Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
X-XSS-Protection
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-UA-Compatible
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Request-Id
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Runtime
X-AspNet-Version
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Xss-Protection
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
X-Ua-Compatible
X-Request-ID
Content-Encoding
X-CDN
Feature-Policy
X-AspNetMvc-Version
Status
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Upgrade
Access-Control-Max-Age
X-Via
Keep-Alive
X-Ws-Request-Id
X-Age
X-AH-Environment
X-Robots-Tag
X-Turbo-Charged-By
Request-Context
EagleId
X-Cache-Group
X-Proxy-Cache
Server-Timing
X-Server
X-Backend
X-Hacker
Host-Header
X-Server-Powered-By
Report-To
X-Amz-Request-Id
X-Nginx-Cache-Status
X-Amz-Id-2
Grace
X-UA-Device
X-Dns-Prefetch-Control
X-Rq
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Page-Speed
X-LiteSpeed-Cache
Cf-Railgun
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
X-Amz-Version-Id
X-OneAgent-JS-Injection
X-CST
X-Cache-Spec
NEL
X-WebKit-CSP
X-Vhost
Allow
X-Host
X-Backend-Server
X-Server-Id
Xkey
X-ASPNET-VERSION
EagleEye-TraceId
X-Dispatcher
Surrogate-Control
X-Node
Request-Id
X-Response-Time
Content-Location
X-Akam-SW-Version
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Cache-Lookup
P3p
X-Application-Context
Accept-Ch-Lifetime
X-Country
X-Ac
X-Ruxit-JS-Agent
Accept-CH
Accept-Ch
X-Mod-Pagespeed
X-Template
X-Readtime
X-Language
X-Cloud-Trace-Context
X-B3-TraceId
MS-Author-Via
X-Url
Rating
X-HW
X-Cnection
Accept-CH-Lifetime
X-MS-InvokeApp
X-Origin-Cache
X-Vname
X-TtlSet
X-PC
Edge-Control
X-Clacks-Overhead
X-ESI
X-GitHub-Request-Id
X-Trace
X-Sol
X-Middleton-Response
Response
X-Content-Type
Display
X-Middleton-Display
Pagespeed
X-D2id
X-ORACLE-DMS-RID
Verso
Arr-Disable-Session-Affinity
X-Oneagent-Js-Injection
X-ORACLE-DMS-ECID
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Kinja-Build
X-Kinja
X-Exp-Id
X-GoogleNews-Bot
X-Cdn-Fetch
X-Exp-Variant
X-Varnish-TTL
X-Goog-Hash
X-Vcap-Request-Id
X-Country-Code
X-Powered-By-Plesk
X-Rack-Cache
X-Navigation-Version
X-VARITI-CCR
Service-Worker-Allowed
X-Server-Name
X-Amz-Rid
X-Fastly-Request-ID
X-Abt-Application-Version
Fastly-Restarts
X-Client-IP
X-Buckets
X-TTL
X-Cache-TTL
X-Cached
X-MSEdge-Ref
X-Release
X-Element-Page-Cache
X-Dw-Request-Base-Id
X-NF-Request-ID
X-SharePointHealthScore
SPRequestGuid
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
Public-Key-Pins
SPRequestDuration
SPIisLatency
RTSS
Access-Control-Request-Method
X-Pinterest-Rid
Pinterest-Generated-By
X-Webkit-CSP
Pinterest-Version
Cache-Tag
X-FastCGI-Cache
X-Edge
Ar-Sid
AR-CACHE
AR-ATIME
AR-Request-ID
AR-PoweredBy
X-Powered-CMS
X-LLID
X-Ezoic-Cdn
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Upstream
X-Litespeed-Cache
Content-MD5
X-Version
X-Ruxit-Js-Agent
X-HP-Webp
S
X-Jurisdiction
X-Fastcgi-Cache
X-Origin-Upstream-Status
X-Recruiting
X-Mid
X-Ttl
X-ECACHE
X-MCACHE
Charset
X-DynaTrace
X-Mg-S
X-Kinsta-Cache
Fusion-Content-Id
Fusion-Component-Id
Fusion-Content-Source
X-PressLabs-Stats
Fusion-Template-Id
Fusion-Deployment-Id
Fusion-Source
X-Content-Digest
X-Px
X-T
Cache-Tags
Fastcgi-Cache
X-Accel-Expires
X-Id
X-Logged-In
X-Forwarded-Proto
Filters
X-Content-Security-Policy-Report-Only
Server-Node
Edge-Cache-Tag
X-Amz-Server-Side-Encryption
TP-Cache
TP-L2-Cache
MicrosoftSharePointTeamServices
Front-End-Https
Server-Name
X-Correlation-Id
TCN
X-Forwarded-For
X-Grace
Nel
Nginx-Cache
X-Request-Received
X-Request-Processing-Time
X-Kong-Proxy-Latency
X-Hits
X-Kong-Upstream-Latency
X-Amzn-Trace-Id
X-Shield-Request-Id
X-Debug
X-B3-Sampled
X-Microsite
X-Request-Handler-Origin-Region
X-Varnish-Age
X-XRDS-LOCATION
X-Az
X-AppVersion
X-Activity-Id
Alternate-Protocol
X-HS-Combine-CSS
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Content-Id
X-Amz-Replication-Status
X-F-Cache
X-Yandex-Sdch-Disable
Surrogate-Key
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Goog-Generation
X-Origin-Server
X-GUploader-UploadID
X-XRDS-Location
X-Ser
X-DIS-Request-ID
X-Frontend
X-Rid
Accept-Charset
X-NWS-LOG-UUID
X-Cache-Age
X-Geo-Country
Host
X-Git-Hash
X-Hostname
Section-Io-Cache
X-Time
X-Respond-Thread
X-Upgrade-Enabled
X-DataDome
X-VCache
Access-Control-Allow-Method
X-Mobile-URL
X-Daa-Tunnel
X-RateLimit-Remaining
MS-CV
X-LB-Cache
Paypal-Debug-Id
ServerID
X-Type
X-AOL-HN
X-Seen-By
X-Source
Cleartype
X-Varnish-Backend
X-Cache-Action
X-Content-Options
X-TT
X-IPLB-Instance
X-App-Environment
Payment
Cache
Healthy
X-Whom
X-Request-Guid
X-Route-Name
X-Signature
X-Providence-Cookie
X-B-Cache
X-Aspnet-Duration-Ms
X-Debug-Info
X-Flags
X-Server-ID
X-Is-Crawler
X-Page-Id
X-WebKit-CSP-Report-Only
X-Load-Cache
Realpath
X-N
X-Cache-Key
X-Jobs
X-Contextid
Fastcgi-Useragent
X-Pinterest-Direct
X-FB-Debug
X-FTR-Request-ID
X-Browser-Type
X-Erf-Bev-Bev
X-Mobile
X-Erf-Bev-Bev-Is-Generated
Node
X-Webkit-Csp
X-Rule
Refresh
X-Cache-Expired-At
Powered-By-ChinaCache
X-Response-Served-From
X-Original-Request-Id
X-Accel-Buffering
DC
Version
Ms-Operation-Id
X-RTag
X-Framework
X-Cacheable-TTL
Access-Control-Request-Headers
X-Zen-Fury
X-Drupal-Cache-Tags
X-Cluster-Name
X-Content-Powered-By
Viewport
X-HTML-Minification-Powered-By
X-Cache-Control
X-Wix-Request-Id
X-Proxy
X-Instance
X-ProcessESI
X-UUID
X-RemovedCookies
X-Real-IP
Referer-Policy
X-B
X-Region
X-Tt-Trace-Tag
X-Cache-Time
VIX-Pulpo-Node
Eomportal-Instance
X-Tt-Trace-Host
X-IPS-LoggedIn
X-Distributor
VIX-Pulpo-Upstream-Status
X-FireWall-Port
X-Page-View
X-Drupal-Cache-Contexts
X-Via-JSL
Countrycode
X-Cached-By
X-Cache-Rule
X-FW-Server
X-Cache-Operation
X-FW-Serve
X-FW-Dynamic
X-FW-Type
X-FW-Hash
X-FW-Static
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
X-Akamai-Edgescape
X-G
Liferay-Portal
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Cache-Hit
X-Nginx-Cache
X-App-Server
X-L-Path
X-Environment-Context
Xserver
X-Pass-Why
X-Www-Served-By
X-Debug-IsPreview
X-Debug-IsConnected
SRV
X-Protected-By
DynaTrace
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
Section-Origin-Responded
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Io-Id
Server-Info
CF-IPCountry
X-User-Agent
X-Device-Type
X-Varnish-Grace
Webserver
From-Origin
X-Tumblr-Pixel-2
X-Adobe-Loc
X-Adobe-Content
X-Mode
Ec-Rule-Version
Retry-After
X-ES-SERVER
X-Hl-Ver
AMP-Access-Control-Allow-Source-Origin
Cache-Status
X-Endurance-Cache-Level
X-UPSTREAM-Address
Meta-Geo
X-Handled-By
X-RN-RSRV
X-Backend-Name
X-Varnish-Server
Cache-Tv-Group
X-MP-GENERATED-AT
X-Uri
Frame-Options
Webcakes-Region
Fastly-SSL
X-PCL
X-Cache-Server
X-Access
X-Origin-Hint
X-PHP-Host
X-OCL
Webcakes-App-Name
Decoy-Debug-Status
X-FB-TRIP-ID
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-LatLong
X-Soup
Decoy-Debug-Key
Apigw-Requestid
X-Section
Country
X-Varnishpool
Property-Id
X-Format
X-Storage
TWC-GeoIP-Country
X-Human
X-ProxyCache-Status
X-Labrador-Cache-Channel
X-BYPASS-REASON
Decoy-Debug-TTL
X-Pubstack
X-ProxyCache-Key
TWC-Locale-Group
TWC-Privacy
X-Request-Time
Webcakes-App-Version
Azure-SiteName
Azure-Version
Azure-SlotName
Mn-Server-Ip
X-LJ-Flow-ID
X-LAGOON
Azure-InstanceId
Azure-RegionName
Selected-Fe
X-AWS-Id
X-VWS-Id
X-S-Maxage
X-No-Session
X-Proxy-Build
X-Be
X-UA-Device-Type
X-R9-Blue-Green-Version
X-Redis-Cache
X-WA-Info
X-Server-W
X-Ratelimit-Limit
X-NYM-Debug-Backend
X-Timing-Wait
X-Via-Fastly
X-PERF
X-ApacheServer
Cache-Name
X-Varnish-Ttl
X-Say-TTL
X-SayCDN-TTL
Protected
X-Cache-TTL-Remaining
X-Info
X-Xfnlog-Site
X-Zipkin-Id
X-Web-Node
GEO-INFO
X-Sql-Count
X-Proto
X-Origin-Date
X-Sql-Duration-Ms
X-Proxied
X-Say-Cacheable
X-Routing-Service
X-Status
X-Alternate-Cache-Key
X-Locale
X-ShardId
X-Loop
X-Storefront-Renderer-Rendered
X-TNCMS
X-Sorting-Hat-PodId
X-Shopify-Stage
X-GG-Cache-Date
X-Hosted-By
X-Site-Version
X-Sorting-Hat-ShopId
X-ShopId
X-Hyper-Cache
X-TA-CDN-Provider
Uber-Trace-Id
X-Is-Bot
X-Proxy-Cache-Status
X-Dc
X-FW-Version
X-Rendered-As
X-AIR-PT
X-Cluster
X-TT-LOGID
X-Cache-Enabled
S-Cnection
X-Node-Name
X-Content-Age
X-Microcachable
X-Cache-Grace
X-Forwarded-Host
X-App-Version
X-Qloud-Router
X-Revision
X-NWS-UUID-VERIFY
X-CCM
X-Platform
X-Backend-Host
X-Azure-Ref
X-Via-CDN
X-CSRF-Token
Cache-Hits
X-SRV
Akamai-GRN
X-Ratelimit-Remaining
X-Trace-Id
X-EdgeConnect-Cache-Status
X-ATG-Version
ServedBy
X-Aspnetmvc-Version
X-Detected-As
X-Cache-Host
X-Cache-NGX
X-Cache-PHP
X-CACHE-KEY
X-Varnish-Hostname
X-Amzn-Remapped-Content-Length
X-B3-SpanId
X-RCS-CacheZone
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Debug-Cache
X-CS
X-FTR-Backend-Server
X-FTR-DC
HostName
X-FTR-Realm
X-FTR-Backend
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Balancer
DB-Nickname
X-Nc
Amp-Access-Control-Allow-Source-Origin
X-Amz-Meta-S3cmd-Attrs
X-TX-ID
SD-X-WS
X-Oss-Storage-Class
X-Oss-Server-Time
X-Akamai-Transformed
X-Oss-Request-Id
X-Unique-ID
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-BCube-Filmed-By
X-Time-Microsecs
X-Adobe-Source
X-DynaTrace-JS-Agent
X-Ms-Version
X-Ms-Request-Id
Backend
X-Correlation-ID
X-ServerID
Who
X-Backend-TTL
X-Destination
X-Varnish-Beresp-Grace
X-D
Country-Code
X-Connection-Hash
X-Cache-NE
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Cdn-Forward
X-Vtex-Remote-Cache
X-Vdms-Path
X-Generated-On
X-Generation-Time
X-Varnish-Cache-Hits
X-Vdms-Version
X-VG-WebCache
X-Vtex-Processado-Em
X-From
X-VG-WebServer
BehaviorPad-Version
X-B-Cookie
Machine
T-Server
Fastcgi-X-Cache-Version
Expiry
MD5-Digest
Meta-Geo-Continent
Odigeo-Trace-Id
Mobile-Detection-Method
Rendered-Blocks
X-A
X-A-Ccd
X-A-Wwc
X-Aed
X-Application
X-ARC
X-A-Dgt
X-A-Dcw
X-A-Dam
DCR-Processing-Time-Ms
DCR-Decision-By
X-Trv-Group
X-External-Request-Id
X-Rewrite-Enabled
X-Request-UUID
X-NAPM-TraceId
Tracecode
X-Air-Hostname
X-Origin-CC
X-Level-Front-Cache
X-PBS-Appsvrname
X-Processor
X-Location
X-PAYTM-SRV-ID
X-Session-Fingerprint
X-Owner
X-S-Cookie
X-SRCache-Key
X-Origin-TTL
X-ScT
X-S
X-Rojux
X-RateLimit-Limit
X-FTR-Expires
X-Policy
X-Core-Value
X-Varnish-Beresp-Ttl
X-Cache-Bucket
X-Cms-Context
X-OVcl-Cache
X-OVcl
X-Cache-Info
Cache-Host
Xc-Version
CacheControlHeader
X-Bip
Wxu-Next-Region
Ssr
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Server-Host
Magicmarker
Pagetype
On-Server
Release
Host-ID
Thinkindot-Control
Fastly-Backend-Name
X-Reqid
X-Tb
Wxu-Next-Hostname
Wxu-Next-Commit
UCS
Gh-Request-Id
V-Age
Content-Disposition
AKAMAI
X-Tumblr-Pixel-3
X-Magnolia-Registration
X-Fastly-Cache
X-HS-Content-Campaign-Id
Path
X-Mvc-Supplant-Cachable
X-GeoIP-City
X-Micro-Cache
X-TrackingId
X-Fetched-On
X-Irp-Debug
X-Thanos
X-Thinkindot-L3
X-Device-Os
X-Geo-Header
X-Developers
X-Swa-Ws
X-Generated-In
X-NewRelic-App-Data
X-Varnish-Beresp-Status
User-Cache-Control
X-Sucuri-ID
Filterid
X-Is-Gdpr
True-Client-Country-4JS
X-GeoIP
Web-Mar-Node
Vix-Hermes-Req-Id
X-User
X-HN
PB-RID
PFcat
X-Scheme
X-SVT-ORM-RULES
X-IP
PB-PID
X-SVT-ORM-VERSION
X-Hnp-Log
Sever-Int
X-Has-Esi
Server-Hostname
X-Var-Ttl
Server-Ext
X-Gzip
X-Ratelimit-Reset
X-Eu-Site
X-Old-Content-Length
X-CGP
X-Nginx-Cache-Key
X-WADP-Cache
X-FC-Vary-Parameters
X-Cache-Id
X-Esi-Check
X-Envoy-Decorator-Operation
X-Developer
X-Wikidot-Static-Cache
X-Origin-Response-Time
X-Csrf-Jwt
X-Dispatcher-Server
X-Wikidot-Backend
X-Cache-Debug
X-Branch-Name
X-Origin
X-VG-TLSProxy
X-Request-Host
X-Request-URI
X-Varnish-Hits
X-VarnishDD-TTL
X-Method
X-Skip-Cache
X-Backend-State
X-Block-Status
X-Fmm-Version
X-Azure-Ref-OriginShield
X-Generated-By
X-Gen-Mode
X-JWT-State
X-Clara-WADP
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-B3-Traceid
Apple-News-Services-Request-Url
Cf-Bgj
L
HA-Ipaddr
Ha-Gx-Prefs
Esi-Enabled
DSUID
CDN-Cache
Apple-News-Services-Handled
Cf-Device-Type
L5d-Success-Class
CDN-Uid
CDCHOST
Arc-Version
CDN-EdgeStorageId
CDN-CachedAt
NM-Fastcgi-Cache
NGX
CDN-PullZone
C-Via
CDN-RequestCountryCode
Geo-Info
CDN-RequestId
Location
Origin
Locid
X-DefHash
X-DPWN-IS-SECURE
X-Fastly-Backend
X-Clientip
X-Cache-Tags
Adler-Geo
X-DefElseHash
X-Li-Fabric
X-Varnish-CookieHashed-On
X-Variation
X-SIPLIST1
X-Rebelmouse-Surrogate-Control
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Cache-Var
X-Cache-Var-Map
X-VServer
X-Rebelmouse-Cache-Control
X-Platform-Server
X-LB-ID
X-Hash
X-Goog-Meta-Goog-Reserved-File-Mtime
X-GoCache-CacheStatus
X-Li-Pop
X-LI-UUID
X-Origin-Expires
X-NU-AKA-ACS-Version
X-Node-Id
X-Gamma-Serve
X-Slack-Backend
X-Aicache-OS
IsBot
Fastly-SWR
Fastly-Drupal-HTML
Platform
Is-Eu
Fastly-SIE
X-CLOUD-TRACE-CONTEXT
X-Unique-Id
X-EC-Lua
X-ID
Rt-Fastcgi-Cache
X-Loc
SR-User-Adfree
X-GEO
X-Mvc-Supplant-OutputCached
Instruction
X-Varnish-Url
X-Epic-Correlation-Id
X-CUA
Pics-Label
X-Via-Popn
X-PF-Uncompressing
X-Via-Poph
X-Via-Popv
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-APP-VERSION
Lfy
X-Matched-Rule
X-Refresh
Sid
NGB
Url
X-Cache-Backend
CloudFront-Viewer-Country
Req-Svc-Chain
Cmsid
Cmstype
X-Cache-Expires
X-Servername
X-Sn-Servicetimems
X-Served-From
X-NCache
Svr
Pramga
X-Cdn-Origin
Kp-EeAlive
X-Srv
X-Cache-Date
VivaBuild
X-Tb-Optimization-Total-Bytes-Saved
Viewtype
MIME-Version
X-Core-Mission
X-TraceId
A
Tcn
M-TraceId
X-Vgn-Hpd-Reason
Cache-Key
X-Request-Start
Cross-Origin-Opener-Policy
Source
Arc-Country
Server-ID
X-Error
X-FireWall-Protection
X-SaId
TDXMobile
X-PHP-Backend
X-NGENIX-Cache
DataCenter
X-JoinUs
X-Geo
X-Edge-Location
X-Webkit-CSP-Report-Only
X-Varnish-Cacheable
X-Vcl-Version
X-Vc
X-DC
X-Kraken-Routeconfig-Destination
X-Instrumentation
X-Kraken-Loop-Name
X-Edge-Location-Klb
X-Server-Lifecycle-Phase
GeoIp-Country-Code
Geoip-Latitude
X-NC
SID
NtCoent-Length
X-Air-Source
Content-Secure-Policy
X-Response-By
X-HS-Status
X-Servedbyhost
X-Service
X-Extlb
X-B3-Spanid
X-Wa
X-Proxy-Cachei7
X-Internal-Host
Xkeyi7
Server-Ttl
N-Cache
X-Forwarded-Site
X-Bc-Bl
X-BBXSRF
FSS-Cache
Resin-Trace
X-LiteSpeed-Cache-Control
X-Li-Proto
HitType
X-Esi
CACHE
X-CDN-Forward
X-Via-NSCOPI
X-Viewer-Country
X-LI-Proto
S-Rt
X-Cache-2
X-Cache-Remote
X-HOST
LB
X-PJAX-URL
X-Contensis-Viewer-Groups
Request-ID
X-Varnish-Authentication
X-Hcs-Proxy-Type
X-Proxy-Upstream
Mail-Subject
X-Cc-Via
Memcached
We-Hiring
X-RAMCache
Surrogated-Key
X-Cache-ASPX
X-WA
D-Cc-Upstream
X-Cc-Req-Id
X-Accel-Expires-Debug
X-Date
X-CCDN-Origin-Time
X-Req
X-Svr
X-CCDN-CacheTTL
Cteonnt-Length
X-UA
X-Erf-Stays-Bingo-Pdp-Web
X-RPM
X-DSS
Env
X-APP
X-VC-Cache
Upgrade-Insecure-Requests
X-DB
X-ServedByHost
X-DI
X-RateLimit-Remaining-Second
X-TIM-N
X-VCL-Version
X-RSL
X-DW
X-RateLimit-Limit-Second
X-Newrelic-Synthetics
X-RPS
Hostname
Ohc-File-Size
X-Sucuri-Cache
Cross-Origin-Window-Policy
X-Sigma
X-Rocket-Build-Number
GeoIP-Latitude
GeoIP-Country-Code
X-Sigma-Backend
X-Server-IP
X-Men
X-Cs
X-Host-Name
XServer
X-API-Version
Memory
ProcessTime
X-MSEdge-Features
X-App
X-FPC
Time
X-ZONE
X-Air-Trace-Id
X-Gdpr
X-Action
CF-Cached-On
X-Cache-Config
X-MSEdge-Flight
X-Origin-Time
X-Nyt-Route
X-HostName
X-Zone
CPC-Age
CPC-Cache
X-Oss-Cdn-Auth
X-CF-Powered-By
X-Check-Cacheable
X-SN
VNS-Age
X-Region-Sid
X-NodeID
Cache-Provider
VNS-Cache
X-Fpc
Server-Id
X-VC
X-Provided-By
X-Swift-Error
X-Dynatrace-Js-Agent
Ohc-Cache-HIT
X-FORWARDED-FOR
X-SB
X-Depends-On
W
X-Webstats-RespID
Mime-Version
X-SD-PageType
Srv
X-ServerName
X-Cdn-Request-ID
Cdn
My-App
X-Ftr-Cache-Host
X-BBC-Edge-Cache-Status
X-CSRF-TOKEN
State
X-BACKEND-TTL
X-TIME
X-UnsetCookies
CDN
Fastcgi-Cache-TTL
X-Client-Ip
X-Akamai-Pragma-Client-IP
X-Minions-Version
X-ABtesting
X-Flog
X-Hello
X-Mg-Request-UUID
X-Parent-Response-Time
EpKe-Alive
X-Fastly-Request-Id
X-Render-Time
X-Fastly-Backend-Reqs
Dnion-Transfer-Encoding
X-Dw-Trace-Id
X-Pf-Uncompressing
Proxy-Connection
X-Acquia-Application-UUID
X-Pad
X-NGINX-Cache
Media-Length
X-Cache-Tag
X-Presslabs-Stats
X-Oracle-DMS-ECID
X-Acquia-Purge-Tags
X-Acquia-Application-Trace
Vha6-Origin
X-Acquia-Site
Cf-Ipcountry
PICS-Label
X-Cache-Type
X-BBC-Origin-Response-Status
X-Worker
X-Auto-Login
Epwk-X-Cache
X-LiteSpeed-Tag
Processtime
X-Via-PopV
X-Snapshot-Date
X-Via-PopH
X-Via-PopN
X-ElasticPress-Search
OT-Force-Account-Verify
X-FTR-Cache-Host
X-Request-URL
X-Orig-Expires
X-Ms-Meta-Staticbatchstarttime
X-Shop-Environment
X-Tenant
X-Ms-Meta-Originalurl
X-Lb-Id
X-Forwarded-Path
X-ND-Cache
X-Traceid
Xet-Cookie
Warning
X-Varnish-URL
X-Cluster-Node
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-Vcache
X-MiniProfiler-Ids
X-Varnish-Beresp-TTL
X-ElasticPress-Query
X-Air-Pt
CountryCode
X-Ua
X-Cache-Status-Check
X-Apw-Access-Object
X-Apw-Hits
X-Apw-Access-Token
NnCoection
X-Ftr-Request-Id
WZWS-RAY
X-Yottaa-OS
X-Storefront-Renderer-Verified
Environment
Ohc-Response-Time
X-Apw-Access-Action
X-Mg-Request-Id
Content-Style-Type
X-Tid
X-Redis-Duration-Ms
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
URI
Inserted-Into-Cache-At
X-Amz-Meta-Cb-Modifiedtime
Datacenter
Content-Script-Type
Phost
X-Litespeed-Cache-Control
X-Debug-Cache-Fetch
X-Redis-Count
X-Debug-Cache-Store
X-B3-Parentspanid