Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Link
X-Powered-By
CF-Cache-Status
Pragma
ETag
CF-RAY
Expect-CT
Via
X-XSS-Protection
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-Xss-Protection
Referrer-Policy
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-UA-Compatible
X-Served-By
Alt-Svc
X-Request-Id
X-Varnish
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Check
Content-Security-Policy-Report-Only
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
X-Generator
X-Cache-Status
CF-Ray
X-Cacheable
X-DNS-Prefetch-Control
X-Kinja-Server-Push
Timing-Allow-Origin
X-Template
X-Language
X-FRAME-OPTIONS
X-AspNetMvc-Version
X-Ua-Compatible
X-Iinfo
Status
X-Buckets
X-Content-Security-Policy
X-CDN
Content-Encoding
Upgrade
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Envoy-Upstream-Service-Time
Keep-Alive
X-Via
X-Drupal-Dynamic-Cache
X-Ws-Request-Id
X-Server
X-Turbo-Charged-By
X-AH-Environment
X-Backend
P3p
X-Age
X-Cache-Group
X-Robots-Tag
Xkey
Feature-Policy
X-Proxy-Cache
X-Request-ID
Request-Context
X-Amz-Request-Id
X-Amz-Id-2
X-Hacker
X-Page-Speed
EagleId
X-UA-Device
X-Server-Powered-By
X-Nginx-Cache-Status
X-Pingback
Grace
X-Varnish-Cache
Server-Timing
X-LiteSpeed-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Report-To
Ali-Swift-Global-Savetime
X-Amz-Version-Id
X-WebKit-CSP
Cf-Railgun
X-Server-Id
X-Rq
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Origin-Cache
X-OneAgent-JS-Injection
X-Dns-Prefetch-Control
EagleEye-TraceId
X-Host
X-Device
Surrogate-Control
X-Response-Time
X-Vhost
X-Backend-Server
X-Cache-Lookup
X-Ac
X-Node
X-Origin-Upstream-Status
X-Readtime
X-Dispatcher
X-HW
Fusion-Content-Source
Fusion-Source
Fusion-Content-Id
Fusion-Component-Id
Fusion-Template-Id
Request-Id
X-DataDome
Content-Location
X-Pass-Why
X-Mod-Pagespeed
X-Application-Context
NEL
X-ORACLE-DMS-ECID
X-Akam-SW-Version
X-ORACLE-DMS-RID
Fusion-Deployment-Id
X-Country
X-Ruxit-JS-Agent
Allow
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Rating
X-Country-Code
Edge-Control
X-Clacks-Overhead
X-Cloud-Trace-Context
X-Cnection
X-Url
X-Px
X-Rack-Cache
X-FTR-Request-ID
RTSS
X-Goog-Hash
X-TtlSet
MS-Author-Via
X-Vname
X-PC
X-Powered-By-Plesk
Accept-CH
Verso
X-Ttl
X-DynaTrace
Public-Key-Pins
Service-Worker-Allowed
X-GitHub-Request-Id
X-Kinja
X-GoogleNews-Bot
X-Kinja-Build
X-Kinja-Revision
X-Use-Magma
X-Kinja-Server
X-Exp-Id
X-Exp-Variant
X-Cdn-Fetch
Accept-CH-Lifetime
X-B3-TraceId
X-MS-InvokeApp
X-Middleton-Response
X-Middleton-Display
Response
Display
X-Amz-Server-Side-Encryption
Pagespeed
X-Sol
Arr-Disable-Session-Affinity
X-Varnish-TTL
X-Forwarded-Proto
X-Cache-TTL
X-D2id
Pinterest-Generated-By
X-Amz-Rid
X-CST
TCN
X-Abt-Application-Version
X-Cached
X-Vcap-Request-Id
X-NF-Request-ID
Accept-Ch
X-VARITI-CCR
X-Content-Type
X-Navigation-Version
Cache-Tag
X-Server-Name
X-Instart-Request-ID
X-ESI
X-Fastly-Request-ID
X-Accel-Expires
X-Version
Accept-Ch-Lifetime
AR-ATIME
AR-PoweredBy
AR-Request-ID
X-MSEdge-Ref
Access-Control-Request-Method
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Grace
Nginx-Cache
AR-CACHE
Ar-Sid
X-Debug
X-Upstream
Charset
X-Powered-CMS
S
SPRequestDuration
SPIisLatency
X-FastCGI-Cache
X-Client-IP
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-SharePointHealthScore
SPRequestGuid
X-DynaTrace-JS-Agent
X-Ezoic-Cdn
Realpath
Content-MD5
X-Pinterest-Rid
Pinterest-Version
X-Trace
X-Mrf-Item-Lastmod
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-Mrf-Section-Lastmod
X-Element-Page-Cache
X-Dw-Request-Base-Id
X-Hp-Webp
X-Jurisdiction
Nel
X-Id
X-Shield-Request-Id
X-Recruiting
X-Amz-Meta-S3cmd-Attrs
X-Node-Name
X-T
Fastcgi-Cache
X-XRDS-Location
X-Content-Digest
X-Kinsta-Cache
X-Logged-In
X-NWS-LOG-UUID
X-ASPNET-VERSION
X-Mobile-URL
X-Frontend
X-Request-Received
X-Request-Processing-Time
X-Cache-Hit
Server-Node
X-Oneagent-Js-Injection
X-FTR-Backend
X-FTR-Cache-Status
X-Country-Code-Real
X-FTR-Realm
X-FTR-Balancer
X-FTR-DC
X-FTR-Backend-Server
Edge-Cache-Tag
X-Cache-Age
X-FTR-Expires
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Metageneration
Front-End-Https
TP-Cache
TP-L2-Cache
Server-Name
ServerID
X-Forwarded-For
X-Cache-Key
X-Amzn-Trace-Id
X-Hostname
DynaTrace
Arc-Version
PB-RID
PB-PID
Fastly-Restarts
X-Zen-Fury
X-Server-ID
Powered
X-DIS-Request-ID
X-Microsite
X-Request-Handler-Origin-Region
Backend-Timing
X-ATS-Timestamp
X-Content-Security-Policy-Report-Only
X-Revision
X-User-Agent
X-Mobile-Rewrite
X-Akamai-Edgescape
X-Page-Id
X-LB-Cache
X-Hits
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Content-Id
X-F-Cache
X-HS-Hub-Id
Accept-Charset
X-Jobs
Filters
X-Cdn
X-ORACLE-APMCS-TAG
X-ORACLE-APMCS-REQUEST-ID
X-Content-Powered-By
AMP-Access-Control-Allow-Source-Origin
X-Yandex-Sdch-Disable
X-FTR-Cache-Host
X-Geo-Country
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Via-JSL
X-Origin-Server
MicrosoftSharePointTeamServices
X-Varnish-Age
X-B
X-N
Alternate-Protocol
X-Rid
X-TTL
X-Ser
X-Daa-Tunnel
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Varnish-Backend
Host-Header
X-Ruxit-Js-Agent
X-Fastcgi-Cache
X-Activity-Id
X-Az
X-WebKit-CSP-Report-Only
X-AppVersion
X-ATG-Version
DC
Paypal-Debug-Id
X-Esi
X-Correlation-Id
X-Amz-Replication-Status
X-FB-Debug
Cache-Tags
X-Git-Hash
X-Type
Retry-After
X-Varnish-Grace
X-Whom
X-TT
X-App-Environment
X-Debug-Info
Actual-Object-TTL
X-B-Cache
Section-Io-Cache
X-Signature
X-App-Server
Frame-Options
X-Contextid
X-Edge
X-Request-Guid
Surrogate-Key
Fastcgi-Useragent
X-Content-Options
X-Status
Host
X-AOL-HN
Healthy
X-Seen-By
X-Cache-Action
X-Pinterest-Direct
Source
Refresh
X-XRDS-LOCATION
X-Host-Name
X-HTML-Minification-Powered-By
X-IPLB-Instance
X-B3-Sampled
X-Endurance-Cache-Level
X-Tumblr-User
X-RateLimit-Remaining
X-Tumblr-Pixel
X-Instance
X-Tumblr-Pixel-0
From-Origin
X-Upgrade-Enabled
Access-Control-Allow-Method
X-ECACHE
X-Accel-Buffering
X-Cache-Rule
X-Response-Served-From
X-RemovedCookies
X-ProcessESI
X-Amz-Apigw-Id
X-Cache-Operation
X-Drupal-Cache-Tags
X-Rule
X-MCACHE
Odigeo-Trace-Id
X-Mid
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Region
X-Amzn-RequestId
MS-CV
Payment
X-UUID
X-Cache-Time
X-FW-Hash
X-FW-Dynamic
X-FW-Server
X-FW-Serve
X-FW-Static
X-Environment-Context
X-FW-Type
X-Varnish-Server
X-Cache-Control
X-Is-Bot
Eomportal-Instance
X-L-Path
X-Rendered-As
X-Cacheable-TTL
Cache-Status
WPE-Backend
X-WA-Info
NR-ENABLED
Countrycode
Srv
X-Adobe-Loc
X-Adobe-Content
X-Protected-By
X-APP-VERSION
Datacenter
X-URL
Xserver
X-GeoIP
X-VCache
X-Correlation-ID
Content-Disposition
X-PressLabs-Stats
X-Akamai-Transformed
X-Cluster
NGB
X-Wix-Request-Id
X-EdgeConnect-Cache-Status
X-RequestSource
X-Cache-Server
X-SERVER-NAME
X-Cached-By
X-Akamai-Request-ID2
Uber-Trace-Id
X-Yottaa-Metrics
X-UnsetCookies
X-Yottaa-Optimizations
X-Origin-Response-Time
X-Tt-Trace-Host
X-Time
X-Tt-Trace-Tag
X-Mode
X-Tumblr-Pixel-1
X-Load-Cache
X-Tumblr-Pixel-2
Filterid
X-IPS-LoggedIn
X-Mobile
X-Proxy
Version
X-Handled-By
X-PHP-Backend
Access-Control-Request-Headers
X-Unique-Id
X-Cache-Remote
Liferay-Portal
X-FireWall-Port
Accept-Language
X-Presslabs-Stats
X-NGENIX-Cache
Cross-Origin-Window-Policy
Meta-Geo
X-Framework
X-Adobe-Source
X-CCM
X-Cache-Var-Map
X-Cache-Var
X-Viewer-Country
X-RN-RSRV
X-Path-Route
X-No-Session
X-Via-Fastly
X-ES-SERVER
X-UA-Device-Type
X-Backend-Name
X-Cache-Status-Check
X-Cache-NGX
X-Pubstack
X-Time-Microsecs
Decoy-Debug-Status
Decoy-Debug-TTL
X-OCL
X-PCL
ServedBy
Cache-Hits
Decoy-Debug-Key
X-NewRelic-App-Data
X-MP-GENERATED-AT
X-PERF
X-LJ-Flow-ID
X-AWS-Id
X-VWS-Id
X-Site-Version
X-Storage
Akamai-GRN
X-Www-Served-By
DSUID
X-Redis-Cache
X-Azure-Ref
X-ApacheServer
Cache
X-Locale
Cache-Name
X-Info
X-RTag
X-Real-IP
X-R9-Blue-Green-Version
X-NCache
X-Say-Cacheable
X-Say-TTL
X-TX-ID
X-SayCDN-TTL
X-Web-Node
X-Human
X-FW-Version
Section-Io-Id
Now
Mn-Server-Ip
Fastly-SSL
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
X-Cache-Config
Webserver
Section-Origin-Responded
Cleartype
Ms-Operation-Id
Upgrade-Insecure-Requests
Webcakes-App-Version
Webcakes-App-Name
Webcakes-Region
X-Section
X-Routing-Service
X-Access
TWC-Privacy
TWC-Locale-Group
Property-Id
Origin-Edge-Control
S-Rt
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-LatLong
X-Bc-Bl
X-Format
X-FC-Vary-Parameters
X-Origin-Hint
X-Origin
X-NWS-UUID-VERIFY
X-Hl-Ver
X-Device-Type
X-CS
X-Cache-Enabled
X-BYPASS-REASON
X-ProxyCache-Status
X-ProxyCache-Key
X-Proxied
Origin-Cache-Control
TWC-GeoIP-Country
X-UPSTREAM-Address
X-Zipkin-Id
X-Generated
DB-Nickname
X-ShardId
X-ShopId
Selected-Fe
X-Proxy-Build
X-Detected-As
X-FB-TRIP-ID
X-Alternate-Cache-Key
X-From
X-ServerID
X-Shopify-Stage
X-Amzn-Remapped-Content-Length
X-NYM-Debug-Backend
X-Sorting-Hat-PodId
X-IP
X-Loop
X-Xfnlog-Site
X-TNCMS
X-Hyper-Cache
X-Timing-Wait
X-Sorting-Hat-ShopId
X-EIG-Tracking-Id
Azure-Version
X-SaId
Azure-SlotName
Azure-SiteName
Azure-InstanceId
Azure-RegionName
X-BCube-Filmed-By
X-Varnish-Cache-Hits
X-JoinUs
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Hosted-By
Country
Load-Balancing
X-Content-Age
X-Source
X-Qloud-Router
Ec-Rule-Version
X-PHP-Host
X-Labrador-Cache-Channel
X-Cluster-Node
X-Air-Hostname
X-Old-Content-Length
X-CSRF-Token
SD-X-WS
X-Geo
Cache-Tv-Group
X-Cache-NE
X-Varnish-Hostname
User-Agent
X-Cache-Host
Time
X-Pad
X-Release
X-Vcache
X-Litespeed-Cache
X-Drupal-Cache-Contexts
X-CDN-Forward
X-Backend-TTL
FilterID
X-Cache-2
X-Parent-Response-Time
X-Cache-TTL-Remaining
X-Urbn-Site-Id
X-Urbn-Context-Path
Locale
X-Ua
X-Cache-Backend
S-Cnection
X-RCS-CacheZone
Server-Info
X-Akamai-Request-ID
X-EC-Lua
X-Proxy-Cache-Status
X-Webkit-CSP
X-Cache-Grace
X-Forwarded-Host
X-Tumblr-Pixel-3
X-RateLimit-Limit
X-Microcachable
X-Debug-Cache
Proxy-Connection
X-Srv
X-UA
X-NC
X-Dc
NGX
X-Soup
Tracecode
X-FORWARDED-FOR
OT-Force-Account-Verify
Sid
X-Tb
X-A-Wwc
X-Reqid
T-Server
X-Date
X-NodeID
X-Destination
GEO-REGION-INFO
X-Accel-Expires-Debug
X-Transaction
X-Cluster-Name
X-PAYTM-SRV-ID
UCS
X-Processor
Cache-Key
True-Client-Country-4JS
X-A-Dgt
X-Connection-Hash
X-D
Apigw-Requestid
Xc-Version
X-Region-Sid
X-CF-Lambda-Version
X-Aed
BehaviorPad-Version
X-Instart-Info
X-ARC
Server-Host
X-Application
X-Geo-Header
X-Generated-On
X-G
Arc-Country
AsisCache
X-External-Request-Id
X-B-Cookie
Fastcgi-X-Cache-Version
X-DevSite-Last-Modified
X-Developer
X-A-Dcw
X-Dispatch
Content-Style-Type
Content-Script-Type
X-Proto
X-Trv-Group
X-Level-Front-Cache
ServerName
X-Vtex-Remote-Cache
X-SRCache-Key
MD5-Digest
Geo-Info
X-Trace-Id
Machine
X-ScT
X-Vdms-Path
M-TraceId
X-Vdms-Version
X-A-Ccd
Meta-Geo-Continent
X-VG-WebCache
Mobile-Detection-Method
X-VG-WebServer
X-Session-Fingerprint
X-ServiceProvider
Who
X-Scheme
Rendered-Blocks
Pagetype
X-CF-Lambda-Fn
X-A
X-Vtex-Processado-Em
X-Rewrite-Enabled
Viewtype
VivaBuild
X-Twitter-Response-Tags
X-Rojux
X-A-Dam
X-Swa-Ws
X-S-Cookie
X-S
User-Cache-Control
X-TIME
X-Magnolia-Registration
X-Branch-Name
N-Cache
On-Server
X-Fmm-Version
NM-Fastcgi-Cache
CDCHOST
X-Cache-Info
X-Cms-Context
X-Core-Value
X-Clara-WADP
X-Bip
X-Gen-Mode
Kp-EeAlive
Release
Magicmarker
X-Cache-FS-Status
X-Dispatcher-Server
X-Device-Os
FNAC-ModuleRouting
Mail-Subject
IsBot
X-Cache-Bucket
X-Ms-Version
Vix-Hermes-Req-Id
Viewport
X-B3-Traceid
X-Vgn-Hpd-Reason
X-SD-PageType
X-WADP-Cache
Thinkindot-Control
X-Uri
X-Generated-In
Thinkindot-CacheControl-Type
X-Wikidot-Backend
We-Hiring
X-User
X-SN
X-Thanos
X-Thinkindot-L3
X-VC-Cache
X-Skip-Cache
X-SIPLIST1
X-Via-PopV
Web-Mar-Node
GEO-INFO
X-Via-PopH
Thinkindot-CacheControl
X-Wikidot-Static-Cache
X-Agile-Age
X-LAGOON
X-TT-TIMESTAMP
X-Node-Id
X-Cache-PHP
X-Agile-Id
AKAMAI
X-Generation-Time
X-Hash
X-Hnp-Log
X-Logging-Id
X-Location
X-Agile
X-Ms-Request-Id
X-Micro-Cache
X-Method
X-Matched-Rule
X-Block-Status
X-Worker
X-Hit
X-Newrelic-Synthetics
X-Envoy-Decorator-Operation
Cf-Ipcountry
X-SRV
X-Backend-State
X-Backend-Host
X-Auto-Login
X-BBXSRF
X-Irp-Debug
X-Req
X-Request-Host
X-Request-UUID
X-Reboot
X-We-Are-Hiring
X-Owner
X-Policy
X-Webstats-RespID
X-Response-By
X-TrackingId
X-Slack-Backend
X-VG-TLSProxy
X-Variation
X-Servername
X-Server-W
X-VServer
Wxu-Next-Region
X-Origin-Expires
X-Origin-Date
X-Distil-CS
X-Envoy-Upstream-Healthchecked-Cluster
X-Eu-Site
X-Developers
X-Clientip
X-Cache-URL
X-CGP
X-Fastly-Cache
X-Has-Esi
X-Mvc-Supplant-Cachable
X-RateLimit-Limit-Second
X-Nginx-Cache-Key
X-RateLimit-Remaining-Second
X-JWT-State
X-Varnish-Cacheable
X-Is-Gdpr
X-Cache-Tags
Wxu-Next-Commit
X-TA-CDN-Provider
HA-Ipaddr
Ha-Gx-Prefs
Wxu-Next-Hostname
Is-Eu
Platform
Memcached
L5d-Success-Class
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-Idcheck
Apple-News-Services-Host
Apple-News-Services-Handled
Adler-Geo
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Cache-Cookie-Set-From
C-Via
Node
Gh-Request-Id
Sever-Int
RNT-Machine
Rt-Fastcgi-Cache
Server-Ext
Server-Hostname
V-Age
RNT-Time
X-Be
X-GoCache-CacheStatus
Esi-Enabled
X-Platform-Server
Fastly-SIE
X-LI-UUID
Fastly-SWR
X-Distributor
X-Epic-Correlation-Id
W
X-Rebelmouse-Cache-Control
CacheControlHeader
X-App
X-Li-Pop
X-Rebelmouse-Surrogate-Control
X-Li-Fabric
Fastly-Drupal-HTML
X-Contensis-Viewer-Groups
X-Var-Ttl
X-Varnish-Authentication
X-Core-Mission
X-Cache-ASPX
X-Nc
Server-ID
X-LI-Proto
X-Refresh
X-Compress-Hint
L
X-DC
Cache-Host
X-Server-IP
X-TH-Server
Ohc-File-Size
X-App-Name
X-CLOUD-TRACE-CONTEXT
X-Gzip
X-Cache-Id
X-VCT
X-Cache-Debug
X-Esi-Check
X-AIR-PT
X-Loc
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-Wa
X-Varnish-Beresp-Ttl
X-Origin-CC
X-Origin-TTL
X-Configured-By
HostName
X-Mvc-Supplant-OutputCached
X-Cdn-Srv
X-ZONE
X-Sucuri-ID
X-BC
X-Storefront-Renderer-Rendered
X-S-Maxage
LB
X-SVT-ORM-VERSION
NtCoent-Length
X-SVT-ORM-RULES
Server-Cache-Control
Server-Surrogate-Control
X-FPC
X-Generated-By
X-Key
X-NU-AKA-ACS-Version
X-MSEdge-Features
Ohc-Response-Time
X-MSEdge-Flight
X-Edge-Location
Memory
X-App-Version
X-Zone
MIME-Version
X-Bc
X-Varnish-URL
X-Varnish-Ttl
Pragrma
X-Rocket-Nginx-Bypass
X-Cdn-Forward
X-CF-Powered-By
CACHE
X-Debug-Panamera-Sitecode
Heartbleed
X-Debug-Panamera-Host
Locid
Referer-Policy
Request-Country
X-Svr
X-Servedbyhost
Request-EU
X-Varnish-Hits
X-GEO
Fastly-Backend-Name
X-Pjax-Url
X-Request-URI
Resin-Trace
X-Batcache
X-COUNTRY
X-Shopify-Generated-Cart-Token
X-Nginx-Cache
FSS-Cache
X-Ratelimit-Remaining
X-BACKEND-TTL
X-Up
X-VCL-Version
SRV
X-Via-CDN
X-Gamma-Serve
WZWS-RAY
X-Minions-Version
X-ND-Cache
Geoip-Latitude
GeoIp-Country-Code
X-Aicache-OS
X-ElasticPress-Query
Hostname
X-Sucuri-Cache
X-WebServer
X-CACHE-KEY
Lfy
CF-Cached-On
X-Amzn-Requestid
X-BE
Cteonnt-Length
Product
X-Oss-Storage-Class
X-Oss-Server-Time
X-Proxy-Upstream
X-Oss-Object-Type
HitType
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
GeoIP-Country-Code
X-CSRF-TOKEN
X-Check-Cacheable
X-ECache
My-App
X-Edge-Server
X-Vcl-Version
X-NGINX-Cache
X-Fetched-On
Cdn-Request-Time
Mime-Version
DCR-Processing-Time-Ms
GeoIP-Latitude
X-Sn-Servicetimems
X-PJAX-URL
Powered-By-ChinaCache
DCR-Decision-By
X-Cdn-Origin
Cdn-Host
X-Unique-ID
Location
X-Azure-Ref-OriginShield
X-PF-Uncompressing
Ohc-Cache-HIT
X-HS-Status
Pramga
X-Fastly-Cache-Status
X-GeoIP-Country-Code
X-Ratelimit-Limit
X-Fastly-Country-Code
SN
X-ServedByHost
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
X-Varnish-Url
X-Fastly-Backend-Reqs
X-Pf-Uncompressing
Amp-Access-Control-Allow-Source-Origin
X-VarnishDD-TTL
X-OVcl-Cache
PFcat
X-LB-ID
X-OVcl
X-CACHE-AGE
X-Request-Start
Group
X-Served-From
URI
XServer
Dt-Cache-Category
X-Fpc
Cdn
X-Vgn-Hpd-Cached
X-B3-Spanid
X-Vgn-Hpd-Variations-Key
X-Vgn-Hpd-Ssi
X-Newrelic-App-Data
X-Shard
X-B3-SpanId
X-Render-Time
X-Instart-Isnd
X-Platform
X-Ratelimit-Reset
X-Via-Ucdn
X-Varnishpool
X-Ftr-Cache-Host
X-Swift-Error
WWW-Authenticate
X-IN-APIGATEWAY
X-Request-Time
X-Cache-Expired-At
A
X-IN-APIGATEWAYSSL
Country-Code
Cf-Alt-Svc
CloudFront-Viewer-Country
X-Via-NSCOPI
X-Fastly-Request-Id
X-Varnish-Beresp-TTL
X-Tb-Optimization-Total-Bytes-Saved
X-Ocache
X-Debug-Cache-Fetch
X-Debug-Cache-Store
Origin
Geoip-City
X-DPWN-IS-SECURE
Lb
X-WPE-Loopback-Upstream-Addr
X-WR-MODIFICATION
X-Debug-Cache-Status
X-C
X-Debug-Cache-Bypass
X-Debug-Xas-Auth
X-Debug-Ysi-Auth
X-LiteSpeed-Cache-Control
Cloudfront-Viewer-Country
PICS-Label
Server-Ttl
X-Debug-Do-Not-Cache-Uri
X-StackifyID
X-Debug-Cache-String
X-Planisys-CDN-Cache
X-Apw-Hits
X-Amzn-Remapped-Date
X-CUA
X-WA
X-Apw-Access-Action
X-Apw-Access-Token
X-Apw-Access-Object
X-Amzn-Remapped-Connection
X-Planisys-CDN-Rules
SID
CF-IPCountry
X-Planisys-CDN-TTL
Epwk-X-Cache
X-Country-IP
X-Oss-Cdn-Auth
NnCoection
Region
X-Cache-Tag
Request-Time
Host-ID
X-Acquia-Application-UUID
Pics-Label
Cneonction
X-Cache-Hfrom
X-Cache-Hm
X-Rocket-Build-Number
X-Nananana
X-Sigma
X-Acquia-Site
X-Sigma-Backend
X-Acquia-Purge-Tags
Proxy-Firewall
X-Acquia-Application-Trace
X-APP
DataCenter
X-Lb-Id
X-Request-URL
X-RPM
X-Varnish-ID
X-Li-Proto
X-ElasticPress-Search
X-RPS
X-RSL
X-Akamai-ERPolicy
X-B3-Parentspanid
Req-ID
X-Akamai-ERRuleID
X-DW
X-SB
X-VC
X-Action
X-Dw-Trace-Id
X-DB
X-DSS
X-Html-Edge-Cache
X-DI
TTL