Threat Level: green Handler on Duty: John Bambenek

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-RAY
CF-Cache-Status
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
X-XSS-Protection
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
P3P
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-Runtime
X-AspNet-Version
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Request-ID
X-Cacheable
X-Ua-Compatible
Timing-Allow-Origin
X-Content-Security-Policy
X-FRAME-OPTIONS
X-Iinfo
Content-Encoding
X-CDN
Feature-Policy
Status
X-AspNetMvc-Version
Access-Control-Expose-Headers
X-Envoy-Upstream-Service-Time
Upgrade
X-Drupal-Dynamic-Cache
Access-Control-Max-Age
X-Via
Keep-Alive
X-Ws-Request-Id
X-AH-Environment
X-Age
X-Robots-Tag
Request-Context
X-Cache-Group
Server-Timing
EagleId
X-Proxy-Cache
X-Turbo-Charged-By
X-Server
X-Hacker
X-Backend
X-Server-Powered-By
Host-Header
Report-To
X-Nginx-Cache-Status
X-Amz-Request-Id
X-Amz-Id-2
Grace
X-UA-Device
X-Rq
X-Varnish-Cache
P3p
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Page-Speed
X-Dns-Prefetch-Control
X-OneAgent-JS-Injection
X-Pingback
Cf-Railgun
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
X-CST
X-Amz-Version-Id
NEL
Allow
X-Vhost
X-Cache-Spec
X-Server-Id
X-Host
X-Backend-Server
X-WebKit-CSP
X-Dispatcher
X-ASPNET-VERSION
EagleEye-TraceId
X-Node
Surrogate-Control
Request-Id
Xkey
X-Response-Time
Accept-CH
Content-Location
X-Akam-SW-Version
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Ruxit-JS-Agent
X-Cache-Lookup
Accept-CH-Lifetime
X-Application-Context
X-Country
X-Ac
X-Readtime
X-Cloud-Trace-Context
X-Mod-Pagespeed
X-B3-TraceId
X-Template
X-Language
X-HW
MS-Author-Via
Rating
X-Url
X-Cnection
X-MS-InvokeApp
X-TtlSet
X-Vname
X-PC
Edge-Control
X-Origin-Cache
Accept-Ch-Lifetime
X-Clacks-Overhead
X-ESI
X-GitHub-Request-Id
X-Varnish-TTL
X-Trace
X-Webkit-CSP
X-D2id
Verso
X-Content-Type
Accept-Ch
Arr-Disable-Session-Affinity
X-Kinja-Build
X-Use-Magma
X-Kinja-Server
X-Kinja
X-Kinja-Revision
X-Cdn-Fetch
X-Exp-Variant
X-Exp-Id
X-GoogleNews-Bot
Pagespeed
Response
X-Middleton-Response
X-Sol
X-Middleton-Display
Display
X-Powered-By-Plesk
X-Goog-Hash
X-Rack-Cache
X-Country-Code
X-FastCGI-Cache
X-Vcap-Request-Id
X-VARITI-CCR
X-Navigation-Version
X-Server-Name
X-TTL
X-Amz-Rid
Fastly-Restarts
X-Abt-Application-Version
X-ORACLE-DMS-RID
X-Cached
X-ORACLE-DMS-ECID
Service-Worker-Allowed
X-Fastly-Request-ID
X-Client-IP
X-Buckets
Cache-Tag
X-MSEdge-Ref
X-Release
X-Element-Page-Cache
X-NF-Request-ID
X-Dw-Request-Base-Id
RTSS
Access-Control-Request-Method
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
Public-Key-Pins
X-SharePointHealthScore
SPRequestGuid
X-Cache-TTL
SPIisLatency
X-Edge
X-Powered-CMS
SPRequestDuration
AR-CACHE
AR-PoweredBy
AR-ATIME
Ar-Sid
X-LLID
AR-Request-ID
X-Ezoic-Cdn
X-Upstream
X-Version
X-SRCache-Fetch-Status
X-SRCache-Store-Status
S
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-Kinsta-Cache
X-Jurisdiction
X-HP-Webp
Content-MD5
X-Recruiting
X-Mid
X-ECACHE
X-MCACHE
Charset
X-Mg-S
X-PressLabs-Stats
X-T
X-Accel-Expires
Cache-Tags
X-Ttl
X-Forwarded-Proto
X-Correlation-Id
X-DynaTrace
X-Content-Digest
X-Content-Security-Policy-Report-Only
Fastcgi-Cache
TP-L2-Cache
TP-Cache
X-Origin-Upstream-Status
X-Logged-In
Filters
Fusion-Content-Source
Fusion-Component-Id
Fusion-Deployment-Id
Fusion-Content-Id
Fusion-Source
Fusion-Template-Id
X-Px
X-Litespeed-Cache
TCN
Server-Node
Server-Name
X-Id
Edge-Cache-Tag
X-Amz-Server-Side-Encryption
Front-End-Https
X-Request-Processing-Time
X-Request-Received
X-Forwarded-For
X-XRDS-Location
Nginx-Cache
X-Shield-Request-Id
X-Oneagent-Js-Injection
Alternate-Protocol
X-Grace
X-Hits
MicrosoftSharePointTeamServices
X-Amzn-Trace-Id
X-NWS-LOG-UUID
X-Request-Handler-Origin-Region
X-B3-Sampled
X-Microsite
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Realpath
X-F-Cache
X-AppVersion
X-Activity-Id
X-Az
X-Amz-Replication-Status
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Hub-Id
X-Origin-Server
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
X-RateLimit-Remaining
X-Ruxit-Js-Agent
X-Fastcgi-Cache
X-Goog-Stored-Content-Length
X-Varnish-Age
X-Goog-Storage-Class
X-Goog-Metageneration
X-Goog-Generation
X-Frontend
X-Rid
X-Daa-Tunnel
Host
X-Cache-Age
Section-Io-Cache
X-Debug
X-Hostname
X-Geo-Country
Nel
Accept-Charset
X-Yandex-Sdch-Disable
X-DIS-Request-ID
X-Git-Hash
X-Contextid
X-VCache
Surrogate-Key
Cleartype
X-WebKit-CSP-Report-Only
X-Ser
X-Respond-Thread
Access-Control-Allow-Method
X-Time
X-Mobile-URL
X-DataDome
X-Seen-By
X-N
MS-CV
Paypal-Debug-Id
X-Type
X-LB-Cache
X-Cache-Key
X-Source
ServerID
X-AOL-HN
X-Route-Name
X-Aspnet-Duration-Ms
X-Request-Guid
X-Providence-Cookie
X-Flags
X-Is-Crawler
Payment
Healthy
X-TT
X-Varnish-Backend
X-Upgrade-Enabled
X-Content-Options
X-Cache-Action
X-Signature
X-Debug-Info
X-B-Cache
X-Whom
X-Server-ID
X-Load-Cache
X-Page-Id
X-IPLB-Instance
X-App-Environment
X-XRDS-LOCATION
X-FB-Debug
Node
Fastcgi-Useragent
X-Jobs
Cache
X-Cache-Expired-At
X-FireWall-Port
X-Webkit-Csp
Viewport
X-Browser-Type
X-Mobile
X-Rule
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
Refresh
X-Original-Request-Id
X-Wix-Request-Id
X-Accel-Buffering
X-Response-Served-From
X-Www-Served-By
DC
X-Cacheable-TTL
Ms-Operation-Id
X-HTML-Minification-Powered-By
Access-Control-Request-Headers
X-Instance
X-Cache-Control
X-RTag
X-Real-IP
X-Content-Powered-By
X-Cluster-Name
X-Page-View
X-ProcessESI
X-Zen-Fury
X-Protected-By
X-Debug-IsConnected
X-Debug-IsPreview
X-Framework
X-Distributor
X-RemovedCookies
X-UUID
X-B
VIX-Pulpo-Node
Version
X-Region
VIX-Pulpo-Upstream-Status
Referer-Policy
X-Cache-Time
X-Proxy
X-IPS-LoggedIn
X-Tt-Trace-Host
X-Tt-Trace-Tag
Countrycode
X-Drupal-Cache-Tags
Eomportal-Instance
X-Varnish-Grace
X-Nginx-Cache
X-Tec-Api-Origin
X-Drupal-Cache-Contexts
X-Tec-Api-Version
X-Tec-Api-Root
X-G
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-Tumblr-User
X-Tumblr-Pixel-0
X-FW-Dynamic
X-FW-Type
X-App-Server
X-FW-Server
X-FW-Serve
X-FW-Static
X-FW-Hash
CF-IPCountry
Xserver
X-Yottaa-Optimizations
Liferay-Portal
Section-Io-Id
Section-Io-Origin-Time-Seconds
X-Yottaa-Metrics
Section-Io-Origin-Status
Section-Origin-Responded
X-Cached-By
GEO-INFO
X-Device-Type
SRV
X-Cache-Rule
X-Via-JSL
X-Cache-Operation
X-FTR-Request-ID
X-Environment-Context
X-L-Path
X-Cache-Hit
X-Akamai-Edgescape
X-Pass-Why
X-Varnish-Server
X-Adobe-Loc
Retry-After
X-Adobe-Content
X-TEC-API-ORIGIN
Cache-Status
X-TEC-API-VERSION
X-TEC-API-ROOT
Server-Info
Frame-Options
X-User-Agent
Uber-Trace-Id
X-Proxy-Cache-Status
DynaTrace
Powered-By-ChinaCache
X-TA-CDN-Provider
Meta-Geo
X-Handled-By
X-Hl-Ver
X-ES-SERVER
X-UPSTREAM-Address
X-RN-RSRV
X-Endurance-Cache-Level
Amp-Access-Control-Allow-Source-Origin
X-Backend-Name
From-Origin
Cache-Tv-Group
Ec-Rule-Version
X-Tumblr-Pixel-2
X-FB-TRIP-ID
Decoy-Debug-Key
X-NYM-Debug-Backend
Property-Id
X-Uri
X-ProxyCache-Status
X-Varnishpool
TWC-Privacy
X-WA-Info
TWC-Locale-Group
X-Pubstack
TWC-Device-Class
TWC-GeoIP-Country
X-Origin-Hint
X-Section
TWC-Connection-Speed
X-Soup
X-Human
X-ProxyCache-Key
Fastly-SSL
X-Access
X-Be
Decoy-Debug-TTL
Decoy-Debug-Status
Country
TWC-GeoIP-LatLong
X-BYPASS-REASON
Webserver
X-MP-GENERATED-AT
X-Request-Time
Webcakes-App-Name
Webcakes-App-Version
X-Cache-Server
Webcakes-Region
Apigw-Requestid
X-Format
X-Mode
X-UA-Device-Type
X-TNCMS
X-Proto
X-Web-Node
X-No-Session
X-Timing-Wait
X-VWS-Id
X-OCL
X-PCL
Cache-Name
X-Origin-Date
X-Sql-Count
X-Storage
X-Sql-Duration-Ms
X-Loop
X-Labrador-Cache-Channel
X-Proxy-Build
X-S-Maxage
X-AWS-Id
Mn-Server-Ip
Selected-Fe
X-Info
X-Say-Cacheable
X-Say-TTL
X-PHP-Host
X-LAGOON
X-LJ-Flow-ID
X-SayCDN-TTL
X-Server-W
X-PERF
X-R9-Blue-Green-Version
X-NWS-UUID-VERIFY
X-Cache-TTL-Remaining
X-Via-Fastly
Azure-Version
Azure-SlotName
X-SRV
X-Content-Age
X-GG-Cache-Date
Azure-SiteName
Azure-RegionName
X-Xfnlog-Site
Protected
X-ApacheServer
Azure-InstanceId
X-Alternate-Cache-Key
X-ShardId
X-Redis-Cache
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Hyper-Cache
X-Storefront-Renderer-Rendered
X-ShopId
X-Status
X-Hosted-By
X-Cache-Enabled
X-Rendered-As
X-Is-Bot
X-Backend-Host
X-Azure-Ref
X-Zipkin-Id
X-App-Version
X-Routing-Service
X-Proxied
X-RateLimit-Limit
X-Locale
S-Cnection
X-Site-Version
X-Cluster
X-Microcachable
X-FW-Version
X-Pinterest-Direct
X-Trace-Id
Akamai-GRN
X-Edge-Location-Klb
X-Cache-Grace
X-EdgeConnect-Cache-Status
X-CSRF-Token
X-Forwarded-Host
X-AIR-PT
Filterid
X-TT-LOGID
ServedBy
Who
X-ATG-Version
X-Cache-NGX
X-Cache-PHP
X-Varnish-Hostname
X-Revision
X-Platform
X-Instrumentation
X-Kraken-Loop-Name
X-Kraken-Routeconfig-Destination
X-RCS-CacheZone
X-Qloud-Router
X-Server-Lifecycle-Phase
X-Aspnetmvc-Version
X-Ratelimit-Limit
X-Debug-Cache
Country-Code
AMP-Access-Control-Allow-Source-Origin
DB-Nickname
X-Via-CDN
Cache-Hits
X-Detected-As
X-Adobe-Source
X-Varnish-Beresp-Grace
X-CS
X-B3-SpanId
NGB
X-Unique-Id
X-TX-ID
X-Ms-Request-Id
X-Cache-Host
X-Varnish-Beresp-Ttl
X-Ms-Version
X-Amzn-Remapped-Content-Length
X-Amzn-RequestId
X-Varnish-Beresp-Status
X-GEO
X-Amz-Apigw-Id
X-Akamai-Transformed
X-BCube-Filmed-By
Backend
SD-X-WS
X-CACHE-KEY
X-CCM
X-ID
X-Dc
X-Rewrite-Enabled
X-S
X-Request-UUID
X-Rojux
X-Session-Fingerprint
X-Vdms-Version
X-VG-WebCache
X-Vtex-Remote-Cache
X-VG-WebServer
X-Vdms-Path
X-Trv-Group
X-ScT
X-Vtex-Processado-Em
X-SRCache-Key
X-Varnish-Cache-Hits
X-S-Cookie
X-Level-Front-Cache
MD5-Digest
X-B-Cookie
Meta-Geo-Continent
Mobile-Detection-Method
X-Cache-Bucket
X-Cache-NE
Expiry
Fastcgi-X-Cache-Version
Fastly-Backend-Name
Odigeo-Trace-Id
X-Application
X-A-Dam
X-A-Dcw
X-A-Dgt
X-A-Ccd
X-A
X-Aed
Rendered-Blocks
T-Server
X-CF-Lambda-Fn
DCR-Processing-Time-Ms
X-Origin-CC
BehaviorPad-Version
X-NAPM-TraceId
X-Location
X-Origin-TTL
X-Owner
X-PBS-Appsvrname
X-PAYTM-SRV-ID
X-ServerID
X-A-Wwc
X-Generation-Time
X-D
X-Connection-Hash
X-CF-Lambda-Version
X-Destination
X-External-Request-Id
X-Generated-On
X-From
DCR-Decision-By
X-Processor
X-ARC
X-Node-Name
X-Backend-TTL
X-Device-Os
Cf-Device-Type
X-FC-Vary-Parameters
Content-Disposition
X-Developers
X-Cms-Context
X-Core-Value
Esi-Enabled
X-Varnish-Ttl
X-Fetched-On
CacheControlHeader
X-IP
X-Irp-Debug
X-Is-Gdpr
X-JWT-State
X-Has-Esi
X-GeoIP-City
Gh-Request-Id
Cache-Host
Arc-Version
X-Generated-In
X-Backend-State
Server-Host
Ssr
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Pagetype
Path
Release
PB-RID
PB-PID
Thinkindot-Control
Magicmarker
X-Azure-Ref-OriginShield
Host-ID
X-Magnolia-Registration
Wxu-Next-Region
Wxu-Next-Hostname
UCS
V-Age
Wxu-Next-Commit
X-Bip
X-Geo-Header
X-TrackingId
X-Vgn-Hpd-Reason
X-Time-Microsecs
X-Thanos
X-OVcl
X-OVcl-Cache
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
X-Var-Ttl
X-Tumblr-Pixel-3
X-Policy
X-Planisys-CDN-Rules
X-Thinkindot-L3
User-Cache-Control
X-Cache-Info
X-Cache-Tags
Web-Mar-Node
X-CGP
X-Cache-Debug
X-Branch-Name
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Block-Status
X-SIPLIST1
Vix-Hermes-Req-Id
X-Variation
X-VG-TLSProxy
Req-Svc-Chain
Server-Ext
X-VServer
X-Wikidot-Backend
X-Micro-Cache
X-Wikidot-Static-Cache
X-VarnishDD-TTL
Server-Hostname
X-Varnish-CookieHashed-On
X-Clientip
True-Client-Country-4JS
X-Varnish-CookieINHashed-On
X-Varnish-Hits
Sever-Int
X-Varnish-Remaining-TTL
X-User
X-Csrf-Jwt
X-Origin-Response-Time
X-GoCache-CacheStatus
X-Origin-Expires
X-GeoIP
Platform
X-Gen-Mode
X-Generated-By
X-HN
X-Hnp-Log
X-Li-Pop
X-LI-UUID
X-Nginx-Cache-Key
X-Li-Fabric
X-Node-Id
X-Origin
X-NU-AKA-ACS-Version
X-Platform-Server
X-Fastly-Cache
X-DefHash
X-Reqid
X-Developer
X-DefElseHash
X-Mvc-Supplant-Cachable
X-Request-URI
X-Request-Host
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Epic-Correlation-Id
X-Eu-Site
X-Fastly-Backend
X-Envoy-Decorator-Operation
X-DPWN-IS-SECURE
X-Ratelimit-Reset
X-Dispatcher-Server
X-Nc
X-Old-Content-Length
CDN-RequestId
CDN-Uid
CDN-RequestCountryCode
CDN-PullZone
CDN-CachedAt
CDN-EdgeStorageId
Cf-Bgj
DSUID
HA-Ipaddr
Is-Eu
Ha-Gx-Prefs
Fastly-SWR
Fastly-SIE
CDN-Cache
CDCHOST
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Storage-Class
X-B3-Traceid
Adler-Geo
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Apple-News-Services-Host
Apple-News-Services-Handled
AKAMAI
IsBot
C-Via
Origin
L
Locid
L5d-Success-Class
Location
NGX
PFcat
Machine
NM-Fastcgi-Cache
X-Amz-Meta-S3cmd-Attrs
X-Tb
X-APP-VERSION
X-Served-From
X-HS-Content-Campaign-Id
X-WADP-Cache
HostName
X-Fmm-Version
Fastly-Drupal-HTML
X-Goog-Meta-Goog-Reserved-File-Mtime
Rt-Fastcgi-Cache
Cmsid
X-Method
X-Servername
X-Loc
X-DC
X-Esi-Check
X-Gamma-Serve
X-Hash
X-LB-ID
Cmstype
X-Gzip
X-Aicache-OS
X-Slack-Backend
Kp-EeAlive
X-Cache-Id
X-Skip-Cache
X-Clara-WADP
X-Scheme
X-DynaTrace-JS-Agent
X-Varnish-Url
X-EC-Lua
X-Sucuri-ID
Svr
A
X-Unique-ID
X-JoinUs
X-NGENIX-Cache
X-CDN-Forward
X-SaId
X-PHP-Backend
X-NewRelic-App-Data
X-Ratelimit-Remaining
X-Air-Hostname
Pics-Label
M-TraceId
X-Edge-Location
X-Country-Code-Real
X-Mvc-Supplant-OutputCached
X-FTR-Realm
Viewtype
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Cache-Status
VivaBuild
X-Via-Poph
X-FTR-DC
X-Via-Popn
On-Server
X-FTR-Backend
X-Via-Popv
SID
X-PF-Uncompressing
Xc-Version
X-Swa-Ws
Cache-Key
Cross-Origin-Opener-Policy
Url
TDXMobile
Arc-Country
X-Refresh
X-NC
X-FTR-Expires
X-Vc
MIME-Version
X-Service
Instruction
Content-Secure-Policy
SR-User-Adfree
X-Cdn-Forward
X-Correlation-ID
X-Extlb
X-Internal-Host
X-Bc-Bl
Tracecode
X-CUA
DataCenter
X-Cache-Var-Map
X-Cache-Var
Sid
Server-ID
X-Servedbyhost
NtCoent-Length
X-Matched-Rule
Lfy
X-Cdn-Origin
X-NCache
X-Tb-Optimization-Total-Bytes-Saved
X-CLOUD-TRACE-CONTEXT
X-Forwarded-Site
X-Cache-Ttl
X-Sn-Servicetimems
X-Cache-Expires
CloudFront-Viewer-Country
X-Wa
X-TraceId
X-Proxy-Upstream
Memcached
LB
Pramga
X-Req
Surrogated-Key
Geo-Info
X-Cache-Backend
Hostname
X-Cache-Date
Mail-Subject
X-Accel-Expires-Debug
We-Hiring
X-VC-Cache
X-Date
Tcn
X-VCL-Version
X-Core-Mission
Source
X-LI-Proto
X-Webkit-CSP-Report-Only
Upgrade-Insecure-Requests
X-Rocket-Build-Number
X-App
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Srv
Env
GeoIp-Country-Code
X-Viewer-Country
Geoip-Latitude
X-Via-NSCOPI
X-Sigma-Backend
X-Request-Start
X-Sigma
FSS-Cache
X-Newrelic-Synthetics
X-B3-Spanid
X-Mg-Request-UUID
X-Zone
X-Men
X-HS-Status
X-Esi
X-MSEdge-Flight
X-Air-Source
X-MSEdge-Features
X-VHOST
CACHE
X-Error
GeoIP-Country-Code
X-PJAX-URL
X-FireWall-Protection
GeoIP-Latitude
X-HOST
CPC-Cache
Memory
CPC-Age
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-Li-Proto
VNS-Age
X-Hcs-Proxy-Type
Time
VNS-Cache
X-Varnish-Cacheable
Request-ID
X-Response-By
XServer
X-LiteSpeed-Cache-Control
X-Geo
S-Rt
X-Vcl-Version
X-RPS
X-Air-Trace-Id
My-App
X-DB
X-RSL
X-RPM
X-DW
X-DSS
State
X-DI
Server-Ttl
Fastcgi-Cache-TTL
X-TIM-N
CF-Cached-On
Resin-Trace
X-Cache-Type
X-ZONE
X-Cs
X-APP
X-Proxy-Cachei7
X-WA
Xkeyi7
X-BBXSRF
X-Minions-Version
X-Dynatrace-Js-Agent
X-RAMCache
X-Action
X-ServedByHost
HitType
N-Cache
X-HostName
X-Contensis-Viewer-Groups
X-Cache-2
X-FPC
X-Region-Sid
X-Cache-ASPX
OT-Force-Account-Verify
X-Oss-Cdn-Auth
ProcessTime
Server-Id
X-Varnish-Authentication
X-Swift-Error
X-Provided-By
X-ND-Cache
X-Depends-On
X-Orig-Expires
X-Cc-Via
W
Mime-Version
D-Cc-Upstream
X-Tenant
X-Svr
X-Shop-Environment
X-Cc-Req-Id
X-UA
X-FORWARDED-FOR
Cache-Provider
X-Dw-Trace-Id
X-Forwarded-Path
Srv
X-Cdn-Request-ID
X-Traceid
X-URL
WZWS-RAY
Datacenter
X-CSRF-TOKEN
X-UnsetCookies
CDN
X-TIME
X-Xrds-Location
X-ServerName
X-Cluster-Node
X-Client-Ip
X-ABtesting
X-Ftr-Request-Id
X-Flog
X-Cache-Config
X-Fastly-Request-Id
X-API-Version
X-Hello
X-Gdpr
X-CF-Powered-By
X-Origin-Time
X-Parent-Response-Time
X-ElasticPress-Search
X-Nyt-Route
Proxy-Connection
X-Server-IP
X-Pf-Uncompressing
X-Fpc
X-Akamai-Pragma-Client-IP
X-BACKEND-TTL
X-IN-APIGATEWAYSSL
X-Presslabs-Stats
X-BBC-Edge-Cache-Status
X-Pad
Vha6-Origin
X-Oracle-DMS-ECID
Cdn
X-Pjax-Url
X-NGINX-Cache
X-VC
X-Conf
Media-Length
X-IN-APIGATEWAY
Cteonnt-Length
X-Air-Pt
Cf-Ipcountry
X-SN
X-SD-PageType
X-Fastly-Backend-Reqs
Count-Hit
X-Via-PopH
X-Snapshot-Date
Dnion-Transfer-Encoding
X-NodeID
X-Check-Cacheable
Ohc-File-Size
Epwk-X-Cache
Cross-Origin-Window-Policy
X-Sucuri-Cache
X-BBC-Origin-Response-Status
PICS-Label
X-Via-PopV
X-Ckpd-Fst-Backend
X-LiteSpeed-Tag
X-Tx-Id
X-V-Cache
X-Via-PopN
X-Cache-Remote
Ohc-Cache-HIT
X-Yottaa-OS
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Acquia-Site
X-Akamai-ERRuleID
X-Acquia-Application-Trace
X-Vcache
X-Ms-Meta-Originalurl
X-Ms-Meta-Staticbatchstarttime
X-SB
X-Akamai-ERPolicy
X-Lb-Id
X-Aws-Lambda-Call-Status
Xet-Cookie
X-Auto-Login
Warning
X-Cache-Tag
X-Worker
X-Varnish-URL
X-Webstats-RespID
X-TH-Server
X-Ua
X-Ftr-Cache-Host
CountryCode
X-C
X-LSADC-Cache
X-ElasticPress-Query
X-Tid
X-Debug-Cache-Fetch
X-Debug-Cache-Store
NnCoection
Inserted-Into-Cache-At
X-B3-Parentspanid
EpKe-Alive
Phost
X-Erf-Stays-Bingo-Pdp-Web
X-MiniProfiler-Ids
Ohc-Response-Time
URI
X-Varnish-Beresp-TTL
X-Apw-Access-Object
X-Apw-Access-Token
X-Apw-Hits
X-Cache-Status-Check
X-Apw-Access-Action
Content-Style-Type
X-Amz-Meta-Cb-Modifiedtime
X-Request-URL
X-Litespeed-Cache-Control
Content-Script-Type
X-Mg-Request-Id