Threat Level: green Handler on Duty: Renato Marinho

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-RAY
CF-Cache-Status
Accept-Ranges
Link
ETag
Pragma
Expect-CT
X-Powered-By
X-XSS-Protection
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-Xss-Protection
Alt-Svc
X-UA-Compatible
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Request-ID
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
P3p
X-Content-Security-Policy
X-Iinfo
Status
X-Ua-Compatible
Feature-Policy
Content-Encoding
X-AspNetMvc-Version
X-CDN
X-Envoy-Upstream-Service-Time
Upgrade
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Access-Control-Max-Age
X-Via
Keep-Alive
X-Dns-Prefetch-Control
X-Ws-Request-Id
Server-Timing
X-Robots-Tag
Request-Context
X-AH-Environment
X-Hacker
X-Server
X-Age
X-Turbo-Charged-By
X-Proxy-Cache
X-Server-Powered-By
X-Cache-Group
X-Backend
X-Amz-Request-Id
Host-Header
X-Amz-Id-2
EagleId
X-Nginx-Cache-Status
Report-To
X-Rq
X-LiteSpeed-Cache
X-Varnish-Cache
X-UA-Device
X-Page-Speed
Grace
X-Pingback
X-Swift-CacheTime
X-Swift-SaveTime
EagleEye-TraceId
X-Device
Ali-Swift-Global-Savetime
X-Vhost
X-OneAgent-JS-Injection
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Amz-Version-Id
NEL
Cf-Railgun
X-Dispatcher
X-Host
X-Server-Id
X-Cache-Spec
X-CST
X-Node
Allow
X-Backend-Server
Request-Id
Surrogate-Control
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-WebKit-CSP
X-Readtime
Accept-CH
X-Akam-SW-Version
X-Response-Time
X-Webkit-CSP
Xkey
X-Ruxit-JS-Agent
X-HW
X-Language
X-Country
Accept-Ch-Lifetime
X-Application-Context
X-Ac
X-Template
Content-Location
X-Cache-Lookup
MS-Author-Via
X-Cloud-Trace-Context
Rating
X-Url
X-B3-TraceId
Edge-Control
X-Mod-Pagespeed
X-TtlSet
X-Vname
X-PC
X-Clacks-Overhead
X-ESI
X-Trace
X-MS-InvokeApp
X-Varnish-TTL
X-Content-Type
Fastly-Restarts
Accept-CH-Lifetime
X-Rack-Cache
X-GitHub-Request-Id
X-Origin-Cache
X-Cnection
Accept-Ch
X-FastCGI-Cache
X-Country-Code
X-Buckets
X-Cdn-Fetch
X-Exp-Id
X-Kinja-Revision
X-Use-Magma
X-Kinja-Build
X-Kinja
X-Goog-Hash
X-GoogleNews-Bot
X-Exp-Variant
X-Kinja-Server
Verso
X-VARITI-CCR
X-D2id
Arr-Disable-Session-Affinity
X-Vcap-Request-Id
X-ORACLE-DMS-ECID
X-Cached
Cache-Tag
X-Server-Name
X-Abt-Application-Version
X-Amz-Rid
Service-Worker-Allowed
X-Client-IP
X-Server-ID
X-Navigation-Version
X-Powered-By-Plesk
RTSS
X-Px
X-Fastly-Request-ID
Access-Control-Request-Method
Public-Key-Pins
X-Powered-CMS
X-Element-Page-Cache
X-MSEdge-Ref
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Upstream
X-Dw-Request-Base-Id
X-Version
X-NF-Request-ID
Response
Display
Pagespeed
X-Cache-TTL
X-Middleton-Display
X-Middleton-Response
X-Sol
S
X-Ttl
X-Edge
X-TTL
X-Kinsta-Cache
X-Edge-Location-Klb
X-LLID
X-B3-TraceId-Primal
Mrf-Cache-Status
Realpath
MRF-Tech
X-Accel-Expires
X-Server-Lifecycle-Phase
X-Kraken-Routeconfig-Destination
X-Kraken-Loop-Name
X-Instrumentation
SPRequestGuid
X-HP-Webp
X-SharePointHealthScore
X-Jurisdiction
SPRequestDuration
SPIisLatency
X-Correlation-Id
X-ECACHE
X-Shield-Request-Id
X-MCACHE
X-T
X-Mid
X-PressLabs-Stats
Pinterest-Version
X-Content-Security-Policy-Report-Only
X-Pinterest-Rid
X-Litespeed-Cache
Pinterest-Generated-By
X-Cache-Key
Edge-Cache-Tag
X-ORACLE-DMS-RID
X-Forwarded-Proto
X-DynaTrace
Fastcgi-Cache
X-XRDS-Location
X-Amz-Server-Side-Encryption
X-Mg-S
X-Content-Digest
TP-L2-Cache
X-Recruiting
TP-Cache
Nginx-Cache
Charset
Filters
Front-End-Https
X-Id
TCN
X-Request-Received
X-Request-Processing-Time
Alternate-Protocol
Server-Node
X-Forwarded-For
X-Logged-In
X-Ezoic-Cdn
Content-MD5
Cache-Tags
X-Geo-Country
Fusion-Content-Source
Fusion-Component-Id
Fusion-Content-Id
Fusion-Source
Fusion-Deployment-Id
Fusion-Template-Id
X-ASPNET-VERSION
X-Protected-By
X-Hostname
X-Amzn-Trace-Id
X-Origin-Upstream-Status
X-Release
X-Grace
X-Origin-Server
X-Goog-Stored-Content-Length
X-Goog-Generation
X-GUploader-UploadID
X-Goog-Storage-Class
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Www-Served-By
X-F-Cache
X-Amz-Replication-Status
X-Oneagent-Js-Injection
Cleartype
X-Rid
X-NWS-LOG-UUID
X-HS-Cache-Config
X-Debug-Info
X-HS-Content-Id
Host
X-HS-Hub-Id
X-HS-Combine-CSS
X-LB-Cache
X-Contextid
X-Az
X-Activity-Id
X-AppVersion
Server-Name
Section-Io-Cache
X-RateLimit-Remaining
X-Frontend
X-Erf-Bev-Bev-Is-Generated
X-Page-Id
X-Erf-Bev-Bev
X-Browser-Type
X-Git-Hash
X-Daa-Tunnel
MicrosoftSharePointTeamServices
X-Ser
X-Respond-Thread
X-VCache
X-Aspnetmvc-Version
X-Cache-Age
X-Content-Options
X-Ruxit-Js-Agent
X-WebKit-CSP-Report-Only
Accept-Charset
Access-Control-Allow-Method
X-Upgrade-Enabled
X-Hits
X-Ab
X-Mobile-URL
X-Source
X-DIS-Request-ID
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-B-Cache
X-Providence-Cookie
X-Is-Crawler
X-Flags
X-Request-Guid
X-Route-Name
X-Aspnet-Duration-Ms
X-Signature
X-CACHE-GROUP
ServerID
X-Varnish-Age
X-Whom
X-Varnish-Grace
Payment
Healthy
X-Varnish-Backend
X-Cache-Action
X-FB-Debug
X-TT
Viewport
Paypal-Debug-Id
X-App-Environment
Node
X-AOL-HN
X-B3-Sampled
Fastcgi-Useragent
DynaTrace
Version
X-Seen-By
X-Load-Cache
X-N
X-Yandex-Sdch-Disable
X-Mobile
DC
X-XRDS-LOCATION
X-Type
X-Tt-Trace-Host
X-HTML-Minification-Powered-By
X-Tt-Trace-Tag
Filterid
X-Distributor
X-Tec-Api-Root
X-Tec-Api-Version
X-Tec-Api-Origin
X-Fastcgi-Cache
Frame-Options
X-Cache-Control
Retry-After
X-User-Agent
MS-CV
SRV
X-Cache-Expired-At
X-Jobs
X-IPLB-Instance
X-Response-Served-From
AR-ATIME
X-Original-Request-Id
AR-Request-ID
AR-CACHE
Ar-Sid
AR-PoweredBy
Refresh
X-UUID
NGB
X-Page-View
X-Adobe-Content
X-Proxy-Cache-Status
X-Adobe-Loc
X-Real-IP
Access-Control-Request-Headers
X-Instance
X-Debug-IsConnected
X-Device-Type
X-Debug-IsPreview
X-Region
X-Varnish-Server
X-Cluster-Name
X-B
X-Cacheable-TTL
X-Cache-Time
VIX-Pulpo-Upstream-Status
X-Content-Powered-By
VIX-Pulpo-Node
X-G
X-Tumblr-Pixel
X-RemovedCookies
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Proxy
X-ProcessESI
X-Tumblr-User
X-Framework
X-IPS-LoggedIn
X-FW-Hash
X-FW-Dynamic
Ms-Operation-Id
X-FW-Static
X-FW-Type
X-FW-Serve
X-FW-Server
Uber-Trace-Id
X-RTag
X-Microsite
X-Vgn-Hpd-Reason
X-Request-Handler-Origin-Region
X-NGENIX-Cache
Amp-Access-Control-Allow-Source-Origin
X-Zen-Fury
X-Azure-Ref
X-CDN-Forward
Countrycode
X-Wix-Request-Id
X-Node-Name
Cache-Status
X-Cache-Rule
X-Time
X-Cache-Hit
Section-Io-Origin-Time-Seconds
Section-Io-Id
X-Mg-Request-UUID
Section-Origin-Responded
Section-Io-Origin-Status
X-Oracle-Dms-Rid
X-Ms-Request-Id
X-Debug
X-Is-Bot
X-Ms-Version
X-Rendered-As
X-Accel-Buffering
SD-X-WS
X-Nginx-Cache
Referer-Policy
Liferay-Portal
X-RateLimit-Limit
X-Drupal-Cache-Tags
X-Aws-Lambda-Call-Status
X-App-Version
Cache
S-Cnection
X-EdgeConnect-Cache-Status
Country
CF-IPCountry
X-FireWall-Port
X-App-Server
X-L-Path
X-Environment-Context
X-HP-Trace-Id
X-Revision
Surrogate-Key
X-Cache-Operation
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Parallel-Accel
Eomportal-Instance
X-UPSTREAM-Address
X-Endurance-Cache-Level
X-ES-SERVER
X-RN-RSRV
X-SaId
X-GG-Cache-Date
X-Timing-Wait
Meta-Geo
X-Proxy-Build
X-JoinUs
X-TA-CDN-Provider
X-TNCMS
Selected-Fe
X-Loop
X-Cache-TTL-Remaining
X-Say-Cacheable
X-Say-TTL
Count-Hit
X-Drupal-Cache-Contexts
From-Origin
X-Alternate-Cache-Key
X-Request-Time
X-Adobe-Source
X-Cache-Type
X-SayCDN-TTL
X-ShopId
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Shopify-Stage
X-Storefront-Renderer-Rendered
X-Varnishpool
X-Xfnlog-Site
X-ShardId
X-LAGOON
X-LJ-Flow-ID
X-Human
X-Sql-Count
Protected
Country-Code
X-Sql-Duration-Ms
X-Origin-Date
X-ProxyCache-Key
X-AWS-Id
X-ProxyCache-Status
X-No-Session
X-NYM-Debug-Backend
X-Backend-Host
X-PHP-Backend
X-Varnish-Hostname
Azure-RegionName
X-S-Maxage
Azure-SiteName
X-Proto
X-VWS-Id
X-Varnish-Beresp-Grace
X-BYPASS-REASON
X-Be
Cache-Name
Azure-SlotName
Azure-InstanceId
Azure-Version
TWC-Connection-Speed
Decoy-Debug-TTL
Decoy-Debug-Status
Property-Id
Fastly-SSL
ServedBy
X-Labrador-Cache-Channel
X-PCL
X-UA-Device-Type
X-Status
X-Origin-Hint
Decoy-Debug-Key
X-Server-W
X-Pubstack
X-R9-Blue-Green-Version
X-RCS-CacheZone
X-PHP-Host
X-OCL
X-Hosted-By
TWC-Privacy
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-GeoIP-Country
Webcakes-App-Name
Webcakes-App-Version
X-Handled-By
X-FB-TRIP-ID
X-Cache-Server
Webcakes-Region
TWC-Device-Class
X-Akamai-Edgescape
Akamai-GRN
Apigw-Requestid
GEO-INFO
Cache-Tv-Group
X-Tumblr-Pixel-2
X-Redis-Cache
X-Section
X-Format
X-Backend-Name
X-Access
X-Via-Fastly
X-Uri
Mn-Server-Ip
X-Web-Node
X-Hl-Ver
X-FW-Version
X-Hyper-Cache
Nel
X-PERF
X-ApacheServer
X-Cluster-Node
X-Ua-Device
X-ServerID
X-Time-Microsecs
X-ATG-Version
Xserver
X-Cache-PHP
X-B3-SpanId
X-TT-LOGID
X-TEC-API-VERSION
X-Servername
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-APP-VERSION
OT-Force-Account-Verify
X-Trace-Id
X-CSRF-Token
X-Content-Age
X-Tumblr-Pixel-3
X-Datadome
Cross-Origin-Opener-Policy
X-WA-Info
X-Azure-Ref-OriginShield
X-Detected-As
Backend
X-MP-GENERATED-AT
Web-Mar-Node
X-Rule
X-Cache-Host
X-Varnish-Cache-Hits
X-Generation-Time
X-Cache-Ttl
X-Cache-Enabled
X-Varnish-Hits
X-Cached-By
X-Soup
X-SRV
X-Akamai-Transformed
X-Bc-Bl
Cross-Origin-Window-Policy
X-Edge-Location
Ec-Rule-Version
X-Ua
Content-Secure-Policy
X-CS
X-Mode
X-Info
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Amzn-Remapped-Content-Length
X-Via-JSL
S-Rt
X-Varnish-Beresp-Status
X-Microcachable
X-Cache-Grace
X-NWS-UUID-VERIFY
X-Magnolia-Registration
X-B3-Traceid
X-Cache-NGX
Url
Source
AMP-Access-Control-Allow-Source-Origin
X-Debug-Cache
X-GEO
X-Storage
X-Origin-TTL
SID
X-Locale
X-Dc
X-Air-Source
X-Air-Hostname
X-Forwarded-Host
Upgrade-Insecure-Requests
X-Air-Trace-Id
X-Ratelimit-Limit
X-Origin-CC
X-Proxied
X-Varnish-Beresp-Ttl
X-Tb
X-Platform
X-Extlb
X-Zipkin-Id
X-Routing-Service
X-Epic-Correlation-Id
CDN-Cache
X-CF-Lambda-Fn
X-Application
BehaviorPad-Version
X-External-Request-Id
Apple-News-Services-Handled
X-AIR-PT
X-Cache-NE
A
X-A-Dam
X-A-Wwc
X-Cache-Bucket
X-Clientip
X-Aed
X-Aicache-OS
X-Connection-Hash
X-A-Dgt
X-D
Apple-News-Services-Request-Url
X-BCube-Filmed-By
CDCHOST
X-B-Cookie
X-Site-Version
X-CF-Lambda-Version
X-Developer
Apple-News-Services-Parsed-Url
X-A-Dcw
X-Destination
X-ARC
DCR-Decision-By
MD5-Digest
X-S-Cookie
X-ScT
Expiry
X-Shop-Environment
X-Session-Fingerprint
X-S
X-Rojux
X-Request-URI
Rendered-Blocks
CDN-CachedAt
X-Rewrite-Enabled
M-TraceId
X-Vtex-Remote-Cache
Fastcgi-X-Cache-Version
Meta-Geo-Continent
Odigeo-Trace-Id
X-Vdms-Version
Mobile-Detection-Method
X-VG-WebCache
Fastly-SWR
Fastly-SIE
X-SRCache-Key
X-Unique-Id
Path
X-Vtex-Processado-Em
X-Tenant
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-A-Ccd
CDN-Uid
X-A
Host-ID
T-Server
CDN-RequestId
X-GoCache-CacheStatus
CDN-PullZone
CDN-EdgeStorageId
X-Forwarded-Path
CDN-RequestCountryCode
X-From
X-VG-WebServer
Surrogated-Key
X-Platform-Server
X-PBS-Appsvrname
X-Processor
DCR-Processing-Time-Ms
X-Ratelimit-Reset
X-PAYTM-SRV-ID
Apple-News-Services-Host
X-NAPM-TraceId
X-NU-AKA-ACS-Version
State
X-Orig-Expires
Req-Svc-Chain
User-Cache-Control
Platform
PB-RID
UCS
X-Accel-Expires-Debug
PB-PID
Origin
NGX
X-Has-Esi
X-Rocket-Build-Number
X-Service
X-Sigma
X-Sigma-Backend
X-Request-UUID
X-Request-Host
X-Loc
X-Men
X-Origin-Expires
X-Proxy-Upstream
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-VServer
X-WADP-Cache
X-Conf
X-Ftr-Request-Id
X-VG-TLSProxy
X-Variation
X-Thanos
X-TrackingId
X-Var-Ttl
X-LI-UUID
X-Li-Pop
X-Cms-Context
X-Core-Value
X-Date
X-Device-Os
X-Clara-WADP
X-Cache-Tags
X-Branch-Name
X-Cache-Debug
X-Cache-Info
X-DPWN-IS-SECURE
X-Envoy-Decorator-Operation
X-Hash
X-Is-Gdpr
X-JWT-State
X-Li-Fabric
L
X-Forwarded-Site
X-Fastly-Backend
X-Fastly-Cache
X-Fmm-Version
X-Backend-State
X-Bip
Cmstype
C-Via
Cache-Host
Cache-Key
Content-Disposition
Fastly-Drupal-HTML
DSUID
Esi-Enabled
Fastly-Backend-Name
Adler-Geo
Cmsid
Arc-Version
X-Varnish-Ttl
Is-Eu
X-Amz-Meta-S3cmd-Attrs
X-Ratelimit-Remaining
Server-Info
X-Level-Front-Cache
X-EC-Lua
X-Gamma-Serve
X-Old-Content-Length
Wxu-Next-Hostname
X-Viewer-Country
X-Nginx-Cache-Key
Wxu-Next-Region
X-Generated-By
Cf-Device-Type
X-Generated-In
X-Thinkindot-L3
X-Gen-Mode
X-Generated-On
CacheControlHeader
X-Block-Status
X-SIPLIST1
X-RateLimit-Remaining-Second
X-DefElseHash
IsBot
X-Csrf-Jwt
X-Req
X-DefHash
X-RateLimit-Limit-Second
X-Eu-Site
X-Policy
X-Developers
X-FC-Vary-Parameters
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-Cache-Id
X-DC
Wxu-Next-Commit
X-Via-NSCOPI
X-Slack-Backend
X-BBC-Edge-Cache-Status
X-Served-From
X-Fetched-On
X-Cluster
X-Scheme
X-CGP
X-Origin
Vix-Hermes-Req-Id
X-HN
NM-Fastcgi-Cache
X-VC-Cache
X-Vdms-Path
X-Hnp-Log
X-VarnishDD-TTL
X-Mvc-Supplant-Cachable
We-Hiring
PFcat
Fastcgi-Cache-TTL
Pagetype
Gh-Request-Id
X-Micro-Cache
Locid
Location
L5d-Success-Class
Kp-EeAlive
HA-Ipaddr
X-Irp-Debug
Memcached
Ha-Gx-Prefs
Mail-Subject
X-Location
X-Varnish-Remaining-TTL
Pics-Label
Thinkindot-Control
X-GeoIP-City
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
TDXMobile
True-Client-Country-4JS
X-GeoIP
VNS-Cache
VNS-Age
X-Esi-Check
X-Geo-Header
X-Varnish-CookieINHashed-On
CPC-Age
Server-Ext
X-Varnish-CookieHashed-On
CPC-Cache
Release
Server-Hostname
Server-Host
X-Gzip
Sever-Int
NtCoent-Length
X-Ckpd-Fst-Backend
X-Planisys-CDN-Cache
X-Owner
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Sucuri-ID
X-DataDome
Webserver
X-Skip-Cache
AKAMAI
V-Age
X-Unique-ID
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
Arc-Country
Svr
Who
DataCenter
X-Mvc-Supplant-OutputCached
X-Worker
X-Qloud-Router
X-HS-Content-Campaign-Id
X-User
X-Via-Poph
X-Via-Popn
Cache-Hits
X-Via-Popv
X-NC
X-V-Cache
X-PF-Uncompressing
X-Auto-Login
X-CACHE-KEY
MIME-Version
X-Servedbyhost
X-NCache
X-Minions-Version
X-Varnish-Url
X-Zone
X-Tx-Id
X-Qnm-Cache
X-Srv
XServer
X-M-Reqid
X-M-Log
X-Vc
X-LSADC-Cache
X-Platform-Router
X-Platform-Processor
X-Render-Time
X-Rocket-Nginx-Serving-Static
X-Platform-Cluster
X-ID
My-App
Powered-By-ChinaCache
X-SD-PageType
X-Traceid
X-LB-ID
X-Refresh
X-Cache-Remote
WebServer
X-Ua-Browser
Environment
X-Content
X-Datadog-Parent-Id
X-Newrelic-Synthetics
X-Internal-Host
Time
Memory
X-ZONE
X-Wa
X-Datadog-Sampling-Priority
X-Datadog-Trace-Id
X-TX-ID
Server-ID
X-Gdpr
X-API-Version
X-BBC-Origin-Response-Status
X-Nyt-Route
X-Webkit-Csp
X-Origin-Time
X-PJAX-URL
X-TIME
X-App
X-Pass-Why
X-NodeID
X-Cache-Var
X-Cache-Var-Map
X-Via-Ucdn
X-VCL-Version
X-Server-IP
Cluster
X-Cache-Config
X-Pod-Name
Candidate-Md5Url
X-Dynatrace
X-OVcl-Cache
X-OVcl
Hostname
X-NewRelic-App-Data
Datacenter
X-CLOUD-TRACE-CONTEXT
Geoip-Latitude
GeoIp-Country-Code
HostName
X-TraceId
Cf-Bgj
X-Webkit-CSP-Report-Only
X-Backend-TTL
X-Edge-Pop
Geo-Info
Magicmarker
X-LI-Proto
N-Cache
X-ElasticPress-Query
Resin-Trace
X-Tb-Optimization-Total-Bytes-Saved
X-VHOST
Web-Mar-Region
Ohc-File-Size
Tcn
X-HITS
X-Dispatcher-Server
X-Method
X-Origin-Response-Time
X-CACHE-AGE
DB-Nickname
X-Varnish-Beresp-TTL
Onion-Location
X-Li-Proto
X-Geo
X-Akamai-Pragma-Client-IP
X-MSEdge-Flight
X-MSEdge-Features
GeoIP-Country-Code
GeoIP-Latitude
X-NODE
WWW-Authenticate
X-EIG-Tracking-Id
Ssr
X-IP
Servername
X-Varnish-Cacheable
X-Correlation-ID
X-AB
X-Wix-Viewer-Type
Proxy-Connection
X-HostName
Cdn
X-Fastly-Request-Id
LB
X-Vcl-Version
X-Cs
X-Node-Id
CDN
CF-Cached-On
X-DynaTrace-JS-Agent
Cf-Ipcountry
Redirect-Candidate
X-Tid
X-APP
X-Fpc
X-TIM-N
X-Dynatrace-Js-Agent
Lb
Server-Id
X-HS-Status
X-ND-Cache
X-Trv-Group
Sid
X-Up
Tracecode
WZWS-RAY
Env
X-Pjax-Url
X-Via-CDN
X-Request-Start
X-WA
X-Fastly-Backend-Reqs
X-MG-S
X-Webkit-Csp-Report-Only
URI
X-ServerName
Cteonnt-Length
Pramga
Is-Us
X-NGINX-Cache
X-Cache-Date
X-Nc
X-Sn-Servicetimems
X-Cdn-Origin
X-VC
X-Tt-Logid
X-Lb-Id
X-Check-Cacheable
X-Reqid
X-Amz-Meta-Cb-Modifiedtime
Ohc-Cache-HIT
X-Esi
X-CSRF-TOKEN
X-Provided-By
Mime-Version
Rt-Fastcgi-Cache
X-ServedByHost
Viewtype
X-Cache-Backend
W
X-Core-Mission
VivaBuild
X-SERVER-NAME
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-Via-PopN
X-Via-PopH
X-Via-PopV
X-UnsetCookies
X-ECache
Shield-Pop
X-LiteSpeed-Cache-Control
X-Cache-Expires
X-SN
Server-Ttl
CountryCode
CloudFront-Viewer-Country
X-Cdn-Forward
X-Contensis-Viewer-Groups
X-Varnish-Authentication
X-Fastly-Cache-Hits
X-Pf-Uncompressing
X-Cache-ASPX
X-Acquia-Purge-Tags
X-Acquia-Application-Trace
CACHE
WP-Super-Cache
X-Acquia-Application-UUID
Machine
X-RAMCache
X-Acquia-Site
X-FORWARDED-FOR
X-Pad
Srv
X-Region-Sid
X-Hcs-Proxy-Type
Xet-Cookie
X-StackifyID
X-Yottaa-OS
X-Sucuri-Cache
X-CUA
X-CCDN-Origin-Time
X-Cdn-Request-ID
X-FTR-Request-ID
X-Edge-POP
X-Cache-Status-Check
X-CCDN-CacheTTL
X-RSL
X-RPM
X-Action
X-DB
X-Webstats-RespID
Vha6-Origin
Ohc-Response-Time
ServerName
X-SB
X-DI
X-RPS
X-DSS
X-Swift-Error
X-Dw-Trace-Id
X-DW
X-B3-Spanid
X-C
X-FTR-Backend
X-MiniProfiler-Ids
PICS-Label
X-Moov-Xdn-Version
Xc-Version
X-Moov-T
X-FPC
X-FTR-Backend-Server
X-CF-Powered-By
X-Country-Code-Real
Content-Style-Type
X-ElasticPress-Search
FSS-Cache
On-Server
X-Oss-Storage-Class
X-Oss-Server-Time
X-Oss-Object-Type
X-Oss-Request-Id
X-TH-Server
X-FTR-Realm
X-FTR-Cache-Status
X-FTR-Balancer
X-FTR-DC
X-FTR-Expires
Content-Script-Type
X-Oss-Hash-Crc64ecma
Req-ID