Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-RAY
CF-Cache-Status
Accept-Ranges
Link
X-XSS-Protection
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-UA-Compatible
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
X-Xss-Protection
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Request-ID
X-Cacheable
Timing-Allow-Origin
X-Ua-Compatible
X-Content-Security-Policy
X-Iinfo
Content-Encoding
X-CDN
Feature-Policy
X-AspNetMvc-Version
Status
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Upgrade
X-Via
Access-Control-Max-Age
Keep-Alive
X-Ws-Request-Id
X-Age
X-AH-Environment
X-Robots-Tag
X-Turbo-Charged-By
Request-Context
EagleId
X-Proxy-Cache
X-Cache-Group
Server-Timing
X-Backend
X-Hacker
X-Server
Host-Header
Report-To
X-Amz-Request-Id
X-Server-Powered-By
X-Amz-Id-2
Grace
X-Nginx-Cache-Status
X-UA-Device
X-Rq
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
X-LiteSpeed-Cache
X-Page-Speed
Cf-Railgun
X-Pingback
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
X-Styx-Req-Id
NEL
X-Cache-Spec
X-Amz-Version-Id
X-Device
X-CST
Allow
X-Vhost
X-WebKit-CSP
X-Host
Xkey
X-Backend-Server
X-Server-Id
EagleEye-TraceId
Surrogate-Control
X-Dispatcher
Request-Id
X-Node
Content-Location
X-Response-Time
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Akam-SW-Version
X-Ruxit-JS-Agent
P3p
X-ASPNET-VERSION
X-Application-Context
X-Ac
X-Cache-Lookup
Accept-CH
X-Country
X-Template
Accept-Ch
X-Language
Accept-CH-Lifetime
X-Mod-Pagespeed
X-Readtime
Accept-Ch-Lifetime
X-Cloud-Trace-Context
MS-Author-Via
X-B3-TraceId
Rating
X-Origin-Cache
X-HW
X-Cnection
X-MS-InvokeApp
X-Url
X-TtlSet
X-PC
X-Vname
X-Clacks-Overhead
Edge-Control
X-GitHub-Request-Id
X-ESI
X-Trace
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Middleton-Response
Display
Pagespeed
X-Middleton-Display
X-Sol
Response
X-Content-Type
X-D2id
Arr-Disable-Session-Affinity
X-Exp-Id
X-Cdn-Fetch
X-Exp-Variant
X-GoogleNews-Bot
X-Use-Magma
X-Kinja-Server
X-Kinja-Revision
X-Kinja-Build
X-Kinja
Verso
X-Vcap-Request-Id
X-Varnish-TTL
X-Goog-Hash
X-Rack-Cache
X-Country-Code
X-Buckets
X-TTL
X-FastCGI-Cache
X-Navigation-Version
X-Powered-By-Plesk
X-Server-Name
Service-Worker-Allowed
X-VARITI-CCR
X-Amz-Rid
X-Abt-Application-Version
X-Fastly-Request-ID
X-Webkit-CSP
X-Client-IP
X-Cache-TTL
Fastly-Restarts
X-Cached
Pinterest-Generated-By
X-Pinterest-Rid
Pinterest-Version
X-Release
X-MSEdge-Ref
X-Dw-Request-Base-Id
SPRequestGuid
X-SharePointHealthScore
X-Element-Page-Cache
X-Oneagent-Js-Injection
X-NF-Request-ID
SPIisLatency
SPRequestDuration
MRF-Tech
Mrf-Cache-Status
Public-Key-Pins
X-B3-TraceId-Primal
RTSS
Access-Control-Request-Method
AR-CACHE
AR-PoweredBy
Ar-Sid
AR-Request-ID
AR-ATIME
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Edge
X-LLID
X-Powered-CMS
X-Ezoic-Cdn
X-Litespeed-Cache
Cache-Tag
Content-MD5
X-Upstream
X-Origin-Upstream-Status
Fusion-Deployment-Id
Fusion-Source
X-HP-Webp
X-Jurisdiction
Fusion-Content-Source
Fusion-Template-Id
Fusion-Component-Id
X-Px
Fusion-Content-Id
S
X-Version
X-MCACHE
X-Mid
X-ECACHE
X-Recruiting
X-Mg-S
Charset
X-Content-Digest
X-PressLabs-Stats
X-Kinsta-Cache
Fastcgi-Cache
X-T
X-Amz-Server-Side-Encryption
X-DynaTrace
Cache-Tags
X-Id
MicrosoftSharePointTeamServices
Filters
X-Logged-In
X-Content-Security-Policy-Report-Only
X-Accel-Expires
Front-End-Https
X-Ttl
Server-Node
Edge-Cache-Tag
X-Forwarded-Proto
X-Debug
X-Grace
X-Correlation-Id
X-Forwarded-For
TP-Cache
TCN
TP-L2-Cache
Server-Name
Nginx-Cache
X-Amzn-Trace-Id
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Request-Processing-Time
Surrogate-Key
X-Request-Received
X-Hits
X-Shield-Request-Id
X-Varnish-Age
X-B3-Sampled
X-Request-Handler-Origin-Region
X-Microsite
X-Yandex-Sdch-Disable
X-Ser
X-Pinterest-Direct
X-Az
X-AppVersion
X-Activity-Id
X-Ruxit-Js-Agent
X-Amz-Replication-Status
X-XRDS-Location
X-Fastcgi-Cache
X-F-Cache
X-XRDS-LOCATION
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Cache-Config
X-DIS-Request-ID
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Origin-Server
X-Geo-Country
Accept-Charset
Alternate-Protocol
X-Git-Hash
X-Cache-Key
X-Rid
X-Respond-Thread
X-Frontend
Section-Io-Cache
Cache
Host
X-LB-Cache
X-Upgrade-Enabled
X-FTR-Request-ID
X-NWS-LOG-UUID
X-DataDome
X-Time
Access-Control-Allow-Method
X-Seen-By
X-Mobile-URL
X-Server-ID
X-VCache
MS-CV
X-Cache-Age
Paypal-Debug-Id
X-AOL-HN
X-IPLB-Instance
Healthy
X-TT
ServerID
X-Whom
X-Hostname
X-Type
X-Content-Options
X-Varnish-Backend
X-Providence-Cookie
X-Route-Name
Cleartype
X-Aspnet-Duration-Ms
X-Is-Crawler
Payment
X-Flags
X-Request-Guid
X-App-Environment
X-Source
X-Cache-Action
X-Signature
X-B-Cache
Powered-By-ChinaCache
X-Page-Id
X-Jobs
X-Debug-Info
Fastcgi-Useragent
X-Load-Cache
X-WebKit-CSP-Report-Only
X-Daa-Tunnel
X-N
X-FB-Debug
X-RateLimit-Remaining
X-Mobile
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
Realpath
X-Contextid
X-Via-JSL
Nel
Refresh
Node
Version
X-Drupal-Cache-Tags
X-Rule
X-Wix-Request-Id
X-Original-Request-Id
X-Response-Served-From
X-Accel-Buffering
X-RTag
X-Zen-Fury
X-Framework
DC
X-Proxy
Ms-Operation-Id
X-Cacheable-TTL
X-Cached-By
X-RemovedCookies
X-ProcessESI
X-Akamai-Edgescape
X-Real-IP
Viewport
Access-Control-Request-Headers
X-HTML-Minification-Powered-By
X-Distributor
X-Cache-Time
X-Instance
Referer-Policy
X-B
X-UUID
X-Cache-Operation
X-Cache-Rule
X-Cluster-Name
X-Region
X-Page-View
X-Drupal-Cache-Contexts
Eomportal-Instance
X-Tt-Trace-Host
X-Cache-Control
X-Cache-Expired-At
X-Tt-Trace-Tag
X-Content-Powered-By
X-FW-Type
X-FW-Serve
X-FW-Server
X-FW-Static
X-FW-Dynamic
Countrycode
VIX-Pulpo-Node
X-FW-Hash
VIX-Pulpo-Upstream-Status
Liferay-Portal
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-IPS-LoggedIn
X-G
X-Cache-Hit
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-FireWall-Port
X-Environment-Context
X-L-Path
X-Pass-Why
DynaTrace
Server-Info
X-App-Server
CF-IPCountry
GEO-INFO
X-User-Agent
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
SRV
X-Protected-By
Section-Io-Origin-Status
Ec-Rule-Version
Section-Io-Id
Webserver
From-Origin
X-Tumblr-Pixel-2
X-Ratelimit-Limit
X-Www-Served-By
Xserver
X-Debug-IsPreview
X-Debug-IsConnected
Protected
X-Nginx-Cache
X-Node-Name
X-UPSTREAM-Address
Meta-Geo
X-Mode
X-RN-RSRV
X-Endurance-Cache-Level
X-Device-Type
X-ES-SERVER
X-Hl-Ver
X-Handled-By
X-Cache-Server
Cache-Tv-Group
X-FB-TRIP-ID
X-Adobe-Loc
X-Adobe-Content
X-Uri
X-Locale
X-MP-GENERATED-AT
X-Site-Version
X-Backend-Name
Cache-Status
X-PHP-Host
X-NYM-Debug-Backend
X-Soup
X-Varnishpool
X-Labrador-Cache-Channel
X-Varnish-Ttl
X-Storage
X-UA-Device-Type
X-Be
Frame-Options
X-Web-Node
X-Proto
Selected-Fe
X-Origin-Date
X-Proxy-Build
X-ProxyCache-Key
X-Ratelimit-Remaining
X-Redis-Cache
X-Pubstack
X-ProxyCache-Status
X-OCL
X-BYPASS-REASON
Country
X-Human
Cache-Name
X-Request-Time
Decoy-Debug-Key
Decoy-Debug-Status
X-No-Session
Fastly-SSL
Decoy-Debug-TTL
X-Origin-Hint
X-PCL
TWC-Device-Class
TWC-GeoIP-Country
X-Sql-Duration-Ms
X-Sql-Count
X-Timing-Wait
Webcakes-App-Version
X-WA-Info
X-Via-Fastly
Webcakes-Region
Property-Id
TWC-GeoIP-LatLong
TWC-Connection-Speed
Webcakes-App-Name
TWC-Locale-Group
TWC-Privacy
X-Tec-Api-Version
X-R9-Blue-Green-Version
X-Server-W
X-FW-Version
X-Tec-Api-Origin
X-Say-Cacheable
X-Tec-Api-Root
Azure-SlotName
Azure-Version
Azure-SiteName
Azure-RegionName
X-S-Maxage
Azure-InstanceId
X-Say-TTL
X-Hosted-By
X-Format
X-LJ-Flow-ID
X-LAGOON
Retry-After
X-Loop
X-VWS-Id
X-SayCDN-TTL
X-TNCMS
X-Section
X-Access
X-Hyper-Cache
X-AWS-Id
X-AIR-PT
X-CCM
X-Cache-Grace
X-Alternate-Cache-Key
X-Webkit-Csp
X-Sorting-Hat-ShopId
X-PERF
X-Sorting-Hat-PodId
X-Shopify-Stage
X-ShardId
X-ShopId
X-Storefront-Renderer-Rendered
X-Cluster
X-Forwarded-Host
X-Cache-TTL-Remaining
X-Status
X-Xfnlog-Site
X-ApacheServer
X-Varnish-Grace
X-TT-LOGID
Mn-Server-Ip
X-Revision
X-Proxied
Apigw-Requestid
X-Routing-Service
X-Zipkin-Id
X-Rendered-As
X-Is-Bot
X-SRV
X-Varnish-Server
X-Info
X-Qloud-Router
X-Dc
X-GG-Cache-Date
S-Cnection
X-Cache-Enabled
X-Cdn
X-Via-CDN
X-FTR-Cache-Status
X-Content-Age
X-FTR-DC
AMP-Access-Control-Allow-Source-Origin
X-FTR-Backend
X-FTR-Backend-Server
X-FTR-Balancer
X-Country-Code-Real
X-Amz-Meta-S3cmd-Attrs
X-TA-CDN-Provider
Cache-Hits
X-FTR-Realm
X-Microcachable
X-Proxy-Cache-Status
X-Platform
Uber-Trace-Id
X-App-Version
X-Cache-Host
X-NWS-UUID-VERIFY
X-Detected-As
X-Azure-Ref
Amp-Access-Control-Allow-Source-Origin
X-Aspnetmvc-Version
X-Backend-Host
X-Amzn-Remapped-Content-Length
X-Amz-Apigw-Id
X-EdgeConnect-Cache-Status
X-Amzn-RequestId
X-FTR-Expires
X-Air-Hostname
Tracecode
Akamai-GRN
X-CSRF-Token
SD-X-WS
X-ATG-Version
X-Oss-Storage-Class
X-Oss-Server-Time
X-Time-Microsecs
X-Oss-Object-Type
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-Trace-Id
X-Cache-Var-Map
X-Cache-Var
X-RCS-CacheZone
X-B3-SpanId
X-Debug-Cache
X-Unique-Id
ServedBy
X-ServerID
X-Backend-TTL
X-Cache-PHP
X-Correlation-ID
X-Cache-NGX
X-CS
X-Varnish-Hostname
X-BCube-Filmed-By
X-Tb
Backend
X-GEO
HostName
X-DynaTrace-JS-Agent
DB-Nickname
Machine
MD5-Digest
Meta-Geo-Continent
Odigeo-Trace-Id
Mobile-Detection-Method
Instruction
Fastcgi-X-Cache-Version
BehaviorPad-Version
DCR-Decision-By
X-Ms-Version
DCR-Processing-Time-Ms
Expiry
Thinkindot-CacheControl
X-PBS-Appsvrname
X-PAYTM-SRV-ID
X-Processor
X-Request-UUID
X-Rojux
X-Rewrite-Enabled
X-Owner
X-Origin-TTL
X-Level-Front-Cache
X-GeoIP-City
X-Location
X-NAPM-TraceId
X-Origin-CC
X-S
X-S-Cookie
X-VG-WebServer
X-VG-WebCache
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-Vdms-Version
X-Vdms-Path
X-Session-Fingerprint
X-ScT
X-SRCache-Key
X-Thinkindot-L3
X-Trv-Group
X-Generation-Time
X-Generated-On
X-A-Dam
X-A-Ccd
X-A-Dcw
X-A-Dgt
X-A-Wwc
Thinkindot-Control
Thinkindot-CacheControl-Type
Rendered-Blocks
Release
SR-User-Adfree
T-Server
X-Ms-Request-Id
X-Aed
X-Application
X-Device-Os
X-Destination
X-External-Request-Id
X-Fetched-On
X-From
X-D
X-Connection-Hash
X-B-Cookie
X-ARC
X-Cache-NE
X-CF-Lambda-Fn
X-CF-Lambda-Version
Path
X-A
X-Magnolia-Registration
X-Sucuri-ID
DSUID
X-Akamai-Transformed
X-Adobe-Source
PB-RID
X-Tumblr-Pixel-3
X-Thanos
X-Cache-Backend
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
PB-PID
X-TrackingId
On-Server
Fastly-Backend-Name
X-VServer
X-Cdn-Forward
Content-Disposition
Gh-Request-Id
Host-ID
UCS
X-NewRelic-App-Data
NGX
Pagetype
X-Skip-Cache
X-JWT-State
X-FC-Vary-Parameters
X-Fastly-Cache
X-Micro-Cache
X-Is-Gdpr
X-Irp-Debug
X-HS-Content-Campaign-Id
X-Has-Esi
X-GeoIP
X-Geo-Header
X-Mvc-Supplant-Cachable
X-Core-Value
X-Bip
X-Azure-Ref-OriginShield
X-Reqid
X-B3-Traceid
X-Cache-Bucket
X-OVcl-Cache
X-Node-Id
X-Cms-Context
X-OVcl
Cf-Device-Type
Server-Host
AKAMAI
C-Via
X-Varnish-Cache-Hits
CacheControlHeader
X-TX-ID
Arc-Version
User-Cache-Control
X-Developers
Sever-Int
Locid
Server-Hostname
X-CUA
X-Request-Host
X-NU-AKA-ACS-Version
X-Scheme
Magicmarker
Web-Mar-Node
X-LI-UUID
Ssr
X-Csrf-Jwt
Server-Ext
X-Swa-Ws
V-Age
X-Li-Pop
CDN-Uid
X-GoCache-CacheStatus
Wxu-Next-Commit
X-CGP
X-Cache-Id
X-Old-Content-Length
X-Gen-Mode
Wxu-Next-Region
X-Cache-Info
X-Origin
X-Fmm-Version
X-Origin-Response-Time
X-Li-Fabric
X-Cache-Tags
X-Generated-By
X-Generated-In
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Clara-WADP
X-Clientip
X-Backend-State
X-Ratelimit-Reset
X-Branch-Name
X-Block-Status
Wxu-Next-Hostname
X-Platform-Server
X-IP
X-Nginx-Cache-Key
Ha-Gx-Prefs
HA-Ipaddr
CDN-Cache
X-Esi-Check
X-Eu-Site
X-Gzip
CDCHOST
L5d-Success-Class
X-DPWN-IS-SECURE
Is-Eu
X-Envoy-Decorator-Operation
Fastly-SWR
Fastly-SIE
X-WADP-Cache
X-Wikidot-Backend
CDN-RequestId
X-Fastly-Backend
CDN-RequestCountryCode
CDN-PullZone
X-HN
CDN-CachedAt
CDN-EdgeStorageId
X-Hnp-Log
Lfy
Location
X-DefHash
PFcat
X-Policy
X-Developer
Platform
X-DefElseHash
X-Var-Ttl
Adler-Geo
X-Variation
X-Varnish-Beresp-Grace
X-User
X-Origin-Expires
X-Varnish-Remaining-TTL
X-VarnishDD-TTL
X-Dispatcher-Server
X-Varnish-CookieHashed-On
X-Matched-Rule
Cache-Host
NM-Fastcgi-Cache
X-Wikidot-Static-Cache
X-Varnish-CookieINHashed-On
X-ID
X-Nc
X-Method
X-Slack-Backend
Cf-Bgj
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Status
X-Cache-Debug
X-Varnish-Hits
X-EC-Lua
CloudFront-Viewer-Country
X-Hash
X-VG-TLSProxy
L
IsBot
Rt-Fastcgi-Cache
Vix-Hermes-Req-Id
X-Gamma-Serve
X-SIPLIST1
X-Request-URI
True-Client-Country-4JS
X-CLOUD-TRACE-CONTEXT
Apple-News-Services-Handled
X-LB-ID
X-Goog-Meta-Goog-Reserved-File-Mtime
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Esi-Enabled
X-Aicache-OS
X-Cache-Expires
X-Sn-Servicetimems
Pramga
X-Loc
X-Cdn-Origin
Origin
Fastly-Drupal-HTML
X-CACHE-KEY
Who
X-APP-VERSION
X-Via-Poph
X-Via-Popv
X-Via-Popn
Sid
X-Cache-Date
X-NCache
X-Mvc-Supplant-OutputCached
X-Servername
X-Unique-ID
X-PF-Uncompressing
Country-Code
X-Varnish-Url
Pics-Label
X-Core-Mission
X-Refresh
Geo-Info
X-Epic-Correlation-Id
X-Request-Start
X-RateLimit-Limit
X-FireWall-Protection
X-Planisys-CDN-Rules
X-Tb-Optimization-Total-Bytes-Saved
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
Url
X-Erf-Stays-Bingo-Pdp-Web
Tcn
Filterid
Req-Svc-Chain
X-TraceId
X-Varnish-Cacheable
X-Response-By
X-Error
X-NC
Cmstype
Cmsid
X-Cache-Remote
Svr
Kp-EeAlive
Xkeyi7
Source
X-Proxy-Cachei7
X-Served-From
X-Webkit-CSP-Report-Only
S-Rt
HitType
Content-Secure-Policy
Geoip-Latitude
GeoIp-Country-Code
N-Cache
Server-Ttl
MIME-Version
X-HS-Status
Viewtype
VivaBuild
A
X-DC
X-Srv
Cache-Key
X-BBXSRF
X-Wa
M-TraceId
NGB
X-Cache-2
X-Servedbyhost
X-B3-Spanid
X-URL
X-Contensis-Viewer-Groups
X-HostName
X-Varnish-Authentication
Ohc-File-Size
X-Sucuri-Cache
X-CDN-Forward
X-LiteSpeed-Cache-Control
X-Air-Source
D-Cc-Upstream
X-Cc-Req-Id
Cross-Origin-Opener-Policy
X-Cache-ASPX
TDXMobile
Server-ID
X-Host-Name
X-Dynatrace
Cross-Origin-Window-Policy
X-Cc-Via
Arc-Country
Cteonnt-Length
X-Vcl-Version
NtCoent-Length
X-Vgn-Hpd-Reason
X-Svr
X-Esi
X-LI-Proto
SID
CACHE
X-Vc
X-RAMCache
X-Server-IP
X-Li-Proto
X-HOST
X-Internal-Host
XServer
X-Service
X-VCL-Version
X-Newrelic-Synthetics
X-PHP-Backend
Resin-Trace
X-SaId
X-JoinUs
Hostname
X-NGENIX-Cache
X-Nyt-Route
X-Gdpr
Request-ID
X-Origin-Time
X-FPC
X-Cache-Config
X-API-Version
X-Edge-Location
X-UA
X-Geo
X-SN
X-Check-Cacheable
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-RPM
X-Cs
X-DI
X-DB
X-DSS
X-DW
X-ServedByHost
X-Hcs-Proxy-Type
X-RPS
X-RSL
X-Viewer-Country
X-VC
Cache-Provider
X-WA
X-TIM-N
DataCenter
CF-Cached-On
Ohc-Cache-HIT
FSS-Cache
X-NGINX-Cache
X-Forwarded-Site
X-Webstats-RespID
X-SB
X-Via-NSCOPI
X-App
Server-Id
X-Extlb
X-NodeID
GeoIP-Latitude
GeoIP-Country-Code
Mime-Version
X-Bc-Bl
ProcessTime
X-SD-PageType
X-Action
X-TIME
X-CF-Powered-By
X-Fpc
X-Region-Sid
X-Proxy-Upstream
X-PJAX-URL
X-Oss-Cdn-Auth
We-Hiring
Surrogated-Key
X-Accel-Expires-Debug
Mail-Subject
X-Date
X-BBC-Edge-Cache-Status
Memcached
X-Req
LB
Srv
X-VC-Cache
X-Render-Time
X-Depends-On
X-Swift-Error
X-Dynatrace-Js-Agent
X-ZONE
X-CSRF-TOKEN
X-Provided-By
W
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-UnsetCookies
Upgrade-Insecure-Requests
X-FTR-Cache-Host
Env
EpKe-Alive
X-FORWARDED-FOR
X-Cdn-Request-ID
X-Oracle-Dms-Rid
X-Sigma
X-Rocket-Build-Number
Processtime
X-Dw-Trace-Id
X-Sigma-Backend
Memory
X-Ua
X-MSEdge-Features
X-MSEdge-Flight
Time
CDN
Cdn
X-Auto-Login
X-Ftr-Cache-Host
X-BACKEND-TTL
X-APP
X-Air-Trace-Id
X-Worker
X-Men
Datacenter
X-Client-Ip
X-Akamai-Pragma-Client-IP
X-CACHE-AGE
X-Fastly-Request-Id
X-Fastly-Backend-Reqs
VNS-Cache
X-Hello
X-Flog
X-ABtesting
Proxy-Connection
X-Parent-Response-Time
X-Cluster-Node
X-Cache-Tag
Dnion-Transfer-Encoding
VNS-Age
CPC-Cache
CPC-Age
X-Acquia-Purge-Tags
Media-Length
X-IN-APIGATEWAYSSL
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-Presslabs-Stats
X-Pad
X-IN-APIGATEWAY
Vha6-Origin
X-BBC-Origin-Response-Status
PICS-Label
X-Oracle-DMS-ECID
X-Pf-Uncompressing
X-Zone
X-Acquia-Site
Epwk-X-Cache
X-LiteSpeed-Tag
X-Snapshot-Date
X-Via-PopH
X-HITS
X-Via-PopN
X-Via-PopV
X-Lb-Id
Cf-Ipcountry
X-Varnish-URL
X-Vcache
State
My-App
X-Request-Url
X-MiniProfiler-Ids
X-Varnish-Beresp-TTL
X-ServerName
X-ElasticPress-Query
X-Request-URL
X-Akamai-ERRuleID
Fastcgi-Cache-TTL
X-Akamai-ERPolicy
X-ElasticPress-Search
Xet-Cookie
X-Ms-Meta-Originalurl
OT-Force-Account-Verify
X-Ms-Meta-Staticbatchstarttime
X-Csrf-Token
CountryCode
X-Tx-Id
X-Amz-Meta-Cb-Modifiedtime
X-Apw-Hits
X-Apw-Access-Action
Content-Style-Type
Content-Script-Type
X-Minions-Version
X-Litespeed-Cache-Control
X-Apw-Access-Object
X-Apw-Access-Token
X-C
X-Redis-Count
X-Redis-Duration-Ms
URI
Environment
X-Storefront-Renderer-Verified
X-ND-Cache
WZWS-RAY
X-Traceid
NnCoection
X-Debug-Cache-Store
Inserted-Into-Cache-At
X-Debug-Cache-Fetch
Ohc-Response-Time
X-B3-Parentspanid
Phost
X-Tid