Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
X-XSS-Protection
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-UA-Compatible
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Xss-Protection
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Request-ID
X-Cacheable
X-Ua-Compatible
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Content-Encoding
X-CDN
X-AspNetMvc-Version
Feature-Policy
Status
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Upgrade
X-Via
Access-Control-Max-Age
Keep-Alive
X-Ws-Request-Id
X-Age
X-Robots-Tag
X-AH-Environment
X-Turbo-Charged-By
Request-Context
EagleId
X-Proxy-Cache
X-Cache-Group
Server-Timing
X-Backend
X-Hacker
X-Server
Host-Header
Report-To
X-Amz-Request-Id
X-Server-Powered-By
X-Amz-Id-2
Grace
X-Nginx-Cache-Status
X-UA-Device
X-Dns-Prefetch-Control
X-Rq
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Page-Speed
X-LiteSpeed-Cache
Cf-Railgun
X-Pingback
X-OneAgent-JS-Injection
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Spec
X-Amz-Version-Id
NEL
X-Device
X-CST
Allow
X-Vhost
X-Host
Xkey
X-Backend-Server
X-Server-Id
X-WebKit-CSP
EagleEye-TraceId
X-Dispatcher
Surrogate-Control
Request-Id
X-Node
Content-Location
X-Response-Time
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Akam-SW-Version
X-Ruxit-JS-Agent
Accept-Ch
P3p
X-ASPNET-VERSION
X-Ac
X-Application-Context
X-Cache-Lookup
X-Country
Accept-Ch-Lifetime
X-Template
X-Language
X-Mod-Pagespeed
X-Readtime
Accept-CH
MS-Author-Via
X-B3-TraceId
X-Cloud-Trace-Context
Accept-CH-Lifetime
Rating
X-HW
X-Origin-Cache
X-MS-InvokeApp
X-Cnection
X-Url
X-TtlSet
X-Vname
X-PC
X-Clacks-Overhead
Edge-Control
X-GitHub-Request-Id
X-ESI
X-Trace
X-ORACLE-DMS-ECID
X-Sol
Display
X-Middleton-Response
X-Middleton-Display
Pagespeed
Response
X-Content-Type
X-ORACLE-DMS-RID
X-D2id
X-Exp-Variant
X-Cdn-Fetch
Arr-Disable-Session-Affinity
X-GoogleNews-Bot
X-Kinja-Build
X-Use-Magma
X-Kinja-Server
X-Kinja-Revision
X-Kinja
X-Exp-Id
Verso
X-Vcap-Request-Id
X-Varnish-TTL
X-Rack-Cache
X-Goog-Hash
X-TTL
X-Country-Code
X-Navigation-Version
X-Powered-By-Plesk
X-Buckets
X-Server-Name
Service-Worker-Allowed
X-Amz-Rid
X-VARITI-CCR
X-Abt-Application-Version
X-Fastly-Request-ID
X-Client-IP
X-FastCGI-Cache
Fastly-Restarts
X-Webkit-CSP
X-Cache-TTL
X-Cached
X-Release
Pinterest-Version
X-Pinterest-Rid
X-MSEdge-Ref
Pinterest-Generated-By
X-Dw-Request-Base-Id
X-Element-Page-Cache
X-SharePointHealthScore
SPRequestGuid
X-Litespeed-Cache
X-NF-Request-ID
SPIisLatency
SPRequestDuration
X-Oneagent-Js-Injection
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
Public-Key-Pins
RTSS
Access-Control-Request-Method
AR-ATIME
AR-Request-ID
AR-CACHE
AR-PoweredBy
Ar-Sid
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Edge
X-LLID
X-Powered-CMS
Cache-Tag
X-Ezoic-Cdn
X-Upstream
Content-MD5
X-Origin-Upstream-Status
X-HP-Webp
X-Jurisdiction
Fusion-Source
Fusion-Template-Id
Fusion-Deployment-Id
Fusion-Content-Source
Fusion-Content-Id
Fusion-Component-Id
S
X-Version
X-Px
X-ECACHE
X-MCACHE
X-Mid
X-Recruiting
X-Mg-S
Charset
X-Content-Digest
X-PressLabs-Stats
X-Kinsta-Cache
X-T
Fastcgi-Cache
X-Amz-Server-Side-Encryption
Cache-Tags
X-Id
X-DynaTrace
Filters
MicrosoftSharePointTeamServices
X-Logged-In
X-Fastcgi-Cache
X-Content-Security-Policy-Report-Only
Front-End-Https
X-Accel-Expires
Server-Node
Edge-Cache-Tag
X-Forwarded-Proto
X-Correlation-Id
X-Forwarded-For
TP-Cache
TP-L2-Cache
X-Ruxit-Js-Agent
X-Debug
X-Grace
X-Ttl
Server-Name
Nginx-Cache
X-XRDS-LOCATION
X-Amzn-Trace-Id
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Request-Processing-Time
X-Request-Received
Surrogate-Key
X-Hits
X-Shield-Request-Id
X-B3-Sampled
X-Varnish-Age
X-Request-Handler-Origin-Region
X-Microsite
TCN
X-Yandex-Sdch-Disable
X-Activity-Id
X-Az
X-AppVersion
X-Ser
X-Amz-Replication-Status
X-F-Cache
X-Pinterest-Direct
X-HS-Cache-Config
X-HS-Combine-CSS
X-HS-Content-Id
X-HS-Hub-Id
X-DIS-Request-ID
X-Origin-Server
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
Alternate-Protocol
Accept-Charset
X-Geo-Country
X-Rid
X-Git-Hash
X-Respond-Thread
X-Time
X-Frontend
X-XRDS-Location
Section-Io-Cache
Host
X-LB-Cache
Nel
Cache
X-FTR-Request-ID
X-DataDome
X-NWS-LOG-UUID
X-Upgrade-Enabled
Access-Control-Allow-Method
X-Seen-By
X-Mobile-URL
X-Cache-Key
X-VCache
MS-CV
ServerID
X-Cache-Age
Paypal-Debug-Id
X-IPLB-Instance
Healthy
X-TT
X-AOL-HN
X-Varnish-Backend
X-Type
X-Content-Options
X-Whom
Payment
X-Is-Crawler
X-Request-Guid
X-Source
X-Route-Name
X-Providence-Cookie
X-Flags
X-App-Environment
Cleartype
X-Aspnet-Duration-Ms
X-B-Cache
X-Server-ID
X-Signature
X-Page-Id
Fastcgi-Useragent
X-Cache-Action
X-Hostname
X-WebKit-CSP-Report-Only
X-Jobs
X-Debug-Info
X-Daa-Tunnel
X-N
X-Load-Cache
Powered-By-ChinaCache
X-FB-Debug
X-Mobile
X-Erf-Bev-Bev-Is-Generated
Realpath
X-Erf-Bev-Bev
X-Browser-Type
X-Contextid
X-RateLimit-Remaining
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Webkit-Csp
X-TEC-API-ORIGIN
X-Via-JSL
Node
Refresh
X-Rule
X-Response-Served-From
X-Drupal-Cache-Tags
Version
X-Original-Request-Id
X-Accel-Buffering
X-Wix-Request-Id
X-Zen-Fury
X-Framework
X-Cacheable-TTL
DC
X-RTag
Ms-Operation-Id
X-Proxy
X-Cached-By
X-ProcessESI
X-RemovedCookies
X-Akamai-Edgescape
X-Cache-Expired-At
X-HTML-Minification-Powered-By
X-Instance
X-Real-IP
X-Distributor
Viewport
X-B
X-Cache-Time
Eomportal-Instance
Referer-Policy
Access-Control-Request-Headers
X-Page-View
X-Region
X-Drupal-Cache-Contexts
X-UUID
X-Content-Powered-By
X-Cache-Control
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Cache-Rule
X-Cluster-Name
X-Cache-Operation
X-FW-Static
X-FW-Server
X-FW-Type
VIX-Pulpo-Node
X-FW-Serve
VIX-Pulpo-Upstream-Status
X-FW-Hash
X-FW-Dynamic
Countrycode
X-Cache-Hit
X-IPS-LoggedIn
Liferay-Portal
X-G
X-FireWall-Port
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel-1
X-Pass-Why
X-Environment-Context
X-L-Path
X-App-Server
Server-Info
DynaTrace
Xserver
CF-IPCountry
X-Protected-By
SRV
Section-Origin-Responded
X-User-Agent
Section-Io-Origin-Status
Section-Io-Id
Section-Io-Origin-Time-Seconds
Webserver
Ec-Rule-Version
X-Tumblr-Pixel-2
X-Ratelimit-Limit
From-Origin
X-Www-Served-By
X-Nginx-Cache
X-Debug-IsConnected
X-Debug-IsPreview
X-Device-Type
Protected
GEO-INFO
X-RN-RSRV
X-Adobe-Loc
X-Adobe-Content
X-ES-SERVER
Meta-Geo
X-Handled-By
X-Hl-Ver
X-Ratelimit-Remaining
X-Node-Name
X-Endurance-Cache-Level
X-Mode
X-UPSTREAM-Address
X-Cache-Server
X-Tec-Api-Root
X-Backend-Name
X-MP-GENERATED-AT
X-Locale
X-FB-TRIP-ID
X-Tec-Api-Origin
X-Site-Version
X-Uri
X-Tec-Api-Version
Cache-Tv-Group
X-Web-Node
Frame-Options
X-Be
X-Labrador-Cache-Channel
X-PHP-Host
X-UA-Device-Type
Cache-Status
X-NYM-Debug-Backend
X-Varnishpool
Retry-After
X-Storage
Decoy-Debug-Status
Decoy-Debug-Key
X-OCL
TWC-Device-Class
TWC-GeoIP-Country
TWC-Connection-Speed
Property-Id
X-WA-Info
TWC-GeoIP-LatLong
TWC-Locale-Group
Webcakes-Region
X-Origin-Hint
Webcakes-App-Version
Webcakes-App-Name
TWC-Privacy
X-Via-Fastly
X-Timing-Wait
X-Origin-Date
X-PCL
X-No-Session
Selected-Fe
Fastly-SSL
X-Proto
X-Proxy-Build
X-Sql-Count
X-Sql-Duration-Ms
X-Soup
X-Redis-Cache
X-Pubstack
Decoy-Debug-TTL
Cache-Name
X-Varnish-Grace
X-Hyper-Cache
X-Say-TTL
X-FW-Version
X-Say-Cacheable
X-Request-Time
X-Server-W
X-Section
Country
X-R9-Blue-Green-Version
X-Hosted-By
X-LJ-Flow-ID
X-Human
X-SayCDN-TTL
X-AIR-PT
X-VWS-Id
X-BYPASS-REASON
X-Loop
X-Format
X-AWS-Id
AMP-Access-Control-Allow-Source-Origin
X-ProxyCache-Key
X-TNCMS
X-Access
X-ProxyCache-Status
X-LAGOON
X-ShardId
Azure-Version
X-CCM
X-Alternate-Cache-Key
X-Cache-TTL-Remaining
Azure-SlotName
X-Storefront-Renderer-Rendered
X-S-Maxage
Azure-InstanceId
X-ApacheServer
X-Status
X-Sorting-Hat-ShopId
X-Varnish-Ttl
X-Xfnlog-Site
X-Shopify-Stage
X-PERF
X-ShopId
Azure-RegionName
X-Sorting-Hat-PodId
Azure-SiteName
X-Forwarded-Host
Mn-Server-Ip
X-Cache-Grace
X-SRV
X-Zipkin-Id
Apigw-Requestid
X-Routing-Service
X-TT-LOGID
X-Cluster
X-Proxied
X-Varnish-Server
X-Dc
X-Is-Bot
X-Rendered-As
X-Revision
S-Cnection
X-Qloud-Router
X-Info
X-Cache-Enabled
X-Microcachable
X-GG-Cache-Date
X-Content-Age
X-Proxy-Cache-Status
Uber-Trace-Id
X-App-Version
X-Country-Code-Real
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-Realm
X-Platform
X-Amz-Meta-S3cmd-Attrs
X-FTR-DC
X-FTR-Backend
X-Cdn
X-Via-CDN
Cache-Hits
X-Azure-Ref
X-Cache-Host
X-TA-CDN-Provider
X-Detected-As
X-Backend-Host
X-CSRF-Token
X-NWS-UUID-VERIFY
X-FTR-Expires
X-Amzn-Remapped-Content-Length
X-Amz-Apigw-Id
X-Amzn-RequestId
X-EdgeConnect-Cache-Status
X-Aspnetmvc-Version
Akamai-GRN
X-ATG-Version
X-Air-Hostname
X-CLOUD-TRACE-CONTEXT
SD-X-WS
X-Oss-Storage-Class
Tracecode
X-Oss-Server-Time
X-Oss-Request-Id
HostName
X-Oss-Hash-Crc64ecma
X-Time-Microsecs
X-Oss-Object-Type
Amp-Access-Control-Allow-Source-Origin
X-B3-SpanId
X-Debug-Cache
ServedBy
X-Trace-Id
X-RCS-CacheZone
X-Backend-TTL
X-CS
X-ServerID
X-Cache-NGX
X-Cache-PHP
X-Akamai-Transformed
X-BCube-Filmed-By
X-Varnish-Hostname
X-Cache-Var-Map
X-Cache-Var
X-DynaTrace-JS-Agent
X-CACHE-KEY
X-Tb
X-TX-ID
Backend
DB-Nickname
X-Cdn-Forward
X-Correlation-ID
BehaviorPad-Version
X-A
Release
Path
X-D
X-ARC
Odigeo-Trace-Id
X-A-Dgt
X-A-Dcw
X-A-Ccd
X-A-Wwc
X-Aed
X-B-Cookie
Rendered-Blocks
X-Application
Mobile-Detection-Method
X-Adobe-Source
Thinkindot-CacheControl
DCR-Decision-By
DCR-Processing-Time-Ms
Expiry
SR-User-Adfree
X-Ms-Version
X-Connection-Hash
X-Magnolia-Registration
T-Server
X-CF-Lambda-Version
X-A-Dam
Machine
X-Cache-NE
X-Ms-Request-Id
MD5-Digest
X-CF-Lambda-Fn
Instruction
Thinkindot-CacheControl-Type
Thinkindot-Control
Fastcgi-X-Cache-Version
Meta-Geo-Continent
X-Processor
X-Request-UUID
X-Destination
X-Rewrite-Enabled
X-Rojux
X-S
X-PAYTM-SRV-ID
X-EC-Lua
X-NAPM-TraceId
X-Origin-CC
X-Origin-TTL
X-Owner
X-S-Cookie
X-ScT
X-VG-WebServer
X-VG-WebCache
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-Vdms-Version
X-Vdms-Path
X-Session-Fingerprint
X-SRCache-Key
X-Thinkindot-L3
X-Trv-Group
X-Location
X-PBS-Appsvrname
X-Fetched-On
X-Generated-On
X-Sucuri-ID
DSUID
X-From
X-External-Request-Id
X-Level-Front-Cache
X-Generation-Time
X-Device-Os
X-GeoIP-City
Arc-Version
AKAMAI
X-TrackingId
X-SVT-ORM-VERSION
X-Thanos
NGX
X-Tumblr-Pixel-3
X-FC-Vary-Parameters
Fastly-Backend-Name
X-VServer
X-Core-Value
Cf-Device-Type
Gh-Request-Id
Host-ID
On-Server
X-Cms-Context
CacheControlHeader
X-Fastly-Cache
C-Via
PB-RID
UCS
X-OVcl-Cache
X-Irp-Debug
X-HS-Content-Campaign-Id
X-Has-Esi
X-OVcl
X-Is-Gdpr
X-Micro-Cache
X-Mvc-Supplant-Cachable
X-Node-Id
X-JWT-State
X-Azure-Ref-OriginShield
Content-Disposition
X-Cache-Bucket
X-Unique-Id
PB-PID
X-SVT-ORM-RULES
X-Skip-Cache
Server-Host
X-Reqid
X-Bip
X-GeoIP
X-Geo-Header
Pagetype
X-GEO
User-Cache-Control
X-Nc
X-Developer
X-NewRelic-App-Data
X-Dispatcher-Server
X-DefHash
X-DefElseHash
X-CUA
Tcn
X-DPWN-IS-SECURE
X-Envoy-Decorator-Operation
X-Fmm-Version
X-Cache-Backend
X-Gen-Mode
X-Fastly-Backend
Server-Ext
X-Esi-Check
X-Eu-Site
X-Csrf-Jwt
Sever-Int
X-Branch-Name
X-Cache-Id
X-Cache-Info
X-Block-Status
X-Nginx-Cache-Key
X-Backend-State
X-Policy
X-Developers
X-Cache-Tags
Wxu-Next-Hostname
Wxu-Next-Commit
Wxu-Next-Region
X-Clientip
X-CGP
X-Clara-WADP
X-Generated-By
X-Generated-In
X-Platform-Server
X-Ratelimit-Reset
X-Rebelmouse-Cache-Control
X-Origin-Response-Time
X-Origin-Expires
X-Old-Content-Length
X-Origin
X-Rebelmouse-Surrogate-Control
X-Request-Host
X-Varnish-CookieHashed-On
X-Varnish-Beresp-Grace
X-Variation
X-Varnish-CookieINHashed-On
X-Scheme
X-VarnishDD-TTL
X-Varnish-Remaining-TTL
X-NU-AKA-ACS-Version
X-Unique-ID
Locid
X-HN
X-Hnp-Log
X-Gzip
X-GoCache-CacheStatus
X-User
Magicmarker
X-IP
X-Wikidot-Static-Cache
X-LI-UUID
X-B3-Traceid
X-Li-Pop
X-Li-Fabric
X-Wikidot-Backend
X-WADP-Cache
X-Var-Ttl
Server-Hostname
Web-Mar-Node
L5d-Success-Class
Ha-Gx-Prefs
CDN-EdgeStorageId
V-Age
CDN-Uid
Fastly-SWR
NM-Fastcgi-Cache
CDN-RequestId
CDN-RequestCountryCode
Adler-Geo
CDN-PullZone
CDN-CachedAt
CDN-Cache
CDCHOST
Location
PFcat
HA-Ipaddr
X-Varnish-Cache-Hits
Platform
Fastly-SIE
Is-Eu
X-Varnish-Beresp-Ttl
Rt-Fastcgi-Cache
X-Gamma-Serve
Lfy
Ssr
X-Matched-Rule
X-VG-TLSProxy
X-LB-ID
True-Client-Country-4JS
X-Varnish-Beresp-Status
Sid
X-Swa-Ws
X-Method
X-Hash
Cache-Host
X-Request-URI
X-SIPLIST1
Cf-Bgj
Geo-Info
IsBot
X-Cache-Debug
Vix-Hermes-Req-Id
X-Slack-Backend
X-ID
Apple-News-Services-Handled
Apple-News-Services-Parsed-Url
X-Varnish-Hits
Apple-News-Services-Request-Url
Esi-Enabled
Who
CloudFront-Viewer-Country
L
X-Aicache-OS
Apple-News-Services-Host
Country-Code
X-Via-Popv
X-Goog-Meta-Goog-Reserved-File-Mtime
X-NCache
Origin
X-Loc
X-Via-Poph
X-Mvc-Supplant-OutputCached
X-Cdn-Origin
X-Sn-Servicetimems
Pramga
X-Cache-Expires
Fastly-Drupal-HTML
X-PF-Uncompressing
X-Via-Popn
X-APP-VERSION
X-Varnish-Url
Pics-Label
X-Cache-Date
X-Servername
X-Core-Mission
Filterid
X-Refresh
X-Tb-Optimization-Total-Bytes-Saved
X-Epic-Correlation-Id
X-Request-Start
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-TraceId
X-RateLimit-Limit
Url
X-FireWall-Protection
X-Erf-Stays-Bingo-Pdp-Web
Req-Svc-Chain
Cmsid
Cmstype
Svr
Source
X-Served-From
X-Error
X-Response-By
X-Varnish-Cacheable
X-NC
X-Cache-Remote
Kp-EeAlive
VivaBuild
Viewtype
X-Proxy-Cachei7
A
GeoIp-Country-Code
Geoip-Latitude
Xkeyi7
Cache-Key
NGB
S-Rt
X-HostName
X-Webkit-CSP-Report-Only
X-Vcl-Version
N-Cache
X-HS-Status
Content-Secure-Policy
X-DC
M-TraceId
Server-Ttl
MIME-Version
X-Srv
X-BBXSRF
HitType
Arc-Country
X-B3-Spanid
X-Air-Source
X-Cache-2
TDXMobile
Cross-Origin-Opener-Policy
X-URL
Server-ID
X-Cache-ASPX
X-Vgn-Hpd-Reason
X-Cc-Req-Id
X-Varnish-Authentication
X-Servedbyhost
X-Cc-Via
D-Cc-Upstream
Cross-Origin-Window-Policy
X-Li-Proto
Ohc-File-Size
Cteonnt-Length
X-Host-Name
X-LiteSpeed-Cache-Control
X-Dynatrace
X-Wa
X-Sucuri-Cache
X-Contensis-Viewer-Groups
X-Geo
Resin-Trace
X-Esi
X-Vc
X-Svr
NtCoent-Length
X-CDN-Forward
CACHE
DataCenter
X-JoinUs
X-NGENIX-Cache
X-PHP-Backend
X-SaId
X-WA
X-Internal-Host
X-Edge-Location
X-RAMCache
X-LI-Proto
X-Service
X-Server-IP
X-ServedByHost
X-HOST
X-Nyt-Route
X-Viewer-Country
X-FPC
X-Origin-Time
X-Gdpr
Request-ID
X-Cache-Config
X-API-Version
SID
X-UA
CF-Cached-On
X-SN
Cache-Provider
X-RSL
X-Newrelic-Synthetics
X-TIM-N
X-Check-Cacheable
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
FSS-Cache
X-Via-NSCOPI
X-RPS
X-Extlb
X-VC
X-VCL-Version
X-DI
X-DB
X-DSS
X-RPM
X-DW
X-Cs
X-Forwarded-Site
X-Bc-Bl
Hostname
Ohc-Cache-HIT
X-Webstats-RespID
GeoIP-Country-Code
X-SB
GeoIP-Latitude
X-NodeID
Server-Id
XServer
ProcessTime
X-Action
X-ZONE
Mime-Version
X-PJAX-URL
X-Date
X-Accel-Expires-Debug
X-App
X-Region-Sid
X-VC-Cache
X-SD-PageType
X-Req
We-Hiring
X-Proxy-Upstream
Surrogated-Key
LB
Mail-Subject
Memcached
X-Kraken-Loop-Name
X-Fpc
X-BBC-Edge-Cache-Status
X-APP
Env
X-Kraken-Routeconfig-Destination
X-Instrumentation
X-NGINX-Cache
X-Oss-Cdn-Auth
X-Render-Time
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
Srv
X-CF-Powered-By
X-Server-Lifecycle-Phase
X-Provided-By
X-Dynatrace-Js-Agent
X-FORWARDED-FOR
Upgrade-Insecure-Requests
X-Men
X-Air-Trace-Id
EpKe-Alive
W
X-Depends-On
X-FTR-Cache-Host
X-Cdn-Request-ID
X-Oracle-Dms-Rid
X-Swift-Error
X-MSEdge-Features
CPC-Cache
CPC-Age
X-MSEdge-Flight
X-CSRF-TOKEN
CDN
VNS-Cache
X-UnsetCookies
X-Ftr-Cache-Host
VNS-Age
X-Ua
X-Auto-Login
X-BACKEND-TTL
X-Rocket-Build-Number
X-Worker
X-Sigma-Backend
X-TIME
Cdn
Processtime
X-Sigma
X-Dw-Trace-Id
X-CACHE-AGE
X-Client-Ip
X-Hello
X-Flog
X-ABtesting
Time
X-Fastly-Backend-Reqs
Memory
X-Cluster-Node
X-Parent-Response-Time
X-Fastly-Request-Id
X-Cache-Tag
Proxy-Connection
Dnion-Transfer-Encoding
X-Akamai-Pragma-Client-IP
X-Snapshot-Date
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-Acquia-Purge-Tags
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
PICS-Label
Datacenter
X-Pad
X-Pf-Uncompressing
X-BBC-Origin-Response-Status
X-Acquia-Site
X-Zone
Media-Length
X-Oracle-DMS-ECID
Vha6-Origin
X-Presslabs-Stats
Fastcgi-Cache-TTL
State
Epwk-X-Cache
My-App
X-HITS
X-Via-PopH
X-LiteSpeed-Tag
X-Via-PopV
X-Via-PopN
X-ServerName
Cf-Ipcountry
X-Apw-Access-Action
X-Apw-Access-Object
X-ElasticPress-Search
Xet-Cookie
X-ElasticPress-Query
X-Request-URL
X-Request-Url
OT-Force-Account-Verify
X-MiniProfiler-Ids
X-Ms-Meta-Originalurl
X-Akamai-ERPolicy
X-Cache-Status-Check
X-Akamai-ERRuleID
X-Minions-Version
X-Vcache
X-Csrf-Token
X-Varnish-Beresp-TTL
X-Varnish-URL
X-Ms-Meta-Staticbatchstarttime
X-Apw-Access-Token
X-Apw-Hits
X-Lb-Id
CountryCode
NnCoection
Inserted-Into-Cache-At
X-Storefront-Renderer-Verified
Environment
X-B3-Parentspanid
X-Debug-Cache-Store
Phost
X-ND-Cache
X-Debug-Cache-Fetch
Content-Style-Type
Content-Script-Type
URI
X-Amz-Meta-Cb-Modifiedtime
WZWS-RAY
X-Traceid
X-Redis-Duration-Ms
X-Redis-Count
X-Litespeed-Cache-Control
Ohc-Response-Time
X-C
X-Tid