Threat Level: green Handler on Duty: Russ McRee

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
Link
ETag
Pragma
Expect-CT
X-Powered-By
X-XSS-Protection
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
P3P
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Timer
X-Download-Options
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-Request-ID
X-Cache-Status
P3p
X-Generator
X-Cacheable
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Content-Security-Policy
X-Iinfo
Status
X-Ua-Compatible
Feature-Policy
Content-Encoding
X-AspNetMvc-Version
X-CDN
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
Upgrade
X-Dns-Prefetch-Control
X-Drupal-Dynamic-Cache
Access-Control-Max-Age
X-Via
Keep-Alive
X-Ws-Request-Id
X-Robots-Tag
Request-Context
Server-Timing
X-AH-Environment
X-Hacker
X-Server
X-Age
X-Turbo-Charged-By
X-Proxy-Cache
X-Server-Powered-By
X-Cache-Group
X-Backend
X-Amz-Request-Id
Host-Header
X-Amz-Id-2
EagleId
X-Nginx-Cache-Status
Report-To
X-LiteSpeed-Cache
X-Rq
X-Varnish-Cache
X-UA-Device
X-Page-Speed
Grace
X-Pingback
X-Swift-SaveTime
X-Swift-CacheTime
EagleEye-TraceId
Ali-Swift-Global-Savetime
X-Device
X-Vhost
X-OneAgent-JS-Injection
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Amz-Version-Id
NEL
X-Dispatcher
Cf-Railgun
X-Host
X-Cache-Spec
X-Server-Id
X-CST
X-WebKit-CSP
X-Node
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Backend-Server
Allow
Request-Id
Surrogate-Control
X-Readtime
X-Akam-SW-Version
X-Response-Time
Accept-CH
Accept-Ch-Lifetime
Xkey
X-HW
X-Ruxit-JS-Agent
X-Language
X-Country
X-Webkit-CSP
X-Application-Context
X-Template
X-Ac
Content-Location
X-Cache-Lookup
MS-Author-Via
Rating
X-Url
X-Cloud-Trace-Context
Edge-Control
X-B3-TraceId
X-Vname
X-TtlSet
X-PC
X-Mod-Pagespeed
X-Clacks-Overhead
Accept-Ch
X-Varnish-TTL
X-Trace
X-ESI
X-MS-InvokeApp
X-Content-Type
Fastly-Restarts
X-Rack-Cache
X-Origin-Cache
X-GitHub-Request-Id
X-Cnection
X-Buckets
X-Country-Code
X-Goog-Hash
Verso
X-D2id
X-VARITI-CCR
X-Exp-Id
X-Cdn-Fetch
X-Use-Magma
X-Kinja-Server
X-Kinja-Build
X-GoogleNews-Bot
X-Kinja
X-Exp-Variant
X-Kinja-Revision
Arr-Disable-Session-Affinity
X-FastCGI-Cache
X-ORACLE-DMS-ECID
X-Vcap-Request-Id
Cache-Tag
X-Cached
X-Server-Name
Service-Worker-Allowed
X-Abt-Application-Version
X-Client-IP
X-Amz-Rid
X-Server-ID
X-Navigation-Version
Accept-CH-Lifetime
X-Px
X-Powered-By-Plesk
RTSS
Public-Key-Pins
Access-Control-Request-Method
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Fastly-Request-ID
X-Powered-CMS
X-Element-Page-Cache
X-MSEdge-Ref
X-Cache-TTL
X-Upstream
X-Dw-Request-Base-Id
X-NF-Request-ID
X-Version
X-TTL
Response
Display
X-Middleton-Display
Pagespeed
X-Middleton-Response
X-Sol
S
X-Kinsta-Cache
X-Edge
X-Edge-Location-Klb
X-LLID
X-ECACHE
X-Ttl
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Kraken-Loop-Name
X-Kraken-Routeconfig-Destination
X-Instrumentation
X-Server-Lifecycle-Phase
X-Accel-Expires
Realpath
X-Jurisdiction
X-HP-Webp
X-Correlation-Id
SPRequestGuid
X-Shield-Request-Id
X-SharePointHealthScore
X-Pinterest-Rid
Pinterest-Generated-By
SPIisLatency
X-T
Pinterest-Version
SPRequestDuration
X-Mid
X-Cache-Key
X-MCACHE
X-PressLabs-Stats
X-Litespeed-Cache
X-Content-Security-Policy-Report-Only
X-ORACLE-DMS-RID
Edge-Cache-Tag
X-DynaTrace
Fastcgi-Cache
X-Forwarded-Proto
X-XRDS-Location
X-Amz-Server-Side-Encryption
X-Mg-S
X-Content-Digest
Nginx-Cache
X-Recruiting
TP-L2-Cache
TP-Cache
Charset
Filters
Front-End-Https
X-Id
X-Request-Processing-Time
X-Request-Received
Alternate-Protocol
Server-Node
X-Logged-In
TCN
X-Ezoic-Cdn
X-Forwarded-For
Content-MD5
X-Geo-Country
Cache-Tags
Fusion-Content-Id
Fusion-Source
Fusion-Deployment-Id
Fusion-Content-Source
Fusion-Template-Id
Fusion-Component-Id
X-ASPNET-VERSION
X-Protected-By
X-Amzn-Trace-Id
X-Grace
X-Origin-Upstream-Status
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Generation
X-GUploader-UploadID
X-NWS-LOG-UUID
X-Hostname
X-Goog-Stored-Content-Encoding
X-Www-Served-By
X-Origin-Server
X-F-Cache
Cleartype
X-Oneagent-Js-Injection
X-Amz-Replication-Status
X-Rid
X-Debug-Info
X-HS-Hub-Id
X-HS-Cache-Config
X-Release
X-HS-Content-Id
X-HS-Combine-CSS
X-LB-Cache
Host
X-AppVersion
X-Activity-Id
X-Az
X-Contextid
Section-Io-Cache
X-Daa-Tunnel
X-Page-Id
Server-Name
X-Browser-Type
X-Git-Hash
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Frontend
X-Ser
X-VCache
X-Respond-Thread
MicrosoftSharePointTeamServices
X-Aspnetmvc-Version
X-Ab
X-RateLimit-Remaining
X-Cache-Age
X-Ruxit-Js-Agent
X-Content-Options
Access-Control-Allow-Method
Accept-Charset
X-Upgrade-Enabled
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Hits
X-Mobile-URL
X-WebKit-CSP-Report-Only
X-DIS-Request-ID
X-Source
ServerID
X-B-Cache
X-Aspnet-Duration-Ms
X-Request-Guid
X-CACHE-GROUP
X-Signature
X-Providence-Cookie
X-Route-Name
X-Is-Crawler
X-Flags
X-Varnish-Backend
Payment
X-Cache-Action
X-Whom
Healthy
X-Varnish-Grace
X-Varnish-Age
X-TT
X-FB-Debug
Viewport
Paypal-Debug-Id
Node
X-Fastcgi-Cache
X-App-Environment
X-AOL-HN
DynaTrace
X-B3-Sampled
Fastcgi-Useragent
X-Load-Cache
Version
X-Yandex-Sdch-Disable
X-Seen-By
X-Mobile
X-N
DC
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-XRDS-LOCATION
X-HTML-Minification-Powered-By
X-Type
Filterid
X-Distributor
SRV
X-User-Agent
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
Frame-Options
Retry-After
X-Cache-Control
MS-CV
X-Jobs
Refresh
X-Cache-Expired-At
X-Response-Served-From
X-Original-Request-Id
X-UUID
X-Page-View
X-Adobe-Loc
X-Proxy-Cache-Status
NGB
X-Real-IP
X-IPLB-Instance
X-Adobe-Content
X-Varnish-Server
X-Instance
X-Region
X-Cluster-Name
X-FW-Serve
X-FW-Hash
X-FW-Dynamic
X-FW-Server
X-FW-Static
X-Debug-IsPreview
X-Debug-IsConnected
X-FW-Type
X-Device-Type
Access-Control-Request-Headers
X-RemovedCookies
X-ProcessESI
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-G
X-Framework
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-B
X-Cacheable-TTL
X-Content-Powered-By
X-Tumblr-User
X-Proxy
X-Vgn-Hpd-Reason
Ms-Operation-Id
X-IPS-LoggedIn
X-CDN-Forward
X-Cache-Time
X-RTag
X-NGENIX-Cache
X-Azure-Ref
Uber-Trace-Id
X-Zen-Fury
Amp-Access-Control-Allow-Source-Origin
X-Node-Name
AR-PoweredBy
AR-Request-ID
AR-CACHE
Ar-Sid
AR-ATIME
Countrycode
X-Cache-Hit
X-Wix-Request-Id
X-Cache-Rule
X-Microsite
X-Request-Handler-Origin-Region
Cache-Status
Section-Io-Origin-Status
Section-Io-Id
X-Ms-Version
X-Ms-Request-Id
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
X-Time
SD-X-WS
X-Is-Bot
X-Rendered-As
X-Mg-Request-UUID
X-Aws-Lambda-Call-Status
Liferay-Portal
X-Oracle-Dms-Rid
Referer-Policy
X-HP-Trace-Id
X-Debug
X-Drupal-Cache-Tags
X-Nginx-Cache
X-Accel-Buffering
X-App-Version
X-EdgeConnect-Cache-Status
X-Parallel-Accel
S-Cnection
Cache
Country
X-RateLimit-Limit
X-Environment-Context
X-L-Path
X-Revision
X-App-Server
CF-IPCountry
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Cache-Operation
Surrogate-Key
X-FireWall-Port
Count-Hit
X-TNCMS
X-TA-CDN-Provider
X-RN-RSRV
X-Loop
X-Endurance-Cache-Level
X-ES-SERVER
X-GG-Cache-Date
X-Drupal-Cache-Contexts
X-JoinUs
X-UPSTREAM-Address
X-SaId
Meta-Geo
Eomportal-Instance
X-SayCDN-TTL
From-Origin
X-LAGOON
X-Timing-Wait
X-Xfnlog-Site
X-Sorting-Hat-PodId
X-ShopId
X-Alternate-Cache-Key
X-Cache-TTL-Remaining
X-Cache-Type
X-ShardId
X-Storefront-Renderer-Rendered
X-Shopify-Stage
Selected-Fe
X-Sorting-Hat-ShopId
X-Proxy-Build
X-Adobe-Source
X-Say-TTL
X-Say-Cacheable
Country-Code
X-Varnishpool
X-Sql-Duration-Ms
Azure-Version
X-Sql-Count
X-Be
X-AWS-Id
X-Proto
X-Origin-Date
Azure-SlotName
X-BYPASS-REASON
X-Varnish-Hostname
X-ProxyCache-Key
X-LJ-Flow-ID
X-No-Session
X-Request-Time
Protected
X-ProxyCache-Status
Azure-RegionName
Azure-InstanceId
Cache-Name
X-Varnish-Beresp-Grace
X-Human
Akamai-GRN
X-FW-Version
X-NYM-Debug-Backend
X-S-Maxage
Azure-SiteName
X-VWS-Id
ServedBy
Cache-Tv-Group
Apigw-Requestid
Decoy-Debug-Key
Decoy-Debug-Status
Decoy-Debug-TTL
Fastly-SSL
X-Labrador-Cache-Channel
X-R9-Blue-Green-Version
X-PHP-Host
X-Akamai-Edgescape
X-Pubstack
X-OCL
X-RCS-CacheZone
X-PCL
X-UA-Device-Type
X-PHP-Backend
X-Hosted-By
X-Status
X-Cache-Server
X-Handled-By
TWC-GeoIP-Country
Webcakes-Region
X-Server-W
X-Backend-Name
TWC-Device-Class
X-Origin-Hint
X-Access
TWC-Connection-Speed
X-Uri
X-Section
X-Format
Webcakes-App-Name
X-Redis-Cache
TWC-Locale-Group
TWC-Privacy
Webcakes-App-Version
X-Tumblr-Pixel-2
X-Via-Fastly
X-Web-Node
X-Hl-Ver
X-Hyper-Cache
TWC-GeoIP-LatLong
Property-Id
X-Backend-Host
X-ApacheServer
Mn-Server-Ip
X-PERF
Nel
X-B3-SpanId
X-FB-TRIP-ID
X-Ua-Device
X-Time-Microsecs
X-ServerID
X-Cluster-Node
GEO-INFO
X-Servername
X-ATG-Version
OT-Force-Account-Verify
X-Cache-PHP
X-TEC-API-VERSION
X-APP-VERSION
X-TEC-API-ORIGIN
Xserver
X-TEC-API-ROOT
Cross-Origin-Opener-Policy
X-Tumblr-Pixel-3
X-TT-LOGID
X-Azure-Ref-OriginShield
X-Datadome
X-Detected-As
X-Trace-Id
Backend
X-CSRF-Token
X-Content-Age
X-WA-Info
Web-Mar-Node
X-MP-GENERATED-AT
X-Generation-Time
X-Varnish-Cache-Hits
X-Cache-Host
Cross-Origin-Window-Policy
X-CS
X-Ua
X-Varnish-Hits
X-Rule
Content-Secure-Policy
X-SRV
X-Akamai-Transformed
X-Bc-Bl
X-Soup
X-Cached-By
Ec-Rule-Version
X-Via-JSL
X-Cache-Enabled
X-Edge-Location
X-Ratelimit-Limit
Source
X-Amzn-Remapped-Content-Length
X-Amzn-RequestId
X-NWS-UUID-VERIFY
X-Mode
X-Amz-Apigw-Id
X-Info
X-Cache-Grace
S-Rt
X-Microcachable
X-Ratelimit-Remaining
X-Origin-CC
X-Origin-TTL
X-Varnish-Beresp-Status
X-Forwarded-Host
X-Locale
Upgrade-Insecure-Requests
Url
X-Magnolia-Registration
X-B3-Traceid
AMP-Access-Control-Allow-Source-Origin
X-Air-Hostname
X-Cache-NGX
SID
X-Air-Source
X-Air-Trace-Id
X-Dc
X-Storage
X-EC-Lua
X-Tb
X-Site-Version
X-Debug-Cache
X-Varnish-Beresp-Ttl
X-Conf
X-VG-WebCache
Expiry
Apple-News-Services-Handled
X-NU-AKA-ACS-Version
X-VG-WebServer
CDN-EdgeStorageId
X-NAPM-TraceId
X-AIR-PT
X-A-Wwc
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
X-Connection-Hash
X-Orig-Expires
X-A-Dgt
CDN-RequestCountryCode
X-Vdms-Version
Req-Svc-Chain
CDN-PullZone
Apple-News-Services-Request-Url
Fastcgi-X-Cache-Version
CDN-CachedAt
X-Destination
X-Zipkin-Id
X-Aicache-OS
X-CF-Lambda-Fn
X-Aed
A
Fastly-SWR
Fastly-SIE
X-CF-Lambda-Version
T-Server
X-Ftr-Request-Id
X-From
X-Vtex-Processado-Em
Host-ID
CDN-Cache
X-Cache-NE
X-Vtex-Remote-Cache
X-PAYTM-SRV-ID
X-GoCache-CacheStatus
CDCHOST
X-Forwarded-Path
Content-Disposition
X-A-Dam
X-Rojux
X-Epic-Correlation-Id
X-Routing-Service
X-S
X-S-Cookie
Odigeo-Trace-Id
X-Rewrite-Enabled
X-Clientip
Surrogated-Key
X-Request-URI
MD5-Digest
State
Rendered-Blocks
X-Session-Fingerprint
X-Shop-Environment
DCR-Decision-By
Mobile-Detection-Method
Meta-Geo-Continent
X-B-Cookie
X-ScT
X-BCube-Filmed-By
DCR-Processing-Time-Ms
X-SRCache-Key
X-A-Dcw
X-Tenant
X-A
X-Processor
X-Proxied
Path
X-D
X-Extlb
X-Unique-Id
X-Platform-Server
User-Cache-Control
CDN-RequestId
X-A-Ccd
BehaviorPad-Version
M-TraceId
X-ARC
X-Rebelmouse-Cache-Control
CDN-Uid
X-Rebelmouse-Surrogate-Control
X-Application
X-Ratelimit-Reset
X-External-Request-Id
X-Developer
X-Cache-Bucket
X-PBS-Appsvrname
X-GEO
X-Cache-Ttl
X-Cms-Context
DSUID
L
Origin
X-Fastly-Backend
X-Fastly-Cache
X-Date
X-Envoy-Decorator-Operation
X-DPWN-IS-SECURE
NGX
PB-PID
PB-RID
X-Core-Value
Platform
Fastly-Drupal-HTML
Pics-Label
X-Forwarded-Site
X-Fmm-Version
Is-Eu
Fastly-Backend-Name
X-Cache-Debug
X-Service
X-Sigma
X-Sigma-Backend
X-Backend-State
X-Bip
X-Rocket-Build-Number
X-Proxy-Upstream
X-Request-Host
X-Request-UUID
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Accel-Expires-Debug
X-VServer
X-WADP-Cache
X-BBC-Edge-Cache-Status
X-VG-TLSProxy
X-Variation
X-Platform
X-Thanos
X-TrackingId
UCS
X-Origin-Expires
X-Has-Esi
Arc-Version
X-Hash
Adler-Geo
X-Is-Gdpr
C-Via
X-Clara-WADP
Cmstype
Cmsid
Cache-Key
Cache-Host
X-JWT-State
X-Li-Fabric
X-Cache-Tags
X-Cache-Info
X-Loc
X-Men
X-Li-Pop
X-LI-UUID
X-Amz-Meta-S3cmd-Attrs
X-DefElseHash
X-Cluster
X-Branch-Name
X-CGP
X-Csrf-Jwt
X-Block-Status
X-Nginx-Cache-Key
X-Scheme
X-Served-From
X-SIPLIST1
X-Slack-Backend
X-Req
X-RateLimit-Remaining-Second
X-Origin
X-Policy
X-RateLimit-Limit-Second
X-Thinkindot-L3
X-Var-Ttl
X-Via-NSCOPI
X-Viewer-Country
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-VC-Cache
X-VarnishDD-TTL
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Old-Content-Length
X-Mvc-Supplant-Cachable
X-Gamma-Serve
X-Gen-Mode
X-Generated-By
X-Generated-In
X-FC-Vary-Parameters
X-Eu-Site
X-Developers
X-Device-Os
X-Esi-Check
X-Generated-On
X-Geo-Header
X-Irp-Debug
X-Level-Front-Cache
X-Location
X-Micro-Cache
X-Hnp-Log
X-HN
X-GeoIP
X-GeoIP-City
X-Gzip
X-DefHash
X-Cache-Id
NM-Fastcgi-Cache
X-DC
Locid
Location
Pagetype
PFcat
Server-Host
Server-Ext
Release
L5d-Success-Class
IsBot
CPC-Cache
CPC-Age
Cf-Device-Type
CacheControlHeader
Esi-Enabled
Fastcgi-Cache-TTL
HA-Ipaddr
Ha-Gx-Prefs
Gh-Request-Id
Server-Hostname
Mail-Subject
Thinkindot-Control
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
True-Client-Country-4JS
Vix-Hermes-Req-Id
We-Hiring
VNS-Cache
TDXMobile
VNS-Age
Sever-Int
Server-Info
AKAMAI
X-DataDome
X-CLOUD-TRACE-CONTEXT
X-Planisys-CDN-TTL
X-Sucuri-ID
Wxu-Next-Commit
X-Worker
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Skip-Cache
Wxu-Next-Region
Wxu-Next-Hostname
Arc-Country
X-Fetched-On
Memcached
X-Planisys-CDN-Cache
NtCoent-Length
X-Unique-ID
Svr
X-Owner
Kp-EeAlive
X-Vdms-Path
V-Age
X-Planisys-CDN-Rules
Webserver
X-Ckpd-Fst-Backend
DataCenter
X-Qloud-Router
X-HS-Content-Campaign-Id
X-M-Reqid
X-M-Log
X-Auto-Login
X-NCache
Who
X-V-Cache
X-Mvc-Supplant-OutputCached
X-Via-Poph
X-Via-Popn
X-Qnm-Cache
X-Tx-Id
X-User
X-Via-Popv
Cache-Hits
X-Content
X-Ua-Browser
X-CACHE-KEY
X-Render-Time
X-Platform-Cluster
X-Platform-Processor
X-Platform-Router
X-PF-Uncompressing
MIME-Version
X-Servedbyhost
X-NC
X-Zone
X-Rocket-Nginx-Serving-Static
X-LSADC-Cache
XServer
X-Srv
X-Varnish-Url
X-Traceid
X-SD-PageType
X-Minions-Version
X-Cache-Remote
X-ID
X-Datadog-Sampling-Priority
Environment
X-Datadog-Parent-Id
X-LB-ID
X-Datadog-Trace-Id
X-Vc
WebServer
X-Varnish-Ttl
X-Cache-Var
My-App
Powered-By-ChinaCache
X-ZONE
X-Cache-Var-Map
X-Refresh
X-Origin-Time
X-Gdpr
X-API-Version
X-NodeID
X-Nyt-Route
X-PJAX-URL
X-Wa
X-BBC-Origin-Response-Status
X-Server-IP
X-Pass-Why
X-TIME
Time
X-Cache-Config
X-Via-Ucdn
Server-ID
X-App
Cluster
Memory
X-Webkit-Csp
X-Internal-Host
X-Newrelic-Synthetics
X-VCL-Version
Candidate-Md5Url
X-TX-ID
X-Pod-Name
X-Webkit-CSP-Report-Only
Geo-Info
Tcn
HostName
X-NewRelic-App-Data
X-Dynatrace
Datacenter
X-OVcl
X-OVcl-Cache
Resin-Trace
Geoip-Latitude
GeoIp-Country-Code
Hostname
X-ElasticPress-Query
Web-Mar-Region
X-LI-Proto
X-Edge-Pop
Cf-Bgj
N-Cache
X-Tb-Optimization-Total-Bytes-Saved
X-TraceId
X-Backend-TTL
X-VHOST
Magicmarker
Onion-Location
X-Geo
Ohc-File-Size
X-Origin-Response-Time
X-HITS
X-CACHE-AGE
X-Akamai-Pragma-Client-IP
X-HostName
X-Varnish-Beresp-TTL
X-Li-Proto
X-Method
X-Dispatcher-Server
X-EIG-Tracking-Id
WWW-Authenticate
Servername
X-Varnish-Cacheable
X-Esi
DB-Nickname
GeoIP-Country-Code
Proxy-Connection
X-NODE
X-AB
X-Correlation-ID
GeoIP-Latitude
X-MSEdge-Flight
X-MSEdge-Features
CDN
X-IP
Ssr
X-Wix-Viewer-Type
Cdn
LB
X-Dynatrace-Js-Agent
X-Fpc
X-TIM-N
Redirect-Candidate
X-Fastly-Request-Id
X-Tid
X-Vcl-Version
Cf-Ipcountry
CF-Cached-On
Server-Id
X-Up
X-Request-Start
Tracecode
X-APP
Lb
X-Node-Id
X-Tt-Logid
X-Cs
X-DynaTrace-JS-Agent
X-ND-Cache
Sid
X-HS-Status
X-WA
X-Trv-Group
X-Fastly-Backend-Reqs
X-Cache-Date
Is-Us
Pramga
X-MG-S
X-Sn-Servicetimems
X-ServerName
X-Amz-Meta-Cb-Modifiedtime
Cteonnt-Length
X-Pjax-Url
X-NGINX-Cache
X-Reqid
X-Webkit-Csp-Report-Only
Env
WZWS-RAY
X-Via-CDN
X-Cdn-Origin
X-Nc
X-FORWARDED-FOR
X-Lb-Id
W
URI
X-VC
X-Check-Cacheable
X-Core-Mission
X-Provided-By
X-UnsetCookies
Ohc-Cache-HIT
X-CSRF-TOKEN
X-Via-PopN
X-ServedByHost
X-SERVER-NAME
X-IN-APIGATEWAY
X-Via-PopV
X-Cache-Backend
X-IN-APIGATEWAYSSL
X-Cache-Expires
CloudFront-Viewer-Country
Mime-Version
X-Via-PopH
Shield-Pop
CountryCode
Server-Ttl
WP-Super-Cache
Rt-Fastcgi-Cache
Viewtype
X-Pf-Uncompressing
X-SN
VivaBuild
X-Fastly-Cache-Hits
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Acquia-Site
CACHE
X-RAMCache
X-Hcs-Proxy-Type
X-Region-Sid
X-Sucuri-Cache
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-Edge-POP
X-Cache-Status-Check
X-LiteSpeed-Cache-Control
X-Acquia-Purge-Tags
X-Varnish-Authentication
X-Cache-ASPX
X-Contensis-Viewer-Groups
X-Pad
X-Cdn-Request-ID
X-StackifyID
X-Action
X-Dw-Trace-Id
Vha6-Origin
ServerName
X-Moov-T
X-Moov-Xdn-Version
Xc-Version
X-CF-Powered-By
EpKe-Alive
X-DI
Ohc-Response-Time
X-CUA
X-DB
X-RSL
X-DSS
X-Webstats-RespID
X-SB
X-Swift-Error
Xet-Cookie
X-RPM
X-RPS
Machine
X-DW
X-Yottaa-OS
X-Cdn-Forward
User-Agent
X-FPC
X-Ig-Push-State
Content-Style-Type
X-TH-Server
Content-Script-Type
X-ElasticPress-Search
Req-ID
X-MiniProfiler-Ids