Threat Level: green Handler on Duty: Renato Marinho

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-RAY
CF-Cache-Status
X-XSS-Protection
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-Served-By
X-UA-Compatible
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Xss-Protection
X-Request-ID
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Ua-Compatible
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Content-Encoding
X-CDN
Feature-Policy
X-AspNetMvc-Version
X-Envoy-Upstream-Service-Time
Status
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-Via
Upgrade
Access-Control-Max-Age
Keep-Alive
X-Ws-Request-Id
X-Age
X-AH-Environment
X-Turbo-Charged-By
X-Robots-Tag
Request-Context
X-Proxy-Cache
X-Cache-Group
EagleId
Server-Timing
X-Backend
X-Hacker
X-Server
Report-To
Host-Header
X-Amz-Request-Id
X-Server-Powered-By
X-Amz-Id-2
Grace
X-Nginx-Cache-Status
X-UA-Device
X-Rq
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Page-Speed
X-LiteSpeed-Cache
Cf-Railgun
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-OneAgent-JS-Injection
NEL
X-Dns-Prefetch-Control
X-Cache-Spec
X-Amz-Version-Id
X-WebKit-CSP
X-Device
X-CST
Allow
Xkey
X-Host
X-Vhost
X-Backend-Server
X-Server-Id
EagleEye-TraceId
Request-Id
Surrogate-Control
X-Dispatcher
X-Node
Content-Location
X-Response-Time
X-Ruxit-JS-Agent
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Akam-SW-Version
Accept-CH
P3p
X-ASPNET-VERSION
X-Application-Context
Accept-CH-Lifetime
X-Ac
X-Cache-Lookup
X-Template
X-Language
X-Country
X-Mod-Pagespeed
X-Readtime
Accept-Ch
X-Cloud-Trace-Context
MS-Author-Via
X-B3-TraceId
Accept-Ch-Lifetime
Rating
X-Origin-Cache
X-MS-InvokeApp
X-Cnection
X-HW
X-Vname
X-TtlSet
X-PC
X-Url
X-Clacks-Overhead
Edge-Control
X-GitHub-Request-Id
X-ORACLE-DMS-ECID
X-Trace
X-ESI
X-Middleton-Response
Response
Pagespeed
X-Content-Type
Display
X-Sol
X-Middleton-Display
X-D2id
X-ORACLE-DMS-RID
Arr-Disable-Session-Affinity
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Exp-Variant
X-Kinja-Build
X-Kinja
X-Cdn-Fetch
X-GoogleNews-Bot
X-Exp-Id
Verso
X-Vcap-Request-Id
X-FastCGI-Cache
X-Goog-Hash
X-Rack-Cache
X-Buckets
X-Country-Code
X-Varnish-TTL
X-Server-Name
Service-Worker-Allowed
X-Navigation-Version
X-Powered-By-Plesk
X-Amz-Rid
X-VARITI-CCR
X-Abt-Application-Version
X-Fastly-Request-ID
X-TTL
X-Webkit-CSP
X-Client-IP
X-Cache-TTL
X-Litespeed-Cache
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
Fastly-Restarts
SPRequestGuid
X-SharePointHealthScore
X-Release
X-Cached
X-MSEdge-Ref
X-Dw-Request-Base-Id
X-Element-Page-Cache
SPRequestDuration
X-Oneagent-Js-Injection
SPIisLatency
X-NF-Request-ID
Public-Key-Pins
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
RTSS
Access-Control-Request-Method
X-SRCache-Store-Status
X-SRCache-Fetch-Status
AR-ATIME
AR-CACHE
AR-PoweredBy
Ar-Sid
AR-Request-ID
X-Edge
X-LLID
X-Powered-CMS
X-Ezoic-Cdn
X-Origin-Upstream-Status
Cache-Tag
Content-MD5
X-Upstream
X-Px
Fusion-Content-Id
Fusion-Content-Source
Fusion-Source
Fusion-Deployment-Id
Fusion-Template-Id
Fusion-Component-Id
X-Jurisdiction
X-HP-Webp
S
X-Version
X-MCACHE
X-Mid
X-ECACHE
X-Recruiting
X-Mg-S
Charset
X-Content-Digest
X-Ttl
X-Amz-Server-Side-Encryption
Fastcgi-Cache
X-PressLabs-Stats
X-Kinsta-Cache
X-T
MicrosoftSharePointTeamServices
Cache-Tags
Filters
Front-End-Https
X-DynaTrace
X-Content-Security-Policy-Report-Only
TCN
X-Logged-In
X-Debug
Server-Node
X-Accel-Expires
Edge-Cache-Tag
X-Grace
X-Id
X-Forwarded-Proto
X-Correlation-Id
TP-Cache
Server-Name
TP-L2-Cache
Nginx-Cache
X-Amzn-Trace-Id
X-Pinterest-Direct
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Forwarded-For
Surrogate-Key
X-Request-Received
X-Request-Processing-Time
X-Varnish-Age
X-Yandex-Sdch-Disable
X-B3-Sampled
X-Shield-Request-Id
X-Microsite
X-Ser
X-Request-Handler-Origin-Region
X-Activity-Id
X-Hits
X-AppVersion
X-Az
X-Amz-Replication-Status
X-XRDS-Location
X-F-Cache
X-HS-Cache-Config
X-XRDS-LOCATION
X-HS-Content-Id
X-DIS-Request-ID
X-HS-Combine-CSS
X-HS-Hub-Id
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Storage-Class
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
X-Origin-Server
Accept-Charset
X-Geo-Country
X-Git-Hash
Alternate-Protocol
X-Cache-Key
X-Respond-Thread
Cache
X-Rid
X-FTR-Request-ID
Section-Io-Cache
X-Frontend
X-Fastcgi-Cache
X-LB-Cache
Host
X-Upgrade-Enabled
X-DataDome
X-Time
Access-Control-Allow-Method
Powered-By-ChinaCache
X-Ruxit-Js-Agent
X-Mobile-URL
X-Seen-By
X-NWS-LOG-UUID
MS-CV
X-Server-ID
Paypal-Debug-Id
X-Cache-Age
X-VCache
X-TT
X-IPLB-Instance
X-AOL-HN
Healthy
Cleartype
X-Content-Options
X-TEC-API-ORIGIN
X-Hostname
X-Whom
ServerID
X-TEC-API-ROOT
X-Varnish-Backend
X-TEC-API-VERSION
X-Type
X-Request-Guid
X-Route-Name
X-App-Environment
Payment
X-Providence-Cookie
X-Flags
X-Is-Crawler
X-Aspnet-Duration-Ms
X-Signature
X-Cache-Action
X-B-Cache
X-Jobs
X-Source
X-Page-Id
Fastcgi-Useragent
X-Debug-Info
X-WebKit-CSP-Report-Only
X-Load-Cache
X-Daa-Tunnel
X-N
X-Mobile
X-FB-Debug
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
Nel
X-Via-JSL
Refresh
X-RateLimit-Remaining
X-Contextid
Realpath
Version
X-Drupal-Cache-Tags
X-Wix-Request-Id
X-Response-Served-From
X-Original-Request-Id
X-Accel-Buffering
X-Akamai-Edgescape
Node
X-Rule
X-Cached-By
DC
X-RTag
Ms-Operation-Id
X-Proxy
X-Cacheable-TTL
X-Zen-Fury
X-Framework
X-Cache-Operation
Viewport
X-ProcessESI
X-RemovedCookies
X-Cache-Rule
Referer-Policy
X-B
X-Distributor
Access-Control-Request-Headers
X-Cache-Time
X-HTML-Minification-Powered-By
X-Real-IP
X-Instance
X-Region
X-Drupal-Cache-Contexts
X-Page-View
X-UUID
Eomportal-Instance
X-Cluster-Name
X-Tt-Trace-Tag
X-Cache-Expired-At
X-Tt-Trace-Host
VIX-Pulpo-Upstream-Status
X-Cache-Control
Liferay-Portal
X-Yottaa-Optimizations
X-Content-Powered-By
Countrycode
X-FW-Hash
X-FW-Serve
X-FW-Server
X-FW-Static
VIX-Pulpo-Node
X-FW-Type
X-FW-Dynamic
X-Yottaa-Metrics
X-IPS-LoggedIn
X-G
X-Cache-Hit
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Environment-Context
X-L-Path
X-Tumblr-User
DynaTrace
X-Pass-Why
X-FireWall-Port
Server-Info
X-App-Server
GEO-INFO
X-Varnish-Ttl
Ec-Rule-Version
X-User-Agent
X-Ratelimit-Limit
X-Tumblr-Pixel-2
Section-Io-Id
CF-IPCountry
Section-Io-Origin-Status
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
X-Protected-By
Webserver
From-Origin
X-Node-Name
X-Ratelimit-Remaining
SRV
X-Www-Served-By
Xserver
Protected
X-Nginx-Cache
X-Cache-Server
X-UPSTREAM-Address
X-Mode
Meta-Geo
X-Hl-Ver
X-Handled-By
X-RN-RSRV
X-ES-SERVER
X-Backend-Name
X-Endurance-Cache-Level
X-FB-TRIP-ID
Cache-Tv-Group
X-Locale
X-Debug-IsConnected
X-Site-Version
X-Debug-IsPreview
Frame-Options
X-Uri
X-Varnishpool
X-UA-Device-Type
X-Storage
X-Device-Type
X-Labrador-Cache-Channel
X-MP-GENERATED-AT
X-Adobe-Loc
X-NYM-Debug-Backend
X-Adobe-Content
X-PHP-Host
X-Web-Node
Cache-Status
X-Be
X-Soup
X-ProxyCache-Status
TWC-Device-Class
X-Pubstack
X-Redis-Cache
TWC-Privacy
Webcakes-App-Version
Webcakes-Region
X-BYPASS-REASON
Webcakes-App-Name
X-ProxyCache-Key
X-Request-Time
TWC-GeoIP-LatLong
TWC-Locale-Group
TWC-GeoIP-Country
X-Hyper-Cache
Decoy-Debug-Status
Decoy-Debug-TTL
Decoy-Debug-Key
X-Timing-Wait
TWC-Connection-Speed
X-Human
X-PCL
Property-Id
X-OCL
X-No-Session
X-Origin-Date
Fastly-SSL
X-Origin-Hint
Cache-Name
Country
X-Via-Fastly
Selected-Fe
X-Sql-Duration-Ms
X-Sql-Count
X-Proto
X-Proxy-Build
X-WA-Info
Azure-InstanceId
Azure-RegionName
Azure-SiteName
Azure-SlotName
Azure-Version
Retry-After
X-Access
X-Say-Cacheable
X-Say-TTL
X-R9-Blue-Green-Version
X-FW-Version
X-Forwarded-Host
X-Format
X-VWS-Id
X-Hosted-By
X-TNCMS
X-S-Maxage
X-Loop
X-LJ-Flow-ID
X-LAGOON
X-AIR-PT
X-Revision
X-Section
X-Cache-Grace
X-Server-W
X-SayCDN-TTL
X-AWS-Id
X-TT-LOGID
X-Alternate-Cache-Key
X-Storefront-Renderer-Rendered
X-PERF
X-Cache-TTL-Remaining
X-CCM
X-Cluster
X-Sorting-Hat-ShopId
X-Xfnlog-Site
X-Shopify-Stage
X-ShardId
X-ShopId
X-Status
X-Sorting-Hat-PodId
X-ApacheServer
Mn-Server-Ip
X-Zipkin-Id
X-Routing-Service
X-Proxied
X-SRV
Apigw-Requestid
X-Amz-Meta-S3cmd-Attrs
X-Is-Bot
X-Qloud-Router
X-Rendered-As
X-Varnish-Grace
X-Varnish-Server
X-Info
S-Cnection
X-FTR-Balancer
X-FTR-Cache-Status
X-Via-CDN
X-FTR-DC
X-FTR-Backend-Server
X-FTR-Realm
X-FTR-Backend
X-Country-Code-Real
Cache-Hits
X-Cdn
X-Microcachable
X-FTR-Expires
X-Cache-Enabled
AMP-Access-Control-Allow-Source-Origin
X-Dc
X-GG-Cache-Date
X-Content-Age
X-Detected-As
X-Cache-Host
X-Platform
Uber-Trace-Id
X-Proxy-Cache-Status
X-EdgeConnect-Cache-Status
X-Aspnetmvc-Version
X-Amzn-Remapped-Content-Length
X-Amzn-RequestId
Amp-Access-Control-Allow-Source-Origin
X-Amz-Apigw-Id
X-Azure-Ref
X-Tec-Api-Root
X-Backend-Host
X-Tec-Api-Origin
X-Tec-Api-Version
Tracecode
X-Air-Hostname
X-NWS-UUID-VERIFY
X-App-Version
SD-X-WS
X-Unique-Id
X-Cache-Var
X-Cache-Var-Map
X-CSRF-Token
X-Time-Microsecs
Akamai-GRN
X-Oss-Request-Id
X-Oss-Object-Type
X-Oss-Server-Time
X-Oss-Storage-Class
X-ATG-Version
X-Oss-Hash-Crc64ecma
X-DynaTrace-JS-Agent
X-GEO
X-ServerID
X-Backend-TTL
X-Tb
X-Trace-Id
X-ID
X-Debug-Cache
X-RCS-CacheZone
X-BCube-Filmed-By
ServedBy
X-Akamai-Transformed
X-Correlation-ID
X-Varnish-Hostname
X-Cache-NGX
HostName
Backend
X-Cache-PHP
X-Cache-Backend
DSUID
X-B3-SpanId
X-Sucuri-ID
X-A-Dcw
X-Fetched-On
X-A-Dgt
X-Cache-NE
Mobile-Detection-Method
X-A-Dam
Meta-Geo-Continent
X-Device-Os
Rendered-Blocks
X-A-Ccd
X-Ms-Version
X-A-Wwc
Release
X-CF-Lambda-Version
X-Origin-CC
X-CF-Lambda-Fn
X-External-Request-Id
Odigeo-Trace-Id
X-Connection-Hash
X-B-Cookie
X-NAPM-TraceId
X-Aed
X-Application
X-ARC
SR-User-Adfree
T-Server
BehaviorPad-Version
X-Generation-Time
Fastcgi-X-Cache-Version
Thinkindot-CacheControl-Type
X-GeoIP-City
X-Generated-On
DCR-Decision-By
Thinkindot-Control
X-Destination
X-D
DCR-Processing-Time-Ms
DB-Nickname
Instruction
MD5-Digest
X-Location
X-Matched-Rule
Thinkindot-CacheControl
X-Level-Front-Cache
Machine
Path
X-From
X-A
Lfy
Expiry
X-Ms-Request-Id
X-Session-Fingerprint
X-Processor
X-CS
X-Vdms-Path
X-VG-WebCache
X-Thinkindot-L3
X-S-Cookie
X-SRCache-Key
X-Rewrite-Enabled
X-Rojux
X-Request-UUID
X-Trv-Group
X-S
X-VG-WebServer
X-Vdms-Version
X-Vtex-Remote-Cache
X-PBS-Appsvrname
X-TA-CDN-Provider
X-Magnolia-Registration
X-ScT
X-Owner
X-Origin-TTL
Xc-Version
X-PAYTM-SRV-ID
X-Vtex-Processado-Em
X-Cdn-Forward
X-Thanos
Arc-Version
X-SVT-ORM-VERSION
X-Skip-Cache
Cf-Device-Type
Content-Disposition
CacheControlHeader
Fastly-Backend-Name
C-Via
Gh-Request-Id
X-SVT-ORM-RULES
Pagetype
X-VServer
X-Adobe-Source
UCS
X-Core-Value
X-Azure-Ref-OriginShield
X-Cache-Bucket
X-Bip
X-Cms-Context
Server-Host
PB-RID
X-Tumblr-Pixel-3
NGX
X-FC-Vary-Parameters
On-Server
X-Fastly-Cache
PB-PID
X-Geo-Header
X-TrackingId
Host-ID
X-Mvc-Supplant-Cachable
X-NewRelic-App-Data
X-Varnish-Cache-Hits
X-Node-Id
X-Has-Esi
X-HS-Content-Campaign-Id
X-Irp-Debug
X-B3-Traceid
X-GeoIP
X-Reqid
X-JWT-State
X-Is-Gdpr
X-OVcl-Cache
X-Micro-Cache
AKAMAI
X-OVcl
User-Cache-Control
X-TX-ID
X-Varnish-CookieHashed-On
Ssr
X-Developer
X-Varnish-Beresp-Grace
X-Varnish-CookieINHashed-On
V-Age
X-DefHash
X-Origin-Response-Time
X-Developers
X-Policy
Sever-Int
X-Dispatcher-Server
X-Cache-Info
X-DPWN-IS-SECURE
X-Var-Ttl
Server-Ext
X-Ratelimit-Reset
X-DefElseHash
X-Variation
Server-Hostname
X-Cache-Id
X-Cache-Tags
X-Wikidot-Static-Cache
X-Branch-Name
X-Nginx-Cache-Key
X-Csrf-Jwt
X-CUA
X-NU-AKA-ACS-Version
X-Old-Content-Length
X-Block-Status
X-WADP-Cache
X-Backend-State
X-Origin
X-Platform-Server
X-Clara-WADP
Wxu-Next-Region
Wxu-Next-Hostname
Wxu-Next-Commit
X-Clientip
X-Varnish-Remaining-TTL
X-Wikidot-Backend
X-CGP
X-Envoy-Decorator-Operation
X-VarnishDD-TTL
Web-Mar-Node
Platform
X-Generated-By
Fastly-SIE
X-Generated-In
X-HN
CloudFront-Viewer-Country
Fastly-SWR
X-Gen-Mode
Is-Eu
HA-Ipaddr
Ha-Gx-Prefs
X-Hnp-Log
X-Gzip
Adler-Geo
CDCHOST
CDN-Cache
Cache-Host
X-GoCache-CacheStatus
X-Scheme
CDN-CachedAt
CDN-EdgeStorageId
CDN-Uid
CDN-RequestId
CDN-RequestCountryCode
CDN-PullZone
X-IP
X-Origin-Expires
X-Fastly-Backend
X-Rebelmouse-Surrogate-Control
X-Request-Host
X-LI-UUID
NM-Fastcgi-Cache
X-EC-Lua
X-Rebelmouse-Cache-Control
X-Esi-Check
X-Eu-Site
X-User
PFcat
X-Li-Fabric
X-Li-Pop
Locid
X-Swa-Ws
Magicmarker
Location
X-Fmm-Version
L5d-Success-Class
X-APP-VERSION
X-VG-TLSProxy
X-Gamma-Serve
X-LB-ID
X-SIPLIST1
X-Varnish-Hits
X-Sn-Servicetimems
X-Hash
X-Varnish-Beresp-Ttl
X-Request-URI
X-Varnish-Beresp-Status
X-Method
X-Slack-Backend
X-Cdn-Origin
X-Cache-Expires
Rt-Fastcgi-Cache
True-Client-Country-4JS
Pramga
IsBot
X-Kinja-Server-Push
Cf-Bgj
Vix-Hermes-Req-Id
L
X-Cache-Debug
X-CLOUD-TRACE-CONTEXT
X-Goog-Meta-Goog-Reserved-File-Mtime
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-Aicache-OS
X-Cache-Date
X-Loc
Fastly-Drupal-HTML
X-CACHE-KEY
X-Servername
Apple-News-Services-Handled
Origin
X-Nc
X-Via-Poph
X-Via-Popn
X-NCache
X-Core-Mission
X-Via-Popv
X-Mvc-Supplant-OutputCached
Esi-Enabled
Sid
X-Erf-Stays-Bingo-Pdp-Web
X-Request-Start
X-URL
X-PF-Uncompressing
Who
X-Varnish-Url
Country-Code
X-Refresh
X-Unique-ID
Url
Pics-Label
X-Epic-Correlation-Id
X-Esi
X-FireWall-Protection
X-NC
X-Cache-Remote
X-Tb-Optimization-Total-Bytes-Saved
X-Dynatrace
Req-Svc-Chain
X-Response-By
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
X-Varnish-Cacheable
X-TraceId
Geo-Info
X-Webkit-Csp
S-Rt
Xkeyi7
X-Error
X-Proxy-Cachei7
X-DC
X-RateLimit-Limit
Cmsid
X-BBXSRF
N-Cache
Content-Secure-Policy
Source
Cmstype
X-Webkit-CSP-Report-Only
Filterid
X-B3-Spanid
X-Srv
X-Host-Name
Geoip-Latitude
GeoIp-Country-Code
Server-Ttl
X-Cache-2
X-Served-From
Svr
Kp-EeAlive
X-HS-Status
HitType
X-Sucuri-Cache
Cross-Origin-Window-Policy
X-LiteSpeed-Cache-Control
X-Cc-Req-Id
Viewtype
MIME-Version
X-Cc-Via
X-Cache-ASPX
X-Servedbyhost
X-Wa
A
X-Contensis-Viewer-Groups
VivaBuild
Cteonnt-Length
X-Varnish-Authentication
Ohc-File-Size
Tcn
D-Cc-Upstream
Cache-Key
X-CDN-Forward
X-HostName
X-Vcl-Version
M-TraceId
X-Svr
X-Oracle-Dms-Rid
X-Server-IP
NGB
X-Air-Source
X-LI-Proto
Cross-Origin-Opener-Policy
TDXMobile
Server-ID
Arc-Country
SID
CACHE
X-Cache-Config
X-FPC
X-Origin-Time
X-Nyt-Route
X-Vgn-Hpd-Reason
X-Li-Proto
X-API-Version
X-Gdpr
X-RAMCache
X-HOST
NtCoent-Length
X-Cs
XServer
X-Vc
X-VC
X-VCL-Version
X-Check-Cacheable
Resin-Trace
Hostname
Request-ID
X-SN
X-UA
Server-Id
X-SB
X-ServedByHost
X-RPM
X-RSL
X-Viewer-Country
X-TIM-N
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-Webstats-RespID
X-WA
X-CCDN-CacheTTL
Cache-Provider
X-RPS
X-DSS
X-Newrelic-Synthetics
X-DI
X-DB
X-Internal-Host
X-NodeID
X-DW
X-FORWARDED-FOR
X-Service
X-NGENIX-Cache
X-JoinUs
Ohc-Cache-HIT
X-SaId
X-PHP-Backend
GeoIP-Latitude
X-Edge-Location
GeoIP-Country-Code
X-Geo
X-App
Mime-Version
X-SD-PageType
Srv
X-NGINX-Cache
X-Forwarded-Site
X-COUNTRY
FSS-Cache
X-Action
X-Provided-By
ProcessTime
DataCenter
X-Render-Time
X-Via-NSCOPI
X-BBC-Edge-Cache-Status
X-Dynatrace-Js-Agent
X-FTR-Cache-Host
CF-Cached-On
X-TIME
X-CF-Powered-By
EpKe-Alive
X-Fpc
W
X-Extlb
X-Oss-Cdn-Auth
X-Presslabs-Stats
X-CSRF-TOKEN
X-Ua
X-Bc-Bl
X-Accel-Expires-Debug
X-Depends-On
X-Date
X-Region-Sid
We-Hiring
Surrogated-Key
Mail-Subject
X-PJAX-URL
X-Req
Memcached
X-Proxy-Upstream
X-VC-Cache
LB
Processtime
Upgrade-Insecure-Requests
X-Worker
X-Auto-Login
Datacenter
X-HITS
X-Cdn-Request-ID
X-RateLimit-Limit-Second
X-MSEdge-Features
X-MSEdge-Flight
X-ZONE
CDN
Proxy-Connection
X-UnsetCookies
X-BACKEND-TTL
Env
X-RateLimit-Remaining-Second
X-Cluster-Node
X-Dw-Trace-Id
X-Ftr-Cache-Host
X-Fastly-Backend-Reqs
Cdn
X-Client-Ip
X-Swift-Error
X-CACHE-AGE
X-Air-Trace-Id
X-Flog
X-Hello
X-ABtesting
X-Men
Memory
PICS-Label
Time
X-Pf-Uncompressing
X-Sigma-Backend
X-Parent-Response-Time
Dnion-Transfer-Encoding
X-Cache-Tag
X-BBC-Origin-Response-Status
X-IN-APIGATEWAY
X-Rocket-Build-Number
X-IN-APIGATEWAYSSL
X-Sigma
X-APP
X-Fastly-Request-Id
X-Akamai-Pragma-Client-IP
X-Acquia-Application-Trace
X-Acquia-Purge-Tags
Media-Length
VNS-Age
X-Acquia-Site
X-Acquia-Application-UUID
X-Oracle-DMS-ECID
CPC-Age
VNS-Cache
X-Zone
Vha6-Origin
CPC-Cache
X-Pad
X-LiteSpeed-Tag
X-Via-PopN
Epwk-X-Cache
OT-Force-Account-Verify
X-Via-PopV
X-Via-PopH
Cf-Ipcountry
X-Varnish-URL
X-Akamai-ERPolicy
X-Request-Url
X-ElasticPress-Query
X-Varnish-Beresp-TTL
X-MiniProfiler-Ids
X-Vcache
X-Akamai-ERRuleID
WZWS-RAY
X-ND-Cache
X-Csrf-Token
X-Snapshot-Date
X-Request-URL
X-Lb-Id
X-Ms-Meta-Originalurl
X-Ms-Meta-Staticbatchstarttime
Xet-Cookie
X-ElasticPress-Search
CountryCode
X-Tx-Id
URI
NnCoection
X-Amz-Meta-Cb-Modifiedtime
Phost
X-Litespeed-Cache-Control
State
Fastcgi-Cache-TTL
Content-Style-Type
Content-Script-Type
X-Redis-Duration-Ms
X-Redis-Count
X-Storefront-Renderer-Verified
Ohc-Response-Time
X-Debug-Cache-Fetch
Environment
Inserted-Into-Cache-At
X-B3-Parentspanid
X-Tid
X-Traceid
X-C
X-ServerName
X-Debug-Cache-Store