Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-RAY
CF-Cache-Status
Accept-Ranges
Link
X-XSS-Protection
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Request-Id
X-Varnish
Access-Control-Allow-Methods
X-Xss-Protection
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Cache-Status
X-Generator
X-Cacheable
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
X-Request-ID
Content-Encoding
X-CDN
X-Ua-Compatible
Feature-Policy
X-AspNetMvc-Version
Status
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Upgrade
X-Via
Access-Control-Max-Age
Keep-Alive
X-Ws-Request-Id
X-Age
X-Robots-Tag
X-AH-Environment
X-Turbo-Charged-By
Request-Context
EagleId
X-Proxy-Cache
X-Cache-Group
Server-Timing
X-Backend
X-Server
X-Hacker
X-Dns-Prefetch-Control
Host-Header
Report-To
X-Server-Powered-By
X-Amz-Request-Id
X-Nginx-Cache-Status
X-Amz-Id-2
Grace
X-UA-Device
X-Rq
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Page-Speed
Cf-Railgun
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Amz-Version-Id
X-Cache-Spec
X-Device
NEL
X-OneAgent-JS-Injection
X-CST
Allow
X-Vhost
X-Host
X-Backend-Server
Xkey
X-Server-Id
X-WebKit-CSP
EagleEye-TraceId
X-Dispatcher
Surrogate-Control
X-Node
Request-Id
X-Response-Time
Content-Location
X-Akam-SW-Version
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
P3p
X-ASPNET-VERSION
X-Cache-Lookup
X-Application-Context
X-Ac
X-Country
Accept-Ch
Accept-Ch-Lifetime
X-Ruxit-JS-Agent
X-Mod-Pagespeed
Accept-CH
X-Template
X-Language
X-Readtime
X-Cloud-Trace-Context
X-B3-TraceId
MS-Author-Via
Rating
Accept-CH-Lifetime
X-HW
X-Url
X-Cnection
X-Origin-Cache
X-MS-InvokeApp
X-Vname
X-PC
X-TtlSet
Edge-Control
X-Clacks-Overhead
X-ESI
X-GitHub-Request-Id
X-Trace
X-Oneagent-Js-Injection
X-ORACLE-DMS-RID
Response
Pagespeed
X-Middleton-Display
Display
X-Sol
X-Middleton-Response
X-Varnish-TTL
X-Content-Type
X-ORACLE-DMS-ECID
X-D2id
Verso
Arr-Disable-Session-Affinity
X-Vcap-Request-Id
X-Kinja-Server
X-Use-Magma
X-Kinja-Revision
X-Kinja-Build
X-Exp-Id
X-Exp-Variant
X-GoogleNews-Bot
X-Kinja
X-Cdn-Fetch
X-Country-Code
X-Goog-Hash
X-Rack-Cache
X-Powered-By-Plesk
X-Navigation-Version
X-VARITI-CCR
Service-Worker-Allowed
X-Server-Name
X-Amz-Rid
X-Webkit-CSP
X-Buckets
X-Fastly-Request-ID
X-Abt-Application-Version
X-TTL
X-Client-IP
Fastly-Restarts
X-Cache-TTL
X-Cached
X-Release
X-MSEdge-Ref
X-Element-Page-Cache
X-Dw-Request-Base-Id
X-SharePointHealthScore
SPRequestGuid
X-NF-Request-ID
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
SPIisLatency
SPRequestDuration
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-FastCGI-Cache
Public-Key-Pins
Access-Control-Request-Method
RTSS
AR-ATIME
AR-PoweredBy
Ar-Sid
AR-CACHE
Cache-Tag
AR-Request-ID
X-Edge
X-LLID
X-SRCache-Store-Status
X-Powered-CMS
X-SRCache-Fetch-Status
X-Ezoic-Cdn
X-Ruxit-Js-Agent
X-Upstream
Content-MD5
X-Version
X-HP-Webp
X-Jurisdiction
X-Origin-Upstream-Status
S
X-Recruiting
X-ECACHE
X-Mid
X-MCACHE
Fusion-Template-Id
Charset
Fusion-Source
Fusion-Content-Source
Fusion-Component-Id
Fusion-Deployment-Id
Fusion-Content-Id
X-Fastcgi-Cache
X-Mg-S
X-Px
X-DynaTrace
X-PressLabs-Stats
X-Content-Digest
X-Kinsta-Cache
X-Ttl
X-T
Fastcgi-Cache
Cache-Tags
X-Litespeed-Cache
X-Id
X-Amz-Server-Side-Encryption
X-Logged-In
X-Accel-Expires
Filters
X-Forwarded-Proto
X-Content-Security-Policy-Report-Only
Server-Node
Edge-Cache-Tag
MicrosoftSharePointTeamServices
Front-End-Https
TP-L2-Cache
TP-Cache
X-Correlation-Id
Server-Name
X-Forwarded-For
X-Grace
TCN
Nginx-Cache
X-Hits
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Debug
X-Request-Processing-Time
X-Request-Received
X-Amzn-Trace-Id
X-XRDS-LOCATION
X-B3-Sampled
X-Shield-Request-Id
X-Microsite
X-Request-Handler-Origin-Region
X-Varnish-Age
Surrogate-Key
X-Yandex-Sdch-Disable
X-AppVersion
X-Az
X-Activity-Id
X-Amz-Replication-Status
X-HS-Hub-Id
X-F-Cache
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Content-Id
Alternate-Protocol
X-Ser
X-Origin-Server
X-Goog-Metageneration
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
X-DIS-Request-ID
Accept-Charset
Nel
X-Geo-Country
X-XRDS-Location
X-Rid
X-Frontend
X-NWS-LOG-UUID
X-Git-Hash
Section-Io-Cache
Host
X-Respond-Thread
X-Time
X-Cache-Age
X-Pinterest-Direct
X-Upgrade-Enabled
Access-Control-Allow-Method
X-LB-Cache
X-DataDome
X-Hostname
X-VCache
X-Mobile-URL
X-Server-ID
X-Seen-By
MS-CV
Paypal-Debug-Id
ServerID
X-Type
Cache
X-Daa-Tunnel
X-AOL-HN
X-IPLB-Instance
X-RateLimit-Remaining
X-TT
X-Source
Healthy
Payment
X-Content-Options
X-Cache-Key
X-Varnish-Backend
X-Is-Crawler
X-App-Environment
X-Providence-Cookie
X-Route-Name
X-Request-Guid
X-Aspnet-Duration-Ms
X-Whom
X-Flags
X-Cache-Action
X-B-Cache
X-Signature
Cleartype
X-Page-Id
X-Debug-Info
Fastcgi-Useragent
X-Jobs
X-FTR-Request-ID
X-WebKit-CSP-Report-Only
X-Load-Cache
X-N
X-FB-Debug
X-Contextid
Realpath
X-Webkit-Csp
Powered-By-ChinaCache
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Mobile
X-Erf-Bev-Bev
Node
X-Rule
Refresh
X-Response-Served-From
X-Accel-Buffering
X-Cache-Expired-At
X-Original-Request-Id
X-RTag
Ms-Operation-Id
X-Wix-Request-Id
X-Drupal-Cache-Tags
X-Zen-Fury
X-Proxy
DC
Version
X-Cacheable-TTL
Referer-Policy
X-Via-JSL
X-Framework
X-HTML-Minification-Powered-By
X-Instance
X-Content-Powered-By
X-Cluster-Name
X-ProcessESI
X-Real-IP
X-RemovedCookies
X-B
Access-Control-Request-Headers
X-Cache-Control
Eomportal-Instance
Viewport
VIX-Pulpo-Upstream-Status
X-Page-View
X-Distributor
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-UUID
X-Region
X-Cache-Time
VIX-Pulpo-Node
X-FW-Server
X-Drupal-Cache-Contexts
X-FW-Static
X-FW-Type
X-IPS-LoggedIn
X-FW-Hash
X-FW-Serve
X-FW-Dynamic
X-Cached-By
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Akamai-Edgescape
X-FireWall-Port
Countrycode
X-Cache-Rule
X-Cache-Operation
Liferay-Portal
X-Yottaa-Optimizations
X-G
X-Yottaa-Metrics
X-Cache-Hit
X-Tumblr-Pixel
X-Pass-Why
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Tumblr-User
X-L-Path
X-Environment-Context
X-App-Server
Xserver
X-Nginx-Cache
DynaTrace
SRV
Server-Info
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Id
X-Debug-IsPreview
X-Debug-IsConnected
Section-Io-Origin-Status
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
X-Www-Served-By
X-Protected-By
CF-IPCountry
X-User-Agent
Ec-Rule-Version
From-Origin
Webserver
X-Tumblr-Pixel-2
X-Device-Type
X-Mode
X-Adobe-Content
X-Adobe-Loc
X-Varnish-Grace
X-UPSTREAM-Address
Meta-Geo
X-RN-RSRV
X-Handled-By
X-ES-SERVER
X-Hl-Ver
X-Endurance-Cache-Level
Retry-After
GEO-INFO
X-Uri
Cache-Tv-Group
X-MP-GENERATED-AT
X-Backend-Name
Property-Id
X-OCL
X-PHP-Host
TWC-Connection-Speed
TWC-GeoIP-Country
X-Section
Fastly-SSL
Decoy-Debug-TTL
Decoy-Debug-Status
TWC-GeoIP-LatLong
X-Pubstack
X-Origin-Hint
X-PCL
Decoy-Debug-Key
TWC-Device-Class
X-Varnishpool
X-Storage
X-FB-TRIP-ID
TWC-Locale-Group
X-Labrador-Cache-Channel
X-Access
X-Ratelimit-Limit
TWC-Privacy
Webcakes-App-Version
X-Format
X-Cache-Server
Webcakes-Region
Webcakes-App-Name
X-PERF
Cache-Status
X-Proto
X-LAGOON
X-Proxy-Build
X-Redis-Cache
X-Request-Time
X-AWS-Id
Frame-Options
X-No-Session
Mn-Server-Ip
X-NYM-Debug-Backend
Selected-Fe
X-Locale
X-ApacheServer
X-Be
X-LJ-Flow-ID
Cache-Name
X-Origin-Date
X-ProxyCache-Key
X-R9-Blue-Green-Version
X-Soup
X-Via-Fastly
X-Server-W
X-BYPASS-REASON
X-ProxyCache-Status
Country
X-VWS-Id
Apigw-Requestid
X-Site-Version
X-Web-Node
X-WA-Info
Protected
X-UA-Device-Type
X-Timing-Wait
X-Human
X-Sql-Count
X-Sql-Duration-Ms
X-Hyper-Cache
X-Xfnlog-Site
X-Hosted-By
X-Cache-TTL-Remaining
Azure-Version
X-Zipkin-Id
Azure-SlotName
AMP-Access-Control-Allow-Source-Origin
X-Routing-Service
X-Varnish-Server
X-Proxied
X-FW-Version
Azure-RegionName
Azure-InstanceId
Azure-SiteName
X-Status
X-S-Maxage
X-AIR-PT
X-Loop
X-Sorting-Hat-ShopId
X-Alternate-Cache-Key
X-Storefront-Renderer-Rendered
X-TNCMS
X-Sorting-Hat-PodId
X-ShopId
X-SayCDN-TTL
X-Say-TTL
X-Say-Cacheable
X-Shopify-Stage
X-ShardId
X-Node-Name
X-Cache-Grace
X-CCM
X-Cluster
X-Forwarded-Host
X-TT-LOGID
X-Info
X-Rendered-As
X-Is-Bot
X-GG-Cache-Date
X-Dc
X-TA-CDN-Provider
X-Revision
S-Cnection
X-Cache-Enabled
X-Qloud-Router
X-Microcachable
X-Content-Age
Uber-Trace-Id
X-Proxy-Cache-Status
X-SRV
X-NWS-UUID-VERIFY
X-Via-CDN
X-Platform
X-Azure-Ref
X-CSRF-Token
X-Backend-Host
Cache-Hits
X-App-Version
X-Varnish-Ttl
X-Ratelimit-Remaining
X-Country-Code-Real
X-FTR-Cache-Status
X-Aspnetmvc-Version
X-Detected-As
X-Cache-Host
X-FTR-DC
X-FTR-Backend-Server
X-FTR-Backend
Akamai-GRN
X-Amz-Meta-S3cmd-Attrs
X-FTR-Realm
X-FTR-Balancer
X-Amz-Apigw-Id
X-Amzn-Remapped-Content-Length
X-Amzn-RequestId
ServedBy
X-ATG-Version
X-EdgeConnect-Cache-Status
X-Cache-NGX
X-Trace-Id
X-FTR-Expires
Amp-Access-Control-Allow-Source-Origin
X-B3-SpanId
X-Cache-PHP
X-RCS-CacheZone
X-Debug-Cache
X-CS
X-Varnish-Hostname
HostName
SD-X-WS
X-Oss-Hash-Crc64ecma
X-CACHE-KEY
X-Oss-Server-Time
X-Oss-Object-Type
X-Oss-Request-Id
X-Time-Microsecs
X-Oss-Storage-Class
Tracecode
DB-Nickname
X-TX-ID
X-Akamai-Transformed
X-DynaTrace-JS-Agent
X-Nc
X-Correlation-ID
X-BCube-Filmed-By
X-Backend-TTL
X-Unique-ID
X-Air-Hostname
X-ServerID
X-Adobe-Source
X-Ms-Version
Backend
X-NewRelic-App-Data
X-Ms-Request-Id
X-Tb
T-Server
X-Location
X-NAPM-TraceId
X-Aed
X-Application
Fastcgi-X-Cache-Version
X-B-Cookie
X-ARC
X-A-Wwc
X-A-Dgt
Mobile-Detection-Method
X-A-Dam
X-Origin-CC
Meta-Geo-Continent
MD5-Digest
X-A-Dcw
Machine
Expiry
DCR-Processing-Time-Ms
X-D
X-Connection-Hash
X-Generated-On
Rendered-Blocks
X-From
BehaviorPad-Version
X-External-Request-Id
X-Generation-Time
Odigeo-Trace-Id
X-CF-Lambda-Fn
X-Cache-NE
DCR-Decision-By
X-CF-Lambda-Version
X-A-Ccd
X-Magnolia-Registration
X-A
X-Destination
X-Level-Front-Cache
X-ScT
Xc-Version
X-S-Cookie
X-S
X-Rewrite-Enabled
X-Rojux
X-SRCache-Key
X-Vtex-Remote-Cache
X-Vdms-Version
X-Vdms-Path
X-Trv-Group
X-VG-WebCache
X-Vtex-Processado-Em
X-VG-WebServer
X-Request-UUID
X-Session-Fingerprint
X-PBS-Appsvrname
X-PAYTM-SRV-ID
X-Processor
X-Owner
X-Origin-TTL
X-Cache-Var-Map
X-Cdn-Forward
X-Cache-Var
X-TrackingId
AKAMAI
X-FC-Vary-Parameters
X-Fastly-Cache
X-Thinkindot-L3
Server-Host
Locid
X-Thanos
X-Varnish-Beresp-Grace
X-OVcl-Cache
Thinkindot-CacheControl-Type
X-Fetched-On
X-Device-Os
X-Cms-Context
X-Bip
X-Core-Value
Cf-Device-Type
X-Cache-Bucket
Fastly-Backend-Name
Content-Disposition
Gh-Request-Id
X-Sucuri-ID
X-Developers
X-Mvc-Supplant-Cachable
Host-ID
Thinkindot-CacheControl
X-Azure-Ref-OriginShield
CacheControlHeader
X-Tumblr-Pixel-3
X-OVcl
X-Generated-In
Wxu-Next-Hostname
X-Reqid
Wxu-Next-Region
X-Irp-Debug
X-Policy
Wxu-Next-Commit
X-Varnish-Cache-Hits
X-B3-Traceid
X-Micro-Cache
Release
UCS
V-Age
Thinkindot-Control
Path
X-GeoIP-City
X-Geo-Header
Pagetype
Magicmarker
On-Server
X-HS-Content-Campaign-Id
Who
User-Cache-Control
X-Cache-Debug
X-Block-Status
X-Branch-Name
X-Swa-Ws
X-WADP-Cache
X-Wikidot-Static-Cache
Web-Mar-Node
X-Cache-Info
X-Wikidot-Backend
True-Client-Country-4JS
X-VServer
Ssr
X-VG-TLSProxy
Cache-Host
X-Cache-Id
X-Backend-State
Vix-Hermes-Req-Id
X-Envoy-Decorator-Operation
X-Request-URI
X-Request-Host
X-Is-Gdpr
X-JWT-State
X-IP
X-Hnp-Log
X-Gzip
X-Scheme
X-Has-Esi
X-HN
SR-User-Adfree
X-Li-Fabric
X-Node-Id
X-Old-Content-Length
X-Origin
X-Origin-Expires
X-Platform-Server
X-Nginx-Cache-Key
X-Li-Pop
X-LI-UUID
X-Ratelimit-Reset
X-Method
X-GoCache-CacheStatus
X-SIPLIST1
X-User
X-Csrf-Jwt
X-DefElseHash
X-DefHash
X-Clara-WADP
X-CGP
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-Var-Ttl
X-Developer
X-Dispatcher-Server
X-Generated-By
X-SVT-ORM-RULES
X-Skip-Cache
X-GeoIP
X-SVT-ORM-VERSION
X-Gen-Mode
X-Origin-Response-Time
X-Esi-Check
X-Eu-Site
X-Fmm-Version
X-VarnishDD-TTL
X-Fastly-Backend
Instruction
CDN-CachedAt
CDN-EdgeStorageId
CDN-Cache
CDCHOST
IsBot
Arc-Version
C-Via
HA-Ipaddr
Ha-Gx-Prefs
Cf-Bgj
DSUID
Esi-Enabled
CDN-Uid
CDN-RequestId
CDN-PullZone
CDN-RequestCountryCode
L5d-Success-Class
Apple-News-Services-Request-Url
X-Varnish-Beresp-Ttl
Apple-News-Services-Handled
Server-Ext
Server-Hostname
Sever-Int
Country-Code
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
NGX
X-RateLimit-Limit
Location
NM-Fastcgi-Cache
PB-PID
PFcat
PB-RID
X-Varnish-Beresp-Status
X-EC-Lua
X-Unique-Id
Geo-Info
X-ID
Fastly-SIE
X-DPWN-IS-SECURE
X-CUA
X-Rebelmouse-Surrogate-Control
Platform
Is-Eu
Adler-Geo
X-LB-ID
X-Varnish-Hits
X-Slack-Backend
X-Gamma-Serve
Rt-Fastcgi-Cache
L
Origin
X-Rebelmouse-Cache-Control
X-Aicache-OS
X-Cache-Tags
X-Variation
X-Hash
Fastly-SWR
X-NU-AKA-ACS-Version
X-GEO
X-Clientip
X-CLOUD-TRACE-CONTEXT
X-Varnish-Url
Fastly-Drupal-HTML
X-Cache-Backend
X-Mvc-Supplant-OutputCached
X-Matched-Rule
X-Loc
X-Goog-Meta-Goog-Reserved-File-Mtime
Lfy
Filterid
X-APP-VERSION
X-Via-Popv
CloudFront-Viewer-Country
Pics-Label
X-Via-Poph
X-PF-Uncompressing
X-Via-Popn
X-Epic-Correlation-Id
Sid
X-Cache-Expires
X-Sn-Servicetimems
X-NCache
X-Refresh
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
Pramga
X-Cdn-Origin
X-Planisys-CDN-TTL
X-Core-Mission
X-Cache-Date
Url
X-Tb-Optimization-Total-Bytes-Saved
Cmstype
X-Servername
Cmsid
Req-Svc-Chain
Svr
Kp-EeAlive
NGB
X-Served-From
Tcn
X-Request-Start
X-TraceId
A
X-FireWall-Protection
MIME-Version
Viewtype
VivaBuild
X-Error
X-Srv
M-TraceId
X-Varnish-Cacheable
Cache-Key
Source
X-Webkit-CSP-Report-Only
Cross-Origin-Opener-Policy
Arc-Country
Server-ID
GeoIp-Country-Code
X-DC
X-Vgn-Hpd-Reason
X-Response-By
Geoip-Latitude
X-NC
X-Proxy-Cachei7
TDXMobile
X-Servedbyhost
X-HS-Status
X-Geo
X-Vcl-Version
Xkeyi7
X-NGENIX-Cache
X-Vc
DataCenter
X-Air-Source
X-PHP-Backend
Server-Ttl
Content-Secure-Policy
N-Cache
HitType
X-BBXSRF
X-B3-Spanid
X-JoinUs
X-Wa
X-SaId
SID
S-Rt
X-Erf-Stays-Bingo-Pdp-Web
NtCoent-Length
X-Cache-Remote
X-Edge-Location
Resin-Trace
X-Service
X-LiteSpeed-Cache-Control
X-Li-Proto
X-Esi
X-Cache-2
X-CDN-Forward
CACHE
X-Varnish-Authentication
X-LI-Proto
D-Cc-Upstream
X-Cache-ASPX
X-Cc-Req-Id
X-Cc-Via
X-Contensis-Viewer-Groups
X-Internal-Host
X-Extlb
Cteonnt-Length
X-HOST
X-WA
X-Svr
X-Viewer-Country
Ohc-File-Size
X-RAMCache
Cross-Origin-Window-Policy
FSS-Cache
X-Forwarded-Site
Request-ID
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Sucuri-Cache
X-Host-Name
X-UA
X-HostName
X-Bc-Bl
X-Newrelic-Synthetics
X-Via-NSCOPI
X-RPM
X-Server-IP
X-ServedByHost
X-TIM-N
X-RSL
X-RPS
X-DB
X-DI
X-DW
X-VCL-Version
X-DSS
Hostname
X-Proxy-Upstream
X-Cs
X-Cache-Config
GeoIP-Latitude
GeoIP-Country-Code
X-VC-Cache
CF-Cached-On
X-Origin-Time
X-Req
X-PJAX-URL
X-Gdpr
X-API-Version
Memcached
Mail-Subject
LB
X-Date
Surrogated-Key
X-FPC
X-Nyt-Route
X-Accel-Expires-Debug
We-Hiring
XServer
Cache-Provider
X-NodeID
X-Kraken-Loop-Name
X-RateLimit-Remaining-Second
X-APP
ProcessTime
Env
X-VC
X-Kraken-Routeconfig-Destination
X-App
X-Instrumentation
X-RateLimit-Limit-Second
X-SN
X-ZONE
X-Check-Cacheable
X-Action
X-Server-Lifecycle-Phase
Ohc-Cache-HIT
Server-Id
X-Edge-Location-Klb
X-SB
X-Oss-Cdn-Auth
X-Sigma
X-Rocket-Build-Number
Upgrade-Insecure-Requests
X-Region-Sid
X-Sigma-Backend
X-Webstats-RespID
X-Men
X-CF-Powered-By
X-Fpc
X-Provided-By
X-URL
X-Dynatrace-Js-Agent
X-Swift-Error
X-FORWARDED-FOR
VNS-Age
CPC-Cache
X-MSEdge-Features
Mime-Version
W
Memory
Time
X-MSEdge-Flight
X-Depends-On
VNS-Cache
CPC-Age
X-SD-PageType
X-Air-Trace-Id
Srv
X-Cdn-Request-ID
X-CSRF-TOKEN
X-UnsetCookies
Cdn
X-Ftr-Cache-Host
X-BACKEND-TTL
X-Render-Time
X-BBC-Edge-Cache-Status
CDN
X-Dw-Trace-Id
X-TIME
X-Client-Ip
X-Akamai-Pragma-Client-IP
X-Zone
X-ServerName
X-Parent-Response-Time
X-ABtesting
EpKe-Alive
X-NGINX-Cache
Dnion-Transfer-Encoding
X-Flog
X-Fastly-Backend-Reqs
X-Fastly-Request-Id
X-Hello
Cf-Ipcountry
X-Dynatrace
Media-Length
X-Worker
Processtime
State
X-Pad
X-Oracle-DMS-ECID
X-Cache-Tag
Vha6-Origin
X-Acquia-Application-Trace
Proxy-Connection
X-Acquia-Application-UUID
Fastcgi-Cache-TTL
X-FTR-Cache-Host
X-Auto-Login
X-Presslabs-Stats
My-App
X-Pf-Uncompressing
X-Acquia-Site
X-Acquia-Purge-Tags
Epwk-X-Cache
PICS-Label
X-Minions-Version
X-Ua
X-LiteSpeed-Tag
X-Snapshot-Date
X-Cluster-Node
X-BBC-Origin-Response-Status
X-ElasticPress-Search
X-Via-PopN
X-Via-PopH
X-Via-PopV
X-Traceid
X-CACHE-AGE
X-MiniProfiler-Ids
X-Ftr-Request-Id
X-Request-URL
X-Akamai-ERPolicy
X-IN-APIGATEWAYSSL
X-Akamai-ERRuleID
X-IN-APIGATEWAY
X-ElasticPress-Query
X-Vcache
X-Varnish-URL
X-Varnish-Beresp-TTL
Xet-Cookie
X-Ms-Meta-Originalurl
X-Ms-Meta-Staticbatchstarttime
Datacenter
X-Lb-Id
CountryCode
X-Mg-Request-UUID
X-Apw-Access-Token
X-Apw-Hits
X-Apw-Access-Object
X-Apw-Access-Action
X-Redis-Duration-Ms
OT-Force-Account-Verify
X-Cache-Status-Check
X-Mg-Request-Id
X-Ftr-Dc
X-Ftr-Realm
X-Ftr-Balancer
X-Ftr-Backend-Server
Warning
X-Ftr-Backend
Phost
Content-Style-Type
X-Debug-Cache-Store
X-Storefront-Renderer-Verified
X-Tid
X-C
Environment
Ohc-Response-Time
X-Amz-Meta-Cb-Modifiedtime
X-Debug-Cache-Fetch
X-Litespeed-Cache-Control
Content-Script-Type
URI
X-Redis-Count
NnCoection
X-B3-Parentspanid
Inserted-Into-Cache-At