Threat Level: green Handler on Duty: Jim Clausing

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
X-XSS-Protection
CF-RAY
Cf-Request-Id
CF-Cache-Status
Last-Modified
Accept-Ranges
Link
Pragma
Expect-CT
ETag
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Cache-Status
X-Request-ID
X-Generator
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Content-Security-Policy
Content-Encoding
X-CDN
X-Envoy-Upstream-Service-Time
Status
X-Ua-Compatible
Feature-Policy
Access-Control-Expose-Headers
X-AspNetMvc-Version
X-Drupal-Dynamic-Cache
Access-Control-Max-Age
X-Xss-Protection
X-Via
Upgrade
Keep-Alive
X-Ws-Request-Id
X-Turbo-Charged-By
X-Age
X-AH-Environment
X-Robots-Tag
Request-Context
X-Proxy-Cache
EagleId
X-Cache-Group
Server-Timing
X-Backend
X-Hacker
X-Amz-Request-Id
Report-To
X-Server
Host-Header
X-Amz-Id-2
X-Server-Powered-By
X-UA-Device
Grace
X-Nginx-Cache-Status
X-LiteSpeed-Cache
X-Dns-Prefetch-Control
X-Varnish-Cache
X-Rq
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Swift-SaveTime
X-Page-Speed
Cf-Railgun
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
NEL
X-Amz-Version-Id
X-OneAgent-JS-Injection
Xkey
X-WebKit-CSP
Allow
X-Cache-Spec
X-Backend-Server
X-Host
X-Vhost
X-CST
X-Device
EagleEye-TraceId
X-Server-Id
Surrogate-Control
Request-Id
X-Dispatcher
Accept-CH
X-Node
X-Kinja-Server-Push
Content-Location
X-Response-Time
Accept-CH-Lifetime
X-Akam-SW-Version
X-Ruxit-JS-Agent
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-ASPNET-VERSION
X-Template
X-Language
X-Ac
X-Application-Context
X-Country
X-Readtime
X-Cloud-Trace-Context
X-Cache-Lookup
X-Mod-Pagespeed
MS-Author-Via
X-Origin-Cache
X-B3-TraceId
Rating
X-MS-InvokeApp
X-Cnection
X-HW
X-ORACLE-DMS-ECID
X-Url
X-TtlSet
X-PC
X-Vname
Accept-Ch
X-Clacks-Overhead
X-ESI
Edge-Control
X-GitHub-Request-Id
X-FastCGI-Cache
Accept-Ch-Lifetime
X-Trace
X-Middleton-Response
X-Middleton-Display
Response
X-Sol
Pagespeed
Display
X-Content-Type
X-Exp-Variant
X-Exp-Id
X-D2id
Verso
X-GoogleNews-Bot
X-Kinja
X-Use-Magma
X-Kinja-Server
X-Kinja-Revision
X-Kinja-Build
X-Cdn-Fetch
X-Buckets
Arr-Disable-Session-Affinity
X-Vcap-Request-Id
X-Server-Name
X-Goog-Hash
X-Rack-Cache
X-Varnish-TTL
X-Country-Code
Service-Worker-Allowed
X-Navigation-Version
X-Abt-Application-Version
X-VARITI-CCR
X-Amz-Rid
X-ORACLE-DMS-RID
X-Oneagent-Js-Injection
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
X-Powered-By-Plesk
X-Client-IP
X-Cache-TTL
SPRequestGuid
X-SharePointHealthScore
X-TTL
SPRequestDuration
SPIisLatency
X-Release
X-Fastly-Request-ID
X-MSEdge-Ref
X-Dw-Request-Base-Id
Fastly-Restarts
X-Element-Page-Cache
X-Cached
X-NF-Request-ID
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
RTSS
Public-Key-Pins
X-Origin-Upstream-Status
X-Edge
Ar-Sid
AR-ATIME
AR-CACHE
AR-PoweredBy
AR-Request-ID
X-Px
Access-Control-Request-Method
X-Webkit-CSP
X-LLID
X-Powered-CMS
Fusion-Content-Id
Fusion-Template-Id
Fusion-Content-Source
Fusion-Deployment-Id
Fusion-Component-Id
Fusion-Source
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Upstream
X-Ezoic-Cdn
Content-MD5
X-Pinterest-Direct
X-Jurisdiction
X-HP-Webp
X-Amz-Server-Side-Encryption
X-MCACHE
X-Mid
X-ECACHE
X-Recruiting
X-Content-Digest
Charset
S
X-Ttl
X-Mg-S
Cache-Tag
X-PressLabs-Stats
X-Aspnetmvc-Version
MicrosoftSharePointTeamServices
TCN
X-Version
X-Debug
Fastcgi-Cache
Front-End-Https
X-XRDS-Location
X-Content-Security-Policy-Report-Only
X-T
X-Grace
Filters
X-Kinsta-Cache
Cache-Tags
Server-Node
Edge-Cache-Tag
X-Forwarded-Proto
X-Id
X-Yandex-Sdch-Disable
X-Accel-Expires
X-Cache-Key
X-Amzn-Trace-Id
X-Correlation-Id
X-Logged-In
Server-Name
X-Forwarded-For
Nginx-Cache
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Varnish-Age
Surrogate-Key
Powered-By-ChinaCache
X-DynaTrace
X-B3-Sampled
X-Hits
X-Microsite
X-DIS-Request-ID
X-Request-Received
X-Request-Handler-Origin-Region
X-Request-Processing-Time
TP-L2-Cache
TP-Cache
X-Ser
X-Shield-Request-Id
X-Activity-Id
X-AppVersion
X-Az
X-Amz-Replication-Status
X-Server-ID
X-HS-Combine-CSS
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Content-Id
X-FTR-Request-ID
X-F-Cache
Accept-Charset
X-Git-Hash
X-Origin-Server
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-GUploader-UploadID
X-Respond-Thread
X-Hostname
X-Geo-Country
X-DataDome
X-LB-Cache
Section-Io-Cache
X-Upgrade-Enabled
X-Rid
X-Frontend
X-Cache-Age
Access-Control-Allow-Method
X-Mobile-URL
Host
Cleartype
Healthy
Alternate-Protocol
Paypal-Debug-Id
X-Type
ServerID
X-IPLB-Instance
MS-CV
X-Content-Options
X-WebKit-CSP-Report-Only
Cache
X-Ruxit-Js-Agent
Payment
X-App-Environment
X-Debug-Info
X-Varnish-Backend
X-Route-Name
X-Is-Crawler
X-Providence-Cookie
X-Flags
X-AOL-HN
X-Aspnet-Duration-Ms
X-Request-Guid
X-Whom
X-B-Cache
X-Signature
X-Cache-Action
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Page-Id
Fastcgi-Useragent
X-TT
X-TEC-API-VERSION
X-Seen-By
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Jobs
X-VCache
X-Mobile
X-NWS-LOG-UUID
X-N
X-Source
X-Load-Cache
X-Time
X-Browser-Type
X-XRDS-LOCATION
X-Via-JSL
X-RateLimit-Remaining
X-Cached-By
X-Akamai-Edgescape
Nel
X-FB-Debug
X-Daa-Tunnel
X-Cache-Operation
DynaTrace
Viewport
X-Cache-Rule
X-Litespeed-Cache
Version
X-Accel-Buffering
X-Original-Request-Id
X-Response-Served-From
X-Rule
Refresh
X-Drupal-Cache-Tags
DC
X-Framework
X-Zen-Fury
X-Proxy
X-Instance
X-ProcessESI
X-RemovedCookies
X-Tt-Trace-Tag
GEO-INFO
X-Tt-Trace-Host
Referer-Policy
Realpath
X-Fastcgi-Cache
X-RTag
Ms-Operation-Id
X-Cacheable-TTL
X-Contextid
X-UUID
X-HTML-Minification-Powered-By
X-Region
Access-Control-Request-Headers
X-Real-IP
X-FW-Hash
X-FW-Type
X-FW-Server
X-FW-Serve
X-FW-Static
X-Cache-Time
X-Yottaa-Optimizations
X-FW-Dynamic
X-Page-View
X-Yottaa-Metrics
X-Drupal-Cache-Contexts
X-Distributor
X-Cache-Expired-At
X-Environment-Context
X-Node-Name
X-L-Path
X-B
Eomportal-Instance
X-Wix-Request-Id
VIX-Pulpo-Upstream-Status
Liferay-Portal
VIX-Pulpo-Node
X-Cluster-Name
Countrycode
Node
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Tumblr-User
X-Tumblr-Pixel
X-Cache-Control
X-G
X-Content-Powered-By
X-IPS-LoggedIn
X-User-Agent
X-Amz-Meta-S3cmd-Attrs
X-Cache-Hit
Webserver
X-Tumblr-Pixel-2
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Id
Section-Io-Origin-Status
SRV
From-Origin
Server-Info
X-Pass-Why
X-Revision
X-App-Server
Protected
X-Ratelimit-Limit
Ec-Rule-Version
Cache-Status
X-Protected-By
X-Backend-Name
X-Cache-Server
X-FireWall-Port
X-Oracle-Dms-Rid
Frame-Options
X-ES-SERVER
X-Hyper-Cache
Meta-Geo
Retry-After
X-Hl-Ver
X-UPSTREAM-Address
X-RN-RSRV
X-Handled-By
X-Mode
X-Forwarded-Host
X-NYM-Debug-Backend
CF-IPCountry
X-Storage
X-Soup
X-Endurance-Cache-Level
X-Locale
X-Site-Version
X-FB-TRIP-ID
X-Section
X-Cache-Grace
TWC-Connection-Speed
X-Be
Property-Id
X-Human
X-Origin-Hint
X-Pubstack
X-Format
X-Access
X-Via-CDN
Decoy-Debug-TTL
Decoy-Debug-Status
Webcakes-App-Version
Webcakes-App-Name
Fastly-SSL
TWC-Privacy
Decoy-Debug-Key
Country
TWC-Locale-Group
TWC-GeoIP-LatLong
Webcakes-Region
X-Www-Served-By
X-Web-Node
X-Varnishpool
TWC-Device-Class
TWC-GeoIP-Country
X-Adobe-Loc
X-Adobe-Content
X-Proto
X-Proxy-Build
X-ApacheServer
Selected-Fe
Azure-InstanceId
X-FW-Version
X-PCL
X-PERF
X-Say-Cacheable
X-OCL
X-Redis-Cache
X-UA-Device-Type
X-TT-LOGID
Azure-SlotName
Azure-SiteName
Azure-RegionName
X-Timing-Wait
Azure-Version
X-Say-TTL
Cache-Tv-Group
X-SayCDN-TTL
Cache-Name
X-AIR-PT
X-BYPASS-REASON
X-Labrador-Cache-Channel
X-PHP-Host
X-Sql-Duration-Ms
X-Uri
X-Via-Fastly
X-WA-Info
X-Sql-Count
X-Server-W
X-Origin-Date
X-ProxyCache-Key
X-ProxyCache-Status
X-Varnish-Ttl
X-LAGOON
X-No-Session
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-Backend
X-Country-Code-Real
S-Cnection
X-FTR-DC
X-FTR-Backend-Server
X-FTR-Realm
X-S-Maxage
X-R9-Blue-Green-Version
X-LJ-Flow-ID
Mn-Server-Ip
X-AWS-Id
X-Qloud-Router
X-VWS-Id
X-TNCMS
X-Hosted-By
X-Loop
X-Request-Time
X-Status
X-FTR-Expires
X-Cluster
X-CCM
X-Cache-TTL-Remaining
X-MP-GENERATED-AT
X-Xfnlog-Site
X-Proxied
X-Zipkin-Id
X-Routing-Service
Cache-Hits
X-ShardId
X-ShopId
X-Alternate-Cache-Key
X-Storefront-Renderer-Rendered
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Shopify-Stage
X-Ratelimit-Remaining
X-Is-Bot
X-Cache-Var-Map
X-Cache-Var
X-Rendered-As
X-Dynatrace
X-Unique-Id
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
AMP-Access-Control-Allow-Source-Origin
X-Air-Hostname
Xserver
X-Detected-As
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Amzn-Remapped-Content-Length
X-SRV
X-EdgeConnect-Cache-Status
X-Info
X-Webkit-Csp
Apigw-Requestid
X-Cdn
X-Cache-Host
X-Dc
X-Device-Type
X-Microcachable
SD-X-WS
X-B3-Traceid
X-Cache-Enabled
X-GEO
X-Nginx-Cache
Amp-Access-Control-Allow-Source-Origin
X-Backend-TTL
Tracecode
X-Cache-Backend
X-Content-Age
X-Platform
X-Varnish-Grace
X-Time-Microsecs
X-Debug-IsConnected
X-Debug-IsPreview
X-APP-VERSION
X-Azure-Ref
X-Varnish-Server
X-ServerID
X-Backend-Host
DSUID
Uber-Trace-Id
X-DynaTrace-JS-Agent
X-GG-Cache-Date
X-Erf-Stays-Bingo-Pdp-Web
X-Oss-Request-Id
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
X-Oss-Storage-Class
X-Tb
X-Sucuri-ID
Akamai-GRN
PB-PID
X-BCube-Filmed-By
Arc-Version
PB-RID
X-NewRelic-App-Data
X-ATG-Version
X-ID
X-Proxy-Cache-Status
X-Trace-Id
X-Akamai-Transformed
X-Magnolia-Registration
X-Origin-Response-Time
X-Correlation-ID
DCR-Processing-Time-Ms
Expiry
Meta-Geo-Continent
X-D
Odigeo-Trace-Id
Mobile-Detection-Method
X-CF-Lambda-Fn
Fastcgi-X-Cache-Version
X-Connection-Hash
Path
X-CF-Lambda-Version
Lfy
Instruction
MD5-Digest
X-Thinkindot-L3
Machine
T-Server
X-A-Ccd
X-Application
X-ARC
X-B-Cookie
X-A-Dam
X-A-Dcw
X-A-Dgt
X-Destination
X-A-Wwc
X-Aed
X-A
Thinkindot-Control
ServedBy
Rendered-Blocks
Pramga
Backend
X-Cache-NE
SR-User-Adfree
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-Varnish-Cache-Hits
X-RCS-CacheZone
X-ScT
X-Rojux
X-VG-WebCache
X-Rewrite-Enabled
X-Generated-On
X-PAYTM-SRV-ID
X-Cache-Remote
X-From
X-Processor
Xc-Version
DCR-Decision-By
X-Generation-Time
X-Location
X-Level-Front-Cache
X-Vdms-Path
X-VG-WebServer
X-Matched-Rule
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
X-Origin-TTL
X-Origin-CC
X-Trv-Group
X-PBS-Appsvrname
X-Fetched-On
X-S-Cookie
X-Session-Fingerprint
X-External-Request-Id
X-Request-UUID
X-SRCache-Key
X-S
X-Vdms-Version
X-Device-Os
X-Varnish-Hostname
X-Adobe-Source
X-Cache-PHP
Fastly-Backend-Name
X-Node-Id
X-Mvc-Supplant-Cachable
X-Micro-Cache
Gh-Request-Id
Ssr
X-Request-URI
PFcat
X-VServer
L
L5d-Success-Class
Magicmarker
X-Reqid
X-OVcl-Cache
X-Request-Start
Locid
HA-Ipaddr
Host-ID
X-OVcl
Pagetype
Ha-Gx-Prefs
X-HN
X-Cache-Info
Release
X-Cdn-Origin
X-Cache-Date
BehaviorPad-Version
X-Bip
X-Cache-Bucket
X-FC-Vary-Parameters
X-GeoIP-City
X-Sn-Servicetimems
X-Thanos
X-Swa-Ws
X-Eu-Site
X-Csrf-Jwt
X-CGP
X-Skip-Cache
X-Backend-State
X-Wikidot-Static-Cache
X-Is-Gdpr
X-Irp-Debug
X-HS-Content-Campaign-Id
X-JWT-State
X-User
Wxu-Next-Region
X-VarnishDD-TTL
X-Developers
X-Has-Esi
X-Generated-In
X-Azure-Ref-OriginShield
X-Wikidot-Backend
X-Geo-Header
X-Tumblr-Pixel-3
X-GeoIP
Wxu-Next-Hostname
Wxu-Next-Commit
X-Cache-NGX
Cf-Device-Type
CacheControlHeader
Cache-Host
C-Via
AKAMAI
CACHE
X-Ms-Version
X-Ms-Request-Id
X-CSRF-Token
On-Server
X-Core-Value
X-NWS-UUID-VERIFY
X-Policy
Server-Ext
User-Cache-Control
X-Owner
X-Request-Host
NGX
X-Clientip
X-Cms-Context
DB-Nickname
Sever-Int
X-NC
X-Generated-By
X-Fastly-Cache
X-Envoy-Decorator-Operation
X-IP
CloudFront-Viewer-Country
X-Nginx-Cache-Key
X-Method
X-CUA
X-Cache-Tags
X-Developer
Server-Hostname
X-SVT-ORM-RULES
Cf-Bgj
X-Varnish-Hits
Apple-News-Services-Handled
X-Var-Ttl
X-SVT-ORM-VERSION
UCS
Content-Disposition
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
CDCHOST
Apple-News-Services-Request-Url
X-Hnp-Log
Fastly-SIE
Fastly-SWR
X-Host-Name
Web-Mar-Node
X-GoCache-CacheStatus
X-Debug-Cache
X-Block-Status
X-VG-TLSProxy
X-B3-Spanid
X-WADP-Cache
X-TrackingId
X-Cache-Expires
X-Cache-Debug
X-Fmm-Version
X-Fastly-Backend
V-Age
X-Gen-Mode
X-TX-ID
Server-Host
X-Clara-WADP
X-Servername
X-SIPLIST1
X-Scheme
Rt-Fastcgi-Cache
Origin
IsBot
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Origin-Expires
X-Platform-Server
X-NU-AKA-ACS-Version
X-Loc
X-Varnish-Beresp-Grace
X-DefHash
X-Cache-Id
Platform
X-Varnish-Url
X-Ratelimit-Reset
X-NCache
X-DefElseHash
NM-Fastcgi-Cache
Location
Adler-Geo
Vix-Hermes-Req-Id
True-Client-Country-4JS
X-Branch-Name
X-Varnish-CookieINHashed-On
X-Li-Pop
X-Old-Content-Length
X-Varnish-CookieHashed-On
X-Origin
X-Variation
X-Gzip
X-LI-UUID
X-Esi-Check
Is-Eu
X-Li-Fabric
X-Dispatcher-Server
X-Varnish-Remaining-TTL
X-DPWN-IS-SECURE
X-Varnish-Beresp-Status
X-Varnish-Beresp-Ttl
X-CS
X-Varnish-Cacheable
CDN-PullZone
X-Goog-Meta-Goog-Reserved-File-Mtime
Fastly-Drupal-HTML
CDN-RequestCountryCode
CDN-Uid
X-Gamma-Serve
CDN-EdgeStorageId
X-Hash
X-Refresh
X-PF-Uncompressing
X-Response-By
CDN-Cache
CDN-CachedAt
X-Slack-Backend
X-App-Version
CDN-RequestId
S-Rt
X-NAPM-TraceId
Url
X-EC-Lua
HostName
X-Aicache-OS
Pics-Label
Xkeyi7
X-Mvc-Supplant-OutputCached
X-Proxy-Cachei7
X-Core-Mission
X-CDN-Forward
Cross-Origin-Window-Policy
Content-Secure-Policy
X-CACHE-GROUP
X-URL
X-BBXSRF
N-Cache
X-Sucuri-Cache
X-Cache-2
X-Cdn-Forward
X-FireWall-Protection
X-B3-SpanId
Ohc-File-Size
X-Varnish-Authentication
X-Cache-ASPX
X-Cc-Req-Id
X-LB-ID
D-Cc-Upstream
X-Contensis-Viewer-Groups
Cteonnt-Length
X-Cc-Via
Sid
X-Via-Poph
X-Via-Popn
X-Via-Popv
Esi-Enabled
X-Wa
X-Servedbyhost
X-Svr
X-Tb-Optimization-Total-Bytes-Saved
X-Epic-Correlation-Id
Source
X-RateLimit-Limit
X-TA-CDN-Provider
MIME-Version
X-Error
X-DC
X-Server-IP
X-Srv
XServer
Geoip-Latitude
X-API-Version
GeoIp-Country-Code
X-Gdpr
X-Cache-Config
X-FPC
X-TIME
X-Unique-ID
X-Nyt-Route
X-Origin-Time
X-TraceId
X-Cs
X-Webkit-CSP-Report-Only
X-Nc
X-SN
Hostname
Who
Req-Svc-Chain
X-NGINX-Cache
X-VC
HitType
Ohc-Cache-HIT
X-LI-Proto
X-Webstats-RespID
X-NodeID
Server-Ttl
X-VCL-Version
X-SB
X-Fastly-Request-Id
X-HS-Status
X-LiteSpeed-Cache-Control
X-SD-PageType
X-Check-Cacheable
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
Server-ID
X-Planisys-CDN-Rules
Country-Code
X-Ua
Geo-Info
Svr
Cmstype
X-Esi
SID
Cmsid
Kp-EeAlive
EpKe-Alive
X-Served-From
X-Viewer-Country
X-BBC-Edge-Cache-Status
X-Render-Time
VivaBuild
Viewtype
NtCoent-Length
X-HOST
X-Vgn-Hpd-Reason
X-Worker
X-Ftr-Cache-Host
Request-ID
X-Auto-Login
X-RAMCache
Cache-Key
A
X-Dynatrace-Js-Agent
X-UA
X-DB
Resin-Trace
X-Vcl-Version
X-DI
X-TIM-N
Cache-Provider
X-DSS
X-DW
X-CCDN-CacheTTL
X-RPS
X-RSL
X-CSRF-TOKEN
X-CCDN-Origin-Time
X-CACHE-KEY
M-TraceId
ProcessTime
X-RPM
X-Hcs-Proxy-Type
Upgrade-Insecure-Requests
X-CF-Powered-By
X-Li-Proto
GeoIP-Latitude
X-Cluster-Node
GeoIP-Country-Code
CDN
Server-Id
TDXMobile
Cross-Origin-Opener-Policy
X-App
Arc-Country
X-Newrelic-Synthetics
X-Internal-Host
X-Air-Source
Processtime
X-Action
Datacenter
X-FTR-Cache-Host
X-Vc
Tcn
X-Oss-Cdn-Auth
X-Fpc
Filterid
CF-Cached-On
X-CLOUD-TRACE-CONTEXT
OT-Force-Account-Verify
WZWS-RAY
Mime-Version
X-WA
X-ServedByHost
X-Geo
X-BBC-Origin-Response-Status
Srv
X-FORWARDED-FOR
X-HITS
X-HostName
X-Dw-Trace-Id
X-MSEdge-Flight
X-ABtesting
X-Service
Cdn
X-Lb-Id
X-Hello
X-Cache-Tag
X-Via-PopV
X-Via-PopN
X-ND-Cache
X-Via-PopH
X-Pinterest-Sli-Latency-Threshold
X-BACKEND-TTL
X-Fastly-Backend-Reqs
X-Flog
X-Pinterest-Sli-Response-Type
X-Parent-Response-Time
X-MSEdge-Features
Proxy-Connection
X-Pinterest-Sli-Endpoint-Name
X-Client-Ip
X-CACHE-AGE
W
X-Forwarded-Site
FSS-Cache
X-Via-NSCOPI
NGB
Dnion-Transfer-Encoding
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-SaId
X-Cdn-Request-ID
X-JoinUs
X-PHP-Backend
X-Presslabs-Stats
X-Oracle-DMS-ECID
X-Vcache
Vha6-Origin
X-Pf-Uncompressing
DataCenter
Media-Length
X-Extlb
URI
PICS-Label
X-Edge-Location
X-Acc-Rdl
X-Acc-Debug-Context
CountryCode
Mail-Subject
X-Provided-By
X-Pad
Epwk-X-Cache
X-LiteSpeed-Tag
X-Akamai-Request-ID
X-NGENIX-Cache
X-VC-Cache
X-ZONE
X-UnsetCookies
Inserted-Into-Cache-At
X-Region-Sid
X-Request-URL
Memcached
X-Akamai-Pragma-Client-IP
X-PJAX-URL
X-RateLimit-Remaining-Second
X-Bc-Bl
We-Hiring
X-Depends-On
X-MiniProfiler-Ids
X-RateLimit-Limit-Second
Surrogated-Key
Cf-Ipcountry
X-Proxy-Upstream
X-Req
Edge-Copy-Time
Content-Script-Type
LB
X-Acquia-Application-Trace
X-Accel-Expires-Debug
Content-Style-Type
X-Date
X-ElasticPress-Search
X-Akamai-ERRuleID
X-Request-Url
X-Swift-Error
X-Rocket-Build-Number
X-Akamai-ERPolicy
X-Traceid
X-B3-Parentspanid
X-Via-SSL
X-Via-Edge
X-Csrf-Token
X-Sigma
X-Sigma-Backend
X-Acquia-Site
X-Varnish-Beresp-TTL
X-Acquia-Application-UUID
X-Ms-Meta-Originalurl
X-Acquia-Purge-Tags
X-ElasticPress-Query
X-Ms-Meta-Staticbatchstarttime
X-APP
X-Tid
Env
X-Zone
X-Varnish-URL
Xet-Cookie
X-C
X-Litespeed-Cache-Control
X-Storefront-Renderer-Verified
X-Snapshot-Date
X-Redis-Duration-Ms
Environment
X-Redis-Count
NnCoection
Phost
Time
X-Debug-Cache-Fetch
Memory
Ohc-Response-Time
X-ServerName
Akamai-Age-Ms
X-Debug-Cache-Store