Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
Link
ETag
X-XSS-Protection
Pragma
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
P3P
X-UA-Compatible
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Xss-Protection
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-Cache-Status
P3p
X-Generator
X-Request-ID
X-Cacheable
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Content-Security-Policy
X-Iinfo
Status
X-Ua-Compatible
Feature-Policy
Content-Encoding
X-AspNetMvc-Version
X-CDN
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
Upgrade
X-Dns-Prefetch-Control
Access-Control-Max-Age
X-Drupal-Dynamic-Cache
X-Via
Keep-Alive
X-Ws-Request-Id
Server-Timing
Request-Context
X-Robots-Tag
X-AH-Environment
X-Hacker
X-Server
X-Age
X-Turbo-Charged-By
X-Proxy-Cache
X-Cache-Group
X-Server-Powered-By
X-Backend
X-Amz-Request-Id
Host-Header
X-Amz-Id-2
EagleId
X-Nginx-Cache-Status
Report-To
X-LiteSpeed-Cache
X-Rq
X-Varnish-Cache
X-UA-Device
Grace
X-Page-Speed
X-Pingback
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
EagleEye-TraceId
X-Device
X-Vhost
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Amz-Version-Id
NEL
X-Dispatcher
X-OneAgent-JS-Injection
Cf-Railgun
X-Host
X-WebKit-CSP
X-Cache-Spec
X-Server-Id
X-CST
X-Node
X-Backend-Server
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Allow
Request-Id
Surrogate-Control
X-Readtime
Accept-CH
X-Akam-SW-Version
X-Response-Time
Accept-Ch-Lifetime
Xkey
X-HW
X-Language
X-Application-Context
X-Template
X-Country
X-Ruxit-JS-Agent
X-Ac
Content-Location
X-Cache-Lookup
X-Cloud-Trace-Context
Rating
MS-Author-Via
X-Url
X-Webkit-CSP
Edge-Control
X-PC
X-Vname
X-TtlSet
X-Clacks-Overhead
X-Mod-Pagespeed
X-B3-TraceId
X-Trace
X-Content-Type
X-Varnish-TTL
Fastly-Restarts
X-Rack-Cache
X-MS-InvokeApp
X-Origin-Cache
X-Buckets
X-ESI
X-GitHub-Request-Id
Accept-Ch
X-Cnection
X-Country-Code
X-Goog-Hash
X-D2id
Verso
X-VARITI-CCR
X-ORACLE-DMS-ECID
X-GoogleNews-Bot
X-Kinja
X-Kinja-Revision
X-Exp-Variant
X-Kinja-Server
X-Exp-Id
X-Kinja-Build
X-Use-Magma
X-Cdn-Fetch
Arr-Disable-Session-Affinity
X-FastCGI-Cache
Cache-Tag
X-Vcap-Request-Id
Service-Worker-Allowed
X-Cached
X-Server-Name
X-Abt-Application-Version
X-Px
Accept-CH-Lifetime
X-Amz-Rid
X-Client-IP
X-Server-ID
X-Navigation-Version
X-Cache-TTL
Public-Key-Pins
RTSS
X-Powered-By-Plesk
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-MSEdge-Ref
Access-Control-Request-Method
X-Element-Page-Cache
X-Powered-CMS
X-Dw-Request-Base-Id
X-Fastly-Request-ID
X-NF-Request-ID
X-Upstream
X-Version
X-TTL
X-Middleton-Display
X-Middleton-Response
X-Sol
Display
Pagespeed
Response
S
X-Kinsta-Cache
X-Edge-Location-Klb
X-Edge
X-LLID
X-Instrumentation
X-Kraken-Loop-Name
X-Kraken-Routeconfig-Destination
X-Server-Lifecycle-Phase
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Ttl
X-Accel-Expires
X-HP-Webp
X-Shield-Request-Id
X-Jurisdiction
Pinterest-Version
X-Correlation-Id
X-Pinterest-Rid
X-Cache-Key
Pinterest-Generated-By
X-ECACHE
Realpath
X-ORACLE-DMS-RID
X-T
SPRequestGuid
X-SharePointHealthScore
X-Litespeed-Cache
X-Mid
X-MCACHE
X-PressLabs-Stats
Edge-Cache-Tag
X-Content-Security-Policy-Report-Only
SPRequestDuration
SPIisLatency
X-DynaTrace
Fastcgi-Cache
X-Amz-Server-Side-Encryption
X-Content-Digest
Nginx-Cache
X-Mg-S
X-XRDS-Location
X-Forwarded-Proto
X-Recruiting
TP-L2-Cache
TP-Cache
Charset
X-Oneagent-Js-Injection
X-Request-Received
X-Request-Processing-Time
Front-End-Https
TCN
Alternate-Protocol
Server-Node
X-Ruxit-Js-Agent
X-Id
X-Logged-In
Filters
X-Geo-Country
Content-MD5
X-Forwarded-For
X-Ezoic-Cdn
Fusion-Source
Fusion-Content-Id
Fusion-Deployment-Id
Fusion-Component-Id
Fusion-Content-Source
Fusion-Template-Id
X-Protected-By
X-ASPNET-VERSION
Cache-Tags
X-Hostname
X-NWS-LOG-UUID
X-Amzn-Trace-Id
X-Grace
X-Origin-Upstream-Status
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Debug-Info
X-F-Cache
X-Www-Served-By
X-Ab
X-Origin-Server
X-Amz-Replication-Status
Cleartype
X-HS-Cache-Config
X-AppVersion
X-Activity-Id
X-Rid
X-LB-Cache
X-HS-Hub-Id
X-Az
X-HS-Content-Id
X-HS-Combine-CSS
Host
X-Daa-Tunnel
X-Contextid
X-Git-Hash
X-Page-Id
Section-Io-Cache
Server-Name
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Ser
X-Browser-Type
X-VCache
X-Frontend
X-RateLimit-Remaining
X-Aspnetmvc-Version
X-Cache-Age
X-Release
X-Content-Options
MicrosoftSharePointTeamServices
X-Upgrade-Enabled
X-Kong-Proxy-Latency
Access-Control-Allow-Method
Accept-Charset
X-Kong-Upstream-Latency
ServerID
X-Source
X-Hits
X-Mobile-URL
X-DIS-Request-ID
X-Is-Crawler
X-Flags
X-Providence-Cookie
X-Route-Name
X-B-Cache
X-Request-Guid
X-Aspnet-Duration-Ms
X-CACHE-GROUP
X-Signature
X-Respond-Thread
X-Varnish-Age
X-Cache-Action
X-WebKit-CSP-Report-Only
Healthy
X-FB-Debug
X-Whom
X-Varnish-Backend
Viewport
X-Varnish-Grace
Paypal-Debug-Id
Payment
X-TT
X-B3-Sampled
Fastcgi-Useragent
X-AOL-HN
Node
X-Fastcgi-Cache
X-Yandex-Sdch-Disable
DynaTrace
X-App-Environment
X-Load-Cache
X-Mobile
DC
Version
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Seen-By
Filterid
X-N
X-Distributor
X-HTML-Minification-Powered-By
X-XRDS-LOCATION
X-User-Agent
X-Cache-Control
X-Tec-Api-Root
X-Tec-Api-Origin
X-Tec-Api-Version
Retry-After
Frame-Options
X-Type
SRV
X-Jobs
MS-CV
Refresh
X-FW-Hash
X-FW-Static
X-FW-Serve
X-FW-Type
X-FW-Dynamic
X-FW-Server
X-HP-Trace-Id
X-Response-Served-From
X-Original-Request-Id
X-UUID
X-Proxy-Cache-Status
X-Adobe-Loc
X-Node-Name
X-Adobe-Content
X-Cache-Expired-At
X-Page-View
NGB
X-NGENIX-Cache
X-Debug-IsPreview
X-Azure-Ref
X-Instance
X-Debug-IsConnected
X-Real-IP
X-Varnish-Server
X-Region
X-IPLB-Instance
X-Cacheable-TTL
X-ProcessESI
X-Vgn-Hpd-Reason
VIX-Pulpo-Upstream-Status
X-B
X-G
X-Cluster-Name
X-RemovedCookies
VIX-Pulpo-Node
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-Content-Powered-By
X-Proxy
X-Framework
X-Device-Type
X-Cache-Time
Access-Control-Request-Headers
Ms-Operation-Id
X-RTag
X-Aws-Lambda-Call-Status
X-Zen-Fury
X-Cache-Hit
X-IPS-LoggedIn
Amp-Access-Control-Allow-Source-Origin
X-CDN-Forward
Uber-Trace-Id
SD-X-WS
X-Cache-Rule
Referer-Policy
Liferay-Portal
X-Parallel-Accel
X-Rendered-As
Cache-Status
X-Is-Bot
X-Ms-Version
X-Drupal-Cache-Tags
X-Ms-Request-Id
X-Wix-Request-Id
X-Oracle-Dms-Rid
X-Time
Section-Origin-Responded
X-Mg-Request-UUID
Section-Io-Id
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Countrycode
X-EdgeConnect-Cache-Status
X-App-Server
X-Debug
X-RateLimit-Limit
X-L-Path
X-Revision
X-Environment-Context
S-Cnection
X-Accel-Buffering
Country
X-Yottaa-Metrics
X-APP-VERSION
X-Yottaa-Optimizations
X-Nginx-Cache
CF-IPCountry
X-Microsite
X-Request-Handler-Origin-Region
Count-Hit
X-Cache-Operation
AR-PoweredBy
AR-CACHE
AR-Request-ID
AR-ATIME
Ar-Sid
X-Drupal-Cache-Contexts
Cache
X-FW-Version
X-ES-SERVER
X-UPSTREAM-Address
X-TA-CDN-Provider
X-RN-RSRV
X-SaId
X-JoinUs
Meta-Geo
X-TNCMS
X-GG-Cache-Date
X-Endurance-Cache-Level
Akamai-GRN
X-Loop
X-Cache-TTL-Remaining
X-LAGOON
From-Origin
X-Adobe-Source
GEO-INFO
X-SayCDN-TTL
X-Say-TTL
X-Say-Cacheable
Surrogate-Key
X-PCL
Fastly-SSL
X-Sql-Duration-Ms
X-Request-Time
Protected
X-Human
X-S-Maxage
X-Sql-Count
Country-Code
X-OCL
Azure-RegionName
X-Varnish-Beresp-Grace
Azure-InstanceId
X-R9-Blue-Green-Version
X-Cache-Type
X-NYM-Debug-Backend
Azure-Version
Azure-SiteName
Azure-SlotName
Decoy-Debug-Key
Apigw-Requestid
X-Pubstack
X-ProxyCache-Status
ServedBy
X-ProxyCache-Key
Cache-Name
Decoy-Debug-Status
Cache-Tv-Group
X-Proto
Decoy-Debug-TTL
X-RCS-CacheZone
X-PHP-Host
X-ShardId
X-Labrador-Cache-Channel
X-Status
X-AWS-Id
X-Alternate-Cache-Key
X-Origin-Date
X-Storefront-Renderer-Rendered
X-Handled-By
X-Hosted-By
X-LJ-Flow-ID
X-Varnish-Hostname
X-Sorting-Hat-ShopId
X-VWS-Id
X-Be
X-No-Session
X-BYPASS-REASON
X-Varnishpool
X-Sorting-Hat-PodId
X-Shopify-Stage
X-ShopId
X-Xfnlog-Site
X-Proxy-Build
X-Format
Selected-Fe
TWC-GeoIP-LatLong
TWC-Locale-Group
TWC-Privacy
Webcakes-App-Name
TWC-GeoIP-Country
TWC-Device-Class
Property-Id
X-Hyper-Cache
X-Via-Fastly
TWC-Connection-Speed
Eomportal-Instance
X-Web-Node
X-Server-W
X-Timing-Wait
X-Access
Webcakes-Region
X-B3-SpanId
X-Akamai-Edgescape
Webcakes-App-Version
X-Origin-Hint
X-UA-Device-Type
X-Tumblr-Pixel-2
X-Section
X-Cache-Server
X-Redis-Cache
X-Uri
X-Backend-Host
X-PHP-Backend
X-ApacheServer
Nel
Mn-Server-Ip
X-Cluster-Node
X-PERF
X-Time-Microsecs
X-FB-TRIP-ID
X-Ua-Device
X-Hl-Ver
X-App-Version
X-Backend-Name
X-Servername
OT-Force-Account-Verify
X-ServerID
Cross-Origin-Opener-Policy
X-FireWall-Port
X-B3-Traceid
X-Tumblr-Pixel-3
X-ATG-Version
X-Detected-As
X-Azure-Ref-OriginShield
Cross-Origin-Window-Policy
X-Ua
Web-Mar-Node
X-Datadome
X-Cache-PHP
X-Generation-Time
X-Varnish-Cache-Hits
X-Cache-Host
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Trace-Id
Backend
X-Content-Age
X-TT-LOGID
X-Varnish-Hits
Content-Secure-Policy
Ec-Rule-Version
X-Via-JSL
Source
X-MP-GENERATED-AT
X-SRV
X-CSRF-Token
X-WA-Info
Xserver
X-Air-Trace-Id
X-Air-Hostname
X-Air-Source
X-Akamai-Transformed
X-CS
X-Cdn
X-Ratelimit-Limit
X-Cache-Grace
X-Microcachable
X-Soup
Upgrade-Insecure-Requests
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Cache-Enabled
X-Mode
X-Edge-Location
X-Amzn-Remapped-Content-Length
X-Bc-Bl
X-Rule
X-NWS-UUID-VERIFY
Url
X-Locale
X-Ratelimit-Remaining
X-Forwarded-Host
X-Info
X-Origin-TTL
X-Unique-Id
X-Origin-CC
X-Ua-Browser
X-Content
S-Rt
AMP-Access-Control-Allow-Source-Origin
X-Site-Version
SID
X-GEO
X-Varnish-Beresp-Status
Content-Disposition
X-Dc
X-Tb
X-Varnish-Beresp-Ttl
X-Magnolia-Registration
Fastly-SWR
Fastcgi-X-Cache-Version
X-Orig-Expires
CDN-Uid
Fastly-SIE
DCR-Decision-By
CDN-RequestId
Expiry
Apple-News-Services-Handled
X-NU-AKA-ACS-Version
Apple-News-Services-Host
A
X-PAYTM-SRV-ID
X-Platform-Server
X-PBS-Appsvrname
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
CDN-EdgeStorageId
CDN-PullZone
CDN-CachedAt
CDN-Cache
BehaviorPad-Version
CDCHOST
CDN-RequestCountryCode
Rendered-Blocks
X-Cache-NE
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Conf
X-Cache-Bucket
X-BCube-Filmed-By
X-ARC
X-B-Cookie
X-BBC-Edge-Cache-Status
X-Connection-Hash
X-D
X-Extlb
X-Forwarded-Path
X-From
X-Ftr-Request-Id
X-External-Request-Id
X-Epic-Correlation-Id
X-Debug-Cache
X-Destination
X-Developer
X-Application
X-AIR-PT
Path
X-Processor
Req-Svc-Chain
State
Odigeo-Trace-Id
Mobile-Detection-Method
X-NAPM-TraceId
MD5-Digest
Meta-Geo-Continent
Surrogated-Key
T-Server
X-A-Wwc
X-Aed
X-Aicache-OS
X-A-Dgt
X-A-Dcw
X-A
X-A-Ccd
X-A-Dam
Host-ID
DCR-Processing-Time-Ms
X-S
X-S-Cookie
X-Vdms-Version
X-VG-WebCache
User-Cache-Control
X-Routing-Service
X-Request-URI
X-Rewrite-Enabled
X-Rojux
X-ScT
X-VG-WebServer
X-Storage
X-Tenant
X-SRCache-Key
X-Shop-Environment
X-Session-Fingerprint
X-Cached-By
X-Vtex-Processado-Em
X-Zipkin-Id
X-Rebelmouse-Surrogate-Control
X-Vtex-Remote-Cache
X-Rebelmouse-Cache-Control
X-Proxied
X-Ratelimit-Reset
X-EC-Lua
X-Loc
X-LI-UUID
X-Li-Pop
X-Cache-NGX
UCS
X-Worker
Adler-Geo
Platform
M-TraceId
L
Is-Eu
X-VServer
X-Men
X-Fastly-Cache
Origin
NGX
X-Li-Fabric
X-JWT-State
X-Cache-Debug
X-SVT-ORM-RULES
X-Backend-State
X-Cache-Info
X-Cms-Context
X-Date
X-Core-Value
X-SVT-ORM-VERSION
X-DPWN-IS-SECURE
X-Envoy-Decorator-Operation
X-Varnish-Ttl
X-Service
X-Proxy-Upstream
X-TrackingId
X-Is-Gdpr
X-Accel-Expires-Debug
X-Has-Esi
X-Fastly-Backend
Cmstype
Fastly-Backend-Name
X-Request-UUID
Cache-Key
X-Origin-Expires
Cache-Host
X-VG-TLSProxy
Cmsid
X-Variation
X-M-Log
X-M-Reqid
X-NCache
X-Geo-Header
Vix-Hermes-Req-Id
X-Thanos
X-Thinkindot-L3
X-Hash
X-RateLimit-Limit-Second
X-Origin
X-Nginx-Cache-Key
X-Auto-Login
X-Rocket-Build-Number
X-Var-Ttl
X-Served-From
VNS-Cache
X-Esi-Check
X-Varnish-CookieHashed-On
X-Qnm-Cache
X-Hnp-Log
X-Scheme
X-HN
X-VC-Cache
X-Bip
X-Req
X-Cluster
X-Clientip
X-Sigma
X-VarnishDD-TTL
X-DefHash
X-Sigma-Backend
X-Varnish-Remaining-TTL
X-SIPLIST1
X-Ckpd-Fst-Backend
X-Slack-Backend
X-Device-Os
X-Branch-Name
X-Block-Status
X-Level-Front-Cache
X-Gamma-Serve
X-Cache-Id
X-Cache-Tags
X-Developers
Arc-Version
C-Via
VNS-Age
Cf-Device-Type
X-Location
Esi-Enabled
X-Old-Content-Length
X-Wikidot-Backend
Server-Ext
Fastly-Drupal-HTML
X-Wikidot-Static-Cache
Pics-Label
PFcat
X-Viewer-Country
X-Via-NSCOPI
X-Micro-Cache
X-DefElseHash
Fastcgi-Cache-TTL
PB-RID
PB-PID
X-Generated-By
Server-Host
X-Forwarded-Site
Thinkindot-CacheControl-Type
Server-Hostname
TDXMobile
Thinkindot-Control
Location
X-Gen-Mode
IsBot
True-Client-Country-4JS
X-Gzip
Thinkindot-CacheControl
Locid
X-Varnish-CookieINHashed-On
X-Generated-On
X-RateLimit-Remaining-Second
Sever-Int
CPC-Cache
CPC-Age
X-Tx-Id
XServer
X-Platform
X-Amz-Meta-S3cmd-Attrs
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Fmm-Version
X-HS-Content-Campaign-Id
X-GoCache-CacheStatus
X-Eu-Site
X-GeoIP-City
X-Generated-In
X-GeoIP
X-FC-Vary-Parameters
X-Fetched-On
Server-Info
Gh-Request-Id
X-DC
DSUID
Ha-Gx-Prefs
HA-Ipaddr
Mail-Subject
X-Mvc-Supplant-Cachable
L5d-Success-Class
X-Vdms-Path
CacheControlHeader
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Policy
X-Planisys-CDN-Cache
X-DataDome
X-Request-Host
X-Owner
Memcached
NM-Fastcgi-Cache
X-Irp-Debug
Svr
Arc-Country
X-Skip-Cache
X-Sucuri-ID
X-Clara-WADP
X-CGP
AKAMAI
Wxu-Next-Region
Release
X-WADP-Cache
Pagetype
V-Age
We-Hiring
Wxu-Next-Hostname
Wxu-Next-Commit
X-Csrf-Jwt
Webserver
DataCenter
NtCoent-Length
X-Platform-Processor
X-Platform-Router
X-Render-Time
X-Qloud-Router
X-V-Cache
X-Rocket-Nginx-Serving-Static
X-LSADC-Cache
X-Platform-Cluster
X-Unique-ID
X-SD-PageType
Kp-EeAlive
Cache-Hits
X-Via-Popv
X-Via-Poph
X-Via-Popn
X-Mvc-Supplant-OutputCached
X-CACHE-KEY
X-Cache-Remote
Environment
X-Cache-Var
X-Servedbyhost
MIME-Version
X-Cache-Var-Map
X-Srv
X-Origin-Time
X-User
X-Datadog-Trace-Id
X-Nyt-Route
X-Gdpr
X-API-Version
X-PJAX-URL
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-NodeID
X-ID
X-Zone
X-NC
Who
X-Via-Ucdn
X-Vc
X-PF-Uncompressing
X-BBC-Origin-Response-Status
WebServer
X-Minions-Version
X-Wa
X-Varnish-Url
Candidate-Md5Url
Cluster
X-Server-IP
X-Traceid
X-Pod-Name
X-Cache-Config
X-TIME
HostName
X-Internal-Host
Time
X-App
X-LB-ID
Memory
X-Webkit-Csp
Server-ID
X-Refresh
X-ZONE
Powered-By-ChinaCache
X-VCL-Version
X-Webkit-CSP-Report-Only
My-App
X-Pass-Why
Geoip-Latitude
Web-Mar-Region
X-NewRelic-App-Data
N-Cache
GeoIp-Country-Code
Onion-Location
X-Newrelic-Synthetics
X-Cache-Ttl
X-Dynatrace
X-Esi
X-Edge-Pop
Datacenter
Resin-Trace
X-CLOUD-TRACE-CONTEXT
X-ElasticPress-Query
X-LI-Proto
Geo-Info
X-TX-ID
X-Tb-Optimization-Total-Bytes-Saved
X-VHOST
X-TraceId
X-Akamai-Pragma-Client-IP
X-OVcl
Servername
X-OVcl-Cache
X-Varnish-Cacheable
Tcn
CDN
Ohc-File-Size
X-Origin-Response-Time
X-CACHE-AGE
X-HITS
Cf-Bgj
WWW-Authenticate
Hostname
X-Backend-TTL
X-Tt-Logid
X-Varnish-Beresp-TTL
X-Geo
X-Li-Proto
Magicmarker
X-EIG-Tracking-Id
X-Fpc
X-NODE
X-TIM-N
Redirect-Candidate
X-Tid
LB
X-AB
X-Correlation-ID
X-Dynatrace-Js-Agent
X-Method
Proxy-Connection
X-Wix-Viewer-Type
Tracecode
X-Up
X-Dispatcher-Server
Cdn
X-HostName
Is-Us
X-Fastly-Request-Id
GeoIP-Country-Code
X-Vcl-Version
Pramga
X-Cs
X-Request-Start
X-Cache-Date
X-MSEdge-Features
X-MSEdge-Flight
Cf-Ipcountry
X-APP
X-NGINX-Cache
X-IP
Lb
Ssr
GeoIP-Latitude
Server-Id
X-Sn-Servicetimems
DB-Nickname
X-Cdn-Origin
X-Fastly-Backend-Reqs
X-Amz-Meta-Cb-Modifiedtime
CF-Cached-On
X-CSRF-TOKEN
X-Core-Mission
Sid
X-HS-Status
W
X-Provided-By
X-COUNTRY
X-WA
X-MG-S
X-UnsetCookies
X-ServerName
CloudFront-Viewer-Country
X-Node-Id
X-Reqid
X-Lb-Id
X-Webkit-Csp-Report-Only
X-Cache-Expires
Cteonnt-Length
X-FORWARDED-FOR
X-Nc
X-Trv-Group
URI
X-DynaTrace-JS-Agent
X-Check-Cacheable
X-ND-Cache
WP-Super-Cache
X-VC
Ohc-Cache-HIT
CountryCode
X-CCDN-CacheTTL
X-Via-CDN
X-Pjax-Url
X-CCDN-Origin-Time
X-SERVER-NAME
X-Cache-Status-Check
X-Hcs-Proxy-Type
X-Region-Sid
Env
WZWS-RAY
X-Sucuri-Cache
X-Cache-Backend
X-Via-PopH
Mime-Version
X-Via-PopN
X-Via-PopV
X-ServedByHost
X-ECache
Shield-Pop
X-SN
X-CUA
X-Moov-Xdn-Version
Xc-Version
X-Pf-Uncompressing
X-Pad
X-Moov-T
X-Cdn-Forward
X-Acquia-Application-Trace
X-Ig-Push-State
X-Varnish-Authentication
X-Acquia-Application-UUID
CACHE
X-Acquia-Site
X-Acquia-Purge-Tags
User-Agent
X-LiteSpeed-Cache-Control
X-IN-APIGATEWAY
X-RAMCache
X-Edge-POP
X-IN-APIGATEWAYSSL
EpKe-Alive
X-Fastly-Cache-Hits
X-Contensis-Viewer-Groups
X-Cache-ASPX
Srv
X-Amz-Meta-Opti
FSS-Cache
X-Cdn-Request-ID
VivaBuild
Ohc-Response-Time
X-Dw-Trace-Id
ServerName
X-Action
X-DB
Viewtype
Server-Ttl
X-Swift-Error
X-SB
X-Webstats-RespID
Rt-Fastcgi-Cache
X-DI
Vha6-Origin
X-RPS
X-RSL
Xet-Cookie
X-RPM
X-StackifyID
X-DSS
X-DW
X-FPC
X-Nginx-Upstream-Cache-Status
X-Dispatch
PICS-Label
X-Oss-Hash-Crc64ecma
X-Parent-Response-Time
On-Server
X-Oss-Request-Id
X-Oss-Storage-Class
X-Oss-Server-Time
X-Oss-Object-Type
X-CF-Powered-By
X-Yottaa-OS
Req-ID
Content-Style-Type
Content-Script-Type
X-MiniProfiler-Ids
X-ElasticPress-Search
Fastly-Drupal-Html
X-TH-Server
Hit
HIT