Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
Link
X-XSS-Protection
ETag
Pragma
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
P3P
X-UA-Compatible
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Xss-Protection
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
P3p
X-Cacheable
X-Request-ID
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Content-Security-Policy
X-Iinfo
Status
X-Ua-Compatible
Feature-Policy
Content-Encoding
X-AspNetMvc-Version
X-CDN
X-Envoy-Upstream-Service-Time
X-Dns-Prefetch-Control
Access-Control-Expose-Headers
Upgrade
Access-Control-Max-Age
X-Drupal-Dynamic-Cache
X-Via
X-Ws-Request-Id
Keep-Alive
Server-Timing
Request-Context
X-Robots-Tag
X-AH-Environment
X-Hacker
X-Server
X-Age
X-Turbo-Charged-By
X-Proxy-Cache
X-Cache-Group
X-Server-Powered-By
X-Amz-Request-Id
X-Backend
Host-Header
X-Amz-Id-2
EagleId
X-Nginx-Cache-Status
Report-To
X-LiteSpeed-Cache
X-Rq
X-Varnish-Cache
Grace
X-UA-Device
X-Page-Speed
X-Pingback
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
EagleEye-TraceId
X-Device
X-Vhost
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Amz-Version-Id
X-Dispatcher
X-OneAgent-JS-Injection
NEL
Cf-Railgun
X-Host
X-WebKit-CSP
X-Cache-Spec
X-Server-Id
X-CST
X-Node
X-Backend-Server
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Allow
Request-Id
Surrogate-Control
X-Readtime
Accept-CH
X-Akam-SW-Version
Accept-Ch-Lifetime
X-Response-Time
Xkey
X-Language
X-HW
X-Template
X-Application-Context
X-Country
Content-Location
X-Ac
X-Cloud-Trace-Context
X-Cache-Lookup
Rating
MS-Author-Via
X-Url
X-Ruxit-JS-Agent
X-Webkit-CSP
Edge-Control
X-Clacks-Overhead
X-PC
X-TtlSet
X-Vname
X-Varnish-TTL
X-Mod-Pagespeed
X-Trace
X-B3-TraceId
Fastly-Restarts
X-Content-Type
Accept-Ch
X-Rack-Cache
X-MS-InvokeApp
X-Buckets
X-ESI
X-Origin-Cache
X-GitHub-Request-Id
X-Country-Code
X-Cnection
X-Goog-Hash
Verso
X-D2id
X-VARITI-CCR
X-ORACLE-DMS-ECID
X-FastCGI-Cache
Arr-Disable-Session-Affinity
X-Use-Magma
X-Kinja
X-Kinja-Build
X-Kinja-Revision
X-Kinja-Server
X-Exp-Variant
X-GoogleNews-Bot
X-Exp-Id
X-Cdn-Fetch
Cache-Tag
Service-Worker-Allowed
X-Cached
X-Vcap-Request-Id
X-Px
X-Server-Name
X-Abt-Application-Version
X-Client-IP
X-Amz-Rid
X-Navigation-Version
X-Cache-TTL
Accept-CH-Lifetime
X-Server-ID
Public-Key-Pins
RTSS
X-Powered-By-Plesk
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-MSEdge-Ref
Access-Control-Request-Method
X-Element-Page-Cache
X-TTL
X-Dw-Request-Base-Id
X-Powered-CMS
X-NF-Request-ID
X-Version
X-Upstream
X-Fastly-Request-ID
Response
Display
X-Middleton-Display
Pagespeed
X-Middleton-Response
X-Sol
S
X-Kinsta-Cache
X-Edge-Location-Klb
X-LLID
X-Edge
X-Cache-Key
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Accel-Expires
X-ECACHE
X-Server-Lifecycle-Phase
X-Kraken-Routeconfig-Destination
X-Instrumentation
X-Kraken-Loop-Name
X-Ruxit-Js-Agent
X-Jurisdiction
X-HP-Webp
Pinterest-Generated-By
X-Pinterest-Rid
X-Shield-Request-Id
Pinterest-Version
X-ORACLE-DMS-RID
Realpath
X-Ttl
X-Correlation-Id
X-T
X-DynaTrace
X-PressLabs-Stats
SPRequestGuid
X-MCACHE
X-Mid
X-SharePointHealthScore
X-Content-Security-Policy-Report-Only
Edge-Cache-Tag
SPRequestDuration
SPIisLatency
X-Litespeed-Cache
Fastcgi-Cache
X-Amz-Server-Side-Encryption
X-XRDS-Location
Nginx-Cache
X-Mg-S
X-Content-Digest
X-Forwarded-Proto
TP-L2-Cache
TP-Cache
X-Recruiting
Charset
X-Request-Received
Front-End-Https
X-Request-Processing-Time
TCN
Alternate-Protocol
Server-Node
X-Logged-In
X-Id
Filters
X-Oneagent-Js-Injection
Content-MD5
X-Forwarded-For
X-Geo-Country
X-Ezoic-Cdn
Fusion-Content-Id
Fusion-Content-Source
Fusion-Component-Id
Fusion-Source
Fusion-Deployment-Id
X-Protected-By
Fusion-Template-Id
Cache-Tags
X-Hostname
X-ASPNET-VERSION
X-Amzn-Trace-Id
X-NWS-LOG-UUID
X-Origin-Upstream-Status
X-Grace
X-Goog-Stored-Content-Encoding
X-Ab
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-GUploader-UploadID
X-Goog-Metageneration
X-Debug-Info
X-Goog-Generation
Cleartype
X-F-Cache
X-Www-Served-By
X-Amz-Replication-Status
X-Az
X-AppVersion
X-Origin-Server
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
X-Activity-Id
X-LB-Cache
X-Rid
X-HS-Combine-CSS
Host
X-Daa-Tunnel
X-Contextid
X-Page-Id
X-Git-Hash
Section-Io-Cache
X-RateLimit-Remaining
Server-Name
X-VCache
X-Content-Options
X-Browser-Type
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Ser
X-Frontend
X-Upgrade-Enabled
X-Cache-Age
MicrosoftSharePointTeamServices
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Access-Control-Allow-Method
X-Aspnetmvc-Version
ServerID
Accept-Charset
X-Release
X-Hits
X-Mobile-URL
X-Source
X-WebKit-CSP-Report-Only
X-Aspnet-Duration-Ms
X-DIS-Request-ID
X-Varnish-Age
X-Flags
X-Is-Crawler
X-Route-Name
X-Providence-Cookie
X-Request-Guid
X-Cache-Action
X-B-Cache
X-Signature
Viewport
X-B3-Sampled
X-Varnish-Backend
X-FB-Debug
Payment
X-Varnish-Grace
Paypal-Debug-Id
Healthy
X-Whom
Fastcgi-Useragent
X-Yandex-Sdch-Disable
X-AOL-HN
X-Respond-Thread
X-App-Environment
X-CACHE-GROUP
X-TT
Node
DynaTrace
X-Load-Cache
X-Mobile
X-Fastcgi-Cache
DC
X-Tt-Trace-Host
X-Tt-Trace-Tag
Filterid
X-Seen-By
Version
X-Distributor
X-N
X-Tec-Api-Root
SRV
X-Tec-Api-Version
X-Tec-Api-Origin
X-User-Agent
X-Cache-Control
X-HTML-Minification-Powered-By
Frame-Options
Retry-After
X-Type
X-XRDS-LOCATION
X-HP-Trace-Id
Refresh
MS-CV
X-Jobs
X-FW-Static
X-FW-Server
X-FW-Type
X-FW-Serve
X-FW-Hash
X-FW-Dynamic
X-Original-Request-Id
X-Response-Served-From
X-Ua-Device
X-NGENIX-Cache
X-Cache-Expired-At
X-UUID
X-Page-View
NGB
X-Node-Name
X-Real-IP
X-Azure-Ref
X-Instance
X-Proxy-Cache-Status
X-Adobe-Loc
X-Adobe-Content
X-Varnish-Server
X-B
VIX-Pulpo-Upstream-Status
X-IPLB-Instance
X-Vgn-Hpd-Reason
X-Debug-IsPreview
X-Debug-IsConnected
VIX-Pulpo-Node
X-CDN-Forward
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-ProcessESI
X-Tumblr-Pixel-1
X-RemovedCookies
X-Region
X-Device-Type
X-Content-Powered-By
Ms-Operation-Id
Access-Control-Request-Headers
X-RTag
X-Cacheable-TTL
X-Cluster-Name
X-Tumblr-User
X-G
X-Cache-Time
X-Framework
Amp-Access-Control-Allow-Source-Origin
X-Proxy
X-Aws-Lambda-Call-Status
X-Cache-Hit
X-Zen-Fury
Nel
X-IPS-LoggedIn
Referer-Policy
X-Cache-Rule
SD-X-WS
Liferay-Portal
X-Parallel-Accel
Uber-Trace-Id
X-Rendered-As
X-Is-Bot
Cache-Status
X-Drupal-Cache-Tags
X-Ms-Request-Id
X-Ms-Version
X-Wix-Request-Id
X-EdgeConnect-Cache-Status
X-Time
Section-Io-Id
Section-Io-Origin-Time-Seconds
Countrycode
Section-Io-Origin-Status
Section-Origin-Responded
X-RateLimit-Limit
X-Oracle-Dms-Rid
X-App-Server
X-L-Path
X-Revision
X-Mg-Request-UUID
X-Environment-Context
X-Debug
S-Cnection
X-Yottaa-Optimizations
Country
X-Yottaa-Metrics
X-Accel-Buffering
CF-IPCountry
X-B3-Traceid
X-Cache-Operation
Count-Hit
X-TA-CDN-Provider
X-APP-VERSION
X-Nginx-Cache
X-Request-Handler-Origin-Region
X-Microsite
X-Drupal-Cache-Contexts
X-FW-Version
Akamai-GRN
Cache
AR-PoweredBy
Ar-Sid
Meta-Geo
X-ES-SERVER
X-Endurance-Cache-Level
X-GG-Cache-Date
X-JoinUs
AR-ATIME
AR-CACHE
AR-Request-ID
X-RN-RSRV
X-UPSTREAM-Address
X-SaId
X-Say-Cacheable
X-Say-TTL
X-LAGOON
X-TNCMS
X-Cache-Type
X-Loop
X-Cache-TTL-Remaining
X-SayCDN-TTL
X-Sql-Duration-Ms
Azure-Version
Surrogate-Key
Fastly-SSL
Azure-InstanceId
X-Human
From-Origin
X-NYM-Debug-Backend
X-Sql-Count
Azure-SiteName
X-Request-Time
Azure-SlotName
X-R9-Blue-Green-Version
Country-Code
X-Adobe-Source
X-S-Maxage
Azure-RegionName
X-OCL
X-Varnish-Beresp-Grace
X-PCL
X-AWS-Id
X-Alternate-Cache-Key
X-Storefront-Renderer-Rendered
X-Status
Protected
X-VWS-Id
Decoy-Debug-Status
X-Varnishpool
X-Varnish-Hostname
Cache-Tv-Group
X-B3-SpanId
Decoy-Debug-TTL
X-ShopId
Decoy-Debug-Key
X-No-Session
X-LJ-Flow-ID
X-Labrador-Cache-Channel
X-PHP-Host
X-Proto
X-Pubstack
X-RCS-CacheZone
X-ProxyCache-Key
X-Be
X-Hosted-By
X-Sorting-Hat-PodId
X-Handled-By
Apigw-Requestid
X-Shopify-Stage
X-ProxyCache-Status
X-Sorting-Hat-ShopId
X-ShardId
X-BYPASS-REASON
TWC-Connection-Speed
ServedBy
Property-Id
Selected-Fe
Eomportal-Instance
X-Origin-Hint
X-Redis-Cache
X-Proxy-Build
X-Origin-Date
X-Section
X-Timing-Wait
X-Via-Fastly
X-Xfnlog-Site
X-Tumblr-Pixel-2
X-Format
X-Cache-Server
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Privacy
Webcakes-App-Name
X-Access
Webcakes-Region
Webcakes-App-Version
TWC-Device-Class
X-Server-W
X-App-Version
Cache-Name
X-Cluster-Node
X-Akamai-Edgescape
X-PERF
GEO-INFO
X-Hyper-Cache
X-ApacheServer
X-PHP-Backend
X-Backend-Host
Mn-Server-Ip
X-UA-Device-Type
X-Time-Microsecs
X-Uri
X-FB-TRIP-ID
X-Backend-Name
X-Hl-Ver
X-Web-Node
X-ServerID
OT-Force-Account-Verify
Cross-Origin-Opener-Policy
X-Tumblr-Pixel-3
X-Detected-As
X-ATG-Version
X-FireWall-Port
X-Servername
X-Webkit-Csp
X-Ua
Web-Mar-Node
X-Azure-Ref-OriginShield
Cross-Origin-Window-Policy
X-Cache-Host
X-Varnish-Cache-Hits
X-Generation-Time
X-Cache-PHP
X-Datadome
X-TEC-API-ORIGIN
X-Varnish-Hits
X-Content-Age
X-TEC-API-ROOT
X-TEC-API-VERSION
Content-Secure-Policy
Ec-Rule-Version
X-TT-LOGID
X-Via-JSL
Backend
X-CS
X-SRV
Source
X-Trace-Id
X-MP-GENERATED-AT
X-Air-Trace-Id
X-Air-Hostname
X-WA-Info
X-Amzn-RequestId
X-Amz-Apigw-Id
Upgrade-Insecure-Requests
X-Air-Source
X-Content
X-Mode
X-Ua-Browser
X-CSRF-Token
X-Akamai-Transformed
X-Microcachable
X-Forwarded-Host
X-Cache-Grace
X-Soup
Xserver
X-Cache-Enabled
X-NWS-UUID-VERIFY
X-Cdn
X-Amzn-Remapped-Content-Length
X-Edge-Location
X-Locale
X-Rule
X-Varnish-Beresp-Ttl
X-Bc-Bl
Url
X-Ratelimit-Limit
X-Origin-TTL
X-Origin-CC
X-Dc
X-Info
X-Site-Version
X-Ratelimit-Remaining
Content-Disposition
X-Tenant
X-Proxied
X-Extlb
SID
X-Routing-Service
X-Varnish-Beresp-Status
X-Unique-Id
X-Zipkin-Id
S-Rt
AMP-Access-Control-Allow-Source-Origin
X-PAYTM-SRV-ID
BehaviorPad-Version
X-Session-Fingerprint
Apple-News-Services-Handled
Apple-News-Services-Host
Apple-News-Services-Request-Url
X-Orig-Expires
A
CDCHOST
X-NU-AKA-ACS-Version
X-NAPM-TraceId
Apple-News-Services-Parsed-Url
Mobile-Detection-Method
X-A-Dcw
X-A-Dam
X-A-Dgt
X-A-Wwc
X-Aed
X-A-Ccd
X-A
X-Epic-Correlation-Id
X-Developer
X-Destination
X-Debug-Cache
X-Aicache-OS
X-AIR-PT
X-Cache-NE
X-Cache-Bucket
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Conf
X-BCube-Filmed-By
X-D
X-Application
X-ARC
X-B-Cookie
X-BBC-Edge-Cache-Status
T-Server
Surrogated-Key
DCR-Processing-Time-Ms
DCR-Decision-By
Expiry
Fastcgi-X-Cache-Version
Fastly-SIE
CDN-Uid
CDN-RequestId
CDN-CachedAt
CDN-EdgeStorageId
CDN-PullZone
CDN-RequestCountryCode
Fastly-SWR
Host-ID
Req-Svc-Chain
X-From
X-Forwarded-Path
X-External-Request-Id
Rendered-Blocks
X-Ftr-Request-Id
MD5-Digest
Meta-Geo-Continent
Odigeo-Trace-Id
Path
CDN-Cache
X-PBS-Appsvrname
X-VG-WebCache
X-Vtex-Processado-Em
X-ScT
X-S
X-Rebelmouse-Cache-Control
X-Request-URI
X-Rewrite-Enabled
X-Vdms-Version
X-Rojux
X-GEO
User-Cache-Control
X-Ratelimit-Reset
X-Rebelmouse-Surrogate-Control
X-Connection-Hash
X-Processor
X-Platform-Server
X-Vtex-Remote-Cache
X-S-Cookie
X-VG-WebServer
X-Shop-Environment
X-SRCache-Key
X-Tb
X-Magnolia-Registration
X-EC-Lua
X-Li-Fabric
X-Backend-State
X-Accel-Expires-Debug
X-Cached-By
X-Cache-NGX
X-LI-UUID
X-Date
X-Li-Pop
State
X-VG-TLSProxy
L
Is-Eu
UCS
X-DPWN-IS-SECURE
X-Has-Esi
X-TrackingId
X-Envoy-Decorator-Operation
Fastly-Drupal-HTML
X-Fastly-Cache
X-JWT-State
X-Is-Gdpr
Fastly-Backend-Name
Cache-Key
X-Request-UUID
X-Cache-Info
X-Micro-Cache
X-Storage
X-M-Log
X-M-Reqid
X-Service
Platform
X-Cms-Context
X-Proxy-Upstream
Pics-Label
X-Core-Value
Adler-Geo
X-Cache-Debug
Cache-Host
X-Men
X-Worker
Origin
X-Variation
X-Qnm-Cache
X-Tx-Id
X-DataDome
X-NCache
XServer
X-Forwarded-Site
X-Esi-Check
X-Fastly-Backend
True-Client-Country-4JS
Server-Host
X-Scheme
X-Developers
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Auto-Login
X-Cache-Id
X-Branch-Name
X-Block-Status
X-Cache-Tags
X-Sigma
X-Cluster
X-Clientip
X-Ckpd-Fst-Backend
X-Bip
X-Sigma-Backend
X-Thanos
VNS-Cache
VNS-Age
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Served-From
X-Slack-Backend
X-Gamma-Serve
Vix-Hermes-Req-Id
X-Geo-Header
CPC-Age
Cmstype
Cmsid
X-Loc
CPC-Cache
Esi-Enabled
X-HN
X-Hnp-Log
PFcat
Fastcgi-Cache-TTL
X-VarnishDD-TTL
X-Location
X-Origin
X-RateLimit-Remaining-Second
X-Origin-Expires
X-RateLimit-Limit-Second
X-Req
X-Old-Content-Length
C-Via
Arc-Version
X-Rocket-Build-Number
Location
X-Level-Front-Cache
X-Generated-By
NGX
M-TraceId
X-VServer
X-Gen-Mode
PB-RID
PB-PID
X-Generated-On
X-Viewer-Country
X-Gzip
X-Amz-Meta-S3cmd-Attrs
X-Platform
X-Request-Host
X-Nginx-Cache-Key
X-FC-Vary-Parameters
X-DefElseHash
X-DefHash
X-Mvc-Supplant-Cachable
X-Skip-Cache
X-Owner
X-Policy
X-Planisys-CDN-TTL
X-Hash
X-Device-Os
X-Generated-In
X-Csrf-Jwt
X-Planisys-CDN-Cache
AKAMAI
X-Vdms-Path
X-VC-Cache
X-Via-NSCOPI
X-Planisys-CDN-Rules
X-Var-Ttl
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Varnish-CookieHashed-On
X-Thinkindot-L3
X-Eu-Site
X-Varnish-Remaining-TTL
X-SIPLIST1
X-Varnish-CookieINHashed-On
X-HS-Content-Campaign-Id
Arc-Country
X-Sucuri-ID
Svr
X-Irp-Debug
Webserver
Pagetype
NM-Fastcgi-Cache
Memcached
Server-Ext
Gh-Request-Id
TDXMobile
Sever-Int
Mail-Subject
CacheControlHeader
Cf-Device-Type
Ha-Gx-Prefs
HA-Ipaddr
IsBot
Locid
L5d-Success-Class
Thinkindot-CacheControl
Server-Hostname
Wxu-Next-Commit
Wxu-Next-Hostname
Thinkindot-CacheControl-Type
DataCenter
We-Hiring
Wxu-Next-Region
V-Age
X-CGP
Thinkindot-Control
X-LSADC-Cache
X-Unique-ID
X-WADP-Cache
DSUID
X-Qloud-Router
X-GoCache-CacheStatus
X-Render-Time
X-Rocket-Nginx-Serving-Static
X-DC
NtCoent-Length
X-Fmm-Version
X-Fetched-On
X-Platform-Cluster
Server-Info
X-Platform-Processor
Release
X-GeoIP
X-Clara-WADP
X-V-Cache
X-Platform-Router
X-GeoIP-City
Cache-Hits
X-Mvc-Supplant-OutputCached
X-SD-PageType
MIME-Version
X-Cache-Var
X-Cache-Remote
X-Cache-Var-Map
X-Via-Popv
Environment
Kp-EeAlive
X-Via-Popn
X-Servedbyhost
X-Via-Poph
X-NodeID
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
X-PJAX-URL
X-Datadog-Parent-Id
X-Zone
X-Nyt-Route
X-API-Version
X-Origin-Time
X-Gdpr
X-Srv
X-Vc
X-User
X-NC
X-ID
X-Wa
Who
X-Server-IP
X-PF-Uncompressing
Server-ID
X-Pod-Name
Candidate-Md5Url
X-Cache-Config
X-Via-Ucdn
X-BBC-Origin-Response-Status
WebServer
X-Varnish-Ttl
X-App
Cluster
X-Refresh
Memory
X-Traceid
X-Internal-Host
X-Minions-Version
X-Varnish-Url
Time
X-LB-ID
X-VCL-Version
HostName
X-TIME
X-CACHE-KEY
X-ZONE
X-Pass-Why
Onion-Location
GeoIp-Country-Code
Powered-By-ChinaCache
X-Webkit-CSP-Report-Only
Web-Mar-Region
My-App
X-NewRelic-App-Data
Geoip-Latitude
Resin-Trace
X-Newrelic-Synthetics
Geo-Info
X-Edge-Pop
N-Cache
X-Cache-Ttl
X-Esi
X-ElasticPress-Query
Datacenter
X-LI-Proto
Servername
X-CLOUD-TRACE-CONTEXT
X-TX-ID
X-Varnish-Cacheable
X-Tb-Optimization-Total-Bytes-Saved
X-VHOST
X-Tt-Logid
X-TraceId
X-Akamai-Pragma-Client-IP
X-Origin-Response-Time
X-EIG-Tracking-Id
X-OVcl-Cache
X-OVcl
CDN
Tcn
X-Geo
X-Fastly-Request-Id
Ohc-File-Size
X-Dynatrace
WWW-Authenticate
X-CACHE-AGE
Cf-Bgj
X-HITS
Hostname
X-Backend-TTL
X-Li-Proto
X-Tid
LB
X-TIM-N
Magicmarker
X-Fpc
Redirect-Candidate
X-Varnish-Beresp-TTL
Tracecode
X-Up
X-NODE
Proxy-Connection
Cdn
X-Dynatrace-Js-Agent
X-Correlation-ID
X-AB
X-Request-Start
X-Wix-Viewer-Type
X-NGINX-Cache
X-Method
X-Dispatcher-Server
Pramga
X-HostName
X-Cache-Date
X-Amz-Meta-Cb-Modifiedtime
GeoIP-Country-Code
X-MSEdge-Features
X-Vcl-Version
X-MSEdge-Flight
Cf-Ipcountry
X-CSRF-TOKEN
Ssr
X-IP
X-Cdn-Origin
W
X-Sn-Servicetimems
X-Provided-By
Lb
X-Fastly-Backend-Reqs
X-ServerName
X-APP
CloudFront-Viewer-Country
GeoIP-Latitude
Is-Us
DB-Nickname
CF-Cached-On
X-Cs
X-UnsetCookies
X-Cache-Expires
X-WA
X-COUNTRY
X-HS-Status
X-Lb-Id
Server-Id
Sid
X-Reqid
X-MG-S
X-Node-Id
X-Webkit-Csp-Report-Only
X-Core-Mission
WP-Super-Cache
Cteonnt-Length
X-Nc
X-FORWARDED-FOR
X-DynaTrace-JS-Agent
X-Check-Cacheable
X-Trv-Group
X-Sucuri-Cache
X-Region-Sid
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-VC
X-Cache-Status-Check
X-ND-Cache
URI
Ohc-Cache-HIT
CountryCode
Env
X-SERVER-NAME
X-Via-PopV
X-Via-PopN
X-Pjax-Url
WZWS-RAY
X-Via-PopH
X-Cache-Backend
X-Via-CDN
Xc-Version
X-ServedByHost
X-Pf-Uncompressing
X-SN
X-Pad
EpKe-Alive
Mime-Version
X-Ig-Push-State
X-Moov-T
X-Moov-Xdn-Version
Shield-Pop
User-Agent
X-IN-APIGATEWAY
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-Acquia-Site
X-IN-APIGATEWAYSSL
X-Edge-POP
FSS-Cache
X-CUA
X-Amz-Meta-Opti
X-RAMCache
X-LiteSpeed-Cache-Control
X-Acquia-Purge-Tags
X-Contensis-Viewer-Groups
CACHE
X-Varnish-Authentication
X-Fastly-Cache-Hits
X-Cache-ASPX
X-TRACE-ID
Ohc-Response-Time
X-Webstats-RespID
X-DI
X-DB
X-Action
Vha6-Origin
X-Parent-Response-Time
X-Oss-Object-Type
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-Nginx-Upstream-Cache-Status
HIT
On-Server
X-Dispatch
X-Dw-Trace-Id
X-DSS
Rt-Fastcgi-Cache
X-SB
X-RSL
X-StackifyID
X-Oss-Storage-Class
Server-Ttl
Xet-Cookie
X-Swift-Error
VivaBuild
Viewtype
X-RPS
X-RPM
X-Cdn-Request-ID
X-DW
X-Cdn-Forward
X-Amzn-Remapped-User-Agent
X-Forwarded-Port
X-Amzn-Remapped-Host
X-Amzn-Remapped-X-Forwarded-For
X-Env-Sha256-Sig
X-Env-Stack-Name
X-Snapshot-Date
X-Ftr-Viewer-Uri
X-ElasticPress-Search
X-MiniProfiler-Ids
ServerName
X-TH-Server
Content-Script-Type
Content-Style-Type
X-CF-Powered-By
X-Yottaa-OS
Req-ID
Hit