Threat Level: green Handler on Duty: Russ McRee

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
Link
ETag
Pragma
Expect-CT
X-Powered-By
X-XSS-Protection
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
Alt-Svc
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Timer
X-Download-Options
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-Request-ID
X-Cache-Status
X-Generator
X-Cacheable
X-Ua-Compatible
X-DNS-Prefetch-Control
Timing-Allow-Origin
P3p
X-Content-Security-Policy
X-Iinfo
Status
Feature-Policy
Content-Encoding
X-AspNetMvc-Version
X-CDN
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
Upgrade
Access-Control-Max-Age
X-Drupal-Dynamic-Cache
X-Via
X-Dns-Prefetch-Control
Keep-Alive
X-Ws-Request-Id
Request-Context
Server-Timing
X-Robots-Tag
X-AH-Environment
X-Hacker
X-Server
X-Age
X-Turbo-Charged-By
X-Proxy-Cache
X-Cache-Group
X-Server-Powered-By
X-Backend
X-Amz-Request-Id
Host-Header
X-Amz-Id-2
EagleId
X-Nginx-Cache-Status
Report-To
X-LiteSpeed-Cache
X-Rq
X-Varnish-Cache
X-UA-Device
Grace
X-Page-Speed
X-Pingback
X-Swift-CacheTime
X-Swift-SaveTime
EagleEye-TraceId
Ali-Swift-Global-Savetime
X-Device
X-Vhost
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Amz-Version-Id
NEL
X-Dispatcher
X-OneAgent-JS-Injection
Cf-Railgun
X-Host
X-WebKit-CSP
X-Cache-Spec
X-Server-Id
X-CST
X-Node
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Backend-Server
Allow
Request-Id
Surrogate-Control
X-Readtime
Accept-CH
X-Akam-SW-Version
X-Response-Time
Accept-Ch-Lifetime
Xkey
X-HW
X-Language
X-Ruxit-JS-Agent
X-Template
X-Application-Context
X-Country
X-Ac
Content-Location
X-Cache-Lookup
X-Webkit-CSP
X-Cloud-Trace-Context
Rating
MS-Author-Via
X-Url
X-B3-TraceId
Edge-Control
X-PC
X-TtlSet
X-Vname
X-Mod-Pagespeed
X-Clacks-Overhead
X-Varnish-TTL
X-Trace
Fastly-Restarts
X-Content-Type
X-MS-InvokeApp
X-Rack-Cache
X-Origin-Cache
X-ESI
X-GitHub-Request-Id
X-Buckets
Accept-Ch
X-Cnection
X-Country-Code
X-Goog-Hash
X-D2id
Verso
X-VARITI-CCR
X-Cdn-Fetch
X-Exp-Id
X-Exp-Variant
X-GoogleNews-Bot
X-Kinja
X-Use-Magma
X-Kinja-Revision
X-Kinja-Build
X-Kinja-Server
Arr-Disable-Session-Affinity
X-FastCGI-Cache
X-ORACLE-DMS-ECID
X-Vcap-Request-Id
Cache-Tag
Service-Worker-Allowed
X-Server-Name
X-Cached
X-Abt-Application-Version
X-Server-ID
X-Client-IP
X-Amz-Rid
Accept-CH-Lifetime
X-Navigation-Version
X-Px
RTSS
X-Powered-By-Plesk
X-Cache-TTL
Public-Key-Pins
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Access-Control-Request-Method
X-Element-Page-Cache
X-MSEdge-Ref
X-Powered-CMS
X-Fastly-Request-ID
X-Dw-Request-Base-Id
X-NF-Request-ID
X-Upstream
X-Version
X-Middleton-Display
Response
Display
X-Sol
Pagespeed
X-Middleton-Response
S
X-Ttl
X-TTL
X-Edge-Location-Klb
X-Kinsta-Cache
X-Edge
X-LLID
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Instrumentation
X-Kraken-Loop-Name
X-Kraken-Routeconfig-Destination
X-Server-Lifecycle-Phase
X-Cache-Key
X-Accel-Expires
Realpath
X-Jurisdiction
X-HP-Webp
X-Shield-Request-Id
Pinterest-Version
X-Pinterest-Rid
X-ECACHE
Pinterest-Generated-By
X-T
SPRequestGuid
X-DynaTrace
X-SharePointHealthScore
X-Litespeed-Cache
X-MCACHE
X-Mid
X-PressLabs-Stats
X-ORACLE-DMS-RID
SPIisLatency
SPRequestDuration
X-Correlation-Id
X-Content-Security-Policy-Report-Only
Edge-Cache-Tag
Fastcgi-Cache
X-Mg-S
X-Amz-Server-Side-Encryption
X-XRDS-Location
X-Forwarded-Proto
X-Content-Digest
Nginx-Cache
TP-L2-Cache
TP-Cache
X-Recruiting
Charset
X-Oneagent-Js-Injection
X-Request-Processing-Time
Front-End-Https
X-Request-Received
TCN
Alternate-Protocol
Filters
X-Id
Server-Node
X-Logged-In
X-Forwarded-For
X-Geo-Country
Content-MD5
X-Ezoic-Cdn
Fusion-Content-Source
Fusion-Deployment-Id
Fusion-Template-Id
Fusion-Component-Id
Fusion-Source
Fusion-Content-Id
X-Protected-By
Cache-Tags
X-ASPNET-VERSION
X-Hostname
X-Amzn-Trace-Id
X-Origin-Upstream-Status
X-Grace
X-NWS-LOG-UUID
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Ruxit-Js-Agent
X-F-Cache
X-Debug-Info
Cleartype
X-Www-Served-By
X-Origin-Server
X-Amz-Replication-Status
X-Rid
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
X-LB-Cache
X-HS-Combine-CSS
Host
X-Az
X-AppVersion
X-Activity-Id
X-Contextid
X-Ab
X-RateLimit-Remaining
X-Daa-Tunnel
X-Release
X-Git-Hash
Section-Io-Cache
X-Erf-Bev-Bev
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Page-Id
Server-Name
X-Frontend
X-Ser
X-VCache
MicrosoftSharePointTeamServices
X-Aspnetmvc-Version
X-Cache-Age
X-Content-Options
X-Upgrade-Enabled
Accept-Charset
X-Respond-Thread
Access-Control-Allow-Method
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Hits
ServerID
X-Mobile-URL
X-DIS-Request-ID
X-Source
X-Providence-Cookie
X-CACHE-GROUP
X-B-Cache
X-Is-Crawler
X-Flags
X-Aspnet-Duration-Ms
X-Request-Guid
X-Signature
X-Route-Name
X-WebKit-CSP-Report-Only
X-Varnish-Age
X-Cache-Action
Viewport
X-FB-Debug
X-Varnish-Backend
X-Whom
Healthy
X-TT
Paypal-Debug-Id
X-Varnish-Grace
Payment
X-Fastcgi-Cache
DynaTrace
X-B3-Sampled
Node
X-AOL-HN
X-App-Environment
Fastcgi-Useragent
X-Yandex-Sdch-Disable
X-Load-Cache
X-Mobile
Version
X-Seen-By
DC
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-N
Filterid
X-Distributor
X-XRDS-LOCATION
SRV
X-HTML-Minification-Powered-By
X-Type
X-Cache-Control
X-Tec-Api-Root
X-Tec-Api-Version
X-User-Agent
Retry-After
X-Tec-Api-Origin
Frame-Options
MS-CV
X-Jobs
Refresh
X-Response-Served-From
X-Original-Request-Id
X-Cache-Expired-At
X-FW-Static
X-FW-Type
X-UUID
X-FW-Server
X-FW-Hash
X-FW-Serve
X-FW-Dynamic
Amp-Access-Control-Allow-Source-Origin
X-Page-View
X-Adobe-Content
NGB
X-Proxy-Cache-Status
X-Adobe-Loc
X-Debug-IsConnected
X-Debug-IsPreview
X-Region
X-Varnish-Server
X-Instance
X-Real-IP
X-Tumblr-Pixel
X-RemovedCookies
X-IPLB-Instance
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Vgn-Hpd-Reason
X-NGENIX-Cache
X-Tumblr-User
Access-Control-Request-Headers
X-G
X-ProcessESI
X-Cluster-Name
X-B
X-Cacheable-TTL
X-Proxy
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Azure-Ref
X-Node-Name
X-Content-Powered-By
X-Framework
X-Device-Type
X-Cache-Time
X-CDN-Forward
X-RTag
Ms-Operation-Id
X-IPS-LoggedIn
Uber-Trace-Id
X-HP-Trace-Id
X-Zen-Fury
X-Cache-Hit
X-Cache-Rule
X-Aws-Lambda-Call-Status
SD-X-WS
Cache-Status
Referer-Policy
Liferay-Portal
X-Rendered-As
X-Wix-Request-Id
X-Is-Bot
X-Ms-Version
X-Ms-Request-Id
Countrycode
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
Section-Io-Id
X-Time
Section-Io-Origin-Status
X-Drupal-Cache-Tags
X-Oracle-Dms-Rid
X-Mg-Request-UUID
X-Parallel-Accel
X-Request-Handler-Origin-Region
X-Microsite
AR-ATIME
AR-CACHE
AR-Request-ID
AR-PoweredBy
Ar-Sid
X-Debug
X-Nginx-Cache
X-EdgeConnect-Cache-Status
X-Accel-Buffering
S-Cnection
X-Revision
X-App-Server
X-RateLimit-Limit
Country
X-L-Path
X-Environment-Context
CF-IPCountry
X-Yottaa-Optimizations
X-Yottaa-Metrics
Cache
X-Cache-Operation
Count-Hit
X-Drupal-Cache-Contexts
X-APP-VERSION
X-TA-CDN-Provider
X-JoinUs
X-ES-SERVER
X-GG-Cache-Date
X-Endurance-Cache-Level
X-RN-RSRV
X-FW-Version
X-TNCMS
X-Loop
Meta-Geo
Surrogate-Key
X-UPSTREAM-Address
X-SaId
X-LAGOON
From-Origin
X-Cache-Type
X-Cache-TTL-Remaining
X-Say-Cacheable
X-Adobe-Source
X-App-Version
Akamai-GRN
X-SayCDN-TTL
X-Say-TTL
Protected
X-Request-Time
X-Human
Azure-RegionName
GEO-INFO
Eomportal-Instance
X-Sorting-Hat-ShopId
X-Sql-Duration-Ms
X-S-Maxage
Azure-SiteName
Country-Code
X-Storefront-Renderer-Rendered
X-Varnish-Beresp-Grace
Azure-Version
X-Sql-Count
X-Shopify-Stage
X-ShopId
Azure-InstanceId
X-Sorting-Hat-PodId
X-ShardId
X-NYM-Debug-Backend
Azure-SlotName
X-Alternate-Cache-Key
X-AWS-Id
Apigw-Requestid
X-Be
X-BYPASS-REASON
Cache-Tv-Group
Decoy-Debug-Key
X-PHP-Host
ServedBy
X-FireWall-Port
X-Handled-By
Decoy-Debug-Status
X-Status
Decoy-Debug-TTL
X-Pubstack
X-ProxyCache-Key
X-Proto
X-ProxyCache-Status
X-Varnish-Hostname
X-Varnishpool
X-No-Session
X-R9-Blue-Green-Version
X-LJ-Flow-ID
X-Labrador-Cache-Channel
X-Hosted-By
X-PCL
X-OCL
Cache-Name
X-RCS-CacheZone
X-VWS-Id
X-Origin-Date
Fastly-SSL
Selected-Fe
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-Country
TWC-GeoIP-LatLong
X-Xfnlog-Site
X-UA-Device-Type
X-PHP-Backend
X-Uri
X-Origin-Hint
X-Tumblr-Pixel-2
X-Timing-Wait
X-Proxy-Build
Property-Id
X-Server-W
X-Section
X-Via-Fastly
X-Web-Node
X-Access
Webcakes-Region
Webcakes-App-Version
Webcakes-App-Name
X-Akamai-Edgescape
X-Cache-Server
X-Redis-Cache
X-Hyper-Cache
X-Format
TWC-Privacy
TWC-Locale-Group
X-Backend-Host
X-PERF
Nel
X-ApacheServer
Mn-Server-Ip
X-FB-TRIP-ID
X-Cluster-Node
X-Time-Microsecs
X-Backend-Name
X-Ua-Device
X-Hl-Ver
X-Servername
OT-Force-Account-Verify
X-ATG-Version
X-B3-SpanId
X-ServerID
Cross-Origin-Opener-Policy
X-Tumblr-Pixel-3
X-Detected-As
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Azure-Ref-OriginShield
X-Cache-PHP
X-TEC-API-ORIGIN
Web-Mar-Node
Backend
X-Content-Age
X-Generation-Time
Cross-Origin-Window-Policy
X-Varnish-Cache-Hits
X-Cache-Host
Xserver
X-Ua
X-CSRF-Token
X-Trace-Id
X-Datadome
X-Varnish-Hits
X-WA-Info
X-MP-GENERATED-AT
Content-Secure-Policy
X-TT-LOGID
Ec-Rule-Version
X-Via-JSL
X-Bc-Bl
X-Cdn
X-Akamai-Transformed
X-Soup
Source
X-CS
X-Cache-Enabled
X-Ratelimit-Limit
X-Edge-Location
X-Amzn-Remapped-Content-Length
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Mode
X-Microcachable
X-SRV
X-Cache-Grace
X-Info
X-Rule
X-NWS-UUID-VERIFY
Upgrade-Insecure-Requests
S-Rt
X-Air-Source
X-Air-Trace-Id
X-Air-Hostname
X-Forwarded-Host
Url
X-Locale
X-Origin-TTL
X-Origin-CC
X-Unique-Id
X-B3-Traceid
X-Varnish-Beresp-Status
X-Cached-By
X-GEO
X-Site-Version
SID
X-Dc
X-Tb
X-Magnolia-Registration
X-Varnish-Beresp-Ttl
M-TraceId
Meta-Geo-Continent
X-Shop-Environment
Rendered-Blocks
X-Session-Fingerprint
Mobile-Detection-Method
Odigeo-Trace-Id
Path
Host-ID
MD5-Digest
X-Vdms-Version
CDCHOST
CDN-Cache
X-VG-WebCache
CDN-CachedAt
BehaviorPad-Version
Apple-News-Services-Request-Url
A
Apple-News-Services-Handled
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
CDN-EdgeStorageId
CDN-PullZone
X-SRCache-Key
Expiry
Fastcgi-X-Cache-Version
Fastly-SIE
DCR-Processing-Time-Ms
X-Tenant
CDN-RequestCountryCode
CDN-RequestId
CDN-Uid
DCR-Decision-By
Fastly-SWR
X-Zipkin-Id
X-Ftr-Request-Id
X-From
X-NAPM-TraceId
X-NU-AKA-ACS-Version
X-S
X-Forwarded-Path
X-Extlb
X-Destination
X-S-Cookie
X-Developer
X-Epic-Correlation-Id
X-External-Request-Id
X-Orig-Expires
X-PAYTM-SRV-ID
X-Request-URI
X-Rebelmouse-Surrogate-Control
X-Routing-Service
X-Rewrite-Enabled
X-Rojux
X-Rebelmouse-Cache-Control
X-Ratelimit-Reset
X-Platform-Server
X-PBS-Appsvrname
X-Vtex-Remote-Cache
X-Processor
X-Proxied
X-ScT
X-Debug-Cache
X-A-Dgt
X-A-Dcw
X-A-Wwc
X-Aed
X-Aicache-OS
X-A-Dam
X-A-Ccd
Surrogated-Key
State
X-Vtex-Processado-Em
T-Server
X-A
X-AIR-PT
X-Application
X-CF-Lambda-Version
X-Cache-NE
X-Conf
X-Connection-Hash
X-D
X-Cache-Bucket
X-VG-WebServer
X-ARC
X-B-Cookie
X-BBC-Edge-Cache-Status
X-BCube-Filmed-By
Req-Svc-Chain
X-CF-Lambda-Fn
User-Cache-Control
X-Storage
X-Cache-NGX
X-DataDome
X-EC-Lua
X-Clientip
X-Clara-WADP
X-Cache-Info
X-Cms-Context
X-Core-Value
X-Envoy-Decorator-Operation
X-DPWN-IS-SECURE
X-Date
X-Cache-Debug
L
UCS
Origin
Platform
NGX
X-Accel-Expires-Debug
X-Backend-State
X-Fastly-Backend
Pics-Label
X-Has-Esi
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Service
X-Request-UUID
X-TrackingId
X-Variation
X-WADP-Cache
X-VServer
X-VG-TLSProxy
X-Proxy-Upstream
X-Men
X-Is-Gdpr
Is-Eu
X-Fmm-Version
X-JWT-State
X-Li-Fabric
X-Loc
X-LI-UUID
X-Li-Pop
X-Fastly-Cache
X-Origin-Expires
Fastly-Drupal-HTML
Cmstype
Fastly-Backend-Name
Cache-Host
Cache-Key
Cmsid
Content-Disposition
Adler-Geo
AMP-Access-Control-Allow-Source-Origin
X-Ratelimit-Remaining
X-Thinkindot-L3
X-Viewer-Country
X-Gzip
X-Gamma-Serve
X-Forwarded-Site
X-Ua-Browser
X-Via-NSCOPI
X-Hash
X-Gen-Mode
X-Slack-Backend
DSUID
X-Wikidot-Static-Cache
X-Generated-On
X-Geo-Header
X-GoCache-CacheStatus
X-Wikidot-Backend
VNS-Age
X-Generated-By
Vix-Hermes-Req-Id
X-Bip
VNS-Cache
X-Cache-Id
X-Esi-Check
X-Varnish-CookieHashed-On
Cf-Device-Type
X-Varnish-CookieINHashed-On
X-DefElseHash
X-DefHash
X-Thanos
X-Device-Os
X-Developers
X-Var-Ttl
X-Varnish-Remaining-TTL
X-Cluster
CPC-Cache
X-HN
X-VC-Cache
X-Branch-Name
X-Cache-Tags
X-VarnishDD-TTL
CPC-Age
X-Ckpd-Fst-Backend
X-Content
X-Block-Status
X-Worker
X-Location
C-Via
X-Micro-Cache
X-Rocket-Build-Number
PB-PID
PB-RID
X-Scheme
X-Level-Front-Cache
Fastcgi-Cache-TTL
True-Client-Country-4JS
X-Nginx-Cache-Key
X-Request-Host
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
IsBot
Arc-Version
Location
Locid
X-Req
X-Old-Content-Length
X-Origin
X-Tx-Id
PFcat
X-Sigma-Backend
Sever-Int
Thinkindot-Control
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-SIPLIST1
TDXMobile
Esi-Enabled
X-Hnp-Log
X-Sigma
X-Served-From
Server-Ext
Server-Hostname
Server-Host
X-Amz-Meta-S3cmd-Attrs
X-DC
X-Platform
Server-Info
X-Eu-Site
X-NCache
X-Planisys-CDN-TTL
X-M-Log
X-Planisys-CDN-Rules
X-Owner
X-Planisys-CDN-Cache
Arc-Country
X-FC-Vary-Parameters
X-Generated-In
X-Irp-Debug
X-Fetched-On
CacheControlHeader
X-Sucuri-ID
X-Mvc-Supplant-Cachable
X-GeoIP-City
X-GeoIP
X-Skip-Cache
AKAMAI
X-Goog-Meta-Goog-Reserved-File-Mtime
X-CGP
V-Age
Svr
We-Hiring
Wxu-Next-Commit
Wxu-Next-Region
Wxu-Next-Hostname
Pagetype
NM-Fastcgi-Cache
Ha-Gx-Prefs
Gh-Request-Id
HA-Ipaddr
L5d-Success-Class
Memcached
Mail-Subject
X-Auto-Login
Release
X-Csrf-Jwt
X-M-Reqid
X-Policy
X-Vdms-Path
Webserver
DataCenter
X-Qnm-Cache
NtCoent-Length
X-HS-Content-Campaign-Id
Kp-EeAlive
X-V-Cache
X-Qloud-Router
X-Srv
X-Unique-ID
XServer
X-Platform-Router
Cache-Hits
X-Rocket-Nginx-Serving-Static
X-Platform-Processor
X-Render-Time
X-Servedbyhost
X-Mvc-Supplant-OutputCached
X-LSADC-Cache
X-Platform-Cluster
X-Zone
X-Via-Popv
X-Via-Popn
X-SD-PageType
X-User
MIME-Version
X-Via-Poph
Who
X-Cache-Remote
X-Cache-Ttl
X-PF-Uncompressing
X-NC
Environment
X-Cache-Var-Map
X-ID
X-Cache-Var
X-BBC-Origin-Response-Status
X-Nyt-Route
X-Origin-Time
X-NodeID
X-PJAX-URL
X-Datadog-Sampling-Priority
X-Vc
X-Traceid
X-Wa
X-Datadog-Trace-Id
X-Varnish-Url
X-API-Version
X-Minions-Version
X-Gdpr
X-Datadog-Parent-Id
WebServer
X-Varnish-Ttl
Cluster
X-Via-Ucdn
X-Refresh
X-LB-ID
X-App
X-Cache-Config
X-Internal-Host
Memory
X-Server-IP
Candidate-Md5Url
Server-ID
Powered-By-ChinaCache
X-Webkit-Csp
Time
My-App
X-TIME
X-Pod-Name
X-ZONE
X-CACHE-KEY
X-Webkit-CSP-Report-Only
HostName
X-VCL-Version
X-Pass-Why
Geoip-Latitude
X-Newrelic-Synthetics
X-Esi
N-Cache
Web-Mar-Region
Datacenter
X-CLOUD-TRACE-CONTEXT
GeoIp-Country-Code
X-NewRelic-App-Data
Onion-Location
X-TX-ID
X-OVcl-Cache
X-LI-Proto
X-Edge-Pop
Geo-Info
Resin-Trace
X-Correlation-ID
X-OVcl
X-Tb-Optimization-Total-Bytes-Saved
X-ElasticPress-Query
X-VHOST
X-TraceId
Servername
Cf-Bgj
Hostname
X-Akamai-Pragma-Client-IP
Tcn
X-Backend-TTL
Ohc-File-Size
X-Varnish-Cacheable
X-Dynatrace
X-HITS
X-Origin-Response-Time
X-CACHE-AGE
Magicmarker
X-Varnish-Beresp-TTL
X-Tt-Logid
X-Li-Proto
WWW-Authenticate
CDN
X-EIG-Tracking-Id
X-Geo
X-NODE
X-Dispatcher-Server
X-Method
X-AB
X-MSEdge-Features
X-Fpc
X-Tid
Proxy-Connection
X-TIM-N
Redirect-Candidate
X-Wix-Viewer-Type
X-MSEdge-Flight
LB
X-Dynatrace-Js-Agent
GeoIP-Country-Code
DB-Nickname
X-HostName
Cdn
Tracecode
X-IP
GeoIP-Latitude
Ssr
X-Vcl-Version
X-Fastly-Request-Id
X-Cs
Cf-Ipcountry
Is-Us
Server-Id
X-Fastly-Backend-Reqs
X-Up
Pramga
X-Cache-Date
X-Request-Start
Lb
X-HS-Status
CF-Cached-On
X-Cdn-Origin
X-APP
X-COUNTRY
Sid
X-Sn-Servicetimems
X-Amz-Meta-Cb-Modifiedtime
X-Node-Id
X-MG-S
X-NGINX-Cache
X-ServerName
X-ND-Cache
Cteonnt-Length
X-WA
X-Core-Mission
W
X-Provided-By
X-CSRF-TOKEN
X-Trv-Group
X-Webkit-Csp-Report-Only
X-Nc
X-UnsetCookies
X-FORWARDED-FOR
WZWS-RAY
X-Cache-Expires
X-Via-CDN
X-DynaTrace-JS-Agent
CloudFront-Viewer-Country
URI
Env
X-Via-PopV
X-Check-Cacheable
X-Via-PopN
X-Via-PopH
X-Lb-Id
X-VC
X-Pjax-Url
Ohc-Cache-HIT
X-SERVER-NAME
X-Cache-Backend
X-Reqid
WP-Super-Cache
Mime-Version
X-ECache
X-Region-Sid
X-Sucuri-Cache
Shield-Pop
X-CCDN-Origin-Time
X-Cache-Status-Check
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-SN
X-Pf-Uncompressing
X-IN-APIGATEWAYSSL
CountryCode
X-IN-APIGATEWAY
X-ServedByHost
Viewtype
Rt-Fastcgi-Cache
X-Acquia-Site
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
X-Edge-POP
X-Moov-T
X-Moov-Xdn-Version
Xc-Version
CACHE
X-CUA
X-RAMCache
X-LiteSpeed-Cache-Control
VivaBuild
Server-Ttl
X-Pad
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Varnish-Authentication
X-Fastly-Cache-Hits
X-B3-Spanid
X-DB
X-DI
X-Cdn-Request-ID
X-SB
X-Action
X-Ig-Push-State
EpKe-Alive
Vha6-Origin
X-DSS
User-Agent
Ohc-Response-Time
X-Yottaa-OS
X-Swift-Error
X-RPS
Xet-Cookie
X-Dw-Trace-Id
X-Webstats-RespID
X-StackifyID
X-DW
X-RPM
X-RSL
X-Cdn-Forward
HIT
X-UP
X-FPC
X-Amz-Meta-Opti
FSS-Cache
X-MiniProfiler-Ids
Content-Script-Type
Content-Style-Type
Req-ID
X-TH-Server
ServerName
X-CF-Powered-By
X-ElasticPress-Search
Machine