Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Cf-Request-Id
CF-Cache-Status
Last-Modified
X-XSS-Protection
CF-RAY
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-Runtime
X-AspNet-Version
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Xss-Protection
X-Cache-Status
X-Generator
X-Request-ID
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Content-Security-Policy
Content-Encoding
X-CDN
X-Envoy-Upstream-Service-Time
Status
Feature-Policy
X-Ua-Compatible
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-AspNetMvc-Version
Access-Control-Max-Age
X-Via
Upgrade
CF-Ray
Keep-Alive
X-Ws-Request-Id
X-Age
X-Turbo-Charged-By
X-AH-Environment
X-Robots-Tag
Request-Context
X-Proxy-Cache
EagleId
X-Cache-Group
Server-Timing
X-Backend
X-Hacker
X-Amz-Request-Id
Report-To
X-Server
Host-Header
X-Amz-Id-2
X-Server-Powered-By
Grace
X-Nginx-Cache-Status
X-UA-Device
X-LiteSpeed-Cache
X-Dns-Prefetch-Control
X-Varnish-Cache
X-Rq
Ali-Swift-Global-Savetime
X-Swift-CacheTime
X-Swift-SaveTime
X-Page-Speed
Cf-Railgun
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Amz-Version-Id
NEL
X-OneAgent-JS-Injection
Xkey
X-WebKit-CSP
X-Cache-Spec
Allow
X-Backend-Server
X-Host
X-CST
X-Vhost
X-Device
EagleEye-TraceId
X-Server-Id
X-ASPNET-VERSION
Surrogate-Control
Request-Id
X-Dispatcher
Accept-CH
X-Node
Content-Location
X-Response-Time
X-Akam-SW-Version
Accept-CH-Lifetime
X-Ruxit-JS-Agent
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
P3p
X-Ac
X-Template
X-Language
X-Application-Context
X-Kinja-Server-Push
X-Country
X-Cache-Lookup
X-Readtime
X-Cloud-Trace-Context
X-Mod-Pagespeed
MS-Author-Via
X-B3-TraceId
X-Origin-Cache
Rating
X-Cnection
X-MS-InvokeApp
X-HW
X-Url
X-TtlSet
X-Vname
X-PC
X-ORACLE-DMS-ECID
Accept-Ch
X-Clacks-Overhead
X-ESI
X-GitHub-Request-Id
X-FastCGI-Cache
Edge-Control
Accept-Ch-Lifetime
X-Trace
X-Sol
X-Middleton-Display
Display
Response
X-Middleton-Response
Pagespeed
X-Content-Type
X-D2id
X-Cdn-Fetch
X-Exp-Id
Verso
Arr-Disable-Session-Affinity
X-Exp-Variant
X-Kinja
X-Kinja-Server
X-Kinja-Revision
X-Kinja-Build
X-GoogleNews-Bot
X-Use-Magma
X-Vcap-Request-Id
X-Buckets
X-Goog-Hash
X-Rack-Cache
X-Server-Name
X-Country-Code
Service-Worker-Allowed
X-Navigation-Version
X-VARITI-CCR
X-Abt-Application-Version
X-Amz-Rid
X-Oneagent-Js-Injection
X-Powered-By-Plesk
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
X-ORACLE-DMS-RID
X-Cache-TTL
X-Varnish-TTL
X-Client-IP
SPRequestGuid
X-SharePointHealthScore
X-Fastly-Request-ID
X-Release
SPRequestDuration
SPIisLatency
X-MSEdge-Ref
X-Dw-Request-Base-Id
Fastly-Restarts
X-Element-Page-Cache
X-NF-Request-ID
X-Cached
Public-Key-Pins
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
RTSS
X-Ttl
AR-ATIME
AR-Request-ID
AR-PoweredBy
AR-CACHE
Ar-Sid
X-Edge
X-Origin-Upstream-Status
Access-Control-Request-Method
X-SRCache-Fetch-Status
X-TTL
X-SRCache-Store-Status
X-Webkit-CSP
X-LLID
X-Px
X-Powered-CMS
Fusion-Content-Source
Fusion-Component-Id
Fusion-Deployment-Id
Fusion-Content-Id
Fusion-Source
Fusion-Template-Id
X-Ezoic-Cdn
X-Upstream
Content-MD5
X-HP-Webp
X-Jurisdiction
X-Amz-Server-Side-Encryption
X-ECACHE
X-MCACHE
X-Mid
Charset
X-Recruiting
Cache-Tag
X-Mg-S
S
X-Content-Digest
X-Pinterest-Direct
X-PressLabs-Stats
X-Version
X-Aspnetmvc-Version
TCN
MicrosoftSharePointTeamServices
Fastcgi-Cache
Front-End-Https
X-Debug
X-T
X-Content-Security-Policy-Report-Only
X-Id
X-Grace
Filters
X-Kinsta-Cache
Cache-Tags
Edge-Cache-Tag
Server-Node
X-Forwarded-Proto
X-Accel-Expires
X-Logged-In
X-Forwarded-For
X-Amzn-Trace-Id
Server-Name
Nginx-Cache
X-Yandex-Sdch-Disable
X-XRDS-Location
Surrogate-Key
X-Kong-Proxy-Latency
X-Varnish-Age
X-Kong-Upstream-Latency
X-Correlation-Id
TP-L2-Cache
TP-Cache
X-Request-Received
X-Request-Processing-Time
X-Request-Handler-Origin-Region
X-Microsite
X-DynaTrace
X-Hits
X-Ser
X-Cache-Key
Powered-By-ChinaCache
X-DIS-Request-ID
X-B3-Sampled
X-Shield-Request-Id
X-Az
X-Activity-Id
X-AppVersion
X-Amz-Replication-Status
X-Server-ID
X-F-Cache
X-HS-Cache-Config
X-HS-Combine-CSS
X-HS-Hub-Id
X-HS-Content-Id
X-Goog-Metageneration
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Generation
Accept-Charset
X-FTR-Request-ID
X-Git-Hash
X-Origin-Server
X-Respond-Thread
X-Hostname
X-Geo-Country
X-LB-Cache
X-Upgrade-Enabled
X-DataDome
Section-Io-Cache
X-Rid
X-XRDS-LOCATION
X-Frontend
Nel
Access-Control-Allow-Method
X-Cache-Age
Alternate-Protocol
Cache
Host
X-Mobile-URL
Cleartype
MS-CV
Paypal-Debug-Id
X-IPLB-Instance
X-Type
X-Content-Options
Healthy
X-Ruxit-Js-Agent
ServerID
X-AOL-HN
X-WebKit-CSP-Report-Only
X-Varnish-Backend
X-App-Environment
X-Whom
Payment
X-Seen-By
X-Route-Name
X-TT
X-Signature
X-Flags
X-Debug-Info
X-Aspnet-Duration-Ms
X-B-Cache
X-Is-Crawler
X-Providence-Cookie
X-Cache-Action
X-Request-Guid
X-VCache
Fastcgi-Useragent
X-Page-Id
X-Jobs
X-NWS-LOG-UUID
X-N
X-Source
X-Mobile
X-Time
X-Load-Cache
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Erf-Bev-Bev
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Via-JSL
X-Cached-By
X-Daa-Tunnel
X-FB-Debug
X-Akamai-Edgescape
Version
X-RateLimit-Remaining
X-Litespeed-Cache
X-Cache-Operation
X-Cache-Rule
Viewport
Refresh
X-Accel-Buffering
X-Response-Served-From
DynaTrace
X-Original-Request-Id
X-Rule
X-Proxy
DC
X-Framework
X-RTag
X-Instance
X-RemovedCookies
X-Zen-Fury
X-Drupal-Cache-Tags
Ms-Operation-Id
X-ProcessESI
X-Cacheable-TTL
GEO-INFO
Realpath
X-Contextid
Access-Control-Request-Headers
X-Fastcgi-Cache
X-Real-IP
X-Cache-Time
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Wix-Request-Id
X-UUID
X-Region
X-HTML-Minification-Powered-By
X-Distributor
X-Yottaa-Optimizations
X-Page-View
Referer-Policy
X-Yottaa-Metrics
Eomportal-Instance
VIX-Pulpo-Node
X-Drupal-Cache-Contexts
X-Varnish-Ttl
Countrycode
Node
VIX-Pulpo-Upstream-Status
X-FW-Dynamic
X-FW-Type
X-FW-Static
X-FW-Server
X-FW-Serve
X-FW-Hash
X-B
X-L-Path
X-Cache-Expired-At
X-Cluster-Name
X-Environment-Context
X-Node-Name
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-G
Liferay-Portal
X-Cache-Control
X-Content-Powered-By
X-IPS-LoggedIn
X-Cache-Hit
X-User-Agent
X-Ratelimit-Limit
Webserver
X-Tumblr-Pixel-2
Server-Info
X-Amz-Meta-S3cmd-Attrs
X-Pass-Why
From-Origin
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
X-App-Server
Section-Io-Id
Protected
Ec-Rule-Version
X-FireWall-Port
X-Protected-By
X-Revision
SRV
Frame-Options
X-Oracle-Dms-Rid
X-Backend-Name
X-Cache-Server
Cache-Status
CF-IPCountry
X-Hl-Ver
X-ES-SERVER
X-RN-RSRV
Meta-Geo
X-UPSTREAM-Address
X-Endurance-Cache-Level
X-Handled-By
X-Www-Served-By
X-Hyper-Cache
X-FB-TRIP-ID
X-Ratelimit-Remaining
X-Forwarded-Host
X-Site-Version
X-Locale
X-NYM-Debug-Backend
Retry-After
X-Storage
X-Soup
Decoy-Debug-Status
X-Pubstack
X-Cache-Grace
X-Varnishpool
X-Adobe-Content
X-Be
Decoy-Debug-Key
X-Web-Node
Cache-Tv-Group
Country
Decoy-Debug-TTL
Fastly-SSL
X-Adobe-Loc
X-Human
Azure-InstanceId
Azure-RegionName
Azure-Version
X-Say-TTL
Cache-Name
X-Mode
Azure-SiteName
Azure-SlotName
Property-Id
Webcakes-Region
X-Timing-Wait
X-Proto
Webcakes-App-Version
X-PCL
X-PHP-Host
X-Access
X-UA-Device-Type
X-ProxyCache-Status
X-BYPASS-REASON
X-ProxyCache-Key
X-Proxy-Build
X-Uri
X-Origin-Hint
TWC-Privacy
Selected-Fe
TWC-Connection-Speed
X-Labrador-Cache-Channel
X-Say-Cacheable
X-Section
X-Format
TWC-Device-Class
X-OCL
X-Redis-Cache
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-GeoIP-Country
X-Origin-Date
X-SayCDN-TTL
Webcakes-App-Name
X-Tec-Api-Root
X-Tec-Api-Origin
X-Tec-Api-Version
X-S-Maxage
X-Sql-Duration-Ms
X-WA-Info
X-TT-LOGID
X-Sql-Count
X-Via-CDN
X-LAGOON
X-FW-Version
X-Via-Fastly
X-No-Session
X-PERF
X-AIR-PT
X-ApacheServer
X-Server-W
X-R9-Blue-Green-Version
Xserver
X-TNCMS
X-Hosted-By
X-Loop
X-FTR-Backend-Server
X-FTR-Balancer
X-VWS-Id
X-FTR-Cache-Status
X-FTR-Realm
X-LJ-Flow-ID
X-FTR-Backend
X-Qloud-Router
X-AWS-Id
X-Request-Time
X-Status
X-MP-GENERATED-AT
X-FTR-DC
X-Country-Code-Real
S-Cnection
X-CCM
X-Cache-TTL-Remaining
X-Cluster
Mn-Server-Ip
X-Sorting-Hat-ShopId
X-Shopify-Stage
X-ShopId
X-ShardId
X-Alternate-Cache-Key
X-Storefront-Renderer-Rendered
X-Sorting-Hat-PodId
X-Xfnlog-Site
Cache-Hits
X-FTR-Expires
AMP-Access-Control-Allow-Source-Origin
X-Is-Bot
X-Rendered-As
X-Zipkin-Id
X-Routing-Service
X-Proxied
X-Dynatrace
X-Dc
X-Device-Type
X-Cache-Var
X-SRV
X-Air-Hostname
X-Cache-Var-Map
X-Info
X-Detected-As
Apigw-Requestid
X-Unique-Id
X-EdgeConnect-Cache-Status
X-Nginx-Cache
X-Cache-Host
X-Amz-Apigw-Id
X-Webkit-Csp
X-Amzn-RequestId
X-Amzn-Remapped-Content-Length
X-Cdn
X-Microcachable
X-Debug-IsConnected
X-Debug-IsPreview
X-Cache-Enabled
X-APP-VERSION
X-GEO
X-Varnish-Grace
X-Content-Age
SD-X-WS
X-Varnish-Server
X-Platform
Tracecode
X-Time-Microsecs
X-Correlation-ID
X-Backend-TTL
X-Azure-Ref
X-ServerID
X-Backend-Host
X-Cache-Backend
X-GG-Cache-Date
Uber-Trace-Id
X-DynaTrace-JS-Agent
X-Proxy-Cache-Status
DSUID
Amp-Access-Control-Allow-Source-Origin
X-Erf-Stays-Bingo-Pdp-Web
X-Tb
Akamai-GRN
X-Oss-Object-Type
X-Oss-Storage-Class
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-BCube-Filmed-By
X-NewRelic-App-Data
X-CSRF-Token
X-ATG-Version
PB-RID
Backend
Arc-Version
PB-PID
X-Sucuri-ID
X-Trace-Id
ServedBy
X-Magnolia-Registration
X-Akamai-Transformed
X-CF-Lambda-Fn
X-B-Cookie
X-ARC
X-Cache-NE
Xc-Version
X-Application
X-Vtex-Remote-Cache
X-A-Dam
Mobile-Detection-Method
Meta-Geo-Continent
MD5-Digest
Odigeo-Trace-Id
Path
Release
Pramga
Machine
BehaviorPad-Version
DCR-Processing-Time-Ms
DCR-Decision-By
Expiry
Fastcgi-X-Cache-Version
Lfy
Instruction
Rendered-Blocks
SR-User-Adfree
X-Vtex-Processado-Em
X-A-Ccd
X-A-Dcw
X-Varnish-Cache-Hits
X-A-Wwc
X-A-Dgt
X-Cache-NGX
X-Cache-PHP
T-Server
X-Varnish-Hostname
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-A
Thinkindot-Control
X-Aed
X-CF-Lambda-Version
X-Destination
X-Device-Os
X-ScT
X-D
X-Location
X-Connection-Hash
X-Matched-Rule
X-External-Request-Id
X-Level-Front-Cache
X-GeoIP-City
X-Generated-On
X-Generation-Time
X-From
X-Origin-Response-Time
X-Session-Fingerprint
X-Fetched-On
X-SRCache-Key
X-S-Cookie
X-Vdms-Path
X-Processor
X-Vdms-Version
X-VG-WebCache
X-Request-UUID
X-VG-WebServer
X-PBS-Appsvrname
X-PAYTM-SRV-ID
X-Origin-TTL
X-Origin-CC
X-Thinkindot-L3
X-S
X-Rewrite-Enabled
X-Trv-Group
X-Rojux
X-Ms-Request-Id
X-RCS-CacheZone
X-Ms-Version
X-Cache-Date
X-OVcl-Cache
X-Owner
X-CGP
X-OVcl
X-Cache-Bucket
X-Mvc-Supplant-Cachable
X-Node-Id
Pagetype
X-Thanos
L5d-Success-Class
X-Tumblr-Pixel-3
X-Cache-Info
X-Reqid
X-User
X-Cdn-Origin
Fastly-Backend-Name
Gh-Request-Id
Host-ID
HA-Ipaddr
Ha-Gx-Prefs
X-Micro-Cache
X-Swa-Ws
X-Skip-Cache
X-Has-Esi
X-SVT-ORM-RULES
X-HS-Content-Campaign-Id
Cf-Device-Type
X-GeoIP
X-Geo-Header
X-Generated-In
X-VServer
UCS
X-Irp-Debug
X-Eu-Site
X-Azure-Ref-OriginShield
X-Csrf-Jwt
X-Backend-State
Ssr
X-SVT-ORM-VERSION
X-Is-Gdpr
X-JWT-State
X-FC-Vary-Parameters
X-Sn-Servicetimems
X-Bip
X-NWS-UUID-VERIFY
C-Via
Cache-Host
X-Adobe-Source
X-Debug-Cache
AKAMAI
CacheControlHeader
DB-Nickname
Wxu-Next-Commit
Wxu-Next-Region
Wxu-Next-Hostname
X-Fastly-Backend
PFcat
X-VarnishDD-TTL
On-Server
X-Varnish-Hits
Server-Host
X-Scheme
X-Var-Ttl
X-Cache-Remote
X-Request-Host
X-Developer
X-CUA
X-Core-Value
X-Developers
X-B3-Traceid
X-Fastly-Cache
X-Envoy-Decorator-Operation
X-Generated-By
X-Cms-Context
X-Origin-Expires
User-Cache-Control
X-Cache-Tags
X-IP
X-Clientip
X-HN
X-Request-URI
V-Age
X-Wikidot-Backend
Locid
L
X-Wikidot-Static-Cache
X-TrackingId
CloudFront-Viewer-Country
Magicmarker
NGX
Content-Disposition
X-Nginx-Cache-Key
X-Block-Status
X-Branch-Name
X-Method
X-NU-AKA-ACS-Version
Fastly-SIE
Fastly-SWR
X-Policy
X-Ratelimit-Reset
X-Platform-Server
NM-Fastcgi-Cache
X-Origin
X-Loc
X-Old-Content-Length
X-Cache-Expires
X-DefElseHash
X-Gen-Mode
X-Clara-WADP
X-DefHash
X-Fmm-Version
X-Esi-Check
X-DPWN-IS-SECURE
X-Dispatcher-Server
X-GoCache-CacheStatus
X-Gzip
X-Cache-Id
X-Rebelmouse-Cache-Control
X-Li-Pop
X-Li-Fabric
HostName
X-TA-CDN-Provider
X-Hnp-Log
X-LI-UUID
Location
X-Varnish-CookieHashed-On
X-TX-ID
True-Client-Country-4JS
X-Servername
Cf-Bgj
Server-Ext
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-Rebelmouse-Surrogate-Control
Sever-Int
X-Varnish-Beresp-Grace
X-Variation
Server-Hostname
Apple-News-Services-Request-Url
Apple-News-Services-Handled
X-Varnish-Remaining-TTL
X-VG-TLSProxy
X-Request-Start
Adler-Geo
Platform
CDCHOST
Web-Mar-Node
X-WADP-Cache
X-Varnish-CookieINHashed-On
Is-Eu
Vix-Hermes-Req-Id
X-ID
X-NC
X-SIPLIST1
X-Gamma-Serve
CDN-Uid
X-Varnish-Beresp-Status
IsBot
X-Slack-Backend
Origin
CDN-CachedAt
CDN-Cache
X-NAPM-TraceId
CDN-RequestId
X-Varnish-Beresp-Ttl
X-Cache-Debug
Fastly-Drupal-HTML
CDN-EdgeStorageId
CDN-PullZone
X-Hash
Rt-Fastcgi-Cache
CDN-RequestCountryCode
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Cdn-Forward
X-PF-Uncompressing
CACHE
X-EC-Lua
X-NCache
X-B3-Spanid
X-Host-Name
Url
X-Varnish-Cacheable
X-Core-Mission
S-Rt
X-Mvc-Supplant-OutputCached
X-Response-By
X-Aicache-OS
X-Varnish-Url
Sid
X-B3-SpanId
X-App-Version
X-LB-ID
X-Proxy-Cachei7
X-Refresh
Xkeyi7
X-CACHE-GROUP
X-CS
Cross-Origin-Window-Policy
N-Cache
Pics-Label
X-BBXSRF
X-Sucuri-Cache
X-Cache-2
Content-Secure-Policy
X-FireWall-Protection
Ohc-File-Size
X-Via-Popv
X-Via-Popn
X-Via-Poph
Esi-Enabled
Cteonnt-Length
X-Cs
X-Cache-ASPX
X-Epic-Correlation-Id
X-Varnish-Authentication
X-CDN-Forward
D-Cc-Upstream
X-Cc-Via
X-Contensis-Viewer-Groups
X-Cc-Req-Id
X-TraceId
Source
X-Tb-Optimization-Total-Bytes-Saved
X-Nc
X-Svr
X-Error
X-Srv
Who
X-CACHE-KEY
X-Servedbyhost
X-Server-IP
X-Unique-ID
Country-Code
Geoip-Latitude
X-Wa
GeoIp-Country-Code
Req-Svc-Chain
MIME-Version
X-Webkit-CSP-Report-Only
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
HitType
X-HS-Status
X-FPC
X-DC
X-Gdpr
X-Nyt-Route
X-Origin-Time
X-API-Version
X-Cache-Config
X-RateLimit-Limit
X-VC
X-SN
X-LiteSpeed-Cache-Control
Server-Ttl
X-NGINX-Cache
X-TIME
X-Fastly-Request-Id
X-URL
Hostname
Ohc-Cache-HIT
XServer
Cmsid
X-LI-Proto
X-NodeID
Kp-EeAlive
X-SB
Cmstype
Svr
X-Webstats-RespID
Geo-Info
X-Esi
Server-ID
X-Served-From
X-VCL-Version
X-Check-Cacheable
VivaBuild
Viewtype
X-SD-PageType
X-Viewer-Country
X-Vcl-Version
X-Ua
A
Cache-Key
X-Render-Time
X-Vgn-Hpd-Reason
X-HOST
NtCoent-Length
X-CCDN-Origin-Time
X-CCDN-CacheTTL
Server-Id
EpKe-Alive
X-Li-Proto
M-TraceId
SID
X-BBC-Edge-Cache-Status
X-Hcs-Proxy-Type
Request-ID
X-UA
X-DSS
X-DW
X-RPM
TDXMobile
X-CF-Powered-By
X-RPS
X-DI
X-Worker
X-TIM-N
Cross-Origin-Opener-Policy
X-RSL
Cache-Provider
X-Air-Source
Resin-Trace
X-DB
X-RAMCache
X-Auto-Login
Srv
X-Ftr-Cache-Host
Filterid
ProcessTime
GeoIP-Country-Code
GeoIP-Latitude
Upgrade-Insecure-Requests
Arc-Country
X-CSRF-TOKEN
X-Dynatrace-Js-Agent
X-WA
X-ServedByHost
CDN
X-App
X-Vc
Mime-Version
X-Action
X-Cluster-Node
X-Internal-Host
Processtime
X-FTR-Cache-Host
X-Newrelic-Synthetics
Tcn
NGB
X-Fpc
X-Oss-Cdn-Auth
X-Service
Proxy-Connection
X-CLOUD-TRACE-CONTEXT
CF-Cached-On
X-BBC-Origin-Response-Status
Datacenter
X-FORWARDED-FOR
DataCenter
X-Geo
X-HostName
OT-Force-Account-Verify
X-HITS
X-Via-NSCOPI
X-MSEdge-Flight
X-Forwarded-Site
X-ND-Cache
X-PHP-Backend
FSS-Cache
X-JoinUs
Cdn
X-NGENIX-Cache
X-MSEdge-Features
WZWS-RAY
X-Fastly-Backend-Reqs
X-Akamai-Pragma-Client-IP
X-Via-PopH
X-BACKEND-TTL
X-Via-PopV
X-Via-PopN
X-Dw-Trace-Id
PICS-Label
X-SaId
X-Client-Ip
X-CACHE-AGE
X-Edge-Location
X-Cache-Tag
X-Lb-Id
X-Parent-Response-Time
X-IN-APIGATEWAYSSL
X-Cdn-Request-ID
X-IN-APIGATEWAY
Dnion-Transfer-Encoding
W
X-Hello
X-ABtesting
X-Flog
X-Provided-By
X-ZONE
X-VC-Cache
X-Swift-Error
X-RateLimit-Remaining-Second
Media-Length
X-Req
X-Pad
X-UnsetCookies
X-Proxy-Upstream
X-Pf-Uncompressing
X-RateLimit-Limit-Second
X-Oracle-DMS-ECID
X-Depends-On
Vha6-Origin
We-Hiring
X-PJAX-URL
X-Accel-Expires-Debug
X-Bc-Bl
X-Date
X-Extlb
Memcached
Surrogated-Key
LB
X-Presslabs-Stats
X-Region-Sid
Epwk-X-Cache
Mail-Subject
Time
URI
Xet-Cookie
X-Sigma-Backend
X-Sigma
Memory
X-MiniProfiler-Ids
Env
X-LiteSpeed-Tag
X-Rocket-Build-Number
Cf-Ipcountry
X-B3-Parentspanid
X-Acquia-Site
X-Varnish-URL
X-Vcache
X-Akamai-Request-ID
X-Request-Url
X-Akamai-ERRuleID
X-Akamai-ERPolicy
X-Amz-Meta-Cb-Modifiedtime
X-Air-Trace-Id
X-Request-URL
X-Varnish-Beresp-TTL
X-ElasticPress-Query
X-Csrf-Token
X-Ms-Meta-Staticbatchstarttime
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-ElasticPress-Search
X-APP
X-Ms-Meta-Originalurl
X-Men
CountryCode
X-Zone
Inserted-Into-Cache-At
X-Tid
NnCoection
X-Redis-Duration-Ms
X-Snapshot-Date
X-Traceid
Content-Script-Type
X-Redis-Count
Environment
X-ServerName
X-C
X-Storefront-Renderer-Verified
X-Acc-Rdl
X-Acc-Debug-Context
Phost
Ohc-Response-Time
X-Debug-Cache-Fetch
Edge-Copy-Time
X-Litespeed-Cache-Control
X-Via-Edge
Content-Style-Type
X-Via-SSL
X-Debug-Cache-Store