Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
Link
X-Powered-By
CF-Cache-Status
Pragma
ETag
CF-RAY
Expect-CT
Via
Age
X-Cache
X-XSS-Protection
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
X-Xss-Protection
P3P
Referrer-Policy
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-UA-Compatible
X-Served-By
Alt-Svc
X-Request-Id
X-Varnish
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Check
Content-Security-Policy-Report-Only
X-Adblock-Key
CF-Ray
X-Permitted-Cross-Domain-Policies
X-Generator
X-Cache-Status
X-Cacheable
X-DNS-Prefetch-Control
X-Kinja-Server-Push
Timing-Allow-Origin
X-Template
X-Language
X-FRAME-OPTIONS
X-Ua-Compatible
X-AspNetMvc-Version
X-Iinfo
Status
X-Buckets
X-Content-Security-Policy
X-CDN
Content-Encoding
Upgrade
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Envoy-Upstream-Service-Time
Keep-Alive
X-Via
X-Drupal-Dynamic-Cache
X-Ws-Request-Id
X-Server
X-Turbo-Charged-By
P3p
X-Backend
X-AH-Environment
X-Age
X-Cache-Group
X-Request-ID
X-Robots-Tag
Xkey
X-Proxy-Cache
Feature-Policy
Request-Context
X-Amz-Id-2
X-Amz-Request-Id
X-Hacker
X-Page-Speed
EagleId
X-UA-Device
X-Server-Powered-By
X-Nginx-Cache-Status
Grace
X-Pingback
X-Varnish-Cache
Server-Timing
X-LiteSpeed-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Report-To
Ali-Swift-Global-Savetime
X-Amz-Version-Id
X-WebKit-CSP
Cf-Railgun
X-Server-Id
X-Rq
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-OneAgent-JS-Injection
X-Origin-Cache
EagleEye-TraceId
X-Host
X-Device
Surrogate-Control
X-Response-Time
X-Vhost
X-Backend-Server
X-Dns-Prefetch-Control
X-Cache-Lookup
X-Ac
X-Node
X-Origin-Upstream-Status
X-Readtime
X-Dispatcher
X-HW
Fusion-Template-Id
Fusion-Source
Fusion-Content-Id
Fusion-Component-Id
Fusion-Content-Source
X-Pass-Why
Request-Id
X-DataDome
Content-Location
X-Mod-Pagespeed
X-Application-Context
X-ORACLE-DMS-ECID
X-Akam-SW-Version
NEL
X-ORACLE-DMS-RID
Fusion-Deployment-Id
X-Ruxit-JS-Agent
X-Country
Allow
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Rating
X-Country-Code
X-Clacks-Overhead
Edge-Control
X-Cnection
X-Cloud-Trace-Context
X-Px
X-Url
X-Rack-Cache
Accept-CH
X-FTR-Request-ID
X-Goog-Hash
RTSS
MS-Author-Via
X-PC
X-Vname
X-TtlSet
Accept-CH-Lifetime
X-Powered-By-Plesk
Verso
X-DynaTrace
Public-Key-Pins
X-B3-TraceId
Service-Worker-Allowed
X-GitHub-Request-Id
X-Kinja
X-Exp-Id
X-GoogleNews-Bot
X-Cdn-Fetch
X-Exp-Variant
X-Kinja-Build
X-Kinja-Server
X-Use-Magma
X-Kinja-Revision
X-Ttl
X-MS-InvokeApp
X-Amz-Server-Side-Encryption
X-Middleton-Display
Pagespeed
X-Middleton-Response
Response
X-Sol
Display
Arr-Disable-Session-Affinity
X-Varnish-TTL
X-Forwarded-Proto
X-Cache-TTL
X-D2id
Pinterest-Generated-By
X-CST
X-Amz-Rid
TCN
X-Cached
X-Abt-Application-Version
X-Vcap-Request-Id
X-NF-Request-ID
X-VARITI-CCR
X-Content-Type
X-Navigation-Version
X-Fastly-Request-ID
Cache-Tag
X-Instart-Request-ID
X-Server-Name
X-Accel-Expires
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-ESI
X-Version
X-MSEdge-Ref
AR-ATIME
AR-Request-ID
AR-PoweredBy
Access-Control-Request-Method
X-Grace
Nginx-Cache
X-FastCGI-Cache
Accept-Ch
Ar-Sid
AR-CACHE
S
Charset
X-Debug
X-Upstream
SPIisLatency
SPRequestDuration
X-Powered-CMS
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-SharePointHealthScore
SPRequestGuid
X-DynaTrace-JS-Agent
X-Client-IP
Content-MD5
Pinterest-Version
X-Pinterest-Rid
X-Ezoic-Cdn
Realpath
Accept-Ch-Lifetime
Nel
X-Trace
X-Element-Page-Cache
X-Mrf-Section-Lastmod
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Mrf-Item-Lastmod
X-Dw-Request-Base-Id
X-Hp-Webp
X-Jurisdiction
X-Id
X-Recruiting
X-Shield-Request-Id
X-Amz-Meta-S3cmd-Attrs
X-Node-Name
X-T
Fastcgi-Cache
X-ASPNET-VERSION
X-Kinsta-Cache
X-Content-Digest
X-XRDS-Location
X-Logged-In
X-NWS-LOG-UUID
X-Mobile-URL
X-Request-Received
X-Frontend
X-Request-Processing-Time
X-FTR-DC
X-FTR-Realm
Edge-Cache-Tag
X-Country-Code-Real
X-FTR-Backend-Server
Server-Node
X-FTR-Balancer
X-Cache-Hit
X-FTR-Cache-Status
X-FTR-Backend
X-Cache-Age
TP-L2-Cache
TP-Cache
X-Goog-Storage-Class
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-FTR-Expires
Front-End-Https
Server-Name
ServerID
DynaTrace
X-Forwarded-For
X-Hostname
X-Amzn-Trace-Id
X-Cache-Key
Fastly-Restarts
PB-PID
Arc-Version
X-Server-ID
PB-RID
X-Zen-Fury
Powered
X-DIS-Request-ID
X-TTL
X-Request-Handler-Origin-Region
X-Microsite
Backend-Timing
X-ATS-Timestamp
X-Content-Security-Policy-Report-Only
X-Revision
X-Mobile-Rewrite
X-User-Agent
X-Oneagent-Js-Injection
X-Cdn
X-Hits
X-LB-Cache
X-Akamai-Edgescape
X-HS-Combine-CSS
X-HS-Content-Id
X-F-Cache
X-Page-Id
X-HS-Hub-Id
X-HS-Cache-Config
Accept-Charset
X-Jobs
X-ORACLE-APMCS-TAG
Filters
X-ORACLE-APMCS-REQUEST-ID
X-FTR-Cache-Host
X-Content-Powered-By
AMP-Access-Control-Allow-Source-Origin
X-Via-JSL
X-Geo-Country
MicrosoftSharePointTeamServices
X-Yandex-Sdch-Disable
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Origin-Server
X-Correlation-Id
X-Varnish-Age
X-B
X-N
Alternate-Protocol
X-Ser
X-Rid
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Daa-Tunnel
X-Varnish-Backend
Host-Header
X-Esi
X-Az
X-WebKit-CSP-Report-Only
DC
X-Activity-Id
X-ATG-Version
X-AppVersion
Cache-Tags
X-Amz-Replication-Status
Paypal-Debug-Id
X-App-Server
Actual-Object-TTL
X-Debug-Info
Retry-After
Frame-Options
X-Git-Hash
X-FB-Debug
X-Type
Section-Io-Cache
X-Varnish-Grace
X-App-Environment
X-B-Cache
X-TT
X-Contextid
X-Signature
X-Whom
X-Fastcgi-Cache
X-Request-Guid
X-Edge
Surrogate-Key
X-Status
Fastcgi-Useragent
X-AOL-HN
X-Content-Options
Host
Healthy
X-XRDS-LOCATION
X-Cache-Action
X-Seen-By
X-Ruxit-Js-Agent
Source
X-Pinterest-Direct
X-Host-Name
Refresh
X-RateLimit-Remaining
X-HTML-Minification-Powered-By
X-IPLB-Instance
X-B3-Sampled
X-Endurance-Cache-Level
X-Instance
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel
X-Upgrade-Enabled
From-Origin
X-ECACHE
Access-Control-Allow-Method
X-RemovedCookies
X-Response-Served-From
X-ProcessESI
X-Cache-Rule
X-Accel-Buffering
NR-ENABLED
X-Cache-Operation
WPE-Backend
X-Drupal-Cache-Tags
X-MCACHE
X-Rule
X-Amz-Apigw-Id
X-Region
VIX-Pulpo-Upstream-Status
Odigeo-Trace-Id
X-Mid
VIX-Pulpo-Node
X-Cacheable-TTL
X-UUID
MS-CV
Payment
X-Environment-Context
Eomportal-Instance
X-L-Path
X-Cache-Control
X-FW-Serve
X-FW-Type
X-FW-Dynamic
X-FW-Static
X-Amzn-RequestId
X-FW-Server
Datacenter
X-Rendered-As
X-Cache-Time
X-Varnish-Server
X-FW-Hash
Cache-Status
X-Is-Bot
X-Adobe-Loc
X-Adobe-Content
Countrycode
X-URL
X-WA-Info
Xserver
Srv
X-Protected-By
X-APP-VERSION
X-GeoIP
NGB
Content-Disposition
X-Wix-Request-Id
X-SERVER-NAME
X-Cluster
X-RequestSource
X-Akamai-Transformed
X-PressLabs-Stats
X-EdgeConnect-Cache-Status
X-Cached-By
X-Time
X-Cache-Server
X-Yottaa-Optimizations
X-VCache
X-Akamai-Request-ID2
X-Yottaa-Metrics
X-UnsetCookies
Uber-Trace-Id
X-Tt-Trace-Host
Version
X-Origin-Response-Time
X-Tt-Trace-Tag
X-Tumblr-Pixel-2
X-IPS-LoggedIn
X-Tumblr-Pixel-1
X-Unique-Id
X-Mode
X-Load-Cache
X-Mobile
Filterid
X-Proxy
X-Presslabs-Stats
X-Correlation-ID
X-Handled-By
Access-Control-Request-Headers
X-PHP-Backend
X-Cache-Remote
Liferay-Portal
X-FireWall-Port
Meta-Geo
Cross-Origin-Window-Policy
X-Framework
X-Adobe-Source
X-Path-Route
Accept-Language
X-Cache-Var
X-Cache-Var-Map
X-CCM
X-UA-Device-Type
X-Cache-Status-Check
X-Backend-Name
X-Via-Fastly
X-RN-RSRV
X-Viewer-Country
X-No-Session
X-ES-SERVER
DSUID
Decoy-Debug-TTL
X-LJ-Flow-ID
X-MP-GENERATED-AT
Decoy-Debug-Key
X-Www-Served-By
Decoy-Debug-Status
X-VWS-Id
X-Locale
Upgrade-Insecure-Requests
X-Time-Microsecs
Fastly-SSL
X-AWS-Id
X-OCL
X-ApacheServer
Cache-Hits
X-NGENIX-Cache
ServedBy
X-Redis-Cache
X-PCL
Akamai-GRN
X-Azure-Ref
X-Site-Version
X-Storage
X-Pubstack
X-PERF
Cache-Name
X-Cache-NGX
X-FW-Version
X-Real-IP
X-R9-Blue-Green-Version
X-NCache
X-Info
X-RTag
X-Say-Cacheable
X-TX-ID
X-SayCDN-TTL
X-Say-TTL
X-Web-Node
X-Human
X-Cache-Config
Origin-Edge-Control
Origin-Cache-Control
Now
Ms-Operation-Id
Section-Io-Id
Section-Io-Origin-Status
Webserver
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Cleartype
Mn-Server-Ip
Cache
X-Hyper-Cache
TWC-Locale-Group
X-Loop
X-Origin
X-Proxied
X-Origin-Hint
X-Hl-Ver
X-Bc-Bl
X-Device-Type
X-BYPASS-REASON
X-CS
Property-Id
X-FC-Vary-Parameters
S-Rt
X-Format
X-Cache-Enabled
X-Access
TWC-GeoIP-Country
TWC-Device-Class
TWC-Connection-Speed
X-TNCMS
TWC-GeoIP-LatLong
X-UPSTREAM-Address
X-Zipkin-Id
X-Xfnlog-Site
TWC-Privacy
Webcakes-App-Name
X-Section
X-Routing-Service
X-ProxyCache-Key
X-ProxyCache-Status
Webcakes-App-Version
X-ServerID
Webcakes-Region
X-Amzn-Remapped-Content-Length
X-BCube-Filmed-By
X-Alternate-Cache-Key
X-NWS-UUID-VERIFY
X-Shopify-Stage
X-ShopId
X-ShardId
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Vcache
X-Timing-Wait
X-SaId
X-Proxy-Build
X-Generated
X-From
X-EIG-Tracking-Id
X-Goog-Meta-Goog-Reserved-File-Mtime
X-IP
X-NYM-Debug-Backend
X-JoinUs
X-Detected-As
X-FB-TRIP-ID
Ec-Rule-Version
Selected-Fe
DB-Nickname
Azure-RegionName
X-Source
Azure-SlotName
Azure-Version
Country
X-Varnish-Cache-Hits
X-Geo
X-CSRF-Token
Azure-InstanceId
X-Hosted-By
Azure-SiteName
Load-Balancing
X-Content-Age
X-Cluster-Node
X-PHP-Host
X-Qloud-Router
X-Labrador-Cache-Channel
X-Old-Content-Length
SD-X-WS
X-Cache-NE
Cache-Tv-Group
X-NewRelic-App-Data
X-Air-Hostname
User-Agent
X-Varnish-Hostname
X-Litespeed-Cache
X-Cache-Host
Time
X-Pad
FilterID
X-CDN-Forward
X-Backend-TTL
X-Cache-TTL-Remaining
X-Drupal-Cache-Contexts
X-Ua
X-Parent-Response-Time
S-Cnection
X-Cache-2
X-Release
X-Cache-Backend
X-RCS-CacheZone
X-Urbn-Context-Path
X-EC-Lua
X-Urbn-Site-Id
Locale
X-Webkit-CSP
Server-Info
X-Proxy-Cache-Status
X-Akamai-Request-ID
X-RateLimit-Limit
X-Cache-Grace
X-Microcachable
X-Forwarded-Host
X-Tumblr-Pixel-3
X-NC
X-Debug-Cache
NGX
Proxy-Connection
X-FORWARDED-FOR
Tracecode
X-SRV
OT-Force-Account-Verify
X-UA
X-Soup
Sid
X-Tb
X-Ah-Environment
X-A-Dgt
X-Processor
X-Instart-Info
X-A-Dcw
X-Aed
X-Uri
X-A-Wwc
X-Accel-Expires-Debug
X-NodeID
X-Ms-Version
X-PAYTM-SRV-ID
Apigw-Requestid
X-Ms-Request-Id
X-Proto
X-Level-Front-Cache
X-Application
X-D
M-TraceId
Machine
MD5-Digest
True-Client-Country-4JS
X-Date
Viewtype
UCS
X-B-Cookie
T-Server
X-Connection-Hash
Rendered-Blocks
X-CF-Lambda-Fn
X-CF-Lambda-Version
Server-Host
ServerName
Meta-Geo-Continent
Mobile-Detection-Method
Pagetype
VivaBuild
X-Destination
Content-Style-Type
X-G
X-A-Dam
Content-Script-Type
X-Generated-On
AsisCache
BehaviorPad-Version
X-Geo-Header
X-A-Ccd
X-A
X-Dispatch
X-DevSite-Last-Modified
X-Developer
GEO-REGION-INFO
Who
Fastcgi-X-Cache-Version
X-ARC
X-External-Request-Id
Arc-Country
X-S
X-Vtex-Processado-Em
X-ScT
X-Vgn-Hpd-Reason
X-Scheme
X-Vtex-Remote-Cache
X-Rojux
X-SRCache-Key
GEO-INFO
X-Vdms-Path
X-VG-WebServer
X-Session-Fingerprint
X-VG-WebCache
X-ServiceProvider
X-Transaction
X-Vdms-Version
X-Rewrite-Enabled
X-S-Cookie
X-Cluster-Name
Cache-Key
X-Reqid
Xc-Version
X-Trv-Group
X-Region-Sid
X-Srv
X-Trace-Id
X-Twitter-Response-Tags
X-Swa-Ws
X-Magnolia-Registration
User-Cache-Control
X-Device-Os
N-Cache
X-User
NM-Fastcgi-Cache
On-Server
X-Cms-Context
Kp-EeAlive
X-VC-Cache
Mail-Subject
Magicmarker
X-Core-Value
Memcached
X-TT-TIMESTAMP
IsBot
X-Clara-WADP
X-Block-Status
Vix-Hermes-Req-Id
We-Hiring
X-WADP-Cache
Viewport
V-Age
Web-Mar-Node
X-Wikidot-Backend
X-Agile-Age
X-Worker
X-Wikidot-Static-Cache
X-Agile-Id
X-Dc
Thinkindot-Control
X-Cache-Bucket
X-Cache-FS-Status
X-Cache-Info
X-Via-PopH
X-Branch-Name
X-Via-PopV
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-VServer
X-Bip
Release
X-Dispatcher-Server
X-Request-UUID
X-Owner
X-SN
X-Generation-Time
X-Micro-Cache
X-TA-CDN-Provider
X-Skip-Cache
X-SIPLIST1
X-Agile
X-Node-Id
AKAMAI
X-Hnp-Log
X-Hash
X-LAGOON
X-Method
X-Generated-In
X-Matched-Rule
CDCHOST
FNAC-ModuleRouting
X-Logging-Id
X-Location
X-Reboot
X-Gen-Mode
X-SD-PageType
X-Thinkindot-L3
X-Thanos
X-Fmm-Version
X-Newrelic-Synthetics
X-Envoy-Decorator-Operation
X-DC
Cf-Ipcountry
Geo-Info
X-Cache-PHP
X-Mvc-Supplant-Cachable
X-Nginx-Cache-Key
X-Webstats-RespID
X-Policy
X-Request-Host
X-Req
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Platform-Server
X-Backend-Host
X-Auto-Login
X-Origin-Date
X-Origin-Expires
X-We-Are-Hiring
X-Response-By
X-JWT-State
X-Varnish-Cacheable
X-Variation
X-GoCache-CacheStatus
X-Slack-Backend
X-Has-Esi
X-VG-TLSProxy
X-Fastly-Cache
X-Eu-Site
X-Distil-CS
X-Distributor
X-TrackingId
X-Epic-Correlation-Id
X-Developers
X-Hit
X-Clientip
X-LI-UUID
X-Li-Pop
X-Servername
X-BBXSRF
X-Server-W
X-Li-Fabric
X-Envoy-Upstream-Healthchecked-Cluster
X-Irp-Debug
X-CGP
X-Is-Gdpr
X-Cache-URL
X-Cache-Tags
X-Backend-State
Wxu-Next-Hostname
X-TIME
Apple-News-Services-Handled
RNT-Machine
RNT-Time
Cache-Cookie-Set-From
Rt-Fastcgi-Cache
Apple-News-Services-Host
Is-Eu
Apple-News-Services-Request-Url
C-Via
L5d-Success-Class
Platform
Apple-News-Services-Parsed-Url
Adler-Geo
HA-Ipaddr
Esi-Enabled
Gh-Request-Id
Wxu-Next-Commit
Fastly-Drupal-HTML
Wxu-Next-Region
Node
Cache-Cookie-Set-Lfrom
Server-Hostname
Server-Ext
Ha-Gx-Prefs
Cache-Cookie-Set-Idcheck
Sever-Int
X-Rebelmouse-Cache-Control
Fastly-SIE
X-Core-Mission
L
X-Var-Ttl
X-Cache-ASPX
X-App
W
X-Rebelmouse-Surrogate-Control
X-LI-Proto
Server-ID
X-Varnish-Authentication
CacheControlHeader
Fastly-SWR
X-Contensis-Viewer-Groups
X-Server-IP
X-App-Name
Cache-Host
Ohc-File-Size
X-Compress-Hint
X-CLOUD-TRACE-CONTEXT
X-Nc
X-Be
X-Refresh
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-TH-Server
X-VCT
X-Wa
X-Loc
X-Cdn-Srv
X-Gzip
X-Mvc-Supplant-OutputCached
X-Cache-Debug
X-Cache-Id
X-Esi-Check
X-Origin-TTL
LB
X-AIR-PT
X-S-Maxage
X-Origin-CC
X-Bc
Server-Surrogate-Control
Server-Cache-Control
X-Configured-By
X-Generated-By
Memory
X-Sucuri-ID
X-Zone
HostName
X-B3-Traceid
X-SVT-ORM-VERSION
X-Storefront-Renderer-Rendered
Ohc-Response-Time
X-NU-AKA-ACS-Version
NtCoent-Length
X-SVT-ORM-RULES
X-FPC
X-Key
X-App-Version
X-BC
X-ZONE
X-Rocket-Nginx-Bypass
X-Varnish-Ttl
X-MSEdge-Flight
X-Edge-Location
X-MSEdge-Features
CACHE
MIME-Version
X-Debug-Panamera-Sitecode
Request-Country
X-Svr
Pragrma
Heartbleed
X-Varnish-URL
Locid
Request-EU
X-Debug-Panamera-Host
X-CF-Powered-By
X-Varnish-Hits
X-Request-URI
X-COUNTRY
X-Servedbyhost
X-Pjax-Url
X-Nginx-Cache
X-Cdn-Forward
X-Shopify-Generated-Cart-Token
Referer-Policy
X-VCL-Version
Fastly-Backend-Name
X-Batcache
Resin-Trace
SRV
WZWS-RAY
X-Up
FSS-Cache
X-GEO
X-Gamma-Serve
X-BACKEND-TTL
X-Minions-Version
Hostname
X-BE
X-Ratelimit-Remaining
X-Via-CDN
X-Aicache-OS
X-Amzn-Requestid
Geoip-Latitude
X-CACHE-KEY
X-ND-Cache
X-ElasticPress-Query
Lfy
GeoIp-Country-Code
GeoIP-Country-Code
X-WebServer
Cteonnt-Length
X-Sucuri-Cache
Product
CF-Cached-On
GeoIP-Latitude
X-Proxy-Upstream
HitType
X-Cdn-Origin
Mime-Version
X-Fetched-On
Cdn-Host
X-ECache
Powered-By-ChinaCache
X-Sn-Servicetimems
My-App
Cdn-Request-Time
X-Edge-Server
X-Check-Cacheable
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Oss-Storage-Class
X-Oss-Request-Id
X-Oss-Server-Time
X-PJAX-URL
X-HS-Status
X-Vcl-Version
DCR-Processing-Time-Ms
DCR-Decision-By
X-NGINX-Cache
Ohc-Cache-HIT
X-GeoIP-Country-Code
X-CSRF-TOKEN
X-Fastly-Cache-Status
X-Fastly-Country-Code
Location
X-PF-Uncompressing
X-ServedByHost
Pramga
X-Azure-Ref-OriginShield
SN
X-Unique-ID
X-Newrelic-App-Data
X-Pf-Uncompressing
Amp-Access-Control-Allow-Source-Origin
X-Varnish-Url
X-Ratelimit-Limit
X-LB-ID
X-Fastly-Backend-Reqs
Group
X-Served-From
X-Request-Start
X-CACHE-AGE
URI
Cdn
X-Fpc
X-B3-Spanid
Dt-Cache-Category
PFcat
X-OVcl
X-OVcl-Cache
X-VarnishDD-TTL
X-Shard
X-Via-Ucdn
X-Vgn-Hpd-Ssi
X-Vgn-Hpd-Variations-Key
XServer
X-Vgn-Hpd-Cached
X-Swift-Error
X-Render-Time
X-B3-SpanId
X-Request-Time
CloudFront-Viewer-Country
X-Instart-Isnd
X-Platform
Country-Code
X-IN-APIGATEWAYSSL
A
X-IN-APIGATEWAY
X-Tec-Api-Root
X-Tec-Api-Version
X-Via-NSCOPI
Cf-Alt-Svc
X-Tec-Api-Origin
X-Ratelimit-Reset
X-Varnishpool
X-Client-Ip
X-Ocache
X-DPWN-IS-SECURE
WWW-Authenticate
Geoip-City
X-Cache-Expired-At
X-Debug-Cache-Store
Origin
X-Varnish-Beresp-TTL
X-Tb-Optimization-Total-Bytes-Saved
X-Debug-Cache-Fetch
X-WR-MODIFICATION
Lb
X-WPE-Loopback-Upstream-Addr
X-Debug-Cache-String
X-StackifyID
X-Debug-Cache-Bypass
X-C
X-Debug-Do-Not-Cache-Uri
Server-Ttl
X-LiteSpeed-Cache-Control
X-Debug-Ysi-Auth
PICS-Label
Cloudfront-Viewer-Country
X-Debug-Xas-Auth
X-Debug-Cache-Status
X-Apw-Access-Token
X-Apw-Hits
X-Planisys-CDN-Rules
X-Apw-Access-Object
X-Apw-Access-Action
X-Planisys-CDN-TTL
SID
X-Planisys-CDN-Cache
X-WA
CF-IPCountry
X-Ftr-Cache-Host
X-Amzn-Remapped-Date
Request-Time
Cneonction
X-Rocket-Build-Number
Region
X-Cache-Hm
X-Acquia-Site
X-Amzn-Remapped-Connection
X-Cache-Hfrom
X-Acquia-Application-UUID
NnCoection
X-Cache-Tag
Epwk-X-Cache
X-Sigma
X-CUA
X-Acquia-Purge-Tags
Host-ID
X-Acquia-Application-Trace
Proxy-Firewall
X-Sigma-Backend
X-Country-IP
X-Nananana
X-APP
X-Akamai-ERPolicy
Pics-Label
X-Oss-Cdn-Auth
X-Html-Edge-Cache
X-Varnish-ID
X-Li-Proto
X-DW
X-B3-Parentspanid
Req-ID
X-RSL
X-RPS
X-RPM
X-ElasticPress-Search
X-Request-URL
X-VC
TTL
X-Action
X-SB
X-Dw-Trace-Id
X-DSS
X-DI
X-DB
X-Akamai-ERRuleID