Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
Link
X-XSS-Protection
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Request-Id
X-Varnish
Access-Control-Allow-Methods
X-Xss-Protection
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Cache-Status
X-Generator
X-Cacheable
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
X-Request-ID
Content-Encoding
X-CDN
X-Ua-Compatible
Feature-Policy
X-AspNetMvc-Version
Status
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Upgrade
X-Via
Access-Control-Max-Age
Keep-Alive
X-Ws-Request-Id
X-Age
X-Robots-Tag
X-AH-Environment
X-Turbo-Charged-By
EagleId
Request-Context
X-Proxy-Cache
X-Cache-Group
Server-Timing
X-Backend
X-Server
X-Hacker
X-Dns-Prefetch-Control
Report-To
Host-Header
X-Server-Powered-By
X-Amz-Request-Id
Grace
X-Nginx-Cache-Status
X-Amz-Id-2
X-UA-Device
X-Rq
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Page-Speed
Cf-Railgun
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
X-Amz-Version-Id
NEL
X-Cache-Spec
X-Device
X-CST
Allow
X-Vhost
X-WebKit-CSP
X-Host
X-Backend-Server
Xkey
X-Server-Id
EagleEye-TraceId
X-Dispatcher
X-Node
Surrogate-Control
Request-Id
Content-Location
X-Response-Time
X-Akam-SW-Version
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
P3p
X-ASPNET-VERSION
X-Ruxit-JS-Agent
X-Cache-Lookup
X-Application-Context
X-Ac
Accept-Ch
X-Country
X-Template
X-Mod-Pagespeed
Accept-CH
Accept-Ch-Lifetime
X-Language
X-Readtime
X-Cloud-Trace-Context
Accept-CH-Lifetime
X-B3-TraceId
MS-Author-Via
Rating
X-HW
X-Url
X-Origin-Cache
X-Cnection
X-MS-InvokeApp
X-TtlSet
X-Vname
X-PC
Edge-Control
X-Clacks-Overhead
X-GitHub-Request-Id
X-ESI
X-Trace
X-ORACLE-DMS-RID
X-Middleton-Display
X-Middleton-Response
X-Sol
Response
Pagespeed
Display
X-ORACLE-DMS-ECID
X-Varnish-TTL
X-Content-Type
X-D2id
Verso
Arr-Disable-Session-Affinity
X-Exp-Id
X-Exp-Variant
X-Kinja-Build
X-Kinja-Server
X-Cdn-Fetch
X-Kinja-Revision
X-Kinja
X-Use-Magma
X-GoogleNews-Bot
X-Vcap-Request-Id
X-Country-Code
X-Rack-Cache
X-Powered-By-Plesk
X-Goog-Hash
X-TTL
X-Oneagent-Js-Injection
X-Navigation-Version
X-Server-Name
Service-Worker-Allowed
X-Abt-Application-Version
X-VARITI-CCR
X-Amz-Rid
X-Buckets
X-Fastly-Request-ID
X-Client-IP
Fastly-Restarts
X-Cache-TTL
X-Cached
X-FastCGI-Cache
X-Release
X-MSEdge-Ref
X-Dw-Request-Base-Id
X-Element-Page-Cache
X-SharePointHealthScore
SPRequestGuid
X-NF-Request-ID
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
SPRequestDuration
X-B3-TraceId-Primal
MRF-Tech
SPIisLatency
Mrf-Cache-Status
Public-Key-Pins
X-Webkit-CSP
Access-Control-Request-Method
RTSS
AR-ATIME
AR-PoweredBy
Ar-Sid
AR-CACHE
AR-Request-ID
X-Edge
Cache-Tag
X-Powered-CMS
X-LLID
X-Ezoic-Cdn
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Upstream
Content-MD5
X-Jurisdiction
X-HP-Webp
X-Version
X-Origin-Upstream-Status
S
X-Recruiting
X-Mid
X-MCACHE
X-ECACHE
Fusion-Template-Id
Fusion-Source
Fusion-Component-Id
Fusion-Deployment-Id
Fusion-Content-Id
Fusion-Content-Source
X-Mg-S
Charset
X-Px
X-Ruxit-Js-Agent
X-DynaTrace
X-Content-Digest
X-PressLabs-Stats
X-Kinsta-Cache
Fastcgi-Cache
X-T
Cache-Tags
X-Litespeed-Cache
X-Fastcgi-Cache
X-Amz-Server-Side-Encryption
X-Id
X-Accel-Expires
X-Logged-In
Filters
X-Forwarded-Proto
Server-Node
X-Content-Security-Policy-Report-Only
Edge-Cache-Tag
X-Ttl
MicrosoftSharePointTeamServices
Front-End-Https
Server-Name
TP-L2-Cache
TP-Cache
X-Correlation-Id
X-Forwarded-For
TCN
X-Grace
Nginx-Cache
X-Debug
X-Request-Received
X-Request-Processing-Time
X-Kong-Proxy-Latency
X-Hits
X-Kong-Upstream-Latency
X-Amzn-Trace-Id
X-B3-Sampled
X-Shield-Request-Id
X-Request-Handler-Origin-Region
X-Microsite
X-Varnish-Age
X-Yandex-Sdch-Disable
X-Activity-Id
X-Az
X-AppVersion
Surrogate-Key
X-Amz-Replication-Status
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Hub-Id
X-HS-Cache-Config
X-F-Cache
X-XRDS-LOCATION
X-Origin-Server
X-XRDS-Location
Alternate-Protocol
X-Ser
X-DIS-Request-ID
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Metageneration
Nel
Accept-Charset
X-Geo-Country
X-Rid
X-NWS-LOG-UUID
Section-Io-Cache
X-Git-Hash
X-Frontend
Host
X-Respond-Thread
X-Pinterest-Direct
X-Cache-Key
X-Cache-Age
X-Upgrade-Enabled
X-Time
X-LB-Cache
X-DataDome
Access-Control-Allow-Method
X-Seen-By
X-Hostname
X-Mobile-URL
X-Server-ID
X-VCache
MS-CV
Paypal-Debug-Id
X-Type
Cache
ServerID
X-Daa-Tunnel
X-IPLB-Instance
Healthy
Payment
X-Is-Crawler
X-Flags
X-Content-Options
X-Aspnet-Duration-Ms
X-App-Environment
X-Providence-Cookie
X-Varnish-Backend
X-Route-Name
X-TT
X-AOL-HN
X-Request-Guid
X-FTR-Request-ID
X-Source
X-B-Cache
X-Signature
X-RateLimit-Remaining
X-Cache-Action
X-Debug-Info
Cleartype
X-Page-Id
X-Whom
Fastcgi-Useragent
X-WebKit-CSP-Report-Only
X-Load-Cache
X-Jobs
X-N
X-FB-Debug
X-Contextid
Powered-By-ChinaCache
X-Webkit-Csp
X-Mobile
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Browser-Type
Realpath
Node
X-Rule
Refresh
X-Response-Served-From
X-Original-Request-Id
X-Cache-Expired-At
X-Accel-Buffering
X-Drupal-Cache-Tags
X-Wix-Request-Id
X-RTag
Ms-Operation-Id
DC
X-Zen-Fury
X-Proxy
X-Framework
Referer-Policy
X-Via-JSL
X-B
X-Cacheable-TTL
X-Cache-Control
X-Instance
X-HTML-Minification-Powered-By
X-RemovedCookies
X-ProcessESI
X-Cluster-Name
X-Tt-Trace-Host
Viewport
X-Real-IP
X-Page-View
X-Tt-Trace-Tag
X-Distributor
X-Content-Powered-By
X-Drupal-Cache-Contexts
Access-Control-Request-Headers
X-UUID
X-Cache-Time
Version
Eomportal-Instance
X-Region
X-IPS-LoggedIn
X-FW-Serve
X-FW-Hash
X-FW-Dynamic
X-FW-Static
X-FW-Server
X-FW-Type
X-TEC-API-ROOT
X-TEC-API-VERSION
VIX-Pulpo-Upstream-Status
X-TEC-API-ORIGIN
VIX-Pulpo-Node
Countrycode
X-FireWall-Port
X-Akamai-Edgescape
Liferay-Portal
X-Cache-Rule
X-Cache-Operation
X-Cached-By
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Cache-Hit
X-Tumblr-Pixel
X-Pass-Why
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-G
X-L-Path
X-Environment-Context
X-App-Server
SRV
Server-Info
DynaTrace
CF-IPCountry
Section-Origin-Responded
Section-Io-Origin-Status
Section-Io-Id
Section-Io-Origin-Time-Seconds
X-Debug-IsConnected
X-Debug-IsPreview
X-Tec-Api-Root
X-Tec-Api-Origin
X-Tec-Api-Version
Xserver
X-Nginx-Cache
X-Www-Served-By
X-User-Agent
X-Protected-By
From-Origin
Ec-Rule-Version
Webserver
X-Tumblr-Pixel-2
GEO-INFO
X-Device-Type
X-Varnish-Grace
X-Mode
X-Handled-By
X-Hl-Ver
X-RN-RSRV
X-UPSTREAM-Address
X-ES-SERVER
Meta-Geo
X-Adobe-Loc
X-Adobe-Content
X-Backend-Name
X-FB-TRIP-ID
X-MP-GENERATED-AT
Retry-After
X-Endurance-Cache-Level
Webcakes-App-Version
Webcakes-Region
Webcakes-App-Name
TWC-Privacy
TWC-Locale-Group
X-Access
X-Section
X-OCL
X-Cache-Server
X-Be
X-Origin-Hint
X-PCL
TWC-GeoIP-LatLong
X-Pubstack
Fastly-SSL
Decoy-Debug-TTL
X-Varnishpool
Property-Id
TWC-Connection-Speed
Decoy-Debug-Status
Decoy-Debug-Key
TWC-GeoIP-Country
Cache-Status
TWC-Device-Class
Cache-Tv-Group
X-Ratelimit-Limit
X-NYM-Debug-Backend
X-Format
X-Uri
X-Storage
X-PHP-Host
X-WA-Info
X-Server-W
X-PERF
X-ApacheServer
X-Sql-Duration-Ms
Cache-Name
X-Web-Node
Country
X-Labrador-Cache-Channel
X-Proxy-Build
X-LAGOON
X-VWS-Id
X-Site-Version
X-Redis-Cache
X-R9-Blue-Green-Version
X-Via-Fastly
X-AWS-Id
X-UA-Device-Type
X-No-Session
X-Locale
X-Proto
Mn-Server-Ip
X-Sql-Count
X-Soup
Selected-Fe
X-Human
X-Timing-Wait
X-LJ-Flow-ID
X-Request-Time
Azure-SiteName
Azure-SlotName
X-Xfnlog-Site
X-Zipkin-Id
X-Proxied
Azure-RegionName
Azure-InstanceId
Apigw-Requestid
Azure-Version
Frame-Options
X-Routing-Service
X-ProxyCache-Key
X-FW-Version
X-SayCDN-TTL
X-Say-TTL
X-ProxyCache-Status
X-Origin-Date
X-BYPASS-REASON
X-Say-Cacheable
X-AIR-PT
X-S-Maxage
X-Hyper-Cache
X-Hosted-By
X-Cache-TTL-Remaining
X-TNCMS
X-Status
X-Loop
X-Alternate-Cache-Key
X-Varnish-Server
Protected
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Shopify-Stage
X-ShopId
X-Storefront-Renderer-Rendered
X-Node-Name
X-ShardId
X-Cache-Grace
X-CCM
X-TT-LOGID
X-GG-Cache-Date
X-Forwarded-Host
X-Info
X-Rendered-As
X-Is-Bot
X-TA-CDN-Provider
X-Cluster
X-Microcachable
X-SRV
X-Qloud-Router
AMP-Access-Control-Allow-Source-Origin
X-Cache-Enabled
X-Dc
S-Cnection
X-Revision
Uber-Trace-Id
X-Proxy-Cache-Status
X-Content-Age
X-NWS-UUID-VERIFY
X-Via-CDN
X-Platform
X-Azure-Ref
X-Backend-Host
Cache-Hits
X-Varnish-Ttl
Amp-Access-Control-Allow-Source-Origin
X-FTR-Backend
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-DC
X-Country-Code-Real
X-FTR-Realm
X-Ratelimit-Remaining
X-Aspnetmvc-Version
X-FTR-Backend-Server
X-CSRF-Token
X-Detected-As
Akamai-GRN
X-Amz-Meta-S3cmd-Attrs
X-Amz-Apigw-Id
X-Cache-Host
X-App-Version
X-Amzn-Remapped-Content-Length
X-Amzn-RequestId
ServedBy
X-EdgeConnect-Cache-Status
X-ATG-Version
X-Trace-Id
X-B3-SpanId
X-Cache-PHP
X-Oss-Object-Type
X-Oss-Request-Id
X-Debug-Cache
X-RCS-CacheZone
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-Oss-Storage-Class
X-Cache-NGX
X-CS
SD-X-WS
X-Varnish-Hostname
X-FTR-Expires
Tracecode
X-BCube-Filmed-By
X-Correlation-ID
X-Nc
HostName
X-Air-Hostname
X-Ms-Version
X-Time-Microsecs
X-Ms-Request-Id
X-Backend-TTL
DB-Nickname
X-Akamai-Transformed
X-Tb
X-NewRelic-App-Data
X-Adobe-Source
X-CF-Lambda-Version
X-VG-WebServer
X-CF-Lambda-Fn
X-Cache-NE
DCR-Decision-By
X-SRCache-Key
X-Magnolia-Registration
X-Connection-Hash
BehaviorPad-Version
X-External-Request-Id
X-ServerID
X-Destination
X-Processor
X-D
T-Server
X-VG-WebCache
X-A-Dcw
X-A-Dgt
X-A-Dam
X-A-Ccd
X-Vdms-Version
X-A
X-A-Wwc
X-Aed
Rendered-Blocks
X-Trv-Group
X-Vdms-Path
X-B-Cookie
X-Application
X-ARC
Odigeo-Trace-Id
X-Vtex-Processado-Em
X-Origin-TTL
X-Vtex-Remote-Cache
Xc-Version
X-Origin-CC
X-NAPM-TraceId
X-Session-Fingerprint
X-Location
Fastcgi-X-Cache-Version
X-PAYTM-SRV-ID
X-Request-UUID
DCR-Processing-Time-Ms
Expiry
X-Rewrite-Enabled
X-DynaTrace-JS-Agent
X-PBS-Appsvrname
X-Rojux
X-Level-Front-Cache
X-Generation-Time
Meta-Geo-Continent
X-TX-ID
X-ScT
X-S-Cookie
Machine
X-From
Mobile-Detection-Method
X-Generated-On
X-S
MD5-Digest
X-Cache-Var
Backend
X-Unique-Id
X-Cache-Var-Map
PB-RID
Release
Thinkindot-CacheControl
Pagetype
Locid
Host-ID
Gh-Request-Id
Fastly-Backend-Name
Magicmarker
On-Server
CacheControlHeader
Cf-Device-Type
Content-Disposition
Path
PB-PID
X-Device-Os
X-Micro-Cache
X-Mvc-Supplant-Cachable
X-OVcl
X-JWT-State
X-Is-Gdpr
X-HS-Content-Campaign-Id
X-Irp-Debug
X-OVcl-Cache
X-Owner
X-TrackingId
X-Tumblr-Pixel-3
X-Thinkindot-L3
X-Thanos
X-Policy
X-Reqid
X-Has-Esi
X-GeoIP-City
Wxu-Next-Region
X-Azure-Ref-OriginShield
X-Bip
Wxu-Next-Hostname
Wxu-Next-Commit
Thinkindot-Control
UCS
X-Cache-Bucket
X-Cms-Context
X-Generated-In
X-Geo-Header
X-FC-Vary-Parameters
X-Fastly-Cache
X-Core-Value
X-Developers
Thinkindot-CacheControl-Type
X-Fetched-On
X-Unique-ID
X-B3-Traceid
X-CACHE-KEY
X-Varnish-Cache-Hits
AKAMAI
X-Sucuri-ID
Arc-Version
Who
X-Varnish-Beresp-Grace
User-Cache-Control
X-Generated-By
X-GeoIP
X-GoCache-CacheStatus
X-Gen-Mode
Server-Ext
X-Fmm-Version
X-HN
X-Hnp-Log
X-Node-Id
X-NU-AKA-ACS-Version
X-Nginx-Cache-Key
X-Method
Server-Host
X-IP
PFcat
Server-Hostname
Web-Mar-Node
X-GEO
V-Age
X-Cache-Tags
X-Swa-Ws
X-Backend-State
X-Block-Status
X-Cache-Debug
X-CGP
X-Clara-WADP
X-Envoy-Decorator-Operation
Sever-Int
X-Eu-Site
SR-User-Adfree
X-Developer
X-Clientip
X-Csrf-Jwt
X-CUA
NGX
X-Origin-Response-Time
Apple-News-Services-Handled
Apple-News-Services-Host
X-VarnishDD-TTL
DSUID
Esi-Enabled
X-User
X-Var-Ttl
Ssr
X-VG-TLSProxy
Apple-News-Services-Parsed-Url
X-WADP-Cache
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Cdn-Forward
Cf-Bgj
X-VServer
Apple-News-Services-Request-Url
Fastly-SIE
Fastly-SWR
X-Request-URI
L5d-Success-Class
IsBot
X-Request-Host
X-Rebelmouse-Surrogate-Control
X-Platform-Server
CDCHOST
X-Rebelmouse-Cache-Control
X-Cache-Info
Instruction
X-Skip-Cache
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
Ha-Gx-Prefs
HA-Ipaddr
C-Via
X-SIPLIST1
Cache-Host
X-RateLimit-Limit
X-ID
X-EC-Lua
Country-Code
X-Varnish-Beresp-Ttl
Is-Eu
X-Esi-Check
True-Client-Country-4JS
Location
Vix-Hermes-Req-Id
X-Scheme
X-Variation
Adler-Geo
X-Li-Fabric
X-Ratelimit-Reset
X-Li-Pop
X-DefElseHash
X-DefHash
NM-Fastcgi-Cache
X-DPWN-IS-SECURE
X-Old-Content-Length
X-Origin
X-APP-VERSION
X-LI-UUID
X-Origin-Expires
X-Dispatcher-Server
X-Varnish-Beresp-Status
CDN-CachedAt
Origin
L
X-Cache-Id
CDN-Cache
X-Gzip
X-Aicache-OS
X-Varnish-Hits
Platform
CDN-PullZone
CDN-EdgeStorageId
X-Fastly-Backend
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
CDN-RequestCountryCode
CDN-Uid
CDN-RequestId
X-Branch-Name
X-CLOUD-TRACE-CONTEXT
Rt-Fastcgi-Cache
X-Hash
X-Matched-Rule
X-LB-ID
Lfy
X-Mvc-Supplant-OutputCached
X-Varnish-Url
X-Cache-Backend
X-Loc
X-Gamma-Serve
X-Slack-Backend
Geo-Info
Filterid
X-NCache
X-Epic-Correlation-Id
X-Goog-Meta-Goog-Reserved-File-Mtime
Pics-Label
X-PF-Uncompressing
Fastly-Drupal-HTML
CloudFront-Viewer-Country
Sid
X-Via-Popn
Pramga
X-Via-Popv
X-Via-Poph
X-Sn-Servicetimems
X-Refresh
X-Cache-Expires
X-Cdn-Origin
X-Planisys-CDN-TTL
X-Core-Mission
X-Cache-Date
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Servername
X-Tb-Optimization-Total-Bytes-Saved
X-TraceId
Cmstype
Cmsid
Url
Req-Svc-Chain
Tcn
X-Served-From
NGB
Kp-EeAlive
Svr
X-Request-Start
Cache-Key
X-Error
A
Viewtype
X-FireWall-Protection
VivaBuild
M-TraceId
Source
X-Varnish-Cacheable
MIME-Version
X-Webkit-CSP-Report-Only
Cross-Origin-Opener-Policy
X-Response-By
GeoIp-Country-Code
X-Srv
Geoip-Latitude
Arc-Country
X-DC
X-NC
X-Vgn-Hpd-Reason
X-Wa
X-Proxy-Cachei7
TDXMobile
Server-ID
X-HS-Status
Xkeyi7
X-Servedbyhost
HitType
X-Air-Source
X-PHP-Backend
X-SaId
Content-Secure-Policy
X-BBXSRF
X-Vcl-Version
N-Cache
X-CDN-Forward
X-JoinUs
Server-Ttl
X-NGENIX-Cache
X-B3-Spanid
X-Vc
X-Edge-Location
X-Geo
NtCoent-Length
X-Erf-Stays-Bingo-Pdp-Web
X-Cache-Remote
S-Rt
SID
X-Cache-2
Resin-Trace
X-LiteSpeed-Cache-Control
X-Internal-Host
X-Esi
DataCenter
CACHE
X-Cc-Req-Id
X-Hcs-Proxy-Type
X-Cache-ASPX
X-Li-Proto
X-LI-Proto
X-Contensis-Viewer-Groups
D-Cc-Upstream
X-Service
X-Varnish-Authentication
X-Cc-Via
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-Extlb
Cteonnt-Length
X-HOST
X-Svr
X-RAMCache
Ohc-File-Size
FSS-Cache
X-Forwarded-Site
X-Sucuri-Cache
Cross-Origin-Window-Policy
X-VCL-Version
X-Viewer-Country
Request-ID
XServer
X-UA
X-HostName
X-Host-Name
X-DB
X-Bc-Bl
X-DI
X-WA
X-ServedByHost
X-RSL
X-Newrelic-Synthetics
X-TIM-N
X-Via-NSCOPI
X-RPS
X-RPM
X-DSS
X-DW
X-Server-IP
Hostname
GeoIP-Country-Code
X-FPC
X-Gdpr
X-VC-Cache
X-API-Version
X-Cache-Config
LB
GeoIP-Latitude
Mail-Subject
Memcached
CF-Cached-On
X-Cs
X-Origin-Time
X-Nyt-Route
X-App
Surrogated-Key
We-Hiring
X-PJAX-URL
X-Proxy-Upstream
Cache-Provider
X-Kraken-Routeconfig-Destination
X-ZONE
X-NodeID
X-Kraken-Loop-Name
X-Action
X-Check-Cacheable
X-Date
X-RateLimit-Limit-Second
X-Accel-Expires-Debug
X-Server-Lifecycle-Phase
X-VC
X-Req
X-Instrumentation
X-SN
X-RateLimit-Remaining-Second
ProcessTime
X-Dynatrace-Js-Agent
X-Swift-Error
Ohc-Cache-HIT
X-TIME
X-APP
X-Rocket-Build-Number
Upgrade-Insecure-Requests
X-Region-Sid
X-Sigma-Backend
Server-Id
Env
X-Sigma
X-SB
X-Fpc
X-Men
X-Oss-Cdn-Auth
X-Webstats-RespID
X-CF-Powered-By
X-URL
X-Edge-Location-Klb
X-Provided-By
X-MSEdge-Flight
W
Mime-Version
X-MSEdge-Features
X-FORWARDED-FOR
X-Air-Trace-Id
X-SD-PageType
CPC-Cache
VNS-Age
X-Depends-On
Memory
CPC-Age
Time
VNS-Cache
X-Cdn-Request-ID
Srv
X-NGINX-Cache
X-Render-Time
X-UnsetCookies
X-Dw-Trace-Id
CDN
X-BACKEND-TTL
X-Ftr-Cache-Host
X-CSRF-TOKEN
Cdn
X-BBC-Edge-Cache-Status
X-Zone
X-Client-Ip
X-Fastly-Request-Id
EpKe-Alive
X-ABtesting
Dnion-Transfer-Encoding
X-Fastly-Backend-Reqs
X-Parent-Response-Time
X-Hello
X-Flog
X-Akamai-Pragma-Client-IP
X-Dynatrace
X-Auto-Login
X-Acquia-Application-Trace
Media-Length
Proxy-Connection
X-Acquia-Purge-Tags
X-ServerName
X-Cache-Tag
Fastcgi-Cache-TTL
My-App
X-Acquia-Site
Processtime
X-Pad
X-Oracle-DMS-ECID
X-Presslabs-Stats
X-Pf-Uncompressing
X-Acquia-Application-UUID
Vha6-Origin
X-FTR-Cache-Host
X-Worker
X-BBC-Origin-Response-Status
X-Ua
X-LiteSpeed-Tag
PICS-Label
Epwk-X-Cache
X-Cluster-Node
X-Via-PopH
Datacenter
X-Snapshot-Date
State
X-Via-PopN
X-Via-PopV
X-CACHE-AGE
Cf-Ipcountry
X-Akamai-ERRuleID
X-Request-URL
X-ElasticPress-Query
X-Varnish-Beresp-TTL
X-Varnish-URL
X-IN-APIGATEWAY
X-MiniProfiler-Ids
X-ElasticPress-Search
X-Ms-Meta-Originalurl
Xet-Cookie
X-Ms-Meta-Staticbatchstarttime
X-Akamai-ERPolicy
X-Minions-Version
X-Vcache
X-Lb-Id
X-IN-APIGATEWAYSSL
CountryCode
X-Tx-Id
X-Litespeed-Cache-Control
OT-Force-Account-Verify
Warning
X-Apw-Access-Object
X-Mg-Request-Id
X-Apw-Access-Token
X-Apw-Hits
X-Apw-Access-Action
Content-Style-Type
X-Cache-Status-Check
Content-Script-Type
X-Redis-Duration-Ms
URI
X-Debug-Cache-Fetch
X-C
Ohc-Response-Time
Phost
X-Traceid
X-Debug-Cache-Store
X-B3-Parentspanid
X-Tid
X-Amz-Meta-Cb-Modifiedtime
Environment
Inserted-Into-Cache-At
NnCoection
X-Redis-Count
X-Storefront-Renderer-Verified