Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
X-XSS-Protection
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
X-Request-Id
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Xss-Protection
X-Cache-Status
X-Generator
X-Cacheable
X-DNS-Prefetch-Control
X-Request-ID
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Content-Encoding
X-CDN
X-Ua-Compatible
Feature-Policy
X-AspNetMvc-Version
Status
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Upgrade
X-Via
Access-Control-Max-Age
Keep-Alive
X-Ws-Request-Id
X-Age
X-Robots-Tag
X-AH-Environment
X-Turbo-Charged-By
EagleId
Request-Context
X-Proxy-Cache
X-Cache-Group
Server-Timing
X-Backend
X-Server
X-Hacker
X-Dns-Prefetch-Control
Report-To
Host-Header
X-Server-Powered-By
X-Amz-Request-Id
X-Nginx-Cache-Status
X-Amz-Id-2
Grace
X-UA-Device
X-Rq
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Page-Speed
Cf-Railgun
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
X-Amz-Version-Id
X-Cache-Spec
X-Device
X-CST
NEL
Allow
X-Vhost
X-WebKit-CSP
X-Host
X-Backend-Server
Xkey
X-Server-Id
EagleEye-TraceId
X-Dispatcher
Surrogate-Control
X-Node
Request-Id
Content-Location
X-Response-Time
X-Akam-SW-Version
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
P3p
X-ASPNET-VERSION
Accept-Ch
X-Ruxit-JS-Agent
X-Cache-Lookup
X-Application-Context
X-Ac
X-Country
X-Mod-Pagespeed
X-Template
Accept-Ch-Lifetime
X-Language
X-Readtime
X-Cloud-Trace-Context
X-B3-TraceId
Accept-CH
MS-Author-Via
Accept-CH-Lifetime
Rating
X-HW
X-Url
X-Origin-Cache
X-Cnection
X-MS-InvokeApp
X-PC
X-TtlSet
X-Vname
Edge-Control
X-Clacks-Overhead
X-ESI
X-GitHub-Request-Id
X-Trace
X-ORACLE-DMS-RID
X-Varnish-TTL
X-ORACLE-DMS-ECID
X-Middleton-Display
Response
X-Sol
X-Content-Type
Pagespeed
Display
X-Middleton-Response
Verso
Arr-Disable-Session-Affinity
X-Kinja
X-GoogleNews-Bot
X-Exp-Variant
X-Exp-Id
X-Kinja-Server
X-Use-Magma
X-Cdn-Fetch
X-Kinja-Build
X-Kinja-Revision
X-Vcap-Request-Id
X-D2id
X-Country-Code
X-Rack-Cache
X-Goog-Hash
X-Powered-By-Plesk
X-TTL
X-Oneagent-Js-Injection
X-Amz-Rid
Service-Worker-Allowed
X-VARITI-CCR
X-Navigation-Version
X-Abt-Application-Version
X-Server-Name
X-Buckets
X-Fastly-Request-ID
X-Client-IP
Fastly-Restarts
X-Cached
X-Cache-TTL
X-FastCGI-Cache
X-MSEdge-Ref
X-Release
X-Element-Page-Cache
X-Dw-Request-Base-Id
X-SharePointHealthScore
SPRequestGuid
X-NF-Request-ID
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
SPRequestDuration
SPIisLatency
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
Public-Key-Pins
Access-Control-Request-Method
X-Webkit-CSP
RTSS
Cache-Tag
AR-ATIME
X-LLID
AR-CACHE
AR-PoweredBy
Ar-Sid
AR-Request-ID
X-Edge
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Powered-CMS
X-Ezoic-Cdn
X-Upstream
Content-MD5
X-HP-Webp
X-Jurisdiction
X-Version
X-Origin-Upstream-Status
S
X-Recruiting
X-Mg-S
Charset
Fusion-Template-Id
X-MCACHE
X-ECACHE
X-Mid
Fusion-Deployment-Id
Fusion-Component-Id
Fusion-Content-Source
Fusion-Content-Id
Fusion-Source
X-Px
X-Ruxit-Js-Agent
X-Content-Digest
X-PressLabs-Stats
X-DynaTrace
X-Kinsta-Cache
Cache-Tags
X-T
Fastcgi-Cache
X-Litespeed-Cache
X-Fastcgi-Cache
X-Id
X-Amz-Server-Side-Encryption
X-Accel-Expires
Filters
X-Logged-In
X-Forwarded-Proto
X-Content-Security-Policy-Report-Only
Edge-Cache-Tag
X-Ttl
Server-Node
MicrosoftSharePointTeamServices
Front-End-Https
TP-L2-Cache
TP-Cache
X-Correlation-Id
Server-Name
X-Grace
Nel
X-Forwarded-For
TCN
X-Hits
X-Kong-Proxy-Latency
Nginx-Cache
X-Kong-Upstream-Latency
X-Amzn-Trace-Id
X-Debug
X-Request-Received
X-Request-Processing-Time
X-B3-Sampled
X-Shield-Request-Id
X-Request-Handler-Origin-Region
X-Microsite
X-Varnish-Age
Surrogate-Key
X-Yandex-Sdch-Disable
X-Az
X-AppVersion
X-Activity-Id
X-F-Cache
X-HS-Combine-CSS
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Cache-Config
X-Amz-Replication-Status
X-XRDS-LOCATION
X-XRDS-Location
X-Ser
Alternate-Protocol
X-Origin-Server
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Storage-Class
X-DIS-Request-ID
Accept-Charset
X-Frontend
X-Geo-Country
X-Rid
X-NWS-LOG-UUID
X-Git-Hash
Section-Io-Cache
Host
X-Cache-Age
X-Time
X-Respond-Thread
X-Pinterest-Direct
X-Cache-Key
X-LB-Cache
X-VCache
Access-Control-Allow-Method
X-Upgrade-Enabled
X-Mobile-URL
X-DataDome
X-Seen-By
X-Hostname
Cache
X-Server-ID
Paypal-Debug-Id
X-Type
MS-CV
X-TT
X-IPLB-Instance
X-Source
ServerID
X-AOL-HN
X-RateLimit-Remaining
X-Daa-Tunnel
X-Content-Options
Payment
X-Route-Name
X-FTR-Request-ID
X-Request-Guid
X-Providence-Cookie
X-Signature
X-Is-Crawler
X-Flags
X-B-Cache
X-Whom
X-App-Environment
X-Varnish-Backend
Healthy
X-Aspnet-Duration-Ms
X-Cache-Action
Cleartype
X-Debug-Info
X-Page-Id
Fastcgi-Useragent
X-Jobs
X-WebKit-CSP-Report-Only
X-Load-Cache
X-N
X-FB-Debug
X-Contextid
Realpath
Powered-By-ChinaCache
X-Webkit-Csp
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Erf-Bev-Bev
X-Mobile
Node
X-Rule
Refresh
X-Response-Served-From
X-TEC-API-ROOT
X-Accel-Buffering
X-Cache-Expired-At
X-Wix-Request-Id
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Original-Request-Id
X-Drupal-Cache-Tags
Version
DC
X-Zen-Fury
Ms-Operation-Id
X-Framework
X-RTag
Referer-Policy
X-Cacheable-TTL
X-Instance
X-B
X-HTML-Minification-Powered-By
X-Cluster-Name
X-Proxy
Access-Control-Request-Headers
VIX-Pulpo-Node
X-Distributor
X-Cache-Time
X-Content-Powered-By
Eomportal-Instance
X-Cache-Control
VIX-Pulpo-Upstream-Status
X-Real-IP
X-Page-View
X-Via-JSL
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Drupal-Cache-Contexts
X-FW-Hash
X-FW-Static
X-FW-Dynamic
X-FW-Type
X-IPS-LoggedIn
X-UUID
Viewport
X-Region
X-FW-Serve
X-FW-Server
Countrycode
X-Akamai-Edgescape
X-Cached-By
X-ProcessESI
X-RemovedCookies
Liferay-Portal
X-Cache-Rule
X-Cache-Operation
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-FireWall-Port
X-G
X-Cache-Hit
X-Pass-Why
X-Tumblr-Pixel
X-Environment-Context
X-Tumblr-User
X-L-Path
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-App-Server
Server-Info
Xserver
SRV
X-Nginx-Cache
CF-IPCountry
DynaTrace
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
Section-Io-Id
X-Debug-IsConnected
X-Debug-IsPreview
X-Protected-By
X-Www-Served-By
X-User-Agent
Ec-Rule-Version
Webserver
From-Origin
GEO-INFO
X-Tumblr-Pixel-2
X-Device-Type
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
X-Adobe-Content
X-Adobe-Loc
X-UPSTREAM-Address
Meta-Geo
X-Mode
X-ES-SERVER
X-RN-RSRV
X-Handled-By
X-Varnish-Grace
Cache-Tv-Group
X-MP-GENERATED-AT
X-Endurance-Cache-Level
X-FB-TRIP-ID
X-Backend-Name
X-Uri
X-Hl-Ver
Decoy-Debug-TTL
Fastly-SSL
Webcakes-Region
X-Be
Webcakes-App-Version
X-Access
Webcakes-App-Name
Decoy-Debug-Key
X-PCL
X-PHP-Host
Decoy-Debug-Status
TWC-GeoIP-LatLong
Property-Id
X-Pubstack
Cache-Status
Retry-After
TWC-Connection-Speed
TWC-Device-Class
TWC-Locale-Group
X-Section
TWC-GeoIP-Country
X-Storage
TWC-Privacy
X-Origin-Hint
X-Format
X-Labrador-Cache-Channel
X-Ratelimit-Limit
X-NYM-Debug-Backend
X-OCL
X-WA-Info
Mn-Server-Ip
X-Proto
X-LJ-Flow-ID
Selected-Fe
X-R9-Blue-Green-Version
Apigw-Requestid
X-Server-W
X-Timing-Wait
X-BYPASS-REASON
X-Varnishpool
X-LAGOON
X-Soup
X-Proxy-Build
X-ProxyCache-Status
X-Cache-Server
X-Sql-Duration-Ms
Frame-Options
X-Human
X-ProxyCache-Key
X-Request-Time
X-AWS-Id
X-VWS-Id
Protected
X-Origin-Date
X-Sql-Count
X-UA-Device-Type
X-Web-Node
Cache-Name
X-Hyper-Cache
X-Hosted-By
X-FW-Version
X-TNCMS
X-Varnish-Server
X-Xfnlog-Site
Azure-SlotName
X-PERF
Azure-SiteName
X-SayCDN-TTL
X-Say-TTL
X-ApacheServer
X-Say-Cacheable
X-Redis-Cache
Country
X-Loop
X-Status
X-No-Session
Azure-InstanceId
X-Cache-TTL-Remaining
Azure-RegionName
Azure-Version
X-Alternate-Cache-Key
X-Locale
X-Routing-Service
X-Site-Version
X-Shopify-Stage
X-ShopId
X-Sorting-Hat-PodId
X-S-Maxage
X-Zipkin-Id
X-Storefront-Renderer-Rendered
X-Proxied
X-ShardId
X-Sorting-Hat-ShopId
X-Via-Fastly
X-CCM
X-GG-Cache-Date
X-AIR-PT
X-Cache-Grace
X-Cluster
X-TT-LOGID
X-Forwarded-Host
X-Node-Name
X-TA-CDN-Provider
X-Rendered-As
X-Is-Bot
X-Info
X-SRV
S-Cnection
AMP-Access-Control-Allow-Source-Origin
X-Qloud-Router
X-Revision
X-Microcachable
X-Proxy-Cache-Status
X-Cache-Enabled
X-Content-Age
Uber-Trace-Id
X-Dc
X-Platform
X-Via-CDN
X-Azure-Ref
X-CSRF-Token
X-NWS-UUID-VERIFY
X-Backend-Host
X-Varnish-Ttl
X-FTR-Backend
X-FTR-Backend-Server
X-App-Version
X-Country-Code-Real
X-FTR-Balancer
X-Ratelimit-Remaining
Amp-Access-Control-Allow-Source-Origin
Cache-Hits
X-Aspnetmvc-Version
X-FTR-Realm
X-FTR-DC
X-FTR-Cache-Status
X-Detected-As
X-Cache-Host
X-Amz-Meta-S3cmd-Attrs
Akamai-GRN
X-Amzn-Remapped-Content-Length
X-Amz-Apigw-Id
X-Amzn-RequestId
ServedBy
X-EdgeConnect-Cache-Status
X-Cache-NGX
X-B3-SpanId
X-Trace-Id
X-ATG-Version
X-Cache-PHP
X-Oss-Object-Type
X-RCS-CacheZone
X-Oss-Storage-Class
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-CS
SD-X-WS
X-Debug-Cache
X-FTR-Expires
X-Time-Microsecs
X-Varnish-Hostname
X-Air-Hostname
Tracecode
X-Correlation-ID
X-BCube-Filmed-By
DB-Nickname
X-ServerID
X-TX-ID
HostName
X-Backend-TTL
X-Akamai-Transformed
X-Ms-Version
X-Tb
X-Adobe-Source
X-Ms-Request-Id
X-NewRelic-App-Data
Backend
X-External-Request-Id
Mobile-Detection-Method
Meta-Geo-Continent
X-A-Dcw
X-A-Dam
X-From
MD5-Digest
X-Destination
Rendered-Blocks
T-Server
X-Magnolia-Registration
X-ARC
X-B-Cookie
X-Application
X-A-Dgt
X-Aed
X-A
X-A-Ccd
X-Cache-NE
Odigeo-Trace-Id
X-Connection-Hash
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-A-Wwc
X-D
Fastcgi-X-Cache-Version
X-ScT
X-Session-Fingerprint
X-SRCache-Key
X-S-Cookie
X-S
X-DynaTrace-JS-Agent
X-Generation-Time
X-Rojux
X-Trv-Group
BehaviorPad-Version
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-VG-WebServer
X-VG-WebCache
X-Vdms-Path
X-Vdms-Version
X-Request-UUID
X-Rewrite-Enabled
X-NAPM-TraceId
X-Origin-TTL
DCR-Processing-Time-Ms
Expiry
Machine
DCR-Decision-By
X-Origin-CC
X-PBS-Appsvrname
X-PAYTM-SRV-ID
X-Processor
X-Owner
X-Unique-Id
X-Nc
X-Cache-Var
X-Cache-Var-Map
Host-ID
Locid
PB-PID
Path
CacheControlHeader
Cf-Device-Type
Content-Disposition
On-Server
Fastly-Backend-Name
Gh-Request-Id
X-Device-Os
X-Level-Front-Cache
X-Location
X-Micro-Cache
X-JWT-State
X-Is-Gdpr
X-HS-Content-Campaign-Id
X-Irp-Debug
X-Mvc-Supplant-Cachable
X-OVcl
X-TrackingId
X-Tumblr-Pixel-3
X-Thanos
X-Reqid
X-OVcl-Cache
X-Policy
X-Has-Esi
X-GeoIP-City
Wxu-Next-Hostname
Wxu-Next-Region
X-Bip
Wxu-Next-Commit
V-Age
Release
UCS
X-Cache-Bucket
X-Cms-Context
X-Generated-In
X-Generated-On
X-FC-Vary-Parameters
X-Fastly-Cache
X-Developers
Arc-Version
PB-RID
X-Fetched-On
X-Varnish-Cache-Hits
X-B3-Traceid
X-CACHE-KEY
X-Varnish-Beresp-Grace
X-Unique-ID
X-GEO
Who
User-Cache-Control
X-IP
X-Li-Fabric
X-Li-Pop
X-VServer
Adler-Geo
X-Cdn-Forward
X-Backend-State
X-Gzip
X-WADP-Cache
X-Azure-Ref-OriginShield
X-Hnp-Log
X-LI-UUID
Web-Mar-Node
Server-Hostname
X-DPWN-IS-SECURE
Server-Host
Server-Ext
X-Node-Id
X-Nginx-Cache-Key
Sever-Int
SR-User-Adfree
True-Client-Country-4JS
Vix-Hermes-Req-Id
Thinkindot-Control
Thinkindot-CacheControl-Type
AKAMAI
Thinkindot-CacheControl
X-GoCache-CacheStatus
X-Block-Status
X-Csrf-Jwt
X-CUA
X-Core-Value
X-Eu-Site
X-Fmm-Version
X-Fastly-Backend
Ssr
X-DefElseHash
X-Envoy-Decorator-Operation
X-Dispatcher-Server
X-Developer
X-Esi-Check
X-DefHash
X-Cache-Info
X-Clientip
X-Swa-Ws
X-Wikidot-Static-Cache
X-Geo-Header
X-GeoIP
X-Branch-Name
X-Wikidot-Backend
X-Cache-Debug
X-Cache-Id
X-CGP
X-Clara-WADP
X-Gen-Mode
X-Cache-Tags
Cache-Host
X-VG-TLSProxy
X-RateLimit-Limit
Esi-Enabled
X-Variation
Fastly-SIE
DSUID
X-Var-Ttl
Apple-News-Services-Handled
X-SIPLIST1
Fastly-SWR
Apple-News-Services-Host
X-Request-Host
X-Varnish-CookieHashed-On
HA-Ipaddr
X-NU-AKA-ACS-Version
X-Request-URI
Country-Code
X-Varnish-Beresp-Ttl
CDN-Uid
C-Via
X-Thinkindot-L3
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
X-User
CDCHOST
CDN-RequestCountryCode
CDN-RequestId
CDN-PullZone
CDN-EdgeStorageId
CDN-Cache
CDN-CachedAt
Instruction
Ha-Gx-Prefs
X-Origin
X-Old-Content-Length
X-Sucuri-ID
X-Ratelimit-Reset
Magicmarker
X-Varnish-Remaining-TTL
X-Platform-Server
X-Origin-Response-Time
X-Origin-Expires
Pagetype
NM-Fastcgi-Cache
NGX
X-Rebelmouse-Cache-Control
Platform
IsBot
X-Varnish-CookieINHashed-On
Is-Eu
X-Rebelmouse-Surrogate-Control
L5d-Success-Class
X-ID
X-Varnish-Beresp-Status
X-EC-Lua
PFcat
X-HN
X-Hash
X-Aicache-OS
X-VarnishDD-TTL
Rt-Fastcgi-Cache
L
X-Generated-By
X-Skip-Cache
Location
X-Scheme
X-Slack-Backend
Origin
X-LB-ID
Cf-Bgj
X-Method
X-CLOUD-TRACE-CONTEXT
Fastly-Drupal-HTML
X-Matched-Rule
X-Cache-Backend
X-Gamma-Serve
X-Varnish-Url
X-Mvc-Supplant-OutputCached
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Loc
Lfy
X-Varnish-Hits
Geo-Info
Filterid
X-APP-VERSION
X-Epic-Correlation-Id
CloudFront-Viewer-Country
X-Via-Popv
X-Via-Popn
Pics-Label
X-Via-Poph
X-NCache
Sid
X-Refresh
X-Planisys-CDN-Rules
Pramga
X-PF-Uncompressing
X-Sn-Servicetimems
X-Cache-Expires
X-Cdn-Origin
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
X-Servername
X-Cache-Date
X-Core-Mission
Url
Cmsid
X-TraceId
Req-Svc-Chain
X-Tb-Optimization-Total-Bytes-Saved
Cmstype
Tcn
X-Served-From
X-Request-Start
NGB
Kp-EeAlive
VivaBuild
X-DC
Cache-Key
A
X-Error
Viewtype
MIME-Version
Svr
X-FireWall-Protection
M-TraceId
X-NC
X-Varnish-Cacheable
Source
X-Webkit-CSP-Report-Only
Cross-Origin-Opener-Policy
Server-ID
X-Response-By
X-Srv
X-Vgn-Hpd-Reason
X-Wa
X-Proxy-Cachei7
X-Servedbyhost
Xkeyi7
GeoIp-Country-Code
Geoip-Latitude
Arc-Country
X-Air-Source
X-HS-Status
Server-Ttl
SID
TDXMobile
X-B3-Spanid
HitType
X-BBXSRF
X-Vcl-Version
X-SaId
X-NGENIX-Cache
Content-Secure-Policy
X-CDN-Forward
X-JoinUs
N-Cache
X-Erf-Stays-Bingo-Pdp-Web
S-Rt
NtCoent-Length
X-Cache-Remote
X-Geo
X-PHP-Backend
X-Edge-Location
X-LiteSpeed-Cache-Control
X-Vc
X-LI-Proto
X-Esi
X-Cache-2
X-Internal-Host
Resin-Trace
CACHE
DataCenter
X-Cc-Req-Id
X-Cc-Via
X-Service
X-Cache-ASPX
X-Li-Proto
D-Cc-Upstream
X-Contensis-Viewer-Groups
X-Varnish-Authentication
Cteonnt-Length
X-HOST
Hostname
X-Viewer-Country
X-VCL-Version
Ohc-File-Size
Cross-Origin-Window-Policy
Request-ID
X-Sucuri-Cache
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-RAMCache
X-Svr
FSS-Cache
X-Forwarded-Site
X-CCDN-CacheTTL
X-HostName
X-UA
X-Extlb
X-Host-Name
X-Via-NSCOPI
GeoIP-Country-Code
GeoIP-Latitude
X-DW
X-RSL
X-TIM-N
X-Bc-Bl
X-RPS
X-RPM
X-DB
X-DI
X-Newrelic-Synthetics
X-DSS
X-Server-IP
X-ServedByHost
X-WA
X-Cs
X-Nyt-Route
X-Proxy-Upstream
X-Cache-Config
Mail-Subject
LB
X-Req
We-Hiring
Surrogated-Key
X-Origin-Time
X-Accel-Expires-Debug
X-Date
X-API-Version
CF-Cached-On
X-Gdpr
X-App
X-FPC
XServer
X-RateLimit-Remaining-Second
X-Dynatrace-Js-Agent
X-Kraken-Routeconfig-Destination
X-PJAX-URL
X-Server-Lifecycle-Phase
X-RateLimit-Limit-Second
Memcached
X-NodeID
X-VC
ProcessTime
X-Kraken-Loop-Name
X-ZONE
X-Instrumentation
X-Action
X-SN
X-VC-Cache
X-Check-Cacheable
Cache-Provider
Env
Ohc-Cache-HIT
Server-Id
X-Oss-Cdn-Auth
X-SB
X-Fpc
X-Rocket-Build-Number
X-Webstats-RespID
Upgrade-Insecure-Requests
X-Sigma
X-Sigma-Backend
X-Men
X-Air-Trace-Id
X-Region-Sid
X-APP
X-CF-Powered-By
X-Provided-By
X-URL
X-Swift-Error
X-Edge-Location-Klb
CPC-Age
X-MSEdge-Features
X-Depends-On
X-MSEdge-Flight
VNS-Age
X-FORWARDED-FOR
W
Mime-Version
VNS-Cache
X-SD-PageType
CPC-Cache
Srv
X-Cdn-Request-ID
X-Ftr-Cache-Host
X-CSRF-TOKEN
X-TIME
X-UnsetCookies
X-BBC-Edge-Cache-Status
X-Render-Time
Memory
X-Dw-Trace-Id
CDN
Time
Cdn
X-BACKEND-TTL
X-Zone
X-Client-Ip
X-Fastly-Request-Id
X-Parent-Response-Time
X-Flog
X-Fastly-Backend-Reqs
X-ABtesting
EpKe-Alive
X-NGINX-Cache
Dnion-Transfer-Encoding
X-Hello
X-Akamai-Pragma-Client-IP
X-Dynatrace
X-Cache-Tag
X-Pad
Fastcgi-Cache-TTL
X-Auto-Login
X-ServerName
State
X-Worker
X-Acquia-Purge-Tags
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Presslabs-Stats
X-Oracle-DMS-ECID
X-FTR-Cache-Host
X-Pf-Uncompressing
Processtime
Vha6-Origin
X-Acquia-Site
Media-Length
Proxy-Connection
Datacenter
PICS-Label
My-App
X-BBC-Origin-Response-Status
X-Cluster-Node
Epwk-X-Cache
X-Snapshot-Date
X-Via-PopH
X-Via-PopN
X-Minions-Version
X-Ua
X-Via-PopV
X-LiteSpeed-Tag
Cf-Ipcountry
X-CACHE-AGE
Xet-Cookie
X-Lb-Id
X-Ms-Meta-Originalurl
X-ElasticPress-Query
X-Vcache
X-Ms-Meta-Staticbatchstarttime
X-Akamai-ERRuleID
X-Varnish-Beresp-TTL
X-IN-APIGATEWAYSSL
X-MiniProfiler-Ids
X-Request-URL
X-Akamai-ERPolicy
X-ElasticPress-Search
X-IN-APIGATEWAY
X-Varnish-URL
X-Air-Pt
CountryCode
X-Apw-Hits
X-Litespeed-Cache-Control
X-Apw-Access-Action
X-Apw-Access-Object
X-Pjax-Url
X-Cache-Status-Check
Content-Style-Type
Warning
X-Mg-Request-UUID
X-Apw-Access-Token
Content-Script-Type
X-Mg-Request-Id
X-Storefront-Renderer-Verified
Phost
URI
Ohc-Response-Time
X-B3-Parentspanid
X-Traceid
OT-Force-Account-Verify
NnCoection
X-Redis-Duration-Ms
X-Redis-Count
Inserted-Into-Cache-At
X-Tid
X-C
X-Debug-Cache-Store
Environment
X-Debug-Cache-Fetch
X-Amz-Meta-Cb-Modifiedtime