Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-RAY
CF-Cache-Status
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
X-XSS-Protection
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
Alt-Svc
X-Served-By
X-Xss-Protection
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Permitted-Cross-Domain-Policies
X-Request-ID
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
P3p
X-FRAME-OPTIONS
X-Content-Security-Policy
X-Iinfo
Status
Content-Encoding
Feature-Policy
X-AspNetMvc-Version
X-CDN
X-Envoy-Upstream-Service-Time
Upgrade
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Access-Control-Max-Age
X-Via
Keep-Alive
X-Ws-Request-Id
Request-Context
X-Robots-Tag
Server-Timing
X-AH-Environment
X-Server
X-Ua-Compatible
X-Hacker
X-Age
X-Dns-Prefetch-Control
X-Turbo-Charged-By
X-Server-Powered-By
X-Proxy-Cache
X-Cache-Group
X-Backend
Host-Header
X-Amz-Request-Id
EagleId
X-Nginx-Cache-Status
X-Amz-Id-2
Report-To
X-LiteSpeed-Cache
X-Rq
X-Varnish-Cache
X-Page-Speed
Grace
X-UA-Device
X-Swift-CacheTime
X-Swift-SaveTime
X-Pingback
Ali-Swift-Global-Savetime
X-Device
EagleEye-TraceId
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Vhost
Cf-Railgun
NEL
X-Amz-Version-Id
X-Host
X-Dispatcher
X-Server-Id
X-OneAgent-JS-Injection
X-CST
X-Node
Allow
Surrogate-Control
X-Cache-Spec
Request-Id
X-Backend-Server
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Accept-CH
X-WebKit-CSP
X-Readtime
X-Response-Time
X-Akam-SW-Version
X-Webkit-CSP
Xkey
X-HW
X-Country
X-Ac
Content-Location
X-Application-Context
Accept-Ch-Lifetime
X-Language
MS-Author-Via
X-Template
X-Cloud-Trace-Context
Rating
X-Cache-Lookup
X-Url
X-Ruxit-JS-Agent
X-Mod-Pagespeed
Edge-Control
X-PC
X-TtlSet
X-Vname
X-Clacks-Overhead
X-B3-TraceId
X-ESI
X-MS-InvokeApp
X-Trace
X-Varnish-TTL
Accept-CH-Lifetime
X-GitHub-Request-Id
X-Content-Type
Fastly-Restarts
X-ASPNET-VERSION
X-Origin-Cache
X-Cnection
X-Rack-Cache
X-FastCGI-Cache
X-D2id
X-Kinja-Build
X-Country-Code
X-Cdn-Fetch
X-Exp-Id
X-Exp-Variant
X-GoogleNews-Bot
X-Kinja
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
Verso
X-VARITI-CCR
Arr-Disable-Session-Affinity
X-Goog-Hash
X-Server-Name
X-Vcap-Request-Id
X-Cached
X-Navigation-Version
Cache-Tag
X-Buckets
X-Client-IP
X-Powered-By-Plesk
X-Amz-Rid
X-Abt-Application-Version
Service-Worker-Allowed
Accept-Ch
X-ORACLE-DMS-ECID
RTSS
X-Cache-TTL
X-Fastly-Request-ID
Access-Control-Request-Method
Display
Response
Pagespeed
X-Middleton-Display
X-Middleton-Response
X-Sol
X-MSEdge-Ref
X-Powered-CMS
X-Element-Page-Cache
X-Ttl
X-Oneagent-Js-Injection
X-NF-Request-ID
Public-Key-Pins
X-Dw-Request-Base-Id
X-Upstream
X-SRCache-Store-Status
X-Version
X-SRCache-Fetch-Status
X-Px
X-Edge
S
X-Kinsta-Cache
X-Edge-Location-Klb
X-LLID
X-TTL
Realpath
X-Ruxit-Js-Agent
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Accel-Expires
X-Server-ID
SPIisLatency
SPRequestDuration
SPRequestGuid
X-SharePointHealthScore
X-Jurisdiction
X-T
X-HP-Webp
X-Aspnetmvc-Version
X-MCACHE
X-Mid
X-ECACHE
X-PressLabs-Stats
X-Forwarded-Proto
X-Content-Security-Policy-Report-Only
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Instrumentation
X-Kraken-Routeconfig-Destination
X-Shield-Request-Id
X-Correlation-Id
X-DynaTrace
Edge-Cache-Tag
Charset
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-Recruiting
Fastcgi-Cache
X-Cache-Key
X-Amz-Server-Side-Encryption
TP-L2-Cache
TP-Cache
X-Mg-S
X-Content-Digest
X-Release
X-Ezoic-Cdn
Nginx-Cache
Filters
X-Request-Processing-Time
X-Id
X-Request-Received
X-ORACLE-DMS-RID
TCN
X-Logged-In
Server-Node
Front-End-Https
Alternate-Protocol
Cache-Tags
X-XRDS-Location
X-Forwarded-For
Content-MD5
X-Litespeed-Cache
X-Origin-Upstream-Status
Fusion-Content-Id
Fusion-Template-Id
Fusion-Source
Fusion-Deployment-Id
Fusion-Content-Source
Fusion-Component-Id
X-Amzn-Trace-Id
Server-Name
X-Geo-Country
X-Grace
X-Origin-Server
X-Hostname
X-Protected-By
Cleartype
X-Amz-Replication-Status
X-F-Cache
X-Contextid
X-Www-Served-By
X-Rid
X-Az
X-AppVersion
Host
X-Activity-Id
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Goog-Generation
X-WebKit-CSP-Report-Only
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Combine-CSS
X-RateLimit-Remaining
X-Debug-Info
X-LB-Cache
Section-Io-Cache
X-Frontend
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
MicrosoftSharePointTeamServices
X-NWS-LOG-UUID
X-Ser
X-Git-Hash
X-Page-Id
X-Cache-Age
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
X-Respond-Thread
AR-ATIME
AR-CACHE
X-Upgrade-Enabled
Ar-Sid
AR-Request-ID
AR-PoweredBy
Accept-Charset
X-VCache
X-Varnish-Age
X-Content-Options
X-Source
X-Hits
X-DIS-Request-ID
Paypal-Debug-Id
X-Mobile-URL
X-Daa-Tunnel
X-Varnish-Backend
ServerID
Access-Control-Allow-Method
X-CACHE-GROUP
X-Varnish-Grace
X-Signature
X-B-Cache
Viewport
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Is-Crawler
X-Flags
Healthy
X-Providence-Cookie
X-Route-Name
X-Request-Guid
X-Cache-Action
X-FB-Debug
X-Aspnet-Duration-Ms
Payment
X-TT
X-Whom
X-B3-Sampled
Node
X-AOL-HN
X-XRDS-LOCATION
X-App-Environment
X-N
Version
X-Seen-By
X-Microsite
X-Request-Handler-Origin-Region
X-Type
Fastcgi-Useragent
X-Mobile
DynaTrace
X-Load-Cache
DC
X-Fastcgi-Cache
MS-CV
X-Yandex-Sdch-Disable
X-Ab
X-HTML-Minification-Powered-By
X-Cache-Expired-At
X-Distributor
SRV
X-Ua-Device
Retry-After
Filterid
X-Cache-Control
X-Tt-Trace-Tag
X-Tt-Trace-Host
Frame-Options
X-IPLB-Instance
X-User-Agent
X-Original-Request-Id
X-Response-Served-From
X-Instance
X-Real-IP
X-UUID
X-IPS-LoggedIn
X-RemovedCookies
X-Varnish-Server
X-ProcessESI
X-Tumblr-Pixel
X-Jobs
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Debug-IsPreview
X-Adobe-Loc
X-Proxy-Cache-Status
Ms-Operation-Id
X-Cluster-Name
X-Content-Powered-By
X-Region
X-Debug-IsConnected
X-Device-Type
X-RTag
X-Proxy
X-Adobe-Content
Access-Control-Request-Headers
Refresh
NGB
X-Cacheable-TTL
VIX-Pulpo-Upstream-Status
X-Page-View
X-B
X-Cache-Time
Uber-Trace-Id
VIX-Pulpo-Node
X-Framework
X-G
X-FireWall-Port
X-Debug
X-Accel-Buffering
Cache
X-Vgn-Hpd-Reason
X-FW-Server
X-FW-Static
X-FW-Hash
X-FW-Serve
X-FW-Dynamic
X-FW-Type
X-Zen-Fury
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
Countrycode
Section-Io-Id
X-Wix-Request-Id
Section-Io-Origin-Status
X-Oracle-Dms-Rid
X-RateLimit-Limit
X-Mg-Request-UUID
X-NGENIX-Cache
X-CDN-Forward
X-Azure-Ref
Cache-Status
X-App-Version
X-Time
Surrogate-Key
X-Is-Bot
X-Rendered-As
Country
X-Nginx-Cache
X-Ms-Request-Id
X-Cache-Hit
X-Drupal-Cache-Tags
X-Cache-Rule
X-Ms-Version
X-EdgeConnect-Cache-Status
S-Cnection
X-Node-Name
X-App-Server
SD-X-WS
Eomportal-Instance
Referer-Policy
Amp-Access-Control-Allow-Source-Origin
Liferay-Portal
X-TA-CDN-Provider
X-Environment-Context
X-L-Path
X-Cache-Operation
Selected-Fe
X-Yottaa-Metrics
From-Origin
X-Yottaa-Optimizations
X-SaId
X-Varnishpool
X-Drupal-Cache-Contexts
X-Tumblr-Pixel-2
Meta-Geo
X-RN-RSRV
X-UPSTREAM-Address
X-Proxy-Build
X-ES-SERVER
X-JoinUs
X-Timing-Wait
X-Shopify-Stage
X-ShopId
X-Xfnlog-Site
X-GG-Cache-Date
X-Sorting-Hat-PodId
X-Handled-By
X-S-Maxage
X-Request-Time
X-Sorting-Hat-ShopId
X-Via-Fastly
X-Cache-TTL-Remaining
X-ShardId
X-PHP-Backend
X-Varnish-Beresp-Grace
X-TNCMS
X-Pubstack
ServedBy
X-Storefront-Renderer-Rendered
X-No-Session
X-Varnish-Hostname
CF-IPCountry
X-Backend-Host
X-Endurance-Cache-Level
Protected
X-R9-Blue-Green-Version
X-Alternate-Cache-Key
X-Cache-Server
X-Loop
Property-Id
Cache-Name
X-Server-W
Fastly-SSL
X-AWS-Id
X-Human
X-LAGOON
Azure-InstanceId
Azure-SlotName
X-ProxyCache-Status
X-ProxyCache-Key
X-LJ-Flow-ID
X-NYM-Debug-Backend
X-Proto
X-PCL
X-Origin-Hint
Azure-RegionName
X-OCL
X-BYPASS-REASON
X-Be
TWC-Locale-Group
TWC-Privacy
TWC-GeoIP-LatLong
X-VWS-Id
TWC-Device-Class
TWC-GeoIP-Country
Webcakes-App-Name
Webcakes-App-Version
Cache-Tv-Group
Azure-Version
X-Adobe-Source
Azure-SiteName
Webcakes-Region
TWC-Connection-Speed
X-Access
X-Format
X-Hl-Ver
X-Origin-Date
X-Backend-Name
X-RCS-CacheZone
Decoy-Debug-Key
Decoy-Debug-Status
Decoy-Debug-TTL
Country-Code
X-Say-TTL
X-SayCDN-TTL
X-Section
Apigw-Requestid
X-Say-Cacheable
Nel
Akamai-GRN
X-ApacheServer
Mn-Server-Ip
X-PHP-Host
X-Sql-Duration-Ms
X-Labrador-Cache-Channel
X-Status
X-FB-TRIP-ID
X-PERF
X-Revision
X-UA-Device-Type
X-Akamai-Edgescape
X-Sql-Count
X-Cache-PHP
X-Uri
X-Hosted-By
X-Hyper-Cache
X-Redis-Cache
X-Rule
X-Web-Node
X-Cache-Type
X-Trace-Id
X-Aws-Lambda-Call-Status
Xserver
AMP-Access-Control-Allow-Source-Origin
X-WA-Info
X-MP-GENERATED-AT
X-FW-Version
X-ATG-Version
X-B3-SpanId
X-B3-Traceid
X-ServerID
X-Time-Microsecs
X-Content-Age
X-Tumblr-Pixel-3
X-Cached-By
X-Dc
X-Parallel-Accel
X-Soup
X-CSRF-Token
X-Akamai-Transformed
Backend
X-Cache-Enabled
X-Edge-Location
GEO-INFO
Count-Hit
X-TT-LOGID
X-Detected-As
X-Datadome
X-Cluster-Node
OT-Force-Account-Verify
X-Mode
X-Varnish-Cache-Hits
X-Azure-Ref-OriginShield
X-APP-VERSION
X-Info
X-Microcachable
X-Bc-Bl
X-Varnish-Beresp-Status
X-Cache-Host
X-Generation-Time
Web-Mar-Node
X-CS
X-Varnish-Hits
Cross-Origin-Opener-Policy
X-Cache-NGX
X-Servername
X-Amzn-Remapped-Content-Length
X-Amz-Apigw-Id
X-Debug-Cache
X-Amzn-RequestId
X-Routing-Service
DataCenter
X-Storage
X-Proxied
X-Platform
X-Zipkin-Id
X-SRV
X-Varnish-Beresp-Ttl
Who
X-HP-Trace-Id
X-Extlb
X-Unique-ID
X-DataDome
X-Origin-TTL
X-Origin-CC
X-PAYTM-SRV-ID
X-PBS-Appsvrname
Host-ID
X-D
Fastly-Backend-Name
Fastcgi-X-Cache-Version
X-NAPM-TraceId
X-Developer
X-Destination
X-Core-Value
X-Connection-Hash
X-Cms-Context
Cache-Host
X-Request-URI
MD5-Digest
X-Rewrite-Enabled
X-Ratelimit-Reset
X-Air-Hostname
X-Magnolia-Registration
X-Processor
X-Air-Trace-Id
X-Air-Source
X-Location
X-Locale
CDN-EdgeStorageId
Apple-News-Services-Handled
X-From
A
CDN-PullZone
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
BehaviorPad-Version
CDN-Cache
CDN-CachedAt
Apple-News-Services-Request-Url
CDN-RequestCountryCode
CDN-RequestId
X-Level-Front-Cache
DCR-Decision-By
DCR-Processing-Time-Ms
Expiry
X-Rojux
X-Epic-Correlation-Id
Content-Disposition
X-Generated-On
X-Geo-Header
CDN-Uid
X-External-Request-Id
CDCHOST
M-TraceId
X-BCube-Filmed-By
Req-Svc-Chain
X-B-Cookie
X-ARC
State
Rendered-Blocks
X-Bip
X-Vdms-Version
X-VG-WebServer
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Surrogated-Key
X-Application
X-A-Dcw
X-A-Dgt
X-A-Dam
X-A-Ccd
X-A
X-A-Wwc
SID
T-Server
X-Aicache-OS
X-Aed
Server-Info
X-Vdms-Path
X-VG-WebCache
X-CF-Lambda-Fn
X-Session-Fingerprint
Mobile-Detection-Method
X-Cache-NE
Odigeo-Trace-Id
X-Service
Meta-Geo-Continent
X-S
X-S-Cookie
X-CF-Lambda-Version
X-ScT
X-Thanos
X-SRCache-Key
X-Cache-Bucket
S-Rt
Upgrade-Insecure-Requests
X-Ua
Fastly-Drupal-HTML
PFcat
UCS
L
Gh-Request-Id
Location
CacheControlHeader
Fastly-SWR
X-Developers
Fastly-SIE
X-Clientip
X-Branch-Name
Memcached
Cmstype
Cmsid
Pics-Label
Fastcgi-Cache-TTL
X-Envoy-Decorator-Operation
X-Backend-State
Server-Host
Pagetype
Esi-Enabled
Kp-EeAlive
Origin
X-Cache-Debug
X-Cache-Grace
X-Proxy-Upstream
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Via-JSL
X-Platform-Server
Path
X-NU-AKA-ACS-Version
X-Origin
X-EC-Lua
X-VG-TLSProxy
X-Request-UUID
X-VarnishDD-TTL
X-Sucuri-ID
X-TrackingId
X-Var-Ttl
X-Sigma-Backend
X-Sigma
X-Rocket-Build-Number
X-Scheme
X-Served-From
X-NWS-UUID-VERIFY
Source
X-Hash
X-HN
X-VHOST
X-Has-Esi
X-GoCache-CacheStatus
AKAMAI
X-Gamma-Serve
X-JWT-State
X-Is-Gdpr
X-Varnish-Ttl
X-Tb
Url
User-Cache-Control
Cross-Origin-Window-Policy
X-AIR-PT
X-SVT-ORM-RULES
X-Orig-Expires
Thinkindot-CacheControl-Type
X-Shop-Environment
X-Tenant
Wxu-Next-Region
X-Varnish-Url
X-Forwarded-Path
Thinkindot-Control
X-VC-Cache
X-WADP-Cache
Thinkindot-CacheControl
NGX
X-Accel-Expires-Debug
X-Thinkindot-L3
X-Device-Os
X-Variation
C-Via
X-SVT-ORM-VERSION
DSUID
TDXMobile
X-Req
X-Li-Pop
X-DPWN-IS-SECURE
X-LI-UUID
X-Loc
X-Men
X-Li-Fabric
X-Eu-Site
X-Fmm-Version
X-Fastly-Cache
X-Forwarded-Site
X-Generated-In
Wxu-Next-Hostname
X-Micro-Cache
X-Minions-Version
X-Clara-WADP
X-Request-Host
X-CGP
X-Cache-Tags
X-Site-Version
X-Fastly-Backend
X-Cluster
X-Date
X-Origin-Expires
X-Owner
X-Csrf-Jwt
X-Policy
X-Cache-Info
X-Generated-By
Content-Secure-Policy
NtCoent-Length
Arc-Country
Adler-Geo
NM-Fastcgi-Cache
PB-RID
X-Ratelimit-Limit
Arc-Version
L5d-Success-Class
Ha-Gx-Prefs
Wxu-Next-Commit
Ec-Rule-Version
HA-Ipaddr
Cf-Device-Type
Is-Eu
Platform
PB-PID
X-Forwarded-Host
Svr
Vix-Hermes-Req-Id
X-Amz-Meta-S3cmd-Attrs
True-Client-Country-4JS
X-Esi-Check
X-Hnp-Log
X-Qloud-Router
X-RateLimit-Limit-Second
X-SIPLIST1
X-PF-Uncompressing
X-Viewer-Country
X-Old-Content-Length
X-Irp-Debug
X-Varnish-Remaining-TTL
Cache-Key
X-RateLimit-Remaining-Second
X-Varnish-CookieINHashed-On
X-Wikidot-Backend
X-Gen-Mode
X-Goog-Meta-Goog-Reserved-File-Mtime
X-FC-Vary-Parameters
X-Slack-Backend
X-Gzip
X-Varnish-CookieHashed-On
X-DefHash
X-Fetched-On
Sever-Int
Mail-Subject
X-Nginx-Cache-Key
X-GeoIP
X-Cache-Id
X-GeoIP-City
X-Skip-Cache
X-Mvc-Supplant-Cachable
X-Block-Status
X-User
Server-Hostname
We-Hiring
X-Wikidot-Static-Cache
X-DefElseHash
X-VServer
Server-Ext
V-Age
Locid
Release
IsBot
X-TEC-API-ORIGIN
X-TEC-API-ROOT
Webserver
X-TEC-API-VERSION
X-Planisys-CDN-Rules
X-HS-Content-Campaign-Id
VNS-Cache
X-CACHE-KEY
VNS-Age
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
X-Ftr-Request-Id
Powered-By-ChinaCache
CPC-Cache
X-Unique-Id
X-Srv
CPC-Age
Cache-Hits
X-Via-NSCOPI
My-App
X-Zone
XServer
X-GEO
X-Mvc-Supplant-OutputCached
X-Refresh
X-Conf
MIME-Version
X-Ratelimit-Remaining
X-Vc
X-Pass-Why
X-TX-ID
X-Via-Popv
X-Via-Poph
X-Via-Popn
X-PJAX-URL
X-BBC-Edge-Cache-Status
X-Cache-Ttl
X-Internal-Host
X-Servedbyhost
X-NC
X-Worker
X-TIME
X-Ckpd-Fst-Backend
Geo-Info
X-ID
X-OVcl-Cache
X-OVcl
Memory
X-Auto-Login
Time
WebServer
X-TraceId
Server-ID
Cf-Bgj
X-V-Cache
X-NCache
X-LSADC-Cache
X-LB-ID
X-Backend-TTL
Magicmarker
X-NewRelic-App-Data
X-Rocket-Nginx-Serving-Static
X-Render-Time
X-Webkit-Csp
X-DC
X-Tx-Id
DB-Nickname
X-ZONE
GeoIp-Country-Code
X-Platform-Cluster
X-Platform-Processor
Hostname
Geoip-Latitude
X-Wa
X-M-Log
X-Qnm-Cache
X-M-Reqid
X-Cache-Remote
X-Traceid
X-Platform-Router
X-Newrelic-Synthetics
X-Geo
X-Method
X-Dispatcher-Server
X-App
HostName
X-SD-PageType
X-Datadog-Trace-Id
Environment
X-Datadog-Sampling-Priority
X-CLOUD-TRACE-CONTEXT
X-Datadog-Parent-Id
X-Nyt-Route
X-NodeID
X-Origin-Time
X-BBC-Origin-Response-Status
X-Cache-Config
Resin-Trace
X-API-Version
X-Gdpr
X-VCL-Version
Ssr
X-Tb-Optimization-Total-Bytes-Saved
X-IP
X-Correlation-ID
LB
X-Pod-Name
Cluster
X-Edge-Pop
X-Server-IP
X-Via-Ucdn
Tcn
Ohc-File-Size
X-Webkit-CSP-Report-Only
X-Li-Proto
X-Dynatrace
X-MSEdge-Features
X-LI-Proto
X-CACHE-AGE
Candidate-Md5Url
X-MSEdge-Flight
X-Origin-Response-Time
X-HITS
X-Cache-Var-Map
X-Cache-Var
X-Nc
X-ElasticPress-Query
X-Trv-Group
X-DynaTrace-JS-Agent
Cf-Ipcountry
X-Node-Id
X-Vcl-Version
X-Via-CDN
N-Cache
Web-Mar-Region
X-Varnish-Beresp-TTL
X-Akamai-Pragma-Client-IP
Datacenter
X-APP
X-Wix-Viewer-Type
Env
X-ND-Cache
X-HostName
X-ServerName
X-Reqid
Proxy-Connection
X-Cs
X-Fastly-Request-Id
Sid
GeoIP-Latitude
GeoIP-Country-Code
X-HS-Status
X-WA
X-Dynatrace-Js-Agent
X-NGINX-Cache
Onion-Location
Servername
CDN
CF-Cached-On
X-Content
X-Ua-Browser
Server-Id
Cdn
X-Varnish-Cacheable
Rt-Fastcgi-Cache
X-EIG-Tracking-Id
VivaBuild
WWW-Authenticate
Viewtype
X-AB
X-MG-S
X-Fastly-Backend-Reqs
Machine
X-Lb-Id
WZWS-RAY
X-CSRF-TOKEN
X-FTR-Request-ID
X-URL
X-Via-PopV
X-Via-PopH
X-Via-PopN
X-Cdn-Forward
X-Fpc
X-Check-Cacheable
X-Xrds-Location
Ohc-Cache-HIT
X-Esi
X-ServedByHost
X-IN-APIGATEWAYSSL
Redirect-Candidate
X-Tid
Cteonnt-Length
FSS-Cache
X-TIM-N
On-Server
X-Request-Start
X-VC
Server-Ttl
X-Pjax-Url
X-Cache-Backend
X-IN-APIGATEWAY
X-ECache
X-Up
Mime-Version
URI
X-Swa-Ws
X-SN
Shield-Pop
CountryCode
X-Tt-Logid
Pramga
X-Cache-Date
X-Amz-Meta-Cb-Modifiedtime
Is-Us
X-Pad
X-Cache-ASPX
X-Contensis-Viewer-Groups
X-Varnish-Authentication
X-Oss-Storage-Class
X-FTR-Cache-Status
X-Swift-Error
X-FORWARDED-FOR
Tracecode
X-FTR-DC
Xc-Version
X-FTR-Realm
X-Air-Pt
X-Country-Code-Real
X-FTR-Backend
Lb
X-Oss-Hash-Crc64ecma
X-FTR-Balancer
X-Oss-Server-Time
X-FTR-Backend-Server
X-Oss-Object-Type
CACHE
X-Oss-Request-Id
X-Cdn-Origin
X-RPS
X-Sn-Servicetimems
X-RPM
X-DI
X-DSS
X-DW
X-RSL
Warning
Xet-Cookie
X-Acquia-Application-Trace
X-Acquia-Site
X-Acquia-Application-UUID
X-StackifyID
X-Acquia-Purge-Tags
X-DB
X-ElasticPress-Search
Ohc-Response-Time
X-Yottaa-OS
WP-Super-Cache
X-Fastly-Cache-Hits
X-Action
Vha6-Origin
X-LiteSpeed-Cache-Control
X-Pf-Uncompressing
X-SB
X-Webstats-RespID
X-Dw-Trace-Id
X-CCM
X-B3-Spanid
X-Core-Mission
X-RAMCache
Content-Style-Type
X-MiniProfiler-Ids
Content-Script-Type
CloudFront-Viewer-Country
X-C
X-CCDN-CacheTTL
X-Mg-Request-Id
X-CCDN-Origin-Time
ServerName
X-CUA
X-Hcs-Proxy-Type
X-FTR-Expires
X-Snapshot-Date
X-TH-Server