Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
Link
X-XSS-Protection
ETag
Pragma
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
P3P
X-UA-Compatible
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Xss-Protection
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
P3p
X-Cacheable
X-Request-ID
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Content-Security-Policy
X-Iinfo
Status
X-Ua-Compatible
Feature-Policy
Content-Encoding
X-AspNetMvc-Version
X-CDN
X-Envoy-Upstream-Service-Time
X-Dns-Prefetch-Control
Access-Control-Expose-Headers
Upgrade
X-Drupal-Dynamic-Cache
Access-Control-Max-Age
X-Via
Keep-Alive
X-Ws-Request-Id
Server-Timing
Request-Context
X-Robots-Tag
X-AH-Environment
X-Hacker
X-Server
X-Age
X-Turbo-Charged-By
X-Proxy-Cache
X-Cache-Group
X-Server-Powered-By
X-Backend
X-Amz-Request-Id
X-Amz-Id-2
Host-Header
EagleId
X-Nginx-Cache-Status
Report-To
X-Rq
X-Varnish-Cache
X-LiteSpeed-Cache
Grace
X-UA-Device
X-Page-Speed
X-Pingback
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
EagleEye-TraceId
X-Device
X-Vhost
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Amz-Version-Id
NEL
X-Dispatcher
X-OneAgent-JS-Injection
Cf-Railgun
X-WebKit-CSP
X-Host
X-Cache-Spec
X-CST
X-Server-Id
X-Node
X-Backend-Server
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Allow
Request-Id
Surrogate-Control
Accept-CH
X-Readtime
X-Akam-SW-Version
X-Response-Time
Accept-Ch-Lifetime
Xkey
X-Language
X-HW
X-Template
X-Application-Context
X-Country
Content-Location
X-Ac
X-Cloud-Trace-Context
X-Cache-Lookup
Rating
X-Ruxit-JS-Agent
MS-Author-Via
X-Url
X-Webkit-CSP
Edge-Control
X-Clacks-Overhead
X-PC
X-TtlSet
X-Vname
X-Mod-Pagespeed
X-Varnish-TTL
X-Trace
Fastly-Restarts
X-B3-TraceId
X-Content-Type
X-Rack-Cache
X-Buckets
X-MS-InvokeApp
X-Origin-Cache
X-ESI
X-GitHub-Request-Id
X-Cnection
X-Country-Code
X-Goog-Hash
Accept-Ch
X-D2id
Verso
X-VARITI-CCR
X-Server-ID
Accept-CH-Lifetime
Arr-Disable-Session-Affinity
X-FastCGI-Cache
X-Exp-Id
X-Cdn-Fetch
X-Exp-Variant
X-Kinja
X-Use-Magma
X-Kinja-Server
X-Kinja-Build
X-GoogleNews-Bot
X-Kinja-Revision
Cache-Tag
X-Vcap-Request-Id
X-Cached
Service-Worker-Allowed
X-ORACLE-DMS-ECID
X-Px
X-Abt-Application-Version
X-Server-Name
X-Client-IP
X-Amz-Rid
X-Navigation-Version
Public-Key-Pins
X-Cache-TTL
X-SRCache-Store-Status
RTSS
X-SRCache-Fetch-Status
X-Powered-By-Plesk
Access-Control-Request-Method
X-MSEdge-Ref
X-TTL
X-Element-Page-Cache
X-Fastly-Request-ID
X-Dw-Request-Base-Id
X-Powered-CMS
X-NF-Request-ID
X-Version
X-Upstream
X-Litespeed-Cache
X-Middleton-Display
X-Sol
Response
Display
X-Middleton-Response
Pagespeed
S
X-Kinsta-Cache
X-Edge-Location-Klb
X-Edge
X-LLID
X-Instrumentation
X-Kraken-Routeconfig-Destination
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
MRF-Tech
X-Cache-Key
Mrf-Cache-Status
X-B3-TraceId-Primal
X-ECACHE
X-Accel-Expires
X-Shield-Request-Id
X-Jurisdiction
X-HP-Webp
X-Correlation-Id
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
Realpath
X-Ttl
X-T
X-XRDS-Location
X-DynaTrace
X-SharePointHealthScore
SPRequestGuid
X-MCACHE
X-Mid
Edge-Cache-Tag
X-Content-Security-Policy-Report-Only
SPRequestDuration
SPIisLatency
X-ORACLE-DMS-RID
Fastcgi-Cache
X-Amz-Server-Side-Encryption
X-PressLabs-Stats
X-Mg-S
X-Ruxit-Js-Agent
Nginx-Cache
X-Content-Digest
X-Forwarded-Proto
X-Recruiting
TP-L2-Cache
TP-Cache
Front-End-Https
X-Request-Processing-Time
X-Request-Received
TCN
Charset
Alternate-Protocol
Server-Node
X-Id
X-Logged-In
X-Oneagent-Js-Injection
Content-MD5
X-Forwarded-For
X-Geo-Country
Filters
Fusion-Source
Fusion-Template-Id
Fusion-Deployment-Id
X-Ezoic-Cdn
Fusion-Component-Id
Fusion-Content-Id
Fusion-Content-Source
X-Protected-By
Cache-Tags
X-Hostname
X-ASPNET-VERSION
X-Amzn-Trace-Id
X-NWS-LOG-UUID
X-Grace
X-Origin-Upstream-Status
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Debug-Info
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Ab
X-F-Cache
Cleartype
X-Www-Served-By
X-LB-Cache
X-Amz-Replication-Status
X-Origin-Server
X-Rid
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
X-AppVersion
X-Activity-Id
X-HS-Combine-CSS
X-Az
Host
X-Contextid
X-Daa-Tunnel
X-Git-Hash
X-Page-Id
Section-Io-Cache
Server-Name
X-RateLimit-Remaining
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-VCache
X-Content-Options
X-Frontend
X-Cache-Age
X-Ser
X-Upgrade-Enabled
MicrosoftSharePointTeamServices
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Release
Access-Control-Allow-Method
Accept-Charset
X-Aspnetmvc-Version
ServerID
X-Hits
X-Mobile-URL
X-Source
X-DIS-Request-ID
X-Is-Crawler
X-Flags
X-Request-Guid
X-Route-Name
X-Providence-Cookie
X-Varnish-Age
X-Aspnet-Duration-Ms
X-Signature
X-Cache-Action
X-B-Cache
X-B3-Sampled
Viewport
Healthy
Payment
X-FB-Debug
X-Varnish-Backend
X-Varnish-Grace
X-Whom
Paypal-Debug-Id
Fastcgi-Useragent
X-TT
X-AOL-HN
X-Yandex-Sdch-Disable
X-App-Environment
X-Respond-Thread
Node
X-CACHE-GROUP
X-WebKit-CSP-Report-Only
DynaTrace
X-Load-Cache
X-Mobile
X-Fastcgi-Cache
X-Tt-Trace-Host
X-Tt-Trace-Tag
DC
Filterid
X-Seen-By
Version
X-Distributor
X-N
SRV
X-User-Agent
X-Cache-Control
X-HTML-Minification-Powered-By
Frame-Options
Retry-After
X-Type
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
X-HP-Trace-Id
X-Jobs
Refresh
MS-CV
X-FW-Server
X-FW-Serve
X-FW-Hash
X-FW-Dynamic
X-FW-Static
X-FW-Type
Amp-Access-Control-Allow-Source-Origin
X-Ua-Device
X-Original-Request-Id
X-Response-Served-From
X-NGENIX-Cache
X-Cache-Expired-At
X-UUID
X-Proxy-Cache-Status
X-Adobe-Content
X-Node-Name
X-Azure-Ref
X-Page-View
NGB
X-Adobe-Loc
X-Instance
X-Real-IP
X-Debug-IsConnected
X-Debug-IsPreview
X-XRDS-LOCATION
X-G
X-ProcessESI
X-IPLB-Instance
X-Cluster-Name
VIX-Pulpo-Upstream-Status
X-B
X-Cacheable-TTL
VIX-Pulpo-Node
X-Region
X-Tumblr-User
X-Varnish-Server
X-Vgn-Hpd-Reason
X-RemovedCookies
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Aws-Lambda-Call-Status
Ms-Operation-Id
Access-Control-Request-Headers
X-Device-Type
X-RTag
X-Content-Powered-By
X-CDN-Forward
X-Cache-Time
X-Framework
X-Proxy
X-Oracle-Dms-Rid
X-Zen-Fury
X-Cache-Hit
X-IPS-LoggedIn
Referer-Policy
X-Cache-Rule
Uber-Trace-Id
Liferay-Portal
SD-X-WS
X-Parallel-Accel
Cache-Status
X-Is-Bot
X-Rendered-As
X-Drupal-Cache-Tags
X-Ms-Request-Id
X-Ms-Version
X-Wix-Request-Id
X-Time
X-EdgeConnect-Cache-Status
Countrycode
X-Mg-Request-UUID
X-App-Server
Section-Io-Id
Section-Io-Origin-Status
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
X-RateLimit-Limit
X-Debug
X-L-Path
X-Revision
X-Environment-Context
S-Cnection
X-Yottaa-Optimizations
X-Yottaa-Metrics
Country
CF-IPCountry
X-Accel-Buffering
X-B3-Traceid
Count-Hit
X-Cache-Operation
X-TA-CDN-Provider
X-Nginx-Cache
X-APP-VERSION
X-Request-Handler-Origin-Region
X-Microsite
X-Drupal-Cache-Contexts
X-FW-Version
Cache
AR-Request-ID
Meta-Geo
X-JoinUs
X-SaId
AR-PoweredBy
Ar-Sid
X-Endurance-Cache-Level
X-ES-SERVER
X-GG-Cache-Date
AR-ATIME
X-UPSTREAM-Address
X-RN-RSRV
AR-CACHE
X-LAGOON
X-Adobe-Source
X-SayCDN-TTL
Surrogate-Key
GEO-INFO
X-Say-TTL
X-TNCMS
X-Loop
X-Cache-Type
X-Cache-TTL-Remaining
X-Say-Cacheable
Akamai-GRN
From-Origin
Fastly-SSL
X-Human
Azure-SiteName
X-NYM-Debug-Backend
X-Sql-Duration-Ms
Azure-InstanceId
Azure-RegionName
X-Sql-Count
X-R9-Blue-Green-Version
X-Varnish-Beresp-Grace
Azure-Version
X-S-Maxage
Country-Code
Azure-SlotName
X-Request-Time
ServedBy
X-OCL
X-PCL
X-AWS-Id
X-Storefront-Renderer-Rendered
X-Status
Protected
X-Alternate-Cache-Key
X-Labrador-Cache-Channel
X-No-Session
Apigw-Requestid
X-PHP-Host
X-RCS-CacheZone
X-Sorting-Hat-ShopId
X-VWS-Id
X-Pubstack
X-ProxyCache-Status
X-Varnish-Hostname
X-Varnishpool
X-Origin-Date
X-ProxyCache-Key
X-Proto
Cache-Name
X-Hosted-By
X-Handled-By
X-B3-SpanId
X-ShardId
X-LJ-Flow-ID
X-Sorting-Hat-PodId
X-Shopify-Stage
X-ShopId
X-BYPASS-REASON
Decoy-Debug-Status
Decoy-Debug-Key
Decoy-Debug-TTL
Property-Id
Selected-Fe
X-Via-Fastly
X-Web-Node
X-Xfnlog-Site
X-Proxy-Build
X-Server-W
X-UA-Device-Type
X-Redis-Cache
X-Tumblr-Pixel-2
X-Origin-Hint
X-Timing-Wait
X-Format
X-Be
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Device-Class
TWC-Locale-Group
TWC-Privacy
X-Akamai-Edgescape
Webcakes-App-Version
Webcakes-App-Name
TWC-Connection-Speed
Webcakes-Region
Cache-Tv-Group
X-App-Version
Mn-Server-Ip
X-Hyper-Cache
X-Cache-Server
X-Access
X-Backend-Host
X-PERF
X-Section
X-Cluster-Node
Eomportal-Instance
X-ApacheServer
X-PHP-Backend
X-Uri
X-Time-Microsecs
X-FB-TRIP-ID
Cross-Origin-Opener-Policy
X-Backend-Name
X-Hl-Ver
X-Servername
X-ServerID
Nel
OT-Force-Account-Verify
X-ATG-Version
X-Tumblr-Pixel-3
X-TEC-API-VERSION
X-FireWall-Port
X-Detected-As
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Azure-Ref-OriginShield
Cross-Origin-Window-Policy
Web-Mar-Node
X-Varnish-Cache-Hits
X-Cache-Host
X-Generation-Time
X-Cache-PHP
X-Ua
Ec-Rule-Version
X-Varnish-Hits
X-Content-Age
Content-Secure-Policy
X-TT-LOGID
Backend
X-Via-JSL
Source
X-SRV
X-CS
X-Datadome
X-Trace-Id
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Air-Hostname
X-Forwarded-Host
X-Air-Trace-Id
X-Air-Source
Upgrade-Insecure-Requests
X-WA-Info
X-Akamai-Transformed
X-Mode
X-CSRF-Token
X-MP-GENERATED-AT
X-Cache-Grace
X-Microcachable
X-Soup
X-Ua-Browser
Xserver
X-Content
X-Locale
X-Cache-Enabled
X-Edge-Location
X-Cdn
X-Unique-Id
X-Amzn-Remapped-Content-Length
Url
X-Rule
X-NWS-UUID-VERIFY
X-Varnish-Beresp-Ttl
X-Ratelimit-Limit
X-Bc-Bl
X-Info
X-Origin-TTL
X-Origin-CC
X-Site-Version
X-Tenant
X-Ratelimit-Remaining
X-GEO
X-Varnish-Beresp-Status
X-Routing-Service
X-Zipkin-Id
Content-Disposition
SID
X-Proxied
X-Extlb
X-DataDome
X-Tb
S-Rt
X-Magnolia-Registration
X-External-Request-Id
X-Forwarded-Path
Apple-News-Services-Request-Url
BehaviorPad-Version
X-Ftr-Request-Id
Apple-News-Services-Parsed-Url
A
Apple-News-Services-Handled
X-Epic-Correlation-Id
X-From
Apple-News-Services-Host
X-Conf
X-B-Cookie
X-ARC
Rendered-Blocks
Req-Svc-Chain
X-BBC-Edge-Cache-Status
Path
Meta-Geo-Continent
Mobile-Detection-Method
Odigeo-Trace-Id
X-BCube-Filmed-By
X-Application
X-AIR-PT
T-Server
X-A-Dam
X-A-Ccd
X-A
Surrogated-Key
X-A-Dcw
X-Aicache-OS
X-Aed
X-A-Wwc
X-A-Dgt
X-Cache-Bucket
MD5-Digest
CDN-Uid
X-Developer
X-Destination
DCR-Decision-By
CDN-RequestId
CDN-RequestCountryCode
CDN-Cache
CDN-CachedAt
CDN-EdgeStorageId
CDN-PullZone
DCR-Processing-Time-Ms
X-Debug-Cache
Host-ID
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-Cache-NE
X-Connection-Hash
Fastly-SWR
Expiry
X-D
Fastcgi-X-Cache-Version
Fastly-SIE
CDCHOST
X-NU-AKA-ACS-Version
X-Session-Fingerprint
X-Orig-Expires
X-Shop-Environment
X-VG-WebCache
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
X-Rewrite-Enabled
User-Cache-Control
X-PBS-Appsvrname
X-Platform-Server
X-PAYTM-SRV-ID
X-ScT
X-VG-WebServer
X-Processor
X-Vdms-Version
X-S
X-S-Cookie
X-Rojux
X-Storage
X-Request-URI
X-Tx-Id
X-NAPM-TraceId
X-Rebelmouse-Surrogate-Control
X-SRCache-Key
X-Ratelimit-Reset
X-Rebelmouse-Cache-Control
X-Dc
X-EC-Lua
Pics-Label
X-DPWN-IS-SECURE
X-Cache-NGX
X-Envoy-Decorator-Operation
X-Service
L
Is-Eu
NGX
X-TrackingId
X-Variation
X-Cache-Debug
X-Cache-Info
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Date
X-Li-Fabric
X-Cached-By
Origin
Fastly-Drupal-HTML
X-Core-Value
X-Backend-State
Cache-Host
X-Request-UUID
State
X-M-Log
X-Accel-Expires-Debug
X-Men
X-Worker
X-Li-Pop
UCS
X-LI-UUID
X-Loc
X-VServer
X-M-Reqid
X-Fastly-Cache
X-Proxy-Upstream
Platform
X-VG-TLSProxy
X-Micro-Cache
Adler-Geo
X-Origin-Expires
Cache-Key
XServer
X-Qnm-Cache
X-NCache
VNS-Cache
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
VNS-Age
X-Branch-Name
X-Varnish-CookieHashed-On
X-Bip
X-Wikidot-Backend
X-VC-Cache
X-Via-NSCOPI
X-Wikidot-Static-Cache
X-Viewer-Country
X-VarnishDD-TTL
X-Block-Status
X-Auto-Login
X-Scheme
X-DefElseHash
X-Gen-Mode
X-Nginx-Cache-Key
X-Generated-By
X-Gamma-Serve
Vix-Hermes-Req-Id
X-Forwarded-Site
X-Origin
X-Old-Content-Length
X-Generated-On
X-Gzip
X-Is-Gdpr
X-JWT-State
X-Level-Front-Cache
X-Hnp-Log
X-Location
X-Has-Esi
X-HN
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Cms-Context
X-Slack-Backend
X-SIPLIST1
X-Cluster
X-Clientip
X-Thinkindot-L3
X-Ckpd-Fst-Backend
X-Thanos
X-Sigma-Backend
X-Sigma
X-Esi-Check
X-Req
X-Fastly-Backend
X-Rocket-Build-Number
X-Device-Os
X-DefHash
X-Served-From
X-Cache-Id
X-Cache-Tags
C-Via
PFcat
X-DC
Server-Ext
Server-Hostname
Location
PB-RID
PB-PID
M-TraceId
Locid
IsBot
Arc-Version
CPC-Age
Sever-Int
Server-Host
Thinkindot-Control
Cmsid
True-Client-Country-4JS
Cmstype
CPC-Cache
Thinkindot-CacheControl-Type
Esi-Enabled
Fastly-Backend-Name
Thinkindot-CacheControl
TDXMobile
X-Amz-Meta-S3cmd-Attrs
AMP-Access-Control-Allow-Source-Origin
X-Platform
X-Generated-In
X-GeoIP
X-Geo-Header
X-Fetched-On
Cf-Device-Type
CacheControlHeader
X-Developers
X-Eu-Site
X-LSADC-Cache
Webserver
X-Planisys-CDN-Cache
X-Sucuri-ID
X-Owner
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Request-Host
X-Policy
X-Var-Ttl
X-Vdms-Path
X-Skip-Cache
X-Hash
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Irp-Debug
Svr
X-Mvc-Supplant-Cachable
Arc-Country
X-GeoIP-City
X-FC-Vary-Parameters
Memcached
HA-Ipaddr
Server-Info
Pagetype
Mail-Subject
DSUID
X-CGP
Release
L5d-Success-Class
Gh-Request-Id
Ha-Gx-Prefs
X-Csrf-Jwt
V-Age
Fastcgi-Cache-TTL
Wxu-Next-Commit
We-Hiring
Wxu-Next-Region
NM-Fastcgi-Cache
Wxu-Next-Hostname
X-Render-Time
X-HS-Content-Campaign-Id
X-GoCache-CacheStatus
X-WADP-Cache
X-Platform-Cluster
X-Fmm-Version
AKAMAI
X-Qloud-Router
X-Clara-WADP
X-V-Cache
X-Platform-Router
X-Rocket-Nginx-Serving-Static
X-Platform-Processor
DataCenter
NtCoent-Length
X-Servedbyhost
Cache-Hits
MIME-Version
X-SD-PageType
X-Mvc-Supplant-OutputCached
X-Unique-ID
X-Cache-Var
X-Cache-Remote
X-Cache-Var-Map
X-Via-Popv
X-Via-Popn
X-Via-Poph
Environment
Kp-EeAlive
X-Datadog-Parent-Id
X-NodeID
X-API-Version
X-Nyt-Route
X-Gdpr
X-Datadog-Sampling-Priority
X-Origin-Time
X-Zone
X-Datadog-Trace-Id
X-Srv
X-Via-Ucdn
X-User
X-NC
X-Vc
X-Cache-Ttl
X-Wa
X-PJAX-URL
X-ID
X-Webkit-CSP-Report-Only
Candidate-Md5Url
X-Server-IP
X-Cache-Config
X-Pod-Name
X-Traceid
X-BBC-Origin-Response-Status
X-App
Server-ID
X-PF-Uncompressing
Who
WebServer
X-Varnish-Ttl
Time
Memory
X-VCL-Version
Cluster
X-Varnish-Url
X-Minions-Version
X-Internal-Host
X-TIME
X-Webkit-Csp
HostName
X-LB-ID
X-Refresh
Onion-Location
X-ZONE
X-CACHE-KEY
Web-Mar-Region
Powered-By-ChinaCache
My-App
Datacenter
X-Pass-Why
Geoip-Latitude
N-Cache
X-ElasticPress-Query
Resin-Trace
X-NewRelic-App-Data
X-LI-Proto
GeoIp-Country-Code
X-Newrelic-Synthetics
X-Esi
X-Edge-Pop
Servername
X-CLOUD-TRACE-CONTEXT
Geo-Info
X-Tb-Optimization-Total-Bytes-Saved
X-Varnish-Cacheable
X-VHOST
X-TraceId
X-Tt-Logid
X-OVcl-Cache
X-OVcl
X-Akamai-Pragma-Client-IP
X-EIG-Tracking-Id
WWW-Authenticate
X-Origin-Response-Time
X-TX-ID
CDN
Ohc-File-Size
Tcn
X-CACHE-AGE
X-Fpc
X-Dynatrace
Cf-Bgj
X-HITS
X-Backend-TTL
Hostname
X-TIM-N
X-Tid
Redirect-Candidate
LB
X-Dynatrace-Js-Agent
Magicmarker
X-Geo
Tracecode
Proxy-Connection
X-Varnish-Beresp-TTL
X-NODE
X-Li-Proto
Cdn
X-Up
X-AB
X-Correlation-ID
X-Cache-Date
X-Request-Start
X-Wix-Viewer-Type
X-Dispatcher-Server
Pramga
GeoIP-Country-Code
X-NGINX-Cache
X-Method
X-HostName
X-Cdn-Origin
X-MSEdge-Features
X-Fastly-Request-Id
X-MSEdge-Flight
X-Sn-Servicetimems
X-Amz-Meta-Cb-Modifiedtime
Cf-Ipcountry
X-CSRF-TOKEN
CloudFront-Viewer-Country
GeoIP-Latitude
Is-Us
X-IP
X-Vcl-Version
X-Fastly-Backend-Reqs
Ssr
DB-Nickname
Lb
X-Provided-By
W
X-UnsetCookies
CF-Cached-On
X-Cs
Server-Id
Sid
X-Cache-Expires
X-APP
X-Reqid
X-COUNTRY
X-HS-Status
X-Lb-Id
X-Core-Mission
X-MG-S
X-WA
X-Node-Id
X-Webkit-Csp-Report-Only
WP-Super-Cache
Cteonnt-Length
X-ServerName
X-Nc
X-Oracle-Dms-Ecid
X-FORWARDED-FOR
X-CCDN-Origin-Time
X-Sucuri-Cache
X-Hcs-Proxy-Type
X-Check-Cacheable
X-Cache-Status-Check
X-Pjax-Url
X-VC
X-Trv-Group
X-CCDN-CacheTTL
X-Region-Sid
URI
X-ND-Cache
Ohc-Cache-HIT
CountryCode
X-Via-CDN
X-DynaTrace-JS-Agent
WZWS-RAY
X-Via-PopH
Xc-Version
X-Cache-Backend
Env
X-Moov-T
X-Moov-Xdn-Version
X-SERVER-NAME
X-Via-PopN
X-Via-PopV
X-SN
X-Edge-POP
X-Pf-Uncompressing
X-Ig-Push-State
EpKe-Alive
Shield-Pop
X-Pad
X-ServedByHost
Mime-Version
User-Agent
X-Presslabs-Stats
X-Amz-Meta-Opti
X-Acquia-Application-UUID
X-Acquia-Application-Trace
FSS-Cache
X-RAMCache
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-CUA
X-Acquia-Site
CACHE
X-Acquia-Purge-Tags
X-LiteSpeed-Cache-Control
X-Varnish-Authentication
X-Fastly-Cache-Hits
X-Contensis-Viewer-Groups
X-TRACE-ID
X-Cache-ASPX
X-Dw-Trace-Id
VivaBuild
Rt-Fastcgi-Cache
X-RSL
X-Webstats-RespID
X-SB
Server-Ttl
Xet-Cookie
Viewtype
Hit
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Oss-Request-Id
X-Oss-Storage-Class
X-Dispatch
X-Parent-Response-Time
On-Server
X-Oss-Server-Time
X-StackifyID
X-DSS
Ohc-Response-Time
X-DW
X-RPM
X-Swift-Error
X-RPS
X-DB
X-DI
X-Action
Vha6-Origin
X-Cdn-Request-ID
X-UA
X-Cdn-Forward
X-Amzn-Remapped-X-Forwarded-For
X-Ftr-Viewer-Uri
X-Snapshot-Date
X-Env-Sha256-Sig
X-Amzn-Remapped-User-Agent
X-Amzn-Remapped-Host
X-Env-Stack-Name
X-Forwarded-Port
X-TH-Server
Req-ID
Content-Style-Type
Content-Script-Type
X-MiniProfiler-Ids
X-Yottaa-OS
ServerName
HIT
X-ElasticPress-Search
X-CF-Powered-By
X-Nginx-Upstream-Cache-Status