Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-RAY
CF-Cache-Status
Accept-Ranges
Link
X-XSS-Protection
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Xss-Protection
X-Cache-Status
X-Generator
X-Request-ID
X-Cacheable
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Content-Encoding
X-CDN
X-Ua-Compatible
Feature-Policy
X-AspNetMvc-Version
Status
X-Envoy-Upstream-Service-Time
X-XSS-PROTECTION
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Upgrade
X-Via
Access-Control-Max-Age
Keep-Alive
X-Ws-Request-Id
X-Age
X-Robots-Tag
X-AH-Environment
X-Turbo-Charged-By
Request-Context
EagleId
X-Proxy-Cache
X-Cache-Group
Server-Timing
X-Backend
X-Hacker
X-Server
X-Dns-Prefetch-Control
Report-To
Host-Header
X-Server-Powered-By
X-Amz-Request-Id
X-Amz-Id-2
Grace
X-Nginx-Cache-Status
X-UA-Device
X-Rq
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Page-Speed
Cf-Railgun
X-Pingback
X-OneAgent-JS-Injection
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
NEL
X-Cache-Spec
X-Amz-Version-Id
X-Device
X-CST
Allow
X-Vhost
X-Host
X-Backend-Server
Xkey
X-Server-Id
X-WebKit-CSP
EagleEye-TraceId
X-Dispatcher
Surrogate-Control
X-Node
Request-Id
Content-Location
X-Response-Time
X-Akam-SW-Version
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Ruxit-JS-Agent
P3p
X-ASPNET-VERSION
Accept-Ch
X-Application-Context
X-Ac
X-Cache-Lookup
X-Country
X-Template
Accept-Ch-Lifetime
X-Mod-Pagespeed
X-Language
Accept-CH
X-Readtime
X-Cloud-Trace-Context
Accept-CH-Lifetime
MS-Author-Via
X-B3-TraceId
Rating
X-HW
X-Cnection
X-Origin-Cache
X-MS-InvokeApp
X-Url
X-PC
X-Vname
X-TtlSet
Edge-Control
X-Clacks-Overhead
X-GitHub-Request-Id
X-ESI
X-ORACLE-DMS-RID
X-Trace
X-ORACLE-DMS-ECID
X-Content-Type
X-Varnish-TTL
X-Middleton-Response
X-Sol
Display
Response
X-Middleton-Display
Pagespeed
X-D2id
Arr-Disable-Session-Affinity
Verso
X-Exp-Variant
X-Exp-Id
X-Cdn-Fetch
X-GoogleNews-Bot
X-Kinja
X-Use-Magma
X-Kinja-Server
X-Kinja-Revision
X-Kinja-Build
X-TTL
X-Vcap-Request-Id
X-Goog-Hash
X-Country-Code
X-Rack-Cache
X-Powered-By-Plesk
X-Navigation-Version
Service-Worker-Allowed
X-Server-Name
X-VARITI-CCR
X-Buckets
X-Amz-Rid
X-Abt-Application-Version
X-Fastly-Request-ID
X-FastCGI-Cache
X-Webkit-CSP
X-Client-IP
Fastly-Restarts
X-Cache-TTL
X-Cached
X-Release
X-MSEdge-Ref
X-Dw-Request-Base-Id
X-Element-Page-Cache
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
X-SharePointHealthScore
SPRequestGuid
X-Oneagent-Js-Injection
X-NF-Request-ID
SPIisLatency
SPRequestDuration
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
Public-Key-Pins
RTSS
Access-Control-Request-Method
AR-ATIME
AR-Request-ID
Ar-Sid
AR-CACHE
AR-PoweredBy
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Edge
X-LLID
Cache-Tag
X-Powered-CMS
X-Litespeed-Cache
X-Ezoic-Cdn
X-Upstream
Content-MD5
X-Jurisdiction
X-Origin-Upstream-Status
X-HP-Webp
X-Version
S
Fusion-Source
Fusion-Deployment-Id
Fusion-Template-Id
Fusion-Content-Id
Fusion-Content-Source
Fusion-Component-Id
X-Px
X-Mid
X-ECACHE
X-MCACHE
X-Recruiting
X-Mg-S
Charset
X-Content-Digest
X-PressLabs-Stats
X-Kinsta-Cache
X-DynaTrace
Fastcgi-Cache
X-T
Cache-Tags
X-Amz-Server-Side-Encryption
X-Id
Filters
X-Logged-In
MicrosoftSharePointTeamServices
X-Accel-Expires
X-Ruxit-Js-Agent
X-Content-Security-Policy-Report-Only
Server-Node
Edge-Cache-Tag
Front-End-Https
X-Forwarded-Proto
X-Correlation-Id
TP-L2-Cache
TP-Cache
X-Forwarded-For
X-Grace
Server-Name
X-Debug
X-Fastcgi-Cache
Nginx-Cache
X-Hits
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Amzn-Trace-Id
X-Request-Received
X-Request-Processing-Time
TCN
X-B3-Sampled
X-Ttl
X-Shield-Request-Id
Surrogate-Key
X-Yandex-Sdch-Disable
X-Microsite
X-Varnish-Age
X-Request-Handler-Origin-Region
X-Az
X-Activity-Id
X-AppVersion
X-Ser
X-Amz-Replication-Status
X-HS-Combine-CSS
X-HS-Content-Id
X-HS-Hub-Id
X-F-Cache
X-HS-Cache-Config
X-XRDS-Location
X-XRDS-LOCATION
X-Origin-Server
X-Goog-Metageneration
X-Goog-Generation
Alternate-Protocol
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-DIS-Request-ID
X-Pinterest-Direct
Accept-Charset
X-Geo-Country
X-Cache-Key
X-Rid
X-Git-Hash
X-Respond-Thread
X-Frontend
Host
Section-Io-Cache
X-NWS-LOG-UUID
Cache
X-Upgrade-Enabled
X-LB-Cache
X-DataDome
X-Time
Access-Control-Allow-Method
X-Seen-By
X-VCache
X-Mobile-URL
X-FTR-Request-ID
X-Server-ID
MS-CV
X-Cache-Age
ServerID
Paypal-Debug-Id
X-AOL-HN
X-Type
X-IPLB-Instance
X-TT
Healthy
X-Varnish-Backend
X-Source
X-Whom
X-Content-Options
X-Hostname
X-Aspnet-Duration-Ms
X-Is-Crawler
X-Providence-Cookie
X-Flags
Payment
X-App-Environment
X-Request-Guid
X-Route-Name
Cleartype
X-Signature
X-Cache-Action
X-B-Cache
X-Daa-Tunnel
X-Page-Id
Fastcgi-Useragent
X-Jobs
X-Debug-Info
X-RateLimit-Remaining
X-WebKit-CSP-Report-Only
X-N
X-Load-Cache
Powered-By-ChinaCache
X-FB-Debug
Nel
X-Mobile
X-Webkit-Csp
X-Contextid
Realpath
X-Erf-Bev-Bev
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Via-JSL
Node
Refresh
X-Rule
X-Drupal-Cache-Tags
X-Response-Served-From
Version
X-Original-Request-Id
X-Wix-Request-Id
X-Zen-Fury
X-Accel-Buffering
X-Cache-Expired-At
DC
Ms-Operation-Id
X-Cacheable-TTL
X-RTag
X-Proxy
X-Framework
Referer-Policy
X-RemovedCookies
X-ProcessESI
X-Drupal-Cache-Contexts
X-Distributor
X-Cache-Time
X-HTML-Minification-Powered-By
X-Region
X-Instance
X-Real-IP
X-B
X-Cluster-Name
Access-Control-Request-Headers
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-UUID
X-Cache-Control
X-Content-Powered-By
X-Page-View
X-FW-Type
X-FW-Hash
Viewport
X-FW-Serve
X-FW-Server
X-FW-Static
Eomportal-Instance
X-FW-Dynamic
X-Cached-By
X-Akamai-Edgescape
X-Cache-Rule
VIX-Pulpo-Upstream-Status
X-IPS-LoggedIn
VIX-Pulpo-Node
X-Cache-Operation
Liferay-Portal
X-G
X-Cache-Hit
X-Yottaa-Metrics
X-FireWall-Port
X-Yottaa-Optimizations
X-Pass-Why
X-Tumblr-Pixel-1
Countrycode
X-Tumblr-User
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Environment-Context
X-L-Path
X-App-Server
DynaTrace
Server-Info
SRV
CF-IPCountry
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Origin-Responded
Section-Io-Id
X-User-Agent
Xserver
X-Debug-IsConnected
X-Protected-By
X-Debug-IsPreview
Ec-Rule-Version
From-Origin
X-Tumblr-Pixel-2
Webserver
X-Www-Served-By
X-Nginx-Cache
GEO-INFO
X-Ratelimit-Limit
X-Device-Type
X-Mode
X-Adobe-Content
X-UPSTREAM-Address
X-Endurance-Cache-Level
Meta-Geo
X-ES-SERVER
X-RN-RSRV
X-Hl-Ver
X-Handled-By
X-Adobe-Loc
X-Locale
X-MP-GENERATED-AT
X-Site-Version
X-FB-TRIP-ID
X-Backend-Name
X-Uri
Protected
X-Cache-Server
Cache-Tv-Group
Webcakes-App-Version
Webcakes-App-Name
TWC-Privacy
Webcakes-Region
X-Web-Node
Cache-Status
X-Be
Retry-After
TWC-Locale-Group
TWC-GeoIP-LatLong
X-Varnishpool
X-Varnish-Grace
X-UA-Device-Type
Property-Id
TWC-Connection-Speed
X-Node-Name
TWC-GeoIP-Country
TWC-Device-Class
X-Labrador-Cache-Channel
X-Soup
X-PHP-Host
X-Origin-Hint
X-Storage
X-NYM-Debug-Backend
X-VWS-Id
X-Proxy-Build
X-Proto
X-Origin-Date
X-Pubstack
X-ProxyCache-Key
Selected-Fe
Decoy-Debug-Status
X-Server-W
X-R9-Blue-Green-Version
X-Redis-Cache
X-Access
Mn-Server-Ip
X-Sql-Duration-Ms
X-ProxyCache-Status
X-Via-Fastly
X-LJ-Flow-ID
X-No-Session
Decoy-Debug-TTL
X-FW-Version
X-Format
X-Human
X-OCL
Cache-Name
X-PCL
Fastly-SSL
Frame-Options
X-Request-Time
Country
X-BYPASS-REASON
X-Sql-Count
X-Section
Decoy-Debug-Key
X-AWS-Id
X-Timing-Wait
X-Status
Azure-RegionName
Azure-SiteName
Azure-Version
X-Cache-TTL-Remaining
X-S-Maxage
X-Say-Cacheable
X-Say-TTL
X-SayCDN-TTL
X-Routing-Service
X-Proxied
Azure-InstanceId
X-Hosted-By
X-Hyper-Cache
X-Loop
X-AIR-PT
Azure-SlotName
X-Tec-Api-Version
X-Zipkin-Id
X-PERF
X-Tec-Api-Root
X-Tec-Api-Origin
X-ApacheServer
X-LAGOON
X-WA-Info
X-Xfnlog-Site
X-TNCMS
X-Alternate-Cache-Key
X-Sorting-Hat-ShopId
X-CCM
X-ShopId
X-Shopify-Stage
X-Storefront-Renderer-Rendered
X-Sorting-Hat-PodId
X-ShardId
X-Forwarded-Host
X-Cluster
X-TT-LOGID
X-Cache-Grace
X-Varnish-Server
Apigw-Requestid
X-GG-Cache-Date
X-Revision
X-Info
X-SRV
X-Is-Bot
X-Rendered-As
X-Qloud-Router
X-Dc
X-Ratelimit-Remaining
S-Cnection
X-Microcachable
X-Cache-Enabled
AMP-Access-Control-Allow-Source-Origin
X-Proxy-Cache-Status
X-Content-Age
Uber-Trace-Id
X-Cdn
X-Via-CDN
Cache-Hits
X-Platform
X-FTR-Backend
X-Country-Code-Real
X-FTR-DC
X-FTR-Cache-Status
X-App-Version
X-FTR-Backend-Server
X-FTR-Realm
X-FTR-Balancer
X-NWS-UUID-VERIFY
X-Azure-Ref
X-TA-CDN-Provider
Amp-Access-Control-Allow-Source-Origin
X-Backend-Host
X-Varnish-Ttl
X-Detected-As
X-Cache-Host
X-Amz-Meta-S3cmd-Attrs
X-Aspnetmvc-Version
X-CSRF-Token
X-Amzn-Remapped-Content-Length
X-Amzn-RequestId
X-Amz-Apigw-Id
X-FTR-Expires
Akamai-GRN
X-EdgeConnect-Cache-Status
X-ATG-Version
X-B3-SpanId
X-Oss-Storage-Class
X-CS
X-Trace-Id
SD-X-WS
X-Oss-Hash-Crc64ecma
Tracecode
X-Air-Hostname
X-Oss-Object-Type
X-Oss-Request-Id
X-Oss-Server-Time
ServedBy
X-Time-Microsecs
X-RCS-CacheZone
X-Debug-Cache
X-Varnish-Hostname
X-Cache-PHP
X-Cache-NGX
X-ServerID
X-Backend-TTL
X-BCube-Filmed-By
X-Correlation-ID
X-Akamai-Transformed
X-Tb
DB-Nickname
X-Cache-Var
X-Cache-Var-Map
HostName
X-Unique-Id
Backend
X-Generated-On
X-Device-Os
X-Generation-Time
X-External-Request-Id
X-B-Cookie
X-Processor
X-CF-Lambda-Fn
X-Magnolia-Registration
X-Location
X-ScT
X-Session-Fingerprint
X-S-Cookie
X-S
X-Ms-Version
X-Rewrite-Enabled
X-Rojux
X-Request-UUID
X-PBS-Appsvrname
Machine
X-Ms-Request-Id
MD5-Digest
X-NewRelic-App-Data
X-D
X-NAPM-TraceId
X-Cache-NE
X-Origin-CC
Meta-Geo-Continent
Odigeo-Trace-Id
X-Owner
X-PAYTM-SRV-ID
X-Destination
X-GeoIP-City
Mobile-Detection-Method
X-Origin-TTL
X-ARC
X-Aed
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
BehaviorPad-Version
X-Fetched-On
X-VG-WebServer
X-Vdms-Path
X-Vdms-Version
X-VG-WebCache
Expiry
T-Server
Thinkindot-Control
X-Connection-Hash
Fastcgi-X-Cache-Version
Thinkindot-CacheControl-Type
Xc-Version
Thinkindot-CacheControl
X-Level-Front-Cache
X-A
X-Adobe-Source
Rendered-Blocks
X-EC-Lua
X-Thinkindot-L3
Release
X-A-Wwc
X-SRCache-Key
DCR-Decision-By
X-A-Dgt
X-Trv-Group
X-DynaTrace-JS-Agent
X-A-Dam
X-A-Ccd
DCR-Processing-Time-Ms
X-From
X-A-Dcw
X-CF-Lambda-Version
X-Application
X-TX-ID
X-Sucuri-ID
X-Nc
X-GEO
Arc-Version
AKAMAI
C-Via
CacheControlHeader
Cf-Device-Type
X-Developers
Fastly-Backend-Name
Content-Disposition
Pagetype
Server-Host
Server-Ext
X-Azure-Ref-OriginShield
PB-RID
Server-Hostname
Sever-Int
Wxu-Next-Hostname
UCS
Wxu-Next-Region
SR-User-Adfree
PB-PID
Path
Instruction
Host-ID
Gh-Request-Id
X-Cms-Context
X-Cache-Bucket
Locid
On-Server
NGX
X-Bip
Magicmarker
X-Core-Value
X-GeoIP
X-Mvc-Supplant-Cachable
X-Nginx-Cache-Key
X-Node-Id
X-Micro-Cache
X-JWT-State
X-HS-Content-Campaign-Id
X-Irp-Debug
X-Is-Gdpr
X-OVcl
X-OVcl-Cache
X-TrackingId
X-Tumblr-Pixel-3
X-VServer
X-Thanos
X-Skip-Cache
X-Policy
X-Reqid
X-B3-Traceid
X-Varnish-Cache-Hits
Wxu-Next-Commit
X-Fastly-Cache
X-Geo-Header
X-FC-Vary-Parameters
X-Has-Esi
X-Varnish-Beresp-Grace
User-Cache-Control
X-Cdn-Forward
DSUID
X-Scheme
X-SIPLIST1
X-Eu-Site
X-SVT-ORM-RULES
X-Esi-Check
X-Rebelmouse-Surrogate-Control
X-User
X-Platform-Server
X-Gen-Mode
X-Ratelimit-Reset
X-Rebelmouse-Cache-Control
X-SVT-ORM-VERSION
X-Fmm-Version
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-Varnish-Remaining-TTL
X-VarnishDD-TTL
X-Wikidot-Backend
X-Variation
X-Var-Ttl
X-WADP-Cache
X-Generated-In
V-Age
X-Wikidot-Static-Cache
X-Swa-Ws
X-DPWN-IS-SECURE
X-Clara-WADP
X-Li-Fabric
X-CGP
X-Li-Pop
X-Method
X-LI-UUID
X-DefHash
X-DefElseHash
X-HN
X-CUA
X-Hnp-Log
X-Csrf-Jwt
X-IP
X-GoCache-CacheStatus
X-Cache-Tags
X-Developer
X-Origin
X-Old-Content-Length
X-Origin-Expires
X-Block-Status
X-Envoy-Decorator-Operation
X-Origin-Response-Time
X-NU-AKA-ACS-Version
X-Dispatcher-Server
X-Cache-Info
X-Generated-By
X-Cache-Id
X-Cache-Debug
X-Branch-Name
X-Fastly-Backend
X-Backend-State
X-Gzip
Fastly-SWR
Fastly-SIE
Cf-Bgj
Ha-Gx-Prefs
Web-Mar-Node
L5d-Success-Class
IsBot
Is-Eu
CDN-Uid
CDN-RequestId
CDCHOST
Cache-Host
Adler-Geo
CDN-Cache
CDN-CachedAt
CDN-RequestCountryCode
CDN-PullZone
CDN-EdgeStorageId
Location
HA-Ipaddr
Platform
PFcat
NM-Fastcgi-Cache
Ssr
X-Cache-Backend
X-ID
X-Varnish-Beresp-Ttl
Apple-News-Services-Handled
X-Request-URI
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
X-Slack-Backend
X-VG-TLSProxy
X-Varnish-Beresp-Status
X-Gamma-Serve
X-Hash
Vix-Hermes-Req-Id
True-Client-Country-4JS
X-Clientip
Esi-Enabled
X-Request-Host
Rt-Fastcgi-Cache
Apple-News-Services-Host
X-Unique-ID
L
Lfy
X-Varnish-Hits
Who
X-Matched-Rule
Origin
Country-Code
X-CLOUD-TRACE-CONTEXT
X-Mvc-Supplant-OutputCached
Fastly-Drupal-HTML
X-Loc
X-Aicache-OS
X-Goog-Meta-Goog-Reserved-File-Mtime
X-LB-ID
CloudFront-Viewer-Country
Geo-Info
Sid
X-APP-VERSION
X-RateLimit-Limit
X-CACHE-KEY
X-NCache
X-PF-Uncompressing
X-Via-Poph
Tcn
X-Cdn-Origin
Pramga
Pics-Label
X-Varnish-Url
X-Cache-Expires
X-Via-Popn
X-Sn-Servicetimems
X-Via-Popv
X-Servername
X-Epic-Correlation-Id
X-Cache-Date
X-Core-Mission
Filterid
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Tb-Optimization-Total-Bytes-Saved
X-Refresh
Url
X-Request-Start
X-Ua-Device
Cmsid
Cmstype
Req-Svc-Chain
X-FireWall-Protection
X-TraceId
Svr
X-Varnish-Cacheable
Kp-EeAlive
X-Error
X-Served-From
A
Source
Cache-Key
VivaBuild
MIME-Version
Viewtype
NGB
X-Response-By
X-NC
X-Webkit-CSP-Report-Only
X-Erf-Stays-Bingo-Pdp-Web
X-Srv
Geoip-Latitude
M-TraceId
X-Proxy-Cachei7
GeoIp-Country-Code
X-DC
Xkeyi7
X-Cache-Remote
X-Air-Source
X-BBXSRF
X-Wa
Cross-Origin-Opener-Policy
TDXMobile
Server-ID
HitType
Server-Ttl
S-Rt
X-Servedbyhost
Content-Secure-Policy
X-HS-Status
N-Cache
Arc-Country
X-URL
X-Vgn-Hpd-Reason
X-HostName
X-CDN-Forward
X-Vcl-Version
X-Cache-2
X-B3-Spanid
X-Varnish-Authentication
X-LI-Proto
X-Vc
X-LiteSpeed-Cache-Control
X-Cc-Via
X-Contensis-Viewer-Groups
X-Cc-Req-Id
X-Cache-ASPX
Resin-Trace
X-Esi
D-Cc-Upstream
X-Host-Name
SID
X-SaId
Ohc-File-Size
CACHE
Cteonnt-Length
NtCoent-Length
X-NGENIX-Cache
X-JoinUs
X-Sucuri-Cache
Cross-Origin-Window-Policy
X-Geo
X-Li-Proto
X-Service
X-Internal-Host
X-Edge-Location
X-RAMCache
X-PHP-Backend
X-Svr
X-HOST
DataCenter
X-VCL-Version
X-Server-IP
X-CCDN-CacheTTL
X-CCDN-Origin-Time
XServer
Request-ID
Hostname
X-Hcs-Proxy-Type
X-Extlb
X-UA
X-Via-NSCOPI
X-API-Version
X-RSL
X-RPS
X-FPC
X-Gdpr
X-DSS
X-DW
X-DI
X-Cache-Config
X-DB
X-Viewer-Country
X-RPM
X-WA
X-Newrelic-Synthetics
X-Origin-Time
X-Forwarded-Site
X-TIM-N
X-Nyt-Route
X-ServedByHost
FSS-Cache
GeoIP-Latitude
X-SN
Cache-Provider
X-VC
X-Bc-Bl
X-Dynatrace
CF-Cached-On
X-Cs
X-Check-Cacheable
GeoIP-Country-Code
X-App
Ohc-Cache-HIT
We-Hiring
ProcessTime
X-VC-Cache
X-Accel-Expires-Debug
X-SB
X-Action
X-Req
X-NodeID
X-Proxy-Upstream
X-Date
X-Region-Sid
X-Webstats-RespID
X-PJAX-URL
Server-Id
Surrogated-Key
LB
Memcached
Mail-Subject
X-TIME
X-Dynatrace-Js-Agent
X-NGINX-Cache
Env
X-Oss-Cdn-Auth
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
Mime-Version
X-Fpc
X-Kraken-Routeconfig-Destination
X-Server-Lifecycle-Phase
X-CF-Powered-By
X-Kraken-Loop-Name
X-Instrumentation
X-SD-PageType
X-Provided-By
X-ZONE
X-CSRF-TOKEN
X-APP
X-Depends-On
X-Air-Trace-Id
X-Sigma
X-FORWARDED-FOR
X-Rocket-Build-Number
Upgrade-Insecure-Requests
X-Sigma-Backend
X-Render-Time
W
X-BBC-Edge-Cache-Status
X-Swift-Error
Srv
X-Cdn-Request-ID
X-Ftr-Cache-Host
CPC-Age
X-Dw-Trace-Id
VNS-Age
X-MSEdge-Features
X-BACKEND-TTL
VNS-Cache
X-UnsetCookies
Cdn
EpKe-Alive
CPC-Cache
CDN
X-Men
X-MSEdge-Flight
X-Client-Ip
X-FTR-Cache-Host
X-CACHE-AGE
X-Flog
Processtime
X-ABtesting
X-Cache-Tag
Time
X-Parent-Response-Time
X-Fastly-Backend-Reqs
X-Hello
X-Auto-Login
Memory
Dnion-Transfer-Encoding
X-Worker
X-Fastly-Request-Id
Datacenter
X-Ua
X-Akamai-Pragma-Client-IP
X-Oracle-DMS-ECID
Media-Length
X-Presslabs-Stats
X-Pad
X-Pf-Uncompressing
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-Zone
Proxy-Connection
X-Acquia-Purge-Tags
X-Cluster-Node
X-Acquia-Site
X-BBC-Origin-Response-Status
Vha6-Origin
X-Via-PopH
PICS-Label
X-Via-PopN
Fastcgi-Cache-TTL
CountryCode
X-ServerName
X-Snapshot-Date
X-IN-APIGATEWAYSSL
X-Via-PopV
X-Lb-Id
X-IN-APIGATEWAY
X-LiteSpeed-Tag
State
My-App
Epwk-X-Cache
Cf-Ipcountry
X-Varnish-URL
X-MiniProfiler-Ids
X-Minions-Version
X-Edge-Location-Klb
X-ElasticPress-Query
X-Varnish-Beresp-TTL
X-Request-URL
X-Vcache
X-ElasticPress-Search
X-Akamai-ERRuleID
X-Akamai-ERPolicy
X-Cache-Status-Check
X-Ms-Meta-Staticbatchstarttime
Xet-Cookie
X-Ms-Meta-Originalurl
X-Tx-Id
X-Apw-Access-Token
Content-Style-Type
Content-Script-Type
X-Nananana
X-Apw-Access-Action
X-Litespeed-Cache-Control
X-Apw-Access-Object
X-Apw-Hits
URI
X-Redis-Count
X-Redis-Duration-Ms
X-Traceid
Environment
X-Storefront-Renderer-Verified
X-Request-Url
X-C
OT-Force-Account-Verify
NnCoection
X-Debug-Cache-Store
Inserted-Into-Cache-At
X-Tid
X-Debug-Cache-Fetch
Ohc-Response-Time
X-B3-Parentspanid
Phost
X-Amz-Meta-Cb-Modifiedtime