Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
CF-Cache-Status
Pragma
Link
CF-RAY
X-Powered-By
ETag
Expect-CT
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Xss-Protection
X-Varnish
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
Alt-Svc
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-FRAME-OPTIONS
X-Drupal-Cache
X-Adblock-Key
X-Request-ID
X-Check
X-Generator
Content-Security-Policy-Report-Only
X-Cache-Status
X-Permitted-Cross-Domain-Policies
X-Cacheable
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Iinfo
X-Template
X-Language
X-AspNetMvc-Version
Status
X-Content-Security-Policy
X-Buckets
Content-Encoding
Access-Control-Expose-Headers
X-CDN
Upgrade
Xkey
Access-Control-Max-Age
X-Drupal-Dynamic-Cache
Keep-Alive
X-Kinja-Server-Push
CF-Ray
X-Turbo-Charged-By
X-AH-Environment
X-Ua-Compatible
X-Age
X-Cache-Group
X-Via
X-Pass-Why
X-Backend
X-Envoy-Upstream-Service-Time
EagleId
X-Server
X-Robots-Tag
X-Amz-Request-Id
X-Amz-Id-2
X-Server-Powered-By
X-Pingback
X-Page-Speed
X-UA-Device
X-Proxy-Cache
X-Swift-SaveTime
X-Swift-CacheTime
X-Hacker
X-Nginx-Cache-Status
Request-Context
Ali-Swift-Global-Savetime
X-Varnish-Cache
Grace
Server-Timing
Feature-Policy
Cf-Railgun
X-Amz-Version-Id
X-LiteSpeed-Cache
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
X-Server-Id
X-Rq
Report-To
X-WebKit-CSP
X-Dns-Prefetch-Control
EagleEye-TraceId
X-Ws-Request-Id
X-Host
X-Response-Time
X-Ac
Request-Id
X-Cnection
X-OneAgent-JS-Injection
X-Backend-Server
Content-Location
X-DataDome
X-Origin-Cache
X-Node
X-Cache-Lookup
NEL
X-Readtime
X-Cloud-Trace-Context
X-Vhost
P3p
X-HW
X-Dispatcher
X-Application-Context
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Cdn
Allow
X-Clacks-Overhead
Surrogate-Control
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Rack-Cache
X-Origin-Upstream-Status
X-DynaTrace
Rating
X-Country
Fusion-Template-Id
Fusion-Source
Fusion-Content-Source
Fusion-Component-Id
Fusion-Content-Id
X-Akam-SW-Version
X-FTR-Request-ID
X-Country-Code
X-Goog-Hash
X-Varnish-TTL
Pinterest-Generated-By
X-Instart-Request-ID
Edge-Control
X-Vname
X-TtlSet
X-PC
X-B3-TraceId
X-Mod-Pagespeed
X-Url
X-Ruxit-JS-Agent
Accept-Ch
X-MS-InvokeApp
Verso
SPRequestGuid
X-Powered-By-Plesk
X-D2id
X-Trace
X-ESI
X-VARITI-CCR
X-Server-Name
X-GitHub-Request-Id
Service-Worker-Allowed
X-SharePointHealthScore
Content-MD5
Response
Pagespeed
X-Sol
X-Middleton-Response
X-Cdn-Fetch
X-Kinja-Build
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Kinja
X-GoogleNews-Bot
X-Exp-Variant
X-Exp-Id
X-Middleton-Display
Display
RTSS
X-TTL
X-Navigation-Version
Accept-Ch-Lifetime
SPIisLatency
SPRequestDuration
X-Vcache
X-Abt-Application-Version
X-Powered-CMS
X-Debug
X-Forwarded-Proto
X-Upstream
X-Cached
X-Amz-Server-Side-Encryption
X-Vcap-Request-Id
Public-Key-Pins
X-CST
Charset
MS-Author-Via
DynaTrace
X-Version
X-NF-Request-ID
X-Amz-Rid
Realpath
Edge-Cache-Tag
X-Px
X-DynaTrace-JS-Agent
MicrosoftSharePointTeamServices
Arr-Disable-Session-Affinity
X-Shard
X-Trafficlayer-App-Scope
X-Trafficlayer-App-Name
X-Ezoic-Cdn
X-Shield-Request-Id
X-MSEdge-Ref
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Ser
Pinterest-Version
Access-Control-Request-Method
X-Pinterest-Rid
TCN
X-Fastly-Request-ID
S
X-Accel-Expires
X-TEC-API-VERSION
Fastly-Restarts
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-DIS-Request-ID
X-Client-IP
X-Goog-Stored-Content-Length
Front-End-Https
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-XRDS-Location
X-Webapp-Samesite-None-Activated-N
X-Amz-Meta-S3cmd-Attrs
X-Recruiting
X-Id
X-T
X-Element-Page-Cache
X-Varnish-Age
X-Goog-Storage-Class
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-Realm
X-FTR-DC
X-FTR-Cache-Status
Cache-Tag
X-Country-Code-Real
X-FTR-Backend
X-Amzn-Trace-Id
X-Mrf-Item-Lastmod
MRF-Tech
X-B3-TraceId-Primal
X-Mrf-Section-Lastmod
Mrf-Cache-Status
Nginx-Cache
X-Server-ID
X-Dw-Request-Base-Id
X-FTR-Expires
X-Webkit-Csp
Fastcgi-Cache
X-Fastcgi-Cache
X-Content-Digest
X-HS-Hub-Id
X-HS-Cache-Config
X-Frontend
X-HS-Content-Id
NR-ENABLED
Powered
X-Ttl
X-Hits
X-Correlation-Id
X-Hp-Webp
Alternate-Protocol
X-Kinsta-Cache
X-Oneagent-Js-Injection
X-FTR-Cache-Host
X-Aspnetmvc-Version
X-Request-Received
X-Request-Processing-Time
X-Content-Type
Server-Name
X-RateLimit-Remaining
ServerID
X-N
X-HS-Combine-CSS
X-Microsite
X-Request-Handler-Origin-Region
TP-Cache
X-Cache-Hit
PB-PID
TP-L2-Cache
PB-RID
X-Grace
X-Mobile-Rewrite
Arc-Version
X-Rid
X-Akamai-Edgescape
Healthy
X-User-Agent
Backend-Timing
X-Revision
X-Analytics
X-Node-Name
X-Ruxit-Js-Agent
X-Forwarded-For
X-Content-Security-Policy-Report-Only
X-Logged-In
X-Zen-Fury
X-Pad
AMP-Access-Control-Allow-Source-Origin
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Mobile-URL
X-LB-Cache
Server-Node
X-Varnish-Grace
X-AppVersion
X-Activity-Id
X-Az
X-Cached-By
Cache-Status
X-B3-Sampled
X-Content-Options
X-NWS-LOG-UUID
X-GUploader-UploadID
Refresh
X-F-Cache
X-Geo-Country
X-IPLB-Instance
Upgrade-Insecure-Requests
X-Type
Retry-After
X-Varnish-Backend
FilterID
X-FastCGI-Cache
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-User
X-App-Environment
Host
Paypal-Debug-Id
X-Srv
X-Cache-2
Accept-Charset
X-Jobs
X-FB-Debug
Actual-Object-TTL
X-AOL-HN
DC
X-B
X-Cluster
X-Framework
X-Page-Id
X-PHP-Backend
X-Instance
X-Request-Guid
X-Debug-Info
Accept-CH-Lifetime
Source
Access-Control-Allow-Method
X-WebKit-CSP-Report-Only
Accept-CH
AR-PoweredBy
AR-CACHE
AR-ATIME
X-ATG-Version
Cache
X-Cache-Key
X-TT
X-Cache-Age
X-Erf-Bev-Bev
X-Seen-By
X-Erf-Bev-Bev-Is-Generated
Fastcgi-Useragent
X-PressLabs-Stats
MS-CV
X-Git-Hash
X-Content-Powered-By
X-Via-JSL
Ar-Sid
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Cache-TTL
Host-Header
X-Signature
X-Amz-Replication-Status
X-B-Cache
X-TA-CDN-Provider
X-Whom
X-Cache-Control
X-Origin-Server
X-Wix-Request-Id
X-Cache-Enabled
NGB
X-Response-Served-From
X-Daa-Tunnel
Xserver
Surrogate-Key
X-UA
X-Mobile
X-ATS-Timestamp
X-RequestSource
X-GeoIP
Cache-Tv-Group
X-Tumblr-Pixel-1
X-Host-Name
X-Tumblr-Pixel-2
Datacenter
X-Hyper-Cache
X-FW-Server
X-Cache-NE
WPE-Backend
Payment
Filters
X-Cacheable-TTL
X-FW-Hash
X-FW-Static
Eomportal-Instance
X-FW-Serve
X-FW-Type
Cleartype
X-Handled-By
X-Litespeed-Cache
X-Adobe-Loc
X-Region
Frame-Options
X-Adobe-Content
X-EdgeConnect-Cache-Status
X-SERVER
X-Cache-Action
X-TX-ID
X-Drupal-Cache-Tags
Webserver
X-Esi
X-Load-Cache
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-XRDS-LOCATION
X-Akamai-Transformed
X-Cache-Operation
AR-Request-ID
X-Cache-Rule
From-Origin
X-NewRelic-App-Data
X-Edge-Location
X-RemovedCookies
X-ProcessESI
X-Cache-TTL-Remaining
X-UA-Device-Type
X-Hostname
Liferay-Portal
Ms-Operation-Id
X-RTag
X-Cache-Server
X-Forwarded-Host
X-Varnish-Hostname
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-ORACLE-APMCS-REQUEST-ID
X-ORACLE-APMCS-TAG
X-Varnish-Server
X-Rule
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Status
Country
X-Contextid
X-Upgrade-Enabled
X-App-Server
Odigeo-Trace-Id
X-UUID
Meta-Geo
X-Cache-Var
X-ES-SERVER
X-Cache-Var-Map
Load-Balancing
X-RN-RSRV
X-BCube-Filmed-By
X-Path-Route
DSUID
X-TT-TIMESTAMP
Webcakes-App-Version
DB-Nickname
Webcakes-App-Name
X-Debug-Cache
X-R9-Blue-Green-Version
X-EIG-Tracking-Id
TWC-Privacy
Webcakes-Region
TWC-GeoIP-LatLong
TWC-Connection-Speed
Property-Id
Release
Mn-Server-Ip
TWC-Device-Class
X-Rocket-Nginx-Bypass
TWC-GeoIP-Country
X-Origin-Hint
TWC-Locale-Group
X-CCM
X-VCT
X-From
X-Origin-Response-Time
X-Akamai-Request-ID
X-Origin
S-Rt
X-Cache-Config
X-Cache-Time
X-Loop
X-OCL
X-Cache-Host
Azure-InstanceId
Azure-RegionName
Cache-Name
Cache-Tags
X-Via-Fastly
X-Pubstack
X-Proxy
X-Proto
Azure-SiteName
Azure-SlotName
Azure-Version
X-Proxy-Build
Fastly-SSL
X-FW-Dynamic
X-Redis-Cache
X-Viewer-Country
X-FireWall-Port
X-Human
X-Vgn-Hpd-Reason
X-PCL
X-IP
Selected-Fe
X-Real-IP
X-FC-Vary-Parameters
Origin-Edge-Control
X-Soup
L5d-Success-Class
X-ServerID
X-TNCMS
X-Drupal-Cache-Contexts
Origin-Cache-Control
X-Timing-Wait
X-Hosted-By
X-Section
Viewport
X-Varnish-Hits
X-Site-Version
X-Web-Node
X-Backend-Name
X-Is-Bot
X-ProxyCache-Key
X-JoinUs
X-Xfnlog-Site
Uber-Trace-Id
X-Rendered-As
X-BYPASS-REASON
X-Format
X-Generated
X-Content-Age
X-Locale
X-Akamai-Request-ID2
X-Access
X-Www-Served-By
X-Labrador-Cache-Channel
X-Cluster-Name
X-ProxyCache-Status
X-Goog-Meta-Goog-Reserved-File-Mtime
NGX
Ec-Rule-Version
X-NWS-UUID-VERIFY
Decoy-Debug-Status
Decoy-Debug-TTL
X-Varnish-Cache-Hits
Server-Info
Decoy-Debug-Key
Version
S-Cnection
X-Accel-Buffering
X-Generated-By
X-Time-Microsecs
X-PHP-Host
Tracecode
X-Time
X-Cache-Backend
X-PERF
X-ApacheServer
X-Info
X-Amzn-Remapped-Content-Length
X-Origin-TTL
X-SaId
X-App-Version
X-Storage
X-Origin-CC
Akamai-GRN
X-Geo
X-VCache
X-URL
Rt-Fastcgi-Cache
X-Nginx-Cache-Key
X-WA-Info
Cteonnt-Length
X-CF-Powered-By
Time
X-Guploader-Uploadid
X-No-Session
X-MServer
Cache-Key
X-Environment-Context
Origin
X-L-Path
X-RateLimit-Limit
X-Cache-Remote
Access-Control-Request-Headers
Accept-Language
X-Tec-Api-Version
X-Tec-Api-Root
X-FB-TRIP-ID
GEO-INFO
X-Tec-Api-Origin
X-Tb
X-Presslabs-Stats
X-GoCache-CacheStatus
X-B3-SpanId
X-NCache
X-Say-TTL
X-SayCDN-TTL
X-Say-Cacheable
Vix-Hermes-Req-Id
Cache-Hits
X-Backend-TTL
X-EC-Lua
X-Hit
X-Unique-Id
X-TIME
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Alternate-Cache-Key
X-ShardId
X-Shopify-Generated-Cart-Token
X-ShopId
X-Trace-Id
X-Shopify-Stage
X-RCS-CacheZone
X-APP-VERSION
X-Source
X-Device-Type
Srv
X-Dc
OT-Force-Account-Verify
Mime-Version
X-CS
X-CDN-Forward
X-Tumblr-Pixel-3
X-S
X-SS-Set-Cookie
X-CACHE-KEY
X-OVcl-Cache
X-OVcl
Node
X-Date
Apple-News-Services-Parsed-Url
X-Vtex-Remote-Cache
User-Cache-Control
Mobile-Detection-Method
X-Processor
X-Destination
Meta-Geo-Continent
X-Vtex-Processado-Em
Apple-News-Services-Request-Url
Request-EU
X-Connection-Hash
Rt-Proxy-Cache
Request-Country
Rendered-Blocks
X-D
Arc-Country
X-Region-Sid
X-Detected-As
Apple-News-Services-Host
Xc-Version
X-G
Content-Script-Type
BehaviorPad-Version
X-Hl-Ver
Fastcgi-X-Cache-Version
Cross-Origin-Window-Policy
Content-Style-Type
X-Magnolia-Registration
X-Trv-Group
X-External-Request-Id
MD5-Digest
Apple-News-Services-Handled
X-Cluster-Node
Machine
X-DPWN-IS-SECURE
AsisCache
IsBot
X-PAYTM-SRV-ID
X-Endurance-Cache-Level
Server-Host
X-Accel-Expires-Debug
X-Svr
X-CF-Lambda-Version
X-Server-Time
VivaBuild
X-A-Dgt
Viewtype
X-ScT
X-A-Wwc
X-A
X-A-Dcw
X-SIPLIST1
X-SRCache-Key
X-A-Dam
X-A-Ccd
X-Service
X-Session-Fingerprint
X-S-Cookie
X-CF-Lambda-Fn
X-Application
X-Rojux
X-Twitter-Response-Tags
X-Request-UUID
X-ARC
X-B-Cookie
T-Server
X-VG-WebServer
X-VG-WebCache
X-Upstream-Ct
X-Ah-Environment
X-Vdms-Version
X-AIR-PT
X-Upstream-Ht
X-Rewrite-Enabled
X-Aed
X-Transaction
X-Parent-Response-Time
ServedBy
ServerName
X-Instart-Isnd
X-Level-Front-Cache
X-IN-APIGATEWAYSSL
X-Dispatcher-Server
X-CUA
Thinkindot-CacheControl-Type
X-Core-Value
Thinkindot-CacheControl
Served-By
Server-Int
Thinkindot-Control
Wxu-Next-Commit
X-Generated-On
X-Hash
X-Cache-Bucket
Wxu-Next-Region
Wxu-Next-Hostname
X-Dispatch
X-IN-APIGATEWAY
X-Location
X-ND-Cache
We-Hiring
X-Via-NSCOPI
X-Nc
X-Webstats-RespID
Now
Mail-Subject
X-Matched-Rule
X-Reboot
X-Thinkindot-L3
X-SRV
Proxy-Connection
X-Uri
NtCoent-Length
X-CSRF-TOKEN
X-Cache-URL
X-Cdn-Srv
X-VG-TLSProxy
X-Rocket-Build-Number
X-S-Maxage
X-Reqid
X-Core-Mission
X-Clientip
X-Cms-Context
X-Compress-Hint
X-Clara-WADP
X-CGP
X-Request-Start
X-VServer
X-Scheme
X-Request-URI
X-VC-Cache
X-Bip
X-Block-Status
X-C
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-BBXSRF
X-B3-Parentspanid
X-TrackingId
X-Thanos
X-Backend-State
X-Up
X-Sucuri-Cache
X-Cache-Debug
X-Server-IP
X-Cache-FS-Status
X-Cache-Info
X-Variation
X-User
X-Skip-Cache
X-Sigma-Backend
X-Sigma
X-SD-PageType
X-RateLimit-Limit-Second
X-Has-Esi
X-GeoIP-City
X-Wikidot-Static-Cache
X-Hnp-Log
X-Origin-Date
X-Geo-Header
X-Generation-Time
X-Fastly-Cache
X-FW-Version
X-Gen-Mode
X-Wikidot-Backend
X-Old-Content-Length
X-NX-Host
X-Key
X-Li-Fabric
X-Li-Pop
X-Logging-Id
X-JWT-State
X-Is-Gdpr
X-Ms-Version
X-Ms-Request-Id
X-Method
X-Irp-Debug
X-Origin-Expires
X-Eu-Site
X-WADP-Cache
X-Debug-Cookies
X-Debug-Log
X-Qloud-Router
X-Proxy-Upstream
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-RateLimit-Remaining-Second
X-LI-UUID
X-Azure-Ref-OriginShield
X-Debug-Cache-Expiry
X-Proxy-Cache-Status
X-Platform-Server
X-Distributor
X-Planisys-CDN-Cache
X-Owner
X-Epic-Correlation-Id
X-Distil-CS
X-Planisys-CDN-Rules
X-We-Are-Hiring
X-Developers
X-Planisys-CDN-TTL
X-WebServer
X-Release
X-App-Name
IBM-Web2-Location
Is-Eu
Heartbleed
HA-Ipaddr
Ha-Gx-Prefs
L
Magicmarker
Pramga
Platform
PFcat
Memcached
Gh-Request-Id
Fastly-Soc-X-Request-Id
X-Azure-Ref
Adler-Geo
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
X-Cache-Grace
AKAMAI
Cache-Host
Esi-Enabled
Countrycode
Content-Disposition
CDCHOST
RNT-Machine
X-Varnish-Beresp-Ttl
Web-Mar-Node
X-Auto-Login
W
X-Agile-Age
X-Agile-Id
X-Amz-Meta-Cache-Control
RNT-Time
Section-Io-Cache
X-Agile
SD-X-WS
Cache-Provider
X-LI-Proto
Server-ID
X-Policy
X-Internal-Host
X-Trafficlayer-App-Version
X-Generated-In
Kp-EeAlive
X-Swa-Ws
X-Cache-Id
X-Via-CDN
X-Cdn-Forward
Powered-By-ChinaCache
X-MSEdge-Features
Cdncip
X-NodeID
X-MSEdge-Flight
X-AK-Request-ID
X-Urbn-Context-Path
Tcn
X-Urbn-Site-Id
Cdnsip
X-ServiceProvider
V-Age
Locale
True-Client-Country-4JS
Environment
Locid
X-B3-Traceid
X-Served-From
X-Req
X-NC
X-HTML-Minification-Powered-By
X-Sucuri-Id
X-GRACE
X-Servername
X-Lb-Id
X-Newrelic-Synthetics
FNAC-ModuleRouting
GEO-REGION-INFO
X-Gamma-Serve
X-Be
X-UnsetCookies
X-Nginx-Cache
X-B3-Spanid
Hostname
X-Refresh
X-FPC
CF-IPCountry
Geo-Info
X-7Graus-Varnish-Cache-Control
X-7Graus-Varnish-XKeys
X-IPS-LoggedIn
X-Render-Time
X-VHOST
X-Zone
ProcessTime
X-NU-AKA-ACS-Version
A
X-Developer
X-Tb-Optimization-Total-Bytes-Saved
X-Edge-O15-RID
X-Webkit-CSP
X-Mode
X-MP-GENERATED-AT
X-GeoIP-Country-Code
X-Device-Os
X-Cdn-Origin
X-Servedbyhost
X-Sn-Servicetimems
X-Microcachable
X-Sucuri-ID
X-Node-Id
X-Pjax-Url
X-Ratelimit-Remaining
Memory
X-VWS-Id
X-AWS-Id
X-FORWARDED-FOR
X-LJ-Flow-ID
X-Pf-Uncompressing
X-Proxied
X-Routing-Service
X-Zipkin-Id
Request-Time
X-COUNTRY
Gannett-Cam-Experience-Id
X-CSRF-Token
TTL
X-Correlation-ID
Cf-Ipcountry
Pics-Label
Amp-Access-Control-Allow-Source-Origin
X-DC
GeoIp-Country-Code
Geoip-Latitude
X-Bc
X-Unique-ID
CF-Cached-On
X-VCL-Version
X-Pod
Cache-Cookie-Set-From
Resin-Trace
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
X-Vcl-Version
Group
GeoIP-Country-Code
PICS-Label
M-TraceId
Cdn
X-Via-SSL
GeoIP-Latitude
X-Via-Edge
GeoIP-City
X-ZONE
HostName
X-Ratelimit-Limit
X-Request-Time
X-Instart-Info
X-Cdn-Request-ID
Geoip-City
X-NODE
X-ElasticPress-Search
X-Swift-Error
X-ECACHE
Host-ID
XServer
X-CLOUD-TRACE-CONTEXT
MIME-Version
X-Backend-Url
Ttl
X-TH-Server
X-Backend-Host
X-Var-Ttl
X-APP
X-BC
X-Check-Cacheable
Backend-Name
HitType
X-PF-Uncompressing
Ohc-Cache-HIT
Ohc-File-Size
X-HostName
X-NGINX-Cache
REQUESTUUID
Lfy
Powered-By
Pagetype
N-Cache
URI
X-NGENIX-Cache
X-UPSTREAM-Address
Fly-Cache
Fly-Request-Id
Media-Length
Cache-Prefix
X-PJAX-URL
X-ServedByHost
On-Server
User-Agent
X-Fastly-Country-Code
X-Fstrz
X-Via-Ucdn
X-Worker
X-Tt-Trace-Tag
X-Cache-Tag
X-WR-MODIFICATION
X-Aicache-OS
SRV
X-LiteSpeed-Cache-Control
X-Fetched-On
X-Tt-Trace-Host
X-Sedo-Request-Id
X-Hp-Ccpa-Warning
Who
FSS-Proxy
X-Cache-Miss-From
FSS-Cache
Pragrma
CDN
X-HS-Status
X-WA
AR-SID
X-BE
X-Server-W
UCS
X-NYM-Debug-Backend
X-Varnish-URL
Processtime
X-LAGOON
X-Varnish-Cacheable
X-Rebelmouse-Surrogate-Control
X-LB-ID
X-GEO
X-Wa
Fastly-SWR
X-Rebelmouse-Cache-Control
Fastly-SIE
X-Fpc
X-ServerName
X-Cache-Tags
X-Cf-Powered-By
Server-Cache-Control
X-Contensis-Viewer-Groups
X-Varnish-Authentication
X-Cache-ASPX
Server-Surrogate-Control
X-Upstream-CT
X-Upstream-HT
Debug
X-Store
X-Fastly-Backend-Reqs
X-Ua
X-Ftr-Cache-Host
X-Apw-Access-Action
X-Apw-Access-Token
X-Apw-Hits
Fastly-Backend-Name
Country-Code
Location
X-Apw-Access-Object
X-Akamai-ERPolicy
X-TT-LOGID
X-Protected-By
X-Varnish-Beresp-TTL
X-Akamai-ERRuleID
X-BACKEND-TTL
Server-Id
X-Li-Proto
X-Amzn-Remapped-Connection
SID
Thinkindot-Cache-Type
X-Amzn-Remapped-Date
XxX-Cache-Status
X-GDPR
X-Dw-Trace-Id
X-Gen-Id
X-Fastly-Cache-Hits
X-VC
X-SB
NnCoection
Product
Xet-Cookie
WP-Super-Cache
Cneonction
Application
X-Nananana
X-Request-Url