Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
CF-RAY
CF-Cache-Status
Pragma
Link
X-Powered-By
ETag
Expect-CT
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Xss-Protection
X-Varnish
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
Alt-Svc
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-FRAME-OPTIONS
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Request-ID
X-Generator
Content-Security-Policy-Report-Only
X-Cache-Status
X-Cacheable
X-Permitted-Cross-Domain-Policies
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-Template
X-Language
X-AspNetMvc-Version
Status
X-Content-Security-Policy
X-Buckets
Content-Encoding
Access-Control-Expose-Headers
Upgrade
X-CDN
Xkey
Access-Control-Max-Age
Keep-Alive
X-Kinja-Server-Push
X-Drupal-Dynamic-Cache
X-Turbo-Charged-By
X-Via
X-AH-Environment
X-Cache-Group
X-Age
X-Pass-Why
X-Backend
X-Ua-Compatible
X-Envoy-Upstream-Service-Time
EagleId
X-Server
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Page-Speed
X-Pingback
X-Server-Powered-By
X-UA-Device
X-Proxy-Cache
X-Swift-CacheTime
X-Swift-SaveTime
X-Hacker
X-Nginx-Cache-Status
Ali-Swift-Global-Savetime
Request-Context
Grace
X-Varnish-Cache
Server-Timing
Feature-Policy
Cf-Railgun
X-Amz-Version-Id
X-LiteSpeed-Cache
X-Device
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-WebKit-CSP
X-Rq
X-Server-Id
Report-To
EagleEye-TraceId
X-Ac
X-Response-Time
X-OneAgent-JS-Injection
X-Host
Request-Id
X-Cnection
X-Backend-Server
X-DataDome
X-Node
Content-Location
X-Origin-Cache
X-Cloud-Trace-Context
X-Ws-Request-Id
X-Readtime
X-Cache-Lookup
NEL
X-Dns-Prefetch-Control
X-Cdn
X-Vhost
X-Application-Context
X-Dispatcher
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-HW
Allow
X-Clacks-Overhead
X-Rack-Cache
X-EdgeConnect-Origin-MEX-Latency
X-Origin-Upstream-Status
X-EdgeConnect-MidMile-RTT
Surrogate-Control
X-DynaTrace
Rating
X-Country
X-FTR-Request-ID
Fusion-Component-Id
Fusion-Source
Fusion-Content-Id
Fusion-Template-Id
Fusion-Content-Source
X-Country-Code
X-Akam-SW-Version
X-Goog-Hash
Pinterest-Generated-By
X-Instart-Request-ID
X-Varnish-TTL
X-Ruxit-JS-Agent
X-TtlSet
X-Vname
X-PC
Edge-Control
X-MS-InvokeApp
X-Mod-Pagespeed
SPRequestGuid
X-Url
Verso
X-Powered-By-Plesk
X-B3-TraceId
X-D2id
X-SharePointHealthScore
X-Trace
Response
X-Sol
Pagespeed
X-Middleton-Response
X-Middleton-Display
Display
X-VARITI-CCR
Service-Worker-Allowed
RTSS
X-Kinja-Build
X-TTL
X-Use-Magma
X-Kinja
X-GoogleNews-Bot
X-Exp-Variant
X-Cdn-Fetch
X-Kinja-Revision
X-Kinja-Server
X-Exp-Id
X-GitHub-Request-Id
Content-MD5
X-Server-Name
SPRequestDuration
SPIisLatency
X-Navigation-Version
X-ESI
X-Vcache
X-Powered-CMS
Accept-Ch
X-Abt-Application-Version
X-Debug
X-Amz-Server-Side-Encryption
Charset
X-Vcap-Request-Id
X-Upstream
X-Forwarded-Proto
MS-Author-Via
Public-Key-Pins
X-CST
X-Cached
X-NF-Request-ID
X-Amz-Rid
X-Version
X-Server-ID
Realpath
Edge-Cache-Tag
DynaTrace
X-Px
MicrosoftSharePointTeamServices
X-Shard
TCN
Arr-Disable-Session-Affinity
Accept-Ch-Lifetime
X-Ezoic-Cdn
X-XRDS-Location
Pinterest-Version
X-DynaTrace-JS-Agent
X-Shield-Request-Id
X-MSEdge-Ref
X-Pinterest-Rid
Fastly-Restarts
Access-Control-Request-Method
X-Ser
X-SRCache-Store-Status
X-Trafficlayer-App-Scope
X-SRCache-Fetch-Status
X-Trafficlayer-App-Name
X-Fastly-Request-ID
S
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Accel-Expires
X-DIS-Request-ID
X-Recruiting
Front-End-Https
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Metageneration
X-Client-IP
X-Amz-Meta-S3cmd-Attrs
Nginx-Cache
X-T
X-Id
X-Goog-Storage-Class
X-Varnish-Age
X-Element-Page-Cache
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-Country-Code-Real
X-FTR-Balancer
X-FTR-Realm
X-FTR-DC
X-FTR-Backend-Server
X-FTR-Cache-Status
X-FTR-Backend
X-Amzn-Trace-Id
X-FTR-Expires
Cache-Tag
X-Dw-Request-Base-Id
X-Webapp-Samesite-None-Activated-N
Fastcgi-Cache
Accept-CH
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Cache-Config
X-Content-Digest
X-Frontend
NR-ENABLED
X-Hits
Accept-CH-Lifetime
Powered
X-Correlation-Id
X-Kinsta-Cache
X-Ttl
X-Hp-Webp
X-RateLimit-Remaining
X-FTR-Cache-Host
Alternate-Protocol
X-Fastcgi-Cache
ServerID
X-Request-Processing-Time
X-Request-Received
X-Cache-Hit
Server-Name
X-N
X-Aspnetmvc-Version
X-Grace
X-HS-Combine-CSS
X-Request-Handler-Origin-Region
X-Microsite
X-Node-Name
X-Webkit-Csp
PB-RID
PB-PID
X-Mobile-Rewrite
TP-L2-Cache
Arc-Version
TP-Cache
X-Content-Type
AMP-Access-Control-Allow-Source-Origin
X-User-Agent
X-Rid
Healthy
X-Zen-Fury
X-Analytics
X-Revision
Backend-Timing
X-Akamai-Edgescape
X-Content-Security-Policy-Report-Only
Server-Node
X-Logged-In
X-FastCGI-Cache
X-Pad
X-Forwarded-For
X-LB-Cache
X-Amz-Apigw-Id
X-Activity-Id
X-AppVersion
X-Az
X-Amzn-RequestId
Cache-Status
X-Mobile-URL
X-Varnish-Grace
X-Cached-By
X-GUploader-UploadID
AR-CACHE
X-IPLB-Instance
X-NWS-LOG-UUID
AR-ATIME
AR-PoweredBy
X-B3-Sampled
X-Oneagent-Js-Injection
X-Type
Retry-After
Refresh
X-Content-Options
X-F-Cache
X-Geo-Country
Upgrade-Insecure-Requests
Paypal-Debug-Id
X-Ruxit-Js-Agent
X-Litespeed-Cache
X-Srv
X-App-Environment
Ar-Sid
X-Instance
X-Tumblr-User
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-PHP-Backend
X-Varnish-Backend
Source
DC
X-Request-Guid
X-Debug-Info
X-Framework
Host
X-B
Access-Control-Allow-Method
Accept-Charset
Actual-Object-TTL
X-Page-Id
X-FB-Debug
X-Jobs
X-AOL-HN
X-Cluster
X-Cache-Key
FilterID
X-Cache-Age
X-Via-JSL
X-WebKit-CSP-Report-Only
X-ATG-Version
X-Cache-2
X-Seen-By
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Esi
Fastcgi-Useragent
X-TT
Cache
X-Git-Hash
MS-CV
X-Content-Powered-By
X-Whom
X-Cache-TTL
X-PressLabs-Stats
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
AR-Request-ID
X-Amz-Replication-Status
X-UA
X-Cache-Control
X-Signature
X-B-Cache
Host-Header
X-Wix-Request-Id
X-Host-Name
Surrogate-Key
X-Response-Served-From
NGB
X-Daa-Tunnel
X-TA-CDN-Provider
X-RequestSource
X-Origin-Server
X-Cache-Enabled
Frame-Options
X-FW-Hash
X-FW-Serve
X-FW-Server
X-FW-Static
X-FW-Type
Cache-Tv-Group
X-Mobile
WPE-Backend
X-TX-ID
X-GeoIP
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
X-EdgeConnect-Cache-Status
X-Handled-By
Filters
X-Cache-Action
X-Region
Eomportal-Instance
X-Drupal-Cache-Tags
Payment
X-Hyper-Cache
X-Cache-Operation
X-Cacheable-TTL
X-Cache-Rule
X-Adobe-Loc
X-Adobe-Content
Cleartype
X-Kong-Proxy-Latency
X-Cache-NE
X-Kong-Upstream-Latency
Webserver
Xserver
From-Origin
X-SERVER
X-Hostname
X-ProcessESI
X-UA-Device-Type
X-RemovedCookies
X-Akamai-Transformed
X-Load-Cache
X-Forwarded-Host
X-NewRelic-App-Data
Datacenter
Ms-Operation-Id
X-RTag
X-Cache-TTL-Remaining
X-Time
X-ATS-Timestamp
X-Edge-Location
X-Cache-Server
Liferay-Portal
X-App-Server
X-Contextid
X-Status
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Varnish-Hostname
X-B3-Traceid
X-Varnish-Server
X-Rule
Tracecode
Country
X-BCube-Filmed-By
X-TT-TIMESTAMP
Odigeo-Trace-Id
X-Oss-Storage-Class
X-URL
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-RN-RSRV
X-Path-Route
X-Cache-Var
X-Cache-Var-Map
X-Upgrade-Enabled
Meta-Geo
X-ES-SERVER
Load-Balancing
X-UUID
X-Viewer-Country
X-Xfnlog-Site
X-Debug-Cache
X-ORACLE-APMCS-TAG
X-ORACLE-APMCS-REQUEST-ID
DSUID
X-R9-Blue-Green-Version
TWC-GeoIP-LatLong
X-VCT
X-Via-Fastly
TWC-GeoIP-Country
TWC-Locale-Group
X-PCL
X-Origin-Hint
Webcakes-App-Version
Webcakes-Region
Webcakes-App-Name
Mn-Server-Ip
X-CCM
TWC-Privacy
TWC-Device-Class
X-Pubstack
Release
Property-Id
Cache-Tags
X-FW-Dynamic
X-OCL
DB-Nickname
TWC-Connection-Speed
Azure-InstanceId
Azure-SlotName
Azure-RegionName
Fastly-SSL
NGX
X-Redis-Cache
Cache-Name
Azure-SiteName
Azure-Version
S-Rt
Server-Info
X-IP
X-Human
X-Cache-Time
X-Web-Node
X-From
X-Origin-Response-Time
X-EIG-Tracking-Id
X-Drupal-Cache-Contexts
X-Cache-Config
X-Rocket-Nginx-Bypass
X-Cache-Host
X-Soup
X-Akamai-Request-ID2
X-Akamai-Request-ID
X-Labrador-Cache-Channel
X-Origin
X-Varnish-Cache-Hits
X-Loop
X-Proto
X-Hosted-By
X-Rendered-As
L5d-Success-Class
X-Site-Version
X-FC-Vary-Parameters
X-Format
X-Www-Served-By
Origin-Cache-Control
X-ApacheServer
X-Locale
X-Section
Ec-Rule-Version
X-PERF
X-Access
Origin-Edge-Control
X-Proxy
X-Real-IP
X-TNCMS
S-Cnection
Decoy-Debug-TTL
Decoy-Debug-Key
X-NWS-UUID-VERIFY
Decoy-Debug-Status
X-Is-Bot
Version
X-ServerID
X-FireWall-Port
X-Content-Age
X-Time-Microsecs
Viewport
X-Timing-Wait
X-Varnish-Hits
X-Proxy-Build
Selected-Fe
X-Vgn-Hpd-Reason
X-Goog-Meta-Goog-Reserved-File-Mtime
X-XRDS-LOCATION
X-Storage
X-Backend-Name
X-Info
Uber-Trace-Id
X-Generated
X-Cluster-Name
X-BYPASS-REASON
X-RateLimit-Limit
X-JoinUs
X-ProxyCache-Key
X-ProxyCache-Status
X-VCache
X-Cache-Backend
X-Generated-By
X-Origin-CC
X-Origin-TTL
X-Accel-Buffering
X-PHP-Host
Rt-Fastcgi-Cache
X-Amzn-Remapped-Content-Length
Akamai-GRN
Cteonnt-Length
Cache-Key
Time
X-WA-Info
X-Presslabs-Stats
X-Nginx-Cache-Key
X-APP-VERSION
X-No-Session
Origin
Cache-Hits
GEO-INFO
X-GoCache-CacheStatus
X-App-Version
X-SaId
X-Tec-Api-Origin
X-Guploader-Uploadid
X-Geo
Vix-Hermes-Req-Id
X-Tec-Api-Version
X-Tec-Api-Root
X-SS-Set-Cookie
X-CF-Powered-By
X-NCache
X-Cache-Remote
X-Environment-Context
X-MServer
X-L-Path
X-Trace-Id
X-Backend-TTL
Accept-Language
X-Unique-Id
X-FB-TRIP-ID
X-Tb
X-Hit
X-CDN-Forward
Srv
Access-Control-Request-Headers
X-SayCDN-TTL
X-Say-Cacheable
X-Say-TTL
X-Device-Type
X-Tumblr-Pixel-3
X-CS
X-OVcl-Cache
X-OVcl
X-CSRF-TOKEN
X-Cache-Grace
X-S
X-B3-SpanId
User-Cache-Control
ServedBy
X-Cluster-Node
X-Shopify-Stage
X-Alternate-Cache-Key
X-ShardId
X-ShopId
X-Sorting-Hat-PodId
X-EC-Lua
X-Shopify-Generated-Cart-Token
X-Sorting-Hat-ShopId
Node
AsisCache
Apple-News-Services-Request-Url
Arc-Country
Mobile-Detection-Method
Apple-News-Services-Handled
Cross-Origin-Window-Policy
Content-Style-Type
Content-Script-Type
BehaviorPad-Version
Fastcgi-X-Cache-Version
IsBot
Meta-Geo-Continent
MD5-Digest
Apple-News-Services-Parsed-Url
Machine
Apple-News-Services-Host
X-A-Dcw
X-Rojux
X-Rewrite-Enabled
X-S-Cookie
X-ScT
X-Server-Time
X-Request-UUID
X-Region-Sid
X-G
X-Hl-Ver
X-PAYTM-SRV-ID
X-Processor
X-Service
X-Session-Fingerprint
X-VG-WebServer
X-VG-WebCache
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-Twitter-Response-Tags
X-Trv-Group
X-SIPLIST1
X-SRCache-Key
X-Svr
X-Transaction
X-External-Request-Id
X-DPWN-IS-SECURE
X-A
VivaBuild
X-A-Ccd
X-A-Dam
X-A-Dgt
Viewtype
T-Server
Request-Country
Request-EU
Rt-Proxy-Cache
Server-Host
X-A-Wwc
X-Accel-Expires-Debug
X-D
X-Connection-Hash
X-Date
X-Destination
X-Detected-As
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-Aed
X-AIR-PT
X-Application
X-B-Cookie
Rendered-Blocks
X-ARC
X-CACHE-KEY
X-Parent-Response-Time
ServerName
OT-Force-Account-Verify
X-Uri
NtCoent-Length
X-Block-Status
X-Ms-Version
X-Cache-Bucket
X-Location
X-Clara-WADP
X-Core-Value
X-CUA
Mime-Version
Cache-Host
X-Cms-Context
CDCHOST
X-WADP-Cache
X-Matched-Rule
Thinkindot-Control
RNT-Time
Served-By
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
Server-Int
RNT-Machine
Web-Mar-Node
X-Reboot
X-Ah-Environment
Wxu-Next-Region
Wxu-Next-Hostname
X-Ms-Request-Id
Wxu-Next-Commit
X-Webstats-RespID
X-Cache-Info
X-Generated-On
X-Request-URI
Proxy-Connection
Mail-Subject
X-Gen-Mode
We-Hiring
X-Level-Front-Cache
X-Vdms-Version
X-Instart-Isnd
X-Hnp-Log
X-RateLimit-Remaining-Second
X-Dispatch
X-Dispatcher-Server
X-RateLimit-Limit-Second
X-Thinkindot-L3
X-Endurance-Cache-Level
X-B3-Parentspanid
X-RCS-CacheZone
X-FW-Version
X-Dc
X-Via-CDN
X-Cache-URL
X-Scheme
X-Up
X-S-Maxage
X-Cdn-Srv
X-Is-Gdpr
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Method
X-Generation-Time
W
X-SVT-ORM-VERSION
X-Compress-Hint
X-Swa-Ws
X-Developers
True-Client-Country-4JS
X-SVT-ORM-RULES
X-JWT-State
X-Has-Esi
X-Server-IP
X-Geo-Header
X-NC
X-Azure-Ref-OriginShield
X-Azure-Ref
X-VC-Cache
X-VG-TLSProxy
X-Logging-Id
X-Variation
X-User
X-Skip-Cache
X-Backend-State
X-App-Name
X-Source
X-Sucuri-Cache
X-C
X-We-Are-Hiring
X-Cache-Id
X-Agile
X-Agile-Age
X-VServer
X-Fastly-Cache
X-Agile-Id
X-BBXSRF
Now
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-NX-Host
Fastly-Soc-X-Request-Id
Heartbleed
IBM-Web2-Location
L
Kp-EeAlive
X-Hash
Is-Eu
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-Magnolia-Registration
X-Reqid
X-Release
X-Qloud-Router
Adler-Geo
AKAMAI
X-Varnish-Beresp-Ttl
Content-Disposition
X-Proxy-Cache-Status
X-Proxy-Upstream
Magicmarker
Esi-Enabled
X-Cache-Debug
Section-Io-Cache
X-Debug-Cookies
Platform
Memcached
Pramga
X-Debug-Log
X-SRV
Cache-Provider
X-Rocket-Build-Number
SD-X-WS
X-Sigma
X-Epic-Correlation-Id
X-B3-Spanid
X-Li-Pop
X-LI-UUID
X-Upstream-Ct
X-Upstream-Ht
X-MSEdge-Flight
X-Distributor
Ha-Gx-Prefs
X-Li-Fabric
X-Owner
X-Via-NSCOPI
X-Platform-Server
X-Auto-Login
X-SD-PageType
PFcat
X-Internal-Host
X-Old-Content-Length
X-Distil-CS
X-Thanos
X-TrackingId
X-NodeID
X-ServiceProvider
X-WebServer
X-Sigma-Backend
Gh-Request-Id
X-Core-Mission
X-Debug-Cache-Expiry
Countrycode
X-Irp-Debug
X-Key
X-Clientip
X-MSEdge-Features
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Eu-Site
Locale
X-Generated-In
X-AK-Request-ID
X-GeoIP-City
X-Amz-Meta-Cache-Control
X-Origin-Expires
X-Origin-Date
X-Bip
Cdncip
X-Cache-FS-Status
X-Urbn-Context-Path
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
X-Policy
X-Planisys-CDN-Rules
HA-Ipaddr
X-CGP
X-Urbn-Site-Id
Cdnsip
X-Nc
Hostname
X-UnsetCookies
V-Age
Powered-By-ChinaCache
X-ND-Cache
X-Request-Start
X-LI-Proto
X-7Graus-Varnish-XKeys
X-7Graus-Varnish-Cache-Control
CF-IPCountry
Server-ID
X-Servername
X-TIME
GEO-REGION-INFO
X-Trafficlayer-App-Version
X-GRACE
Environment
X-COUNTRY
X-Cdn-Forward
A
X-Be
X-FPC
Locid
X-Req
X-Developer
X-Newrelic-Synthetics
X-Nginx-Cache
FNAC-ModuleRouting
X-Served-From
X-Sn-Servicetimems
Geo-Info
X-Cdn-Origin
X-Device-Os
X-Servedbyhost
X-Sucuri-Id
X-Lb-Id
X-Sucuri-ID
X-Zone
X-Gamma-Serve
X-Refresh
X-Node-Id
X-Microcachable
X-HTML-Minification-Powered-By
X-VHOST
ProcessTime
Tcn
X-FORWARDED-FOR
X-Webkit-CSP
Memory
X-Render-Time
X-Tb-Optimization-Total-Bytes-Saved
X-IPS-LoggedIn
X-NU-AKA-ACS-Version
X-VCL-Version
X-AWS-Id
X-VWS-Id
Request-Time
X-LJ-Flow-ID
X-Pf-Uncompressing
XServer
X-GeoIP-Country-Code
X-DC
X-Pjax-Url
Resin-Trace
X-Mode
X-MP-GENERATED-AT
Gannett-Cam-Experience-Id
X-Correlation-ID
CF-Cached-On
X-Edge-O15-RID
PICS-Label
GeoIp-Country-Code
Group
MIME-Version
X-Ratelimit-Remaining
Geoip-Latitude
Amp-Access-Control-Allow-Source-Origin
Geoip-City
X-Instart-Info
X-ECACHE
X-ElasticPress-Search
Ttl
TTL
X-Bc
GeoIP-Country-Code
GeoIP-Latitude
Cf-Ipcountry
Pics-Label
X-Backend-Host
X-Backend-Url
X-Pod
X-Var-Ttl
X-Proxied
X-Zipkin-Id
X-Routing-Service
X-NGENIX-Cache
X-CSRF-Token
X-Via-Edge
Cdn
GeoIP-City
Backend-Name
X-Via-SSL
Host-ID
X-APP
X-ZONE
X-Unique-ID
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-From
N-Cache
Cache-Cookie-Set-Idcheck
Pagetype
REQUESTUUID
Lfy
HostName
M-TraceId
Ohc-File-Size
Ohc-Cache-HIT
X-CLOUD-TRACE-CONTEXT
X-PJAX-URL
X-Vcl-Version
X-Check-Cacheable
Cache-Prefix
Fly-Cache
Fly-Request-Id
X-Fstrz
X-BC
X-GEO
X-PF-Uncompressing
X-Via-Ucdn
HitType
X-Worker
X-Cdn-Request-ID
X-Request-Time
X-Ratelimit-Limit
X-Swift-Error
X-Fastly-Country-Code
X-Sedo-Request-Id
X-Cache-Miss-From
X-TH-Server
X-NGINX-Cache
X-Dynatrace-Js-Agent
X-Server-W
User-Agent
X-UPSTREAM-Address
X-Tt-Trace-Tag
Pragrma
URI
X-Aicache-OS
X-Fetched-On
On-Server
X-HS-Status
X-Upstream-CT
X-Upstream-HT
X-HostName
X-LiteSpeed-Cache-Control
X-Cache-Tag
Powered-By
X-ServedByHost
Fastly-SWR
X-WR-MODIFICATION
CDN
X-Rebelmouse-Cache-Control
Fastly-SIE
X-Wa
X-Rebelmouse-Surrogate-Control
SRV
X-SERVER-NAME
Media-Length
X-BE
Who
X-WA
AR-SID
X-LB-ID
X-TT-LOGID
Dynatrace
X-LAGOON
FSS-Cache
X-Fastly-Backend-Reqs
X-Varnish-Cacheable
X-Fpc
X-Tt-Trace-Host
X-GDPR
FSS-Proxy
X-Varnish-URL
DataCenter
X-Cf-Powered-By
Debug
UCS
X-ServerName
X-Hp-Ccpa-Warning
Server-Id
Cdn-Host
X-Edge-Server
Cdn-Request-Time
CACHE
X-Ftr-Cache-Host
X-Ua
Filterid
X-RateLimit-Reset
Is-Session-Tracking
X-Hello
Get-Access-Time
X-Store
X-Gen-Id
WP-Super-Cache
X-ABtesting
SS
X-Protected-By
X-Flog
X-Cache-Tags
LB
X-Varnish-Beresp-TTL
X-Akamai-ERPolicy
X-SN
X-Akamai-ERRuleID
Processtime
Cneonction
XxX-Cache-Status
SN
X-Amzn-Remapped-Connection
X-Li-Proto
X-Response-By
X-Dw-Trace-Id
Country-Code
Thinkindot-Cache-Type
Xet-Cookie
X-Amzn-Remapped-Date
X-SB
X-VC
Requestid
X-Nananana
Application
X-RSL
X-Org
X-Request-Url
X-LiteSpeed-Tag
Product
X-RPS
X-DW
X-DSS
NnCoection
Warning
X-RPM
X-Action
X-Fastly-Cache-Hits
X-DI
X-DB
SID