Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
X-XSS-Protection
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-UA-Compatible
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Request-ID
X-Xss-Protection
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
X-Ua-Compatible
Content-Encoding
X-CDN
X-Envoy-Upstream-Service-Time
X-AspNetMvc-Version
Feature-Policy
Status
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Access-Control-Max-Age
Upgrade
X-Via
Keep-Alive
X-Ws-Request-Id
X-Age
X-Turbo-Charged-By
X-Robots-Tag
X-AH-Environment
Request-Context
X-Proxy-Cache
EagleId
X-Cache-Group
Server-Timing
X-Backend
X-Hacker
X-Server
Report-To
X-Amz-Request-Id
Host-Header
X-Server-Powered-By
X-Amz-Id-2
Grace
X-Nginx-Cache-Status
X-UA-Device
X-Rq
X-Varnish-Cache
X-LiteSpeed-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Page-Speed
X-Dns-Prefetch-Control
Cf-Railgun
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
NEL
X-Amz-Version-Id
X-Cache-Spec
X-WebKit-CSP
Xkey
X-Device
Allow
X-CST
X-Backend-Server
X-Vhost
X-Host
EagleEye-TraceId
X-Server-Id
Surrogate-Control
Request-Id
X-Dispatcher
X-Node
Content-Location
X-Response-Time
X-Ruxit-JS-Agent
Accept-CH
X-Akam-SW-Version
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Accept-CH-Lifetime
X-Ac
P3p
X-ASPNET-VERSION
X-Application-Context
X-Template
X-Language
X-Country
X-Cache-Lookup
X-Mod-Pagespeed
X-Readtime
X-Cloud-Trace-Context
MS-Author-Via
X-B3-TraceId
X-Origin-Cache
Rating
X-Cnection
Accept-Ch
X-MS-InvokeApp
X-HW
X-Url
X-TtlSet
X-PC
X-Vname
Accept-Ch-Lifetime
X-Clacks-Overhead
X-GitHub-Request-Id
X-ORACLE-DMS-ECID
Edge-Control
X-ESI
X-Trace
X-FastCGI-Cache
X-Middleton-Response
X-Sol
X-Middleton-Display
Response
Display
Pagespeed
X-Content-Type
X-D2id
X-Cdn-Fetch
X-Exp-Variant
X-Kinja-Server
X-Use-Magma
Arr-Disable-Session-Affinity
X-Kinja-Revision
X-Kinja-Build
X-Vcap-Request-Id
X-Kinja
X-Exp-Id
X-GoogleNews-Bot
Verso
X-Goog-Hash
X-Buckets
X-Rack-Cache
X-Country-Code
X-ORACLE-DMS-RID
X-Server-Name
X-Varnish-TTL
Service-Worker-Allowed
X-Navigation-Version
X-VARITI-CCR
X-Abt-Application-Version
X-Amz-Rid
X-Fastly-Request-ID
X-Powered-By-Plesk
X-Client-IP
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
X-Cache-TTL
X-Webkit-CSP
X-Release
Fastly-Restarts
X-SharePointHealthScore
SPRequestGuid
X-MSEdge-Ref
X-Element-Page-Cache
X-Dw-Request-Base-Id
X-Cached
SPIisLatency
SPRequestDuration
X-Kinja-Server-Push
X-TTL
X-NF-Request-ID
X-Oneagent-Js-Injection
Public-Key-Pins
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
RTSS
AR-ATIME
AR-CACHE
Ar-Sid
X-Edge
AR-Request-ID
Access-Control-Request-Method
AR-PoweredBy
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Powered-CMS
X-LLID
X-Origin-Upstream-Status
X-Ezoic-Cdn
X-Px
X-Upstream
X-Ttl
Content-MD5
Fusion-Content-Source
Fusion-Deployment-Id
Fusion-Component-Id
Fusion-Source
Fusion-Content-Id
Fusion-Template-Id
Cache-Tag
X-Jurisdiction
X-HP-Webp
X-MCACHE
X-Mid
X-ECACHE
S
X-Version
X-Recruiting
X-Mg-S
X-Content-Digest
Charset
X-Amz-Server-Side-Encryption
X-PressLabs-Stats
Fastcgi-Cache
TCN
X-T
X-Kinsta-Cache
MicrosoftSharePointTeamServices
X-Content-Security-Policy-Report-Only
Front-End-Https
X-Id
Cache-Tags
X-Pinterest-Direct
Filters
X-Litespeed-Cache
X-Debug
X-Grace
Edge-Cache-Tag
Server-Node
X-Accel-Expires
X-Logged-In
X-Forwarded-Proto
X-Forwarded-For
X-DynaTrace
X-Amzn-Trace-Id
Server-Name
Nginx-Cache
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
TP-Cache
TP-L2-Cache
X-Correlation-Id
X-Yandex-Sdch-Disable
Surrogate-Key
X-Varnish-Age
X-B3-Sampled
X-Request-Processing-Time
X-Request-Received
X-Microsite
X-Request-Handler-Origin-Region
X-XRDS-LOCATION
X-Ser
X-Shield-Request-Id
X-Hits
X-Az
X-Activity-Id
X-AppVersion
X-Amz-Replication-Status
X-DIS-Request-ID
X-Server-ID
X-HS-Combine-CSS
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Content-Id
X-GUploader-UploadID
X-F-Cache
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Metageneration
X-Cache-Key
X-Origin-Server
Accept-Charset
X-XRDS-Location
X-Geo-Country
X-Git-Hash
Powered-By-ChinaCache
X-Respond-Thread
X-FTR-Request-ID
Cache
X-Rid
Alternate-Protocol
X-LB-Cache
Section-Io-Cache
X-Frontend
X-DataDome
X-Upgrade-Enabled
Host
X-Hostname
Access-Control-Allow-Method
X-Mobile-URL
X-Seen-By
X-Cache-Age
Cleartype
Paypal-Debug-Id
MS-CV
X-AOL-HN
Healthy
X-IPLB-Instance
X-Type
X-Content-Options
X-Varnish-Backend
X-Ruxit-Js-Agent
X-NWS-LOG-UUID
X-VCache
X-Whom
ServerID
X-App-Environment
X-Flags
X-Aspnet-Duration-Ms
X-Providence-Cookie
X-Is-Crawler
X-Route-Name
X-WebKit-CSP-Report-Only
X-Request-Guid
X-TT
X-Cache-Action
Payment
X-Page-Id
X-Jobs
X-B-Cache
X-Debug-Info
X-Signature
X-Time
Fastcgi-Useragent
X-N
X-Source
X-Load-Cache
X-Mobile
X-Fastcgi-Cache
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Daa-Tunnel
X-FB-Debug
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Browser-Type
X-Via-JSL
X-RateLimit-Remaining
Version
Nel
X-Cached-By
Refresh
X-Cache-Operation
X-Cache-Rule
X-Akamai-Edgescape
X-Original-Request-Id
X-Response-Served-From
X-Wix-Request-Id
X-Accel-Buffering
X-Rule
Viewport
X-Cacheable-TTL
X-Proxy
X-Drupal-Cache-Tags
DC
X-Framework
X-RTag
X-Contextid
Access-Control-Request-Headers
Ms-Operation-Id
X-RemovedCookies
X-ProcessESI
Node
Realpath
X-Real-IP
X-Instance
X-Zen-Fury
X-Cache-Time
X-HTML-Minification-Powered-By
DynaTrace
X-Region
X-UUID
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Page-View
Eomportal-Instance
X-Tt-Trace-Host
X-Distributor
X-Tt-Trace-Tag
X-Drupal-Cache-Contexts
Referer-Policy
X-FW-Serve
X-FW-Server
X-FW-Type
X-FW-Static
Countrycode
X-FW-Hash
X-FW-Dynamic
X-Cluster-Name
X-Cache-Expired-At
X-B
VIX-Pulpo-Upstream-Status
X-Content-Powered-By
X-Cache-Control
VIX-Pulpo-Node
X-Environment-Context
GEO-INFO
X-IPS-LoggedIn
X-L-Path
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel-1
X-Cache-Hit
X-G
Liferay-Portal
X-Ratelimit-Limit
Server-Info
X-App-Server
X-User-Agent
X-Pass-Why
X-FireWall-Port
X-Node-Name
Section-Io-Id
Section-Io-Origin-Status
Section-Origin-Responded
Webserver
Section-Io-Origin-Time-Seconds
From-Origin
X-Tumblr-Pixel-2
Ec-Rule-Version
X-Varnish-Ttl
X-Protected-By
Protected
Xserver
CF-IPCountry
X-Cache-Server
SRV
X-Ratelimit-Remaining
X-Www-Served-By
X-Amz-Meta-S3cmd-Attrs
Frame-Options
X-Backend-Name
X-Revision
X-Handled-By
X-Mode
X-Hl-Ver
X-RN-RSRV
Meta-Geo
X-Endurance-Cache-Level
X-ES-SERVER
X-UPSTREAM-Address
X-Locale
X-Hyper-Cache
X-FB-TRIP-ID
X-Soup
X-Site-Version
Cache-Status
X-Storage
X-NYM-Debug-Backend
X-Forwarded-Host
X-Varnishpool
Country
X-Web-Node
X-Human
X-Cache-Grace
X-Be
Cache-Tv-Group
Cache-Name
Azure-Version
Decoy-Debug-TTL
Fastly-SSL
Decoy-Debug-Key
Decoy-Debug-Status
Azure-RegionName
X-Uri
X-Proto
X-Proxy-Build
X-Pubstack
X-ProxyCache-Status
X-Origin-Hint
X-Origin-Date
Azure-SiteName
Azure-InstanceId
X-Request-Time
X-Redis-Cache
Azure-SlotName
X-TT-LOGID
Retry-After
TWC-GeoIP-LatLong
TWC-GeoIP-Country
X-UA-Device-Type
TWC-Locale-Group
Webcakes-Region
Webcakes-App-Name
TWC-Privacy
Webcakes-App-Version
TWC-Device-Class
X-Timing-Wait
X-BYPASS-REASON
X-ProxyCache-Key
TWC-Connection-Speed
X-Labrador-Cache-Channel
Selected-Fe
X-PHP-Host
Property-Id
X-AIR-PT
X-Format
X-PCL
X-Access
X-Adobe-Content
X-S-Maxage
X-Hosted-By
X-FW-Version
X-Loop
X-No-Session
X-Adobe-Loc
X-OCL
X-MP-GENERATED-AT
X-Via-Fastly
X-Say-Cacheable
X-Tec-Api-Version
X-Tec-Api-Root
X-Say-TTL
X-Sql-Duration-Ms
X-SayCDN-TTL
X-Section
X-Server-W
X-Sql-Count
X-Tec-Api-Origin
X-TNCMS
X-LAGOON
X-ApacheServer
X-VWS-Id
X-Nginx-Cache
X-PERF
X-Status
X-AWS-Id
X-WA-Info
X-LJ-Flow-ID
X-Cluster
X-R9-Blue-Green-Version
Mn-Server-Ip
X-ShopId
X-Device-Type
X-Alternate-Cache-Key
X-Proxied
X-Storefront-Renderer-Rendered
X-ShardId
X-Sorting-Hat-PodId
X-Zipkin-Id
X-Routing-Service
X-Cache-TTL-Remaining
X-Shopify-Stage
X-Sorting-Hat-ShopId
X-Rendered-As
X-Is-Bot
X-CCM
X-Xfnlog-Site
X-Via-CDN
X-Debug-IsConnected
X-Debug-IsPreview
X-FTR-Backend
X-FTR-Balancer
X-FTR-DC
X-FTR-Cache-Status
X-Dc
X-FTR-Backend-Server
S-Cnection
X-FTR-Realm
X-Country-Code-Real
X-Qloud-Router
Cache-Hits
X-Info
Apigw-Requestid
X-SRV
X-Varnish-Grace
X-FTR-Expires
AMP-Access-Control-Allow-Source-Origin
X-Varnish-Server
X-Detected-As
X-Cache-Enabled
X-Cdn
X-GG-Cache-Date
X-Amzn-Remapped-Content-Length
X-Unique-Id
X-EdgeConnect-Cache-Status
X-Content-Age
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Microcachable
X-Air-Hostname
X-Platform
X-Cache-Host
X-Cache-Var-Map
X-Cache-Var
X-Azure-Ref
Uber-Trace-Id
X-Correlation-ID
X-Backend-Host
SD-X-WS
Tracecode
X-Aspnetmvc-Version
X-DynaTrace-JS-Agent
X-CSRF-Token
X-Proxy-Cache-Status
Amp-Access-Control-Allow-Source-Origin
X-Time-Microsecs
X-GEO
X-NWS-UUID-VERIFY
X-Backend-TTL
X-ServerID
Akamai-GRN
X-ATG-Version
X-APP-VERSION
X-Tb
X-Cache-Backend
X-Oss-Request-Id
X-Oss-Storage-Class
X-Oss-Server-Time
X-Oss-Object-Type
X-Trace-Id
X-Oss-Hash-Crc64ecma
Backend
X-BCube-Filmed-By
DSUID
X-Varnish-Hostname
ServedBy
X-Akamai-Transformed
X-RCS-CacheZone
X-Cache-PHP
X-Cache-NGX
X-TA-CDN-Provider
X-Oracle-Dms-Rid
X-Cache-NE
Rendered-Blocks
X-Magnolia-Registration
X-CF-Lambda-Fn
X-PBS-Appsvrname
SR-User-Adfree
X-Thinkindot-L3
X-VG-WebServer
X-Vtex-Remote-Cache
X-CF-Lambda-Version
X-Connection-Hash
Release
Path
Thinkindot-Control
X-External-Request-Id
X-Device-Os
X-D
X-Destination
X-Vtex-Processado-Em
X-B-Cookie
Arc-Version
X-Vdms-Path
X-A-Ccd
X-A-Dam
X-A-Dcw
X-A
X-Vdms-Version
Thinkindot-CacheControl-Type
X-Debug-Cache
X-VG-WebCache
PB-RID
X-A-Dgt
X-Application
X-ARC
T-Server
X-Trv-Group
X-Aed
X-Varnish-Cache-Hits
X-A-Wwc
Thinkindot-CacheControl
X-SRCache-Key
X-Fetched-On
X-Matched-Rule
BehaviorPad-Version
X-Origin-CC
X-Location
X-Level-Front-Cache
X-From
Lfy
Instruction
X-Sucuri-ID
Fastcgi-X-Cache-Version
DCR-Decision-By
X-Processor
X-PAYTM-SRV-ID
DCR-Processing-Time-Ms
X-Origin-TTL
X-Request-UUID
Expiry
X-Rewrite-Enabled
Machine
Odigeo-Trace-Id
X-S-Cookie
HostName
X-ScT
X-Dynatrace
X-Generation-Time
Mobile-Detection-Method
X-Session-Fingerprint
Meta-Geo-Continent
X-Generated-On
X-Rojux
MD5-Digest
Xc-Version
PB-PID
X-S
X-GeoIP-City
X-NewRelic-App-Data
X-Erf-Stays-Bingo-Pdp-Web
X-VServer
Pagetype
Host-ID
Gh-Request-Id
Ssr
Fastly-Backend-Name
X-Cache-Bucket
X-Is-Gdpr
X-JWT-State
X-Irp-Debug
X-HS-Content-Campaign-Id
X-GeoIP
X-Has-Esi
X-Micro-Cache
X-Mvc-Supplant-Cachable
X-OVcl
X-OVcl-Cache
X-Reqid
X-Origin-Response-Time
X-Node-Id
Cf-Device-Type
X-Skip-Cache
X-Thanos
X-Swa-Ws
X-Azure-Ref-OriginShield
X-TrackingId
X-Tumblr-Pixel-3
X-SVT-ORM-VERSION
X-Bip
X-FC-Vary-Parameters
X-Sn-Servicetimems
X-Owner
X-SVT-ORM-RULES
X-Cdn-Origin
UCS
X-Geo-Header
Cache-Host
C-Via
X-Ms-Request-Id
CacheControlHeader
X-Ms-Version
AKAMAI
X-TX-ID
X-Core-Value
X-Clientip
X-CGP
X-Developer
X-Csrf-Jwt
X-Cache-Tags
X-CUA
X-Developers
X-Adobe-Source
X-NAPM-TraceId
Sever-Int
Server-Hostname
Wxu-Next-Commit
Wxu-Next-Hostname
X-Backend-State
X-Eu-Site
Wxu-Next-Region
X-Cache-Info
X-B3-Traceid
X-Request-Host
X-App-Version
X-Policy
X-Origin-Expires
X-VarnishDD-TTL
X-Scheme
X-User
X-Var-Ttl
X-Varnish-Beresp-Grace
X-Varnish-Hits
X-Nginx-Cache-Key
X-Wikidot-Backend
X-Generated-In
X-Generated-By
Server-Ext
X-Fastly-Cache
X-HN
X-IP
X-Wikidot-Static-Cache
DB-Nickname
Server-Host
X-Fastly-Backend
X-Cms-Context
Locid
Magicmarker
On-Server
PFcat
Location
L5d-Success-Class
CloudFront-Viewer-Country
Content-Disposition
Ha-Gx-Prefs
HA-Ipaddr
Pramga
L
X-B3-SpanId
User-Cache-Control
X-Gen-Mode
X-DefElseHash
X-Gamma-Serve
X-DefHash
Rt-Fastcgi-Cache
IsBot
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Branch-Name
X-Cache-Id
X-Dispatcher-Server
X-Fmm-Version
Cf-Bgj
NGX
X-Clara-WADP
X-Li-Fabric
X-Gzip
X-DPWN-IS-SECURE
X-Envoy-Decorator-Operation
X-Esi-Check
X-Hash
X-Hnp-Log
CDCHOST
X-Request-URI
Fastly-Drupal-HTML
X-Ratelimit-Reset
X-Cdn-Forward
X-Varnish-Beresp-Ttl
X-SIPLIST1
X-Servername
X-Varnish-Beresp-Status
X-Platform-Server
X-NU-AKA-ACS-Version
NM-Fastcgi-Cache
Platform
X-Li-Pop
X-Loc
Is-Eu
X-WADP-Cache
Adler-Geo
X-Method
X-Slack-Backend
V-Age
X-Varnish-CookieHashed-On
X-Variation
Origin
X-Cache-Date
X-Origin
X-Varnish-CookieINHashed-On
X-LI-UUID
Web-Mar-Node
X-Old-Content-Length
X-Block-Status
X-Varnish-Remaining-TTL
X-ID
Fastly-SWR
X-Cache-Expires
True-Client-Country-4JS
Apple-News-Services-Host
X-GoCache-CacheStatus
Vix-Hermes-Req-Id
Apple-News-Services-Request-Url
Apple-News-Services-Handled
Apple-News-Services-Parsed-Url
X-Rebelmouse-Surrogate-Control
Fastly-SIE
X-Rebelmouse-Cache-Control
X-Core-Mission
X-VG-TLSProxy
X-EC-Lua
X-CS
Sid
X-Request-Start
CDN-RequestId
CDN-Uid
X-LB-ID
CDN-RequestCountryCode
X-NCache
CDN-PullZone
X-PF-Uncompressing
CDN-EdgeStorageId
CDN-CachedAt
CDN-Cache
X-Mvc-Supplant-OutputCached
X-Aicache-OS
X-Cache-Debug
X-Refresh
X-Varnish-Url
X-Cache-Remote
Url
X-NC
X-Via-Popn
X-Via-Popv
X-Via-Poph
Esi-Enabled
X-CACHE-GROUP
X-Nc
S-Rt
X-Response-By
X-Varnish-Cacheable
X-B3-Spanid
X-CACHE-KEY
Who
Xkeyi7
X-Host-Name
X-FireWall-Protection
Pics-Label
Country-Code
X-Epic-Correlation-Id
X-Proxy-Cachei7
X-BBXSRF
X-Tb-Optimization-Total-Bytes-Saved
X-TraceId
N-Cache
X-Unique-ID
Ohc-File-Size
Server-Ttl
Req-Svc-Chain
X-Error
X-Planisys-CDN-Cache
Source
X-Planisys-CDN-Rules
Content-Secure-Policy
X-Cache-2
X-Webkit-Csp
X-Planisys-CDN-TTL
Cross-Origin-Window-Policy
X-Srv
X-Cc-Via
D-Cc-Upstream
GeoIp-Country-Code
X-Varnish-Authentication
X-Contensis-Viewer-Groups
X-HS-Status
X-Sucuri-Cache
X-Cache-ASPX
X-Cc-Req-Id
Geoip-Latitude
X-Webkit-CSP-Report-Only
X-CDN-Forward
Kp-EeAlive
HitType
X-Cs
X-Svr
X-LiteSpeed-Cache-Control
X-DC
Cteonnt-Length
X-CLOUD-TRACE-CONTEXT
CACHE
Geo-Info
Cmstype
Cmsid
X-RateLimit-Limit
Svr
X-Wa
X-Served-From
X-Server-IP
X-Servedbyhost
MIME-Version
X-URL
X-Cache-Config
X-FPC
X-Gdpr
X-Origin-Time
Filterid
X-API-Version
X-Vcl-Version
A
Cache-Key
X-Nyt-Route
VivaBuild
Viewtype
Resin-Trace
X-Esi
X-RAMCache
X-Li-Proto
M-TraceId
Server-Id
X-SN
X-VC
Ohc-Cache-HIT
X-SB
Arc-Country
TDXMobile
X-Air-Source
Server-ID
X-Vgn-Hpd-Reason
X-TIME
X-NodeID
Cross-Origin-Opener-Policy
X-Webstats-RespID
X-LI-Proto
Hostname
X-HOST
X-HostName
NtCoent-Length
X-NGINX-Cache
SID
X-Check-Cacheable
NGB
Request-ID
X-VCL-Version
X-SD-PageType
X-Viewer-Country
Tcn
X-UA
X-CCDN-Origin-Time
X-Vc
X-RPM
X-RSL
X-ServedByHost
X-CCDN-CacheTTL
Mime-Version
X-RPS
X-Newrelic-Synthetics
X-DW
X-Hcs-Proxy-Type
X-DSS
X-DI
X-DB
XServer
X-Render-Time
X-TIM-N
Cache-Provider
X-Internal-Host
GeoIP-Latitude
GeoIP-Country-Code
X-WA
X-App
X-Service
Srv
X-Ua
X-BBC-Edge-Cache-Status
EpKe-Alive
X-SaId
X-PHP-Backend
X-Worker
DataCenter
X-Action
Processtime
ProcessTime
X-NGENIX-Cache
X-CF-Powered-By
X-Auto-Login
Upgrade-Insecure-Requests
X-JoinUs
X-Edge-Location
X-FTR-Cache-Host
X-Geo
X-Extlb
X-Via-NSCOPI
FSS-Cache
X-Fpc
X-Forwarded-Site
X-Oss-Cdn-Auth
X-Ftr-Cache-Host
X-Cdn-Request-ID
X-Dynatrace-Js-Agent
X-Provided-By
Proxy-Connection
X-CSRF-TOKEN
X-FORWARDED-FOR
Datacenter
W
X-Cluster-Node
CDN
CF-Cached-On
X-HITS
X-Swift-Error
X-Req
X-Region-Sid
We-Hiring
X-VC-Cache
X-Date
X-BBC-Origin-Response-Status
X-Bc-Bl
PICS-Label
X-Parent-Response-Time
X-BACKEND-TTL
X-Accel-Expires-Debug
Mail-Subject
Memcached
LB
X-Fastly-Backend-Reqs
X-Dw-Trace-Id
Cdn
X-Proxy-Upstream
X-PJAX-URL
X-MSEdge-Features
X-Depends-On
X-MSEdge-Flight
Surrogated-Key
X-CACHE-AGE
X-Client-Ip
X-ABtesting
X-Pad
X-RateLimit-Limit-Second
X-Flog
X-Hello
Dnion-Transfer-Encoding
X-Rocket-Build-Number
X-IN-APIGATEWAY
X-Sigma
X-IN-APIGATEWAYSSL
X-Sigma-Backend
X-Cache-Tag
X-Fastly-Request-Id
X-UnsetCookies
X-RateLimit-Remaining-Second
Env
OT-Force-Account-Verify
X-Akamai-Pragma-Client-IP
X-ZONE
X-Air-Trace-Id
Vha6-Origin
X-Oracle-DMS-ECID
X-Via-PopN
X-Presslabs-Stats
X-Via-PopH
X-ND-Cache
X-Acquia-Purge-Tags
X-Zone
X-Men
X-Pf-Uncompressing
X-Via-PopV
X-Acquia-Site
X-Acquia-Application-Trace
X-APP
X-Acquia-Application-UUID
Media-Length
Time
X-MiniProfiler-Ids
Memory
Epwk-X-Cache
CPC-Cache
X-LiteSpeed-Tag
CPC-Age
VNS-Cache
WZWS-RAY
VNS-Age
X-Lb-Id
Cf-Ipcountry
X-Varnish-URL
X-Vcache
X-Varnish-Beresp-TTL
URI
X-Csrf-Token
X-Snapshot-Date
X-Akamai-ERPolicy
X-ElasticPress-Search
Xet-Cookie
X-Ms-Meta-Staticbatchstarttime
X-ElasticPress-Query
X-Request-URL
X-Request-Url
X-Ms-Meta-Originalurl
X-Akamai-ERRuleID
CountryCode
X-C
Content-Style-Type
Content-Script-Type
X-Litespeed-Cache-Control
X-Tid
X-Amz-Meta-Cb-Modifiedtime
Inserted-Into-Cache-At
X-B3-Parentspanid
NnCoection
X-Debug-Cache-Store
X-Debug-Cache-Fetch
Phost
X-Traceid
X-Redis-Duration-Ms
X-Storefront-Renderer-Verified
Ohc-Response-Time
Environment
X-Redis-Count
X-ServerName