Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-Powered-By
Pragma
CF-Cache-Status
Link
ETag
Expect-CT
Via
CF-RAY
Age
X-Cache
X-XSS-Protection
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-Xss-Protection
X-Cache-Hits
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
P3P
X-UA-Compatible
X-Served-By
CF-Ray
Alt-Svc
X-Varnish
X-Timer
X-Request-Id
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-FRAME-OPTIONS
X-Drupal-Cache
X-Check
X-Adblock-Key
Content-Security-Policy-Report-Only
P3p
X-Cacheable
X-Permitted-Cross-Domain-Policies
X-Generator
X-Cache-Status
X-DNS-Prefetch-Control
X-Ua-Compatible
Timing-Allow-Origin
X-Iinfo
X-Template
X-Language
Status
Upgrade
X-Content-Security-Policy
X-AspNetMvc-Version
X-CDN
X-Request-ID
X-Buckets
Content-Encoding
Access-Control-Expose-Headers
X-Kinja-Server-Push
Access-Control-Max-Age
Keep-Alive
X-Via
X-AH-Environment
X-Envoy-Upstream-Service-Time
X-Drupal-Dynamic-Cache
X-Turbo-Charged-By
X-Cache-Group
X-Pass-Why
X-Ws-Request-Id
X-Backend
X-Age
X-Server
X-Proxy-Cache
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
Xkey
EagleId
X-Page-Speed
Feature-Policy
X-Hacker
X-Server-Powered-By
Request-Context
X-Pingback
Server-Timing
X-Nginx-Cache-Status
X-Swift-SaveTime
X-Swift-CacheTime
Grace
Ali-Swift-Global-Savetime
X-UA-Device
X-Varnish-Cache
X-Amz-Version-Id
Report-To
Cf-Railgun
X-OneAgent-JS-Injection
X-Rq
X-LiteSpeed-Cache
X-Device
X-Origin-Cache
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
CONTENT-SECURITY-POLICY
X-Server-Id
X-Vhost
X-Host
EagleEye-TraceId
X-Backend-Server
NEL
X-Node
X-Response-Time
X-Dispatcher
X-WebKit-CSP
X-Ac
X-Cache-Lookup
X-Origin-Upstream-Status
Surrogate-Control
Request-Id
X-Dns-Prefetch-Control
X-Readtime
X-Application-Context
Fusion-Template-Id
Fusion-Content-Source
Fusion-Content-Id
Fusion-Component-Id
Fusion-Source
Content-Location
X-DataDome
X-Ruxit-JS-Agent
X-ORACLE-DMS-ECID
X-HW
X-ORACLE-DMS-RID
X-Cnection
X-Mod-Pagespeed
X-Country
X-Akam-SW-Version
Edge-Control
Rating
X-Rack-Cache
X-Cloud-Trace-Context
X-Clacks-Overhead
X-Url
RTSS
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Fusion-Deployment-Id
X-FTR-Request-ID
X-Goog-Hash
X-TtlSet
X-Vname
X-PC
X-Country-Code
X-DynaTrace
Allow
X-ASPNET-VERSION
X-Varnish-TTL
Verso
Service-Worker-Allowed
X-GitHub-Request-Id
X-MS-InvokeApp
X-Instart-Request-ID
Accept-CH
X-D2id
X-Kinja-Build
X-Kinja
X-Cdn-Fetch
X-Exp-Id
X-Exp-Variant
X-GoogleNews-Bot
X-Use-Magma
X-Kinja-Revision
X-Kinja-Server
X-Server-Name
Content-MD5
SPRequestGuid
X-Powered-By-Plesk
X-Forwarded-Proto
X-Cached
Pinterest-Generated-By
X-Navigation-Version
Accept-CH-Lifetime
X-Trace
TCN
X-Amz-Server-Side-Encryption
X-Amz-Rid
X-SharePointHealthScore
X-Abt-Application-Version
Public-Key-Pins
X-Fastly-Request-ID
X-Vcap-Request-Id
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
Nginx-Cache
X-MSEdge-Ref
X-Debug
X-Vcache
SPIisLatency
SPRequestDuration
Arr-Disable-Session-Affinity
X-DynaTrace-JS-Agent
X-VARITI-CCR
X-ESI
Charset
X-Accel-Expires
X-Cache-TTL
MS-Author-Via
NR-ENABLED
X-NF-Request-ID
Response
X-Middleton-Display
Pagespeed
Display
X-Middleton-Response
X-B3-TraceId
X-Server-ID
X-Px
X-Sol
X-Content-Type
X-Ttl
Realpath
X-Client-IP
Access-Control-Request-Method
S
Cache-Tag
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Ser
WPE-Backend
X-Id
Edge-Cache-Tag
X-Grace
X-Pinterest-Rid
Pinterest-Version
X-Powered-CMS
X-Shield-Request-Id
X-Jurisdiction
X-Hp-Webp
Front-End-Https
X-Webkit-Csp
X-T
X-Upstream
X-Hits
X-Amz-Meta-S3cmd-Attrs
X-Element-Page-Cache
AR-Request-ID
AR-ATIME
AR-PoweredBy
X-Version
X-Dw-Request-Base-Id
X-Content-Digest
DynaTrace
X-Node-Name
X-TTL
X-Cache-Hit
Mrf-Cache-Status
MRF-Tech
X-Recruiting
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
ServerID
Fastcgi-Cache
AMP-Access-Control-Allow-Source-Origin
X-Mobile-URL
X-Fastcgi-Cache
AR-CACHE
Ar-Sid
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-DC
X-Request-Processing-Time
X-Country-Code-Real
X-Correlation-Id
X-Request-Received
X-FTR-Realm
X-Goog-Storage-Class
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Generation
Server-Node
X-Goog-Metageneration
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Hub-Id
X-Frontend
PB-PID
PB-RID
X-FTR-Expires
X-XRDS-Location
Accept-Ch
TP-L2-Cache
TP-Cache
Powered
Upgrade-Insecure-Requests
X-DIS-Request-ID
X-FastCGI-Cache
X-Ezoic-Cdn
X-Mobile-Rewrite
Arc-Version
X-Shard
X-Forwarded-For
Refresh
X-HS-Combine-CSS
Host-Header
Alternate-Protocol
Server-Name
X-Geo-Country
X-Amzn-Trace-Id
Fastly-Restarts
X-N
X-Request-Handler-Origin-Region
X-Microsite
Accept-Ch-Lifetime
X-Akamai-Edgescape
X-NWS-LOG-UUID
X-Rid
X-Page-Id
X-LB-Cache
X-User-Agent
X-F-Cache
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-FTR-Cache-Host
X-B
X-Logged-In
Backend-Timing
X-ATS-Timestamp
X-Cache-Key
X-Content-Security-Policy-Report-Only
X-Varnish-Age
MicrosoftSharePointTeamServices
X-Aspnetmvc-Version
X-Esi
X-Zen-Fury
X-Kinsta-Cache
Healthy
X-XRDS-LOCATION
X-Revision
X-ORACLE-APMCS-TAG
X-ORACLE-APMCS-REQUEST-ID
X-Via-JSL
X-Cache-Age
X-Origin-Server
X-Varnish-Grace
X-Request-Guid
Paypal-Debug-Id
X-Amzn-Requestid
X-Instance
X-Jobs
X-Varnish-Backend
X-Type
Fastcgi-Useragent
X-Git-Hash
X-Hostname
X-App-Environment
X-B3-Sampled
X-ATG-Version
Section-Io-Cache
X-Signature
X-Amz-Replication-Status
X-TT
X-Tumblr-Pixel
X-B-Cache
X-Tumblr-Pixel-0
X-Tumblr-User
X-Seen-By
Actual-Object-TTL
X-AOL-HN
Host
X-Cache-Action
X-Debug-Info
X-WebKit-CSP-Report-Only
X-FB-Debug
X-Whom
Frame-Options
X-Cluster
Cache-Status
X-Presslabs-Stats
Access-Control-Allow-Method
X-Endurance-Cache-Level
X-Content-Options
X-Contextid
X-Cache-Rule
X-Cache-Operation
Source
X-Host-Name
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Content-Powered-By
Trailer
Tracecode
Accept-Charset
X-Activity-Id
X-AppVersion
DC
X-SERVER
X-Az
X-IPLB-Instance
X-Amz-Apigw-Id
X-FireWall-Port
X-Daa-Tunnel
X-Upgrade-Enabled
X-APP-VERSION
Liferay-Portal
X-Tt-Trace-Host
From-Origin
X-Tt-Trace-Tag
X-RateLimit-Remaining
X-PHP-Backend
NGB
X-Response-Served-From
X-Accel-Buffering
X-Framework
X-WA-Info
X-ProcessESI
X-RemovedCookies
Srv
Retry-After
X-FW-Static
X-FW-Server
X-FW-Type
X-UUID
X-FW-Hash
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-FW-Serve
Payment
X-Is-Bot
Surrogate-Key
X-Tumblr-Pixel-1
X-Rendered-As
X-Tumblr-Pixel-2
X-Region
Eomportal-Instance
Filters
X-Adobe-Content
X-GeoIP
X-L-Path
X-Wix-Request-Id
X-RequestSource
X-Environment-Context
X-Cacheable-TTL
X-Time-Microsecs
X-Adobe-Loc
X-Varnish-Server
X-Cache-NE
X-Mobile
X-B3-Traceid
X-Handled-By
X-UA-Device-Type
X-Proxy
X-Unique-Id
X-NGENIX-Cache
X-TIME
X-Origin-Response-Time
Filterid
X-CST
X-Varnish-Hostname
X-Cache-Server
X-Cached-By
X-Cache-Control
X-Cache-TTL-Remaining
X-URL
Datacenter
X-EdgeConnect-Cache-Status
X-Cache-Time
GEO-INFO
X-Webkit-CSP
X-Akamai-Transformed
Xserver
MS-CV
X-Backend-Name
X-Srv
Odigeo-Trace-Id
X-Mode
X-Rule
Version
X-Litespeed-Cache
Cache-Tags
X-Status
S-Cnection
X-Yottaa-Metrics
Cache-Tv-Group
X-FW-Dynamic
X-Yottaa-Optimizations
X-Cache-Var
X-Cache-Var-Map
X-ES-SERVER
X-Path-Route
X-IP
X-CCM
Meta-Geo
X-Pinterest-Direct
Server-Info
Azure-SlotName
Azure-Version
Country
X-Amzn-Remapped-Content-Length
X-MP-GENERATED-AT
Azure-SiteName
Webserver
X-RN-RSRV
DB-Nickname
S-Rt
X-Cache-Enabled
Azure-RegionName
Ec-Rule-Version
X-Cache-2
Azure-InstanceId
X-Akamai-Request-ID2
X-Adobe-Source
X-Detected-As
Cross-Origin-Window-Policy
X-Cache-NGX
TWC-Privacy
TWC-Device-Class
TWC-Connection-Speed
ServedBy
NGX
TWC-GeoIP-Country
TWC-GeoIP-LatLong
Webcakes-App-Version
Webcakes-App-Name
X-FC-Vary-Parameters
TWC-Locale-Group
Webcakes-Region
X-Human
X-TNCMS
X-TX-ID
X-SayCDN-TTL
X-Say-TTL
X-Say-Cacheable
Akamai-GRN
X-Web-Node
X-Via-Fastly
X-Pubstack
X-PERF
X-ApacheServer
Node
X-Redis-Cache
X-Loop
Property-Id
X-Forwarded-Host
X-Real-IP
Content-Disposition
X-Origin-Hint
X-R9-Blue-Green-Version
Cache-Hits
Now
Decoy-Debug-Key
Decoy-Debug-TTL
Cache-Key
Decoy-Debug-Status
Cleartype
X-AWS-Id
X-Origin
X-NYM-Debug-Backend
X-No-Session
X-NCache
X-RCS-CacheZone
X-Section
X-Site-Version
X-Locale
X-VWS-Id
X-Ua-Device
X-Hl-Ver
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
X-Access
X-Cache-Config
X-Format
X-Device-Type
X-Cache-Status-Check
Section-Io-Id
X-LJ-Flow-ID
X-Proxy-Cache-Status
X-Proxy-Build
X-ProxyCache-Key
X-ProxyCache-Status
X-ServerID
X-Hosted-By
X-Goog-Meta-Goog-Reserved-File-Mtime
X-HTML-Minification-Powered-By
X-BYPASS-REASON
X-EIG-Tracking-Id
X-FB-TRIP-ID
X-ShardId
X-ShopId
X-Proxied
Origin-Edge-Control
X-Routing-Service
X-Zipkin-Id
X-Www-Served-By
Origin-Cache-Control
X-Xfnlog-Site
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
Access-Control-Request-Headers
X-Alternate-Cache-Key
X-Timing-Wait
X-Microcachable
Mn-Server-Ip
Selected-Fe
OT-Force-Account-Verify
X-Content-Age
X-Dc
X-Shopify-Generated-Cart-Token
X-Vgn-Hpd-Reason
X-Viewer-Country
X-BCube-Filmed-By
X-Debug-Cache
X-Generated
X-Tb
X-SaId
X-Proto
X-JoinUs
X-Soup
X-Backend-TTL
X-Request-Time
X-EC-Lua
X-Cdn
X-Cache-Remote
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-From
X-Oss-Storage-Class
X-Oss-Object-Type
X-Oss-Request-Id
X-Drupal-Cache-Tags
Accept-Language
Cf-Ipcountry
X-Akamai-Request-ID
X-Generated-By
X-CF-Powered-By
Time
Nel
X-Varnish-Hits
X-Pad
X-NewRelic-App-Data
X-COUNTRY
X-MCACHE
X-Edge
X-RateLimit-Limit
X-NC
X-Old-Content-Length
X-VCT
X-Azure-Ref
X-IPS-LoggedIn
X-ECACHE
X-Source
X-Cache-Grace
X-VCache
Uber-Trace-Id
Cache-Name
X-CS
Ms-Operation-Id
X-NWS-UUID-VERIFY
X-RTag
X-Geo
X-UA
X-FORWARDED-FOR
FilterID
X-Ruxit-Js-Agent
X-PressLabs-Stats
X-Mid
X-Uri
X-GoCache-CacheStatus
User-Agent
Cache
X-OCL
X-PCL
Proxy-Connection
X-APP
X-Magnolia-Registration
X-Qloud-Router
X-Drupal-Cache-Contexts
X-Edge-Location
X-Nginx-Cache
X-FW-Version
X-Labrador-Cache-Channel
X-PHP-Host
X-Varnish-Cache-Hits
X-CDN-Forward
X-Info
X-Tumblr-Pixel-3
X-Amzn-RequestId
Viewtype
X-Connection-Hash
X-Destination
X-Processor
X-DPWN-IS-SECURE
X-Session-Fingerprint
True-Client-Country-4JS
X-Developer
X-D
X-Date
X-Accel-Expires-Debug
X-Aed
X-Rocket-Nginx-Bypass
X-Is-Gdpr
X-Trv-Group
AsisCache
User-Cache-Control
Apple-News-Services-Request-Url
X-B-Cookie
Arc-Country
X-Twitter-Response-Tags
BehaviorPad-Version
Apple-News-Services-Parsed-Url
VivaBuild
X-CF-Lambda-Fn
X-Application
X-ScT
X-A-Dam
X-A-Ccd
X-A
X-CF-Lambda-Version
Fastcgi-X-Cache-Version
X-VG-WebCache
Meta-Geo-Continent
Apple-News-Services-Host
X-S
Mobile-Detection-Method
X-PAYTM-SRV-ID
X-Region-Sid
Apple-News-Services-Handled
X-Request-URI
X-Rojux
X-Has-Esi
X-Vtex-Processado-Em
Machine
X-Request-UUID
X-JWT-State
X-Vtex-Remote-Cache
Xc-Version
X-VG-WebServer
MD5-Digest
X-Transaction
X-A-Dcw
X-SRCache-Key
Countrycode
X-External-Request-Id
X-G
ServerName
X-Instart-Info
X-ARC
X-Reboot
X-Newrelic-Synthetics
T-Server
X-S-Cookie
X-A-Wwc
X-Geo-Header
X-GeoIP-Country-Code
Rendered-Blocks
X-Vdms-Version
X-Rewrite-Enabled
Request-Country
X-A-Dgt
GEO-REGION-INFO
Request-EU
X-UnsetCookies
X-Sucuri-ID
Thinkindot-CacheControl-Type
Server-Cache-Control
On-Server
N-Cache
Memcached
Server-Host
Server-Surrogate-Control
Vix-Hermes-Req-Id
Viewport
Thinkindot-Control
Thinkindot-CacheControl
Web-Mar-Node
X-Cms-Context
X-Hnp-Log
X-Varnish-Authentication
X-Generation-Time
Locale
X-Urbn-Site-Id
X-Gen-Mode
X-Servername
X-Sn-Servicetimems
X-VG-TLSProxy
AKAMAI
X-VServer
X-Server-W
X-Thinkindot-L3
X-Request-Host
X-Matched-Rule
X-Generated-On
X-Level-Front-Cache
X-Cache-ASPX
X-Cache-Bucket
X-Cdn-Origin
X-Block-Status
X-Bc-Bl
X-Backend-Host
X-Backend-State
X-ServiceProvider
X-Cdn-Srv
X-Served-From
X-Urbn-Context-Path
X-DevSite-Last-Modified
X-Developers
X-Contensis-Viewer-Groups
X-Core-Value
X-Auto-Login
SD-X-WS
Cache-Cookie-Set-From
X-Oneagent-Js-Injection
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
Content-Style-Type
Gh-Request-Id
Heartbleed
X-Hyper-Cache
Content-Script-Type
X-Cluster-Node
X-S-Maxage
X-Cluster-Name
X-Device-Os
X-NodeID
X-Distil-CS
X-Ms-Version
X-Ms-Request-Id
X-Fmm-Version
X-Fastly-Cache
X-Logging-Id
X-Micro-Cache
X-Trafficlayer-App-Version
X-Slack-Backend
X-Cache-Info
X-Cache-PHP
X-C
X-TT-TIMESTAMP
X-BBXSRF
X-Scheme
X-Cache-URL
X-Trace-Id
X-Swa-Ws
X-CUA
X-Trafficlayer-App-Scope
X-Clientip
X-Clara-WADP
X-Skip-Cache
X-IN-APIGATEWAY
X-Rocket-Build-Number
X-Storage
X-Webstats-RespID
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Req
X-TrackingId
X-WebServer
X-SN
X-Sigma-Backend
X-SIPLIST1
X-Sigma
X-WADP-Cache
X-We-Are-Hiring
IsBot
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Li-Fabric
X-Li-Pop
X-LAGOON
X-IN-APIGATEWAYSSL
X-Dispatch
X-Vdms-Path
X-LI-Proto
X-LI-UUID
X-Agile-Age
X-Agile
X-Agile-Id
X-Bip
X-Trafficlayer-App-Name
X-Nginx-Cache-Key
X-Gamma-Serve
X-Thanos
FNAC-ModuleRouting
Wxu-Next-Region
Adler-Geo
Group
X-Var-Ttl
CDCHOST
Wxu-Next-Hostname
W
We-Hiring
Cache-Host
X-Variation
Wxu-Next-Commit
Platform
Fastly-SIE
Rt-Fastcgi-Cache
Fastly-SWR
X-VC-Cache
Locid
X-App-Name
Kp-EeAlive
Is-Eu
RNT-Machine
Mail-Subject
RNT-Time
X-Varnish-Cacheable
V-Age
X-Dispatcher-Server
X-Distributor
X-Cache-FS-Status
Country-Code
Proxy-Firewall
X-Fetched-On
X-Generated-In
X-Irp-Debug
X-GeoIP-City
X-Hash
Server-ID
Request-Time
X-Eu-Site
Fastly-Drupal-HTML
X-Owner
X-Epic-Correlation-Id
X-Proxy-Upstream
X-CGP
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
Ha-Gx-Prefs
X-Cache-Tags
NM-Fastcgi-Cache
X-Response-By
X-Core-Mission
X-Origin-Expires
X-Origin-Date
L5d-Success-Class
HA-Ipaddr
X-Platform-Server
X-B3-Spanid
Server-Ext
Server-Hostname
Sever-Int
X-Refresh
CF-Cached-On
X-Hit
X-CSRF-Token
A
X-App-Server
X-NX-Host
M-TraceId
X-SS-Set-Cookie
X-RESPONSE-TIME
X-Varnish-Beresp-Status
X-Debug-Log
X-Debug-Cookies
Pagetype
X-Varnish-Beresp-Grace
X-Protected-By
X-Cache-Expired-At
X-Debug-Cache-Expiry
X-OVcl
X-Method
X-GEO
X-CLOUD-TRACE-CONTEXT
X-OVcl-Cache
X-Instart-Isnd
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Node-Id
HostName
X-TA-CDN-Provider
XServer
X-Parent-Response-Time
X-FPC
X-Varnish-Beresp-Ttl
X-Varnish-URL
X-Worker
Mime-Version
PFcat
X-Nc
X-Via-PopH
Magicmarker
X-Branch-Name
X-Wa
X-Via-PopV
X-MSEdge-Features
Origin
X-MSEdge-Flight
X-Request-Start
X-Time
X-SRV
X-Be
X-Varnish-Ttl
Geo-Info
X-Envoy-Upstream-Healthchecked-Cluster
Geoip-City
Geoip-Latitude
PICS-Label
X-Policy
X-CACHE-KEY
GeoIp-Country-Code
Powered-By-ChinaCache
Memory
Pramga
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Lb-Id
Esi-Enabled
X-Planisys-CDN-Cache
X-Ratelimit-Remaining
X-Load-Cache
X-Service
X-C-Zone
Cloudfront-Viewer-Country
Who
X-ND-Cache
X-C-Key
X-SERVER-NAME
HitType
X-BACKEND-TTL
X-Pjax-Url
X-HS-Status
X-Via-Ucdn
X-Reqid
Cteonnt-Length
X-Country-IP
Dt-Cache-Category
Environment
X-Servedbyhost
X-ECache
X-Wix-Viewer-Type
X-VCL-Version
X-Myra-Origin2
X-Newrelic-App-Data
X-Azure-Ref-OriginShield
X-Ua
X-Tec-Api-Root
X-Tec-Api-Version
X-Cdn-Forward
X-DC
X-Tec-Api-Origin
X-ZONE
TTL
X-Zone
X-BC
Product
UCS
X-Bc
X-CSRF-TOKEN
X-Referer
Ttl
X-Correlation-ID
NtCoent-Length
X-Cache-Metadata
X-Up
Fastly-Backend-Name
SRV
X-Vcl-Version
X-Origin-CC
X-Cache-Host
X-Origin-TTL
Resin-Trace
X-NGINX-Cache
X-Ratelimit-Limit
X-Server-Time
Pragrma
X-Swift-Error
Release
X-TT-LOGID
X-ServedByHost
X-Pf-Uncompressing
X-Server-IP
X-Fastly-Country-Code
FSS-Cache
Cdn
X-App-Version
X-PJAX-URL
Cdn-Host
C-Via
Cdn-Request-Time
Hostname
X-Edge-Server
CACHE
LB
X-AIR-PT
Cdnsip
X-AK-Request-ID
Cdncip
X-Cache-Backend
Lb
GeoIP-Country-Code
X-Node-ID
Sid
X-NU-AKA-ACS-Version
Load-Balancing
X-SVT-ORM-RULES
X-Location
X-SVT-ORM-VERSION
X-UPSTREAM-Address
My-App
X-WPE-Loopback-Upstream-Addr
GeoIP-City
X-Configured-By
Warning
GeoIP-Latitude
MIME-Version
X-Fastly-Backend-Reqs
X-Air-Hostname
X-Sucuri-Cache
X-WA
Dnion-Transfer-Encoding
X-BE
Ohc-File-Size
X-Mvc-Supplant-Cachable
X-RAMCache
X-Tb-Optimization-Total-Bytes-Saved
X-Varnish-Beresp-TTL
X-Cache-Id
X-Powered-Y
X-Svr
X-Gzip
X-Esi-Check
Fastly-SSL
X-Fpc
Ohc-Cache-HIT
X-Cache-Debug
CDN
Lfy
RequestId
X-Varnish-Url
X-Mvc-Supplant-OutputCached
X-User
X-TH-Server
X-VarnishDD-TTL
X-Fastly-Request-Id
X-LiteSpeed-Cache-Control
Pics-Label
X-Amzn-Remapped-Date
X-MID
IBM-Web2-Location
X-B3-SpanId
X-Amzn-Remapped-Connection
Processtime
X-Apw-Access-Object
X-Apw-Access-Token
X-SD-PageType
X-Apw-Access-Action
X-Apw-Hits
X-Unique-ID
X-B3-Parentspanid
Cneonction
X-ElasticPress-Query
Host-ID
X-ElasticPress-Search
DSUID
X-Flow-Id
X-Zalando-Child-Request-Id
Requestid
X-Agile-Brick-Ok
Xet-Cookie
X-Page-Impression-Id
CF-IPCountry
X-RPM
X-DW
X-DSS
X-DB
X-Via-NSCOPI
X-Check-Cacheable
L
X-Compress-Hint
X-DI
X-Debug-Revision
X-RPS
X-Aicache-OS
X-Ocache
Server-Int
X-RSL
X-Debug-Controller
X-Sucuri-Id
X-App
X-Action
WZWS-RAY
ProcessTime
X-Envoy-Decorator-Operation
X-Fastly-Cache-Hits
CloudFront-Viewer-Country
URI
X-Request-URL
X-Edge-O15-RID
X-LB-ID
X-MiniProfiler-Ids
X-Dw-Trace-Id
X-Nananana
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-Request-Url
X-Cache-Tag
Powered-By
DataCenter