Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-RAY
CF-Cache-Status
X-XSS-Protection
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-UA-Compatible
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Request-ID
X-Xss-Protection
X-Cache-Status
X-DNS-Prefetch-Control
X-Generator
X-Cacheable
X-Ua-Compatible
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Content-Encoding
X-CDN
X-AspNetMvc-Version
Feature-Policy
X-Envoy-Upstream-Service-Time
Status
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Upgrade
X-Via
Access-Control-Max-Age
Keep-Alive
X-Ws-Request-Id
X-Age
X-Turbo-Charged-By
X-Robots-Tag
X-AH-Environment
Request-Context
X-Proxy-Cache
EagleId
X-Cache-Group
Server-Timing
X-Backend
X-Hacker
X-Server
Report-To
X-Amz-Request-Id
Host-Header
X-Server-Powered-By
X-Amz-Id-2
Grace
X-Nginx-Cache-Status
X-UA-Device
X-Rq
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Page-Speed
Cf-Railgun
X-Pingback
X-OneAgent-JS-Injection
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
NEL
X-Amz-Version-Id
X-Cache-Spec
X-Dns-Prefetch-Control
X-WebKit-CSP
X-Device
X-CST
Allow
Xkey
X-Vhost
X-Backend-Server
X-Host
X-Server-Id
EagleEye-TraceId
Request-Id
Surrogate-Control
X-Dispatcher
X-Node
Content-Location
X-Response-Time
X-Ruxit-JS-Agent
X-Akam-SW-Version
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Accept-CH
Accept-CH-Lifetime
P3p
X-Ac
X-ASPNET-VERSION
X-Application-Context
X-Template
X-Country
X-Language
X-Cache-Lookup
X-Mod-Pagespeed
X-Readtime
MS-Author-Via
X-Cloud-Trace-Context
X-B3-TraceId
Accept-Ch
Rating
X-Origin-Cache
Accept-Ch-Lifetime
X-Cnection
X-HW
X-MS-InvokeApp
X-Url
X-TtlSet
X-Vname
X-PC
X-Clacks-Overhead
X-GitHub-Request-Id
Edge-Control
X-ESI
X-ORACLE-DMS-ECID
X-Trace
X-Content-Type
Response
Pagespeed
Display
X-Middleton-Display
X-Middleton-Response
X-Sol
X-D2id
X-FastCGI-Cache
X-Kinja-Server
X-Kinja
X-Kinja-Build
X-Kinja-Revision
X-GoogleNews-Bot
X-Cdn-Fetch
X-Exp-Variant
X-Exp-Id
Arr-Disable-Session-Affinity
X-Use-Magma
Verso
X-Vcap-Request-Id
X-ORACLE-DMS-RID
X-Goog-Hash
X-Buckets
X-Rack-Cache
X-Country-Code
X-Server-Name
X-Varnish-TTL
X-Navigation-Version
Service-Worker-Allowed
X-VARITI-CCR
X-Abt-Application-Version
X-Powered-By-Plesk
X-Amz-Rid
X-Fastly-Request-ID
X-Client-IP
X-Cache-TTL
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-Webkit-CSP
X-TTL
Fastly-Restarts
X-Release
X-MSEdge-Ref
X-SharePointHealthScore
SPRequestGuid
X-Dw-Request-Base-Id
X-Element-Page-Cache
X-Cached
SPRequestDuration
SPIisLatency
X-NF-Request-ID
X-Oneagent-Js-Injection
Public-Key-Pins
RTSS
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
Access-Control-Request-Method
AR-CACHE
X-SRCache-Store-Status
AR-PoweredBy
AR-Request-ID
Ar-Sid
X-SRCache-Fetch-Status
AR-ATIME
X-Edge
X-Powered-CMS
X-LLID
X-Origin-Upstream-Status
X-Ezoic-Cdn
X-Upstream
Cache-Tag
Content-MD5
X-Litespeed-Cache
Fusion-Content-Id
Fusion-Template-Id
Fusion-Component-Id
Fusion-Source
Fusion-Deployment-Id
Fusion-Content-Source
X-Px
X-HP-Webp
X-Jurisdiction
X-ECACHE
X-MCACHE
X-Version
X-Mid
S
X-Mg-S
X-Recruiting
Charset
X-Ttl
X-Content-Digest
X-PressLabs-Stats
X-Amz-Server-Side-Encryption
Fastcgi-Cache
X-Kinsta-Cache
X-T
X-Id
MicrosoftSharePointTeamServices
Cache-Tags
X-Content-Security-Policy-Report-Only
Front-End-Https
Filters
TCN
X-Debug
X-Grace
X-Logged-In
X-Accel-Expires
Edge-Cache-Tag
Server-Node
X-DynaTrace
X-Forwarded-Proto
X-Pinterest-Direct
X-Forwarded-For
Server-Name
TP-L2-Cache
X-XRDS-LOCATION
TP-Cache
X-Amzn-Trace-Id
Nginx-Cache
X-Correlation-Id
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Surrogate-Key
X-Request-Received
X-Request-Processing-Time
X-Varnish-Age
X-Yandex-Sdch-Disable
X-B3-Sampled
X-Shield-Request-Id
X-Request-Handler-Origin-Region
X-Microsite
X-Ser
X-Hits
X-AppVersion
X-Activity-Id
X-Az
X-Amz-Replication-Status
X-DIS-Request-ID
X-F-Cache
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Combine-CSS
X-HS-Cache-Config
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Kinja-Server-Push
X-Origin-Server
Accept-Charset
X-Geo-Country
X-Git-Hash
X-Cache-Key
Cache
X-Respond-Thread
Alternate-Protocol
X-Rid
X-FTR-Request-ID
X-LB-Cache
X-Frontend
X-XRDS-Location
Section-Io-Cache
Powered-By-ChinaCache
X-DataDome
Host
X-Upgrade-Enabled
X-Fastcgi-Cache
Access-Control-Allow-Method
X-Mobile-URL
X-Seen-By
X-Cache-Age
MS-CV
Paypal-Debug-Id
Healthy
X-VCache
X-Time
X-AOL-HN
Cleartype
X-NWS-LOG-UUID
X-Hostname
X-Varnish-Backend
X-Whom
X-TT
X-IPLB-Instance
X-Ruxit-Js-Agent
X-Type
ServerID
X-Content-Options
X-App-Environment
X-Route-Name
X-Request-Guid
X-Providence-Cookie
X-Is-Crawler
X-Flags
X-Server-ID
X-Aspnet-Duration-Ms
X-B-Cache
Payment
X-Jobs
X-Page-Id
X-Signature
X-Cache-Action
X-WebKit-CSP-Report-Only
X-Source
Fastcgi-Useragent
X-Debug-Info
X-Load-Cache
X-N
X-Daa-Tunnel
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Mobile
X-FB-Debug
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Via-JSL
Refresh
Nel
Version
X-Akamai-Edgescape
X-Cached-By
X-Contextid
X-Rule
X-Response-Served-From
X-Original-Request-Id
X-Accel-Buffering
Realpath
X-Wix-Request-Id
Node
X-Framework
X-Drupal-Cache-Tags
X-Proxy
X-Cacheable-TTL
DC
Viewport
X-RTag
X-ProcessESI
Ms-Operation-Id
X-RemovedCookies
X-Cache-Operation
X-Cache-Rule
X-RateLimit-Remaining
Access-Control-Request-Headers
X-Cache-Time
X-B
X-Instance
X-Zen-Fury
X-Real-IP
X-Region
X-HTML-Minification-Powered-By
X-Distributor
X-Page-View
Eomportal-Instance
Referer-Policy
X-Drupal-Cache-Contexts
X-UUID
X-Yottaa-Metrics
X-FW-Server
VIX-Pulpo-Upstream-Status
X-FW-Static
X-Cluster-Name
Countrycode
VIX-Pulpo-Node
X-Yottaa-Optimizations
X-Cache-Expired-At
X-FW-Dynamic
X-FW-Hash
X-FW-Type
X-FW-Serve
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Cache-Control
X-Content-Powered-By
X-G
X-IPS-LoggedIn
DynaTrace
X-Cache-Hit
X-Tumblr-User
X-Tumblr-Pixel-0
X-L-Path
X-Environment-Context
X-Tumblr-Pixel
X-Tumblr-Pixel-1
Liferay-Portal
GEO-INFO
X-Ratelimit-Limit
Server-Info
X-FireWall-Port
X-App-Server
X-Pass-Why
X-User-Agent
Ec-Rule-Version
Xserver
From-Origin
X-Varnish-Ttl
X-Tumblr-Pixel-2
Webserver
X-Node-Name
X-Protected-By
Section-Origin-Responded
X-Ratelimit-Remaining
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Io-Id
CF-IPCountry
Protected
X-Www-Served-By
SRV
X-Cache-Server
X-Backend-Name
X-Mode
X-UPSTREAM-Address
Meta-Geo
X-RN-RSRV
Frame-Options
X-Handled-By
X-ES-SERVER
X-Hl-Ver
X-FB-TRIP-ID
X-Site-Version
X-Endurance-Cache-Level
Cache-Tv-Group
X-Locale
Cache-Status
X-Labrador-Cache-Channel
X-Nginx-Cache
X-Soup
X-Storage
X-Uri
X-PHP-Host
X-Varnishpool
X-NYM-Debug-Backend
X-Be
X-Hyper-Cache
X-Web-Node
X-UA-Device-Type
X-Proto
TWC-Locale-Group
TWC-Privacy
X-Origin-Hint
Decoy-Debug-TTL
X-Origin-Date
TWC-GeoIP-LatLong
TWC-GeoIP-Country
X-Timing-Wait
X-Adobe-Content
X-MP-GENERATED-AT
X-Adobe-Loc
Property-Id
TWC-Device-Class
Fastly-SSL
X-Revision
Webcakes-App-Version
Decoy-Debug-Key
X-Proxy-Build
X-Pubstack
X-Redis-Cache
Webcakes-Region
Decoy-Debug-Status
X-Human
TWC-Connection-Speed
Cache-Name
Country
Webcakes-App-Name
Selected-Fe
Azure-RegionName
Azure-SlotName
Azure-InstanceId
Azure-SiteName
X-S-Maxage
X-Say-Cacheable
X-Server-W
X-Section
X-SayCDN-TTL
X-Say-TTL
Azure-Version
X-Sql-Count
X-AIR-PT
X-Format
X-Access
X-Amz-Meta-S3cmd-Attrs
X-ProxyCache-Status
X-Request-Time
X-Sql-Duration-Ms
X-Hosted-By
X-FW-Version
X-Forwarded-Host
X-WA-Info
X-Via-Fastly
X-Cache-Grace
X-PCL
X-ProxyCache-Key
X-TNCMS
Retry-After
X-No-Session
X-OCL
X-Loop
X-BYPASS-REASON
X-Cluster
X-Debug-IsConnected
X-Debug-IsPreview
X-VWS-Id
X-AWS-Id
X-LJ-Flow-ID
X-Status
X-LAGOON
X-Device-Type
X-PERF
X-ApacheServer
X-TT-LOGID
Mn-Server-Ip
X-Shopify-Stage
X-Alternate-Cache-Key
X-R9-Blue-Green-Version
X-ShopId
X-Sorting-Hat-PodId
X-Storefront-Renderer-Rendered
X-Sorting-Hat-ShopId
X-ShardId
X-Tec-Api-Origin
X-Zipkin-Id
X-Tec-Api-Root
X-Tec-Api-Version
X-Cache-TTL-Remaining
X-Routing-Service
X-Proxied
X-Rendered-As
X-Is-Bot
X-CCM
X-Xfnlog-Site
X-Varnish-Grace
X-Qloud-Router
X-Dc
Apigw-Requestid
X-Varnish-Server
X-Info
X-SRV
S-Cnection
X-Country-Code-Real
X-Via-CDN
X-FTR-Backend
X-FTR-DC
X-FTR-Backend-Server
X-FTR-Cache-Status
X-FTR-Balancer
Cache-Hits
X-FTR-Realm
AMP-Access-Control-Allow-Source-Origin
X-Cache-Enabled
X-FTR-Expires
X-Detected-As
X-Content-Age
X-Cdn
X-Platform
X-Microcachable
X-Cache-Host
X-GG-Cache-Date
X-Amzn-RequestId
X-Amz-Apigw-Id
Uber-Trace-Id
X-EdgeConnect-Cache-Status
X-Amzn-Remapped-Content-Length
X-Air-Hostname
X-Azure-Ref
X-CSRF-Token
X-Backend-Host
X-Proxy-Cache-Status
X-Correlation-ID
X-Aspnetmvc-Version
X-Unique-Id
Tracecode
Amp-Access-Control-Allow-Source-Origin
X-Cache-Var
X-Cache-Var-Map
SD-X-WS
X-DynaTrace-JS-Agent
X-Time-Microsecs
X-NWS-UUID-VERIFY
Akamai-GRN
X-Backend-TTL
X-GEO
X-ServerID
X-ATG-Version
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
X-Tb
X-Oss-Request-Id
X-Oss-Object-Type
X-Trace-Id
Backend
HostName
ServedBy
X-BCube-Filmed-By
X-RCS-CacheZone
X-Cache-Backend
X-Cache-NGX
X-Cache-PHP
X-Varnish-Hostname
X-APP-VERSION
DSUID
X-Akamai-Transformed
X-App-Version
X-Debug-Cache
X-Connection-Hash
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Fetched-On
X-Generated-On
X-Generation-Time
X-From
X-External-Request-Id
X-Destination
X-Device-Os
X-D
X-Aed
Thinkindot-Control
Path
X-A
X-A-Ccd
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
Release
SR-User-Adfree
T-Server
X-A-Dam
X-A-Dcw
X-B-Cookie
X-Magnolia-Registration
Odigeo-Trace-Id
X-ARC
X-Application
X-A-Dgt
X-A-Wwc
Mobile-Detection-Method
X-Cache-NE
Instruction
DB-Nickname
X-SRCache-Key
Fastcgi-X-Cache-Version
Expiry
X-Session-Fingerprint
X-ScT
X-Rojux
X-S
X-GeoIP-City
DCR-Processing-Time-Ms
X-Thinkindot-L3
X-VG-WebServer
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-VG-WebCache
X-Vdms-Version
DCR-Decision-By
X-Trv-Group
X-Vdms-Path
X-Rewrite-Enabled
X-S-Cookie
X-Matched-Rule
X-Request-UUID
Lfy
Rendered-Blocks
X-Location
X-Level-Front-Cache
BehaviorPad-Version
Meta-Geo-Continent
MD5-Digest
X-Origin-CC
Machine
X-PAYTM-SRV-ID
X-PBS-Appsvrname
X-Origin-TTL
X-Owner
X-Processor
Arc-Version
X-NewRelic-App-Data
PB-PID
X-Sucuri-ID
X-B3-SpanId
PB-RID
C-Via
Pagetype
Fastly-Backend-Name
Gh-Request-Id
Host-ID
CacheControlHeader
Cf-Device-Type
X-Has-Esi
X-Skip-Cache
X-SVT-ORM-RULES
X-Reqid
X-OVcl-Cache
X-OVcl
X-SVT-ORM-VERSION
X-Thanos
X-NAPM-TraceId
X-VServer
X-Tumblr-Pixel-3
X-TrackingId
X-Node-Id
X-Mvc-Supplant-Cachable
X-Cache-Bucket
X-FC-Vary-Parameters
X-Bip
X-Azure-Ref-OriginShield
UCS
X-Geo-Header
X-GeoIP
X-Micro-Cache
X-JWT-State
X-Is-Gdpr
X-HS-Content-Campaign-Id
Server-Host
X-Irp-Debug
X-Ms-Version
X-TX-ID
X-Varnish-Cache-Hits
X-TA-CDN-Provider
AKAMAI
X-Ms-Request-Id
X-Cdn-Forward
X-Adobe-Source
X-Cms-Context
Server-Ext
X-Dispatcher-Server
X-Cache-Info
Wxu-Next-Hostname
Wxu-Next-Commit
V-Age
X-DPWN-IS-SECURE
Ssr
X-B3-Traceid
X-Fastly-Backend
Server-Hostname
Wxu-Next-Region
X-Esi-Check
X-Eu-Site
Sever-Int
On-Server
X-Branch-Name
X-CGP
X-Clientip
X-Backend-State
X-VarnishDD-TTL
X-Cache-Tags
X-Cache-Id
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-DefHash
X-Developer
X-Varnish-Beresp-Grace
X-DefElseHash
X-Varnish-CookieHashed-On
X-Csrf-Jwt
X-CUA
Content-Disposition
X-Developers
X-Core-Value
X-LI-UUID
HA-Ipaddr
Ha-Gx-Prefs
Is-Eu
X-Li-Pop
Location
X-Fastly-Cache
X-Li-Fabric
X-Scheme
X-Nginx-Cache-Key
X-Origin-Response-Time
X-Policy
Cache-Host
X-Origin-Expires
X-Request-Host
Adler-Geo
X-Old-Content-Length
X-Origin
Locid
L5d-Success-Class
X-Variation
X-Var-Ttl
X-Swa-Ws
PFcat
Platform
X-Generated-By
X-Generated-In
X-Gzip
X-User
NM-Fastcgi-Cache
X-IP
X-HN
Magicmarker
User-Cache-Control
X-CS
X-Cdn-Origin
X-Slack-Backend
X-Gamma-Serve
X-Sn-Servicetimems
X-Varnish-Beresp-Status
X-Hash
X-Method
X-SIPLIST1
X-Varnish-Beresp-Ttl
X-Varnish-Hits
X-EC-Lua
X-Request-URI
CDN-CachedAt
True-Client-Country-4JS
X-Rebelmouse-Surrogate-Control
X-Block-Status
L
Vix-Hermes-Req-Id
X-NU-AKA-ACS-Version
Web-Mar-Node
X-Hnp-Log
X-Clara-WADP
Pramga
X-Gen-Mode
X-Fmm-Version
X-Envoy-Decorator-Operation
IsBot
Rt-Fastcgi-Cache
NGX
X-Platform-Server
X-Ratelimit-Reset
CDN-EdgeStorageId
X-Rebelmouse-Cache-Control
CDN-Cache
Cf-Bgj
CDCHOST
Fastly-SWR
CDN-PullZone
CDN-Uid
CloudFront-Viewer-Country
Fastly-SIE
CDN-RequestId
X-WADP-Cache
CDN-RequestCountryCode
X-Erf-Stays-Bingo-Pdp-Web
X-ID
X-Cache-Date
X-LB-ID
X-Goog-Meta-Goog-Reserved-File-Mtime
Origin
X-Aicache-OS
Apple-News-Services-Request-Url
Apple-News-Services-Handled
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Fastly-Drupal-HTML
X-Servername
X-VG-TLSProxy
X-Loc
X-Cache-Debug
Sid
X-GoCache-CacheStatus
X-Dynatrace
X-CLOUD-TRACE-CONTEXT
X-Mvc-Supplant-OutputCached
X-CACHE-KEY
X-Core-Mission
X-PF-Uncompressing
X-Cache-Expires
X-NCache
X-Nc
X-Via-Poph
X-Request-Start
Esi-Enabled
X-Via-Popn
X-Varnish-Url
X-Via-Popv
X-Refresh
X-CACHE-GROUP
Url
Who
Country-Code
X-Oracle-Dms-Rid
X-NC
X-Cache-Remote
X-Unique-ID
X-FireWall-Protection
X-Response-By
Pics-Label
X-Epic-Correlation-Id
X-Varnish-Cacheable
X-TraceId
S-Rt
X-Proxy-Cachei7
Xkeyi7
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
Req-Svc-Chain
X-Tb-Optimization-Total-Bytes-Saved
X-Planisys-CDN-Rules
Geo-Info
X-Host-Name
X-Webkit-Csp
N-Cache
X-B3-Spanid
X-Error
Source
Content-Secure-Policy
X-BBXSRF
X-Srv
Geoip-Latitude
Cmsid
GeoIp-Country-Code
X-Cache-2
Cmstype
Ohc-File-Size
Filterid
X-Webkit-CSP-Report-Only
Cross-Origin-Window-Policy
X-Contensis-Viewer-Groups
Cteonnt-Length
HitType
D-Cc-Upstream
X-DC
Server-Ttl
Kp-EeAlive
X-HS-Status
X-Served-From
X-Cache-ASPX
X-Cc-Req-Id
Svr
X-Varnish-Authentication
X-Cc-Via
X-Sucuri-Cache
X-RateLimit-Limit
X-Vcl-Version
X-LiteSpeed-Cache-Control
VivaBuild
Viewtype
Tcn
X-Svr
A
Cache-Key
X-URL
X-CDN-Forward
X-Cs
X-Server-IP
M-TraceId
X-HostName
X-Li-Proto
X-Servedbyhost
X-Wa
MIME-Version
X-FPC
X-Nyt-Route
X-Esi
X-Origin-Time
Arc-Country
X-Cache-Config
X-Air-Source
X-Gdpr
NGB
Cross-Origin-Opener-Policy
X-API-Version
TDXMobile
X-Vgn-Hpd-Reason
CACHE
Server-ID
X-RAMCache
X-LI-Proto
Server-Id
Resin-Trace
X-SN
X-VC
NtCoent-Length
X-HOST
SID
X-SB
Request-ID
X-Webstats-RespID
X-NodeID
X-Viewer-Country
X-Newrelic-Synthetics
Ohc-Cache-HIT
X-Vc
X-Check-Cacheable
X-ServedByHost
X-UA
Hostname
X-DI
X-NGINX-Cache
X-DB
X-Internal-Host
X-VCL-Version
X-SD-PageType
Cache-Provider
X-RSL
X-RPS
X-RPM
X-DW
X-DSS
X-Service
X-WA
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
Mime-Version
X-TIM-N
X-TIME
X-PHP-Backend
X-JoinUs
X-NGENIX-Cache
X-SaId
DataCenter
GeoIP-Latitude
GeoIP-Country-Code
X-Render-Time
X-Geo
Srv
X-Edge-Location
X-App
XServer
EpKe-Alive
FSS-Cache
X-Action
X-Provided-By
X-Forwarded-Site
X-Via-NSCOPI
X-BBC-Edge-Cache-Status
ProcessTime
X-Ua
CF-Cached-On
X-FTR-Cache-Host
X-Worker
X-Fpc
Processtime
W
Upgrade-Insecure-Requests
X-CF-Powered-By
X-Oss-Cdn-Auth
X-Extlb
X-Auto-Login
X-Bc-Bl
X-Dynatrace-Js-Agent
X-VC-Cache
X-PJAX-URL
X-Proxy-Upstream
X-Depends-On
X-FORWARDED-FOR
X-Req
X-Region-Sid
Surrogated-Key
X-Accel-Expires-Debug
X-Cluster-Node
We-Hiring
Mail-Subject
Memcached
Proxy-Connection
LB
X-Date
X-HITS
X-Cdn-Request-ID
X-Parent-Response-Time
CDN
Cdn
X-Ftr-Cache-Host
X-ZONE
X-UnsetCookies
Env
X-RateLimit-Limit-Second
X-Fastly-Backend-Reqs
PICS-Label
X-CSRF-TOKEN
X-RateLimit-Remaining-Second
X-BACKEND-TTL
Datacenter
X-Dw-Trace-Id
X-MSEdge-Features
X-MSEdge-Flight
X-CACHE-AGE
X-Swift-Error
X-Client-Ip
X-Flog
X-ABtesting
X-Air-Trace-Id
X-Sigma
X-Rocket-Build-Number
Memory
X-Sigma-Backend
X-Men
X-APP
Time
X-Hello
X-Cache-Tag
X-IN-APIGATEWAY
X-BBC-Origin-Response-Status
X-Fastly-Request-Id
X-IN-APIGATEWAYSSL
Dnion-Transfer-Encoding
X-Akamai-Pragma-Client-IP
X-Pad
Vha6-Origin
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Acquia-Site
X-Acquia-Purge-Tags
OT-Force-Account-Verify
X-Pf-Uncompressing
VNS-Age
VNS-Cache
CPC-Cache
CPC-Age
X-Presslabs-Stats
X-Oracle-DMS-ECID
Media-Length
X-Zone
X-Via-PopV
Epwk-X-Cache
X-LiteSpeed-Tag
X-Via-PopH
X-Via-PopN
X-ND-Cache
Cf-Ipcountry
X-Lb-Id
X-Varnish-URL
X-Vcache
X-Ms-Meta-Staticbatchstarttime
X-Csrf-Token
X-Akamai-ERPolicy
X-Akamai-ERRuleID
WZWS-RAY
X-Request-URL
Xet-Cookie
X-Ms-Meta-Originalurl
X-Varnish-Beresp-TTL
X-ElasticPress-Query
X-ElasticPress-Search
X-MiniProfiler-Ids
X-Snapshot-Date
X-Request-Url
CountryCode
Content-Style-Type
Fastcgi-Cache-TTL
X-Tid
Content-Script-Type
X-Litespeed-Cache-Control
URI
X-Amz-Meta-Cb-Modifiedtime
NnCoection
Environment
Phost
X-ServerName
X-Storefront-Renderer-Verified
Ohc-Response-Time
X-C
X-B3-Parentspanid
X-Redis-Count
X-Redis-Duration-Ms
X-Traceid
X-Debug-Cache-Store
X-Debug-Cache-Fetch
Inserted-Into-Cache-At