Threat Level: green Handler on Duty: Renato Marinho

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
X-XSS-Protection
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-UA-Compatible
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Xss-Protection
X-Cache-Status
X-Request-ID
X-Generator
X-DNS-Prefetch-Control
X-Cacheable
X-Ua-Compatible
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Content-Encoding
X-CDN
X-AspNetMvc-Version
Feature-Policy
Status
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Upgrade
X-Via
Access-Control-Max-Age
Keep-Alive
X-Ws-Request-Id
X-Age
X-AH-Environment
X-Robots-Tag
X-Turbo-Charged-By
Request-Context
X-Proxy-Cache
X-Cache-Group
EagleId
Server-Timing
X-Backend
X-Hacker
X-Server
Host-Header
Report-To
X-Amz-Request-Id
X-Server-Powered-By
X-Amz-Id-2
Grace
X-Nginx-Cache-Status
X-UA-Device
X-Dns-Prefetch-Control
X-Rq
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Page-Speed
Cf-Railgun
X-Pingback
X-OneAgent-JS-Injection
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Amz-Version-Id
X-Cache-Spec
NEL
X-Device
X-CST
Allow
Xkey
X-Vhost
X-Host
X-Backend-Server
X-Server-Id
X-WebKit-CSP
EagleEye-TraceId
Surrogate-Control
Request-Id
X-Dispatcher
X-Node
Content-Location
X-Response-Time
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Akam-SW-Version
X-Ruxit-JS-Agent
P3p
X-ASPNET-VERSION
X-Ac
X-Application-Context
X-Cache-Lookup
X-Country
Accept-Ch
X-Template
Accept-CH
X-Language
X-Mod-Pagespeed
X-Readtime
Accept-Ch-Lifetime
Accept-CH-Lifetime
X-Cloud-Trace-Context
MS-Author-Via
X-B3-TraceId
Rating
X-Origin-Cache
X-HW
X-MS-InvokeApp
X-Cnection
X-Url
X-PC
X-Vname
X-TtlSet
X-Clacks-Overhead
Edge-Control
X-GitHub-Request-Id
X-ESI
X-ORACLE-DMS-ECID
X-Trace
Response
Pagespeed
Display
X-Content-Type
X-Middleton-Display
X-Sol
X-Middleton-Response
X-D2id
Arr-Disable-Session-Affinity
X-Exp-Variant
X-Exp-Id
X-Cdn-Fetch
X-Use-Magma
X-GoogleNews-Bot
X-Kinja-Build
X-Kinja-Server
X-Kinja
X-Kinja-Revision
Verso
X-ORACLE-DMS-RID
X-Vcap-Request-Id
X-Goog-Hash
X-Rack-Cache
X-Country-Code
X-Buckets
X-Varnish-TTL
X-Server-Name
X-Navigation-Version
Service-Worker-Allowed
X-Powered-By-Plesk
X-VARITI-CCR
X-Amz-Rid
X-Abt-Application-Version
X-TTL
X-FastCGI-Cache
X-Fastly-Request-ID
X-Client-IP
X-Cache-TTL
X-Webkit-CSP
Fastly-Restarts
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-Cached
X-Release
X-MSEdge-Ref
X-SharePointHealthScore
SPRequestGuid
X-Dw-Request-Base-Id
X-Element-Page-Cache
X-NF-Request-ID
SPIisLatency
SPRequestDuration
X-Oneagent-Js-Injection
Mrf-Cache-Status
X-B3-TraceId-Primal
Public-Key-Pins
MRF-Tech
RTSS
Access-Control-Request-Method
Ar-Sid
AR-Request-ID
X-SRCache-Store-Status
X-SRCache-Fetch-Status
AR-ATIME
AR-CACHE
AR-PoweredBy
X-Edge
X-LLID
X-Powered-CMS
X-Ezoic-Cdn
Cache-Tag
X-Upstream
Content-MD5
X-Origin-Upstream-Status
X-Litespeed-Cache
X-Px
Fusion-Content-Source
Fusion-Source
Fusion-Template-Id
Fusion-Content-Id
Fusion-Deployment-Id
Fusion-Component-Id
X-Jurisdiction
X-HP-Webp
S
X-Version
X-ECACHE
X-Mid
X-MCACHE
X-Recruiting
X-Mg-S
Charset
X-Content-Digest
X-PressLabs-Stats
X-Kinsta-Cache
X-Amz-Server-Side-Encryption
Fastcgi-Cache
X-T
X-Ttl
Cache-Tags
X-Id
MicrosoftSharePointTeamServices
Filters
X-Content-Security-Policy-Report-Only
Front-End-Https
X-DynaTrace
X-Logged-In
X-Accel-Expires
Server-Node
Edge-Cache-Tag
X-Debug
X-Forwarded-Proto
X-Correlation-Id
X-Grace
X-Forwarded-For
TP-L2-Cache
X-Ruxit-Js-Agent
TP-Cache
Server-Name
Nginx-Cache
X-XRDS-LOCATION
X-Amzn-Trace-Id
X-Kong-Upstream-Latency
TCN
Nel
X-Kong-Proxy-Latency
X-Request-Received
X-Request-Processing-Time
Surrogate-Key
X-Fastcgi-Cache
X-Pinterest-Direct
X-Shield-Request-Id
X-Varnish-Age
X-B3-Sampled
X-Request-Handler-Origin-Region
X-Yandex-Sdch-Disable
X-Microsite
X-Ser
X-Activity-Id
X-Hits
X-Az
X-AppVersion
X-Amz-Replication-Status
X-F-Cache
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Combine-CSS
X-DIS-Request-ID
X-GUploader-UploadID
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Origin-Server
Accept-Charset
X-Geo-Country
Alternate-Protocol
X-Git-Hash
X-Rid
X-Respond-Thread
Cache
X-Frontend
X-Time
Section-Io-Cache
X-XRDS-Location
X-FTR-Request-ID
X-LB-Cache
Host
X-Upgrade-Enabled
X-DataDome
Access-Control-Allow-Method
X-NWS-LOG-UUID
X-Seen-By
X-Mobile-URL
X-Cache-Age
MS-CV
X-Cache-Key
Paypal-Debug-Id
X-VCache
X-TT
X-IPLB-Instance
Healthy
ServerID
X-AOL-HN
X-Hostname
Powered-By-ChinaCache
X-Type
Cleartype
X-Varnish-Backend
X-Content-Options
X-Whom
X-Flags
Payment
X-App-Environment
X-Aspnet-Duration-Ms
X-Is-Crawler
X-Route-Name
X-Request-Guid
X-Providence-Cookie
X-Server-ID
X-Signature
X-Cache-Action
X-B-Cache
X-Source
X-Page-Id
X-WebKit-CSP-Report-Only
Fastcgi-Useragent
X-Jobs
X-Debug-Info
X-Load-Cache
X-Daa-Tunnel
X-N
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Mobile
X-FB-Debug
X-Browser-Type
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Via-JSL
X-RateLimit-Remaining
Realpath
X-Webkit-Csp
X-Contextid
Refresh
Version
Node
X-Wix-Request-Id
X-Original-Request-Id
X-Cached-By
X-Accel-Buffering
X-Response-Served-From
X-Rule
X-Drupal-Cache-Tags
X-Cacheable-TTL
Ms-Operation-Id
X-Akamai-Edgescape
X-RTag
X-Framework
X-Zen-Fury
DC
X-Proxy
X-RemovedCookies
X-ProcessESI
Viewport
X-Cache-Rule
X-Cache-Operation
Access-Control-Request-Headers
X-Distributor
X-B
X-Real-IP
X-HTML-Minification-Powered-By
X-Cache-Time
X-Instance
X-Drupal-Cache-Contexts
Eomportal-Instance
X-Region
X-UUID
Referer-Policy
X-Page-View
X-Cluster-Name
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Cache-Expired-At
X-FW-Hash
X-FW-Dynamic
VIX-Pulpo-Upstream-Status
X-FW-Serve
Liferay-Portal
X-FW-Static
X-FW-Server
Countrycode
X-FW-Type
VIX-Pulpo-Node
X-Cache-Control
X-Content-Powered-By
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Cache-Hit
X-G
X-IPS-LoggedIn
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Tumblr-User
X-L-Path
X-Environment-Context
DynaTrace
X-FireWall-Port
X-Pass-Why
Server-Info
X-App-Server
Xserver
X-User-Agent
CF-IPCountry
X-Varnish-Ttl
X-Protected-By
Section-Io-Id
Section-Io-Origin-Status
Section-Origin-Responded
X-Tumblr-Pixel-2
Webserver
Ec-Rule-Version
Section-Io-Origin-Time-Seconds
From-Origin
X-Ratelimit-Limit
GEO-INFO
X-Www-Served-By
SRV
X-Node-Name
Protected
X-Nginx-Cache
X-Cache-Server
X-Ratelimit-Remaining
X-Mode
X-Hl-Ver
X-ES-SERVER
X-UPSTREAM-Address
X-Debug-IsConnected
X-RN-RSRV
X-Debug-IsPreview
X-Backend-Name
Meta-Geo
X-Handled-By
X-Endurance-Cache-Level
X-Site-Version
X-Adobe-Loc
X-Device-Type
Cache-Status
X-Uri
Frame-Options
X-FB-TRIP-ID
X-Locale
X-Adobe-Content
Cache-Tv-Group
X-Soup
X-Web-Node
X-Varnishpool
X-UA-Device-Type
X-MP-GENERATED-AT
X-NYM-Debug-Backend
X-Storage
X-Be
X-PHP-Host
X-Labrador-Cache-Channel
X-Redis-Cache
X-Sql-Count
X-Pubstack
TWC-Connection-Speed
TWC-Device-Class
X-ProxyCache-Key
TWC-GeoIP-Country
X-WA-Info
X-Timing-Wait
Decoy-Debug-Key
Decoy-Debug-Status
Country
Cache-Name
X-Human
Decoy-Debug-TTL
X-No-Session
X-OCL
Property-Id
X-Sql-Duration-Ms
Fastly-SSL
Selected-Fe
X-Request-Time
X-Origin-Date
X-ProxyCache-Status
TWC-GeoIP-LatLong
Webcakes-Region
X-Proxy-Build
X-Hyper-Cache
X-PCL
X-Proto
Webcakes-App-Name
X-Origin-Hint
TWC-Privacy
Webcakes-App-Version
TWC-Locale-Group
X-BYPASS-REASON
X-Via-Fastly
Azure-Version
X-Say-Cacheable
X-LJ-Flow-ID
X-Say-TTL
X-S-Maxage
Azure-SlotName
X-LAGOON
Azure-RegionName
X-SayCDN-TTL
Azure-SiteName
Azure-InstanceId
X-Section
X-Access
X-FW-Version
Retry-After
X-Format
X-R9-Blue-Green-Version
X-Server-W
X-AIR-PT
X-Loop
X-TNCMS
X-VWS-Id
X-Hosted-By
X-AWS-Id
X-ApacheServer
X-Cache-TTL-Remaining
X-Forwarded-Host
X-Revision
X-Cluster
X-PERF
X-CCM
X-ShopId
X-Storefront-Renderer-Rendered
X-Xfnlog-Site
X-Status
X-Sorting-Hat-ShopId
X-ShardId
X-Cache-Grace
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Alternate-Cache-Key
X-Varnish-Grace
Mn-Server-Ip
AMP-Access-Control-Allow-Source-Origin
X-TT-LOGID
X-SRV
X-Tec-Api-Version
X-Tec-Api-Origin
X-Zipkin-Id
X-Proxied
X-Tec-Api-Root
X-Routing-Service
X-Dc
Apigw-Requestid
X-Rendered-As
X-Is-Bot
X-Varnish-Server
X-Qloud-Router
X-Amz-Meta-S3cmd-Attrs
S-Cnection
X-Info
X-FTR-Balancer
X-Country-Code-Real
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Cache-Status
X-Via-CDN
X-FTR-DC
X-FTR-Realm
X-Cache-Enabled
X-GG-Cache-Date
Cache-Hits
X-Microcachable
X-Content-Age
X-Cdn
X-Platform
Uber-Trace-Id
X-Proxy-Cache-Status
X-Detected-As
X-TA-CDN-Provider
X-Cache-Host
X-EdgeConnect-Cache-Status
X-Azure-Ref
X-FTR-Expires
X-Backend-Host
X-Amz-Apigw-Id
X-Amzn-Remapped-Content-Length
X-CSRF-Token
X-Amzn-RequestId
X-NWS-UUID-VERIFY
X-App-Version
X-Air-Hostname
X-Aspnetmvc-Version
Tracecode
SD-X-WS
Akamai-GRN
X-ATG-Version
X-Time-Microsecs
X-Cache-Var
X-Oss-Storage-Class
X-Oss-Object-Type
HostName
X-Cache-Var-Map
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-Backend-TTL
X-Trace-Id
X-ServerID
Amp-Access-Control-Allow-Source-Origin
X-DynaTrace-JS-Agent
X-Debug-Cache
ServedBy
X-CACHE-KEY
X-RCS-CacheZone
X-Tb
X-Cache-PHP
X-Varnish-Hostname
X-BCube-Filmed-By
X-Cdn-Forward
X-Cache-NGX
X-Unique-Id
Backend
X-Correlation-ID
X-Sucuri-ID
X-CS
DB-Nickname
DSUID
X-TX-ID
X-B3-SpanId
Expiry
Path
X-Fetched-On
X-Origin-CC
Fastcgi-X-Cache-Version
Instruction
X-External-Request-Id
X-From
Machine
X-Origin-TTL
Mobile-Detection-Method
X-Magnolia-Registration
X-A-Ccd
X-A
Odigeo-Trace-Id
MD5-Digest
Meta-Geo-Continent
DCR-Processing-Time-Ms
DCR-Decision-By
Thinkindot-CacheControl
X-Ms-Version
T-Server
Thinkindot-CacheControl-Type
Thinkindot-Control
X-Location
X-Level-Front-Cache
X-Destination
X-Ms-Request-Id
SR-User-Adfree
X-NAPM-TraceId
X-Generated-On
Release
X-Generation-Time
Rendered-Blocks
X-GeoIP-City
BehaviorPad-Version
X-Device-Os
X-D
X-A-Dcw
X-S-Cookie
X-ARC
X-ScT
X-Session-Fingerprint
X-S
X-Rewrite-Enabled
X-Application
X-VG-WebCache
X-Request-UUID
X-Connection-Hash
X-Vdms-Version
X-Thinkindot-L3
X-Trv-Group
X-GEO
X-B-Cookie
X-CF-Lambda-Version
X-Vdms-Path
X-CF-Lambda-Fn
X-SRCache-Key
X-VG-WebServer
X-Rojux
X-A-Wwc
Xc-Version
X-Cache-NE
X-A-Dgt
X-Processor
X-PBS-Appsvrname
X-A-Dam
X-PAYTM-SRV-ID
X-Aed
X-Vtex-Remote-Cache
X-Owner
X-Vtex-Processado-Em
X-NewRelic-App-Data
X-Akamai-Transformed
X-Adobe-Source
X-Cache-Backend
X-GeoIP
X-Geo-Header
Arc-Version
C-Via
CacheControlHeader
Cf-Device-Type
NGX
Server-Host
X-Bip
X-Fastly-Cache
Host-ID
PB-RID
PB-PID
On-Server
X-VServer
AKAMAI
X-FC-Vary-Parameters
X-Cache-Bucket
Pagetype
Fastly-Backend-Name
Gh-Request-Id
Content-Disposition
X-Has-Esi
UCS
X-Skip-Cache
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Is-Gdpr
X-JWT-State
X-Micro-Cache
X-Varnish-Cache-Hits
X-Node-Id
X-OVcl
X-Reqid
X-Core-Value
X-Mvc-Supplant-Cachable
X-Irp-Debug
X-Azure-Ref-OriginShield
X-Tumblr-Pixel-3
X-OVcl-Cache
X-Cms-Context
X-HS-Content-Campaign-Id
X-TrackingId
X-Thanos
User-Cache-Control
Wxu-Next-Commit
X-Fastly-Backend
X-Block-Status
X-Cache-Tags
X-Backend-State
X-Clara-WADP
Server-Ext
X-Csrf-Jwt
NM-Fastcgi-Cache
X-Clientip
X-CUA
X-Cache-Id
Wxu-Next-Hostname
Wxu-Next-Region
X-Developer
Web-Mar-Node
X-DPWN-IS-SECURE
Ssr
X-DefHash
Sever-Int
X-Developers
X-Branch-Name
X-CGP
X-DefElseHash
X-Envoy-Decorator-Operation
X-Dispatcher-Server
PFcat
V-Age
X-Eu-Site
X-Esi-Check
Platform
Server-Hostname
X-Nginx-Cache-Key
X-Platform-Server
X-Origin-Response-Time
X-Policy
X-B3-Traceid
X-Rebelmouse-Cache-Control
X-Ratelimit-Reset
X-Origin-Expires
X-Origin
Magicmarker
X-Li-Pop
X-Matched-Rule
X-Cache-Info
X-Old-Content-Length
X-NU-AKA-ACS-Version
X-Rebelmouse-Surrogate-Control
X-Request-Host
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-VarnishDD-TTL
X-WADP-Cache
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-Varnish-CookieHashed-On
X-Varnish-Beresp-Grace
X-Swa-Ws
X-Scheme
X-User
X-Var-Ttl
X-Variation
X-Li-Fabric
X-LI-UUID
Lfy
X-Generated-By
X-Generated-In
CDN-Uid
CDN-RequestCountryCode
CDN-RequestId
L5d-Success-Class
X-Gen-Mode
Ha-Gx-Prefs
Is-Eu
X-Fmm-Version
Fastly-SWR
Fastly-SIE
HA-Ipaddr
CDN-PullZone
Location
Adler-Geo
Locid
X-HN
X-IP
X-Hnp-Log
CDN-EdgeStorageId
X-Gzip
CDN-CachedAt
CDN-Cache
CDCHOST
X-GoCache-CacheStatus
Cache-Host
X-VG-TLSProxy
X-Varnish-Hits
X-Request-URI
X-LB-ID
X-Method
X-Hash
X-SIPLIST1
X-Slack-Backend
X-Varnish-Beresp-Status
X-Gamma-Serve
X-Varnish-Beresp-Ttl
X-Cache-Expires
Vix-Hermes-Req-Id
X-EC-Lua
X-Cache-Debug
True-Client-Country-4JS
Rt-Fastcgi-Cache
IsBot
Cf-Bgj
L
CloudFront-Viewer-Country
Sid
X-Nc
X-APP-VERSION
X-ID
Apple-News-Services-Host
Origin
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Loc
X-Cdn-Origin
X-Kinja-Server-Push
Fastly-Drupal-HTML
Apple-News-Services-Parsed-Url
X-Sn-Servicetimems
Apple-News-Services-Handled
Pramga
X-Unique-ID
Apple-News-Services-Request-Url
X-CLOUD-TRACE-CONTEXT
X-Aicache-OS
X-PF-Uncompressing
X-Via-Popn
X-Mvc-Supplant-OutputCached
X-Via-Poph
X-Via-Popv
X-NCache
Esi-Enabled
X-Cache-Date
Who
Geo-Info
X-Varnish-Url
Country-Code
X-Refresh
X-Core-Mission
Tcn
X-Servername
X-Erf-Stays-Bingo-Pdp-Web
X-Request-Start
Pics-Label
X-Tb-Optimization-Total-Bytes-Saved
X-Epic-Correlation-Id
Url
X-RateLimit-Limit
X-TraceId
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-FireWall-Protection
Req-Svc-Chain
X-Planisys-CDN-Cache
X-Cache-Remote
X-NC
Filterid
X-Response-By
X-Dynatrace
X-Varnish-Cacheable
S-Rt
X-Error
Cmsid
Source
X-Proxy-Cachei7
Xkeyi7
Cmstype
Content-Secure-Policy
GeoIp-Country-Code
N-Cache
X-BBXSRF
Geoip-Latitude
X-Served-From
Svr
X-HS-Status
Kp-EeAlive
X-Webkit-CSP-Report-Only
X-B3-Spanid
X-DC
X-Cache-2
A
VivaBuild
MIME-Version
X-Host-Name
Server-Ttl
HitType
Viewtype
Cache-Key
X-Vcl-Version
X-Srv
Cross-Origin-Window-Policy
X-Sucuri-Cache
Ohc-File-Size
X-Cc-Via
NGB
X-Varnish-Authentication
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Cc-Req-Id
D-Cc-Upstream
X-LiteSpeed-Cache-Control
Cteonnt-Length
M-TraceId
X-URL
X-Air-Source
Server-ID
X-HostName
X-Wa
Arc-Country
X-Li-Proto
Cross-Origin-Opener-Policy
TDXMobile
X-Servedbyhost
X-Svr
X-Oracle-Dms-Rid
NtCoent-Length
X-Server-IP
X-Vgn-Hpd-Reason
X-Esi
CACHE
X-CDN-Forward
X-LI-Proto
X-RAMCache
X-WA
X-Origin-Time
X-Nyt-Route
X-API-Version
X-Geo
X-Vc
X-ServedByHost
X-Gdpr
X-Cache-Config
X-FPC
X-Cs
X-HOST
X-VC
DataCenter
X-JoinUs
X-Viewer-Country
Resin-Trace
X-Check-Cacheable
X-Service
X-SaId
X-PHP-Backend
X-NGENIX-Cache
SID
X-SN
Request-ID
X-Edge-Location
X-UA
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
Server-Id
Cache-Provider
X-SB
X-RSL
X-Webstats-RespID
X-TIM-N
X-Internal-Host
X-DI
X-VCL-Version
X-RPS
X-NodeID
X-DB
X-DW
X-Newrelic-Synthetics
X-DSS
X-RPM
Ohc-Cache-HIT
Hostname
X-Via-NSCOPI
X-SD-PageType
X-Forwarded-Site
Srv
GeoIP-Country-Code
Mime-Version
X-Extlb
GeoIP-Latitude
FSS-Cache
XServer
X-NGINX-Cache
CF-Cached-On
X-Action
ProcessTime
X-App
X-Bc-Bl
X-Render-Time
X-BBC-Edge-Cache-Status
X-FTR-Cache-Host
X-Oss-Cdn-Auth
X-VC-Cache
X-PJAX-URL
X-Region-Sid
X-Req
X-Depends-On
Memcached
Mail-Subject
LB
Surrogated-Key
We-Hiring
X-Date
X-Accel-Expires-Debug
Upgrade-Insecure-Requests
EpKe-Alive
X-Proxy-Upstream
X-Fpc
X-CF-Powered-By
X-Dynatrace-Js-Agent
X-Ua
X-Swift-Error
X-Provided-By
X-ZONE
X-RateLimit-Remaining-Second
X-Worker
W
X-RateLimit-Limit-Second
X-APP
X-Auto-Login
Processtime
X-FORWARDED-FOR
X-UnsetCookies
Env
X-Cdn-Request-ID
X-HITS
Cdn
Proxy-Connection
X-BACKEND-TTL
CDN
X-Fastly-Backend-Reqs
Time
Memory
X-Rocket-Build-Number
X-MSEdge-Flight
X-MSEdge-Features
X-Dw-Trace-Id
X-Sigma
X-Men
X-Sigma-Backend
X-CSRF-TOKEN
X-Cluster-Node
X-Ftr-Cache-Host
X-Air-Trace-Id
X-TIME
X-CACHE-AGE
X-Client-Ip
X-Parent-Response-Time
X-Cache-Tag
X-Flog
X-Hello
X-ABtesting
X-BBC-Origin-Response-Status
VNS-Cache
VNS-Age
CPC-Cache
Datacenter
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
CPC-Age
PICS-Label
Dnion-Transfer-Encoding
X-Fastly-Request-Id
X-Akamai-Pragma-Client-IP
Media-Length
X-Acquia-Purge-Tags
X-Zone
X-Oracle-DMS-ECID
X-Pf-Uncompressing
X-Acquia-Site
Vha6-Origin
X-Acquia-Application-Trace
X-Pad
X-Presslabs-Stats
X-Acquia-Application-UUID
Epwk-X-Cache
X-LiteSpeed-Tag
X-Via-PopH
X-ServerName
X-Via-PopN
OT-Force-Account-Verify
X-Via-PopV
Cf-Ipcountry
X-Akamai-ERRuleID
X-Vcache
X-MiniProfiler-Ids
X-Snapshot-Date
X-Csrf-Token
State
X-ElasticPress-Query
X-Request-URL
X-Varnish-Beresp-TTL
X-Akamai-ERPolicy
X-ND-Cache
X-ElasticPress-Search
My-App
Xet-Cookie
X-Lb-Id
X-Ms-Meta-Staticbatchstarttime
X-Ms-Meta-Originalurl
WZWS-RAY
Fastcgi-Cache-TTL
X-Varnish-URL
X-Request-Url
CountryCode
X-Litespeed-Cache-Control
X-Amz-Meta-Cb-Modifiedtime
Content-Style-Type
X-C
Content-Script-Type
X-Redis-Duration-Ms
X-Debug-Cache-Fetch
X-Debug-Cache-Store
NnCoection
X-B3-Parentspanid
Phost
X-Traceid
URI
Inserted-Into-Cache-At
X-Storefront-Renderer-Verified
Environment
X-Redis-Count
Ohc-Response-Time
X-Tid