Threat Level: green Handler on Duty: Russ McRee

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-RAY
CF-Cache-Status
Accept-Ranges
Link
ETag
Pragma
Expect-CT
X-Powered-By
X-XSS-Protection
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
P3P
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-Cache-Status
X-Request-ID
X-Generator
P3p
X-Cacheable
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Content-Security-Policy
X-Iinfo
Status
X-Ua-Compatible
Feature-Policy
Content-Encoding
X-AspNetMvc-Version
X-CDN
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
Upgrade
X-Drupal-Dynamic-Cache
Access-Control-Max-Age
X-Dns-Prefetch-Control
X-Via
Keep-Alive
X-Ws-Request-Id
Request-Context
Server-Timing
X-Robots-Tag
X-AH-Environment
X-Hacker
X-Server
X-Age
X-Turbo-Charged-By
X-Proxy-Cache
X-Cache-Group
X-Server-Powered-By
X-Backend
X-Amz-Request-Id
Host-Header
X-Amz-Id-2
EagleId
X-Nginx-Cache-Status
Report-To
X-Rq
X-Varnish-Cache
X-LiteSpeed-Cache
X-UA-Device
Grace
X-Page-Speed
X-Pingback
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
EagleEye-TraceId
X-Device
X-Vhost
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Amz-Version-Id
NEL
X-OneAgent-JS-Injection
X-Dispatcher
Cf-Railgun
X-Host
X-WebKit-CSP
X-Cache-Spec
X-CST
X-Server-Id
X-Node
X-Backend-Server
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Allow
Request-Id
Surrogate-Control
Accept-CH
X-Readtime
X-Akam-SW-Version
X-Response-Time
Accept-Ch-Lifetime
Xkey
X-HW
X-Language
X-Application-Context
X-Template
X-Country
X-Ruxit-JS-Agent
X-Ac
Content-Location
X-Cloud-Trace-Context
X-Cache-Lookup
Rating
MS-Author-Via
X-Url
X-Webkit-CSP
Edge-Control
X-PC
X-TtlSet
X-Vname
X-Mod-Pagespeed
X-Clacks-Overhead
X-B3-TraceId
X-Varnish-TTL
X-Trace
Fastly-Restarts
X-Content-Type
X-Rack-Cache
X-MS-InvokeApp
X-Origin-Cache
X-ESI
X-Buckets
X-GitHub-Request-Id
X-Cnection
X-Country-Code
X-Goog-Hash
Accept-Ch
X-D2id
X-VARITI-CCR
Verso
X-Server-ID
X-FastCGI-Cache
X-Kinja-Revision
X-Use-Magma
X-Kinja-Build
X-Kinja
X-Exp-Variant
X-Cdn-Fetch
Arr-Disable-Session-Affinity
X-GoogleNews-Bot
X-Exp-Id
X-Kinja-Server
Accept-CH-Lifetime
Cache-Tag
X-Vcap-Request-Id
X-Cached
Service-Worker-Allowed
X-ORACLE-DMS-ECID
X-Server-Name
X-Abt-Application-Version
X-Client-IP
X-Amz-Rid
X-Px
X-Navigation-Version
Public-Key-Pins
RTSS
X-Powered-By-Plesk
X-Fastly-Request-ID
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Element-Page-Cache
X-Cache-TTL
Access-Control-Request-Method
X-MSEdge-Ref
X-Powered-CMS
X-Dw-Request-Base-Id
X-NF-Request-ID
X-Upstream
X-Version
X-TTL
X-Litespeed-Cache
Response
Pagespeed
Display
X-Sol
X-Middleton-Response
X-Middleton-Display
S
X-Kinsta-Cache
X-Edge-Location-Klb
X-Edge
X-LLID
X-Ttl
X-Server-Lifecycle-Phase
X-Kraken-Routeconfig-Destination
X-Kraken-Loop-Name
X-Instrumentation
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-ECACHE
X-Cache-Key
X-Accel-Expires
X-HP-Webp
X-Shield-Request-Id
Realpath
X-Jurisdiction
X-Correlation-Id
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-XRDS-Location
X-T
X-DynaTrace
SPRequestGuid
X-SharePointHealthScore
X-MCACHE
X-Mid
SPIisLatency
SPRequestDuration
X-Content-Security-Policy-Report-Only
Edge-Cache-Tag
X-PressLabs-Stats
X-ORACLE-DMS-RID
Fastcgi-Cache
X-Mg-S
X-Amz-Server-Side-Encryption
X-Content-Digest
Nginx-Cache
X-Forwarded-Proto
TP-Cache
TP-L2-Cache
X-Recruiting
Charset
TCN
Front-End-Https
X-Request-Processing-Time
X-Request-Received
Alternate-Protocol
Server-Node
X-Id
X-Logged-In
X-Oneagent-Js-Injection
Filters
X-Forwarded-For
Content-MD5
X-Ruxit-Js-Agent
X-Geo-Country
X-Ezoic-Cdn
Fusion-Component-Id
Fusion-Content-Id
Fusion-Template-Id
Fusion-Content-Source
Fusion-Deployment-Id
Fusion-Source
X-Protected-By
Cache-Tags
X-Hostname
X-ASPNET-VERSION
X-Origin-Upstream-Status
X-Amzn-Trace-Id
X-Grace
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Goog-Generation
X-NWS-LOG-UUID
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
X-Goog-Storage-Class
X-F-Cache
Cleartype
X-Debug-Info
X-Origin-Server
X-Www-Served-By
X-Rid
X-Amz-Replication-Status
X-LB-Cache
X-HS-Hub-Id
Host
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Combine-CSS
X-Activity-Id
X-RateLimit-Remaining
X-Az
X-AppVersion
X-Contextid
X-Ab
X-Daa-Tunnel
X-Git-Hash
X-Page-Id
Section-Io-Cache
Server-Name
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Release
X-Browser-Type
X-VCache
X-Frontend
X-Ser
MicrosoftSharePointTeamServices
X-Cache-Age
X-Content-Options
X-Upgrade-Enabled
Access-Control-Allow-Method
Accept-Charset
X-Aspnetmvc-Version
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Hits
ServerID
X-Mobile-URL
X-Source
X-DIS-Request-ID
X-Providence-Cookie
X-Signature
X-Route-Name
X-Request-Guid
X-Aspnet-Duration-Ms
X-Is-Crawler
X-Respond-Thread
X-B-Cache
X-Flags
X-Cache-Action
X-Varnish-Age
X-Whom
Viewport
Healthy
X-Varnish-Backend
X-FB-Debug
Payment
X-Varnish-Grace
Paypal-Debug-Id
X-TT
X-B3-Sampled
X-App-Environment
X-CACHE-GROUP
X-AOL-HN
DynaTrace
Node
X-Yandex-Sdch-Disable
Fastcgi-Useragent
X-WebKit-CSP-Report-Only
X-Load-Cache
X-Mobile
X-Fastcgi-Cache
X-Tt-Trace-Tag
X-Tt-Trace-Host
Version
X-Seen-By
DC
Filterid
X-N
X-Distributor
SRV
X-HTML-Minification-Powered-By
X-User-Agent
X-Cache-Control
X-Type
Frame-Options
Retry-After
X-Jobs
MS-CV
Refresh
X-FW-Static
X-Original-Request-Id
X-Response-Served-From
X-FW-Server
X-FW-Hash
X-FW-Dynamic
X-Cache-Expired-At
X-FW-Serve
X-FW-Type
Amp-Access-Control-Allow-Source-Origin
X-UUID
X-Adobe-Loc
X-Tec-Api-Origin
X-Proxy-Cache-Status
X-Adobe-Content
NGB
X-Page-View
X-Tec-Api-Version
X-Tec-Api-Root
X-Instance
X-Debug-IsPreview
X-NGENIX-Cache
X-Debug-IsConnected
X-Region
X-Real-IP
X-Tumblr-Pixel-0
X-IPLB-Instance
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Tumblr-Pixel-1
X-Tumblr-User
X-Vgn-Hpd-Reason
X-Node-Name
X-Azure-Ref
X-Varnish-Server
X-Tumblr-Pixel
X-B
X-Cluster-Name
X-HP-Trace-Id
X-G
X-RemovedCookies
X-Cacheable-TTL
X-ProcessESI
X-XRDS-LOCATION
X-Framework
X-Device-Type
X-Cache-Time
X-Content-Powered-By
Access-Control-Request-Headers
X-CDN-Forward
X-Oracle-Dms-Rid
Ms-Operation-Id
X-Proxy
X-RTag
X-IPS-LoggedIn
X-Zen-Fury
Uber-Trace-Id
X-Cache-Hit
X-Aws-Lambda-Call-Status
X-Cache-Rule
SD-X-WS
Referer-Policy
Cache-Status
Liferay-Portal
X-Is-Bot
X-Rendered-As
X-RateLimit-Limit
X-Wix-Request-Id
X-Ms-Version
X-Ms-Request-Id
X-Drupal-Cache-Tags
X-Parallel-Accel
X-Time
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Io-Id
X-Mg-Request-UUID
Section-Origin-Responded
Countrycode
X-Debug
X-EdgeConnect-Cache-Status
AR-ATIME
S-Cnection
X-Accel-Buffering
AR-PoweredBy
X-Revision
AR-CACHE
X-Environment-Context
X-Microsite
X-App-Server
Ar-Sid
X-L-Path
X-Request-Handler-Origin-Region
AR-Request-ID
X-Nginx-Cache
Country
CF-IPCountry
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Cache-Operation
Count-Hit
Cache
X-App-Version
X-Drupal-Cache-Contexts
X-FW-Version
X-Loop
X-Endurance-Cache-Level
X-GG-Cache-Date
Surrogate-Key
X-ES-SERVER
X-SaId
GEO-INFO
X-JoinUs
X-RN-RSRV
X-UPSTREAM-Address
Meta-Geo
X-TNCMS
X-Cache-TTL-Remaining
X-Adobe-Source
X-Say-Cacheable
From-Origin
X-Cache-Type
X-SayCDN-TTL
X-LAGOON
X-Say-TTL
X-Sql-Count
X-Human
X-Sql-Duration-Ms
Akamai-GRN
X-APP-VERSION
Azure-Version
X-S-Maxage
X-NYM-Debug-Backend
Country-Code
X-Request-Time
Azure-SlotName
X-Varnish-Beresp-Grace
Protected
Azure-InstanceId
Azure-SiteName
Azure-RegionName
X-BYPASS-REASON
ServedBy
Cache-Name
Apigw-Requestid
X-R9-Blue-Green-Version
X-Alternate-Cache-Key
X-AWS-Id
X-VWS-Id
X-Pubstack
X-ProxyCache-Key
X-Storefront-Renderer-Rendered
X-RCS-CacheZone
X-ShardId
X-Xfnlog-Site
X-TA-CDN-Provider
X-Status
X-Origin-Date
X-LJ-Flow-ID
X-Sorting-Hat-PodId
Fastly-SSL
X-ProxyCache-Status
X-No-Session
X-Shopify-Stage
X-Labrador-Cache-Channel
X-Sorting-Hat-ShopId
X-Hosted-By
X-Handled-By
X-PHP-Host
X-Proto
X-Varnishpool
X-Varnish-Hostname
X-ShopId
Selected-Fe
X-OCL
X-Redis-Cache
Decoy-Debug-Status
X-PCL
X-Timing-Wait
X-UA-Device-Type
Property-Id
Decoy-Debug-TTL
X-Via-Fastly
Decoy-Debug-Key
Webcakes-Region
X-Web-Node
Webcakes-App-Version
X-Tumblr-Pixel-2
X-Akamai-Edgescape
X-Hyper-Cache
X-Be
X-Server-W
Webcakes-App-Name
X-Origin-Hint
TWC-GeoIP-Country
TWC-Device-Class
TWC-Connection-Speed
TWC-GeoIP-LatLong
X-Format
TWC-Locale-Group
X-Proxy-Build
X-Uri
TWC-Privacy
Eomportal-Instance
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
Cache-Tv-Group
X-B3-SpanId
X-PERF
X-ApacheServer
X-PHP-Backend
X-Access
X-Backend-Host
X-Section
Mn-Server-Ip
X-Cache-Server
X-Cluster-Node
X-FireWall-Port
X-FB-TRIP-ID
X-Backend-Name
X-Servername
X-Time-Microsecs
X-Hl-Ver
Nel
Cross-Origin-Opener-Policy
OT-Force-Account-Verify
X-ServerID
X-ATG-Version
X-Ua-Device
X-Tumblr-Pixel-3
X-B3-Traceid
X-Detected-As
X-Azure-Ref-OriginShield
X-Cache-PHP
Web-Mar-Node
X-Varnish-Cache-Hits
X-Cache-Host
Cross-Origin-Window-Policy
X-Trace-Id
Backend
X-Generation-Time
X-Content-Age
X-TT-LOGID
X-Varnish-Hits
X-Ua
Content-Secure-Policy
X-CS
X-SRV
Ec-Rule-Version
Xserver
X-CSRF-Token
X-Via-JSL
X-Datadome
X-WA-Info
X-MP-GENERATED-AT
Source
X-Akamai-Transformed
X-Soup
X-Cache-Enabled
Upgrade-Insecure-Requests
X-Microcachable
X-Edge-Location
X-Cache-Grace
X-Bc-Bl
X-Amzn-Remapped-Content-Length
X-Cdn
X-Air-Trace-Id
X-Unique-Id
X-Mode
X-Air-Source
X-Air-Hostname
X-Amzn-RequestId
X-Amz-Apigw-Id
X-NWS-UUID-VERIFY
X-Forwarded-Host
Url
X-Locale
X-Varnish-Beresp-Ttl
X-Info
X-Rule
X-Origin-CC
X-Origin-TTL
SID
S-Rt
X-GEO
X-Site-Version
X-Varnish-Beresp-Status
X-DataDome
X-Tb
Content-Disposition
X-Magnolia-Registration
X-Cached-By
X-Cache-Bucket
X-NAPM-TraceId
X-NU-AKA-ACS-Version
Path
Odigeo-Trace-Id
X-BCube-Filmed-By
X-External-Request-Id
DCR-Processing-Time-Ms
X-CF-Lambda-Version
X-Developer
DCR-Decision-By
X-Epic-Correlation-Id
CDN-RequestId
CDN-Uid
X-CF-Lambda-Fn
X-Destination
Expiry
X-Connection-Hash
Host-ID
X-Conf
X-D
X-Debug-Cache
Fastcgi-X-Cache-Version
Fastly-SIE
Fastly-SWR
CDN-RequestCountryCode
CDN-PullZone
A
Apple-News-Services-Handled
Apple-News-Services-Host
X-From
X-Ftr-Request-Id
Meta-Geo-Continent
X-Cache-NE
MD5-Digest
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
CDN-Cache
CDN-CachedAt
CDN-EdgeStorageId
CDCHOST
X-Orig-Expires
X-Forwarded-Path
BehaviorPad-Version
X-Extlb
Mobile-Detection-Method
X-Proxied
X-ScT
X-B-Cookie
X-ARC
X-Session-Fingerprint
X-Shop-Environment
X-S-Cookie
X-A-Dam
State
Req-Svc-Chain
X-Routing-Service
X-Vdms-Version
X-S
X-Application
X-AIR-PT
X-A-Dgt
T-Server
Surrogated-Key
X-A-Wwc
X-DC
X-A-Dcw
X-Tenant
X-Aed
X-Aicache-OS
X-SRCache-Key
X-Content
X-Ua-Browser
X-Rewrite-Enabled
X-Rojux
X-Processor
X-VG-WebCache
X-BBC-Edge-Cache-Status
X-Vtex-Processado-Em
X-Storage
X-Platform-Server
User-Cache-Control
X-PAYTM-SRV-ID
X-PBS-Appsvrname
X-Zipkin-Id
X-Ratelimit-Reset
X-Vtex-Remote-Cache
X-Rebelmouse-Surrogate-Control
X-VG-WebServer
X-Request-URI
X-A
X-A-Ccd
Rendered-Blocks
X-Rebelmouse-Cache-Control
X-Cache-NGX
X-EC-Lua
X-Ratelimit-Limit
X-VG-TLSProxy
L
Is-Eu
X-Variation
X-Core-Value
Fastly-Drupal-HTML
X-VServer
X-Envoy-Decorator-Operation
X-Date
M-TraceId
X-DPWN-IS-SECURE
Cmsid
Cmstype
UCS
Adler-Geo
X-Li-Fabric
X-Li-Pop
X-TrackingId
X-Request-UUID
Origin
X-LI-UUID
X-Loc
X-Men
Pics-Label
X-Proxy-Upstream
X-Backend-State
X-Cache-Debug
NGX
Cache-Key
X-Fastly-Backend
X-Accel-Expires-Debug
Cache-Host
X-Fastly-Cache
X-SVT-ORM-VERSION
X-Service
X-Cache-Info
Platform
X-Origin-Expires
X-SVT-ORM-RULES
X-Tx-Id
X-Bip
X-Clientip
VNS-Age
X-Branch-Name
X-Cache-Tags
X-Ckpd-Fst-Backend
X-Block-Status
X-Cluster
VNS-Cache
X-Nginx-Cache-Key
X-Sigma-Backend
X-SIPLIST1
X-Slack-Backend
X-Thanos
X-Sigma
X-Served-From
X-RateLimit-Remaining-Second
X-Req
X-Rocket-Build-Number
X-Scheme
X-Thinkindot-L3
X-Var-Ttl
X-Viewer-Country
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Worker
X-Via-NSCOPI
X-VC-Cache
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-VarnishDD-TTL
X-RateLimit-Limit-Second
X-Origin
X-Gen-Mode
X-Generated-By
X-Generated-On
X-Gzip
X-Gamma-Serve
X-Forwarded-Site
X-DefElseHash
X-DefHash
X-Device-Os
X-Esi-Check
X-Has-Esi
X-Hash
X-Location
X-Micro-Cache
Vix-Hermes-Req-Id
X-Old-Content-Length
X-Level-Front-Cache
X-JWT-State
X-HN
X-Hnp-Log
X-Is-Gdpr
X-Cms-Context
X-Cache-Id
PB-RID
PB-PID
Locid
PFcat
X-Dc
Server-Host
Server-Ext
X-Cache-Ttl
IsBot
C-Via
Arc-Version
CPC-Age
CPC-Cache
Fastly-Backend-Name
Esi-Enabled
Server-Hostname
Location
TDXMobile
True-Client-Country-4JS
Thinkindot-CacheControl-Type
Sever-Int
Thinkindot-Control
Thinkindot-CacheControl
Server-Info
X-Ratelimit-Remaining
X-M-Reqid
AMP-Access-Control-Allow-Source-Origin
X-NCache
X-Amz-Meta-S3cmd-Attrs
X-M-Log
X-Platform
We-Hiring
V-Age
X-Planisys-CDN-Cache
X-Eu-Site
Cf-Device-Type
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Auto-Login
CacheControlHeader
X-Fmm-Version
X-Generated-In
X-Qnm-Cache
X-GoCache-CacheStatus
X-Geo-Header
X-GeoIP
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Irp-Debug
DSUID
X-Fetched-On
Arc-Country
X-Owner
X-Mvc-Supplant-Cachable
X-FC-Vary-Parameters
X-Request-Host
X-Sucuri-ID
NM-Fastcgi-Cache
Memcached
Mail-Subject
X-Skip-Cache
Pagetype
X-Vdms-Path
X-WADP-Cache
Webserver
Svr
Release
X-CGP
X-Clara-WADP
Wxu-Next-Hostname
Gh-Request-Id
Fastcgi-Cache-TTL
Wxu-Next-Commit
X-Policy
X-Csrf-Jwt
Ha-Gx-Prefs
L5d-Success-Class
X-GeoIP-City
Wxu-Next-Region
HA-Ipaddr
X-Developers
NtCoent-Length
XServer
X-V-Cache
X-Qloud-Router
AKAMAI
X-Platform-Cluster
X-Render-Time
Cache-Hits
X-Platform-Processor
X-Platform-Router
X-Mvc-Supplant-OutputCached
X-Rocket-Nginx-Serving-Static
X-LSADC-Cache
X-Servedbyhost
X-Via-Popn
MIME-Version
X-Via-Poph
Kp-EeAlive
X-Via-Popv
X-HS-Content-Campaign-Id
X-Unique-ID
X-SD-PageType
DataCenter
X-Cache-Remote
Environment
X-Cache-Var
X-Cache-Var-Map
X-Zone
X-User
X-NC
X-Srv
Who
X-Vc
X-API-Version
X-BBC-Origin-Response-Status
X-Wa
X-Traceid
X-Origin-Time
X-PF-Uncompressing
X-Nyt-Route
X-Gdpr
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-NodeID
X-Datadog-Parent-Id
X-ID
Cluster
X-Webkit-CSP-Report-Only
X-App
X-Minions-Version
X-Via-Ucdn
Server-ID
X-Varnish-Url
X-Refresh
X-PJAX-URL
WebServer
X-Varnish-Ttl
X-Cache-Config
X-Pod-Name
X-LB-ID
X-VCL-Version
Candidate-Md5Url
X-Internal-Host
X-Server-IP
HostName
Datacenter
X-TIME
My-App
Powered-By-ChinaCache
Time
X-Webkit-Csp
Memory
X-CACHE-KEY
X-ZONE
X-Newrelic-Synthetics
X-Pass-Why
X-LI-Proto
Geoip-Latitude
Web-Mar-Region
X-NewRelic-App-Data
Onion-Location
N-Cache
X-Esi
GeoIp-Country-Code
X-CLOUD-TRACE-CONTEXT
X-Tb-Optimization-Total-Bytes-Saved
X-ElasticPress-Query
Servername
Resin-Trace
X-Edge-Pop
Geo-Info
X-OVcl
X-TX-ID
X-OVcl-Cache
X-VHOST
X-Akamai-Pragma-Client-IP
Hostname
X-Varnish-Cacheable
Cf-Bgj
X-Origin-Response-Time
X-Backend-TTL
Tcn
X-TraceId
Ohc-File-Size
X-Dynatrace
WWW-Authenticate
X-CACHE-AGE
X-HITS
Magicmarker
X-Tt-Logid
X-Fpc
X-Geo
X-EIG-Tracking-Id
CDN
LB
Cdn
X-Dispatcher-Server
X-NODE
X-Tid
X-TIM-N
Redirect-Candidate
X-Method
X-MSEdge-Features
X-Li-Proto
X-Varnish-Beresp-TTL
GeoIP-Country-Code
X-MSEdge-Flight
X-AB
X-Correlation-ID
Tracecode
Proxy-Connection
X-Wix-Viewer-Type
X-Dynatrace-Js-Agent
X-Up
X-HostName
DB-Nickname
Ssr
Is-Us
Pramga
X-IP
GeoIP-Latitude
X-Cache-Date
X-Request-Start
Cf-Ipcountry
X-Fastly-Backend-Reqs
X-HS-Status
Lb
X-NGINX-Cache
X-Cdn-Origin
X-Vcl-Version
X-Sn-Servicetimems
X-Amz-Meta-Cb-Modifiedtime
X-Cs
X-CSRF-TOKEN
CF-Cached-On
Server-Id
X-Node-Id
X-Provided-By
X-Core-Mission
W
X-APP
X-COUNTRY
Sid
X-MG-S
X-UnsetCookies
X-WA
X-ServerName
CloudFront-Viewer-Country
X-Cache-Expires
X-Pjax-Url
X-ND-Cache
X-Lb-Id
X-Reqid
X-Webkit-Csp-Report-Only
X-Trv-Group
Cteonnt-Length
X-FORWARDED-FOR
X-Nc
X-Oracle-Dms-Ecid
URI
WP-Super-Cache
WZWS-RAY
X-Via-CDN
X-Check-Cacheable
Env
X-DynaTrace-JS-Agent
X-VC
CountryCode
Ohc-Cache-HIT
X-Via-PopN
X-CCDN-Origin-Time
X-Via-PopH
X-Fastly-Request-Id
X-Via-PopV
X-Hcs-Proxy-Type
X-Cache-Status-Check
X-SERVER-NAME
X-Sucuri-Cache
X-CCDN-CacheTTL
X-Region-Sid
X-Cache-Backend
X-CUA
X-ServedByHost
Mime-Version
X-IN-APIGATEWAY
Shield-Pop
X-Moov-Xdn-Version
X-Pad
X-Moov-T
X-IN-APIGATEWAYSSL
X-Pf-Uncompressing
Xc-Version
X-Edge-POP
X-SN
X-Presslabs-Stats
X-RAMCache
EpKe-Alive
X-Acquia-Application-Trace
X-Ig-Push-State
X-Acquia-Site
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
Viewtype
X-Contensis-Viewer-Groups
X-Fastly-Cache-Hits
X-LiteSpeed-Cache-Control
X-Varnish-Authentication
User-Agent
X-Cache-ASPX
CACHE
VivaBuild
Rt-Fastcgi-Cache
Server-Ttl
X-Dw-Trace-Id
X-Swift-Error
X-Yottaa-OS
X-Cdn-Request-ID
X-SB
X-Webstats-RespID
FSS-Cache
X-DW
X-DSS
X-RPM
Xet-Cookie
X-RSL
X-RPS
X-StackifyID
X-DI
Ohc-Response-Time
Hit
X-DB
X-Amz-Meta-Opti
Vha6-Origin
X-Action
X-UA
X-Cdn-Forward
X-Dispatch
X-Parent-Response-Time
On-Server
X-TH-Server
X-MiniProfiler-Ids
X-ElasticPress-Search
Machine
ServerName
Content-Script-Type
Req-ID
Content-Style-Type
X-CF-Powered-By