Threat Level: green Handler on Duty: Renato Marinho

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
Link
X-XSS-Protection
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-Served-By
X-UA-Compatible
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
X-Xss-Protection
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Request-ID
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Ua-Compatible
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Content-Encoding
X-CDN
X-AspNetMvc-Version
Feature-Policy
X-Envoy-Upstream-Service-Time
Status
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-Via
Upgrade
Access-Control-Max-Age
Keep-Alive
X-Ws-Request-Id
X-Age
X-AH-Environment
X-Turbo-Charged-By
X-Robots-Tag
Request-Context
X-Proxy-Cache
X-Cache-Group
EagleId
Server-Timing
X-Backend
X-Hacker
X-Server
Report-To
Host-Header
X-Amz-Request-Id
X-Server-Powered-By
X-Amz-Id-2
Grace
X-Nginx-Cache-Status
X-UA-Device
X-Rq
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Dns-Prefetch-Control
X-Page-Speed
Cf-Railgun
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-OneAgent-JS-Injection
NEL
X-Amz-Version-Id
X-Cache-Spec
X-Device
X-CST
Allow
Xkey
X-Host
X-Vhost
X-Backend-Server
X-WebKit-CSP
EagleEye-TraceId
X-Server-Id
Request-Id
Surrogate-Control
X-Dispatcher
X-Node
Content-Location
X-Response-Time
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Ruxit-JS-Agent
X-Akam-SW-Version
P3p
X-ASPNET-VERSION
Accept-CH
X-Ac
X-Application-Context
X-Cache-Lookup
X-Country
X-Template
X-Language
Accept-Ch
Accept-CH-Lifetime
X-Mod-Pagespeed
X-Readtime
Accept-Ch-Lifetime
X-Cloud-Trace-Context
MS-Author-Via
X-B3-TraceId
Rating
X-Origin-Cache
X-MS-InvokeApp
X-Cnection
X-HW
X-Url
X-Vname
X-PC
X-TtlSet
X-Clacks-Overhead
Edge-Control
X-GitHub-Request-Id
X-ESI
X-ORACLE-DMS-ECID
X-Trace
X-Middleton-Display
Response
X-Content-Type
X-Middleton-Response
Display
Pagespeed
X-Sol
X-D2id
X-Webkit-CSP
X-ORACLE-DMS-RID
X-Kinja-Revision
X-Use-Magma
X-Kinja-Server
X-Kinja-Build
X-Exp-Variant
Arr-Disable-Session-Affinity
X-Cdn-Fetch
X-GoogleNews-Bot
X-Kinja
X-Exp-Id
Verso
X-Vcap-Request-Id
X-FastCGI-Cache
X-Goog-Hash
X-Rack-Cache
X-Buckets
X-Country-Code
X-Varnish-TTL
X-Navigation-Version
Service-Worker-Allowed
X-Server-Name
X-Powered-By-Plesk
X-VARITI-CCR
X-Amz-Rid
X-Abt-Application-Version
X-Fastly-Request-ID
X-TTL
X-Client-IP
X-Cache-TTL
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
Fastly-Restarts
SPRequestGuid
X-Release
X-SharePointHealthScore
X-Cached
X-MSEdge-Ref
X-Dw-Request-Base-Id
X-Element-Page-Cache
X-Oneagent-Js-Injection
SPRequestDuration
SPIisLatency
X-NF-Request-ID
Public-Key-Pins
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
RTSS
Access-Control-Request-Method
X-SRCache-Fetch-Status
X-SRCache-Store-Status
AR-CACHE
AR-PoweredBy
AR-ATIME
Ar-Sid
AR-Request-ID
X-Edge
X-LLID
X-Powered-CMS
X-Ezoic-Cdn
X-Litespeed-Cache
X-Origin-Upstream-Status
Cache-Tag
Content-MD5
X-Upstream
X-Px
Fusion-Deployment-Id
Fusion-Source
Fusion-Template-Id
Fusion-Content-Id
Fusion-Content-Source
Fusion-Component-Id
X-HP-Webp
X-Jurisdiction
S
X-Version
X-ECACHE
X-Mid
X-MCACHE
X-Recruiting
Charset
X-Content-Digest
X-PressLabs-Stats
X-Mg-S
X-Ttl
X-Amz-Server-Side-Encryption
Fastcgi-Cache
X-Kinsta-Cache
X-T
Cache-Tags
MicrosoftSharePointTeamServices
X-Id
Filters
Front-End-Https
X-Content-Security-Policy-Report-Only
X-DynaTrace
X-Logged-In
TCN
X-Debug
Server-Node
X-Accel-Expires
Edge-Cache-Tag
X-Grace
X-Forwarded-Proto
X-Correlation-Id
X-Forwarded-For
TP-L2-Cache
TP-Cache
Server-Name
Nginx-Cache
X-Pinterest-Direct
X-Amzn-Trace-Id
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Surrogate-Key
X-Request-Received
X-Request-Processing-Time
X-Yandex-Sdch-Disable
X-Varnish-Age
X-Shield-Request-Id
X-B3-Sampled
X-Server-ID
X-Microsite
X-Request-Handler-Origin-Region
X-Ser
X-Hits
X-AppVersion
X-Activity-Id
X-Az
X-Amz-Replication-Status
X-F-Cache
X-XRDS-Location
X-HS-Content-Id
X-DIS-Request-ID
X-HS-Cache-Config
X-HS-Combine-CSS
X-XRDS-LOCATION
X-HS-Hub-Id
X-Goog-Generation
X-Origin-Server
X-Goog-Storage-Class
X-Goog-Metageneration
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
Accept-Charset
X-Geo-Country
X-Git-Hash
Alternate-Protocol
X-Cache-Key
X-Respond-Thread
Cache
X-Rid
X-Time
X-FTR-Request-ID
X-Fastcgi-Cache
X-Frontend
Section-Io-Cache
X-LB-Cache
Host
X-Upgrade-Enabled
X-DataDome
Powered-By-ChinaCache
X-Ruxit-Js-Agent
Access-Control-Allow-Method
X-Mobile-URL
X-Seen-By
X-NWS-LOG-UUID
MS-CV
X-Cache-Age
Paypal-Debug-Id
X-VCache
X-IPLB-Instance
Healthy
X-TT
X-AOL-HN
X-Varnish-Backend
X-Whom
X-Type
Cleartype
X-Hostname
X-Content-Options
ServerID
X-Aspnet-Duration-Ms
Payment
X-Providence-Cookie
X-Flags
X-Request-Guid
X-Is-Crawler
X-Route-Name
X-Cache-Action
X-Signature
X-App-Environment
X-B-Cache
X-Page-Id
X-Source
X-Jobs
X-Debug-Info
Fastcgi-Useragent
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Load-Cache
X-N
X-Daa-Tunnel
X-WebKit-CSP-Report-Only
X-Mobile
X-FB-Debug
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
Nel
X-Via-JSL
X-RateLimit-Remaining
Refresh
X-Contextid
Realpath
Version
X-Accel-Buffering
X-Drupal-Cache-Tags
Node
X-Cached-By
X-Akamai-Edgescape
X-Response-Served-From
X-Wix-Request-Id
X-Rule
X-Original-Request-Id
X-Proxy
DC
X-RTag
X-Framework
X-Cacheable-TTL
X-Zen-Fury
Ms-Operation-Id
X-RemovedCookies
X-Cache-Operation
X-Cache-Rule
X-ProcessESI
Viewport
Access-Control-Request-Headers
X-Instance
X-Distributor
X-Real-IP
X-B
X-Cache-Time
X-HTML-Minification-Powered-By
X-UUID
Eomportal-Instance
X-Drupal-Cache-Contexts
X-Region
Referer-Policy
X-Page-View
X-Tt-Trace-Host
X-Cache-Expired-At
X-Cluster-Name
X-Tt-Trace-Tag
Liferay-Portal
VIX-Pulpo-Node
Countrycode
X-Content-Powered-By
X-Yottaa-Metrics
VIX-Pulpo-Upstream-Status
X-FW-Serve
X-FW-Server
X-FW-Static
X-FW-Type
X-FW-Dynamic
X-FW-Hash
X-Cache-Control
X-Yottaa-Optimizations
X-IPS-LoggedIn
X-G
X-Cache-Hit
X-L-Path
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
DynaTrace
X-Environment-Context
X-Tumblr-User
X-Pass-Why
X-FireWall-Port
Server-Info
X-App-Server
GEO-INFO
X-Varnish-Ttl
Ec-Rule-Version
X-Ratelimit-Limit
X-User-Agent
Xserver
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Id
From-Origin
X-Tumblr-Pixel-2
CF-IPCountry
Section-Io-Origin-Status
X-Protected-By
Webserver
X-Node-Name
X-Ratelimit-Remaining
SRV
X-Www-Served-By
Protected
X-Cache-Server
X-Nginx-Cache
X-Endurance-Cache-Level
Meta-Geo
X-RN-RSRV
X-Hl-Ver
X-Mode
X-UPSTREAM-Address
X-Backend-Name
X-ES-SERVER
X-Handled-By
X-FB-TRIP-ID
X-Uri
X-Locale
X-Debug-IsPreview
X-Site-Version
Frame-Options
X-Debug-IsConnected
Cache-Tv-Group
X-Adobe-Content
X-Varnishpool
X-Web-Node
X-PHP-Host
X-Device-Type
X-Soup
Cache-Status
X-Storage
X-Labrador-Cache-Channel
X-Adobe-Loc
X-Be
X-NYM-Debug-Backend
X-UA-Device-Type
TWC-GeoIP-LatLong
TWC-Locale-Group
Selected-Fe
TWC-Device-Class
TWC-Connection-Speed
TWC-GeoIP-Country
X-MP-GENERATED-AT
Decoy-Debug-TTL
Decoy-Debug-Status
Cache-Name
Country
Fastly-SSL
X-BYPASS-REASON
Webcakes-App-Name
Webcakes-App-Version
Webcakes-Region
Property-Id
TWC-Privacy
X-No-Session
X-PCL
X-ProxyCache-Key
X-Origin-Hint
X-Origin-Date
X-OCL
X-Timing-Wait
X-Proxy-Build
X-Via-Fastly
X-Sql-Count
X-Sql-Duration-Ms
X-Proto
X-WA-Info
Decoy-Debug-Key
X-ProxyCache-Status
X-Pubstack
X-Request-Time
X-Human
X-Redis-Cache
X-Say-TTL
X-VWS-Id
X-Say-Cacheable
X-SayCDN-TTL
X-S-Maxage
X-Server-W
X-R9-Blue-Green-Version
Retry-After
X-Section
X-Access
X-AIR-PT
X-Loop
X-Hosted-By
X-FW-Version
X-LJ-Flow-ID
X-LAGOON
X-Forwarded-Host
X-Cache-Grace
X-Hyper-Cache
X-Revision
X-AWS-Id
X-Format
X-TNCMS
X-ShopId
X-ShardId
X-CCM
X-Xfnlog-Site
X-Storefront-Renderer-Rendered
X-TT-LOGID
X-Alternate-Cache-Key
X-PERF
X-Cache-TTL-Remaining
X-Sorting-Hat-PodId
X-Cluster
X-Sorting-Hat-ShopId
X-Shopify-Stage
X-ApacheServer
Azure-InstanceId
Azure-SiteName
Azure-SlotName
Azure-RegionName
Azure-Version
X-Status
Mn-Server-Ip
X-Zipkin-Id
X-Proxied
X-Routing-Service
X-Is-Bot
X-Varnish-Grace
X-Amz-Meta-S3cmd-Attrs
X-Qloud-Router
X-Rendered-As
Apigw-Requestid
X-Varnish-Server
X-Info
X-FTR-Balancer
X-FTR-Realm
X-FTR-Cache-Status
X-FTR-Backend
X-Country-Code-Real
X-Via-CDN
X-FTR-Backend-Server
X-FTR-DC
S-Cnection
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
Cache-Hits
X-Cdn
X-SRV
X-Cache-Enabled
X-Microcachable
X-Dc
X-FTR-Expires
AMP-Access-Control-Allow-Source-Origin
X-GG-Cache-Date
X-Content-Age
X-Platform
X-Cache-Host
X-Detected-As
X-Proxy-Cache-Status
Uber-Trace-Id
X-Amzn-RequestId
X-Aspnetmvc-Version
X-Azure-Ref
Amp-Access-Control-Allow-Source-Origin
X-Amz-Apigw-Id
X-EdgeConnect-Cache-Status
X-Amzn-Remapped-Content-Length
X-Backend-Host
X-CSRF-Token
X-NWS-UUID-VERIFY
X-Air-Hostname
Tracecode
SD-X-WS
X-Cache-Var-Map
X-App-Version
X-Cache-Var
X-Time-Microsecs
X-Oss-Hash-Crc64ecma
X-DynaTrace-JS-Agent
X-Oss-Object-Type
X-Oss-Request-Id
X-Oss-Storage-Class
Akamai-GRN
X-Oss-Server-Time
HostName
X-ServerID
X-Backend-TTL
X-GEO
X-ATG-Version
X-Trace-Id
X-Unique-Id
X-BCube-Filmed-By
X-RCS-CacheZone
X-Correlation-ID
X-Debug-Cache
ServedBy
X-Tb
X-Varnish-Hostname
Backend
X-Cache-PHP
X-Cdn-Forward
X-Cache-NGX
X-Sucuri-ID
X-Akamai-Transformed
DSUID
X-B3-SpanId
X-Cache-Backend
X-Destination
X-Thinkindot-L3
X-Connection-Hash
X-Ms-Version
X-TX-ID
X-Ms-Request-Id
X-Device-Os
X-D
X-Trv-Group
X-A-Dgt
Meta-Geo-Continent
Mobile-Detection-Method
Odigeo-Trace-Id
X-S
MD5-Digest
Machine
X-A
Lfy
X-Rojux
X-Session-Fingerprint
Path
Release
Rendered-Blocks
SR-User-Adfree
T-Server
X-ScT
Thinkindot-Control
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-A-Ccd
X-A-Dam
X-B-Cookie
X-SRCache-Key
DCR-Decision-By
X-Request-UUID
BehaviorPad-Version
DB-Nickname
X-CF-Lambda-Fn
X-Cache-NE
DCR-Processing-Time-Ms
X-ARC
X-A-Wwc
Instruction
X-A-Dcw
X-Aed
X-Rewrite-Enabled
Expiry
Fastcgi-X-Cache-Version
X-Application
X-CF-Lambda-Version
X-VG-WebServer
X-Matched-Rule
X-Owner
X-Location
X-CS
X-Fetched-On
Xc-Version
X-PAYTM-SRV-ID
X-Processor
X-GeoIP-City
X-Vtex-Remote-Cache
X-From
X-Vtex-Processado-Em
X-NAPM-TraceId
X-Origin-CC
X-PBS-Appsvrname
X-Generation-Time
X-External-Request-Id
X-Magnolia-Registration
X-Vdms-Path
X-Vdms-Version
X-VG-WebCache
X-Level-Front-Cache
X-Generated-On
X-S-Cookie
X-TA-CDN-Provider
X-Origin-TTL
X-OVcl
X-Mvc-Supplant-Cachable
X-Cache-Bucket
C-Via
X-Geo-Header
CacheControlHeader
Arc-Version
Content-Disposition
Gh-Request-Id
X-Skip-Cache
X-Adobe-Source
X-Irp-Debug
X-Is-Gdpr
X-JWT-State
Host-ID
Fastly-Backend-Name
X-HS-Content-Campaign-Id
X-Azure-Ref-OriginShield
Cf-Device-Type
X-GeoIP
NGX
X-SVT-ORM-RULES
X-Has-Esi
X-Micro-Cache
X-Bip
On-Server
X-Reqid
X-B3-Traceid
X-Core-Value
PB-RID
X-Cms-Context
X-VServer
UCS
X-OVcl-Cache
Server-Host
X-Varnish-Cache-Hits
X-NewRelic-App-Data
X-Fastly-Cache
PB-PID
X-FC-Vary-Parameters
X-Node-Id
X-SVT-ORM-VERSION
X-TrackingId
X-Thanos
X-Tumblr-Pixel-3
Pagetype
AKAMAI
User-Cache-Control
X-Origin-Expires
X-Li-Fabric
X-Origin-Response-Time
Ssr
Sever-Int
X-Li-Pop
Web-Mar-Node
X-Origin
Wxu-Next-Region
Wxu-Next-Commit
Wxu-Next-Hostname
X-Nginx-Cache-Key
X-Old-Content-Length
V-Age
X-NU-AKA-ACS-Version
X-LI-UUID
X-Branch-Name
X-Csrf-Jwt
X-Ratelimit-Reset
X-Fastly-Backend
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Fmm-Version
X-Clientip
X-CUA
X-DefElseHash
X-Dispatcher-Server
X-Esi-Check
X-Envoy-Decorator-Operation
X-Developers
X-Developer
X-DefHash
X-Eu-Site
X-Gen-Mode
X-Clara-WADP
X-Gzip
X-GoCache-CacheStatus
X-Backend-State
X-HN
X-Hnp-Log
X-Platform-Server
X-Policy
X-Block-Status
X-DPWN-IS-SECURE
X-Generated-In
X-Generated-By
X-CGP
X-Cache-Tags
X-Cache-Info
X-Request-Host
X-Cache-Id
X-IP
CDN-EdgeStorageId
CDN-RequestCountryCode
X-WADP-Cache
CDN-PullZone
CDN-CachedAt
CDN-Cache
CDN-RequestId
CDN-Uid
Fastly-SWR
Fastly-SIE
X-Varnish-Beresp-Grace
CloudFront-Viewer-Country
CDCHOST
Cache-Host
Server-Hostname
X-User
X-Var-Ttl
X-Variation
X-Varnish-CookieHashed-On
X-Swa-Ws
X-VarnishDD-TTL
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
Adler-Geo
Ha-Gx-Prefs
X-Wikidot-Backend
HA-Ipaddr
NM-Fastcgi-Cache
Magicmarker
Locid
X-EC-Lua
PFcat
Server-Ext
X-Scheme
Platform
Location
X-Wikidot-Static-Cache
L5d-Success-Class
Is-Eu
X-ID
X-APP-VERSION
X-Cdn-Origin
True-Client-Country-4JS
X-LB-ID
X-Varnish-Hits
X-Method
X-Slack-Backend
X-Varnish-Beresp-Status
Rt-Fastcgi-Cache
X-Varnish-Beresp-Ttl
X-Hash
Pramga
IsBot
Vix-Hermes-Req-Id
X-Gamma-Serve
X-SIPLIST1
X-Request-URI
Cf-Bgj
X-Kinja-Server-Push
X-Cache-Debug
X-Cache-Expires
X-VG-TLSProxy
X-Sn-Servicetimems
L
X-CLOUD-TRACE-CONTEXT
X-Goog-Meta-Goog-Reserved-File-Mtime
X-CACHE-KEY
Apple-News-Services-Parsed-Url
Fastly-Drupal-HTML
Apple-News-Services-Handled
X-Cache-Date
Apple-News-Services-Host
Apple-News-Services-Request-Url
X-Aicache-OS
X-Servername
Origin
X-Loc
X-Nc
X-Via-Popv
X-NCache
X-Core-Mission
X-Unique-ID
X-Mvc-Supplant-OutputCached
X-Via-Poph
X-PF-Uncompressing
X-Via-Popn
Esi-Enabled
X-Erf-Stays-Bingo-Pdp-Web
Sid
X-Refresh
Who
X-Varnish-Url
X-Request-Start
Country-Code
Url
Pics-Label
X-Epic-Correlation-Id
X-FireWall-Protection
X-NC
X-Webkit-CSP-Report-Only
X-Cache-Remote
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Varnish-Cacheable
Req-Svc-Chain
X-Response-By
X-Tb-Optimization-Total-Bytes-Saved
X-Dynatrace
X-TraceId
Geo-Info
X-Srv
X-Proxy-Cachei7
X-RateLimit-Limit
X-Error
S-Rt
Xkeyi7
X-Webkit-Csp
X-DC
Cmstype
N-Cache
Source
X-BBXSRF
Cmsid
Content-Secure-Policy
Filterid
X-B3-Spanid
Server-Ttl
X-Host-Name
Kp-EeAlive
X-Served-From
HitType
Svr
X-Cache-2
X-HS-Status
X-Sucuri-Cache
Cross-Origin-Window-Policy
A
Cache-Key
X-Servedbyhost
X-Varnish-Authentication
X-Wa
MIME-Version
Viewtype
VivaBuild
X-Cc-Req-Id
X-Cc-Via
Geoip-Latitude
D-Cc-Upstream
GeoIp-Country-Code
Tcn
Cteonnt-Length
X-Cache-ASPX
X-LiteSpeed-Cache-Control
Ohc-File-Size
X-Contensis-Viewer-Groups
X-URL
M-TraceId
X-Vcl-Version
X-Svr
X-HostName
X-Oracle-Dms-Rid
Server-ID
X-Esi
X-LI-Proto
Arc-Country
TDXMobile
Cross-Origin-Opener-Policy
NGB
X-Server-IP
X-Air-Source
X-CDN-Forward
SID
CACHE
NtCoent-Length
X-RAMCache
X-Vgn-Hpd-Reason
X-Nyt-Route
X-FPC
X-Cache-Config
X-Li-Proto
X-Origin-Time
X-API-Version
X-Gdpr
X-HOST
X-Cs
Resin-Trace
Request-ID
X-VCL-Version
X-Check-Cacheable
X-VC
X-Vc
X-SN
X-UA
X-Service
X-Webstats-RespID
X-Viewer-Country
Server-Id
X-DW
GeoIP-Country-Code
GeoIP-Latitude
X-Internal-Host
X-NodeID
X-DB
X-DI
X-RSL
X-RPS
X-RPM
X-DSS
Cache-Provider
X-WA
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-TIM-N
X-SB
X-ServedByHost
X-Newrelic-Synthetics
X-Hcs-Proxy-Type
X-NGENIX-Cache
X-PHP-Backend
Ohc-Cache-HIT
X-JoinUs
X-SaId
Hostname
DataCenter
Srv
X-App
X-SD-PageType
X-Edge-Location
Mime-Version
X-Geo
X-NGINX-Cache
XServer
X-Forwarded-Site
X-Extlb
X-Via-NSCOPI
ProcessTime
X-BBC-Edge-Cache-Status
X-Action
FSS-Cache
X-Render-Time
CF-Cached-On
X-FTR-Cache-Host
EpKe-Alive
X-CF-Powered-By
X-Fpc
X-Oss-Cdn-Auth
X-Dynatrace-Js-Agent
X-Ua
X-Bc-Bl
X-Provided-By
X-Proxy-Upstream
X-PJAX-URL
We-Hiring
X-Region-Sid
X-Req
Processtime
X-Depends-On
Surrogated-Key
X-Accel-Expires-Debug
X-Date
X-Worker
X-Auto-Login
Upgrade-Insecure-Requests
Memcached
LB
X-VC-Cache
W
X-FORWARDED-FOR
Mail-Subject
X-HITS
X-Cdn-Request-ID
CDN
X-MSEdge-Flight
X-Dw-Trace-Id
X-ZONE
X-BACKEND-TTL
X-Fastly-Backend-Reqs
Cdn
Proxy-Connection
X-MSEdge-Features
X-RateLimit-Limit-Second
X-CSRF-TOKEN
X-Ftr-Cache-Host
X-TIME
Env
X-Cluster-Node
X-RateLimit-Remaining-Second
X-UnsetCookies
X-Client-Ip
X-CACHE-AGE
X-Swift-Error
Memory
X-BBC-Origin-Response-Status
PICS-Label
Datacenter
Time
X-IN-APIGATEWAY
X-Rocket-Build-Number
X-Air-Trace-Id
X-Flog
X-Sigma
X-ABtesting
X-Parent-Response-Time
X-Sigma-Backend
X-Fastly-Request-Id
X-Hello
X-IN-APIGATEWAYSSL
X-Men
X-APP
Dnion-Transfer-Encoding
X-Cache-Tag
X-Akamai-Pragma-Client-IP
CPC-Age
Media-Length
X-Acquia-Application-Trace
CPC-Cache
X-Zone
X-Acquia-Site
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Presslabs-Stats
X-Pad
X-Oracle-DMS-ECID
VNS-Age
X-Pf-Uncompressing
Vha6-Origin
VNS-Cache
X-MG-S
OT-Force-Account-Verify
Epwk-X-Cache
X-Via-PopV
X-LiteSpeed-Tag
X-Via-PopH
X-Via-PopN
Cf-Ipcountry
X-Varnish-URL
X-ElasticPress-Query
X-Ms-Meta-Staticbatchstarttime
X-Snapshot-Date
WZWS-RAY
X-MiniProfiler-Ids
X-Request-Url
X-Request-URL
X-Varnish-Beresp-TTL
X-Akamai-ERPolicy
X-Csrf-Token
X-ElasticPress-Search
Xet-Cookie
X-Ms-Meta-Originalurl
X-Vcache
X-ND-Cache
X-Akamai-ERRuleID
X-Lb-Id
CountryCode
State
My-App
Content-Script-Type
X-Amz-Meta-Cb-Modifiedtime
X-Litespeed-Cache-Control
Content-Style-Type
Fastcgi-Cache-TTL
X-Tid
X-Storefront-Renderer-Verified
X-Redis-Duration-Ms
URI
X-Redis-Count
Environment
X-C
X-ServerName
X-Traceid
NnCoection
X-Debug-Cache-Fetch
X-Debug-Cache-Store
Ohc-Response-Time
Phost
X-B3-Parentspanid
Inserted-Into-Cache-At