Threat Level: green Handler on Duty: Renato Marinho

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
X-XSS-Protection
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-Served-By
X-UA-Compatible
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Xss-Protection
X-Request-ID
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Ua-Compatible
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Content-Encoding
X-CDN
Feature-Policy
X-AspNetMvc-Version
X-Envoy-Upstream-Service-Time
Status
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-Via
Upgrade
Access-Control-Max-Age
Keep-Alive
X-Ws-Request-Id
X-Age
X-AH-Environment
X-Turbo-Charged-By
X-Robots-Tag
Request-Context
X-Cache-Group
X-Proxy-Cache
EagleId
Server-Timing
X-Backend
X-Hacker
X-Server
Report-To
Host-Header
X-Amz-Request-Id
X-Server-Powered-By
X-Amz-Id-2
Grace
X-Nginx-Cache-Status
X-UA-Device
X-Rq
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Page-Speed
X-LiteSpeed-Cache
Cf-Railgun
X-Pingback
X-OneAgent-JS-Injection
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
NEL
X-Dns-Prefetch-Control
X-Cache-Spec
X-Amz-Version-Id
X-WebKit-CSP
X-Device
X-CST
Allow
Xkey
X-Host
X-Vhost
X-Backend-Server
X-Server-Id
EagleEye-TraceId
Request-Id
Surrogate-Control
X-Dispatcher
X-Node
Content-Location
X-Response-Time
X-Ruxit-JS-Agent
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Akam-SW-Version
Accept-CH
P3p
X-ASPNET-VERSION
X-Application-Context
Accept-CH-Lifetime
X-Ac
X-Cache-Lookup
X-Template
X-Language
X-Country
X-Mod-Pagespeed
X-Readtime
Accept-Ch
X-Cloud-Trace-Context
MS-Author-Via
X-B3-TraceId
Accept-Ch-Lifetime
Rating
X-Origin-Cache
X-Cnection
X-MS-InvokeApp
X-HW
X-Vname
X-PC
X-TtlSet
X-Url
X-Clacks-Overhead
Edge-Control
X-GitHub-Request-Id
X-ORACLE-DMS-ECID
X-Trace
X-ESI
X-Content-Type
Response
X-Middleton-Response
X-Sol
X-Middleton-Display
Display
Pagespeed
X-D2id
X-ORACLE-DMS-RID
Arr-Disable-Session-Affinity
X-GoogleNews-Bot
X-Exp-Id
X-Kinja-Revision
X-Cdn-Fetch
X-Kinja
X-Use-Magma
X-Kinja-Build
X-Kinja-Server
X-Exp-Variant
X-Vcap-Request-Id
Verso
X-FastCGI-Cache
X-Goog-Hash
X-Buckets
X-Rack-Cache
X-Country-Code
X-Varnish-TTL
X-Server-Name
Service-Worker-Allowed
X-Navigation-Version
X-Powered-By-Plesk
X-Amz-Rid
X-Abt-Application-Version
X-VARITI-CCR
X-Fastly-Request-ID
X-Webkit-CSP
X-TTL
X-Client-IP
X-Cache-TTL
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
Fastly-Restarts
X-Litespeed-Cache
X-MSEdge-Ref
X-SharePointHealthScore
SPRequestGuid
X-Release
X-Dw-Request-Base-Id
X-Cached
X-Element-Page-Cache
X-Oneagent-Js-Injection
X-NF-Request-ID
SPIisLatency
SPRequestDuration
Public-Key-Pins
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
RTSS
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Access-Control-Request-Method
AR-PoweredBy
AR-CACHE
Ar-Sid
AR-Request-ID
AR-ATIME
X-LLID
X-Edge
X-Powered-CMS
X-Ezoic-Cdn
X-Origin-Upstream-Status
Cache-Tag
Content-MD5
X-Upstream
X-Px
Fusion-Content-Id
Fusion-Deployment-Id
Fusion-Content-Source
Fusion-Component-Id
Fusion-Template-Id
Fusion-Source
X-HP-Webp
X-Jurisdiction
S
X-Version
X-Recruiting
X-Mid
X-ECACHE
X-MCACHE
X-Mg-S
Charset
X-Content-Digest
X-Ttl
Fastcgi-Cache
X-Amz-Server-Side-Encryption
X-Kinsta-Cache
X-PressLabs-Stats
X-T
Cache-Tags
MicrosoftSharePointTeamServices
Front-End-Https
X-DynaTrace
X-Content-Security-Policy-Report-Only
TCN
X-Logged-In
Filters
X-Debug
Edge-Cache-Tag
X-Accel-Expires
Server-Node
X-Id
X-Grace
X-Correlation-Id
X-Forwarded-Proto
TP-Cache
TP-L2-Cache
Nginx-Cache
Server-Name
X-Pinterest-Direct
X-Amzn-Trace-Id
X-Forwarded-For
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Surrogate-Key
X-Request-Processing-Time
X-Request-Received
X-Yandex-Sdch-Disable
X-Varnish-Age
X-Shield-Request-Id
X-B3-Sampled
X-Request-Handler-Origin-Region
X-Microsite
X-Ser
X-Hits
X-Az
X-Activity-Id
X-AppVersion
X-XRDS-Location
X-Amz-Replication-Status
X-F-Cache
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Cache-Config
X-DIS-Request-ID
X-XRDS-LOCATION
X-Goog-Generation
X-GUploader-UploadID
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Origin-Server
Accept-Charset
X-Geo-Country
X-Git-Hash
Alternate-Protocol
X-Cache-Key
X-Respond-Thread
Cache
X-Rid
X-FTR-Request-ID
X-Frontend
X-Fastcgi-Cache
Section-Io-Cache
X-Upgrade-Enabled
X-LB-Cache
Host
X-DataDome
X-Time
Powered-By-ChinaCache
X-Ruxit-Js-Agent
X-NWS-LOG-UUID
X-Mobile-URL
X-Seen-By
Access-Control-Allow-Method
X-Server-ID
X-Cache-Age
X-VCache
Paypal-Debug-Id
X-AOL-HN
MS-CV
Healthy
Cleartype
ServerID
X-TT
X-Hostname
X-Varnish-Backend
X-IPLB-Instance
X-Type
X-Content-Options
X-Aspnet-Duration-Ms
X-Is-Crawler
X-Providence-Cookie
X-Route-Name
X-Whom
X-App-Environment
X-Flags
X-Request-Guid
X-TEC-API-ROOT
X-Signature
X-Cache-Action
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-B-Cache
X-Jobs
X-Source
Payment
Fastcgi-Useragent
X-Debug-Info
X-Page-Id
X-WebKit-CSP-Report-Only
X-Load-Cache
X-N
X-Daa-Tunnel
X-Mobile
X-FB-Debug
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
Nel
X-Via-JSL
X-RateLimit-Remaining
X-Contextid
Realpath
Refresh
Version
Node
X-Cached-By
X-Response-Served-From
X-Drupal-Cache-Tags
X-Akamai-Edgescape
X-Wix-Request-Id
X-Original-Request-Id
X-Accel-Buffering
X-Rule
X-Cacheable-TTL
DC
X-Zen-Fury
X-Proxy
Viewport
X-ProcessESI
X-Framework
X-RTag
X-Cache-Operation
Ms-Operation-Id
X-RemovedCookies
X-Cache-Rule
X-B
Referer-Policy
X-Cache-Time
X-Distributor
X-HTML-Minification-Powered-By
X-Instance
X-UUID
Access-Control-Request-Headers
X-Page-View
X-Real-IP
X-Drupal-Cache-Contexts
X-Region
X-Cache-Expired-At
X-Tt-Trace-Tag
X-Tt-Trace-Host
Eomportal-Instance
X-Cluster-Name
X-Cache-Control
X-FW-Static
X-FW-Type
Liferay-Portal
X-FW-Hash
X-FW-Server
VIX-Pulpo-Upstream-Status
X-FW-Serve
VIX-Pulpo-Node
X-FW-Dynamic
X-Content-Powered-By
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-IPS-LoggedIn
X-G
X-Cache-Hit
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
Countrycode
X-L-Path
DynaTrace
X-Tumblr-Pixel
X-Tumblr-User
X-Environment-Context
X-FireWall-Port
X-Pass-Why
Server-Info
X-App-Server
GEO-INFO
X-Varnish-Ttl
Ec-Rule-Version
X-Ratelimit-Limit
X-User-Agent
X-Protected-By
From-Origin
CF-IPCountry
X-Tumblr-Pixel-2
Section-Io-Origin-Status
Section-Origin-Responded
Webserver
Section-Io-Id
Section-Io-Origin-Time-Seconds
X-Node-Name
SRV
X-Ratelimit-Remaining
Xserver
X-Www-Served-By
Protected
X-Cache-Server
X-Nginx-Cache
X-Endurance-Cache-Level
X-ES-SERVER
X-Mode
X-UPSTREAM-Address
Meta-Geo
X-RN-RSRV
X-Handled-By
X-Site-Version
X-Uri
X-FB-TRIP-ID
X-Locale
X-Debug-IsConnected
X-Debug-IsPreview
Frame-Options
Cache-Tv-Group
X-NYM-Debug-Backend
X-Be
X-Adobe-Content
X-Soup
X-Web-Node
X-Adobe-Loc
X-UA-Device-Type
Cache-Status
X-Storage
X-PHP-Host
X-Labrador-Cache-Channel
Decoy-Debug-Key
Fastly-SSL
Decoy-Debug-TTL
Decoy-Debug-Status
Country
TWC-Privacy
Webcakes-App-Name
Webcakes-App-Version
Webcakes-Region
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-Country
Property-Id
X-Backend-Name
X-No-Session
X-Sql-Count
X-Hyper-Cache
X-Varnishpool
X-Via-Fastly
X-Request-Time
X-Redis-Cache
X-Origin-Hint
X-PCL
X-Origin-Date
X-OCL
X-Pubstack
X-Human
X-Sql-Duration-Ms
X-MP-GENERATED-AT
X-Hl-Ver
X-ProxyCache-Status
X-AIR-PT
X-BYPASS-REASON
Retry-After
X-R9-Blue-Green-Version
X-Say-Cacheable
X-S-Maxage
X-Cache-Grace
X-AWS-Id
X-Device-Type
Azure-SiteName
Azure-SlotName
Azure-Version
Azure-RegionName
Azure-InstanceId
X-Hosted-By
X-ProxyCache-Key
X-Proto
X-Revision
X-Say-TTL
X-SayCDN-TTL
X-TNCMS
X-Forwarded-Host
X-FW-Version
X-VWS-Id
X-WA-Info
X-Loop
X-Format
X-LAGOON
X-Section
X-Server-W
Cache-Name
X-Access
X-LJ-Flow-ID
X-Xfnlog-Site
X-TT-LOGID
X-Cache-TTL-Remaining
X-CCM
X-Cluster
X-Status
X-PERF
X-ApacheServer
X-ShardId
X-Sorting-Hat-ShopId
X-ShopId
Selected-Fe
X-Shopify-Stage
X-Sorting-Hat-PodId
Mn-Server-Ip
X-Storefront-Renderer-Rendered
X-Proxy-Build
X-Timing-Wait
X-Alternate-Cache-Key
X-Zipkin-Id
X-Routing-Service
X-Proxied
X-Qloud-Router
X-SRV
X-Rendered-As
X-Is-Bot
X-Varnish-Grace
Apigw-Requestid
X-Amz-Meta-S3cmd-Attrs
X-Info
X-Varnish-Server
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-DC
X-FTR-Backend-Server
X-FTR-Backend
X-Via-CDN
X-FTR-Realm
X-Country-Code-Real
S-Cnection
X-Cdn
Cache-Hits
X-Microcachable
X-Cache-Enabled
X-Dc
X-FTR-Expires
X-GG-Cache-Date
AMP-Access-Control-Allow-Source-Origin
X-Content-Age
X-Cache-Host
X-Detected-As
Uber-Trace-Id
X-Proxy-Cache-Status
X-Platform
X-Aspnetmvc-Version
X-Azure-Ref
X-Amzn-Remapped-Content-Length
Amp-Access-Control-Allow-Source-Origin
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Backend-Host
X-Tec-Api-Version
X-EdgeConnect-Cache-Status
X-Tec-Api-Root
X-Tec-Api-Origin
Tracecode
X-Air-Hostname
X-NWS-UUID-VERIFY
X-Cache-Var
X-Unique-Id
X-App-Version
SD-X-WS
X-CSRF-Token
X-Cache-Var-Map
X-Time-Microsecs
Akamai-GRN
X-DynaTrace-JS-Agent
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Oss-Request-Id
X-Oss-Server-Time
X-ATG-Version
X-GEO
X-Backend-TTL
X-Tb
X-Trace-Id
X-Correlation-ID
ServedBy
X-ServerID
X-ID
X-Debug-Cache
X-RCS-CacheZone
X-BCube-Filmed-By
X-Akamai-Transformed
HostName
Backend
X-Varnish-Hostname
X-Cache-PHP
X-B3-SpanId
X-Cache-NGX
X-Sucuri-ID
X-Cache-Backend
SR-User-Adfree
Thinkindot-CacheControl-Type
X-Ms-Version
Rendered-Blocks
T-Server
X-Ms-Request-Id
Thinkindot-CacheControl
Odigeo-Trace-Id
Fastcgi-X-Cache-Version
Expiry
Instruction
Machine
Meta-Geo-Continent
DCR-Processing-Time-Ms
DCR-Decision-By
Mobile-Detection-Method
MD5-Digest
DB-Nickname
BehaviorPad-Version
Thinkindot-Control
Path
X-D
X-Rewrite-Enabled
X-Rojux
X-S
X-S-Cookie
X-Request-UUID
X-Processor
X-Origin-TTL
X-Owner
X-PAYTM-SRV-ID
X-PBS-Appsvrname
X-ScT
X-Session-Fingerprint
X-VG-WebServer
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-VG-WebCache
X-Vdms-Version
X-SRCache-Key
X-Thinkindot-L3
X-Trv-Group
X-Vdms-Path
X-Origin-CC
X-NAPM-TraceId
X-Application
X-ARC
X-B-Cookie
X-CF-Lambda-Fn
X-Aed
X-A-Wwc
X-A-Ccd
X-A-Dam
X-A-Dcw
X-A-Dgt
X-CF-Lambda-Version
X-Connection-Hash
X-Generation-Time
X-Level-Front-Cache
X-Location
X-Matched-Rule
X-Generated-On
X-From
X-Destination
X-Device-Os
X-External-Request-Id
X-Fetched-On
X-A
X-Cache-NE
X-TA-CDN-Provider
X-CS
X-Cdn-Forward
DSUID
X-B3-Traceid
Server-Host
Release
X-Adobe-Source
X-Cache-Bucket
X-Azure-Ref-OriginShield
Cf-Device-Type
Pagetype
NGX
X-Magnolia-Registration
Content-Disposition
Fastly-Backend-Name
Host-ID
X-Cms-Context
Lfy
On-Server
X-Fastly-Cache
X-Reqid
X-OVcl-Cache
X-OVcl
X-Skip-Cache
X-TrackingId
X-VServer
X-Tumblr-Pixel-3
X-Micro-Cache
X-JWT-State
X-GeoIP
X-Geo-Header
CacheControlHeader
X-GeoIP-City
X-Has-Esi
X-Is-Gdpr
X-HS-Content-Campaign-Id
X-Core-Value
X-Node-Id
AKAMAI
X-Varnish-Cache-Hits
X-TX-ID
X-NewRelic-App-Data
User-Cache-Control
X-Rebelmouse-Cache-Control
X-Backend-State
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Swa-Ws
X-Scheme
X-Bip
X-Branch-Name
X-Cache-Id
X-Thanos
X-Block-Status
X-Rebelmouse-Surrogate-Control
X-Cache-Info
X-Variation
Ssr
UCS
X-Varnish-CookieHashed-On
Sever-Int
Server-Hostname
X-Varnish-CookieINHashed-On
X-Varnish-Beresp-Grace
V-Age
X-Ratelimit-Reset
X-IP
Wxu-Next-Region
Wxu-Next-Hostname
Web-Mar-Node
Wxu-Next-Commit
X-User
X-Platform-Server
X-Gen-Mode
X-Generated-By
X-EC-Lua
X-Mvc-Supplant-Cachable
X-Fmm-Version
X-Nginx-Cache-Key
X-FC-Vary-Parameters
X-LI-UUID
X-GoCache-CacheStatus
X-Li-Fabric
X-Irp-Debug
X-Hnp-Log
X-HN
X-Gzip
X-Li-Pop
X-Fastly-Backend
X-NU-AKA-ACS-Version
X-Origin
X-DefElseHash
X-CUA
X-Origin-Expires
Server-Ext
X-Origin-Response-Time
X-DefHash
X-Developer
X-Envoy-Decorator-Operation
X-Esi-Check
X-DPWN-IS-SECURE
X-Dispatcher-Server
X-Developers
X-Old-Content-Length
X-Clara-WADP
X-Var-Ttl
Is-Eu
Gh-Request-Id
Fastly-SWR
Fastly-SIE
Location
Locid
X-WADP-Cache
X-Wikidot-Backend
X-Wikidot-Static-Cache
Magicmarker
CloudFront-Viewer-Country
CDN-Uid
CDCHOST
Arc-Version
Cache-Host
C-Via
CDN-Cache
CDN-CachedAt
CDN-RequestId
CDN-RequestCountryCode
CDN-PullZone
CDN-EdgeStorageId
NM-Fastcgi-Cache
Adler-Geo
PB-PID
PFcat
Platform
X-VarnishDD-TTL
PB-RID
X-Varnish-Remaining-TTL
X-APP-VERSION
L
X-CGP
X-Policy
L5d-Success-Class
X-Cdn-Origin
X-Hash
Cf-Bgj
X-Varnish-Hits
IsBot
Vix-Hermes-Req-Id
X-Csrf-Jwt
Ha-Gx-Prefs
X-VG-TLSProxy
Rt-Fastcgi-Cache
HA-Ipaddr
Pramga
True-Client-Country-4JS
X-Method
X-Gamma-Serve
X-Clientip
X-Cache-Tags
X-Slack-Backend
X-Sn-Servicetimems
X-Varnish-Beresp-Ttl
X-SIPLIST1
X-Kinja-Server-Push
X-Varnish-Beresp-Status
X-Request-URI
X-Cache-Debug
X-Eu-Site
X-Request-Host
X-Cache-Expires
X-Generated-In
X-CLOUD-TRACE-CONTEXT
Origin
Apple-News-Services-Parsed-Url
Fastly-Drupal-HTML
Apple-News-Services-Handled
X-CACHE-KEY
X-Aicache-OS
Apple-News-Services-Host
X-Servername
X-Loc
X-Cache-Date
X-Goog-Meta-Goog-Reserved-File-Mtime
X-LB-ID
Apple-News-Services-Request-Url
X-Nc
X-NCache
X-Core-Mission
X-Via-Poph
Esi-Enabled
X-Via-Popv
X-Via-Popn
Sid
X-Erf-Stays-Bingo-Pdp-Web
X-PF-Uncompressing
Who
X-Varnish-Url
X-Mvc-Supplant-OutputCached
X-Request-Start
X-URL
Country-Code
Url
Pics-Label
X-Unique-ID
X-Refresh
X-FireWall-Protection
X-Epic-Correlation-Id
X-NC
X-Cache-Remote
X-Planisys-CDN-Cache
X-Varnish-Cacheable
X-Tb-Optimization-Total-Bytes-Saved
Req-Svc-Chain
X-Planisys-CDN-TTL
X-Dynatrace
X-Planisys-CDN-Rules
X-Response-By
Geo-Info
S-Rt
Xkeyi7
X-Error
X-Proxy-Cachei7
X-TraceId
X-RateLimit-Limit
X-Esi
X-Webkit-Csp
X-DC
Cmsid
Content-Secure-Policy
N-Cache
X-BBXSRF
Source
Cmstype
X-Webkit-CSP-Report-Only
Filterid
X-B3-Spanid
Server-Ttl
HitType
X-Served-From
X-Srv
Kp-EeAlive
Geoip-Latitude
GeoIp-Country-Code
X-HS-Status
X-Host-Name
X-Cache-2
Svr
X-Sucuri-Cache
Cross-Origin-Window-Policy
X-Varnish-Authentication
Ohc-File-Size
X-Cc-Via
Viewtype
X-Servedbyhost
MIME-Version
X-Wa
X-LiteSpeed-Cache-Control
A
D-Cc-Upstream
VivaBuild
X-Cc-Req-Id
X-Contensis-Viewer-Groups
Tcn
Cache-Key
X-Cache-ASPX
Cteonnt-Length
X-CDN-Forward
X-Svr
M-TraceId
X-HostName
X-Vcl-Version
X-Oracle-Dms-Rid
NGB
X-Server-IP
Server-ID
Cross-Origin-Opener-Policy
X-Air-Source
X-LI-Proto
Arc-Country
TDXMobile
SID
CACHE
X-Gdpr
X-Origin-Time
X-RAMCache
X-API-Version
X-FPC
X-Cache-Config
X-Vgn-Hpd-Reason
X-Nyt-Route
X-Li-Proto
X-HOST
NtCoent-Length
X-Cs
Request-ID
X-Vc
Resin-Trace
X-VCL-Version
X-VC
Hostname
X-Check-Cacheable
XServer
X-SN
X-UA
X-DW
X-RSL
X-DSS
X-DI
Cache-Provider
X-Viewer-Country
X-CCDN-CacheTTL
X-Webstats-RespID
X-WA
X-Newrelic-Synthetics
X-ServedByHost
X-DB
X-SB
X-RPS
X-Service
X-Hcs-Proxy-Type
X-TIM-N
X-Internal-Host
X-CCDN-Origin-Time
Server-Id
X-NodeID
X-RPM
X-SaId
X-JoinUs
Ohc-Cache-HIT
Mime-Version
X-Edge-Location
X-NGENIX-Cache
X-Geo
GeoIP-Latitude
X-App
X-FORWARDED-FOR
Srv
X-PHP-Backend
GeoIP-Country-Code
X-SD-PageType
X-NGINX-Cache
X-Action
ProcessTime
X-Provided-By
FSS-Cache
X-Via-NSCOPI
X-Render-Time
DataCenter
X-BBC-Edge-Cache-Status
X-FTR-Cache-Host
X-TIME
X-Dynatrace-Js-Agent
CF-Cached-On
X-Forwarded-Site
X-CF-Powered-By
EpKe-Alive
X-Fpc
X-COUNTRY
X-Oss-Cdn-Auth
W
X-Extlb
X-Presslabs-Stats
X-Ua
X-CSRF-TOKEN
X-VC-Cache
X-Auto-Login
X-Req
Upgrade-Insecure-Requests
X-Region-Sid
X-Proxy-Upstream
Processtime
X-Depends-On
X-Worker
Memcached
X-Accel-Expires-Debug
Surrogated-Key
We-Hiring
X-PJAX-URL
Mail-Subject
X-Date
LB
Datacenter
X-Cdn-Request-ID
X-HITS
X-Fastly-Backend-Reqs
X-Cluster-Node
Env
X-Bc-Bl
X-Dw-Trace-Id
X-RateLimit-Limit-Second
Proxy-Connection
X-RateLimit-Remaining-Second
X-UnsetCookies
X-Ftr-Cache-Host
Cdn
CDN
X-BACKEND-TTL
X-MSEdge-Features
X-MSEdge-Flight
X-CACHE-AGE
X-Client-Ip
X-Swift-Error
Memory
X-Flog
X-Sigma
X-Air-Trace-Id
X-Sigma-Backend
Time
X-Rocket-Build-Number
X-APP
X-Hello
X-ABtesting
Dnion-Transfer-Encoding
PICS-Label
X-IN-APIGATEWAY
X-Cache-Tag
X-IN-APIGATEWAYSSL
X-Parent-Response-Time
X-Fastly-Request-Id
X-BBC-Origin-Response-Status
X-Akamai-Pragma-Client-IP
X-ZONE
CPC-Age
X-Acquia-Purge-Tags
Media-Length
X-Men
X-Acquia-Application-UUID
X-Zone
X-Oracle-DMS-ECID
X-Pad
CPC-Cache
X-Pf-Uncompressing
X-Acquia-Application-Trace
X-Acquia-Site
VNS-Cache
Vha6-Origin
VNS-Age
X-Via-PopH
X-Via-PopV
X-LiteSpeed-Tag
OT-Force-Account-Verify
X-Via-PopN
Epwk-X-Cache
Cf-Ipcountry
X-Csrf-Token
X-ElasticPress-Search
X-Varnish-URL
X-Vcache
X-Snapshot-Date
X-Akamai-ERPolicy
WZWS-RAY
X-Akamai-ERRuleID
X-Varnish-Beresp-TTL
X-Request-URL
X-Lb-Id
X-Ms-Meta-Originalurl
X-Ms-Meta-Staticbatchstarttime
X-ND-Cache
Xet-Cookie
X-Request-Url
X-MiniProfiler-Ids
X-ElasticPress-Query
CountryCode
X-Tx-Id
X-Litespeed-Cache-Control
X-Amz-Meta-Cb-Modifiedtime
Content-Script-Type
X-Tid
State
Content-Style-Type
Fastcgi-Cache-TTL
X-C
X-Redis-Duration-Ms
X-Redis-Count
X-B3-Parentspanid
URI
X-Traceid
NnCoection
Environment
Phost
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-ServerName
Ohc-Response-Time
X-Storefront-Renderer-Verified
Inserted-Into-Cache-At