Threat Level: green Handler on Duty: Renato Marinho

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-RAY
CF-Cache-Status
X-XSS-Protection
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-Served-By
X-UA-Compatible
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Xss-Protection
X-Request-ID
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Ua-Compatible
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Content-Encoding
X-CDN
Feature-Policy
X-AspNetMvc-Version
X-Envoy-Upstream-Service-Time
Status
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-Via
Upgrade
Access-Control-Max-Age
Keep-Alive
X-Ws-Request-Id
X-Age
X-AH-Environment
X-Robots-Tag
X-Turbo-Charged-By
Request-Context
X-Cache-Group
X-Proxy-Cache
EagleId
Server-Timing
X-Backend
X-Hacker
X-Server
Report-To
Host-Header
X-Amz-Request-Id
X-Server-Powered-By
X-Amz-Id-2
Grace
X-Nginx-Cache-Status
X-UA-Device
X-Rq
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Page-Speed
Cf-Railgun
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-OneAgent-JS-Injection
NEL
X-Dns-Prefetch-Control
X-Amz-Version-Id
X-Cache-Spec
X-WebKit-CSP
X-Device
X-CST
Allow
Xkey
X-Vhost
X-Host
X-Backend-Server
X-Server-Id
EagleEye-TraceId
Request-Id
Surrogate-Control
X-Dispatcher
X-Node
Content-Location
X-Response-Time
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Akam-SW-Version
X-Ruxit-JS-Agent
Accept-CH
P3p
X-ASPNET-VERSION
X-Application-Context
Accept-CH-Lifetime
X-Ac
X-Country
X-Cache-Lookup
X-Template
X-Language
X-Mod-Pagespeed
X-Readtime
Accept-Ch
X-Cloud-Trace-Context
MS-Author-Via
X-B3-TraceId
Accept-Ch-Lifetime
Rating
X-Origin-Cache
X-MS-InvokeApp
X-Cnection
X-HW
X-Url
X-TtlSet
X-PC
X-Vname
X-Clacks-Overhead
Edge-Control
X-GitHub-Request-Id
X-ORACLE-DMS-ECID
X-Trace
X-ESI
X-Content-Type
X-Middleton-Display
X-Middleton-Response
Response
Pagespeed
Display
X-Sol
X-ORACLE-DMS-RID
X-D2id
Arr-Disable-Session-Affinity
X-GoogleNews-Bot
X-Kinja
X-Kinja-Revision
X-Kinja-Build
X-Use-Magma
X-Exp-Id
X-Kinja-Server
X-Cdn-Fetch
X-Exp-Variant
Verso
X-Vcap-Request-Id
X-FastCGI-Cache
X-Goog-Hash
X-Rack-Cache
X-Buckets
X-Country-Code
X-Varnish-TTL
Service-Worker-Allowed
X-Server-Name
X-Navigation-Version
X-Powered-By-Plesk
X-VARITI-CCR
X-Amz-Rid
X-Abt-Application-Version
X-Fastly-Request-ID
X-Webkit-CSP
X-Client-IP
X-Cache-TTL
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
Fastly-Restarts
SPRequestGuid
X-Release
X-SharePointHealthScore
X-MSEdge-Ref
X-TTL
X-Dw-Request-Base-Id
X-Element-Page-Cache
X-Cached
SPIisLatency
SPRequestDuration
X-Oneagent-Js-Injection
X-NF-Request-ID
Public-Key-Pins
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
RTSS
Access-Control-Request-Method
X-SRCache-Store-Status
Ar-Sid
AR-CACHE
X-SRCache-Fetch-Status
AR-ATIME
AR-Request-ID
AR-PoweredBy
X-Edge
X-LLID
X-Powered-CMS
X-Litespeed-Cache
X-Ezoic-Cdn
X-Origin-Upstream-Status
Cache-Tag
Content-MD5
X-Upstream
X-Px
Fusion-Content-Source
Fusion-Source
Fusion-Template-Id
Fusion-Content-Id
Fusion-Deployment-Id
Fusion-Component-Id
X-Jurisdiction
X-HP-Webp
X-Ttl
S
X-Version
X-ECACHE
X-MCACHE
X-Mid
X-Recruiting
X-Mg-S
Charset
X-Content-Digest
X-PressLabs-Stats
X-Amz-Server-Side-Encryption
X-Kinsta-Cache
Fastcgi-Cache
X-T
Cache-Tags
MicrosoftSharePointTeamServices
Front-End-Https
Filters
X-Content-Security-Policy-Report-Only
X-DynaTrace
X-Logged-In
TCN
X-Debug
Server-Node
X-Accel-Expires
Edge-Cache-Tag
X-Id
X-Forwarded-Proto
X-Grace
X-Correlation-Id
TP-Cache
TP-L2-Cache
Server-Name
Nginx-Cache
X-Pinterest-Direct
X-Amzn-Trace-Id
X-Forwarded-For
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Surrogate-Key
X-Request-Processing-Time
X-Request-Received
X-Varnish-Age
X-Yandex-Sdch-Disable
X-B3-Sampled
X-Ser
X-Shield-Request-Id
X-Microsite
X-Request-Handler-Origin-Region
X-Ruxit-Js-Agent
X-Az
X-Hits
X-AppVersion
X-Activity-Id
X-Amz-Replication-Status
X-F-Cache
X-XRDS-LOCATION
X-DIS-Request-ID
X-HS-Combine-CSS
X-HS-Hub-Id
X-HS-Cache-Config
X-XRDS-Location
X-HS-Content-Id
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Origin-Server
Accept-Charset
X-Geo-Country
X-Git-Hash
Alternate-Protocol
X-Cache-Key
X-Respond-Thread
X-Rid
Cache
X-FTR-Request-ID
Section-Io-Cache
X-Frontend
X-Fastcgi-Cache
X-LB-Cache
Host
X-Upgrade-Enabled
X-DataDome
X-Time
Access-Control-Allow-Method
Powered-By-ChinaCache
X-Mobile-URL
X-NWS-LOG-UUID
X-Seen-By
MS-CV
X-Server-ID
X-Cache-Age
X-VCache
Paypal-Debug-Id
X-AOL-HN
X-TT
Healthy
X-Hostname
X-Type
Cleartype
X-Whom
X-IPLB-Instance
ServerID
X-Providence-Cookie
Payment
X-Request-Guid
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Varnish-Backend
X-Is-Crawler
X-Aspnet-Duration-Ms
X-Route-Name
X-Content-Options
X-Flags
X-B-Cache
X-Cache-Action
X-Signature
X-Jobs
X-Page-Id
X-Source
X-App-Environment
Fastcgi-Useragent
X-Debug-Info
X-WebKit-CSP-Report-Only
X-N
X-Load-Cache
X-Daa-Tunnel
X-Mobile
X-FB-Debug
X-Erf-Bev-Bev
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
Nel
X-Via-JSL
Refresh
X-RateLimit-Remaining
X-Contextid
Realpath
Version
X-Accel-Buffering
X-Original-Request-Id
X-Wix-Request-Id
X-Drupal-Cache-Tags
X-Cached-By
X-Response-Served-From
X-Rule
X-Framework
X-Akamai-Edgescape
X-RTag
X-Cacheable-TTL
DC
Ms-Operation-Id
Node
X-Proxy
X-Zen-Fury
X-RemovedCookies
X-ProcessESI
Viewport
X-Cache-Rule
X-Cache-Operation
Referer-Policy
X-Real-IP
X-Instance
X-Distributor
X-B
Access-Control-Request-Headers
X-HTML-Minification-Powered-By
X-Page-View
X-UUID
X-Cache-Time
Eomportal-Instance
X-Drupal-Cache-Contexts
X-Region
X-Cache-Expired-At
X-Tt-Trace-Host
X-Cluster-Name
X-Tt-Trace-Tag
Liferay-Portal
VIX-Pulpo-Upstream-Status
X-FW-Hash
VIX-Pulpo-Node
X-FW-Type
X-Yottaa-Optimizations
X-Content-Powered-By
X-Yottaa-Metrics
Countrycode
X-FW-Server
X-FW-Static
X-FW-Serve
X-FW-Dynamic
X-Cache-Control
X-G
X-IPS-LoggedIn
X-Cache-Hit
X-Environment-Context
DynaTrace
X-Tumblr-Pixel-0
X-L-Path
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-Tumblr-User
X-Pass-Why
X-FireWall-Port
Server-Info
GEO-INFO
X-App-Server
X-Varnish-Ttl
Ec-Rule-Version
X-Ratelimit-Limit
X-User-Agent
Section-Io-Origin-Status
Section-Io-Id
Section-Origin-Responded
Webserver
X-Tumblr-Pixel-2
X-Protected-By
Section-Io-Origin-Time-Seconds
From-Origin
CF-IPCountry
X-Node-Name
SRV
X-Ratelimit-Remaining
Xserver
X-Www-Served-By
Protected
X-Nginx-Cache
X-Endurance-Cache-Level
X-RN-RSRV
X-Handled-By
X-Hl-Ver
Meta-Geo
X-Cache-Server
X-Backend-Name
X-UPSTREAM-Address
X-ES-SERVER
X-Mode
X-Debug-IsPreview
Cache-Tv-Group
X-FB-TRIP-ID
X-Debug-IsConnected
X-Site-Version
Frame-Options
X-Uri
X-Locale
X-Varnishpool
X-Web-Node
X-Soup
X-PHP-Host
X-Labrador-Cache-Channel
X-Adobe-Content
X-Device-Type
X-Adobe-Loc
X-MP-GENERATED-AT
X-Storage
Cache-Status
X-NYM-Debug-Backend
X-ProxyCache-Key
X-Proto
X-Pubstack
Selected-Fe
Cache-Name
Decoy-Debug-TTL
TWC-Device-Class
X-Sql-Duration-Ms
X-Human
X-Timing-Wait
X-Origin-Hint
X-Be
X-PCL
X-BYPASS-REASON
Property-Id
TWC-Connection-Speed
X-OCL
X-Request-Time
Webcakes-Region
X-Redis-Cache
X-Via-Fastly
Decoy-Debug-Key
X-Sql-Count
Fastly-SSL
Decoy-Debug-Status
TWC-GeoIP-Country
X-ProxyCache-Status
X-Hyper-Cache
X-WA-Info
TWC-GeoIP-LatLong
TWC-Privacy
X-Proxy-Build
X-UA-Device-Type
Webcakes-App-Name
TWC-Locale-Group
Webcakes-App-Version
Country
Azure-RegionName
X-S-Maxage
Azure-InstanceId
X-TNCMS
X-Hosted-By
X-Access
X-Forwarded-Host
X-Revision
X-Section
X-No-Session
X-Say-TTL
Retry-After
X-R9-Blue-Green-Version
X-Loop
X-LAGOON
X-Format
X-Cache-Grace
X-Origin-Date
X-Say-Cacheable
Azure-SlotName
X-SayCDN-TTL
Azure-Version
X-FW-Version
Azure-SiteName
X-CCM
X-Shopify-Stage
X-ShopId
X-ShardId
X-VWS-Id
X-LJ-Flow-ID
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Server-W
X-Cluster
X-ApacheServer
X-Alternate-Cache-Key
X-PERF
X-Storefront-Renderer-Rendered
X-Cache-TTL-Remaining
X-Status
X-Xfnlog-Site
X-TT-LOGID
X-AWS-Id
X-AIR-PT
X-Proxied
X-Zipkin-Id
X-Routing-Service
Mn-Server-Ip
X-SRV
X-Qloud-Router
Apigw-Requestid
X-Rendered-As
X-Is-Bot
X-Amz-Meta-S3cmd-Attrs
X-Info
X-Varnish-Grace
X-Varnish-Server
X-FTR-DC
X-FTR-Backend
S-Cnection
X-FTR-Balancer
X-Via-CDN
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Realm
X-FTR-Backend-Server
Cache-Hits
X-Cdn
AMP-Access-Control-Allow-Source-Origin
X-Dc
X-Microcachable
X-Cache-Enabled
X-GG-Cache-Date
X-FTR-Expires
X-Content-Age
X-Platform
X-Detected-As
X-Cache-Host
X-Proxy-Cache-Status
X-EdgeConnect-Cache-Status
X-Amzn-Remapped-Content-Length
Uber-Trace-Id
X-Aspnetmvc-Version
X-Azure-Ref
X-Amz-Apigw-Id
X-Amzn-RequestId
Amp-Access-Control-Allow-Source-Origin
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
X-Backend-Host
X-Air-Hostname
Tracecode
X-NWS-UUID-VERIFY
X-Cache-Var
X-App-Version
SD-X-WS
X-Cache-Var-Map
X-Unique-Id
X-CSRF-Token
X-Time-Microsecs
Akamai-GRN
X-Oss-Object-Type
X-Oss-Server-Time
X-Oss-Storage-Class
X-DynaTrace-JS-Agent
X-ATG-Version
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
X-GEO
X-Backend-TTL
X-ServerID
X-ID
X-Tb
X-Trace-Id
X-RCS-CacheZone
X-Debug-Cache
ServedBy
X-Akamai-Transformed
X-BCube-Filmed-By
X-Correlation-ID
X-Cache-PHP
X-Cache-NGX
HostName
Backend
X-Sucuri-ID
X-Cache-Backend
X-Varnish-Hostname
X-B3-SpanId
DSUID
X-External-Request-Id
X-CS
X-GeoIP-City
BehaviorPad-Version
DB-Nickname
Odigeo-Trace-Id
X-Owner
X-Magnolia-Registration
X-PAYTM-SRV-ID
X-PBS-Appsvrname
X-Generation-Time
X-Origin-TTL
Meta-Geo-Continent
X-NAPM-TraceId
Instruction
Expiry
X-Ms-Request-Id
X-Ms-Version
X-Matched-Rule
X-Location
Fastcgi-X-Cache-Version
X-From
Lfy
X-Fetched-On
DCR-Decision-By
X-Generated-On
X-Origin-CC
X-Level-Front-Cache
DCR-Processing-Time-Ms
Machine
MD5-Digest
Mobile-Detection-Method
X-Session-Fingerprint
X-A-Dgt
X-A-Dcw
X-A-Wwc
X-Aed
X-Application
X-Processor
X-Trv-Group
X-D
X-A
X-Thinkindot-L3
X-A-Ccd
X-ARC
X-Connection-Hash
X-Vtex-Processado-Em
X-CF-Lambda-Fn
X-Vtex-Remote-Cache
X-Cache-NE
Xc-Version
X-VG-WebServer
X-VG-WebCache
X-B-Cookie
X-Vdms-Path
X-Vdms-Version
X-CF-Lambda-Version
X-Destination
X-A-Dam
X-Rewrite-Enabled
X-Rojux
X-SRCache-Key
X-Request-UUID
X-Device-Os
Path
Release
Rendered-Blocks
X-S-Cookie
X-S
X-ScT
X-TA-CDN-Provider
Thinkindot-CacheControl
Thinkindot-Control
T-Server
Thinkindot-CacheControl-Type
SR-User-Adfree
X-Cdn-Forward
Content-Disposition
PB-RID
On-Server
X-Geo-Header
Arc-Version
UCS
PB-PID
X-Cache-Bucket
C-Via
Cf-Device-Type
AKAMAI
X-Core-Value
NGX
Gh-Request-Id
X-Adobe-Source
X-FC-Vary-Parameters
X-Fastly-Cache
Fastly-Backend-Name
Host-ID
X-Bip
X-Cms-Context
X-Azure-Ref-OriginShield
Server-Host
X-Mvc-Supplant-Cachable
X-Tumblr-Pixel-3
X-TrackingId
X-Node-Id
X-JWT-State
X-Is-Gdpr
X-Thanos
X-Skip-Cache
X-Micro-Cache
X-Varnish-Cache-Hits
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Irp-Debug
X-HS-Content-Campaign-Id
X-Has-Esi
X-VServer
X-NewRelic-App-Data
X-B3-Traceid
X-OVcl-Cache
X-OVcl
X-TX-ID
User-Cache-Control
Ssr
X-Envoy-Decorator-Operation
X-Esi-Check
X-DefHash
X-Eu-Site
Platform
X-Developer
Server-Hostname
Server-Ext
X-Request-Host
X-DefElseHash
X-Developers
X-Scheme
X-Reqid
Sever-Int
X-DPWN-IS-SECURE
Wxu-Next-Hostname
X-VarnishDD-TTL
X-Block-Status
X-Clara-WADP
X-Clientip
X-Varnish-Remaining-TTL
X-CGP
X-WADP-Cache
X-Cache-Info
X-Wikidot-Static-Cache
X-Cache-Tags
X-Wikidot-Backend
X-Backend-State
X-Varnish-CookieINHashed-On
PFcat
Wxu-Next-Region
Wxu-Next-Commit
Web-Mar-Node
X-Swa-Ws
X-EC-Lua
X-User
X-Varnish-CookieHashed-On
X-Varnish-Beresp-Grace
X-Csrf-Jwt
X-Variation
V-Age
X-Rebelmouse-Cache-Control
CloudFront-Viewer-Country
X-Li-Fabric
X-IP
CDN-Uid
CDN-RequestId
X-Generated-In
X-Li-Pop
Fastly-SWR
X-Gen-Mode
X-Rebelmouse-Surrogate-Control
X-Generated-By
X-LI-UUID
CDN-RequestCountryCode
CDN-PullZone
X-HN
X-Hnp-Log
X-GeoIP
X-GoCache-CacheStatus
X-Gzip
Cache-Host
CacheControlHeader
CDN-EdgeStorageId
CDN-CachedAt
CDN-Cache
CDCHOST
Ha-Gx-Prefs
Fastly-SIE
L5d-Success-Class
X-Old-Content-Length
X-Platform-Server
X-Origin
Location
X-Origin-Response-Time
X-NU-AKA-ACS-Version
Locid
Magicmarker
X-Policy
X-Fmm-Version
Is-Eu
X-Cache-Id
HA-Ipaddr
X-Nginx-Cache-Key
Adler-Geo
X-Fastly-Backend
Pagetype
X-Ratelimit-Reset
X-Origin-Expires
X-APP-VERSION
X-VG-TLSProxy
X-Dispatcher-Server
X-Varnish-Beresp-Ttl
X-Slack-Backend
X-Sn-Servicetimems
X-Method
X-CUA
X-SIPLIST1
X-Var-Ttl
X-Varnish-Hits
X-Gamma-Serve
X-Varnish-Beresp-Status
X-LB-ID
X-Request-URI
X-Cdn-Origin
Pramga
Rt-Fastcgi-Cache
True-Client-Country-4JS
NM-Fastcgi-Cache
L
X-Kinja-Server-Push
X-Cache-Expires
IsBot
Vix-Hermes-Req-Id
Cf-Bgj
X-Cache-Debug
X-Branch-Name
X-CLOUD-TRACE-CONTEXT
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Fastly-Drupal-HTML
X-Goog-Meta-Goog-Reserved-File-Mtime
Apple-News-Services-Request-Url
X-Cache-Date
X-CACHE-KEY
X-Servername
X-Loc
Origin
X-Hash
Apple-News-Services-Handled
X-Aicache-OS
X-Nc
X-Mvc-Supplant-OutputCached
X-Via-Popn
X-Via-Poph
X-Core-Mission
X-NCache
X-Via-Popv
X-Erf-Stays-Bingo-Pdp-Web
Sid
X-PF-Uncompressing
Who
X-Varnish-Url
Esi-Enabled
X-Request-Start
Country-Code
X-Unique-ID
Pics-Label
X-Refresh
Url
X-Epic-Correlation-Id
X-Esi
X-FireWall-Protection
X-NC
X-Cache-Remote
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
X-Tb-Optimization-Total-Bytes-Saved
X-Dynatrace
Req-Svc-Chain
X-Planisys-CDN-Rules
X-Response-By
X-Varnish-Cacheable
Geo-Info
X-TraceId
X-Webkit-Csp
X-Error
Xkeyi7
S-Rt
X-DC
X-Proxy-Cachei7
X-RateLimit-Limit
Content-Secure-Policy
Cmstype
Cmsid
N-Cache
Source
X-BBXSRF
X-Webkit-CSP-Report-Only
X-B3-Spanid
X-Served-From
X-Srv
Svr
Server-Ttl
HitType
X-Cache-2
Filterid
X-Host-Name
X-Sucuri-Cache
Cross-Origin-Window-Policy
Kp-EeAlive
Cteonnt-Length
Cache-Key
A
VivaBuild
MIME-Version
X-Wa
Viewtype
X-Varnish-Authentication
X-Servedbyhost
Ohc-File-Size
Tcn
X-LiteSpeed-Cache-Control
X-Cc-Via
D-Cc-Upstream
X-Cc-Req-Id
Geoip-Latitude
GeoIp-Country-Code
X-HS-Status
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-URL
X-Svr
X-CDN-Forward
M-TraceId
X-HostName
X-Vcl-Version
X-Oracle-Dms-Rid
TDXMobile
X-Server-IP
Server-ID
Arc-Country
X-Air-Source
Cross-Origin-Opener-Policy
NGB
X-LI-Proto
SID
CACHE
X-Li-Proto
X-API-Version
X-RAMCache
X-Vgn-Hpd-Reason
X-Origin-Time
X-Gdpr
X-Nyt-Route
X-FPC
X-Cache-Config
X-HOST
NtCoent-Length
X-Cs
X-Check-Cacheable
X-VCL-Version
XServer
Hostname
X-VC
Resin-Trace
X-SN
Request-ID
X-UA
X-RPS
X-WA
X-Service
X-Vc
Cache-Provider
X-Webstats-RespID
Server-Id
X-Internal-Host
X-Viewer-Country
X-RSL
X-TIM-N
X-Newrelic-Synthetics
X-DB
X-RPM
X-DI
X-ServedByHost
X-NodeID
X-CCDN-CacheTTL
X-SB
X-CCDN-Origin-Time
X-DSS
X-FORWARDED-FOR
X-DW
X-Hcs-Proxy-Type
X-NGENIX-Cache
X-JoinUs
Ohc-Cache-HIT
X-SaId
GeoIP-Latitude
X-App
X-Geo
GeoIP-Country-Code
X-SD-PageType
Mime-Version
Srv
X-Edge-Location
X-PHP-Backend
X-NGINX-Cache
ProcessTime
X-Via-NSCOPI
X-Render-Time
X-Provided-By
DataCenter
X-Forwarded-Site
FSS-Cache
X-Action
X-BBC-Edge-Cache-Status
CF-Cached-On
X-Dynatrace-Js-Agent
X-TIME
X-FTR-Cache-Host
X-CF-Powered-By
X-Fpc
W
X-Oss-Cdn-Auth
EpKe-Alive
X-Extlb
X-Bc-Bl
X-Ua
X-CSRF-TOKEN
X-Auto-Login
LB
X-PJAX-URL
X-Depends-On
Processtime
X-Proxy-Upstream
X-Region-Sid
X-VC-Cache
X-Req
X-Accel-Expires-Debug
X-Date
X-Worker
Surrogated-Key
X-Cdn-Request-ID
X-HITS
X-MSEdge-Features
X-UnsetCookies
Env
CDN
X-MSEdge-Flight
X-RateLimit-Limit-Second
We-Hiring
Memcached
Mail-Subject
X-RateLimit-Remaining-Second
Upgrade-Insecure-Requests
X-BACKEND-TTL
Proxy-Connection
Datacenter
X-Fastly-Backend-Reqs
X-Ftr-Cache-Host
X-Dw-Trace-Id
Cdn
X-Cluster-Node
X-ZONE
X-Swift-Error
X-Client-Ip
X-CACHE-AGE
X-ABtesting
X-Cache-Tag
PICS-Label
X-IN-APIGATEWAYSSL
X-APP
X-Air-Trace-Id
X-Men
X-Fastly-Request-Id
Dnion-Transfer-Encoding
X-Hello
X-IN-APIGATEWAY
X-Parent-Response-Time
X-Flog
X-BBC-Origin-Response-Status
X-Pf-Uncompressing
X-Akamai-Pragma-Client-IP
X-Oracle-DMS-ECID
X-Presslabs-Stats
X-Pad
X-Zone
Memory
Vha6-Origin
X-Rocket-Build-Number
VNS-Age
VNS-Cache
CPC-Cache
CPC-Age
X-Sigma
X-Sigma-Backend
Media-Length
Time
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-Acquia-Purge-Tags
X-Acquia-Site
X-Via-PopN
X-LiteSpeed-Tag
X-Via-PopV
X-Via-PopH
Epwk-X-Cache
OT-Force-Account-Verify
Cf-Ipcountry
X-Lb-Id
X-Snapshot-Date
WZWS-RAY
X-ND-Cache
X-MiniProfiler-Ids
X-ElasticPress-Search
Xet-Cookie
X-Csrf-Token
X-Ms-Meta-Originalurl
X-Request-URL
X-Akamai-ERRuleID
X-Akamai-ERPolicy
X-Vcache
X-Request-Url
X-ElasticPress-Query
X-Varnish-Beresp-TTL
X-Ms-Meta-Staticbatchstarttime
X-Varnish-URL
X-Tx-Id
CountryCode
X-Amz-Meta-Cb-Modifiedtime
State
X-C
X-Litespeed-Cache-Control
Fastcgi-Cache-TTL
Content-Style-Type
NnCoection
Content-Script-Type
X-Traceid
Environment
X-ServerName
X-Debug-Cache-Fetch
Ohc-Response-Time
X-Storefront-Renderer-Verified
Phost
X-Debug-Cache-Store
X-Redis-Count
X-B3-Parentspanid
URI
Inserted-Into-Cache-At
X-Redis-Duration-Ms
X-Tid