Threat Level: green Handler on Duty: Renato Marinho

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
CF-RAY
CF-Cache-Status
Pragma
Link
X-Powered-By
ETag
Expect-CT
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Xss-Protection
X-Varnish
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
Alt-Svc
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-FRAME-OPTIONS
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Request-ID
Content-Security-Policy-Report-Only
X-Generator
X-Cache-Status
X-Cacheable
X-Permitted-Cross-Domain-Policies
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Template
X-Iinfo
X-Language
X-AspNetMvc-Version
X-Content-Security-Policy
Status
Content-Encoding
X-Buckets
Access-Control-Expose-Headers
Upgrade
X-CDN
Xkey
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Drupal-Dynamic-Cache
X-Turbo-Charged-By
X-Via
X-Cache-Group
X-Age
X-AH-Environment
X-Pass-Why
X-Backend
X-Envoy-Upstream-Service-Time
X-Ua-Compatible
EagleId
X-Server
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Page-Speed
X-Pingback
X-Server-Powered-By
X-UA-Device
X-Swift-CacheTime
X-Swift-SaveTime
X-Proxy-Cache
X-Hacker
Ali-Swift-Global-Savetime
X-Nginx-Cache-Status
Request-Context
Grace
X-Varnish-Cache
Server-Timing
Feature-Policy
Cf-Railgun
X-Amz-Version-Id
X-Device
X-LiteSpeed-Cache
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-WebKit-CSP
X-Rq
Report-To
EagleEye-TraceId
X-Ac
X-Server-Id
X-OneAgent-JS-Injection
X-Response-Time
X-Host
Request-Id
X-Cnection
X-Backend-Server
X-DataDome
Content-Location
X-Node
X-Cloud-Trace-Context
X-Origin-Cache
X-Readtime
X-Cache-Lookup
NEL
X-Cdn
X-Vhost
X-Ws-Request-Id
X-Application-Context
X-Dispatcher
X-ORACLE-DMS-ECID
X-HW
X-ORACLE-DMS-RID
Allow
X-Clacks-Overhead
X-Rack-Cache
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Dns-Prefetch-Control
X-Origin-Upstream-Status
Surrogate-Control
X-DynaTrace
Rating
X-Country
X-FTR-Request-ID
Fusion-Content-Id
X-Country-Code
Fusion-Template-Id
Fusion-Component-Id
Fusion-Content-Source
Fusion-Source
X-Goog-Hash
X-Akam-SW-Version
X-Varnish-TTL
Pinterest-Generated-By
X-TtlSet
X-Vname
X-PC
X-Instart-Request-ID
X-MS-InvokeApp
Edge-Control
X-Ruxit-JS-Agent
X-Url
X-B3-TraceId
X-Mod-Pagespeed
Verso
X-Powered-By-Plesk
SPRequestGuid
X-D2id
Accept-Ch
X-Trace
Pagespeed
X-Middleton-Response
Response
X-Sol
Display
X-Middleton-Display
X-SharePointHealthScore
X-VARITI-CCR
RTSS
Service-Worker-Allowed
X-Server-Name
X-Kinja-Revision
X-Cdn-Fetch
X-GitHub-Request-Id
X-Exp-Id
X-Exp-Variant
X-Use-Magma
X-Kinja-Build
X-Kinja
X-Kinja-Server
X-GoogleNews-Bot
SPRequestDuration
X-Server-ID
SPIisLatency
X-Navigation-Version
Content-MD5
X-ESI
X-TTL
X-Powered-CMS
X-Debug
X-Abt-Application-Version
X-Vcache
X-Vcap-Request-Id
X-Amz-Server-Side-Encryption
Public-Key-Pins
X-CST
Charset
Accept-Ch-Lifetime
MS-Author-Via
X-Forwarded-Proto
X-Upstream
X-Cached
X-NF-Request-ID
X-Amz-Rid
X-Px
X-Version
DynaTrace
Realpath
Edge-Cache-Tag
X-Shard
TCN
MicrosoftSharePointTeamServices
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
Arr-Disable-Session-Affinity
Fastly-Restarts
X-Ezoic-Cdn
X-XRDS-Location
X-MSEdge-Ref
Access-Control-Request-Method
X-Shield-Request-Id
X-Pinterest-Rid
X-DynaTrace-JS-Agent
X-Ser
Pinterest-Version
X-Recruiting
X-SRCache-Store-Status
X-SRCache-Fetch-Status
S
X-Fastly-Request-ID
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Accel-Expires
X-DIS-Request-ID
Front-End-Https
Nginx-Cache
X-Trafficlayer-App-Scope
X-Trafficlayer-App-Name
X-Amz-Meta-S3cmd-Attrs
X-Client-IP
X-Goog-Storage-Class
X-Id
X-Element-Page-Cache
X-Varnish-Age
X-T
MRF-Tech
Mrf-Cache-Status
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
X-B3-TraceId-Primal
X-FTR-Cache-Status
X-FTR-DC
X-Country-Code-Real
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Realm
X-FTR-Balancer
X-FTR-Expires
X-Amzn-Trace-Id
X-Dw-Request-Base-Id
Cache-Tag
Fastcgi-Cache
X-Ttl
X-HS-Content-Id
X-HS-Hub-Id
X-Content-Digest
X-Frontend
NR-ENABLED
X-HS-Cache-Config
X-Hits
Powered
X-RateLimit-Remaining
X-Fastcgi-Cache
X-Webapp-Samesite-None-Activated-N
X-Kinsta-Cache
X-Correlation-Id
ServerID
X-Litespeed-Cache
Alternate-Protocol
X-Hp-Webp
X-Grace
X-FTR-Cache-Host
X-N
TP-Cache
TP-L2-Cache
X-Cache-Hit
X-Request-Processing-Time
X-Request-Received
X-Node-Name
X-Aspnetmvc-Version
X-Request-Handler-Origin-Region
X-Microsite
PB-PID
X-Webkit-Csp
PB-RID
X-Mobile-Rewrite
Server-Name
Arc-Version
AMP-Access-Control-Allow-Source-Origin
X-User-Agent
X-Zen-Fury
X-Rid
Healthy
X-Content-Type
X-Analytics
X-HS-Combine-CSS
Backend-Timing
X-Revision
Accept-CH
Server-Node
AR-CACHE
AR-ATIME
X-Akamai-Edgescape
AR-PoweredBy
X-Content-Security-Policy-Report-Only
X-Ruxit-Js-Agent
Accept-CH-Lifetime
X-Logged-In
X-LB-Cache
X-Forwarded-For
Ar-Sid
X-Az
X-AppVersion
X-Activity-Id
Cache-Status
X-Amz-Apigw-Id
X-Pad
X-Amzn-RequestId
X-FastCGI-Cache
X-IPLB-Instance
X-NWS-LOG-UUID
X-Cached-By
Retry-After
X-Varnish-Grace
X-Type
X-Mobile-URL
X-Oneagent-Js-Injection
X-GUploader-UploadID
X-B3-Sampled
Paypal-Debug-Id
X-Srv
Refresh
X-Content-Options
X-Via-JSL
X-F-Cache
FilterID
Upgrade-Insecure-Requests
X-Instance
Accept-Charset
X-Tumblr-Pixel
X-Tumblr-User
X-Cache-Age
X-Tumblr-Pixel-0
X-FB-Debug
X-Debug-Info
X-App-Environment
X-AOL-HN
X-Jobs
X-Request-Guid
X-Cluster
Host
X-Varnish-Backend
X-Page-Id
Access-Control-Allow-Method
Source
X-Geo-Country
X-PHP-Backend
X-B
Actual-Object-TTL
X-Erf-Bev-Bev
DC
X-Erf-Bev-Bev-Is-Generated
X-Framework
X-WebKit-CSP-Report-Only
X-Seen-By
AR-Request-ID
X-ATG-Version
X-Esi
X-PressLabs-Stats
MS-CV
X-Content-Powered-By
X-Cache-Key
VIX-Pulpo-Node
Fastcgi-Useragent
VIX-Pulpo-Upstream-Status
X-TT
X-Whom
X-Git-Hash
X-Cache-2
X-Cache-TTL
Cache
X-Cache-Control
X-Amz-Replication-Status
X-Host-Name
X-TA-CDN-Provider
X-Wix-Request-Id
X-B-Cache
X-UA
X-Signature
Surrogate-Key
Host-Header
X-Response-Served-From
Frame-Options
NGB
X-Cache-Rule
X-FW-Type
X-FW-Static
X-FW-Hash
X-FW-Server
X-FW-Serve
X-Cache-Operation
X-Origin-Server
X-Daa-Tunnel
X-Kong-Proxy-Latency
Cache-Tv-Group
X-Kong-Upstream-Latency
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
X-RequestSource
X-TX-ID
WPE-Backend
X-Region
X-Drupal-Cache-Tags
X-Cache-Action
X-Hyper-Cache
X-Cache-NE
Webserver
Payment
Cleartype
X-GeoIP
X-Handled-By
X-Cache-Enabled
Eomportal-Instance
X-Adobe-Loc
X-Adobe-Content
Xserver
X-Cacheable-TTL
X-Mobile
X-Time
Filters
X-Forwarded-Host
X-Ah-Environment
X-EdgeConnect-Cache-Status
From-Origin
X-UA-Device-Type
X-RemovedCookies
X-ProcessESI
X-SERVER
Datacenter
X-Load-Cache
X-Hostname
X-Akamai-Transformed
X-RTag
X-Cache-TTL-Remaining
X-NewRelic-App-Data
Ms-Operation-Id
X-App-Server
Tracecode
X-Cache-Server
X-Edge-Location
X-Status
Liferay-Portal
X-Contextid
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Varnish-Hostname
X-BCube-Filmed-By
X-VCache
X-Varnish-Server
X-TT-TIMESTAMP
X-ATS-Timestamp
X-Rule
Odigeo-Trace-Id
Country
X-Cache-Var
Meta-Geo
X-Cache-Var-Map
X-Path-Route
X-ES-SERVER
X-FW-Dynamic
X-RN-RSRV
Load-Balancing
X-RateLimit-Limit
X-Upgrade-Enabled
Server-Info
X-Viewer-Country
X-Xfnlog-Site
X-Via-Fastly
X-OCL
X-CCM
X-Rocket-Nginx-Bypass
X-Cache-Config
Cache-Tags
DB-Nickname
X-PCL
Version
X-Debug-Cache
Azure-SlotName
Azure-SiteName
Azure-Version
X-Origin-Hint
Webcakes-App-Version
L5d-Success-Class
Fastly-SSL
Azure-RegionName
Azure-InstanceId
X-TNCMS
TWC-GeoIP-LatLong
X-UUID
TWC-Locale-Group
X-Pubstack
X-ServerID
TWC-Privacy
X-EIG-Tracking-Id
X-Real-IP
X-Origin-Response-Time
X-From
X-FC-Vary-Parameters
X-Origin
X-Hosted-By
X-Labrador-Cache-Channel
X-IP
X-Cache-Host
X-Drupal-Cache-Contexts
X-Proxy
S-Rt
X-Akamai-Request-ID
X-Proto
X-Cache-Time
Webcakes-Region
TWC-GeoIP-Country
Webcakes-App-Name
Mn-Server-Ip
X-R9-Blue-Green-Version
TWC-Device-Class
X-Loop
TWC-Connection-Speed
Property-Id
X-Redis-Cache
X-Varnish-Cache-Hits
X-Web-Node
Viewport
X-Access
X-ApacheServer
X-VCT
X-Backend-Name
X-Rendered-As
Decoy-Debug-TTL
Ec-Rule-Version
X-Human
X-PERF
X-Cluster-Name
X-Generated
X-Goog-Meta-Goog-Reserved-File-Mtime
Selected-Fe
X-JoinUs
X-Timing-Wait
X-Format
X-Content-Age
X-Akamai-Request-ID2
Release
X-FireWall-Port
Decoy-Debug-Status
S-Cnection
Cache-Name
X-Section
NGX
Origin-Cache-Control
Origin-Edge-Control
Decoy-Debug-Key
X-Proxy-Build
DSUID
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Time-Microsecs
X-Soup
X-Oss-Storage-Class
X-Vgn-Hpd-Reason
X-Oss-Server-Time
X-Www-Served-By
X-Info
X-Oss-Request-Id
X-Varnish-Hits
X-NWS-UUID-VERIFY
X-Origin-TTL
X-XRDS-LOCATION
X-Storage
X-Origin-CC
X-Site-Version
X-Is-Bot
X-Locale
X-ProxyCache-Key
X-BYPASS-REASON
Uber-Trace-Id
X-ProxyCache-Status
X-ORACLE-APMCS-REQUEST-ID
X-ORACLE-APMCS-TAG
Rt-Fastcgi-Cache
X-B3-Traceid
X-Guploader-Uploadid
Cache-Key
X-URL
X-PHP-Host
X-WA-Info
X-Cache-Backend
X-App-Version
X-Generated-By
X-Amzn-Remapped-Content-Length
X-Accel-Buffering
Akamai-GRN
Time
Cteonnt-Length
Vix-Hermes-Req-Id
X-SS-Set-Cookie
X-GoCache-CacheStatus
X-Hit
Cache-Hits
X-Cache-Remote
X-NCache
X-CF-Powered-By
X-Backend-TTL
X-Nginx-Cache-Key
Origin
GEO-INFO
X-FB-TRIP-ID
Accept-Language
X-Cache-Grace
X-Device-Type
X-SaId
X-Environment-Context
X-L-Path
X-Trace-Id
X-CS
X-Tumblr-Pixel-3
X-APP-VERSION
X-No-Session
X-Presslabs-Stats
X-Tb
X-CACHE-KEY
X-MServer
X-B3-SpanId
Access-Control-Request-Headers
X-OVcl
X-OVcl-Cache
X-Say-Cacheable
X-Say-TTL
X-SayCDN-TTL
X-S
X-Cluster-Node
X-CSRF-TOKEN
X-Uri
Fastcgi-X-Cache-Version
User-Cache-Control
X-Geo
Srv
X-A
VivaBuild
Rendered-Blocks
Viewtype
T-Server
Request-EU
Rt-Proxy-Cache
Request-Country
Content-Script-Type
Arc-Country
AsisCache
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
Apple-News-Services-Host
BehaviorPad-Version
Content-Style-Type
Meta-Geo-Continent
Mobile-Detection-Method
MD5-Digest
Machine
Cross-Origin-Window-Policy
IsBot
Node
X-Application
X-ScT
X-Server-Time
X-Session-Fingerprint
X-SIPLIST1
X-S-Cookie
X-Rojux
X-Region-Sid
X-Request-UUID
X-Rewrite-Enabled
X-SRCache-Key
X-Svr
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-VG-WebServer
X-VG-WebCache
X-Transaction
X-Trv-Group
X-Twitter-Response-Tags
X-Processor
X-PAYTM-SRV-ID
X-Aed
X-AIR-PT
X-ARC
X-B-Cookie
X-Accel-Expires-Debug
X-A-Wwc
X-A-Dam
X-A-Dcw
X-A-Dgt
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-External-Request-Id
X-G
X-Hl-Ver
X-DPWN-IS-SECURE
X-Detected-As
X-Connection-Hash
X-D
X-Date
X-A-Ccd
X-Destination
X-Tec-Api-Version
X-Tec-Api-Root
Mime-Version
Now
X-CDN-Forward
X-Tec-Api-Origin
NtCoent-Length
X-Via-CDN
Hostname
OT-Force-Account-Verify
X-FW-Version
ServerName
X-Endurance-Cache-Level
X-Proxy-Cache-Status
X-Proxy-Upstream
X-NX-Host
X-Matched-Rule
X-Location
X-Hnp-Log
X-Unique-Id
Mail-Subject
We-Hiring
CDCHOST
X-Thinkindot-L3
X-S-Maxage
X-UnsetCookies
X-Request-URI
RNT-Time
X-Clara-WADP
X-Cms-Context
X-Core-Value
X-EC-Lua
X-Cache-Info
X-Block-Status
X-Cache-Bucket
X-Cache-Debug
X-Debug-Cookies
Web-Mar-Node
Server-Int
X-Gen-Mode
X-Service
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-Debug-Log
Thinkindot-Control
RNT-Machine
X-Reboot
X-Shopify-Stage
X-Sorting-Hat-PodId
X-ShopId
X-ShardId
Server-Host
ServedBy
X-Sorting-Hat-ShopId
X-Alternate-Cache-Key
X-WADP-Cache
X-B3-Parentspanid
X-Dc
X-Parent-Response-Time
X-Distributor
X-Epic-Correlation-Id
X-Distil-CS
X-Developers
X-Generated-On
X-Dispatcher-Server
X-Webstats-RespID
X-Dispatch
Wxu-Next-Region
X-Generated-In
X-Generation-Time
X-RateLimit-Remaining-Second
Wxu-Next-Commit
Wxu-Next-Hostname
X-Hash
X-Eu-Site
X-Fastly-Cache
X-CUA
X-Debug-Cache-Expiry
X-Ms-Version
X-CGP
X-Instart-Isnd
X-Level-Front-Cache
X-Cdn-Srv
X-Ms-Request-Id
X-Cache-FS-Status
X-Cache-URL
X-Clientip
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-Cache-Id
X-Debug-Cache-Fetch
X-Core-Mission
X-C
X-RateLimit-Limit-Second
X-Compress-Hint
X-Geo-Header
X-Debug-Cache-Store
X-Irp-Debug
X-Scheme
X-SD-PageType
X-Skip-Cache
X-We-Are-Hiring
X-Backend-State
X-Platform-Server
X-Policy
X-Request-Start
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-VG-TLSProxy
X-VServer
X-User
X-VC-Cache
X-Variation
X-TrackingId
X-Up
X-Origin-Expires
X-Origin-Date
X-Is-Gdpr
X-JWT-State
X-Key
X-Reqid
Cache-Host
X-GeoIP-City
Kp-EeAlive
X-Has-Esi
X-Li-Fabric
X-Li-Pop
X-Method
X-WebServer
X-Old-Content-Length
X-Wikidot-Backend
X-Magnolia-Registration
X-LI-UUID
X-Wikidot-Static-Cache
Served-By
X-Nc
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
Countrycode
Esi-Enabled
Fastly-Soc-X-Request-Id
Content-Disposition
X-Varnish-Beresp-Ttl
Adler-Geo
AKAMAI
X-7Graus-Varnish-Cache-Control
W
Gh-Request-Id
Ha-Gx-Prefs
Section-Io-Cache
Memcached
SD-X-WS
PFcat
Platform
Magicmarker
L
True-Client-Country-4JS
HA-Ipaddr
IBM-Web2-Location
Is-Eu
X-Shopify-Generated-Cart-Token
X-7Graus-Varnish-XKeys
X-Auto-Login
Proxy-Connection
X-App-Name
X-Amz-Meta-Cache-Control
X-Azure-Ref
X-Azure-Ref-OriginShield
X-NC
X-Sucuri-Cache
X-Sigma-Backend
Locale
X-Sigma
X-Swa-Ws
X-Thanos
X-Vdms-Version
X-LI-Proto
X-Server-IP
X-MSEdge-Features
X-MSEdge-Flight
X-Release
X-Agile-Id
X-BBXSRF
X-Urbn-Site-Id
X-Agile-Age
X-Internal-Host
Pramga
X-Agile
X-Urbn-Context-Path
Cdncip
X-Qloud-Router
Heartbleed
X-Owner
X-Logging-Id
Cdnsip
X-Bip
X-Rocket-Build-Number
X-ServiceProvider
X-AK-Request-ID
V-Age
X-Cdn-Forward
X-GRACE
Cache-Provider
X-Planisys-CDN-Rules
Server-ID
X-NodeID
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
X-RCS-CacheZone
A
X-Upstream-Ct
X-Upstream-Ht
Powered-By-ChinaCache
X-Servername
X-Via-NSCOPI
X-Developer
X-Source
X-B3-Spanid
X-COUNTRY
X-Sucuri-Id
X-SRV
X-Cdn-Origin
CF-IPCountry
X-Sn-Servicetimems
X-ND-Cache
GEO-REGION-INFO
X-Nginx-Cache
Environment
X-Be
X-Node-Id
X-Trafficlayer-App-Version
X-Device-Os
X-FPC
X-Servedbyhost
Geo-Info
X-Lb-Id
X-FORWARDED-FOR
X-Microcachable
X-Zone
X-Req
X-Newrelic-Synthetics
X-VHOST
Locid
Tcn
X-Served-From
X-Gamma-Serve
FNAC-ModuleRouting
X-Correlation-ID
X-Webkit-CSP
X-TIME
X-Tb-Optimization-Total-Bytes-Saved
X-Refresh
Resin-Trace
ProcessTime
Request-Time
X-Sucuri-ID
CF-Cached-On
X-Pjax-Url
Memory
X-HTML-Minification-Powered-By
X-IPS-LoggedIn
X-AWS-Id
X-VWS-Id
X-LJ-Flow-ID
X-VCL-Version
X-Instart-Info
X-ECACHE
X-Pf-Uncompressing
X-Render-Time
X-ElasticPress-Search
X-NGENIX-Cache
X-Unique-ID
X-Backend-Host
X-Edge-O15-RID
X-NU-AKA-ACS-Version
Gannett-Cam-Experience-Id
X-DC
Group
X-Backend-Url
Cf-Ipcountry
X-GEO
X-Var-Ttl
X-GeoIP-Country-Code
Amp-Access-Control-Allow-Source-Origin
Pics-Label
XServer
TTL
Backend-Name
X-Ratelimit-Remaining
X-Mode
Geoip-Latitude
N-Cache
GeoIP-City
GeoIp-Country-Code
Geoip-City
X-Pod
GeoIP-Country-Code
PICS-Label
GeoIP-Latitude
X-Bc
X-MP-GENERATED-AT
MIME-Version
REQUESTUUID
X-Via-Edge
Fly-Cache
X-CSRF-Token
Cache-Prefix
Cdn
X-Via-SSL
Ttl
X-Check-Cacheable
Lfy
Pagetype
Fly-Request-Id
X-APP
M-TraceId
X-Vcl-Version
X-ZONE
X-Worker
X-CLOUD-TRACE-CONTEXT
X-PF-Uncompressing
X-Fstrz
X-Cache-Miss-From
X-Sedo-Request-Id
Ohc-Cache-HIT
X-Via-Ucdn
Ohc-File-Size
HostName
Host-ID
SRV
X-Zipkin-Id
X-Routing-Service
X-Upstream-HT
X-Upstream-CT
X-Proxied
Cache-Cookie-Set-From
HitType
X-LiteSpeed-Cache-Control
Cache-Cookie-Set-Lfrom
X-Server-W
Cache-Cookie-Set-Idcheck
X-Fetched-On
X-Swift-Error
X-Ratelimit-Limit
X-BC
X-Wa
X-Fastly-Country-Code
X-PJAX-URL
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
Fastly-SIE
X-Cdn-Request-ID
Fastly-SWR
X-HS-Status
X-Dynatrace-Js-Agent
Pragrma
On-Server
X-Tt-Trace-Tag
User-Agent
X-TH-Server
URI
X-Oracle-Dms-Rid
X-Cache-Tag
X-HostName
X-Dynatrace
Powered-By
X-WR-MODIFICATION
X-ServedByHost
X-Aicache-OS
X-UPSTREAM-Address
X-NGINX-Cache
X-Request-Time
X-WA
Who
CDN
X-GDPR
X-TT-LOGID
X-Ftr-Cache-Host
X-RateLimit-Reset
CACHE
X-Fastly-Backend-Reqs
Cdn-Request-Time
X-Fpc
X-BE
Media-Length
Cdn-Host
X-Edge-Server
X-LB-ID
Dynatrace
X-Ua
X-Varnish-URL
X-Flog
X-LAGOON
X-ABtesting
X-Varnish-Cacheable
X-SN
X-Hello
DataCenter
X-Cf-Powered-By
X-DW
X-DSS
X-ServerName
Debug
X-DB
SN
X-DI
X-Response-By
X-Org
LB
FSS-Cache
SS
Server-Id
FSS-Proxy
Get-Access-Time
Is-Session-Tracking
X-RPS
X-RPM
X-Action
X-RSL
X-Cache-Ttl
AR-SID
X-Gen-Id
X-Tt-Trace-Host
X-Varnish-Beresp-TTL
X-Protected-By
X-Upstream-Proxy
Xet-Cookie
X-VC
X-Nananana
XxX-Cache-Status
Cneonction
UCS
X-SB
X-Fastly-Cache-Hits
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
RequestId
X-Akamai-ERRuleID
X-Akamai-ERPolicy
Warning
Requestid
X-Dw-Trace-Id
Thinkindot-Cache-Type
Product
X-Request-Url
Application
X-LiteSpeed-Tag
X-Li-Proto
SID
NnCoection