Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
X-XSS-Protection
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Request-Id
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Xss-Protection
X-Cache-Status
X-Generator
X-Cacheable
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
X-Request-ID
Content-Encoding
X-CDN
X-Ua-Compatible
Feature-Policy
X-AspNetMvc-Version
Status
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Upgrade
X-Via
Access-Control-Max-Age
Keep-Alive
X-Ws-Request-Id
X-Age
X-Robots-Tag
X-AH-Environment
X-Turbo-Charged-By
EagleId
Request-Context
X-Proxy-Cache
X-Cache-Group
Server-Timing
X-Backend
X-Server
X-Hacker
X-Dns-Prefetch-Control
Host-Header
Report-To
X-Server-Powered-By
X-Amz-Request-Id
X-Nginx-Cache-Status
Grace
X-Amz-Id-2
X-UA-Device
X-Rq
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Page-Speed
Cf-Railgun
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Amz-Version-Id
NEL
X-Device
X-Cache-Spec
X-OneAgent-JS-Injection
X-CST
Allow
X-Vhost
X-WebKit-CSP
X-Host
X-Backend-Server
Xkey
X-Server-Id
EagleEye-TraceId
X-Dispatcher
Surrogate-Control
X-Node
Request-Id
X-Response-Time
Content-Location
X-Akam-SW-Version
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
P3p
X-ASPNET-VERSION
X-Cache-Lookup
X-Application-Context
X-Ac
X-Country
Accept-Ch
X-Ruxit-JS-Agent
X-Template
X-Mod-Pagespeed
Accept-CH
Accept-Ch-Lifetime
X-Language
X-Readtime
X-Cloud-Trace-Context
Accept-CH-Lifetime
X-B3-TraceId
MS-Author-Via
Rating
X-HW
X-Url
X-Origin-Cache
X-Cnection
X-MS-InvokeApp
X-TtlSet
X-Vname
X-PC
Edge-Control
X-Clacks-Overhead
X-GitHub-Request-Id
X-Trace
X-ESI
X-ORACLE-DMS-RID
X-Oneagent-Js-Injection
X-Middleton-Response
X-Sol
X-Middleton-Display
Response
Pagespeed
Display
X-Varnish-TTL
X-Content-Type
X-ORACLE-DMS-ECID
X-D2id
Verso
Arr-Disable-Session-Affinity
X-Kinja-Revision
X-Kinja
X-Kinja-Build
X-GoogleNews-Bot
X-Exp-Variant
X-Use-Magma
X-Exp-Id
X-Cdn-Fetch
X-Kinja-Server
X-Vcap-Request-Id
X-Country-Code
X-Rack-Cache
X-Goog-Hash
X-Powered-By-Plesk
X-Navigation-Version
X-VARITI-CCR
Service-Worker-Allowed
X-Server-Name
X-Abt-Application-Version
X-Amz-Rid
X-Buckets
X-Fastly-Request-ID
X-TTL
X-Client-IP
Fastly-Restarts
X-Cached
X-Cache-TTL
X-FastCGI-Cache
X-Release
X-MSEdge-Ref
X-Element-Page-Cache
X-Dw-Request-Base-Id
X-SharePointHealthScore
SPRequestGuid
X-NF-Request-ID
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
SPRequestDuration
SPIisLatency
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
Public-Key-Pins
Access-Control-Request-Method
RTSS
X-Webkit-CSP
AR-ATIME
AR-PoweredBy
AR-CACHE
AR-Request-ID
Ar-Sid
Cache-Tag
X-Edge
X-LLID
X-SRCache-Fetch-Status
X-Powered-CMS
X-SRCache-Store-Status
X-Ezoic-Cdn
X-Ruxit-Js-Agent
X-Upstream
Content-MD5
X-Version
X-HP-Webp
X-Jurisdiction
X-Origin-Upstream-Status
S
X-Recruiting
X-ECACHE
X-Mid
X-MCACHE
X-Mg-S
Fusion-Template-Id
Fusion-Source
Fusion-Content-Source
Fusion-Content-Id
Fusion-Component-Id
Charset
Fusion-Deployment-Id
X-Px
X-DynaTrace
X-Content-Digest
X-PressLabs-Stats
X-Kinsta-Cache
X-Ttl
X-T
Fastcgi-Cache
Cache-Tags
X-Litespeed-Cache
X-Fastcgi-Cache
X-Amz-Server-Side-Encryption
X-Accel-Expires
X-Logged-In
Filters
X-Forwarded-Proto
X-Content-Security-Policy-Report-Only
Server-Node
Edge-Cache-Tag
Front-End-Https
MicrosoftSharePointTeamServices
X-Id
TP-L2-Cache
TP-Cache
Server-Name
X-Correlation-Id
X-Grace
TCN
Nginx-Cache
X-Hits
X-Request-Received
X-Request-Processing-Time
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Debug
X-Forwarded-For
X-Amzn-Trace-Id
X-B3-Sampled
X-Shield-Request-Id
X-Microsite
X-Request-Handler-Origin-Region
X-Varnish-Age
X-Yandex-Sdch-Disable
Surrogate-Key
X-AppVersion
X-Az
X-Activity-Id
X-F-Cache
X-Amz-Replication-Status
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Hub-Id
X-XRDS-Location
X-HS-Combine-CSS
X-XRDS-LOCATION
X-Ser
Alternate-Protocol
X-Origin-Server
X-DIS-Request-ID
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Metageneration
Nel
Accept-Charset
X-Geo-Country
X-Frontend
X-Rid
X-NWS-LOG-UUID
X-Git-Hash
Section-Io-Cache
Host
X-Respond-Thread
X-Cache-Age
X-Pinterest-Direct
X-Cache-Key
X-Upgrade-Enabled
X-LB-Cache
X-Hostname
X-VCache
Access-Control-Allow-Method
X-Time
X-DataDome
X-Mobile-URL
X-Seen-By
MS-CV
X-Server-ID
Cache
X-Type
Paypal-Debug-Id
ServerID
X-Source
X-Daa-Tunnel
X-RateLimit-Remaining
X-TT
X-IPLB-Instance
X-AOL-HN
Payment
X-Varnish-Backend
X-Content-Options
Healthy
X-Is-Crawler
X-Flags
X-B-Cache
X-Aspnet-Duration-Ms
X-Providence-Cookie
X-Request-Guid
X-Whom
X-Signature
X-Route-Name
X-App-Environment
X-FTR-Request-ID
Cleartype
X-Cache-Action
X-Page-Id
X-Debug-Info
Fastcgi-Useragent
X-Jobs
X-WebKit-CSP-Report-Only
X-Load-Cache
X-N
X-FB-Debug
X-Contextid
Realpath
Powered-By-ChinaCache
X-Webkit-Csp
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Mobile
Node
X-Rule
Refresh
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Accel-Buffering
X-Response-Served-From
X-Cache-Expired-At
X-Original-Request-Id
X-Drupal-Cache-Tags
X-Wix-Request-Id
X-Zen-Fury
Version
DC
Ms-Operation-Id
X-Proxy
X-RTag
Referer-Policy
X-Framework
X-Cacheable-TTL
X-Via-JSL
Access-Control-Request-Headers
X-RemovedCookies
X-Content-Powered-By
X-Real-IP
X-Cluster-Name
X-ProcessESI
X-HTML-Minification-Powered-By
X-B
X-Distributor
X-Instance
X-Cache-Control
X-Cache-Time
X-Region
X-Tt-Trace-Tag
X-Drupal-Cache-Contexts
X-Page-View
X-Tt-Trace-Host
VIX-Pulpo-Upstream-Status
Viewport
VIX-Pulpo-Node
X-UUID
Eomportal-Instance
X-FW-Dynamic
X-FW-Hash
X-FW-Serve
X-FW-Static
X-IPS-LoggedIn
X-FW-Server
X-FW-Type
Countrycode
X-Akamai-Edgescape
X-Cached-By
X-FireWall-Port
Liferay-Portal
X-Cache-Rule
X-Cache-Operation
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Cache-Hit
X-G
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-Tumblr-User
X-Pass-Why
X-L-Path
X-Environment-Context
X-App-Server
SRV
X-Nginx-Cache
Server-Info
CF-IPCountry
DynaTrace
X-Debug-IsPreview
Section-Origin-Responded
Section-Io-Id
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
X-Debug-IsConnected
X-Protected-By
Xserver
X-Www-Served-By
X-User-Agent
Ec-Rule-Version
From-Origin
X-Tumblr-Pixel-2
Webserver
X-Device-Type
GEO-INFO
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
X-Varnish-Grace
X-Mode
X-Adobe-Content
X-Adobe-Loc
Meta-Geo
X-Hl-Ver
X-Handled-By
X-UPSTREAM-Address
X-ES-SERVER
X-RN-RSRV
X-Endurance-Cache-Level
Cache-Tv-Group
X-MP-GENERATED-AT
X-FB-TRIP-ID
X-Uri
X-Backend-Name
Retry-After
TWC-Device-Class
X-Format
TWC-Connection-Speed
Property-Id
Decoy-Debug-Status
TWC-GeoIP-LatLong
Cache-Status
X-Section
Decoy-Debug-Key
Decoy-Debug-TTL
X-Pubstack
Fastly-SSL
TWC-GeoIP-Country
X-Varnishpool
X-Ratelimit-Limit
X-PCL
X-Storage
X-Labrador-Cache-Channel
X-Be
X-Cache-Server
X-NYM-Debug-Backend
X-OCL
X-PHP-Host
X-Origin-Hint
Webcakes-App-Name
TWC-Privacy
Webcakes-App-Version
Webcakes-Region
TWC-Locale-Group
X-Access
Selected-Fe
X-Locale
X-R9-Blue-Green-Version
X-Redis-Cache
X-Timing-Wait
X-No-Session
X-Origin-Date
X-LJ-Flow-ID
X-Proto
X-PERF
X-ApacheServer
Cache-Name
Frame-Options
X-AWS-Id
Mn-Server-Ip
X-Proxy-Build
X-Server-W
X-Sql-Duration-Ms
X-BYPASS-REASON
X-Sql-Count
X-Human
X-ProxyCache-Status
X-ProxyCache-Key
Apigw-Requestid
X-Web-Node
X-UA-Device-Type
Protected
X-LAGOON
X-Via-Fastly
X-WA-Info
X-VWS-Id
X-Request-Time
Country
X-Site-Version
X-Soup
X-Routing-Service
Azure-RegionName
Azure-SiteName
X-SayCDN-TTL
Azure-Version
Azure-SlotName
X-Zipkin-Id
X-Xfnlog-Site
X-Loop
X-TNCMS
X-Hyper-Cache
X-Cache-TTL-Remaining
X-FW-Version
X-Hosted-By
X-Status
Azure-InstanceId
X-Say-TTL
X-Proxied
X-Say-Cacheable
X-S-Maxage
X-Varnish-Server
X-ShopId
X-Sorting-Hat-PodId
X-Storefront-Renderer-Rendered
X-ShardId
X-Sorting-Hat-ShopId
X-Alternate-Cache-Key
X-Shopify-Stage
X-Node-Name
X-TT-LOGID
X-Cache-Grace
X-CCM
X-Cluster
X-GG-Cache-Date
X-Info
X-Forwarded-Host
X-AIR-PT
X-Rendered-As
X-Is-Bot
X-TA-CDN-Provider
X-SRV
AMP-Access-Control-Allow-Source-Origin
X-Revision
X-Microcachable
X-Cache-Enabled
S-Cnection
X-Qloud-Router
X-Proxy-Cache-Status
Uber-Trace-Id
X-Content-Age
X-NWS-UUID-VERIFY
X-Dc
X-Azure-Ref
X-Platform
X-Via-CDN
X-Backend-Host
Cache-Hits
Amp-Access-Control-Allow-Source-Origin
X-Varnish-Ttl
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Balancer
X-Country-Code-Real
X-FTR-Realm
X-Ratelimit-Remaining
X-Aspnetmvc-Version
X-FTR-DC
X-FTR-Cache-Status
X-Detected-As
X-CSRF-Token
X-Cache-Host
Akamai-GRN
X-Amz-Meta-S3cmd-Attrs
X-App-Version
X-Amzn-Remapped-Content-Length
X-Amz-Apigw-Id
X-Amzn-RequestId
ServedBy
X-ATG-Version
X-EdgeConnect-Cache-Status
X-Cache-NGX
X-Cache-PHP
X-Trace-Id
X-B3-SpanId
X-Oss-Object-Type
X-RCS-CacheZone
X-CS
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
X-Debug-Cache
X-Oss-Server-Time
X-Oss-Request-Id
SD-X-WS
X-FTR-Expires
X-Varnish-Hostname
X-ID
X-Time-Microsecs
X-Air-Hostname
Tracecode
X-Nc
X-BCube-Filmed-By
X-Correlation-ID
DB-Nickname
X-Akamai-Transformed
HostName
X-ServerID
X-Backend-TTL
X-Tb
Backend
X-Ms-Version
X-Ms-Request-Id
X-Adobe-Source
X-NewRelic-App-Data
X-D
X-Magnolia-Registration
X-TX-ID
X-From
X-Connection-Hash
Odigeo-Trace-Id
X-External-Request-Id
BehaviorPad-Version
X-Destination
X-Application
X-A-Dam
X-A-Dcw
X-A-Ccd
X-A
T-Server
Rendered-Blocks
X-A-Dgt
X-A-Wwc
X-Cache-NE
X-CF-Lambda-Fn
X-B-Cookie
X-ARC
X-Aed
Mobile-Detection-Method
X-CF-Lambda-Version
Machine
X-DynaTrace-JS-Agent
X-S
X-S-Cookie
X-ScT
X-Rojux
X-Rewrite-Enabled
Expiry
X-Processor
DCR-Processing-Time-Ms
X-Generated-On
X-Session-Fingerprint
X-SRCache-Key
X-VG-WebServer
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-VG-WebCache
X-Vdms-Version
DCR-Decision-By
X-Trv-Group
X-Vdms-Path
X-PBS-Appsvrname
X-Request-UUID
X-PAYTM-SRV-ID
X-NAPM-TraceId
X-Level-Front-Cache
MD5-Digest
X-Generation-Time
Meta-Geo-Continent
X-Origin-CC
X-Location
X-Owner
Fastcgi-X-Cache-Version
X-Origin-TTL
X-Cache-Var
X-Cache-Var-Map
X-Unique-Id
Thinkindot-CacheControl
Locid
Magicmarker
PB-PID
Server-Host
On-Server
Fastly-Backend-Name
Host-ID
Pagetype
Gh-Request-Id
PB-RID
Release
Path
Cf-Device-Type
Content-Disposition
CacheControlHeader
X-Developers
X-JWT-State
X-Micro-Cache
X-Mvc-Supplant-Cachable
X-Is-Gdpr
X-Irp-Debug
X-Has-Esi
X-HS-Content-Campaign-Id
X-OVcl
X-OVcl-Cache
X-TrackingId
X-Tumblr-Pixel-3
X-Thinkindot-L3
X-Thanos
X-Policy
X-Reqid
X-GeoIP-City
X-Geo-Header
Wxu-Next-Hostname
Wxu-Next-Region
X-Azure-Ref-OriginShield
Wxu-Next-Commit
V-Age
Thinkindot-Control
UCS
X-Bip
X-Cache-Bucket
X-Fetched-On
X-Generated-In
X-FC-Vary-Parameters
X-Device-Os
X-Cms-Context
X-Core-Value
Thinkindot-CacheControl-Type
X-Fastly-Cache
X-B3-Traceid
X-Varnish-Cache-Hits
X-Varnish-Beresp-Grace
AKAMAI
Arc-Version
X-CACHE-KEY
X-Unique-ID
X-Sucuri-ID
Who
X-GEO
User-Cache-Control
X-Clara-WADP
X-Clientip
X-SVT-ORM-VERSION
X-CGP
X-User
X-Cache-Tags
X-Variation
X-Var-Ttl
CDN-Cache
X-SVT-ORM-RULES
X-Developer
X-Skip-Cache
X-SIPLIST1
X-DefHash
X-DefElseHash
X-Csrf-Jwt
X-CUA
X-Varnish-CookieHashed-On
X-Cache-Id
X-WADP-Cache
X-Cdn-Forward
X-VServer
CDN-CachedAt
X-Wikidot-Backend
X-Wikidot-Static-Cache
CDN-EdgeStorageId
X-NU-AKA-ACS-Version
X-Backend-State
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-Cache-Debug
X-VarnishDD-TTL
CDN-Uid
X-VG-TLSProxy
X-Block-Status
X-Dispatcher-Server
X-DPWN-IS-SECURE
C-Via
X-Li-Fabric
X-Li-Pop
X-IP
X-Platform-Server
X-Hnp-Log
X-Ratelimit-Reset
X-Origin-Response-Time
X-LI-UUID
X-Nginx-Cache-Key
X-Node-Id
X-Old-Content-Length
X-Origin
X-RateLimit-Limit
X-Origin-Expires
X-Method
X-HN
X-Rebelmouse-Cache-Control
X-Scheme
CDCHOST
Apple-News-Services-Request-Url
X-Fastly-Backend
X-Eu-Site
X-Envoy-Decorator-Operation
X-Esi-Check
X-Fmm-Version
X-Request-URI
X-Rebelmouse-Surrogate-Control
X-GoCache-CacheStatus
X-Gzip
X-GeoIP
X-Request-Host
X-Gen-Mode
X-Generated-By
Cache-Host
X-Branch-Name
IsBot
Server-Hostname
L5d-Success-Class
Sever-Int
Is-Eu
X-Cache-Info
SR-User-Adfree
Instruction
Location
X-Varnish-Beresp-Ttl
X-Swa-Ws
Country-Code
PFcat
NM-Fastcgi-Cache
NGX
Server-Ext
CDN-RequestCountryCode
HA-Ipaddr
Ha-Gx-Prefs
Web-Mar-Node
CDN-RequestId
Vix-Hermes-Req-Id
Apple-News-Services-Handled
Apple-News-Services-Host
Cf-Bgj
CDN-PullZone
Apple-News-Services-Parsed-Url
DSUID
Esi-Enabled
True-Client-Country-4JS
Ssr
Platform
Fastly-SWR
Adler-Geo
Fastly-SIE
X-APP-VERSION
X-Varnish-Beresp-Status
X-EC-Lua
Rt-Fastcgi-Cache
X-Slack-Backend
Origin
X-Gamma-Serve
X-Hash
X-LB-ID
X-Varnish-Hits
X-Aicache-OS
L
X-CLOUD-TRACE-CONTEXT
Lfy
X-Loc
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Varnish-Url
X-Mvc-Supplant-OutputCached
X-Cache-Backend
X-Matched-Rule
Fastly-Drupal-HTML
Geo-Info
Filterid
CloudFront-Viewer-Country
X-Via-Popn
Pics-Label
X-Via-Poph
X-Via-Popv
X-NCache
X-Epic-Correlation-Id
Sid
X-Planisys-CDN-Rules
Pramga
X-Refresh
X-Sn-Servicetimems
X-Cache-Expires
X-Cdn-Origin
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
X-PF-Uncompressing
X-Servername
Url
X-Cache-Date
X-Core-Mission
Req-Svc-Chain
X-Tb-Optimization-Total-Bytes-Saved
Cmsid
X-TraceId
X-Esi
Cmstype
Tcn
Svr
Kp-EeAlive
NGB
X-Request-Start
X-Served-From
Viewtype
A
X-Error
X-DC
MIME-Version
VivaBuild
X-FireWall-Protection
Cache-Key
X-Varnish-Cacheable
Source
M-TraceId
X-Webkit-CSP-Report-Only
Server-ID
Arc-Country
X-Response-By
Cross-Origin-Opener-Policy
X-Srv
X-Vgn-Hpd-Reason
X-NC
X-Proxy-Cachei7
X-HS-Status
Geoip-Latitude
X-Air-Source
TDXMobile
GeoIp-Country-Code
Xkeyi7
X-Servedbyhost
X-Wa
X-JoinUs
X-NGENIX-Cache
X-PHP-Backend
X-CDN-Forward
HitType
X-BBXSRF
Server-Ttl
SID
X-SaId
X-B3-Spanid
N-Cache
Content-Secure-Policy
X-Vcl-Version
X-Geo
S-Rt
X-Erf-Stays-Bingo-Pdp-Web
X-Edge-Location
X-Cache-Remote
NtCoent-Length
X-LI-Proto
X-Cache-2
X-Internal-Host
Resin-Trace
X-Service
X-Vc
X-LiteSpeed-Cache-Control
DataCenter
CACHE
X-Contensis-Viewer-Groups
X-Varnish-Authentication
X-Cc-Via
X-Cc-Req-Id
X-Cache-ASPX
D-Cc-Upstream
X-Li-Proto
Cteonnt-Length
X-Extlb
X-HOST
X-Svr
Cross-Origin-Window-Policy
X-VCL-Version
X-RAMCache
Request-ID
Hostname
X-Viewer-Country
X-CCDN-CacheTTL
Ohc-File-Size
X-Sucuri-Cache
X-Forwarded-Site
FSS-Cache
XServer
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-UA
X-Host-Name
X-HostName
X-DB
X-ServedByHost
X-DI
X-DSS
X-RPS
X-RPM
X-Via-NSCOPI
X-RSL
X-Server-IP
X-DW
X-Newrelic-Synthetics
X-WA
X-TIM-N
X-Bc-Bl
GeoIP-Country-Code
GeoIP-Latitude
X-FORWARDED-FOR
X-Date
X-Origin-Time
Surrogated-Key
X-Accel-Expires-Debug
LB
Mail-Subject
Memcached
X-Nyt-Route
We-Hiring
X-Gdpr
X-Req
X-PJAX-URL
X-Proxy-Upstream
X-VC
X-API-Version
X-App
X-FPC
X-Cs
X-VC-Cache
CF-Cached-On
X-Cache-Config
X-Check-Cacheable
X-Server-Lifecycle-Phase
X-NodeID
X-ZONE
X-SN
Cache-Provider
ProcessTime
X-Kraken-Routeconfig-Destination
Env
X-Instrumentation
X-Action
X-Dynatrace-Js-Agent
X-Kraken-Loop-Name
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-TIME
Ohc-Cache-HIT
X-Swift-Error
Server-Id
X-Oss-Cdn-Auth
X-Sigma-Backend
X-APP
X-Region-Sid
Upgrade-Insecure-Requests
X-Rocket-Build-Number
X-Sigma
X-CF-Powered-By
X-Webstats-RespID
X-SB
X-Fpc
X-Edge-Location-Klb
X-Air-Trace-Id
X-Men
X-CSRF-TOKEN
X-URL
X-Provided-By
CPC-Cache
X-SD-PageType
VNS-Age
Memory
X-Depends-On
Time
X-MSEdge-Features
W
X-MSEdge-Flight
CPC-Age
Mime-Version
VNS-Cache
Srv
X-Cdn-Request-ID
Cdn
X-UnsetCookies
X-BACKEND-TTL
CDN
X-Ftr-Cache-Host
X-BBC-Edge-Cache-Status
X-Render-Time
X-Dw-Trace-Id
X-Zone
X-Client-Ip
X-Hello
X-ABtesting
X-Fastly-Request-Id
X-Flog
X-NGINX-Cache
Dnion-Transfer-Encoding
EpKe-Alive
X-Pf-Uncompressing
X-Fastly-Backend-Reqs
X-Parent-Response-Time
X-Dynatrace
X-Akamai-Pragma-Client-IP
X-Presslabs-Stats
Media-Length
X-Acquia-Site
State
X-Oracle-DMS-ECID
X-Cache-Tag
Processtime
X-Acquia-Purge-Tags
X-ServerName
Proxy-Connection
X-Pad
X-FTR-Cache-Host
X-Worker
X-Auto-Login
Fastcgi-Cache-TTL
Vha6-Origin
X-Acquia-Application-UUID
X-Acquia-Application-Trace
My-App
Datacenter
X-Ua
X-Snapshot-Date
Epwk-X-Cache
X-Minions-Version
PICS-Label
X-Via-PopV
X-Cluster-Node
X-LiteSpeed-Tag
X-BBC-Origin-Response-Status
X-Via-PopH
X-Via-PopN
X-CACHE-AGE
Cf-Ipcountry
X-Varnish-URL
X-Varnish-Beresp-TTL
X-Vcache
X-MiniProfiler-Ids
X-Request-URL
X-Akamai-ERRuleID
X-Akamai-ERPolicy
X-IN-APIGATEWAY
X-ElasticPress-Search
X-IN-APIGATEWAYSSL
X-Ms-Meta-Staticbatchstarttime
X-ElasticPress-Query
Xet-Cookie
X-Ms-Meta-Originalurl
X-Lb-Id
X-Air-Pt
X-Tx-Id
CountryCode
Content-Style-Type
Content-Script-Type
X-Litespeed-Cache-Control
X-Apw-Hits
Warning
X-Mg-Request-UUID
X-Mg-Request-Id
X-Cache-Status-Check
X-Apw-Access-Object
X-Apw-Access-Token
X-Apw-Access-Action
Environment
NnCoection
OT-Force-Account-Verify
Inserted-Into-Cache-At
X-B3-Parentspanid
Phost
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Traceid
URI
X-Amz-Meta-Cb-Modifiedtime
X-Storefront-Renderer-Verified
Ohc-Response-Time
X-Tid
X-Redis-Duration-Ms
X-Redis-Count
X-C