Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
Link
X-XSS-Protection
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Request-Id
X-Varnish
Access-Control-Allow-Methods
X-Xss-Protection
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Cache-Status
X-Generator
X-Cacheable
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
X-Request-ID
Content-Encoding
X-CDN
X-Ua-Compatible
Feature-Policy
X-AspNetMvc-Version
Status
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Upgrade
X-Via
Access-Control-Max-Age
Keep-Alive
X-Ws-Request-Id
X-Age
X-Robots-Tag
X-AH-Environment
X-Turbo-Charged-By
Request-Context
EagleId
X-Proxy-Cache
X-Cache-Group
Server-Timing
X-Backend
X-Server
X-Hacker
X-Dns-Prefetch-Control
Host-Header
Report-To
X-Server-Powered-By
X-Amz-Request-Id
X-Nginx-Cache-Status
X-Amz-Id-2
Grace
X-UA-Device
X-Rq
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Page-Speed
Cf-Railgun
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
X-Amz-Version-Id
NEL
X-Cache-Spec
X-Device
X-CST
Allow
X-Vhost
X-WebKit-CSP
X-Host
X-Backend-Server
Xkey
X-Server-Id
EagleEye-TraceId
X-Dispatcher
Surrogate-Control
X-Node
Request-Id
Content-Location
X-Response-Time
X-Akam-SW-Version
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
P3p
X-ASPNET-VERSION
X-Ruxit-JS-Agent
X-Cache-Lookup
X-Application-Context
X-Ac
Accept-Ch
X-Country
X-Mod-Pagespeed
X-Template
Accept-CH
Accept-Ch-Lifetime
X-Language
X-Readtime
X-Cloud-Trace-Context
Accept-CH-Lifetime
X-B3-TraceId
MS-Author-Via
Rating
X-HW
X-Url
X-Origin-Cache
X-Cnection
X-MS-InvokeApp
X-Vname
X-TtlSet
X-PC
Edge-Control
X-Clacks-Overhead
X-ESI
X-GitHub-Request-Id
X-Trace
X-ORACLE-DMS-RID
X-Middleton-Response
X-Sol
Display
Pagespeed
Response
X-Middleton-Display
X-Varnish-TTL
X-Content-Type
X-ORACLE-DMS-ECID
X-D2id
Verso
Arr-Disable-Session-Affinity
X-Kinja
X-GoogleNews-Bot
X-Exp-Variant
X-Use-Magma
X-Exp-Id
X-Kinja-Server
X-Cdn-Fetch
X-Kinja-Build
X-Kinja-Revision
X-Vcap-Request-Id
X-Country-Code
X-Goog-Hash
X-Rack-Cache
X-Powered-By-Plesk
X-TTL
X-Navigation-Version
X-Oneagent-Js-Injection
Service-Worker-Allowed
X-VARITI-CCR
X-Amz-Rid
X-Server-Name
X-Abt-Application-Version
X-Buckets
X-Fastly-Request-ID
X-Client-IP
Fastly-Restarts
X-Cached
X-Cache-TTL
X-FastCGI-Cache
X-MSEdge-Ref
X-Release
X-Element-Page-Cache
X-Dw-Request-Base-Id
X-SharePointHealthScore
SPRequestGuid
X-NF-Request-ID
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
SPRequestDuration
SPIisLatency
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
Public-Key-Pins
Access-Control-Request-Method
X-Webkit-CSP
RTSS
Cache-Tag
AR-ATIME
X-LLID
AR-CACHE
X-Edge
Ar-Sid
AR-Request-ID
AR-PoweredBy
X-SRCache-Fetch-Status
X-Powered-CMS
X-SRCache-Store-Status
X-Ezoic-Cdn
X-Upstream
Content-MD5
X-HP-Webp
X-Version
X-Jurisdiction
S
X-Origin-Upstream-Status
X-Recruiting
X-Mid
X-MCACHE
X-ECACHE
Fusion-Template-Id
Fusion-Source
Fusion-Component-Id
Charset
X-Mg-S
Fusion-Content-Id
Fusion-Content-Source
Fusion-Deployment-Id
X-Px
X-Ruxit-Js-Agent
X-Content-Digest
X-PressLabs-Stats
X-DynaTrace
X-Kinsta-Cache
Fastcgi-Cache
X-T
Cache-Tags
X-Litespeed-Cache
X-Amz-Server-Side-Encryption
X-Fastcgi-Cache
X-Logged-In
X-Accel-Expires
Filters
X-Forwarded-Proto
X-Content-Security-Policy-Report-Only
Edge-Cache-Tag
X-Ttl
Server-Node
Front-End-Https
X-Id
MicrosoftSharePointTeamServices
TP-Cache
TP-L2-Cache
Server-Name
X-Correlation-Id
X-Grace
X-Forwarded-For
TCN
Nginx-Cache
X-Hits
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Request-Received
X-Amzn-Trace-Id
X-Debug
X-Request-Processing-Time
X-B3-Sampled
X-Shield-Request-Id
X-Request-Handler-Origin-Region
X-Microsite
X-Varnish-Age
X-Server-ID
Surrogate-Key
X-Yandex-Sdch-Disable
X-AppVersion
X-Activity-Id
X-Az
X-Amz-Replication-Status
X-F-Cache
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Combine-CSS
X-XRDS-LOCATION
X-XRDS-Location
Alternate-Protocol
X-Origin-Server
X-Ser
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Generation
X-GUploader-UploadID
X-Goog-Storage-Class
X-DIS-Request-ID
Nel
Accept-Charset
X-Geo-Country
X-Rid
X-Frontend
X-NWS-LOG-UUID
X-Git-Hash
Section-Io-Cache
Host
X-Time
X-Cache-Age
X-Respond-Thread
X-Pinterest-Direct
X-Cache-Key
X-Upgrade-Enabled
X-VCache
X-LB-Cache
X-DataDome
Access-Control-Allow-Method
X-Mobile-URL
X-Hostname
X-Seen-By
MS-CV
Cache
Paypal-Debug-Id
X-Type
ServerID
X-AOL-HN
X-TT
X-Source
X-IPLB-Instance
X-RateLimit-Remaining
Payment
X-Content-Options
X-Varnish-Backend
X-Daa-Tunnel
Healthy
X-B-Cache
X-Request-Guid
X-Providence-Cookie
X-Flags
X-FTR-Request-ID
X-Route-Name
X-Signature
X-Is-Crawler
X-App-Environment
X-Whom
X-Aspnet-Duration-Ms
X-Cache-Action
Cleartype
X-Page-Id
X-Debug-Info
Fastcgi-Useragent
X-Jobs
X-WebKit-CSP-Report-Only
X-Load-Cache
X-N
X-FB-Debug
Realpath
X-Contextid
X-Webkit-Csp
Powered-By-ChinaCache
X-Mobile
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Browser-Type
Node
X-Rule
Refresh
X-Drupal-Cache-Tags
X-Wix-Request-Id
X-Cache-Expired-At
X-Original-Request-Id
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Accel-Buffering
X-TEC-API-ROOT
X-Response-Served-From
X-Zen-Fury
X-RTag
Version
DC
Ms-Operation-Id
Referer-Policy
X-Framework
X-Cacheable-TTL
Access-Control-Request-Headers
X-B
X-Cluster-Name
X-Distributor
X-Instance
X-Content-Powered-By
X-HTML-Minification-Powered-By
X-Proxy
X-Cache-Control
X-Tt-Trace-Host
VIX-Pulpo-Upstream-Status
X-Via-JSL
X-Real-IP
X-Tt-Trace-Tag
X-RemovedCookies
VIX-Pulpo-Node
X-Drupal-Cache-Contexts
X-Page-View
X-Cache-Time
Eomportal-Instance
X-UUID
X-ProcessESI
X-FW-Type
Viewport
X-FW-Serve
X-FW-Hash
X-FW-Dynamic
X-FW-Static
X-IPS-LoggedIn
X-FW-Server
X-Region
Countrycode
X-Akamai-Edgescape
X-Cached-By
Liferay-Portal
X-FireWall-Port
X-Cache-Operation
X-Cache-Rule
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Cache-Hit
X-G
X-Tumblr-Pixel-0
X-Tumblr-User
X-Pass-Why
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-L-Path
X-Environment-Context
X-App-Server
SRV
Server-Info
X-Nginx-Cache
DynaTrace
CF-IPCountry
X-Debug-IsConnected
Section-Io-Origin-Status
X-Debug-IsPreview
Section-Io-Id
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
Xserver
X-Protected-By
X-Www-Served-By
X-User-Agent
From-Origin
Ec-Rule-Version
Webserver
X-Tumblr-Pixel-2
GEO-INFO
X-Device-Type
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
X-Adobe-Content
X-Varnish-Grace
X-Adobe-Loc
Meta-Geo
X-ES-SERVER
X-UPSTREAM-Address
X-RN-RSRV
X-Mode
X-Handled-By
X-Endurance-Cache-Level
X-Hl-Ver
Cache-Tv-Group
X-Uri
X-MP-GENERATED-AT
X-Backend-Name
X-FB-TRIP-ID
TWC-Privacy
Webcakes-App-Name
TWC-Locale-Group
X-Section
TWC-GeoIP-LatLong
Webcakes-App-Version
Webcakes-Region
X-Origin-Hint
X-Varnishpool
X-PHP-Host
X-Access
TWC-GeoIP-Country
TWC-Device-Class
Decoy-Debug-Key
Decoy-Debug-Status
Decoy-Debug-TTL
Fastly-SSL
X-Labrador-Cache-Channel
Retry-After
TWC-Connection-Speed
X-Pubstack
Property-Id
Cache-Status
X-Format
X-PCL
X-Be
X-NYM-Debug-Backend
X-Ratelimit-Limit
X-Storage
X-OCL
X-Timing-Wait
X-UA-Device-Type
Protected
X-Origin-Date
X-Web-Node
Cache-Name
X-Server-W
X-Human
X-Cache-Server
X-R9-Blue-Green-Version
Selected-Fe
Apigw-Requestid
X-Proto
X-Proxy-Build
X-BYPASS-REASON
X-AWS-Id
X-Request-Time
Frame-Options
X-ProxyCache-Status
X-Sql-Count
X-ProxyCache-Key
Mn-Server-Ip
X-Soup
X-LJ-Flow-ID
X-WA-Info
X-LAGOON
X-Sql-Duration-Ms
X-VWS-Id
X-Loop
X-Cache-TTL-Remaining
X-Hyper-Cache
X-No-Session
X-Varnish-Server
X-Xfnlog-Site
Azure-RegionName
X-Say-TTL
X-SayCDN-TTL
X-PERF
X-Say-Cacheable
X-ApacheServer
X-FW-Version
X-S-Maxage
Country
Azure-Version
Azure-InstanceId
X-TNCMS
X-Hosted-By
X-Redis-Cache
X-Status
Azure-SlotName
Azure-SiteName
X-Alternate-Cache-Key
X-Locale
X-Routing-Service
X-Sorting-Hat-ShopId
X-Proxied
X-ShardId
X-ShopId
X-Site-Version
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Zipkin-Id
X-Storefront-Renderer-Rendered
X-Via-Fastly
X-Forwarded-Host
X-TT-LOGID
X-Cache-Grace
X-Cluster
X-CCM
X-GG-Cache-Date
X-AIR-PT
X-TA-CDN-Provider
X-Info
X-Rendered-As
X-Is-Bot
X-Node-Name
X-SRV
X-Qloud-Router
S-Cnection
AMP-Access-Control-Allow-Source-Origin
X-Microcachable
X-Revision
X-Cache-Enabled
X-Content-Age
X-Proxy-Cache-Status
Uber-Trace-Id
X-Dc
X-Azure-Ref
X-Via-CDN
X-Platform
Cache-Hits
X-NWS-UUID-VERIFY
X-Backend-Host
X-CSRF-Token
X-Varnish-Ttl
X-FTR-Backend
X-App-Version
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Realm
Amp-Access-Control-Allow-Source-Origin
X-Ratelimit-Remaining
X-Aspnetmvc-Version
X-FTR-DC
X-FTR-Cache-Status
X-FTR-Balancer
X-Detected-As
X-Cache-Host
Akamai-GRN
X-Amz-Meta-S3cmd-Attrs
X-Amzn-Remapped-Content-Length
X-Amz-Apigw-Id
X-Amzn-RequestId
X-EdgeConnect-Cache-Status
X-ATG-Version
ServedBy
X-Trace-Id
X-Cache-PHP
X-B3-SpanId
X-Cache-NGX
X-Oss-Object-Type
X-CS
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Storage-Class
X-RCS-CacheZone
X-Oss-Hash-Crc64ecma
X-Varnish-Hostname
X-FTR-Expires
SD-X-WS
X-Debug-Cache
X-Time-Microsecs
X-ID
Tracecode
X-Air-Hostname
X-BCube-Filmed-By
X-Correlation-ID
X-Nc
DB-Nickname
X-ServerID
HostName
X-Backend-TTL
X-Akamai-Transformed
X-Tb
Backend
X-NewRelic-App-Data
X-Ms-Request-Id
X-Ms-Version
X-Adobe-Source
Mobile-Detection-Method
X-TX-ID
Odigeo-Trace-Id
BehaviorPad-Version
Meta-Geo-Continent
Fastcgi-X-Cache-Version
X-CF-Lambda-Fn
MD5-Digest
X-Destination
X-Connection-Hash
X-Magnolia-Registration
Expiry
X-CF-Lambda-Version
X-Cache-NE
T-Server
X-A
X-A-Ccd
DCR-Processing-Time-Ms
X-External-Request-Id
DCR-Decision-By
Machine
X-A-Dam
X-A-Dcw
X-ARC
X-B-Cookie
X-Application
X-Aed
X-A-Dgt
X-A-Wwc
Rendered-Blocks
X-D
X-Rewrite-Enabled
X-Rojux
X-DynaTrace-JS-Agent
X-S
X-Processor
X-PBS-Appsvrname
X-Origin-CC
X-Origin-TTL
X-Owner
X-PAYTM-SRV-ID
X-S-Cookie
X-ScT
X-VG-WebServer
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-VG-WebCache
X-Vdms-Version
X-Session-Fingerprint
X-SRCache-Key
X-Trv-Group
X-Vdms-Path
X-NAPM-TraceId
X-Request-UUID
X-Generation-Time
X-Location
X-From
X-Generated-On
X-Level-Front-Cache
X-Cache-Var
X-Cache-Var-Map
X-Unique-Id
X-Cms-Context
X-Tumblr-Pixel-3
X-TrackingId
X-Generated-In
On-Server
X-Thanos
Pagetype
Path
X-Thinkindot-L3
Arc-Version
Content-Disposition
X-Developers
Cf-Device-Type
CacheControlHeader
X-Device-Os
X-FC-Vary-Parameters
Fastly-Backend-Name
PB-PID
Magicmarker
Locid
Host-ID
Gh-Request-Id
X-Core-Value
Release
V-Age
Wxu-Next-Commit
X-Policy
UCS
X-Is-Gdpr
Wxu-Next-Hostname
Wxu-Next-Region
X-Micro-Cache
X-Azure-Ref-OriginShield
X-OVcl
X-OVcl-Cache
X-JWT-State
X-Reqid
X-Fastly-Cache
X-Has-Esi
Thinkindot-CacheControl
Server-Host
X-GeoIP-City
X-Mvc-Supplant-Cachable
Thinkindot-CacheControl-Type
X-Cache-Bucket
Thinkindot-Control
X-Irp-Debug
X-Bip
X-HS-Content-Campaign-Id
PB-RID
X-Fetched-On
X-Sucuri-ID
X-CACHE-KEY
X-Varnish-Beresp-Grace
X-Unique-ID
X-Varnish-Cache-Hits
X-B3-Traceid
Who
User-Cache-Control
X-GEO
X-Esi-Check
X-Eu-Site
X-DPWN-IS-SECURE
X-Developer
X-Fastly-Backend
X-Dispatcher-Server
X-Envoy-Decorator-Operation
X-Gen-Mode
X-Geo-Header
X-GeoIP
X-Wikidot-Static-Cache
Ssr
Cache-Host
X-Fmm-Version
X-Csrf-Jwt
X-Cache-Id
X-Swa-Ws
X-Cache-Debug
X-Branch-Name
X-Backend-State
X-Block-Status
X-Cache-Tags
X-CGP
X-CUA
X-DefElseHash
X-Wikidot-Backend
X-Cache-Info
X-SVT-ORM-VERSION
X-Clientip
X-DefHash
X-WADP-Cache
X-Ratelimit-Reset
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Varnish-CookieINHashed-On
X-Platform-Server
X-Origin-Response-Time
X-VarnishDD-TTL
X-Varnish-Remaining-TTL
X-Varnish-CookieHashed-On
X-Request-Host
X-User
X-SIPLIST1
X-SVT-ORM-RULES
X-Var-Ttl
X-Variation
X-Request-URI
Apple-News-Services-Request-Url
X-Origin-Expires
X-RateLimit-Limit
X-Cdn-Forward
X-VServer
X-IP
X-Hnp-Log
X-HN
X-Gzip
Web-Mar-Node
X-Li-Fabric
X-Li-Pop
X-NU-AKA-ACS-Version
X-Old-Content-Length
X-Origin
X-Node-Id
X-Nginx-Cache-Key
X-LI-UUID
X-VG-TLSProxy
X-GoCache-CacheStatus
X-Clara-WADP
Apple-News-Services-Host
PFcat
Country-Code
NM-Fastcgi-Cache
Apple-News-Services-Handled
NGX
Platform
CDN-Uid
CDN-PullZone
Sever-Int
Server-Hostname
CDN-RequestCountryCode
Server-Ext
CDN-RequestId
AKAMAI
Vix-Hermes-Req-Id
Adler-Geo
Ha-Gx-Prefs
DSUID
Esi-Enabled
Fastly-SIE
Fastly-SWR
HA-Ipaddr
Instruction
Location
X-Varnish-Beresp-Ttl
L5d-Success-Class
IsBot
Is-Eu
SR-User-Adfree
Cf-Bgj
CDN-EdgeStorageId
CDCHOST
Apple-News-Services-Parsed-Url
CDN-Cache
True-Client-Country-4JS
CDN-CachedAt
C-Via
X-Varnish-Beresp-Status
X-EC-Lua
L
X-Gamma-Serve
X-Scheme
X-Method
Origin
X-Aicache-OS
X-Skip-Cache
Rt-Fastcgi-Cache
X-LB-ID
X-Hash
X-Slack-Backend
X-Generated-By
X-Varnish-Hits
X-CLOUD-TRACE-CONTEXT
X-Cache-Backend
Lfy
Fastly-Drupal-HTML
X-Matched-Rule
X-Varnish-Url
X-Mvc-Supplant-OutputCached
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Loc
X-APP-VERSION
Filterid
Geo-Info
X-Epic-Correlation-Id
CloudFront-Viewer-Country
X-NCache
X-Via-Poph
Pics-Label
X-Via-Popn
X-Via-Popv
Sid
X-PF-Uncompressing
X-Cdn-Origin
X-Planisys-CDN-TTL
X-Sn-Servicetimems
X-Refresh
X-Planisys-CDN-Rules
Pramga
X-Planisys-CDN-Cache
X-Cache-Expires
X-Servername
X-Cache-Date
X-Core-Mission
Url
Req-Svc-Chain
X-Tb-Optimization-Total-Bytes-Saved
Cmstype
X-TraceId
Cmsid
NGB
Kp-EeAlive
Tcn
X-Served-From
X-Request-Start
X-Error
VivaBuild
Viewtype
Svr
MIME-Version
A
X-DC
X-FireWall-Protection
Cache-Key
X-Varnish-Cacheable
M-TraceId
Source
X-Webkit-CSP-Report-Only
X-Response-By
Cross-Origin-Opener-Policy
X-Vgn-Hpd-Reason
X-Srv
Server-ID
X-NC
X-Proxy-Cachei7
Arc-Country
Xkeyi7
X-Servedbyhost
X-Wa
X-Air-Source
TDXMobile
X-HS-Status
GeoIp-Country-Code
Geoip-Latitude
X-PHP-Backend
Server-Ttl
X-BBXSRF
X-SaId
X-CDN-Forward
X-NGENIX-Cache
N-Cache
X-B3-Spanid
Content-Secure-Policy
HitType
X-JoinUs
X-Vcl-Version
SID
NtCoent-Length
X-Erf-Stays-Bingo-Pdp-Web
X-Edge-Location
S-Rt
X-Cache-Remote
X-Geo
X-LiteSpeed-Cache-Control
X-LI-Proto
X-Vc
X-Internal-Host
Resin-Trace
X-Cache-2
X-Esi
X-Service
CACHE
DataCenter
X-Cc-Req-Id
D-Cc-Upstream
X-Li-Proto
X-Contensis-Viewer-Groups
X-Cc-Via
X-Varnish-Authentication
X-Cache-ASPX
Cteonnt-Length
X-HOST
Request-ID
X-Sucuri-Cache
XServer
Hostname
X-Viewer-Country
X-VCL-Version
Cross-Origin-Window-Policy
X-RAMCache
FSS-Cache
X-Forwarded-Site
X-Svr
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
Ohc-File-Size
X-Extlb
X-Host-Name
X-HostName
X-UA
GeoIP-Country-Code
GeoIP-Latitude
X-Via-NSCOPI
X-DW
X-RSL
X-Bc-Bl
X-TIM-N
X-RPS
X-RPM
X-DB
X-DSS
X-Newrelic-Synthetics
X-DI
X-ServedByHost
X-Server-IP
X-WA
CF-Cached-On
Mail-Subject
Memcached
X-Accel-Expires-Debug
We-Hiring
Surrogated-Key
X-Cache-Config
X-Cs
X-API-Version
X-Nyt-Route
X-VC
X-App
X-Origin-Time
X-Date
LB
X-VC-Cache
X-Gdpr
X-Req
X-FPC
X-Proxy-Upstream
X-Instrumentation
X-Action
X-PJAX-URL
X-ZONE
X-Kraken-Routeconfig-Destination
X-NodeID
X-Kraken-Loop-Name
X-SN
X-Server-Lifecycle-Phase
ProcessTime
X-RateLimit-Remaining-Second
Cache-Provider
X-Check-Cacheable
Env
X-RateLimit-Limit-Second
X-Dynatrace-Js-Agent
Ohc-Cache-HIT
X-Sigma-Backend
X-Men
X-Air-Trace-Id
Upgrade-Insecure-Requests
Server-Id
X-Region-Sid
X-APP
X-Rocket-Build-Number
X-Oss-Cdn-Auth
X-Sigma
X-SB
X-Webstats-RespID
X-CF-Powered-By
X-Fpc
X-URL
X-Provided-By
X-Swift-Error
X-Edge-Location-Klb
X-SD-PageType
X-Depends-On
Memory
W
X-MSEdge-Features
Mime-Version
X-MSEdge-Flight
Time
CPC-Age
X-FORWARDED-FOR
VNS-Age
CPC-Cache
VNS-Cache
X-Cdn-Request-ID
Srv
X-TIME
Cdn
CDN
X-Render-Time
X-CSRF-TOKEN
X-Dw-Trace-Id
X-UnsetCookies
X-BBC-Edge-Cache-Status
X-BACKEND-TTL
X-Ftr-Cache-Host
X-Zone
X-Client-Ip
X-Akamai-Pragma-Client-IP
X-Fastly-Request-Id
X-NGINX-Cache
X-Flog
Dnion-Transfer-Encoding
X-Hello
EpKe-Alive
X-ABtesting
X-Parent-Response-Time
X-Fastly-Backend-Reqs
X-Dynatrace
Vha6-Origin
Proxy-Connection
Media-Length
Processtime
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
X-Acquia-Site
X-Auto-Login
X-Pad
X-Pf-Uncompressing
X-FTR-Cache-Host
X-Cache-Tag
X-Oracle-DMS-ECID
X-ServerName
X-Presslabs-Stats
My-App
State
Fastcgi-Cache-TTL
X-Worker
Datacenter
X-Ua
X-BBC-Origin-Response-Status
PICS-Label
Epwk-X-Cache
X-Snapshot-Date
X-Minions-Version
X-Via-PopN
X-Via-PopH
X-Via-PopV
X-LiteSpeed-Tag
X-Cluster-Node
X-CACHE-AGE
Cf-Ipcountry
X-Request-URL
X-Varnish-Beresp-TTL
X-Varnish-URL
X-IN-APIGATEWAY
X-Akamai-ERRuleID
Xet-Cookie
X-ElasticPress-Query
X-Lb-Id
X-Ms-Meta-Originalurl
X-Ms-Meta-Staticbatchstarttime
X-ElasticPress-Search
X-IN-APIGATEWAYSSL
X-Vcache
X-MiniProfiler-Ids
X-Akamai-ERPolicy
CountryCode
X-Air-Pt
X-Tx-Id
X-Apw-Hits
Content-Style-Type
X-Pjax-Url
Content-Script-Type
X-Litespeed-Cache-Control
X-Apw-Access-Object
X-Mg-Request-UUID
Warning
X-Mg-Request-Id
X-Apw-Access-Action
X-Cache-Status-Check
X-Apw-Access-Token
X-Debug-Cache-Store
Ohc-Response-Time
OT-Force-Account-Verify
X-C
Environment
Phost
NnCoection
X-B3-Parentspanid
X-Debug-Cache-Fetch
X-Storefront-Renderer-Verified
X-Amz-Meta-Cb-Modifiedtime
X-Redis-Duration-Ms
X-Tid
URI
X-Traceid
Inserted-Into-Cache-At
X-Redis-Count