Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-RAY
CF-Cache-Status
X-XSS-Protection
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-UA-Compatible
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Request-Id
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Runtime
X-AspNet-Version
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Xss-Protection
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
X-Ua-Compatible
X-Request-ID
Content-Encoding
X-CDN
Feature-Policy
X-AspNetMvc-Version
Status
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Upgrade
Access-Control-Max-Age
X-Via
Keep-Alive
X-Ws-Request-Id
X-Age
X-Robots-Tag
X-AH-Environment
X-Turbo-Charged-By
EagleId
Request-Context
X-Cache-Group
X-Proxy-Cache
Server-Timing
X-Server
X-Backend
X-Hacker
Host-Header
X-Server-Powered-By
Report-To
X-Amz-Request-Id
X-Nginx-Cache-Status
X-Amz-Id-2
Grace
X-UA-Device
X-Dns-Prefetch-Control
X-Rq
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Page-Speed
Cf-Railgun
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-Amz-Version-Id
NEL
X-OneAgent-JS-Injection
X-CST
X-Cache-Spec
X-WebKit-CSP
Allow
X-Vhost
X-Host
X-Backend-Server
X-Server-Id
Xkey
X-ASPNET-VERSION
EagleEye-TraceId
Surrogate-Control
X-Dispatcher
X-Node
Request-Id
X-Response-Time
Content-Location
X-Akam-SW-Version
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Accept-CH
X-Cache-Lookup
P3p
X-Application-Context
X-Country
X-Ac
X-Ruxit-JS-Agent
Accept-Ch-Lifetime
X-Mod-Pagespeed
X-Cloud-Trace-Context
X-Template
X-Readtime
X-Language
Accept-Ch
X-B3-TraceId
MS-Author-Via
Accept-CH-Lifetime
X-Url
Rating
X-HW
X-Cnection
X-MS-InvokeApp
X-Origin-Cache
X-PC
X-TtlSet
X-Vname
Edge-Control
X-Clacks-Overhead
X-GitHub-Request-Id
X-ESI
X-Trace
Display
Response
X-Sol
X-Middleton-Response
X-Middleton-Display
Pagespeed
X-Content-Type
X-D2id
X-ORACLE-DMS-RID
Arr-Disable-Session-Affinity
Verso
X-Oneagent-Js-Injection
X-ORACLE-DMS-ECID
X-Exp-Id
X-Cdn-Fetch
X-Use-Magma
X-Exp-Variant
X-GoogleNews-Bot
X-Kinja-Revision
X-Kinja-Server
X-Kinja-Build
X-Kinja
X-Goog-Hash
X-Vcap-Request-Id
X-Country-Code
X-Powered-By-Plesk
X-Rack-Cache
X-Varnish-TTL
X-Navigation-Version
X-VARITI-CCR
X-Server-Name
Service-Worker-Allowed
X-Amz-Rid
X-Fastly-Request-ID
X-Abt-Application-Version
Fastly-Restarts
X-Buckets
X-Client-IP
X-Cache-TTL
X-Cached
X-MSEdge-Ref
X-Release
X-Element-Page-Cache
X-Dw-Request-Base-Id
X-FastCGI-Cache
X-NF-Request-ID
X-TTL
SPRequestGuid
X-SharePointHealthScore
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
SPRequestDuration
SPIisLatency
Public-Key-Pins
Access-Control-Request-Method
RTSS
X-Webkit-CSP
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
Cache-Tag
AR-Request-ID
Ar-Sid
AR-ATIME
AR-PoweredBy
X-Edge
AR-CACHE
X-Ezoic-Cdn
X-Powered-CMS
X-LLID
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Ttl
X-Upstream
Content-MD5
X-Version
X-Ruxit-Js-Agent
X-HP-Webp
S
X-Jurisdiction
X-Recruiting
X-Origin-Upstream-Status
X-ECACHE
X-MCACHE
Charset
X-Mid
X-DynaTrace
X-Mg-S
X-Kinsta-Cache
Fusion-Component-Id
Fusion-Content-Id
Fusion-Template-Id
Fusion-Deployment-Id
Fusion-Content-Source
Fusion-Source
X-PressLabs-Stats
X-Content-Digest
X-Px
X-Fastcgi-Cache
X-T
Fastcgi-Cache
Cache-Tags
X-Accel-Expires
X-Id
X-Logged-In
X-Forwarded-Proto
Filters
X-Content-Security-Policy-Report-Only
Server-Node
TCN
Edge-Cache-Tag
X-Litespeed-Cache
X-Amz-Server-Side-Encryption
TP-Cache
TP-L2-Cache
MicrosoftSharePointTeamServices
Front-End-Https
Server-Name
X-Forwarded-For
X-Correlation-Id
X-Grace
Nginx-Cache
X-Request-Processing-Time
X-Request-Received
X-Hits
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Amzn-Trace-Id
X-Shield-Request-Id
X-Debug
X-B3-Sampled
X-Microsite
X-Request-Handler-Origin-Region
X-Varnish-Age
X-XRDS-LOCATION
X-Az
X-AppVersion
X-Activity-Id
Alternate-Protocol
X-HS-Combine-CSS
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Content-Id
X-Amz-Replication-Status
X-F-Cache
Surrogate-Key
X-Origin-Server
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Metageneration
X-Yandex-Sdch-Disable
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
X-XRDS-Location
X-Ser
X-DIS-Request-ID
Accept-Charset
X-Frontend
X-Rid
X-NWS-LOG-UUID
X-Geo-Country
X-Cache-Age
Host
Nel
X-Git-Hash
Section-Io-Cache
X-Hostname
X-Time
X-Respond-Thread
X-Upgrade-Enabled
X-Mobile-URL
X-VCache
Access-Control-Allow-Method
X-DataDome
MS-CV
X-Daa-Tunnel
X-RateLimit-Remaining
X-LB-Cache
Paypal-Debug-Id
X-Source
X-Type
X-AOL-HN
ServerID
X-Seen-By
X-TT
X-Varnish-Backend
X-IPLB-Instance
X-Cache-Action
Cleartype
Payment
X-Content-Options
X-Whom
X-App-Environment
X-Signature
Healthy
X-Route-Name
X-Providence-Cookie
X-B-Cache
X-Debug-Info
X-Is-Crawler
X-Aspnet-Duration-Ms
X-Request-Guid
X-Flags
X-Server-ID
X-Page-Id
X-WebKit-CSP-Report-Only
X-Load-Cache
X-N
X-Cache-Key
Realpath
Cache
X-Jobs
X-Contextid
X-Pinterest-Direct
Fastcgi-Useragent
X-FB-Debug
X-FTR-Request-ID
X-Browser-Type
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Mobile
Node
X-Webkit-Csp
X-Rule
Refresh
Powered-By-ChinaCache
X-Cache-Expired-At
X-Response-Served-From
X-Accel-Buffering
X-Original-Request-Id
DC
X-RTag
Version
Ms-Operation-Id
X-Content-Powered-By
Viewport
X-Cluster-Name
Access-Control-Request-Headers
X-Framework
X-Cacheable-TTL
X-Drupal-Cache-Tags
X-Proxy
X-UUID
X-Wix-Request-Id
X-ProcessESI
X-B
X-Cache-Control
X-RemovedCookies
X-HTML-Minification-Powered-By
X-Real-IP
X-Zen-Fury
Referer-Policy
X-FireWall-Port
Eomportal-Instance
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Distributor
X-Instance
X-Cache-Time
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Page-View
X-IPS-LoggedIn
X-Region
X-Drupal-Cache-Contexts
X-Via-JSL
X-Cached-By
Countrycode
X-Cache-Operation
X-FW-Hash
X-FW-Serve
X-FW-Type
X-FW-Static
X-FW-Server
X-Cache-Rule
X-FW-Dynamic
X-Tec-Api-Root
X-Tec-Api-Origin
X-Tec-Api-Version
X-Akamai-Edgescape
X-G
Liferay-Portal
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-Cache-Hit
X-App-Server
X-Nginx-Cache
X-Environment-Context
X-L-Path
Xserver
X-Debug-IsConnected
X-Debug-IsPreview
X-Www-Served-By
X-Pass-Why
X-Protected-By
Section-Origin-Responded
X-TEC-API-VERSION
Section-Io-Origin-Time-Seconds
X-TEC-API-ORIGIN
Section-Io-Id
Section-Io-Origin-Status
X-TEC-API-ROOT
DynaTrace
Server-Info
SRV
X-Varnish-Ttl
CF-IPCountry
X-User-Agent
X-Device-Type
X-Varnish-Grace
X-Tumblr-Pixel-2
Webserver
From-Origin
Ec-Rule-Version
X-Adobe-Content
X-Mode
X-Adobe-Loc
Retry-After
X-Handled-By
X-Hl-Ver
X-Endurance-Cache-Level
Meta-Geo
X-RN-RSRV
X-ES-SERVER
X-UPSTREAM-Address
X-MP-GENERATED-AT
X-Uri
Cache-Tv-Group
X-Backend-Name
Cache-Status
AMP-Access-Control-Allow-Source-Origin
X-Soup
X-ProxyCache-Status
Country
X-Cache-Server
Frame-Options
X-Pubstack
Apigw-Requestid
X-OCL
X-PCL
X-FB-TRIP-ID
Decoy-Debug-Key
X-Labrador-Cache-Channel
X-Human
X-Storage
X-Varnish-Server
GEO-INFO
X-Request-Time
X-ProxyCache-Key
X-PHP-Host
X-BYPASS-REASON
Decoy-Debug-Status
Decoy-Debug-TTL
X-Varnishpool
Webcakes-Region
Azure-RegionName
Property-Id
X-UA-Device-Type
X-Redis-Cache
Azure-SiteName
X-No-Session
X-LJ-Flow-ID
X-Be
X-Ratelimit-Limit
X-LAGOON
X-VWS-Id
Selected-Fe
Azure-InstanceId
TWC-Privacy
X-Server-W
X-Timing-Wait
TWC-Device-Class
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Connection-Speed
X-Section
X-WA-Info
X-Format
X-Proxy-Build
Fastly-SSL
Webcakes-App-Version
X-AWS-Id
Azure-SlotName
X-R9-Blue-Green-Version
X-S-Maxage
Webcakes-App-Name
X-Origin-Hint
X-Access
TWC-Locale-Group
Azure-Version
X-Via-Fastly
Protected
Cache-Name
Mn-Server-Ip
X-Sql-Duration-Ms
X-Sql-Count
X-Origin-Date
X-PERF
X-ApacheServer
X-Proto
X-Proxied
X-SayCDN-TTL
X-NYM-Debug-Backend
X-Say-Cacheable
X-Routing-Service
X-Web-Node
X-Say-TTL
X-Zipkin-Id
X-Info
X-Xfnlog-Site
X-Shopify-Stage
X-Sorting-Hat-PodId
X-ShopId
X-TNCMS
X-ShardId
X-Site-Version
X-Sorting-Hat-ShopId
X-Loop
X-Cache-TTL-Remaining
X-Locale
X-Hyper-Cache
X-Hosted-By
X-Storefront-Renderer-Rendered
X-GG-Cache-Date
X-Alternate-Cache-Key
X-Status
X-Is-Bot
X-TA-CDN-Provider
X-Rendered-As
X-Dc
X-Proxy-Cache-Status
X-AIR-PT
X-FW-Version
X-Cluster
X-TT-LOGID
Uber-Trace-Id
X-Cache-Enabled
S-Cnection
X-Content-Age
X-Microcachable
X-Node-Name
X-Cache-Grace
X-Revision
X-NWS-UUID-VERIFY
X-Qloud-Router
X-Forwarded-Host
X-CCM
X-Platform
X-Backend-Host
X-Azure-Ref
X-Via-CDN
X-CSRF-Token
Cache-Hits
X-SRV
X-App-Version
X-Trace-Id
X-Ratelimit-Remaining
Akamai-GRN
X-Detected-As
X-EdgeConnect-Cache-Status
X-Aspnetmvc-Version
X-Cache-Host
X-ATG-Version
ServedBy
X-Varnish-Hostname
X-CACHE-KEY
X-Cache-NGX
X-Cache-PHP
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Debug-Cache
X-Amzn-Remapped-Content-Length
X-RCS-CacheZone
X-B3-SpanId
X-Country-Code-Real
X-FTR-Realm
HostName
X-FTR-Cache-Status
X-FTR-Backend
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-DC
DB-Nickname
X-TX-ID
X-Nc
Amp-Access-Control-Allow-Source-Origin
SD-X-WS
X-Amz-Meta-S3cmd-Attrs
X-CS
X-Oss-Request-Id
X-Akamai-Transformed
X-Oss-Server-Time
X-Oss-Object-Type
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
X-BCube-Filmed-By
X-Time-Microsecs
X-Adobe-Source
X-DynaTrace-JS-Agent
X-ServerID
X-Ms-Version
Who
Backend
X-Ms-Request-Id
X-Correlation-ID
X-Backend-TTL
X-Aed
X-Unique-ID
X-SRCache-Key
X-Vtex-Remote-Cache
MD5-Digest
X-S
X-Vtex-Processado-Em
X-Cdn-Forward
X-Destination
X-Connection-Hash
X-VG-WebCache
DCR-Processing-Time-Ms
DCR-Decision-By
Country-Code
X-D
X-Generation-Time
X-Generated-On
Mobile-Detection-Method
Odigeo-Trace-Id
X-A-Dcw
X-A-Dgt
X-Vdms-Path
Machine
X-Vdms-Version
X-Trv-Group
X-From
X-A
X-A-Wwc
X-VG-WebServer
X-A-Ccd
X-Varnish-Cache-Hits
X-A-Dam
X-External-Request-Id
X-Level-Front-Cache
Meta-Geo-Continent
X-PBS-Appsvrname
X-Application
X-Processor
X-PAYTM-SRV-ID
BehaviorPad-Version
X-Air-Hostname
X-Owner
X-ARC
Rendered-Blocks
X-Rojux
X-S-Cookie
X-B-Cookie
X-Rewrite-Enabled
X-ScT
X-Request-UUID
X-Cache-NE
Tracecode
X-Varnish-Beresp-Grace
X-CF-Lambda-Fn
T-Server
X-NAPM-TraceId
X-Location
X-CF-Lambda-Version
X-Session-Fingerprint
Expiry
X-Origin-CC
X-Origin-TTL
Fastcgi-X-Cache-Version
X-FTR-Expires
X-RateLimit-Limit
AKAMAI
Cache-Host
X-Cms-Context
Xc-Version
X-Device-Os
X-Cache-Info
CacheControlHeader
X-Cache-Bucket
X-Varnish-Beresp-Ttl
X-Core-Value
X-Fastly-Cache
X-Geo-Header
Ssr
X-Bip
X-OVcl
X-Mvc-Supplant-Cachable
X-Micro-Cache
X-Magnolia-Registration
Thinkindot-CacheControl
X-OVcl-Cache
X-Tb
Release
Gh-Request-Id
X-Reqid
Server-Host
Fastly-Backend-Name
X-Policy
Thinkindot-CacheControl-Type
X-Irp-Debug
X-Thanos
X-Swa-Ws
V-Age
On-Server
X-Thinkindot-L3
X-Tumblr-Pixel-3
X-TrackingId
X-GeoIP-City
Pagetype
Thinkindot-Control
X-HS-Content-Campaign-Id
Content-Disposition
UCS
Path
Host-ID
X-Fetched-On
User-Cache-Control
X-NewRelic-App-Data
X-Unique-Id
X-Sucuri-ID
X-Varnish-Beresp-Status
Filterid
X-Request-Host
X-Ratelimit-Reset
Server-Ext
Server-Hostname
Sever-Int
X-Old-Content-Length
X-Origin
X-Origin-Response-Time
X-Scheme
PB-PID
NGX
NM-Fastcgi-Cache
X-Varnish-Hits
X-VG-TLSProxy
X-WADP-Cache
X-Var-Ttl
Origin
X-Nginx-Cache-Key
X-Skip-Cache
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
PB-RID
X-Is-Gdpr
X-FC-Vary-Parameters
X-Esi-Check
X-Fmm-Version
X-Gen-Mode
X-Generated-By
X-Dispatcher-Server
X-Developers
X-Azure-Ref-OriginShield
X-Branch-Name
X-Cache-Id
X-Developer
X-Generated-In
Wxu-Next-Region
X-Has-Esi
True-Client-Country-4JS
X-Hnp-Log
X-IP
X-Block-Status
X-Gzip
X-GeoIP
Wxu-Next-Hostname
Wxu-Next-Commit
Web-Mar-Node
Vix-Hermes-Req-Id
X-JWT-State
X-Clara-WADP
CDN-RequestCountryCode
CDN-PullZone
CDN-CachedAt
X-B3-Traceid
CDN-RequestId
CDN-Uid
Esi-Enabled
DSUID
Cf-Device-Type
CDN-Cache
CDN-EdgeStorageId
Location
Magicmarker
C-Via
Arc-Version
X-GEO
X-HN
Adler-Geo
X-Cache-Var
X-Request-URI
X-Wikidot-Static-Cache
X-Backend-State
X-Wikidot-Backend
Apple-News-Services-Parsed-Url
X-Cache-Debug
Apple-News-Services-Request-Url
X-Cache-Var-Map
Apple-News-Services-Host
X-APP-VERSION
X-Cache-Tags
X-Gamma-Serve
X-LI-UUID
X-Method
X-Fastly-Backend
X-Eu-Site
X-Li-Pop
X-Li-Fabric
X-Hash
X-Goog-Meta-Goog-Reserved-File-Mtime
X-GoCache-CacheStatus
X-LB-ID
X-Node-Id
X-Envoy-Decorator-Operation
X-Origin-Expires
X-CGP
X-Platform-Server
X-Rebelmouse-Cache-Control
X-Aicache-OS
X-Clientip
X-Csrf-Jwt
X-DPWN-IS-SECURE
X-NU-AKA-ACS-Version
X-DefHash
X-DefElseHash
X-Rebelmouse-Surrogate-Control
Apple-News-Services-Handled
IsBot
X-SIPLIST1
X-Varnish-CookieINHashed-On
Fastly-SWR
Fastly-SIE
Fastly-Drupal-HTML
X-Variation
X-Varnish-Remaining-TTL
Ha-Gx-Prefs
X-VarnishDD-TTL
L
Is-Eu
HA-Ipaddr
PFcat
Platform
L5d-Success-Class
Locid
X-Varnish-CookieHashed-On
CDCHOST
X-VServer
X-User
Cf-Bgj
X-Slack-Backend
X-ID
X-EC-Lua
Rt-Fastcgi-Cache
X-Mvc-Supplant-OutputCached
X-Loc
Instruction
Geo-Info
X-Epic-Correlation-Id
SR-User-Adfree
X-Varnish-Url
X-Via-Popn
X-Via-Poph
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-CUA
X-Planisys-CDN-Cache
X-PF-Uncompressing
X-Via-Popv
X-Refresh
Pics-Label
X-Matched-Rule
Sid
Url
NGB
Lfy
X-Cache-Backend
X-Cache-Expires
Req-Svc-Chain
CloudFront-Viewer-Country
Cmsid
Cmstype
X-Servername
X-Served-From
X-Sn-Servicetimems
X-NCache
Svr
Kp-EeAlive
X-Cdn-Origin
Pramga
X-Cache-Date
X-Core-Mission
X-Srv
A
X-Tb-Optimization-Total-Bytes-Saved
X-TraceId
MIME-Version
M-TraceId
X-Vgn-Hpd-Reason
Viewtype
Cache-Key
VivaBuild
X-Request-Start
Source
Cross-Origin-Opener-Policy
Arc-Country
X-CLOUD-TRACE-CONTEXT
DataCenter
X-PHP-Backend
X-FireWall-Protection
Server-ID
X-SaId
X-NGENIX-Cache
X-JoinUs
X-Error
TDXMobile
X-Webkit-CSP-Report-Only
X-Edge-Location
X-Vcl-Version
X-DC
X-Server-Lifecycle-Phase
X-Vc
X-Kraken-Routeconfig-Destination
X-Kraken-Loop-Name
X-Instrumentation
X-Edge-Location-Klb
GeoIp-Country-Code
X-Varnish-Cacheable
Geoip-Latitude
X-NC
SID
Tcn
CACHE
X-Response-By
X-HS-Status
X-Service
X-Air-Source
X-Servedbyhost
X-Geo
Content-Secure-Policy
X-Extlb
NtCoent-Length
X-Internal-Host
X-B3-Spanid
Xkeyi7
X-Proxy-Cachei7
X-Wa
FSS-Cache
Resin-Trace
X-BBXSRF
X-LiteSpeed-Cache-Control
HitType
X-Esi
N-Cache
X-Bc-Bl
X-Forwarded-Site
X-Li-Proto
Server-Ttl
X-CDN-Forward
X-LI-Proto
X-Cache-2
S-Rt
X-Viewer-Country
X-Via-NSCOPI
X-HOST
X-Cache-Remote
X-Accel-Expires-Debug
We-Hiring
D-Cc-Upstream
X-Req
X-Varnish-Authentication
X-WA
X-Proxy-Upstream
X-Svr
X-PJAX-URL
X-Date
X-Cc-Req-Id
X-Hcs-Proxy-Type
X-Cc-Via
Surrogated-Key
X-CCDN-CacheTTL
Request-ID
X-Contensis-Viewer-Groups
X-RAMCache
X-CCDN-Origin-Time
LB
Memcached
X-Cache-ASPX
Mail-Subject
Cteonnt-Length
X-UA
X-Erf-Stays-Bingo-Pdp-Web
X-DSS
X-DW
X-APP
X-VCL-Version
X-RPM
X-DB
X-RSL
X-VC-Cache
Env
X-DI
X-TIM-N
X-RPS
X-ServedByHost
X-Cs
X-Newrelic-Synthetics
Upgrade-Insecure-Requests
Cross-Origin-Window-Policy
Hostname
Ohc-File-Size
X-Sucuri-Cache
X-Rocket-Build-Number
X-Sigma
GeoIP-Country-Code
GeoIP-Latitude
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Sigma-Backend
X-Men
X-Server-IP
XServer
X-Host-Name
ProcessTime
X-MSEdge-Features
Server-Id
X-Nyt-Route
X-MSEdge-Flight
X-Gdpr
Time
CF-Cached-On
X-API-Version
X-Origin-Time
Memory
X-Action
X-App
X-ZONE
X-Air-Trace-Id
X-FPC
X-Cache-Config
X-HostName
X-Zone
X-CF-Powered-By
X-NodeID
X-VC
X-Check-Cacheable
Cache-Provider
X-Oss-Cdn-Auth
X-SN
VNS-Age
CPC-Cache
Mime-Version
VNS-Cache
X-Fpc
Srv
X-Region-Sid
CPC-Age
X-Provided-By
X-Swift-Error
X-Dynatrace-Js-Agent
Ohc-Cache-HIT
X-Depends-On
X-SD-PageType
X-Webstats-RespID
X-SB
X-FORWARDED-FOR
W
X-ServerName
X-Cdn-Request-ID
X-CSRF-TOKEN
CDN
Fastcgi-Cache-TTL
X-BACKEND-TTL
X-BBC-Edge-Cache-Status
Cdn
X-Ftr-Cache-Host
X-TIME
State
My-App
X-UnsetCookies
X-Client-Ip
X-Akamai-Pragma-Client-IP
X-Hello
X-ABtesting
X-Minions-Version
X-Fastly-Backend-Reqs
EpKe-Alive
Dnion-Transfer-Encoding
X-Render-Time
X-Fastly-Request-Id
X-Flog
X-Dw-Trace-Id
X-Mg-Request-UUID
X-Parent-Response-Time
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-Acquia-Purge-Tags
X-Acquia-Site
Media-Length
Proxy-Connection
X-Pad
Vha6-Origin
X-Cache-Tag
X-Oracle-DMS-ECID
X-NGINX-Cache
Cf-Ipcountry
X-Presslabs-Stats
X-Pf-Uncompressing
X-Auto-Login
Processtime
X-Snapshot-Date
X-Via-PopH
X-Via-PopN
PICS-Label
Epwk-X-Cache
OT-Force-Account-Verify
X-Worker
X-Varnish-URL
X-LiteSpeed-Tag
X-ElasticPress-Search
X-BBC-Origin-Response-Status
X-Via-PopV
X-FTR-Cache-Host
X-Cache-Type
X-Shop-Environment
X-Traceid
X-Akamai-ERRuleID
X-Vcache
X-MiniProfiler-Ids
X-ElasticPress-Query
X-Orig-Expires
X-Request-URL
X-Akamai-ERPolicy
X-Cluster-Node
X-Tenant
X-Varnish-Beresp-TTL
Warning
Xet-Cookie
X-Forwarded-Path
X-Lb-Id
X-Ms-Meta-Originalurl
X-ND-Cache
X-Ms-Meta-Staticbatchstarttime
X-Air-Pt
X-Ua
CountryCode
X-Apw-Access-Action
X-Mg-Request-Id
WZWS-RAY
X-Ftr-Request-Id
X-Cache-Status-Check
X-Yottaa-OS
X-Apw-Access-Token
X-Apw-Hits
X-Apw-Access-Object
X-B3-Parentspanid
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
NnCoection
URI
X-Redis-Duration-Ms
X-Storefront-Renderer-Verified
Environment
X-Redis-Count
Phost
Ohc-Response-Time
X-Amz-Meta-Cb-Modifiedtime
X-Litespeed-Cache-Control
Content-Script-Type
X-Tid
Inserted-Into-Cache-At
X-Debug-Cache-Fetch
X-Debug-Cache-Store
Datacenter
Content-Style-Type