Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
Link
ETag
X-XSS-Protection
Pragma
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
Alt-Svc
X-UA-Compatible
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Xss-Protection
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-Request-ID
X-Cacheable
Timing-Allow-Origin
X-DNS-Prefetch-Control
P3p
X-Content-Security-Policy
X-Iinfo
Status
Feature-Policy
Content-Encoding
X-AspNetMvc-Version
X-CDN
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
X-Ua-Compatible
Upgrade
X-Dns-Prefetch-Control
Access-Control-Max-Age
X-Drupal-Dynamic-Cache
X-Via
Keep-Alive
X-Ws-Request-Id
Server-Timing
Request-Context
X-Robots-Tag
X-AH-Environment
X-Hacker
X-Server
X-Age
X-Turbo-Charged-By
X-Proxy-Cache
X-Cache-Group
X-Server-Powered-By
X-Backend
X-Amz-Request-Id
X-Amz-Id-2
Host-Header
EagleId
Report-To
X-Nginx-Cache-Status
X-LiteSpeed-Cache
X-Rq
X-Varnish-Cache
Grace
X-UA-Device
X-Page-Speed
X-Pingback
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
EagleEye-TraceId
X-Device
X-Vhost
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Amz-Version-Id
NEL
X-Dispatcher
X-OneAgent-JS-Injection
Cf-Railgun
X-Host
X-WebKit-CSP
X-Cache-Spec
X-Server-Id
X-CST
X-Node
X-Backend-Server
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Allow
Request-Id
Surrogate-Control
X-Readtime
Accept-CH
X-Akam-SW-Version
X-Response-Time
Accept-Ch-Lifetime
Xkey
X-Language
X-HW
X-Template
X-Application-Context
X-Country
Content-Location
X-Cache-Lookup
X-Ac
X-Cloud-Trace-Context
Rating
MS-Author-Via
X-Ruxit-JS-Agent
X-Url
X-Webkit-CSP
X-Clacks-Overhead
Edge-Control
X-TtlSet
X-Vname
X-PC
X-Mod-Pagespeed
X-Trace
Fastly-Restarts
X-Content-Type
X-Varnish-TTL
X-B3-TraceId
X-Buckets
X-Rack-Cache
X-MS-InvokeApp
X-Origin-Cache
X-ESI
X-GitHub-Request-Id
Accept-Ch
X-Country-Code
X-Goog-Hash
X-Cnection
Verso
X-VARITI-CCR
X-D2id
X-ORACLE-DMS-ECID
Arr-Disable-Session-Affinity
X-Kinja-Build
X-GoogleNews-Bot
X-Kinja
X-Kinja-Server
X-Use-Magma
X-Exp-Variant
X-Cdn-Fetch
X-Exp-Id
X-Kinja-Revision
X-FastCGI-Cache
Cache-Tag
X-Px
X-Vcap-Request-Id
Service-Worker-Allowed
X-Cached
X-Abt-Application-Version
Accept-CH-Lifetime
X-Server-Name
X-Client-IP
X-Server-ID
X-Amz-Rid
X-Navigation-Version
X-Cache-TTL
Public-Key-Pins
X-SRCache-Fetch-Status
X-SRCache-Store-Status
RTSS
X-Powered-By-Plesk
X-MSEdge-Ref
Access-Control-Request-Method
X-Dw-Request-Base-Id
X-Element-Page-Cache
X-Powered-CMS
X-NF-Request-ID
X-Version
X-TTL
X-Upstream
X-Fastly-Request-ID
X-Middleton-Response
X-Middleton-Display
Pagespeed
X-Sol
Display
Response
S
X-Kinsta-Cache
X-Edge-Location-Klb
X-Edge
X-LLID
X-Instrumentation
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Kraken-Routeconfig-Destination
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Accel-Expires
X-Ttl
X-Shield-Request-Id
Pinterest-Generated-By
X-Pinterest-Rid
Pinterest-Version
X-HP-Webp
X-Cache-Key
X-Jurisdiction
X-Correlation-Id
X-ECACHE
X-ORACLE-DMS-RID
X-DynaTrace
X-T
Realpath
X-PressLabs-Stats
X-Litespeed-Cache
X-MCACHE
X-Mid
SPRequestGuid
Edge-Cache-Tag
X-SharePointHealthScore
X-Content-Security-Policy-Report-Only
X-Ruxit-Js-Agent
SPRequestDuration
SPIisLatency
Fastcgi-Cache
X-Amz-Server-Side-Encryption
Nginx-Cache
X-Mg-S
X-Content-Digest
X-XRDS-Location
X-Forwarded-Proto
TP-L2-Cache
TP-Cache
X-Recruiting
X-Id
X-Oneagent-Js-Injection
X-Request-Processing-Time
Front-End-Https
X-Request-Received
TCN
Charset
Alternate-Protocol
Server-Node
X-Logged-In
Filters
X-Geo-Country
Content-MD5
X-Forwarded-For
Fusion-Deployment-Id
Fusion-Source
Fusion-Template-Id
X-Protected-By
Fusion-Content-Source
Fusion-Content-Id
Fusion-Component-Id
X-Ezoic-Cdn
X-ASPNET-VERSION
Cache-Tags
X-Hostname
X-NWS-LOG-UUID
X-Ab
X-Amzn-Trace-Id
X-Origin-Upstream-Status
X-Grace
X-Debug-Info
X-Goog-Metageneration
X-Www-Served-By
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Generation
X-F-Cache
X-LB-Cache
Cleartype
X-Amz-Replication-Status
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
X-Origin-Server
X-Activity-Id
X-Rid
X-Az
X-AppVersion
X-HS-Combine-CSS
Host
X-Daa-Tunnel
X-Contextid
X-Git-Hash
X-Page-Id
Section-Io-Cache
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Browser-Type
X-Content-Options
Server-Name
X-VCache
X-Ser
X-Upgrade-Enabled
X-Aspnetmvc-Version
MicrosoftSharePointTeamServices
X-Frontend
X-Cache-Age
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Access-Control-Allow-Method
ServerID
X-RateLimit-Remaining
Accept-Charset
X-Hits
X-Source
X-Mobile-URL
X-DIS-Request-ID
X-Release
X-CACHE-GROUP
X-Request-Guid
X-Providence-Cookie
X-Varnish-Age
X-Is-Crawler
X-Route-Name
X-Aspnet-Duration-Ms
X-Flags
X-B-Cache
X-Cache-Action
X-WebKit-CSP-Report-Only
X-Signature
Viewport
Healthy
Payment
X-Varnish-Grace
X-Varnish-Backend
X-Whom
X-FB-Debug
Paypal-Debug-Id
X-Yandex-Sdch-Disable
X-B3-Sampled
X-AOL-HN
DynaTrace
Fastcgi-Useragent
X-TT
X-Respond-Thread
X-App-Environment
Node
X-Fastcgi-Cache
X-Load-Cache
X-Mobile
X-Tt-Trace-Host
X-Tt-Trace-Tag
DC
Filterid
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
X-Seen-By
Version
X-Distributor
X-User-Agent
X-XRDS-LOCATION
X-Cache-Control
X-HTML-Minification-Powered-By
Frame-Options
Retry-After
X-N
X-Type
X-HP-Trace-Id
SRV
X-Ua-Device
Refresh
X-Jobs
X-FW-Server
X-FW-Static
X-Node-Name
MS-CV
X-FW-Serve
X-FW-Type
X-FW-Hash
X-FW-Dynamic
X-Response-Served-From
X-NGENIX-Cache
X-Original-Request-Id
X-Azure-Ref
X-UUID
X-Cache-Expired-At
X-Adobe-Content
X-Adobe-Loc
X-Page-View
X-Proxy-Cache-Status
NGB
X-Aws-Lambda-Call-Status
X-Instance
X-Real-IP
X-Debug-IsConnected
X-Debug-IsPreview
X-Varnish-Server
X-Vgn-Hpd-Reason
X-ProcessESI
VIX-Pulpo-Node
X-Region
X-Tumblr-Pixel-0
X-RemovedCookies
VIX-Pulpo-Upstream-Status
X-G
X-Cacheable-TTL
X-Tumblr-User
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-Cluster-Name
X-IPLB-Instance
X-B
X-Framework
Ms-Operation-Id
X-Cache-Time
X-Content-Powered-By
X-Device-Type
X-RTag
Access-Control-Request-Headers
X-Proxy
X-Cache-Hit
Amp-Access-Control-Allow-Source-Origin
X-Parallel-Accel
X-Zen-Fury
SD-X-WS
X-IPS-LoggedIn
Referer-Policy
X-CDN-Forward
X-Cache-Rule
Uber-Trace-Id
Liferay-Portal
X-Rendered-As
X-Is-Bot
X-Drupal-Cache-Tags
Cache-Status
X-Ms-Request-Id
X-Ms-Version
X-Wix-Request-Id
X-Oracle-Dms-Rid
X-EdgeConnect-Cache-Status
X-Time
X-App-Server
Section-Io-Id
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Countrycode
Section-Origin-Responded
X-Mg-Request-UUID
X-Environment-Context
X-Revision
X-L-Path
X-Debug
S-Cnection
X-B3-Traceid
Country
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-APP-VERSION
X-TA-CDN-Provider
CF-IPCountry
X-Accel-Buffering
Count-Hit
X-Cache-Operation
X-RateLimit-Limit
X-FW-Version
X-Drupal-Cache-Contexts
X-Nginx-Cache
Akamai-GRN
X-Microsite
X-SaId
X-JoinUs
X-GG-Cache-Date
X-Request-Handler-Origin-Region
X-ES-SERVER
X-UPSTREAM-Address
X-RN-RSRV
X-Endurance-Cache-Level
Meta-Geo
X-SayCDN-TTL
X-Cache-TTL-Remaining
X-LAGOON
X-Adobe-Source
From-Origin
X-Cache-Type
Cache
X-TNCMS
X-Loop
X-Say-Cacheable
X-Say-TTL
Azure-SlotName
Fastly-SSL
X-Request-Time
Azure-Version
X-Sql-Count
Surrogate-Key
X-NYM-Debug-Backend
X-OCL
Azure-RegionName
GEO-INFO
Azure-SiteName
X-Varnish-Beresp-Grace
X-PCL
Country-Code
X-R9-Blue-Green-Version
X-Human
X-Sql-Duration-Ms
X-S-Maxage
Azure-InstanceId
Apigw-Requestid
Decoy-Debug-TTL
X-Alternate-Cache-Key
Protected
X-B3-SpanId
Decoy-Debug-Status
Cache-Name
Cache-Tv-Group
Decoy-Debug-Key
X-Pubstack
X-Via-Fastly
X-Varnishpool
X-ShardId
X-Be
X-No-Session
X-Labrador-Cache-Channel
X-Varnish-Hostname
X-ShopId
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Storefront-Renderer-Rendered
X-Shopify-Stage
X-Status
X-Origin-Date
X-ProxyCache-Status
X-PHP-Host
X-Proto
X-Handled-By
X-BYPASS-REASON
X-ProxyCache-Key
X-Hosted-By
X-Akamai-Edgescape
Eomportal-Instance
X-Origin-Hint
Selected-Fe
Property-Id
X-LJ-Flow-ID
X-Timing-Wait
X-ApacheServer
X-AWS-Id
X-Cache-Server
X-Tumblr-Pixel-2
X-UA-Device-Type
X-Cluster-Node
X-Format
X-VWS-Id
X-Redis-Cache
X-Xfnlog-Site
TWC-GeoIP-LatLong
X-RCS-CacheZone
TWC-Locale-Group
Webcakes-App-Name
TWC-Privacy
Webcakes-Region
TWC-GeoIP-Country
X-Section
X-Proxy-Build
TWC-Connection-Speed
X-Web-Node
X-PERF
X-Access
TWC-Device-Class
ServedBy
Webcakes-App-Version
Nel
X-Time-Microsecs
AR-Request-ID
AR-ATIME
AR-CACHE
AR-PoweredBy
Ar-Sid
X-Server-W
Mn-Server-Ip
X-PHP-Backend
X-Hyper-Cache
X-Backend-Host
Cross-Origin-Opener-Policy
X-FB-TRIP-ID
X-Uri
OT-Force-Account-Verify
X-App-Version
X-Backend-Name
X-Hl-Ver
X-Servername
X-ServerID
X-Tumblr-Pixel-3
X-Detected-As
X-ATG-Version
Cross-Origin-Window-Policy
X-Azure-Ref-OriginShield
Web-Mar-Node
X-Ua
X-Varnish-Cache-Hits
X-Generation-Time
X-FireWall-Port
X-Cache-Host
X-Cache-PHP
Source
Ec-Rule-Version
Content-Secure-Policy
X-Varnish-Hits
X-Ratelimit-Limit
X-Content-Age
X-Ratelimit-Remaining
X-Datadome
X-Trace-Id
Backend
X-Via-JSL
X-Ua-Browser
X-TEC-API-VERSION
X-SRV
X-Content
X-TEC-API-ROOT
X-Akamai-Transformed
X-TEC-API-ORIGIN
X-Air-Trace-Id
Xserver
X-Forwarded-Host
Upgrade-Insecure-Requests
X-Air-Hostname
X-Air-Source
X-Amzn-RequestId
X-MP-GENERATED-AT
X-Amz-Apigw-Id
X-Cache-Grace
X-WA-Info
X-Microcachable
X-Cdn
X-CSRF-Token
X-CS
X-TT-LOGID
X-Locale
X-NWS-UUID-VERIFY
X-Dc
X-Amzn-Remapped-Content-Length
X-Soup
X-Edge-Location
X-Cache-Enabled
Url
X-Site-Version
X-Origin-TTL
X-Bc-Bl
X-Origin-CC
X-Mode
X-Info
X-Rule
AMP-Access-Control-Allow-Source-Origin
X-Tenant
Content-Disposition
X-GEO
X-Unique-Id
S-Rt
X-Varnish-Beresp-Status
X-Tb
SID
X-Varnish-Beresp-Ttl
X-Magnolia-Registration
X-Forwarded-Path
X-A-Dcw
X-A-Dgt
BehaviorPad-Version
Host-ID
CDN-Uid
X-A-Dam
X-Connection-Hash
X-Conf
X-A-Wwc
X-Vtex-Remote-Cache
X-NU-AKA-ACS-Version
X-CF-Lambda-Fn
A
X-Cache-NE
X-CF-Lambda-Version
X-Vtex-Processado-Em
Apple-News-Services-Request-Url
CDN-RequestId
X-NAPM-TraceId
X-Shop-Environment
X-D
X-Developer
Apple-News-Services-Handled
X-Vdms-Version
X-A
DCR-Processing-Time-Ms
DCR-Decision-By
X-Ftr-Request-Id
X-Epic-Correlation-Id
X-From
X-Destination
Expiry
Fastly-SIE
Fastly-SWR
Surrogated-Key
Apple-News-Services-Parsed-Url
X-A-Ccd
X-Debug-Cache
T-Server
Fastcgi-X-Cache-Version
Apple-News-Services-Host
MD5-Digest
X-Orig-Expires
Rendered-Blocks
X-M-Log
X-Application
X-ARC
X-SRCache-Key
X-Rojux
X-Rewrite-Enabled
Odigeo-Trace-Id
X-Aed
X-External-Request-Id
CDCHOST
X-BBC-Edge-Cache-Status
X-B-Cookie
CDN-Cache
X-Session-Fingerprint
X-BCube-Filmed-By
X-ScT
X-S
X-S-Cookie
Path
CDN-EdgeStorageId
Req-Svc-Chain
Meta-Geo-Continent
Mobile-Detection-Method
X-VG-WebCache
X-Ratelimit-Reset
CDN-PullZone
CDN-RequestCountryCode
X-Platform-Server
User-Cache-Control
X-Processor
X-Aicache-OS
X-PBS-Appsvrname
X-Cache-Bucket
CDN-CachedAt
X-AIR-PT
X-Request-URI
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-M-Reqid
X-PAYTM-SRV-ID
X-VG-WebServer
X-Proxied
X-Routing-Service
X-Zipkin-Id
X-Qnm-Cache
X-Storage
X-EC-Lua
X-DataDome
X-NCache
X-Extlb
L
X-Cache-Debug
X-Cache-Info
X-Accel-Expires-Debug
NGX
Origin
X-Backend-State
Platform
X-Cms-Context
Is-Eu
UCS
X-DPWN-IS-SECURE
Fastly-Backend-Name
X-Date
X-Core-Value
State
X-Envoy-Decorator-Operation
X-Li-Fabric
X-Men
Cache-Key
X-Proxy-Upstream
X-Loc
X-LI-UUID
X-JWT-State
X-Worker
X-Li-Pop
X-Varnish-Ttl
X-Request-UUID
X-TrackingId
X-Variation
X-VG-TLSProxy
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-VServer
X-Scheme
X-Service
X-Is-Gdpr
X-Origin-Expires
X-Fastly-Cache
Cache-Host
Adler-Geo
X-Micro-Cache
X-Has-Esi
X-Cached-By
X-Cache-NGX
X-Slack-Backend
X-Skip-Cache
X-Esi-Check
X-Via-NSCOPI
X-Forwarded-Site
X-Viewer-Country
X-SIPLIST1
X-Sigma
X-Sigma-Backend
X-Auto-Login
X-Thanos
X-DefElseHash
X-Served-From
X-HN
VNS-Cache
VNS-Age
Vix-Hermes-Req-Id
X-VarnishDD-TTL
X-Varnish-Remaining-TTL
X-VC-Cache
X-Fastly-Backend
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Thinkindot-L3
X-Gamma-Serve
X-Clientip
X-Wikidot-Backend
X-Ckpd-Fst-Backend
True-Client-Country-4JS
X-Old-Content-Length
X-Cluster
X-Generated-On
X-DefHash
X-Gzip
X-Wikidot-Static-Cache
X-Geo-Header
X-Location
X-Cache-Tags
X-Origin
X-Block-Status
X-Device-Os
X-Rocket-Build-Number
X-Hnp-Log
X-Bip
X-Branch-Name
X-Developers
X-Gen-Mode
X-Generated-By
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Req
X-Level-Front-Cache
X-Cache-Id
M-TraceId
Locid
Location
Arc-Version
AKAMAI
DataCenter
Pics-Label
PFcat
PB-RID
IsBot
C-Via
Cmstype
CPC-Cache
CPC-Age
Esi-Enabled
Fastcgi-Cache-TTL
Cf-Device-Type
Cmsid
Fastly-Drupal-HTML
Server-Ext
PB-PID
Thinkindot-CacheControl-Type
X-Tx-Id
Sever-Int
Svr
TDXMobile
Thinkindot-Control
Thinkindot-CacheControl
Server-Hostname
Server-Host
X-LSADC-Cache
X-Amz-Meta-S3cmd-Attrs
X-Platform
X-Planisys-CDN-Cache
X-FC-Vary-Parameters
X-Planisys-CDN-Rules
X-Owner
X-Mvc-Supplant-Cachable
X-Eu-Site
X-Nginx-Cache-Key
X-Fetched-On
X-Planisys-CDN-TTL
X-Platform-Cluster
X-Platform-Processor
CacheControlHeader
X-Request-Host
X-Vdms-Path
X-HS-Content-Campaign-Id
X-Sucuri-ID
X-Irp-Debug
X-Var-Ttl
NtCoent-Length
X-Hash
X-Goog-Meta-Goog-Reserved-File-Mtime
XServer
Arc-Country
X-Render-Time
X-Generated-In
X-GeoIP-City
X-GeoIP
X-Policy
X-Platform-Router
X-CGP
Server-Info
Wxu-Next-Region
Release
Pagetype
DSUID
Memcached
Mail-Subject
L5d-Success-Class
Wxu-Next-Hostname
We-Hiring
V-Age
X-Rocket-Nginx-Serving-Static
X-Csrf-Jwt
Gh-Request-Id
HA-Ipaddr
Wxu-Next-Commit
Ha-Gx-Prefs
NM-Fastcgi-Cache
Webserver
X-V-Cache
X-SD-PageType
X-WADP-Cache
X-GoCache-CacheStatus
X-Fmm-Version
X-Qloud-Router
X-Clara-WADP
X-Cache-Var
X-Unique-ID
X-Cache-Var-Map
X-Cache-Remote
X-Mvc-Supplant-OutputCached
Environment
X-DC
Cache-Hits
X-CACHE-KEY
X-PJAX-URL
MIME-Version
X-Datadog-Parent-Id
X-NodeID
Kp-EeAlive
X-Via-Popv
X-Nyt-Route
X-Origin-Time
X-Servedbyhost
X-Gdpr
X-Datadog-Trace-Id
X-Via-Poph
X-API-Version
X-Via-Popn
X-Datadog-Sampling-Priority
X-Srv
X-NC
X-Vc
X-Via-Ucdn
X-Zone
X-Cache-Config
Candidate-Md5Url
X-PF-Uncompressing
X-Pod-Name
X-Server-IP
X-User
X-BBC-Origin-Response-Status
WebServer
X-Wa
Time
Cluster
Memory
Who
X-Internal-Host
X-Traceid
X-Minions-Version
X-Webkit-Csp
X-Refresh
X-App
X-TIME
Server-ID
HostName
X-Varnish-Url
X-ZONE
Onion-Location
X-Webkit-CSP-Report-Only
X-LB-ID
X-VCL-Version
GeoIp-Country-Code
Web-Mar-Region
X-Pass-Why
X-Edge-Pop
X-Tt-Logid
N-Cache
My-App
X-NewRelic-App-Data
X-ID
Geoip-Latitude
Resin-Trace
Powered-By-ChinaCache
X-Newrelic-Synthetics
X-Cache-Ttl
X-Esi
X-Tb-Optimization-Total-Bytes-Saved
X-CLOUD-TRACE-CONTEXT
X-ElasticPress-Query
X-TraceId
Servername
X-Akamai-Pragma-Client-IP
X-TX-ID
X-LI-Proto
Geo-Info
CDN
Datacenter
X-VHOST
X-EIG-Tracking-Id
X-Varnish-Cacheable
WWW-Authenticate
X-Fastly-Request-Id
Ohc-File-Size
Tcn
X-CACHE-AGE
X-Origin-Response-Time
X-OVcl-Cache
X-HITS
X-OVcl
X-Dynatrace
X-Varnish-Beresp-TTL
X-TIM-N
Redirect-Candidate
X-Fpc
X-Tid
X-Li-Proto
Cf-Bgj
X-Geo
X-Backend-TTL
LB
X-Up
X-NODE
Tracecode
Hostname
Magicmarker
Proxy-Connection
X-Correlation-ID
X-AB
Pramga
X-Method
X-Cache-Date
X-Wix-Viewer-Type
X-Request-Start
X-NGINX-Cache
X-Dynatrace-Js-Agent
X-HostName
Cdn
X-Dispatcher-Server
X-Sn-Servicetimems
X-Cs
X-Vcl-Version
X-Amz-Meta-Cb-Modifiedtime
X-Cdn-Origin
X-CSRF-TOKEN
Cf-Ipcountry
CloudFront-Viewer-Country
X-MSEdge-Features
Is-Us
Server-Id
Lb
X-Fastly-Backend-Reqs
X-MSEdge-Flight
W
X-Provided-By
GeoIP-Country-Code
CF-Cached-On
X-UnsetCookies
X-COUNTRY
X-WA
X-HS-Status
X-APP
Ssr
X-Lb-Id
X-Cache-Expires
X-IP
X-Core-Mission
Sid
GeoIP-Latitude
X-MG-S
DB-Nickname
WP-Super-Cache
X-Reqid
X-ServerName
Cteonnt-Length
X-Webkit-Csp-Report-Only
X-FORWARDED-FOR
X-DynaTrace-JS-Agent
X-Cache-Status-Check
X-Hcs-Proxy-Type
URI
X-Sucuri-Cache
X-CCDN-Origin-Time
X-Region-Sid
X-Node-Id
X-CCDN-CacheTTL
X-Check-Cacheable
CountryCode
Ohc-Cache-HIT
X-Nc
X-Moov-T
X-Moov-Xdn-Version
Xc-Version
X-Cache-Backend
X-ND-Cache
X-Trv-Group
X-SERVER-NAME
X-Via-PopV
X-Via-PopN
X-ServedByHost
X-Via-PopH
Mime-Version
X-VC
X-ECache
X-Ig-Push-State
X-Pad
User-Agent
X-Via-CDN
WZWS-RAY
EpKe-Alive
X-SN
X-Pjax-Url
Env
Shield-Pop
X-Cdn-Forward
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-Contensis-Viewer-Groups
X-Acquia-Purge-Tags
X-Edge-POP
X-Acquia-Site
X-Cache-ASPX
X-RAMCache
X-CUA
X-Fastly-Cache-Hits
X-LiteSpeed-Cache-Control
CACHE
X-Pf-Uncompressing
FSS-Cache
X-Amz-Meta-Opti
X-Varnish-Authentication
X-Nginx-Upstream-Cache-Status
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Oss-Request-Id
X-Oss-Storage-Class
Srv
HIT
X-Oss-Server-Time
X-IN-APIGATEWAY
X-Parent-Response-Time
X-Cdn-Request-ID
On-Server
X-IN-APIGATEWAYSSL
X-Dispatch
X-Swift-Error
X-DSS
X-DI
X-RPM
X-RPS
X-RSL
X-DB
X-Action
Ohc-Response-Time
ServerName
Vha6-Origin
X-Dw-Trace-Id
X-StackifyID
X-DW
Server-Ttl
X-SB
X-Webstats-RespID
Xet-Cookie
X-TRACE-ID
X-Amzn-Remapped-X-Forwarded-For
X-Amzn-Remapped-User-Agent
X-Env-Sha256-Sig
X-Amzn-Remapped-Host
X-Snapshot-Date
X-FPC
X-Env-Stack-Name
PICS-Label
X-Ftr-Viewer-Uri
X-Forwarded-Port
X-MiniProfiler-Ids
Hit
X-CF-Powered-By
Rt-Fastcgi-Cache
Viewtype
Req-ID
Content-Script-Type
X-Yottaa-OS
VivaBuild
Content-Style-Type
Fastly-Drupal-Html