Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
X-XSS-Protection
CF-RAY
Cf-Request-Id
CF-Cache-Status
Last-Modified
Accept-Ranges
Link
Pragma
Expect-CT
ETag
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Cache-Status
X-Generator
X-Request-ID
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Content-Security-Policy
Content-Encoding
X-CDN
X-Envoy-Upstream-Service-Time
Status
Feature-Policy
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-AspNetMvc-Version
X-Xss-Protection
Access-Control-Max-Age
X-Via
Upgrade
Keep-Alive
X-Ws-Request-Id
X-Ua-Compatible
X-Turbo-Charged-By
X-Age
X-AH-Environment
X-Robots-Tag
Request-Context
X-Proxy-Cache
EagleId
X-Cache-Group
Server-Timing
X-Backend
X-Hacker
X-Amz-Request-Id
Report-To
X-Server
Host-Header
X-Amz-Id-2
X-Server-Powered-By
X-UA-Device
X-Nginx-Cache-Status
Grace
X-Dns-Prefetch-Control
X-LiteSpeed-Cache
X-Varnish-Cache
X-Rq
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Page-Speed
Cf-Railgun
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Amz-Version-Id
NEL
X-OneAgent-JS-Injection
Xkey
X-Cache-Spec
X-WebKit-CSP
Allow
X-Backend-Server
X-Host
X-Vhost
X-CST
X-Device
EagleEye-TraceId
X-Server-Id
Surrogate-Control
Request-Id
X-Dispatcher
X-Node
Content-Location
X-Response-Time
X-Akam-SW-Version
Accept-CH
X-Ruxit-JS-Agent
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Accept-CH-Lifetime
X-ASPNET-VERSION
X-Kinja-Server-Push
X-Template
X-Language
X-Ac
X-Application-Context
X-Country
X-Readtime
X-Cache-Lookup
X-Mod-Pagespeed
X-Cloud-Trace-Context
MS-Author-Via
X-B3-TraceId
X-Origin-Cache
Accept-Ch
Rating
X-Cnection
X-MS-InvokeApp
X-Url
Accept-Ch-Lifetime
X-HW
X-ORACLE-DMS-ECID
X-TtlSet
X-Vname
X-PC
X-Clacks-Overhead
X-ESI
Edge-Control
X-GitHub-Request-Id
X-Trace
X-Middleton-Display
X-Middleton-Response
X-Sol
Response
Pagespeed
Display
X-Content-Type
X-FastCGI-Cache
X-D2id
Verso
X-Vcap-Request-Id
X-Cdn-Fetch
X-Kinja
X-GoogleNews-Bot
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Exp-Variant
X-Kinja-Build
X-Exp-Id
Arr-Disable-Session-Affinity
X-Buckets
X-Goog-Hash
X-Rack-Cache
X-Varnish-TTL
X-Server-Name
X-Country-Code
Service-Worker-Allowed
X-Oneagent-Js-Injection
X-Navigation-Version
X-VARITI-CCR
X-Abt-Application-Version
X-Amz-Rid
X-ORACLE-DMS-RID
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
X-Powered-By-Plesk
X-Client-IP
X-Cache-TTL
X-SharePointHealthScore
SPRequestGuid
X-Release
X-Fastly-Request-ID
SPRequestDuration
SPIisLatency
X-TTL
X-MSEdge-Ref
X-Dw-Request-Base-Id
X-Element-Page-Cache
Fastly-Restarts
X-NF-Request-ID
X-Cached
X-Webkit-CSP
Public-Key-Pins
X-B3-TraceId-Primal
Mrf-Cache-Status
RTSS
MRF-Tech
X-Origin-Upstream-Status
AR-Request-ID
X-Edge
Ar-Sid
AR-PoweredBy
AR-CACHE
AR-ATIME
X-Px
X-SRCache-Fetch-Status
Access-Control-Request-Method
X-SRCache-Store-Status
X-LLID
Fusion-Template-Id
Fusion-Deployment-Id
Fusion-Source
X-Powered-CMS
Fusion-Content-Id
Fusion-Component-Id
Fusion-Content-Source
X-Ezoic-Cdn
X-Upstream
Content-MD5
X-Jurisdiction
X-HP-Webp
X-Pinterest-Direct
X-Ttl
X-Amz-Server-Side-Encryption
X-ECACHE
X-MCACHE
X-Mid
Charset
X-Recruiting
X-Content-Digest
X-Aspnetmvc-Version
S
X-Mg-S
Cache-Tag
X-PressLabs-Stats
X-Version
MicrosoftSharePointTeamServices
Fastcgi-Cache
X-Debug
Front-End-Https
TCN
X-Content-Security-Policy-Report-Only
X-T
X-Grace
X-Id
Filters
Cache-Tags
X-Kinsta-Cache
Server-Node
Edge-Cache-Tag
X-Forwarded-Proto
X-XRDS-Location
X-Yandex-Sdch-Disable
X-Logged-In
X-Amzn-Trace-Id
X-Correlation-Id
X-Accel-Expires
Server-Name
X-Forwarded-For
Surrogate-Key
Nginx-Cache
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Varnish-Age
X-Cache-Key
Powered-By-ChinaCache
X-B3-Sampled
TP-Cache
TP-L2-Cache
X-Ser
X-Request-Processing-Time
X-Request-Received
X-Microsite
X-Server-ID
X-Request-Handler-Origin-Region
X-Hits
X-DIS-Request-ID
X-DynaTrace
X-Az
X-AppVersion
X-Shield-Request-Id
X-Activity-Id
X-Amz-Replication-Status
X-F-Cache
X-HS-Hub-Id
X-HS-Combine-CSS
X-HS-Content-Id
X-HS-Cache-Config
X-Litespeed-Cache
Accept-Charset
X-FTR-Request-ID
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Metageneration
X-Origin-Server
X-Goog-Generation
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
X-Git-Hash
X-Hostname
X-Respond-Thread
X-Geo-Country
Nel
X-LB-Cache
X-DataDome
Section-Io-Cache
X-Upgrade-Enabled
X-Rid
X-Frontend
Cache
Access-Control-Allow-Method
X-Ruxit-Js-Agent
X-Cache-Age
X-Mobile-URL
Host
Alternate-Protocol
Cleartype
X-Type
Paypal-Debug-Id
Healthy
X-XRDS-LOCATION
MS-CV
X-IPLB-Instance
ServerID
X-Content-Options
X-AOL-HN
X-App-Environment
X-Varnish-Backend
Payment
X-Whom
X-WebKit-CSP-Report-Only
X-Request-Guid
X-Aspnet-Duration-Ms
X-Route-Name
X-B-Cache
X-Signature
X-Providence-Cookie
X-VCache
X-Flags
X-TT
X-Is-Crawler
X-Seen-By
X-Cache-Action
X-Page-Id
X-Debug-Info
Fastcgi-Useragent
X-Jobs
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Fastcgi-Cache
X-Mobile
X-Source
X-N
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Time
X-Erf-Bev-Bev
X-NWS-LOG-UUID
X-Load-Cache
X-Cached-By
X-RateLimit-Remaining
X-Akamai-Edgescape
X-Via-JSL
X-FB-Debug
Version
X-Daa-Tunnel
Viewport
X-Response-Served-From
X-Rule
X-Original-Request-Id
Refresh
X-Accel-Buffering
X-Drupal-Cache-Tags
DC
X-Cache-Operation
X-Cache-Rule
X-Proxy
X-Framework
X-Zen-Fury
X-Instance
Ms-Operation-Id
X-RemovedCookies
X-Cacheable-TTL
X-RTag
X-ProcessESI
DynaTrace
X-Tt-Trace-Host
X-Region
Referer-Policy
Realpath
X-Tt-Trace-Tag
X-Real-IP
X-Cache-Time
X-Contextid
X-HTML-Minification-Powered-By
Access-Control-Request-Headers
X-Wix-Request-Id
X-FW-Hash
X-FW-Static
X-Distributor
X-FW-Type
X-Page-View
X-Drupal-Cache-Contexts
X-FW-Serve
X-FW-Server
X-UUID
X-FW-Dynamic
X-Cache-Expired-At
X-L-Path
X-Environment-Context
X-Yottaa-Optimizations
X-Yottaa-Metrics
Countrycode
Eomportal-Instance
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
Node
X-B
GEO-INFO
X-Node-Name
Liferay-Portal
X-Cluster-Name
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-0
X-Cache-Control
X-Tumblr-Pixel-1
X-G
X-Content-Powered-By
X-IPS-LoggedIn
X-Cache-Hit
X-User-Agent
Server-Info
Webserver
X-Tumblr-Pixel-2
X-Amz-Meta-S3cmd-Attrs
Section-Io-Origin-Status
Section-Io-Id
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
SRV
From-Origin
X-Ratelimit-Limit
X-App-Server
Protected
X-Pass-Why
X-Revision
Ec-Rule-Version
X-Oracle-Dms-Rid
X-Protected-By
X-FireWall-Port
X-Backend-Name
Frame-Options
X-Cache-Server
Cache-Status
X-UPSTREAM-Address
X-Hl-Ver
X-Handled-By
X-ES-SERVER
X-RN-RSRV
X-Hyper-Cache
CF-IPCountry
Meta-Geo
X-Endurance-Cache-Level
X-Mode
X-FB-TRIP-ID
X-Www-Served-By
X-Forwarded-Host
X-Soup
Retry-After
X-NYM-Debug-Backend
X-Locale
X-Site-Version
X-Varnish-Ttl
X-Storage
TWC-GeoIP-Country
X-Cache-Grace
X-Be
X-Access
Webcakes-Region
X-Format
X-Web-Node
X-Pubstack
X-Origin-Hint
X-Section
X-Varnishpool
Webcakes-App-Name
TWC-Privacy
Fastly-SSL
Decoy-Debug-TTL
Decoy-Debug-Status
Decoy-Debug-Key
Property-Id
TWC-Connection-Speed
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-Device-Class
Cache-Tv-Group
Webcakes-App-Version
X-Adobe-Content
X-Adobe-Loc
X-Labrador-Cache-Channel
X-SayCDN-TTL
X-Origin-Date
X-Human
X-TT-LOGID
X-Say-TTL
X-Say-Cacheable
X-PHP-Host
X-PERF
X-PCL
X-Proto
X-Proxy-Build
X-Redis-Cache
X-OCL
X-UA-Device-Type
X-Timing-Wait
X-Uri
Cache-Name
Selected-Fe
Country
X-ApacheServer
X-Via-CDN
X-FW-Version
X-ProxyCache-Key
X-ProxyCache-Status
Azure-SlotName
Azure-SiteName
Azure-Version
X-Via-Fastly
X-BYPASS-REASON
X-No-Session
Azure-RegionName
X-LAGOON
X-Sql-Count
X-Sql-Duration-Ms
X-Server-W
X-AIR-PT
Azure-InstanceId
X-WA-Info
X-LJ-Flow-ID
X-AWS-Id
X-S-Maxage
X-FTR-Backend-Server
X-FTR-Backend
X-Qloud-Router
X-FTR-Balancer
X-TNCMS
X-FTR-Realm
X-FTR-DC
X-FTR-Cache-Status
X-Hosted-By
X-Loop
X-Country-Code-Real
Mn-Server-Ip
X-R9-Blue-Green-Version
X-Status
S-Cnection
Xserver
X-VWS-Id
X-MP-GENERATED-AT
X-Cache-TTL-Remaining
X-Ratelimit-Remaining
X-Request-Time
X-Cluster
X-Proxied
X-ShardId
X-CCM
X-Alternate-Cache-Key
X-Xfnlog-Site
X-Zipkin-Id
X-ShopId
X-Shopify-Stage
X-Storefront-Renderer-Rendered
X-FTR-Expires
X-Routing-Service
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Dynatrace
Cache-Hits
X-Tec-Api-Origin
X-Tec-Api-Root
X-Rendered-As
X-Cache-Var
X-Cache-Var-Map
AMP-Access-Control-Allow-Source-Origin
X-Is-Bot
X-Tec-Api-Version
X-Dc
X-Air-Hostname
X-Webkit-Csp
X-Device-Type
X-Cdn
X-Detected-As
X-Cache-Host
Apigw-Requestid
X-Amzn-Remapped-Content-Length
X-SRV
X-Amzn-RequestId
X-Amz-Apigw-Id
X-EdgeConnect-Cache-Status
X-Info
X-Microcachable
X-Nginx-Cache
X-Unique-Id
X-Cache-Enabled
SD-X-WS
X-Debug-IsPreview
X-Debug-IsConnected
X-Content-Age
X-Cache-Backend
X-Platform
X-Time-Microsecs
Tracecode
X-Varnish-Server
X-Backend-TTL
X-Varnish-Grace
X-ServerID
X-DynaTrace-JS-Agent
X-Azure-Ref
X-GEO
X-Erf-Stays-Bingo-Pdp-Web
Amp-Access-Control-Allow-Source-Origin
X-Backend-Host
Uber-Trace-Id
X-APP-VERSION
DSUID
X-Tb
X-GG-Cache-Date
X-Oss-Hash-Crc64ecma
X-Oss-Storage-Class
X-Oss-Object-Type
X-Oss-Server-Time
X-Oss-Request-Id
Akamai-GRN
X-Proxy-Cache-Status
X-Correlation-ID
X-BCube-Filmed-By
X-NewRelic-App-Data
Backend
PB-PID
X-CSRF-Token
X-ATG-Version
PB-RID
X-Sucuri-ID
Arc-Version
X-Akamai-Transformed
X-Magnolia-Registration
X-Trace-Id
DCR-Decision-By
X-Fetched-On
T-Server
X-Origin-TTL
DCR-Processing-Time-Ms
X-Aed
X-PBS-Appsvrname
SR-User-Adfree
Rendered-Blocks
X-Processor
X-Device-Os
X-GeoIP-City
BehaviorPad-Version
X-External-Request-Id
X-PAYTM-SRV-ID
Thinkindot-CacheControl
X-Level-Front-Cache
X-A
Thinkindot-Control
X-A-Ccd
X-A-Dcw
X-A-Dam
X-Location
X-Generated-On
Thinkindot-CacheControl-Type
X-Origin-CC
Xc-Version
X-Vtex-Remote-Cache
ServedBy
X-A-Dgt
X-Matched-Rule
X-From
X-RCS-CacheZone
X-Request-UUID
X-Trv-Group
X-Thinkindot-L3
X-S-Cookie
MD5-Digest
Machine
X-Rojux
X-S
Meta-Geo-Continent
Mobile-Detection-Method
X-Session-Fingerprint
Pramga
X-ScT
X-Generation-Time
Odigeo-Trace-Id
Release
X-SRCache-Key
X-Vdms-Path
X-Vdms-Version
Fastcgi-X-Cache-Version
X-D
X-Application
X-Destination
Expiry
X-Vtex-Processado-Em
X-Rewrite-Enabled
X-Connection-Hash
X-CF-Lambda-Version
X-Cache-NE
X-B-Cookie
Lfy
X-CF-Lambda-Fn
Instruction
X-VG-WebServer
X-VG-WebCache
X-ARC
X-A-Wwc
X-Origin-Response-Time
X-Cache-PHP
X-Cache-NGX
X-Bip
X-Cache-Bucket
X-Backend-State
X-Azure-Ref-OriginShield
Wxu-Next-Region
X-Adobe-Source
X-Cache-Date
X-Cache-Info
X-Developers
X-Eu-Site
X-Csrf-Jwt
X-CGP
X-Cdn-Origin
Wxu-Next-Hostname
Gh-Request-Id
Magicmarker
X-B3-Traceid
Locid
L5d-Success-Class
Host-ID
Pagetype
Path
Wxu-Next-Commit
X-FC-Vary-Parameters
UCS
Ha-Gx-Prefs
PFcat
HA-Ipaddr
X-Geo-Header
X-SVT-ORM-VERSION
X-Thanos
X-SVT-ORM-RULES
X-Sn-Servicetimems
X-Request-URI
X-Skip-Cache
X-Tumblr-Pixel-3
X-User
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-VServer
X-Cache-Remote
X-VarnishDD-TTL
X-Reqid
X-Owner
X-HN
X-HS-Content-Campaign-Id
X-Has-Esi
X-GeoIP
Fastly-Backend-Name
X-Irp-Debug
X-Is-Gdpr
X-Node-Id
X-OVcl-Cache
X-Mvc-Supplant-Cachable
X-Micro-Cache
X-JWT-State
X-Generated-In
X-OVcl
C-Via
X-Varnish-Cache-Hits
Cf-Device-Type
X-Varnish-Hostname
X-Ms-Version
CacheControlHeader
AKAMAI
X-Ms-Request-Id
X-NWS-UUID-VERIFY
DB-Nickname
X-Debug-Cache
X-Envoy-Decorator-Operation
Server-Ext
Server-Host
Server-Hostname
User-Cache-Control
Apple-News-Services-Handled
X-Fastly-Cache
X-Fastly-Backend
X-Nginx-Cache-Key
X-Policy
Sever-Int
X-CUA
Cache-Host
X-Core-Value
V-Age
X-Origin-Expires
X-Swa-Ws
X-Developer
Ssr
X-Clientip
X-Cache-Tags
Apple-News-Services-Host
CloudFront-Viewer-Country
X-Generated-By
X-Method
X-IP
Content-Disposition
X-Request-Host
X-Request-Start
L
X-TrackingId
Apple-News-Services-Parsed-Url
X-Cms-Context
X-Scheme
On-Server
Apple-News-Services-Request-Url
NGX
Cf-Bgj
CDCHOST
X-Var-Ttl
X-ID
X-NC
X-Variation
X-Cache-Id
X-Cache-Debug
X-Old-Content-Length
X-Branch-Name
X-TX-ID
X-Clara-WADP
X-Esi-Check
X-Li-Pop
X-Li-Fabric
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Ratelimit-Reset
X-LI-UUID
X-Origin
X-NU-AKA-ACS-Version
X-Platform-Server
X-Hnp-Log
X-Gzip
X-Dispatcher-Server
Adler-Geo
X-DefHash
X-DPWN-IS-SECURE
X-SIPLIST1
X-GoCache-CacheStatus
X-Gen-Mode
X-Fmm-Version
X-DefElseHash
X-Block-Status
Platform
X-VG-TLSProxy
True-Client-Country-4JS
X-Varnish-Hits
X-Varnish-Beresp-Grace
Rt-Fastcgi-Cache
X-WADP-Cache
Location
Vix-Hermes-Req-Id
Web-Mar-Node
X-Varnish-CookieINHashed-On
X-Varnish-Remaining-TTL
Is-Eu
Fastly-SIE
Fastly-SWR
IsBot
NM-Fastcgi-Cache
X-Varnish-CookieHashed-On
HostName
X-App-Version
X-NCache
X-Host-Name
X-Loc
CDN-PullZone
CDN-RequestCountryCode
CDN-Uid
X-Slack-Backend
X-Gamma-Serve
X-Servername
Origin
CDN-RequestId
X-NAPM-TraceId
X-Hash
X-Varnish-Beresp-Ttl
CDN-Cache
X-Varnish-Url
X-Cache-Expires
CDN-EdgeStorageId
CDN-CachedAt
CACHE
X-Varnish-Beresp-Status
X-CS
X-Varnish-Cacheable
S-Rt
X-EC-Lua
X-PF-Uncompressing
X-Cdn-Forward
X-B3-Spanid
X-Response-By
X-Core-Mission
X-Goog-Meta-Goog-Reserved-File-Mtime
Fastly-Drupal-HTML
Url
X-B3-SpanId
X-Mvc-Supplant-OutputCached
X-Aicache-OS
X-CACHE-GROUP
X-Proxy-Cachei7
Xkeyi7
X-TA-CDN-Provider
Pics-Label
X-Refresh
X-LB-ID
X-BBXSRF
Cross-Origin-Window-Policy
N-Cache
Sid
X-Cache-2
X-FireWall-Protection
Content-Secure-Policy
Ohc-File-Size
X-Sucuri-Cache
X-CDN-Forward
X-Unique-ID
X-Contensis-Viewer-Groups
Esi-Enabled
X-Varnish-Authentication
X-Via-Popv
X-Via-Popn
X-Cc-Via
X-Cache-ASPX
Cteonnt-Length
X-Via-Poph
D-Cc-Upstream
X-Cc-Req-Id
X-Svr
X-Tb-Optimization-Total-Bytes-Saved
X-Error
X-Srv
X-Epic-Correlation-Id
X-Servedbyhost
X-Wa
X-Server-IP
MIME-Version
Source
X-Cs
X-TraceId
X-Webkit-CSP-Report-Only
X-Cache-Config
X-Gdpr
X-DC
X-FPC
Who
GeoIp-Country-Code
Geoip-Latitude
Req-Svc-Chain
HitType
X-Nc
X-Nyt-Route
X-API-Version
Geo-Info
X-Origin-Time
Country-Code
X-RateLimit-Limit
X-CLOUD-TRACE-CONTEXT
X-SN
X-Planisys-CDN-Cache
Server-Ttl
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-VC
X-Fastly-Request-Id
Hostname
X-NGINX-Cache
Ohc-Cache-HIT
X-TIME
X-URL
X-HS-Status
X-LI-Proto
X-NodeID
XServer
X-LiteSpeed-Cache-Control
X-Webstats-RespID
X-SB
X-CACHE-KEY
Kp-EeAlive
X-Esi
Svr
Server-ID
X-VCL-Version
Cmsid
Cmstype
X-Check-Cacheable
X-SD-PageType
X-Served-From
X-Render-Time
Viewtype
X-Ua
VivaBuild
NtCoent-Length
X-HOST
EpKe-Alive
SID
X-Viewer-Country
Tcn
A
Request-ID
X-Vgn-Hpd-Reason
X-Vcl-Version
X-BBC-Edge-Cache-Status
Cache-Key
X-UA
X-Worker
X-RAMCache
X-Auto-Login
X-CCDN-CacheTTL
M-TraceId
X-DB
X-Li-Proto
Resin-Trace
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
X-DSS
X-TIM-N
X-RSL
X-RPS
X-RPM
Cache-Provider
X-DI
X-DW
X-Ftr-Cache-Host
Server-Id
ProcessTime
Cross-Origin-Opener-Policy
X-Air-Source
GeoIP-Country-Code
GeoIP-Latitude
Arc-Country
TDXMobile
X-Dynatrace-Js-Agent
X-CSRF-TOKEN
Processtime
CDN
X-Internal-Host
X-App
X-Action
X-Cluster-Node
X-CF-Powered-By
Upgrade-Insecure-Requests
X-Geo
X-Newrelic-Synthetics
X-FTR-Cache-Host
X-ServedByHost
Filterid
X-Oss-Cdn-Auth
X-Fpc
X-Vc
X-WA
CF-Cached-On
X-Service
Mime-Version
Proxy-Connection
Datacenter
X-BBC-Origin-Response-Status
Srv
X-FORWARDED-FOR
X-HITS
X-HostName
OT-Force-Account-Verify
X-Via-PopH
X-Via-PopN
X-Via-PopV
Cdn
X-MSEdge-Flight
WZWS-RAY
X-Dw-Trace-Id
NGB
X-ND-Cache
X-MSEdge-Features
X-BACKEND-TTL
X-Fastly-Backend-Reqs
X-Client-Ip
X-CACHE-AGE
DataCenter
FSS-Cache
W
X-Via-NSCOPI
X-Flog
X-IN-APIGATEWAY
X-Lb-Id
X-Parent-Response-Time
X-IN-APIGATEWAYSSL
X-Forwarded-Site
X-ABtesting
X-Hello
X-Cache-Tag
Dnion-Transfer-Encoding
X-Edge-Location
X-PHP-Backend
X-JoinUs
X-NGENIX-Cache
X-Cdn-Request-ID
X-SaId
X-Oracle-DMS-ECID
Media-Length
PICS-Label
X-Presslabs-Stats
X-Extlb
X-Pf-Uncompressing
Vha6-Origin
X-Pad
X-Date
X-PJAX-URL
X-Bc-Bl
X-Accel-Expires-Debug
X-Proxy-Upstream
Mail-Subject
LB
Epwk-X-Cache
Memcached
Surrogated-Key
X-RateLimit-Remaining-Second
We-Hiring
X-RateLimit-Limit-Second
X-LiteSpeed-Tag
X-Swift-Error
URI
X-MiniProfiler-Ids
X-Region-Sid
X-Akamai-Pragma-Client-IP
X-VC-Cache
X-UnsetCookies
X-Provided-By
X-Req
X-Depends-On
X-ZONE
Cf-Ipcountry
X-Acquia-Application-UUID
X-Varnish-Beresp-TTL
X-B3-Parentspanid
Env
X-ElasticPress-Query
Time
Memory
X-Acquia-Purge-Tags
X-Acquia-Application-Trace
X-Request-URL
X-Ms-Meta-Staticbatchstarttime
X-Akamai-ERRuleID
X-ElasticPress-Search
X-Akamai-ERPolicy
X-Rocket-Build-Number
X-APP
X-Csrf-Token
X-Sigma-Backend
X-Sigma
X-Acquia-Site
X-Request-Url
X-Akamai-Request-ID
X-Ms-Meta-Originalurl
Xet-Cookie
X-Vcache
CountryCode
X-Air-Trace-Id
X-Men
X-Varnish-URL
X-Zone
X-Tid
Inserted-Into-Cache-At
Content-Style-Type
X-Litespeed-Cache-Control
Content-Script-Type
X-C
X-ServerName
X-Via-SSL
X-Via-Edge
Edge-Copy-Time
X-Acc-Rdl
X-Acc-Debug-Context
X-Storefront-Renderer-Verified
Environment
Phost
Ohc-Response-Time
X-Debug-Cache-Fetch
NnCoection
X-Traceid
X-Redis-Count
X-Redis-Duration-Ms
X-Snapshot-Date
X-Debug-Cache-Store