Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
CF-RAY
CF-Cache-Status
Pragma
Link
X-Powered-By
ETag
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Timer
Access-Control-Allow-Headers
X-Request-Id
X-Xss-Protection
Access-Control-Allow-Methods
X-Download-Options
Alt-Svc
X-AspNet-Version
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
Content-Security-Policy-Report-Only
X-Generator
X-Cache-Status
X-Cacheable
X-Permitted-Cross-Domain-Policies
Timing-Allow-Origin
X-Request-ID
X-Template
X-Language
X-DNS-Prefetch-Control
X-Iinfo
X-Content-Security-Policy
Status
Content-Encoding
X-Buckets
X-AspNetMvc-Version
Upgrade
Access-Control-Expose-Headers
Xkey
X-Kinja-Server-Push
Access-Control-Max-Age
Keep-Alive
X-CDN
X-Drupal-Dynamic-Cache
X-Turbo-Charged-By
X-Via
X-Ua-Compatible
X-Cache-Group
X-Age
X-Pass-Why
X-Envoy-Upstream-Service-Time
X-Backend
EagleId
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-AH-Environment
X-Page-Speed
X-Server-Powered-By
X-Pingback
X-UA-Device
X-Swift-SaveTime
X-Swift-CacheTime
X-Server
X-Proxy-Cache
X-Hacker
Ali-Swift-Global-Savetime
X-Nginx-Cache-Status
Request-Context
Grace
X-Varnish-Cache
Server-Timing
Feature-Policy
Cf-Railgun
X-Amz-Version-Id
X-Device
X-Dns-Prefetch-Control
X-LiteSpeed-Cache
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Rq
X-Ac
Report-To
EagleEye-TraceId
X-WebKit-CSP
X-OneAgent-JS-Injection
X-Server-Id
X-Response-Time
X-Cdn
Request-Id
X-Cnection
X-Host
X-Backend-Server
X-DataDome
Content-Location
X-Cloud-Trace-Context
X-Node
X-Origin-Cache
X-Readtime
X-Cache-Lookup
NEL
X-Vhost
P3p
X-Application-Context
X-Dispatcher
X-ORACLE-DMS-ECID
X-HW
Allow
X-ORACLE-DMS-RID
X-Clacks-Overhead
X-Rack-Cache
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Origin-Upstream-Status
X-Country
Surrogate-Control
Rating
X-DynaTrace
X-FTR-Request-ID
X-Country-Code
Pinterest-Generated-By
X-Goog-Hash
Fusion-Source
Fusion-Content-Source
Fusion-Template-Id
Fusion-Content-Id
Fusion-Component-Id
X-Ws-Request-Id
X-Akam-SW-Version
X-MS-InvokeApp
X-Vname
X-TtlSet
X-PC
X-Url
X-Ruxit-JS-Agent
X-Instart-Request-ID
Accept-Ch
X-Varnish-TTL
X-B3-TraceId
X-Aspnetmvc-Version
Edge-Control
Verso
X-Powered-By-Plesk
SPRequestGuid
X-Mod-Pagespeed
Response
X-Middleton-Response
X-Sol
Display
X-D2id
X-Middleton-Display
X-SharePointHealthScore
X-Trace
X-VARITI-CCR
X-Exp-Id
X-Exp-Variant
X-GoogleNews-Bot
X-Kinja-Build
X-Cdn-Fetch
X-Kinja-Server
X-Kinja-Revision
X-Use-Magma
X-Kinja
X-Server-ID
Accept-Ch-Lifetime
RTSS
X-Server-Name
Service-Worker-Allowed
X-ESI
X-GitHub-Request-Id
SPIisLatency
SPRequestDuration
Pagespeed
X-Navigation-Version
X-CST
X-Powered-CMS
X-Debug
X-Vcap-Request-Id
X-Abt-Application-Version
Content-MD5
Public-Key-Pins
X-Amz-Server-Side-Encryption
X-Ah-Environment
X-Vcache
X-Px
MS-Author-Via
X-Version
X-Upstream
Charset
X-Amz-Rid
X-NF-Request-ID
X-Forwarded-Proto
X-TTL
DynaTrace
X-Cached
Realpath
X-Shard
Fastly-Restarts
TCN
X-Recruiting
MicrosoftSharePointTeamServices
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Ezoic-Cdn
Edge-Cache-Tag
X-Pinterest-Rid
Pinterest-Version
Arr-Disable-Session-Affinity
X-MSEdge-Ref
X-Shield-Request-Id
Access-Control-Request-Method
X-DynaTrace-JS-Agent
Nginx-Cache
X-SRCache-Store-Status
X-SRCache-Fetch-Status
S
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Ser
Front-End-Https
X-Fastly-Request-ID
X-XRDS-Location
X-Accel-Expires
X-Amz-Meta-S3cmd-Attrs
X-DIS-Request-ID
X-Goog-Storage-Class
X-Ttl
X-Id
X-Varnish-Age
X-Element-Page-Cache
X-Client-IP
X-T
X-FTR-DC
X-FTR-Cache-Status
X-FTR-Backend
X-Country-Code-Real
X-FTR-Realm
X-FTR-Balancer
X-FTR-Backend-Server
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-FTR-Expires
X-Webkit-Csp
X-SERVER
X-Amzn-Trace-Id
X-Dw-Request-Base-Id
X-RateLimit-Remaining
X-Trafficlayer-App-Name
X-Trafficlayer-App-Scope
Fastcgi-Cache
NR-ENABLED
X-Fastcgi-Cache
X-HS-Hub-Id
X-HS-Content-Id
X-Frontend
X-Content-Digest
X-Hits
Powered
X-Correlation-Id
X-Forwarded-For
X-Kinsta-Cache
Cache-Tag
X-Grace
X-Litespeed-Cache
ServerID
AR-ATIME
AR-CACHE
Ar-Sid
AR-PoweredBy
X-FTR-Cache-Host
X-HS-Cache-Config
TP-L2-Cache
TP-Cache
X-Cache-Hit
X-Node-Name
PB-PID
PB-RID
X-N
AMP-Access-Control-Allow-Source-Origin
Arc-Version
Alternate-Protocol
X-Mobile-Rewrite
X-Request-Received
X-Request-Processing-Time
X-Request-Handler-Origin-Region
X-Microsite
X-Content-Type
X-Srv
X-Zen-Fury
X-Hp-Webp
X-User-Agent
X-Rid
Server-Name
Server-Node
X-Revision
Backend-Timing
X-Analytics
Healthy
X-LB-Cache
X-Webapp-Samesite-None-Activated-N
X-Via-JSL
Cache-Status
X-Activity-Id
X-AppVersion
X-Az
Retry-After
X-Content-Security-Policy-Report-Only
X-FastCGI-Cache
X-Akamai-Edgescape
X-Logged-In
Paypal-Debug-Id
AR-Request-ID
X-IPLB-Instance
X-Oneagent-Js-Injection
X-Type
X-Amzn-RequestId
X-Amz-Apigw-Id
X-NWS-LOG-UUID
X-Cached-By
X-HS-Combine-CSS
X-Pad
X-Varnish-Grace
X-GUploader-UploadID
X-Ruxit-Js-Agent
X-Cache-Age
FilterID
X-B3-Sampled
X-Mobile-URL
X-F-Cache
X-Content-Options
X-Tumblr-Pixel
Refresh
X-FB-Debug
X-Tumblr-Pixel-0
X-Geo-Country
X-Tumblr-User
Accept-Charset
X-Debug-Info
X-Instance
X-Cluster
X-Jobs
X-Request-Guid
Host
Access-Control-Allow-Method
X-App-Environment
X-AOL-HN
X-Page-Id
X-Seen-By
Source
X-B
Actual-Object-TTL
X-Framework
X-Erf-Bev-Bev
DC
X-Erf-Bev-Bev-Is-Generated
X-PHP-Backend
X-Whom
Upgrade-Insecure-Requests
MS-CV
X-WebKit-CSP-Report-Only
X-Cache-Key
X-Varnish-Backend
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
Fastcgi-Useragent
X-Content-Powered-By
X-ATG-Version
X-Host-Name
X-Cache-2
X-Git-Hash
X-PressLabs-Stats
X-Time
X-TT
X-Cache-Control
X-TA-CDN-Provider
X-Cache-TTL
X-Esi
Surrogate-Key
X-Cache-Operation
X-Cache-Rule
Accept-CH-Lifetime
X-Amz-Replication-Status
X-Forwarded-Host
Cache
X-Wix-Request-Id
X-Daa-Tunnel
Frame-Options
X-Kong-Upstream-Latency
X-FW-Server
X-FW-Hash
X-FW-Serve
X-FW-Type
X-Kong-Proxy-Latency
X-FW-Static
Accept-CH
X-Response-Served-From
NGB
X-B-Cache
X-Signature
Xserver
X-Origin-Server
X-Mobile
Host-Header
X-Tumblr-Pixel-1
X-Tumblr-Pixel-2
Cache-Tv-Group
X-Cache-Action
X-Drupal-Cache-Tags
X-GeoIP
WPE-Backend
X-UA-Device-Type
X-TX-ID
X-Cache-NE
X-RequestSource
X-Region
Webserver
X-Hyper-Cache
Tracecode
Filters
Eomportal-Instance
X-VCache
Payment
X-Cacheable-TTL
X-Adobe-Content
From-Origin
X-Adobe-Loc
X-Webkit-CSP
X-Handled-By
X-App-Server
Cleartype
X-RemovedCookies
X-ProcessESI
X-EdgeConnect-Cache-Status
X-Cache-Enabled
X-UA
X-RTag
Ms-Operation-Id
Datacenter
X-Cache-TTL-Remaining
X-Akamai-Transformed
X-Status
X-Contextid
X-Hostname
X-NewRelic-App-Data
X-RateLimit-Limit
X-Load-Cache
X-Cache-Server
Liferay-Portal
X-Yottaa-Optimizations
X-XRDS-LOCATION
X-BCube-Filmed-By
X-Yottaa-Metrics
X-Edge-Location
X-TT-TIMESTAMP
X-FW-Dynamic
Odigeo-Trace-Id
X-Varnish-Hostname
Server-Info
Meta-Geo
X-RN-RSRV
X-Cache-Var
Load-Balancing
X-ES-SERVER
Version
X-Cache-Var-Map
X-Varnish-Server
X-IP
X-Path-Route
X-Xfnlog-Site
X-Viewer-Country
X-Rule
X-UUID
X-Debug-Cache
X-Cache-Config
Cache-Tags
X-OCL
DB-Nickname
X-PCL
X-Rocket-Nginx-Bypass
Country
X-CCM
Azure-SlotName
Cache-Name
Azure-Version
Azure-SiteName
Azure-RegionName
Azure-InstanceId
S-Rt
X-Info
X-Hosted-By
X-Via-Fastly
X-Web-Node
X-Labrador-Cache-Channel
X-Proto
X-Proxy
X-Loop
X-Varnish-Cache-Hits
X-Upgrade-Enabled
X-Real-IP
X-FC-Vary-Parameters
X-EIG-Tracking-Id
X-From
X-Pubstack
X-TNCMS
X-ServerID
X-Cache-Host
X-Akamai-Request-ID
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-Country
X-Drupal-Cache-Contexts
Property-Id
X-R9-Blue-Green-Version
Mn-Server-Ip
X-Origin
TWC-GeoIP-LatLong
X-Origin-Response-Time
Webcakes-App-Version
Webcakes-Region
X-Origin-Hint
Webcakes-App-Name
TWC-Locale-Group
TWC-Privacy
Fastly-SSL
L5d-Success-Class
Selected-Fe
S-Cnection
X-Access
X-Akamai-Request-ID2
X-Backend-Name
X-ApacheServer
Release
GEO-INFO
DSUID
Decoy-Debug-TTL
Ec-Rule-Version
Origin-Cache-Control
Origin-Edge-Control
X-Cache-Time
X-Cluster-Name
X-Rendered-As
X-Proxy-Build
X-Section
X-Time-Microsecs
X-VCT
X-Timing-Wait
X-PERF
X-JoinUs
X-Format
X-Content-Age
X-Generated
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Human
Decoy-Debug-Status
X-FireWall-Port
Decoy-Debug-Key
X-Redis-Cache
X-Varnish-Hits
X-Origin-CC
X-Soup
X-Origin-TTL
X-Vgn-Hpd-Reason
Rt-Fastcgi-Cache
X-App-Version
Viewport
X-Storage
X-Site-Version
NGX
X-Locale
X-Www-Served-By
X-NWS-UUID-VERIFY
X-WA-Info
X-Cache-Grace
Cache-Key
X-Guploader-Uploadid
X-Is-Bot
Vix-Hermes-Req-Id
X-BYPASS-REASON
Cteonnt-Length
X-GoCache-CacheStatus
X-ProxyCache-Key
Uber-Trace-Id
X-ProxyCache-Status
X-Cache-Remote
X-Hit
Cache-Hits
X-ATS-Timestamp
X-Oss-Hash-Crc64ecma
X-Backend-TTL
X-Oss-Server-Time
X-NCache
X-Oss-Object-Type
X-Oss-Storage-Class
X-Oss-Request-Id
Time
X-PHP-Host
X-SS-Set-Cookie
X-Cache-Backend
Origin
X-Generated-By
X-CS
X-Device-Type
X-Trace-Id
X-Amzn-Remapped-Content-Length
Akamai-GRN
Mime-Version
X-CF-Powered-By
X-Tumblr-Pixel-3
X-B3-SpanId
Hostname
Accept-Language
X-OVcl-Cache
X-Presslabs-Stats
X-UnsetCookies
X-OVcl
X-Nginx-Cache-Key
X-Accel-Buffering
X-S
X-Via-CDN
X-ORACLE-APMCS-REQUEST-ID
X-ORACLE-APMCS-TAG
X-Cluster-Node
X-FB-TRIP-ID
Fastcgi-X-Cache-Version
X-Uri
X-L-Path
X-Environment-Context
X-No-Session
X-URL
X-Cdn-Forward
X-B3-Traceid
X-MServer
X-Tb
Now
X-Tec-Api-Root
Access-Control-Request-Headers
X-Tec-Api-Version
X-FW-Version
X-Tec-Api-Origin
X-CACHE-KEY
X-Say-TTL
User-Cache-Control
X-Say-Cacheable
ServerName
X-SayCDN-TTL
Mobile-Detection-Method
Apple-News-Services-Handled
Apple-News-Services-Parsed-Url
Xc-Version
Machine
Content-Script-Type
Content-Style-Type
Cross-Origin-Window-Policy
BehaviorPad-Version
AsisCache
Apple-News-Services-Request-Url
IsBot
Meta-Geo-Continent
MD5-Digest
Arc-Country
Apple-News-Services-Host
X-A-Wwc
X-DPWN-IS-SECURE
X-Detected-As
X-External-Request-Id
X-G
X-Hl-Ver
X-Destination
X-Date
X-Twitter-Response-Tags
X-Trv-Group
X-Transaction
X-Svr
X-PAYTM-SRV-ID
X-SRCache-Key
X-S-Cookie
X-Session-Fingerprint
X-Server-Time
X-ScT
X-Rojux
X-Rewrite-Enabled
X-Processor
X-SIPLIST1
X-Region-Sid
X-Request-UUID
X-D
X-Connection-Hash
VivaBuild
Viewtype
X-A
X-A-Ccd
X-A-Dcw
T-Server
Rt-Proxy-Cache
Node
Rendered-Blocks
Request-Country
Request-EU
X-A-Dgt
X-Accel-Expires-Debug
X-ARC
X-B-Cookie
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Application
X-AIR-PT
X-Vtex-Processado-Em
X-Aed
X-VG-WebServer
X-VG-WebCache
X-Vtex-Remote-Cache
X-A-Dam
X-APP-VERSION
OT-Force-Account-Verify
X-NC
X-SaId
X-Endurance-Cache-Level
X-CSRF-TOKEN
X-Cache-Info
X-Thinkindot-L3
X-Cache-Debug
Thinkindot-CacheControl
X-Debug-Log
X-WADP-Cache
X-Developer
X-Debug-Cookies
CDCHOST
X-Cache-Bucket
X-Cms-Context
X-NX-Host
X-Proxy-Cache-Status
Server-Host
X-S-Maxage
Server-Int
Thinkindot-Control
Thinkindot-CacheControl-Type
X-Request-URI
RNT-Time
X-Proxy-Upstream
X-Reboot
Web-Mar-Node
RNT-Machine
X-Block-Status
X-Clara-WADP
X-Matched-Rule
We-Hiring
A
X-Location
X-Gen-Mode
Mail-Subject
X-Hnp-Log
X-Parent-Response-Time
X-Varnish-Beresp-Grace
ServedBy
Proxy-Connection
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Status
X-RateLimit-Limit-Second
X-Li-Fabric
X-RateLimit-Remaining-Second
X-IN-APIGATEWAY
X-App-Name
X-Policy
X-Platform-Server
X-Auto-Login
X-Release
X-Hash
X-Alternate-Cache-Key
X-Amz-Meta-Cache-Control
X-Li-Pop
Wxu-Next-Hostname
X-Irp-Debug
X-Request-Start
X-Internal-Host
X-Level-Front-Cache
X-Is-Gdpr
X-Key
X-JWT-State
X-Instart-Isnd
W
X-7Graus-Varnish-Cache-Control
X-7Graus-Varnish-XKeys
Wxu-Next-Region
X-Azure-Ref
X-IN-APIGATEWAYSSL
Wxu-Next-Commit
X-Reqid
X-Origin-Expires
X-CUA
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
X-Core-Mission
X-Magnolia-Registration
X-Fastly-Cache
X-Compress-Hint
X-Eu-Site
X-Debug-Cache-Store
X-Developers
X-Dispatch
X-Dispatcher-Server
X-Distributor
X-Ms-Version
X-Epic-Correlation-Id
X-Ms-Request-Id
X-Clientip
X-CGP
X-Has-Esi
X-C
X-Generation-Time
X-Origin-Date
X-Distil-CS
X-Backend-State
X-BBXSRF
X-Generated-On
X-Cache-FS-Status
X-Cache-URL
X-Cdn-Origin
X-Cdn-Srv
X-LI-UUID
X-Old-Content-Length
X-Cache-Id
X-Generated-In
X-Azure-Ref-OriginShield
True-Client-Country-4JS
HA-Ipaddr
X-Skip-Cache
X-Sn-Servicetimems
Memcached
Ha-Gx-Prefs
X-User
X-Shopify-Stage
X-Variation
Content-Disposition
X-Sorting-Hat-PodId
Magicmarker
Kp-EeAlive
Adler-Geo
X-Up
Is-Eu
Fastly-Soc-X-Request-Id
X-WebServer
X-Sorting-Hat-ShopId
Countrycode
Esi-Enabled
IBM-Web2-Location
X-ShopId
X-VServer
SD-X-WS
X-SD-PageType
Section-Io-Cache
Served-By
X-We-Are-Hiring
X-Webstats-RespID
X-TrackingId
X-Wikidot-Static-Cache
X-Server-IP
X-VG-TLSProxy
Platform
Gh-Request-Id
X-ShardId
Cache-Host
X-Service
X-Wikidot-Backend
X-Geo
X-B3-Parentspanid
Cache-Provider
X-Nc
NtCoent-Length
AKAMAI
X-MSEdge-Features
X-VC-Cache
X-Dc
X-MSEdge-Flight
X-Method
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Node-Id
L
PFcat
Pramga
X-LI-Proto
X-Qloud-Router
X-Logging-Id
X-ServiceProvider
X-Geo-Header
X-Scheme
X-Sucuri-Id
V-Age
X-GeoIP-City
X-Agile
X-Agile-Age
X-Owner
Heartbleed
X-Bip
X-Swa-Ws
X-SVT-ORM-VERSION
X-Device-Os
X-Agile-Id
Locale
X-Core-Value
X-SVT-ORM-RULES
X-Thanos
X-Vdms-Version
X-Lb-Id
X-NodeID
Server-ID
X-Servername
X-EC-Lua
Srv
X-GRACE
X-Sigma-Backend
Cdnsip
X-AK-Request-ID
CF-IPCountry
X-Unique-Id
X-Rocket-Build-Number
X-Sigma
Cdncip
X-Sucuri-Cache
GEO-REGION-INFO
X-Shopify-Generated-Cart-Token
X-Newrelic-Synthetics
Environment
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
Request-Time
X-Planisys-CDN-TTL
X-Be
X-FPC
X-CDN-Forward
X-B3-Spanid
X-Pjax-Url
X-Via-NSCOPI
X-VHOST
X-Upstream-Ht
X-Upstream-Ct
Powered-By-ChinaCache
X-ECACHE
X-NGENIX-Cache
X-ND-Cache
X-GEO
X-Microcachable
X-Tb-Optimization-Total-Bytes-Saved
X-Servedbyhost
X-Instart-Info
X-ElasticPress-Search
Tcn
Resin-Trace
X-Zone
X-RCS-CacheZone
X-Nginx-Cache
Group
X-Source
X-Backend-Url
X-Backend-Host
X-Trafficlayer-App-Version
X-Ratelimit-Remaining
X-Oracle-Dms-Rid
CF-Cached-On
X-Var-Ttl
SRV
Backend-Name
X-Unique-ID
Locid
X-IPS-LoggedIn
N-Cache
X-Req
Memory
Ohc-Cache-HIT
Ohc-File-Size
X-Dynatrace
X-Gamma-Serve
X-VCL-Version
X-Served-From
X-COUNTRY
Fly-Cache
Gannett-Cam-Experience-Id
Pagetype
X-VWS-Id
FNAC-ModuleRouting
Fly-Request-Id
Lfy
Cache-Prefix
X-AWS-Id
X-LJ-Flow-ID
X-DC
X-Correlation-ID
Cf-Ipcountry
TTL
X-Upstream-CT
X-Check-Cacheable
X-Pf-Uncompressing
X-Refresh
X-Upstream-HT
Amp-Access-Control-Allow-Source-Origin
Cdn
X-Worker
X-CSRF-Token
Geoip-City
PICS-Label
GeoIp-Country-Code
X-Cache-Miss-From
X-Pod
Geoip-Latitude
Geo-Info
X-Via-Ucdn
Pics-Label
X-Sucuri-ID
X-Sedo-Request-Id
X-Bc
X-Fetched-On
ProcessTime
X-Via-Edge
REQUESTUUID
GeoIP-Latitude
X-Via-SSL
GeoIP-City
GeoIP-Country-Code
X-Server-W
X-Render-Time
PageSpeed
XServer
Fastly-SIE
X-NU-AKA-ACS-Version
X-TIME
Ttl
M-TraceId
X-Vcl-Version
Fastly-SWR
X-APP
X-Rebelmouse-Cache-Control
X-Ua
X-HTML-Minification-Powered-By
X-Rebelmouse-Surrogate-Control
X-Wa
X-Ratelimit-Limit
X-CLOUD-TRACE-CONTEXT
X-HS-Status
X-LiteSpeed-Cache-Control
X-PF-Uncompressing
X-GeoIP-Country-Code
X-Fstrz
X-SRV
X-Mode
X-ZONE
X-Tt-Trace-Tag
X-Upstream-Proxy
Cache-Cookie-Set-Lfrom
X-GDPR
Cache-Cookie-Set-From
Cache-Cookie-Set-Idcheck
X-Fastly-Country-Code
X-Ratelimit-Reset
X-Dynatrace-Js-Agent
HitType
X-ServedByHost
X-Cache-Tag
Cdn-Host
On-Server
User-Agent
Cdn-Request-Time
Pragrma
X-Edge-Server
X-NGINX-Cache
X-Swift-Error
MIME-Version
X-Varnish-Ttl
X-MP-GENERATED-AT
X-HostName
X-FORWARDED-FOR
HostName
Host-ID
X-SN
X-WR-MODIFICATION
X-Aicache-OS
URI
SS
X-TT-LOGID
X-Org
Who
X-BC
X-Flog
X-Response-By
X-Hello
X-ABtesting
X-WA
CACHE
X-RateLimit-Reset
X-UPSTREAM-Address
X-Cdn-Request-ID
X-DI
X-RPS
X-Edge-O15-RID
X-RSL
X-Fastly-Backend-Reqs
SN
X-RPM
X-PJAX-URL
X-Cache-Ttl
X-DB
X-BE
X-DSS
X-Action
X-DW
Dynatrace
X-Zipkin-Id
X-Routing-Service
X-Proxied
X-Cf-Powered-By
Requestid
X-Varnish-URL
X-Varnish-Cacheable
X-TH-Server
X-LAGOON
X-Fpc
DataCenter
Lb
Powered-By
RequestUuid
X-ServerName
Debug
X-Page-Type
Country-Code
Get-Access-Time
CDN
Server-Id
Is-Session-Tracking
LB
X-Ftr-Cache-Host
XxX-Cache-Status
X-SB
X-VC
X-Gen-Id
X-Nananana
X-Varnish-Beresp-TTL
X-Protected-By
Media-Length
Warning
UCS
X-Request-Url
RequestId
X-MID
NnCoection
X-LB-ID
X-LiteSpeed-Tag
X-Li-Proto
X-Amzn-Remapped-Connection
X-Akamai-ERRuleID
X-Amzn-Remapped-Date
Thinkindot-Cache-Type
X-Tt-Trace-Host
X-MCACHE
X-Akamai-ERPolicy
X-Edge
X-Dw-Trace-Id
Application
X-Fastly-Cache-Hits
Correlation-Id
SID
Xet-Cookie
Product