Threat Level: green Handler on Duty: Renato Marinho

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-RAY
CF-Cache-Status
Accept-Ranges
Link
X-XSS-Protection
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-UA-Compatible
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
X-Xss-Protection
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Request-ID
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Ua-Compatible
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Content-Encoding
X-CDN
X-AspNetMvc-Version
Feature-Policy
X-Envoy-Upstream-Service-Time
Status
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-Via
Upgrade
Access-Control-Max-Age
Keep-Alive
X-Ws-Request-Id
X-Age
X-AH-Environment
X-Robots-Tag
X-Turbo-Charged-By
Request-Context
X-Proxy-Cache
X-Cache-Group
EagleId
Server-Timing
X-Backend
X-Hacker
X-Server
Report-To
Host-Header
X-Amz-Request-Id
X-Server-Powered-By
X-Amz-Id-2
Grace
X-Nginx-Cache-Status
X-UA-Device
X-Rq
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Page-Speed
Cf-Railgun
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-OneAgent-JS-Injection
NEL
X-Dns-Prefetch-Control
X-Cache-Spec
X-Amz-Version-Id
X-WebKit-CSP
X-Device
X-CST
Allow
Xkey
X-Vhost
X-Host
X-Backend-Server
X-Server-Id
EagleEye-TraceId
Request-Id
Surrogate-Control
X-Dispatcher
X-Node
Content-Location
X-Response-Time
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Ruxit-JS-Agent
X-Akam-SW-Version
Accept-CH
P3p
X-ASPNET-VERSION
X-Ac
X-Application-Context
X-Cache-Lookup
X-Country
X-Template
X-Language
Accept-CH-Lifetime
X-Mod-Pagespeed
X-Readtime
Accept-Ch-Lifetime
Accept-Ch
X-Cloud-Trace-Context
MS-Author-Via
X-B3-TraceId
Rating
X-Origin-Cache
X-MS-InvokeApp
X-Cnection
X-HW
X-Url
X-TtlSet
X-PC
X-Vname
X-Clacks-Overhead
X-GitHub-Request-Id
Edge-Control
X-ESI
X-ORACLE-DMS-ECID
X-Trace
X-Sol
X-Middleton-Display
Response
Pagespeed
X-Content-Type
X-Middleton-Response
Display
X-D2id
X-ORACLE-DMS-RID
Arr-Disable-Session-Affinity
Verso
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Vcap-Request-Id
X-Kinja
X-Exp-Id
X-Exp-Variant
X-GoogleNews-Bot
X-Kinja-Build
X-Cdn-Fetch
X-Goog-Hash
X-Rack-Cache
X-Country-Code
X-Buckets
X-FastCGI-Cache
X-Server-Name
X-Varnish-TTL
X-Navigation-Version
Service-Worker-Allowed
X-Powered-By-Plesk
X-VARITI-CCR
X-Amz-Rid
X-Fastly-Request-ID
X-Abt-Application-Version
X-Webkit-CSP
X-Client-IP
X-Cache-TTL
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
Fastly-Restarts
X-Release
SPRequestGuid
X-SharePointHealthScore
X-MSEdge-Ref
X-Cached
X-TTL
X-Element-Page-Cache
X-Dw-Request-Base-Id
X-Oneagent-Js-Injection
SPRequestDuration
SPIisLatency
X-NF-Request-ID
Public-Key-Pins
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
RTSS
Access-Control-Request-Method
X-SRCache-Store-Status
X-SRCache-Fetch-Status
AR-Request-ID
AR-CACHE
X-Edge
Ar-Sid
AR-PoweredBy
AR-ATIME
X-LLID
X-Powered-CMS
X-Ezoic-Cdn
X-Litespeed-Cache
X-Origin-Upstream-Status
Cache-Tag
X-Upstream
Content-MD5
X-Px
Fusion-Content-Source
Fusion-Source
Fusion-Template-Id
Fusion-Content-Id
Fusion-Deployment-Id
Fusion-Component-Id
X-Jurisdiction
X-HP-Webp
X-Ttl
S
X-Version
X-ECACHE
X-MCACHE
X-Mid
X-Recruiting
X-Mg-S
Charset
X-Content-Digest
X-PressLabs-Stats
Fastcgi-Cache
X-Amz-Server-Side-Encryption
X-Kinsta-Cache
X-T
Cache-Tags
MicrosoftSharePointTeamServices
X-Id
Front-End-Https
Filters
X-DynaTrace
X-Content-Security-Policy-Report-Only
TCN
X-Logged-In
X-Debug
Server-Node
Edge-Cache-Tag
X-Accel-Expires
X-Grace
X-Forwarded-Proto
X-Correlation-Id
X-Forwarded-For
TP-Cache
TP-L2-Cache
Server-Name
Nginx-Cache
X-Pinterest-Direct
X-Amzn-Trace-Id
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Surrogate-Key
X-Request-Processing-Time
X-Request-Received
X-XRDS-LOCATION
X-Varnish-Age
X-Yandex-Sdch-Disable
X-Shield-Request-Id
X-Microsite
X-Request-Handler-Origin-Region
X-B3-Sampled
X-Ser
X-Activity-Id
X-Az
X-Hits
X-AppVersion
X-Fastcgi-Cache
X-Amz-Replication-Status
X-F-Cache
X-HS-Combine-CSS
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
X-DIS-Request-ID
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Metageneration
X-Goog-Generation
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
X-Origin-Server
Accept-Charset
X-Geo-Country
X-Git-Hash
Alternate-Protocol
X-XRDS-Location
X-Respond-Thread
X-Rid
Cache
X-Time
Section-Io-Cache
X-Frontend
X-LB-Cache
X-FTR-Request-ID
Host
X-Cache-Key
X-Upgrade-Enabled
X-DataDome
Access-Control-Allow-Method
X-Ruxit-Js-Agent
Powered-By-ChinaCache
X-Mobile-URL
MS-CV
X-Server-ID
X-NWS-LOG-UUID
Paypal-Debug-Id
X-Cache-Age
X-TT
Healthy
X-Seen-By
X-VCache
Cleartype
X-IPLB-Instance
X-AOL-HN
X-Content-Options
X-Varnish-Backend
ServerID
X-Whom
X-Hostname
X-Type
X-Providence-Cookie
X-Request-Guid
X-Is-Crawler
X-Flags
X-Aspnet-Duration-Ms
X-App-Environment
X-Route-Name
Payment
X-Cache-Action
X-Page-Id
X-Jobs
X-Signature
X-B-Cache
X-Source
X-Debug-Info
X-WebKit-CSP-Report-Only
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Load-Cache
X-TEC-API-ROOT
X-N
Fastcgi-Useragent
X-Daa-Tunnel
X-Mobile
X-FB-Debug
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Browser-Type
Nel
X-Via-JSL
X-RateLimit-Remaining
X-Contextid
Refresh
Realpath
Version
X-Response-Served-From
X-Original-Request-Id
X-Akamai-Edgescape
X-Rule
X-Accel-Buffering
X-Cached-By
Ms-Operation-Id
X-Cacheable-TTL
X-Framework
X-RTag
DC
X-Zen-Fury
Node
X-Proxy
X-Drupal-Cache-Tags
Viewport
X-Cache-Operation
X-RemovedCookies
X-Cache-Rule
X-ProcessESI
X-B
Access-Control-Request-Headers
X-Cache-Time
X-HTML-Minification-Powered-By
Referer-Policy
X-Real-IP
X-Instance
X-Wix-Request-Id
X-Distributor
X-UUID
Eomportal-Instance
X-Region
X-Page-View
X-Cluster-Name
X-Cache-Expired-At
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Drupal-Cache-Contexts
X-FW-Hash
X-FW-Serve
X-FW-Dynamic
VIX-Pulpo-Upstream-Status
Liferay-Portal
VIX-Pulpo-Node
X-FW-Server
X-FW-Static
X-Content-Powered-By
X-FW-Type
X-Cache-Control
X-Yottaa-Optimizations
Countrycode
X-Yottaa-Metrics
X-IPS-LoggedIn
X-G
X-Cache-Hit
X-L-Path
X-Environment-Context
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel-1
DynaTrace
X-Pass-Why
X-FireWall-Port
Server-Info
X-App-Server
X-Varnish-Ttl
X-User-Agent
X-Ratelimit-Limit
Ec-Rule-Version
Xserver
GEO-INFO
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Origin-Responded
Webserver
Section-Io-Id
X-Protected-By
X-Tumblr-Pixel-2
From-Origin
X-Node-Name
SRV
X-Ratelimit-Remaining
CF-IPCountry
X-Www-Served-By
Protected
X-Cache-Server
X-Nginx-Cache
X-Endurance-Cache-Level
X-UPSTREAM-Address
X-Mode
X-Hl-Ver
X-Handled-By
X-Backend-Name
Meta-Geo
X-ES-SERVER
X-RN-RSRV
X-Site-Version
Frame-Options
Cache-Tv-Group
X-Uri
X-Debug-IsPreview
X-Locale
X-Debug-IsConnected
X-Storage
X-UA-Device-Type
X-MP-GENERATED-AT
X-FB-TRIP-ID
X-Adobe-Loc
X-Varnishpool
X-PHP-Host
X-Soup
X-Adobe-Content
X-Labrador-Cache-Channel
X-Device-Type
X-BYPASS-REASON
X-Proxy-Build
X-ProxyCache-Status
Webcakes-App-Name
Property-Id
Selected-Fe
TWC-Connection-Speed
Country
Decoy-Debug-Key
Decoy-Debug-TTL
Decoy-Debug-Status
TWC-Device-Class
TWC-GeoIP-Country
Webcakes-App-Version
Webcakes-Region
X-Web-Node
TWC-Privacy
TWC-GeoIP-LatLong
TWC-Locale-Group
X-Be
X-Pubstack
X-Via-Fastly
X-Sql-Duration-Ms
Fastly-SSL
X-ProxyCache-Key
X-Sql-Count
X-Timing-Wait
X-No-Session
X-Request-Time
X-Origin-Date
X-Origin-Hint
Cache-Status
X-OCL
X-NYM-Debug-Backend
X-Proto
X-Hyper-Cache
X-Human
X-WA-Info
X-PCL
X-Redis-Cache
X-R9-Blue-Green-Version
X-LJ-Flow-ID
Azure-Version
X-Access
Azure-SlotName
X-LAGOON
Azure-RegionName
Retry-After
Azure-InstanceId
X-VWS-Id
X-Section
Azure-SiteName
X-Server-W
X-Format
X-S-Maxage
X-Revision
X-AWS-Id
Cache-Name
X-Hosted-By
X-FW-Version
X-Sorting-Hat-PodId
X-PERF
X-Status
X-Say-TTL
X-Sorting-Hat-ShopId
X-Loop
X-Cache-TTL-Remaining
X-Alternate-Cache-Key
X-TNCMS
X-ShardId
X-Shopify-Stage
X-ShopId
X-AIR-PT
X-CCM
X-TT-LOGID
X-Say-Cacheable
X-Storefront-Renderer-Rendered
X-SayCDN-TTL
X-Xfnlog-Site
X-Cluster
X-ApacheServer
X-Cache-Grace
Mn-Server-Ip
X-Forwarded-Host
X-Routing-Service
X-Zipkin-Id
X-Proxied
X-Is-Bot
X-Rendered-As
X-Varnish-Grace
AMP-Access-Control-Allow-Source-Origin
X-Qloud-Router
X-Amz-Meta-S3cmd-Attrs
Apigw-Requestid
X-Dc
S-Cnection
X-Info
X-Varnish-Server
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
X-Via-CDN
X-SRV
Cache-Hits
X-Cdn
X-FTR-Realm
X-FTR-Backend-Server
X-Cache-Enabled
X-FTR-Cache-Status
X-FTR-Backend
X-Country-Code-Real
X-FTR-Balancer
X-FTR-DC
X-GG-Cache-Date
X-Content-Age
X-FTR-Expires
X-Detected-As
X-Cache-Host
X-Microcachable
X-Platform
Uber-Trace-Id
X-Proxy-Cache-Status
X-Azure-Ref
X-Amzn-RequestId
X-Aspnetmvc-Version
X-Amzn-Remapped-Content-Length
X-EdgeConnect-Cache-Status
X-Amz-Apigw-Id
X-Backend-Host
X-CSRF-Token
X-NWS-UUID-VERIFY
Tracecode
X-App-Version
X-Cache-Var
SD-X-WS
X-Cache-Var-Map
X-Air-Hostname
X-Time-Microsecs
Amp-Access-Control-Allow-Source-Origin
Akamai-GRN
X-DynaTrace-JS-Agent
X-ATG-Version
X-ServerID
X-Backend-TTL
HostName
X-Oss-Object-Type
X-Oss-Request-Id
X-Trace-Id
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
X-Unique-Id
X-Oss-Storage-Class
X-BCube-Filmed-By
X-Debug-Cache
ServedBy
X-RCS-CacheZone
X-Correlation-ID
X-Varnish-Hostname
Backend
X-Cache-PHP
X-Cache-NGX
X-GEO
X-Cdn-Forward
X-Tb
X-Akamai-Transformed
X-Sucuri-ID
X-B3-SpanId
DSUID
X-Cache-Backend
X-Level-Front-Cache
X-Aed
X-CF-Lambda-Fn
X-A-Wwc
X-TX-ID
X-Generation-Time
BehaviorPad-Version
X-GeoIP-City
X-Cache-NE
X-Origin-CC
X-Connection-Hash
X-NAPM-TraceId
X-ARC
X-B-Cookie
X-Ms-Version
X-CF-Lambda-Version
DCR-Decision-By
X-Location
X-Matched-Rule
X-Application
Xc-Version
X-Ms-Request-Id
Expiry
X-Destination
SR-User-Adfree
Rendered-Blocks
X-A-Dcw
X-Device-Os
Release
T-Server
Thinkindot-CacheControl
X-D
X-A
Thinkindot-Control
X-A-Dam
Thinkindot-CacheControl-Type
Path
X-External-Request-Id
Instruction
X-Fetched-On
X-From
Fastcgi-X-Cache-Version
X-Generated-On
X-A-Ccd
Lfy
X-A-Dgt
Mobile-Detection-Method
Odigeo-Trace-Id
Meta-Geo-Continent
MD5-Digest
Machine
DCR-Processing-Time-Ms
DB-Nickname
X-Session-Fingerprint
X-ScT
X-VG-WebServer
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
X-PBS-Appsvrname
X-SRCache-Key
X-Vdms-Path
X-VG-WebCache
X-Processor
X-Rojux
X-Rewrite-Enabled
X-Request-UUID
X-Vdms-Version
X-S
X-TA-CDN-Provider
X-S-Cookie
X-PAYTM-SRV-ID
X-CS
X-Owner
X-Origin-TTL
X-Thinkindot-L3
X-Trv-Group
X-Magnolia-Registration
X-Bip
X-Azure-Ref-OriginShield
X-FC-Vary-Parameters
X-Tumblr-Pixel-3
Gh-Request-Id
X-Cache-Bucket
Cf-Device-Type
X-GeoIP
CacheControlHeader
Content-Disposition
X-Geo-Header
X-Cms-Context
X-Reqid
Fastly-Backend-Name
X-CACHE-KEY
Pagetype
C-Via
UCS
X-Skip-Cache
X-SVT-ORM-VERSION
Server-Host
X-Core-Value
X-Thanos
X-Fastly-Cache
X-SVT-ORM-RULES
X-TrackingId
NGX
On-Server
X-Adobe-Source
Host-ID
AKAMAI
X-OVcl
X-Micro-Cache
X-Irp-Debug
X-B3-Traceid
X-HS-Content-Campaign-Id
X-NewRelic-App-Data
X-OVcl-Cache
X-VServer
X-Mvc-Supplant-Cachable
X-Varnish-Cache-Hits
User-Cache-Control
X-Swa-Ws
Sever-Int
Ssr
X-Wikidot-Backend
X-Developer
X-Envoy-Decorator-Operation
PFcat
PB-RID
PB-PID
X-Dispatcher-Server
X-VarnishDD-TTL
X-WADP-Cache
Server-Ext
X-Cache-Id
X-Developers
Server-Hostname
Web-Mar-Node
X-Varnish-Beresp-Grace
X-CGP
X-Clara-WADP
X-Backend-State
X-Block-Status
X-Branch-Name
X-Cache-Info
X-Origin-Expires
X-Var-Ttl
X-User
X-Origin
X-Wikidot-Static-Cache
Wxu-Next-Commit
X-Eu-Site
X-Csrf-Jwt
V-Age
Wxu-Next-Hostname
Wxu-Next-Region
X-EC-Lua
X-Old-Content-Length
X-Node-Id
X-Nginx-Cache-Key
X-CUA
X-Esi-Check
X-HN
X-Request-Host
X-Has-Esi
X-Gzip
X-Generated-In
X-Generated-By
HA-Ipaddr
Ha-Gx-Prefs
X-Ratelimit-Reset
X-Hnp-Log
CloudFront-Viewer-Country
X-GoCache-CacheStatus
CDN-Cache
CDCHOST
Arc-Version
Cache-Host
CDN-CachedAt
CDN-EdgeStorageId
CDN-Uid
CDN-RequestId
CDN-RequestCountryCode
CDN-PullZone
X-Origin-Response-Time
X-Gen-Mode
X-Policy
X-Scheme
X-Fastly-Backend
Locid
X-Fmm-Version
X-JWT-State
Magicmarker
X-Is-Gdpr
Location
X-Li-Fabric
L5d-Success-Class
X-LI-UUID
X-IP
NM-Fastcgi-Cache
X-Li-Pop
X-ID
X-APP-VERSION
X-Varnish-Beresp-Status
X-Platform-Server
X-DPWN-IS-SECURE
X-Varnish-Remaining-TTL
X-Cache-Tags
X-LB-ID
X-Variation
X-VG-TLSProxy
X-Rebelmouse-Surrogate-Control
X-Gamma-Serve
X-Method
X-DefHash
X-Sn-Servicetimems
X-DefElseHash
X-Varnish-Hits
X-Slack-Backend
X-Rebelmouse-Cache-Control
X-Varnish-Beresp-Ttl
X-NU-AKA-ACS-Version
X-Request-URI
X-Hash
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-Clientip
X-Cdn-Origin
Platform
Pramga
X-Cache-Expires
True-Client-Country-4JS
Is-Eu
Fastly-SWR
X-Kinja-Server-Push
Adler-Geo
Cf-Bgj
Fastly-SIE
Vix-Hermes-Req-Id
L
X-Cache-Debug
X-CLOUD-TRACE-CONTEXT
X-SIPLIST1
Fastly-Drupal-HTML
X-Goog-Meta-Goog-Reserved-File-Mtime
Apple-News-Services-Parsed-Url
Origin
Apple-News-Services-Host
IsBot
Apple-News-Services-Handled
X-Cache-Date
Rt-Fastcgi-Cache
X-Aicache-OS
X-Loc
Apple-News-Services-Request-Url
X-PF-Uncompressing
X-Unique-ID
X-Mvc-Supplant-OutputCached
X-Core-Mission
X-Nc
X-Via-Poph
X-NCache
X-Via-Popv
X-Servername
X-Via-Popn
Esi-Enabled
Sid
X-Erf-Stays-Bingo-Pdp-Web
X-Request-Start
Who
X-Refresh
X-Varnish-Url
Country-Code
Geo-Info
Pics-Label
Url
X-Epic-Correlation-Id
X-FireWall-Protection
X-NC
X-Cache-Remote
X-Tb-Optimization-Total-Bytes-Saved
X-Response-By
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
Req-Svc-Chain
X-Planisys-CDN-Cache
X-Dynatrace
X-Varnish-Cacheable
X-Webkit-Csp
S-Rt
X-Proxy-Cachei7
X-Error
X-Srv
X-RateLimit-Limit
Xkeyi7
X-TraceId
Content-Secure-Policy
X-BBXSRF
Cmstype
N-Cache
Cmsid
Source
Filterid
X-Webkit-CSP-Report-Only
X-B3-Spanid
X-DC
X-Host-Name
Geoip-Latitude
GeoIp-Country-Code
Server-Ttl
X-Cache-2
X-Served-From
Svr
Kp-EeAlive
X-HS-Status
HitType
Cross-Origin-Window-Policy
X-Sucuri-Cache
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Cc-Via
X-LiteSpeed-Cache-Control
Tcn
X-Varnish-Authentication
D-Cc-Upstream
Cteonnt-Length
Ohc-File-Size
X-Vcl-Version
X-Cc-Req-Id
MIME-Version
VivaBuild
A
Viewtype
X-URL
X-HostName
Cache-Key
X-Svr
X-Wa
X-Servedbyhost
M-TraceId
X-Oracle-Dms-Rid
TDXMobile
NGB
X-Server-IP
Cross-Origin-Opener-Policy
Arc-Country
X-Esi
X-Li-Proto
Server-ID
X-CDN-Forward
SID
CACHE
NtCoent-Length
X-Vgn-Hpd-Reason
X-LI-Proto
X-Gdpr
X-API-Version
X-Cache-Config
X-RAMCache
X-FPC
X-Air-Source
X-Origin-Time
X-Nyt-Route
X-HOST
X-Cs
X-Vc
X-VC
Resin-Trace
X-Check-Cacheable
X-SN
Request-ID
X-UA
X-Geo
X-ServedByHost
X-CCDN-Origin-Time
X-RPS
X-SB
Server-Id
X-Viewer-Country
X-Webstats-RespID
X-Hcs-Proxy-Type
X-RSL
X-CCDN-CacheTTL
Cache-Provider
X-DW
X-NodeID
X-DI
X-DB
X-VCL-Version
X-Internal-Host
X-RPM
X-DSS
X-Service
X-WA
X-TIM-N
X-Newrelic-Synthetics
X-NGENIX-Cache
X-JoinUs
DataCenter
X-SaId
Ohc-Cache-HIT
X-PHP-Backend
Hostname
Mime-Version
GeoIP-Country-Code
Srv
X-SD-PageType
GeoIP-Latitude
X-Edge-Location
X-NGINX-Cache
XServer
X-Forwarded-Site
X-BBC-Edge-Cache-Status
ProcessTime
X-Via-NSCOPI
X-Extlb
X-Render-Time
X-Action
FSS-Cache
X-App
CF-Cached-On
X-FTR-Cache-Host
X-CF-Powered-By
X-Fpc
X-Oss-Cdn-Auth
EpKe-Alive
X-Provided-By
X-Bc-Bl
X-Dynatrace-Js-Agent
X-Ua
X-PJAX-URL
X-Worker
We-Hiring
X-Req
Surrogated-Key
W
X-Region-Sid
X-Proxy-Upstream
Upgrade-Insecure-Requests
X-Depends-On
X-Date
Memcached
LB
Processtime
X-Accel-Expires-Debug
X-FORWARDED-FOR
Mail-Subject
X-Auto-Login
X-Cdn-Request-ID
X-HITS
X-Swift-Error
X-UnsetCookies
X-Cluster-Node
X-CSRF-TOKEN
X-Dw-Trace-Id
Proxy-Connection
X-MSEdge-Flight
X-BACKEND-TTL
X-Ftr-Cache-Host
X-MSEdge-Features
X-RateLimit-Limit-Second
Cdn
Env
X-VC-Cache
X-ZONE
X-APP
X-RateLimit-Remaining-Second
CDN
X-Fastly-Backend-Reqs
X-TIME
X-CACHE-AGE
X-Client-Ip
Datacenter
X-Fastly-Request-Id
X-Hello
X-Men
PICS-Label
Memory
X-Parent-Response-Time
Time
X-Sigma
X-Rocket-Build-Number
X-BBC-Origin-Response-Status
Dnion-Transfer-Encoding
X-Sigma-Backend
X-ABtesting
X-IN-APIGATEWAY
X-Cache-Tag
X-IN-APIGATEWAYSSL
X-Flog
X-Akamai-Pragma-Client-IP
Cf-Ipcountry
Media-Length
X-Acquia-Application-Trace
X-Zone
X-Pad
X-Presslabs-Stats
X-Air-Trace-Id
X-Acquia-Application-UUID
X-Pf-Uncompressing
X-Oracle-DMS-ECID
X-Acquia-Purge-Tags
Vha6-Origin
X-Acquia-Site
OT-Force-Account-Verify
CPC-Age
Epwk-X-Cache
X-Via-PopN
VNS-Age
X-LiteSpeed-Tag
VNS-Cache
X-Via-PopH
CPC-Cache
X-Via-PopV
X-Varnish-URL
X-Akamai-ERPolicy
X-ServerName
X-ElasticPress-Query
X-Varnish-Beresp-TTL
X-MiniProfiler-Ids
X-Request-Url
X-Vcache
WZWS-RAY
X-ND-Cache
X-Csrf-Token
X-Akamai-ERRuleID
X-Snapshot-Date
X-Request-URL
X-Ms-Meta-Staticbatchstarttime
X-ElasticPress-Search
X-Ms-Meta-Originalurl
X-Lb-Id
Xet-Cookie
CountryCode
X-Amz-Meta-Cb-Modifiedtime
X-Litespeed-Cache-Control
My-App
State
Fastcgi-Cache-TTL
Content-Style-Type
Content-Script-Type
Phost
X-Tid
NnCoection
Environment
X-Redis-Count
X-Redis-Duration-Ms
X-Traceid
X-B3-Parentspanid
Ohc-Response-Time
X-Debug-Cache-Fetch
X-C
X-Debug-Cache-Store
X-Storefront-Renderer-Verified
Inserted-Into-Cache-At
URI