Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
Link
X-XSS-Protection
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-UA-Compatible
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
X-Request-Id
Access-Control-Allow-Methods
X-Xss-Protection
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Cache-Status
X-Generator
X-Cacheable
X-Ua-Compatible
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Request-ID
X-Content-Security-Policy
X-Iinfo
Content-Encoding
X-CDN
Feature-Policy
X-AspNetMvc-Version
Status
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Upgrade
X-Via
Access-Control-Max-Age
Keep-Alive
X-Ws-Request-Id
X-Age
X-Robots-Tag
X-AH-Environment
X-Turbo-Charged-By
Request-Context
EagleId
X-Cache-Group
X-Proxy-Cache
Server-Timing
X-Backend
X-Server
X-Hacker
Host-Header
Report-To
X-Server-Powered-By
X-Dns-Prefetch-Control
X-Amz-Request-Id
X-Nginx-Cache-Status
X-Amz-Id-2
Grace
X-UA-Device
X-Rq
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Page-Speed
Cf-Railgun
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
X-Amz-Version-Id
X-Device
NEL
X-Cache-Spec
X-CST
Allow
X-Vhost
X-Host
X-Backend-Server
X-WebKit-CSP
X-Server-Id
Xkey
EagleEye-TraceId
X-Dispatcher
Surrogate-Control
X-Node
Request-Id
X-Response-Time
Content-Location
X-Akam-SW-Version
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Ruxit-JS-Agent
P3p
Accept-Ch-Lifetime
X-ASPNET-VERSION
X-Application-Context
X-Cache-Lookup
X-Ac
X-Country
Accept-CH
Accept-Ch
X-Mod-Pagespeed
X-Template
X-Language
X-Readtime
X-Cloud-Trace-Context
X-B3-TraceId
MS-Author-Via
Rating
X-HW
X-Url
Accept-CH-Lifetime
X-Cnection
X-Origin-Cache
X-MS-InvokeApp
X-PC
X-TtlSet
X-Vname
Edge-Control
X-Clacks-Overhead
X-ESI
X-GitHub-Request-Id
X-Trace
X-Varnish-TTL
X-ORACLE-DMS-RID
X-Middleton-Response
X-Middleton-Display
Response
Display
X-Sol
Pagespeed
X-Content-Type
X-D2id
X-ORACLE-DMS-ECID
Verso
Arr-Disable-Session-Affinity
X-GoogleNews-Bot
X-Exp-Id
X-Cdn-Fetch
X-Kinja
X-Kinja-Revision
X-Use-Magma
X-Kinja-Server
X-Vcap-Request-Id
X-Kinja-Build
X-Exp-Variant
X-Country-Code
X-Rack-Cache
X-Goog-Hash
X-Powered-By-Plesk
X-Navigation-Version
X-VARITI-CCR
Service-Worker-Allowed
X-Server-Name
X-Amz-Rid
X-Fastly-Request-ID
X-Abt-Application-Version
X-Oneagent-Js-Injection
X-Buckets
X-Client-IP
Fastly-Restarts
X-TTL
X-Cached
X-Cache-TTL
X-MSEdge-Ref
X-Release
X-Element-Page-Cache
X-Dw-Request-Base-Id
SPRequestGuid
X-SharePointHealthScore
X-NF-Request-ID
X-B3-TraceId-Primal
MRF-Tech
Pinterest-Generated-By
Mrf-Cache-Status
SPIisLatency
X-Pinterest-Rid
SPRequestDuration
Pinterest-Version
Public-Key-Pins
Access-Control-Request-Method
RTSS
X-FastCGI-Cache
X-Webkit-CSP
Cache-Tag
AR-Request-ID
Ar-Sid
AR-CACHE
X-Edge
AR-PoweredBy
AR-ATIME
X-LLID
X-Powered-CMS
X-Ezoic-Cdn
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Upstream
Content-MD5
X-Version
X-Jurisdiction
X-HP-Webp
X-Fastcgi-Cache
S
X-Origin-Upstream-Status
X-Recruiting
X-Ttl
X-Mid
X-ECACHE
X-MCACHE
Charset
Fusion-Template-Id
Fusion-Content-Id
Fusion-Component-Id
X-Mg-S
Fusion-Content-Source
Fusion-Deployment-Id
Fusion-Source
X-DynaTrace
X-PressLabs-Stats
X-Kinsta-Cache
X-Content-Digest
X-Px
X-Ruxit-Js-Agent
X-T
Fastcgi-Cache
Cache-Tags
X-Id
X-Amz-Server-Side-Encryption
X-Accel-Expires
X-Logged-In
Filters
X-Forwarded-Proto
X-Litespeed-Cache
Server-Node
X-Content-Security-Policy-Report-Only
Edge-Cache-Tag
Front-End-Https
TP-Cache
MicrosoftSharePointTeamServices
TP-L2-Cache
X-Correlation-Id
Server-Name
X-Forwarded-For
TCN
X-Grace
Nginx-Cache
X-XRDS-LOCATION
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Hits
X-Request-Received
X-Request-Processing-Time
X-Debug
X-Amzn-Trace-Id
X-B3-Sampled
X-Shield-Request-Id
X-Request-Handler-Origin-Region
X-Microsite
X-Varnish-Age
X-Az
X-AppVersion
X-Activity-Id
Surrogate-Key
X-Yandex-Sdch-Disable
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Combine-CSS
X-HS-Cache-Config
X-Amz-Replication-Status
X-F-Cache
Alternate-Protocol
X-Origin-Server
X-Ser
X-Webkit-Csp
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Metageneration
X-DIS-Request-ID
Accept-Charset
X-Geo-Country
X-Frontend
X-Rid
Section-Io-Cache
Host
Nel
X-NWS-LOG-UUID
X-Git-Hash
X-Time
X-XRDS-Location
X-Respond-Thread
X-Cache-Age
X-Hostname
X-Upgrade-Enabled
X-DataDome
Access-Control-Allow-Method
X-VCache
X-Mobile-URL
X-LB-Cache
X-RateLimit-Remaining
MS-CV
X-Seen-By
X-Pinterest-Direct
ServerID
Paypal-Debug-Id
X-Type
Cache
X-IPLB-Instance
Payment
X-TT
X-Varnish-Backend
X-Source
Healthy
X-Content-Options
X-AOL-HN
X-Request-Guid
X-App-Environment
X-Whom
X-Providence-Cookie
X-Daa-Tunnel
X-Route-Name
X-Is-Crawler
X-Flags
X-Aspnet-Duration-Ms
X-Signature
X-B-Cache
Cleartype
X-Server-ID
X-Cache-Action
X-Page-Id
X-FTR-Request-ID
Fastcgi-Useragent
X-Debug-Info
X-Cache-Key
X-WebKit-CSP-Report-Only
X-Jobs
X-N
X-Load-Cache
X-Contextid
Realpath
X-FB-Debug
X-Browser-Type
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Mobile
Powered-By-ChinaCache
Node
X-Rule
Refresh
X-Cache-Expired-At
X-Accel-Buffering
X-Response-Served-From
X-Original-Request-Id
X-Drupal-Cache-Tags
Ms-Operation-Id
DC
X-RTag
X-Proxy
X-Wix-Request-Id
Version
X-Framework
X-Cacheable-TTL
X-Zen-Fury
X-B
Access-Control-Request-Headers
X-Content-Powered-By
X-RemovedCookies
X-Real-IP
X-Instance
X-Cache-Control
X-ProcessESI
X-HTML-Minification-Powered-By
Referer-Policy
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
Viewport
Eomportal-Instance
X-UUID
X-Cache-Time
X-Tt-Trace-Tag
X-Page-View
X-Region
X-Distributor
X-Tt-Trace-Host
X-Via-JSL
X-Cluster-Name
X-Drupal-Cache-Contexts
X-IPS-LoggedIn
X-FW-Server
X-FW-Static
X-FW-Hash
X-FW-Dynamic
X-FW-Type
X-FW-Serve
X-Cached-By
X-FireWall-Port
Countrycode
X-Akamai-Edgescape
X-Cache-Rule
X-Cache-Operation
Liferay-Portal
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-G
X-TEC-API-ROOT
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Cache-Hit
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Pass-Why
X-Environment-Context
X-App-Server
X-L-Path
Xserver
X-Tec-Api-Version
X-Tec-Api-Root
DynaTrace
X-Nginx-Cache
SRV
X-Tec-Api-Origin
X-Www-Served-By
Server-Info
CF-IPCountry
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
Section-Io-Id
Section-Io-Origin-Status
X-Debug-IsPreview
X-Debug-IsConnected
X-Protected-By
X-User-Agent
X-Device-Type
X-Tumblr-Pixel-2
From-Origin
Webserver
X-Varnish-Grace
Ec-Rule-Version
X-Mode
X-Adobe-Content
X-Adobe-Loc
X-Endurance-Cache-Level
X-RN-RSRV
X-Hl-Ver
Retry-After
X-ES-SERVER
Meta-Geo
X-UPSTREAM-Address
X-Handled-By
AMP-Access-Control-Allow-Source-Origin
Cache-Tv-Group
X-Uri
X-Backend-Name
X-MP-GENERATED-AT
X-Pubstack
X-Labrador-Cache-Channel
X-FB-TRIP-ID
Webcakes-Region
X-Cache-Server
Webcakes-App-Name
TWC-Privacy
X-Varnishpool
Webcakes-App-Version
X-Format
TWC-GeoIP-LatLong
Property-Id
Fastly-SSL
Decoy-Debug-TTL
X-Access
X-Storage
Decoy-Debug-Status
TWC-GeoIP-Country
TWC-Connection-Speed
X-PHP-Host
X-Section
TWC-Device-Class
X-PCL
X-Origin-Hint
Decoy-Debug-Key
TWC-Locale-Group
X-OCL
Selected-Fe
X-LAGOON
X-Be
X-Proto
X-NYM-Debug-Backend
Frame-Options
X-PERF
X-LJ-Flow-ID
Mn-Server-Ip
X-No-Session
X-AWS-Id
X-Proxy-Build
X-ApacheServer
X-Varnish-Server
Cache-Status
X-BYPASS-REASON
X-Via-Fastly
X-WA-Info
X-UA-Device-Type
X-Timing-Wait
X-Sql-Duration-Ms
Protected
Apigw-Requestid
Country
X-Request-Time
X-Soup
X-ProxyCache-Status
X-ProxyCache-Key
X-Human
X-Sql-Count
X-VWS-Id
X-Redis-Cache
X-R9-Blue-Green-Version
X-Server-W
Azure-InstanceId
Azure-SiteName
X-Xfnlog-Site
X-Web-Node
Azure-SlotName
X-Zipkin-Id
X-Routing-Service
X-S-Maxage
X-Cache-TTL-Remaining
X-Hosted-By
X-Hyper-Cache
X-Locale
X-Proxied
Azure-Version
Azure-RegionName
X-Origin-Date
Cache-Name
X-Site-Version
X-Status
GEO-INFO
X-FW-Version
X-Shopify-Stage
X-Storefront-Renderer-Rendered
X-AIR-PT
X-Say-Cacheable
X-Say-TTL
X-Sorting-Hat-PodId
X-Alternate-Cache-Key
X-SayCDN-TTL
X-ShardId
X-Loop
X-ShopId
X-TNCMS
X-Ratelimit-Limit
X-Sorting-Hat-ShopId
X-Info
X-Node-Name
X-Cluster
X-Is-Bot
X-Dc
X-TT-LOGID
X-GG-Cache-Date
X-Rendered-As
X-Cache-Grace
X-Forwarded-Host
X-CCM
X-Cache-Enabled
Uber-Trace-Id
X-Proxy-Cache-Status
S-Cnection
X-Microcachable
X-Revision
X-Qloud-Router
X-Content-Age
X-TA-CDN-Provider
X-NWS-UUID-VERIFY
X-Platform
X-Azure-Ref
X-Via-CDN
X-Backend-Host
X-CSRF-Token
X-App-Version
X-SRV
Cache-Hits
X-Varnish-Ttl
X-Cache-Host
Akamai-GRN
X-Detected-As
X-FTR-Backend
X-Country-Code-Real
X-FTR-DC
X-Amz-Meta-S3cmd-Attrs
X-Aspnetmvc-Version
X-FTR-Balancer
X-FTR-Realm
X-Ratelimit-Remaining
X-FTR-Cache-Status
X-FTR-Backend-Server
X-ATG-Version
X-CACHE-KEY
X-Amzn-RequestId
ServedBy
X-Amz-Apigw-Id
X-Amzn-Remapped-Content-Length
X-B3-SpanId
X-Cache-PHP
X-Trace-Id
X-EdgeConnect-Cache-Status
X-Cache-NGX
X-CS
X-Debug-Cache
X-RCS-CacheZone
X-Varnish-Hostname
HostName
Amp-Access-Control-Allow-Source-Origin
SD-X-WS
X-FTR-Expires
X-Nc
X-Unique-ID
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Akamai-Transformed
DB-Nickname
X-Time-Microsecs
X-TX-ID
X-Oss-Request-Id
X-DynaTrace-JS-Agent
X-BCube-Filmed-By
X-ServerID
X-NewRelic-App-Data
X-Air-Hostname
Tracecode
X-Backend-TTL
X-Ms-Request-Id
X-Correlation-ID
X-Ms-Version
Backend
X-Adobe-Source
X-Generation-Time
X-Origin-TTL
X-B-Cookie
X-Origin-CC
X-ARC
X-Generated-On
X-PBS-Appsvrname
X-PAYTM-SRV-ID
X-Owner
X-Connection-Hash
Fastcgi-X-Cache-Version
Expiry
X-Cache-NE
X-CF-Lambda-Fn
X-External-Request-Id
X-Destination
BehaviorPad-Version
X-CF-Lambda-Version
DCR-Decision-By
X-D
DCR-Processing-Time-Ms
X-Level-Front-Cache
X-NAPM-TraceId
X-Location
X-Request-UUID
Meta-Geo-Continent
Mobile-Detection-Method
Odigeo-Trace-Id
X-Application
MD5-Digest
X-A-Ccd
X-A
Machine
X-Vdms-Path
X-Vdms-Version
T-Server
Rendered-Blocks
X-Cdn-Forward
Xc-Version
X-Vtex-Remote-Cache
X-VG-WebCache
X-VG-WebServer
X-Vtex-Processado-Em
X-SRCache-Key
X-Trv-Group
X-ScT
X-Rewrite-Enabled
X-A-Dcw
X-S-Cookie
X-S
X-A-Wwc
X-Rojux
X-From
X-Aed
X-A-Dam
X-Session-Fingerprint
X-A-Dgt
X-Processor
X-Tb
X-RateLimit-Limit
X-Varnish-Beresp-Grace
X-Fastly-Cache
V-Age
Thinkindot-Control
Gh-Request-Id
Release
X-Fetched-On
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-FC-Vary-Parameters
Path
UCS
AKAMAI
Magicmarker
X-Cms-Context
Wxu-Next-Hostname
Wxu-Next-Region
Content-Disposition
X-Cache-Bucket
X-Core-Value
CacheControlHeader
On-Server
Pagetype
Fastly-Backend-Name
X-Developers
X-Bip
Wxu-Next-Commit
Host-ID
Who
X-Mvc-Supplant-Cachable
X-Sucuri-ID
X-Tumblr-Pixel-3
X-Magnolia-Registration
X-Thanos
X-HS-Content-Campaign-Id
X-OVcl
X-Irp-Debug
X-Varnish-Cache-Hits
X-Micro-Cache
Server-Host
X-TrackingId
X-GeoIP-City
X-Reqid
X-Policy
X-OVcl-Cache
X-Thinkindot-L3
X-Generated-In
X-Geo-Header
Geo-Info
Country-Code
X-Cache-Var-Map
X-Varnish-Beresp-Ttl
X-Cache-Var
User-Cache-Control
X-Scheme
X-Request-Host
X-Ratelimit-Reset
X-Request-URI
X-Skip-Cache
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
Vix-Hermes-Req-Id
Ssr
Cache-Host
True-Client-Country-4JS
X-Cache-Info
X-Swa-Ws
Server-Hostname
Sever-Int
X-Wikidot-Static-Cache
X-Wikidot-Backend
Web-Mar-Node
X-Var-Ttl
X-VarnishDD-TTL
X-VG-TLSProxy
X-WADP-Cache
X-VServer
X-User
X-Node-Id
X-Dispatcher-Server
X-Hnp-Log
X-HN
X-Device-Os
X-Developer
X-Is-Gdpr
X-IP
X-Esi-Check
X-Eu-Site
X-GeoIP
X-Generated-By
X-Fmm-Version
X-GoCache-CacheStatus
X-Gzip
X-Has-Esi
X-Fastly-Backend
X-Csrf-Jwt
X-JWT-State
X-Gen-Mode
X-Block-Status
X-Nginx-Cache-Key
X-Old-Content-Length
X-Origin
X-Origin-Response-Time
X-Backend-State
X-Branch-Name
X-Method
X-CGP
X-Clara-WADP
X-Li-Fabric
X-Li-Pop
X-LI-UUID
X-Cache-Debug
X-Cache-Id
X-Azure-Ref-OriginShield
X-Envoy-Decorator-Operation
C-Via
CDCHOST
CDN-Cache
Esi-Enabled
Arc-Version
Ha-Gx-Prefs
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
DSUID
CDN-CachedAt
Cf-Bgj
CDN-RequestId
CDN-Uid
Cf-Device-Type
CDN-RequestCountryCode
CDN-EdgeStorageId
CDN-PullZone
Server-Ext
Apple-News-Services-Handled
HA-Ipaddr
NGX
X-Varnish-Beresp-Status
NM-Fastcgi-Cache
PB-RID
X-B3-Traceid
PFcat
Locid
PB-PID
Location
L5d-Success-Class
X-Varnish-CookieHashed-On
X-Platform-Server
X-LB-ID
X-Origin-Expires
X-DPWN-IS-SECURE
X-Gamma-Serve
X-Rebelmouse-Cache-Control
X-NU-AKA-ACS-Version
X-Variation
Adler-Geo
X-DefElseHash
X-DefHash
X-Slack-Backend
X-SIPLIST1
X-Rebelmouse-Surrogate-Control
X-Varnish-CookieINHashed-On
X-Clientip
X-Cache-Tags
X-Varnish-Remaining-TTL
Instruction
Origin
Fastly-SWR
Fastly-SIE
Is-Eu
IsBot
Rt-Fastcgi-Cache
X-Varnish-Hits
SR-User-Adfree
Platform
L
X-Aicache-OS
X-Hash
X-ID
Filterid
X-EC-Lua
X-Unique-Id
X-GEO
X-Varnish-Url
X-Mvc-Supplant-OutputCached
Fastly-Drupal-HTML
X-CUA
X-Goog-Meta-Goog-Reserved-File-Mtime
X-CLOUD-TRACE-CONTEXT
X-PF-Uncompressing
X-Loc
Pics-Label
X-Via-Popn
X-Cache-Backend
X-Epic-Correlation-Id
X-Matched-Rule
X-Via-Popv
X-Via-Poph
Lfy
X-APP-VERSION
CloudFront-Viewer-Country
X-Refresh
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
Sid
X-Sn-Servicetimems
Url
X-Cache-Expires
X-NCache
X-Cdn-Origin
Pramga
Cmstype
NGB
X-Cache-Date
X-Core-Mission
Req-Svc-Chain
Cmsid
X-TraceId
X-Tb-Optimization-Total-Bytes-Saved
Svr
X-Servername
X-Srv
X-Served-From
Kp-EeAlive
X-Request-Start
Tcn
MIME-Version
VivaBuild
A
Viewtype
Source
X-FireWall-Protection
Cache-Key
M-TraceId
X-Error
X-Vgn-Hpd-Reason
X-Varnish-Cacheable
GeoIp-Country-Code
Geoip-Latitude
Server-ID
Cross-Origin-Opener-Policy
Arc-Country
X-Webkit-CSP-Report-Only
X-Geo
X-Response-By
X-DC
X-Vcl-Version
X-HS-Status
TDXMobile
X-NC
X-PHP-Backend
SID
X-JoinUs
DataCenter
X-SaId
X-NGENIX-Cache
X-Proxy-Cachei7
X-Air-Source
X-Vc
X-Edge-Location
Xkeyi7
X-Li-Proto
N-Cache
HitType
X-BBXSRF
Server-Ttl
Content-Secure-Policy
X-B3-Spanid
X-Wa
X-Service
X-Servedbyhost
X-Erf-Stays-Bingo-Pdp-Web
S-Rt
X-Cache-Remote
NtCoent-Length
Resin-Trace
X-LiteSpeed-Cache-Control
X-Cache-2
X-Internal-Host
X-Esi
X-CDN-Forward
CACHE
X-Extlb
X-Cc-Via
X-Varnish-Authentication
X-WA
X-Viewer-Country
X-Cache-ASPX
D-Cc-Upstream
X-Contensis-Viewer-Groups
X-Cc-Req-Id
X-Kraken-Loop-Name
FSS-Cache
X-Forwarded-Site
X-Kraken-Routeconfig-Destination
X-Instrumentation
X-Server-Lifecycle-Phase
X-LI-Proto
X-Edge-Location-Klb
X-HOST
Cteonnt-Length
X-CCDN-Origin-Time
X-Svr
Cross-Origin-Window-Policy
X-CCDN-CacheTTL
X-Sucuri-Cache
Ohc-File-Size
X-Bc-Bl
X-ServedByHost
X-Hcs-Proxy-Type
Request-ID
X-RAMCache
X-UA
X-HostName
X-Host-Name
Surrogated-Key
X-Newrelic-Synthetics
LB
X-Req
X-VCL-Version
X-PJAX-URL
X-Proxy-Upstream
X-RSL
X-Date
X-TIM-N
X-Server-IP
We-Hiring
X-DW
X-RPM
X-RPS
X-Accel-Expires-Debug
X-Via-NSCOPI
X-DSS
X-DB
Memcached
X-DI
Mail-Subject
Hostname
GeoIP-Latitude
GeoIP-Country-Code
Env
X-APP
X-Cache-Config
X-Origin-Time
X-API-Version
X-VC-Cache
X-RateLimit-Remaining-Second
X-FPC
X-Cs
CF-Cached-On
X-Gdpr
X-Nyt-Route
X-RateLimit-Limit-Second
XServer
Upgrade-Insecure-Requests
X-Sigma
X-Sigma-Backend
ProcessTime
X-Action
X-Men
X-Rocket-Build-Number
X-App
X-VC
Cache-Provider
X-SN
X-NodeID
X-ZONE
X-Check-Cacheable
Ohc-Cache-HIT
X-Webstats-RespID
X-Fpc
Server-Id
Memory
X-Oss-Cdn-Auth
Time
X-SB
X-MSEdge-Features
CPC-Age
CPC-Cache
VNS-Age
VNS-Cache
X-Air-Trace-Id
X-CF-Powered-By
X-MSEdge-Flight
X-Region-Sid
X-URL
X-Dynatrace-Js-Agent
X-Provided-By
X-Swift-Error
W
X-ServerName
X-SD-PageType
X-FORWARDED-FOR
X-Zone
Mime-Version
X-Depends-On
X-Cdn-Request-ID
X-Akamai-Pragma-Client-IP
Srv
X-CSRF-TOKEN
X-Render-Time
CDN
X-UnsetCookies
X-Ftr-Cache-Host
X-Dw-Trace-Id
X-BACKEND-TTL
Cdn
X-TIME
X-BBC-Edge-Cache-Status
X-Client-Ip
Dnion-Transfer-Encoding
X-ABtesting
My-App
State
X-NGINX-Cache
X-Parent-Response-Time
X-Hello
Fastcgi-Cache-TTL
X-Fastly-Request-Id
X-Fastly-Backend-Reqs
X-Flog
EpKe-Alive
X-Dynatrace
X-Minions-Version
Media-Length
X-Acquia-Site
X-Auto-Login
Processtime
X-Cache-Tag
X-FTR-Cache-Host
X-Pad
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
Proxy-Connection
X-Acquia-Application-Trace
X-ElasticPress-Search
Vha6-Origin
X-Worker
X-Pf-Uncompressing
X-Presslabs-Stats
X-Oracle-DMS-ECID
X-Snapshot-Date
X-LiteSpeed-Tag
X-Ua
PICS-Label
X-Cluster-Node
X-BBC-Origin-Response-Status
X-Via-PopN
Epwk-X-Cache
X-Via-PopH
X-Via-PopV
Cf-Ipcountry
X-CACHE-AGE
X-Mg-Request-UUID
X-Ms-Meta-Originalurl
X-Varnish-URL
X-Ms-Meta-Staticbatchstarttime
Xet-Cookie
X-Vcache
Datacenter
X-IN-APIGATEWAY
X-Varnish-Beresp-TTL
X-Request-URL
X-MiniProfiler-Ids
X-ElasticPress-Query
Warning
X-Lb-Id
X-Akamai-ERPolicy
X-IN-APIGATEWAYSSL
X-Akamai-ERRuleID
CountryCode
Content-Style-Type
Content-Script-Type
X-Traceid
X-Apw-Access-Action
Phost
X-Mg-Request-Id
X-Cache-Status-Check
X-Apw-Hits
X-Litespeed-Cache-Control
X-Apw-Access-Token
X-Apw-Access-Object
X-C
X-Redis-Duration-Ms
X-Redis-Count
X-B3-Parentspanid
URI
X-Debug-Cache-Fetch
X-Debug-Cache-Store
Environment
OT-Force-Account-Verify
X-Amz-Meta-Cb-Modifiedtime
X-Storefront-Renderer-Verified
X-Tid
NnCoection
Inserted-Into-Cache-At
Ohc-Response-Time