Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-RAY
CF-Cache-Status
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
X-XSS-Protection
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
Alt-Svc
X-Served-By
X-Xss-Protection
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Permitted-Cross-Domain-Policies
X-Request-ID
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
P3p
X-Content-Security-Policy
X-Iinfo
X-FRAME-OPTIONS
Status
Content-Encoding
Feature-Policy
X-AspNetMvc-Version
X-CDN
X-Envoy-Upstream-Service-Time
Upgrade
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Access-Control-Max-Age
X-Via
Keep-Alive
X-Ws-Request-Id
Request-Context
X-Robots-Tag
Server-Timing
X-AH-Environment
X-Server
X-Hacker
X-Age
X-Ua-Compatible
X-Turbo-Charged-By
X-Proxy-Cache
X-Dns-Prefetch-Control
X-Server-Powered-By
X-Cache-Group
X-Backend
Host-Header
X-Amz-Request-Id
EagleId
X-Nginx-Cache-Status
X-Amz-Id-2
Report-To
X-LiteSpeed-Cache
X-Rq
X-UA-Device
X-Varnish-Cache
X-Page-Speed
Grace
X-Swift-SaveTime
X-Swift-CacheTime
X-Pingback
Ali-Swift-Global-Savetime
X-Device
EagleEye-TraceId
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Vhost
NEL
X-Amz-Version-Id
Cf-Railgun
X-OneAgent-JS-Injection
X-Host
X-Dispatcher
X-Server-Id
X-CST
Allow
X-Node
X-Cache-Spec
Surrogate-Control
Request-Id
X-Backend-Server
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Webkit-CSP
Accept-CH
X-Readtime
X-WebKit-CSP
X-Response-Time
X-Akam-SW-Version
Xkey
X-HW
X-Country
Accept-Ch-Lifetime
X-Ac
X-Application-Context
Content-Location
X-Language
X-Ruxit-JS-Agent
X-Cloud-Trace-Context
MS-Author-Via
X-Template
Rating
X-Cache-Lookup
X-Url
X-Mod-Pagespeed
X-B3-TraceId
Edge-Control
X-TtlSet
X-Vname
X-PC
X-Clacks-Overhead
X-ESI
X-MS-InvokeApp
X-Trace
X-GitHub-Request-Id
X-Content-Type
Fastly-Restarts
X-Varnish-TTL
X-Origin-Cache
X-Cnection
X-Rack-Cache
Accept-CH-Lifetime
X-ASPNET-VERSION
X-D2id
X-Country-Code
X-Kinja
X-Kinja-Build
X-Exp-Id
X-Use-Magma
X-Exp-Variant
X-Kinja-Server
X-Cdn-Fetch
X-GoogleNews-Bot
X-Kinja-Revision
Verso
X-VARITI-CCR
Arr-Disable-Session-Affinity
X-Goog-Hash
X-FastCGI-Cache
Accept-Ch
X-Server-Name
X-Vcap-Request-Id
X-Cached
X-Buckets
X-Navigation-Version
Cache-Tag
X-Client-IP
X-Amz-Rid
Service-Worker-Allowed
X-Abt-Application-Version
X-Powered-By-Plesk
X-ORACLE-DMS-ECID
RTSS
X-Fastly-Request-ID
X-Ttl
Access-Control-Request-Method
X-Sol
X-Middleton-Display
Display
Pagespeed
Response
X-Middleton-Response
X-MSEdge-Ref
X-Powered-CMS
X-Element-Page-Cache
X-Cache-TTL
Public-Key-Pins
X-NF-Request-ID
X-Dw-Request-Base-Id
X-Upstream
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Version
X-Server-ID
X-Px
X-Edge
S
X-Kinsta-Cache
X-Edge-Location-Klb
X-LLID
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
Realpath
X-Accel-Expires
SPIisLatency
SPRequestDuration
X-TTL
SPRequestGuid
X-SharePointHealthScore
X-T
X-Jurisdiction
X-HP-Webp
X-Oneagent-Js-Injection
X-MCACHE
X-Mid
X-ECACHE
X-PressLabs-Stats
X-Instrumentation
X-Kraken-Loop-Name
X-Content-Security-Policy-Report-Only
X-Server-Lifecycle-Phase
X-Kraken-Routeconfig-Destination
X-Forwarded-Proto
X-Shield-Request-Id
X-Correlation-Id
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
Edge-Cache-Tag
X-Recruiting
Charset
Fastcgi-Cache
X-DynaTrace
X-Amz-Server-Side-Encryption
X-Ruxit-Js-Agent
TP-Cache
TP-L2-Cache
X-ORACLE-DMS-RID
X-Mg-S
X-Content-Digest
Nginx-Cache
X-Cache-Key
X-Id
X-Request-Processing-Time
X-Request-Received
Filters
X-Ezoic-Cdn
TCN
X-Release
Front-End-Https
Server-Node
X-Logged-In
Alternate-Protocol
Cache-Tags
X-Forwarded-For
Content-MD5
X-XRDS-Location
Fusion-Source
Fusion-Template-Id
Fusion-Component-Id
Fusion-Content-Id
Fusion-Content-Source
Fusion-Deployment-Id
X-Amzn-Trace-Id
X-Geo-Country
X-Origin-Upstream-Status
X-Litespeed-Cache
X-Hostname
X-Origin-Server
X-Grace
Server-Name
X-Protected-By
X-F-Cache
X-Www-Served-By
Cleartype
X-Rid
X-Amz-Replication-Status
X-Az
Host
X-Contextid
X-Activity-Id
X-AppVersion
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Generation
X-Goog-Metageneration
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Combine-CSS
X-RateLimit-Remaining
X-Debug-Info
X-WebKit-CSP-Report-Only
X-LB-Cache
Section-Io-Cache
X-Frontend
X-NWS-LOG-UUID
MicrosoftSharePointTeamServices
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Ser
X-Git-Hash
X-Page-Id
X-Cache-Age
X-Upgrade-Enabled
X-Respond-Thread
Accept-Charset
X-Aspnetmvc-Version
X-Content-Options
X-Daa-Tunnel
X-Hits
X-Source
X-Varnish-Age
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
X-DIS-Request-ID
X-XRDS-LOCATION
Paypal-Debug-Id
Access-Control-Allow-Method
X-Mobile-URL
X-Varnish-Backend
ServerID
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Varnish-Grace
AR-CACHE
AR-ATIME
AR-Request-ID
AR-PoweredBy
X-B-Cache
X-VCache
Ar-Sid
X-Signature
Viewport
X-Flags
X-Cache-Action
X-Aspnet-Duration-Ms
X-FB-Debug
X-Is-Crawler
X-Providence-Cookie
X-Request-Guid
Healthy
Payment
X-Route-Name
X-Fastcgi-Cache
X-TT
X-Whom
X-B3-Sampled
Node
X-CACHE-GROUP
X-AOL-HN
X-App-Environment
X-N
X-Seen-By
Version
X-Type
X-Mobile
X-Load-Cache
Fastcgi-Useragent
DC
DynaTrace
X-Request-Handler-Origin-Region
X-Microsite
X-Yandex-Sdch-Disable
MS-CV
X-HTML-Minification-Powered-By
X-Cache-Expired-At
X-Distributor
Retry-After
X-Tt-Trace-Tag
X-Cache-Control
X-Tt-Trace-Host
Filterid
X-Ab
Frame-Options
X-IPLB-Instance
X-User-Agent
SRV
X-Original-Request-Id
X-Response-Served-From
X-Jobs
X-Instance
X-UUID
X-Real-IP
X-IPS-LoggedIn
X-Varnish-Server
Refresh
X-RemovedCookies
X-ProcessESI
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Tumblr-User
X-Debug-IsPreview
X-Device-Type
X-Debug-IsConnected
X-Adobe-Loc
Access-Control-Request-Headers
Ms-Operation-Id
X-Adobe-Content
X-Content-Powered-By
X-RTag
X-Region
X-Proxy-Cache-Status
X-Cluster-Name
X-Proxy
VIX-Pulpo-Node
NGB
Uber-Trace-Id
VIX-Pulpo-Upstream-Status
X-Cache-Time
X-Cacheable-TTL
X-B
X-Page-View
X-Framework
X-G
X-Debug
X-FireWall-Port
X-FW-Hash
X-FW-Dynamic
X-Accel-Buffering
X-FW-Server
X-Vgn-Hpd-Reason
X-FW-Serve
X-FW-Type
X-Zen-Fury
X-FW-Static
Countrycode
Cache
X-Time
Section-Io-Origin-Status
Section-Origin-Responded
X-Wix-Request-Id
Section-Io-Origin-Time-Seconds
Section-Io-Id
X-RateLimit-Limit
X-NGENIX-Cache
Cache-Status
X-Mg-Request-UUID
X-App-Version
X-Azure-Ref
X-Nginx-Cache
X-Oracle-Dms-Rid
X-Is-Bot
X-Rendered-As
X-Cache-Rule
Surrogate-Key
X-CDN-Forward
X-Drupal-Cache-Tags
X-Ms-Version
Country
X-Ms-Request-Id
X-Node-Name
S-Cnection
X-Cache-Hit
X-EdgeConnect-Cache-Status
X-App-Server
Referer-Policy
Liferay-Portal
SD-X-WS
Eomportal-Instance
X-Environment-Context
X-L-Path
Amp-Access-Control-Allow-Source-Origin
X-Cache-Operation
X-TA-CDN-Provider
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-SaId
X-Proxy-Build
From-Origin
X-Varnishpool
Meta-Geo
CF-IPCountry
X-JoinUs
X-UPSTREAM-Address
Selected-Fe
X-Drupal-Cache-Contexts
X-RN-RSRV
X-Timing-Wait
X-Tumblr-Pixel-2
X-ES-SERVER
X-Sorting-Hat-ShopId
X-ShardId
Protected
X-Shopify-Stage
X-Varnish-Beresp-Grace
X-ShopId
X-Sorting-Hat-PodId
X-R9-Blue-Green-Version
X-S-Maxage
X-Backend-Host
X-Cache-TTL-Remaining
X-Alternate-Cache-Key
X-Varnish-Hostname
X-PHP-Backend
X-Endurance-Cache-Level
X-Cache-Server
X-Xfnlog-Site
X-TNCMS
X-Request-Time
X-No-Session
X-GG-Cache-Date
X-Via-Fastly
X-Pubstack
X-Storefront-Renderer-Rendered
X-Handled-By
X-Loop
Fastly-SSL
Cache-Name
Cache-Tv-Group
Azure-Version
Azure-SlotName
Azure-InstanceId
Azure-SiteName
X-Server-W
Azure-RegionName
TWC-GeoIP-Country
X-NYM-Debug-Backend
X-ProxyCache-Status
Webcakes-App-Version
Webcakes-App-Name
TWC-Privacy
X-Adobe-Source
X-VWS-Id
X-LAGOON
X-Proto
X-LJ-Flow-ID
Webcakes-Region
X-Origin-Hint
TWC-Locale-Group
TWC-GeoIP-LatLong
X-PCL
X-OCL
ServedBy
Property-Id
X-ProxyCache-Key
X-Human
X-BYPASS-REASON
X-Be
X-AWS-Id
TWC-Connection-Speed
TWC-Device-Class
Apigw-Requestid
X-Backend-Name
X-Format
Akamai-GRN
X-Access
Decoy-Debug-Status
X-SayCDN-TTL
Decoy-Debug-TTL
X-Section
X-Origin-Date
X-Hl-Ver
Decoy-Debug-Key
Country-Code
X-RCS-CacheZone
X-Revision
X-Say-TTL
X-Say-Cacheable
X-ApacheServer
Mn-Server-Ip
X-Akamai-Edgescape
X-FB-TRIP-ID
X-Sql-Duration-Ms
X-Labrador-Cache-Channel
X-Status
Xserver
X-PHP-Host
X-PERF
X-Sql-Count
X-UA-Device-Type
X-Hyper-Cache
X-Uri
X-Hosted-By
X-Redis-Cache
X-Cache-PHP
Nel
X-Aws-Lambda-Call-Status
AMP-Access-Control-Allow-Source-Origin
X-Rule
X-Cache-Type
X-Web-Node
X-ATG-Version
X-FW-Version
X-Trace-Id
X-Ua-Device
X-WA-Info
X-TT-LOGID
X-B3-SpanId
X-MP-GENERATED-AT
X-ServerID
X-Time-Microsecs
X-Parallel-Accel
X-Content-Age
X-CSRF-Token
X-Tumblr-Pixel-3
X-Cached-By
GEO-INFO
X-Soup
Count-Hit
X-Dc
Backend
X-Datadome
X-Cache-Enabled
X-Akamai-Transformed
X-Edge-Location
X-Cluster-Node
OT-Force-Account-Verify
X-Detected-As
X-Mode
X-Azure-Ref-OriginShield
X-Varnish-Cache-Hits
X-Cache-Host
X-Varnish-Ttl
X-Info
X-CS
X-Microcachable
X-HP-Trace-Id
X-Varnish-Beresp-Status
X-Bc-Bl
X-Generation-Time
Web-Mar-Node
Cross-Origin-Opener-Policy
X-Servername
X-Varnish-Hits
X-APP-VERSION
X-Cache-NGX
X-Amzn-Remapped-Content-Length
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Debug-Cache
X-Proxied
X-Platform
X-Zipkin-Id
X-Unique-ID
X-Routing-Service
X-Storage
SID
X-SRV
X-Varnish-Beresp-Ttl
DataCenter
X-Extlb
Who
X-Origin-TTL
X-Magnolia-Registration
X-Origin-CC
X-B3-Traceid
X-ScT
X-Service
MD5-Digest
M-TraceId
X-NAPM-TraceId
S-Rt
X-Ua
X-Rojux
X-S
X-S-Cookie
X-CACHE-KEY
X-Session-Fingerprint
X-SRCache-Key
X-Air-Hostname
X-Thanos
Rendered-Blocks
Req-Svc-Chain
X-Air-Source
X-Air-Trace-Id
Meta-Geo-Continent
X-Location
Mobile-Detection-Method
X-Locale
X-Rewrite-Enabled
X-Request-URI
Content-Disposition
CDCHOST
X-PBS-Appsvrname
Cache-Host
X-Processor
CDN-Cache
CDN-CachedAt
CDN-RequestId
CDN-Uid
CDN-RequestCountryCode
CDN-PullZone
CDN-EdgeStorageId
BehaviorPad-Version
DCR-Decision-By
Fastcgi-X-Cache-Version
Expiry
Fastly-Backend-Name
X-Ratelimit-Reset
Host-ID
A
X-PAYTM-SRV-ID
Apple-News-Services-Request-Url
DCR-Processing-Time-Ms
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Handled
X-Level-Front-Cache
Odigeo-Trace-Id
Ec-Rule-Version
X-Core-Value
X-Connection-Hash
X-Application
X-Aicache-OS
X-Aed
X-Cache-Bucket
X-A-Dcw
X-A-Dgt
X-A-Wwc
X-ARC
X-B-Cookie
X-Cache-NE
X-Bip
X-Generated-On
X-Geo-Header
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Cms-Context
X-NWS-UUID-VERIFY
X-BCube-Filmed-By
X-A-Ccd
X-A-Dam
T-Server
X-Vtex-Remote-Cache
Server-Info
X-Destination
Surrogated-Key
X-Epic-Correlation-Id
State
X-External-Request-Id
Upgrade-Insecure-Requests
X-From
X-Developer
X-VG-WebServer
X-A
X-Vtex-Processado-Em
X-Vdms-Path
X-VG-WebCache
X-D
X-Vdms-Version
X-Cache-Grace
Source
Cmstype
X-Cache-Debug
X-Envoy-Decorator-Operation
Esi-Enabled
X-Clientip
X-Developers
X-Gamma-Serve
L
X-HN
UCS
X-Hash
X-Has-Esi
Memcached
X-Is-Gdpr
Cmsid
X-JWT-State
PFcat
Pagetype
Origin
Location
X-NU-AKA-ACS-Version
Fastly-SWR
Fastly-SIE
Fastly-Drupal-HTML
X-Branch-Name
X-Origin
Gh-Request-Id
X-GoCache-CacheStatus
Server-Host
X-Backend-State
Kp-EeAlive
Fastcgi-Cache-TTL
X-Platform-Server
X-Scheme
X-Served-From
X-Rocket-Build-Number
X-Request-UUID
X-Rebelmouse-Surrogate-Control
Path
X-DataDome
Cross-Origin-Window-Policy
X-TrackingId
X-Var-Ttl
X-VarnishDD-TTL
X-VG-TLSProxy
X-Sigma
X-Sigma-Backend
X-Rebelmouse-Cache-Control
X-Cache-Ttl
AKAMAI
CacheControlHeader
Url
X-Via-JSL
X-Proxy-Upstream
X-AIR-PT
X-Tb
User-Cache-Control
X-Forwarded-Host
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
Cf-Device-Type
X-Thinkindot-L3
Wxu-Next-Commit
X-Generated-In
Wxu-Next-Hostname
X-VC-Cache
X-Generated-By
X-Date
Wxu-Next-Region
Vix-Hermes-Req-Id
True-Client-Country-4JS
X-CGP
X-Forwarded-Site
X-WADP-Cache
Content-Secure-Policy
NGX
DSUID
X-SVT-ORM-RULES
X-Cluster
Thinkindot-CacheControl
TDXMobile
Thinkindot-Control
X-Device-Os
X-Accel-Expires-Debug
X-Clara-WADP
Thinkindot-CacheControl-Type
X-Cache-Tags
X-Csrf-Jwt
X-Cache-Info
Svr
C-Via
X-SVT-ORM-VERSION
Platform
HA-Ipaddr
Ha-Gx-Prefs
X-VHOST
X-Req
Is-Eu
L5d-Success-Class
X-Request-Host
X-Shop-Environment
X-Origin-Expires
X-Owner
X-Policy
X-Fastly-Backend
X-Fastly-Cache
Arc-Version
Arc-Country
X-Eu-Site
X-Tenant
Adler-Geo
X-DPWN-IS-SECURE
X-Orig-Expires
X-EC-Lua
Pics-Label
X-Amz-Meta-S3cmd-Attrs
X-LI-UUID
X-Li-Pop
X-Forwarded-Path
X-Variation
X-Li-Fabric
PB-PID
PB-RID
X-Site-Version
X-Sucuri-ID
X-Fmm-Version
X-Loc
X-Men
NM-Fastcgi-Cache
X-Micro-Cache
X-VServer
X-Nginx-Cache-Key
X-Gen-Mode
X-Skip-Cache
X-FC-Vary-Parameters
X-User
X-Varnish-Remaining-TTL
X-SIPLIST1
X-Minions-Version
X-Slack-Backend
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Mvc-Supplant-Cachable
X-Old-Content-Length
X-PF-Uncompressing
X-Qloud-Router
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Varnish-Url
X-Irp-Debug
Server-Hostname
Server-Ext
Sever-Int
X-Fetched-On
X-GeoIP
Release
X-Wikidot-Static-Cache
X-Hnp-Log
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Viewer-Country
X-Wikidot-Backend
X-GeoIP-City
X-Gzip
We-Hiring
X-Block-Status
X-Cache-Id
IsBot
Locid
V-Age
Mail-Subject
Webserver
Cache-Key
X-Srv
X-DefElseHash
X-DefHash
X-Ratelimit-Limit
X-Esi-Check
NtCoent-Length
X-Planisys-CDN-TTL
X-HS-Content-Campaign-Id
Cache-Hits
X-Planisys-CDN-Rules
CPC-Age
X-Planisys-CDN-Cache
X-Via-NSCOPI
X-Ftr-Request-Id
CPC-Cache
VNS-Cache
VNS-Age
X-GEO
X-Pass-Why
X-Conf
X-Mvc-Supplant-OutputCached
X-Unique-Id
My-App
Powered-By-ChinaCache
X-Via-Poph
X-Via-Popn
X-Via-Popv
X-TX-ID
X-Vc
X-Zone
MIME-Version
X-Ratelimit-Remaining
X-BBC-Edge-Cache-Status
X-PJAX-URL
X-Ckpd-Fst-Backend
X-Worker
X-Refresh
XServer
X-Servedbyhost
X-NC
X-Auto-Login
X-LB-ID
X-Internal-Host
Memory
Time
Geo-Info
X-ID
X-DC
X-LSADC-Cache
X-OVcl-Cache
X-OVcl
X-V-Cache
X-NCache
WebServer
X-NewRelic-App-Data
X-TraceId
Cf-Bgj
Server-ID
X-ZONE
X-Rocket-Nginx-Serving-Static
X-Render-Time
X-Backend-TTL
X-M-Reqid
X-TIME
X-Qnm-Cache
X-Traceid
X-M-Log
X-Webkit-Csp
Magicmarker
HostName
X-Platform-Cluster
X-Platform-Router
X-Platform-Processor
X-Newrelic-Synthetics
X-Tx-Id
X-Cache-Remote
DB-Nickname
GeoIp-Country-Code
X-SD-PageType
X-Wa
Geoip-Latitude
X-Geo
Hostname
X-Dispatcher-Server
X-Datadog-Sampling-Priority
Environment
X-App
X-Datadog-Parent-Id
X-Method
X-Datadog-Trace-Id
X-Dynatrace
X-Webkit-CSP-Report-Only
X-BBC-Origin-Response-Status
Resin-Trace
X-Gdpr
X-API-Version
X-Cache-Config
X-Nyt-Route
X-NodeID
X-Tb-Optimization-Total-Bytes-Saved
X-CLOUD-TRACE-CONTEXT
X-Origin-Time
X-VCL-Version
X-Via-Ucdn
X-IP
Ssr
X-Pod-Name
X-Edge-Pop
Cluster
X-Server-IP
X-Correlation-ID
X-Cache-Var-Map
X-Origin-Response-Time
X-Cache-Var
X-Li-Proto
Candidate-Md5Url
X-Akamai-Pragma-Client-IP
Ohc-File-Size
Tcn
X-Nc
X-MSEdge-Features
X-MSEdge-Flight
X-HITS
X-LI-Proto
X-CACHE-AGE
LB
X-Varnish-Beresp-TTL
X-Trv-Group
Datacenter
N-Cache
Web-Mar-Region
X-ElasticPress-Query
X-Vcl-Version
Cf-Ipcountry
X-DynaTrace-JS-Agent
X-APP
X-Via-CDN
X-Node-Id
X-NODE
X-Ua-Browser
X-Content
X-AB
Env
X-ND-Cache
X-Wix-Viewer-Type
Onion-Location
X-HostName
X-ServerName
X-Reqid
GeoIP-Latitude
GeoIP-Country-Code
X-Fastly-Request-Id
X-Cs
X-WA
CDN
Servername
X-EIG-Tracking-Id
Server-Id
X-Varnish-Cacheable
Cdn
Proxy-Connection
X-HS-Status
WWW-Authenticate
CF-Cached-On
WZWS-RAY
X-Cdn-Forward
X-Dynatrace-Js-Agent
Sid
Viewtype
VivaBuild
Rt-Fastcgi-Cache
X-MG-S
X-NGINX-Cache
X-Fastly-Backend-Reqs
X-FTR-Request-ID
Machine
Lb
Cteonnt-Length
X-Lb-Id
X-Check-Cacheable
X-Pjax-Url
X-ServedByHost
X-Fpc
X-URL
Redirect-Candidate
X-TIM-N
X-Tid
X-Request-Start
X-Esi
X-Xrds-Location
Ohc-Cache-HIT
X-CSRF-TOKEN
On-Server
X-IN-APIGATEWAYSSL
X-VC
X-Up
FSS-Cache
X-Via-PopN
X-Via-PopV
X-IN-APIGATEWAY
X-Via-PopH
Tracecode
X-Cache-Backend
Mime-Version
X-ECache
Pramga
X-Cache-Date
X-Amz-Meta-Cb-Modifiedtime
URI
CountryCode
Is-Us
X-Swa-Ws
Shield-Pop
X-SN
Server-Ttl
X-Sn-Servicetimems
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Cache-Status
X-Cdn-Origin
X-FTR-Backend
X-Varnish-Authentication
X-FTR-DC
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Fastly-Cache-Hits
X-LiteSpeed-Cache-Control
X-Oss-Storage-Class
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Object-Type
Xc-Version
X-Air-Pt
X-FORWARDED-FOR
X-Swift-Error
X-Vcache
X-FTR-Realm
X-Oss-Hash-Crc64ecma
CACHE
X-Country-Code-Real
Srv
X-Core-Mission
X-Dw-Trace-Id
X-StackifyID
X-Yottaa-OS
X-RPM
X-RPS
X-RSL
W
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
X-Acquia-Site
X-Acquia-Application-Trace
Warning
Xet-Cookie
X-ElasticPress-Search
X-DW
X-DSS
ServerName
Vha6-Origin
Content-Style-Type
Ohc-Response-Time
X-Webstats-RespID
CloudFront-Viewer-Country
X-SB
Content-Script-Type
WP-Super-Cache
X-DB
X-DI
X-Action
X-Provided-By
X-Pf-Uncompressing
X-RAMCache
X-Pad
X-CCM
X-B3-Spanid
X-Cdn-Request-ID
PICS-Label
Req-ID
X-Cache-Expires
X-FPC
X-Mg-Request-Id
X-TH-Server
X-FTR-Expires
X-C
X-Snapshot-Date
X-MiniProfiler-Ids
X-Hcs-Proxy-Type
X-CUA
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-Tt-Logid