Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Cf-Request-Id
CF-RAY
CF-Cache-Status
Last-Modified
X-XSS-Protection
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Xss-Protection
X-Cache-Status
X-Generator
X-Request-ID
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Content-Security-Policy
Content-Encoding
X-CDN
X-Ua-Compatible
X-Envoy-Upstream-Service-Time
Status
Feature-Policy
X-AspNetMvc-Version
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Access-Control-Max-Age
X-Via
Upgrade
Keep-Alive
X-Ws-Request-Id
X-Age
X-Turbo-Charged-By
X-AH-Environment
X-Robots-Tag
Request-Context
X-Proxy-Cache
EagleId
X-Cache-Group
Server-Timing
X-Backend
X-Hacker
Report-To
X-Amz-Request-Id
X-Server
Host-Header
X-Amz-Id-2
X-Server-Powered-By
Grace
X-Nginx-Cache-Status
X-UA-Device
X-LiteSpeed-Cache
X-Varnish-Cache
X-Rq
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Page-Speed
X-Dns-Prefetch-Control
Cf-Railgun
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
NEL
X-Amz-Version-Id
X-WebKit-CSP
X-Cache-Spec
Xkey
X-OneAgent-JS-Injection
Allow
X-Backend-Server
X-CST
X-Host
X-Device
X-Vhost
EagleEye-TraceId
X-Server-Id
Surrogate-Control
Request-Id
X-Dispatcher
X-Node
Accept-CH
Content-Location
X-Response-Time
X-Akam-SW-Version
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Accept-CH-Lifetime
X-Ruxit-JS-Agent
X-ASPNET-VERSION
X-Ac
X-Template
X-Language
X-Application-Context
X-Country
X-Cache-Lookup
X-Readtime
X-Cloud-Trace-Context
X-Mod-Pagespeed
MS-Author-Via
X-Origin-Cache
X-B3-TraceId
Rating
X-Cnection
X-MS-InvokeApp
X-Kinja-Server-Push
X-HW
X-Url
Accept-Ch
X-TtlSet
X-Vname
X-PC
X-ORACLE-DMS-ECID
X-Clacks-Overhead
X-GitHub-Request-Id
Edge-Control
X-FastCGI-Cache
Accept-Ch-Lifetime
X-Oneagent-Js-Injection
X-ESI
X-Trace
Display
X-Sol
X-Middleton-Response
X-Middleton-Display
Response
Pagespeed
X-Content-Type
X-D2id
X-Vcap-Request-Id
X-Kinja
X-Kinja-Build
X-Kinja-Server
X-Exp-Variant
X-Kinja-Revision
X-Exp-Id
X-GoogleNews-Bot
Verso
X-Cdn-Fetch
Arr-Disable-Session-Affinity
X-Use-Magma
X-Goog-Hash
X-Buckets
X-Rack-Cache
X-Server-Name
X-Country-Code
Service-Worker-Allowed
X-Navigation-Version
X-ORACLE-DMS-RID
X-Abt-Application-Version
X-VARITI-CCR
X-Varnish-TTL
X-Amz-Rid
X-Powered-By-Plesk
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-Cache-TTL
X-Client-IP
X-Fastly-Request-ID
SPRequestGuid
X-SharePointHealthScore
X-Release
X-MSEdge-Ref
SPRequestDuration
SPIisLatency
Fastly-Restarts
X-Dw-Request-Base-Id
X-Element-Page-Cache
X-Cached
X-NF-Request-ID
X-Ttl
Public-Key-Pins
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
X-Webkit-CSP
RTSS
Ar-Sid
AR-PoweredBy
AR-Request-ID
X-Origin-Upstream-Status
AR-CACHE
X-Edge
AR-ATIME
Access-Control-Request-Method
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-LLID
X-Px
X-Powered-CMS
Fusion-Content-Id
Fusion-Content-Source
Fusion-Template-Id
Fusion-Component-Id
Fusion-Deployment-Id
Fusion-Source
X-TTL
X-Ezoic-Cdn
X-Upstream
Content-MD5
X-Jurisdiction
X-HP-Webp
Cache-Tag
X-Mid
X-MCACHE
X-ECACHE
Charset
X-Recruiting
X-Amz-Server-Side-Encryption
X-Mg-S
X-Content-Digest
S
X-Version
X-Pinterest-Direct
X-PressLabs-Stats
TCN
MicrosoftSharePointTeamServices
Fastcgi-Cache
Front-End-Https
X-Debug
X-T
X-Content-Security-Policy-Report-Only
X-Kinsta-Cache
X-Grace
Filters
Cache-Tags
Server-Node
Edge-Cache-Tag
X-XRDS-Location
X-Accel-Expires
X-Forwarded-Proto
X-Id
X-Logged-In
X-Amzn-Trace-Id
X-Correlation-Id
Server-Name
X-Yandex-Sdch-Disable
Nginx-Cache
Surrogate-Key
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-DynaTrace
X-Varnish-Age
X-Cache-Key
X-Forwarded-For
TP-Cache
TP-L2-Cache
X-B3-Sampled
X-Request-Processing-Time
X-Request-Received
X-Server-ID
X-Microsite
X-Ser
X-Request-Handler-Origin-Region
X-Ruxit-Js-Agent
X-Hits
X-DIS-Request-ID
X-Shield-Request-Id
Powered-By-ChinaCache
X-Az
X-AppVersion
X-Activity-Id
X-Amz-Replication-Status
X-F-Cache
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Combine-CSS
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
X-Goog-Metageneration
X-Goog-Storage-Class
X-Goog-Generation
Accept-Charset
X-Origin-Server
X-Git-Hash
X-FTR-Request-ID
X-Respond-Thread
X-Hostname
X-Geo-Country
X-LB-Cache
X-DataDome
X-Upgrade-Enabled
X-Rid
Section-Io-Cache
Cache
X-Frontend
Access-Control-Allow-Method
Alternate-Protocol
Host
X-Aspnetmvc-Version
X-Cache-Age
X-Mobile-URL
Cleartype
MS-CV
X-XRDS-LOCATION
Paypal-Debug-Id
X-IPLB-Instance
X-Type
X-Content-Options
Healthy
X-Varnish-Backend
X-TEC-API-VERSION
X-Seen-By
X-AOL-HN
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Whom
X-App-Environment
ServerID
Payment
X-WebKit-CSP-Report-Only
X-VCache
X-Cache-Action
X-B-Cache
X-Aspnet-Duration-Ms
X-Flags
X-Debug-Info
X-Providence-Cookie
X-Request-Guid
X-Route-Name
X-Is-Crawler
X-Signature
X-TT
X-Jobs
X-Page-Id
X-NWS-LOG-UUID
Fastcgi-Useragent
X-Source
X-N
X-Mobile
X-Load-Cache
X-RateLimit-Remaining
X-Time
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Browser-Type
X-Daa-Tunnel
X-Via-JSL
X-FB-Debug
Nel
X-Litespeed-Cache
X-Cached-By
X-Akamai-Edgescape
Version
X-Cache-Operation
X-Cache-Rule
Viewport
X-Fastcgi-Cache
Refresh
X-Accel-Buffering
X-Response-Served-From
X-Rule
X-Original-Request-Id
DynaTrace
X-Proxy
DC
X-Framework
X-Drupal-Cache-Tags
X-Zen-Fury
X-RTag
X-RemovedCookies
X-Instance
X-ProcessESI
X-Cacheable-TTL
Ms-Operation-Id
GEO-INFO
Access-Control-Request-Headers
X-Real-IP
X-Wix-Request-Id
Referer-Policy
X-Tt-Trace-Tag
X-Tt-Trace-Host
Realpath
X-Cache-Time
X-Region
X-UUID
X-HTML-Minification-Powered-By
X-Contextid
X-Distributor
Node
X-Yottaa-Metrics
X-Drupal-Cache-Contexts
X-Yottaa-Optimizations
X-Page-View
X-FW-Serve
X-FW-Dynamic
X-Cache-Expired-At
X-FW-Type
X-FW-Static
VIX-Pulpo-Upstream-Status
X-FW-Hash
Countrycode
X-FW-Server
VIX-Pulpo-Node
Eomportal-Instance
X-B
X-L-Path
X-Environment-Context
X-Cluster-Name
X-Cache-Control
X-IPS-LoggedIn
X-Tumblr-Pixel
Liferay-Portal
X-G
X-Tumblr-Pixel-1
X-Content-Powered-By
X-Tumblr-User
X-Tumblr-Pixel-0
X-Node-Name
X-Cache-Hit
X-User-Agent
Server-Info
X-Varnish-Ttl
X-Pass-Why
X-Tumblr-Pixel-2
Webserver
From-Origin
X-App-Server
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Io-Id
Section-Origin-Responded
Protected
Ec-Rule-Version
SRV
X-Ratelimit-Limit
X-Amz-Meta-S3cmd-Attrs
X-FireWall-Port
X-Protected-By
X-Revision
X-Cache-Server
X-Backend-Name
Frame-Options
CF-IPCountry
X-ES-SERVER
Meta-Geo
X-Endurance-Cache-Level
X-Hyper-Cache
X-Www-Served-By
X-Hl-Ver
Cache-Status
X-Handled-By
X-Mode
X-RN-RSRV
X-UPSTREAM-Address
X-NYM-Debug-Backend
X-Storage
X-Locale
X-Site-Version
X-Soup
X-FB-TRIP-ID
X-Forwarded-Host
X-Pubstack
X-Varnishpool
X-Human
Decoy-Debug-TTL
X-Cache-Grace
X-Web-Node
Fastly-SSL
Country
Decoy-Debug-Key
Decoy-Debug-Status
Cache-Tv-Group
Retry-After
X-Be
Azure-RegionName
Azure-SiteName
Azure-SlotName
Azure-InstanceId
Cache-Name
Azure-Version
TWC-Privacy
X-ProxyCache-Status
X-Uri
X-ProxyCache-Key
X-Say-TTL
X-Labrador-Cache-Channel
X-Proxy-Build
X-UA-Device-Type
X-TT-LOGID
X-Say-Cacheable
X-Format
X-Redis-Cache
X-Section
X-SayCDN-TTL
X-Timing-Wait
X-Proto
X-PHP-Host
TWC-GeoIP-LatLong
TWC-Locale-Group
TWC-GeoIP-Country
TWC-Device-Class
Selected-Fe
TWC-Connection-Speed
Webcakes-App-Name
Webcakes-App-Version
X-Origin-Hint
X-PCL
X-Origin-Date
X-OCL
X-Access
X-BYPASS-REASON
Property-Id
Webcakes-Region
X-Adobe-Content
X-Adobe-Loc
X-LAGOON
X-Loop
X-Hosted-By
X-FW-Version
X-AIR-PT
X-ApacheServer
X-No-Session
X-PERF
X-WA-Info
X-Request-Time
X-Via-Fastly
X-TNCMS
X-Sql-Count
X-Sql-Duration-Ms
X-Server-W
X-S-Maxage
X-AWS-Id
X-LJ-Flow-ID
X-R9-Blue-Green-Version
X-Via-CDN
X-MP-GENERATED-AT
X-VWS-Id
X-Qloud-Router
X-Cluster
X-Alternate-Cache-Key
X-Sorting-Hat-PodId
X-Storefront-Renderer-Rendered
X-Status
X-Sorting-Hat-ShopId
Mn-Server-Ip
X-ShopId
X-ShardId
X-Shopify-Stage
Xserver
X-Cache-TTL-Remaining
X-FTR-Backend
X-Country-Code-Real
X-Proxied
X-Zipkin-Id
X-Routing-Service
S-Cnection
X-FTR-Backend-Server
X-CCM
X-FTR-Realm
X-FTR-DC
X-FTR-Balancer
X-FTR-Cache-Status
X-Xfnlog-Site
X-Is-Bot
Cache-Hits
X-Rendered-As
X-FTR-Expires
X-Device-Type
X-Nginx-Cache
X-Oracle-Dms-Rid
X-Ratelimit-Remaining
X-Unique-Id
X-Cdn
X-Info
Apigw-Requestid
X-Cache-Var-Map
X-Detected-As
X-B3-Traceid
X-Cache-Var
X-EdgeConnect-Cache-Status
X-Debug-IsConnected
X-Air-Hostname
X-Debug-IsPreview
X-SRV
X-Amzn-Remapped-Content-Length
X-Amzn-RequestId
X-Dc
X-Amz-Apigw-Id
X-Cache-Host
X-Microcachable
AMP-Access-Control-Allow-Source-Origin
X-Tec-Api-Version
X-Tec-Api-Root
X-Cache-Enabled
X-Tec-Api-Origin
Amp-Access-Control-Allow-Source-Origin
X-Content-Age
X-Varnish-Grace
X-Dynatrace
X-GEO
X-Platform
X-Varnish-Server
SD-X-WS
Tracecode
X-APP-VERSION
X-GG-Cache-Date
X-Time-Microsecs
X-Azure-Ref
X-DynaTrace-JS-Agent
X-Backend-TTL
X-Cache-Backend
Uber-Trace-Id
X-Backend-Host
X-Erf-Stays-Bingo-Pdp-Web
X-ServerID
X-Proxy-Cache-Status
X-ID
X-Tb
DSUID
X-Oss-Storage-Class
Akamai-GRN
X-BCube-Filmed-By
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Object-Type
X-Correlation-ID
X-ATG-Version
X-NewRelic-App-Data
X-Trace-Id
Backend
X-CSRF-Token
ServedBy
X-Sucuri-ID
Arc-Version
PB-RID
PB-PID
X-Akamai-Transformed
X-Aed
X-Origin-CC
X-A-Wwc
X-A-Dgt
X-Cache-NGX
X-A-Dam
X-A-Dcw
X-Cache-PHP
X-Application
X-NWS-UUID-VERIFY
X-B-Cookie
X-Magnolia-Registration
X-VG-WebCache
X-Matched-Rule
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Vdms-Version
X-SRCache-Key
X-Varnish-Cache-Hits
X-A-Ccd
X-Session-Fingerprint
X-Vdms-Path
X-ARC
X-Origin-TTL
Machine
BehaviorPad-Version
MD5-Digest
Meta-Geo-Continent
Mobile-Detection-Method
Lfy
Instruction
DCR-Decision-By
DCR-Processing-Time-Ms
Expiry
Fastcgi-X-Cache-Version
Odigeo-Trace-Id
Path
X-Varnish-Hostname
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-ScT
Thinkindot-Control
T-Server
X-RCS-CacheZone
Pramga
Release
Rendered-Blocks
SR-User-Adfree
X-A
X-Cache-NE
X-Vtex-Processado-Em
X-S
X-Fetched-On
X-From
X-Vtex-Remote-Cache
X-Thinkindot-L3
X-Destination
X-Device-Os
X-S-Cookie
X-Rojux
X-PAYTM-SRV-ID
X-GeoIP-City
X-PBS-Appsvrname
X-Processor
X-Trv-Group
X-Generation-Time
X-Generated-On
X-Rewrite-Enabled
X-Request-UUID
X-VG-WebServer
X-External-Request-Id
Xc-Version
X-D
X-Connection-Hash
X-Level-Front-Cache
X-Location
X-Origin-Response-Time
X-Geo-Header
X-Thanos
X-HS-Content-Campaign-Id
X-Sn-Servicetimems
X-SVT-ORM-RULES
X-Cdn-Origin
X-Tumblr-Pixel-3
X-SVT-ORM-VERSION
X-Reqid
Pagetype
X-GeoIP
Ha-Gx-Prefs
Gh-Request-Id
Fastly-Backend-Name
HA-Ipaddr
Host-ID
Cf-Device-Type
L5d-Success-Class
X-Has-Esi
X-Csrf-Jwt
X-Cache-Info
X-Cache-Bucket
X-TrackingId
X-Is-Gdpr
X-Mvc-Supplant-Cachable
X-Eu-Site
X-Swa-Ws
X-Backend-State
X-Node-Id
X-OVcl-Cache
X-Owner
X-OVcl
X-CGP
X-FC-Vary-Parameters
X-Cache-Date
X-Generated-In
X-Skip-Cache
X-Azure-Ref-OriginShield
X-User
X-VServer
X-JWT-State
UCS
X-Micro-Cache
X-Irp-Debug
Ssr
X-Bip
X-Ms-Request-Id
CacheControlHeader
AKAMAI
Cache-Host
X-Ms-Version
C-Via
X-Debug-Cache
X-Adobe-Source
X-Envoy-Decorator-Operation
X-IP
NGX
X-Request-Host
X-TA-CDN-Provider
On-Server
X-Request-URI
X-Fastly-Backend
Server-Ext
Server-Host
Server-Hostname
Sever-Int
X-Nginx-Cache-Key
X-Origin-Expires
Magicmarker
X-Policy
PFcat
X-Fastly-Cache
Wxu-Next-Region
Locid
X-Cache-Tags
Wxu-Next-Commit
X-VarnishDD-TTL
X-Clientip
X-Wikidot-Backend
X-Wikidot-Static-Cache
CloudFront-Viewer-Country
Content-Disposition
DB-Nickname
V-Age
X-Scheme
X-Varnish-Hits
X-Developer
X-Developers
L
Location
X-Cms-Context
Wxu-Next-Hostname
X-Core-Value
X-CUA
X-Var-Ttl
X-Generated-By
X-HN
User-Cache-Control
X-GoCache-CacheStatus
X-DPWN-IS-SECURE
X-DefElseHash
X-Clara-WADP
X-Cache-Id
X-DefHash
X-Dispatcher-Server
X-Fmm-Version
X-Esi-Check
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Gen-Mode
X-NU-AKA-ACS-Version
X-TX-ID
X-Variation
X-Slack-Backend
X-SIPLIST1
Cf-Bgj
X-Servername
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Varnish-Beresp-Grace
X-NAPM-TraceId
X-WADP-Cache
X-VG-TLSProxy
X-Varnish-Remaining-TTL
X-Request-Start
X-Rebelmouse-Surrogate-Control
X-LI-UUID
X-Loc
X-Li-Pop
X-Li-Fabric
X-Hash
X-Hnp-Log
X-Method
X-Cache-Expires
X-Ratelimit-Reset
X-Rebelmouse-Cache-Control
X-Platform-Server
X-Origin
X-Old-Content-Length
X-Gzip
X-Cache-Remote
Apple-News-Services-Host
True-Client-Country-4JS
IsBot
X-Branch-Name
Rt-Fastcgi-Cache
Vix-Hermes-Req-Id
Web-Mar-Node
Is-Eu
Apple-News-Services-Request-Url
CDCHOST
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
X-Block-Status
NM-Fastcgi-Cache
Platform
Origin
Fastly-SWR
Adler-Geo
Fastly-SIE
HostName
X-Varnish-Beresp-Ttl
X-Cache-Debug
X-Varnish-Beresp-Status
CDN-PullZone
Fastly-Drupal-HTML
CDN-RequestId
CDN-CachedAt
CDN-Cache
X-NC
X-Gamma-Serve
CDN-RequestCountryCode
X-Core-Mission
CDN-Uid
CDN-EdgeStorageId
X-B3-Spanid
X-CS
X-Varnish-Url
X-Mvc-Supplant-OutputCached
X-NCache
X-Cdn-Forward
Url
X-EC-Lua
X-B3-SpanId
X-Response-By
X-App-Version
X-LB-ID
X-Host-Name
X-Varnish-Cacheable
X-PF-Uncompressing
S-Rt
X-CACHE-GROUP
X-Aicache-OS
Xkeyi7
X-Proxy-Cachei7
X-Refresh
Sid
Pics-Label
X-BBXSRF
CACHE
X-Esi
X-FireWall-Protection
Esi-Enabled
N-Cache
X-Via-Popn
X-Via-Popv
X-Via-Poph
Cross-Origin-Window-Policy
X-Cache-2
X-Epic-Correlation-Id
Ohc-File-Size
Content-Secure-Policy
X-Sucuri-Cache
X-CDN-Forward
X-Webkit-Csp
D-Cc-Upstream
X-Cc-Req-Id
X-DC
X-Error
X-Cc-Via
X-Tb-Optimization-Total-Bytes-Saved
X-Varnish-Authentication
X-Contensis-Viewer-Groups
X-Nc
X-Cache-ASPX
X-RateLimit-Limit
Cteonnt-Length
Who
X-Srv
X-Wa
Req-Svc-Chain
X-Svr
X-TraceId
X-Servedbyhost
MIME-Version
Country-Code
Source
X-Unique-ID
X-Webkit-CSP-Report-Only
X-Server-IP
X-LiteSpeed-Cache-Control
Server-Ttl
HitType
X-Planisys-CDN-Cache
X-Cs
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-API-Version
X-Gdpr
X-FPC
X-HS-Status
X-VC
X-TIME
X-Cache-Config
X-Origin-Time
GeoIp-Country-Code
X-Nyt-Route
Geoip-Latitude
Hostname
X-URL
Svr
Kp-EeAlive
XServer
X-SN
Cmstype
Cmsid
X-LI-Proto
X-CACHE-KEY
Ohc-Cache-HIT
Geo-Info
X-Webstats-RespID
X-Served-From
X-NodeID
X-VCL-Version
VivaBuild
X-NGINX-Cache
Viewtype
Server-ID
X-SB
SID
A
Cache-Key
X-Check-Cacheable
X-SD-PageType
NtCoent-Length
X-HOST
X-Vcl-Version
X-Vgn-Hpd-Reason
X-CCDN-Origin-Time
M-TraceId
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-Viewer-Country
X-Render-Time
Request-ID
X-UA
X-Ua
X-Li-Proto
X-CF-Powered-By
Cache-Provider
X-RSL
Resin-Trace
X-BBC-Edge-Cache-Status
Server-Id
X-TIM-N
X-FORWARDED-FOR
X-Air-Source
X-RAMCache
X-DSS
X-DI
X-DB
GeoIP-Latitude
X-DW
X-RPS
Cross-Origin-Opener-Policy
X-RPM
GeoIP-Country-Code
Arc-Country
TDXMobile
EpKe-Alive
Filterid
X-Fastly-Request-Id
X-App
X-CSRF-TOKEN
X-Internal-Host
X-Worker
X-Auto-Login
X-Newrelic-Synthetics
Processtime
X-Ftr-Cache-Host
Srv
X-Action
ProcessTime
X-FTR-Cache-Host
X-Dynatrace-Js-Agent
Datacenter
Upgrade-Insecure-Requests
X-Fpc
CDN
NGB
X-Vc
X-Service
X-Oss-Cdn-Auth
X-WA
X-Cluster-Node
Mime-Version
X-ServedByHost
Tcn
X-CLOUD-TRACE-CONTEXT
X-BBC-Origin-Response-Status
Proxy-Connection
X-Geo
X-HostName
CF-Cached-On
X-HITS
X-BACKEND-TTL
X-Fastly-Backend-Reqs
FSS-Cache
X-Via-NSCOPI
X-PHP-Backend
X-Akamai-Pragma-Client-IP
X-MSEdge-Flight
X-Forwarded-Site
X-JoinUs
X-SaId
X-NGENIX-Cache
Cdn
X-Cache-Tag
X-MSEdge-Features
X-Dw-Trace-Id
X-Cdn-Request-ID
X-Client-Ip
X-CACHE-AGE
X-Edge-Location
X-Extlb
W
X-Pf-Uncompressing
X-ABtesting
X-Flog
Dnion-Transfer-Encoding
X-IN-APIGATEWAY
X-ND-Cache
X-Hello
X-Parent-Response-Time
X-IN-APIGATEWAYSSL
PICS-Label
X-Via-PopV
OT-Force-Account-Verify
X-Via-PopH
X-Via-PopN
DataCenter
WZWS-RAY
X-Provided-By
X-RateLimit-Remaining-Second
X-Oracle-DMS-ECID
X-Lb-Id
X-Region-Sid
X-RateLimit-Limit-Second
Media-Length
X-Pad
X-Proxy-Upstream
X-PJAX-URL
X-LiteSpeed-Tag
X-Swift-Error
Surrogated-Key
X-Accel-Expires-Debug
X-Bc-Bl
X-Req
Epwk-X-Cache
Mail-Subject
LB
Memcached
X-Date
We-Hiring
X-Depends-On
Vha6-Origin
X-Presslabs-Stats
X-UnsetCookies
X-VC-Cache
Memory
X-Rocket-Build-Number
X-Sigma-Backend
X-Sigma
X-ZONE
Env
Time
X-MiniProfiler-Ids
Xet-Cookie
Cf-Ipcountry
X-Zone
X-Request-URL
X-Amz-Meta-Cb-Modifiedtime
X-Request-Url
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
X-Men
URI
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-Vcache
X-Csrf-Token
X-Acquia-Site
X-Air-Trace-Id
X-Snapshot-Date
X-B3-Parentspanid
X-APP
X-Ms-Meta-Originalurl
X-Ms-Meta-Staticbatchstarttime
X-ElasticPress-Query
X-Varnish-URL
X-Varnish-Beresp-TTL
X-ElasticPress-Search
CountryCode
X-Tid
Inserted-Into-Cache-At
X-Redis-Count
X-Storefront-Renderer-Verified
X-Akamai-Request-ID
X-ServerName
X-C
X-Litespeed-Cache-Control
Environment
X-Redis-Duration-Ms
Ohc-Response-Time
X-Debug-Cache-Fetch
Phost
NnCoection
X-Traceid
X-Debug-Cache-Store