Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Cf-Request-Id
CF-Cache-Status
Last-Modified
X-XSS-Protection
CF-RAY
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-Runtime
X-AspNet-Version
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Xss-Protection
X-Cache-Status
X-Generator
X-Request-ID
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Content-Security-Policy
Content-Encoding
X-CDN
X-Envoy-Upstream-Service-Time
Status
Feature-Policy
X-Ua-Compatible
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-AspNetMvc-Version
Access-Control-Max-Age
X-Via
CF-Ray
Upgrade
Keep-Alive
X-Ws-Request-Id
X-Age
X-Turbo-Charged-By
X-AH-Environment
X-Robots-Tag
Request-Context
X-Proxy-Cache
EagleId
X-Cache-Group
Server-Timing
X-Backend
X-Hacker
X-Amz-Request-Id
Report-To
X-Server
Host-Header
X-Amz-Id-2
X-Server-Powered-By
Grace
X-Nginx-Cache-Status
X-UA-Device
X-LiteSpeed-Cache
X-Dns-Prefetch-Control
X-Varnish-Cache
X-Rq
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Page-Speed
Cf-Railgun
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
NEL
X-Amz-Version-Id
X-OneAgent-JS-Injection
Xkey
X-WebKit-CSP
X-Cache-Spec
Allow
X-Backend-Server
X-Host
X-CST
X-Vhost
X-Device
EagleEye-TraceId
X-Server-Id
X-ASPNET-VERSION
Surrogate-Control
Request-Id
X-Dispatcher
X-Node
Accept-CH
Content-Location
X-Response-Time
Accept-CH-Lifetime
X-Akam-SW-Version
X-Ruxit-JS-Agent
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
P3p
X-Ac
X-Template
X-Language
X-Application-Context
X-Kinja-Server-Push
X-Country
X-Cache-Lookup
X-Readtime
X-Cloud-Trace-Context
X-Mod-Pagespeed
MS-Author-Via
X-B3-TraceId
X-Origin-Cache
Rating
X-Cnection
X-MS-InvokeApp
X-Url
X-HW
X-TtlSet
X-Vname
X-PC
X-ORACLE-DMS-ECID
Accept-Ch
X-Clacks-Overhead
X-ESI
X-GitHub-Request-Id
X-FastCGI-Cache
Edge-Control
Accept-Ch-Lifetime
X-Trace
X-Sol
X-Middleton-Display
Display
Response
X-Middleton-Response
Pagespeed
X-Content-Type
X-D2id
Verso
Arr-Disable-Session-Affinity
X-Vcap-Request-Id
X-Cdn-Fetch
X-Exp-Id
X-GoogleNews-Bot
X-Kinja-Server
X-Kinja-Revision
X-Kinja-Build
X-Kinja
X-Exp-Variant
X-Use-Magma
X-Buckets
X-Goog-Hash
X-Rack-Cache
X-Server-Name
X-Country-Code
Service-Worker-Allowed
X-Navigation-Version
X-Varnish-TTL
X-Abt-Application-Version
X-VARITI-CCR
X-Amz-Rid
X-Oneagent-Js-Injection
X-Powered-By-Plesk
Pinterest-Version
X-ORACLE-DMS-RID
X-Pinterest-Rid
Pinterest-Generated-By
X-Cache-TTL
X-Client-IP
X-SharePointHealthScore
SPRequestGuid
X-Fastly-Request-ID
X-MSEdge-Ref
SPIisLatency
SPRequestDuration
X-Release
X-Dw-Request-Base-Id
X-Element-Page-Cache
Fastly-Restarts
X-TTL
X-NF-Request-ID
X-Cached
Public-Key-Pins
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
RTSS
X-Origin-Upstream-Status
AR-PoweredBy
AR-CACHE
AR-ATIME
Ar-Sid
X-Edge
AR-Request-ID
X-SRCache-Store-Status
Access-Control-Request-Method
X-SRCache-Fetch-Status
X-Px
X-Webkit-CSP
X-LLID
X-Powered-CMS
Fusion-Content-Source
Fusion-Deployment-Id
Fusion-Content-Id
Fusion-Source
Fusion-Template-Id
Fusion-Component-Id
X-Ezoic-Cdn
X-Upstream
Content-MD5
X-Ttl
X-Jurisdiction
X-HP-Webp
X-Amz-Server-Side-Encryption
X-MCACHE
X-Mid
X-ECACHE
Charset
Cache-Tag
X-Recruiting
X-Mg-S
S
X-Content-Digest
X-Pinterest-Direct
X-PressLabs-Stats
X-Aspnetmvc-Version
X-Version
TCN
MicrosoftSharePointTeamServices
Fastcgi-Cache
Front-End-Https
X-Debug
X-Content-Security-Policy-Report-Only
X-T
X-Grace
X-Kinsta-Cache
Cache-Tags
X-XRDS-Location
Edge-Cache-Tag
Server-Node
Filters
X-Id
X-Forwarded-Proto
X-Accel-Expires
X-Correlation-Id
X-Logged-In
X-Amzn-Trace-Id
X-Forwarded-For
X-Yandex-Sdch-Disable
Server-Name
Nginx-Cache
Surrogate-Key
X-Varnish-Age
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Cache-Key
TP-L2-Cache
TP-Cache
X-B3-Sampled
X-Request-Received
X-Request-Processing-Time
X-Microsite
X-DynaTrace
X-Hits
X-Request-Handler-Origin-Region
X-DIS-Request-ID
Powered-By-ChinaCache
X-Ser
X-Shield-Request-Id
X-Az
X-Activity-Id
X-AppVersion
X-Amz-Replication-Status
X-Server-ID
X-HS-Content-Id
X-F-Cache
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Combine-CSS
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-GUploader-UploadID
X-Origin-Server
Accept-Charset
X-FTR-Request-ID
X-Git-Hash
X-Hostname
X-Respond-Thread
X-Geo-Country
X-Upgrade-Enabled
X-DataDome
X-LB-Cache
X-Rid
Section-Io-Cache
X-Frontend
X-Cache-Age
Access-Control-Allow-Method
Alternate-Protocol
Cache
Host
X-Mobile-URL
Cleartype
MS-CV
Paypal-Debug-Id
Healthy
X-Type
X-IPLB-Instance
X-Content-Options
ServerID
X-AOL-HN
X-WebKit-CSP-Report-Only
X-Ruxit-Js-Agent
X-Whom
X-Varnish-Backend
X-App-Environment
X-Seen-By
Payment
X-Aspnet-Duration-Ms
X-Flags
X-Is-Crawler
X-Debug-Info
X-Route-Name
X-Signature
X-Request-Guid
X-Providence-Cookie
X-Cache-Action
X-B-Cache
X-XRDS-LOCATION
X-VCache
X-TT
X-Page-Id
Fastcgi-Useragent
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Jobs
X-NWS-LOG-UUID
X-N
X-Source
X-Mobile
X-Time
X-Erf-Bev-Bev
X-Load-Cache
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-RateLimit-Remaining
X-Via-JSL
X-Cached-By
X-Daa-Tunnel
X-Akamai-Edgescape
X-FB-Debug
Version
Nel
X-Cache-Operation
X-Cache-Rule
X-Litespeed-Cache
Viewport
Refresh
X-Accel-Buffering
DynaTrace
X-Original-Request-Id
X-Rule
X-Response-Served-From
DC
X-Proxy
X-Zen-Fury
X-Framework
X-Drupal-Cache-Tags
GEO-INFO
X-RemovedCookies
Ms-Operation-Id
X-Cacheable-TTL
Realpath
X-Instance
X-ProcessESI
X-RTag
X-Contextid
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Fastcgi-Cache
X-Real-IP
Access-Control-Request-Headers
X-Cache-Time
X-HTML-Minification-Powered-By
X-Region
X-UUID
X-Wix-Request-Id
X-Distributor
Referer-Policy
X-Drupal-Cache-Contexts
X-Page-View
X-FW-Type
X-Cache-Expired-At
VIX-Pulpo-Upstream-Status
Node
VIX-Pulpo-Node
X-FW-Hash
X-FW-Serve
X-FW-Dynamic
X-Yottaa-Metrics
X-FW-Server
X-Yottaa-Optimizations
X-FW-Static
X-Environment-Context
X-L-Path
Eomportal-Instance
X-B
X-Cluster-Name
Liferay-Portal
Countrycode
X-Tumblr-User
X-Cache-Control
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-G
X-Tumblr-Pixel-0
X-Node-Name
X-Content-Powered-By
X-IPS-LoggedIn
X-Cache-Hit
X-User-Agent
Server-Info
Webserver
X-Tumblr-Pixel-2
X-Amz-Meta-S3cmd-Attrs
X-Pass-Why
From-Origin
X-App-Server
Section-Io-Origin-Status
X-Varnish-Ttl
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
Section-Io-Id
X-Ratelimit-Limit
SRV
Protected
X-Protected-By
Ec-Rule-Version
X-FireWall-Port
X-Revision
X-Backend-Name
X-Cache-Server
X-Oracle-Dms-Rid
Frame-Options
Cache-Status
CF-IPCountry
X-ES-SERVER
X-UPSTREAM-Address
Meta-Geo
X-Mode
X-Www-Served-By
X-RN-RSRV
X-Handled-By
X-Hyper-Cache
X-Endurance-Cache-Level
X-Hl-Ver
X-NYM-Debug-Backend
X-Storage
X-Forwarded-Host
Retry-After
X-FB-TRIP-ID
X-Locale
X-Soup
X-Site-Version
Country
X-Cache-Grace
Decoy-Debug-Key
X-Web-Node
X-Pubstack
X-Human
X-Varnishpool
X-Adobe-Content
X-Be
Decoy-Debug-TTL
X-Adobe-Loc
Decoy-Debug-Status
Cache-Tv-Group
Fastly-SSL
Azure-InstanceId
Azure-SiteName
Azure-Version
Azure-SlotName
Azure-RegionName
Webcakes-App-Version
X-ProxyCache-Status
X-Labrador-Cache-Channel
X-Redis-Cache
X-Format
X-UA-Device-Type
X-Uri
X-ProxyCache-Key
X-Proxy-Build
X-Origin-Date
X-OCL
X-Origin-Hint
X-PCL
X-Proto
X-PHP-Host
X-TT-LOGID
X-Timing-Wait
TWC-GeoIP-LatLong
TWC-Locale-Group
TWC-GeoIP-Country
TWC-Device-Class
Selected-Fe
TWC-Connection-Speed
TWC-Privacy
Webcakes-Region
X-Say-TTL
X-Say-Cacheable
X-Section
X-SayCDN-TTL
X-Access
X-BYPASS-REASON
Property-Id
Webcakes-App-Name
X-PERF
X-AIR-PT
X-ApacheServer
X-Via-Fastly
X-FW-Version
X-No-Session
X-LAGOON
X-Sql-Duration-Ms
X-S-Maxage
X-Via-CDN
X-Server-W
X-Sql-Count
Cache-Name
X-Hosted-By
X-AWS-Id
X-TNCMS
X-Request-Time
X-Loop
X-R9-Blue-Green-Version
X-WA-Info
X-VWS-Id
X-LJ-Flow-ID
X-FTR-Cache-Status
X-FTR-Balancer
X-Qloud-Router
X-MP-GENERATED-AT
X-FTR-Realm
X-FTR-Backend
X-FTR-DC
Mn-Server-Ip
X-Status
X-Country-Code-Real
S-Cnection
X-Cluster
X-FTR-Backend-Server
X-Zipkin-Id
X-Cache-TTL-Remaining
X-Proxied
X-Routing-Service
X-CCM
X-ShopId
X-ShardId
X-Alternate-Cache-Key
X-Ratelimit-Remaining
X-Xfnlog-Site
X-Sorting-Hat-PodId
X-Shopify-Stage
X-Sorting-Hat-ShopId
X-Storefront-Renderer-Rendered
X-FTR-Expires
Cache-Hits
X-Rendered-As
Xserver
X-Is-Bot
X-Dynatrace
X-Tec-Api-Origin
X-Tec-Api-Root
X-Unique-Id
X-Tec-Api-Version
X-Device-Type
X-Air-Hostname
X-Cache-Var
X-Cache-Var-Map
X-SRV
X-Info
AMP-Access-Control-Allow-Source-Origin
Apigw-Requestid
X-Detected-As
X-EdgeConnect-Cache-Status
X-Webkit-Csp
X-Cache-Host
X-Amz-Apigw-Id
X-Amzn-Remapped-Content-Length
X-Dc
X-Amzn-RequestId
X-Cdn
X-Microcachable
X-Debug-IsConnected
X-Debug-IsPreview
X-Cache-Enabled
X-Nginx-Cache
SD-X-WS
X-Content-Age
X-GEO
X-Varnish-Grace
X-Platform
X-Varnish-Server
Tracecode
Amp-Access-Control-Allow-Source-Origin
X-Time-Microsecs
X-Azure-Ref
X-Backend-TTL
X-Backend-Host
Uber-Trace-Id
X-Cache-Backend
X-ServerID
X-APP-VERSION
X-GG-Cache-Date
X-DynaTrace-JS-Agent
X-Proxy-Cache-Status
X-Erf-Stays-Bingo-Pdp-Web
X-BCube-Filmed-By
X-Tb
Akamai-GRN
X-Oss-Storage-Class
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
X-Oss-Object-Type
X-ATG-Version
DSUID
Arc-Version
X-Trace-Id
PB-PID
PB-RID
X-Sucuri-ID
Backend
ServedBy
X-NewRelic-App-Data
X-Akamai-Transformed
X-Correlation-ID
X-ID
X-Magnolia-Registration
X-A-Dam
X-VG-WebServer
X-Varnish-Cache-Hits
X-VG-WebCache
X-A-Dcw
X-A-Ccd
X-A
Thinkindot-Control
X-Cache-PHP
X-Cache-NGX
X-Vtex-Processado-Em
X-Vdms-Version
X-A-Dgt
X-ARC
X-SRCache-Key
X-Session-Fingerprint
X-ScT
X-Application
X-Aed
X-A-Wwc
X-Vdms-Path
X-Trv-Group
X-Thinkindot-L3
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
Machine
MD5-Digest
Meta-Geo-Continent
Mobile-Detection-Method
Lfy
Instruction
DCR-Processing-Time-Ms
Expiry
Fastcgi-X-Cache-Version
BehaviorPad-Version
Odigeo-Trace-Id
Path
SR-User-Adfree
X-Vtex-Remote-Cache
T-Server
X-S-Cookie
X-Varnish-Hostname
Xc-Version
Pramga
X-RCS-CacheZone
Release
Rendered-Blocks
DCR-Decision-By
X-B-Cookie
X-Location
X-CF-Lambda-Version
X-Level-Front-Cache
X-Connection-Hash
X-CF-Lambda-Fn
X-Origin-CC
X-PBS-Appsvrname
X-PAYTM-SRV-ID
X-Origin-TTL
X-D
X-Destination
X-Fetched-On
X-Generated-On
X-From
X-Generation-Time
X-External-Request-Id
X-Device-Os
X-GeoIP-City
X-Origin-Response-Time
X-Processor
X-Matched-Rule
X-Request-UUID
X-Rewrite-Enabled
X-CSRF-Token
X-S
X-Rojux
X-Cache-NE
X-Ms-Version
X-Ms-Request-Id
X-GeoIP
X-Skip-Cache
X-Bip
Cf-Device-Type
Pagetype
X-Sn-Servicetimems
X-Geo-Header
X-Eu-Site
X-Cache-Bucket
Gh-Request-Id
Fastly-Backend-Name
X-Generated-In
X-Cache-Info
Ha-Gx-Prefs
HA-Ipaddr
X-Swa-Ws
X-FC-Vary-Parameters
Host-ID
L5d-Success-Class
X-CGP
X-Node-Id
X-Mvc-Supplant-Cachable
X-VServer
X-Micro-Cache
X-Cdn-Origin
X-Reqid
X-Tumblr-Pixel-3
X-Owner
X-OVcl-Cache
X-OVcl
X-Thanos
X-Cache-Date
X-HS-Content-Campaign-Id
X-User
X-Has-Esi
X-Azure-Ref-OriginShield
X-Irp-Debug
Ssr
UCS
X-JWT-State
X-Is-Gdpr
X-Csrf-Jwt
X-Backend-State
C-Via
Cache-Host
AKAMAI
X-Debug-Cache
X-Adobe-Source
X-NWS-UUID-VERIFY
CacheControlHeader
DB-Nickname
X-Wikidot-Backend
X-Cache-Tags
X-Wikidot-Static-Cache
X-Core-Value
X-CUA
X-Developers
X-Developer
X-B3-Traceid
X-TrackingId
Wxu-Next-Region
Server-Hostname
Server-Host
Server-Ext
Sever-Int
V-Age
Wxu-Next-Hostname
Wxu-Next-Commit
X-Envoy-Decorator-Operation
X-Fastly-Backend
X-Cache-Remote
X-Request-URI
User-Cache-Control
X-Scheme
X-Var-Ttl
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Policy
X-Origin-Expires
X-HN
X-Generated-By
X-Fastly-Cache
X-VarnishDD-TTL
X-IP
X-Nginx-Cache-Key
X-Varnish-Hits
PFcat
X-Cms-Context
NGX
Locid
On-Server
Magicmarker
L
CloudFront-Viewer-Country
Content-Disposition
X-DPWN-IS-SECURE
Is-Eu
X-Esi-Check
X-VG-TLSProxy
X-GoCache-CacheStatus
X-TA-CDN-Provider
X-Gen-Mode
X-Dispatcher-Server
X-Fmm-Version
Apple-News-Services-Parsed-Url
X-Clara-WADP
X-Clientip
Apple-News-Services-Handled
X-Cache-Id
X-Cache-Expires
X-WADP-Cache
X-TX-ID
X-Gzip
X-DefHash
X-DefElseHash
Apple-News-Services-Host
IsBot
CDCHOST
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Ratelimit-Reset
X-Platform-Server
Fastly-SIE
X-Varnish-Beresp-Grace
X-Request-Host
X-SIPLIST1
X-Servername
X-Variation
X-Request-Start
X-Origin
X-Old-Content-Length
X-LI-UUID
X-Loc
X-Li-Pop
X-Li-Fabric
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
Cf-Bgj
X-NU-AKA-ACS-Version
Fastly-SWR
X-Varnish-CookieHashed-On
X-Method
X-Hnp-Log
Apple-News-Services-Request-Url
NM-Fastcgi-Cache
Location
Origin
Adler-Geo
Web-Mar-Node
Vix-Hermes-Req-Id
True-Client-Country-4JS
Platform
Rt-Fastcgi-Cache
X-Block-Status
X-Branch-Name
X-NC
X-Gamma-Serve
X-Slack-Backend
CDN-CachedAt
X-Varnish-Beresp-Ttl
X-B3-Spanid
X-Cache-Debug
CDN-Cache
CDN-RequestCountryCode
X-Varnish-Beresp-Status
Fastly-Drupal-HTML
X-NAPM-TraceId
X-Hash
CDN-PullZone
X-Goog-Meta-Goog-Reserved-File-Mtime
CDN-EdgeStorageId
CDN-Uid
CDN-RequestId
HostName
X-App-Version
Url
X-PF-Uncompressing
X-EC-Lua
CACHE
X-Varnish-Url
X-Core-Mission
X-NCache
X-Host-Name
X-CS
X-Cdn-Forward
X-Mvc-Supplant-OutputCached
X-Varnish-Cacheable
X-Aicache-OS
X-Response-By
S-Rt
X-B3-SpanId
X-CACHE-GROUP
X-Proxy-Cachei7
X-Refresh
Xkeyi7
Pics-Label
N-Cache
Sid
X-BBXSRF
Cross-Origin-Window-Policy
X-LB-ID
X-CDN-Forward
X-Sucuri-Cache
Esi-Enabled
Ohc-File-Size
X-Via-Popv
X-FireWall-Protection
X-Via-Popn
X-Via-Poph
Content-Secure-Policy
X-Cache-2
X-Varnish-Authentication
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Cc-Req-Id
X-Cc-Via
Cteonnt-Length
X-Epic-Correlation-Id
D-Cc-Upstream
X-Servedbyhost
X-Wa
X-Svr
X-Error
X-Tb-Optimization-Total-Bytes-Saved
MIME-Version
Source
X-RateLimit-Limit
X-Nc
X-TraceId
Who
X-Cs
X-Srv
X-DC
Geoip-Latitude
X-Server-IP
GeoIp-Country-Code
Req-Svc-Chain
Country-Code
X-Unique-ID
X-NGINX-Cache
X-Webkit-CSP-Report-Only
X-API-Version
HitType
X-HS-Status
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
XServer
X-Gdpr
X-LiteSpeed-Cache-Control
X-Cache-Config
X-Origin-Time
X-FPC
Hostname
X-Nyt-Route
Server-Ttl
X-LI-Proto
X-VC
X-SN
X-TIME
Ohc-Cache-HIT
X-URL
X-Fastly-Request-Id
X-Webstats-RespID
Kp-EeAlive
Cmsid
X-NodeID
Server-ID
Svr
Cmstype
X-SB
X-VCL-Version
Geo-Info
X-CACHE-KEY
Viewtype
X-Served-From
VivaBuild
X-SD-PageType
X-Check-Cacheable
X-Esi
SID
X-Viewer-Country
X-Vgn-Hpd-Reason
A
Cache-Key
X-Render-Time
X-Ua
X-HOST
NtCoent-Length
X-BBC-Edge-Cache-Status
X-Vcl-Version
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
Request-ID
M-TraceId
X-CCDN-CacheTTL
EpKe-Alive
X-UA
X-DW
X-RPM
X-RPS
X-DSS
TDXMobile
X-CF-Powered-By
X-Auto-Login
X-DB
X-DI
Server-Id
X-RAMCache
X-Worker
Cache-Provider
Arc-Country
X-RSL
Cross-Origin-Opener-Policy
Resin-Trace
X-Li-Proto
X-Air-Source
X-TIM-N
X-CSRF-TOKEN
X-Ftr-Cache-Host
Filterid
X-Dynatrace-Js-Agent
GeoIP-Latitude
ProcessTime
GeoIP-Country-Code
Upgrade-Insecure-Requests
X-Internal-Host
X-App
Srv
X-Vc
CDN
Processtime
X-Cluster-Node
X-Action
X-FTR-Cache-Host
Datacenter
X-Newrelic-Synthetics
Tcn
X-WA
X-Fpc
X-ServedByHost
X-Oss-Cdn-Auth
NGB
Proxy-Connection
X-Service
Mime-Version
CF-Cached-On
X-CLOUD-TRACE-CONTEXT
X-BBC-Origin-Response-Status
X-FORWARDED-FOR
X-Geo
X-HostName
X-HITS
OT-Force-Account-Verify
X-SaId
X-Via-NSCOPI
X-ND-Cache
X-Dw-Trace-Id
Cdn
X-Lb-Id
WZWS-RAY
X-Akamai-Pragma-Client-IP
X-JoinUs
X-BACKEND-TTL
X-Via-PopV
X-Fastly-Backend-Reqs
X-Cache-Tag
X-MSEdge-Features
X-NGENIX-Cache
FSS-Cache
X-Via-PopH
X-Via-PopN
X-MSEdge-Flight
X-Cdn-Request-ID
X-Client-Ip
X-PHP-Backend
X-Extlb
X-CACHE-AGE
X-Edge-Location
DataCenter
W
X-ABtesting
X-IN-APIGATEWAY
X-Hello
Dnion-Transfer-Encoding
X-Forwarded-Site
X-IN-APIGATEWAYSSL
X-Parent-Response-Time
PICS-Label
X-Flog
X-Provided-By
X-Pf-Uncompressing
Media-Length
Epwk-X-Cache
LB
Memcached
X-UnsetCookies
X-LiteSpeed-Tag
X-PJAX-URL
X-Region-Sid
X-Req
X-Presslabs-Stats
X-Oracle-DMS-ECID
X-RateLimit-Remaining-Second
X-VC-Cache
X-Swift-Error
Mail-Subject
X-Date
X-Bc-Bl
X-RateLimit-Limit-Second
X-Proxy-Upstream
X-Pad
X-Depends-On
We-Hiring
X-Accel-Expires-Debug
Surrogated-Key
Vha6-Origin
Time
Xet-Cookie
Memory
X-Sigma-Backend
X-Sigma
X-ZONE
X-Rocket-Build-Number
CountryCode
X-MiniProfiler-Ids
Env
URI
Cf-Ipcountry
X-Vcache
X-Akamai-ERRuleID
X-Akamai-Request-ID
X-Request-URL
X-Akamai-ERPolicy
X-ElasticPress-Query
X-Acquia-Site
X-Varnish-Beresp-TTL
X-Varnish-URL
X-Snapshot-Date
X-Amz-Meta-Cb-Modifiedtime
X-Air-Trace-Id
X-Csrf-Token
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-B3-Parentspanid
X-ElasticPress-Search
X-Ms-Meta-Staticbatchstarttime
X-Request-Url
X-Acquia-Application-Trace
X-APP
X-Ms-Meta-Originalurl
X-Men
X-Zone
Inserted-Into-Cache-At
X-Tid
X-Via-SSL
X-Storefront-Renderer-Verified
X-ServerName
Edge-Copy-Time
Environment
X-Redis-Count
Content-Style-Type
X-Traceid
X-Redis-Duration-Ms
X-C
X-Acc-Debug-Context
X-Via-Edge
Ohc-Response-Time
X-Debug-Cache-Fetch
Content-Script-Type
Phost
X-Acc-Rdl
NnCoection
X-Litespeed-Cache-Control
X-Debug-Cache-Store