Threat Level: green Handler on Duty: Renato Marinho

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-RAY
CF-Cache-Status
Accept-Ranges
Link
X-XSS-Protection
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
P3P
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-UA-Compatible
X-Served-By
X-Timer
X-Request-Id
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Xss-Protection
Access-Control-Allow-Credentials
X-Runtime
X-AspNet-Version
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Content-Security-Policy
X-Ua-Compatible
X-Iinfo
Content-Encoding
X-CDN
X-Request-ID
Feature-Policy
X-AspNetMvc-Version
Status
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Upgrade
Access-Control-Max-Age
X-Via
Keep-Alive
X-Ws-Request-Id
X-AH-Environment
X-Age
X-Robots-Tag
Request-Context
X-Turbo-Charged-By
EagleId
X-Proxy-Cache
Server-Timing
X-Server
X-Cache-Group
X-Backend
X-Hacker
Host-Header
X-Server-Powered-By
Report-To
X-Amz-Request-Id
X-Nginx-Cache-Status
Grace
X-Amz-Id-2
X-UA-Device
X-Dns-Prefetch-Control
X-Rq
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Page-Speed
X-OneAgent-JS-Injection
Cf-Railgun
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-CST
X-Amz-Version-Id
NEL
X-Cache-Spec
Allow
X-Vhost
X-Host
X-Backend-Server
X-WebKit-CSP
X-ASPNET-VERSION
X-Server-Id
X-Dispatcher
Surrogate-Control
X-Node
EagleEye-TraceId
Xkey
Request-Id
X-Response-Time
Content-Location
X-Akam-SW-Version
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Accept-CH
X-Ruxit-JS-Agent
P3p
X-Cache-Lookup
X-Application-Context
X-Country
X-Ac
Accept-CH-Lifetime
X-Mod-Pagespeed
X-Cloud-Trace-Context
X-Readtime
X-Template
X-Language
X-B3-TraceId
MS-Author-Via
X-HW
Rating
Accept-Ch-Lifetime
X-Url
X-Cnection
X-MS-InvokeApp
Accept-Ch
X-Origin-Cache
X-PC
X-Vname
X-TtlSet
Edge-Control
X-Clacks-Overhead
X-ESI
X-GitHub-Request-Id
X-Trace
X-Varnish-TTL
X-D2id
X-Middleton-Display
Display
Response
Pagespeed
X-Middleton-Response
X-Sol
X-Content-Type
Verso
Arr-Disable-Session-Affinity
X-Cdn-Fetch
X-Exp-Variant
X-Kinja-Server
X-Kinja-Build
X-Kinja
X-GoogleNews-Bot
X-Kinja-Revision
X-Use-Magma
X-Exp-Id
X-Powered-By-Plesk
X-Vcap-Request-Id
X-Country-Code
X-Goog-Hash
X-Rack-Cache
X-ORACLE-DMS-RID
X-FastCGI-Cache
X-Webkit-CSP
X-ORACLE-DMS-ECID
X-VARITI-CCR
X-Navigation-Version
X-Server-Name
X-Abt-Application-Version
X-Amz-Rid
Service-Worker-Allowed
X-TTL
Fastly-Restarts
X-Fastly-Request-ID
X-Client-IP
X-Cached
X-Buckets
X-MSEdge-Ref
X-Release
X-Cache-TTL
X-Element-Page-Cache
Cache-Tag
X-Dw-Request-Base-Id
X-NF-Request-ID
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
Access-Control-Request-Method
Public-Key-Pins
X-SharePointHealthScore
SPRequestGuid
RTSS
SPIisLatency
SPRequestDuration
AR-Request-ID
AR-CACHE
AR-ATIME
Ar-Sid
AR-PoweredBy
X-Edge
X-Ezoic-Cdn
X-Powered-CMS
X-LLID
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
X-Upstream
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Version
S
Content-MD5
X-HP-Webp
X-Jurisdiction
X-Recruiting
X-Mid
X-Oneagent-Js-Injection
X-Kinsta-Cache
X-ECACHE
X-MCACHE
Charset
X-Mg-S
X-Ttl
X-PressLabs-Stats
X-Origin-Upstream-Status
X-DynaTrace
X-T
Cache-Tags
X-Content-Digest
X-Accel-Expires
Fusion-Source
Fusion-Content-Id
Fusion-Component-Id
Fusion-Content-Source
Fusion-Deployment-Id
Fusion-Template-Id
X-Forwarded-Proto
Fastcgi-Cache
X-Litespeed-Cache
X-Px
X-Id
X-Content-Security-Policy-Report-Only
X-Logged-In
Filters
TP-L2-Cache
TP-Cache
Server-Node
Edge-Cache-Tag
Server-Name
TCN
X-Correlation-Id
X-Ruxit-Js-Agent
X-Amz-Server-Side-Encryption
Front-End-Https
X-Forwarded-For
MicrosoftSharePointTeamServices
X-Request-Processing-Time
X-Request-Received
Nginx-Cache
X-Grace
X-Shield-Request-Id
X-B3-Sampled
X-Hits
X-Amzn-Trace-Id
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Alternate-Protocol
X-Request-Handler-Origin-Region
X-Server-ID
X-Microsite
X-Az
X-Activity-Id
X-AppVersion
X-F-Cache
X-NWS-LOG-UUID
X-XRDS-Location
X-Varnish-Age
X-HS-Hub-Id
X-Amz-Replication-Status
X-HS-Cache-Config
X-HS-Combine-CSS
X-HS-Content-Id
X-Fastcgi-Cache
X-Debug
X-Origin-Server
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Frontend
X-Rid
X-Yandex-Sdch-Disable
Nel
Surrogate-Key
Host
X-Geo-Country
X-Cache-Age
X-RateLimit-Remaining
Section-Io-Cache
X-DIS-Request-ID
X-Daa-Tunnel
X-XRDS-LOCATION
Accept-Charset
X-Hostname
Realpath
X-Ser
X-Git-Hash
X-VCache
Access-Control-Allow-Method
X-Source
X-Respond-Thread
X-Mobile-URL
MS-CV
X-Seen-By
X-Upgrade-Enabled
X-Type
X-AOL-HN
Cleartype
X-DataDome
Paypal-Debug-Id
ServerID
X-Time
X-LB-Cache
Payment
Healthy
X-Contextid
X-Varnish-Backend
X-IPLB-Instance
X-TT
X-Signature
X-Content-Options
X-B-Cache
X-Debug-Info
X-Cache-Action
X-Providence-Cookie
X-Is-Crawler
X-Flags
X-Request-Guid
X-Route-Name
X-Aspnet-Duration-Ms
X-Whom
X-Cache-Key
X-WebKit-CSP-Report-Only
X-App-Environment
X-Page-Id
X-Load-Cache
Fastcgi-Useragent
X-N
X-FB-Debug
Cache
X-Jobs
Node
X-Webkit-Csp
X-Rule
X-Mobile
X-Cache-Expired-At
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
Refresh
X-Erf-Bev-Bev-Is-Generated
X-FTR-Request-ID
X-Erf-Bev-Bev
X-Browser-Type
X-Response-Served-From
Viewport
X-Wix-Request-Id
X-Original-Request-Id
X-FireWall-Port
X-Accel-Buffering
DC
X-RTag
Ms-Operation-Id
Access-Control-Request-Headers
X-Cluster-Name
X-Content-Powered-By
X-Cacheable-TTL
X-Framework
X-HTML-Minification-Powered-By
X-Drupal-Cache-Tags
X-Debug-IsConnected
X-Debug-IsPreview
X-Zen-Fury
X-Distributor
X-Real-IP
X-B
X-Instance
X-ProcessESI
Referer-Policy
X-RemovedCookies
X-IPS-LoggedIn
X-UUID
Eomportal-Instance
X-Cache-Control
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
Version
X-Region
X-Cache-Time
X-Tt-Trace-Tag
X-Proxy
X-Tt-Trace-Host
X-Page-View
Countrycode
X-Drupal-Cache-Contexts
X-Www-Served-By
X-FW-Static
X-FW-Serve
X-FW-Server
X-FW-Hash
X-FW-Type
X-FW-Dynamic
X-App-Server
X-Nginx-Cache
X-Protected-By
X-G
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Tumblr-Pixel
Xserver
X-Cached-By
X-Cache-Rule
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Cache-Operation
Liferay-Portal
X-Via-JSL
X-Akamai-Edgescape
Powered-By-ChinaCache
X-Environment-Context
X-Pinterest-Direct
X-L-Path
X-Cache-Hit
X-Pass-Why
SRV
Section-Io-Id
X-Varnish-Grace
Section-Io-Origin-Status
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
X-Device-Type
CF-IPCountry
GEO-INFO
Server-Info
X-TA-CDN-Provider
DynaTrace
X-User-Agent
X-Varnish-Server
X-Adobe-Loc
X-Adobe-Content
Cache-Status
Retry-After
X-Mode
Frame-Options
From-Origin
Ec-Rule-Version
X-Tumblr-Pixel-2
X-RN-RSRV
X-Endurance-Cache-Level
X-Hl-Ver
X-ES-SERVER
Webserver
Meta-Geo
X-UPSTREAM-Address
X-Handled-By
X-Backend-Name
Cache-Tv-Group
X-FB-TRIP-ID
X-TEC-API-ROOT
X-Varnishpool
X-TEC-API-VERSION
X-TEC-API-ORIGIN
TWC-Privacy
X-Pubstack
X-Cache-Server
Property-Id
Webcakes-App-Name
X-ProxyCache-Key
TWC-Device-Class
X-OCL
X-NYM-Debug-Backend
Fastly-SSL
X-MP-GENERATED-AT
X-Origin-Hint
X-PCL
TWC-Locale-Group
Apigw-Requestid
TWC-GeoIP-LatLong
TWC-GeoIP-Country
X-ProxyCache-Status
Webcakes-App-Version
X-Format
X-Access
X-Be
X-Storage
X-Soup
X-Section
Country
X-Request-Time
TWC-Connection-Speed
X-Uri
X-BYPASS-REASON
Webcakes-Region
X-Server-W
X-Origin-Date
X-PERF
X-PHP-Host
X-WA-Info
X-S-Maxage
Decoy-Debug-TTL
Decoy-Debug-Status
Decoy-Debug-Key
Selected-Fe
X-Proxy-Cache-Status
Cache-Name
X-LJ-Flow-ID
X-No-Session
Uber-Trace-Id
X-Via-Fastly
X-VWS-Id
X-Proxy-Build
X-ApacheServer
X-AWS-Id
X-UA-Device-Type
Mn-Server-Ip
X-R9-Blue-Green-Version
X-Human
X-Labrador-Cache-Channel
X-Info
X-Proto
X-Timing-Wait
Azure-InstanceId
Azure-Version
X-GG-Cache-Date
Azure-RegionName
X-Cache-TTL-Remaining
Azure-SiteName
Azure-SlotName
Protected
X-LAGOON
X-TNCMS
X-SayCDN-TTL
X-Xfnlog-Site
X-Zipkin-Id
X-Sql-Duration-Ms
X-Loop
X-Ratelimit-Limit
X-Web-Node
X-Say-Cacheable
X-Routing-Service
X-Proxied
X-Say-TTL
X-Sql-Count
X-Alternate-Cache-Key
X-ShardId
X-Hyper-Cache
X-Storefront-Renderer-Rendered
X-ShopId
X-Hosted-By
X-Status
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Shopify-Stage
X-Redis-Cache
X-Locale
X-NWS-UUID-VERIFY
X-Cache-Enabled
X-Content-Age
X-FW-Version
X-Site-Version
X-Backend-Host
X-Is-Bot
X-Microcachable
X-Rendered-As
Amp-Access-Control-Allow-Source-Origin
X-Azure-Ref
X-Cluster
S-Cnection
X-Cache-Grace
X-AIR-PT
X-Forwarded-Host
X-SRV
X-TT-LOGID
AMP-Access-Control-Allow-Source-Origin
X-Platform
X-Qloud-Router
X-Dc
X-CSRF-Token
X-App-Version
X-Trace-Id
X-Varnish-Ttl
Akamai-GRN
X-Revision
ServedBy
X-Aspnetmvc-Version
X-Via-CDN
X-Cache-NGX
X-Cache-PHP
X-ATG-Version
X-Varnish-Hostname
Cache-Hits
X-EdgeConnect-Cache-Status
X-RCS-CacheZone
X-CCM
X-Debug-Cache
X-Node-Name
Who
X-Cache-Host
X-Detected-As
X-Akamai-Transformed
DB-Nickname
Country-Code
X-Amz-Apigw-Id
X-B3-SpanId
X-Amzn-Remapped-Content-Length
X-Amzn-RequestId
Filterid
X-CACHE-KEY
X-Adobe-Source
X-TX-ID
X-Nc
X-BCube-Filmed-By
X-CS
X-RateLimit-Limit
X-Varnish-Beresp-Grace
SD-X-WS
X-Oss-Request-Id
X-Correlation-ID
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Oss-Storage-Class
X-Ms-Version
X-Ms-Request-Id
X-Varnish-Cache-Hits
X-Vdms-Version
X-Vdms-Path
DCR-Processing-Time-Ms
X-VG-WebServer
X-Vtex-Processado-Em
X-Varnish-Beresp-Ttl
X-VG-WebCache
BehaviorPad-Version
X-Vtex-Remote-Cache
DCR-Decision-By
Expiry
T-Server
X-Location
X-NAPM-TraceId
X-Origin-CC
X-Session-Fingerprint
X-Level-Front-Cache
X-SRCache-Key
X-External-Request-Id
X-From
X-Generated-On
X-Generation-Time
X-Origin-TTL
X-Owner
X-Rewrite-Enabled
X-Rojux
X-S
X-S-Cookie
X-Request-UUID
X-ScT
X-PAYTM-SRV-ID
X-PBS-Appsvrname
X-Processor
X-Destination
X-D
X-A
X-A-Ccd
X-A-Dam
X-A-Dcw
Rendered-Blocks
Odigeo-Trace-Id
MD5-Digest
Meta-Geo-Continent
Mobile-Detection-Method
X-A-Dgt
X-A-Wwc
X-Cache-NE
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Connection-Hash
X-Trv-Group
X-B-Cookie
X-Aed
X-Application
X-ARC
Machine
Fastcgi-X-Cache-Version
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-DC
X-FTR-Backend
X-Country-Code-Real
X-Time-Microsecs
X-GEO
X-FTR-Realm
X-FTR-Cache-Status
HostName
X-Magnolia-Registration
X-Varnish-Beresp-Status
Backend
X-Ratelimit-Remaining
X-Unique-Id
PB-RID
Release
Ssr
UCS
V-Age
Thinkindot-Control
Thinkindot-CacheControl-Type
PB-PID
Server-Host
Pagetype
Cf-Device-Type
CacheControlHeader
Cache-Host
Arc-Version
Content-Disposition
Gh-Request-Id
Path
Wxu-Next-Commit
Magicmarker
Host-ID
X-Reqid
X-ServerID
X-Developers
X-Device-Os
X-Core-Value
X-Cms-Context
X-Thanos
X-FC-Vary-Parameters
X-Fetched-On
X-Has-Esi
X-GeoIP-City
X-Geo-Header
X-Generated-In
X-Thinkindot-L3
X-TrackingId
X-OVcl-Cache
X-Policy
X-Is-Gdpr
Wxu-Next-Region
X-OVcl
AKAMAI
X-JWT-State
X-Tumblr-Pixel-3
X-Bip
X-Azure-Ref-OriginShield
Wxu-Next-Hostname
Thinkindot-CacheControl
Fastly-Backend-Name
X-B3-Traceid
X-Backend-TTL
X-Cache-Bucket
X-APP-VERSION
X-EC-Lua
X-Unique-ID
X-Variation
X-Skip-Cache
X-NU-AKA-ACS-Version
X-User
X-Branch-Name
X-Cache-Info
X-Cache-Tags
X-Cache-Debug
Adler-Geo
X-Varnish-CookieHashed-On
X-Nginx-Cache-Key
X-Node-Id
X-SIPLIST1
X-Varnish-Hits
Sever-Int
X-Request-URI
Server-Hostname
X-Varnish-Remaining-TTL
Server-Ext
NGB
True-Client-Country-4JS
X-Var-Ttl
X-Mvc-Supplant-Cachable
X-Origin
Esi-Enabled
X-Rebelmouse-Surrogate-Control
X-Varnish-CookieINHashed-On
X-Micro-Cache
X-Li-Fabric
X-IP
X-Fastly-Cache
X-Fastly-Backend
X-Eu-Site
X-Li-Pop
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-HN
X-HS-Content-Campaign-Id
X-GoCache-CacheStatus
X-Backend-State
X-Rebelmouse-Cache-Control
X-GeoIP
X-LI-UUID
X-Epic-Correlation-Id
X-Csrf-Jwt
X-DefElseHash
X-DynaTrace-JS-Agent
X-Clientip
X-CGP
X-Method
X-DefHash
X-Ratelimit-Reset
X-DPWN-IS-SECURE
X-Envoy-Decorator-Operation
X-Dispatcher-Server
X-Irp-Debug
X-Developer
X-Origin-Expires
Vix-Hermes-Req-Id
X-VarnishDD-TTL
X-VServer
HA-Ipaddr
Ha-Gx-Prefs
Fastly-SWR
Platform
CDN-Cache
IsBot
Locid
Apple-News-Services-Request-Url
Location
L5d-Success-Class
L
Fastly-SIE
C-Via
CDN-RequestCountryCode
CDN-RequestId
CDN-PullZone
CDN-EdgeStorageId
CDN-CachedAt
CDN-Uid
Cf-Bgj
DSUID
X-Scheme
X-VG-TLSProxy
X-Platform-Server
CDCHOST
Apple-News-Services-Parsed-Url
Is-Eu
NGX
NM-Fastcgi-Cache
Origin
Apple-News-Services-Handled
PFcat
On-Server
Apple-News-Services-Host
X-Amz-Meta-S3cmd-Attrs
User-Cache-Control
X-NewRelic-App-Data
X-ID
X-Hash
X-WADP-Cache
Xc-Version
X-Tb
X-Wikidot-Backend
X-Planisys-CDN-Rules
Fastly-Drupal-HTML
X-Clara-WADP
X-Sucuri-ID
X-Planisys-CDN-Cache
X-Esi-Check
X-CACHE-GROUP
X-Swa-Ws
X-Gamma-Serve
X-Fmm-Version
X-Planisys-CDN-TTL
Rt-Fastcgi-Cache
X-Gzip
X-Wikidot-Static-Cache
X-Aicache-OS
X-Generated-By
X-Hnp-Log
X-Gen-Mode
X-Block-Status
X-Cache-Id
X-Old-Content-Length
X-Goog-Meta-Goog-Reserved-File-Mtime
Web-Mar-Node
X-Origin-Response-Time
X-Loc
X-Request-Host
X-FTR-Expires
X-Air-Hostname
Req-Svc-Chain
Cmsid
X-Slack-Backend
Cmstype
X-Edge-Location-Klb
X-Varnish-Url
X-LB-ID
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Kraken-Routeconfig-Destination
X-Instrumentation
X-Servername
X-Mvc-Supplant-OutputCached
Svr
Kp-EeAlive
X-Served-From
Tracecode
Pics-Label
X-Cdn-Forward
X-PF-Uncompressing
X-Vgn-Hpd-Reason
X-Via-Popn
A
Url
SR-User-Adfree
X-Refresh
X-Via-Popv
X-Via-Poph
Instruction
X-Cache-Var-Map
X-Cache-Var
Viewtype
X-CUA
VivaBuild
M-TraceId
X-Matched-Rule
X-SaId
Cache-Key
X-PHP-Backend
Arc-Country
X-JoinUs
Lfy
Cross-Origin-Opener-Policy
Sid
X-NGENIX-Cache
X-TraceId
X-Edge-Location
X-Tb-Optimization-Total-Bytes-Saved
MIME-Version
CloudFront-Viewer-Country
TDXMobile
X-Sn-Servicetimems
X-Cache-Expires
X-Cdn-Origin
X-CDN-Forward
SID
DataCenter
X-Cache-Backend
X-Srv
X-DC
X-Vc
X-NCache
Pramga
X-NC
Geo-Info
X-Servedbyhost
X-Cache-Date
X-Core-Mission
X-Service
X-Extlb
X-Webkit-CSP-Report-Only
NtCoent-Length
X-CLOUD-TRACE-CONTEXT
Content-Secure-Policy
X-Wa
X-Internal-Host
X-Request-Start
Server-ID
Tcn
GeoIp-Country-Code
X-Bc-Bl
Geoip-Latitude
Source
X-Forwarded-Site
FSS-Cache
X-Error
X-HS-Status
X-B3-Spanid
X-FireWall-Protection
LB
X-Via-NSCOPI
X-Varnish-Cacheable
Surrogated-Key
Memcached
X-LI-Proto
X-Esi
X-Req
X-Proxy-Upstream
X-VHOST
Hostname
CACHE
X-Newrelic-Synthetics
X-PJAX-URL
X-Air-Source
We-Hiring
Resin-Trace
X-Accel-Expires-Debug
X-Date
X-VCL-Version
X-VC-Cache
X-Vcl-Version
X-Li-Proto
Mail-Subject
X-Response-By
Upgrade-Insecure-Requests
X-HOST
X-Geo
X-App
Xkeyi7
Request-ID
Env
X-CCDN-CacheTTL
X-RateLimit-Remaining-Second
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-Proxy-Cachei7
X-Rocket-Build-Number
X-Viewer-Country
X-Sigma-Backend
X-RateLimit-Limit-Second
X-Sigma
X-LiteSpeed-Cache-Control
X-Cs
CF-Cached-On
X-RPM
X-DB
GeoIP-Country-Code
HitType
X-BBXSRF
X-RSL
GeoIP-Latitude
Memory
X-DI
X-Men
Time
X-MSEdge-Features
X-RPS
Server-Ttl
N-Cache
X-DW
X-TIM-N
X-DSS
X-MSEdge-Flight
X-ZONE
X-RAMCache
X-Zone
X-WA
X-APP
X-Cache-2
XServer
X-UA
X-Cc-Req-Id
X-Cc-Via
X-Varnish-Authentication
X-Mg-Request-UUID
X-Svr
VNS-Cache
VNS-Age
CPC-Cache
CPC-Age
ProcessTime
S-Rt
X-Cache-ASPX
X-Contensis-Viewer-Groups
X-Action
X-ServedByHost
X-Air-Trace-Id
D-Cc-Upstream
Server-Id
X-TIME
X-HostName
X-Oss-Cdn-Auth
X-FPC
X-Region-Sid
My-App
Fastcgi-Cache-TTL
State
X-Swift-Error
X-Provided-By
X-Dynatrace-Js-Agent
X-Minions-Version
X-Fpc
Cache-Provider
X-Gdpr
X-Server-IP
X-Nyt-Route
X-Origin-Time
X-CF-Powered-By
X-Cache-Config
X-Depends-On
W
X-FORWARDED-FOR
Mime-Version
X-API-Version
Cteonnt-Length
X-Akamai-Pragma-Client-IP
X-Cdn-Request-ID
Srv
X-Cache-Remote
X-UnsetCookies
CDN
Cross-Origin-Window-Policy
X-Erf-Stays-Bingo-Pdp-Web
X-Cache-Type
X-BACKEND-TTL
X-Dw-Trace-Id
X-CSRF-TOKEN
X-Cache-Ttl
X-Sucuri-Cache
X-URL
Ohc-File-Size
X-Xrds-Location
X-Client-Ip
X-ServerName
Proxy-Connection
X-ABtesting
X-Flog
X-Parent-Response-Time
X-Hello
OT-Force-Account-Verify
X-SN
X-NodeID
X-Check-Cacheable
X-VC
X-Fastly-Request-Id
Cdn
X-Ftr-Cache-Host
Ohc-Cache-HIT
Cf-Ipcountry
X-SD-PageType
X-Snapshot-Date
X-NGINX-Cache
X-SB
X-Webstats-RespID
X-Pad
X-Fastly-Backend-Reqs
Dnion-Transfer-Encoding
Vha6-Origin
X-Pf-Uncompressing
X-Presslabs-Stats
X-Tenant
X-Shop-Environment
X-Via-PopH
X-Via-PopN
X-Via-PopV
X-Orig-Expires
X-Oracle-DMS-ECID
Media-Length
X-Forwarded-Path
X-ND-Cache
X-Host-Name
X-BBC-Edge-Cache-Status
X-Cluster-Node
WZWS-RAY
X-LiteSpeed-Tag
X-Air-Pt
Epwk-X-Cache
X-Lb-Id
PICS-Label
X-ElasticPress-Search
X-Acquia-Purge-Tags
X-Acquia-Site
X-Acquia-Application-UUID
X-Akamai-ERRuleID
Xet-Cookie
X-BBC-Origin-Response-Status
X-MiniProfiler-Ids
X-Render-Time
X-Vcache
X-Ms-Meta-Originalurl
X-Ms-Meta-Staticbatchstarttime
X-Ftr-Request-Id
Warning
X-Varnish-Beresp-TTL
X-Request-URL
X-Cache-Tag
X-Acquia-Application-Trace
EpKe-Alive
X-Akamai-ERPolicy
X-Varnish-URL
X-Traceid
CountryCode
Datacenter
X-Tx-Id
X-Debug-Cache-Fetch
X-Mg-Request-Id
URI
Environment
X-Debug-Cache-Store
Ohc-Response-Time
X-B3-Parentspanid
X-Conf
X-Pjax-Url
X-C
X-Yottaa-OS
X-Redis-Count
X-Apw-Access-Token
Phost
Content-Script-Type
X-Litespeed-Cache-Control
X-Tid
NnCoection
Content-Style-Type
Inserted-Into-Cache-At
X-Amz-Meta-Cb-Modifiedtime
X-Apw-Hits
X-Apw-Access-Object
X-Apw-Access-Action
X-Redis-Duration-Ms
X-Cache-Status-Check