Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
Link
Pragma
ETag
X-XSS-Protection
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
Alt-Svc
X-UA-Compatible
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Xss-Protection
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Request-ID
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
P3p
X-FRAME-OPTIONS
X-Content-Security-Policy
X-Iinfo
Status
Content-Encoding
Feature-Policy
X-AspNetMvc-Version
X-CDN
X-Ua-Compatible
X-Envoy-Upstream-Service-Time
Upgrade
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Access-Control-Max-Age
X-Via
Keep-Alive
X-Dns-Prefetch-Control
Request-Context
X-Robots-Tag
Server-Timing
X-Ws-Request-Id
X-AH-Environment
X-Server
X-Hacker
X-Age
X-Turbo-Charged-By
X-Server-Powered-By
X-Proxy-Cache
X-Cache-Group
X-Backend
Host-Header
X-Amz-Request-Id
X-Nginx-Cache-Status
EagleId
X-Amz-Id-2
Report-To
X-LiteSpeed-Cache
X-Rq
X-UA-Device
X-Varnish-Cache
X-Page-Speed
Grace
X-Swift-SaveTime
X-Swift-CacheTime
X-Pingback
Ali-Swift-Global-Savetime
X-Device
EagleEye-TraceId
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Cf-Railgun
X-Vhost
X-Amz-Version-Id
NEL
X-Host
X-OneAgent-JS-Injection
X-Dispatcher
X-Server-Id
X-CST
X-Node
Allow
Surrogate-Control
X-Cache-Spec
Request-Id
X-Backend-Server
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-WebKit-CSP
X-Readtime
Accept-CH
X-Response-Time
X-Akam-SW-Version
X-Webkit-CSP
Xkey
X-HW
Accept-Ch-Lifetime
X-Country
X-Ac
Content-Location
X-Application-Context
X-Language
X-Ruxit-JS-Agent
MS-Author-Via
X-Template
X-Cloud-Trace-Context
Rating
X-Cache-Lookup
X-Url
X-Mod-Pagespeed
X-B3-TraceId
Edge-Control
X-PC
X-Vname
X-TtlSet
X-Clacks-Overhead
X-ESI
X-MS-InvokeApp
X-Trace
X-Varnish-TTL
X-GitHub-Request-Id
X-Content-Type
Fastly-Restarts
X-ASPNET-VERSION
X-Origin-Cache
X-Cnection
X-Rack-Cache
X-FastCGI-Cache
X-D2id
Accept-Ch
X-Kinja
X-Kinja-Build
X-Cdn-Fetch
X-GoogleNews-Bot
X-Exp-Variant
X-Use-Magma
X-Country-Code
X-Kinja-Revision
X-Exp-Id
X-Kinja-Server
Verso
Arr-Disable-Session-Affinity
X-Goog-Hash
X-VARITI-CCR
Accept-CH-Lifetime
X-Server-Name
X-Vcap-Request-Id
X-Cached
X-Navigation-Version
Cache-Tag
X-Buckets
X-Client-IP
X-Powered-By-Plesk
X-Amz-Rid
X-Abt-Application-Version
Service-Worker-Allowed
X-ORACLE-DMS-ECID
X-Fastly-Request-ID
RTSS
X-Cache-TTL
X-Sol
Access-Control-Request-Method
X-Middleton-Display
Display
X-Middleton-Response
Pagespeed
Response
X-MSEdge-Ref
X-Element-Page-Cache
X-Powered-CMS
X-Ttl
X-NF-Request-ID
Public-Key-Pins
X-Dw-Request-Base-Id
X-Server-ID
X-Upstream
X-Version
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Px
S
X-Edge
X-LLID
X-Kinsta-Cache
X-Edge-Location-Klb
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
Realpath
X-TTL
X-Oneagent-Js-Injection
X-Accel-Expires
SPIisLatency
SPRequestDuration
X-SharePointHealthScore
SPRequestGuid
X-ECACHE
X-Jurisdiction
X-HP-Webp
X-T
X-Mid
X-PressLabs-Stats
X-MCACHE
X-Forwarded-Proto
X-Content-Security-Policy-Report-Only
X-Instrumentation
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Kraken-Routeconfig-Destination
X-Shield-Request-Id
X-Correlation-Id
X-DynaTrace
X-Ruxit-Js-Agent
Charset
X-Recruiting
Edge-Cache-Tag
Pinterest-Generated-By
X-Pinterest-Rid
Pinterest-Version
X-Cache-Key
Fastcgi-Cache
TP-L2-Cache
TP-Cache
X-Amz-Server-Side-Encryption
X-Mg-S
X-Release
X-Content-Digest
X-Ezoic-Cdn
X-ORACLE-DMS-RID
Filters
X-Id
Nginx-Cache
X-Request-Processing-Time
X-Request-Received
TCN
X-Logged-In
Front-End-Https
Server-Node
Alternate-Protocol
Cache-Tags
X-Forwarded-For
X-XRDS-Location
Content-MD5
X-Litespeed-Cache
X-Origin-Upstream-Status
Fusion-Template-Id
Fusion-Deployment-Id
Fusion-Component-Id
Fusion-Content-Id
Fusion-Content-Source
Fusion-Source
X-Amzn-Trace-Id
Server-Name
X-Grace
X-Origin-Server
X-Geo-Country
X-Hostname
X-Protected-By
X-Contextid
X-F-Cache
X-RateLimit-Remaining
Cleartype
X-AppVersion
X-Activity-Id
X-Az
X-Rid
X-Www-Served-By
X-Goog-Storage-Class
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
X-Amz-Replication-Status
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Goog-Generation
X-HS-Cache-Config
Host
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Combine-CSS
X-Debug-Info
X-Frontend
X-WebKit-CSP-Report-Only
Section-Io-Cache
X-LB-Cache
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
MicrosoftSharePointTeamServices
X-Erf-Bev-Bev
X-NWS-LOG-UUID
X-Ser
X-Git-Hash
X-Aspnetmvc-Version
X-Page-Id
X-Cache-Age
AR-Request-ID
AR-PoweredBy
AR-ATIME
X-VCache
AR-CACHE
Accept-Charset
Ar-Sid
X-Upgrade-Enabled
X-Respond-Thread
X-Content-Options
X-Varnish-Age
X-Source
X-Hits
X-Mobile-URL
Paypal-Debug-Id
X-Tec-Api-Root
X-Tec-Api-Version
X-DIS-Request-ID
X-Daa-Tunnel
X-Varnish-Backend
X-Tec-Api-Origin
Access-Control-Allow-Method
X-Signature
X-B-Cache
X-CACHE-GROUP
ServerID
X-Kong-Upstream-Latency
X-Varnish-Grace
X-Kong-Proxy-Latency
Payment
X-Request-Guid
X-FB-Debug
X-Providence-Cookie
X-Is-Crawler
X-Flags
X-Cache-Action
Viewport
X-Route-Name
X-Aspnet-Duration-Ms
X-TT
Healthy
X-Whom
X-B3-Sampled
X-AOL-HN
Node
X-XRDS-LOCATION
X-App-Environment
X-N
X-Seen-By
Version
X-Request-Handler-Origin-Region
X-Microsite
X-Type
Fastcgi-Useragent
X-Mobile
DynaTrace
X-Load-Cache
DC
X-Fastcgi-Cache
MS-CV
X-Yandex-Sdch-Disable
X-HTML-Minification-Powered-By
X-Ab
X-Cache-Expired-At
X-Distributor
SRV
X-Cache-Control
Filterid
Retry-After
X-Tt-Trace-Host
X-Tt-Trace-Tag
Frame-Options
X-IPLB-Instance
X-User-Agent
X-Response-Served-From
X-Original-Request-Id
X-UUID
X-Instance
X-Varnish-Server
X-IPS-LoggedIn
X-Jobs
X-Real-IP
Nel
X-RTag
X-Device-Type
X-Adobe-Content
X-Adobe-Loc
X-Proxy-Cache-Status
X-Cluster-Name
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Tumblr-User
X-Tumblr-Pixel
Access-Control-Request-Headers
Ms-Operation-Id
X-B
NGB
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Page-View
X-Region
X-RemovedCookies
X-Cacheable-TTL
X-Cache-Time
X-Debug-IsConnected
X-Debug-IsPreview
X-Content-Powered-By
X-ProcessESI
Uber-Trace-Id
X-Framework
X-Proxy
Refresh
X-G
X-FireWall-Port
X-Debug
X-Accel-Buffering
Cache
X-FW-Type
X-FW-Serve
X-RateLimit-Limit
X-FW-Server
X-Zen-Fury
X-FW-Hash
X-Vgn-Hpd-Reason
X-FW-Static
X-FW-Dynamic
Section-Io-Id
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
X-Wix-Request-Id
Countrycode
X-App-Version
X-Time
X-Oracle-Dms-Rid
X-NGENIX-Cache
X-Mg-Request-UUID
X-CDN-Forward
X-Nginx-Cache
Cache-Status
X-Azure-Ref
Surrogate-Key
X-Is-Bot
X-Rendered-As
X-Cache-Hit
X-Ms-Request-Id
X-Ms-Version
Country
X-Drupal-Cache-Tags
X-Cache-Rule
X-EdgeConnect-Cache-Status
S-Cnection
X-Node-Name
X-App-Server
Eomportal-Instance
SD-X-WS
Liferay-Portal
Amp-Access-Control-Allow-Source-Origin
Referer-Policy
X-TA-CDN-Provider
X-Environment-Context
X-L-Path
X-Cache-Operation
X-UPSTREAM-Address
X-ES-SERVER
From-Origin
X-RN-RSRV
X-Proxy-Build
X-SaId
X-JoinUs
X-Yottaa-Metrics
X-Timing-Wait
Selected-Fe
X-Drupal-Cache-Contexts
Meta-Geo
X-Yottaa-Optimizations
X-ShardId
X-Sorting-Hat-ShopId
X-ShopId
X-Shopify-Stage
X-Sorting-Hat-PodId
X-R9-Blue-Green-Version
X-Request-Time
X-Backend-Host
Protected
X-Endurance-Cache-Level
X-Alternate-Cache-Key
X-Cache-TTL-Remaining
X-Pubstack
ServedBy
X-Handled-By
X-Tumblr-Pixel-2
X-Storefront-Renderer-Rendered
X-Varnishpool
X-GG-Cache-Date
X-TNCMS
CF-IPCountry
X-Varnish-Beresp-Grace
X-Loop
X-Xfnlog-Site
X-PCL
Property-Id
Fastly-SSL
X-Proto
X-VWS-Id
TWC-GeoIP-Country
TWC-Device-Class
X-PHP-Backend
X-Varnish-Hostname
X-S-Maxage
Azure-RegionName
Azure-InstanceId
X-OCL
X-No-Session
Azure-SiteName
Cache-Tv-Group
Azure-Version
Azure-SlotName
TWC-GeoIP-LatLong
TWC-Connection-Speed
X-LJ-Flow-ID
X-NYM-Debug-Backend
X-AWS-Id
TWC-Locale-Group
X-Be
X-Origin-Hint
X-BYPASS-REASON
X-Human
X-Cache-Server
X-ProxyCache-Key
X-LAGOON
Webcakes-App-Version
Webcakes-App-Name
TWC-Privacy
X-Server-W
Webcakes-Region
X-ProxyCache-Status
X-Adobe-Source
Decoy-Debug-TTL
Apigw-Requestid
X-Access
X-Origin-Date
X-Backend-Name
Country-Code
X-RCS-CacheZone
Cache-Name
Decoy-Debug-Status
Decoy-Debug-Key
Akamai-GRN
X-Format
X-Say-TTL
X-Say-Cacheable
X-Section
X-SayCDN-TTL
X-UA-Device-Type
Mn-Server-Ip
X-Akamai-Edgescape
X-Hl-Ver
X-PHP-Host
X-Sql-Count
X-Labrador-Cache-Channel
X-Sql-Duration-Ms
X-Revision
X-FB-TRIP-ID
X-Status
X-Via-Fastly
X-ApacheServer
X-PERF
X-Cache-PHP
Xserver
X-Hyper-Cache
X-Uri
X-Hosted-By
X-Rule
X-Ua-Device
X-Web-Node
X-Redis-Cache
X-Cache-Type
X-B3-SpanId
X-Aws-Lambda-Call-Status
X-Trace-Id
AMP-Access-Control-Allow-Source-Origin
X-WA-Info
X-FW-Version
X-MP-GENERATED-AT
X-ATG-Version
X-Time-Microsecs
X-Content-Age
X-ServerID
X-Cached-By
X-CSRF-Token
X-Tumblr-Pixel-3
X-Parallel-Accel
X-Soup
Backend
X-Cache-Enabled
X-Edge-Location
GEO-INFO
X-Dc
X-Akamai-Transformed
Count-Hit
X-Mode
X-Datadome
X-Cluster-Node
X-TT-LOGID
X-Detected-As
X-CS
X-Varnish-Cache-Hits
OT-Force-Account-Verify
X-Info
X-Varnish-Beresp-Status
X-Cache-Host
X-Azure-Ref-OriginShield
X-Bc-Bl
X-Generation-Time
Web-Mar-Node
Cross-Origin-Opener-Policy
X-Microcachable
X-Varnish-Hits
X-Cache-NGX
X-Servername
X-Debug-Cache
X-Amzn-Remapped-Content-Length
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Zipkin-Id
X-Varnish-Beresp-Ttl
X-APP-VERSION
X-Storage
X-Platform
X-Proxied
X-Routing-Service
X-SRV
Who
X-HP-Trace-Id
SID
X-Extlb
X-Unique-ID
X-B3-Traceid
DataCenter
X-DataDome
X-Origin-TTL
X-Origin-CC
Host-ID
Mobile-Detection-Method
Odigeo-Trace-Id
Meta-Geo-Continent
MD5-Digest
M-TraceId
Rendered-Blocks
X-A-Dgt
Surrogated-Key
X-A-Dcw
X-A-Dam
X-A
Fastly-Backend-Name
T-Server
State
X-A-Ccd
Req-Svc-Chain
DCR-Processing-Time-Ms
BehaviorPad-Version
Cache-Host
CDCHOST
CDN-Cache
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
A
Apple-News-Services-Handled
Apple-News-Services-Host
CDN-CachedAt
CDN-EdgeStorageId
DCR-Decision-By
X-A-Wwc
Expiry
Content-Disposition
CDN-Uid
CDN-PullZone
CDN-RequestCountryCode
CDN-RequestId
Fastcgi-X-Cache-Version
X-ARC
X-Rewrite-Enabled
X-Rojux
X-S
X-S-Cookie
X-Request-URI
X-Ratelimit-Reset
X-PAYTM-SRV-ID
X-PBS-Appsvrname
X-Processor
X-ScT
X-Session-Fingerprint
X-VG-WebServer
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
X-VG-WebCache
X-Vdms-Version
X-SRCache-Key
X-Thanos
X-Vdms-Path
X-NAPM-TraceId
X-Level-Front-Cache
X-Cache-Bucket
X-Cache-NE
X-CF-Lambda-Fn
X-Bip
X-BCube-Filmed-By
X-Aicache-OS
X-Application
X-B-Cookie
X-CF-Lambda-Version
X-Cms-Context
X-Epic-Correlation-Id
X-External-Request-Id
X-From
X-Developer
X-Destination
X-Connection-Hash
X-Core-Value
X-D
X-Aed
X-Generated-On
Server-Info
X-Magnolia-Registration
X-Air-Source
X-Air-Trace-Id
X-Air-Hostname
Upgrade-Insecure-Requests
X-TEC-API-ORIGIN
S-Rt
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Ua
X-Has-Esi
Location
X-Geo-Header
Origin
X-GoCache-CacheStatus
X-Hash
Fastly-Drupal-HTML
Fastcgi-Cache-TTL
Esi-Enabled
X-Is-Gdpr
Fastly-SIE
Fastly-SWR
Kp-EeAlive
Pagetype
Gh-Request-Id
L
X-Rebelmouse-Cache-Control
X-Sigma-Backend
X-Rocket-Build-Number
X-Cache-Debug
X-Branch-Name
X-Sigma
X-Clientip
Ec-Rule-Version
X-Served-From
X-Service
X-Developers
X-Backend-State
UCS
X-VG-TLSProxy
X-Rebelmouse-Surrogate-Control
Server-Host
X-Envoy-Decorator-Operation
X-Var-Ttl
X-Request-UUID
X-Sucuri-ID
X-TrackingId
Pics-Label
Path
X-NU-AKA-ACS-Version
X-Via-JSL
X-Platform-Server
X-Location
X-Locale
CacheControlHeader
Source
Cmstype
X-Proxy-Upstream
X-VHOST
Cmsid
X-Cache-Grace
X-Origin
X-JWT-State
X-Varnish-Ttl
Url
X-NWS-UUID-VERIFY
X-Tb
Cross-Origin-Window-Policy
X-AIR-PT
User-Cache-Control
Wxu-Next-Commit
Wxu-Next-Region
X-Varnish-Url
X-VarnishDD-TTL
X-Eu-Site
Wxu-Next-Hostname
X-Forwarded-Site
True-Client-Country-4JS
X-Forwarded-Host
X-Request-Host
X-Men
X-Fmm-Version
X-Fastly-Cache
Vix-Hermes-Req-Id
X-Fastly-Backend
X-Forwarded-Path
X-Csrf-Jwt
Content-Secure-Policy
X-Cache-Tags
X-Cache-Info
X-CGP
X-Clara-WADP
X-Owner
X-Origin-Expires
X-Cluster
X-Date
X-Tenant
X-Policy
X-Variation
X-Accel-Expires-Debug
X-DPWN-IS-SECURE
X-Req
X-Micro-Cache
X-Shop-Environment
X-Minions-Version
X-Orig-Expires
NtCoent-Length
AKAMAI
L5d-Success-Class
X-Li-Pop
X-Li-Fabric
X-LI-UUID
X-Amz-Meta-S3cmd-Attrs
DSUID
NGX
X-Thinkindot-L3
Is-Eu
HA-Ipaddr
Cf-Device-Type
Thinkindot-Control
X-Device-Os
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
Ha-Gx-Prefs
X-HN
TDXMobile
Memcached
X-Scheme
PB-PID
X-WADP-Cache
X-SVT-ORM-VERSION
C-Via
PB-RID
Platform
PFcat
X-Gamma-Serve
X-SVT-ORM-RULES
Arc-Version
X-Loc
Adler-Geo
X-Generated-In
X-EC-Lua
NM-Fastcgi-Cache
X-Qloud-Router
X-RateLimit-Limit-Second
X-Irp-Debug
X-Old-Content-Length
X-Gen-Mode
X-RateLimit-Remaining-Second
X-Gzip
X-Esi-Check
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Generated-By
X-DefHash
X-FC-Vary-Parameters
X-Mvc-Supplant-Cachable
X-DefElseHash
X-Hnp-Log
X-VC-Cache
Release
IsBot
Server-Ext
Mail-Subject
X-Wikidot-Static-Cache
Svr
X-Viewer-Country
X-Wikidot-Backend
Server-Hostname
Sever-Int
Arc-Country
X-User
X-VServer
Cache-Key
X-Nginx-Cache-Key
X-Fetched-On
X-GeoIP
X-GeoIP-City
V-Age
Locid
X-Site-Version
X-SIPLIST1
X-Varnish-CookieHashed-On
We-Hiring
X-Slack-Backend
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Cache-Id
X-Block-Status
Webserver
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-HS-Content-Campaign-Id
X-PF-Uncompressing
CPC-Cache
X-Planisys-CDN-TTL
X-Via-NSCOPI
X-Srv
X-Ftr-Request-Id
X-Skip-Cache
X-CACHE-KEY
CPC-Age
VNS-Cache
Powered-By-ChinaCache
X-Unique-Id
My-App
VNS-Age
X-Zone
MIME-Version
X-GEO
X-Via-Poph
X-Mvc-Supplant-OutputCached
X-Refresh
X-Via-Popv
X-Conf
X-Via-Popn
X-Ratelimit-Limit
Cache-Hits
X-Pass-Why
X-TX-ID
X-BBC-Edge-Cache-Status
X-Cache-Ttl
X-Vc
XServer
X-Internal-Host
X-Servedbyhost
X-Ckpd-Fst-Backend
X-PJAX-URL
X-Worker
X-NC
Geo-Info
X-ID
X-Auto-Login
X-OVcl-Cache
X-OVcl
X-DC
X-LB-ID
WebServer
Server-ID
X-V-Cache
X-Ratelimit-Remaining
Cf-Bgj
Memory
Time
X-Backend-TTL
X-TIME
X-Webkit-Csp
X-Traceid
X-LSADC-Cache
Magicmarker
X-TraceId
X-NCache
X-Render-Time
X-NewRelic-App-Data
DB-Nickname
X-ZONE
X-Wa
X-Platform-Processor
X-Platform-Router
X-Qnm-Cache
X-Platform-Cluster
X-M-Reqid
HostName
X-Rocket-Nginx-Serving-Static
X-M-Log
X-Tx-Id
X-Cache-Remote
X-Newrelic-Synthetics
X-Geo
X-SD-PageType
Geoip-Latitude
Hostname
GeoIp-Country-Code
X-App
X-Dispatcher-Server
X-Method
X-Datadog-Sampling-Priority
Environment
X-CLOUD-TRACE-CONTEXT
X-Datadog-Trace-Id
X-Datadog-Parent-Id
X-Cache-Config
X-Gdpr
X-NodeID
X-API-Version
X-IP
Resin-Trace
Ssr
X-Origin-Time
X-Nyt-Route
X-VCL-Version
X-Tb-Optimization-Total-Bytes-Saved
X-BBC-Origin-Response-Status
X-Correlation-ID
X-Server-IP
X-Via-Ucdn
Cluster
X-Pod-Name
Tcn
Ohc-File-Size
LB
Candidate-Md5Url
X-Origin-Response-Time
X-LI-Proto
X-Edge-Pop
X-Dynatrace
X-MSEdge-Features
X-HITS
X-CACHE-AGE
X-Webkit-CSP-Report-Only
X-MSEdge-Flight
X-Li-Proto
X-Cache-Var
X-Cache-Var-Map
X-Akamai-Pragma-Client-IP
Datacenter
X-ElasticPress-Query
X-Nc
X-Trv-Group
Cf-Ipcountry
X-DynaTrace-JS-Agent
X-Vcl-Version
X-Varnish-Beresp-TTL
X-Node-Id
Web-Mar-Region
N-Cache
X-Via-CDN
X-Wix-Viewer-Type
X-APP
X-ND-Cache
Env
X-HostName
X-ServerName
GeoIP-Country-Code
GeoIP-Latitude
X-Reqid
Proxy-Connection
X-WA
Servername
Onion-Location
X-HS-Status
X-Dynatrace-Js-Agent
CF-Cached-On
X-Cs
X-EIG-Tracking-Id
Sid
Cdn
X-Ua-Browser
Viewtype
X-AB
VivaBuild
CDN
X-Varnish-Cacheable
X-Content
Server-Id
WWW-Authenticate
Rt-Fastcgi-Cache
X-MG-S
X-NGINX-Cache
X-FTR-Request-ID
WZWS-RAY
Machine
X-Fastly-Backend-Reqs
X-Check-Cacheable
X-Cdn-Forward
X-URL
X-Fpc
X-Pjax-Url
X-Lb-Id
X-Xrds-Location
Ohc-Cache-HIT
X-Esi
X-CSRF-TOKEN
X-Via-PopH
On-Server
Cteonnt-Length
X-Via-PopV
Redirect-Candidate
X-Via-PopN
X-IN-APIGATEWAY
X-Fastly-Request-Id
X-Cache-Backend
X-VC
X-IN-APIGATEWAYSSL
FSS-Cache
X-Tid
X-ServedByHost
X-TIM-N
X-SN
Shield-Pop
X-Request-Start
Mime-Version
URI
Server-Ttl
X-Up
CountryCode
X-Swa-Ws
X-Tt-Logid
X-Webkit-Csp-Report-Only
X-Swift-Error
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-FORWARDED-FOR
X-Pad
X-Country-Code-Real
X-Oss-Hash-Crc64ecma
X-Amz-Meta-Cb-Modifiedtime
X-Varnish-Authentication
X-Oss-Storage-Class
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-DC
X-FTR-Realm
Lb
CACHE
X-Cache-Date
Is-Us
X-Oss-Request-Id
X-Oss-Server-Time
X-LiteSpeed-Cache-Control
X-Air-Pt
X-Oss-Object-Type
Xc-Version
X-FTR-Backend
Tracecode
X-RPS
X-DW
X-RPM
X-DSS
X-Acquia-Application-Trace
X-Acquia-Purge-Tags
X-Acquia-Site
X-Cdn-Origin
X-Sn-Servicetimems
X-Acquia-Application-UUID
X-DI
X-StackifyID
Xet-Cookie
Pramga
X-RSL
X-Pf-Uncompressing
X-DB
X-SB
X-Dw-Trace-Id
X-ElasticPress-Search
Warning
X-Webstats-RespID
X-Yottaa-OS
WP-Super-Cache
X-Action
Ohc-Response-Time
Vha6-Origin
X-Fastly-Cache-Hits
X-CCM
Content-Script-Type
CloudFront-Viewer-Country
Content-Style-Type
X-CCDN-Origin-Time
W
X-RAMCache
X-Provided-By
X-Edge-POP
X-Core-Mission
X-CUA
X-C
X-FTR-Expires
X-CCDN-CacheTTL
X-Mg-Request-Id
X-Snapshot-Date
X-MiniProfiler-Ids
X-Hcs-Proxy-Type
ServerName
X-TH-Server