Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
CF-RAY
Cf-Request-Id
CF-Cache-Status
Last-Modified
X-XSS-Protection
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-Runtime
X-AspNet-Version
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Xss-Protection
X-Cache-Status
X-Generator
X-Request-ID
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Content-Security-Policy
Content-Encoding
X-CDN
X-Envoy-Upstream-Service-Time
Status
Feature-Policy
X-Ua-Compatible
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-AspNetMvc-Version
Access-Control-Max-Age
X-Via
Upgrade
Keep-Alive
X-Ws-Request-Id
X-Age
X-Turbo-Charged-By
X-AH-Environment
X-Robots-Tag
Request-Context
X-Proxy-Cache
EagleId
X-Cache-Group
Server-Timing
X-Backend
X-Hacker
X-Amz-Request-Id
Report-To
X-Server
Host-Header
X-Amz-Id-2
X-Server-Powered-By
Grace
X-Nginx-Cache-Status
X-UA-Device
X-LiteSpeed-Cache
X-Dns-Prefetch-Control
X-Varnish-Cache
X-Rq
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Page-Speed
Cf-Railgun
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
NEL
X-Amz-Version-Id
X-OneAgent-JS-Injection
Xkey
X-WebKit-CSP
X-Cache-Spec
Allow
X-Backend-Server
X-Host
X-Vhost
X-CST
X-Device
EagleEye-TraceId
X-Server-Id
X-ASPNET-VERSION
Surrogate-Control
Request-Id
X-Dispatcher
Accept-CH
X-Node
Content-Location
X-Response-Time
Accept-CH-Lifetime
X-Akam-SW-Version
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Ruxit-JS-Agent
X-Template
X-Ac
X-Application-Context
X-Language
X-Kinja-Server-Push
X-Country
X-Cache-Lookup
X-Readtime
X-Mod-Pagespeed
X-Cloud-Trace-Context
MS-Author-Via
X-B3-TraceId
X-Origin-Cache
Rating
X-Cnection
X-MS-InvokeApp
X-HW
X-Url
X-Vname
X-TtlSet
X-PC
X-ORACLE-DMS-ECID
Accept-Ch
X-Clacks-Overhead
X-FastCGI-Cache
Edge-Control
X-GitHub-Request-Id
X-ESI
X-Trace
Accept-Ch-Lifetime
Display
Pagespeed
Response
X-Sol
X-Middleton-Response
X-Middleton-Display
X-Content-Type
X-D2id
X-Vcap-Request-Id
X-Exp-Variant
X-Exp-Id
X-GoogleNews-Bot
X-Cdn-Fetch
Arr-Disable-Session-Affinity
Verso
X-Kinja
X-Kinja-Revision
X-Use-Magma
X-Kinja-Build
X-Kinja-Server
X-Buckets
X-Goog-Hash
X-Rack-Cache
X-Server-Name
X-Country-Code
Service-Worker-Allowed
X-Navigation-Version
X-Varnish-TTL
X-Abt-Application-Version
X-VARITI-CCR
X-Amz-Rid
X-Oneagent-Js-Injection
X-ORACLE-DMS-RID
X-Powered-By-Plesk
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-Cache-TTL
X-Client-IP
SPRequestGuid
X-SharePointHealthScore
X-Fastly-Request-ID
X-Release
SPIisLatency
SPRequestDuration
X-MSEdge-Ref
X-Dw-Request-Base-Id
Fastly-Restarts
X-Element-Page-Cache
X-NF-Request-ID
X-Cached
Public-Key-Pins
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
RTSS
X-Ttl
X-Origin-Upstream-Status
AR-CACHE
Ar-Sid
AR-Request-ID
AR-ATIME
AR-PoweredBy
X-Edge
Access-Control-Request-Method
X-TTL
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Webkit-CSP
X-Px
X-LLID
X-Powered-CMS
Fusion-Content-Source
Fusion-Deployment-Id
Fusion-Source
Fusion-Template-Id
Fusion-Content-Id
Fusion-Component-Id
X-Ezoic-Cdn
X-Upstream
Content-MD5
X-HP-Webp
X-Jurisdiction
X-Amz-Server-Side-Encryption
X-Mid
X-ECACHE
X-MCACHE
Charset
Cache-Tag
X-Recruiting
X-Mg-S
S
X-Content-Digest
X-Pinterest-Direct
X-PressLabs-Stats
X-Version
X-Aspnetmvc-Version
TCN
MicrosoftSharePointTeamServices
Fastcgi-Cache
X-Debug
Front-End-Https
X-T
X-Content-Security-Policy-Report-Only
X-Grace
Filters
X-Kinsta-Cache
Cache-Tags
X-XRDS-Location
Edge-Cache-Tag
Server-Node
X-Id
X-Forwarded-Proto
X-Accel-Expires
X-Correlation-Id
X-Logged-In
X-Amzn-Trace-Id
X-Yandex-Sdch-Disable
Server-Name
Nginx-Cache
Surrogate-Key
X-Varnish-Age
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Cache-Key
X-Forwarded-For
TP-Cache
TP-L2-Cache
X-B3-Sampled
X-Request-Received
X-Request-Processing-Time
X-Request-Handler-Origin-Region
X-Microsite
X-DynaTrace
X-Hits
X-Ser
Powered-By-ChinaCache
X-DIS-Request-ID
X-Shield-Request-Id
X-AppVersion
X-Activity-Id
X-Az
X-Amz-Replication-Status
X-Server-ID
X-HS-Cache-Config
X-HS-Combine-CSS
X-HS-Content-Id
X-HS-Hub-Id
X-F-Cache
X-Ruxit-Js-Agent
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
X-Origin-Server
Accept-Charset
X-FTR-Request-ID
X-Git-Hash
X-Hostname
X-Respond-Thread
X-Geo-Country
X-LB-Cache
X-DataDome
X-Upgrade-Enabled
Section-Io-Cache
X-Rid
X-Frontend
Access-Control-Allow-Method
X-Cache-Age
Cache
Alternate-Protocol
Host
X-Mobile-URL
Cleartype
Paypal-Debug-Id
MS-CV
Healthy
X-IPLB-Instance
X-Type
X-Content-Options
X-WebKit-CSP-Report-Only
ServerID
X-AOL-HN
X-App-Environment
X-Varnish-Backend
X-Seen-By
X-Whom
Payment
X-Cache-Action
X-B-Cache
X-Aspnet-Duration-Ms
X-Flags
X-Debug-Info
X-Providence-Cookie
X-Route-Name
X-Signature
X-TT
X-Is-Crawler
X-Request-Guid
X-VCache
X-XRDS-LOCATION
X-Page-Id
Fastcgi-Useragent
X-TEC-API-ROOT
X-Jobs
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-NWS-LOG-UUID
X-N
X-Source
X-Mobile
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Load-Cache
X-Browser-Type
X-Time
X-RateLimit-Remaining
X-Via-JSL
X-Cached-By
X-Daa-Tunnel
X-FB-Debug
X-Akamai-Edgescape
Version
Nel
X-Cache-Rule
X-Cache-Operation
X-Litespeed-Cache
Viewport
Refresh
X-Rule
X-Response-Served-From
DynaTrace
X-Original-Request-Id
X-Accel-Buffering
X-Framework
DC
X-Drupal-Cache-Tags
X-Zen-Fury
X-Proxy
X-RTag
X-Cacheable-TTL
Realpath
X-ProcessESI
X-Instance
X-RemovedCookies
Ms-Operation-Id
GEO-INFO
Access-Control-Request-Headers
X-Contextid
X-Tt-Trace-Host
X-Real-IP
X-Fastcgi-Cache
X-Tt-Trace-Tag
X-UUID
X-Cache-Time
X-Region
X-HTML-Minification-Powered-By
X-Wix-Request-Id
X-Drupal-Cache-Contexts
X-Distributor
Referer-Policy
X-Yottaa-Optimizations
X-Page-View
X-Yottaa-Metrics
VIX-Pulpo-Upstream-Status
X-FW-Dynamic
Countrycode
VIX-Pulpo-Node
X-Cache-Expired-At
Node
X-FW-Type
Eomportal-Instance
X-FW-Hash
X-FW-Static
X-FW-Server
X-FW-Serve
X-B
X-Environment-Context
X-L-Path
X-Cluster-Name
Liferay-Portal
X-Tumblr-Pixel-1
X-Cache-Control
X-Tumblr-User
X-Tumblr-Pixel-0
X-G
X-Node-Name
X-Tumblr-Pixel
X-Content-Powered-By
X-IPS-LoggedIn
X-Cache-Hit
X-User-Agent
Webserver
Server-Info
X-Tumblr-Pixel-2
X-Amz-Meta-S3cmd-Attrs
X-Pass-Why
Section-Io-Origin-Status
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
From-Origin
Section-Io-Id
X-App-Server
X-Varnish-Ttl
SRV
Protected
X-Ratelimit-Limit
X-Protected-By
Ec-Rule-Version
X-FireWall-Port
X-Revision
Frame-Options
X-Oracle-Dms-Rid
X-Cache-Server
X-Backend-Name
Cache-Status
CF-IPCountry
X-Endurance-Cache-Level
X-Mode
X-Hl-Ver
Meta-Geo
X-ES-SERVER
X-Www-Served-By
X-Hyper-Cache
X-UPSTREAM-Address
X-Handled-By
X-RN-RSRV
Retry-After
X-NYM-Debug-Backend
X-Locale
X-Storage
X-Soup
X-Forwarded-Host
X-FB-TRIP-ID
X-Site-Version
X-Web-Node
X-Human
X-Pubstack
Cache-Tv-Group
X-Varnishpool
Country
Decoy-Debug-Status
X-Adobe-Content
Decoy-Debug-TTL
Decoy-Debug-Key
X-Be
X-Adobe-Loc
X-Cache-Grace
Fastly-SSL
TWC-Locale-Group
Azure-SlotName
X-Labrador-Cache-Channel
Azure-Version
TWC-GeoIP-LatLong
X-PCL
Azure-SiteName
X-BYPASS-REASON
Webcakes-Region
TWC-Privacy
Webcakes-App-Name
X-Format
X-Access
Azure-InstanceId
X-Origin-Date
X-Origin-Hint
Azure-RegionName
TWC-GeoIP-Country
X-UA-Device-Type
X-TT-LOGID
Property-Id
Selected-Fe
X-Uri
X-Say-TTL
X-ProxyCache-Status
X-Say-Cacheable
X-ProxyCache-Key
X-SayCDN-TTL
X-OCL
TWC-Device-Class
X-Redis-Cache
X-PHP-Host
X-Proto
X-Proxy-Build
X-Timing-Wait
X-Section
TWC-Connection-Speed
Cache-Name
Webcakes-App-Version
X-Via-CDN
X-No-Session
X-Via-Fastly
X-LAGOON
X-FW-Version
X-AIR-PT
X-ApacheServer
X-PERF
X-WA-Info
X-Sql-Count
X-Sql-Duration-Ms
X-S-Maxage
X-Server-W
X-Hosted-By
X-Loop
X-Request-Time
X-AWS-Id
X-R9-Blue-Green-Version
X-VWS-Id
X-TNCMS
X-LJ-Flow-ID
S-Cnection
Mn-Server-Ip
X-MP-GENERATED-AT
X-Country-Code-Real
X-FTR-Backend
X-FTR-Cache-Status
X-FTR-Balancer
X-FTR-DC
X-FTR-Realm
X-Cluster
X-Status
X-FTR-Backend-Server
X-Qloud-Router
X-Alternate-Cache-Key
X-Zipkin-Id
X-Proxied
X-Routing-Service
X-CCM
X-Storefront-Renderer-Rendered
X-Sorting-Hat-PodId
X-ShopId
X-ShardId
X-Cache-TTL-Remaining
X-Shopify-Stage
X-Sorting-Hat-ShopId
Cache-Hits
X-FTR-Expires
X-Xfnlog-Site
X-Ratelimit-Remaining
Xserver
X-Rendered-As
X-Is-Bot
X-Dynatrace
X-Tec-Api-Origin
X-Device-Type
X-Tec-Api-Root
X-Tec-Api-Version
X-Unique-Id
X-Cache-Var
X-Cache-Var-Map
X-SRV
X-Air-Hostname
Apigw-Requestid
X-Detected-As
AMP-Access-Control-Allow-Source-Origin
X-Info
X-Nginx-Cache
X-EdgeConnect-Cache-Status
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Amzn-Remapped-Content-Length
X-Cache-Host
X-Dc
X-Webkit-Csp
X-Cdn
X-Debug-IsConnected
X-Debug-IsPreview
X-Microcachable
X-Cache-Enabled
SD-X-WS
X-Varnish-Grace
X-GEO
X-Content-Age
X-Platform
X-Varnish-Server
X-Time-Microsecs
Amp-Access-Control-Allow-Source-Origin
Tracecode
X-Azure-Ref
X-Backend-TTL
Uber-Trace-Id
X-Backend-Host
X-Cache-Backend
X-GG-Cache-Date
X-ServerID
X-APP-VERSION
X-DynaTrace-JS-Agent
X-Erf-Stays-Bingo-Pdp-Web
X-Proxy-Cache-Status
DSUID
Akamai-GRN
X-Oss-Object-Type
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
X-BCube-Filmed-By
X-Oss-Server-Time
X-Tb
X-ATG-Version
X-NewRelic-App-Data
X-Trace-Id
Backend
X-Sucuri-ID
X-ID
PB-PID
PB-RID
Arc-Version
X-Akamai-Transformed
ServedBy
X-Correlation-ID
X-Magnolia-Registration
X-Varnish-Hostname
Xc-Version
SR-User-Adfree
X-SRCache-Key
X-Generated-On
T-Server
X-B-Cookie
Rendered-Blocks
X-Vtex-Remote-Cache
Release
X-ScT
X-S-Cookie
X-S
X-Rojux
X-CSRF-Token
Pramga
X-RCS-CacheZone
X-Session-Fingerprint
X-Cache-NE
X-ARC
Thinkindot-CacheControl
X-A-Dcw
X-VG-WebServer
X-A-Dgt
X-Varnish-Cache-Hits
X-A-Dam
X-A-Ccd
X-Cache-NGX
X-Vtex-Processado-Em
X-A
X-VG-WebCache
X-A-Wwc
Thinkindot-CacheControl-Type
X-Trv-Group
X-Thinkindot-L3
Thinkindot-Control
X-Vdms-Path
X-Vdms-Version
X-Aed
X-Application
X-CF-Lambda-Fn
X-CF-Lambda-Version
Instruction
DCR-Processing-Time-Ms
BehaviorPad-Version
X-Cache-PHP
X-Level-Front-Cache
X-Generation-Time
X-Location
X-D
X-Destination
X-From
X-Fetched-On
Fastcgi-X-Cache-Version
X-Origin-Response-Time
Expiry
X-Device-Os
X-External-Request-Id
X-GeoIP-City
X-Matched-Rule
X-PBS-Appsvrname
X-PAYTM-SRV-ID
DCR-Decision-By
X-Processor
Path
X-Rewrite-Enabled
X-Request-UUID
X-Connection-Hash
Odigeo-Trace-Id
MD5-Digest
Machine
Lfy
Meta-Geo-Continent
X-Origin-CC
Mobile-Detection-Method
X-Origin-TTL
UCS
L5d-Success-Class
Ssr
Pagetype
Host-ID
HA-Ipaddr
Gh-Request-Id
Ha-Gx-Prefs
Fastly-Backend-Name
X-SVT-ORM-VERSION
X-JWT-State
X-Is-Gdpr
X-Csrf-Jwt
X-Micro-Cache
X-Mvc-Supplant-Cachable
X-Node-Id
X-CGP
X-Irp-Debug
X-Eu-Site
X-Generated-In
X-Geo-Header
Cf-Device-Type
X-GeoIP
X-Has-Esi
X-HS-Content-Campaign-Id
X-FC-Vary-Parameters
X-OVcl
X-OVcl-Cache
X-Swa-Ws
X-Bip
X-Cache-Bucket
X-Azure-Ref-OriginShield
X-Thanos
X-User
X-Tumblr-Pixel-3
X-SVT-ORM-RULES
X-Cache-Date
X-Reqid
X-Owner
X-Cdn-Origin
X-Skip-Cache
X-Cache-Info
X-Sn-Servicetimems
X-VServer
X-Backend-State
AKAMAI
C-Via
Cache-Host
X-Debug-Cache
X-Ms-Request-Id
X-NWS-UUID-VERIFY
X-Adobe-Source
CacheControlHeader
X-Ms-Version
DB-Nickname
X-Wikidot-Backend
On-Server
X-TrackingId
X-Cms-Context
X-Request-Host
X-Core-Value
X-Var-Ttl
X-CUA
X-Wikidot-Static-Cache
X-Origin-Expires
NGX
X-Clientip
Server-Host
Server-Hostname
X-Varnish-Hits
Sever-Int
Server-Ext
X-Policy
CloudFront-Viewer-Country
X-HN
X-VarnishDD-TTL
X-Cache-Tags
PFcat
Magicmarker
Wxu-Next-Commit
X-Fastly-Cache
X-Fastly-Backend
X-Cache-Remote
Wxu-Next-Hostname
Wxu-Next-Region
X-IP
X-Generated-By
X-Scheme
X-Envoy-Decorator-Operation
X-B3-Traceid
Content-Disposition
X-Nginx-Cache-Key
X-Request-URI
Locid
X-Developer
L
User-Cache-Control
V-Age
X-Developers
X-Request-Start
X-Rebelmouse-Surrogate-Control
X-SIPLIST1
X-Rebelmouse-Cache-Control
X-Branch-Name
X-Block-Status
X-Servername
X-Origin
X-Loc
X-Method
X-Esi-Check
X-Fmm-Version
X-LI-UUID
X-Gen-Mode
X-Li-Fabric
X-Li-Pop
X-DPWN-IS-SECURE
X-Dispatcher-Server
X-Platform-Server
X-Cache-Id
X-Cache-Expires
X-Clara-WADP
X-Old-Content-Length
X-DefHash
X-DefElseHash
X-NU-AKA-ACS-Version
X-Ratelimit-Reset
X-TX-ID
Fastly-SIE
Fastly-SWR
Platform
X-WADP-Cache
X-VG-TLSProxy
CDCHOST
X-Varnish-CookieINHashed-On
Apple-News-Services-Parsed-Url
X-Varnish-Remaining-TTL
Origin
NM-Fastcgi-Cache
IsBot
Is-Eu
Apple-News-Services-Request-Url
Apple-News-Services-Host
Apple-News-Services-Handled
X-GoCache-CacheStatus
Location
Adler-Geo
X-Varnish-CookieHashed-On
Rt-Fastcgi-Cache
X-Variation
Vix-Hermes-Req-Id
True-Client-Country-4JS
Web-Mar-Node
X-Varnish-Beresp-Grace
Cf-Bgj
X-TA-CDN-Provider
X-Hnp-Log
X-Gzip
X-NC
CDN-RequestCountryCode
CDN-RequestId
CDN-CachedAt
X-Goog-Meta-Goog-Reserved-File-Mtime
X-NAPM-TraceId
CDN-EdgeStorageId
CDN-PullZone
X-Gamma-Serve
X-Varnish-Beresp-Status
X-Hash
X-Slack-Backend
X-Cache-Debug
Fastly-Drupal-HTML
CDN-Uid
X-B3-Spanid
CDN-Cache
X-Varnish-Beresp-Ttl
X-App-Version
HostName
X-Core-Mission
CACHE
X-EC-Lua
X-NCache
Url
X-Host-Name
X-Varnish-Url
X-CS
X-Varnish-Cacheable
X-Mvc-Supplant-OutputCached
X-Response-By
X-PF-Uncompressing
X-Aicache-OS
S-Rt
X-Cdn-Forward
X-B3-SpanId
Xkeyi7
X-Proxy-Cachei7
Pics-Label
X-CACHE-GROUP
X-LB-ID
X-Refresh
Cross-Origin-Window-Policy
N-Cache
Sid
X-BBXSRF
X-CDN-Forward
X-Sucuri-Cache
X-Via-Popv
Esi-Enabled
X-Esi
Ohc-File-Size
X-Via-Popn
X-Cache-2
X-FireWall-Protection
X-Via-Poph
Content-Secure-Policy
X-Epic-Correlation-Id
X-Cc-Via
X-Varnish-Authentication
Cteonnt-Length
X-Cache-ASPX
X-Cc-Req-Id
X-Contensis-Viewer-Groups
D-Cc-Upstream
X-RateLimit-Limit
X-TraceId
X-Error
X-Svr
X-Servedbyhost
X-Wa
MIME-Version
Source
X-DC
X-Tb-Optimization-Total-Bytes-Saved
X-Nc
Who
X-Cs
X-TIME
X-Srv
X-Unique-ID
X-Server-IP
Country-Code
Req-Svc-Chain
X-Webkit-CSP-Report-Only
Geoip-Latitude
X-Planisys-CDN-Rules
X-API-Version
X-VC
X-Planisys-CDN-Cache
X-LiteSpeed-Cache-Control
Server-Ttl
HitType
GeoIp-Country-Code
XServer
X-Planisys-CDN-TTL
X-FPC
X-Cache-Config
Hostname
X-Origin-Time
X-Gdpr
X-Nyt-Route
X-LI-Proto
X-SN
X-HS-Status
Ohc-Cache-HIT
X-NGINX-Cache
X-URL
X-Fastly-Request-Id
Cmstype
Server-ID
X-NodeID
Cmsid
X-Webstats-RespID
Kp-EeAlive
Svr
X-VCL-Version
X-SB
X-CACHE-KEY
Geo-Info
X-Check-Cacheable
VivaBuild
X-SD-PageType
Viewtype
X-Served-From
SID
X-Ua
Cache-Key
A
X-Render-Time
X-Viewer-Country
X-Vgn-Hpd-Reason
X-HOST
NtCoent-Length
X-CCDN-CacheTTL
X-Vcl-Version
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
M-TraceId
Request-ID
X-BBC-Edge-Cache-Status
EpKe-Alive
X-UA
X-CF-Powered-By
TDXMobile
Server-Id
X-TIM-N
Cross-Origin-Opener-Policy
Cache-Provider
X-DW
X-RPM
X-Worker
X-DSS
X-DI
X-DB
X-RPS
X-RSL
X-Air-Source
X-Li-Proto
X-RAMCache
GeoIP-Country-Code
GeoIP-Latitude
Arc-Country
Resin-Trace
X-Auto-Login
X-CSRF-TOKEN
X-FORWARDED-FOR
Filterid
X-Dynatrace-Js-Agent
X-Ftr-Cache-Host
Upgrade-Insecure-Requests
X-Internal-Host
X-App
ProcessTime
X-Newrelic-Synthetics
Srv
X-Cluster-Node
X-Action
Processtime
CDN
Datacenter
X-FTR-Cache-Host
X-Fpc
X-WA
X-Service
X-Vc
X-Oss-Cdn-Auth
Tcn
X-ServedByHost
NGB
Mime-Version
X-CLOUD-TRACE-CONTEXT
CF-Cached-On
X-Geo
Proxy-Connection
X-BBC-Origin-Response-Status
X-HostName
X-HITS
OT-Force-Account-Verify
X-MSEdge-Flight
Cdn
WZWS-RAY
X-MSEdge-Features
X-Forwarded-Site
X-Via-NSCOPI
X-BACKEND-TTL
X-Via-PopH
X-Dw-Trace-Id
X-Via-PopV
X-Akamai-Pragma-Client-IP
X-PHP-Backend
X-NGENIX-Cache
X-SaId
X-Fastly-Backend-Reqs
X-Via-PopN
FSS-Cache
X-JoinUs
X-Cache-Tag
X-ND-Cache
X-Extlb
X-Edge-Location
DataCenter
X-CACHE-AGE
X-Cdn-Request-ID
X-Client-Ip
X-Hello
X-Parent-Response-Time
X-ABtesting
X-Flog
Dnion-Transfer-Encoding
X-Lb-Id
X-IN-APIGATEWAYSSL
W
X-Pf-Uncompressing
X-IN-APIGATEWAY
PICS-Label
X-Provided-By
X-LiteSpeed-Tag
X-VC-Cache
X-Oracle-DMS-ECID
Epwk-X-Cache
X-PJAX-URL
X-Pad
X-Depends-On
X-Proxy-Upstream
X-RateLimit-Limit-Second
X-Req
X-Region-Sid
X-RateLimit-Remaining-Second
X-Date
X-Bc-Bl
Mail-Subject
LB
Media-Length
Memcached
Surrogated-Key
X-Accel-Expires-Debug
We-Hiring
X-UnsetCookies
Vha6-Origin
X-Swift-Error
X-Presslabs-Stats
X-Sigma
X-Sigma-Backend
Time
X-Rocket-Build-Number
Xet-Cookie
URI
X-ZONE
Env
X-MiniProfiler-Ids
Memory
X-Zone
Cf-Ipcountry
X-ElasticPress-Query
X-Acquia-Purge-Tags
X-Request-Url
X-Akamai-ERRuleID
X-Akamai-ERPolicy
X-Vcache
X-Acquia-Application-Trace
X-Request-URL
X-Acquia-Application-UUID
X-Acquia-Site
X-APP
X-Csrf-Token
X-Varnish-Beresp-TTL
X-ElasticPress-Search
X-Varnish-URL
X-Amz-Meta-Cb-Modifiedtime
X-Ms-Meta-Originalurl
X-Ms-Meta-Staticbatchstarttime
X-B3-Parentspanid
X-Men
X-Snapshot-Date
X-Akamai-Request-ID
X-Air-Trace-Id
CountryCode
X-Tid
Inserted-Into-Cache-At
Content-Style-Type
Content-Script-Type
X-ServerName
X-Litespeed-Cache-Control
Phost
X-Redis-Duration-Ms
X-Traceid
NnCoection
X-Via-SSL
X-Via-Edge
X-Redis-Count
Environment
Edge-Copy-Time
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Storefront-Renderer-Verified
X-Acc-Debug-Context
X-Acc-Rdl
Ohc-Response-Time
X-C