Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
Link
ETag
Pragma
Expect-CT
X-Powered-By
X-XSS-Protection
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
Alt-Svc
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Timer
X-Download-Options
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Request-ID
P3p
X-DNS-Prefetch-Control
X-Content-Security-Policy
X-Iinfo
Status
Feature-Policy
Content-Encoding
X-AspNetMvc-Version
X-CDN
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
X-Ua-Compatible
Upgrade
X-Dns-Prefetch-Control
Access-Control-Max-Age
X-Drupal-Dynamic-Cache
X-Via
X-Ws-Request-Id
Keep-Alive
Server-Timing
Request-Context
X-Robots-Tag
X-AH-Environment
X-Hacker
X-Server
X-Age
X-Turbo-Charged-By
X-Proxy-Cache
X-Server-Powered-By
X-Backend
X-Amz-Request-Id
X-Cache-Group
X-Amz-Id-2
EagleId
Host-Header
X-Nginx-Cache-Status
Report-To
X-LiteSpeed-Cache
X-Rq
X-Varnish-Cache
Grace
X-UA-Device
X-Page-Speed
X-Pingback
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
EagleEye-TraceId
X-Device
X-Vhost
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Amz-Version-Id
NEL
X-Dispatcher
X-OneAgent-JS-Injection
Cf-Railgun
X-Host
X-WebKit-CSP
X-Cache-Spec
X-Server-Id
X-CST
X-Node
X-EdgeConnect-MidMile-RTT
X-Backend-Server
X-EdgeConnect-Origin-MEX-Latency
Request-Id
Allow
Surrogate-Control
X-Readtime
Accept-CH
X-Akam-SW-Version
X-Response-Time
Accept-Ch-Lifetime
Xkey
X-Language
X-HW
X-Template
X-Application-Context
X-Country
Content-Location
X-Ac
X-Cache-Lookup
X-Cloud-Trace-Context
Rating
MS-Author-Via
X-Ruxit-JS-Agent
X-Url
X-Webkit-CSP
Edge-Control
X-Clacks-Overhead
X-PC
X-Vname
X-TtlSet
X-Mod-Pagespeed
X-Varnish-TTL
X-Trace
Fastly-Restarts
X-Content-Type
X-B3-TraceId
X-Rack-Cache
X-Buckets
X-MS-InvokeApp
X-Origin-Cache
X-ESI
X-GitHub-Request-Id
Accept-Ch
X-Country-Code
X-Goog-Hash
X-Cnection
Verso
X-VARITI-CCR
X-D2id
X-ORACLE-DMS-ECID
Arr-Disable-Session-Affinity
X-Exp-Variant
X-GoogleNews-Bot
X-Use-Magma
X-Exp-Id
X-Kinja-Server
X-Kinja-Revision
X-Kinja
X-Kinja-Build
X-Cdn-Fetch
X-FastCGI-Cache
Cache-Tag
X-Px
X-Vcap-Request-Id
Service-Worker-Allowed
X-Cached
X-Abt-Application-Version
Accept-CH-Lifetime
X-Server-Name
X-Client-IP
X-Server-ID
X-Amz-Rid
X-Navigation-Version
X-Cache-TTL
Public-Key-Pins
X-SRCache-Fetch-Status
X-SRCache-Store-Status
RTSS
X-Powered-By-Plesk
X-MSEdge-Ref
Access-Control-Request-Method
X-Element-Page-Cache
X-Dw-Request-Base-Id
X-Powered-CMS
X-NF-Request-ID
X-Version
X-TTL
X-Upstream
X-Fastly-Request-ID
Response
X-Middleton-Display
X-Middleton-Response
X-Sol
Pagespeed
Display
S
X-Edge-Location-Klb
X-Kinsta-Cache
X-Edge
X-LLID
X-Instrumentation
X-Server-Lifecycle-Phase
X-Kraken-Routeconfig-Destination
X-Kraken-Loop-Name
X-Cache-Key
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-Ttl
X-Accel-Expires
X-Shield-Request-Id
X-Pinterest-Rid
X-HP-Webp
X-Jurisdiction
Pinterest-Version
Pinterest-Generated-By
X-ORACLE-DMS-RID
X-ECACHE
X-Correlation-Id
X-DynaTrace
X-T
Realpath
X-PressLabs-Stats
SPRequestGuid
X-Litespeed-Cache
X-SharePointHealthScore
X-MCACHE
X-Mid
Edge-Cache-Tag
X-Content-Security-Policy-Report-Only
X-Ruxit-Js-Agent
SPRequestDuration
SPIisLatency
Fastcgi-Cache
X-Amz-Server-Side-Encryption
Nginx-Cache
X-Mg-S
X-XRDS-Location
X-Content-Digest
X-Forwarded-Proto
TP-Cache
X-Recruiting
TP-L2-Cache
X-Id
X-Oneagent-Js-Injection
X-Request-Processing-Time
X-Request-Received
Front-End-Https
TCN
Charset
Server-Node
Alternate-Protocol
X-Logged-In
Filters
X-Geo-Country
Content-MD5
X-CACHE-GROUP
X-Forwarded-For
Fusion-Source
Fusion-Template-Id
X-Protected-By
Fusion-Content-Source
Fusion-Deployment-Id
Fusion-Content-Id
Fusion-Component-Id
X-Ezoic-Cdn
X-ASPNET-VERSION
Cache-Tags
X-Hostname
X-NWS-LOG-UUID
X-Ab
X-Amzn-Trace-Id
X-Origin-Upstream-Status
X-Debug-Info
X-Grace
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Storage-Class
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Www-Served-By
X-Goog-Generation
X-LB-Cache
Cleartype
X-F-Cache
X-Amz-Replication-Status
X-HS-Content-Id
X-Rid
X-AppVersion
X-Az
X-Activity-Id
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Combine-CSS
X-Origin-Server
Host
X-Daa-Tunnel
X-Contextid
X-Git-Hash
X-Page-Id
X-Browser-Type
Section-Io-Cache
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-VCache
Server-Name
X-Content-Options
X-RateLimit-Remaining
MicrosoftSharePointTeamServices
X-Upgrade-Enabled
X-Ser
X-Aspnetmvc-Version
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Frontend
X-Cache-Age
Access-Control-Allow-Method
ServerID
Accept-Charset
X-Source
X-Hits
X-Mobile-URL
X-Release
X-DIS-Request-ID
X-Providence-Cookie
X-Request-Guid
X-Is-Crawler
X-Route-Name
X-Varnish-Age
X-Flags
X-Aspnet-Duration-Ms
X-Signature
X-B3-Sampled
X-WebKit-CSP-Report-Only
X-Cache-Action
X-B-Cache
Healthy
Viewport
X-FB-Debug
X-Varnish-Grace
X-Varnish-Backend
Paypal-Debug-Id
Payment
X-Yandex-Sdch-Disable
X-Whom
X-AOL-HN
Fastcgi-Useragent
X-TT
DynaTrace
X-App-Environment
Node
X-Fastcgi-Cache
X-Respond-Thread
X-Load-Cache
X-Mobile
X-Tt-Trace-Host
X-Tt-Trace-Tag
DC
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
Filterid
Version
X-Seen-By
X-Distributor
X-User-Agent
X-XRDS-LOCATION
SRV
X-Cache-Control
X-HTML-Minification-Powered-By
Frame-Options
X-N
Retry-After
X-Type
X-HP-Trace-Id
Refresh
X-Ua-Device
X-Jobs
X-FW-Hash
X-FW-Serve
X-FW-Type
X-FW-Dynamic
MS-CV
X-Node-Name
X-FW-Static
X-FW-Server
X-Response-Served-From
X-Original-Request-Id
Amp-Access-Control-Allow-Source-Origin
X-Azure-Ref
X-UUID
X-Cache-Expired-At
X-Adobe-Content
X-Adobe-Loc
X-Page-View
X-Debug-IsConnected
X-Instance
X-Debug-IsPreview
X-Proxy-Cache-Status
X-Varnish-Server
X-Real-IP
X-B
X-Region
X-ProcessESI
NGB
X-Cacheable-TTL
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Tumblr-Pixel
X-Vgn-Hpd-Reason
X-Aws-Lambda-Call-Status
X-IPLB-Instance
X-Cluster-Name
X-Tumblr-User
X-RemovedCookies
X-Tumblr-Pixel-1
X-G
X-Tumblr-Pixel-0
X-NGENIX-Cache
Access-Control-Request-Headers
X-RTag
Ms-Operation-Id
X-CDN-Forward
X-Framework
X-Content-Powered-By
X-Cache-Time
X-Proxy
X-Parallel-Accel
X-Cache-Hit
X-Device-Type
SD-X-WS
X-Zen-Fury
Referer-Policy
X-Cache-Rule
Liferay-Portal
X-IPS-LoggedIn
Uber-Trace-Id
X-Rendered-As
X-Drupal-Cache-Tags
X-Is-Bot
X-Ms-Request-Id
Cache-Status
X-Ms-Version
X-Wix-Request-Id
X-Oracle-Dms-Rid
X-Time
X-EdgeConnect-Cache-Status
Section-Io-Id
Countrycode
X-Mg-Request-UUID
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
X-App-Server
X-Environment-Context
X-Revision
X-L-Path
S-Cnection
X-B3-Traceid
X-Debug
X-Yottaa-Optimizations
X-Yottaa-Metrics
Country
X-TA-CDN-Provider
X-APP-VERSION
CF-IPCountry
X-Accel-Buffering
X-Cache-Operation
Count-Hit
X-RateLimit-Limit
X-Drupal-Cache-Contexts
X-FW-Version
X-Nginx-Cache
Akamai-GRN
X-Request-Handler-Origin-Region
Meta-Geo
X-GG-Cache-Date
X-RN-RSRV
X-SaId
X-Microsite
X-JoinUs
X-ES-SERVER
X-UPSTREAM-Address
X-Loop
From-Origin
Cache
X-Say-Cacheable
X-Endurance-Cache-Level
X-SayCDN-TTL
X-Say-TTL
X-LAGOON
X-TNCMS
X-Cache-TTL-Remaining
X-Cache-Type
X-Adobe-Source
X-R9-Blue-Green-Version
X-Request-Time
X-Sql-Duration-Ms
X-S-Maxage
GEO-INFO
X-OCL
Surrogate-Key
X-NYM-Debug-Backend
X-Varnish-Beresp-Grace
X-Human
Azure-SlotName
Azure-RegionName
Azure-Version
Country-Code
X-PCL
Azure-InstanceId
Azure-SiteName
Fastly-SSL
X-Sql-Count
Protected
Cache-Tv-Group
X-No-Session
X-Storefront-Renderer-Rendered
X-Alternate-Cache-Key
X-Status
Cache-Name
X-Sorting-Hat-ShopId
X-Origin-Date
Decoy-Debug-Status
Decoy-Debug-TTL
X-LJ-Flow-ID
X-Sorting-Hat-PodId
Apigw-Requestid
X-Pubstack
X-ShardId
X-VWS-Id
X-Labrador-Cache-Channel
Decoy-Debug-Key
X-Handled-By
X-Proto
X-Via-Fastly
X-Varnish-Hostname
X-Varnishpool
X-ShopId
X-PHP-Host
X-Shopify-Stage
X-Hosted-By
X-Be
X-AWS-Id
X-RCS-CacheZone
Eomportal-Instance
X-Web-Node
X-UA-Device-Type
X-Cache-Server
X-Tumblr-Pixel-2
Property-Id
X-Server-W
X-Access
X-Proxy-Build
X-ApacheServer
X-Akamai-Edgescape
X-ProxyCache-Status
X-BYPASS-REASON
Selected-Fe
X-PERF
X-Cluster-Node
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-GeoIP-Country
X-Format
Webcakes-App-Version
TWC-Privacy
X-Redis-Cache
TWC-Device-Class
X-Timing-Wait
ServedBy
X-ProxyCache-Key
TWC-Connection-Speed
X-Xfnlog-Site
X-Origin-Hint
X-Section
Webcakes-App-Name
Webcakes-Region
X-Backend-Host
AR-ATIME
X-Uri
AR-CACHE
AR-PoweredBy
X-PHP-Backend
Ar-Sid
AR-Request-ID
X-Time-Microsecs
Nel
Mn-Server-Ip
Cross-Origin-Opener-Policy
X-FB-TRIP-ID
X-Hyper-Cache
X-Backend-Name
OT-Force-Account-Verify
X-B3-SpanId
X-App-Version
X-Hl-Ver
X-Servername
X-ServerID
X-Tumblr-Pixel-3
X-Detected-As
X-ATG-Version
Cross-Origin-Window-Policy
X-Azure-Ref-OriginShield
Web-Mar-Node
X-FireWall-Port
X-Varnish-Cache-Hits
X-Generation-Time
X-Ua
X-Cache-Host
X-Cache-PHP
Source
X-Content-Age
X-Varnish-Hits
X-Ratelimit-Limit
Content-Secure-Policy
Ec-Rule-Version
X-Datadome
Backend
X-Via-JSL
X-Content
X-TEC-API-VERSION
X-Ua-Browser
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Akamai-Transformed
X-Trace-Id
X-Air-Source
X-Air-Trace-Id
X-Forwarded-Host
X-MP-GENERATED-AT
X-Air-Hostname
Xserver
Upgrade-Insecure-Requests
X-Amzn-RequestId
X-Amz-Apigw-Id
X-WA-Info
X-Cdn
X-Microcachable
X-Cache-Grace
X-TT-LOGID
X-Mode
X-CSRF-Token
X-CS
X-Soup
X-NWS-UUID-VERIFY
X-Amzn-Remapped-Content-Length
X-Dc
X-Locale
X-SRV
X-Cache-Enabled
X-Ratelimit-Remaining
Url
X-Bc-Bl
X-Origin-CC
X-Origin-TTL
X-Unique-Id
X-Site-Version
X-Tenant
X-Info
X-Rule
Content-Disposition
X-Edge-Location
X-GEO
X-Extlb
X-Proxied
X-Zipkin-Id
X-Routing-Service
X-Varnish-Beresp-Ttl
X-Magnolia-Registration
X-Tb
S-Rt
X-Varnish-Beresp-Status
X-Epic-Correlation-Id
DCR-Decision-By
CDN-Uid
CDN-RequestId
X-D
DCR-Processing-Time-Ms
X-Developer
Fastly-SIE
X-Debug-Cache
Fastly-SWR
Expiry
X-Destination
Fastcgi-X-Cache-Version
CDN-RequestCountryCode
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Apple-News-Services-Host
Apple-News-Services-Handled
X-SRCache-Key
A
X-Forwarded-Path
BehaviorPad-Version
CDN-EdgeStorageId
CDN-PullZone
CDN-CachedAt
CDN-Cache
X-External-Request-Id
CDCHOST
X-Connection-Hash
X-CF-Lambda-Version
X-Aed
X-A-Wwc
X-Aicache-OS
X-AIR-PT
Rendered-Blocks
Req-Svc-Chain
X-A-Dgt
X-A-Dcw
T-Server
X-A
X-A-Ccd
Surrogated-Key
X-A-Dam
X-Application
X-ARC
MD5-Digest
X-Cache-Bucket
X-Cache-NE
X-CF-Lambda-Fn
Host-ID
X-Vtex-Remote-Cache
Meta-Geo-Continent
Mobile-Detection-Method
X-BBC-Edge-Cache-Status
X-B-Cookie
Path
X-BCube-Filmed-By
Odigeo-Trace-Id
X-Conf
X-Ftr-Request-Id
X-NU-AKA-ACS-Version
X-Orig-Expires
X-S
X-Vtex-Processado-Em
X-M-Log
X-S-Cookie
X-M-Reqid
X-Ratelimit-Reset
X-Vdms-Version
X-Rojux
X-Processor
X-Rebelmouse-Cache-Control
X-VG-WebServer
User-Cache-Control
X-Rewrite-Enabled
X-PAYTM-SRV-ID
X-PBS-Appsvrname
X-Platform-Server
X-ScT
X-NAPM-TraceId
X-Session-Fingerprint
X-Rebelmouse-Surrogate-Control
X-VG-WebCache
X-Request-URI
X-Shop-Environment
X-Storage
X-NCache
X-Qnm-Cache
X-DataDome
X-Tx-Id
X-EC-Lua
X-Envoy-Decorator-Operation
X-DPWN-IS-SECURE
X-Is-Gdpr
X-Date
X-LI-UUID
X-TrackingId
X-Backend-State
X-Origin-Expires
X-Core-Value
X-Cache-Debug
Origin
Fastly-Backend-Name
UCS
X-Li-Fabric
NGX
X-SVT-ORM-VERSION
Is-Eu
X-JWT-State
X-Loc
X-Request-UUID
X-Li-Pop
X-Has-Esi
X-Scheme
X-SVT-ORM-RULES
Adler-Geo
X-Worker
X-Accel-Expires-Debug
X-Variation
State
X-Service
L
X-Men
X-From
Cache-Key
Cache-Host
Platform
Pics-Label
X-VServer
SID
X-Cache-Info
X-Fastly-Cache
X-VG-TLSProxy
AMP-Access-Control-Allow-Source-Origin
X-Cache-NGX
X-Cached-By
X-Micro-Cache
X-Auto-Login
X-Sigma-Backend
VNS-Cache
VNS-Age
Vix-Hermes-Req-Id
X-Sigma
X-Served-From
X-Rocket-Build-Number
X-Block-Status
X-Bip
X-VC-Cache
X-Branch-Name
X-Via-NSCOPI
X-Gen-Mode
X-Location
X-Generated-By
X-Generated-On
X-SIPLIST1
X-Slack-Backend
X-Thinkindot-L3
X-Skip-Cache
X-Gamma-Serve
X-Thanos
X-Varnish-CookieHashed-On
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-Level-Front-Cache
X-VarnishDD-TTL
X-Hnp-Log
X-Geo-Header
X-Gzip
X-HN
X-Forwarded-Site
X-Varnish-Remaining-TTL
X-Proxy-Upstream
X-DefElseHash
X-DefHash
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Clientip
X-Cluster
X-Cms-Context
X-Varnish-CookieINHashed-On
X-Developers
True-Client-Country-4JS
X-Nginx-Cache-Key
X-Fastly-Backend
X-Old-Content-Length
X-Origin
X-Device-Os
X-Viewer-Country
X-Esi-Check
X-Cache-Tags
X-Cache-Id
Location
IsBot
Fastly-Drupal-HTML
Locid
M-TraceId
PFcat
PB-RID
PB-PID
Fastcgi-Cache-TTL
Esi-Enabled
Arc-Country
AKAMAI
X-LSADC-Cache
Arc-Version
C-Via
CPC-Cache
DataCenter
Cf-Device-Type
Server-Ext
CPC-Age
TDXMobile
Svr
Thinkindot-CacheControl
Server-Host
Thinkindot-Control
Sever-Int
Thinkindot-CacheControl-Type
Server-Hostname
X-Amz-Meta-S3cmd-Attrs
X-Platform-Processor
Cmsid
Release
X-Eu-Site
X-Platform-Cluster
Cmstype
X-Rocket-Nginx-Serving-Static
Wxu-Next-Hostname
DSUID
Wxu-Next-Commit
X-Platform-Router
We-Hiring
CacheControlHeader
X-Vdms-Path
V-Age
X-Render-Time
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Generated-In
X-GeoIP-City
X-Hash
X-HS-Content-Campaign-Id
X-GeoIP
X-FC-Vary-Parameters
X-Fetched-On
X-Irp-Debug
NtCoent-Length
Wxu-Next-Region
X-Mvc-Supplant-Cachable
Memcached
Mail-Subject
X-Platform
X-Policy
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Owner
Pagetype
NM-Fastcgi-Cache
X-Planisys-CDN-Cache
X-Var-Ttl
X-CGP
Gh-Request-Id
X-Csrf-Jwt
XServer
Server-Info
Ha-Gx-Prefs
HA-Ipaddr
X-Req
X-Ckpd-Fst-Backend
L5d-Success-Class
X-Request-Host
X-Sucuri-ID
Webserver
X-GoCache-CacheStatus
X-Qloud-Router
X-V-Cache
X-Fmm-Version
X-Clara-WADP
X-SD-PageType
X-WADP-Cache
X-Srv
X-Cache-Var
X-Unique-ID
X-Cache-Var-Map
X-Cache-Remote
Cache-Hits
X-DC
X-Mvc-Supplant-OutputCached
X-Servedbyhost
Environment
X-Datadog-Sampling-Priority
Kp-EeAlive
X-Datadog-Trace-Id
X-Origin-Time
MIME-Version
X-PJAX-URL
X-Datadog-Parent-Id
X-API-Version
X-NodeID
X-Gdpr
X-Nyt-Route
X-NC
X-Via-Popn
X-Via-Popv
X-Via-Ucdn
X-Via-Poph
X-Vc
X-Server-IP
X-Cache-Config
X-Pod-Name
X-PF-Uncompressing
X-Wa
Candidate-Md5Url
X-User
X-BBC-Origin-Response-Status
X-Varnish-Ttl
WebServer
Memory
X-Zone
Time
X-App
X-ZONE
Cluster
Who
X-Internal-Host
X-Webkit-Csp
X-Minions-Version
X-TIME
Server-ID
X-VCL-Version
X-Varnish-Url
X-Traceid
X-Refresh
Onion-Location
X-CACHE-KEY
HostName
Web-Mar-Region
X-Webkit-CSP-Report-Only
GeoIp-Country-Code
X-Newrelic-Synthetics
X-Pass-Why
N-Cache
Resin-Trace
X-LB-ID
X-Tt-Logid
Geoip-Latitude
X-ID
Powered-By-ChinaCache
X-NewRelic-App-Data
X-Edge-Pop
My-App
X-Esi
X-Cache-Ttl
X-CLOUD-TRACE-CONTEXT
X-ElasticPress-Query
X-Tb-Optimization-Total-Bytes-Saved
Servername
X-TraceId
CDN
Geo-Info
X-LI-Proto
X-Akamai-Pragma-Client-IP
X-Varnish-Cacheable
X-VHOST
Datacenter
WWW-Authenticate
X-Fastly-Request-Id
Tcn
Ohc-File-Size
X-TX-ID
X-EIG-Tracking-Id
X-OVcl
X-Origin-Response-Time
X-OVcl-Cache
X-Dynatrace
X-HITS
X-CACHE-AGE
X-Varnish-Beresp-TTL
X-Fpc
LB
X-TIM-N
Redirect-Candidate
X-Li-Proto
X-Tid
Cf-Bgj
X-Geo
X-Backend-TTL
Magicmarker
Hostname
X-NODE
Proxy-Connection
Tracecode
X-Correlation-ID
X-AB
X-Wix-Viewer-Type
X-Request-Start
X-Method
Pramga
X-Cache-Date
X-NGINX-Cache
X-Up
Cdn
X-HostName
X-Dynatrace-Js-Agent
X-Amz-Meta-Cb-Modifiedtime
X-Sn-Servicetimems
X-Dispatcher-Server
X-Cdn-Origin
X-Cs
CloudFront-Viewer-Country
Cf-Ipcountry
X-CSRF-TOKEN
X-Provided-By
W
X-MSEdge-Flight
X-MSEdge-Features
Sid
Server-Id
X-Vcl-Version
X-Fastly-Backend-Reqs
Is-Us
GeoIP-Country-Code
X-UnsetCookies
CF-Cached-On
X-IP
X-HS-Status
X-Cache-Expires
X-APP
X-Core-Mission
X-Lb-Id
GeoIP-Latitude
Ssr
X-COUNTRY
X-MG-S
DB-Nickname
Lb
X-WA
WP-Super-Cache
Cteonnt-Length
X-ServerName
X-Reqid
X-Webkit-Csp-Report-Only
X-FORWARDED-FOR
X-Hcs-Proxy-Type
X-Region-Sid
X-Cache-Status-Check
X-Via-PopN
X-Node-Id
X-Check-Cacheable
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Sucuri-Cache
X-DynaTrace-JS-Agent
X-Via-PopV
X-Via-PopH
URI
CountryCode
Ohc-Cache-HIT
Xc-Version
X-Moov-T
X-Moov-Xdn-Version
X-Trv-Group
X-Nc
X-SERVER-NAME
X-ND-Cache
X-VC
X-Cache-Backend
X-ECache
EpKe-Alive
User-Agent
X-Pjax-Url
Shield-Pop
X-ServedByHost
Mime-Version
X-SN
WZWS-RAY
Env
X-Pad
X-Ig-Push-State
X-Via-CDN
X-Acquia-Application-Trace
X-Varnish-Authentication
FSS-Cache
X-Acquia-Application-UUID
X-Acquia-Site
X-Pf-Uncompressing
X-Edge-POP
X-RAMCache
X-Acquia-Purge-Tags
X-LiteSpeed-Cache-Control
X-Cache-ASPX
X-CUA
X-Contensis-Viewer-Groups
X-Fastly-Cache-Hits
X-TRACE-ID
CACHE
X-Amz-Meta-Opti
X-Nginx-Upstream-Cache-Status
On-Server
X-Oss-Storage-Class
X-Cdn-Request-ID
X-Parent-Response-Time
X-Oss-Object-Type
HIT
X-Dispatch
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
Server-Ttl
X-B3-Spanid
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-DB
Vha6-Origin
Ohc-Response-Time
X-Webstats-RespID
X-SB
X-Dw-Trace-Id
X-Swift-Error
X-DI
X-Action
X-StackifyID
X-DSS
Xet-Cookie
X-RPS
X-RSL
X-RPM
X-DW
X-Cdn-Forward
X-Amzn-Remapped-X-Forwarded-For
X-Snapshot-Date
X-Amzn-Remapped-User-Agent
X-UP
X-Amzn-Remapped-Host
X-Env-Stack-Name
X-FPC
Fastly-Drupal-Html
X-Forwarded-Port
X-Env-Sha256-Sig
X-Ftr-Viewer-Uri
Hit
X-CF-Powered-By
X-Yottaa-OS
Content-Script-Type
Content-Style-Type
Req-ID
ServerName
VivaBuild
Viewtype
X-MiniProfiler-Ids
Rt-Fastcgi-Cache