Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-RAY
CF-Cache-Status
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
X-XSS-Protection
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
Alt-Svc
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Request-ID
X-Check
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
P3p
X-Content-Security-Policy
X-FRAME-OPTIONS
X-Iinfo
Status
Content-Encoding
Feature-Policy
X-AspNetMvc-Version
X-CDN
X-Envoy-Upstream-Service-Time
Upgrade
Access-Control-Expose-Headers
X-Ua-Compatible
X-Drupal-Dynamic-Cache
Access-Control-Max-Age
X-Via
Keep-Alive
X-Dns-Prefetch-Control
X-Robots-Tag
Request-Context
X-Ws-Request-Id
Server-Timing
X-AH-Environment
X-Server
X-Age
X-Hacker
X-Turbo-Charged-By
X-Server-Powered-By
X-Proxy-Cache
X-Cache-Group
X-Backend
Host-Header
EagleId
X-Nginx-Cache-Status
X-Amz-Request-Id
X-Amz-Id-2
Report-To
X-LiteSpeed-Cache
X-Rq
X-UA-Device
X-Varnish-Cache
Grace
X-Page-Speed
X-Swift-SaveTime
X-Swift-CacheTime
X-Pingback
Ali-Swift-Global-Savetime
X-Device
EagleEye-TraceId
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Cf-Railgun
X-Vhost
X-Amz-Version-Id
X-Server-Id
X-OneAgent-JS-Injection
X-Host
X-Dispatcher
NEL
X-CST
X-Node
Allow
Surrogate-Control
X-Cache-Spec
Request-Id
X-Backend-Server
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Accept-CH
X-Response-Time
X-Readtime
X-Akam-SW-Version
X-WebKit-CSP
Xkey
X-Webkit-CSP
X-HW
Accept-Ch-Lifetime
X-Country
X-Ac
X-Application-Context
Content-Location
X-Language
MS-Author-Via
X-Template
X-Cloud-Trace-Context
Rating
X-Cache-Lookup
X-Url
X-Ruxit-JS-Agent
X-Mod-Pagespeed
X-B3-TraceId
Edge-Control
X-PC
X-TtlSet
X-Vname
X-Clacks-Overhead
X-ESI
X-MS-InvokeApp
X-Varnish-TTL
X-Trace
X-GitHub-Request-Id
X-Content-Type
Fastly-Restarts
X-Cnection
X-Rack-Cache
X-Origin-Cache
X-ASPNET-VERSION
X-D2id
X-Exp-Variant
X-GoogleNews-Bot
X-Kinja-Build
X-Kinja-Revision
X-Cdn-Fetch
X-Kinja
X-Kinja-Server
X-Country-Code
X-Exp-Id
X-Use-Magma
Arr-Disable-Session-Affinity
X-Goog-Hash
Verso
X-VARITI-CCR
Accept-CH-Lifetime
X-Server-Name
X-Cached
X-Vcap-Request-Id
X-FastCGI-Cache
Accept-Ch
X-Navigation-Version
Cache-Tag
X-Powered-By-Plesk
X-Client-IP
X-Abt-Application-Version
X-Amz-Rid
X-Buckets
Service-Worker-Allowed
X-Fastly-Request-ID
X-ORACLE-DMS-ECID
RTSS
X-Middleton-Display
X-Sol
X-Middleton-Response
Display
Pagespeed
Response
X-Cache-TTL
X-Ttl
Access-Control-Request-Method
X-MSEdge-Ref
X-Element-Page-Cache
X-Powered-CMS
X-NF-Request-ID
Public-Key-Pins
X-Dw-Request-Base-Id
X-Upstream
X-Version
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Edge
X-Ruxit-Js-Agent
S
X-Kinsta-Cache
X-LLID
X-Px
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
Realpath
X-TTL
X-Accel-Expires
SPRequestDuration
SPIisLatency
X-ECACHE
X-Edge-Location-Klb
SPRequestGuid
X-SharePointHealthScore
X-T
X-Oneagent-Js-Injection
X-Jurisdiction
X-HP-Webp
X-MCACHE
X-Mid
X-Forwarded-Proto
X-PressLabs-Stats
X-Content-Security-Policy-Report-Only
X-Shield-Request-Id
Charset
X-Correlation-Id
X-Recruiting
Edge-Cache-Tag
X-Mg-S
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
X-DynaTrace
TP-Cache
TP-L2-Cache
X-Release
Fastcgi-Cache
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Kraken-Routeconfig-Destination
X-Ezoic-Cdn
X-Instrumentation
X-Amz-Server-Side-Encryption
X-Content-Digest
X-Id
Filters
X-Request-Processing-Time
X-Request-Received
X-ORACLE-DMS-RID
Nginx-Cache
Server-Node
X-Logged-In
Alternate-Protocol
Cache-Tags
X-Server-ID
Front-End-Https
X-Cache-Key
Content-MD5
X-Forwarded-For
TCN
X-Origin-Upstream-Status
Server-Name
Fusion-Content-Id
X-Amzn-Trace-Id
Fusion-Template-Id
Fusion-Content-Source
Fusion-Deployment-Id
Fusion-Component-Id
Fusion-Source
X-Litespeed-Cache
X-Origin-Server
X-Grace
X-WebKit-CSP-Report-Only
X-Hostname
X-Geo-Country
X-RateLimit-Remaining
X-Contextid
X-Rid
X-F-Cache
X-Goog-Metageneration
X-Goog-Generation
X-Activity-Id
X-Goog-Storage-Class
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
X-Amz-Replication-Status
X-Goog-Stored-Content-Length
Host
X-Az
X-AppVersion
Cleartype
X-HS-Cache-Config
X-Protected-By
X-HS-Hub-Id
X-XRDS-LOCATION
X-HS-Content-Id
X-HS-Combine-CSS
X-Www-Served-By
X-XRDS-Location
X-Frontend
Section-Io-Cache
X-Debug-Info
AR-CACHE
AR-PoweredBy
AR-ATIME
X-Webkit-Csp
X-LB-Cache
AR-Request-ID
Ar-Sid
MicrosoftSharePointTeamServices
X-Fastcgi-Cache
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Tec-Api-Version
X-Ser
X-Tec-Api-Root
X-Tec-Api-Origin
X-Git-Hash
X-Page-Id
X-Cache-Age
Accept-Charset
X-Varnish-Age
X-NWS-LOG-UUID
X-Upgrade-Enabled
X-Respond-Thread
X-Aspnetmvc-Version
X-VCache
X-Hits
X-Content-Options
X-Source
ServerID
X-Mobile-URL
X-DIS-Request-ID
Paypal-Debug-Id
X-Varnish-Backend
Access-Control-Allow-Method
X-B-Cache
X-Varnish-Grace
X-Kong-Upstream-Latency
X-Signature
X-Kong-Proxy-Latency
X-Request-Guid
X-Flags
X-Providence-Cookie
X-Route-Name
X-Is-Crawler
Nel
Healthy
Payment
X-Aspnet-Duration-Ms
X-FB-Debug
X-Cache-Action
X-Whom
Viewport
X-Request-Handler-Origin-Region
X-Microsite
X-B3-Sampled
X-N
X-Daa-Tunnel
X-TT
X-CACHE-GROUP
X-App-Environment
X-AOL-HN
Node
X-Seen-By
X-Type
Version
X-Load-Cache
Fastcgi-Useragent
X-Mobile
DC
MS-CV
DynaTrace
X-Cache-Expired-At
X-HTML-Minification-Powered-By
Filterid
X-Yandex-Sdch-Disable
X-Distributor
X-Ab
X-Cache-Control
X-IPLB-Instance
SRV
Retry-After
X-Original-Request-Id
X-Tt-Trace-Tag
X-Response-Served-From
X-Tt-Trace-Host
Frame-Options
X-Instance
X-UUID
X-Real-IP
X-FireWall-Port
NGB
X-Tumblr-Pixel-1
X-RemovedCookies
X-Proxy-Cache-Status
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-User
X-IPS-LoggedIn
X-ProcessESI
X-Varnish-Server
X-User-Agent
X-Proxy
Access-Control-Request-Headers
Ms-Operation-Id
X-RTag
X-Region
X-Content-Powered-By
X-Cluster-Name
X-Jobs
X-Device-Type
X-Cache-Time
X-Debug-IsConnected
X-Debug-IsPreview
X-Page-View
Refresh
X-Cacheable-TTL
Uber-Trace-Id
X-B
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Adobe-Loc
X-Adobe-Content
X-Framework
X-Debug
X-G
X-Accel-Buffering
Cache
X-RateLimit-Limit
X-Wix-Request-Id
X-FW-Server
X-FW-Static
X-FW-Serve
X-FW-Hash
X-FW-Dynamic
X-FW-Type
X-Zen-Fury
Countrycode
X-App-Version
Section-Io-Id
Section-Origin-Responded
X-Time
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
X-Vgn-Hpd-Reason
Cache-Status
X-Cache-Hit
X-Nginx-Cache
X-NGENIX-Cache
Surrogate-Key
X-Oracle-Dms-Rid
X-TA-CDN-Provider
Country
X-Azure-Ref
X-Is-Bot
X-Drupal-Cache-Tags
X-Rendered-As
X-Mg-Request-UUID
S-Cnection
Eomportal-Instance
X-EdgeConnect-Cache-Status
X-App-Server
X-CDN-Forward
X-Cache-Rule
X-Ms-Version
X-Ms-Request-Id
Referer-Policy
X-Node-Name
AMP-Access-Control-Allow-Source-Origin
SD-X-WS
Liferay-Portal
X-Drupal-Cache-Contexts
X-L-Path
X-Environment-Context
X-Cache-Operation
X-JoinUs
X-Tumblr-Pixel-2
X-ES-SERVER
Meta-Geo
X-RN-RSRV
Selected-Fe
X-SaId
X-Varnishpool
X-Proxy-Build
X-Timing-Wait
X-UPSTREAM-Address
From-Origin
X-No-Session
X-Backend-Host
X-Alternate-Cache-Key
X-Xfnlog-Site
X-Cache-Server
X-GG-Cache-Date
X-Handled-By
X-Yottaa-Optimizations
X-Endurance-Cache-Level
X-Storefront-Renderer-Rendered
X-Via-Fastly
CF-IPCountry
Azure-RegionName
Azure-SiteName
Azure-SlotName
Azure-Version
Azure-InstanceId
X-PHP-Backend
Protected
X-Sorting-Hat-ShopId
X-Cache-TTL-Remaining
X-Varnish-Hostname
ServedBy
X-Yottaa-Metrics
X-Request-Time
X-ShopId
X-Pubstack
X-Sorting-Hat-PodId
X-Shopify-Stage
X-R9-Blue-Green-Version
X-S-Maxage
X-Loop
X-TNCMS
X-ShardId
TWC-GeoIP-LatLong
TWC-Locale-Group
Webcakes-App-Name
TWC-Privacy
TWC-GeoIP-Country
TWC-Connection-Speed
Cache-Tv-Group
Property-Id
X-Proto
Fastly-SSL
X-ProxyCache-Key
X-ProxyCache-Status
Akamai-GRN
Webcakes-App-Version
X-Server-W
TWC-Device-Class
X-Rule
X-NYM-Debug-Backend
X-OCL
X-BYPASS-REASON
X-Origin-Hint
X-Human
X-PCL
X-AWS-Id
X-Be
X-VWS-Id
Xserver
X-LJ-Flow-ID
Webcakes-Region
X-LAGOON
X-SayCDN-TTL
X-Say-TTL
X-Status
X-Hl-Ver
X-Format
X-Varnish-Beresp-Grace
Decoy-Debug-TTL
X-Section
X-RCS-CacheZone
X-Say-Cacheable
X-Access
X-Backend-Name
Apigw-Requestid
Country-Code
Cache-Name
Decoy-Debug-Status
Decoy-Debug-Key
X-Labrador-Cache-Channel
X-Cache-PHP
X-FB-TRIP-ID
X-Sql-Count
X-Adobe-Source
X-PERF
Mn-Server-Ip
X-ApacheServer
X-Origin-Date
X-PHP-Host
X-Sql-Duration-Ms
X-UA-Device-Type
X-Akamai-Edgescape
X-Uri
X-Hyper-Cache
X-Hosted-By
X-Redis-Cache
X-Revision
X-Dc
X-Trace-Id
X-Web-Node
X-MP-GENERATED-AT
X-WA-Info
X-Ua-Device
Amp-Access-Control-Allow-Source-Origin
X-Cached-By
X-ATG-Version
X-FW-Version
X-B3-SpanId
X-Content-Age
X-CSRF-Token
X-Cache-Type
X-Time-Microsecs
X-ServerID
X-Soup
X-Cache-Enabled
X-Datadome
X-Tumblr-Pixel-3
X-Edge-Location
X-Aws-Lambda-Call-Status
X-Mode
Backend
X-CS
X-TT-LOGID
X-Info
X-Bc-Bl
X-Akamai-Transformed
X-Microcachable
X-Detected-As
X-Varnish-Beresp-Status
X-Varnish-Cache-Hits
X-Cache-Host
X-Unique-ID
X-Azure-Ref-OriginShield
X-Cache-NGX
X-Parallel-Accel
Who
X-Debug-Cache
Web-Mar-Node
X-Generation-Time
X-Cluster-Node
X-Proxied
X-Storage
X-Varnish-Hits
X-Zipkin-Id
X-Platform
X-Routing-Service
DataCenter
Count-Hit
X-SRV
OT-Force-Account-Verify
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Amzn-Remapped-Content-Length
X-Via-JSL
Cross-Origin-Opener-Policy
X-CACHE-KEY
X-Varnish-Beresp-Ttl
X-APP-VERSION
GEO-INFO
X-Extlb
X-Locale
X-Origin-TTL
X-Origin-CC
X-B3-Traceid
X-SRCache-Key
X-Thanos
DCR-Processing-Time-Ms
DCR-Decision-By
X-Session-Fingerprint
CDN-Uid
Content-Disposition
Expiry
Fastcgi-X-Cache-Version
X-Vtex-Remote-Cache
CDN-RequestId
M-TraceId
Host-ID
X-Sucuri-ID
MD5-Digest
Fastly-Backend-Name
CDN-Cache
Apple-News-Services-Handled
X-Vdms-Path
Apple-News-Services-Host
A
X-Vdms-Version
X-Vtex-Processado-Em
X-VG-WebServer
X-VG-WebCache
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
CDN-EdgeStorageId
X-Varnish-Url
CDN-PullZone
CDN-CachedAt
CDCHOST
BehaviorPad-Version
Cache-Host
X-Service
CDN-RequestCountryCode
Rendered-Blocks
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Cms-Context
X-Connection-Hash
X-Cache-NE
X-Bip
X-Application
X-ARC
X-B-Cookie
X-BCube-Filmed-By
X-Core-Value
X-D
X-From
X-Generated-On
X-Location
X-Level-Front-Cache
X-External-Request-Id
X-Epic-Correlation-Id
X-PAYTM-SRV-ID
X-NAPM-TraceId
X-Destination
X-Developer
X-PBS-Appsvrname
X-Processor
Req-Svc-Chain
State
Surrogated-Key
T-Server
X-S
X-S-Cookie
Mobile-Detection-Method
X-ScT
Odigeo-Trace-Id
X-Geo-Header
X-Rojux
X-A
X-A-Wwc
X-Ratelimit-Reset
X-Aed
X-Proxy-Upstream
X-A-Dgt
X-Request-URI
X-Rewrite-Enabled
X-A-Ccd
X-A-Dam
X-A-Dcw
Meta-Geo-Continent
X-Cache-Bucket
X-Air-Hostname
Server-Info
X-Air-Trace-Id
X-Air-Source
Upgrade-Insecure-Requests
X-AIR-PT
X-NU-AKA-ACS-Version
L
Location
X-Platform-Server
Memcached
Kp-EeAlive
X-Origin
Gh-Request-Id
Fastly-Drupal-HTML
Fastcgi-Cache-TTL
X-Request-UUID
Esi-Enabled
Fastly-SIE
Fastly-SWR
Origin
X-Rebelmouse-Surrogate-Control
X-Req
X-Rebelmouse-Cache-Control
Path
X-DataDome
X-Backend-State
X-Site-Version
X-Accel-Expires-Debug
X-Envoy-Decorator-Operation
X-Branch-Name
X-Clientip
X-Date
X-Developers
X-Cache-Debug
X-Gamma-Serve
X-GoCache-CacheStatus
Server-Host
Pics-Label
PFcat
X-Rocket-Build-Number
X-JWT-State
X-Is-Gdpr
UCS
X-Has-Esi
X-Hash
X-HN
Pagetype
SID
X-Aicache-OS
X-Var-Ttl
Cmsid
X-Magnolia-Registration
X-VG-TLSProxy
CacheControlHeader
X-VarnishDD-TTL
X-TrackingId
Cmstype
AKAMAI
X-Minions-Version
X-Served-From
X-Servername
X-Sigma
X-Scheme
X-Sigma-Backend
X-Cluster
X-Tb
Geo-Info
User-Cache-Control
X-Generated-In
Svr
Vix-Hermes-Req-Id
X-Generated-By
X-Variation
TDXMobile
Thinkindot-Control
X-Li-Fabric
Adler-Geo
Thinkindot-CacheControl
True-Client-Country-4JS
Thinkindot-CacheControl-Type
X-Forwarded-Site
X-DPWN-IS-SECURE
Source
X-WADP-Cache
X-Device-Os
X-Cache-Info
X-Clara-WADP
X-Cache-Tags
X-Csrf-Jwt
X-Viewer-Country
X-Eu-Site
Wxu-Next-Region
Wxu-Next-Hostname
Wxu-Next-Commit
X-TX-ID
X-Fmm-Version
X-Fastly-Backend
X-Fastly-Cache
We-Hiring
X-Li-Pop
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Policy
X-Owner
X-LI-UUID
NGX
X-CGP
L5d-Success-Class
X-Amz-Meta-S3cmd-Attrs
Ha-Gx-Prefs
X-Request-Host
DSUID
HA-Ipaddr
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
Is-Eu
NM-Fastcgi-Cache
Mail-Subject
PB-RID
PB-PID
C-Via
Arc-Country
Platform
X-Varnish-Ttl
X-Men
X-Micro-Cache
X-Thinkindot-L3
Arc-Version
X-VHOST
X-EC-Lua
X-NWS-UUID-VERIFY
X-Wikidot-Backend
X-Irp-Debug
X-Hnp-Log
X-Loc
X-Slack-Backend
X-Wikidot-Static-Cache
X-Skip-Cache
X-Mvc-Supplant-Cachable
X-VServer
X-User
NtCoent-Length
X-Esi-Check
X-Fetched-On
X-FC-Vary-Parameters
X-PF-Uncompressing
X-Gzip
X-Origin-Expires
X-Ua
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Nginx-Cache-Key
X-Via-NSCOPI
Webserver
X-Gen-Mode
X-VC-Cache
X-Old-Content-Length
Cf-Device-Type
CPC-Age
VNS-Age
Cache-Key
X-HP-Trace-Id
X-Block-Status
V-Age
CPC-Cache
Release
My-App
Server-Ext
Server-Hostname
Ec-Rule-Version
Sever-Int
X-Cache-Grace
VNS-Cache
S-Rt
X-Cache-Id
X-Pass-Why
Locid
X-Tenant
X-Shop-Environment
Url
X-DefHash
Cache-Hits
X-SIPLIST1
X-Qloud-Router
IsBot
X-GeoIP-City
X-GeoIP
X-HS-Content-Campaign-Id
X-DefElseHash
X-Orig-Expires
X-Varnish-CookieINHashed-On
X-Planisys-CDN-TTL
X-Varnish-Remaining-TTL
X-Forwarded-Path
X-Varnish-CookieHashed-On
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Forwarded-Host
Cross-Origin-Window-Policy
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Via-Popn
MIME-Version
X-Via-Popv
X-Mvc-Supplant-OutputCached
X-PJAX-URL
X-Srv
Powered-By-ChinaCache
X-Via-Poph
X-Vc
Content-Secure-Policy
X-Zone
X-Ratelimit-Limit
X-Ftr-Request-Id
X-Internal-Host
X-TraceId
X-OVcl-Cache
X-Cache-Ttl
X-OVcl
X-Refresh
X-Conf
X-Unique-Id
XServer
X-Geo
X-NC
X-BBC-Edge-Cache-Status
Cf-Bgj
X-LB-ID
Tcn
X-ID
DB-Nickname
X-Backend-TTL
X-Ckpd-Fst-Backend
Magicmarker
X-GEO
X-Worker
Server-ID
X-NCache
WebServer
X-Auto-Login
GeoIp-Country-Code
Geoip-Latitude
X-ZONE
Time
X-Servedbyhost
X-Ratelimit-Remaining
HostName
Memory
X-Method
X-V-Cache
X-TIME
X-NewRelic-App-Data
X-Dispatcher-Server
X-LSADC-Cache
X-Render-Time
X-Rocket-Nginx-Serving-Static
Ssr
X-Newrelic-Synthetics
X-IP
X-Qnm-Cache
Hostname
X-M-Log
X-Platform-Processor
X-M-Reqid
X-Platform-Cluster
X-Platform-Router
X-DC
X-Traceid
X-Li-Proto
X-SD-PageType
X-Wa
X-Tb-Optimization-Total-Bytes-Saved
X-Cache-Remote
Resin-Trace
X-CLOUD-TRACE-CONTEXT
X-Tx-Id
X-Datadog-Parent-Id
Environment
X-Nc
X-Datadog-Sampling-Priority
X-App
LB
X-Datadog-Trace-Id
X-Correlation-ID
X-Vcl-Version
X-API-Version
X-Origin-Time
X-Gdpr
X-Nyt-Route
X-Trv-Group
X-Cache-Config
X-BBC-Origin-Response-Status
X-NodeID
Ohc-File-Size
X-Pod-Name
X-HITS
X-VCL-Version
X-MSEdge-Features
Cluster
X-APP
X-MSEdge-Flight
X-Dynatrace
X-Origin-Response-Time
X-Node-Id
X-Via-CDN
X-CACHE-AGE
X-Edge-Pop
X-Server-IP
X-ServerName
X-DynaTrace-JS-Agent
Candidate-Md5Url
Env
X-Via-Ucdn
Cf-Ipcountry
X-Reqid
X-WA
X-Cache-Var
X-Akamai-Pragma-Client-IP
X-Varnish-Beresp-TTL
X-Cache-Var-Map
X-LI-Proto
Datacenter
N-Cache
X-Wix-Viewer-Type
Web-Mar-Region
X-ND-Cache
X-ElasticPress-Query
Sid
X-FTR-Request-ID
CF-Cached-On
X-Webkit-CSP-Report-Only
X-HostName
VivaBuild
Rt-Fastcgi-Cache
Viewtype
X-HS-Status
Machine
Proxy-Connection
X-Cdn-Forward
X-Cs
GeoIP-Latitude
GeoIP-Country-Code
X-Dynatrace-Js-Agent
Server-Id
Servername
CDN
Cdn
Onion-Location
WWW-Authenticate
X-Fastly-Backend-Reqs
X-EIG-Tracking-Id
X-ServedByHost
X-NGINX-Cache
X-Varnish-Cacheable
On-Server
FSS-Cache
X-Check-Cacheable
X-Lb-Id
WZWS-RAY
X-URL
X-Swa-Ws
X-Esi
X-Xrds-Location
Ohc-Cache-HIT
X-CSRF-TOKEN
Xc-Version
X-Via-PopH
X-Oss-Storage-Class
X-Oss-Request-Id
X-FTR-Realm
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Oss-Server-Time
X-Via-PopV
X-FTR-Backend
X-Fastly-Request-Id
X-Via-PopN
X-FTR-DC
X-Cache-Backend
X-VC
X-FTR-Backend-Server
X-Country-Code-Real
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Pjax-Url
X-FTR-Cache-Status
X-FTR-Balancer
X-CCM
Redirect-Candidate
X-Tid
X-TIM-N
X-Fpc
X-Request-Start
X-MG-S
X-AB
URI
Mime-Version
Shield-Pop
Cteonnt-Length
X-SN
CountryCode
Tracecode
Server-Ttl
X-Swift-Error
X-FORWARDED-FOR
X-Ua-Browser
X-CUA
Lb
X-Up
CACHE
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Content
X-Varnish-Authentication
X-Air-Pt
X-Yottaa-OS
X-Snapshot-Date
X-LiteSpeed-Cache-Control
X-StackifyID
X-Webstats-RespID
Ohc-Response-Time
Xet-Cookie
X-FTR-Expires
X-DB
X-RPM
X-RPS
X-RSL
X-DW
X-DSS
X-Fastly-Cache-Hits
X-DI
X-Action
X-SB
Instruction
X-Acquia-Purge-Tags
X-Pf-Uncompressing
X-Dw-Trace-Id
X-Region-Sid
X-Cache-Date
X-Amz-Meta-Cb-Modifiedtime
X-Acquia-Site
X-Acquia-Application-UUID
WP-Super-Cache
Is-Us
SR-User-Adfree
Warning
X-ElasticPress-Search
X-Acquia-Application-Trace
Pramga
X-Apw-Access-Token
X-Apw-Access-Object
X-Apw-Hits
X-Apw-Access-Action
X-CCDN-CacheTTL
X-TH-Server
X-Pad
X-UnsetCookies
X-Depends-On
X-C
X-Cache-Expires
X-Tt-Logid
X-MiniProfiler-Ids
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-Mg-Request-Id
Vha6-Origin
ServerName
X-Cache-Status-Check