Threat Level: green Handler on Duty: Russ McRee

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-RAY
CF-Cache-Status
Accept-Ranges
Link
ETag
Pragma
Expect-CT
X-Powered-By
X-XSS-Protection
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
P3P
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-Cache-Status
X-Request-ID
X-Generator
P3p
X-Cacheable
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Content-Security-Policy
X-Iinfo
Status
X-Ua-Compatible
Feature-Policy
Content-Encoding
X-AspNetMvc-Version
X-CDN
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
Upgrade
Access-Control-Max-Age
X-Drupal-Dynamic-Cache
X-Dns-Prefetch-Control
X-Via
Keep-Alive
X-Ws-Request-Id
Server-Timing
Request-Context
X-Robots-Tag
X-AH-Environment
X-Hacker
X-Server
X-Age
X-Turbo-Charged-By
X-Proxy-Cache
X-Cache-Group
X-Server-Powered-By
X-Backend
X-Amz-Request-Id
Host-Header
X-Amz-Id-2
EagleId
X-Nginx-Cache-Status
Report-To
X-LiteSpeed-Cache
X-Rq
X-Varnish-Cache
X-UA-Device
Grace
X-Page-Speed
X-Pingback
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
EagleEye-TraceId
X-Device
X-Vhost
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Amz-Version-Id
NEL
X-OneAgent-JS-Injection
X-Dispatcher
Cf-Railgun
X-Host
X-Cache-Spec
X-WebKit-CSP
X-CST
X-Server-Id
X-Node
X-Backend-Server
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Allow
Request-Id
Surrogate-Control
X-Readtime
Accept-CH
X-Akam-SW-Version
Accept-Ch-Lifetime
X-Response-Time
Xkey
X-HW
X-Language
X-Application-Context
X-Template
X-Webkit-CSP
X-Country
X-Ruxit-JS-Agent
X-Ac
Content-Location
X-Cloud-Trace-Context
X-Cache-Lookup
Rating
MS-Author-Via
X-Url
Edge-Control
X-PC
X-Vname
X-TtlSet
X-Mod-Pagespeed
X-Clacks-Overhead
X-B3-TraceId
X-Varnish-TTL
Accept-Ch
X-Trace
X-Content-Type
Fastly-Restarts
X-MS-InvokeApp
X-Rack-Cache
X-ESI
X-Buckets
X-Origin-Cache
X-GitHub-Request-Id
X-Cnection
X-Country-Code
X-Goog-Hash
X-D2id
Verso
X-VARITI-CCR
X-Server-ID
X-FastCGI-Cache
X-Exp-Variant
X-Cdn-Fetch
X-Kinja-Revision
X-Exp-Id
X-Use-Magma
X-Kinja-Server
X-Kinja-Build
X-Kinja
X-GoogleNews-Bot
Arr-Disable-Session-Affinity
Cache-Tag
X-Vcap-Request-Id
Service-Worker-Allowed
X-Cached
X-ORACLE-DMS-ECID
X-Abt-Application-Version
X-Server-Name
X-Client-IP
X-Amz-Rid
X-Px
X-Navigation-Version
Accept-CH-Lifetime
X-Cache-TTL
RTSS
X-Powered-By-Plesk
Public-Key-Pins
X-Fastly-Request-ID
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Access-Control-Request-Method
X-Element-Page-Cache
X-MSEdge-Ref
X-TTL
X-Powered-CMS
X-Dw-Request-Base-Id
X-NF-Request-ID
X-Upstream
X-Version
X-Middleton-Display
X-Middleton-Response
Display
Response
Pagespeed
X-Sol
S
X-Edge-Location-Klb
X-Kinsta-Cache
X-Edge
X-LLID
X-Kraken-Routeconfig-Destination
X-Server-Lifecycle-Phase
X-Instrumentation
X-Kraken-Loop-Name
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-Cache-Key
X-ECACHE
X-Accel-Expires
Realpath
X-Jurisdiction
X-Shield-Request-Id
X-HP-Webp
X-Correlation-Id
X-Ttl
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
X-T
X-XRDS-Location
X-DynaTrace
X-SharePointHealthScore
SPRequestGuid
X-Mid
X-MCACHE
X-PressLabs-Stats
X-Content-Security-Policy-Report-Only
SPRequestDuration
SPIisLatency
Edge-Cache-Tag
X-Litespeed-Cache
Fastcgi-Cache
X-ORACLE-DMS-RID
X-Amz-Server-Side-Encryption
Nginx-Cache
X-Content-Digest
X-Forwarded-Proto
TP-L2-Cache
TP-Cache
X-Recruiting
X-Mg-S
Charset
X-Request-Received
X-Request-Processing-Time
TCN
Front-End-Https
Alternate-Protocol
X-Id
Server-Node
X-Logged-In
X-Oneagent-Js-Injection
Filters
Content-MD5
X-Forwarded-For
X-Ruxit-Js-Agent
X-Geo-Country
X-Ezoic-Cdn
Fusion-Template-Id
Fusion-Source
X-Protected-By
Fusion-Content-Id
Fusion-Content-Source
Fusion-Component-Id
Fusion-Deployment-Id
Cache-Tags
X-Hostname
X-ASPNET-VERSION
X-Amzn-Trace-Id
X-Origin-Upstream-Status
X-Grace
X-NWS-LOG-UUID
X-Goog-Generation
X-Goog-Metageneration
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-F-Cache
X-Www-Served-By
Cleartype
X-Debug-Info
X-Origin-Server
X-Amz-Replication-Status
X-Rid
X-LB-Cache
X-HS-Cache-Config
X-HS-Content-Id
Host
X-HS-Hub-Id
X-HS-Combine-CSS
X-Az
X-AppVersion
X-Activity-Id
X-Contextid
X-RateLimit-Remaining
X-Daa-Tunnel
X-Git-Hash
X-Page-Id
Server-Name
Section-Io-Cache
X-Erf-Bev-Bev-Is-Generated
X-Release
X-Erf-Bev-Bev
X-Browser-Type
X-VCache
X-Frontend
X-Ab
X-Ser
X-Cache-Age
MicrosoftSharePointTeamServices
X-Content-Options
Access-Control-Allow-Method
X-Upgrade-Enabled
X-Kong-Upstream-Latency
X-Aspnetmvc-Version
X-Kong-Proxy-Latency
Accept-Charset
X-Hits
X-Mobile-URL
ServerID
X-Source
X-DIS-Request-ID
X-Providence-Cookie
X-B-Cache
X-Is-Crawler
X-Flags
X-Aspnet-Duration-Ms
X-Signature
X-Respond-Thread
X-Request-Guid
X-Route-Name
X-Cache-Action
X-Varnish-Age
X-Varnish-Backend
Healthy
Viewport
X-Whom
X-FB-Debug
X-Varnish-Grace
Paypal-Debug-Id
Payment
X-B3-Sampled
X-TT
X-AOL-HN
DynaTrace
Node
X-CACHE-GROUP
X-App-Environment
Fastcgi-Useragent
X-WebKit-CSP-Report-Only
X-Yandex-Sdch-Disable
X-Load-Cache
X-Mobile
X-Fastcgi-Cache
X-Tt-Trace-Tag
X-Tt-Trace-Host
Version
DC
X-Seen-By
X-N
Filterid
SRV
X-Distributor
X-HTML-Minification-Powered-By
X-Cache-Control
X-User-Agent
X-Type
Retry-After
Frame-Options
X-Tec-Api-Origin
X-Jobs
X-Tec-Api-Version
X-Tec-Api-Root
MS-CV
Refresh
X-FW-Static
X-Cache-Expired-At
X-FW-Dynamic
X-FW-Type
X-Original-Request-Id
Amp-Access-Control-Allow-Source-Origin
X-Response-Served-From
X-FW-Serve
X-FW-Server
X-FW-Hash
X-UUID
X-Adobe-Loc
X-Page-View
NGB
X-Proxy-Cache-Status
X-Adobe-Content
X-Debug-IsPreview
X-Debug-IsConnected
X-Varnish-Server
X-NGENIX-Cache
X-Instance
X-Region
X-Real-IP
X-G
X-Cacheable-TTL
X-B
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Tumblr-Pixel
X-RemovedCookies
X-Tumblr-Pixel-0
X-HP-Trace-Id
X-ProcessESI
X-Tumblr-Pixel-1
X-Vgn-Hpd-Reason
X-Tumblr-User
X-Cluster-Name
X-Azure-Ref
X-IPLB-Instance
X-Node-Name
X-XRDS-LOCATION
Access-Control-Request-Headers
X-Content-Powered-By
X-Framework
X-CDN-Forward
X-Oracle-Dms-Rid
X-Cache-Time
X-Proxy
X-Device-Type
X-RTag
Ms-Operation-Id
X-Zen-Fury
X-IPS-LoggedIn
X-Cache-Hit
Uber-Trace-Id
X-Cache-Rule
X-Aws-Lambda-Call-Status
SD-X-WS
Liferay-Portal
X-Is-Bot
X-Rendered-As
Cache-Status
Referer-Policy
X-Ms-Request-Id
X-Wix-Request-Id
X-RateLimit-Limit
X-Ms-Version
X-Drupal-Cache-Tags
X-Time
X-Parallel-Accel
X-Mg-Request-UUID
Section-Io-Id
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Countrycode
X-EdgeConnect-Cache-Status
X-Debug
X-Microsite
AR-PoweredBy
Ar-Sid
AR-CACHE
AR-Request-ID
AR-ATIME
S-Cnection
X-App-Server
X-Environment-Context
X-Request-Handler-Origin-Region
X-Accel-Buffering
X-Revision
X-L-Path
X-Nginx-Cache
CF-IPCountry
Country
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Cache-Operation
Cache
Count-Hit
X-Drupal-Cache-Contexts
X-App-Version
X-FW-Version
Meta-Geo
X-GG-Cache-Date
X-JoinUs
X-ES-SERVER
X-UPSTREAM-Address
X-Endurance-Cache-Level
GEO-INFO
X-SaId
X-TNCMS
X-Loop
X-RN-RSRV
Surrogate-Key
X-SayCDN-TTL
X-Say-TTL
X-Adobe-Source
Akamai-GRN
X-Cache-TTL-Remaining
X-Cache-Type
X-Say-Cacheable
From-Origin
X-LAGOON
X-Human
X-NYM-Debug-Backend
X-Sql-Duration-Ms
X-Sql-Count
X-S-Maxage
X-APP-VERSION
X-Request-Time
X-Varnish-Beresp-Grace
Protected
X-ProxyCache-Status
Eomportal-Instance
X-TA-CDN-Provider
X-Alternate-Cache-Key
X-Storefront-Renderer-Rendered
X-AWS-Id
Decoy-Debug-TTL
X-Be
Decoy-Debug-Status
ServedBy
Decoy-Debug-Key
X-ProxyCache-Key
Azure-SiteName
Azure-RegionName
Azure-SlotName
Azure-Version
Cache-Name
Azure-InstanceId
Apigw-Requestid
X-Proto
X-PHP-Host
Country-Code
X-BYPASS-REASON
Cache-Tv-Group
X-Pubstack
X-ShardId
X-Handled-By
X-R9-Blue-Green-Version
X-PCL
X-OCL
X-Hosted-By
X-Varnishpool
X-Labrador-Cache-Channel
X-LJ-Flow-ID
X-Varnish-Hostname
X-Origin-Date
X-Xfnlog-Site
Fastly-SSL
X-ShopId
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-No-Session
X-RCS-CacheZone
X-VWS-Id
X-Section
TWC-Connection-Speed
Selected-Fe
X-Origin-Hint
X-Redis-Cache
X-Web-Node
X-Via-Fastly
TWC-Device-Class
X-Proxy-Build
X-Access
X-Tumblr-Pixel-2
X-Timing-Wait
Property-Id
X-UA-Device-Type
X-Cache-Server
X-Server-W
X-Akamai-Edgescape
X-Format
X-Status
TWC-Locale-Group
TWC-GeoIP-LatLong
X-Uri
X-Hyper-Cache
TWC-Privacy
Webcakes-App-Version
Webcakes-App-Name
TWC-GeoIP-Country
Webcakes-Region
X-B3-SpanId
X-PERF
X-ApacheServer
X-Backend-Host
Mn-Server-Ip
X-PHP-Backend
X-FB-TRIP-ID
X-FireWall-Port
X-Cluster-Node
X-Backend-Name
X-Hl-Ver
X-Servername
X-Time-Microsecs
Nel
OT-Force-Account-Verify
Cross-Origin-Opener-Policy
X-ServerID
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Ua-Device
X-TEC-API-ROOT
X-Tumblr-Pixel-3
X-Detected-As
X-B3-Traceid
X-ATG-Version
X-Azure-Ref-OriginShield
X-Cache-PHP
Web-Mar-Node
X-Cache-Host
X-Varnish-Cache-Hits
Cross-Origin-Window-Policy
X-Generation-Time
X-Content-Age
X-Ua
Backend
X-Trace-Id
X-TT-LOGID
X-Varnish-Hits
Xserver
Content-Secure-Policy
Ec-Rule-Version
X-CS
X-CSRF-Token
X-MP-GENERATED-AT
X-Datadome
X-WA-Info
X-Via-JSL
Source
X-SRV
X-Akamai-Transformed
X-Soup
X-Microcachable
X-Cache-Grace
X-Cache-Enabled
X-Edge-Location
Upgrade-Insecure-Requests
X-Bc-Bl
X-Mode
X-Air-Source
X-Air-Hostname
X-Cdn
X-Air-Trace-Id
X-Amzn-Remapped-Content-Length
X-Amz-Apigw-Id
X-Amzn-RequestId
Url
X-Locale
X-Varnish-Beresp-Ttl
X-Forwarded-Host
X-Rule
X-NWS-UUID-VERIFY
X-Info
X-Origin-TTL
X-Origin-CC
X-Varnish-Beresp-Status
S-Rt
X-Site-Version
SID
X-GEO
Content-Disposition
X-DataDome
X-Unique-Id
X-Content
X-Magnolia-Registration
X-Ua-Browser
X-Cached-By
CDCHOST
X-Aed
Apple-News-Services-Host
X-Aicache-OS
X-A-Wwc
Apple-News-Services-Handled
X-Ftr-Request-Id
X-Connection-Hash
X-A-Dgt
X-Conf
X-DC
X-Vtex-Remote-Cache
Meta-Geo-Continent
X-NU-AKA-ACS-Version
X-CF-Lambda-Version
X-AIR-PT
X-NAPM-TraceId
MD5-Digest
CDN-Cache
Apple-News-Services-Parsed-Url
T-Server
X-Epic-Correlation-Id
X-A-Dcw
X-A
X-A-Ccd
X-Developer
X-Destination
Fastly-SWR
Fastly-SIE
Expiry
X-VG-WebCache
X-VG-WebServer
BehaviorPad-Version
A
X-Debug-Cache
X-Orig-Expires
DCR-Processing-Time-Ms
X-D
DCR-Decision-By
X-A-Dam
X-Forwarded-Path
X-Vdms-Version
X-From
Host-ID
Fastcgi-X-Cache-Version
Mobile-Detection-Method
CDN-Uid
X-SRCache-Key
X-Rewrite-Enabled
X-Extlb
X-Rojux
X-Request-URI
CDN-RequestId
X-Application
X-Rebelmouse-Cache-Control
X-ARC
X-Rebelmouse-Surrogate-Control
X-Routing-Service
X-S
X-External-Request-Id
X-Session-Fingerprint
X-Shop-Environment
X-BCube-Filmed-By
X-BBC-Edge-Cache-Status
Req-Svc-Chain
Rendered-Blocks
X-B-Cookie
X-S-Cookie
X-Cache-Bucket
X-ScT
Apple-News-Services-Request-Url
X-Ratelimit-Reset
Surrogated-Key
X-Platform-Server
State
X-Vtex-Processado-Em
Odigeo-Trace-Id
CDN-CachedAt
X-PBS-Appsvrname
X-Zipkin-Id
X-CF-Lambda-Fn
User-Cache-Control
X-PAYTM-SRV-ID
CDN-RequestCountryCode
X-Storage
X-Tenant
CDN-EdgeStorageId
X-Cache-NE
Path
CDN-PullZone
X-Proxied
X-Processor
X-Ratelimit-Limit
X-EC-Lua
X-Tb
X-Cache-NGX
X-Envoy-Decorator-Operation
Cmstype
M-TraceId
Cmsid
Origin
NGX
X-Cache-Info
X-Cache-Debug
X-Backend-State
Platform
Pics-Label
X-Cms-Context
X-Accel-Expires-Debug
Is-Eu
Fastly-Drupal-HTML
Fastly-Backend-Name
X-Date
L
UCS
X-Core-Value
X-DPWN-IS-SECURE
X-Loc
X-Men
X-Fastly-Backend
X-Proxy-Upstream
X-LI-UUID
X-Li-Pop
X-JWT-State
X-Li-Fabric
X-Request-UUID
X-Service
X-Variation
X-VG-TLSProxy
X-TrackingId
X-VServer
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Is-Gdpr
X-Origin-Expires
Adler-Geo
Cache-Key
Cache-Host
X-Fastly-Cache
X-Has-Esi
X-Tx-Id
X-Rocket-Build-Number
X-Sigma-Backend
X-SIPLIST1
X-Slack-Backend
X-Scheme
X-Sigma
X-Block-Status
X-Served-From
X-Bip
X-Branch-Name
X-Device-Os
X-Thinkindot-L3
X-VarnishDD-TTL
X-Viewer-Country
X-VC-Cache
X-Esi-Check
X-Via-NSCOPI
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-Thanos
X-Gamma-Serve
X-Var-Ttl
X-Varnish-CookieHashed-On
X-Forwarded-Site
X-Cache-Id
X-Location
X-Generated-On
X-Generated-By
VNS-Cache
X-Cluster
X-Geo-Header
X-Gzip
X-HN
X-DefElseHash
X-Hnp-Log
X-Hash
X-Level-Front-Cache
X-Clientip
X-Micro-Cache
X-Developers
X-Wikidot-Backend
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-DefHash
X-Cache-Tags
X-Wikidot-Static-Cache
X-Nginx-Cache-Key
X-Worker
X-Old-Content-Length
X-Origin
X-Gen-Mode
X-Req
X-Ckpd-Fst-Backend
Server-Hostname
Server-Host
Esi-Enabled
Sever-Int
CPC-Age
CPC-Cache
Server-Ext
Fastcgi-Cache-TTL
PB-RID
PB-PID
PFcat
Location
IsBot
Cf-Device-Type
TDXMobile
Locid
Arc-Version
Vix-Hermes-Req-Id
X-Dc
VNS-Age
C-Via
True-Client-Country-4JS
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
Thinkindot-Control
X-M-Log
X-M-Reqid
X-NCache
AMP-Access-Control-Allow-Source-Origin
Server-Info
X-Ratelimit-Remaining
X-Amz-Meta-S3cmd-Attrs
X-Platform
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
AKAMAI
X-Owner
X-Fmm-Version
Arc-Country
X-Fetched-On
Svr
V-Age
CacheControlHeader
X-FC-Vary-Parameters
X-Auto-Login
Wxu-Next-Region
X-Vdms-Path
X-WADP-Cache
Wxu-Next-Commit
We-Hiring
X-Irp-Debug
X-Goog-Meta-Goog-Reserved-File-Mtime
X-GoCache-CacheStatus
X-Qnm-Cache
X-Generated-In
Wxu-Next-Hostname
X-GeoIP
X-GeoIP-City
NM-Fastcgi-Cache
X-Eu-Site
Pagetype
L5d-Success-Class
X-Planisys-CDN-TTL
Release
X-Mvc-Supplant-Cachable
Mail-Subject
X-Request-Host
X-CGP
Memcached
X-Clara-WADP
HA-Ipaddr
X-Csrf-Jwt
Ha-Gx-Prefs
DSUID
X-Sucuri-ID
X-Policy
Gh-Request-Id
X-Skip-Cache
X-Unique-ID
Webserver
XServer
NtCoent-Length
X-Qloud-Router
X-V-Cache
DataCenter
X-Via-Poph
X-Via-Popn
X-Servedbyhost
X-Mvc-Supplant-OutputCached
X-HS-Content-Campaign-Id
X-Platform-Cluster
X-Render-Time
X-LSADC-Cache
X-Via-Popv
Kp-EeAlive
MIME-Version
X-Rocket-Nginx-Serving-Static
X-Platform-Router
Cache-Hits
X-Platform-Processor
X-Srv
X-SD-PageType
X-Cache-Remote
X-Cache-Var
X-Cache-Var-Map
X-Zone
Environment
X-User
Who
X-Cache-Ttl
X-API-Version
X-Datadog-Trace-Id
X-Gdpr
X-Nyt-Route
X-Origin-Time
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-NodeID
X-PF-Uncompressing
X-BBC-Origin-Response-Status
X-PJAX-URL
X-Vc
X-Wa
X-NC
X-Traceid
X-ID
X-Webkit-CSP-Report-Only
X-Minions-Version
X-App
Server-ID
X-Via-Ucdn
X-Varnish-Url
WebServer
X-Varnish-Ttl
X-Cache-Config
X-LB-ID
X-VCL-Version
Candidate-Md5Url
X-Pod-Name
Cluster
X-Internal-Host
X-Server-IP
X-Refresh
My-App
Powered-By-ChinaCache
X-TIME
Time
X-Webkit-Csp
HostName
Memory
X-Pass-Why
X-CACHE-KEY
X-ZONE
X-Newrelic-Synthetics
Datacenter
Onion-Location
Geoip-Latitude
X-LI-Proto
X-NewRelic-App-Data
N-Cache
Web-Mar-Region
X-Esi
GeoIp-Country-Code
X-Edge-Pop
X-ElasticPress-Query
X-CLOUD-TRACE-CONTEXT
Resin-Trace
X-OVcl
Geo-Info
X-OVcl-Cache
Servername
X-Tb-Optimization-Total-Bytes-Saved
X-TX-ID
X-AB
X-VHOST
Hostname
X-Origin-Response-Time
X-Akamai-Pragma-Client-IP
Cf-Bgj
X-Varnish-Cacheable
X-Backend-TTL
Ohc-File-Size
Tcn
X-TraceId
X-Dynatrace
X-CACHE-AGE
WWW-Authenticate
X-HITS
Magicmarker
X-Tt-Logid
X-Geo
X-Fpc
CDN
X-EIG-Tracking-Id
LB
X-TIM-N
X-MSEdge-Flight
X-Dispatcher-Server
Cdn
GeoIP-Country-Code
X-Varnish-Beresp-TTL
X-Tid
X-Li-Proto
X-MSEdge-Features
X-Method
Redirect-Candidate
X-NODE
X-Correlation-ID
X-Up
X-Dynatrace-Js-Agent
Tracecode
X-MG-S
X-Wix-Viewer-Type
Proxy-Connection
DB-Nickname
X-HostName
X-Cache-Date
X-IP
Pramga
X-Request-Start
Is-Us
GeoIP-Latitude
Ssr
Cf-Ipcountry
X-Sn-Servicetimems
X-NGINX-Cache
X-Amz-Meta-Cb-Modifiedtime
X-Vcl-Version
X-Fastly-Backend-Reqs
X-Cdn-Origin
X-HS-Status
Lb
X-CSRF-TOKEN
X-Cs
CF-Cached-On
W
Sid
X-COUNTRY
X-APP
X-Node-Id
Server-Id
X-Core-Mission
X-Provided-By
X-Nc
X-UnsetCookies
X-Oracle-Dms-Ecid
X-Cache-Expires
X-Trv-Group
X-WA
X-ND-Cache
X-ServerName
X-Webkit-Csp-Report-Only
Cteonnt-Length
X-Lb-Id
X-DynaTrace-JS-Agent
CloudFront-Viewer-Country
X-Reqid
X-FORWARDED-FOR
URI
X-VC
X-Via-CDN
X-Pjax-Url
WZWS-RAY
Env
X-Check-Cacheable
Ohc-Cache-HIT
CountryCode
X-CCDN-CacheTTL
X-CCDN-Origin-Time
WP-Super-Cache
X-Via-PopV
X-Via-PopH
X-Via-PopN
X-Region-Sid
X-Sucuri-Cache
X-Hcs-Proxy-Type
X-SERVER-NAME
X-Fastly-Request-Id
X-Cache-Backend
X-Cache-Status-Check
X-Moov-T
X-Moov-Xdn-Version
Shield-Pop
X-CUA
Xc-Version
X-SN
X-Pf-Uncompressing
X-IN-APIGATEWAYSSL
X-ServedByHost
Mime-Version
X-Pad
X-IN-APIGATEWAY
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Acquia-Application-Trace
Viewtype
X-RAMCache
X-LiteSpeed-Cache-Control
Rt-Fastcgi-Cache
Server-Ttl
VivaBuild
X-Acquia-Site
X-Cache-ASPX
X-Ig-Push-State
CACHE
EpKe-Alive
X-Varnish-Authentication
X-Fastly-Cache-Hits
X-Contensis-Viewer-Groups
User-Agent
X-Edge-POP
X-Amz-Meta-Opti
FSS-Cache
X-Yottaa-OS
Vha6-Origin
X-Cdn-Request-ID
X-Swift-Error
X-SB
X-RPM
X-RPS
X-RSL
X-Webstats-RespID
X-DSS
X-Action
X-DB
X-DI
Ohc-Response-Time
X-DW
X-Dw-Trace-Id
X-StackifyID
Xet-Cookie
X-Cdn-Forward
X-Oss-Hash-Crc64ecma
X-Nginx-Upstream-Cache-Status
X-Dispatch
On-Server
X-Oss-Object-Type
X-Oss-Server-Time
X-Oss-Request-Id
HIT
X-Parent-Response-Time
X-Oss-Storage-Class
Content-Style-Type
X-MiniProfiler-Ids
Machine
X-ElasticPress-Search
X-CF-Powered-By
Req-ID
Hit
X-TH-Server
Content-Script-Type
ServerName