Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
CF-RAY
CF-Cache-Status
Pragma
Link
X-Powered-By
ETag
Expect-CT
X-XSS-Protection
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Xss-Protection
X-Varnish
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
Alt-Svc
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-FRAME-OPTIONS
X-Drupal-Cache
X-Adblock-Key
X-Request-ID
X-Check
Content-Security-Policy-Report-Only
X-Generator
X-Cache-Status
X-Cacheable
X-Permitted-Cross-Domain-Policies
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Template
X-Iinfo
X-Language
X-Content-Security-Policy
Status
X-AspNetMvc-Version
Content-Encoding
X-Buckets
Access-Control-Expose-Headers
Upgrade
X-CDN
Xkey
X-Kinja-Server-Push
Access-Control-Max-Age
Keep-Alive
X-Drupal-Dynamic-Cache
X-Turbo-Charged-By
X-Via
X-Cache-Group
X-Age
X-Pass-Why
X-Envoy-Upstream-Service-Time
X-Backend
X-Ua-Compatible
EagleId
X-AH-Environment
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Server
X-Page-Speed
X-Pingback
X-Server-Powered-By
X-UA-Device
X-Swift-CacheTime
X-Swift-SaveTime
X-Proxy-Cache
X-Hacker
Ali-Swift-Global-Savetime
X-Nginx-Cache-Status
Request-Context
Grace
X-Varnish-Cache
Server-Timing
Feature-Policy
Cf-Railgun
X-Amz-Version-Id
X-Device
X-LiteSpeed-Cache
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-WebKit-CSP
X-Rq
Report-To
X-Ac
EagleEye-TraceId
X-Server-Id
X-OneAgent-JS-Injection
X-Response-Time
X-Host
Request-Id
X-Cnection
X-Backend-Server
X-DataDome
Content-Location
X-Node
X-Cloud-Trace-Context
X-Origin-Cache
X-Readtime
X-Cache-Lookup
NEL
X-Cdn
X-Vhost
X-Application-Context
X-Dispatcher
X-ORACLE-DMS-ECID
X-HW
X-Ws-Request-Id
Allow
X-ORACLE-DMS-RID
X-Clacks-Overhead
X-Rack-Cache
X-Dns-Prefetch-Control
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Origin-Upstream-Status
Surrogate-Control
X-Country
Rating
X-DynaTrace
X-FTR-Request-ID
X-Country-Code
Fusion-Component-Id
Fusion-Source
Fusion-Content-Source
Fusion-Template-Id
Fusion-Content-Id
X-Goog-Hash
X-Akam-SW-Version
Pinterest-Generated-By
X-Varnish-TTL
X-Ruxit-JS-Agent
X-PC
X-TtlSet
X-Vname
X-Instart-Request-ID
X-Url
X-MS-InvokeApp
Edge-Control
X-Mod-Pagespeed
Verso
X-Powered-By-Plesk
SPRequestGuid
Accept-Ch
X-B3-TraceId
X-D2id
X-Trace
Pagespeed
X-Sol
X-Middleton-Response
Response
Display
X-Middleton-Display
X-SharePointHealthScore
RTSS
X-VARITI-CCR
Service-Worker-Allowed
X-Exp-Id
X-Kinja-Revision
X-Kinja-Server
X-Server-Name
X-Use-Magma
X-Kinja
X-Kinja-Build
X-GoogleNews-Bot
X-Exp-Variant
X-Cdn-Fetch
X-GitHub-Request-Id
X-Vcache
SPRequestDuration
SPIisLatency
X-Server-ID
X-Navigation-Version
Content-MD5
X-Powered-CMS
X-Debug
X-Abt-Application-Version
X-Vcap-Request-Id
X-ESI
X-CST
X-Amz-Server-Side-Encryption
Public-Key-Pins
Charset
MS-Author-Via
Accept-Ch-Lifetime
X-Forwarded-Proto
X-Upstream
X-Cached
X-Version
X-Px
X-NF-Request-ID
X-Amz-Rid
DynaTrace
X-TTL
Realpath
X-Shard
X-Aspnetmvc-Version
Edge-Cache-Tag
TCN
Fastly-Restarts
MicrosoftSharePointTeamServices
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
Arr-Disable-Session-Affinity
X-Ezoic-Cdn
X-MSEdge-Ref
X-Recruiting
X-XRDS-Location
X-Shield-Request-Id
Access-Control-Request-Method
X-Pinterest-Rid
Pinterest-Version
X-DynaTrace-JS-Agent
X-Ser
X-SRCache-Store-Status
X-SRCache-Fetch-Status
S
X-Fastly-Request-ID
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
Nginx-Cache
Front-End-Https
X-Ttl
X-Accel-Expires
X-DIS-Request-ID
X-Amz-Meta-S3cmd-Attrs
X-Goog-Storage-Class
X-Client-IP
X-Trafficlayer-App-Name
X-Trafficlayer-App-Scope
X-Id
X-Varnish-Age
X-Element-Page-Cache
X-T
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-DC
X-FTR-Backend
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-Realm
X-FTR-Expires
X-Amzn-Trace-Id
X-Dw-Request-Base-Id
Fastcgi-Cache
X-RateLimit-Remaining
Cache-Tag
NR-ENABLED
X-HS-Hub-Id
X-HS-Content-Id
X-Frontend
X-Content-Digest
X-Correlation-Id
Powered
X-Hits
X-Fastcgi-Cache
X-Kinsta-Cache
X-HS-Cache-Config
X-Grace
X-FTR-Cache-Host
ServerID
X-Webapp-Samesite-None-Activated-N
X-Litespeed-Cache
Alternate-Protocol
TP-Cache
X-Hp-Webp
TP-L2-Cache
X-Cache-Hit
X-Request-Processing-Time
X-Node-Name
X-Request-Received
X-Request-Handler-Origin-Region
PB-RID
X-Microsite
PB-PID
X-Mobile-Rewrite
X-Webkit-Csp
Arc-Version
AMP-Access-Control-Allow-Source-Origin
X-N
Ar-Sid
AR-ATIME
AR-PoweredBy
AR-CACHE
Server-Name
X-Content-Type
X-Zen-Fury
X-Rid
X-User-Agent
X-Forwarded-For
Healthy
X-Ah-Environment
X-Revision
Backend-Timing
X-Analytics
Server-Node
X-Content-Security-Policy-Report-Only
Accept-CH-Lifetime
X-LB-Cache
X-Akamai-Edgescape
X-Logged-In
X-SERVER
X-HS-Combine-CSS
X-AppVersion
X-Activity-Id
X-Az
X-FastCGI-Cache
Cache-Status
X-GUploader-UploadID
X-Pad
X-Amzn-RequestId
Retry-After
X-Amz-Apigw-Id
X-IPLB-Instance
X-Srv
X-Cached-By
X-NWS-LOG-UUID
X-Type
Paypal-Debug-Id
X-Via-JSL
X-Varnish-Grace
X-Oneagent-Js-Injection
X-Esi
X-Mobile-URL
Accept-CH
X-B3-Sampled
X-Content-Options
X-F-Cache
Refresh
FilterID
X-Ruxit-Js-Agent
X-Cache-Age
AR-Request-ID
X-Geo-Country
X-Tumblr-Pixel-0
X-Debug-Info
X-FB-Debug
Accept-Charset
X-Tumblr-User
Upgrade-Insecure-Requests
X-Tumblr-Pixel
X-Instance
Host
X-Page-Id
Source
X-AOL-HN
X-App-Environment
X-Cluster
X-Request-Guid
Access-Control-Allow-Method
X-Jobs
X-Erf-Bev-Bev
X-Varnish-Backend
X-Erf-Bev-Bev-Is-Generated
X-B
Actual-Object-TTL
X-PHP-Backend
X-Framework
X-PressLabs-Stats
DC
X-Seen-By
X-WebKit-CSP-Report-Only
X-Cache-Key
X-ATG-Version
Fastcgi-Useragent
MS-CV
X-Content-Powered-By
X-Whom
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Git-Hash
X-TT
X-Cache-2
X-Host-Name
X-Cache-Control
Cache
X-Cache-TTL
X-Amz-Replication-Status
Surrogate-Key
X-Wix-Request-Id
X-Signature
X-B-Cache
X-Cache-Operation
Frame-Options
X-Cache-Rule
X-Daa-Tunnel
NGB
X-Time
X-Kong-Upstream-Latency
X-FW-Serve
Host-Header
X-FW-Hash
X-Kong-Proxy-Latency
Xserver
X-Response-Served-From
X-FW-Type
X-FW-Server
X-FW-Static
X-TA-CDN-Provider
X-UA
X-Origin-Server
X-Forwarded-Host
X-Tumblr-Pixel-1
Cache-Tv-Group
X-Tumblr-Pixel-2
X-Cache-NE
X-Cache-Action
Cleartype
WPE-Backend
Payment
Webserver
X-Drupal-Cache-Tags
X-Hyper-Cache
X-Region
X-GeoIP
X-TX-ID
X-Mobile
X-RequestSource
Eomportal-Instance
X-Cacheable-TTL
X-Handled-By
X-Adobe-Loc
X-Adobe-Content
Filters
X-Cache-Enabled
From-Origin
X-UA-Device-Type
X-ProcessESI
X-RemovedCookies
X-EdgeConnect-Cache-Status
Datacenter
X-RTag
X-App-Server
Ms-Operation-Id
X-Hostname
X-Cache-TTL-Remaining
X-Akamai-Transformed
Tracecode
X-Load-Cache
X-NewRelic-App-Data
X-Status
X-Cache-Server
X-Contextid
X-Edge-Location
Liferay-Portal
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-BCube-Filmed-By
X-RateLimit-Limit
X-B3-Traceid
X-TT-TIMESTAMP
X-Varnish-Hostname
X-Varnish-Server
Odigeo-Trace-Id
X-Rule
X-FW-Dynamic
Server-Info
Country
Load-Balancing
Meta-Geo
X-Path-Route
X-ES-SERVER
X-Cache-Var-Map
X-Cache-Var
X-RN-RSRV
X-Xfnlog-Site
X-ATS-Timestamp
X-Viewer-Country
Cache-Tags
DB-Nickname
X-CCM
X-Cache-Config
X-Via-Fastly
X-Rocket-Nginx-Bypass
X-UUID
X-OCL
X-PCL
X-IP
Version
X-Debug-Cache
X-ServerID
X-R9-Blue-Green-Version
X-Proxy
L5d-Success-Class
Property-Id
X-Pubstack
X-Real-IP
X-Redis-Cache
X-TNCMS
Azure-Version
Azure-InstanceId
Azure-SlotName
Azure-RegionName
Azure-SiteName
TWC-GeoIP-LatLong
TWC-Device-Class
TWC-GeoIP-Country
TWC-Locale-Group
S-Rt
TWC-Privacy
Mn-Server-Ip
TWC-Connection-Speed
Fastly-SSL
Webcakes-App-Name
X-FC-Vary-Parameters
X-From
X-Upgrade-Enabled
X-Drupal-Cache-Contexts
X-Web-Node
X-Proto
X-Hosted-By
X-Origin-Hint
X-Origin-Response-Time
X-Origin
X-Loop
X-Labrador-Cache-Channel
X-Cache-Time
X-EIG-Tracking-Id
X-Akamai-Request-ID
X-Cache-Host
Webcakes-App-Version
Webcakes-Region
X-Varnish-Cache-Hits
X-JoinUs
Cache-Name
X-Human
X-Access
X-Timing-Wait
X-Info
Decoy-Debug-Key
Ec-Rule-Version
X-PERF
Viewport
DSUID
Decoy-Debug-TTL
X-Origin-CC
Decoy-Debug-Status
X-Rendered-As
X-Goog-Meta-Goog-Reserved-File-Mtime
Release
X-Content-Age
Origin-Edge-Control
X-Cluster-Name
X-Section
S-Cnection
X-VCT
Origin-Cache-Control
Selected-Fe
X-Format
X-Akamai-Request-ID2
X-Generated
X-FireWall-Port
X-ApacheServer
X-Proxy-Build
X-Backend-Name
X-Origin-TTL
X-Soup
X-Time-Microsecs
X-Www-Served-By
X-Vgn-Hpd-Reason
NGX
X-Varnish-Hits
X-NWS-UUID-VERIFY
X-XRDS-LOCATION
X-Oss-Hash-Crc64ecma
X-Storage
X-Site-Version
X-Oss-Object-Type
X-Oss-Storage-Class
X-Oss-Server-Time
X-Locale
X-Oss-Request-Id
X-Is-Bot
X-VCache
Rt-Fastcgi-Cache
X-BYPASS-REASON
X-ProxyCache-Key
X-ProxyCache-Status
Uber-Trace-Id
Cache-Key
X-WA-Info
X-PHP-Host
X-App-Version
X-Cache-Backend
X-Generated-By
X-ORACLE-APMCS-TAG
X-ORACLE-APMCS-REQUEST-ID
Vix-Hermes-Req-Id
X-GoCache-CacheStatus
X-Webkit-CSP
X-Amzn-Remapped-Content-Length
Cteonnt-Length
Cache-Hits
X-Hit
X-Accel-Buffering
X-NCache
X-SS-Set-Cookie
Akamai-GRN
X-Cache-Remote
Origin
Time
X-Backend-TTL
X-Cache-Grace
X-Nginx-Cache-Key
GEO-INFO
X-Guploader-Uploadid
X-Trace-Id
X-CS
X-Device-Type
X-FB-TRIP-ID
X-Tumblr-Pixel-3
X-APP-VERSION
X-L-Path
Accept-Language
X-Environment-Context
X-OVcl
X-No-Session
X-OVcl-Cache
X-MServer
X-S
X-Tb
X-SaId
X-B3-SpanId
Access-Control-Request-Headers
X-Say-TTL
X-Uri
X-Cluster-Node
X-Say-Cacheable
X-SayCDN-TTL
X-CF-Powered-By
Mime-Version
X-CSRF-TOKEN
Fastcgi-X-Cache-Version
Hostname
X-Geo
X-URL
X-Via-CDN
X-UnsetCookies
User-Cache-Control
Now
BehaviorPad-Version
IsBot
X-External-Request-Id
X-Processor
X-Presslabs-Stats
AsisCache
Rt-Proxy-Cache
X-Region-Sid
X-DPWN-IS-SECURE
X-Request-UUID
X-Rewrite-Enabled
X-Accel-Expires-Debug
X-Aed
X-AIR-PT
X-CF-Lambda-Fn
X-PAYTM-SRV-ID
X-CACHE-KEY
Apple-News-Services-Parsed-Url
X-Tec-Api-Origin
X-Tec-Api-Root
Machine
X-Tec-Api-Version
X-B-Cookie
X-Hl-Ver
Meta-Geo-Continent
Mobile-Detection-Method
Node
Rendered-Blocks
X-G
X-Rojux
X-Application
Apple-News-Services-Request-Url
X-ARC
Request-EU
Apple-News-Services-Handled
Apple-News-Services-Host
Request-Country
Arc-Country
X-S-Cookie
X-Destination
MD5-Digest
X-A
X-Twitter-Response-Tags
X-Trv-Group
X-Detected-As
X-Transaction
VivaBuild
X-A-Dcw
Viewtype
Cross-Origin-Window-Policy
X-Vtex-Remote-Cache
X-VG-WebServer
X-VG-WebCache
X-A-Dam
X-A-Ccd
Content-Style-Type
T-Server
X-ScT
X-A-Wwc
X-Server-Time
X-D
X-FW-Version
X-CF-Lambda-Version
Xc-Version
X-Date
X-Connection-Hash
X-Svr
X-A-Dgt
X-SRCache-Key
Content-Script-Type
X-Session-Fingerprint
X-SIPLIST1
X-Vtex-Processado-Em
ServerName
Srv
X-Endurance-Cache-Level
X-NC
X-Clara-WADP
X-Hnp-Log
X-Cache-Info
CDCHOST
X-Cms-Context
X-Gen-Mode
X-Debug-Cookies
X-Cache-Bucket
X-Cache-Debug
X-Debug-Log
X-NX-Host
X-Reboot
X-Request-URI
X-S-Maxage
X-Proxy-Upstream
X-Proxy-Cache-Status
Mail-Subject
X-Core-Value
RNT-Machine
Server-Host
X-Service
X-WADP-Cache
X-Unique-Id
Web-Mar-Node
Thinkindot-Control
Thinkindot-CacheControl-Type
Server-Int
X-Thinkindot-L3
Thinkindot-CacheControl
We-Hiring
RNT-Time
OT-Force-Account-Verify
X-Block-Status
X-Location
X-Matched-Rule
X-B3-Parentspanid
X-ShardId
X-ShopId
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Parent-Response-Time
X-Sorting-Hat-ShopId
X-Alternate-Cache-Key
X-Azure-Ref-OriginShield
X-Backend-State
X-Core-Mission
X-7Graus-Varnish-Cache-Control
X-7Graus-Varnish-XKeys
X-Azure-Ref
X-Compress-Hint
X-Clientip
X-Amz-Meta-Cache-Control
X-C
X-App-Name
X-Cache-URL
X-CGP
X-Cache-FS-Status
X-Cache-Id
X-Cdn-Srv
X-Auto-Login
X-GeoIP-City
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Reqid
X-Request-Start
X-SD-PageType
X-Scheme
X-Policy
X-Platform-Server
X-Ms-Version
X-Ms-Request-Id
X-Old-Content-Length
X-Origin-Date
X-Origin-Expires
X-Skip-Cache
X-SVT-ORM-RULES
X-We-Are-Hiring
X-VServer
X-WebServer
X-Webstats-RespID
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-VG-TLSProxy
X-VC-Cache
X-TrackingId
X-SVT-ORM-VERSION
X-Up
X-User
X-Variation
X-Method
X-Magnolia-Registration
X-Eu-Site
X-Epic-Correlation-Id
X-Fastly-Cache
X-Generated-In
X-Generation-Time
X-Generated-On
X-Distributor
X-Distil-CS
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Developers
X-Dispatch
X-Dispatcher-Server
X-Geo-Header
Wxu-Next-Region
X-Key
X-JWT-State
X-Level-Front-Cache
X-Li-Fabric
X-LI-UUID
X-Li-Pop
X-Is-Gdpr
X-Irp-Debug
X-Hash
X-Has-Esi
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Instart-Isnd
X-Debug-Cache-Expiry
X-CUA
Content-Disposition
X-CDN-Forward
Proxy-Connection
Countrycode
PFcat
Cache-Host
X-Varnish-Beresp-Grace
Wxu-Next-Hostname
Platform
Esi-Enabled
Fastly-Soc-X-Request-Id
IBM-Web2-Location
L
Is-Eu
HA-Ipaddr
Ha-Gx-Prefs
Memcached
Magicmarker
Gh-Request-Id
Kp-EeAlive
X-Varnish-Beresp-Status
AKAMAI
Served-By
True-Client-Country-4JS
W
Wxu-Next-Commit
Adler-Geo
ServedBy
X-Varnish-Beresp-Ttl
SD-X-WS
Section-Io-Cache
X-Cdn-Forward
NtCoent-Length
X-MSEdge-Features
X-MSEdge-Flight
Heartbleed
X-Owner
X-Release
X-ServiceProvider
X-LI-Proto
X-Qloud-Router
X-Logging-Id
X-Server-IP
X-Urbn-Site-Id
V-Age
X-Urbn-Context-Path
X-BBXSRF
X-Agile-Id
X-Vdms-Version
Pramga
X-Agile
X-Agile-Age
X-Bip
X-Swa-Ws
X-Thanos
Locale
X-Shopify-Generated-Cart-Token
X-Nc
Cache-Provider
X-Sucuri-Cache
X-Rocket-Build-Number
A
X-NodeID
X-Developer
X-Sigma-Backend
X-Internal-Host
Server-ID
X-Sigma
X-AK-Request-ID
Cdnsip
Cdncip
X-Sucuri-Id
CF-IPCountry
X-EC-Lua
X-Cdn-Origin
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
X-B3-Spanid
X-Sn-Servicetimems
X-Planisys-CDN-Rules
X-Servername
X-Dc
X-RCS-CacheZone
X-Upstream-Ht
X-Via-NSCOPI
X-Upstream-Ct
GEO-REGION-INFO
X-Node-Id
Powered-By-ChinaCache
X-Device-Os
X-Source
X-GRACE
Environment
X-Lb-Id
X-FPC
X-ND-Cache
X-Nginx-Cache
X-Servedbyhost
X-Zone
Geo-Info
X-Trafficlayer-App-Version
X-Be
X-VHOST
X-Microcachable
X-SRV
X-Newrelic-Synthetics
X-Tb-Optimization-Total-Bytes-Saved
Request-Time
Locid
X-Req
Tcn
X-DC
FNAC-ModuleRouting
Resin-Trace
X-Gamma-Serve
X-Pjax-Url
X-Served-From
X-NGENIX-Cache
X-VCL-Version
X-ECACHE
X-Instart-Info
X-Refresh
X-Oracle-Dms-Rid
X-ElasticPress-Search
ProcessTime
X-FORWARDED-FOR
X-TIME
X-Pf-Uncompressing
X-VWS-Id
X-Sucuri-ID
X-IPS-LoggedIn
X-AWS-Id
Group
X-LJ-Flow-ID
X-Backend-Url
X-Backend-Host
X-HTML-Minification-Powered-By
X-Dynatrace
Gannett-Cam-Experience-Id
X-Render-Time
X-GEO
Memory
Backend-Name
X-Var-Ttl
X-COUNTRY
CF-Cached-On
X-Unique-ID
X-Correlation-ID
X-NU-AKA-ACS-Version
X-Ratelimit-Remaining
GeoIP-City
GeoIP-Country-Code
GeoIP-Latitude
Pics-Label
Amp-Access-Control-Allow-Source-Origin
N-Cache
X-Bc
X-Pod
Pagetype
Lfy
M-TraceId
X-Check-Cacheable
Fly-Request-Id
Fly-Cache
PICS-Label
X-GeoIP-Country-Code
Cf-Ipcountry
Cache-Prefix
Ttl
TTL
X-Via-SSL
X-APP
X-Mode
X-CSRF-Token
X-Via-Edge
X-Worker
Geoip-City
Cdn
REQUESTUUID
GeoIp-Country-Code
Geoip-Latitude
SRV
Ohc-File-Size
XServer
Ohc-Cache-HIT
X-MP-GENERATED-AT
X-Upstream-CT
X-Upstream-HT
X-Via-Ucdn
X-Sedo-Request-Id
MIME-Version
X-LiteSpeed-Cache-Control
X-Cache-Miss-From
X-CLOUD-TRACE-CONTEXT
HitType
X-PF-Uncompressing
X-Server-W
X-Vcl-Version
X-Fetched-On
X-Fstrz
X-ZONE
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
Host-ID
X-Wa
HostName
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-From
X-Fastly-Country-Code
Fastly-SWR
Fastly-SIE
X-Ratelimit-Limit
X-Routing-Service
X-HS-Status
X-Proxied
X-Zipkin-Id
X-Dynatrace-Js-Agent
Pragrma
URI
User-Agent
On-Server
X-Cdn-Request-ID
X-PJAX-URL
X-Swift-Error
X-BC
X-HostName
X-BE
X-Cache-Tag
X-GDPR
X-TH-Server
X-NGINX-Cache
X-Aicache-OS
X-ServedByHost
X-WR-MODIFICATION
X-Tt-Trace-Tag
X-Ua
X-TT-LOGID
X-UPSTREAM-Address
Powered-By
X-Edge-Server
X-WA
Cdn-Request-Time
Cdn-Host
Who
X-RateLimit-Reset
CACHE
X-Fastly-Backend-Reqs
X-Cache-Ttl
X-Hello
Media-Length
X-ABtesting
X-Edge-O15-RID
X-Flog
X-Cf-Powered-By
X-SN
X-Request-Time
CDN
Dynatrace
X-Org
X-RPS
X-DB
SS
X-DSS
X-DW
X-LAGOON
X-LB-ID
X-Varnish-URL
X-DI
X-Action
X-Response-By
X-Varnish-Cacheable
X-RPM
X-Fpc
X-RSL
DataCenter
X-Upstream-Proxy
Debug
LB
X-ServerName
Get-Access-Time
Server-Id
SN
X-Ratelimit-Reset
Is-Session-Tracking
X-Ftr-Cache-Host
FSS-Proxy
X-Varnish-Beresp-TTL
Requestid
X-Gen-Id
X-Protected-By
FSS-Cache
X-Request-Url
XxX-Cache-Status
Cneonction
X-Nananana
NnCoection
X-Amzn-Remapped-Connection
X-Akamai-ERRuleID
X-Amzn-Remapped-Date
X-Dw-Trace-Id
X-Akamai-ERPolicy
X-LiteSpeed-Tag
RequestId
X-Page-Type
Warning
Thinkindot-Cache-Type
X-Li-Proto
X-Fastly-Cache-Hits
RequestUuid
Application
SID
Lb
Correlation-Id
Country-Code
Product