Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
CF-RAY
CF-Cache-Status
Pragma
Link
X-Powered-By
ETag
Expect-CT
Via
X-XSS-Protection
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Xss-Protection
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
Alt-Svc
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Request-ID
Content-Security-Policy-Report-Only
X-Generator
X-Cache-Status
X-Cacheable
X-Permitted-Cross-Domain-Policies
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Template
X-Iinfo
X-Language
X-AspNetMvc-Version
X-Content-Security-Policy
Status
X-Buckets
Content-Encoding
Access-Control-Expose-Headers
Upgrade
X-CDN
Xkey
X-Kinja-Server-Push
Access-Control-Max-Age
Keep-Alive
X-Drupal-Dynamic-Cache
X-Turbo-Charged-By
X-Via
X-Ua-Compatible
X-Cache-Group
X-Age
X-Pass-Why
X-Envoy-Upstream-Service-Time
X-Backend
EagleId
X-AH-Environment
X-Server
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Page-Speed
X-Pingback
X-Server-Powered-By
X-UA-Device
X-Swift-SaveTime
X-Swift-CacheTime
X-Proxy-Cache
X-Hacker
Ali-Swift-Global-Savetime
X-Nginx-Cache-Status
Request-Context
Grace
X-Varnish-Cache
Server-Timing
Feature-Policy
Cf-Railgun
X-Amz-Version-Id
X-Device
X-LiteSpeed-Cache
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Rq
X-WebKit-CSP
Report-To
X-Ac
EagleEye-TraceId
X-Response-Time
X-Server-Id
X-Host
Request-Id
X-Cnection
X-Backend-Server
X-OneAgent-JS-Injection
X-DataDome
Content-Location
X-Node
X-Cloud-Trace-Context
X-Dns-Prefetch-Control
X-Origin-Cache
X-Readtime
X-Cache-Lookup
NEL
X-Vhost
X-Application-Context
X-Dispatcher
X-ORACLE-DMS-ECID
X-HW
X-Cdn
Allow
X-ORACLE-DMS-RID
X-Clacks-Overhead
X-Ws-Request-Id
X-Rack-Cache
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Origin-Upstream-Status
Surrogate-Control
X-Country
Rating
X-DynaTrace
X-FTR-Request-ID
X-Country-Code
X-Goog-Hash
Fusion-Content-Id
Fusion-Source
Fusion-Component-Id
Fusion-Content-Source
Fusion-Template-Id
X-Akam-SW-Version
Pinterest-Generated-By
X-Varnish-TTL
X-PC
X-TtlSet
X-Vname
X-Instart-Request-ID
X-MS-InvokeApp
X-Url
Edge-Control
X-Ruxit-JS-Agent
Accept-Ch
Verso
X-Mod-Pagespeed
X-Powered-By-Plesk
SPRequestGuid
X-B3-TraceId
X-D2id
X-Trace
Response
X-Sol
X-Middleton-Response
Pagespeed
Display
X-Middleton-Display
X-SharePointHealthScore
X-VARITI-CCR
RTSS
X-Kinja
X-Kinja-Build
X-GoogleNews-Bot
X-Exp-Variant
X-Kinja-Revision
X-Cdn-Fetch
X-Exp-Id
X-Use-Magma
X-Kinja-Server
Service-Worker-Allowed
X-Server-ID
X-Server-Name
X-GitHub-Request-Id
X-ESI
SPRequestDuration
SPIisLatency
X-Vcache
X-Navigation-Version
Accept-Ch-Lifetime
X-Powered-CMS
Content-MD5
X-Debug
X-Abt-Application-Version
X-Vcap-Request-Id
X-CST
X-Amz-Server-Side-Encryption
Public-Key-Pins
MS-Author-Via
Charset
X-Upstream
X-Forwarded-Proto
X-Version
X-Px
X-NF-Request-ID
DynaTrace
X-Amz-Rid
X-Cached
Realpath
X-Shard
X-TTL
Fastly-Restarts
Edge-Cache-Tag
MicrosoftSharePointTeamServices
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
Arr-Disable-Session-Affinity
X-Ezoic-Cdn
X-Recruiting
X-MSEdge-Ref
TCN
Access-Control-Request-Method
X-Shield-Request-Id
X-Pinterest-Rid
Pinterest-Version
X-DynaTrace-JS-Agent
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Ser
S
X-Ttl
X-Fastly-Request-ID
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Generation
Nginx-Cache
X-XRDS-Location
Front-End-Https
X-Accel-Expires
X-DIS-Request-ID
X-Amz-Meta-S3cmd-Attrs
X-Goog-Storage-Class
X-Client-IP
X-Id
X-Element-Page-Cache
X-Varnish-Age
X-Trafficlayer-App-Scope
X-Trafficlayer-App-Name
X-T
MRF-Tech
Mrf-Cache-Status
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
X-Mrf-Item-Lastmod
X-FTR-DC
X-FTR-Backend
X-FTR-Realm
X-Country-Code-Real
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-Cache-Status
X-Webkit-Csp
X-FTR-Expires
X-Amzn-Trace-Id
X-Dw-Request-Base-Id
Fastcgi-Cache
X-RateLimit-Remaining
X-Fastcgi-Cache
X-HS-Content-Id
NR-ENABLED
X-HS-Hub-Id
Cache-Tag
X-Frontend
X-Content-Digest
X-Hits
Powered
X-Correlation-Id
X-Kinsta-Cache
X-HS-Cache-Config
X-Litespeed-Cache
X-Grace
X-Oneagent-Js-Injection
ServerID
X-FTR-Cache-Host
X-Webapp-Samesite-None-Activated-N
X-Aspnetmvc-Version
Alternate-Protocol
TP-L2-Cache
TP-Cache
X-Hp-Webp
X-Cache-Hit
X-Node-Name
X-Request-Processing-Time
X-Request-Received
X-Forwarded-For
X-N
X-Ah-Environment
X-Request-Handler-Origin-Region
PB-PID
X-Microsite
PB-RID
X-Mobile-Rewrite
Arc-Version
AR-ATIME
Ar-Sid
AR-CACHE
AR-PoweredBy
AMP-Access-Control-Allow-Source-Origin
X-Zen-Fury
Server-Name
X-Content-Type
X-Rid
X-User-Agent
X-Ruxit-Js-Agent
Healthy
X-Revision
X-Analytics
Server-Node
Backend-Timing
X-LB-Cache
X-Content-Security-Policy-Report-Only
X-Akamai-Edgescape
X-Logged-In
Cache-Status
X-Activity-Id
X-HS-Combine-CSS
X-AppVersion
X-Az
X-Srv
Retry-After
X-IPLB-Instance
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Cached-By
X-FastCGI-Cache
X-NWS-LOG-UUID
X-Pad
X-Via-JSL
X-Type
Paypal-Debug-Id
X-Varnish-Grace
X-GUploader-UploadID
X-B3-Sampled
X-Mobile-URL
FilterID
X-Content-Options
Refresh
AR-Request-ID
X-F-Cache
X-Cache-Age
X-Geo-Country
X-Tumblr-Pixel-0
X-FB-Debug
X-Tumblr-User
Accept-Charset
X-Debug-Info
X-Instance
X-Tumblr-Pixel
X-Page-Id
Host
X-App-Environment
X-Cluster
X-Jobs
Source
X-Request-Guid
X-AOL-HN
Upgrade-Insecure-Requests
Access-Control-Allow-Method
X-Framework
Actual-Object-TTL
X-B
X-PHP-Backend
X-Varnish-Backend
DC
X-Seen-By
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
Accept-CH-Lifetime
Accept-CH
X-WebKit-CSP-Report-Only
X-PressLabs-Stats
X-ATG-Version
X-Cache-Key
Fastcgi-Useragent
MS-CV
X-Content-Powered-By
X-Whom
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-TT
X-Git-Hash
X-Cache-2
X-Host-Name
X-Cache-Control
X-Esi
X-Cache-TTL
X-Amz-Replication-Status
Cache
Surrogate-Key
X-Wix-Request-Id
X-TA-CDN-Provider
X-Cache-Rule
X-Cache-Operation
Frame-Options
X-Signature
X-B-Cache
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-FW-Type
X-FW-Static
NGB
X-FW-Hash
X-FW-Server
X-FW-Serve
Host-Header
X-Response-Served-From
X-Daa-Tunnel
X-Forwarded-Host
X-Time
X-UA
Xserver
X-Origin-Server
X-Tumblr-Pixel-1
X-Tumblr-Pixel-2
Cache-Tv-Group
X-TX-ID
Webserver
X-Mobile
X-Drupal-Cache-Tags
X-Cache-Action
X-Cache-NE
Filters
X-Hyper-Cache
Payment
WPE-Backend
Eomportal-Instance
X-RequestSource
X-Region
Cleartype
X-GeoIP
X-Cacheable-TTL
X-Adobe-Content
X-Handled-By
From-Origin
X-Adobe-Loc
X-UA-Device-Type
X-SERVER
X-Cache-Enabled
X-ProcessESI
X-RemovedCookies
X-App-Server
X-EdgeConnect-Cache-Status
X-RTag
Ms-Operation-Id
Datacenter
X-NewRelic-App-Data
Tracecode
X-Cache-TTL-Remaining
X-Akamai-Transformed
X-Load-Cache
X-Status
X-Contextid
X-Cache-Server
X-Hostname
X-Edge-Location
Liferay-Portal
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-B3-Traceid
X-XRDS-LOCATION
X-BCube-Filmed-By
X-RateLimit-Limit
X-TT-TIMESTAMP
X-Varnish-Hostname
Odigeo-Trace-Id
X-Varnish-Server
X-FW-Dynamic
Server-Info
X-Rule
X-Path-Route
X-RN-RSRV
X-ES-SERVER
X-Cache-Var
Load-Balancing
X-Cache-Var-Map
Meta-Geo
Country
X-Viewer-Country
X-Xfnlog-Site
X-CCM
X-IP
X-Cache-Config
X-OCL
Version
Cache-Tags
DB-Nickname
X-PCL
X-UUID
X-Debug-Cache
X-Via-Fastly
X-Rocket-Nginx-Bypass
TWC-Connection-Speed
X-Varnish-Cache-Hits
S-Rt
TWC-Device-Class
TWC-GeoIP-Country
TWC-Privacy
X-Upgrade-Enabled
TWC-Locale-Group
TWC-GeoIP-LatLong
Property-Id
Mn-Server-Ip
Azure-SlotName
Azure-SiteName
Azure-RegionName
Azure-InstanceId
Azure-Version
Cache-Name
L5d-Success-Class
Fastly-SSL
X-Web-Node
Webcakes-App-Name
Webcakes-App-Version
X-Loop
X-Labrador-Cache-Channel
X-Info
X-Hosted-By
X-Pubstack
X-Origin
X-Proxy
X-Origin-Response-Time
X-Origin-Hint
X-From
X-R9-Blue-Green-Version
X-Cache-Host
X-ServerID
X-Akamai-Request-ID
Webcakes-Region
X-Cache-Time
X-Real-IP
X-FC-Vary-Parameters
X-EIG-Tracking-Id
X-Drupal-Cache-Contexts
X-Proto
X-TNCMS
X-Origin-CC
X-Origin-TTL
X-ATS-Timestamp
X-Redis-Cache
X-Www-Served-By
X-FireWall-Port
X-VCT
Decoy-Debug-TTL
DSUID
X-Generated
X-Content-Age
X-Format
Origin-Cache-Control
X-ApacheServer
X-Akamai-Request-ID2
X-Access
Viewport
Selected-Fe
X-Backend-Name
Decoy-Debug-Status
Origin-Edge-Control
Release
S-Cnection
X-Cluster-Name
Ec-Rule-Version
X-Timing-Wait
X-Rendered-As
Decoy-Debug-Key
X-PERF
X-Section
X-JoinUs
X-Human
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Proxy-Build
X-Soup
X-VCache
NGX
X-Time-Microsecs
X-Varnish-Hits
X-Vgn-Hpd-Reason
X-NWS-UUID-VERIFY
X-Locale
X-Storage
X-Site-Version
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Storage-Class
X-Is-Bot
X-Guploader-Uploadid
Rt-Fastcgi-Cache
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-ProxyCache-Key
X-App-Version
Uber-Trace-Id
X-BYPASS-REASON
Cache-Key
X-ProxyCache-Status
X-WA-Info
Cteonnt-Length
X-PHP-Host
Vix-Hermes-Req-Id
X-ORACLE-APMCS-REQUEST-ID
X-ORACLE-APMCS-TAG
X-GoCache-CacheStatus
X-Generated-By
X-Cache-Backend
X-NCache
X-Hit
Cache-Hits
X-Amzn-Remapped-Content-Length
X-SS-Set-Cookie
X-Cache-Grace
Time
GEO-INFO
Akamai-GRN
X-Cache-Remote
X-Backend-TTL
X-Accel-Buffering
Origin
X-Trace-Id
X-CS
X-Nginx-Cache-Key
X-Device-Type
X-Tumblr-Pixel-3
X-B3-SpanId
X-FB-TRIP-ID
Accept-Language
X-L-Path
X-OVcl-Cache
X-No-Session
X-Environment-Context
X-OVcl
X-S
X-CF-Powered-By
X-SaId
X-Tb
Mime-Version
X-APP-VERSION
X-MServer
X-URL
Access-Control-Request-Headers
Hostname
X-Cluster-Node
X-Uri
X-SayCDN-TTL
X-Via-CDN
X-Say-TTL
X-UnsetCookies
Fastcgi-X-Cache-Version
X-Say-Cacheable
X-CACHE-KEY
X-Tec-Api-Root
X-Tec-Api-Version
X-Tec-Api-Origin
X-Presslabs-Stats
ServerName
User-Cache-Control
X-Geo
Now
Cross-Origin-Window-Policy
X-DPWN-IS-SECURE
X-External-Request-Id
Content-Style-Type
Content-Script-Type
X-Detected-As
X-Destination
X-Connection-Hash
IsBot
X-D
X-Date
X-G
BehaviorPad-Version
X-Session-Fingerprint
X-SIPLIST1
X-Server-Time
X-SRCache-Key
X-Hl-Ver
Apple-News-Services-Handled
AsisCache
Arc-Country
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Machine
MD5-Digest
X-AIR-PT
X-A
X-Application
X-ARC
VivaBuild
X-A-Ccd
X-A-Dam
X-Aed
X-A-Wwc
X-A-Dgt
X-A-Dcw
Viewtype
T-Server
Node
X-CF-Lambda-Version
Mobile-Detection-Method
Meta-Geo-Continent
X-CF-Lambda-Fn
Rendered-Blocks
X-B-Cookie
Rt-Proxy-Cache
Request-EU
Request-Country
X-Svr
Apple-News-Services-Host
X-S-Cookie
X-Processor
X-Rojux
X-Accel-Expires-Debug
X-Trv-Group
Xc-Version
X-ScT
X-PAYTM-SRV-ID
X-Transaction
X-Region-Sid
X-Vtex-Processado-Em
X-Rewrite-Enabled
X-Request-UUID
X-Twitter-Response-Tags
X-FW-Version
X-VG-WebCache
X-Vtex-Remote-Cache
X-VG-WebServer
X-Endurance-Cache-Level
X-CSRF-TOKEN
Server-Host
Server-Int
X-Reboot
X-Debug-Log
X-Block-Status
X-Cache-Bucket
X-Cache-Debug
X-Gen-Mode
CDCHOST
RNT-Machine
RNT-Time
X-Request-URI
Thinkindot-CacheControl
X-Proxy-Cache-Status
X-Proxy-Upstream
X-Hnp-Log
X-Clara-WADP
Proxy-Connection
X-Nc
Mail-Subject
We-Hiring
X-WADP-Cache
X-Thinkindot-L3
X-S-Maxage
X-NX-Host
X-Cms-Context
X-Core-Value
X-Cache-Info
X-Matched-Rule
X-Debug-Cookies
Srv
Thinkindot-Control
Web-Mar-Node
X-Service
OT-Force-Account-Verify
X-Location
X-Cdn-Forward
Thinkindot-CacheControl-Type
X-B3-Parentspanid
NtCoent-Length
X-Variation
X-Clientip
X-Cache-URL
X-CGP
X-VG-TLSProxy
X-VC-Cache
X-Cdn-Srv
X-BBXSRF
X-App-Name
X-VServer
X-Wikidot-Backend
X-Auto-Login
X-Amz-Meta-Cache-Control
X-Alternate-Cache-Key
X-WebServer
X-Webstats-RespID
X-We-Are-Hiring
X-Azure-Ref
X-Azure-Ref-OriginShield
X-ShopId
X-Release
X-Cache-FS-Status
X-Wikidot-Static-Cache
X-C
X-Compress-Hint
X-Request-Start
X-Reqid
X-Backend-State
X-Cache-Id
X-Dispatcher-Server
X-Key
X-JWT-State
X-Level-Front-Cache
X-Li-Fabric
X-Li-Pop
X-Shopify-Stage
X-Is-Gdpr
X-Instart-Isnd
X-IN-APIGATEWAYSSL
X-Internal-Host
X-Irp-Debug
X-ShardId
X-Skip-Cache
X-LI-UUID
X-Ms-Version
X-SD-PageType
X-Origin-Date
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Server-IP
X-Ms-Request-Id
X-Magnolia-Registration
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Method
X-TrackingId
X-IN-APIGATEWAY
X-Origin-Expires
X-Old-Content-Length
X-Dispatch
X-Distil-CS
X-Distributor
X-RateLimit-Limit-Second
X-Developers
X-RateLimit-Remaining-Second
X-User
X-CUA
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Epic-Correlation-Id
X-Eu-Site
X-Up
X-Has-Esi
X-Hash
X-Policy
X-Platform-Server
X-GeoIP-City
X-Geo-Header
X-Fastly-Cache
X-Scheme
X-Generated-In
X-Generated-On
X-Generation-Time
X-Core-Mission
SD-X-WS
Content-Disposition
Platform
Countrycode
Esi-Enabled
Cache-Host
HA-Ipaddr
Adler-Geo
AKAMAI
Served-By
PFcat
Memcached
IBM-Web2-Location
Gh-Request-Id
Ha-Gx-Prefs
Is-Eu
Kp-EeAlive
Magicmarker
Fastly-Soc-X-Request-Id
L
ServedBy
Section-Io-Cache
X-7Graus-Varnish-Cache-Control
X-Varnish-Beresp-Status
X-Varnish-Beresp-Ttl
Wxu-Next-Hostname
True-Client-Country-4JS
X-7Graus-Varnish-XKeys
Wxu-Next-Region
Wxu-Next-Commit
X-Varnish-Beresp-Grace
W
X-NC
Cache-Provider
X-Parent-Response-Time
X-Vdms-Version
X-LI-Proto
X-MSEdge-Features
X-MSEdge-Flight
X-Logging-Id
X-Urbn-Site-Id
X-Swa-Ws
X-ServiceProvider
X-Qloud-Router
X-Dc
X-Owner
X-CDN-Forward
X-Thanos
A
X-Urbn-Context-Path
X-Developer
Pramga
X-Agile-Age
X-Agile-Id
Locale
X-Agile
X-Bip
Heartbleed
V-Age
X-Sucuri-Id
Tcn
X-Sn-Servicetimems
X-NodeID
X-Unique-Id
X-Shopify-Generated-Cart-Token
Server-ID
X-AK-Request-ID
X-Sucuri-Cache
X-Cdn-Origin
X-Rocket-Build-Number
Cdncip
X-Sigma
Cdnsip
X-Sigma-Backend
X-Node-Id
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Device-Os
X-B3-Spanid
X-GRACE
X-Upstream-Ct
X-Via-NSCOPI
Powered-By-ChinaCache
X-Upstream-Ht
X-Lb-Id
X-Servername
GEO-REGION-INFO
X-RCS-CacheZone
Environment
CF-IPCountry
X-Source
X-EC-Lua
X-FPC
X-Be
X-ND-Cache
X-Nginx-Cache
X-Trafficlayer-App-Version
X-VHOST
X-Zone
Geo-Info
X-Newrelic-Synthetics
Resin-Trace
X-Microcachable
Request-Time
X-Servedbyhost
X-Webkit-CSP
Locid
X-Req
X-Pjax-Url
X-NGENIX-Cache
X-Gamma-Serve
FNAC-ModuleRouting
X-Served-From
X-Tb-Optimization-Total-Bytes-Saved
X-Oracle-Dms-Rid
X-ElasticPress-Search
X-ECACHE
X-Instart-Info
X-Unique-ID
X-SRV
X-Backend-Url
X-Backend-Host
Group
X-TIME
X-Pf-Uncompressing
X-Refresh
X-Dynatrace
X-Var-Ttl
X-DC
X-AWS-Id
Gannett-Cam-Experience-Id
X-GEO
X-VWS-Id
Backend-Name
X-COUNTRY
ProcessTime
Memory
X-IPS-LoggedIn
X-LJ-Flow-ID
CF-Cached-On
X-VCL-Version
X-Sucuri-ID
X-Correlation-ID
Pics-Label
N-Cache
TTL
X-HTML-Minification-Powered-By
X-Render-Time
Cf-Ipcountry
X-Ratelimit-Remaining
Amp-Access-Control-Allow-Source-Origin
X-CSRF-Token
Cache-Prefix
Lfy
Geoip-City
GeoIp-Country-Code
Geoip-Latitude
X-Check-Cacheable
Pagetype
Fly-Cache
X-Pod
X-NU-AKA-ACS-Version
Fly-Request-Id
X-FORWARDED-FOR
REQUESTUUID
X-Via-Edge
X-Via-SSL
PICS-Label
X-Bc
X-GeoIP-Country-Code
GeoIP-Latitude
X-Worker
GeoIP-Country-Code
GeoIP-City
Ohc-File-Size
XServer
Ohc-Cache-HIT
SRV
X-Sedo-Request-Id
X-Upstream-HT
X-Via-Ucdn
Cdn
X-APP
X-Upstream-CT
Ttl
M-TraceId
X-Cache-Miss-From
X-Vcl-Version
X-CLOUD-TRACE-CONTEXT
X-Mode
X-Server-W
X-Fstrz
X-Fetched-On
MIME-Version
X-MP-GENERATED-AT
X-ZONE
X-PF-Uncompressing
HitType
X-Wa
X-HostName
X-Fastly-Country-Code
Fastly-SWR
Fastly-SIE
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-LiteSpeed-Cache-Control
X-Ratelimit-Limit
X-HS-Status
Cache-Cookie-Set-Idcheck
HostName
Cache-Cookie-Set-From
Host-ID
Cache-Cookie-Set-Lfrom
X-Dynatrace-Js-Agent
On-Server
Pragrma
User-Agent
X-ServedByHost
X-Swift-Error
X-Routing-Service
X-Proxied
X-BC
X-Zipkin-Id
X-GDPR
X-PJAX-URL
X-Tt-Trace-Tag
X-WR-MODIFICATION
URI
X-Cache-Tag
X-Cdn-Request-ID
X-Ua
X-NGINX-Cache
X-Aicache-OS
X-TT-LOGID
Cdn-Host
X-TH-Server
X-Edge-O15-RID
X-WA
Cdn-Request-Time
X-Edge-Server
Who
X-RateLimit-Reset
CACHE
X-Cf-Powered-By
X-Flog
X-SN
X-Cache-Ttl
Powered-By
X-Fastly-Backend-Reqs
X-UPSTREAM-Address
X-BE
CDN
X-ABtesting
X-Hello
Dynatrace
X-Response-By
SS
X-DI
X-DW
X-ServerName
X-DB
X-Fpc
X-RPM
X-RSL
X-Varnish-Cacheable
X-Action
Media-Length
X-RPS
X-LAGOON
X-Varnish-URL
X-DSS
X-Org
DataCenter
Server-Id
Get-Access-Time
X-Request-Time
LB
SN
X-Upstream-Proxy
Is-Session-Tracking
X-Ratelimit-Reset
Debug
X-LB-ID
X-Ftr-Cache-Host
Cneonction
X-Protected-By
X-Varnish-Beresp-TTL
X-Gen-Id
Requestid
X-Nananana
Warning
NnCoection
X-LiteSpeed-Tag
RequestId
Country-Code
Lb
XxX-Cache-Status
Correlation-Id
RequestUuid
X-Akamai-ERPolicy
Product
X-Li-Proto
Application
SID
X-Page-Type
Thinkindot-Cache-Type
X-Request-Url
X-Akamai-ERRuleID
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
X-Dw-Trace-Id
X-Fastly-Cache-Hits