Threat Level: green Handler on Duty: Russ McRee

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-RAY
CF-Cache-Status
Accept-Ranges
Link
ETag
Pragma
Expect-CT
X-Powered-By
X-XSS-Protection
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
Alt-Svc
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Timer
X-Download-Options
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Request-ID
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-Cacheable
X-DNS-Prefetch-Control
Timing-Allow-Origin
P3p
X-Content-Security-Policy
X-Iinfo
Status
X-Ua-Compatible
Feature-Policy
Content-Encoding
X-AspNetMvc-Version
X-CDN
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
Upgrade
X-Drupal-Dynamic-Cache
Access-Control-Max-Age
X-Via
X-Dns-Prefetch-Control
Keep-Alive
X-Ws-Request-Id
X-Robots-Tag
Server-Timing
Request-Context
X-AH-Environment
X-Hacker
X-Server
X-Age
X-Turbo-Charged-By
X-Proxy-Cache
X-Server-Powered-By
X-Cache-Group
X-Backend
X-Amz-Request-Id
Host-Header
X-Amz-Id-2
EagleId
X-Nginx-Cache-Status
Report-To
X-LiteSpeed-Cache
X-Rq
X-Varnish-Cache
X-UA-Device
X-Page-Speed
Grace
X-Pingback
X-Swift-SaveTime
X-Swift-CacheTime
EagleEye-TraceId
Ali-Swift-Global-Savetime
X-Device
X-Vhost
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
X-Amz-Version-Id
NEL
X-Dispatcher
Cf-Railgun
X-Host
X-Cache-Spec
X-Server-Id
X-CST
X-WebKit-CSP
X-Node
X-Backend-Server
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Allow
Request-Id
Surrogate-Control
X-Readtime
Accept-CH
X-Akam-SW-Version
X-Response-Time
Accept-Ch-Lifetime
Xkey
X-HW
X-Ruxit-JS-Agent
X-Language
X-Country
X-Webkit-CSP
X-Application-Context
X-Template
X-Ac
Content-Location
X-Cache-Lookup
MS-Author-Via
X-Cloud-Trace-Context
Rating
X-Url
Edge-Control
X-B3-TraceId
X-TtlSet
X-Vname
X-PC
X-Mod-Pagespeed
X-Clacks-Overhead
X-Varnish-TTL
X-Trace
X-MS-InvokeApp
X-ESI
X-Content-Type
Fastly-Restarts
X-Rack-Cache
X-Origin-Cache
X-GitHub-Request-Id
X-Cnection
Accept-Ch
X-Buckets
X-Country-Code
X-Goog-Hash
Accept-CH-Lifetime
Verso
X-D2id
X-VARITI-CCR
X-Cdn-Fetch
X-Exp-Variant
X-GoogleNews-Bot
X-Kinja
X-Kinja-Server
X-Kinja-Build
X-Use-Magma
X-Kinja-Revision
X-Exp-Id
Arr-Disable-Session-Affinity
X-FastCGI-Cache
X-ORACLE-DMS-ECID
X-Vcap-Request-Id
Cache-Tag
X-Cached
Service-Worker-Allowed
X-Abt-Application-Version
X-Server-Name
X-Amz-Rid
X-Client-IP
X-Server-ID
X-Navigation-Version
X-Px
X-Powered-By-Plesk
RTSS
Public-Key-Pins
Access-Control-Request-Method
X-SRCache-Fetch-Status
X-Fastly-Request-ID
X-SRCache-Store-Status
X-Element-Page-Cache
X-Powered-CMS
X-MSEdge-Ref
X-Cache-TTL
X-Upstream
X-Dw-Request-Base-Id
X-NF-Request-ID
X-Version
Response
Display
X-Sol
Pagespeed
X-Middleton-Display
X-Middleton-Response
S
X-Ttl
X-TTL
X-Edge
X-Edge-Location-Klb
X-Kinsta-Cache
X-LLID
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Kraken-Routeconfig-Destination
X-Instrumentation
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
Realpath
X-Cache-Key
X-Accel-Expires
X-Jurisdiction
X-HP-Webp
X-ECACHE
X-SharePointHealthScore
SPRequestGuid
X-Shield-Request-Id
SPRequestDuration
SPIisLatency
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
X-MCACHE
X-T
X-Mid
X-PressLabs-Stats
X-DynaTrace
X-Litespeed-Cache
X-Content-Security-Policy-Report-Only
X-ORACLE-DMS-RID
X-Correlation-Id
Edge-Cache-Tag
Fastcgi-Cache
X-Forwarded-Proto
X-XRDS-Location
X-Mg-S
X-Amz-Server-Side-Encryption
X-Content-Digest
Nginx-Cache
TP-Cache
X-Recruiting
TP-L2-Cache
Charset
Filters
Front-End-Https
TCN
X-Id
Alternate-Protocol
X-Request-Processing-Time
X-Request-Received
Server-Node
X-Logged-In
X-Forwarded-For
X-Ezoic-Cdn
Content-MD5
X-Geo-Country
Cache-Tags
Fusion-Component-Id
Fusion-Source
Fusion-Template-Id
Fusion-Deployment-Id
Fusion-Content-Source
Fusion-Content-Id
X-Protected-By
X-ASPNET-VERSION
X-Hostname
X-Amzn-Trace-Id
X-Grace
X-Origin-Upstream-Status
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Storage-Class
X-NWS-LOG-UUID
X-Www-Served-By
X-Origin-Server
X-F-Cache
X-Amz-Replication-Status
Cleartype
X-Oneagent-Js-Injection
X-Rid
X-Debug-Info
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
X-Release
X-LB-Cache
Host
X-HS-Combine-CSS
X-Az
X-AppVersion
X-Activity-Id
X-Contextid
Section-Io-Cache
X-Daa-Tunnel
X-Page-Id
Server-Name
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Git-Hash
X-Erf-Bev-Bev
X-Frontend
X-Ser
X-VCache
MicrosoftSharePointTeamServices
X-Aspnetmvc-Version
X-Ab
X-Respond-Thread
X-RateLimit-Remaining
X-Cache-Age
X-Content-Options
X-Ruxit-Js-Agent
Accept-Charset
Access-Control-Allow-Method
X-Upgrade-Enabled
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Hits
X-Mobile-URL
ServerID
X-DIS-Request-ID
X-Source
X-WebKit-CSP-Report-Only
X-B-Cache
X-Is-Crawler
X-Aspnet-Duration-Ms
X-CACHE-GROUP
X-Signature
X-Flags
X-Route-Name
X-Providence-Cookie
X-Request-Guid
X-Varnish-Backend
Payment
X-Cache-Action
X-Whom
X-FB-Debug
X-Varnish-Age
X-Varnish-Grace
Viewport
Healthy
X-TT
Paypal-Debug-Id
Node
X-AOL-HN
X-Fastcgi-Cache
X-App-Environment
DynaTrace
X-B3-Sampled
Fastcgi-Useragent
X-Load-Cache
Version
X-Yandex-Sdch-Disable
X-Mobile
X-Seen-By
X-N
DC
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-XRDS-LOCATION
X-HTML-Minification-Powered-By
X-Distributor
X-Type
Filterid
SRV
Retry-After
Frame-Options
X-Tec-Api-Version
X-User-Agent
X-Tec-Api-Origin
X-Tec-Api-Root
X-Cache-Control
MS-CV
X-Jobs
X-Cache-Expired-At
Refresh
X-Original-Request-Id
X-Response-Served-From
X-UUID
X-Adobe-Loc
X-Real-IP
X-Proxy-Cache-Status
X-Page-View
X-Adobe-Content
NGB
X-IPLB-Instance
Amp-Access-Control-Allow-Source-Origin
X-Varnish-Server
X-Region
X-Instance
X-Debug-IsConnected
X-FW-Server
X-FW-Serve
X-FW-Hash
X-FW-Static
X-FW-Type
X-Debug-IsPreview
X-FW-Dynamic
X-Cluster-Name
X-Device-Type
Access-Control-Request-Headers
X-Proxy
X-ProcessESI
X-RemovedCookies
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Framework
X-Content-Powered-By
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-B
X-Cacheable-TTL
X-Tumblr-Pixel-1
X-G
X-Tumblr-User
X-NGENIX-Cache
Ms-Operation-Id
X-IPS-LoggedIn
X-Cache-Time
X-RTag
X-Azure-Ref
X-Vgn-Hpd-Reason
Uber-Trace-Id
X-Zen-Fury
X-Node-Name
AR-Request-ID
X-CDN-Forward
AR-PoweredBy
AR-ATIME
AR-CACHE
Ar-Sid
Countrycode
X-Request-Handler-Origin-Region
X-Wix-Request-Id
X-Microsite
X-Cache-Hit
Cache-Status
X-Cache-Rule
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Io-Id
X-Ms-Request-Id
X-Ms-Version
Section-Origin-Responded
X-Time
X-Rendered-As
SD-X-WS
X-Is-Bot
Liferay-Portal
X-Oracle-Dms-Rid
X-Mg-Request-UUID
Referer-Policy
X-Aws-Lambda-Call-Status
X-HP-Trace-Id
X-Debug
X-Drupal-Cache-Tags
X-Nginx-Cache
X-Accel-Buffering
X-EdgeConnect-Cache-Status
X-Parallel-Accel
S-Cnection
Cache
Country
CF-IPCountry
X-L-Path
X-App-Server
X-Revision
X-RateLimit-Limit
X-Environment-Context
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Cache-Operation
X-App-Version
Surrogate-Key
X-FireWall-Port
Count-Hit
Meta-Geo
X-GG-Cache-Date
X-TNCMS
X-ES-SERVER
X-TA-CDN-Provider
X-SaId
X-RN-RSRV
X-Loop
X-Drupal-Cache-Contexts
Eomportal-Instance
X-JoinUs
X-Endurance-Cache-Level
X-UPSTREAM-Address
X-LAGOON
X-Adobe-Source
X-Timing-Wait
X-Cache-TTL-Remaining
Selected-Fe
X-Proxy-Build
X-Say-TTL
From-Origin
X-Say-Cacheable
X-SayCDN-TTL
X-Cache-Type
X-Xfnlog-Site
X-Sql-Duration-Ms
Country-Code
X-Human
Azure-RegionName
X-Alternate-Cache-Key
X-BYPASS-REASON
X-AWS-Id
X-Be
X-FW-Version
Akamai-GRN
Azure-Version
Azure-SlotName
Azure-SiteName
Azure-InstanceId
Cache-Name
X-No-Session
X-Varnishpool
X-Origin-Date
X-ShardId
X-NYM-Debug-Backend
X-Varnish-Hostname
X-ProxyCache-Key
X-Proto
X-Sql-Count
X-ProxyCache-Status
X-Varnish-Beresp-Grace
X-Storefront-Renderer-Rendered
X-VWS-Id
X-LJ-Flow-ID
Protected
X-ShopId
X-Sorting-Hat-ShopId
X-Shopify-Stage
X-Sorting-Hat-PodId
X-S-Maxage
X-Request-Time
X-PHP-Backend
Apigw-Requestid
X-Pubstack
X-PHP-Host
Cache-Tv-Group
Fastly-SSL
ServedBy
Decoy-Debug-TTL
Decoy-Debug-Status
Decoy-Debug-Key
X-Status
X-R9-Blue-Green-Version
X-Cache-Server
X-RCS-CacheZone
GEO-INFO
X-OCL
X-Handled-By
X-Labrador-Cache-Channel
X-Hosted-By
X-PCL
X-UA-Device-Type
X-Akamai-Edgescape
X-Redis-Cache
X-Format
X-Web-Node
TWC-Device-Class
X-Tumblr-Pixel-2
X-Via-Fastly
X-Access
X-Hl-Ver
TWC-Connection-Speed
X-Hyper-Cache
Webcakes-App-Version
X-Origin-Hint
X-Section
TWC-GeoIP-LatLong
TWC-Locale-Group
Webcakes-Region
X-Uri
TWC-Privacy
Webcakes-App-Name
X-Backend-Name
X-Server-W
TWC-GeoIP-Country
Property-Id
X-APP-VERSION
X-PERF
X-Backend-Host
X-ApacheServer
Mn-Server-Ip
Nel
X-FB-TRIP-ID
X-Ua-Device
X-ServerID
X-Cluster-Node
X-Time-Microsecs
X-B3-SpanId
X-ATG-Version
X-Servername
OT-Force-Account-Verify
X-Cache-PHP
Xserver
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
Cross-Origin-Opener-Policy
X-Tumblr-Pixel-3
X-Detected-As
X-Azure-Ref-OriginShield
X-Trace-Id
X-CSRF-Token
Backend
X-Content-Age
Web-Mar-Node
X-MP-GENERATED-AT
X-Varnish-Cache-Hits
X-Generation-Time
X-TT-LOGID
X-Cache-Host
X-WA-Info
X-Datadome
Cross-Origin-Window-Policy
X-Ua
X-Varnish-Hits
X-Bc-Bl
Content-Secure-Policy
X-Rule
X-SRV
X-Soup
X-Akamai-Transformed
X-Cached-By
X-Edge-Location
X-CS
Ec-Rule-Version
X-Cache-Enabled
X-Via-JSL
X-Ratelimit-Limit
X-Amzn-Remapped-Content-Length
Source
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Mode
X-NWS-UUID-VERIFY
X-Info
S-Rt
X-Microcachable
X-Ratelimit-Remaining
X-Cache-Grace
X-Origin-TTL
X-Varnish-Beresp-Status
X-Origin-CC
Url
X-Forwarded-Host
X-Locale
X-Magnolia-Registration
Upgrade-Insecure-Requests
X-B3-Traceid
X-Cache-NGX
SID
X-GEO
X-Air-Hostname
X-Air-Source
X-Air-Trace-Id
X-Site-Version
X-Storage
X-EC-Lua
X-Varnish-Beresp-Ttl
X-Dc
X-Debug-Cache
X-Tb
X-Destination
X-PBS-Appsvrname
User-Cache-Control
X-Platform-Server
X-Aicache-OS
X-Application
X-NU-AKA-ACS-Version
X-Orig-Expires
X-From
X-A-Dgt
Path
X-PAYTM-SRV-ID
X-Ftr-Request-Id
X-ARC
Apple-News-Services-Request-Url
X-AIR-PT
X-Forwarded-Path
Meta-Geo-Continent
MD5-Digest
X-Tenant
X-Extlb
X-External-Request-Id
M-TraceId
X-Epic-Correlation-Id
X-VG-WebServer
Mobile-Detection-Method
X-Aed
X-GoCache-CacheStatus
X-A
X-Zipkin-Id
X-NAPM-TraceId
Odigeo-Trace-Id
BehaviorPad-Version
X-Developer
X-Vdms-Version
X-A-Wwc
X-D
T-Server
X-BCube-Filmed-By
X-CF-Lambda-Fn
Fastcgi-X-Cache-Version
X-ScT
X-CF-Lambda-Version
X-Routing-Service
X-S
X-S-Cookie
A
X-A-Ccd
X-Cache-NE
X-VG-WebCache
X-SRCache-Key
X-Unique-Id
DCR-Decision-By
X-Cache-Bucket
DCR-Processing-Time-Ms
X-Session-Fingerprint
X-Shop-Environment
Expiry
Apple-News-Services-Handled
Host-ID
X-Rojux
Content-Disposition
X-Connection-Hash
X-A-Dam
X-Ratelimit-Reset
Req-Svc-Chain
Rendered-Blocks
X-Processor
CDCHOST
X-Proxied
X-A-Dcw
Surrogated-Key
X-Vtex-Remote-Cache
X-Request-URI
State
X-Vtex-Processado-Em
X-Rewrite-Enabled
X-Conf
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
X-B-Cookie
X-Clientip
X-DataDome
X-Cache-Ttl
Fastly-SWR
Cmstype
DSUID
Fastly-Backend-Name
Fastly-Drupal-HTML
X-Forwarded-Site
Fastly-SIE
X-Fmm-Version
Platform
X-Clara-WADP
X-Cms-Context
X-Core-Value
Cmsid
X-Cache-Tags
X-Cache-Info
X-Backend-State
X-Bip
UCS
X-BBC-Edge-Cache-Status
X-Date
PB-RID
X-Envoy-Decorator-Operation
X-Fastly-Backend
L
X-Fastly-Cache
X-DPWN-IS-SECURE
NGX
PB-PID
X-Accel-Expires-Debug
Origin
Is-Eu
X-Li-Fabric
X-Li-Pop
X-LI-UUID
X-Loc
X-Men
X-VG-TLSProxy
X-JWT-State
X-Thanos
X-SVT-ORM-VERSION
X-Platform
X-Is-Gdpr
X-Sigma-Backend
X-Sigma
X-WADP-Cache
X-Request-Host
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Request-UUID
X-Proxy-Upstream
X-Service
X-Origin-Expires
X-VServer
X-Rocket-Build-Number
X-Hash
X-SVT-ORM-RULES
CDN-Uid
Cache-Key
Cache-Host
CDN-PullZone
CDN-RequestId
CDN-EdgeStorageId
CDN-Cache
CDN-CachedAt
C-Via
X-TrackingId
X-Has-Esi
Adler-Geo
Arc-Version
CDN-RequestCountryCode
X-Variation
X-Amz-Meta-S3cmd-Attrs
AMP-Access-Control-Allow-Source-Origin
X-Varnish-Remaining-TTL
X-VarnishDD-TTL
X-VC-Cache
X-Scheme
X-CGP
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-Cache-Debug
X-Block-Status
X-Var-Ttl
X-Via-NSCOPI
X-Req
X-Branch-Name
X-Slack-Backend
X-Viewer-Country
X-Thinkindot-L3
X-SIPLIST1
X-Served-From
X-Origin
X-Hnp-Log
X-HN
X-FC-Vary-Parameters
X-Irp-Debug
X-Eu-Site
X-Level-Front-Cache
X-Esi-Check
X-Gzip
X-GeoIP-City
X-Generated-In
X-Generated-On
X-GeoIP
X-Generated-By
X-Gamma-Serve
X-Gen-Mode
X-Device-Os
X-Location
X-Wikidot-Backend
X-DefElseHash
X-Policy
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Csrf-Jwt
X-DefHash
X-Geo-Header
X-Micro-Cache
X-Developers
X-Mvc-Supplant-Cachable
X-Nginx-Cache-Key
X-Old-Content-Length
X-Wikidot-Static-Cache
X-Cluster
X-Cache-Id
Pagetype
NM-Fastcgi-Cache
CacheControlHeader
Cf-Device-Type
PFcat
Pics-Label
Server-Host
Server-Ext
Release
CPC-Age
CPC-Cache
L5d-Success-Class
Gh-Request-Id
IsBot
Ha-Gx-Prefs
Location
Locid
Mail-Subject
Esi-Enabled
Fastcgi-Cache-TTL
HA-Ipaddr
Server-Hostname
Thinkindot-Control
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
VNS-Age
X-DC
Vix-Hermes-Req-Id
True-Client-Country-4JS
TDXMobile
VNS-Cache
Sever-Int
Server-Info
We-Hiring
X-Worker
X-Ckpd-Fst-Backend
X-Unique-ID
Webserver
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Owner
X-Skip-Cache
X-Planisys-CDN-Rules
AKAMAI
X-Sucuri-ID
NtCoent-Length
X-Planisys-CDN-Cache
Arc-Country
X-Vdms-Path
X-Planisys-CDN-TTL
Svr
X-Fetched-On
Wxu-Next-Hostname
V-Age
Wxu-Next-Commit
Memcached
Wxu-Next-Region
Kp-EeAlive
DataCenter
X-M-Reqid
X-HS-Content-Campaign-Id
X-Auto-Login
X-Qloud-Router
X-M-Log
X-NCache
X-User
X-Tx-Id
X-Mvc-Supplant-OutputCached
X-Qnm-Cache
X-V-Cache
X-Via-Popv
X-Via-Popn
X-Via-Poph
Cache-Hits
Who
X-Content
X-Ua-Browser
X-Platform-Cluster
X-Render-Time
MIME-Version
X-PF-Uncompressing
X-Platform-Processor
X-Rocket-Nginx-Serving-Static
X-LSADC-Cache
X-NC
X-Servedbyhost
X-Platform-Router
XServer
X-Srv
X-Traceid
X-Minions-Version
X-SD-PageType
X-Varnish-Url
X-ID
X-Zone
X-ZONE
X-Cache-Remote
Environment
X-Datadog-Trace-Id
X-Datadog-Parent-Id
X-LB-ID
X-Vc
X-Datadog-Sampling-Priority
WebServer
X-Varnish-Ttl
X-App
X-Origin-Time
X-Nyt-Route
X-Refresh
X-Cache-Var
My-App
X-Cache-Var-Map
X-Gdpr
X-PJAX-URL
X-NodeID
X-Wa
X-BBC-Origin-Response-Status
Powered-By-ChinaCache
X-API-Version
X-TIME
X-Internal-Host
X-Webkit-Csp
Cluster
Server-ID
Memory
X-Pass-Why
X-Via-Ucdn
X-Server-IP
X-Cache-Config
Time
X-Newrelic-Synthetics
X-CACHE-KEY
X-Webkit-CSP-Report-Only
X-Pod-Name
X-TX-ID
X-VCL-Version
Candidate-Md5Url
HostName
X-NewRelic-App-Data
X-CLOUD-TRACE-CONTEXT
GeoIp-Country-Code
X-OVcl-Cache
Resin-Trace
X-OVcl
Datacenter
Geoip-Latitude
Hostname
Cf-Bgj
X-Edge-Pop
Geo-Info
X-Tb-Optimization-Total-Bytes-Saved
X-LI-Proto
X-Correlation-ID
Web-Mar-Region
X-ElasticPress-Query
N-Cache
X-VHOST
X-TraceId
X-Backend-TTL
Magicmarker
Onion-Location
Ohc-File-Size
Tcn
X-Origin-Response-Time
X-Akamai-Pragma-Client-IP
X-Dynatrace
X-HITS
X-CACHE-AGE
X-Varnish-Beresp-TTL
X-Geo
WWW-Authenticate
X-Dispatcher-Server
X-Method
X-Varnish-Cacheable
Servername
X-Li-Proto
X-Esi
GeoIP-Country-Code
X-EIG-Tracking-Id
X-NODE
Proxy-Connection
DB-Nickname
X-AB
X-MSEdge-Flight
Ssr
X-IP
X-Wix-Viewer-Type
X-Tt-Logid
X-MSEdge-Features
CDN
GeoIP-Latitude
Cdn
X-HostName
LB
X-Dynatrace-Js-Agent
X-Cs
Redirect-Candidate
X-Tid
X-TIM-N
X-Fastly-Request-Id
X-Vcl-Version
X-Fpc
CF-Cached-On
Cf-Ipcountry
Server-Id
Lb
X-Request-Start
X-Up
X-Node-Id
Tracecode
X-DynaTrace-JS-Agent
X-HS-Status
X-Trv-Group
Pramga
X-ND-Cache
Is-Us
X-Fastly-Backend-Reqs
X-Cache-Date
X-APP
Sid
X-WA
X-MG-S
X-Sn-Servicetimems
X-Amz-Meta-Cb-Modifiedtime
X-Cdn-Origin
X-NGINX-Cache
Cteonnt-Length
X-Via-CDN
X-Pjax-Url
X-Webkit-Csp-Report-Only
X-Reqid
Env
X-ServerName
WZWS-RAY
X-Nc
X-FORWARDED-FOR
URI
X-VC
W
X-Core-Mission
X-Provided-By
X-Check-Cacheable
X-Lb-Id
Ohc-Cache-HIT
X-UnsetCookies
X-CSRF-TOKEN
X-ServedByHost
CloudFront-Viewer-Country
X-SERVER-NAME
X-Via-PopV
X-IN-APIGATEWAY
Mime-Version
X-Cache-Backend
X-Cache-Expires
X-Via-PopH
X-IN-APIGATEWAYSSL
X-Via-PopN
X-ECache
Shield-Pop
WP-Super-Cache
VivaBuild
Server-Ttl
X-Pf-Uncompressing
Viewtype
CountryCode
X-SN
Rt-Fastcgi-Cache
X-Cdn-Forward
X-RAMCache
X-Acquia-Site
X-Acquia-Purge-Tags
CACHE
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-LiteSpeed-Cache-Control
X-Pad
X-Cache-ASPX
X-Sucuri-Cache
X-Region-Sid
X-Hcs-Proxy-Type
X-Fastly-Cache-Hits
X-Contensis-Viewer-Groups
X-CCDN-CacheTTL
X-Cache-Status-Check
X-CCDN-Origin-Time
X-Edge-POP
X-Varnish-Authentication
X-Moov-Xdn-Version
X-CUA
Xc-Version
X-Cdn-Request-ID
X-Moov-T
EpKe-Alive
X-DSS
ServerName
Machine
X-Action
X-DB
Ohc-Response-Time
X-Dw-Trace-Id
X-Webstats-RespID
X-SB
X-Swift-Error
X-Yottaa-OS
X-DI
Vha6-Origin
X-StackifyID
Xet-Cookie
X-RSL
X-RPS
X-DW
X-RPM
X-B3-Spanid
PICS-Label
X-Ig-Push-State
X-FPC
User-Agent
X-TH-Server
Content-Script-Type
Content-Style-Type
X-ElasticPress-Search
Req-ID
X-MiniProfiler-Ids
X-CF-Powered-By