Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-RAY
CF-Cache-Status
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
X-XSS-Protection
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
Alt-Svc
X-Served-By
X-Xss-Protection
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Permitted-Cross-Domain-Policies
X-Request-ID
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
P3p
X-FRAME-OPTIONS
X-Content-Security-Policy
X-Iinfo
Status
Content-Encoding
Feature-Policy
X-AspNetMvc-Version
X-CDN
X-Envoy-Upstream-Service-Time
Upgrade
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Access-Control-Max-Age
X-Via
Keep-Alive
X-Ws-Request-Id
Request-Context
X-Robots-Tag
Server-Timing
X-AH-Environment
X-Ua-Compatible
X-Server
X-Hacker
X-Dns-Prefetch-Control
X-Age
X-Turbo-Charged-By
X-Proxy-Cache
X-Server-Powered-By
X-Cache-Group
X-Backend
Host-Header
X-Amz-Request-Id
EagleId
X-Nginx-Cache-Status
X-Amz-Id-2
Report-To
X-LiteSpeed-Cache
X-Rq
X-Varnish-Cache
X-UA-Device
X-Page-Speed
Grace
X-Swift-SaveTime
X-Swift-CacheTime
X-Pingback
X-Device
Ali-Swift-Global-Savetime
EagleEye-TraceId
NEL
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Vhost
X-Amz-Version-Id
Cf-Railgun
X-OneAgent-JS-Injection
X-Dispatcher
X-Host
X-Server-Id
X-CST
X-Cache-Spec
Allow
X-Node
Surrogate-Control
Request-Id
X-Backend-Server
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Webkit-CSP
Accept-CH
X-Readtime
X-Response-Time
X-Akam-SW-Version
X-WebKit-CSP
Xkey
Accept-Ch-Lifetime
X-HW
X-Country
X-Ac
X-Language
Content-Location
X-Application-Context
X-Ruxit-JS-Agent
MS-Author-Via
X-Template
X-Cloud-Trace-Context
Rating
X-Cache-Lookup
X-Url
X-Mod-Pagespeed
X-B3-TraceId
Edge-Control
X-Vname
X-PC
X-TtlSet
X-Clacks-Overhead
X-ESI
X-MS-InvokeApp
X-Trace
X-Varnish-TTL
X-Content-Type
X-GitHub-Request-Id
X-ASPNET-VERSION
Fastly-Restarts
X-Cnection
X-Origin-Cache
X-Rack-Cache
X-D2id
X-Country-Code
X-Cdn-Fetch
X-Exp-Id
X-Kinja-Server
X-Use-Magma
X-Kinja-Revision
X-Kinja-Build
X-GoogleNews-Bot
X-Exp-Variant
X-Kinja
X-VARITI-CCR
X-Goog-Hash
Verso
Arr-Disable-Session-Affinity
Accept-CH-Lifetime
X-FastCGI-Cache
X-Cached
X-Buckets
X-Vcap-Request-Id
Accept-Ch
X-Navigation-Version
Cache-Tag
X-Server-Name
X-Client-IP
X-Amz-Rid
Service-Worker-Allowed
X-Abt-Application-Version
X-ORACLE-DMS-ECID
X-Powered-By-Plesk
X-Fastly-Request-ID
RTSS
Access-Control-Request-Method
X-Powered-CMS
X-MSEdge-Ref
X-Sol
Pagespeed
X-Element-Page-Cache
X-Middleton-Response
Display
X-Middleton-Display
Response
X-Cache-TTL
Public-Key-Pins
X-Server-ID
X-NF-Request-ID
X-Dw-Request-Base-Id
X-Upstream
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Version
X-Px
X-Ttl
X-TTL
S
X-Edge
X-Kinsta-Cache
X-Edge-Location-Klb
X-LLID
Realpath
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Accel-Expires
X-ECACHE
SPRequestDuration
SPIisLatency
X-SharePointHealthScore
SPRequestGuid
X-HP-Webp
X-Jurisdiction
X-T
X-Kraken-Routeconfig-Destination
X-Instrumentation
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Mid
X-MCACHE
X-PressLabs-Stats
X-Content-Security-Policy-Report-Only
X-Shield-Request-Id
X-Forwarded-Proto
X-Cache-Key
X-Correlation-Id
X-DynaTrace
Edge-Cache-Tag
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
X-Recruiting
Charset
Fastcgi-Cache
X-Amz-Server-Side-Encryption
TP-L2-Cache
TP-Cache
X-ORACLE-DMS-RID
Nginx-Cache
X-Content-Digest
X-Mg-S
X-XRDS-Location
X-Oneagent-Js-Injection
X-Request-Processing-Time
X-Request-Received
Filters
X-Id
X-Ezoic-Cdn
TCN
Front-End-Https
Server-Node
X-Logged-In
X-Release
Alternate-Protocol
X-Ruxit-Js-Agent
X-Forwarded-For
Cache-Tags
Content-MD5
X-Litespeed-Cache
Fusion-Content-Id
Fusion-Template-Id
Fusion-Component-Id
Fusion-Deployment-Id
Fusion-Source
Fusion-Content-Source
X-Origin-Upstream-Status
X-Geo-Country
X-Amzn-Trace-Id
X-Hostname
X-Protected-By
X-Grace
X-Origin-Server
Server-Name
X-Www-Served-By
Cleartype
X-Rid
X-F-Cache
X-Amz-Replication-Status
Host
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Activity-Id
X-Contextid
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Az
X-AppVersion
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Combine-CSS
X-LB-Cache
X-Debug-Info
X-RateLimit-Remaining
X-Frontend
Section-Io-Cache
X-Erf-Bev-Bev-Is-Generated
X-NWS-LOG-UUID
X-Erf-Bev-Bev
X-Browser-Type
MicrosoftSharePointTeamServices
X-WebKit-CSP-Report-Only
X-Page-Id
X-Ser
X-Git-Hash
X-Aspnetmvc-Version
X-Cache-Age
X-VCache
X-Respond-Thread
X-Upgrade-Enabled
X-Daa-Tunnel
Accept-Charset
X-Source
X-Content-Options
X-Hits
Access-Control-Allow-Method
X-DIS-Request-ID
X-Mobile-URL
X-Fastcgi-Cache
X-Varnish-Age
ServerID
X-Varnish-Backend
X-B-Cache
X-Signature
Paypal-Debug-Id
Viewport
X-Varnish-Grace
X-CACHE-GROUP
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Cache-Action
X-Aspnet-Duration-Ms
Payment
Healthy
X-Flags
X-Is-Crawler
X-Whom
X-Route-Name
X-Request-Guid
X-FB-Debug
X-Providence-Cookie
X-B3-Sampled
X-TT
Ar-Sid
AR-Request-ID
AR-PoweredBy
AR-ATIME
AR-CACHE
X-AOL-HN
Node
X-Tec-Api-Root
X-Tec-Api-Origin
X-App-Environment
X-Tec-Api-Version
X-N
Version
X-Seen-By
X-Load-Cache
X-Type
DynaTrace
Fastcgi-Useragent
X-Mobile
DC
X-Microsite
X-Yandex-Sdch-Disable
X-Request-Handler-Origin-Region
X-XRDS-LOCATION
MS-CV
X-Ab
X-Distributor
X-HTML-Minification-Powered-By
X-Cache-Expired-At
SRV
Retry-After
X-Tt-Trace-Host
X-Cache-Control
X-Tt-Trace-Tag
Frame-Options
X-User-Agent
Filterid
X-IPLB-Instance
X-Response-Served-From
X-Original-Request-Id
X-Tumblr-Pixel-0
X-Instance
X-Jobs
X-Tumblr-User
X-UUID
X-RemovedCookies
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-ProcessESI
X-Real-IP
X-Varnish-Server
X-IPS-LoggedIn
X-Proxy-Cache-Status
X-Cluster-Name
Refresh
X-Region
Ms-Operation-Id
Access-Control-Request-Headers
X-Device-Type
X-RTag
X-Cache-Time
X-Content-Powered-By
X-Adobe-Loc
X-Adobe-Content
X-Debug-IsPreview
X-Debug-IsConnected
Uber-Trace-Id
NGB
X-Proxy
X-G
X-Page-View
VIX-Pulpo-Node
X-B
VIX-Pulpo-Upstream-Status
X-Cacheable-TTL
X-Framework
X-Debug
X-Vgn-Hpd-Reason
X-FireWall-Port
X-FW-Static
X-FW-Type
X-FW-Server
X-FW-Serve
X-FW-Hash
X-FW-Dynamic
X-Accel-Buffering
X-Zen-Fury
Countrycode
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Origin-Responded
X-Time
X-Mg-Request-UUID
Section-Io-Id
X-Wix-Request-Id
X-CDN-Forward
Cache
X-NGENIX-Cache
Cache-Status
X-Oracle-Dms-Rid
X-RateLimit-Limit
X-Azure-Ref
X-App-Version
X-Nginx-Cache
X-Rendered-As
Amp-Access-Control-Allow-Source-Origin
X-Is-Bot
X-Node-Name
X-Cache-Rule
Surrogate-Key
Country
X-EdgeConnect-Cache-Status
X-Ms-Version
X-Cache-Hit
X-Drupal-Cache-Tags
X-Ms-Request-Id
S-Cnection
SD-X-WS
Referer-Policy
X-App-Server
Liferay-Portal
Eomportal-Instance
X-Environment-Context
X-L-Path
X-Cache-Operation
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-TA-CDN-Provider
X-Proxy-Build
Selected-Fe
Meta-Geo
X-UPSTREAM-Address
X-Timing-Wait
X-JoinUs
X-Tumblr-Pixel-2
X-RN-RSRV
X-ES-SERVER
X-Drupal-Cache-Contexts
X-SaId
X-Cache-Server
X-Sorting-Hat-PodId
X-Request-Time
X-Storefront-Renderer-Rendered
X-Backend-Host
From-Origin
X-Varnish-Hostname
X-Varnishpool
X-Alternate-Cache-Key
Protected
X-Cache-TTL-Remaining
X-GG-Cache-Date
X-Xfnlog-Site
X-TNCMS
CF-IPCountry
X-No-Session
X-Loop
X-PHP-Backend
X-Via-Fastly
X-ShardId
X-ShopId
X-Shopify-Stage
X-Sorting-Hat-ShopId
X-Endurance-Cache-Level
X-S-Maxage
Azure-SiteName
Azure-SlotName
TWC-GeoIP-LatLong
TWC-Device-Class
X-Pubstack
Azure-RegionName
TWC-Connection-Speed
X-Varnish-Beresp-Grace
TWC-Privacy
TWC-Locale-Group
Webcakes-App-Name
Webcakes-App-Version
Cache-Tv-Group
Webcakes-Region
Azure-InstanceId
X-Revision
Fastly-SSL
Azure-Version
Property-Id
X-BYPASS-REASON
X-PCL
X-Be
X-Origin-Hint
X-OCL
X-Adobe-Source
X-ProxyCache-Status
X-VWS-Id
X-ProxyCache-Key
X-Proto
X-LAGOON
X-Server-W
TWC-GeoIP-Country
X-R9-Blue-Green-Version
Cache-Name
X-LJ-Flow-ID
X-NYM-Debug-Backend
X-AWS-Id
X-Handled-By
Decoy-Debug-TTL
X-Origin-Date
Apigw-Requestid
Akamai-GRN
Decoy-Debug-Key
X-Section
Country-Code
X-Format
X-Access
X-Human
X-Say-Cacheable
X-UA-Device-Type
X-Hl-Ver
ServedBy
Decoy-Debug-Status
X-RCS-CacheZone
X-SayCDN-TTL
X-Say-TTL
X-Backend-Name
Mn-Server-Ip
X-Aws-Lambda-Call-Status
X-Sql-Count
X-Cache-Type
X-Akamai-Edgescape
X-Sql-Duration-Ms
X-ApacheServer
X-Status
X-FB-TRIP-ID
X-Labrador-Cache-Channel
X-PERF
X-PHP-Host
X-Hyper-Cache
X-Uri
X-Hosted-By
X-Redis-Cache
X-Cache-PHP
X-Web-Node
Xserver
X-B3-SpanId
X-Ua-Device
X-Parallel-Accel
X-ATG-Version
X-Rule
X-FW-Version
X-Trace-Id
X-WA-Info
X-Time-Microsecs
X-ServerID
X-MP-GENERATED-AT
X-Tumblr-Pixel-3
X-CSRF-Token
GEO-INFO
X-Content-Age
Count-Hit
X-Cached-By
X-TT-LOGID
X-Cluster-Node
Backend
OT-Force-Account-Verify
AMP-Access-Control-Allow-Source-Origin
X-Detected-As
X-Soup
X-Cache-Enabled
X-Akamai-Transformed
X-HP-Trace-Id
X-Datadome
X-Azure-Ref-OriginShield
X-CS
X-Edge-Location
X-Cache-Host
X-Varnish-Cache-Hits
X-APP-VERSION
X-Servername
X-Mode
Web-Mar-Node
Cross-Origin-Opener-Policy
X-Bc-Bl
X-Generation-Time
X-Info
X-Microcachable
X-Varnish-Hits
X-Dc
X-Varnish-Beresp-Status
X-Amzn-Remapped-Content-Length
X-Amzn-RequestId
X-Amz-Apigw-Id
X-TEC-API-VERSION
X-Cache-NGX
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Debug-Cache
X-Storage
X-Routing-Service
X-Zipkin-Id
X-Varnish-Beresp-Ttl
X-Proxied
SID
X-Unique-ID
X-B3-Traceid
X-SRV
X-Extlb
X-Platform
X-Ua
X-Origin-CC
X-Magnolia-Registration
X-Origin-TTL
S-Rt
Who
Req-Svc-Chain
Rendered-Blocks
X-SRCache-Key
X-Cache-Ttl
State
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
X-VG-WebCache
Mobile-Detection-Method
X-VG-WebServer
Odigeo-Trace-Id
Path
Surrogated-Key
T-Server
X-Aicache-OS
X-Aed
X-Air-Trace-Id
X-Air-Source
X-Air-Hostname
X-A-Wwc
X-A-Dgt
X-A
Cross-Origin-Window-Policy
X-A-Ccd
X-A-Dam
X-A-Dcw
Meta-Geo-Continent
Url
CDN-RequestId
CDN-Uid
CDN-RequestCountryCode
CDN-PullZone
CDN-EdgeStorageId
Host-ID
Content-Disposition
Fastcgi-X-Cache-Version
Expiry
Fastly-Backend-Name
DCR-Processing-Time-Ms
DCR-Decision-By
CDN-CachedAt
CDN-Cache
MD5-Digest
Apple-News-Services-Handled
A
X-Vdms-Path
X-Vdms-Version
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
CDCHOST
M-TraceId
BehaviorPad-Version
Apple-News-Services-Request-Url
X-Service
X-Session-Fingerprint
Upgrade-Insecure-Requests
X-Geo-Header
X-Via-JSL
X-S-Cookie
X-Application
X-External-Request-Id
X-Destination
X-Developer
X-ScT
X-Epic-Correlation-Id
X-S
X-Rojux
X-PAYTM-SRV-ID
X-PBS-Appsvrname
X-Ratelimit-Reset
X-Processor
X-Request-URI
X-NAPM-TraceId
X-Locale
X-NWS-UUID-VERIFY
X-Location
X-Rewrite-Enabled
X-D
X-From
X-Cache-Bucket
X-CF-Lambda-Fn
X-Cache-NE
X-Cms-Context
X-CF-Lambda-Version
X-BCube-Filmed-By
X-Core-Value
X-B-Cookie
X-Connection-Hash
X-ARC
Server-Info
X-Cache-Grace
DataCenter
Location
X-Rocket-Build-Number
X-Thinkindot-L3
X-Cache-Debug
L
Kp-EeAlive
X-Var-Ttl
X-Backend-State
Fastly-Drupal-HTML
X-Proxy-Upstream
X-TrackingId
X-Origin
X-Branch-Name
X-Level-Front-Cache
X-Bip
Gh-Request-Id
X-Request-UUID
X-Scheme
Pagetype
Thinkindot-CacheControl
Origin
X-SVT-ORM-RULES
Thinkindot-CacheControl-Type
PFcat
Pics-Label
X-Developers
X-Device-Os
TDXMobile
X-Envoy-Decorator-Operation
NGX
Thinkindot-Control
X-Sigma-Backend
X-HN
Server-Host
X-Sigma
Fastcgi-Cache-TTL
X-Hash
X-SVT-ORM-VERSION
X-Gamma-Serve
X-Generated-On
UCS
X-GoCache-CacheStatus
X-Thanos
Memcached
Content-Secure-Policy
X-Platform-Server
X-Varnish-Ttl
X-Orig-Expires
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Shop-Environment
Ec-Rule-Version
X-VHOST
X-NU-AKA-ACS-Version
X-JWT-State
X-Forwarded-Path
Fastly-SWR
X-Clientip
Fastly-SIE
Source
X-Is-Gdpr
Esi-Enabled
X-Has-Esi
X-VG-TLSProxy
X-DataDome
X-Tenant
Cmsid
Cache-Host
CacheControlHeader
Cmstype
X-VarnishDD-TTL
DSUID
C-Via
AKAMAI
User-Cache-Control
X-Tb
X-Forwarded-Host
PB-RID
X-Li-Fabric
X-Generated-In
X-Variation
X-Cache-Info
X-Amz-Meta-S3cmd-Attrs
X-Cache-Tags
X-DPWN-IS-SECURE
X-AIR-PT
X-Accel-Expires-Debug
X-GeoIP-City
X-VC-Cache
Platform
X-GeoIP
X-Clara-WADP
X-Forwarded-Site
X-Li-Pop
X-Srv
X-Fmm-Version
X-Eu-Site
X-Fastly-Cache
X-Fetched-On
X-Fastly-Backend
X-Served-From
PB-PID
X-Cluster
X-CGP
X-Loc
X-Origin-Expires
X-Csrf-Jwt
X-Date
X-Generated-By
X-LI-UUID
Wxu-Next-Region
Server-Ext
X-Sucuri-ID
Release
X-VServer
Server-Hostname
Sever-Int
Arc-Version
Adler-Geo
X-Skip-Cache
X-Policy
NM-Fastcgi-Cache
HA-Ipaddr
Ha-Gx-Prefs
X-User
L5d-Success-Class
X-Req
X-Nginx-Cache-Key
X-Request-Host
Arc-Country
Svr
X-WADP-Cache
Wxu-Next-Commit
Is-Eu
X-Men
Vix-Hermes-Req-Id
True-Client-Country-4JS
Wxu-Next-Hostname
X-Site-Version
Cf-Device-Type
Nel
X-Ratelimit-Limit
Mail-Subject
X-Hnp-Log
X-Gzip
X-RateLimit-Remaining-Second
X-Micro-Cache
X-Varnish-CookieINHashed-On
X-FC-Vary-Parameters
IsBot
X-Gen-Mode
X-Old-Content-Length
X-Owner
Locid
X-Irp-Debug
We-Hiring
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Varnish-Remaining-TTL
X-Varnish-Url
X-Esi-Check
X-Ftr-Request-Id
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-Slack-Backend
NtCoent-Length
X-Cache-Id
Cache-Key
X-Block-Status
V-Age
X-Varnish-CookieHashed-On
X-Mvc-Supplant-Cachable
X-Minions-Version
X-RateLimit-Limit-Second
X-Via-NSCOPI
X-Viewer-Country
X-EC-Lua
X-DefHash
X-DefElseHash
X-SIPLIST1
Webserver
X-GEO
VNS-Cache
X-Conf
X-Planisys-CDN-TTL
VNS-Age
X-HS-Content-Campaign-Id
X-Qloud-Router
X-Planisys-CDN-Rules
Cache-Hits
X-Unique-Id
X-Planisys-CDN-Cache
CPC-Cache
CPC-Age
X-PF-Uncompressing
X-Zone
My-App
MIME-Version
X-Via-Poph
Powered-By-ChinaCache
X-Mvc-Supplant-OutputCached
X-BBC-Edge-Cache-Status
X-Via-Popv
X-Via-Popn
X-Pass-Why
X-Ratelimit-Remaining
X-Servedbyhost
X-DC
X-Vc
X-Ckpd-Fst-Backend
X-Worker
XServer
X-Internal-Host
X-NC
X-Auto-Login
X-TX-ID
X-Refresh
X-CACHE-KEY
X-ID
X-V-Cache
X-LSADC-Cache
X-LB-ID
Memory
Time
X-PJAX-URL
WebServer
X-Rocket-Nginx-Serving-Static
X-OVcl
X-Tx-Id
X-Traceid
Server-ID
X-OVcl-Cache
X-Render-Time
X-NCache
X-M-Reqid
X-Newrelic-Synthetics
X-M-Log
Cf-Bgj
X-TIME
X-Wa
X-Platform-Processor
X-Webkit-Csp
X-Platform-Router
X-Qnm-Cache
Geo-Info
X-Platform-Cluster
X-ZONE
X-Backend-TTL
X-NewRelic-App-Data
X-Cache-Remote
X-SD-PageType
X-App
Magicmarker
X-TraceId
HostName
X-Datadog-Sampling-Priority
Hostname
Environment
X-Datadog-Trace-Id
X-Datadog-Parent-Id
DB-Nickname
X-Webkit-CSP-Report-Only
X-Origin-Time
X-CLOUD-TRACE-CONTEXT
X-VCL-Version
X-Nyt-Route
X-API-Version
X-NodeID
X-Geo
X-BBC-Origin-Response-Status
X-Cache-Config
X-Gdpr
Geoip-Latitude
X-Method
X-Dispatcher-Server
GeoIp-Country-Code
Cluster
X-Via-Ucdn
Resin-Trace
X-Server-IP
X-Pod-Name
X-Tb-Optimization-Total-Bytes-Saved
X-Correlation-ID
X-Cache-Var
Candidate-Md5Url
X-Cache-Var-Map
Ssr
X-Edge-Pop
X-IP
X-LI-Proto
Tcn
Datacenter
Ohc-File-Size
LB
X-CACHE-AGE
X-Origin-Response-Time
X-MSEdge-Flight
X-MSEdge-Features
X-Akamai-Pragma-Client-IP
X-HITS
X-Dynatrace
Web-Mar-Region
X-ElasticPress-Query
X-Li-Proto
Cf-Ipcountry
X-Node-Id
X-Trv-Group
X-Varnish-Beresp-TTL
X-Nc
X-NODE
N-Cache
X-AB
X-Ua-Browser
X-Content
X-ND-Cache
X-DynaTrace-JS-Agent
X-Wix-Viewer-Type
X-Vcl-Version
GeoIP-Country-Code
X-Via-CDN
GeoIP-Latitude
X-HostName
Onion-Location
Servername
Proxy-Connection
Env
X-APP
CF-Cached-On
CDN
X-ServerName
X-Reqid
Cdn
X-Varnish-Cacheable
WWW-Authenticate
X-HS-Status
X-EIG-Tracking-Id
X-Cs
X-Dynatrace-Js-Agent
X-WA
Sid
Server-Id
WZWS-RAY
X-MG-S
X-Fastly-Backend-Reqs
X-Fpc
X-NGINX-Cache
Viewtype
Rt-Fastcgi-Cache
VivaBuild
X-Lb-Id
X-Check-Cacheable
Cteonnt-Length
X-URL
X-VC
Machine
X-Request-Start
Redirect-Candidate
X-TIM-N
X-Pjax-Url
X-Tid
X-Xrds-Location
Ohc-Cache-HIT
X-Esi
X-CSRF-TOKEN
X-Via-PopV
X-Via-PopN
X-Cache-Backend
X-Via-PopH
URI
X-FTR-Request-ID
Tracecode
X-Up
X-Fastly-Request-Id
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-SERVER-NAME
X-Cdn-Forward
Lb
Server-Ttl
FSS-Cache
Mime-Version
X-Cache-Date
CountryCode
X-Amz-Meta-Cb-Modifiedtime
Shield-Pop
X-SN
On-Server
Is-Us
X-ServedByHost
X-Webkit-Csp-Report-Only
X-Tt-Logid
X-Varnish-Authentication
X-Fastly-Cache-Hits
X-Cache-ASPX
CACHE
X-Swa-Ws
X-Contensis-Viewer-Groups
X-Sn-Servicetimems
X-LiteSpeed-Cache-Control
X-Cdn-Origin
X-Pf-Uncompressing
X-FORWARDED-FOR
Pramga
X-Air-Pt
X-DI
X-DW
X-DSS
Xet-Cookie
X-RAMCache
X-Provided-By
X-StackifyID
X-Acquia-Application-Trace
X-Acquia-Site
Content-Script-Type
X-RPS
Content-Style-Type
X-Core-Mission
X-RSL
X-RPM
X-Acquia-Purge-Tags
W
X-DB
X-Acquia-Application-UUID
X-Yottaa-OS
X-Dw-Trace-Id
X-Country-Code-Real
X-FTR-Backend
X-FTR-Backend-Server
X-FTR-Cache-Status
X-Action
X-Oss-Storage-Class
X-Oss-Server-Time
Warning
X-ElasticPress-Search
Xc-Version
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
X-Oss-Object-Type
X-FTR-DC
X-FTR-Balancer
X-FTR-Realm
X-Webstats-RespID
WP-Super-Cache
X-Pad
Ohc-Response-Time
X-SB
X-Swift-Error
Vha6-Origin
X-UnsetCookies
X-Edge-POP
X-Cdn-Request-ID
X-Cache-Expires
Req-ID
ServerName
CloudFront-Viewer-Country
X-Snapshot-Date
X-C
X-FTR-Expires
X-TH-Server
X-MiniProfiler-Ids