Threat Level: green Handler on Duty: Russ McRee

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
Link
ETag
Pragma
Expect-CT
X-Powered-By
X-XSS-Protection
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
P3P
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Timer
X-Download-Options
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-Request-ID
X-Cache-Status
P3p
X-Generator
X-Cacheable
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Content-Security-Policy
X-Iinfo
Status
X-Ua-Compatible
Feature-Policy
Content-Encoding
X-AspNetMvc-Version
X-CDN
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
Upgrade
X-Dns-Prefetch-Control
X-Drupal-Dynamic-Cache
Access-Control-Max-Age
X-Via
Keep-Alive
X-Ws-Request-Id
X-Robots-Tag
Request-Context
Server-Timing
X-AH-Environment
X-Hacker
X-Server
X-Age
X-Turbo-Charged-By
X-Proxy-Cache
X-Server-Powered-By
X-Cache-Group
X-Backend
X-Amz-Request-Id
Host-Header
X-Amz-Id-2
EagleId
X-Nginx-Cache-Status
Report-To
X-LiteSpeed-Cache
X-Rq
X-Varnish-Cache
X-UA-Device
X-Page-Speed
Grace
X-Pingback
X-Swift-SaveTime
X-Swift-CacheTime
EagleEye-TraceId
Ali-Swift-Global-Savetime
X-Device
X-Vhost
X-OneAgent-JS-Injection
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Amz-Version-Id
NEL
X-Dispatcher
Cf-Railgun
X-Host
X-Cache-Spec
X-Server-Id
X-CST
X-WebKit-CSP
X-Node
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Backend-Server
Allow
Request-Id
Surrogate-Control
X-Readtime
X-Akam-SW-Version
X-Response-Time
Accept-CH
Accept-Ch-Lifetime
Xkey
X-HW
X-Ruxit-JS-Agent
X-Language
X-Country
X-Webkit-CSP
X-Application-Context
X-Template
X-Ac
Content-Location
X-Cache-Lookup
MS-Author-Via
Rating
X-Url
X-Cloud-Trace-Context
Edge-Control
X-B3-TraceId
X-Vname
X-TtlSet
X-PC
X-Mod-Pagespeed
X-Clacks-Overhead
Accept-Ch
X-Varnish-TTL
X-Trace
X-ESI
X-MS-InvokeApp
X-Content-Type
Fastly-Restarts
X-Rack-Cache
X-Origin-Cache
X-GitHub-Request-Id
X-Cnection
X-Buckets
X-Country-Code
X-Goog-Hash
Verso
X-D2id
X-VARITI-CCR
X-Exp-Id
X-Cdn-Fetch
X-Use-Magma
X-Kinja-Server
X-Kinja-Build
X-GoogleNews-Bot
X-Kinja
X-Exp-Variant
X-Kinja-Revision
Arr-Disable-Session-Affinity
X-FastCGI-Cache
X-ORACLE-DMS-ECID
X-Vcap-Request-Id
Cache-Tag
X-Cached
X-Server-Name
Service-Worker-Allowed
X-Abt-Application-Version
X-Client-IP
X-Amz-Rid
X-Server-ID
X-Navigation-Version
Accept-CH-Lifetime
X-Px
X-Powered-By-Plesk
RTSS
Public-Key-Pins
Access-Control-Request-Method
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Fastly-Request-ID
X-Powered-CMS
X-Element-Page-Cache
X-MSEdge-Ref
X-Cache-TTL
X-Upstream
X-Dw-Request-Base-Id
X-NF-Request-ID
X-Version
X-TTL
Response
Display
X-Middleton-Display
Pagespeed
X-Middleton-Response
X-Sol
S
X-Edge
X-Edge-Location-Klb
X-Kinsta-Cache
X-LLID
X-ECACHE
X-Ttl
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Kraken-Loop-Name
X-Kraken-Routeconfig-Destination
X-Instrumentation
X-Server-Lifecycle-Phase
X-Accel-Expires
Realpath
X-Jurisdiction
X-HP-Webp
X-Correlation-Id
SPRequestGuid
X-Shield-Request-Id
X-SharePointHealthScore
X-Pinterest-Rid
Pinterest-Generated-By
SPIisLatency
X-T
Pinterest-Version
SPRequestDuration
X-Mid
X-Cache-Key
X-MCACHE
X-PressLabs-Stats
X-Litespeed-Cache
X-Content-Security-Policy-Report-Only
X-ORACLE-DMS-RID
Edge-Cache-Tag
X-DynaTrace
Fastcgi-Cache
X-Forwarded-Proto
X-XRDS-Location
X-Mg-S
X-Amz-Server-Side-Encryption
X-Content-Digest
Nginx-Cache
X-Recruiting
TP-L2-Cache
TP-Cache
Charset
Filters
Front-End-Https
X-Id
X-Request-Processing-Time
X-Request-Received
Alternate-Protocol
Server-Node
X-Logged-In
TCN
X-Ezoic-Cdn
X-Forwarded-For
Content-MD5
X-Geo-Country
Cache-Tags
Fusion-Content-Id
Fusion-Source
Fusion-Deployment-Id
Fusion-Content-Source
Fusion-Template-Id
Fusion-Component-Id
X-ASPNET-VERSION
X-Protected-By
X-Amzn-Trace-Id
X-Grace
X-Origin-Upstream-Status
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Generation
X-GUploader-UploadID
X-NWS-LOG-UUID
X-Hostname
X-Goog-Stored-Content-Encoding
X-Www-Served-By
X-Origin-Server
X-F-Cache
Cleartype
X-Oneagent-Js-Injection
X-Amz-Replication-Status
X-Rid
X-Debug-Info
X-HS-Hub-Id
X-Release
X-HS-Cache-Config
X-HS-Content-Id
X-LB-Cache
X-HS-Combine-CSS
Host
X-Az
X-Activity-Id
X-AppVersion
X-Contextid
Section-Io-Cache
X-Daa-Tunnel
X-Page-Id
X-Browser-Type
Server-Name
X-Erf-Bev-Bev-Is-Generated
X-Git-Hash
X-Erf-Bev-Bev
X-Frontend
X-Ser
X-VCache
MicrosoftSharePointTeamServices
X-Aspnetmvc-Version
X-Respond-Thread
X-Ab
X-Cache-Age
X-RateLimit-Remaining
X-Ruxit-Js-Agent
X-Content-Options
Accept-Charset
Access-Control-Allow-Method
X-Upgrade-Enabled
X-Kong-Upstream-Latency
X-Hits
X-Kong-Proxy-Latency
X-Mobile-URL
X-DIS-Request-ID
ServerID
X-Source
X-CACHE-GROUP
X-WebKit-CSP-Report-Only
X-Signature
X-B-Cache
X-Aspnet-Duration-Ms
X-Is-Crawler
X-Flags
X-Route-Name
X-Providence-Cookie
X-Request-Guid
X-Varnish-Backend
Payment
X-Cache-Action
X-Whom
Healthy
X-Varnish-Grace
X-Varnish-Age
X-TT
X-FB-Debug
Viewport
Paypal-Debug-Id
Node
X-Fastcgi-Cache
X-App-Environment
X-AOL-HN
DynaTrace
X-B3-Sampled
Fastcgi-Useragent
X-Load-Cache
Version
X-Yandex-Sdch-Disable
X-Seen-By
X-Mobile
X-N
DC
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-XRDS-LOCATION
X-HTML-Minification-Powered-By
X-Type
Filterid
X-Distributor
SRV
X-User-Agent
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
Frame-Options
Retry-After
X-Cache-Control
MS-CV
X-Jobs
Refresh
X-Cache-Expired-At
X-Response-Served-From
X-Original-Request-Id
X-UUID
X-Page-View
X-Adobe-Loc
X-Proxy-Cache-Status
NGB
X-Real-IP
X-IPLB-Instance
X-Adobe-Content
X-Varnish-Server
X-Instance
X-Region
X-Cluster-Name
X-FW-Serve
X-FW-Hash
X-FW-Dynamic
X-FW-Server
X-FW-Static
X-Debug-IsPreview
X-Debug-IsConnected
X-FW-Type
X-Device-Type
Access-Control-Request-Headers
X-RemovedCookies
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-ProcessESI
X-G
X-B
X-Cacheable-TTL
X-Content-Powered-By
X-Framework
X-Tumblr-User
X-Proxy
X-IPS-LoggedIn
X-RTag
X-Cache-Time
X-NGENIX-Cache
Ms-Operation-Id
X-Vgn-Hpd-Reason
X-CDN-Forward
X-Azure-Ref
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
Uber-Trace-Id
X-Zen-Fury
Amp-Access-Control-Allow-Source-Origin
X-Node-Name
Ar-Sid
AR-CACHE
AR-ATIME
AR-PoweredBy
AR-Request-ID
Countrycode
X-Microsite
X-Request-Handler-Origin-Region
X-Wix-Request-Id
X-Cache-Hit
Cache-Status
X-Cache-Rule
Section-Io-Id
Section-Io-Origin-Status
X-Ms-Version
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
X-Ms-Request-Id
X-Time
X-Is-Bot
X-Rendered-As
SD-X-WS
X-Mg-Request-UUID
Referer-Policy
X-Oracle-Dms-Rid
X-Aws-Lambda-Call-Status
X-HP-Trace-Id
Liferay-Portal
X-Debug
X-Drupal-Cache-Tags
X-Nginx-Cache
X-Accel-Buffering
X-App-Version
X-EdgeConnect-Cache-Status
X-Parallel-Accel
S-Cnection
Cache
Country
X-RateLimit-Limit
X-Environment-Context
X-L-Path
X-Revision
X-App-Server
CF-IPCountry
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Cache-Operation
Surrogate-Key
X-FireWall-Port
Count-Hit
X-TNCMS
X-TA-CDN-Provider
X-RN-RSRV
X-Loop
X-Endurance-Cache-Level
X-ES-SERVER
X-GG-Cache-Date
X-Drupal-Cache-Contexts
X-JoinUs
X-UPSTREAM-Address
X-SaId
Meta-Geo
Eomportal-Instance
X-SayCDN-TTL
From-Origin
X-LAGOON
X-Timing-Wait
X-Xfnlog-Site
X-Sorting-Hat-PodId
X-ShopId
X-Alternate-Cache-Key
X-Cache-TTL-Remaining
X-Cache-Type
X-ShardId
X-Storefront-Renderer-Rendered
X-Shopify-Stage
Selected-Fe
X-Sorting-Hat-ShopId
X-Proxy-Build
X-Adobe-Source
X-Say-TTL
X-Say-Cacheable
Country-Code
X-Varnishpool
X-Sql-Duration-Ms
Azure-Version
X-Sql-Count
X-Be
X-AWS-Id
X-Proto
X-Origin-Date
Azure-SlotName
X-BYPASS-REASON
X-Varnish-Hostname
X-ProxyCache-Key
X-LJ-Flow-ID
X-No-Session
X-Request-Time
Protected
X-ProxyCache-Status
Azure-RegionName
Azure-InstanceId
Cache-Name
X-Varnish-Beresp-Grace
X-Human
Akamai-GRN
X-FW-Version
X-NYM-Debug-Backend
X-S-Maxage
Azure-SiteName
X-VWS-Id
ServedBy
Cache-Tv-Group
Apigw-Requestid
Decoy-Debug-Key
Decoy-Debug-Status
Decoy-Debug-TTL
Fastly-SSL
X-Labrador-Cache-Channel
X-R9-Blue-Green-Version
X-PHP-Host
X-Akamai-Edgescape
X-Pubstack
X-OCL
X-RCS-CacheZone
X-PCL
X-UA-Device-Type
X-PHP-Backend
X-Hosted-By
X-Status
X-Cache-Server
X-Handled-By
TWC-GeoIP-Country
Webcakes-Region
X-Server-W
X-Backend-Name
TWC-Device-Class
X-Origin-Hint
X-Access
TWC-Connection-Speed
X-Uri
X-Section
X-Format
Webcakes-App-Name
X-Redis-Cache
TWC-Locale-Group
TWC-Privacy
Webcakes-App-Version
X-Tumblr-Pixel-2
X-Via-Fastly
X-Web-Node
X-Hl-Ver
X-Hyper-Cache
TWC-GeoIP-LatLong
Property-Id
Nel
X-ApacheServer
X-Backend-Host
X-PERF
Mn-Server-Ip
X-FB-TRIP-ID
X-B3-SpanId
X-Ua-Device
X-Time-Microsecs
X-Cluster-Node
X-ServerID
GEO-INFO
X-ATG-Version
X-Servername
X-Cache-PHP
OT-Force-Account-Verify
X-TEC-API-VERSION
X-APP-VERSION
Xserver
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TT-LOGID
Cross-Origin-Opener-Policy
X-Tumblr-Pixel-3
X-Detected-As
X-Azure-Ref-OriginShield
X-Datadome
X-CSRF-Token
X-Trace-Id
Backend
X-Content-Age
X-WA-Info
Web-Mar-Node
X-Varnish-Cache-Hits
X-Generation-Time
X-Cache-Host
X-MP-GENERATED-AT
Cross-Origin-Window-Policy
X-Ua
X-CS
X-SRV
Content-Secure-Policy
X-Rule
X-Varnish-Hits
X-Cached-By
X-Akamai-Transformed
X-Soup
X-Bc-Bl
Ec-Rule-Version
X-Edge-Location
X-Cache-Enabled
X-Via-JSL
X-Ratelimit-Limit
X-Amzn-Remapped-Content-Length
X-NWS-UUID-VERIFY
X-Amzn-RequestId
X-Mode
X-Amz-Apigw-Id
Source
X-Info
X-Microcachable
X-Ratelimit-Remaining
X-Cache-Grace
S-Rt
X-Origin-TTL
X-Origin-CC
X-Varnish-Beresp-Status
X-B3-Traceid
X-Forwarded-Host
AMP-Access-Control-Allow-Source-Origin
Upgrade-Insecure-Requests
X-Magnolia-Registration
Url
X-Locale
X-Air-Source
X-Air-Trace-Id
X-Air-Hostname
X-Dc
SID
X-Cache-NGX
X-Storage
X-Tb
X-Debug-Cache
X-Site-Version
X-Varnish-Beresp-Ttl
X-EC-Lua
X-Platform-Server
X-PBS-Appsvrname
Rendered-Blocks
X-PAYTM-SRV-ID
Req-Svc-Chain
X-Orig-Expires
X-Forwarded-Path
CDCHOST
User-Cache-Control
X-D
X-NU-AKA-ACS-Version
CDN-PullZone
X-Epic-Correlation-Id
A
Content-Disposition
MD5-Digest
CDN-Cache
M-TraceId
X-External-Request-Id
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Handled
CDN-CachedAt
Meta-Geo-Continent
CDN-RequestId
CDN-RequestCountryCode
X-NAPM-TraceId
X-Aicache-OS
CDN-Uid
Path
X-Destination
Mobile-Detection-Method
CDN-EdgeStorageId
X-Developer
Odigeo-Trace-Id
X-Zipkin-Id
X-Vtex-Remote-Cache
X-SRCache-Key
Host-ID
X-VG-WebCache
X-BCube-Filmed-By
X-B-Cookie
X-GoCache-CacheStatus
X-VG-WebServer
X-Cache-Bucket
X-Session-Fingerprint
DCR-Decision-By
X-Shop-Environment
DCR-Processing-Time-Ms
Fastly-SIE
X-Tenant
X-ARC
X-A-Wwc
X-A-Dgt
Expiry
X-Aed
X-Vdms-Version
X-A-Dcw
X-Unique-Id
X-AIR-PT
X-Application
X-A
X-A-Ccd
X-A-Dam
Fastcgi-X-Cache-Version
Fastly-SWR
X-Ratelimit-Reset
X-Extlb
X-Vtex-Processado-Em
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-From
X-Clientip
X-Processor
X-Connection-Hash
X-Proxied
X-Conf
BehaviorPad-Version
State
Surrogated-Key
X-S
X-Routing-Service
X-S-Cookie
X-Ftr-Request-Id
X-ScT
X-Rojux
X-CF-Lambda-Fn
X-Request-URI
X-Cache-NE
T-Server
X-CF-Lambda-Version
X-Rewrite-Enabled
X-Cache-Ttl
X-GEO
X-Forwarded-Site
Fastly-Backend-Name
Fastly-Drupal-HTML
Is-Eu
X-Fmm-Version
X-Core-Value
X-Cache-Info
X-Cache-Tags
X-Clara-WADP
X-Cms-Context
X-BBC-Edge-Cache-Status
UCS
X-Accel-Expires-Debug
X-Backend-State
X-Bip
X-Cache-Debug
X-Date
Platform
X-DPWN-IS-SECURE
X-Envoy-Decorator-Operation
X-Fastly-Backend
L
NGX
Origin
Pics-Label
PB-RID
PB-PID
X-Fastly-Cache
X-JWT-State
X-Li-Fabric
X-Li-Pop
X-LI-UUID
X-Loc
X-WADP-Cache
X-SVT-ORM-RULES
X-Hash
X-SVT-ORM-VERSION
X-Platform
X-Men
X-Sigma-Backend
X-Request-UUID
X-Request-Host
X-Proxy-Upstream
X-Origin-Expires
X-VServer
X-Sigma
X-Service
X-Rocket-Build-Number
X-Thanos
X-Is-Gdpr
Cache-Key
X-TrackingId
Cache-Host
X-VG-TLSProxy
Cmsid
DSUID
Cmstype
C-Via
X-Variation
Adler-Geo
X-Has-Esi
Arc-Version
X-Amz-Meta-S3cmd-Attrs
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-RateLimit-Remaining-Second
X-CGP
X-Req
X-VC-Cache
X-VarnishDD-TTL
X-Scheme
X-SIPLIST1
X-Slack-Backend
X-Block-Status
X-Var-Ttl
X-Varnish-CookieHashed-On
X-Via-NSCOPI
X-Served-From
X-Thinkindot-L3
X-Branch-Name
X-Old-Content-Length
X-Eu-Site
X-Gzip
X-Esi-Check
X-HN
X-Irp-Debug
X-Hnp-Log
X-FC-Vary-Parameters
X-GeoIP-City
X-Generated-By
X-Gen-Mode
X-Generated-In
X-Generated-On
X-GeoIP
X-Geo-Header
X-Device-Os
X-Level-Front-Cache
X-Origin
X-Gamma-Serve
X-Wikidot-Backend
X-Csrf-Jwt
X-RateLimit-Limit-Second
X-Policy
X-DefElseHash
X-Wikidot-Static-Cache
X-Location
X-Developers
X-Micro-Cache
X-Mvc-Supplant-Cachable
X-Nginx-Cache-Key
X-DefHash
X-Cluster
X-Cache-Id
IsBot
Server-Hostname
Server-Host
Sever-Int
Esi-Enabled
TDXMobile
Fastcgi-Cache-TTL
Server-Ext
CacheControlHeader
Pagetype
NM-Fastcgi-Cache
PFcat
CPC-Age
Cf-Device-Type
Release
CPC-Cache
Thinkindot-CacheControl
We-Hiring
VNS-Cache
VNS-Age
HA-Ipaddr
Locid
L5d-Success-Class
Location
Ha-Gx-Prefs
Mail-Subject
X-DC
Thinkindot-Control
True-Client-Country-4JS
Gh-Request-Id
Thinkindot-CacheControl-Type
Server-Info
X-Viewer-Country
Arc-Country
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Owner
X-Worker
X-Planisys-CDN-TTL
X-Ckpd-Fst-Backend
AKAMAI
Webserver
X-CLOUD-TRACE-CONTEXT
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Fetched-On
X-DataDome
V-Age
Kp-EeAlive
Vix-Hermes-Req-Id
X-Sucuri-ID
Svr
X-Vdms-Path
Wxu-Next-Hostname
X-Unique-ID
X-Skip-Cache
NtCoent-Length
Wxu-Next-Commit
Memcached
Wxu-Next-Region
DataCenter
X-HS-Content-Campaign-Id
X-M-Reqid
X-Auto-Login
X-M-Log
X-Qloud-Router
X-NCache
X-User
X-Tx-Id
Cache-Hits
X-Via-Poph
X-Mvc-Supplant-OutputCached
X-Via-Popn
X-Via-Popv
Who
X-V-Cache
X-Qnm-Cache
X-CACHE-KEY
X-Content
X-Ua-Browser
X-Platform-Cluster
X-Platform-Processor
X-Servedbyhost
X-LSADC-Cache
X-Render-Time
X-Platform-Router
X-Rocket-Nginx-Serving-Static
X-Zone
X-NC
X-PF-Uncompressing
MIME-Version
XServer
X-Srv
X-Traceid
X-SD-PageType
X-Varnish-Url
X-Minions-Version
X-ID
X-Cache-Remote
Environment
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-LB-ID
X-Vc
X-Datadog-Trace-Id
WebServer
X-Varnish-Ttl
X-ZONE
X-Refresh
X-PJAX-URL
My-App
Powered-By-ChinaCache
X-Origin-Time
X-Nyt-Route
X-Gdpr
X-Wa
X-API-Version
X-Cache-Var-Map
X-Cache-Var
X-BBC-Origin-Response-Status
X-NodeID
Memory
X-Server-IP
Server-ID
X-App
Time
X-Pass-Why
X-TIME
X-Cache-Config
Cluster
X-Internal-Host
X-Via-Ucdn
X-Webkit-Csp
X-Newrelic-Synthetics
X-VCL-Version
Candidate-Md5Url
X-Pod-Name
X-Webkit-CSP-Report-Only
X-TX-ID
Geo-Info
Tcn
HostName
X-Dynatrace
X-NewRelic-App-Data
X-OVcl-Cache
Datacenter
X-OVcl
Resin-Trace
Geoip-Latitude
GeoIp-Country-Code
Hostname
Web-Mar-Region
N-Cache
X-Edge-Pop
Cf-Bgj
X-ElasticPress-Query
X-LI-Proto
X-Tb-Optimization-Total-Bytes-Saved
X-TraceId
X-Backend-TTL
X-VHOST
Magicmarker
Onion-Location
Ohc-File-Size
X-Geo
X-CACHE-AGE
X-HostName
X-Origin-Response-Time
X-HITS
X-Akamai-Pragma-Client-IP
X-Varnish-Beresp-TTL
X-EIG-Tracking-Id
X-Dispatcher-Server
Servername
X-Method
WWW-Authenticate
X-Varnish-Cacheable
X-Li-Proto
X-Esi
DB-Nickname
GeoIP-Country-Code
Proxy-Connection
X-NODE
X-AB
X-Correlation-ID
X-Wix-Viewer-Type
X-IP
Ssr
GeoIP-Latitude
X-MSEdge-Flight
CDN
X-MSEdge-Features
LB
Cdn
X-Vcl-Version
X-Tid
X-TIM-N
X-Fpc
X-Dynatrace-Js-Agent
X-Fastly-Request-Id
Redirect-Candidate
Cf-Ipcountry
CF-Cached-On
Server-Id
X-Up
Lb
X-Request-Start
X-APP
Tracecode
X-Node-Id
X-DynaTrace-JS-Agent
X-Tt-Logid
X-Cs
X-WA
Is-Us
Sid
X-Trv-Group
X-HS-Status
X-Cache-Date
X-Fastly-Backend-Reqs
X-ND-Cache
Pramga
X-MG-S
Env
X-NGINX-Cache
X-Cdn-Origin
X-Reqid
X-Sn-Servicetimems
X-Pjax-Url
Cteonnt-Length
X-Via-CDN
X-Amz-Meta-Cb-Modifiedtime
WZWS-RAY
X-ServerName
X-Webkit-Csp-Report-Only
X-FORWARDED-FOR
X-Nc
X-Check-Cacheable
X-Core-Mission
URI
X-Provided-By
X-Lb-Id
X-VC
W
X-CSRF-TOKEN
X-UnsetCookies
Ohc-Cache-HIT
X-Via-PopH
X-Via-PopN
X-ServedByHost
X-Via-PopV
Mime-Version
CloudFront-Viewer-Country
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-SERVER-NAME
X-Cache-Backend
Shield-Pop
X-Cache-Expires
Rt-Fastcgi-Cache
WP-Super-Cache
Viewtype
X-Pf-Uncompressing
X-SN
Server-Ttl
VivaBuild
CountryCode
X-Acquia-Application-UUID
X-Fastly-Cache-Hits
X-Acquia-Application-Trace
X-Region-Sid
CACHE
X-Sucuri-Cache
X-Acquia-Site
X-LiteSpeed-Cache-Control
X-CCDN-CacheTTL
X-Edge-POP
X-CCDN-Origin-Time
X-RAMCache
X-Hcs-Proxy-Type
X-Cache-Status-Check
X-Acquia-Purge-Tags
X-Varnish-Authentication
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Pad
Vha6-Origin
X-DB
X-Action
X-Cdn-Request-ID
X-CUA
ServerName
X-Moov-Xdn-Version
Xc-Version
X-Moov-T
X-CF-Powered-By
Ohc-Response-Time
EpKe-Alive
X-StackifyID
X-Yottaa-OS
X-RSL
X-RPS
X-RPM
X-SB
X-Dw-Trace-Id
Machine
X-Webstats-RespID
Xet-Cookie
X-DSS
X-DW
X-Swift-Error
X-DI
X-Cdn-Forward
X-Ig-Push-State
User-Agent
X-FPC
Content-Style-Type
Content-Script-Type
X-MiniProfiler-Ids
X-TH-Server
X-ElasticPress-Search
Req-ID