Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-RAY
CF-Cache-Status
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
X-XSS-Protection
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
Alt-Svc
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Permitted-Cross-Domain-Policies
X-Request-ID
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-Cache-Status
X-DNS-Prefetch-Control
X-Generator
X-Cacheable
Timing-Allow-Origin
P3p
X-Content-Security-Policy
X-Iinfo
X-FRAME-OPTIONS
Status
Content-Encoding
Feature-Policy
X-AspNetMvc-Version
X-CDN
X-Envoy-Upstream-Service-Time
Upgrade
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-Ua-Compatible
Access-Control-Max-Age
X-Via
Keep-Alive
X-Ws-Request-Id
Request-Context
X-Robots-Tag
Server-Timing
X-AH-Environment
X-Server
X-Hacker
X-Age
X-Turbo-Charged-By
X-Proxy-Cache
X-Server-Powered-By
X-Cache-Group
X-Backend
Host-Header
X-Amz-Request-Id
EagleId
X-Nginx-Cache-Status
X-Amz-Id-2
X-Dns-Prefetch-Control
Report-To
X-LiteSpeed-Cache
X-Rq
X-UA-Device
X-Varnish-Cache
X-Page-Speed
Grace
X-Pingback
X-Swift-SaveTime
X-Swift-CacheTime
X-Device
Ali-Swift-Global-Savetime
EagleEye-TraceId
NEL
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Vhost
X-OneAgent-JS-Injection
X-Amz-Version-Id
Cf-Railgun
X-Dispatcher
X-Host
X-CST
X-Cache-Spec
X-Server-Id
Allow
X-Node
Surrogate-Control
X-Backend-Server
Request-Id
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Webkit-CSP
X-Readtime
X-WebKit-CSP
X-Response-Time
X-Akam-SW-Version
Accept-CH
Xkey
Accept-Ch-Lifetime
X-HW
X-Country
X-Application-Context
X-Language
X-Ac
Content-Location
X-Ruxit-JS-Agent
X-Template
MS-Author-Via
X-Cloud-Trace-Context
Rating
X-Cache-Lookup
X-Url
X-Mod-Pagespeed
X-B3-TraceId
Edge-Control
X-Vname
X-TtlSet
X-PC
X-Clacks-Overhead
X-ESI
X-MS-InvokeApp
X-Varnish-TTL
X-Trace
Accept-Ch
X-GitHub-Request-Id
X-Content-Type
Fastly-Restarts
X-Rack-Cache
X-Cnection
X-Origin-Cache
X-ASPNET-VERSION
X-GoogleNews-Bot
X-Exp-Variant
X-Kinja
X-Kinja-Build
X-Use-Magma
X-Kinja-Server
X-Cdn-Fetch
X-Exp-Id
X-Kinja-Revision
X-Country-Code
X-VARITI-CCR
X-D2id
X-Goog-Hash
Verso
X-FastCGI-Cache
Arr-Disable-Session-Affinity
X-Server-ID
X-Server-Name
Accept-CH-Lifetime
X-Cached
X-Vcap-Request-Id
X-Buckets
Cache-Tag
X-Navigation-Version
X-Abt-Application-Version
X-ORACLE-DMS-ECID
X-Amz-Rid
X-Client-IP
Service-Worker-Allowed
X-Powered-By-Plesk
X-Fastly-Request-ID
RTSS
Access-Control-Request-Method
X-Powered-CMS
X-MSEdge-Ref
X-Element-Page-Cache
Public-Key-Pins
X-Middleton-Display
Display
X-Sol
Response
Pagespeed
X-Middleton-Response
X-NF-Request-ID
X-Upstream
X-Dw-Request-Base-Id
X-Cache-TTL
X-Px
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Ttl
X-Version
X-Edge
S
X-TTL
X-Kinsta-Cache
X-Edge-Location-Klb
X-LLID
Realpath
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-ECACHE
X-Accel-Expires
SPIisLatency
SPRequestDuration
SPRequestGuid
X-SharePointHealthScore
X-Jurisdiction
X-HP-Webp
X-Instrumentation
X-MCACHE
X-Kraken-Routeconfig-Destination
X-Mid
X-T
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-PressLabs-Stats
X-Shield-Request-Id
X-Content-Security-Policy-Report-Only
X-Forwarded-Proto
X-Cache-Key
X-DynaTrace
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
Edge-Cache-Tag
Fastcgi-Cache
X-Recruiting
Charset
X-Correlation-Id
X-Amz-Server-Side-Encryption
X-ORACLE-DMS-RID
X-Ruxit-Js-Agent
X-XRDS-Location
TP-Cache
TP-L2-Cache
X-Content-Digest
X-Mg-S
Nginx-Cache
X-Id
Filters
X-Request-Processing-Time
TCN
X-Request-Received
Front-End-Https
X-Ezoic-Cdn
X-Oneagent-Js-Injection
Server-Node
Alternate-Protocol
X-Logged-In
X-Forwarded-For
X-Release
Cache-Tags
Content-MD5
X-Origin-Upstream-Status
X-Geo-Country
Fusion-Source
Fusion-Template-Id
Fusion-Content-Id
Fusion-Component-Id
Fusion-Deployment-Id
Fusion-Content-Source
X-Hostname
X-Litespeed-Cache
X-Amzn-Trace-Id
X-Protected-By
X-Grace
X-Origin-Server
X-RateLimit-Remaining
X-Www-Served-By
Server-Name
Host
Cleartype
X-F-Cache
X-Rid
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Metageneration
X-Amz-Replication-Status
X-Contextid
X-GUploader-UploadID
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
X-Az
X-HS-Combine-CSS
X-AppVersion
X-Activity-Id
X-LB-Cache
X-Debug-Info
X-Frontend
Section-Io-Cache
MicrosoftSharePointTeamServices
X-NWS-LOG-UUID
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Git-Hash
X-Page-Id
X-Ser
X-Cache-Age
X-WebKit-CSP-Report-Only
X-Respond-Thread
X-VCache
X-Upgrade-Enabled
Accept-Charset
X-Daa-Tunnel
X-Aspnetmvc-Version
X-Content-Options
Access-Control-Allow-Method
X-DIS-Request-ID
X-Mobile-URL
X-Hits
X-Varnish-Age
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Varnish-Grace
X-Source
Healthy
X-Signature
X-Varnish-Backend
X-B-Cache
Paypal-Debug-Id
Viewport
X-B3-Sampled
ServerID
Payment
X-Whom
X-Route-Name
X-Cache-Action
X-Aspnet-Duration-Ms
X-Flags
X-Request-Guid
X-Providence-Cookie
X-TT
X-FB-Debug
X-Is-Crawler
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
X-CACHE-GROUP
Node
X-AOL-HN
X-Fastcgi-Cache
X-App-Environment
AR-ATIME
AR-CACHE
Ar-Sid
AR-Request-ID
AR-PoweredBy
Version
X-N
X-Seen-By
DynaTrace
X-Mobile
X-Load-Cache
Fastcgi-Useragent
X-Type
DC
X-Yandex-Sdch-Disable
X-HTML-Minification-Powered-By
MS-CV
X-Distributor
X-Microsite
X-Request-Handler-Origin-Region
X-XRDS-LOCATION
SRV
Retry-After
X-Cache-Expired-At
X-Tt-Trace-Tag
X-Tt-Trace-Host
Frame-Options
Filterid
X-Cache-Control
X-Ab
X-User-Agent
X-Response-Served-From
X-IPLB-Instance
X-Original-Request-Id
X-Jobs
X-Real-IP
X-Region
X-RemovedCookies
X-Proxy-Cache-Status
X-ProcessESI
Refresh
X-UUID
X-IPS-LoggedIn
X-Varnish-Server
X-Adobe-Content
X-Adobe-Loc
X-Debug-IsPreview
X-Debug-IsConnected
X-Tumblr-User
X-Tumblr-Pixel
X-Cluster-Name
X-Content-Powered-By
X-Instance
X-Cacheable-TTL
X-Device-Type
X-Tumblr-Pixel-0
Uber-Trace-Id
X-Tumblr-Pixel-1
Access-Control-Request-Headers
X-B
VIX-Pulpo-Node
NGB
X-Proxy
X-Cache-Time
VIX-Pulpo-Upstream-Status
X-G
X-Framework
X-Page-View
X-RTag
Ms-Operation-Id
X-RateLimit-Limit
X-App-Version
X-Vgn-Hpd-Reason
X-Zen-Fury
X-Debug
X-FW-Static
X-FW-Server
X-FW-Dynamic
Countrycode
X-FW-Type
X-FW-Serve
X-FW-Hash
X-FireWall-Port
X-Time
X-Accel-Buffering
X-NGENIX-Cache
Cache-Status
Section-Io-Id
Section-Io-Origin-Status
X-CDN-Forward
X-Wix-Request-Id
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
X-Mg-Request-UUID
Cache
X-Azure-Ref
X-Nginx-Cache
X-Cache-Rule
X-Node-Name
X-Oracle-Dms-Rid
X-Is-Bot
X-Rendered-As
X-Drupal-Cache-Tags
X-Ms-Version
X-Ms-Request-Id
Liferay-Portal
Referer-Policy
S-Cnection
Surrogate-Key
SD-X-WS
X-Cache-Hit
Country
X-App-Server
Amp-Access-Control-Allow-Source-Origin
X-EdgeConnect-Cache-Status
X-L-Path
Eomportal-Instance
X-Environment-Context
X-Cache-Operation
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-UPSTREAM-Address
X-ES-SERVER
Meta-Geo
X-JoinUs
Selected-Fe
X-Drupal-Cache-Contexts
X-Timing-Wait
X-RN-RSRV
X-SaId
X-Proxy-Build
X-Varnishpool
X-S-Maxage
X-Via-Fastly
X-ShopId
From-Origin
X-PHP-Backend
X-TNCMS
X-Xfnlog-Site
X-Request-Time
X-Cache-TTL-Remaining
X-GG-Cache-Date
X-Alternate-Cache-Key
X-Shopify-Stage
X-ShardId
X-Loop
X-Sorting-Hat-PodId
X-Varnish-Hostname
X-No-Session
X-Sorting-Hat-ShopId
X-Storefront-Renderer-Rendered
X-Varnish-Beresp-Grace
X-Adobe-Source
Cache-Name
X-Cache-Server
X-BYPASS-REASON
X-Backend-Host
X-Pubstack
X-ProxyCache-Key
X-Revision
ServedBy
X-AWS-Id
X-ProxyCache-Status
Protected
X-LAGOON
X-VWS-Id
X-Handled-By
X-Human
X-Endurance-Cache-Level
X-R9-Blue-Green-Version
X-Aws-Lambda-Call-Status
X-LJ-Flow-ID
TWC-GeoIP-Country
Country-Code
TWC-Locale-Group
Property-Id
TWC-Privacy
Cache-Tv-Group
TWC-GeoIP-LatLong
Azure-Version
Azure-SiteName
Azure-RegionName
Apigw-Requestid
Fastly-SSL
Azure-SlotName
TWC-Connection-Speed
Azure-InstanceId
TWC-Device-Class
Webcakes-Region
X-Origin-Date
X-Proto
X-NYM-Debug-Backend
Webcakes-App-Name
X-Say-Cacheable
X-Hl-Ver
X-Say-TTL
X-Origin-Hint
X-PCL
X-Tumblr-Pixel-2
X-RCS-CacheZone
X-SayCDN-TTL
X-Be
X-Server-W
Webcakes-App-Version
X-UA-Device-Type
X-OCL
X-Cache-Type
X-ApacheServer
Mn-Server-Ip
X-Section
X-FB-TRIP-ID
X-PERF
X-Backend-Name
X-Format
X-Status
X-Akamai-Edgescape
X-Access
X-TA-CDN-Provider
Akamai-GRN
X-Labrador-Cache-Channel
X-PHP-Host
Xserver
Decoy-Debug-Status
X-Sql-Duration-Ms
Decoy-Debug-Key
CF-IPCountry
Decoy-Debug-TTL
X-Sql-Count
X-Hyper-Cache
X-Hosted-By
X-Uri
X-Web-Node
X-Parallel-Accel
X-B3-SpanId
X-Redis-Cache
X-Cache-PHP
X-ATG-Version
X-Ua-Device
X-TT-LOGID
X-Time-Microsecs
X-FW-Version
X-Trace-Id
X-ServerID
X-WA-Info
GEO-INFO
X-Rule
Count-Hit
X-CSRF-Token
X-HP-Trace-Id
AMP-Access-Control-Allow-Source-Origin
X-MP-GENERATED-AT
OT-Force-Account-Verify
X-Tumblr-Pixel-3
X-Cluster-Node
X-Content-Age
X-Akamai-Transformed
X-Soup
X-Datadome
X-Detected-As
X-Cached-By
X-Azure-Ref-OriginShield
X-Servername
Backend
X-Edge-Location
X-CS
X-Varnish-Cache-Hits
Cross-Origin-Opener-Policy
X-Mode
X-Cache-Host
X-Cache-Enabled
X-Generation-Time
X-Varnish-Beresp-Status
X-Bc-Bl
X-Dc
X-Varnish-Hits
Web-Mar-Node
X-Cache-Ttl
X-Microcachable
X-Unique-ID
X-Info
X-Amzn-Remapped-Content-Length
X-Varnish-Beresp-Ttl
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Cache-NGX
X-Storage
X-Debug-Cache
X-Routing-Service
X-Zipkin-Id
X-Proxied
X-Platform
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-APP-VERSION
SID
Ec-Rule-Version
X-Extlb
X-Magnolia-Registration
X-B3-Traceid
X-NWS-UUID-VERIFY
X-Origin-CC
X-Srv
Cross-Origin-Window-Policy
S-Rt
Upgrade-Insecure-Requests
Url
X-Origin-TTL
X-Ua
State
Apple-News-Services-Request-Url
CDCHOST
Cache-Host
X-Cache-Bucket
X-CF-Lambda-Version
X-CF-Lambda-Fn
Fastcgi-X-Cache-Version
MD5-Digest
M-TraceId
X-Cache-NE
CDN-Cache
X-Bip
CDN-RequestCountryCode
Source
DCR-Decision-By
T-Server
X-ARC
X-A-Dcw
X-A-Dam
X-A-Ccd
X-A-Dgt
X-Cache-Grace
Path
X-A-Wwc
A
X-A
Apple-News-Services-Parsed-Url
Odigeo-Trace-Id
Apple-News-Services-Host
CDN-EdgeStorageId
Apple-News-Services-Handled
X-Air-Trace-Id
Mobile-Detection-Method
X-Aed
Meta-Geo-Continent
DCR-Processing-Time-Ms
X-B-Cookie
Req-Svc-Chain
CDN-RequestId
CDN-Uid
BehaviorPad-Version
Expiry
X-Aicache-OS
CDN-CachedAt
CDN-PullZone
Rendered-Blocks
X-Application
Surrogated-Key
X-BCube-Filmed-By
X-NAPM-TraceId
X-S
X-S-Cookie
X-ScT
X-Air-Source
X-Rojux
X-Rewrite-Enabled
X-PAYTM-SRV-ID
X-Processor
X-Ratelimit-Reset
X-Request-URI
X-Service
X-Session-Fingerprint
X-VG-WebServer
X-VG-WebCache
X-Vdms-Path
X-Vdms-Version
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
X-SRCache-Key
X-Via-JSL
X-Thanos
Host-ID
X-PBS-Appsvrname
Content-Secure-Policy
X-Destination
DataCenter
X-Epic-Correlation-Id
X-External-Request-Id
X-From
X-D
X-Developer
X-Locale
X-Connection-Hash
X-Air-Hostname
Server-Info
Who
L
X-Clientip
Fastly-SWR
X-Tenant
Fastly-SIE
Kp-EeAlive
X-Forwarded-Path
X-Platform-Server
NGX
X-NU-AKA-ACS-Version
X-VG-TLSProxy
Origin
PFcat
X-Rebelmouse-Cache-Control
Memcached
X-Orig-Expires
X-Rebelmouse-Surrogate-Control
Pics-Label
X-Shop-Environment
X-Served-From
X-GoCache-CacheStatus
X-Geo-Header
X-Hash
X-HN
X-Level-Front-Cache
X-Generated-On
X-Gamma-Serve
X-Device-Os
X-Core-Value
X-Envoy-Decorator-Operation
X-Cache-Debug
X-Branch-Name
X-Location
X-Backend-State
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
UCS
X-TrackingId
X-Var-Ttl
X-Sigma-Backend
X-Sigma
X-Proxy-Upstream
X-Request-UUID
X-Rocket-Build-Number
X-Scheme
X-VarnishDD-TTL
X-Cms-Context
DSUID
Esi-Enabled
Fastly-Backend-Name
Content-Disposition
Cmstype
C-Via
Cmsid
Fastly-Drupal-HTML
X-Forwarded-Host
X-Tb
X-DataDome
Wxu-Next-Region
Wxu-Next-Hostname
Wxu-Next-Commit
AKAMAI
X-Owner
Arc-Version
X-Eu-Site
X-GeoIP
X-Fastly-Backend
Is-Eu
X-Csrf-Jwt
Arc-Country
True-Client-Country-4JS
PB-RID
PB-PID
Adler-Geo
Vix-Hermes-Req-Id
Platform
X-Varnish-Ttl
X-Request-Host
X-Site-Version
X-Skip-Cache
X-CGP
X-Date
X-Req
X-Cluster
X-Developers
X-Thinkindot-L3
X-VServer
X-AIR-PT
Thinkindot-Control
X-Policy
X-SRV
X-User
Ha-Gx-Prefs
X-Accel-Expires-Debug
X-Fetched-On
X-VC-Cache
Location
X-JWT-State
Thinkindot-CacheControl-Type
X-LI-UUID
Release
X-Is-Gdpr
Pagetype
X-Loc
X-Origin-Expires
Fastcgi-Cache-TTL
X-VHOST
X-Li-Fabric
NM-Fastcgi-Cache
X-Li-Pop
L5d-Success-Class
X-GeoIP-City
Gh-Request-Id
CacheControlHeader
X-Variation
X-Has-Esi
X-Cache-Tags
Svr
TDXMobile
HA-Ipaddr
Thinkindot-CacheControl
X-Nginx-Cache-Key
Server-Ext
X-DPWN-IS-SECURE
X-Origin
Server-Host
Server-Hostname
Sever-Int
X-Generated-In
User-Cache-Control
X-Generated-By
X-RateLimit-Limit-Second
X-PF-Uncompressing
X-Fmm-Version
X-Fastly-Cache
X-FC-Vary-Parameters
X-Forwarded-Site
X-Goog-Meta-Goog-Reserved-File-Mtime
X-GEO
X-Amz-Meta-S3cmd-Attrs
X-Qloud-Router
X-Men
X-DefElseHash
X-DefHash
V-Age
Locid
IsBot
X-Ftr-Request-Id
X-Varnish-Remaining-TTL
Mail-Subject
X-Varnish-CookieINHashed-On
X-SIPLIST1
Webserver
We-Hiring
Cf-Device-Type
X-Sucuri-ID
X-Via-NSCOPI
X-Slack-Backend
X-Cache-Info
X-Clara-WADP
X-RateLimit-Remaining-Second
X-Viewer-Country
X-Varnish-CookieHashed-On
X-Micro-Cache
X-WADP-Cache
Nel
X-Mvc-Supplant-Cachable
X-Minions-Version
X-Wikidot-Backend
Cache-Key
X-Conf
X-EC-Lua
NtCoent-Length
X-Irp-Debug
X-Wikidot-Static-Cache
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Old-Content-Length
X-Varnish-Url
X-Cache-Id
X-Esi-Check
X-Gen-Mode
X-Block-Status
VNS-Cache
CPC-Cache
CPC-Age
Cache-Hits
X-Gzip
VNS-Age
X-Hnp-Log
X-Vc
X-Via-Poph
X-Via-Popn
MIME-Version
X-Via-Popv
X-BBC-Edge-Cache-Status
X-HS-Content-Campaign-Id
X-Zone
X-Ckpd-Fst-Backend
Powered-By-ChinaCache
X-Ratelimit-Limit
My-App
X-Mvc-Supplant-OutputCached
X-Servedbyhost
X-TX-ID
X-Unique-Id
X-DC
X-Internal-Host
X-Worker
XServer
X-Webkit-CSP-Report-Only
X-Pass-Why
Memory
X-Refresh
X-PJAX-URL
X-LB-ID
Time
X-V-Cache
X-Auto-Login
X-ID
X-CACHE-KEY
X-NCache
X-NC
X-Rocket-Nginx-Serving-Static
Server-ID
X-Traceid
WebServer
X-LSADC-Cache
X-Render-Time
X-Wa
X-Platform-Router
X-Platform-Processor
X-Newrelic-Synthetics
X-ZONE
X-Tx-Id
X-Platform-Cluster
X-OVcl-Cache
X-OVcl
X-Ratelimit-Remaining
X-NewRelic-App-Data
X-App
Cf-Bgj
Geo-Info
X-Webkit-Csp
X-SD-PageType
X-TIME
HostName
X-Cache-Remote
X-Correlation-ID
X-Backend-TTL
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-M-Reqid
X-Qnm-Cache
X-Datadog-Trace-Id
Magicmarker
Environment
X-M-Log
X-TraceId
X-NodeID
X-Nyt-Route
X-Origin-Time
X-Gdpr
DB-Nickname
X-API-Version
X-BBC-Origin-Response-Status
Hostname
X-Server-IP
GeoIp-Country-Code
Resin-Trace
X-VCL-Version
X-Dispatcher-Server
Geoip-Latitude
X-Geo
Cluster
X-Cache-Config
X-Method
X-CLOUD-TRACE-CONTEXT
X-Cache-Var
X-Cache-Var-Map
X-Edge-Pop
X-LI-Proto
Candidate-Md5Url
X-Pod-Name
X-Via-Ucdn
X-Tb-Optimization-Total-Bytes-Saved
X-AB
Ssr
X-IP
Datacenter
Ohc-File-Size
X-Ua-Browser
X-Content
Tcn
X-MSEdge-Features
X-Dynatrace
X-HITS
X-ElasticPress-Query
X-Akamai-Pragma-Client-IP
Cf-Ipcountry
X-CACHE-AGE
N-Cache
X-MSEdge-Flight
X-Nc
X-Origin-Response-Time
X-Li-Proto
LB
Web-Mar-Region
GeoIP-Country-Code
GeoIP-Latitude
X-DynaTrace-JS-Agent
X-Node-Id
Cdn
X-Varnish-Beresp-TTL
X-Trv-Group
X-NODE
Proxy-Connection
X-Vcl-Version
Servername
X-Via-CDN
X-Wix-Viewer-Type
X-ND-Cache
Onion-Location
X-HostName
Env
WWW-Authenticate
X-Varnish-Cacheable
X-APP
X-EIG-Tracking-Id
X-ServerName
CF-Cached-On
X-Reqid
X-HS-Status
WZWS-RAY
X-Cs
Server-Id
Sid
X-WA
X-Dynatrace-Js-Agent
CDN
X-Fpc
Lb
X-MG-S
X-Fastly-Backend-Reqs
Cteonnt-Length
X-NGINX-Cache
Rt-Fastcgi-Cache
X-Request-Start
Viewtype
X-Tid
X-TIM-N
Redirect-Candidate
VivaBuild
X-Pjax-Url
X-Up
URI
X-URL
X-Lb-Id
Tracecode
Machine
X-Check-Cacheable
X-Esi
X-CSRF-TOKEN
Ohc-Cache-HIT
X-Xrds-Location
X-Via-PopV
X-Via-PopN
X-Fastly-Request-Id
X-VC
X-Cache-Date
X-Via-PopH
Is-Us
X-IN-APIGATEWAY
X-Cache-Backend
Pramga
X-IN-APIGATEWAYSSL
X-FTR-Request-ID
X-Cdn-Forward
X-Sn-Servicetimems
X-Cdn-Origin
Shield-Pop
Mime-Version
X-Amz-Meta-Cb-Modifiedtime
X-ServedByHost
FSS-Cache
Server-Ttl
CountryCode
X-SN
On-Server
X-Acquia-Application-Trace
X-Cache-ASPX
X-Swa-Ws
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Fastly-Cache-Hits
X-UnsetCookies
CACHE
X-Varnish-Authentication
X-FORWARDED-FOR
X-Contensis-Viewer-Groups
X-Acquia-Site
X-Provided-By
X-RAMCache
X-LiteSpeed-Cache-Control
X-Core-Mission
W
CloudFront-Viewer-Country
X-Air-Pt
X-Cdn-Request-ID
X-StackifyID
X-Oss-Hash-Crc64ecma
X-RPS
Warning
X-RSL
X-Oss-Object-Type
Req-ID
Content-Script-Type
X-RPM
Content-Style-Type
X-ElasticPress-Search
Xet-Cookie
Xc-Version
X-Cache-Expires
X-Action
X-Pad
X-FTR-Cache-Status
X-FTR-Balancer
X-DW
X-FTR-Backend-Server
X-FTR-DC
X-FTR-Realm
X-Pf-Uncompressing
X-Swift-Error
X-Yottaa-OS
X-SB
X-FTR-Backend
Ohc-Response-Time
WP-Super-Cache
X-DB
X-DI
X-DSS
X-Oss-Request-Id
X-Oss-Server-Time
X-Webstats-RespID
Vha6-Origin
X-Dw-Trace-Id
X-Oss-Storage-Class
X-Country-Code-Real
X-TH-Server
X-MiniProfiler-Ids
X-Tt-Logid
ServerName
X-Snapshot-Date
X-C
X-FTR-Expires