Threat Level: green Handler on Duty: Russ McRee

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-RAY
CF-Cache-Status
Accept-Ranges
Link
ETag
Pragma
Expect-CT
X-Powered-By
X-XSS-Protection
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
Alt-Svc
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Timer
X-Download-Options
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-Request-ID
X-Cache-Status
X-Generator
X-Cacheable
X-DNS-Prefetch-Control
Timing-Allow-Origin
P3p
X-Content-Security-Policy
X-Iinfo
Status
X-Ua-Compatible
Feature-Policy
Content-Encoding
X-AspNetMvc-Version
X-CDN
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
Upgrade
X-Drupal-Dynamic-Cache
Access-Control-Max-Age
X-Via
X-Dns-Prefetch-Control
Keep-Alive
X-Ws-Request-Id
X-Robots-Tag
Request-Context
Server-Timing
X-AH-Environment
X-Hacker
X-Server
X-Age
X-Turbo-Charged-By
X-Proxy-Cache
X-Server-Powered-By
X-Cache-Group
X-Backend
X-Amz-Request-Id
Host-Header
X-Amz-Id-2
EagleId
X-Nginx-Cache-Status
Report-To
X-LiteSpeed-Cache
X-Rq
X-Varnish-Cache
X-Page-Speed
Grace
X-UA-Device
X-Pingback
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
EagleEye-TraceId
X-Device
X-Vhost
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Amz-Version-Id
NEL
X-OneAgent-JS-Injection
X-Dispatcher
Cf-Railgun
X-Host
X-Cache-Spec
X-Server-Id
X-CST
X-WebKit-CSP
X-Node
X-Backend-Server
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Allow
Request-Id
Surrogate-Control
X-Readtime
Accept-CH
X-Akam-SW-Version
X-Response-Time
Accept-Ch-Lifetime
Xkey
X-HW
X-Language
X-Webkit-CSP
X-Country
X-Ruxit-JS-Agent
X-Application-Context
X-Template
X-Ac
Content-Location
X-Cache-Lookup
X-Cloud-Trace-Context
MS-Author-Via
Rating
X-Url
Edge-Control
X-Vname
X-PC
X-TtlSet
X-Mod-Pagespeed
X-Clacks-Overhead
X-Varnish-TTL
X-B3-TraceId
X-Trace
X-ESI
X-MS-InvokeApp
X-Content-Type
Fastly-Restarts
X-Rack-Cache
X-Origin-Cache
X-GitHub-Request-Id
Accept-Ch
X-Buckets
X-Cnection
X-Country-Code
X-Goog-Hash
Accept-CH-Lifetime
Verso
X-D2id
X-VARITI-CCR
X-GoogleNews-Bot
X-Kinja
X-Kinja-Revision
X-Cdn-Fetch
X-Exp-Variant
X-Use-Magma
X-Kinja-Server
X-Exp-Id
X-Kinja-Build
Arr-Disable-Session-Affinity
X-FastCGI-Cache
X-ORACLE-DMS-ECID
X-Vcap-Request-Id
Cache-Tag
X-Cached
X-Server-Name
X-Abt-Application-Version
Service-Worker-Allowed
X-Client-IP
X-Amz-Rid
X-Server-ID
X-Navigation-Version
X-Px
X-Powered-By-Plesk
RTSS
Public-Key-Pins
Access-Control-Request-Method
X-Fastly-Request-ID
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Element-Page-Cache
X-Powered-CMS
X-MSEdge-Ref
X-Cache-TTL
X-Upstream
X-Dw-Request-Base-Id
X-NF-Request-ID
X-Version
X-TTL
X-Sol
Display
Pagespeed
X-Middleton-Response
X-Middleton-Display
Response
S
X-Edge-Location-Klb
X-Edge
X-Kinsta-Cache
X-LLID
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Ttl
X-ECACHE
X-Server-Lifecycle-Phase
X-Kraken-Routeconfig-Destination
X-Kraken-Loop-Name
X-Instrumentation
X-Cache-Key
X-Accel-Expires
Realpath
X-Jurisdiction
X-HP-Webp
X-Aspnetmvc-Version
X-Correlation-Id
X-Shield-Request-Id
X-SharePointHealthScore
SPRequestGuid
Pinterest-Version
X-Pinterest-Rid
SPRequestDuration
SPIisLatency
X-T
Pinterest-Generated-By
X-MCACHE
X-Mid
X-DynaTrace
X-PressLabs-Stats
X-XRDS-Location
X-Litespeed-Cache
X-Content-Security-Policy-Report-Only
X-ORACLE-DMS-RID
Edge-Cache-Tag
Fastcgi-Cache
X-Forwarded-Proto
X-Mg-S
X-Amz-Server-Side-Encryption
X-Content-Digest
Nginx-Cache
TP-L2-Cache
TP-Cache
X-Recruiting
Charset
X-Oneagent-Js-Injection
Filters
Front-End-Https
X-Id
X-Request-Received
TCN
X-Request-Processing-Time
Alternate-Protocol
Server-Node
X-Logged-In
X-Ezoic-Cdn
X-Forwarded-For
Content-MD5
X-Geo-Country
Cache-Tags
Fusion-Source
Fusion-Template-Id
Fusion-Content-Id
Fusion-Deployment-Id
Fusion-Component-Id
Fusion-Content-Source
X-ASPNET-VERSION
X-Protected-By
X-Hostname
X-Amzn-Trace-Id
X-Grace
X-Origin-Upstream-Status
X-Ruxit-Js-Agent
X-NWS-LOG-UUID
X-Goog-Generation
X-F-Cache
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Www-Served-By
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Origin-Server
X-Amz-Replication-Status
Cleartype
X-Rid
X-Debug-Info
X-Release
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Cache-Config
Host
X-HS-Combine-CSS
X-LB-Cache
X-Activity-Id
X-Az
X-AppVersion
X-Contextid
Section-Io-Cache
X-Daa-Tunnel
X-Page-Id
Server-Name
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Git-Hash
X-Erf-Bev-Bev
X-Frontend
X-Ser
X-VCache
X-Respond-Thread
MicrosoftSharePointTeamServices
X-Ab
X-RateLimit-Remaining
X-Cache-Age
X-Content-Options
Access-Control-Allow-Method
Accept-Charset
X-Upgrade-Enabled
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Hits
X-Mobile-URL
X-DIS-Request-ID
X-WebKit-CSP-Report-Only
X-Source
ServerID
X-Signature
X-Route-Name
X-Request-Guid
X-B-Cache
X-CACHE-GROUP
X-Aspnet-Duration-Ms
X-Is-Crawler
X-Flags
X-Providence-Cookie
X-Varnish-Backend
X-Cache-Action
X-Whom
Payment
X-FB-Debug
X-Varnish-Grace
Healthy
Viewport
X-Varnish-Age
X-TT
Paypal-Debug-Id
Node
X-Fastcgi-Cache
X-AOL-HN
X-App-Environment
DynaTrace
Fastcgi-Useragent
X-B3-Sampled
X-Load-Cache
Version
X-Yandex-Sdch-Disable
X-Seen-By
X-Mobile
X-N
DC
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-HTML-Minification-Powered-By
X-Type
X-Distributor
Filterid
SRV
X-User-Agent
Retry-After
Frame-Options
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
X-Cache-Control
MS-CV
X-Ua-Device
X-Jobs
X-Cache-Expired-At
Refresh
X-Original-Request-Id
X-Response-Served-From
X-XRDS-LOCATION
X-UUID
X-Page-View
X-IPLB-Instance
Amp-Access-Control-Allow-Source-Origin
X-Adobe-Content
X-Real-IP
X-Adobe-Loc
NGB
X-Proxy-Cache-Status
X-FW-Type
X-FW-Hash
X-FW-Dynamic
X-FW-Serve
X-FW-Server
X-Cluster-Name
X-FW-Static
Access-Control-Request-Headers
X-Debug-IsPreview
X-Device-Type
X-Region
X-Instance
X-Debug-IsConnected
X-Varnish-Server
X-RemovedCookies
X-Proxy
X-Tumblr-Pixel-1
X-Tumblr-User
X-Content-Powered-By
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-ProcessESI
X-B
X-Cacheable-TTL
X-Framework
X-G
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-NGENIX-Cache
X-Vgn-Hpd-Reason
X-CDN-Forward
X-IPS-LoggedIn
X-RTag
Ms-Operation-Id
X-Cache-Time
X-Azure-Ref
Uber-Trace-Id
X-Zen-Fury
X-Node-Name
Ar-Sid
AR-ATIME
AR-Request-ID
AR-CACHE
AR-PoweredBy
Countrycode
Cache-Status
X-Request-Handler-Origin-Region
X-Wix-Request-Id
X-Microsite
X-Cache-Hit
Section-Io-Origin-Time-Seconds
X-Cache-Rule
Section-Origin-Responded
Section-Io-Origin-Status
X-Ms-Request-Id
Section-Io-Id
X-Ms-Version
X-Rendered-As
SD-X-WS
X-Is-Bot
X-Time
Referer-Policy
X-Oracle-Dms-Rid
Liferay-Portal
X-Aws-Lambda-Call-Status
X-Mg-Request-UUID
X-HP-Trace-Id
X-Debug
X-Drupal-Cache-Tags
X-Accel-Buffering
X-EdgeConnect-Cache-Status
X-Parallel-Accel
S-Cnection
Cache
X-Nginx-Cache
Country
X-Environment-Context
X-L-Path
CF-IPCountry
X-RateLimit-Limit
X-App-Server
X-Revision
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-App-Version
X-Cache-Operation
Surrogate-Key
X-FireWall-Port
Count-Hit
X-Endurance-Cache-Level
Eomportal-Instance
X-TNCMS
X-UPSTREAM-Address
X-Loop
X-RN-RSRV
X-ES-SERVER
X-SaId
X-TA-CDN-Provider
Meta-Geo
X-JoinUs
X-Drupal-Cache-Contexts
X-GG-Cache-Date
X-Say-Cacheable
From-Origin
X-Proxy-Build
X-Say-TTL
Selected-Fe
X-LAGOON
X-Cache-Type
X-Cache-TTL-Remaining
X-Adobe-Source
X-Timing-Wait
X-Xfnlog-Site
X-SayCDN-TTL
X-Alternate-Cache-Key
X-AWS-Id
X-Human
Akamai-GRN
Protected
X-FW-Version
X-Be
Azure-RegionName
Azure-SiteName
Azure-SlotName
Cache-Name
X-BYPASS-REASON
Country-Code
Azure-Version
Azure-InstanceId
X-NYM-Debug-Backend
X-Origin-Date
X-Sql-Count
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-ShopId
X-Shopify-Stage
X-Sql-Duration-Ms
X-VWS-Id
X-Proto
X-ProxyCache-Key
X-Varnish-Beresp-Grace
X-Varnish-Hostname
X-Varnishpool
X-ShardId
X-Storefront-Renderer-Rendered
X-Request-Time
X-LJ-Flow-ID
X-No-Session
X-ProxyCache-Status
X-S-Maxage
ServedBy
X-Handled-By
X-PHP-Host
Apigw-Requestid
X-PHP-Backend
Cache-Tv-Group
X-Labrador-Cache-Channel
Decoy-Debug-Status
Fastly-SSL
GEO-INFO
X-Hosted-By
Decoy-Debug-Key
Decoy-Debug-TTL
X-UA-Device-Type
X-PCL
X-Akamai-Edgescape
X-Pubstack
X-RCS-CacheZone
X-R9-Blue-Green-Version
X-Status
X-Cache-Server
X-OCL
X-Backend-Name
X-Section
X-Origin-Hint
X-Format
TWC-GeoIP-LatLong
TWC-Locale-Group
X-Redis-Cache
TWC-Device-Class
X-Uri
TWC-Connection-Speed
X-Server-W
X-Tumblr-Pixel-2
Webcakes-Region
X-Access
Webcakes-App-Version
Webcakes-App-Name
X-Hl-Ver
X-Via-Fastly
X-Web-Node
X-Hyper-Cache
TWC-Privacy
TWC-GeoIP-Country
Property-Id
X-Backend-Host
X-PERF
X-ApacheServer
X-APP-VERSION
Nel
Mn-Server-Ip
X-FB-TRIP-ID
X-B3-SpanId
X-ServerID
X-Cluster-Node
X-Time-Microsecs
X-Servername
X-ATG-Version
X-Cache-PHP
OT-Force-Account-Verify
X-TEC-API-VERSION
X-B3-Traceid
X-TEC-API-ROOT
X-TEC-API-ORIGIN
Cross-Origin-Opener-Policy
X-Tumblr-Pixel-3
X-Detected-As
X-Azure-Ref-OriginShield
X-Trace-Id
Backend
X-Content-Age
X-WA-Info
Xserver
Web-Mar-Node
X-Cache-Host
X-MP-GENERATED-AT
X-Generation-Time
X-Varnish-Cache-Hits
X-CSRF-Token
X-TT-LOGID
Cross-Origin-Window-Policy
X-Datadome
X-Ua
X-Varnish-Hits
Content-Secure-Policy
X-Rule
X-Bc-Bl
X-SRV
X-Soup
X-Akamai-Transformed
Ec-Rule-Version
X-Cache-Enabled
X-Via-JSL
X-CS
X-Edge-Location
X-Ratelimit-Limit
X-Cached-By
X-NWS-UUID-VERIFY
X-Amz-Apigw-Id
Source
X-Amzn-Remapped-Content-Length
X-Amzn-RequestId
X-Info
X-Mode
S-Rt
X-Ratelimit-Remaining
X-Microcachable
X-Origin-CC
X-Origin-TTL
X-Varnish-Beresp-Ttl
X-Cache-Grace
X-Varnish-Beresp-Status
Url
X-Locale
Upgrade-Insecure-Requests
X-Magnolia-Registration
X-Forwarded-Host
X-Cache-NGX
X-Air-Hostname
X-Air-Source
X-Air-Trace-Id
X-GEO
X-EC-Lua
X-Storage
X-Tb
X-Dc
X-Site-Version
X-Debug-Cache
Meta-Geo-Continent
Rendered-Blocks
Req-Svc-Chain
Path
Odigeo-Trace-Id
Mobile-Detection-Method
DCR-Decision-By
CDN-Cache
CDN-CachedAt
CDN-EdgeStorageId
CDN-PullZone
CDCHOST
BehaviorPad-Version
Apple-News-Services-Handled
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
CDN-RequestCountryCode
CDN-RequestId
Fastly-SIE
Fastly-SWR
Host-ID
M-TraceId
Fastcgi-X-Cache-Version
Expiry
CDN-Uid
State
DCR-Processing-Time-Ms
MD5-Digest
X-Clientip
X-Ratelimit-Reset
X-Proxied
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Rewrite-Enabled
X-Request-URI
X-Processor
X-Platform-Server
X-NU-AKA-ACS-Version
X-NAPM-TraceId
X-Orig-Expires
X-PAYTM-SRV-ID
X-PBS-Appsvrname
X-Rojux
X-Routing-Service
X-VG-WebCache
X-Vdms-Version
X-VG-WebServer
X-Vtex-Processado-Em
X-Zipkin-Id
X-Vtex-Remote-Cache
X-Tenant
X-SRCache-Key
X-S-Cookie
X-S
X-ScT
X-Session-Fingerprint
X-Shop-Environment
X-Ftr-Request-Id
X-From
X-Aicache-OS
X-Aed
X-AIR-PT
X-Application
X-B-Cookie
X-ARC
X-A-Wwc
X-A-Dgt
X-A
T-Server
X-A-Ccd
X-A-Dam
X-A-Dcw
X-BCube-Filmed-By
X-Cache-NE
X-Epic-Correlation-Id
X-Developer
X-External-Request-Id
X-Extlb
X-Forwarded-Path
X-Destination
X-D
X-CF-Lambda-Version
X-CF-Lambda-Fn
A
X-Conf
X-Connection-Hash
Surrogated-Key
X-Cache-Bucket
Content-Disposition
X-Unique-Id
User-Cache-Control
SID
X-Cache-Ttl
X-DataDome
X-Date
X-Cms-Context
X-Core-Value
X-Fastly-Backend
X-Fmm-Version
X-Forwarded-Site
X-Fastly-Cache
X-Clara-WADP
X-Envoy-Decorator-Operation
X-DPWN-IS-SECURE
X-Cache-Debug
Pics-Label
Platform
PB-RID
PB-PID
Origin
UCS
X-Accel-Expires-Debug
X-Cache-Info
X-GoCache-CacheStatus
X-Bip
X-Backend-State
X-Cache-Tags
X-Hash
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Sigma-Backend
X-Sigma
X-Service
X-Thanos
X-TrackingId
X-WADP-Cache
X-BBC-Edge-Cache-Status
X-VServer
X-VG-TLSProxy
X-Variation
X-Rocket-Build-Number
X-Request-UUID
X-Li-Fabric
X-Li-Pop
X-JWT-State
X-Is-Gdpr
NGX
X-LI-UUID
X-Loc
X-Request-Host
X-Proxy-Upstream
X-Origin-Expires
X-Men
X-Has-Esi
X-Platform
DSUID
Cache-Host
Cmsid
C-Via
L
Arc-Version
Cache-Key
Fastly-Backend-Name
Cmstype
Fastly-Drupal-HTML
Adler-Geo
Is-Eu
X-Amz-Meta-S3cmd-Attrs
AMP-Access-Control-Allow-Source-Origin
CPC-Cache
X-Gamma-Serve
X-Generated-In
X-GeoIP-City
CPC-Age
X-Gzip
X-GeoIP
X-Geo-Header
X-Generated-By
X-Generated-On
X-Gen-Mode
X-Eu-Site
X-Cluster
X-Csrf-Jwt
X-CGP
X-Cache-Id
X-Branch-Name
Fastcgi-Cache-TTL
X-DefElseHash
Esi-Enabled
X-Esi-Check
X-Device-Os
X-Developers
X-DefHash
X-FC-Vary-Parameters
X-Level-Front-Cache
X-Var-Ttl
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Thinkindot-L3
X-Slack-Backend
X-Served-From
X-SIPLIST1
X-Varnish-Remaining-TTL
X-VarnishDD-TTL
X-Wikidot-Static-Cache
Server-Info
X-Wikidot-Backend
X-Viewer-Country
X-VC-Cache
X-Via-NSCOPI
X-Scheme
X-Req
X-Location
X-Micro-Cache
X-Block-Status
Cf-Device-Type
X-Hnp-Log
X-Irp-Debug
X-Mvc-Supplant-Cachable
X-Nginx-Cache-Key
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Policy
X-DC
X-Old-Content-Length
X-Origin
X-HN
CacheControlHeader
TDXMobile
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Locid
NM-Fastcgi-Cache
HA-Ipaddr
IsBot
Thinkindot-Control
Pagetype
Sever-Int
L5d-Success-Class
PFcat
True-Client-Country-4JS
Vix-Hermes-Req-Id
VNS-Age
We-Hiring
VNS-Cache
Release
Gh-Request-Id
Server-Ext
Server-Host
Mail-Subject
Ha-Gx-Prefs
Server-Hostname
Wxu-Next-Region
X-Skip-Cache
X-Fetched-On
X-Sucuri-ID
Wxu-Next-Commit
X-Owner
V-Age
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Worker
X-Planisys-CDN-TTL
Wxu-Next-Hostname
Arc-Country
X-Vdms-Path
NtCoent-Length
Webserver
AKAMAI
Svr
X-Unique-ID
Memcached
Location
X-Ckpd-Fst-Backend
Kp-EeAlive
X-Tx-Id
DataCenter
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Auto-Login
X-HS-Content-Campaign-Id
X-Qloud-Router
XServer
X-M-Log
X-M-Reqid
X-NCache
X-Mvc-Supplant-OutputCached
Cache-Hits
X-V-Cache
MIME-Version
Who
X-Qnm-Cache
X-User
X-Servedbyhost
X-Ua-Browser
X-Content
X-Platform-Cluster
X-Platform-Processor
X-Rocket-Nginx-Serving-Static
X-Render-Time
X-Platform-Router
X-PF-Uncompressing
X-Via-Poph
X-LSADC-Cache
X-Via-Popv
X-Via-Popn
X-NC
X-Srv
X-Traceid
X-SD-PageType
X-Varnish-Url
X-Minions-Version
X-ID
X-Zone
X-ZONE
X-Cache-Remote
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
Environment
X-Datadog-Trace-Id
X-Wa
X-Vc
X-Varnish-Ttl
WebServer
My-App
X-Cache-Var
Powered-By-ChinaCache
X-PJAX-URL
X-LB-ID
X-Cache-Var-Map
X-Refresh
X-App
X-BBC-Origin-Response-Status
X-Nyt-Route
X-Gdpr
X-API-Version
Server-ID
X-Origin-Time
X-NodeID
Memory
X-Server-IP
Cluster
X-VCL-Version
X-Webkit-Csp
X-Cache-Config
X-Pass-Why
X-Internal-Host
X-TIME
X-Via-Ucdn
Time
X-CACHE-KEY
X-Newrelic-Synthetics
X-Pod-Name
X-Webkit-CSP-Report-Only
Candidate-Md5Url
X-NewRelic-App-Data
Hostname
X-TX-ID
Datacenter
Geoip-Latitude
HostName
X-CLOUD-TRACE-CONTEXT
GeoIp-Country-Code
Resin-Trace
X-LI-Proto
X-OVcl-Cache
X-OVcl
Web-Mar-Region
X-ElasticPress-Query
Cf-Bgj
X-Tb-Optimization-Total-Bytes-Saved
N-Cache
X-Edge-Pop
Geo-Info
X-TraceId
X-VHOST
X-Backend-TTL
Magicmarker
Onion-Location
Tcn
Ohc-File-Size
X-HITS
Servername
X-Origin-Response-Time
X-Dynatrace
X-Akamai-Pragma-Client-IP
X-CACHE-AGE
X-EIG-Tracking-Id
X-Geo
WWW-Authenticate
X-Dispatcher-Server
X-Varnish-Cacheable
X-Method
X-Esi
DB-Nickname
LB
X-Varnish-Beresp-TTL
Proxy-Connection
X-NODE
GeoIP-Country-Code
X-Li-Proto
X-AB
CDN
X-Correlation-ID
Ssr
X-MSEdge-Features
X-Wix-Viewer-Type
GeoIP-Latitude
X-MSEdge-Flight
X-Tt-Logid
X-IP
X-Dynatrace-Js-Agent
X-HostName
Cdn
X-Fpc
X-Cs
X-TIM-N
Redirect-Candidate
X-Fastly-Request-Id
X-Tid
Sid
CF-Cached-On
Cf-Ipcountry
Tracecode
X-NGINX-Cache
X-Vcl-Version
X-Node-Id
X-Request-Start
X-Fastly-Backend-Reqs
X-Up
Pramga
Is-Us
Server-Id
X-Trv-Group
X-ND-Cache
X-APP
X-HS-Status
X-DynaTrace-JS-Agent
Lb
X-MG-S
X-Webkit-Csp-Report-Only
X-CSRF-TOKEN
X-Pjax-Url
X-WA
X-Lb-Id
X-Via-CDN
X-Reqid
X-Cache-Date
WZWS-RAY
X-Amz-Meta-Cb-Modifiedtime
X-ServerName
Cteonnt-Length
Env
X-Nc
X-FORWARDED-FOR
URI
W
X-Via-PopV
X-VC
X-Via-PopH
X-Via-PopN
X-Check-Cacheable
X-Core-Mission
X-Cdn-Origin
X-Provided-By
X-Sn-Servicetimems
Ohc-Cache-HIT
X-UnsetCookies
X-Cache-Backend
X-Cache-Expires
X-IN-APIGATEWAYSSL
X-SERVER-NAME
CloudFront-Viewer-Country
X-IN-APIGATEWAY
Shield-Pop
VivaBuild
Viewtype
WP-Super-Cache
CountryCode
X-ServedByHost
Rt-Fastcgi-Cache
X-Pf-Uncompressing
X-SN
Server-Ttl
Mime-Version
X-Acquia-Purge-Tags
X-LiteSpeed-Cache-Control
X-Acquia-Application-Trace
X-Contensis-Viewer-Groups
X-Acquia-Site
X-RAMCache
X-Region-Sid
X-Sucuri-Cache
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-Cache-Status-Check
X-CCDN-CacheTTL
X-Edge-POP
X-Acquia-Application-UUID
X-Fastly-Cache-Hits
X-Pad
X-Cache-ASPX
CACHE
X-Varnish-Authentication
X-Action
X-Dw-Trace-Id
X-StackifyID
X-DB
X-Yottaa-OS
X-Cdn-Request-ID
X-CUA
EpKe-Alive
Vha6-Origin
X-Moov-T
Ohc-Response-Time
Xc-Version
X-Swift-Error
X-RPS
X-RSL
Xet-Cookie
X-Webstats-RespID
X-SB
X-RPM
X-DW
X-Moov-Xdn-Version
Machine
X-DI
X-DSS
X-Cdn-Forward
X-Ig-Push-State
X-CF-Powered-By
X-ElasticPress-Search
X-TH-Server
X-MiniProfiler-Ids
Content-Script-Type
Content-Style-Type
Req-ID
ServerName