Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-RAY
CF-Cache-Status
X-XSS-Protection
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-UA-Compatible
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Xss-Protection
X-Cache-Status
X-Request-ID
X-DNS-Prefetch-Control
X-Generator
X-Cacheable
X-Ua-Compatible
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Content-Encoding
X-CDN
X-AspNetMvc-Version
X-Envoy-Upstream-Service-Time
Feature-Policy
Status
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-Via
Upgrade
Access-Control-Max-Age
Keep-Alive
X-Ws-Request-Id
X-Age
X-AH-Environment
X-Turbo-Charged-By
X-Robots-Tag
Request-Context
X-Proxy-Cache
EagleId
X-Cache-Group
Server-Timing
X-Backend
X-Hacker
X-Server
Report-To
X-Amz-Request-Id
Host-Header
X-Server-Powered-By
X-Amz-Id-2
Grace
X-Nginx-Cache-Status
X-UA-Device
X-Rq
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Page-Speed
X-LiteSpeed-Cache
Cf-Railgun
X-Pingback
X-OneAgent-JS-Injection
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
NEL
X-Amz-Version-Id
X-Cache-Spec
X-Dns-Prefetch-Control
X-WebKit-CSP
X-Device
X-CST
Allow
Xkey
X-Vhost
X-Backend-Server
X-Host
X-Server-Id
EagleEye-TraceId
Surrogate-Control
Request-Id
X-Dispatcher
X-Node
Content-Location
X-Response-Time
X-Ruxit-JS-Agent
X-Akam-SW-Version
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Accept-CH
Accept-CH-Lifetime
P3p
X-ASPNET-VERSION
X-Application-Context
X-Ac
X-Template
X-Cache-Lookup
X-Language
X-Country
X-Mod-Pagespeed
X-Readtime
X-Cloud-Trace-Context
MS-Author-Via
X-B3-TraceId
Accept-Ch
Rating
X-Origin-Cache
Accept-Ch-Lifetime
X-Cnection
X-HW
X-MS-InvokeApp
X-Vname
X-TtlSet
X-PC
X-Url
X-Clacks-Overhead
Edge-Control
X-GitHub-Request-Id
X-ORACLE-DMS-ECID
X-Trace
X-ESI
X-Content-Type
Display
X-Middleton-Display
Response
Pagespeed
X-Middleton-Response
X-Sol
X-D2id
X-FastCGI-Cache
Arr-Disable-Session-Affinity
X-Kinja-Revision
X-Kinja-Build
X-Cdn-Fetch
X-GoogleNews-Bot
X-Exp-Id
X-Exp-Variant
X-Use-Magma
X-Kinja-Server
X-Kinja
X-Vcap-Request-Id
Verso
X-Goog-Hash
X-ORACLE-DMS-RID
X-Buckets
X-Rack-Cache
X-Country-Code
X-Varnish-TTL
X-Server-Name
X-Navigation-Version
Service-Worker-Allowed
X-Powered-By-Plesk
X-Abt-Application-Version
X-VARITI-CCR
X-Amz-Rid
X-Fastly-Request-ID
X-Client-IP
X-Cache-TTL
Pinterest-Generated-By
X-Pinterest-Rid
Pinterest-Version
X-Webkit-CSP
X-TTL
Fastly-Restarts
X-MSEdge-Ref
X-Release
X-SharePointHealthScore
SPRequestGuid
X-Element-Page-Cache
X-Dw-Request-Base-Id
X-Cached
X-Litespeed-Cache
X-NF-Request-ID
SPRequestDuration
SPIisLatency
X-Oneagent-Js-Injection
Public-Key-Pins
RTSS
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
Ar-Sid
AR-CACHE
X-SRCache-Fetch-Status
AR-Request-ID
X-SRCache-Store-Status
AR-ATIME
AR-PoweredBy
Access-Control-Request-Method
X-Edge
X-LLID
X-Powered-CMS
X-Origin-Upstream-Status
X-Ezoic-Cdn
X-Upstream
Cache-Tag
Content-MD5
X-Px
Fusion-Content-Source
Fusion-Content-Id
Fusion-Source
Fusion-Component-Id
Fusion-Deployment-Id
Fusion-Template-Id
X-Jurisdiction
X-HP-Webp
X-MCACHE
X-Mid
S
X-Version
X-Mg-S
X-ECACHE
X-Recruiting
X-Ttl
Charset
X-Content-Digest
X-Amz-Server-Side-Encryption
X-PressLabs-Stats
Fastcgi-Cache
X-Kinsta-Cache
X-T
Cache-Tags
MicrosoftSharePointTeamServices
Front-End-Https
X-Content-Security-Policy-Report-Only
TCN
Filters
X-Debug
Edge-Cache-Tag
X-Accel-Expires
X-Grace
X-Id
X-Logged-In
Server-Node
X-DynaTrace
X-Correlation-Id
X-Pinterest-Direct
X-Forwarded-Proto
TP-L2-Cache
Server-Name
TP-Cache
Nginx-Cache
X-Amzn-Trace-Id
X-Forwarded-For
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Surrogate-Key
X-Request-Received
X-Request-Processing-Time
X-Varnish-Age
X-Yandex-Sdch-Disable
X-B3-Sampled
X-Shield-Request-Id
X-Microsite
X-Request-Handler-Origin-Region
X-XRDS-LOCATION
X-Ser
X-Hits
X-Az
X-AppVersion
X-Activity-Id
X-Amz-Replication-Status
X-F-Cache
X-DIS-Request-ID
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Combine-CSS
X-HS-Cache-Config
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Metageneration
X-GUploader-UploadID
X-Goog-Storage-Class
X-Kinja-Server-Push
X-Origin-Server
X-XRDS-Location
Accept-Charset
X-Geo-Country
X-Git-Hash
X-Cache-Key
Cache
X-Respond-Thread
Alternate-Protocol
X-Rid
X-Frontend
X-FTR-Request-ID
X-DataDome
X-Upgrade-Enabled
Section-Io-Cache
Powered-By-ChinaCache
X-LB-Cache
Host
X-Fastcgi-Cache
X-Mobile-URL
X-Seen-By
X-Cache-Age
Access-Control-Allow-Method
Paypal-Debug-Id
X-VCache
X-AOL-HN
Cleartype
X-Hostname
Healthy
X-Time
X-NWS-LOG-UUID
X-Type
X-Ruxit-Js-Agent
X-Varnish-Backend
X-Content-Options
MS-CV
ServerID
X-App-Environment
X-Whom
X-IPLB-Instance
X-TT
X-Aspnet-Duration-Ms
X-Flags
X-Server-ID
X-Request-Guid
X-Providence-Cookie
X-Is-Crawler
X-Route-Name
X-Signature
X-Jobs
X-B-Cache
X-Cache-Action
Payment
Fastcgi-Useragent
X-Source
X-Debug-Info
X-Page-Id
X-WebKit-CSP-Report-Only
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Load-Cache
X-N
X-Daa-Tunnel
X-Mobile
X-FB-Debug
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Erf-Bev-Bev
X-Via-JSL
X-RateLimit-Remaining
Nel
Refresh
Version
X-Cached-By
X-Contextid
Realpath
X-Akamai-Edgescape
X-Original-Request-Id
X-Response-Served-From
X-Wix-Request-Id
X-Accel-Buffering
X-Cacheable-TTL
X-Drupal-Cache-Tags
Node
X-Proxy
Viewport
DC
X-Rule
X-RemovedCookies
X-Zen-Fury
X-Cache-Operation
X-ProcessESI
X-Framework
X-Cache-Rule
Ms-Operation-Id
X-RTag
X-B
X-Instance
X-Cache-Time
X-HTML-Minification-Powered-By
X-Real-IP
X-Region
X-Distributor
Access-Control-Request-Headers
X-UUID
X-Drupal-Cache-Contexts
X-Page-View
Referer-Policy
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-FW-Type
X-FW-Static
X-Cache-Expired-At
X-Tt-Trace-Tag
Eomportal-Instance
X-FW-Server
X-Tt-Trace-Host
X-FW-Serve
X-FW-Hash
X-FW-Dynamic
X-Cache-Control
X-Cluster-Name
X-Content-Powered-By
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-G
X-IPS-LoggedIn
X-Cache-Hit
DynaTrace
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-1
Countrycode
X-L-Path
Liferay-Portal
X-Environment-Context
X-Tumblr-Pixel-0
GEO-INFO
Server-Info
X-FireWall-Port
X-App-Server
X-Pass-Why
Ec-Rule-Version
X-User-Agent
X-Ratelimit-Limit
X-Tumblr-Pixel-2
From-Origin
X-Varnish-Ttl
Webserver
X-Node-Name
X-Protected-By
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Io-Id
Section-Origin-Responded
CF-IPCountry
Protected
Xserver
SRV
X-Www-Served-By
X-Cache-Server
X-Ratelimit-Remaining
X-UPSTREAM-Address
X-ES-SERVER
Meta-Geo
X-Mode
X-Handled-By
Frame-Options
X-RN-RSRV
X-FB-TRIP-ID
X-Site-Version
Cache-Tv-Group
X-Endurance-Cache-Level
X-Locale
Cache-Status
X-Be
X-Web-Node
X-Labrador-Cache-Channel
X-Storage
X-NYM-Debug-Backend
X-Backend-Name
X-Uri
X-Hyper-Cache
X-PHP-Host
X-Soup
X-Origin-Hint
Property-Id
TWC-Connection-Speed
TWC-GeoIP-LatLong
X-UA-Device-Type
TWC-Privacy
Webcakes-App-Name
Webcakes-Region
TWC-Locale-Group
TWC-GeoIP-Country
X-Nginx-Cache
TWC-Device-Class
X-Pubstack
X-Adobe-Content
X-Redis-Cache
X-Revision
Decoy-Debug-Key
X-Origin-Date
Country
X-Adobe-Loc
X-Varnishpool
Fastly-SSL
Webcakes-App-Version
X-Hl-Ver
Decoy-Debug-TTL
Decoy-Debug-Status
X-Human
Azure-SlotName
Azure-SiteName
Azure-RegionName
Azure-Version
Cache-Name
X-Debug-IsConnected
Retry-After
X-Loop
X-Debug-IsPreview
X-OCL
X-Access
X-TNCMS
X-MP-GENERATED-AT
X-Proto
X-Cache-Grace
X-Format
X-Forwarded-Host
X-S-Maxage
X-PCL
Azure-InstanceId
X-FW-Version
X-AIR-PT
X-Server-W
X-Sql-Duration-Ms
X-Sql-Count
X-SayCDN-TTL
X-Request-Time
X-Section
X-Say-Cacheable
X-Say-TTL
X-Via-Fastly
X-Hosted-By
X-No-Session
X-TT-LOGID
X-Status
X-AWS-Id
X-LJ-Flow-ID
X-ProxyCache-Key
X-PERF
X-ProxyCache-Status
X-VWS-Id
X-WA-Info
X-LAGOON
X-R9-Blue-Green-Version
X-Cluster
X-BYPASS-REASON
X-ApacheServer
X-Amz-Meta-S3cmd-Attrs
Mn-Server-Ip
X-Cache-TTL-Remaining
X-Proxy-Build
X-Timing-Wait
Selected-Fe
X-Sorting-Hat-PodId
X-ShardId
X-Sorting-Hat-ShopId
X-Zipkin-Id
X-Routing-Service
X-Storefront-Renderer-Rendered
X-Alternate-Cache-Key
X-Proxied
X-ShopId
X-Device-Type
X-Shopify-Stage
X-Rendered-As
X-CCM
X-Is-Bot
X-Xfnlog-Site
X-Qloud-Router
Apigw-Requestid
X-Varnish-Grace
X-SRV
S-Cnection
X-Info
X-Varnish-Server
X-Country-Code-Real
X-FTR-DC
X-FTR-Cache-Status
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Realm
X-Via-CDN
Cache-Hits
AMP-Access-Control-Allow-Source-Origin
X-Dc
X-Cache-Enabled
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
X-FTR-Expires
X-Detected-As
X-Cdn
X-Content-Age
X-Microcachable
X-Cache-Host
X-GG-Cache-Date
X-Amz-Apigw-Id
Uber-Trace-Id
X-EdgeConnect-Cache-Status
X-Platform
X-Amzn-RequestId
X-Amzn-Remapped-Content-Length
X-Air-Hostname
X-Azure-Ref
X-Backend-Host
X-Proxy-Cache-Status
Amp-Access-Control-Allow-Source-Origin
Tracecode
X-Unique-Id
X-Aspnetmvc-Version
X-Cache-Var-Map
SD-X-WS
X-CSRF-Token
X-Cache-Var
X-Time-Microsecs
X-NWS-UUID-VERIFY
Akamai-GRN
X-ATG-Version
X-DynaTrace-JS-Agent
X-App-Version
X-GEO
X-Backend-TTL
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
X-Oss-Server-Time
X-Trace-Id
X-Oss-Storage-Class
X-ServerID
X-Oss-Object-Type
X-Tb
ServedBy
Backend
X-RCS-CacheZone
X-BCube-Filmed-By
X-Varnish-Hostname
X-Cache-Backend
X-ID
X-Debug-Cache
X-Correlation-ID
X-Cache-PHP
X-Cache-NGX
X-Akamai-Transformed
X-Location
X-Level-Front-Cache
X-Matched-Rule
X-Connection-Hash
Meta-Geo-Continent
Mobile-Detection-Method
X-A-Dcw
MD5-Digest
X-A-Dgt
X-Aed
X-A-Wwc
Machine
X-A-Dam
Odigeo-Trace-Id
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
T-Server
Thinkindot-Control
Rendered-Blocks
X-A-Ccd
X-A
Path
X-Application
X-ARC
X-Device-Os
X-Destination
X-D
DB-Nickname
X-External-Request-Id
X-Generated-On
X-From
X-Fetched-On
BehaviorPad-Version
X-CF-Lambda-Version
Fastcgi-X-Cache-Version
Instruction
X-B-Cookie
Expiry
X-Cache-NE
X-CF-Lambda-Fn
DCR-Decision-By
DCR-Processing-Time-Ms
X-Generation-Time
X-Origin-TTL
X-Session-Fingerprint
HostName
X-SRCache-Key
X-ScT
X-S-Cookie
X-Rewrite-Enabled
X-Rojux
X-S
X-Thinkindot-L3
X-Vdms-Path
X-Vtex-Remote-Cache
Xc-Version
DSUID
X-Vtex-Processado-Em
X-VG-WebServer
X-Vdms-Version
X-VG-WebCache
X-Request-UUID
X-Trv-Group
X-PAYTM-SRV-ID
SR-User-Adfree
X-Owner
X-Origin-CC
X-PBS-Appsvrname
X-Processor
X-B3-SpanId
X-Sucuri-ID
X-Micro-Cache
X-Node-Id
Fastly-Backend-Name
X-Skip-Cache
Release
X-Magnolia-Registration
X-Azure-Ref-OriginShield
X-TrackingId
AKAMAI
Cf-Device-Type
X-VServer
CacheControlHeader
X-Tumblr-Pixel-3
X-CS
Pagetype
X-Geo-Header
X-NewRelic-App-Data
Lfy
X-GeoIP
Server-Host
X-HS-Content-Campaign-Id
X-Cache-Bucket
X-Is-Gdpr
X-JWT-State
Host-ID
X-NAPM-TraceId
X-Reqid
X-Ms-Request-Id
X-Varnish-Cache-Hits
X-TA-CDN-Provider
X-Has-Esi
X-Ms-Version
X-OVcl
X-GeoIP-City
X-OVcl-Cache
X-Cdn-Forward
PB-RID
PB-PID
X-APP-VERSION
Arc-Version
X-Origin-Response-Time
X-Old-Content-Length
X-Origin
X-Nginx-Cache-Key
Wxu-Next-Region
UCS
V-Age
Wxu-Next-Commit
X-Cms-Context
X-Core-Value
Ssr
X-Fastly-Cache
Wxu-Next-Hostname
X-Backend-State
X-Origin-Expires
X-Wikidot-Static-Cache
Content-Disposition
NGX
X-Adobe-Source
On-Server
X-Wikidot-Backend
X-Variation
X-Swa-Ws
X-Generated-By
X-SVT-ORM-VERSION
X-Thanos
X-FC-Vary-Parameters
X-Esi-Check
X-Fastly-Backend
X-SVT-ORM-RULES
X-Mvc-Supplant-Cachable
X-Irp-Debug
X-Li-Fabric
X-Li-Pop
X-IP
X-HN
X-Gzip
X-Scheme
X-Dispatcher-Server
X-Developers
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-VarnishDD-TTL
X-Cache-Info
X-Branch-Name
X-Cache-Id
X-Varnish-Beresp-Grace
X-CUA
X-User
X-Developer
X-DefHash
X-DefElseHash
X-LI-UUID
X-Var-Ttl
X-Bip
X-DPWN-IS-SECURE
NM-Fastcgi-Cache
Cache-Host
Adler-Geo
Is-Eu
Platform
X-B3-Traceid
Magicmarker
Gh-Request-Id
Location
Sever-Int
Server-Hostname
Server-Ext
Locid
C-Via
PFcat
User-Cache-Control
X-TX-ID
CDCHOST
X-Sn-Servicetimems
X-Varnish-Hits
X-EC-Lua
X-Slack-Backend
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Status
X-Policy
X-Generated-In
X-Gamma-Serve
X-Eu-Site
X-Hash
X-Method
X-Request-URI
X-Request-Host
CDN-Cache
X-SIPLIST1
CDN-Uid
X-NU-AKA-ACS-Version
X-Hnp-Log
X-GoCache-CacheStatus
X-Gen-Mode
X-Platform-Server
X-Ratelimit-Reset
X-WADP-Cache
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Fmm-Version
X-Envoy-Decorator-Operation
CloudFront-Viewer-Country
CDN-RequestId
CDN-PullZone
CDN-EdgeStorageId
Fastly-SIE
Fastly-SWR
X-Clara-WADP
X-Block-Status
Web-Mar-Node
CDN-CachedAt
CDN-RequestCountryCode
X-Cache-Tags
Ha-Gx-Prefs
X-Cdn-Origin
Cf-Bgj
X-CGP
HA-Ipaddr
IsBot
True-Client-Country-4JS
Rt-Fastcgi-Cache
Vix-Hermes-Req-Id
L5d-Success-Class
L
X-Clientip
Pramga
X-Csrf-Jwt
X-Erf-Stays-Bingo-Pdp-Web
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Cache-Date
Fastly-Drupal-HTML
X-Servername
X-Loc
Apple-News-Services-Request-Url
Apple-News-Services-Handled
X-VG-TLSProxy
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Origin
X-Cache-Expires
X-Cache-Debug
X-CLOUD-TRACE-CONTEXT
X-Dynatrace
X-NCache
X-CACHE-KEY
X-Aicache-OS
X-LB-ID
X-Core-Mission
Sid
X-Nc
X-Request-Start
X-PF-Uncompressing
X-Via-Popv
X-Varnish-Url
X-Mvc-Supplant-OutputCached
Esi-Enabled
X-Via-Popn
X-Via-Poph
Who
X-Refresh
X-CACHE-GROUP
Url
X-Oracle-Dms-Rid
X-URL
Country-Code
X-Unique-ID
Pics-Label
X-Cache-Remote
X-NC
X-Varnish-Cacheable
X-Epic-Correlation-Id
X-Response-By
X-FireWall-Protection
S-Rt
X-TraceId
X-Tb-Optimization-Total-Bytes-Saved
X-Planisys-CDN-TTL
Req-Svc-Chain
Xkeyi7
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Proxy-Cachei7
Geo-Info
X-B3-Spanid
X-Error
X-Esi
X-BBXSRF
N-Cache
X-Webkit-Csp
X-Host-Name
X-RateLimit-Limit
Content-Secure-Policy
Source
X-Srv
X-DC
GeoIp-Country-Code
Cmstype
X-Cache-2
Geoip-Latitude
Cmsid
X-Webkit-CSP-Report-Only
Ohc-File-Size
Filterid
Cross-Origin-Window-Policy
X-Varnish-Authentication
Svr
X-Cache-ASPX
Cteonnt-Length
Kp-EeAlive
X-Cc-Via
X-Cc-Req-Id
X-Served-From
X-Contensis-Viewer-Groups
D-Cc-Upstream
HitType
X-HS-Status
Server-Ttl
X-Sucuri-Cache
X-LiteSpeed-Cache-Control
X-Servedbyhost
VivaBuild
Tcn
MIME-Version
X-Wa
X-Svr
X-CDN-Forward
Viewtype
Cache-Key
A
X-Server-IP
M-TraceId
X-Vcl-Version
X-HostName
X-Gdpr
Server-ID
X-Air-Source
X-Nyt-Route
X-API-Version
TDXMobile
X-Li-Proto
X-LI-Proto
Cross-Origin-Opener-Policy
X-FPC
NGB
X-Cs
X-Cache-Config
X-Vgn-Hpd-Reason
Arc-Country
X-Origin-Time
CACHE
SID
X-SN
Hostname
X-VC
X-RAMCache
Resin-Trace
X-HOST
NtCoent-Length
Server-Id
X-SB
X-Vc
X-VCL-Version
X-Check-Cacheable
X-NodeID
XServer
Request-ID
Ohc-Cache-HIT
X-Viewer-Country
X-Webstats-RespID
X-UA
X-RSL
X-Service
X-CCDN-CacheTTL
X-RPS
X-ServedByHost
X-TIM-N
X-DSS
X-DI
X-DB
X-CCDN-Origin-Time
X-WA
X-Internal-Host
X-Hcs-Proxy-Type
X-DW
X-RPM
Cache-Provider
X-Newrelic-Synthetics
X-NGINX-Cache
X-SD-PageType
X-TIME
X-JoinUs
X-SaId
Srv
X-Render-Time
Mime-Version
GeoIP-Country-Code
GeoIP-Latitude
X-Edge-Location
X-App
X-Geo
X-NGENIX-Cache
X-PHP-Backend
X-FORWARDED-FOR
X-Provided-By
X-Action
EpKe-Alive
FSS-Cache
X-BBC-Edge-Cache-Status
X-Via-NSCOPI
ProcessTime
DataCenter
CF-Cached-On
X-FTR-Cache-Host
X-Ua
X-Dynatrace-Js-Agent
X-Oss-Cdn-Auth
W
X-COUNTRY
X-Fpc
X-Forwarded-Site
X-Worker
X-CF-Powered-By
Upgrade-Insecure-Requests
Processtime
X-Auto-Login
X-Extlb
Datacenter
X-Presslabs-Stats
X-CSRF-TOKEN
LB
X-Depends-On
X-PJAX-URL
X-VC-Cache
X-Region-Sid
Mail-Subject
X-Date
X-Proxy-Upstream
X-Accel-Expires-Debug
Proxy-Connection
We-Hiring
Surrogated-Key
X-Req
X-Cluster-Node
Memcached
X-HITS
X-Cdn-Request-ID
Env
X-UnsetCookies
X-Parent-Response-Time
X-Dw-Trace-Id
X-MSEdge-Flight
X-Ftr-Cache-Host
Cdn
X-MSEdge-Features
CDN
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-BACKEND-TTL
X-Bc-Bl
X-Fastly-Backend-Reqs
X-Client-Ip
X-Swift-Error
X-CACHE-AGE
PICS-Label
X-BBC-Origin-Response-Status
X-IN-APIGATEWAY
X-Rocket-Build-Number
X-APP
X-Cache-Tag
Time
X-Flog
X-Hello
X-ABtesting
Memory
X-Sigma
Dnion-Transfer-Encoding
X-IN-APIGATEWAYSSL
X-Fastly-Request-Id
X-Air-Trace-Id
X-Sigma-Backend
X-ZONE
X-Akamai-Pragma-Client-IP
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Acquia-Application-Trace
Media-Length
X-Acquia-Site
Vha6-Origin
X-Oracle-DMS-ECID
VNS-Cache
X-Men
CPC-Cache
X-Pad
X-Pf-Uncompressing
VNS-Age
X-Zone
OT-Force-Account-Verify
CPC-Age
Epwk-X-Cache
X-Via-PopV
X-Via-PopN
X-ND-Cache
X-LiteSpeed-Tag
X-Via-PopH
Cf-Ipcountry
X-ElasticPress-Search
X-Akamai-ERRuleID
X-Request-Url
WZWS-RAY
X-Varnish-Beresp-TTL
X-Varnish-URL
X-Request-URL
X-Snapshot-Date
X-Csrf-Token
X-MiniProfiler-Ids
X-Vcache
X-Ms-Meta-Originalurl
X-Ms-Meta-Staticbatchstarttime
X-ElasticPress-Query
X-Akamai-ERPolicy
X-Lb-Id
Xet-Cookie
CountryCode
X-Tx-Id
X-ServerName
State
X-Redis-Count
X-Redis-Duration-Ms
Fastcgi-Cache-TTL
X-Traceid
Content-Script-Type
X-Litespeed-Cache-Control
X-Amz-Meta-Cb-Modifiedtime
Content-Style-Type
URI
Environment
Ohc-Response-Time
X-C
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-B3-Parentspanid
Inserted-Into-Cache-At
X-Tid
X-Storefront-Renderer-Verified
NnCoection
Phost