Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
X-XSS-Protection
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
P3P
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Permitted-Cross-Domain-Policies
X-Request-ID
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
P3p
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-FRAME-OPTIONS
X-Iinfo
Status
Content-Encoding
Feature-Policy
X-AspNetMvc-Version
X-CDN
X-Envoy-Upstream-Service-Time
Upgrade
Access-Control-Expose-Headers
X-Ua-Compatible
X-Drupal-Dynamic-Cache
Access-Control-Max-Age
X-Via
Keep-Alive
X-Dns-Prefetch-Control
X-Ws-Request-Id
Request-Context
X-Robots-Tag
Server-Timing
X-AH-Environment
X-Server
X-Hacker
X-Age
X-Turbo-Charged-By
X-Server-Powered-By
X-Proxy-Cache
X-Cache-Group
X-Backend
Host-Header
EagleId
X-Nginx-Cache-Status
X-Amz-Request-Id
X-Amz-Id-2
Report-To
X-LiteSpeed-Cache
X-Rq
X-UA-Device
X-Varnish-Cache
Grace
X-Page-Speed
X-Swift-CacheTime
X-Swift-SaveTime
X-Pingback
Ali-Swift-Global-Savetime
X-Device
EagleEye-TraceId
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Cf-Railgun
X-Vhost
X-Amz-Version-Id
X-OneAgent-JS-Injection
NEL
X-Host
X-Dispatcher
X-Server-Id
X-CST
X-Node
Allow
Surrogate-Control
X-Cache-Spec
Request-Id
X-Backend-Server
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Accept-CH
X-WebKit-CSP
X-Readtime
X-Response-Time
X-Akam-SW-Version
X-Webkit-CSP
Xkey
X-HW
X-Country
Accept-Ch-Lifetime
X-Ac
Content-Location
X-Application-Context
X-Language
MS-Author-Via
X-Cloud-Trace-Context
X-Template
Rating
X-Ruxit-JS-Agent
X-Cache-Lookup
X-Url
X-Mod-Pagespeed
X-B3-TraceId
Edge-Control
X-Vname
X-TtlSet
X-PC
X-Clacks-Overhead
X-ESI
X-MS-InvokeApp
X-Trace
X-GitHub-Request-Id
X-Content-Type
Fastly-Restarts
X-Varnish-TTL
X-Cnection
X-Origin-Cache
X-Rack-Cache
Accept-CH-Lifetime
X-ASPNET-VERSION
X-D2id
X-Country-Code
X-Cdn-Fetch
X-Exp-Id
X-Kinja
X-Use-Magma
X-Kinja-Server
X-Kinja-Revision
X-Kinja-Build
X-GoogleNews-Bot
X-Exp-Variant
Arr-Disable-Session-Affinity
X-Goog-Hash
Verso
X-VARITI-CCR
X-FastCGI-Cache
Accept-Ch
X-Server-Name
X-Vcap-Request-Id
X-Cached
X-Navigation-Version
Cache-Tag
X-Powered-By-Plesk
X-Buckets
X-Abt-Application-Version
X-Amz-Rid
X-Client-IP
Service-Worker-Allowed
X-ORACLE-DMS-ECID
RTSS
X-Fastly-Request-ID
X-Cache-TTL
Pagespeed
X-Middleton-Display
X-Middleton-Response
Response
X-Sol
Display
X-Ttl
Access-Control-Request-Method
X-MSEdge-Ref
X-Element-Page-Cache
X-Powered-CMS
X-NF-Request-ID
X-Dw-Request-Base-Id
Public-Key-Pins
X-Upstream
X-Version
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Edge
S
X-Px
X-Kinsta-Cache
X-LLID
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Edge-Location-Klb
Realpath
X-Accel-Expires
X-TTL
SPRequestDuration
SPIisLatency
SPRequestGuid
X-SharePointHealthScore
X-Ruxit-Js-Agent
X-HP-Webp
X-Oneagent-Js-Injection
X-T
X-Jurisdiction
X-Server-ID
X-ECACHE
X-Mid
X-MCACHE
X-PressLabs-Stats
X-Forwarded-Proto
X-Instrumentation
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Kraken-Routeconfig-Destination
X-Content-Security-Policy-Report-Only
X-Shield-Request-Id
X-Correlation-Id
Edge-Cache-Tag
Pinterest-Version
Pinterest-Generated-By
Charset
X-Pinterest-Rid
X-Recruiting
Fastcgi-Cache
TP-Cache
TP-L2-Cache
X-DynaTrace
X-Amz-Server-Side-Encryption
X-Mg-S
X-Content-Digest
X-Ezoic-Cdn
X-Release
X-Id
X-ORACLE-DMS-RID
X-Request-Processing-Time
Filters
X-Request-Received
Nginx-Cache
X-Logged-In
Server-Node
Alternate-Protocol
Front-End-Https
X-Cache-Key
Cache-Tags
Content-MD5
TCN
X-Forwarded-For
X-Origin-Upstream-Status
Fusion-Deployment-Id
Fusion-Content-Source
Fusion-Source
Fusion-Component-Id
Fusion-Template-Id
Fusion-Content-Id
X-Amzn-Trace-Id
X-XRDS-Location
X-Litespeed-Cache
X-Grace
Server-Name
X-Origin-Server
X-Geo-Country
X-Hostname
X-Contextid
X-Rid
X-Amz-Replication-Status
X-F-Cache
X-AppVersion
X-Az
X-Activity-Id
X-Protected-By
X-Www-Served-By
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
Cleartype
Host
X-WebKit-CSP-Report-Only
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Combine-CSS
X-RateLimit-Remaining
Section-Io-Cache
X-LB-Cache
X-Debug-Info
X-Frontend
MicrosoftSharePointTeamServices
X-XRDS-LOCATION
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Erf-Bev-Bev
X-NWS-LOG-UUID
X-Page-Id
X-Tec-Api-Version
X-Ser
X-Tec-Api-Root
X-Tec-Api-Origin
X-Git-Hash
AR-CACHE
AR-PoweredBy
X-Cache-Age
Ar-Sid
AR-ATIME
AR-Request-ID
X-Respond-Thread
X-Source
X-Upgrade-Enabled
X-Aspnetmvc-Version
Accept-Charset
X-Varnish-Age
X-DIS-Request-ID
X-Hits
X-Content-Options
X-Mobile-URL
Paypal-Debug-Id
X-Varnish-Backend
ServerID
X-Daa-Tunnel
X-Varnish-Grace
Access-Control-Allow-Method
X-Signature
X-B-Cache
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-VCache
X-B3-Sampled
X-Route-Name
X-Providence-Cookie
X-Request-Guid
X-Aspnet-Duration-Ms
X-Cache-Action
X-Fastcgi-Cache
X-Is-Crawler
X-Flags
X-FB-Debug
Payment
X-Whom
X-TT
Viewport
Healthy
X-AOL-HN
X-CACHE-GROUP
Node
X-N
X-App-Environment
X-Seen-By
Version
X-Microsite
X-Request-Handler-Origin-Region
X-Type
X-Load-Cache
Fastcgi-Useragent
X-Mobile
DynaTrace
DC
MS-CV
X-HTML-Minification-Powered-By
X-Yandex-Sdch-Disable
X-Cache-Expired-At
X-Distributor
Retry-After
Filterid
X-Cache-Control
X-IPLB-Instance
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Ab
X-Original-Request-Id
X-User-Agent
SRV
Frame-Options
X-Response-Served-From
X-Real-IP
X-UUID
X-ProcessESI
X-Tumblr-Pixel-1
X-RemovedCookies
X-Tumblr-Pixel-0
X-Jobs
X-Tumblr-Pixel
X-Tumblr-User
X-Instance
X-Debug-IsPreview
X-Adobe-Loc
X-Debug-IsConnected
X-Adobe-Content
Access-Control-Request-Headers
Ms-Operation-Id
X-Cluster-Name
X-Content-Powered-By
X-Device-Type
X-Proxy-Cache-Status
X-IPS-LoggedIn
X-RTag
X-Proxy
X-Varnish-Server
X-Cacheable-TTL
X-B
Refresh
NGB
X-Region
X-Cache-Time
X-Page-View
X-Framework
Uber-Trace-Id
Nel
X-FireWall-Port
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Debug
X-G
X-Accel-Buffering
Cache
X-FW-Hash
X-FW-Server
X-FW-Dynamic
X-FW-Static
X-FW-Type
X-FW-Serve
X-Zen-Fury
Countrycode
X-Time
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
Section-Io-Origin-Status
Section-Io-Id
X-Wix-Request-Id
X-Vgn-Hpd-Reason
X-RateLimit-Limit
X-NGENIX-Cache
X-App-Version
X-Nginx-Cache
X-Azure-Ref
Cache-Status
Surrogate-Key
X-Mg-Request-UUID
X-Oracle-Dms-Rid
X-Cache-Hit
X-Is-Bot
X-Drupal-Cache-Tags
Country
X-Rendered-As
X-Cache-Rule
X-Ms-Version
X-App-Server
X-Ms-Request-Id
S-Cnection
X-EdgeConnect-Cache-Status
X-TA-CDN-Provider
Eomportal-Instance
X-CDN-Forward
X-Node-Name
Referer-Policy
SD-X-WS
Liferay-Portal
X-L-Path
X-Environment-Context
X-Drupal-Cache-Contexts
X-Cache-Operation
X-UPSTREAM-Address
Selected-Fe
CF-IPCountry
X-Tumblr-Pixel-2
X-Varnishpool
X-JoinUs
X-SaId
X-RN-RSRV
X-Proxy-Build
X-ES-SERVER
Meta-Geo
From-Origin
X-Timing-Wait
X-R9-Blue-Green-Version
X-Backend-Host
X-Cache-Server
X-GG-Cache-Date
X-PHP-Backend
X-Shopify-Stage
X-Handled-By
X-Loop
X-No-Session
X-Endurance-Cache-Level
Protected
X-Sorting-Hat-ShopId
X-Varnish-Hostname
X-ShardId
X-Storefront-Renderer-Rendered
X-TNCMS
X-ShopId
X-Via-Fastly
X-Request-Time
X-Sorting-Hat-PodId
X-S-Maxage
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Alternate-Cache-Key
X-ProxyCache-Key
X-ProxyCache-Status
ServedBy
X-Cache-TTL-Remaining
X-Proto
X-Xfnlog-Site
X-Adobe-Source
X-Pubstack
X-Server-W
Azure-Version
Cache-Name
Cache-Tv-Group
Azure-SlotName
Azure-SiteName
Azure-InstanceId
Azure-RegionName
X-AWS-Id
X-VWS-Id
X-Varnish-Beresp-Grace
X-BYPASS-REASON
X-OCL
X-LJ-Flow-ID
X-Human
X-Be
X-PCL
AMP-Access-Control-Allow-Source-Origin
Country-Code
X-Origin-Date
X-LAGOON
Property-Id
X-Origin-Hint
X-Say-Cacheable
X-Hl-Ver
Fastly-SSL
X-NYM-Debug-Backend
TWC-Connection-Speed
X-Backend-Name
Webcakes-App-Name
X-Say-TTL
Webcakes-App-Version
Webcakes-Region
TWC-Device-Class
TWC-Privacy
X-SayCDN-TTL
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-GeoIP-Country
X-Labrador-Cache-Channel
Amp-Access-Control-Allow-Source-Origin
Decoy-Debug-Status
X-Akamai-Edgescape
X-PHP-Host
X-Access
X-RCS-CacheZone
Decoy-Debug-TTL
X-FB-TRIP-ID
X-Format
Decoy-Debug-Key
X-UA-Device-Type
X-Rule
X-Sql-Duration-Ms
X-Sql-Count
Akamai-GRN
Apigw-Requestid
X-Section
Xserver
X-Status
X-Hyper-Cache
X-Cache-PHP
X-Revision
Mn-Server-Ip
X-Uri
X-Hosted-By
X-Redis-Cache
X-PERF
X-Web-Node
X-ApacheServer
X-B3-SpanId
X-Webkit-Csp
X-Trace-Id
X-Ua-Device
X-WA-Info
X-MP-GENERATED-AT
X-FW-Version
X-ATG-Version
X-Cache-Type
X-Content-Age
X-Aws-Lambda-Call-Status
X-Dc
X-Time-Microsecs
X-ServerID
X-CSRF-Token
X-Tumblr-Pixel-3
X-TT-LOGID
X-Cached-By
X-Datadome
X-Soup
X-Cache-Enabled
X-Akamai-Transformed
Backend
X-Parallel-Accel
X-Mode
X-Detected-As
X-Edge-Location
X-Azure-Ref-OriginShield
X-Info
X-Bc-Bl
X-Varnish-Cache-Hits
Count-Hit
X-Microcachable
X-CS
X-Varnish-Beresp-Status
OT-Force-Account-Verify
X-Cache-Host
X-Generation-Time
X-Varnish-Ttl
Web-Mar-Node
X-Cluster-Node
GEO-INFO
X-Cache-NGX
X-Varnish-Hits
X-APP-VERSION
Cross-Origin-Opener-Policy
X-Debug-Cache
X-CACHE-KEY
X-SRV
X-Platform
X-Amzn-RequestId
X-Proxied
X-Routing-Service
X-Amz-Apigw-Id
DataCenter
X-Zipkin-Id
X-Amzn-Remapped-Content-Length
X-Unique-ID
X-Servername
Who
X-Storage
X-Extlb
X-HP-Trace-Id
X-Varnish-Beresp-Ttl
SID
X-Origin-CC
X-Locale
X-B3-Traceid
Server-Info
X-Origin-TTL
DCR-Decision-By
Fastcgi-X-Cache-Version
Host-ID
X-Level-Front-Cache
Fastly-Backend-Name
Content-Disposition
X-Location
Expiry
DCR-Processing-Time-Ms
CDN-Cache
X-NAPM-TraceId
A
X-Via-JSL
X-PAYTM-SRV-ID
X-EC-Lua
X-PBS-Appsvrname
BehaviorPad-Version
Cache-Host
CDN-RequestCountryCode
CDN-RequestId
CDN-EdgeStorageId
CDN-CachedAt
M-TraceId
CDN-Uid
Surrogated-Key
X-Cache-Bucket
X-Cache-NE
X-CF-Lambda-Fn
X-Bip
X-BCube-Filmed-By
X-From
X-ARC
X-B-Cookie
X-CF-Lambda-Version
X-Cms-Context
X-Developer
X-Epic-Correlation-Id
X-External-Request-Id
X-Destination
X-D
X-Connection-Hash
X-Core-Value
X-Application
X-Aicache-OS
State
X-Magnolia-Registration
T-Server
Req-Svc-Chain
Rendered-Blocks
Meta-Geo-Continent
Mobile-Detection-Method
Odigeo-Trace-Id
X-Geo-Header
X-Generated-On
X-A-Dgt
X-A-Wwc
X-Aed
X-A-Dcw
X-A-Dam
X-A
X-A-Ccd
MD5-Digest
CDN-PullZone
X-Ratelimit-Reset
X-S
X-Request-URI
X-Vdms-Path
X-Service
X-ScT
X-Rojux
X-Vdms-Version
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
X-VG-WebServer
X-VG-WebCache
X-Rewrite-Enabled
X-Session-Fingerprint
X-S-Cookie
X-Air-Source
X-Air-Trace-Id
X-Air-Hostname
X-SRCache-Key
X-Thanos
X-Processor
Upgrade-Insecure-Requests
X-DataDome
X-VG-TLSProxy
X-NWS-UUID-VERIFY
Kp-EeAlive
X-Sucuri-ID
Location
Gh-Request-Id
X-JWT-State
Fastly-SIE
Esi-Enabled
X-TrackingId
Cmstype
Fastcgi-Cache-TTL
X-Request-UUID
Cmsid
Fastly-Drupal-HTML
Fastly-SWR
Memcached
X-Branch-Name
X-GoCache-CacheStatus
Server-Host
UCS
X-Scheme
X-Sigma-Backend
X-Served-From
X-Gamma-Serve
X-Has-Esi
X-Hash
Pagetype
Origin
X-Sigma
Path
X-Var-Ttl
X-AIR-PT
X-Clientip
X-Is-Gdpr
X-Rocket-Build-Number
X-Rebelmouse-Surrogate-Control
AKAMAI
X-Platform-Server
Apple-News-Services-Handled
X-Origin
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Apple-News-Services-Host
Source
CacheControlHeader
CDCHOST
X-Rebelmouse-Cache-Control
X-Proxy-Upstream
X-NU-AKA-ACS-Version
X-Cache-Grace
X-Site-Version
User-Cache-Control
X-Ua
S-Rt
X-Tb
X-Origin-Expires
X-Owner
X-HN
PB-PID
X-Cache-Tags
PB-RID
PFcat
Pics-Label
Platform
X-Variation
X-Cache-Info
X-Generated-By
X-Backend-State
Thinkindot-Control
X-VC-Cache
X-VarnishDD-TTL
X-Envoy-Decorator-Operation
X-Accel-Expires-Debug
X-Varnish-Url
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-Amz-Meta-S3cmd-Attrs
NGX
X-Thinkindot-L3
X-Cache-Debug
X-SVT-ORM-RULES
TDXMobile
X-DPWN-IS-SECURE
X-Forwarded-Site
NM-Fastcgi-Cache
X-Loc
Arc-Country
Arc-Version
X-LI-UUID
X-Li-Pop
X-Req
X-SVT-ORM-VERSION
X-Micro-Cache
C-Via
Ec-Rule-Version
DSUID
X-Men
X-VHOST
X-Date
X-WADP-Cache
X-Li-Fabric
X-Fastly-Backend
X-Fastly-Cache
Is-Eu
X-Policy
X-Cluster
X-Clara-WADP
X-Request-Host
X-Developers
X-Device-Os
Cf-Device-Type
X-Fmm-Version
L
X-Minions-Version
Adler-Geo
Url
X-Forwarded-Host
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Gen-Mode
X-SIPLIST1
X-Ratelimit-Limit
X-Slack-Backend
X-Csrf-Jwt
X-Fetched-On
X-Varnish-CookieHashed-On
X-CGP
Cross-Origin-Window-Policy
X-FC-Vary-Parameters
X-Cache-Id
Webserver
X-Skip-Cache
X-Block-Status
X-DefElseHash
X-Generated-In
X-DefHash
X-Gzip
X-Nginx-Cache-Key
X-Eu-Site
Mail-Subject
X-Hnp-Log
X-Old-Content-Length
X-Tenant
Release
X-Esi-Check
X-Irp-Debug
L5d-Success-Class
Cache-Key
NtCoent-Length
X-VServer
X-Mvc-Supplant-Cachable
Ha-Gx-Prefs
IsBot
HA-Ipaddr
X-PF-Uncompressing
Server-Ext
Wxu-Next-Commit
We-Hiring
X-Orig-Expires
Wxu-Next-Hostname
Wxu-Next-Region
X-Qloud-Router
X-Forwarded-Path
Vix-Hermes-Req-Id
X-GeoIP
Content-Secure-Policy
X-Goog-Meta-Goog-Reserved-File-Mtime
Sever-Int
Svr
X-Shop-Environment
Server-Hostname
X-GeoIP-City
True-Client-Country-4JS
X-TX-ID
X-RateLimit-Limit-Second
X-Wikidot-Backend
X-HS-Content-Campaign-Id
X-Via-NSCOPI
X-Viewer-Country
X-RateLimit-Remaining-Second
X-Wikidot-Static-Cache
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-User
V-Age
X-Zone
CPC-Cache
VNS-Age
VNS-Cache
My-App
CPC-Age
Locid
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Pass-Why
X-Mvc-Supplant-OutputCached
Cache-Hits
X-Vc
X-Unique-Id
Powered-By-ChinaCache
X-Ftr-Request-Id
X-Via-Popv
X-Srv
X-Via-Poph
X-Via-Popn
X-Ratelimit-Remaining
X-Internal-Host
X-Conf
Geo-Info
X-PJAX-URL
MIME-Version
X-Refresh
X-GEO
X-BBC-Edge-Cache-Status
X-Cache-Ttl
XServer
X-Worker
X-Ckpd-Fst-Backend
X-OVcl-Cache
X-TraceId
X-OVcl
X-NC
X-LB-ID
X-ID
Time
X-Auto-Login
Cf-Bgj
Memory
X-Servedbyhost
WebServer
X-Backend-TTL
Server-ID
X-V-Cache
Magicmarker
X-LSADC-Cache
DB-Nickname
X-NCache
HostName
X-DC
X-TIME
X-Geo
X-Render-Time
X-Rocket-Nginx-Serving-Static
GeoIp-Country-Code
Geoip-Latitude
X-NewRelic-App-Data
X-ZONE
X-Traceid
X-Qnm-Cache
X-Dynatrace
X-M-Log
X-M-Reqid
X-Cache-Remote
X-Dispatcher-Server
X-Method
X-Newrelic-Synthetics
Tcn
X-Platform-Processor
X-Platform-Router
X-SD-PageType
Hostname
X-Wa
X-Platform-Cluster
X-Tx-Id
X-Datadog-Sampling-Priority
Resin-Trace
X-App
Ssr
X-Tb-Optimization-Total-Bytes-Saved
X-IP
X-CLOUD-TRACE-CONTEXT
X-Datadog-Trace-Id
X-Datadog-Parent-Id
Environment
X-BBC-Origin-Response-Status
X-Cache-Config
X-Nyt-Route
X-Origin-Time
X-Gdpr
X-API-Version
X-Li-Proto
X-Correlation-ID
X-Server-IP
Cluster
X-Edge-Pop
LB
X-Via-Ucdn
X-VCL-Version
X-NodeID
X-Origin-Response-Time
X-Nc
X-DynaTrace-JS-Agent
Ohc-File-Size
Candidate-Md5Url
X-Pod-Name
X-Trv-Group
X-MSEdge-Flight
X-Vcl-Version
X-HITS
X-Webkit-CSP-Report-Only
X-CACHE-AGE
X-MSEdge-Features
X-Cache-Var
X-Cache-Var-Map
X-Varnish-Beresp-TTL
X-LI-Proto
X-ElasticPress-Query
X-APP
X-Via-CDN
X-Node-Id
Cf-Ipcountry
Env
N-Cache
Web-Mar-Region
X-ServerName
X-Akamai-Pragma-Client-IP
Datacenter
X-WA
X-Reqid
X-ND-Cache
X-Wix-Viewer-Type
X-HostName
X-Fastly-Request-Id
CF-Cached-On
X-HS-Status
X-Cs
Sid
Server-Id
GeoIP-Country-Code
Proxy-Connection
GeoIP-Latitude
CDN
X-FTR-Request-ID
Rt-Fastcgi-Cache
Viewtype
X-Cdn-Forward
VivaBuild
Onion-Location
X-Varnish-Cacheable
Servername
Cdn
WWW-Authenticate
Machine
X-Dynatrace-Js-Agent
X-EIG-Tracking-Id
X-AB
X-MG-S
X-Ua-Browser
X-Content
WZWS-RAY
X-ServedByHost
X-NGINX-Cache
X-Fastly-Backend-Reqs
X-Lb-Id
On-Server
X-URL
X-Check-Cacheable
FSS-Cache
Ohc-Cache-HIT
X-Esi
X-CSRF-TOKEN
X-Xrds-Location
X-Fpc
Cteonnt-Length
X-Pjax-Url
Mime-Version
X-TIM-N
X-Via-PopV
X-Cache-Backend
X-Via-PopH
X-Via-PopN
Redirect-Candidate
X-Swa-Ws
X-Tid
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-VC
Server-Ttl
X-Request-Start
Lb
X-Oss-Hash-Crc64ecma
X-FTR-DC
X-SN
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Object-Type
URI
X-FTR-Realm
X-FTR-Backend
X-FTR-Backend-Server
X-Up
Shield-Pop
Xc-Version
X-Country-Code-Real
X-FTR-Balancer
X-ECache
X-FTR-Cache-Status
X-Oss-Storage-Class
CountryCode
X-Varnish-Authentication
Vha6-Origin
X-Pad
X-Contensis-Viewer-Groups
X-Swift-Error
X-Cache-Date
X-Cache-ASPX
CACHE
Pramga
X-Amz-Meta-Cb-Modifiedtime
Is-Us
Tracecode
X-FORWARDED-FOR
X-Air-Pt
X-CCM
X-Vcache
X-Sn-Servicetimems
Xet-Cookie
X-RSL
X-StackifyID
X-Acquia-Purge-Tags
X-Cdn-Origin
X-RPM
X-DB
X-Acquia-Site
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-DI
X-DW
X-DSS
X-Action
X-RPS
WP-Super-Cache
Warning
X-FTR-Expires
X-LiteSpeed-Cache-Control
X-Snapshot-Date
X-CUA
X-Pf-Uncompressing
ServerName
X-SB
X-Webstats-RespID
X-Dw-Trace-Id
Ohc-Response-Time
X-ElasticPress-Search
X-Yottaa-OS
X-Fastly-Cache-Hits
Srv
X-Mg-Request-Id
X-CCDN-CacheTTL
Content-Script-Type
X-FPC
X-RAMCache
X-Core-Mission
Content-Style-Type
CloudFront-Viewer-Country
X-Hcs-Proxy-Type
X-Apw-Hits
X-Region-Sid
X-MiniProfiler-Ids
X-CCDN-Origin-Time
Instruction
X-Tt-Logid
SR-User-Adfree
X-TH-Server
X-Apw-Access-Object
X-Apw-Access-Action
X-C
X-Cache-Status-Check
X-Apw-Access-Token