Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
CF-RAY
CF-Cache-Status
Pragma
Link
X-Powered-By
ETag
X-XSS-Protection
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Xss-Protection
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Download-Options
Alt-Svc
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-FRAME-OPTIONS
X-Drupal-Cache
X-Adblock-Key
X-Check
Content-Security-Policy-Report-Only
X-Generator
X-Cache-Status
X-Cacheable
X-Permitted-Cross-Domain-Policies
X-Request-ID
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Template
X-Language
X-Iinfo
X-Content-Security-Policy
Status
Content-Encoding
X-Buckets
X-AspNetMvc-Version
Access-Control-Expose-Headers
Upgrade
Xkey
X-Kinja-Server-Push
Access-Control-Max-Age
X-CDN
Keep-Alive
X-Drupal-Dynamic-Cache
X-Turbo-Charged-By
X-Via
X-Cache-Group
X-Age
X-Pass-Why
X-Envoy-Upstream-Service-Time
X-Ua-Compatible
X-Backend
EagleId
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-AH-Environment
X-Page-Speed
X-Pingback
X-Server-Powered-By
X-UA-Device
X-Server
X-Swift-CacheTime
X-Swift-SaveTime
X-Proxy-Cache
X-Hacker
Ali-Swift-Global-Savetime
X-Nginx-Cache-Status
Request-Context
Grace
X-Varnish-Cache
Server-Timing
Feature-Policy
Cf-Railgun
X-Amz-Version-Id
X-LiteSpeed-Cache
X-Device
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Rq
X-WebKit-CSP
Report-To
X-Ac
EagleEye-TraceId
X-Server-Id
X-Dns-Prefetch-Control
X-OneAgent-JS-Injection
X-Response-Time
X-Host
X-Cnection
Request-Id
X-Backend-Server
X-DataDome
X-Cdn
Content-Location
X-Cloud-Trace-Context
X-Node
X-Origin-Cache
X-Readtime
X-Cache-Lookup
NEL
X-Vhost
X-Application-Context
X-Dispatcher
X-ORACLE-DMS-ECID
X-HW
Allow
X-ORACLE-DMS-RID
X-Clacks-Overhead
X-Rack-Cache
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Origin-Upstream-Status
X-Country
Surrogate-Control
Rating
X-DynaTrace
X-FTR-Request-ID
X-Ws-Request-Id
X-Country-Code
Pinterest-Generated-By
X-Goog-Hash
Fusion-Content-Source
Fusion-Component-Id
Fusion-Template-Id
Fusion-Source
Fusion-Content-Id
X-Akam-SW-Version
X-Varnish-TTL
X-MS-InvokeApp
X-TtlSet
X-Vname
X-PC
X-Url
Accept-Ch
X-Instart-Request-ID
X-Ruxit-JS-Agent
Edge-Control
X-B3-TraceId
Verso
X-Powered-By-Plesk
X-Mod-Pagespeed
X-Aspnetmvc-Version
SPRequestGuid
X-Sol
X-Middleton-Response
Response
X-D2id
Display
X-Middleton-Display
X-Trace
X-SharePointHealthScore
X-VARITI-CCR
Accept-Ch-Lifetime
X-Cdn-Fetch
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Kinja-Build
X-Kinja
X-Exp-Variant
X-GoogleNews-Bot
X-Exp-Id
RTSS
Service-Worker-Allowed
X-Server-Name
X-GitHub-Request-Id
Pagespeed
SPIisLatency
SPRequestDuration
X-Server-ID
X-Navigation-Version
X-ESI
X-Powered-CMS
X-Debug
X-Abt-Application-Version
X-Vcap-Request-Id
X-CST
Content-MD5
Public-Key-Pins
X-Amz-Server-Side-Encryption
MS-Author-Via
X-Px
X-Version
X-TTL
X-Upstream
Charset
X-Ah-Environment
X-Amz-Rid
X-Forwarded-Proto
X-Vcache
X-NF-Request-ID
DynaTrace
X-Cached
Realpath
X-Shard
TCN
Fastly-Restarts
X-Recruiting
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
MicrosoftSharePointTeamServices
X-Ezoic-Cdn
Edge-Cache-Tag
Arr-Disable-Session-Affinity
X-MSEdge-Ref
X-Pinterest-Rid
Pinterest-Version
X-DynaTrace-JS-Agent
X-Shield-Request-Id
Access-Control-Request-Method
X-XRDS-Location
Nginx-Cache
X-SRCache-Fetch-Status
X-SRCache-Store-Status
S
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Ser
X-Goog-Stored-Content-Length
X-Fastly-Request-ID
Front-End-Https
X-Accel-Expires
X-Amz-Meta-S3cmd-Attrs
X-DIS-Request-ID
X-Goog-Storage-Class
X-Id
X-Element-Page-Cache
X-Varnish-Age
X-Client-IP
X-T
X-FTR-Realm
X-FTR-DC
X-FTR-Backend
X-Country-Code-Real
X-FTR-Backend-Server
X-FTR-Cache-Status
X-FTR-Balancer
X-Ttl
Mrf-Cache-Status
X-Mrf-Item-Lastmod
MRF-Tech
X-B3-TraceId-Primal
X-Mrf-Section-Lastmod
X-FTR-Expires
X-Amzn-Trace-Id
X-RateLimit-Remaining
X-Trafficlayer-App-Scope
X-Trafficlayer-App-Name
X-Dw-Request-Base-Id
X-SERVER
Fastcgi-Cache
NR-ENABLED
X-HS-Content-Id
X-HS-Hub-Id
X-Frontend
X-Content-Digest
Powered
X-Hits
X-Fastcgi-Cache
Cache-Tag
X-Kinsta-Cache
ServerID
X-Correlation-Id
AR-ATIME
AR-CACHE
AR-PoweredBy
Ar-Sid
X-Grace
X-Forwarded-For
X-HS-Cache-Config
X-Litespeed-Cache
TP-Cache
TP-L2-Cache
X-FTR-Cache-Host
X-Cache-Hit
X-Node-Name
X-N
PB-PID
Alternate-Protocol
PB-RID
Arc-Version
AMP-Access-Control-Allow-Source-Origin
X-Mobile-Rewrite
X-Request-Received
X-Request-Processing-Time
X-Request-Handler-Origin-Region
X-Microsite
X-Content-Type
X-Hp-Webp
X-Webkit-Csp
X-Zen-Fury
Server-Name
X-Rid
X-User-Agent
X-Webapp-Samesite-None-Activated-N
X-Srv
Server-Node
X-Analytics
X-Revision
Healthy
Backend-Timing
X-FastCGI-Cache
X-LB-Cache
X-AppVersion
X-Content-Security-Policy-Report-Only
X-Az
X-Activity-Id
Cache-Status
X-Ruxit-Js-Agent
X-Akamai-Edgescape
X-Via-JSL
X-Logged-In
Retry-After
Paypal-Debug-Id
X-IPLB-Instance
AR-Request-ID
X-Amzn-RequestId
X-Type
X-Amz-Apigw-Id
X-Cached-By
X-HS-Combine-CSS
X-NWS-LOG-UUID
X-Oneagent-Js-Injection
X-GUploader-UploadID
X-Varnish-Grace
X-Pad
FilterID
X-Cache-Age
X-B3-Sampled
X-Mobile-URL
X-F-Cache
X-Content-Options
X-Geo-Country
Refresh
X-Tumblr-Pixel-0
X-Instance
X-FB-Debug
X-Tumblr-Pixel
Accept-Charset
X-Debug-Info
X-Tumblr-User
Source
Host
Access-Control-Allow-Method
X-App-Environment
X-Page-Id
X-Request-Guid
X-Jobs
X-AOL-HN
X-Cluster
Actual-Object-TTL
X-Seen-By
X-B
X-Framework
X-PHP-Backend
DC
X-Erf-Bev-Bev-Is-Generated
X-PressLabs-Stats
X-Erf-Bev-Bev
Upgrade-Insecure-Requests
X-Whom
X-Varnish-Backend
MS-CV
X-WebKit-CSP-Report-Only
X-Esi
Fastcgi-Useragent
VIX-Pulpo-Upstream-Status
X-Content-Powered-By
VIX-Pulpo-Node
X-ATG-Version
X-Cache-Key
X-Cache-2
X-Git-Hash
X-TT
X-Time
X-Host-Name
X-Cache-Control
X-VCache
X-Cache-TTL
Surrogate-Key
X-Cache-Rule
X-Cache-Operation
X-Amz-Replication-Status
X-TA-CDN-Provider
Cache
X-Wix-Request-Id
Frame-Options
X-Forwarded-Host
X-FW-Hash
X-FW-Serve
X-FW-Static
X-Kong-Upstream-Latency
X-FW-Type
X-FW-Server
X-Kong-Proxy-Latency
Accept-CH-Lifetime
X-B-Cache
X-Signature
NGB
X-Response-Served-From
Xserver
Host-Header
Accept-CH
X-Origin-Server
X-Daa-Tunnel
X-Mobile
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
Cache-Tv-Group
X-Cache-Action
Eomportal-Instance
WPE-Backend
X-Hyper-Cache
X-Region
X-TX-ID
X-GeoIP
X-Drupal-Cache-Tags
Payment
Webserver
X-Cache-NE
Filters
X-RequestSource
X-Adobe-Loc
X-Adobe-Content
From-Origin
X-Handled-By
X-Cacheable-TTL
X-UA-Device-Type
Cleartype
Tracecode
X-App-Server
X-RemovedCookies
X-EdgeConnect-Cache-Status
X-Cache-Enabled
X-ProcessESI
X-Webkit-CSP
X-UA
X-RTag
Ms-Operation-Id
Datacenter
X-Cache-TTL-Remaining
X-RateLimit-Limit
X-Akamai-Transformed
X-Status
X-Contextid
X-Hostname
X-NewRelic-App-Data
X-Load-Cache
Liferay-Portal
X-Cache-Server
X-Edge-Location
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-BCube-Filmed-By
X-TT-TIMESTAMP
X-Varnish-Hostname
X-FW-Dynamic
Odigeo-Trace-Id
X-Varnish-Server
Server-Info
X-Path-Route
X-IP
Version
X-Rule
X-Cache-Var
X-Cache-Var-Map
Meta-Geo
Load-Balancing
X-RN-RSRV
X-ES-SERVER
X-Viewer-Country
X-Xfnlog-Site
X-Rocket-Nginx-Bypass
X-UUID
X-CCM
X-OCL
X-PCL
Country
DB-Nickname
Cache-Tags
X-Cache-Config
X-Debug-Cache
X-Web-Node
X-Drupal-Cache-Contexts
X-Info
X-Labrador-Cache-Channel
X-Akamai-Request-ID
X-Loop
X-Cache-Host
Azure-InstanceId
TWC-GeoIP-LatLong
Mn-Server-Ip
L5d-Success-Class
Fastly-SSL
X-From
X-FC-Vary-Parameters
Property-Id
TWC-Device-Class
TWC-Connection-Speed
X-EIG-Tracking-Id
S-Rt
TWC-Locale-Group
X-Origin-Hint
Azure-RegionName
TWC-GeoIP-Country
Webcakes-App-Version
Webcakes-Region
Azure-SiteName
Azure-SlotName
Cache-Name
TWC-Privacy
Azure-Version
Webcakes-App-Name
X-Hosted-By
X-Origin
X-Origin-Response-Time
X-Pubstack
X-R9-Blue-Green-Version
X-TNCMS
X-Upgrade-Enabled
X-Proto
X-Via-Fastly
X-Varnish-Cache-Hits
X-Proxy
X-Origin-TTL
X-Real-IP
X-ServerID
X-Origin-CC
X-Backend-Name
X-ApacheServer
DSUID
Decoy-Debug-TTL
X-Cache-Time
X-Content-Age
X-Generated
Decoy-Debug-Key
Decoy-Debug-Status
X-Cluster-Name
Ec-Rule-Version
X-Akamai-Request-ID2
S-Cnection
X-Rendered-As
X-Section
Selected-Fe
Release
X-VCT
X-Access
X-FireWall-Port
Origin-Cache-Control
Origin-Edge-Control
X-Proxy-Build
X-Format
X-JoinUs
X-Human
X-Timing-Wait
X-App-Version
X-PERF
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Redis-Cache
X-Vgn-Hpd-Reason
X-Varnish-Hits
X-Soup
X-Time-Microsecs
X-XRDS-LOCATION
Viewport
X-Site-Version
X-Www-Served-By
X-Storage
Rt-Fastcgi-Cache
NGX
X-Locale
X-WA-Info
Cache-Key
X-NWS-UUID-VERIFY
X-Is-Bot
GEO-INFO
X-ATS-Timestamp
X-Guploader-Uploadid
X-ProxyCache-Key
X-ProxyCache-Status
X-BYPASS-REASON
Vix-Hermes-Req-Id
X-B3-Traceid
Uber-Trace-Id
X-Cache-Grace
X-Oss-Object-Type
X-Oss-Storage-Class
X-GoCache-CacheStatus
Cteonnt-Length
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-Hit
Cache-Hits
X-Backend-TTL
X-PHP-Host
X-NCache
X-Cache-Backend
X-Generated-By
Time
X-SS-Set-Cookie
X-B3-SpanId
X-Amzn-Remapped-Content-Length
Origin
X-Cache-Remote
X-CS
X-Device-Type
X-Trace-Id
Akamai-GRN
X-CF-Powered-By
X-Tumblr-Pixel-3
Accept-Language
X-Accel-Buffering
X-OVcl
X-OVcl-Cache
X-ORACLE-APMCS-TAG
X-Nginx-Cache-Key
Mime-Version
X-ORACLE-APMCS-REQUEST-ID
Hostname
X-S
X-CACHE-KEY
X-UnsetCookies
X-Environment-Context
X-L-Path
X-Cluster-Node
X-No-Session
X-FB-TRIP-ID
X-Uri
X-Via-CDN
Fastcgi-X-Cache-Version
X-Tb
X-MServer
X-CSRF-TOKEN
Now
Access-Control-Request-Headers
X-Say-TTL
X-SayCDN-TTL
X-URL
X-Cdn-Forward
X-FW-Version
X-Say-Cacheable
ServerName
User-Cache-Control
Request-EU
Rendered-Blocks
Request-Country
Viewtype
Node
X-A
VivaBuild
T-Server
Rt-Proxy-Cache
AsisCache
Arc-Country
X-A-Ccd
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
Apple-News-Services-Host
BehaviorPad-Version
Content-Script-Type
MD5-Digest
Meta-Geo-Continent
Machine
IsBot
Content-Style-Type
Cross-Origin-Window-Policy
Mobile-Detection-Method
X-A-Wwc
X-Rewrite-Enabled
X-Rojux
X-S-Cookie
X-ScT
X-Request-UUID
X-Region-Sid
X-Processor
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
X-Server-Time
X-Session-Fingerprint
X-Twitter-Response-Tags
X-VG-WebCache
X-VG-WebServer
X-Trv-Group
X-Transaction
X-SIPLIST1
X-SRCache-Key
X-Svr
X-PAYTM-SRV-ID
X-Hl-Ver
Xc-Version
X-Application
X-ARC
X-AIR-PT
X-Aed
X-A-Dcw
X-A-Dgt
X-Accel-Expires-Debug
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-DPWN-IS-SECURE
X-External-Request-Id
X-G
X-Detected-As
X-Destination
X-Connection-Hash
X-D
X-Date
X-A-Dam
X-B-Cookie
X-Tec-Api-Root
X-Tec-Api-Origin
X-Tec-Api-Version
X-SaId
OT-Force-Account-Verify
X-Presslabs-Stats
Proxy-Connection
X-Endurance-Cache-Level
X-Cache-Info
X-Cache-Debug
X-Thinkindot-L3
X-Debug-Log
X-NC
X-WADP-Cache
Thinkindot-CacheControl
X-Cache-Bucket
X-Debug-Cookies
X-Clara-WADP
CDCHOST
X-Proxy-Cache-Status
X-Location
Web-Mar-Node
Server-Host
Server-Int
Thinkindot-CacheControl-Type
Thinkindot-Control
RNT-Time
RNT-Machine
X-APP-VERSION
X-Proxy-Upstream
X-Reboot
X-Request-URI
X-S-Maxage
X-Block-Status
X-Cms-Context
X-Gen-Mode
X-Hnp-Log
We-Hiring
Mail-Subject
X-NX-Host
X-Matched-Rule
NtCoent-Length
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Ttl
ServedBy
X-Internal-Host
X-Irp-Debug
X-Request-Start
X-Alternate-Cache-Key
X-Release
X-Reqid
X-Amz-Meta-Cache-Control
X-Instart-Isnd
X-Auto-Login
X-RateLimit-Limit-Second
X-IN-APIGATEWAYSSL
X-Magnolia-Registration
X-RateLimit-Remaining-Second
X-App-Name
X-Is-Gdpr
X-Level-Front-Cache
X-Key
X-Nc
True-Client-Country-4JS
X-Li-Fabric
X-LI-UUID
X-Li-Pop
W
X-Dispatcher-Server
Wxu-Next-Region
X-7Graus-Varnish-Cache-Control
X-7Graus-Varnish-XKeys
Wxu-Next-Hostname
Wxu-Next-Commit
X-Dispatch
X-JWT-State
X-Azure-Ref
X-Azure-Ref-OriginShield
X-Core-Mission
X-CUA
X-Origin-Expires
X-Compress-Hint
X-Ms-Request-Id
X-Distributor
X-Clientip
X-Origin-Date
X-Debug-Cache-Expiry
X-Debug-Cache-Store
X-Epic-Correlation-Id
X-Developer
X-Eu-Site
X-Debug-Cache-Fetch
X-Ms-Version
X-Fastly-Cache
X-CGP
X-Generated-In
X-Policy
X-Developers
X-C
X-BBXSRF
X-Distil-CS
X-IN-APIGATEWAY
X-Backend-State
X-Hash
X-Has-Esi
X-Platform-Server
X-Cache-URL
X-Cdn-Srv
X-Generated-On
X-Cache-Id
X-Generation-Time
X-Cache-FS-Status
X-Old-Content-Length
X-SD-PageType
Gh-Request-Id
Ha-Gx-Prefs
X-TrackingId
X-Up
Esi-Enabled
Fastly-Soc-X-Request-Id
HA-Ipaddr
IBM-Web2-Location
Memcached
X-Sorting-Hat-ShopId
Magicmarker
Kp-EeAlive
Is-Eu
X-Server-IP
Countrycode
X-Wikidot-Backend
X-Webstats-RespID
X-Wikidot-Static-Cache
Adler-Geo
A
X-WebServer
X-We-Are-Hiring
Content-Disposition
X-Variation
X-VG-TLSProxy
X-VServer
Cache-Host
X-Sorting-Hat-PodId
X-User
X-Shopify-Stage
X-ShopId
X-Skip-Cache
X-ShardId
Platform
Section-Io-Cache
SD-X-WS
Served-By
X-Service
Cache-Provider
X-Sucuri-Id
X-Parent-Response-Time
X-B3-Parentspanid
X-MSEdge-Features
X-GRACE
X-Owner
X-Urbn-Site-Id
X-Core-Value
V-Age
AKAMAI
X-Scheme
X-ServiceProvider
X-VC-Cache
X-MSEdge-Flight
Pramga
X-Urbn-Context-Path
X-Geo-Header
X-Qloud-Router
X-Logging-Id
L
X-Swa-Ws
X-Agile
X-SVT-ORM-VERSION
Locale
X-Agile-Age
PFcat
X-Method
X-GeoIP-City
X-SVT-ORM-RULES
X-Agile-Id
X-LI-Proto
Heartbleed
X-Bip
X-Thanos
X-Geo
Srv
X-NodeID
Server-ID
X-Device-Os
X-Sn-Servicetimems
X-Cdn-Origin
X-Node-Id
X-Dc
X-Vdms-Version
X-Servername
X-Lb-Id
X-EC-Lua
X-Rocket-Build-Number
GEO-REGION-INFO
X-AK-Request-ID
X-Sigma-Backend
X-Sucuri-Cache
X-CDN-Forward
X-Shopify-Generated-Cart-Token
Cdnsip
X-Sigma
Cdncip
CF-IPCountry
Environment
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Unique-Id
X-Newrelic-Synthetics
X-FPC
X-Nginx-Cache
Powered-By-ChinaCache
X-Via-NSCOPI
X-Upstream-Ct
X-Upstream-Ht
X-Be
Request-Time
X-Servedbyhost
X-GEO
X-Zone
X-B3-Spanid
X-ND-Cache
X-VHOST
X-Tb-Optimization-Total-Bytes-Saved
X-Microcachable
X-Pjax-Url
Resin-Trace
X-RCS-CacheZone
X-Source
X-ECACHE
X-NGENIX-Cache
X-Trafficlayer-App-Version
X-ElasticPress-Search
Tcn
X-Instart-Info
X-Unique-ID
X-Correlation-ID
X-Backend-Url
Group
X-Backend-Host
Geo-Info
X-Var-Ttl
Backend-Name
X-Req
X-IPS-LoggedIn
Locid
X-Oracle-Dms-Rid
X-DC
CF-Cached-On
X-AWS-Id
N-Cache
X-Served-From
X-VWS-Id
X-VCL-Version
Memory
X-LJ-Flow-ID
FNAC-ModuleRouting
X-Gamma-Serve
Ohc-Cache-HIT
X-Dynatrace
Ohc-File-Size
SRV
Fly-Request-Id
Pagetype
Fly-Cache
Gannett-Cam-Experience-Id
Cache-Prefix
Lfy
X-Refresh
X-COUNTRY
X-Worker
X-Upstream-HT
GeoIP-City
X-Ratelimit-Remaining
X-Upstream-CT
GeoIP-Latitude
Pics-Label
Cf-Ipcountry
Amp-Access-Control-Allow-Source-Origin
X-Pf-Uncompressing
TTL
X-Check-Cacheable
GeoIP-Country-Code
Cdn
ProcessTime
PICS-Label
X-Render-Time
M-TraceId
X-Cache-Miss-From
X-Pod
X-Sucuri-ID
X-Bc
X-Via-Ucdn
X-SRV
X-Sedo-Request-Id
X-Fetched-On
X-HTML-Minification-Powered-By
X-Via-Edge
REQUESTUUID
X-Via-SSL
GeoIp-Country-Code
Ttl
Geoip-Latitude
X-Server-W
X-NU-AKA-ACS-Version
Geoip-City
X-CSRF-Token
XServer
PageSpeed
X-Vcl-Version
X-Wa
Fastly-SWR
Fastly-SIE
X-APP
X-Rebelmouse-Cache-Control
X-Ua
X-Rebelmouse-Surrogate-Control
X-Mode
X-GeoIP-Country-Code
X-PF-Uncompressing
X-TIME
X-CLOUD-TRACE-CONTEXT
X-Fstrz
X-LiteSpeed-Cache-Control
X-FORWARDED-FOR
X-HS-Status
Cache-Cookie-Set-Lfrom
X-ZONE
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-From
X-Tt-Trace-Tag
X-Ratelimit-Limit
X-Upstream-Proxy
X-Fastly-Country-Code
X-Cache-Tag
HitType
MIME-Version
X-Ratelimit-Reset
X-GDPR
X-MP-GENERATED-AT
X-Dynatrace-Js-Agent
User-Agent
HostName
Cdn-Request-Time
Pragrma
Cdn-Host
On-Server
Host-ID
X-Edge-Server
X-Swift-Error
X-HostName
X-WR-MODIFICATION
X-Aicache-OS
X-NGINX-Cache
X-BC
X-SN
X-ServedByHost
URI
X-Proxied
X-Flog
X-Hello
X-WA
X-Org
X-TT-LOGID
X-PJAX-URL
X-BE
X-Zipkin-Id
X-ABtesting
X-Response-By
SS
Who
X-Routing-Service
X-Ftr-Cache-Host
X-Cdn-Request-ID
X-RateLimit-Reset
CACHE
X-DW
X-DSS
X-DB
X-Edge-O15-RID
X-Action
SN
X-DI
X-UPSTREAM-Address
X-RSL
X-Fastly-Backend-Reqs
X-TH-Server
X-RPS
X-Fpc
X-RPM
X-Cache-Ttl
Dynatrace
Requestid
X-Cf-Powered-By
CDN
X-Varnish-Cacheable
X-Varnish-URL
Powered-By
X-LAGOON
Lb
DataCenter
X-Page-Type
RequestUuid
Get-Access-Time
Is-Session-Tracking
X-ServerName
Server-Id
Country-Code
Media-Length
LB
Debug
X-VC
X-SB
X-Nananana
X-LB-ID
X-Varnish-Beresp-TTL
X-Gen-Id
X-Request-Time
X-Protected-By
XxX-Cache-Status
X-MID
X-Request-Url
X-Edge
NnCoection
X-MCACHE
UCS
X-Fastly-Cache-Hits
X-LiteSpeed-Tag
Warning
Thinkindot-Cache-Type
X-Dw-Trace-Id
X-Akamai-ERPolicy
X-Amzn-Remapped-Connection
X-Akamai-ERRuleID
X-Li-Proto
RequestId
Application
Product
X-Amzn-Remapped-Date
Xet-Cookie
SID
Correlation-Id
X-Tt-Trace-Host