Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Cf-Request-Id
CF-RAY
CF-Cache-Status
Last-Modified
X-XSS-Protection
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-Runtime
X-AspNet-Version
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Xss-Protection
X-Cache-Status
X-Generator
X-Request-ID
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Content-Security-Policy
Content-Encoding
X-CDN
X-Envoy-Upstream-Service-Time
Status
Feature-Policy
X-Ua-Compatible
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-AspNetMvc-Version
Access-Control-Max-Age
X-Via
Upgrade
Keep-Alive
X-Ws-Request-Id
X-Age
X-Turbo-Charged-By
X-AH-Environment
X-Robots-Tag
Request-Context
X-Proxy-Cache
EagleId
X-Cache-Group
Server-Timing
X-Backend
X-Hacker
X-Amz-Request-Id
Report-To
X-Server
Host-Header
X-Amz-Id-2
X-Server-Powered-By
Grace
X-Nginx-Cache-Status
X-UA-Device
X-LiteSpeed-Cache
X-Dns-Prefetch-Control
X-Varnish-Cache
X-Rq
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Page-Speed
Cf-Railgun
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
NEL
X-Amz-Version-Id
X-OneAgent-JS-Injection
Xkey
X-WebKit-CSP
X-Cache-Spec
Allow
X-Backend-Server
X-Host
X-CST
X-Vhost
X-Device
EagleEye-TraceId
X-Server-Id
X-ASPNET-VERSION
Surrogate-Control
Request-Id
X-Dispatcher
Accept-CH
X-Node
Content-Location
X-Response-Time
Accept-CH-Lifetime
X-Akam-SW-Version
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Ruxit-JS-Agent
X-Template
X-Ac
X-Language
X-Application-Context
X-Kinja-Server-Push
X-Country
X-Cache-Lookup
X-Readtime
X-Cloud-Trace-Context
X-Mod-Pagespeed
MS-Author-Via
X-B3-TraceId
X-Origin-Cache
Rating
X-MS-InvokeApp
X-Cnection
X-Url
X-HW
X-PC
X-TtlSet
X-Vname
X-ORACLE-DMS-ECID
Accept-Ch
X-Clacks-Overhead
X-FastCGI-Cache
X-GitHub-Request-Id
Edge-Control
X-ESI
Accept-Ch-Lifetime
X-Trace
Display
Pagespeed
X-Sol
X-Middleton-Display
X-Middleton-Response
Response
X-Content-Type
X-Cdn-Fetch
X-Vcap-Request-Id
X-Kinja-Revision
X-Kinja-Build
X-D2id
X-Kinja-Server
Arr-Disable-Session-Affinity
X-GoogleNews-Bot
Verso
X-Exp-Variant
X-Exp-Id
X-Use-Magma
X-Kinja
X-Buckets
X-Goog-Hash
X-Rack-Cache
X-Server-Name
X-Country-Code
Service-Worker-Allowed
X-Varnish-TTL
X-Navigation-Version
X-VARITI-CCR
X-Abt-Application-Version
X-Amz-Rid
X-Oneagent-Js-Injection
Pinterest-Generated-By
X-Pinterest-Rid
X-ORACLE-DMS-RID
Pinterest-Version
X-Powered-By-Plesk
X-Cache-TTL
X-Client-IP
SPRequestGuid
X-SharePointHealthScore
X-Fastly-Request-ID
X-Release
SPIisLatency
SPRequestDuration
X-MSEdge-Ref
X-Element-Page-Cache
X-Dw-Request-Base-Id
Fastly-Restarts
X-NF-Request-ID
X-Cached
Public-Key-Pins
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
RTSS
X-Ttl
X-Origin-Upstream-Status
AR-ATIME
AR-CACHE
AR-Request-ID
X-Edge
Ar-Sid
AR-PoweredBy
Access-Control-Request-Method
X-TTL
X-Webkit-CSP
X-SRCache-Store-Status
X-Px
X-SRCache-Fetch-Status
X-LLID
X-Powered-CMS
Fusion-Template-Id
Fusion-Source
Fusion-Deployment-Id
Fusion-Component-Id
Fusion-Content-Id
Fusion-Content-Source
X-Ezoic-Cdn
X-Upstream
Content-MD5
X-HP-Webp
X-Jurisdiction
X-Mid
X-MCACHE
X-Amz-Server-Side-Encryption
X-ECACHE
Charset
X-Recruiting
Cache-Tag
X-Content-Digest
S
X-Mg-S
X-Pinterest-Direct
X-Version
X-PressLabs-Stats
X-Aspnetmvc-Version
TCN
MicrosoftSharePointTeamServices
Fastcgi-Cache
Front-End-Https
X-Debug
X-Content-Security-Policy-Report-Only
X-T
Filters
X-Grace
X-Kinsta-Cache
Cache-Tags
Server-Node
Edge-Cache-Tag
X-XRDS-Location
X-Id
X-Forwarded-Proto
X-Accel-Expires
X-Correlation-Id
X-Logged-In
X-Amzn-Trace-Id
X-Yandex-Sdch-Disable
Nginx-Cache
Server-Name
Surrogate-Key
X-Varnish-Age
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Cache-Key
X-Forwarded-For
TP-Cache
TP-L2-Cache
X-B3-Sampled
X-Request-Processing-Time
X-Request-Received
X-Microsite
X-DynaTrace
X-Hits
X-Request-Handler-Origin-Region
X-Ser
Powered-By-ChinaCache
X-DIS-Request-ID
X-AppVersion
X-Az
X-Activity-Id
X-Shield-Request-Id
X-Amz-Replication-Status
X-Server-ID
X-F-Cache
X-HS-Cache-Config
X-HS-Content-Id
X-Ruxit-Js-Agent
X-HS-Hub-Id
X-HS-Combine-CSS
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
X-Goog-Stored-Content-Length
Accept-Charset
X-Origin-Server
X-FTR-Request-ID
X-Git-Hash
X-Respond-Thread
X-Hostname
X-Geo-Country
X-LB-Cache
X-DataDome
X-Upgrade-Enabled
Section-Io-Cache
X-Rid
X-Frontend
X-Cache-Age
Access-Control-Allow-Method
Cache
Alternate-Protocol
X-Mobile-URL
Host
Cleartype
MS-CV
Paypal-Debug-Id
Healthy
X-Type
X-WebKit-CSP-Report-Only
X-AOL-HN
X-Content-Options
X-IPLB-Instance
ServerID
X-Seen-By
Payment
X-Whom
X-Aspnet-Duration-Ms
X-Flags
X-Signature
X-Debug-Info
X-TT
X-Cache-Action
X-Is-Crawler
X-B-Cache
X-Providence-Cookie
X-Request-Guid
X-Route-Name
X-Varnish-Backend
X-VCache
X-App-Environment
X-XRDS-LOCATION
X-Page-Id
Fastcgi-Useragent
X-Jobs
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-NWS-LOG-UUID
X-Source
X-N
X-Mobile
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Erf-Bev-Bev
X-Load-Cache
X-Time
X-RateLimit-Remaining
X-Via-JSL
X-Cached-By
X-Daa-Tunnel
X-FB-Debug
X-Akamai-Edgescape
Version
Nel
X-Litespeed-Cache
X-Cache-Rule
X-Cache-Operation
Viewport
Refresh
X-Rule
X-Accel-Buffering
DynaTrace
X-Original-Request-Id
X-Response-Served-From
DC
X-Zen-Fury
X-Drupal-Cache-Tags
X-Framework
X-Proxy
X-RemovedCookies
X-ProcessESI
Ms-Operation-Id
X-Cacheable-TTL
Realpath
X-Instance
X-RTag
X-Tt-Trace-Tag
Access-Control-Request-Headers
X-Real-IP
X-Tt-Trace-Host
X-Fastcgi-Cache
GEO-INFO
X-Contextid
X-Wix-Request-Id
X-Region
X-UUID
X-Yottaa-Optimizations
X-Cache-Time
X-Yottaa-Metrics
X-Distributor
X-Drupal-Cache-Contexts
X-Page-View
Referer-Policy
X-HTML-Minification-Powered-By
Eomportal-Instance
Countrycode
X-FW-Server
X-FW-Static
X-FW-Type
X-FW-Serve
X-FW-Hash
X-Cache-Expired-At
X-FW-Dynamic
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
Node
X-Environment-Context
X-B
X-L-Path
X-Cluster-Name
Liferay-Portal
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Node-Name
X-Tumblr-User
X-G
X-Cache-Control
X-Content-Powered-By
X-Cache-Hit
X-IPS-LoggedIn
X-User-Agent
Server-Info
X-Tumblr-Pixel-2
Webserver
X-Pass-Why
X-Amz-Meta-S3cmd-Attrs
Section-Io-Origin-Status
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Id
From-Origin
X-App-Server
X-Varnish-Ttl
X-Ratelimit-Limit
SRV
Protected
Ec-Rule-Version
X-Protected-By
X-FireWall-Port
X-Revision
X-Backend-Name
X-Oracle-Dms-Rid
Frame-Options
X-Cache-Server
Cache-Status
CF-IPCountry
X-Handled-By
X-RN-RSRV
X-Hl-Ver
X-ES-SERVER
X-Mode
X-Www-Served-By
Meta-Geo
X-Endurance-Cache-Level
X-Hyper-Cache
X-UPSTREAM-Address
X-FB-TRIP-ID
X-Storage
X-Soup
X-Locale
X-NYM-Debug-Backend
Retry-After
X-Forwarded-Host
X-Site-Version
X-Web-Node
Fastly-SSL
Country
X-Pubstack
X-Adobe-Content
Decoy-Debug-Status
X-Adobe-Loc
Decoy-Debug-TTL
Decoy-Debug-Key
X-Human
Cache-Tv-Group
X-Cache-Grace
X-Varnishpool
X-ProxyCache-Key
Azure-RegionName
X-TT-LOGID
TWC-Locale-Group
TWC-Privacy
Azure-SiteName
X-OCL
Webcakes-Region
X-Access
X-Be
X-Proto
X-PHP-Host
X-PCL
Webcakes-App-Name
Azure-SlotName
X-Origin-Hint
Azure-InstanceId
X-Timing-Wait
Cache-Name
X-Redis-Cache
TWC-Connection-Speed
Selected-Fe
X-Format
X-Proxy-Build
Property-Id
X-Say-Cacheable
X-Labrador-Cache-Channel
TWC-Device-Class
Azure-Version
X-SayCDN-TTL
X-Say-TTL
TWC-GeoIP-LatLong
X-Section
X-Uri
X-BYPASS-REASON
TWC-GeoIP-Country
X-ProxyCache-Status
Webcakes-App-Version
X-Origin-Date
X-S-Maxage
X-LAGOON
X-PERF
X-Via-CDN
X-WA-Info
X-FW-Version
X-Sql-Duration-Ms
X-UA-Device-Type
X-Sql-Count
X-ApacheServer
X-Via-Fastly
X-TNCMS
X-No-Session
X-Loop
X-R9-Blue-Green-Version
X-Request-Time
X-Server-W
X-Hosted-By
X-FTR-Cache-Status
X-FTR-DC
X-AWS-Id
X-FTR-Balancer
X-MP-GENERATED-AT
X-Country-Code-Real
S-Cnection
X-LJ-Flow-ID
X-Cluster
X-FTR-Backend
X-FTR-Backend-Server
X-FTR-Realm
X-Qloud-Router
X-Status
X-VWS-Id
X-Shopify-Stage
X-Zipkin-Id
Mn-Server-Ip
X-Routing-Service
X-Alternate-Cache-Key
X-ShardId
X-Sorting-Hat-PodId
X-ShopId
X-Proxied
X-Storefront-Renderer-Rendered
X-CCM
X-AIR-PT
X-Sorting-Hat-ShopId
X-Cache-TTL-Remaining
Cache-Hits
X-FTR-Expires
X-Xfnlog-Site
X-Ratelimit-Remaining
X-Rendered-As
X-Is-Bot
Xserver
X-Dynatrace
X-Device-Type
X-Tec-Api-Root
X-Tec-Api-Version
X-Tec-Api-Origin
X-Unique-Id
X-Cache-Var-Map
X-Cache-Var
X-Air-Hostname
X-SRV
X-Detected-As
Apigw-Requestid
X-Nginx-Cache
X-Info
X-EdgeConnect-Cache-Status
AMP-Access-Control-Allow-Source-Origin
X-Webkit-Csp
X-Cache-Host
X-Amz-Apigw-Id
X-Amzn-Remapped-Content-Length
X-Amzn-RequestId
X-Dc
X-Cdn
X-Debug-IsPreview
X-Microcachable
X-Debug-IsConnected
X-Cache-Enabled
SD-X-WS
X-Content-Age
X-GEO
X-Varnish-Server
X-Platform
Tracecode
Amp-Access-Control-Allow-Source-Origin
X-Time-Microsecs
X-Varnish-Grace
X-Azure-Ref
X-Backend-TTL
X-GG-Cache-Date
X-APP-VERSION
X-Cache-Backend
X-ServerID
X-Backend-Host
Uber-Trace-Id
X-DynaTrace-JS-Agent
X-Proxy-Cache-Status
X-Erf-Stays-Bingo-Pdp-Web
DSUID
X-Tb
Akamai-GRN
X-BCube-Filmed-By
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Oss-Storage-Class
X-Oss-Server-Time
X-Oss-Request-Id
X-ATG-Version
X-NewRelic-App-Data
Backend
X-ID
X-Sucuri-ID
Arc-Version
PB-PID
PB-RID
X-Trace-Id
X-Akamai-Transformed
X-Magnolia-Registration
ServedBy
X-Correlation-ID
Meta-Geo-Continent
Expiry
Machine
X-Varnish-Cache-Hits
MD5-Digest
Fastcgi-X-Cache-Version
BehaviorPad-Version
Lfy
Instruction
X-Cache-PHP
X-Cache-NGX
DCR-Decision-By
X-RCS-CacheZone
DCR-Processing-Time-Ms
X-Aed
X-PBS-Appsvrname
X-PAYTM-SRV-ID
X-Processor
X-Request-UUID
X-Rojux
X-Rewrite-Enabled
X-Origin-TTL
X-Origin-CC
X-GeoIP-City
X-Generation-Time
X-Level-Front-Cache
X-Location
X-Matched-Rule
X-S
X-S-Cookie
X-VG-WebServer
X-VG-WebCache
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-Vdms-Version
X-Vdms-Path
X-Session-Fingerprint
X-ScT
X-SRCache-Key
X-Thinkindot-L3
X-Trv-Group
X-Generated-On
X-From
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
Thinkindot-Control
X-A
X-A-Dam
X-A-Ccd
T-Server
SR-User-Adfree
Path
Odigeo-Trace-Id
Pramga
Release
Rendered-Blocks
X-A-Dcw
X-A-Dgt
X-Destination
X-D
X-Device-Os
X-External-Request-Id
X-Fetched-On
X-Connection-Hash
X-CF-Lambda-Version
X-Application
X-A-Wwc
X-ARC
X-Cache-NE
X-CF-Lambda-Fn
Mobile-Detection-Method
X-B-Cookie
X-Origin-Response-Time
X-CSRF-Token
X-Varnish-Hostname
Gh-Request-Id
X-Is-Gdpr
X-Azure-Ref-OriginShield
Ha-Gx-Prefs
HA-Ipaddr
X-Irp-Debug
Host-ID
Fastly-Backend-Name
X-Micro-Cache
Cf-Device-Type
X-OVcl
X-OVcl-Cache
X-Node-Id
X-Mvc-Supplant-Cachable
X-HS-Content-Campaign-Id
Cache-Host
X-Owner
L5d-Success-Class
X-Cdn-Origin
X-NWS-UUID-VERIFY
X-CGP
X-Cache-Info
X-Cache-Date
X-Backend-State
X-Bip
X-Cache-Bucket
UCS
X-Csrf-Jwt
X-Generated-In
X-Geo-Header
X-Has-Esi
X-FC-Vary-Parameters
X-Eu-Site
Ssr
X-Adobe-Source
C-Via
X-JWT-State
X-SVT-ORM-RULES
X-Sn-Servicetimems
X-Skip-Cache
X-SVT-ORM-VERSION
X-Swa-Ws
X-User
X-Tumblr-Pixel-3
X-Thanos
AKAMAI
X-Debug-Cache
X-Ms-Version
X-Ms-Request-Id
X-VServer
DB-Nickname
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-Cache-Tags
X-Fastly-Cache
PFcat
X-B3-Traceid
User-Cache-Control
On-Server
Pagetype
X-Generated-By
X-TrackingId
X-Fastly-Backend
Server-Ext
X-Core-Value
Wxu-Next-Region
X-VarnishDD-TTL
X-Cms-Context
V-Age
Wxu-Next-Commit
X-Clientip
X-Developer
X-Developers
Server-Hostname
Server-Host
X-Envoy-Decorator-Operation
Sever-Int
X-Varnish-Hits
X-GeoIP
Wxu-Next-Hostname
NGX
X-Cache-Remote
X-Origin-Expires
X-Request-Host
X-Reqid
CloudFront-Viewer-Country
Content-Disposition
X-Nginx-Cache-Key
X-Request-URI
X-Scheme
L
X-IP
Magicmarker
Locid
X-HN
CacheControlHeader
X-Policy
X-Request-Start
X-Ratelimit-Reset
X-NU-AKA-ACS-Version
Location
X-Block-Status
X-Clara-WADP
X-Origin
X-Rebelmouse-Surrogate-Control
X-Platform-Server
X-WADP-Cache
X-Varnish-Remaining-TTL
X-Cache-Expires
X-Cache-Id
X-VG-TLSProxy
X-Old-Content-Length
X-Servername
X-TX-ID
X-Gen-Mode
X-Fmm-Version
X-Varnish-CookieHashed-On
X-Hnp-Log
X-Varnish-Beresp-Grace
X-GoCache-CacheStatus
X-Var-Ttl
X-Variation
X-Rebelmouse-Cache-Control
X-Li-Fabric
X-Varnish-CookieINHashed-On
X-DPWN-IS-SECURE
X-Method
X-Gzip
X-DefElseHash
X-Loc
X-SIPLIST1
X-Esi-Check
X-Li-Pop
X-LI-UUID
X-CUA
X-DefHash
True-Client-Country-4JS
Web-Mar-Node
X-TA-CDN-Provider
CDCHOST
Cf-Bgj
Origin
Fastly-SIE
Platform
Fastly-SWR
Rt-Fastcgi-Cache
Apple-News-Services-Request-Url
Vix-Hermes-Req-Id
IsBot
Apple-News-Services-Handled
Adler-Geo
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Is-Eu
X-NC
CDN-RequestId
X-Cache-Debug
CDN-RequestCountryCode
X-B3-Spanid
X-Dispatcher-Server
X-Varnish-Beresp-Status
CDN-Uid
X-NAPM-TraceId
X-Slack-Backend
X-Branch-Name
NM-Fastcgi-Cache
CDN-Cache
Fastly-Drupal-HTML
X-Gamma-Serve
X-Varnish-Beresp-Ttl
CDN-CachedAt
X-Goog-Meta-Goog-Reserved-File-Mtime
CDN-PullZone
CDN-EdgeStorageId
HostName
X-App-Version
X-Core-Mission
Url
X-Hash
X-NCache
X-Host-Name
X-Varnish-Url
X-EC-Lua
CACHE
X-CS
X-Mvc-Supplant-OutputCached
X-Cdn-Forward
X-Response-By
S-Rt
X-Aicache-OS
X-PF-Uncompressing
X-Varnish-Cacheable
X-B3-SpanId
Pics-Label
X-LB-ID
X-Proxy-Cachei7
X-Refresh
X-CACHE-GROUP
Xkeyi7
Sid
X-BBXSRF
N-Cache
Cross-Origin-Window-Policy
X-CDN-Forward
X-Via-Popv
X-Cache-2
X-FireWall-Protection
X-Via-Popn
X-Esi
Content-Secure-Policy
X-Via-Poph
X-Sucuri-Cache
Ohc-File-Size
X-Cc-Req-Id
X-Varnish-Authentication
X-Epic-Correlation-Id
X-Contensis-Viewer-Groups
Esi-Enabled
X-Cc-Via
Cteonnt-Length
D-Cc-Upstream
X-Cache-ASPX
X-RateLimit-Limit
X-Svr
X-Servedbyhost
X-Error
X-Nc
X-Wa
X-Tb-Optimization-Total-Bytes-Saved
MIME-Version
Source
X-DC
X-TraceId
X-Cs
Who
X-Srv
X-TIME
X-Server-IP
Country-Code
X-Unique-ID
Req-Svc-Chain
X-Webkit-CSP-Report-Only
XServer
X-Gdpr
Hostname
X-Planisys-CDN-Rules
GeoIp-Country-Code
HitType
X-LiteSpeed-Cache-Control
Geoip-Latitude
X-FPC
X-API-Version
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
X-Origin-Time
X-Nyt-Route
Server-Ttl
X-Cache-Config
X-SN
X-VC
X-HS-Status
X-LI-Proto
X-URL
Ohc-Cache-HIT
X-NGINX-Cache
X-Fastly-Request-Id
X-Webstats-RespID
X-VCL-Version
X-NodeID
Cmstype
Server-ID
Svr
Cmsid
X-SB
Geo-Info
X-CACHE-KEY
X-Check-Cacheable
X-Served-From
X-SD-PageType
Viewtype
Kp-EeAlive
VivaBuild
SID
X-Viewer-Country
X-Render-Time
X-Vgn-Hpd-Reason
X-Ua
A
Cache-Key
X-HOST
NtCoent-Length
Request-ID
X-Vcl-Version
M-TraceId
X-BBC-Edge-Cache-Status
EpKe-Alive
X-UA
X-DB
X-DI
X-Worker
X-RAMCache
X-FORWARDED-FOR
X-DW
X-DSS
X-Air-Source
TDXMobile
X-Auto-Login
X-CCDN-CacheTTL
X-CCDN-Origin-Time
Cache-Provider
X-Li-Proto
Arc-Country
X-CF-Powered-By
X-RSL
X-RPS
X-CSRF-TOKEN
Server-Id
Resin-Trace
Cross-Origin-Opener-Policy
X-Hcs-Proxy-Type
X-TIM-N
X-RPM
X-Dynatrace-Js-Agent
X-Ftr-Cache-Host
Filterid
X-Internal-Host
ProcessTime
X-App
GeoIP-Country-Code
GeoIP-Latitude
Processtime
CDN
Srv
Upgrade-Insecure-Requests
X-Cluster-Node
X-Action
X-Newrelic-Synthetics
Datacenter
X-FTR-Cache-Host
X-ServedByHost
Tcn
X-Oss-Cdn-Auth
X-Vc
X-WA
X-Fpc
Mime-Version
X-Service
NGB
CF-Cached-On
X-CLOUD-TRACE-CONTEXT
X-Geo
X-BBC-Origin-Response-Status
Proxy-Connection
OT-Force-Account-Verify
X-HITS
X-HostName
X-SaId
Cdn
X-Via-PopV
X-Via-NSCOPI
X-Akamai-Pragma-Client-IP
X-ND-Cache
X-Via-PopH
X-Via-PopN
X-PHP-Backend
WZWS-RAY
X-Dw-Trace-Id
X-NGENIX-Cache
X-MSEdge-Features
X-MSEdge-Flight
FSS-Cache
X-Fastly-Backend-Reqs
X-BACKEND-TTL
X-JoinUs
X-Cache-Tag
X-Forwarded-Site
DataCenter
X-Client-Ip
X-Edge-Location
X-Cdn-Request-ID
X-CACHE-AGE
X-Extlb
X-Lb-Id
PICS-Label
W
X-IN-APIGATEWAY
X-Flog
X-Hello
X-ABtesting
X-Parent-Response-Time
X-Pf-Uncompressing
Dnion-Transfer-Encoding
X-IN-APIGATEWAYSSL
X-Provided-By
LB
X-Presslabs-Stats
Media-Length
Vha6-Origin
X-LiteSpeed-Tag
X-Swift-Error
X-Oracle-DMS-ECID
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Proxy-Upstream
X-Region-Sid
X-Req
X-VC-Cache
X-UnsetCookies
X-PJAX-URL
X-Pad
X-Accel-Expires-Debug
Surrogated-Key
X-Bc-Bl
X-Date
X-Depends-On
Env
X-MiniProfiler-Ids
Epwk-X-Cache
Memcached
We-Hiring
Mail-Subject
Xet-Cookie
URI
X-ZONE
X-Zone
Cf-Ipcountry
Memory
X-Snapshot-Date
X-Akamai-ERPolicy
X-ElasticPress-Query
X-Acquia-Site
X-Vcache
X-Akamai-Request-ID
X-B3-Parentspanid
X-Varnish-Beresp-TTL
X-Air-Trace-Id
X-Amz-Meta-Cb-Modifiedtime
X-Men
X-Varnish-URL
X-Sigma-Backend
X-APP
X-Rocket-Build-Number
X-Sigma
X-Akamai-ERRuleID
Time
X-Ms-Meta-Staticbatchstarttime
X-Request-URL
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-Acquia-Purge-Tags
X-Csrf-Token
X-Ms-Meta-Originalurl
X-Request-Url
X-ElasticPress-Search
CountryCode
X-Storefront-Renderer-Verified
NnCoection
Phost
X-Via-SSL
Inserted-Into-Cache-At
X-Tid
X-Litespeed-Cache-Control
X-Redis-Duration-Ms
Content-Script-Type
X-Traceid
Content-Style-Type
X-Acc-Rdl
X-Acc-Debug-Context
Edge-Copy-Time
Ohc-Response-Time
X-ServerName
X-C
X-Redis-Count
X-Via-Edge
X-Debug-Cache-Store
X-Debug-Cache-Fetch
Environment