Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
CF-RAY
CF-Cache-Status
Pragma
Link
X-Powered-By
ETag
Expect-CT
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Xss-Protection
X-Varnish
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
Alt-Svc
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-FRAME-OPTIONS
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Request-ID
X-Generator
Content-Security-Policy-Report-Only
X-Cache-Status
X-Cacheable
X-Permitted-Cross-Domain-Policies
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-Template
X-Language
Status
X-Content-Security-Policy
X-AspNetMvc-Version
X-Buckets
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Xkey
X-CDN
Access-Control-Max-Age
Keep-Alive
X-Drupal-Dynamic-Cache
X-Kinja-Server-Push
X-Turbo-Charged-By
X-Via
X-AH-Environment
X-Cache-Group
X-Age
X-Pass-Why
X-Backend
X-Ua-Compatible
X-Envoy-Upstream-Service-Time
EagleId
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Server
X-Page-Speed
X-Server-Powered-By
X-Pingback
X-UA-Device
X-Proxy-Cache
X-Swift-SaveTime
X-Swift-CacheTime
X-Hacker
X-Nginx-Cache-Status
Ali-Swift-Global-Savetime
Request-Context
Grace
X-Varnish-Cache
Server-Timing
Feature-Policy
Cf-Railgun
X-Amz-Version-Id
X-LiteSpeed-Cache
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Rq
X-WebKit-CSP
Report-To
X-Server-Id
EagleEye-TraceId
X-Ac
X-Response-Time
X-Host
X-OneAgent-JS-Injection
Request-Id
X-Cnection
X-Backend-Server
X-DataDome
X-Cdn
X-Node
Content-Location
X-Origin-Cache
X-Cloud-Trace-Context
X-Ws-Request-Id
X-Readtime
X-Cache-Lookup
NEL
X-Dns-Prefetch-Control
X-Vhost
X-Application-Context
X-Dispatcher
X-ORACLE-DMS-ECID
X-HW
X-ORACLE-DMS-RID
Allow
X-Clacks-Overhead
X-Rack-Cache
X-Origin-Upstream-Status
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Surrogate-Control
X-DynaTrace
Rating
X-Country
X-FTR-Request-ID
Fusion-Template-Id
Fusion-Source
Fusion-Component-Id
Fusion-Content-Source
Fusion-Content-Id
X-Country-Code
X-Akam-SW-Version
X-Goog-Hash
X-Instart-Request-ID
X-Varnish-TTL
X-Ruxit-JS-Agent
Pinterest-Generated-By
X-TtlSet
X-PC
X-Vname
Edge-Control
X-MS-InvokeApp
X-Mod-Pagespeed
X-B3-TraceId
X-Url
Verso
SPRequestGuid
X-Powered-By-Plesk
X-SharePointHealthScore
X-Trace
Response
Pagespeed
X-Middleton-Response
X-Sol
X-D2id
X-Middleton-Display
Display
Service-Worker-Allowed
X-VARITI-CCR
X-Server-Name
RTSS
X-Cdn-Fetch
X-Use-Magma
X-Kinja-Server
X-Kinja-Build
X-Exp-Id
X-GoogleNews-Bot
X-Kinja
X-Exp-Variant
X-Kinja-Revision
X-GitHub-Request-Id
Content-MD5
SPIisLatency
SPRequestDuration
Accept-Ch
X-ESI
X-TTL
X-Vcache
X-Powered-CMS
X-Abt-Application-Version
X-Navigation-Version
X-Debug
X-Amz-Server-Side-Encryption
Charset
X-Vcap-Request-Id
X-Upstream
MS-Author-Via
X-Cached
X-Forwarded-Proto
Public-Key-Pins
X-CST
X-Amz-Rid
X-Server-ID
DynaTrace
X-NF-Request-ID
X-Version
Edge-Cache-Tag
X-Px
Realpath
MicrosoftSharePointTeamServices
X-Shard
X-Aspnetmvc-Version
TCN
Accept-Ch-Lifetime
Arr-Disable-Session-Affinity
X-Ezoic-Cdn
X-DynaTrace-JS-Agent
X-MSEdge-Ref
X-Shield-Request-Id
Fastly-Restarts
Access-Control-Request-Method
X-XRDS-Location
X-Ser
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Pinterest-Rid
Pinterest-Version
S
X-Fastly-Request-ID
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Accel-Expires
X-Trafficlayer-App-Scope
X-Trafficlayer-App-Name
X-DIS-Request-ID
X-Recruiting
Front-End-Https
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Generation
X-Client-IP
X-Amz-Meta-S3cmd-Attrs
Nginx-Cache
X-Id
X-T
X-Varnish-Age
X-Goog-Storage-Class
X-Element-Page-Cache
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
X-FTR-Realm
X-FTR-DC
X-FTR-Balancer
X-FTR-Backend
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Backend-Server
X-Amzn-Trace-Id
Cache-Tag
X-FTR-Expires
X-Dw-Request-Base-Id
Fastcgi-Cache
X-Ttl
X-Webapp-Samesite-None-Activated-N
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Cache-Config
X-Frontend
NR-ENABLED
X-Content-Digest
X-Hits
X-Correlation-Id
Powered
X-Kinsta-Cache
X-Hp-Webp
X-RateLimit-Remaining
Alternate-Protocol
Accept-CH-Lifetime
X-FTR-Cache-Host
X-Fastcgi-Cache
Accept-CH
ServerID
X-Request-Processing-Time
X-Request-Received
X-Cache-Hit
Server-Name
X-Grace
X-Request-Handler-Origin-Region
X-Microsite
X-N
X-HS-Combine-CSS
X-Webkit-Csp
TP-L2-Cache
X-Content-Type
PB-RID
PB-PID
TP-Cache
X-Node-Name
X-Mobile-Rewrite
Arc-Version
AMP-Access-Control-Allow-Source-Origin
X-Rid
X-User-Agent
X-Zen-Fury
X-Revision
X-Analytics
Backend-Timing
Healthy
X-Akamai-Edgescape
X-Content-Security-Policy-Report-Only
Server-Node
X-FastCGI-Cache
X-Pad
X-Logged-In
X-Forwarded-For
X-LB-Cache
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Az
X-Activity-Id
X-AppVersion
Cache-Status
X-Mobile-URL
X-Varnish-Grace
X-Cached-By
X-SERVER
X-GUploader-UploadID
X-NWS-LOG-UUID
X-IPLB-Instance
AR-CACHE
AR-PoweredBy
AR-ATIME
X-Oneagent-Js-Injection
X-Type
Retry-After
X-B3-Sampled
X-Content-Options
Refresh
X-F-Cache
X-Geo-Country
Upgrade-Insecure-Requests
X-Litespeed-Cache
X-Ruxit-Js-Agent
X-Srv
Paypal-Debug-Id
X-App-Environment
X-Tumblr-User
X-Tumblr-Pixel
Ar-Sid
X-Tumblr-Pixel-0
X-Instance
Source
X-Debug-Info
X-Request-Guid
X-Varnish-Backend
Host
X-B
DC
X-Jobs
X-Framework
Access-Control-Allow-Method
X-Page-Id
X-PHP-Backend
Accept-Charset
X-AOL-HN
X-FB-Debug
FilterID
Actual-Object-TTL
X-Cluster
X-Cache-Age
X-Cache-Key
X-WebKit-CSP-Report-Only
X-Via-JSL
X-Seen-By
X-Cache-2
X-ATG-Version
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Esi
X-TT
Fastcgi-Useragent
Cache
X-Git-Hash
MS-CV
X-Content-Powered-By
X-Whom
X-Cache-TTL
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-PressLabs-Stats
AR-Request-ID
X-UA
X-Cache-Control
X-Amz-Replication-Status
X-B-Cache
X-Signature
X-Wix-Request-Id
Host-Header
X-Host-Name
Surrogate-Key
NGB
X-Response-Served-From
X-TA-CDN-Provider
X-Daa-Tunnel
X-Cache-Enabled
X-RequestSource
Frame-Options
X-FW-Static
WPE-Backend
X-FW-Server
X-Origin-Server
X-FW-Type
X-FW-Serve
X-FW-Hash
Cache-Tv-Group
X-Tumblr-Pixel-1
X-Tumblr-Pixel-2
X-GeoIP
X-Handled-By
X-TX-ID
Filters
X-EdgeConnect-Cache-Status
X-Cache-Action
X-Cache-Rule
Payment
Eomportal-Instance
X-Drupal-Cache-Tags
X-Cache-Operation
X-Region
X-Hyper-Cache
X-Mobile
X-Cacheable-TTL
X-Adobe-Content
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Adobe-Loc
X-Cache-NE
Webserver
Cleartype
From-Origin
Xserver
X-UA-Device-Type
X-Hostname
X-Load-Cache
X-Akamai-Transformed
Datacenter
X-Forwarded-Host
X-RemovedCookies
X-ProcessESI
X-NewRelic-App-Data
X-RTag
Ms-Operation-Id
X-Cache-TTL-Remaining
X-Edge-Location
X-Time
X-ATS-Timestamp
X-Cache-Server
Liferay-Portal
X-App-Server
X-Yottaa-Optimizations
X-Contextid
X-Yottaa-Metrics
X-Varnish-Hostname
X-Status
X-Varnish-Server
Tracecode
X-Rule
Country
X-TT-TIMESTAMP
Odigeo-Trace-Id
X-BCube-Filmed-By
X-Oss-Server-Time
X-URL
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
X-Oss-Object-Type
X-Path-Route
X-RN-RSRV
X-Upgrade-Enabled
X-Cache-Var-Map
Load-Balancing
Meta-Geo
X-ES-SERVER
X-Cache-Var
X-ORACLE-APMCS-REQUEST-ID
X-Xfnlog-Site
X-Debug-Cache
X-Viewer-Country
X-ORACLE-APMCS-TAG
X-UUID
Mn-Server-Ip
X-Origin-Hint
X-OCL
TWC-Connection-Speed
Webcakes-App-Name
TWC-Privacy
TWC-Locale-Group
Property-Id
Webcakes-App-Version
Webcakes-Region
DSUID
Cache-Tags
DB-Nickname
X-VCT
TWC-GeoIP-Country
TWC-GeoIP-LatLong
X-FW-Dynamic
Release
X-R9-Blue-Green-Version
X-PCL
TWC-Device-Class
X-CCM
Cache-Name
Azure-InstanceId
Azure-Version
Azure-SlotName
Fastly-SSL
Azure-SiteName
Azure-RegionName
X-Akamai-Request-ID
X-Origin
X-Origin-Response-Time
X-Drupal-Cache-Contexts
X-Labrador-Cache-Channel
X-IP
X-EIG-Tracking-Id
X-From
X-Human
X-Pubstack
X-Soup
X-Cache-Host
X-Akamai-Request-ID2
X-Rocket-Nginx-Bypass
X-Cache-Config
X-Web-Node
X-Varnish-Cache-Hits
X-Via-Fastly
NGX
S-Rt
Server-Info
X-NWS-UUID-VERIFY
X-Real-IP
X-ApacheServer
X-Proxy
X-TNCMS
Decoy-Debug-TTL
Ec-Rule-Version
S-Cnection
X-Proto
X-Loop
L5d-Success-Class
X-Rendered-As
X-Section
X-PERF
X-FC-Vary-Parameters
Decoy-Debug-Status
X-Hosted-By
X-Format
X-Cache-Time
X-Access
X-Redis-Cache
Decoy-Debug-Key
X-Content-Age
Origin-Edge-Control
X-Time-Microsecs
X-Is-Bot
Origin-Cache-Control
X-ServerID
X-FireWall-Port
Version
X-Timing-Wait
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Vgn-Hpd-Reason
X-Varnish-Hits
X-Proxy-Build
Selected-Fe
X-Site-Version
X-Generated
X-Www-Served-By
X-Storage
X-XRDS-LOCATION
X-Cluster-Name
X-Backend-Name
X-Locale
Uber-Trace-Id
X-Info
X-BYPASS-REASON
X-ProxyCache-Key
X-ProxyCache-Status
Viewport
X-JoinUs
X-RateLimit-Limit
X-VCache
X-Generated-By
X-Origin-CC
X-Origin-TTL
X-Accel-Buffering
X-B3-Traceid
X-PHP-Host
X-Cache-Backend
Rt-Fastcgi-Cache
X-Amzn-Remapped-Content-Length
Akamai-GRN
Time
Cteonnt-Length
Cache-Key
X-App-Version
X-WA-Info
X-Nginx-Cache-Key
X-Presslabs-Stats
GEO-INFO
Origin
X-GoCache-CacheStatus
X-No-Session
X-Tec-Api-Origin
X-MServer
X-Tec-Api-Version
X-L-Path
X-SS-Set-Cookie
X-CF-Powered-By
X-Tec-Api-Root
X-Geo
X-SaId
X-Cache-Remote
Vix-Hermes-Req-Id
X-Environment-Context
X-NCache
X-Guploader-Uploadid
Cache-Hits
X-Webkit-CSP
X-Backend-TTL
X-FB-TRIP-ID
X-Unique-Id
Accept-Language
X-Hit
X-Tb
Access-Control-Request-Headers
X-Trace-Id
X-APP-VERSION
Srv
X-CDN-Forward
X-Say-Cacheable
X-Say-TTL
X-SayCDN-TTL
X-Device-Type
X-Tumblr-Pixel-3
X-B3-SpanId
X-CS
X-OVcl
X-CSRF-TOKEN
X-OVcl-Cache
X-S
X-Cache-Grace
X-Cluster-Node
User-Cache-Control
ServedBy
X-EC-Lua
X-Alternate-Cache-Key
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Shopify-Stage
X-ShopId
X-ShardId
X-Shopify-Generated-Cart-Token
AsisCache
X-Server-Time
X-ScT
BehaviorPad-Version
X-Rojux
Content-Style-Type
Cross-Origin-Window-Policy
Content-Script-Type
Arc-Country
Xc-Version
X-S-Cookie
Apple-News-Services-Host
X-Svr
X-SRCache-Key
X-Transaction
X-Trv-Group
X-VG-WebCache
X-Twitter-Response-Tags
Fastcgi-X-Cache-Version
Apple-News-Services-Handled
X-Session-Fingerprint
Apple-News-Services-Parsed-Url
X-Vtex-Remote-Cache
X-SIPLIST1
X-VG-WebServer
X-Vtex-Processado-Em
Apple-News-Services-Request-Url
X-Request-UUID
Request-Country
Request-EU
X-AIR-PT
X-Application
X-ARC
X-CF-Lambda-Fn
X-B-Cookie
Rendered-Blocks
Rt-Proxy-Cache
T-Server
X-A-Dgt
X-A-Dcw
X-A-Ccd
X-A
X-A-Wwc
Viewtype
X-Aed
VivaBuild
X-CF-Lambda-Version
X-Connection-Hash
X-Region-Sid
Mobile-Detection-Method
X-Processor
X-A-Dam
Meta-Geo-Continent
Machine
MD5-Digest
X-Rewrite-Enabled
X-PAYTM-SRV-ID
X-Hl-Ver
X-Destination
X-Date
X-D
X-Detected-As
X-DPWN-IS-SECURE
Node
X-G
X-External-Request-Id
IsBot
X-Accel-Expires-Debug
X-CACHE-KEY
X-Parent-Response-Time
NtCoent-Length
X-Uri
ServerName
OT-Force-Account-Verify
Web-Mar-Node
Thinkindot-Control
X-Vdms-Version
Wxu-Next-Commit
Wxu-Next-Hostname
X-Service
X-Thinkindot-L3
Wxu-Next-Region
Thinkindot-CacheControl
X-Instart-Isnd
X-WADP-Cache
X-Webstats-RespID
X-Ah-Environment
RNT-Machine
RNT-Time
Server-Int
Server-Host
Served-By
X-Request-URI
X-Block-Status
X-Matched-Rule
X-Endurance-Cache-Level
X-Dispatcher-Server
X-Location
X-Level-Front-Cache
X-Hnp-Log
X-Generated-On
X-Gen-Mode
X-Dispatch
X-CUA
X-Reboot
X-Cache-Info
X-Cache-Bucket
X-RateLimit-Remaining-Second
X-Clara-WADP
X-RateLimit-Limit-Second
X-Cms-Context
Mime-Version
Thinkindot-CacheControl-Type
We-Hiring
Mail-Subject
Proxy-Connection
CDCHOST
Cache-Host
X-Via-CDN
X-RCS-CacheZone
X-Dc
X-FW-Version
X-IN-APIGATEWAYSSL
W
X-Core-Value
X-Up
X-User
X-Qloud-Router
Adler-Geo
X-Developers
X-Varnish-Beresp-Status
X-Hash
X-C
X-Proxy-Cache-Status
X-VG-TLSProxy
X-Swa-Ws
True-Client-Country-4JS
X-IN-APIGATEWAY
X-Variation
X-Varnish-Beresp-Ttl
X-Azure-Ref
X-Cache-Id
X-Server-IP
X-Azure-Ref-OriginShield
X-S-Maxage
X-BBXSRF
X-Backend-State
X-NC
X-App-Name
X-NX-Host
X-Debug-Log
Content-Disposition
X-Compress-Hint
X-Skip-Cache
X-Cdn-Srv
X-Reqid
X-Cache-URL
X-Release
Section-Io-Cache
X-VServer
X-JWT-State
X-Has-Esi
Memcached
X-Fastly-Cache
Is-Eu
X-Is-Gdpr
Magicmarker
Now
Heartbleed
IBM-Web2-Location
X-Varnish-Beresp-Grace
Kp-EeAlive
X-Generation-Time
X-Cache-Debug
X-Source
X-Ms-Request-Id
Pramga
X-Ms-Version
X-We-Are-Hiring
X-Proxy-Upstream
Esi-Enabled
Platform
Fastly-Soc-X-Request-Id
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-Debug-Cookies
Cache-Provider
X-SRV
X-Magnolia-Registration
X-B3-Parentspanid
X-Origin-Expires
X-Sigma-Backend
X-Cache-FS-Status
X-TrackingId
X-Geo-Header
X-Planisys-CDN-Cache
X-Rocket-Build-Number
X-Epic-Correlation-Id
X-Platform-Server
X-Method
X-Policy
X-Distributor
X-MSEdge-Flight
X-MSEdge-Features
X-Logging-Id
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Internal-Host
X-Li-Fabric
X-Li-Pop
X-Old-Content-Length
X-LI-UUID
X-Sigma
X-SVT-ORM-RULES
X-Eu-Site
X-Distil-CS
X-WebServer
Cdncip
X-Generated-In
SD-X-WS
X-Upstream-Ht
X-Upstream-Ct
X-Origin-Date
Countrycode
Gh-Request-Id
X-CGP
L
X-Auto-Login
X-Clientip
Locale
X-Core-Mission
Ha-Gx-Prefs
HA-Ipaddr
X-Debug-Cache-Expiry
X-VC-Cache
X-ServiceProvider
X-Agile-Id
X-Agile-Age
X-Agile
X-AK-Request-ID
X-Amz-Meta-Cache-Control
Cdnsip
X-Scheme
X-SD-PageType
X-Sucuri-Cache
X-SVT-ORM-VERSION
AKAMAI
X-Debug-Cache-Fetch
X-Irp-Debug
X-Debug-Cache-Store
X-Urbn-Site-Id
X-Key
X-Urbn-Context-Path
Hostname
X-UnsetCookies
X-Nc
X-Thanos
X-GeoIP-City
X-Via-NSCOPI
X-ND-Cache
Powered-By-ChinaCache
X-Owner
X-Request-Start
PFcat
X-LI-Proto
X-Bip
X-NodeID
V-Age
X-B3-Spanid
Server-ID
X-Servername
X-7Graus-Varnish-Cache-Control
CF-IPCountry
X-7Graus-Varnish-XKeys
X-TIME
GEO-REGION-INFO
X-COUNTRY
Environment
X-GRACE
X-Cdn-Forward
X-Developer
Locid
X-Sucuri-Id
X-Req
X-FPC
X-Be
A
X-Trafficlayer-App-Version
X-Newrelic-Synthetics
X-Nginx-Cache
X-Servedbyhost
Geo-Info
X-Cdn-Origin
X-Sn-Servicetimems
X-Device-Os
X-Lb-Id
FNAC-ModuleRouting
X-Zone
X-HTML-Minification-Powered-By
X-Refresh
X-Gamma-Serve
X-Served-From
X-Microcachable
X-Node-Id
X-VHOST
Tcn
X-FORWARDED-FOR
ProcessTime
X-Sucuri-ID
Memory
X-Render-Time
X-Tb-Optimization-Total-Bytes-Saved
X-IPS-LoggedIn
X-VWS-Id
X-AWS-Id
X-NU-AKA-ACS-Version
X-LJ-Flow-ID
Request-Time
X-VCL-Version
XServer
X-GeoIP-Country-Code
X-DC
X-Pjax-Url
Resin-Trace
X-Pf-Uncompressing
X-MP-GENERATED-AT
X-Mode
Gannett-Cam-Experience-Id
CF-Cached-On
X-Edge-O15-RID
X-Correlation-ID
GeoIp-Country-Code
PICS-Label
Group
Geoip-Latitude
Geoip-City
X-Instart-Info
MIME-Version
Amp-Access-Control-Allow-Source-Origin
X-Ratelimit-Remaining
X-ECACHE
X-ElasticPress-Search
GeoIP-Latitude
X-Pod
TTL
X-Backend-Url
GeoIP-Country-Code
Cf-Ipcountry
Ttl
Pics-Label
X-Var-Ttl
X-Backend-Host
X-Bc
X-NGENIX-Cache
X-Zipkin-Id
X-Routing-Service
X-Proxied
Cdn
X-CSRF-Token
X-Via-Edge
X-Via-SSL
GeoIP-City
X-APP
Backend-Name
X-Unique-ID
X-ZONE
Cache-Cookie-Set-Idcheck
HostName
Cache-Cookie-Set-Lfrom
M-TraceId
Pagetype
N-Cache
REQUESTUUID
Host-ID
Cache-Cookie-Set-From
Lfy
Ohc-Cache-HIT
Ohc-File-Size
X-CLOUD-TRACE-CONTEXT
X-Check-Cacheable
X-Vcl-Version
Fly-Cache
Cache-Prefix
Fly-Request-Id
X-Fstrz
X-Via-Ucdn
X-Cdn-Request-ID
X-GEO
HitType
X-Worker
X-PJAX-URL
X-PF-Uncompressing
X-BC
X-Request-Time
X-Swift-Error
X-Ratelimit-Limit
X-Fastly-Country-Code
X-Sedo-Request-Id
X-Cache-Miss-From
X-TH-Server
X-NGINX-Cache
X-Dynatrace-Js-Agent
URI
On-Server
User-Agent
X-Aicache-OS
X-HS-Status
X-Server-W
Pragrma
X-Tt-Trace-Tag
X-Fetched-On
X-UPSTREAM-Address
X-LiteSpeed-Cache-Control
X-Upstream-CT
X-Upstream-HT
X-HostName
Powered-By
X-ServedByHost
CDN
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Cache-Tag
Fastly-SIE
Fastly-SWR
X-WR-MODIFICATION
X-Wa
SRV
X-WA
X-BE
Media-Length
Who
AR-SID
X-TT-LOGID
X-Fpc
X-LB-ID
X-Varnish-URL
X-Fastly-Backend-Reqs
X-LAGOON
X-Varnish-Cacheable
X-GDPR
X-Tt-Trace-Host
FSS-Cache
FSS-Proxy
X-Cf-Powered-By
DataCenter
Cdn-Request-Time
Debug
Cdn-Host
Server-Id
X-Hp-Ccpa-Warning
UCS
X-ServerName
CACHE
X-Edge-Server
Filterid
X-Ftr-Cache-Host
X-RateLimit-Reset
X-Ua
X-Protected-By
WP-Super-Cache
Get-Access-Time
X-Flog
Is-Session-Tracking
X-Cache-Tags
X-ABtesting
X-Store
SS
X-Gen-Id
X-Akamai-ERRuleID
X-Hello
X-Akamai-ERPolicy
X-Varnish-Beresp-TTL
X-SN
LB
Processtime
Country-Code
NnCoection
Cneonction
XxX-Cache-Status
X-SB
X-Nananana
X-VC
Xet-Cookie
X-DB
X-DI
X-DSS
X-DW
X-LiteSpeed-Tag
X-Action
Warning
X-Org
X-Response-By
SN
Requestid
X-RPM
X-RPS
SID
X-Fastly-Cache-Hits
Application
Product
X-Li-Proto
Thinkindot-Cache-Type
X-RSL
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
X-Dw-Trace-Id
X-Request-Url