Threat Level: green Handler on Duty: Russ McRee

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-RAY
CF-Cache-Status
Accept-Ranges
Link
ETag
Pragma
Expect-CT
X-Powered-By
X-XSS-Protection
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-Xss-Protection
Alt-Svc
P3P
X-UA-Compatible
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Request-ID
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
P3p
X-Cacheable
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Content-Security-Policy
X-Iinfo
Status
X-Ua-Compatible
Feature-Policy
Content-Encoding
X-AspNetMvc-Version
X-CDN
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
Upgrade
X-Dns-Prefetch-Control
X-Drupal-Dynamic-Cache
Access-Control-Max-Age
X-Via
Keep-Alive
X-Ws-Request-Id
Request-Context
Server-Timing
X-Robots-Tag
X-AH-Environment
X-Hacker
X-Server
X-Age
X-Turbo-Charged-By
X-Proxy-Cache
X-Server-Powered-By
X-Cache-Group
X-Backend
X-Amz-Request-Id
Host-Header
X-Amz-Id-2
EagleId
X-Nginx-Cache-Status
Report-To
X-LiteSpeed-Cache
X-Rq
X-Varnish-Cache
X-Page-Speed
Grace
X-UA-Device
X-Pingback
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Device
EagleEye-TraceId
X-Vhost
X-Styx-Req-Id
X-OneAgent-JS-Injection
X-Pantheon-Styx-Hostname
X-Amz-Version-Id
NEL
Cf-Railgun
X-Dispatcher
X-Host
X-Cache-Spec
X-CST
X-WebKit-CSP
X-Server-Id
X-Node
X-Backend-Server
X-EdgeConnect-MidMile-RTT
Request-Id
X-EdgeConnect-Origin-MEX-Latency
Allow
Surrogate-Control
X-Readtime
X-Akam-SW-Version
X-Response-Time
Accept-CH
Accept-Ch-Lifetime
Xkey
X-HW
X-Ruxit-JS-Agent
X-Language
X-Webkit-CSP
X-Country
X-Application-Context
X-Template
X-Ac
Content-Location
X-Cache-Lookup
X-Cloud-Trace-Context
Rating
MS-Author-Via
X-Url
X-B3-TraceId
Edge-Control
X-TtlSet
X-Vname
X-PC
X-Mod-Pagespeed
X-Clacks-Overhead
X-Varnish-TTL
Accept-Ch
X-Trace
X-MS-InvokeApp
X-ESI
Fastly-Restarts
X-Content-Type
X-Rack-Cache
X-Origin-Cache
X-GitHub-Request-Id
X-Cnection
X-Buckets
X-Country-Code
X-Goog-Hash
X-Server-ID
Verso
X-D2id
X-Cdn-Fetch
X-Kinja-Revision
X-Kinja-Build
X-Exp-Variant
X-Kinja
X-Use-Magma
X-VARITI-CCR
X-GoogleNews-Bot
X-Exp-Id
X-Kinja-Server
Arr-Disable-Session-Affinity
X-FastCGI-Cache
X-ORACLE-DMS-ECID
X-Vcap-Request-Id
Cache-Tag
X-Cached
X-Abt-Application-Version
X-Server-Name
Service-Worker-Allowed
X-Amz-Rid
X-Client-IP
X-Navigation-Version
Accept-CH-Lifetime
X-Px
X-Powered-By-Plesk
RTSS
Public-Key-Pins
Access-Control-Request-Method
X-Fastly-Request-ID
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Powered-CMS
X-Element-Page-Cache
X-MSEdge-Ref
X-Cache-TTL
X-Upstream
X-Dw-Request-Base-Id
X-NF-Request-ID
X-Version
X-Sol
Pagespeed
X-Middleton-Display
Display
X-Middleton-Response
Response
X-Ttl
S
X-TTL
X-Edge
X-Edge-Location-Klb
X-Kinsta-Cache
X-LLID
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Kraken-Routeconfig-Destination
X-Instrumentation
X-Accel-Expires
X-Cache-Key
Realpath
X-Jurisdiction
X-HP-Webp
X-ECACHE
X-SharePointHealthScore
X-Shield-Request-Id
X-Correlation-Id
SPRequestGuid
SPIisLatency
X-T
SPRequestDuration
X-MCACHE
X-Mid
X-Pinterest-Rid
X-PressLabs-Stats
Pinterest-Version
X-DynaTrace
Pinterest-Generated-By
X-Litespeed-Cache
X-XRDS-Location
X-Content-Security-Policy-Report-Only
X-ORACLE-DMS-RID
Edge-Cache-Tag
X-Forwarded-Proto
Fastcgi-Cache
X-Amz-Server-Side-Encryption
X-Mg-S
X-Content-Digest
Nginx-Cache
TP-Cache
TP-L2-Cache
X-Recruiting
Charset
Filters
Front-End-Https
TCN
X-Request-Received
X-Request-Processing-Time
X-Id
Alternate-Protocol
Server-Node
X-Logged-In
X-Forwarded-For
X-Ezoic-Cdn
Content-MD5
X-Geo-Country
Cache-Tags
Fusion-Component-Id
Fusion-Content-Source
Fusion-Content-Id
Fusion-Template-Id
Fusion-Deployment-Id
Fusion-Source
X-ASPNET-VERSION
X-Protected-By
X-Hostname
X-Origin-Upstream-Status
X-Amzn-Trace-Id
X-Grace
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-NWS-LOG-UUID
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-F-Cache
X-Origin-Server
X-Oneagent-Js-Injection
X-Amz-Replication-Status
Cleartype
X-Debug-Info
X-Rid
X-HS-Cache-Config
X-Www-Served-By
X-HS-Hub-Id
X-HS-Content-Id
X-Release
Host
X-LB-Cache
X-HS-Combine-CSS
X-Az
X-Activity-Id
X-AppVersion
X-Contextid
Section-Io-Cache
X-Daa-Tunnel
X-Page-Id
X-RateLimit-Remaining
X-Git-Hash
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
Server-Name
X-Browser-Type
X-Frontend
X-Ser
X-VCache
X-Aspnetmvc-Version
MicrosoftSharePointTeamServices
X-Respond-Thread
X-Ab
X-Cache-Age
X-Content-Options
X-Ruxit-Js-Agent
Accept-Charset
Access-Control-Allow-Method
X-Upgrade-Enabled
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Hits
X-Mobile-URL
X-DIS-Request-ID
X-Source
X-WebKit-CSP-Report-Only
ServerID
X-Route-Name
X-CACHE-GROUP
X-Signature
X-Request-Guid
X-Flags
X-Aspnet-Duration-Ms
X-Providence-Cookie
X-B-Cache
X-Is-Crawler
Payment
X-Varnish-Backend
X-Cache-Action
X-Varnish-Grace
X-Whom
X-FB-Debug
X-Varnish-Age
Healthy
Viewport
Paypal-Debug-Id
X-TT
X-App-Environment
X-AOL-HN
X-Fastcgi-Cache
X-B3-Sampled
DynaTrace
Node
Fastcgi-Useragent
X-Load-Cache
Version
X-Yandex-Sdch-Disable
X-Seen-By
X-Mobile
X-N
DC
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Distributor
Filterid
X-Type
SRV
X-HTML-Minification-Powered-By
X-Tec-Api-Version
Frame-Options
X-Tec-Api-Root
X-Tec-Api-Origin
X-User-Agent
X-Cache-Control
Retry-After
MS-CV
X-Ua-Device
X-Jobs
X-Cache-Expired-At
Refresh
X-Response-Served-From
X-XRDS-LOCATION
X-Original-Request-Id
X-UUID
X-Real-IP
X-Page-View
Amp-Access-Control-Allow-Source-Origin
X-IPLB-Instance
X-Debug-IsPreview
X-Varnish-Server
X-Debug-IsConnected
X-Adobe-Loc
X-Adobe-Content
X-Instance
X-FW-Type
X-Proxy-Cache-Status
X-FW-Dynamic
X-Cluster-Name
X-FW-Server
X-FW-Serve
X-FW-Hash
X-FW-Static
X-Region
Access-Control-Request-Headers
NGB
X-Cacheable-TTL
X-Framework
X-Tumblr-User
X-Content-Powered-By
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-ProcessESI
X-RemovedCookies
X-Proxy
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Tumblr-Pixel
X-IPS-LoggedIn
X-Device-Type
X-Vgn-Hpd-Reason
X-RTag
Ms-Operation-Id
X-CDN-Forward
X-B
X-G
X-Cache-Time
X-Azure-Ref
Uber-Trace-Id
X-Zen-Fury
X-Node-Name
Ar-Sid
AR-ATIME
AR-CACHE
AR-PoweredBy
AR-Request-ID
Countrycode
X-NGENIX-Cache
X-Cache-Rule
Cache-Status
X-Cache-Hit
X-Microsite
X-Request-Handler-Origin-Region
X-Wix-Request-Id
X-Ms-Request-Id
Section-Io-Id
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
X-Ms-Version
Section-Origin-Responded
X-Is-Bot
SD-X-WS
X-Time
X-Rendered-As
Referer-Policy
X-Mg-Request-UUID
X-Oracle-Dms-Rid
Liferay-Portal
X-Aws-Lambda-Call-Status
X-HP-Trace-Id
X-Drupal-Cache-Tags
X-Nginx-Cache
X-Debug
X-Accel-Buffering
X-App-Version
X-EdgeConnect-Cache-Status
X-Parallel-Accel
S-Cnection
Cache
Country
X-L-Path
X-RateLimit-Limit
X-Revision
X-App-Server
X-Environment-Context
CF-IPCountry
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Cache-Operation
Surrogate-Key
X-FireWall-Port
X-TNCMS
X-GG-Cache-Date
X-JoinUs
X-RN-RSRV
Eomportal-Instance
Meta-Geo
X-Drupal-Cache-Contexts
X-Loop
X-ES-SERVER
X-SaId
Count-Hit
X-TA-CDN-Provider
X-UPSTREAM-Address
X-Sorting-Hat-PodId
X-Shopify-Stage
X-SayCDN-TTL
X-Cache-Type
X-Endurance-Cache-Level
X-Cache-TTL-Remaining
X-Alternate-Cache-Key
X-Adobe-Source
X-ShardId
X-LAGOON
From-Origin
Selected-Fe
X-Sorting-Hat-ShopId
X-Storefront-Renderer-Rendered
X-Proxy-Build
X-Say-TTL
X-Timing-Wait
X-Say-Cacheable
X-ShopId
X-VWS-Id
X-Be
X-Proto
X-Varnishpool
X-Varnish-Hostname
X-Origin-Date
Country-Code
X-Xfnlog-Site
Cache-Name
Azure-RegionName
Azure-SiteName
Azure-SlotName
Azure-InstanceId
X-Varnish-Beresp-Grace
X-FW-Version
Akamai-GRN
Azure-Version
X-AWS-Id
X-Request-Time
X-Sql-Duration-Ms
X-Human
X-LJ-Flow-ID
X-No-Session
X-Sql-Count
X-NYM-Debug-Backend
X-S-Maxage
GEO-INFO
X-Akamai-Edgescape
Apigw-Requestid
Decoy-Debug-Status
X-PCL
X-Status
X-ProxyCache-Status
Protected
X-ProxyCache-Key
Decoy-Debug-Key
X-Pubstack
X-Cache-Server
X-RCS-CacheZone
X-BYPASS-REASON
ServedBy
X-PHP-Backend
X-UA-Device-Type
X-OCL
X-R9-Blue-Green-Version
X-Handled-By
X-Hosted-By
Fastly-SSL
Decoy-Debug-TTL
X-Section
TWC-Device-Class
X-PHP-Host
TWC-GeoIP-Country
TWC-Connection-Speed
X-Redis-Cache
X-Web-Node
X-Hyper-Cache
X-Access
X-Backend-Name
X-Hl-Ver
X-Uri
X-Format
X-Origin-Hint
Webcakes-Region
TWC-Privacy
TWC-Locale-Group
Webcakes-App-Name
Webcakes-App-Version
X-Tumblr-Pixel-2
X-Labrador-Cache-Channel
X-Server-W
TWC-GeoIP-LatLong
Cache-Tv-Group
Property-Id
X-ApacheServer
X-Backend-Host
Nel
X-PERF
X-Via-Fastly
Mn-Server-Ip
X-FB-TRIP-ID
X-Cluster-Node
X-ServerID
X-Time-Microsecs
X-B3-SpanId
X-ATG-Version
X-Servername
OT-Force-Account-Verify
X-Cache-PHP
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-APP-VERSION
X-Tumblr-Pixel-3
Cross-Origin-Opener-Policy
X-Azure-Ref-OriginShield
X-Detected-As
Backend
X-Content-Age
Xserver
X-WA-Info
Web-Mar-Node
X-Trace-Id
X-Cache-Host
X-Generation-Time
X-Varnish-Cache-Hits
X-MP-GENERATED-AT
X-CSRF-Token
X-TT-LOGID
Cross-Origin-Window-Policy
X-Datadome
X-Varnish-Hits
X-Bc-Bl
X-Ua
X-Rule
Content-Secure-Policy
X-Akamai-Transformed
X-Soup
X-Cached-By
X-CS
Ec-Rule-Version
X-Via-JSL
X-Cache-Enabled
X-Ratelimit-Limit
X-Edge-Location
X-Amzn-RequestId
X-SRV
X-NWS-UUID-VERIFY
X-Amz-Apigw-Id
X-Amzn-Remapped-Content-Length
Source
X-Info
X-Mode
X-Cache-Grace
X-Microcachable
S-Rt
X-Origin-TTL
X-Origin-CC
X-Varnish-Beresp-Status
Upgrade-Insecure-Requests
X-Locale
X-B3-Traceid
X-Magnolia-Registration
X-Forwarded-Host
Url
X-Air-Trace-Id
X-Cache-NGX
X-Dc
X-Air-Hostname
X-Air-Source
X-Tb
X-Storage
X-Varnish-Beresp-Ttl
X-Site-Version
X-Debug-Cache
X-GEO
X-EC-Lua
X-A-Wwc
Apple-News-Services-Handled
X-Application
X-AIR-PT
X-Zipkin-Id
X-Aed
X-Aicache-OS
A
X-NAPM-TraceId
X-ARC
X-Vtex-Processado-Em
X-PBS-Appsvrname
X-Cache-Bucket
X-VG-WebServer
X-VG-WebCache
X-Vtex-Remote-Cache
X-PAYTM-SRV-ID
Apple-News-Services-Host
X-B-Cookie
X-Orig-Expires
X-BCube-Filmed-By
X-NU-AKA-ACS-Version
Apple-News-Services-Request-Url
Meta-Geo-Continent
Mobile-Detection-Method
MD5-Digest
M-TraceId
X-Forwarded-Path
X-From
T-Server
Odigeo-Trace-Id
Rendered-Blocks
Req-Svc-Chain
State
Surrogated-Key
X-Ftr-Request-Id
Path
Host-ID
Fastly-SWR
X-A-Dam
X-A-Ccd
X-A-Dcw
CDCHOST
BehaviorPad-Version
X-A-Dgt
X-A
X-Extlb
Fastcgi-X-Cache-Version
Fastly-SIE
Expiry
DCR-Processing-Time-Ms
DCR-Decision-By
Apple-News-Services-Parsed-Url
X-External-Request-Id
X-Rebelmouse-Cache-Control
X-Clientip
X-Developer
X-Rewrite-Enabled
X-Ratelimit-Reset
X-ScT
X-Rebelmouse-Surrogate-Control
X-Shop-Environment
X-Rojux
X-Request-URI
X-Epic-Correlation-Id
X-Routing-Service
X-Destination
X-Unique-Id
X-Session-Fingerprint
X-D
X-SRCache-Key
X-S-Cookie
X-Connection-Hash
X-S
X-Platform-Server
X-Proxied
X-Processor
X-Conf
User-Cache-Control
X-Tenant
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Cache-NE
X-Vdms-Version
SID
X-Cache-Ttl
X-DataDome
X-Service
Fastly-Backend-Name
DSUID
X-Date
X-Thanos
X-Platform
Fastly-Drupal-HTML
X-Fastly-Backend
X-JWT-State
X-Fastly-Cache
X-Forwarded-Site
PB-RID
PB-PID
Origin
X-Envoy-Decorator-Operation
Pics-Label
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
NGX
X-GoCache-CacheStatus
L
X-TrackingId
X-Sigma
UCS
X-Sigma-Backend
X-Has-Esi
X-Hash
X-Is-Gdpr
CDN-Uid
X-Men
X-Request-Host
X-Accel-Expires-Debug
X-VG-TLSProxy
X-Request-UUID
X-Loc
CDN-RequestId
X-Cache-Debug
X-Backend-State
X-Bip
X-Origin-Expires
X-Cache-Tags
X-VServer
X-BBC-Edge-Cache-Status
X-LI-UUID
X-Cache-Info
Cache-Key
X-Core-Value
X-Li-Fabric
CDN-Cache
CDN-CachedAt
CDN-RequestCountryCode
CDN-PullZone
CDN-EdgeStorageId
C-Via
Cache-Host
Arc-Version
X-Li-Pop
X-Rocket-Build-Number
Content-Disposition
AMP-Access-Control-Allow-Source-Origin
X-Ratelimit-Remaining
X-Amz-Meta-S3cmd-Attrs
X-Gen-Mode
X-Generated-By
Server-Info
X-Gamma-Serve
X-Device-Os
Sever-Int
Server-Hostname
X-Eu-Site
X-Block-Status
X-Developers
X-Cluster
VNS-Age
Vix-Hermes-Req-Id
VNS-Cache
We-Hiring
X-Csrf-Jwt
X-FC-Vary-Parameters
X-Fmm-Version
X-Cms-Context
Thinkindot-CacheControl
TDXMobile
X-Clara-WADP
Thinkindot-CacheControl-Type
X-Generated-In
Thinkindot-Control
X-CGP
Cmsid
X-Old-Content-Length
X-Nginx-Cache-Key
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-Viewer-Country
X-WADP-Cache
X-DPWN-IS-SECURE
Server-Ext
CacheControlHeader
X-Level-Front-Cache
Adler-Geo
X-Location
X-Micro-Cache
X-Via-NSCOPI
X-Policy
X-Scheme
X-Var-Ttl
X-Served-From
X-SIPLIST1
X-Slack-Backend
X-Thinkindot-L3
X-Variation
X-DC
X-RateLimit-Limit-Second
X-Proxy-Upstream
X-RateLimit-Remaining-Second
X-VC-Cache
X-VarnishDD-TTL
Cf-Device-Type
X-Mvc-Supplant-Cachable
Mail-Subject
X-GeoIP-City
X-HN
Locid
L5d-Success-Class
Cmstype
Pagetype
PFcat
X-Geo-Header
X-Generated-On
Release
X-GeoIP
Platform
X-Hnp-Log
Location
HA-Ipaddr
Ha-Gx-Prefs
Fastcgi-Cache-TTL
X-Irp-Debug
Gh-Request-Id
Esi-Enabled
Is-Eu
CPC-Age
CPC-Cache
IsBot
X-Varnish-CookieHashed-On
X-Sucuri-ID
X-Esi-Check
X-Skip-Cache
X-Worker
X-Varnish-Remaining-TTL
X-Fetched-On
X-Planisys-CDN-TTL
X-Owner
X-Planisys-CDN-Rules
X-Origin
X-Vdms-Path
X-Planisys-CDN-Cache
X-Req
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Gzip
X-Varnish-CookieINHashed-On
X-Cache-Id
Server-Host
NtCoent-Length
Svr
X-Unique-ID
Kp-EeAlive
Memcached
NM-Fastcgi-Cache
Webserver
V-Age
True-Client-Country-4JS
X-Branch-Name
Wxu-Next-Hostname
AKAMAI
Wxu-Next-Commit
X-DefElseHash
X-DefHash
Arc-Country
Wxu-Next-Region
DataCenter
X-Tx-Id
X-Auto-Login
X-HS-Content-Campaign-Id
X-Qloud-Router
X-Ckpd-Fst-Backend
X-NCache
X-Srv
X-M-Reqid
X-M-Log
X-Servedbyhost
XServer
X-User
Cache-Hits
X-V-Cache
Who
X-Mvc-Supplant-OutputCached
X-Qnm-Cache
X-Ua-Browser
X-Content
MIME-Version
X-NC
X-LSADC-Cache
X-Via-Poph
X-Via-Popv
X-Via-Popn
X-PF-Uncompressing
X-Platform-Cluster
X-Render-Time
X-Platform-Router
X-Platform-Processor
X-Rocket-Nginx-Serving-Static
X-Traceid
X-Varnish-Url
X-SD-PageType
X-Minions-Version
X-ZONE
X-ID
X-Cache-Remote
X-Zone
X-Wa
X-Vc
X-Varnish-Ttl
WebServer
X-App
X-Refresh
Environment
X-Origin-Time
X-Cache-Var
X-Datadog-Trace-Id
X-API-Version
X-BBC-Origin-Response-Status
X-Nyt-Route
X-PJAX-URL
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-LB-ID
X-Cache-Var-Map
My-App
X-Gdpr
Powered-By-ChinaCache
X-Server-IP
X-Webkit-Csp
X-TIME
X-Internal-Host
X-NodeID
X-Via-Ucdn
X-Cache-Config
Memory
Cluster
Time
X-Pass-Why
Server-ID
X-Newrelic-Synthetics
X-CACHE-KEY
X-VCL-Version
X-Pod-Name
Candidate-Md5Url
X-Webkit-CSP-Report-Only
X-NewRelic-App-Data
X-TX-ID
X-OVcl-Cache
X-CLOUD-TRACE-CONTEXT
Datacenter
GeoIp-Country-Code
X-OVcl
HostName
Geoip-Latitude
Resin-Trace
Hostname
Cf-Bgj
X-LI-Proto
Web-Mar-Region
X-Edge-Pop
Geo-Info
X-ElasticPress-Query
N-Cache
X-Tb-Optimization-Total-Bytes-Saved
X-TraceId
X-VHOST
X-Backend-TTL
Magicmarker
Onion-Location
Ohc-File-Size
Tcn
X-Dynatrace
X-CACHE-AGE
X-HITS
Servername
X-Akamai-Pragma-Client-IP
X-Origin-Response-Time
X-Varnish-Beresp-TTL
X-Method
X-Geo
X-Dispatcher-Server
X-Li-Proto
X-Varnish-Cacheable
X-EIG-Tracking-Id
WWW-Authenticate
X-Esi
Proxy-Connection
X-NODE
GeoIP-Country-Code
DB-Nickname
X-AB
LB
X-Correlation-ID
X-IP
X-Wix-Viewer-Type
Ssr
CDN
X-MSEdge-Features
X-MSEdge-Flight
GeoIP-Latitude
X-Tt-Logid
X-HostName
Cdn
X-Fpc
Redirect-Candidate
X-Dynatrace-Js-Agent
X-Cs
X-TIM-N
X-Fastly-Request-Id
X-Tid
CF-Cached-On
Cf-Ipcountry
Sid
X-Vcl-Version
Server-Id
Tracecode
X-Node-Id
X-Request-Start
X-Cache-Date
Pramga
X-Up
X-Trv-Group
X-Fastly-Backend-Reqs
X-APP
X-HS-Status
X-ND-Cache
X-DynaTrace-JS-Agent
Lb
X-MG-S
X-WA
X-Amz-Meta-Cb-Modifiedtime
X-Via-CDN
X-Pjax-Url
X-Webkit-Csp-Report-Only
X-ServerName
WZWS-RAY
X-Cdn-Origin
Is-Us
Env
Cteonnt-Length
X-Sn-Servicetimems
X-NGINX-Cache
X-Nc
X-CSRF-TOKEN
X-FORWARDED-FOR
X-Reqid
X-Via-PopH
X-Lb-Id
URI
X-Provided-By
X-Via-PopN
X-Via-PopV
W
X-Check-Cacheable
X-VC
X-Core-Mission
X-UnsetCookies
Ohc-Cache-HIT
X-Cache-Expires
X-SERVER-NAME
CloudFront-Viewer-Country
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-Cache-Backend
X-ECache
Viewtype
CountryCode
Shield-Pop
WP-Super-Cache
X-ServedByHost
Server-Ttl
Rt-Fastcgi-Cache
X-Pf-Uncompressing
X-SN
VivaBuild
Mime-Version
X-Hcs-Proxy-Type
X-Acquia-Application-UUID
X-Region-Sid
X-Sucuri-Cache
X-Acquia-Purge-Tags
X-Acquia-Site
X-Edge-POP
CACHE
X-Cache-Status-Check
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-RAMCache
X-Acquia-Application-Trace
X-Contensis-Viewer-Groups
X-LiteSpeed-Cache-Control
X-Fastly-Cache-Hits
X-Varnish-Authentication
X-Cache-ASPX
X-Pad
X-RSL
X-Dw-Trace-Id
Vha6-Origin
X-SB
X-Cdn-Request-ID
X-CUA
Xc-Version
X-Moov-Xdn-Version
X-Moov-T
EpKe-Alive
Ohc-Response-Time
X-Webstats-RespID
Machine
X-DSS
X-DI
Xet-Cookie
X-RPM
X-RPS
X-StackifyID
X-DB
X-DW
X-Yottaa-OS
X-Action
X-Swift-Error
X-B3-Spanid
X-Cdn-Forward
Content-Style-Type
User-Agent
X-FPC
X-Ig-Push-State
X-UP
X-MiniProfiler-Ids
Content-Script-Type
Req-ID
X-ElasticPress-Search
ServerName
X-CF-Powered-By
X-TH-Server