Threat Level: green Handler on Duty: Russ McRee

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Cf-Request-Id
CF-RAY
CF-Cache-Status
Last-Modified
X-XSS-Protection
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Xss-Protection
X-Cache-Status
X-Generator
X-Request-ID
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Content-Security-Policy
Content-Encoding
X-CDN
X-Ua-Compatible
X-Envoy-Upstream-Service-Time
Status
Feature-Policy
X-AspNetMvc-Version
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Access-Control-Max-Age
X-Via
Upgrade
Keep-Alive
X-Ws-Request-Id
X-Age
X-Turbo-Charged-By
X-AH-Environment
X-Robots-Tag
Request-Context
X-Proxy-Cache
EagleId
X-Cache-Group
Server-Timing
X-Backend
X-Hacker
Report-To
X-Amz-Request-Id
X-Server
Host-Header
X-Amz-Id-2
X-Server-Powered-By
X-Nginx-Cache-Status
Grace
X-UA-Device
X-LiteSpeed-Cache
X-Varnish-Cache
X-Rq
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Page-Speed
X-Dns-Prefetch-Control
Cf-Railgun
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Amz-Version-Id
NEL
X-OneAgent-JS-Injection
X-WebKit-CSP
X-Cache-Spec
Xkey
Allow
X-Backend-Server
X-Host
X-Device
X-CST
X-Vhost
EagleEye-TraceId
X-Server-Id
Surrogate-Control
Request-Id
X-Dispatcher
X-Node
Content-Location
X-Response-Time
X-Akam-SW-Version
Accept-CH
X-Ruxit-JS-Agent
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Accept-CH-Lifetime
X-ASPNET-VERSION
X-Ac
X-Template
X-Application-Context
X-Language
X-Country
X-Cache-Lookup
X-Readtime
X-Mod-Pagespeed
X-Cloud-Trace-Context
MS-Author-Via
X-B3-TraceId
X-Origin-Cache
Accept-Ch
Rating
X-Cnection
X-MS-InvokeApp
X-Kinja-Server-Push
Accept-Ch-Lifetime
X-HW
X-Url
X-PC
X-Vname
X-TtlSet
X-ORACLE-DMS-ECID
X-Clacks-Overhead
X-GitHub-Request-Id
X-ESI
Edge-Control
X-Trace
X-Middleton-Response
Display
X-Sol
X-Middleton-Display
Response
Pagespeed
X-FastCGI-Cache
X-Content-Type
X-Vcap-Request-Id
X-D2id
X-Kinja-Server
X-Use-Magma
Verso
X-Kinja-Revision
X-Kinja-Build
X-Exp-Variant
X-GoogleNews-Bot
X-Kinja
X-Cdn-Fetch
X-Exp-Id
Arr-Disable-Session-Affinity
X-Buckets
X-Goog-Hash
X-Rack-Cache
X-Server-Name
X-Country-Code
Service-Worker-Allowed
X-Oneagent-Js-Injection
X-Navigation-Version
X-ORACLE-DMS-RID
X-Abt-Application-Version
X-VARITI-CCR
X-Varnish-TTL
X-Amz-Rid
X-Powered-By-Plesk
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-Client-IP
X-Cache-TTL
X-Fastly-Request-ID
X-SharePointHealthScore
SPRequestGuid
X-Release
SPRequestDuration
SPIisLatency
X-MSEdge-Ref
Fastly-Restarts
X-Dw-Request-Base-Id
X-Element-Page-Cache
X-Cached
X-NF-Request-ID
X-TTL
Public-Key-Pins
RTSS
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
X-Webkit-CSP
Ar-Sid
AR-ATIME
AR-CACHE
AR-PoweredBy
AR-Request-ID
X-Edge
Access-Control-Request-Method
X-Origin-Upstream-Status
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-LLID
X-Px
X-Ttl
X-Powered-CMS
Fusion-Content-Source
Fusion-Deployment-Id
Fusion-Template-Id
Fusion-Component-Id
Fusion-Source
Fusion-Content-Id
X-Ezoic-Cdn
X-Upstream
Content-MD5
X-Jurisdiction
X-HP-Webp
Cache-Tag
X-MCACHE
X-ECACHE
X-Mid
Charset
X-Recruiting
X-Amz-Server-Side-Encryption
S
X-Content-Digest
X-Mg-S
X-Version
X-Pinterest-Direct
X-PressLabs-Stats
MicrosoftSharePointTeamServices
Fastcgi-Cache
TCN
X-Debug
Front-End-Https
X-Content-Security-Policy-Report-Only
X-T
X-Kinsta-Cache
X-Id
Filters
X-Grace
Cache-Tags
Server-Node
Edge-Cache-Tag
X-Forwarded-Proto
X-Logged-In
X-Accel-Expires
X-Correlation-Id
X-Forwarded-For
X-Amzn-Trace-Id
Server-Name
X-Yandex-Sdch-Disable
Nginx-Cache
Surrogate-Key
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Varnish-Age
X-XRDS-Location
X-DynaTrace
TP-L2-Cache
TP-Cache
X-B3-Sampled
X-Request-Processing-Time
X-Request-Received
X-Server-ID
X-Ser
X-Microsite
X-Request-Handler-Origin-Region
X-Hits
X-DIS-Request-ID
X-Shield-Request-Id
X-Cache-Key
X-AppVersion
X-Az
X-Activity-Id
Powered-By-ChinaCache
X-Amz-Replication-Status
X-F-Cache
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Cache-Config
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Metageneration
X-Goog-Generation
Accept-Charset
X-Origin-Server
X-Litespeed-Cache
X-Git-Hash
X-FTR-Request-ID
X-Geo-Country
X-Respond-Thread
X-Hostname
Nel
X-XRDS-LOCATION
X-LB-Cache
X-DataDome
X-Rid
X-Upgrade-Enabled
Section-Io-Cache
Cache
X-Frontend
Access-Control-Allow-Method
Alternate-Protocol
X-Ruxit-Js-Agent
X-Mobile-URL
Host
X-Aspnetmvc-Version
X-Cache-Age
Cleartype
Paypal-Debug-Id
MS-CV
X-Content-Options
X-IPLB-Instance
X-Type
Healthy
X-Varnish-Backend
X-Seen-By
X-WebKit-CSP-Report-Only
X-AOL-HN
X-Whom
X-App-Environment
X-VCache
Payment
ServerID
X-Providence-Cookie
X-TT
X-Request-Guid
X-Route-Name
X-Signature
X-B-Cache
X-Is-Crawler
X-Flags
X-Aspnet-Duration-Ms
X-Jobs
X-Page-Id
X-Cache-Action
Fastcgi-Useragent
X-Time
X-Debug-Info
X-NWS-LOG-UUID
X-Source
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Fastcgi-Cache
X-TEC-API-ROOT
X-N
X-Mobile
X-Load-Cache
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-FB-Debug
X-RateLimit-Remaining
X-Via-JSL
X-Daa-Tunnel
X-Cached-By
X-Akamai-Edgescape
Version
Viewport
Refresh
X-Original-Request-Id
X-Accel-Buffering
X-Rule
X-Response-Served-From
X-Drupal-Cache-Tags
X-Cache-Operation
X-Zen-Fury
X-Proxy
DC
X-Framework
X-Cache-Rule
X-Cacheable-TTL
X-ProcessESI
X-RTag
X-RemovedCookies
Ms-Operation-Id
X-Instance
X-Real-IP
X-Contextid
X-Wix-Request-Id
X-Cache-Time
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Region
Referer-Policy
Access-Control-Request-Headers
Realpath
DynaTrace
X-HTML-Minification-Powered-By
X-Distributor
Node
X-Drupal-Cache-Contexts
X-Page-View
X-UUID
X-Cache-Expired-At
X-FW-Server
X-FW-Hash
Eomportal-Instance
X-FW-Static
VIX-Pulpo-Upstream-Status
X-FW-Serve
X-Yottaa-Optimizations
X-FW-Dynamic
Countrycode
X-Yottaa-Metrics
VIX-Pulpo-Node
X-FW-Type
X-L-Path
X-Environment-Context
X-B
GEO-INFO
X-Cluster-Name
X-Cache-Control
Liferay-Portal
X-Content-Powered-By
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-G
X-IPS-LoggedIn
X-Node-Name
X-Cache-Hit
X-User-Agent
Server-Info
X-Varnish-Ttl
X-Tumblr-Pixel-2
X-Ratelimit-Limit
Webserver
From-Origin
X-App-Server
Section-Io-Origin-Time-Seconds
Section-Io-Id
Section-Io-Origin-Status
Section-Origin-Responded
X-Pass-Why
Protected
Ec-Rule-Version
SRV
X-Amz-Meta-S3cmd-Attrs
X-FireWall-Port
X-Protected-By
X-Revision
X-Cache-Server
CF-IPCountry
X-Backend-Name
Frame-Options
X-Hl-Ver
X-Hyper-Cache
X-Mode
X-RN-RSRV
X-UPSTREAM-Address
X-Www-Served-By
X-Handled-By
Meta-Geo
X-ES-SERVER
X-Endurance-Cache-Level
Xserver
Cache-Status
X-Site-Version
X-FB-TRIP-ID
X-Forwarded-Host
X-NYM-Debug-Backend
X-Soup
X-Locale
X-Storage
X-Varnishpool
X-Be
X-Pubstack
X-Cache-Grace
X-Web-Node
Decoy-Debug-Status
Decoy-Debug-Key
Cache-Tv-Group
Fastly-SSL
Retry-After
Decoy-Debug-TTL
TWC-Locale-Group
X-Origin-Hint
Property-Id
X-Format
TWC-Connection-Speed
X-SayCDN-TTL
TWC-GeoIP-Country
X-OCL
X-Section
TWC-GeoIP-LatLong
TWC-Privacy
X-Human
X-Origin-Date
Selected-Fe
X-Timing-Wait
X-Uri
X-Proto
X-PHP-Host
Webcakes-App-Name
Webcakes-App-Version
X-Proxy-Build
Webcakes-Region
X-UA-Device-Type
X-TT-LOGID
X-Say-Cacheable
TWC-Device-Class
X-Say-TTL
Country
X-Labrador-Cache-Channel
Cache-Name
X-Redis-Cache
X-PCL
X-Access
X-Adobe-Content
X-Adobe-Loc
X-ApacheServer
X-BYPASS-REASON
X-FW-Version
X-AIR-PT
Azure-RegionName
Azure-SlotName
Azure-Version
X-LAGOON
Azure-SiteName
X-Loop
X-Sql-Duration-Ms
X-TNCMS
X-Via-Fastly
X-WA-Info
X-Sql-Count
X-Server-W
X-No-Session
X-PERF
X-ProxyCache-Key
X-ProxyCache-Status
Azure-InstanceId
X-Hosted-By
X-Ratelimit-Remaining
X-R9-Blue-Green-Version
X-Request-Time
X-LJ-Flow-ID
X-AWS-Id
X-MP-GENERATED-AT
X-Via-CDN
X-VWS-Id
X-S-Maxage
X-Shopify-Stage
X-Storefront-Renderer-Rendered
X-Sorting-Hat-PodId
X-Status
X-Cluster
X-ShopId
X-Alternate-Cache-Key
X-ShardId
X-Qloud-Router
Mn-Server-Ip
X-Sorting-Hat-ShopId
S-Cnection
X-Cache-TTL-Remaining
X-Proxied
X-Zipkin-Id
X-Routing-Service
X-CCM
X-FTR-Backend-Server
X-FTR-Cache-Status
X-FTR-Backend
X-FTR-Realm
X-FTR-Balancer
X-Country-Code-Real
X-FTR-DC
X-Rendered-As
Cache-Hits
X-Xfnlog-Site
X-Is-Bot
X-FTR-Expires
X-Tec-Api-Root
X-Oracle-Dms-Rid
X-Tec-Api-Origin
X-Dc
X-Tec-Api-Version
AMP-Access-Control-Allow-Source-Origin
X-Device-Type
X-Nginx-Cache
X-Cache-Var-Map
Apigw-Requestid
X-Cdn
X-Detected-As
X-Cache-Var
X-Debug-IsConnected
X-Info
X-Air-Hostname
X-Debug-IsPreview
X-SRV
X-Cache-Host
X-Amzn-RequestId
X-Amzn-Remapped-Content-Length
X-Amz-Apigw-Id
X-EdgeConnect-Cache-Status
X-Microcachable
X-Cache-Enabled
X-Unique-Id
X-Content-Age
X-Varnish-Grace
X-Dynatrace
X-Varnish-Server
SD-X-WS
X-Platform
Tracecode
X-DynaTrace-JS-Agent
X-Azure-Ref
X-Time-Microsecs
Uber-Trace-Id
X-Backend-Host
X-Backend-TTL
X-Cache-Backend
X-GEO
X-ServerID
X-Erf-Stays-Bingo-Pdp-Web
Amp-Access-Control-Allow-Source-Origin
X-GG-Cache-Date
X-APP-VERSION
X-Proxy-Cache-Status
X-CSRF-Token
X-Oss-Request-Id
DSUID
Akamai-GRN
X-Tb
X-Oss-Object-Type
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
X-NewRelic-App-Data
X-ATG-Version
X-BCube-Filmed-By
X-Correlation-ID
X-Trace-Id
Backend
ServedBy
PB-PID
Arc-Version
X-Sucuri-ID
X-NWS-UUID-VERIFY
X-Akamai-Transformed
PB-RID
Pramga
X-Cache-NGX
X-RCS-CacheZone
X-Cache-PHP
Release
MD5-Digest
Xc-Version
Expiry
Fastcgi-X-Cache-Version
Machine
Lfy
X-Vtex-Remote-Cache
Instruction
BehaviorPad-Version
Mobile-Detection-Method
Meta-Geo-Continent
DCR-Processing-Time-Ms
Odigeo-Trace-Id
X-Aed
X-Generation-Time
X-Generated-On
X-GeoIP-City
X-Level-Front-Cache
X-Location
X-From
X-Thinkindot-L3
X-Device-Os
X-External-Request-Id
X-Fetched-On
X-Trv-Group
X-Matched-Rule
X-Origin-CC
X-S
X-S-Cookie
X-Processor
X-Request-UUID
X-Rewrite-Enabled
X-ScT
X-PBS-Appsvrname
X-SRCache-Key
X-Session-Fingerprint
X-Origin-TTL
X-PAYTM-SRV-ID
X-Destination
X-D
X-A
Thinkindot-Control
X-A-Ccd
X-A-Dam
X-VG-WebCache
Thinkindot-CacheControl-Type
X-VG-WebServer
SR-User-Adfree
X-Vtex-Processado-Em
T-Server
Thinkindot-CacheControl
X-Vdms-Version
X-A-Dcw
X-Cache-NE
X-B-Cookie
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Connection-Hash
X-Vdms-Path
X-ARC
X-A-Dgt
X-A-Wwc
X-Rojux
X-Application
Rendered-Blocks
DCR-Decision-By
X-Magnolia-Registration
X-Varnish-Hostname
X-Origin-Response-Time
X-Cache-Date
X-Cache-Bucket
X-TrackingId
X-Micro-Cache
X-SVT-ORM-RULES
X-Mvc-Supplant-Cachable
UCS
X-Cache-Info
AKAMAI
C-Via
CacheControlHeader
X-Node-Id
X-HS-Content-Campaign-Id
X-SVT-ORM-VERSION
Cf-Device-Type
X-Irp-Debug
X-Is-Gdpr
Gh-Request-Id
Ha-Gx-Prefs
Host-ID
HA-Ipaddr
X-Sn-Servicetimems
X-Backend-State
X-Bip
L5d-Success-Class
X-Eu-Site
X-Azure-Ref-OriginShield
Fastly-Backend-Name
X-JWT-State
X-Has-Esi
X-FC-Vary-Parameters
X-OVcl-Cache
X-Owner
X-Debug-Cache
X-OVcl
Path
X-Tumblr-Pixel-3
X-VServer
X-B3-Traceid
X-Varnish-Cache-Hits
X-Csrf-Jwt
X-Geo-Header
X-Ms-Request-Id
X-GeoIP
X-Ms-Version
X-CGP
X-Reqid
Pagetype
X-Cdn-Origin
X-Thanos
X-User
X-Generated-In
X-Skip-Cache
X-TA-CDN-Provider
X-Adobe-Source
Server-Ext
X-HN
Server-Host
HostName
NGX
Server-Hostname
X-Scheme
PFcat
Magicmarker
X-Fastly-Cache
X-IP
X-Core-Value
Location
Locid
On-Server
X-Envoy-Decorator-Operation
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Origin-Expires
V-Age
X-Request-URI
X-Var-Ttl
Wxu-Next-Region
X-Request-Host
X-Cms-Context
X-CUA
Wxu-Next-Commit
X-Policy
X-Clientip
X-Fastly-Backend
X-VarnishDD-TTL
CloudFront-Viewer-Country
Sever-Int
Content-Disposition
Wxu-Next-Hostname
X-Swa-Ws
Ssr
X-Nginx-Cache-Key
X-Cache-Tags
X-Developer
X-Developers
Cache-Host
X-Generated-By
DB-Nickname
X-ID
X-TX-ID
User-Cache-Control
X-Block-Status
X-Slack-Backend
X-Cache-Id
X-DefHash
X-SIPLIST1
X-DefElseHash
X-Clara-WADP
X-Dispatcher-Server
X-DPWN-IS-SECURE
X-VG-TLSProxy
X-Fmm-Version
X-Branch-Name
X-Esi-Check
X-Varnish-CookieINHashed-On
X-Gen-Mode
X-Hnp-Log
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Handled
Adler-Geo
Apple-News-Services-Request-Url
X-WADP-Cache
X-LI-UUID
X-Varnish-Beresp-Grace
X-Method
CDCHOST
X-NU-AKA-ACS-Version
X-Old-Content-Length
X-Ratelimit-Reset
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Varnish-CookieHashed-On
X-Platform-Server
X-Variation
X-Origin
X-Request-Start
X-Cache-Remote
Web-Mar-Node
Cf-Bgj
X-Hash
X-Varnish-Remaining-TTL
L
NM-Fastcgi-Cache
X-Gzip
Platform
X-GoCache-CacheStatus
X-Varnish-Hits
Rt-Fastcgi-Cache
IsBot
Is-Eu
X-Li-Fabric
X-NAPM-TraceId
True-Client-Country-4JS
X-Li-Pop
Fastly-SWR
Fastly-SIE
Vix-Hermes-Req-Id
X-B3-SpanId
X-Cdn-Forward
X-App-Version
X-Servername
X-Loc
X-Varnish-Beresp-Status
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Gamma-Serve
CDN-CachedAt
CDN-Uid
CDN-Cache
CDN-RequestId
X-NC
CDN-RequestCountryCode
CDN-PullZone
CDN-EdgeStorageId
X-Cache-Expires
X-Cache-Debug
X-Varnish-Beresp-Ttl
Origin
X-Core-Mission
X-CS
X-Varnish-Url
X-PF-Uncompressing
Url
Fastly-Drupal-HTML
X-EC-Lua
X-Mvc-Supplant-OutputCached
X-NCache
Sid
S-Rt
X-Varnish-Cacheable
X-Response-By
X-Host-Name
X-Aicache-OS
X-Refresh
X-CACHE-GROUP
X-LB-ID
X-B3-Spanid
Xkeyi7
X-Proxy-Cachei7
Pics-Label
Esi-Enabled
X-FireWall-Protection
X-Via-Poph
X-Via-Popn
X-Via-Popv
N-Cache
X-BBXSRF
CACHE
Cross-Origin-Window-Policy
X-Cache-2
Ohc-File-Size
X-Unique-ID
X-Tb-Optimization-Total-Bytes-Saved
Content-Secure-Policy
X-Sucuri-Cache
X-Cc-Req-Id
X-Epic-Correlation-Id
X-Webkit-Csp
X-Cache-ASPX
X-Varnish-Authentication
D-Cc-Upstream
X-Nc
X-Contensis-Viewer-Groups
X-Cc-Via
X-Error
X-Srv
Cteonnt-Length
Who
X-TraceId
Country-Code
X-CDN-Forward
X-CACHE-KEY
Source
Req-Svc-Chain
X-Svr
X-Webkit-CSP-Report-Only
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
GeoIp-Country-Code
Server-Ttl
X-Servedbyhost
X-Server-IP
X-Cs
Geo-Info
X-DC
HitType
X-Wa
Geoip-Latitude
MIME-Version
X-Planisys-CDN-TTL
X-RateLimit-Limit
X-Cache-Config
X-API-Version
X-FPC
X-Gdpr
X-HS-Status
X-Origin-Time
X-Nyt-Route
X-URL
X-CLOUD-TRACE-CONTEXT
X-LiteSpeed-Cache-Control
X-SN
X-VC
Svr
Cmstype
Cmsid
Kp-EeAlive
Ohc-Cache-HIT
Hostname
Viewtype
X-Webstats-RespID
X-Esi
VivaBuild
X-NGINX-Cache
X-LI-Proto
X-SB
X-NodeID
X-Served-From
Cache-Key
Server-ID
X-Vcl-Version
X-SD-PageType
X-VCL-Version
XServer
A
X-TIME
X-Check-Cacheable
NtCoent-Length
X-HOST
X-Vgn-Hpd-Reason
X-Viewer-Country
Resin-Trace
X-Li-Proto
Request-ID
SID
M-TraceId
Tcn
X-Render-Time
X-Ua
X-UA
X-DB
X-CCDN-Origin-Time
Cross-Origin-Opener-Policy
Cache-Provider
TDXMobile
X-Hcs-Proxy-Type
X-RAMCache
X-Air-Source
X-DI
X-CCDN-CacheTTL
X-RSL
Arc-Country
X-RPS
X-RPM
X-DSS
X-TIM-N
X-DW
Server-Id
X-BBC-Edge-Cache-Status
EpKe-Alive
Filterid
GeoIP-Country-Code
X-Auto-Login
GeoIP-Latitude
X-Internal-Host
X-CF-Powered-By
X-Fastly-Request-Id
X-Worker
X-Newrelic-Synthetics
X-Ftr-Cache-Host
Processtime
ProcessTime
X-Action
X-ServedByHost
X-App
X-WA
Srv
X-Vc
X-FTR-Cache-Host
X-CSRF-TOKEN
X-Geo
Upgrade-Insecure-Requests
CDN
X-Cluster-Node
NGB
X-Service
X-Fpc
Mime-Version
X-Oss-Cdn-Auth
X-Dynatrace-Js-Agent
X-FORWARDED-FOR
Proxy-Connection
Datacenter
X-BBC-Origin-Response-Status
X-HostName
CF-Cached-On
X-HITS
X-BACKEND-TTL
X-Forwarded-Site
X-MSEdge-Flight
X-SaId
DataCenter
X-Via-NSCOPI
X-Fastly-Backend-Reqs
X-Parent-Response-Time
FSS-Cache
X-MSEdge-Features
X-JoinUs
X-NGENIX-Cache
X-PHP-Backend
Cdn
X-Dw-Trace-Id
X-Edge-Location
X-CACHE-AGE
X-Extlb
X-Cdn-Request-ID
X-Akamai-Pragma-Client-IP
X-Client-Ip
X-Via-PopN
X-ND-Cache
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Cache-Tag
X-Flog
X-ABtesting
X-Hello
W
X-Via-PopH
PICS-Label
OT-Force-Account-Verify
Dnion-Transfer-Encoding
X-Via-PopV
X-Swift-Error
WZWS-RAY
X-Provided-By
X-Region-Sid
X-RateLimit-Remaining-Second
X-Req
X-Pf-Uncompressing
LB
X-UnsetCookies
X-Lb-Id
Media-Length
X-Accel-Expires-Debug
X-VC-Cache
Mail-Subject
Memcached
X-Depends-On
X-Presslabs-Stats
X-Bc-Bl
X-Date
We-Hiring
X-Oracle-DMS-ECID
Surrogated-Key
X-RateLimit-Limit-Second
X-Proxy-Upstream
X-PJAX-URL
Vha6-Origin
X-Rocket-Build-Number
X-Sigma-Backend
X-Sigma
X-APP
Epwk-X-Cache
X-Pad
Memory
Time
X-MiniProfiler-Ids
Env
X-LiteSpeed-Tag
X-ZONE
Cf-Ipcountry
X-Zone
X-Snapshot-Date
X-Acquia-Purge-Tags
X-Men
X-Amz-Meta-Cb-Modifiedtime
X-Varnish-Beresp-TTL
X-Request-URL
X-ElasticPress-Query
X-Varnish-URL
X-Air-Trace-Id
X-Acquia-Application-Trace
URI
Xet-Cookie
X-Acquia-Application-UUID
X-Ms-Meta-Originalurl
X-Ms-Meta-Staticbatchstarttime
X-Litespeed-Cache-Control
X-ElasticPress-Search
X-Acquia-Site
X-Vcache
X-B3-Parentspanid
X-Request-Url
X-Akamai-ERRuleID
X-Csrf-Token
X-Akamai-ERPolicy
CountryCode
CPC-Age
VNS-Cache
VNS-Age
CPC-Cache
X-Tid
X-C
X-Redis-Count
X-Traceid
X-Debug-Cache-Fetch
X-Akamai-Request-ID
NnCoection
Ohc-Response-Time
X-Debug-Cache-Store
X-Redis-Duration-Ms
X-ServerName
X-Storefront-Renderer-Verified
Environment
Phost
Inserted-Into-Cache-At