Threat Level: green Handler on Duty: Russ McRee

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-RAY
CF-Cache-Status
Accept-Ranges
Link
ETag
Pragma
Expect-CT
X-Powered-By
X-XSS-Protection
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
Alt-Svc
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-Request-ID
X-Cache-Status
X-Generator
X-Cacheable
X-DNS-Prefetch-Control
Timing-Allow-Origin
P3p
X-Content-Security-Policy
X-Iinfo
Status
X-Ua-Compatible
Feature-Policy
Content-Encoding
X-AspNetMvc-Version
X-CDN
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
Upgrade
Access-Control-Max-Age
X-Drupal-Dynamic-Cache
X-Via
X-Dns-Prefetch-Control
Keep-Alive
X-Ws-Request-Id
Request-Context
Server-Timing
X-Robots-Tag
X-AH-Environment
X-Hacker
X-Server
X-Age
X-Turbo-Charged-By
X-Proxy-Cache
X-Cache-Group
X-Server-Powered-By
X-Backend
X-Amz-Request-Id
Host-Header
X-Amz-Id-2
EagleId
X-Nginx-Cache-Status
Report-To
X-LiteSpeed-Cache
X-Rq
X-Varnish-Cache
X-UA-Device
Grace
X-Page-Speed
X-Pingback
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
EagleEye-TraceId
X-Device
X-Vhost
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
NEL
X-Amz-Version-Id
X-OneAgent-JS-Injection
X-Dispatcher
Cf-Railgun
X-Host
X-Cache-Spec
X-CST
X-Server-Id
X-Node
X-Backend-Server
X-WebKit-CSP
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Allow
Request-Id
Surrogate-Control
X-Readtime
X-Akam-SW-Version
Accept-CH
Accept-Ch-Lifetime
X-Response-Time
Xkey
X-Webkit-CSP
X-HW
X-Language
X-Ruxit-JS-Agent
X-Application-Context
X-Country
X-Template
X-Ac
Content-Location
X-Cloud-Trace-Context
X-Cache-Lookup
Rating
MS-Author-Via
X-Url
X-B3-TraceId
Edge-Control
X-TtlSet
X-PC
X-Vname
X-Mod-Pagespeed
X-Clacks-Overhead
X-Varnish-TTL
X-Trace
Accept-Ch
X-Content-Type
Fastly-Restarts
X-MS-InvokeApp
X-Rack-Cache
X-ESI
X-Origin-Cache
X-GitHub-Request-Id
X-Buckets
X-Cnection
X-Country-Code
X-Goog-Hash
Verso
X-D2id
X-VARITI-CCR
X-Server-ID
X-Kinja
X-Kinja-Revision
X-Kinja-Server
X-Exp-Id
X-Cdn-Fetch
X-Use-Magma
X-Exp-Variant
X-Kinja-Build
X-GoogleNews-Bot
X-FastCGI-Cache
Arr-Disable-Session-Affinity
X-ORACLE-DMS-ECID
X-Vcap-Request-Id
Cache-Tag
X-Cached
Service-Worker-Allowed
X-Abt-Application-Version
X-Server-Name
X-Amz-Rid
X-Client-IP
X-Navigation-Version
X-Px
Accept-CH-Lifetime
X-Powered-By-Plesk
RTSS
X-Fastly-Request-ID
Public-Key-Pins
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Access-Control-Request-Method
X-MSEdge-Ref
X-Element-Page-Cache
X-Cache-TTL
X-Powered-CMS
X-Dw-Request-Base-Id
X-NF-Request-ID
X-Upstream
X-Version
Display
X-Sol
X-Middleton-Response
Pagespeed
Response
X-Middleton-Display
X-TTL
S
X-Edge-Location-Klb
X-Kinsta-Cache
X-Edge
X-LLID
X-Ttl
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Instrumentation
X-Server-Lifecycle-Phase
X-Kraken-Routeconfig-Destination
X-Kraken-Loop-Name
X-ECACHE
X-Cache-Key
X-Accel-Expires
Realpath
X-HP-Webp
X-Jurisdiction
X-Correlation-Id
X-Shield-Request-Id
X-XRDS-Location
Pinterest-Generated-By
X-Pinterest-Rid
Pinterest-Version
X-T
SPRequestGuid
X-SharePointHealthScore
X-Mid
X-MCACHE
X-DynaTrace
SPRequestDuration
X-ORACLE-DMS-RID
X-PressLabs-Stats
SPIisLatency
X-Content-Security-Policy-Report-Only
Edge-Cache-Tag
X-Litespeed-Cache
Fastcgi-Cache
X-Forwarded-Proto
X-Amz-Server-Side-Encryption
X-Content-Digest
Nginx-Cache
TP-L2-Cache
TP-Cache
X-Recruiting
X-Mg-S
Charset
X-Id
X-Request-Received
X-Request-Processing-Time
TCN
Front-End-Https
Filters
Alternate-Protocol
Server-Node
X-Logged-In
X-Oneagent-Js-Injection
X-Forwarded-For
X-Ezoic-Cdn
X-Geo-Country
Content-MD5
Cache-Tags
Fusion-Content-Id
X-Protected-By
Fusion-Template-Id
Fusion-Source
Fusion-Deployment-Id
Fusion-Content-Source
Fusion-Component-Id
X-Hostname
X-ASPNET-VERSION
X-Amzn-Trace-Id
X-Grace
X-Origin-Upstream-Status
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
X-Goog-Storage-Class
X-F-Cache
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Www-Served-By
X-NWS-LOG-UUID
Cleartype
X-Origin-Server
X-Debug-Info
X-Amz-Replication-Status
X-Rid
X-HS-Cache-Config
X-Ruxit-Js-Agent
Host
X-HS-Content-Id
X-LB-Cache
X-HS-Hub-Id
X-AppVersion
X-Az
X-Activity-Id
X-HS-Combine-CSS
X-Contextid
X-Release
X-RateLimit-Remaining
Section-Io-Cache
X-Daa-Tunnel
X-Page-Id
Server-Name
X-Git-Hash
X-Erf-Bev-Bev
X-Frontend
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-VCache
X-Ser
X-Cache-Age
MicrosoftSharePointTeamServices
X-Respond-Thread
X-Content-Options
X-Ab
Access-Control-Allow-Method
Accept-Charset
X-Aspnetmvc-Version
X-Hits
X-Upgrade-Enabled
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Mobile-URL
X-DIS-Request-ID
ServerID
X-Request-Guid
X-Flags
X-Source
X-Aspnet-Duration-Ms
X-B-Cache
X-Is-Crawler
X-Providence-Cookie
X-Route-Name
X-Signature
X-Cache-Action
X-Varnish-Age
X-FB-Debug
Healthy
X-Varnish-Backend
X-Whom
Viewport
Paypal-Debug-Id
X-Varnish-Grace
X-TT
Payment
X-AOL-HN
X-CACHE-GROUP
Node
Fastcgi-Useragent
X-App-Environment
X-WebKit-CSP-Report-Only
X-B3-Sampled
DynaTrace
X-Yandex-Sdch-Disable
X-Load-Cache
X-Mobile
Version
X-Fastcgi-Cache
X-Seen-By
DC
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-N
Filterid
X-Type
X-HTML-Minification-Powered-By
X-Distributor
SRV
Retry-After
X-Cache-Control
Frame-Options
X-User-Agent
X-Tec-Api-Version
MS-CV
X-Tec-Api-Origin
X-Tec-Api-Root
X-Jobs
X-Cache-Expired-At
Refresh
Amp-Access-Control-Allow-Source-Origin
X-Original-Request-Id
X-Response-Served-From
X-UUID
X-Page-View
X-Proxy-Cache-Status
X-FW-Static
X-FW-Serve
X-FW-Hash
X-FW-Dynamic
X-FW-Server
X-Adobe-Loc
NGB
X-FW-Type
X-Adobe-Content
X-Varnish-Server
X-Debug-IsConnected
X-Debug-IsPreview
X-Instance
X-Real-IP
X-Region
X-IPLB-Instance
X-Cacheable-TTL
X-Cluster-Name
X-B
X-XRDS-LOCATION
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-ProcessESI
X-Proxy
X-Tumblr-Pixel-1
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-RemovedCookies
Access-Control-Request-Headers
X-G
X-CDN-Forward
X-Content-Powered-By
X-Device-Type
X-Framework
X-NGENIX-Cache
X-Cache-Time
X-Vgn-Hpd-Reason
Ms-Operation-Id
X-RTag
X-Azure-Ref
X-Node-Name
X-IPS-LoggedIn
X-Zen-Fury
Uber-Trace-Id
X-Cache-Hit
X-Cache-Rule
X-HP-Trace-Id
AR-Request-ID
Ar-Sid
Cache-Status
AR-PoweredBy
X-Wix-Request-Id
AR-CACHE
AR-ATIME
Section-Origin-Responded
Countrycode
SD-X-WS
Liferay-Portal
X-Is-Bot
Section-Io-Origin-Status
X-Time
Section-Io-Id
Section-Io-Origin-Time-Seconds
X-Rendered-As
X-Ms-Version
X-Ms-Request-Id
X-Aws-Lambda-Call-Status
X-RateLimit-Limit
Referer-Policy
X-Drupal-Cache-Tags
X-Microsite
X-Request-Handler-Origin-Region
X-Mg-Request-UUID
X-Debug
X-Nginx-Cache
X-Oracle-Dms-Rid
X-Accel-Buffering
X-Parallel-Accel
X-EdgeConnect-Cache-Status
S-Cnection
CF-IPCountry
X-App-Version
X-Revision
X-L-Path
Country
X-Environment-Context
X-App-Server
Cache
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Cache-Operation
X-TA-CDN-Provider
Surrogate-Key
X-Drupal-Cache-Contexts
Count-Hit
X-SaId
X-TNCMS
X-Loop
X-UPSTREAM-Address
X-JoinUs
X-ES-SERVER
X-RN-RSRV
X-GG-Cache-Date
Meta-Geo
X-Endurance-Cache-Level
X-Say-TTL
X-Xfnlog-Site
X-FW-Version
X-Adobe-Source
From-Origin
X-Cache-TTL-Remaining
X-LAGOON
X-Say-Cacheable
Eomportal-Instance
X-Cache-Type
X-SayCDN-TTL
X-FireWall-Port
GEO-INFO
X-Sorting-Hat-ShopId
X-Shopify-Stage
X-Request-Time
Protected
X-Alternate-Cache-Key
X-Human
X-Sorting-Hat-PodId
X-S-Maxage
X-ShopId
X-NYM-Debug-Backend
Akamai-GRN
X-Sql-Count
X-Sql-Duration-Ms
X-Varnish-Beresp-Grace
X-ShardId
X-Storefront-Renderer-Rendered
Cache-Name
Decoy-Debug-Status
Fastly-SSL
X-Be
Azure-SiteName
Azure-SlotName
Azure-Version
Cache-Tv-Group
Country-Code
Decoy-Debug-TTL
Apigw-Requestid
ServedBy
Decoy-Debug-Key
X-AWS-Id
Azure-InstanceId
Azure-RegionName
X-Pubstack
X-PCL
X-Varnish-Hostname
X-ProxyCache-Status
X-ProxyCache-Key
X-RCS-CacheZone
X-BYPASS-REASON
X-OCL
X-No-Session
X-VWS-Id
X-R9-Blue-Green-Version
X-LJ-Flow-ID
X-Varnishpool
X-Hosted-By
X-Origin-Date
X-Proto
X-PHP-Host
X-Labrador-Cache-Channel
X-Handled-By
Property-Id
X-Origin-Hint
X-Via-Fastly
Selected-Fe
X-Proxy-Build
X-Redis-Cache
X-Section
X-PHP-Backend
X-Server-W
X-Web-Node
TWC-Locale-Group
X-Status
X-Access
Webcakes-Region
X-Akamai-Edgescape
X-Hyper-Cache
X-Cache-Server
X-Format
Webcakes-App-Version
Webcakes-App-Name
X-UA-Device-Type
X-Uri
TWC-Device-Class
X-Tumblr-Pixel-2
TWC-GeoIP-LatLong
TWC-Privacy
X-Timing-Wait
TWC-Connection-Speed
TWC-GeoIP-Country
X-ApacheServer
X-PERF
Mn-Server-Ip
X-Backend-Host
X-B3-SpanId
X-FB-TRIP-ID
X-Cluster-Node
X-Backend-Name
X-Hl-Ver
Nel
X-Time-Microsecs
X-APP-VERSION
X-Servername
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
OT-Force-Account-Verify
X-ServerID
X-ATG-Version
X-Ua-Device
Cross-Origin-Opener-Policy
X-Tumblr-Pixel-3
X-Detected-As
X-Cache-PHP
X-Azure-Ref-OriginShield
Xserver
X-TT-LOGID
X-Content-Age
Web-Mar-Node
X-Trace-Id
Backend
X-Varnish-Cache-Hits
X-Generation-Time
X-Cache-Host
X-CSRF-Token
X-WA-Info
Cross-Origin-Window-Policy
X-MP-GENERATED-AT
X-CS
X-Ua
Content-Secure-Policy
X-Varnish-Hits
X-Datadome
Ec-Rule-Version
X-Soup
X-Akamai-Transformed
X-Via-JSL
X-SRV
X-Rule
X-Bc-Bl
X-Cache-Enabled
X-Edge-Location
X-Amzn-Remapped-Content-Length
X-Info
X-Amz-Apigw-Id
X-Cache-Grace
Source
X-Origin-TTL
X-Origin-CC
X-Amzn-RequestId
X-Cdn
X-Mode
X-Cached-By
X-Microcachable
X-Varnish-Beresp-Ttl
Upgrade-Insecure-Requests
X-NWS-UUID-VERIFY
X-Locale
Url
X-Forwarded-Host
X-Varnish-Beresp-Status
X-Air-Source
S-Rt
X-GEO
SID
X-Air-Trace-Id
X-Air-Hostname
X-DataDome
X-Site-Version
X-Storage
X-B3-Traceid
X-Magnolia-Registration
X-DC
X-Debug-Cache
Content-Disposition
X-ARC
X-B-Cookie
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Cache-NE
X-Cache-Bucket
X-BCube-Filmed-By
Apple-News-Services-Handled
CDN-RequestId
CDN-Uid
Path
Odigeo-Trace-Id
CDN-RequestCountryCode
CDN-PullZone
CDN-Cache
CDN-CachedAt
CDN-EdgeStorageId
Mobile-Detection-Method
DCR-Decision-By
Fastcgi-X-Cache-Version
Host-ID
Fastly-SIE
Expiry
M-TraceId
DCR-Processing-Time-Ms
Meta-Geo-Continent
MD5-Digest
CDCHOST
Rendered-Blocks
X-A-Dcw
X-A-Dam
A
X-A-Ccd
X-A-Dgt
X-A-Wwc
X-AIR-PT
X-Aicache-OS
X-Aed
X-A
X-Conf
Surrogated-Key
State
Req-Svc-Chain
BehaviorPad-Version
T-Server
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
X-Application
X-Extlb
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Request-URI
X-Rewrite-Enabled
X-Routing-Service
X-Rojux
X-Ratelimit-Reset
X-Processor
X-Orig-Expires
X-NU-AKA-ACS-Version
X-PAYTM-SRV-ID
X-PBS-Appsvrname
X-Platform-Server
X-S
X-S-Cookie
X-VG-WebServer
X-VG-WebCache
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
X-Zipkin-Id
X-Vdms-Version
X-Cache-NGX
X-Session-Fingerprint
X-ScT
X-Shop-Environment
X-SRCache-Key
X-Tenant
X-NAPM-TraceId
X-Proxied
X-Connection-Hash
X-Forwarded-Path
X-From
X-Ftr-Request-Id
X-D
Fastly-SWR
X-Developer
X-Destination
X-Epic-Correlation-Id
X-External-Request-Id
User-Cache-Control
X-Tb
X-EC-Lua
X-Ratelimit-Limit
X-Date
Is-Eu
X-WADP-Cache
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-BBC-Edge-Cache-Status
X-Clientip
L
X-Clara-WADP
NGX
X-VServer
X-Core-Value
X-Variation
Origin
Pics-Label
X-TrackingId
X-VG-TLSProxy
X-Envoy-Decorator-Operation
X-Origin-Expires
X-Is-Gdpr
X-Has-Esi
X-Backend-State
X-Accel-Expires-Debug
X-JWT-State
X-Loc
X-Men
X-Li-Pop
X-Li-Fabric
X-Cms-Context
X-Proxy-Upstream
X-Cache-Info
X-LI-UUID
X-Service
Platform
UCS
X-Fastly-Backend
X-Fmm-Version
X-Fastly-Cache
X-Request-UUID
X-DPWN-IS-SECURE
X-Cache-Debug
Fastly-Backend-Name
Cmsid
Cmstype
X-Unique-Id
Fastly-Drupal-HTML
Cache-Host
Adler-Geo
Cache-Key
X-Cache-Ttl
X-Geo-Header
X-Gzip
X-GoCache-CacheStatus
X-Hnp-Log
X-Location
X-Level-Front-Cache
X-Generated-On
X-HN
X-Hash
X-Gamma-Serve
X-Cache-Tags
X-Cluster
X-Cache-Id
X-Branch-Name
X-Bip
X-Block-Status
X-DefElseHash
X-DefHash
X-Micro-Cache
X-Gen-Mode
X-Forwarded-Site
X-Esi-Check
X-Developers
X-Device-Os
X-Generated-By
X-RateLimit-Limit-Second
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Varnish-CookieHashed-On
X-Unique-ID
X-Thinkindot-L3
X-Var-Ttl
X-VarnishDD-TTL
X-VC-Cache
X-Wikidot-Backend
X-Wikidot-Static-Cache
Server-Info
X-Viewer-Country
X-Via-NSCOPI
X-Thanos
X-Dc
X-Req
X-Request-Host
X-RateLimit-Remaining-Second
VNS-Cache
X-Old-Content-Length
X-Origin
X-Rocket-Build-Number
X-Scheme
X-SIPLIST1
X-Slack-Backend
X-Sigma-Backend
X-Sigma
X-Served-From
X-Nginx-Cache-Key
X-Platform
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Vix-Hermes-Req-Id
IsBot
Cf-Device-Type
PB-RID
Server-Hostname
Thinkindot-Control
Locid
True-Client-Country-4JS
Server-Ext
PFcat
Server-Host
Sever-Int
PB-PID
C-Via
Location
Fastcgi-Cache-TTL
VNS-Age
TDXMobile
Esi-Enabled
CPC-Age
Arc-Version
CPC-Cache
DSUID
X-Ratelimit-Remaining
AMP-Access-Control-Allow-Source-Origin
X-Amz-Meta-S3cmd-Attrs
X-Worker
Release
X-Fetched-On
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Ckpd-Fst-Backend
X-Generated-In
X-GeoIP-City
X-GeoIP
Svr
X-Owner
X-Skip-Cache
NM-Fastcgi-Cache
Pagetype
X-Ua-Browser
Memcached
X-Sucuri-ID
L5d-Success-Class
We-Hiring
Mail-Subject
X-Content
X-Policy
Ha-Gx-Prefs
CacheControlHeader
X-Mvc-Supplant-Cachable
HA-Ipaddr
X-FC-Vary-Parameters
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
Gh-Request-Id
X-Irp-Debug
Wxu-Next-Region
X-Tx-Id
Wxu-Next-Hostname
Arc-Country
AKAMAI
V-Age
X-CGP
X-Eu-Site
X-Csrf-Jwt
Wxu-Next-Commit
Webserver
X-Auto-Login
X-Qloud-Router
X-M-Reqid
X-M-Log
NtCoent-Length
Kp-EeAlive
X-NCache
X-Vdms-Path
X-Qnm-Cache
DataCenter
Cache-Hits
X-Via-Poph
X-Servedbyhost
X-Via-Popn
MIME-Version
X-V-Cache
X-HS-Content-Campaign-Id
X-Via-Popv
XServer
X-Srv
X-Platform-Processor
X-Render-Time
X-Mvc-Supplant-OutputCached
X-LSADC-Cache
X-Platform-Cluster
X-Platform-Router
Who
X-Rocket-Nginx-Serving-Static
X-User
X-NC
X-Zone
X-Traceid
X-SD-PageType
X-PF-Uncompressing
X-Cache-Remote
Environment
X-Varnish-Url
X-Vc
X-Wa
X-Minions-Version
X-Cache-Var
X-Cache-Var-Map
X-ID
X-Webkit-CSP-Report-Only
X-Refresh
X-App
X-Origin-Time
X-Nyt-Route
X-Gdpr
X-Datadog-Trace-Id
X-BBC-Origin-Response-Status
X-PJAX-URL
X-NodeID
X-LB-ID
Server-ID
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-API-Version
WebServer
X-Varnish-Ttl
X-VCL-Version
Time
My-App
X-Via-Ucdn
X-ZONE
Cluster
Memory
Powered-By-ChinaCache
X-TIME
X-Pass-Why
X-Webkit-Csp
X-Internal-Host
X-Pod-Name
X-Server-IP
X-Cache-Config
Candidate-Md5Url
X-Newrelic-Synthetics
X-CACHE-KEY
HostName
Datacenter
X-NewRelic-App-Data
X-LI-Proto
Resin-Trace
X-TX-ID
X-Esi
Web-Mar-Region
N-Cache
X-OVcl
Geoip-Latitude
X-CLOUD-TRACE-CONTEXT
X-OVcl-Cache
Onion-Location
Hostname
Geo-Info
X-ElasticPress-Query
Cf-Bgj
X-Edge-Pop
GeoIp-Country-Code
X-Tb-Optimization-Total-Bytes-Saved
X-VHOST
X-AB
X-Backend-TTL
Servername
Magicmarker
X-Akamai-Pragma-Client-IP
X-Origin-Response-Time
Ohc-File-Size
X-TraceId
Tcn
X-Dynatrace
X-CACHE-AGE
X-Varnish-Cacheable
X-HITS
X-EIG-Tracking-Id
GeoIP-Country-Code
X-Geo
X-Method
WWW-Authenticate
X-Dispatcher-Server
GeoIP-Latitude
X-NODE
DB-Nickname
LB
Cdn
X-Li-Proto
X-Varnish-Beresp-TTL
X-Fpc
CDN
X-Correlation-ID
Ssr
Proxy-Connection
X-Wix-Viewer-Type
X-IP
X-MSEdge-Features
X-Tt-Logid
X-TIM-N
Redirect-Candidate
X-Tid
X-MSEdge-Flight
X-Dynatrace-Js-Agent
X-MG-S
X-HostName
X-Fastly-Backend-Reqs
X-Up
Tracecode
CF-Cached-On
Cf-Ipcountry
X-Cache-Date
Pramga
Is-Us
X-Vcl-Version
X-Request-Start
Lb
X-Node-Id
X-Cs
X-Cdn-Origin
X-Trv-Group
Server-Id
Sid
X-COUNTRY
X-Sn-Servicetimems
X-APP
X-HS-Status
X-ND-Cache
X-Amz-Meta-Cb-Modifiedtime
X-Nc
X-DynaTrace-JS-Agent
WZWS-RAY
X-Via-CDN
X-NGINX-Cache
X-Reqid
W
Env
X-ServerName
X-Provided-By
X-Core-Mission
X-WA
X-Webkit-Csp-Report-Only
X-Pjax-Url
X-CSRF-TOKEN
Cteonnt-Length
X-FORWARDED-FOR
X-UnsetCookies
X-VC
X-Lb-Id
URI
X-Check-Cacheable
CloudFront-Viewer-Country
X-Cache-Expires
Ohc-Cache-HIT
X-SERVER-NAME
X-Fastly-Request-Id
X-Via-PopV
X-Via-PopH
X-IN-APIGATEWAY
X-Via-PopN
X-Cache-Backend
X-IN-APIGATEWAYSSL
X-Region-Sid
X-Sucuri-Cache
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
CountryCode
X-Cache-Status-Check
X-CCDN-Origin-Time
Shield-Pop
X-Pf-Uncompressing
WP-Super-Cache
Server-Ttl
Rt-Fastcgi-Cache
Viewtype
VivaBuild
X-SN
Mime-Version
X-ServedByHost
X-Acquia-Purge-Tags
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Acquia-Site
X-RAMCache
X-Moov-Xdn-Version
Xc-Version
X-Moov-T
X-LiteSpeed-Cache-Control
X-CUA
X-Edge-POP
CACHE
X-Fastly-Cache-Hits
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Varnish-Authentication
X-Pad
X-Cdn-Request-ID
Xet-Cookie
X-Action
X-Webstats-RespID
X-SB
X-DB
X-Swift-Error
X-Ig-Push-State
User-Agent
Ohc-Response-Time
EpKe-Alive
X-DSS
X-DI
Machine
Vha6-Origin
X-Dw-Trace-Id
X-Yottaa-OS
X-StackifyID
X-RSL
X-RPS
X-RPM
X-DW
X-Cdn-Forward
X-Amz-Meta-Opti
X-ElasticPress-Search
FSS-Cache
HIT
ServerName
X-MiniProfiler-Ids
Content-Style-Type
Content-Script-Type
X-TH-Server
Req-ID
X-CF-Powered-By