Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-RAY
CF-Cache-Status
X-XSS-Protection
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
P3P
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-UA-Compatible
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
X-Request-Id
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Xss-Protection
X-Cache-Status
X-Generator
X-Cacheable
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Request-ID
X-Content-Security-Policy
X-Iinfo
X-Ua-Compatible
Content-Encoding
X-CDN
X-AspNetMvc-Version
Feature-Policy
Status
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Upgrade
X-Via
Access-Control-Max-Age
Keep-Alive
X-Ws-Request-Id
X-Age
X-Robots-Tag
X-AH-Environment
X-Turbo-Charged-By
Request-Context
EagleId
X-Cache-Group
X-Proxy-Cache
Server-Timing
X-Backend
X-Server
X-Hacker
Host-Header
Report-To
X-Server-Powered-By
X-Dns-Prefetch-Control
X-Amz-Request-Id
X-Nginx-Cache-Status
X-Amz-Id-2
Grace
X-UA-Device
X-Rq
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
P3p
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Page-Speed
Cf-Railgun
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-OneAgent-JS-Injection
X-Amz-Version-Id
X-Device
NEL
X-Cache-Spec
X-CST
X-WebKit-CSP
Allow
X-Vhost
X-Host
X-Backend-Server
X-Server-Id
Xkey
EagleEye-TraceId
X-Dispatcher
Surrogate-Control
X-Node
Request-Id
X-Response-Time
Content-Location
X-Akam-SW-Version
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Ruxit-JS-Agent
X-ASPNET-VERSION
X-Application-Context
X-Cache-Lookup
X-Ac
X-Country
Accept-CH
Accept-Ch
Accept-Ch-Lifetime
X-Mod-Pagespeed
X-Template
X-Language
X-Readtime
X-Cloud-Trace-Context
X-B3-TraceId
MS-Author-Via
Accept-CH-Lifetime
Rating
X-HW
X-Url
X-Cnection
X-Origin-Cache
X-MS-InvokeApp
X-PC
X-TtlSet
X-Vname
Edge-Control
X-Clacks-Overhead
X-ESI
X-GitHub-Request-Id
X-Trace
X-ORACLE-DMS-RID
X-Varnish-TTL
X-Middleton-Display
Response
Display
Pagespeed
X-Sol
X-Middleton-Response
X-Content-Type
X-D2id
X-ORACLE-DMS-ECID
Verso
Arr-Disable-Session-Affinity
X-Kinja-Revision
X-Kinja-Build
X-Kinja
X-Exp-Variant
X-Exp-Id
X-GoogleNews-Bot
X-Cdn-Fetch
X-Use-Magma
X-Kinja-Server
X-Vcap-Request-Id
X-Country-Code
X-Goog-Hash
X-Rack-Cache
X-Powered-By-Plesk
X-Navigation-Version
X-VARITI-CCR
X-TTL
X-Server-Name
Service-Worker-Allowed
X-Amz-Rid
X-Fastly-Request-ID
X-Abt-Application-Version
X-Oneagent-Js-Injection
X-Buckets
X-Client-IP
Fastly-Restarts
X-Cached
X-Cache-TTL
X-MSEdge-Ref
X-Release
X-Element-Page-Cache
X-Dw-Request-Base-Id
X-FastCGI-Cache
SPRequestGuid
X-SharePointHealthScore
X-NF-Request-ID
MRF-Tech
Pinterest-Generated-By
SPIisLatency
Pinterest-Version
SPRequestDuration
X-Pinterest-Rid
Mrf-Cache-Status
X-B3-TraceId-Primal
Public-Key-Pins
Access-Control-Request-Method
RTSS
X-Webkit-CSP
Cache-Tag
AR-CACHE
AR-Request-ID
Ar-Sid
AR-PoweredBy
AR-ATIME
X-Edge
X-LLID
X-Powered-CMS
X-Ezoic-Cdn
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Upstream
Content-MD5
X-Version
X-Jurisdiction
X-HP-Webp
X-Origin-Upstream-Status
S
X-Recruiting
X-Mid
X-MCACHE
X-ECACHE
Charset
Fusion-Template-Id
X-Mg-S
Fusion-Content-Id
Fusion-Component-Id
Fusion-Content-Source
Fusion-Deployment-Id
Fusion-Source
X-DynaTrace
X-PressLabs-Stats
X-Content-Digest
X-Px
X-Kinsta-Cache
X-Fastcgi-Cache
X-Ruxit-Js-Agent
X-T
Cache-Tags
Fastcgi-Cache
X-Ttl
X-Id
X-Amz-Server-Side-Encryption
X-Accel-Expires
X-Logged-In
Filters
X-Forwarded-Proto
X-Litespeed-Cache
X-Content-Security-Policy-Report-Only
Server-Node
Edge-Cache-Tag
MicrosoftSharePointTeamServices
TP-Cache
TP-L2-Cache
Front-End-Https
Server-Name
X-Forwarded-For
TCN
X-Grace
Nginx-Cache
X-Kong-Upstream-Latency
X-XRDS-LOCATION
X-Kong-Proxy-Latency
X-Correlation-Id
X-Request-Processing-Time
X-Hits
X-Request-Received
X-Amzn-Trace-Id
X-Debug
X-B3-Sampled
X-Shield-Request-Id
X-Request-Handler-Origin-Region
X-Microsite
X-Varnish-Age
X-Az
X-Activity-Id
X-AppVersion
X-Yandex-Sdch-Disable
Surrogate-Key
X-Amz-Replication-Status
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Cache-Config
X-F-Cache
Alternate-Protocol
X-Ser
X-Origin-Server
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Storage-Class
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-DIS-Request-ID
Accept-Charset
X-Frontend
X-Geo-Country
X-Rid
Nel
Section-Io-Cache
X-Git-Hash
Host
X-NWS-LOG-UUID
X-Respond-Thread
X-XRDS-Location
X-Cache-Age
X-Upgrade-Enabled
X-Hostname
Access-Control-Allow-Method
X-LB-Cache
X-Time
X-DataDome
X-Mobile-URL
X-VCache
X-Pinterest-Direct
MS-CV
X-Seen-By
X-RateLimit-Remaining
X-Type
ServerID
Paypal-Debug-Id
X-IPLB-Instance
X-Cache-Key
Cache
Healthy
X-Varnish-Backend
Payment
X-Content-Options
X-Source
X-AOL-HN
X-Daa-Tunnel
X-App-Environment
X-Request-Guid
X-Route-Name
X-TT
X-Whom
Cleartype
X-Providence-Cookie
X-Flags
X-Is-Crawler
X-Aspnet-Duration-Ms
X-Cache-Action
X-Signature
X-B-Cache
X-Server-ID
X-Page-Id
Fastcgi-Useragent
X-FTR-Request-ID
X-Debug-Info
X-WebKit-CSP-Report-Only
X-Jobs
X-N
X-Load-Cache
Realpath
X-FB-Debug
X-Contextid
X-Erf-Bev-Bev-Is-Generated
X-Mobile
X-Erf-Bev-Bev
X-Browser-Type
Powered-By-ChinaCache
X-Webkit-Csp
Node
X-Rule
Refresh
X-Response-Served-From
X-Cache-Expired-At
X-Accel-Buffering
X-Original-Request-Id
Ms-Operation-Id
DC
X-RTag
X-Wix-Request-Id
X-Drupal-Cache-Tags
X-Proxy
Version
X-Zen-Fury
X-Framework
X-Cacheable-TTL
X-Cluster-Name
X-B
X-Cache-Control
X-Instance
X-ProcessESI
X-RemovedCookies
X-HTML-Minification-Powered-By
Access-Control-Request-Headers
Viewport
X-Real-IP
Referer-Policy
X-Content-Powered-By
X-Page-View
X-UUID
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Cache-Time
X-Region
X-Via-JSL
X-Distributor
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Drupal-Cache-Contexts
X-IPS-LoggedIn
Eomportal-Instance
X-FireWall-Port
X-FW-Server
X-FW-Dynamic
X-FW-Hash
X-FW-Serve
X-FW-Type
X-FW-Static
X-Cached-By
Countrycode
X-Akamai-Edgescape
X-Cache-Operation
X-Cache-Rule
X-G
Liferay-Portal
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Tumblr-Pixel-0
X-Cache-Hit
X-Tumblr-Pixel-1
X-Tumblr-Pixel
X-Yottaa-Optimizations
X-Tumblr-User
X-Yottaa-Metrics
X-L-Path
X-Pass-Why
X-App-Server
X-Environment-Context
Xserver
X-Nginx-Cache
X-Tec-Api-Version
DynaTrace
X-Tec-Api-Origin
SRV
X-Tec-Api-Root
Server-Info
CF-IPCountry
X-Debug-IsConnected
Section-Io-Id
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
X-Debug-IsPreview
X-Protected-By
X-Www-Served-By
X-User-Agent
X-Tumblr-Pixel-2
From-Origin
Webserver
X-Device-Type
X-Varnish-Grace
X-Mode
Ec-Rule-Version
X-Adobe-Loc
X-Adobe-Content
Meta-Geo
X-Endurance-Cache-Level
X-UPSTREAM-Address
Retry-After
X-RN-RSRV
X-Hl-Ver
X-Handled-By
X-ES-SERVER
GEO-INFO
X-Ratelimit-Limit
Cache-Tv-Group
X-Backend-Name
X-Uri
X-MP-GENERATED-AT
X-Storage
X-Varnishpool
X-Access
X-Cache-Server
X-Format
X-Origin-Hint
X-PHP-Host
Decoy-Debug-Key
X-Pubstack
X-Labrador-Cache-Channel
Webcakes-App-Version
X-Section
X-FB-TRIP-ID
Webcakes-Region
Property-Id
Cache-Status
Fastly-SSL
Frame-Options
Decoy-Debug-Status
Decoy-Debug-TTL
TWC-Device-Class
TWC-Connection-Speed
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Locale-Group
TWC-Privacy
Webcakes-App-Name
X-NYM-Debug-Backend
X-OCL
X-LAGOON
X-PCL
X-Varnish-Server
Selected-Fe
X-ApacheServer
X-Be
Mn-Server-Ip
X-PERF
X-WA-Info
Protected
X-Proto
X-Timing-Wait
X-Sql-Duration-Ms
Country
X-BYPASS-REASON
X-Request-Time
X-Soup
X-ProxyCache-Status
X-ProxyCache-Key
X-Human
X-Sql-Count
X-UA-Device-Type
X-Redis-Cache
X-Server-W
X-R9-Blue-Green-Version
X-Proxy-Build
Azure-SlotName
Azure-SiteName
X-LJ-Flow-ID
Azure-Version
X-No-Session
X-Origin-Date
X-S-Maxage
X-Proxied
X-Locale
Azure-InstanceId
X-Hyper-Cache
X-Via-Fastly
X-AWS-Id
X-Hosted-By
X-Site-Version
X-VWS-Id
X-Routing-Service
X-Cache-TTL-Remaining
Apigw-Requestid
X-Zipkin-Id
X-Web-Node
Azure-RegionName
X-Status
Cache-Name
X-Sorting-Hat-PodId
X-Alternate-Cache-Key
X-AIR-PT
X-Shopify-Stage
X-Sorting-Hat-ShopId
X-ShopId
X-FW-Version
X-Loop
X-ShardId
X-TNCMS
X-Storefront-Renderer-Rendered
X-Say-TTL
X-Say-Cacheable
X-SayCDN-TTL
X-Info
X-Node-Name
AMP-Access-Control-Allow-Source-Origin
X-Xfnlog-Site
X-Is-Bot
X-Dc
X-GG-Cache-Date
X-Cluster
X-TT-LOGID
X-Rendered-As
X-CCM
X-Forwarded-Host
X-Cache-Grace
X-Cache-Enabled
S-Cnection
Uber-Trace-Id
X-Proxy-Cache-Status
X-Microcachable
X-Qloud-Router
X-Revision
X-Content-Age
X-TA-CDN-Provider
X-NWS-UUID-VERIFY
X-Platform
X-CSRF-Token
X-Backend-Host
X-Azure-Ref
X-Via-CDN
X-SRV
Cache-Hits
Amp-Access-Control-Allow-Source-Origin
X-Varnish-Ttl
X-App-Version
X-Cache-Host
Akamai-GRN
X-Detected-As
X-FTR-Cache-Status
X-FTR-DC
X-Aspnetmvc-Version
X-FTR-Balancer
X-Amz-Meta-S3cmd-Attrs
X-FTR-Backend
X-FTR-Backend-Server
X-FTR-Realm
X-Ratelimit-Remaining
X-Correlation-ID
X-Country-Code-Real
X-Amzn-Remapped-Content-Length
ServedBy
X-Amzn-RequestId
X-Amz-Apigw-Id
X-EdgeConnect-Cache-Status
X-ATG-Version
X-Cache-PHP
X-B3-SpanId
X-Cache-NGX
X-RCS-CacheZone
X-Trace-Id
X-Varnish-Hostname
HostName
SD-X-WS
X-Nc
X-FTR-Expires
X-Akamai-Transformed
X-DynaTrace-JS-Agent
X-Oss-Storage-Class
X-CS
X-Debug-Cache
DB-Nickname
X-Time-Microsecs
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-BCube-Filmed-By
X-Air-Hostname
X-CACHE-KEY
X-ServerID
X-Backend-TTL
Tracecode
X-TX-ID
X-Adobe-Source
Backend
X-A-Wwc
X-Generation-Time
X-A-Ccd
X-A-Dcw
X-A-Dam
X-PBS-Appsvrname
X-External-Request-Id
X-A
X-Level-Front-Cache
X-From
X-Processor
X-PAYTM-SRV-ID
X-Owner
X-Location
Expiry
X-A-Dgt
X-Generated-On
X-Vtex-Processado-Em
X-Destination
X-Trv-Group
X-D
X-Connection-Hash
Odigeo-Trace-Id
X-ARC
X-Application
T-Server
X-Vdms-Version
DCR-Processing-Time-Ms
X-B-Cookie
BehaviorPad-Version
X-Origin-CC
Rendered-Blocks
X-ScT
X-Origin-TTL
X-Cache-NE
X-CF-Lambda-Fn
X-SRCache-Key
X-CF-Lambda-Version
X-Session-Fingerprint
X-VG-WebCache
X-Vdms-Path
X-NAPM-TraceId
X-Request-UUID
X-Rewrite-Enabled
X-VG-WebServer
MD5-Digest
Fastcgi-X-Cache-Version
Xc-Version
DCR-Decision-By
Machine
X-Vtex-Remote-Cache
X-Rojux
Meta-Geo-Continent
X-Unique-ID
X-Aed
X-S
Mobile-Detection-Method
X-S-Cookie
X-Tb
X-Varnish-Beresp-Grace
X-Ms-Request-Id
X-NewRelic-App-Data
X-Ms-Version
X-Bip
X-Fetched-On
X-Device-Os
X-Cache-Bucket
CacheControlHeader
X-Generated-In
AKAMAI
X-Core-Value
X-Geo-Header
X-Fastly-Cache
X-FC-Vary-Parameters
X-Developers
X-Policy
X-Sucuri-ID
Release
Thinkindot-CacheControl
Magicmarker
X-GeoIP-City
UCS
Thinkindot-Control
X-Reqid
X-OVcl
On-Server
Pagetype
Path
Server-Host
X-Thanos
X-Thinkindot-L3
X-Tumblr-Pixel-3
X-TrackingId
V-Age
Thinkindot-CacheControl-Type
Gh-Request-Id
X-OVcl-Cache
Wxu-Next-Hostname
X-Irp-Debug
X-HS-Content-Campaign-Id
Fastly-Backend-Name
X-Varnish-Cache-Hits
Who
Wxu-Next-Commit
Wxu-Next-Region
X-Micro-Cache
Host-ID
X-Magnolia-Registration
X-Mvc-Supplant-Cachable
X-Unique-Id
X-Varnish-Beresp-Ttl
Country-Code
X-Cache-Var
X-Cache-Var-Map
X-Cdn-Forward
User-Cache-Control
Server-Ext
X-Block-Status
True-Client-Country-4JS
X-Azure-Ref-OriginShield
Web-Mar-Node
Sever-Int
X-Branch-Name
X-Backend-State
Server-Hostname
X-IP
X-Wikidot-Backend
X-Request-Host
X-Request-URI
X-Nginx-Cache-Key
X-Wikidot-Static-Cache
Cache-Host
X-Ratelimit-Reset
X-Swa-Ws
X-Cache-Info
Ssr
X-VServer
X-Node-Id
X-Skip-Cache
X-Old-Content-Length
X-Origin
X-Origin-Response-Time
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Scheme
X-VarnishDD-TTL
X-Var-Ttl
X-User
X-Method
X-LI-UUID
X-Envoy-Decorator-Operation
X-Esi-Check
X-Eu-Site
X-Fastly-Backend
X-Dispatcher-Server
X-Developer
X-Cache-Id
X-CGP
X-Cms-Context
X-Csrf-Jwt
X-Gen-Mode
X-Generated-By
X-Is-Gdpr
X-JWT-State
X-Li-Fabric
X-Li-Pop
X-Hnp-Log
X-HN
X-GeoIP
X-GoCache-CacheStatus
X-Gzip
X-Has-Esi
X-Cache-Debug
Vix-Hermes-Req-Id
CDN-Uid
CDN-RequestId
CDN-RequestCountryCode
CDN-PullZone
Cf-Bgj
Cf-Device-Type
Ha-Gx-Prefs
Esi-Enabled
DSUID
Content-Disposition
CDN-EdgeStorageId
CDN-CachedAt
Apple-News-Services-Host
Apple-News-Services-Handled
X-Varnish-Beresp-Status
X-B3-Traceid
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
CDN-Cache
C-Via
Arc-Version
HA-Ipaddr
CDCHOST
Locid
Location
NGX
NM-Fastcgi-Cache
PB-RID
PB-PID
L5d-Success-Class
PFcat
X-GEO
X-APP-VERSION
X-SIPLIST1
Rt-Fastcgi-Cache
X-DefHash
X-VG-TLSProxy
X-Aicache-OS
L
X-Clara-WADP
X-Clientip
Adler-Geo
X-Variation
Platform
X-RateLimit-Limit
X-WADP-Cache
X-Varnish-Hits
X-Hash
Origin
X-Origin-Expires
X-DPWN-IS-SECURE
X-Fmm-Version
X-Gamma-Serve
X-LB-ID
X-DefElseHash
IsBot
X-Slack-Backend
X-Varnish-Remaining-TTL
Instruction
Is-Eu
X-Rebelmouse-Cache-Control
X-Varnish-CookieHashed-On
X-Rebelmouse-Surrogate-Control
Fastly-SIE
X-Cache-Tags
Fastly-SWR
X-Varnish-CookieINHashed-On
SR-User-Adfree
Geo-Info
X-EC-Lua
Filterid
X-ID
X-Platform-Server
X-NU-AKA-ACS-Version
X-Mvc-Supplant-OutputCached
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Varnish-Url
X-CUA
Fastly-Drupal-HTML
X-CLOUD-TRACE-CONTEXT
Lfy
X-Cache-Backend
X-Epic-Correlation-Id
X-Loc
X-Matched-Rule
X-PF-Uncompressing
Sid
X-Via-Popv
CloudFront-Viewer-Country
X-Planisys-CDN-Cache
Pics-Label
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Refresh
X-Via-Popn
X-Via-Poph
Pramga
X-Sn-Servicetimems
X-Cache-Expires
X-Cdn-Origin
Url
X-NCache
X-Servername
Req-Svc-Chain
Cmstype
Cmsid
X-TraceId
X-Cache-Date
X-Core-Mission
X-Tb-Optimization-Total-Bytes-Saved
Svr
NGB
Kp-EeAlive
X-Served-From
X-Srv
VivaBuild
X-Request-Start
Viewtype
A
Tcn
MIME-Version
X-FireWall-Protection
Source
X-Error
Cache-Key
M-TraceId
X-Vgn-Hpd-Reason
X-Varnish-Cacheable
Geoip-Latitude
GeoIp-Country-Code
Arc-Country
Cross-Origin-Opener-Policy
X-Webkit-CSP-Report-Only
X-DC
X-Response-By
Server-ID
TDXMobile
X-PHP-Backend
X-SaId
DataCenter
X-JoinUs
X-NC
X-Vcl-Version
X-HS-Status
X-Geo
X-Proxy-Cachei7
X-Air-Source
Xkeyi7
X-Wa
X-Vc
X-Edge-Location
NtCoent-Length
Server-Ttl
X-BBXSRF
SID
X-B3-Spanid
X-Li-Proto
N-Cache
X-NGENIX-Cache
X-Service
HitType
Content-Secure-Policy
X-Servedbyhost
X-CDN-Forward
X-Erf-Stays-Bingo-Pdp-Web
X-Cache-Remote
S-Rt
X-Internal-Host
Resin-Trace
X-Cache-2
X-Extlb
X-LiteSpeed-Cache-Control
X-Esi
CACHE
X-Varnish-Authentication
X-Forwarded-Site
FSS-Cache
X-Viewer-Country
X-Kraken-Routeconfig-Destination
X-Kraken-Loop-Name
X-LI-Proto
X-Instrumentation
X-Server-Lifecycle-Phase
D-Cc-Upstream
X-Cache-ASPX
X-Cc-Req-Id
X-Cc-Via
X-Contensis-Viewer-Groups
Cteonnt-Length
X-Bc-Bl
X-HOST
X-Sucuri-Cache
X-Via-NSCOPI
Request-ID
Cross-Origin-Window-Policy
X-Hcs-Proxy-Type
X-WA
X-CCDN-CacheTTL
Ohc-File-Size
X-Edge-Location-Klb
X-CCDN-Origin-Time
X-RAMCache
X-Svr
X-Host-Name
X-UA
X-Cs
X-HostName
X-Date
Surrogated-Key
We-Hiring
X-RPS
X-TIM-N
X-Newrelic-Synthetics
X-RSL
X-PJAX-URL
X-RPM
Mail-Subject
LB
X-DW
Memcached
X-Accel-Expires-Debug
X-ServedByHost
X-DSS
X-Req
X-DI
X-Server-IP
X-DB
X-VCL-Version
Hostname
X-FPC
X-Proxy-Upstream
X-Cache-Config
GeoIP-Country-Code
GeoIP-Latitude
Env
X-Gdpr
X-VC-Cache
X-Nyt-Route
X-RateLimit-Remaining-Second
X-API-Version
CF-Cached-On
X-App
X-Origin-Time
X-RateLimit-Limit-Second
XServer
X-SN
X-ZONE
Cache-Provider
X-Check-Cacheable
X-Sigma
Upgrade-Insecure-Requests
Server-Id
ProcessTime
X-NodeID
X-Action
X-APP
X-Men
X-Rocket-Build-Number
X-VC
X-Sigma-Backend
Ohc-Cache-HIT
X-TIME
Memory
CPC-Age
CPC-Cache
VNS-Age
VNS-Cache
X-Air-Trace-Id
X-Region-Sid
X-MSEdge-Flight
Mime-Version
Time
X-MSEdge-Features
X-Oss-Cdn-Auth
X-Webstats-RespID
X-CF-Powered-By
X-SB
X-Fpc
X-Swift-Error
X-URL
X-Dynatrace-Js-Agent
X-Provided-By
X-SD-PageType
X-Depends-On
X-FORWARDED-FOR
W
X-Zone
X-Akamai-Pragma-Client-IP
X-Cdn-Request-ID
Srv
Cdn
X-Render-Time
X-Ftr-Cache-Host
X-CSRF-TOKEN
X-BBC-Edge-Cache-Status
X-BACKEND-TTL
X-Dw-Trace-Id
X-UnsetCookies
CDN
X-ServerName
X-Client-Ip
X-NGINX-Cache
X-Fastly-Request-Id
X-ABtesting
X-Parent-Response-Time
Fastcgi-Cache-TTL
EpKe-Alive
My-App
X-Fastly-Backend-Reqs
X-Flog
Dnion-Transfer-Encoding
X-Hello
X-Dynatrace
X-Acquia-Purge-Tags
Media-Length
X-Worker
State
X-Oracle-DMS-ECID
X-FTR-Cache-Host
X-Acquia-Site
X-Acquia-Application-Trace
X-Pad
X-Acquia-Application-UUID
Processtime
X-Auto-Login
X-Presslabs-Stats
Vha6-Origin
X-Cache-Tag
X-Pf-Uncompressing
Proxy-Connection
X-ElasticPress-Search
X-LiteSpeed-Tag
X-Via-PopV
X-Snapshot-Date
X-Mg-Request-UUID
X-Via-PopH
X-Ua
X-Via-PopN
X-Cluster-Node
X-BBC-Origin-Response-Status
PICS-Label
X-Minions-Version
Epwk-X-Cache
Cf-Ipcountry
X-CACHE-AGE
X-Akamai-ERPolicy
Warning
X-Akamai-ERRuleID
X-Vcache
X-Request-URL
X-MiniProfiler-Ids
X-Varnish-Beresp-TTL
X-Varnish-URL
OT-Force-Account-Verify
X-Ms-Meta-Staticbatchstarttime
Xet-Cookie
X-Lb-Id
X-Ms-Meta-Originalurl
Datacenter
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-ElasticPress-Query
X-Cache-Type
CountryCode
X-Apw-Access-Token
X-Apw-Hits
X-Apw-Access-Object
X-Apw-Access-Action
X-Tenant
X-Tx-Id
X-Cache-Status-Check
Phost
X-Forwarded-Path
X-Orig-Expires
URI
X-Shop-Environment
X-Mg-Request-Id
X-ND-Cache
X-Traceid
NnCoection
X-B3-Parentspanid
Environment
Inserted-Into-Cache-At
X-C
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Tid
X-Redis-Count
X-Litespeed-Cache-Control
Content-Script-Type
X-Storefront-Renderer-Verified
X-Redis-Duration-Ms
X-Amz-Meta-Cb-Modifiedtime
Ohc-Response-Time
Content-Style-Type