Threat Level: green Handler on Duty: Jim Clausing

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
X-XSS-Protection
CF-RAY
Cf-Request-Id
CF-Cache-Status
Last-Modified
Accept-Ranges
Link
Pragma
Expect-CT
ETag
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Cache-Status
X-Generator
X-Request-ID
X-Cacheable
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-Content-Security-Policy
Content-Encoding
X-CDN
X-Envoy-Upstream-Service-Time
Status
Feature-Policy
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-AspNetMvc-Version
X-Xss-Protection
Access-Control-Max-Age
X-Via
Upgrade
Keep-Alive
X-Ws-Request-Id
X-Ua-Compatible
X-Turbo-Charged-By
X-Age
X-AH-Environment
X-Robots-Tag
Request-Context
X-Proxy-Cache
EagleId
X-Cache-Group
X-Backend
Server-Timing
X-Hacker
X-Amz-Request-Id
Report-To
X-Dns-Prefetch-Control
X-Server
X-Amz-Id-2
Host-Header
X-Server-Powered-By
X-UA-Device
X-Nginx-Cache-Status
Grace
X-LiteSpeed-Cache
X-Varnish-Cache
X-Rq
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Page-Speed
Cf-Railgun
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Amz-Version-Id
NEL
X-OneAgent-JS-Injection
Xkey
X-Cache-Spec
X-Backend-Server
Allow
X-Host
X-Vhost
EagleEye-TraceId
X-Device
X-CST
X-WebKit-CSP
X-Server-Id
Surrogate-Control
Request-Id
X-Dispatcher
X-Kinja-Server-Push
X-Node
Content-Location
X-Response-Time
X-Akam-SW-Version
Accept-CH
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Accept-CH-Lifetime
X-Ruxit-JS-Agent
X-Template
X-Language
X-Ac
X-Application-Context
X-Country
X-Readtime
X-Cloud-Trace-Context
X-Mod-Pagespeed
X-Cache-Lookup
MS-Author-Via
X-Origin-Cache
Accept-Ch
X-B3-TraceId
Rating
X-Cnection
X-MS-InvokeApp
Accept-Ch-Lifetime
X-ORACLE-DMS-ECID
X-HW
X-Url
X-TtlSet
X-Vname
X-PC
X-Clacks-Overhead
X-ESI
X-GitHub-Request-Id
Edge-Control
X-ASPNET-VERSION
X-Trace
Display
X-Middleton-Response
X-Middleton-Display
X-Sol
Pagespeed
Response
X-Content-Type
X-FastCGI-Cache
X-Buckets
X-D2id
Verso
X-Vcap-Request-Id
X-Cdn-Fetch
X-Exp-Id
X-Exp-Variant
X-Kinja-Revision
X-GoogleNews-Bot
X-Kinja
X-Kinja-Build
X-Use-Magma
Arr-Disable-Session-Affinity
X-Kinja-Server
X-Varnish-TTL
X-Goog-Hash
X-Server-Name
X-Rack-Cache
Service-Worker-Allowed
X-Country-Code
X-Oneagent-Js-Injection
X-Navigation-Version
X-VARITI-CCR
X-Abt-Application-Version
X-Amz-Rid
X-ORACLE-DMS-RID
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
X-Cache-TTL
X-TTL
X-Client-IP
X-Powered-By-Plesk
X-SharePointHealthScore
SPRequestGuid
SPRequestDuration
SPIisLatency
X-Fastly-Request-ID
X-Release
X-MSEdge-Ref
X-Dw-Request-Base-Id
X-Element-Page-Cache
Fastly-Restarts
X-NF-Request-ID
X-Cached
X-Origin-Upstream-Status
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-Webkit-CSP
Public-Key-Pins
RTSS
X-Px
AR-Request-ID
Ar-Sid
AR-CACHE
X-Edge
AR-PoweredBy
AR-ATIME
Fusion-Source
Fusion-Deployment-Id
Fusion-Template-Id
Fusion-Content-Id
Fusion-Content-Source
Fusion-Component-Id
Access-Control-Request-Method
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-LLID
X-Powered-CMS
X-Upstream
X-Pinterest-Direct
X-Ezoic-Cdn
Content-MD5
X-Jurisdiction
X-HP-Webp
X-Amz-Server-Side-Encryption
X-Mid
X-ECACHE
X-MCACHE
X-Content-Digest
Charset
X-Recruiting
S
X-Mg-S
X-Aspnetmvc-Version
X-PressLabs-Stats
Cache-Tag
MicrosoftSharePointTeamServices
X-Debug
X-Version
X-Ttl
Front-End-Https
Fastcgi-Cache
TCN
X-Grace
X-Content-Security-Policy-Report-Only
X-XRDS-Location
X-T
Filters
Cache-Tags
X-Kinsta-Cache
Server-Node
Edge-Cache-Tag
X-Id
X-Yandex-Sdch-Disable
X-Forwarded-Proto
X-Amzn-Trace-Id
X-Cache-Key
Powered-By-ChinaCache
X-Accel-Expires
Nginx-Cache
X-Correlation-Id
Surrogate-Key
X-Logged-In
X-Forwarded-For
Server-Name
X-Varnish-Age
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-DynaTrace
X-B3-Sampled
X-Hits
X-DIS-Request-ID
X-Ruxit-Js-Agent
X-Request-Handler-Origin-Region
X-Microsite
X-Server-ID
X-Ser
TP-Cache
TP-L2-Cache
X-Request-Received
X-Request-Processing-Time
X-AppVersion
X-Activity-Id
X-Shield-Request-Id
X-Amz-Replication-Status
X-Az
X-FTR-Request-ID
X-HS-Cache-Config
X-F-Cache
X-HS-Combine-CSS
X-HS-Content-Id
X-HS-Hub-Id
Accept-Charset
X-Goog-Generation
X-Git-Hash
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Origin-Server
X-Respond-Thread
Nel
X-Hostname
X-Geo-Country
X-DataDome
X-LB-Cache
Section-Io-Cache
X-Upgrade-Enabled
X-Rid
X-Frontend
X-Cache-Age
Access-Control-Allow-Method
Cleartype
X-Mobile-URL
Host
Paypal-Debug-Id
Alternate-Protocol
Healthy
X-Type
Cache
X-TEC-API-ROOT
X-IPLB-Instance
X-TEC-API-ORIGIN
X-Content-Options
ServerID
X-TEC-API-VERSION
MS-CV
X-AOL-HN
Payment
X-Varnish-Backend
X-WebKit-CSP-Report-Only
X-App-Environment
X-Whom
X-Signature
X-Providence-Cookie
X-TT
X-Debug-Info
X-Route-Name
X-Aspnet-Duration-Ms
X-Flags
X-B-Cache
X-Cache-Action
X-Request-Guid
X-Is-Crawler
X-VCache
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Page-Id
Fastcgi-Useragent
X-Seen-By
X-Jobs
X-Mobile
X-Fastcgi-Cache
X-RateLimit-Remaining
X-Source
X-XRDS-LOCATION
X-N
X-Cached-By
X-Load-Cache
X-Browser-Type
X-NWS-LOG-UUID
X-Time
X-Akamai-Edgescape
X-Via-JSL
X-Litespeed-Cache
Version
X-Webkit-Csp
X-FB-Debug
X-Cache-Rule
X-Cache-Operation
DynaTrace
Viewport
X-Accel-Buffering
X-Rule
X-Response-Served-From
X-Original-Request-Id
X-Zen-Fury
X-Proxy
X-Framework
X-Drupal-Cache-Tags
DC
Refresh
X-Daa-Tunnel
Realpath
X-Instance
X-Tt-Trace-Host
X-ProcessESI
X-RemovedCookies
X-Tt-Trace-Tag
X-Cacheable-TTL
Ms-Operation-Id
X-RTag
Access-Control-Request-Headers
X-Real-IP
Referer-Policy
X-Region
X-Cache-Time
X-UUID
X-HTML-Minification-Powered-By
X-FW-Dynamic
X-FW-Static
X-Contextid
X-FW-Type
X-Page-View
X-FW-Server
X-Yottaa-Optimizations
X-FW-Hash
X-Environment-Context
X-Drupal-Cache-Contexts
X-Distributor
X-Yottaa-Metrics
X-L-Path
X-FW-Serve
X-Node-Name
X-Cache-Expired-At
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
Eomportal-Instance
X-B
X-Wix-Request-Id
GEO-INFO
Liferay-Portal
Node
X-Cluster-Name
X-G
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
Countrycode
X-Tumblr-User
X-Cache-Control
X-Amz-Meta-S3cmd-Attrs
X-Content-Powered-By
X-User-Agent
X-IPS-LoggedIn
SRV
X-Cache-Hit
X-Tumblr-Pixel-2
Webserver
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
Section-Io-Origin-Status
Section-Io-Id
Server-Info
From-Origin
Protected
X-App-Server
X-Revision
X-Protected-By
X-Pass-Why
X-Oracle-Dms-Rid
Ec-Rule-Version
X-Ratelimit-Limit
Cache-Status
Frame-Options
X-Backend-Name
X-Cache-Server
X-Hyper-Cache
X-FireWall-Port
X-UPSTREAM-Address
X-Hl-Ver
X-Handled-By
X-RN-RSRV
Retry-After
X-Mode
X-Endurance-Cache-Level
X-ES-SERVER
Meta-Geo
X-Site-Version
X-NYM-Debug-Backend
X-Locale
X-Via-CDN
X-Adobe-Loc
X-Forwarded-Host
X-Storage
X-Adobe-Content
X-Soup
X-FB-TRIP-ID
TWC-Connection-Speed
Decoy-Debug-TTL
Property-Id
X-Human
Decoy-Debug-Key
Cache-Tv-Group
Decoy-Debug-Status
X-Be
X-Cache-Grace
Webcakes-Region
X-Format
Webcakes-App-Version
X-Web-Node
TWC-Locale-Group
X-Access
X-Varnishpool
X-Section
TWC-GeoIP-Country
Fastly-SSL
Country
TWC-GeoIP-LatLong
X-Www-Served-By
X-Pubstack
Webcakes-App-Name
TWC-Privacy
X-Origin-Hint
TWC-Device-Class
X-BYPASS-REASON
X-ApacheServer
X-FW-Version
X-Labrador-Cache-Channel
X-PCL
X-Origin-Date
Selected-Fe
Cache-Name
Azure-RegionName
Azure-InstanceId
Azure-SiteName
Azure-SlotName
Azure-Version
X-PERF
X-PHP-Host
X-Timing-Wait
X-SayCDN-TTL
X-TT-LOGID
X-UA-Device-Type
X-Uri
X-Say-TTL
X-Say-Cacheable
X-Proxy-Build
X-Proto
X-ProxyCache-Key
X-ProxyCache-Status
X-Redis-Cache
CF-IPCountry
X-OCL
X-FTR-Backend
X-Country-Code-Real
X-FTR-Backend-Server
X-FTR-Cache-Status
X-FTR-Realm
X-FTR-DC
S-Cnection
X-FTR-Balancer
X-Qloud-Router
X-No-Session
X-LAGOON
X-Server-W
X-Sql-Count
X-WA-Info
X-Via-Fastly
X-Sql-Duration-Ms
X-AIR-PT
X-S-Maxage
Mn-Server-Ip
X-TNCMS
X-Status
X-R9-Blue-Green-Version
X-LJ-Flow-ID
X-Loop
X-VWS-Id
X-FTR-Expires
X-AWS-Id
X-Hosted-By
X-Request-Time
X-Cache-TTL-Remaining
Cache-Hits
X-Cache-Var-Map
X-Cache-Var
X-Cluster
X-CCM
X-ShardId
X-Proxied
X-Alternate-Cache-Key
X-MP-GENERATED-AT
X-ShopId
X-Routing-Service
X-Dynatrace
X-Zipkin-Id
X-Shopify-Stage
X-Xfnlog-Site
X-Storefront-Renderer-Rendered
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Rendered-As
Xserver
X-Air-Hostname
X-Is-Bot
AMP-Access-Control-Allow-Source-Origin
X-Detected-As
X-Cdn
X-Amz-Apigw-Id
X-EdgeConnect-Cache-Status
X-Amzn-Remapped-Content-Length
X-Cache-Host
X-Amzn-RequestId
X-SRV
X-Info
X-Device-Type
X-Ratelimit-Remaining
Apigw-Requestid
X-B3-Traceid
X-Dc
X-Microcachable
X-Tec-Api-Origin
X-Unique-Id
X-Tec-Api-Version
X-Varnish-Ttl
X-Nginx-Cache
SD-X-WS
X-Tec-Api-Root
X-Cache-Backend
X-Time-Microsecs
X-Cache-Enabled
X-Content-Age
Tracecode
X-Backend-TTL
X-ServerID
X-Platform
X-Varnish-Server
X-Debug-IsConnected
X-Debug-IsPreview
X-GEO
Amp-Access-Control-Allow-Source-Origin
X-Azure-Ref
X-Erf-Stays-Bingo-Pdp-Web
X-Backend-Host
X-Varnish-Grace
X-DynaTrace-JS-Agent
DSUID
X-APP-VERSION
X-Tb
X-Oss-Request-Id
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
X-ID
X-GG-Cache-Date
Uber-Trace-Id
X-Sucuri-ID
X-Oss-Storage-Class
Backend
PB-PID
Arc-Version
X-Correlation-ID
PB-RID
Akamai-GRN
X-BCube-Filmed-By
X-Cache-Remote
X-Akamai-Transformed
X-ATG-Version
X-Proxy-Cache-Status
X-NewRelic-App-Data
X-Magnolia-Registration
X-Origin-Response-Time
Mobile-Detection-Method
Meta-Geo-Continent
X-External-Request-Id
X-A-Dgt
Odigeo-Trace-Id
X-Destination
Pramga
Path
X-Cache-NE
MD5-Digest
Expiry
DCR-Processing-Time-Ms
X-Device-Os
Fastcgi-X-Cache-Version
Instruction
Machine
Lfy
X-B-Cookie
Rendered-Blocks
SR-User-Adfree
X-Application
X-CF-Lambda-Fn
Thinkindot-Control
X-Aed
X-A-Dcw
X-A-Ccd
X-CF-Lambda-Version
X-A
Thinkindot-CacheControl-Type
X-Varnish-Cache-Hits
X-D
Thinkindot-CacheControl
T-Server
X-ARC
X-Trace-Id
X-Connection-Hash
X-A-Wwc
X-A-Dam
X-Thinkindot-L3
X-Vtex-Remote-Cache
X-S
X-Rojux
X-Vtex-Processado-Em
X-S-Cookie
X-ScT
Xc-Version
X-PAYTM-SRV-ID
X-Rewrite-Enabled
CACHE
X-Origin-CC
X-Origin-TTL
X-PBS-Appsvrname
X-Processor
X-Matched-Rule
X-Request-UUID
X-Level-Front-Cache
X-Location
X-Session-Fingerprint
DCR-Decision-By
X-SRCache-Key
X-VG-WebServer
X-Trv-Group
X-Generated-On
X-Generation-Time
X-Vdms-Path
X-VG-WebCache
X-Fetched-On
X-From
X-Vdms-Version
X-Adobe-Source
ServedBy
X-RCS-CacheZone
X-CSRF-Token
X-Reqid
X-Request-Start
X-Skip-Cache
X-Request-URI
Locid
Magicmarker
Wxu-Next-Hostname
Wxu-Next-Commit
L5d-Success-Class
X-SVT-ORM-RULES
X-Sn-Servicetimems
L
Ha-Gx-Prefs
Pagetype
PFcat
Gh-Request-Id
Ssr
Host-ID
Fastly-Backend-Name
X-VServer
HA-Ipaddr
X-Wikidot-Backend
X-Swa-Ws
BehaviorPad-Version
Release
X-VarnishDD-TTL
X-User
X-GeoIP
X-Cache-Info
X-Has-Esi
X-Cdn-Origin
X-Geo-Header
X-CGP
X-Generated-In
X-GeoIP-City
X-FC-Vary-Parameters
X-Developers
X-SVT-ORM-VERSION
X-Tumblr-Pixel-3
X-Csrf-Jwt
X-HN
X-Cache-Date
X-Micro-Cache
X-Eu-Site
X-Azure-Ref-OriginShield
X-Mvc-Supplant-Cachable
X-Node-Id
X-OVcl-Cache
X-OVcl
X-JWT-State
X-Is-Gdpr
X-Backend-State
X-Bip
X-Cache-Bucket
X-HS-Content-Campaign-Id
X-Thanos
X-Irp-Debug
X-Wikidot-Static-Cache
X-Owner
Wxu-Next-Region
Cache-Host
CacheControlHeader
DB-Nickname
X-Cache-NGX
AKAMAI
X-Varnish-Hostname
X-NC
Cf-Device-Type
C-Via
X-Ms-Version
X-Ms-Request-Id
X-Cache-PHP
X-Method
X-Host-Name
X-Nginx-Cache-Key
X-Debug-Cache
NGX
Apple-News-Services-Host
On-Server
X-Envoy-Decorator-Operation
Apple-News-Services-Handled
Rt-Fastcgi-Cache
X-Fastly-Backend
V-Age
X-Generated-By
X-Fastly-Cache
UCS
Sever-Int
Server-Ext
Server-Host
Server-Hostname
X-IP
Cf-Bgj
Content-Disposition
X-CUA
X-Scheme
CloudFront-Viewer-Country
Apple-News-Services-Parsed-Url
X-Var-Ttl
X-Core-Value
X-Varnish-Hits
X-Clientip
X-Cms-Context
User-Cache-Control
X-Request-Host
X-Cache-Tags
Apple-News-Services-Request-Url
X-Origin-Expires
X-Developer
CDCHOST
X-Policy
X-Varnish-Beresp-Grace
X-Cache-Debug
X-DPWN-IS-SECURE
X-Clara-WADP
X-Cache-Id
X-DefElseHash
X-Dispatcher-Server
X-DefHash
X-Esi-Check
X-Cache-Expires
X-CS
X-TX-ID
X-Variation
X-SIPLIST1
X-NWS-UUID-VERIFY
X-Rebelmouse-Surrogate-Control
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-WADP-Cache
X-TrackingId
X-VG-TLSProxy
X-Varnish-Url
X-Varnish-Remaining-TTL
X-Rebelmouse-Cache-Control
X-Ratelimit-Reset
X-Hnp-Log
X-Li-Pop
X-Gzip
X-GoCache-CacheStatus
X-Gen-Mode
X-LI-UUID
X-Loc
X-Origin
X-Platform-Server
X-Old-Content-Length
X-NU-AKA-ACS-Version
X-Branch-Name
X-Fmm-Version
X-Li-Fabric
IsBot
Fastly-SWR
Location
NM-Fastcgi-Cache
Adler-Geo
Is-Eu
X-Block-Status
True-Client-Country-4JS
Vix-Hermes-Req-Id
Web-Mar-Node
Origin
Fastly-SIE
Platform
X-B3-Spanid
X-Varnish-Beresp-Status
X-Varnish-Beresp-Ttl
X-App-Version
CDN-RequestId
CDN-Uid
CDN-CachedAt
X-Varnish-Cacheable
CDN-PullZone
X-Slack-Backend
X-Servername
CDN-RequestCountryCode
X-Gamma-Serve
X-Goog-Meta-Goog-Reserved-File-Mtime
X-NCache
S-Rt
CDN-EdgeStorageId
Fastly-Drupal-HTML
X-Hash
CDN-Cache
X-Response-By
X-PF-Uncompressing
HostName
X-NAPM-TraceId
Url
Pics-Label
X-Core-Mission
X-EC-Lua
X-Proxy-Cachei7
Xkeyi7
X-Refresh
Cross-Origin-Window-Policy
X-Aicache-OS
X-URL
N-Cache
X-Sucuri-Cache
X-CACHE-GROUP
X-Mvc-Supplant-OutputCached
X-BBXSRF
X-Cdn-Forward
X-Cache-2
Ohc-File-Size
Content-Secure-Policy
X-CDN-Forward
X-B3-SpanId
X-FireWall-Protection
X-LB-ID
D-Cc-Upstream
X-Cc-Via
X-Cache-ASPX
X-Varnish-Authentication
X-Cc-Req-Id
X-Contensis-Viewer-Groups
Cteonnt-Length
Sid
X-Via-Popn
X-Unique-ID
X-Via-Poph
X-Svr
MIME-Version
X-Via-Popv
X-RateLimit-Limit
X-DC
X-Servedbyhost
X-Wa
X-Server-IP
X-TA-CDN-Provider
X-Tb-Optimization-Total-Bytes-Saved
Esi-Enabled
X-Error
X-Srv
X-FPC
X-Origin-Time
X-Gdpr
Source
X-TIME
X-API-Version
X-Cache-Config
X-Nyt-Route
X-Epic-Correlation-Id
X-Webkit-CSP-Report-Only
HitType
Hostname
X-VC
X-SN
GeoIp-Country-Code
Geoip-Latitude
XServer
Geo-Info
Ohc-Cache-HIT
X-SB
Server-Ttl
X-Webstats-RespID
Server-ID
Req-Svc-Chain
X-NodeID
X-LI-Proto
X-TraceId
X-Cs
Who
X-Fastly-Request-Id
X-NGINX-Cache
X-VCL-Version
X-SD-PageType
X-Planisys-CDN-TTL
X-LiteSpeed-Cache-Control
X-Check-Cacheable
X-Nc
X-HS-Status
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
Country-Code
X-Ua
X-Esi
Cmstype
Svr
Kp-EeAlive
EpKe-Alive
Cmsid
X-BBC-Edge-Cache-Status
SID
X-Render-Time
X-HOST
VivaBuild
X-Vgn-Hpd-Reason
X-Ftr-Cache-Host
X-Worker
Viewtype
X-Auto-Login
Tcn
X-Viewer-Country
Request-ID
X-Dynatrace-Js-Agent
X-UA
NtCoent-Length
Cache-Provider
X-CSRF-TOKEN
X-DW
X-Vcl-Version
X-RPM
X-RPS
Resin-Trace
X-RSL
X-CACHE-KEY
X-Served-From
X-DB
A
ProcessTime
X-DI
X-DSS
Cache-Key
X-CCDN-Origin-Time
GeoIP-Country-Code
X-TIM-N
GeoIP-Latitude
X-CCDN-CacheTTL
X-Li-Proto
X-RAMCache
M-TraceId
X-Cluster-Node
X-Hcs-Proxy-Type
CDN
Upgrade-Insecure-Requests
X-Newrelic-Synthetics
X-Air-Source
Server-Id
X-CF-Powered-By
Processtime
Cross-Origin-Opener-Policy
X-Internal-Host
X-App
Arc-Country
TDXMobile
X-Action
X-FTR-Cache-Host
X-Geo
X-Fpc
Datacenter
X-Oss-Cdn-Auth
CF-Cached-On
OT-Force-Account-Verify
X-CLOUD-TRACE-CONTEXT
X-WA
X-ServedByHost
X-Vc
X-FORWARDED-FOR
X-BBC-Origin-Response-Status
WZWS-RAY
X-HostName
X-HITS
X-BACKEND-TTL
X-Pinterest-Sli-Endpoint-Name
X-MSEdge-Flight
X-Dw-Trace-Id
Cdn
Mime-Version
X-Via-PopN
X-Via-PopV
X-Via-PopH
X-Lb-Id
X-ND-Cache
X-MSEdge-Features
X-Cache-Tag
X-Pinterest-Sli-Latency-Threshold
X-Fastly-Backend-Reqs
Proxy-Connection
X-Service
X-Pinterest-Sli-Response-Type
Filterid
X-CACHE-AGE
X-Client-Ip
X-Flog
X-Hello
X-IN-APIGATEWAYSSL
X-Parent-Response-Time
Srv
X-IN-APIGATEWAY
X-ABtesting
Dnion-Transfer-Encoding
X-Pf-Uncompressing
Vha6-Origin
X-Via-NSCOPI
X-Oracle-DMS-ECID
FSS-Cache
URI
X-Presslabs-Stats
NGB
DataCenter
X-Forwarded-Site
W
X-Acc-Debug-Context
X-Acc-Rdl
CountryCode
X-Edge-Location
X-SaId
X-NGENIX-Cache
X-PHP-Backend
X-LiteSpeed-Tag
X-Cdn-Request-ID
Media-Length
X-Akamai-Pragma-Client-IP
X-Akamai-Request-ID
PICS-Label
X-JoinUs
X-MiniProfiler-Ids
X-Request-URL
X-Extlb
Cf-Ipcountry
X-RateLimit-Limit-Second
X-VC-Cache
X-UnsetCookies
X-Req
X-Region-Sid
X-RateLimit-Remaining-Second
X-PJAX-URL
Memcached
Surrogated-Key
X-Ms-Meta-Staticbatchstarttime
Mail-Subject
Epwk-X-Cache
LB
We-Hiring
X-Accel-Expires-Debug
X-Pad
X-Proxy-Upstream
X-Depends-On
X-Date
X-Bc-Bl
X-Ms-Meta-Originalurl
X-Newrelic-App-Data
X-B3-Parentspanid
X-ElasticPress-Search
X-Request-Url
Inserted-Into-Cache-At
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-Via-SSL
X-Via-Edge
X-Akamai-ERPolicy
X-Akamai-ERRuleID
Content-Style-Type
X-Traceid
X-Csrf-Token
X-Vcache
X-Acquia-Purge-Tags
X-Varnish-Beresp-TTL
X-Acquia-Site
X-Swift-Error
Content-Script-Type
X-ElasticPress-Query
X-ServerName
Edge-Copy-Time
X-ZONE
X-Provided-By
X-Tid
X-Sigma
X-Sigma-Backend
X-Zone
Akamai-Age-Ms
Env
X-APP
X-Rocket-Build-Number
Time
X-Redis-Count
Phost
X-Redis-Duration-Ms
X-Snapshot-Date
NnCoection
Xet-Cookie
Environment
X-Storefront-Renderer-Verified
Memory
X-Debug-Cache-Fetch
X-Litespeed-Cache-Control
X-C
Ohc-Response-Time
X-Debug-Cache-Store