Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-RAY
CF-Cache-Status
X-XSS-Protection
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-UA-Compatible
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Xss-Protection
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Request-ID
X-Cacheable
Timing-Allow-Origin
X-Ua-Compatible
X-Content-Security-Policy
X-Iinfo
Content-Encoding
X-CDN
Feature-Policy
X-AspNetMvc-Version
Status
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Upgrade
X-Via
Access-Control-Max-Age
Keep-Alive
X-Ws-Request-Id
X-Age
X-AH-Environment
X-Robots-Tag
X-Turbo-Charged-By
Request-Context
EagleId
X-Proxy-Cache
X-Cache-Group
Server-Timing
X-Backend
X-Hacker
X-Server
Report-To
Host-Header
X-Amz-Request-Id
X-Server-Powered-By
X-Amz-Id-2
Grace
X-Nginx-Cache-Status
X-UA-Device
X-Rq
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
X-LiteSpeed-Cache
X-Page-Speed
Cf-Railgun
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-OneAgent-JS-Injection
NEL
X-Cache-Spec
X-Amz-Version-Id
X-Device
X-CST
Allow
X-Vhost
X-WebKit-CSP
X-Host
Xkey
X-Backend-Server
X-Server-Id
EagleEye-TraceId
Surrogate-Control
X-Dispatcher
Request-Id
X-Node
Content-Location
X-Response-Time
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Akam-SW-Version
X-Ruxit-JS-Agent
P3p
X-ASPNET-VERSION
X-Application-Context
X-Ac
X-Cache-Lookup
Accept-CH
X-Country
X-Template
Accept-Ch
X-Language
Accept-CH-Lifetime
X-Mod-Pagespeed
X-Readtime
Accept-Ch-Lifetime
X-Cloud-Trace-Context
MS-Author-Via
X-B3-TraceId
Rating
X-Origin-Cache
X-HW
X-MS-InvokeApp
X-Cnection
X-Url
X-PC
X-Vname
X-TtlSet
X-Clacks-Overhead
X-GitHub-Request-Id
Edge-Control
X-Trace
X-ORACLE-DMS-ECID
X-ESI
X-ORACLE-DMS-RID
X-Sol
Display
Pagespeed
X-Content-Type
X-Middleton-Display
X-Middleton-Response
Response
X-D2id
Arr-Disable-Session-Affinity
X-Exp-Id
X-Exp-Variant
X-Cdn-Fetch
X-Kinja-Build
X-Use-Magma
X-Kinja-Server
X-Kinja-Revision
X-GoogleNews-Bot
X-Kinja
Verso
X-Vcap-Request-Id
X-Varnish-TTL
X-Goog-Hash
X-Rack-Cache
X-Country-Code
X-FastCGI-Cache
X-Buckets
X-Navigation-Version
X-Powered-By-Plesk
X-Server-Name
Service-Worker-Allowed
X-VARITI-CCR
X-Amz-Rid
X-Abt-Application-Version
X-Fastly-Request-ID
X-Webkit-CSP
X-TTL
X-Client-IP
X-Cache-TTL
Fastly-Restarts
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
X-Release
X-MSEdge-Ref
X-Cached
SPRequestGuid
X-SharePointHealthScore
X-Dw-Request-Base-Id
X-Element-Page-Cache
X-Oneagent-Js-Injection
X-NF-Request-ID
SPRequestDuration
SPIisLatency
Public-Key-Pins
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
RTSS
Access-Control-Request-Method
AR-CACHE
AR-PoweredBy
Ar-Sid
AR-Request-ID
AR-ATIME
X-Edge
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-LLID
X-Powered-CMS
X-Litespeed-Cache
X-Ezoic-Cdn
Cache-Tag
Content-MD5
X-Origin-Upstream-Status
X-Upstream
Fusion-Source
Fusion-Deployment-Id
X-HP-Webp
Fusion-Content-Source
X-Jurisdiction
Fusion-Template-Id
Fusion-Component-Id
X-Px
Fusion-Content-Id
S
X-Version
X-MCACHE
X-ECACHE
X-Mid
X-Recruiting
X-Mg-S
Charset
X-Content-Digest
X-PressLabs-Stats
X-Ttl
X-Kinsta-Cache
X-T
Fastcgi-Cache
X-Amz-Server-Side-Encryption
X-DynaTrace
Cache-Tags
MicrosoftSharePointTeamServices
Filters
X-Logged-In
X-Content-Security-Policy-Report-Only
Front-End-Https
X-Accel-Expires
Server-Node
Edge-Cache-Tag
X-Forwarded-Proto
X-Id
X-Debug
X-Correlation-Id
X-Grace
TP-L2-Cache
TCN
TP-Cache
Server-Name
Nginx-Cache
X-Amzn-Trace-Id
X-Forwarded-For
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Request-Received
Surrogate-Key
X-Request-Processing-Time
X-Hits
X-Varnish-Age
X-B3-Sampled
X-Shield-Request-Id
X-Request-Handler-Origin-Region
X-Microsite
X-Yandex-Sdch-Disable
X-Ser
X-Pinterest-Direct
X-AppVersion
X-Az
X-Activity-Id
X-Ruxit-Js-Agent
X-Amz-Replication-Status
X-Fastcgi-Cache
X-F-Cache
X-XRDS-LOCATION
X-XRDS-Location
X-HS-Hub-Id
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Content-Id
X-DIS-Request-ID
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Origin-Server
X-Geo-Country
Accept-Charset
Alternate-Protocol
X-Git-Hash
X-Cache-Key
X-Rid
X-Respond-Thread
X-Frontend
Section-Io-Cache
Cache
Host
X-LB-Cache
X-Upgrade-Enabled
X-FTR-Request-ID
X-NWS-LOG-UUID
X-DataDome
X-Time
Access-Control-Allow-Method
X-Seen-By
X-Mobile-URL
X-VCache
MS-CV
X-Server-ID
Paypal-Debug-Id
X-Cache-Age
ServerID
X-AOL-HN
X-TT
Healthy
X-Type
X-Whom
X-IPLB-Instance
X-Hostname
X-Content-Options
Cleartype
X-Aspnet-Duration-Ms
X-Providence-Cookie
X-Varnish-Backend
X-Source
X-Request-Guid
Payment
X-Route-Name
X-Is-Crawler
X-Flags
X-Signature
X-Cache-Action
X-B-Cache
X-Page-Id
X-App-Environment
Powered-By-ChinaCache
X-Jobs
X-Debug-Info
Fastcgi-Useragent
X-WebKit-CSP-Report-Only
X-Daa-Tunnel
X-Load-Cache
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-N
X-FB-Debug
X-RateLimit-Remaining
X-Mobile
X-Browser-Type
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Via-JSL
X-Contextid
Realpath
Nel
Refresh
Version
Node
X-Wix-Request-Id
X-Rule
X-Accel-Buffering
X-Original-Request-Id
X-Drupal-Cache-Tags
X-Response-Served-From
X-Cacheable-TTL
X-Framework
DC
Ms-Operation-Id
X-Zen-Fury
X-RTag
X-Proxy
X-Cached-By
X-RemovedCookies
X-ProcessESI
X-Akamai-Edgescape
Viewport
X-B
X-Distributor
X-Real-IP
Access-Control-Request-Headers
X-Instance
Referer-Policy
X-Cache-Rule
X-Cache-Operation
X-Drupal-Cache-Contexts
X-Cache-Expired-At
X-UUID
Eomportal-Instance
X-Cluster-Name
X-Page-View
X-Cache-Time
X-Region
X-HTML-Minification-Powered-By
X-Content-Powered-By
X-Tt-Trace-Tag
X-Tt-Trace-Host
Countrycode
X-FW-Dynamic
X-FW-Static
X-FW-Server
X-FW-Serve
X-FW-Hash
X-FW-Type
X-Cache-Control
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
Liferay-Portal
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-IPS-LoggedIn
X-G
X-Cache-Hit
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-FireWall-Port
X-Tumblr-User
X-Environment-Context
X-Pass-Why
X-L-Path
DynaTrace
Server-Info
X-App-Server
CF-IPCountry
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
X-User-Agent
SRV
Ec-Rule-Version
GEO-INFO
X-Protected-By
Section-Io-Id
Section-Io-Origin-Status
X-Tumblr-Pixel-2
Webserver
From-Origin
X-Ratelimit-Limit
Xserver
X-Nginx-Cache
X-Www-Served-By
X-Debug-IsPreview
X-Debug-IsConnected
X-Node-Name
Protected
X-Mode
X-RN-RSRV
X-UPSTREAM-Address
X-Device-Type
X-Endurance-Cache-Level
Meta-Geo
X-ES-SERVER
X-Hl-Ver
X-Handled-By
X-Adobe-Content
X-Cache-Server
X-Adobe-Loc
X-Site-Version
Cache-Tv-Group
X-Locale
X-Backend-Name
X-FB-TRIP-ID
X-Uri
X-MP-GENERATED-AT
X-Soup
X-Varnishpool
X-Varnish-Ttl
X-NYM-Debug-Backend
X-Labrador-Cache-Channel
Frame-Options
X-Web-Node
Cache-Status
X-PHP-Host
X-Storage
Webcakes-App-Name
Country
X-Proxy-Build
X-ProxyCache-Key
X-Proto
Decoy-Debug-Key
X-PCL
X-ProxyCache-Status
Webcakes-Region
X-OCL
TWC-Device-Class
X-Ratelimit-Remaining
Webcakes-App-Version
Cache-Name
X-Pubstack
X-Timing-Wait
Property-Id
X-BYPASS-REASON
TWC-Connection-Speed
X-Origin-Hint
Selected-Fe
X-Be
X-Sql-Count
X-Via-Fastly
X-Human
X-WA-Info
TWC-GeoIP-Country
Decoy-Debug-TTL
X-Request-Time
Decoy-Debug-Status
X-Redis-Cache
TWC-Privacy
Fastly-SSL
X-UA-Device-Type
TWC-GeoIP-LatLong
TWC-Locale-Group
X-Sql-Duration-Ms
X-FW-Version
X-Loop
Azure-InstanceId
Azure-Version
X-Hyper-Cache
Retry-After
Azure-SlotName
Azure-SiteName
X-Hosted-By
Azure-RegionName
X-LAGOON
X-No-Session
X-S-Maxage
X-Format
X-SayCDN-TTL
X-Origin-Date
X-Section
X-TNCMS
X-Access
X-R9-Blue-Green-Version
X-Say-TTL
X-Say-Cacheable
X-Webkit-Csp
X-PERF
X-LJ-Flow-ID
X-ShardId
X-Sorting-Hat-PodId
X-Alternate-Cache-Key
X-ApacheServer
X-Shopify-Stage
X-Sorting-Hat-ShopId
X-Xfnlog-Site
X-Server-W
X-Storefront-Renderer-Rendered
X-Cache-Grace
X-Forwarded-Host
X-CCM
X-Cluster
X-Cache-TTL-Remaining
X-Status
X-ShopId
X-AWS-Id
X-VWS-Id
X-Revision
X-TT-LOGID
Mn-Server-Ip
X-Varnish-Grace
X-AIR-PT
Apigw-Requestid
X-Proxied
X-Routing-Service
X-Zipkin-Id
X-Varnish-Server
X-Rendered-As
X-SRV
X-Is-Bot
X-Info
X-Qloud-Router
X-GG-Cache-Date
S-Cnection
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
X-Cdn
X-Cache-Enabled
X-Via-CDN
Cache-Hits
X-TA-CDN-Provider
AMP-Access-Control-Allow-Source-Origin
X-FTR-Balancer
X-Content-Age
X-FTR-Backend-Server
X-Country-Code-Real
X-Amz-Meta-S3cmd-Attrs
X-FTR-Realm
X-Dc
X-FTR-Backend
X-FTR-DC
X-Microcachable
X-FTR-Cache-Status
X-Platform
X-Proxy-Cache-Status
Uber-Trace-Id
X-NWS-UUID-VERIFY
X-Azure-Ref
X-App-Version
X-Detected-As
X-Cache-Host
Amp-Access-Control-Allow-Source-Origin
X-Aspnetmvc-Version
X-Amzn-RequestId
X-Amzn-Remapped-Content-Length
X-Amz-Apigw-Id
X-Backend-Host
X-EdgeConnect-Cache-Status
X-FTR-Expires
X-CSRF-Token
X-Air-Hostname
Tracecode
Akamai-GRN
X-ATG-Version
SD-X-WS
X-Time-Microsecs
X-Oss-Storage-Class
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
X-Oss-Request-Id
X-Cache-Var-Map
X-Cache-Var
X-Trace-Id
X-ID
X-Backend-TTL
X-B3-SpanId
ServedBy
X-RCS-CacheZone
X-Unique-Id
X-ServerID
X-Debug-Cache
X-Cache-PHP
X-CS
X-Tb
X-BCube-Filmed-By
X-Cache-NGX
X-Correlation-ID
X-Varnish-Hostname
X-GEO
Backend
HostName
DB-Nickname
X-DynaTrace-JS-Agent
DCR-Processing-Time-Ms
Expiry
X-Processor
X-Rewrite-Enabled
X-Request-UUID
Fastcgi-X-Cache-Version
DCR-Decision-By
Instruction
X-PAYTM-SRV-ID
X-Owner
Mobile-Detection-Method
Meta-Geo-Continent
MD5-Digest
X-PBS-Appsvrname
Machine
X-Rojux
BehaviorPad-Version
X-VG-WebServer
X-VG-WebCache
X-Vdms-Version
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
X-Ms-Version
Xc-Version
X-Vdms-Path
X-Trv-Group
X-S-Cookie
X-Origin-TTL
X-ScT
X-Session-Fingerprint
X-Thinkindot-L3
X-SRCache-Key
X-S
Odigeo-Trace-Id
X-A-Wwc
X-A-Dgt
X-A-Dcw
X-Aed
X-Application
X-B-Cookie
X-ARC
X-A-Dam
X-A-Ccd
T-Server
SR-User-Adfree
Rendered-Blocks
Thinkindot-CacheControl
X-Ms-Request-Id
Thinkindot-Control
Thinkindot-CacheControl-Type
X-Cache-NE
X-CF-Lambda-Fn
X-GeoIP-City
X-Generation-Time
X-Generated-On
X-Level-Front-Cache
X-Location
Release
X-NAPM-TraceId
X-From
X-Fetched-On
Path
X-Connection-Hash
X-CF-Lambda-Version
X-D
X-Destination
X-External-Request-Id
X-Device-Os
X-Origin-CC
X-A
DSUID
X-Magnolia-Registration
X-Sucuri-ID
X-Adobe-Source
X-Akamai-Transformed
Gh-Request-Id
X-JWT-State
Host-ID
X-HS-Content-Campaign-Id
X-Irp-Debug
X-Is-Gdpr
X-Cache-Backend
X-OVcl
Cf-Device-Type
X-OVcl-Cache
Content-Disposition
X-Node-Id
Fastly-Backend-Name
X-Mvc-Supplant-Cachable
X-Has-Esi
NGX
X-Cache-Bucket
X-Cms-Context
X-Core-Value
UCS
X-Bip
X-B3-Traceid
X-Azure-Ref-OriginShield
Server-Host
PB-RID
On-Server
X-Skip-Cache
X-FC-Vary-Parameters
X-Fastly-Cache
PB-PID
X-NewRelic-App-Data
X-Geo-Header
X-Micro-Cache
C-Via
AKAMAI
X-Cdn-Forward
X-TrackingId
Arc-Version
X-Thanos
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-TX-ID
X-VServer
X-Varnish-Cache-Hits
X-Tumblr-Pixel-3
User-Cache-Control
Server-Ext
X-DefHash
X-DefElseHash
X-Developer
X-Esi-Check
Locid
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-WADP-Cache
Magicmarker
X-Fastly-Backend
X-Envoy-Decorator-Operation
X-Csrf-Jwt
X-Eu-Site
X-DPWN-IS-SECURE
X-Clientip
Wxu-Next-Region
X-Block-Status
X-Backend-State
X-Developers
X-Policy
X-Nginx-Cache-Key
Wxu-Next-Hostname
X-Cache-Id
Wxu-Next-Commit
Sever-Int
X-Clara-WADP
X-CGP
X-Cache-Info
X-Cache-Tags
Server-Hostname
X-Varnish-Remaining-TTL
X-Old-Content-Length
X-Origin
X-Origin-Expires
X-NU-AKA-ACS-Version
X-Matched-Rule
X-Li-Pop
X-LI-UUID
X-Origin-Response-Time
X-Swa-Ws
X-Reqid
X-Request-Host
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Platform-Server
X-Ratelimit-Reset
X-Li-Fabric
X-User
X-GeoIP
X-GoCache-CacheStatus
X-Scheme
X-Generated-In
X-VarnishDD-TTL
X-Generated-By
X-Gzip
X-Varnish-CookieINHashed-On
X-Varnish-Beresp-Grace
X-Variation
X-IP
X-Varnish-CookieHashed-On
X-HN
X-Hnp-Log
X-Gen-Mode
X-Fmm-Version
Platform
PFcat
Pagetype
CDN-EdgeStorageId
CDN-CachedAt
CDN-Cache
Adler-Geo
Is-Eu
CacheControlHeader
CDCHOST
CDN-PullZone
CDN-RequestCountryCode
HA-Ipaddr
Location
Lfy
L5d-Success-Class
Ha-Gx-Prefs
Fastly-SWR
CDN-RequestId
CDN-Uid
Fastly-SIE
Ssr
Cache-Host
Web-Mar-Node
V-Age
X-Nc
X-Request-URI
True-Client-Country-4JS
X-Branch-Name
X-Slack-Backend
Rt-Fastcgi-Cache
X-CUA
X-Cache-Debug
X-Method
NM-Fastcgi-Cache
CloudFront-Viewer-Country
X-Gamma-Serve
Vix-Hermes-Req-Id
L
X-SIPLIST1
X-LB-ID
X-Dispatcher-Server
X-EC-Lua
X-VG-TLSProxy
IsBot
X-Varnish-Beresp-Ttl
X-Varnish-Hits
X-Var-Ttl
Cf-Bgj
X-Varnish-Beresp-Status
X-CLOUD-TRACE-CONTEXT
X-Sn-Servicetimems
Apple-News-Services-Handled
X-Aicache-OS
Apple-News-Services-Host
X-Cdn-Origin
X-Loc
Apple-News-Services-Parsed-Url
X-Goog-Meta-Goog-Reserved-File-Mtime
Origin
Apple-News-Services-Request-Url
Pramga
Fastly-Drupal-HTML
X-Cache-Expires
X-Hash
X-CACHE-KEY
X-APP-VERSION
Who
Esi-Enabled
X-Via-Poph
X-Cache-Date
Country-Code
X-Servername
Sid
X-Mvc-Supplant-OutputCached
X-Via-Popv
X-Via-Popn
X-Unique-ID
X-NCache
X-Varnish-Url
X-Core-Mission
Pics-Label
X-Refresh
X-PF-Uncompressing
X-Request-Start
Geo-Info
X-Epic-Correlation-Id
X-RateLimit-Limit
X-Esi
X-FireWall-Protection
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Tb-Optimization-Total-Bytes-Saved
X-Planisys-CDN-Cache
Url
X-Erf-Stays-Bingo-Pdp-Web
Req-Svc-Chain
X-TraceId
Tcn
Filterid
X-Response-By
X-Varnish-Cacheable
X-NC
X-DC
Cmstype
X-Error
Cmsid
X-Cache-Remote
X-Served-From
Xkeyi7
Source
Svr
X-Proxy-Cachei7
X-Webkit-CSP-Report-Only
S-Rt
Viewtype
A
VivaBuild
Kp-EeAlive
X-BBXSRF
N-Cache
Content-Secure-Policy
Cache-Key
HitType
MIME-Version
Server-Ttl
X-Srv
M-TraceId
X-HS-Status
X-Servedbyhost
Geoip-Latitude
X-Wa
GeoIp-Country-Code
X-Cache-2
NGB
X-B3-Spanid
X-URL
D-Cc-Upstream
X-HostName
X-Cc-Via
Ohc-File-Size
Arc-Country
Server-ID
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Cc-Req-Id
Cross-Origin-Window-Policy
X-Dynatrace
X-Vcl-Version
X-CDN-Forward
Cteonnt-Length
X-Air-Source
X-Sucuri-Cache
X-Host-Name
TDXMobile
Cross-Origin-Opener-Policy
X-LiteSpeed-Cache-Control
X-Varnish-Authentication
X-Svr
X-Vgn-Hpd-Reason
X-LI-Proto
CACHE
NtCoent-Length
SID
X-RAMCache
X-Server-IP
X-Li-Proto
X-HOST
XServer
X-FPC
X-Cache-Config
X-VCL-Version
X-API-Version
X-SaId
X-Gdpr
X-Nyt-Route
X-Origin-Time
Resin-Trace
Request-ID
X-Service
Hostname
X-JoinUs
X-Vc
X-NGENIX-Cache
X-Internal-Host
X-Geo
X-Edge-Location
X-UA
X-PHP-Backend
X-DB
X-Newrelic-Synthetics
X-CCDN-CacheTTL
X-Viewer-Country
X-CCDN-Origin-Time
X-ServedByHost
X-Check-Cacheable
X-RPS
X-SN
Cache-Provider
X-DSS
X-DI
X-VC
X-Hcs-Proxy-Type
X-DW
X-WA
X-RSL
X-Cs
X-TIM-N
X-RPM
X-FORWARDED-FOR
DataCenter
CF-Cached-On
Ohc-Cache-HIT
X-Webstats-RespID
X-SB
X-App
X-Via-NSCOPI
Server-Id
GeoIP-Country-Code
X-Forwarded-Site
X-NodeID
FSS-Cache
X-Extlb
GeoIP-Latitude
X-Bc-Bl
X-Action
X-SD-PageType
Mime-Version
ProcessTime
X-TIME
LB
X-Fpc
X-Oss-Cdn-Auth
Surrogated-Key
X-Accel-Expires-Debug
X-Region-Sid
X-Req
X-Proxy-Upstream
X-PJAX-URL
X-Date
X-Depends-On
X-VC-Cache
X-Render-Time
X-BBC-Edge-Cache-Status
Srv
X-CF-Powered-By
X-NGINX-Cache
X-ZONE
X-Swift-Error
X-CSRF-TOKEN
X-Dynatrace-Js-Agent
X-Provided-By
We-Hiring
X-RateLimit-Limit-Second
X-UnsetCookies
X-RateLimit-Remaining-Second
Env
Memcached
EpKe-Alive
W
X-FTR-Cache-Host
Mail-Subject
X-Oracle-Dms-Rid
X-Cdn-Request-ID
CDN
X-Auto-Login
X-APP
Upgrade-Insecure-Requests
Processtime
X-Ua
X-Worker
X-Air-Trace-Id
X-Men
X-BACKEND-TTL
X-Ftr-Cache-Host
X-Dw-Trace-Id
X-MSEdge-Flight
Cdn
X-MSEdge-Features
X-Client-Ip
X-Akamai-Pragma-Client-IP
X-CACHE-AGE
X-Pf-Uncompressing
Datacenter
Time
X-Hello
X-ABtesting
Proxy-Connection
X-Flog
Memory
X-Rocket-Build-Number
CPC-Age
X-Cache-Tag
X-Parent-Response-Time
X-Sigma
X-Sigma-Backend
X-Fastly-Backend-Reqs
CPC-Cache
VNS-Age
X-Cluster-Node
Dnion-Transfer-Encoding
X-Fastly-Request-Id
VNS-Cache
X-Acquia-Purge-Tags
Media-Length
X-Zone
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-BBC-Origin-Response-Status
X-Pad
PICS-Label
X-IN-APIGATEWAY
Vha6-Origin
X-Acquia-Site
X-IN-APIGATEWAYSSL
X-Presslabs-Stats
X-Oracle-DMS-ECID
Epwk-X-Cache
X-Snapshot-Date
X-LiteSpeed-Tag
X-Via-PopH
X-HITS
X-Via-PopV
X-Via-PopN
Cf-Ipcountry
State
My-App
Fastcgi-Cache-TTL
X-Varnish-URL
Xet-Cookie
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-Vcache
X-Csrf-Token
X-MiniProfiler-Ids
X-ServerName
X-Request-URL
X-Varnish-Beresp-TTL
OT-Force-Account-Verify
X-Request-Url
X-ElasticPress-Query
X-Ms-Meta-Staticbatchstarttime
X-Lb-Id
X-Ms-Meta-Originalurl
X-ElasticPress-Search
CountryCode
X-Tx-Id
Phost
Content-Style-Type
X-Litespeed-Cache-Control
X-Storefront-Renderer-Verified
Content-Script-Type
X-Apw-Access-Action
X-Apw-Hits
X-Minions-Version
X-Apw-Access-Token
X-Apw-Access-Object
X-C
Ohc-Response-Time
X-Amz-Meta-Cb-Modifiedtime
Inserted-Into-Cache-At
X-ND-Cache
X-Debug-Cache-Store
WZWS-RAY
NnCoection
X-Traceid
X-Debug-Cache-Fetch
X-B3-Parentspanid
X-Redis-Count
X-Redis-Duration-Ms
URI
X-Tid
Environment