Threat Level: green Handler on Duty: Renato Marinho

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
X-XSS-Protection
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-Served-By
X-UA-Compatible
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Xss-Protection
X-Request-ID
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Ua-Compatible
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Content-Encoding
X-CDN
X-AspNetMvc-Version
Feature-Policy
X-Envoy-Upstream-Service-Time
Status
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-Via
Upgrade
Access-Control-Max-Age
Keep-Alive
X-Ws-Request-Id
X-Age
X-Turbo-Charged-By
X-Robots-Tag
X-AH-Environment
Request-Context
X-Proxy-Cache
X-Cache-Group
EagleId
Server-Timing
X-Backend
X-Hacker
X-Server
Report-To
Host-Header
X-Amz-Request-Id
X-Server-Powered-By
X-Amz-Id-2
Grace
X-Nginx-Cache-Status
X-UA-Device
X-Rq
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Dns-Prefetch-Control
X-Page-Speed
Cf-Railgun
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-OneAgent-JS-Injection
X-Amz-Version-Id
X-Cache-Spec
NEL
X-Device
X-CST
Allow
Xkey
X-Host
X-Vhost
X-Backend-Server
X-WebKit-CSP
X-Server-Id
EagleEye-TraceId
Request-Id
Surrogate-Control
X-Dispatcher
X-Node
Content-Location
X-Response-Time
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Akam-SW-Version
X-Ruxit-JS-Agent
P3p
X-ASPNET-VERSION
Accept-CH
X-Application-Context
X-Ac
X-Cache-Lookup
X-Country
X-Template
X-Language
Accept-CH-Lifetime
Accept-Ch
X-Mod-Pagespeed
X-Readtime
Accept-Ch-Lifetime
X-Cloud-Trace-Context
MS-Author-Via
X-B3-TraceId
Rating
X-Origin-Cache
X-MS-InvokeApp
X-Cnection
X-HW
X-Url
X-PC
X-TtlSet
X-Vname
X-Clacks-Overhead
Edge-Control
X-GitHub-Request-Id
X-ESI
X-ORACLE-DMS-ECID
X-Trace
X-Middleton-Display
X-Content-Type
Display
Pagespeed
Response
X-Middleton-Response
X-Sol
X-D2id
X-ORACLE-DMS-RID
X-Use-Magma
X-GoogleNews-Bot
X-Exp-Id
X-Exp-Variant
X-Kinja
X-Cdn-Fetch
X-Kinja-Server
X-Kinja-Revision
X-Kinja-Build
Arr-Disable-Session-Affinity
Verso
X-Vcap-Request-Id
X-Goog-Hash
X-Rack-Cache
X-Country-Code
X-Buckets
X-FastCGI-Cache
X-Varnish-TTL
X-Server-Name
X-Navigation-Version
Service-Worker-Allowed
X-Powered-By-Plesk
X-VARITI-CCR
X-Amz-Rid
X-Abt-Application-Version
X-Fastly-Request-ID
X-Webkit-CSP
X-TTL
X-Client-IP
X-Cache-TTL
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
Fastly-Restarts
X-Release
X-SharePointHealthScore
SPRequestGuid
X-Cached
X-Dw-Request-Base-Id
X-MSEdge-Ref
X-Element-Page-Cache
SPIisLatency
X-Oneagent-Js-Injection
SPRequestDuration
X-NF-Request-ID
Public-Key-Pins
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
RTSS
Access-Control-Request-Method
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Ar-Sid
AR-Request-ID
AR-CACHE
AR-ATIME
AR-PoweredBy
X-Edge
X-LLID
X-Powered-CMS
X-Ezoic-Cdn
X-Litespeed-Cache
X-Origin-Upstream-Status
Cache-Tag
Content-MD5
X-Upstream
X-Px
Fusion-Content-Source
Fusion-Template-Id
Fusion-Content-Id
Fusion-Deployment-Id
Fusion-Source
Fusion-Component-Id
X-Jurisdiction
X-HP-Webp
S
X-Mid
X-ECACHE
X-Version
X-MCACHE
X-Recruiting
X-Mg-S
Charset
X-Content-Digest
X-PressLabs-Stats
X-Ttl
X-Amz-Server-Side-Encryption
Fastcgi-Cache
X-Kinsta-Cache
X-T
Cache-Tags
MicrosoftSharePointTeamServices
X-Id
Filters
Front-End-Https
X-DynaTrace
X-Content-Security-Policy-Report-Only
X-Debug
X-Logged-In
Edge-Cache-Tag
Server-Node
X-Accel-Expires
X-Grace
X-Forwarded-Proto
X-Correlation-Id
X-Forwarded-For
TCN
Server-Name
Nginx-Cache
TP-L2-Cache
TP-Cache
X-Pinterest-Direct
X-Amzn-Trace-Id
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Surrogate-Key
X-Request-Received
X-XRDS-LOCATION
X-Request-Processing-Time
X-Yandex-Sdch-Disable
X-Varnish-Age
X-B3-Sampled
X-Shield-Request-Id
X-Ser
X-Request-Handler-Origin-Region
X-Microsite
X-Hits
X-Activity-Id
X-AppVersion
X-Az
X-Ruxit-Js-Agent
X-Amz-Replication-Status
X-F-Cache
X-HS-Cache-Config
X-HS-Hub-Id
X-Fastcgi-Cache
X-HS-Combine-CSS
X-HS-Content-Id
X-DIS-Request-ID
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Origin-Server
Accept-Charset
X-Geo-Country
X-Git-Hash
Alternate-Protocol
X-XRDS-Location
X-Respond-Thread
Cache
Nel
X-Rid
X-FTR-Request-ID
X-Time
X-Frontend
Section-Io-Cache
X-LB-Cache
X-Upgrade-Enabled
Host
X-Cache-Key
X-DataDome
Powered-By-ChinaCache
Access-Control-Allow-Method
X-Seen-By
X-Mobile-URL
X-NWS-LOG-UUID
X-Server-ID
MS-CV
X-Cache-Age
X-VCache
Paypal-Debug-Id
X-TT
Healthy
X-IPLB-Instance
X-AOL-HN
X-Whom
X-Content-Options
ServerID
Cleartype
X-Type
X-Hostname
X-Request-Guid
Payment
X-Route-Name
X-Is-Crawler
X-Flags
X-Varnish-Backend
X-Providence-Cookie
X-Aspnet-Duration-Ms
X-App-Environment
X-Cache-Action
X-B-Cache
X-Signature
X-Source
X-Jobs
X-Page-Id
X-Debug-Info
Fastcgi-Useragent
X-WebKit-CSP-Report-Only
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Load-Cache
X-TEC-API-ORIGIN
X-Daa-Tunnel
X-N
X-Mobile
X-FB-Debug
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Erf-Bev-Bev
X-Via-JSL
X-RateLimit-Remaining
Realpath
X-Contextid
Refresh
Version
X-Akamai-Edgescape
Node
X-Response-Served-From
X-Original-Request-Id
X-Accel-Buffering
X-Rule
X-Wix-Request-Id
X-Drupal-Cache-Tags
X-Cached-By
X-RTag
X-Framework
Ms-Operation-Id
X-Proxy
X-Zen-Fury
DC
X-ProcessESI
X-RemovedCookies
Viewport
X-Cache-Operation
X-Cacheable-TTL
X-Cache-Rule
X-Real-IP
X-HTML-Minification-Powered-By
X-Distributor
X-Cache-Time
X-B
Referer-Policy
X-Instance
Eomportal-Instance
X-UUID
X-Drupal-Cache-Contexts
X-Page-View
X-Region
Access-Control-Request-Headers
X-Tt-Trace-Tag
X-Cluster-Name
X-Cache-Expired-At
X-Tt-Trace-Host
VIX-Pulpo-Upstream-Status
X-Cache-Control
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-FW-Server
X-FW-Static
Liferay-Portal
X-FW-Hash
X-FW-Serve
Countrycode
X-FW-Dynamic
VIX-Pulpo-Node
X-FW-Type
X-Content-Powered-By
X-G
X-IPS-LoggedIn
X-Cache-Hit
X-L-Path
X-Tumblr-Pixel
X-Tumblr-User
X-Environment-Context
DynaTrace
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-FireWall-Port
X-Pass-Why
Server-Info
X-App-Server
X-Varnish-Ttl
X-User-Agent
X-Ratelimit-Limit
GEO-INFO
Ec-Rule-Version
Xserver
X-Protected-By
Section-Io-Id
Section-Io-Origin-Status
X-Tumblr-Pixel-2
From-Origin
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
Webserver
CF-IPCountry
X-Node-Name
X-Ratelimit-Remaining
SRV
X-Www-Served-By
Protected
X-Cache-Server
X-Nginx-Cache
X-Mode
Meta-Geo
X-Backend-Name
X-Endurance-Cache-Level
X-Hl-Ver
X-RN-RSRV
X-ES-SERVER
X-UPSTREAM-Address
X-Debug-IsPreview
X-Debug-IsConnected
X-FB-TRIP-ID
X-Uri
Frame-Options
X-Site-Version
X-Locale
X-Handled-By
X-UA-Device-Type
Cache-Tv-Group
X-Device-Type
X-NYM-Debug-Backend
X-Soup
Cache-Status
X-Web-Node
X-Be
X-MP-GENERATED-AT
X-Adobe-Loc
X-Varnishpool
X-Adobe-Content
X-PCL
X-Origin-Hint
X-Origin-Date
Selected-Fe
TWC-Privacy
Webcakes-App-Name
X-PHP-Host
TWC-Locale-Group
Decoy-Debug-Status
X-ProxyCache-Status
X-No-Session
TWC-Device-Class
X-Sql-Duration-Ms
X-Sql-Count
TWC-Connection-Speed
X-Storage
TWC-GeoIP-Country
X-OCL
Decoy-Debug-TTL
Decoy-Debug-Key
TWC-GeoIP-LatLong
X-BYPASS-REASON
X-Human
X-Request-Time
X-Labrador-Cache-Channel
X-WA-Info
Cache-Name
X-ProxyCache-Key
X-Via-Fastly
Property-Id
X-Hyper-Cache
X-Proto
X-Proxy-Build
Webcakes-App-Version
X-Timing-Wait
Country
X-Redis-Cache
X-Pubstack
Fastly-SSL
Webcakes-Region
Azure-SlotName
Azure-RegionName
Azure-Version
Retry-After
Azure-SiteName
X-AIR-PT
X-TNCMS
X-Hosted-By
X-Section
X-LAGOON
X-Server-W
X-Loop
X-LJ-Flow-ID
Azure-InstanceId
X-FW-Version
X-Forwarded-Host
X-Access
X-Say-Cacheable
X-S-Maxage
X-Cache-Grace
X-Say-TTL
X-Format
X-SayCDN-TTL
X-VWS-Id
X-R9-Blue-Green-Version
X-AWS-Id
X-Revision
X-Cache-TTL-Remaining
X-PERF
X-Status
X-Alternate-Cache-Key
X-Storefront-Renderer-Rendered
X-Sorting-Hat-ShopId
X-Xfnlog-Site
X-Shopify-Stage
X-ShardId
X-ApacheServer
X-ShopId
X-Cluster
X-TT-LOGID
X-CCM
X-Sorting-Hat-PodId
Mn-Server-Ip
X-Webkit-Csp
X-Routing-Service
X-Proxied
X-Zipkin-Id
X-Is-Bot
X-Varnish-Grace
X-Rendered-As
Apigw-Requestid
X-Qloud-Router
X-SRV
X-Amz-Meta-S3cmd-Attrs
AMP-Access-Control-Allow-Source-Origin
X-Dc
X-Varnish-Server
X-Info
S-Cnection
X-FTR-Cache-Status
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Backend
X-FTR-Balancer
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
X-FTR-Realm
X-Via-CDN
X-FTR-DC
X-Cdn
Cache-Hits
X-GG-Cache-Date
X-Cache-Enabled
X-Microcachable
X-Content-Age
X-Detected-As
X-Cache-Host
X-FTR-Expires
X-Platform
X-Proxy-Cache-Status
Uber-Trace-Id
X-Aspnetmvc-Version
X-Azure-Ref
X-EdgeConnect-Cache-Status
X-Amzn-Remapped-Content-Length
X-Amzn-RequestId
X-Amz-Apigw-Id
X-CSRF-Token
X-Backend-Host
Tracecode
X-NWS-UUID-VERIFY
X-Air-Hostname
X-App-Version
X-Cache-Var
SD-X-WS
X-Cache-Var-Map
Akamai-GRN
Amp-Access-Control-Allow-Source-Origin
X-ATG-Version
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-DynaTrace-JS-Agent
X-Oss-Request-Id
X-Oss-Storage-Class
X-Oss-Server-Time
X-Backend-TTL
X-Time-Microsecs
X-ServerID
HostName
X-Tb
X-Unique-Id
X-Trace-Id
X-BCube-Filmed-By
X-Correlation-ID
X-Debug-Cache
X-RCS-CacheZone
ServedBy
X-Cache-NGX
X-Varnish-Hostname
X-GEO
X-Cdn-Forward
Backend
X-Sucuri-ID
X-B3-SpanId
DSUID
X-Cache-Backend
X-Akamai-Transformed
X-Cache-PHP
X-Fetched-On
X-Origin-TTL
X-Processor
X-Magnolia-Registration
X-Owner
X-PAYTM-SRV-ID
X-PBS-Appsvrname
X-From
Path
X-NAPM-TraceId
X-Level-Front-Cache
Expiry
Fastcgi-X-Cache-Version
X-Location
DCR-Processing-Time-Ms
DCR-Decision-By
BehaviorPad-Version
DB-Nickname
X-GeoIP-City
X-TX-ID
X-Generation-Time
X-Generated-On
MD5-Digest
Meta-Geo-Continent
X-Origin-CC
Mobile-Detection-Method
X-CF-Lambda-Fn
Machine
X-Vtex-Remote-Cache
X-Ms-Version
X-Ms-Request-Id
Instruction
Odigeo-Trace-Id
X-VG-WebServer
X-A-Dam
X-Session-Fingerprint
X-A-Dcw
X-A-Dgt
X-A-Wwc
X-CS
X-A-Ccd
X-ScT
X-Vdms-Path
X-Device-Os
X-A
X-Aed
X-SRCache-Key
X-Connection-Hash
X-D
Xc-Version
X-Cache-NE
X-CF-Lambda-Version
X-Trv-Group
X-B-Cookie
X-Destination
X-Application
X-ARC
X-Thinkindot-L3
Thinkindot-Control
X-TA-CDN-Provider
SR-User-Adfree
X-Vtex-Processado-Em
T-Server
X-Request-UUID
X-Vdms-Version
X-External-Request-Id
Rendered-Blocks
Release
X-VG-WebCache
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-S
X-Rewrite-Enabled
X-S-Cookie
X-Rojux
X-CACHE-KEY
X-Fastly-Cache
X-Bip
X-Core-Value
Arc-Version
X-GeoIP
X-Cache-Bucket
Content-Disposition
X-Has-Esi
X-FC-Vary-Parameters
X-Cms-Context
Cf-Device-Type
CacheControlHeader
X-Geo-Header
Lfy
Host-ID
On-Server
UCS
NGX
X-Adobe-Source
Pagetype
X-Azure-Ref-OriginShield
PB-PID
Fastly-Backend-Name
Server-Host
Gh-Request-Id
PB-RID
X-Is-Gdpr
X-Mvc-Supplant-Cachable
X-SVT-ORM-VERSION
X-OVcl
X-VServer
X-B3-Traceid
X-Micro-Cache
X-Varnish-Cache-Hits
X-Tumblr-Pixel-3
X-HS-Content-Campaign-Id
X-OVcl-Cache
X-JWT-State
X-SVT-ORM-RULES
X-Matched-Rule
X-NewRelic-App-Data
X-Thanos
AKAMAI
X-TrackingId
X-Reqid
X-Node-Id
X-Irp-Debug
User-Cache-Control
X-VarnishDD-TTL
Wxu-Next-Commit
Web-Mar-Node
X-Developers
V-Age
X-Dispatcher-Server
X-Request-Host
Server-Ext
X-Eu-Site
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
Server-Hostname
X-Esi-Check
X-Scheme
Ssr
X-Envoy-Decorator-Operation
Sever-Int
X-DPWN-IS-SECURE
X-Varnish-CookieHashed-On
X-Clientip
X-Clara-WADP
X-Var-Ttl
X-EC-Lua
X-Branch-Name
X-Variation
X-Cache-Id
X-CGP
X-Cache-Tags
X-Varnish-Beresp-Grace
X-Cache-Info
X-Block-Status
X-User
X-Skip-Cache
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
X-Developer
Wxu-Next-Region
X-DefHash
X-Swa-Ws
X-Csrf-Jwt
X-CUA
X-Backend-State
X-DefElseHash
Wxu-Next-Hostname
X-Ratelimit-Reset
X-IP
X-Li-Fabric
X-GoCache-CacheStatus
CloudFront-Viewer-Country
Adler-Geo
X-Li-Pop
X-LI-UUID
HA-Ipaddr
X-Fastly-Backend
Ha-Gx-Prefs
Fastly-SWR
Fastly-SIE
X-Gzip
CDN-Uid
Cache-Host
CDCHOST
C-Via
X-Hnp-Log
X-HN
CDN-Cache
CDN-CachedAt
CDN-RequestId
CDN-RequestCountryCode
CDN-PullZone
CDN-EdgeStorageId
Is-Eu
X-Nginx-Cache-Key
NM-Fastcgi-Cache
X-Origin-Response-Time
X-Origin-Expires
X-Generated-In
X-Gen-Mode
X-Fmm-Version
X-Wikidot-Backend
X-WADP-Cache
Platform
PFcat
X-Policy
X-Platform-Server
X-Origin
X-Wikidot-Static-Cache
Location
Locid
L5d-Success-Class
Magicmarker
X-Old-Content-Length
X-Generated-By
X-NU-AKA-ACS-Version
X-APP-VERSION
X-ID
X-SIPLIST1
X-Varnish-Hits
X-Hash
X-Varnish-Beresp-Status
X-VG-TLSProxy
X-Request-URI
X-LB-ID
X-Method
X-Varnish-Beresp-Ttl
X-Sn-Servicetimems
X-Slack-Backend
X-Gamma-Serve
X-Cache-Expires
Rt-Fastcgi-Cache
IsBot
Cf-Bgj
Vix-Hermes-Req-Id
True-Client-Country-4JS
L
X-Kinja-Server-Push
Pramga
X-Cache-Debug
X-Cdn-Origin
X-CLOUD-TRACE-CONTEXT
X-Aicache-OS
Apple-News-Services-Handled
Apple-News-Services-Parsed-Url
Fastly-Drupal-HTML
Apple-News-Services-Host
X-Loc
Apple-News-Services-Request-Url
Origin
X-Cache-Date
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Nc
Sid
X-Mvc-Supplant-OutputCached
X-Via-Popn
Esi-Enabled
X-Via-Poph
X-Unique-ID
X-PF-Uncompressing
X-Servername
X-NCache
X-Via-Popv
X-Core-Mission
X-Erf-Stays-Bingo-Pdp-Web
Who
X-Varnish-Url
X-Request-Start
X-Refresh
Country-Code
Geo-Info
Pics-Label
Url
X-Tb-Optimization-Total-Bytes-Saved
X-Epic-Correlation-Id
X-FireWall-Protection
X-NC
X-Cache-Remote
X-Varnish-Cacheable
X-Planisys-CDN-TTL
X-Response-By
X-Dynatrace
Req-Svc-Chain
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-TraceId
X-Error
Xkeyi7
X-Proxy-Cachei7
Tcn
X-RateLimit-Limit
S-Rt
Cmstype
N-Cache
X-BBXSRF
Cmsid
Content-Secure-Policy
Source
X-B3-Spanid
X-Webkit-CSP-Report-Only
Filterid
GeoIp-Country-Code
X-HS-Status
X-Host-Name
X-DC
HitType
X-Cache-2
X-Srv
Server-Ttl
Geoip-Latitude
Kp-EeAlive
Svr
X-Sucuri-Cache
Cross-Origin-Window-Policy
X-Served-From
X-Vcl-Version
Cache-Key
A
X-Contensis-Viewer-Groups
Ohc-File-Size
X-Cache-ASPX
X-Varnish-Authentication
Cteonnt-Length
Viewtype
D-Cc-Upstream
X-Cc-Via
X-Cc-Req-Id
MIME-Version
VivaBuild
X-LiteSpeed-Cache-Control
X-URL
X-Servedbyhost
M-TraceId
X-Wa
X-Svr
X-HostName
X-Oracle-Dms-Rid
Cross-Origin-Opener-Policy
X-Server-IP
NGB
TDXMobile
Server-ID
X-Li-Proto
X-Esi
X-Air-Source
Arc-Country
X-CDN-Forward
CACHE
NtCoent-Length
X-Cache-Config
X-Vgn-Hpd-Reason
X-LI-Proto
X-Gdpr
X-FPC
X-RAMCache
X-Origin-Time
X-API-Version
X-Nyt-Route
X-HOST
X-Cs
Resin-Trace
X-VC
SID
Request-ID
X-Vc
X-WA
X-ServedByHost
X-SN
X-Check-Cacheable
X-UA
X-Geo
X-NodeID
X-Webstats-RespID
X-Newrelic-Synthetics
X-Viewer-Country
Cache-Provider
X-Internal-Host
X-Service
X-RSL
X-RPS
X-CCDN-CacheTTL
X-CCDN-Origin-Time
Server-Id
X-TIM-N
X-Hcs-Proxy-Type
X-RPM
X-DW
X-DSS
X-DI
X-DB
X-VCL-Version
X-SB
X-JoinUs
X-NGENIX-Cache
X-PHP-Backend
X-SaId
DataCenter
Hostname
Ohc-Cache-HIT
Srv
X-Edge-Location
Mime-Version
GeoIP-Country-Code
GeoIP-Latitude
X-SD-PageType
XServer
X-NGINX-Cache
X-Via-NSCOPI
X-Action
X-App
X-BBC-Edge-Cache-Status
ProcessTime
X-Render-Time
X-Extlb
X-Forwarded-Site
FSS-Cache
X-FTR-Cache-Host
CF-Cached-On
X-Fpc
EpKe-Alive
X-CF-Powered-By
X-Oss-Cdn-Auth
X-Ua
X-Provided-By
X-Dynatrace-Js-Agent
X-Bc-Bl
X-Req
Mail-Subject
Upgrade-Insecure-Requests
X-Worker
W
Processtime
X-VC-Cache
X-FORWARDED-FOR
Surrogated-Key
LB
Memcached
X-Date
X-Accel-Expires-Debug
X-Depends-On
X-PJAX-URL
X-Auto-Login
X-Region-Sid
X-Proxy-Upstream
We-Hiring
X-Cdn-Request-ID
X-HITS
X-Swift-Error
CDN
X-APP
X-Fastly-Backend-Reqs
X-BACKEND-TTL
X-TIME
Env
Proxy-Connection
Cdn
X-MSEdge-Features
X-Cluster-Node
X-ZONE
X-CSRF-TOKEN
X-UnsetCookies
X-Dw-Trace-Id
X-Ftr-Cache-Host
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-MSEdge-Flight
X-CACHE-AGE
X-Client-Ip
X-Men
X-ABtesting
Datacenter
X-Air-Trace-Id
X-Sigma
Dnion-Transfer-Encoding
Time
X-BBC-Origin-Response-Status
X-Cache-Tag
X-Rocket-Build-Number
PICS-Label
Memory
X-Sigma-Backend
X-Flog
X-IN-APIGATEWAYSSL
X-Hello
X-Fastly-Request-Id
X-Parent-Response-Time
X-IN-APIGATEWAY
X-Akamai-Pragma-Client-IP
X-Acquia-Purge-Tags
Media-Length
X-Acquia-Application-UUID
X-Acquia-Application-Trace
Vha6-Origin
VNS-Cache
VNS-Age
X-Oracle-DMS-ECID
CPC-Age
X-Acquia-Site
CPC-Cache
X-Pad
X-Pf-Uncompressing
X-Zone
X-Presslabs-Stats
OT-Force-Account-Verify
X-LiteSpeed-Tag
X-Via-PopH
Epwk-X-Cache
X-Via-PopN
X-Via-PopV
Cf-Ipcountry
X-ElasticPress-Search
X-Akamai-ERPolicy
X-Csrf-Token
X-Request-Url
X-ServerName
X-ND-Cache
X-Vcache
X-Akamai-ERRuleID
X-MiniProfiler-Ids
X-Ms-Meta-Originalurl
Xet-Cookie
X-ElasticPress-Query
X-Lb-Id
WZWS-RAY
X-Ms-Meta-Staticbatchstarttime
X-Request-URL
X-Snapshot-Date
X-Varnish-Beresp-TTL
X-Varnish-URL
CountryCode
My-App
State
Content-Style-Type
X-Litespeed-Cache-Control
Content-Script-Type
X-Amz-Meta-Cb-Modifiedtime
Fastcgi-Cache-TTL
X-Debug-Cache-Fetch
Ohc-Response-Time
URI
X-Traceid
Phost
X-B3-Parentspanid
NnCoection
X-Redis-Duration-Ms
X-Redis-Count
X-C
Inserted-Into-Cache-At
X-Debug-Cache-Store
X-Storefront-Renderer-Verified
Environment
X-Tid