Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-RAY
CF-Cache-Status
Accept-Ranges
Link
Pragma
ETag
X-XSS-Protection
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
Alt-Svc
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Xss-Protection
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Request-ID
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
P3p
X-FRAME-OPTIONS
X-Content-Security-Policy
X-Iinfo
Status
Content-Encoding
Feature-Policy
X-AspNetMvc-Version
X-CDN
X-Envoy-Upstream-Service-Time
Upgrade
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Access-Control-Max-Age
X-Via
Keep-Alive
X-Dns-Prefetch-Control
Request-Context
X-Robots-Tag
Server-Timing
X-Ws-Request-Id
X-AH-Environment
X-Server
X-Ua-Compatible
X-Hacker
X-Age
X-Turbo-Charged-By
X-Server-Powered-By
X-Proxy-Cache
X-Cache-Group
X-Backend
Host-Header
X-Nginx-Cache-Status
EagleId
X-Amz-Request-Id
X-Amz-Id-2
Report-To
X-LiteSpeed-Cache
X-Rq
X-Varnish-Cache
X-UA-Device
Grace
X-Page-Speed
X-Swift-CacheTime
X-Swift-SaveTime
X-Pingback
Ali-Swift-Global-Savetime
X-Device
EagleEye-TraceId
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Cf-Railgun
X-Vhost
X-Amz-Version-Id
X-Server-Id
NEL
X-OneAgent-JS-Injection
X-Host
X-Dispatcher
X-CST
X-Node
Allow
Surrogate-Control
X-Cache-Spec
Request-Id
X-Backend-Server
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Accept-CH
X-WebKit-CSP
X-Readtime
X-Response-Time
X-Akam-SW-Version
X-Webkit-CSP
Xkey
X-HW
X-Country
X-Ac
X-Application-Context
Content-Location
X-Language
Accept-Ch-Lifetime
X-Template
MS-Author-Via
X-Cloud-Trace-Context
Rating
X-Url
X-Ruxit-JS-Agent
X-Cache-Lookup
X-Mod-Pagespeed
X-B3-TraceId
Edge-Control
X-PC
X-TtlSet
X-Vname
X-Clacks-Overhead
X-ESI
X-MS-InvokeApp
X-Trace
X-Varnish-TTL
Accept-CH-Lifetime
X-GitHub-Request-Id
X-Content-Type
Fastly-Restarts
X-ASPNET-VERSION
X-Cnection
X-Rack-Cache
X-Origin-Cache
X-D2id
X-Country-Code
X-Use-Magma
X-Kinja
X-GoogleNews-Bot
X-Exp-Variant
X-Exp-Id
X-Kinja-Build
Verso
X-Kinja-Server
X-Kinja-Revision
Arr-Disable-Session-Affinity
X-Cdn-Fetch
X-Goog-Hash
X-VARITI-CCR
X-FastCGI-Cache
X-Server-Name
X-Vcap-Request-Id
X-Cached
X-Navigation-Version
Cache-Tag
X-Powered-By-Plesk
X-Buckets
X-Client-IP
X-Amz-Rid
X-Abt-Application-Version
Service-Worker-Allowed
X-ORACLE-DMS-ECID
Accept-Ch
X-Fastly-Request-ID
RTSS
X-Middleton-Response
X-Sol
Pagespeed
X-Middleton-Display
Response
Display
X-Cache-TTL
Access-Control-Request-Method
X-MSEdge-Ref
X-Element-Page-Cache
X-Powered-CMS
X-Ttl
X-NF-Request-ID
Public-Key-Pins
X-Dw-Request-Base-Id
X-Upstream
X-Version
X-SRCache-Fetch-Status
X-SRCache-Store-Status
S
X-Edge
X-Kinsta-Cache
X-Px
X-LLID
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-TTL
X-Edge-Location-Klb
X-Ruxit-Js-Agent
Realpath
X-Oneagent-Js-Injection
SPRequestDuration
SPIisLatency
X-Accel-Expires
X-ECACHE
SPRequestGuid
X-SharePointHealthScore
X-T
X-HP-Webp
X-Jurisdiction
X-MCACHE
X-Mid
X-PressLabs-Stats
X-Forwarded-Proto
X-Content-Security-Policy-Report-Only
X-Shield-Request-Id
X-Kraken-Loop-Name
X-Correlation-Id
X-Kraken-Routeconfig-Destination
X-Instrumentation
X-Server-Lifecycle-Phase
Charset
X-Recruiting
Edge-Cache-Tag
X-DynaTrace
X-Mg-S
X-Release
TP-Cache
TP-L2-Cache
Fastcgi-Cache
Pinterest-Generated-By
X-Pinterest-Rid
Pinterest-Version
X-Amz-Server-Side-Encryption
X-Ezoic-Cdn
X-Content-Digest
X-Id
Filters
X-Request-Processing-Time
X-Server-ID
X-Request-Received
X-Cache-Key
Nginx-Cache
X-ORACLE-DMS-RID
Server-Node
Alternate-Protocol
Front-End-Https
X-Logged-In
Cache-Tags
Content-MD5
TCN
X-Forwarded-For
X-Origin-Upstream-Status
X-XRDS-Location
X-Litespeed-Cache
Server-Name
Fusion-Content-Id
Fusion-Component-Id
Fusion-Content-Source
Fusion-Template-Id
Fusion-Source
Fusion-Deployment-Id
X-Amzn-Trace-Id
X-Grace
X-Origin-Server
X-Hostname
X-Geo-Country
X-Contextid
X-F-Cache
X-Amz-Replication-Status
X-Rid
X-Activity-Id
X-Az
X-Protected-By
X-Goog-Stored-Content-Length
X-AppVersion
X-GUploader-UploadID
Host
X-Goog-Generation
X-Goog-Stored-Content-Encoding
Cleartype
X-Goog-Storage-Class
X-Goog-Metageneration
X-Www-Served-By
X-HS-Cache-Config
X-HS-Hub-Id
X-WebKit-CSP-Report-Only
X-HS-Content-Id
X-HS-Combine-CSS
X-RateLimit-Remaining
X-Frontend
Section-Io-Cache
X-Debug-Info
X-LB-Cache
X-Browser-Type
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
Ar-Sid
AR-ATIME
AR-PoweredBy
AR-Request-ID
AR-CACHE
MicrosoftSharePointTeamServices
X-Ser
X-Page-Id
X-Aspnetmvc-Version
X-Git-Hash
X-NWS-LOG-UUID
X-Cache-Age
X-XRDS-LOCATION
Accept-Charset
X-Upgrade-Enabled
X-Respond-Thread
X-Source
X-VCache
X-Varnish-Age
X-Hits
X-Content-Options
X-Fastcgi-Cache
X-DIS-Request-ID
X-Tec-Api-Root
X-Tec-Api-Origin
X-Tec-Api-Version
Paypal-Debug-Id
X-Mobile-URL
ServerID
X-Varnish-Backend
X-CACHE-GROUP
X-B-Cache
X-Varnish-Grace
X-Signature
Access-Control-Allow-Method
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Providence-Cookie
X-Is-Crawler
X-Request-Guid
X-Flags
X-Route-Name
Viewport
X-Cache-Action
Payment
X-FB-Debug
X-Aspnet-Duration-Ms
X-B3-Sampled
X-TT
Healthy
X-Daa-Tunnel
X-Whom
X-Request-Handler-Origin-Region
X-Microsite
X-N
Node
X-AOL-HN
X-App-Environment
X-Seen-By
Version
X-Type
X-Load-Cache
Fastcgi-Useragent
DC
MS-CV
X-Mobile
DynaTrace
X-Yandex-Sdch-Disable
X-Cache-Expired-At
X-Ab
X-HTML-Minification-Powered-By
Filterid
X-Distributor
X-Cache-Control
SRV
Retry-After
X-IPLB-Instance
X-Tt-Trace-Host
X-Tt-Trace-Tag
Frame-Options
X-Response-Served-From
X-Original-Request-Id
Nel
X-Instance
X-UUID
X-Real-IP
X-User-Agent
NGB
X-ProcessESI
X-Proxy-Cache-Status
X-Tumblr-Pixel
X-Tumblr-User
X-Varnish-Server
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-IPS-LoggedIn
X-RemovedCookies
X-Adobe-Loc
X-Debug-IsPreview
X-Device-Type
X-Jobs
X-Region
X-Content-Powered-By
X-Cluster-Name
Ms-Operation-Id
X-Adobe-Content
X-RTag
Access-Control-Request-Headers
X-Debug-IsConnected
X-FireWall-Port
Uber-Trace-Id
Refresh
VIX-Pulpo-Node
X-B
X-Page-View
X-Cache-Time
VIX-Pulpo-Upstream-Status
X-Proxy
X-Cacheable-TTL
X-Debug
X-Framework
X-Accel-Buffering
X-G
Cache
X-Wix-Request-Id
X-FW-Type
X-FW-Static
X-FW-Dynamic
X-FW-Server
X-FW-Serve
X-FW-Hash
X-Zen-Fury
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
Section-Io-Id
Countrycode
X-Vgn-Hpd-Reason
X-Time
X-Oracle-Dms-Rid
Cache-Status
X-RateLimit-Limit
X-NGENIX-Cache
X-Nginx-Cache
X-Mg-Request-UUID
X-Cache-Hit
Surrogate-Key
X-Azure-Ref
X-App-Version
Country
X-Is-Bot
X-Rendered-As
X-CDN-Forward
X-Drupal-Cache-Tags
S-Cnection
X-App-Server
X-EdgeConnect-Cache-Status
X-Ms-Request-Id
X-Ms-Version
Eomportal-Instance
X-Cache-Rule
X-TA-CDN-Provider
X-Node-Name
Referer-Policy
SD-X-WS
Liferay-Portal
X-Drupal-Cache-Contexts
X-L-Path
X-Environment-Context
X-Proxy-Build
X-Timing-Wait
X-RN-RSRV
Meta-Geo
X-JoinUs
X-Cache-Operation
X-UPSTREAM-Address
X-Tumblr-Pixel-2
X-ES-SERVER
Selected-Fe
X-SaId
X-Request-Time
X-S-Maxage
Protected
Amp-Access-Control-Allow-Source-Origin
Azure-Version
Azure-RegionName
X-GG-Cache-Date
X-Endurance-Cache-Level
X-Cache-TTL-Remaining
X-Backend-Host
X-Cache-Server
X-Alternate-Cache-Key
Azure-SiteName
From-Origin
Azure-InstanceId
X-Loop
Azure-SlotName
X-Pubstack
X-Storefront-Renderer-Rendered
X-Xfnlog-Site
X-TNCMS
X-ShopId
X-Yottaa-Metrics
X-ShardId
CF-IPCountry
X-Via-Fastly
X-Varnish-Hostname
X-PHP-Backend
X-Varnishpool
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Yottaa-Optimizations
X-Shopify-Stage
X-No-Session
Webcakes-App-Version
Akamai-GRN
TWC-Connection-Speed
Cache-Name
Webcakes-Region
X-LJ-Flow-ID
X-LAGOON
X-AWS-Id
X-VWS-Id
Cache-Tv-Group
Webcakes-App-Name
Property-Id
X-Proto
ServedBy
TWC-Device-Class
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Privacy
TWC-Locale-Group
Fastly-SSL
X-R9-Blue-Green-Version
X-Adobe-Source
X-ProxyCache-Key
X-PCL
X-Be
X-Origin-Hint
X-ProxyCache-Status
X-Handled-By
X-OCL
X-Server-W
X-BYPASS-REASON
X-NYM-Debug-Backend
Decoy-Debug-TTL
Decoy-Debug-Status
Decoy-Debug-Key
X-SayCDN-TTL
X-Say-Cacheable
X-Origin-Date
X-Hl-Ver
X-Rule
X-Status
X-Format
X-Varnish-Beresp-Grace
Country-Code
Apigw-Requestid
X-Human
X-Backend-Name
X-Access
X-Section
X-Say-TTL
X-RCS-CacheZone
X-ApacheServer
X-Labrador-Cache-Channel
X-Sql-Duration-Ms
X-PHP-Host
X-UA-Device-Type
X-FB-TRIP-ID
X-Sql-Count
X-PERF
X-Cache-PHP
X-Akamai-Edgescape
Xserver
Mn-Server-Ip
AMP-Access-Control-Allow-Source-Origin
X-Uri
X-Hosted-By
X-Hyper-Cache
X-Revision
X-Redis-Cache
X-Webkit-Csp
X-Web-Node
X-Ua-Device
X-Trace-Id
X-B3-SpanId
X-WA-Info
X-MP-GENERATED-AT
X-FW-Version
X-ATG-Version
X-Cache-Type
X-Content-Age
X-Cached-By
X-Time-Microsecs
X-CSRF-Token
X-ServerID
X-Dc
X-Tumblr-Pixel-3
X-Aws-Lambda-Call-Status
X-Cache-Enabled
X-Edge-Location
Backend
X-Soup
X-Akamai-Transformed
X-TT-LOGID
X-Mode
X-CS
X-Datadome
X-APP-VERSION
X-Parallel-Accel
X-Microcachable
X-Info
X-Detected-As
X-Bc-Bl
X-Varnish-Cache-Hits
X-Azure-Ref-OriginShield
X-Cluster-Node
Count-Hit
X-Cache-Host
GEO-INFO
X-SRV
X-Cache-NGX
Web-Mar-Node
X-Generation-Time
OT-Force-Account-Verify
X-Varnish-Beresp-Status
X-Varnish-Hits
Who
X-Debug-Cache
X-Proxied
X-Storage
X-Amzn-RequestId
X-Routing-Service
X-Amz-Apigw-Id
X-Amzn-Remapped-Content-Length
Cross-Origin-Opener-Policy
X-Zipkin-Id
X-Platform
X-Varnish-Beresp-Ttl
X-Servername
X-Extlb
X-B3-Traceid
DataCenter
X-Unique-ID
X-Via-JSL
X-Origin-TTL
Server-Info
X-Locale
X-Origin-CC
Rendered-Blocks
X-PBS-Appsvrname
X-Air-Trace-Id
X-Epic-Correlation-Id
X-Proxy-Upstream
X-ARC
X-B-Cookie
X-BCube-Filmed-By
X-Ratelimit-Reset
X-Air-Hostname
X-Air-Source
Fastly-Backend-Name
Fastcgi-X-Cache-Version
X-Processor
X-Magnolia-Registration
X-PAYTM-SRV-ID
X-External-Request-Id
X-A-Dgt
BehaviorPad-Version
CDN-Uid
X-VG-WebCache
Apple-News-Services-Request-Url
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
CDN-RequestId
CDN-RequestCountryCode
CDN-Cache
CDN-CachedAt
CDCHOST
CDN-PullZone
X-Location
Apple-News-Services-Handled
Content-Disposition
X-A-Wwc
X-A-Dcw
Expiry
X-Aed
X-Aicache-OS
X-NAPM-TraceId
X-A-Dam
X-A
A
DCR-Decision-By
X-A-Ccd
DCR-Processing-Time-Ms
X-Application
SID
X-CF-Lambda-Fn
Meta-Geo-Continent
X-From
X-CF-Lambda-Version
Odigeo-Trace-Id
Mobile-Detection-Method
X-Sucuri-ID
X-SRCache-Key
X-TEC-API-VERSION
X-TEC-API-ROOT
State
MD5-Digest
X-Request-URI
X-DataDome
X-Cms-Context
X-VG-WebServer
X-Destination
X-Vdms-Path
X-Vdms-Version
Req-Svc-Chain
X-Geo-Header
X-D
X-Core-Value
X-Connection-Hash
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
X-Developer
X-TEC-API-ORIGIN
X-Cache-NE
X-Service
CDN-EdgeStorageId
X-Cache-Bucket
X-ScT
X-S-Cookie
X-Rewrite-Enabled
X-S
T-Server
Host-ID
M-TraceId
X-Rojux
X-Session-Fingerprint
Surrogated-Key
X-Tb
X-CACHE-KEY
Upgrade-Insecure-Requests
X-Level-Front-Cache
Server-Host
X-Generated-On
PFcat
X-JWT-State
Pics-Label
Fastly-SIE
Fastly-SWR
Fastly-Drupal-HTML
X-Is-Gdpr
Gh-Request-Id
Cmsid
Origin
Memcached
Esi-Enabled
Location
X-HN
Fastcgi-Cache-TTL
X-Has-Esi
UCS
L
Kp-EeAlive
Path
Pagetype
X-Hash
X-Gamma-Serve
X-GoCache-CacheStatus
Cmstype
X-Platform-Server
X-Branch-Name
X-Scheme
X-AIR-PT
X-Sigma
X-Varnish-Ttl
X-Envoy-Decorator-Operation
X-Bip
X-Request-UUID
X-VHOST
CacheControlHeader
X-Sigma-Backend
X-Cache-Debug
X-Varnish-Url
X-VarnishDD-TTL
X-Date
X-VG-TLSProxy
X-EC-Lua
X-Developers
X-Thanos
X-TrackingId
X-Clientip
X-Var-Ttl
X-Req
X-Rocket-Build-Number
X-Minions-Version
X-NU-AKA-ACS-Version
X-Origin
X-Rebelmouse-Surrogate-Control
AKAMAI
X-Rebelmouse-Cache-Control
X-Backend-State
Cache-Host
X-Accel-Expires-Debug
X-Cache-Grace
X-Site-Version
User-Cache-Control
Thinkindot-CacheControl-Type
X-Cluster
Wxu-Next-Region
X-Clara-WADP
X-Generated-In
Wxu-Next-Hostname
Vix-Hermes-Req-Id
We-Hiring
Wxu-Next-Commit
X-Fastly-Cache
X-Csrf-Jwt
X-Generated-By
X-CGP
TDXMobile
X-Eu-Site
X-Fastly-Backend
True-Client-Country-4JS
Thinkindot-Control
X-DPWN-IS-SECURE
Thinkindot-CacheControl
X-Forwarded-Site
X-Fmm-Version
X-Cache-Tags
X-Device-Os
X-Cache-Info
Svr
Arc-Version
X-Origin-Expires
Source
X-Policy
X-RateLimit-Limit-Second
S-Rt
Adler-Geo
X-Loc
X-Men
C-Via
Arc-Country
X-RateLimit-Remaining-Second
X-Amz-Meta-S3cmd-Attrs
X-Variation
X-WADP-Cache
X-Viewer-Country
X-VC-Cache
X-Thinkindot-L3
X-SVT-ORM-VERSION
X-Request-Host
X-Served-From
X-HP-Trace-Id
X-SVT-ORM-RULES
Cf-Device-Type
X-Ua
L5d-Success-Class
Is-Eu
HA-Ipaddr
Ha-Gx-Prefs
NGX
NM-Fastcgi-Cache
Platform
PB-RID
PB-PID
X-Li-Fabric
Mail-Subject
DSUID
Ec-Rule-Version
X-LI-UUID
X-Li-Pop
X-Forwarded-Host
X-Ratelimit-Limit
X-NWS-UUID-VERIFY
X-Via-NSCOPI
X-GeoIP
X-Gen-Mode
X-Slack-Backend
X-Skip-Cache
X-User
X-Wikidot-Backend
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Varnish-CookieHashed-On
X-Fetched-On
X-VServer
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-Wikidot-Static-Cache
X-Tenant
X-Irp-Debug
X-Esi-Check
X-Owner
X-Mvc-Supplant-Cachable
X-GeoIP-City
X-DefHash
X-Nginx-Cache-Key
X-Shop-Environment
X-Micro-Cache
Url
X-Gzip
X-SIPLIST1
X-Forwarded-Path
X-Orig-Expires
X-Hnp-Log
X-FC-Vary-Parameters
X-Old-Content-Length
X-Cache-Id
V-Age
Server-Ext
VNS-Age
VNS-Cache
Locid
Cross-Origin-Window-Policy
Server-Hostname
Cache-Key
Sever-Int
CPC-Age
Release
CPC-Cache
NtCoent-Length
X-Block-Status
My-App
X-DefElseHash
IsBot
Webserver
Powered-By-ChinaCache
Content-Secure-Policy
X-PF-Uncompressing
Cache-Hits
X-Planisys-CDN-Rules
X-TX-ID
X-HS-Content-Campaign-Id
X-Qloud-Router
X-Planisys-CDN-TTL
X-Unique-Id
X-Planisys-CDN-Cache
X-Zone
X-Pass-Why
X-Ftr-Request-Id
X-Via-Popv
X-Via-Poph
X-Mvc-Supplant-OutputCached
Geo-Info
X-Via-Popn
MIME-Version
X-Ratelimit-Remaining
X-Cache-Ttl
X-Vc
X-PJAX-URL
X-Srv
X-Conf
X-Internal-Host
X-GEO
XServer
X-BBC-Edge-Cache-Status
X-OVcl-Cache
X-NC
X-OVcl
X-Refresh
X-ID
X-LB-ID
X-Servedbyhost
X-Ckpd-Fst-Backend
X-Worker
Cf-Bgj
X-Backend-TTL
X-TraceId
WebServer
Magicmarker
X-Auto-Login
Server-ID
X-NCache
DB-Nickname
X-LSADC-Cache
X-V-Cache
Memory
X-Geo
Time
X-TIME
X-DC
HostName
X-ZONE
Geoip-Latitude
X-Traceid
X-Dispatcher-Server
GeoIp-Country-Code
X-Rocket-Nginx-Serving-Static
X-Render-Time
X-Method
Tcn
X-NewRelic-App-Data
X-Wa
X-Tx-Id
Hostname
X-M-Log
X-Platform-Processor
X-Platform-Router
X-Qnm-Cache
X-M-Reqid
X-Platform-Cluster
X-Newrelic-Synthetics
X-CLOUD-TRACE-CONTEXT
Ssr
X-Cache-Remote
X-App
Resin-Trace
X-SD-PageType
X-IP
X-Tb-Optimization-Total-Bytes-Saved
LB
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-Datadog-Parent-Id
Environment
X-Correlation-ID
X-Origin-Time
X-Nyt-Route
X-VCL-Version
X-BBC-Origin-Response-Status
X-Li-Proto
X-NodeID
X-API-Version
X-Gdpr
X-Cache-Config
Ohc-File-Size
X-HITS
X-Trv-Group
X-Server-IP
Cluster
X-Pod-Name
X-Nc
X-MSEdge-Flight
X-MSEdge-Features
X-Dynatrace
X-CACHE-AGE
X-Via-Ucdn
X-Vcl-Version
Datacenter
X-Edge-Pop
Candidate-Md5Url
X-Node-Id
X-Origin-Response-Time
X-LI-Proto
X-Via-CDN
Cf-Ipcountry
X-DynaTrace-JS-Agent
X-Varnish-Beresp-TTL
Env
X-Cache-Var-Map
X-Cache-Var
X-APP
X-ServerName
X-Akamai-Pragma-Client-IP
X-ElasticPress-Query
Web-Mar-Region
X-Wix-Viewer-Type
X-ND-Cache
X-Reqid
X-HostName
X-Webkit-CSP-Report-Only
N-Cache
X-WA
CF-Cached-On
X-HS-Status
Sid
Rt-Fastcgi-Cache
GeoIP-Country-Code
Proxy-Connection
GeoIP-Latitude
Viewtype
X-Dynatrace-Js-Agent
CDN
X-FTR-Request-ID
VivaBuild
X-Cs
Machine
Servername
Server-Id
Onion-Location
X-Cdn-Forward
X-NGINX-Cache
X-Varnish-Cacheable
X-Fastly-Backend-Reqs
Cdn
WWW-Authenticate
X-EIG-Tracking-Id
X-URL
On-Server
X-Lb-Id
X-VC
X-Check-Cacheable
FSS-Cache
WZWS-RAY
X-ServedByHost
Ohc-Cache-HIT
X-Xrds-Location
X-Esi
X-CSRF-TOKEN
X-Content
X-Swa-Ws
X-Via-PopH
X-Fpc
X-Via-PopV
X-Via-PopN
X-Cache-Backend
X-Ua-Browser
X-IN-APIGATEWAY
X-Pjax-Url
X-IN-APIGATEWAYSSL
X-Fastly-Request-Id
Shield-Pop
X-Oss-Storage-Class
Redirect-Candidate
Cteonnt-Length
X-SN
URI
X-Oss-Server-Time
X-Oss-Request-Id
CountryCode
X-FTR-Realm
X-Request-Start
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
Mime-Version
Server-Ttl
X-FTR-Backend-Server
X-FTR-Balancer
X-Tid
X-TIM-N
X-FTR-Backend
X-AB
X-MG-S
X-FTR-DC
X-FTR-Cache-Status
Xc-Version
X-Country-Code-Real
X-Webkit-Csp-Report-Only
X-CCM
X-FORWARDED-FOR
Tracecode
CACHE
X-Varnish-Authentication
X-Air-Pt
X-Swift-Error
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Pf-Uncompressing
X-Up
Is-Us
Ohc-Response-Time
X-Cache-Date
X-RPS
X-Acquia-Purge-Tags
Xet-Cookie
X-DI
X-Acquia-Application-Trace
X-DW
X-DSS
X-DB
X-Action
X-RSL
X-StackifyID
X-RPM
X-Acquia-Application-UUID
X-Acquia-Site
X-Amz-Meta-Cb-Modifiedtime
X-CUA
X-SB
X-LiteSpeed-Cache-Control
X-Dw-Trace-Id
X-Yottaa-OS
X-Webstats-RespID
WP-Super-Cache
X-Snapshot-Date
X-Fastly-Cache-Hits
Warning
X-ElasticPress-Search
X-FTR-Expires
Lb
Instruction
Pramga
X-Apw-Access-Action
X-Apw-Access-Object
X-Sn-Servicetimems
X-Region-Sid
SR-User-Adfree
X-Cdn-Origin
X-Edge-POP
X-Apw-Access-Token
X-Mg-Request-Id
X-MiniProfiler-Ids
X-TH-Server
X-Pad
X-Tt-Logid
Vha6-Origin
X-C
X-Cache-Status-Check
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
ServerName
X-Apw-Hits