Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
CF-Cache-Status
Pragma
Link
CF-RAY
X-Powered-By
ETag
Expect-CT
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Xss-Protection
X-Varnish
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
Alt-Svc
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-FRAME-OPTIONS
X-Drupal-Cache
X-Adblock-Key
X-Request-ID
X-Check
X-Generator
Content-Security-Policy-Report-Only
X-Cache-Status
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-Template
X-Language
X-AspNetMvc-Version
Status
X-Content-Security-Policy
X-Buckets
Content-Encoding
Access-Control-Expose-Headers
X-CDN
Upgrade
Xkey
Access-Control-Max-Age
Keep-Alive
X-Drupal-Dynamic-Cache
X-Kinja-Server-Push
X-Turbo-Charged-By
CF-Ray
X-AH-Environment
X-Via
X-Age
X-Cache-Group
X-Pass-Why
X-Backend
X-Ua-Compatible
X-Envoy-Upstream-Service-Time
EagleId
X-Server
X-Robots-Tag
X-Amz-Request-Id
X-Amz-Id-2
X-Server-Powered-By
X-Pingback
X-Page-Speed
X-UA-Device
X-Proxy-Cache
X-Swift-SaveTime
X-Swift-CacheTime
X-Hacker
X-Nginx-Cache-Status
Request-Context
Ali-Swift-Global-Savetime
X-Varnish-Cache
Grace
Server-Timing
Feature-Policy
Cf-Railgun
X-Amz-Version-Id
X-LiteSpeed-Cache
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
X-WebKit-CSP
X-Server-Id
X-Rq
Report-To
EagleEye-TraceId
X-Response-Time
X-Host
X-Ac
X-OneAgent-JS-Injection
X-Ws-Request-Id
Request-Id
X-Cnection
X-Backend-Server
X-DataDome
Content-Location
X-Origin-Cache
X-Cache-Lookup
X-Node
NEL
X-Readtime
X-Cloud-Trace-Context
X-Dns-Prefetch-Control
X-Vhost
X-HW
X-Application-Context
X-Dispatcher
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
P3p
X-Cdn
Allow
X-Clacks-Overhead
Surrogate-Control
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Rack-Cache
X-Origin-Upstream-Status
X-DynaTrace
Rating
X-Country
Fusion-Content-Id
Fusion-Content-Source
Fusion-Component-Id
Fusion-Source
Fusion-Template-Id
X-FTR-Request-ID
X-Akam-SW-Version
X-Country-Code
X-Goog-Hash
X-Varnish-TTL
X-Ruxit-JS-Agent
X-Instart-Request-ID
Edge-Control
X-Vname
X-TtlSet
X-PC
Pinterest-Generated-By
X-Mod-Pagespeed
X-Url
X-B3-TraceId
X-MS-InvokeApp
Verso
Accept-Ch
SPRequestGuid
X-Powered-By-Plesk
X-D2id
X-ESI
X-Trace
X-VARITI-CCR
X-Server-Name
X-SharePointHealthScore
X-GitHub-Request-Id
Service-Worker-Allowed
Pagespeed
X-Middleton-Response
X-Sol
Response
X-TTL
X-GoogleNews-Bot
X-Kinja
X-Cdn-Fetch
X-Exp-Variant
Content-MD5
X-Middleton-Display
Display
X-Exp-Id
X-Kinja-Revision
X-Kinja-Build
X-Use-Magma
X-Kinja-Server
RTSS
X-Navigation-Version
SPRequestDuration
SPIisLatency
X-Abt-Application-Version
X-Powered-CMS
Accept-Ch-Lifetime
X-Debug
X-Forwarded-Proto
X-Upstream
X-Cached
X-Amz-Server-Side-Encryption
X-Vcap-Request-Id
Public-Key-Pins
X-Vcache
Charset
X-Version
MS-Author-Via
X-CST
DynaTrace
X-NF-Request-ID
X-Amz-Rid
Realpath
Edge-Cache-Tag
X-Px
MicrosoftSharePointTeamServices
X-DynaTrace-JS-Agent
Arr-Disable-Session-Affinity
X-Shard
TCN
X-Trafficlayer-App-Scope
X-Trafficlayer-App-Name
X-Ezoic-Cdn
X-MSEdge-Ref
X-Shield-Request-Id
X-Pinterest-Rid
Pinterest-Version
Access-Control-Request-Method
X-Ser
X-Fastly-Request-ID
X-SRCache-Store-Status
X-SRCache-Fetch-Status
S
X-Accel-Expires
Fastly-Restarts
X-Server-ID
X-DIS-Request-ID
X-Client-IP
Front-End-Https
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Length
X-XRDS-Location
X-Recruiting
X-Amz-Meta-S3cmd-Attrs
X-T
X-Id
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Element-Page-Cache
X-Varnish-Age
X-Goog-Storage-Class
X-Webapp-Samesite-None-Activated-N
Nginx-Cache
X-FTR-Realm
X-FTR-DC
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Balancer
Cache-Tag
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
MRF-Tech
X-FTR-Expires
X-Amzn-Trace-Id
Mrf-Cache-Status
X-Dw-Request-Base-Id
Fastcgi-Cache
X-Content-Digest
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
X-Frontend
NR-ENABLED
Powered
X-Hits
X-Correlation-Id
X-Hp-Webp
Alternate-Protocol
X-Ttl
X-Kinsta-Cache
X-FTR-Cache-Host
X-Fastcgi-Cache
X-Content-Type
X-Request-Processing-Time
X-Request-Received
ServerID
X-Aspnetmvc-Version
X-N
X-Microsite
Server-Name
X-Request-Handler-Origin-Region
X-RateLimit-Remaining
X-HS-Combine-CSS
X-Grace
X-Webkit-Csp
X-Cache-Hit
PB-PID
PB-RID
X-Rid
X-Mobile-Rewrite
Arc-Version
TP-L2-Cache
TP-Cache
Healthy
X-Akamai-Edgescape
X-Node-Name
X-User-Agent
X-Forwarded-For
X-Revision
X-Analytics
Backend-Timing
X-Content-Security-Policy-Report-Only
AMP-Access-Control-Allow-Source-Origin
X-Zen-Fury
X-Logged-In
Server-Node
X-LB-Cache
X-Mobile-URL
X-FastCGI-Cache
X-Pad
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Varnish-Grace
X-Activity-Id
X-AppVersion
X-Az
Cache-Status
X-Cached-By
X-GUploader-UploadID
X-NWS-LOG-UUID
X-B3-Sampled
X-Content-Options
X-Oneagent-Js-Injection
Refresh
X-IPLB-Instance
X-F-Cache
Accept-CH-Lifetime
Accept-CH
Upgrade-Insecure-Requests
X-Geo-Country
Retry-After
X-Type
X-Varnish-Backend
X-Srv
X-Ruxit-Js-Agent
Paypal-Debug-Id
X-App-Environment
X-Tumblr-User
X-Tumblr-Pixel
FilterID
X-Tumblr-Pixel-0
X-FB-Debug
X-Framework
AR-ATIME
AR-CACHE
X-Cluster
X-Request-Guid
DC
X-PHP-Backend
X-Jobs
X-Instance
AR-PoweredBy
X-Cache-2
X-Debug-Info
Access-Control-Allow-Method
Accept-Charset
Source
X-Page-Id
Host
Actual-Object-TTL
X-AOL-HN
X-WebKit-CSP-Report-Only
X-B
X-Cache-Key
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-ATG-Version
X-TT
Cache
X-Cache-Age
X-Seen-By
Fastcgi-Useragent
Ar-Sid
MS-CV
X-Git-Hash
X-Content-Powered-By
X-Via-JSL
VIX-Pulpo-Upstream-Status
X-Cache-TTL
VIX-Pulpo-Node
X-Signature
X-Whom
X-Amz-Replication-Status
X-B-Cache
Host-Header
X-PressLabs-Stats
X-Cache-Control
X-Daa-Tunnel
X-Wix-Request-Id
X-Origin-Server
NGB
X-Response-Served-From
Surrogate-Key
X-UA
X-Cache-Enabled
X-Mobile
X-RequestSource
X-Host-Name
X-Tumblr-Pixel-2
X-EdgeConnect-Cache-Status
X-GeoIP
Cache-Tv-Group
X-Tumblr-Pixel-1
X-FW-Type
X-FW-Static
WPE-Backend
Filters
Eomportal-Instance
Cleartype
Payment
X-Hyper-Cache
X-FW-Serve
X-FW-Hash
X-FW-Server
X-Handled-By
X-Region
AR-Request-ID
X-Cacheable-TTL
Xserver
X-TA-CDN-Provider
X-Adobe-Content
X-Adobe-Loc
X-Cache-NE
X-ATS-Timestamp
X-Drupal-Cache-Tags
Frame-Options
X-TX-ID
X-Cache-Action
X-Kong-Upstream-Latency
Webserver
X-Kong-Proxy-Latency
Datacenter
X-Hostname
X-Cache-Operation
X-Cache-Rule
X-Litespeed-Cache
X-SERVER
X-Load-Cache
X-Akamai-Transformed
From-Origin
X-NewRelic-App-Data
X-Esi
X-XRDS-LOCATION
X-RemovedCookies
X-ProcessESI
X-UA-Device-Type
X-Edge-Location
X-Cache-TTL-Remaining
Liferay-Portal
Ms-Operation-Id
X-RTag
X-VCache
X-Cache-Server
X-Forwarded-Host
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Varnish-Hostname
X-Varnish-Server
X-Yottaa-Metrics
X-Rule
X-Status
X-Yottaa-Optimizations
X-ORACLE-APMCS-REQUEST-ID
X-ORACLE-APMCS-TAG
X-App-Server
X-Contextid
Country
X-Upgrade-Enabled
Odigeo-Trace-Id
X-Tec-Api-Version
X-UUID
X-Tec-Api-Origin
X-Tec-Api-Root
X-TT-TIMESTAMP
Load-Balancing
X-ES-SERVER
X-Cache-Var
Meta-Geo
X-BCube-Filmed-By
X-Path-Route
X-RN-RSRV
X-Cache-Var-Map
DSUID
Mn-Server-Ip
X-Rocket-Nginx-Bypass
X-Origin-Hint
X-R9-Blue-Green-Version
Property-Id
Webcakes-App-Name
Release
TWC-Privacy
TWC-Locale-Group
Webcakes-App-Version
Webcakes-Region
X-From
X-Debug-Cache
X-CCM
TWC-GeoIP-LatLong
X-VCT
TWC-Connection-Speed
TWC-GeoIP-Country
TWC-Device-Class
X-IP
X-Hosted-By
X-Akamai-Request-ID
X-PCL
X-Cache-Config
Selected-Fe
X-FC-Vary-Parameters
X-Drupal-Cache-Contexts
S-Rt
X-Proto
X-FW-Dynamic
Azure-RegionName
X-Human
X-Origin-Response-Time
Cache-Name
Fastly-SSL
Cache-Tags
X-Loop
L5d-Success-Class
X-OCL
Azure-SiteName
Azure-SlotName
Azure-Version
Azure-InstanceId
X-Pubstack
X-Viewer-Country
X-TNCMS
X-Timing-Wait
X-EIG-Tracking-Id
DB-Nickname
X-Via-Fastly
X-Soup
X-Redis-Cache
X-Proxy-Build
X-Proxy
X-Vgn-Hpd-Reason
X-Real-IP
X-Locale
X-Backend-Name
Origin-Edge-Control
X-Origin
X-Akamai-Request-ID2
NGX
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Format
Viewport
X-Access
X-Cache-Host
X-Cache-Time
X-Xfnlog-Site
X-Site-Version
X-Www-Served-By
X-Section
X-NWS-UUID-VERIFY
X-Web-Node
Ec-Rule-Version
X-Time
X-ServerID
Origin-Cache-Control
Tracecode
X-Generated
X-Content-Age
X-FireWall-Port
X-ProxyCache-Key
X-ProxyCache-Status
X-BYPASS-REASON
Uber-Trace-Id
S-Cnection
X-Labrador-Cache-Channel
X-Cluster-Name
X-Is-Bot
Server-Info
X-JoinUs
X-Varnish-Cache-Hits
Decoy-Debug-Key
Decoy-Debug-Status
Decoy-Debug-TTL
X-Rendered-As
Version
X-Accel-Buffering
X-Time-Microsecs
X-Varnish-Hits
X-Generated-By
X-ApacheServer
X-Cache-Backend
X-PERF
X-Info
X-Presslabs-Stats
X-Amzn-Remapped-Content-Length
X-PHP-Host
X-Storage
Akamai-GRN
X-Origin-CC
X-Origin-TTL
X-SaId
Rt-Fastcgi-Cache
X-CF-Powered-By
GEO-INFO
X-Geo
X-Nginx-Cache-Key
X-URL
X-WA-Info
Cteonnt-Length
Cache-Key
Time
X-No-Session
X-MServer
X-L-Path
X-Unique-Id
X-App-Version
X-APP-VERSION
Origin
X-Environment-Context
X-Cache-Remote
X-Backend-TTL
X-Guploader-Uploadid
X-FB-TRIP-ID
X-GoCache-CacheStatus
Accept-Language
Access-Control-Request-Headers
X-Tb
X-CDN-Forward
X-NCache
X-Say-TTL
X-SayCDN-TTL
X-Say-Cacheable
Vix-Hermes-Req-Id
X-RateLimit-Limit
X-Hit
Cache-Hits
X-EC-Lua
X-Trace-Id
X-ShopId
X-Alternate-Cache-Key
X-ShardId
X-Shopify-Stage
X-Sorting-Hat-ShopId
Srv
X-Sorting-Hat-PodId
X-SS-Set-Cookie
X-Shopify-Generated-Cart-Token
X-Device-Type
X-CS
X-Tumblr-Pixel-3
X-TIME
X-Dc
X-B3-Traceid
X-RCS-CacheZone
X-B3-SpanId
X-Source
X-OVcl
X-OVcl-Cache
X-Cluster-Node
Mime-Version
X-S
OT-Force-Account-Verify
Server-Host
BehaviorPad-Version
X-CF-Lambda-Fn
Mobile-Detection-Method
T-Server
X-Rewrite-Enabled
X-G
X-Request-UUID
Rt-Proxy-Cache
X-Region-Sid
X-CF-Lambda-Version
Meta-Geo-Continent
Node
Rendered-Blocks
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Request-Country
Request-EU
MD5-Digest
Apple-News-Services-Request-Url
Arc-Country
X-Endurance-Cache-Level
Apple-News-Services-Handled
X-Processor
X-B-Cookie
User-Cache-Control
X-PAYTM-SRV-ID
AsisCache
X-Hl-Ver
VivaBuild
X-A-Ccd
X-Vdms-Version
X-VG-WebCache
X-VG-WebServer
IsBot
X-A
X-AIR-PT
X-Trv-Group
X-External-Request-Id
X-Destination
X-Connection-Hash
X-A-Dam
X-Vtex-Processado-Em
X-Accel-Expires-Debug
X-A-Wwc
Xc-Version
X-Aed
X-D
X-Parent-Response-Time
X-Date
X-Vtex-Remote-Cache
NtCoent-Length
X-A-Dcw
X-A-Dgt
X-Transaction
X-Twitter-Response-Tags
X-Service
X-Detected-As
Cross-Origin-Window-Policy
X-DPWN-IS-SECURE
X-Server-Time
Content-Style-Type
X-Rojux
X-S-Cookie
Content-Script-Type
X-ScT
Viewtype
X-Session-Fingerprint
X-Application
X-CACHE-KEY
Fastcgi-X-Cache-Version
Machine
X-SIPLIST1
X-Svr
X-Magnolia-Registration
X-SRCache-Key
X-ARC
ServedBy
ServerName
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
Now
X-Generated-On
X-Hash
X-Dispatch
X-CUA
Server-Int
X-Core-Value
Thinkindot-CacheControl
X-Reboot
Served-By
X-Ah-Environment
X-Instart-Isnd
X-Upstream-Ht
X-Thinkindot-L3
Wxu-Next-Hostname
Thinkindot-Control
Thinkindot-CacheControl-Type
X-Upstream-Ct
Wxu-Next-Commit
Wxu-Next-Region
X-Matched-Rule
X-Location
X-Level-Front-Cache
X-Via-NSCOPI
X-Webstats-RespID
X-Cache-Bucket
X-Uri
X-Cache-Grace
X-CSRF-TOKEN
X-Agile-Id
X-Core-Mission
X-Cms-Context
X-Compress-Hint
X-Clientip
X-App-Name
X-CGP
X-C
X-Block-Status
X-Cache-Debug
X-Cache-Info
X-Cache-URL
X-Bip
X-BBXSRF
X-Azure-Ref
X-Clara-WADP
X-Azure-Ref-OriginShield
X-B3-Parentspanid
X-Backend-State
X-Auto-Login
X-Method
X-Server-IP
X-Scheme
X-Sigma
X-Sigma-Backend
X-Sucuri-Cache
X-Skip-Cache
X-Rocket-Build-Number
X-Reqid
X-Qloud-Router
X-Proxy-Upstream
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Release
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-We-Are-Hiring
X-WADP-Cache
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-ND-Cache
X-Dispatcher-Server
X-VServer
X-VG-TLSProxy
X-TrackingId
X-Thanos
X-Up
X-User
X-VC-Cache
X-Proxy-Cache-Status
X-Planisys-CDN-TTL
X-FW-Version
X-Fastly-Cache
X-Gen-Mode
X-Generation-Time
X-GeoIP-City
X-Geo-Header
X-Eu-Site
X-Distil-CS
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Debug-Cookies
X-Debug-Log
X-Developers
X-Has-Esi
X-Hnp-Log
X-NX-Host
X-Ms-Version
X-Origin-Date
X-Origin-Expires
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Ms-Request-Id
X-Agile-Age
X-Is-Gdpr
X-Irp-Debug
X-JWT-State
X-Key
X-Logging-Id
X-Debug-Cache-Expiry
X-Cdn-Srv
Ha-Gx-Prefs
Gh-Request-Id
Fastly-Soc-X-Request-Id
Esi-Enabled
HA-Ipaddr
Heartbleed
Magicmarker
L
IBM-Web2-Location
Countrycode
Content-Disposition
Proxy-Connection
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
X-Agile
Mail-Subject
We-Hiring
CDCHOST
Cache-Host
AKAMAI
Memcached
X-Varnish-Beresp-Ttl
RNT-Time
RNT-Machine
Section-Io-Cache
Pramga
PFcat
Web-Mar-Node
W
X-SRV
Cache-Provider
X-WebServer
SD-X-WS
X-LI-UUID
X-Variation
X-Internal-Host
X-S-Maxage
X-Owner
X-Request-Start
X-Request-URI
X-Generated-In
X-SD-PageType
Platform
X-Old-Content-Length
X-Policy
X-Li-Fabric
X-Amz-Meta-Cache-Control
X-NC
X-Epic-Correlation-Id
X-Distributor
X-Swa-Ws
X-Cache-FS-Status
Is-Eu
Kp-EeAlive
Adler-Geo
X-Li-Pop
X-Platform-Server
X-B3-Spanid
X-Nc
X-Via-CDN
X-Cache-Id
X-LI-Proto
True-Client-Country-4JS
X-MSEdge-Features
X-Urbn-Site-Id
Locale
X-AK-Request-ID
X-Urbn-Context-Path
Cdncip
X-NodeID
X-Trafficlayer-App-Version
Cdnsip
Server-ID
X-MSEdge-Flight
X-ServiceProvider
X-NODE
Powered-By-ChinaCache
X-Servername
V-Age
CF-IPCountry
Environment
X-Req
X-Served-From
GEO-REGION-INFO
Locid
X-Be
X-Lb-Id
Hostname
X-Newrelic-Synthetics
X-UnsetCookies
X-HTML-Minification-Powered-By
X-Cdn-Forward
X-GRACE
X-7Graus-Varnish-XKeys
X-Gamma-Serve
FNAC-ModuleRouting
X-Refresh
X-7Graus-Varnish-Cache-Control
X-FPC
X-Sucuri-Id
X-Sucuri-ID
X-Zone
X-VHOST
X-IPS-LoggedIn
A
X-Nginx-Cache
X-Render-Time
X-Developer
X-Servedbyhost
X-Cdn-Origin
X-NU-AKA-ACS-Version
X-Sn-Servicetimems
Tcn
X-Microcachable
X-Device-Os
X-Tb-Optimization-Total-Bytes-Saved
Geo-Info
X-Mode
X-Edge-O15-RID
X-Webkit-CSP
X-MP-GENERATED-AT
X-Node-Id
X-GeoIP-Country-Code
ProcessTime
X-Pf-Uncompressing
X-Ratelimit-Remaining
X-FORWARDED-FOR
Memory
X-LJ-Flow-ID
X-Pjax-Url
Request-Time
X-AWS-Id
X-VWS-Id
X-Zipkin-Id
X-Routing-Service
X-Proxied
Gannett-Cam-Experience-Id
Geoip-Latitude
GeoIp-Country-Code
X-CSRF-Token
TTL
X-COUNTRY
X-Correlation-ID
X-VCL-Version
Amp-Access-Control-Allow-Source-Origin
PICS-Label
X-DC
Resin-Trace
XServer
CF-Cached-On
M-TraceId
Cache-Cookie-Set-Lfrom
Cf-Ipcountry
Pics-Label
X-Pod
Cache-Cookie-Set-Idcheck
Group
X-Ratelimit-Limit
Cache-Cookie-Set-From
MIME-Version
X-Vcl-Version
GeoIP-Country-Code
X-ZONE
X-Bc
X-Instart-Info
Geoip-City
X-Via-Edge
X-Via-SSL
X-ECACHE
X-ElasticPress-Search
HostName
GeoIP-City
GeoIP-Latitude
X-Unique-ID
X-Request-Time
X-Var-Ttl
Host-ID
X-Backend-Url
Cdn
X-Backend-Host
X-NGINX-Cache
X-Cdn-Request-ID
X-CLOUD-TRACE-CONTEXT
X-Swift-Error
Ttl
Backend-Name
X-TH-Server
Ohc-Cache-HIT
Ohc-File-Size
X-APP
X-BC
X-NGENIX-Cache
Pagetype
X-UPSTREAM-Address
X-PJAX-URL
Lfy
N-Cache
HitType
X-PF-Uncompressing
URI
X-Check-Cacheable
REQUESTUUID
Powered-By
Fly-Cache
Fly-Request-Id
X-Fastly-Country-Code
X-Fstrz
Cache-Prefix
X-Tt-Trace-Tag
X-Via-Ucdn
Media-Length
X-Worker
On-Server
User-Agent
X-HostName
X-Aicache-OS
X-Cache-Tag
X-Sedo-Request-Id
CDN
X-WR-MODIFICATION
Pragrma
X-Cache-Miss-From
X-ServedByHost
X-LiteSpeed-Cache-Control
SRV
Who
X-Hp-Ccpa-Warning
X-Tt-Trace-Host
X-HS-Status
FSS-Cache
X-GEO
FSS-Proxy
X-WA
X-Fetched-On
X-Server-W
AR-SID
Processtime
UCS
X-Rebelmouse-Cache-Control
X-BE
Fastly-SWR
Fastly-SIE
X-Wa
X-Rebelmouse-Surrogate-Control
X-Upstream-CT
X-Upstream-HT
X-NYM-Debug-Backend
X-Cache-Tags
X-LB-ID
X-Varnish-URL
X-Varnish-Cacheable
X-Fpc
X-Dynatrace-Js-Agent
X-LAGOON
X-Cf-Powered-By
X-Cache-ASPX
Debug
X-Store
X-Fastly-Backend-Reqs
X-Varnish-Authentication
X-Contensis-Viewer-Groups
Server-Cache-Control
X-ServerName
Server-Surrogate-Control
X-TT-LOGID
X-Ftr-Cache-Host
X-Ua
X-GDPR
Server-Id
Country-Code
X-Protected-By
X-Varnish-Beresp-TTL
X-Akamai-ERPolicy
Fastly-Backend-Name
X-Apw-Access-Token
X-Apw-Hits
X-Apw-Access-Object
X-Apw-Access-Action
Location
X-Akamai-ERRuleID
DataCenter
X-Nananana
X-Edge-Server
Cdn-Request-Time
X-Li-Proto
SID
NnCoection
Product
Application
X-Fastly-Cache-Hits
X-Gen-Id
Cdn-Host
Thinkindot-Cache-Type
X-Amzn-Remapped-Date
X-Request-Url
XxX-Cache-Status
X-Amzn-Remapped-Connection
X-SB
X-VC
X-SN
X-Dw-Trace-Id
WP-Super-Cache
Xet-Cookie
Cneonction