Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
Link
Pragma
ETag
X-XSS-Protection
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
Alt-Svc
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Xss-Protection
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Permitted-Cross-Domain-Policies
X-Request-ID
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
P3p
X-FRAME-OPTIONS
X-Content-Security-Policy
X-Iinfo
Status
Content-Encoding
Feature-Policy
X-AspNetMvc-Version
X-CDN
X-Envoy-Upstream-Service-Time
Upgrade
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Access-Control-Max-Age
X-Via
Keep-Alive
X-Ws-Request-Id
Request-Context
Server-Timing
X-Robots-Tag
X-AH-Environment
X-Server
X-Ua-Compatible
X-Hacker
X-Age
X-Dns-Prefetch-Control
X-Turbo-Charged-By
X-Proxy-Cache
X-Server-Powered-By
X-Cache-Group
X-Backend
Host-Header
X-Amz-Request-Id
EagleId
X-Nginx-Cache-Status
X-Amz-Id-2
Report-To
X-LiteSpeed-Cache
X-Rq
X-Varnish-Cache
X-Page-Speed
Grace
X-UA-Device
X-Swift-CacheTime
X-Swift-SaveTime
X-Pingback
Ali-Swift-Global-Savetime
X-Device
EagleEye-TraceId
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Vhost
Cf-Railgun
NEL
X-Amz-Version-Id
X-Host
X-Dispatcher
X-Server-Id
X-OneAgent-JS-Injection
X-CST
X-Node
Allow
Surrogate-Control
X-Cache-Spec
Request-Id
X-Backend-Server
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Accept-CH
X-WebKit-CSP
X-Readtime
X-Response-Time
X-Akam-SW-Version
X-Webkit-CSP
Xkey
X-HW
X-Country
X-Ac
Content-Location
Accept-Ch-Lifetime
X-Application-Context
X-Language
MS-Author-Via
X-Template
X-Cloud-Trace-Context
Rating
X-Cache-Lookup
X-Url
X-Ruxit-JS-Agent
X-Mod-Pagespeed
Edge-Control
X-Vname
X-PC
X-TtlSet
X-Clacks-Overhead
X-B3-TraceId
X-ESI
X-MS-InvokeApp
X-Trace
X-Varnish-TTL
Accept-CH-Lifetime
X-GitHub-Request-Id
X-Content-Type
Fastly-Restarts
X-ASPNET-VERSION
X-Cnection
X-Origin-Cache
X-Rack-Cache
X-FastCGI-Cache
X-D2id
X-Exp-Variant
X-Exp-Id
X-Cdn-Fetch
X-GoogleNews-Bot
X-Kinja
X-Use-Magma
X-Kinja-Server
X-Kinja-Revision
X-Kinja-Build
X-Country-Code
Verso
X-VARITI-CCR
Arr-Disable-Session-Affinity
X-Goog-Hash
X-Server-Name
X-Cached
X-Vcap-Request-Id
X-Navigation-Version
X-Buckets
Cache-Tag
X-Client-IP
X-Powered-By-Plesk
X-Amz-Rid
X-Abt-Application-Version
Service-Worker-Allowed
Accept-Ch
X-ORACLE-DMS-ECID
RTSS
X-Fastly-Request-ID
X-Cache-TTL
X-Sol
Response
Access-Control-Request-Method
X-Middleton-Response
Display
Pagespeed
X-Middleton-Display
X-Powered-CMS
X-MSEdge-Ref
X-Element-Page-Cache
X-Ttl
X-Oneagent-Js-Injection
X-NF-Request-ID
Public-Key-Pins
X-Dw-Request-Base-Id
X-Upstream
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Version
X-Px
X-Edge
S
X-Kinsta-Cache
X-LLID
X-Edge-Location-Klb
Realpath
X-TTL
Mrf-Cache-Status
X-Ruxit-Js-Agent
MRF-Tech
X-B3-TraceId-Primal
X-Server-ID
X-Accel-Expires
SPRequestDuration
SPIisLatency
X-SharePointHealthScore
SPRequestGuid
X-T
X-HP-Webp
X-Jurisdiction
X-Aspnetmvc-Version
X-Mid
X-MCACHE
X-ECACHE
X-PressLabs-Stats
X-Forwarded-Proto
X-Content-Security-Policy-Report-Only
X-Instrumentation
X-Server-Lifecycle-Phase
X-Kraken-Routeconfig-Destination
X-Kraken-Loop-Name
X-Shield-Request-Id
X-DynaTrace
X-Correlation-Id
X-Recruiting
Charset
Pinterest-Version
Pinterest-Generated-By
Edge-Cache-Tag
X-Pinterest-Rid
Fastcgi-Cache
X-Cache-Key
X-Amz-Server-Side-Encryption
TP-L2-Cache
TP-Cache
X-Mg-S
X-Content-Digest
X-Ezoic-Cdn
X-Release
X-Request-Processing-Time
Filters
X-Request-Received
X-Id
X-ORACLE-DMS-RID
Nginx-Cache
TCN
Server-Node
Front-End-Https
X-Logged-In
Alternate-Protocol
Cache-Tags
X-XRDS-Location
X-Forwarded-For
Content-MD5
X-Litespeed-Cache
X-Origin-Upstream-Status
Fusion-Deployment-Id
Fusion-Template-Id
Fusion-Source
Fusion-Content-Id
Fusion-Component-Id
Fusion-Content-Source
X-Amzn-Trace-Id
Server-Name
X-Geo-Country
X-Grace
X-Origin-Server
X-Hostname
X-Protected-By
X-Amz-Replication-Status
X-Contextid
X-Rid
X-Www-Served-By
X-AppVersion
Cleartype
X-Az
X-Activity-Id
X-F-Cache
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Metageneration
Host
X-WebKit-CSP-Report-Only
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Combine-CSS
X-RateLimit-Remaining
X-Debug-Info
Section-Io-Cache
X-Frontend
X-LB-Cache
MicrosoftSharePointTeamServices
X-Browser-Type
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-NWS-LOG-UUID
X-Ser
X-Page-Id
X-Git-Hash
X-Tec-Api-Root
X-Tec-Api-Version
X-Tec-Api-Origin
X-Cache-Age
X-Respond-Thread
AR-PoweredBy
AR-Request-ID
AR-ATIME
X-Upgrade-Enabled
Accept-Charset
Ar-Sid
X-VCache
AR-CACHE
X-Content-Options
X-Source
X-Varnish-Age
X-DIS-Request-ID
X-Hits
X-Mobile-URL
X-Daa-Tunnel
Paypal-Debug-Id
X-Varnish-Backend
ServerID
Access-Control-Allow-Method
X-CACHE-GROUP
X-Signature
X-B-Cache
X-Varnish-Grace
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Viewport
X-Aspnet-Duration-Ms
Payment
X-Flags
X-Is-Crawler
Healthy
X-Request-Guid
X-Route-Name
X-Providence-Cookie
X-Whom
X-B3-Sampled
X-Cache-Action
X-FB-Debug
X-TT
X-XRDS-LOCATION
Node
X-App-Environment
X-N
X-AOL-HN
X-Seen-By
Version
X-Type
X-Request-Handler-Origin-Region
X-Microsite
DynaTrace
X-Load-Cache
Fastcgi-Useragent
X-Mobile
DC
X-Fastcgi-Cache
MS-CV
X-Yandex-Sdch-Disable
X-Ab
X-Cache-Expired-At
X-HTML-Minification-Powered-By
Retry-After
X-Ua-Device
SRV
X-Distributor
X-Cache-Control
Filterid
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-IPLB-Instance
Frame-Options
X-User-Agent
X-Original-Request-Id
X-Response-Served-From
X-UUID
X-Instance
X-Real-IP
X-Tumblr-Pixel
X-ProcessESI
X-IPS-LoggedIn
X-Tumblr-Pixel-0
X-Tumblr-User
X-RemovedCookies
X-Tumblr-Pixel-1
X-Cluster-Name
X-RTag
X-Adobe-Content
X-Proxy
X-Jobs
X-Varnish-Server
X-Proxy-Cache-Status
Ms-Operation-Id
X-Device-Type
X-Region
X-Adobe-Loc
X-Page-View
X-Debug-IsConnected
Access-Control-Request-Headers
Refresh
X-Cache-Time
Uber-Trace-Id
X-Content-Powered-By
X-Debug-IsPreview
NGB
X-Framework
X-Cacheable-TTL
X-B
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-G
X-FireWall-Port
X-Debug
X-Accel-Buffering
Cache
X-FW-Server
X-FW-Hash
X-FW-Dynamic
X-FW-Static
X-FW-Serve
X-Zen-Fury
X-FW-Type
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Io-Id
Section-Origin-Responded
X-Wix-Request-Id
Countrycode
X-Vgn-Hpd-Reason
X-Oracle-Dms-Rid
X-RateLimit-Limit
X-NGENIX-Cache
X-Mg-Request-UUID
X-CDN-Forward
Cache-Status
X-Azure-Ref
X-Time
X-App-Version
Surrogate-Key
Country
X-Is-Bot
X-Rendered-As
X-Ms-Version
X-Ms-Request-Id
X-Cache-Rule
X-Cache-Hit
X-Nginx-Cache
X-Drupal-Cache-Tags
X-EdgeConnect-Cache-Status
X-Node-Name
S-Cnection
SD-X-WS
Referer-Policy
X-App-Server
Eomportal-Instance
Amp-Access-Control-Allow-Source-Origin
Liferay-Portal
X-TA-CDN-Provider
X-Environment-Context
X-Cache-Operation
X-L-Path
X-Varnishpool
Selected-Fe
X-Yottaa-Metrics
X-Drupal-Cache-Contexts
X-Yottaa-Optimizations
X-Timing-Wait
X-Proxy-Build
X-ES-SERVER
X-UPSTREAM-Address
X-Tumblr-Pixel-2
X-SaId
Meta-Geo
X-RN-RSRV
X-JoinUs
From-Origin
X-TNCMS
X-Backend-Host
X-Cache-Server
X-Endurance-Cache-Level
X-Varnish-Hostname
X-Via-Fastly
X-S-Maxage
X-Pubstack
X-R9-Blue-Green-Version
X-Request-Time
X-Xfnlog-Site
X-PHP-Backend
X-Loop
X-No-Session
X-Handled-By
CF-IPCountry
Protected
X-GG-Cache-Date
ServedBy
Webcakes-App-Name
TWC-Privacy
Azure-SlotName
Azure-SiteName
Webcakes-App-Version
X-Cache-TTL-Remaining
Azure-Version
TWC-Locale-Group
Azure-RegionName
Fastly-SSL
TWC-Connection-Speed
Webcakes-Region
Property-Id
Cache-Tv-Group
TWC-Device-Class
TWC-GeoIP-Country
Azure-InstanceId
TWC-GeoIP-LatLong
X-VWS-Id
X-OCL
X-Adobe-Source
X-Server-W
Cache-Name
X-ShardId
X-Origin-Hint
X-PCL
X-ProxyCache-Key
X-Proto
X-Human
X-ProxyCache-Status
X-ShopId
X-NYM-Debug-Backend
X-Storefront-Renderer-Rendered
X-BYPASS-REASON
X-AWS-Id
X-Be
X-Alternate-Cache-Key
X-Sorting-Hat-ShopId
X-Shopify-Stage
X-LJ-Flow-ID
X-Varnish-Beresp-Grace
X-Sorting-Hat-PodId
X-LAGOON
X-Origin-Date
Decoy-Debug-Key
Country-Code
X-SayCDN-TTL
X-Section
X-Format
X-Backend-Name
X-Say-TTL
X-Say-Cacheable
Decoy-Debug-TTL
X-Hl-Ver
X-RCS-CacheZone
Decoy-Debug-Status
X-Access
Akamai-GRN
Nel
X-Labrador-Cache-Channel
X-Sql-Count
X-Sql-Duration-Ms
X-ApacheServer
X-PHP-Host
Mn-Server-Ip
X-PERF
Apigw-Requestid
X-FB-TRIP-ID
X-UA-Device-Type
X-Hyper-Cache
X-Akamai-Edgescape
X-Status
X-Cache-PHP
X-Revision
X-Uri
X-Redis-Cache
X-Rule
X-Hosted-By
X-Cache-Type
X-Web-Node
Xserver
X-Trace-Id
X-WA-Info
X-Aws-Lambda-Call-Status
X-ATG-Version
X-MP-GENERATED-AT
AMP-Access-Control-Allow-Source-Origin
X-FW-Version
X-B3-SpanId
X-Content-Age
X-B3-Traceid
X-Time-Microsecs
X-ServerID
X-Tumblr-Pixel-3
X-Dc
X-Parallel-Accel
X-Cached-By
X-Soup
X-CSRF-Token
X-Cache-Enabled
X-Akamai-Transformed
Backend
X-Edge-Location
GEO-INFO
Count-Hit
X-Mode
X-Datadome
X-TT-LOGID
OT-Force-Account-Verify
X-Cluster-Node
X-Detected-As
X-Azure-Ref-OriginShield
X-Varnish-Cache-Hits
X-APP-VERSION
X-Info
X-Bc-Bl
X-Varnish-Beresp-Status
X-Microcachable
Web-Mar-Node
X-Generation-Time
X-Cache-Host
X-CS
Cross-Origin-Opener-Policy
X-Varnish-Hits
X-Servername
X-Cache-NGX
X-Debug-Cache
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Amzn-Remapped-Content-Length
X-Proxied
DataCenter
X-Routing-Service
X-Platform
X-Zipkin-Id
X-Storage
X-HP-Trace-Id
Who
X-Varnish-Beresp-Ttl
X-SRV
X-Unique-ID
X-Extlb
X-Origin-TTL
X-Origin-CC
X-DataDome
M-TraceId
Fastly-Backend-Name
Fastcgi-X-Cache-Version
Mobile-Detection-Method
Meta-Geo-Continent
Host-ID
MD5-Digest
CDN-EdgeStorageId
BehaviorPad-Version
Cache-Host
CDCHOST
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
A
Apple-News-Services-Handled
Apple-News-Services-Host
CDN-Cache
CDN-CachedAt
Content-Disposition
DCR-Decision-By
DCR-Processing-Time-Ms
CDN-Uid
CDN-RequestId
Odigeo-Trace-Id
CDN-PullZone
CDN-RequestCountryCode
Expiry
X-Cms-Context
X-Processor
X-PBS-Appsvrname
X-Ratelimit-Reset
X-Request-URI
X-Rewrite-Enabled
X-PAYTM-SRV-ID
X-NAPM-TraceId
X-Geo-Header
X-Generated-On
X-Level-Front-Cache
X-Locale
X-Location
X-Rojux
X-S
X-VG-WebCache
X-Vdms-Version
X-VG-WebServer
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
X-Vdms-Path
X-Thanos
X-ScT
X-S-Cookie
X-Service
X-Session-Fingerprint
X-SRCache-Key
X-From
X-External-Request-Id
X-A-Dgt
X-A-Dcw
X-A-Wwc
X-Aed
X-Aicache-OS
X-A-Dam
X-A-Ccd
State
Req-Svc-Chain
Surrogated-Key
T-Server
X-A
X-Application
X-ARC
X-D
X-Core-Value
X-Destination
X-Developer
X-Epic-Correlation-Id
X-Connection-Hash
X-CF-Lambda-Version
X-BCube-Filmed-By
X-B-Cookie
X-Bip
X-Cache-Bucket
X-Cache-NE
Rendered-Blocks
X-CF-Lambda-Fn
SID
X-Air-Source
Server-Info
X-Air-Hostname
X-Magnolia-Registration
X-Air-Trace-Id
Upgrade-Insecure-Requests
X-Ua
PFcat
X-GoCache-CacheStatus
Pagetype
Memcached
X-EC-Lua
X-Varnish-Ttl
Origin
Kp-EeAlive
Fastly-SIE
Fastly-SWR
X-HN
Fastcgi-Cache-TTL
Esi-Enabled
X-Hash
X-Has-Esi
L
Pics-Label
Path
Gh-Request-Id
Location
Server-Host
X-Branch-Name
X-Sucuri-ID
X-Backend-State
X-TrackingId
X-Cache-Debug
X-Scheme
X-Clientip
X-Sigma
X-Sigma-Backend
X-Served-From
X-Var-Ttl
X-Developers
X-NWS-UUID-VERIFY
X-VG-TLSProxy
X-Via-JSL
X-Rebelmouse-Surrogate-Control
X-Request-UUID
UCS
X-Rocket-Build-Number
X-Envoy-Decorator-Operation
S-Rt
X-VarnishDD-TTL
X-Rebelmouse-Cache-Control
X-VHOST
CacheControlHeader
X-Proxy-Upstream
X-JWT-State
X-Is-Gdpr
X-Platform-Server
X-Cache-Grace
Source
X-Origin
X-NU-AKA-ACS-Version
Cmsid
AKAMAI
Cmstype
Cross-Origin-Window-Policy
X-Tb
User-Cache-Control
Url
X-AIR-PT
X-Fastly-Cache
X-Clara-WADP
X-Fmm-Version
Wxu-Next-Commit
Wxu-Next-Hostname
X-Eu-Site
X-Fastly-Backend
Wxu-Next-Region
X-Men
X-Varnish-Url
True-Client-Country-4JS
X-Thinkindot-L3
Svr
NtCoent-Length
X-Forwarded-Site
X-Ratelimit-Limit
TDXMobile
X-Forwarded-Host
X-DPWN-IS-SECURE
Thinkindot-CacheControl-Type
X-Date
X-Tenant
X-Cache-Info
X-Csrf-Jwt
Thinkindot-CacheControl
X-Site-Version
X-Cache-Tags
X-Shop-Environment
X-Orig-Expires
X-SVT-ORM-VERSION
X-Accel-Expires-Debug
X-Micro-Cache
X-Variation
X-Forwarded-Path
X-CGP
X-Minions-Version
X-Origin-Expires
X-VC-Cache
Adler-Geo
X-Policy
X-Generated-In
X-Generated-By
HA-Ipaddr
NM-Fastcgi-Cache
Is-Eu
C-Via
NGX
Fastly-Drupal-HTML
L5d-Success-Class
DSUID
X-Amz-Meta-S3cmd-Attrs
Thinkindot-Control
Ha-Gx-Prefs
X-WADP-Cache
X-Req
X-Loc
X-Request-Host
X-SVT-ORM-RULES
Cf-Device-Type
Ec-Rule-Version
X-Gamma-Serve
Platform
PB-PID
Arc-Version
PB-RID
Arc-Country
X-Device-Os
Content-Secure-Policy
X-Owner
X-Gzip
X-PF-Uncompressing
X-Goog-Meta-Goog-Reserved-File-Mtime
X-DefHash
X-Esi-Check
X-Gen-Mode
X-LI-UUID
X-FC-Vary-Parameters
X-RateLimit-Limit-Second
X-Qloud-Router
X-RateLimit-Remaining-Second
X-DefElseHash
X-Li-Fabric
X-Mvc-Supplant-Cachable
X-Li-Pop
X-Irp-Debug
X-Hnp-Log
Vix-Hermes-Req-Id
IsBot
Release
Server-Ext
X-Cluster
Mail-Subject
X-Viewer-Country
X-Wikidot-Backend
X-Wikidot-Static-Cache
Server-Hostname
Sever-Int
X-Skip-Cache
X-User
X-VServer
Cache-Key
X-Nginx-Cache-Key
X-Fetched-On
X-GeoIP
X-GeoIP-City
We-Hiring
Locid
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-Cache-Id
X-Block-Status
X-SIPLIST1
X-TEC-API-VERSION
Webserver
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Old-Content-Length
X-HS-Content-Campaign-Id
X-Srv
X-Ftr-Request-Id
VNS-Cache
X-Slack-Backend
Cache-Hits
X-Unique-Id
X-Via-NSCOPI
CPC-Cache
CPC-Age
X-CACHE-KEY
Powered-By-ChinaCache
V-Age
My-App
VNS-Age
XServer
X-Zone
X-Refresh
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Mvc-Supplant-OutputCached
X-Vc
X-Conf
X-Planisys-CDN-TTL
X-GEO
MIME-Version
X-Pass-Why
X-Ratelimit-Remaining
X-TX-ID
X-Via-Popv
X-PJAX-URL
X-Via-Poph
X-Cache-Ttl
X-Via-Popn
X-BBC-Edge-Cache-Status
X-Ckpd-Fst-Backend
X-NC
X-Worker
X-Internal-Host
X-TIME
X-Servedbyhost
Geo-Info
X-ID
X-OVcl-Cache
X-Auto-Login
X-OVcl
Memory
Time
X-TraceId
WebServer
X-LB-ID
X-NCache
Cf-Bgj
X-LSADC-Cache
X-Backend-TTL
X-Webkit-Csp
Server-ID
Magicmarker
X-Rocket-Nginx-Serving-Static
X-Render-Time
X-V-Cache
X-DC
DB-Nickname
X-NewRelic-App-Data
X-Tx-Id
X-ZONE
GeoIp-Country-Code
Geoip-Latitude
X-Platform-Processor
X-Traceid
Hostname
X-M-Reqid
X-M-Log
X-Cache-Remote
X-Platform-Cluster
X-Qnm-Cache
X-Wa
X-Platform-Router
X-Newrelic-Synthetics
X-Geo
X-SD-PageType
X-Method
X-App
HostName
X-Dispatcher-Server
Environment
X-CLOUD-TRACE-CONTEXT
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Datadog-Trace-Id
X-Tb-Optimization-Total-Bytes-Saved
X-VCL-Version
X-NodeID
X-API-Version
Resin-Trace
X-Origin-Time
X-IP
X-BBC-Origin-Response-Status
X-Gdpr
X-Nyt-Route
Ssr
X-Cache-Config
X-Correlation-ID
LB
X-Server-IP
X-Via-Ucdn
X-Pod-Name
X-Edge-Pop
Cluster
Tcn
Ohc-File-Size
X-HITS
X-Origin-Response-Time
Candidate-Md5Url
X-Li-Proto
X-Dynatrace
X-CACHE-AGE
X-MSEdge-Features
X-MSEdge-Flight
X-Webkit-CSP-Report-Only
X-Cache-Var
X-Cache-Var-Map
X-LI-Proto
X-ElasticPress-Query
X-Trv-Group
X-Nc
Cf-Ipcountry
X-DynaTrace-JS-Agent
X-Node-Id
X-Varnish-Beresp-TTL
N-Cache
Web-Mar-Region
X-Via-CDN
X-Vcl-Version
X-Akamai-Pragma-Client-IP
Datacenter
X-ND-Cache
X-APP
X-Wix-Viewer-Type
Env
X-ServerName
X-HostName
X-Cs
Proxy-Connection
X-Fastly-Request-Id
X-Reqid
Sid
X-WA
GeoIP-Country-Code
Servername
GeoIP-Latitude
X-Dynatrace-Js-Agent
CDN
X-HS-Status
CF-Cached-On
X-Content
Onion-Location
X-Ua-Browser
X-NGINX-Cache
X-Varnish-Cacheable
WWW-Authenticate
Rt-Fastcgi-Cache
Cdn
X-EIG-Tracking-Id
VivaBuild
X-AB
Viewtype
Server-Id
X-MG-S
X-Lb-Id
X-Fastly-Backend-Reqs
WZWS-RAY
X-CSRF-TOKEN
Machine
X-FTR-Request-ID
X-Check-Cacheable
X-Via-PopH
X-Via-PopV
X-Cdn-Forward
X-Via-PopN
X-URL
X-Xrds-Location
Ohc-Cache-HIT
X-Esi
X-IN-APIGATEWAY
On-Server
X-VC
Server-Ttl
Cteonnt-Length
X-Pjax-Url
X-ServedByHost
X-Cache-Backend
FSS-Cache
X-IN-APIGATEWAYSSL
X-TIM-N
X-Fpc
X-Request-Start
Redirect-Candidate
X-ECache
CountryCode
X-SN
X-Tid
X-Swa-Ws
Mime-Version
Shield-Pop
URI
X-Tt-Logid
X-Cache-Date
X-FTR-Cache-Status
X-FTR-Realm
X-FTR-Balancer
X-Oss-Server-Time
X-Varnish-Authentication
X-Up
X-Oss-Request-Id
X-FTR-Backend-Server
X-Oss-Hash-Crc64ecma
X-Contensis-Viewer-Groups
Is-Us
X-Pad
X-Cache-ASPX
X-Oss-Object-Type
X-Amz-Meta-Cb-Modifiedtime
Pramga
X-FTR-DC
X-Swift-Error
Lb
X-Oss-Storage-Class
CACHE
Xc-Version
X-Air-Pt
X-Country-Code-Real
Tracecode
X-FORWARDED-FOR
X-FTR-Backend
X-RSL
X-RPS
X-StackifyID
X-DW
X-RPM
Xet-Cookie
X-Acquia-Site
X-Yottaa-OS
X-Cdn-Origin
X-Sn-Servicetimems
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-DI
X-Dw-Trace-Id
X-Acquia-Application-Trace
X-Pf-Uncompressing
X-DSS
X-DB
X-Webstats-RespID
Ohc-Response-Time
WP-Super-Cache
X-SB
Vha6-Origin
X-Action
X-ElasticPress-Search
Warning
X-LiteSpeed-Cache-Control
X-Fastly-Cache-Hits
X-B3-Spanid
X-CCM
Content-Script-Type
X-CUA
CloudFront-Viewer-Country
Content-Style-Type
X-Core-Mission
X-UP
X-RAMCache
X-FPC
X-FTR-Expires
X-Snapshot-Date
X-TH-Server
ServerName
X-Mg-Request-Id
X-MiniProfiler-Ids
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-C