Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
CF-RAY
CF-Cache-Status
Pragma
Link
X-Powered-By
ETag
Expect-CT
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Xss-Protection
X-Varnish
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Download-Options
Alt-Svc
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-FRAME-OPTIONS
X-Drupal-Cache
X-Adblock-Key
X-Check
Content-Security-Policy-Report-Only
X-Generator
X-Cache-Status
X-Cacheable
X-Permitted-Cross-Domain-Policies
X-Request-ID
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Template
X-Language
X-Iinfo
X-Content-Security-Policy
Status
Content-Encoding
X-Buckets
X-AspNetMvc-Version
Access-Control-Expose-Headers
Upgrade
Xkey
X-Kinja-Server-Push
Access-Control-Max-Age
X-CDN
Keep-Alive
X-Drupal-Dynamic-Cache
X-Turbo-Charged-By
X-Via
X-Cache-Group
X-Age
X-Pass-Why
X-Envoy-Upstream-Service-Time
X-Ua-Compatible
X-Backend
EagleId
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-AH-Environment
X-Page-Speed
X-Pingback
X-Server-Powered-By
X-UA-Device
X-Server
X-Swift-CacheTime
X-Swift-SaveTime
X-Proxy-Cache
X-Hacker
Ali-Swift-Global-Savetime
X-Nginx-Cache-Status
Request-Context
Grace
X-Varnish-Cache
Server-Timing
Feature-Policy
Cf-Railgun
X-Amz-Version-Id
X-Device
X-LiteSpeed-Cache
X-Dns-Prefetch-Control
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Rq
Report-To
X-Ac
EagleEye-TraceId
X-WebKit-CSP
X-Server-Id
X-Response-Time
X-Host
X-Cnection
Request-Id
X-OneAgent-JS-Injection
X-Backend-Server
X-DataDome
X-Cdn
Content-Location
X-Cloud-Trace-Context
X-Node
X-Origin-Cache
X-Readtime
X-Cache-Lookup
NEL
X-Vhost
X-Application-Context
X-Dispatcher
X-ORACLE-DMS-ECID
X-HW
Allow
X-ORACLE-DMS-RID
X-Clacks-Overhead
X-Rack-Cache
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Origin-Upstream-Status
X-Country
Surrogate-Control
Rating
X-DynaTrace
X-FTR-Request-ID
X-Ws-Request-Id
X-Country-Code
Pinterest-Generated-By
X-Goog-Hash
Fusion-Template-Id
Fusion-Source
Fusion-Content-Source
Fusion-Content-Id
Fusion-Component-Id
X-Akam-SW-Version
X-Varnish-TTL
X-MS-InvokeApp
X-Vname
X-TtlSet
X-PC
Accept-Ch
X-Url
X-Instart-Request-ID
X-Ruxit-JS-Agent
Edge-Control
X-B3-TraceId
X-Powered-By-Plesk
Verso
X-Mod-Pagespeed
X-Aspnetmvc-Version
SPRequestGuid
Response
X-Middleton-Response
X-Sol
X-D2id
X-Middleton-Display
Display
X-Trace
X-SharePointHealthScore
X-VARITI-CCR
Accept-Ch-Lifetime
RTSS
X-Cdn-Fetch
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Kinja-Build
X-Kinja
X-Exp-Variant
X-Exp-Id
X-GoogleNews-Bot
Service-Worker-Allowed
X-Server-Name
X-GitHub-Request-Id
Pagespeed
SPIisLatency
SPRequestDuration
X-Server-ID
X-Navigation-Version
X-ESI
X-Powered-CMS
X-Debug
X-Abt-Application-Version
X-Vcap-Request-Id
X-CST
Content-MD5
Public-Key-Pins
X-Amz-Server-Side-Encryption
X-Vcache
MS-Author-Via
X-Px
X-Version
X-Upstream
Charset
X-Ah-Environment
X-Amz-Rid
X-Forwarded-Proto
X-NF-Request-ID
DynaTrace
X-Cached
Realpath
X-Shard
X-TTL
Fastly-Restarts
X-Recruiting
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
MicrosoftSharePointTeamServices
X-Ezoic-Cdn
Edge-Cache-Tag
TCN
Arr-Disable-Session-Affinity
X-MSEdge-Ref
X-Pinterest-Rid
Pinterest-Version
Access-Control-Request-Method
X-Shield-Request-Id
X-DynaTrace-JS-Agent
Nginx-Cache
X-SRCache-Fetch-Status
X-SRCache-Store-Status
S
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Ser
X-Goog-Metageneration
X-Fastly-Request-ID
X-XRDS-Location
Front-End-Https
X-Ttl
X-Accel-Expires
X-Amz-Meta-S3cmd-Attrs
X-DIS-Request-ID
X-Goog-Storage-Class
X-Id
X-Client-IP
X-Varnish-Age
X-Element-Page-Cache
X-T
X-Country-Code-Real
X-FTR-DC
X-FTR-Backend
X-FTR-Backend-Server
X-FTR-Cache-Status
X-FTR-Realm
X-FTR-Balancer
X-Mrf-Item-Lastmod
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
X-Mrf-Section-Lastmod
X-FTR-Expires
X-Amzn-Trace-Id
X-RateLimit-Remaining
X-Trafficlayer-App-Scope
X-Trafficlayer-App-Name
X-Webkit-Csp
X-SERVER
X-Dw-Request-Base-Id
Fastcgi-Cache
NR-ENABLED
X-HS-Content-Id
X-HS-Hub-Id
X-Frontend
X-Content-Digest
X-Hits
X-Correlation-Id
Powered
X-Fastcgi-Cache
Cache-Tag
X-Kinsta-Cache
X-Grace
ServerID
X-FTR-Cache-Host
AR-PoweredBy
AR-CACHE
Ar-Sid
AR-ATIME
X-Forwarded-For
X-HS-Cache-Config
X-Litespeed-Cache
TP-Cache
TP-L2-Cache
X-Cache-Hit
X-Oneagent-Js-Injection
X-Node-Name
PB-RID
PB-PID
Alternate-Protocol
X-N
X-Mobile-Rewrite
X-Request-Processing-Time
AMP-Access-Control-Allow-Source-Origin
Arc-Version
X-Request-Received
X-Request-Handler-Origin-Region
X-Hp-Webp
X-Content-Type
X-Microsite
X-Zen-Fury
X-User-Agent
X-Rid
Server-Name
X-Srv
X-Webapp-Samesite-None-Activated-N
Server-Node
X-Analytics
X-Revision
Backend-Timing
Healthy
X-FastCGI-Cache
X-LB-Cache
X-Az
X-AppVersion
X-Content-Security-Policy-Report-Only
X-Activity-Id
Cache-Status
X-Via-JSL
X-Ruxit-Js-Agent
X-Akamai-Edgescape
Retry-After
X-Logged-In
Paypal-Debug-Id
X-IPLB-Instance
AR-Request-ID
X-Amzn-RequestId
X-Type
X-Amz-Apigw-Id
X-Cached-By
X-HS-Combine-CSS
X-NWS-LOG-UUID
X-GUploader-UploadID
X-Pad
X-Varnish-Grace
FilterID
X-Cache-Age
X-B3-Sampled
X-Mobile-URL
X-F-Cache
X-Content-Options
Refresh
X-Geo-Country
X-Tumblr-Pixel
X-Instance
X-FB-Debug
X-Tumblr-Pixel-0
X-Tumblr-User
Accept-Charset
X-Debug-Info
Source
X-Jobs
Host
X-App-Environment
X-Page-Id
X-Cluster
X-Request-Guid
X-AOL-HN
Access-Control-Allow-Method
X-Framework
X-Seen-By
Actual-Object-TTL
X-B
DC
X-PHP-Backend
X-Erf-Bev-Bev-Is-Generated
X-PressLabs-Stats
X-Erf-Bev-Bev
X-Cache-Key
Upgrade-Insecure-Requests
X-Varnish-Backend
X-Whom
MS-CV
X-WebKit-CSP-Report-Only
X-Esi
Fastcgi-Useragent
X-Content-Powered-By
X-ATG-Version
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Cache-2
X-Host-Name
X-TT
X-Git-Hash
X-Cache-Control
X-Cache-TTL
X-Time
Surrogate-Key
X-TA-CDN-Provider
X-Cache-Rule
X-Cache-Operation
X-Amz-Replication-Status
Cache
Frame-Options
X-Wix-Request-Id
X-FW-Type
X-FW-Static
X-Forwarded-Host
X-Kong-Proxy-Latency
X-FW-Hash
X-Kong-Upstream-Latency
X-FW-Server
X-FW-Serve
Accept-CH-Lifetime
X-Signature
X-B-Cache
Xserver
X-Response-Served-From
NGB
X-Origin-Server
X-Mobile
Accept-CH
Host-Header
X-Daa-Tunnel
X-Tumblr-Pixel-2
Cache-Tv-Group
X-Tumblr-Pixel-1
X-GeoIP
WPE-Backend
X-Cache-NE
Webserver
Eomportal-Instance
X-Cache-Action
X-Hyper-Cache
Filters
Payment
X-Drupal-Cache-Tags
X-RequestSource
X-Region
X-TX-ID
X-Adobe-Content
X-Adobe-Loc
X-Handled-By
X-UA-Device-Type
X-Cacheable-TTL
From-Origin
Cleartype
Tracecode
X-App-Server
X-VCache
X-Cache-Enabled
X-ProcessESI
X-RemovedCookies
X-EdgeConnect-Cache-Status
X-Webkit-CSP
X-UA
X-RTag
Ms-Operation-Id
Datacenter
X-Cache-TTL-Remaining
X-RateLimit-Limit
X-Akamai-Transformed
X-Status
X-Contextid
X-NewRelic-App-Data
X-Load-Cache
Liferay-Portal
X-Cache-Server
X-Hostname
X-Edge-Location
X-Yottaa-Metrics
X-BCube-Filmed-By
X-Yottaa-Optimizations
X-TT-TIMESTAMP
X-XRDS-LOCATION
X-Varnish-Hostname
X-FW-Dynamic
Odigeo-Trace-Id
X-Varnish-Server
Server-Info
X-RN-RSRV
Version
X-Path-Route
X-IP
Meta-Geo
X-Cache-Var
Load-Balancing
X-ES-SERVER
X-Cache-Var-Map
X-Rule
X-Xfnlog-Site
X-Viewer-Country
X-PCL
X-OCL
X-Rocket-Nginx-Bypass
X-Debug-Cache
Cache-Tags
X-Cache-Config
Country
X-CCM
DB-Nickname
X-UUID
X-FC-Vary-Parameters
X-TNCMS
Mn-Server-Ip
X-Labrador-Cache-Channel
Azure-InstanceId
X-Hosted-By
Azure-RegionName
Azure-SiteName
Azure-Version
Azure-SlotName
X-From
X-Info
X-Loop
X-Origin
L5d-Success-Class
Property-Id
Fastly-SSL
X-Origin-Hint
S-Rt
X-Proto
Webcakes-App-Version
Webcakes-App-Name
X-Web-Node
X-Origin-TTL
TWC-Privacy
Webcakes-Region
X-Akamai-Request-ID
X-Cache-Host
X-Proxy
X-Origin-CC
X-ServerID
X-Pubstack
TWC-GeoIP-LatLong
TWC-Locale-Group
TWC-GeoIP-Country
X-Real-IP
X-Drupal-Cache-Contexts
Cache-Name
X-Origin-Response-Time
X-Varnish-Cache-Hits
X-Upgrade-Enabled
TWC-Connection-Speed
TWC-Device-Class
X-Via-Fastly
X-R9-Blue-Green-Version
X-EIG-Tracking-Id
X-Backend-Name
X-ApacheServer
X-Cache-Time
X-Cluster-Name
X-Generated
X-Content-Age
X-Format
Origin-Cache-Control
X-FireWall-Port
Origin-Edge-Control
Selected-Fe
S-Cnection
Release
X-Access
Decoy-Debug-TTL
Decoy-Debug-Status
DSUID
Ec-Rule-Version
X-Akamai-Request-ID2
Decoy-Debug-Key
X-JoinUs
X-Proxy-Build
X-Redis-Cache
X-Timing-Wait
X-App-Version
X-VCT
X-Human
X-Rendered-As
X-PERF
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Section
X-Varnish-Hits
X-Vgn-Hpd-Reason
X-Soup
X-Time-Microsecs
Rt-Fastcgi-Cache
X-Storage
Viewport
X-Locale
X-Site-Version
X-Www-Served-By
NGX
X-WA-Info
X-NWS-UUID-VERIFY
Cache-Key
X-Is-Bot
X-ATS-Timestamp
GEO-INFO
X-Guploader-Uploadid
X-ProxyCache-Key
X-ProxyCache-Status
Vix-Hermes-Req-Id
Uber-Trace-Id
X-B3-Traceid
X-BYPASS-REASON
X-Oss-Hash-Crc64ecma
X-Oss-Storage-Class
X-Cache-Grace
X-Oss-Request-Id
X-Oss-Object-Type
Cteonnt-Length
X-GoCache-CacheStatus
X-Oss-Server-Time
Cache-Hits
X-Hit
X-Backend-TTL
X-PHP-Host
Time
X-NCache
X-SS-Set-Cookie
X-Cache-Backend
X-Generated-By
X-Cache-Remote
Origin
X-B3-SpanId
X-Amzn-Remapped-Content-Length
X-Device-Type
X-Trace-Id
X-CS
Akamai-GRN
X-CF-Powered-By
X-Tumblr-Pixel-3
Accept-Language
X-Accel-Buffering
X-ORACLE-APMCS-REQUEST-ID
X-ORACLE-APMCS-TAG
Mime-Version
X-OVcl-Cache
X-OVcl
X-Nginx-Cache-Key
Hostname
X-S
X-UnsetCookies
X-FB-TRIP-ID
X-L-Path
X-No-Session
X-Cluster-Node
X-Environment-Context
X-Via-CDN
X-Uri
Fastcgi-X-Cache-Version
X-MServer
X-Tb
Access-Control-Request-Headers
Now
X-Say-TTL
X-Cdn-Forward
X-SayCDN-TTL
X-Say-Cacheable
X-FW-Version
X-URL
ServerName
User-Cache-Control
Request-EU
X-A
Request-Country
Rendered-Blocks
Rt-Proxy-Cache
T-Server
X-A-Ccd
Node
VivaBuild
Viewtype
Arc-Country
AsisCache
BehaviorPad-Version
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
Apple-News-Services-Host
Content-Script-Type
Content-Style-Type
MD5-Digest
Meta-Geo-Continent
Machine
IsBot
Cross-Origin-Window-Policy
Mobile-Detection-Method
X-Aed
X-ScT
X-Server-Time
X-Session-Fingerprint
X-SIPLIST1
X-S-Cookie
X-Rojux
X-Region-Sid
X-Request-UUID
X-Rewrite-Enabled
X-SRCache-Key
X-Svr
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-VG-WebServer
X-VG-WebCache
X-Transaction
X-Trv-Group
X-Twitter-Response-Tags
X-Processor
X-PAYTM-SRV-ID
X-Application
X-ARC
X-CF-Lambda-Fn
X-AIR-PT
X-Accel-Expires-Debug
X-A-Dcw
X-A-Dgt
X-A-Wwc
X-CF-Lambda-Version
X-Connection-Hash
X-External-Request-Id
X-G
X-Hl-Ver
X-DPWN-IS-SECURE
X-Detected-As
X-D
X-Date
X-Destination
X-A-Dam
X-B-Cookie
X-Tec-Api-Version
OT-Force-Account-Verify
X-Tec-Api-Origin
X-Tec-Api-Root
X-Presslabs-Stats
X-SaId
X-CACHE-KEY
X-CSRF-TOKEN
X-Endurance-Cache-Level
Proxy-Connection
X-Hnp-Log
X-Reboot
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Server-Int
Thinkindot-Control
Server-Host
CDCHOST
X-Thinkindot-L3
X-S-Maxage
X-Request-URI
RNT-Time
RNT-Machine
X-Proxy-Upstream
X-Proxy-Cache-Status
X-Cache-Debug
X-Cache-Bucket
X-Cache-Info
X-Matched-Rule
X-Cms-Context
X-Clara-WADP
X-Block-Status
X-NX-Host
X-Gen-Mode
X-Debug-Cookies
X-Location
X-Debug-Log
X-APP-VERSION
Web-Mar-Node
X-NC
We-Hiring
X-WADP-Cache
Mail-Subject
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
ServedBy
NtCoent-Length
X-Varnish-Beresp-Ttl
X-Backend-State
X-Ms-Version
X-BBXSRF
X-Azure-Ref-OriginShield
X-Azure-Ref
X-App-Name
X-Auto-Login
X-C
X-IN-APIGATEWAY
X-Internal-Host
X-Ms-Request-Id
X-Irp-Debug
X-WebServer
X-Cache-Id
X-We-Are-Hiring
X-Cache-FS-Status
X-IN-APIGATEWAYSSL
X-Amz-Meta-Cache-Control
X-VG-TLSProxy
Wxu-Next-Commit
Wxu-Next-Hostname
W
X-RateLimit-Limit-Second
X-Variation
True-Client-Country-4JS
Wxu-Next-Region
X-7Graus-Varnish-Cache-Control
X-Origin-Date
X-Old-Content-Length
X-Alternate-Cache-Key
X-Origin-Expires
X-Platform-Server
X-7Graus-Varnish-XKeys
X-Policy
X-Cache-URL
X-Cdn-Srv
X-Distributor
X-LI-UUID
X-Li-Pop
X-Distil-CS
X-Has-Esi
X-Dispatch
X-Dispatcher-Server
X-Epic-Correlation-Id
X-Eu-Site
X-JWT-State
X-Generated-In
X-Generated-On
X-Key
X-Level-Front-Cache
X-Li-Fabric
X-Fastly-Cache
X-Developers
X-Developer
X-Hash
X-Compress-Hint
X-Magnolia-Registration
X-User
X-Clientip
X-CGP
X-Is-Gdpr
X-Core-Mission
X-CUA
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Webstats-RespID
X-Debug-Cache-Store
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
X-Generation-Time
X-VServer
HA-Ipaddr
IBM-Web2-Location
Ha-Gx-Prefs
X-Nc
Gh-Request-Id
Is-Eu
Kp-EeAlive
A
Platform
Memcached
Magicmarker
X-Server-IP
X-Service
X-ShardId
X-Sorting-Hat-PodId
Content-Disposition
X-Sorting-Hat-ShopId
Cache-Host
X-TrackingId
X-Skip-Cache
Countrycode
X-Shopify-Stage
X-ShopId
Fastly-Soc-X-Request-Id
Esi-Enabled
Adler-Geo
X-Request-Start
X-SD-PageType
SD-X-WS
X-Release
Section-Io-Cache
Served-By
X-Instart-Isnd
X-Geo
X-Reqid
X-Up
X-RateLimit-Remaining-Second
X-B3-Parentspanid
Cache-Provider
X-Sucuri-Id
X-Parent-Response-Time
X-Owner
Heartbleed
X-LI-Proto
Pramga
AKAMAI
L
X-Swa-Ws
X-Logging-Id
X-MSEdge-Flight
X-Core-Value
X-MSEdge-Features
X-ServiceProvider
X-Thanos
X-VC-Cache
X-Qloud-Router
V-Age
X-Agile-Id
X-Scheme
Locale
X-GeoIP-City
PFcat
X-Geo-Header
X-Bip
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Method
X-Agile
X-Agile-Age
X-Urbn-Context-Path
X-Urbn-Site-Id
Srv
X-Device-Os
X-NodeID
Server-ID
X-Dc
X-Sn-Servicetimems
X-Cdn-Origin
X-Vdms-Version
X-Node-Id
X-Lb-Id
Tcn
X-EC-Lua
X-Shopify-Generated-Cart-Token
Cdnsip
X-Servername
X-Rocket-Build-Number
X-Sigma
X-Sigma-Backend
X-CDN-Forward
Cdncip
GEO-REGION-INFO
X-Sucuri-Cache
X-AK-Request-ID
CF-IPCountry
X-GRACE
Environment
X-FPC
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Unique-Id
X-Newrelic-Synthetics
X-Be
Powered-By-ChinaCache
X-Nginx-Cache
X-Upstream-Ct
X-Upstream-Ht
Request-Time
X-Via-NSCOPI
X-B3-Spanid
X-Zone
X-Tb-Optimization-Total-Bytes-Saved
X-Microcachable
X-Servedbyhost
Resin-Trace
X-Pjax-Url
X-RCS-CacheZone
X-VHOST
X-ND-Cache
X-Source
X-NGENIX-Cache
X-ECACHE
X-Instart-Info
X-ElasticPress-Search
X-Trafficlayer-App-Version
X-GEO
X-Unique-ID
X-Backend-Host
Group
X-Backend-Url
Backend-Name
Locid
X-Var-Ttl
Geo-Info
X-IPS-LoggedIn
Memory
X-Oracle-Dms-Rid
X-Req
X-DC
CF-Cached-On
N-Cache
FNAC-ModuleRouting
X-LJ-Flow-ID
X-Served-From
X-VCL-Version
X-VWS-Id
X-AWS-Id
X-Gamma-Serve
Ohc-File-Size
Ohc-Cache-HIT
X-Dynatrace
SRV
Fly-Cache
Fly-Request-Id
Lfy
X-Refresh
Cache-Prefix
Gannett-Cam-Experience-Id
Pagetype
X-Pf-Uncompressing
X-COUNTRY
X-Correlation-ID
Pics-Label
Cdn
TTL
X-Worker
X-Check-Cacheable
X-Ratelimit-Remaining
Amp-Access-Control-Allow-Source-Origin
X-Upstream-CT
Cf-Ipcountry
X-Upstream-HT
X-TIME
X-CSRF-Token
ProcessTime
X-Cache-Miss-From
X-Sucuri-ID
PICS-Label
Geoip-Latitude
GeoIp-Country-Code
X-Pod
GeoIP-City
X-Sedo-Request-Id
M-TraceId
X-Via-Ucdn
Geoip-City
X-Render-Time
GeoIP-Country-Code
GeoIP-Latitude
X-SRV
X-Bc
X-HTML-Minification-Powered-By
X-Fetched-On
REQUESTUUID
X-Via-Edge
X-Server-W
X-Via-SSL
X-NU-AKA-ACS-Version
Ttl
XServer
PageSpeed
X-Wa
X-Vcl-Version
Fastly-SWR
Fastly-SIE
X-Mode
X-APP
X-Ua
X-GeoIP-Country-Code
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-CLOUD-TRACE-CONTEXT
X-PF-Uncompressing
X-LiteSpeed-Cache-Control
X-Fstrz
X-FORWARDED-FOR
X-ZONE
X-HS-Status
X-HostName
Cache-Cookie-Set-From
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
X-Ratelimit-Limit
X-Upstream-Proxy
X-Tt-Trace-Tag
X-Ratelimit-Reset
X-GDPR
MIME-Version
X-Fastly-Country-Code
X-MP-GENERATED-AT
X-Cache-Tag
HitType
X-Dynatrace-Js-Agent
Pragrma
X-Edge-Server
Cdn-Host
X-ServedByHost
Cdn-Request-Time
On-Server
Host-ID
HostName
User-Agent
X-Swift-Error
X-SN
X-NGINX-Cache
X-WR-MODIFICATION
X-Aicache-OS
X-BC
URI
X-ABtesting
X-BE
X-TT-LOGID
X-Cdn-Request-ID
X-Zipkin-Id
X-Routing-Service
X-WA
SS
X-Proxied
X-PJAX-URL
Who
X-Org
X-Response-By
X-Flog
X-Hello
X-RateLimit-Reset
CACHE
X-Action
X-TH-Server
X-DB
X-RPM
X-DSS
X-RPS
X-RSL
X-DI
X-Fastly-Backend-Reqs
SN
X-UPSTREAM-Address
X-DW
X-Cache-Ttl
X-Edge-O15-RID
Dynatrace
X-Varnish-URL
Powered-By
X-Cf-Powered-By
X-ServerName
Requestid
CDN
X-Fpc
X-LAGOON
X-Varnish-Cacheable
Lb
DataCenter
Country-Code
Get-Access-Time
Is-Session-Tracking
LB
Server-Id
RequestUuid
X-Page-Type
Debug
Media-Length
X-Ftr-Cache-Host
X-VC
X-Nananana
X-LB-ID
X-SB
X-Protected-By
X-Varnish-Beresp-TTL
X-Request-Time
X-Gen-Id
X-Request-Url
XxX-Cache-Status
X-MCACHE
NnCoection
UCS
X-Edge
X-MID
X-Fastly-Cache-Hits
X-LiteSpeed-Tag
Warning
Thinkindot-Cache-Type
X-Dw-Trace-Id
X-Akamai-ERPolicy
X-Amzn-Remapped-Connection
X-Akamai-ERRuleID
X-Li-Proto
RequestId
Application
Product
X-Amzn-Remapped-Date
Xet-Cookie
SID
Correlation-Id
X-Tt-Trace-Host