Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-RAY
CF-Cache-Status
Accept-Ranges
Link
ETag
X-XSS-Protection
Pragma
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
Alt-Svc
X-UA-Compatible
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Xss-Protection
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Request-ID
P3p
X-DNS-Prefetch-Control
X-Content-Security-Policy
X-Iinfo
Status
Feature-Policy
Content-Encoding
X-AspNetMvc-Version
X-CDN
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
X-Ua-Compatible
Upgrade
X-Dns-Prefetch-Control
Access-Control-Max-Age
X-Drupal-Dynamic-Cache
X-Via
X-Ws-Request-Id
Keep-Alive
Server-Timing
Request-Context
X-Robots-Tag
X-AH-Environment
X-Hacker
X-Server
X-Age
X-Turbo-Charged-By
X-Proxy-Cache
X-Cache-Group
X-Server-Powered-By
X-Amz-Request-Id
X-Backend
X-Amz-Id-2
Host-Header
EagleId
X-Nginx-Cache-Status
Report-To
X-LiteSpeed-Cache
X-Rq
X-Varnish-Cache
Grace
X-UA-Device
X-Page-Speed
X-Pingback
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
EagleEye-TraceId
X-Device
X-Vhost
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Amz-Version-Id
NEL
X-Dispatcher
X-OneAgent-JS-Injection
Cf-Railgun
X-Host
X-Cache-Spec
X-WebKit-CSP
X-Server-Id
X-CST
X-Node
X-Backend-Server
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Request-Id
Allow
Surrogate-Control
X-Readtime
Accept-Ch-Lifetime
X-Akam-SW-Version
Accept-CH
X-Response-Time
Xkey
X-Language
X-HW
X-Template
X-Application-Context
X-Country
Content-Location
X-Ac
X-Cache-Lookup
Rating
X-Webkit-CSP
MS-Author-Via
X-Url
X-Ruxit-JS-Agent
X-Cloud-Trace-Context
Edge-Control
X-Clacks-Overhead
X-PC
X-Vname
X-TtlSet
X-Mod-Pagespeed
X-Varnish-TTL
Accept-Ch
X-Trace
X-Content-Type
Fastly-Restarts
X-Rack-Cache
X-B3-TraceId
X-Buckets
X-MS-InvokeApp
X-Origin-Cache
X-ESI
X-GitHub-Request-Id
X-Country-Code
X-Cnection
X-Goog-Hash
Verso
X-VARITI-CCR
X-D2id
X-ORACLE-DMS-ECID
Arr-Disable-Session-Affinity
X-Kinja-Server
X-Kinja-Build
X-Kinja-Revision
X-Kinja
X-Exp-Variant
X-GoogleNews-Bot
X-Exp-Id
X-Use-Magma
X-Cdn-Fetch
X-FastCGI-Cache
Cache-Tag
Service-Worker-Allowed
X-Vcap-Request-Id
X-Px
X-Cached
X-Abt-Application-Version
X-Server-Name
X-Client-IP
X-Server-ID
X-Amz-Rid
X-Navigation-Version
X-Cache-TTL
Public-Key-Pins
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-TTL
RTSS
X-Powered-By-Plesk
Accept-CH-Lifetime
Access-Control-Request-Method
X-Dw-Request-Base-Id
X-MSEdge-Ref
X-Element-Page-Cache
X-Powered-CMS
X-NF-Request-ID
X-Version
X-Upstream
X-Fastly-Request-ID
Pagespeed
X-Middleton-Display
X-Sol
X-Middleton-Response
Response
Display
X-Edge-Location-Klb
S
X-Kinsta-Cache
X-Edge
X-LLID
X-Instrumentation
X-Kraken-Routeconfig-Destination
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-ECACHE
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Accel-Expires
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
X-Shield-Request-Id
X-Jurisdiction
X-Cache-Key
X-HP-Webp
X-Correlation-Id
X-ORACLE-DMS-RID
Realpath
X-T
X-PressLabs-Stats
X-Litespeed-Cache
X-Mid
X-SharePointHealthScore
SPRequestGuid
X-MCACHE
Edge-Cache-Tag
X-Content-Security-Policy-Report-Only
X-Ruxit-Js-Agent
X-DynaTrace
X-Ttl
SPRequestDuration
SPIisLatency
Fastcgi-Cache
X-Amz-Server-Side-Encryption
Nginx-Cache
X-Mg-S
X-Content-Digest
X-XRDS-Location
X-Forwarded-Proto
TP-Cache
X-Recruiting
TP-L2-Cache
X-Id
X-Oneagent-Js-Injection
X-Request-Received
Front-End-Https
X-Request-Processing-Time
Charset
Alternate-Protocol
Server-Node
X-Logged-In
Filters
Content-MD5
X-Geo-Country
TCN
X-Forwarded-For
X-Protected-By
Fusion-Component-Id
Fusion-Content-Id
Fusion-Content-Source
Fusion-Source
Fusion-Deployment-Id
Fusion-Template-Id
X-Ezoic-Cdn
X-ASPNET-VERSION
Cache-Tags
X-Amzn-Trace-Id
X-NWS-LOG-UUID
X-Ab
X-Origin-Upstream-Status
X-Debug-Info
X-Hostname
X-Grace
X-Www-Served-By
X-F-Cache
Cleartype
X-LB-Cache
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Amz-Replication-Status
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
X-Goog-Generation
X-HS-Hub-Id
X-HS-Content-Id
X-Activity-Id
X-AppVersion
X-Origin-Server
X-HS-Cache-Config
X-Rid
X-Az
X-HS-Combine-CSS
Host
X-Daa-Tunnel
X-Git-Hash
X-Page-Id
X-Contextid
Section-Io-Cache
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Content-Options
Server-Name
X-VCache
MicrosoftSharePointTeamServices
X-Upgrade-Enabled
X-Aspnetmvc-Version
X-Ser
X-Frontend
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Cache-Age
Access-Control-Allow-Method
ServerID
Accept-Charset
X-RateLimit-Remaining
X-Hits
X-Source
X-Mobile-URL
X-DIS-Request-ID
X-Release
X-Is-Crawler
X-Flags
X-Providence-Cookie
X-Route-Name
X-Request-Guid
X-CACHE-GROUP
X-Aspnet-Duration-Ms
X-Signature
X-B-Cache
X-WebKit-CSP-Report-Only
X-B3-Sampled
X-Varnish-Age
Viewport
Healthy
X-Varnish-Backend
X-Whom
X-Varnish-Grace
X-FB-Debug
X-Cache-Action
Payment
Paypal-Debug-Id
X-Yandex-Sdch-Disable
DynaTrace
Fastcgi-Useragent
X-TT
X-AOL-HN
X-Respond-Thread
Node
X-Fastcgi-Cache
X-App-Environment
X-Load-Cache
X-Mobile
X-Tt-Trace-Host
DC
X-Tt-Trace-Tag
X-Tec-Api-Origin
Filterid
X-Tec-Api-Root
X-Tec-Api-Version
X-Seen-By
Version
X-Distributor
X-User-Agent
X-XRDS-LOCATION
SRV
X-HTML-Minification-Powered-By
X-Cache-Control
X-N
Retry-After
Frame-Options
X-HP-Trace-Id
X-Type
X-Ua-Device
Refresh
X-Jobs
X-FW-Dynamic
X-FW-Serve
X-FW-Hash
X-Node-Name
MS-CV
X-FW-Server
X-FW-Type
X-FW-Static
X-Original-Request-Id
X-NGENIX-Cache
X-Response-Served-From
X-Azure-Ref
X-UUID
X-Page-View
X-Proxy-Cache-Status
NGB
X-Cache-Expired-At
X-Adobe-Content
X-Adobe-Loc
X-Debug-IsPreview
X-Debug-IsConnected
X-Instance
X-Varnish-Server
X-Real-IP
X-Aws-Lambda-Call-Status
X-Tumblr-Pixel-0
X-Cluster-Name
X-Tumblr-Pixel-1
X-ProcessESI
X-Tumblr-Pixel
X-Region
X-RemovedCookies
X-IPLB-Instance
X-G
X-B
X-Cacheable-TTL
VIX-Pulpo-Node
X-Vgn-Hpd-Reason
X-Tumblr-User
VIX-Pulpo-Upstream-Status
X-Device-Type
X-Framework
Access-Control-Request-Headers
Ms-Operation-Id
X-CDN-Forward
X-RTag
X-Content-Powered-By
X-Cache-Time
X-Proxy
X-Cache-Hit
X-Parallel-Accel
Amp-Access-Control-Allow-Source-Origin
SD-X-WS
X-Zen-Fury
X-Cache-Rule
Liferay-Portal
Referer-Policy
X-IPS-LoggedIn
Uber-Trace-Id
X-Drupal-Cache-Tags
X-Is-Bot
X-Rendered-As
X-Ms-Version
X-Ms-Request-Id
Cache-Status
X-Wix-Request-Id
X-Oracle-Dms-Rid
X-App-Server
X-EdgeConnect-Cache-Status
X-Time
Countrycode
Section-Origin-Responded
X-Mg-Request-UUID
Section-Io-Origin-Status
Section-Io-Id
Section-Io-Origin-Time-Seconds
X-Revision
X-Debug
X-Environment-Context
X-B3-Traceid
S-Cnection
X-L-Path
X-Yottaa-Metrics
X-Yottaa-Optimizations
Country
CF-IPCountry
X-TA-CDN-Provider
Count-Hit
X-Accel-Buffering
X-Cache-Operation
X-RateLimit-Limit
X-Drupal-Cache-Contexts
X-FW-Version
X-Nginx-Cache
X-APP-VERSION
Akamai-GRN
X-RN-RSRV
X-Microsite
X-JoinUs
X-ES-SERVER
X-Endurance-Cache-Level
Meta-Geo
X-SaId
X-GG-Cache-Date
X-Request-Handler-Origin-Region
X-UPSTREAM-Address
Cache
X-Adobe-Source
X-TNCMS
X-Loop
X-Cache-TTL-Remaining
X-LAGOON
From-Origin
Country-Code
X-PCL
Fastly-SSL
X-R9-Blue-Green-Version
X-Request-Time
Surrogate-Key
X-OCL
X-Sql-Duration-Ms
X-Say-TTL
X-SayCDN-TTL
X-Say-Cacheable
X-Human
X-Sql-Count
X-NYM-Debug-Backend
X-Varnish-Beresp-Grace
X-Labrador-Cache-Channel
X-No-Session
X-Hosted-By
X-Handled-By
X-Be
X-BYPASS-REASON
X-B3-SpanId
X-Origin-Date
X-ProxyCache-Status
X-Pubstack
X-ProxyCache-Key
X-Proto
X-PHP-Host
Apigw-Requestid
Azure-InstanceId
Decoy-Debug-Status
Decoy-Debug-Key
Decoy-Debug-TTL
X-Alternate-Cache-Key
Protected
X-AWS-Id
Cache-Tv-Group
Azure-SiteName
Azure-RegionName
Azure-SlotName
Azure-Version
Cache-Name
X-RCS-CacheZone
X-LJ-Flow-ID
X-Sorting-Hat-PodId
X-Shopify-Stage
X-ShopId
X-Status
X-Storefront-Renderer-Rendered
X-VWS-Id
X-Via-Fastly
X-Varnishpool
X-ShardId
X-Sorting-Hat-ShopId
X-S-Maxage
X-App-Version
X-Web-Node
Eomportal-Instance
X-ApacheServer
X-Varnish-Hostname
X-Timing-Wait
X-Origin-Hint
X-UA-Device-Type
X-Xfnlog-Site
X-Akamai-Edgescape
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-Country
TWC-GeoIP-LatLong
Webcakes-Region
ServedBy
X-Access
Property-Id
Selected-Fe
X-Section
X-Tumblr-Pixel-2
Webcakes-App-Name
X-Proxy-Build
X-Cluster-Node
X-PERF
Webcakes-App-Version
X-Server-W
TWC-Locale-Group
X-Cache-Type
X-Format
X-Redis-Cache
X-Cache-Server
TWC-Privacy
X-Time-Microsecs
Nel
AR-Request-ID
Ar-Sid
X-Hyper-Cache
AR-PoweredBy
X-Backend-Host
Mn-Server-Ip
AR-ATIME
X-PHP-Backend
AR-CACHE
X-FB-TRIP-ID
GEO-INFO
X-Uri
X-Servername
X-Hl-Ver
X-Backend-Name
X-ServerID
OT-Force-Account-Verify
Cross-Origin-Opener-Policy
X-Tumblr-Pixel-3
X-ATG-Version
Cross-Origin-Window-Policy
X-Detected-As
X-Azure-Ref-OriginShield
X-Ua
Web-Mar-Node
X-FireWall-Port
X-Datadome
X-Generation-Time
X-Cache-Host
X-Varnish-Cache-Hits
X-Cache-PHP
Ec-Rule-Version
Source
X-Ratelimit-Limit
X-Content-Age
X-Ratelimit-Remaining
X-Varnish-Hits
Content-Secure-Policy
X-TT-LOGID
X-Via-JSL
Backend
X-Trace-Id
X-TEC-API-ROOT
X-SRV
X-CS
X-Akamai-Transformed
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Amzn-RequestId
X-Forwarded-Host
X-Content
X-Ua-Browser
X-Air-Trace-Id
Xserver
X-Amz-Apigw-Id
X-Air-Hostname
X-Air-Source
X-MP-GENERATED-AT
X-WA-Info
X-Cache-Grace
X-Cdn
Upgrade-Insecure-Requests
X-Mode
X-Microcachable
X-CSRF-Token
X-Amzn-Remapped-Content-Length
X-Locale
X-Dc
X-NWS-UUID-VERIFY
X-Cache-Enabled
Url
X-Edge-Location
X-Origin-TTL
X-Site-Version
X-Soup
X-Bc-Bl
X-Origin-CC
AMP-Access-Control-Allow-Source-Origin
X-Rule
Content-Disposition
X-Proxied
X-Extlb
X-Zipkin-Id
X-Routing-Service
X-Varnish-Beresp-Ttl
X-Tb
X-Info
SID
X-Varnish-Beresp-Status
X-Tenant
S-Rt
X-Magnolia-Registration
X-Developer
X-S
A
X-S-Cookie
CDN-RequestCountryCode
DCR-Processing-Time-Ms
X-Vdms-Version
Fastcgi-X-Cache-Version
X-VG-WebCache
X-Rojux
CDN-Cache
DCR-Decision-By
X-Aicache-OS
X-AIR-PT
Apple-News-Services-Handled
Apple-News-Services-Parsed-Url
X-SRCache-Key
CDN-RequestId
CDN-EdgeStorageId
X-A-Dcw
CDN-PullZone
X-Destination
Apple-News-Services-Request-Url
X-A-Ccd
X-A-Dam
X-A-Dgt
Apple-News-Services-Host
X-A-Wwc
Surrogated-Key
CDN-Uid
CDN-CachedAt
Expiry
T-Server
BehaviorPad-Version
X-A
X-Aed
X-From
X-Rebelmouse-Surrogate-Control
X-CF-Lambda-Version
Meta-Geo-Continent
X-Platform-Server
X-Cache-Bucket
X-Rewrite-Enabled
X-External-Request-Id
X-PAYTM-SRV-ID
X-PBS-Appsvrname
X-VG-WebServer
Rendered-Blocks
MD5-Digest
Mobile-Detection-Method
X-CF-Lambda-Fn
X-Vtex-Remote-Cache
X-Request-URI
X-Vtex-Processado-Em
X-Session-Fingerprint
X-Orig-Expires
Odigeo-Trace-Id
X-Cache-NE
X-Unique-Id
X-Shop-Environment
X-M-Log
X-M-Reqid
X-D
X-Rebelmouse-Cache-Control
X-NAPM-TraceId
Fastly-SWR
X-ScT
X-Connection-Hash
X-Conf
Fastly-SIE
X-B-Cookie
X-Processor
X-NU-AKA-ACS-Version
X-Application
User-Cache-Control
X-ARC
X-Debug-Cache
X-Ftr-Request-Id
X-Ratelimit-Reset
Host-ID
X-BCube-Filmed-By
X-Forwarded-Path
CDCHOST
X-NCache
X-GEO
X-Qnm-Cache
X-Storage
X-EC-Lua
Is-Eu
X-Fastly-Cache
Platform
X-DPWN-IS-SECURE
X-Envoy-Decorator-Operation
Path
L
X-Epic-Correlation-Id
UCS
X-Service
Req-Svc-Chain
NGX
Fastly-Backend-Name
State
Origin
X-Has-Esi
X-BBC-Edge-Cache-Status
X-Cms-Context
X-Men
Pics-Label
X-Proxy-Upstream
X-Core-Value
X-Accel-Expires-Debug
X-VG-TLSProxy
X-Backend-State
X-LI-UUID
X-Li-Pop
X-Cache-Debug
X-VServer
X-Request-UUID
X-Origin-Expires
X-Is-Gdpr
X-Date
X-Li-Fabric
X-JWT-State
X-Variation
X-Worker
X-SVT-ORM-RULES
X-Micro-Cache
Adler-Geo
X-SVT-ORM-VERSION
X-TrackingId
Cache-Key
X-Scheme
X-Cached-By
X-Cache-NGX
X-Branch-Name
X-Ckpd-Fst-Backend
X-DefHash
Vix-Hermes-Req-Id
X-Cache-Id
X-Cache-Info
X-Block-Status
X-Cache-Tags
VNS-Age
VNS-Cache
X-Device-Os
X-Developers
Thinkindot-CacheControl-Type
Sever-Int
Thinkindot-CacheControl
X-DefElseHash
X-Auto-Login
TDXMobile
Thinkindot-Control
X-Bip
Server-Host
Server-Ext
Svr
X-Clientip
Server-Hostname
X-Cluster
X-Served-From
True-Client-Country-4JS
X-Via-NSCOPI
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-Varnish-Remaining-TTL
X-VarnishDD-TTL
DataCenter
X-VC-Cache
X-Gzip
X-Geo-Header
AKAMAI
Arc-Country
X-LSADC-Cache
X-Thanos
PFcat
X-Generated-On
X-HN
X-Hnp-Log
X-Loc
X-Wikidot-Static-Cache
X-Location
X-RateLimit-Remaining-Second
X-Nginx-Cache-Key
X-RateLimit-Limit-Second
X-Wikidot-Backend
X-Level-Front-Cache
X-Tx-Id
X-Viewer-Country
X-Origin
X-Old-Content-Length
X-Req
Arc-Version
X-Thinkindot-L3
Fastly-Drupal-HTML
X-SIPLIST1
X-Esi-Check
Fastcgi-Cache-TTL
X-Skip-Cache
X-Forwarded-Site
C-Via
Location
IsBot
Locid
M-TraceId
X-Fastly-Backend
X-Gamma-Serve
Esi-Enabled
X-Slack-Backend
CPC-Cache
X-Gen-Mode
PB-RID
X-Generated-By
Cache-Host
Cmsid
Cf-Device-Type
CPC-Age
PB-PID
Cmstype
X-Unique-ID
X-Amz-Meta-S3cmd-Attrs
X-FC-Vary-Parameters
X-Request-Host
X-Irp-Debug
X-Eu-Site
X-Mvc-Supplant-Cachable
X-Csrf-Jwt
X-Hash
X-HS-Content-Campaign-Id
X-GeoIP-City
X-GeoIP
X-Generated-In
X-Rocket-Build-Number
X-Planisys-CDN-Rules
X-Policy
X-Platform
X-Owner
X-Planisys-CDN-TTL
X-Fetched-On
X-Var-Ttl
Gh-Request-Id
X-Sigma-Backend
DSUID
Ha-Gx-Prefs
HA-Ipaddr
X-Sigma
L5d-Success-Class
CacheControlHeader
X-Sucuri-ID
X-Platform-Processor
X-Planisys-CDN-Cache
X-Vdms-Path
X-Platform-Router
X-CLOUD-TRACE-CONTEXT
X-DataDome
Mail-Subject
NtCoent-Length
V-Age
Memcached
X-Platform-Cluster
We-Hiring
Wxu-Next-Commit
Wxu-Next-Hostname
Wxu-Next-Region
Server-Info
X-Render-Time
XServer
X-CGP
NM-Fastcgi-Cache
Pagetype
Release
Webserver
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Clara-WADP
X-WADP-Cache
X-Fmm-Version
X-SD-PageType
X-Qloud-Router
X-V-Cache
X-Rocket-Nginx-Serving-Static
X-GoCache-CacheStatus
X-Cache-Var-Map
X-Cache-Var
X-Cache-Remote
Cache-Hits
Environment
X-DC
X-Mvc-Supplant-OutputCached
X-CACHE-KEY
Kp-EeAlive
MIME-Version
X-Servedbyhost
X-Datadog-Trace-Id
X-API-Version
X-Nyt-Route
X-Datadog-Parent-Id
X-Via-Poph
X-Via-Popn
X-Datadog-Sampling-Priority
X-NodeID
X-Gdpr
X-PJAX-URL
X-Origin-Time
X-Via-Popv
X-Srv
X-Vc
X-Via-Ucdn
X-NC
X-Zone
X-Cache-Config
X-User
X-PF-Uncompressing
X-Server-IP
Candidate-Md5Url
X-Pod-Name
WebServer
X-Varnish-Ttl
X-Wa
X-BBC-Origin-Response-Status
Time
Memory
Cluster
Who
X-Refresh
X-App
X-Traceid
X-Varnish-Url
Server-ID
X-Internal-Host
X-Minions-Version
X-Webkit-Csp
X-TIME
HostName
Onion-Location
X-ZONE
Web-Mar-Region
X-VCL-Version
X-LB-ID
GeoIp-Country-Code
X-Webkit-CSP-Report-Only
Tcn
X-Pass-Why
X-Dynatrace
Geo-Info
My-App
X-Edge-Pop
Resin-Trace
Geoip-Latitude
X-ID
X-NewRelic-App-Data
Powered-By-ChinaCache
N-Cache
X-Cache-Ttl
X-Esi
X-Newrelic-Synthetics
X-ElasticPress-Query
X-Tb-Optimization-Total-Bytes-Saved
X-TraceId
X-TX-ID
X-Akamai-Pragma-Client-IP
X-LI-Proto
CDN
Servername
X-Varnish-Cacheable
Datacenter
X-VHOST
X-Tt-Logid
WWW-Authenticate
X-Fastly-Request-Id
Ohc-File-Size
X-Geo
X-EIG-Tracking-Id
X-CACHE-AGE
X-HITS
X-OVcl-Cache
X-Origin-Response-Time
X-OVcl
X-HostName
X-Varnish-Beresp-TTL
X-Fpc
X-Li-Proto
Cf-Bgj
Redirect-Candidate
X-TIM-N
X-Tid
X-Backend-TTL
LB
Hostname
Magicmarker
X-Up
X-NODE
Proxy-Connection
Tracecode
X-AB
X-Correlation-ID
Pramga
X-Cache-Date
X-Request-Start
X-Method
X-Wix-Viewer-Type
X-NGINX-Cache
Cdn
X-Dynatrace-Js-Agent
X-Sn-Servicetimems
X-Vcl-Version
X-Amz-Meta-Cb-Modifiedtime
X-Cdn-Origin
X-Dispatcher-Server
CloudFront-Viewer-Country
Cf-Ipcountry
X-CSRF-TOKEN
GeoIP-Country-Code
X-APP
Is-Us
W
X-Provided-By
X-MSEdge-Flight
Lb
X-MSEdge-Features
X-Fastly-Backend-Reqs
CF-Cached-On
X-Cs
X-UnsetCookies
X-COUNTRY
X-WA
X-HS-Status
X-Lb-Id
GeoIP-Latitude
Sid
X-Core-Mission
X-IP
Server-Id
Ssr
DB-Nickname
X-MG-S
X-Cache-Expires
X-ServerName
Cteonnt-Length
X-Reqid
X-Webkit-Csp-Report-Only
WP-Super-Cache
X-FORWARDED-FOR
X-Region-Sid
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-Check-Cacheable
X-DynaTrace-JS-Agent
X-Node-Id
X-Sucuri-Cache
X-Cache-Status-Check
X-CCDN-CacheTTL
URI
Ohc-Cache-HIT
CountryCode
X-Moov-T
X-Moov-Xdn-Version
X-ServedByHost
X-Via-PopN
Xc-Version
X-Nc
X-VC
X-Trv-Group
X-ND-Cache
X-Via-PopV
X-Via-PopH
X-Cache-Backend
X-SERVER-NAME
Env
Mime-Version
User-Agent
X-Ig-Push-State
X-SN
Shield-Pop
X-Pad
X-Via-CDN
X-Pjax-Url
WZWS-RAY
X-CUA
X-Amz-Meta-Opti
X-Acquia-Site
X-Edge-POP
X-RAMCache
FSS-Cache
EpKe-Alive
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
X-Acquia-Application-Trace
X-Varnish-Authentication
X-Fastly-Cache-Hits
CACHE
X-LiteSpeed-Cache-Control
X-Pf-Uncompressing
X-Cache-ASPX
X-Contensis-Viewer-Groups
X-Swift-Error
Xet-Cookie
X-Dw-Trace-Id
X-IN-APIGATEWAY
X-SB
HIT
X-Oss-Server-Time
X-Oss-Storage-Class
X-Parent-Response-Time
X-Oss-Request-Id
X-Oss-Object-Type
X-Dispatch
X-Nginx-Upstream-Cache-Status
X-Oss-Hash-Crc64ecma
On-Server
X-Webstats-RespID
X-DW
X-DSS
X-DI
X-RPM
X-RPS
X-StackifyID
Server-Ttl
X-RSL
X-Action
X-DB
ServerName
X-Cdn-Request-ID
X-IN-APIGATEWAYSSL
Vha6-Origin
Ohc-Response-Time
X-TRACE-ID
X-Cdn-Forward
X-Env-Sha256-Sig
X-Amzn-Remapped-X-Forwarded-For
X-Amzn-Remapped-User-Agent
X-Amzn-Remapped-Host
X-Env-Stack-Name
X-Forwarded-Port
X-Snapshot-Date
X-Ftr-Viewer-Uri
X-FPC
Fastly-Drupal-Html
X-MiniProfiler-Ids
X-CF-Powered-By
X-Yottaa-OS
Content-Script-Type
Content-Style-Type
Req-ID
Hit
Rt-Fastcgi-Cache
Viewtype
VivaBuild