Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
CF-Cache-Status
Pragma
Link
CF-RAY
X-Powered-By
ETag
Expect-CT
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Xss-Protection
X-Varnish
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
Alt-Svc
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-FRAME-OPTIONS
X-Drupal-Cache
X-Adblock-Key
X-Request-ID
X-Check
X-Generator
Content-Security-Policy-Report-Only
X-Cache-Status
X-Permitted-Cross-Domain-Policies
X-Cacheable
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Iinfo
X-Template
X-Language
X-AspNetMvc-Version
Status
X-Content-Security-Policy
X-Buckets
Content-Encoding
Access-Control-Expose-Headers
X-CDN
Upgrade
Xkey
Access-Control-Max-Age
Keep-Alive
X-Drupal-Dynamic-Cache
X-Kinja-Server-Push
X-Turbo-Charged-By
CF-Ray
X-Via
X-AH-Environment
X-Age
X-Cache-Group
X-Pass-Why
X-Backend
X-Ua-Compatible
X-Envoy-Upstream-Service-Time
EagleId
X-Server
X-Robots-Tag
X-Amz-Id-2
X-Amz-Request-Id
X-Page-Speed
X-Pingback
X-Server-Powered-By
X-UA-Device
X-Proxy-Cache
X-Swift-CacheTime
X-Swift-SaveTime
X-Hacker
X-Nginx-Cache-Status
Ali-Swift-Global-Savetime
Request-Context
X-Varnish-Cache
Grace
Server-Timing
Feature-Policy
Cf-Railgun
X-Amz-Version-Id
X-LiteSpeed-Cache
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-WebKit-CSP
X-Rq
Report-To
X-Server-Id
EagleEye-TraceId
X-Dns-Prefetch-Control
X-Ac
X-Response-Time
X-Host
X-OneAgent-JS-Injection
Request-Id
X-Cnection
X-Backend-Server
X-Node
X-DataDome
X-Ws-Request-Id
Content-Location
X-Origin-Cache
X-Cache-Lookup
X-Cloud-Trace-Context
NEL
X-Readtime
X-Vhost
X-Application-Context
X-Dispatcher
X-HW
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
P3p
X-Cdn
Allow
X-Clacks-Overhead
X-Rack-Cache
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Origin-Upstream-Status
Surrogate-Control
X-DynaTrace
X-Country
Rating
Fusion-Content-Id
Fusion-Source
Fusion-Template-Id
Fusion-Component-Id
Fusion-Content-Source
X-FTR-Request-ID
X-Akam-SW-Version
X-Country-Code
X-Goog-Hash
X-Ruxit-JS-Agent
X-Varnish-TTL
X-Instart-Request-ID
Pinterest-Generated-By
X-TtlSet
X-Vname
X-PC
Edge-Control
X-Mod-Pagespeed
X-MS-InvokeApp
X-Url
Verso
X-B3-TraceId
SPRequestGuid
X-Powered-By-Plesk
Accept-Ch
X-ESI
X-D2id
X-Trace
X-VARITI-CCR
X-SharePointHealthScore
Pagespeed
X-Server-Name
Response
X-Middleton-Response
X-Sol
Service-Worker-Allowed
Display
X-GitHub-Request-Id
X-Middleton-Display
X-Exp-Variant
X-Cdn-Fetch
X-Use-Magma
X-Kinja
X-Kinja-Build
X-GoogleNews-Bot
X-Kinja-Server
X-Exp-Id
X-Kinja-Revision
RTSS
Content-MD5
SPIisLatency
SPRequestDuration
X-Server-ID
X-Navigation-Version
X-TTL
X-Abt-Application-Version
X-Powered-CMS
X-Debug
X-Vcache
X-Amz-Server-Side-Encryption
X-Upstream
X-Forwarded-Proto
Charset
Public-Key-Pins
Accept-Ch-Lifetime
X-Cached
X-Vcap-Request-Id
MS-Author-Via
X-CST
DynaTrace
X-Version
X-NF-Request-ID
X-Amz-Rid
Realpath
X-Px
Edge-Cache-Tag
MicrosoftSharePointTeamServices
X-Shard
TCN
Arr-Disable-Session-Affinity
X-Trafficlayer-App-Scope
X-Trafficlayer-App-Name
X-Ezoic-Cdn
X-XRDS-Location
Access-Control-Request-Method
Pinterest-Version
X-Pinterest-Rid
X-Shield-Request-Id
X-DynaTrace-JS-Agent
X-MSEdge-Ref
X-Ser
Fastly-Restarts
X-SRCache-Store-Status
X-SRCache-Fetch-Status
S
X-Fastly-Request-ID
X-Accel-Expires
X-DIS-Request-ID
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Goog-Generation
Front-End-Https
X-Client-IP
X-Recruiting
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Amz-Meta-S3cmd-Attrs
X-Id
X-Goog-Storage-Class
X-Element-Page-Cache
X-T
Nginx-Cache
X-Varnish-Age
Mrf-Cache-Status
X-Country-Code-Real
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-DC
X-FTR-Backend-Server
X-FTR-Backend
X-B3-TraceId-Primal
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
MRF-Tech
X-FTR-Realm
Cache-Tag
X-Amzn-Trace-Id
X-FTR-Expires
X-Dw-Request-Base-Id
X-Webapp-Samesite-None-Activated-N
X-Ttl
Fastcgi-Cache
X-Frontend
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Content-Id
X-Content-Digest
NR-ENABLED
X-Fastcgi-Cache
Powered
X-Hits
X-Correlation-Id
X-Kinsta-Cache
Alternate-Protocol
X-Hp-Webp
X-FTR-Cache-Host
X-RateLimit-Remaining
ServerID
X-Aspnetmvc-Version
X-Request-Received
X-Request-Processing-Time
X-HS-Combine-CSS
X-Request-Handler-Origin-Region
Server-Name
X-N
X-Cache-Hit
X-Microsite
X-Content-Type
X-Webkit-Csp
X-Node-Name
TP-Cache
TP-L2-Cache
PB-PID
X-User-Agent
X-Grace
PB-RID
X-Mobile-Rewrite
X-Rid
Healthy
Arc-Version
X-Akamai-Edgescape
X-Revision
X-Analytics
Backend-Timing
X-Forwarded-For
X-Content-Security-Policy-Report-Only
AMP-Access-Control-Allow-Source-Origin
Accept-CH
X-Zen-Fury
X-Logged-In
Accept-CH-Lifetime
Server-Node
X-LB-Cache
X-Pad
X-Mobile-URL
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Az
X-Activity-Id
X-GUploader-UploadID
X-AppVersion
Cache-Status
X-NWS-LOG-UUID
X-Cached-By
X-Varnish-Grace
X-FastCGI-Cache
X-B3-Sampled
X-Oneagent-Js-Injection
X-IPLB-Instance
X-Content-Options
Refresh
X-F-Cache
Retry-After
Upgrade-Insecure-Requests
X-Type
AR-ATIME
AR-PoweredBy
AR-CACHE
X-Geo-Country
FilterID
X-Ruxit-Js-Agent
X-App-Environment
X-Tumblr-Pixel
Source
X-Tumblr-Pixel-0
X-Tumblr-User
X-FB-Debug
X-Varnish-Backend
X-Request-Guid
X-Jobs
X-Debug-Info
X-Framework
X-Instance
Access-Control-Allow-Method
Paypal-Debug-Id
X-PHP-Backend
X-Cluster
X-Page-Id
Host
Accept-Charset
DC
Actual-Object-TTL
X-AOL-HN
X-WebKit-CSP-Report-Only
X-Litespeed-Cache
X-Cache-2
X-Srv
X-B
X-Cache-Age
X-ATG-Version
X-Erf-Bev-Bev
Ar-Sid
X-Erf-Bev-Bev-Is-Generated
X-Seen-By
Cache
X-TT
X-Via-JSL
Fastcgi-Useragent
X-Cache-Key
MS-CV
X-Git-Hash
X-Content-Powered-By
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Cache-TTL
X-Whom
X-PressLabs-Stats
X-B-Cache
X-Signature
X-Amz-Replication-Status
X-UA
X-TA-CDN-Provider
Host-Header
X-Daa-Tunnel
X-Wix-Request-Id
X-Cache-Control
AR-Request-ID
X-Response-Served-From
NGB
Surrogate-Key
X-Cache-Enabled
X-Host-Name
X-RequestSource
X-Mobile
X-GeoIP
X-Origin-Server
Cache-Tv-Group
Frame-Options
X-Tumblr-Pixel-1
WPE-Backend
X-Handled-By
Filters
X-TX-ID
X-Tumblr-Pixel-2
X-Region
Payment
Eomportal-Instance
Cleartype
X-FW-Serve
X-FW-Static
X-FW-Hash
X-Cache-Action
X-Hyper-Cache
X-EdgeConnect-Cache-Status
X-Drupal-Cache-Tags
X-FW-Type
X-Cacheable-TTL
X-FW-Server
X-Adobe-Loc
X-Adobe-Content
X-Cache-NE
X-Kong-Proxy-Latency
X-Cache-Operation
X-Cache-Rule
Webserver
X-Kong-Upstream-Latency
X-Hostname
X-NewRelic-App-Data
Xserver
X-SERVER
From-Origin
X-ATS-Timestamp
X-UA-Device-Type
Datacenter
X-Esi
X-RemovedCookies
X-Load-Cache
X-ProcessESI
X-Akamai-Transformed
X-Forwarded-Host
X-Cache-TTL-Remaining
X-Edge-Location
Ms-Operation-Id
X-RTag
Liferay-Portal
X-Cache-Server
X-App-Server
X-Status
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Contextid
X-Varnish-Server
X-Time
X-Rule
X-Varnish-Hostname
X-Oss-Storage-Class
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-VCache
Country
Odigeo-Trace-Id
X-Upgrade-Enabled
X-TT-TIMESTAMP
X-ORACLE-APMCS-REQUEST-ID
X-BCube-Filmed-By
X-ORACLE-APMCS-TAG
X-RN-RSRV
Tracecode
X-ES-SERVER
X-Path-Route
Load-Balancing
X-UUID
Meta-Geo
X-Cache-Var
X-Cache-Var-Map
X-Xfnlog-Site
DSUID
X-Rocket-Nginx-Bypass
X-R9-Blue-Green-Version
Cache-Tags
X-OCL
X-PCL
X-VCT
Mn-Server-Ip
X-CCM
Release
X-Debug-Cache
X-Cache-Config
X-Viewer-Country
Selected-Fe
DB-Nickname
Fastly-SSL
TWC-Connection-Speed
X-From
L5d-Success-Class
NGX
X-Cache-Host
X-Real-IP
X-Human
X-Hosted-By
X-Soup
X-TNCMS
X-Timing-Wait
X-Pubstack
X-Proxy-Build
X-Origin-Hint
X-Loop
X-Origin-Response-Time
X-Proto
X-Proxy
X-Goog-Meta-Goog-Reserved-File-Mtime
X-FC-Vary-Parameters
TWC-Privacy
Webcakes-App-Name
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-GeoIP-Country
Webcakes-App-Version
Webcakes-Region
X-Web-Node
X-Vgn-Hpd-Reason
X-EIG-Tracking-Id
X-Akamai-Request-ID2
X-Akamai-Request-ID
TWC-Device-Class
Property-Id
X-Redis-Cache
X-PERF
X-Locale
Origin-Cache-Control
Origin-Edge-Control
X-ApacheServer
X-Section
Ec-Rule-Version
X-Content-Age
X-ServerID
X-Labrador-Cache-Channel
Decoy-Debug-TTL
X-Format
X-Drupal-Cache-Contexts
Version
X-FW-Dynamic
X-Generated
S-Cnection
S-Rt
X-IP
Viewport
X-Site-Version
Azure-Version
X-Via-Fastly
X-NWS-UUID-VERIFY
Azure-SiteName
Azure-RegionName
X-Access
X-Www-Served-By
Azure-InstanceId
Cache-Name
Azure-SlotName
Decoy-Debug-Key
Decoy-Debug-Status
Server-Info
X-Origin
X-Cluster-Name
X-FireWall-Port
X-Backend-Name
X-Is-Bot
X-Cache-Time
X-Rendered-As
X-JoinUs
X-Time-Microsecs
X-ProxyCache-Status
X-ProxyCache-Key
X-BYPASS-REASON
Uber-Trace-Id
X-Varnish-Cache-Hits
X-Storage
X-XRDS-LOCATION
X-Tec-Api-Version
X-Accel-Buffering
X-Cache-Backend
X-Varnish-Hits
X-Tec-Api-Origin
X-Info
X-Tec-Api-Root
X-Generated-By
X-PHP-Host
X-Origin-TTL
X-Origin-CC
X-B3-Traceid
Akamai-GRN
Rt-Fastcgi-Cache
X-Amzn-Remapped-Content-Length
X-App-Version
Time
X-WA-Info
X-RateLimit-Limit
X-URL
Cache-Key
X-Geo
X-SaId
Cteonnt-Length
X-Nginx-Cache-Key
X-Presslabs-Stats
X-CF-Powered-By
X-No-Session
Origin
X-MServer
X-Cache-Remote
GEO-INFO
X-L-Path
X-Environment-Context
Cache-Hits
Accept-Language
X-GoCache-CacheStatus
Vix-Hermes-Req-Id
X-Guploader-Uploadid
X-Tb
X-FB-TRIP-ID
X-Trace-Id
Access-Control-Request-Headers
X-Hit
X-Say-TTL
X-NCache
X-SS-Set-Cookie
X-Backend-TTL
X-Say-Cacheable
X-SayCDN-TTL
Srv
X-Unique-Id
X-APP-VERSION
X-CACHE-KEY
X-B3-SpanId
X-Device-Type
X-CDN-Forward
X-CS
X-Shopify-Generated-Cart-Token
X-ShardId
X-Alternate-Cache-Key
X-ShopId
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Shopify-Stage
X-CSRF-TOKEN
X-Tumblr-Pixel-3
X-Parent-Response-Time
X-SRV
NtCoent-Length
X-S
X-Cluster-Node
User-Cache-Control
X-EC-Lua
X-OVcl-Cache
X-OVcl
ServedBy
X-Aed
Node
X-RCS-CacheZone
Rendered-Blocks
Mobile-Detection-Method
X-Accel-Expires-Debug
Meta-Geo-Continent
X-Application
IsBot
Content-Script-Type
Content-Style-Type
Fastcgi-X-Cache-Version
X-B-Cookie
X-ARC
Request-Country
MD5-Digest
Machine
X-AIR-PT
AsisCache
Xc-Version
Rt-Proxy-Cache
Apple-News-Services-Handled
Apple-News-Services-Host
VivaBuild
Server-Host
X-CF-Lambda-Fn
Viewtype
T-Server
X-A
Apple-News-Services-Parsed-Url
X-A-Dgt
X-A-Wwc
Request-EU
X-A-Dcw
Arc-Country
X-A-Ccd
Apple-News-Services-Request-Url
X-A-Dam
BehaviorPad-Version
X-Detected-As
X-SRCache-Key
X-Svr
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
X-SIPLIST1
X-Region-Sid
X-Service
X-Session-Fingerprint
X-VG-WebServer
X-Transaction
X-Trv-Group
X-Processor
X-PAYTM-SRV-ID
X-Twitter-Response-Tags
X-Vdms-Version
Cross-Origin-Window-Policy
X-VG-WebCache
X-G
X-Hl-Ver
X-Server-Time
OT-Force-Account-Verify
X-S-Cookie
X-Date
X-External-Request-Id
X-CF-Lambda-Version
X-Cache-Grace
X-Rojux
X-Destination
X-DPWN-IS-SECURE
X-Request-UUID
X-ScT
X-Connection-Hash
X-Rewrite-Enabled
X-D
X-Endurance-Cache-Level
ServerName
X-Magnolia-Registration
X-Source
X-Dc
Server-Int
Served-By
X-Proxy-Upstream
X-Reboot
Thinkindot-CacheControl
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Thinkindot-L3
X-Proxy-Cache-Status
X-Matched-Rule
X-Gen-Mode
X-Debug-Log
X-Generated-On
X-Hash
X-Hnp-Log
X-Debug-Cookies
X-Webstats-RespID
X-Cache-Bucket
X-Block-Status
X-Core-Value
X-CUA
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Ms-Request-Id
X-Cache-Info
X-Ms-Version
X-NX-Host
Thinkindot-Control
Web-Mar-Node
Wxu-Next-Commit
X-Instart-Isnd
X-Level-Front-Cache
X-Location
Wxu-Next-Hostname
Thinkindot-CacheControl-Type
Wxu-Next-Region
Mime-Version
CDCHOST
X-Ah-Environment
Proxy-Connection
X-B3-Parentspanid
X-Azure-Ref
X-Azure-Ref-OriginShield
X-Origin-Date
X-Origin-Expires
X-App-Name
We-Hiring
X-BBXSRF
X-Eu-Site
Mail-Subject
X-Bip
X-Method
X-Agile-Id
X-Backend-State
X-Agile
X-Request-URI
X-Reqid
X-Rocket-Build-Number
X-Scheme
W
X-Fastly-Cache
X-Qloud-Router
X-Planisys-CDN-Cache
X-C
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Policy
X-Agile-Age
X-Logging-Id
X-Varnish-Beresp-Status
X-Uri
X-Varnish-Beresp-Ttl
X-Generated-In
X-Irp-Debug
X-Developers
X-Has-Esi
X-Distil-CS
X-Varnish-Beresp-Grace
X-Dispatcher-Server
X-Dispatch
X-GeoIP-City
X-Is-Gdpr
X-Upstream-Ct
X-CGP
X-Key
X-Cache-URL
X-Server-IP
X-Cache-Debug
X-Clara-WADP
X-Clientip
X-Core-Mission
X-Upstream-Ht
X-JWT-State
X-Compress-Hint
X-Cms-Context
X-Geo-Header
X-Release
X-VC-Cache
Now
Memcached
Magicmarker
X-VServer
X-User
PFcat
X-TrackingId
Cache-Host
X-Up
Pramga
L
Kp-EeAlive
X-Wikidot-Backend
X-We-Are-Hiring
X-Wikidot-Static-Cache
Fastly-Soc-X-Request-Id
Countrycode
Ha-Gx-Prefs
HA-Ipaddr
Content-Disposition
X-WADP-Cache
IBM-Web2-Location
Heartbleed
X-Thanos
X-VG-TLSProxy
X-Sucuri-Cache
Section-Io-Cache
X-Swa-Ws
X-SVT-ORM-RULES
AKAMAI
RNT-Machine
RNT-Time
X-Sigma-Backend
X-SVT-ORM-VERSION
X-Sigma
X-Nc
Cache-Provider
X-Via-CDN
X-TIME
X-Request-Start
Adler-Geo
X-Li-Fabric
Locale
X-Li-Pop
Is-Eu
X-Internal-Host
X-SD-PageType
Gh-Request-Id
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Cdn-Srv
X-Skip-Cache
X-Debug-Cache-Expiry
X-S-Maxage
Esi-Enabled
X-Urbn-Context-Path
X-Platform-Server
Platform
X-ND-Cache
X-Urbn-Site-Id
X-Auto-Login
X-Owner
X-ServiceProvider
X-Epic-Correlation-Id
X-Amz-Meta-Cache-Control
X-FW-Version
X-NodeID
SD-X-WS
X-Cache-Id
X-WebServer
X-LI-UUID
X-Via-NSCOPI
X-Distributor
X-Variation
True-Client-Country-4JS
X-Generation-Time
X-MSEdge-Flight
V-Age
X-MSEdge-Features
Cdnsip
X-AK-Request-ID
X-NC
X-Old-Content-Length
X-Cache-FS-Status
Cdncip
X-LI-Proto
Hostname
X-GRACE
X-Cdn-Forward
X-Trafficlayer-App-Version
X-Servername
Powered-By-ChinaCache
Server-ID
X-B3-Spanid
X-UnsetCookies
Environment
X-Lb-Id
X-Be
X-7Graus-Varnish-Cache-Control
X-7Graus-Varnish-XKeys
GEO-REGION-INFO
CF-IPCountry
X-Sucuri-Id
FNAC-ModuleRouting
X-Newrelic-Synthetics
Locid
X-Req
X-Served-From
X-Nginx-Cache
X-HTML-Minification-Powered-By
X-Developer
X-Refresh
X-Gamma-Serve
A
X-FPC
Geo-Info
X-Servedbyhost
X-Microcachable
X-VHOST
X-Device-Os
X-Sn-Servicetimems
X-Cdn-Origin
X-Edge-O15-RID
X-Sucuri-ID
X-Node-Id
Tcn
ProcessTime
X-Webkit-CSP
X-IPS-LoggedIn
X-Tb-Optimization-Total-Bytes-Saved
X-Render-Time
Memory
X-Zone
X-NU-AKA-ACS-Version
X-VWS-Id
X-Pjax-Url
X-GeoIP-Country-Code
X-AWS-Id
X-MP-GENERATED-AT
X-Mode
X-LJ-Flow-ID
Request-Time
X-Ratelimit-Remaining
X-Pf-Uncompressing
X-FORWARDED-FOR
XServer
X-DC
X-VCL-Version
Gannett-Cam-Experience-Id
Resin-Trace
X-COUNTRY
X-Correlation-ID
X-ZONE
Geoip-Latitude
X-Proxied
GeoIp-Country-Code
Pics-Label
Group
X-Routing-Service
X-Zipkin-Id
Amp-Access-Control-Allow-Source-Origin
MIME-Version
CF-Cached-On
GeoIP-Latitude
Cf-Ipcountry
Geoip-City
GeoIP-Country-Code
TTL
X-Instart-Info
X-ElasticPress-Search
X-Unique-ID
X-ECACHE
X-Pod
PICS-Label
Cache-Cookie-Set-Lfrom
X-CSRF-Token
X-Via-SSL
X-Via-Edge
X-Var-Ttl
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-From
X-Backend-Url
X-Bc
M-TraceId
X-Backend-Host
GeoIP-City
Backend-Name
X-NGENIX-Cache
Host-ID
Ttl
Cdn
X-BC
HostName
X-CLOUD-TRACE-CONTEXT
Ohc-Cache-HIT
Ohc-File-Size
X-Cdn-Request-ID
Pagetype
X-Check-Cacheable
X-Request-Time
N-Cache
REQUESTUUID
X-APP
X-Vcl-Version
X-PF-Uncompressing
Lfy
X-Ratelimit-Limit
X-Swift-Error
HitType
Fly-Request-Id
X-TH-Server
Fly-Cache
Cache-Prefix
X-PJAX-URL
X-NGINX-Cache
X-Fstrz
X-Worker
X-Via-Ucdn
X-Fastly-Country-Code
URI
X-Dynatrace-Js-Agent
X-UPSTREAM-Address
X-Cache-Miss-From
X-GEO
Pragrma
X-Sedo-Request-Id
X-Cache-Tag
Powered-By
On-Server
X-Tt-Trace-Tag
User-Agent
X-LiteSpeed-Cache-Control
X-HostName
X-ServedByHost
X-WR-MODIFICATION
X-Fetched-On
CDN
Media-Length
X-Server-W
X-HS-Status
SRV
X-Upstream-CT
Who
X-Aicache-OS
Fastly-SIE
X-Upstream-HT
X-WA
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Wa
Fastly-SWR
AR-SID
X-BE
X-Tt-Trace-Host
X-Hp-Ccpa-Warning
FSS-Proxy
X-Varnish-URL
X-LB-ID
X-Fpc
X-TT-LOGID
UCS
X-Varnish-Cacheable
FSS-Cache
X-LAGOON
X-Cf-Powered-By
DataCenter
X-Fastly-Backend-Reqs
Debug
X-GDPR
X-Cache-Tags
Server-Id
X-ServerName
X-Store
Processtime
X-Ftr-Cache-Host
X-NYM-Debug-Backend
X-Ua
X-SN
Cdn-Host
X-Protected-By
Cdn-Request-Time
Country-Code
X-Akamai-ERRuleID
X-Edge-Server
X-Varnish-Beresp-TTL
X-Akamai-ERPolicy
X-Varnish-Authentication
NnCoection
X-Flog
Server-Surrogate-Control
X-SB
WP-Super-Cache
X-VC
Xet-Cookie
Server-Cache-Control
Cneonction
X-Contensis-Viewer-Groups
X-Cache-ASPX
XxX-Cache-Status
X-Nananana
X-Li-Proto
X-RPM
X-RPS
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
X-Dw-Trace-Id
X-RateLimit-Reset
X-RSL
Warning
SS
Requestid
LB
Is-Session-Tracking
Get-Access-Time
X-ABtesting
X-Action
X-DI
X-Hello
Product
X-DSS
X-Request-Url
Application
X-Fastly-Cache-Hits
X-LiteSpeed-Tag
Thinkindot-Cache-Type
SID
X-Gen-Id
X-DB
X-DW