Threat Level: green Handler on Duty: Bojan Zdrnja

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-RAY
CF-Cache-Status
Accept-Ranges
Link
ETag
Pragma
Expect-CT
X-Powered-By
X-XSS-Protection
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
Alt-Svc
X-Xss-Protection
X-UA-Compatible
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Request-ID
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
X-Ua-Compatible
P3p
X-Content-Security-Policy
X-Iinfo
X-FRAME-OPTIONS
Status
Content-Encoding
Feature-Policy
X-AspNetMvc-Version
X-CDN
X-Envoy-Upstream-Service-Time
Upgrade
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Access-Control-Max-Age
X-Via
Keep-Alive
X-Ws-Request-Id
X-Dns-Prefetch-Control
Request-Context
X-Robots-Tag
Server-Timing
X-AH-Environment
X-Server
X-Hacker
X-Age
X-Turbo-Charged-By
X-Proxy-Cache
X-Server-Powered-By
X-Cache-Group
X-Backend
X-Amz-Request-Id
Host-Header
EagleId
X-Amz-Id-2
X-Nginx-Cache-Status
Report-To
X-LiteSpeed-Cache
X-Rq
X-Varnish-Cache
X-UA-Device
X-Page-Speed
Grace
X-Pingback
X-Swift-SaveTime
X-Swift-CacheTime
X-Device
Ali-Swift-Global-Savetime
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Vhost
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
NEL
X-Amz-Version-Id
Cf-Railgun
X-Dispatcher
X-Host
X-CST
X-Cache-Spec
X-Server-Id
X-Node
Allow
X-Backend-Server
Request-Id
Surrogate-Control
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-WebKit-CSP
X-Readtime
X-Akam-SW-Version
X-Response-Time
X-Webkit-CSP
Accept-CH
Accept-Ch-Lifetime
Xkey
X-HW
X-Ruxit-JS-Agent
X-Language
X-Country
X-Application-Context
X-Ac
Content-Location
X-Template
MS-Author-Via
X-Cache-Lookup
Rating
X-Cloud-Trace-Context
X-Url
X-B3-TraceId
Accept-Ch
Edge-Control
X-Mod-Pagespeed
X-PC
X-TtlSet
X-Vname
X-Clacks-Overhead
X-Varnish-TTL
X-ESI
X-MS-InvokeApp
X-Trace
X-Content-Type
Fastly-Restarts
X-GitHub-Request-Id
X-Rack-Cache
X-Origin-Cache
X-Cnection
X-FastCGI-Cache
X-Kinja-Revision
X-Exp-Id
X-Cdn-Fetch
X-Country-Code
X-Exp-Variant
X-GoogleNews-Bot
X-Kinja-Server
X-Kinja-Build
X-Kinja
X-Use-Magma
X-Buckets
Verso
X-D2id
X-VARITI-CCR
X-Goog-Hash
Arr-Disable-Session-Affinity
X-Server-ID
Accept-CH-Lifetime
X-Vcap-Request-Id
X-Cached
Cache-Tag
X-ORACLE-DMS-ECID
X-Abt-Application-Version
X-Server-Name
X-Amz-Rid
X-Client-IP
Service-Worker-Allowed
X-Navigation-Version
X-Powered-By-Plesk
RTSS
Access-Control-Request-Method
X-Fastly-Request-ID
X-Px
X-Powered-CMS
Public-Key-Pins
X-TTL
X-Element-Page-Cache
X-MSEdge-Ref
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Upstream
X-Middleton-Response
X-Dw-Request-Base-Id
X-Cache-TTL
X-Sol
Pagespeed
Response
X-Middleton-Display
Display
X-NF-Request-ID
X-Version
S
X-Edge
X-Kinsta-Cache
X-Edge-Location-Klb
X-LLID
Realpath
X-B3-TraceId-Primal
Mrf-Cache-Status
X-ECACHE
MRF-Tech
X-Accel-Expires
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Kraken-Routeconfig-Destination
X-Instrumentation
X-SharePointHealthScore
SPRequestGuid
X-HP-Webp
X-Jurisdiction
SPIisLatency
SPRequestDuration
X-Ttl
X-Mid
X-MCACHE
X-T
X-Shield-Request-Id
X-Content-Security-Policy-Report-Only
X-PressLabs-Stats
X-Cache-Key
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-Correlation-Id
X-ORACLE-DMS-RID
X-Forwarded-Proto
Edge-Cache-Tag
X-Litespeed-Cache
X-DynaTrace
Fastcgi-Cache
X-Amz-Server-Side-Encryption
X-Recruiting
X-Mg-S
Charset
TP-Cache
X-Content-Digest
TP-L2-Cache
X-XRDS-Location
Nginx-Cache
X-Id
Filters
Front-End-Https
X-Request-Received
X-Request-Processing-Time
Alternate-Protocol
Server-Node
X-Logged-In
X-Forwarded-For
X-Ezoic-Cdn
TCN
Cache-Tags
Content-MD5
X-Geo-Country
Fusion-Content-Id
Fusion-Deployment-Id
Fusion-Source
Fusion-Template-Id
Fusion-Component-Id
Fusion-Content-Source
X-Release
X-Protected-By
X-Amzn-Trace-Id
X-Origin-Upstream-Status
X-ASPNET-VERSION
X-Grace
X-Origin-Server
X-Hostname
X-F-Cache
X-Www-Served-By
Cleartype
X-Amz-Replication-Status
X-Rid
X-Ruxit-Js-Agent
Host
X-GUploader-UploadID
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Cache-Config
X-NWS-LOG-UUID
X-LB-Cache
X-HS-Combine-CSS
X-Activity-Id
X-Contextid
X-AppVersion
X-Az
X-Debug-Info
Server-Name
X-Oneagent-Js-Injection
Section-Io-Cache
X-RateLimit-Remaining
X-Frontend
X-Page-Id
X-Erf-Bev-Bev
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
MicrosoftSharePointTeamServices
X-Git-Hash
X-Daa-Tunnel
X-VCache
X-Ser
X-Cache-Age
X-Respond-Thread
X-Content-Options
Access-Control-Allow-Method
Accept-Charset
X-Aspnetmvc-Version
X-Hits
X-Upgrade-Enabled
X-WebKit-CSP-Report-Only
X-Mobile-URL
X-DIS-Request-ID
X-Source
X-Signature
ServerID
X-B-Cache
X-Kong-Proxy-Latency
X-Varnish-Backend
X-Kong-Upstream-Latency
Payment
X-Flags
X-Aspnet-Duration-Ms
X-Is-Crawler
X-Providence-Cookie
X-Route-Name
X-Request-Guid
Healthy
X-Varnish-Grace
Viewport
X-Whom
X-Varnish-Age
X-FB-Debug
X-TT
X-Ab
Paypal-Debug-Id
X-Cache-Action
X-B3-Sampled
Node
X-CACHE-GROUP
X-AOL-HN
X-App-Environment
Fastcgi-Useragent
Version
DynaTrace
X-Seen-By
X-Load-Cache
X-Yandex-Sdch-Disable
X-N
X-Mobile
DC
X-Type
X-HTML-Minification-Powered-By
X-Distributor
X-Tt-Trace-Host
X-Tec-Api-Root
X-Tt-Trace-Tag
X-Tec-Api-Origin
X-Tec-Api-Version
SRV
X-XRDS-LOCATION
Filterid
MS-CV
Frame-Options
X-Cache-Control
Retry-After
X-User-Agent
AR-Request-ID
AR-CACHE
AR-ATIME
Ar-Sid
AR-PoweredBy
X-Fastcgi-Cache
X-Cache-Expired-At
X-Jobs
X-IPLB-Instance
X-Original-Request-Id
X-Response-Served-From
Refresh
X-Real-IP
X-Proxy-Cache-Status
X-Adobe-Content
X-Adobe-Loc
X-Debug-IsPreview
X-Page-View
Access-Control-Request-Headers
X-Varnish-Server
X-Device-Type
X-Region
X-Cluster-Name
X-Instance
X-UUID
X-Debug-IsConnected
X-Tumblr-Pixel
Uber-Trace-Id
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Tumblr-User
X-B
X-Cache-Time
X-Cacheable-TTL
NGB
X-Content-Powered-By
X-G
X-RemovedCookies
X-Microsite
VIX-Pulpo-Node
X-Request-Handler-Origin-Region
VIX-Pulpo-Upstream-Status
X-ProcessESI
X-Framework
X-IPS-LoggedIn
X-RTag
X-Proxy
Ms-Operation-Id
X-CDN-Forward
X-FW-Hash
X-FW-Serve
X-FW-Server
X-FW-Type
X-FW-Static
X-FW-Dynamic
X-Vgn-Hpd-Reason
X-NGENIX-Cache
X-Zen-Fury
X-Azure-Ref
Countrycode
Amp-Access-Control-Allow-Source-Origin
X-Time
X-Wix-Request-Id
X-Node-Name
Cache-Status
X-App-Version
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
Section-Io-Origin-Status
X-Debug
Section-Io-Id
X-Mg-Request-UUID
X-Cache-Rule
X-Accel-Buffering
X-Cache-Hit
X-Rendered-As
X-Ms-Request-Id
X-Is-Bot
X-Ms-Version
Cache
Liferay-Portal
X-RateLimit-Limit
X-Nginx-Cache
SD-X-WS
Referer-Policy
X-Oracle-Dms-Rid
X-Drupal-Cache-Tags
S-Cnection
X-FireWall-Port
X-Aws-Lambda-Call-Status
X-App-Server
X-EdgeConnect-Cache-Status
Country
Surrogate-Key
X-L-Path
X-Environment-Context
X-Yottaa-Optimizations
CF-IPCountry
X-Yottaa-Metrics
X-HP-Trace-Id
X-Cache-Operation
X-Revision
Eomportal-Instance
X-Parallel-Accel
X-Endurance-Cache-Level
Meta-Geo
Selected-Fe
X-ES-SERVER
X-Proxy-Build
X-JoinUs
X-TNCMS
X-Timing-Wait
X-SaId
X-Loop
X-UPSTREAM-Address
X-RN-RSRV
X-Drupal-Cache-Contexts
X-Alternate-Cache-Key
X-Cache-TTL-Remaining
From-Origin
X-Adobe-Source
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Storefront-Renderer-Rendered
X-Varnishpool
X-TA-CDN-Provider
X-Shopify-Stage
X-Xfnlog-Site
X-ShardId
X-ShopId
X-NYM-Debug-Backend
X-VWS-Id
Protected
X-No-Session
X-Proto
X-Say-Cacheable
X-LJ-Flow-ID
X-Origin-Date
X-PHP-Backend
X-Say-TTL
X-LAGOON
X-Backend-Host
X-Be
X-SayCDN-TTL
X-Varnish-Beresp-Grace
X-AWS-Id
X-Request-Time
Cache-Name
X-Sql-Count
TWC-Device-Class
TWC-GeoIP-Country
X-Server-W
X-GG-Cache-Date
Property-Id
Apigw-Requestid
Cache-Tv-Group
X-FB-TRIP-ID
Fastly-SSL
X-BYPASS-REASON
TWC-Connection-Speed
ServedBy
X-Handled-By
Country-Code
Webcakes-App-Version
X-Akamai-Edgescape
X-Cache-Server
X-ProxyCache-Status
X-Sql-Duration-Ms
X-Pubstack
X-R9-Blue-Green-Version
X-UA-Device-Type
X-S-Maxage
X-Varnish-Hostname
X-RCS-CacheZone
X-ProxyCache-Key
X-Human
TWC-Privacy
TWC-Locale-Group
TWC-GeoIP-LatLong
Webcakes-App-Name
X-OCL
Webcakes-Region
X-PCL
X-Origin-Hint
X-Backend-Name
X-Hosted-By
X-Access
Decoy-Debug-TTL
X-Labrador-Cache-Channel
X-Cache-Type
Mn-Server-Ip
Azure-SlotName
X-Format
X-Status
Azure-RegionName
Count-Hit
Akamai-GRN
X-Section
X-Tumblr-Pixel-2
X-Via-Fastly
Azure-SiteName
Azure-InstanceId
Decoy-Debug-Key
Decoy-Debug-Status
Azure-Version
X-PHP-Host
X-Hl-Ver
X-FW-Version
X-ApacheServer
X-Hyper-Cache
X-Web-Node
X-PERF
X-Uri
X-Redis-Cache
GEO-INFO
Xserver
X-B3-SpanId
Nel
X-ServerID
X-Time-Microsecs
X-Cache-PHP
X-Cluster-Node
X-ATG-Version
X-Ua-Device
X-Servername
X-TEC-API-VERSION
X-TEC-API-ROOT
X-CSRF-Token
X-TT-LOGID
X-TEC-API-ORIGIN
X-Content-Age
X-Tumblr-Pixel-3
OT-Force-Account-Verify
X-WA-Info
X-Trace-Id
X-Detected-As
X-Azure-Ref-OriginShield
X-Datadome
X-MP-GENERATED-AT
X-Rule
Cross-Origin-Opener-Policy
Backend
X-Generation-Time
X-Cache-Host
X-CS
Web-Mar-Node
X-Varnish-Cache-Hits
X-Cached-By
X-Akamai-Transformed
X-Cache-Enabled
X-Bc-Bl
X-Varnish-Hits
X-Edge-Location
X-APP-VERSION
X-Cache-Ttl
X-Soup
Content-Secure-Policy
Ec-Rule-Version
X-Mode
X-SRV
Cross-Origin-Window-Policy
X-Ua
X-Varnish-Beresp-Status
X-Microcachable
X-Amz-Apigw-Id
X-Amzn-Remapped-Content-Length
X-Via-JSL
AMP-Access-Control-Allow-Source-Origin
X-Amzn-RequestId
X-Info
X-Cache-Grace
X-Cache-NGX
X-Magnolia-Registration
SID
X-Debug-Cache
Url
S-Rt
X-Dc
X-Storage
X-Origin-CC
X-Air-Source
X-Forwarded-Host
X-Air-Hostname
X-Air-Trace-Id
X-Zipkin-Id
X-Locale
X-NWS-UUID-VERIFY
X-Platform
X-Origin-TTL
X-Proxied
X-Routing-Service
X-Varnish-Beresp-Ttl
Source
X-Extlb
X-B3-Traceid
Upgrade-Insecure-Requests
Odigeo-Trace-Id
Fastcgi-X-Cache-Version
Expiry
Fastly-SWR
MD5-Digest
Apple-News-Services-Request-Url
Host-ID
Mobile-Detection-Method
Meta-Geo-Continent
Fastly-SIE
CDN-Uid
CDN-RequestCountryCode
CDN-RequestId
CDN-PullZone
CDN-EdgeStorageId
CDN-CachedAt
CDN-Cache
CDCHOST
A
DCR-Decision-By
DCR-Processing-Time-Ms
BehaviorPad-Version
Apple-News-Services-Host
Apple-News-Services-Handled
Apple-News-Services-Parsed-Url
X-BCube-Filmed-By
X-Rebelmouse-Cache-Control
X-Ratelimit-Reset
X-Rebelmouse-Surrogate-Control
X-Request-URI
X-Rewrite-Enabled
X-Processor
X-Platform-Server
X-NU-AKA-ACS-Version
X-NAPM-TraceId
X-Orig-Expires
X-PAYTM-SRV-ID
X-PBS-Appsvrname
X-Rojux
X-S
X-VG-WebCache
X-Vdms-Version
X-VG-WebServer
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
X-Tenant
X-SRCache-Key
X-S-Cookie
X-ScT
X-Session-Fingerprint
X-Shop-Environment
X-GoCache-CacheStatus
X-From
X-A-Wwc
X-A-Dgt
X-Aed
X-Aicache-OS
X-Application
X-A-Dcw
X-A-Dam
Surrogated-Key
State
T-Server
X-A
X-A-Ccd
X-ARC
X-B-Cookie
X-Destination
X-D
X-Developer
X-External-Request-Id
X-Forwarded-Path
X-Connection-Hash
X-Clientip
X-Cache-Bucket
X-Cache-NE
X-CF-Lambda-Fn
X-CF-Lambda-Version
Rendered-Blocks
M-TraceId
X-Ratelimit-Limit
X-Unique-ID
X-Tb
X-Bip
X-VServer
X-Branch-Name
X-Backend-State
X-Cache-Tags
X-Device-Os
X-Core-Value
X-Cms-Context
X-Cache-Debug
Req-Svc-Chain
Origin
NGX
X-AIR-PT
Is-Eu
Path
PB-PID
X-DPWN-IS-SECURE
Platform
Pics-Label
PB-RID
UCS
X-Epic-Correlation-Id
X-SVT-ORM-RULES
X-Service
X-Request-UUID
X-Proxy-Upstream
X-SVT-ORM-VERSION
X-Thanos
X-Variation
X-Var-Ttl
X-TrackingId
X-VG-TLSProxy
X-Origin-Expires
X-Hash
X-Has-Esi
X-Fastly-Backend
Fastly-Backend-Name
X-Is-Gdpr
X-JWT-State
X-LI-UUID
X-Li-Pop
X-Li-Fabric
X-Envoy-Decorator-Operation
Server-Info
Adler-Geo
DSUID
Arc-Version
Esi-Enabled
C-Via
Content-Disposition
X-Site-Version
Cmsid
Cmstype
User-Cache-Control
X-GEO
Cache-Host
Wxu-Next-Hostname
X-Men
Wxu-Next-Commit
X-Ftr-Request-Id
CacheControlHeader
X-Level-Front-Cache
X-Cluster
Wxu-Next-Region
Vix-Hermes-Req-Id
X-Csrf-Jwt
Thinkindot-CacheControl
TDXMobile
X-FC-Vary-Parameters
X-Developers
Thinkindot-CacheControl-Type
Thinkindot-Control
X-Loc
True-Client-Country-4JS
X-Location
X-Clara-WADP
X-Thinkindot-L3
X-GeoIP-City
X-Ratelimit-Remaining
X-DataDome
X-Conf
X-GeoIP
X-Geo-Header
X-Fastly-Cache
X-Generated-On
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-DefElseHash
X-Varnish-Remaining-TTL
X-Fmm-Version
X-Gamma-Serve
X-CGP
X-Date
X-HN
X-DefHash
X-Amz-Meta-S3cmd-Attrs
X-Generated-In
Server-Hostname
L5d-Success-Class
L
Kp-EeAlive
IsBot
X-Fetched-On
Location
X-Eu-Site
X-Req
X-Forwarded-Site
Locid
X-Accel-Expires-Debug
X-Rocket-Build-Number
X-VHOST
X-Served-From
Fastly-Drupal-HTML
Fastcgi-Cache-TTL
X-Scheme
X-VarnishDD-TTL
HA-Ipaddr
Ha-Gx-Prefs
Gh-Request-Id
X-WADP-Cache
Memcached
X-VC-Cache
X-Cache-Info
X-Sigma-Backend
Release
X-Origin
X-Request-Host
Server-Ext
X-Nginx-Cache-Key
Sever-Int
Server-Host
Cf-Device-Type
X-Sigma
X-Vdms-Path
X-EC-Lua
X-Policy
NM-Fastcgi-Cache
X-SIPLIST1
Pagetype
PFcat
Cache-Key
X-Old-Content-Length
X-Micro-Cache
X-Block-Status
X-Mvc-Supplant-Cachable
X-Hnp-Log
NtCoent-Length
X-Owner
We-Hiring
X-DC
X-Unique-Id
DataCenter
X-Gen-Mode
VNS-Cache
X-Irp-Debug
AKAMAI
X-Gzip
X-Generated-By
VNS-Age
X-Sucuri-ID
X-Esi-Check
X-RateLimit-Remaining-Second
Arc-Country
V-Age
Webserver
X-RateLimit-Limit-Second
X-Slack-Backend
CPC-Cache
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Viewer-Country
X-Via-NSCOPI
CPC-Age
Mail-Subject
Svr
X-Cache-Id
X-Skip-Cache
Who
X-CLOUD-TRACE-CONTEXT
X-User
X-Planisys-CDN-TTL
X-BBC-Edge-Cache-Status
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Qloud-Router
X-Planisys-CDN-Rules
X-Ckpd-Fst-Backend
X-Planisys-CDN-Cache
X-Via-Popn
X-Worker
X-Via-Popv
X-PF-Uncompressing
X-Mvc-Supplant-OutputCached
X-HS-Content-Campaign-Id
Cache-Hits
X-Via-Poph
X-Srv
X-Zone
X-V-Cache
X-Minions-Version
X-Auto-Login
X-Varnish-Url
X-NC
MIME-Version
X-Servedbyhost
X-CACHE-KEY
X-Vc
X-NCache
X-Qnm-Cache
X-M-Reqid
X-Tx-Id
XServer
X-M-Log
X-Platform-Cluster
X-Refresh
X-Platform-Processor
X-Render-Time
X-LB-ID
X-LSADC-Cache
Powered-By-ChinaCache
X-Rocket-Nginx-Serving-Static
My-App
X-Platform-Router
X-ID
X-Internal-Host
Memory
Time
X-Traceid
X-SD-PageType
X-Wa
WebServer
X-Cache-Remote
X-Varnish-Ttl
X-TX-ID
X-Content
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
X-App
Environment
Server-ID
X-Newrelic-Synthetics
X-Pass-Why
X-Datadog-Trace-Id
X-ZONE
X-PJAX-URL
X-Ua-Browser
X-NodeID
X-TIME
X-Nyt-Route
X-Gdpr
X-Webkit-Csp
X-Origin-Time
X-Webkit-CSP-Report-Only
X-API-Version
X-Cache-Var-Map
X-Cache-Var
X-Via-Ucdn
X-BBC-Origin-Response-Status
X-Cache-Config
X-VCL-Version
X-OVcl-Cache
X-OVcl
X-Server-IP
Cluster
Tcn
HostName
X-TraceId
Geo-Info
X-NewRelic-App-Data
Candidate-Md5Url
Hostname
X-Dynatrace
X-Pod-Name
Cf-Bgj
X-Backend-TTL
Datacenter
X-LI-Proto
Geoip-Latitude
GeoIp-Country-Code
Magicmarker
X-Edge-Pop
Resin-Trace
X-ElasticPress-Query
X-Tb-Optimization-Total-Bytes-Saved
N-Cache
X-Correlation-ID
X-Geo
Web-Mar-Region
X-Dispatcher-Server
X-Method
DB-Nickname
Ohc-File-Size
X-HITS
X-CACHE-AGE
X-Origin-Response-Time
Onion-Location
X-Varnish-Beresp-TTL
X-HostName
X-IP
GeoIP-Country-Code
X-Akamai-Pragma-Client-IP
X-Li-Proto
GeoIP-Latitude
Ssr
Proxy-Connection
X-MSEdge-Features
X-NODE
X-Varnish-Cacheable
WWW-Authenticate
Servername
X-MSEdge-Flight
X-AB
Cf-Ipcountry
X-Wix-Viewer-Type
X-EIG-Tracking-Id
X-Node-Id
LB
Cdn
CDN
X-ND-Cache
X-Trv-Group
X-Vcl-Version
X-Fastly-Request-Id
X-DynaTrace-JS-Agent
CF-Cached-On
X-TIM-N
X-Dynatrace-Js-Agent
X-HS-Status
X-Fpc
X-APP
Lb
WZWS-RAY
Redirect-Candidate
X-Tid
X-Via-CDN
X-Cs
X-Nc
Server-Id
X-Up
Sid
Tracecode
X-WA
X-Fastly-Backend-Reqs
Env
X-Request-Start
X-Pjax-Url
X-MG-S
Pramga
Is-Us
X-Webkit-Csp-Report-Only
X-NGINX-Cache
URI
Cteonnt-Length
X-Reqid
X-ServerName
X-Cache-Date
X-Check-Cacheable
X-Tt-Logid
X-Lb-Id
X-VC
X-Amz-Meta-Cb-Modifiedtime
X-Cdn-Origin
X-Sn-Servicetimems
X-URL
Rt-Fastcgi-Cache
X-Esi
X-Xrds-Location
X-CSRF-TOKEN
Ohc-Cache-HIT
X-ServedByHost
W
X-Core-Mission
X-Cache-Backend
VivaBuild
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Provided-By
X-Via-PopH
Viewtype
X-Via-PopV
X-Via-PopN
X-SERVER-NAME
X-UnsetCookies
CountryCode
Shield-Pop
Mime-Version
CloudFront-Viewer-Country
X-FTR-Request-ID
X-LiteSpeed-Cache-Control
Server-Ttl
X-SN
Machine
X-Contensis-Viewer-Groups
X-Cache-Expires
X-Varnish-Authentication
X-Yottaa-OS
X-Acquia-Purge-Tags
X-RAMCache
X-Fastly-Cache-Hits
X-Cache-ASPX
X-Dw-Trace-Id
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-Pf-Uncompressing
CACHE
X-FORWARDED-FOR
X-Acquia-Site
X-Pad
X-Hcs-Proxy-Type
X-Region-Sid
X-StackifyID
X-Sucuri-Cache
X-RSL
X-CCDN-CacheTTL
X-Cdn-Request-ID
Xet-Cookie
X-RPS
X-Edge-POP
X-CCDN-Origin-Time
X-Cache-Status-Check
X-CUA
WP-Super-Cache
X-Country-Code-Real
On-Server
FSS-Cache
X-Swift-Error
X-RPM
X-FTR-Backend-Server
X-FTR-Realm
X-FTR-DC
X-FTR-Cache-Status
X-FTR-Balancer
X-SB
X-FTR-Backend
X-Webstats-RespID
X-DW
X-DSS
X-DI
X-Action
X-DB
Vha6-Origin
Ohc-Response-Time
X-Cdn-Forward
X-Air-Pt
X-Moov-T
Xc-Version
X-Moov-Xdn-Version
X-FTR-Expires
X-C
X-Swa-Ws
X-Snapshot-Date
X-FPC
X-Oss-Object-Type
ServerName
X-ElasticPress-Search
X-TH-Server
X-MiniProfiler-Ids
Content-Script-Type
Content-Style-Type
Req-ID
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma