Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Link
X-Powered-By
CF-Cache-Status
Pragma
ETag
CF-RAY
Expect-CT
Via
Age
X-Cache
X-XSS-Protection
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-Xss-Protection
P3P
Referrer-Policy
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-UA-Compatible
X-Served-By
Alt-Svc
X-Request-Id
X-Varnish
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Check
Content-Security-Policy-Report-Only
X-Adblock-Key
X-Generator
CF-Ray
X-Permitted-Cross-Domain-Policies
X-Cache-Status
X-Cacheable
X-DNS-Prefetch-Control
X-Kinja-Server-Push
Timing-Allow-Origin
X-Template
X-Language
X-FRAME-OPTIONS
X-Ua-Compatible
X-AspNetMvc-Version
X-Iinfo
Status
X-Buckets
X-Content-Security-Policy
X-CDN
Upgrade
Content-Encoding
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Envoy-Upstream-Service-Time
Keep-Alive
X-Request-ID
X-Via
X-Drupal-Dynamic-Cache
X-Ws-Request-Id
X-Server
X-Turbo-Charged-By
X-AH-Environment
X-Backend
X-Age
X-Cache-Group
Xkey
X-Robots-Tag
Feature-Policy
X-Proxy-Cache
X-Amz-Request-Id
X-Amz-Id-2
Request-Context
X-Hacker
X-Page-Speed
X-UA-Device
EagleId
X-Server-Powered-By
X-Nginx-Cache-Status
X-Pingback
Grace
X-Varnish-Cache
Server-Timing
P3p
X-LiteSpeed-Cache
Report-To
X-Swift-CacheTime
X-Swift-SaveTime
X-WebKit-CSP
Ali-Swift-Global-Savetime
X-Amz-Version-Id
Cf-Railgun
X-Server-Id
X-Rq
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-OneAgent-JS-Injection
X-Origin-Cache
X-Host
EagleEye-TraceId
X-Device
Surrogate-Control
X-Response-Time
X-Vhost
X-Backend-Server
X-Dns-Prefetch-Control
X-Cache-Lookup
X-Ac
X-Node
X-Pass-Why
X-Origin-Upstream-Status
X-Readtime
X-Dispatcher
X-HW
Fusion-Template-Id
Fusion-Component-Id
Fusion-Content-Source
Fusion-Source
Fusion-Content-Id
Request-Id
X-DataDome
X-Mod-Pagespeed
X-Application-Context
Content-Location
X-Akam-SW-Version
X-ORACLE-DMS-ECID
X-Ruxit-JS-Agent
Fusion-Deployment-Id
X-ORACLE-DMS-RID
X-Country
NEL
Allow
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Rating
X-Country-Code
X-Clacks-Overhead
Edge-Control
X-Cnection
X-Url
X-Rack-Cache
X-Px
X-Cloud-Trace-Context
X-FTR-Request-ID
X-Goog-Hash
RTSS
X-PC
X-TtlSet
X-Vname
MS-Author-Via
X-Powered-By-Plesk
Verso
X-DynaTrace
X-Ttl
Accept-CH
Public-Key-Pins
X-B3-TraceId
X-GitHub-Request-Id
Service-Worker-Allowed
X-GoogleNews-Bot
X-Exp-Variant
X-Cdn-Fetch
X-Kinja
X-Exp-Id
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Kinja-Build
Response
Pagespeed
Display
X-MS-InvokeApp
X-Middleton-Display
X-Sol
X-Amz-Server-Side-Encryption
X-Middleton-Response
Arr-Disable-Session-Affinity
X-Forwarded-Proto
X-Varnish-TTL
X-Cache-TTL
Accept-CH-Lifetime
X-D2id
X-Abt-Application-Version
TCN
X-CST
Pinterest-Generated-By
X-Amz-Rid
X-Cached
Accept-Ch
X-Vcap-Request-Id
X-NF-Request-ID
X-VARITI-CCR
X-Content-Type
X-Navigation-Version
Nel
X-Fastly-Request-ID
Cache-Tag
X-Server-Name
X-Instart-Request-ID
X-Accel-Expires
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-ESI
Accept-Ch-Lifetime
X-MSEdge-Ref
X-Version
Nginx-Cache
Access-Control-Request-Method
AR-ATIME
AR-PoweredBy
X-Grace
S
AR-Request-ID
Charset
X-Debug
SPRequestDuration
SPIisLatency
X-Upstream
AR-CACHE
Ar-Sid
X-Powered-CMS
X-SharePointHealthScore
SPRequestGuid
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Client-IP
X-Trace
X-DynaTrace-JS-Agent
Pinterest-Version
X-Pinterest-Rid
X-FastCGI-Cache
X-Ezoic-Cdn
Realpath
Content-MD5
X-Mrf-Item-Lastmod
X-Element-Page-Cache
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
X-Dw-Request-Base-Id
X-Id
X-Jurisdiction
X-Hp-Webp
X-Recruiting
X-Amz-Meta-S3cmd-Attrs
X-Node-Name
X-Shield-Request-Id
Fastcgi-Cache
X-T
X-ASPNET-VERSION
X-Content-Digest
X-Kinsta-Cache
X-Logged-In
X-NWS-LOG-UUID
X-Mobile-URL
X-FTR-Cache-Status
X-FTR-DC
X-FTR-Realm
X-FTR-Balancer
X-FTR-Backend-Server
Server-Node
X-Frontend
X-FTR-Backend
Edge-Cache-Tag
X-Country-Code-Real
X-XRDS-Location
X-Request-Processing-Time
X-Request-Received
X-Cache-Hit
TP-L2-Cache
X-Goog-Generation
X-Goog-Storage-Class
X-GUploader-UploadID
X-Goog-Stored-Content-Length
TP-Cache
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Cache-Age
X-FTR-Expires
Front-End-Https
Server-Name
DynaTrace
Fastly-Restarts
X-Forwarded-For
X-Hostname
ServerID
X-Amzn-Trace-Id
PB-RID
Arc-Version
PB-PID
X-Zen-Fury
X-DIS-Request-ID
Powered
X-Microsite
X-Request-Handler-Origin-Region
Backend-Timing
X-ATS-Timestamp
X-Content-Security-Policy-Report-Only
X-Mobile-Rewrite
X-User-Agent
X-Revision
X-HS-Hub-Id
X-Hits
X-HS-Cache-Config
X-HS-Combine-CSS
X-HS-Content-Id
X-F-Cache
X-Akamai-Edgescape
Accept-Charset
X-Oneagent-Js-Injection
X-Cdn
X-Jobs
X-LB-Cache
X-Cache-Key
X-Page-Id
X-FTR-Cache-Host
X-Fastcgi-Cache
X-Geo-Country
Filters
X-ORACLE-APMCS-TAG
X-ORACLE-APMCS-REQUEST-ID
AMP-Access-Control-Allow-Source-Origin
X-Content-Powered-By
MicrosoftSharePointTeamServices
X-Via-JSL
X-Varnish-Age
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-TTL
X-Origin-Server
X-B
X-Ser
Alternate-Protocol
X-Rid
X-N
X-Yandex-Sdch-Disable
X-Varnish-Backend
X-Erf-Bev-Bev-Is-Generated
X-Daa-Tunnel
Host-Header
X-Erf-Bev-Bev
X-Esi
X-Debug-Info
X-XRDS-LOCATION
X-Az
DC
X-WebKit-CSP-Report-Only
X-Activity-Id
X-Git-Hash
X-AppVersion
X-Amz-Replication-Status
X-Server-ID
X-Type
X-App-Server
Retry-After
Frame-Options
X-ATG-Version
Paypal-Debug-Id
X-FB-Debug
X-Contextid
Section-Io-Cache
Actual-Object-TTL
X-Varnish-Grace
Cache-Tags
X-Signature
X-B-Cache
X-TT
Fastcgi-Useragent
X-Correlation-Id
X-App-Environment
X-Whom
X-Request-Guid
Surrogate-Key
X-AOL-HN
X-Edge
X-Content-Options
X-Status
X-Seen-By
X-RateLimit-Remaining
Host
Source
Healthy
X-Ruxit-Js-Agent
X-Cache-Action
X-Host-Name
X-B3-Sampled
NR-ENABLED
Refresh
WPE-Backend
X-Instance
X-HTML-Minification-Powered-By
X-Pinterest-Direct
X-IPLB-Instance
X-Upgrade-Enabled
X-Endurance-Cache-Level
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel
X-ECACHE
From-Origin
Access-Control-Allow-Method
X-APP-VERSION
X-Response-Served-From
X-Cache-Rule
X-Accel-Buffering
X-Drupal-Cache-Tags
X-Cache-Operation
X-RemovedCookies
X-ProcessESI
Payment
Odigeo-Trace-Id
X-Rule
X-Cacheable-TTL
VIX-Pulpo-Upstream-Status
X-Cache-Control
X-MCACHE
VIX-Pulpo-Node
X-Mid
X-UUID
X-FW-Static
X-FW-Server
X-FW-Type
X-L-Path
X-FW-Serve
X-FW-Dynamic
Eomportal-Instance
X-Amz-Apigw-Id
X-Cache-Time
X-Environment-Context
MS-CV
X-FW-Hash
X-Varnish-Server
X-Region
Datacenter
Countrycode
Cache-Status
X-Is-Bot
X-Rendered-As
X-Adobe-Content
X-WA-Info
Xserver
X-Adobe-Loc
X-URL
X-Correlation-ID
X-Protected-By
X-GeoIP
X-Amzn-RequestId
X-Wix-Request-Id
X-Cluster
NGB
X-RequestSource
X-SERVER-NAME
Content-Disposition
X-Akamai-Transformed
X-Cache-Server
Srv
X-Yottaa-Optimizations
X-Cached-By
X-VCache
Filterid
X-Presslabs-Stats
X-Yottaa-Metrics
X-EdgeConnect-Cache-Status
X-PressLabs-Stats
Uber-Trace-Id
X-Akamai-Request-ID2
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
X-UnsetCookies
Version
X-Unique-Id
X-Origin-Response-Time
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-IPS-LoggedIn
Upgrade-Insecure-Requests
X-Mobile
X-Load-Cache
Access-Control-Request-Headers
X-Mode
X-Vcache
Liferay-Portal
X-PHP-Backend
X-Time
X-Handled-By
X-Proxy
X-Cache-Remote
X-FireWall-Port
X-Time-Microsecs
Cross-Origin-Window-Policy
Meta-Geo
X-CCM
X-Adobe-Source
X-Cache-Var-Map
X-RN-RSRV
X-Cache-Status-Check
X-Cache-Var
X-ES-SERVER
X-Framework
X-Storage
X-Via-Fastly
X-PCL
X-Path-Route
X-OCL
X-No-Session
X-Viewer-Country
X-MP-GENERATED-AT
Cache
X-SayCDN-TTL
Decoy-Debug-Key
Decoy-Debug-Status
X-Backend-Name
X-Say-Cacheable
X-Say-TTL
Accept-Language
Akamai-GRN
Cache-Hits
X-Cache-Config
X-Redis-Cache
X-Locale
X-NGENIX-Cache
X-NYM-Debug-Backend
X-Pubstack
X-PERF
X-LJ-Flow-ID
X-Human
Webserver
ServedBy
X-ApacheServer
X-AWS-Id
X-FW-Version
X-BCube-Filmed-By
Fastly-SSL
Decoy-Debug-TTL
X-VWS-Id
X-Xfnlog-Site
X-Www-Served-By
X-UA-Device-Type
X-Site-Version
X-TX-ID
X-Access
Cache-Name
Section-Io-Origin-Status
X-BYPASS-REASON
S-Rt
X-RTag
Section-Io-Id
Cleartype
Section-Io-Origin-Time-Seconds
Origin-Edge-Control
Now
Ms-Operation-Id
X-FC-Vary-Parameters
Section-Origin-Responded
Mn-Server-Ip
Origin-Cache-Control
X-Cache-NGX
X-Hyper-Cache
X-Real-IP
X-NCache
X-TNCMS
X-Loop
X-Section
X-Origin
X-ProxyCache-Status
X-R9-Blue-Green-Version
X-Web-Node
X-Format
X-ProxyCache-Key
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Device-Class
TWC-Locale-Group
X-Proxied
TWC-Connection-Speed
X-Origin-Hint
Webcakes-App-Version
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Hl-Ver
X-Cache-Enabled
X-CS
X-Device-Type
X-Bc-Bl
X-Routing-Service
X-FB-TRIP-ID
Webcakes-App-Name
X-Info
Webcakes-Region
X-Amzn-Remapped-Content-Length
X-ServerID
TWC-Privacy
X-Azure-Ref
Property-Id
X-Zipkin-Id
X-Generated
X-Hosted-By
X-Timing-Wait
X-From
X-Sorting-Hat-ShopId
X-Source
X-EIG-Tracking-Id
X-JoinUs
X-ShopId
X-ShardId
X-UPSTREAM-Address
X-Proxy-Build
X-Shopify-Stage
X-Alternate-Cache-Key
X-Sorting-Hat-PodId
X-IP
X-Detected-As
Ec-Rule-Version
Country
DSUID
DB-Nickname
X-SaId
Selected-Fe
Azure-InstanceId
X-Geo
Azure-RegionName
X-Varnish-Cache-Hits
Azure-SlotName
Azure-Version
X-Cache-NE
Azure-SiteName
X-CLOUD-TRACE-CONTEXT
X-CSRF-Token
SD-X-WS
X-Cluster-Node
X-Content-Age
X-Old-Content-Length
X-NWS-UUID-VERIFY
X-Labrador-Cache-Channel
X-NewRelic-App-Data
X-CDN-Forward
X-PHP-Host
X-Backend-TTL
X-Qloud-Router
X-Varnish-Hostname
Cache-Tv-Group
Time
Load-Balancing
X-Pad
User-Agent
X-Cache-Host
X-Litespeed-Cache
X-Air-Hostname
S-Cnection
X-EC-Lua
X-Cache-TTL-Remaining
X-Drupal-Cache-Contexts
X-Cache-Backend
X-RCS-CacheZone
FilterID
X-Parent-Response-Time
X-Cache-2
X-Microcachable
X-Proxy-Cache-Status
X-Urbn-Context-Path
Locale
X-Forwarded-Host
X-Urbn-Site-Id
X-Ua
X-Cache-Grace
Server-Info
X-NC
X-UA
X-Tumblr-Pixel-3
X-RateLimit-Limit
X-Akamai-Request-ID
Tracecode
X-Release
X-TIME
OT-Force-Account-Verify
Proxy-Connection
X-Debug-Cache
Sid
X-FORWARDED-FOR
X-Soup
X-Vgn-Hpd-Reason
NGX
X-SRV
X-Dc
Cache-Key
X-Tb
X-Newrelic-Synthetics
X-Ms-Version
X-NodeID
X-Ms-Request-Id
X-Connection-Hash
X-Date
Server-Host
X-Destination
T-Server
X-D
ServerName
True-Client-Country-4JS
X-Rewrite-Enabled
X-Request-UUID
X-Rojux
X-S
X-CF-Lambda-Version
VivaBuild
X-Reqid
X-Processor
X-Developer
UCS
X-Region-Sid
X-Uri
X-PAYTM-SRV-ID
X-S-Cookie
X-External-Request-Id
Meta-Geo-Continent
Fastcgi-X-Cache-Version
Mobile-Detection-Method
MD5-Digest
GEO-REGION-INFO
X-Generated-On
M-TraceId
X-Geo-Header
Machine
X-Instart-Info
Content-Style-Type
Arc-Country
Rendered-Blocks
X-Dispatch
X-DevSite-Last-Modified
AsisCache
BehaviorPad-Version
Content-Script-Type
CDCHOST
X-Level-Front-Cache
Pagetype
X-G
Viewtype
X-Aed
X-Scheme
X-Agile
X-Vdms-Path
X-User
X-Twitter-Response-Tags
X-Trace-Id
X-Transaction
X-Trv-Group
X-Accel-Expires-Debug
X-B-Cookie
X-Vtex-Remote-Cache
X-VG-WebCache
X-ARC
X-Application
X-VG-WebServer
X-Agile-Id
X-Agile-Age
X-Vdms-Version
X-Vtex-Processado-Em
GEO-INFO
X-A-Dgt
X-A-Wwc
X-Session-Fingerprint
Xc-Version
X-Worker
X-A-Dcw
X-ServiceProvider
X-CF-Lambda-Fn
X-ScT
X-Magnolia-Registration
Who
X-A
X-Skip-Cache
X-SRCache-Key
X-A-Dam
X-A-Ccd
X-Srv
User-Cache-Control
X-Proto
L5d-Success-Class
X-Cache-Bucket
X-Cache-Info
Kp-EeAlive
X-Eu-Site
X-Cache-FS-Status
X-Block-Status
X-Backend-State
Magicmarker
X-Fmm-Version
X-Branch-Name
Memcached
Mail-Subject
Rt-Fastcgi-Cache
X-Cache-Tags
V-Age
X-CGP
X-Clara-WADP
Viewport
IsBot
We-Hiring
Web-Mar-Node
Vix-Hermes-Req-Id
X-Clientip
X-Cms-Context
Platform
On-Server
NM-Fastcgi-Cache
X-Epic-Correlation-Id
X-Distil-CS
X-Core-Value
X-Cache-PHP
X-Dispatcher-Server
N-Cache
X-LAGOON
X-VG-TLSProxy
X-Logging-Id
X-Method
X-Micro-Cache
Node
X-Location
X-Via-PopH
X-WADP-Cache
X-SN
X-Swa-Ws
X-Via-PopV
X-Node-Id
Is-Eu
X-Cluster-Name
X-Reboot
X-Servername
X-Thanos
X-TA-CDN-Provider
X-TT-TIMESTAMP
X-Variation
X-VC-Cache
X-Owner
X-Platform-Server
X-Varnish-Cacheable
Adler-Geo
AKAMAI
X-Hash
X-Has-Esi
FNAC-ModuleRouting
X-Hit
X-Hnp-Log
X-Wikidot-Static-Cache
X-Generation-Time
X-Gen-Mode
X-Generated-In
HA-Ipaddr
Ha-Gx-Prefs
Fastly-Drupal-HTML
Esi-Enabled
X-SIPLIST1
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-We-Are-Hiring
Apple-News-Services-Handled
Apple-News-Services-Request-Url
C-Via
X-Wikidot-Backend
X-Is-Gdpr
X-JWT-State
X-Bip
X-SD-PageType
Geo-Info
X-Envoy-Decorator-Operation
Apigw-Requestid
X-Webstats-RespID
X-VServer
X-TrackingId
X-Thinkindot-L3
X-Origin-Date
X-Device-Os
X-Li-Pop
X-Developers
X-LI-UUID
X-Li-Fabric
X-Distributor
X-GoCache-CacheStatus
X-Irp-Debug
X-Envoy-Upstream-Healthchecked-Cluster
X-Matched-Rule
X-Mvc-Supplant-Cachable
X-Request-Host
X-Server-W
X-Cache-URL
X-Req
X-Rebelmouse-Surrogate-Control
X-Origin-Expires
X-Policy
X-Rebelmouse-Cache-Control
X-Slack-Backend
X-Fastly-Cache
Thinkindot-CacheControl-Type
RNT-Machine
W
Wxu-Next-Commit
Thinkindot-CacheControl
Release
RNT-Time
X-BBXSRF
Gh-Request-Id
Server-ID
Cache-Cookie-Set-From
Thinkindot-Control
Cache-Cookie-Set-Idcheck
Fastly-SIE
Fastly-SWR
X-Backend-Host
Cache-Cookie-Set-Lfrom
X-Auto-Login
Wxu-Next-Region
L
Wxu-Next-Hostname
Cf-Ipcountry
X-LI-Proto
Cache-Host
X-Var-Ttl
X-RateLimit-Remaining-Second
X-Refresh
X-Be
X-Response-By
X-Server-IP
X-Nginx-Cache-Key
X-Varnish-Authentication
X-Core-Mission
X-App
X-Contensis-Viewer-Groups
X-RateLimit-Limit-Second
X-App-Name
X-Cache-ASPX
Sever-Int
Server-Ext
Server-Hostname
X-DC
X-VCT
CacheControlHeader
X-Compress-Hint
Ohc-File-Size
X-Wa
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-Mvc-Supplant-OutputCached
X-Cdn-Srv
X-Nc
X-S-Maxage
Server-Surrogate-Control
X-Generated-By
X-TH-Server
Server-Cache-Control
X-FPC
HostName
X-Sucuri-ID
X-Esi-Check
X-Gzip
Memory
X-Cache-Id
X-Bc
X-Zone
NtCoent-Length
X-Cache-Debug
X-Origin-CC
X-B3-Traceid
X-Origin-TTL
X-CACHE-KEY
LB
SRV
X-AIR-PT
Ohc-Response-Time
X-Rocket-Nginx-Bypass
X-Configured-By
X-NU-AKA-ACS-Version
X-Loc
X-Webkit-CSP
X-Varnish-Ttl
X-MSEdge-Features
X-BC
Request-Country
Request-EU
X-MSEdge-Flight
Locid
X-ZONE
X-Key
Heartbleed
CACHE
X-Storefront-Renderer-Rendered
X-Request-URI
X-Edge-Location
X-Debug-Panamera-Host
X-SVT-ORM-VERSION
X-Shopify-Generated-Cart-Token
X-Debug-Panamera-Sitecode
X-Svr
X-SVT-ORM-RULES
X-CF-Powered-By
X-Varnish-Hits
Pragrma
X-COUNTRY
X-Pjax-Url
X-Amzn-Requestid
MIME-Version
X-Servedbyhost
X-Varnish-URL
X-Gamma-Serve
WZWS-RAY
Resin-Trace
X-Nginx-Cache
FSS-Cache
X-Batcache
X-VCL-Version
Referer-Policy
X-GEO
Fastly-Backend-Name
X-Cdn-Forward
X-WebServer
GeoIp-Country-Code
X-Up
Geoip-Latitude
X-App-Version
X-Minions-Version
Product
X-BACKEND-TTL
X-Proxy-Upstream
Lfy
X-NGINX-Cache
Hostname
X-Sucuri-Cache
X-BE
X-Sn-Servicetimems
GeoIP-Country-Code
X-Aicache-OS
Cteonnt-Length
My-App
X-Fetched-On
X-Cdn-Origin
Mime-Version
HitType
X-ND-Cache
X-ElasticPress-Query
X-Vcl-Version
GeoIP-Latitude
X-GeoIP-Country-Code
X-Via-CDN
X-ServedByHost
CF-Cached-On
X-Edge-Server
Cdn-Request-Time
Cdn-Host
Powered-By-ChinaCache
X-Ratelimit-Remaining
X-PJAX-URL
X-Varnish-Url
X-HS-Status
SN
Ohc-Cache-HIT
X-CSRF-TOKEN
X-Shard
X-Oss-Storage-Class
X-Oss-Server-Time
X-Oss-Object-Type
DCR-Decision-By
DCR-Processing-Time-Ms
X-Oss-Hash-Crc64ecma
X-Fastly-Country-Code
X-Oss-Request-Id
X-ECache
X-Unique-ID
X-Check-Cacheable
X-Azure-Ref-OriginShield
X-Request-Start
Amp-Access-Control-Allow-Source-Origin
X-Fastly-Backend-Reqs
X-Served-From
X-PF-Uncompressing
Location
Pramga
X-Ratelimit-Limit
X-Fastly-Cache-Status
X-Pf-Uncompressing
Group
X-B3-Spanid
X-CACHE-AGE
Cdn
URI
X-LB-ID
X-Via-Ucdn
X-Newrelic-App-Data
Dt-Cache-Category
X-Request-Time
Country-Code
X-IN-APIGATEWAYSSL
CloudFront-Viewer-Country
X-Fpc
XServer
X-IN-APIGATEWAY
X-Via-NSCOPI
X-VarnishDD-TTL
X-OVcl-Cache
X-OVcl
PFcat
X-Swift-Error
X-Tec-Api-Origin
X-Tec-Api-Root
X-Debug-Cache-Store
A
X-Tec-Api-Version
X-Vgn-Hpd-Variations-Key
X-DPWN-IS-SECURE
X-Vgn-Hpd-Cached
X-Vgn-Hpd-Ssi
Cf-Alt-Svc
X-Debug-Cache-Fetch
Geoip-City
X-B3-SpanId
CF-IPCountry
X-Instart-Isnd
X-Tb-Optimization-Total-Bytes-Saved
X-Platform
PICS-Label
X-Varnish-Beresp-TTL
X-C
Origin
X-Ocache
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Render-Time
X-WR-MODIFICATION
X-WPE-Loopback-Upstream-Addr
Lb
Proxy-Firewall
X-Apw-Hits
X-Country-IP
WWW-Authenticate
X-Cache-Tag
X-Cache-Expired-At
X-Apw-Access-Token
X-Apw-Access-Object
X-Sigma
Server-Ttl
X-StackifyID
Host-ID
X-Apw-Access-Action
X-WA
X-Sigma-Backend
Request-Time
X-Debug-Cache-Status
X-Debug-Cache-Bypass
SID
X-Debug-Ysi-Auth
X-Debug-Do-Not-Cache-Uri
X-Debug-Xas-Auth
X-Debug-Cache-String
X-Ratelimit-Reset
X-APP
X-Rocket-Build-Number
X-LiteSpeed-Cache-Control
X-Varnishpool
X-Ftr-Cache-Host
X-Cache-Hfrom
X-RPM
Cloudfront-Viewer-Country
NnCoection
X-RSL
X-RPS
TTL
X-Acquia-Purge-Tags
X-Acquia-Site
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-Cache-Hm
X-Action
Cneonction
Region
X-DW
X-DB
X-DI
X-DSS
Req-ID
X-Varnish-ID
X-B3-Parentspanid
X-VC
X-SB
X-Dw-Trace-Id
X-Nananana
X-Html-Edge-Cache
X-Request-URL
X-Akamai-ERRuleID
X-Akamai-ERPolicy
X-ElasticPress-Search
X-Li-Proto