Threat Level: green Handler on Duty: Russ McRee

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
Link
X-XSS-Protection
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-UA-Compatible
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
X-Xss-Protection
Access-Control-Allow-Credentials
X-Runtime
X-AspNet-Version
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Request-ID
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Content-Security-Policy
X-Ua-Compatible
Content-Encoding
X-CDN
X-Envoy-Upstream-Service-Time
Status
Feature-Policy
X-AspNetMvc-Version
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Access-Control-Max-Age
X-Via
Upgrade
Keep-Alive
X-Ws-Request-Id
X-Age
X-Turbo-Charged-By
X-AH-Environment
X-Robots-Tag
Request-Context
X-Proxy-Cache
EagleId
X-Cache-Group
Server-Timing
X-Backend
X-Hacker
X-Amz-Request-Id
Report-To
X-Server
Host-Header
X-Amz-Id-2
X-Server-Powered-By
Grace
X-Nginx-Cache-Status
X-UA-Device
X-LiteSpeed-Cache
X-Rq
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Page-Speed
X-Dns-Prefetch-Control
Cf-Railgun
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
NEL
X-Amz-Version-Id
X-OneAgent-JS-Injection
X-Cache-Spec
X-WebKit-CSP
Xkey
Allow
X-Backend-Server
X-Device
X-CST
X-Host
X-Vhost
EagleEye-TraceId
X-Server-Id
X-ASPNET-VERSION
Request-Id
Surrogate-Control
X-Dispatcher
X-Node
Accept-CH
Content-Location
X-Response-Time
Accept-CH-Lifetime
X-Akam-SW-Version
X-Ruxit-JS-Agent
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
P3p
X-Ac
X-Application-Context
X-Template
X-Language
X-Country
X-Cache-Lookup
X-Readtime
X-Cloud-Trace-Context
X-Mod-Pagespeed
MS-Author-Via
X-B3-TraceId
X-Origin-Cache
Rating
X-Cnection
X-MS-InvokeApp
X-HW
X-Url
X-TtlSet
X-PC
X-Kinja-Server-Push
X-Vname
X-ORACLE-DMS-ECID
Accept-Ch
X-Clacks-Overhead
X-GitHub-Request-Id
Edge-Control
X-FastCGI-Cache
X-ESI
X-Trace
Accept-Ch-Lifetime
X-Sol
Pagespeed
Display
X-Middleton-Response
Response
X-Middleton-Display
X-Content-Type
X-Vcap-Request-Id
X-D2id
X-Kinja-Server
X-GoogleNews-Bot
X-Cdn-Fetch
X-Use-Magma
X-Exp-Id
X-Exp-Variant
X-Kinja
X-Kinja-Build
X-Kinja-Revision
Arr-Disable-Session-Affinity
Verso
X-Goog-Hash
X-Buckets
X-Rack-Cache
X-Country-Code
X-Server-Name
Service-Worker-Allowed
X-Navigation-Version
X-ORACLE-DMS-RID
X-Abt-Application-Version
X-VARITI-CCR
X-Amz-Rid
X-Oneagent-Js-Injection
X-Powered-By-Plesk
X-Varnish-TTL
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-Fastly-Request-ID
X-Cache-TTL
X-Client-IP
X-Webkit-CSP
SPRequestGuid
X-SharePointHealthScore
X-Release
X-MSEdge-Ref
Fastly-Restarts
SPIisLatency
SPRequestDuration
X-Dw-Request-Base-Id
X-Element-Page-Cache
X-Cached
X-NF-Request-ID
Public-Key-Pins
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
RTSS
X-Ttl
AR-Request-ID
AR-ATIME
Ar-Sid
AR-CACHE
AR-PoweredBy
Access-Control-Request-Method
X-Edge
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-TTL
X-Origin-Upstream-Status
X-LLID
X-Px
X-Powered-CMS
X-Ezoic-Cdn
Fusion-Component-Id
Fusion-Content-Id
Fusion-Content-Source
Fusion-Deployment-Id
Fusion-Source
Fusion-Template-Id
X-Upstream
Content-MD5
X-HP-Webp
X-Jurisdiction
Cache-Tag
X-MCACHE
X-Mid
X-ECACHE
S
X-Mg-S
X-Recruiting
X-Amz-Server-Side-Encryption
X-Content-Digest
Charset
X-Version
X-PressLabs-Stats
TCN
X-Pinterest-Direct
Fastcgi-Cache
MicrosoftSharePointTeamServices
X-T
Front-End-Https
X-Kinsta-Cache
X-Content-Security-Policy-Report-Only
X-Debug
X-Id
Filters
X-Grace
Cache-Tags
Edge-Cache-Tag
Server-Node
X-Accel-Expires
X-Forwarded-Proto
X-Logged-In
X-Forwarded-For
X-Correlation-Id
X-Amzn-Trace-Id
Nginx-Cache
X-Yandex-Sdch-Disable
Server-Name
X-DynaTrace
X-Kong-Proxy-Latency
Surrogate-Key
X-Kong-Upstream-Latency
TP-L2-Cache
X-Varnish-Age
TP-Cache
X-B3-Sampled
X-Request-Received
X-Request-Processing-Time
X-Request-Handler-Origin-Region
X-Microsite
X-XRDS-Location
X-Ser
X-Hits
X-Shield-Request-Id
X-DIS-Request-ID
X-Activity-Id
X-Az
X-AppVersion
X-Amz-Replication-Status
X-Server-ID
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Content-Id
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Generation
X-F-Cache
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Cache-Key
Powered-By-ChinaCache
X-Origin-Server
Accept-Charset
X-Git-Hash
X-XRDS-LOCATION
X-Litespeed-Cache
X-FTR-Request-ID
X-Geo-Country
X-Respond-Thread
X-LB-Cache
Section-Io-Cache
X-Rid
X-Hostname
X-Upgrade-Enabled
Cache
X-DataDome
X-Frontend
Alternate-Protocol
Access-Control-Allow-Method
X-Cache-Age
X-Mobile-URL
Host
Cleartype
Paypal-Debug-Id
MS-CV
X-IPLB-Instance
X-Seen-By
X-Ruxit-Js-Agent
X-Content-Options
X-Varnish-Backend
Healthy
X-AOL-HN
X-Type
X-App-Environment
X-Whom
X-WebKit-CSP-Report-Only
X-Aspnetmvc-Version
Payment
X-VCache
ServerID
X-Flags
X-Route-Name
X-TT
X-Request-Guid
X-Providence-Cookie
X-Is-Crawler
X-Aspnet-Duration-Ms
X-Cache-Action
X-Debug-Info
X-B-Cache
X-Time
X-Jobs
X-Page-Id
X-Signature
Fastcgi-Useragent
X-NWS-LOG-UUID
X-Source
X-Load-Cache
X-N
X-Mobile
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Daa-Tunnel
X-FB-Debug
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Via-JSL
X-Cached-By
X-RateLimit-Remaining
X-Akamai-Edgescape
Nel
Version
X-Cache-Operation
X-Cache-Rule
Refresh
Viewport
X-Accel-Buffering
X-Original-Request-Id
X-Rule
X-Response-Served-From
DC
X-Proxy
X-Framework
X-Drupal-Cache-Tags
X-RemovedCookies
X-Cacheable-TTL
X-Zen-Fury
DynaTrace
X-RTag
X-Wix-Request-Id
X-ProcessESI
Ms-Operation-Id
X-Fastcgi-Cache
Access-Control-Request-Headers
X-Contextid
X-Real-IP
Realpath
X-Instance
X-Cache-Time
X-Tt-Trace-Host
GEO-INFO
X-UUID
X-HTML-Minification-Powered-By
X-Tt-Trace-Tag
X-Distributor
X-Drupal-Cache-Contexts
X-Yottaa-Optimizations
Node
X-Yottaa-Metrics
X-Page-View
X-Region
Countrycode
X-Cache-Expired-At
Referer-Policy
Eomportal-Instance
X-FW-Dynamic
X-FW-Hash
X-FW-Static
X-B
X-FW-Server
X-FW-Serve
X-FW-Type
X-Cluster-Name
X-L-Path
X-Varnish-Ttl
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Environment-Context
X-Cache-Control
X-Tumblr-Pixel-1
X-G
Liferay-Portal
X-Tumblr-Pixel-0
X-Content-Powered-By
X-Tumblr-User
X-Tumblr-Pixel
X-Cache-Hit
X-IPS-LoggedIn
X-Node-Name
X-User-Agent
X-Ratelimit-Limit
Server-Info
Webserver
X-Tumblr-Pixel-2
X-App-Server
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Io-Id
Section-Origin-Responded
From-Origin
X-FireWall-Port
X-Pass-Why
Ec-Rule-Version
Protected
X-Protected-By
X-Amz-Meta-S3cmd-Attrs
X-Cache-Server
CF-IPCountry
X-Revision
X-Backend-Name
Frame-Options
X-Www-Served-By
X-Handled-By
X-Ratelimit-Remaining
X-Mode
X-Hl-Ver
Meta-Geo
X-UPSTREAM-Address
X-ES-SERVER
X-Hyper-Cache
SRV
X-Endurance-Cache-Level
X-RN-RSRV
X-FB-TRIP-ID
X-Site-Version
X-Soup
Cache-Status
X-Locale
Xserver
Cache-Tv-Group
Country
X-Be
X-Storage
X-Varnishpool
X-NYM-Debug-Backend
X-Web-Node
X-Human
Retry-After
X-Cache-Grace
X-Forwarded-Host
X-Proxy-Build
X-TT-LOGID
X-ProxyCache-Status
X-ProxyCache-Key
X-Pubstack
Decoy-Debug-TTL
X-Redis-Cache
X-Uri
X-Timing-Wait
X-BYPASS-REASON
X-Proto
X-UA-Device-Type
Selected-Fe
Fastly-SSL
X-PHP-Host
Azure-SlotName
Azure-RegionName
Azure-SiteName
X-Adobe-Loc
X-Labrador-Cache-Channel
Azure-Version
Cache-Name
Decoy-Debug-Key
X-Adobe-Content
X-Origin-Date
Decoy-Debug-Status
Azure-InstanceId
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Connection-Speed
X-Request-Time
X-WA-Info
Property-Id
TWC-Locale-Group
X-Via-Fastly
TWC-Device-Class
X-Server-W
X-PCL
X-AIR-PT
X-TNCMS
X-Origin-Hint
X-Hosted-By
X-Loop
X-No-Session
X-OCL
X-S-Maxage
X-Say-Cacheable
X-Sql-Duration-Ms
Webcakes-App-Version
Webcakes-App-Name
TWC-Privacy
X-Sql-Count
Webcakes-Region
X-Say-TTL
X-SayCDN-TTL
X-Format
X-LAGOON
X-FW-Version
X-LJ-Flow-ID
X-R9-Blue-Green-Version
X-Section
X-VWS-Id
X-AWS-Id
X-MP-GENERATED-AT
X-Access
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
X-PERF
X-Cluster
X-Alternate-Cache-Key
X-ApacheServer
X-ShardId
X-ShopId
X-Storefront-Renderer-Rendered
X-Via-CDN
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Shopify-Stage
X-Status
X-Zipkin-Id
X-Routing-Service
Mn-Server-Ip
X-Qloud-Router
X-Proxied
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-DC
X-CCM
X-FTR-Backend-Server
X-FTR-Backend
X-Cache-TTL-Remaining
X-Rendered-As
X-Is-Bot
X-Country-Code-Real
X-FTR-Realm
S-Cnection
X-Nginx-Cache
X-Xfnlog-Site
Cache-Hits
X-Dc
X-Device-Type
AMP-Access-Control-Allow-Source-Origin
X-FTR-Expires
X-Debug-IsPreview
X-Debug-IsConnected
X-SRV
X-Unique-Id
X-Info
X-Oracle-Dms-Rid
X-Detected-As
Apigw-Requestid
X-Air-Hostname
X-Cache-Host
X-Cache-Var-Map
X-Cache-Var
X-Cdn
X-Amzn-RequestId
X-Varnish-Grace
X-EdgeConnect-Cache-Status
X-Amz-Apigw-Id
X-Amzn-Remapped-Content-Length
X-Microcachable
X-Cache-Enabled
X-Content-Age
X-Platform
X-Varnish-Server
X-GEO
SD-X-WS
X-GG-Cache-Date
X-DynaTrace-JS-Agent
X-Azure-Ref
Tracecode
X-Dynatrace
X-Time-Microsecs
Uber-Trace-Id
X-Backend-Host
X-APP-VERSION
X-Backend-TTL
X-ServerID
X-Proxy-Cache-Status
X-CSRF-Token
X-Cache-Backend
Amp-Access-Control-Allow-Source-Origin
X-Erf-Stays-Bingo-Pdp-Web
X-Tb
X-ATG-Version
Backend
X-TA-CDN-Provider
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Oss-Storage-Class
X-Oss-Server-Time
X-Oss-Request-Id
Akamai-GRN
DSUID
X-Trace-Id
X-NWS-UUID-VERIFY
X-BCube-Filmed-By
X-NewRelic-App-Data
X-Akamai-Transformed
X-Varnish-Hostname
Arc-Version
X-Correlation-ID
ServedBy
X-Sucuri-ID
PB-PID
PB-RID
X-A-Dam
X-A-Dcw
Xc-Version
X-Generation-Time
X-RCS-CacheZone
X-GeoIP-City
X-Application
X-Device-Os
X-Connection-Hash
X-Cache-NGX
X-B-Cookie
X-ARC
X-Varnish-Cache-Hits
X-D
X-Destination
X-External-Request-Id
X-Aed
X-A-Dgt
BehaviorPad-Version
X-Cache-PHP
X-From
X-Fetched-On
X-Magnolia-Registration
X-A-Wwc
X-Generated-On
X-Vdms-Version
X-S
X-Rojux
X-S-Cookie
X-CF-Lambda-Version
X-ScT
X-Rewrite-Enabled
X-Request-UUID
DCR-Processing-Time-Ms
X-Processor
Expiry
Fastcgi-X-Cache-Version
Lfy
X-Session-Fingerprint
X-Thinkindot-L3
X-CF-Lambda-Fn
Instruction
X-Trv-Group
Mobile-Detection-Method
Path
X-SRCache-Key
Meta-Geo-Continent
Rendered-Blocks
Release
Pramga
X-A-Ccd
X-PBS-Appsvrname
Thinkindot-CacheControl-Type
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
MD5-Digest
Thinkindot-Control
X-Matched-Rule
X-A
Machine
X-Level-Front-Cache
X-Location
X-VG-WebCache
X-VG-WebServer
X-PAYTM-SRV-ID
SR-User-Adfree
X-Vdms-Path
X-Origin-TTL
Odigeo-Trace-Id
Thinkindot-CacheControl
T-Server
X-Origin-CC
DCR-Decision-By
X-Debug-Cache
X-Origin-Response-Time
X-Cache-Date
X-Cache-NE
Cf-Device-Type
Fastly-Backend-Name
Ssr
Gh-Request-Id
Pagetype
Host-ID
UCS
CacheControlHeader
X-Azure-Ref-OriginShield
X-Bip
AKAMAI
C-Via
Cache-Host
X-Cache-Bucket
X-Is-Gdpr
X-Skip-Cache
X-Cdn-Origin
X-Sn-Servicetimems
X-FC-Vary-Parameters
X-SVT-ORM-RULES
X-Geo-Header
X-GeoIP
X-Irp-Debug
X-JWT-State
X-Mvc-Supplant-Cachable
X-HS-Content-Campaign-Id
X-Has-Esi
X-SVT-ORM-VERSION
X-Swa-Ws
X-OVcl-Cache
X-Ms-Version
X-Reqid
X-Owner
X-VServer
X-Ms-Request-Id
X-OVcl
X-Node-Id
X-Thanos
X-TrackingId
X-Tumblr-Pixel-3
X-Micro-Cache
HostName
X-Adobe-Source
X-Var-Ttl
Server-Ext
X-Varnish-Hits
X-Request-Host
NGX
X-Policy
On-Server
X-Scheme
X-User
X-Nginx-Cache-Key
X-Backend-State
X-Csrf-Jwt
X-CUA
X-Core-Value
X-Cache-Info
X-CGP
X-Clientip
X-Cms-Context
X-Developer
X-Eu-Site
X-Origin-Expires
Sever-Int
Server-Hostname
X-IP
X-Generated-In
X-Fastly-Backend
X-Fastly-Cache
X-Generated-By
Server-Host
X-Cache-Tags
X-B3-Traceid
Content-Disposition
DB-Nickname
Ha-Gx-Prefs
CloudFront-Viewer-Country
X-TX-ID
Location
L5d-Success-Class
HA-Ipaddr
X-B3-SpanId
User-Cache-Control
Adler-Geo
X-Clara-WADP
X-Esi-Check
X-Envoy-Decorator-Operation
X-DPWN-IS-SECURE
X-Wikidot-Backend
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-Origin
X-Gen-Mode
X-LI-UUID
X-Loc
X-Variation
X-Fmm-Version
X-WADP-Cache
X-Varnish-Beresp-Grace
X-Branch-Name
X-Block-Status
X-Old-Content-Length
X-NU-AKA-ACS-Version
X-Cache-Expires
X-DefHash
X-Varnish-Remaining-TTL
X-Developers
X-Dispatcher-Server
X-VarnishDD-TTL
X-Cache-Id
X-NAPM-TraceId
X-Cdn-Forward
X-DefElseHash
Wxu-Next-Commit
X-Slack-Backend
PFcat
X-SIPLIST1
Platform
X-Ratelimit-Reset
Wxu-Next-Region
Fastly-SWR
Origin
Is-Eu
X-Platform-Server
Magicmarker
L
X-Servername
NM-Fastcgi-Cache
IsBot
Rt-Fastcgi-Cache
Fastly-SIE
X-GoCache-CacheStatus
X-Rebelmouse-Cache-Control
Locid
V-Age
X-Wikidot-Static-Cache
X-Li-Pop
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Gzip
X-Hnp-Log
X-Rebelmouse-Surrogate-Control
X-HN
X-Hash
X-Li-Fabric
Wxu-Next-Hostname
Web-Mar-Node
X-ID
X-Method
X-Core-Mission
X-VG-TLSProxy
X-Varnish-Beresp-Ttl
CDN-RequestId
CDN-RequestCountryCode
CDN-Uid
CDN-EdgeStorageId
X-Cache-Remote
CDN-PullZone
True-Client-Country-4JS
Vix-Hermes-Req-Id
CDN-CachedAt
CDN-Cache
CDCHOST
X-Request-Start
Cf-Bgj
Fastly-Drupal-HTML
X-Gamma-Serve
X-Varnish-Beresp-Status
X-Request-URI
X-App-Version
X-Cache-Debug
Apple-News-Services-Parsed-Url
X-NC
Apple-News-Services-Request-Url
Apple-News-Services-Host
Apple-News-Services-Handled
X-EC-Lua
Sid
X-PF-Uncompressing
X-Mvc-Supplant-OutputCached
X-CS
Url
X-NCache
X-Refresh
X-LB-ID
X-Aicache-OS
X-CACHE-GROUP
S-Rt
X-Varnish-Cacheable
X-Varnish-Url
X-Host-Name
X-Response-By
X-B3-Spanid
X-Proxy-Cachei7
Esi-Enabled
Xkeyi7
X-Via-Poph
X-Via-Popn
X-Via-Popv
X-CACHE-KEY
N-Cache
CACHE
X-Tb-Optimization-Total-Bytes-Saved
X-FireWall-Protection
X-BBXSRF
Pics-Label
X-Nc
Cross-Origin-Window-Policy
Ohc-File-Size
Who
X-Epic-Correlation-Id
X-Cache-2
Content-Secure-Policy
X-Sucuri-Cache
Country-Code
X-TraceId
Req-Svc-Chain
D-Cc-Upstream
Source
X-Error
X-Cache-ASPX
X-Cc-Req-Id
X-Contensis-Viewer-Groups
X-Cc-Via
X-Varnish-Authentication
X-Webkit-Csp
X-Srv
Cteonnt-Length
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
Server-Ttl
X-CDN-Forward
X-Unique-ID
X-Cs
X-Svr
GeoIp-Country-Code
Geoip-Latitude
X-Webkit-CSP-Report-Only
X-Server-IP
HitType
MIME-Version
X-Servedbyhost
X-Wa
X-DC
X-RateLimit-Limit
Cmsid
Cmstype
X-Cache-Config
X-FPC
X-Gdpr
X-HS-Status
X-API-Version
X-Origin-Time
X-Nyt-Route
Kp-EeAlive
X-URL
X-SN
X-Served-From
X-LiteSpeed-Cache-Control
Svr
X-VC
Ohc-Cache-HIT
Hostname
Geo-Info
X-Webstats-RespID
X-NGINX-Cache
A
Cache-Key
VivaBuild
X-Esi
X-NodeID
X-LI-Proto
X-Vcl-Version
X-SB
Viewtype
X-VCL-Version
M-TraceId
Server-ID
X-Li-Proto
Server-Id
X-Check-Cacheable
Resin-Trace
X-Vgn-Hpd-Reason
X-RAMCache
X-SD-PageType
XServer
X-TIME
Filterid
X-HOST
NtCoent-Length
SID
Arc-Country
Request-ID
X-Render-Time
Srv
X-Air-Source
X-Viewer-Country
Cross-Origin-Opener-Policy
TDXMobile
X-UA
X-Ua
X-RPM
X-DSS
X-DB
EpKe-Alive
X-RPS
X-DW
X-Internal-Host
X-CCDN-Origin-Time
X-CCDN-CacheTTL
Cache-Provider
X-Hcs-Proxy-Type
X-TIM-N
X-RSL
X-BBC-Edge-Cache-Status
X-DI
X-ServedByHost
Mime-Version
X-WA
GeoIP-Country-Code
GeoIP-Latitude
X-Fastly-Request-Id
X-CF-Powered-By
NGB
X-Worker
X-Vc
X-Auto-Login
X-HostName
Upgrade-Insecure-Requests
X-App
ProcessTime
Processtime
X-Ftr-Cache-Host
X-Action
X-Service
X-FTR-Cache-Host
X-CSRF-TOKEN
X-Newrelic-Synthetics
X-Oss-Cdn-Auth
Tcn
CDN
X-Fpc
X-Cluster-Node
X-SaId
X-PHP-Backend
DataCenter
X-JoinUs
X-Dynatrace-Js-Agent
X-NGENIX-Cache
X-CLOUD-TRACE-CONTEXT
Proxy-Connection
X-Via-NSCOPI
X-Extlb
Datacenter
X-FORWARDED-FOR
X-BBC-Origin-Response-Status
X-Parent-Response-Time
X-Geo
X-Forwarded-Site
FSS-Cache
CF-Cached-On
X-Edge-Location
X-HITS
X-Cdn-Request-ID
PICS-Label
Cdn
X-Provided-By
X-Dw-Trace-Id
X-Swift-Error
X-MSEdge-Flight
X-MSEdge-Features
X-BACKEND-TTL
X-Fastly-Backend-Reqs
X-CACHE-AGE
X-Client-Ip
X-Bc-Bl
X-Accel-Expires-Debug
We-Hiring
X-Date
X-Via-PopH
X-Depends-On
Surrogated-Key
X-Via-PopN
Memcached
X-Flog
X-Hello
X-VC-Cache
W
X-ABtesting
X-IN-APIGATEWAYSSL
Mail-Subject
LB
X-IN-APIGATEWAY
X-Cache-Tag
X-Via-PopV
X-Region-Sid
X-Proxy-Upstream
OT-Force-Account-Verify
X-PJAX-URL
X-ND-Cache
X-Req
Dnion-Transfer-Encoding
WZWS-RAY
X-Akamai-Pragma-Client-IP
Time
X-UnsetCookies
Memory
X-Zone
X-RateLimit-Remaining-Second
X-Presslabs-Stats
X-Lb-Id
X-Sigma
X-Sigma-Backend
Vha6-Origin
Media-Length
X-Pf-Uncompressing
X-RateLimit-Limit-Second
X-Rocket-Build-Number
Env
X-Oracle-DMS-ECID
X-APP
X-Pad
X-Litespeed-Cache-Control
X-ZONE
X-Snapshot-Date
X-MiniProfiler-Ids
X-Air-Trace-Id
X-LiteSpeed-Tag
Epwk-X-Cache
X-Men
X-Varnish-URL
Cf-Ipcountry
X-Vcache
X-Acquia-Application-UUID
X-Csrf-Token
X-ElasticPress-Query
VNS-Cache
X-Acquia-Application-Trace
X-Request-URL
CPC-Cache
CPC-Age
URI
X-Akamai-ERRuleID
X-Akamai-ERPolicy
X-Acquia-Site
Xet-Cookie
X-Ms-Meta-Originalurl
X-Ms-Meta-Staticbatchstarttime
VNS-Age
X-ElasticPress-Search
X-Request-Url
X-Acquia-Purge-Tags
X-Varnish-Beresp-TTL
X-B3-Parentspanid
CountryCode
X-Amz-Meta-Cb-Modifiedtime
X-Nananana
X-Tid
Environment
X-Storefront-Renderer-Verified
X-Redis-Count
X-ServerName
X-C
X-Akamai-Request-ID
X-Redis-Duration-Ms
X-Traceid
X-Debug-Cache-Fetch
X-Debug-Cache-Store
Ohc-Response-Time
Phost
NnCoection
Inserted-Into-Cache-At