Threat Level: green Handler on Duty: Renato Marinho

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-RAY
CF-Cache-Status
Accept-Ranges
Link
ETag
Pragma
Expect-CT
X-Powered-By
Via
X-XSS-Protection
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-Xss-Protection
P3P
Alt-Svc
X-UA-Compatible
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Request-ID
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-Cacheable
X-DNS-Prefetch-Control
Timing-Allow-Origin
P3p
X-Content-Security-Policy
X-Iinfo
Status
X-Ua-Compatible
Feature-Policy
Content-Encoding
X-AspNetMvc-Version
X-CDN
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
Upgrade
X-Drupal-Dynamic-Cache
Access-Control-Max-Age
X-Dns-Prefetch-Control
X-Via
Keep-Alive
X-Ws-Request-Id
Request-Context
Server-Timing
X-Robots-Tag
X-AH-Environment
X-Hacker
X-Server
X-Age
X-Turbo-Charged-By
X-Proxy-Cache
X-Cache-Group
X-Server-Powered-By
X-Backend
X-Amz-Request-Id
Host-Header
X-Amz-Id-2
EagleId
X-Nginx-Cache-Status
Report-To
X-Rq
X-LiteSpeed-Cache
X-Varnish-Cache
X-UA-Device
X-Page-Speed
Grace
X-Pingback
X-Swift-SaveTime
X-Swift-CacheTime
X-Device
Ali-Swift-Global-Savetime
EagleEye-TraceId
X-Vhost
X-OneAgent-JS-Injection
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
NEL
X-Amz-Version-Id
Cf-Railgun
X-Dispatcher
X-Host
X-Server-Id
X-Cache-Spec
X-CST
X-Node
Allow
X-Backend-Server
Request-Id
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Surrogate-Control
X-WebKit-CSP
X-Readtime
X-Akam-SW-Version
X-Response-Time
Accept-CH
X-Webkit-CSP
Accept-Ch-Lifetime
Xkey
X-Ruxit-JS-Agent
X-HW
X-Language
X-Application-Context
X-Country
X-Ac
X-Template
Content-Location
X-Cache-Lookup
MS-Author-Via
X-Cloud-Trace-Context
Rating
X-Url
X-B3-TraceId
Edge-Control
X-Mod-Pagespeed
X-TtlSet
X-PC
X-Vname
X-Clacks-Overhead
X-Varnish-TTL
Accept-Ch
X-Trace
X-MS-InvokeApp
X-ESI
X-Content-Type
Fastly-Restarts
X-Rack-Cache
X-GitHub-Request-Id
X-Origin-Cache
X-Cnection
X-FastCGI-Cache
X-Goog-Hash
X-Country-Code
X-Buckets
X-GoogleNews-Bot
X-Use-Magma
X-Kinja
X-Exp-Id
X-Kinja-Build
X-Kinja-Server
X-Exp-Variant
X-Cdn-Fetch
X-Kinja-Revision
X-D2id
Verso
X-VARITI-CCR
Accept-CH-Lifetime
Arr-Disable-Session-Affinity
X-Vcap-Request-Id
X-Cached
Cache-Tag
X-ORACLE-DMS-ECID
X-Abt-Application-Version
X-Server-Name
X-Amz-Rid
Service-Worker-Allowed
X-Server-ID
X-Client-IP
X-Navigation-Version
X-Powered-By-Plesk
RTSS
X-Fastly-Request-ID
X-Px
Access-Control-Request-Method
Public-Key-Pins
X-Element-Page-Cache
X-MSEdge-Ref
X-Powered-CMS
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Dw-Request-Base-Id
X-TTL
X-Upstream
X-NF-Request-ID
X-Cache-TTL
X-Sol
X-Version
Display
X-Middleton-Response
Pagespeed
Response
X-Middleton-Display
S
X-Edge
X-Edge-Location-Klb
X-Kinsta-Cache
X-LLID
X-Ttl
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
Realpath
X-Accel-Expires
X-ECACHE
X-Kraken-Routeconfig-Destination
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Instrumentation
X-HP-Webp
X-Cache-Key
X-Jurisdiction
X-Correlation-Id
SPRequestGuid
X-SharePointHealthScore
SPRequestDuration
X-Shield-Request-Id
SPIisLatency
X-T
X-Mid
X-MCACHE
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-Litespeed-Cache
X-XRDS-Location
X-DynaTrace
X-Content-Security-Policy-Report-Only
Edge-Cache-Tag
X-PressLabs-Stats
X-Forwarded-Proto
X-ORACLE-DMS-RID
Fastcgi-Cache
X-Mg-S
X-Amz-Server-Side-Encryption
X-Recruiting
TP-L2-Cache
TP-Cache
X-Content-Digest
Nginx-Cache
Charset
Front-End-Https
X-Request-Processing-Time
X-Request-Received
X-Id
TCN
Alternate-Protocol
Filters
Server-Node
X-Logged-In
X-Forwarded-For
X-Ezoic-Cdn
Content-MD5
Cache-Tags
X-Geo-Country
Fusion-Component-Id
Fusion-Deployment-Id
Fusion-Content-Source
Fusion-Template-Id
Fusion-Source
Fusion-Content-Id
X-ASPNET-VERSION
X-Protected-By
X-Hostname
X-Amzn-Trace-Id
X-Origin-Upstream-Status
X-Release
X-Grace
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Metageneration
X-Origin-Server
X-F-Cache
X-Www-Served-By
Cleartype
X-Oneagent-Js-Injection
X-Amz-Replication-Status
X-Rid
X-Debug-Info
X-NWS-LOG-UUID
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
X-Contextid
X-HS-Combine-CSS
Host
X-RateLimit-Remaining
X-LB-Cache
X-Activity-Id
X-AppVersion
X-Az
Server-Name
Section-Io-Cache
X-Frontend
X-Browser-Type
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Git-Hash
X-Page-Id
X-Ser
X-Daa-Tunnel
MicrosoftSharePointTeamServices
X-VCache
X-Aspnetmvc-Version
X-Respond-Thread
X-Cache-Age
X-Ruxit-Js-Agent
X-Content-Options
Accept-Charset
X-WebKit-CSP-Report-Only
X-Upgrade-Enabled
X-Hits
Access-Control-Allow-Method
X-Mobile-URL
X-Ab
X-Source
X-DIS-Request-ID
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Route-Name
X-CACHE-GROUP
X-Providence-Cookie
ServerID
X-Request-Guid
X-Is-Crawler
X-Flags
X-Signature
X-Aspnet-Duration-Ms
X-B-Cache
Healthy
X-Cache-Action
X-Varnish-Backend
X-Varnish-Grace
X-Varnish-Age
Viewport
X-FB-Debug
X-Whom
X-App-Environment
Payment
X-TT
Paypal-Debug-Id
Node
X-AOL-HN
X-B3-Sampled
Fastcgi-Useragent
DynaTrace
X-Seen-By
Version
X-Load-Cache
X-Yandex-Sdch-Disable
X-N
X-Mobile
DC
X-Type
X-Tt-Trace-Host
X-Distributor
X-HTML-Minification-Powered-By
Filterid
X-Tt-Trace-Tag
SRV
X-Cache-Control
Retry-After
X-Fastcgi-Cache
Frame-Options
X-User-Agent
MS-CV
X-Cache-Expired-At
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
X-Jobs
X-XRDS-LOCATION
AR-ATIME
AR-CACHE
AR-Request-ID
AR-PoweredBy
X-Original-Request-Id
X-Response-Served-From
Ar-Sid
Refresh
X-UUID
NGB
X-IPLB-Instance
X-Adobe-Content
Amp-Access-Control-Allow-Source-Origin
X-Proxy-Cache-Status
X-Page-View
X-Adobe-Loc
X-Instance
X-Debug-IsConnected
X-Debug-IsPreview
X-Region
X-ProcessESI
X-G
X-Proxy
X-Real-IP
X-Tumblr-User
X-Varnish-Server
VIX-Pulpo-Node
X-Cacheable-TTL
X-Cache-Time
X-B
VIX-Pulpo-Upstream-Status
X-Cluster-Name
X-RemovedCookies
X-Tumblr-Pixel-0
Access-Control-Request-Headers
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-FW-Type
X-Content-Powered-By
X-CDN-Forward
X-FW-Serve
X-IPS-LoggedIn
X-FW-Server
Uber-Trace-Id
X-FW-Static
X-Device-Type
X-FW-Dynamic
X-Framework
X-FW-Hash
X-Microsite
X-Vgn-Hpd-Reason
Ms-Operation-Id
X-Request-Handler-Origin-Region
X-RTag
X-NGENIX-Cache
X-Zen-Fury
X-Azure-Ref
X-Wix-Request-Id
X-Node-Name
Cache-Status
X-Cache-Rule
X-Time
X-RateLimit-Limit
Countrycode
X-Cache-Hit
X-Mg-Request-UUID
X-Oracle-Dms-Rid
Section-Io-Id
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
Section-Io-Origin-Status
X-Debug
X-Rendered-As
X-Is-Bot
X-Accel-Buffering
X-Ms-Request-Id
X-Ms-Version
SD-X-WS
Referer-Policy
Liferay-Portal
X-Nginx-Cache
Cache
X-App-Version
X-Drupal-Cache-Tags
X-Aws-Lambda-Call-Status
S-Cnection
X-EdgeConnect-Cache-Status
Country
X-FireWall-Port
CF-IPCountry
X-App-Server
X-HP-Trace-Id
X-Environment-Context
X-L-Path
X-Revision
X-Cache-Operation
X-Parallel-Accel
Surrogate-Key
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-TA-CDN-Provider
X-Endurance-Cache-Level
X-ES-SERVER
Meta-Geo
X-Loop
X-RN-RSRV
X-TNCMS
X-GG-Cache-Date
X-SaId
Eomportal-Instance
X-JoinUs
X-UPSTREAM-Address
X-Say-Cacheable
X-Say-TTL
X-Cache-TTL-Remaining
X-Cache-Type
X-Request-Time
X-Xfnlog-Site
X-Drupal-Cache-Contexts
X-Adobe-Source
X-LAGOON
From-Origin
X-SayCDN-TTL
Count-Hit
X-Sorting-Hat-PodId
X-Sql-Count
X-Varnish-Beresp-Grace
X-Varnish-Hostname
X-Shopify-Stage
X-VWS-Id
X-Varnishpool
X-Sql-Duration-Ms
X-Sorting-Hat-ShopId
X-S-Maxage
Protected
X-LJ-Flow-ID
X-Alternate-Cache-Key
X-AWS-Id
X-Backend-Host
X-Human
Country-Code
Azure-Version
Azure-InstanceId
X-ShardId
Azure-RegionName
Azure-SiteName
X-NYM-Debug-Backend
Azure-SlotName
X-ShopId
X-Storefront-Renderer-Rendered
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Device-Class
TWC-Connection-Speed
TWC-Locale-Group
TWC-Privacy
Webcakes-Region
Webcakes-App-Version
Webcakes-App-Name
X-Server-W
ServedBy
Decoy-Debug-Status
Decoy-Debug-Key
X-Status
X-Timing-Wait
Decoy-Debug-TTL
Fastly-SSL
X-No-Session
GEO-INFO
Property-Id
X-Akamai-Edgescape
X-RCS-CacheZone
X-Hosted-By
X-Handled-By
X-PHP-Backend
X-FB-TRIP-ID
X-PCL
X-Labrador-Cache-Channel
X-OCL
X-Origin-Date
X-Origin-Hint
X-PHP-Host
X-Proto
X-ProxyCache-Status
X-Pubstack
X-R9-Blue-Green-Version
X-Be
X-BYPASS-REASON
X-Proxy-Build
X-Cache-Server
X-ProxyCache-Key
Cache-Tv-Group
Selected-Fe
X-UA-Device-Type
Akamai-GRN
Apigw-Requestid
Cache-Name
X-Section
X-Access
X-FW-Version
X-Via-Fastly
X-Redis-Cache
X-Web-Node
X-Uri
Mn-Server-Ip
X-Hyper-Cache
X-Format
X-Tumblr-Pixel-2
X-PERF
X-TEC-API-ROOT
Nel
X-ApacheServer
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-B3-SpanId
X-Ua-Device
X-Hl-Ver
X-Backend-Name
X-Cluster-Node
X-ATG-Version
X-Time-Microsecs
X-Servername
X-Cache-PHP
X-APP-VERSION
X-ServerID
OT-Force-Account-Verify
Xserver
X-Tumblr-Pixel-3
X-Trace-Id
Backend
X-Detected-As
X-Content-Age
Cross-Origin-Opener-Policy
X-Azure-Ref-OriginShield
X-TT-LOGID
X-CSRF-Token
Web-Mar-Node
X-WA-Info
X-Cache-Host
X-Generation-Time
X-MP-GENERATED-AT
X-Varnish-Cache-Hits
X-Datadome
X-CS
X-Cache-Enabled
X-Cached-By
X-Cache-Ttl
X-Rule
X-Akamai-Transformed
X-Soup
X-Varnish-Hits
X-SRV
X-Edge-Location
Cross-Origin-Window-Policy
X-Bc-Bl
Content-Secure-Policy
X-Ua
Ec-Rule-Version
X-Mode
X-Info
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Amzn-Remapped-Content-Length
X-Microcachable
X-Via-JSL
S-Rt
X-Varnish-Beresp-Status
X-Varnish-Beresp-Ttl
X-Cache-Grace
X-B3-Traceid
X-NWS-UUID-VERIFY
Url
X-Origin-TTL
X-Forwarded-Host
Upgrade-Insecure-Requests
X-Origin-CC
X-Storage
X-GEO
Source
X-Locale
X-Debug-Cache
SID
X-Tb
X-Zipkin-Id
X-Magnolia-Registration
X-Proxied
X-Cache-NGX
X-Routing-Service
X-Extlb
CDN-RequestId
CDN-PullZone
CDN-EdgeStorageId
CDN-Uid
X-PAYTM-SRV-ID
X-PBS-Appsvrname
X-Shop-Environment
Fastcgi-X-Cache-Version
Expiry
DCR-Processing-Time-Ms
DCR-Decision-By
CDN-Cache
X-Orig-Expires
A
X-Site-Version
X-NU-AKA-ACS-Version
X-NAPM-TraceId
Apple-News-Services-Handled
Apple-News-Services-Host
CDCHOST
BehaviorPad-Version
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
CDN-CachedAt
MD5-Digest
X-BCube-Filmed-By
X-From
X-Cache-Bucket
X-B-Cookie
X-ARC
X-Aicache-OS
X-AIR-PT
X-Application
X-Cache-NE
X-CF-Lambda-Fn
X-Forwarded-Path
X-Epic-Correlation-Id
X-External-Request-Id
X-Developer
X-Destination
X-CF-Lambda-Version
X-Connection-Hash
X-D
X-Aed
X-A-Wwc
Odigeo-Trace-Id
Path
X-GoCache-CacheStatus
Mobile-Detection-Method
Meta-Geo-Continent
Fastly-SWR
Host-ID
M-TraceId
Rendered-Blocks
Req-Svc-Chain
X-A-Dam
X-A-Dcw
X-A-Dgt
X-A-Ccd
X-A
State
Surrogated-Key
T-Server
Fastly-SIE
CDN-RequestCountryCode
X-Air-Hostname
X-S
X-S-Cookie
X-Air-Source
X-Rojux
X-Processor
X-Session-Fingerprint
X-SRCache-Key
X-Vtex-Processado-Em
X-Rebelmouse-Cache-Control
X-Request-URI
X-ScT
X-Tenant
X-Rebelmouse-Surrogate-Control
X-Unique-Id
X-Vtex-Remote-Cache
X-Rewrite-Enabled
X-VG-WebServer
X-Air-Trace-Id
X-VG-WebCache
X-Platform-Server
X-Vdms-Version
X-DataDome
Content-Disposition
X-Platform
X-DC
User-Cache-Control
X-Hash
X-Rocket-Build-Number
X-Request-UUID
X-WADP-Cache
X-Envoy-Decorator-Operation
X-Clientip
X-Has-Esi
X-DPWN-IS-SECURE
L
Is-Eu
Fastly-Drupal-HTML
Fastly-Backend-Name
X-Fastly-Cache
X-Clara-WADP
X-Fastly-Backend
X-Is-Gdpr
X-JWT-State
X-Device-Os
Pics-Label
X-Branch-Name
X-Cms-Context
X-Fmm-Version
Esi-Enabled
X-Accel-Expires-Debug
X-Variation
X-Var-Ttl
X-TrackingId
UCS
X-Core-Value
Platform
X-VG-TLSProxy
X-Backend-State
X-Cache-Info
X-Date
X-VServer
X-Cache-Debug
Origin
NGX
X-LI-UUID
X-Origin-Expires
X-Proxy-Upstream
Adler-Geo
X-Conf
X-Li-Pop
X-Ratelimit-Reset
X-Dc
X-Ftr-Request-Id
X-Sigma
X-Li-Fabric
X-Loc
Cache-Host
X-Sigma-Backend
Cache-Key
Cmstype
Cmsid
AMP-Access-Control-Allow-Source-Origin
Server-Info
X-Thinkindot-L3
X-Varnish-CookieHashed-On
X-Men
X-Location
X-Service
X-Gamma-Serve
X-Gen-Mode
Vix-Hermes-Req-Id
VNS-Age
X-Generated-By
DSUID
X-Generated-On
VNS-Cache
We-Hiring
X-SVT-ORM-RULES
Wxu-Next-Region
Wxu-Next-Hostname
Wxu-Next-Commit
X-Viewer-Country
X-Block-Status
X-DefElseHash
X-DefHash
X-EC-Lua
X-Forwarded-Site
X-Origin
X-Developers
X-SIPLIST1
X-Fetched-On
NtCoent-Length
X-Esi-Check
X-Vdms-Path
X-Cluster
X-Old-Content-Length
X-Bip
Thinkindot-Control
X-VarnishDD-TTL
X-RateLimit-Limit-Second
X-Varnish-Remaining-TTL
X-Micro-Cache
X-Via-NSCOPI
X-Cache-Tags
X-Amz-Meta-S3cmd-Attrs
X-Nginx-Cache-Key
X-Cache-Id
X-Varnish-CookieINHashed-On
True-Client-Country-4JS
Thinkindot-CacheControl-Type
Memcached
Mail-Subject
X-HN
X-Hnp-Log
X-Request-Host
X-Req
NM-Fastcgi-Cache
X-Slack-Backend
X-Gzip
CacheControlHeader
X-Wikidot-Backend
Locid
Fastcgi-Cache-TTL
X-SVT-ORM-VERSION
X-Served-From
X-Wikidot-Static-Cache
X-Level-Front-Cache
CPC-Cache
CPC-Age
Location
Kp-EeAlive
IsBot
Cf-Device-Type
X-Ratelimit-Limit
X-VC-Cache
Sever-Int
X-GeoIP
Server-Hostname
Server-Host
X-BBC-Edge-Cache-Status
X-Thanos
Thinkindot-CacheControl
TDXMobile
X-RateLimit-Remaining-Second
Server-Ext
X-Geo-Header
C-Via
PB-RID
PFcat
Arc-Version
PB-PID
X-Planisys-CDN-TTL
X-Unique-ID
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Owner
Svr
X-FC-Vary-Parameters
X-Skip-Cache
X-Eu-Site
X-Planisys-CDN-Cache
AKAMAI
V-Age
X-Planisys-CDN-Rules
X-Generated-In
Gh-Request-Id
X-Sucuri-ID
X-CGP
Arc-Country
Release
X-Mvc-Supplant-Cachable
X-Scheme
X-Ckpd-Fst-Backend
L5d-Success-Class
Ha-Gx-Prefs
X-GeoIP-City
X-Csrf-Jwt
HA-Ipaddr
X-Policy
Pagetype
X-Irp-Debug
Who
Webserver
X-User
X-HS-Content-Campaign-Id
X-Worker
X-Qloud-Router
XServer
DataCenter
Cache-Hits
X-NC
MIME-Version
X-Servedbyhost
X-Tx-Id
X-Mvc-Supplant-OutputCached
X-Ratelimit-Remaining
X-V-Cache
X-Auto-Login
X-Via-Poph
X-Via-Popv
X-Via-Popn
X-NCache
X-M-Log
X-Minions-Version
X-M-Reqid
X-Varnish-Url
X-PF-Uncompressing
X-Srv
X-Qnm-Cache
X-Platform-Router
X-Platform-Processor
X-Vc
X-Platform-Cluster
X-Render-Time
X-Rocket-Nginx-Serving-Static
X-LSADC-Cache
X-ID
X-Zone
X-Traceid
X-Refresh
X-SD-PageType
X-Wa
My-App
Powered-By-ChinaCache
X-Varnish-Ttl
X-Cache-Remote
WebServer
X-Datadog-Trace-Id
Server-ID
X-Datadog-Sampling-Priority
X-Datadog-Parent-Id
Environment
Time
X-LB-ID
X-Internal-Host
X-Newrelic-Synthetics
Memory
X-ZONE
X-Ua-Browser
X-App
X-Content
X-Nyt-Route
X-TIME
X-NodeID
X-Gdpr
X-PJAX-URL
X-Origin-Time
X-Pass-Why
X-Webkit-Csp
X-API-Version
X-VCL-Version
X-BBC-Origin-Response-Status
X-Cache-Var
X-Cache-Var-Map
X-CACHE-KEY
X-TX-ID
X-Server-IP
Cluster
X-Via-Ucdn
Datacenter
X-NewRelic-App-Data
X-Cache-Config
X-OVcl-Cache
Candidate-Md5Url
Hostname
X-Pod-Name
X-OVcl
X-LI-Proto
Geoip-Latitude
GeoIp-Country-Code
HostName
X-CLOUD-TRACE-CONTEXT
Cf-Bgj
X-Backend-TTL
X-Webkit-CSP-Report-Only
Geo-Info
Magicmarker
N-Cache
X-ElasticPress-Query
Resin-Trace
X-Tb-Optimization-Total-Bytes-Saved
X-TraceId
X-VHOST
X-Edge-Pop
Web-Mar-Region
Ohc-File-Size
Tcn
X-Origin-Response-Time
X-CACHE-AGE
X-HITS
X-Dispatcher-Server
X-Method
X-Dynatrace
DB-Nickname
Onion-Location
X-Akamai-Pragma-Client-IP
Servername
X-Geo
Ssr
X-NODE
X-Varnish-Cacheable
X-Li-Proto
GeoIP-Latitude
X-MSEdge-Flight
X-IP
GeoIP-Country-Code
X-MSEdge-Features
X-Varnish-Beresp-TTL
X-EIG-Tracking-Id
X-AB
X-Correlation-ID
LB
Proxy-Connection
X-Wix-Viewer-Type
WWW-Authenticate
Cdn
X-Esi
X-HostName
X-Node-Id
X-Dynatrace-Js-Agent
CDN
X-Fpc
CF-Cached-On
Cf-Ipcountry
X-Vcl-Version
X-TIM-N
X-Tid
X-Trv-Group
X-ND-Cache
Redirect-Candidate
X-HS-Status
X-Cs
X-DynaTrace-JS-Agent
Server-Id
Tracecode
Sid
X-Fastly-Backend-Reqs
WZWS-RAY
X-Via-CDN
X-Tt-Logid
X-Pjax-Url
X-APP
X-COUNTRY
X-Up
Env
X-MG-S
Lb
Cteonnt-Length
X-Webkit-Csp-Report-Only
Is-Us
X-Request-Start
X-NGINX-Cache
Pramga
X-URL
X-ServerName
X-Cache-Date
X-WA
X-CSRF-TOKEN
X-Nc
X-Amz-Meta-Cb-Modifiedtime
X-Lb-Id
X-Cdn-Origin
X-Sn-Servicetimems
URI
X-Check-Cacheable
X-VC
X-Reqid
Ohc-Cache-HIT
X-Cache-Backend
W
X-IN-APIGATEWAYSSL
X-Provided-By
VivaBuild
Viewtype
X-SERVER-NAME
Rt-Fastcgi-Cache
X-Core-Mission
X-IN-APIGATEWAY
X-Via-PopN
X-Via-PopH
X-Via-PopV
X-Fastly-Request-Id
X-UnsetCookies
Shield-Pop
Mime-Version
Server-Ttl
X-ServedByHost
CountryCode
X-Cache-Expires
CloudFront-Viewer-Country
X-SN
X-Presslabs-Stats
X-Acquia-Purge-Tags
X-Acquia-Site
CACHE
X-Contensis-Viewer-Groups
X-Acquia-Application-UUID
X-Cache-ASPX
Machine
X-Acquia-Application-Trace
X-FORWARDED-FOR
X-Fastly-Cache-Hits
X-Varnish-Authentication
X-LiteSpeed-Cache-Control
X-RAMCache
WP-Super-Cache
X-Pad
X-Pf-Uncompressing
X-StackifyID
X-Edge-POP
X-Hcs-Proxy-Type
X-RPS
X-Cdn-Request-ID
X-FTR-Request-ID
Xet-Cookie
X-SB
X-Swift-Error
X-Sucuri-Cache
X-RPM
X-Region-Sid
X-RSL
Vha6-Origin
X-DW
X-CUA
Ohc-Response-Time
X-Yottaa-OS
X-Webstats-RespID
X-CCDN-Origin-Time
X-Dw-Trace-Id
X-DI
X-DSS
X-Action
X-DB
X-CCDN-CacheTTL
X-Cache-Status-Check
X-Cdn-Forward
Content-Style-Type
Xc-Version
X-Moov-T
X-CF-Powered-By
Req-ID
X-Moov-Xdn-Version
X-FTR-Expires
FSS-Cache
On-Server
X-FTR-Realm
X-ElasticPress-Search
X-Oss-Storage-Class
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Oss-Request-Id
X-TH-Server
X-FTR-DC
X-MiniProfiler-Ids
X-Country-Code-Real
ServerName
X-C
X-FTR-Backend
X-FTR-Cache-Status
X-FTR-Balancer
X-FTR-Backend-Server
Content-Script-Type