Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
X-XSS-Protection
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-UA-Compatible
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Request-Id
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Runtime
X-AspNet-Version
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Xss-Protection
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
X-Ua-Compatible
X-Request-ID
Content-Encoding
X-CDN
Feature-Policy
X-AspNetMvc-Version
Status
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Upgrade
Access-Control-Max-Age
X-Via
Keep-Alive
X-Ws-Request-Id
X-Age
X-Robots-Tag
X-AH-Environment
X-Turbo-Charged-By
EagleId
Request-Context
X-Cache-Group
X-Proxy-Cache
Server-Timing
X-Server
X-Backend
X-Hacker
Host-Header
X-Server-Powered-By
Report-To
X-Amz-Request-Id
X-Nginx-Cache-Status
X-Amz-Id-2
Grace
X-UA-Device
X-Dns-Prefetch-Control
X-Rq
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Page-Speed
X-LiteSpeed-Cache
Cf-Railgun
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-Amz-Version-Id
X-OneAgent-JS-Injection
X-CST
X-Cache-Spec
NEL
X-WebKit-CSP
X-Vhost
Allow
X-Host
X-Backend-Server
X-Server-Id
Xkey
X-ASPNET-VERSION
EagleEye-TraceId
X-Dispatcher
Surrogate-Control
X-Node
Request-Id
X-Response-Time
Content-Location
X-Akam-SW-Version
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
P3p
X-Cache-Lookup
X-Application-Context
Accept-Ch-Lifetime
X-Ac
X-Country
X-Ruxit-JS-Agent
Accept-CH
Accept-Ch
X-Mod-Pagespeed
X-Template
X-Readtime
X-Language
X-Cloud-Trace-Context
X-B3-TraceId
MS-Author-Via
Rating
X-Url
X-HW
X-Cnection
Accept-CH-Lifetime
X-MS-InvokeApp
X-Origin-Cache
X-PC
X-TtlSet
X-Vname
Edge-Control
X-Clacks-Overhead
X-GitHub-Request-Id
X-ESI
X-Trace
X-Content-Type
Display
Pagespeed
X-Middleton-Display
X-Sol
X-Middleton-Response
Response
X-D2id
X-ORACLE-DMS-RID
Verso
Arr-Disable-Session-Affinity
X-Oneagent-Js-Injection
X-ORACLE-DMS-ECID
X-Cdn-Fetch
X-Kinja-Revision
X-Kinja-Build
X-Exp-Variant
X-Kinja-Server
X-Use-Magma
X-Exp-Id
X-Kinja
X-GoogleNews-Bot
X-Varnish-TTL
X-Vcap-Request-Id
X-Goog-Hash
X-Country-Code
X-Rack-Cache
X-Powered-By-Plesk
X-Navigation-Version
X-VARITI-CCR
Service-Worker-Allowed
X-Server-Name
X-Amz-Rid
X-Fastly-Request-ID
X-Abt-Application-Version
X-Client-IP
Fastly-Restarts
X-Buckets
X-TTL
X-Cache-TTL
X-Cached
X-MSEdge-Ref
X-Release
X-Element-Page-Cache
X-Dw-Request-Base-Id
X-NF-Request-ID
SPRequestGuid
X-SharePointHealthScore
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
Public-Key-Pins
SPIisLatency
SPRequestDuration
Access-Control-Request-Method
RTSS
X-Pinterest-Rid
Pinterest-Generated-By
X-Webkit-CSP
Pinterest-Version
Cache-Tag
X-FastCGI-Cache
AR-ATIME
AR-CACHE
X-Edge
Ar-Sid
AR-PoweredBy
AR-Request-ID
X-Ezoic-Cdn
X-Powered-CMS
X-LLID
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Upstream
X-Litespeed-Cache
Content-MD5
X-Version
X-Ruxit-Js-Agent
X-HP-Webp
S
X-Jurisdiction
X-Fastcgi-Cache
X-Recruiting
X-Origin-Upstream-Status
X-Ttl
X-ECACHE
Charset
X-Mid
X-MCACHE
X-DynaTrace
X-Mg-S
X-Kinsta-Cache
Fusion-Content-Id
Fusion-Content-Source
Fusion-Deployment-Id
Fusion-Source
Fusion-Component-Id
Fusion-Template-Id
X-PressLabs-Stats
X-Content-Digest
X-Px
X-T
Cache-Tags
Fastcgi-Cache
X-Id
X-Accel-Expires
X-Logged-In
X-Forwarded-Proto
X-Content-Security-Policy-Report-Only
Filters
Server-Node
X-Amz-Server-Side-Encryption
Edge-Cache-Tag
TP-L2-Cache
TP-Cache
MicrosoftSharePointTeamServices
Front-End-Https
Server-Name
X-Correlation-Id
TCN
X-Forwarded-For
X-Grace
Nginx-Cache
Nel
X-Request-Processing-Time
X-Request-Received
X-Kong-Upstream-Latency
X-Hits
X-Kong-Proxy-Latency
X-Amzn-Trace-Id
X-Shield-Request-Id
X-Debug
X-B3-Sampled
X-Request-Handler-Origin-Region
X-Microsite
X-XRDS-LOCATION
X-Varnish-Age
X-Activity-Id
X-Az
X-AppVersion
Alternate-Protocol
X-F-Cache
X-HS-Content-Id
X-Amz-Replication-Status
X-HS-Combine-CSS
X-HS-Hub-Id
X-HS-Cache-Config
X-Yandex-Sdch-Disable
Surrogate-Key
X-Origin-Server
X-Goog-Metageneration
X-Goog-Generation
X-GUploader-UploadID
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-XRDS-Location
X-Ser
X-DIS-Request-ID
Accept-Charset
X-Rid
X-Frontend
X-NWS-LOG-UUID
X-Cache-Age
X-Geo-Country
Host
X-Hostname
Section-Io-Cache
X-Git-Hash
X-Time
X-Respond-Thread
X-DataDome
Access-Control-Allow-Method
X-VCache
X-Upgrade-Enabled
X-Mobile-URL
X-Daa-Tunnel
X-RateLimit-Remaining
X-LB-Cache
MS-CV
ServerID
X-Type
Paypal-Debug-Id
X-Source
X-Seen-By
Cleartype
X-Content-Options
X-IPLB-Instance
X-AOL-HN
X-Varnish-Backend
X-TT
Cache
X-Cache-Action
X-App-Environment
Healthy
Payment
X-Whom
X-Route-Name
X-B-Cache
X-Aspnet-Duration-Ms
X-Flags
X-Request-Guid
X-Providence-Cookie
X-Signature
X-Server-ID
X-Is-Crawler
X-Page-Id
X-Debug-Info
X-WebKit-CSP-Report-Only
X-Load-Cache
X-N
Realpath
X-Cache-Key
X-Jobs
X-Contextid
X-Pinterest-Direct
Fastcgi-Useragent
X-FB-Debug
X-FTR-Request-ID
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Mobile
X-Erf-Bev-Bev
Node
X-Webkit-Csp
X-Rule
Refresh
X-Cache-Expired-At
Powered-By-ChinaCache
X-Response-Served-From
X-Original-Request-Id
X-Accel-Buffering
Ms-Operation-Id
X-RTag
Version
DC
X-Framework
X-Zen-Fury
X-Content-Powered-By
X-Drupal-Cache-Tags
X-Cacheable-TTL
Viewport
X-Wix-Request-Id
X-HTML-Minification-Powered-By
X-ProcessESI
Referer-Policy
X-Instance
X-RemovedCookies
Access-Control-Request-Headers
X-Cluster-Name
X-Cache-Control
X-B
X-Real-IP
X-Proxy
VIX-Pulpo-Node
X-Distributor
X-Cache-Time
VIX-Pulpo-Upstream-Status
Eomportal-Instance
X-Region
X-UUID
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-FireWall-Port
X-Page-View
X-IPS-LoggedIn
X-Drupal-Cache-Contexts
X-Via-JSL
X-Cached-By
Countrycode
X-FW-Serve
X-Cache-Operation
X-Cache-Rule
X-FW-Hash
X-FW-Dynamic
X-FW-Server
X-FW-Type
X-FW-Static
X-Akamai-Edgescape
Liferay-Portal
X-Tec-Api-Version
X-Tec-Api-Root
X-G
X-Tec-Api-Origin
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-Tumblr-User
X-Cache-Hit
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-App-Server
X-Environment-Context
X-L-Path
X-Nginx-Cache
Xserver
X-Pass-Why
X-Www-Served-By
X-Debug-IsPreview
X-Debug-IsConnected
SRV
X-Protected-By
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
Section-Origin-Responded
Server-Info
Section-Io-Origin-Time-Seconds
Section-Io-Id
Section-Io-Origin-Status
DynaTrace
CF-IPCountry
X-Device-Type
X-User-Agent
X-Varnish-Grace
From-Origin
Webserver
X-Tumblr-Pixel-2
X-Adobe-Loc
Ec-Rule-Version
X-Mode
X-Adobe-Content
Retry-After
X-UPSTREAM-Address
AMP-Access-Control-Allow-Source-Origin
X-RN-RSRV
Meta-Geo
X-Handled-By
X-Hl-Ver
X-Endurance-Cache-Level
X-ES-SERVER
X-Varnish-Server
Frame-Options
Cache-Tv-Group
Cache-Status
X-Backend-Name
X-Uri
X-MP-GENERATED-AT
X-Format
X-OCL
X-Origin-Hint
Decoy-Debug-TTL
Fastly-SSL
Webcakes-Region
X-PCL
X-Labrador-Cache-Channel
Decoy-Debug-Status
X-Section
X-Soup
X-Storage
Apigw-Requestid
X-Pubstack
X-FB-TRIP-ID
Decoy-Debug-Key
Country
X-PHP-Host
X-Varnishpool
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Locale-Group
X-Cache-Server
TWC-Connection-Speed
Property-Id
Webcakes-App-Version
TWC-Privacy
TWC-Device-Class
X-Access
Webcakes-App-Name
X-Be
X-Redis-Cache
X-Timing-Wait
X-UA-Device-Type
X-ApacheServer
X-Server-W
X-Request-Time
X-AWS-Id
X-R9-Blue-Green-Version
X-PERF
X-LAGOON
X-Via-Fastly
Mn-Server-Ip
X-Human
X-VWS-Id
X-LJ-Flow-ID
Selected-Fe
X-BYPASS-REASON
X-Proxy-Build
X-WA-Info
X-NYM-Debug-Backend
X-No-Session
X-ProxyCache-Status
X-ProxyCache-Key
Protected
X-SayCDN-TTL
X-Say-Cacheable
X-Sql-Count
X-Sql-Duration-Ms
Azure-Version
Cache-Name
X-Status
X-S-Maxage
X-Varnish-Ttl
X-Cache-TTL-Remaining
X-Web-Node
X-Origin-Date
X-Proto
X-Proxied
X-Routing-Service
GEO-INFO
Azure-SlotName
X-Say-TTL
Azure-SiteName
X-Zipkin-Id
X-Ratelimit-Limit
X-Xfnlog-Site
Azure-InstanceId
Azure-RegionName
X-ShardId
X-TNCMS
X-Hosted-By
X-Hyper-Cache
X-Alternate-Cache-Key
X-Locale
X-Info
X-ShopId
X-Sorting-Hat-ShopId
X-Shopify-Stage
X-Storefront-Renderer-Rendered
X-Loop
X-Sorting-Hat-PodId
X-Site-Version
X-AIR-PT
X-GG-Cache-Date
X-FW-Version
X-TA-CDN-Provider
Uber-Trace-Id
X-Rendered-As
X-Dc
X-Is-Bot
X-Proxy-Cache-Status
X-TT-LOGID
X-Cluster
X-Cache-Enabled
S-Cnection
X-Content-Age
X-Microcachable
X-Node-Name
X-Cache-Grace
X-Forwarded-Host
X-App-Version
X-Qloud-Router
X-Revision
X-NWS-UUID-VERIFY
X-CCM
X-Azure-Ref
X-Platform
X-Backend-Host
X-Via-CDN
X-CSRF-Token
X-SRV
Cache-Hits
Akamai-GRN
X-Trace-Id
X-EdgeConnect-Cache-Status
X-Cache-Host
ServedBy
X-ATG-Version
X-Aspnetmvc-Version
X-Ratelimit-Remaining
X-Detected-As
X-Cache-NGX
X-CACHE-KEY
X-Cache-PHP
X-Varnish-Hostname
X-RCS-CacheZone
X-B3-SpanId
X-Amz-Apigw-Id
X-Amzn-Remapped-Content-Length
X-Amzn-RequestId
X-Debug-Cache
X-CS
X-Country-Code-Real
X-FTR-Backend
X-FTR-Realm
X-FTR-Cache-Status
HostName
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-DC
X-Amz-Meta-S3cmd-Attrs
X-TX-ID
DB-Nickname
X-Nc
SD-X-WS
Amp-Access-Control-Allow-Source-Origin
X-Oss-Storage-Class
X-Oss-Server-Time
X-Unique-ID
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Oss-Request-Id
X-Akamai-Transformed
X-Time-Microsecs
X-BCube-Filmed-By
X-Adobe-Source
X-DynaTrace-JS-Agent
X-Ms-Request-Id
X-Correlation-ID
X-Ms-Version
Backend
X-ServerID
X-Backend-TTL
Who
Machine
MD5-Digest
X-Origin-TTL
X-External-Request-Id
DCR-Decision-By
Fastcgi-X-Cache-Version
X-Owner
X-Location
X-PBS-Appsvrname
DCR-Processing-Time-Ms
X-PAYTM-SRV-ID
X-From
Expiry
BehaviorPad-Version
Rendered-Blocks
X-Level-Front-Cache
Country-Code
X-Connection-Hash
X-S
T-Server
X-D
X-Generation-Time
X-Generated-On
Mobile-Detection-Method
X-Origin-CC
X-NAPM-TraceId
X-Destination
Odigeo-Trace-Id
Meta-Geo-Continent
X-Processor
X-A-Wwc
X-A-Dgt
X-Cdn-Forward
X-CF-Lambda-Fn
X-Vtex-Processado-Em
X-A-Dcw
X-Air-Hostname
X-A-Dam
X-Vdms-Version
X-VG-WebCache
Tracecode
X-VG-WebServer
X-CF-Lambda-Version
X-Cache-NE
X-ScT
X-Session-Fingerprint
X-Rewrite-Enabled
X-S-Cookie
X-Rojux
X-B-Cookie
X-Request-UUID
X-Aed
X-Application
X-ARC
X-SRCache-Key
X-Vdms-Path
X-Vtex-Remote-Cache
X-A-Ccd
X-A
X-Trv-Group
X-RateLimit-Limit
X-Varnish-Beresp-Grace
X-FTR-Expires
AKAMAI
X-Cache-Bucket
X-Geo-Header
X-Magnolia-Registration
X-GeoIP-City
Xc-Version
X-HS-Content-Campaign-Id
X-Cache-Info
Release
Pagetype
On-Server
X-Developers
X-Generated-In
X-Policy
V-Age
Magicmarker
X-Device-Os
CacheControlHeader
X-OVcl
Host-ID
X-OVcl-Cache
Cache-Host
Content-Disposition
X-Tb
X-Core-Value
Wxu-Next-Region
Thinkindot-CacheControl-Type
Wxu-Next-Hostname
X-Thinkindot-L3
X-Fetched-On
Wxu-Next-Commit
X-Tumblr-Pixel-3
X-Micro-Cache
Gh-Request-Id
X-TrackingId
X-Bip
X-Varnish-Cache-Hits
X-Mvc-Supplant-Cachable
Thinkindot-CacheControl
X-Cms-Context
X-Fastly-Cache
UCS
X-Reqid
Server-Host
Fastly-Backend-Name
X-Thanos
X-Irp-Debug
Thinkindot-Control
X-Sucuri-ID
Filterid
X-Varnish-Beresp-Ttl
User-Cache-Control
X-NewRelic-App-Data
X-Backend-State
X-Block-Status
Location
Locid
L5d-Success-Class
X-Eu-Site
HA-Ipaddr
X-Dispatcher-Server
X-Envoy-Decorator-Operation
X-Esi-Check
PB-RID
Sever-Int
Ha-Gx-Prefs
Server-Hostname
Server-Ext
X-Clara-WADP
Vix-Hermes-Req-Id
Ssr
X-CGP
Web-Mar-Node
True-Client-Country-4JS
X-Cache-Id
NM-Fastcgi-Cache
X-Branch-Name
NGX
X-Developer
Path
PB-PID
X-Csrf-Jwt
X-Cache-Debug
PFcat
X-Azure-Ref-OriginShield
X-Old-Content-Length
X-JWT-State
X-Is-Gdpr
X-SVT-ORM-VERSION
X-Swa-Ws
X-Request-Host
X-IP
X-Hnp-Log
X-Gzip
X-VarnishDD-TTL
X-Has-Esi
X-SVT-ORM-RULES
X-HN
X-Wikidot-Static-Cache
X-B3-Traceid
X-User
Geo-Info
X-Var-Ttl
X-Ratelimit-Reset
X-VG-TLSProxy
X-Origin-Response-Time
X-Origin
X-Method
X-Nginx-Cache-Key
X-Wikidot-Backend
X-WADP-Cache
X-Skip-Cache
X-Request-URI
Cf-Bgj
Cf-Device-Type
CDN-Uid
X-Varnish-Beresp-Status
CDN-RequestCountryCode
X-Generated-By
X-Gen-Mode
Esi-Enabled
X-FC-Vary-Parameters
X-Fmm-Version
DSUID
X-Scheme
CDN-PullZone
CDN-RequestId
CDN-EdgeStorageId
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Handled
X-GeoIP
Apple-News-Services-Request-Url
CDCHOST
CDN-CachedAt
C-Via
Arc-Version
CDN-Cache
X-VServer
X-Slack-Backend
X-SIPLIST1
X-Cache-Tags
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Li-Fabric
X-Hash
X-LB-ID
X-Fastly-Backend
X-Clientip
X-DefElseHash
X-DefHash
X-DPWN-IS-SECURE
X-Gamma-Serve
X-GoCache-CacheStatus
X-Li-Pop
X-LI-UUID
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Varnish-Hits
X-Variation
X-Platform-Server
X-Node-Id
X-NU-AKA-ACS-Version
X-Origin-Expires
X-Varnish-Remaining-TTL
X-Cache-Var-Map
L
Origin
Platform
Is-Eu
Fastly-SWR
X-Cache-Var
Adler-Geo
Fastly-SIE
X-Aicache-OS
IsBot
X-ID
X-EC-Lua
X-Unique-Id
Instruction
Rt-Fastcgi-Cache
X-Loc
Fastly-Drupal-HTML
X-Mvc-Supplant-OutputCached
X-Goog-Meta-Goog-Reserved-File-Mtime
SR-User-Adfree
X-GEO
X-Varnish-Url
X-CLOUD-TRACE-CONTEXT
Pics-Label
X-CUA
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Epic-Correlation-Id
X-Via-Poph
X-PF-Uncompressing
X-Planisys-CDN-TTL
X-Via-Popn
X-Via-Popv
X-APP-VERSION
Lfy
X-Refresh
Url
NGB
X-Matched-Rule
Sid
X-Cache-Backend
Req-Svc-Chain
CloudFront-Viewer-Country
Cmsid
X-Cache-Expires
Cmstype
X-Served-From
X-NCache
X-Servername
X-Sn-Servicetimems
Svr
Pramga
X-Cdn-Origin
Kp-EeAlive
X-TraceId
X-Cache-Date
MIME-Version
A
Viewtype
VivaBuild
X-Srv
X-Tb-Optimization-Total-Bytes-Saved
X-Core-Mission
Tcn
X-Vgn-Hpd-Reason
Cache-Key
M-TraceId
Source
Server-ID
Arc-Country
X-Request-Start
DataCenter
X-SaId
X-NGENIX-Cache
X-FireWall-Protection
X-JoinUs
X-Error
X-PHP-Backend
TDXMobile
Cross-Origin-Opener-Policy
X-Webkit-CSP-Report-Only
X-Edge-Location
X-Geo
X-Varnish-Cacheable
X-Instrumentation
X-Kraken-Loop-Name
X-Kraken-Routeconfig-Destination
X-Server-Lifecycle-Phase
X-Edge-Location-Klb
Geoip-Latitude
X-DC
X-Vc
X-Vcl-Version
GeoIp-Country-Code
X-NC
SID
NtCoent-Length
X-Service
X-HS-Status
X-Servedbyhost
Content-Secure-Policy
X-Air-Source
X-Response-By
X-Extlb
X-Proxy-Cachei7
Xkeyi7
X-Wa
X-Internal-Host
X-B3-Spanid
Server-Ttl
X-Esi
X-Bc-Bl
X-LiteSpeed-Cache-Control
N-Cache
X-BBXSRF
HitType
Resin-Trace
X-Li-Proto
FSS-Cache
X-Forwarded-Site
CACHE
X-CDN-Forward
X-Via-NSCOPI
X-Cache-2
X-Viewer-Country
S-Rt
X-LI-Proto
X-HOST
X-Cache-Remote
Surrogated-Key
We-Hiring
X-Accel-Expires-Debug
Memcached
X-Date
LB
Mail-Subject
X-Cache-ASPX
X-RAMCache
Request-ID
X-WA
X-Proxy-Upstream
X-PJAX-URL
X-Cc-Req-Id
X-Cc-Via
X-Contensis-Viewer-Groups
X-Varnish-Authentication
D-Cc-Upstream
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-Req
X-Svr
Cteonnt-Length
X-UA
X-Erf-Stays-Bingo-Pdp-Web
X-RSL
X-RPM
X-VC-Cache
Upgrade-Insecure-Requests
X-RPS
Env
X-DW
X-DB
X-RateLimit-Limit-Second
X-DI
X-Newrelic-Synthetics
X-DSS
X-VCL-Version
X-APP
X-RateLimit-Remaining-Second
X-ServedByHost
X-TIM-N
Hostname
X-Sucuri-Cache
Ohc-File-Size
Cross-Origin-Window-Policy
GeoIP-Latitude
X-Men
X-Rocket-Build-Number
X-Cs
X-Server-IP
GeoIP-Country-Code
X-Sigma-Backend
X-Sigma
XServer
X-Host-Name
ProcessTime
X-Nyt-Route
Time
X-API-Version
X-FPC
X-Gdpr
X-Action
X-ZONE
X-Cache-Config
CF-Cached-On
Memory
X-Origin-Time
X-App
X-Air-Trace-Id
X-Zone
X-HostName
X-Region-Sid
X-SN
Cache-Provider
VNS-Age
X-MSEdge-Features
X-VC
CPC-Cache
X-Oss-Cdn-Auth
CPC-Age
X-CF-Powered-By
X-Check-Cacheable
X-Fpc
VNS-Cache
X-NodeID
Server-Id
X-MSEdge-Flight
X-Swift-Error
Ohc-Cache-HIT
X-Dynatrace-Js-Agent
X-Provided-By
X-Webstats-RespID
X-FORWARDED-FOR
X-Depends-On
X-SB
W
X-SD-PageType
Mime-Version
Srv
X-Cdn-Request-ID
X-ServerName
CDN
X-UnsetCookies
Cdn
X-BACKEND-TTL
Fastcgi-Cache-TTL
My-App
X-BBC-Edge-Cache-Status
State
X-Ftr-Cache-Host
X-CSRF-TOKEN
X-TIME
X-Client-Ip
X-Akamai-Pragma-Client-IP
X-ABtesting
EpKe-Alive
X-Fastly-Backend-Reqs
X-Minions-Version
X-Dw-Trace-Id
X-Flog
Dnion-Transfer-Encoding
X-Fastly-Request-Id
X-Render-Time
X-Mg-Request-UUID
X-Parent-Response-Time
X-Hello
X-Pad
Media-Length
X-Oracle-DMS-ECID
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
X-Acquia-Site
Vha6-Origin
X-Acquia-Application-Trace
Cf-Ipcountry
X-Presslabs-Stats
X-Cache-Tag
X-NGINX-Cache
X-Pf-Uncompressing
Proxy-Connection
X-Via-PopN
X-LiteSpeed-Tag
X-Via-PopV
Processtime
X-Cache-Type
X-Worker
X-Via-PopH
X-Snapshot-Date
PICS-Label
X-BBC-Origin-Response-Status
X-ElasticPress-Search
X-Auto-Login
OT-Force-Account-Verify
Epwk-X-Cache
X-FTR-Cache-Host
X-Ms-Meta-Originalurl
X-Shop-Environment
X-Tenant
X-Orig-Expires
Warning
X-Varnish-URL
X-ND-Cache
X-Akamai-ERPolicy
X-Forwarded-Path
X-Vcache
X-Akamai-ERRuleID
X-Varnish-Beresp-TTL
X-MiniProfiler-Ids
X-ElasticPress-Query
X-Traceid
X-Request-URL
X-Ms-Meta-Staticbatchstarttime
Xet-Cookie
X-Lb-Id
X-Cluster-Node
X-Ua
CountryCode
X-Air-Pt
X-Apw-Hits
X-Apw-Access-Token
X-Apw-Access-Action
X-Apw-Access-Object
X-Mg-Request-Id
X-B3-Parentspanid
X-Ftr-Request-Id
NnCoection
Phost
Ohc-Response-Time
X-Cache-Status-Check
X-Litespeed-Cache-Control
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
Inserted-Into-Cache-At
X-Storefront-Renderer-Verified
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Tid
X-Amz-Meta-Cb-Modifiedtime
Content-Style-Type
X-Redis-Duration-Ms
Content-Script-Type
X-Redis-Count
Datacenter
Environment
URI