Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
Link
ETag
X-XSS-Protection
Pragma
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
P3P
X-UA-Compatible
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Xss-Protection
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-Cache-Status
P3p
X-Generator
X-Request-ID
X-Cacheable
X-Ua-Compatible
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Content-Security-Policy
X-Iinfo
Status
Feature-Policy
Content-Encoding
X-AspNetMvc-Version
X-CDN
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
Upgrade
X-Dns-Prefetch-Control
Access-Control-Max-Age
X-Drupal-Dynamic-Cache
X-Via
Keep-Alive
X-Ws-Request-Id
Request-Context
Server-Timing
X-Robots-Tag
X-AH-Environment
X-Hacker
X-Server
X-Age
X-Turbo-Charged-By
X-Proxy-Cache
X-Cache-Group
X-Server-Powered-By
X-Backend
X-Amz-Request-Id
X-Amz-Id-2
Host-Header
EagleId
X-Nginx-Cache-Status
Report-To
X-LiteSpeed-Cache
X-Rq
X-Varnish-Cache
X-UA-Device
Grace
X-Page-Speed
X-Pingback
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
EagleEye-TraceId
X-Device
X-Vhost
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Amz-Version-Id
NEL
X-Dispatcher
X-OneAgent-JS-Injection
Cf-Railgun
X-Host
X-WebKit-CSP
X-Cache-Spec
X-Server-Id
X-CST
X-Node
X-Backend-Server
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Allow
Request-Id
Surrogate-Control
X-Readtime
Accept-CH
X-Akam-SW-Version
X-Response-Time
Accept-Ch-Lifetime
Xkey
X-HW
X-Language
X-Template
X-Application-Context
X-Country
X-Ruxit-JS-Agent
X-Ac
Content-Location
X-Cache-Lookup
X-Cloud-Trace-Context
Rating
MS-Author-Via
X-Url
X-Webkit-CSP
Edge-Control
X-TtlSet
X-PC
X-Vname
X-Clacks-Overhead
X-Mod-Pagespeed
X-B3-TraceId
X-Trace
Fastly-Restarts
X-Content-Type
X-Varnish-TTL
X-MS-InvokeApp
X-Rack-Cache
X-Buckets
X-Origin-Cache
X-ESI
X-GitHub-Request-Id
Accept-Ch
X-Cnection
X-Country-Code
X-Goog-Hash
X-D2id
Verso
X-VARITI-CCR
X-Kinja
X-GoogleNews-Bot
X-Exp-Id
Arr-Disable-Session-Affinity
X-Use-Magma
X-Cdn-Fetch
X-Kinja-Server
X-Kinja-Revision
X-Exp-Variant
X-Kinja-Build
X-ORACLE-DMS-ECID
X-FastCGI-Cache
Cache-Tag
X-Vcap-Request-Id
X-Cached
Service-Worker-Allowed
X-Abt-Application-Version
X-Server-Name
Accept-CH-Lifetime
X-Px
X-Client-IP
X-Amz-Rid
X-Server-ID
X-Navigation-Version
X-Cache-TTL
Public-Key-Pins
RTSS
X-Powered-By-Plesk
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Access-Control-Request-Method
X-MSEdge-Ref
X-Element-Page-Cache
X-Powered-CMS
X-Fastly-Request-ID
X-Dw-Request-Base-Id
X-NF-Request-ID
X-Upstream
X-Version
X-TTL
X-Middleton-Display
Response
Pagespeed
Display
X-Sol
X-Middleton-Response
S
X-Kinsta-Cache
X-Edge-Location-Klb
X-Edge
X-LLID
X-Server-Lifecycle-Phase
X-Instrumentation
X-Kraken-Loop-Name
X-Kraken-Routeconfig-Destination
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Ttl
X-Accel-Expires
X-HP-Webp
X-Jurisdiction
X-Shield-Request-Id
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
X-Cache-Key
Realpath
X-Correlation-Id
X-ECACHE
X-T
X-Litespeed-Cache
SPRequestGuid
X-SharePointHealthScore
X-PressLabs-Stats
X-Mid
X-MCACHE
Edge-Cache-Tag
X-Content-Security-Policy-Report-Only
SPIisLatency
SPRequestDuration
X-DynaTrace
Fastcgi-Cache
X-Amz-Server-Side-Encryption
X-ORACLE-DMS-RID
X-Content-Digest
Nginx-Cache
X-Mg-S
X-XRDS-Location
X-Forwarded-Proto
X-Recruiting
TP-L2-Cache
TP-Cache
Charset
X-Oneagent-Js-Injection
X-Request-Received
Front-End-Https
X-Request-Processing-Time
TCN
Alternate-Protocol
X-Ruxit-Js-Agent
Server-Node
X-Id
X-Logged-In
Filters
Content-MD5
X-Geo-Country
X-Forwarded-For
X-Ezoic-Cdn
Fusion-Content-Source
Fusion-Content-Id
Fusion-Deployment-Id
Fusion-Source
X-Protected-By
Fusion-Component-Id
Fusion-Template-Id
X-ASPNET-VERSION
Cache-Tags
X-Hostname
X-NWS-LOG-UUID
X-Amzn-Trace-Id
X-Origin-Upstream-Status
X-Grace
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-F-Cache
X-Debug-Info
X-Www-Served-By
Cleartype
X-Ab
X-Amz-Replication-Status
X-HS-Hub-Id
X-AppVersion
X-Az
X-Activity-Id
X-LB-Cache
X-HS-Content-Id
X-HS-Cache-Config
X-Rid
X-Origin-Server
X-HS-Combine-CSS
Host
X-Daa-Tunnel
X-Contextid
X-Git-Hash
X-Page-Id
Section-Io-Cache
X-Browser-Type
Server-Name
X-VCache
X-Erf-Bev-Bev
X-Ser
X-Erf-Bev-Bev-Is-Generated
X-Frontend
X-RateLimit-Remaining
X-Aspnetmvc-Version
X-Cache-Age
X-Content-Options
X-Release
MicrosoftSharePointTeamServices
X-Upgrade-Enabled
X-Kong-Upstream-Latency
Accept-Charset
X-Kong-Proxy-Latency
Access-Control-Allow-Method
ServerID
X-Hits
X-Source
X-Mobile-URL
X-DIS-Request-ID
X-Signature
X-Is-Crawler
X-Request-Guid
X-CACHE-GROUP
X-B-Cache
X-Flags
X-Aspnet-Duration-Ms
X-Providence-Cookie
X-Route-Name
X-Respond-Thread
X-WebKit-CSP-Report-Only
X-Varnish-Age
X-Cache-Action
X-Whom
X-FB-Debug
X-Varnish-Backend
Viewport
Healthy
Paypal-Debug-Id
X-Varnish-Grace
Payment
Fastcgi-Useragent
X-B3-Sampled
X-AOL-HN
X-TT
Node
X-App-Environment
X-Fastcgi-Cache
DynaTrace
X-Yandex-Sdch-Disable
X-Load-Cache
X-Mobile
Version
DC
X-Seen-By
X-Tt-Trace-Host
X-Tt-Trace-Tag
Filterid
X-Distributor
X-N
X-XRDS-LOCATION
X-HTML-Minification-Powered-By
X-User-Agent
X-Cache-Control
Frame-Options
Retry-After
X-Tec-Api-Origin
X-Type
X-Tec-Api-Version
X-Tec-Api-Root
SRV
X-Jobs
MS-CV
Refresh
X-FW-Hash
X-FW-Serve
X-FW-Server
X-FW-Dynamic
X-FW-Static
X-FW-Type
X-Original-Request-Id
X-Response-Served-From
X-HP-Trace-Id
X-Cache-Expired-At
X-UUID
X-NGENIX-Cache
X-Adobe-Content
X-Page-View
X-Node-Name
X-Adobe-Loc
X-Proxy-Cache-Status
NGB
X-Debug-IsConnected
X-Region
X-Instance
X-Real-IP
X-Varnish-Server
X-Azure-Ref
X-Oracle-Dms-Rid
X-Debug-IsPreview
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-B
X-IPLB-Instance
X-Cluster-Name
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-ProcessESI
X-RemovedCookies
X-Tumblr-User
X-G
X-Cacheable-TTL
X-Vgn-Hpd-Reason
X-Device-Type
X-Cache-Time
X-Content-Powered-By
X-RTag
X-Framework
Ms-Operation-Id
Access-Control-Request-Headers
X-Proxy
X-Aws-Lambda-Call-Status
X-IPS-LoggedIn
X-Cache-Hit
Amp-Access-Control-Allow-Source-Origin
X-Zen-Fury
Uber-Trace-Id
X-CDN-Forward
X-Cache-Rule
SD-X-WS
Liferay-Portal
Referer-Policy
X-Parallel-Accel
X-Rendered-As
Cache-Status
X-Is-Bot
X-Ms-Request-Id
X-Drupal-Cache-Tags
X-Ms-Version
X-Wix-Request-Id
X-Time
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Io-Id
X-Mg-Request-UUID
Section-Origin-Responded
Countrycode
X-EdgeConnect-Cache-Status
X-App-Server
X-Debug
X-RateLimit-Limit
X-Revision
X-L-Path
S-Cnection
X-Environment-Context
X-Accel-Buffering
Country
X-Yottaa-Metrics
X-Nginx-Cache
X-Yottaa-Optimizations
CF-IPCountry
X-APP-VERSION
X-Microsite
X-Request-Handler-Origin-Region
X-Cache-Operation
Count-Hit
Ar-Sid
AR-CACHE
AR-Request-ID
AR-PoweredBy
AR-ATIME
X-FW-Version
X-Drupal-Cache-Contexts
Cache
X-RN-RSRV
X-JoinUs
X-TA-CDN-Provider
X-SaId
Akamai-GRN
X-ES-SERVER
X-Endurance-Cache-Level
X-TNCMS
X-Loop
X-GG-Cache-Date
Meta-Geo
X-UPSTREAM-Address
X-Cache-Type
From-Origin
X-Say-Cacheable
X-LAGOON
X-Cache-TTL-Remaining
X-Adobe-Source
X-Say-TTL
X-SayCDN-TTL
GEO-INFO
Surrogate-Key
X-PCL
Country-Code
Azure-Version
Fastly-SSL
X-NYM-Debug-Backend
Protected
X-Human
Azure-SlotName
X-OCL
X-Varnish-Beresp-Grace
X-R9-Blue-Green-Version
X-Sql-Duration-Ms
Azure-RegionName
X-S-Maxage
X-Sql-Count
Azure-SiteName
Azure-InstanceId
X-Request-Time
ServedBy
Apigw-Requestid
X-Handled-By
X-Hosted-By
Decoy-Debug-TTL
X-AWS-Id
Cache-Tv-Group
Cache-Name
X-Labrador-Cache-Channel
X-Be
Decoy-Debug-Key
X-Alternate-Cache-Key
X-BYPASS-REASON
Decoy-Debug-Status
X-Origin-Date
X-Shopify-Stage
X-Sorting-Hat-PodId
X-LJ-Flow-ID
X-ShardId
X-RCS-CacheZone
X-Sorting-Hat-ShopId
X-Status
X-VWS-Id
X-Xfnlog-Site
X-Varnishpool
X-Varnish-Hostname
X-Storefront-Renderer-Rendered
X-Pubstack
X-ShopId
X-PHP-Host
X-Proto
X-ProxyCache-Key
X-No-Session
X-ProxyCache-Status
X-Uri
X-Origin-Hint
X-UA-Device-Type
X-Tumblr-Pixel-2
X-Timing-Wait
X-Via-Fastly
TWC-GeoIP-Country
TWC-Device-Class
Eomportal-Instance
X-Hyper-Cache
X-Web-Node
Property-Id
Selected-Fe
TWC-Connection-Speed
X-Format
X-Access
X-Server-W
X-Section
X-Akamai-Edgescape
X-B3-SpanId
X-Redis-Cache
Webcakes-Region
Webcakes-App-Version
TWC-Locale-Group
TWC-GeoIP-LatLong
Webcakes-App-Name
TWC-Privacy
X-Cache-Server
X-Proxy-Build
X-Backend-Host
X-ApacheServer
X-PHP-Backend
X-Cluster-Node
X-PERF
Nel
Mn-Server-Ip
X-FB-TRIP-ID
X-Time-Microsecs
X-Backend-Name
X-Ua-Device
X-App-Version
X-Hl-Ver
X-Servername
X-ServerID
X-FireWall-Port
Cross-Origin-Opener-Policy
OT-Force-Account-Verify
X-B3-Traceid
X-Tumblr-Pixel-3
X-ATG-Version
X-Detected-As
X-Azure-Ref-OriginShield
Cross-Origin-Window-Policy
X-Ua
Web-Mar-Node
X-TEC-API-VERSION
X-Cache-Host
X-Cache-PHP
X-Varnish-Cache-Hits
X-TEC-API-ORIGIN
X-Generation-Time
X-TEC-API-ROOT
X-Trace-Id
Backend
X-Content-Age
X-Varnish-Hits
Content-Secure-Policy
X-Datadome
Ec-Rule-Version
X-Via-JSL
Source
X-MP-GENERATED-AT
X-SRV
X-CSRF-Token
X-TT-LOGID
X-WA-Info
Xserver
X-Air-Trace-Id
X-Cdn
X-Akamai-Transformed
X-Air-Hostname
X-Air-Source
X-CS
X-Soup
X-Cache-Grace
Upgrade-Insecure-Requests
X-Ratelimit-Limit
X-Microcachable
X-Amzn-Remapped-Content-Length
X-Edge-Location
X-Mode
X-Cache-Enabled
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Bc-Bl
X-Rule
X-Ratelimit-Remaining
X-Locale
X-Forwarded-Host
X-NWS-UUID-VERIFY
Url
X-Origin-TTL
X-Origin-CC
X-Info
X-Unique-Id
X-Ua-Browser
X-Content
S-Rt
X-Site-Version
AMP-Access-Control-Allow-Source-Origin
SID
X-GEO
X-Varnish-Beresp-Status
X-Dc
Content-Disposition
X-Magnolia-Registration
X-Tb
X-Varnish-Beresp-Ttl
X-PBS-Appsvrname
CDN-RequestCountryCode
CDN-RequestId
X-Platform-Server
Apple-News-Services-Parsed-Url
CDN-CachedAt
CDN-Cache
A
Apple-News-Services-Handled
X-PAYTM-SRV-ID
BehaviorPad-Version
CDN-EdgeStorageId
CDCHOST
X-Orig-Expires
Apple-News-Services-Host
CDN-PullZone
Mobile-Detection-Method
X-BCube-Filmed-By
X-BBC-Edge-Cache-Status
X-Cache-Bucket
X-Cache-NE
X-CF-Lambda-Fn
X-B-Cookie
X-ARC
X-Aed
X-Aicache-OS
X-AIR-PT
X-Application
X-CF-Lambda-Version
X-Conf
X-Extlb
X-External-Request-Id
X-Forwarded-Path
X-From
X-Ftr-Request-Id
X-Epic-Correlation-Id
X-Developer
X-Connection-Hash
X-D
X-Debug-Cache
X-Destination
X-A-Wwc
X-A-Dgt
X-NAPM-TraceId
Fastly-SWR
Host-ID
MD5-Digest
Meta-Geo-Continent
Fastly-SIE
Fastcgi-X-Cache-Version
DCR-Decision-By
DCR-Processing-Time-Ms
X-NU-AKA-ACS-Version
Expiry
X-Processor
Odigeo-Trace-Id
X-A
X-A-Ccd
X-A-Dam
X-A-Dcw
T-Server
Surrogated-Key
Path
Rendered-Blocks
Req-Svc-Chain
State
CDN-Uid
Apple-News-Services-Request-Url
X-S
X-Vdms-Version
User-Cache-Control
X-Routing-Service
X-Tenant
X-Rojux
X-Proxied
X-ScT
X-Storage
X-Shop-Environment
X-VG-WebCache
X-VG-WebServer
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
X-Rewrite-Enabled
X-S-Cookie
X-Rebelmouse-Cache-Control
X-Ratelimit-Reset
X-SRCache-Key
X-Request-URI
X-Rebelmouse-Surrogate-Control
X-Cached-By
X-Session-Fingerprint
X-Zipkin-Id
X-DataDome
X-EC-Lua
Platform
X-Loc
X-Fastly-Cache
X-VG-TLSProxy
X-Cache-Debug
NGX
Is-Eu
X-Service
L
M-TraceId
X-VServer
X-Cache-Info
X-Cms-Context
X-LI-UUID
X-Varnish-Ttl
X-Backend-State
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Worker
X-Accel-Expires-Debug
X-DPWN-IS-SECURE
X-Is-Gdpr
X-Li-Pop
X-Envoy-Decorator-Operation
X-Li-Fabric
X-TrackingId
X-JWT-State
UCS
X-Fastly-Backend
X-Men
X-Variation
Cache-Host
X-Core-Value
Cmsid
Adler-Geo
X-Origin-Expires
X-Proxy-Upstream
X-Has-Esi
X-Date
X-Request-UUID
Cmstype
Cache-Key
Fastly-Backend-Name
X-Cache-NGX
X-NCache
X-M-Reqid
X-M-Log
X-Origin
X-Rocket-Build-Number
X-Gamma-Serve
X-Wikidot-Static-Cache
X-Served-From
X-VC-Cache
X-Gen-Mode
Arc-Version
X-Thanos
X-Level-Front-Cache
VNS-Cache
VNS-Age
X-Esi-Check
X-SIPLIST1
X-Thinkindot-L3
C-Via
Vix-Hermes-Req-Id
X-Qnm-Cache
X-Device-Os
X-RateLimit-Remaining-Second
X-Cache-Id
X-Gzip
X-Cache-Tags
X-RateLimit-Limit-Second
X-Generated-By
X-Ckpd-Fst-Backend
X-Developers
X-Nginx-Cache-Key
X-Branch-Name
X-DefElseHash
X-DefHash
X-Auto-Login
X-HN
X-Req
X-Block-Status
X-Bip
X-Hnp-Log
X-Generated-On
Esi-Enabled
CPC-Age
X-Scheme
CPC-Cache
X-Location
Origin
X-Sigma
PFcat
PB-RID
PB-PID
IsBot
X-Viewer-Country
X-Clientip
X-Varnish-Remaining-TTL
Locid
Location
X-Forwarded-Site
X-Micro-Cache
X-Sigma-Backend
X-Via-NSCOPI
X-Slack-Backend
X-Tx-Id
Pics-Label
Cf-Device-Type
X-Var-Ttl
X-Wikidot-Backend
X-VarnishDD-TTL
Sever-Int
Fastly-Drupal-HTML
TDXMobile
Thinkindot-Control
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-Hash
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Geo-Header
X-Old-Content-Length
True-Client-Country-4JS
Server-Ext
Server-Hostname
Server-Host
X-Amz-Meta-S3cmd-Attrs
XServer
X-Platform
X-Skip-Cache
X-Fetched-On
X-GeoIP-City
X-GoCache-CacheStatus
X-Goog-Meta-Goog-Reserved-File-Mtime
X-GeoIP
X-Generated-In
X-FC-Vary-Parameters
X-Fmm-Version
X-Eu-Site
Server-Info
Ha-Gx-Prefs
Gh-Request-Id
X-Vdms-Path
HA-Ipaddr
X-Mvc-Supplant-Cachable
Memcached
Mail-Subject
L5d-Success-Class
Fastcgi-Cache-TTL
DSUID
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Request-Host
X-Owner
X-DC
CacheControlHeader
NM-Fastcgi-Cache
Pagetype
Arc-Country
X-Sucuri-ID
X-HS-Content-Campaign-Id
X-CGP
X-Clara-WADP
X-Csrf-Jwt
X-Cluster
AKAMAI
X-Irp-Debug
V-Age
X-WADP-Cache
Release
We-Hiring
Wxu-Next-Commit
Wxu-Next-Region
Wxu-Next-Hostname
Svr
Webserver
NtCoent-Length
DataCenter
X-V-Cache
X-Qloud-Router
X-LSADC-Cache
X-Platform-Cluster
X-Rocket-Nginx-Serving-Static
X-Platform-Router
X-Platform-Processor
X-Policy
X-Render-Time
X-Unique-ID
X-Via-Popv
X-SD-PageType
X-Via-Popn
Kp-EeAlive
X-Mvc-Supplant-OutputCached
Cache-Hits
X-Via-Poph
X-CACHE-KEY
X-Cache-Remote
X-Cache-Var
X-Cache-Var-Map
X-Servedbyhost
Environment
MIME-Version
X-Srv
X-NodeID
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Datadog-Trace-Id
X-PJAX-URL
X-User
X-API-Version
X-Origin-Time
X-Gdpr
X-Nyt-Route
X-ID
X-Zone
X-PF-Uncompressing
X-NC
X-BBC-Origin-Response-Status
X-Via-Ucdn
Who
X-Vc
WebServer
X-Server-IP
X-Traceid
X-Wa
X-Varnish-Url
Candidate-Md5Url
X-Pod-Name
X-Minions-Version
Cluster
X-Cache-Config
Server-ID
X-App
HostName
X-Refresh
Time
X-TIME
X-Internal-Host
X-Webkit-Csp
Memory
X-LB-ID
X-ZONE
X-Webkit-CSP-Report-Only
X-VCL-Version
Powered-By-ChinaCache
My-App
X-Pass-Why
X-NewRelic-App-Data
GeoIp-Country-Code
Web-Mar-Region
N-Cache
Onion-Location
Geoip-Latitude
X-Newrelic-Synthetics
X-Cache-Ttl
X-Esi
X-Dynatrace
X-Edge-Pop
Datacenter
X-ElasticPress-Query
X-CLOUD-TRACE-CONTEXT
Resin-Trace
X-LI-Proto
X-Tb-Optimization-Total-Bytes-Saved
Geo-Info
X-TX-ID
X-Tt-Logid
X-VHOST
X-TraceId
Servername
X-Varnish-Cacheable
X-OVcl
X-OVcl-Cache
X-Akamai-Pragma-Client-IP
CDN
Ohc-File-Size
Tcn
Cf-Bgj
WWW-Authenticate
X-HITS
X-CACHE-AGE
X-Origin-Response-Time
X-Varnish-Beresp-TTL
Hostname
X-Backend-TTL
X-Geo
X-Li-Proto
X-EIG-Tracking-Id
Magicmarker
Redirect-Candidate
X-Fpc
X-NODE
X-TIM-N
X-Tid
X-AB
LB
X-Correlation-ID
X-Dynatrace-Js-Agent
Tracecode
X-Method
X-Wix-Viewer-Type
Proxy-Connection
X-Dispatcher-Server
X-Up
X-HostName
Cdn
X-MSEdge-Features
Is-Us
Pramga
X-Fastly-Request-Id
X-MSEdge-Flight
X-Request-Start
GeoIP-Country-Code
X-Cache-Date
X-Vcl-Version
X-Cs
Cf-Ipcountry
X-Fastly-Backend-Reqs
X-NGINX-Cache
X-IP
X-Cdn-Origin
GeoIP-Latitude
Server-Id
DB-Nickname
X-Amz-Meta-Cb-Modifiedtime
X-APP
X-Sn-Servicetimems
Lb
Ssr
X-CSRF-TOKEN
CF-Cached-On
X-HS-Status
Sid
X-Provided-By
X-COUNTRY
X-Core-Mission
W
X-WA
X-UnsetCookies
X-MG-S
X-Cache-Expires
CloudFront-Viewer-Country
X-Node-Id
X-Lb-Id
X-Reqid
X-ServerName
X-Webkit-Csp-Report-Only
Cteonnt-Length
X-FORWARDED-FOR
X-Nc
URI
X-Trv-Group
X-VC
WP-Super-Cache
X-Check-Cacheable
X-ND-Cache
X-DynaTrace-JS-Agent
Ohc-Cache-HIT
CountryCode
X-Via-CDN
WZWS-RAY
X-SERVER-NAME
Mime-Version
X-Via-PopH
X-Pjax-Url
X-Via-PopN
X-Via-PopV
X-Cache-Status-Check
X-Region-Sid
X-Sucuri-Cache
Env
X-ServedByHost
X-Cache-Backend
X-ECache
Shield-Pop
X-CCDN-Origin-Time
X-CUA
X-Hcs-Proxy-Type
X-Moov-T
Xc-Version
X-Pf-Uncompressing
X-CCDN-CacheTTL
X-Pad
X-SN
X-Moov-Xdn-Version
X-Cdn-Forward
User-Agent
EpKe-Alive
X-Acquia-Purge-Tags
X-Edge-POP
X-Ig-Push-State
X-Acquia-Site
X-RAMCache
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-IN-APIGATEWAY
X-Contensis-Viewer-Groups
X-Fastly-Cache-Hits
X-Cache-ASPX
X-IN-APIGATEWAYSSL
CACHE
X-Varnish-Authentication
X-LiteSpeed-Cache-Control
Srv
Xet-Cookie
X-Swift-Error
X-SB
X-Webstats-RespID
X-Dw-Trace-Id
Viewtype
X-DSS
Rt-Fastcgi-Cache
FSS-Cache
X-StackifyID
VivaBuild
X-Cdn-Request-ID
X-Amz-Meta-Opti
X-RSL
Vha6-Origin
ServerName
Server-Ttl
X-DB
X-DI
Ohc-Response-Time
X-Action
X-RPS
X-RPM
X-DW
X-Nginx-Upstream-Cache-Status
X-FPC
X-Dispatch
PICS-Label
X-Oss-Hash-Crc64ecma
X-Parent-Response-Time
X-Oss-Request-Id
X-Oss-Object-Type
On-Server
X-Oss-Storage-Class
X-Oss-Server-Time
Fastly-Drupal-Html
Content-Script-Type
X-CF-Powered-By
X-ElasticPress-Search
Content-Style-Type
X-TH-Server
Req-ID
X-MiniProfiler-Ids
X-Yottaa-OS
Hit
HIT