Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
X-XSS-Protection
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Request-Id
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Runtime
X-AspNet-Version
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Xss-Protection
X-Cache-Status
X-Generator
X-Cacheable
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
X-Request-ID
Content-Encoding
X-CDN
X-Ua-Compatible
Feature-Policy
X-AspNetMvc-Version
Status
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Upgrade
X-Via
Access-Control-Max-Age
Keep-Alive
X-Ws-Request-Id
X-Age
X-Robots-Tag
X-AH-Environment
X-Turbo-Charged-By
EagleId
Request-Context
X-Proxy-Cache
X-Cache-Group
Server-Timing
X-Backend
X-Server
X-Hacker
X-Dns-Prefetch-Control
Report-To
Host-Header
X-Server-Powered-By
X-Amz-Request-Id
X-Nginx-Cache-Status
X-Amz-Id-2
Grace
X-UA-Device
X-Rq
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Page-Speed
Cf-Railgun
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Amz-Version-Id
NEL
X-Cache-Spec
X-Device
X-OneAgent-JS-Injection
X-CST
Allow
X-Vhost
X-Host
X-Backend-Server
Xkey
X-Server-Id
X-ASPNET-VERSION
X-WebKit-CSP
EagleEye-TraceId
X-Dispatcher
Surrogate-Control
X-Node
Request-Id
Content-Location
X-Response-Time
X-Akam-SW-Version
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
P3p
X-Cache-Lookup
X-Application-Context
X-Ac
X-Country
Accept-Ch
Accept-Ch-Lifetime
X-Ruxit-JS-Agent
X-Mod-Pagespeed
Accept-CH
X-Template
X-Language
X-Readtime
X-Cloud-Trace-Context
X-B3-TraceId
MS-Author-Via
Rating
Accept-CH-Lifetime
X-HW
X-Url
X-Origin-Cache
X-Cnection
X-MS-InvokeApp
X-TtlSet
X-Vname
X-PC
Edge-Control
X-Clacks-Overhead
X-GitHub-Request-Id
X-ESI
X-Trace
X-ORACLE-DMS-RID
X-Oneagent-Js-Injection
Pagespeed
Display
X-Sol
Response
X-Middleton-Response
X-Middleton-Display
X-Content-Type
X-ORACLE-DMS-ECID
X-D2id
Arr-Disable-Session-Affinity
Verso
X-Use-Magma
X-GoogleNews-Bot
X-Kinja-Server
X-Kinja-Build
X-Kinja-Revision
X-Exp-Variant
X-Exp-Id
X-Cdn-Fetch
X-Kinja
X-Vcap-Request-Id
X-Varnish-TTL
X-Country-Code
X-Goog-Hash
X-Rack-Cache
X-Powered-By-Plesk
X-Navigation-Version
X-VARITI-CCR
Service-Worker-Allowed
X-Server-Name
X-Amz-Rid
X-Abt-Application-Version
X-Buckets
X-Webkit-CSP
X-Fastly-Request-ID
X-TTL
X-Client-IP
Fastly-Restarts
X-Cache-TTL
X-Cached
X-Release
X-MSEdge-Ref
X-Element-Page-Cache
X-Dw-Request-Base-Id
X-SharePointHealthScore
SPRequestGuid
X-NF-Request-ID
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
SPIisLatency
SPRequestDuration
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-FastCGI-Cache
Public-Key-Pins
Access-Control-Request-Method
RTSS
AR-CACHE
AR-ATIME
AR-PoweredBy
Ar-Sid
AR-Request-ID
Cache-Tag
X-Edge
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-LLID
X-Powered-CMS
X-Ezoic-Cdn
X-Ruxit-Js-Agent
X-Upstream
Content-MD5
X-Jurisdiction
X-HP-Webp
X-Version
X-Origin-Upstream-Status
S
X-Recruiting
X-ECACHE
X-MCACHE
X-Mid
Fusion-Template-Id
Charset
Fusion-Deployment-Id
Fusion-Component-Id
Fusion-Content-Id
Fusion-Content-Source
Fusion-Source
X-Mg-S
X-Px
X-Fastcgi-Cache
X-DynaTrace
X-PressLabs-Stats
X-Content-Digest
X-Kinsta-Cache
X-Ttl
X-T
Fastcgi-Cache
Cache-Tags
X-Litespeed-Cache
X-Id
X-Amz-Server-Side-Encryption
X-Logged-In
X-Accel-Expires
Filters
X-Forwarded-Proto
Server-Node
X-Content-Security-Policy-Report-Only
Edge-Cache-Tag
MicrosoftSharePointTeamServices
Front-End-Https
Server-Name
TP-Cache
TP-L2-Cache
X-Correlation-Id
X-Forwarded-For
X-Grace
TCN
Nginx-Cache
X-Kong-Upstream-Latency
X-Hits
X-Kong-Proxy-Latency
X-Debug
X-Request-Received
X-Request-Processing-Time
X-Amzn-Trace-Id
X-B3-Sampled
X-Shield-Request-Id
X-Microsite
X-Request-Handler-Origin-Region
X-Varnish-Age
Surrogate-Key
X-Yandex-Sdch-Disable
X-Activity-Id
X-AppVersion
X-Az
X-Amz-Replication-Status
X-F-Cache
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Combine-CSS
X-HS-Content-Id
X-XRDS-Location
X-XRDS-LOCATION
Alternate-Protocol
X-Ser
X-Origin-Server
X-Goog-Storage-Class
X-Goog-Generation
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-DIS-Request-ID
X-Goog-Metageneration
Accept-Charset
Nel
X-Geo-Country
X-Frontend
X-Rid
X-NWS-LOG-UUID
X-Git-Hash
Section-Io-Cache
Host
X-Time
X-Respond-Thread
X-Cache-Age
X-Pinterest-Direct
X-Cache-Key
X-Upgrade-Enabled
X-DataDome
X-Hostname
Access-Control-Allow-Method
X-VCache
X-LB-Cache
X-Mobile-URL
Cache
X-Server-ID
MS-CV
X-Type
Paypal-Debug-Id
ServerID
X-Seen-By
X-Source
X-RateLimit-Remaining
X-AOL-HN
X-TT
X-Daa-Tunnel
X-IPLB-Instance
X-Varnish-Backend
X-Content-Options
X-Whom
Healthy
X-App-Environment
X-B-Cache
X-Signature
Payment
X-Is-Crawler
X-Providence-Cookie
X-Request-Guid
X-Route-Name
X-Cache-Action
X-Flags
X-Aspnet-Duration-Ms
Cleartype
X-Debug-Info
X-Page-Id
X-Jobs
X-FTR-Request-ID
X-WebKit-CSP-Report-Only
X-Load-Cache
X-N
Fastcgi-Useragent
X-FB-Debug
X-Contextid
Realpath
X-Webkit-Csp
Powered-By-ChinaCache
X-Mobile
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Erf-Bev-Bev
Node
Refresh
X-Rule
X-Accel-Buffering
X-Response-Served-From
X-Original-Request-Id
X-Cache-Expired-At
X-Drupal-Cache-Tags
X-Proxy
X-RTag
DC
X-Zen-Fury
Ms-Operation-Id
Version
Referer-Policy
X-Wix-Request-Id
X-Framework
X-Via-JSL
X-Cacheable-TTL
X-Distributor
X-B
X-Cache-Control
X-Instance
X-HTML-Minification-Powered-By
Access-Control-Request-Headers
X-Cluster-Name
X-Content-Powered-By
X-RemovedCookies
X-Real-IP
X-ProcessESI
X-UUID
VIX-Pulpo-Upstream-Status
X-Cache-Time
VIX-Pulpo-Node
Viewport
X-Drupal-Cache-Contexts
X-Region
X-Tt-Trace-Host
X-Tt-Trace-Tag
Eomportal-Instance
X-Page-View
X-IPS-LoggedIn
X-FW-Server
X-FW-Type
X-FW-Static
X-FW-Serve
X-FW-Hash
X-FW-Dynamic
Countrycode
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Cached-By
X-Akamai-Edgescape
X-TEC-API-VERSION
X-FireWall-Port
X-Cache-Rule
Liferay-Portal
X-Cache-Operation
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-G
X-Cache-Hit
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Pass-Why
X-Environment-Context
X-L-Path
X-App-Server
Xserver
Server-Info
X-Nginx-Cache
SRV
DynaTrace
Section-Io-Id
Section-Origin-Responded
Section-Io-Origin-Status
X-Debug-IsPreview
Section-Io-Origin-Time-Seconds
X-Debug-IsConnected
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
X-Protected-By
X-Www-Served-By
CF-IPCountry
X-User-Agent
Ec-Rule-Version
From-Origin
X-Tumblr-Pixel-2
Webserver
X-Device-Type
X-Mode
X-Adobe-Loc
X-Varnish-Grace
X-Adobe-Content
X-UPSTREAM-Address
X-Endurance-Cache-Level
X-ES-SERVER
X-Handled-By
X-RN-RSRV
X-Hl-Ver
Meta-Geo
GEO-INFO
X-Varnish-Ttl
Cache-Tv-Group
Retry-After
X-FB-TRIP-ID
X-Uri
X-Backend-Name
X-MP-GENERATED-AT
X-Varnishpool
X-Ratelimit-Limit
Decoy-Debug-Status
Property-Id
Decoy-Debug-Key
X-Section
Webcakes-App-Version
Cache-Status
Webcakes-App-Name
X-Access
X-Cache-Server
X-Storage
TWC-Connection-Speed
X-Pubstack
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Device-Class
X-Format
Decoy-Debug-TTL
X-Be
X-PCL
Webcakes-Region
X-PHP-Host
X-Labrador-Cache-Channel
TWC-Privacy
X-Origin-Hint
TWC-Locale-Group
X-NYM-Debug-Backend
X-OCL
Fastly-SSL
X-R9-Blue-Green-Version
Cache-Name
X-AWS-Id
X-ApacheServer
Frame-Options
Selected-Fe
X-Locale
X-LJ-Flow-ID
X-LAGOON
X-PERF
X-Origin-Date
X-No-Session
Mn-Server-Ip
X-Proxy-Build
X-BYPASS-REASON
X-WA-Info
X-Redis-Cache
X-VWS-Id
X-Via-Fastly
X-Timing-Wait
X-UA-Device-Type
Apigw-Requestid
Country
X-Request-Time
X-Soup
X-ProxyCache-Status
X-ProxyCache-Key
X-Human
Protected
X-Web-Node
X-Server-W
X-Site-Version
Azure-InstanceId
X-Proxied
X-Zipkin-Id
X-Loop
X-Proto
X-Xfnlog-Site
Azure-RegionName
Azure-Version
X-Say-TTL
X-SayCDN-TTL
X-Cache-TTL-Remaining
X-Say-Cacheable
X-S-Maxage
AMP-Access-Control-Allow-Source-Origin
X-Routing-Service
Azure-SlotName
Azure-SiteName
X-Sql-Count
X-Sql-Duration-Ms
X-TNCMS
X-Status
X-Varnish-Server
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Hosted-By
X-Hyper-Cache
X-Storefront-Renderer-Rendered
X-Alternate-Cache-Key
X-ShardId
X-ShopId
X-Shopify-Stage
X-FW-Version
X-Node-Name
X-Cluster
X-GG-Cache-Date
X-Forwarded-Host
X-CCM
X-AIR-PT
X-Cache-Grace
X-TT-LOGID
X-Info
X-Is-Bot
X-Rendered-As
X-Dc
X-Cache-Enabled
X-Qloud-Router
X-TA-CDN-Provider
X-Revision
S-Cnection
X-Microcachable
X-Proxy-Cache-Status
Uber-Trace-Id
X-Content-Age
X-SRV
X-NWS-UUID-VERIFY
X-Via-CDN
X-Platform
X-Azure-Ref
Cache-Hits
X-Backend-Host
X-CSRF-Token
X-App-Version
X-Aspnetmvc-Version
X-Ratelimit-Remaining
X-Cache-Host
X-Detected-As
X-FTR-Realm
X-FTR-Backend-Server
X-FTR-Backend
X-Country-Code-Real
X-Amz-Meta-S3cmd-Attrs
Akamai-GRN
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-DC
X-Amz-Apigw-Id
X-Amzn-Remapped-Content-Length
X-Amzn-RequestId
X-EdgeConnect-Cache-Status
X-ATG-Version
ServedBy
Amp-Access-Control-Allow-Source-Origin
X-Cache-PHP
X-B3-SpanId
X-Cache-NGX
X-Trace-Id
X-CS
X-Debug-Cache
X-RCS-CacheZone
X-Oss-Hash-Crc64ecma
X-Oss-Storage-Class
X-Oss-Object-Type
X-Oss-Server-Time
X-Oss-Request-Id
X-FTR-Expires
X-Varnish-Hostname
SD-X-WS
HostName
X-Air-Hostname
Tracecode
X-Time-Microsecs
X-Correlation-ID
X-BCube-Filmed-By
X-Akamai-Transformed
DB-Nickname
X-TX-ID
X-Nc
X-ServerID
X-DynaTrace-JS-Agent
X-Unique-ID
X-Backend-TTL
X-Adobe-Source
Backend
X-NewRelic-App-Data
X-Ms-Version
X-Ms-Request-Id
X-Tb
X-Vtex-Processado-Em
X-VG-WebServer
X-Vtex-Remote-Cache
Fastcgi-X-Cache-Version
Rendered-Blocks
Expiry
X-Owner
X-Origin-CC
X-B-Cookie
X-Cache-NE
X-Magnolia-Registration
X-PAYTM-SRV-ID
X-Connection-Hash
BehaviorPad-Version
X-Destination
Xc-Version
X-Generation-Time
X-Generated-On
X-From
X-External-Request-Id
X-D
X-PBS-Appsvrname
DCR-Decision-By
X-NAPM-TraceId
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Level-Front-Cache
X-Location
DCR-Processing-Time-Ms
X-Origin-TTL
Meta-Geo-Continent
X-ScT
X-Session-Fingerprint
MD5-Digest
X-VG-WebCache
X-Rojux
X-S
X-Vdms-Path
Mobile-Detection-Method
X-A-Dam
Odigeo-Trace-Id
X-Trv-Group
X-A-Dcw
X-Vdms-Version
X-A-Dgt
X-SRCache-Key
X-Rewrite-Enabled
X-S-Cookie
Machine
X-Aed
X-Request-UUID
X-A-Wwc
X-A-Ccd
T-Server
X-ARC
X-A
X-Processor
X-Application
X-Cdn-Forward
X-Cache-Var
X-Cache-Var-Map
X-Developers
X-Device-Os
Arc-Version
Wxu-Next-Commit
PB-PID
Wxu-Next-Hostname
Path
Thinkindot-Control
Wxu-Next-Region
X-Varnish-Beresp-Grace
AKAMAI
PB-RID
X-Fastly-Cache
Thinkindot-CacheControl-Type
X-Cms-Context
Fastly-Backend-Name
X-Fetched-On
Magicmarker
Locid
X-Cache-Bucket
Host-ID
X-Bip
Gh-Request-Id
Server-Host
Content-Disposition
On-Server
CacheControlHeader
Pagetype
V-Age
X-Core-Value
Release
Cf-Device-Type
X-Azure-Ref-OriginShield
UCS
X-Varnish-Cache-Hits
X-Mvc-Supplant-Cachable
X-CACHE-KEY
X-Has-Esi
X-Tumblr-Pixel-3
X-JWT-State
X-HS-Content-Campaign-Id
X-Irp-Debug
Thinkindot-CacheControl
X-Thanos
X-Thinkindot-L3
X-Is-Gdpr
X-GeoIP-City
X-OVcl-Cache
X-Micro-Cache
X-Policy
X-Generated-In
X-OVcl
X-Reqid
X-B3-Traceid
X-TrackingId
X-Geo-Header
User-Cache-Control
Who
X-Scheme
X-Request-Host
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Request-URI
X-SIPLIST1
X-SVT-ORM-RULES
X-Skip-Cache
X-SVT-ORM-VERSION
X-Var-Ttl
X-Wikidot-Static-Cache
X-Wikidot-Backend
Vix-Hermes-Req-Id
Cache-Host
True-Client-Country-4JS
X-Swa-Ws
X-Cache-Info
Ssr
Web-Mar-Node
X-WADP-Cache
X-Varnish-CookieHashed-On
X-Variation
X-Ratelimit-Reset
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-VG-TLSProxy
X-VarnishDD-TTL
X-User
X-Branch-Name
X-Developer
X-HN
X-Gzip
X-Hnp-Log
X-DefHash
X-IP
X-DefElseHash
X-Dispatcher-Server
X-DPWN-IS-SECURE
X-FC-Vary-Parameters
X-Gen-Mode
X-Generated-By
X-Eu-Site
X-GeoIP
X-Envoy-Decorator-Operation
X-Csrf-Jwt
X-Clientip
X-Origin-Expires
X-Cache-Debug
X-Cache-Id
X-Fmm-Version
X-Origin-Response-Time
X-Backend-State
X-Block-Status
X-Origin
X-Old-Content-Length
X-CGP
X-Clara-WADP
X-Method
X-Nginx-Cache-Key
X-NU-AKA-ACS-Version
X-Cache-Tags
X-Platform-Server
X-Esi-Check
CDN-RequestId
CDN-Uid
CDN-RequestCountryCode
CDN-PullZone
CDN-EdgeStorageId
Cf-Bgj
DSUID
Ha-Gx-Prefs
Fastly-SWR
Fastly-SIE
Esi-Enabled
CDN-CachedAt
CDN-Cache
SR-User-Adfree
X-Varnish-Beresp-Ttl
Country-Code
X-Sucuri-ID
X-RateLimit-Limit
Apple-News-Services-Handled
Apple-News-Services-Host
CDCHOST
C-Via
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
HA-Ipaddr
Adler-Geo
Is-Eu
Server-Hostname
Server-Ext
IsBot
L5d-Success-Class
Platform
PFcat
Instruction
Location
NGX
Sever-Int
NM-Fastcgi-Cache
X-Unique-Id
X-EC-Lua
X-Varnish-Beresp-Status
X-ID
Geo-Info
X-Fastly-Backend
X-VServer
X-Hash
X-LI-UUID
X-Node-Id
X-GEO
X-Slack-Backend
X-Li-Pop
X-CUA
X-LB-ID
X-Li-Fabric
X-GoCache-CacheStatus
X-Gamma-Serve
X-Varnish-Hits
Origin
L
X-Aicache-OS
X-CLOUD-TRACE-CONTEXT
X-Varnish-Url
X-Loc
Fastly-Drupal-HTML
X-Cache-Backend
X-Matched-Rule
X-Mvc-Supplant-OutputCached
X-Goog-Meta-Goog-Reserved-File-Mtime
Rt-Fastcgi-Cache
Lfy
X-APP-VERSION
Filterid
X-Via-Popv
X-PF-Uncompressing
X-Via-Popn
X-Epic-Correlation-Id
Pics-Label
CloudFront-Viewer-Country
X-Via-Poph
Sid
X-Cdn-Origin
X-Planisys-CDN-Cache
X-Sn-Servicetimems
X-Planisys-CDN-Rules
X-NCache
X-Refresh
Pramga
X-Planisys-CDN-TTL
X-Cache-Expires
X-Cache-Date
X-Core-Mission
Url
X-Tb-Optimization-Total-Bytes-Saved
Req-Svc-Chain
Cmstype
X-Servername
Cmsid
Kp-EeAlive
Svr
Tcn
X-Served-From
X-Request-Start
NGB
X-TraceId
X-FireWall-Protection
A
VivaBuild
MIME-Version
X-Srv
Viewtype
X-Error
Cache-Key
X-Varnish-Cacheable
Source
M-TraceId
X-Webkit-CSP-Report-Only
X-Response-By
Cross-Origin-Opener-Policy
Arc-Country
Server-ID
X-Vgn-Hpd-Reason
X-DC
X-NC
X-HS-Status
Xkeyi7
X-Proxy-Cachei7
X-Air-Source
GeoIp-Country-Code
X-Geo
X-Vcl-Version
X-Servedbyhost
Geoip-Latitude
TDXMobile
X-Wa
X-B3-Spanid
Content-Secure-Policy
X-NGENIX-Cache
SID
X-SaId
X-Vc
X-JoinUs
X-PHP-Backend
Server-Ttl
HitType
X-BBXSRF
DataCenter
N-Cache
X-Edge-Location
S-Rt
X-Erf-Stays-Bingo-Pdp-Web
NtCoent-Length
X-Cache-Remote
X-LiteSpeed-Cache-Control
X-Service
X-Esi
X-Internal-Host
X-Cache-2
Resin-Trace
X-CDN-Forward
CACHE
X-Cc-Via
X-Cc-Req-Id
X-Cache-ASPX
X-Li-Proto
X-Contensis-Viewer-Groups
D-Cc-Upstream
X-LI-Proto
X-Varnish-Authentication
X-Extlb
Cteonnt-Length
X-HOST
FSS-Cache
Ohc-File-Size
X-Svr
X-Viewer-Country
Cross-Origin-Window-Policy
X-RAMCache
X-CCDN-CacheTTL
X-Forwarded-Site
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
Request-ID
X-Sucuri-Cache
X-HostName
X-UA
X-Host-Name
X-TIM-N
X-DI
X-VCL-Version
X-RSL
X-WA
X-DSS
X-Bc-Bl
X-ServedByHost
X-Newrelic-Synthetics
X-Server-IP
X-DB
X-RPS
X-RPM
X-Via-NSCOPI
X-DW
Hostname
X-Req
X-Origin-Time
LB
CF-Cached-On
X-FPC
X-API-Version
X-Cs
X-VC-Cache
X-Gdpr
X-Proxy-Upstream
Mail-Subject
X-Accel-Expires-Debug
X-Nyt-Route
X-Date
GeoIP-Latitude
GeoIP-Country-Code
We-Hiring
Memcached
X-Cache-Config
Surrogated-Key
X-PJAX-URL
XServer
X-Action
X-Check-Cacheable
X-Kraken-Loop-Name
X-RateLimit-Limit-Second
X-ZONE
Cache-Provider
X-Kraken-Routeconfig-Destination
ProcessTime
X-SN
X-VC
X-Server-Lifecycle-Phase
X-NodeID
X-Instrumentation
X-RateLimit-Remaining-Second
X-APP
Env
X-App
Ohc-Cache-HIT
X-Men
X-Oss-Cdn-Auth
X-CF-Powered-By
Server-Id
X-Edge-Location-Klb
X-SB
X-Air-Trace-Id
X-Fpc
Upgrade-Insecure-Requests
X-Region-Sid
X-Sigma-Backend
X-Rocket-Build-Number
X-Sigma
X-Webstats-RespID
X-Dynatrace-Js-Agent
X-Provided-By
X-Swift-Error
X-URL
Memory
X-MSEdge-Flight
X-Depends-On
X-SD-PageType
Time
X-FORWARDED-FOR
Mime-Version
W
X-MSEdge-Features
Srv
X-Cdn-Request-ID
VNS-Age
X-BACKEND-TTL
CPC-Cache
X-Ftr-Cache-Host
X-Dw-Trace-Id
CDN
VNS-Cache
X-UnsetCookies
CPC-Age
X-CSRF-TOKEN
X-TIME
Cdn
X-Render-Time
X-BBC-Edge-Cache-Status
X-Client-Ip
X-Zone
X-Akamai-Pragma-Client-IP
X-Hello
X-ABtesting
X-ServerName
Dnion-Transfer-Encoding
EpKe-Alive
X-Fastly-Backend-Reqs
X-NGINX-Cache
X-Flog
X-Fastly-Request-Id
X-Parent-Response-Time
X-Dynatrace
Cf-Ipcountry
X-Acquia-Application-UUID
State
My-App
X-Pf-Uncompressing
X-Acquia-Application-Trace
X-Acquia-Site
Media-Length
Proxy-Connection
X-Cache-Tag
X-Pad
X-Presslabs-Stats
Processtime
X-Acquia-Purge-Tags
X-FTR-Cache-Host
Fastcgi-Cache-TTL
X-Auto-Login
Vha6-Origin
X-Oracle-DMS-ECID
X-Worker
PICS-Label
X-Cluster-Node
Epwk-X-Cache
X-Ua
X-Via-PopN
X-Via-PopV
X-Snapshot-Date
X-ElasticPress-Search
X-LiteSpeed-Tag
X-Via-PopH
X-BBC-Origin-Response-Status
X-Minions-Version
X-CACHE-AGE
X-Lb-Id
X-ElasticPress-Query
X-IN-APIGATEWAYSSL
Xet-Cookie
Datacenter
X-Ms-Meta-Originalurl
X-Ms-Meta-Staticbatchstarttime
X-Vcache
X-Traceid
X-IN-APIGATEWAY
X-MiniProfiler-Ids
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-Varnish-URL
X-Request-URL
X-Varnish-Beresp-TTL
X-Air-Pt
X-Mg-Request-UUID
CountryCode
Content-Script-Type
X-Litespeed-Cache-Control
Warning
X-Cache-Status-Check
X-Apw-Access-Token
X-Apw-Hits
X-Apw-Access-Object
X-Mg-Request-Id
X-Ftr-Request-Id
X-Apw-Access-Action
Content-Style-Type
X-B3-Parentspanid
URI
OT-Force-Account-Verify
X-Redis-Duration-Ms
X-Redis-Count
X-Storefront-Renderer-Verified
Environment
NnCoection
Phost
Inserted-Into-Cache-At
X-Tid
X-C
X-Debug-Cache-Store
Ohc-Response-Time
X-Debug-Cache-Fetch
X-Amz-Meta-Cb-Modifiedtime