Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
X-XSS-Protection
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
P3P
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-UA-Compatible
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Request-ID
X-Xss-Protection
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
X-Ua-Compatible
Content-Encoding
X-CDN
X-Envoy-Upstream-Service-Time
X-AspNetMvc-Version
Status
Feature-Policy
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Upgrade
Access-Control-Max-Age
X-Via
Keep-Alive
X-Ws-Request-Id
X-Age
X-Turbo-Charged-By
X-AH-Environment
X-Robots-Tag
Request-Context
X-Proxy-Cache
EagleId
X-Cache-Group
Server-Timing
X-Backend
X-Hacker
X-Server
Report-To
X-Amz-Request-Id
Host-Header
X-Server-Powered-By
X-Amz-Id-2
Grace
X-Nginx-Cache-Status
X-UA-Device
X-Rq
X-Varnish-Cache
P3p
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Page-Speed
X-Dns-Prefetch-Control
Cf-Railgun
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
NEL
X-Amz-Version-Id
X-Cache-Spec
Xkey
X-Device
Allow
X-CST
X-Backend-Server
X-Vhost
X-WebKit-CSP
X-Host
EagleEye-TraceId
X-Server-Id
Request-Id
Surrogate-Control
X-Dispatcher
X-Node
Content-Location
X-Response-Time
X-Ruxit-JS-Agent
Accept-CH
X-Akam-SW-Version
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Accept-CH-Lifetime
X-Ac
X-ASPNET-VERSION
X-Application-Context
X-Template
X-Language
X-Country
X-Cache-Lookup
X-Mod-Pagespeed
X-Readtime
X-Cloud-Trace-Context
MS-Author-Via
X-B3-TraceId
X-Origin-Cache
Rating
X-Cnection
Accept-Ch
X-MS-InvokeApp
X-HW
X-Url
X-TtlSet
X-Vname
X-PC
Accept-Ch-Lifetime
X-Clacks-Overhead
X-GitHub-Request-Id
X-ORACLE-DMS-ECID
Edge-Control
X-ESI
X-Trace
X-FastCGI-Cache
X-Middleton-Display
X-Middleton-Response
Response
Pagespeed
Display
X-Content-Type
X-Sol
X-D2id
X-Use-Magma
X-Vcap-Request-Id
X-GoogleNews-Bot
Arr-Disable-Session-Affinity
X-Exp-Id
X-Kinja
X-Kinja-Revision
X-Kinja-Build
X-Cdn-Fetch
X-Kinja-Server
X-Exp-Variant
Verso
X-Goog-Hash
X-Webkit-CSP
X-Buckets
X-Rack-Cache
X-ORACLE-DMS-RID
X-Country-Code
X-Server-Name
X-Varnish-TTL
Service-Worker-Allowed
X-Navigation-Version
X-VARITI-CCR
X-Abt-Application-Version
X-Fastly-Request-ID
X-Amz-Rid
X-Powered-By-Plesk
X-Client-IP
X-Cache-TTL
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
X-Release
SPRequestGuid
X-SharePointHealthScore
Fastly-Restarts
X-MSEdge-Ref
X-Dw-Request-Base-Id
X-Element-Page-Cache
SPRequestDuration
X-Kinja-Server-Push
SPIisLatency
X-Cached
X-NF-Request-ID
X-TTL
X-Oneagent-Js-Injection
Public-Key-Pins
X-B3-TraceId-Primal
MRF-Tech
RTSS
Mrf-Cache-Status
AR-CACHE
AR-ATIME
Ar-Sid
X-Edge
AR-Request-ID
AR-PoweredBy
X-SRCache-Fetch-Status
Access-Control-Request-Method
X-SRCache-Store-Status
X-LLID
X-Powered-CMS
X-Origin-Upstream-Status
X-Ezoic-Cdn
X-Px
X-Upstream
X-Ttl
Content-MD5
Fusion-Content-Source
Fusion-Component-Id
Fusion-Content-Id
Fusion-Deployment-Id
Fusion-Template-Id
Fusion-Source
X-Litespeed-Cache
Cache-Tag
X-Jurisdiction
X-HP-Webp
X-MCACHE
X-Mid
X-ECACHE
S
X-Version
X-Mg-S
X-Content-Digest
X-Recruiting
X-PressLabs-Stats
X-Amz-Server-Side-Encryption
Charset
Fastcgi-Cache
X-T
TCN
MicrosoftSharePointTeamServices
X-Kinsta-Cache
Front-End-Https
X-Content-Security-Policy-Report-Only
X-Id
X-Pinterest-Direct
Filters
X-Debug
Cache-Tags
X-Grace
Edge-Cache-Tag
X-Accel-Expires
X-Logged-In
Server-Node
X-Forwarded-Proto
X-Forwarded-For
X-Correlation-Id
X-DynaTrace
X-Amzn-Trace-Id
Nginx-Cache
Server-Name
X-Kong-Proxy-Latency
TP-L2-Cache
TP-Cache
X-Kong-Upstream-Latency
X-Yandex-Sdch-Disable
X-Varnish-Age
X-B3-Sampled
Surrogate-Key
X-Request-Received
X-Request-Processing-Time
X-Microsite
X-Request-Handler-Origin-Region
X-Shield-Request-Id
X-Ser
X-XRDS-LOCATION
X-Hits
X-Activity-Id
X-AppVersion
X-Az
X-DIS-Request-ID
X-Amz-Replication-Status
X-Server-ID
X-HS-Combine-CSS
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Hub-Id
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-F-Cache
X-Origin-Server
Accept-Charset
X-XRDS-Location
X-Git-Hash
X-Geo-Country
X-Cache-Key
X-Respond-Thread
Powered-By-ChinaCache
X-FTR-Request-ID
Cache
X-Rid
Alternate-Protocol
X-LB-Cache
X-Upgrade-Enabled
Section-Io-Cache
X-Frontend
X-DataDome
Host
Access-Control-Allow-Method
X-Mobile-URL
X-Cache-Age
X-Seen-By
Cleartype
Paypal-Debug-Id
MS-CV
Healthy
X-Time
X-IPLB-Instance
X-AOL-HN
X-NWS-LOG-UUID
X-Varnish-Backend
X-Hostname
X-Ruxit-Js-Agent
X-VCache
ServerID
X-Whom
X-App-Environment
X-Type
X-Content-Options
X-Request-Guid
X-Cache-Action
X-Is-Crawler
X-Flags
X-Aspnet-Duration-Ms
X-Providence-Cookie
X-Route-Name
X-TT
X-WebKit-CSP-Report-Only
X-Page-Id
X-Jobs
Payment
X-Debug-Info
X-Signature
Fastcgi-Useragent
X-B-Cache
X-N
X-Source
X-Load-Cache
X-Mobile
X-TEC-API-VERSION
X-Daa-Tunnel
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Fastcgi-Cache
X-FB-Debug
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Via-JSL
Nel
X-RateLimit-Remaining
Version
Refresh
X-Cached-By
X-Cache-Rule
X-Cache-Operation
X-Akamai-Edgescape
X-Response-Served-From
X-Wix-Request-Id
Viewport
X-Accel-Buffering
X-Rule
X-Original-Request-Id
X-Drupal-Cache-Tags
DC
X-Framework
X-Proxy
X-Cacheable-TTL
X-RTag
Access-Control-Request-Headers
X-ProcessESI
Ms-Operation-Id
X-RemovedCookies
X-Zen-Fury
X-Contextid
X-Real-IP
Realpath
X-Region
Node
X-UUID
X-HTML-Minification-Powered-By
DynaTrace
X-Instance
X-Cache-Time
X-Tt-Trace-Host
X-Distributor
X-Page-View
Referer-Policy
X-Drupal-Cache-Contexts
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Tt-Trace-Tag
Eomportal-Instance
X-FW-Dynamic
X-FW-Static
X-FW-Hash
X-Cache-Expired-At
X-FW-Type
X-FW-Serve
Countrycode
X-FW-Server
X-Cluster-Name
X-B
X-Cache-Control
X-Content-Powered-By
X-Environment-Context
X-L-Path
Liferay-Portal
X-Cache-Hit
X-IPS-LoggedIn
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-G
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Tumblr-Pixel
X-Tumblr-User
GEO-INFO
X-Ratelimit-Limit
Server-Info
X-User-Agent
X-App-Server
X-Node-Name
X-FireWall-Port
X-Pass-Why
X-Tumblr-Pixel-2
From-Origin
Webserver
Section-Io-Id
Ec-Rule-Version
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
Section-Io-Origin-Status
X-Varnish-Ttl
X-Protected-By
Protected
CF-IPCountry
Xserver
X-Cache-Server
X-Ratelimit-Remaining
X-Www-Served-By
X-Amz-Meta-S3cmd-Attrs
X-Revision
X-Backend-Name
Meta-Geo
X-Mode
X-Endurance-Cache-Level
X-UPSTREAM-Address
X-Hl-Ver
X-ES-SERVER
SRV
X-Handled-By
X-RN-RSRV
Frame-Options
X-Locale
X-FB-TRIP-ID
X-Soup
X-Site-Version
Cache-Status
X-Hyper-Cache
X-Be
X-Web-Node
Country
X-Human
X-Cache-Grace
Cache-Tv-Group
X-Varnishpool
X-Timing-Wait
X-Storage
X-Uri
TWC-Privacy
Cache-Name
X-TT-LOGID
X-ProxyCache-Status
TWC-Device-Class
TWC-GeoIP-Country
X-Forwarded-Host
X-Request-Time
TWC-Connection-Speed
X-BYPASS-REASON
TWC-Locale-Group
Selected-Fe
Property-Id
X-ProxyCache-Key
Azure-Version
X-Redis-Cache
Webcakes-Region
X-Proto
Retry-After
X-Origin-Date
X-Origin-Hint
X-NYM-Debug-Backend
Webcakes-App-Version
Azure-InstanceId
Azure-RegionName
Azure-SiteName
Azure-SlotName
X-PHP-Host
X-Labrador-Cache-Channel
X-Proxy-Build
Webcakes-App-Name
X-UA-Device-Type
TWC-GeoIP-LatLong
X-Hosted-By
Decoy-Debug-TTL
Decoy-Debug-Status
Decoy-Debug-Key
Fastly-SSL
X-Loop
X-Pubstack
X-No-Session
X-FW-Version
X-AIR-PT
X-MP-GENERATED-AT
X-Sql-Duration-Ms
X-Adobe-Loc
X-Adobe-Content
X-S-Maxage
X-TNCMS
X-Tec-Api-Origin
X-Via-Fastly
X-WA-Info
X-Tec-Api-Version
X-Tec-Api-Root
X-Server-W
X-Sql-Count
X-Format
X-AWS-Id
X-LJ-Flow-ID
X-Section
X-Say-Cacheable
X-Status
X-SayCDN-TTL
X-Say-TTL
X-PCL
X-R9-Blue-Green-Version
X-VWS-Id
X-Nginx-Cache
X-OCL
X-Access
Mn-Server-Ip
X-ApacheServer
X-Cache-TTL-Remaining
X-Storefront-Renderer-Rendered
X-LAGOON
X-Alternate-Cache-Key
X-Shopify-Stage
X-ShardId
X-ShopId
X-Cluster
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-PERF
X-Proxied
X-Routing-Service
X-Device-Type
X-Zipkin-Id
X-Debug-IsConnected
X-Rendered-As
X-Xfnlog-Site
X-Debug-IsPreview
X-Is-Bot
X-Qloud-Router
AMP-Access-Control-Allow-Source-Origin
X-Dc
X-CCM
X-FTR-Backend
X-FTR-Backend-Server
X-Country-Code-Real
Cache-Hits
S-Cnection
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-Realm
X-FTR-DC
X-Via-CDN
X-Info
X-FTR-Expires
X-SRV
X-Varnish-Grace
X-Varnish-Server
Apigw-Requestid
X-Detected-As
X-Cdn
X-Cache-Enabled
X-Cache-Host
X-GG-Cache-Date
X-Amz-Apigw-Id
X-Content-Age
X-EdgeConnect-Cache-Status
X-Microcachable
X-Amzn-Remapped-Content-Length
X-Air-Hostname
X-Amzn-RequestId
X-Platform
X-Unique-Id
X-Cache-Var-Map
X-Cache-Var
X-Azure-Ref
Uber-Trace-Id
Tracecode
X-Aspnetmvc-Version
X-Backend-Host
SD-X-WS
X-CSRF-Token
X-Proxy-Cache-Status
X-DynaTrace-JS-Agent
X-Time-Microsecs
X-GEO
X-Backend-TTL
X-NWS-UUID-VERIFY
Akamai-GRN
X-ServerID
X-ATG-Version
Amp-Access-Control-Allow-Source-Origin
X-Cache-Backend
X-Tb
X-Trace-Id
X-Oss-Hash-Crc64ecma
X-Oss-Storage-Class
X-Oss-Server-Time
X-Oss-Object-Type
X-Oss-Request-Id
DSUID
X-BCube-Filmed-By
Backend
X-Varnish-Hostname
X-RCS-CacheZone
X-Akamai-Transformed
X-Correlation-ID
X-App-Version
ServedBy
X-Oracle-Dms-Rid
X-TA-CDN-Provider
Odigeo-Trace-Id
SR-User-Adfree
Rendered-Blocks
Path
Mobile-Detection-Method
Release
DCR-Processing-Time-Ms
BehaviorPad-Version
DCR-Decision-By
X-Debug-Cache
X-Cache-PHP
X-Varnish-Cache-Hits
X-Cache-NGX
T-Server
Expiry
Machine
MD5-Digest
Lfy
Instruction
Fastcgi-X-Cache-Version
Meta-Geo-Continent
X-Aed
X-Processor
X-Request-UUID
X-Rewrite-Enabled
X-Rojux
X-PBS-Appsvrname
X-PAYTM-SRV-ID
X-Location
X-Matched-Rule
X-Origin-CC
X-Origin-TTL
X-S
X-S-Cookie
X-Vdms-Version
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-Vdms-Path
X-Trv-Group
X-ScT
X-Session-Fingerprint
X-SRCache-Key
X-Thinkindot-L3
X-Level-Front-Cache
X-GeoIP-City
X-A-Dgt
X-A-Wwc
X-Application
X-ARC
X-A-Dcw
X-A-Dam
Thinkindot-CacheControl-Type
Thinkindot-Control
X-A
X-A-Ccd
X-B-Cookie
X-Cache-NE
X-External-Request-Id
X-Fetched-On
X-From
X-Generated-On
X-Device-Os
X-Destination
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Connection-Hash
X-D
Thinkindot-CacheControl
X-Generation-Time
HostName
X-APP-VERSION
PB-PID
X-Dynatrace
X-Sucuri-ID
Arc-Version
X-Magnolia-Registration
PB-RID
X-Erf-Stays-Bingo-Pdp-Web
X-NewRelic-App-Data
X-B3-SpanId
X-VG-WebServer
X-VServer
X-VG-WebCache
X-Origin-Response-Time
X-Ms-Request-Id
Pagetype
X-Cache-Bucket
X-Node-Id
X-Mvc-Supplant-Cachable
CacheControlHeader
Cf-Device-Type
Fastly-Backend-Name
X-Bip
X-Cdn-Origin
Gh-Request-Id
X-Tumblr-Pixel-3
UCS
X-Sn-Servicetimems
X-OVcl-Cache
X-Skip-Cache
X-Reqid
X-Azure-Ref-OriginShield
X-Has-Esi
X-SVT-ORM-RULES
X-TrackingId
Cache-Host
X-Thanos
X-Swa-Ws
X-SVT-ORM-VERSION
Ssr
X-OVcl
Host-ID
AKAMAI
X-Owner
X-GeoIP
X-Is-Gdpr
X-FC-Vary-Parameters
C-Via
X-JWT-State
X-HS-Content-Campaign-Id
X-Irp-Debug
X-Micro-Cache
X-Geo-Header
X-Ms-Version
X-TX-ID
X-Cdn-Forward
X-Var-Ttl
X-Fastly-Backend
X-Fastly-Cache
Server-Ext
Pramga
X-Varnish-Beresp-Grace
PFcat
X-Varnish-Hits
NGX
X-Developers
X-NAPM-TraceId
X-Generated-By
X-Scheme
Wxu-Next-Commit
Wxu-Next-Hostname
Wxu-Next-Region
X-IP
X-VarnishDD-TTL
X-Policy
X-Adobe-Source
X-Request-Host
Sever-Int
Server-Hostname
On-Server
X-B3-Traceid
X-Wikidot-Backend
X-Core-Value
X-Nginx-Cache-Key
X-Cache-Tags
X-Wikidot-Static-Cache
DB-Nickname
X-Clientip
X-Cms-Context
Server-Host
CloudFront-Viewer-Country
Content-Disposition
L
X-CUA
X-Developer
Location
Magicmarker
X-HN
X-Origin-Expires
Locid
X-CS
User-Cache-Control
X-CGP
X-Eu-Site
X-Loc
X-GoCache-CacheStatus
X-Ratelimit-Reset
X-Backend-State
X-Hnp-Log
X-Clara-WADP
X-Generated-In
X-Fmm-Version
X-Cache-Date
X-Rebelmouse-Cache-Control
X-NU-AKA-ACS-Version
X-Cache-Info
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Block-Status
X-Method
X-Cache-Expires
X-Gen-Mode
X-Csrf-Jwt
X-Gamma-Serve
X-Platform-Server
Rt-Fastcgi-Cache
X-Cache-Id
X-DefElseHash
X-DefHash
X-Dispatcher-Server
X-Branch-Name
X-Rebelmouse-Surrogate-Control
Is-Eu
Cf-Bgj
NM-Fastcgi-Cache
CDCHOST
X-DPWN-IS-SECURE
X-Esi-Check
X-Variation
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Origin
X-Old-Content-Length
X-Gzip
X-Li-Fabric
X-Li-Pop
X-LI-UUID
Adler-Geo
Platform
X-Varnish-Beresp-Status
Origin
L5d-Success-Class
IsBot
X-User
X-Hash
X-Servername
Web-Mar-Node
X-SIPLIST1
X-Slack-Backend
HA-Ipaddr
X-Varnish-Beresp-Ttl
X-WADP-Cache
Fastly-SWR
Fastly-SIE
Ha-Gx-Prefs
Fastly-Drupal-HTML
X-ID
CDN-EdgeStorageId
CDN-CachedAt
CDN-Cache
CDN-PullZone
X-Envoy-Decorator-Operation
CDN-RequestId
CDN-RequestCountryCode
CDN-Uid
X-Request-URI
X-Cache-Debug
X-EC-Lua
V-Age
X-Core-Mission
Sid
X-LB-ID
X-Aicache-OS
True-Client-Country-4JS
X-NCache
X-Request-Start
Vix-Hermes-Req-Id
X-Mvc-Supplant-OutputCached
X-VG-TLSProxy
X-PF-Uncompressing
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Handled
Apple-News-Services-Request-Url
X-CACHE-KEY
X-Cache-Remote
X-Refresh
X-NC
X-Via-Popn
Url
Esi-Enabled
X-CACHE-GROUP
X-Varnish-Url
X-Via-Poph
X-Via-Popv
X-Response-By
X-Varnish-Cacheable
S-Rt
X-Nc
Who
X-Host-Name
Xkeyi7
X-Proxy-Cachei7
Country-Code
Pics-Label
X-FireWall-Protection
X-B3-Spanid
N-Cache
X-Unique-ID
X-Epic-Correlation-Id
X-Tb-Optimization-Total-Bytes-Saved
Req-Svc-Chain
X-BBXSRF
X-TraceId
Content-Secure-Policy
X-Error
Server-Ttl
Source
Cross-Origin-Window-Policy
Ohc-File-Size
X-Planisys-CDN-Cache
X-Cache-2
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Webkit-Csp
X-Srv
X-Cache-ASPX
D-Cc-Upstream
X-HS-Status
GeoIp-Country-Code
X-Contensis-Viewer-Groups
X-Varnish-Authentication
X-Sucuri-Cache
X-Cc-Req-Id
X-Cc-Via
Geoip-Latitude
X-Webkit-CSP-Report-Only
Kp-EeAlive
X-LiteSpeed-Cache-Control
X-Svr
X-DC
Geo-Info
Cteonnt-Length
X-CLOUD-TRACE-CONTEXT
Cmstype
CACHE
Cmsid
HitType
X-RateLimit-Limit
X-CDN-Forward
X-Served-From
X-Wa
X-Servedbyhost
MIME-Version
X-Server-IP
X-URL
X-Cs
X-HostName
Cache-Key
X-FPC
X-Gdpr
A
X-Cache-Config
X-API-Version
X-Vcl-Version
X-Origin-Time
X-Nyt-Route
Svr
Filterid
X-RAMCache
M-TraceId
VivaBuild
Viewtype
Resin-Trace
X-Li-Proto
X-VC
X-SN
Server-Id
X-Esi
Ohc-Cache-HIT
Hostname
X-NodeID
Server-ID
Arc-Country
X-LI-Proto
X-Air-Source
Cross-Origin-Opener-Policy
TDXMobile
X-SB
X-Vgn-Hpd-Reason
X-Webstats-RespID
NtCoent-Length
X-HOST
X-NGINX-Cache
Request-ID
Tcn
X-Internal-Host
X-VCL-Version
X-SD-PageType
NGB
SID
X-Check-Cacheable
X-UA
XServer
X-ServedByHost
X-DI
X-DB
X-DSS
X-TIM-N
Cache-Provider
X-DW
X-RSL
X-Viewer-Country
X-RPS
X-Render-Time
Srv
X-RPM
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-WA
Mime-Version
X-Vc
X-Newrelic-Synthetics
X-TIME
X-Ua
EpKe-Alive
X-Service
GeoIP-Country-Code
GeoIP-Latitude
X-BBC-Edge-Cache-Status
X-App
X-Auto-Login
X-SaId
X-CF-Powered-By
Processtime
X-NGENIX-Cache
X-JoinUs
DataCenter
X-Worker
X-Action
Upgrade-Insecure-Requests
X-PHP-Backend
ProcessTime
X-Geo
X-FTR-Cache-Host
X-Extlb
X-Edge-Location
X-Oss-Cdn-Auth
FSS-Cache
X-Via-NSCOPI
X-Forwarded-Site
X-Fpc
X-Dynatrace-Js-Agent
X-Ftr-Cache-Host
X-Provided-By
X-Cdn-Request-ID
X-CSRF-TOKEN
Proxy-Connection
Datacenter
X-FORWARDED-FOR
X-Cluster-Node
CDN
W
CF-Cached-On
X-HITS
X-Swift-Error
We-Hiring
X-BBC-Origin-Response-Status
X-MSEdge-Flight
LB
Mail-Subject
Memcached
Surrogated-Key
X-Accel-Expires-Debug
X-Bc-Bl
X-PJAX-URL
X-MSEdge-Features
X-Depends-On
X-Date
X-Proxy-Upstream
Cdn
X-BACKEND-TTL
X-Fastly-Backend-Reqs
X-Region-Sid
X-Dw-Trace-Id
X-Parent-Response-Time
X-Req
X-VC-Cache
X-Client-Ip
X-Zone
X-CACHE-AGE
X-Rocket-Build-Number
PICS-Label
X-Sigma
X-Cache-Tag
X-Sigma-Backend
X-IN-APIGATEWAY
OT-Force-Account-Verify
X-APP
X-IN-APIGATEWAYSSL
X-Pad
X-Fastly-Request-Id
Env
X-ABtesting
X-Hello
X-Flog
Dnion-Transfer-Encoding
X-Akamai-Pragma-Client-IP
X-UnsetCookies
X-Presslabs-Stats
X-Oracle-DMS-ECID
Media-Length
X-RateLimit-Remaining-Second
X-Men
X-Via-PopV
X-RateLimit-Limit-Second
X-ND-Cache
Vha6-Origin
X-Acquia-Application-Trace
X-Via-PopN
X-Acquia-Purge-Tags
X-Acquia-Site
X-Air-Trace-Id
X-Pf-Uncompressing
X-Via-PopH
X-Acquia-Application-UUID
Time
Epwk-X-Cache
Memory
X-LiteSpeed-Tag
X-Lb-Id
X-MiniProfiler-Ids
CPC-Age
CPC-Cache
WZWS-RAY
VNS-Cache
X-ZONE
VNS-Age
Cf-Ipcountry
X-Varnish-URL
X-Vcache
X-Request-Url
X-ElasticPress-Query
X-Request-URL
X-Akamai-ERRuleID
X-Akamai-ERPolicy
URI
X-Csrf-Token
X-Snapshot-Date
X-Varnish-Beresp-TTL
X-Ms-Meta-Originalurl
X-Ms-Meta-Staticbatchstarttime
X-ElasticPress-Search
Xet-Cookie
CountryCode
X-Debug-Cache-Store
X-Amz-Meta-Cb-Modifiedtime
X-Debug-Cache-Fetch
X-B3-Parentspanid
X-Traceid
X-Litespeed-Cache-Control
Phost
X-C
X-Tid
Inserted-Into-Cache-At
Ohc-Response-Time
Environment
X-Redis-Duration-Ms
X-Storefront-Renderer-Verified
X-ServerName
NnCoection
X-Redis-Count