Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-RAY
CF-Cache-Status
Accept-Ranges
Link
X-XSS-Protection
ETag
Pragma
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
Alt-Svc
X-UA-Compatible
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Xss-Protection
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-Cache-Status
X-Request-ID
X-Generator
X-Cacheable
Timing-Allow-Origin
X-DNS-Prefetch-Control
P3p
X-Content-Security-Policy
X-Iinfo
Status
Feature-Policy
Content-Encoding
X-AspNetMvc-Version
X-CDN
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
Upgrade
X-Ua-Compatible
Access-Control-Max-Age
X-Drupal-Dynamic-Cache
X-Dns-Prefetch-Control
X-Via
X-Ws-Request-Id
Keep-Alive
Server-Timing
Request-Context
X-Robots-Tag
X-AH-Environment
X-Hacker
X-Server
X-Age
X-Proxy-Cache
X-Turbo-Charged-By
X-Cache-Group
X-Server-Powered-By
X-Amz-Request-Id
X-Backend
X-Amz-Id-2
EagleId
Host-Header
Report-To
X-Nginx-Cache-Status
X-LiteSpeed-Cache
X-Rq
X-Varnish-Cache
Grace
X-Page-Speed
X-UA-Device
X-Pingback
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
EagleEye-TraceId
X-Device
X-Vhost
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Amz-Version-Id
X-Dispatcher
NEL
Cf-Railgun
X-WebKit-CSP
X-OneAgent-JS-Injection
X-Host
X-Cache-Spec
X-Server-Id
X-CST
X-Node
X-Backend-Server
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Request-Id
Allow
Surrogate-Control
Accept-CH
X-Readtime
X-Akam-SW-Version
Accept-Ch-Lifetime
X-Response-Time
Xkey
X-Language
X-HW
X-Template
X-Application-Context
X-Country
Content-Location
X-Cloud-Trace-Context
X-Cache-Lookup
X-Ac
Rating
MS-Author-Via
X-Url
X-Ruxit-JS-Agent
X-Webkit-CSP
Edge-Control
X-Clacks-Overhead
X-Vname
X-TtlSet
X-PC
X-Mod-Pagespeed
X-Varnish-TTL
X-Trace
Fastly-Restarts
X-Content-Type
X-Buckets
X-Rack-Cache
X-MS-InvokeApp
X-ESI
X-Origin-Cache
X-B3-TraceId
X-GitHub-Request-Id
X-Cnection
X-Goog-Hash
X-Country-Code
Accept-Ch
Verso
X-D2id
X-VARITI-CCR
X-ORACLE-DMS-ECID
Arr-Disable-Session-Affinity
Cache-Tag
X-Use-Magma
X-Kinja-Revision
X-Kinja-Server
X-Kinja-Build
X-Cdn-Fetch
X-Exp-Variant
X-GoogleNews-Bot
X-Kinja
X-Exp-Id
X-Vcap-Request-Id
X-Px
Service-Worker-Allowed
X-Cached
X-Abt-Application-Version
X-FastCGI-Cache
X-Server-Name
X-Amz-Rid
X-Client-IP
X-Navigation-Version
Accept-CH-Lifetime
X-Cache-TTL
X-Server-ID
X-TTL
Public-Key-Pins
X-SRCache-Store-Status
X-SRCache-Fetch-Status
RTSS
X-Powered-By-Plesk
X-MSEdge-Ref
X-Dw-Request-Base-Id
Access-Control-Request-Method
X-Element-Page-Cache
X-Powered-CMS
X-NF-Request-ID
X-Version
X-Upstream
X-Fastly-Request-ID
Response
Pagespeed
X-Middleton-Response
Display
X-Middleton-Display
X-Sol
S
X-Kinsta-Cache
X-Edge-Location-Klb
X-Edge
X-LLID
X-Kraken-Routeconfig-Destination
X-Kraken-Loop-Name
X-Instrumentation
X-Server-Lifecycle-Phase
X-Cache-Key
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-ECACHE
X-Accel-Expires
X-Ruxit-Js-Agent
X-Shield-Request-Id
X-ORACLE-DMS-RID
X-Jurisdiction
X-HP-Webp
X-Correlation-Id
Pinterest-Version
Pinterest-Generated-By
X-Oneagent-Js-Injection
X-Pinterest-Rid
X-T
X-DynaTrace
Realpath
X-XRDS-Location
X-SharePointHealthScore
SPRequestGuid
X-PressLabs-Stats
X-MCACHE
Edge-Cache-Tag
X-Mid
X-Aspnetmvc-Version
X-Content-Security-Policy-Report-Only
SPRequestDuration
SPIisLatency
Fastcgi-Cache
X-Amz-Server-Side-Encryption
X-Litespeed-Cache
Nginx-Cache
X-Mg-S
X-Ttl
X-Content-Digest
X-Forwarded-Proto
X-Recruiting
TP-L2-Cache
TP-Cache
X-Id
TCN
Front-End-Https
X-Request-Processing-Time
X-Request-Received
Charset
Alternate-Protocol
Server-Node
X-Logged-In
Content-MD5
Filters
X-Geo-Country
X-Forwarded-For
Fusion-Content-Source
Fusion-Deployment-Id
Fusion-Source
X-Protected-By
Fusion-Template-Id
Fusion-Content-Id
X-Ezoic-Cdn
Fusion-Component-Id
X-Hostname
Cache-Tags
X-Ab
X-ASPNET-VERSION
X-Amzn-Trace-Id
X-NWS-LOG-UUID
X-Origin-Upstream-Status
X-Grace
X-Debug-Info
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Length
X-F-Cache
Cleartype
X-Www-Served-By
X-LB-Cache
X-Amz-Replication-Status
X-Az
X-AppVersion
X-Activity-Id
X-HS-Cache-Config
X-HS-Hub-Id
X-Rid
X-HS-Content-Id
X-HS-Combine-CSS
X-Origin-Server
Host
X-Daa-Tunnel
X-Contextid
X-Page-Id
X-Git-Hash
Server-Name
X-Ua-Device
X-VCache
Section-Io-Cache
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
MicrosoftSharePointTeamServices
X-Content-Options
X-Browser-Type
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Cache-Age
X-Upgrade-Enabled
X-Frontend
X-Ser
Access-Control-Allow-Method
X-Fastcgi-Cache
X-RateLimit-Remaining
ServerID
X-Hits
Accept-Charset
X-Source
X-Mobile-URL
X-Varnish-Age
X-DIS-Request-ID
X-B3-Sampled
X-Aspnet-Duration-Ms
X-Providence-Cookie
X-Flags
X-Is-Crawler
X-Request-Guid
X-Route-Name
X-B-Cache
X-Signature
X-Cache-Action
Healthy
Viewport
X-Release
X-Yandex-Sdch-Disable
X-FB-Debug
Payment
X-Varnish-Backend
X-Varnish-Grace
X-Whom
X-AOL-HN
Fastcgi-Useragent
X-TT
Node
DynaTrace
X-App-Environment
Paypal-Debug-Id
X-CACHE-GROUP
X-Load-Cache
X-WebKit-CSP-Report-Only
X-Mobile
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Respond-Thread
Filterid
DC
X-Seen-By
X-Distributor
Version
X-User-Agent
X-Tec-Api-Origin
X-Tec-Api-Root
X-HTML-Minification-Powered-By
X-Tec-Api-Version
X-Cache-Control
X-HP-Trace-Id
SRV
Frame-Options
X-N
Retry-After
X-Type
X-FW-Dynamic
X-FW-Hash
X-FW-Type
X-FW-Static
X-FW-Server
X-FW-Serve
X-Jobs
Refresh
MS-CV
X-Node-Name
X-NGENIX-Cache
Amp-Access-Control-Allow-Source-Origin
X-Azure-Ref
X-Original-Request-Id
X-Response-Served-From
X-UUID
X-IPLB-Instance
X-Cache-Expired-At
X-Page-View
X-Adobe-Content
X-Aws-Lambda-Call-Status
NGB
X-Proxy-Cache-Status
X-Adobe-Loc
X-Debug-IsConnected
X-Varnish-Server
X-Instance
X-Real-IP
X-Debug-IsPreview
X-Vgn-Hpd-Reason
X-Tumblr-Pixel-1
VIX-Pulpo-Upstream-Status
X-Tumblr-Pixel-0
X-B
X-G
X-Cluster-Name
X-XRDS-LOCATION
X-Tumblr-Pixel
X-Tumblr-User
X-Region
VIX-Pulpo-Node
X-Cacheable-TTL
X-CDN-Forward
X-Content-Powered-By
X-Device-Type
X-Cache-Time
X-ProcessESI
Access-Control-Request-Headers
X-RTag
Ms-Operation-Id
X-RemovedCookies
X-Framework
X-Cache-Hit
X-B3-Traceid
X-Parallel-Accel
SD-X-WS
Liferay-Portal
X-Proxy
X-Zen-Fury
X-Cache-Rule
Nel
X-IPS-LoggedIn
Referer-Policy
X-Is-Bot
X-Rendered-As
Uber-Trace-Id
X-Drupal-Cache-Tags
Cache-Status
X-Ms-Request-Id
X-Ms-Version
X-App-Server
X-Wix-Request-Id
X-Time
Countrycode
X-Oracle-Dms-Rid
Section-Io-Origin-Time-Seconds
X-EdgeConnect-Cache-Status
Section-Origin-Responded
Section-Io-Origin-Status
X-Mg-Request-UUID
Section-Io-Id
X-L-Path
X-Environment-Context
X-Debug
X-Revision
X-APP-VERSION
X-Yottaa-Optimizations
S-Cnection
X-Yottaa-Metrics
CF-IPCountry
Country
Count-Hit
X-RateLimit-Limit
X-Accel-Buffering
X-Cache-Operation
X-FW-Version
X-TA-CDN-Provider
X-Drupal-Cache-Contexts
Akamai-GRN
X-SaId
X-Nginx-Cache
X-RN-RSRV
X-GG-Cache-Date
Meta-Geo
X-JoinUs
X-ES-SERVER
X-UPSTREAM-Address
X-Endurance-Cache-Level
X-Cache-Type
X-SayCDN-TTL
X-Say-TTL
X-Say-Cacheable
X-Loop
X-Cache-TTL-Remaining
X-LAGOON
X-Adobe-Source
X-TNCMS
GEO-INFO
Azure-SiteName
X-Request-Time
Azure-Version
Azure-RegionName
Azure-SlotName
Country-Code
X-B3-SpanId
From-Origin
Fastly-SSL
Azure-InstanceId
X-R9-Blue-Green-Version
X-Sql-Duration-Ms
Surrogate-Key
X-Sql-Count
X-OCL
Cache
X-NYM-Debug-Backend
X-PCL
X-Varnish-Beresp-Grace
X-Human
X-S-Maxage
Decoy-Debug-Status
X-Handled-By
X-Sorting-Hat-PodId
Decoy-Debug-Key
Apigw-Requestid
Decoy-Debug-TTL
X-Varnish-Hostname
X-Shopify-Stage
Protected
X-ProxyCache-Key
X-Labrador-Cache-Channel
X-Sorting-Hat-ShopId
X-Storefront-Renderer-Rendered
X-Origin-Date
X-ShopId
X-Status
X-Hosted-By
X-BYPASS-REASON
X-PHP-Host
Cache-Name
X-RCS-CacheZone
X-Microsite
Cache-Tv-Group
X-VWS-Id
X-Request-Handler-Origin-Region
X-Be
X-Proto
X-Varnishpool
X-ShardId
X-LJ-Flow-ID
X-ProxyCache-Status
X-Alternate-Cache-Key
X-AWS-Id
X-Timing-Wait
X-Pubstack
Eomportal-Instance
X-No-Session
Property-Id
TWC-GeoIP-LatLong
X-Server-W
X-Access
X-Proxy-Build
Webcakes-Region
X-Akamai-Edgescape
X-Cache-Server
X-Web-Node
X-Cluster-Node
X-Via-Fastly
Webcakes-App-Name
X-Origin-Hint
TWC-Device-Class
X-Section
TWC-Connection-Speed
X-Tumblr-Pixel-2
X-UA-Device-Type
TWC-GeoIP-Country
TWC-Privacy
TWC-Locale-Group
X-Format
Selected-Fe
Webcakes-App-Version
X-Redis-Cache
X-Time-Microsecs
Mn-Server-Ip
X-Backend-Host
ServedBy
X-ApacheServer
Cross-Origin-Opener-Policy
X-Xfnlog-Site
X-PERF
X-Uri
X-PHP-Backend
X-FB-TRIP-ID
X-Servername
OT-Force-Account-Verify
X-Hyper-Cache
X-Hl-Ver
X-Backend-Name
AR-PoweredBy
AR-Request-ID
Ar-Sid
X-ServerID
AR-CACHE
AR-ATIME
X-Tumblr-Pixel-3
X-ATG-Version
Cross-Origin-Window-Policy
X-App-Version
X-Detected-As
X-Azure-Ref-OriginShield
Web-Mar-Node
X-Ua
X-Cache-Host
X-Generation-Time
X-Varnish-Cache-Hits
X-TEC-API-VERSION
X-FireWall-Port
X-TEC-API-ROOT
X-Cache-PHP
Source
X-TEC-API-ORIGIN
Content-Secure-Policy
X-Content
Ec-Rule-Version
X-Ua-Browser
X-Varnish-Hits
X-Content-Age
X-SRV
X-Via-JSL
Backend
X-Forwarded-Host
X-Ratelimit-Remaining
X-Ratelimit-Limit
Upgrade-Insecure-Requests
X-Air-Hostname
X-Air-Source
X-Amz-Apigw-Id
X-Datadome
X-Air-Trace-Id
X-Amzn-RequestId
X-MP-GENERATED-AT
X-Microcachable
X-Cache-Grace
X-WA-Info
X-CS
X-Mode
X-Akamai-Transformed
Xserver
X-Trace-Id
X-Cdn
Url
X-Amzn-Remapped-Content-Length
X-Locale
X-NWS-UUID-VERIFY
X-Unique-Id
X-Varnish-Beresp-Ttl
X-Edge-Location
X-CSRF-Token
X-TT-LOGID
X-Cache-Enabled
X-Tenant
Content-Disposition
X-Site-Version
X-Soup
X-Dc
X-Origin-CC
X-Origin-TTL
X-Bc-Bl
X-Rule
X-Info
X-GEO
X-Extlb
X-Zipkin-Id
X-Routing-Service
X-Proxied
X-DataDome
X-Debug-Cache
X-Tb
X-M-Log
X-M-Reqid
X-Varnish-Beresp-Status
X-Magnolia-Registration
Fastly-SIE
Fastcgi-X-Cache-Version
X-Conf
CDN-EdgeStorageId
Expiry
X-Vtex-Remote-Cache
CDCHOST
X-CF-Lambda-Version
X-A-Ccd
X-Cache-NE
X-VG-WebServer
X-VG-WebCache
Path
X-A
Host-ID
X-Ftr-Request-Id
X-CF-Lambda-Fn
X-Vtex-Processado-Em
CDN-Cache
Fastly-SWR
Surrogated-Key
X-Destination
A
X-External-Request-Id
X-D
Apple-News-Services-Handled
Apple-News-Services-Host
X-Epic-Correlation-Id
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
BehaviorPad-Version
DCR-Decision-By
CDN-PullZone
X-Connection-Hash
T-Server
X-Developer
DCR-Processing-Time-Ms
X-Forwarded-Path
CDN-Uid
CDN-RequestId
CDN-RequestCountryCode
X-Qnm-Cache
X-A-Dam
Mobile-Detection-Method
X-Request-URI
X-Aed
CDN-CachedAt
X-Rewrite-Enabled
X-Tx-Id
X-Rebelmouse-Surrogate-Control
Meta-Geo-Continent
X-BBC-Edge-Cache-Status
X-Ratelimit-Reset
X-Vdms-Version
X-A-Wwc
X-B-Cookie
X-Rojux
X-Shop-Environment
X-Session-Fingerprint
X-SRCache-Key
X-ARC
X-Application
X-AIR-PT
X-Aicache-OS
X-S
X-S-Cookie
X-ScT
Odigeo-Trace-Id
X-BCube-Filmed-By
X-Rebelmouse-Cache-Control
Rendered-Blocks
X-PAYTM-SRV-ID
X-PBS-Appsvrname
X-Platform-Server
MD5-Digest
X-Orig-Expires
X-NAPM-TraceId
X-NU-AKA-ACS-Version
X-Cache-Bucket
X-A-Dcw
X-Processor
User-Cache-Control
X-A-Dgt
Req-Svc-Chain
X-EC-Lua
SID
X-NCache
X-Cached-By
X-Storage
S-Rt
Is-Eu
X-Cache-Debug
X-Cache-Info
L
Origin
X-Cms-Context
State
Platform
Fastly-Drupal-HTML
X-Core-Value
X-Accel-Expires-Debug
Fastly-Backend-Name
UCS
Pics-Label
X-Backend-State
X-Date
NGX
X-Men
X-LI-UUID
X-Loc
X-Li-Pop
X-Li-Fabric
X-VG-TLSProxy
X-JWT-State
X-Variation
X-TrackingId
X-Request-UUID
X-Service
X-Proxy-Upstream
X-Origin-Expires
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Has-Esi
X-Is-Gdpr
X-VServer
X-Fastly-Cache
X-Envoy-Decorator-Operation
Adler-Geo
X-Worker
X-DPWN-IS-SECURE
Cache-Key
Cache-Host
X-LSADC-Cache
X-Cache-NGX
True-Client-Country-4JS
X-Thinkindot-L3
X-SIPLIST1
X-Sigma
X-Sigma-Backend
Thinkindot-Control
X-Slack-Backend
X-Varnish-CookieINHashed-On
Vix-Hermes-Req-Id
X-VC-Cache
VNS-Age
X-Via-NSCOPI
X-Viewer-Country
X-Auto-Login
X-VarnishDD-TTL
X-Varnish-CookieHashed-On
VNS-Cache
X-Wikidot-Backend
X-Varnish-Remaining-TTL
X-Wikidot-Static-Cache
X-Branch-Name
X-Gen-Mode
X-Gamma-Serve
X-Generated-By
X-Gzip
X-Hnp-Log
X-HN
X-From
X-Forwarded-Site
X-Esi-Check
X-Device-Os
X-DefHash
X-DefElseHash
X-Fastly-Backend
X-Cluster
X-Clientip
X-Origin
X-Developers
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Rocket-Build-Number
X-Req
X-Old-Content-Length
X-Nginx-Cache-Key
X-Cache-Tags
X-Ckpd-Fst-Backend
X-Location
Thinkindot-CacheControl-Type
X-Cache-Id
X-Scheme
X-Block-Status
Locid
Location
IsBot
XServer
PB-PID
PFcat
PB-RID
Thinkindot-CacheControl
Esi-Enabled
Cf-Device-Type
C-Via
Arc-Version
Cmsid
Cmstype
CPC-Cache
CPC-Age
Server-Ext
Fastcgi-Cache-TTL
Sever-Int
Server-Hostname
Server-Host
TDXMobile
NtCoent-Length
X-Micro-Cache
AMP-Access-Control-Allow-Source-Origin
X-Amz-Meta-S3cmd-Attrs
X-Rocket-Nginx-Serving-Static
X-Policy
X-Planisys-CDN-TTL
X-FC-Vary-Parameters
X-Fetched-On
X-Eu-Site
AKAMAI
CacheControlHeader
X-Platform
V-Age
Arc-Country
X-Mvc-Supplant-Cachable
X-Platform-Cluster
X-Hash
X-Render-Time
X-Vdms-Path
X-HS-Content-Campaign-Id
Webserver
X-Irp-Debug
X-Level-Front-Cache
X-Goog-Meta-Goog-Reserved-File-Mtime
X-GeoIP-City
X-Planisys-CDN-Rules
X-Platform-Processor
X-Generated-In
X-Generated-On
X-GeoIP
X-Geo-Header
X-Platform-Router
Svr
Wxu-Next-Region
Mail-Subject
X-Bip
X-Planisys-CDN-Cache
Wxu-Next-Hostname
L5d-Success-Class
Wxu-Next-Commit
Memcached
DataCenter
X-Request-Host
X-Served-From
Release
X-Skip-Cache
Pagetype
X-Sucuri-ID
NM-Fastcgi-Cache
X-Thanos
M-TraceId
Gh-Request-Id
Server-Info
We-Hiring
DSUID
X-CGP
X-Csrf-Jwt
Ha-Gx-Prefs
HA-Ipaddr
X-Owner
X-Cache-Var
X-V-Cache
X-Var-Ttl
X-DC
X-Cache-Var-Map
X-SD-PageType
X-Qloud-Router
X-Cache-Remote
X-WADP-Cache
X-Servedbyhost
MIME-Version
X-Clara-WADP
X-Fmm-Version
X-Mvc-Supplant-OutputCached
Environment
X-GoCache-CacheStatus
Cache-Hits
X-Unique-ID
X-NodeID
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-API-Version
X-Gdpr
X-Origin-Time
X-Nyt-Route
X-Via-Popv
Kp-EeAlive
X-NC
X-Via-Ucdn
X-Via-Popn
X-Via-Poph
X-PJAX-URL
X-Srv
X-BBC-Origin-Response-Status
X-Pod-Name
X-Vc
X-Cache-Config
Candidate-Md5Url
X-Server-IP
X-Wa
X-Zone
Server-ID
Time
X-App
Memory
X-User
X-PF-Uncompressing
WebServer
X-Varnish-Ttl
Onion-Location
X-Traceid
X-ZONE
X-VCL-Version
Cluster
X-Refresh
X-Internal-Host
Who
X-Tt-Logid
X-Varnish-Url
Web-Mar-Region
HostName
X-TIME
X-Newrelic-Synthetics
X-Minions-Version
X-Webkit-Csp
X-Pass-Why
X-CACHE-KEY
X-Webkit-CSP-Report-Only
Resin-Trace
GeoIp-Country-Code
N-Cache
X-LB-ID
X-Akamai-Pragma-Client-IP
X-NewRelic-App-Data
Powered-By-ChinaCache
X-LI-Proto
Geoip-Latitude
My-App
Servername
X-Tb-Optimization-Total-Bytes-Saved
X-Edge-Pop
X-ID
X-Cache-Ttl
X-Esi
Datacenter
X-ElasticPress-Query
X-Varnish-Cacheable
X-CLOUD-TRACE-CONTEXT
X-TraceId
CDN
Geo-Info
WWW-Authenticate
X-VHOST
X-Fastly-Request-Id
X-Fpc
X-Origin-Response-Time
Ohc-File-Size
X-TX-ID
Tcn
X-Tid
X-OVcl-Cache
X-TIM-N
X-OVcl
X-Dynatrace
X-CACHE-AGE
X-EIG-Tracking-Id
X-HITS
Redirect-Candidate
LB
X-Geo
X-Up
Hostname
Cf-Bgj
X-NGINX-Cache
X-Dynatrace-Js-Agent
Proxy-Connection
X-Backend-TTL
Magicmarker
Tracecode
X-Cache-Date
X-Li-Proto
X-Varnish-Beresp-TTL
X-NODE
X-Correlation-ID
X-AB
X-Wix-Viewer-Type
X-CSRF-TOKEN
X-Method
X-Request-Start
Pramga
X-Sn-Servicetimems
X-Cdn-Origin
X-Amz-Meta-Cb-Modifiedtime
X-HostName
Cdn
X-Webkit-Csp-Report-Only
CloudFront-Viewer-Country
X-Dispatcher-Server
W
X-Provided-By
GeoIP-Country-Code
X-Cs
Sid
X-UnsetCookies
Cf-Ipcountry
X-Vcl-Version
X-Lb-Id
X-Cache-Expires
X-MSEdge-Features
X-Core-Mission
X-MSEdge-Flight
X-Fastly-Backend-Reqs
Is-Us
CF-Cached-On
GeoIP-Latitude
X-COUNTRY
X-IP
X-HS-Status
X-Reqid
Ssr
X-APP
Server-Id
WP-Super-Cache
Lb
X-MG-S
DB-Nickname
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-Cache-Status-Check
X-WA
X-ServerName
Cteonnt-Length
X-Sucuri-Cache
X-FORWARDED-FOR
X-Moov-T
X-Via-PopN
X-Region-Sid
X-Moov-Xdn-Version
X-Via-PopH
X-Check-Cacheable
X-Via-PopV
URI
X-Node-Id
Xc-Version
X-VC
CountryCode
Ohc-Cache-HIT
X-Trv-Group
X-ND-Cache
EpKe-Alive
X-DynaTrace-JS-Agent
X-Nc
X-Ig-Push-State
X-Cache-Backend
User-Agent
X-SERVER-NAME
X-TRACE-ID
X-Nginx-Upstream-Cache-Status
X-Edge-POP
X-Pjax-Url
X-Via-CDN
X-LiteSpeed-Cache-Control
Shield-Pop
X-Pad
Env
WZWS-RAY
X-ServedByHost
Mime-Version
X-SN
FSS-Cache
On-Server
X-Acquia-Site
X-Acquia-Purge-Tags
X-Oss-Server-Time
X-Parent-Response-Time
X-RAMCache
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Varnish-Authentication
X-Oss-Storage-Class
X-Acquia-Application-UUID
X-Pf-Uncompressing
X-Cache-ASPX
X-Contensis-Viewer-Groups
X-Fastly-Cache-Hits
X-Acquia-Application-Trace
X-Oss-Request-Id
X-CUA
CACHE
X-Amz-Meta-Opti
X-Cdn-Request-ID
Hit
HIT
X-Dispatch
X-IN-APIGATEWAY
Vha6-Origin
X-Action
X-DB
X-DI
Ohc-Response-Time
X-Dw-Trace-Id
X-Swift-Error
X-SB
X-Webstats-RespID
X-DW
X-DSS
X-IN-APIGATEWAYSSL
Xet-Cookie
Server-Ttl
X-RSL
X-StackifyID
X-RPS
X-RPM
X-Cdn-Forward
X-Forwarded-Port
X-Ftr-Viewer-Uri
X-Snapshot-Date
X-Amzn-Remapped-Host
X-Env-Sha256-Sig
X-Env-Stack-Name
X-Amzn-Remapped-X-Forwarded-For
X-Amzn-Remapped-User-Agent
ServerName
Content-Script-Type
X-Yottaa-OS
Content-Style-Type
X-CF-Powered-By
Req-ID
Rt-Fastcgi-Cache
VivaBuild
Viewtype
X-MiniProfiler-Ids