Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-RAY
CF-Cache-Status
Accept-Ranges
Link
X-XSS-Protection
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Request-Id
X-Varnish
Access-Control-Allow-Methods
X-Xss-Protection
Access-Control-Allow-Credentials
X-Runtime
X-AspNet-Version
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Content-Security-Policy
X-Iinfo
X-Request-ID
Content-Encoding
X-CDN
X-Ua-Compatible
Feature-Policy
X-AspNetMvc-Version
Status
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Upgrade
X-Via
Access-Control-Max-Age
X-POWERED-BY
Keep-Alive
X-Ws-Request-Id
X-Age
X-Robots-Tag
X-AH-Environment
X-Dns-Prefetch-Control
X-Turbo-Charged-By
EagleId
Request-Context
X-Proxy-Cache
X-Cache-Group
Server-Timing
X-Backend
X-Server
X-Hacker
Host-Header
Report-To
X-Server-Powered-By
X-Amz-Request-Id
X-Nginx-Cache-Status
Grace
X-Amz-Id-2
X-UA-Device
X-Rq
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Page-Speed
Cf-Railgun
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
X-Amz-Version-Id
NEL
X-Device
X-Cache-Spec
X-CST
Allow
X-Vhost
X-WebKit-CSP
X-Host
X-Backend-Server
Xkey
X-Server-Id
X-ASPNET-VERSION
EagleEye-TraceId
X-Dispatcher
Surrogate-Control
X-Node
Request-Id
Content-Location
X-Response-Time
X-Akam-SW-Version
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
P3p
X-Ruxit-JS-Agent
X-Cache-Lookup
X-Application-Context
X-Ac
X-Country
Accept-Ch
X-Template
X-Mod-Pagespeed
Accept-CH
Accept-Ch-Lifetime
X-Language
X-Readtime
X-Cloud-Trace-Context
Accept-CH-Lifetime
X-B3-TraceId
MS-Author-Via
Rating
X-HW
X-Url
X-Cnection
X-Origin-Cache
X-MS-InvokeApp
X-Vname
X-TtlSet
X-PC
Edge-Control
X-Clacks-Overhead
X-GitHub-Request-Id
X-Trace
X-ESI
X-ORACLE-DMS-RID
X-Middleton-Display
X-Middleton-Response
X-Sol
Response
Pagespeed
Display
X-Varnish-TTL
X-ORACLE-DMS-ECID
X-Content-Type
X-D2id
Verso
Arr-Disable-Session-Affinity
X-Cdn-Fetch
X-Exp-Id
X-Exp-Variant
X-GoogleNews-Bot
X-Kinja-Build
X-Kinja-Server
X-Kinja-Revision
X-Use-Magma
X-Kinja
X-Vcap-Request-Id
X-Country-Code
X-Goog-Hash
X-Rack-Cache
X-Powered-By-Plesk
X-Navigation-Version
X-Oneagent-Js-Injection
X-VARITI-CCR
Service-Worker-Allowed
X-Amz-Rid
X-Abt-Application-Version
X-Buckets
X-Fastly-Request-ID
X-TTL
X-Server-Name
X-Client-IP
Fastly-Restarts
X-Cached
X-Cache-TTL
X-FastCGI-Cache
X-MSEdge-Ref
X-Release
X-Element-Page-Cache
X-Dw-Request-Base-Id
SPRequestGuid
X-NF-Request-ID
X-SharePointHealthScore
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
SPIisLatency
SPRequestDuration
Public-Key-Pins
Access-Control-Request-Method
X-Webkit-CSP
RTSS
AR-CACHE
Ar-Sid
AR-Request-ID
AR-ATIME
AR-PoweredBy
Cache-Tag
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Powered-CMS
X-LLID
X-Edge
X-Ezoic-Cdn
X-Upstream
Content-MD5
X-Version
X-Jurisdiction
X-HP-Webp
X-Origin-Upstream-Status
S
X-Recruiting
Fusion-Template-Id
X-Mg-S
Fusion-Source
Charset
Fusion-Deployment-Id
X-MCACHE
X-Mid
X-ECACHE
Fusion-Component-Id
Fusion-Content-Source
Fusion-Content-Id
X-Px
X-Ruxit-Js-Agent
X-DynaTrace
X-PressLabs-Stats
X-Content-Digest
X-Kinsta-Cache
X-Ttl
X-T
Fastcgi-Cache
Cache-Tags
X-Litespeed-Cache
X-Amz-Server-Side-Encryption
X-Fastcgi-Cache
Filters
X-Accel-Expires
X-Logged-In
X-Forwarded-Proto
X-Content-Security-Policy-Report-Only
Server-Node
Edge-Cache-Tag
Front-End-Https
X-Id
TP-Cache
MicrosoftSharePointTeamServices
TP-L2-Cache
X-Correlation-Id
Server-Name
X-Grace
TCN
Nginx-Cache
X-Hits
X-Request-Processing-Time
X-Debug
X-Kong-Proxy-Latency
X-Request-Received
X-Kong-Upstream-Latency
X-Forwarded-For
X-Amzn-Trace-Id
X-B3-Sampled
X-Shield-Request-Id
X-Microsite
X-Request-Handler-Origin-Region
X-Varnish-Age
X-Yandex-Sdch-Disable
Surrogate-Key
X-Az
X-Activity-Id
X-AppVersion
X-Amz-Replication-Status
X-F-Cache
X-HS-Cache-Config
X-HS-Content-Id
X-XRDS-Location
X-HS-Combine-CSS
X-HS-Hub-Id
X-XRDS-LOCATION
Alternate-Protocol
X-Ser
X-Origin-Server
X-DIS-Request-ID
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
Accept-Charset
Nel
X-Geo-Country
X-Frontend
X-Rid
X-NWS-LOG-UUID
Section-Io-Cache
X-Git-Hash
Host
X-Time
X-Cache-Age
X-Respond-Thread
X-Pinterest-Direct
X-Cache-Key
X-Upgrade-Enabled
X-Hostname
X-VCache
X-DataDome
Access-Control-Allow-Method
X-Seen-By
X-LB-Cache
X-Mobile-URL
MS-CV
Cache
X-Server-ID
Paypal-Debug-Id
ServerID
X-Source
X-Type
X-IPLB-Instance
X-AOL-HN
X-TT
X-Daa-Tunnel
X-Varnish-Backend
Payment
X-RateLimit-Remaining
X-Whom
Healthy
X-FTR-Request-ID
X-App-Environment
X-Route-Name
X-Aspnet-Duration-Ms
X-Signature
X-Request-Guid
X-Is-Crawler
X-B-Cache
X-Providence-Cookie
X-Content-Options
X-Flags
X-Cache-Action
Cleartype
X-Page-Id
X-Debug-Info
Fastcgi-Useragent
X-WebKit-CSP-Report-Only
X-Jobs
X-Load-Cache
X-N
X-FB-Debug
X-Contextid
Realpath
X-Webkit-Csp
Powered-By-ChinaCache
X-Erf-Bev-Bev
X-Mobile
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
Node
Refresh
X-Rule
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Accel-Buffering
X-Response-Served-From
X-Wix-Request-Id
X-Original-Request-Id
X-Drupal-Cache-Tags
DC
Version
X-Cache-Expired-At
X-RTag
X-Zen-Fury
Ms-Operation-Id
X-Framework
X-Proxy
X-Cacheable-TTL
Referer-Policy
X-Via-JSL
X-Instance
X-ProcessESI
Access-Control-Request-Headers
X-B
X-Distributor
X-Cache-Control
X-Content-Powered-By
X-Real-IP
X-Cluster-Name
X-RemovedCookies
X-Cache-Time
X-Region
VIX-Pulpo-Node
X-Tt-Trace-Host
X-Page-View
X-HTML-Minification-Powered-By
X-UUID
X-Drupal-Cache-Contexts
VIX-Pulpo-Upstream-Status
Viewport
X-Tt-Trace-Tag
Eomportal-Instance
X-FW-Type
X-FW-Server
X-IPS-LoggedIn
X-FW-Serve
X-FW-Hash
X-FW-Static
X-FW-Dynamic
Countrycode
X-Cached-By
X-Akamai-Edgescape
X-FireWall-Port
X-Cache-Rule
X-Cache-Operation
Liferay-Portal
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Cache-Hit
X-G
X-Tumblr-Pixel-1
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Pass-Why
X-L-Path
X-Environment-Context
X-App-Server
SRV
Server-Info
DynaTrace
X-Nginx-Cache
CF-IPCountry
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
Section-Io-Id
Section-Io-Origin-Status
X-Debug-IsConnected
X-Debug-IsPreview
Xserver
X-Protected-By
X-Www-Served-By
X-User-Agent
Ec-Rule-Version
From-Origin
X-Tumblr-Pixel-2
Webserver
X-Device-Type
GEO-INFO
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
X-Adobe-Content
X-Adobe-Loc
X-Mode
X-Varnish-Grace
X-UPSTREAM-Address
X-Endurance-Cache-Level
X-Hl-Ver
X-RN-RSRV
X-ES-SERVER
X-Handled-By
Meta-Geo
X-Uri
X-MP-GENERATED-AT
Retry-After
Cache-Tv-Group
X-Backend-Name
Cache-Status
X-Cache-Server
X-Ratelimit-Limit
X-Format
Fastly-SSL
X-Pubstack
X-NYM-Debug-Backend
X-OCL
X-Section
X-Be
X-PCL
X-Labrador-Cache-Channel
X-Storage
X-Access
X-PHP-Host
Decoy-Debug-Key
Decoy-Debug-Status
Decoy-Debug-TTL
X-Origin-Hint
Webcakes-App-Name
X-Origin-Date
X-Proto
Country
X-R9-Blue-Green-Version
X-ApacheServer
X-Redis-Cache
TWC-Privacy
X-No-Session
X-PERF
X-Human
X-Web-Node
TWC-Connection-Speed
TWC-Device-Class
X-LJ-Flow-ID
X-Sql-Duration-Ms
TWC-Locale-Group
Property-Id
X-Soup
X-WA-Info
X-Via-Fastly
TWC-GeoIP-LatLong
X-VWS-Id
X-LAGOON
Protected
TWC-GeoIP-Country
Mn-Server-Ip
X-Sql-Count
X-AWS-Id
Cache-Name
Apigw-Requestid
Webcakes-Region
X-BYPASS-REASON
X-UA-Device-Type
Webcakes-App-Version
X-Varnishpool
X-Server-W
X-Locale
X-ProxyCache-Key
X-ProxyCache-Status
Frame-Options
X-Site-Version
X-Loop
X-Hyper-Cache
X-Varnish-Server
Selected-Fe
Azure-Version
X-SayCDN-TTL
X-FW-Version
X-Hosted-By
X-Timing-Wait
X-Say-TTL
X-Status
X-Xfnlog-Site
X-S-Maxage
X-Cache-TTL-Remaining
X-Request-Time
X-FB-TRIP-ID
X-Zipkin-Id
X-TNCMS
X-Proxy-Build
X-Proxied
X-Routing-Service
Azure-SlotName
Azure-InstanceId
Azure-RegionName
Azure-SiteName
X-Say-Cacheable
X-Alternate-Cache-Key
X-ShardId
X-Storefront-Renderer-Rendered
X-ShopId
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Node-Name
X-Forwarded-Host
X-Info
X-CCM
X-AIR-PT
X-Cluster
X-TT-LOGID
X-GG-Cache-Date
X-Cache-Grace
X-Is-Bot
X-Rendered-As
X-TA-CDN-Provider
X-SRV
X-Revision
X-Qloud-Router
AMP-Access-Control-Allow-Source-Origin
X-Microcachable
Uber-Trace-Id
X-Cache-Enabled
X-Proxy-Cache-Status
S-Cnection
X-Content-Age
X-NWS-UUID-VERIFY
X-Dc
X-Azure-Ref
X-Via-CDN
Cache-Hits
X-Platform
X-Backend-Host
X-CSRF-Token
X-Varnish-Ttl
Amp-Access-Control-Allow-Source-Origin
X-Country-Code-Real
X-FTR-Backend
X-FTR-Backend-Server
X-Aspnetmvc-Version
X-FTR-Realm
X-FTR-DC
X-Ratelimit-Remaining
X-FTR-Cache-Status
X-FTR-Balancer
X-Cache-Host
X-Detected-As
X-Amz-Meta-S3cmd-Attrs
Akamai-GRN
X-Amzn-RequestId
X-Amzn-Remapped-Content-Length
X-Amz-Apigw-Id
X-App-Version
X-ATG-Version
ServedBy
X-EdgeConnect-Cache-Status
X-B3-SpanId
X-Trace-Id
X-Cache-PHP
X-Cache-NGX
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-RCS-CacheZone
X-Debug-Cache
X-Oss-Object-Type
X-CS
X-Varnish-Hostname
X-FTR-Expires
SD-X-WS
X-Time-Microsecs
X-ID
X-Air-Hostname
Tracecode
X-Correlation-ID
X-Nc
X-BCube-Filmed-By
HostName
X-ServerID
X-Akamai-Transformed
DB-Nickname
X-Tb
X-Adobe-Source
X-NewRelic-App-Data
X-Ms-Version
Backend
X-Ms-Request-Id
X-PBS-Appsvrname
X-Magnolia-Registration
X-Owner
X-PAYTM-SRV-ID
Machine
Mobile-Detection-Method
Meta-Geo-Continent
MD5-Digest
X-Processor
X-External-Request-Id
X-CF-Lambda-Version
Fastcgi-X-Cache-Version
BehaviorPad-Version
Expiry
X-NAPM-TraceId
DCR-Decision-By
DCR-Processing-Time-Ms
X-Connection-Hash
X-Origin-CC
X-Origin-TTL
X-Level-Front-Cache
X-CF-Lambda-Fn
X-Destination
X-D
X-Location
X-Cache-NE
X-Rewrite-Enabled
X-A-Dam
X-A-Ccd
X-Backend-TTL
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
X-A-Dcw
X-Trv-Group
X-A-Dgt
X-Generated-On
X-A
X-VG-WebServer
X-Vdms-Version
X-VG-WebCache
X-TX-ID
X-Vdms-Path
X-DynaTrace-JS-Agent
Xc-Version
T-Server
X-Generation-Time
Rendered-Blocks
X-A-Wwc
X-S-Cookie
X-ScT
X-Aed
X-S
X-Rojux
Odigeo-Trace-Id
X-Request-UUID
X-From
X-Session-Fingerprint
X-ARC
X-SRCache-Key
X-B-Cookie
X-Application
X-Unique-Id
X-Cache-Var
X-Cache-Var-Map
X-Fastly-Cache
X-FC-Vary-Parameters
CacheControlHeader
X-Generated-In
AKAMAI
Arc-Version
X-Varnish-Beresp-Grace
X-Geo-Header
Magicmarker
X-Azure-Ref-OriginShield
Release
PB-RID
PB-PID
Path
Server-Host
Thinkindot-CacheControl
V-Age
UCS
Thinkindot-Control
Thinkindot-CacheControl-Type
Pagetype
On-Server
Fastly-Backend-Name
X-Core-Value
Content-Disposition
Cf-Device-Type
X-Cms-Context
Gh-Request-Id
X-Bip
Locid
X-Cache-Bucket
Host-ID
X-Developers
X-Is-Gdpr
X-Sucuri-ID
X-Tumblr-Pixel-3
X-Reqid
X-Micro-Cache
X-Irp-Debug
X-TrackingId
X-Thinkindot-L3
X-Varnish-Cache-Hits
X-CACHE-KEY
X-Mvc-Supplant-Cachable
X-Thanos
X-Policy
X-JWT-State
X-OVcl-Cache
X-OVcl
X-Has-Esi
X-B3-Traceid
X-HS-Content-Campaign-Id
X-GeoIP-City
X-Unique-ID
X-GEO
User-Cache-Control
Who
X-Request-Host
X-Cache-Info
X-Request-URI
X-Branch-Name
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Block-Status
X-Platform-Server
X-Ratelimit-Reset
X-Backend-State
X-SVT-ORM-RULES
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
Wxu-Next-Region
X-Varnish-Remaining-TTL
Wxu-Next-Hostname
Wxu-Next-Commit
X-VG-TLSProxy
X-VarnishDD-TTL
X-VServer
Cache-Host
Ssr
X-Skip-Cache
X-SIPLIST1
X-Cache-Debug
X-SVT-ORM-VERSION
X-Variation
X-Var-Ttl
X-User
X-Scheme
X-CGP
X-Eu-Site
X-Wikidot-Backend
X-Li-Fabric
X-Fastly-Backend
X-Esi-Check
X-Li-Pop
X-Dispatcher-Server
X-DPWN-IS-SECURE
X-WADP-Cache
X-IP
X-Wikidot-Static-Cache
X-HN
X-Gzip
X-GoCache-CacheStatus
X-Hnp-Log
X-Generated-By
X-Fetched-On
X-Fmm-Version
X-Gen-Mode
X-Device-Os
X-LI-UUID
X-Clientip
X-Origin
X-Old-Content-Length
X-NU-AKA-ACS-Version
X-Clara-WADP
X-GeoIP
X-Cache-Tags
X-Origin-Response-Time
X-Origin-Expires
X-Node-Id
X-Nginx-Cache-Key
X-DefHash
Web-Mar-Node
X-Developer
X-DefElseHash
X-Method
X-Csrf-Jwt
X-Swa-Ws
X-CUA
X-Cache-Id
X-Envoy-Decorator-Operation
Adler-Geo
Ha-Gx-Prefs
Fastly-SWR
Fastly-SIE
Esi-Enabled
HA-Ipaddr
C-Via
L5d-Success-Class
Is-Eu
Instruction
Apple-News-Services-Handled
DSUID
Country-Code
CDN-EdgeStorageId
CDN-CachedAt
CDN-Cache
CDCHOST
CDN-PullZone
CDN-RequestCountryCode
X-Varnish-Beresp-Ttl
Cf-Bgj
CDN-Uid
CDN-RequestId
Vix-Hermes-Req-Id
IsBot
Apple-News-Services-Host
Server-Ext
NM-Fastcgi-Cache
Sever-Int
Platform
X-Cdn-Forward
Server-Hostname
SR-User-Adfree
PFcat
Location
True-Client-Country-4JS
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
NGX
X-EC-Lua
X-APP-VERSION
X-Varnish-Beresp-Status
X-RateLimit-Limit
X-Gamma-Serve
X-Aicache-OS
X-Varnish-Hits
Rt-Fastcgi-Cache
L
X-Slack-Backend
Origin
X-LB-ID
X-Hash
X-CLOUD-TRACE-CONTEXT
X-Matched-Rule
X-Varnish-Url
Lfy
X-Cache-Backend
Fastly-Drupal-HTML
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Mvc-Supplant-OutputCached
X-Loc
Geo-Info
Filterid
X-Epic-Correlation-Id
X-Via-Popv
X-Via-Popn
X-NCache
X-Via-Poph
CloudFront-Viewer-Country
Pics-Label
Sid
X-Planisys-CDN-Rules
Pramga
X-Cdn-Origin
X-Planisys-CDN-Cache
X-Refresh
X-Sn-Servicetimems
X-PF-Uncompressing
X-Cache-Expires
X-Planisys-CDN-TTL
X-Servername
Url
X-Cache-Date
X-Core-Mission
Req-Svc-Chain
Cmsid
X-Esi
Cmstype
X-Tb-Optimization-Total-Bytes-Saved
X-TraceId
X-Served-From
NGB
Kp-EeAlive
X-Request-Start
Tcn
Svr
X-DC
X-Error
MIME-Version
X-FireWall-Protection
Cache-Key
A
Viewtype
VivaBuild
M-TraceId
Source
X-Varnish-Cacheable
X-Webkit-CSP-Report-Only
Server-ID
X-Response-By
Cross-Origin-Opener-Policy
X-Srv
Arc-Country
X-Vgn-Hpd-Reason
X-NC
Xkeyi7
X-Proxy-Cachei7
X-HS-Status
X-Servedbyhost
X-Wa
Geoip-Latitude
GeoIp-Country-Code
X-Air-Source
TDXMobile
X-Vcl-Version
X-NGENIX-Cache
X-SaId
HitType
X-B3-Spanid
X-PHP-Backend
SID
X-JoinUs
Server-Ttl
X-BBXSRF
N-Cache
X-CDN-Forward
Content-Secure-Policy
NtCoent-Length
X-Geo
S-Rt
X-Erf-Stays-Bingo-Pdp-Web
X-Cache-Remote
X-Edge-Location
X-Service
X-Cache-2
Resin-Trace
X-LI-Proto
X-Vc
X-Internal-Host
X-LiteSpeed-Cache-Control
CACHE
DataCenter
X-Cc-Req-Id
X-Varnish-Authentication
X-Contensis-Viewer-Groups
X-Li-Proto
X-Cc-Via
X-Cache-ASPX
D-Cc-Upstream
X-HOST
Cteonnt-Length
X-Extlb
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
Ohc-File-Size
X-Viewer-Country
Hostname
Request-ID
X-Svr
Cross-Origin-Window-Policy
X-RAMCache
X-Forwarded-Site
FSS-Cache
X-Sucuri-Cache
X-VCL-Version
X-CCDN-CacheTTL
X-Host-Name
X-UA
XServer
X-HostName
X-DSS
X-RPS
X-ServedByHost
X-RSL
X-RPM
X-DW
X-DI
X-TIM-N
X-Via-NSCOPI
X-Bc-Bl
GeoIP-Latitude
GeoIP-Country-Code
X-DB
X-Newrelic-Synthetics
X-Server-IP
X-WA
X-FORWARDED-FOR
X-Accel-Expires-Debug
X-Cs
X-Date
X-API-Version
We-Hiring
X-PJAX-URL
X-VC-Cache
Memcached
X-App
X-Gdpr
X-FPC
X-Cache-Config
LB
X-Proxy-Upstream
Mail-Subject
Surrogated-Key
X-VC
CF-Cached-On
X-Nyt-Route
X-Req
X-Origin-Time
X-Check-Cacheable
X-Kraken-Loop-Name
ProcessTime
X-Server-Lifecycle-Phase
X-SN
X-Action
X-ZONE
X-RateLimit-Limit-Second
X-Kraken-Routeconfig-Destination
X-Dynatrace-Js-Agent
X-Instrumentation
X-NodeID
Cache-Provider
X-RateLimit-Remaining-Second
Env
Ohc-Cache-HIT
X-CF-Powered-By
Upgrade-Insecure-Requests
Server-Id
X-Edge-Location-Klb
X-Oss-Cdn-Auth
X-SB
X-Region-Sid
X-Sigma-Backend
X-APP
X-Men
X-Fpc
X-Rocket-Build-Number
X-Air-Trace-Id
X-Sigma
X-Webstats-RespID
X-URL
X-Swift-Error
X-Provided-By
W
X-MSEdge-Flight
Mime-Version
X-MSEdge-Features
Time
CPC-Age
X-Depends-On
VNS-Cache
Memory
VNS-Age
X-SD-PageType
CPC-Cache
Srv
X-Cdn-Request-ID
X-UnsetCookies
CDN
X-Dw-Trace-Id
X-Ftr-Cache-Host
X-BACKEND-TTL
X-Render-Time
Cdn
X-TIME
X-CSRF-TOKEN
X-BBC-Edge-Cache-Status
X-Zone
X-Client-Ip
X-Flog
X-Fastly-Request-Id
X-Fastly-Backend-Reqs
X-NGINX-Cache
EpKe-Alive
X-ABtesting
Dnion-Transfer-Encoding
X-Parent-Response-Time
X-Pf-Uncompressing
X-Hello
X-Akamai-Pragma-Client-IP
X-Dynatrace
X-SERVER-NAME
X-Pad
State
Media-Length
My-App
Fastcgi-Cache-TTL
X-FTR-Cache-Host
X-ServerName
X-Acquia-Site
Processtime
X-Cache-Tag
Proxy-Connection
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-Presslabs-Stats
X-Oracle-DMS-ECID
X-Worker
X-Auto-Login
Vha6-Origin
X-Acquia-Purge-Tags
Datacenter
X-Ua
X-Via-PopN
X-Via-PopH
X-BBC-Origin-Response-Status
X-Via-PopV
X-Cluster-Node
PICS-Label
Epwk-X-Cache
X-LiteSpeed-Tag
X-Minions-Version
X-Snapshot-Date
X-CACHE-AGE
Cf-Ipcountry
X-ElasticPress-Search
X-IN-APIGATEWAY
X-Ms-Meta-Originalurl
Xet-Cookie
X-Vcache
X-Varnish-URL
X-IN-APIGATEWAYSSL
X-Akamai-ERPolicy
X-Ms-Meta-Staticbatchstarttime
X-Akamai-ERRuleID
X-Varnish-Beresp-TTL
X-Request-URL
X-MiniProfiler-Ids
X-Lb-Id
X-ElasticPress-Query
X-Tx-Id
X-Air-Pt
CountryCode
X-Apw-Access-Action
X-Apw-Access-Object
Phost
X-B3-Parentspanid
Content-Style-Type
Ohc-Response-Time
X-Apw-Access-Token
X-Apw-Hits
Warning
X-Mg-Request-UUID
X-Mg-Request-Id
X-Traceid
X-Cache-Status-Check
Content-Script-Type
X-Litespeed-Cache-Control
X-Tid
OT-Force-Account-Verify
Inserted-Into-Cache-At
X-Storefront-Renderer-Verified
X-C
Environment
X-Amz-Meta-Cb-Modifiedtime
X-Redis-Duration-Ms
URI
X-Redis-Count
X-Debug-Cache-Store
X-Debug-Cache-Fetch
NnCoection