Threat Level: green Handler on Duty: Russ McRee

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-RAY
CF-Cache-Status
Accept-Ranges
Link
ETag
Pragma
Expect-CT
X-Powered-By
X-XSS-Protection
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
Alt-Svc
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Timer
X-Download-Options
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-Request-ID
X-Cache-Status
X-Generator
X-Cacheable
X-DNS-Prefetch-Control
Timing-Allow-Origin
P3p
X-Content-Security-Policy
X-Iinfo
Status
X-Ua-Compatible
Feature-Policy
Content-Encoding
X-AspNetMvc-Version
X-CDN
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
Upgrade
X-Drupal-Dynamic-Cache
Access-Control-Max-Age
X-Via
X-Dns-Prefetch-Control
Keep-Alive
X-Ws-Request-Id
Request-Context
Server-Timing
X-Robots-Tag
X-AH-Environment
X-Hacker
X-Server
X-Age
X-Turbo-Charged-By
X-Proxy-Cache
X-Cache-Group
X-Server-Powered-By
X-Backend
X-Amz-Request-Id
Host-Header
X-Amz-Id-2
EagleId
X-Nginx-Cache-Status
Report-To
X-LiteSpeed-Cache
X-Rq
X-Varnish-Cache
X-UA-Device
Grace
X-Page-Speed
X-Pingback
X-Swift-CacheTime
X-Swift-SaveTime
EagleEye-TraceId
Ali-Swift-Global-Savetime
X-Device
X-Vhost
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Amz-Version-Id
NEL
X-Dispatcher
X-OneAgent-JS-Injection
Cf-Railgun
X-Host
X-WebKit-CSP
X-Cache-Spec
X-Server-Id
X-CST
X-Node
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Backend-Server
Allow
Request-Id
Surrogate-Control
X-Readtime
Accept-CH
X-Akam-SW-Version
X-Response-Time
Accept-Ch-Lifetime
Xkey
X-HW
X-Language
X-Ruxit-JS-Agent
X-Application-Context
X-Template
X-Country
X-Ac
Content-Location
X-Cache-Lookup
X-Cloud-Trace-Context
X-Webkit-CSP
Rating
MS-Author-Via
X-Url
X-B3-TraceId
Edge-Control
X-TtlSet
X-Vname
X-PC
X-Mod-Pagespeed
X-Clacks-Overhead
X-Varnish-TTL
X-Trace
Fastly-Restarts
X-Content-Type
X-MS-InvokeApp
X-Rack-Cache
X-Origin-Cache
X-ESI
X-GitHub-Request-Id
X-Buckets
Accept-Ch
X-Cnection
X-Country-Code
X-Goog-Hash
X-D2id
X-VARITI-CCR
Verso
X-Kinja-Server
X-GoogleNews-Bot
X-Exp-Variant
X-Exp-Id
X-Cdn-Fetch
X-Kinja-Build
X-Use-Magma
X-Kinja-Revision
X-Kinja
Arr-Disable-Session-Affinity
X-FastCGI-Cache
X-ORACLE-DMS-ECID
X-Vcap-Request-Id
Cache-Tag
Service-Worker-Allowed
X-Abt-Application-Version
X-Cached
X-Server-Name
X-Client-IP
X-Server-ID
X-Amz-Rid
Accept-CH-Lifetime
X-Navigation-Version
X-Px
RTSS
X-Powered-By-Plesk
X-Cache-TTL
Public-Key-Pins
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Access-Control-Request-Method
X-Element-Page-Cache
X-MSEdge-Ref
X-Powered-CMS
X-Fastly-Request-ID
X-Dw-Request-Base-Id
X-Upstream
X-NF-Request-ID
X-Version
X-Middleton-Response
Response
Pagespeed
Display
X-Sol
X-Middleton-Display
S
X-TTL
X-Ttl
X-Kinsta-Cache
X-Edge-Location-Klb
X-Edge
X-LLID
X-Instrumentation
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Kraken-Routeconfig-Destination
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Cache-Key
X-Accel-Expires
Realpath
X-Jurisdiction
X-HP-Webp
X-Shield-Request-Id
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
X-ECACHE
X-T
SPRequestGuid
X-DynaTrace
X-SharePointHealthScore
X-MCACHE
X-Mid
X-Litespeed-Cache
X-PressLabs-Stats
X-ORACLE-DMS-RID
SPIisLatency
SPRequestDuration
X-Content-Security-Policy-Report-Only
X-Correlation-Id
Edge-Cache-Tag
Fastcgi-Cache
X-Mg-S
X-XRDS-Location
X-Amz-Server-Side-Encryption
X-Forwarded-Proto
X-Content-Digest
Nginx-Cache
TP-Cache
TP-L2-Cache
X-Recruiting
Charset
X-Oneagent-Js-Injection
Front-End-Https
X-Request-Received
X-Request-Processing-Time
TCN
Alternate-Protocol
Filters
X-Id
Server-Node
X-Logged-In
X-Forwarded-For
X-Geo-Country
Content-MD5
X-Ezoic-Cdn
Fusion-Deployment-Id
Fusion-Content-Source
Fusion-Source
Fusion-Template-Id
Fusion-Content-Id
Fusion-Component-Id
X-Protected-By
X-ASPNET-VERSION
Cache-Tags
X-Hostname
X-Amzn-Trace-Id
X-Origin-Upstream-Status
X-Grace
X-NWS-LOG-UUID
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Ruxit-Js-Agent
X-Goog-Generation
X-GUploader-UploadID
X-F-Cache
X-Origin-Server
Cleartype
X-Debug-Info
X-Www-Served-By
X-Amz-Replication-Status
X-Rid
X-HS-Cache-Config
X-LB-Cache
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Combine-CSS
Host
X-Az
X-Activity-Id
X-AppVersion
X-Contextid
X-Ab
X-Daa-Tunnel
X-Release
X-Git-Hash
Section-Io-Cache
X-Browser-Type
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Page-Id
Server-Name
X-Frontend
X-Ser
X-VCache
X-RateLimit-Remaining
X-Aspnetmvc-Version
MicrosoftSharePointTeamServices
X-Cache-Age
X-Content-Options
Accept-Charset
X-Upgrade-Enabled
X-Respond-Thread
Access-Control-Allow-Method
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Hits
X-Mobile-URL
ServerID
X-DIS-Request-ID
X-Source
X-Aspnet-Duration-Ms
X-CACHE-GROUP
X-B-Cache
X-Request-Guid
X-Signature
X-Providence-Cookie
X-Route-Name
X-Is-Crawler
X-Flags
X-Cache-Action
X-WebKit-CSP-Report-Only
X-Varnish-Age
X-Varnish-Backend
X-FB-Debug
X-Whom
Healthy
Viewport
X-TT
X-Varnish-Grace
Paypal-Debug-Id
Payment
X-Fastcgi-Cache
X-App-Environment
X-AOL-HN
Node
X-B3-Sampled
DynaTrace
Fastcgi-Useragent
X-Yandex-Sdch-Disable
X-Mobile
X-Load-Cache
Version
X-Seen-By
DC
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-N
Filterid
X-Distributor
X-XRDS-LOCATION
X-HTML-Minification-Powered-By
SRV
X-Type
X-User-Agent
Retry-After
X-Tec-Api-Version
X-Tec-Api-Origin
X-Cache-Control
X-Tec-Api-Root
Frame-Options
MS-CV
X-Jobs
Refresh
X-Original-Request-Id
X-Cache-Expired-At
X-Response-Served-From
X-FW-Server
X-FW-Hash
X-UUID
X-FW-Static
X-FW-Type
X-FW-Serve
X-FW-Dynamic
X-Proxy-Cache-Status
X-Adobe-Content
NGB
Amp-Access-Control-Allow-Source-Origin
X-Page-View
X-Adobe-Loc
X-Instance
X-Varnish-Server
X-Real-IP
X-Region
X-Cacheable-TTL
VIX-Pulpo-Upstream-Status
X-NGENIX-Cache
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel-1
X-B
X-Proxy
X-IPLB-Instance
X-Cluster-Name
X-Debug-IsPreview
X-G
X-Tumblr-Pixel
Access-Control-Request-Headers
VIX-Pulpo-Node
X-ProcessESI
X-Debug-IsConnected
X-RemovedCookies
X-Vgn-Hpd-Reason
X-Azure-Ref
X-Node-Name
X-Framework
X-Content-Powered-By
X-Device-Type
X-Cache-Time
X-RTag
X-CDN-Forward
Ms-Operation-Id
X-IPS-LoggedIn
X-HP-Trace-Id
X-Zen-Fury
Uber-Trace-Id
X-Cache-Hit
X-Aws-Lambda-Call-Status
X-Cache-Rule
Cache-Status
SD-X-WS
X-Wix-Request-Id
X-Is-Bot
Referer-Policy
X-Rendered-As
Countrycode
X-Ms-Request-Id
X-Ms-Version
Liferay-Portal
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
X-Oracle-Dms-Rid
X-Drupal-Cache-Tags
Section-Io-Id
X-Time
Section-Origin-Responded
X-Mg-Request-UUID
X-Parallel-Accel
AR-PoweredBy
Ar-Sid
AR-Request-ID
AR-CACHE
AR-ATIME
X-Request-Handler-Origin-Region
X-Microsite
X-Nginx-Cache
X-Debug
X-EdgeConnect-Cache-Status
X-Accel-Buffering
S-Cnection
X-RateLimit-Limit
X-L-Path
Country
X-Revision
X-App-Server
X-Environment-Context
CF-IPCountry
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Cache-Operation
Cache
Count-Hit
X-APP-VERSION
X-Drupal-Cache-Contexts
X-SaId
X-JoinUs
X-TNCMS
X-ES-SERVER
X-RN-RSRV
X-Endurance-Cache-Level
X-UPSTREAM-Address
X-GG-Cache-Date
X-FW-Version
X-TA-CDN-Provider
Surrogate-Key
X-Loop
Meta-Geo
X-Say-Cacheable
X-Say-TTL
X-SayCDN-TTL
Akamai-GRN
X-Adobe-Source
X-Xfnlog-Site
X-Cache-Type
X-App-Version
X-LAGOON
From-Origin
X-Human
Azure-SlotName
Azure-InstanceId
Country-Code
X-Cache-TTL-Remaining
Azure-RegionName
Azure-SiteName
Azure-Version
Protected
X-NYM-Debug-Backend
X-S-Maxage
X-Varnish-Beresp-Grace
X-Request-Time
GEO-INFO
X-Sql-Duration-Ms
Eomportal-Instance
X-Sql-Count
X-PCL
X-ShopId
Apigw-Requestid
X-PHP-Host
X-ShardId
X-OCL
X-Alternate-Cache-Key
X-Sorting-Hat-ShopId
X-VWS-Id
X-RCS-CacheZone
X-Sorting-Hat-PodId
X-FireWall-Port
Decoy-Debug-Key
Decoy-Debug-Status
Decoy-Debug-TTL
X-ProxyCache-Key
ServedBy
X-ProxyCache-Status
X-AWS-Id
X-Pubstack
Cache-Name
Cache-Tv-Group
X-Proto
Fastly-SSL
X-Handled-By
X-Hosted-By
X-Origin-Date
X-Storefront-Renderer-Rendered
X-Be
X-No-Session
X-Shopify-Stage
X-Status
X-LJ-Flow-ID
X-Varnishpool
X-BYPASS-REASON
X-Varnish-Hostname
X-Labrador-Cache-Channel
X-Origin-Hint
X-Proxy-Build
X-Timing-Wait
X-Tumblr-Pixel-2
X-Hyper-Cache
X-Format
Selected-Fe
TWC-Device-Class
Property-Id
TWC-Connection-Speed
X-UA-Device-Type
X-Access
Webcakes-Region
Webcakes-App-Version
X-Section
X-Web-Node
X-Via-Fastly
X-Akamai-Edgescape
X-Cache-Server
X-Redis-Cache
X-PHP-Backend
X-R9-Blue-Green-Version
TWC-GeoIP-LatLong
TWC-Privacy
Webcakes-App-Name
X-Server-W
X-Uri
TWC-GeoIP-Country
TWC-Locale-Group
Nel
Mn-Server-Ip
X-PERF
X-ApacheServer
X-Backend-Host
X-Cluster-Node
X-FB-TRIP-ID
X-Hl-Ver
X-Ua-Device
X-Time-Microsecs
X-Backend-Name
X-Servername
X-ATG-Version
OT-Force-Account-Verify
X-B3-SpanId
X-ServerID
Cross-Origin-Opener-Policy
X-Tumblr-Pixel-3
X-Detected-As
X-Cache-PHP
X-TEC-API-VERSION
X-Azure-Ref-OriginShield
X-TEC-API-ROOT
X-TEC-API-ORIGIN
Web-Mar-Node
X-Trace-Id
X-Varnish-Cache-Hits
X-Generation-Time
X-Content-Age
Cross-Origin-Window-Policy
Backend
X-Cache-Host
X-Ua
Xserver
X-CSRF-Token
X-Varnish-Hits
X-Datadome
X-TT-LOGID
X-MP-GENERATED-AT
Content-Secure-Policy
X-WA-Info
X-SRV
Ec-Rule-Version
X-Via-JSL
X-Cdn
Source
X-Bc-Bl
X-Soup
X-Akamai-Transformed
X-CS
X-Ratelimit-Limit
X-Cache-Enabled
X-Edge-Location
X-Amzn-RequestId
X-Cache-Grace
X-Mode
X-Amz-Apigw-Id
X-Amzn-Remapped-Content-Length
S-Rt
X-Ratelimit-Remaining
X-Microcachable
X-Rule
X-Info
X-NWS-UUID-VERIFY
X-Air-Hostname
X-Air-Source
X-Air-Trace-Id
Upgrade-Insecure-Requests
X-Origin-TTL
X-Locale
Url
X-Forwarded-Host
X-Unique-Id
X-Origin-CC
X-Varnish-Beresp-Status
X-B3-Traceid
X-Cached-By
X-GEO
SID
X-Site-Version
Content-Disposition
X-Tb
X-Varnish-Beresp-Ttl
X-Magnolia-Registration
X-Dc
A
MD5-Digest
X-SRCache-Key
Meta-Geo-Continent
Rendered-Blocks
Mobile-Detection-Method
X-Zipkin-Id
Path
Odigeo-Trace-Id
X-Shop-Environment
X-Vtex-Processado-Em
Host-ID
Req-Svc-Chain
Apple-News-Services-Handled
BehaviorPad-Version
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
X-VG-WebCache
X-VG-WebServer
X-Vtex-Remote-Cache
X-Vdms-Version
Fastcgi-X-Cache-Version
X-Tenant
Apple-News-Services-Request-Url
Expiry
DCR-Processing-Time-Ms
CDCHOST
DCR-Decision-By
M-TraceId
X-A-Ccd
X-Epic-Correlation-Id
X-Developer
X-External-Request-Id
X-Extlb
X-Forwarded-Path
X-Destination
X-Debug-Cache
X-Conf
X-Connection-Hash
X-Rojux
X-D
X-From
X-Ftr-Request-Id
X-PBS-Appsvrname
X-Ratelimit-Reset
X-Proxied
X-Platform-Server
X-Request-URI
X-PAYTM-SRV-ID
X-NAPM-TraceId
X-NU-AKA-ACS-Version
X-Rewrite-Enabled
X-Orig-Expires
X-CF-Lambda-Version
X-Cache-NE
X-Processor
X-A-Dam
X-S
X-A-Dcw
X-A
T-Server
X-ScT
State
X-S-Cookie
Surrogated-Key
X-A-Dgt
X-A-Wwc
X-BBC-Edge-Cache-Status
X-Routing-Service
X-BCube-Filmed-By
X-Cache-Bucket
X-B-Cookie
X-ARC
X-Aed
X-Aicache-OS
X-AIR-PT
X-Application
X-Session-Fingerprint
X-CF-Lambda-Fn
User-Cache-Control
X-Storage
X-DataDome
X-Cache-NGX
X-EC-Lua
X-Cms-Context
X-Rebelmouse-Surrogate-Control
X-Core-Value
X-Backend-State
X-Cache-Info
X-VG-TLSProxy
X-Variation
X-Clientip
X-Clara-WADP
X-WADP-Cache
Is-Eu
Fastly-SWR
Fastly-SIE
Fastly-Drupal-HTML
L
Origin
X-VServer
X-TrackingId
Platform
UCS
X-SVT-ORM-VERSION
X-Men
X-Loc
X-LI-UUID
X-Li-Pop
X-Service
X-Origin-Expires
X-Rebelmouse-Cache-Control
X-Proxy-Upstream
X-Request-UUID
X-Li-Fabric
X-JWT-State
X-Envoy-Decorator-Operation
X-SVT-ORM-RULES
X-DPWN-IS-SECURE
Fastly-Backend-Name
X-Fastly-Backend
X-Fastly-Cache
X-Is-Gdpr
X-Has-Esi
X-Fmm-Version
X-Date
X-Accel-Expires-Debug
CDN-RequestCountryCode
CDN-RequestId
CDN-Uid
Cmsid
CDN-PullZone
CDN-EdgeStorageId
Adler-Geo
Cache-Host
Cache-Key
CDN-CachedAt
Cmstype
CDN-Cache
AMP-Access-Control-Allow-Source-Origin
X-DefHash
X-Thanos
X-DefElseHash
X-Thinkindot-L3
Fastcgi-Cache-TTL
X-Cluster
X-Developers
X-Device-Os
X-Esi-Check
X-Ua-Browser
X-Content
Arc-Version
C-Via
X-Ckpd-Fst-Backend
X-Var-Ttl
X-Varnish-CookieINHashed-On
X-Bip
X-Varnish-Remaining-TTL
X-VarnishDD-TTL
X-VC-Cache
X-Block-Status
X-Branch-Name
X-Varnish-CookieHashed-On
X-Cache-Tags
DSUID
X-Cache-Id
X-Cache-Debug
X-Forwarded-Site
X-Via-NSCOPI
X-Served-From
X-Scheme
X-Micro-Cache
X-Location
X-Level-Front-Cache
X-Nginx-Cache-Key
X-Old-Content-Length
X-Req
X-RateLimit-Limit-Second
X-Request-Host
X-Rocket-Build-Number
X-Origin
X-Sigma
X-Sigma-Backend
X-Generated-On
X-Geo-Header
X-Generated-By
X-Gen-Mode
X-Gamma-Serve
X-GoCache-CacheStatus
X-Gzip
X-Slack-Backend
X-SIPLIST1
X-Hnp-Log
X-HN
X-Hash
X-RateLimit-Remaining-Second
Esi-Enabled
TDXMobile
PB-PID
PB-RID
Thinkindot-CacheControl
Thinkindot-Control
Vix-Hermes-Req-Id
X-Viewer-Country
True-Client-Country-4JS
PFcat
Pics-Label
Server-Host
Server-Ext
X-Wikidot-Static-Cache
Server-Hostname
X-Wikidot-Backend
Sever-Int
Cf-Device-Type
VNS-Age
Thinkindot-CacheControl-Type
X-Worker
IsBot
CPC-Age
Location
Locid
NGX
CPC-Cache
VNS-Cache
X-Platform
X-DC
Server-Info
X-Amz-Meta-S3cmd-Attrs
X-NCache
Memcached
X-Owner
X-Fetched-On
X-FC-Vary-Parameters
NM-Fastcgi-Cache
X-Mvc-Supplant-Cachable
X-Sucuri-ID
L5d-Success-Class
Mail-Subject
X-Planisys-CDN-TTL
AKAMAI
X-Auto-Login
X-GeoIP
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Skip-Cache
X-GeoIP-City
X-Eu-Site
X-Irp-Debug
X-Generated-In
Release
X-Planisys-CDN-Cache
Wxu-Next-Hostname
Pagetype
X-Planisys-CDN-Rules
HA-Ipaddr
Ha-Gx-Prefs
X-Csrf-Jwt
X-M-Reqid
X-Vdms-Path
X-CGP
CacheControlHeader
Gh-Request-Id
We-Hiring
Arc-Country
V-Age
X-Policy
X-M-Log
Wxu-Next-Commit
Wxu-Next-Region
Svr
X-Tx-Id
NtCoent-Length
DataCenter
X-Qnm-Cache
Webserver
X-Qloud-Router
X-HS-Content-Campaign-Id
Kp-EeAlive
X-V-Cache
XServer
X-Unique-ID
X-Render-Time
X-Rocket-Nginx-Serving-Static
X-Platform-Cluster
X-Via-Poph
Cache-Hits
X-Platform-Processor
X-Via-Popn
X-Via-Popv
X-Platform-Router
X-Mvc-Supplant-OutputCached
X-LSADC-Cache
X-Zone
X-SD-PageType
MIME-Version
X-User
X-Servedbyhost
X-Srv
Who
X-Cache-Remote
X-Cache-Ttl
X-PF-Uncompressing
Environment
X-NC
X-Cache-Var
X-ID
X-Cache-Var-Map
X-NodeID
X-PJAX-URL
X-Traceid
X-Datadog-Trace-Id
X-BBC-Origin-Response-Status
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
X-Vc
X-Varnish-Url
X-Gdpr
X-API-Version
X-Minions-Version
X-Origin-Time
X-Nyt-Route
WebServer
X-Varnish-Ttl
X-LB-ID
X-Wa
X-Refresh
X-Via-Ucdn
Cluster
X-App
Memory
X-Pod-Name
X-Cache-Config
X-Server-IP
Time
Candidate-Md5Url
X-TIME
Server-ID
X-Webkit-Csp
My-App
X-Internal-Host
Powered-By-ChinaCache
X-CACHE-KEY
X-ZONE
HostName
X-Newrelic-Synthetics
X-Webkit-CSP-Report-Only
X-VCL-Version
X-Pass-Why
Geoip-Latitude
X-TX-ID
X-Esi
N-Cache
X-CLOUD-TRACE-CONTEXT
Datacenter
Web-Mar-Region
X-NewRelic-App-Data
GeoIp-Country-Code
Onion-Location
X-OVcl
X-OVcl-Cache
X-Edge-Pop
X-Correlation-ID
Geo-Info
X-Tb-Optimization-Total-Bytes-Saved
X-ElasticPress-Query
Resin-Trace
X-LI-Proto
X-TraceId
X-VHOST
Hostname
X-Akamai-Pragma-Client-IP
Cf-Bgj
X-Backend-TTL
Tcn
Ohc-File-Size
X-HITS
Magicmarker
X-CACHE-AGE
Servername
X-Dynatrace
X-Varnish-Cacheable
X-Origin-Response-Time
X-Tt-Logid
X-Varnish-Beresp-TTL
X-Geo
X-EIG-Tracking-Id
WWW-Authenticate
CDN
X-Li-Proto
X-NODE
X-Method
X-Dispatcher-Server
X-AB
X-MSEdge-Features
Proxy-Connection
X-MSEdge-Flight
GeoIP-Country-Code
X-Wix-Viewer-Type
X-Fpc
Redirect-Candidate
X-Dynatrace-Js-Agent
LB
X-TIM-N
X-Tid
Cdn
X-HostName
DB-Nickname
Tracecode
GeoIP-Latitude
X-Cs
X-IP
X-Fastly-Request-Id
Ssr
X-Up
X-Vcl-Version
Cf-Ipcountry
X-Cache-Date
Lb
Server-Id
Is-Us
X-Request-Start
X-HS-Status
Pramga
X-Fastly-Backend-Reqs
CF-Cached-On
X-COUNTRY
X-APP
X-Node-Id
Sid
X-Sn-Servicetimems
X-Cdn-Origin
X-Amz-Meta-Cb-Modifiedtime
X-MG-S
X-Provided-By
W
X-WA
X-Core-Mission
X-ServerName
Cteonnt-Length
X-ND-Cache
X-Trv-Group
X-Webkit-Csp-Report-Only
X-NGINX-Cache
X-CSRF-TOKEN
X-Nc
X-UnsetCookies
X-FORWARDED-FOR
X-Check-Cacheable
X-VC
X-Cache-Expires
URI
X-Reqid
WZWS-RAY
X-Lb-Id
CloudFront-Viewer-Country
Env
X-DynaTrace-JS-Agent
X-Via-CDN
X-Pjax-Url
Ohc-Cache-HIT
X-ServedByHost
X-SERVER-NAME
Mime-Version
X-Via-PopN
X-Via-PopV
X-Via-PopH
X-Cache-Backend
WP-Super-Cache
X-ECache
X-Cache-Status-Check
X-CCDN-CacheTTL
X-SN
CountryCode
Shield-Pop
X-CCDN-Origin-Time
X-Region-Sid
X-IN-APIGATEWAYSSL
X-Pf-Uncompressing
X-IN-APIGATEWAY
X-Sucuri-Cache
X-Hcs-Proxy-Type
X-Acquia-Site
X-Acquia-Purge-Tags
X-Acquia-Application-Trace
X-Acquia-Application-UUID
VivaBuild
X-Contensis-Viewer-Groups
CACHE
X-Pad
X-RAMCache
X-Moov-T
X-Moov-Xdn-Version
Xc-Version
X-LiteSpeed-Cache-Control
X-Cache-ASPX
X-CUA
Viewtype
X-Edge-POP
X-Fastly-Cache-Hits
Server-Ttl
Rt-Fastcgi-Cache
X-Varnish-Authentication
X-Ig-Push-State
User-Agent
X-Cdn-Request-ID
EpKe-Alive
X-RPM
Xet-Cookie
ServerName
Vha6-Origin
X-Action
X-Yottaa-OS
X-Dw-Trace-Id
X-Webstats-RespID
X-SB
X-Swift-Error
X-DB
Ohc-Response-Time
X-StackifyID
X-B3-Spanid
X-DI
X-RSL
X-RPS
X-DSS
X-DW
X-Cdn-Forward
FSS-Cache
X-Amz-Meta-Opti
X-FPC
PICS-Label
HIT
X-CF-Powered-By
X-ElasticPress-Search
Req-ID
X-TH-Server
Content-Style-Type
X-MiniProfiler-Ids
Machine
Content-Script-Type