Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
Link
X-XSS-Protection
ETag
Pragma
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
P3P
X-UA-Compatible
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Xss-Protection
X-Request-Id
Access-Control-Allow-Credentials
X-Adblock-Key
X-AspNet-Version
X-Runtime
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
P3p
X-Cacheable
X-Request-ID
Timing-Allow-Origin
X-Ua-Compatible
X-DNS-Prefetch-Control
X-Content-Security-Policy
X-Iinfo
Status
Feature-Policy
Content-Encoding
X-AspNetMvc-Version
X-CDN
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
Upgrade
Access-Control-Max-Age
X-Drupal-Dynamic-Cache
X-Dns-Prefetch-Control
X-Via
X-Ws-Request-Id
Keep-Alive
Server-Timing
Request-Context
X-Robots-Tag
X-AH-Environment
X-Hacker
X-Server
X-Age
X-Turbo-Charged-By
X-Proxy-Cache
X-Cache-Group
X-Server-Powered-By
X-Backend
X-Amz-Request-Id
X-Amz-Id-2
Host-Header
EagleId
X-Nginx-Cache-Status
Report-To
X-LiteSpeed-Cache
X-Rq
X-Varnish-Cache
Grace
X-UA-Device
X-Page-Speed
X-Pingback
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
EagleEye-TraceId
X-Device
X-Vhost
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Amz-Version-Id
NEL
X-Dispatcher
Cf-Railgun
X-OneAgent-JS-Injection
X-Host
X-WebKit-CSP
X-Cache-Spec
X-Server-Id
X-CST
X-Node
X-Backend-Server
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Allow
Request-Id
Surrogate-Control
Accept-CH
X-Readtime
X-Akam-SW-Version
X-Response-Time
Accept-Ch-Lifetime
Xkey
X-Language
X-HW
X-Template
X-Application-Context
X-Country
Content-Location
X-Ac
X-Cloud-Trace-Context
X-Cache-Lookup
Rating
MS-Author-Via
X-Url
X-Webkit-CSP
X-Ruxit-JS-Agent
Edge-Control
X-Clacks-Overhead
X-PC
X-TtlSet
X-Vname
X-Mod-Pagespeed
X-Trace
X-Varnish-TTL
Fastly-Restarts
X-B3-TraceId
X-Content-Type
X-Rack-Cache
X-Buckets
X-MS-InvokeApp
X-Origin-Cache
X-ESI
X-GitHub-Request-Id
X-ASPNET-VERSION
X-Country-Code
X-Cnection
X-Goog-Hash
Accept-Ch
Verso
X-D2id
X-VARITI-CCR
Accept-CH-Lifetime
X-ORACLE-DMS-ECID
Arr-Disable-Session-Affinity
X-GoogleNews-Bot
X-Exp-Variant
X-Kinja
X-Exp-Id
X-Kinja-Build
X-Kinja-Server
X-Kinja-Revision
X-Use-Magma
X-Cdn-Fetch
Cache-Tag
X-Vcap-Request-Id
X-Cached
Service-Worker-Allowed
X-Px
X-FastCGI-Cache
X-Server-Name
X-Abt-Application-Version
X-Amz-Rid
X-Client-IP
X-Navigation-Version
X-Cache-TTL
X-Server-ID
Public-Key-Pins
RTSS
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Powered-By-Plesk
X-MSEdge-Ref
Access-Control-Request-Method
X-TTL
X-Element-Page-Cache
X-Powered-CMS
X-Fastly-Request-ID
X-Dw-Request-Base-Id
X-NF-Request-ID
X-Version
X-Upstream
X-Middleton-Response
X-Middleton-Display
Pagespeed
Response
X-Sol
Display
S
X-Kinsta-Cache
X-Edge-Location-Klb
X-Edge
X-LLID
X-Kraken-Loop-Name
X-Instrumentation
X-Kraken-Routeconfig-Destination
X-Server-Lifecycle-Phase
X-Cache-Key
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-ECACHE
X-Accel-Expires
X-Ruxit-Js-Agent
X-Shield-Request-Id
X-HP-Webp
X-Jurisdiction
X-ORACLE-DMS-RID
X-Correlation-Id
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
Realpath
X-Ttl
X-Oneagent-Js-Injection
X-T
X-DynaTrace
X-PressLabs-Stats
X-Mid
X-MCACHE
X-SharePointHealthScore
SPRequestGuid
X-Content-Security-Policy-Report-Only
Edge-Cache-Tag
SPRequestDuration
SPIisLatency
X-Litespeed-Cache
Fastcgi-Cache
X-Amz-Server-Side-Encryption
X-XRDS-Location
Nginx-Cache
X-Content-Digest
X-Forwarded-Proto
X-Mg-S
X-Recruiting
TP-L2-Cache
TP-Cache
X-Request-Processing-Time
X-Request-Received
Front-End-Https
Charset
TCN
Alternate-Protocol
X-Id
Server-Node
X-Logged-In
Filters
Content-MD5
X-Geo-Country
X-Forwarded-For
Fusion-Component-Id
Fusion-Source
X-Ezoic-Cdn
Fusion-Deployment-Id
Fusion-Content-Id
Fusion-Template-Id
Fusion-Content-Source
X-Protected-By
Cache-Tags
X-Hostname
X-Amzn-Trace-Id
X-NWS-LOG-UUID
X-Grace
X-Origin-Upstream-Status
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Metageneration
X-GUploader-UploadID
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Ab
X-Debug-Info
X-Www-Served-By
Cleartype
X-LB-Cache
X-F-Cache
X-Amz-Replication-Status
X-Rid
X-AppVersion
X-Az
X-Activity-Id
X-HS-Hub-Id
X-Origin-Server
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Combine-CSS
Host
X-Daa-Tunnel
X-Contextid
X-Git-Hash
X-Page-Id
X-RateLimit-Remaining
Section-Io-Cache
Server-Name
X-Content-Options
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Erf-Bev-Bev
X-VCache
X-Cache-Age
X-Ser
X-Frontend
X-Upgrade-Enabled
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
MicrosoftSharePointTeamServices
X-Release
X-Fastcgi-Cache
Access-Control-Allow-Method
X-Aspnetmvc-Version
Accept-Charset
X-Hits
ServerID
X-Mobile-URL
X-DIS-Request-ID
X-WebKit-CSP-Report-Only
X-Source
X-Is-Crawler
X-Providence-Cookie
X-Varnish-Age
X-Request-Guid
X-Route-Name
X-Flags
X-Aspnet-Duration-Ms
X-Cache-Action
X-B3-Sampled
X-Signature
X-B-Cache
Healthy
Viewport
X-FB-Debug
X-Varnish-Backend
X-Varnish-Grace
X-Whom
Paypal-Debug-Id
Payment
X-AOL-HN
X-Yandex-Sdch-Disable
Fastcgi-Useragent
X-TT
X-CACHE-GROUP
X-App-Environment
X-Respond-Thread
Node
X-Load-Cache
DynaTrace
X-Mobile
X-Tt-Trace-Tag
DC
X-Tt-Trace-Host
Filterid
X-Seen-By
Version
X-N
X-Distributor
X-Tec-Api-Root
SRV
X-Tec-Api-Origin
X-User-Agent
X-Tec-Api-Version
X-Cache-Control
X-HTML-Minification-Powered-By
Frame-Options
Retry-After
X-Type
X-XRDS-LOCATION
X-HP-Trace-Id
X-Jobs
Refresh
MS-CV
X-FW-Type
X-FW-Hash
X-FW-Serve
X-FW-Static
X-FW-Server
X-FW-Dynamic
X-Response-Served-From
X-Ua-Device
X-Original-Request-Id
X-UUID
X-Cache-Expired-At
X-NGENIX-Cache
X-Proxy-Cache-Status
X-Page-View
X-Adobe-Loc
NGB
X-Azure-Ref
X-Node-Name
X-Adobe-Content
X-Debug-IsConnected
X-Debug-IsPreview
X-Real-IP
X-Instance
X-Varnish-Server
X-Cluster-Name
X-G
X-Tumblr-Pixel-0
X-B
X-IPLB-Instance
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-ProcessESI
X-Cacheable-TTL
X-Tumblr-Pixel-1
X-Tumblr-User
X-RemovedCookies
X-Region
X-Vgn-Hpd-Reason
X-Tumblr-Pixel
X-Cache-Time
X-Aws-Lambda-Call-Status
Access-Control-Request-Headers
Ms-Operation-Id
X-RTag
X-Content-Powered-By
X-CDN-Forward
X-Framework
X-Device-Type
X-Proxy
Amp-Access-Control-Allow-Source-Origin
X-Zen-Fury
X-Cache-Hit
X-IPS-LoggedIn
Referer-Policy
Uber-Trace-Id
X-Cache-Rule
Liferay-Portal
SD-X-WS
X-Parallel-Accel
X-Drupal-Cache-Tags
X-Is-Bot
Cache-Status
X-Rendered-As
X-Ms-Request-Id
X-Ms-Version
X-Wix-Request-Id
X-EdgeConnect-Cache-Status
X-Time
X-App-Server
X-Mg-Request-UUID
Countrycode
Section-Io-Origin-Time-Seconds
Section-Io-Id
Section-Io-Origin-Status
Section-Origin-Responded
X-RateLimit-Limit
X-Oracle-Dms-Rid
X-Revision
X-L-Path
X-Environment-Context
X-Debug
S-Cnection
X-Yottaa-Metrics
X-Yottaa-Optimizations
Country
X-Accel-Buffering
X-B3-Traceid
Count-Hit
X-Cache-Operation
X-TA-CDN-Provider
CF-IPCountry
X-APP-VERSION
X-Nginx-Cache
X-Request-Handler-Origin-Region
X-Microsite
X-Drupal-Cache-Contexts
X-FW-Version
Akamai-GRN
AR-Request-ID
Ar-Sid
Meta-Geo
X-RN-RSRV
X-SaId
AR-PoweredBy
X-GG-Cache-Date
X-ES-SERVER
X-Endurance-Cache-Level
AR-ATIME
AR-CACHE
X-JoinUs
X-UPSTREAM-Address
X-SayCDN-TTL
X-Cache-Type
From-Origin
X-Say-TTL
Surrogate-Key
Cache
X-Adobe-Source
X-Cache-TTL-Remaining
X-Say-Cacheable
X-LAGOON
X-Varnish-Beresp-Grace
Azure-SiteName
Azure-RegionName
Azure-InstanceId
Azure-SlotName
Azure-Version
Country-Code
Fastly-SSL
X-Sql-Count
X-PCL
X-R9-Blue-Green-Version
X-OCL
X-NYM-Debug-Backend
X-Human
X-Loop
X-S-Maxage
X-Request-Time
X-Sql-Duration-Ms
X-TNCMS
X-Alternate-Cache-Key
Apigw-Requestid
X-PHP-Host
X-ProxyCache-Key
X-VWS-Id
X-ProxyCache-Status
X-Origin-Date
X-Status
X-Labrador-Cache-Channel
X-Hosted-By
X-LJ-Flow-ID
X-Storefront-Renderer-Rendered
X-No-Session
X-Pubstack
X-Varnishpool
Decoy-Debug-Key
X-Shopify-Stage
X-ShopId
Decoy-Debug-Status
Decoy-Debug-TTL
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
Cache-Tv-Group
Cache-Name
X-RCS-CacheZone
X-BYPASS-REASON
X-Varnish-Hostname
X-AWS-Id
X-ShardId
X-Handled-By
Protected
X-Proto
X-B3-SpanId
Property-Id
X-Be
Selected-Fe
X-Cache-Server
ServedBy
X-Format
X-App-Version
X-Akamai-Edgescape
Eomportal-Instance
TWC-Connection-Speed
TWC-Device-Class
Webcakes-App-Version
Webcakes-Region
X-Access
Webcakes-App-Name
TWC-Privacy
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Locale-Group
X-Proxy-Build
X-Origin-Hint
X-Redis-Cache
X-Tumblr-Pixel-2
X-Web-Node
X-Xfnlog-Site
X-Via-Fastly
X-Timing-Wait
X-UA-Device-Type
X-Section
X-Server-W
X-ApacheServer
X-Cluster-Node
X-PERF
X-Backend-Host
GEO-INFO
X-PHP-Backend
Mn-Server-Ip
X-Hyper-Cache
X-Uri
X-Time-Microsecs
X-FB-TRIP-ID
X-Servername
Cross-Origin-Opener-Policy
X-Backend-Name
X-Hl-Ver
X-ServerID
OT-Force-Account-Verify
Nel
X-ATG-Version
X-Tumblr-Pixel-3
X-FireWall-Port
X-Detected-As
X-Azure-Ref-OriginShield
X-Ua
Web-Mar-Node
Cross-Origin-Window-Policy
X-Cache-Host
X-Generation-Time
X-Varnish-Cache-Hits
X-Cache-PHP
X-Datadome
X-TEC-API-VERSION
X-Content-Age
X-TEC-API-ORIGIN
Ec-Rule-Version
X-Varnish-Hits
X-TEC-API-ROOT
Content-Secure-Policy
X-TT-LOGID
Source
X-Via-JSL
Backend
X-CS
X-Trace-Id
X-MP-GENERATED-AT
X-Air-Trace-Id
X-Air-Source
X-Air-Hostname
Upgrade-Insecure-Requests
X-Amz-Apigw-Id
X-Amzn-RequestId
X-WA-Info
X-Forwarded-Host
X-Ua-Browser
X-SRV
X-Akamai-Transformed
X-Mode
X-CSRF-Token
X-Cache-Grace
X-Content
X-Microcachable
X-Soup
Xserver
X-Amzn-Remapped-Content-Length
X-NWS-UUID-VERIFY
X-Cache-Enabled
X-Edge-Location
X-Locale
X-Cdn
X-Varnish-Beresp-Ttl
X-Rule
X-Bc-Bl
X-Ratelimit-Limit
Url
X-Dc
X-Info
X-Site-Version
X-Origin-CC
X-Origin-TTL
X-Ratelimit-Remaining
Content-Disposition
X-Tenant
X-Unique-Id
X-Zipkin-Id
SID
X-Proxied
X-Routing-Service
X-Extlb
X-Varnish-Beresp-Status
X-Tb
S-Rt
X-Magnolia-Registration
AMP-Access-Control-Allow-Source-Origin
CDN-Cache
Mobile-Detection-Method
CDCHOST
X-Destination
X-Processor
CDN-EdgeStorageId
X-Ratelimit-Reset
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
Path
CDN-RequestCountryCode
CDN-PullZone
CDN-CachedAt
CDN-Uid
X-Debug-Cache
Odigeo-Trace-Id
DCR-Processing-Time-Ms
Fastly-SWR
X-Orig-Expires
X-D
Apple-News-Services-Handled
Expiry
Fastly-SIE
X-Developer
X-NAPM-TraceId
X-NU-AKA-ACS-Version
A
Apple-News-Services-Host
Host-ID
Fastcgi-X-Cache-Version
MD5-Digest
Meta-Geo-Continent
X-Platform-Server
BehaviorPad-Version
Apple-News-Services-Request-Url
X-PAYTM-SRV-ID
Apple-News-Services-Parsed-Url
X-PBS-Appsvrname
DCR-Decision-By
Req-Svc-Chain
X-VG-WebServer
X-VG-WebCache
X-Aed
X-Aicache-OS
X-Vtex-Processado-Em
X-AIR-PT
X-A-Wwc
X-SRCache-Key
X-A-Dcw
X-A-Dam
X-Request-URI
X-Conf
X-A-Dgt
X-Vtex-Remote-Cache
X-External-Request-Id
X-S-Cookie
X-Cache-Bucket
X-Cache-NE
X-Session-Fingerprint
X-CF-Lambda-Fn
X-BCube-Filmed-By
X-Shop-Environment
X-Application
X-Epic-Correlation-Id
X-ARC
X-B-Cookie
X-BBC-Edge-Cache-Status
X-A-Ccd
X-Vdms-Version
X-S
X-CF-Lambda-Version
CDN-RequestId
User-Cache-Control
X-Storage
X-ScT
X-Rojux
Surrogated-Key
T-Server
X-From
X-Ftr-Request-Id
X-Rewrite-Enabled
X-A
Rendered-Blocks
X-Connection-Hash
X-Forwarded-Path
X-GEO
X-EC-Lua
X-Li-Pop
X-Date
Pics-Label
X-LI-UUID
Origin
X-Loc
X-Cache-Debug
X-Cache-Info
Platform
NGX
L
X-Cms-Context
X-Fastly-Cache
X-Li-Fabric
Is-Eu
Fastly-Drupal-HTML
X-Core-Value
X-Envoy-Decorator-Operation
State
UCS
X-Accel-Expires-Debug
Fastly-Backend-Name
X-Backend-State
X-Micro-Cache
X-M-Log
X-SVT-ORM-VERSION
Adler-Geo
X-SVT-ORM-RULES
X-VServer
X-TrackingId
X-Cached-By
X-Origin-Expires
X-VG-TLSProxy
X-Request-UUID
X-Variation
X-Proxy-Upstream
X-Service
Cache-Key
X-M-Reqid
X-Cache-NGX
X-Men
Cache-Host
X-Worker
X-DPWN-IS-SECURE
X-Tx-Id
X-DataDome
XServer
X-Qnm-Cache
X-NCache
Vix-Hermes-Req-Id
X-Location
X-Sigma-Backend
VNS-Age
X-Gamma-Serve
X-Forwarded-Site
Sever-Int
X-Varnish-CookieINHashed-On
True-Client-Country-4JS
Thinkindot-CacheControl-Type
X-Sigma
Thinkindot-CacheControl
Thinkindot-Control
TDXMobile
X-VarnishDD-TTL
X-Wikidot-Backend
X-Auto-Login
X-Cache-Tags
X-Varnish-CookieHashed-On
X-Wikidot-Static-Cache
X-Bip
X-Varnish-Ttl
X-Branch-Name
X-Block-Status
X-Viewer-Country
X-Via-NSCOPI
X-Fastly-Backend
X-Ckpd-Fst-Backend
X-Scheme
X-Varnish-Remaining-TTL
X-SIPLIST1
X-Gen-Mode
X-Slack-Backend
X-Esi-Check
X-VC-Cache
VNS-Cache
X-Generated-On
X-JWT-State
X-Level-Front-Cache
X-Origin
X-Old-Content-Length
X-Is-Gdpr
X-Developers
X-Hnp-Log
X-DefHash
IsBot
X-Served-From
X-Nginx-Cache-Key
X-Device-Os
CPC-Age
Cmstype
Cmsid
Cf-Device-Type
CPC-Cache
C-Via
Fastcgi-Cache-TTL
Esi-Enabled
Arc-Version
Location
Locid
X-Geo-Header
X-Cluster
PFcat
PB-RID
X-Cache-Id
X-Rocket-Build-Number
Server-Hostname
Server-Host
Server-Ext
X-Clientip
PB-PID
X-Req
X-Has-Esi
X-DefElseHash
X-HN
M-TraceId
X-Thinkindot-L3
X-Gzip
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Thanos
X-Generated-By
X-Amz-Meta-S3cmd-Attrs
X-Platform
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Policy
X-Hash
X-Var-Ttl
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Planisys-CDN-Cache
X-Mvc-Supplant-Cachable
X-Irp-Debug
X-Owner
X-HS-Content-Campaign-Id
X-GeoIP-City
X-Skip-Cache
Svr
X-Sucuri-ID
X-Eu-Site
Arc-Country
X-Vdms-Path
X-FC-Vary-Parameters
X-GeoIP
X-Request-Host
X-Generated-In
X-Fetched-On
AKAMAI
Webserver
Memcached
Mail-Subject
NM-Fastcgi-Cache
Pagetype
Server-Info
Release
L5d-Success-Class
HA-Ipaddr
X-LSADC-Cache
DataCenter
CacheControlHeader
Gh-Request-Id
Ha-Gx-Prefs
V-Age
DSUID
X-CGP
X-Csrf-Jwt
Wxu-Next-Hostname
Wxu-Next-Region
We-Hiring
Wxu-Next-Commit
X-Unique-ID
X-Platform-Processor
X-Platform-Router
X-Rocket-Nginx-Serving-Static
NtCoent-Length
X-Clara-WADP
X-WADP-Cache
X-V-Cache
X-Qloud-Router
X-Platform-Cluster
X-DC
X-Render-Time
X-Fmm-Version
X-GoCache-CacheStatus
MIME-Version
X-SD-PageType
X-Servedbyhost
Cache-Hits
X-Mvc-Supplant-OutputCached
X-Cache-Var-Map
X-Srv
X-Cache-Var
X-Cache-Remote
X-Via-Popv
X-Via-Poph
Kp-EeAlive
X-Via-Popn
Environment
X-NodeID
X-API-Version
X-Nyt-Route
X-Datadog-Trace-Id
X-PJAX-URL
X-Datadog-Sampling-Priority
X-Zone
X-Origin-Time
X-Gdpr
X-Datadog-Parent-Id
X-User
X-NC
X-Vc
X-Via-Ucdn
X-ID
X-Cache-Config
X-Pod-Name
X-Traceid
Who
X-BBC-Origin-Response-Status
Server-ID
Candidate-Md5Url
X-Server-IP
X-PF-Uncompressing
X-Wa
WebServer
Time
X-Refresh
X-Internal-Host
Cluster
X-Varnish-Url
Memory
X-Minions-Version
X-App
X-LB-ID
X-Webkit-Csp
HostName
X-TIME
X-VCL-Version
X-CACHE-KEY
X-ZONE
Onion-Location
X-Pass-Why
Web-Mar-Region
GeoIp-Country-Code
X-Webkit-CSP-Report-Only
My-App
Powered-By-ChinaCache
Resin-Trace
X-NewRelic-App-Data
Geo-Info
X-Edge-Pop
N-Cache
X-Newrelic-Synthetics
Geoip-Latitude
X-Cache-Ttl
X-Esi
X-ElasticPress-Query
X-CLOUD-TRACE-CONTEXT
X-Tb-Optimization-Total-Bytes-Saved
Servername
X-LI-Proto
Datacenter
X-TX-ID
X-Varnish-Cacheable
X-TraceId
X-Tt-Logid
X-VHOST
X-Akamai-Pragma-Client-IP
WWW-Authenticate
X-OVcl
X-OVcl-Cache
X-EIG-Tracking-Id
X-Origin-Response-Time
Tcn
CDN
X-Geo
Ohc-File-Size
Cf-Bgj
X-Dynatrace
X-CACHE-AGE
X-Fpc
X-HITS
Hostname
X-Backend-TTL
LB
Redirect-Candidate
X-Tid
X-TIM-N
X-Li-Proto
Magicmarker
X-NODE
X-Dynatrace-Js-Agent
Tracecode
X-Up
Proxy-Connection
X-Varnish-Beresp-TTL
Cdn
X-AB
Cf-Ipcountry
X-Correlation-ID
X-Request-Start
X-Wix-Viewer-Type
Pramga
X-Cache-Date
X-NGINX-Cache
X-Method
X-Dispatcher-Server
X-HostName
X-Sn-Servicetimems
X-Amz-Meta-Cb-Modifiedtime
GeoIP-Country-Code
X-Cdn-Origin
X-MSEdge-Flight
X-MSEdge-Features
X-Vcl-Version
X-Fastly-Request-Id
X-CSRF-TOKEN
CloudFront-Viewer-Country
Lb
W
Ssr
X-Provided-By
X-APP
Is-Us
DB-Nickname
X-IP
GeoIP-Latitude
X-Fastly-Backend-Reqs
CF-Cached-On
X-Cs
X-UnsetCookies
X-Cache-Expires
X-WA
X-Core-Mission
X-HS-Status
X-Lb-Id
X-Reqid
X-COUNTRY
Server-Id
Sid
X-MG-S
X-ServerName
WP-Super-Cache
X-Webkit-Csp-Report-Only
X-Node-Id
Cteonnt-Length
X-FORWARDED-FOR
X-Nc
X-DynaTrace-JS-Agent
X-Check-Cacheable
X-Trv-Group
X-Hcs-Proxy-Type
X-Sucuri-Cache
X-VC
X-ND-Cache
X-Cache-Status-Check
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Region-Sid
URI
CountryCode
Ohc-Cache-HIT
X-Via-CDN
X-SERVER-NAME
WZWS-RAY
X-Pjax-Url
Env
X-Cache-Backend
X-Via-PopV
Xc-Version
X-Via-PopN
X-Moov-T
X-Moov-Xdn-Version
X-Via-PopH
EpKe-Alive
User-Agent
X-Pad
X-Pf-Uncompressing
X-SN
X-Ig-Push-State
X-ServedByHost
Mime-Version
Shield-Pop
X-Amz-Meta-Opti
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-LiteSpeed-Cache-Control
FSS-Cache
X-Acquia-Site
X-Edge-POP
X-CUA
X-TRACE-ID
X-RAMCache
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Acquia-Application-Trace
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Varnish-Authentication
X-Fastly-Cache-Hits
CACHE
X-SB
X-Swift-Error
HIT
X-Dw-Trace-Id
Xet-Cookie
Ohc-Response-Time
X-Webstats-RespID
Server-Ttl
On-Server
X-Dispatch
X-Oss-Server-Time
X-Oss-Storage-Class
X-Parent-Response-Time
X-Oss-Request-Id
X-Oss-Object-Type
X-Nginx-Upstream-Cache-Status
X-Oss-Hash-Crc64ecma
Vha6-Origin
X-StackifyID
VivaBuild
X-DW
X-Cdn-Request-ID
Viewtype
Rt-Fastcgi-Cache
X-RSL
X-RPS
X-DSS
X-RPM
X-DB
X-Action
X-DI
X-Cdn-Forward
X-Amzn-Remapped-Host
X-Amzn-Remapped-User-Agent
X-Env-Sha256-Sig
X-Snapshot-Date
X-Ftr-Viewer-Uri
X-Forwarded-Port
X-Env-Stack-Name
X-Amzn-Remapped-X-Forwarded-For
Content-Script-Type
X-ElasticPress-Search
Hit
X-MiniProfiler-Ids
Req-ID
X-Yottaa-OS
Content-Style-Type
X-CF-Powered-By
ServerName
X-TH-Server