Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-RAY
CF-Cache-Status
X-XSS-Protection
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
P3P
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-UA-Compatible
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Request-ID
X-Xss-Protection
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
X-Ua-Compatible
Content-Encoding
X-CDN
X-Envoy-Upstream-Service-Time
X-AspNetMvc-Version
Feature-Policy
Status
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Access-Control-Max-Age
Upgrade
X-Via
Keep-Alive
X-Ws-Request-Id
X-Age
X-Turbo-Charged-By
X-AH-Environment
X-Robots-Tag
Request-Context
X-Proxy-Cache
EagleId
X-Cache-Group
Server-Timing
X-Backend
X-Hacker
X-Server
Report-To
X-Amz-Request-Id
Host-Header
X-Server-Powered-By
X-Amz-Id-2
Grace
X-Nginx-Cache-Status
X-UA-Device
X-Rq
X-Varnish-Cache
P3p
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Page-Speed
X-Dns-Prefetch-Control
Cf-Railgun
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-OneAgent-JS-Injection
NEL
X-Amz-Version-Id
X-Cache-Spec
Xkey
Allow
X-Device
X-CST
X-Backend-Server
X-Vhost
X-WebKit-CSP
X-Host
EagleEye-TraceId
X-Server-Id
Surrogate-Control
Request-Id
X-Dispatcher
X-Node
Content-Location
X-Response-Time
X-Ruxit-JS-Agent
Accept-CH
X-Akam-SW-Version
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Accept-CH-Lifetime
X-Ac
X-ASPNET-VERSION
X-Application-Context
X-Template
X-Language
X-Country
X-Cache-Lookup
X-Mod-Pagespeed
X-Readtime
X-Cloud-Trace-Context
MS-Author-Via
X-B3-TraceId
X-Origin-Cache
Rating
X-Cnection
Accept-Ch
X-MS-InvokeApp
X-HW
X-Url
X-PC
X-TtlSet
X-Vname
Accept-Ch-Lifetime
X-Clacks-Overhead
X-ORACLE-DMS-ECID
X-GitHub-Request-Id
Edge-Control
X-ESI
X-Trace
X-FastCGI-Cache
X-Middleton-Display
Response
Pagespeed
X-Sol
Display
X-Middleton-Response
X-Content-Type
X-D2id
Arr-Disable-Session-Affinity
X-Use-Magma
X-Vcap-Request-Id
X-GoogleNews-Bot
X-Cdn-Fetch
X-Kinja-Revision
X-Kinja
X-Kinja-Server
X-Kinja-Build
X-Exp-Id
X-Exp-Variant
Verso
X-Goog-Hash
X-Webkit-CSP
X-Buckets
X-Rack-Cache
X-Country-Code
X-ORACLE-DMS-RID
X-Server-Name
X-Varnish-TTL
Service-Worker-Allowed
X-Navigation-Version
X-VARITI-CCR
X-Abt-Application-Version
X-Amz-Rid
X-Fastly-Request-ID
X-Powered-By-Plesk
X-Client-IP
X-Cache-TTL
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
Fastly-Restarts
X-Release
SPRequestGuid
X-SharePointHealthScore
X-MSEdge-Ref
X-Element-Page-Cache
X-Dw-Request-Base-Id
SPIisLatency
SPRequestDuration
X-Kinja-Server-Push
X-Cached
X-NF-Request-ID
X-TTL
X-Oneagent-Js-Injection
Public-Key-Pins
RTSS
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
Access-Control-Request-Method
AR-PoweredBy
AR-ATIME
AR-CACHE
Ar-Sid
X-Edge
AR-Request-ID
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-LLID
X-Powered-CMS
X-Origin-Upstream-Status
X-Ezoic-Cdn
X-Px
X-Upstream
X-Ttl
Fusion-Template-Id
Fusion-Deployment-Id
Fusion-Component-Id
Fusion-Source
Content-MD5
Fusion-Content-Source
Fusion-Content-Id
X-Litespeed-Cache
Cache-Tag
X-Jurisdiction
X-HP-Webp
X-MCACHE
X-ECACHE
X-Mid
S
X-Version
X-Recruiting
X-Mg-S
Charset
X-Content-Digest
X-Amz-Server-Side-Encryption
X-PressLabs-Stats
Fastcgi-Cache
X-T
TCN
X-Kinsta-Cache
MicrosoftSharePointTeamServices
X-Content-Security-Policy-Report-Only
X-Id
Front-End-Https
Cache-Tags
Filters
X-Pinterest-Direct
X-Debug
X-Grace
Edge-Cache-Tag
Server-Node
X-Accel-Expires
X-Logged-In
X-Forwarded-Proto
X-Forwarded-For
X-Correlation-Id
X-DynaTrace
Server-Name
X-Amzn-Trace-Id
Nginx-Cache
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
TP-L2-Cache
TP-Cache
X-Yandex-Sdch-Disable
X-Varnish-Age
Surrogate-Key
X-B3-Sampled
X-Request-Received
X-Request-Processing-Time
X-Request-Handler-Origin-Region
X-Microsite
X-Shield-Request-Id
X-Ser
X-XRDS-LOCATION
X-Hits
X-AppVersion
X-Az
X-Activity-Id
X-DIS-Request-ID
X-Amz-Replication-Status
X-Server-ID
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Combine-CSS
X-HS-Hub-Id
X-Goog-Metageneration
X-Goog-Storage-Class
X-F-Cache
X-GUploader-UploadID
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Origin-Server
Accept-Charset
X-XRDS-Location
X-Git-Hash
X-Geo-Country
X-Cache-Key
X-Respond-Thread
Powered-By-ChinaCache
X-FTR-Request-ID
Cache
X-Rid
Section-Io-Cache
Alternate-Protocol
X-LB-Cache
X-Upgrade-Enabled
X-Frontend
X-DataDome
Host
Access-Control-Allow-Method
X-Cache-Age
X-Mobile-URL
X-Seen-By
Cleartype
Paypal-Debug-Id
MS-CV
X-Time
X-IPLB-Instance
X-AOL-HN
Healthy
X-Varnish-Backend
X-Type
X-NWS-LOG-UUID
X-Hostname
X-Ruxit-Js-Agent
X-Content-Options
X-VCache
ServerID
X-Whom
X-App-Environment
X-Cache-Action
Payment
X-Aspnet-Duration-Ms
X-Is-Crawler
X-Request-Guid
X-Flags
X-Route-Name
X-Providence-Cookie
X-TT
X-WebKit-CSP-Report-Only
X-Debug-Info
X-B-Cache
X-Page-Id
X-Jobs
X-Signature
Fastcgi-Useragent
X-N
X-Source
X-Load-Cache
X-Mobile
X-Daa-Tunnel
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Fastcgi-Cache
X-TEC-API-VERSION
X-FB-Debug
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Via-JSL
X-RateLimit-Remaining
Nel
Version
X-Cached-By
X-Cache-Operation
X-Cache-Rule
Refresh
X-Akamai-Edgescape
Viewport
X-Accel-Buffering
X-Original-Request-Id
X-Wix-Request-Id
X-Rule
X-Response-Served-From
DC
X-Cacheable-TTL
X-Framework
X-Drupal-Cache-Tags
X-Proxy
X-Contextid
Access-Control-Request-Headers
Ms-Operation-Id
X-RTag
X-RemovedCookies
X-Zen-Fury
X-ProcessESI
X-Real-IP
Node
Realpath
X-Instance
DynaTrace
X-Cache-Time
X-UUID
X-Region
X-HTML-Minification-Powered-By
Eomportal-Instance
X-Tt-Trace-Tag
X-Distributor
X-Yottaa-Metrics
Referer-Policy
X-Tt-Trace-Host
X-Page-View
X-Yottaa-Optimizations
X-Drupal-Cache-Contexts
X-FW-Static
X-FW-Server
Countrycode
X-FW-Hash
X-Cache-Expired-At
X-FW-Dynamic
X-FW-Type
X-Cluster-Name
X-FW-Serve
X-B
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Cache-Control
X-Content-Powered-By
X-L-Path
X-IPS-LoggedIn
GEO-INFO
X-Environment-Context
X-Tumblr-Pixel-1
X-Tumblr-User
X-Cache-Hit
X-Tumblr-Pixel
X-G
X-Tumblr-Pixel-0
Liferay-Portal
X-Ratelimit-Limit
Server-Info
X-User-Agent
X-Pass-Why
X-App-Server
X-FireWall-Port
X-Node-Name
X-Tumblr-Pixel-2
Section-Io-Id
Section-Origin-Responded
Webserver
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
From-Origin
X-Varnish-Ttl
Ec-Rule-Version
X-Protected-By
Protected
CF-IPCountry
Xserver
X-Cache-Server
X-Ratelimit-Remaining
X-Www-Served-By
X-Backend-Name
X-Amz-Meta-S3cmd-Attrs
X-Revision
Frame-Options
X-Mode
X-RN-RSRV
X-Hl-Ver
Meta-Geo
X-Endurance-Cache-Level
X-ES-SERVER
X-UPSTREAM-Address
SRV
X-Handled-By
X-Hyper-Cache
X-Site-Version
X-FB-TRIP-ID
X-Soup
X-Locale
Cache-Status
X-Storage
X-NYM-Debug-Backend
X-Human
Country
X-Varnishpool
X-Cache-Grace
X-Web-Node
X-Forwarded-Host
X-Be
Cache-Tv-Group
Cache-Name
Decoy-Debug-Status
TWC-GeoIP-LatLong
Azure-RegionName
X-Pubstack
TWC-Device-Class
Azure-Version
X-Request-Time
TWC-Connection-Speed
Azure-SlotName
Selected-Fe
Azure-SiteName
Webcakes-App-Version
X-ProxyCache-Status
X-Redis-Cache
TWC-Privacy
X-UA-Device-Type
X-Origin-Date
X-Origin-Hint
X-TT-LOGID
Webcakes-Region
Fastly-SSL
Webcakes-App-Name
X-PHP-Host
TWC-GeoIP-Country
Decoy-Debug-Key
X-Uri
X-Proto
Property-Id
X-Timing-Wait
X-Proxy-Build
X-ProxyCache-Key
Retry-After
X-BYPASS-REASON
Decoy-Debug-TTL
Azure-InstanceId
X-Labrador-Cache-Channel
TWC-Locale-Group
X-PCL
X-OCL
X-Loop
X-Tec-Api-Root
X-Adobe-Loc
X-Adobe-Content
X-Section
X-MP-GENERATED-AT
X-Sql-Duration-Ms
X-Hosted-By
X-Access
X-Server-W
X-S-Maxage
X-Format
X-AIR-PT
X-FW-Version
X-TNCMS
X-Tec-Api-Version
X-Say-TTL
X-WA-Info
X-Say-Cacheable
X-Via-Fastly
X-Tec-Api-Origin
X-Sql-Count
X-No-Session
X-SayCDN-TTL
X-LJ-Flow-ID
X-LAGOON
X-ApacheServer
X-Status
X-R9-Blue-Green-Version
X-AWS-Id
X-Nginx-Cache
X-PERF
X-VWS-Id
Mn-Server-Ip
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Storefront-Renderer-Rendered
X-Cache-TTL-Remaining
X-Cluster
X-Shopify-Stage
X-Alternate-Cache-Key
X-ShopId
X-ShardId
X-Proxied
X-Device-Type
X-Zipkin-Id
X-Routing-Service
X-CCM
X-Xfnlog-Site
X-Is-Bot
X-Qloud-Router
AMP-Access-Control-Allow-Source-Origin
X-Debug-IsConnected
X-Debug-IsPreview
X-Rendered-As
X-Dc
X-Via-CDN
X-FTR-Realm
X-FTR-Backend-Server
S-Cnection
X-Country-Code-Real
Cache-Hits
X-FTR-Balancer
X-FTR-Backend
X-FTR-Cache-Status
X-FTR-DC
X-Info
Apigw-Requestid
X-Varnish-Grace
X-SRV
X-FTR-Expires
X-Varnish-Server
X-Detected-As
X-Cdn
X-Cache-Enabled
X-Cache-Host
X-GG-Cache-Date
X-Amzn-Remapped-Content-Length
X-Air-Hostname
X-EdgeConnect-Cache-Status
X-Unique-Id
X-Microcachable
X-Amz-Apigw-Id
X-Content-Age
X-Amzn-RequestId
X-Platform
X-Cache-Var-Map
X-Cache-Var
X-Azure-Ref
Uber-Trace-Id
Tracecode
X-Backend-Host
X-Aspnetmvc-Version
SD-X-WS
X-DynaTrace-JS-Agent
X-Proxy-Cache-Status
X-CSRF-Token
X-Time-Microsecs
X-GEO
X-NWS-UUID-VERIFY
X-Backend-TTL
X-ServerID
Akamai-GRN
Amp-Access-Control-Allow-Source-Origin
X-ATG-Version
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
X-Cache-Backend
X-Oss-Request-Id
X-Tb
X-Oss-Object-Type
X-Trace-Id
DSUID
Backend
X-BCube-Filmed-By
X-Varnish-Hostname
ServedBy
X-RCS-CacheZone
X-Akamai-Transformed
X-TA-CDN-Provider
X-Oracle-Dms-Rid
X-Cache-NGX
X-App-Version
X-Cache-PHP
X-Correlation-ID
X-From
X-A
DCR-Decision-By
X-Fetched-On
X-Generated-On
X-Generation-Time
HostName
X-GeoIP-City
X-Debug-Cache
T-Server
X-A-Ccd
X-External-Request-Id
X-Varnish-Cache-Hits
X-Aed
X-Cache-NE
X-A-Wwc
X-Application
X-Dynatrace
X-B-Cookie
Thinkindot-CacheControl-Type
X-ARC
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Device-Os
X-A-Dcw
Thinkindot-CacheControl
X-Destination
X-D
X-Magnolia-Registration
X-Connection-Hash
X-A-Dgt
X-A-Dam
Release
BehaviorPad-Version
X-Thinkindot-L3
X-Trv-Group
Fastcgi-X-Cache-Version
Instruction
X-SRCache-Key
X-S-Cookie
X-Session-Fingerprint
Machine
Lfy
X-Vdms-Path
X-Vdms-Version
PB-PID
PB-RID
Xc-Version
DCR-Processing-Time-Ms
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
X-VG-WebCache
X-VG-WebServer
Arc-Version
Expiry
X-S
X-ScT
X-Origin-CC
Path
Odigeo-Trace-Id
X-Origin-TTL
Mobile-Detection-Method
Thinkindot-Control
X-Matched-Rule
SR-User-Adfree
Rendered-Blocks
X-Level-Front-Cache
X-Location
X-Rojux
X-Sucuri-ID
MD5-Digest
X-Processor
X-Request-UUID
X-Rewrite-Enabled
X-APP-VERSION
X-PBS-Appsvrname
X-PAYTM-SRV-ID
Meta-Geo-Continent
X-B3-SpanId
X-Erf-Stays-Bingo-Pdp-Web
X-NewRelic-App-Data
Gh-Request-Id
Ssr
Host-ID
Pagetype
Fastly-Backend-Name
X-Has-Esi
X-Sn-Servicetimems
X-SVT-ORM-RULES
X-Skip-Cache
X-Reqid
X-OVcl
X-OVcl-Cache
X-SVT-ORM-VERSION
X-Swa-Ws
X-VServer
X-Owner
X-Tumblr-Pixel-3
X-TrackingId
X-Thanos
X-Origin-Response-Time
X-Node-Id
X-Cdn-Origin
X-FC-Vary-Parameters
X-Cache-Bucket
X-Bip
X-Azure-Ref-OriginShield
X-GeoIP
X-HS-Content-Campaign-Id
X-Micro-Cache
X-Mvc-Supplant-Cachable
X-JWT-State
X-Is-Gdpr
X-Irp-Debug
UCS
X-Geo-Header
CacheControlHeader
Cache-Host
AKAMAI
X-Ms-Version
C-Via
Cf-Device-Type
X-Ms-Request-Id
X-Cdn-Forward
X-TX-ID
Wxu-Next-Hostname
X-Adobe-Source
Wxu-Next-Region
X-Nginx-Cache-Key
X-Policy
X-Scheme
Server-Hostname
Server-Ext
Sever-Int
X-Core-Value
X-Origin-Expires
X-IP
Wxu-Next-Commit
X-B3-Traceid
X-Developer
X-NAPM-TraceId
X-Developers
X-CUA
X-CGP
X-Cms-Context
X-Clientip
X-Csrf-Jwt
X-Eu-Site
X-Cache-Tags
X-Generated-In
Pramga
X-Backend-State
X-Generated-By
X-Fastly-Cache
X-Fastly-Backend
X-Cache-Info
X-HN
X-Request-Host
Locid
L5d-Success-Class
L
Magicmarker
X-Varnish-Beresp-Grace
X-User
X-Var-Ttl
X-Varnish-Hits
X-VarnishDD-TTL
X-Wikidot-Static-Cache
DB-Nickname
Content-Disposition
X-Wikidot-Backend
Server-Host
HA-Ipaddr
Ha-Gx-Prefs
CloudFront-Viewer-Country
Location
NGX
PFcat
On-Server
User-Cache-Control
X-CS
X-Gamma-Serve
NM-Fastcgi-Cache
X-Dispatcher-Server
X-Gen-Mode
X-DefElseHash
X-Gzip
X-Cache-Id
X-DefHash
V-Age
Platform
Adler-Geo
Is-Eu
X-SIPLIST1
X-Servername
X-Esi-Check
X-GoCache-CacheStatus
X-Slack-Backend
X-Envoy-Decorator-Operation
X-WADP-Cache
X-Branch-Name
X-Hash
X-Rebelmouse-Surrogate-Control
X-Origin
X-Variation
X-Varnish-Beresp-Status
X-NU-AKA-ACS-Version
X-Rebelmouse-Cache-Control
X-LI-UUID
X-Platform-Server
X-Old-Content-Length
X-Ratelimit-Reset
X-Li-Fabric
X-Varnish-CookieHashed-On
X-Varnish-Beresp-Ttl
X-Hnp-Log
X-Request-URI
X-Li-Pop
X-Varnish-Remaining-TTL
X-Loc
X-DPWN-IS-SECURE
X-Method
X-Varnish-CookieINHashed-On
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Fmm-Version
IsBot
X-Cache-Expires
Fastly-SIE
X-Cache-Date
Web-Mar-Node
X-Block-Status
Fastly-SWR
CDCHOST
Fastly-Drupal-HTML
X-Clara-WADP
Cf-Bgj
Origin
Rt-Fastcgi-Cache
X-ID
X-EC-Lua
CDN-EdgeStorageId
Vix-Hermes-Req-Id
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
X-VG-TLSProxy
CDN-CachedAt
CDN-Cache
Apple-News-Services-Host
Apple-News-Services-Request-Url
CDN-RequestCountryCode
CDN-RequestId
X-Core-Mission
X-Cache-Debug
CDN-Uid
True-Client-Country-4JS
CDN-PullZone
Sid
X-PF-Uncompressing
X-Aicache-OS
X-Request-Start
X-NCache
X-LB-ID
X-Mvc-Supplant-OutputCached
X-CACHE-KEY
Url
X-Refresh
X-Cache-Remote
X-NC
Esi-Enabled
X-Via-Popn
X-Via-Popv
X-CACHE-GROUP
X-Via-Poph
X-Varnish-Url
X-Nc
X-Varnish-Cacheable
S-Rt
X-Response-By
Who
Pics-Label
Xkeyi7
Country-Code
X-Host-Name
X-Proxy-Cachei7
X-Epic-Correlation-Id
X-FireWall-Protection
X-B3-Spanid
N-Cache
X-TraceId
X-BBXSRF
X-Unique-ID
Req-Svc-Chain
X-Tb-Optimization-Total-Bytes-Saved
X-Planisys-CDN-TTL
X-Cache-2
Source
X-Planisys-CDN-Rules
Content-Secure-Policy
X-Planisys-CDN-Cache
X-Webkit-Csp
Ohc-File-Size
Server-Ttl
Cross-Origin-Window-Policy
X-Error
X-Srv
X-Varnish-Authentication
X-HS-Status
GeoIp-Country-Code
X-Cc-Req-Id
X-Sucuri-Cache
D-Cc-Upstream
X-Cache-ASPX
X-Cc-Via
X-Contensis-Viewer-Groups
Geoip-Latitude
X-Webkit-CSP-Report-Only
Cteonnt-Length
X-DC
X-CLOUD-TRACE-CONTEXT
X-LiteSpeed-Cache-Control
HitType
X-Svr
Cmsid
Cmstype
CACHE
Geo-Info
Kp-EeAlive
X-CDN-Forward
X-RateLimit-Limit
X-Served-From
Svr
MIME-Version
X-Wa
X-Server-IP
X-Servedbyhost
X-URL
X-Cs
X-HostName
Viewtype
VivaBuild
X-Origin-Time
X-Cache-Config
X-Gdpr
Filterid
X-Nyt-Route
X-Vcl-Version
Cache-Key
A
X-FPC
X-API-Version
Resin-Trace
X-Li-Proto
M-TraceId
X-VC
Server-Id
X-RAMCache
X-Esi
X-SN
Ohc-Cache-HIT
Arc-Country
X-LI-Proto
X-Air-Source
Cross-Origin-Opener-Policy
TDXMobile
X-Webstats-RespID
Hostname
X-SB
X-NodeID
Server-ID
X-Vgn-Hpd-Reason
X-NGINX-Cache
NtCoent-Length
X-HOST
X-Check-Cacheable
X-VCL-Version
X-Internal-Host
Tcn
NGB
SID
X-Viewer-Country
Srv
Request-ID
X-SD-PageType
X-UA
X-DB
X-DW
X-DSS
Mime-Version
X-ServedByHost
X-WA
Cache-Provider
X-RPM
X-DI
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
XServer
X-RPS
X-CCDN-CacheTTL
X-Vc
X-TIM-N
X-Render-Time
X-RSL
X-Newrelic-Synthetics
X-TIME
X-Ua
GeoIP-Latitude
GeoIP-Country-Code
X-BBC-Edge-Cache-Status
X-Service
EpKe-Alive
DataCenter
X-Auto-Login
Upgrade-Insecure-Requests
X-PHP-Backend
X-Worker
X-Action
ProcessTime
X-NGENIX-Cache
X-App
Processtime
X-JoinUs
X-SaId
X-CF-Powered-By
X-Edge-Location
X-Extlb
X-Geo
X-FTR-Cache-Host
X-Via-NSCOPI
X-Oss-Cdn-Auth
X-Fpc
X-Forwarded-Site
FSS-Cache
X-Provided-By
X-Cdn-Request-ID
X-Dynatrace-Js-Agent
X-Ftr-Cache-Host
W
Proxy-Connection
CDN
X-CSRF-TOKEN
X-FORWARDED-FOR
Datacenter
X-Cluster-Node
X-Swift-Error
X-HITS
CF-Cached-On
X-PJAX-URL
X-Proxy-Upstream
X-MSEdge-Features
X-MSEdge-Flight
X-Fastly-Backend-Reqs
X-Depends-On
We-Hiring
X-Parent-Response-Time
X-Region-Sid
X-Req
X-BBC-Origin-Response-Status
X-Dw-Trace-Id
Cdn
X-VC-Cache
X-Date
Mail-Subject
LB
Memcached
Surrogated-Key
PICS-Label
X-BACKEND-TTL
X-Accel-Expires-Debug
X-Bc-Bl
X-Zone
X-Client-Ip
X-CACHE-AGE
X-ABtesting
X-Pad
X-Cache-Tag
X-IN-APIGATEWAY
X-RateLimit-Limit-Second
X-Hello
X-RateLimit-Remaining-Second
X-Flog
X-IN-APIGATEWAYSSL
OT-Force-Account-Verify
X-APP
X-Rocket-Build-Number
Env
X-Fastly-Request-Id
X-UnsetCookies
X-Sigma
Dnion-Transfer-Encoding
X-Sigma-Backend
X-Akamai-Pragma-Client-IP
X-Men
X-Via-PopV
X-Air-Trace-Id
Media-Length
X-Acquia-Site
X-Acquia-Purge-Tags
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Pf-Uncompressing
X-Via-PopN
X-Oracle-DMS-ECID
X-Presslabs-Stats
X-ND-Cache
X-Via-PopH
Vha6-Origin
X-Varnish-URL
CPC-Cache
Time
WZWS-RAY
Memory
Epwk-X-Cache
CPC-Age
VNS-Cache
X-Lb-Id
VNS-Age
X-MiniProfiler-Ids
X-LiteSpeed-Tag
X-ZONE
Cf-Ipcountry
X-Akamai-ERRuleID
X-Snapshot-Date
X-Csrf-Token
X-Akamai-ERPolicy
X-ElasticPress-Query
URI
X-Request-URL
X-Varnish-Beresp-TTL
X-Request-Url
X-Vcache
X-Ms-Meta-Staticbatchstarttime
Xet-Cookie
X-Ms-Meta-Originalurl
X-ElasticPress-Search
CountryCode
Content-Style-Type
X-Storefront-Renderer-Verified
Content-Script-Type
X-Litespeed-Cache-Control
X-C
X-ServerName
X-Amz-Meta-Cb-Modifiedtime
Inserted-Into-Cache-At
X-B3-Parentspanid
X-Debug-Cache-Store
X-Debug-Cache-Fetch
Phost
NnCoection
X-Traceid
Environment
X-Redis-Count
Ohc-Response-Time
X-Redis-Duration-Ms
X-Tid