Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
CF-RAY
Cf-Request-Id
CF-Cache-Status
Last-Modified
X-XSS-Protection
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-Runtime
X-AspNet-Version
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Xss-Protection
X-Cache-Status
X-Generator
X-Request-ID
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Content-Security-Policy
Content-Encoding
X-CDN
X-Envoy-Upstream-Service-Time
Status
Feature-Policy
X-Ua-Compatible
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-AspNetMvc-Version
Access-Control-Max-Age
X-Via
Upgrade
Keep-Alive
X-Ws-Request-Id
X-Age
X-Turbo-Charged-By
X-AH-Environment
X-Robots-Tag
Request-Context
X-Proxy-Cache
EagleId
X-Cache-Group
Server-Timing
X-Backend
X-Hacker
X-Amz-Request-Id
Report-To
X-Server
Host-Header
X-Amz-Id-2
X-Server-Powered-By
Grace
X-Nginx-Cache-Status
X-UA-Device
X-LiteSpeed-Cache
X-Dns-Prefetch-Control
X-Varnish-Cache
X-Rq
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Page-Speed
Cf-Railgun
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
NEL
X-Amz-Version-Id
Xkey
X-OneAgent-JS-Injection
X-WebKit-CSP
X-Cache-Spec
Allow
X-Backend-Server
X-Host
X-Vhost
X-CST
X-Device
EagleEye-TraceId
X-Server-Id
X-ASPNET-VERSION
Surrogate-Control
Request-Id
X-Dispatcher
Accept-CH
X-Node
Content-Location
X-Response-Time
Accept-CH-Lifetime
X-Akam-SW-Version
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Ruxit-JS-Agent
X-Template
X-Ac
X-Application-Context
X-Language
X-Kinja-Server-Push
X-Country
X-Cache-Lookup
X-Readtime
X-Mod-Pagespeed
X-Cloud-Trace-Context
MS-Author-Via
X-Origin-Cache
X-B3-TraceId
Rating
X-Cnection
X-MS-InvokeApp
X-HW
X-Url
X-Vname
X-TtlSet
X-PC
X-ORACLE-DMS-ECID
Accept-Ch
X-Clacks-Overhead
X-FastCGI-Cache
Edge-Control
X-GitHub-Request-Id
X-ESI
X-Trace
Accept-Ch-Lifetime
Display
Pagespeed
Response
X-Sol
X-Middleton-Response
X-Middleton-Display
X-Content-Type
X-Oneagent-Js-Injection
X-D2id
X-Vcap-Request-Id
X-Exp-Variant
X-Exp-Id
Verso
Arr-Disable-Session-Affinity
X-GoogleNews-Bot
X-Cdn-Fetch
X-Kinja-Build
X-Use-Magma
X-Kinja
X-Kinja-Server
X-Kinja-Revision
X-Buckets
X-Goog-Hash
X-Rack-Cache
X-Server-Name
X-Country-Code
Service-Worker-Allowed
X-Navigation-Version
X-Varnish-TTL
X-Abt-Application-Version
X-VARITI-CCR
X-Amz-Rid
X-ORACLE-DMS-RID
X-Powered-By-Plesk
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
X-Cache-TTL
X-Client-IP
X-SharePointHealthScore
SPRequestGuid
X-Fastly-Request-ID
X-Release
SPIisLatency
X-MSEdge-Ref
SPRequestDuration
X-Dw-Request-Base-Id
X-Element-Page-Cache
Fastly-Restarts
X-NF-Request-ID
X-Cached
Public-Key-Pins
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
RTSS
X-Ttl
X-Origin-Upstream-Status
AR-CACHE
Ar-Sid
AR-Request-ID
AR-ATIME
AR-PoweredBy
X-Edge
Access-Control-Request-Method
X-TTL
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Webkit-CSP
X-Px
X-LLID
X-Powered-CMS
Fusion-Content-Source
Fusion-Deployment-Id
Fusion-Source
Fusion-Template-Id
Fusion-Content-Id
Fusion-Component-Id
X-Ezoic-Cdn
X-Upstream
Content-MD5
X-HP-Webp
X-Jurisdiction
X-Amz-Server-Side-Encryption
X-Mid
X-ECACHE
X-MCACHE
Charset
Cache-Tag
X-Recruiting
X-Mg-S
S
X-Content-Digest
X-Pinterest-Direct
X-PressLabs-Stats
X-Version
X-Aspnetmvc-Version
TCN
MicrosoftSharePointTeamServices
Fastcgi-Cache
X-Debug
Front-End-Https
X-T
X-Content-Security-Policy-Report-Only
X-Grace
Filters
X-Kinsta-Cache
Cache-Tags
X-XRDS-Location
Edge-Cache-Tag
Server-Node
X-Id
X-Forwarded-Proto
X-Accel-Expires
X-Correlation-Id
X-Logged-In
X-Amzn-Trace-Id
X-Yandex-Sdch-Disable
Server-Name
Nginx-Cache
Surrogate-Key
X-Varnish-Age
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Cache-Key
X-Forwarded-For
TP-Cache
TP-L2-Cache
X-B3-Sampled
X-Request-Received
X-Request-Processing-Time
X-Request-Handler-Origin-Region
X-Microsite
X-DynaTrace
X-Hits
X-Ser
Powered-By-ChinaCache
X-DIS-Request-ID
X-Shield-Request-Id
X-AppVersion
X-Activity-Id
X-Az
X-Amz-Replication-Status
X-Server-ID
X-HS-Cache-Config
X-HS-Combine-CSS
X-HS-Content-Id
X-HS-Hub-Id
X-F-Cache
X-Ruxit-Js-Agent
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
X-Origin-Server
Accept-Charset
X-FTR-Request-ID
X-Git-Hash
X-Hostname
X-Respond-Thread
X-Geo-Country
X-LB-Cache
X-DataDome
X-Upgrade-Enabled
Section-Io-Cache
X-Rid
X-Frontend
Access-Control-Allow-Method
X-Cache-Age
Cache
Alternate-Protocol
Host
X-Mobile-URL
Cleartype
Paypal-Debug-Id
MS-CV
Healthy
X-IPLB-Instance
X-Type
X-Content-Options
X-WebKit-CSP-Report-Only
ServerID
X-AOL-HN
X-App-Environment
X-Varnish-Backend
X-Seen-By
X-Whom
Payment
X-Cache-Action
X-B-Cache
X-Aspnet-Duration-Ms
X-Flags
X-Debug-Info
X-Providence-Cookie
X-Route-Name
X-Signature
X-TT
X-Is-Crawler
X-Request-Guid
X-VCache
X-XRDS-LOCATION
X-Page-Id
Fastcgi-Useragent
X-TEC-API-ROOT
X-Jobs
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-NWS-LOG-UUID
X-N
X-Source
X-Mobile
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Load-Cache
X-Browser-Type
X-Time
X-RateLimit-Remaining
X-Via-JSL
X-Cached-By
X-Daa-Tunnel
X-FB-Debug
X-Akamai-Edgescape
Version
Nel
X-Cache-Rule
X-Cache-Operation
X-Litespeed-Cache
Viewport
Refresh
X-Response-Served-From
DynaTrace
X-Rule
X-Original-Request-Id
X-Accel-Buffering
DC
X-Framework
X-Drupal-Cache-Tags
X-Zen-Fury
X-Proxy
X-Cacheable-TTL
Realpath
Ms-Operation-Id
X-ProcessESI
X-Instance
X-RemovedCookies
X-RTag
GEO-INFO
X-Real-IP
Access-Control-Request-Headers
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Fastcgi-Cache
X-Contextid
X-Region
X-Wix-Request-Id
X-Cache-Time
X-UUID
X-HTML-Minification-Powered-By
X-Drupal-Cache-Contexts
X-Distributor
Referer-Policy
X-Yottaa-Optimizations
X-Page-View
X-Yottaa-Metrics
Node
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
Eomportal-Instance
X-Cache-Expired-At
Countrycode
X-FW-Type
X-FW-Static
X-FW-Dynamic
X-FW-Server
X-FW-Serve
X-FW-Hash
X-B
X-Environment-Context
X-L-Path
X-Cluster-Name
Liferay-Portal
X-Tumblr-Pixel-1
X-Cache-Control
X-Tumblr-User
X-Tumblr-Pixel-0
X-G
X-Node-Name
X-Tumblr-Pixel
X-Content-Powered-By
X-IPS-LoggedIn
X-Cache-Hit
X-User-Agent
Webserver
Server-Info
X-Tumblr-Pixel-2
X-Amz-Meta-S3cmd-Attrs
X-Pass-Why
Section-Io-Id
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
From-Origin
Section-Io-Origin-Status
X-App-Server
X-Varnish-Ttl
SRV
Protected
X-Ratelimit-Limit
Ec-Rule-Version
X-Protected-By
X-FireWall-Port
X-Revision
X-Oracle-Dms-Rid
X-Cache-Server
X-Backend-Name
Frame-Options
Cache-Status
CF-IPCountry
X-Hyper-Cache
X-Hl-Ver
X-UPSTREAM-Address
X-RN-RSRV
X-ES-SERVER
Meta-Geo
X-Handled-By
X-Endurance-Cache-Level
X-Www-Served-By
X-Mode
X-Forwarded-Host
X-FB-TRIP-ID
Retry-After
X-NYM-Debug-Backend
X-Storage
X-Locale
X-Site-Version
X-Soup
Cache-Tv-Group
Decoy-Debug-Key
X-Varnishpool
X-Adobe-Content
X-Web-Node
X-Be
X-Pubstack
Decoy-Debug-TTL
Fastly-SSL
Decoy-Debug-Status
Country
X-Adobe-Loc
X-Cache-Grace
X-Human
Azure-Version
Azure-InstanceId
X-Format
Azure-RegionName
Azure-SiteName
Cache-Name
Azure-SlotName
X-Labrador-Cache-Channel
X-Say-TTL
X-Origin-Date
TWC-Locale-Group
X-PHP-Host
TWC-GeoIP-LatLong
X-Proto
TWC-GeoIP-Country
X-PCL
TWC-Privacy
Webcakes-Region
Webcakes-App-Name
X-Access
X-Origin-Hint
X-BYPASS-REASON
X-Proxy-Build
TWC-Device-Class
X-Uri
X-Say-Cacheable
X-UA-Device-Type
X-TT-LOGID
X-Timing-Wait
X-SayCDN-TTL
X-Redis-Cache
X-ProxyCache-Status
TWC-Connection-Speed
X-OCL
Selected-Fe
Property-Id
X-ProxyCache-Key
X-Section
Webcakes-App-Version
X-Server-W
X-S-Maxage
X-AIR-PT
X-ApacheServer
X-Sql-Duration-Ms
X-PERF
X-Sql-Count
X-WA-Info
X-Via-CDN
X-Via-Fastly
X-LAGOON
X-No-Session
X-FW-Version
X-R9-Blue-Green-Version
X-Request-Time
X-VWS-Id
X-LJ-Flow-ID
X-Hosted-By
X-AWS-Id
X-TNCMS
X-Loop
X-Qloud-Router
X-FTR-Backend
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Balancer
Mn-Server-Ip
X-FTR-Cache-Status
X-FTR-DC
X-MP-GENERATED-AT
X-FTR-Realm
S-Cnection
X-Status
X-Cluster
X-Shopify-Stage
X-Alternate-Cache-Key
X-ShopId
X-ShardId
X-Storefront-Renderer-Rendered
X-Routing-Service
X-Proxied
X-Cache-TTL-Remaining
X-Sorting-Hat-ShopId
X-CCM
X-Zipkin-Id
X-Sorting-Hat-PodId
X-Ratelimit-Remaining
X-FTR-Expires
Cache-Hits
X-Xfnlog-Site
Xserver
X-Is-Bot
X-Rendered-As
X-Dynatrace
X-Tec-Api-Origin
X-Tec-Api-Version
X-Device-Type
X-Tec-Api-Root
X-Unique-Id
X-Cache-Var
X-SRV
X-Air-Hostname
X-Cache-Var-Map
X-Detected-As
AMP-Access-Control-Allow-Source-Origin
X-Nginx-Cache
X-Info
Apigw-Requestid
X-EdgeConnect-Cache-Status
X-Cache-Host
X-Amzn-Remapped-Content-Length
X-Amz-Apigw-Id
X-Dc
X-Amzn-RequestId
X-Webkit-Csp
X-Cdn
X-B3-Traceid
X-Debug-IsConnected
X-Debug-IsPreview
X-Microcachable
X-Cache-Enabled
X-GEO
X-APP-VERSION
X-Varnish-Grace
SD-X-WS
X-Content-Age
X-Platform
X-Varnish-Server
Amp-Access-Control-Allow-Source-Origin
Tracecode
X-Time-Microsecs
X-Backend-TTL
X-Azure-Ref
X-Backend-Host
X-GG-Cache-Date
X-Cache-Backend
Uber-Trace-Id
X-ServerID
X-DynaTrace-JS-Agent
DSUID
X-Proxy-Cache-Status
X-Erf-Stays-Bingo-Pdp-Web
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
X-BCube-Filmed-By
X-Oss-Storage-Class
X-Tb
X-Oss-Request-Id
Akamai-GRN
X-NewRelic-App-Data
X-ATG-Version
X-Sucuri-ID
X-ID
X-Trace-Id
PB-PID
Arc-Version
Backend
PB-RID
X-Correlation-ID
ServedBy
X-Magnolia-Registration
X-Akamai-Transformed
X-CSRF-Token
X-Cache-NE
X-CF-Lambda-Fn
X-A-Dcw
Odigeo-Trace-Id
Mobile-Detection-Method
Meta-Geo-Continent
Path
Pramga
Rendered-Blocks
X-RCS-CacheZone
Release
MD5-Digest
Machine
Expiry
DCR-Processing-Time-Ms
DCR-Decision-By
Fastcgi-X-Cache-Version
BehaviorPad-Version
Lfy
Instruction
SR-User-Adfree
X-Varnish-Hostname
X-A-Wwc
X-A-Dgt
X-CF-Lambda-Version
X-Varnish-Cache-Hits
X-Aed
X-ARC
X-Application
X-A-Dam
X-A-Ccd
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
T-Server
Thinkindot-Control
X-A
X-Cache-NGX
X-Cache-PHP
X-B-Cookie
X-Generated-On
X-Session-Fingerprint
X-Trv-Group
X-Thinkindot-L3
X-Origin-Response-Time
X-Vdms-Path
X-Request-UUID
X-Vdms-Version
X-GeoIP-City
X-Level-Front-Cache
X-Location
X-Origin-CC
X-Origin-TTL
X-SRCache-Key
X-PAYTM-SRV-ID
X-PBS-Appsvrname
X-Matched-Rule
X-Processor
X-VG-WebCache
X-VG-WebServer
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
X-External-Request-Id
X-Device-Os
X-Destination
X-Connection-Hash
Xc-Version
X-D
X-ScT
X-Fetched-On
X-Rewrite-Enabled
X-Generation-Time
X-Rojux
X-S
X-From
X-S-Cookie
X-Skip-Cache
X-Sn-Servicetimems
X-SVT-ORM-RULES
X-User
Ha-Gx-Prefs
HA-Ipaddr
Gh-Request-Id
Fastly-Backend-Name
X-VServer
Host-ID
L5d-Success-Class
X-Swa-Ws
X-Thanos
Pagetype
X-Tumblr-Pixel-3
X-SVT-ORM-VERSION
X-Owner
X-Cache-Bucket
X-Cache-Date
X-Bip
X-Geo-Header
X-GeoIP
Cf-Device-Type
X-Cache-Info
X-Eu-Site
X-Csrf-Jwt
X-Cdn-Origin
X-FC-Vary-Parameters
X-Generated-In
X-Azure-Ref-OriginShield
X-Has-Esi
X-OVcl-Cache
X-OVcl
X-CGP
X-Reqid
UCS
X-Node-Id
X-Mvc-Supplant-Cachable
X-Irp-Debug
X-HS-Content-Campaign-Id
X-Is-Gdpr
X-JWT-State
X-Micro-Cache
Ssr
X-Backend-State
X-Debug-Cache
AKAMAI
CacheControlHeader
X-Adobe-Source
X-Ms-Request-Id
X-Ms-Version
Cache-Host
X-NWS-UUID-VERIFY
C-Via
DB-Nickname
Wxu-Next-Region
X-Origin-Expires
Wxu-Next-Hostname
Sever-Int
X-TrackingId
PFcat
User-Cache-Control
Server-Ext
Server-Host
X-Policy
Server-Hostname
Wxu-Next-Commit
X-Wikidot-Backend
X-Developer
X-CUA
X-Generated-By
X-Developers
X-Envoy-Decorator-Operation
X-Fastly-Cache
X-Fastly-Backend
X-Varnish-Hits
X-Core-Value
X-VarnishDD-TTL
X-Var-Ttl
X-Nginx-Cache-Key
X-Request-Host
X-IP
X-HN
X-Cms-Context
X-Clientip
X-Cache-Tags
X-Wikidot-Static-Cache
V-Age
X-Cache-Remote
Content-Disposition
Magicmarker
L
Locid
NGX
X-Request-URI
On-Server
X-Scheme
CloudFront-Viewer-Country
X-Branch-Name
X-Block-Status
X-Varnish-Beresp-Grace
X-VG-TLSProxy
X-Hnp-Log
X-Variation
Fastly-SWR
X-LI-UUID
X-Method
X-Cache-Expires
X-Li-Pop
X-Li-Fabric
Fastly-SIE
Origin
X-Clara-WADP
X-Dispatcher-Server
X-Varnish-Remaining-TTL
X-SIPLIST1
X-DPWN-IS-SECURE
X-Esi-Check
X-Fmm-Version
Cf-Bgj
X-DefHash
X-DefElseHash
X-GoCache-CacheStatus
X-Gzip
X-TA-CDN-Provider
X-NU-AKA-ACS-Version
X-Servername
X-Gen-Mode
X-Varnish-CookieHashed-On
X-Cache-Id
X-Loc
Location
Rt-Fastcgi-Cache
NM-Fastcgi-Cache
X-Varnish-CookieINHashed-On
X-Platform-Server
True-Client-Country-4JS
X-Rebelmouse-Surrogate-Control
Platform
X-Rebelmouse-Cache-Control
X-Ratelimit-Reset
Apple-News-Services-Handled
X-Old-Content-Length
Web-Mar-Node
Vix-Hermes-Req-Id
IsBot
Apple-News-Services-Host
Adler-Geo
Is-Eu
X-TX-ID
CDCHOST
X-WADP-Cache
Apple-News-Services-Parsed-Url
X-Request-Start
X-Origin
Apple-News-Services-Request-Url
X-NC
CDN-PullZone
CDN-CachedAt
X-Slack-Backend
X-NAPM-TraceId
CDN-EdgeStorageId
X-B3-Spanid
X-Gamma-Serve
X-Cache-Debug
CDN-Uid
Fastly-Drupal-HTML
CDN-RequestId
CDN-RequestCountryCode
CDN-Cache
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Status
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Hash
HostName
X-EC-Lua
X-Core-Mission
CACHE
Url
X-Varnish-Url
X-NCache
X-Host-Name
X-CS
X-Varnish-Cacheable
X-PF-Uncompressing
X-Cdn-Forward
X-Response-By
S-Rt
X-Mvc-Supplant-OutputCached
X-Aicache-OS
X-B3-SpanId
X-Proxy-Cachei7
X-App-Version
Xkeyi7
Pics-Label
X-LB-ID
X-Refresh
X-CACHE-GROUP
X-BBXSRF
N-Cache
Sid
Cross-Origin-Window-Policy
X-CDN-Forward
X-Sucuri-Cache
Content-Secure-Policy
Ohc-File-Size
X-FireWall-Protection
X-Via-Poph
X-Via-Popv
X-Via-Popn
Esi-Enabled
X-Esi
X-Cache-2
X-Contensis-Viewer-Groups
Cteonnt-Length
X-Cache-ASPX
X-Varnish-Authentication
D-Cc-Upstream
X-Cc-Via
X-Epic-Correlation-Id
X-Cc-Req-Id
X-Wa
X-DC
X-Error
X-Nc
X-Servedbyhost
X-Tb-Optimization-Total-Bytes-Saved
X-Svr
Source
X-TraceId
MIME-Version
X-RateLimit-Limit
X-Srv
X-Cs
Who
X-TIME
Req-Svc-Chain
X-Unique-ID
Country-Code
X-Server-IP
X-Webkit-CSP-Report-Only
HitType
X-Planisys-CDN-TTL
X-Gdpr
X-Cache-Config
Geoip-Latitude
GeoIp-Country-Code
XServer
X-API-Version
Hostname
X-VC
X-FPC
X-Planisys-CDN-Rules
X-LiteSpeed-Cache-Control
X-Nyt-Route
X-Planisys-CDN-Cache
Server-Ttl
X-Origin-Time
X-HS-Status
X-SN
X-LI-Proto
Ohc-Cache-HIT
X-Fastly-Request-Id
X-NGINX-Cache
X-URL
X-Webstats-RespID
Kp-EeAlive
Svr
X-VCL-Version
X-NodeID
Server-ID
Cmstype
Cmsid
X-SB
X-CACHE-KEY
Geo-Info
X-Check-Cacheable
VivaBuild
Viewtype
X-Served-From
X-SD-PageType
SID
A
X-Vgn-Hpd-Reason
X-Viewer-Country
Cache-Key
X-Ua
X-Render-Time
NtCoent-Length
X-HOST
X-Vcl-Version
EpKe-Alive
X-BBC-Edge-Cache-Status
X-CCDN-CacheTTL
X-CCDN-Origin-Time
M-TraceId
Request-ID
X-Hcs-Proxy-Type
X-UA
Cross-Origin-Opener-Policy
X-Worker
X-RSL
TDXMobile
X-RPS
X-CF-Powered-By
Resin-Trace
Arc-Country
X-RPM
X-Li-Proto
Server-Id
Cache-Provider
X-Air-Source
X-TIM-N
X-Auto-Login
X-DSS
X-DW
X-CSRF-TOKEN
X-DI
X-FORWARDED-FOR
GeoIP-Latitude
X-DB
X-RAMCache
GeoIP-Country-Code
Filterid
X-Ftr-Cache-Host
X-Dynatrace-Js-Agent
X-App
Upgrade-Insecure-Requests
X-Internal-Host
ProcessTime
X-Newrelic-Synthetics
Srv
CDN
X-Action
X-Cluster-Node
Processtime
Datacenter
X-FTR-Cache-Host
X-Fpc
X-Oss-Cdn-Auth
NGB
X-WA
X-ServedByHost
Tcn
Mime-Version
X-Service
X-Vc
X-CLOUD-TRACE-CONTEXT
CF-Cached-On
X-BBC-Origin-Response-Status
Proxy-Connection
X-Geo
OT-Force-Account-Verify
X-HostName
X-HITS
X-BACKEND-TTL
X-ND-Cache
X-Via-NSCOPI
WZWS-RAY
X-JoinUs
X-NGENIX-Cache
FSS-Cache
X-Forwarded-Site
X-MSEdge-Flight
X-MSEdge-Features
X-PHP-Backend
X-Akamai-Pragma-Client-IP
X-Via-PopH
X-SaId
X-Via-PopN
X-Cache-Tag
X-Dw-Trace-Id
X-Via-PopV
Cdn
X-Fastly-Backend-Reqs
DataCenter
X-Edge-Location
X-CACHE-AGE
X-Extlb
X-Client-Ip
X-Cdn-Request-ID
PICS-Label
Dnion-Transfer-Encoding
X-Parent-Response-Time
X-IN-APIGATEWAY
X-Lb-Id
W
X-Pf-Uncompressing
X-Hello
X-IN-APIGATEWAYSSL
X-ABtesting
X-Flog
X-Provided-By
LB
Mail-Subject
Epwk-X-Cache
X-Swift-Error
X-LiteSpeed-Tag
Vha6-Origin
Media-Length
X-Presslabs-Stats
X-RateLimit-Limit-Second
X-Proxy-Upstream
Memcached
X-Pad
X-RateLimit-Remaining-Second
X-Region-Sid
X-VC-Cache
X-UnsetCookies
X-Req
X-Depends-On
X-PJAX-URL
We-Hiring
Surrogated-Key
X-Date
X-Oracle-DMS-ECID
X-Accel-Expires-Debug
X-Bc-Bl
Env
X-Sigma
X-Sigma-Backend
Xet-Cookie
X-Rocket-Build-Number
X-MiniProfiler-Ids
URI
Time
X-ZONE
Memory
X-Zone
Cf-Ipcountry
X-ElasticPress-Query
X-Snapshot-Date
X-Acquia-Site
X-Ms-Meta-Originalurl
X-Akamai-Request-ID
X-Csrf-Token
X-Varnish-Beresp-TTL
X-Request-URL
X-Akamai-ERRuleID
X-Vcache
X-Akamai-ERPolicy
X-Acquia-Purge-Tags
X-APP
X-Air-Trace-Id
X-ElasticPress-Search
X-Amz-Meta-Cb-Modifiedtime
X-Men
X-Ms-Meta-Staticbatchstarttime
X-Varnish-URL
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Request-Url
X-B3-Parentspanid
CountryCode
Inserted-Into-Cache-At
X-ServerName
X-Via-Edge
X-Tid
X-Storefront-Renderer-Verified
Environment
NnCoection
X-Litespeed-Cache-Control
Ohc-Response-Time
Edge-Copy-Time
Phost
Content-Style-Type
Content-Script-Type
X-Acc-Debug-Context
X-Acc-Rdl
X-Redis-Count
X-Debug-Cache-Fetch
X-Redis-Duration-Ms
X-C
X-Traceid
X-Via-SSL
X-Debug-Cache-Store