Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
CF-RAY
CF-Cache-Status
Pragma
Link
X-Powered-By
ETag
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Timer
Access-Control-Allow-Headers
X-Request-Id
X-Xss-Protection
Access-Control-Allow-Methods
X-Download-Options
Alt-Svc
X-AspNet-Version
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
Content-Security-Policy-Report-Only
X-Generator
X-Cache-Status
X-Cacheable
X-Permitted-Cross-Domain-Policies
Timing-Allow-Origin
X-Request-ID
X-DNS-Prefetch-Control
X-Template
X-Language
X-Iinfo
X-Content-Security-Policy
Status
Content-Encoding
X-Buckets
X-AspNetMvc-Version
Upgrade
Access-Control-Expose-Headers
X-Kinja-Server-Push
Xkey
Access-Control-Max-Age
Keep-Alive
X-CDN
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
X-Via
X-Ua-Compatible
X-Cache-Group
X-Age
X-Pass-Why
X-Envoy-Upstream-Service-Time
X-Backend
EagleId
X-Robots-Tag
X-Amz-Request-Id
X-Amz-Id-2
X-AH-Environment
X-Page-Speed
X-Server-Powered-By
X-Pingback
X-UA-Device
X-Swift-CacheTime
X-Swift-SaveTime
X-Proxy-Cache
X-Hacker
X-Nginx-Cache-Status
Ali-Swift-Global-Savetime
X-Server
Request-Context
Grace
X-Varnish-Cache
Server-Timing
Feature-Policy
Cf-Railgun
X-Amz-Version-Id
X-Device
X-LiteSpeed-Cache
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Rq
X-WebKit-CSP
X-Dns-Prefetch-Control
X-Ac
Report-To
EagleEye-TraceId
X-Cdn
X-OneAgent-JS-Injection
X-Server-Id
X-Response-Time
Request-Id
X-Cnection
X-Host
X-Backend-Server
X-DataDome
Content-Location
X-Cloud-Trace-Context
X-Node
X-Readtime
X-Origin-Cache
X-Cache-Lookup
X-Vhost
NEL
X-Application-Context
X-Dispatcher
X-ORACLE-DMS-ECID
X-HW
Allow
X-ORACLE-DMS-RID
X-Clacks-Overhead
X-Rack-Cache
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Origin-Upstream-Status
Surrogate-Control
Rating
X-Country
Pinterest-Generated-By
X-DynaTrace
X-FTR-Request-ID
X-Country-Code
X-Goog-Hash
Fusion-Content-Source
Fusion-Template-Id
Fusion-Source
Fusion-Content-Id
Fusion-Component-Id
Accept-Ch
X-Akam-SW-Version
X-MS-InvokeApp
X-Varnish-TTL
X-TtlSet
X-PC
X-Vname
X-Ruxit-JS-Agent
X-Url
X-Instart-Request-ID
X-Aspnetmvc-Version
X-B3-TraceId
X-Ws-Request-Id
X-Powered-By-Plesk
Edge-Control
Verso
SPRequestGuid
X-Mod-Pagespeed
X-Sol
Response
X-Middleton-Response
X-D2id
X-Middleton-Display
Display
Accept-Ch-Lifetime
X-SharePointHealthScore
X-Kinja-Build
X-Kinja-Revision
X-Kinja-Server
X-Kinja
X-Exp-Variant
X-Use-Magma
X-Trace
X-Cdn-Fetch
X-Exp-Id
X-GoogleNews-Bot
X-VARITI-CCR
X-Server-ID
X-Server-Name
RTSS
X-GitHub-Request-Id
SPIisLatency
SPRequestDuration
X-ESI
Service-Worker-Allowed
X-Navigation-Version
X-CST
X-Powered-CMS
X-Vcap-Request-Id
Pagespeed
X-Abt-Application-Version
X-Debug
Public-Key-Pins
X-Ah-Environment
X-Px
Content-MD5
X-TTL
MS-Author-Via
X-Amz-Server-Side-Encryption
X-Version
X-Upstream
X-Amz-Rid
Realpath
X-NF-Request-ID
Charset
DynaTrace
X-Forwarded-Proto
X-Shard
X-Cached
Fastly-Restarts
TCN
X-Recruiting
X-SERVER
X-Vcache
X-Pinterest-Rid
MicrosoftSharePointTeamServices
Pinterest-Version
X-Ezoic-Cdn
X-MSEdge-Ref
Nginx-Cache
Arr-Disable-Session-Affinity
X-Shield-Request-Id
X-DynaTrace-JS-Agent
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
Access-Control-Request-Method
Edge-Cache-Tag
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-SRCache-Fetch-Status
X-SRCache-Store-Status
S
X-Fastly-Request-ID
X-Ser
Front-End-Https
X-XRDS-Location
X-Accel-Expires
X-DIS-Request-ID
X-Amz-Meta-S3cmd-Attrs
X-Goog-Storage-Class
X-Id
X-T
X-Element-Page-Cache
X-Varnish-Age
X-Client-IP
X-FTR-Realm
X-FTR-DC
X-FTR-Backend
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Balancer
Mrf-Cache-Status
MRF-Tech
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
X-B3-TraceId-Primal
X-FTR-Expires
X-RateLimit-Remaining
X-Ttl
X-Amzn-Trace-Id
X-Dw-Request-Base-Id
NR-ENABLED
Fastcgi-Cache
X-Content-Digest
X-HS-Hub-Id
X-HS-Content-Id
Ar-Sid
AR-CACHE
AR-PoweredBy
X-Frontend
Powered
AR-ATIME
X-Trafficlayer-App-Scope
X-Trafficlayer-App-Name
X-Hits
X-Correlation-Id
X-Grace
X-Forwarded-For
ServerID
X-Fastcgi-Cache
X-Litespeed-Cache
X-Kinsta-Cache
X-FTR-Cache-Host
Cache-Tag
TP-L2-Cache
TP-Cache
X-Node-Name
X-Cache-Hit
X-Webkit-Csp
X-HS-Cache-Config
AMP-Access-Control-Allow-Source-Origin
X-Content-Type
X-Request-Received
PB-RID
X-Request-Processing-Time
PB-PID
X-N
X-Mobile-Rewrite
X-Zen-Fury
Arc-Version
X-Srv
X-Request-Handler-Origin-Region
X-Microsite
X-FastCGI-Cache
Alternate-Protocol
X-Hp-Webp
Server-Node
X-Rid
Healthy
X-User-Agent
X-LB-Cache
Server-Name
X-Revision
X-Via-JSL
AR-Request-ID
X-Analytics
Backend-Timing
Paypal-Debug-Id
X-Az
X-Activity-Id
X-AppVersion
Cache-Status
X-Webapp-Samesite-None-Activated-N
Retry-After
X-Logged-In
X-Content-Security-Policy-Report-Only
X-Akamai-Edgescape
X-IPLB-Instance
X-Oneagent-Js-Injection
X-GUploader-UploadID
X-Type
X-NWS-LOG-UUID
X-Cached-By
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Cache-Age
X-Varnish-Grace
X-Ruxit-Js-Agent
FilterID
X-Pad
X-HS-Combine-CSS
X-B3-Sampled
X-VCache
Refresh
X-Content-Options
X-Mobile-URL
X-Instance
Accept-Charset
X-F-Cache
X-Tumblr-User
X-Seen-By
X-Tumblr-Pixel
X-FB-Debug
X-Tumblr-Pixel-0
X-Jobs
X-Request-Guid
X-PHP-Backend
X-Page-Id
X-App-Environment
DC
Actual-Object-TTL
X-Geo-Country
X-AOL-HN
X-B
X-Debug-Info
X-Cluster
X-Framework
Source
Host
Access-Control-Allow-Method
X-Whom
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
MS-CV
X-Content-Powered-By
Upgrade-Insecure-Requests
X-Cache-Key
Fastcgi-Useragent
X-Varnish-Backend
VIX-Pulpo-Node
X-WebKit-CSP-Report-Only
VIX-Pulpo-Upstream-Status
X-Host-Name
X-Cache-2
X-ATG-Version
X-Git-Hash
X-PressLabs-Stats
X-Time
X-TT
X-Cache-Control
X-Forwarded-Host
X-TA-CDN-Provider
X-Cache-Rule
X-Esi
X-Cache-Operation
X-Cache-TTL
Surrogate-Key
X-Amz-Replication-Status
X-FW-Serve
X-FW-Hash
X-Wix-Request-Id
X-Kong-Upstream-Latency
X-FW-Static
X-FW-Type
X-FW-Server
X-Kong-Proxy-Latency
Frame-Options
Cache
X-Daa-Tunnel
X-Mobile
X-Response-Served-From
Tracecode
NGB
X-Origin-Server
Host-Header
X-RemovedCookies
X-ProcessESI
Cache-Tv-Group
X-B-Cache
X-Signature
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
WPE-Backend
X-UA-Device-Type
X-Cache-Action
X-Drupal-Cache-Tags
X-Handled-By
X-Cacheable-TTL
Webserver
X-Hyper-Cache
X-Region
X-GeoIP
Cleartype
X-RequestSource
X-Cache-NE
Payment
Filters
Eomportal-Instance
X-App-Server
X-Adobe-Loc
From-Origin
X-Adobe-Content
X-Webkit-CSP
X-TX-ID
Xserver
X-RTag
Ms-Operation-Id
X-Cache-Enabled
X-EdgeConnect-Cache-Status
Datacenter
Accept-CH-Lifetime
X-RateLimit-Limit
X-Cache-TTL-Remaining
X-Status
X-Akamai-Transformed
X-UA
X-Contextid
Accept-CH
X-Hostname
X-NewRelic-App-Data
X-Cache-Server
X-BCube-Filmed-By
Liferay-Portal
X-TT-TIMESTAMP
X-XRDS-LOCATION
X-Load-Cache
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Edge-Location
Odigeo-Trace-Id
X-FW-Dynamic
Version
Server-Info
X-IP
X-Varnish-Hostname
X-RN-RSRV
Meta-Geo
Load-Balancing
X-Path-Route
X-Cache-Var-Map
GEO-INFO
X-Cache-Var
X-ES-SERVER
X-Varnish-Server
X-UUID
X-Info
X-R9-Blue-Green-Version
DB-Nickname
X-CCM
X-Rule
Azure-InstanceId
Azure-RegionName
Cache-Tags
Country
Fastly-SSL
Cache-Name
Azure-Version
Azure-SlotName
Azure-SiteName
Webcakes-Region
X-Origin-Hint
X-Origin
X-OCL
X-Loop
X-Drupal-Cache-Contexts
X-Debug-Cache
X-Real-IP
X-ServerID
X-TNCMS
X-Upgrade-Enabled
X-Varnish-Cache-Hits
X-Human
X-Hosted-By
X-From
X-FC-Vary-Parameters
X-EIG-Tracking-Id
X-Rocket-Nginx-Bypass
X-Labrador-Cache-Channel
X-Via-Fastly
X-Web-Node
X-Pubstack
X-Proxy
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-Country
TWC-GeoIP-LatLong
S-Rt
Release
Origin-Cache-Control
Origin-Edge-Control
Property-Id
TWC-Locale-Group
TWC-Privacy
X-Cache-Time
X-PCL
X-Origin-Response-Time
X-Proto
X-Cache-Host
X-Cache-Config
Webcakes-App-Name
Webcakes-App-Version
X-Akamai-Request-ID
Mn-Server-Ip
L5d-Success-Class
X-Content-Age
X-FireWall-Port
X-Format
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Cluster-Name
X-JoinUs
X-Access
Ec-Rule-Version
Selected-Fe
Viewport
X-Locale
X-Backend-Name
X-Proxy-Build
X-Vgn-Hpd-Reason
X-Viewer-Country
X-Www-Served-By
X-Xfnlog-Site
X-VCT
X-Timing-Wait
X-Rendered-As
X-Section
X-Site-Version
X-Soup
DSUID
X-Generated
X-Redis-Cache
X-App-Version
S-Cnection
X-Cache-Grace
X-Akamai-Request-ID2
X-ApacheServer
X-PERF
X-Varnish-Hits
Rt-Fastcgi-Cache
Decoy-Debug-TTL
X-WA-Info
Decoy-Debug-Key
Decoy-Debug-Status
X-Time-Microsecs
X-Origin-TTL
X-Origin-CC
NGX
X-NWS-UUID-VERIFY
Cache-Key
Cache-Hits
Cteonnt-Length
X-Storage
X-Is-Bot
X-Cache-Remote
X-GoCache-CacheStatus
Vix-Hermes-Req-Id
X-Hit
Uber-Trace-Id
X-BYPASS-REASON
X-ProxyCache-Key
X-ProxyCache-Status
X-Backend-TTL
X-NCache
Time
X-Trace-Id
X-SS-Set-Cookie
Origin
Hostname
X-CF-Powered-By
X-Guploader-Uploadid
X-Cache-Backend
X-CS
X-Device-Type
X-PHP-Host
X-Tec-Api-Origin
X-Generated-By
X-UnsetCookies
X-Tumblr-Pixel-3
Mime-Version
X-Tec-Api-Version
X-B3-SpanId
X-Tec-Api-Root
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Amzn-Remapped-Content-Length
X-Oss-Storage-Class
X-Oss-Server-Time
X-ATS-Timestamp
X-Oss-Request-Id
X-OVcl-Cache
X-OVcl
Akamai-GRN
Accept-Language
X-S
X-Presslabs-Stats
X-Cluster-Node
X-Via-CDN
X-Nginx-Cache-Key
X-FB-TRIP-ID
X-Accel-Buffering
Fastcgi-X-Cache-Version
X-Uri
X-L-Path
X-B3-Traceid
X-URL
X-Environment-Context
X-ORACLE-APMCS-TAG
X-ORACLE-APMCS-REQUEST-ID
X-No-Session
X-FW-Version
X-Cdn-Forward
X-MServer
Now
X-Tb
X-CACHE-KEY
OT-Force-Account-Verify
Access-Control-Request-Headers
ServerName
MD5-Digest
Machine
Arc-Country
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
IsBot
Meta-Geo-Continent
Mobile-Detection-Method
AsisCache
Content-Script-Type
Content-Style-Type
X-SayCDN-TTL
X-Say-Cacheable
A
Xc-Version
X-Say-TTL
BehaviorPad-Version
Cross-Origin-Window-Policy
Apple-News-Services-Handled
Apple-News-Services-Host
X-A-Dgt
X-Detected-As
X-Svr
X-SRCache-Key
X-Developer
X-DPWN-IS-SECURE
X-Destination
X-Date
X-CF-Lambda-Version
X-Connection-Hash
X-Transaction
X-D
X-External-Request-Id
X-G
X-S-Cookie
X-Rojux
X-ScT
X-Server-Time
X-SIPLIST1
X-Rewrite-Enabled
X-Request-UUID
X-Hl-Ver
X-PAYTM-SRV-ID
X-Processor
X-Region-Sid
X-CF-Lambda-Fn
X-B-Cookie
T-Server
X-VG-WebServer
Viewtype
VivaBuild
X-A
Rt-Proxy-Cache
Request-EU
Node
Rendered-Blocks
X-Vtex-Processado-Em
Request-Country
X-A-Ccd
X-A-Dam
X-Application
X-ARC
X-Twitter-Response-Tags
X-Trv-Group
X-AIR-PT
X-VG-WebCache
X-Session-Fingerprint
X-A-Wwc
X-Accel-Expires-Debug
X-Aed
X-Vtex-Remote-Cache
X-A-Dcw
X-APP-VERSION
X-CSRF-TOKEN
X-Nc
X-Varnish-Beresp-Status
X-Varnish-Beresp-Ttl
User-Cache-Control
X-Varnish-Beresp-Grace
X-NC
X-Cdn-Origin
X-Sn-Servicetimems
X-Cache-Info
Thinkindot-Control
X-S-Maxage
ServedBy
X-Generated-On
X-Reboot
Server-Host
Thinkindot-CacheControl
X-NX-Host
Thinkindot-CacheControl-Type
X-Cache-Debug
We-Hiring
Server-Int
Mail-Subject
X-Debug-Cookies
X-Level-Front-Cache
X-Debug-Log
X-Location
X-Device-Os
X-Thinkindot-L3
X-Node-Id
X-Cache-Bucket
X-Instart-Isnd
X-Matched-Rule
X-Sorting-Hat-ShopId
X-Alternate-Cache-Key
X-Sorting-Hat-PodId
X-ShardId
X-ShopId
X-Shopify-Stage
X-Parent-Response-Time
X-Endurance-Cache-Level
NtCoent-Length
X-B3-Parentspanid
X-Amz-Meta-Cache-Control
X-Agile-Id
X-Developers
X-Auto-Login
X-Azure-Ref-OriginShield
X-Azure-Ref
X-Agile-Age
X-App-Name
X-Dispatcher-Server
X-Eu-Site
X-Fastly-Cache
X-Gen-Mode
X-Epic-Correlation-Id
X-Distributor
X-Backend-State
X-Distil-CS
X-Dispatch
X-Block-Status
X-Compress-Hint
X-Cache-URL
X-Core-Mission
X-Cms-Context
X-Clientip
X-Clara-WADP
X-Cdn-Srv
X-CUA
X-Cache-Id
X-C
X-CGP
X-Bip
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Cache-FS-Status
X-Debug-Cache-Expiry
X-BBXSRF
X-Key
X-Skip-Cache
X-Service
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Swa-Ws
X-Server-IP
X-SD-PageType
X-Reqid
X-Release
X-Request-Start
X-Request-URI
X-Scheme
X-Thanos
X-TrackingId
X-WebServer
X-We-Are-Hiring
X-Webstats-RespID
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-WADP-Cache
X-VServer
X-User
X-Up
X-Variation
X-VC-Cache
X-VG-TLSProxy
X-Qloud-Router
X-Proxy-Upstream
X-Is-Gdpr
X-Irp-Debug
X-JWT-State
X-Agile
X-Li-Fabric
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-GeoIP-City
X-Geo-Header
X-Has-Esi
X-Hash
X-Hnp-Log
X-Li-Pop
X-LI-UUID
X-Origin-Expires
X-Origin-Date
X-Owner
X-Platform-Server
X-Proxy-Cache-Status
X-Old-Content-Length
X-Ms-Version
X-Logging-Id
X-Magnolia-Registration
X-Method
X-Ms-Request-Id
X-Generation-Time
X-Internal-Host
Memcached
PFcat
Magicmarker
L
Kp-EeAlive
Platform
Pramga
Section-Io-Cache
Served-By
SD-X-WS
RNT-Time
RNT-Machine
IBM-Web2-Location
Heartbleed
CDCHOST
X-SaId
Cache-Host
AKAMAI
Adler-Geo
Content-Disposition
Countrycode
Ha-Gx-Prefs
HA-Ipaddr
Gh-Request-Id
Fastly-Soc-X-Request-Id
Esi-Enabled
True-Client-Country-4JS
Is-Eu
X-7Graus-Varnish-XKeys
Wxu-Next-Region
Web-Mar-Node
Wxu-Next-Commit
Wxu-Next-Hostname
X-7Graus-Varnish-Cache-Control
W
Proxy-Connection
Cache-Provider
X-Generated-In
X-LI-Proto
X-RateLimit-Remaining-Second
X-Dc
X-RateLimit-Limit-Second
X-Policy
X-MSEdge-Features
X-MSEdge-Flight
X-Sucuri-Id
X-Lb-Id
X-Urbn-Context-Path
X-NodeID
X-Core-Value
X-Urbn-Site-Id
Locale
X-ServiceProvider
V-Age
X-Geo
X-Vdms-Version
X-Servername
Server-ID
CF-IPCountry
X-GRACE
X-EC-Lua
Request-Time
GEO-REGION-INFO
Srv
X-Sucuri-Cache
X-Newrelic-Synthetics
X-CDN-Forward
Environment
X-Shopify-Generated-Cart-Token
X-ECACHE
X-NGENIX-Cache
X-Sigma
X-Rocket-Build-Number
X-Be
X-Sigma-Backend
X-GEO
X-FPC
X-B3-Spanid
X-Instart-Info
X-Planisys-CDN-TTL
X-Unique-Id
X-Pjax-Url
X-VHOST
X-Planisys-CDN-Rules
Cdnsip
Cdncip
X-Planisys-CDN-Cache
X-AK-Request-ID
X-ElasticPress-Search
X-Upstream-Ht
X-Microcachable
X-Via-NSCOPI
X-Upstream-Ct
Tcn
X-Servedbyhost
X-Backend-Url
X-Tb-Optimization-Total-Bytes-Saved
Resin-Trace
Group
X-Backend-Host
Powered-By-ChinaCache
X-Nginx-Cache
PageSpeed
X-Var-Ttl
X-ND-Cache
Backend-Name
Ohc-Cache-HIT
Ohc-File-Size
X-Source
X-Unique-ID
SRV
X-Oracle-Dms-Rid
N-Cache
X-RCS-CacheZone
X-Trafficlayer-App-Version
X-Zone
Memory
X-IPS-LoggedIn
Fly-Request-Id
Lfy
Cache-Prefix
CF-Cached-On
Pagetype
Fly-Cache
X-Dynatrace
X-Upstream-HT
X-DC
X-Upstream-CT
X-Check-Cacheable
X-VCL-Version
X-COUNTRY
Locid
X-Worker
Cdn
X-Served-From
Gannett-Cam-Experience-Id
X-Correlation-ID
Amp-Access-Control-Allow-Source-Origin
X-Via-Ucdn
X-Gamma-Serve
X-Req
X-LJ-Flow-ID
TTL
X-AWS-Id
X-VWS-Id
X-Pf-Uncompressing
X-Ratelimit-Remaining
X-Refresh
X-CSRF-Token
X-Ua
X-Sedo-Request-Id
GeoIp-Country-Code
X-Cache-Miss-From
Pics-Label
Geoip-City
Cf-Ipcountry
X-Pod
FNAC-ModuleRouting
Geoip-Latitude
X-Sucuri-ID
XServer
PICS-Label
X-Server-W
X-Fetched-On
X-Rebelmouse-Surrogate-Control
GeoIP-Latitude
GeoIP-Country-Code
X-Via-Edge
M-TraceId
Fastly-SWR
X-Rebelmouse-Cache-Control
X-Via-SSL
REQUESTUUID
X-Wa
Fastly-SIE
GeoIP-City
X-Upstream-Proxy
Ttl
X-APP
Geo-Info
X-TIME
X-Bc
X-Render-Time
X-Ratelimit-Reset
X-Datadome
X-PF-Uncompressing
X-CLOUD-TRACE-CONTEXT
X-Ratelimit-Limit
X-Fstrz
X-ZONE
X-NU-AKA-ACS-Version
X-Vcl-Version
X-HS-Status
X-Tt-Trace-Tag
X-LiteSpeed-Cache-Control
X-SRV
X-GDPR
ProcessTime
X-GeoIP-Country-Code
X-HTML-Minification-Powered-By
X-Mode
X-Fastly-Country-Code
Cdn-Request-Time
Cdn-Host
Cache-Cookie-Set-From
X-Edge-Server
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-Idcheck
X-Dynatrace-Js-Agent
X-SN
Pragrma
X-Aicache-OS
User-Agent
X-NGINX-Cache
X-Cache-Tag
MIME-Version
X-HostName
X-Swift-Error
X-Flog
Host-ID
URI
X-ABtesting
On-Server
X-FORWARDED-FOR
X-WR-MODIFICATION
SS
X-ServedByHost
X-Org
X-BC
HitType
X-Hello
X-Response-By
X-WA
X-MP-GENERATED-AT
X-TT-LOGID
Who
CACHE
X-RateLimit-Reset
X-UPSTREAM-Address
X-BE
Requestid
X-Cache-Ttl
X-RPM
X-DSS
SN
X-DI
X-PJAX-URL
X-Action
X-DB
X-DW
HostName
X-RPS
X-Edge-O15-RID
X-Fastly-Backend-Reqs
X-RSL
Dynatrace
Country-Code
X-LAGOON
X-Page-Type
X-Fpc
RequestUuid
X-Varnish-Cacheable
X-Cf-Powered-By
X-Varnish-URL
X-Cdn-Request-ID
Lb
DataCenter
X-ServerName
Debug
CDN
X-Proxied
LB
Is-Session-Tracking
Get-Access-Time
X-Routing-Service
X-TH-Server
X-Zipkin-Id
Server-Id
X-Ftr-Cache-Host
X-VC
X-SB
X-MCACHE
X-Tt-Trace-Host
X-Nananana
X-MID
X-Edge
X-Varnish-Beresp-TTL
UCS
X-Gen-Id
X-Protected-By
Powered-By
Processtime
NnCoection
X-Request-Url
Media-Length
RequestId
Warning
X-LiteSpeed-Tag
X-Akamai-ERPolicy
X-LB-ID
Correlation-Id
X-Request-Time
Xet-Cookie
X-Akamai-ERRuleID
X-Amzn-Remapped-Connection
SID
X-Fastly-Cache-Hits
Application
X-Li-Proto
Thinkindot-Cache-Type
X-Amzn-Remapped-Date
X-Dw-Trace-Id
Product