Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
Link
X-XSS-Protection
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
X-Request-Id
Access-Control-Allow-Methods
X-Xss-Protection
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Cacheable
X-Request-ID
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Content-Encoding
X-CDN
X-Ua-Compatible
Feature-Policy
X-AspNetMvc-Version
Status
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Upgrade
X-Via
Access-Control-Max-Age
Keep-Alive
X-Ws-Request-Id
X-Age
X-Robots-Tag
X-AH-Environment
X-Turbo-Charged-By
Request-Context
EagleId
X-Proxy-Cache
X-Cache-Group
Server-Timing
X-Backend
X-Hacker
X-Server
Report-To
Host-Header
X-Server-Powered-By
X-Amz-Request-Id
X-Amz-Id-2
X-Nginx-Cache-Status
Grace
X-UA-Device
X-Dns-Prefetch-Control
X-Rq
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Page-Speed
Cf-Railgun
X-Pingback
X-OneAgent-JS-Injection
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Cache-Spec
NEL
X-Amz-Version-Id
X-Device
X-CST
Allow
X-Vhost
X-Host
X-Backend-Server
Xkey
X-Server-Id
X-WebKit-CSP
EagleEye-TraceId
X-Dispatcher
Surrogate-Control
Request-Id
X-Node
Content-Location
X-Response-Time
X-Akam-SW-Version
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Ruxit-JS-Agent
Accept-Ch
P3p
X-ASPNET-VERSION
X-Ac
X-Application-Context
X-Cache-Lookup
X-Country
X-Template
Accept-Ch-Lifetime
X-Mod-Pagespeed
X-Language
X-Readtime
X-Cloud-Trace-Context
Accept-CH
MS-Author-Via
X-B3-TraceId
Accept-CH-Lifetime
Rating
X-HW
X-Cnection
X-Origin-Cache
X-MS-InvokeApp
X-Url
X-TtlSet
X-PC
X-Vname
Edge-Control
X-Clacks-Overhead
X-GitHub-Request-Id
X-ESI
X-ORACLE-DMS-RID
X-Trace
X-ORACLE-DMS-ECID
X-Content-Type
X-Varnish-TTL
Display
Pagespeed
X-Sol
X-Middleton-Response
X-Middleton-Display
Response
Verso
Arr-Disable-Session-Affinity
X-Vcap-Request-Id
X-Kinja
X-Kinja-Server
X-Kinja-Revision
X-Use-Magma
X-GoogleNews-Bot
X-Cdn-Fetch
X-Kinja-Build
X-Exp-Id
X-Exp-Variant
X-D2id
X-TTL
X-Goog-Hash
X-Rack-Cache
X-Country-Code
X-Powered-By-Plesk
Service-Worker-Allowed
X-Server-Name
X-Buckets
X-Amz-Rid
X-VARITI-CCR
X-Navigation-Version
X-Abt-Application-Version
X-Fastly-Request-ID
X-FastCGI-Cache
X-Webkit-CSP
X-Client-IP
Fastly-Restarts
X-Cache-TTL
X-MSEdge-Ref
X-Cached
X-Release
X-Element-Page-Cache
X-Dw-Request-Base-Id
SPRequestGuid
X-SharePointHealthScore
X-Oneagent-Js-Injection
X-NF-Request-ID
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
SPRequestDuration
SPIisLatency
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
Public-Key-Pins
Access-Control-Request-Method
RTSS
AR-Request-ID
AR-PoweredBy
X-SRCache-Store-Status
AR-ATIME
AR-CACHE
X-SRCache-Fetch-Status
Ar-Sid
X-Edge
Cache-Tag
X-LLID
X-Powered-CMS
X-Ezoic-Cdn
X-Litespeed-Cache
X-Upstream
Content-MD5
X-Jurisdiction
X-HP-Webp
X-Origin-Upstream-Status
X-Version
S
Fusion-Template-Id
Fusion-Source
X-Px
Fusion-Deployment-Id
Fusion-Component-Id
Fusion-Content-Id
Fusion-Content-Source
X-Mid
X-MCACHE
X-Mg-S
X-ECACHE
X-Recruiting
Charset
X-Content-Digest
X-PressLabs-Stats
X-Kinsta-Cache
Fastcgi-Cache
X-DynaTrace
X-T
Cache-Tags
X-Id
X-Amz-Server-Side-Encryption
Filters
MicrosoftSharePointTeamServices
X-Accel-Expires
X-Logged-In
X-Ruxit-Js-Agent
X-Content-Security-Policy-Report-Only
X-Forwarded-Proto
Edge-Cache-Tag
Server-Node
Front-End-Https
X-Correlation-Id
TP-Cache
TP-L2-Cache
X-Grace
X-Forwarded-For
Server-Name
X-Debug
X-Fastcgi-Cache
X-Hits
Nginx-Cache
X-Amzn-Trace-Id
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
TCN
X-Request-Received
X-Request-Processing-Time
X-Ttl
X-B3-Sampled
X-Shield-Request-Id
Surrogate-Key
X-Microsite
X-Yandex-Sdch-Disable
X-Request-Handler-Origin-Region
X-Varnish-Age
X-Activity-Id
X-AppVersion
X-Az
X-Ser
X-F-Cache
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Combine-CSS
X-HS-Content-Id
X-Amz-Replication-Status
X-XRDS-LOCATION
X-XRDS-Location
X-Origin-Server
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
Alternate-Protocol
X-DIS-Request-ID
X-Pinterest-Direct
Accept-Charset
X-Cache-Key
X-Rid
Nel
X-Git-Hash
X-Geo-Country
X-Frontend
Section-Io-Cache
X-Respond-Thread
X-Time
X-NWS-LOG-UUID
Host
X-LB-Cache
Cache
Access-Control-Allow-Method
X-Upgrade-Enabled
X-DataDome
X-VCache
X-Seen-By
X-Mobile-URL
X-Cache-Age
X-FTR-Request-ID
X-Server-ID
MS-CV
ServerID
X-TT
X-Type
X-IPLB-Instance
X-AOL-HN
X-Content-Options
X-Whom
Healthy
X-Source
Paypal-Debug-Id
X-Providence-Cookie
Payment
X-Varnish-Backend
X-Is-Crawler
X-Request-Guid
X-Route-Name
X-Aspnet-Duration-Ms
X-Flags
X-App-Environment
X-Cache-Action
X-Signature
X-Hostname
X-B-Cache
Cleartype
X-Page-Id
Fastcgi-Useragent
X-Debug-Info
X-Jobs
X-Daa-Tunnel
X-RateLimit-Remaining
X-Load-Cache
X-N
X-WebKit-CSP-Report-Only
Powered-By-ChinaCache
X-FB-Debug
X-Webkit-Csp
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Mobile
Realpath
X-TEC-API-ORIGIN
X-Contextid
Node
X-Rule
X-Via-JSL
Refresh
X-Drupal-Cache-Tags
Version
X-Accel-Buffering
X-Response-Served-From
X-Original-Request-Id
X-Zen-Fury
X-Wix-Request-Id
X-Cache-Expired-At
X-Framework
X-RTag
X-Cacheable-TTL
Ms-Operation-Id
Referer-Policy
DC
X-Proxy
Access-Control-Request-Headers
X-HTML-Minification-Powered-By
X-Drupal-Cache-Contexts
X-B
X-Cache-Time
X-Instance
X-Cluster-Name
X-FW-Serve
X-FW-Server
X-FW-Hash
X-FW-Static
X-Real-IP
Eomportal-Instance
X-Distributor
X-FW-Type
X-FW-Dynamic
X-Tt-Trace-Tag
X-Page-View
X-Region
X-Akamai-Edgescape
X-Tt-Trace-Host
X-Content-Powered-By
Viewport
X-UUID
X-Cached-By
X-Cache-Control
VIX-Pulpo-Node
Countrycode
VIX-Pulpo-Upstream-Status
X-ProcessESI
X-Cache-Rule
X-RemovedCookies
X-Cache-Operation
X-IPS-LoggedIn
Liferay-Portal
X-G
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Cache-Hit
X-Pass-Why
X-FireWall-Port
X-Tumblr-Pixel
X-L-Path
X-Environment-Context
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel-1
X-App-Server
Server-Info
DynaTrace
SRV
Xserver
CF-IPCountry
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
X-Nginx-Cache
Section-Io-Origin-Status
Section-Io-Id
X-User-Agent
X-Protected-By
Ec-Rule-Version
X-Debug-IsPreview
Webserver
X-Debug-IsConnected
X-Www-Served-By
X-Tumblr-Pixel-2
From-Origin
GEO-INFO
X-Ratelimit-Limit
X-Device-Type
X-UPSTREAM-Address
X-ES-SERVER
X-Mode
X-RN-RSRV
Meta-Geo
X-Adobe-Loc
X-Adobe-Content
Protected
X-FB-TRIP-ID
X-Handled-By
X-Backend-Name
X-Hl-Ver
X-Endurance-Cache-Level
X-Uri
Cache-Tv-Group
X-MP-GENERATED-AT
Webcakes-Region
TWC-Connection-Speed
TWC-GeoIP-Country
X-UA-Device-Type
X-Cache-Server
Property-Id
X-Origin-Hint
X-NYM-Debug-Backend
X-Be
X-Storage
Cache-Status
TWC-Device-Class
Webcakes-App-Name
TWC-Privacy
X-PHP-Host
X-Web-Node
TWC-Locale-Group
X-Labrador-Cache-Channel
TWC-GeoIP-LatLong
Webcakes-App-Version
X-VWS-Id
Decoy-Debug-Key
X-ProxyCache-Key
X-Varnish-Grace
X-Proxy-Build
X-ProxyCache-Status
X-PCL
X-Timing-Wait
X-Soup
Decoy-Debug-Status
X-WA-Info
X-Varnishpool
Frame-Options
Retry-After
X-Sql-Duration-Ms
X-Request-Time
Fastly-SSL
X-Origin-Date
X-Proto
X-Format
Decoy-Debug-TTL
X-Access
X-BYPASS-REASON
X-Server-W
X-AWS-Id
Selected-Fe
X-Section
X-OCL
X-LJ-Flow-ID
X-Sql-Count
X-FW-Version
Mn-Server-Ip
Country
X-Cache-TTL-Remaining
X-Say-TTL
X-Say-Cacheable
X-No-Session
Azure-SlotName
Azure-Version
Azure-SiteName
Azure-RegionName
Cache-Name
Azure-InstanceId
X-TNCMS
X-Human
X-Site-Version
X-R9-Blue-Green-Version
X-Redis-Cache
X-LAGOON
X-Xfnlog-Site
X-Pubstack
X-Node-Name
X-Status
X-Loop
X-Tec-Api-Version
X-Tec-Api-Root
X-Locale
X-Hosted-By
X-Tec-Api-Origin
X-SayCDN-TTL
X-Hyper-Cache
X-Proxied
X-Alternate-Cache-Key
X-Storefront-Renderer-Rendered
X-PERF
X-S-Maxage
X-Routing-Service
X-Shopify-Stage
X-Sorting-Hat-PodId
X-ShardId
X-ShopId
X-Sorting-Hat-ShopId
X-CCM
X-ApacheServer
X-Zipkin-Id
X-Via-Fastly
X-TT-LOGID
X-Cache-Grace
X-Cluster
X-Varnish-Server
Apigw-Requestid
X-Forwarded-Host
X-AIR-PT
X-GG-Cache-Date
X-Is-Bot
X-Revision
X-Rendered-As
X-SRV
X-Info
S-Cnection
X-Ratelimit-Remaining
AMP-Access-Control-Allow-Source-Origin
X-Qloud-Router
X-Cdn
X-Content-Age
X-Microcachable
X-Cache-Enabled
X-Proxy-Cache-Status
X-Dc
Uber-Trace-Id
X-Via-CDN
X-Platform
X-FTR-Cache-Status
X-FTR-Balancer
X-FTR-Backend-Server
X-CSRF-Token
X-FTR-DC
X-FTR-Realm
X-Country-Code-Real
X-FTR-Backend
X-Azure-Ref
Cache-Hits
X-Backend-Host
X-TA-CDN-Provider
X-Varnish-Ttl
X-App-Version
X-Aspnetmvc-Version
X-Amz-Meta-S3cmd-Attrs
X-Cache-Host
X-NWS-UUID-VERIFY
X-Detected-As
Amp-Access-Control-Allow-Source-Origin
X-Amz-Apigw-Id
X-Amzn-Remapped-Content-Length
X-FTR-Expires
X-Amzn-RequestId
Akamai-GRN
X-EdgeConnect-Cache-Status
X-B3-SpanId
X-ATG-Version
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Oss-Request-Id
X-Oss-Server-Time
X-CS
X-Air-Hostname
X-Oss-Storage-Class
Tracecode
SD-X-WS
X-Trace-Id
X-RCS-CacheZone
X-Time-Microsecs
X-Debug-Cache
ServedBy
X-Cache-PHP
X-Cache-NGX
X-Backend-TTL
X-BCube-Filmed-By
X-ServerID
X-Varnish-Hostname
X-Correlation-ID
DB-Nickname
X-Tb
X-Cache-Var-Map
X-Unique-Id
HostName
X-Cache-Var
X-TX-ID
X-NewRelic-App-Data
Backend
X-Rewrite-Enabled
X-Rojux
X-S
X-Request-UUID
X-From
X-Processor
Mobile-Detection-Method
Odigeo-Trace-Id
X-S-Cookie
X-ScT
Rendered-Blocks
X-Magnolia-Registration
X-External-Request-Id
Release
X-Adobe-Source
X-Session-Fingerprint
X-SRCache-Key
Meta-Geo-Continent
MD5-Digest
X-NAPM-TraceId
Expiry
Fastcgi-X-Cache-Version
DCR-Processing-Time-Ms
DCR-Decision-By
X-CF-Lambda-Version
BehaviorPad-Version
X-CF-Lambda-Fn
X-GeoIP-City
X-Origin-CC
X-PAYTM-SRV-ID
X-PBS-Appsvrname
Machine
X-Ms-Request-Id
X-Ms-Version
X-Origin-TTL
X-Generation-Time
X-Trv-Group
X-Fetched-On
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
X-A-Dcw
X-A-Dgt
X-DynaTrace-JS-Agent
X-A-Ccd
X-VG-WebCache
X-A
X-VG-WebServer
Xc-Version
X-A-Wwc
X-Destination
X-D
X-Cache-NE
X-Connection-Hash
X-B-Cookie
X-Device-Os
X-Aed
X-Application
X-ARC
X-Akamai-Transformed
X-A-Dam
X-Vdms-Version
T-Server
X-Vdms-Path
DSUID
X-GEO
X-Cache-Bucket
X-Has-Esi
Thinkindot-CacheControl-Type
X-Developers
Thinkindot-CacheControl
Fastly-Backend-Name
SR-User-Adfree
Server-Hostname
Arc-Version
X-Irp-Debug
X-Is-Gdpr
Server-Ext
C-Via
X-GeoIP
Cf-Device-Type
X-HS-Content-Campaign-Id
Content-Disposition
Gh-Request-Id
Wxu-Next-Hostname
Wxu-Next-Commit
Sever-Int
PB-PID
Wxu-Next-Region
On-Server
Path
NGX
PB-RID
X-Cms-Context
Instruction
Thinkindot-Control
Host-ID
UCS
X-Generated-On
X-FC-Vary-Parameters
Locid
X-Fastly-Cache
CacheControlHeader
X-Location
X-Tumblr-Pixel-3
X-TrackingId
X-Policy
X-Owner
X-Node-Id
X-B3-Traceid
X-Mvc-Supplant-Cachable
X-Nginx-Cache-Key
X-Varnish-Cache-Hits
X-Thinkindot-L3
X-SVT-ORM-RULES
X-EC-Lua
X-Reqid
X-Level-Front-Cache
X-SVT-ORM-VERSION
X-VServer
X-JWT-State
X-Sucuri-ID
X-Cdn-Forward
User-Cache-Control
X-Variation
Ssr
X-Varnish-CookieHashed-On
X-Varnish-Beresp-Grace
X-Varnish-CookieINHashed-On
X-Eu-Site
X-Fastly-Backend
Platform
X-Skip-Cache
X-Thanos
Server-Host
X-Envoy-Decorator-Operation
X-Esi-Check
Web-Mar-Node
X-Var-Ttl
X-Wikidot-Backend
X-Cache-Debug
X-Csrf-Jwt
X-CUA
X-Generated-In
X-DefElseHash
X-Cache-Id
X-Cache-Info
X-Clientip
X-CGP
X-User
X-Cache-Tags
X-Core-Value
X-DefHash
X-Branch-Name
X-DPWN-IS-SECURE
X-Dispatcher-Server
X-Wikidot-Static-Cache
X-SIPLIST1
X-WADP-Cache
X-Azure-Ref-OriginShield
X-Backend-State
X-Block-Status
X-Bip
X-Developer
V-Age
X-Varnish-Remaining-TTL
X-Fmm-Version
AKAMAI
X-GoCache-CacheStatus
X-NU-AKA-ACS-Version
X-Gzip
X-Li-Fabric
Fastly-SIE
Fastly-SWR
Adler-Geo
X-Origin-Expires
X-Origin
X-Old-Content-Length
X-Li-Pop
X-LI-UUID
CDN-RequestId
CDN-RequestCountryCode
CDN-PullZone
CDN-EdgeStorageId
CDN-Uid
CDN-Cache
X-Micro-Cache
X-Hnp-Log
X-Clara-WADP
CDCHOST
CDN-CachedAt
Ha-Gx-Prefs
X-Gen-Mode
X-Ratelimit-Reset
Magicmarker
HA-Ipaddr
X-Rebelmouse-Cache-Control
NM-Fastcgi-Cache
Pagetype
X-Request-Host
X-Rebelmouse-Surrogate-Control
Location
X-Platform-Server
X-OVcl
X-IP
X-Origin-Response-Time
X-Geo-Header
IsBot
Is-Eu
X-OVcl-Cache
L5d-Success-Class
X-Cache-Backend
X-Nc
X-ID
X-Request-URI
X-VG-TLSProxy
X-LB-ID
Apple-News-Services-Handled
X-VarnishDD-TTL
X-Scheme
X-Varnish-Beresp-Ttl
X-Generated-By
X-Slack-Backend
X-Swa-Ws
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
X-Matched-Rule
X-HN
X-Method
True-Client-Country-4JS
Apple-News-Services-Request-Url
Esi-Enabled
Vix-Hermes-Req-Id
X-Hash
X-Unique-ID
PFcat
Cf-Bgj
Origin
Cache-Host
L
Who
Lfy
Rt-Fastcgi-Cache
Country-Code
X-CLOUD-TRACE-CONTEXT
X-Gamma-Serve
Fastly-Drupal-HTML
X-Varnish-Hits
X-Goog-Meta-Goog-Reserved-File-Mtime
CloudFront-Viewer-Country
X-Varnish-Beresp-Status
X-Mvc-Supplant-OutputCached
X-Loc
X-Aicache-OS
X-APP-VERSION
X-CACHE-KEY
X-RateLimit-Limit
Sid
Geo-Info
Tcn
X-Cdn-Origin
X-NCache
X-Sn-Servicetimems
Pics-Label
X-Via-Poph
X-Via-Popn
X-Cache-Expires
Pramga
X-Varnish-Url
X-Via-Popv
X-Epic-Correlation-Id
X-PF-Uncompressing
X-Core-Mission
X-Cache-Date
X-Servername
Filterid
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
X-Refresh
Url
X-Tb-Optimization-Total-Bytes-Saved
X-Request-Start
X-TraceId
Cmsid
Cmstype
X-FireWall-Protection
Req-Svc-Chain
X-DC
X-NC
Kp-EeAlive
X-Error
X-Varnish-Cacheable
NGB
MIME-Version
X-Response-By
Cache-Key
X-Served-From
A
VivaBuild
Svr
Viewtype
X-Webkit-CSP-Report-Only
X-Erf-Stays-Bingo-Pdp-Web
Source
M-TraceId
X-Srv
Xkeyi7
X-Proxy-Cachei7
X-Cache-Remote
X-HS-Status
N-Cache
X-Wa
Server-Ttl
X-Air-Source
Cross-Origin-Opener-Policy
X-BBXSRF
Geoip-Latitude
HitType
GeoIp-Country-Code
S-Rt
Content-Secure-Policy
Server-ID
X-Servedbyhost
X-URL
X-Vgn-Hpd-Reason
Arc-Country
TDXMobile
X-CDN-Forward
X-HostName
X-B3-Spanid
X-Vcl-Version
X-Cache-2
NtCoent-Length
X-Cc-Req-Id
X-Contensis-Viewer-Groups
X-Esi
X-LI-Proto
X-LiteSpeed-Cache-Control
X-Cache-ASPX
D-Cc-Upstream
Resin-Trace
X-Cc-Via
X-Varnish-Authentication
X-JoinUs
Cteonnt-Length
X-Sucuri-Cache
Cross-Origin-Window-Policy
Ohc-File-Size
X-SaId
X-NGENIX-Cache
X-Host-Name
SID
CACHE
X-RAMCache
X-Edge-Location
X-Geo
X-Vc
X-Internal-Host
X-PHP-Backend
X-Li-Proto
X-Svr
X-HOST
X-VCL-Version
Hostname
X-Service
X-Server-IP
X-CCDN-CacheTTL
DataCenter
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
Request-ID
X-UA
X-WA
X-RPS
X-Viewer-Country
X-Cache-Config
X-TIM-N
X-API-Version
X-Newrelic-Synthetics
X-DI
X-RSL
FSS-Cache
X-Nyt-Route
GeoIP-Country-Code
X-Forwarded-Site
X-Origin-Time
GeoIP-Latitude
X-DB
X-DSS
X-DW
X-Via-NSCOPI
X-ServedByHost
X-FPC
X-RPM
X-Gdpr
X-Extlb
X-SN
X-App
X-Cs
X-Dynatrace
X-VC
CF-Cached-On
Cache-Provider
X-Bc-Bl
X-Check-Cacheable
Ohc-Cache-HIT
XServer
X-Accel-Expires-Debug
Mail-Subject
LB
Server-Id
ProcessTime
Surrogated-Key
X-ZONE
X-Action
X-Date
X-Region-Sid
X-Proxy-Upstream
X-Req
X-Webstats-RespID
X-SB
We-Hiring
X-NodeID
X-Dynatrace-Js-Agent
X-RateLimit-Remaining-Second
Mime-Version
X-RateLimit-Limit-Second
X-Oss-Cdn-Auth
X-PJAX-URL
X-VC-Cache
Env
Memcached
X-Server-Lifecycle-Phase
X-CF-Powered-By
X-SD-PageType
X-Kraken-Routeconfig-Destination
X-Kraken-Loop-Name
X-Fpc
X-Instrumentation
X-Provided-By
X-Swift-Error
Upgrade-Insecure-Requests
X-Depends-On
X-BBC-Edge-Cache-Status
X-FORWARDED-FOR
X-Rocket-Build-Number
X-Air-Trace-Id
X-Men
W
X-APP
X-Render-Time
X-Sigma-Backend
X-Sigma
X-Cdn-Request-ID
X-NGINX-Cache
Srv
X-TIME
X-CSRF-TOKEN
X-MSEdge-Features
X-MSEdge-Flight
X-BACKEND-TTL
CDN
X-UnsetCookies
X-Ftr-Cache-Host
VNS-Cache
X-Dw-Trace-Id
VNS-Age
Cdn
EpKe-Alive
CPC-Age
CPC-Cache
X-FTR-Cache-Host
X-Client-Ip
X-CACHE-AGE
X-Hello
Dnion-Transfer-Encoding
X-Flog
X-Auto-Login
X-Fastly-Backend-Reqs
Time
Processtime
Memory
X-ABtesting
X-Parent-Response-Time
X-Cache-Tag
X-Worker
X-Fastly-Request-Id
Datacenter
X-Akamai-Pragma-Client-IP
X-Ua
Media-Length
X-Oracle-DMS-ECID
X-Presslabs-Stats
X-Zone
X-Pad
Vha6-Origin
X-BBC-Origin-Response-Status
X-Acquia-Purge-Tags
X-Pf-Uncompressing
X-Cluster-Node
Proxy-Connection
X-Acquia-Application-Trace
X-Acquia-Application-UUID
X-Acquia-Site
Epwk-X-Cache
PICS-Label
X-ServerName
X-IN-APIGATEWAYSSL
Fastcgi-Cache-TTL
State
My-App
X-Via-PopV
X-IN-APIGATEWAY
X-Via-PopN
X-Via-PopH
X-LiteSpeed-Tag
X-Snapshot-Date
Cf-Ipcountry
X-Varnish-URL
X-Minions-Version
X-Akamai-ERRuleID
X-Request-URL
X-ElasticPress-Search
X-Varnish-Beresp-TTL
X-ElasticPress-Query
X-Akamai-ERPolicy
X-Vcache
X-MiniProfiler-Ids
Xet-Cookie
X-Lb-Id
X-Ms-Meta-Staticbatchstarttime
X-Edge-Location-Klb
X-Ms-Meta-Originalurl
X-Air-Pt
CountryCode
X-Litespeed-Cache-Control
X-C
X-Apw-Access-Action
X-Apw-Hits
X-Cache-Status-Check
X-Apw-Access-Token
X-Apw-Access-Object
Content-Style-Type
X-Request-Url
Content-Script-Type
X-Tid
NnCoection
OT-Force-Account-Verify
X-B3-Parentspanid
Phost
X-Debug-Cache-Store
Ohc-Response-Time
X-Traceid
Inserted-Into-Cache-At
X-Debug-Cache-Fetch
X-Amz-Meta-Cb-Modifiedtime
Environment
X-Redis-Count
URI
X-Redis-Duration-Ms
X-Storefront-Renderer-Verified