Threat Level: green Handler on Duty: Russ McRee

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
CF-RAY
Cf-Request-Id
CF-Cache-Status
Last-Modified
X-XSS-Protection
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-UA-Compatible
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Xss-Protection
X-Cache-Status
X-Generator
X-Request-ID
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
X-Ua-Compatible
X-Iinfo
X-Content-Security-Policy
Content-Encoding
X-CDN
X-Envoy-Upstream-Service-Time
Status
Feature-Policy
X-AspNetMvc-Version
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Access-Control-Max-Age
X-Via
Upgrade
Keep-Alive
X-Ws-Request-Id
X-Age
X-Turbo-Charged-By
X-AH-Environment
X-Robots-Tag
Request-Context
X-Proxy-Cache
EagleId
X-Cache-Group
Server-Timing
X-Backend
X-Hacker
Report-To
X-Amz-Request-Id
X-Server
Host-Header
X-Amz-Id-2
X-Server-Powered-By
Grace
X-Nginx-Cache-Status
X-UA-Device
X-LiteSpeed-Cache
X-Varnish-Cache
X-Rq
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Page-Speed
X-Dns-Prefetch-Control
Cf-Railgun
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
NEL
X-Amz-Version-Id
X-OneAgent-JS-Injection
X-WebKit-CSP
X-Cache-Spec
Xkey
Allow
X-Backend-Server
X-CST
X-Host
X-Device
X-Vhost
EagleEye-TraceId
X-Server-Id
Surrogate-Control
Request-Id
X-Dispatcher
X-Node
Content-Location
X-Response-Time
X-Akam-SW-Version
Accept-CH
X-Ruxit-JS-Agent
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Accept-CH-Lifetime
X-ASPNET-VERSION
X-Ac
X-Template
X-Application-Context
X-Language
X-Country
X-Cache-Lookup
X-Readtime
X-Mod-Pagespeed
X-Cloud-Trace-Context
MS-Author-Via
X-B3-TraceId
X-Origin-Cache
Accept-Ch
Rating
X-Cnection
X-MS-InvokeApp
X-Kinja-Server-Push
X-HW
X-Url
Accept-Ch-Lifetime
X-PC
X-Vname
X-TtlSet
X-ORACLE-DMS-ECID
X-Clacks-Overhead
X-ESI
X-GitHub-Request-Id
Edge-Control
X-Trace
X-Middleton-Response
X-Sol
Pagespeed
Response
X-Middleton-Display
Display
X-FastCGI-Cache
X-Content-Type
X-Vcap-Request-Id
X-D2id
X-Kinja
Arr-Disable-Session-Affinity
X-Kinja-Revision
X-Exp-Variant
X-Cdn-Fetch
X-Exp-Id
X-Kinja-Server
X-GoogleNews-Bot
X-Kinja-Build
Verso
X-Use-Magma
X-Goog-Hash
X-Buckets
X-Rack-Cache
X-Server-Name
X-Country-Code
X-Oneagent-Js-Injection
Service-Worker-Allowed
X-Navigation-Version
X-ORACLE-DMS-RID
X-Abt-Application-Version
X-Varnish-TTL
X-VARITI-CCR
X-Amz-Rid
X-Powered-By-Plesk
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
X-Cache-TTL
X-Client-IP
X-Fastly-Request-ID
SPRequestGuid
X-SharePointHealthScore
X-Release
X-MSEdge-Ref
SPIisLatency
SPRequestDuration
X-Dw-Request-Base-Id
Fastly-Restarts
X-Element-Page-Cache
X-Cached
X-NF-Request-ID
Public-Key-Pins
X-TTL
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
RTSS
X-Webkit-CSP
AR-Request-ID
AR-ATIME
X-Edge
AR-CACHE
Ar-Sid
AR-PoweredBy
Access-Control-Request-Method
X-Origin-Upstream-Status
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-LLID
X-Px
X-Ttl
X-Powered-CMS
Fusion-Source
Fusion-Content-Source
Fusion-Component-Id
Fusion-Deployment-Id
Fusion-Template-Id
Fusion-Content-Id
X-Ezoic-Cdn
X-Upstream
Content-MD5
X-HP-Webp
X-Jurisdiction
X-Mid
X-ECACHE
X-MCACHE
Cache-Tag
Charset
X-Recruiting
X-Amz-Server-Side-Encryption
S
X-Content-Digest
X-Mg-S
X-Pinterest-Direct
X-Version
X-PressLabs-Stats
MicrosoftSharePointTeamServices
Fastcgi-Cache
TCN
Front-End-Https
X-Debug
X-Content-Security-Policy-Report-Only
X-T
X-Kinsta-Cache
X-Id
X-Grace
Filters
Cache-Tags
Server-Node
Edge-Cache-Tag
X-Accel-Expires
X-Forwarded-Proto
X-Logged-In
X-Correlation-Id
X-Forwarded-For
X-Amzn-Trace-Id
Server-Name
X-Yandex-Sdch-Disable
Nginx-Cache
Surrogate-Key
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Varnish-Age
X-DynaTrace
X-XRDS-Location
TP-Cache
TP-L2-Cache
X-B3-Sampled
X-Request-Received
X-Request-Processing-Time
X-Ser
X-Server-ID
X-Microsite
X-Request-Handler-Origin-Region
X-Hits
X-DIS-Request-ID
X-Cache-Key
X-Shield-Request-Id
X-AppVersion
Powered-By-ChinaCache
X-Az
X-Activity-Id
X-Amz-Replication-Status
X-F-Cache
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Hub-Id
X-HS-Cache-Config
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Litespeed-Cache
X-Origin-Server
Accept-Charset
X-Git-Hash
X-FTR-Request-ID
X-Geo-Country
X-Respond-Thread
X-XRDS-LOCATION
X-LB-Cache
X-Hostname
Section-Io-Cache
X-DataDome
X-Upgrade-Enabled
X-Frontend
Cache
X-Rid
Access-Control-Allow-Method
Alternate-Protocol
X-Ruxit-Js-Agent
X-Aspnetmvc-Version
X-Mobile-URL
X-Cache-Age
Host
Cleartype
Paypal-Debug-Id
MS-CV
X-IPLB-Instance
X-Type
X-Content-Options
Healthy
X-AOL-HN
X-Varnish-Backend
X-Seen-By
X-Whom
X-App-Environment
X-VCache
X-WebKit-CSP-Report-Only
ServerID
Payment
X-Route-Name
X-Signature
X-TT
X-Request-Guid
X-Is-Crawler
X-B-Cache
X-Cache-Action
X-Debug-Info
X-Flags
X-Aspnet-Duration-Ms
X-Providence-Cookie
X-Page-Id
X-Jobs
Fastcgi-Useragent
X-Time
X-NWS-LOG-UUID
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Source
X-Fastcgi-Cache
X-TEC-API-ORIGIN
X-Mobile
X-N
X-Load-Cache
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Browser-Type
X-Via-JSL
X-Daa-Tunnel
X-FB-Debug
Nel
X-RateLimit-Remaining
X-Cached-By
X-Akamai-Edgescape
Version
X-Cache-Operation
X-Cache-Rule
Refresh
Viewport
X-Response-Served-From
X-Rule
X-Original-Request-Id
X-Accel-Buffering
X-Proxy
DC
X-Zen-Fury
X-Framework
X-Drupal-Cache-Tags
DynaTrace
X-ProcessESI
X-Cacheable-TTL
Ms-Operation-Id
X-RTag
X-RemovedCookies
X-Instance
X-Wix-Request-Id
Access-Control-Request-Headers
X-Contextid
X-Real-IP
Referer-Policy
X-UUID
X-HTML-Minification-Powered-By
X-Tt-Trace-Tag
Realpath
X-Cache-Time
X-Tt-Trace-Host
X-Region
Node
X-Distributor
X-Page-View
X-Drupal-Cache-Contexts
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Cache-Expired-At
Eomportal-Instance
X-FW-Type
X-FW-Static
X-FW-Server
X-FW-Hash
VIX-Pulpo-Upstream-Status
X-FW-Dynamic
X-FW-Serve
Countrycode
VIX-Pulpo-Node
X-Environment-Context
X-B
X-L-Path
X-Cluster-Name
GEO-INFO
X-Cache-Control
X-Tumblr-User
Liferay-Portal
X-IPS-LoggedIn
X-G
X-Content-Powered-By
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Cache-Hit
X-Node-Name
X-User-Agent
Server-Info
X-Ratelimit-Limit
X-Varnish-Ttl
Webserver
X-Tumblr-Pixel-2
Section-Io-Origin-Time-Seconds
Section-Io-Id
Section-Io-Origin-Status
Section-Origin-Responded
X-App-Server
From-Origin
X-Pass-Why
Protected
X-FireWall-Port
X-Amz-Meta-S3cmd-Attrs
SRV
Ec-Rule-Version
X-Protected-By
X-Revision
X-Cache-Server
Frame-Options
X-Backend-Name
CF-IPCountry
X-ES-SERVER
X-Www-Served-By
X-Hyper-Cache
X-RN-RSRV
X-UPSTREAM-Address
X-Endurance-Cache-Level
Meta-Geo
Cache-Status
X-Mode
X-Hl-Ver
X-Handled-By
X-NYM-Debug-Backend
X-Site-Version
X-Locale
Xserver
X-Soup
X-FB-TRIP-ID
X-Storage
X-Forwarded-Host
X-Cache-Grace
X-Pubstack
X-Varnishpool
X-Web-Node
X-Be
Decoy-Debug-Status
Decoy-Debug-TTL
Fastly-SSL
Decoy-Debug-Key
Country
X-Human
Cache-Tv-Group
Retry-After
Azure-RegionName
Azure-Version
Azure-SlotName
Azure-SiteName
Azure-InstanceId
X-Origin-Hint
X-ProxyCache-Status
X-Uri
X-UA-Device-Type
X-ProxyCache-Key
X-BYPASS-REASON
X-Proto
X-Proxy-Build
X-TT-LOGID
X-Timing-Wait
X-SayCDN-TTL
X-Section
X-Format
X-Say-Cacheable
X-Redis-Cache
X-Say-TTL
X-Labrador-Cache-Channel
Webcakes-Region
TWC-Connection-Speed
TWC-Device-Class
Selected-Fe
Property-Id
Cache-Name
X-Origin-Date
TWC-GeoIP-Country
TWC-GeoIP-LatLong
Webcakes-App-Version
X-PHP-Host
Webcakes-App-Name
TWC-Privacy
TWC-Locale-Group
X-PCL
X-OCL
X-Access
X-Adobe-Loc
X-Adobe-Content
X-TNCMS
X-PERF
X-Via-Fastly
X-Server-W
X-Sql-Duration-Ms
X-AIR-PT
X-Sql-Count
X-Request-Time
X-ApacheServer
X-S-Maxage
X-FW-Version
X-Hosted-By
X-No-Session
X-WA-Info
X-Ratelimit-Remaining
X-Loop
X-LAGOON
X-MP-GENERATED-AT
X-AWS-Id
X-VWS-Id
X-R9-Blue-Green-Version
X-Via-CDN
X-LJ-Flow-ID
Mn-Server-Ip
X-Storefront-Renderer-Rendered
X-Status
X-Sorting-Hat-PodId
X-ShopId
X-ShardId
X-Qloud-Router
X-Alternate-Cache-Key
X-Shopify-Stage
X-Cluster
X-Sorting-Hat-ShopId
X-Proxied
X-Routing-Service
X-Country-Code-Real
X-CCM
X-FTR-Backend
S-Cnection
X-FTR-DC
X-FTR-Realm
X-Cache-TTL-Remaining
X-FTR-Cache-Status
X-Zipkin-Id
X-FTR-Backend-Server
X-FTR-Balancer
X-Xfnlog-Site
X-Is-Bot
Cache-Hits
X-Rendered-As
X-FTR-Expires
X-Tec-Api-Root
X-Tec-Api-Version
X-Tec-Api-Origin
X-Oracle-Dms-Rid
AMP-Access-Control-Allow-Source-Origin
X-Nginx-Cache
X-Device-Type
X-Dc
X-Cdn
X-Cache-Var-Map
Apigw-Requestid
X-Info
X-Detected-As
X-Cache-Var
X-Air-Hostname
X-Debug-IsConnected
X-SRV
X-Debug-IsPreview
X-Amzn-RequestId
X-EdgeConnect-Cache-Status
X-Cache-Host
X-Amz-Apigw-Id
X-Amzn-Remapped-Content-Length
X-Microcachable
X-Unique-Id
X-Cache-Enabled
X-Varnish-Grace
X-Content-Age
X-Dynatrace
SD-X-WS
X-Platform
X-Varnish-Server
X-DynaTrace-JS-Agent
Tracecode
X-GG-Cache-Date
X-Time-Microsecs
X-Azure-Ref
X-Backend-Host
Uber-Trace-Id
X-Cache-Backend
X-Backend-TTL
X-GEO
X-ServerID
X-Erf-Stays-Bingo-Pdp-Web
Amp-Access-Control-Allow-Source-Origin
X-APP-VERSION
X-CSRF-Token
X-Proxy-Cache-Status
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
Akamai-GRN
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Storage-Class
X-Tb
DSUID
Backend
X-BCube-Filmed-By
X-ATG-Version
X-NewRelic-App-Data
X-Correlation-ID
X-Trace-Id
PB-RID
Arc-Version
X-Akamai-Transformed
X-Sucuri-ID
PB-PID
X-NWS-UUID-VERIFY
ServedBy
X-Vdms-Version
X-Origin-TTL
Meta-Geo-Continent
MD5-Digest
X-Origin-CC
X-Cache-NGX
Pramga
X-Vdms-Path
Mobile-Detection-Method
X-External-Request-Id
X-Cache-PHP
X-D
Path
Odigeo-Trace-Id
Machine
X-Destination
X-Magnolia-Registration
Expiry
DCR-Decision-By
Fastcgi-X-Cache-Version
X-From
X-Fetched-On
X-Matched-Rule
X-Location
X-Varnish-Cache-Hits
Xc-Version
X-Level-Front-Cache
X-Generated-On
Release
Lfy
DCR-Processing-Time-Ms
X-Device-Os
Instruction
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
X-VG-WebServer
X-VG-WebCache
SR-User-Adfree
X-ARC
X-CF-Lambda-Fn
X-RCS-CacheZone
X-Application
X-SRCache-Key
Rendered-Blocks
BehaviorPad-Version
X-CF-Lambda-Version
X-B-Cookie
X-Generation-Time
X-S-Cookie
X-S
X-Rojux
X-GeoIP-City
X-Rewrite-Enabled
X-Session-Fingerprint
X-Cache-NE
X-ScT
X-A-Wwc
X-Aed
X-PBS-Appsvrname
Thinkindot-CacheControl-Type
Thinkindot-Control
X-A-Dgt
X-PAYTM-SRV-ID
Thinkindot-CacheControl
X-Varnish-Hostname
X-Request-UUID
T-Server
X-Connection-Hash
X-Processor
X-A
X-A-Dam
X-A-Ccd
X-A-Dcw
X-Trv-Group
X-Thinkindot-L3
X-Origin-Response-Time
CacheControlHeader
Cache-Host
C-Via
X-Geo-Header
X-GeoIP
X-Generated-In
Pagetype
X-Azure-Ref-OriginShield
X-CGP
UCS
Ssr
X-Cdn-Origin
X-Backend-State
X-Cache-Date
X-Bip
X-Cache-Info
X-Csrf-Jwt
AKAMAI
Fastly-Backend-Name
X-Eu-Site
Cf-Device-Type
Gh-Request-Id
Ha-Gx-Prefs
L5d-Success-Class
Host-ID
HA-Ipaddr
X-FC-Vary-Parameters
X-Has-Esi
X-SVT-ORM-RULES
X-VServer
X-Reqid
X-SVT-ORM-VERSION
X-Mvc-Supplant-Cachable
X-Sn-Servicetimems
X-Ms-Request-Id
X-Micro-Cache
X-Skip-Cache
X-Swa-Ws
X-Cache-Bucket
X-User
X-Tumblr-Pixel-3
X-B3-Traceid
X-Owner
X-OVcl-Cache
X-OVcl
X-Thanos
X-TrackingId
X-Ms-Version
X-Node-Id
X-HS-Content-Campaign-Id
X-JWT-State
X-Debug-Cache
X-Is-Gdpr
X-Irp-Debug
X-TA-CDN-Provider
X-Adobe-Source
X-Varnish-Hits
HostName
PFcat
X-IP
X-VarnishDD-TTL
NGX
X-CUA
On-Server
X-HN
Wxu-Next-Commit
X-Var-Ttl
X-Policy
X-Request-URI
V-Age
X-Cms-Context
Wxu-Next-Hostname
X-Core-Value
Server-Ext
X-Fastly-Backend
Server-Host
Server-Hostname
Sever-Int
Wxu-Next-Region
X-Developer
X-Request-Host
X-Wikidot-Backend
X-Envoy-Decorator-Operation
X-Origin-Expires
X-Wikidot-Static-Cache
DB-Nickname
CloudFront-Viewer-Country
Content-Disposition
X-Fastly-Cache
X-Generated-By
X-Cache-Tags
X-Nginx-Cache-Key
X-Developers
X-Scheme
Location
Magicmarker
Locid
X-Clientip
L
User-Cache-Control
X-TX-ID
X-ID
X-NAPM-TraceId
X-Clara-WADP
X-Servername
X-Rebelmouse-Surrogate-Control
X-SIPLIST1
X-Rebelmouse-Cache-Control
X-Request-Start
X-Cache-Expires
X-Slack-Backend
X-Cache-Id
X-DefHash
X-LI-UUID
X-Fmm-Version
X-Loc
X-Varnish-Beresp-Grace
X-Esi-Check
X-Method
X-Li-Pop
X-Gen-Mode
X-Gzip
X-GoCache-CacheStatus
X-Hash
X-Hnp-Log
X-Li-Fabric
X-DPWN-IS-SECURE
X-Dispatcher-Server
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Varnish-CookieHashed-On
X-Variation
X-Platform-Server
X-DefElseHash
X-Goog-Meta-Goog-Reserved-File-Mtime
X-NU-AKA-ACS-Version
X-WADP-Cache
X-Old-Content-Length
X-Origin
X-VG-TLSProxy
X-Ratelimit-Reset
X-Block-Status
NM-Fastcgi-Cache
IsBot
Is-Eu
Fastly-SWR
Web-Mar-Node
Vix-Hermes-Req-Id
True-Client-Country-4JS
Platform
Origin
Rt-Fastcgi-Cache
Fastly-SIE
X-Branch-Name
Apple-News-Services-Host
Apple-News-Services-Handled
Adler-Geo
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
CDCHOST
X-Cache-Remote
Cf-Bgj
X-B3-SpanId
X-Cdn-Forward
X-App-Version
CDN-PullZone
CDN-EdgeStorageId
CDN-RequestCountryCode
CDN-RequestId
X-Core-Mission
X-Gamma-Serve
CDN-CachedAt
X-NC
X-Varnish-Beresp-Ttl
X-Cache-Debug
X-Varnish-Beresp-Status
CDN-Cache
Fastly-Drupal-HTML
CDN-Uid
X-CS
X-PF-Uncompressing
Url
X-EC-Lua
X-Varnish-Url
X-Mvc-Supplant-OutputCached
X-NCache
Sid
X-Response-By
X-LB-ID
X-Aicache-OS
X-Host-Name
X-Varnish-Cacheable
X-Refresh
S-Rt
X-CACHE-GROUP
X-B3-Spanid
X-Proxy-Cachei7
Xkeyi7
Pics-Label
CACHE
X-Via-Popn
X-Via-Poph
X-Via-Popv
X-FireWall-Protection
N-Cache
X-BBXSRF
Esi-Enabled
Cross-Origin-Window-Policy
X-Unique-ID
X-Cache-2
Ohc-File-Size
X-Tb-Optimization-Total-Bytes-Saved
Content-Secure-Policy
X-Epic-Correlation-Id
X-Sucuri-Cache
X-Cache-ASPX
X-Cc-Req-Id
X-Contensis-Viewer-Groups
X-Cc-Via
X-Webkit-Csp
X-Varnish-Authentication
X-Nc
X-Error
D-Cc-Upstream
Cteonnt-Length
Who
X-Srv
X-CACHE-KEY
X-CDN-Forward
X-TraceId
Country-Code
Req-Svc-Chain
Source
X-Svr
X-Webkit-CSP-Report-Only
X-Server-IP
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
HitType
X-Servedbyhost
Geo-Info
GeoIp-Country-Code
X-Cs
Server-Ttl
X-DC
MIME-Version
X-Wa
X-Planisys-CDN-Cache
Geoip-Latitude
X-RateLimit-Limit
X-Nyt-Route
X-Cache-Config
X-Origin-Time
X-API-Version
X-Gdpr
X-FPC
X-HS-Status
X-CLOUD-TRACE-CONTEXT
X-URL
X-SN
Cmsid
Cmstype
Kp-EeAlive
Svr
X-VC
X-LiteSpeed-Cache-Control
Ohc-Cache-HIT
Hostname
X-Webstats-RespID
X-NGINX-Cache
X-Served-From
VivaBuild
Viewtype
X-LI-Proto
X-Esi
X-SB
X-NodeID
X-TIME
A
X-Check-Cacheable
Server-ID
Cache-Key
X-SD-PageType
X-Vcl-Version
XServer
X-VCL-Version
NtCoent-Length
X-HOST
SID
Resin-Trace
M-TraceId
Tcn
X-RAMCache
Server-Id
X-Render-Time
Request-ID
X-Vgn-Hpd-Reason
X-Viewer-Country
X-Li-Proto
X-Ua
X-UA
X-DB
Cache-Provider
EpKe-Alive
X-BBC-Edge-Cache-Status
X-Air-Source
X-RPS
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-TIM-N
TDXMobile
Cross-Origin-Opener-Policy
X-DI
Arc-Country
X-RSL
X-RPM
X-DW
X-DSS
Filterid
X-Worker
X-Internal-Host
GeoIP-Country-Code
X-Fastly-Request-Id
X-Auto-Login
GeoIP-Latitude
X-CF-Powered-By
X-HostName
X-Newrelic-Synthetics
X-Vc
X-ServedByHost
X-Action
Mime-Version
ProcessTime
X-App
X-WA
X-Ftr-Cache-Host
Processtime
Srv
X-CSRF-TOKEN
X-Geo
X-FTR-Cache-Host
Upgrade-Insecure-Requests
X-Cluster-Node
NGB
X-Service
CDN
X-Fpc
X-Oss-Cdn-Auth
X-Dynatrace-Js-Agent
X-FORWARDED-FOR
X-BBC-Origin-Response-Status
Datacenter
Proxy-Connection
CF-Cached-On
X-HITS
X-BACKEND-TTL
X-Via-NSCOPI
X-MSEdge-Features
X-MSEdge-Flight
Cdn
DataCenter
FSS-Cache
X-PHP-Backend
X-Fastly-Backend-Reqs
X-NGENIX-Cache
X-Forwarded-Site
X-JoinUs
X-Parent-Response-Time
X-Dw-Trace-Id
X-SaId
X-Client-Ip
X-Extlb
X-Cdn-Request-ID
X-CACHE-AGE
X-Edge-Location
PICS-Label
Dnion-Transfer-Encoding
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-ND-Cache
X-Via-PopV
X-Via-PopN
X-Via-PopH
X-ABtesting
X-Hello
X-Cache-Tag
OT-Force-Account-Verify
X-Flog
W
X-Provided-By
X-Swift-Error
X-Akamai-Pragma-Client-IP
WZWS-RAY
Mail-Subject
LB
Media-Length
Memcached
Surrogated-Key
X-Presslabs-Stats
X-Oracle-DMS-ECID
X-Pf-Uncompressing
X-Accel-Expires-Debug
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
Vha6-Origin
X-PJAX-URL
X-Region-Sid
X-Req
X-Lb-Id
X-VC-Cache
X-UnsetCookies
X-Depends-On
X-Proxy-Upstream
We-Hiring
X-Date
X-Bc-Bl
X-MiniProfiler-Ids
Epwk-X-Cache
Env
X-ZONE
X-Sigma-Backend
X-APP
Time
Memory
X-Pad
X-LiteSpeed-Tag
X-Rocket-Build-Number
X-Sigma
X-Zone
Cf-Ipcountry
X-Air-Trace-Id
X-Amz-Meta-Cb-Modifiedtime
X-Men
X-Varnish-URL
X-ElasticPress-Query
X-Request-URL
X-Varnish-Beresp-TTL
X-Csrf-Token
X-Akamai-ERPolicy
X-Litespeed-Cache-Control
X-Acquia-Site
URI
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
X-Request-Url
X-Akamai-ERRuleID
Xet-Cookie
X-Vcache
X-B3-Parentspanid
X-Ms-Meta-Originalurl
X-Ms-Meta-Staticbatchstarttime
X-Snapshot-Date
X-ElasticPress-Search
CountryCode
VNS-Cache
CPC-Age
X-Tid
CPC-Cache
VNS-Age
X-ServerName
X-Redis-Duration-Ms
X-Redis-Count
X-Traceid
NnCoection
Phost
X-Debug-Cache-Fetch
X-Debug-Cache-Store
Ohc-Response-Time
X-C
X-Storefront-Renderer-Verified
X-Akamai-Request-ID
Environment
Inserted-Into-Cache-At