Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-RAY
CF-Cache-Status
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
X-XSS-Protection
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
Alt-Svc
X-Served-By
X-Xss-Protection
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Permitted-Cross-Domain-Policies
X-Request-ID
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-Cache-Status
X-DNS-Prefetch-Control
X-Generator
X-Cacheable
Timing-Allow-Origin
P3p
X-FRAME-OPTIONS
X-Content-Security-Policy
X-Iinfo
Status
Content-Encoding
Feature-Policy
X-AspNetMvc-Version
X-CDN
X-Envoy-Upstream-Service-Time
Upgrade
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Access-Control-Max-Age
X-Via
Keep-Alive
X-Ws-Request-Id
Request-Context
X-Robots-Tag
Server-Timing
X-AH-Environment
X-Ua-Compatible
X-Server
X-Hacker
X-Age
X-Turbo-Charged-By
X-Proxy-Cache
X-Server-Powered-By
X-Cache-Group
X-Backend
Host-Header
X-Amz-Request-Id
X-Nginx-Cache-Status
EagleId
X-Dns-Prefetch-Control
X-Amz-Id-2
Report-To
X-LiteSpeed-Cache
X-Rq
X-Varnish-Cache
X-UA-Device
X-Page-Speed
Grace
X-Pingback
X-Swift-SaveTime
X-Swift-CacheTime
X-Device
Ali-Swift-Global-Savetime
EagleEye-TraceId
NEL
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Vhost
X-Amz-Version-Id
Cf-Railgun
X-OneAgent-JS-Injection
X-Host
X-Dispatcher
X-Server-Id
X-CST
Allow
X-Cache-Spec
X-Node
Surrogate-Control
Request-Id
X-Backend-Server
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Webkit-CSP
Accept-CH
X-Readtime
X-Response-Time
X-Akam-SW-Version
X-WebKit-CSP
Xkey
Accept-Ch-Lifetime
X-HW
X-Country
X-Language
Content-Location
X-Application-Context
X-Ac
X-Ruxit-JS-Agent
X-Template
MS-Author-Via
X-Cloud-Trace-Context
Rating
X-Cache-Lookup
X-Url
X-Mod-Pagespeed
X-B3-TraceId
Edge-Control
X-PC
X-Vname
X-TtlSet
X-Clacks-Overhead
X-MS-InvokeApp
X-Trace
X-ESI
X-Varnish-TTL
X-GitHub-Request-Id
X-Content-Type
X-ASPNET-VERSION
Fastly-Restarts
X-Origin-Cache
X-Rack-Cache
X-Cnection
X-D2id
X-Use-Magma
X-Kinja
X-Kinja-Server
X-Kinja-Build
X-Cdn-Fetch
X-Exp-Id
X-GoogleNews-Bot
X-Exp-Variant
X-Kinja-Revision
X-Country-Code
X-Goog-Hash
X-VARITI-CCR
Verso
Arr-Disable-Session-Affinity
Accept-CH-Lifetime
X-FastCGI-Cache
X-Server-Name
X-Cached
X-Buckets
X-Vcap-Request-Id
Accept-Ch
Cache-Tag
X-Navigation-Version
X-Client-IP
Service-Worker-Allowed
X-Amz-Rid
X-ORACLE-DMS-ECID
X-Abt-Application-Version
X-Powered-By-Plesk
X-Fastly-Request-ID
RTSS
Access-Control-Request-Method
X-MSEdge-Ref
X-Element-Page-Cache
X-Powered-CMS
Response
Display
Pagespeed
X-Middleton-Display
X-Sol
X-Middleton-Response
X-Cache-TTL
Public-Key-Pins
X-Ttl
X-Server-ID
X-NF-Request-ID
X-Dw-Request-Base-Id
X-Upstream
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Version
X-Px
X-Edge
S
X-Kinsta-Cache
X-Edge-Location-Klb
X-LLID
X-TTL
Realpath
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-ECACHE
X-Accel-Expires
SPIisLatency
SPRequestDuration
X-HP-Webp
X-T
X-Jurisdiction
SPRequestGuid
X-SharePointHealthScore
X-Instrumentation
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Kraken-Routeconfig-Destination
X-Mid
X-MCACHE
X-PressLabs-Stats
X-Content-Security-Policy-Report-Only
X-Forwarded-Proto
X-Shield-Request-Id
X-Cache-Key
X-Correlation-Id
Pinterest-Version
Pinterest-Generated-By
X-DynaTrace
X-Pinterest-Rid
Edge-Cache-Tag
X-Recruiting
Charset
Fastcgi-Cache
X-Amz-Server-Side-Encryption
TP-Cache
TP-L2-Cache
X-ORACLE-DMS-RID
X-Mg-S
Nginx-Cache
X-Content-Digest
X-Oneagent-Js-Injection
X-Request-Received
X-Request-Processing-Time
X-XRDS-Location
Filters
X-Id
TCN
X-Ezoic-Cdn
Front-End-Https
X-Logged-In
Server-Node
X-Release
Alternate-Protocol
X-Ruxit-Js-Agent
X-Forwarded-For
Cache-Tags
Content-MD5
X-Litespeed-Cache
Fusion-Template-Id
Fusion-Source
Fusion-Content-Source
X-Origin-Upstream-Status
Fusion-Component-Id
Fusion-Content-Id
Fusion-Deployment-Id
X-Geo-Country
X-Amzn-Trace-Id
X-Hostname
X-Origin-Server
X-Protected-By
X-Grace
Server-Name
X-Www-Served-By
Cleartype
X-RateLimit-Remaining
X-Rid
X-F-Cache
X-Amz-Replication-Status
X-Goog-Generation
X-AppVersion
X-Activity-Id
X-Az
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Contextid
Host
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Combine-CSS
X-Debug-Info
X-LB-Cache
Section-Io-Cache
X-Frontend
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Browser-Type
X-NWS-LOG-UUID
X-WebKit-CSP-Report-Only
MicrosoftSharePointTeamServices
X-Git-Hash
X-Page-Id
X-Ser
X-Aspnetmvc-Version
X-Cache-Age
X-Respond-Thread
X-Upgrade-Enabled
X-VCache
Accept-Charset
X-Daa-Tunnel
X-Source
X-Content-Options
X-Varnish-Age
X-Hits
X-Mobile-URL
Paypal-Debug-Id
Access-Control-Allow-Method
X-DIS-Request-ID
ServerID
X-Fastcgi-Cache
X-CACHE-GROUP
X-Signature
X-Varnish-Backend
X-B-Cache
Viewport
Healthy
X-FB-Debug
X-Flags
X-Varnish-Grace
X-Aspnet-Duration-Ms
X-Cache-Action
X-Providence-Cookie
X-Is-Crawler
X-Request-Guid
X-Route-Name
AR-PoweredBy
AR-CACHE
AR-ATIME
AR-Request-ID
Ar-Sid
X-Whom
Payment
X-TT
X-B3-Sampled
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-AOL-HN
X-Tec-Api-Root
X-Tec-Api-Version
X-Tec-Api-Origin
Node
X-N
X-App-Environment
Version
X-Seen-By
X-Type
DynaTrace
X-Mobile
X-Load-Cache
DC
Fastcgi-Useragent
X-Yandex-Sdch-Disable
X-Request-Handler-Origin-Region
X-Microsite
MS-CV
X-XRDS-LOCATION
X-Ab
X-HTML-Minification-Powered-By
X-Distributor
Retry-After
SRV
X-Tt-Trace-Host
X-Cache-Expired-At
X-Tt-Trace-Tag
X-Cache-Control
Frame-Options
X-User-Agent
Filterid
X-Response-Served-From
X-IPLB-Instance
X-Original-Request-Id
X-Tumblr-Pixel-0
X-Real-IP
X-ProcessESI
X-RemovedCookies
X-Instance
X-UUID
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-Tumblr-User
X-Varnish-Server
X-Region
X-Proxy-Cache-Status
X-Jobs
Refresh
X-RTag
X-Cluster-Name
X-IPS-LoggedIn
X-Content-Powered-By
X-Adobe-Content
Ms-Operation-Id
Access-Control-Request-Headers
X-Proxy
X-Debug-IsConnected
X-Debug-IsPreview
X-Cacheable-TTL
X-Adobe-Loc
X-Page-View
NGB
VIX-Pulpo-Node
X-Cache-Time
X-B
X-Device-Type
X-G
Uber-Trace-Id
VIX-Pulpo-Upstream-Status
X-Framework
X-Debug
X-RateLimit-Limit
X-FireWall-Port
X-Vgn-Hpd-Reason
X-FW-Server
X-FW-Static
X-Accel-Buffering
X-Zen-Fury
X-FW-Dynamic
X-FW-Serve
X-FW-Type
X-FW-Hash
Section-Io-Id
X-Mg-Request-UUID
X-CDN-Forward
X-Wix-Request-Id
X-Time
Section-Io-Origin-Status
Cache
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
Countrycode
X-NGENIX-Cache
Cache-Status
X-Oracle-Dms-Rid
X-App-Version
X-Azure-Ref
X-Nginx-Cache
X-Cache-Rule
X-Node-Name
X-Is-Bot
X-Rendered-As
Amp-Access-Control-Allow-Source-Origin
Country
X-Drupal-Cache-Tags
X-EdgeConnect-Cache-Status
Surrogate-Key
X-Cache-Hit
X-App-Server
X-Ms-Request-Id
SD-X-WS
X-Ms-Version
Referer-Policy
Liferay-Portal
S-Cnection
Eomportal-Instance
X-L-Path
X-Environment-Context
X-Cache-Operation
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-TA-CDN-Provider
X-UPSTREAM-Address
X-ES-SERVER
Meta-Geo
X-Drupal-Cache-Contexts
X-JoinUs
X-Tumblr-Pixel-2
From-Origin
X-SaId
X-RN-RSRV
X-Varnishpool
X-Endurance-Cache-Level
X-Alternate-Cache-Key
X-Timing-Wait
CF-IPCountry
X-Via-Fastly
X-Storefront-Renderer-Rendered
X-Xfnlog-Site
X-Handled-By
X-Loop
X-Varnish-Beresp-Grace
X-Sorting-Hat-ShopId
X-S-Maxage
X-ShardId
X-TNCMS
X-Shopify-Stage
X-ShopId
X-GG-Cache-Date
X-R9-Blue-Green-Version
Protected
X-Cache-TTL-Remaining
Selected-Fe
X-Proxy-Build
X-Pubstack
X-Sorting-Hat-PodId
X-NYM-Debug-Backend
Cache-Tv-Group
Azure-SiteName
Azure-RegionName
Azure-InstanceId
Azure-SlotName
Azure-Version
Fastly-SSL
ServedBy
X-Varnish-Hostname
X-Adobe-Source
Cache-Name
X-OCL
X-Human
X-PHP-Backend
X-PCL
X-Cache-Server
X-No-Session
X-LAGOON
X-Request-Time
Country-Code
X-LJ-Flow-ID
X-Origin-Hint
X-Proto
X-Section
X-Server-W
Akamai-GRN
X-RCS-CacheZone
X-ProxyCache-Status
X-ProxyCache-Key
Decoy-Debug-Key
TWC-Locale-Group
TWC-Privacy
Webcakes-App-Name
Property-Id
TWC-GeoIP-LatLong
TWC-Device-Class
TWC-GeoIP-Country
Webcakes-App-Version
Webcakes-Region
Decoy-Debug-Status
TWC-Connection-Speed
Decoy-Debug-TTL
X-BYPASS-REASON
X-Access
X-AWS-Id
X-Format
Apigw-Requestid
X-Say-Cacheable
X-SayCDN-TTL
X-Revision
X-Say-TTL
X-VWS-Id
X-Be
X-PHP-Host
X-Cache-Type
X-Sql-Duration-Ms
X-ApacheServer
X-PERF
X-Labrador-Cache-Channel
X-Hl-Ver
X-Status
X-Sql-Count
X-Backend-Name
X-Origin-Date
X-Backend-Host
X-Aws-Lambda-Call-Status
X-UA-Device-Type
X-Akamai-Edgescape
X-Uri
X-Hyper-Cache
Mn-Server-Ip
X-Hosted-By
X-Redis-Cache
X-Web-Node
X-Cache-PHP
Xserver
X-Ua-Device
X-FB-TRIP-ID
X-B3-SpanId
X-ATG-Version
X-Rule
X-Trace-Id
X-FW-Version
X-Parallel-Accel
X-Time-Microsecs
X-WA-Info
X-Tumblr-Pixel-3
X-MP-GENERATED-AT
X-Content-Age
Count-Hit
GEO-INFO
X-CSRF-Token
X-Cached-By
X-ServerID
X-TT-LOGID
X-Soup
OT-Force-Account-Verify
X-Akamai-Transformed
Backend
AMP-Access-Control-Allow-Source-Origin
X-Cluster-Node
X-Detected-As
X-Varnish-Cache-Hits
X-HP-Trace-Id
X-CS
X-Edge-Location
X-Datadome
X-Servername
X-Azure-Ref-OriginShield
X-Mode
X-APP-VERSION
X-Cache-Enabled
X-Cache-Host
X-Varnish-Beresp-Status
Web-Mar-Node
X-Generation-Time
Cross-Origin-Opener-Policy
X-Bc-Bl
X-Dc
X-Varnish-Hits
X-Microcachable
X-Info
X-Amzn-RequestId
X-Cache-NGX
X-Amzn-Remapped-Content-Length
X-Amz-Apigw-Id
X-TEC-API-ORIGIN
X-Varnish-Beresp-Ttl
X-Debug-Cache
X-TEC-API-ROOT
X-Storage
X-TEC-API-VERSION
X-Routing-Service
X-Platform
X-Zipkin-Id
X-Proxied
X-Unique-ID
X-B3-Traceid
SID
X-SRV
X-Ua
X-Extlb
X-Magnolia-Registration
X-Origin-TTL
X-Origin-CC
S-Rt
Who
Path
X-Cache-Ttl
Rendered-Blocks
Req-Svc-Chain
X-SRCache-Key
Odigeo-Trace-Id
X-Vtex-Remote-Cache
MD5-Digest
X-Thanos
Meta-Geo-Continent
Mobile-Detection-Method
X-Vtex-Processado-Em
State
Cross-Origin-Window-Policy
X-A-Dcw
X-A-Dam
X-A-Dgt
X-A-Wwc
X-Aed
X-A-Ccd
X-A
Surrogated-Key
T-Server
X-Session-Fingerprint
Content-Disposition
M-TraceId
X-VG-WebServer
CDN-CachedAt
CDN-EdgeStorageId
CDN-Cache
CDCHOST
Cache-Host
CDN-PullZone
CDN-RequestCountryCode
DCR-Decision-By
DCR-Processing-Time-Ms
CDN-Uid
CDN-RequestId
Expiry
BehaviorPad-Version
X-Vdms-Path
A
X-Vdms-Version
Host-ID
X-VG-WebCache
Fastly-Backend-Name
Apple-News-Services-Handled
Fastcgi-X-Cache-Version
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-Aicache-OS
X-Service
X-Geo-Header
X-S-Cookie
X-S
X-Rojux
X-Generated-On
X-External-Request-Id
X-Developer
X-ScT
X-Epic-Correlation-Id
X-Level-Front-Cache
X-Locale
X-Ratelimit-Reset
X-PAYTM-SRV-ID
X-PBS-Appsvrname
X-Processor
X-NAPM-TraceId
X-Request-URI
X-Location
X-Rewrite-Enabled
Ec-Rule-Version
X-Destination
X-From
X-Connection-Hash
X-BCube-Filmed-By
X-CF-Lambda-Version
X-Bip
X-Cms-Context
X-Cache-Bucket
X-Core-Value
X-Cache-NE
X-D
X-Application
X-ARC
X-B-Cookie
X-CF-Lambda-Fn
X-Cache-Grace
X-NWS-UUID-VERIFY
Url
Server-Info
Upgrade-Insecure-Requests
DataCenter
X-DataDome
Thinkindot-Control
X-Proxy-Upstream
Thinkindot-CacheControl-Type
X-Backend-State
X-Origin
DSUID
Thinkindot-CacheControl
X-Cache-Debug
X-Request-UUID
Fastcgi-Cache-TTL
X-GoCache-CacheStatus
X-Envoy-Decorator-Operation
Server-Host
X-SVT-ORM-VERSION
X-Scheme
NGX
PFcat
Origin
X-Developers
X-Served-From
Location
X-Thinkindot-L3
Fastly-Drupal-HTML
X-HN
Pics-Label
Gh-Request-Id
L
X-Gamma-Serve
TDXMobile
X-SVT-ORM-RULES
X-Air-Trace-Id
X-Air-Source
X-Air-Hostname
X-Clientip
X-Via-JSL
Fastly-SWR
X-VHOST
X-Varnish-Ttl
Source
X-Rebelmouse-Cache-Control
X-Forwarded-Path
Cmstype
X-Orig-Expires
X-Shop-Environment
X-Platform-Server
X-Rebelmouse-Surrogate-Control
X-NU-AKA-ACS-Version
X-JWT-State
X-Tenant
X-Has-Esi
X-Is-Gdpr
Content-Secure-Policy
Fastly-SIE
X-VarnishDD-TTL
C-Via
X-VG-TLSProxy
AKAMAI
Cmsid
X-Tb
User-Cache-Control
X-Forwarded-Host
X-Req
X-Accel-Expires-Debug
X-TrackingId
X-Fmm-Version
X-User
X-Generated-By
PB-PID
X-Nginx-Cache-Key
UCS
Vix-Hermes-Req-Id
X-GeoIP-City
PB-RID
X-Forwarded-Site
Platform
X-DPWN-IS-SECURE
X-Clara-WADP
X-Srv
CacheControlHeader
X-Cluster
X-Policy
X-Date
X-Device-Os
X-Origin-Expires
X-Loc
X-Var-Ttl
X-Fastly-Backend
True-Client-Country-4JS
X-Fastly-Cache
Arc-Country
X-Owner
X-Cache-Info
Esi-Enabled
X-Branch-Name
X-AIR-PT
X-Sigma
X-Sigma-Backend
Adler-Geo
X-LI-UUID
Release
Memcached
X-Variation
Arc-Version
Pagetype
X-EC-Lua
X-Li-Fabric
X-Li-Pop
X-VServer
X-WADP-Cache
X-Sucuri-ID
X-Rocket-Build-Number
Kp-EeAlive
Server-Ext
X-Men
Cf-Device-Type
X-Micro-Cache
Svr
Is-Eu
X-Hash
X-VC-Cache
X-Request-Host
Server-Hostname
X-Site-Version
X-Skip-Cache
Sever-Int
Nel
X-RateLimit-Limit-Second
X-Minions-Version
NtCoent-Length
X-Qloud-Router
X-Varnish-CookieINHashed-On
X-Old-Content-Length
X-Generated-In
X-GeoIP
X-Gzip
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Gen-Mode
X-Hnp-Log
X-Eu-Site
X-Esi-Check
X-Varnish-Remaining-TTL
X-Varnish-CookieHashed-On
X-Fetched-On
X-SIPLIST1
X-Amz-Meta-S3cmd-Attrs
X-Slack-Backend
Cache-Key
X-Wikidot-Static-Cache
IsBot
Locid
Wxu-Next-Commit
V-Age
NM-Fastcgi-Cache
X-Viewer-Country
Ha-Gx-Prefs
X-Varnish-Url
HA-Ipaddr
X-Via-NSCOPI
X-RateLimit-Remaining-Second
L5d-Success-Class
Wxu-Next-Hostname
X-Wikidot-Backend
X-Block-Status
X-Cache-Tags
X-DefHash
X-CGP
X-Ftr-Request-Id
X-Cache-Id
Wxu-Next-Region
X-DefElseHash
X-Csrf-Jwt
X-GEO
X-Mvc-Supplant-Cachable
CPC-Cache
Mail-Subject
CPC-Age
Webserver
X-Planisys-CDN-Rules
X-PF-Uncompressing
Cache-Hits
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
X-Conf
X-Unique-Id
VNS-Cache
X-FC-Vary-Parameters
X-HS-Content-Campaign-Id
We-Hiring
X-Irp-Debug
VNS-Age
X-Zone
Powered-By-ChinaCache
X-Ratelimit-Limit
X-BBC-Edge-Cache-Status
MIME-Version
X-Via-Popn
X-Via-Popv
My-App
X-Via-Poph
X-Pass-Why
X-Worker
X-Mvc-Supplant-OutputCached
X-Vc
X-Servedbyhost
X-DC
XServer
X-PJAX-URL
X-Ckpd-Fst-Backend
X-NC
X-Internal-Host
X-Refresh
X-Auto-Login
X-TX-ID
X-CACHE-KEY
X-ID
X-LSADC-Cache
X-LB-ID
WebServer
X-OVcl
Memory
X-V-Cache
X-Ratelimit-Remaining
Time
X-Traceid
Server-ID
X-Tx-Id
X-NCache
X-OVcl-Cache
X-Render-Time
X-Rocket-Nginx-Serving-Static
Cf-Bgj
X-Platform-Router
X-Qnm-Cache
X-Platform-Processor
X-Webkit-Csp
X-Newrelic-Synthetics
X-M-Log
X-Wa
X-M-Reqid
X-TIME
X-Platform-Cluster
Geo-Info
X-ZONE
X-Cache-Remote
X-Backend-TTL
X-NewRelic-App-Data
X-SD-PageType
Magicmarker
X-App
X-TraceId
HostName
DB-Nickname
Environment
Hostname
X-Webkit-CSP-Report-Only
X-Cache-Config
X-Gdpr
X-Nyt-Route
X-CLOUD-TRACE-CONTEXT
X-API-Version
X-VCL-Version
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-NodeID
X-Method
X-Origin-Time
Geoip-Latitude
X-BBC-Origin-Response-Status
X-Geo
X-Dispatcher-Server
GeoIp-Country-Code
X-Server-IP
Resin-Trace
Cluster
X-Via-Ucdn
X-Pod-Name
X-Tb-Optimization-Total-Bytes-Saved
X-Correlation-ID
X-Edge-Pop
X-LI-Proto
X-IP
Candidate-Md5Url
Ssr
X-Cache-Var
X-Cache-Var-Map
LB
Ohc-File-Size
Tcn
X-Akamai-Pragma-Client-IP
X-Origin-Response-Time
X-MSEdge-Flight
X-MSEdge-Features
X-HITS
X-Dynatrace
Datacenter
X-CACHE-AGE
X-Li-Proto
N-Cache
Web-Mar-Region
X-ElasticPress-Query
Cf-Ipcountry
X-NODE
X-Trv-Group
X-Nc
X-Varnish-Beresp-TTL
X-Node-Id
X-Esi
X-AB
X-Content
X-Ua-Browser
X-Wix-Viewer-Type
X-Via-CDN
X-DynaTrace-JS-Agent
X-ND-Cache
X-Vcl-Version
Onion-Location
X-HostName
GeoIP-Latitude
Env
GeoIP-Country-Code
Servername
X-APP
CF-Cached-On
X-ServerName
CDN
X-EIG-Tracking-Id
X-Reqid
X-HS-Status
Proxy-Connection
X-Varnish-Cacheable
Cdn
X-Cs
WWW-Authenticate
WZWS-RAY
Sid
X-Dynatrace-Js-Agent
Server-Id
X-WA
X-MG-S
X-Fastly-Backend-Reqs
X-NGINX-Cache
Viewtype
X-Fpc
VivaBuild
Rt-Fastcgi-Cache
X-Lb-Id
Cteonnt-Length
Machine
X-URL
Redirect-Candidate
X-Request-Start
X-TIM-N
X-Check-Cacheable
X-Pjax-Url
X-Tid
X-CSRF-TOKEN
Ohc-Cache-HIT
X-Xrds-Location
X-Via-PopV
X-Via-PopN
X-Via-PopH
X-FTR-Request-ID
X-Up
X-VC
X-Fastly-Request-Id
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
URI
X-Cache-Backend
Tracecode
Lb
X-Cdn-Forward
Is-Us
Mime-Version
X-ServedByHost
On-Server
Shield-Pop
X-Amz-Meta-Cb-Modifiedtime
X-Cache-Date
Server-Ttl
X-SN
FSS-Cache
CountryCode
Pramga
X-Tt-Logid
CACHE
X-Swa-Ws
X-Fastly-Cache-Hits
X-Cache-ASPX
X-Sn-Servicetimems
X-Cdn-Origin
X-Webkit-Csp-Report-Only
X-Air-Pt
X-Contensis-Viewer-Groups
X-FORWARDED-FOR
X-Varnish-Authentication
X-LiteSpeed-Cache-Control
X-DW
X-DSS
X-DI
X-DB
Content-Style-Type
Content-Script-Type
CloudFront-Viewer-Country
W
X-Core-Mission
X-RAMCache
X-Provided-By
X-Acquia-Site
X-Acquia-Purge-Tags
X-RSL
X-RPS
X-StackifyID
Xet-Cookie
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-RPM
X-Yottaa-OS
X-Dw-Trace-Id
X-Country-Code-Real
X-FTR-Backend
X-FTR-Backend-Server
X-Action
X-FTR-Balancer
X-Oss-Storage-Class
X-Oss-Server-Time
Warning
X-ElasticPress-Search
Xc-Version
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
X-Oss-Object-Type
X-FTR-DC
X-FTR-Cache-Status
X-FTR-Realm
X-SB
WP-Super-Cache
X-Pad
Vha6-Origin
Ohc-Response-Time
X-Swift-Error
X-Webstats-RespID
X-Pf-Uncompressing
X-UnsetCookies
Req-ID
X-Cache-Expires
X-Cdn-Request-ID
X-Edge-POP
X-Snapshot-Date
ServerName
X-FTR-Expires
X-C
X-MiniProfiler-Ids
X-TH-Server