Threat Level: green Handler on Duty: Russ McRee

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
Link
ETag
Pragma
Expect-CT
X-Powered-By
X-XSS-Protection
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
Alt-Svc
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Timer
X-Download-Options
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-Request-ID
X-Cache-Status
X-Generator
X-Cacheable
X-DNS-Prefetch-Control
Timing-Allow-Origin
P3p
X-Content-Security-Policy
X-Iinfo
Status
X-Ua-Compatible
Feature-Policy
Content-Encoding
X-AspNetMvc-Version
X-CDN
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
Upgrade
X-Drupal-Dynamic-Cache
Access-Control-Max-Age
X-Dns-Prefetch-Control
X-Via
Keep-Alive
X-Ws-Request-Id
X-Robots-Tag
Request-Context
Server-Timing
X-AH-Environment
X-Hacker
X-Server
X-Age
X-Turbo-Charged-By
X-Proxy-Cache
X-Server-Powered-By
X-Cache-Group
X-Backend
X-Amz-Request-Id
Host-Header
X-Amz-Id-2
EagleId
X-Nginx-Cache-Status
Report-To
X-LiteSpeed-Cache
X-Rq
X-Varnish-Cache
X-UA-Device
X-Page-Speed
Grace
X-Pingback
X-Swift-CacheTime
X-Swift-SaveTime
EagleEye-TraceId
Ali-Swift-Global-Savetime
X-Device
X-Vhost
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-OneAgent-JS-Injection
X-Amz-Version-Id
NEL
Cf-Railgun
X-Dispatcher
X-Host
X-Cache-Spec
X-Server-Id
X-CST
X-WebKit-CSP
X-Node
X-EdgeConnect-MidMile-RTT
X-Backend-Server
X-EdgeConnect-Origin-MEX-Latency
Request-Id
Allow
Surrogate-Control
X-Readtime
Accept-CH
X-Akam-SW-Version
X-Response-Time
Accept-Ch-Lifetime
X-HW
Xkey
X-Ruxit-JS-Agent
X-Language
X-Webkit-CSP
X-Country
X-Application-Context
X-Template
X-Ac
Content-Location
X-Cache-Lookup
MS-Author-Via
X-Cloud-Trace-Context
Rating
X-Url
Edge-Control
X-TtlSet
X-Vname
X-PC
X-Mod-Pagespeed
X-B3-TraceId
X-Clacks-Overhead
X-Trace
X-Varnish-TTL
X-MS-InvokeApp
Fastly-Restarts
X-Content-Type
X-ESI
X-Rack-Cache
X-Origin-Cache
X-GitHub-Request-Id
Accept-Ch
X-Cnection
X-Buckets
X-Country-Code
X-Goog-Hash
X-D2id
X-Use-Magma
X-Kinja
X-Kinja-Build
X-Kinja-Revision
X-Kinja-Server
X-GoogleNews-Bot
X-Exp-Variant
X-Cdn-Fetch
X-Exp-Id
X-VARITI-CCR
Verso
Accept-CH-Lifetime
Arr-Disable-Session-Affinity
X-FastCGI-Cache
X-ORACLE-DMS-ECID
X-Vcap-Request-Id
Cache-Tag
X-Cached
X-Server-Name
X-Abt-Application-Version
Service-Worker-Allowed
X-Server-ID
X-Navigation-Version
X-Amz-Rid
X-Client-IP
X-Px
X-Powered-By-Plesk
RTSS
Public-Key-Pins
Access-Control-Request-Method
X-Fastly-Request-ID
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Powered-CMS
X-Element-Page-Cache
X-MSEdge-Ref
X-Cache-TTL
X-Dw-Request-Base-Id
X-Upstream
X-NF-Request-ID
X-Version
X-Sol
Display
Pagespeed
X-Middleton-Response
Response
X-Middleton-Display
S
X-Ttl
X-TTL
X-Kinsta-Cache
X-Edge-Location-Klb
X-Edge
X-LLID
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Instrumentation
X-Kraken-Routeconfig-Destination
MRF-Tech
X-B3-TraceId-Primal
X-Accel-Expires
Mrf-Cache-Status
Realpath
X-HP-Webp
X-Jurisdiction
X-ECACHE
SPRequestGuid
X-Shield-Request-Id
X-SharePointHealthScore
X-Correlation-Id
SPRequestDuration
X-T
SPIisLatency
X-Cache-Key
X-Pinterest-Rid
Pinterest-Version
X-Mid
X-MCACHE
Pinterest-Generated-By
X-PressLabs-Stats
X-Litespeed-Cache
X-Content-Security-Policy-Report-Only
X-ORACLE-DMS-RID
Edge-Cache-Tag
X-DynaTrace
Fastcgi-Cache
X-Forwarded-Proto
X-XRDS-Location
X-Amz-Server-Side-Encryption
X-Mg-S
X-Content-Digest
Nginx-Cache
TP-L2-Cache
TP-Cache
X-Recruiting
Charset
Filters
X-Request-Processing-Time
X-Request-Received
Front-End-Https
X-Id
Alternate-Protocol
TCN
Server-Node
X-Logged-In
X-Forwarded-For
X-Ezoic-Cdn
Content-MD5
X-Geo-Country
Fusion-Source
Fusion-Content-Id
Fusion-Deployment-Id
Fusion-Component-Id
Fusion-Template-Id
Fusion-Content-Source
X-ASPNET-VERSION
Cache-Tags
X-Protected-By
X-Hostname
X-Amzn-Trace-Id
X-Grace
X-Origin-Upstream-Status
X-Goog-Generation
X-Goog-Storage-Class
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-NWS-LOG-UUID
X-Goog-Stored-Content-Encoding
X-Www-Served-By
X-Origin-Server
X-F-Cache
X-Oneagent-Js-Injection
X-Amz-Replication-Status
X-Rid
Cleartype
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Cache-Config
X-Debug-Info
X-HS-Combine-CSS
X-LB-Cache
X-Release
X-Az
Host
X-AppVersion
X-Activity-Id
X-Contextid
Section-Io-Cache
X-Daa-Tunnel
X-Page-Id
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Git-Hash
X-Browser-Type
Server-Name
X-Ser
X-Frontend
X-Aspnetmvc-Version
MicrosoftSharePointTeamServices
X-Respond-Thread
X-Cache-Age
X-VCache
X-RateLimit-Remaining
X-Ab
X-Ruxit-Js-Agent
X-Content-Options
Accept-Charset
X-Upgrade-Enabled
Access-Control-Allow-Method
X-Kong-Proxy-Latency
X-Hits
X-Mobile-URL
X-Kong-Upstream-Latency
X-Source
X-DIS-Request-ID
X-WebKit-CSP-Report-Only
X-Aspnet-Duration-Ms
X-Is-Crawler
ServerID
X-CACHE-GROUP
X-Flags
X-Route-Name
X-Request-Guid
X-Providence-Cookie
X-Cache-Action
X-Signature
X-B-Cache
X-Whom
Payment
X-Varnish-Backend
X-TT
X-Varnish-Grace
X-FB-Debug
Healthy
Viewport
Paypal-Debug-Id
X-Varnish-Age
X-Fastcgi-Cache
Node
X-App-Environment
X-AOL-HN
DynaTrace
Fastcgi-Useragent
X-B3-Sampled
X-Load-Cache
Version
X-Seen-By
X-Mobile
X-Yandex-Sdch-Disable
X-N
DC
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-XRDS-LOCATION
Filterid
X-HTML-Minification-Powered-By
X-Distributor
X-Type
Retry-After
X-User-Agent
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
X-Cache-Control
Frame-Options
SRV
MS-CV
X-Jobs
Refresh
X-Cache-Expired-At
X-Original-Request-Id
X-Response-Served-From
X-UUID
X-Real-IP
X-Proxy-Cache-Status
NGB
X-IPLB-Instance
X-Adobe-Loc
X-Adobe-Content
X-Page-View
Access-Control-Request-Headers
X-Debug-IsConnected
X-Debug-IsPreview
X-Device-Type
X-Cluster-Name
X-FW-Type
X-FW-Hash
X-FW-Server
X-FW-Static
X-FW-Dynamic
X-FW-Serve
X-Framework
X-G
X-Instance
X-Content-Powered-By
X-Cacheable-TTL
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-B
X-Proxy
X-ProcessESI
X-Region
X-Tumblr-Pixel-1
X-Tumblr-User
X-Varnish-Server
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-RemovedCookies
X-Vgn-Hpd-Reason
Ms-Operation-Id
X-NGENIX-Cache
X-IPS-LoggedIn
X-RTag
X-Cache-Time
X-Azure-Ref
Uber-Trace-Id
Amp-Access-Control-Allow-Source-Origin
Ar-Sid
X-CDN-Forward
X-Zen-Fury
AR-CACHE
AR-ATIME
AR-Request-ID
AR-PoweredBy
X-Node-Name
Countrycode
X-Request-Handler-Origin-Region
X-Cache-Hit
X-Wix-Request-Id
X-Cache-Rule
X-Microsite
Cache-Status
Section-Io-Origin-Status
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Id
X-Ms-Version
X-Ms-Request-Id
X-Time
X-Is-Bot
X-Rendered-As
SD-X-WS
X-Mg-Request-UUID
X-Oracle-Dms-Rid
X-Aws-Lambda-Call-Status
Liferay-Portal
X-HP-Trace-Id
Referer-Policy
X-Debug
X-Drupal-Cache-Tags
X-Accel-Buffering
X-Nginx-Cache
X-EdgeConnect-Cache-Status
X-Parallel-Accel
S-Cnection
Cache
Country
X-App-Server
X-Revision
X-L-Path
CF-IPCountry
X-RateLimit-Limit
X-Environment-Context
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Cache-Operation
X-App-Version
Surrogate-Key
X-FireWall-Port
Count-Hit
X-ES-SERVER
X-Loop
X-JoinUs
X-TA-CDN-Provider
X-TNCMS
Meta-Geo
X-GG-Cache-Date
X-RN-RSRV
X-SaId
Eomportal-Instance
X-Endurance-Cache-Level
X-UPSTREAM-Address
X-Drupal-Cache-Contexts
X-Sorting-Hat-PodId
Selected-Fe
X-Say-TTL
X-Proxy-Build
X-Alternate-Cache-Key
X-Sorting-Hat-ShopId
X-Adobe-Source
From-Origin
X-Shopify-Stage
X-ShardId
X-SayCDN-TTL
X-ShopId
X-Timing-Wait
X-Say-Cacheable
X-Storefront-Renderer-Rendered
X-Varnishpool
X-Cache-Type
Azure-SiteName
X-FW-Version
X-VWS-Id
X-Varnish-Hostname
X-Cache-TTL-Remaining
Country-Code
X-Be
X-BYPASS-REASON
X-Proto
X-AWS-Id
Azure-InstanceId
X-Varnish-Beresp-Grace
X-Human
X-S-Maxage
X-ProxyCache-Status
X-Sql-Count
Azure-Version
X-Sql-Duration-Ms
Protected
X-LJ-Flow-ID
Azure-RegionName
X-Xfnlog-Site
Cache-Name
X-Request-Time
X-No-Session
X-ProxyCache-Key
X-LAGOON
X-Origin-Date
Azure-SlotName
Cache-Tv-Group
X-Akamai-Edgescape
Akamai-GRN
X-OCL
X-PCL
X-NYM-Debug-Backend
X-PHP-Host
X-UA-Device-Type
X-R9-Blue-Green-Version
X-Labrador-Cache-Channel
X-PHP-Backend
X-Handled-By
X-Hosted-By
X-Cache-Server
X-Pubstack
X-Redis-Cache
X-Status
X-Tumblr-Pixel-2
Decoy-Debug-Key
X-Server-W
Decoy-Debug-TTL
ServedBy
X-Backend-Name
X-RCS-CacheZone
Fastly-SSL
X-Hyper-Cache
Decoy-Debug-Status
X-Uri
X-Hl-Ver
X-Via-Fastly
Apigw-Requestid
X-Web-Node
X-Origin-Hint
TWC-Device-Class
TWC-Connection-Speed
X-Access
Webcakes-Region
Webcakes-App-Name
TWC-Locale-Group
X-Backend-Host
X-Section
TWC-Privacy
X-Format
TWC-GeoIP-Country
Webcakes-App-Version
TWC-GeoIP-LatLong
X-APP-VERSION
Nel
GEO-INFO
Property-Id
X-FB-TRIP-ID
Mn-Server-Ip
X-Time-Microsecs
X-ServerID
X-Ua-Device
X-ApacheServer
X-PERF
X-Cluster-Node
X-ATG-Version
X-Servername
X-B3-SpanId
OT-Force-Account-Verify
X-Cache-PHP
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Tumblr-Pixel-3
Cross-Origin-Opener-Policy
X-TT-LOGID
X-Azure-Ref-OriginShield
X-Detected-As
X-Datadome
Xserver
X-CSRF-Token
X-Trace-Id
Backend
X-Content-Age
X-WA-Info
Web-Mar-Node
X-Generation-Time
X-MP-GENERATED-AT
X-Varnish-Cache-Hits
X-Cache-Host
Cross-Origin-Window-Policy
X-Ua
Content-Secure-Policy
X-SRV
X-Varnish-Hits
X-Rule
X-Soup
X-Bc-Bl
X-Cached-By
X-Akamai-Transformed
X-Cache-Enabled
Ec-Rule-Version
X-CS
X-Via-JSL
X-Ratelimit-Limit
X-Mode
X-Amzn-Remapped-Content-Length
X-Amz-Apigw-Id
Source
X-Amzn-RequestId
X-Info
X-NWS-UUID-VERIFY
X-Edge-Location
S-Rt
X-Cache-Grace
X-Microcachable
X-Ratelimit-Remaining
X-Origin-TTL
X-Varnish-Beresp-Status
X-Origin-CC
X-Magnolia-Registration
X-B3-Traceid
Upgrade-Insecure-Requests
Url
X-Locale
X-Forwarded-Host
X-Air-Hostname
SID
X-Cache-NGX
X-Air-Source
X-Dc
AMP-Access-Control-Allow-Source-Origin
X-Air-Trace-Id
X-Varnish-Beresp-Ttl
X-GEO
X-Tb
X-Site-Version
X-Debug-Cache
X-EC-Lua
Req-Svc-Chain
Rendered-Blocks
Content-Disposition
X-Cache-Bucket
X-BCube-Filmed-By
X-VG-WebServer
X-VG-WebCache
X-Vtex-Processado-Em
Odigeo-Trace-Id
A
X-Zipkin-Id
X-GoCache-CacheStatus
X-Ftr-Request-Id
Host-ID
X-Developer
X-Destination
X-Epic-Correlation-Id
X-CF-Lambda-Version
X-Extlb
X-External-Request-Id
Path
M-TraceId
Meta-Geo-Continent
Mobile-Detection-Method
X-Clientip
X-Conf
X-Connection-Hash
X-D
MD5-Digest
Fastly-SWR
Fastly-SIE
CDN-EdgeStorageId
CDN-PullZone
CDN-RequestCountryCode
CDN-CachedAt
CDN-Cache
BehaviorPad-Version
State
CDN-RequestId
CDN-Uid
X-CF-Lambda-Fn
Expiry
Fastcgi-X-Cache-Version
DCR-Processing-Time-Ms
DCR-Decision-By
X-From
X-Forwarded-Path
X-Cache-NE
X-Vtex-Remote-Cache
X-Ratelimit-Reset
X-Proxied
X-Rebelmouse-Cache-Control
X-Shop-Environment
X-Session-Fingerprint
X-Processor
X-Aicache-OS
X-PAYTM-SRV-ID
X-PBS-Appsvrname
X-Platform-Server
X-A-Dcw
X-A-Dgt
X-ScT
X-Rewrite-Enabled
X-Rojux
X-S
X-Routing-Service
X-Request-URI
X-Aed
X-Rebelmouse-Surrogate-Control
X-A-Wwc
Surrogated-Key
X-S-Cookie
X-Application
X-AIR-PT
X-Unique-Id
X-B-Cookie
X-SRCache-Key
X-A-Ccd
X-A
X-Tenant
X-Orig-Expires
User-Cache-Control
X-NU-AKA-ACS-Version
T-Server
X-NAPM-TraceId
X-ARC
X-Vdms-Version
X-A-Dam
X-Storage
X-Cache-Ttl
X-Cms-Context
DSUID
NGX
X-SVT-ORM-RULES
X-Fmm-Version
UCS
X-Fastly-Backend
X-Variation
Origin
X-Fastly-Cache
X-Service
Cmstype
X-Clara-WADP
Is-Eu
X-DPWN-IS-SECURE
PB-PID
X-TrackingId
PB-RID
X-Date
Fastly-Drupal-HTML
Fastly-Backend-Name
X-Sigma-Backend
X-Platform
X-Sigma
X-Core-Value
X-Thanos
Cache-Host
X-Origin-Expires
X-Is-Gdpr
X-JWT-State
X-Hash
X-Has-Esi
Cmsid
X-BBC-Edge-Cache-Status
X-Li-Fabric
X-WADP-Cache
X-VServer
X-Bip
X-Men
X-VG-TLSProxy
X-Loc
X-Li-Pop
X-LI-UUID
X-Cache-Info
X-SVT-ORM-VERSION
Platform
C-Via
X-Proxy-Upstream
Cache-Key
CDCHOST
X-Rocket-Build-Number
X-Request-UUID
X-Request-Host
X-Accel-Expires-Debug
Arc-Version
Apple-News-Services-Handled
Adler-Geo
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
X-Forwarded-Site
X-Cache-Tags
X-Amz-Meta-S3cmd-Attrs
X-Backend-State
X-Branch-Name
X-Cache-Debug
X-Block-Status
X-GeoIP-City
X-Origin
X-VC-Cache
X-Varnish-Remaining-TTL
X-Old-Content-Length
X-Nginx-Cache-Key
X-Via-NSCOPI
X-Micro-Cache
X-Mvc-Supplant-Cachable
X-Policy
X-Req
X-SIPLIST1
X-Slack-Backend
X-Thinkindot-L3
X-Var-Ttl
X-Served-From
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-Scheme
X-Viewer-Country
We-Hiring
X-FC-Vary-Parameters
X-Gamma-Serve
X-Gen-Mode
X-Esi-Check
X-Envoy-Decorator-Operation
X-DefElseHash
X-DefHash
X-Device-Os
X-Generated-By
X-Generated-On
X-Irp-Debug
X-Level-Front-Cache
X-Location
X-Hnp-Log
X-Gzip
X-Geo-Header
X-GeoIP
X-Cluster
X-Cache-Id
Release
CPC-Cache
Pics-Label
CPC-Age
Cf-Device-Type
CacheControlHeader
Server-Host
Server-Ext
Pagetype
NM-Fastcgi-Cache
IsBot
Location
L
Gh-Request-Id
Mail-Subject
Esi-Enabled
Fastcgi-Cache-TTL
Sever-Int
Server-Hostname
X-DC
Thinkindot-CacheControl-Type
VNS-Cache
VNS-Age
Vix-Hermes-Req-Id
X-Varnish-Ttl
Thinkindot-Control
Thinkindot-CacheControl
Server-Info
TDXMobile
Kp-EeAlive
X-Ckpd-Fst-Backend
X-Eu-Site
HA-Ipaddr
X-Vdms-Path
X-HN
Ha-Gx-Prefs
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Developers
X-Generated-In
Arc-Country
Webserver
X-Fetched-On
X-Wikidot-Backend
AKAMAI
X-Unique-ID
X-Wikidot-Static-Cache
X-VarnishDD-TTL
L5d-Success-Class
X-Skip-Cache
X-Planisys-CDN-Rules
PFcat
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Sucuri-ID
True-Client-Country-4JS
X-DataDome
X-CGP
X-Planisys-CDN-TTL
X-Csrf-Jwt
X-Planisys-CDN-Cache
X-Worker
Locid
Memcached
NtCoent-Length
X-Owner
DataCenter
X-M-Log
V-Age
X-M-Reqid
X-Auto-Login
Wxu-Next-Region
Wxu-Next-Commit
Wxu-Next-Hostname
Svr
X-HS-Content-Campaign-Id
X-Qloud-Router
X-V-Cache
X-Mvc-Supplant-OutputCached
X-User
X-Tx-Id
Who
X-Via-Poph
X-Via-Popn
X-Via-Popv
X-Qnm-Cache
X-NCache
X-CACHE-KEY
X-Servedbyhost
X-Rocket-Nginx-Serving-Static
X-Zone
MIME-Version
X-PF-Uncompressing
X-NC
Cache-Hits
X-Render-Time
X-LSADC-Cache
X-Ua-Browser
X-Srv
XServer
X-Content
X-Minions-Version
X-Traceid
X-Varnish-Url
X-SD-PageType
X-Platform-Processor
X-Platform-Cluster
X-Platform-Router
X-ID
X-Cache-Remote
X-LB-ID
X-Vc
X-Datadog-Sampling-Priority
Environment
X-Datadog-Trace-Id
X-Datadog-Parent-Id
WebServer
X-ZONE
X-Refresh
Powered-By-ChinaCache
X-Gdpr
X-Nyt-Route
X-Origin-Time
X-API-Version
X-PJAX-URL
X-Wa
X-BBC-Origin-Response-Status
X-Cache-Var
My-App
X-Cache-Var-Map
Cluster
X-TIME
X-Internal-Host
X-NodeID
X-Server-IP
X-Pass-Why
X-Cache-Config
Memory
X-Webkit-Csp
X-Via-Ucdn
Server-ID
Time
X-App
X-Newrelic-Synthetics
X-Webkit-CSP-Report-Only
Candidate-Md5Url
X-VCL-Version
X-TX-ID
HostName
X-Pod-Name
X-Dynatrace
X-NewRelic-App-Data
X-OVcl
X-OVcl-Cache
GeoIp-Country-Code
Geoip-Latitude
Resin-Trace
Datacenter
X-CLOUD-TRACE-CONTEXT
Hostname
X-Edge-Pop
X-ElasticPress-Query
Cf-Bgj
X-LI-Proto
Geo-Info
N-Cache
X-Tb-Optimization-Total-Bytes-Saved
Web-Mar-Region
X-VHOST
X-TraceId
X-Backend-TTL
Magicmarker
Onion-Location
Tcn
Ohc-File-Size
X-Origin-Response-Time
X-HITS
X-Akamai-Pragma-Client-IP
X-CACHE-AGE
X-Varnish-Beresp-TTL
X-Geo
X-Method
WWW-Authenticate
X-EIG-Tracking-Id
X-Dispatcher-Server
X-Varnish-Cacheable
X-Li-Proto
Servername
X-Esi
DB-Nickname
GeoIP-Country-Code
X-NODE
X-AB
X-Correlation-ID
X-IP
Proxy-Connection
CDN
X-MSEdge-Features
GeoIP-Latitude
X-Wix-Viewer-Type
Ssr
X-MSEdge-Flight
LB
Cdn
X-HostName
X-TIM-N
X-Dynatrace-Js-Agent
X-Fastly-Request-Id
X-Tid
X-Fpc
X-Vcl-Version
Redirect-Candidate
X-Cs
Cf-Ipcountry
CF-Cached-On
X-Request-Start
Server-Id
X-APP
X-Up
X-Node-Id
Tracecode
Lb
X-DynaTrace-JS-Agent
X-Tt-Logid
Pramga
X-Cache-Date
X-Trv-Group
X-HS-Status
X-Fastly-Backend-Reqs
X-WA
Sid
Is-Us
X-ND-Cache
X-MG-S
WZWS-RAY
X-Via-CDN
X-NGINX-Cache
X-Pjax-Url
X-Reqid
X-ServerName
X-Sn-Servicetimems
X-Cdn-Origin
X-Amz-Meta-Cb-Modifiedtime
Env
X-Webkit-Csp-Report-Only
Cteonnt-Length
X-FORWARDED-FOR
X-Nc
X-Core-Mission
X-Provided-By
X-VC
X-Check-Cacheable
X-Lb-Id
URI
X-CSRF-TOKEN
Ohc-Cache-HIT
X-ServedByHost
X-Via-PopN
X-Via-PopH
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-SERVER-NAME
Mime-Version
CloudFront-Viewer-Country
W
X-Cache-Expires
X-Cache-Backend
X-Via-PopV
X-UnsetCookies
Shield-Pop
CountryCode
X-SN
X-Pf-Uncompressing
Server-Ttl
Rt-Fastcgi-Cache
X-ECache
VivaBuild
Viewtype
X-Sucuri-Cache
X-Cdn-Forward
X-Acquia-Site
X-Cache-ASPX
X-Acquia-Application-Trace
X-Acquia-Application-UUID
CACHE
X-Region-Sid
X-RAMCache
X-Cache-Status-Check
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-Edge-POP
X-Acquia-Purge-Tags
X-Varnish-Authentication
X-Contensis-Viewer-Groups
X-LiteSpeed-Cache-Control
WP-Super-Cache
X-Fastly-Cache-Hits
X-Pad
X-Cdn-Request-ID
X-Dw-Trace-Id
X-Action
X-Swift-Error
Vha6-Origin
X-CUA
X-Moov-Xdn-Version
Xc-Version
X-Moov-T
EpKe-Alive
Ohc-Response-Time
X-DB
ServerName
X-Webstats-RespID
X-RPS
X-RPM
X-RSL
X-Yottaa-OS
X-StackifyID
Xet-Cookie
X-DW
X-SB
Machine
X-DI
X-DSS
Srv
User-Agent
X-FPC
X-Ig-Push-State
Content-Script-Type
X-B3-Spanid
X-CF-Powered-By
Content-Style-Type
Req-ID
X-ElasticPress-Search
X-TH-Server
X-MiniProfiler-Ids