Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-RAY
CF-Cache-Status
Accept-Ranges
Link
ETag
Pragma
Expect-CT
X-Powered-By
X-XSS-Protection
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-UA-Compatible
P3P
X-Served-By
X-Xss-Protection
X-Timer
X-Download-Options
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
P3p
X-Cacheable
Timing-Allow-Origin
X-Request-ID
X-DNS-Prefetch-Control
X-Content-Security-Policy
X-Iinfo
Status
Feature-Policy
Content-Encoding
X-AspNetMvc-Version
X-CDN
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
X-Ua-Compatible
Upgrade
X-Dns-Prefetch-Control
Access-Control-Max-Age
X-Drupal-Dynamic-Cache
X-Via
X-Ws-Request-Id
Keep-Alive
Request-Context
Server-Timing
X-Robots-Tag
X-AH-Environment
X-Hacker
X-Server
X-Age
X-Turbo-Charged-By
X-Proxy-Cache
X-Cache-Group
X-Server-Powered-By
X-Backend
X-Amz-Request-Id
X-Amz-Id-2
Host-Header
EagleId
X-Nginx-Cache-Status
Report-To
X-LiteSpeed-Cache
X-Rq
X-Varnish-Cache
Grace
X-UA-Device
X-Page-Speed
X-Pingback
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
EagleEye-TraceId
X-Device
X-Vhost
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Amz-Version-Id
NEL
X-Dispatcher
X-OneAgent-JS-Injection
Cf-Railgun
X-Host
X-WebKit-CSP
X-Cache-Spec
X-Server-Id
X-CST
X-Node
X-Backend-Server
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Request-Id
Allow
Surrogate-Control
X-Readtime
Accept-CH
X-Akam-SW-Version
X-Response-Time
Accept-Ch-Lifetime
Xkey
X-Language
X-HW
X-Template
X-Application-Context
X-Country
Content-Location
X-Cache-Lookup
X-Ac
X-Cloud-Trace-Context
Rating
MS-Author-Via
X-Ruxit-JS-Agent
X-Url
X-Webkit-CSP
Edge-Control
X-Clacks-Overhead
X-Vname
X-PC
X-TtlSet
X-Mod-Pagespeed
X-Trace
Fastly-Restarts
X-Varnish-TTL
X-Content-Type
X-Buckets
X-B3-TraceId
X-Rack-Cache
X-MS-InvokeApp
X-Origin-Cache
X-ESI
X-GitHub-Request-Id
Accept-Ch
X-Country-Code
X-Goog-Hash
X-Cnection
X-D2id
X-VARITI-CCR
Verso
X-ORACLE-DMS-ECID
Arr-Disable-Session-Affinity
X-Kinja-Build
X-Kinja-Revision
X-Kinja-Server
X-GoogleNews-Bot
X-Cdn-Fetch
X-Exp-Variant
X-Exp-Id
X-Kinja
X-Use-Magma
X-FastCGI-Cache
Cache-Tag
X-Px
X-Vcap-Request-Id
Service-Worker-Allowed
X-Cached
X-Abt-Application-Version
X-Server-Name
Accept-CH-Lifetime
X-Server-ID
X-Amz-Rid
X-Navigation-Version
X-Client-IP
X-Cache-TTL
Public-Key-Pins
X-SRCache-Fetch-Status
X-SRCache-Store-Status
RTSS
X-Powered-By-Plesk
X-MSEdge-Ref
Access-Control-Request-Method
X-Dw-Request-Base-Id
X-Element-Page-Cache
X-Powered-CMS
X-NF-Request-ID
X-Version
X-TTL
X-Upstream
X-Fastly-Request-ID
X-Sol
X-Middleton-Response
Pagespeed
X-Middleton-Display
Response
Display
S
X-Kinsta-Cache
X-Edge-Location-Klb
X-Edge
X-LLID
X-Instrumentation
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Kraken-Routeconfig-Destination
X-B3-TraceId-Primal
X-Accel-Expires
Mrf-Cache-Status
MRF-Tech
X-Ttl
X-Shield-Request-Id
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
X-HP-Webp
X-Jurisdiction
X-Cache-Key
X-ECACHE
X-ORACLE-DMS-RID
X-Correlation-Id
Realpath
X-T
X-Litespeed-Cache
X-SharePointHealthScore
X-PressLabs-Stats
SPRequestGuid
X-Mid
Edge-Cache-Tag
X-MCACHE
X-Content-Security-Policy-Report-Only
X-Ruxit-Js-Agent
X-DynaTrace
SPIisLatency
SPRequestDuration
Fastcgi-Cache
X-Amz-Server-Side-Encryption
Nginx-Cache
X-Mg-S
X-Content-Digest
X-XRDS-Location
X-Forwarded-Proto
TP-Cache
TP-L2-Cache
X-Recruiting
X-Id
X-Oneagent-Js-Injection
X-Request-Received
X-Request-Processing-Time
Front-End-Https
Server-Node
TCN
Alternate-Protocol
Charset
X-Logged-In
Filters
X-Geo-Country
Content-MD5
X-Forwarded-For
Fusion-Component-Id
Fusion-Content-Source
Fusion-Content-Id
Fusion-Template-Id
Fusion-Source
Fusion-Deployment-Id
X-Protected-By
X-Ezoic-Cdn
X-ASPNET-VERSION
X-Hostname
Cache-Tags
X-NWS-LOG-UUID
X-Amzn-Trace-Id
X-Ab
X-Origin-Upstream-Status
X-Grace
X-Goog-Stored-Content-Encoding
X-Www-Served-By
X-GUploader-UploadID
X-Debug-Info
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Metageneration
X-Goog-Generation
Cleartype
X-LB-Cache
X-F-Cache
X-Amz-Replication-Status
X-HS-Hub-Id
X-Rid
X-HS-Content-Id
X-Activity-Id
X-Az
X-Origin-Server
X-AppVersion
X-HS-Cache-Config
X-HS-Combine-CSS
Host
X-Daa-Tunnel
X-Contextid
X-Git-Hash
X-Page-Id
Section-Io-Cache
X-Erf-Bev-Bev
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Ser
X-Content-Options
MicrosoftSharePointTeamServices
X-Upgrade-Enabled
X-Aspnetmvc-Version
Server-Name
X-Cache-Age
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-VCache
X-Frontend
Access-Control-Allow-Method
Accept-Charset
X-RateLimit-Remaining
X-Source
ServerID
X-Hits
X-Mobile-URL
X-DIS-Request-ID
X-Flags
X-Is-Crawler
X-Aspnet-Duration-Ms
X-Request-Guid
X-Route-Name
X-CACHE-GROUP
X-Providence-Cookie
X-Varnish-Age
X-Release
X-WebKit-CSP-Report-Only
X-Cache-Action
X-Signature
X-B3-Sampled
Viewport
X-B-Cache
X-Varnish-Grace
X-Whom
Healthy
X-Varnish-Backend
Payment
X-FB-Debug
Paypal-Debug-Id
X-TT
Fastcgi-Useragent
X-AOL-HN
DynaTrace
X-App-Environment
X-Yandex-Sdch-Disable
X-Respond-Thread
X-Fastcgi-Cache
X-Load-Cache
Node
X-Mobile
X-Tt-Trace-Host
X-Tt-Trace-Tag
DC
Filterid
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
Version
X-Seen-By
X-Distributor
X-User-Agent
X-XRDS-LOCATION
X-Cache-Control
X-HTML-Minification-Powered-By
X-N
Retry-After
Frame-Options
X-HP-Trace-Id
SRV
X-Type
Refresh
X-Ua-Device
X-Jobs
X-FW-Dynamic
X-FW-Hash
X-FW-Static
MS-CV
X-FW-Serve
X-FW-Type
X-FW-Server
X-Node-Name
X-Response-Served-From
X-NGENIX-Cache
X-Original-Request-Id
X-Azure-Ref
X-UUID
NGB
X-Cache-Expired-At
X-Proxy-Cache-Status
X-Adobe-Loc
X-Adobe-Content
X-Page-View
X-Aws-Lambda-Call-Status
X-Debug-IsPreview
X-Real-IP
X-Debug-IsConnected
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-IPLB-Instance
X-Cacheable-TTL
X-Cluster-Name
X-B
X-G
X-Varnish-Server
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-RemovedCookies
X-ProcessESI
X-Instance
X-Vgn-Hpd-Reason
X-Tumblr-User
Access-Control-Request-Headers
X-Framework
X-RTag
X-Region
X-Device-Type
X-Content-Powered-By
Ms-Operation-Id
X-Cache-Time
X-Proxy
Amp-Access-Control-Allow-Source-Origin
X-Parallel-Accel
X-Cache-Hit
SD-X-WS
Liferay-Portal
X-IPS-LoggedIn
X-CDN-Forward
X-Cache-Rule
X-Zen-Fury
Referer-Policy
Uber-Trace-Id
X-Is-Bot
X-Drupal-Cache-Tags
X-Rendered-As
X-Ms-Version
X-Ms-Request-Id
Cache-Status
X-Wix-Request-Id
X-Oracle-Dms-Rid
X-EdgeConnect-Cache-Status
X-App-Server
X-Time
Countrycode
X-Mg-Request-UUID
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Io-Id
Section-Origin-Responded
X-Environment-Context
X-Revision
X-L-Path
S-Cnection
X-Debug
X-B3-Traceid
Country
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-TA-CDN-Provider
CF-IPCountry
X-Accel-Buffering
Count-Hit
X-APP-VERSION
X-Cache-Operation
X-RateLimit-Limit
X-Drupal-Cache-Contexts
X-Nginx-Cache
X-FW-Version
Meta-Geo
X-RN-RSRV
X-SaId
X-UPSTREAM-Address
X-JoinUs
X-Endurance-Cache-Level
X-ES-SERVER
X-GG-Cache-Date
X-Microsite
Akamai-GRN
X-Request-Handler-Origin-Region
From-Origin
X-Cache-Type
Cache
X-Adobe-Source
X-Say-Cacheable
X-Say-TTL
X-SayCDN-TTL
X-Loop
X-TNCMS
X-R9-Blue-Green-Version
X-Human
Azure-Version
X-Request-Time
X-Cache-TTL-Remaining
Azure-RegionName
X-S-Maxage
Azure-InstanceId
X-OCL
Azure-SiteName
Azure-SlotName
X-PCL
X-Sql-Count
Country-Code
X-LAGOON
Surrogate-Key
X-Sql-Duration-Ms
X-Varnish-Beresp-Grace
X-LJ-Flow-ID
X-BYPASS-REASON
X-Proto
X-Be
X-AWS-Id
Fastly-SSL
X-Shopify-Stage
X-Varnishpool
X-ShopId
X-ProxyCache-Key
X-Alternate-Cache-Key
X-ShardId
X-Origin-Date
X-Labrador-Cache-Channel
X-Hosted-By
X-Handled-By
X-VWS-Id
X-Sorting-Hat-ShopId
X-Storefront-Renderer-Rendered
X-Varnish-Hostname
X-Via-Fastly
Cache-Name
X-ProxyCache-Status
X-PHP-Host
X-NYM-Debug-Backend
Protected
X-Sorting-Hat-PodId
Cache-Tv-Group
X-No-Session
Eomportal-Instance
X-B3-SpanId
Decoy-Debug-TTL
Decoy-Debug-Key
X-Proxy-Build
X-Status
X-Timing-Wait
X-Pubstack
GEO-INFO
X-Redis-Cache
X-RCS-CacheZone
Apigw-Requestid
X-Tumblr-Pixel-2
X-Cache-Server
X-Akamai-Edgescape
X-Web-Node
Selected-Fe
Decoy-Debug-Status
X-UA-Device-Type
X-Server-W
Property-Id
X-Origin-Hint
X-Format
X-Cluster-Node
X-Backend-Host
X-Hyper-Cache
X-PHP-Backend
X-Time-Microsecs
X-Section
X-Access
Webcakes-App-Version
TWC-GeoIP-Country
TWC-Device-Class
TWC-GeoIP-LatLong
TWC-Locale-Group
Webcakes-App-Name
TWC-Privacy
TWC-Connection-Speed
Webcakes-Region
AR-ATIME
Nel
Ar-Sid
AR-CACHE
AR-PoweredBy
AR-Request-ID
Cross-Origin-Opener-Policy
X-Xfnlog-Site
X-Uri
ServedBy
X-FB-TRIP-ID
Mn-Server-Ip
OT-Force-Account-Verify
X-ApacheServer
X-App-Version
X-PERF
X-Backend-Name
X-Hl-Ver
X-Servername
X-ServerID
X-Tumblr-Pixel-3
X-ATG-Version
X-Detected-As
Cross-Origin-Window-Policy
X-Azure-Ref-OriginShield
X-Ua
Web-Mar-Node
X-FireWall-Port
X-Datadome
X-Generation-Time
X-Cache-Host
X-Varnish-Cache-Hits
X-Cache-PHP
Source
Ec-Rule-Version
X-Varnish-Hits
X-Content-Age
Content-Secure-Policy
X-Ratelimit-Limit
X-Ratelimit-Remaining
X-Trace-Id
X-TT-LOGID
Backend
X-Via-JSL
X-TEC-API-ROOT
X-SRV
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Akamai-Transformed
X-Amzn-RequestId
X-Air-Trace-Id
X-Air-Hostname
X-MP-GENERATED-AT
X-Air-Source
X-Amz-Apigw-Id
Upgrade-Insecure-Requests
X-Content
X-Cache-Grace
X-Microcachable
X-Ua-Browser
X-WA-Info
X-Forwarded-Host
X-Cdn
X-Mode
X-CS
X-CSRF-Token
Xserver
X-Soup
X-Amzn-Remapped-Content-Length
X-NWS-UUID-VERIFY
X-Dc
X-Locale
X-Cache-Enabled
Url
X-Unique-Id
X-Site-Version
X-Bc-Bl
X-Origin-CC
X-Origin-TTL
X-Edge-Location
Content-Disposition
X-Info
X-Tenant
X-Rule
X-Proxied
X-Zipkin-Id
X-Extlb
X-Routing-Service
AMP-Access-Control-Allow-Source-Origin
X-Varnish-Beresp-Ttl
S-Rt
SID
X-Tb
X-GEO
X-Magnolia-Registration
X-Varnish-Beresp-Status
Fastly-SIE
X-NAPM-TraceId
X-Cache-NE
X-CF-Lambda-Version
T-Server
X-NU-AKA-ACS-Version
X-CF-Lambda-Fn
Fastly-SWR
X-Ftr-Request-Id
CDN-CachedAt
X-External-Request-Id
CDN-EdgeStorageId
CDN-PullZone
X-Forwarded-Path
CDN-Cache
A
BehaviorPad-Version
X-Developer
X-Destination
X-Epic-Correlation-Id
CDN-RequestCountryCode
CDN-RequestId
DCR-Processing-Time-Ms
X-Connection-Hash
X-Conf
Expiry
DCR-Decision-By
X-D
X-From
User-Cache-Control
CDN-Uid
X-Debug-Cache
Fastcgi-X-Cache-Version
X-Rojux
X-Aed
Path
X-A-Wwc
X-A-Dgt
X-A-Dcw
X-Aicache-OS
X-SRCache-Key
Mobile-Detection-Method
X-Shop-Environment
X-Application
X-Orig-Expires
Odigeo-Trace-Id
X-A-Dam
X-A-Ccd
X-M-Reqid
X-M-Log
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Surrogated-Key
X-A
X-VG-WebServer
Rendered-Blocks
X-Vdms-Version
Req-Svc-Chain
X-VG-WebCache
X-Session-Fingerprint
X-AIR-PT
X-Cache-Bucket
X-Rebelmouse-Surrogate-Control
X-Request-URI
X-ARC
X-BBC-Edge-Cache-Status
X-Rebelmouse-Cache-Control
X-Ratelimit-Reset
X-PAYTM-SRV-ID
Host-ID
X-PBS-Appsvrname
X-Platform-Server
X-Processor
X-Rewrite-Enabled
X-BCube-Filmed-By
X-B-Cookie
X-ScT
X-S-Cookie
X-S
MD5-Digest
Meta-Geo-Continent
X-Qnm-Cache
X-EC-Lua
CDCHOST
NGX
State
X-Core-Value
Is-Eu
Cache-Host
Cache-Key
X-Date
Fastly-Backend-Name
X-DPWN-IS-SECURE
Platform
Origin
X-Accel-Expires-Debug
X-Cms-Context
X-Cache-Info
UCS
X-Loc
X-VG-TLSProxy
X-Has-Esi
X-TrackingId
X-Origin-Expires
X-SVT-ORM-VERSION
X-Proxy-Upstream
X-Variation
X-Is-Gdpr
X-Li-Fabric
X-Li-Pop
X-LI-UUID
X-Men
X-JWT-State
X-SVT-ORM-RULES
X-Request-UUID
Apple-News-Services-Handled
Adler-Geo
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
X-Service
Apple-News-Services-Request-Url
X-Worker
X-Micro-Cache
X-Scheme
X-NCache
X-Fastly-Cache
X-VServer
X-Storage
X-Cached-By
X-Cache-NGX
Thinkindot-Control
X-SIPLIST1
X-Skip-Cache
X-Slack-Backend
Thinkindot-CacheControl-Type
X-Sigma-Backend
TDXMobile
Thinkindot-CacheControl
X-Sigma
X-Viewer-Country
Vix-Hermes-Req-Id
X-VC-Cache
X-Served-From
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Via-NSCOPI
X-Thinkindot-L3
VNS-Age
VNS-Cache
X-Thanos
X-Varnish-Remaining-TTL
X-Cache-Debug
X-Generated-On
X-Generated-By
X-Geo-Header
X-Gzip
X-Level-Front-Cache
X-Hnp-Log
X-Gen-Mode
X-DefElseHash
X-Esi-Check
X-Device-Os
X-Fastly-Backend
X-Forwarded-Site
X-DefHash
X-Gamma-Serve
X-Cluster
X-Clientip
X-Branch-Name
X-Req
X-Block-Status
X-Bip
X-Rocket-Build-Number
X-Backend-State
X-Envoy-Decorator-Operation
X-Origin
X-Ckpd-Fst-Backend
X-Location
X-Nginx-Cache-Key
X-Cache-Tags
X-Old-Content-Length
X-Auto-Login
X-Cache-Id
Fastly-Drupal-HTML
Fastcgi-Cache-TTL
Esi-Enabled
CPC-Cache
IsBot
L
PB-RID
PB-PID
M-TraceId
CPC-Age
Cmstype
Arc-Country
AKAMAI
X-Varnish-Ttl
X-LSADC-Cache
X-Tx-Id
Arc-Version
Cmsid
Cf-Device-Type
C-Via
Pics-Label
Location
Sever-Int
Server-Ext
Server-Hostname
DataCenter
Server-Host
X-Amz-Meta-S3cmd-Attrs
XServer
X-Hash
DSUID
X-Irp-Debug
X-Goog-Meta-Goog-Reserved-File-Mtime
We-Hiring
X-Sucuri-ID
CacheControlHeader
X-Developers
X-RateLimit-Remaining-Second
Server-Info
X-Mvc-Supplant-Cachable
X-RateLimit-Limit-Second
X-FC-Vary-Parameters
X-HS-Content-Campaign-Id
True-Client-Country-4JS
X-Wikidot-Backend
X-HN
X-Request-Host
X-Rocket-Nginx-Serving-Static
X-DataDome
Svr
Mail-Subject
Memcached
X-Vdms-Path
X-VarnishDD-TTL
X-Render-Time
X-Owner
NM-Fastcgi-Cache
PFcat
X-Wikidot-Static-Cache
Release
Pagetype
X-Policy
Locid
Gh-Request-Id
X-Fetched-On
X-GeoIP-City
X-Planisys-CDN-Rules
X-Platform
X-Var-Ttl
X-Planisys-CDN-Cache
X-GeoIP
NtCoent-Length
X-Planisys-CDN-TTL
Webserver
X-GoCache-CacheStatus
X-Qloud-Router
X-Generated-In
X-Fmm-Version
X-Clara-WADP
X-Platform-Cluster
X-Eu-Site
X-WADP-Cache
Wxu-Next-Region
Wxu-Next-Hostname
X-Platform-Router
Wxu-Next-Commit
V-Age
L5d-Success-Class
X-CGP
X-Csrf-Jwt
X-V-Cache
X-SD-PageType
HA-Ipaddr
Ha-Gx-Prefs
X-Platform-Processor
X-Cache-Var-Map
X-Cache-Remote
X-Cache-Var
X-Unique-ID
Environment
X-Mvc-Supplant-OutputCached
X-DC
X-CACHE-KEY
X-Datadog-Trace-Id
X-Via-Poph
X-Datadog-Sampling-Priority
X-Via-Popn
X-Via-Popv
X-API-Version
X-Datadog-Parent-Id
MIME-Version
Kp-EeAlive
X-Servedbyhost
X-PJAX-URL
X-Origin-Time
X-Gdpr
X-Nyt-Route
Cache-Hits
X-Srv
X-NC
X-Vc
X-NodeID
X-Via-Ucdn
X-Zone
X-User
X-BBC-Origin-Response-Status
X-Server-IP
X-Cache-Config
X-PF-Uncompressing
Candidate-Md5Url
WebServer
X-Pod-Name
Time
Memory
X-Wa
Cluster
Who
X-Refresh
X-Webkit-Csp
X-Internal-Host
X-TIME
X-App
X-Varnish-Url
X-Traceid
Server-ID
X-Minions-Version
HostName
X-ZONE
Onion-Location
X-VCL-Version
X-Webkit-CSP-Report-Only
Web-Mar-Region
GeoIp-Country-Code
X-LB-ID
X-Pass-Why
X-Dynatrace
Powered-By-ChinaCache
N-Cache
X-NewRelic-App-Data
Resin-Trace
X-Edge-Pop
Geoip-Latitude
My-App
X-Newrelic-Synthetics
X-ID
X-Cache-Ttl
X-Esi
X-CLOUD-TRACE-CONTEXT
X-ElasticPress-Query
X-Tb-Optimization-Total-Bytes-Saved
X-TraceId
CDN
X-Akamai-Pragma-Client-IP
Servername
X-Varnish-Cacheable
Geo-Info
X-TX-ID
X-LI-Proto
X-Tt-Logid
Datacenter
X-VHOST
WWW-Authenticate
X-EIG-Tracking-Id
X-Fastly-Request-Id
Tcn
Ohc-File-Size
X-HITS
X-OVcl
X-Origin-Response-Time
X-CACHE-AGE
X-OVcl-Cache
X-Varnish-Beresp-TTL
X-Fpc
X-TIM-N
X-Li-Proto
X-Geo
Cf-Bgj
X-Tid
Redirect-Candidate
X-Backend-TTL
Hostname
X-Up
Tracecode
LB
X-NODE
Magicmarker
X-Correlation-ID
X-AB
X-Method
Pramga
X-Cache-Date
Proxy-Connection
X-Wix-Viewer-Type
X-NGINX-Cache
X-Request-Start
X-Dynatrace-Js-Agent
Cdn
X-HostName
X-Vcl-Version
X-Amz-Meta-Cb-Modifiedtime
X-Dispatcher-Server
X-Cdn-Origin
X-Sn-Servicetimems
CloudFront-Viewer-Country
Cf-Ipcountry
X-CSRF-TOKEN
X-Cs
Server-Id
Lb
X-APP
X-Provided-By
X-Fastly-Backend-Reqs
GeoIP-Country-Code
X-MSEdge-Flight
X-MSEdge-Features
Is-Us
CF-Cached-On
X-Lb-Id
Sid
W
X-Cache-Expires
X-COUNTRY
X-WA
X-HS-Status
X-IP
GeoIP-Latitude
X-Core-Mission
Ssr
X-UnsetCookies
X-MG-S
DB-Nickname
X-Webkit-Csp-Report-Only
X-Reqid
X-ServerName
Cteonnt-Length
X-FORWARDED-FOR
URI
X-Node-Id
X-Check-Cacheable
X-Region-Sid
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-DynaTrace-JS-Agent
X-Sucuri-Cache
X-Cache-Status-Check
WP-Super-Cache
Ohc-Cache-HIT
CountryCode
X-ServedByHost
X-Via-PopN
X-Nc
X-Via-PopH
X-Moov-T
X-Trv-Group
X-ND-Cache
X-Via-PopV
X-SERVER-NAME
X-Cache-Backend
Mime-Version
Xc-Version
X-Moov-Xdn-Version
X-VC
Shield-Pop
EpKe-Alive
X-ECache
Env
X-Via-CDN
WZWS-RAY
X-SN
User-Agent
X-Pad
X-Ig-Push-State
X-Pjax-Url
X-CUA
X-Acquia-Application-UUID
X-Amz-Meta-Opti
X-Edge-POP
FSS-Cache
X-Acquia-Site
X-RAMCache
X-Acquia-Purge-Tags
X-Acquia-Application-Trace
X-LiteSpeed-Cache-Control
X-Fastly-Cache-Hits
X-Varnish-Authentication
CACHE
X-Pf-Uncompressing
X-Cdn-Forward
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Vcache
X-IN-APIGATEWAYSSL
X-Swift-Error
X-StackifyID
X-IN-APIGATEWAY
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Storage-Class
X-Parent-Response-Time
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
HIT
On-Server
X-Dispatch
X-Nginx-Upstream-Cache-Status
X-Webstats-RespID
X-SB
X-DSS
Ohc-Response-Time
X-DI
ServerName
Vha6-Origin
X-DB
X-Action
X-DW
X-Cdn-Request-ID
X-Dw-Trace-Id
Xet-Cookie
X-RSL
X-RPS
X-RPM
Server-Ttl
X-TRACE-ID
Srv
X-Snapshot-Date
X-Env-Sha256-Sig
X-Env-Stack-Name
Fastly-Drupal-Html
X-FPC
X-Amzn-Remapped-X-Forwarded-For
X-Forwarded-Port
X-Ftr-Viewer-Uri
X-Amzn-Remapped-User-Agent
X-Amzn-Remapped-Host
VivaBuild
Req-ID
Content-Style-Type
Content-Script-Type
X-Yottaa-OS
X-MiniProfiler-Ids
X-CF-Powered-By
Rt-Fastcgi-Cache
Viewtype
Hit