Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Accept-Ranges
Link
Cf-Request-Id
CF-Cache-Status
CF-RAY
ETag
Pragma
X-XSS-Protection
Expect-CT
X-Powered-By
Via
X-Cache
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
P3P
X-Served-By
X-Download-Options
X-Timer
Access-Control-Allow-Headers
X-Xss-Protection
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
P3p
X-DNS-Prefetch-Control
X-Cache-Status
X-Generator
X-Check
X-Cacheable
X-Request-ID
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Iinfo
Feature-Policy
X-Content-Security-Policy
Content-Encoding
X-Envoy-Upstream-Service-Time
X-CONTENT-TYPE-OPTIONS
Status
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
X-CDN
X-AspNetMvc-Version
Upgrade
X-XSS-PROTECTION
X-Via
CF-Ray
Access-Control-Max-Age
Server-Timing
X-Akamai-Path-Stats
X-Ws-Request-Id
X-Cache-Group
X-Turbo-Charged-By
Keep-Alive
Request-Context
X-Backend
EagleId
X-Dns-Prefetch-Control
X-Robots-Tag
X-Age
X-Server
X-Amz-Request-Id
X-AH-Environment
Host-Header
X-Amz-Id-2
X-Proxy-Cache
X-UA-Device
X-Hacker
Grace
X-Rq
X-Server-Powered-By
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Vhost
X-Dispatcher
X-Amz-Version-Id
X-Ua-Compatible
Allow
CONTENT-SECURITY-POLICY
X-LiteSpeed-Cache
EagleEye-TraceId
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Nginx-Cache-Status
X-OneAgent-JS-Injection
X-Device
X-WebKit-CSP
X-Cache-Spec
Cf-Railgun
X-Host
X-Page-Speed
X-Node
X-Server-Id
X-Aws-Lambda-Call-Status
Cf-Edge-Cache
X-CST
X-Pingback
Surrogate-Control
Request-Id
X-Backend-Server
X-Readtime
X-Akam-SW-Version
Accept-CH
X-Response-Time
X-Cache-Lookup
X-HW
Xkey
X-Application-Context
Accept-CH-Lifetime
Content-Location
Rating
X-Cloud-Trace-Context
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Trace
X-Url
X-Country
X-Ruxit-JS-Agent
Fastly-Restarts
Accept-Ch
Accept-Ch-Lifetime
X-MS-InvokeApp
X-Rack-Cache
X-Mod-Pagespeed
X-Clacks-Overhead
X-PC
X-TtlSet
X-Vname
RTSS
Edge-Control
X-VARITI-CCR
X-Amz-Server-Side-Encryption
X-Server-Name
X-ESI
X-Varnish-TTL
Cache-Tag
X-ASPNET-VERSION
X-Content-Type
X-B3-TraceId
X-Vcap-Request-Id
X-FastCGI-Cache
X-Dw-Request-Base-Id
X-Kinja-Build
X-Kinja-Revision
X-GoogleNews-Bot
X-Exp-Variant
X-Cdn-Fetch
X-Exp-Id
X-Kinja-Server
X-Kinja
X-Use-Magma
X-Edge
X-Amz-Rid
X-Px
Public-Key-Pins
X-D2id
X-Cnection
X-Ser
X-Navigation-Version
X-Ac
Display
X-Sol
X-Middleton-Display
Pagespeed
X-Element-Page-Cache
X-Powered-By-Plesk
X-Abt-Application-Version
Verso
X-RateLimit-Remaining
X-Version
X-Ttl
X-Client-IP
X-Content-Security-Policy-Report-Only
Arr-Disable-Session-Affinity
X-Litespeed-Cache
X-Cache-TTL
X-Country-Code
Service-Worker-Allowed
Response
X-Middleton-Response
X-GitHub-Request-Id
X-NF-Request-ID
X-Goog-Hash
Access-Control-Request-Method
SPIisLatency
SPRequestDuration
X-Cached
X-Kinsta-Cache
X-Correlation-Id
X-SharePointHealthScore
SPRequestGuid
AR-SID
AR-PoweredBy
AR-CACHE
X-Edge-Location-Klb
AR-ATIME
AR-Request-ID
X-Powered-CMS
X-Kraken-Loop-Name
X-Instrumentation
X-Server-Lifecycle-Phase
X-Upstream
X-LLID
Edge-Cache-Tag
X-Forwarded-For
X-NWS-LOG-UUID
Content-MD5
X-Cache-Key
X-RateLimit-Limit
Nginx-Cache
X-Id
X-TTL
X-Shield-Request-Id
X-MSEdge-Ref
X-WebKit-CSP-Report-Only
X-ECACHE
MRF-Tech
Mrf-Cache-Status
TCN
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Ruxit-Js-Agent
X-Recruiting
S
X-T
X-Content-Digest
X-Daa-Tunnel
X-B3-TraceId-Primal
X-Webkit-Csp
X-Mg-S
X-Ua-Device
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Jurisdiction
X-HP-Trace-Id
X-HP-Webp
X-DataDome
TP-Cache
TP-L2-Cache
X-Grace
X-Accel-Expires
X-DynaTrace
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Combine-CSS
X-Frontend
MicrosoftSharePointTeamServices
X-Ezoic-Cdn
X-Server-ID
X-Ab
X-Content
X-Yandex-Sdch-Disable
X-Ua-Browser
Front-End-Https
Server-Node
Filters
X-Request-Processing-Time
X-Request-Received
X-Protected-By
X-Origin-Server
X-Distributor
MS-Author-Via
X-PressLabs-Stats
X-Hits
X-Mcache
Fastcgi-Cache
X-Geo-Country
X-LB-Cache
X-Mid
X-Microsite
X-Request-Handler-Origin-Region
X-ORACLE-DMS-ECID
X-Fastly-Request-Id
X-Tt-Trace-Tag
X-ORACLE-DMS-RID
X-Tt-Trace-Host
X-Amzn-Trace-Id
Charset
Cleartype
Host
X-Git-Hash
X-Debug-Info
X-F-Cache
X-Page-Id
X-B3-Sampled
X-Forwarded-Proto
Cross-Origin-Opener-Policy
Cache-Status
X-Cache-Age
X-Seen-By
Realpath
X-Webkit-CSP
X-DIS-Request-ID
Access-Control-Allow-Method
X-Activity-Id
X-AppVersion
X-Az
X-Www-Served-By
X-Ratelimit-Reset
Accept-Charset
Filterid
ServerID
X-Aspnetmvc-Version
X-Nginx-Upstream-Cache-Status
X-Varnish-Age
Pinterest-Version
Pinterest-Generated-By
Cache-Tags
X-Pinterest-Rid
X-Cluster-Name
X-Content-Options
X-Rid
Permissions-Policy
X-Type
X-FB-Debug
Retry-After
X-Varnish-Backend
X-App-Environment
X-Oracle-Dms-Ecid
Server-Name
X-Tb
X-User-Agent
Country
X-Oracle-Dms-Rid
Viewport
X-Varnish-Grace
X-Signature
X-Is-Crawler
X-Route-Name
X-Wix-Request-Id
X-Request-Guid
Paypal-Debug-Id
X-B-Cache
X-Flags
X-Drupal-Cache-Tags
X-Aspnet-Duration-Ms
DC
X-Providence-Cookie
X-Goog-Storage-Class
X-B
X-Goog-Generation
Node
X-TT
X-Goog-Metageneration
X-Whom
X-Upgrade-Enabled
X-Goog-Stored-Content-Length
X-Language
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
X-VCache
X-Kong-Proxy-Latency
X-Amz-Meta-S3cmd-Attrs
X-Kong-Upstream-Latency
Fastcgi-Useragent
X-Origin-Cache
X-Debug
X-Mobile-URL
Protected
X-NWS-UUID-VERIFY
X-N
X-Cache-NGX
X-Amz-Replication-Status
X-Logged-In
Payment
X-Load-Cache
Surrogate-Key
X-XRDS-LOCATION
X-XRDS-Location
X-Midtier
WPO-Cache-Status
Amp-Access-Control-Allow-Source-Origin
WPO-Cache-Message
X-Via-JSL
X-MCACHE
X-Cache-Control
X-Contextid
Count-Hit
Healthy
X-Node-Name
Alternate-Protocol
X-Restarts
X-Mobile
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-NGENIX-Cache
X-Erf-Bev-Bev
Content-Disposition
X-FW-Dynamic
X-FW-Serve
X-FW-Type
X-FW-Static
X-FW-Hash
X-FW-Server
X-Proxy
SD-X-WS
X-Response-Served-From
X-Original-Request-Id
Akamai-GRN
Refresh
X-Revision
X-Jobs
X-G
Url
X-Cache-Time
X-Zen-Fury
X-Page-View
X-Adobe-Loc
X-Adobe-Content
X-Framework
X-Akamai-Request-ID2
X-Real-IP
X-Cache-TTL-Remaining
X-UUID
X-Servername
Uber-Trace-Id
X-Device-Type
VIX-Pulpo-Node
X-Debug-IsPreview
X-Drupal-Cache-Contexts
X-Debug-IsConnected
X-Cacheable-TTL
X-Is-Bot
X-Http-Reason
X-Rendered-As
X-Instance
VIX-Pulpo-Upstream-Status
X-Proxy-Cache-Status
X-Cache-Grace
X-Mg-Request-UUID
X-Template
NGB
X-Varnish-Server
X-Yottaa-Metrics
X-Yottaa-Optimizations
Access-Control-Request-Headers
X-ECache
X-HTML-Minification-Powered-By
X-IPLB-Instance
X-Environment-Context
X-Hostname
X-L-Path
X-B3-Traceid
X-Source
X-EdgeConnect-Cache-Status
Version
Frame-Options
Accept-Language
Countrycode
X-Oneagent-Js-Injection
X-RTag
Ms-Operation-Id
Referer-Policy
MS-CV
Liferay-Portal
X-Datadome
X-Trace-Id
X-Ratelimit-Remaining
X-NYM-Debug-Backend
X-Cache-Hit
X-Cache-Rule
X-App-Server
X-Cache-Expired-At
From-Origin
X-Vgn-Hpd-Reason
Cross-Origin-Window-Policy
Backend
X-Fastly-Request-ID
X-Tumblr-User
X-COUNTRY
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Hosted-By
X-IPS-LoggedIn
X-Nginx-Cache
Content-Secure-Policy
X-Unique-Id
X-FW-Version
X-Fastcgi-Cache
WP-Super-Cache
Upgrade-Insecure-Requests
Meta-Geo
X-Cache-Server
X-UPSTREAM-Address
Section-Io-Cache
Load-Balancing
CF-IPCountry
X-Status
X-RN-RSRV
X-FB-TRIP-ID
X-Labrador-Cache-Channel
X-Cache-Enabled
X-ProcessESI
X-RemovedCookies
X-OCL
X-APP-VERSION
X-No-Session
X-PHP-Host
X-PCL
X-Redis-Cache
Mn-Server-Ip
TWC-GeoIP-Country
TWC-Locale-Group
X-Server-W
X-Section
X-Akamai-Edgescape
X-Access
Webcakes-Region
X-Uri
X-UA-Device-Type
TWC-Privacy
Webcakes-App-Name
Webcakes-App-Version
S-Rt
X-Sql-Count
TWC-GeoIP-LatLong
Property-Id
X-Sql-Duration-Ms
TWC-Device-Class
X-AWS-Id
Azure-SiteName
X-LJ-Flow-ID
X-Cluster-Node
Azure-SlotName
X-VWS-Id
X-Origin-Date
X-PHP-Backend
Azure-Version
Fastly-SSL
X-Region
X-AOL-HN
X-Origin-Hint
X-Via-Fastly
Apigw-Requestid
X-Be
Azure-RegionName
X-Request-Time
Azure-InstanceId
X-Varnish-Cache-Hits
TWC-Connection-Speed
X-Content-Age
X-Mode
X-Format
X-Content-Powered-By
X-Debug-Cache
X-Forwarded-Host
X-Human
X-GG-Cache-Date
X-Cms-Context
X-Cache-Tags
Locale
Eomportal-Instance
X-Adobe-Source
X-ApacheServer
X-Cache-Host
X-BYPASS-REASON
X-Locale
X-PERF
X-Urbn-Site-Id
X-Urbn-Context-Path
X-Xfnlog-Site
X-JoinUs
X-VC-Cache
X-SaId
X-Storage
X-Site-Version
X-ProxyCache-Key
X-Platform-Server
X-ProxyCache-Status
X-Say-Cacheable
X-SayCDN-TTL
X-Say-TTL
X-Nginx-Cache-Key
X-Generated-By
X-Alternate-Cache-Key
X-ShardId
X-ShopId
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-GeoCountry
X-GeoCode
X-Generation-Time
X-NewRelic-App-Data
X-Detected-As
X-Extlb
X-Hl-Ver
X-ServerID
X-Varnishpool
X-Tid
X-Ua
X-Web-Node
X-Routing-Service
X-Backend-Name
X-Proxied
X-Zipkin-Id
X-Cache-Type
X-Handled-By
X-Edge-Location
X-Storefront-Renderer-Rendered
Cache-Tv-Group
CDN-RequestId
CDN-PullZone
CDN-Uid
Ec-Rule-Version
CDN-EdgeStorageId
CDN-CachedAt
X-Timing-Wait
X-Proxy-Build
CDN-Cache
X-Proto
CDN-RequestCountryCode
Selected-Fe
Webserver
X-App-Version
ServedBy
X-Cache-Action
Fastly-Drupal-Html
X-Dc
X-Ratelimit-Limit
Web-Mar-Node
X-CDN-Forward
X-LSADC-Cache
X-GEO
Onion-Location
SRV
X-Parallel-Accel
X-Cached-By
X-Varnish-Hostname
X-IPLB-Request-ID
Cache-Hits
X-Hyper-Cache
Mime-Version
X-Cache-Remote
X-Magnolia-Registration
X-Cdn
X-Rule
SID
X-Cache-Operation
X-Cluster
X-Rewrite-Enabled
X-Varnish-Ttl
X-SRV
X-Air-Trace-Id
X-Air-Hostname
X-Envoy-Decorator-Operation
X-Soup
X-Tt-Logid
X-Air-Source
X-Varnish-Hits
X-Origin-TTL
X-Origin-CC
LB
Xserver
X-Accel-Buffering
X-Pubstack
X-Microcachable
Xet-Cookie
X-Reqid
X-TT-LOGID
Cache
Server-Info
Country-Code
X-MP-GENERATED-AT
DB-Nickname
Source
X-CSRF-Token
X-Buckets
X-Tumblr-Pixel-3
X-TA-CDN-Provider
X-Tumblr-Pixel-2
Decoy-Debug-Key
Decoy-Debug-TTL
Decoy-Debug-Status
X-Request-Host
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Via-NSCOPI
X-B3-SpanId
X-Endurance-Cache-Level
X-Origin-Response-Time
X-Tx-Id
Rendered-Blocks
Cdncip
Sslversion
Cdnsip
BehaviorPad-Version
Surrogated-Key
X-Skip-Cache
A
Cmsid
Cache-Key
Candidate-Md5Url
Host-ID
X-Vtex-Remote-Cache
Mobile-Detection-Method
DCR-Processing-Time-Ms
Expiry
Xc-Version
Meta-Geo-Continent
Fastcgi-X-Cache-Version
NM-Fastcgi-Cache
X-Vtex-Processado-Em
MD5-Digest
X-VG-WebCache
DCR-Decision-By
Lang
Odigeo-Trace-Id
Pramga
Cmstype
X-Conf
X-Forwarded-Path
X-External-Request-Id
X-Ftr-Request-Id
X-Geo-Header
X-Gzip
X-Esi-Check
X-Epic-Correlation-Id
X-Ec-Fail
X-Developer
X-Ec-GeoHdr
X-Shop-Environment
X-Session-Fingerprint
X-Hash
X-HS-Content-Campaign-Id
X-Rojux
X-Processor
X-S
X-S-Cookie
X-ScT
X-PBS-Appsvrname
X-SD-PageType
X-Ig-Push-State
X-NAPM-TraceId
X-Orig-Expires
X-PAYTM-SRV-ID
X-Destination
X-D
X-A-Wwc
X-User
X-Aed
X-AK-Request-ID
X-Application
X-Vdms-Path
X-A-Dgt
X-A
X-A-Ccd
X-Vdms-Version
X-A-Dcw
X-ARC
X-TrackingId
X-Cdn-Srv
X-Cache-NE
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Connection-Hash
X-SRCache-Key
X-Cache-Id
X-TIM-N
X-B-Cookie
X-Tenant
X-BCube-Filmed-By
T-Server
X-A-Dam
X-Time
DynaTrace
Datacenter
X-Newrelic-Synthetics
X-Ms-Request-Id
X-Ms-Version
X-Cache-Status-Check
Machine
X-JWT-State
X-GeoIP
X-Irp-Debug
Memcached
X-Has-Esi
X-Is-Gdpr
Is-Eu
X-Origin-Expires
Fastly-GeoIP-CountryCode
Environment
X-RateLimit-Limit-Second
X-Origin
X-Ad-Defer-Variation
Platform
X-Loop
X-Mvc-Supplant-Cachable
X-Node-Id
Kp-EeAlive
Producers
X-Cache-Info
X-Cache-Bucket
X-CacheTTL
X-Ckpd-Fst-Backend
X-Clara-WADP
Wxu-Next-Commit
Wxu-Next-Hostname
X-Amzn-Remapped-Content-Length
X-Bc-Bl
X-Cache-Backend
Wxu-Next-Region
X-Core-Mission
X-Core-Value
X-DPWN-IS-SECURE
X-Fastly-Cache
X-Fetched-On
X-RateLimit-Remaining-Second
Server-Host
X-Device-Os
State
X-DefElseHash
X-DefHash
X-Developers
X-Fmm-Version
X-NodeID
X-Wix-Viewer-Type
Adler-Geo
X-SVT-ORM-RULES
AKAMAI
X-Worker
X-Scheme
CPC-Age
X-Sigma
X-SVT-ORM-VERSION
X-WADP-Cache
X-Variation
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-V-Cache
X-Varnish-Remaining-TTL
X-TNCMS
X-Via-Ucdn
X-SB
X-Sigma-Backend
VNS-Cache
X-SplitTest
XM
VNS-Age
We-Hiring
CPC-Cache
Mail-Subject
X-Rocket-Build-Number
X-Azure-Ref
X-NCache
X-RCS-CacheZone
X-VarnishDD-TTL
X-VG-TLSProxy
Fastly-Backend-Name
X-Viewer-Country
X-BBC-Edge-Cache-Status
X-Block-Status
X-Auto-Login
Redirect-Candidate
X-Dispatcher-Number
X-Aicache-OS
X-Datadog-Parent-Id
X-Wikidot-Static-Cache
X-Eu-Site
X-Cache-Date
X-CGP
X-Csrf-Jwt
X-Wikidot-Backend
X-Branch-Name
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Cdn-Origin
X-VServer
X-Gdpr
HostName
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Region-Sid
X-Origin-Time
X-Rocket-Nginx-Serving-Static
X-Nyt-Route
X-Request-URI
X-Rebelmouse-Surrogate-Control
X-Planisys-CDN-TTL
X-Proxy-Cache-Info
X-Proxy-Upstream
X-Qloud-Router
X-Pool
X-Policy
X-Platform
X-Pod-Name
X-Minions-Version
X-Served-From
X-Generated-On
X-Thinkindot-L3
X-GeoIP-City
X-Gen-Mode
X-Rebelmouse-Cache-Control
X-ZONE
X-Forwarded-Site
X-Gamma-Serve
X-HN
X-Hnp-Log
X-LAGOON
X-Level-Front-Cache
X-Loc
X-SIPLIST1
X-Slack-Backend
X-Httpd
X-Sn-Servicetimems
X-Varnish-Beresp-Grace
X-Ec-Custom-Error
Thinkindot-Control
Ohc-File-Size
N-Cache
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
L5d-Success-Class
Traceparent
Ha-Gx-Prefs
HA-Ipaddr
IsBot
L
TDXMobile
NGX
Ssr
Req-Svc-Chain
Sever-Int
Server-Ext
Release
PFcat
Origin
Origin-CC
Svr
Origin-EX
Gh-Request-Id
User-Cache-Control
Server-Hostname
Cluster
CloudFront-Viewer-Country
X-Xrds-Location
Apple-News-Services-Handled
CDCHOST
Apple-News-Services-Host
Fastcgi-Cache-TTL
Fastly-SWR
V-Age
Apple-News-Services-Parsed-Url
Fastly-SIE
Vix-Hermes-Req-Id
Apple-News-Services-Request-Url
Web-Mar-Region
Cache-Name
X-WA-Info
X-Micro-Cache
X-R9-Blue-Green-Version
X-Optimistic-Header
DSUID
X-Scale
X-Server-IP
X-Owner
GEO-INFO
X-AIR-PT
X-VC
Pics-Label
X-WP-CF-Super-Cache
X-CS
CDN
X-EC-Lua
X-Refresh
X-WP-CF-Super-Cache-Cache-Control
X-CACHE-KEY
X-From
X-Cache-ASPX
X-Ah-Environment
X-Parent-Response-Time
Path
X-Contensis-Viewer-Groups
X-Webstats-RespID
Ms-Author-Via
X-Tb-Optimization-Total-Bytes-Saved
X-Mvc-Supplant-OutputCached
Env
X-Varnish-Authentication
X-LB-NoCache
X-NC
Servername
X-Location
Ngx.Var.Host
Cache-Host
X-RateLimit-Reset
X-Udemy-Cache-App-Namespace
X-Edge-Pop
Locid
X-Servedbyhost
X-TIME
X-Correlation-ID
X-Proxy-CacheRZ
XkeyRZ
Lb
X-Response-By
X-Srv
X-Generated-In
X-Via-Popv
X-Amz-Meta-Cb-Modifiedtime
X-TraceId
X-Men
X-Via-Popn
X-Via-Poph
X-Varnish-Beresp-TTL
Arc-Country
Ohc-Cache-HIT
X-Presslabs-Stats
Memory
Time
X-Trace-ID
ITXSESSIONID
X-Clientip
X-Old-Content-Length
X-Akamai-Transformed
AMP-Access-Control-Allow-Source-Origin
Client
X-S-Maxage
X-DB
X-Accel-Expires-Debug
GeoIp-Country-Code
X-DW
X-DI
X-DSS
X-API-Version
X-Date
X-HA-Backend
X-RSL
X-RPS
X-RPM
True-Client-IP
X-VCL-Version
X-Vc
X-Cs
X-VHOST
Server-ID
Geoip-Latitude
X-Tec-Api-Version
X-Tec-Api-Root
X-GeoIP-Region-Code
X-Dmc
X-DC
X-Tec-Api-Origin
X-GeoIP-Country-Code
X-URL
X-Api-Version
X-MSEdge-Features
X-MSEdge-Flight
FSS-Cache
Hostname
X-Fpc
X-Render-Time
X-Cache-Debug
Fusion-Source
Fusion-Deployment-Id
Fusion-Template-Id
Fusion-Content-Id
Fusion-Content-Source
Fusion-Component-Id
X-INCAP-ABP
X-DynaTrace-JS-Agent
X-Zone
X-TRACE-ID
X-Gateway-Skip-Cache
CacheControlHeader
X-Gateway-Cache-Status
X-Gateway-Request-Id
X-Gateway-Cache-Key
NtCoent-Length
X-Service
Powered-By
X-Webkit-Csp-Report-Only
Rip
X-FireWall-Port
C-Via
X-TX-ID
X-M-Reqid
X-Action
X-TH-Server
X-Qnm-Cache
X-B3-Spanid
Click-Count-Action-Start
True-Client-Country-4JS
Tube-Return
Click-Count-Error
X-M-Log
Esi-Enabled
Tube-Got-Results
Tube-Get-Contents
Tube-Got-Eval
X-PX
HIT
Test
On-Server
X-Backend-TTL
X-Traceid
Tcn
Request-ID
X-NGINX-Cache
X-CSRF-TOKEN
X-Cdn-Request-ID
X-HS-Status
Edge-Cache
X-Alfa-Service
X-FPC
Cdn
X-Pass-Why
X-Beluga-Response-Time
OT-Force-Account-Verify
X-Vcl-Version
X-Beluga-Status
X-Beluga-Record
X-Beluga-Trace
X-Req
Server-Id
User-Agent
X-Beluga-Node
X-Beluga-Cache-Status
Geo-Info
X-Akamai-Pragma-Client-IP
X-Origin-Upstream-Status
My-App
X-Edge-Origin-Shield-Region
X-Edge-Origin-Shield-Bytes
Uri
X-Check-Cacheable
GeoIP-Country-Code
X-Proxy-Cache-Hk
GeoIP-Latitude
X-Via-PopV
Resin-Trace
Proxy-Connection
X-Via-PopH
Srv
Cf-Int-Pingora-Origin-Digest
X-Ha-Backend
Srvid
X-Via-PopN
X-CLOUD-TRACE-CONTEXT
X-Up
Sid
X-APP
M-TraceId
X-Webkit-CSP-Report-Only
X-App
X-CCDN-Origin-Time
Epwk-X-Cache
X-Varnish-Beresp-Ttl
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
DT-Hot-News
X-ServedByHost
X-Provided-By
X-LB-ID
MIME-Version
X-Cdn-Forward
X-Github-Request-Id
WebServer
ENV
X-Fastly-Backend-Reqs
X-Backend-Host
X-LI-Proto
X-Client-Ip
Server-Ttl
X-Li-Fabric
X-Li-Pop
X-Edge-POP
X-LI-UUID
Warning
X-Esi
X-RAMCache
ServerName
X-Fetch-By
X-B3-Traceid-Primal
X-UnsetCookies
X-Geo
XServer
X-Lb-Nocache
X-Bip
X-Thanos
True-Client-Ip
X-HostName
X-CF-Powered-By
X-Cc-Via
X-Request-Start
X-Nc
PICS-Label
X-HITS
WZWS-RAY
X-Akamai-Request-ID
CF-Cached-On
X-ND-Cache
X-ElasticPress-Query
X-Newrelic-App-Data
X-Serial
X-Dw-Trace-Id
X-Yottaa-OS
X-Request-Url
Section-Io-Id
Section-Io-Origin-Status
X-Time-Microsecs
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
DataCenter
X-LiteSpeed-Cache-Control
Fastly-Drupal-HTML
Inserted-Into-Cache-At
X-Vercel-Cache
Dt-Hot-News
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
Cf-Device-Type
X-CUA
X-Vcache
D-Url-Rewrites
X-Iplb-Instance
X-Vercel-Id
X-Iplb-Request-Id
Cdn-Cache
Cdn-Requestid
Cdn-Requestcountrycode
Cdn-Pullzone
Cdn-Edgestorageid
Cdn-Cachedat
Wp-Super-Cache
Cdn-Uid
Servedby
X-Air-Pt
X-UA
Content-Style-Type
Vha6-Origin
Content-Script-Type
X-Dist-Code
X-Azure-Ref-OriginShield
X-Platform-Cluster
X-Storefront-Renderer-Verified
X-Th-Server
Hit
Magicmarker
X-Snapshot-Date
X-MiniProfiler-Ids
X-BBC-Origin-Response-Status
X-Platform-Processor
X-LiteSpeed-Tag
X-Back
CountryCode
X-Sucuri-ID
X-Fastly-Cache-Hits
X-Wp-Cf-Super-Cache
X-ATG-Version
Fastcgi-Cache-Ttl
Target-Params
Tracecode
X-Wp-Cf-Super-Cache-Cache-Control
X-Request-URL
X-FC-Vary-Parameters
X-Fragments
X-Var-Ttl
X-Sucuri-Cache
X-Release
X-Fastly-Backend
X-Platform-Router