Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
X-XSS-Protection
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-UA-Compatible
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Xss-Protection
X-Cache-Status
X-Request-ID
X-DNS-Prefetch-Control
X-Generator
X-Cacheable
X-Ua-Compatible
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Content-Encoding
X-CDN
X-AspNetMvc-Version
X-Envoy-Upstream-Service-Time
Feature-Policy
Status
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-Via
Upgrade
Access-Control-Max-Age
Keep-Alive
X-Ws-Request-Id
X-Age
X-Turbo-Charged-By
X-AH-Environment
X-Robots-Tag
Request-Context
X-Proxy-Cache
EagleId
X-Cache-Group
Server-Timing
X-Backend
X-Hacker
X-Server
Report-To
X-Amz-Request-Id
Host-Header
X-Server-Powered-By
X-Amz-Id-2
Grace
X-Nginx-Cache-Status
X-UA-Device
X-Rq
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Page-Speed
Cf-Railgun
X-Pingback
X-OneAgent-JS-Injection
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
NEL
X-Amz-Version-Id
X-Cache-Spec
X-Dns-Prefetch-Control
X-WebKit-CSP
X-Device
X-CST
Allow
Xkey
X-Vhost
X-Backend-Server
X-Host
X-Server-Id
EagleEye-TraceId
Request-Id
X-Dispatcher
Surrogate-Control
X-Node
Content-Location
X-Response-Time
X-Ruxit-JS-Agent
X-Akam-SW-Version
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Accept-CH
Accept-CH-Lifetime
P3p
X-ASPNET-VERSION
X-Ac
X-Application-Context
X-Template
X-Country
X-Language
X-Cache-Lookup
X-Mod-Pagespeed
X-Readtime
MS-Author-Via
X-Cloud-Trace-Context
Accept-Ch
X-B3-TraceId
Rating
X-Origin-Cache
Accept-Ch-Lifetime
X-Cnection
X-MS-InvokeApp
X-HW
X-Url
X-TtlSet
X-Vname
X-PC
X-Clacks-Overhead
Edge-Control
X-GitHub-Request-Id
X-ESI
X-ORACLE-DMS-ECID
X-Trace
X-Content-Type
X-Sol
X-Middleton-Response
Display
Response
X-Middleton-Display
Pagespeed
X-D2id
X-FastCGI-Cache
Arr-Disable-Session-Affinity
X-GoogleNews-Bot
X-Exp-Variant
X-Exp-Id
X-Kinja
X-Kinja-Revision
Verso
X-Kinja-Server
X-Cdn-Fetch
X-Kinja-Build
X-Use-Magma
X-Vcap-Request-Id
X-ORACLE-DMS-RID
X-Goog-Hash
X-Buckets
X-Rack-Cache
X-Country-Code
X-Varnish-TTL
X-Server-Name
X-Navigation-Version
Service-Worker-Allowed
X-VARITI-CCR
X-Powered-By-Plesk
X-Abt-Application-Version
X-Amz-Rid
X-Fastly-Request-ID
X-Client-IP
X-Cache-TTL
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-TTL
X-Webkit-CSP
Fastly-Restarts
X-Release
X-MSEdge-Ref
SPRequestGuid
X-SharePointHealthScore
X-Element-Page-Cache
X-Dw-Request-Base-Id
X-Cached
SPIisLatency
SPRequestDuration
X-NF-Request-ID
X-Oneagent-Js-Injection
Public-Key-Pins
RTSS
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
AR-Request-ID
AR-CACHE
AR-PoweredBy
Access-Control-Request-Method
Ar-Sid
X-SRCache-Fetch-Status
AR-ATIME
X-SRCache-Store-Status
X-Edge
X-LLID
X-Powered-CMS
X-Origin-Upstream-Status
X-Ezoic-Cdn
X-Upstream
Cache-Tag
X-Litespeed-Cache
Content-MD5
X-Px
Fusion-Content-Source
Fusion-Deployment-Id
Fusion-Content-Id
Fusion-Source
Fusion-Template-Id
Fusion-Component-Id
X-HP-Webp
X-Jurisdiction
S
X-Mid
X-ECACHE
X-Version
X-MCACHE
X-Mg-S
X-Recruiting
Charset
X-Ttl
X-Content-Digest
X-PressLabs-Stats
X-Amz-Server-Side-Encryption
Fastcgi-Cache
X-Kinsta-Cache
X-T
Cache-Tags
MicrosoftSharePointTeamServices
X-Content-Security-Policy-Report-Only
Front-End-Https
TCN
Filters
X-Debug
X-Grace
X-Logged-In
X-Id
X-Accel-Expires
Server-Node
Edge-Cache-Tag
X-DynaTrace
X-Correlation-Id
X-Forwarded-Proto
X-Pinterest-Direct
X-Forwarded-For
Server-Name
TP-Cache
TP-L2-Cache
Nginx-Cache
X-Amzn-Trace-Id
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Surrogate-Key
X-Request-Processing-Time
X-Request-Received
X-Yandex-Sdch-Disable
X-Varnish-Age
X-B3-Sampled
X-Microsite
X-Request-Handler-Origin-Region
X-Shield-Request-Id
X-XRDS-LOCATION
X-Ser
X-Hits
X-Az
X-AppVersion
X-Activity-Id
X-Amz-Replication-Status
X-DIS-Request-ID
X-F-Cache
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Hub-Id
X-HS-Cache-Config
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Origin-Server
X-Kinja-Server-Push
X-XRDS-Location
Accept-Charset
X-Geo-Country
X-Git-Hash
X-Cache-Key
Cache
X-Respond-Thread
Alternate-Protocol
X-Rid
X-Frontend
X-FTR-Request-ID
X-LB-Cache
Host
Powered-By-ChinaCache
X-Upgrade-Enabled
Section-Io-Cache
X-DataDome
X-Fastcgi-Cache
X-Mobile-URL
Access-Control-Allow-Method
X-Seen-By
X-Cache-Age
Paypal-Debug-Id
MS-CV
X-NWS-LOG-UUID
Healthy
Cleartype
X-Hostname
X-AOL-HN
X-Time
X-VCache
X-Whom
X-Varnish-Backend
ServerID
X-Content-Options
X-Type
X-IPLB-Instance
X-Ruxit-Js-Agent
X-TT
X-App-Environment
X-Request-Guid
X-Flags
X-Aspnet-Duration-Ms
X-Providence-Cookie
X-Route-Name
X-Is-Crawler
X-Server-ID
X-Cache-Action
Payment
X-Page-Id
X-Signature
X-B-Cache
X-Jobs
X-WebKit-CSP-Report-Only
X-Source
Fastcgi-Useragent
X-Debug-Info
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Load-Cache
X-N
X-Daa-Tunnel
X-Mobile
X-FB-Debug
X-Erf-Bev-Bev
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Via-JSL
X-RateLimit-Remaining
Nel
Version
Refresh
X-Cached-By
X-Contextid
X-Akamai-Edgescape
Realpath
X-Rule
X-Response-Served-From
X-Wix-Request-Id
X-Accel-Buffering
X-Original-Request-Id
Viewport
X-Proxy
Node
X-Framework
DC
X-Cacheable-TTL
X-Drupal-Cache-Tags
X-Cache-Rule
Ms-Operation-Id
X-ProcessESI
X-Zen-Fury
X-RTag
X-Cache-Operation
X-RemovedCookies
X-Instance
X-Cache-Time
X-Real-IP
X-B
Access-Control-Request-Headers
X-Region
X-Distributor
X-HTML-Minification-Powered-By
Referer-Policy
X-UUID
X-Page-View
X-Drupal-Cache-Contexts
X-Tt-Trace-Tag
X-Cluster-Name
X-Tt-Trace-Host
VIX-Pulpo-Upstream-Status
X-FW-Server
Eomportal-Instance
X-Cache-Expired-At
X-FW-Type
X-FW-Static
X-FW-Hash
X-FW-Serve
X-FW-Dynamic
VIX-Pulpo-Node
X-Cache-Control
X-Content-Powered-By
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-G
X-IPS-LoggedIn
X-Cache-Hit
DynaTrace
X-Tumblr-Pixel-0
X-Tumblr-Pixel
Liferay-Portal
X-L-Path
X-Environment-Context
X-Tumblr-Pixel-1
X-Tumblr-User
Countrycode
GEO-INFO
X-FireWall-Port
Server-Info
X-App-Server
X-Pass-Why
X-User-Agent
X-Ratelimit-Limit
Ec-Rule-Version
Webserver
From-Origin
X-Tumblr-Pixel-2
X-Varnish-Ttl
X-Protected-By
X-Node-Name
Section-Io-Id
Section-Io-Origin-Status
Section-Origin-Responded
CF-IPCountry
Section-Io-Origin-Time-Seconds
Protected
Xserver
SRV
X-Www-Served-By
X-Cache-Server
X-Backend-Name
X-Ratelimit-Remaining
X-ES-SERVER
X-RN-RSRV
X-Handled-By
X-UPSTREAM-Address
Frame-Options
X-Hl-Ver
X-Mode
Meta-Geo
X-FB-TRIP-ID
Cache-Tv-Group
X-Locale
X-Endurance-Cache-Level
X-Site-Version
Cache-Status
X-NYM-Debug-Backend
X-PHP-Host
X-Storage
X-Uri
X-Web-Node
X-Hyper-Cache
X-Soup
X-Be
X-Labrador-Cache-Channel
Webcakes-App-Name
Decoy-Debug-TTL
TWC-Device-Class
TWC-Privacy
TWC-GeoIP-LatLong
TWC-Locale-Group
Webcakes-App-Version
Webcakes-Region
Country
Property-Id
Decoy-Debug-Key
TWC-Connection-Speed
Fastly-SSL
Decoy-Debug-Status
TWC-GeoIP-Country
X-MP-GENERATED-AT
X-Redis-Cache
X-Origin-Hint
X-Origin-Date
X-Proto
X-Adobe-Content
X-Varnishpool
X-UA-Device-Type
X-Revision
X-Pubstack
X-Adobe-Loc
X-Human
X-Debug-IsConnected
X-Debug-IsPreview
X-OCL
X-PCL
X-ProxyCache-Key
X-Via-Fastly
X-BYPASS-REASON
Azure-Version
Azure-SlotName
Azure-SiteName
Azure-InstanceId
X-Sql-Count
Cache-Name
X-No-Session
X-ProxyCache-Status
Azure-RegionName
X-Request-Time
Retry-After
X-S-Maxage
X-AIR-PT
X-Server-W
X-Loop
X-Forwarded-Host
X-TNCMS
X-Cache-Grace
X-Sql-Duration-Ms
X-Amz-Meta-S3cmd-Attrs
X-Section
X-Say-TTL
X-Say-Cacheable
X-Format
X-FW-Version
X-Access
X-Hosted-By
X-SayCDN-TTL
X-Status
X-Cluster
X-WA-Info
X-PERF
X-VWS-Id
X-AWS-Id
X-TT-LOGID
X-LAGOON
X-LJ-Flow-ID
X-R9-Blue-Green-Version
X-ApacheServer
X-Device-Type
Mn-Server-Ip
Selected-Fe
X-Timing-Wait
X-Cache-TTL-Remaining
X-Nginx-Cache
X-Proxy-Build
X-Alternate-Cache-Key
X-Zipkin-Id
X-Routing-Service
X-Proxied
X-ShardId
X-ShopId
X-Storefront-Renderer-Rendered
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Shopify-Stage
X-Xfnlog-Site
X-CCM
X-Is-Bot
X-Rendered-As
X-Varnish-Grace
X-Qloud-Router
Apigw-Requestid
X-SRV
X-Info
X-Varnish-Server
S-Cnection
X-FTR-DC
X-FTR-Cache-Status
X-Country-Code-Real
X-FTR-Backend
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Realm
Cache-Hits
X-Via-CDN
X-Dc
AMP-Access-Control-Allow-Source-Origin
X-Cache-Enabled
X-FTR-Expires
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
X-Detected-As
X-Content-Age
X-Cdn
X-Cache-Host
X-GG-Cache-Date
X-Platform
X-Microcachable
X-Amzn-RequestId
X-Amzn-Remapped-Content-Length
Uber-Trace-Id
X-Amz-Apigw-Id
X-EdgeConnect-Cache-Status
X-Azure-Ref
X-Air-Hostname
X-B3-Traceid
X-Proxy-Cache-Status
X-Backend-Host
X-Aspnetmvc-Version
Amp-Access-Control-Allow-Source-Origin
X-Unique-Id
Tracecode
X-Cache-Var
X-CSRF-Token
SD-X-WS
X-Cache-Var-Map
X-Time-Microsecs
Akamai-GRN
X-NWS-UUID-VERIFY
X-GEO
X-Backend-TTL
X-ATG-Version
X-DynaTrace-JS-Agent
X-App-Version
X-ServerID
X-Oss-Object-Type
X-Oss-Request-Id
X-Oss-Storage-Class
X-Tb
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
X-Trace-Id
X-RCS-CacheZone
ServedBy
X-BCube-Filmed-By
Backend
X-Cache-Backend
X-Varnish-Hostname
X-Cache-PHP
X-Correlation-ID
X-ID
X-Debug-Cache
X-Cache-NGX
X-Akamai-Transformed
Thinkindot-CacheControl
T-Server
Expiry
X-Magnolia-Registration
X-Level-Front-Cache
Path
X-CF-Lambda-Fn
Odigeo-Trace-Id
X-B-Cookie
Release
X-A-Wwc
X-CF-Lambda-Version
Thinkindot-CacheControl-Type
X-Application
X-Aed
X-Connection-Hash
X-ARC
X-Matched-Rule
X-Location
SR-User-Adfree
Fastcgi-X-Cache-Version
Instruction
Lfy
DCR-Processing-Time-Ms
Meta-Geo-Continent
X-From
X-A-Dgt
MD5-Digest
X-A-Dcw
X-Fetched-On
Thinkindot-Control
X-Device-Os
X-External-Request-Id
DB-Nickname
X-Destination
X-Generated-On
X-Generation-Time
BehaviorPad-Version
Rendered-Blocks
X-D
Machine
X-GeoIP-City
X-A-Ccd
X-A-Dam
X-Cache-NE
Mobile-Detection-Method
DCR-Decision-By
X-A
X-Origin-TTL
X-ScT
X-Session-Fingerprint
HostName
X-S-Cookie
X-S
X-Request-UUID
X-Rewrite-Enabled
X-Rojux
X-SRCache-Key
X-Trv-Group
X-Vtex-Remote-Cache
Xc-Version
DSUID
X-Vtex-Processado-Em
X-VG-WebServer
X-Vdms-Path
X-Vdms-Version
X-VG-WebCache
X-Processor
X-Thinkindot-L3
X-Origin-CC
X-Owner
X-PAYTM-SRV-ID
X-PBS-Appsvrname
X-B3-SpanId
X-Sucuri-ID
X-FC-Vary-Parameters
Gh-Request-Id
Server-Host
X-OVcl-Cache
X-OVcl
X-Mvc-Supplant-Cachable
Host-ID
X-VServer
AKAMAI
Pagetype
X-Tumblr-Pixel-3
X-Azure-Ref-OriginShield
Cf-Device-Type
X-Node-Id
Fastly-Backend-Name
X-TrackingId
CacheControlHeader
X-Geo-Header
X-Skip-Cache
X-Ms-Request-Id
X-Ms-Version
X-NAPM-TraceId
X-Micro-Cache
X-Irp-Debug
X-Reqid
X-JWT-State
X-Varnish-Cache-Hits
X-Is-Gdpr
X-TA-CDN-Provider
X-Cache-Bucket
X-Has-Esi
X-NewRelic-App-Data
X-GeoIP
X-HS-Content-Campaign-Id
X-CS
PB-PID
PB-RID
X-APP-VERSION
Arc-Version
X-Cdn-Forward
X-Branch-Name
X-Bip
X-Backend-State
X-Cache-Id
X-Origin-Response-Time
X-Nginx-Cache-Key
On-Server
Wxu-Next-Commit
Wxu-Next-Hostname
X-Cms-Context
V-Age
X-Fastly-Cache
X-Core-Value
Wxu-Next-Region
X-Adobe-Source
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-Origin-Expires
Content-Disposition
X-VarnishDD-TTL
NGX
X-Old-Content-Length
X-User
X-Fastly-Backend
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Swa-Ws
X-Thanos
X-Esi-Check
X-Eu-Site
X-Generated-By
X-Generated-In
X-Li-Pop
X-IP
X-Li-Fabric
X-LI-UUID
X-HN
X-Scheme
X-Gzip
X-Dispatcher-Server
X-Origin
X-Varnish-CookieHashed-On
X-Csrf-Jwt
X-CUA
X-CGP
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Cache-Tags
X-Varnish-Beresp-Grace
X-Variation
UCS
X-Developer
X-Developers
X-DefHash
X-DefElseHash
X-Var-Ttl
X-Policy
X-Cache-Info
X-DPWN-IS-SECURE
Platform
L5d-Success-Class
Adler-Geo
PFcat
Location
Magicmarker
Locid
NM-Fastcgi-Cache
C-Via
Cache-Host
Sever-Int
Ha-Gx-Prefs
Ssr
Is-Eu
HA-Ipaddr
Server-Ext
Server-Hostname
X-TX-ID
User-Cache-Control
CloudFront-Viewer-Country
X-NU-AKA-ACS-Version
Fastly-SIE
X-Platform-Server
Fastly-SWR
True-Client-Country-4JS
Cf-Bgj
X-Block-Status
X-Method
X-Hnp-Log
X-Hash
X-Ratelimit-Reset
X-Varnish-Hits
X-Rebelmouse-Cache-Control
X-WADP-Cache
X-GoCache-CacheStatus
X-Gamma-Serve
CDN-Uid
X-Clara-WADP
X-Envoy-Decorator-Operation
X-Gen-Mode
X-Fmm-Version
Web-Mar-Node
X-Clientip
CDCHOST
Pramga
CDN-Cache
X-Request-Host
CDN-PullZone
CDN-EdgeStorageId
X-SIPLIST1
X-Slack-Backend
X-Varnish-Beresp-Status
X-Varnish-Beresp-Ttl
Vix-Hermes-Req-Id
X-EC-Lua
X-Sn-Servicetimems
Rt-Fastcgi-Cache
CDN-RequestCountryCode
CDN-CachedAt
CDN-RequestId
X-Cdn-Origin
IsBot
X-Rebelmouse-Surrogate-Control
L
X-Request-URI
X-Erf-Stays-Bingo-Pdp-Web
X-Goog-Meta-Goog-Reserved-File-Mtime
X-VG-TLSProxy
Fastly-Drupal-HTML
Apple-News-Services-Request-Url
Apple-News-Services-Host
Origin
X-Loc
Apple-News-Services-Handled
X-Cache-Date
X-Cache-Debug
X-Servername
Apple-News-Services-Parsed-Url
X-Cache-Expires
X-Dynatrace
X-CLOUD-TRACE-CONTEXT
X-Core-Mission
X-PF-Uncompressing
X-CACHE-KEY
X-LB-ID
X-Aicache-OS
X-NCache
X-Mvc-Supplant-OutputCached
X-Nc
Sid
X-Via-Popv
Esi-Enabled
X-Request-Start
X-Via-Popn
X-Varnish-Url
X-Via-Poph
X-Refresh
Who
X-CACHE-GROUP
Url
Country-Code
X-Oracle-Dms-Rid
X-Unique-ID
X-NC
X-Cache-Remote
Pics-Label
X-Varnish-Cacheable
X-Response-By
X-Epic-Correlation-Id
X-FireWall-Protection
S-Rt
X-Planisys-CDN-Cache
X-Tb-Optimization-Total-Bytes-Saved
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Proxy-Cachei7
X-TraceId
Xkeyi7
Req-Svc-Chain
Geo-Info
Content-Secure-Policy
X-B3-Spanid
X-BBXSRF
N-Cache
X-Host-Name
X-RateLimit-Limit
Source
X-Error
X-Webkit-Csp
X-Srv
X-DC
Cmsid
Cmstype
X-Cache-2
Geoip-Latitude
GeoIp-Country-Code
Ohc-File-Size
Filterid
Cross-Origin-Window-Policy
X-Webkit-CSP-Report-Only
X-HS-Status
HitType
X-Contensis-Viewer-Groups
Server-Ttl
Cteonnt-Length
X-Cache-ASPX
X-Varnish-Authentication
Svr
Kp-EeAlive
D-Cc-Upstream
X-Cc-Req-Id
X-Cc-Via
X-Served-From
X-Sucuri-Cache
Cache-Key
VivaBuild
Viewtype
MIME-Version
X-Wa
A
X-Servedbyhost
X-LiteSpeed-Cache-Control
X-Svr
X-CDN-Forward
Tcn
X-URL
M-TraceId
X-Server-IP
X-HostName
X-Vcl-Version
NGB
X-Nyt-Route
X-Esi
Arc-Country
X-Air-Source
X-API-Version
X-Origin-Time
Cross-Origin-Opener-Policy
X-Gdpr
X-Li-Proto
X-LI-Proto
X-Cs
X-FPC
TDXMobile
X-Cache-Config
X-Vgn-Hpd-Reason
Server-ID
SID
CACHE
Hostname
X-NGINX-Cache
Resin-Trace
X-RAMCache
X-VC
X-SN
X-HOST
NtCoent-Length
X-Viewer-Country
X-Vc
X-Webstats-RespID
X-VCL-Version
X-Check-Cacheable
X-SB
Server-Id
Request-ID
Ohc-Cache-HIT
XServer
X-NodeID
X-UA
X-WA
X-Internal-Host
X-ServedByHost
X-Newrelic-Synthetics
X-Service
X-Hcs-Proxy-Type
X-RPM
X-TIM-N
X-RPS
X-RSL
X-CCDN-Origin-Time
X-DSS
X-DW
Cache-Provider
X-SD-PageType
X-CCDN-CacheTTL
X-DB
X-DI
X-TIME
X-NGENIX-Cache
X-JoinUs
X-SaId
GeoIP-Country-Code
X-PHP-Backend
X-Geo
Mime-Version
X-App
X-Edge-Location
Srv
X-Render-Time
GeoIP-Latitude
FSS-Cache
X-Action
EpKe-Alive
ProcessTime
X-Via-NSCOPI
DataCenter
X-Provided-By
X-BBC-Edge-Cache-Status
CF-Cached-On
X-FTR-Cache-Host
X-Ua
X-Dynatrace-Js-Agent
X-Extlb
W
X-Fpc
X-Auto-Login
X-CF-Powered-By
X-Oss-Cdn-Auth
X-Forwarded-Site
Upgrade-Insecure-Requests
X-Worker
Processtime
X-CSRF-TOKEN
Datacenter
Mail-Subject
X-Cluster-Node
X-PJAX-URL
X-FORWARDED-FOR
X-Accel-Expires-Debug
LB
X-Proxy-Upstream
Proxy-Connection
Memcached
Surrogated-Key
We-Hiring
X-Date
X-Depends-On
X-VC-Cache
X-Region-Sid
X-Req
X-HITS
X-Cdn-Request-ID
X-MSEdge-Flight
X-Ftr-Cache-Host
X-Dw-Trace-Id
X-Parent-Response-Time
Cdn
X-RateLimit-Remaining-Second
X-BACKEND-TTL
X-Fastly-Backend-Reqs
Env
CDN
X-RateLimit-Limit-Second
X-MSEdge-Features
X-UnsetCookies
X-Bc-Bl
X-CACHE-AGE
X-Swift-Error
X-Client-Ip
X-Hello
Dnion-Transfer-Encoding
X-Cache-Tag
X-Fastly-Request-Id
Time
X-Rocket-Build-Number
X-BBC-Origin-Response-Status
X-APP
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-ABtesting
X-Sigma
X-Sigma-Backend
X-Flog
Memory
X-Air-Trace-Id
PICS-Label
X-ZONE
X-Akamai-Pragma-Client-IP
X-Men
CPC-Age
X-Pad
CPC-Cache
VNS-Age
Media-Length
VNS-Cache
X-Presslabs-Stats
X-Acquia-Application-Trace
X-Acquia-Application-UUID
OT-Force-Account-Verify
X-Oracle-DMS-ECID
X-Pf-Uncompressing
Vha6-Origin
X-Acquia-Purge-Tags
X-Acquia-Site
X-Zone
Epwk-X-Cache
X-LiteSpeed-Tag
CountryCode
X-Via-PopH
X-Via-PopN
X-Via-PopV
X-Lb-Id
X-ND-Cache
Cf-Ipcountry
X-ElasticPress-Search
X-Akamai-ERPolicy
X-Snapshot-Date
X-MiniProfiler-Ids
Xet-Cookie
X-Request-URL
X-Varnish-Beresp-TTL
X-Csrf-Token
X-Ms-Meta-Originalurl
X-Varnish-URL
X-Akamai-ERRuleID
WZWS-RAY
X-Vcache
X-ElasticPress-Query
X-Ms-Meta-Staticbatchstarttime
X-Request-Url
X-Tx-Id
State
X-Amz-Meta-Cb-Modifiedtime
Fastcgi-Cache-TTL
X-Tid
X-Litespeed-Cache-Control
Content-Script-Type
X-C
Content-Style-Type
URI
NnCoection
X-Traceid
X-B3-Parentspanid
Ohc-Response-Time
Phost
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Storefront-Renderer-Verified
Inserted-Into-Cache-At
Environment
X-Redis-Count
X-Redis-Duration-Ms
X-ServerName