Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
CF-RAY
CF-Cache-Status
Pragma
Link
X-Powered-By
ETag
Expect-CT
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Xss-Protection
X-Varnish
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
Alt-Svc
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Request-ID
Content-Security-Policy-Report-Only
X-Generator
X-Cache-Status
X-Cacheable
X-Permitted-Cross-Domain-Policies
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Template
X-Iinfo
X-Language
X-AspNetMvc-Version
X-Content-Security-Policy
Status
X-Buckets
Content-Encoding
Access-Control-Expose-Headers
Upgrade
X-CDN
Xkey
X-Kinja-Server-Push
Access-Control-Max-Age
Keep-Alive
X-Drupal-Dynamic-Cache
X-Turbo-Charged-By
X-Via
X-Ua-Compatible
X-Cache-Group
X-Age
X-AH-Environment
X-Pass-Why
X-Envoy-Upstream-Service-Time
X-Backend
EagleId
X-Server
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Page-Speed
X-Pingback
X-Server-Powered-By
X-UA-Device
X-Swift-SaveTime
X-Swift-CacheTime
X-Proxy-Cache
X-Hacker
Ali-Swift-Global-Savetime
X-Nginx-Cache-Status
Request-Context
Grace
X-Varnish-Cache
Server-Timing
Feature-Policy
Cf-Railgun
X-Amz-Version-Id
X-Device
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-WebKit-CSP
X-LiteSpeed-Cache
X-Rq
Report-To
X-Ac
EagleEye-TraceId
X-Response-Time
X-Server-Id
X-OneAgent-JS-Injection
X-Host
Request-Id
X-Cnection
X-Backend-Server
X-DataDome
Content-Location
X-Node
X-Cloud-Trace-Context
X-Origin-Cache
X-Readtime
X-Cache-Lookup
NEL
X-Vhost
X-Application-Context
X-Dispatcher
X-Ws-Request-Id
X-ORACLE-DMS-ECID
X-HW
X-Cdn
X-ORACLE-DMS-RID
Allow
X-Dns-Prefetch-Control
X-Clacks-Overhead
X-Rack-Cache
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Origin-Upstream-Status
Surrogate-Control
X-DynaTrace
X-Country
Rating
X-FTR-Request-ID
X-Country-Code
X-Goog-Hash
Fusion-Content-Id
Fusion-Source
Fusion-Template-Id
Fusion-Content-Source
Fusion-Component-Id
X-Akam-SW-Version
X-Varnish-TTL
X-TtlSet
X-Vname
Pinterest-Generated-By
X-PC
X-Instart-Request-ID
X-Ruxit-JS-Agent
X-Url
X-MS-InvokeApp
Edge-Control
X-B3-TraceId
X-Mod-Pagespeed
Verso
X-Powered-By-Plesk
SPRequestGuid
Accept-Ch
X-D2id
X-Trace
X-Middleton-Response
X-Sol
Response
Pagespeed
X-Middleton-Display
Display
X-SharePointHealthScore
X-VARITI-CCR
RTSS
X-Exp-Variant
X-Exp-Id
X-Cdn-Fetch
X-Server-ID
X-GoogleNews-Bot
X-Use-Magma
X-Kinja
X-Kinja-Server
X-Server-Name
X-Kinja-Build
X-Kinja-Revision
Service-Worker-Allowed
X-GitHub-Request-Id
X-ESI
SPIisLatency
SPRequestDuration
X-Navigation-Version
Content-MD5
X-Powered-CMS
X-Abt-Application-Version
X-Debug
X-Vcache
X-Vcap-Request-Id
Accept-Ch-Lifetime
X-CST
Public-Key-Pins
X-Amz-Server-Side-Encryption
MS-Author-Via
X-Upstream
X-Forwarded-Proto
Charset
X-TTL
X-Cached
X-Version
X-NF-Request-ID
X-Amz-Rid
DynaTrace
X-Px
Realpath
Edge-Cache-Tag
X-Shard
TCN
MicrosoftSharePointTeamServices
Fastly-Restarts
Arr-Disable-Session-Affinity
X-Ezoic-Cdn
X-MSEdge-Ref
Pinterest-Version
X-DynaTrace-JS-Agent
X-Pinterest-Rid
X-Shield-Request-Id
X-Ser
Access-Control-Request-Method
X-TEC-API-ORIGIN
X-SRCache-Store-Status
X-Recruiting
X-SRCache-Fetch-Status
X-TEC-API-ROOT
X-TEC-API-VERSION
S
X-Fastly-Request-ID
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-XRDS-Location
Nginx-Cache
X-Accel-Expires
X-DIS-Request-ID
Front-End-Https
X-Trafficlayer-App-Name
X-Trafficlayer-App-Scope
X-Amz-Meta-S3cmd-Attrs
X-Client-IP
X-Goog-Storage-Class
X-Ttl
X-Id
X-Element-Page-Cache
X-Varnish-Age
X-T
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
X-Litespeed-Cache
X-FTR-Balancer
X-FTR-Realm
X-FTR-Backend-Server
X-FTR-Cache-Status
X-FTR-Backend
X-Country-Code-Real
X-FTR-DC
X-FTR-Expires
X-Amzn-Trace-Id
X-Dw-Request-Base-Id
Fastcgi-Cache
Cache-Tag
X-Content-Digest
X-HS-Hub-Id
NR-ENABLED
X-HS-Content-Id
X-Frontend
Powered
X-Correlation-Id
X-Hits
X-HS-Cache-Config
X-Kinsta-Cache
X-Webapp-Samesite-None-Activated-N
X-Fastcgi-Cache
X-RateLimit-Remaining
X-Grace
X-FTR-Cache-Host
ServerID
X-Aspnetmvc-Version
Alternate-Protocol
X-Webkit-Csp
X-Hp-Webp
TP-Cache
TP-L2-Cache
X-Request-Processing-Time
X-Request-Received
X-Node-Name
X-Cache-Hit
X-N
X-Microsite
X-Request-Handler-Origin-Region
PB-RID
PB-PID
X-Mobile-Rewrite
AMP-Access-Control-Allow-Source-Origin
Arc-Version
Server-Name
X-Zen-Fury
X-Rid
Healthy
X-User-Agent
X-Content-Type
Backend-Timing
X-Revision
X-Analytics
AR-PoweredBy
AR-ATIME
Server-Node
AR-CACHE
X-Forwarded-For
Ar-Sid
X-HS-Combine-CSS
X-Akamai-Edgescape
X-Content-Security-Policy-Report-Only
X-LB-Cache
X-Logged-In
X-FastCGI-Cache
X-Az
X-AppVersion
X-Activity-Id
Cache-Status
X-Pad
X-Oneagent-Js-Injection
X-Amz-Apigw-Id
X-IPLB-Instance
Retry-After
X-Amzn-RequestId
X-GUploader-UploadID
X-Cached-By
X-NWS-LOG-UUID
Accept-CH-Lifetime
Accept-CH
X-Type
X-Varnish-Grace
X-Srv
X-Mobile-URL
X-Via-JSL
X-Ruxit-Js-Agent
X-B3-Sampled
Paypal-Debug-Id
X-Content-Options
Refresh
X-F-Cache
FilterID
Upgrade-Insecure-Requests
X-Cache-Age
X-Geo-Country
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-0
Accept-Charset
X-FB-Debug
X-Instance
X-Request-Guid
X-Debug-Info
Host
Source
X-Cluster
X-Jobs
X-App-Environment
X-AOL-HN
Actual-Object-TTL
X-B
X-Varnish-Backend
Access-Control-Allow-Method
X-Page-Id
X-PHP-Backend
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
AR-Request-ID
DC
X-Framework
X-Seen-By
X-ATG-Version
X-WebKit-CSP-Report-Only
X-Cache-Key
MS-CV
Fastcgi-Useragent
X-Content-Powered-By
X-TT
X-PressLabs-Stats
X-Whom
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Git-Hash
X-Cache-2
X-Cache-TTL
X-Esi
X-Cache-Control
X-Host-Name
X-TA-CDN-Provider
X-Amz-Replication-Status
Cache
Surrogate-Key
X-Wix-Request-Id
X-UA
X-Signature
X-Daa-Tunnel
Host-Header
X-B-Cache
NGB
X-Cache-Rule
X-Cache-Operation
X-Response-Served-From
X-FW-Type
X-FW-Hash
X-FW-Serve
X-FW-Static
X-FW-Server
X-Kong-Upstream-Latency
Frame-Options
X-Kong-Proxy-Latency
X-Ah-Environment
X-Origin-Server
X-Tumblr-Pixel-2
Cache-Tv-Group
X-Tumblr-Pixel-1
X-Cache-Action
X-Drupal-Cache-Tags
X-GeoIP
X-RequestSource
WPE-Backend
X-Region
Payment
Webserver
X-Hyper-Cache
Cleartype
X-Cache-NE
X-Forwarded-Host
X-Cache-Enabled
X-Adobe-Content
Eomportal-Instance
X-Mobile
X-Handled-By
X-Cacheable-TTL
X-Adobe-Loc
X-TX-ID
Filters
Xserver
X-SERVER
X-Time
From-Origin
X-RemovedCookies
X-UA-Device-Type
X-ProcessESI
X-EdgeConnect-Cache-Status
Datacenter
X-RTag
Ms-Operation-Id
X-Load-Cache
X-Cache-TTL-Remaining
X-Akamai-Transformed
X-Hostname
X-App-Server
X-NewRelic-App-Data
Tracecode
X-Cache-Server
X-Status
X-Edge-Location
X-Contextid
Liferay-Portal
X-XRDS-LOCATION
X-VCache
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-BCube-Filmed-By
X-Varnish-Hostname
X-TT-TIMESTAMP
X-Varnish-Server
Odigeo-Trace-Id
X-ATS-Timestamp
X-Rule
Meta-Geo
X-Cache-Var-Map
X-ES-SERVER
X-Cache-Var
X-RN-RSRV
X-FW-Dynamic
X-Path-Route
Load-Balancing
Server-Info
Country
DB-Nickname
X-Rocket-Nginx-Bypass
X-Upgrade-Enabled
Version
X-Real-IP
X-EIG-Tracking-Id
X-CCM
Azure-SlotName
X-Via-Fastly
Azure-RegionName
Azure-InstanceId
X-UUID
X-ServerID
X-TNCMS
X-Redis-Cache
X-Web-Node
Mn-Server-Ip
Cache-Tags
Azure-Version
X-IP
Azure-SiteName
X-Origin-Hint
X-Drupal-Cache-Contexts
TWC-GeoIP-LatLong
TWC-Locale-Group
TWC-Privacy
X-R9-Blue-Green-Version
X-Loop
TWC-Device-Class
TWC-GeoIP-Country
X-Cache-Config
Webcakes-App-Name
X-Cache-Time
Webcakes-Region
X-Hosted-By
X-Varnish-Cache-Hits
X-Labrador-Cache-Channel
Webcakes-App-Version
X-Debug-Cache
X-Cache-Host
X-PCL
TWC-Connection-Speed
Fastly-SSL
X-FC-Vary-Parameters
S-Rt
X-Origin
X-Proto
Property-Id
L5d-Success-Class
X-Origin-Response-Time
X-Akamai-Request-ID
X-OCL
X-Proxy
X-From
X-Section
X-Cluster-Name
X-Backend-Name
X-Access
Viewport
Ec-Rule-Version
X-Human
X-Info
X-FireWall-Port
Release
Origin-Edge-Control
X-Proxy-Build
X-Pubstack
X-Format
X-Goog-Meta-Goog-Reserved-File-Mtime
X-RateLimit-Limit
X-Generated
X-VCT
Selected-Fe
Origin-Cache-Control
NGX
X-Content-Age
X-Xfnlog-Site
X-Timing-Wait
X-JoinUs
X-Viewer-Country
Cache-Name
DSUID
X-Varnish-Hits
X-PERF
X-Soup
X-Akamai-Request-ID2
X-NWS-UUID-VERIFY
X-ApacheServer
S-Cnection
X-Rendered-As
Decoy-Debug-Status
Decoy-Debug-Key
X-Vgn-Hpd-Reason
X-Www-Served-By
Decoy-Debug-TTL
X-Origin-TTL
X-Origin-CC
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Object-Type
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
X-Time-Microsecs
X-Locale
X-Site-Version
X-Is-Bot
X-B3-Traceid
Uber-Trace-Id
Rt-Fastcgi-Cache
X-Storage
X-ProxyCache-Status
X-ProxyCache-Key
X-BYPASS-REASON
X-ORACLE-APMCS-TAG
X-ORACLE-APMCS-REQUEST-ID
X-PHP-Host
X-WA-Info
X-Cache-Backend
Cache-Key
X-Generated-By
X-Amzn-Remapped-Content-Length
Akamai-GRN
Time
Cteonnt-Length
X-Accel-Buffering
X-App-Version
X-SS-Set-Cookie
X-GoCache-CacheStatus
Cache-Hits
X-Guploader-Uploadid
X-Hit
Vix-Hermes-Req-Id
GEO-INFO
X-NCache
X-Tec-Api-Origin
Origin
X-Tec-Api-Version
X-Cache-Remote
X-Backend-TTL
X-Tec-Api-Root
X-Cache-Grace
X-Nginx-Cache-Key
X-CF-Powered-By
X-APP-VERSION
X-FB-TRIP-ID
X-Device-Type
X-Presslabs-Stats
X-Trace-Id
X-CS
X-Environment-Context
X-Tumblr-Pixel-3
X-L-Path
X-SaId
X-OVcl
X-No-Session
X-OVcl-Cache
X-MServer
X-Tb
Accept-Language
X-S
Access-Control-Request-Headers
X-URL
X-Say-TTL
X-Say-Cacheable
X-SayCDN-TTL
X-B3-SpanId
X-Uri
X-Geo
X-Cluster-Node
X-CACHE-KEY
X-CDN-Forward
Fastcgi-X-Cache-Version
Hostname
X-Via-CDN
X-A-Ccd
X-Accel-Expires-Debug
X-AIR-PT
X-Application
X-Aed
X-A-Wwc
X-A-Dcw
X-A-Dgt
X-A-Dam
Rendered-Blocks
Content-Style-Type
Cross-Origin-Window-Policy
IsBot
Machine
Content-Script-Type
BehaviorPad-Version
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Arc-Country
AsisCache
MD5-Digest
Meta-Geo-Continent
T-Server
Viewtype
VivaBuild
Apple-News-Services-Host
Rt-Proxy-Cache
Request-EU
Mobile-Detection-Method
Node
Request-Country
X-A
X-D
X-ScT
X-Server-Time
X-Session-Fingerprint
X-SIPLIST1
X-S-Cookie
X-Rojux
X-Processor
X-Region-Sid
X-Request-UUID
X-Rewrite-Enabled
X-SRCache-Key
X-Svr
X-VG-WebServer
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-Unique-Id
X-VG-WebCache
X-Transaction
X-Trv-Group
X-Twitter-Response-Tags
Srv
X-PAYTM-SRV-ID
X-Detected-As
X-UnsetCookies
X-DPWN-IS-SECURE
X-External-Request-Id
X-Destination
X-CF-Lambda-Fn
X-CF-Lambda-Version
Apple-News-Services-Handled
X-Date
X-Connection-Hash
X-G
X-Hl-Ver
X-B-Cookie
X-ARC
Mime-Version
ServerName
User-Cache-Control
X-FW-Version
X-CSRF-TOKEN
X-Service
Server-Host
X-Cache-Info
X-Cache-Bucket
X-Debug-Log
Thinkindot-CacheControl-Type
X-NX-Host
Server-Int
X-Matched-Rule
X-Location
X-Reboot
X-Thinkindot-L3
Thinkindot-CacheControl
X-S-Maxage
Thinkindot-Control
X-Core-Value
X-Debug-Cookies
We-Hiring
Now
Mail-Subject
OT-Force-Account-Verify
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
NtCoent-Length
X-Shopify-Stage
X-B3-Parentspanid
X-Endurance-Cache-Level
X-Alternate-Cache-Key
X-ShardId
X-NC
X-ShopId
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
X-Parent-Response-Time
X-Compress-Hint
X-Cms-Context
X-Debug-Cache-Store
Kp-EeAlive
X-Core-Mission
X-Wikidot-Static-Cache
X-We-Are-Hiring
X-Developers
X-Varnish-Beresp-Grace
X-CUA
X-WebServer
X-Amz-Meta-Cache-Control
X-Wikidot-Backend
X-Clientip
X-CGP
X-Block-Status
X-C
Wxu-Next-Commit
Wxu-Next-Hostname
X-Backend-State
X-Auto-Login
X-Azure-Ref
Wxu-Next-Region
X-Cache-Debug
X-Cache-FS-Status
ServedBy
Served-By
X-App-Name
X-Cdn-Srv
X-Cache-URL
X-Cache-Id
X-WADP-Cache
X-Clara-WADP
X-VG-TLSProxy
X-SVT-ORM-RULES
X-Method
X-Skip-Cache
X-Magnolia-Registration
X-SVT-ORM-VERSION
X-Li-Fabric
X-Li-Pop
X-LI-UUID
X-Old-Content-Length
X-Origin-Date
X-Request-Start
X-Request-URI
X-Scheme
X-SD-PageType
X-Proxy-Upstream
X-Origin-Expires
X-Platform-Server
X-Proxy-Cache-Status
X-Key
X-JWT-State
X-VC-Cache
X-Fastly-Cache
X-Variation
X-Eu-Site
X-Epic-Correlation-Id
X-Distributor
X-VServer
X-Varnish-Beresp-Status
X-Up
X-Gen-Mode
X-TrackingId
X-Irp-Debug
X-Is-Gdpr
X-Hnp-Log
X-Has-Esi
X-Generation-Time
X-Geo-Header
X-GeoIP-City
X-Distil-CS
X-Azure-Ref-OriginShield
X-IN-APIGATEWAYSSL
X-Varnish-Beresp-Ttl
X-Instart-Isnd
IBM-Web2-Location
HA-Ipaddr
X-Hash
X-IN-APIGATEWAY
Ha-Gx-Prefs
Is-Eu
Section-Io-Cache
X-Level-Front-Cache
Memcached
PFcat
RNT-Machine
RNT-Time
SD-X-WS
L
Magicmarker
Gh-Request-Id
X-Generated-On
X-Dispatch
X-Dispatcher-Server
X-7Graus-Varnish-XKeys
X-User
X-Webstats-RespID
Adler-Geo
AKAMAI
Platform
CDCHOST
Esi-Enabled
Fastly-Soc-X-Request-Id
X-Reqid
X-7Graus-Varnish-Cache-Control
W
Countrycode
Web-Mar-Node
Content-Disposition
X-Shopify-Generated-Cart-Token
X-Nc
X-Dc
Cache-Host
X-Sigma-Backend
X-Internal-Host
X-Sucuri-Cache
X-Sigma
X-Server-IP
X-Release
X-Rocket-Build-Number
X-Generated-In
X-Swa-Ws
X-Agile-Age
X-Vdms-Version
X-BBXSRF
X-Policy
X-Bip
X-MSEdge-Flight
X-MSEdge-Features
X-LI-Proto
X-Thanos
X-Agile-Id
True-Client-Country-4JS
X-Agile
X-RateLimit-Limit-Second
Proxy-Connection
Pramga
X-Logging-Id
X-Owner
X-Ms-Version
Heartbleed
X-Ms-Request-Id
X-RateLimit-Remaining-Second
X-Qloud-Router
X-EC-Lua
Cache-Provider
X-Urbn-Context-Path
Cdncip
Cdnsip
X-Urbn-Site-Id
X-Planisys-CDN-Cache
X-AK-Request-ID
X-Planisys-CDN-Rules
X-Developer
X-Planisys-CDN-TTL
X-B3-Spanid
A
Locale
X-ServiceProvider
V-Age
X-Cdn-Forward
X-Cdn-Origin
X-Via-NSCOPI
X-Servername
X-NodeID
X-Sn-Servicetimems
CF-IPCountry
X-RCS-CacheZone
Powered-By-ChinaCache
X-Upstream-Ct
Server-ID
X-Upstream-Ht
X-Source
X-GRACE
X-Device-Os
X-Sucuri-Id
X-ND-Cache
X-Node-Id
GEO-REGION-INFO
Environment
X-Trafficlayer-App-Version
X-Lb-Id
X-Be
X-FPC
X-VHOST
X-SRV
X-Nginx-Cache
X-Newrelic-Synthetics
Geo-Info
X-Servedbyhost
X-Microcachable
Tcn
X-Webkit-CSP
X-TIME
X-Zone
X-Gamma-Serve
X-Tb-Optimization-Total-Bytes-Saved
Locid
X-Req
X-Served-From
Request-Time
Resin-Trace
X-Sucuri-ID
X-Refresh
FNAC-ModuleRouting
X-FORWARDED-FOR
X-Ratelimit-Remaining
X-ECACHE
Memory
X-Instart-Info
X-ElasticPress-Search
X-Pf-Uncompressing
X-Pjax-Url
CF-Cached-On
X-NGENIX-Cache
X-Render-Time
X-Backend-Host
X-VCL-Version
X-DC
X-IPS-LoggedIn
X-COUNTRY
Gannett-Cam-Experience-Id
ProcessTime
Group
X-HTML-Minification-Powered-By
X-Backend-Url
X-Correlation-ID
Amp-Access-Control-Allow-Source-Origin
X-AWS-Id
X-LJ-Flow-ID
Backend-Name
X-Var-Ttl
TTL
X-NU-AKA-ACS-Version
X-VWS-Id
X-CSRF-Token
X-Unique-ID
Geoip-City
Pics-Label
X-Pod
X-GeoIP-Country-Code
Geoip-Latitude
GeoIp-Country-Code
Cf-Ipcountry
N-Cache
XServer
PICS-Label
X-GEO
MIME-Version
Cache-Prefix
REQUESTUUID
GeoIP-Latitude
GeoIP-City
Fly-Request-Id
X-Check-Cacheable
Fly-Cache
M-TraceId
GeoIP-Country-Code
X-Mode
Pagetype
X-Via-SSL
X-Via-Edge
Lfy
X-MP-GENERATED-AT
Ttl
Cdn
X-APP
X-Worker
X-Bc
X-CLOUD-TRACE-CONTEXT
X-ZONE
Ohc-File-Size
X-Fstrz
X-LiteSpeed-Cache-Control
X-Via-Ucdn
X-Ratelimit-Limit
X-Sedo-Request-Id
Ohc-Cache-HIT
X-Cache-Miss-From
X-Vcl-Version
SRV
X-Upstream-HT
X-Upstream-CT
X-Fetched-On
X-Server-W
Host-ID
X-PF-Uncompressing
HitType
Fastly-SIE
Fastly-SWR
X-Rebelmouse-Cache-Control
X-Zipkin-Id
X-Proxied
X-Fastly-Country-Code
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-From
X-Routing-Service
Cache-Cookie-Set-Lfrom
X-HS-Status
X-Rebelmouse-Surrogate-Control
HostName
X-Wa
X-Swift-Error
X-Dynatrace-Js-Agent
X-NGINX-Cache
X-BC
On-Server
X-Cache-Tag
User-Agent
Pragrma
X-Oracle-Dms-Rid
URI
X-Cdn-Request-ID
X-PJAX-URL
X-Dynatrace
X-HostName
X-TH-Server
X-WR-MODIFICATION
X-Aicache-OS
X-ServedByHost
X-Tt-Trace-Tag
Who
X-UPSTREAM-Address
X-GDPR
X-TT-LOGID
Powered-By
X-WA
X-RateLimit-Reset
CACHE
X-Request-Time
Cdn-Request-Time
X-Fastly-Backend-Reqs
X-Edge-Server
CDN
X-BE
X-Edge-O15-RID
Cdn-Host
X-Ua
Dynatrace
Media-Length
X-LAGOON
X-SN
X-LB-ID
X-ABtesting
X-Fpc
X-Varnish-URL
X-Flog
X-Hello
X-Varnish-Cacheable
X-Cf-Powered-By
DataCenter
Debug
X-ServerName
X-Response-By
X-RPS
X-RPM
X-RSL
Is-Session-Tracking
LB
X-Org
X-DW
X-Action
SN
X-DB
X-DI
X-DSS
SS
Get-Access-Time
Server-Id
X-Cache-Ttl
X-Ftr-Cache-Host
FSS-Cache
X-Gen-Id
X-Varnish-Beresp-TTL
FSS-Proxy
X-Protected-By
X-Upstream-Proxy
X-Amzn-Remapped-Date
X-Nananana
XxX-Cache-Status
Processtime
X-Tt-Trace-Host
Cneonction
X-Amzn-Remapped-Connection
Thinkindot-Cache-Type
X-Dw-Trace-Id
SID
X-Request-Url
Warning
RequestId
Product
Application
X-Li-Proto
X-Fastly-Cache-Hits
X-Akamai-ERRuleID
Requestid
X-Akamai-ERPolicy
X-LiteSpeed-Tag
NnCoection