Threat Level: green Handler on Duty: Renato Marinho

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
X-XSS-Protection
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-Served-By
X-UA-Compatible
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Xss-Protection
X-Request-ID
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Ua-Compatible
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Content-Encoding
X-CDN
X-AspNetMvc-Version
Feature-Policy
X-Envoy-Upstream-Service-Time
Status
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-Via
Upgrade
Access-Control-Max-Age
Keep-Alive
X-Ws-Request-Id
X-Age
X-AH-Environment
X-Robots-Tag
X-Turbo-Charged-By
Request-Context
X-Proxy-Cache
EagleId
X-Cache-Group
Server-Timing
X-Backend
X-Hacker
X-Server
Report-To
Host-Header
X-Amz-Request-Id
X-Server-Powered-By
X-Amz-Id-2
Grace
X-Nginx-Cache-Status
X-UA-Device
X-Rq
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
X-LiteSpeed-Cache
X-Page-Speed
Cf-Railgun
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
X-Cache-Spec
X-Amz-Version-Id
NEL
X-Device
X-CST
Allow
Xkey
X-Vhost
X-Host
X-Backend-Server
X-WebKit-CSP
X-Server-Id
EagleEye-TraceId
Request-Id
Surrogate-Control
X-Dispatcher
X-Node
Content-Location
X-Response-Time
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Akam-SW-Version
X-Ruxit-JS-Agent
P3p
X-ASPNET-VERSION
Accept-CH
X-Ac
X-Application-Context
X-Cache-Lookup
X-Country
X-Template
X-Language
Accept-CH-Lifetime
Accept-Ch
X-Mod-Pagespeed
X-Readtime
Accept-Ch-Lifetime
X-Cloud-Trace-Context
MS-Author-Via
X-B3-TraceId
Rating
X-Origin-Cache
X-MS-InvokeApp
X-HW
X-Cnection
X-Url
X-PC
X-Vname
X-TtlSet
X-Clacks-Overhead
Edge-Control
X-GitHub-Request-Id
X-ESI
X-ORACLE-DMS-ECID
X-Trace
Response
Display
X-Content-Type
Pagespeed
X-Sol
X-Middleton-Display
X-Middleton-Response
X-D2id
X-ORACLE-DMS-RID
Arr-Disable-Session-Affinity
X-Use-Magma
X-GoogleNews-Bot
X-Exp-Id
X-Exp-Variant
X-Kinja
X-Cdn-Fetch
X-Kinja-Revision
X-Kinja-Build
X-Kinja-Server
Verso
X-Vcap-Request-Id
X-Goog-Hash
X-Rack-Cache
X-Country-Code
X-Buckets
X-FastCGI-Cache
X-Varnish-TTL
X-Server-Name
X-Navigation-Version
Service-Worker-Allowed
X-Powered-By-Plesk
X-VARITI-CCR
X-Amz-Rid
X-Abt-Application-Version
X-Fastly-Request-ID
X-Webkit-CSP
X-TTL
X-Client-IP
X-Cache-TTL
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
Fastly-Restarts
X-Release
X-SharePointHealthScore
SPRequestGuid
X-MSEdge-Ref
X-Cached
X-Dw-Request-Base-Id
X-Element-Page-Cache
SPIisLatency
SPRequestDuration
X-Oneagent-Js-Injection
X-NF-Request-ID
Public-Key-Pins
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
RTSS
Access-Control-Request-Method
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Ar-Sid
AR-Request-ID
AR-CACHE
AR-ATIME
AR-PoweredBy
X-Edge
X-LLID
X-Powered-CMS
X-Ezoic-Cdn
X-Litespeed-Cache
X-Origin-Upstream-Status
Cache-Tag
Content-MD5
X-Upstream
X-Px
Fusion-Content-Source
Fusion-Template-Id
Fusion-Content-Id
Fusion-Deployment-Id
Fusion-Source
Fusion-Component-Id
X-Jurisdiction
X-HP-Webp
S
X-Mid
X-ECACHE
X-Version
X-MCACHE
X-Recruiting
X-Mg-S
Charset
X-Content-Digest
X-PressLabs-Stats
X-Ttl
X-Amz-Server-Side-Encryption
Fastcgi-Cache
X-Kinsta-Cache
X-T
Cache-Tags
MicrosoftSharePointTeamServices
X-Id
Front-End-Https
Filters
X-Content-Security-Policy-Report-Only
X-DynaTrace
X-Logged-In
X-Debug
Edge-Cache-Tag
Server-Node
X-Accel-Expires
X-Grace
X-Forwarded-Proto
X-Correlation-Id
X-Forwarded-For
TCN
TP-Cache
TP-L2-Cache
Server-Name
Nginx-Cache
X-Pinterest-Direct
X-Amzn-Trace-Id
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Surrogate-Key
X-Request-Received
X-Request-Processing-Time
X-XRDS-LOCATION
X-Varnish-Age
X-Yandex-Sdch-Disable
X-Shield-Request-Id
X-B3-Sampled
X-Ser
X-Microsite
X-Request-Handler-Origin-Region
X-Hits
X-Az
X-AppVersion
X-Activity-Id
X-Ruxit-Js-Agent
X-Amz-Replication-Status
X-F-Cache
X-Fastcgi-Cache
X-HS-Cache-Config
X-DIS-Request-ID
X-HS-Hub-Id
X-HS-Combine-CSS
X-HS-Content-Id
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Generation
X-Goog-Storage-Class
X-Origin-Server
Accept-Charset
X-Geo-Country
X-Git-Hash
Alternate-Protocol
Nel
X-XRDS-Location
X-Respond-Thread
Cache
X-Rid
X-Time
X-FTR-Request-ID
X-Frontend
Section-Io-Cache
X-LB-Cache
X-Upgrade-Enabled
Host
X-Cache-Key
X-DataDome
Access-Control-Allow-Method
Powered-By-ChinaCache
X-Mobile-URL
X-Seen-By
X-NWS-LOG-UUID
X-Server-ID
MS-CV
X-Cache-Age
X-VCache
Paypal-Debug-Id
X-TT
Healthy
X-IPLB-Instance
X-AOL-HN
X-Whom
ServerID
X-Content-Options
X-Varnish-Backend
X-Type
X-Hostname
Cleartype
X-Flags
X-Providence-Cookie
X-Route-Name
X-Aspnet-Duration-Ms
X-Request-Guid
X-Is-Crawler
Payment
X-App-Environment
X-Signature
X-B-Cache
X-Cache-Action
X-Page-Id
X-Source
X-Jobs
Fastcgi-Useragent
X-Debug-Info
X-WebKit-CSP-Report-Only
X-Load-Cache
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Daa-Tunnel
X-N
X-Mobile
X-FB-Debug
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Erf-Bev-Bev
X-Via-JSL
X-RateLimit-Remaining
Realpath
X-Contextid
Refresh
Version
X-Rule
X-Akamai-Edgescape
X-Response-Served-From
X-Accel-Buffering
X-Wix-Request-Id
Node
X-Drupal-Cache-Tags
X-Cached-By
X-Original-Request-Id
X-RTag
X-Cacheable-TTL
X-Zen-Fury
X-Proxy
DC
X-Framework
Ms-Operation-Id
X-RemovedCookies
X-Cache-Operation
X-ProcessESI
Viewport
X-Cache-Rule
X-HTML-Minification-Powered-By
X-Cache-Time
X-B
X-Distributor
Referer-Policy
X-Instance
X-Real-IP
Access-Control-Request-Headers
X-Region
X-Drupal-Cache-Contexts
X-Page-View
X-UUID
Eomportal-Instance
X-Cache-Expired-At
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Cluster-Name
X-FW-Static
VIX-Pulpo-Upstream-Status
X-FW-Type
X-FW-Server
X-Content-Powered-By
X-Cache-Control
X-FW-Serve
X-FW-Hash
X-FW-Dynamic
X-Yottaa-Optimizations
Liferay-Portal
Countrycode
VIX-Pulpo-Node
X-Yottaa-Metrics
X-G
X-IPS-LoggedIn
X-Cache-Hit
X-Environment-Context
DynaTrace
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Tumblr-User
X-L-Path
X-FireWall-Port
X-Pass-Why
Server-Info
X-App-Server
X-Varnish-Ttl
X-User-Agent
X-Ratelimit-Limit
GEO-INFO
Ec-Rule-Version
Xserver
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
X-Protected-By
Webserver
Section-Io-Id
X-Tumblr-Pixel-2
Section-Origin-Responded
CF-IPCountry
From-Origin
X-Node-Name
SRV
X-Www-Served-By
X-Ratelimit-Remaining
Protected
X-Nginx-Cache
X-Cache-Server
X-RN-RSRV
X-Endurance-Cache-Level
Meta-Geo
X-ES-SERVER
X-UPSTREAM-Address
X-Handled-By
X-Mode
X-Backend-Name
X-Hl-Ver
Cache-Tv-Group
X-Debug-IsPreview
X-Debug-IsConnected
X-FB-TRIP-ID
X-Uri
X-Site-Version
X-Locale
Frame-Options
X-Device-Type
X-Soup
X-Web-Node
X-NYM-Debug-Backend
X-Storage
X-PHP-Host
X-MP-GENERATED-AT
X-UA-Device-Type
X-Labrador-Cache-Channel
Cache-Status
X-Be
X-Adobe-Loc
X-Adobe-Content
X-Varnishpool
Country
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-GeoIP-Country
Decoy-Debug-Key
Cache-Name
Decoy-Debug-TTL
TWC-Device-Class
TWC-Connection-Speed
Property-Id
TWC-Privacy
Fastly-SSL
Decoy-Debug-Status
Selected-Fe
Webcakes-App-Name
X-BYPASS-REASON
X-Proto
X-PCL
X-Timing-Wait
X-Human
Webcakes-App-Version
X-Origin-Hint
X-Origin-Date
X-Sql-Count
X-Sql-Duration-Ms
X-No-Session
X-OCL
X-Via-Fastly
X-ProxyCache-Key
X-Proxy-Build
X-WA-Info
X-Redis-Cache
Webcakes-Region
X-ProxyCache-Status
X-Pubstack
X-Request-Time
X-Hyper-Cache
X-Say-Cacheable
X-Loop
X-R9-Blue-Green-Version
X-Say-TTL
X-FW-Version
Azure-Version
X-Forwarded-Host
Azure-RegionName
Azure-SiteName
X-Format
Azure-SlotName
X-VWS-Id
Azure-InstanceId
X-LAGOON
X-Section
X-Access
X-Hosted-By
X-AIR-PT
Retry-After
X-TNCMS
X-SayCDN-TTL
X-Server-W
X-LJ-Flow-ID
X-S-Maxage
X-Cache-Grace
X-AWS-Id
X-Revision
X-Status
X-Cache-TTL-Remaining
X-Xfnlog-Site
X-PERF
X-Alternate-Cache-Key
X-Storefront-Renderer-Rendered
X-Webkit-Csp
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-ShardId
X-ApacheServer
X-ShopId
X-Cluster
X-Shopify-Stage
X-CCM
X-TT-LOGID
Mn-Server-Ip
X-Zipkin-Id
X-Proxied
X-Routing-Service
X-Is-Bot
X-Varnish-Grace
X-SRV
X-Rendered-As
Apigw-Requestid
X-Qloud-Router
AMP-Access-Control-Allow-Source-Origin
X-Amz-Meta-S3cmd-Attrs
X-Dc
X-Varnish-Server
X-Info
S-Cnection
X-FTR-Cache-Status
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Backend
X-FTR-Balancer
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
X-FTR-Realm
X-Via-CDN
X-FTR-DC
X-Cdn
Cache-Hits
X-GG-Cache-Date
X-Cache-Enabled
X-Microcachable
X-Content-Age
X-Detected-As
X-Cache-Host
X-FTR-Expires
X-Platform
X-Proxy-Cache-Status
Uber-Trace-Id
X-Aspnetmvc-Version
X-Azure-Ref
X-EdgeConnect-Cache-Status
X-Amz-Apigw-Id
X-Amzn-Remapped-Content-Length
X-Amzn-RequestId
X-CSRF-Token
X-Backend-Host
Tracecode
X-Air-Hostname
X-NWS-UUID-VERIFY
X-Cache-Var-Map
X-TA-CDN-Provider
SD-X-WS
X-Cache-Var
X-App-Version
Amp-Access-Control-Allow-Source-Origin
Akamai-GRN
X-Time-Microsecs
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Oss-Storage-Class
X-Oss-Server-Time
X-Oss-Request-Id
X-ATG-Version
X-DynaTrace-JS-Agent
X-Backend-TTL
HostName
X-ServerID
X-Unique-Id
X-Tb
X-Trace-Id
X-BCube-Filmed-By
X-RCS-CacheZone
X-Correlation-ID
X-Debug-Cache
ServedBy
X-GEO
X-Varnish-Hostname
Backend
X-Cdn-Forward
X-Cache-PHP
X-Cache-NGX
X-B3-SpanId
X-Cache-Backend
DSUID
X-Sucuri-ID
X-Akamai-Transformed
X-Origin-TTL
BehaviorPad-Version
X-From
DB-Nickname
X-GeoIP-City
X-Magnolia-Registration
X-Processor
X-Fetched-On
Path
X-TX-ID
X-PAYTM-SRV-ID
X-PBS-Appsvrname
X-Owner
DCR-Decision-By
X-Generated-On
X-Generation-Time
X-Level-Front-Cache
X-Ms-Request-Id
X-Ms-Version
Expiry
X-NAPM-TraceId
X-Vtex-Remote-Cache
Instruction
Machine
Mobile-Detection-Method
Fastcgi-X-Cache-Version
Odigeo-Trace-Id
X-Origin-CC
Meta-Geo-Continent
X-CF-Lambda-Fn
MD5-Digest
DCR-Processing-Time-Ms
X-Location
X-VG-WebServer
X-A-Ccd
X-Connection-Hash
X-Session-Fingerprint
X-A-Dam
X-A
X-Device-Os
X-Vdms-Version
X-B-Cookie
X-ScT
X-Vdms-Path
X-A-Dcw
X-A-Dgt
X-ARC
X-D
X-Trv-Group
X-Thinkindot-L3
X-Application
X-Destination
X-A-Wwc
X-Aed
X-SRCache-Key
X-S-Cookie
Thinkindot-Control
X-Vtex-Processado-Em
Xc-Version
SR-User-Adfree
X-External-Request-Id
X-VG-WebCache
X-CF-Lambda-Version
Rendered-Blocks
Release
Thinkindot-CacheControl
T-Server
X-Rojux
X-Cache-NE
X-S
X-Rewrite-Enabled
X-CS
X-Request-UUID
Thinkindot-CacheControl-Type
X-CACHE-KEY
X-Bip
Arc-Version
C-Via
Content-Disposition
X-Cache-Bucket
X-Cms-Context
Cf-Device-Type
X-Core-Value
X-GeoIP
CacheControlHeader
Host-ID
Server-Host
Pagetype
On-Server
X-Has-Esi
PB-PID
X-FC-Vary-Parameters
PB-RID
NGX
UCS
X-Geo-Header
Fastly-Backend-Name
Gh-Request-Id
X-Adobe-Source
Lfy
X-Fastly-Cache
X-Azure-Ref-OriginShield
X-Is-Gdpr
X-Varnish-Cache-Hits
X-OVcl
X-OVcl-Cache
X-Node-Id
X-Mvc-Supplant-Cachable
X-JWT-State
X-Matched-Rule
X-Micro-Cache
X-VServer
X-Reqid
X-Thanos
X-TrackingId
X-Tumblr-Pixel-3
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-B3-Traceid
X-Skip-Cache
X-Irp-Debug
X-NewRelic-App-Data
AKAMAI
X-HS-Content-Campaign-Id
User-Cache-Control
Wxu-Next-Commit
Web-Mar-Node
X-Developers
Wxu-Next-Hostname
Wxu-Next-Region
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Developer
V-Age
CDN-Cache
X-VarnishDD-TTL
Sever-Int
X-Envoy-Decorator-Operation
X-IP
Server-Hostname
CDN-EdgeStorageId
CDN-CachedAt
Ssr
X-Varnish-CookieHashed-On
X-DPWN-IS-SECURE
X-Scheme
X-Request-Host
X-Dispatcher-Server
X-DefHash
X-Clara-WADP
X-Clientip
X-Var-Ttl
X-EC-Lua
X-Variation
X-Cache-Id
X-CGP
X-Cache-Tags
X-Varnish-Beresp-Grace
X-Cache-Info
X-Branch-Name
X-Block-Status
Cache-Host
X-DefElseHash
X-Swa-Ws
Server-Ext
X-Hnp-Log
X-Backend-State
X-User
X-Csrf-Jwt
X-CUA
X-HN
CDCHOST
X-Esi-Check
Magicmarker
X-NU-AKA-ACS-Version
Locid
Location
X-Old-Content-Length
Fastly-SIE
X-Wikidot-Static-Cache
X-Gen-Mode
X-Origin
X-Eu-Site
CDN-Uid
L5d-Success-Class
Ha-Gx-Prefs
Adler-Geo
CloudFront-Viewer-Country
Fastly-SWR
HA-Ipaddr
X-Nginx-Cache-Key
X-Generated-By
X-Generated-In
Is-Eu
X-Gzip
X-LI-UUID
X-Li-Pop
Platform
X-GoCache-CacheStatus
X-WADP-Cache
PFcat
X-Ratelimit-Reset
X-Fastly-Backend
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
CDN-PullZone
X-Platform-Server
X-Policy
X-Origin-Response-Time
NM-Fastcgi-Cache
X-Origin-Expires
X-Li-Fabric
X-Fmm-Version
CDN-RequestId
CDN-RequestCountryCode
X-Wikidot-Backend
X-APP-VERSION
X-ID
X-LB-ID
X-Varnish-Beresp-Status
X-Method
X-Slack-Backend
X-VG-TLSProxy
X-Request-URI
X-Hash
X-Gamma-Serve
X-Varnish-Hits
X-Sn-Servicetimems
X-SIPLIST1
X-Varnish-Beresp-Ttl
X-Cache-Expires
Rt-Fastcgi-Cache
IsBot
Cf-Bgj
Vix-Hermes-Req-Id
True-Client-Country-4JS
L
X-Kinja-Server-Push
Pramga
X-Cache-Debug
X-Cdn-Origin
X-CLOUD-TRACE-CONTEXT
X-Aicache-OS
Apple-News-Services-Handled
Apple-News-Services-Parsed-Url
Fastly-Drupal-HTML
Apple-News-Services-Host
X-Loc
X-Goog-Meta-Goog-Reserved-File-Mtime
Sid
Origin
X-Cache-Date
Apple-News-Services-Request-Url
X-Nc
X-Mvc-Supplant-OutputCached
X-Via-Popn
Esi-Enabled
X-Via-Poph
X-Unique-ID
X-PF-Uncompressing
X-Servername
X-NCache
X-Via-Popv
X-Core-Mission
X-Erf-Stays-Bingo-Pdp-Web
Who
X-Varnish-Url
X-Request-Start
X-Refresh
Country-Code
Geo-Info
Pics-Label
Url
X-Tb-Optimization-Total-Bytes-Saved
X-Epic-Correlation-Id
X-FireWall-Protection
X-Cache-Remote
X-NC
X-Varnish-Cacheable
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Response-By
Req-Svc-Chain
X-Planisys-CDN-Cache
X-Dynatrace
Tcn
X-TraceId
X-Error
Xkeyi7
X-Proxy-Cachei7
X-RateLimit-Limit
S-Rt
Cmstype
X-BBXSRF
Cmsid
N-Cache
Content-Secure-Policy
Source
X-B3-Spanid
X-Webkit-CSP-Report-Only
Filterid
X-Host-Name
GeoIp-Country-Code
X-HS-Status
X-Cache-2
X-DC
HitType
X-Srv
X-Served-From
Server-Ttl
Geoip-Latitude
Kp-EeAlive
Svr
X-Sucuri-Cache
Cross-Origin-Window-Policy
X-Vcl-Version
Cache-Key
X-Contensis-Viewer-Groups
A
X-Cache-ASPX
X-Varnish-Authentication
Ohc-File-Size
Cteonnt-Length
Viewtype
D-Cc-Upstream
X-Cc-Via
X-Cc-Req-Id
MIME-Version
VivaBuild
X-LiteSpeed-Cache-Control
X-URL
X-Servedbyhost
M-TraceId
X-Wa
X-Svr
X-HostName
X-Oracle-Dms-Rid
Cross-Origin-Opener-Policy
X-Server-IP
NGB
TDXMobile
Server-ID
X-Li-Proto
X-Esi
X-Air-Source
Arc-Country
X-CDN-Forward
CACHE
NtCoent-Length
X-Cache-Config
X-Vgn-Hpd-Reason
X-LI-Proto
X-Gdpr
X-FPC
X-RAMCache
X-Origin-Time
X-API-Version
X-Nyt-Route
X-HOST
X-Cs
Resin-Trace
X-VC
SID
Request-ID
X-Vc
X-WA
X-ServedByHost
X-SN
X-Check-Cacheable
X-UA
X-Geo
X-NodeID
X-Webstats-RespID
X-Newrelic-Synthetics
X-Viewer-Country
Cache-Provider
X-Internal-Host
X-Service
X-RSL
X-RPS
X-CCDN-CacheTTL
X-CCDN-Origin-Time
Server-Id
X-TIM-N
X-Hcs-Proxy-Type
X-RPM
X-DW
X-DSS
X-DI
X-DB
X-VCL-Version
X-SB
X-JoinUs
X-NGENIX-Cache
X-PHP-Backend
X-SaId
DataCenter
Hostname
Ohc-Cache-HIT
Srv
X-Edge-Location
Mime-Version
GeoIP-Country-Code
GeoIP-Latitude
X-SD-PageType
XServer
X-NGINX-Cache
X-Via-NSCOPI
X-Action
X-App
X-BBC-Edge-Cache-Status
ProcessTime
X-Render-Time
X-Extlb
X-Forwarded-Site
FSS-Cache
X-FTR-Cache-Host
CF-Cached-On
X-Fpc
EpKe-Alive
X-CF-Powered-By
X-Oss-Cdn-Auth
X-Ua
X-Provided-By
X-Dynatrace-Js-Agent
X-Bc-Bl
X-Req
Mail-Subject
Upgrade-Insecure-Requests
X-Worker
W
Processtime
X-VC-Cache
X-FORWARDED-FOR
Surrogated-Key
LB
Memcached
X-Date
X-Accel-Expires-Debug
X-Depends-On
X-PJAX-URL
X-Auto-Login
X-Region-Sid
X-Proxy-Upstream
We-Hiring
X-Cdn-Request-ID
X-HITS
X-Swift-Error
CDN
X-APP
X-Fastly-Backend-Reqs
X-BACKEND-TTL
X-TIME
Env
Proxy-Connection
Cdn
X-MSEdge-Features
X-Cluster-Node
X-ZONE
X-CSRF-TOKEN
X-UnsetCookies
X-Dw-Trace-Id
X-Ftr-Cache-Host
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-MSEdge-Flight
X-CACHE-AGE
X-Client-Ip
X-Men
X-ABtesting
Datacenter
X-Air-Trace-Id
X-Sigma
Dnion-Transfer-Encoding
Time
X-BBC-Origin-Response-Status
X-Cache-Tag
X-Rocket-Build-Number
PICS-Label
Memory
X-Sigma-Backend
X-Flog
X-IN-APIGATEWAYSSL
X-Hello
X-Fastly-Request-Id
X-Parent-Response-Time
X-IN-APIGATEWAY
X-Akamai-Pragma-Client-IP
X-Acquia-Purge-Tags
Media-Length
X-Acquia-Application-UUID
X-Acquia-Application-Trace
Vha6-Origin
VNS-Cache
VNS-Age
X-Oracle-DMS-ECID
CPC-Age
X-Acquia-Site
CPC-Cache
X-Pad
X-Pf-Uncompressing
X-Zone
X-Presslabs-Stats
OT-Force-Account-Verify
X-LiteSpeed-Tag
X-Via-PopH
Epwk-X-Cache
X-Via-PopN
X-Via-PopV
Cf-Ipcountry
X-ElasticPress-Search
X-Akamai-ERPolicy
X-Csrf-Token
X-Request-Url
X-ServerName
X-ND-Cache
X-Vcache
X-Akamai-ERRuleID
X-MiniProfiler-Ids
X-Ms-Meta-Originalurl
Xet-Cookie
X-ElasticPress-Query
X-Lb-Id
WZWS-RAY
X-Ms-Meta-Staticbatchstarttime
X-Request-URL
X-Snapshot-Date
X-Varnish-Beresp-TTL
X-Varnish-URL
CountryCode
My-App
State
Content-Style-Type
X-Litespeed-Cache-Control
Content-Script-Type
X-Amz-Meta-Cb-Modifiedtime
Fastcgi-Cache-TTL
X-Debug-Cache-Fetch
Ohc-Response-Time
URI
X-Traceid
Phost
X-B3-Parentspanid
NnCoection
X-Redis-Duration-Ms
X-Redis-Count
X-C
Inserted-Into-Cache-At
X-Debug-Cache-Store
X-Storefront-Renderer-Verified
Environment
X-Tid