Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
X-XSS-Protection
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
X-Request-Id
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Xss-Protection
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Cacheable
X-Request-ID
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Content-Encoding
X-CDN
X-Ua-Compatible
Feature-Policy
X-AspNetMvc-Version
Status
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Upgrade
X-Via
Access-Control-Max-Age
Keep-Alive
X-Ws-Request-Id
X-Age
X-Robots-Tag
X-AH-Environment
X-Turbo-Charged-By
Request-Context
EagleId
X-Proxy-Cache
X-Cache-Group
Server-Timing
X-Backend
X-Hacker
X-Server
Report-To
Host-Header
X-Server-Powered-By
X-Amz-Request-Id
X-Amz-Id-2
Grace
X-Nginx-Cache-Status
X-UA-Device
X-Dns-Prefetch-Control
X-Rq
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Page-Speed
Cf-Railgun
X-Pingback
X-OneAgent-JS-Injection
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
NEL
X-Cache-Spec
X-Amz-Version-Id
X-Device
X-CST
Allow
X-Vhost
X-Host
X-Backend-Server
Xkey
X-Server-Id
EagleEye-TraceId
X-WebKit-CSP
X-Dispatcher
Surrogate-Control
X-Node
Request-Id
Content-Location
X-Response-Time
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Akam-SW-Version
X-Ruxit-JS-Agent
P3p
X-ASPNET-VERSION
Accept-Ch
Accept-Ch-Lifetime
X-Application-Context
X-Cache-Lookup
X-Ac
X-Country
X-Template
X-Mod-Pagespeed
Accept-CH
X-Language
X-Readtime
X-Cloud-Trace-Context
MS-Author-Via
X-B3-TraceId
Rating
Accept-CH-Lifetime
X-HW
X-Origin-Cache
X-Cnection
X-MS-InvokeApp
X-Url
X-Vname
X-TtlSet
X-PC
X-Clacks-Overhead
Edge-Control
X-GitHub-Request-Id
X-ESI
X-ORACLE-DMS-RID
X-Trace
X-ORACLE-DMS-ECID
Display
X-Content-Type
X-Sol
Pagespeed
X-Middleton-Response
Response
X-Middleton-Display
X-Varnish-TTL
X-Webkit-CSP
X-D2id
Verso
Arr-Disable-Session-Affinity
X-Use-Magma
X-Exp-Variant
X-Vcap-Request-Id
X-Kinja-Revision
X-Exp-Id
X-Cdn-Fetch
X-Kinja-Build
X-Kinja-Server
X-GoogleNews-Bot
X-Kinja
X-Goog-Hash
X-Country-Code
X-Rack-Cache
X-TTL
X-Powered-By-Plesk
X-Navigation-Version
Service-Worker-Allowed
X-Server-Name
X-VARITI-CCR
X-Buckets
X-Amz-Rid
X-Fastly-Request-ID
X-Abt-Application-Version
X-Client-IP
Fastly-Restarts
X-Cache-TTL
X-FastCGI-Cache
X-Release
X-Cached
X-MSEdge-Ref
X-Element-Page-Cache
X-Dw-Request-Base-Id
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
SPRequestGuid
X-SharePointHealthScore
X-Oneagent-Js-Injection
X-NF-Request-ID
SPRequestDuration
SPIisLatency
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
Public-Key-Pins
Access-Control-Request-Method
RTSS
AR-CACHE
Ar-Sid
X-Edge
AR-Request-ID
AR-PoweredBy
AR-ATIME
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-LLID
X-Powered-CMS
Cache-Tag
X-Ezoic-Cdn
X-Litespeed-Cache
X-Upstream
Content-MD5
X-Jurisdiction
X-HP-Webp
X-Version
X-Origin-Upstream-Status
S
Fusion-Template-Id
X-Px
Fusion-Source
Fusion-Component-Id
Fusion-Deployment-Id
Fusion-Content-Id
Fusion-Content-Source
X-MCACHE
X-Mid
X-ECACHE
X-Recruiting
Charset
X-Mg-S
X-Content-Digest
X-PressLabs-Stats
X-Kinsta-Cache
X-DynaTrace
Fastcgi-Cache
X-T
Cache-Tags
X-Fastcgi-Cache
X-Id
X-Amz-Server-Side-Encryption
X-Logged-In
Filters
X-Accel-Expires
MicrosoftSharePointTeamServices
X-Content-Security-Policy-Report-Only
X-Ruxit-Js-Agent
X-Ttl
X-Forwarded-Proto
Edge-Cache-Tag
Server-Node
Front-End-Https
X-Correlation-Id
TP-L2-Cache
TP-Cache
X-Forwarded-For
X-Grace
Server-Name
X-Debug
Nginx-Cache
X-Hits
X-Kong-Upstream-Latency
X-Amzn-Trace-Id
X-Kong-Proxy-Latency
X-Request-Received
X-Request-Processing-Time
TCN
X-XRDS-LOCATION
X-B3-Sampled
X-Shield-Request-Id
Surrogate-Key
X-Yandex-Sdch-Disable
X-Request-Handler-Origin-Region
X-Microsite
X-Varnish-Age
X-Az
X-AppVersion
X-Activity-Id
X-Ser
X-HS-Content-Id
X-HS-Hub-Id
X-Amz-Replication-Status
X-HS-Cache-Config
X-HS-Combine-CSS
X-F-Cache
X-Origin-Server
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Metageneration
Alternate-Protocol
X-DIS-Request-ID
X-Pinterest-Direct
Accept-Charset
X-Geo-Country
X-Rid
X-Git-Hash
X-XRDS-Location
X-Respond-Thread
X-Frontend
Host
Section-Io-Cache
X-Time
X-NWS-LOG-UUID
X-Cache-Key
X-LB-Cache
X-DataDome
X-Upgrade-Enabled
Access-Control-Allow-Method
X-Mobile-URL
Cache
X-Server-ID
MS-CV
X-VCache
X-Seen-By
X-Cache-Age
Paypal-Debug-Id
ServerID
X-Type
X-IPLB-Instance
X-TT
X-FTR-Request-ID
Healthy
X-Whom
X-Content-Options
X-Varnish-Backend
X-Hostname
X-AOL-HN
X-Source
X-Is-Crawler
X-App-Environment
X-Route-Name
Payment
X-Providence-Cookie
X-Request-Guid
X-Flags
X-Aspnet-Duration-Ms
Cleartype
X-Cache-Action
X-B-Cache
X-Signature
X-Daa-Tunnel
X-Page-Id
X-Jobs
Fastcgi-Useragent
X-Debug-Info
X-RateLimit-Remaining
X-Load-Cache
X-WebKit-CSP-Report-Only
X-N
Powered-By-ChinaCache
X-FB-Debug
Nel
X-Mobile
X-Webkit-Csp
X-Contextid
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
Realpath
X-Via-JSL
Refresh
Node
X-TEC-API-ORIGIN
X-Rule
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Accel-Buffering
Version
X-Response-Served-From
X-Original-Request-Id
X-Drupal-Cache-Tags
X-Zen-Fury
X-Cache-Expired-At
DC
X-Wix-Request-Id
X-Framework
X-Proxy
X-Cacheable-TTL
X-RTag
Ms-Operation-Id
X-ProcessESI
Referer-Policy
X-RemovedCookies
Access-Control-Request-Headers
X-HTML-Minification-Powered-By
X-Real-IP
X-Region
X-Cluster-Name
X-Instance
X-Cache-Time
X-B
X-Drupal-Cache-Contexts
X-FW-Dynamic
X-Page-View
X-Distributor
X-Akamai-Edgescape
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-UUID
Eomportal-Instance
X-Cache-Control
Viewport
X-FW-Static
X-FW-Server
X-FW-Serve
X-FW-Type
X-Cached-By
X-Content-Powered-By
X-FW-Hash
VIX-Pulpo-Node
X-Cache-Operation
X-IPS-LoggedIn
X-Cache-Rule
VIX-Pulpo-Upstream-Status
Liferay-Portal
Countrycode
X-G
X-FireWall-Port
X-Cache-Hit
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Tumblr-User
X-L-Path
X-Environment-Context
X-Pass-Why
X-App-Server
DynaTrace
Server-Info
Xserver
SRV
Section-Io-Origin-Status
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Id
X-Nginx-Cache
X-User-Agent
X-Protected-By
CF-IPCountry
X-Debug-IsConnected
X-Debug-IsPreview
Ec-Rule-Version
From-Origin
X-Tumblr-Pixel-2
Webserver
X-Www-Served-By
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
X-Ratelimit-Limit
X-Device-Type
X-Mode
X-RN-RSRV
X-Hl-Ver
X-ES-SERVER
X-Adobe-Content
X-Adobe-Loc
Meta-Geo
X-Endurance-Cache-Level
X-Handled-By
X-UPSTREAM-Address
Protected
Cache-Tv-Group
X-Uri
X-MP-GENERATED-AT
X-Backend-Name
GEO-INFO
X-Cache-Server
X-PHP-Host
Property-Id
X-Varnish-Grace
X-Soup
TWC-Connection-Speed
X-Varnishpool
X-Origin-Hint
X-Node-Name
X-UA-Device-Type
Retry-After
TWC-Device-Class
X-FB-TRIP-ID
Webcakes-Region
X-Site-Version
X-Storage
X-Labrador-Cache-Channel
X-Locale
TWC-GeoIP-Country
Webcakes-App-Version
TWC-Privacy
TWC-Locale-Group
TWC-GeoIP-LatLong
Webcakes-App-Name
X-Web-Node
X-OCL
X-Human
X-Via-Fastly
X-PCL
X-VWS-Id
X-Format
X-AWS-Id
Selected-Fe
X-Be
X-BYPASS-REASON
X-Sql-Duration-Ms
X-Sql-Count
Mn-Server-Ip
X-Timing-Wait
Country
Frame-Options
X-FW-Version
X-Access
Cache-Status
X-WA-Info
X-ProxyCache-Key
X-Proto
X-R9-Blue-Green-Version
X-Redis-Cache
X-Proxy-Build
X-No-Session
X-Origin-Date
X-NYM-Debug-Backend
X-LJ-Flow-ID
Decoy-Debug-TTL
Decoy-Debug-Status
X-ProxyCache-Status
Fastly-SSL
X-Section
X-Request-Time
X-Server-W
Decoy-Debug-Key
X-Pubstack
Azure-RegionName
Azure-InstanceId
X-LAGOON
X-Cache-TTL-Remaining
X-Proxied
X-Status
Cache-Name
X-Routing-Service
Azure-SlotName
X-S-Maxage
Azure-SiteName
Azure-Version
X-PERF
X-ApacheServer
X-Zipkin-Id
X-Hyper-Cache
X-Hosted-By
X-Xfnlog-Site
X-Alternate-Cache-Key
X-Storefront-Renderer-Rendered
X-ShardId
X-Say-TTL
X-Say-Cacheable
X-Sorting-Hat-ShopId
X-ShopId
X-AIR-PT
X-Shopify-Stage
X-Sorting-Hat-PodId
X-TNCMS
AMP-Access-Control-Allow-Source-Origin
X-SayCDN-TTL
X-CCM
X-Loop
Apigw-Requestid
X-Varnish-Server
X-TT-LOGID
X-Cluster
X-Info
X-Forwarded-Host
X-Cache-Grace
X-Is-Bot
X-Rendered-As
X-GG-Cache-Date
X-Revision
X-Dc
X-Qloud-Router
S-Cnection
X-Ratelimit-Remaining
X-Cache-Enabled
Uber-Trace-Id
X-Proxy-Cache-Status
X-Microcachable
X-TA-CDN-Provider
X-SRV
X-Content-Age
X-Cdn
X-Via-CDN
X-Platform
Cache-Hits
X-CSRF-Token
X-NWS-UUID-VERIFY
X-Azure-Ref
X-App-Version
X-Backend-Host
X-Varnish-Ttl
X-Aspnetmvc-Version
X-FTR-Backend-Server
X-FTR-Backend
X-Country-Code-Real
X-Cache-Host
X-FTR-Realm
X-FTR-Balancer
X-Detected-As
X-Amz-Meta-S3cmd-Attrs
X-FTR-Cache-Status
X-FTR-DC
X-Amzn-Remapped-Content-Length
X-Amz-Apigw-Id
X-FTR-Expires
X-Amzn-RequestId
Akamai-GRN
X-EdgeConnect-Cache-Status
X-ATG-Version
X-B3-SpanId
Amp-Access-Control-Allow-Source-Origin
X-Trace-Id
Tracecode
X-CS
SD-X-WS
HostName
X-Time-Microsecs
ServedBy
X-Debug-Cache
X-RCS-CacheZone
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Varnish-Hostname
X-Oss-Server-Time
X-Cache-NGX
X-Oss-Request-Id
X-Cache-PHP
X-Air-Hostname
X-Oss-Storage-Class
X-Backend-TTL
X-DynaTrace-JS-Agent
X-Correlation-ID
X-ServerID
X-BCube-Filmed-By
DB-Nickname
X-Akamai-Transformed
X-TX-ID
X-Cache-Var
X-Cache-Var-Map
X-Ms-Version
X-NewRelic-App-Data
X-Ms-Request-Id
Backend
X-A-Dam
X-A-Ccd
X-Processor
X-PAYTM-SRV-ID
X-Origin-CC
X-NAPM-TraceId
X-Origin-TTL
X-Owner
X-A-Dcw
X-PBS-Appsvrname
X-A-Wwc
X-Aed
X-ScT
X-Session-Fingerprint
X-SRCache-Key
X-S-Cookie
X-S
Thinkindot-Control
X-Request-UUID
X-Rewrite-Enabled
X-Rojux
X-A-Dgt
X-Location
Odigeo-Trace-Id
X-GeoIP-City
Fastcgi-X-Cache-Version
Expiry
DCR-Processing-Time-Ms
X-Generation-Time
Machine
Mobile-Detection-Method
X-Generated-On
Meta-Geo-Continent
MD5-Digest
DCR-Decision-By
X-From
X-Adobe-Source
T-Server
Thinkindot-CacheControl
X-Application
X-Level-Front-Cache
BehaviorPad-Version
X-Fetched-On
Release
Rendered-Blocks
X-External-Request-Id
Thinkindot-CacheControl-Type
X-A
X-VG-WebServer
X-B-Cookie
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-Connection-Hash
X-Vdms-Version
X-Cdn-Forward
X-Cache-NE
X-Device-Os
X-Vdms-Path
X-Tb
X-Magnolia-Registration
X-Destination
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Thinkindot-L3
X-D
X-ARC
X-Trv-Group
X-VG-WebCache
X-Sucuri-ID
X-Nc
DSUID
Cf-Device-Type
X-FC-Vary-Parameters
C-Via
X-Cache-Bucket
Sever-Int
AKAMAI
CacheControlHeader
Server-Hostname
Server-Ext
Server-Host
X-Fastly-Cache
Fastly-Backend-Name
X-Geo-Header
X-GeoIP
Instruction
NGX
Locid
X-Cms-Context
Magicmarker
Host-ID
On-Server
X-Unique-Id
X-HS-Content-Campaign-Id
X-Irp-Debug
X-Core-Value
Path
Gh-Request-Id
Pagetype
Content-Disposition
SR-User-Adfree
X-Tumblr-Pixel-3
X-OVcl-Cache
X-OVcl
Wxu-Next-Region
Wxu-Next-Commit
Wxu-Next-Hostname
X-SVT-ORM-VERSION
X-EC-Lua
X-Policy
X-Bip
X-Varnish-Cache-Hits
X-Reqid
X-Azure-Ref-OriginShield
X-Developers
X-TrackingId
X-VServer
X-Micro-Cache
X-Unique-ID
X-Thanos
X-SVT-ORM-RULES
X-B3-Traceid
X-Mvc-Supplant-Cachable
X-Skip-Cache
X-Node-Id
UCS
X-Nginx-Cache-Key
X-Varnish-Beresp-Grace
User-Cache-Control
X-CACHE-KEY
X-Dispatcher-Server
X-CGP
X-Backend-State
X-Esi-Check
X-Envoy-Decorator-Operation
NM-Fastcgi-Cache
X-Csrf-Jwt
X-Cache-Debug
Web-Mar-Node
X-Cache-Id
X-Fastly-Backend
X-Developer
X-Eu-Site
Ssr
X-Fmm-Version
X-Cache-Info
PB-PID
X-Branch-Name
X-Block-Status
PB-RID
X-Generated-By
PFcat
X-CUA
X-Gen-Mode
CDN-CachedAt
X-Method
X-User
X-Old-Content-Length
X-Origin
Geo-Info
X-LI-UUID
X-Wikidot-Backend
X-WADP-Cache
X-Li-Fabric
X-Li-Pop
X-Origin-Expires
X-Origin-Response-Time
X-Request-Host
X-Scheme
X-GEO
V-Age
X-Generated-In
X-Var-Ttl
X-VarnishDD-TTL
Location
X-Ratelimit-Reset
Arc-Version
Cache-Host
X-HN
X-Hnp-Log
X-IP
X-Wikidot-Static-Cache
X-Has-Esi
X-Gzip
L5d-Success-Class
X-GoCache-CacheStatus
HA-Ipaddr
Ha-Gx-Prefs
X-Is-Gdpr
Cf-Bgj
X-Clara-WADP
CDN-Cache
CDCHOST
X-JWT-State
CDN-EdgeStorageId
CDN-PullZone
CDN-Uid
CDN-RequestId
CDN-RequestCountryCode
X-Swa-Ws
X-Cache-Backend
X-ID
X-Varnish-Beresp-Ttl
X-DefElseHash
X-Clientip
X-DefHash
Apple-News-Services-Handled
X-VG-TLSProxy
Apple-News-Services-Host
X-Request-URI
True-Client-Country-4JS
Esi-Enabled
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Vix-Hermes-Req-Id
X-Platform-Server
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-NU-AKA-ACS-Version
X-Matched-Rule
X-Gamma-Serve
X-LB-ID
X-SIPLIST1
X-Slack-Backend
X-Varnish-CookieINHashed-On
X-Varnish-Hits
X-Varnish-CookieHashed-On
X-Varnish-Beresp-Status
X-DPWN-IS-SECURE
X-Variation
X-Varnish-Remaining-TTL
X-Hash
Lfy
Fastly-SIE
Adler-Geo
Fastly-SWR
Rt-Fastcgi-Cache
X-Cache-Tags
Platform
Is-Eu
IsBot
L
Origin
Who
Country-Code
X-CLOUD-TRACE-CONTEXT
Fastly-Drupal-HTML
X-Aicache-OS
X-Loc
CloudFront-Viewer-Country
X-Mvc-Supplant-OutputCached
X-Goog-Meta-Goog-Reserved-File-Mtime
X-RateLimit-Limit
Sid
X-APP-VERSION
Pramga
Pics-Label
X-Via-Popv
X-PF-Uncompressing
Tcn
X-Cdn-Origin
X-Sn-Servicetimems
X-Cache-Expires
X-Via-Popn
X-NCache
X-Via-Poph
X-Varnish-Url
X-Epic-Correlation-Id
X-Core-Mission
X-Cache-Date
Filterid
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Servername
X-Refresh
Url
X-Request-Start
Cmsid
X-Tb-Optimization-Total-Bytes-Saved
Cmstype
X-FireWall-Protection
Req-Svc-Chain
X-TraceId
X-Varnish-Cacheable
X-Srv
X-Error
Svr
X-Served-From
Kp-EeAlive
Viewtype
VivaBuild
A
X-Response-By
MIME-Version
Source
NGB
X-NC
X-Webkit-CSP-Report-Only
X-Erf-Stays-Bingo-Pdp-Web
M-TraceId
Xkeyi7
X-Proxy-Cachei7
X-DC
Cache-Key
GeoIp-Country-Code
Geoip-Latitude
X-Cache-Remote
Cross-Origin-Opener-Policy
TDXMobile
HitType
Content-Secure-Policy
N-Cache
X-Vcl-Version
X-HS-Status
X-BBXSRF
Server-Ttl
S-Rt
Arc-Country
Server-ID
X-URL
X-Vgn-Hpd-Reason
X-Wa
X-Servedbyhost
X-HostName
X-B3-Spanid
X-Air-Source
X-Cache-2
NtCoent-Length
X-Geo
X-LiteSpeed-Cache-Control
X-Cache-ASPX
X-Cc-Via
X-Esi
X-Vc
X-Cc-Req-Id
D-Cc-Upstream
X-Contensis-Viewer-Groups
Resin-Trace
X-Li-Proto
X-Varnish-Authentication
X-SaId
SID
X-Host-Name
X-JoinUs
X-NGENIX-Cache
X-PHP-Backend
X-CDN-Forward
CACHE
X-Sucuri-Cache
Cross-Origin-Window-Policy
DataCenter
Ohc-File-Size
Cteonnt-Length
X-Service
X-Svr
X-RAMCache
X-LI-Proto
X-Edge-Location
X-HOST
Request-ID
X-WA
X-Internal-Host
X-Server-IP
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-UA
X-Extlb
X-Forwarded-Site
X-ServedByHost
X-DB
FSS-Cache
X-Viewer-Country
X-Cache-Config
X-API-Version
X-Newrelic-Synthetics
X-VCL-Version
X-RSL
X-TIM-N
X-RPM
X-DW
X-Via-NSCOPI
X-DSS
X-Gdpr
X-Nyt-Route
X-Origin-Time
X-DI
X-RPS
X-FPC
Hostname
GeoIP-Latitude
GeoIP-Country-Code
X-Bc-Bl
Cache-Provider
X-Dynatrace
X-SN
X-Cs
CF-Cached-On
X-VC
X-Check-Cacheable
Ohc-Cache-HIT
XServer
X-Proxy-Upstream
X-Webstats-RespID
X-SB
LB
Server-Id
X-ZONE
ProcessTime
Memcached
X-Action
Mail-Subject
X-PJAX-URL
We-Hiring
X-App
Surrogated-Key
X-NodeID
X-Req
X-Accel-Expires-Debug
X-Date
X-Fpc
Mime-Version
X-Oss-Cdn-Auth
X-Server-Lifecycle-Phase
Env
X-Kraken-Routeconfig-Destination
X-APP
X-VC-Cache
X-Instrumentation
X-SD-PageType
X-CF-Powered-By
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Kraken-Loop-Name
X-Region-Sid
X-Provided-By
X-Dynatrace-Js-Agent
X-Swift-Error
X-BBC-Edge-Cache-Status
X-Rocket-Build-Number
Upgrade-Insecure-Requests
X-FORWARDED-FOR
X-Sigma
X-Men
X-Depends-On
W
X-Sigma-Backend
X-Render-Time
Srv
X-NGINX-Cache
X-Cdn-Request-ID
VNS-Cache
CDN
VNS-Age
X-UnsetCookies
X-CSRF-TOKEN
X-Dw-Trace-Id
Cdn
Memory
X-BACKEND-TTL
EpKe-Alive
X-MSEdge-Features
X-TIME
X-MSEdge-Flight
X-Air-Trace-Id
X-Ftr-Cache-Host
CPC-Age
Time
CPC-Cache
X-FTR-Cache-Host
X-CACHE-AGE
X-Client-Ip
X-Worker
X-Auto-Login
X-Cache-Tag
X-ABtesting
Dnion-Transfer-Encoding
X-Fastly-Request-Id
X-Fastly-Backend-Reqs
X-Flog
X-Hello
X-Parent-Response-Time
Processtime
X-Akamai-Pragma-Client-IP
Cf-Ipcountry
X-Ua
Media-Length
X-Pad
X-ServerName
X-Cluster-Node
X-Acquia-Purge-Tags
X-Acquia-Site
X-Acquia-Application-Trace
X-Zone
X-Presslabs-Stats
X-Oracle-DMS-ECID
Proxy-Connection
X-Acquia-Application-UUID
X-BBC-Origin-Response-Status
Vha6-Origin
X-Pf-Uncompressing
X-Edge-Location-Klb
Fastcgi-Cache-TTL
PICS-Label
My-App
State
X-LiteSpeed-Tag
Datacenter
X-Via-PopN
X-Via-PopV
X-Snapshot-Date
X-Via-PopH
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
Epwk-X-Cache
X-Varnish-URL
X-Minions-Version
X-Vcache
X-ElasticPress-Query
X-ElasticPress-Search
X-MiniProfiler-Ids
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-Lb-Id
Xet-Cookie
X-Request-URL
X-Varnish-Beresp-TTL
X-Ms-Meta-Staticbatchstarttime
X-Ms-Meta-Originalurl
CountryCode
Content-Script-Type
X-C
Content-Style-Type
X-Litespeed-Cache-Control
X-Apw-Access-Object
X-Cache-Status-Check
X-Mg-Request-Id
X-Apw-Hits
X-Apw-Access-Token
X-Apw-Access-Action
X-Request-Url
Environment
NnCoection
Inserted-Into-Cache-At
X-B3-Parentspanid
Phost
X-Debug-Cache-Fetch
Ohc-Response-Time
OT-Force-Account-Verify
X-Traceid
X-Debug-Cache-Store
X-Amz-Meta-Cb-Modifiedtime
X-Tid
X-Redis-Count
URI
X-Redis-Duration-Ms
X-Storefront-Renderer-Verified