Threat Level: green Handler on Duty: Jim Clausing

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
X-XSS-Protection
Cf-Request-Id
CF-RAY
CF-Cache-Status
Last-Modified
Accept-Ranges
Link
Pragma
Expect-CT
ETag
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Cache-Status
X-Generator
X-Request-ID
X-Cacheable
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-Content-Security-Policy
Content-Encoding
X-CDN
X-Envoy-Upstream-Service-Time
Status
Feature-Policy
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-AspNetMvc-Version
X-Xss-Protection
Access-Control-Max-Age
X-Via
Upgrade
Keep-Alive
X-Ws-Request-Id
X-Ua-Compatible
X-Turbo-Charged-By
X-Age
X-AH-Environment
X-Robots-Tag
Request-Context
X-Proxy-Cache
EagleId
X-Cache-Group
Server-Timing
X-Backend
X-Hacker
X-Amz-Request-Id
Report-To
X-Dns-Prefetch-Control
X-Server
Host-Header
X-Amz-Id-2
X-Server-Powered-By
X-UA-Device
X-Nginx-Cache-Status
Grace
X-LiteSpeed-Cache
X-Varnish-Cache
X-Rq
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Page-Speed
Cf-Railgun
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Amz-Version-Id
NEL
Xkey
X-OneAgent-JS-Injection
X-WebKit-CSP
X-Backend-Server
X-Cache-Spec
Allow
X-Host
X-Vhost
EagleEye-TraceId
X-CST
X-Device
X-Server-Id
Surrogate-Control
Request-Id
X-Dispatcher
X-Kinja-Server-Push
X-Node
Content-Location
X-Response-Time
X-Akam-SW-Version
Accept-CH
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Accept-CH-Lifetime
X-Ruxit-JS-Agent
X-Template
X-Language
X-Ac
X-Application-Context
X-Country
X-Readtime
X-Mod-Pagespeed
X-Cloud-Trace-Context
X-Cache-Lookup
MS-Author-Via
X-Origin-Cache
Accept-Ch
X-B3-TraceId
X-Cnection
Rating
X-MS-InvokeApp
Accept-Ch-Lifetime
X-ORACLE-DMS-ECID
X-HW
X-Url
X-PC
X-TtlSet
X-Vname
X-Clacks-Overhead
X-ESI
Edge-Control
X-GitHub-Request-Id
X-ASPNET-VERSION
X-Oneagent-Js-Injection
Pagespeed
Display
Response
X-Middleton-Response
X-Middleton-Display
X-Sol
X-Trace
X-Content-Type
X-FastCGI-Cache
X-Buckets
X-D2id
Verso
X-Vcap-Request-Id
X-Exp-Variant
X-Exp-Id
X-Kinja-Build
X-Cdn-Fetch
X-Kinja
X-Use-Magma
X-Kinja-Server
X-GoogleNews-Bot
X-Kinja-Revision
Arr-Disable-Session-Affinity
X-Varnish-TTL
X-Goog-Hash
X-Server-Name
X-Rack-Cache
Service-Worker-Allowed
X-Country-Code
X-Navigation-Version
X-VARITI-CCR
X-Amz-Rid
X-Abt-Application-Version
X-ORACLE-DMS-RID
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
X-Cache-TTL
X-Client-IP
X-TTL
X-Powered-By-Plesk
X-SharePointHealthScore
SPRequestGuid
SPIisLatency
SPRequestDuration
X-Fastly-Request-ID
X-Release
X-Dw-Request-Base-Id
X-MSEdge-Ref
X-Element-Page-Cache
Fastly-Restarts
X-NF-Request-ID
X-Cached
X-Origin-Upstream-Status
X-Webkit-CSP
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
Public-Key-Pins
RTSS
X-Px
AR-Request-ID
Ar-Sid
AR-CACHE
X-Edge
AR-ATIME
AR-PoweredBy
Fusion-Component-Id
Fusion-Source
Fusion-Template-Id
Fusion-Content-Id
Fusion-Deployment-Id
Fusion-Content-Source
X-SRCache-Fetch-Status
Access-Control-Request-Method
X-SRCache-Store-Status
X-LLID
X-Powered-CMS
X-Upstream
X-Pinterest-Direct
X-Ezoic-Cdn
Content-MD5
X-Jurisdiction
X-HP-Webp
X-Amz-Server-Side-Encryption
Charset
X-Mid
X-MCACHE
X-ECACHE
X-Content-Digest
X-Recruiting
S
X-Aspnetmvc-Version
X-Mg-S
X-PressLabs-Stats
Cache-Tag
MicrosoftSharePointTeamServices
X-Debug
X-Version
X-Ttl
Front-End-Https
Fastcgi-Cache
TCN
X-Grace
X-Content-Security-Policy-Report-Only
X-XRDS-Location
X-T
Filters
Cache-Tags
X-Kinsta-Cache
Server-Node
Edge-Cache-Tag
X-Yandex-Sdch-Disable
X-Id
X-Forwarded-Proto
X-Amzn-Trace-Id
X-Cache-Key
Powered-By-ChinaCache
Nginx-Cache
Surrogate-Key
X-Correlation-Id
X-Accel-Expires
X-Logged-In
Server-Name
X-Forwarded-For
X-Varnish-Age
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-DynaTrace
X-Ruxit-Js-Agent
X-B3-Sampled
X-Hits
X-Microsite
X-Ser
X-DIS-Request-ID
X-Server-ID
X-Request-Handler-Origin-Region
X-Request-Processing-Time
X-Request-Received
TP-L2-Cache
TP-Cache
X-Amz-Replication-Status
X-Az
X-Activity-Id
X-AppVersion
X-Shield-Request-Id
X-FTR-Request-ID
X-F-Cache
X-HS-Combine-CSS
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Content-Id
Accept-Charset
X-Git-Hash
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Origin-Server
X-Respond-Thread
X-Hostname
Nel
X-DataDome
X-LB-Cache
X-Geo-Country
Section-Io-Cache
X-Upgrade-Enabled
X-Frontend
X-Rid
X-Cache-Age
X-Mobile-URL
Cleartype
Host
Paypal-Debug-Id
Alternate-Protocol
Cache
X-Type
Access-Control-Allow-Method
Healthy
X-IPLB-Instance
X-TEC-API-VERSION
X-Content-Options
X-TEC-API-ROOT
ServerID
MS-CV
X-TEC-API-ORIGIN
X-AOL-HN
Payment
X-WebKit-CSP-Report-Only
X-App-Environment
X-Whom
X-B-Cache
X-Request-Guid
X-Route-Name
X-Signature
X-TT
X-Providence-Cookie
X-Is-Crawler
X-Cache-Action
X-Debug-Info
X-Flags
X-Varnish-Backend
X-Aspnet-Duration-Ms
X-VCache
X-Erf-Bev-Bev-Is-Generated
Fastcgi-Useragent
X-Seen-By
X-Page-Id
X-Erf-Bev-Bev
X-Jobs
X-Mobile
X-Fastcgi-Cache
X-Source
X-RateLimit-Remaining
X-N
X-XRDS-LOCATION
X-Cached-By
X-NWS-LOG-UUID
X-Browser-Type
X-Load-Cache
X-Akamai-Edgescape
X-Time
X-Via-JSL
X-Litespeed-Cache
Version
X-FB-Debug
X-Cache-Rule
X-Cache-Operation
DynaTrace
Viewport
X-Accel-Buffering
X-Response-Served-From
X-Original-Request-Id
X-Rule
X-Zen-Fury
DC
X-Framework
X-Daa-Tunnel
Refresh
X-Proxy
X-Tt-Trace-Tag
X-RemovedCookies
X-Instance
X-Drupal-Cache-Tags
Realpath
X-ProcessESI
X-Tt-Trace-Host
X-RTag
X-Real-IP
Ms-Operation-Id
Referer-Policy
X-Cacheable-TTL
Access-Control-Request-Headers
X-HTML-Minification-Powered-By
X-Region
X-UUID
X-Node-Name
X-Contextid
X-Cache-Time
X-Yottaa-Metrics
X-Distributor
X-L-Path
X-FW-Static
X-FW-Serve
X-FW-Hash
X-Environment-Context
X-Page-View
X-Yottaa-Optimizations
X-FW-Dynamic
X-FW-Server
X-FW-Type
VIX-Pulpo-Node
X-Drupal-Cache-Contexts
X-Cache-Expired-At
VIX-Pulpo-Upstream-Status
Eomportal-Instance
X-Wix-Request-Id
X-B
Liferay-Portal
GEO-INFO
X-Cluster-Name
Node
Countrycode
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-1
X-G
X-Cache-Control
X-Content-Powered-By
X-Amz-Meta-S3cmd-Attrs
X-User-Agent
X-IPS-LoggedIn
SRV
X-Cache-Hit
X-Tumblr-Pixel-2
Webserver
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
Server-Info
Section-Io-Id
Protected
From-Origin
X-Revision
X-App-Server
X-Protected-By
X-Pass-Why
X-Oracle-Dms-Rid
Ec-Rule-Version
X-Ratelimit-Limit
X-Cache-Server
X-Backend-Name
Frame-Options
Cache-Status
X-Hyper-Cache
X-ES-SERVER
X-Endurance-Cache-Level
X-Hl-Ver
X-UPSTREAM-Address
X-RN-RSRV
X-FireWall-Port
X-Mode
Meta-Geo
Retry-After
X-Via-CDN
X-NYM-Debug-Backend
X-FB-TRIP-ID
X-Adobe-Content
X-Forwarded-Host
X-Adobe-Loc
X-Handled-By
X-Locale
X-Site-Version
TWC-Locale-Group
X-Varnishpool
Decoy-Debug-TTL
Decoy-Debug-Status
Decoy-Debug-Key
Country
Fastly-SSL
X-Origin-Hint
X-Human
X-Section
X-Soup
X-Storage
X-Pubstack
X-Www-Served-By
CF-IPCountry
X-Access
X-Be
Webcakes-Region
Webcakes-App-Version
Webcakes-App-Name
X-Cache-Grace
TWC-Device-Class
X-Format
Property-Id
TWC-Privacy
TWC-Connection-Speed
TWC-GeoIP-LatLong
TWC-GeoIP-Country
X-PERF
X-PCL
X-Origin-Date
X-OCL
X-Proto
X-Proxy-Build
Azure-InstanceId
X-ProxyCache-Status
X-ProxyCache-Key
X-FW-Version
X-BYPASS-REASON
Azure-SlotName
Azure-SiteName
Azure-RegionName
Azure-Version
Cache-Name
X-ApacheServer
Selected-Fe
Cache-Tv-Group
X-Say-Cacheable
X-Redis-Cache
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-Backend
S-Cnection
X-Uri
X-FTR-Cache-Status
X-FTR-Realm
X-Web-Node
X-FTR-DC
X-TT-LOGID
X-UA-Device-Type
X-SayCDN-TTL
X-Country-Code-Real
X-Say-TTL
X-Timing-Wait
X-WA-Info
X-Qloud-Router
X-S-Maxage
X-Via-Fastly
X-AIR-PT
X-LAGOON
X-Sql-Duration-Ms
X-Labrador-Cache-Channel
X-PHP-Host
X-Sql-Count
X-Server-W
X-No-Session
X-AWS-Id
X-Hosted-By
X-LJ-Flow-ID
X-Loop
Mn-Server-Ip
X-R9-Blue-Green-Version
X-TNCMS
X-Status
X-FTR-Expires
X-VWS-Id
X-Cache-TTL-Remaining
X-Cache-Var-Map
X-Cluster
Cache-Hits
X-Request-Time
X-Cache-Var
X-CCM
X-Dynatrace
X-Proxied
X-ShardId
X-Storefront-Renderer-Rendered
X-Xfnlog-Site
X-Zipkin-Id
X-MP-GENERATED-AT
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Routing-Service
X-ShopId
X-Shopify-Stage
X-Alternate-Cache-Key
X-Rendered-As
Xserver
X-Is-Bot
X-Air-Hostname
AMP-Access-Control-Allow-Source-Origin
X-Detected-As
X-Webkit-Csp
X-Amzn-RequestId
X-Amzn-Remapped-Content-Length
X-Cache-Host
X-EdgeConnect-Cache-Status
X-Cdn
X-Amz-Apigw-Id
X-SRV
X-Info
X-Ratelimit-Remaining
X-Device-Type
Apigw-Requestid
X-Dc
X-B3-Traceid
X-Microcachable
X-Tec-Api-Origin
X-Nginx-Cache
X-Varnish-Ttl
X-Unique-Id
SD-X-WS
X-Tec-Api-Root
X-Tec-Api-Version
X-Cache-Backend
X-Cache-Enabled
X-Content-Age
Tracecode
X-Backend-TTL
X-ServerID
X-Time-Microsecs
X-Platform
X-Debug-IsConnected
X-Debug-IsPreview
X-Varnish-Server
X-GEO
X-Azure-Ref
X-Erf-Stays-Bingo-Pdp-Web
Amp-Access-Control-Allow-Source-Origin
X-Backend-Host
X-DynaTrace-JS-Agent
X-Varnish-Grace
X-APP-VERSION
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
X-Sucuri-ID
DSUID
X-Tb
X-Oss-Storage-Class
X-ID
X-GG-Cache-Date
X-Oss-Server-Time
X-Oss-Object-Type
Backend
PB-PID
Arc-Version
Uber-Trace-Id
PB-RID
X-Correlation-ID
Akamai-GRN
X-Cache-Remote
X-Magnolia-Registration
X-Akamai-Transformed
X-Origin-Response-Time
X-NewRelic-App-Data
X-A-Wwc
X-Proxy-Cache-Status
X-Connection-Hash
Rendered-Blocks
X-Application
X-Aed
X-D
X-Destination
X-A-Dcw
X-A-Dam
X-A-Dgt
X-Trace-Id
SR-User-Adfree
Pramga
X-Varnish-Cache-Hits
X-ARC
X-A-Ccd
X-B-Cookie
X-ATG-Version
X-Cache-NE
X-Rojux
Thinkindot-Control
Thinkindot-CacheControl-Type
X-CF-Lambda-Fn
X-Request-UUID
X-S
X-Rewrite-Enabled
X-Origin-CC
X-CF-Lambda-Version
Thinkindot-CacheControl
T-Server
Odigeo-Trace-Id
X-VG-WebServer
X-VG-WebCache
X-Vdms-Version
Machine
Expiry
Meta-Geo-Continent
MD5-Digest
X-SRCache-Key
X-Matched-Rule
Fastcgi-X-Cache-Version
Instruction
X-PBS-Appsvrname
X-Generated-On
X-From
X-Generation-Time
X-Vdms-Path
X-Trv-Group
X-Fetched-On
X-PAYTM-SRV-ID
Mobile-Detection-Method
DCR-Decision-By
CACHE
X-A
X-Device-Os
Path
X-Location
X-Thinkindot-L3
Xc-Version
X-Session-Fingerprint
X-Processor
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
X-External-Request-Id
X-Origin-TTL
X-S-Cookie
X-ScT
X-Level-Front-Cache
DCR-Processing-Time-Ms
X-Adobe-Source
X-CSRF-Token
X-BCube-Filmed-By
X-RCS-CacheZone
ServedBy
Magicmarker
Fastly-Backend-Name
Ssr
PFcat
Pagetype
Gh-Request-Id
Wxu-Next-Commit
Lfy
L5d-Success-Class
Wxu-Next-Region
Host-ID
Locid
Ha-Gx-Prefs
HA-Ipaddr
L
X-Mvc-Supplant-Cachable
Cf-Device-Type
X-Generated-In
X-Tumblr-Pixel-3
X-VarnishDD-TTL
X-Is-Gdpr
X-Sn-Servicetimems
X-FC-Vary-Parameters
X-VServer
X-Owner
X-Geo-Header
X-OVcl
X-Swa-Ws
X-Irp-Debug
X-OVcl-Cache
X-HS-Content-Campaign-Id
X-GeoIP
X-Has-Esi
X-HN
X-JWT-State
X-Wikidot-Backend
X-CGP
X-Node-Id
X-Request-URI
X-Cdn-Origin
X-Cache-Info
X-Backend-State
X-Bip
X-Cache-Bucket
X-GeoIP-City
X-Thanos
X-Request-Start
X-Reqid
X-Eu-Site
X-Wikidot-Static-Cache
BehaviorPad-Version
X-Csrf-Jwt
X-Micro-Cache
X-Developers
X-Azure-Ref-OriginShield
Wxu-Next-Hostname
Cache-Host
DB-Nickname
X-Cache-PHP
X-Varnish-Hostname
AKAMAI
CacheControlHeader
X-NC
X-Cache-NGX
X-Ms-Version
X-Ms-Request-Id
Rt-Fastcgi-Cache
Server-Host
X-Fastly-Backend
Cf-Bgj
Release
X-Fastly-Cache
On-Server
X-Envoy-Decorator-Operation
X-CUA
X-Developer
X-Skip-Cache
X-Cache-Date
X-Host-Name
X-SVT-ORM-VERSION
X-Varnish-Hits
X-Var-Ttl
X-User
V-Age
X-SVT-ORM-RULES
X-Clientip
X-Cms-Context
X-Debug-Cache
User-Cache-Control
X-Cache-Tags
X-Core-Value
X-Scheme
X-IP
X-Policy
X-Request-Host
X-Nginx-Cache-Key
X-Origin-Expires
X-Method
CDCHOST
Content-Disposition
C-Via
Apple-News-Services-Request-Url
Apple-News-Services-Handled
Apple-News-Services-Host
UCS
CloudFront-Viewer-Country
Apple-News-Services-Parsed-Url
X-Generated-By
X-Varnish-Beresp-Grace
X-Cache-Id
X-Li-Fabric
X-Cache-Expires
X-Li-Pop
X-LI-UUID
X-Branch-Name
X-NU-AKA-ACS-Version
X-Old-Content-Length
X-Block-Status
X-NWS-UUID-VERIFY
X-Loc
X-Origin
X-Cache-Debug
X-SIPLIST1
X-Dispatcher-Server
X-Rebelmouse-Surrogate-Control
X-DefHash
X-DPWN-IS-SECURE
X-Esi-Check
X-Fmm-Version
X-Variation
X-DefElseHash
X-Rebelmouse-Cache-Control
X-Hnp-Log
X-Clara-WADP
X-CS
X-Gen-Mode
X-Ratelimit-Reset
X-GoCache-CacheStatus
X-Gzip
X-Platform-Server
X-TX-ID
Sever-Int
Server-Hostname
Server-Ext
IsBot
Fastly-SIE
X-VG-TLSProxy
True-Client-Country-4JS
X-WADP-Cache
Platform
Is-Eu
Adler-Geo
Location
NGX
NM-Fastcgi-Cache
X-TrackingId
Origin
Vix-Hermes-Req-Id
Fastly-SWR
X-Varnish-Url
X-Varnish-Remaining-TTL
Web-Mar-Node
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Status
X-B3-Spanid
X-App-Version
X-Slack-Backend
X-Varnish-Cacheable
X-Servername
CDN-RequestId
X-Hash
X-Goog-Meta-Goog-Reserved-File-Mtime
X-NCache
CDN-Uid
X-Response-By
X-Gamma-Serve
CDN-EdgeStorageId
S-Rt
CDN-Cache
CDN-PullZone
CDN-CachedAt
Fastly-Drupal-HTML
CDN-RequestCountryCode
X-PF-Uncompressing
HostName
Xkeyi7
Url
Pics-Label
X-Proxy-Cachei7
X-Refresh
X-NAPM-TraceId
X-Core-Mission
X-EC-Lua
Cross-Origin-Window-Policy
N-Cache
X-URL
X-CACHE-GROUP
X-Aicache-OS
X-BBXSRF
X-Sucuri-Cache
X-Mvc-Supplant-OutputCached
X-Cdn-Forward
X-Cache-2
X-CDN-Forward
Ohc-File-Size
X-B3-SpanId
Content-Secure-Policy
X-Cc-Via
X-Varnish-Authentication
X-FireWall-Protection
X-Cache-ASPX
Cteonnt-Length
D-Cc-Upstream
X-Cc-Req-Id
X-Contensis-Viewer-Groups
X-LB-ID
X-Unique-ID
X-Via-Popn
X-Via-Poph
X-Svr
Sid
X-Via-Popv
MIME-Version
X-RateLimit-Limit
X-Servedbyhost
X-Error
Esi-Enabled
X-Server-IP
X-TA-CDN-Provider
X-Wa
X-Tb-Optimization-Total-Bytes-Saved
X-DC
X-Srv
X-Nyt-Route
X-TIME
X-Epic-Correlation-Id
X-Origin-Time
Source
X-Cache-Config
X-Gdpr
X-API-Version
X-FPC
X-Webkit-CSP-Report-Only
HitType
XServer
Hostname
GeoIp-Country-Code
X-VC
Geoip-Latitude
Geo-Info
X-SN
Ohc-Cache-HIT
X-TraceId
X-Webstats-RespID
X-Cs
Server-ID
X-SB
X-NodeID
Server-Ttl
X-LI-Proto
Req-Svc-Chain
X-Fastly-Request-Id
Who
X-NGINX-Cache
X-Planisys-CDN-Rules
X-SD-PageType
X-Check-Cacheable
X-HS-Status
X-Planisys-CDN-TTL
X-LiteSpeed-Cache-Control
X-VCL-Version
X-Planisys-CDN-Cache
Country-Code
X-Nc
X-Ua
X-Esi
X-BBC-Edge-Cache-Status
Cmstype
Kp-EeAlive
EpKe-Alive
SID
Svr
Cmsid
X-Render-Time
X-HOST
X-Auto-Login
X-Ftr-Cache-Host
X-Served-From
Request-ID
Viewtype
X-Viewer-Country
X-Worker
VivaBuild
X-Vgn-Hpd-Reason
NtCoent-Length
X-UA
X-Dynatrace-Js-Agent
ProcessTime
Cache-Provider
X-Vcl-Version
X-DB
Resin-Trace
X-DSS
Tcn
Cache-Key
X-RSL
X-CACHE-KEY
A
X-CSRF-TOKEN
X-RPM
X-RPS
X-DW
X-DI
X-Li-Proto
M-TraceId
GeoIP-Latitude
X-CCDN-CacheTTL
GeoIP-Country-Code
X-Hcs-Proxy-Type
CDN
X-TIM-N
X-RAMCache
X-CCDN-Origin-Time
X-Cluster-Node
Upgrade-Insecure-Requests
X-Newrelic-Synthetics
TDXMobile
Cross-Origin-Opener-Policy
X-CF-Powered-By
Arc-Country
X-Action
X-Internal-Host
Server-Id
Processtime
X-Air-Source
X-App
X-Geo
X-FTR-Cache-Host
X-Fpc
Datacenter
X-Oss-Cdn-Auth
X-CLOUD-TRACE-CONTEXT
OT-Force-Account-Verify
CF-Cached-On
X-WA
X-FORWARDED-FOR
X-ServedByHost
X-BBC-Origin-Response-Status
X-Vc
WZWS-RAY
X-HostName
X-HITS
X-Service
Cdn
X-MSEdge-Flight
X-Dw-Trace-Id
X-ND-Cache
X-Via-PopH
X-Via-PopN
X-Via-PopV
X-Pinterest-Sli-Latency-Threshold
X-Pinterest-Sli-Endpoint-Name
X-BACKEND-TTL
X-Cache-Tag
X-Lb-Id
X-Pinterest-Sli-Response-Type
X-Fastly-Backend-Reqs
Mime-Version
X-MSEdge-Features
Proxy-Connection
X-CACHE-AGE
Filterid
X-Client-Ip
Srv
Dnion-Transfer-Encoding
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-Parent-Response-Time
X-Via-NSCOPI
DataCenter
URI
X-Oracle-DMS-ECID
X-Flog
X-Pf-Uncompressing
X-Presslabs-Stats
NGB
Vha6-Origin
X-ABtesting
FSS-Cache
W
X-Hello
X-Forwarded-Site
X-Acc-Rdl
X-Acc-Debug-Context
CountryCode
X-Edge-Location
X-Akamai-Request-ID
X-Akamai-Pragma-Client-IP
Media-Length
X-JoinUs
X-MiniProfiler-Ids
X-PHP-Backend
PICS-Label
X-SaId
X-LiteSpeed-Tag
X-Cdn-Request-ID
X-NGENIX-Cache
X-Request-URL
Cf-Ipcountry
X-Extlb
X-UnsetCookies
LB
X-Region-Sid
X-PJAX-URL
Memcached
X-Req
Mail-Subject
Epwk-X-Cache
Surrogated-Key
X-Date
We-Hiring
X-Ms-Meta-Staticbatchstarttime
X-VC-Cache
X-Proxy-Upstream
X-Accel-Expires-Debug
X-RateLimit-Limit-Second
X-Pad
X-Depends-On
X-RateLimit-Remaining-Second
X-Bc-Bl
X-Ms-Meta-Originalurl
X-Akamai-ERRuleID
Inserted-Into-Cache-At
X-B3-Parentspanid
X-Request-Url
Edge-Copy-Time
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-ElasticPress-Search
X-Via-SSL
X-Akamai-ERPolicy
X-Vcache
X-Traceid
X-Csrf-Token
X-Via-Edge
X-Newrelic-App-Data
X-Acquia-Purge-Tags
X-Swift-Error
X-Acquia-Site
Content-Script-Type
X-Varnish-Beresp-TTL
X-ServerName
Content-Style-Type
X-ElasticPress-Query
X-ZONE
X-Provided-By
X-Sigma-Backend
X-Tid
Env
Akamai-Age-Ms
X-Zone
X-APP
X-Rocket-Build-Number
X-Sigma
Time
X-Redis-Count
Phost
X-Redis-Duration-Ms
X-Snapshot-Date
NnCoection
Xet-Cookie
Environment
X-Storefront-Renderer-Verified
Memory
X-Debug-Cache-Fetch
X-Litespeed-Cache-Control
X-C
Ohc-Response-Time
X-Debug-Cache-Store