Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Link
X-Powered-By
CF-Cache-Status
Pragma
ETag
CF-RAY
Expect-CT
X-XSS-Protection
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Xss-Protection
X-UA-Compatible
X-Served-By
Alt-Svc
X-Request-Id
X-Varnish
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Check
Content-Security-Policy-Report-Only
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
X-Generator
X-Cache-Status
CF-Ray
X-Cacheable
X-Kinja-Server-Push
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Ua-Compatible
X-Template
X-Language
X-FRAME-OPTIONS
X-AspNetMvc-Version
X-Iinfo
Status
X-Buckets
X-Content-Security-Policy
X-CDN
Content-Encoding
Upgrade
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Envoy-Upstream-Service-Time
Keep-Alive
X-Via
X-Drupal-Dynamic-Cache
X-Ws-Request-Id
X-Request-ID
X-AH-Environment
X-Server
X-Turbo-Charged-By
X-Backend
X-Age
P3p
X-Cache-Group
X-Robots-Tag
Xkey
Feature-Policy
X-Proxy-Cache
Request-Context
X-Amz-Id-2
X-Amz-Request-Id
X-Hacker
EagleId
X-Page-Speed
X-UA-Device
X-Server-Powered-By
X-Nginx-Cache-Status
X-Pingback
Grace
Server-Timing
X-Varnish-Cache
X-LiteSpeed-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
Report-To
X-Amz-Version-Id
X-WebKit-CSP
Cf-Railgun
X-Server-Id
X-Dns-Prefetch-Control
X-Rq
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Origin-Cache
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Host
X-Device
Surrogate-Control
X-Response-Time
X-Backend-Server
X-Cache-Lookup
X-Vhost
X-Ac
X-Node
X-Readtime
X-Origin-Upstream-Status
X-Dispatcher
X-HW
Fusion-Source
Fusion-Content-Source
Fusion-Template-Id
Fusion-Component-Id
Fusion-Content-Id
Request-Id
Content-Location
X-Mod-Pagespeed
X-DataDome
X-Application-Context
NEL
X-ORACLE-DMS-ECID
X-Akam-SW-Version
Fusion-Deployment-Id
X-Country
X-Pass-Why
X-ORACLE-DMS-RID
Allow
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Ruxit-JS-Agent
X-Cloud-Trace-Context
Rating
X-Country-Code
X-Cnection
X-Clacks-Overhead
Edge-Control
X-Url
X-Rack-Cache
X-Px
X-FTR-Request-ID
RTSS
MS-Author-Via
X-Goog-Hash
X-TtlSet
X-PC
X-Vname
X-Powered-By-Plesk
Verso
Accept-CH
X-B3-TraceId
X-Ttl
Service-Worker-Allowed
Public-Key-Pins
X-GitHub-Request-Id
X-DynaTrace
X-Kinja-Server
X-Kinja-Build
X-Use-Magma
X-Kinja-Revision
X-GoogleNews-Bot
X-Kinja
X-Cdn-Fetch
X-Exp-Variant
X-Exp-Id
X-Varnish-TTL
Arr-Disable-Session-Affinity
X-MS-InvokeApp
X-Middleton-Display
X-Sol
X-Middleton-Response
Pagespeed
Display
Response
X-Forwarded-Proto
X-Amz-Server-Side-Encryption
Accept-CH-Lifetime
X-Cache-TTL
Accept-Ch
X-D2id
TCN
X-Abt-Application-Version
Pinterest-Generated-By
X-Amz-Rid
X-CST
X-Vcap-Request-Id
X-NF-Request-ID
X-Cached
X-Content-Type
X-VARITI-CCR
Accept-Ch-Lifetime
X-Navigation-Version
X-Fastly-Request-ID
Cache-Tag
X-ESI
X-Server-Name
X-Instart-Request-ID
AR-ATIME
AR-Request-ID
AR-PoweredBy
X-Version
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Accel-Expires
AR-CACHE
Ar-Sid
X-Upstream
Access-Control-Request-Method
X-MSEdge-Ref
X-Grace
X-Powered-CMS
X-Debug
Charset
Nginx-Cache
S
SPIisLatency
SPRequestDuration
X-Client-IP
X-DynaTrace-JS-Agent
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Content-MD5
SPRequestGuid
Realpath
X-Ezoic-Cdn
X-SharePointHealthScore
X-B3-TraceId-Primal
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
Pinterest-Version
Mrf-Cache-Status
MRF-Tech
X-Pinterest-Rid
X-Element-Page-Cache
X-FastCGI-Cache
X-Trace
X-Jurisdiction
X-Dw-Request-Base-Id
X-Hp-Webp
X-Shield-Request-Id
X-Id
X-Recruiting
X-Amz-Meta-S3cmd-Attrs
X-Oneagent-Js-Injection
X-Node-Name
Nel
X-XRDS-Location
X-T
X-Kinsta-Cache
Fastcgi-Cache
X-Content-Digest
X-Logged-In
Host-Header
X-Mobile-URL
X-NWS-LOG-UUID
X-Frontend
X-ASPNET-VERSION
X-Request-Received
X-Cache-Hit
X-Request-Processing-Time
TP-L2-Cache
Server-Node
TP-Cache
X-FTR-Cache-Status
X-Cache-Age
X-FTR-Realm
X-Country-Code-Real
X-FTR-DC
X-FTR-Backend
Edge-Cache-Tag
X-FTR-Backend-Server
X-FTR-Balancer
Front-End-Https
ServerID
X-Goog-Metageneration
X-Goog-Storage-Class
X-Goog-Generation
X-FTR-Expires
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-Amzn-Trace-Id
X-Cache-Key
X-Forwarded-For
X-Hostname
Server-Name
PB-PID
Arc-Version
Fastly-Restarts
PB-RID
DynaTrace
Powered
X-Microsite
X-Request-Handler-Origin-Region
X-DIS-Request-ID
X-Content-Security-Policy-Report-Only
X-Zen-Fury
X-Revision
X-User-Agent
X-Server-ID
X-Akamai-Edgescape
X-Page-Id
X-Mobile-Rewrite
X-F-Cache
X-Hits
Filters
X-Jobs
X-Yandex-Sdch-Disable
X-LB-Cache
Accept-Charset
X-HS-Content-Id
X-HS-Cache-Config
Backend-Timing
X-ATS-Timestamp
X-HS-Combine-CSS
X-HS-Hub-Id
X-ORACLE-APMCS-REQUEST-ID
X-ORACLE-APMCS-TAG
X-Ruxit-Js-Agent
X-TTL
X-Content-Powered-By
X-Kong-Upstream-Latency
X-Cdn
X-Kong-Proxy-Latency
X-Geo-Country
AMP-Access-Control-Allow-Source-Origin
X-Fastcgi-Cache
X-Varnish-Age
X-Origin-Server
X-N
X-B
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
MicrosoftSharePointTeamServices
X-FTR-Cache-Host
Alternate-Protocol
X-Via-JSL
X-Rid
X-Daa-Tunnel
X-Varnish-Backend
X-Ser
X-AppVersion
X-ATG-Version
X-Az
DC
X-Activity-Id
X-WebKit-CSP-Report-Only
Cache-Tags
Paypal-Debug-Id
X-Debug-Info
X-FB-Debug
X-Type
X-Git-Hash
X-Amz-Replication-Status
Retry-After
Frame-Options
X-Varnish-Grace
X-Whom
X-TT
X-Signature
X-B-Cache
X-App-Environment
Section-Io-Cache
Actual-Object-TTL
X-App-Server
X-Esi
X-Correlation-Id
X-Edge
Surrogate-Key
X-Status
X-Content-Options
Fastcgi-Useragent
Host
X-Request-Guid
X-Contextid
Healthy
X-AOL-HN
X-Pinterest-Direct
X-RateLimit-Remaining
X-IPLB-Instance
X-Cache-Action
X-Seen-By
X-HTML-Minification-Powered-By
X-Host-Name
X-Endurance-Cache-Level
Refresh
Source
X-XRDS-LOCATION
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Tumblr-User
X-B3-Sampled
From-Origin
X-Upgrade-Enabled
X-Instance
X-Amzn-RequestId
Access-Control-Allow-Method
X-Amz-Apigw-Id
X-ECACHE
X-RemovedCookies
X-Cache-Rule
X-ProcessESI
X-Accel-Buffering
X-Response-Served-From
X-Cache-Operation
X-Drupal-Cache-Tags
VIX-Pulpo-Node
X-MCACHE
X-Mid
VIX-Pulpo-Upstream-Status
Odigeo-Trace-Id
X-Region
X-Rule
X-Cacheable-TTL
MS-CV
X-UUID
X-Varnish-Server
X-Environment-Context
X-Is-Bot
Eomportal-Instance
X-Rendered-As
X-L-Path
X-Cache-Time
X-FW-Type
X-FW-Static
Srv
X-FW-Dynamic
Payment
X-FW-Hash
X-FW-Serve
X-VCache
Datacenter
Countrycode
X-Protected-By
X-FW-Server
X-WA-Info
X-Adobe-Content
X-Adobe-Loc
Xserver
Cache-Status
X-Cache-Control
X-Correlation-ID
X-PressLabs-Stats
Content-Disposition
X-GeoIP
X-URL
X-EdgeConnect-Cache-Status
X-Time
X-Cache-Server
X-Akamai-Transformed
X-APP-VERSION
X-Cached-By
X-Akamai-Request-ID2
X-Cluster
X-Wix-Request-Id
X-UnsetCookies
Uber-Trace-Id
NR-ENABLED
WPE-Backend
NGB
X-Yottaa-Optimizations
X-Proxy
X-Yottaa-Metrics
X-Load-Cache
X-Tt-Trace-Tag
Version
X-Tt-Trace-Host
X-Origin-Response-Time
X-SERVER-NAME
X-Mobile
X-Tumblr-Pixel-2
X-PHP-Backend
Access-Control-Request-Headers
X-Tumblr-Pixel-1
X-RequestSource
X-Handled-By
X-Mode
X-Cache-Remote
X-IPS-LoggedIn
X-Azure-Ref
X-NGENIX-Cache
X-FireWall-Port
X-Backend-Name
X-NWS-UUID-VERIFY
X-Cache-NGX
Accept-Language
Cross-Origin-Window-Policy
Cache
X-Viewer-Country
X-Via-Fastly
X-ES-SERVER
X-UA-Device-Type
X-CCM
X-No-Session
X-Cache-Var-Map
X-Cache-Var
X-Cache-Status-Check
X-Path-Route
Meta-Geo
X-RN-RSRV
X-OCL
X-Locale
X-Www-Served-By
X-ApacheServer
X-Framework
X-PERF
DSUID
X-Storage
Akamai-GRN
Cache-Hits
X-MP-GENERATED-AT
X-Pubstack
X-PCL
X-AWS-Id
Cleartype
X-Cache-Config
Decoy-Debug-Key
Webserver
ServedBy
X-RTag
X-FW-Version
Now
X-LJ-Flow-ID
Decoy-Debug-TTL
X-Redis-Cache
X-Site-Version
X-Real-IP
X-VWS-Id
Decoy-Debug-Status
X-UPSTREAM-Address
Ms-Operation-Id
X-CSRF-Token
Liferay-Portal
X-Time-Microsecs
X-NewRelic-App-Data
Filterid
Cache-Name
X-Section
X-SayCDN-TTL
TWC-Connection-Speed
X-ServerID
TWC-GeoIP-Country
TWC-Privacy
Webcakes-App-Name
TWC-Locale-Group
TWC-GeoIP-LatLong
Section-Origin-Responded
TWC-Device-Class
Section-Io-Origin-Time-Seconds
X-R9-Blue-Green-Version
S-Rt
X-ProxyCache-Status
X-ProxyCache-Key
Property-Id
Mn-Server-Ip
Section-Io-Id
Webcakes-App-Version
X-Say-Cacheable
Section-Io-Origin-Status
Fastly-SSL
X-Say-TTL
X-Origin-Hint
X-CS
X-NCache
Webcakes-Region
Load-Balancing
X-Device-Type
X-Hl-Ver
X-Format
X-Web-Node
X-BYPASS-REASON
X-Adobe-Source
X-Access
X-Human
X-TX-ID
X-Origin
X-FC-Vary-Parameters
X-FB-TRIP-ID
X-Bc-Bl
X-Info
Selected-Fe
X-Release
X-Detected-As
X-JoinUs
X-IP
X-BCube-Filmed-By
X-Amzn-Remapped-Content-Length
X-NYM-Debug-Backend
X-Proxy-Build
X-Air-Hostname
X-Timing-Wait
X-SaId
DB-Nickname
X-EIG-Tracking-Id
X-Sorting-Hat-ShopId
X-Generated
X-Sorting-Hat-PodId
X-Alternate-Cache-Key
X-Loop
X-Hyper-Cache
X-Geo
X-Shopify-Stage
X-Varnish-Cache-Hits
X-Cache-Enabled
X-TNCMS
X-Hosted-By
X-ShardId
X-ShopId
Origin-Cache-Control
Azure-SiteName
X-Xfnlog-Site
X-Labrador-Cache-Channel
X-Routing-Service
X-Unique-Id
Origin-Edge-Control
X-Zipkin-Id
X-Proxied
Azure-SlotName
Azure-Version
Azure-InstanceId
Azure-RegionName
X-PHP-Host
X-Qloud-Router
X-Goog-Meta-Goog-Reserved-File-Mtime
X-From
Cache-Tv-Group
FilterID
Country
Upgrade-Insecure-Requests
X-Content-Age
X-Source
X-Presslabs-Stats
X-Cache-Host
X-Cluster-Node
SD-X-WS
X-Cache-NE
Ec-Rule-Version
User-Agent
X-Old-Content-Length
X-Ua
X-Varnish-Hostname
Time
X-Pad
X-Drupal-Cache-Contexts
X-Cache-2
X-Urbn-Site-Id
X-Litespeed-Cache
X-Parent-Response-Time
X-Urbn-Context-Path
Locale
X-Cache-TTL-Remaining
X-EC-Lua
X-Cache-Backend
Server-Info
X-Srv
X-TA-CDN-Provider
X-RateLimit-Limit
X-Akamai-Request-ID
X-RCS-CacheZone
X-Backend-TTL
X-Proxy-Cache-Status
X-Debug-Cache
X-CDN-Forward
Geo-Info
S-Cnection
X-Webkit-CSP
X-Cache-Grace
X-Soup
Proxy-Connection
X-Tumblr-Pixel-3
Apigw-Requestid
X-Forwarded-Host
X-Dc
X-Nc
OT-Force-Account-Verify
X-Microcachable
NGX
X-Vcache
X-Proto
X-Tb
M-TraceId
Machine
Mobile-Detection-Method
X-Rewrite-Enabled
Pagetype
X-S
Meta-Geo-Continent
X-Rojux
MD5-Digest
Content-Script-Type
X-Swa-Ws
X-SRCache-Key
Arc-Country
X-Cache-PHP
X-Trace-Id
X-Trv-Group
X-Transaction
AsisCache
BehaviorPad-Version
X-ScT
X-Scheme
GEO-REGION-INFO
Fastcgi-X-Cache-Version
Content-Style-Type
X-ServiceProvider
X-S-Cookie
ServerName
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Connection-Hash
X-PAYTM-SRV-ID
X-B-Cookie
X-Geo-Header
X-Application
X-ARC
X-D
X-Date
X-NodeID
X-G
X-Generated-On
X-External-Request-Id
X-Dispatch
X-Destination
X-Developer
X-DevSite-Last-Modified
X-Processor
X-Aed
True-Client-Country-4JS
UCS
Viewtype
T-Server
X-Twitter-Response-Tags
Rendered-Blocks
X-Region-Sid
Server-Host
VivaBuild
Who
X-A-Dgt
X-A-Wwc
X-Accel-Expires-Debug
X-A-Dcw
X-A-Dam
X-A
X-A-Ccd
X-Reqid
X-Session-Fingerprint
X-Uri
X-VG-WebServer
Sid
X-Level-Front-Cache
X-Vdms-Path
X-VG-WebCache
X-Vtex-Processado-Em
Xc-Version
X-Vdms-Version
X-FORWARDED-FOR
X-Cluster-Name
X-Vtex-Remote-Cache
X-Newrelic-Synthetics
Cache-Key
We-Hiring
Mail-Subject
Magicmarker
X-Branch-Name
X-Cache-FS-Status
X-Via-PopV
X-Generation-Time
IsBot
X-Method
X-Bip
Vix-Hermes-Req-Id
CDCHOST
X-Agile
AKAMAI
X-Agile-Age
FNAC-ModuleRouting
X-RateLimit-Limit-Second
X-SD-PageType
X-Worker
X-Agile-Id
X-Generated-In
X-UA
X-Via-PopH
X-Location
Viewport
On-Server
X-Device-Os
X-Thinkindot-L3
Thinkindot-CacheControl
X-Instart-Info
X-Dispatcher-Server
X-Hash
X-Node-Id
X-User
X-Matched-Rule
Release
Thinkindot-Control
X-RateLimit-Remaining-Second
Thinkindot-CacheControl-Type
V-Age
X-SN
X-Cms-Context
X-Skip-Cache
X-SIPLIST1
Kp-EeAlive
N-Cache
NM-Fastcgi-Cache
X-Owner
X-Thanos
X-Be
Cf-Ipcountry
X-Hit
User-Cache-Control
RNT-Time
Wxu-Next-Region
RNT-Machine
X-Logging-Id
Wxu-Next-Commit
Wxu-Next-Hostname
X-WADP-Cache
Web-Mar-Node
Rt-Fastcgi-Cache
X-Backend-State
X-Response-By
X-Magnolia-Registration
X-Developers
CacheControlHeader
X-Micro-Cache
X-Distil-CS
X-Epic-Correlation-Id
Tracecode
X-Gen-Mode
X-Fmm-Version
X-Eu-Site
X-Core-Value
X-Clientip
X-Backend-Host
X-Block-Status
X-Auto-Login
X-App
X-Wikidot-Static-Cache
X-Platform-Server
X-Cache-Bucket
X-Clara-WADP
X-CGP
X-Cache-Tags
X-Cache-Info
X-Wikidot-Backend
X-Req
Adler-Geo
Apple-News-Services-Handled
X-Servername
X-Is-Gdpr
X-Request-UUID
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
X-LAGOON
L5d-Success-Class
X-JWT-State
Apple-News-Services-Request-Url
C-Via
X-VC-Cache
Ha-Gx-Prefs
X-Hnp-Log
Gh-Request-Id
X-Variation
Fastly-Drupal-HTML
Platform
HA-Ipaddr
Is-Eu
X-Has-Esi
X-Envoy-Decorator-Operation
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-From
Cache-Cookie-Set-Lfrom
X-BBXSRF
X-Mvc-Supplant-Cachable
X-Slack-Backend
X-Origin-Date
X-Ms-Request-Id
X-Nginx-Cache-Key
X-Ms-Version
X-Origin-Expires
X-Distributor
X-Irp-Debug
X-TrackingId
X-Varnish-Cacheable
X-TT-TIMESTAMP
X-VG-TLSProxy
X-Policy
X-We-Are-Hiring
Node
X-Webstats-RespID
Sever-Int
Server-Hostname
X-Reboot
X-Request-Host
Server-Ext
X-NC
X-VServer
X-Server-W
X-Compress-Hint
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-Varnish-Beresp-Ttl
X-Vgn-Hpd-Reason
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Fastly-Cache
Fastly-SIE
X-Contensis-Viewer-Groups
X-Envoy-Upstream-Healthchecked-Cluster
X-Core-Mission
X-LI-UUID
X-Li-Fabric
X-Refresh
Fastly-SWR
X-Cache-ASPX
X-Li-Pop
X-Varnish-Authentication
X-Var-Ttl
X-TH-Server
X-AIR-PT
X-LI-Proto
X-Cache-URL
Memcached
W
X-TIME
GEO-INFO
HostName
X-App-Version
X-SRV
Esi-Enabled
X-Gzip
X-Esi-Check
X-Cache-Id
LB
X-GoCache-CacheStatus
X-DC
X-Origin-TTL
X-Origin-CC
X-Configured-By
L
Server-ID
Ohc-File-Size
X-Loc
X-Cache-Debug
X-Storefront-Renderer-Rendered
NtCoent-Length
X-Server-IP
X-Mvc-Supplant-OutputCached
X-NU-AKA-ACS-Version
X-Wa
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
Cache-Host
X-App-Name
X-Cdn-Forward
X-Key
X-Edge-Location
X-VCT
X-BC
MIME-Version
X-Sucuri-ID
X-ZONE
X-Cdn-Srv
X-Bc
X-Zone
Pragrma
X-B3-Traceid
Referer-Policy
X-S-Maxage
X-Varnish-URL
X-MSEdge-Features
X-MSEdge-Flight
Server-Surrogate-Control
X-FPC
Memory
Server-Cache-Control
X-Generated-By
Ohc-Response-Time
Fastly-Backend-Name
X-BACKEND-TTL
X-Servedbyhost
X-Varnish-Ttl
X-Pjax-Url
X-Nginx-Cache
CACHE
X-Svr
X-Debug-Panamera-Sitecode
X-Rocket-Nginx-Bypass
X-Debug-Panamera-Host
X-Via-CDN
Locid
FSS-Cache
Heartbleed
Request-EU
X-Batcache
X-Up
X-COUNTRY
Request-Country
X-CF-Powered-By
X-Minions-Version
X-Varnish-Hits
X-Aicache-OS
X-ElasticPress-Query
X-Request-URI
Resin-Trace
X-ND-Cache
X-CLOUD-TRACE-CONTEXT
X-VCL-Version
X-GEO
X-Shopify-Generated-Cart-Token
X-Unique-ID
X-Oss-Hash-Crc64ecma
SRV
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Object-Type
X-Gamma-Serve
X-Sucuri-Cache
X-Ratelimit-Remaining
WZWS-RAY
Cteonnt-Length
X-CACHE-KEY
Lfy
GeoIP-Country-Code
Geoip-Latitude
GeoIp-Country-Code
DCR-Processing-Time-Ms
DCR-Decision-By
Hostname
X-BE
CF-Cached-On
X-PF-Uncompressing
X-Vcl-Version
X-WebServer
Pramga
GeoIP-Latitude
Location
HitType
X-Check-Cacheable
Cdn-Request-Time
X-ECache
X-Azure-Ref-OriginShield
X-HS-Status
Cdn-Host
X-Edge-Server
X-Fastly-Cache-Status
X-Proxy-Upstream
Product
Powered-By-ChinaCache
X-VHOST
X-LB-ID
X-Cdn-Origin
X-Sn-Servicetimems
Mime-Version
X-PJAX-URL
X-Fetched-On
X-Fastly-Country-Code
Ohc-Cache-HIT
My-App
X-Amzn-Requestid
X-NGINX-Cache
X-CSRF-TOKEN
X-Ratelimit-Limit
X-GeoIP-Country-Code
PFcat
X-ServedByHost
X-VarnishDD-TTL
X-OVcl-Cache
X-OVcl
X-Vgn-Hpd-Ssi
X-Vgn-Hpd-Cached
X-Newrelic-App-Data
SN
X-Varnishpool
X-Fpc
X-Fastly-Backend-Reqs
X-Vgn-Hpd-Variations-Key
Amp-Access-Control-Allow-Source-Origin
X-Pf-Uncompressing
X-Ratelimit-Reset
X-Ftr-Cache-Host
X-Render-Time
X-Instart-Isnd
X-Oracle-Dms-Rid
X-CACHE-AGE
X-Platform
URI
X-Varnish-Url
WWW-Authenticate
Dt-Cache-Category
Group
X-B3-Spanid
X-Served-From
X-Request-Start
X-Swift-Error
XServer
Cdn
X-Cache-Expired-At
A
X-Via-Ucdn
CloudFront-Viewer-Country
Cf-Alt-Svc
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
X-CUA
Epwk-X-Cache
X-B3-SpanId
Country-Code
X-Request-Time
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Via-NSCOPI
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Original-Request-Id
Origin
PICS-Label
Lb
X-WR-MODIFICATION
X-Cache-Tag
X-DPWN-IS-SECURE
Pics-Label
X-Oss-Cdn-Auth
Backend
Cloudfront-Viewer-Country
X-Ocache
Server-Ttl
X-LiteSpeed-Cache-Control
X-StackifyID
Geoip-City
X-WA
X-Apw-Access-Object
X-Apw-Access-Token
X-Debug-Ysi-Auth
X-Cache-Version
X-Varnish-Beresp-TTL
SID
X-Tb-Optimization-Total-Bytes-Saved
X-Apw-Hits
X-Apw-Access-Action
X-Debug-Cache-String
X-Debug-Cache-Bypass
X-Debug-Do-Not-Cache-Uri
X-Debug-Xas-Auth
X-Debug-Cache-Status
X-Shard
X-WPE-Loopback-Upstream-Addr
X-RunCloud-Cache
X-C
X-Planisys-CDN-Cache
NnCoection
Proxy-Firewall
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Cache-Hm
X-Acquia-Application-Trace
Cneonction
X-Acquia-Site
X-Acquia-Purge-Tags
Backend-Name
X-Nananana
X-Acquia-Application-UUID
X-Cache-Hfrom
Region
CF-IPCountry
X-B3-Parentspanid
Req-ID
X-Akamai-ERRuleID
X-Dw-Trace-Id
X-Request-URL
X-Sigma
X-Rocket-Build-Number
X-Html-Edge-Cache
Host-ID
X-SB
X-VC
X-Akamai-ERPolicy
X-Country-IP
Request-Time
X-Sigma-Backend
X-ElasticPress-Search
X-Varnish-ID