Threat Level: green Handler on Duty: Bojan Zdrnja

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
Link
ETag
Pragma
Expect-CT
X-Powered-By
X-XSS-Protection
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
Alt-Svc
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Request-ID
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
P3p
X-FRAME-OPTIONS
X-Content-Security-Policy
X-Iinfo
Status
Feature-Policy
Content-Encoding
X-AspNetMvc-Version
X-CDN
X-Envoy-Upstream-Service-Time
Upgrade
Access-Control-Expose-Headers
X-Ua-Compatible
X-Drupal-Dynamic-Cache
Access-Control-Max-Age
X-Via
Keep-Alive
X-Ws-Request-Id
Request-Context
X-Robots-Tag
Server-Timing
X-AH-Environment
X-Server
X-Hacker
X-Dns-Prefetch-Control
X-Age
X-Turbo-Charged-By
X-Proxy-Cache
X-Server-Powered-By
X-Cache-Group
X-Backend
X-Amz-Request-Id
Host-Header
EagleId
X-Nginx-Cache-Status
X-Amz-Id-2
Report-To
X-LiteSpeed-Cache
X-Rq
X-Varnish-Cache
X-UA-Device
X-Page-Speed
Grace
X-Pingback
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Device
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Vhost
NEL
X-Amz-Version-Id
Cf-Railgun
X-Dispatcher
X-Host
X-CST
X-Cache-Spec
X-Server-Id
X-Node
Allow
X-Backend-Server
Request-Id
Surrogate-Control
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Readtime
X-WebKit-CSP
X-Akam-SW-Version
X-Webkit-CSP
X-Response-Time
Accept-CH
Xkey
X-HW
X-Language
X-Country
X-Ruxit-JS-Agent
Accept-Ch-Lifetime
X-Application-Context
X-Ac
Content-Location
X-Template
MS-Author-Via
X-Cache-Lookup
X-Cloud-Trace-Context
Rating
X-Url
X-B3-TraceId
X-Mod-Pagespeed
Edge-Control
X-PC
X-Vname
X-TtlSet
X-Clacks-Overhead
X-ESI
Accept-Ch
X-MS-InvokeApp
X-Trace
X-Varnish-TTL
Accept-CH-Lifetime
Fastly-Restarts
X-Content-Type
X-GitHub-Request-Id
X-FastCGI-Cache
X-Rack-Cache
X-Origin-Cache
X-Cnection
X-Kinja-Revision
X-Use-Magma
X-Exp-Variant
X-Exp-Id
X-GoogleNews-Bot
X-Kinja-Build
X-Cdn-Fetch
X-Kinja-Server
X-Kinja
X-Country-Code
X-Server-ID
X-Goog-Hash
Verso
X-D2id
X-VARITI-CCR
X-Buckets
Arr-Disable-Session-Affinity
X-Server-Name
X-Cached
X-Vcap-Request-Id
Cache-Tag
X-ORACLE-DMS-ECID
X-Abt-Application-Version
X-Amz-Rid
X-Client-IP
Service-Worker-Allowed
X-Navigation-Version
X-Powered-By-Plesk
RTSS
Access-Control-Request-Method
X-Fastly-Request-ID
X-Px
X-Powered-CMS
Public-Key-Pins
X-Element-Page-Cache
X-MSEdge-Ref
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Middleton-Response
X-Sol
X-Middleton-Display
Pagespeed
Display
Response
X-Upstream
X-Dw-Request-Base-Id
X-NF-Request-ID
X-Cache-TTL
X-Version
X-Ttl
S
X-TTL
X-Edge
X-Kinsta-Cache
X-LLID
X-Edge-Location-Klb
Realpath
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-Accel-Expires
X-SharePointHealthScore
SPIisLatency
SPRequestDuration
SPRequestGuid
X-Instrumentation
X-Jurisdiction
X-Server-Lifecycle-Phase
X-HP-Webp
X-Kraken-Routeconfig-Destination
X-Kraken-Loop-Name
X-ECACHE
X-Mid
X-T
X-MCACHE
X-Shield-Request-Id
X-Pinterest-Rid
X-Content-Security-Policy-Report-Only
Pinterest-Generated-By
Pinterest-Version
X-PressLabs-Stats
X-Cache-Key
X-Correlation-Id
X-Forwarded-Proto
Edge-Cache-Tag
X-ORACLE-DMS-RID
X-DynaTrace
Fastcgi-Cache
X-Amz-Server-Side-Encryption
X-Recruiting
X-Mg-S
Charset
TP-Cache
TP-L2-Cache
X-Content-Digest
Nginx-Cache
X-XRDS-Location
X-Id
Filters
Front-End-Https
X-Request-Received
X-Request-Processing-Time
TCN
Server-Node
X-Logged-In
Alternate-Protocol
X-Forwarded-For
X-Ezoic-Cdn
Cache-Tags
Content-MD5
X-Geo-Country
X-Release
X-Litespeed-Cache
X-ASPNET-VERSION
Fusion-Component-Id
Fusion-Content-Source
Fusion-Template-Id
Fusion-Content-Id
Fusion-Source
Fusion-Deployment-Id
X-Protected-By
X-Origin-Upstream-Status
X-Hostname
X-Amzn-Trace-Id
X-Grace
X-Ruxit-Js-Agent
X-Origin-Server
X-Www-Served-By
X-F-Cache
X-Goog-Metageneration
X-Oneagent-Js-Injection
Cleartype
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-Rid
X-Amz-Replication-Status
X-Contextid
Host
X-Debug-Info
X-HS-Hub-Id
Server-Name
X-HS-Content-Id
X-HS-Cache-Config
X-AppVersion
X-Az
X-Activity-Id
X-HS-Combine-CSS
X-LB-Cache
X-RateLimit-Remaining
X-NWS-LOG-UUID
Section-Io-Cache
X-Frontend
X-Browser-Type
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Git-Hash
X-Page-Id
MicrosoftSharePointTeamServices
X-Ser
X-Aspnetmvc-Version
X-Cache-Age
X-WebKit-CSP-Report-Only
X-Respond-Thread
X-Daa-Tunnel
X-Content-Options
Accept-Charset
Access-Control-Allow-Method
X-Upgrade-Enabled
X-VCache
X-Source
X-Mobile-URL
X-Hits
X-DIS-Request-ID
X-Signature
X-CACHE-GROUP
X-B-Cache
Payment
ServerID
Paypal-Debug-Id
X-Varnish-Age
X-Aspnet-Duration-Ms
X-Varnish-Grace
X-Route-Name
X-Varnish-Backend
X-Flags
Healthy
X-Providence-Cookie
X-Request-Guid
X-Is-Crawler
X-Whom
X-Cache-Action
X-TT
X-FB-Debug
Viewport
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-B3-Sampled
Node
X-AOL-HN
X-App-Environment
X-Ab
Fastcgi-Useragent
X-Seen-By
DynaTrace
Version
X-Mobile
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
X-N
X-Load-Cache
X-Yandex-Sdch-Disable
DC
X-Type
X-XRDS-LOCATION
X-HTML-Minification-Powered-By
AR-ATIME
AR-PoweredBy
AR-Request-ID
AR-CACHE
Ar-Sid
X-Distributor
X-Tt-Trace-Host
X-Tt-Trace-Tag
MS-CV
Frame-Options
X-Cache-Control
Filterid
Retry-After
X-User-Agent
X-Cache-Expired-At
SRV
X-Jobs
X-Request-Handler-Origin-Region
X-Microsite
X-Original-Request-Id
X-Response-Served-From
X-IPLB-Instance
X-Proxy-Cache-Status
Refresh
X-UUID
X-Adobe-Loc
X-Real-IP
X-Adobe-Content
X-Device-Type
X-Debug-IsPreview
X-Debug-IsConnected
X-Cacheable-TTL
X-Cluster-Name
Access-Control-Request-Headers
X-Instance
X-Varnish-Server
X-Page-View
X-Region
X-IPS-LoggedIn
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
Uber-Trace-Id
X-Framework
NGB
X-Tumblr-User
X-Tumblr-Pixel
X-ProcessESI
X-Content-Powered-By
X-RemovedCookies
X-Cache-Time
X-G
X-B
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Proxy
X-RTag
Ms-Operation-Id
X-FW-Dynamic
X-FW-Hash
X-FW-Serve
X-FW-Server
X-FW-Type
X-FW-Static
X-Vgn-Hpd-Reason
X-Zen-Fury
X-Fastcgi-Cache
X-NGENIX-Cache
X-CDN-Forward
Countrycode
X-Wix-Request-Id
X-Azure-Ref
Cache-Status
X-Debug
X-Time
X-Mg-Request-UUID
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Io-Id
Section-Origin-Responded
Amp-Access-Control-Allow-Source-Origin
X-Accel-Buffering
X-App-Version
X-RateLimit-Limit
X-Node-Name
X-Cache-Rule
X-Oracle-Dms-Rid
Cache
X-Ms-Request-Id
X-Ms-Version
X-Nginx-Cache
X-Rendered-As
X-Cache-Hit
X-Is-Bot
SD-X-WS
X-FireWall-Port
Liferay-Portal
X-Drupal-Cache-Tags
Referer-Policy
S-Cnection
X-EdgeConnect-Cache-Status
Country
X-App-Server
Surrogate-Key
X-Aws-Lambda-Call-Status
X-Environment-Context
X-L-Path
X-Cache-Operation
X-Yottaa-Metrics
X-Yottaa-Optimizations
CF-IPCountry
Eomportal-Instance
X-TA-CDN-Provider
X-Revision
X-SaId
Selected-Fe
X-ES-SERVER
Meta-Geo
X-GG-Cache-Date
X-Timing-Wait
X-Loop
X-Endurance-Cache-Level
X-TNCMS
X-RN-RSRV
From-Origin
X-Parallel-Accel
X-UPSTREAM-Address
X-JoinUs
X-Proxy-Build
X-Varnishpool
X-Xfnlog-Site
X-Varnish-Beresp-Grace
X-Drupal-Cache-Contexts
X-Cache-Type
X-Sorting-Hat-PodId
X-Request-Time
X-Adobe-Source
X-Alternate-Cache-Key
X-Shopify-Stage
X-ShopId
X-ShardId
X-Cache-TTL-Remaining
X-Storefront-Renderer-Rendered
X-Sorting-Hat-ShopId
X-S-Maxage
X-AWS-Id
ServedBy
Cache-Name
X-Pubstack
X-R9-Blue-Green-Version
X-LJ-Flow-ID
Protected
X-BYPASS-REASON
X-Varnish-Hostname
X-Be
X-Backend-Host
X-VWS-Id
X-NYM-Debug-Backend
X-SayCDN-TTL
X-HP-Trace-Id
X-Say-TTL
X-Say-Cacheable
X-LAGOON
X-Human
X-Origin-Date
X-No-Session
X-ProxyCache-Key
X-Handled-By
X-ProxyCache-Status
X-Proto
X-PHP-Backend
X-PCL
Azure-Version
X-Sql-Duration-Ms
Property-Id
X-Server-W
TWC-Connection-Speed
Cache-Tv-Group
Apigw-Requestid
Fastly-SSL
TWC-Locale-Group
Country-Code
X-Akamai-Edgescape
X-Cache-Server
X-RCS-CacheZone
X-FB-TRIP-ID
Webcakes-Region
Webcakes-App-Version
TWC-GeoIP-LatLong
TWC-GeoIP-Country
Azure-SlotName
TWC-Privacy
Webcakes-App-Name
TWC-Device-Class
X-Origin-Hint
Azure-SiteName
X-OCL
X-UA-Device-Type
X-Sql-Count
Azure-RegionName
Azure-InstanceId
X-PHP-Host
X-Tumblr-Pixel-2
X-Status
X-Access
X-Backend-Name
X-Labrador-Cache-Channel
Decoy-Debug-Status
Mn-Server-Ip
X-Hosted-By
X-Hl-Ver
X-Via-Fastly
X-Format
Akamai-GRN
Decoy-Debug-TTL
Decoy-Debug-Key
X-Section
Nel
X-ApacheServer
X-Web-Node
X-PERF
Count-Hit
X-Uri
GEO-INFO
X-FW-Version
X-Hyper-Cache
X-Redis-Cache
X-Ua-Device
Xserver
X-Cache-PHP
X-ServerID
X-Time-Microsecs
X-B3-SpanId
X-ATG-Version
X-Cluster-Node
X-TT-LOGID
X-Servername
X-Trace-Id
OT-Force-Account-Verify
X-CSRF-Token
X-Datadome
X-WA-Info
X-Tumblr-Pixel-3
X-Detected-As
X-MP-GENERATED-AT
X-Content-Age
X-Rule
X-Azure-Ref-OriginShield
Backend
Cross-Origin-Opener-Policy
X-Akamai-Transformed
X-Varnish-Cache-Hits
X-Soup
X-TEC-API-VERSION
X-Cache-Host
X-Generation-Time
X-TEC-API-ROOT
X-APP-VERSION
X-TEC-API-ORIGIN
X-Cached-By
Web-Mar-Node
X-Cache-Enabled
X-Cache-Ttl
X-Varnish-Hits
X-Edge-Location
X-Bc-Bl
X-CS
AMP-Access-Control-Allow-Source-Origin
X-Mode
X-Varnish-Beresp-Status
X-Info
X-SRV
Content-Secure-Policy
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Microcachable
Cross-Origin-Window-Policy
Ec-Rule-Version
X-Amzn-Remapped-Content-Length
X-Ua
X-Dc
S-Rt
X-Via-JSL
X-Cache-NGX
X-B3-Traceid
X-Magnolia-Registration
X-Debug-Cache
X-Storage
X-Cache-Grace
SID
X-Varnish-Beresp-Ttl
X-Platform
X-Air-Trace-Id
X-Air-Hostname
X-Proxied
X-Origin-CC
X-Air-Source
Url
X-Zipkin-Id
X-Routing-Service
X-Origin-TTL
Source
X-Extlb
Upgrade-Insecure-Requests
X-Locale
X-Forwarded-Host
X-NWS-UUID-VERIFY
Req-Svc-Chain
State
Surrogated-Key
Host-ID
Fastly-SWR
Path
Mobile-Detection-Method
Meta-Geo-Continent
Odigeo-Trace-Id
MD5-Digest
M-TraceId
Rendered-Blocks
DCR-Decision-By
Cache-Host
CDCHOST
CDN-Cache
CDN-CachedAt
BehaviorPad-Version
A
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
CDN-EdgeStorageId
CDN-PullZone
DCR-Processing-Time-Ms
Expiry
Fastcgi-X-Cache-Version
Apple-News-Services-Handled
CDN-Uid
T-Server
CDN-RequestCountryCode
CDN-RequestId
Fastly-SIE
X-Bip
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Request-URI
X-Rewrite-Enabled
X-Rojux
X-Ratelimit-Reset
X-Processor
X-Orig-Expires
X-PAYTM-SRV-ID
X-PBS-Appsvrname
X-Platform-Server
X-S
X-S-Cookie
X-VG-WebCache
X-Vdms-Version
X-VG-WebServer
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
X-Thanos
X-Tenant
X-ScT
X-Session-Fingerprint
X-Shop-Environment
X-SRCache-Key
X-NU-AKA-ACS-Version
X-NAPM-TraceId
X-Application
X-Aicache-OS
X-ARC
X-B-Cookie
X-BCube-Filmed-By
X-Aed
X-A-Wwc
X-A-Ccd
X-A-Dam
X-A-Dcw
X-A-Dgt
X-Cache-Bucket
X-Cache-NE
X-External-Request-Id
X-Epic-Correlation-Id
X-Forwarded-Path
X-From
X-GoCache-CacheStatus
X-Developer
X-Destination
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Clientip
X-Connection-Hash
X-A
X-D
X-GEO
X-Tb
Server-Info
X-TrackingId
Is-Eu
X-Fastly-Backend
L
Kp-EeAlive
X-LI-UUID
X-Backend-State
Esi-Enabled
DSUID
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Envoy-Decorator-Operation
Fastly-Drupal-HTML
Fastly-Backend-Name
X-VServer
X-Service
X-Li-Pop
X-Hash
Platform
PB-RID
X-Has-Esi
X-Var-Ttl
X-AIR-PT
X-Generated-On
PB-PID
UCS
X-JWT-State
X-Level-Front-Cache
X-Li-Fabric
X-Is-Gdpr
NGX
X-Variation
Origin
X-Branch-Name
X-Loc
X-Proxy-Upstream
X-VHOST
X-Vdms-Path
Content-Disposition
Arc-Version
C-Via
X-Unique-ID
Adler-Geo
X-Request-UUID
X-Device-Os
X-Served-From
X-EC-Lua
X-Sigma
X-Sigma-Backend
X-Rocket-Build-Number
X-Cms-Context
X-Core-Value
X-VG-TLSProxy
X-DPWN-IS-SECURE
X-Cache-Debug
X-Origin-Expires
X-Cache-Tags
Cmsid
Cmstype
X-Varnish-Ttl
User-Cache-Control
X-Site-Version
True-Client-Country-4JS
X-Gamma-Serve
X-DefElseHash
Thinkindot-Control
X-Generated-In
X-Geo-Header
TDXMobile
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-DefHash
X-VC-Cache
Wxu-Next-Commit
X-Eu-Site
X-Varnish-Remaining-TTL
X-VarnishDD-TTL
X-WADP-Cache
X-Fetched-On
X-Amz-Meta-S3cmd-Attrs
Cache-Key
X-FC-Vary-Parameters
X-Varnish-CookieINHashed-On
X-Ratelimit-Limit
X-GeoIP
Wxu-Next-Hostname
X-Cluster
X-Csrf-Jwt
DataCenter
X-Varnish-CookieHashed-On
X-CGP
Wxu-Next-Region
Vix-Hermes-Req-Id
NM-Fastcgi-Cache
X-Thinkindot-L3
Fastcgi-Cache-TTL
X-Nginx-Cache-Key
Cf-Device-Type
X-Location
X-Forwarded-Site
HA-Ipaddr
X-Accel-Expires-Debug
Ha-Gx-Prefs
Gh-Request-Id
X-Scheme
X-Men
X-SIPLIST1
X-Owner
X-Policy
X-Req
CacheControlHeader
X-Conf
X-Micro-Cache
X-Origin
X-Request-Host
X-Ftr-Request-Id
IsBot
L5d-Success-Class
Release
Pics-Label
PFcat
X-HN
X-GeoIP-City
Server-Ext
Sever-Int
Server-Hostname
Server-Host
Pagetype
X-Cache-Info
X-Date
X-Fastly-Cache
Locid
Location
X-Unique-Id
Memcached
X-Developers
X-Clara-WADP
X-Fmm-Version
Who
NtCoent-Length
X-DataDome
X-Goog-Meta-Goog-Reserved-File-Mtime
X-User
X-Sucuri-ID
X-Skip-Cache
X-Qloud-Router
Mail-Subject
X-Generated-By
X-Hnp-Log
X-BBC-Edge-Cache-Status
X-Irp-Debug
X-Gen-Mode
X-Esi-Check
We-Hiring
X-Block-Status
X-Cache-Id
X-Mvc-Supplant-Cachable
X-Old-Content-Length
X-RateLimit-Remaining-Second
X-Slack-Backend
X-Via-NSCOPI
X-Viewer-Country
X-RateLimit-Limit-Second
AKAMAI
X-Wikidot-Static-Cache
X-Wikidot-Backend
Arc-Country
VNS-Cache
X-Gzip
CPC-Age
V-Age
CPC-Cache
VNS-Age
Svr
Webserver
X-PF-Uncompressing
X-Ckpd-Fst-Backend
X-DC
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Srv
X-Via-Popn
X-Via-Poph
X-Worker
X-Via-Popv
X-Ratelimit-Remaining
X-Mvc-Supplant-OutputCached
X-HS-Content-Campaign-Id
Cache-Hits
X-Varnish-Url
X-Minions-Version
X-CACHE-KEY
X-V-Cache
MIME-Version
X-NC
X-Vc
X-Servedbyhost
X-Auto-Login
XServer
Powered-By-ChinaCache
My-App
X-ID
X-ZONE
X-Zone
X-Platform-Cluster
X-Platform-Processor
X-Refresh
X-Qnm-Cache
X-M-Reqid
X-Render-Time
X-Rocket-Nginx-Serving-Static
X-M-Log
X-Platform-Router
X-LSADC-Cache
X-Internal-Host
X-Tx-Id
X-LB-ID
X-NCache
X-TX-ID
WebServer
X-PJAX-URL
Time
X-Traceid
X-Pass-Why
X-SD-PageType
X-Newrelic-Synthetics
X-Wa
Memory
X-Cache-Remote
X-Datadog-Parent-Id
X-App
X-Datadog-Trace-Id
X-Datadog-Sampling-Priority
Environment
X-TIME
X-Webkit-CSP-Report-Only
Server-ID
X-Webkit-Csp
X-Origin-Time
X-API-Version
X-Dynatrace
X-Gdpr
X-Nyt-Route
X-BBC-Origin-Response-Status
X-OVcl
X-OVcl-Cache
X-NodeID
X-TraceId
X-Cache-Var
X-Via-Ucdn
X-Cache-Config
X-Cache-Var-Map
Cluster
Hostname
X-NewRelic-App-Data
X-VCL-Version
X-Server-IP
Cf-Bgj
HostName
X-Ua-Browser
X-Backend-TTL
X-Content
Magicmarker
X-CLOUD-TRACE-CONTEXT
Candidate-Md5Url
GeoIp-Country-Code
Geoip-Latitude
X-Pod-Name
X-Tb-Optimization-Total-Bytes-Saved
Resin-Trace
Geo-Info
X-LI-Proto
X-Edge-Pop
Datacenter
X-Correlation-ID
X-ElasticPress-Query
X-Dispatcher-Server
DB-Nickname
X-Method
N-Cache
Tcn
Ohc-File-Size
X-CACHE-AGE
X-Geo
Web-Mar-Region
X-HITS
X-Varnish-Beresp-TTL
X-IP
X-Akamai-Pragma-Client-IP
X-Origin-Response-Time
X-Li-Proto
Ssr
GeoIP-Country-Code
X-MSEdge-Features
X-NODE
GeoIP-Latitude
X-MSEdge-Flight
Onion-Location
X-AB
Servername
LB
X-EIG-Tracking-Id
Cf-Ipcountry
X-Node-Id
X-Varnish-Cacheable
WWW-Authenticate
X-Wix-Viewer-Type
X-HostName
Cdn
X-Trv-Group
X-Vcl-Version
X-ND-Cache
Proxy-Connection
X-Cs
X-Fastly-Request-Id
CF-Cached-On
X-Via-CDN
WZWS-RAY
CDN
X-APP
Lb
Server-Id
X-Dynatrace-Js-Agent
X-Nc
X-DynaTrace-JS-Agent
X-HS-Status
Env
Redirect-Candidate
X-Fpc
X-TIM-N
X-Tid
X-Fastly-Backend-Reqs
X-WA
Sid
X-Pjax-Url
X-MG-S
X-ServerName
Tracecode
X-Reqid
X-Request-Start
X-NGINX-Cache
Cteonnt-Length
X-Up
X-Cache-Date
Is-Us
X-Lb-Id
Pramga
Rt-Fastcgi-Cache
X-Check-Cacheable
X-URL
Ohc-Cache-HIT
X-CSRF-TOKEN
X-Esi
X-Xrds-Location
X-IN-APIGATEWAY
X-Sn-Servicetimems
X-Cdn-Origin
X-Via-PopH
X-Via-PopN
X-Via-PopV
URI
X-IN-APIGATEWAYSSL
Viewtype
X-Amz-Meta-Cb-Modifiedtime
X-VC
VivaBuild
X-Cache-Backend
Mime-Version
X-ServedByHost
X-ECache
Server-Ttl
X-Provided-By
Machine
Shield-Pop
X-Core-Mission
X-SN
CountryCode
W
X-FTR-Request-ID
CloudFront-Viewer-Country
X-Tt-Logid
X-UnsetCookies
X-Cdn-Forward
X-Webkit-Csp-Report-Only
X-Fastly-Cache-Hits
X-Cdn-Request-ID
CACHE
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Pad
X-Acquia-Site
X-LiteSpeed-Cache-Control
X-Vcache
X-Dw-Trace-Id
X-FORWARDED-FOR
X-Yottaa-OS
X-Cache-Expires
X-RAMCache
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-Varnish-Authentication
X-Acquia-Purge-Tags
Srv
X-RSL
X-RPS
X-DI
X-DB
Xet-Cookie
X-DW
X-DSS
X-StackifyID
X-RPM
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Cache-Status
X-Pf-Uncompressing
X-FTR-DC
X-FTR-Realm
FSS-Cache
On-Server
X-Action
X-FTR-Balancer
Ohc-Response-Time
ServerName
Vha6-Origin
X-Country-Code-Real
WP-Super-Cache
X-Webstats-RespID
X-Swift-Error
X-SB
X-B3-Spanid
X-Air-Pt
X-Cache-Status-Check
X-Region-Sid
X-Sucuri-Cache
X-FPC
PICS-Label
X-Edge-POP
Req-ID
X-Swa-Ws
X-Oss-Storage-Class
X-Oss-Server-Time
X-ElasticPress-Search
X-TH-Server
X-MiniProfiler-Ids
X-Oss-Request-Id
X-Oss-Object-Type
X-Snapshot-Date
Content-Script-Type
X-C
X-FTR-Expires
X-Oss-Hash-Crc64ecma
Content-Style-Type