Threat Level: green Handler on Duty: Russ McRee

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
Link
ETag
Pragma
Expect-CT
X-Powered-By
X-XSS-Protection
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
Alt-Svc
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Timer
X-Download-Options
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-Request-ID
X-Cache-Status
X-Generator
X-Cacheable
X-DNS-Prefetch-Control
Timing-Allow-Origin
P3p
X-Content-Security-Policy
X-Iinfo
Status
X-Ua-Compatible
Feature-Policy
Content-Encoding
X-AspNetMvc-Version
X-CDN
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
Upgrade
Access-Control-Max-Age
X-Drupal-Dynamic-Cache
X-Via
X-Dns-Prefetch-Control
Keep-Alive
X-Ws-Request-Id
Request-Context
Server-Timing
X-Robots-Tag
X-AH-Environment
X-Hacker
X-Server
X-Age
X-Turbo-Charged-By
X-Proxy-Cache
X-Cache-Group
X-Server-Powered-By
X-Backend
X-Amz-Request-Id
Host-Header
X-Amz-Id-2
EagleId
X-Nginx-Cache-Status
Report-To
X-LiteSpeed-Cache
X-Rq
X-Varnish-Cache
Grace
X-Page-Speed
X-UA-Device
X-Pingback
X-Swift-CacheTime
X-Swift-SaveTime
EagleEye-TraceId
Ali-Swift-Global-Savetime
X-Device
X-Vhost
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Amz-Version-Id
NEL
X-Dispatcher
X-OneAgent-JS-Injection
Cf-Railgun
X-Host
X-WebKit-CSP
X-Cache-Spec
X-Server-Id
X-CST
X-Node
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Backend-Server
Allow
Request-Id
Surrogate-Control
X-Readtime
Accept-CH
X-Akam-SW-Version
X-Response-Time
Accept-Ch-Lifetime
Xkey
X-HW
X-Language
X-Application-Context
X-Template
X-Country
X-Ac
X-Ruxit-JS-Agent
Content-Location
X-Cache-Lookup
X-Cloud-Trace-Context
X-Webkit-CSP
Rating
MS-Author-Via
X-Url
Edge-Control
X-Vname
X-TtlSet
X-PC
X-Mod-Pagespeed
X-Clacks-Overhead
X-Varnish-TTL
X-B3-TraceId
X-Trace
Fastly-Restarts
X-Content-Type
X-MS-InvokeApp
X-Rack-Cache
X-Origin-Cache
X-ESI
X-Buckets
X-GitHub-Request-Id
Accept-Ch
X-Cnection
X-Country-Code
X-Goog-Hash
X-VARITI-CCR
X-D2id
Verso
X-Exp-Variant
X-Kinja-Build
X-Kinja
X-Kinja-Revision
X-Use-Magma
X-Exp-Id
X-GoogleNews-Bot
X-Cdn-Fetch
X-Kinja-Server
Arr-Disable-Session-Affinity
X-FastCGI-Cache
X-ORACLE-DMS-ECID
X-Vcap-Request-Id
Cache-Tag
Service-Worker-Allowed
X-Abt-Application-Version
X-Server-Name
X-Cached
X-Amz-Rid
X-Server-ID
X-Client-IP
Accept-CH-Lifetime
X-Navigation-Version
X-Px
RTSS
X-Powered-By-Plesk
X-Cache-TTL
Public-Key-Pins
X-Fastly-Request-ID
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Access-Control-Request-Method
X-Element-Page-Cache
X-MSEdge-Ref
X-Powered-CMS
X-Dw-Request-Base-Id
X-Upstream
X-NF-Request-ID
X-TTL
X-Version
Response
Pagespeed
Display
X-Middleton-Response
X-Middleton-Display
X-Sol
S
X-Kinsta-Cache
X-Edge-Location-Klb
X-Edge
X-LLID
Mrf-Cache-Status
MRF-Tech
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-B3-TraceId-Primal
X-Kraken-Routeconfig-Destination
X-Instrumentation
X-ECACHE
X-Ttl
X-Cache-Key
X-Accel-Expires
Realpath
X-HP-Webp
X-Jurisdiction
X-Shield-Request-Id
X-Correlation-Id
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
X-T
SPRequestGuid
X-DynaTrace
X-SharePointHealthScore
X-Litespeed-Cache
X-Mid
X-MCACHE
X-PressLabs-Stats
X-ORACLE-DMS-RID
X-XRDS-Location
SPRequestDuration
SPIisLatency
X-Content-Security-Policy-Report-Only
Edge-Cache-Tag
Fastcgi-Cache
X-Mg-S
X-Forwarded-Proto
X-Amz-Server-Side-Encryption
Nginx-Cache
X-Content-Digest
TP-L2-Cache
TP-Cache
X-Recruiting
Charset
X-Oneagent-Js-Injection
Front-End-Https
X-Request-Received
X-Request-Processing-Time
TCN
Filters
X-Id
Alternate-Protocol
Server-Node
X-Ruxit-Js-Agent
X-Logged-In
X-Forwarded-For
X-Geo-Country
Content-MD5
X-Ezoic-Cdn
Fusion-Component-Id
Fusion-Content-Id
Fusion-Deployment-Id
Fusion-Source
Fusion-Content-Source
Fusion-Template-Id
Cache-Tags
X-Protected-By
X-ASPNET-VERSION
X-Hostname
X-Amzn-Trace-Id
X-Origin-Upstream-Status
X-Grace
X-NWS-LOG-UUID
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-F-Cache
X-Origin-Server
Cleartype
X-Www-Served-By
X-Debug-Info
X-Amz-Replication-Status
X-Rid
X-LB-Cache
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Combine-CSS
Host
X-Az
X-AppVersion
X-Activity-Id
X-Contextid
X-Ab
X-Daa-Tunnel
X-Release
X-Git-Hash
Section-Io-Cache
X-Erf-Bev-Bev-Is-Generated
X-Page-Id
X-Erf-Bev-Bev
X-Browser-Type
Server-Name
X-Ser
X-Frontend
X-VCache
X-RateLimit-Remaining
MicrosoftSharePointTeamServices
X-Aspnetmvc-Version
X-Cache-Age
X-Content-Options
Accept-Charset
X-Upgrade-Enabled
X-Respond-Thread
Access-Control-Allow-Method
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Hits
X-Source
ServerID
X-Mobile-URL
X-DIS-Request-ID
X-Flags
X-B-Cache
X-Is-Crawler
X-Providence-Cookie
X-Route-Name
X-Request-Guid
X-Signature
X-Aspnet-Duration-Ms
X-CACHE-GROUP
X-WebKit-CSP-Report-Only
X-Varnish-Age
X-Cache-Action
X-Varnish-Backend
Healthy
Viewport
X-FB-Debug
X-Whom
Payment
X-TT
Paypal-Debug-Id
X-Varnish-Grace
Node
DynaTrace
X-B3-Sampled
X-App-Environment
X-Fastcgi-Cache
X-AOL-HN
Fastcgi-Useragent
X-Yandex-Sdch-Disable
X-Load-Cache
X-Mobile
Version
X-Seen-By
DC
X-Tt-Trace-Tag
X-N
X-Tt-Trace-Host
Filterid
X-Distributor
SRV
X-HTML-Minification-Powered-By
X-Type
X-User-Agent
X-Tec-Api-Origin
X-Cache-Control
Retry-After
X-Tec-Api-Root
X-Tec-Api-Version
Frame-Options
X-Ua-Device
MS-CV
X-Jobs
Refresh
X-Response-Served-From
X-Cache-Expired-At
X-XRDS-LOCATION
X-Original-Request-Id
X-FW-Dynamic
X-FW-Hash
X-FW-Server
X-FW-Static
X-FW-Type
X-UUID
X-FW-Serve
X-Proxy-Cache-Status
X-Adobe-Loc
NGB
X-Page-View
X-Adobe-Content
Amp-Access-Control-Allow-Source-Origin
X-Debug-IsConnected
X-Instance
X-Debug-IsPreview
X-Region
X-G
X-Real-IP
X-RemovedCookies
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-Cluster-Name
X-Proxy
X-NGENIX-Cache
X-ProcessESI
X-Cacheable-TTL
Access-Control-Request-Headers
VIX-Pulpo-Node
X-Tumblr-User
X-IPLB-Instance
X-Vgn-Hpd-Reason
X-Varnish-Server
VIX-Pulpo-Upstream-Status
X-Azure-Ref
X-Content-Powered-By
X-Node-Name
X-CDN-Forward
X-Framework
X-Device-Type
X-B
X-Cache-Time
Ms-Operation-Id
X-RTag
X-IPS-LoggedIn
X-HP-Trace-Id
X-Zen-Fury
Uber-Trace-Id
X-Cache-Hit
X-Aws-Lambda-Call-Status
X-Cache-Rule
Cache-Status
SD-X-WS
Referer-Policy
X-Wix-Request-Id
X-Rendered-As
Liferay-Portal
X-Is-Bot
X-Ms-Request-Id
X-Ms-Version
Countrycode
X-Drupal-Cache-Tags
Section-Io-Origin-Status
X-Oracle-Dms-Rid
Section-Origin-Responded
Section-Io-Id
Section-Io-Origin-Time-Seconds
X-Time
X-Mg-Request-UUID
X-Parallel-Accel
AR-ATIME
X-Request-Handler-Origin-Region
AR-PoweredBy
Ar-Sid
AR-Request-ID
AR-CACHE
X-Microsite
X-Debug
X-EdgeConnect-Cache-Status
X-Accel-Buffering
S-Cnection
X-Revision
X-RateLimit-Limit
X-Environment-Context
X-L-Path
X-App-Server
Country
X-Nginx-Cache
CF-IPCountry
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Cache-Operation
Cache
Count-Hit
X-APP-VERSION
X-Drupal-Cache-Contexts
X-ES-SERVER
X-UPSTREAM-Address
X-Endurance-Cache-Level
X-TNCMS
Meta-Geo
X-RN-RSRV
X-Loop
X-TA-CDN-Provider
X-GG-Cache-Date
X-FW-Version
X-JoinUs
X-SaId
X-Adobe-Source
X-LAGOON
From-Origin
X-SayCDN-TTL
X-Cache-Type
X-Cache-TTL-Remaining
X-App-Version
Surrogate-Key
X-Say-TTL
Akamai-GRN
X-Say-Cacheable
Azure-SlotName
Azure-SiteName
X-Xfnlog-Site
Azure-RegionName
X-Human
X-Request-Time
Protected
GEO-INFO
X-S-Maxage
X-NYM-Debug-Backend
Azure-Version
Eomportal-Instance
X-ShardId
X-Sql-Duration-Ms
X-Storefront-Renderer-Rendered
X-Varnish-Beresp-Grace
X-Alternate-Cache-Key
X-Sql-Count
X-Shopify-Stage
X-ShopId
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
Azure-InstanceId
Country-Code
Decoy-Debug-Key
Decoy-Debug-TTL
Decoy-Debug-Status
Cache-Name
Apigw-Requestid
X-AWS-Id
X-Be
X-BYPASS-REASON
Cache-Tv-Group
X-Status
X-Varnish-Hostname
X-FireWall-Port
X-VWS-Id
X-RCS-CacheZone
X-OCL
X-PHP-Host
X-Proto
X-R9-Blue-Green-Version
X-ProxyCache-Key
Fastly-SSL
ServedBy
X-ProxyCache-Status
X-Hosted-By
X-Handled-By
X-Labrador-Cache-Channel
X-LJ-Flow-ID
X-Pubstack
X-Varnishpool
X-No-Session
X-PCL
X-Web-Node
X-Redis-Cache
TWC-Device-Class
TWC-Connection-Speed
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Locale-Group
X-Proxy-Build
Webcakes-App-Version
X-PHP-Backend
X-Server-W
X-Akamai-Edgescape
X-Origin-Hint
X-Origin-Date
X-Hyper-Cache
X-Cache-Server
X-Timing-Wait
X-Section
X-Format
X-Uri
Webcakes-App-Name
Webcakes-Region
X-UA-Device-Type
X-Access
X-Tumblr-Pixel-2
X-Via-Fastly
TWC-Privacy
Property-Id
Selected-Fe
X-PERF
X-Backend-Host
Nel
X-B3-SpanId
X-ApacheServer
Mn-Server-Ip
X-FB-TRIP-ID
X-Cluster-Node
X-Hl-Ver
X-Time-Microsecs
X-Backend-Name
X-Servername
X-ATG-Version
OT-Force-Account-Verify
X-ServerID
X-B3-Traceid
Cross-Origin-Opener-Policy
X-Tumblr-Pixel-3
X-Detected-As
X-Azure-Ref-OriginShield
X-Cache-PHP
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
Web-Mar-Node
X-Varnish-Cache-Hits
Cross-Origin-Window-Policy
X-Cache-Host
Backend
X-Trace-Id
X-Content-Age
X-Generation-Time
X-Ua
X-Datadome
X-WA-Info
X-Varnish-Hits
Content-Secure-Policy
X-MP-GENERATED-AT
X-TT-LOGID
X-CS
X-SRV
Ec-Rule-Version
X-CSRF-Token
Xserver
X-Via-JSL
X-Soup
Source
X-Akamai-Transformed
X-Cdn
X-Bc-Bl
X-Cache-Enabled
X-Edge-Location
X-Ratelimit-Limit
X-Microcachable
X-Cache-Grace
X-Amz-Apigw-Id
X-Mode
X-Amzn-RequestId
X-Amzn-Remapped-Content-Length
X-Info
X-Ratelimit-Remaining
X-Rule
S-Rt
X-NWS-UUID-VERIFY
X-Forwarded-Host
X-Varnish-Beresp-Ttl
Url
Upgrade-Insecure-Requests
X-Air-Hostname
X-Air-Source
X-Origin-TTL
X-Unique-Id
X-Air-Trace-Id
X-Origin-CC
X-Locale
X-Varnish-Beresp-Status
X-Cached-By
X-Site-Version
X-GEO
X-Dc
SID
Content-Disposition
X-Tb
X-Magnolia-Registration
Fastcgi-X-Cache-Version
Fastly-SIE
Fastly-SWR
X-Vtex-Remote-Cache
Req-Svc-Chain
Rendered-Blocks
X-External-Request-Id
X-Epic-Correlation-Id
Expiry
X-Forwarded-Path
X-BCube-Filmed-By
Meta-Geo-Continent
X-A
X-Destination
Host-ID
X-VG-WebServer
X-Developer
X-Vtex-Processado-Em
X-Zipkin-Id
CDN-Cache
X-Cache-Bucket
CDCHOST
X-Cache-NE
Apple-News-Services-Handled
CDN-RequestId
CDN-Uid
CDN-PullZone
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
BehaviorPad-Version
X-Ftr-Request-Id
CDN-RequestCountryCode
Apple-News-Services-Request-Url
A
Odigeo-Trace-Id
DCR-Decision-By
X-NU-AKA-ACS-Version
DCR-Processing-Time-Ms
CDN-CachedAt
X-Extlb
X-CF-Lambda-Fn
Mobile-Detection-Method
CDN-EdgeStorageId
Path
X-CF-Lambda-Version
X-From
X-NAPM-TraceId
X-Connection-Hash
X-Request-URI
X-Rewrite-Enabled
X-Aicache-OS
X-D
X-AIR-PT
X-SRCache-Key
X-BBC-Edge-Cache-Status
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-ARC
X-Application
X-Rojux
X-Routing-Service
X-A-Dgt
X-Shop-Environment
X-A-Dcw
X-A-Dam
X-A-Ccd
X-Session-Fingerprint
X-A-Wwc
X-S-Cookie
X-S
X-ScT
X-Aed
M-TraceId
X-Ratelimit-Reset
X-Vdms-Version
X-Conf
X-PAYTM-SRV-ID
X-PBS-Appsvrname
X-Processor
User-Cache-Control
MD5-Digest
X-B-Cookie
X-VG-WebCache
X-Proxied
X-Debug-Cache
X-Platform-Server
T-Server
X-Orig-Expires
State
X-Storage
Surrogated-Key
X-Tenant
X-Cache-NGX
X-EC-Lua
X-DataDome
X-Cms-Context
Is-Eu
Fastly-Drupal-HTML
L
Cmstype
X-Fastly-Backend
Cmsid
X-Fastly-Cache
Fastly-Backend-Name
X-Envoy-Decorator-Operation
X-DPWN-IS-SECURE
X-Li-Fabric
X-Loc
X-Cache-Debug
X-Men
X-LI-UUID
X-Li-Pop
X-Cache-Info
Cache-Key
X-VServer
X-Backend-State
X-Request-UUID
UCS
X-Proxy-Upstream
X-VG-TLSProxy
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-JWT-State
X-Core-Value
X-Has-Esi
Cache-Host
X-TrackingId
X-Clientip
NGX
Origin
X-Variation
X-Is-Gdpr
Platform
Pics-Label
Adler-Geo
AMP-Access-Control-Allow-Source-Origin
X-Accel-Expires-Debug
X-Clara-WADP
X-Branch-Name
X-Worker
X-Cache-Id
X-Cluster
X-Block-Status
X-Bip
X-Ckpd-Fst-Backend
X-Gen-Mode
X-Origin-Expires
X-Origin
X-Thanos
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Old-Content-Length
X-Nginx-Cache-Key
X-Varnish-CookieHashed-On
X-Viewer-Country
X-Micro-Cache
X-Via-NSCOPI
X-Req
X-Request-Host
X-Sigma
X-SIPLIST1
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-Service
X-Served-From
X-VC-Cache
X-Slack-Backend
X-Rocket-Build-Number
X-VarnishDD-TTL
X-WADP-Cache
X-Location
X-Forwarded-Site
X-Gamma-Serve
X-Sigma-Backend
X-Generated-By
X-Fmm-Version
X-Esi-Check
X-DefElseHash
X-DefHash
X-Developers
X-Device-Os
X-Generated-On
X-Geo-Header
X-Hnp-Log
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-Level-Front-Cache
X-HN
X-Hash
X-GoCache-CacheStatus
X-Gzip
X-Var-Ttl
X-Thinkindot-L3
X-Date
X-Cache-Tags
Locid
Location
IsBot
PB-PID
PB-RID
Server-Host
Server-Ext
PFcat
Fastcgi-Cache-TTL
Esi-Enabled
X-Ua-Browser
X-Content
X-Tx-Id
Arc-Version
C-Via
DSUID
CPC-Age
Cf-Device-Type
Server-Hostname
CPC-Cache
TDXMobile
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Thinkindot-Control
True-Client-Country-4JS
VNS-Age
Vix-Hermes-Req-Id
VNS-Cache
Sever-Int
X-DC
X-Platform
XServer
X-Amz-Meta-S3cmd-Attrs
Server-Info
X-Generated-In
AKAMAI
X-NCache
X-GeoIP
We-Hiring
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-FC-Vary-Parameters
X-Fetched-On
CacheControlHeader
X-GeoIP-City
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Sucuri-ID
Wxu-Next-Commit
X-Skip-Cache
X-Scheme
X-Mvc-Supplant-Cachable
X-Owner
X-Irp-Debug
Wxu-Next-Region
X-Vdms-Path
X-Policy
Wxu-Next-Hostname
X-Planisys-CDN-TTL
Arc-Country
X-M-Log
Svr
X-Csrf-Jwt
Memcached
Gh-Request-Id
HA-Ipaddr
Ha-Gx-Prefs
X-Auto-Login
L5d-Success-Class
X-CGP
Release
X-Eu-Site
Mail-Subject
Pagetype
NM-Fastcgi-Cache
X-M-Reqid
V-Age
NtCoent-Length
Webserver
X-Qnm-Cache
X-Qloud-Router
X-HS-Content-Campaign-Id
X-V-Cache
Kp-EeAlive
X-Unique-ID
X-Mvc-Supplant-OutputCached
Cache-Hits
X-Via-Popv
MIME-Version
X-Servedbyhost
X-Via-Popn
X-LSADC-Cache
X-Via-Poph
X-Platform-Router
X-Render-Time
DataCenter
X-Platform-Processor
X-Rocket-Nginx-Serving-Static
X-Platform-Cluster
X-Zone
X-User
X-SD-PageType
X-Cache-Ttl
X-Srv
X-Cache-Remote
Who
Environment
X-PF-Uncompressing
X-NC
X-Cache-Var
X-Cache-Var-Map
X-ID
X-PJAX-URL
X-Wa
X-Vc
X-Varnish-Url
X-Origin-Time
X-Nyt-Route
X-BBC-Origin-Response-Status
X-NodeID
X-Minions-Version
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-API-Version
X-Traceid
X-Gdpr
X-Datadog-Trace-Id
X-Varnish-Ttl
WebServer
Cluster
X-Refresh
X-Via-Ucdn
Server-ID
X-App
X-Pod-Name
Memory
X-VCL-Version
Time
X-Internal-Host
X-Cache-Config
X-TIME
X-LB-ID
X-Server-IP
My-App
Powered-By-ChinaCache
Candidate-Md5Url
X-Webkit-Csp
X-CACHE-KEY
X-ZONE
HostName
X-Webkit-CSP-Report-Only
X-Pass-Why
X-Newrelic-Synthetics
Datacenter
Geoip-Latitude
X-Esi
X-CLOUD-TRACE-CONTEXT
X-LI-Proto
X-NewRelic-App-Data
Web-Mar-Region
N-Cache
GeoIp-Country-Code
Onion-Location
X-TX-ID
X-ElasticPress-Query
X-Tb-Optimization-Total-Bytes-Saved
X-Edge-Pop
X-OVcl-Cache
X-OVcl
Geo-Info
Resin-Trace
X-TraceId
X-VHOST
Servername
Cf-Bgj
X-Akamai-Pragma-Client-IP
Hostname
X-Backend-TTL
Ohc-File-Size
Tcn
X-Dynatrace
X-CACHE-AGE
X-HITS
X-Origin-Response-Time
Magicmarker
X-Varnish-Cacheable
X-Tt-Logid
WWW-Authenticate
X-Geo
X-EIG-Tracking-Id
CDN
LB
X-Dispatcher-Server
X-Li-Proto
X-Method
X-Fpc
X-NODE
X-Varnish-Beresp-TTL
X-AB
X-Correlation-ID
Proxy-Connection
X-Wix-Viewer-Type
X-TIM-N
X-MSEdge-Features
X-Tid
GeoIP-Country-Code
Redirect-Candidate
X-Dynatrace-Js-Agent
X-MSEdge-Flight
Cdn
X-HostName
DB-Nickname
Ssr
Tracecode
X-IP
X-Up
GeoIP-Latitude
Cf-Ipcountry
X-Cache-Date
X-Fastly-Backend-Reqs
Pramga
Is-Us
X-Vcl-Version
X-Request-Start
X-HS-Status
X-NGINX-Cache
X-CSRF-TOKEN
X-Cs
CF-Cached-On
X-Sn-Servicetimems
X-APP
X-Amz-Meta-Cb-Modifiedtime
X-Node-Id
Server-Id
X-COUNTRY
Sid
X-Cdn-Origin
Lb
X-MG-S
X-Provided-By
X-Core-Mission
W
X-WA
X-Trv-Group
X-ND-Cache
X-ServerName
X-Lb-Id
X-Webkit-Csp-Report-Only
Cteonnt-Length
X-UnsetCookies
X-FORWARDED-FOR
X-Nc
URI
X-Via-CDN
WZWS-RAY
X-Check-Cacheable
CloudFront-Viewer-Country
X-Pjax-Url
Env
X-VC
X-Cache-Expires
X-DynaTrace-JS-Agent
X-Reqid
Ohc-Cache-HIT
X-SERVER-NAME
X-Via-PopN
X-Fastly-Request-Id
X-Via-PopV
X-Via-PopH
WP-Super-Cache
X-Cache-Backend
X-CCDN-Origin-Time
Shield-Pop
X-Cache-Status-Check
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-ServedByHost
X-Region-Sid
X-Pf-Uncompressing
X-SN
Mime-Version
X-Sucuri-Cache
X-IN-APIGATEWAYSSL
CountryCode
X-IN-APIGATEWAY
X-Acquia-Site
Server-Ttl
VivaBuild
X-Acquia-Application-UUID
CACHE
Viewtype
X-Acquia-Application-Trace
X-Acquia-Purge-Tags
X-Fastly-Cache-Hits
X-Moov-T
X-Pad
X-Moov-Xdn-Version
Xc-Version
X-LiteSpeed-Cache-Control
X-RAMCache
X-Cache-ASPX
X-Contensis-Viewer-Groups
X-Edge-POP
X-Varnish-Authentication
X-CUA
Rt-Fastcgi-Cache
X-Ig-Push-State
User-Agent
X-Cdn-Request-ID
EpKe-Alive
X-RPM
Ohc-Response-Time
X-Action
X-DB
X-DI
X-Dw-Trace-Id
X-Yottaa-OS
X-Webstats-RespID
X-SB
X-Swift-Error
X-DSS
Vha6-Origin
X-DW
Xet-Cookie
X-StackifyID
X-RSL
X-RPS
X-Cdn-Forward
X-Amz-Meta-Opti
Content-Script-Type
HIT
Content-Style-Type
FSS-Cache
X-ElasticPress-Search
Machine
Req-ID
ServerName
X-CF-Powered-By
X-TH-Server
X-MiniProfiler-Ids