Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-RAY
CF-Cache-Status
X-XSS-Protection
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
X-Request-Id
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Xss-Protection
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Cacheable
X-Request-ID
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Content-Encoding
X-CDN
X-Ua-Compatible
Feature-Policy
X-AspNetMvc-Version
Status
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Upgrade
X-Via
Access-Control-Max-Age
Keep-Alive
X-Ws-Request-Id
X-Age
X-Robots-Tag
X-AH-Environment
X-Turbo-Charged-By
Request-Context
EagleId
X-Proxy-Cache
X-Cache-Group
Server-Timing
X-Backend
X-Hacker
X-Server
Report-To
Host-Header
X-Server-Powered-By
X-Amz-Request-Id
X-Amz-Id-2
Grace
X-Nginx-Cache-Status
X-UA-Device
X-Dns-Prefetch-Control
X-Rq
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Page-Speed
Cf-Railgun
X-Pingback
X-OneAgent-JS-Injection
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
NEL
X-Cache-Spec
X-Amz-Version-Id
X-Device
X-CST
X-Vhost
Allow
X-Host
X-Backend-Server
Xkey
X-Server-Id
X-WebKit-CSP
EagleEye-TraceId
X-Dispatcher
Surrogate-Control
X-Node
Request-Id
Content-Location
X-Response-Time
X-Akam-SW-Version
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Ruxit-JS-Agent
P3p
X-ASPNET-VERSION
Accept-Ch
X-Application-Context
X-Ac
X-Cache-Lookup
X-Country
X-Template
Accept-Ch-Lifetime
X-Mod-Pagespeed
X-Language
Accept-CH
X-Readtime
X-Cloud-Trace-Context
Accept-CH-Lifetime
MS-Author-Via
X-B3-TraceId
Rating
X-HW
X-Origin-Cache
X-Cnection
X-MS-InvokeApp
X-Url
X-TtlSet
X-Vname
X-PC
Edge-Control
X-Clacks-Overhead
X-GitHub-Request-Id
X-ESI
X-ORACLE-DMS-RID
X-Trace
X-ORACLE-DMS-ECID
X-Content-Type
X-Middleton-Display
X-Middleton-Response
X-Varnish-TTL
X-Sol
Pagespeed
Response
Display
X-D2id
Arr-Disable-Session-Affinity
Verso
X-Vcap-Request-Id
X-Exp-Id
X-Cdn-Fetch
X-GoogleNews-Bot
X-Kinja-Build
X-Use-Magma
X-Kinja-Server
X-Kinja-Revision
X-Kinja
X-Exp-Variant
X-Goog-Hash
X-Rack-Cache
X-Country-Code
X-TTL
X-Powered-By-Plesk
X-Navigation-Version
Service-Worker-Allowed
X-Buckets
X-Server-Name
X-VARITI-CCR
X-Amz-Rid
X-Abt-Application-Version
X-Fastly-Request-ID
X-FastCGI-Cache
X-Webkit-CSP
X-Client-IP
Fastly-Restarts
X-Cache-TTL
X-Cached
X-Release
X-MSEdge-Ref
X-Element-Page-Cache
X-Dw-Request-Base-Id
X-SharePointHealthScore
SPRequestGuid
X-Oneagent-Js-Injection
Pinterest-Generated-By
X-Pinterest-Rid
Pinterest-Version
X-NF-Request-ID
SPIisLatency
SPRequestDuration
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
Public-Key-Pins
RTSS
Access-Control-Request-Method
AR-Request-ID
Ar-Sid
X-Edge
AR-CACHE
AR-PoweredBy
AR-ATIME
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Cache-Tag
X-Powered-CMS
X-LLID
X-Ezoic-Cdn
X-Litespeed-Cache
X-Upstream
Content-MD5
X-HP-Webp
X-Jurisdiction
X-Origin-Upstream-Status
X-Version
S
Fusion-Source
Fusion-Template-Id
Fusion-Deployment-Id
Fusion-Content-Source
Fusion-Content-Id
Fusion-Component-Id
X-Px
X-Mid
X-MCACHE
X-ECACHE
X-Recruiting
X-Mg-S
Charset
X-Content-Digest
X-PressLabs-Stats
X-Kinsta-Cache
Fastcgi-Cache
X-DynaTrace
X-T
Cache-Tags
X-Amz-Server-Side-Encryption
Filters
X-Accel-Expires
X-Logged-In
MicrosoftSharePointTeamServices
X-Ruxit-Js-Agent
X-Content-Security-Policy-Report-Only
Edge-Cache-Tag
X-Forwarded-Proto
Server-Node
X-Ttl
Front-End-Https
X-Id
X-Correlation-Id
TP-Cache
TP-L2-Cache
X-Grace
X-Forwarded-For
Server-Name
X-Debug
X-Fastcgi-Cache
Nginx-Cache
X-Hits
X-Kong-Upstream-Latency
X-Amzn-Trace-Id
X-Kong-Proxy-Latency
X-Request-Received
X-Request-Processing-Time
TCN
X-B3-Sampled
X-Shield-Request-Id
X-Yandex-Sdch-Disable
Surrogate-Key
X-Varnish-Age
X-Microsite
X-Request-Handler-Origin-Region
X-Az
X-Activity-Id
X-AppVersion
X-Amz-Replication-Status
X-Ser
X-HS-Cache-Config
X-HS-Content-Id
X-F-Cache
X-XRDS-Location
X-HS-Combine-CSS
X-HS-Hub-Id
X-XRDS-LOCATION
X-Origin-Server
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Storage-Class
X-DIS-Request-ID
Alternate-Protocol
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Pinterest-Direct
Accept-Charset
X-Geo-Country
X-Rid
X-Git-Hash
X-Cache-Key
X-Frontend
X-Respond-Thread
Section-Io-Cache
Host
X-Time
X-NWS-LOG-UUID
X-LB-Cache
X-Upgrade-Enabled
Cache
Access-Control-Allow-Method
X-DataDome
X-Mobile-URL
X-VCache
X-Seen-By
X-Cache-Age
X-Server-ID
MS-CV
X-FTR-Request-ID
ServerID
X-Type
Healthy
X-IPLB-Instance
X-TT
X-AOL-HN
X-Whom
X-Varnish-Backend
X-Content-Options
X-Source
X-Hostname
Paypal-Debug-Id
X-Is-Crawler
X-Request-Guid
X-Providence-Cookie
X-Flags
Payment
X-Aspnet-Duration-Ms
X-Route-Name
X-App-Environment
Cleartype
X-Signature
X-B-Cache
X-Cache-Action
X-Page-Id
X-Debug-Info
X-Jobs
Fastcgi-Useragent
X-Daa-Tunnel
X-RateLimit-Remaining
X-WebKit-CSP-Report-Only
X-N
X-Load-Cache
Powered-By-ChinaCache
X-FB-Debug
Nel
X-Webkit-Csp
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Mobile
X-Contextid
Realpath
Node
Refresh
X-Via-JSL
X-Rule
X-Drupal-Cache-Tags
X-Wix-Request-Id
X-Accel-Buffering
Version
X-Original-Request-Id
X-Response-Served-From
X-Zen-Fury
X-RTag
X-Cache-Expired-At
Ms-Operation-Id
X-Proxy
X-Cacheable-TTL
Referer-Policy
X-Framework
X-ProcessESI
X-RemovedCookies
X-Cache-Time
X-Drupal-Cache-Contexts
X-Distributor
Access-Control-Request-Headers
DC
X-Instance
X-Region
X-Cluster-Name
X-B
X-Real-IP
X-HTML-Minification-Powered-By
X-Tt-Trace-Host
X-FW-Server
X-Content-Powered-By
X-Tt-Trace-Tag
X-Cache-Control
X-FW-Hash
X-UUID
X-FW-Serve
X-FW-Dynamic
X-FW-Static
X-Akamai-Edgescape
Viewport
X-FW-Type
Eomportal-Instance
X-Page-View
X-Cached-By
VIX-Pulpo-Node
X-Cache-Operation
VIX-Pulpo-Upstream-Status
X-Cache-Rule
Countrycode
X-IPS-LoggedIn
Liferay-Portal
X-Yottaa-Optimizations
X-FireWall-Port
X-Yottaa-Metrics
X-G
X-Cache-Hit
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-1
X-Pass-Why
X-Environment-Context
X-L-Path
X-App-Server
DynaTrace
Server-Info
SRV
CF-IPCountry
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
X-Nginx-Cache
Section-Io-Id
X-Protected-By
X-User-Agent
Ec-Rule-Version
Xserver
X-Debug-IsPreview
X-Debug-IsConnected
X-Www-Served-By
X-Tumblr-Pixel-2
Webserver
From-Origin
GEO-INFO
X-Device-Type
X-Ratelimit-Limit
X-Mode
X-Hl-Ver
X-UPSTREAM-Address
X-Endurance-Cache-Level
X-ES-SERVER
X-Adobe-Loc
Meta-Geo
X-RN-RSRV
X-Adobe-Content
X-FB-TRIP-ID
Protected
Cache-Tv-Group
X-Uri
X-Handled-By
X-Backend-Name
X-MP-GENERATED-AT
X-Cache-Server
X-Varnish-Grace
X-Be
X-UA-Device-Type
Cache-Status
X-Labrador-Cache-Channel
X-Storage
TWC-Device-Class
X-Web-Node
X-NYM-Debug-Backend
Retry-After
Webcakes-Region
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Connection-Speed
TWC-Locale-Group
Property-Id
Webcakes-App-Version
Webcakes-App-Name
TWC-Privacy
X-Node-Name
X-Varnishpool
X-Origin-Hint
X-PHP-Host
X-Section
X-FW-Version
X-BYPASS-REASON
X-Server-W
X-ProxyCache-Status
X-Timing-Wait
X-ProxyCache-Key
X-LJ-Flow-ID
X-Sql-Count
X-Redis-Cache
X-AWS-Id
Mn-Server-Ip
X-Proto
X-Format
Selected-Fe
Frame-Options
X-OCL
X-Via-Fastly
X-PCL
Cache-Name
Country
X-Request-Time
X-Soup
X-Access
X-Origin-Date
Decoy-Debug-Key
Decoy-Debug-Status
Fastly-SSL
Decoy-Debug-TTL
X-No-Session
X-Sql-Duration-Ms
X-WA-Info
X-VWS-Id
X-Proxy-Build
Azure-SiteName
Azure-SlotName
Azure-Version
Azure-RegionName
Azure-InstanceId
X-Routing-Service
X-Loop
X-Xfnlog-Site
X-Zipkin-Id
X-LAGOON
X-S-Maxage
X-Status
X-Pubstack
X-Locale
X-Site-Version
X-PERF
X-ApacheServer
X-TNCMS
X-Tec-Api-Root
X-Tec-Api-Origin
X-Proxied
X-Say-Cacheable
X-Tec-Api-Version
X-Hosted-By
X-R9-Blue-Green-Version
X-Cache-TTL-Remaining
X-SayCDN-TTL
X-Hyper-Cache
X-Human
X-Say-TTL
X-Alternate-Cache-Key
X-Sorting-Hat-PodId
X-ShardId
X-Storefront-Renderer-Rendered
X-CCM
X-Shopify-Stage
X-Sorting-Hat-ShopId
X-ShopId
X-TT-LOGID
Apigw-Requestid
X-Forwarded-Host
X-Cache-Grace
X-Cluster
X-Varnish-Server
X-GG-Cache-Date
X-AIR-PT
X-Rendered-As
X-Revision
X-SRV
X-Info
X-Is-Bot
X-Ratelimit-Remaining
S-Cnection
AMP-Access-Control-Allow-Source-Origin
X-Microcachable
X-Cache-Enabled
X-Qloud-Router
X-Content-Age
X-Proxy-Cache-Status
Uber-Trace-Id
X-Cdn
X-Dc
X-Via-CDN
Cache-Hits
X-Platform
X-FTR-DC
X-FTR-Realm
X-Azure-Ref
X-FTR-Cache-Status
X-FTR-Backend-Server
X-FTR-Backend
X-CSRF-Token
X-Country-Code-Real
X-FTR-Balancer
X-Backend-Host
X-Varnish-Ttl
Amp-Access-Control-Allow-Source-Origin
X-TA-CDN-Provider
X-Cache-Host
X-Amz-Meta-S3cmd-Attrs
X-Aspnetmvc-Version
X-Detected-As
X-NWS-UUID-VERIFY
X-Amz-Apigw-Id
X-Amzn-Remapped-Content-Length
X-Amzn-RequestId
X-FTR-Expires
X-App-Version
Akamai-GRN
X-EdgeConnect-Cache-Status
X-ATG-Version
X-B3-SpanId
X-Oss-Request-Id
X-CS
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
X-Air-Hostname
X-Oss-Storage-Class
Tracecode
SD-X-WS
X-Time-Microsecs
X-Debug-Cache
X-Trace-Id
X-RCS-CacheZone
X-Cache-NGX
ServedBy
X-ID
X-Cache-PHP
X-Varnish-Hostname
X-Backend-TTL
X-Correlation-ID
X-BCube-Filmed-By
X-ServerID
HostName
X-Tb
DB-Nickname
X-Cache-Var
X-Cache-Var-Map
X-Akamai-Transformed
X-Unique-Id
X-NewRelic-App-Data
Backend
X-ARC
X-Application
X-Aed
X-Vtex-Remote-Cache
X-CF-Lambda-Fn
X-Cache-NE
X-A-Wwc
X-CF-Lambda-Version
X-Connection-Hash
X-B-Cookie
X-Magnolia-Registration
X-Ms-Version
X-Adobe-Source
Odigeo-Trace-Id
Release
DCR-Processing-Time-Ms
Rendered-Blocks
Mobile-Detection-Method
Meta-Geo-Continent
Fastcgi-X-Cache-Version
Machine
MD5-Digest
BehaviorPad-Version
DCR-Decision-By
T-Server
X-A-Ccd
X-A
X-A-Dam
X-A-Dcw
Xc-Version
X-Ms-Request-Id
Expiry
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Thinkindot-Control
X-Destination
X-A-Dgt
X-D
X-Session-Fingerprint
X-Trv-Group
X-Location
X-DynaTrace-JS-Agent
X-Request-UUID
X-Rojux
X-PAYTM-SRV-ID
X-Vdms-Path
X-NAPM-TraceId
X-PBS-Appsvrname
X-ScT
X-Origin-TTL
X-Origin-CC
X-Vtex-Processado-Em
X-Processor
X-S
X-Rewrite-Enabled
X-VG-WebCache
X-GeoIP-City
X-VG-WebServer
X-Thinkindot-L3
X-Device-Os
X-External-Request-Id
X-From
X-Fetched-On
X-SRCache-Key
X-S-Cookie
X-Generation-Time
X-Vdms-Version
X-Nc
X-TX-ID
X-Sucuri-ID
X-GEO
DSUID
Server-Ext
PB-RID
PB-PID
NGX
Gh-Request-Id
Host-ID
Instruction
Fastly-Backend-Name
X-SVT-ORM-RULES
Content-Disposition
X-SVT-ORM-VERSION
Locid
X-Skip-Cache
On-Server
Pagetype
X-Tumblr-Pixel-3
Server-Host
Magicmarker
X-TrackingId
Path
Wxu-Next-Commit
X-Cache-Bucket
X-GeoIP
X-Has-Esi
X-Azure-Ref-OriginShield
X-Irp-Debug
X-HS-Content-Campaign-Id
Cf-Device-Type
X-Geo-Header
X-Fastly-Cache
X-Developers
X-Cms-Context
X-FC-Vary-Parameters
X-Generated-On
X-Is-Gdpr
X-JWT-State
UCS
X-Policy
X-Reqid
X-VServer
Sever-Int
SR-User-Adfree
Wxu-Next-Hostname
X-Owner
X-Mvc-Supplant-Cachable
X-Level-Front-Cache
X-Nginx-Cache-Key
X-Node-Id
Wxu-Next-Region
Server-Hostname
X-Core-Value
X-B3-Traceid
Arc-Version
C-Via
CacheControlHeader
AKAMAI
X-EC-Lua
X-Varnish-Cache-Hits
User-Cache-Control
X-Cdn-Forward
X-Envoy-Decorator-Operation
X-Dispatcher-Server
X-Wikidot-Static-Cache
X-Esi-Check
X-DPWN-IS-SECURE
X-Gen-Mode
X-Wikidot-Backend
X-Fastly-Backend
X-Developer
X-WADP-Cache
X-Fmm-Version
X-Eu-Site
X-Var-Ttl
X-Branch-Name
X-Cache-Debug
X-Cache-Id
X-Block-Status
X-Bip
V-Age
X-Backend-State
X-Cache-Info
X-Cache-Tags
X-Generated-By
X-DefElseHash
X-Csrf-Jwt
X-Clientip
X-CGP
X-Clara-WADP
X-DefHash
X-Hnp-Log
X-Rebelmouse-Surrogate-Control
X-Varnish-Remaining-TTL
X-Rebelmouse-Cache-Control
X-Ratelimit-Reset
X-VarnishDD-TTL
X-Platform-Server
X-Request-Host
X-Varnish-CookieINHashed-On
X-Varnish-Beresp-Grace
X-Variation
X-Thanos
X-SIPLIST1
X-Varnish-CookieHashed-On
X-Scheme
X-OVcl-Cache
X-OVcl
X-Li-Fabric
X-Li-Pop
X-IP
X-Generated-In
X-Gzip
X-HN
X-LI-UUID
X-Method
X-Origin-Expires
X-Origin-Response-Time
X-Origin
X-Old-Content-Length
X-Micro-Cache
X-NU-AKA-ACS-Version
X-GoCache-CacheStatus
X-CUA
IsBot
Is-Eu
CDCHOST
CDN-Cache
L5d-Success-Class
Location
X-User
Platform
PFcat
Adler-Geo
HA-Ipaddr
Ha-Gx-Prefs
CDN-RequestCountryCode
CDN-RequestId
CDN-Uid
Cf-Bgj
CDN-PullZone
CDN-EdgeStorageId
CDN-CachedAt
Fastly-SWR
Fastly-SIE
Ssr
NM-Fastcgi-Cache
Web-Mar-Node
X-APP-VERSION
X-Cache-Backend
X-Hash
X-VG-TLSProxy
X-Varnish-Beresp-Ttl
X-Unique-ID
Esi-Enabled
X-Gamma-Serve
Rt-Fastcgi-Cache
Vix-Hermes-Req-Id
Origin
X-Varnish-Hits
True-Client-Country-4JS
X-Slack-Backend
Who
L
Apple-News-Services-Parsed-Url
X-Request-URI
X-LB-ID
Apple-News-Services-Request-Url
Cache-Host
X-Matched-Rule
Lfy
X-Swa-Ws
Apple-News-Services-Host
Apple-News-Services-Handled
Country-Code
X-CLOUD-TRACE-CONTEXT
X-Loc
X-Aicache-OS
Fastly-Drupal-HTML
X-Goog-Meta-Goog-Reserved-File-Mtime
CloudFront-Viewer-Country
X-Mvc-Supplant-OutputCached
X-Varnish-Beresp-Status
Sid
X-RateLimit-Limit
Geo-Info
X-CACHE-KEY
X-Via-Poph
X-NCache
X-Via-Popn
X-Via-Popv
Tcn
Pics-Label
X-Varnish-Url
X-Cdn-Origin
Pramga
X-Cache-Expires
X-Sn-Servicetimems
X-Epic-Correlation-Id
X-Servername
X-Core-Mission
X-Cache-Date
X-PF-Uncompressing
Filterid
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Tb-Optimization-Total-Bytes-Saved
Url
X-Request-Start
X-Refresh
X-TraceId
Req-Svc-Chain
Cmstype
Cmsid
X-FireWall-Protection
X-Error
Kp-EeAlive
X-DC
X-Varnish-Cacheable
X-Response-By
VivaBuild
Viewtype
NGB
X-Served-From
A
Cache-Key
MIME-Version
Svr
X-Erf-Stays-Bingo-Pdp-Web
X-Webkit-CSP-Report-Only
X-NC
Xkeyi7
X-Srv
Source
X-Proxy-Cachei7
M-TraceId
X-Cache-Remote
Server-ID
Arc-Country
S-Rt
X-BBXSRF
GeoIp-Country-Code
Server-Ttl
Geoip-Latitude
X-Air-Source
HitType
X-Wa
TDXMobile
Cross-Origin-Opener-Policy
Content-Secure-Policy
X-HS-Status
X-Servedbyhost
N-Cache
X-URL
X-Vgn-Hpd-Reason
X-B3-Spanid
X-Vcl-Version
X-Cache-2
X-CDN-Forward
X-HostName
NtCoent-Length
X-LI-Proto
D-Cc-Upstream
X-Cache-ASPX
X-Varnish-Authentication
X-Esi
X-Contensis-Viewer-Groups
X-LiteSpeed-Cache-Control
X-Cc-Via
Resin-Trace
X-Cc-Req-Id
X-SaId
Ohc-File-Size
Cteonnt-Length
SID
X-JoinUs
CACHE
Cross-Origin-Window-Policy
X-Sucuri-Cache
X-PHP-Backend
X-NGENIX-Cache
X-Host-Name
X-Li-Proto
X-Edge-Location
X-Internal-Host
X-Geo
X-Vc
X-RAMCache
X-Svr
X-Service
X-HOST
X-VCL-Version
X-CCDN-Origin-Time
Request-ID
XServer
X-Server-IP
X-CCDN-CacheTTL
Hostname
DataCenter
X-Hcs-Proxy-Type
X-UA
X-Extlb
X-Gdpr
FSS-Cache
X-FPC
X-DI
X-API-Version
GeoIP-Country-Code
GeoIP-Latitude
X-Via-NSCOPI
X-Viewer-Country
X-WA
X-Newrelic-Synthetics
X-Forwarded-Site
X-Cache-Config
X-Origin-Time
X-DB
X-ServedByHost
X-RPS
X-RPM
X-Nyt-Route
X-VC
X-TIM-N
X-DW
X-DSS
X-RSL
X-Cs
X-Bc-Bl
X-Dynatrace
CF-Cached-On
X-SN
X-Check-Cacheable
X-App
Cache-Provider
Ohc-Cache-HIT
X-Date
X-Accel-Expires-Debug
X-Proxy-Upstream
X-VC-Cache
X-Req
X-Region-Sid
ProcessTime
X-NodeID
X-ZONE
Surrogated-Key
Memcached
Mail-Subject
LB
X-Action
X-Webstats-RespID
Server-Id
X-SB
We-Hiring
X-Dynatrace-Js-Agent
Env
X-Fpc
X-RateLimit-Remaining-Second
X-PJAX-URL
X-RateLimit-Limit-Second
X-Oss-Cdn-Auth
X-SD-PageType
Mime-Version
X-CF-Powered-By
X-Kraken-Loop-Name
X-Instrumentation
X-Kraken-Routeconfig-Destination
X-Server-Lifecycle-Phase
X-Provided-By
X-Swift-Error
X-FORWARDED-FOR
W
X-Render-Time
X-BBC-Edge-Cache-Status
X-Depends-On
X-Sigma
X-Sigma-Backend
X-Men
X-Rocket-Build-Number
X-Air-Trace-Id
Upgrade-Insecure-Requests
X-APP
X-NGINX-Cache
X-Cdn-Request-ID
Srv
CPC-Age
Time
CPC-Cache
VNS-Age
VNS-Cache
X-Ftr-Cache-Host
CDN
X-MSEdge-Flight
EpKe-Alive
X-CSRF-TOKEN
X-MSEdge-Features
Memory
X-UnsetCookies
X-BACKEND-TTL
X-Dw-Trace-Id
Cdn
X-TIME
X-CACHE-AGE
X-FTR-Cache-Host
X-Client-Ip
X-Fastly-Backend-Reqs
X-Fastly-Request-Id
Dnion-Transfer-Encoding
X-Worker
X-Auto-Login
X-Cache-Tag
X-Parent-Response-Time
X-Hello
X-Flog
X-Pf-Uncompressing
X-ABtesting
Processtime
X-Akamai-Pragma-Client-IP
Datacenter
X-Ua
Proxy-Connection
X-Zone
X-Oracle-DMS-ECID
X-Acquia-Site
X-BBC-Origin-Response-Status
X-Cluster-Node
Vha6-Origin
X-Acquia-Application-Trace
X-Presslabs-Stats
X-Pad
Media-Length
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
Epwk-X-Cache
State
X-ServerName
X-Snapshot-Date
Fastcgi-Cache-TTL
My-App
PICS-Label
X-IN-APIGATEWAY
X-LiteSpeed-Tag
X-Via-PopH
X-Via-PopN
X-Via-PopV
X-IN-APIGATEWAYSSL
Cf-Ipcountry
X-Vcache
X-ElasticPress-Search
X-Akamai-ERPolicy
X-MiniProfiler-Ids
X-ElasticPress-Query
X-Akamai-ERRuleID
X-Varnish-URL
Xet-Cookie
X-Varnish-Beresp-TTL
X-Ms-Meta-Staticbatchstarttime
X-Edge-Location-Klb
X-Ms-Meta-Originalurl
X-Request-URL
X-Lb-Id
X-Minions-Version
CountryCode
X-Tx-Id
X-Air-Pt
Content-Script-Type
X-Litespeed-Cache-Control
X-Apw-Access-Action
X-Apw-Hits
X-Cache-Status-Check
X-Nananana
X-Apw-Access-Token
X-Apw-Access-Object
X-Request-Url
OT-Force-Account-Verify
X-Storefront-Renderer-Verified
Content-Style-Type
X-Redis-Count
X-Traceid
URI
X-Debug-Cache-Store
X-Debug-Cache-Fetch
Phost
X-C
X-B3-Parentspanid
NnCoection
Environment
X-Tid
Ohc-Response-Time
Inserted-Into-Cache-At
X-Redis-Duration-Ms
X-Amz-Meta-Cb-Modifiedtime