Threat Level: green Handler on Duty: Renato Marinho

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-RAY
CF-Cache-Status
Accept-Ranges
Link
X-XSS-Protection
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
P3P
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-UA-Compatible
X-Served-By
X-Timer
X-Request-Id
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Xss-Protection
Access-Control-Allow-Credentials
X-Runtime
X-AspNet-Version
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Content-Security-Policy
X-Ua-Compatible
X-Iinfo
Content-Encoding
X-Request-ID
Feature-Policy
X-AspNetMvc-Version
Status
X-CDN
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Upgrade
Access-Control-Max-Age
X-Via
Keep-Alive
X-Ws-Request-Id
X-AH-Environment
X-Age
X-Robots-Tag
Request-Context
EagleId
X-Turbo-Charged-By
X-Cache-Group
X-Proxy-Cache
Server-Timing
X-Server
X-Backend
X-Hacker
Host-Header
X-Server-Powered-By
Report-To
X-Amz-Request-Id
X-Nginx-Cache-Status
Grace
X-Amz-Id-2
X-UA-Device
X-Dns-Prefetch-Control
X-Rq
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Page-Speed
X-OneAgent-JS-Injection
Cf-Railgun
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-CST
X-Amz-Version-Id
NEL
X-Cache-Spec
Allow
X-Vhost
X-Host
X-WebKit-CSP
X-Backend-Server
X-ASPNET-VERSION
X-Server-Id
X-Dispatcher
Surrogate-Control
EagleEye-TraceId
X-Node
Xkey
Request-Id
X-Response-Time
Content-Location
X-Akam-SW-Version
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Accept-CH
X-Ruxit-JS-Agent
P3p
X-Cache-Lookup
X-Application-Context
X-Ac
X-Country
Accept-CH-Lifetime
X-Mod-Pagespeed
X-Cloud-Trace-Context
X-Readtime
X-Template
X-Language
X-B3-TraceId
MS-Author-Via
X-HW
Rating
Accept-Ch-Lifetime
X-Cnection
X-Url
X-MS-InvokeApp
Accept-Ch
X-Origin-Cache
X-PC
X-Vname
X-TtlSet
Edge-Control
X-Clacks-Overhead
X-GitHub-Request-Id
X-ESI
X-Trace
X-Varnish-TTL
X-Middleton-Display
X-Middleton-Response
X-Sol
Display
Pagespeed
Response
X-Content-Type
X-D2id
Arr-Disable-Session-Affinity
Verso
X-Kinja
X-GoogleNews-Bot
X-Cdn-Fetch
X-Kinja-Build
X-Exp-Id
X-Exp-Variant
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Powered-By-Plesk
X-Country-Code
X-Vcap-Request-Id
X-Goog-Hash
X-Rack-Cache
X-TTL
X-Webkit-CSP
X-ORACLE-DMS-RID
X-FastCGI-Cache
X-VARITI-CCR
X-ORACLE-DMS-ECID
X-Navigation-Version
X-Server-Name
X-Abt-Application-Version
X-Amz-Rid
Service-Worker-Allowed
Fastly-Restarts
X-Fastly-Request-ID
X-Client-IP
X-Cached
X-Buckets
X-MSEdge-Ref
X-Release
X-Cache-TTL
X-Element-Page-Cache
Cache-Tag
X-Dw-Request-Base-Id
X-NF-Request-ID
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
Public-Key-Pins
Access-Control-Request-Method
RTSS
X-SharePointHealthScore
SPRequestGuid
SPRequestDuration
SPIisLatency
AR-PoweredBy
Ar-Sid
AR-Request-ID
AR-CACHE
AR-ATIME
X-Ezoic-Cdn
X-Edge
X-LLID
X-Powered-CMS
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Upstream
X-Version
Content-MD5
S
X-HP-Webp
X-Jurisdiction
X-Recruiting
X-Oneagent-Js-Injection
X-Kinsta-Cache
X-Mid
X-MCACHE
X-ECACHE
Charset
X-Mg-S
X-Origin-Upstream-Status
X-DynaTrace
X-T
Cache-Tags
X-Content-Digest
X-Accel-Expires
X-PressLabs-Stats
Fusion-Source
Fusion-Content-Id
Fusion-Component-Id
Fusion-Template-Id
Fusion-Deployment-Id
Fusion-Content-Source
X-Forwarded-Proto
X-Litespeed-Cache
Fastcgi-Cache
X-Px
X-Content-Security-Policy-Report-Only
X-Logged-In
X-Ttl
Filters
TP-L2-Cache
TP-Cache
Server-Node
Edge-Cache-Tag
TCN
Server-Name
X-Id
X-Amz-Server-Side-Encryption
X-Ruxit-Js-Agent
X-Correlation-Id
Front-End-Https
X-Request-Processing-Time
X-Request-Received
Nginx-Cache
MicrosoftSharePointTeamServices
X-Grace
X-Forwarded-For
X-XRDS-Location
X-Shield-Request-Id
X-Hits
X-B3-Sampled
X-Amzn-Trace-Id
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Alternate-Protocol
X-Request-Handler-Origin-Region
X-Server-ID
X-Microsite
X-Az
X-Activity-Id
X-AppVersion
X-NWS-LOG-UUID
X-F-Cache
X-Varnish-Age
X-Amz-Replication-Status
X-Fastcgi-Cache
X-HS-Combine-CSS
X-HS-Hub-Id
X-HS-Cache-Config
X-Debug
X-HS-Content-Id
X-Origin-Server
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Frontend
X-Yandex-Sdch-Disable
Nel
X-Rid
X-Geo-Country
Section-Io-Cache
Host
X-RateLimit-Remaining
X-Cache-Age
Surrogate-Key
X-Daa-Tunnel
X-DIS-Request-ID
Accept-Charset
Realpath
X-Hostname
X-Ser
X-Git-Hash
X-VCache
Access-Control-Allow-Method
X-Mobile-URL
X-Respond-Thread
X-Source
X-Seen-By
X-Upgrade-Enabled
X-DataDome
X-Type
X-XRDS-LOCATION
ServerID
Cleartype
Paypal-Debug-Id
X-AOL-HN
MS-CV
X-Time
X-TT
Healthy
X-LB-Cache
X-Contextid
X-Content-Options
X-Varnish-Backend
X-Signature
Payment
X-Debug-Info
X-IPLB-Instance
X-Cache-Action
X-B-Cache
X-Request-Guid
X-Is-Crawler
X-Flags
X-Aspnet-Duration-Ms
X-Route-Name
X-Providence-Cookie
X-Whom
X-App-Environment
X-Cache-Key
X-N
X-WebKit-CSP-Report-Only
Fastcgi-Useragent
X-Load-Cache
X-Page-Id
X-FB-Debug
Cache
X-Jobs
Node
X-Webkit-Csp
X-Mobile
X-Rule
X-Cache-Expired-At
X-FTR-Request-ID
Refresh
X-Browser-Type
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
Viewport
X-Wix-Request-Id
X-FireWall-Port
X-Original-Request-Id
X-Response-Served-From
X-Accel-Buffering
DC
Ms-Operation-Id
X-Cacheable-TTL
X-RTag
Access-Control-Request-Headers
X-Distributor
X-Instance
X-RemovedCookies
X-Zen-Fury
X-Drupal-Cache-Tags
X-ProcessESI
Referer-Policy
X-Debug-IsConnected
X-Debug-IsPreview
X-B
X-Cluster-Name
X-Content-Powered-By
Eomportal-Instance
X-Framework
Version
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Cache-Time
X-Real-IP
X-UUID
X-HTML-Minification-Powered-By
X-Cache-Control
X-Region
X-Proxy
X-IPS-LoggedIn
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Page-View
X-Tec-Api-Root
X-Tec-Api-Origin
X-Tec-Api-Version
X-Drupal-Cache-Contexts
Countrycode
X-Www-Served-By
X-FW-Server
X-App-Server
X-FW-Dynamic
X-FW-Static
X-FW-Hash
X-FW-Serve
X-FW-Type
X-Protected-By
X-G
X-Nginx-Cache
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-1
X-Cached-By
X-Yottaa-Metrics
X-Yottaa-Optimizations
Liferay-Portal
X-Cache-Rule
X-Cache-Operation
X-Via-JSL
X-Akamai-Edgescape
Powered-By-ChinaCache
X-Cache-Hit
X-Environment-Context
X-L-Path
X-Pinterest-Direct
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Io-Id
Xserver
X-Pass-Why
SRV
Section-Origin-Responded
X-Varnish-Grace
GEO-INFO
CF-IPCountry
X-Device-Type
Server-Info
DynaTrace
X-TA-CDN-Provider
X-Varnish-Server
X-User-Agent
X-Adobe-Loc
X-Adobe-Content
X-TEC-API-VERSION
Cache-Status
X-TEC-API-ROOT
X-TEC-API-ORIGIN
Retry-After
Ec-Rule-Version
Frame-Options
X-Mode
From-Origin
X-Tumblr-Pixel-2
X-Endurance-Cache-Level
X-UPSTREAM-Address
Meta-Geo
X-RN-RSRV
X-Handled-By
X-ES-SERVER
Webserver
X-FB-TRIP-ID
Cache-Tv-Group
X-Format
X-Origin-Hint
X-Section
X-Access
X-NYM-Debug-Backend
X-Request-Time
Webcakes-Region
X-Pubstack
Country
X-Storage
X-Soup
Apigw-Requestid
X-PCL
TWC-Connection-Speed
Webcakes-App-Version
Property-Id
X-Varnishpool
X-Uri
Fastly-SSL
TWC-Privacy
Webcakes-App-Name
X-OCL
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-Device-Class
TWC-GeoIP-Country
X-PERF
X-Labrador-Cache-Channel
X-Cache-Server
X-BYPASS-REASON
X-Be
X-PHP-Host
X-R9-Blue-Green-Version
X-MP-GENERATED-AT
X-ApacheServer
X-ProxyCache-Key
X-Proxy-Build
X-ProxyCache-Status
Cache-Name
X-Proxy-Cache-Status
Uber-Trace-Id
Selected-Fe
X-AWS-Id
X-Info
X-Hl-Ver
Mn-Server-Ip
X-LJ-Flow-ID
X-VWS-Id
X-Timing-Wait
X-WA-Info
X-Human
Decoy-Debug-Status
X-Server-W
X-Via-Fastly
Decoy-Debug-Key
Decoy-Debug-TTL
X-S-Maxage
Azure-SiteName
Azure-SlotName
X-Loop
Azure-InstanceId
Azure-RegionName
X-Cache-TTL-Remaining
X-Say-Cacheable
X-Backend-Name
X-Web-Node
X-Say-TTL
X-LAGOON
X-SayCDN-TTL
X-Origin-Date
Protected
Azure-Version
X-TNCMS
X-Proto
X-UA-Device-Type
X-Routing-Service
X-GG-Cache-Date
X-Sql-Count
X-Proxied
X-Xfnlog-Site
X-Zipkin-Id
X-No-Session
X-Sql-Duration-Ms
X-Shopify-Stage
X-Sorting-Hat-PodId
X-ShardId
X-Sorting-Hat-ShopId
X-ShopId
X-Hosted-By
X-Alternate-Cache-Key
X-Storefront-Renderer-Rendered
X-Status
X-Hyper-Cache
X-Redis-Cache
X-Locale
X-NWS-UUID-VERIFY
X-Cache-Enabled
X-Content-Age
X-Rendered-As
X-Ratelimit-Limit
X-Microcachable
X-SRV
X-Site-Version
X-Is-Bot
X-FW-Version
X-Backend-Host
X-Cluster
X-Azure-Ref
Amp-Access-Control-Allow-Source-Origin
S-Cnection
X-Cache-Grace
X-AIR-PT
X-Forwarded-Host
AMP-Access-Control-Allow-Source-Origin
X-TT-LOGID
X-Qloud-Router
X-App-Version
X-Platform
X-Trace-Id
X-Varnish-Ttl
Akamai-GRN
X-Via-CDN
X-Aspnetmvc-Version
X-Revision
ServedBy
X-ATG-Version
X-Cache-NGX
X-Cache-PHP
X-Varnish-Hostname
X-CSRF-Token
Cache-Hits
X-EdgeConnect-Cache-Status
X-Dc
X-RCS-CacheZone
X-CCM
X-Cdn
X-Debug-Cache
X-Node-Name
Who
X-RateLimit-Limit
DB-Nickname
Country-Code
X-Akamai-Transformed
X-Detected-As
X-Cache-Host
X-B3-SpanId
X-Amzn-RequestId
X-Amzn-Remapped-Content-Length
X-Amz-Apigw-Id
X-CS
Filterid
X-Adobe-Source
X-ID
X-CACHE-KEY
X-Nc
X-BCube-Filmed-By
X-TX-ID
X-Oss-Storage-Class
X-Oss-Request-Id
X-Correlation-ID
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-Varnish-Beresp-Grace
SD-X-WS
X-Oss-Object-Type
X-Ms-Request-Id
X-Ms-Version
X-Varnish-Cache-Hits
X-A-Ccd
X-A-Dam
X-NAPM-TraceId
X-PAYTM-SRV-ID
X-Origin-TTL
X-Owner
Backend
X-Origin-CC
X-PBS-Appsvrname
X-A
X-A-Dgt
X-B-Cookie
X-Destination
X-Varnish-Beresp-Ttl
X-ARC
X-External-Request-Id
X-D
X-Connection-Hash
X-CF-Lambda-Fn
BehaviorPad-Version
X-CF-Lambda-Version
X-Cache-NE
X-Application
X-Aed
X-Level-Front-Cache
X-A-Dcw
Expiry
Fastcgi-X-Cache-Version
DCR-Processing-Time-Ms
DCR-Decision-By
X-From
X-Generated-On
X-Generation-Time
X-A-Wwc
X-Location
X-Processor
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-Realm
X-Trv-Group
X-Time-Microsecs
Machine
X-Country-Code-Real
X-FTR-Backend
MD5-Digest
Meta-Geo-Continent
X-VG-WebServer
Odigeo-Trace-Id
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
X-VG-WebCache
X-Vdms-Version
Mobile-Detection-Method
Rendered-Blocks
X-Vdms-Path
X-SRCache-Key
X-FTR-DC
X-Rewrite-Enabled
X-Session-Fingerprint
X-GEO
X-Request-UUID
X-S
X-ScT
T-Server
X-Rojux
X-S-Cookie
X-Varnish-Beresp-Status
X-Ratelimit-Remaining
HostName
X-Unique-Id
Cf-Device-Type
V-Age
X-Fetched-On
Host-ID
Cache-Host
UCS
X-Bip
X-Cache-Bucket
X-Cms-Context
Arc-Version
PB-RID
Path
AKAMAI
X-Core-Value
X-Azure-Ref-OriginShield
X-Device-Os
X-Developers
Fastly-Backend-Name
Thinkindot-Control
Server-Host
X-OVcl
X-OVcl-Cache
X-B3-Traceid
Ssr
Wxu-Next-Hostname
X-TrackingId
Wxu-Next-Region
X-Thinkindot-L3
PB-PID
Thinkindot-CacheControl
X-Thanos
X-JWT-State
Thinkindot-CacheControl-Type
Wxu-Next-Commit
X-Geo-Header
Magicmarker
Content-Disposition
X-Has-Esi
X-Backend-TTL
X-Is-Gdpr
X-Tumblr-Pixel-3
X-APP-VERSION
X-EC-Lua
X-Unique-ID
X-Magnolia-Registration
Sever-Int
PFcat
Platform
True-Client-Country-4JS
Release
Server-Ext
Vix-Hermes-Req-Id
X-Branch-Name
X-Cache-Info
X-Cache-Debug
Server-Hostname
X-Method
X-SIPLIST1
X-ServerID
X-Skip-Cache
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Scheme
X-Request-URI
X-Ratelimit-Reset
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Reqid
X-User
X-Variation
Esi-Enabled
X-VServer
X-Backend-State
X-IP
X-Var-Ttl
X-VG-TLSProxy
X-VarnishDD-TTL
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-Varnish-Hits
X-Varnish-Remaining-TTL
X-Policy
X-Platform-Server
X-Fastly-Backend
X-Epic-Correlation-Id
X-FC-Vary-Parameters
X-Generated-In
X-GeoIP
X-Envoy-Decorator-Operation
X-DPWN-IS-SECURE
X-DefElseHash
X-DefHash
X-Developer
X-Dispatcher-Server
X-GeoIP-City
X-GoCache-CacheStatus
X-Node-Id
X-Nginx-Cache-Key
X-NU-AKA-ACS-Version
X-Origin
X-Origin-Expires
X-Micro-Cache
X-LI-UUID
X-HN
X-HS-Content-Campaign-Id
X-Li-Fabric
X-Li-Pop
X-Clientip
X-Fastly-Cache
CDN-Uid
CDN-RequestId
CDN-RequestCountryCode
CDN-PullZone
Cf-Bgj
DSUID
NGB
Pagetype
Fastly-SWR
Fastly-SIE
CDN-EdgeStorageId
CDN-CachedAt
C-Via
Apple-News-Services-Request-Url
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
Adler-Geo
CDN-Cache
CDCHOST
CacheControlHeader
Gh-Request-Id
X-DynaTrace-JS-Agent
IsBot
NM-Fastcgi-Cache
NGX
Location
Is-Eu
L
Locid
On-Server
Origin
X-NewRelic-App-Data
User-Cache-Control
X-Fmm-Version
X-Gamma-Serve
X-Eu-Site
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Wikidot-Backend
X-Esi-Check
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Csrf-Jwt
X-Gzip
X-Planisys-CDN-Cache
X-Wikidot-Static-Cache
X-Origin-Response-Time
X-Clara-WADP
X-Generated-By
X-Sucuri-ID
X-Gen-Mode
X-Block-Status
Xc-Version
X-WADP-Cache
X-Tb
X-Hnp-Log
X-Loc
X-Hash
Web-Mar-Node
X-Old-Content-Length
X-Mvc-Supplant-Cachable
X-Irp-Debug
X-Request-Host
X-Swa-Ws
Fastly-Drupal-HTML
X-Cache-Id
L5d-Success-Class
HA-Ipaddr
Ha-Gx-Prefs
X-Cache-Tags
Rt-Fastcgi-Cache
X-CGP
X-Aicache-OS
X-Air-Hostname
X-Amz-Meta-S3cmd-Attrs
X-FTR-Expires
Req-Svc-Chain
X-Varnish-Url
X-Edge-Location-Klb
X-LB-ID
X-Slack-Backend
Cmstype
Cmsid
X-Servername
X-Instrumentation
X-Kraken-Routeconfig-Destination
X-Kraken-Loop-Name
X-Server-Lifecycle-Phase
X-Via-Popv
X-Via-Poph
X-Cdn-Forward
Kp-EeAlive
Svr
X-Served-From
Pics-Label
X-Via-Popn
Tracecode
X-Mvc-Supplant-OutputCached
A
X-PF-Uncompressing
Instruction
SR-User-Adfree
Url
X-Vgn-Hpd-Reason
X-Refresh
X-Cache-Var
X-Cache-Var-Map
VivaBuild
M-TraceId
X-CUA
Viewtype
X-SaId
X-Matched-Rule
Arc-Country
Cross-Origin-Opener-Policy
Cache-Key
X-DC
X-PHP-Backend
SID
Lfy
X-JoinUs
X-NGENIX-Cache
X-Edge-Location
X-Cdn-Origin
TDXMobile
X-Tb-Optimization-Total-Bytes-Saved
X-Cache-Expires
MIME-Version
CloudFront-Viewer-Country
X-Sn-Servicetimems
X-CDN-Forward
Sid
X-TraceId
X-Esi
Pramga
X-Vc
X-Cache-Backend
X-NCache
X-NC
Geo-Info
X-CLOUD-TRACE-CONTEXT
X-Service
DataCenter
X-Servedbyhost
X-Core-Mission
Content-Secure-Policy
Server-ID
X-Cache-Date
NtCoent-Length
X-Extlb
X-Webkit-CSP-Report-Only
X-Request-Start
X-Internal-Host
X-Wa
X-Srv
X-Bc-Bl
Source
Geoip-Latitude
GeoIp-Country-Code
Tcn
X-Forwarded-Site
X-FireWall-Protection
X-B3-Spanid
FSS-Cache
X-Error
X-LI-Proto
X-HS-Status
X-Varnish-Cacheable
X-Via-NSCOPI
Surrogated-Key
X-Req
X-Proxy-Upstream
LB
Memcached
X-VHOST
X-Newrelic-Synthetics
Hostname
CACHE
X-URL
Resin-Trace
X-Vcl-Version
X-Accel-Expires-Debug
X-VC-Cache
X-Response-By
X-Air-Source
X-PJAX-URL
X-VCL-Version
X-Date
Upgrade-Insecure-Requests
X-HOST
X-Geo
X-Viewer-Country
Xkeyi7
X-Rocket-Build-Number
Mail-Subject
X-CCDN-Origin-Time
X-Proxy-Cachei7
X-RateLimit-Limit-Second
X-Li-Proto
XServer
X-Sigma-Backend
X-Sigma
Request-ID
X-Hcs-Proxy-Type
X-RateLimit-Remaining-Second
Server-Ttl
X-CCDN-CacheTTL
Env
We-Hiring
X-App
X-LiteSpeed-Cache-Control
X-MSEdge-Flight
X-MSEdge-Features
X-TIM-N
X-BBXSRF
HitType
Memory
Time
X-Men
CF-Cached-On
X-RSL
GeoIP-Latitude
X-DSS
X-DI
X-DB
X-DW
X-RPM
N-Cache
GeoIP-Country-Code
X-RPS
X-ZONE
X-WA
X-Zone
X-RAMCache
X-FORWARDED-FOR
X-Cs
X-Cache-2
X-APP
X-Mg-Request-UUID
X-Varnish-Authentication
X-Cc-Req-Id
CPC-Age
CPC-Cache
X-Air-Trace-Id
X-Action
X-Svr
ProcessTime
VNS-Age
X-Cache-ASPX
VNS-Cache
X-UA
X-Cc-Via
X-ServedByHost
X-Contensis-Viewer-Groups
D-Cc-Upstream
S-Rt
X-HostName
X-COUNTRY
X-TIME
Server-Id
X-FPC
My-App
State
X-Oss-Cdn-Auth
X-Region-Sid
Fastcgi-Cache-TTL
X-Provided-By
X-Presslabs-Stats
X-Swift-Error
X-CSRF-TOKEN
X-Dynatrace-Js-Agent
X-Nyt-Route
X-Fpc
X-Origin-Time
X-Depends-On
W
X-Server-IP
X-API-Version
Mime-Version
X-CF-Powered-By
X-Minions-Version
X-Cache-Config
X-Gdpr
Cache-Provider
Cteonnt-Length
X-Cache-Remote
X-Cdn-Request-ID
Srv
X-Dw-Trace-Id
X-BACKEND-TTL
CDN
X-Sucuri-Cache
X-Cache-Ttl
Cross-Origin-Window-Policy
Ohc-File-Size
X-Cache-Type
X-UnsetCookies
X-Erf-Stays-Bingo-Pdp-Web
X-Client-Ip
X-ServerName
X-Xrds-Location
X-Akamai-Pragma-Client-IP
Cdn
X-SN
X-Fastly-Request-Id
X-NodeID
Proxy-Connection
X-Hello
X-Flog
X-ABtesting
OT-Force-Account-Verify
X-Check-Cacheable
X-VC
X-Parent-Response-Time
Ohc-Cache-HIT
X-Ftr-Cache-Host
X-SD-PageType
X-Pad
Media-Length
X-SB
X-Orig-Expires
X-Snapshot-Date
Dnion-Transfer-Encoding
X-Tenant
X-Oracle-DMS-ECID
X-Webstats-RespID
X-Fastly-Backend-Reqs
X-ND-Cache
Vha6-Origin
X-NGINX-Cache
X-Pf-Uncompressing
Cf-Ipcountry
X-Forwarded-Path
X-Shop-Environment
X-Host-Name
X-Air-Pt
Datacenter
PICS-Label
X-Traceid
X-LiteSpeed-Tag
X-ElasticPress-Search
X-Cluster-Node
X-Via-PopV
X-BBC-Edge-Cache-Status
X-Via-PopH
Epwk-X-Cache
X-Via-PopN
Warning
WZWS-RAY
X-Acquia-Site
X-Acquia-Purge-Tags
X-Acquia-Application-Trace
X-Ftr-Request-Id
X-Varnish-URL
X-Acquia-Application-UUID
X-Akamai-ERPolicy
X-Vcache
EpKe-Alive
X-Cache-Tag
X-Akamai-ERRuleID
X-Varnish-Beresp-TTL
X-BBC-Origin-Response-Status
X-Render-Time
X-Request-URL
Xet-Cookie
X-MiniProfiler-Ids
X-Ms-Meta-Staticbatchstarttime
X-Lb-Id
X-Ms-Meta-Originalurl
X-Tx-Id
CountryCode
Phost
Ohc-Response-Time
X-Amz-Meta-Cb-Modifiedtime
X-Conf
X-Mg-Request-Id
X-Pjax-Url
X-Tid
X-Debug-Cache-Store
X-C
Environment
X-Debug-Cache-Fetch
X-Yottaa-OS
X-Apw-Hits
URI
X-Redis-Duration-Ms
NnCoection
X-Litespeed-Cache-Control
X-B3-Parentspanid
Content-Script-Type
Content-Style-Type
X-Apw-Access-Object
X-Apw-Access-Token
X-Apw-Access-Action
Inserted-Into-Cache-At
X-Redis-Count
X-Cache-Status-Check