Threat Level: green Handler on Duty: Renato Marinho

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
Link
X-XSS-Protection
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-Served-By
X-UA-Compatible
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
X-Xss-Protection
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Request-ID
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Ua-Compatible
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Content-Encoding
X-CDN
Feature-Policy
X-AspNetMvc-Version
Status
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-Via
Upgrade
Access-Control-Max-Age
Keep-Alive
X-Ws-Request-Id
X-Age
X-Robots-Tag
X-AH-Environment
X-Turbo-Charged-By
Request-Context
EagleId
X-Proxy-Cache
X-Cache-Group
Server-Timing
X-Backend
X-Hacker
X-Server
Report-To
Host-Header
X-Amz-Request-Id
X-Server-Powered-By
X-Amz-Id-2
Grace
X-Nginx-Cache-Status
X-UA-Device
X-Rq
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
X-LiteSpeed-Cache
X-Page-Speed
Cf-Railgun
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
NEL
X-OneAgent-JS-Injection
X-Amz-Version-Id
X-Cache-Spec
X-WebKit-CSP
X-Device
X-CST
Allow
Xkey
X-Vhost
X-Host
X-Backend-Server
X-Server-Id
EagleEye-TraceId
Request-Id
Surrogate-Control
X-Dispatcher
X-Node
Content-Location
X-Response-Time
X-Akam-SW-Version
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Ruxit-JS-Agent
P3p
X-ASPNET-VERSION
Accept-CH
X-Ac
X-Application-Context
X-Cache-Lookup
X-Country
X-Template
X-Language
Accept-CH-Lifetime
Accept-Ch
X-Mod-Pagespeed
X-Readtime
Accept-Ch-Lifetime
X-Cloud-Trace-Context
MS-Author-Via
X-B3-TraceId
Rating
X-Origin-Cache
X-MS-InvokeApp
X-Cnection
X-HW
X-Url
X-PC
X-Vname
X-TtlSet
X-Clacks-Overhead
Edge-Control
X-GitHub-Request-Id
X-ESI
X-ORACLE-DMS-ECID
X-Trace
Pagespeed
Display
X-Middleton-Display
X-Sol
Response
X-Middleton-Response
X-Content-Type
X-D2id
X-ORACLE-DMS-RID
Arr-Disable-Session-Affinity
Verso
X-Kinja-Build
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Kinja
X-Vcap-Request-Id
X-Exp-Variant
X-Cdn-Fetch
X-GoogleNews-Bot
X-Exp-Id
X-Goog-Hash
X-Rack-Cache
X-Country-Code
X-Buckets
X-FastCGI-Cache
X-Varnish-TTL
X-Server-Name
X-Navigation-Version
X-Oneagent-Js-Injection
Service-Worker-Allowed
X-Powered-By-Plesk
X-VARITI-CCR
X-Abt-Application-Version
X-Amz-Rid
X-Fastly-Request-ID
X-Webkit-CSP
X-Client-IP
X-Cache-TTL
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
Fastly-Restarts
X-SharePointHealthScore
SPRequestGuid
X-MSEdge-Ref
X-Cached
X-Release
X-TTL
X-Element-Page-Cache
X-Dw-Request-Base-Id
X-NF-Request-ID
SPRequestDuration
SPIisLatency
Public-Key-Pins
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
RTSS
Access-Control-Request-Method
AR-ATIME
X-SRCache-Store-Status
X-SRCache-Fetch-Status
AR-CACHE
AR-Request-ID
Ar-Sid
AR-PoweredBy
X-Edge
X-LLID
X-Powered-CMS
X-Litespeed-Cache
X-Ezoic-Cdn
X-Origin-Upstream-Status
Cache-Tag
Content-MD5
X-Upstream
Fusion-Content-Id
Fusion-Deployment-Id
Fusion-Source
Fusion-Template-Id
Fusion-Component-Id
Fusion-Content-Source
X-Px
X-HP-Webp
X-Jurisdiction
X-Ttl
S
X-ECACHE
X-Version
X-Mid
X-Recruiting
X-MCACHE
X-Mg-S
Charset
X-Content-Digest
X-PressLabs-Stats
X-Amz-Server-Side-Encryption
Fastcgi-Cache
X-T
X-Kinsta-Cache
Cache-Tags
MicrosoftSharePointTeamServices
X-Id
Filters
Front-End-Https
X-Content-Security-Policy-Report-Only
X-DynaTrace
X-Logged-In
TCN
Server-Node
X-Debug
X-Accel-Expires
Edge-Cache-Tag
X-Grace
X-Forwarded-Proto
X-Forwarded-For
X-Correlation-Id
TP-Cache
TP-L2-Cache
Server-Name
Nginx-Cache
X-Pinterest-Direct
X-Amzn-Trace-Id
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Surrogate-Key
X-Request-Processing-Time
X-XRDS-LOCATION
X-Request-Received
X-Varnish-Age
X-Yandex-Sdch-Disable
X-B3-Sampled
X-Ser
X-Request-Handler-Origin-Region
X-Microsite
X-Shield-Request-Id
X-Hits
X-Az
X-Activity-Id
X-AppVersion
X-Amz-Replication-Status
X-Ruxit-Js-Agent
X-Fastcgi-Cache
X-F-Cache
X-DIS-Request-ID
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Combine-CSS
X-HS-Cache-Config
X-Goog-Generation
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Metageneration
X-Origin-Server
Accept-Charset
X-Geo-Country
X-Git-Hash
Alternate-Protocol
X-XRDS-Location
X-Respond-Thread
Cache
X-Rid
X-FTR-Request-ID
X-Time
Section-Io-Cache
X-Frontend
Host
X-Cache-Key
X-LB-Cache
X-Upgrade-Enabled
X-DataDome
Powered-By-ChinaCache
X-Mobile-URL
X-Seen-By
Access-Control-Allow-Method
MS-CV
X-NWS-LOG-UUID
X-Server-ID
X-VCache
Paypal-Debug-Id
X-Cache-Age
X-IPLB-Instance
X-AOL-HN
ServerID
X-Varnish-Backend
X-Type
X-TT
Cleartype
X-Content-Options
Healthy
X-Providence-Cookie
X-Request-Guid
Payment
X-App-Environment
X-Whom
X-Is-Crawler
X-Aspnet-Duration-Ms
X-Hostname
X-Route-Name
X-Flags
X-Signature
X-Cache-Action
X-B-Cache
X-Jobs
X-Source
X-Page-Id
Fastcgi-Useragent
X-Debug-Info
X-WebKit-CSP-Report-Only
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Load-Cache
X-Daa-Tunnel
X-N
X-Mobile
X-FB-Debug
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
Nel
X-Via-JSL
X-RateLimit-Remaining
Realpath
X-Contextid
Refresh
Version
X-Response-Served-From
X-Accel-Buffering
Node
X-Wix-Request-Id
X-Rule
X-Cached-By
X-Original-Request-Id
X-Zen-Fury
X-Drupal-Cache-Tags
DC
Ms-Operation-Id
X-Proxy
X-Akamai-Edgescape
X-Cacheable-TTL
X-RTag
X-Cache-Operation
X-Framework
Viewport
X-Cache-Rule
X-HTML-Minification-Powered-By
X-B
X-ProcessESI
Referer-Policy
X-RemovedCookies
Access-Control-Request-Headers
X-Instance
X-Real-IP
X-Distributor
X-Cache-Time
X-Page-View
Eomportal-Instance
X-UUID
X-Drupal-Cache-Contexts
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Region
X-Cache-Expired-At
VIX-Pulpo-Upstream-Status
X-Cluster-Name
X-FW-Static
X-Content-Powered-By
Liferay-Portal
X-FW-Server
VIX-Pulpo-Node
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-FW-Serve
X-FW-Type
X-Cache-Control
Countrycode
X-FW-Dynamic
X-FW-Hash
X-IPS-LoggedIn
X-Cache-Hit
X-L-Path
DynaTrace
X-Environment-Context
X-G
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Tumblr-User
X-Pass-Why
X-FireWall-Port
Server-Info
X-App-Server
X-Varnish-Ttl
X-Ratelimit-Limit
X-User-Agent
Xserver
GEO-INFO
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Origin-Responded
Webserver
X-Tumblr-Pixel-2
Section-Io-Id
X-Protected-By
Ec-Rule-Version
From-Origin
CF-IPCountry
X-Node-Name
X-Ratelimit-Remaining
SRV
X-Www-Served-By
Protected
X-Cache-Server
X-Nginx-Cache
Meta-Geo
X-Hl-Ver
X-UPSTREAM-Address
X-ES-SERVER
X-RN-RSRV
X-Backend-Name
X-Endurance-Cache-Level
X-Handled-By
X-Mode
X-Site-Version
Cache-Tv-Group
X-Uri
X-FB-TRIP-ID
Frame-Options
X-Locale
X-Labrador-Cache-Channel
X-PHP-Host
Cache-Status
X-Varnishpool
X-Debug-IsConnected
X-Device-Type
X-NYM-Debug-Backend
X-Debug-IsPreview
X-Be
X-Storage
X-MP-GENERATED-AT
X-WA-Info
X-Sql-Count
Selected-Fe
X-Request-Time
X-Proxy-Build
X-ProxyCache-Key
X-Redis-Cache
Webcakes-App-Name
X-No-Session
X-Web-Node
X-ProxyCache-Status
TWC-GeoIP-Country
Property-Id
TWC-Device-Class
X-Pubstack
Fastly-SSL
TWC-Privacy
TWC-Locale-Group
TWC-GeoIP-LatLong
X-Human
TWC-Connection-Speed
Webcakes-Region
X-Proto
X-Hyper-Cache
X-Sql-Duration-Ms
Decoy-Debug-TTL
X-Adobe-Loc
X-Soup
X-OCL
X-Origin-Hint
X-PCL
X-Timing-Wait
Cache-Name
X-Via-Fastly
Webcakes-App-Version
Decoy-Debug-Status
X-BYPASS-REASON
Decoy-Debug-Key
X-UA-Device-Type
X-Adobe-Content
Country
Azure-RegionName
Azure-SiteName
Azure-Version
X-LAGOON
Retry-After
X-LJ-Flow-ID
Azure-SlotName
X-S-Maxage
X-Server-W
X-TNCMS
X-Section
X-Access
Azure-InstanceId
X-Cache-Grace
X-AIR-PT
X-Origin-Date
X-Format
X-Forwarded-Host
X-Hosted-By
X-R9-Blue-Green-Version
X-FW-Version
X-Say-Cacheable
X-Say-TTL
X-SayCDN-TTL
X-VWS-Id
X-Loop
X-AWS-Id
X-Revision
X-Storefront-Renderer-Rendered
X-Status
X-Cache-TTL-Remaining
X-TT-LOGID
X-Xfnlog-Site
X-Alternate-Cache-Key
X-ApacheServer
X-Sorting-Hat-ShopId
X-ShopId
X-ShardId
X-Shopify-Stage
X-PERF
X-Cluster
X-Sorting-Hat-PodId
X-CCM
Mn-Server-Ip
X-Zipkin-Id
X-Routing-Service
X-Proxied
AMP-Access-Control-Allow-Source-Origin
X-Is-Bot
X-Qloud-Router
Apigw-Requestid
X-Rendered-As
X-Amz-Meta-S3cmd-Attrs
X-Varnish-Grace
X-Dc
X-SRV
X-Varnish-Server
X-Info
S-Cnection
X-FTR-Balancer
X-Tec-Api-Version
X-Tec-Api-Origin
X-FTR-Backend
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Backend-Server
X-FTR-Realm
X-FTR-DC
X-Tec-Api-Root
X-Via-CDN
X-Cdn
Cache-Hits
X-Cache-Enabled
X-Microcachable
X-GG-Cache-Date
X-Content-Age
X-Detected-As
X-Platform
X-FTR-Expires
X-Cache-Host
X-Amzn-Remapped-Content-Length
Uber-Trace-Id
X-Proxy-Cache-Status
X-Aspnetmvc-Version
X-Amz-Apigw-Id
X-EdgeConnect-Cache-Status
X-Amzn-RequestId
X-Azure-Ref
X-Backend-Host
X-CSRF-Token
X-NWS-UUID-VERIFY
Tracecode
X-Air-Hostname
X-App-Version
SD-X-WS
X-Cache-Var
X-Cache-Var-Map
Amp-Access-Control-Allow-Source-Origin
X-Time-Microsecs
Akamai-GRN
X-Oss-Storage-Class
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-DynaTrace-JS-Agent
X-Oss-Object-Type
X-ServerID
HostName
X-ATG-Version
X-Backend-TTL
X-Tb
X-Unique-Id
X-Trace-Id
X-Correlation-ID
X-Debug-Cache
X-RCS-CacheZone
ServedBy
X-BCube-Filmed-By
Backend
X-Varnish-Hostname
X-Cdn-Forward
X-Cache-NGX
X-Cache-PHP
X-GEO
X-Sucuri-ID
X-Akamai-Transformed
X-Cache-Backend
X-B3-SpanId
X-Origin-TTL
X-Vtex-Remote-Cache
X-Processor
X-Vtex-Processado-Em
X-CS
Path
X-PBS-Appsvrname
Odigeo-Trace-Id
Mobile-Detection-Method
X-Owner
X-PAYTM-SRV-ID
X-From
Fastcgi-X-Cache-Version
DCR-Processing-Time-Ms
Expiry
X-Ms-Version
DCR-Decision-By
X-Location
X-TX-ID
BehaviorPad-Version
X-Level-Front-Cache
X-Ms-Request-Id
X-NAPM-TraceId
X-Origin-CC
Machine
MD5-Digest
Instruction
X-Cache-NE
X-Generation-Time
X-Generated-On
Meta-Geo-Continent
X-VG-WebCache
X-VG-WebServer
X-Session-Fingerprint
X-Destination
X-Trv-Group
X-TA-CDN-Provider
X-Connection-Hash
X-ScT
T-Server
X-B-Cookie
X-ARC
X-D
X-A-Dgt
X-A-Wwc
X-Aed
X-Application
X-A-Dcw
X-SRCache-Key
X-A
X-A-Ccd
X-A-Dam
SR-User-Adfree
X-Vdms-Path
X-Vdms-Version
X-Request-UUID
X-CF-Lambda-Version
Rendered-Blocks
X-External-Request-Id
X-CF-Lambda-Fn
X-Rewrite-Enabled
Xc-Version
X-Rojux
DB-Nickname
X-S
X-S-Cookie
DSUID
X-CACHE-KEY
AKAMAI
X-Has-Esi
Arc-Version
X-Bip
X-Cms-Context
X-Geo-Header
Content-Disposition
X-GeoIP-City
C-Via
CacheControlHeader
X-Cache-Bucket
Gh-Request-Id
X-FC-Vary-Parameters
X-Fetched-On
On-Server
Release
X-Fastly-Cache
PB-PID
PB-RID
Pagetype
Server-Host
X-Device-Os
Host-ID
Fastly-Backend-Name
UCS
Lfy
Thinkindot-Control
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-Core-Value
X-Irp-Debug
X-Thinkindot-L3
X-TrackingId
X-OVcl
X-OVcl-Cache
X-Thanos
X-Matched-Rule
X-Skip-Cache
X-Varnish-Cache-Hits
X-Mvc-Supplant-Cachable
X-Micro-Cache
X-B3-Traceid
X-Tumblr-Pixel-3
X-Is-Gdpr
X-HS-Content-Campaign-Id
X-NewRelic-App-Data
X-JWT-State
X-Magnolia-Registration
X-Reqid
User-Cache-Control
X-DefElseHash
X-Scheme
X-Rebelmouse-Surrogate-Control
Ssr
X-Varnish-Remaining-TTL
PFcat
X-DefHash
X-VarnishDD-TTL
X-Dispatcher-Server
X-Fastly-Backend
V-Age
X-Esi-Check
X-Request-Host
X-Envoy-Decorator-Operation
X-DPWN-IS-SECURE
Platform
X-Developers
X-Eu-Site
X-Developer
X-CUA
X-Var-Ttl
X-Block-Status
X-Clara-WADP
X-Clientip
X-EC-Lua
X-Branch-Name
X-CGP
X-Cache-Id
X-Cache-Info
X-Variation
X-Cache-Tags
X-Varnish-Beresp-Grace
X-Backend-State
X-Azure-Ref-OriginShield
Wxu-Next-Region
X-Rebelmouse-Cache-Control
Wxu-Next-Hostname
Wxu-Next-Commit
Web-Mar-Node
X-Varnish-CookieHashed-On
X-SVT-ORM-RULES
X-Csrf-Jwt
X-Swa-Ws
X-Adobe-Source
X-SVT-ORM-VERSION
X-Varnish-CookieINHashed-On
X-Ratelimit-Reset
CloudFront-Viewer-Country
X-Li-Pop
Cf-Device-Type
X-GoCache-CacheStatus
CDN-Uid
X-LI-UUID
X-GeoIP
X-Wikidot-Static-Cache
X-Generated-In
Fastly-SWR
X-Hnp-Log
X-Node-Id
CDN-RequestId
CDN-RequestCountryCode
X-Gzip
Cache-Host
X-IP
X-HN
Adler-Geo
X-Li-Fabric
CDCHOST
CDN-PullZone
CDN-EdgeStorageId
CDN-CachedAt
CDN-Cache
X-NU-AKA-ACS-Version
Fastly-SIE
X-Generated-By
X-Fmm-Version
NGX
X-Gen-Mode
L5d-Success-Class
Ha-Gx-Prefs
Location
X-Wikidot-Backend
Is-Eu
X-WADP-Cache
X-Origin
X-Old-Content-Length
HA-Ipaddr
X-VServer
X-Policy
Magicmarker
X-Platform-Server
X-Origin-Response-Time
NM-Fastcgi-Cache
X-ID
X-APP-VERSION
X-Hash
X-Cdn-Origin
X-Varnish-Beresp-Status
X-LB-ID
X-VG-TLSProxy
X-Slack-Backend
X-Nginx-Cache-Key
X-Varnish-Hits
X-SIPLIST1
X-Sn-Servicetimems
X-Method
X-Request-URI
X-User
X-Gamma-Serve
X-Varnish-Beresp-Ttl
X-Origin-Expires
X-Cache-Expires
X-Kinja-Server-Push
Vix-Hermes-Req-Id
Server-Hostname
Cf-Bgj
True-Client-Country-4JS
Sever-Int
Rt-Fastcgi-Cache
Server-Ext
Pramga
Locid
X-Cache-Debug
L
IsBot
X-CLOUD-TRACE-CONTEXT
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
X-Goog-Meta-Goog-Reserved-File-Mtime
Fastly-Drupal-HTML
X-Aicache-OS
X-Cache-Date
Apple-News-Services-Host
Apple-News-Services-Handled
Origin
X-Nc
X-Via-Popv
Esi-Enabled
X-Via-Popn
X-PF-Uncompressing
X-Loc
X-Mvc-Supplant-OutputCached
X-NCache
X-Servername
X-Unique-ID
X-Via-Poph
X-Core-Mission
X-Erf-Stays-Bingo-Pdp-Web
Sid
X-Request-Start
Who
X-Varnish-Url
X-Refresh
Country-Code
Geo-Info
Pics-Label
Url
X-Epic-Correlation-Id
X-Tb-Optimization-Total-Bytes-Saved
X-FireWall-Protection
X-Cache-Remote
X-NC
X-Planisys-CDN-Cache
X-Response-By
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
Req-Svc-Chain
X-Dynatrace
X-Varnish-Cacheable
X-TraceId
X-RateLimit-Limit
X-Webkit-Csp
X-Proxy-Cachei7
Xkeyi7
X-Error
S-Rt
N-Cache
Content-Secure-Policy
X-BBXSRF
Cmstype
Cmsid
Source
Filterid
X-B3-Spanid
X-Webkit-CSP-Report-Only
X-Srv
Svr
X-Served-From
Kp-EeAlive
HitType
X-DC
X-Cache-2
X-Host-Name
Server-Ttl
X-HS-Status
GeoIp-Country-Code
Geoip-Latitude
Cross-Origin-Window-Policy
X-Sucuri-Cache
X-Cc-Req-Id
Cache-Key
Tcn
X-LiteSpeed-Cache-Control
A
Viewtype
VivaBuild
D-Cc-Upstream
X-Cache-ASPX
X-Contensis-Viewer-Groups
X-Cc-Via
MIME-Version
X-Varnish-Authentication
X-Vcl-Version
Cteonnt-Length
Ohc-File-Size
X-URL
X-Wa
M-TraceId
X-Servedbyhost
X-HostName
X-Svr
X-Oracle-Dms-Rid
X-Air-Source
X-Server-IP
Server-ID
X-Li-Proto
X-Esi
Cross-Origin-Opener-Policy
Arc-Country
NGB
CACHE
SID
NtCoent-Length
X-CDN-Forward
X-Origin-Time
X-Gdpr
X-LI-Proto
X-Nyt-Route
X-Vgn-Hpd-Reason
X-FPC
TDXMobile
X-API-Version
X-Cache-Config
X-RAMCache
X-HOST
X-Cs
X-ServedByHost
X-Vc
X-Check-Cacheable
Request-ID
Resin-Trace
X-VC
X-SN
X-WA
X-Geo
X-UA
X-Viewer-Country
Cache-Provider
X-Webstats-RespID
Server-Id
X-DSS
X-CCDN-CacheTTL
X-SB
X-RSL
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-Newrelic-Synthetics
X-Service
X-TIM-N
X-RPM
X-RPS
X-Internal-Host
X-VCL-Version
X-DI
X-DB
X-DW
X-NodeID
Ohc-Cache-HIT
Hostname
X-SaId
X-PHP-Backend
X-NGENIX-Cache
X-JoinUs
DataCenter
GeoIP-Country-Code
Mime-Version
GeoIP-Latitude
X-SD-PageType
Srv
X-Edge-Location
XServer
X-NGINX-Cache
X-Forwarded-Site
X-Extlb
FSS-Cache
X-Render-Time
X-BBC-Edge-Cache-Status
ProcessTime
X-Action
X-App
CF-Cached-On
X-FTR-Cache-Host
X-CF-Powered-By
X-Fpc
X-Via-NSCOPI
X-Oss-Cdn-Auth
EpKe-Alive
X-Provided-By
X-Ua
X-Bc-Bl
X-Dynatrace-Js-Agent
X-FORWARDED-FOR
Processtime
X-Worker
Mail-Subject
X-Proxy-Upstream
X-PJAX-URL
X-Depends-On
X-Region-Sid
X-Req
Upgrade-Insecure-Requests
X-VC-Cache
X-Date
X-Accel-Expires-Debug
X-Auto-Login
LB
W
Memcached
Surrogated-Key
We-Hiring
X-HITS
X-Cdn-Request-ID
X-Swift-Error
X-CSRF-TOKEN
X-RateLimit-Remaining-Second
X-UnsetCookies
Env
X-APP
X-RateLimit-Limit-Second
X-MSEdge-Flight
X-BACKEND-TTL
CDN
X-MSEdge-Features
X-Ftr-Cache-Host
X-Cluster-Node
X-Fastly-Backend-Reqs
X-ZONE
X-Dw-Trace-Id
Proxy-Connection
X-TIME
Cdn
X-CACHE-AGE
X-Client-Ip
Datacenter
X-ABtesting
X-Cache-Tag
X-IN-APIGATEWAYSSL
X-Men
Time
Memory
X-Flog
X-Air-Trace-Id
PICS-Label
X-Parent-Response-Time
X-Fastly-Request-Id
X-IN-APIGATEWAY
X-BBC-Origin-Response-Status
X-Sigma-Backend
X-Hello
X-Rocket-Build-Number
X-Sigma
Dnion-Transfer-Encoding
X-Akamai-Pragma-Client-IP
Media-Length
X-Acquia-Site
CPC-Cache
X-Presslabs-Stats
Vha6-Origin
X-Pf-Uncompressing
VNS-Cache
X-Pad
CPC-Age
VNS-Age
X-Zone
X-Acquia-Purge-Tags
X-Acquia-Application-Trace
X-Oracle-DMS-ECID
X-Acquia-Application-UUID
OT-Force-Account-Verify
Epwk-X-Cache
X-Via-PopN
X-Via-PopV
X-LiteSpeed-Tag
X-Via-PopH
Cf-Ipcountry
X-ND-Cache
X-MiniProfiler-Ids
X-ElasticPress-Query
X-Snapshot-Date
WZWS-RAY
X-Request-Url
X-Varnish-Beresp-TTL
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-ElasticPress-Search
X-Ms-Meta-Originalurl
X-Ms-Meta-Staticbatchstarttime
X-Varnish-URL
X-ServerName
X-Lb-Id
Xet-Cookie
X-Vcache
X-Request-URL
X-Csrf-Token
CountryCode
My-App
State
Content-Script-Type
X-Litespeed-Cache-Control
X-Amz-Meta-Cb-Modifiedtime
Content-Style-Type
Fastcgi-Cache-TTL
Ohc-Response-Time
Environment
NnCoection
X-Redis-Count
X-Redis-Duration-Ms
X-Traceid
URI
X-B3-Parentspanid
X-Storefront-Renderer-Verified
X-C
Inserted-Into-Cache-At
X-Debug-Cache-Store
X-Debug-Cache-Fetch
Phost
X-Tid