Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-XSS-Protection
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
P3P
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-UA-Compatible
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Request-Id
X-Xss-Protection
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Runtime
X-AspNet-Version
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Cache-Status
X-Generator
X-Cacheable
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Content-Security-Policy
X-Ua-Compatible
X-Request-ID
X-Iinfo
Content-Encoding
X-CDN
Feature-Policy
X-AspNetMvc-Version
Status
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Upgrade
Access-Control-Max-Age
X-Via
Keep-Alive
X-Ws-Request-Id
X-AH-Environment
X-Age
X-Robots-Tag
Request-Context
EagleId
X-Cache-Group
X-Turbo-Charged-By
X-Proxy-Cache
Server-Timing
X-Server
X-Backend
X-Hacker
X-Dns-Prefetch-Control
Host-Header
X-Server-Powered-By
Report-To
X-Amz-Request-Id
X-Nginx-Cache-Status
X-Amz-Id-2
Grace
X-UA-Device
X-Rq
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Page-Speed
X-OneAgent-JS-Injection
Cf-Railgun
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-CST
X-Amz-Version-Id
NEL
X-Cache-Spec
Allow
X-Vhost
X-Host
X-Backend-Server
X-WebKit-CSP
X-ASPNET-VERSION
X-Server-Id
X-Dispatcher
EagleEye-TraceId
Surrogate-Control
X-Node
Xkey
Request-Id
X-Response-Time
Content-Location
Accept-CH
X-Akam-SW-Version
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Ruxit-JS-Agent
P3p
X-Cache-Lookup
Accept-CH-Lifetime
X-Application-Context
X-Country
X-Ac
X-Mod-Pagespeed
X-Cloud-Trace-Context
X-Readtime
X-Template
X-Language
X-B3-TraceId
MS-Author-Via
X-HW
Rating
X-Url
X-Cnection
X-MS-InvokeApp
Accept-Ch-Lifetime
X-PC
X-Vname
X-TtlSet
X-Origin-Cache
Edge-Control
X-Clacks-Overhead
X-ESI
X-GitHub-Request-Id
X-Varnish-TTL
X-Trace
Accept-Ch
X-Middleton-Display
Response
Display
Pagespeed
X-Middleton-Response
X-Content-Type
X-Sol
X-D2id
Verso
Arr-Disable-Session-Affinity
X-FastCGI-Cache
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Kinja-Build
X-Kinja
X-Cdn-Fetch
X-GoogleNews-Bot
X-Exp-Variant
X-Exp-Id
X-Powered-By-Plesk
X-Goog-Hash
X-Vcap-Request-Id
X-Country-Code
X-Rack-Cache
X-Webkit-CSP
X-TTL
X-VARITI-CCR
X-ORACLE-DMS-RID
X-Navigation-Version
X-Amz-Rid
X-Abt-Application-Version
X-ORACLE-DMS-ECID
Fastly-Restarts
Service-Worker-Allowed
X-Server-Name
X-Fastly-Request-ID
X-Cached
X-Client-IP
X-Buckets
X-MSEdge-Ref
X-Release
Cache-Tag
X-Element-Page-Cache
X-Dw-Request-Base-Id
X-NF-Request-ID
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
Access-Control-Request-Method
RTSS
X-Cache-TTL
Public-Key-Pins
SPRequestGuid
X-SharePointHealthScore
SPRequestDuration
SPIisLatency
X-Edge
X-Ezoic-Cdn
AR-ATIME
Ar-Sid
AR-CACHE
AR-Request-ID
AR-PoweredBy
X-Powered-CMS
X-LLID
X-Upstream
X-Version
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
S
X-HP-Webp
X-Jurisdiction
Content-MD5
X-Kinsta-Cache
X-Recruiting
X-MCACHE
X-Mid
X-ECACHE
Charset
X-Mg-S
X-PressLabs-Stats
X-T
X-DynaTrace
X-Origin-Upstream-Status
X-Accel-Expires
Cache-Tags
X-Content-Digest
X-Forwarded-Proto
Fastcgi-Cache
Fusion-Component-Id
X-Litespeed-Cache
Fusion-Content-Id
Fusion-Template-Id
Fusion-Content-Source
Fusion-Deployment-Id
Fusion-Source
X-Content-Security-Policy-Report-Only
X-Px
X-Ttl
X-Correlation-Id
TP-Cache
TP-L2-Cache
X-Logged-In
Filters
Server-Node
Edge-Cache-Tag
Server-Name
TCN
X-Id
X-Amz-Server-Side-Encryption
X-Oneagent-Js-Injection
Front-End-Https
X-Request-Received
X-Forwarded-For
X-Request-Processing-Time
Nginx-Cache
X-Grace
MicrosoftSharePointTeamServices
X-XRDS-Location
X-Shield-Request-Id
Alternate-Protocol
X-Hits
X-Amzn-Trace-Id
X-B3-Sampled
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Server-ID
X-Microsite
X-Request-Handler-Origin-Region
X-NWS-LOG-UUID
X-Activity-Id
X-AppVersion
X-Az
X-Ruxit-Js-Agent
X-F-Cache
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Hub-Id
X-Amz-Replication-Status
X-HS-Combine-CSS
X-Origin-Server
X-Varnish-Age
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Debug
X-Frontend
X-RateLimit-Remaining
X-Rid
Nel
X-Daa-Tunnel
Realpath
Host
X-Yandex-Sdch-Disable
Section-Io-Cache
X-Cache-Age
Accept-Charset
X-Geo-Country
X-Hostname
X-Fastcgi-Cache
X-DIS-Request-ID
Surrogate-Key
X-Ser
X-Git-Hash
X-VCache
X-Respond-Thread
X-Time
Access-Control-Allow-Method
X-Contextid
X-Mobile-URL
X-WebKit-CSP-Report-Only
Cleartype
X-Source
MS-CV
X-Seen-By
X-XRDS-LOCATION
X-AOL-HN
X-Type
ServerID
X-Upgrade-Enabled
X-Route-Name
X-Request-Guid
X-LB-Cache
X-Aspnet-Duration-Ms
X-DataDome
X-Flags
X-Providence-Cookie
X-Is-Crawler
X-Varnish-Backend
Healthy
X-TT
Payment
Paypal-Debug-Id
X-Load-Cache
X-Signature
X-Whom
X-Cache-Action
X-B-Cache
X-IPLB-Instance
X-Content-Options
X-Debug-Info
X-N
X-Page-Id
X-Cache-Key
X-App-Environment
X-FB-Debug
Fastcgi-Useragent
Node
X-Jobs
Cache
X-Webkit-Csp
X-Rule
X-Cache-Expired-At
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Browser-Type
X-Mobile
Refresh
X-FireWall-Port
Viewport
X-Accel-Buffering
X-Response-Served-From
X-Wix-Request-Id
X-Original-Request-Id
X-RTag
Ms-Operation-Id
X-Cacheable-TTL
Access-Control-Request-Headers
X-HTML-Minification-Powered-By
X-Content-Powered-By
X-Real-IP
X-Cache-Control
X-Instance
X-Cluster-Name
X-Zen-Fury
X-B
X-Debug-IsConnected
X-Debug-IsPreview
X-Distributor
DC
X-RemovedCookies
X-UUID
X-ProcessESI
X-Page-View
Referer-Policy
X-Cache-Time
X-Proxy
Version
X-Tt-Trace-Tag
X-IPS-LoggedIn
X-Region
VIX-Pulpo-Upstream-Status
Eomportal-Instance
X-Framework
X-Drupal-Cache-Tags
VIX-Pulpo-Node
X-Tt-Trace-Host
X-Www-Served-By
X-Tec-Api-Root
X-Tec-Api-Origin
X-Tec-Api-Version
Countrycode
X-FTR-Request-ID
X-Protected-By
X-Drupal-Cache-Contexts
X-Nginx-Cache
X-FW-Static
X-FW-Type
X-App-Server
X-FW-Server
X-G
X-FW-Dynamic
X-FW-Serve
X-FW-Hash
X-Tumblr-Pixel-1
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Cached-By
X-Yottaa-Optimizations
X-Varnish-Grace
Liferay-Portal
X-Yottaa-Metrics
GEO-INFO
X-Via-JSL
CF-IPCountry
X-Cache-Rule
X-Cache-Operation
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
Section-Io-Origin-Status
Section-Io-Id
X-Pass-Why
Xserver
X-Environment-Context
X-L-Path
X-Device-Type
X-Akamai-Edgescape
SRV
X-Cache-Hit
X-TA-CDN-Provider
Powered-By-ChinaCache
Server-Info
X-Varnish-Server
Retry-After
X-Adobe-Content
X-Adobe-Loc
X-User-Agent
DynaTrace
X-TEC-API-ROOT
X-TEC-API-ORIGIN
Cache-Status
X-TEC-API-VERSION
Frame-Options
X-Pinterest-Direct
Ec-Rule-Version
Meta-Geo
X-Endurance-Cache-Level
X-UPSTREAM-Address
X-ES-SERVER
X-RN-RSRV
X-Hl-Ver
X-Tumblr-Pixel-2
X-Backend-Name
X-Mode
Fastly-SSL
Uber-Trace-Id
Webserver
X-Handled-By
X-FB-TRIP-ID
Cache-Tv-Group
X-Proxy-Cache-Status
From-Origin
Apigw-Requestid
X-ProxyCache-Status
Decoy-Debug-Key
Country
Webcakes-Region
X-ProxyCache-Key
X-Request-Time
TWC-Privacy
Decoy-Debug-Status
Decoy-Debug-TTL
Property-Id
X-Access
TWC-Connection-Speed
TWC-Device-Class
Webcakes-App-Name
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-GeoIP-Country
Webcakes-App-Version
X-NYM-Debug-Backend
X-Be
X-Varnishpool
X-MP-GENERATED-AT
X-BYPASS-REASON
X-Uri
X-Storage
X-Section
X-Format
X-WA-Info
X-Cache-Server
X-Origin-Hint
X-OCL
X-PCL
X-Sql-Count
X-Soup
X-LAGOON
X-Say-Cacheable
X-Say-TTL
X-UA-Device-Type
X-Server-W
X-TNCMS
X-Proto
Cache-Name
X-Info
X-Labrador-Cache-Channel
X-Sql-Duration-Ms
X-Timing-Wait
X-SayCDN-TTL
X-LJ-Flow-ID
Mn-Server-Ip
X-VWS-Id
X-Origin-Date
X-Via-Fastly
X-Web-Node
X-ApacheServer
X-Human
X-No-Session
X-Pubstack
X-Loop
X-PHP-Host
X-PERF
X-AWS-Id
X-S-Maxage
Selected-Fe
X-Proxy-Build
Azure-SlotName
Azure-SiteName
X-R9-Blue-Green-Version
Azure-Version
Azure-RegionName
X-GG-Cache-Date
X-Xfnlog-Site
Protected
X-Cache-TTL-Remaining
Azure-InstanceId
Amp-Access-Control-Allow-Source-Origin
X-ShardId
X-ShopId
X-Shopify-Stage
X-SRV
X-Alternate-Cache-Key
X-NWS-UUID-VERIFY
X-Sorting-Hat-PodId
X-Redis-Cache
X-Content-Age
X-Status
X-Storefront-Renderer-Rendered
X-Hosted-By
X-Sorting-Hat-ShopId
X-Hyper-Cache
X-Routing-Service
X-Is-Bot
X-Zipkin-Id
X-Proxied
X-Rendered-As
X-Cache-Enabled
X-Locale
X-Backend-Host
X-Azure-Ref
X-Site-Version
X-Cluster
X-FW-Version
S-Cnection
X-Microcachable
X-Cache-Grace
X-App-Version
X-TT-LOGID
X-Forwarded-Host
X-Ratelimit-Limit
X-AIR-PT
X-Platform
Akamai-GRN
X-CSRF-Token
X-Revision
X-Trace-Id
X-Varnish-Hostname
ServedBy
X-RateLimit-Limit
X-Cache-NGX
X-Qloud-Router
X-EdgeConnect-Cache-Status
X-Aspnetmvc-Version
X-Cache-PHP
X-ATG-Version
AMP-Access-Control-Allow-Source-Origin
Who
X-RCS-CacheZone
X-Debug-Cache
X-Via-CDN
Cache-Hits
X-Detected-As
Filterid
Country-Code
X-Akamai-Transformed
DB-Nickname
X-CCM
X-Dc
X-TX-ID
X-B3-SpanId
X-CS
X-Cache-Host
X-Node-Name
X-Adobe-Source
X-Amz-Apigw-Id
X-Amzn-Remapped-Content-Length
X-Amzn-RequestId
X-Varnish-Beresp-Grace
SD-X-WS
X-ID
X-CACHE-KEY
X-Unique-Id
X-BCube-Filmed-By
X-GEO
X-Ms-Request-Id
X-Ms-Version
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Status
Backend
X-Edge-Location-Klb
X-A-Ccd
X-A-Dam
X-A-Dcw
X-A-Wwc
X-A-Dgt
X-NAPM-TraceId
X-A
MD5-Digest
X-Oss-Server-Time
Mobile-Detection-Method
X-Oss-Request-Id
X-Oss-Object-Type
Meta-Geo-Continent
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
Odigeo-Trace-Id
Rendered-Blocks
T-Server
Machine
X-ARC
X-Connection-Hash
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-Cache-NE
X-D
BehaviorPad-Version
X-Generation-Time
X-External-Request-Id
X-Destination
X-Cache-Bucket
DCR-Decision-By
X-From
X-Application
X-Varnish-Cache-Hits
Fastly-Backend-Name
Fastcgi-X-Cache-Version
DCR-Processing-Time-Ms
X-B-Cookie
Expiry
X-Aed
X-Location
X-Request-UUID
X-Origin-TTL
X-Rewrite-Enabled
X-Rojux
X-Vtex-Remote-Cache
X-Nc
X-PBS-Appsvrname
X-PAYTM-SRV-ID
X-SRCache-Key
X-Trv-Group
X-Processor
X-S
X-VG-WebCache
X-Vdms-Path
X-Vdms-Version
X-Varnish-Ttl
X-S-Cookie
X-VG-WebServer
X-ScT
X-Session-Fingerprint
X-Vtex-Processado-Em
NGB
X-Origin-CC
X-Instrumentation
X-Kraken-Routeconfig-Destination
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Time-Microsecs
Wxu-Next-Hostname
X-Fetched-On
X-FC-Vary-Parameters
PB-PID
X-ServerID
Path
X-Magnolia-Registration
Release
X-Generated-On
X-Generated-In
CacheControlHeader
Wxu-Next-Commit
PB-RID
Wxu-Next-Region
X-Device-Os
Content-Disposition
X-Developers
AKAMAI
X-B3-Traceid
X-Var-Ttl
Gh-Request-Id
Host-ID
Cf-Device-Type
Arc-Version
Server-Host
X-Tumblr-Pixel-3
Pagetype
Thinkindot-CacheControl
X-Thinkindot-L3
X-TrackingId
X-Azure-Ref-OriginShield
X-Backend-TTL
X-IP
Thinkindot-Control
X-JWT-State
X-Policy
Thinkindot-CacheControl-Type
X-Is-Gdpr
X-Irp-Debug
X-Backend-State
X-Owner
V-Age
UCS
Esi-Enabled
X-Core-Value
X-Geo-Header
X-GeoIP-City
Ssr
X-Reqid
X-Cms-Context
Magicmarker
X-Has-Esi
X-Level-Front-Cache
X-APP-VERSION
User-Cache-Control
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Wikidot-Static-Cache
Sever-Int
Server-Hostname
X-Planisys-CDN-TTL
Server-Ext
X-Variation
X-Bip
X-Varnish-CookieHashed-On
True-Client-Country-4JS
X-Varnish-Hits
X-Varnish-Remaining-TTL
X-VServer
X-VarnishDD-TTL
X-Varnish-CookieINHashed-On
Web-Mar-Node
X-Wikidot-Backend
Vix-Hermes-Req-Id
X-Block-Status
X-VG-TLSProxy
X-Dispatcher-Server
X-Rebelmouse-Cache-Control
X-HS-Content-Campaign-Id
X-Ratelimit-Reset
X-Platform-Server
X-Li-Fabric
X-Rebelmouse-Surrogate-Control
X-Hnp-Log
X-GeoIP
X-Request-Host
X-GoCache-CacheStatus
X-HN
X-Li-Pop
X-LI-UUID
X-Origin
X-Nginx-Cache-Key
X-Node-Id
X-NU-AKA-ACS-Version
X-Origin-Expires
X-Mvc-Supplant-Cachable
X-OVcl-Cache
X-OVcl
X-Method
X-Origin-Response-Time
X-Request-URI
X-Generated-By
X-SVT-ORM-VERSION
X-Csrf-Jwt
X-SVT-ORM-RULES
X-DefElseHash
X-DefHash
X-Thanos
X-Clientip
X-User
X-Cache-Debug
X-Cache-Tags
X-CGP
X-Developer
X-Old-Content-Length
X-SIPLIST1
X-Fastly-Cache
X-Scheme
X-Gen-Mode
X-Fastly-Backend
X-Skip-Cache
X-DPWN-IS-SECURE
X-Envoy-Decorator-Operation
X-Epic-Correlation-Id
X-Eu-Site
X-Branch-Name
X-Cache-Info
CDN-EdgeStorageId
CDN-PullZone
CDN-CachedAt
CDN-Cache
CDCHOST
CDN-RequestCountryCode
CDN-RequestId
Fastly-SIE
Fastly-SWR
DSUID
Cf-Bgj
CDN-Uid
Cache-Host
C-Via
X-FTR-Cache-Status
X-FTR-Balancer
X-FTR-DC
X-FTR-Realm
HostName
X-FTR-Backend-Server
X-Country-Code-Real
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Apple-News-Services-Host
Apple-News-Services-Handled
Adler-Geo
Ha-Gx-Prefs
X-FTR-Backend
L
L5d-Success-Class
IsBot
Is-Eu
Origin
Platform
Location
PFcat
NGX
HA-Ipaddr
Locid
NM-Fastcgi-Cache
X-Amz-Meta-S3cmd-Attrs
X-NewRelic-App-Data
X-DynaTrace-JS-Agent
X-Hash
X-Gzip
X-Tb
X-EC-Lua
X-LB-ID
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Loc
X-Fmm-Version
X-Gamma-Serve
X-Slack-Backend
X-Clara-WADP
X-Esi-Check
Fastly-Drupal-HTML
Cmsid
Req-Svc-Chain
X-WADP-Cache
On-Server
Cmstype
X-Aicache-OS
X-Micro-Cache
Rt-Fastcgi-Cache
X-Cache-Id
X-Sucuri-ID
X-Ratelimit-Remaining
X-Correlation-ID
X-Unique-ID
X-Vgn-Hpd-Reason
X-Varnish-Url
Xc-Version
Kp-EeAlive
X-Swa-Ws
X-Servername
Svr
X-Via-Popn
X-Served-From
X-Mvc-Supplant-OutputCached
A
X-Via-Poph
X-Via-Popv
X-Air-Hostname
Pics-Label
X-FTR-Expires
Url
Viewtype
VivaBuild
X-DC
M-TraceId
X-Refresh
X-PF-Uncompressing
X-Cdn-Forward
X-SaId
X-JoinUs
X-PHP-Backend
X-NGENIX-Cache
SID
X-Edge-Location
Cross-Origin-Opener-Policy
Instruction
Cache-Key
SR-User-Adfree
Tracecode
Arc-Country
X-CDN-Forward
X-Cache-Var-Map
X-Cache-Var
TDXMobile
X-CUA
X-NC
Lfy
MIME-Version
X-Matched-Rule
X-Cdn-Origin
Content-Secure-Policy
X-Service
X-Tb-Optimization-Total-Bytes-Saved
NtCoent-Length
X-Vc
CloudFront-Viewer-Country
X-Cache-Expires
X-Sn-Servicetimems
X-NCache
Sid
X-Extlb
X-TraceId
X-CLOUD-TRACE-CONTEXT
X-Internal-Host
Server-ID
X-Cache-Backend
DataCenter
Pramga
X-Servedbyhost
X-Core-Mission
X-Wa
X-Bc-Bl
X-Cache-Date
Geo-Info
X-Forwarded-Site
Tcn
Source
X-Request-Start
Hostname
LB
X-B3-Spanid
X-LI-Proto
Memcached
X-Req
X-HS-Status
X-Webkit-CSP-Report-Only
Geoip-Latitude
Surrogated-Key
GeoIp-Country-Code
X-Proxy-Upstream
FSS-Cache
X-Srv
X-FireWall-Protection
X-Esi
Mail-Subject
X-VCL-Version
X-Error
We-Hiring
X-Via-NSCOPI
X-VC-Cache
X-Date
X-Accel-Expires-Debug
X-Newrelic-Synthetics
X-VHOST
Upgrade-Insecure-Requests
CACHE
X-Sigma-Backend
X-Sigma
X-Viewer-Country
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
Env
X-App
X-Rocket-Build-Number
X-Varnish-Cacheable
X-Response-By
X-HOST
X-Vcl-Version
X-Men
GeoIP-Latitude
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-Cache-Ttl
Request-ID
Resin-Trace
GeoIP-Country-Code
X-CCDN-Origin-Time
XServer
X-MSEdge-Features
X-PJAX-URL
X-Li-Proto
X-Air-Source
X-MSEdge-Flight
Server-Ttl
Time
Memory
X-Geo
X-Zone
X-LiteSpeed-Cache-Control
X-Mg-Request-UUID
CF-Cached-On
Xkeyi7
X-RPM
X-BBXSRF
X-TIM-N
X-RSL
X-RPS
X-DSS
X-DW
X-DI
X-DB
X-Proxy-Cachei7
X-ZONE
X-Cs
S-Rt
VNS-Age
X-RAMCache
CPC-Age
N-Cache
X-WA
X-APP
HitType
VNS-Cache
CPC-Cache
X-Cache-ASPX
Fastcgi-Cache-TTL
ProcessTime
X-Action
X-Air-Trace-Id
My-App
X-ServedByHost
X-Varnish-Authentication
State
X-Cache-2
X-Contensis-Viewer-Groups
X-HostName
D-Cc-Upstream
X-Oss-Cdn-Auth
X-Svr
X-Cc-Via
X-FPC
X-Cc-Req-Id
Server-Id
X-Minions-Version
X-Region-Sid
X-UA
X-Dynatrace-Js-Agent
X-Provided-By
X-Cache-Type
X-Swift-Error
Cache-Provider
W
X-Depends-On
X-FORWARDED-FOR
Mime-Version
Srv
X-Cdn-Request-ID
X-Origin-Time
X-Server-IP
X-UnsetCookies
X-API-Version
X-CF-Powered-By
X-TIME
CDN
X-URL
X-Cache-Config
X-Nyt-Route
X-Gdpr
OT-Force-Account-Verify
X-Dw-Trace-Id
X-BACKEND-TTL
X-Fpc
X-CSRF-TOKEN
X-Xrds-Location
X-Client-Ip
X-ServerName
Cteonnt-Length
X-Parent-Response-Time
X-Fastly-Request-Id
Proxy-Connection
X-Flog
X-Hello
Cdn
X-ABtesting
X-ND-Cache
X-VC
X-Forwarded-Path
X-Tenant
X-Shop-Environment
X-SERVER-NAME
X-Orig-Expires
X-Pf-Uncompressing
X-Sucuri-Cache
X-Cache-Remote
Cross-Origin-Window-Policy
Datacenter
Ohc-File-Size
X-Akamai-Pragma-Client-IP
X-Pad
Media-Length
X-Check-Cacheable
WZWS-RAY
X-NGINX-Cache
X-Fastly-Backend-Reqs
X-Oracle-DMS-ECID
Vha6-Origin
X-Presslabs-Stats
X-NodeID
X-Traceid
Dnion-Transfer-Encoding
X-SD-PageType
X-SN
X-Snapshot-Date
Ohc-Cache-HIT
X-Erf-Stays-Bingo-Pdp-Web
X-BBC-Edge-Cache-Status
X-Ftr-Request-Id
X-Cluster-Node
X-ElasticPress-Search
X-Ftr-Cache-Host
X-Via-PopH
X-LiteSpeed-Tag
X-Webstats-RespID
Cf-Ipcountry
X-Air-Pt
X-Via-PopN
X-SB
Epwk-X-Cache
PICS-Label
X-Via-PopV
X-MiniProfiler-Ids
X-Acquia-Site
X-Acquia-Purge-Tags
X-IN-APIGATEWAYSSL
X-Cache-Tag
X-Acquia-Application-Trace
Warning
X-Yottaa-OS
X-Conf
X-Pjax-Url
X-IN-APIGATEWAY
X-Host-Name
X-Akamai-ERRuleID
X-Akamai-ERPolicy
X-Vcache
X-Acquia-Application-UUID
Xet-Cookie
X-Ms-Meta-Originalurl
EpKe-Alive
X-Lb-Id
X-Varnish-URL
X-Ms-Meta-Staticbatchstarttime
CountryCode
X-Tx-Id
X-Render-Time
X-Redis-Duration-Ms
X-V-Cache
Inserted-Into-Cache-At
X-Redis-Count
Environment
Phost
Ohc-Response-Time
Count-Hit
X-Ckpd-Fst-Backend
X-C
X-Debug-Cache-Fetch
X-B3-Parentspanid
X-Varnish-Beresp-TTL
Content-Script-Type
Content-Style-Type
X-Debug-Cache-Store
NnCoection
X-Request-URL
X-Litespeed-Cache-Control
URI
X-Tid
X-Apw-Hits
X-Cache-Status-Check
X-Amz-Meta-Cb-Modifiedtime
X-Apw-Access-Token
X-Apw-Access-Object
X-BBC-Origin-Response-Status
X-Apw-Access-Action
X-Mg-Request-Id