Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
X-XSS-Protection
CF-RAY
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Xss-Protection
X-Cache-Status
X-Generator
X-Request-ID
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Content-Encoding
X-CDN
X-Ua-Compatible
Feature-Policy
X-AspNetMvc-Version
Status
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Upgrade
X-Via
CF-Ray
Access-Control-Max-Age
Keep-Alive
X-Ws-Request-Id
X-Age
X-Robots-Tag
X-AH-Environment
X-Turbo-Charged-By
Request-Context
EagleId
X-Proxy-Cache
X-Cache-Group
Server-Timing
X-Backend
X-Hacker
X-Server
Report-To
Host-Header
X-Server-Powered-By
X-Amz-Request-Id
Grace
X-Amz-Id-2
X-Nginx-Cache-Status
X-UA-Device
X-Dns-Prefetch-Control
X-Rq
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Page-Speed
Cf-Railgun
X-Pingback
X-OneAgent-JS-Injection
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
NEL
X-Cache-Spec
X-Amz-Version-Id
X-Device
X-CST
Allow
X-Vhost
X-Host
X-Backend-Server
Xkey
X-Server-Id
EagleEye-TraceId
X-WebKit-CSP
X-Dispatcher
Surrogate-Control
X-Node
Request-Id
Content-Location
X-Response-Time
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Akam-SW-Version
X-Ruxit-JS-Agent
P3p
X-ASPNET-VERSION
Accept-Ch
X-Application-Context
X-Ac
X-Cache-Lookup
X-Country
X-Template
Accept-Ch-Lifetime
X-Language
X-Mod-Pagespeed
Accept-CH
X-Readtime
X-Cloud-Trace-Context
Accept-CH-Lifetime
MS-Author-Via
X-B3-TraceId
Rating
X-HW
X-Cnection
X-Origin-Cache
X-MS-InvokeApp
X-Url
X-PC
X-TtlSet
X-Vname
Edge-Control
X-GitHub-Request-Id
X-Clacks-Overhead
X-ESI
X-ORACLE-DMS-RID
X-Trace
X-ORACLE-DMS-ECID
X-Middleton-Response
X-Content-Type
X-Sol
Response
Pagespeed
Display
X-Middleton-Display
X-Varnish-TTL
X-Webkit-CSP
X-D2id
Arr-Disable-Session-Affinity
X-Kinja-Revision
Verso
X-Kinja-Server
X-Kinja-Build
X-Use-Magma
X-Exp-Id
X-GoogleNews-Bot
X-Cdn-Fetch
X-Exp-Variant
X-Kinja
X-Vcap-Request-Id
X-Goog-Hash
X-Country-Code
X-Rack-Cache
X-TTL
X-Powered-By-Plesk
X-Navigation-Version
Service-Worker-Allowed
X-Buckets
X-Server-Name
X-VARITI-CCR
X-Amz-Rid
X-Abt-Application-Version
X-Fastly-Request-ID
X-Client-IP
Fastly-Restarts
X-Cache-TTL
X-FastCGI-Cache
X-Cached
X-Release
X-Element-Page-Cache
X-MSEdge-Ref
X-Dw-Request-Base-Id
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
SPRequestGuid
X-SharePointHealthScore
X-Oneagent-Js-Injection
X-NF-Request-ID
SPIisLatency
SPRequestDuration
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
Public-Key-Pins
RTSS
Access-Control-Request-Method
Ar-Sid
AR-Request-ID
AR-PoweredBy
AR-CACHE
AR-ATIME
X-Edge
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-LLID
X-Powered-CMS
Cache-Tag
X-Ezoic-Cdn
X-Litespeed-Cache
X-Upstream
Content-MD5
X-Jurisdiction
X-HP-Webp
X-Origin-Upstream-Status
X-Version
S
Fusion-Source
Fusion-Deployment-Id
Fusion-Template-Id
Fusion-Content-Source
Fusion-Component-Id
Fusion-Content-Id
X-Px
X-MCACHE
X-Mid
X-ECACHE
X-Recruiting
X-Mg-S
Charset
X-Content-Digest
X-Kinsta-Cache
X-DynaTrace
Fastcgi-Cache
X-PressLabs-Stats
X-T
Cache-Tags
X-Amz-Server-Side-Encryption
X-Id
X-Fastcgi-Cache
MicrosoftSharePointTeamServices
X-Logged-In
X-Accel-Expires
X-Content-Security-Policy-Report-Only
Filters
X-Ruxit-Js-Agent
X-Ttl
Server-Node
X-Forwarded-Proto
Edge-Cache-Tag
Front-End-Https
X-Correlation-Id
TP-Cache
TP-L2-Cache
X-Grace
X-Forwarded-For
Server-Name
X-Debug
Nginx-Cache
X-Hits
X-Kong-Upstream-Latency
X-Amzn-Trace-Id
X-Kong-Proxy-Latency
X-Request-Received
X-Request-Processing-Time
TCN
X-B3-Sampled
X-Shield-Request-Id
Surrogate-Key
X-Yandex-Sdch-Disable
X-Microsite
X-Request-Handler-Origin-Region
X-Varnish-Age
X-Ser
X-Amz-Replication-Status
X-Activity-Id
X-AppVersion
X-Az
X-F-Cache
X-XRDS-Location
X-HS-Cache-Config
X-HS-Combine-CSS
X-HS-Content-Id
X-HS-Hub-Id
X-XRDS-LOCATION
X-Origin-Server
X-Goog-Stored-Content-Length
Alternate-Protocol
X-Goog-Generation
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Metageneration
X-DIS-Request-ID
X-Pinterest-Direct
Accept-Charset
X-Geo-Country
X-Git-Hash
X-Rid
X-Cache-Key
X-Frontend
X-Respond-Thread
Host
X-Time
Section-Io-Cache
X-NWS-LOG-UUID
X-LB-Cache
X-DataDome
Cache
X-Upgrade-Enabled
Access-Control-Allow-Method
X-VCache
X-Seen-By
X-Mobile-URL
X-Cache-Age
X-Server-ID
X-FTR-Request-ID
ServerID
MS-CV
Paypal-Debug-Id
X-Type
Healthy
X-TT
X-IPLB-Instance
X-Whom
X-Hostname
X-AOL-HN
X-Source
X-Content-Options
X-Varnish-Backend
X-Providence-Cookie
X-App-Environment
X-Aspnet-Duration-Ms
X-Request-Guid
X-Flags
X-Is-Crawler
X-Route-Name
Payment
Cleartype
X-Signature
X-Cache-Action
X-B-Cache
X-Daa-Tunnel
X-Page-Id
X-Jobs
Fastcgi-Useragent
X-Debug-Info
X-RateLimit-Remaining
X-N
X-WebKit-CSP-Report-Only
X-Load-Cache
Powered-By-ChinaCache
X-FB-Debug
Nel
X-Webkit-Csp
X-Erf-Bev-Bev
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Mobile
X-Browser-Type
Realpath
X-Erf-Bev-Bev-Is-Generated
X-TEC-API-ROOT
X-Contextid
Node
Refresh
X-Via-JSL
X-Drupal-Cache-Tags
X-Accel-Buffering
X-Wix-Request-Id
X-Response-Served-From
X-Zen-Fury
Version
X-Original-Request-Id
X-Rule
X-Framework
X-Cacheable-TTL
DC
X-Proxy
X-Cache-Expired-At
Ms-Operation-Id
Referer-Policy
X-ProcessESI
X-RTag
X-RemovedCookies
X-Cluster-Name
X-Distributor
X-Real-IP
X-Drupal-Cache-Contexts
X-B
X-Cache-Time
Access-Control-Request-Headers
X-Region
X-HTML-Minification-Powered-By
X-Instance
X-Content-Powered-By
X-FW-Type
X-Page-View
X-Cached-By
X-FW-Static
X-FW-Server
X-FW-Dynamic
X-FW-Hash
X-FW-Serve
Viewport
X-Tt-Trace-Host
X-Akamai-Edgescape
X-Cache-Control
X-UUID
X-Tt-Trace-Tag
Eomportal-Instance
X-IPS-LoggedIn
Countrycode
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Cache-Operation
X-Cache-Rule
Liferay-Portal
X-G
X-Cache-Hit
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-FireWall-Port
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Pass-Why
X-Tumblr-Pixel
X-L-Path
X-Environment-Context
X-App-Server
DynaTrace
Server-Info
SRV
Xserver
CF-IPCountry
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
X-Nginx-Cache
Section-Io-Id
Section-Io-Origin-Status
X-Protected-By
X-User-Agent
X-Debug-IsPreview
X-Debug-IsConnected
Ec-Rule-Version
From-Origin
X-Tumblr-Pixel-2
X-Www-Served-By
Webserver
GEO-INFO
X-Device-Type
X-Ratelimit-Limit
X-Mode
X-UPSTREAM-Address
Meta-Geo
X-Handled-By
X-Adobe-Content
X-ES-SERVER
X-RN-RSRV
X-Hl-Ver
X-Adobe-Loc
X-Endurance-Cache-Level
X-Uri
X-MP-GENERATED-AT
Cache-Tv-Group
X-FB-TRIP-ID
X-Cache-Server
Protected
X-Backend-Name
X-Labrador-Cache-Channel
Property-Id
TWC-Locale-Group
X-Web-Node
X-NYM-Debug-Backend
TWC-Privacy
Webcakes-App-Name
X-Locale
Webcakes-App-Version
Webcakes-Region
Retry-After
X-Be
X-Node-Name
TWC-GeoIP-LatLong
TWC-GeoIP-Country
X-Varnishpool
X-PHP-Host
TWC-Device-Class
X-UA-Device-Type
X-Varnish-Grace
X-Origin-Hint
X-Site-Version
Cache-Status
X-Soup
TWC-Connection-Speed
X-Timing-Wait
X-Storage
X-Origin-Date
X-VWS-Id
X-Format
X-Section
X-Pubstack
X-WA-Info
Selected-Fe
X-Via-Fastly
X-Proto
X-FW-Version
X-Server-W
X-Sql-Duration-Ms
X-BYPASS-REASON
X-Human
Mn-Server-Ip
Frame-Options
X-Request-Time
X-Sql-Count
Country
X-Proxy-Build
X-ProxyCache-Key
Cache-Name
X-AWS-Id
X-Redis-Cache
X-No-Session
X-ProxyCache-Status
X-Access
X-LJ-Flow-ID
X-Cache-TTL-Remaining
Azure-InstanceId
Azure-SlotName
Azure-RegionName
Azure-SiteName
X-TNCMS
X-Loop
X-Hyper-Cache
X-Status
X-Hosted-By
Azure-Version
X-Proxied
X-ApacheServer
X-LAGOON
X-Tec-Api-Root
Decoy-Debug-TTL
Decoy-Debug-Status
X-OCL
Fastly-SSL
X-PCL
X-PERF
X-R9-Blue-Green-Version
Decoy-Debug-Key
X-Tec-Api-Version
X-S-Maxage
X-Routing-Service
X-Zipkin-Id
X-Say-TTL
X-Say-Cacheable
X-Xfnlog-Site
X-SayCDN-TTL
X-Tec-Api-Origin
X-Alternate-Cache-Key
X-CCM
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Shopify-Stage
X-ShardId
X-Storefront-Renderer-Rendered
X-ShopId
X-Forwarded-Host
X-Cluster
X-TT-LOGID
X-Cache-Grace
Apigw-Requestid
X-GG-Cache-Date
X-AIR-PT
X-Varnish-Server
X-SRV
X-Revision
X-Is-Bot
X-Rendered-As
X-Info
X-Qloud-Router
X-Ratelimit-Remaining
S-Cnection
X-Cache-Enabled
AMP-Access-Control-Allow-Source-Origin
X-Microcachable
X-Content-Age
X-Cdn
X-Proxy-Cache-Status
Uber-Trace-Id
X-Via-CDN
X-Dc
Cache-Hits
X-FTR-DC
X-CSRF-Token
X-Azure-Ref
X-FTR-Realm
X-FTR-Cache-Status
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Backend
X-Platform
X-FTR-Balancer
X-NWS-UUID-VERIFY
Amp-Access-Control-Allow-Source-Origin
X-Backend-Host
X-TA-CDN-Provider
X-App-Version
X-Varnish-Ttl
X-Aspnetmvc-Version
X-Amz-Meta-S3cmd-Attrs
X-Cache-Host
X-Detected-As
X-FTR-Expires
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Amzn-Remapped-Content-Length
Akamai-GRN
X-EdgeConnect-Cache-Status
X-ATG-Version
X-B3-SpanId
X-Oss-Object-Type
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
X-CS
X-Trace-Id
X-Air-Hostname
X-Oss-Storage-Class
SD-X-WS
Tracecode
ServedBy
X-RCS-CacheZone
X-Debug-Cache
X-Time-Microsecs
X-Varnish-Hostname
X-Cache-PHP
X-Cache-NGX
X-BCube-Filmed-By
X-Correlation-ID
X-ServerID
X-Backend-TTL
DB-Nickname
X-TX-ID
X-Tb
X-Akamai-Transformed
X-Cache-Var
HostName
X-Cache-Var-Map
X-Unique-Id
X-NewRelic-App-Data
Backend
X-Ms-Request-Id
X-Ms-Version
X-Request-UUID
X-Rewrite-Enabled
X-ARC
X-Processor
X-Rojux
X-PBS-Appsvrname
X-Application
X-B-Cookie
DCR-Decision-By
DCR-Processing-Time-Ms
Expiry
Fastcgi-X-Cache-Version
X-Fetched-On
X-Session-Fingerprint
X-S-Cookie
X-PAYTM-SRV-ID
X-ScT
X-S
X-Aed
BehaviorPad-Version
X-Location
X-A
T-Server
X-Level-Front-Cache
Thinkindot-CacheControl
Thinkindot-Control
X-Adobe-Source
Thinkindot-CacheControl-Type
X-NAPM-TraceId
X-External-Request-Id
X-A-Wwc
X-Origin-TTL
Odigeo-Trace-Id
X-Magnolia-Registration
X-A-Dgt
X-Origin-CC
X-A-Ccd
X-A-Dam
X-A-Dcw
X-Owner
X-SRCache-Key
X-Vtex-Remote-Cache
Xc-Version
Machine
X-Vtex-Processado-Em
Rendered-Blocks
X-VG-WebCache
X-VG-WebServer
X-Cache-NE
X-D
X-CF-Lambda-Version
Mobile-Detection-Method
X-Connection-Hash
X-CF-Lambda-Fn
X-Generated-On
MD5-Digest
Meta-Geo-Continent
X-Vdms-Version
X-DynaTrace-JS-Agent
Release
X-Thinkindot-L3
X-Trv-Group
X-GeoIP-City
X-Destination
X-Device-Os
X-Vdms-Path
X-From
DSUID
X-Sucuri-ID
X-GEO
NGX
X-Cms-Context
Magicmarker
On-Server
SR-User-Adfree
CacheControlHeader
AKAMAI
X-Has-Esi
C-Via
X-Irp-Debug
Arc-Version
PB-RID
X-Fastly-Cache
PB-PID
X-GeoIP
Server-Hostname
Path
Cf-Device-Type
Server-Ext
Server-Host
Instruction
Content-Disposition
X-Generation-Time
Locid
X-FC-Vary-Parameters
X-Geo-Header
Sever-Int
Host-ID
Pagetype
Gh-Request-Id
X-OVcl
X-Core-Value
X-Azure-Ref-OriginShield
X-Varnish-Cache-Hits
X-Policy
X-VServer
X-Skip-Cache
X-SVT-ORM-RULES
X-Tumblr-Pixel-3
X-Bip
X-TrackingId
X-Thanos
X-SVT-ORM-VERSION
X-OVcl-Cache
X-Developers
X-Node-Id
X-JWT-State
Wxu-Next-Region
X-Cache-Bucket
Wxu-Next-Commit
Wxu-Next-Hostname
X-B3-Traceid
UCS
X-Is-Gdpr
X-Nginx-Cache-Key
X-Mvc-Supplant-Cachable
X-Micro-Cache
X-EC-Lua
X-Varnish-Beresp-Grace
User-Cache-Control
X-Cdn-Forward
X-DefElseHash
X-DefHash
X-Cache-Id
X-Cache-Debug
X-Csrf-Jwt
X-Clara-WADP
X-Clientip
X-Gen-Mode
X-CGP
X-Cache-Tags
X-CUA
X-Cache-Info
X-Dispatcher-Server
X-Esi-Check
X-Envoy-Decorator-Operation
X-Eu-Site
X-Fastly-Backend
Web-Mar-Node
Ssr
X-Backend-State
X-DPWN-IS-SECURE
PFcat
X-Branch-Name
X-Block-Status
Platform
X-Fmm-Version
X-Developer
CDN-Cache
X-Ratelimit-Reset
X-Platform-Server
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Request-Host
X-Reqid
X-Origin-Response-Time
NM-Fastcgi-Cache
X-Method
X-LI-UUID
X-NU-AKA-ACS-Version
X-Old-Content-Length
X-Origin
X-Scheme
X-SIPLIST1
X-Wikidot-Backend
X-WADP-Cache
X-Wikidot-Static-Cache
V-Age
X-User
X-Generated-In
X-VarnishDD-TTL
X-Varnish-Remaining-TTL
X-Var-Ttl
X-Swa-Ws
X-Variation
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Li-Pop
X-Origin-Expires
Fastly-SIE
X-Li-Fabric
Fastly-Backend-Name
X-HN
Cf-Bgj
X-Generated-By
Fastly-SWR
X-Gzip
Is-Eu
IsBot
HA-Ipaddr
Ha-Gx-Prefs
X-GoCache-CacheStatus
L5d-Success-Class
CDN-Uid
X-Hnp-Log
CDN-RequestId
Cache-Host
Adler-Geo
X-IP
X-HS-Content-Campaign-Id
CDCHOST
CDN-RequestCountryCode
CDN-EdgeStorageId
CDN-PullZone
CDN-CachedAt
X-Varnish-Beresp-Ttl
X-Cache-Backend
X-Nc
X-ID
X-VG-TLSProxy
True-Client-Country-4JS
X-Request-URI
Esi-Enabled
Vix-Hermes-Req-Id
X-Varnish-Beresp-Status
X-Slack-Backend
X-Matched-Rule
X-LB-ID
X-Varnish-Hits
X-Gamma-Serve
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Handled
Apple-News-Services-Request-Url
X-Hash
X-Unique-ID
Lfy
L
Location
Who
Origin
Rt-Fastcgi-Cache
Country-Code
X-CLOUD-TRACE-CONTEXT
Fastly-Drupal-HTML
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Mvc-Supplant-OutputCached
X-Loc
CloudFront-Viewer-Country
X-Aicache-OS
Geo-Info
X-CACHE-KEY
X-APP-VERSION
X-RateLimit-Limit
Sid
X-PF-Uncompressing
Pics-Label
Tcn
X-Varnish-Url
X-NCache
Pramga
X-Sn-Servicetimems
X-Via-Popv
X-Via-Popn
X-Via-Poph
X-Cache-Expires
X-Cdn-Origin
X-Core-Mission
X-Epic-Correlation-Id
X-Servername
X-Cache-Date
Filterid
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Tb-Optimization-Total-Bytes-Saved
X-Request-Start
X-Refresh
Url
X-TraceId
X-FireWall-Protection
Cmsid
Cmstype
Req-Svc-Chain
X-NC
Svr
X-DC
X-Served-From
Kp-EeAlive
X-Varnish-Cacheable
X-Error
VivaBuild
NGB
X-Response-By
Source
MIME-Version
Viewtype
Cache-Key
A
X-Erf-Stays-Bingo-Pdp-Web
X-Webkit-CSP-Report-Only
X-Srv
X-Proxy-Cachei7
Xkeyi7
M-TraceId
X-Cache-Remote
X-Wa
N-Cache
Server-ID
Content-Secure-Policy
X-Servedbyhost
Server-Ttl
S-Rt
Arc-Country
X-Air-Source
Geoip-Latitude
HitType
X-BBXSRF
TDXMobile
Cross-Origin-Opener-Policy
X-HS-Status
GeoIp-Country-Code
X-URL
X-Vgn-Hpd-Reason
X-Cache-2
X-CDN-Forward
X-HostName
X-Vcl-Version
X-B3-Spanid
NtCoent-Length
X-Vc
Resin-Trace
X-Varnish-Authentication
X-Cache-ASPX
D-Cc-Upstream
X-Contensis-Viewer-Groups
X-Cc-Req-Id
X-Cc-Via
X-LiteSpeed-Cache-Control
X-LI-Proto
X-Esi
SID
X-PHP-Backend
X-SaId
X-JoinUs
X-NGENIX-Cache
Cross-Origin-Window-Policy
X-Host-Name
Cteonnt-Length
Ohc-File-Size
CACHE
X-Sucuri-Cache
X-Internal-Host
X-Edge-Location
X-Service
X-Svr
X-RAMCache
X-Geo
X-Li-Proto
X-HOST
X-VCL-Version
Hostname
X-CCDN-Origin-Time
X-CCDN-CacheTTL
Request-ID
DataCenter
X-Hcs-Proxy-Type
X-Server-IP
X-Extlb
X-UA
X-Origin-Time
X-Cache-Config
FSS-Cache
X-Newrelic-Synthetics
X-RSL
X-Via-NSCOPI
X-Viewer-Country
X-Forwarded-Site
GeoIP-Country-Code
GeoIP-Latitude
X-FPC
X-RPS
X-TIM-N
X-Gdpr
X-API-Version
X-Nyt-Route
X-DI
X-DW
X-ServedByHost
X-DB
X-DSS
X-RPM
X-WA
X-VC
X-App
X-SN
X-Bc-Bl
CF-Cached-On
X-Check-Cacheable
Cache-Provider
X-Dynatrace
X-Cs
XServer
Ohc-Cache-HIT
X-VC-Cache
We-Hiring
Server-Id
X-Proxy-Upstream
X-Accel-Expires-Debug
X-Date
X-Action
X-Req
X-Webstats-RespID
X-ZONE
Mail-Subject
X-SB
ProcessTime
LB
X-NodeID
Surrogated-Key
Memcached
X-Dynatrace-Js-Agent
X-Instrumentation
X-Oss-Cdn-Auth
X-Fpc
X-PJAX-URL
X-RateLimit-Remaining-Second
X-SD-PageType
X-Kraken-Routeconfig-Destination
X-Kraken-Loop-Name
Env
X-Server-Lifecycle-Phase
Mime-Version
X-RateLimit-Limit-Second
X-CF-Powered-By
X-Region-Sid
X-Provided-By
X-Swift-Error
X-Presslabs-Stats
W
Upgrade-Insecure-Requests
X-Sigma
X-Render-Time
X-APP
X-Sigma-Backend
X-Air-Trace-Id
X-BBC-Edge-Cache-Status
X-Men
X-FORWARDED-FOR
X-Rocket-Build-Number
X-Depends-On
Srv
X-Cdn-Request-ID
X-NGINX-Cache
CPC-Age
CPC-Cache
VNS-Age
X-MSEdge-Flight
CDN
VNS-Cache
Time
EpKe-Alive
X-CSRF-TOKEN
Cdn
X-BACKEND-TTL
X-MSEdge-Features
X-TIME
X-UnsetCookies
X-Dw-Trace-Id
X-Ftr-Cache-Host
Memory
X-CACHE-AGE
X-FTR-Cache-Host
X-Client-Ip
X-Worker
X-Parent-Response-Time
X-Flog
X-Hello
X-Cache-Tag
X-ABtesting
X-Fastly-Request-Id
X-Fastly-Backend-Reqs
Dnion-Transfer-Encoding
Processtime
X-Auto-Login
X-Ua
Datacenter
X-Akamai-Pragma-Client-IP
X-Acquia-Site
X-Pad
Media-Length
Proxy-Connection
X-Acquia-Application-UUID
X-Cluster-Node
X-BBC-Origin-Response-Status
X-Zone
X-Oracle-DMS-ECID
Vha6-Origin
X-Acquia-Application-Trace
X-Acquia-Purge-Tags
X-Pf-Uncompressing
X-LiteSpeed-Tag
X-Via-PopH
PICS-Label
X-Via-PopN
X-ServerName
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
State
X-Snapshot-Date
Fastcgi-Cache-TTL
X-Via-PopV
Epwk-X-Cache
Cf-Ipcountry
X-Edge-Location-Klb
X-Vcache
X-Akamai-ERRuleID
X-Ms-Meta-Staticbatchstarttime
X-Varnish-URL
X-Minions-Version
My-App
Xet-Cookie
X-Lb-Id
X-Ms-Meta-Originalurl
X-Akamai-ERPolicy
X-ElasticPress-Query
X-Varnish-Beresp-TTL
X-MiniProfiler-Ids
X-Request-URL
X-ElasticPress-Search
CountryCode
X-Air-Pt
Phost
X-Apw-Access-Action
Ohc-Response-Time
URI
Content-Script-Type
Content-Style-Type
X-Apw-Access-Object
X-Apw-Access-Token
X-Mg-Request-Id
X-Pjax-Url
X-Traceid
X-Cache-Status-Check
X-Apw-Hits
X-Litespeed-Cache-Control
X-B3-Parentspanid
X-Debug-Cache-Fetch
X-Tid
OT-Force-Account-Verify
Inserted-Into-Cache-At
X-Request-Url
Environment
X-Debug-Cache-Store
X-Redis-Count
X-Redis-Duration-Ms
X-C
NnCoection
X-Amz-Meta-Cb-Modifiedtime
X-Storefront-Renderer-Verified