host
FSS-Cache
CACHE
Cdn-Host
FSS-Proxy
Cdn-Request-Time
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-Ua
X-RateLimit-Reset
X-Ftr-Cache-Host
X-ABtesting
X-Varnish-Beresp-TTL
LB
Get-Access-Time
Is-Session-Tracking
X-Flog
X-Gen-Id
X-Protected-By
X-Hello
X-SN
SS
UCS
X-Hp-Ccpa-Warning
Cneonction
XxX-Cache-Status
NnCoection
Xet-Cookie
X-SB
X-VC
X-Nananana
Warning
X-DI
X-DSS
X-DW
X-LiteSpeed-Tag
X-DB
X-Action
X-Org
X-Response-By
SN
Requestid
X-RPM
X-RPS
SID
X-Fastly-Cache-Hits
Application
Product
X-Li-Proto
Thinkindot-Cache-Type
X-RSL
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
X-Dw-Trace-Id
X-Request-Url