Threat Level: green Handler on Duty: John Bambenek

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
X-XSS-Protection
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
P3P
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Runtime
X-AspNet-Version
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Request-ID
X-Cacheable
X-Ua-Compatible
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Content-Encoding
X-CDN
Feature-Policy
X-AspNetMvc-Version
Status
Access-Control-Expose-Headers
X-Envoy-Upstream-Service-Time
Upgrade
X-Drupal-Dynamic-Cache
Access-Control-Max-Age
X-Via
Keep-Alive
X-Ws-Request-Id
X-AH-Environment
X-Age
X-Robots-Tag
Request-Context
X-Cache-Group
Server-Timing
EagleId
X-Proxy-Cache
X-Turbo-Charged-By
X-Server
X-Hacker
X-Backend
X-Server-Powered-By
Host-Header
Report-To
X-Nginx-Cache-Status
X-Amz-Request-Id
X-Amz-Id-2
Grace
X-UA-Device
X-Rq
X-Varnish-Cache
P3p
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Page-Speed
X-Dns-Prefetch-Control
X-OneAgent-JS-Injection
X-Pingback
Cf-Railgun
X-Pantheon-Styx-Hostname
X-Device
X-Styx-Req-Id
X-CST
X-Amz-Version-Id
NEL
Allow
X-Cache-Spec
X-Vhost
X-Server-Id
X-Host
X-Backend-Server
X-WebKit-CSP
X-Dispatcher
X-ASPNET-VERSION
EagleEye-TraceId
X-Node
Surrogate-Control
Request-Id
Accept-CH
Xkey
X-Response-Time
Content-Location
X-Akam-SW-Version
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Ruxit-JS-Agent
X-Cache-Lookup
Accept-CH-Lifetime
X-Application-Context
X-Country
X-Ac
X-Readtime
X-Cloud-Trace-Context
X-Mod-Pagespeed
X-B3-TraceId
X-Template
X-Language
X-HW
MS-Author-Via
Rating
X-Cnection
X-Url
X-MS-InvokeApp
X-PC
X-Vname
X-TtlSet
Edge-Control
X-Origin-Cache
Accept-Ch-Lifetime
X-Clacks-Overhead
X-ESI
X-GitHub-Request-Id
X-Webkit-CSP
X-Trace
X-Varnish-TTL
X-D2id
Verso
X-FastCGI-Cache
Arr-Disable-Session-Affinity
X-Content-Type
X-Cdn-Fetch
X-Kinja
X-GoogleNews-Bot
X-Exp-Variant
X-Exp-Id
X-Kinja-Revision
X-Kinja-Build
X-Kinja-Server
X-Use-Magma
X-Sol
Display
X-Middleton-Display
Pagespeed
X-Middleton-Response
Response
X-Powered-By-Plesk
X-Country-Code
X-Rack-Cache
X-Goog-Hash
X-Vcap-Request-Id
X-VARITI-CCR
X-Navigation-Version
X-TTL
Accept-Ch
X-Server-Name
X-Amz-Rid
X-Abt-Application-Version
Fastly-Restarts
X-ORACLE-DMS-RID
X-Cached
X-ORACLE-DMS-ECID
Service-Worker-Allowed
X-Client-IP
X-Fastly-Request-ID
X-Buckets
X-Release
Cache-Tag
X-MSEdge-Ref
X-Element-Page-Cache
X-NF-Request-ID
X-Dw-Request-Base-Id
Access-Control-Request-Method
RTSS
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
Public-Key-Pins
SPRequestGuid
X-SharePointHealthScore
X-Cache-TTL
X-Edge
X-Powered-CMS
SPRequestDuration
SPIisLatency
Ar-Sid
AR-ATIME
AR-Request-ID
AR-CACHE
AR-PoweredBy
X-LLID
X-Upstream
X-Ezoic-Cdn
X-Version
X-SRCache-Store-Status
X-SRCache-Fetch-Status
S
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
X-HP-Webp
X-Jurisdiction
X-Kinsta-Cache
Content-MD5
X-Recruiting
X-MCACHE
X-ECACHE
X-Mid
Charset
X-PressLabs-Stats
X-T
X-Mg-S
X-Accel-Expires
Cache-Tags
X-Ttl
X-Forwarded-Proto
X-DynaTrace
X-Content-Digest
X-Content-Security-Policy-Report-Only
TP-L2-Cache
TP-Cache
Fastcgi-Cache
X-Correlation-Id
X-Origin-Upstream-Status
X-Logged-In
Filters
Fusion-Content-Id
Fusion-Deployment-Id
Fusion-Component-Id
Fusion-Source
Fusion-Content-Source
Fusion-Template-Id
X-Px
X-Litespeed-Cache
Server-Name
Server-Node
TCN
X-Id
Edge-Cache-Tag
X-Amz-Server-Side-Encryption
X-Request-Processing-Time
X-Request-Received
Front-End-Https
X-Forwarded-For
X-XRDS-Location
X-Ruxit-Js-Agent
Nginx-Cache
X-Shield-Request-Id
X-Oneagent-Js-Injection
X-Grace
Alternate-Protocol
MicrosoftSharePointTeamServices
X-Hits
X-Amzn-Trace-Id
X-Microsite
X-Request-Handler-Origin-Region
X-B3-Sampled
X-NWS-LOG-UUID
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-F-Cache
X-Activity-Id
Realpath
X-Az
X-AppVersion
X-Amz-Replication-Status
X-Origin-Server
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Combine-CSS
X-Varnish-Age
X-RateLimit-Remaining
X-Frontend
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Goog-Generation
X-GUploader-UploadID
X-Rid
X-Daa-Tunnel
Host
Section-Io-Cache
X-Cache-Age
X-Debug
X-Hostname
X-Geo-Country
Nel
X-Yandex-Sdch-Disable
X-DIS-Request-ID
Accept-Charset
X-VCache
X-Git-Hash
X-Fastcgi-Cache
Surrogate-Key
X-Contextid
X-WebKit-CSP-Report-Only
X-Ser
Access-Control-Allow-Method
Cleartype
X-Mobile-URL
X-Respond-Thread
X-Time
X-Seen-By
X-Type
X-Cache-Key
X-DataDome
X-LB-Cache
ServerID
X-N
MS-CV
Paypal-Debug-Id
X-Source
X-AOL-HN
Healthy
Payment
X-Varnish-Backend
X-TT
X-Signature
X-B-Cache
X-Content-Options
X-Upgrade-Enabled
X-Debug-Info
X-Route-Name
X-Aspnet-Duration-Ms
X-Load-Cache
X-Request-Guid
X-Is-Crawler
X-Flags
X-Providence-Cookie
X-Server-ID
X-Cache-Action
X-Whom
X-XRDS-LOCATION
X-IPLB-Instance
X-Page-Id
X-FB-Debug
X-App-Environment
Node
Fastcgi-Useragent
X-Jobs
Cache
X-Cache-Expired-At
X-Webkit-Csp
X-FireWall-Port
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Mobile
X-Rule
Viewport
Refresh
X-Response-Served-From
X-Wix-Request-Id
X-Accel-Buffering
X-Original-Request-Id
DC
X-Www-Served-By
Access-Control-Request-Headers
Ms-Operation-Id
X-Cluster-Name
X-Content-Powered-By
X-RTag
X-Instance
X-Cacheable-TTL
X-B
X-Protected-By
X-Debug-IsConnected
X-Debug-IsPreview
X-HTML-Minification-Powered-By
X-RemovedCookies
X-ProcessESI
X-Distributor
X-Real-IP
X-Tec-Api-Version
X-Region
X-Tec-Api-Origin
X-Tec-Api-Root
X-Framework
Version
X-UUID
VIX-Pulpo-Node
X-Proxy
VIX-Pulpo-Upstream-Status
X-Zen-Fury
X-Cache-Control
X-IPS-LoggedIn
X-Cache-Time
X-Tt-Trace-Host
Referer-Policy
X-Tt-Trace-Tag
X-Page-View
X-Drupal-Cache-Tags
Countrycode
Eomportal-Instance
X-Nginx-Cache
X-Drupal-Cache-Contexts
X-G
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-1
X-Varnish-Grace
X-FW-Static
X-FW-Dynamic
X-App-Server
X-FW-Hash
X-FW-Server
X-FW-Serve
X-FW-Type
Xserver
Liferay-Portal
X-Device-Type
X-Yottaa-Optimizations
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
X-Yottaa-Metrics
Section-Io-Id
Section-Origin-Responded
X-Cache-Rule
X-Cached-By
X-Cache-Operation
SRV
X-Via-JSL
CF-IPCountry
X-L-Path
X-Environment-Context
X-FTR-Request-ID
GEO-INFO
X-Akamai-Edgescape
X-Cache-Hit
X-Pass-Why
X-Varnish-Server
X-Adobe-Loc
X-Adobe-Content
Cache-Status
Server-Info
Retry-After
Frame-Options
X-User-Agent
Powered-By-ChinaCache
DynaTrace
X-Proxy-Cache-Status
Uber-Trace-Id
X-TA-CDN-Provider
X-Endurance-Cache-Level
X-Handled-By
X-UPSTREAM-Address
X-Hl-Ver
X-ES-SERVER
Meta-Geo
X-RN-RSRV
X-FB-TRIP-ID
From-Origin
X-Backend-Name
X-TEC-API-ORIGIN
Cache-Tv-Group
Ec-Rule-Version
X-Tumblr-Pixel-2
X-TEC-API-ROOT
X-TEC-API-VERSION
X-NYM-Debug-Backend
X-WA-Info
X-ProxyCache-Status
X-Soup
X-Varnishpool
X-Section
X-Request-Time
X-ProxyCache-Key
X-Pubstack
X-Origin-Hint
X-BYPASS-REASON
TWC-Device-Class
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Connection-Speed
Property-Id
Country
Fastly-SSL
TWC-Locale-Group
TWC-Privacy
X-Be
Apigw-Requestid
X-Access
Webcakes-Region
Webcakes-App-Name
Webcakes-App-Version
X-Cache-Server
X-Format
X-Mode
X-Timing-Wait
Decoy-Debug-Status
X-TNCMS
X-S-Maxage
X-OCL
X-No-Session
Decoy-Debug-TTL
X-Storage
Webserver
X-Human
Cache-Name
X-LJ-Flow-ID
X-UA-Device-Type
X-Loop
Decoy-Debug-Key
X-MP-GENERATED-AT
Mn-Server-Ip
X-Proto
X-Proxy-Build
X-PCL
X-AWS-Id
X-VWS-Id
X-Uri
X-Server-W
X-Origin-Date
Selected-Fe
X-Cache-TTL-Remaining
X-R9-Blue-Green-Version
X-ApacheServer
X-Say-Cacheable
X-Say-TTL
X-GG-Cache-Date
Protected
X-SayCDN-TTL
X-Info
X-Labrador-Cache-Channel
X-PHP-Host
X-Web-Node
X-SRV
X-PERF
X-Xfnlog-Site
X-LAGOON
X-Via-Fastly
X-Sql-Duration-Ms
X-Sql-Count
Azure-InstanceId
X-Sorting-Hat-PodId
X-Shopify-Stage
X-ShopId
X-Sorting-Hat-ShopId
X-Alternate-Cache-Key
Azure-SlotName
X-ShardId
X-Storefront-Renderer-Rendered
Azure-SiteName
Azure-Version
X-Content-Age
Azure-RegionName
X-Hosted-By
X-NWS-UUID-VERIFY
X-Cache-Enabled
X-Status
X-Hyper-Cache
X-Backend-Host
Amp-Access-Control-Allow-Source-Origin
X-Zipkin-Id
X-Proxied
X-Redis-Cache
X-Routing-Service
X-Rendered-As
X-Azure-Ref
X-App-Version
X-Is-Bot
X-RateLimit-Limit
X-Locale
X-Microcachable
X-FW-Version
X-Cluster
X-Pinterest-Direct
X-Site-Version
S-Cnection
X-Trace-Id
X-Forwarded-Host
X-AIR-PT
X-EdgeConnect-Cache-Status
X-CSRF-Token
AMP-Access-Control-Allow-Source-Origin
Akamai-GRN
ServedBy
X-Platform
X-Cache-Grace
X-Cache-PHP
X-Cache-NGX
X-Varnish-Hostname
Who
X-Edge-Location-Klb
Filterid
X-Revision
X-TT-LOGID
X-RCS-CacheZone
X-Qloud-Router
X-ATG-Version
X-Varnish-Ttl
X-Instrumentation
X-Kraken-Routeconfig-Destination
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Aspnetmvc-Version
X-Via-CDN
DB-Nickname
X-Debug-Cache
X-Ratelimit-Limit
Cache-Hits
Country-Code
X-Detected-As
X-CS
X-TX-ID
X-Adobe-Source
X-Varnish-Beresp-Grace
X-B3-SpanId
NGB
X-Cache-Host
X-Ms-Version
X-Ms-Request-Id
X-Unique-Id
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Status
X-Amzn-RequestId
X-Amzn-Remapped-Content-Length
X-Dc
X-Amz-Apigw-Id
X-Akamai-Transformed
SD-X-WS
X-BCube-Filmed-By
X-CCM
X-CACHE-KEY
Backend
X-ID
X-GEO
Mobile-Detection-Method
Fastcgi-X-Cache-Version
Odigeo-Trace-Id
BehaviorPad-Version
Meta-Geo-Continent
Fastly-Backend-Name
DCR-Decision-By
Expiry
DCR-Processing-Time-Ms
X-Level-Front-Cache
X-Location
MD5-Digest
X-Owner
X-A
X-Processor
X-Varnish-Cache-Hits
X-Request-UUID
X-Rewrite-Enabled
X-Backend-TTL
T-Server
X-PBS-Appsvrname
Rendered-Blocks
X-ServerID
X-Origin-CC
X-Origin-TTL
X-PAYTM-SRV-ID
X-Rojux
X-NAPM-TraceId
X-A-Dcw
X-D
X-Vdms-Version
X-Trv-Group
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-Generated-On
X-From
X-Vtex-Processado-Em
X-Vdms-Path
X-B-Cookie
X-External-Request-Id
X-Connection-Hash
X-Cache-Bucket
X-ARC
X-Vtex-Remote-Cache
X-Destination
X-Cache-NE
X-A-Dam
X-Session-Fingerprint
X-A-Dgt
X-VG-WebServer
X-ScT
X-S-Cookie
X-A-Ccd
X-VG-WebCache
X-A-Wwc
X-Aed
X-Node-Name
X-S
X-Generation-Time
X-Application
X-SRCache-Key
Release
X-Has-Esi
X-FC-Vary-Parameters
X-Cms-Context
X-OVcl
Cache-Host
X-Magnolia-Registration
Cf-Device-Type
X-JWT-State
Content-Disposition
Host-ID
Gh-Request-Id
X-Device-Os
X-Developers
Magicmarker
X-Is-Gdpr
Pagetype
Path
PB-PID
X-Core-Value
Arc-Version
CacheControlHeader
X-Fetched-On
PB-RID
X-OVcl-Cache
X-Thanos
X-Bip
X-Tumblr-Pixel-3
X-Generated-In
V-Age
Thinkindot-CacheControl
X-Azure-Ref-OriginShield
Thinkindot-Control
Thinkindot-CacheControl-Type
X-GeoIP-City
X-Geo-Header
Wxu-Next-Commit
Wxu-Next-Hostname
Wxu-Next-Region
X-Thinkindot-L3
X-TrackingId
Server-Host
Ssr
X-Policy
UCS
X-Vgn-Hpd-Reason
X-Time-Microsecs
X-GeoIP
Locid
Location
Machine
X-DefHash
X-Dispatcher-Server
X-Li-Fabric
X-DPWN-IS-SECURE
HA-Ipaddr
Ha-Gx-Prefs
Is-Eu
X-Developer
L
X-DefElseHash
IsBot
Vix-Hermes-Req-Id
L5d-Success-Class
X-Csrf-Jwt
X-Cache-Debug
X-Clientip
Req-Svc-Chain
X-Branch-Name
X-Fastly-Backend
X-CGP
Server-Hostname
Sever-Int
X-GoCache-CacheStatus
Server-Ext
X-HN
Platform
True-Client-Country-4JS
X-Cache-Tags
NGX
X-Irp-Debug
NM-Fastcgi-Cache
X-IP
PFcat
X-Backend-State
X-Eu-Site
Origin
X-Epic-Correlation-Id
X-Rebelmouse-Cache-Control
X-Reqid
X-Rebelmouse-Surrogate-Control
X-Envoy-Decorator-Operation
X-Request-URI
X-Oss-Storage-Class
X-Li-Pop
X-Oss-Server-Time
X-Ratelimit-Reset
X-Platform-Server
X-Origin
X-NU-AKA-ACS-Version
X-Origin-Expires
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Varnish-Remaining-TTL
X-Varnish-Hits
X-Varnish-CookieINHashed-On
X-VarnishDD-TTL
X-VG-TLSProxy
X-Nc
X-VServer
X-Varnish-CookieHashed-On
X-Variation
X-B3-Traceid
X-SIPLIST1
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Var-Ttl
X-User
X-Node-Id
X-Oss-Request-Id
Apple-News-Services-Host
Apple-News-Services-Handled
AKAMAI
Esi-Enabled
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
CDCHOST
CDN-CachedAt
C-Via
CDN-EdgeStorageId
CDN-PullZone
Adler-Geo
DSUID
CDN-RequestId
CDN-Uid
Cf-Bgj
X-Nginx-Cache-Key
X-LI-UUID
Fastly-SIE
Fastly-SWR
CDN-RequestCountryCode
CDN-Cache
User-Cache-Control
X-APP-VERSION
Kp-EeAlive
X-Block-Status
X-LB-ID
X-Micro-Cache
X-Wikidot-Static-Cache
X-Served-From
X-Tb
X-Loc
X-Fastly-Cache
Fastly-Drupal-HTML
Cmstype
HostName
X-Gamma-Serve
X-Gen-Mode
X-Cache-Info
X-Generated-By
X-Wikidot-Backend
Cmsid
X-Method
Web-Mar-Node
X-Hnp-Log
X-Request-Host
X-Mvc-Supplant-Cachable
X-Servername
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Hash
X-Origin-Response-Time
X-Aicache-OS
X-Old-Content-Length
X-Scheme
X-Skip-Cache
Rt-Fastcgi-Cache
X-Amz-Meta-S3cmd-Attrs
X-Clara-WADP
A
X-Cache-Id
Svr
X-HS-Content-Campaign-Id
X-Sucuri-ID
X-Slack-Backend
X-WADP-Cache
X-Varnish-Url
X-DynaTrace-JS-Agent
X-Fmm-Version
X-Gzip
X-Esi-Check
X-EC-Lua
X-PHP-Backend
X-Unique-ID
X-Ratelimit-Remaining
X-NewRelic-App-Data
X-CDN-Forward
X-NGENIX-Cache
M-TraceId
X-Via-Popn
X-Via-Poph
X-Via-Popv
X-Air-Hostname
X-FTR-Balancer
X-JoinUs
X-Edge-Location
X-FTR-Cache-Status
X-FTR-Realm
On-Server
Pics-Label
X-FTR-DC
X-FTR-Backend-Server
X-SaId
X-Country-Code-Real
X-Correlation-ID
X-FTR-Backend
X-DC
Url
X-Swa-Ws
Xc-Version
X-PF-Uncompressing
Cross-Origin-Opener-Policy
SID
Viewtype
X-Mvc-Supplant-OutputCached
VivaBuild
TDXMobile
Cache-Key
Arc-Country
X-Refresh
X-NC
X-FTR-Expires
Instruction
X-Service
X-Vc
SR-User-Adfree
Content-Secure-Policy
X-Cdn-Forward
MIME-Version
X-Extlb
Tracecode
X-Bc-Bl
X-CUA
X-Internal-Host
X-Cache-Var-Map
X-Cache-Var
DataCenter
Sid
X-Servedbyhost
NtCoent-Length
Lfy
Server-ID
X-Matched-Rule
X-Tb-Optimization-Total-Bytes-Saved
X-Sn-Servicetimems
Geo-Info
X-Wa
X-Cdn-Origin
X-Cache-Ttl
X-CLOUD-TRACE-CONTEXT
X-Cache-Expires
X-NCache
CloudFront-Viewer-Country
X-TraceId
Surrogated-Key
X-Forwarded-Site
LB
X-Req
Pramga
X-Proxy-Upstream
Memcached
X-Cache-Backend
Hostname
X-LI-Proto
Source
Tcn
X-VC-Cache
Mail-Subject
We-Hiring
X-Cache-Date
X-Core-Mission
X-Webkit-CSP-Report-Only
Upgrade-Insecure-Requests
X-Accel-Expires-Debug
X-Request-Start
X-Srv
X-Sigma-Backend
X-Sigma
X-VCL-Version
X-Date
X-Rocket-Build-Number
FSS-Cache
Geoip-Latitude
X-Mg-Request-UUID
X-Viewer-Country
X-B3-Spanid
GeoIp-Country-Code
X-Newrelic-Synthetics
X-Zone
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-MSEdge-Features
X-HS-Status
Env
X-Air-Source
X-MSEdge-Flight
X-Esi
X-Via-NSCOPI
X-App
CACHE
X-VHOST
X-Men
X-PJAX-URL
X-FireWall-Protection
GeoIP-Country-Code
X-Error
GeoIP-Latitude
X-Geo
X-HOST
XServer
CPC-Cache
X-Response-By
CPC-Age
X-CCDN-Origin-Time
X-CCDN-CacheTTL
Time
X-Varnish-Cacheable
X-Li-Proto
Memory
VNS-Cache
X-Hcs-Proxy-Type
Request-ID
VNS-Age
X-LiteSpeed-Cache-Control
X-URL
X-DSS
X-DW
X-DI
Server-Ttl
X-Air-Trace-Id
X-RPM
X-RPS
State
X-TIM-N
My-App
Fastcgi-Cache-TTL
X-RSL
X-Vcl-Version
X-DB
Resin-Trace
CF-Cached-On
X-ZONE
X-Cache-Type
X-APP
X-Minions-Version
X-BBXSRF
S-Rt
Xkeyi7
X-WA
X-Proxy-Cachei7
X-Cs
HitType
X-Dynatrace-Js-Agent
N-Cache
X-Action
X-ServedByHost
X-RAMCache
X-HostName
OT-Force-Account-Verify
X-Cache-2
ProcessTime
X-Varnish-Authentication
X-Cache-ASPX
X-Oss-Cdn-Auth
X-FPC
X-Contensis-Viewer-Groups
Server-Id
X-Region-Sid
X-Swift-Error
X-Provided-By
X-Cc-Req-Id
X-Shop-Environment
X-Tenant
X-Orig-Expires
X-ND-Cache
X-Cc-Via
X-FORWARDED-FOR
X-UA
X-Svr
W
X-Forwarded-Path
Cache-Provider
D-Cc-Upstream
Mime-Version
X-Depends-On
X-Cdn-Request-ID
Srv
CDN
X-UnsetCookies
WZWS-RAY
X-Traceid
X-TIME
Datacenter
X-Dw-Trace-Id
X-CSRF-TOKEN
X-Cluster-Node
X-ServerName
X-Xrds-Location
X-Client-Ip
X-Cache-Config
X-Hello
X-ElasticPress-Search
X-Flog
X-Server-IP
X-Parent-Response-Time
X-API-Version
X-CF-Powered-By
Proxy-Connection
X-Fastly-Request-Id
X-ABtesting
X-Ftr-Request-Id
X-Pf-Uncompressing
X-Gdpr
X-Nyt-Route
X-Origin-Time
X-Fpc
X-Akamai-Pragma-Client-IP
Cf-Ipcountry
X-BACKEND-TTL
X-Oracle-DMS-ECID
X-VC
Cdn
X-IN-APIGATEWAY
Cteonnt-Length
X-IN-APIGATEWAYSSL
X-Conf
X-Pjax-Url
X-Presslabs-Stats
X-Pad
X-NGINX-Cache
Media-Length
Vha6-Origin
X-BBC-Edge-Cache-Status
X-V-Cache
X-Ckpd-Fst-Backend
X-Via-PopH
X-Via-PopN
Ohc-File-Size
Cross-Origin-Window-Policy
Dnion-Transfer-Encoding
X-LiteSpeed-Tag
X-NodeID
X-Air-Pt
X-BBC-Origin-Response-Status
Count-Hit
X-Snapshot-Date
X-Via-PopV
PICS-Label
Epwk-X-Cache
X-SN
X-Fastly-Backend-Reqs
X-Check-Cacheable
X-SD-PageType
X-Sucuri-Cache
Ohc-Cache-HIT
X-Cache-Remote
X-Acquia-Purge-Tags
X-Vcache
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-Cache-Tag
X-Yottaa-OS
Xet-Cookie
Warning
X-Lb-Id
X-Acquia-Site
X-Aws-Lambda-Call-Status
X-Ua
X-Webstats-RespID
X-Auto-Login
X-Worker
X-Akamai-ERPolicy
X-Varnish-URL
X-Ms-Meta-Staticbatchstarttime
X-TH-Server
X-SB
X-Akamai-ERRuleID
X-Ms-Meta-Originalurl
X-Ftr-Cache-Host
CountryCode
X-Tx-Id
X-LSADC-Cache
X-ElasticPress-Query
X-C
X-Erf-Stays-Bingo-Pdp-Web
Inserted-Into-Cache-At
NnCoection
X-Tid
X-Varnish-Beresp-TTL
X-Amz-Meta-Cb-Modifiedtime
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-MiniProfiler-Ids
Phost
X-Request-URL
Ohc-Response-Time
X-B3-Parentspanid
X-Litespeed-Cache-Control
X-Apw-Access-Token
X-Apw-Hits
X-Cache-Status-Check
URI
X-Apw-Access-Object
X-Apw-Access-Action
Content-Script-Type
Content-Style-Type
EpKe-Alive
X-Mg-Request-Id