Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
X-XSS-Protection
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
X-Request-Id
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Xss-Protection
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Cacheable
X-Request-ID
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Content-Encoding
X-CDN
X-Ua-Compatible
Feature-Policy
X-AspNetMvc-Version
Status
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Upgrade
X-Via
Access-Control-Max-Age
Keep-Alive
X-Ws-Request-Id
X-Age
X-Robots-Tag
X-AH-Environment
X-Turbo-Charged-By
EagleId
Request-Context
X-Proxy-Cache
X-Cache-Group
Server-Timing
X-Backend
X-Hacker
X-Server
Report-To
Host-Header
X-Server-Powered-By
X-Amz-Request-Id
X-Amz-Id-2
X-Nginx-Cache-Status
Grace
X-UA-Device
X-Dns-Prefetch-Control
X-Rq
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Page-Speed
X-LiteSpeed-Cache
Cf-Railgun
X-Pingback
X-OneAgent-JS-Injection
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
NEL
X-Cache-Spec
X-Amz-Version-Id
X-Device
X-CST
Allow
X-Vhost
X-Host
X-Backend-Server
Xkey
X-Server-Id
X-WebKit-CSP
EagleEye-TraceId
X-Dispatcher
Surrogate-Control
X-Node
Request-Id
Content-Location
X-Response-Time
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Akam-SW-Version
X-Ruxit-JS-Agent
P3p
X-ASPNET-VERSION
Accept-Ch
X-Application-Context
X-Cache-Lookup
X-Ac
X-Template
X-Country
Accept-Ch-Lifetime
X-Mod-Pagespeed
X-Language
Accept-CH
X-Readtime
X-Cloud-Trace-Context
Accept-CH-Lifetime
X-B3-TraceId
MS-Author-Via
Rating
X-HW
X-Cnection
X-Origin-Cache
X-MS-InvokeApp
X-TtlSet
X-PC
X-Vname
X-Url
X-Clacks-Overhead
Edge-Control
X-GitHub-Request-Id
X-ORACLE-DMS-RID
X-Trace
X-ESI
X-ORACLE-DMS-ECID
X-Middleton-Response
X-Middleton-Display
Response
X-Sol
Display
Pagespeed
X-Content-Type
X-Varnish-TTL
X-D2id
Arr-Disable-Session-Affinity
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Kinja-Build
X-Kinja
X-GoogleNews-Bot
X-Exp-Id
X-Exp-Variant
X-Cdn-Fetch
X-Vcap-Request-Id
Verso
X-TTL
X-Goog-Hash
X-Country-Code
X-Rack-Cache
X-Powered-By-Plesk
X-Navigation-Version
Service-Worker-Allowed
X-Server-Name
X-Buckets
X-VARITI-CCR
X-Amz-Rid
X-Abt-Application-Version
X-Fastly-Request-ID
X-FastCGI-Cache
X-Webkit-CSP
X-Client-IP
Fastly-Restarts
X-Litespeed-Cache
X-Cache-TTL
X-Release
X-Cached
X-MSEdge-Ref
X-Dw-Request-Base-Id
X-Element-Page-Cache
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
X-Oneagent-Js-Injection
X-NF-Request-ID
SPRequestGuid
X-SharePointHealthScore
SPRequestDuration
SPIisLatency
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
Public-Key-Pins
RTSS
Access-Control-Request-Method
Ar-Sid
AR-PoweredBy
AR-Request-ID
AR-ATIME
AR-CACHE
X-Edge
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-LLID
Cache-Tag
X-Powered-CMS
X-Ezoic-Cdn
X-Upstream
Content-MD5
X-Origin-Upstream-Status
X-Jurisdiction
X-HP-Webp
X-Version
Fusion-Source
S
Fusion-Template-Id
Fusion-Deployment-Id
Fusion-Content-Source
Fusion-Component-Id
Fusion-Content-Id
X-Px
X-MCACHE
X-Mid
X-ECACHE
X-Recruiting
X-Mg-S
Charset
X-Content-Digest
X-Kinsta-Cache
Fastcgi-Cache
X-DynaTrace
X-T
X-PressLabs-Stats
Cache-Tags
X-Amz-Server-Side-Encryption
Filters
X-Accel-Expires
X-Logged-In
MicrosoftSharePointTeamServices
X-Ruxit-Js-Agent
Edge-Cache-Tag
X-Forwarded-Proto
X-Content-Security-Policy-Report-Only
Server-Node
X-Id
Front-End-Https
X-Correlation-Id
TP-Cache
TP-L2-Cache
Server-Name
X-Grace
X-Debug
X-Fastcgi-Cache
Nginx-Cache
X-Hits
X-Forwarded-For
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Amzn-Trace-Id
X-Request-Processing-Time
X-Request-Received
TCN
X-B3-Sampled
X-Ttl
X-Shield-Request-Id
X-Yandex-Sdch-Disable
Surrogate-Key
X-Microsite
X-Request-Handler-Origin-Region
X-Varnish-Age
X-Az
X-Activity-Id
X-AppVersion
X-Amz-Replication-Status
X-Ser
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Combine-CSS
X-F-Cache
X-XRDS-Location
X-XRDS-LOCATION
X-Origin-Server
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-GUploader-UploadID
X-DIS-Request-ID
Alternate-Protocol
X-Pinterest-Direct
Accept-Charset
X-Geo-Country
X-Cache-Key
X-Git-Hash
X-Rid
X-Frontend
X-Respond-Thread
Section-Io-Cache
Host
X-NWS-LOG-UUID
Cache
X-LB-Cache
X-Time
X-DataDome
X-Upgrade-Enabled
X-Mobile-URL
Access-Control-Allow-Method
X-Seen-By
X-VCache
X-Server-ID
X-Cache-Age
X-FTR-Request-ID
Paypal-Debug-Id
MS-CV
ServerID
Healthy
X-TT
X-AOL-HN
X-Type
X-Source
X-IPLB-Instance
X-Hostname
X-Varnish-Backend
X-Content-Options
X-Request-Guid
X-App-Environment
X-Whom
X-Providence-Cookie
X-Is-Crawler
X-Aspnet-Duration-Ms
X-Flags
X-Route-Name
X-Signature
Cleartype
X-Cache-Action
X-B-Cache
Payment
X-Page-Id
X-Daa-Tunnel
X-Debug-Info
X-Jobs
Fastcgi-Useragent
X-RateLimit-Remaining
X-N
X-Load-Cache
X-WebKit-CSP-Report-Only
Powered-By-ChinaCache
X-FB-Debug
Nel
X-Webkit-Csp
X-Mobile
X-Contextid
X-Browser-Type
Realpath
X-Erf-Bev-Bev-Is-Generated
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Erf-Bev-Bev
X-TEC-API-ROOT
X-Via-JSL
Node
Refresh
X-Rule
X-Drupal-Cache-Tags
Version
X-Zen-Fury
X-Accel-Buffering
X-Original-Request-Id
X-Response-Served-From
X-Wix-Request-Id
X-Cache-Expired-At
DC
X-Proxy
X-Cacheable-TTL
Ms-Operation-Id
X-RTag
X-ProcessESI
X-RemovedCookies
X-Framework
Referer-Policy
X-HTML-Minification-Powered-By
X-B
X-Distributor
X-Region
X-Drupal-Cache-Contexts
X-Instance
Access-Control-Request-Headers
X-Cache-Time
X-Real-IP
X-Cache-Control
X-Page-View
X-Tt-Trace-Host
X-UUID
Viewport
X-Cached-By
X-Tt-Trace-Tag
Eomportal-Instance
X-Cluster-Name
X-FW-Server
X-FW-Hash
X-Akamai-Edgescape
X-FW-Dynamic
X-FW-Serve
X-FW-Type
X-FW-Static
X-Content-Powered-By
X-IPS-LoggedIn
X-Cache-Operation
X-Cache-Rule
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
Liferay-Portal
Countrycode
X-Cache-Hit
X-G
X-Yottaa-Metrics
X-FireWall-Port
X-Yottaa-Optimizations
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-Tumblr-User
X-Pass-Why
X-Environment-Context
X-L-Path
X-App-Server
Server-Info
DynaTrace
SRV
CF-IPCountry
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
Section-Io-Id
X-Nginx-Cache
X-Protected-By
X-User-Agent
Ec-Rule-Version
X-Debug-IsConnected
X-Debug-IsPreview
From-Origin
Xserver
X-Www-Served-By
X-Tumblr-Pixel-2
Webserver
GEO-INFO
X-Ratelimit-Limit
X-Mode
X-Device-Type
X-Endurance-Cache-Level
X-UPSTREAM-Address
X-ES-SERVER
X-Handled-By
X-RN-RSRV
Meta-Geo
X-Adobe-Loc
X-Adobe-Content
X-Hl-Ver
X-Site-Version
X-FB-TRIP-ID
X-Cache-Server
Protected
X-Locale
Cache-Tv-Group
X-Uri
Property-Id
X-Varnish-Grace
X-Storage
Webcakes-App-Name
Cache-Status
Retry-After
Webcakes-Region
TWC-GeoIP-LatLong
X-MP-GENERATED-AT
TWC-Device-Class
TWC-Connection-Speed
X-Varnishpool
TWC-GeoIP-Country
X-UA-Device-Type
TWC-Locale-Group
X-Soup
X-Web-Node
TWC-Privacy
Webcakes-App-Version
X-Origin-Hint
X-PHP-Host
X-Backend-Name
X-NYM-Debug-Backend
X-Be
X-Labrador-Cache-Channel
X-Node-Name
Decoy-Debug-TTL
X-Sql-Count
X-Section
X-Timing-Wait
X-Origin-Date
X-Pubstack
X-Server-W
Selected-Fe
X-PCL
X-Format
X-Via-Fastly
X-OCL
X-Access
X-WA-Info
Cache-Name
X-No-Session
X-Sql-Duration-Ms
X-AWS-Id
Frame-Options
Fastly-SSL
X-Request-Time
X-FW-Version
X-LJ-Flow-ID
Mn-Server-Ip
X-Human
Decoy-Debug-Key
X-R9-Blue-Green-Version
X-VWS-Id
X-Redis-Cache
Decoy-Debug-Status
Country
X-Proxy-Build
X-Status
Azure-RegionName
Azure-InstanceId
X-TNCMS
Azure-SiteName
Azure-SlotName
Azure-Version
X-S-Maxage
X-LAGOON
X-PERF
X-Proto
X-Proxied
X-Tec-Api-Version
X-Hyper-Cache
X-Cache-TTL-Remaining
X-Loop
X-ApacheServer
X-BYPASS-REASON
X-ProxyCache-Key
X-ProxyCache-Status
X-SayCDN-TTL
X-Zipkin-Id
X-Xfnlog-Site
X-Tec-Api-Origin
X-Say-TTL
X-Hosted-By
X-AIR-PT
X-Tec-Api-Root
X-Routing-Service
X-Say-Cacheable
X-Alternate-Cache-Key
X-Storefront-Renderer-Rendered
X-Shopify-Stage
X-ShopId
X-CCM
X-ShardId
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
Apigw-Requestid
X-Forwarded-Host
X-Cluster
X-Cache-Grace
X-Varnish-Server
X-TT-LOGID
X-GG-Cache-Date
X-Is-Bot
X-SRV
X-Rendered-As
X-Revision
X-Info
X-Qloud-Router
X-Ratelimit-Remaining
S-Cnection
X-Microcachable
AMP-Access-Control-Allow-Source-Origin
X-Cache-Enabled
X-Cdn
X-Proxy-Cache-Status
X-Content-Age
Uber-Trace-Id
X-Via-CDN
X-Dc
Cache-Hits
X-Platform
X-FTR-Realm
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-Backend
X-Country-Code-Real
X-Azure-Ref
X-App-Version
X-FTR-DC
X-NWS-UUID-VERIFY
X-TA-CDN-Provider
X-Varnish-Ttl
Amp-Access-Control-Allow-Source-Origin
X-Backend-Host
X-Detected-As
X-Aspnetmvc-Version
X-Cache-Host
X-CSRF-Token
X-Amzn-RequestId
X-FTR-Expires
X-Amz-Meta-S3cmd-Attrs
X-Amz-Apigw-Id
X-Amzn-Remapped-Content-Length
Akamai-GRN
X-EdgeConnect-Cache-Status
X-ATG-Version
X-B3-SpanId
X-Trace-Id
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Oss-Storage-Class
SD-X-WS
Tracecode
X-Air-Hostname
X-CS
X-Oss-Server-Time
X-Oss-Request-Id
ServedBy
X-Debug-Cache
X-RCS-CacheZone
X-Time-Microsecs
X-Cache-PHP
X-Varnish-Hostname
X-Cache-NGX
X-ID
X-Akamai-Transformed
X-Correlation-ID
X-BCube-Filmed-By
X-Backend-TTL
DB-Nickname
X-Tb
X-Cache-Var-Map
X-Unique-Id
HostName
X-Cache-Var
Backend
X-ServerID
X-NewRelic-App-Data
X-Owner
X-PAYTM-SRV-ID
X-PBS-Appsvrname
X-Device-Os
X-Origin-TTL
X-A-Wwc
X-Origin-CC
X-Aed
X-Application
X-A-Dgt
X-Magnolia-Registration
X-Rewrite-Enabled
X-Rojux
Rendered-Blocks
Release
X-Processor
X-External-Request-Id
X-A-Dcw
X-Destination
X-Ms-Request-Id
Mobile-Detection-Method
X-B-Cookie
X-From
MD5-Digest
X-Generated-On
X-Generation-Time
X-GeoIP-City
Meta-Geo-Continent
X-Adobe-Source
Machine
X-Ms-Version
X-S
X-NAPM-TraceId
X-ARC
X-Location
X-Level-Front-Cache
X-Fetched-On
Odigeo-Trace-Id
BehaviorPad-Version
X-Request-UUID
X-DynaTrace-JS-Agent
X-A
X-S-Cookie
Fastcgi-X-Cache-Version
Expiry
X-VG-WebCache
T-Server
X-CF-Lambda-Version
X-Vtex-Remote-Cache
X-VG-WebServer
X-Vdms-Path
X-Vdms-Version
X-Cache-NE
X-CF-Lambda-Fn
X-Connection-Hash
X-Vtex-Processado-Em
DCR-Processing-Time-Ms
X-Trv-Group
Thinkindot-CacheControl-Type
X-A-Ccd
Xc-Version
X-Session-Fingerprint
Thinkindot-Control
X-A-Dam
X-ScT
Thinkindot-CacheControl
X-SRCache-Key
DCR-Decision-By
X-EC-Lua
X-Thinkindot-L3
X-D
DSUID
X-GEO
X-Sucuri-ID
X-TX-ID
X-Nc
Magicmarker
C-Via
Content-Disposition
X-Developers
X-Cache-Bucket
Cf-Device-Type
Host-ID
X-Geo-Header
Instruction
X-Core-Value
CacheControlHeader
X-Cms-Context
X-Fastly-Cache
X-Bip
AKAMAI
Fastly-Backend-Name
Arc-Version
Locid
Path
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
Server-Ext
X-Skip-Cache
X-Reqid
X-GeoIP
X-OVcl-Cache
X-Policy
X-Thanos
Server-Host
SR-User-Adfree
X-VServer
Wxu-Next-Commit
Wxu-Next-Hostname
Sever-Int
X-Tumblr-Pixel-3
Server-Hostname
Wxu-Next-Region
PB-RID
X-OVcl
X-JWT-State
X-Azure-Ref-OriginShield
On-Server
X-Is-Gdpr
NGX
X-Has-Esi
X-B3-Traceid
X-HS-Content-Campaign-Id
Pagetype
X-Micro-Cache
Gh-Request-Id
PB-PID
X-Nginx-Cache-Key
X-Varnish-Cache-Hits
X-Node-Id
X-Varnish-Beresp-Grace
User-Cache-Control
X-Cdn-Forward
X-Cache-Debug
X-Block-Status
X-Backend-State
X-Cache-Id
X-Cache-Info
X-Branch-Name
X-GoCache-CacheStatus
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Request-Host
X-Scheme
X-SIPLIST1
X-Ratelimit-Reset
X-Platform-Server
X-Old-Content-Length
X-Origin
X-Origin-Expires
X-Origin-Response-Time
X-Swa-Ws
X-TrackingId
X-Wikidot-Backend
X-WADP-Cache
X-Wikidot-Static-Cache
V-Age
X-User
X-VarnishDD-TTL
X-Varnish-Remaining-TTL
X-Var-Ttl
X-Variation
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-NU-AKA-ACS-Version
X-Mvc-Supplant-Cachable
X-Envoy-Decorator-Operation
X-DPWN-IS-SECURE
X-Esi-Check
X-Fastly-Backend
X-FC-Vary-Parameters
X-Dispatcher-Server
X-Developer
X-Clientip
X-CUA
X-DefElseHash
X-DefHash
X-Fmm-Version
X-Gen-Mode
X-Li-Fabric
X-Li-Pop
X-LI-UUID
X-Method
X-Irp-Debug
X-IP
X-Generated-By
Web-Mar-Node
X-HN
X-Hnp-Log
X-Clara-WADP
X-Gzip
Cf-Bgj
CDN-Uid
CDN-RequestId
Fastly-SIE
Fastly-SWR
IsBot
Is-Eu
CDN-RequestCountryCode
CDN-PullZone
Cache-Host
UCS
CDCHOST
CDN-Cache
CDN-EdgeStorageId
CDN-CachedAt
Location
Adler-Geo
PFcat
NM-Fastcgi-Cache
Platform
Ssr
X-Varnish-Beresp-Ttl
X-Cache-Backend
True-Client-Country-4JS
Vix-Hermes-Req-Id
X-Generated-In
X-VG-TLSProxy
X-Csrf-Jwt
Rt-Fastcgi-Cache
X-Eu-Site
Esi-Enabled
X-Request-URI
Apple-News-Services-Request-Url
X-Varnish-Beresp-Status
X-Unique-ID
Who
X-Slack-Backend
X-Varnish-Hits
X-Matched-Rule
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Handled
X-LB-ID
X-Hash
X-Gamma-Serve
HA-Ipaddr
X-Cache-Tags
Ha-Gx-Prefs
X-CGP
Origin
L5d-Success-Class
L
Lfy
Country-Code
X-CLOUD-TRACE-CONTEXT
Fastly-Drupal-HTML
X-Loc
X-Aicache-OS
X-Goog-Meta-Goog-Reserved-File-Mtime
CloudFront-Viewer-Country
X-CACHE-KEY
X-APP-VERSION
Geo-Info
Sid
X-RateLimit-Limit
X-NCache
Tcn
X-Mvc-Supplant-OutputCached
X-Cache-Expires
X-Varnish-Url
X-Via-Popv
X-Cdn-Origin
X-Via-Poph
X-Sn-Servicetimems
X-Via-Popn
Pics-Label
Pramga
X-PF-Uncompressing
X-Servername
X-Epic-Correlation-Id
X-Core-Mission
X-Cache-Date
X-URL
Filterid
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
X-Request-Start
X-Tb-Optimization-Total-Bytes-Saved
X-Refresh
Url
X-TraceId
Req-Svc-Chain
X-FireWall-Protection
X-Esi
Cmsid
Cmstype
X-DC
X-Varnish-Cacheable
X-Served-From
Kp-EeAlive
X-Error
Svr
MIME-Version
Source
A
X-Response-By
VivaBuild
Viewtype
NGB
Cache-Key
X-NC
X-Webkit-CSP-Report-Only
X-Erf-Stays-Bingo-Pdp-Web
X-Proxy-Cachei7
Geoip-Latitude
Xkeyi7
GeoIp-Country-Code
M-TraceId
X-Srv
X-Cache-Remote
Server-Ttl
Cross-Origin-Opener-Policy
TDXMobile
Server-ID
N-Cache
X-Wa
HitType
Arc-Country
X-BBXSRF
X-Air-Source
S-Rt
Content-Secure-Policy
X-HS-Status
X-Servedbyhost
X-Vgn-Hpd-Reason
X-B3-Spanid
X-Vcl-Version
X-HostName
X-Cache-2
X-CDN-Forward
X-Contensis-Viewer-Groups
X-Cc-Via
D-Cc-Upstream
X-Varnish-Authentication
X-LiteSpeed-Cache-Control
X-Cc-Req-Id
X-LI-Proto
Resin-Trace
X-Cache-ASPX
X-Vc
X-JoinUs
Cteonnt-Length
X-Host-Name
X-Sucuri-Cache
Ohc-File-Size
Cross-Origin-Window-Policy
SID
NtCoent-Length
X-NGENIX-Cache
CACHE
X-PHP-Backend
X-SaId
X-Internal-Host
X-Service
X-Geo
X-RAMCache
X-Svr
X-Li-Proto
X-Edge-Location
X-HOST
X-CCDN-Origin-Time
X-VCL-Version
Request-ID
DataCenter
Hostname
X-Hcs-Proxy-Type
X-Server-IP
XServer
X-CCDN-CacheTTL
X-UA
X-Extlb
X-Forwarded-Site
X-WA
X-DW
X-Cache-Config
X-RSL
X-RPM
X-RPS
X-Via-NSCOPI
X-Origin-Time
X-API-Version
FSS-Cache
X-Nyt-Route
X-Newrelic-Synthetics
X-FPC
X-TIM-N
X-Viewer-Country
X-Gdpr
X-DSS
X-DI
X-DB
X-ServedByHost
X-FORWARDED-FOR
X-App
X-VC
X-Dynatrace
CF-Cached-On
X-Bc-Bl
X-Cs
X-SN
X-Check-Cacheable
GeoIP-Country-Code
GeoIP-Latitude
Cache-Provider
Ohc-Cache-HIT
LB
We-Hiring
ProcessTime
X-Req
X-VC-Cache
X-Date
X-Region-Sid
X-SB
X-Accel-Expires-Debug
Server-Id
X-Webstats-RespID
X-Proxy-Upstream
Memcached
X-ZONE
X-Action
X-PJAX-URL
Surrogated-Key
Mail-Subject
X-NodeID
X-TIME
X-COUNTRY
X-Dynatrace-Js-Agent
X-Presslabs-Stats
X-Oss-Cdn-Auth
Env
Mime-Version
X-Instrumentation
X-Kraken-Loop-Name
X-RateLimit-Limit-Second
X-Server-Lifecycle-Phase
X-CF-Powered-By
X-SD-PageType
X-Kraken-Routeconfig-Destination
X-RateLimit-Remaining-Second
X-Fpc
X-Provided-By
X-CSRF-TOKEN
X-BBC-Edge-Cache-Status
X-Render-Time
Upgrade-Insecure-Requests
W
X-APP
X-Depends-On
X-Sigma-Backend
X-Men
X-Air-Trace-Id
X-Rocket-Build-Number
X-Sigma
Srv
X-NGINX-Cache
X-Swift-Error
X-Cdn-Request-ID
CPC-Age
VNS-Age
VNS-Cache
CPC-Cache
EpKe-Alive
X-MSEdge-Flight
X-MSEdge-Features
X-Ftr-Cache-Host
X-Dw-Trace-Id
X-UnsetCookies
Cdn
CDN
X-BACKEND-TTL
X-CACHE-AGE
X-Client-Ip
X-FTR-Cache-Host
Processtime
X-Fastly-Backend-Reqs
X-Auto-Login
Dnion-Transfer-Encoding
X-Fastly-Request-Id
Memory
Time
X-Cache-Tag
X-ABtesting
X-Flog
X-Parent-Response-Time
X-Worker
X-Hello
X-Ua
Datacenter
X-Akamai-Pragma-Client-IP
Media-Length
X-Pad
X-Acquia-Site
X-Acquia-Purge-Tags
Proxy-Connection
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-Oracle-DMS-ECID
X-Zone
Vha6-Origin
X-Cluster-Node
X-BBC-Origin-Response-Status
X-Pf-Uncompressing
X-IN-APIGATEWAY
X-LiteSpeed-Tag
X-IN-APIGATEWAYSSL
My-App
PICS-Label
Epwk-X-Cache
X-Via-PopV
State
X-Via-PopH
X-Snapshot-Date
X-Via-PopN
Fastcgi-Cache-TTL
X-ServerName
Cf-Ipcountry
X-Varnish-URL
X-Request-URL
X-Minions-Version
X-ElasticPress-Query
X-Cache-Status-Check
X-Edge-Location-Klb
X-Vcache
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-Varnish-Beresp-TTL
X-MiniProfiler-Ids
X-Lb-Id
X-ElasticPress-Search
X-Ms-Meta-Originalurl
X-Ms-Meta-Staticbatchstarttime
Xet-Cookie
CountryCode
X-Tx-Id
X-Litespeed-Cache-Control
X-Apw-Access-Token
X-Nananana
Content-Style-Type
Content-Script-Type
X-Apw-Access-Action
X-Apw-Hits
X-Apw-Access-Object
X-Redis-Duration-Ms
X-Redis-Count
URI
X-Traceid
Environment
X-Storefront-Renderer-Verified
X-Request-Url
X-C
OT-Force-Account-Verify
NnCoection
X-Debug-Cache-Store
Inserted-Into-Cache-At
X-Tid
X-Debug-Cache-Fetch
Ohc-Response-Time
X-B3-Parentspanid
Phost
X-Amz-Meta-Cb-Modifiedtime