Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
X-XSS-Protection
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
P3P
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-Runtime
X-AspNet-Version
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Cacheable
X-Request-ID
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Content-Security-Policy
X-Ua-Compatible
X-Iinfo
Content-Encoding
X-CDN
Feature-Policy
X-AspNetMvc-Version
Status
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Upgrade
Access-Control-Max-Age
X-Via
Keep-Alive
X-Ws-Request-Id
X-AH-Environment
X-Age
X-Robots-Tag
Request-Context
EagleId
X-Cache-Group
X-Turbo-Charged-By
X-Proxy-Cache
Server-Timing
X-Server
X-Backend
X-Hacker
Host-Header
X-Server-Powered-By
Report-To
X-Amz-Request-Id
X-Nginx-Cache-Status
X-Amz-Id-2
Grace
X-UA-Device
X-Dns-Prefetch-Control
X-Rq
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Page-Speed
X-OneAgent-JS-Injection
Cf-Railgun
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-CST
X-Amz-Version-Id
NEL
X-Cache-Spec
Allow
X-Vhost
X-Host
X-Backend-Server
X-ASPNET-VERSION
X-Server-Id
X-Dispatcher
X-WebKit-CSP
Surrogate-Control
EagleEye-TraceId
X-Node
Xkey
Request-Id
X-Response-Time
Content-Location
Accept-CH
X-Akam-SW-Version
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Ruxit-JS-Agent
P3p
X-Cache-Lookup
Accept-CH-Lifetime
X-Application-Context
X-Country
X-Ac
X-Mod-Pagespeed
X-Cloud-Trace-Context
X-Readtime
X-Template
X-Language
X-B3-TraceId
MS-Author-Via
X-HW
Rating
X-Url
X-Cnection
X-MS-InvokeApp
Accept-Ch-Lifetime
X-PC
X-TtlSet
X-Vname
X-Origin-Cache
Edge-Control
X-Clacks-Overhead
X-ESI
X-Webkit-CSP
X-GitHub-Request-Id
X-Varnish-TTL
X-Trace
Accept-Ch
X-D2id
X-Content-Type
Pagespeed
Display
Response
X-Sol
X-Middleton-Display
X-Middleton-Response
Verso
Arr-Disable-Session-Affinity
X-Kinja-Server
X-Cdn-Fetch
X-Kinja
X-Use-Magma
X-Kinja-Revision
X-Exp-Variant
X-GoogleNews-Bot
X-Kinja-Build
X-Exp-Id
X-FastCGI-Cache
X-Powered-By-Plesk
X-Vcap-Request-Id
X-Country-Code
X-Goog-Hash
X-Rack-Cache
X-VARITI-CCR
X-ORACLE-DMS-RID
X-Navigation-Version
X-Server-Name
X-Amz-Rid
X-ORACLE-DMS-ECID
X-Abt-Application-Version
Fastly-Restarts
X-TTL
Service-Worker-Allowed
X-Fastly-Request-ID
X-Cached
X-Client-IP
X-Buckets
X-Release
X-MSEdge-Ref
X-Element-Page-Cache
Cache-Tag
X-Dw-Request-Base-Id
X-NF-Request-ID
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
Access-Control-Request-Method
RTSS
Public-Key-Pins
X-SharePointHealthScore
SPRequestGuid
SPRequestDuration
SPIisLatency
X-Cache-TTL
AR-ATIME
X-Edge
AR-Request-ID
AR-PoweredBy
AR-CACHE
Ar-Sid
X-Ezoic-Cdn
X-Powered-CMS
X-LLID
X-Upstream
X-Version
X-Pinterest-Rid
X-SRCache-Store-Status
Pinterest-Generated-By
Pinterest-Version
X-SRCache-Fetch-Status
S
Content-MD5
X-HP-Webp
X-Jurisdiction
X-Kinsta-Cache
X-Recruiting
X-Mid
X-ECACHE
X-MCACHE
Charset
X-Mg-S
X-Ttl
X-PressLabs-Stats
X-T
X-DynaTrace
X-Accel-Expires
X-Origin-Upstream-Status
Cache-Tags
X-Content-Digest
X-Forwarded-Proto
Fastcgi-Cache
Fusion-Template-Id
Fusion-Content-Id
Fusion-Component-Id
X-Litespeed-Cache
Fusion-Deployment-Id
Fusion-Content-Source
Fusion-Source
X-Content-Security-Policy-Report-Only
X-Id
X-Px
X-Correlation-Id
TP-L2-Cache
TP-Cache
X-Logged-In
Filters
Server-Node
Server-Name
TCN
Edge-Cache-Tag
X-Amz-Server-Side-Encryption
X-Oneagent-Js-Injection
Front-End-Https
X-Forwarded-For
X-Request-Received
X-Request-Processing-Time
Nginx-Cache
MicrosoftSharePointTeamServices
X-Grace
X-XRDS-Location
X-Shield-Request-Id
Alternate-Protocol
X-Hits
X-Amzn-Trace-Id
X-B3-Sampled
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Server-ID
X-Request-Handler-Origin-Region
X-Microsite
X-NWS-LOG-UUID
X-Ruxit-Js-Agent
X-F-Cache
X-Amz-Replication-Status
X-Activity-Id
X-Az
X-AppVersion
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Combine-CSS
X-HS-Hub-Id
X-Origin-Server
X-Varnish-Age
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Metageneration
X-GUploader-UploadID
X-RateLimit-Remaining
X-Debug
X-Frontend
X-Rid
Realpath
Nel
X-Daa-Tunnel
Host
X-Yandex-Sdch-Disable
Section-Io-Cache
X-Cache-Age
Accept-Charset
X-Geo-Country
X-DIS-Request-ID
X-Fastcgi-Cache
X-Hostname
Surrogate-Key
X-Ser
X-Git-Hash
X-VCache
X-Respond-Thread
X-Time
Access-Control-Allow-Method
X-WebKit-CSP-Report-Only
Cleartype
X-Mobile-URL
X-Contextid
X-Seen-By
X-DataDome
X-Source
ServerID
X-XRDS-LOCATION
Paypal-Debug-Id
MS-CV
X-Type
X-Upgrade-Enabled
X-LB-Cache
X-Providence-Cookie
X-Route-Name
X-Request-Guid
X-Is-Crawler
X-Flags
X-Aspnet-Duration-Ms
X-AOL-HN
Healthy
X-TT
X-Varnish-Backend
X-Content-Options
Payment
X-B-Cache
X-Debug-Info
X-Whom
X-N
X-IPLB-Instance
X-Signature
X-Cache-Action
X-Load-Cache
X-Cache-Key
X-Page-Id
X-App-Environment
X-FB-Debug
Fastcgi-Useragent
Node
X-Jobs
Cache
X-Webkit-Csp
X-Cache-Expired-At
X-Mobile
X-Rule
X-Erf-Bev-Bev
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-FireWall-Port
Refresh
Viewport
X-Response-Served-From
X-Original-Request-Id
X-Wix-Request-Id
X-Accel-Buffering
DC
X-Cacheable-TTL
X-Content-Powered-By
X-Cache-Control
Ms-Operation-Id
X-HTML-Minification-Powered-By
X-Instance
X-RTag
X-Real-IP
Access-Control-Request-Headers
X-Cluster-Name
X-Distributor
X-Debug-IsConnected
X-B
X-Zen-Fury
X-Framework
X-Page-View
X-UUID
X-RemovedCookies
X-ProcessESI
Referer-Policy
X-Debug-IsPreview
X-Tt-Trace-Tag
X-Cache-Time
VIX-Pulpo-Upstream-Status
X-Tt-Trace-Host
X-Region
X-Drupal-Cache-Tags
X-IPS-LoggedIn
VIX-Pulpo-Node
X-Proxy
Eomportal-Instance
Version
X-Www-Served-By
X-Tec-Api-Version
X-Tec-Api-Root
X-FTR-Request-ID
X-Tec-Api-Origin
Countrycode
X-Drupal-Cache-Contexts
X-Protected-By
X-Nginx-Cache
Xserver
X-FW-Serve
X-FW-Server
X-FW-Hash
X-FW-Dynamic
X-FW-Type
X-FW-Static
X-G
X-App-Server
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Tumblr-User
X-Tumblr-Pixel
X-Cached-By
X-Varnish-Grace
X-Yottaa-Optimizations
X-Yottaa-Metrics
Liferay-Portal
CF-IPCountry
X-Cache-Operation
GEO-INFO
X-Via-JSL
X-Cache-Rule
Section-Io-Id
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
X-L-Path
X-Device-Type
X-Environment-Context
SRV
X-Akamai-Edgescape
X-Cache-Hit
X-Pass-Why
X-TA-CDN-Provider
Powered-By-ChinaCache
Server-Info
Retry-After
X-Varnish-Server
X-Adobe-Loc
X-Adobe-Content
X-TEC-API-VERSION
Cache-Status
X-User-Agent
X-TEC-API-ROOT
DynaTrace
X-TEC-API-ORIGIN
Frame-Options
X-Pinterest-Direct
Ec-Rule-Version
X-Tumblr-Pixel-2
X-ES-SERVER
Meta-Geo
From-Origin
X-Endurance-Cache-Level
X-RN-RSRV
X-UPSTREAM-Address
X-Handled-By
X-Hl-Ver
Webserver
Uber-Trace-Id
X-Backend-Name
Cache-Tv-Group
X-Mode
X-FB-TRIP-ID
X-Proxy-Cache-Status
Webcakes-App-Version
X-Section
Webcakes-App-Name
Property-Id
TWC-Connection-Speed
TWC-Privacy
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Locale-Group
X-Access
TWC-Device-Class
Webcakes-Region
X-ProxyCache-Status
X-NYM-Debug-Backend
X-Uri
X-WA-Info
X-MP-GENERATED-AT
X-Varnishpool
X-Format
X-Human
X-Origin-Hint
Country
Apigw-Requestid
X-ProxyCache-Key
X-Request-Time
Decoy-Debug-Key
Decoy-Debug-Status
X-Pubstack
X-Soup
X-Be
Decoy-Debug-TTL
X-Cache-Server
X-BYPASS-REASON
Fastly-SSL
Selected-Fe
Cache-Name
X-SayCDN-TTL
Mn-Server-Ip
X-Say-TTL
X-Timing-Wait
X-Via-Fastly
X-Web-Node
X-LJ-Flow-ID
X-Server-W
X-OCL
X-Loop
X-Origin-Date
X-LAGOON
X-PERF
X-PHP-Host
X-Info
X-PCL
X-Labrador-Cache-Channel
X-No-Session
X-Say-Cacheable
X-VWS-Id
X-Proto
X-Sql-Count
X-AWS-Id
X-TNCMS
X-ApacheServer
X-UA-Device-Type
X-S-Maxage
X-Storage
X-Proxy-Build
X-Sql-Duration-Ms
Azure-SiteName
Azure-SlotName
Azure-RegionName
Azure-Version
Protected
X-GG-Cache-Date
X-Xfnlog-Site
X-R9-Blue-Green-Version
X-Cache-TTL-Remaining
Amp-Access-Control-Allow-Source-Origin
Azure-InstanceId
X-SRV
X-Content-Age
X-ShopId
X-Hosted-By
X-Hyper-Cache
X-Sorting-Hat-PodId
X-ShardId
X-NWS-UUID-VERIFY
X-Alternate-Cache-Key
X-Storefront-Renderer-Rendered
X-Redis-Cache
X-Status
X-Sorting-Hat-ShopId
X-Shopify-Stage
X-Proxied
X-Routing-Service
X-Is-Bot
X-Cache-Enabled
X-Zipkin-Id
X-Rendered-As
X-Locale
X-App-Version
X-Backend-Host
X-Site-Version
X-Azure-Ref
X-Microcachable
X-Cluster
X-FW-Version
S-Cnection
X-Cache-Grace
X-Ratelimit-Limit
X-Forwarded-Host
X-TT-LOGID
X-AIR-PT
X-CSRF-Token
X-Trace-Id
X-Qloud-Router
Akamai-GRN
X-Platform
X-Revision
X-RateLimit-Limit
ServedBy
X-Cache-PHP
X-Varnish-Hostname
AMP-Access-Control-Allow-Source-Origin
X-Cache-NGX
X-EdgeConnect-Cache-Status
X-ATG-Version
X-Aspnetmvc-Version
Who
X-RCS-CacheZone
X-Via-CDN
Cache-Hits
X-Debug-Cache
X-Detected-As
Filterid
X-TX-ID
DB-Nickname
Country-Code
X-CCM
X-Akamai-Transformed
X-Dc
X-Cache-Host
X-Node-Name
X-B3-SpanId
X-CS
X-Adobe-Source
X-Varnish-Beresp-Grace
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Amzn-Remapped-Content-Length
SD-X-WS
X-CACHE-KEY
X-Varnish-Beresp-Ttl
X-Unique-Id
X-BCube-Filmed-By
X-Ms-Version
X-Ms-Request-Id
X-GEO
X-Varnish-Beresp-Status
Backend
X-Edge-Location-Klb
DCR-Processing-Time-Ms
BehaviorPad-Version
Expiry
X-Varnish-Cache-Hits
MD5-Digest
Fastly-Backend-Name
Meta-Geo-Continent
Machine
DCR-Decision-By
Fastcgi-X-Cache-Version
X-A-Dcw
X-Processor
X-PBS-Appsvrname
X-Request-UUID
X-Rewrite-Enabled
X-Rojux
X-PAYTM-SRV-ID
X-Owner
X-Location
X-NAPM-TraceId
X-Origin-CC
X-Origin-TTL
X-S
X-S-Cookie
X-VG-WebCache
X-VG-WebServer
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
X-Vdms-Version
X-Vdms-Path
X-ScT
X-Session-Fingerprint
X-SRCache-Key
X-Trv-Group
X-Level-Front-Cache
X-Generation-Time
X-Oss-Storage-Class
X-A-Dgt
X-A-Wwc
X-Aed
X-A-Dam
X-A-Ccd
Odigeo-Trace-Id
Rendered-Blocks
T-Server
X-A
X-Application
X-ARC
X-Destination
X-External-Request-Id
X-From
X-Generated-On
X-D
X-Connection-Hash
X-B-Cookie
X-Cache-Bucket
X-CF-Lambda-Fn
X-CF-Lambda-Version
Mobile-Detection-Method
X-Cache-NE
X-Oss-Request-Id
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
NGB
X-Oss-Server-Time
X-Varnish-Ttl
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Kraken-Routeconfig-Destination
X-Instrumentation
X-Time-Microsecs
CacheControlHeader
Cf-Device-Type
X-Has-Esi
Cache-Host
Pagetype
Path
Arc-Version
Content-Disposition
X-Magnolia-Registration
X-Irp-Debug
PB-PID
X-JWT-State
X-IP
Gh-Request-Id
Magicmarker
Host-ID
Esi-Enabled
Release
X-FC-Vary-Parameters
X-Device-Os
Wxu-Next-Region
Wxu-Next-Hostname
Wxu-Next-Commit
X-Azure-Ref-OriginShield
X-Backend-State
X-Cms-Context
X-Core-Value
X-Bip
X-Developers
V-Age
X-Fetched-On
X-Generated-In
X-Geo-Header
AKAMAI
X-GeoIP-City
Server-Host
Ssr
UCS
Thinkindot-Control
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
PB-RID
X-Is-Gdpr
X-OVcl-Cache
X-OVcl
X-Tumblr-Pixel-3
X-ServerID
X-Policy
X-B3-Traceid
X-Backend-TTL
X-Var-Ttl
X-Thinkindot-L3
X-Thanos
X-TrackingId
User-Cache-Control
X-FTR-Cache-Status
Sever-Int
X-Gen-Mode
NM-Fastcgi-Cache
X-Varnish-CookieHashed-On
X-Varnish-Hits
X-VarnishDD-TTL
True-Client-Country-4JS
X-Varnish-Remaining-TTL
Server-Hostname
X-Varnish-CookieINHashed-On
X-Generated-By
X-GeoIP
Platform
X-GoCache-CacheStatus
PFcat
X-User
X-Nc
Server-Ext
Origin
X-Variation
X-FTR-DC
X-Origin-Expires
X-VServer
X-Branch-Name
X-DefHash
X-Block-Status
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Developer
X-DefElseHash
X-Csrf-Jwt
X-Cache-Tags
X-FTR-Backend-Server
X-CGP
X-Cache-Info
X-Cache-Debug
X-Clientip
X-Planisys-CDN-Cache
X-Country-Code-Real
X-Fastly-Cache
X-Fastly-Backend
X-Wikidot-Backend
NGX
Vix-Hermes-Req-Id
Web-Mar-Node
X-FTR-Balancer
X-Eu-Site
X-Dispatcher-Server
X-Wikidot-Static-Cache
X-DPWN-IS-SECURE
X-Envoy-Decorator-Operation
X-Epic-Correlation-Id
X-VG-TLSProxy
X-SVT-ORM-VERSION
Cf-Bgj
X-Nginx-Cache-Key
CDN-Uid
CDN-RequestId
CDN-PullZone
CDN-RequestCountryCode
X-Mvc-Supplant-Cachable
X-Micro-Cache
X-Li-Pop
X-Li-Fabric
DSUID
X-Rebelmouse-Cache-Control
X-Ratelimit-Reset
X-Method
CDN-EdgeStorageId
CDN-CachedAt
Apple-News-Services-Handled
Apple-News-Services-Host
X-Origin-Response-Time
Adler-Geo
X-Origin
X-Old-Content-Length
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
X-Node-Id
CDN-Cache
CDCHOST
X-Platform-Server
X-NU-AKA-ACS-Version
C-Via
X-Rebelmouse-Surrogate-Control
X-LI-UUID
X-Hnp-Log
Is-Eu
X-FTR-Realm
X-Skip-Cache
Ha-Gx-Prefs
HA-Ipaddr
IsBot
L
Locid
X-SIPLIST1
Location
X-HN
L5d-Success-Class
X-Scheme
X-Request-URI
Fastly-SIE
HostName
X-FTR-Backend
Fastly-SWR
X-SVT-ORM-RULES
X-Reqid
X-Request-Host
X-NewRelic-App-Data
X-Amz-Meta-S3cmd-Attrs
X-DynaTrace-JS-Agent
X-ID
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Slack-Backend
X-Tb
X-Clara-WADP
Req-Svc-Chain
X-WADP-Cache
X-Gzip
X-LB-ID
X-Fmm-Version
X-Esi-Check
X-HS-Content-Campaign-Id
X-Gamma-Serve
X-Hash
X-Loc
X-Cache-Id
Cmstype
Cmsid
X-EC-Lua
Fastly-Drupal-HTML
X-Aicache-OS
On-Server
Rt-Fastcgi-Cache
X-Correlation-ID
X-Ratelimit-Remaining
X-Unique-ID
X-Sucuri-ID
X-Served-From
X-Swa-Ws
X-Vgn-Hpd-Reason
Svr
X-Servername
Kp-EeAlive
X-Varnish-Url
Xc-Version
X-APP-VERSION
Pics-Label
A
X-Via-Popv
X-PF-Uncompressing
X-Via-Popn
X-Mvc-Supplant-OutputCached
X-Via-Poph
X-Air-Hostname
X-FTR-Expires
X-Refresh
X-DC
Url
Viewtype
VivaBuild
M-TraceId
X-SaId
X-PHP-Backend
SID
X-JoinUs
X-NGENIX-Cache
X-NC
X-Cdn-Forward
SR-User-Adfree
Instruction
Cross-Origin-Opener-Policy
Tracecode
Arc-Country
X-Edge-Location
Cache-Key
X-CDN-Forward
TDXMobile
X-Cache-Var
X-Cache-Var-Map
X-CUA
MIME-Version
X-Vc
X-Matched-Rule
Lfy
NtCoent-Length
X-Service
X-Cdn-Origin
X-NCache
X-Sn-Servicetimems
CloudFront-Viewer-Country
X-Cache-Expires
X-Tb-Optimization-Total-Bytes-Saved
Content-Secure-Policy
X-Extlb
X-TraceId
Sid
Pramga
Server-ID
X-Cache-Backend
X-Cache-Ttl
X-CLOUD-TRACE-CONTEXT
X-Servedbyhost
X-Internal-Host
DataCenter
X-Core-Mission
X-Bc-Bl
X-Cache-Date
X-Wa
Geo-Info
X-Request-Start
X-Forwarded-Site
Source
Tcn
X-B3-Spanid
Surrogated-Key
FSS-Cache
Memcached
LB
Hostname
X-LI-Proto
X-Webkit-CSP-Report-Only
Geoip-Latitude
X-Proxy-Upstream
X-Req
GeoIp-Country-Code
X-Srv
X-HS-Status
X-FireWall-Protection
X-Via-NSCOPI
X-Esi
X-VCL-Version
Mail-Subject
X-VC-Cache
We-Hiring
X-Accel-Expires-Debug
X-Date
X-Error
X-Newrelic-Synthetics
Upgrade-Insecure-Requests
CACHE
X-VHOST
X-App
X-RateLimit-Limit-Second
Env
X-Rocket-Build-Number
X-Sigma
X-Sigma-Backend
X-RateLimit-Remaining-Second
X-Viewer-Country
X-Response-By
X-Varnish-Cacheable
X-HOST
X-CCDN-CacheTTL
X-Air-Source
X-Men
Resin-Trace
GeoIP-Latitude
GeoIP-Country-Code
X-CCDN-Origin-Time
Server-Ttl
X-MSEdge-Flight
X-PJAX-URL
X-MSEdge-Features
Request-ID
X-Vcl-Version
X-Li-Proto
X-Hcs-Proxy-Type
X-LiteSpeed-Cache-Control
X-Geo
X-Zone
X-TIM-N
X-Mg-Request-UUID
X-RPS
X-RPM
X-BBXSRF
X-DB
Xkeyi7
X-DI
X-DSS
CF-Cached-On
X-DW
X-RSL
Time
X-Proxy-Cachei7
Memory
X-ZONE
VNS-Age
X-RAMCache
VNS-Cache
X-Cs
X-WA
N-Cache
S-Rt
CPC-Cache
X-APP
CPC-Age
HitType
XServer
State
X-Action
ProcessTime
X-Air-Trace-Id
X-ServedByHost
X-Varnish-Authentication
X-Cache-ASPX
X-Cache-2
Fastcgi-Cache-TTL
X-Contensis-Viewer-Groups
My-App
X-HostName
X-UA
X-Cc-Via
X-Cc-Req-Id
X-Svr
D-Cc-Upstream
X-Region-Sid
Server-Id
X-Oss-Cdn-Auth
X-FPC
X-Minions-Version
X-Swift-Error
X-Dynatrace-Js-Agent
X-Provided-By
X-Cache-Type
Cache-Provider
X-FORWARDED-FOR
W
Mime-Version
X-Depends-On
Srv
X-Cdn-Request-ID
X-CSRF-TOKEN
X-URL
X-TIME
X-CF-Powered-By
CDN
X-Server-IP
X-Nyt-Route
X-BACKEND-TTL
OT-Force-Account-Verify
X-UnsetCookies
X-API-Version
X-Gdpr
X-Origin-Time
X-Fpc
X-Cache-Config
X-Dw-Trace-Id
X-Xrds-Location
X-Client-Ip
Cteonnt-Length
X-ServerName
X-Hello
X-Fastly-Request-Id
X-Shop-Environment
Cdn
X-Flog
X-ABtesting
Proxy-Connection
X-Tenant
X-Parent-Response-Time
X-Forwarded-Path
X-ND-Cache
X-Orig-Expires
Ohc-File-Size
X-Cache-Remote
Cross-Origin-Window-Policy
X-Akamai-Pragma-Client-IP
X-Sucuri-Cache
Datacenter
X-Check-Cacheable
X-Fastly-Backend-Reqs
WZWS-RAY
X-Pf-Uncompressing
X-Traceid
Media-Length
X-Pad
X-VC
X-Snapshot-Date
X-NodeID
X-Oracle-DMS-ECID
X-SD-PageType
Dnion-Transfer-Encoding
X-SN
X-NGINX-Cache
Vha6-Origin
X-Presslabs-Stats
Ohc-Cache-HIT
X-Erf-Stays-Bingo-Pdp-Web
X-Ftr-Request-Id
X-BBC-Edge-Cache-Status
X-Air-Pt
Cf-Ipcountry
X-SB
X-ElasticPress-Search
X-Via-PopV
X-Via-PopN
X-Via-PopH
X-LiteSpeed-Tag
X-Pjax-Url
PICS-Label
X-Ftr-Cache-Host
X-Webstats-RespID
X-Cluster-Node
Epwk-X-Cache
EpKe-Alive
X-Conf
X-Acquia-Application-Trace
Warning
X-IN-APIGATEWAY
X-Acquia-Site
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Cache-Tag
Xet-Cookie
X-Varnish-URL
X-Vcache
X-Akamai-ERRuleID
X-Akamai-ERPolicy
X-IN-APIGATEWAYSSL
X-Host-Name
X-Yottaa-OS
X-MiniProfiler-Ids
X-Ms-Meta-Originalurl
X-Lb-Id
X-Ms-Meta-Staticbatchstarttime
CountryCode
X-Ckpd-Fst-Backend
X-Cache-Status-Check
Count-Hit
X-Apw-Hits
X-C
X-Mg-Request-Id
X-V-Cache
URI
X-BBC-Origin-Response-Status
X-B3-Parentspanid
Phost
Ohc-Response-Time
NnCoection
X-Request-URL
Environment
X-Redis-Count
X-Redis-Duration-Ms
X-Render-Time
X-Debug-Cache-Fetch
X-Debug-Cache-Store
Content-Script-Type
Content-Style-Type
X-Apw-Access-Action
X-Apw-Access-Object
X-Litespeed-Cache-Control
X-Amz-Meta-Cb-Modifiedtime
Inserted-Into-Cache-At
X-Tid
X-Varnish-Beresp-TTL
X-Apw-Access-Token