Threat Level: green Handler on Duty: Russ McRee

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Cf-Request-Id
CF-RAY
CF-Cache-Status
Last-Modified
X-XSS-Protection
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Xss-Protection
X-Request-ID
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Content-Security-Policy
Content-Encoding
X-CDN
X-Ua-Compatible
X-Envoy-Upstream-Service-Time
Status
Feature-Policy
X-AspNetMvc-Version
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Access-Control-Max-Age
X-Via
Upgrade
Keep-Alive
X-Ws-Request-Id
X-Age
X-Turbo-Charged-By
X-AH-Environment
X-Robots-Tag
Request-Context
X-Proxy-Cache
EagleId
X-Cache-Group
Server-Timing
X-Backend
X-Hacker
Report-To
X-Amz-Request-Id
X-Server
Host-Header
X-Amz-Id-2
X-Server-Powered-By
Grace
X-Nginx-Cache-Status
X-UA-Device
X-LiteSpeed-Cache
X-Varnish-Cache
X-Rq
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
X-Page-Speed
Cf-Railgun
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
NEL
X-Amz-Version-Id
X-OneAgent-JS-Injection
X-Cache-Spec
Xkey
X-WebKit-CSP
Allow
X-Backend-Server
X-Host
X-Vhost
X-Device
X-CST
EagleEye-TraceId
X-Server-Id
Surrogate-Control
Request-Id
X-Dispatcher
X-Node
Accept-CH
Content-Location
X-Response-Time
X-Akam-SW-Version
X-Ruxit-JS-Agent
Accept-CH-Lifetime
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
P3p
X-ASPNET-VERSION
X-Ac
X-Template
X-Language
X-Application-Context
X-Country
X-Cache-Lookup
X-Readtime
X-Cloud-Trace-Context
X-Mod-Pagespeed
MS-Author-Via
X-B3-TraceId
X-Origin-Cache
Rating
X-Cnection
X-MS-InvokeApp
X-Kinja-Server-Push
X-Url
X-HW
Accept-Ch
X-Vname
X-TtlSet
X-PC
X-ORACLE-DMS-ECID
X-Clacks-Overhead
X-GitHub-Request-Id
Edge-Control
X-ESI
Accept-Ch-Lifetime
X-FastCGI-Cache
X-Trace
Response
Pagespeed
X-Middleton-Display
Display
X-Middleton-Response
X-Sol
X-Content-Type
X-Vcap-Request-Id
X-D2id
X-Exp-Id
X-Use-Magma
X-Kinja-Build
X-Kinja
Arr-Disable-Session-Affinity
X-Exp-Variant
X-GoogleNews-Bot
X-Kinja-Server
X-Cdn-Fetch
X-Kinja-Revision
Verso
X-Goog-Hash
X-Buckets
X-Rack-Cache
X-Server-Name
X-Country-Code
Service-Worker-Allowed
X-Oneagent-Js-Injection
X-Navigation-Version
X-ORACLE-DMS-RID
X-VARITI-CCR
X-Varnish-TTL
X-Abt-Application-Version
X-Amz-Rid
X-Powered-By-Plesk
Pinterest-Generated-By
X-Webkit-CSP
Pinterest-Version
X-Pinterest-Rid
X-Client-IP
X-Cache-TTL
X-Fastly-Request-ID
SPRequestGuid
X-SharePointHealthScore
X-Release
X-MSEdge-Ref
SPRequestDuration
SPIisLatency
X-Dw-Request-Base-Id
X-Element-Page-Cache
Fastly-Restarts
X-Cached
X-NF-Request-ID
Public-Key-Pins
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-TTL
RTSS
AR-PoweredBy
AR-ATIME
AR-Request-ID
AR-CACHE
Ar-Sid
X-Edge
X-Origin-Upstream-Status
Access-Control-Request-Method
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-LLID
X-Px
X-Ttl
X-Powered-CMS
Fusion-Component-Id
Fusion-Content-Id
Fusion-Content-Source
Fusion-Source
Fusion-Template-Id
Fusion-Deployment-Id
X-Ezoic-Cdn
X-Upstream
Content-MD5
X-Jurisdiction
X-HP-Webp
X-Mid
Cache-Tag
X-MCACHE
X-ECACHE
X-Amz-Server-Side-Encryption
X-Recruiting
S
X-Content-Digest
X-Mg-S
Charset
X-Pinterest-Direct
X-Version
X-PressLabs-Stats
TCN
MicrosoftSharePointTeamServices
Fastcgi-Cache
X-Debug
Front-End-Https
X-T
X-Content-Security-Policy-Report-Only
X-Kinsta-Cache
Filters
X-Grace
X-Id
Cache-Tags
Edge-Cache-Tag
Server-Node
X-Accel-Expires
X-Forwarded-Proto
X-Logged-In
X-Amzn-Trace-Id
X-Forwarded-For
X-Yandex-Sdch-Disable
X-Correlation-Id
Nginx-Cache
Server-Name
Surrogate-Key
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-DynaTrace
X-Varnish-Age
X-XRDS-Location
TP-L2-Cache
TP-Cache
X-B3-Sampled
X-Request-Processing-Time
X-Request-Received
X-Request-Handler-Origin-Region
X-Ser
X-Microsite
X-Server-ID
X-DIS-Request-ID
X-Hits
X-Cache-Key
X-Shield-Request-Id
X-AppVersion
Powered-By-ChinaCache
X-Activity-Id
X-Az
X-Amz-Replication-Status
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Combine-CSS
X-Goog-Metageneration
X-F-Cache
X-Goog-Generation
X-Goog-Storage-Class
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Litespeed-Cache
X-Origin-Server
Accept-Charset
X-Git-Hash
X-FTR-Request-ID
X-Respond-Thread
X-Geo-Country
X-XRDS-LOCATION
X-LB-Cache
X-Hostname
X-Upgrade-Enabled
X-DataDome
Section-Io-Cache
X-Rid
Cache
X-Frontend
Alternate-Protocol
X-Ruxit-Js-Agent
Access-Control-Allow-Method
X-Cache-Age
Host
X-Aspnetmvc-Version
X-Mobile-URL
Cleartype
Paypal-Debug-Id
MS-CV
X-IPLB-Instance
Healthy
X-Varnish-Backend
X-AOL-HN
X-Type
X-Seen-By
X-Content-Options
ServerID
X-Whom
X-App-Environment
X-VCache
Payment
X-Route-Name
X-TT
X-Providence-Cookie
X-Is-Crawler
X-Cache-Action
X-Flags
X-Aspnet-Duration-Ms
X-Request-Guid
X-WebKit-CSP-Report-Only
X-Page-Id
X-Jobs
X-B-Cache
X-Signature
X-Debug-Info
X-Time
Fastcgi-Useragent
X-NWS-LOG-UUID
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Source
X-Mobile
X-N
X-Load-Cache
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Via-JSL
X-RateLimit-Remaining
X-FB-Debug
X-Daa-Tunnel
Nel
X-Cached-By
X-Akamai-Edgescape
Version
X-Cache-Operation
X-Cache-Rule
Refresh
X-Fastcgi-Cache
Viewport
X-Rule
X-Response-Served-From
X-Accel-Buffering
X-Original-Request-Id
X-Drupal-Cache-Tags
DC
DynaTrace
X-Framework
X-Proxy
X-ProcessESI
X-Cacheable-TTL
X-RTag
X-Zen-Fury
X-RemovedCookies
Ms-Operation-Id
Access-Control-Request-Headers
X-Wix-Request-Id
X-Instance
X-Real-IP
X-Tt-Trace-Host
X-Cache-Time
X-Tt-Trace-Tag
X-UUID
X-Contextid
Referer-Policy
X-Region
X-HTML-Minification-Powered-By
Realpath
X-Yottaa-Metrics
X-Drupal-Cache-Contexts
X-Distributor
GEO-INFO
X-Page-View
X-Yottaa-Optimizations
Node
X-FW-Server
X-FW-Static
X-FW-Serve
X-Cache-Expired-At
X-FW-Hash
Countrycode
Eomportal-Instance
X-FW-Type
X-FW-Dynamic
X-Environment-Context
X-L-Path
X-B
X-Cluster-Name
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Cache-Control
X-Tumblr-Pixel-1
Liferay-Portal
X-Tumblr-User
X-G
X-Content-Powered-By
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-IPS-LoggedIn
X-Cache-Hit
X-Node-Name
X-User-Agent
Server-Info
X-Ratelimit-Limit
X-Varnish-Ttl
Webserver
X-Tumblr-Pixel-2
X-App-Server
From-Origin
Section-Io-Origin-Status
Section-Origin-Responded
Section-Io-Id
Section-Io-Origin-Time-Seconds
Protected
X-Pass-Why
X-Amz-Meta-S3cmd-Attrs
X-FireWall-Port
Ec-Rule-Version
X-Protected-By
X-Revision
SRV
X-Cache-Server
X-Backend-Name
CF-IPCountry
Frame-Options
X-RN-RSRV
X-Hyper-Cache
X-Mode
X-Hl-Ver
X-UPSTREAM-Address
X-Handled-By
X-Endurance-Cache-Level
X-ES-SERVER
Meta-Geo
Cache-Status
X-Www-Served-By
X-Soup
X-Locale
X-FB-TRIP-ID
X-Site-Version
Cache-Tv-Group
X-Web-Node
Xserver
X-Be
Country
X-Varnishpool
X-Human
X-NYM-Debug-Backend
X-Cache-Grace
X-Forwarded-Host
X-Storage
Retry-After
X-Pubstack
X-Labrador-Cache-Channel
Azure-Version
Cache-Name
Azure-SlotName
Azure-SiteName
Decoy-Debug-TTL
Decoy-Debug-Status
X-BYPASS-REASON
TWC-GeoIP-LatLong
Webcakes-App-Version
Webcakes-Region
Webcakes-App-Name
TWC-Privacy
Decoy-Debug-Key
TWC-GeoIP-Country
TWC-Device-Class
X-Origin-Hint
X-Origin-Date
X-PHP-Host
X-Proto
X-ProxyCache-Key
X-Proxy-Build
TWC-Locale-Group
Azure-InstanceId
Selected-Fe
TWC-Connection-Speed
Property-Id
Fastly-SSL
Azure-RegionName
X-ProxyCache-Status
X-UA-Device-Type
X-Timing-Wait
X-Adobe-Loc
X-Redis-Cache
X-TT-LOGID
X-Uri
X-Adobe-Content
X-SayCDN-TTL
X-OCL
X-Say-TTL
X-Say-Cacheable
X-Section
X-S-Maxage
X-No-Session
X-WA-Info
X-FW-Version
X-Via-Fastly
X-Format
X-Ratelimit-Remaining
X-TNCMS
X-Sql-Count
X-Hosted-By
X-Sql-Duration-Ms
X-Server-W
X-Loop
X-Request-Time
X-Access
X-AIR-PT
X-PCL
X-LAGOON
X-MP-GENERATED-AT
X-LJ-Flow-ID
X-ApacheServer
X-VWS-Id
X-Via-CDN
X-PERF
X-AWS-Id
X-R9-Blue-Green-Version
Mn-Server-Ip
X-Cluster
X-Storefront-Renderer-Rendered
X-Alternate-Cache-Key
X-Sorting-Hat-ShopId
X-Qloud-Router
X-Shopify-Stage
X-ShopId
X-Status
X-Sorting-Hat-PodId
X-ShardId
X-Zipkin-Id
X-Country-Code-Real
X-Routing-Service
X-Cache-TTL-Remaining
S-Cnection
X-Proxied
X-FTR-Backend
X-FTR-Cache-Status
X-FTR-Balancer
X-FTR-DC
X-FTR-Realm
X-FTR-Backend-Server
X-Xfnlog-Site
Cache-Hits
X-CCM
X-Rendered-As
X-Is-Bot
X-Tec-Api-Origin
X-FTR-Expires
X-Tec-Api-Root
X-Tec-Api-Version
AMP-Access-Control-Allow-Source-Origin
X-Dc
X-Nginx-Cache
X-Device-Type
X-Oracle-Dms-Rid
X-Cache-Var-Map
X-Info
X-Cache-Var
X-Detected-As
X-Cdn
Apigw-Requestid
X-Air-Hostname
X-Debug-IsPreview
X-Unique-Id
X-Debug-IsConnected
X-SRV
X-Cache-Host
X-Amz-Apigw-Id
X-Amzn-Remapped-Content-Length
X-Amzn-RequestId
X-EdgeConnect-Cache-Status
X-Microcachable
X-Cache-Enabled
X-Varnish-Grace
X-Dynatrace
X-Content-Age
SD-X-WS
X-Platform
X-Varnish-Server
X-GG-Cache-Date
Tracecode
X-GEO
X-DynaTrace-JS-Agent
X-Time-Microsecs
X-Azure-Ref
X-Cache-Backend
X-Backend-Host
X-Backend-TTL
Amp-Access-Control-Allow-Source-Origin
X-Erf-Stays-Bingo-Pdp-Web
X-ServerID
Uber-Trace-Id
X-APP-VERSION
X-Proxy-Cache-Status
X-CSRF-Token
X-Oss-Server-Time
DSUID
X-Oss-Storage-Class
X-Oss-Request-Id
Akamai-GRN
X-Oss-Hash-Crc64ecma
X-Tb
X-Oss-Object-Type
X-ATG-Version
X-NewRelic-App-Data
X-BCube-Filmed-By
X-Correlation-ID
Backend
X-Trace-Id
X-Akamai-Transformed
PB-RID
PB-PID
Arc-Version
X-NWS-UUID-VERIFY
X-Sucuri-ID
X-A
X-External-Request-Id
X-Vtex-Remote-Cache
Instruction
X-Device-Os
Mobile-Detection-Method
X-D
X-Destination
X-A-Ccd
X-Varnish-Cache-Hits
DCR-Decision-By
X-Vtex-Processado-Em
X-Generation-Time
X-VG-WebCache
X-GeoIP-City
X-Vdms-Version
X-Generated-On
X-Magnolia-Registration
Thinkindot-Control
X-VG-WebServer
X-From
Odigeo-Trace-Id
SR-User-Adfree
T-Server
DCR-Processing-Time-Ms
Xc-Version
Thinkindot-CacheControl-Type
X-Cache-NE
X-B-Cookie
BehaviorPad-Version
X-A-Wwc
X-Aed
X-Application
X-ARC
X-A-Dcw
Expiry
X-Vdms-Path
Thinkindot-CacheControl
X-A-Dam
X-Connection-Hash
X-Varnish-Hostname
ServedBy
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-RCS-CacheZone
Fastcgi-X-Cache-Version
X-A-Dgt
X-Fetched-On
X-PBS-Appsvrname
X-Trv-Group
Pramga
X-Processor
X-PAYTM-SRV-ID
X-Origin-TTL
X-Matched-Rule
Release
X-Origin-CC
X-Request-UUID
X-Thinkindot-L3
X-ScT
X-Session-Fingerprint
X-SRCache-Key
Machine
X-S-Cookie
X-Rewrite-Enabled
X-Rojux
X-S
Path
Lfy
MD5-Digest
X-Level-Front-Cache
Meta-Geo-Continent
Rendered-Blocks
X-Location
X-Origin-Response-Time
X-Cache-PHP
X-Cache-NGX
X-Sn-Servicetimems
X-Bip
X-B3-Traceid
Cf-Device-Type
AKAMAI
X-Cache-Bucket
X-Cdn-Origin
X-TrackingId
X-Reqid
X-Cache-Date
X-Thanos
C-Via
Pagetype
X-GeoIP
X-Swa-Ws
X-SVT-ORM-VERSION
UCS
X-Azure-Ref-OriginShield
Cache-Host
CacheControlHeader
X-Skip-Cache
X-HS-Content-Campaign-Id
X-Geo-Header
X-FC-Vary-Parameters
X-Ms-Version
X-Node-Id
X-Debug-Cache
X-SVT-ORM-RULES
X-Ms-Request-Id
Gh-Request-Id
X-Micro-Cache
X-Tumblr-Pixel-3
X-Mvc-Supplant-Cachable
X-Has-Esi
X-JWT-State
X-Owner
X-Is-Gdpr
X-Irp-Debug
Host-ID
X-OVcl-Cache
Fastly-Backend-Name
Ssr
X-OVcl
X-VServer
X-TA-CDN-Provider
X-Adobe-Source
Server-Hostname
Server-Ext
Server-Host
Sever-Int
PFcat
On-Server
X-Generated-By
X-Origin-Expires
X-Policy
X-Nginx-Cache-Key
X-IP
X-Generated-In
X-HN
X-Request-Host
X-Scheme
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-VarnishDD-TTL
X-Varnish-Hits
X-User
X-Var-Ttl
X-Fastly-Cache
X-Fastly-Backend
X-CGP
X-Clientip
X-Cache-Tags
X-Cache-Info
Wxu-Next-Region
X-Backend-State
X-Cms-Context
X-Core-Value
X-Developers
X-Eu-Site
X-Developer
X-CUA
X-Csrf-Jwt
Wxu-Next-Hostname
Wxu-Next-Commit
HA-Ipaddr
L
L5d-Success-Class
DB-Nickname
HostName
CloudFront-Viewer-Country
Content-Disposition
Location
Ha-Gx-Prefs
NGX
Locid
Magicmarker
X-TX-ID
User-Cache-Control
X-ID
X-Hash
X-Gzip
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Cache-Id
X-Cache-Expires
X-Li-Fabric
X-Li-Pop
X-Hnp-Log
X-Gen-Mode
X-DPWN-IS-SECURE
X-Dispatcher-Server
X-DefHash
X-Clara-WADP
X-LI-UUID
X-Envoy-Decorator-Operation
X-DefElseHash
X-Fmm-Version
X-Esi-Check
X-GoCache-CacheStatus
X-Old-Content-Length
X-Variation
X-Slack-Backend
X-SIPLIST1
X-Servername
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-NAPM-TraceId
X-Varnish-Beresp-Grace
X-WADP-Cache
X-Varnish-Remaining-TTL
X-Cache-Remote
X-Request-URI
X-Origin
Adler-Geo
X-NU-AKA-ACS-Version
X-Method
X-Platform-Server
X-Ratelimit-Reset
X-Request-Start
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
NM-Fastcgi-Cache
X-Loc
Platform
Fastly-SWR
Web-Mar-Node
Rt-Fastcgi-Cache
X-Block-Status
IsBot
V-Age
CDCHOST
Cf-Bgj
Fastly-SIE
X-Branch-Name
Origin
Is-Eu
X-App-Version
X-Cdn-Forward
X-B3-SpanId
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
True-Client-Country-4JS
Vix-Hermes-Req-Id
CDN-EdgeStorageId
CDN-CachedAt
CDN-PullZone
CDN-RequestCountryCode
CDN-Uid
CDN-RequestId
Apple-News-Services-Request-Url
Apple-News-Services-Handled
Fastly-Drupal-HTML
X-NC
X-Gamma-Serve
X-Varnish-Beresp-Status
X-Cache-Debug
X-Varnish-Beresp-Ttl
X-Core-Mission
X-VG-TLSProxy
CDN-Cache
X-CS
X-EC-Lua
X-NCache
X-Mvc-Supplant-OutputCached
X-PF-Uncompressing
Sid
X-CACHE-GROUP
S-Rt
X-Varnish-Cacheable
X-Aicache-OS
X-Refresh
X-Host-Name
X-Varnish-Url
X-LB-ID
Url
X-Response-By
X-B3-Spanid
Xkeyi7
X-Proxy-Cachei7
X-BBXSRF
Pics-Label
CACHE
X-Via-Poph
X-FireWall-Protection
X-Via-Popv
N-Cache
X-Via-Popn
Esi-Enabled
Cross-Origin-Window-Policy
Ohc-File-Size
X-Cache-2
Content-Secure-Policy
X-Tb-Optimization-Total-Bytes-Saved
X-Sucuri-Cache
X-Varnish-Authentication
D-Cc-Upstream
X-Cache-ASPX
X-Cc-Req-Id
X-Contensis-Viewer-Groups
X-Cc-Via
X-Error
X-Epic-Correlation-Id
X-Webkit-Csp
Who
X-Srv
Cteonnt-Length
X-Nc
X-TraceId
Req-Svc-Chain
Country-Code
X-Unique-ID
X-CACHE-KEY
X-CDN-Forward
Source
X-Svr
X-Webkit-CSP-Report-Only
X-Cs
X-Server-IP
GeoIp-Country-Code
X-DC
X-Planisys-CDN-Rules
MIME-Version
X-Wa
Server-Ttl
X-Servedbyhost
Geoip-Latitude
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
HitType
X-RateLimit-Limit
X-HS-Status
X-Gdpr
X-API-Version
X-Cache-Config
X-FPC
X-Origin-Time
X-Nyt-Route
X-URL
Cmsid
X-LiteSpeed-Cache-Control
Cmstype
Kp-EeAlive
X-VC
X-SN
Hostname
Geo-Info
Ohc-Cache-HIT
X-Webstats-RespID
X-Served-From
X-NGINX-Cache
Svr
X-LI-Proto
X-SB
X-Esi
X-NodeID
A
X-Check-Cacheable
Server-ID
Viewtype
X-VCL-Version
X-SD-PageType
X-Vcl-Version
Cache-Key
XServer
X-TIME
VivaBuild
NtCoent-Length
X-HOST
M-TraceId
X-RAMCache
Request-ID
Resin-Trace
X-Li-Proto
Server-Id
SID
X-Vgn-Hpd-Reason
X-Render-Time
X-Ua
X-UA
X-CCDN-CacheTTL
X-DSS
X-Hcs-Proxy-Type
X-Viewer-Country
X-RSL
Arc-Country
EpKe-Alive
X-RPM
X-Air-Source
Cross-Origin-Opener-Policy
TDXMobile
X-BBC-Edge-Cache-Status
X-CCDN-Origin-Time
X-TIM-N
X-RPS
Cache-Provider
X-DI
X-DB
X-DW
Srv
GeoIP-Country-Code
X-Worker
X-CF-Powered-By
GeoIP-Latitude
X-Fastly-Request-Id
X-Auto-Login
Filterid
X-Internal-Host
X-HostName
X-ServedByHost
Mime-Version
X-WA
ProcessTime
X-Action
X-Vc
X-App
Processtime
X-Ftr-Cache-Host
Upgrade-Insecure-Requests
X-Newrelic-Synthetics
X-CSRF-TOKEN
X-FTR-Cache-Host
X-Service
Tcn
X-Fpc
CDN
X-Cluster-Node
X-Oss-Cdn-Auth
NGB
X-Dynatrace-Js-Agent
X-CLOUD-TRACE-CONTEXT
X-BBC-Origin-Response-Status
X-FORWARDED-FOR
Datacenter
X-Geo
Proxy-Connection
CF-Cached-On
X-HITS
X-BACKEND-TTL
X-Via-NSCOPI
X-MSEdge-Flight
X-SaId
X-MSEdge-Features
DataCenter
X-Dw-Trace-Id
X-JoinUs
X-Fastly-Backend-Reqs
FSS-Cache
X-Parent-Response-Time
X-Forwarded-Site
X-NGENIX-Cache
X-PHP-Backend
Cdn
X-Client-Ip
X-CACHE-AGE
X-Edge-Location
X-Extlb
X-Cdn-Request-ID
PICS-Label
X-Cache-Tag
X-IN-APIGATEWAY
X-Flog
X-ABtesting
OT-Force-Account-Verify
X-Hello
W
X-Via-PopH
X-ND-Cache
Dnion-Transfer-Encoding
X-Via-PopN
X-Via-PopV
X-IN-APIGATEWAYSSL
WZWS-RAY
X-Swift-Error
X-Akamai-Pragma-Client-IP
X-Provided-By
X-Presslabs-Stats
X-Bc-Bl
X-Date
X-Depends-On
X-Pf-Uncompressing
X-Oracle-DMS-ECID
Media-Length
X-Accel-Expires-Debug
Memcached
Mail-Subject
Surrogated-Key
We-Hiring
X-PJAX-URL
LB
X-Lb-Id
X-Region-Sid
Vha6-Origin
X-Req
X-VC-Cache
X-Proxy-Upstream
X-APP
Time
Memory
Epwk-X-Cache
X-Sigma-Backend
X-Sigma
Env
X-Rocket-Build-Number
X-ZONE
X-RateLimit-Limit-Second
X-Pad
X-MiniProfiler-Ids
X-RateLimit-Remaining-Second
X-UnsetCookies
X-LiteSpeed-Tag
Cf-Ipcountry
X-Zone
X-Men
X-Varnish-URL
X-Air-Trace-Id
X-Csrf-Token
X-Litespeed-Cache-Control
X-B3-Parentspanid
X-ElasticPress-Query
X-Acquia-Site
URI
X-Request-Url
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-ElasticPress-Search
X-Request-URL
Xet-Cookie
X-Varnish-Beresp-TTL
X-Vcache
X-Ms-Meta-Staticbatchstarttime
X-Ms-Meta-Originalurl
X-Snapshot-Date
X-Akamai-ERPolicy
X-Akamai-ERRuleID
CountryCode
X-Tid
X-Redis-Count
X-Redis-Duration-Ms
X-Traceid
VNS-Age
VNS-Cache
CPC-Cache
CPC-Age
Environment
X-Amz-Meta-Cb-Modifiedtime
X-C
X-Akamai-Request-ID
NnCoection
Phost
X-Debug-Cache-Fetch
X-Debug-Cache-Store
Inserted-Into-Cache-At
X-ServerName
Ohc-Response-Time
X-Storefront-Renderer-Verified