Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
CF-Cache-Status
Pragma
Link
CF-RAY
X-Powered-By
ETag
Expect-CT
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Xss-Protection
X-Varnish
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
Alt-Svc
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-FRAME-OPTIONS
X-Drupal-Cache
X-Request-ID
X-Adblock-Key
X-Check
X-Generator
Content-Security-Policy-Report-Only
X-Cache-Status
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-Template
X-Language
X-AspNetMvc-Version
Status
X-Content-Security-Policy
X-Buckets
Content-Encoding
Access-Control-Expose-Headers
X-CDN
Upgrade
Xkey
Access-Control-Max-Age
X-Drupal-Dynamic-Cache
Keep-Alive
X-Kinja-Server-Push
X-Turbo-Charged-By
CF-Ray
X-AH-Environment
X-Age
X-Cache-Group
X-Via
X-Pass-Why
X-Backend
X-Ua-Compatible
X-Envoy-Upstream-Service-Time
EagleId
X-Server
X-Robots-Tag
X-Amz-Id-2
X-Amz-Request-Id
X-Server-Powered-By
X-Page-Speed
X-Pingback
X-UA-Device
X-Proxy-Cache
X-Swift-CacheTime
X-Swift-SaveTime
X-Hacker
X-Nginx-Cache-Status
Request-Context
Ali-Swift-Global-Savetime
X-Varnish-Cache
Grace
Server-Timing
Feature-Policy
Cf-Railgun
X-Amz-Version-Id
X-LiteSpeed-Cache
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Server-Id
X-Device
X-WebKit-CSP
X-Rq
Report-To
X-Ws-Request-Id
EagleEye-TraceId
X-Host
X-Response-Time
X-Ac
X-OneAgent-JS-Injection
Request-Id
X-Cnection
X-Backend-Server
Content-Location
X-DataDome
X-Origin-Cache
NEL
X-Node
X-Cache-Lookup
X-Readtime
X-Dns-Prefetch-Control
X-Cloud-Trace-Context
X-Vhost
X-HW
X-Dispatcher
X-ORACLE-DMS-ECID
X-Application-Context
X-ORACLE-DMS-RID
P3p
X-Cdn
Allow
Surrogate-Control
X-Origin-Upstream-Status
X-Clacks-Overhead
X-Rack-Cache
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-DynaTrace
Rating
X-Country
Fusion-Content-Id
Fusion-Content-Source
Fusion-Source
Fusion-Template-Id
Fusion-Component-Id
X-Akam-SW-Version
X-FTR-Request-ID
X-Country-Code
X-Goog-Hash
X-Varnish-TTL
X-Ruxit-JS-Agent
Pinterest-Generated-By
Edge-Control
X-Instart-Request-ID
X-PC
X-TtlSet
X-Vname
X-B3-TraceId
X-Mod-Pagespeed
X-Url
Accept-Ch
X-MS-InvokeApp
Verso
SPRequestGuid
X-Powered-By-Plesk
X-TTL
X-ESI
X-D2id
X-Trace
X-VARITI-CCR
X-Server-Name
X-GitHub-Request-Id
Service-Worker-Allowed
Content-MD5
X-SharePointHealthScore
Pagespeed
X-Kinja
Response
X-Kinja-Revision
X-Kinja-Server
X-Sol
X-Use-Magma
X-Cdn-Fetch
X-Exp-Id
X-GoogleNews-Bot
X-Middleton-Response
X-Kinja-Build
X-Exp-Variant
RTSS
Display
X-Middleton-Display
Accept-Ch-Lifetime
X-Navigation-Version
SPIisLatency
SPRequestDuration
X-Abt-Application-Version
X-Powered-CMS
X-Debug
X-Forwarded-Proto
X-Vcache
X-Upstream
X-Cached
X-Amz-Server-Side-Encryption
Public-Key-Pins
X-Vcap-Request-Id
Charset
X-Version
X-CST
MS-Author-Via
DynaTrace
X-NF-Request-ID
X-Amz-Rid
Realpath
Edge-Cache-Tag
X-Px
X-DynaTrace-JS-Agent
MicrosoftSharePointTeamServices
Arr-Disable-Session-Affinity
X-Shard
TCN
X-Trafficlayer-App-Scope
X-Trafficlayer-App-Name
X-Shield-Request-Id
X-Ezoic-Cdn
X-MSEdge-Ref
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Access-Control-Request-Method
X-Fastly-Request-ID
X-Ser
Pinterest-Version
X-Pinterest-Rid
S
X-Accel-Expires
X-DIS-Request-ID
Fastly-Restarts
X-Client-IP
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
Front-End-Https
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Webapp-Samesite-None-Activated-N
X-Amz-Meta-S3cmd-Attrs
X-Recruiting
X-Id
X-T
X-Varnish-Age
X-Element-Page-Cache
X-XRDS-Location
X-Goog-Storage-Class
Cache-Tag
X-FTR-Realm
X-FTR-Balancer
X-Country-Code-Real
X-FTR-Backend-Server
X-FTR-Cache-Status
X-FTR-DC
X-FTR-Backend
X-Amzn-Trace-Id
X-Mrf-Item-Lastmod
MRF-Tech
X-Mrf-Section-Lastmod
X-FTR-Expires
X-Dw-Request-Base-Id
Mrf-Cache-Status
X-B3-TraceId-Primal
Nginx-Cache
X-Server-ID
Fastcgi-Cache
X-Content-Digest
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Cache-Config
X-Frontend
NR-ENABLED
Powered
X-Hits
X-Fastcgi-Cache
X-Correlation-Id
X-Hp-Webp
Alternate-Protocol
X-Kinsta-Cache
X-FTR-Cache-Host
X-Content-Type
X-Request-Received
X-Request-Processing-Time
Server-Name
X-Aspnetmvc-Version
X-HS-Combine-CSS
X-RateLimit-Remaining
ServerID
X-Request-Handler-Origin-Region
X-Microsite
PB-PID
PB-RID
X-Webkit-Csp
TP-L2-Cache
X-Cache-Hit
TP-Cache
Arc-Version
X-N
X-Mobile-Rewrite
X-Grace
X-Rid
X-Ttl
X-Akamai-Edgescape
X-Pad
Healthy
X-Forwarded-For
X-User-Agent
Backend-Timing
X-Revision
X-Analytics
X-Node-Name
X-Content-Security-Policy-Report-Only
AMP-Access-Control-Allow-Source-Origin
X-Logged-In
X-Mobile-URL
X-Zen-Fury
X-Amz-Apigw-Id
X-Amzn-RequestId
X-LB-Cache
Server-Node
X-Varnish-Grace
X-AppVersion
X-Activity-Id
X-Az
X-Cached-By
Cache-Status
X-B3-Sampled
X-GUploader-UploadID
X-Content-Options
X-F-Cache
X-Oneagent-Js-Injection
Refresh
X-Geo-Country
X-NWS-LOG-UUID
X-FastCGI-Cache
Upgrade-Insecure-Requests
X-IPLB-Instance
X-Type
Retry-After
X-Varnish-Backend
X-Cache-2
X-Srv
X-Ruxit-Js-Agent
X-App-Environment
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-User
Accept-Charset
Host
X-Jobs
X-FB-Debug
Paypal-Debug-Id
X-Cluster
X-B
X-AOL-HN
DC
X-Debug-Info
X-Framework
X-PHP-Backend
X-Page-Id
X-Instance
Actual-Object-TTL
X-Request-Guid
Source
Access-Control-Allow-Method
FilterID
X-WebKit-CSP-Report-Only
Cache
Accept-CH-Lifetime
X-ATG-Version
AR-CACHE
AR-PoweredBy
X-TT
AR-ATIME
Accept-CH
Fastcgi-Useragent
X-Cache-Age
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Seen-By
X-Cache-Key
X-Git-Hash
MS-CV
X-Content-Powered-By
X-Via-JSL
X-TA-CDN-Provider
Ar-Sid
VIX-Pulpo-Upstream-Status
X-B-Cache
X-Signature
VIX-Pulpo-Node
X-Amz-Replication-Status
X-Cache-TTL
Host-Header
X-Whom
X-Origin-Server
X-PressLabs-Stats
X-Cache-Control
X-Wix-Request-Id
X-Cache-Enabled
X-Mobile
NGB
X-Response-Served-From
Xserver
Surrogate-Key
X-ATS-Timestamp
X-UA
X-XRDS-LOCATION
X-Daa-Tunnel
X-RequestSource
X-Tumblr-Pixel-2
X-GeoIP
Cache-Tv-Group
X-Tumblr-Pixel-1
X-FW-Hash
X-Host-Name
X-FW-Static
X-FW-Type
X-Hyper-Cache
X-Cacheable-TTL
Cleartype
X-FW-Server
X-FW-Serve
Eomportal-Instance
Datacenter
WPE-Backend
X-Cache-NE
Filters
Payment
X-Adobe-Loc
X-Adobe-Content
Frame-Options
X-TX-ID
X-Region
X-Handled-By
X-Drupal-Cache-Tags
Webserver
X-Cache-Action
X-EdgeConnect-Cache-Status
X-Load-Cache
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Litespeed-Cache
X-Akamai-Transformed
X-SERVER
X-Hostname
X-Cache-Rule
X-Cache-Operation
AR-Request-ID
X-Esi
From-Origin
X-Edge-Location
X-Cache-TTL-Remaining
X-ProcessESI
X-RemovedCookies
X-NewRelic-App-Data
Liferay-Portal
X-UA-Device-Type
Ms-Operation-Id
X-RTag
X-Cache-Server
X-Varnish-Hostname
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Request-Id
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Forwarded-Host
X-ORACLE-APMCS-REQUEST-ID
X-ORACLE-APMCS-TAG
X-Varnish-Server
X-Rule
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Status
Country
X-Upgrade-Enabled
X-Contextid
X-App-Server
X-UUID
Odigeo-Trace-Id
X-ES-SERVER
X-BCube-Filmed-By
X-Path-Route
Load-Balancing
X-Cache-Var-Map
Meta-Geo
X-RN-RSRV
X-Cache-Var
X-VCache
DSUID
X-TT-TIMESTAMP
TWC-Device-Class
X-CCM
Webcakes-App-Version
X-Debug-Cache
Webcakes-App-Name
Mn-Server-Ip
Webcakes-Region
TWC-Privacy
DB-Nickname
X-EIG-Tracking-Id
TWC-GeoIP-LatLong
TWC-Connection-Speed
X-Rocket-Nginx-Bypass
Release
TWC-Locale-Group
X-Origin-Hint
TWC-GeoIP-Country
X-R9-Blue-Green-Version
Property-Id
X-From
X-VCT
Cache-Tags
X-OCL
Cache-Name
X-Loop
X-ServerID
Fastly-SSL
X-Origin
Azure-Version
Azure-InstanceId
X-Origin-Response-Time
Azure-RegionName
Azure-SiteName
Azure-SlotName
Origin-Cache-Control
Origin-Edge-Control
X-Cache-Time
X-Human
X-Hosted-By
X-Drupal-Cache-Contexts
X-FireWall-Port
X-FC-Vary-Parameters
X-Cache-Host
X-Cache-Config
S-Rt
X-FW-Dynamic
Selected-Fe
X-Akamai-Request-ID
X-IP
X-Viewer-Country
L5d-Success-Class
X-Proxy-Build
X-Proxy
X-Pubstack
X-Real-IP
X-Redis-Cache
X-Timing-Wait
X-Proto
X-TNCMS
X-Via-Fastly
X-Soup
X-Vgn-Hpd-Reason
X-PCL
X-Www-Served-By
X-Format
X-ProxyCache-Status
X-Site-Version
X-ProxyCache-Key
X-Generated
X-Section
X-Rendered-As
Viewport
X-Access
X-Backend-Name
X-Varnish-Hits
X-JoinUs
X-Akamai-Request-ID2
X-Cluster-Name
X-Accel-Buffering
X-Xfnlog-Site
X-Labrador-Cache-Channel
X-Content-Age
Ec-Rule-Version
X-Locale
X-BYPASS-REASON
Uber-Trace-Id
X-Is-Bot
X-Goog-Meta-Goog-Reserved-File-Mtime
Decoy-Debug-Key
Version
Decoy-Debug-TTL
X-Web-Node
NGX
Decoy-Debug-Status
X-Varnish-Cache-Hits
S-Cnection
Server-Info
X-Generated-By
X-Time-Microsecs
X-NWS-UUID-VERIFY
X-Cache-Backend
X-PHP-Host
Tracecode
X-Presslabs-Stats
X-PERF
X-ApacheServer
X-Amzn-Remapped-Content-Length
X-Info
X-Time
X-Storage
X-Origin-TTL
X-Origin-CC
X-SaId
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
X-Geo
Akamai-GRN
X-WA-Info
X-Nginx-Cache-Key
X-URL
GEO-INFO
Cteonnt-Length
Rt-Fastcgi-Cache
Time
X-CF-Powered-By
X-MServer
X-No-Session
X-Environment-Context
X-L-Path
Origin
X-APP-VERSION
X-Unique-Id
X-Cache-Remote
X-App-Version
Accept-Language
X-Tb
Cache-Key
Access-Control-Request-Headers
X-Guploader-Uploadid
X-Backend-TTL
X-FB-TRIP-ID
X-Say-TTL
X-GoCache-CacheStatus
X-CDN-Forward
X-SayCDN-TTL
X-TIME
X-Say-Cacheable
X-EC-Lua
X-NCache
Cache-Hits
X-Hit
Vix-Hermes-Req-Id
X-CACHE-KEY
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-RCS-CacheZone
X-Shopify-Stage
X-ShardId
X-Shopify-Generated-Cart-Token
X-ShopId
X-Alternate-Cache-Key
X-RateLimit-Limit
X-Dc
X-Trace-Id
OT-Force-Account-Verify
Mime-Version
X-Device-Type
X-Source
X-CS
X-Tumblr-Pixel-3
X-S
X-B3-SpanId
X-SS-Set-Cookie
Srv
X-Endurance-Cache-Level
X-OVcl-Cache
X-OVcl
X-Magnolia-Registration
X-Parent-Response-Time
X-Processor
X-Region-Sid
Request-Country
X-Cluster-Node
Request-EU
X-ARC
X-PAYTM-SRV-ID
T-Server
X-Destination
Server-Host
Rt-Proxy-Cache
Viewtype
X-CF-Lambda-Version
X-CF-Lambda-Fn
Xc-Version
Apple-News-Services-Handled
Meta-Geo-Continent
X-Date
Mobile-Detection-Method
Fastcgi-X-Cache-Version
X-D
X-G
MD5-Digest
IsBot
X-Detected-As
X-DPWN-IS-SECURE
Machine
X-External-Request-Id
Cross-Origin-Window-Policy
Node
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Apple-News-Services-Host
VivaBuild
X-Connection-Hash
Arc-Country
AsisCache
Content-Style-Type
Content-Script-Type
X-Hl-Ver
BehaviorPad-Version
Rendered-Blocks
User-Cache-Control
X-SIPLIST1
X-A-Dcw
X-A-Dgt
X-SRCache-Key
X-Vtex-Remote-Cache
X-Session-Fingerprint
X-A-Ccd
X-Upstream-Ct
X-Upstream-Ht
X-A
X-Server-Time
X-Service
X-A-Wwc
X-Svr
X-Vdms-Version
X-AIR-PT
X-Application
X-VG-WebCache
X-VG-WebServer
X-B-Cookie
X-Twitter-Response-Tags
X-Aed
X-Accel-Expires-Debug
X-Transaction
X-Vtex-Processado-Em
X-Trv-Group
X-ScT
X-A-Dam
X-S-Cookie
X-Rojux
X-Request-UUID
X-Rewrite-Enabled
Now
ServedBy
ServerName
X-CUA
X-Hash
X-Instart-Isnd
X-Core-Value
X-Thinkindot-L3
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
Thinkindot-CacheControl-Type
X-Dispatcher-Server
X-Dispatch
Mail-Subject
We-Hiring
X-Reboot
X-Cache-Bucket
Wxu-Next-Commit
Thinkindot-Control
X-Generated-On
Proxy-Connection
X-Ah-Environment
Served-By
X-Location
X-Matched-Rule
Thinkindot-CacheControl
Wxu-Next-Region
X-ND-Cache
X-Via-NSCOPI
X-Webstats-RespID
Wxu-Next-Hostname
X-Level-Front-Cache
Server-Int
X-Uri
X-Block-Status
X-Clara-WADP
X-Debug-Cache-Fetch
X-BBXSRF
X-Auto-Login
X-Debug-Cookies
X-Debug-Log
X-Clientip
X-Azure-Ref
X-Bip
X-Debug-Cache-Store
X-Cdn-Srv
X-B3-Parentspanid
X-Compress-Hint
X-Backend-State
X-C
X-Cache-Info
X-CGP
X-Core-Mission
X-Azure-Ref-OriginShield
X-Cms-Context
X-Cache-Debug
X-Cache-FS-Status
X-Debug-Cache-Expiry
X-Li-Fabric
X-Request-URI
X-Request-Start
X-Reqid
X-Rocket-Build-Number
X-S-Maxage
X-SD-PageType
X-Scheme
X-Release
X-RateLimit-Remaining-Second
X-Platform-Server
X-Planisys-CDN-TTL
X-Proxy-Cache-Status
X-Proxy-Upstream
X-RateLimit-Limit-Second
X-Qloud-Router
X-Server-IP
X-WADP-Cache
X-User
X-Up
X-Variation
X-VServer
X-VG-TLSProxy
X-VC-Cache
X-TrackingId
X-Thanos
X-Sigma-Backend
X-Sigma
X-Skip-Cache
X-Sucuri-Cache
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Has-Esi
X-GeoIP-City
X-Geo-Header
X-Hnp-Log
X-Irp-Debug
X-JWT-State
X-Is-Gdpr
X-Generation-Time
X-Gen-Mode
X-Distributor
X-Distil-CS
X-Epic-Correlation-Id
X-Eu-Site
X-FW-Version
X-Fastly-Cache
X-Key
X-Li-Pop
X-Wikidot-Backend
X-Origin-Date
X-Origin-Expires
X-WebServer
X-Owner
X-We-Are-Hiring
X-Old-Content-Length
X-NX-Host
X-Logging-Id
X-LI-UUID
X-Method
X-Wikidot-Static-Cache
X-Ms-Version
X-Ms-Request-Id
X-Developers
X-Cache-URL
Magicmarker
AKAMAI
Cache-Host
L
Memcached
Adler-Geo
RNT-Machine
Pramga
Platform
PFcat
CDCHOST
Is-Eu
Countrycode
Gh-Request-Id
Esi-Enabled
Fastly-Soc-X-Request-Id
Content-Disposition
Ha-Gx-Prefs
IBM-Web2-Location
Heartbleed
HA-Ipaddr
RNT-Time
X-App-Name
SD-X-WS
Web-Mar-Node
X-Amz-Meta-Cache-Control
W
Section-Io-Cache
X-Agile-Id
X-Agile
X-Agile-Age
NtCoent-Length
Cache-Provider
X-CSRF-TOKEN
X-SRV
X-Internal-Host
Kp-EeAlive
Powered-By-ChinaCache
X-Cache-Id
Server-ID
X-Policy
X-Varnish-Beresp-Status
X-Generated-In
X-Swa-Ws
X-Trafficlayer-App-Version
X-Varnish-Beresp-Grace
X-Cache-Grace
X-LI-Proto
X-Varnish-Beresp-Ttl
X-NC
X-B3-Spanid
X-Nc
X-Urbn-Site-Id
X-NodeID
X-Urbn-Context-Path
Cdncip
Cdnsip
X-ServiceProvider
V-Age
X-AK-Request-ID
True-Client-Country-4JS
Locale
X-Newrelic-Synthetics
X-NODE
Environment
X-Via-CDN
X-Servername
X-Served-From
Locid
X-HTML-Minification-Powered-By
CF-IPCountry
X-Req
X-MSEdge-Features
X-MSEdge-Flight
X-Be
X-Lb-Id
X-Gamma-Serve
FNAC-ModuleRouting
X-B3-Traceid
GEO-REGION-INFO
X-IPS-LoggedIn
X-GRACE
X-Cdn-Forward
X-FPC
X-Refresh
X-CLOUD-TRACE-CONTEXT
Hostname
X-UnsetCookies
X-Sucuri-Id
X-7Graus-Varnish-XKeys
X-7Graus-Varnish-Cache-Control
X-Render-Time
X-Sucuri-ID
X-Nginx-Cache
X-MP-GENERATED-AT
X-VHOST
X-Tb-Optimization-Total-Bytes-Saved
X-NU-AKA-ACS-Version
X-Mode
X-Zone
Tcn
X-Servedbyhost
ProcessTime
A
X-GeoIP-Country-Code
X-Developer
Geo-Info
X-Microcachable
X-Webkit-CSP
X-Edge-O15-RID
X-Cdn-Origin
X-Device-Os
X-Sn-Servicetimems
X-Routing-Service
X-Pf-Uncompressing
Memory
X-Pjax-Url
X-LJ-Flow-ID
X-Proxied
X-VWS-Id
X-Node-Id
X-AWS-Id
X-Zipkin-Id
X-CSRF-Token
X-Ratelimit-Remaining
X-FORWARDED-FOR
TTL
Geoip-Latitude
GeoIp-Country-Code
Resin-Trace
Request-Time
Gannett-Cam-Experience-Id
X-COUNTRY
X-Correlation-ID
X-Ratelimit-Limit
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
Amp-Access-Control-Allow-Source-Origin
Cache-Cookie-Set-From
X-DC
PICS-Label
CF-Cached-On
X-Bc
X-ZONE
X-Pod
X-Vcl-Version
Cdn
Pics-Label
X-VCL-Version
Cf-Ipcountry
HostName
X-Request-Time
X-Swift-Error
GeoIP-Latitude
Group
GeoIP-City
GeoIP-Country-Code
M-TraceId
X-Via-SSL
X-Via-Edge
X-Cdn-Request-ID
X-NGINX-Cache
X-Unique-ID
Geoip-City
Host-ID
X-ElasticPress-Search
X-Instart-Info
X-TH-Server
X-ECACHE
XServer
X-BC
MIME-Version
Ohc-Cache-HIT
Ohc-File-Size
X-Backend-Url
X-Backend-Host
X-Var-Ttl
Ttl
HitType
X-Check-Cacheable
Powered-By
X-APP
Backend-Name
X-PF-Uncompressing
X-UPSTREAM-Address
N-Cache
URI
Media-Length
REQUESTUUID
X-PJAX-URL
X-NGENIX-Cache
Lfy
Pagetype
X-HS-Status
Fly-Request-Id
X-Fstrz
On-Server
Fly-Cache
User-Agent
X-ServedByHost
Cache-Prefix
X-Tt-Trace-Tag
X-Fastly-Country-Code
X-HostName
SRV
X-Hp-Ccpa-Warning
X-Via-Ucdn
X-Worker
X-Cache-Tag
X-Tt-Trace-Host
FSS-Proxy
FSS-Cache
X-WR-MODIFICATION
X-Aicache-OS
X-LiteSpeed-Cache-Control
Who
X-WA
X-NYM-Debug-Backend
X-Fetched-On
X-Cache-Miss-From
CDN
UCS
X-Sedo-Request-Id
Pragrma
AR-SID
Processtime
X-Cache-Tags
X-Server-W
X-BE
X-Cache-ASPX
X-Varnish-Cacheable
Server-Cache-Control
X-LB-ID
Fastly-SIE
Server-Surrogate-Control
X-LAGOON
X-Varnish-URL
Fastly-SWR
X-Fpc
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-GEO
X-Varnish-Authentication
X-Contensis-Viewer-Groups
X-Wa
X-Cf-Powered-By
Country-Code
X-ServerName
X-Varnish-Beresp-TTL
X-Store
X-Upstream-CT
X-Fastly-Backend-Reqs
Filterid
X-Upstream-HT
Fastly-Backend-Name
Debug
Location
X-Ftr-Cache-Host
X-Ua
X-Protected-By
X-TT-LOGID
X-Akamai-ERPolicy
X-Response-By
X-Akamai-ERRuleID
Xet-Cookie
WP-Super-Cache
X-Apw-Access-Token
X-Apw-Hits
Ohc-Response-Time
X-Apw-Access-Action
X-Apw-Access-Object
Server-Id
SID
X-Gen-Id
X-Fastly-Cache-Hits
X-Li-Proto
Thinkindot-Cache-Type
X-Amzn-Remapped-Date
X-Amzn-Remapped-Connection
X-Dw-Trace-Id
Application
Product
XxX-Cache-Status
Cneonction
X-SB
X-Nananana
NnCoection
X-Request-Url
X-GDPR
X-VC