Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
X-XSS-Protection
Cf-Request-Id
CF-Cache-Status
Last-Modified
CF-RAY
Accept-Ranges
Link
Pragma
Expect-CT
ETag
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Cache-Status
X-Generator
X-Request-ID
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Content-Security-Policy
Content-Encoding
X-CDN
X-Ua-Compatible
X-Envoy-Upstream-Service-Time
Status
Feature-Policy
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-AspNetMvc-Version
CF-Ray
X-Xss-Protection
Access-Control-Max-Age
X-Via
Upgrade
Keep-Alive
X-Ws-Request-Id
X-Turbo-Charged-By
X-Age
X-AH-Environment
X-Robots-Tag
Request-Context
X-Proxy-Cache
EagleId
X-Cache-Group
Server-Timing
X-Backend
X-Hacker
X-Amz-Request-Id
Report-To
X-Server
Host-Header
X-Amz-Id-2
X-Server-Powered-By
Grace
X-UA-Device
X-Nginx-Cache-Status
X-Dns-Prefetch-Control
X-LiteSpeed-Cache
X-Varnish-Cache
X-Rq
Ali-Swift-Global-Savetime
X-Swift-CacheTime
X-Swift-SaveTime
X-Page-Speed
Cf-Railgun
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
NEL
X-Amz-Version-Id
X-OneAgent-JS-Injection
Xkey
X-Cache-Spec
X-WebKit-CSP
Allow
X-Backend-Server
X-Host
X-Vhost
X-CST
X-Device
EagleEye-TraceId
X-Server-Id
Surrogate-Control
Request-Id
X-Dispatcher
X-Node
Content-Location
X-Response-Time
X-Akam-SW-Version
Accept-CH
X-Ruxit-JS-Agent
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Accept-CH-Lifetime
X-ASPNET-VERSION
X-Kinja-Server-Push
X-Template
X-Language
X-Ac
X-Application-Context
X-Country
X-Readtime
X-Cache-Lookup
X-Mod-Pagespeed
X-Cloud-Trace-Context
MS-Author-Via
X-B3-TraceId
X-Origin-Cache
Accept-Ch
Rating
X-Cnection
X-MS-InvokeApp
X-Url
Accept-Ch-Lifetime
X-HW
X-ORACLE-DMS-ECID
X-PC
X-Vname
X-TtlSet
X-Clacks-Overhead
X-ESI
Edge-Control
X-GitHub-Request-Id
X-Trace
Pagespeed
Response
X-Middleton-Display
X-Sol
Display
X-Middleton-Response
X-Content-Type
X-FastCGI-Cache
X-D2id
X-Vcap-Request-Id
Verso
X-Exp-Variant
X-Exp-Id
Arr-Disable-Session-Affinity
X-GoogleNews-Bot
X-Cdn-Fetch
X-Kinja-Build
X-Use-Magma
X-Kinja
X-Kinja-Server
X-Kinja-Revision
X-Buckets
X-Goog-Hash
X-Rack-Cache
X-Server-Name
X-Varnish-TTL
X-Country-Code
Service-Worker-Allowed
X-Oneagent-Js-Injection
X-Navigation-Version
X-VARITI-CCR
X-Abt-Application-Version
X-Amz-Rid
Pinterest-Generated-By
X-ORACLE-DMS-RID
X-Pinterest-Rid
Pinterest-Version
X-Client-IP
X-Powered-By-Plesk
X-Cache-TTL
SPRequestGuid
X-SharePointHealthScore
X-Release
SPRequestDuration
SPIisLatency
X-Fastly-Request-ID
X-MSEdge-Ref
X-TTL
X-Dw-Request-Base-Id
X-Element-Page-Cache
Fastly-Restarts
X-NF-Request-ID
X-Cached
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
Public-Key-Pins
X-Webkit-CSP
RTSS
X-Origin-Upstream-Status
X-Edge
Ar-Sid
AR-Request-ID
AR-PoweredBy
AR-CACHE
AR-ATIME
X-Px
X-SRCache-Store-Status
X-SRCache-Fetch-Status
Access-Control-Request-Method
X-LLID
Fusion-Deployment-Id
Fusion-Content-Source
Fusion-Source
X-Powered-CMS
Fusion-Content-Id
Fusion-Template-Id
Fusion-Component-Id
X-Ezoic-Cdn
X-Upstream
Content-MD5
X-Jurisdiction
X-HP-Webp
X-Pinterest-Direct
X-Ttl
X-ECACHE
X-Mid
X-MCACHE
X-Amz-Server-Side-Encryption
Charset
X-Recruiting
X-Content-Digest
X-Aspnetmvc-Version
X-Mg-S
Cache-Tag
S
X-PressLabs-Stats
X-Version
MicrosoftSharePointTeamServices
Fastcgi-Cache
X-Debug
Front-End-Https
TCN
X-Content-Security-Policy-Report-Only
X-T
X-Grace
X-Id
Filters
X-Kinsta-Cache
Cache-Tags
Edge-Cache-Tag
Server-Node
X-Forwarded-Proto
X-XRDS-Location
X-Yandex-Sdch-Disable
X-Accel-Expires
X-Logged-In
X-Amzn-Trace-Id
X-Correlation-Id
X-Forwarded-For
Server-Name
Nginx-Cache
Surrogate-Key
X-Varnish-Age
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Cache-Key
Powered-By-ChinaCache
X-B3-Sampled
TP-L2-Cache
TP-Cache
X-Request-Handler-Origin-Region
X-Server-ID
X-Request-Received
X-Ser
X-Request-Processing-Time
X-Microsite
X-Hits
X-DynaTrace
X-DIS-Request-ID
X-Shield-Request-Id
X-Activity-Id
X-Az
X-AppVersion
X-Amz-Replication-Status
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Cache-Config
X-F-Cache
X-HS-Hub-Id
X-Litespeed-Cache
Accept-Charset
X-FTR-Request-ID
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Git-Hash
X-Goog-Metageneration
X-GUploader-UploadID
X-Origin-Server
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Respond-Thread
X-Geo-Country
X-DataDome
X-LB-Cache
X-Upgrade-Enabled
X-Hostname
Section-Io-Cache
X-Rid
X-Frontend
Access-Control-Allow-Method
X-Ruxit-Js-Agent
Cache
X-Cache-Age
X-Mobile-URL
Alternate-Protocol
Host
Cleartype
Healthy
X-XRDS-LOCATION
Paypal-Debug-Id
X-Type
MS-CV
X-IPLB-Instance
X-Content-Options
ServerID
X-AOL-HN
Payment
X-Varnish-Backend
X-Whom
X-WebKit-CSP-Report-Only
X-App-Environment
X-Providence-Cookie
X-Request-Guid
X-Route-Name
X-TT
X-Flags
X-B-Cache
X-Aspnet-Duration-Ms
X-VCache
X-Seen-By
X-Is-Crawler
X-Signature
X-Debug-Info
X-Cache-Action
X-Page-Id
Fastcgi-Useragent
X-Jobs
X-TEC-API-ORIGIN
X-Fastcgi-Cache
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Source
X-NWS-LOG-UUID
X-Mobile
X-N
X-Erf-Bev-Bev-Is-Generated
X-Time
X-Erf-Bev-Bev
X-Browser-Type
X-Load-Cache
X-Cached-By
Nel
X-Via-JSL
X-RateLimit-Remaining
X-Akamai-Edgescape
X-FB-Debug
Version
X-Daa-Tunnel
X-Cache-Rule
X-Cache-Operation
Viewport
DynaTrace
X-Original-Request-Id
X-Rule
X-Response-Served-From
Refresh
X-Accel-Buffering
X-Drupal-Cache-Tags
X-Proxy
X-Zen-Fury
DC
X-Framework
X-Instance
X-ProcessESI
X-Cacheable-TTL
X-RTag
X-RemovedCookies
Ms-Operation-Id
X-Tt-Trace-Tag
Realpath
Access-Control-Request-Headers
X-Real-IP
X-Region
X-Tt-Trace-Host
Referer-Policy
X-UUID
X-HTML-Minification-Powered-By
X-Cache-Time
X-Contextid
X-FW-Hash
X-FW-Serve
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-FW-Dynamic
X-Distributor
X-Drupal-Cache-Contexts
X-Wix-Request-Id
X-FW-Server
X-Page-View
X-FW-Type
X-FW-Static
X-Cache-Expired-At
Eomportal-Instance
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
Countrycode
X-L-Path
Node
X-B
X-Environment-Context
X-Node-Name
X-Cluster-Name
GEO-INFO
Liferay-Portal
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Cache-Control
X-Tumblr-User
X-G
X-Tumblr-Pixel-1
X-IPS-LoggedIn
X-Content-Powered-By
X-Cache-Hit
X-User-Agent
X-Tumblr-Pixel-2
X-Amz-Meta-S3cmd-Attrs
Server-Info
Webserver
X-Ratelimit-Limit
SRV
Section-Origin-Responded
Section-Io-Id
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
From-Origin
X-Pass-Why
X-App-Server
Protected
X-Oracle-Dms-Rid
Ec-Rule-Version
X-Protected-By
X-Revision
X-FireWall-Port
X-Backend-Name
X-Cache-Server
Cache-Status
Frame-Options
X-Endurance-Cache-Level
X-ES-SERVER
CF-IPCountry
X-UPSTREAM-Address
X-Hl-Ver
X-Mode
Meta-Geo
X-Handled-By
X-Hyper-Cache
X-RN-RSRV
X-Locale
X-Storage
X-Forwarded-Host
X-Www-Served-By
Retry-After
X-FB-TRIP-ID
X-NYM-Debug-Backend
X-Varnish-Ttl
X-Site-Version
Cache-Tv-Group
TWC-Connection-Speed
X-Soup
Property-Id
Fastly-SSL
Decoy-Debug-TTL
TWC-Device-Class
TWC-GeoIP-Country
X-Section
TWC-GeoIP-LatLong
X-Origin-Hint
X-Pubstack
Decoy-Debug-Status
X-Varnishpool
X-Be
X-Cache-Grace
X-Access
Webcakes-Region
Decoy-Debug-Key
X-Format
Webcakes-App-Version
TWC-Locale-Group
X-Web-Node
TWC-Privacy
X-Human
Country
Webcakes-App-Name
X-Adobe-Loc
X-Adobe-Content
X-ProxyCache-Status
X-Redis-Cache
X-ProxyCache-Key
X-Proto
X-Say-Cacheable
X-Proxy-Build
Selected-Fe
X-UA-Device-Type
X-TT-LOGID
X-Timing-Wait
X-PHP-Host
X-Say-TTL
X-PERF
Cache-Name
X-OCL
X-Labrador-Cache-Channel
X-FW-Version
X-ApacheServer
X-BYPASS-REASON
Azure-Version
Azure-SlotName
X-Origin-Date
X-PCL
Azure-InstanceId
Azure-RegionName
Azure-SiteName
X-Uri
X-SayCDN-TTL
X-Server-W
X-WA-Info
X-S-Maxage
X-Via-Fastly
X-Sql-Count
X-AIR-PT
X-Sql-Duration-Ms
X-LAGOON
X-No-Session
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Balancer
X-Country-Code-Real
X-FTR-Cache-Status
X-Request-Time
X-FTR-Realm
X-LJ-Flow-ID
X-FTR-DC
X-Via-CDN
Xserver
X-Ratelimit-Remaining
X-AWS-Id
X-Status
X-VWS-Id
S-Cnection
X-R9-Blue-Green-Version
X-Qloud-Router
X-TNCMS
Mn-Server-Ip
X-Hosted-By
X-Loop
X-MP-GENERATED-AT
X-Cluster
X-Cache-TTL-Remaining
X-CCM
X-Sorting-Hat-PodId
X-Alternate-Cache-Key
X-Routing-Service
X-Zipkin-Id
X-Xfnlog-Site
X-Proxied
X-ShardId
X-Storefront-Renderer-Rendered
X-Sorting-Hat-ShopId
X-Shopify-Stage
X-Dynatrace
X-ShopId
X-FTR-Expires
X-Tec-Api-Root
X-Tec-Api-Version
X-Tec-Api-Origin
X-Rendered-As
X-Cache-Var-Map
X-Cache-Var
Cache-Hits
AMP-Access-Control-Allow-Source-Origin
X-Is-Bot
X-Dc
X-Webkit-Csp
X-Air-Hostname
X-Device-Type
X-Cdn
X-Detected-As
X-Info
X-Cache-Host
X-EdgeConnect-Cache-Status
X-SRV
X-Amz-Apigw-Id
Apigw-Requestid
X-Amzn-RequestId
X-Amzn-Remapped-Content-Length
X-Nginx-Cache
X-Microcachable
X-Unique-Id
X-Debug-IsConnected
X-Cache-Enabled
SD-X-WS
X-Debug-IsPreview
X-Content-Age
X-Varnish-Server
X-Cache-Backend
X-Platform
X-Time-Microsecs
Tracecode
X-Varnish-Grace
X-Backend-TTL
X-ServerID
X-DynaTrace-JS-Agent
X-Azure-Ref
X-GEO
Amp-Access-Control-Allow-Source-Origin
X-Erf-Stays-Bingo-Pdp-Web
X-Backend-Host
X-GG-Cache-Date
X-APP-VERSION
Uber-Trace-Id
DSUID
X-Oss-Object-Type
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-Oss-Storage-Class
X-Oss-Server-Time
X-Tb
Akamai-GRN
X-NewRelic-App-Data
X-Proxy-Cache-Status
X-Correlation-ID
X-BCube-Filmed-By
PB-PID
PB-RID
X-Sucuri-ID
Backend
X-ATG-Version
Arc-Version
X-CSRF-Token
X-Akamai-Transformed
X-Magnolia-Registration
X-Trace-Id
X-Level-Front-Cache
X-Origin-CC
X-Location
X-Varnish-Cache-Hits
ServedBy
X-External-Request-Id
Thinkindot-Control
X-Connection-Hash
X-A
X-A-Ccd
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
Rendered-Blocks
X-D
SR-User-Adfree
T-Server
X-A-Dam
X-A-Dcw
X-Application
X-ARC
X-B-Cookie
X-Cache-NE
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-A-Dgt
X-A-Wwc
X-Aed
Release
Pramga
DCR-Decision-By
DCR-Processing-Time-Ms
X-Fetched-On
Expiry
X-From
X-Generated-On
BehaviorPad-Version
X-GeoIP-City
X-Generation-Time
Fastcgi-X-Cache-Version
X-Origin-TTL
Mobile-Detection-Method
X-Device-Os
Odigeo-Trace-Id
X-Destination
Meta-Geo-Continent
MD5-Digest
Instruction
Lfy
Machine
X-RCS-CacheZone
X-Matched-Rule
X-VG-WebServer
X-VG-WebCache
X-Thinkindot-L3
X-S-Cookie
X-Vtex-Processado-Em
X-PBS-Appsvrname
X-Vtex-Remote-Cache
X-S
X-Processor
X-Origin-Response-Time
X-Vdms-Path
X-Vdms-Version
X-Request-UUID
X-Rewrite-Enabled
X-Trv-Group
X-PAYTM-SRV-ID
X-Rojux
Xc-Version
X-Session-Fingerprint
X-SRCache-Key
X-ScT
X-Cache-PHP
X-Cache-NGX
X-Varnish-Hostname
X-Generated-In
Locid
X-Bip
X-User
Pagetype
X-Request-URI
X-Developers
L5d-Success-Class
Magicmarker
L
X-OVcl
X-FC-Vary-Parameters
X-Reqid
Cf-Device-Type
X-Eu-Site
Gh-Request-Id
Host-ID
X-Cache-Info
HA-Ipaddr
Ha-Gx-Prefs
X-Cache-Date
X-Tumblr-Pixel-3
X-Skip-Cache
X-Cdn-Origin
X-Sn-Servicetimems
UCS
Wxu-Next-Commit
X-CGP
X-Swa-Ws
Wxu-Next-Region
Wxu-Next-Hostname
X-Thanos
X-Azure-Ref-OriginShield
X-SVT-ORM-VERSION
X-Adobe-Source
PFcat
X-Backend-State
X-Csrf-Jwt
X-VarnishDD-TTL
X-SVT-ORM-RULES
Ssr
Path
Fastly-Backend-Name
Cache-Host
X-JWT-State
X-Ms-Version
X-Ms-Request-Id
CacheControlHeader
X-Is-Gdpr
C-Via
X-HN
X-Has-Esi
X-HS-Content-Campaign-Id
X-B3-Traceid
X-Irp-Debug
AKAMAI
X-VServer
X-Owner
X-Wikidot-Static-Cache
X-OVcl-Cache
X-GeoIP
X-Geo-Header
X-Node-Id
X-Mvc-Supplant-Cachable
X-Cache-Remote
X-Wikidot-Backend
X-Micro-Cache
X-Cache-Bucket
X-NWS-UUID-VERIFY
X-Debug-Cache
DB-Nickname
X-Core-Value
X-Request-Host
X-Cms-Context
V-Age
X-Clientip
X-Envoy-Decorator-Operation
X-Fastly-Cache
Server-Host
Server-Ext
Server-Hostname
X-CUA
Sever-Int
X-Method
X-Varnish-Hits
Cf-Bgj
X-Cache-Tags
X-Origin-Expires
X-Generated-By
X-TrackingId
CloudFront-Viewer-Country
X-Nginx-Cache-Key
CDCHOST
X-Scheme
Content-Disposition
User-Cache-Control
X-Fastly-Backend
X-Policy
Apple-News-Services-Request-Url
On-Server
X-IP
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
X-Request-Start
NGX
X-Var-Ttl
X-Developer
Apple-News-Services-Handled
X-NC
X-ID
X-Gen-Mode
X-Cache-Debug
X-DPWN-IS-SECURE
X-Hnp-Log
X-Cache-Expires
X-SIPLIST1
X-Cache-Id
X-Old-Content-Length
X-Variation
X-Origin
X-Servername
X-Gzip
Location
X-GoCache-CacheStatus
X-NU-AKA-ACS-Version
X-TX-ID
X-Li-Pop
X-VG-TLSProxy
X-LI-UUID
X-Esi-Check
X-Li-Fabric
X-Varnish-Beresp-Grace
X-DefElseHash
X-Rebelmouse-Surrogate-Control
X-DefHash
X-Varnish-CookieHashed-On
X-Loc
X-Dispatcher-Server
X-Fmm-Version
X-WADP-Cache
X-Ratelimit-Reset
X-Varnish-CookieINHashed-On
X-Platform-Server
X-Rebelmouse-Cache-Control
X-Clara-WADP
X-Varnish-Remaining-TTL
Vix-Hermes-Req-Id
NM-Fastcgi-Cache
Origin
Rt-Fastcgi-Cache
True-Client-Country-4JS
IsBot
Is-Eu
Fastly-SIE
Fastly-SWR
Adler-Geo
Web-Mar-Node
Platform
X-Block-Status
X-Branch-Name
HostName
X-App-Version
CACHE
CDN-Cache
X-Varnish-Beresp-Status
X-Host-Name
X-Goog-Meta-Goog-Reserved-File-Mtime
X-NAPM-TraceId
Fastly-Drupal-HTML
X-Slack-Backend
X-Varnish-Beresp-Ttl
X-NCache
CDN-RequestCountryCode
X-Hash
CDN-PullZone
CDN-EdgeStorageId
CDN-RequestId
CDN-CachedAt
CDN-Uid
X-Varnish-Url
X-Gamma-Serve
X-CS
X-Response-By
X-PF-Uncompressing
X-B3-Spanid
X-Cdn-Forward
X-Varnish-Cacheable
X-EC-Lua
X-Core-Mission
Url
S-Rt
X-B3-SpanId
Xkeyi7
X-Aicache-OS
X-Mvc-Supplant-OutputCached
X-TA-CDN-Provider
Pics-Label
X-Refresh
X-Proxy-Cachei7
X-CACHE-GROUP
N-Cache
X-BBXSRF
Sid
X-LB-ID
Cross-Origin-Window-Policy
Content-Secure-Policy
X-FireWall-Protection
X-Sucuri-Cache
Ohc-File-Size
X-Cache-2
X-Via-Popn
X-Via-Poph
X-Via-Popv
X-Cache-ASPX
X-CDN-Forward
X-Varnish-Authentication
D-Cc-Upstream
X-Cc-Via
X-Cc-Req-Id
Cteonnt-Length
X-Contensis-Viewer-Groups
X-Unique-ID
Esi-Enabled
X-Svr
X-Error
X-Epic-Correlation-Id
X-Tb-Optimization-Total-Bytes-Saved
X-Srv
X-Servedbyhost
X-Server-IP
MIME-Version
X-Wa
Source
X-Webkit-CSP-Report-Only
X-TraceId
X-Cs
X-FPC
Who
Geo-Info
X-Cache-Config
X-API-Version
X-DC
X-Nc
X-CLOUD-TRACE-CONTEXT
Geoip-Latitude
GeoIp-Country-Code
HitType
X-Nyt-Route
X-Gdpr
X-Origin-Time
X-RateLimit-Limit
Country-Code
X-Planisys-CDN-TTL
X-SN
X-Planisys-CDN-Rules
Req-Svc-Chain
X-Planisys-CDN-Cache
Server-Ttl
X-HS-Status
X-VC
Hostname
Ohc-Cache-HIT
X-NGINX-Cache
X-URL
X-TIME
X-Fastly-Request-Id
X-LI-Proto
XServer
X-Webstats-RespID
X-SB
X-LiteSpeed-Cache-Control
X-NodeID
X-CACHE-KEY
X-SD-PageType
X-VCL-Version
Cmstype
Server-ID
Cmsid
X-Check-Cacheable
Svr
X-Esi
Kp-EeAlive
VivaBuild
Viewtype
X-Served-From
X-Ua
X-Render-Time
X-HOST
NtCoent-Length
EpKe-Alive
SID
A
X-Viewer-Country
X-Vcl-Version
Request-ID
X-Vgn-Hpd-Reason
Tcn
Cache-Key
X-BBC-Edge-Cache-Status
X-UA
X-CCDN-Origin-Time
X-Worker
X-RSL
X-Hcs-Proxy-Type
X-TIM-N
X-RPS
X-DI
X-DSS
X-DB
Cache-Provider
X-RAMCache
X-DW
X-Li-Proto
X-CCDN-CacheTTL
X-RPM
Resin-Trace
M-TraceId
Server-Id
X-Auto-Login
X-Ftr-Cache-Host
Cross-Origin-Opener-Policy
TDXMobile
Arc-Country
ProcessTime
X-CF-Powered-By
X-Air-Source
GeoIP-Latitude
GeoIP-Country-Code
X-CSRF-TOKEN
X-Dynatrace-Js-Agent
X-Cluster-Node
X-Action
Processtime
X-Internal-Host
X-HostName
X-App
CDN
X-FTR-Cache-Host
X-Geo
X-Newrelic-Synthetics
X-Fpc
X-ServedByHost
X-WA
Filterid
Upgrade-Insecure-Requests
X-Oss-Cdn-Auth
X-Vc
Mime-Version
CF-Cached-On
X-BBC-Origin-Response-Status
X-FORWARDED-FOR
Datacenter
Proxy-Connection
Srv
X-Service
OT-Force-Account-Verify
X-HITS
WZWS-RAY
X-Dw-Trace-Id
X-MSEdge-Features
X-MSEdge-Flight
X-Fastly-Backend-Reqs
X-ND-Cache
X-BACKEND-TTL
NGB
X-Via-PopH
X-Via-PopN
Cdn
X-Via-PopV
DataCenter
X-Client-Ip
X-CACHE-AGE
X-Lb-Id
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-Via-NSCOPI
X-Parent-Response-Time
X-ABtesting
X-Flog
W
X-Forwarded-Site
X-Cache-Tag
FSS-Cache
X-Hello
Dnion-Transfer-Encoding
X-SaId
X-Cdn-Request-ID
X-NGENIX-Cache
X-Edge-Location
X-JoinUs
X-PHP-Backend
Media-Length
PICS-Label
X-Extlb
X-Pf-Uncompressing
Vha6-Origin
X-Presslabs-Stats
X-Akamai-Pragma-Client-IP
X-Oracle-DMS-ECID
X-Date
X-MiniProfiler-Ids
X-Depends-On
We-Hiring
X-RateLimit-Limit-Second
X-Pad
X-RateLimit-Remaining-Second
Surrogated-Key
X-LiteSpeed-Tag
X-Proxy-Upstream
X-PJAX-URL
X-VC-Cache
LB
X-Provided-By
X-ZONE
X-Region-Sid
X-Bc-Bl
X-Req
X-UnsetCookies
Mail-Subject
Memcached
URI
Epwk-X-Cache
X-Accel-Expires-Debug
Cf-Ipcountry
X-Csrf-Token
X-APP
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Ms-Meta-Staticbatchstarttime
X-Acquia-Site
X-ElasticPress-Query
Env
X-Acquia-Application-Trace
Time
X-Swift-Error
X-Akamai-ERPolicy
X-Vcache
X-Akamai-ERRuleID
X-Varnish-Beresp-TTL
X-Request-URL
X-B3-Parentspanid
Xet-Cookie
Memory
X-ElasticPress-Search
X-Request-Url
X-Akamai-Request-ID
X-Ms-Meta-Originalurl
CountryCode
X-Zone
X-Varnish-URL
Inserted-Into-Cache-At
X-Air-Trace-Id
X-Men
X-Sigma
X-Rocket-Build-Number
X-Sigma-Backend
X-Tid
X-Acc-Debug-Context
X-Via-SSL
X-Litespeed-Cache-Control
X-C
X-ServerName
X-Via-Edge
X-Acc-Rdl
Content-Script-Type
Content-Style-Type
Edge-Copy-Time
X-Storefront-Renderer-Verified
Environment
Phost
Ohc-Response-Time
X-Debug-Cache-Fetch
NnCoection
X-Traceid
X-Redis-Count
X-Redis-Duration-Ms
X-Snapshot-Date
X-Debug-Cache-Store