Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-RAY
CF-Cache-Status
Accept-Ranges
Link
Pragma
X-XSS-Protection
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
Alt-Svc
X-UA-Compatible
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Xss-Protection
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
X-Request-ID
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
P3p
X-Content-Security-Policy
X-FRAME-OPTIONS
X-Iinfo
Status
Content-Encoding
Feature-Policy
X-AspNetMvc-Version
X-CDN
Upgrade
Access-Control-Expose-Headers
X-Envoy-Upstream-Service-Time
X-Ua-Compatible
X-Drupal-Dynamic-Cache
Access-Control-Max-Age
X-Via
Keep-Alive
X-Robots-Tag
Server-Timing
Request-Context
X-Dns-Prefetch-Control
X-Ws-Request-Id
X-Server
X-AH-Environment
X-Age
X-Hacker
X-Turbo-Charged-By
X-Proxy-Cache
X-Server-Powered-By
X-Cache-Group
X-Backend
Host-Header
EagleId
X-Nginx-Cache-Status
X-Amz-Request-Id
X-Amz-Id-2
Report-To
X-Rq
X-Varnish-Cache
Grace
X-Page-Speed
X-LiteSpeed-Cache
X-UA-Device
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Device
X-Pingback
EagleEye-TraceId
X-Styx-Req-Id
X-Vhost
X-Pantheon-Styx-Hostname
Cf-Railgun
X-Server-Id
X-Amz-Version-Id
X-OneAgent-JS-Injection
X-Host
X-Dispatcher
NEL
X-CST
X-Node
Allow
Surrogate-Control
X-Cache-Spec
X-WebKit-CSP
Request-Id
X-Backend-Server
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Response-Time
X-Akam-SW-Version
X-Readtime
Xkey
X-HW
Accept-Ch-Lifetime
X-Country
Accept-CH
Content-Location
X-Ac
X-Application-Context
X-Language
X-Ruxit-JS-Agent
Rating
X-Template
MS-Author-Via
X-Webkit-CSP
X-Url
X-Cache-Lookup
X-Mod-Pagespeed
X-Cloud-Trace-Context
Accept-Ch
X-B3-TraceId
Edge-Control
X-Vname
X-PC
X-TtlSet
X-Clacks-Overhead
X-ESI
X-MS-InvokeApp
X-Trace
X-Varnish-TTL
X-GitHub-Request-Id
X-Content-Type
Fastly-Restarts
X-Cnection
X-Origin-Cache
X-Rack-Cache
X-ASPNET-VERSION
X-D2id
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Kinja-Build
X-GoogleNews-Bot
X-Exp-Id
X-Exp-Variant
Arr-Disable-Session-Affinity
X-Kinja
X-Cdn-Fetch
X-Country-Code
Verso
X-Goog-Hash
X-VARITI-CCR
X-Cached
Accept-CH-Lifetime
X-Server-Name
X-Vcap-Request-Id
X-Powered-By-Plesk
X-Navigation-Version
Cache-Tag
X-Client-IP
X-Amz-Rid
X-Abt-Application-Version
X-FastCGI-Cache
Service-Worker-Allowed
X-Fastly-Request-ID
X-Buckets
X-Middleton-Response
X-Middleton-Display
X-Sol
Display
Pagespeed
Response
X-ORACLE-DMS-ECID
RTSS
Access-Control-Request-Method
X-Ttl
X-Element-Page-Cache
X-Cache-TTL
X-MSEdge-Ref
X-Powered-CMS
X-NF-Request-ID
Public-Key-Pins
X-Dw-Request-Base-Id
X-Upstream
X-Version
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Edge
S
X-Kinsta-Cache
X-LLID
X-Litespeed-Cache
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
SPIisLatency
SPRequestDuration
X-TTL
X-Ruxit-Js-Agent
Realpath
X-Accel-Expires
X-SharePointHealthScore
SPRequestGuid
X-Jurisdiction
X-T
X-Px
X-Oneagent-Js-Injection
X-HP-Webp
X-Correlation-Id
X-Release
X-Mid
X-MCACHE
X-Forwarded-Proto
X-PressLabs-Stats
X-Mg-S
X-ECACHE
Charset
X-Content-Security-Policy-Report-Only
X-Edge-Location-Klb
X-Recruiting
X-Shield-Request-Id
X-Ezoic-Cdn
TP-L2-Cache
TP-Cache
Edge-Cache-Tag
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
Fastcgi-Cache
X-DynaTrace
X-ORACLE-DMS-RID
X-Amz-Server-Side-Encryption
X-Id
X-Content-Digest
X-Request-Processing-Time
Filters
X-Request-Received
Cache-Tags
Content-MD5
Server-Node
X-Logged-In
Alternate-Protocol
X-Kraken-Routeconfig-Destination
X-Kraken-Loop-Name
X-Instrumentation
X-Server-Lifecycle-Phase
X-Forwarded-For
Front-End-Https
Nginx-Cache
Server-Name
X-WebKit-CSP-Report-Only
X-Origin-Upstream-Status
X-XRDS-LOCATION
X-Amzn-Trace-Id
Fusion-Source
Fusion-Deployment-Id
Fusion-Content-Id
AR-ATIME
AR-CACHE
Ar-Sid
Fusion-Template-Id
Fusion-Component-Id
X-Cache-Key
AR-Request-ID
Fusion-Content-Source
AR-PoweredBy
X-Origin-Server
X-Grace
X-Fastcgi-Cache
X-Amz-Replication-Status
X-Contextid
X-Geo-Country
X-Rid
TCN
X-F-Cache
X-Az
X-Activity-Id
X-AppVersion
Host
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Content-Id
X-Goog-Metageneration
X-GUploader-UploadID
X-HS-Combine-CSS
Cleartype
X-Frontend
X-Server-ID
X-Www-Served-By
X-Protected-By
X-Hostname
Section-Io-Cache
X-LB-Cache
X-Debug-Info
X-RateLimit-Remaining
X-Ser
MicrosoftSharePointTeamServices
X-XRDS-Location
X-Tec-Api-Version
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Tec-Api-Origin
X-Browser-Type
X-Tec-Api-Root
X-Request-Handler-Origin-Region
X-Microsite
X-Cache-Age
X-Page-Id
X-Git-Hash
X-Varnish-Age
Accept-Charset
X-Respond-Thread
X-Aspnetmvc-Version
X-Hits
X-Source
X-Upgrade-Enabled
ServerID
X-DIS-Request-ID
Paypal-Debug-Id
X-VCache
X-NWS-LOG-UUID
X-Mobile-URL
X-Content-Options
X-Varnish-Backend
X-N
X-B-Cache
X-Signature
X-Varnish-Grace
X-B3-Sampled
X-Aspnet-Duration-Ms
X-Flags
X-Route-Name
X-Is-Crawler
X-Request-Guid
X-Providence-Cookie
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Whom
Healthy
X-FB-Debug
Access-Control-Allow-Method
Payment
Nel
X-TT
X-Cache-Action
X-App-Environment
X-Seen-By
Node
Viewport
X-CACHE-GROUP
X-AOL-HN
X-Daa-Tunnel
X-Type
X-Load-Cache
Fastcgi-Useragent
Version
MS-CV
X-Mobile
DC
X-Cache-Expired-At
Filterid
X-IPLB-Instance
X-HTML-Minification-Powered-By
X-Distributor
X-Webkit-Csp
DynaTrace
X-Yandex-Sdch-Disable
X-Cache-Control
X-FireWall-Port
X-Ua-Device
SRV
Retry-After
X-Debug
X-Original-Request-Id
X-Response-Served-From
X-Real-IP
X-Jobs
Refresh
X-Instance
X-Tumblr-Pixel-1
X-UUID
X-Tt-Trace-Tag
X-Proxy-Cache-Status
NGB
X-Tt-Trace-Host
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Accel-Buffering
X-RemovedCookies
X-Tumblr-User
X-Varnish-Server
X-ProcessESI
X-IPS-LoggedIn
X-Proxy
X-Region
X-Ab
X-Page-View
X-Device-Type
X-RTag
Ms-Operation-Id
X-Content-Powered-By
Cache
VIX-Pulpo-Upstream-Status
Access-Control-Request-Headers
X-Cacheable-TTL
X-Cluster-Name
X-Cache-Time
X-Debug-IsConnected
VIX-Pulpo-Node
X-B
X-Framework
Uber-Trace-Id
X-Debug-IsPreview
Frame-Options
X-G
X-Adobe-Content
X-Wix-Request-Id
X-Adobe-Loc
X-User-Agent
X-FW-Static
X-FW-Type
X-Zen-Fury
X-FW-Dynamic
X-FW-Serve
X-FW-Hash
X-FW-Server
Countrycode
X-Cache-Hit
Section-Io-Origin-Status
Section-Origin-Responded
Section-Io-Id
Section-Io-Origin-Time-Seconds
Surrogate-Key
Cache-Status
X-Nginx-Cache
X-Time
X-Vgn-Hpd-Reason
X-App-Version
X-Drupal-Cache-Tags
Eomportal-Instance
X-NGENIX-Cache
Country
X-Azure-Ref
X-Is-Bot
X-Rendered-As
X-App-Server
X-EdgeConnect-Cache-Status
X-TA-CDN-Provider
X-RateLimit-Limit
X-Drupal-Cache-Contexts
CF-IPCountry
X-Rule
S-Cnection
X-Mg-Request-UUID
AMP-Access-Control-Allow-Source-Origin
X-Cache-Rule
X-Ms-Request-Id
Liferay-Portal
X-Ms-Version
Referer-Policy
X-Oracle-Dms-Rid
X-SaId
X-ES-SERVER
X-Varnishpool
X-Yottaa-Optimizations
X-JoinUs
Meta-Geo
X-RN-RSRV
Selected-Fe
X-Timing-Wait
From-Origin
X-Yottaa-Metrics
X-Proxy-Build
X-UPSTREAM-Address
X-Tumblr-Pixel-2
X-Cached-By
SD-X-WS
Protected
ServedBy
X-Backend-Host
X-CDN-Forward
X-Alternate-Cache-Key
X-PHP-Backend
X-Sorting-Hat-ShopId
X-Storefront-Renderer-Rendered
X-Xfnlog-Site
X-Via-Fastly
X-ShardId
X-Sorting-Hat-PodId
X-Shopify-Stage
X-ShopId
X-TNCMS
Country-Code
X-Loop
X-Handled-By
X-Endurance-Cache-Level
X-Cache-Server
X-R9-Blue-Green-Version
X-No-Session
X-Pubstack
X-Cache-TTL-Remaining
Azure-InstanceId
Azure-RegionName
Property-Id
Azure-SlotName
Cache-Name
Cache-Tv-Group
Decoy-Debug-Key
Azure-Version
Decoy-Debug-Status
Decoy-Debug-TTL
Azure-SiteName
Fastly-SSL
X-PCL
X-Request-Time
X-S-Maxage
X-Proto
X-Origin-Hint
X-OCL
X-Say-Cacheable
X-Say-TTL
X-VWS-Id
X-Varnish-Hostname
Akamai-GRN
X-Server-W
X-SayCDN-TTL
X-NYM-Debug-Backend
X-LJ-Flow-ID
TWC-Locale-Group
TWC-Privacy
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Device-Class
Webcakes-App-Name
Webcakes-App-Version
X-Human
X-LAGOON
X-Cache-PHP
X-Be
Webcakes-Region
TWC-Connection-Speed
X-AWS-Id
X-Environment-Context
X-Cache-Operation
X-L-Path
X-Node-Name
X-ProxyCache-Key
X-Access
X-PHP-Host
X-Dc
X-Labrador-Cache-Channel
X-Hl-Ver
X-Hyper-Cache
X-ProxyCache-Status
X-Origin-Date
X-RCS-CacheZone
X-BYPASS-REASON
X-Backend-Name
Apigw-Requestid
X-Format
X-Status
X-Redis-Cache
X-Sql-Duration-Ms
X-Section
X-Sql-Count
X-FB-TRIP-ID
X-ApacheServer
X-PERF
X-UA-Device-Type
X-Uri
X-GG-Cache-Date
Mn-Server-Ip
Xserver
X-Hosted-By
X-Akamai-Edgescape
X-Adobe-Source
X-Varnish-Beresp-Grace
X-Web-Node
X-MP-GENERATED-AT
X-Trace-Id
X-WA-Info
X-Content-Age
X-ATG-Version
X-B3-SpanId
Amp-Access-Control-Allow-Source-Origin
X-FW-Version
X-Cache-Enabled
X-Revision
X-Soup
X-CACHE-KEY
X-Edge-Location
X-Mode
X-Info
X-Time-Microsecs
X-ServerID
X-CSRF-Token
Backend
X-SRV
Who
X-Tumblr-Pixel-3
X-Cache-Type
X-Bc-Bl
X-Cache-NGX
X-Akamai-Transformed
X-Microcachable
X-CS
X-Varnish-Beresp-Status
X-Debug-Cache
X-Platform
X-Detected-As
X-Proxied
X-Routing-Service
X-Storage
X-Zipkin-Id
X-APP-VERSION
X-CLOUD-TRACE-CONTEXT
X-Azure-Ref-OriginShield
DataCenter
Web-Mar-Node
X-TT-LOGID
X-Cache-Host
X-DataDome
X-Via-JSL
X-Aws-Lambda-Call-Status
X-Generation-Time
X-Varnish-Cache-Hits
X-Datadome
X-Amz-Apigw-Id
X-Amzn-Remapped-Content-Length
X-Amzn-RequestId
X-Unique-ID
Server-Info
X-Extlb
X-Locale
X-Varnish-Hits
X-Ratelimit-Limit
Geo-Info
X-Site-Version
Cross-Origin-Opener-Policy
OT-Force-Account-Verify
X-Pass-Why
X-Origin-TTL
X-B3-Traceid
X-Origin-CC
X-Cluster-Node
X-AIR-PT
X-S-Cookie
X-PAYTM-SRV-ID
X-Vtex-Remote-Cache
X-Cache-NE
X-External-Request-Id
X-PBS-Appsvrname
X-CF-Lambda-Fn
Expiry
X-Processor
Fastcgi-X-Cache-Version
Fastly-Backend-Name
X-Proxy-Upstream
X-S
X-Cache-Bucket
X-Air-Hostname
X-Thanos
X-Bip
X-BCube-Filmed-By
X-Air-Source
X-Air-Trace-Id
Host-ID
User-Cache-Control
X-Vtex-Processado-Em
X-Magnolia-Registration
X-EC-Lua
X-Destination
CDN-Cache
CDN-CachedAt
CDCHOST
X-Connection-Hash
X-Core-Value
CDN-EdgeStorageId
CDN-PullZone
X-Cms-Context
CDN-Uid
CDN-RequestId
CDN-RequestCountryCode
BehaviorPad-Version
Content-Disposition
A
DCR-Decision-By
DCR-Processing-Time-Ms
X-Rewrite-Enabled
M-TraceId
X-CF-Lambda-Version
Apple-News-Services-Handled
X-D
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-Developer
X-From
X-Service
Rendered-Blocks
X-Session-Fingerprint
X-A-Dam
X-A-Dcw
X-A-Dgt
X-Varnish-Url
X-ScT
Odigeo-Trace-Id
X-A-Wwc
X-Request-URI
X-A-Ccd
T-Server
X-Vdms-Path
X-Vdms-Version
X-NAPM-TraceId
Surrogated-Key
X-Location
X-A
X-VG-WebServer
X-VG-WebCache
X-Level-Front-Cache
X-Geo-Header
X-Rojux
MD5-Digest
Ec-Rule-Version
Meta-Geo-Continent
X-Application
X-SRCache-Key
X-Sucuri-ID
X-B-Cookie
X-ARC
Mobile-Detection-Method
X-Ratelimit-Reset
X-Generated-On
X-Aed
Count-Hit
X-Varnish-Beresp-Ttl
X-Tb
X-Parallel-Accel
Tcn
X-Cluster
GEO-INFO
Location
Cmstype
UCS
Cmsid
Fastly-SWR
Server-Host
X-Clientip
X-Clara-WADP
X-Branch-Name
X-Cache-Debug
PFcat
Pics-Label
X-Accel-Expires-Debug
X-WADP-Cache
Path
Esi-Enabled
X-Backend-State
X-Aicache-OS
Memcached
Pagetype
X-Cache-Info
Req-Svc-Chain
X-VarnishDD-TTL
Gh-Request-Id
Fastly-SIE
X-Date
X-Generated-By
X-GoCache-CacheStatus
X-Served-From
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Gamma-Serve
X-Forwarded-Site
X-Amz-Meta-S3cmd-Attrs
X-Scheme
CacheControlHeader
X-Has-Esi
X-Req
X-JWT-State
X-Origin
X-Men
X-Micro-Cache
X-Is-Gdpr
X-Request-Host
X-Hash
X-Request-UUID
X-HN
X-Fmm-Version
X-VG-TLSProxy
X-Fastly-Cache
X-TrackingId
X-NU-AKA-ACS-Version
AKAMAI
X-Envoy-Decorator-Operation
X-Developers
X-Epic-Correlation-Id
X-Platform-Server
Cache-Host
X-Var-Ttl
X-Cache-Grace
X-TX-ID
X-Servername
X-NWS-UUID-VERIFY
Upgrade-Insecure-Requests
X-Irp-Debug
X-Hnp-Log
X-HS-Content-Campaign-Id
X-Sigma
X-Rocket-Build-Number
Wxu-Next-Region
Vix-Hermes-Req-Id
X-Csrf-Jwt
X-Mvc-Supplant-Cachable
True-Client-Country-4JS
X-Sigma-Backend
We-Hiring
X-CGP
Wxu-Next-Commit
X-Origin-Expires
Wxu-Next-Hostname
X-Gzip
X-Block-Status
X-Eu-Site
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Thinkindot-L3
X-Owner
X-Fastly-Backend
X-Cache-Id
X-RateLimit-Limit-Second
X-Cache-Tags
X-RateLimit-Remaining-Second
X-DPWN-IS-SECURE
X-VC-Cache
X-Device-Os
X-Generated-In
X-Gen-Mode
X-Variation
X-Slack-Backend
X-Esi-Check
X-Policy
DSUID
Kp-EeAlive
Is-Eu
HA-Ipaddr
Ha-Gx-Prefs
L
L5d-Success-Class
NM-Fastcgi-Cache
NGX
Mail-Subject
X-Viewer-Country
X-Wikidot-Backend
Cf-Device-Type
My-App
State
Thinkindot-Control
X-Varnish-Ttl
X-Wikidot-Static-Cache
Adler-Geo
Cache-Key
C-Via
Arc-Version
Arc-Country
Webserver
Fastly-Drupal-HTML
PB-RID
Platform
TDXMobile
PB-PID
Thinkindot-CacheControl-Type
Origin
Svr
Thinkindot-CacheControl
Source
X-Forwarded-Host
Fastcgi-Cache-TTL
X-Nginx-Cache-Key
X-DefElseHash
VNS-Cache
V-Age
X-DefHash
X-Old-Content-Length
X-Loc
X-Li-Fabric
X-Skip-Cache
X-GeoIP-City
X-GeoIP
X-Li-Pop
X-LI-UUID
X-Fetched-On
X-User
X-Minions-Version
X-SIPLIST1
X-FC-Vary-Parameters
VNS-Age
Server-Ext
X-PF-Uncompressing
X-Varnish-CookieINHashed-On
X-VServer
X-Varnish-CookieHashed-On
X-Qloud-Router
Release
X-Planisys-CDN-Cache
CPC-Cache
Locid
X-Planisys-CDN-Rules
IsBot
X-Varnish-Remaining-TTL
X-Planisys-CDN-TTL
Sever-Int
X-Via-NSCOPI
CPC-Age
Server-Hostname
X-TraceId
X-Ratelimit-Remaining
Url
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Mvc-Supplant-OutputCached
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-OVcl
X-OVcl-Cache
X-Unique-Id
Cache-Hits
X-PJAX-URL
X-Vc
NtCoent-Length
XServer
SID
X-Zone
X-Tenant
X-Refresh
X-Forwarded-Path
DB-Nickname
X-Ua
X-Orig-Expires
S-Rt
Cf-Bgj
X-Via-Popv
X-Via-Poph
X-Via-Popn
X-Shop-Environment
Powered-By-ChinaCache
X-Backend-TTL
Cross-Origin-Window-Policy
Magicmarker
X-Cache-Ttl
MIME-Version
X-Geo
X-Internal-Host
X-Ftr-Request-Id
Geoip-Latitude
X-NC
GeoIp-Country-Code
X-TIME
X-ID
X-Dispatcher-Server
X-NCache
Memory
Content-Secure-Policy
X-Srv
X-Conf
Time
X-GEO
X-Method
X-LB-ID
WebServer
X-BBC-Edge-Cache-Status
HostName
X-ZONE
X-Servedbyhost
X-Worker
X-IP
X-HP-Trace-Id
X-Ckpd-Fst-Backend
Ssr
Hostname
Server-ID
X-Auto-Login
X-Newrelic-Synthetics
X-Nc
X-Li-Proto
X-V-Cache
X-LSADC-Cache
LB
X-Rocket-Nginx-Serving-Static
X-Trv-Group
X-NewRelic-App-Data
X-Render-Time
X-M-Log
X-M-Reqid
X-Qnm-Cache
X-Tx-Id
X-Wa
X-Node-Id
X-Vcl-Version
X-HostName
X-Platform-Processor
X-Platform-Cluster
X-Platform-Router
X-Tb-Optimization-Total-Bytes-Saved
Resin-Trace
X-DC
Sid
X-App
X-Cache-Remote
X-SD-PageType
X-APP
X-FTR-Request-ID
X-Origin-Response-Time
Env
Ohc-File-Size
X-Traceid
X-CACHE-AGE
X-VCL-Version
X-Via-CDN
X-HITS
X-Dynatrace
X-Reqid
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
Environment
X-MSEdge-Flight
X-MSEdge-Features
X-Datadog-Parent-Id
X-Varnish-Beresp-TTL
X-VHOST
X-Nyt-Route
X-Gdpr
X-Cache-Config
X-Via-Ucdn
X-API-Version
X-BBC-Origin-Response-Status
X-Origin-Time
X-NodeID
X-WA
X-ServerName
X-DynaTrace-JS-Agent
Viewtype
VivaBuild
Rt-Fastcgi-Cache
CF-Cached-On
X-Cdn-Forward
Cluster
X-Server-IP
X-Edge-Pop
X-Pod-Name
X-Correlation-ID
Datacenter
Machine
X-ND-Cache
Cf-Ipcountry
X-Wix-Viewer-Type
X-ElasticPress-Query
X-HS-Status
Candidate-Md5Url
X-Cs
X-LI-Proto
Server-Id
Web-Mar-Region
X-ServedByHost
X-Cache-Var
CDN
X-Dynatrace-Js-Agent
FSS-Cache
X-Cache-Var-Map
X-Akamai-Pragma-Client-IP
N-Cache
On-Server
X-CCM
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
X-FTR-Realm
X-Oss-Object-Type
X-FTR-DC
Proxy-Connection
X-Oss-Server-Time
X-Oss-Request-Id
X-FTR-Balancer
X-Lb-Id
X-FTR-Cache-Status
X-NGINX-Cache
Xc-Version
X-Country-Code-Real
X-Swa-Ws
X-CSRF-TOKEN
X-FTR-Backend-Server
X-FTR-Backend
X-Via-PopH
X-Check-Cacheable
Servername
GeoIP-Latitude
WZWS-RAY
GeoIP-Country-Code
X-Via-PopV
X-Via-PopN
X-URL
Tracecode
X-Xrds-Location
X-Esi
Ohc-Cache-HIT
X-IN-APIGATEWAY
WWW-Authenticate
X-VC
X-IN-APIGATEWAYSSL
Mime-Version
X-Fastly-Request-Id
X-Fastly-Backend-Reqs
X-Pjax-Url
X-EIG-Tracking-Id
Cdn
X-CUA
X-Varnish-Cacheable
Onion-Location
X-Cache-Backend
X-Swift-Error
X-ECache
X-Region-Sid
CountryCode
Instruction
X-SN
Cteonnt-Length
URI
SR-User-Adfree
X-FTR-Expires
X-Webkit-CSP-Report-Only
X-UnsetCookies
X-LiteSpeed-Cache-Control
X-Varnish-Authentication
X-Air-Pt
Server-Ttl
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Tt-Logid
X-FORWARDED-FOR
X-Depends-On
X-Provided-By
CACHE
X-Fpc
X-RSL
X-RPS
Redirect-Candidate
X-Tid
X-TIM-N
X-Matched-Rule
X-StackifyID
X-Request-Start
X-DW
X-DB
X-Action
Shield-Pop
X-Fastly-Cache-Hits
X-DI
X-RPM
Ohc-Response-Time
X-DSS
X-Pad
WP-Super-Cache
CloudFront-Viewer-Country
Lfy
X-Webstats-RespID
X-Dw-Trace-Id
X-Core-Mission
X-Pf-Uncompressing
X-Snapshot-Date
X-Yottaa-OS
W
X-SB
X-Acquia-Site
X-Cache-Expires
X-ElasticPress-Search
Warning
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-C
X-FPC
Xet-Cookie
X-Cache-Status-Check
X-CCDN-Origin-Time
X-Mg-Request-Id
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
Content-Style-Type
X-RAMCache
ServerName
X-Cdn-Origin
X-Sn-Servicetimems
X-Cdn-Request-ID
Vha6-Origin
X-MiniProfiler-Ids
X-Apw-Access-Token
X-TH-Server
X-Apw-Access-Object
X-Apw-Access-Action
Content-Script-Type
X-Apw-Hits