Threat Level: green Handler on Duty: Renato Marinho

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-RAY
CF-Cache-Status
X-XSS-Protection
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-Served-By
X-UA-Compatible
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Xss-Protection
X-Ua-Compatible
X-Request-ID
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Content-Encoding
X-CDN
X-AspNetMvc-Version
Feature-Policy
X-Envoy-Upstream-Service-Time
Status
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-Via
Upgrade
Access-Control-Max-Age
Keep-Alive
X-Ws-Request-Id
X-Age
X-AH-Environment
X-Turbo-Charged-By
X-Robots-Tag
Request-Context
X-Proxy-Cache
X-Cache-Group
EagleId
Server-Timing
X-Backend
X-Hacker
X-Server
Report-To
Host-Header
X-Amz-Request-Id
X-Server-Powered-By
X-Amz-Id-2
Grace
X-Nginx-Cache-Status
X-UA-Device
X-Rq
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Page-Speed
Cf-Railgun
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
NEL
X-Dns-Prefetch-Control
X-OneAgent-JS-Injection
X-Cache-Spec
X-Amz-Version-Id
X-WebKit-CSP
X-Device
X-CST
Allow
Xkey
X-Vhost
X-Host
X-Backend-Server
X-Server-Id
EagleEye-TraceId
Request-Id
Surrogate-Control
X-Dispatcher
X-Node
Content-Location
X-Response-Time
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Akam-SW-Version
X-Ruxit-JS-Agent
Accept-CH
P3p
X-ASPNET-VERSION
X-Ac
X-Application-Context
X-Cache-Lookup
X-Country
X-Template
X-Language
Accept-CH-Lifetime
X-Mod-Pagespeed
X-Readtime
Accept-Ch-Lifetime
Accept-Ch
X-Cloud-Trace-Context
MS-Author-Via
X-B3-TraceId
Rating
X-Origin-Cache
X-MS-InvokeApp
X-Cnection
X-HW
X-Url
X-Vname
X-PC
X-TtlSet
X-Clacks-Overhead
X-GitHub-Request-Id
Edge-Control
X-ESI
X-ORACLE-DMS-ECID
X-Trace
X-Middleton-Response
X-Middleton-Display
X-Content-Type
X-Sol
Pagespeed
Response
Display
X-D2id
X-ORACLE-DMS-RID
Arr-Disable-Session-Affinity
Verso
X-Vcap-Request-Id
X-Use-Magma
X-Exp-Variant
X-Kinja-Server
X-Kinja-Revision
X-Cdn-Fetch
X-Exp-Id
X-Kinja-Build
X-GoogleNews-Bot
X-Kinja
X-Goog-Hash
X-Rack-Cache
X-Buckets
X-Country-Code
X-FastCGI-Cache
X-Server-Name
X-Oneagent-Js-Injection
X-Varnish-TTL
X-Navigation-Version
Service-Worker-Allowed
X-Powered-By-Plesk
X-VARITI-CCR
X-Amz-Rid
X-Fastly-Request-ID
X-Abt-Application-Version
X-Webkit-CSP
X-Client-IP
X-Cache-TTL
X-Pinterest-Rid
Pinterest-Version
Pinterest-Generated-By
Fastly-Restarts
X-Release
SPRequestGuid
X-SharePointHealthScore
X-Cached
X-MSEdge-Ref
X-TTL
X-Dw-Request-Base-Id
X-Element-Page-Cache
SPIisLatency
SPRequestDuration
X-NF-Request-ID
Public-Key-Pins
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
RTSS
Access-Control-Request-Method
X-SRCache-Store-Status
X-SRCache-Fetch-Status
AR-ATIME
AR-PoweredBy
AR-Request-ID
Ar-Sid
X-Edge
AR-CACHE
X-LLID
X-Powered-CMS
X-Ezoic-Cdn
X-Litespeed-Cache
X-Origin-Upstream-Status
Cache-Tag
Content-MD5
X-Upstream
X-Px
Fusion-Content-Source
Fusion-Source
Fusion-Template-Id
Fusion-Content-Id
Fusion-Deployment-Id
Fusion-Component-Id
X-Jurisdiction
X-HP-Webp
X-Ttl
X-Version
S
X-ECACHE
X-MCACHE
X-Mid
X-Recruiting
X-Mg-S
Charset
X-Content-Digest
X-PressLabs-Stats
X-Amz-Server-Side-Encryption
Fastcgi-Cache
X-Kinsta-Cache
X-T
Cache-Tags
MicrosoftSharePointTeamServices
X-Id
Filters
Front-End-Https
X-DynaTrace
X-Content-Security-Policy-Report-Only
X-Logged-In
TCN
X-Debug
Edge-Cache-Tag
X-Accel-Expires
Server-Node
X-Grace
X-Forwarded-Proto
X-Correlation-Id
X-Forwarded-For
Nginx-Cache
TP-Cache
Server-Name
TP-L2-Cache
X-Amzn-Trace-Id
X-Pinterest-Direct
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Surrogate-Key
X-Request-Processing-Time
X-Request-Received
X-XRDS-LOCATION
X-Varnish-Age
X-Yandex-Sdch-Disable
X-B3-Sampled
X-Shield-Request-Id
X-Ser
X-Microsite
X-Request-Handler-Origin-Region
X-Activity-Id
X-AppVersion
X-Hits
X-Az
X-Ruxit-Js-Agent
X-Amz-Replication-Status
X-Fastcgi-Cache
X-HS-Hub-Id
X-F-Cache
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Content-Id
X-DIS-Request-ID
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Storage-Class
X-GUploader-UploadID
X-Goog-Metageneration
X-Origin-Server
Accept-Charset
X-Geo-Country
X-Git-Hash
Alternate-Protocol
X-XRDS-Location
X-Respond-Thread
X-Rid
X-Time
Cache
Section-Io-Cache
X-Frontend
X-FTR-Request-ID
X-LB-Cache
X-Cache-Key
Host
X-Upgrade-Enabled
X-DataDome
Access-Control-Allow-Method
Powered-By-ChinaCache
X-Mobile-URL
X-Server-ID
X-NWS-LOG-UUID
MS-CV
Paypal-Debug-Id
X-Cache-Age
X-TT
X-AOL-HN
X-Seen-By
Healthy
X-VCache
X-Varnish-Backend
X-Type
X-Content-Options
X-Whom
Cleartype
ServerID
X-Hostname
X-IPLB-Instance
X-Flags
X-Is-Crawler
X-Route-Name
X-Request-Guid
X-App-Environment
Payment
X-Providence-Cookie
X-Aspnet-Duration-Ms
X-Cache-Action
X-B-Cache
X-Page-Id
X-Jobs
X-Signature
X-Source
X-Debug-Info
X-WebKit-CSP-Report-Only
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Load-Cache
X-N
X-Daa-Tunnel
Fastcgi-Useragent
X-Mobile
X-FB-Debug
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
Nel
X-Via-JSL
X-RateLimit-Remaining
Refresh
X-Contextid
Realpath
Version
X-Rule
X-Response-Served-From
X-Akamai-Edgescape
X-Original-Request-Id
X-Accel-Buffering
X-Cached-By
X-Proxy
X-Drupal-Cache-Tags
X-Zen-Fury
Node
Ms-Operation-Id
X-Cacheable-TTL
DC
X-Framework
X-RTag
X-ProcessESI
X-Cache-Operation
X-RemovedCookies
Viewport
X-Cache-Rule
X-Instance
X-Cache-Time
X-HTML-Minification-Powered-By
Referer-Policy
Access-Control-Request-Headers
X-B
X-Real-IP
Eomportal-Instance
X-UUID
X-Region
X-Wix-Request-Id
X-Page-View
X-Distributor
X-Tt-Trace-Tag
X-Drupal-Cache-Contexts
X-Tt-Trace-Host
X-Cache-Expired-At
X-Cluster-Name
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Cache-Control
X-FW-Serve
Liferay-Portal
X-FW-Static
X-FW-Server
X-FW-Dynamic
X-Content-Powered-By
X-FW-Type
X-FW-Hash
X-Yottaa-Optimizations
X-Yottaa-Metrics
Countrycode
X-G
X-IPS-LoggedIn
X-Cache-Hit
X-Environment-Context
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-L-Path
DynaTrace
X-Tumblr-User
X-Tumblr-Pixel-1
X-FireWall-Port
X-Pass-Why
Server-Info
X-App-Server
X-Varnish-Ttl
X-User-Agent
X-Ratelimit-Limit
Ec-Rule-Version
GEO-INFO
Xserver
Webserver
Section-Io-Id
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
From-Origin
Section-Origin-Responded
X-Tumblr-Pixel-2
X-Protected-By
X-Node-Name
X-Www-Served-By
SRV
X-Ratelimit-Remaining
CF-IPCountry
Protected
X-Nginx-Cache
X-Cache-Server
X-UPSTREAM-Address
X-Hl-Ver
X-Handled-By
X-ES-SERVER
X-Backend-Name
X-Mode
Meta-Geo
X-Endurance-Cache-Level
X-RN-RSRV
X-Debug-IsConnected
X-Site-Version
Frame-Options
Cache-Tv-Group
X-Uri
X-Debug-IsPreview
X-Locale
X-UA-Device-Type
X-Adobe-Loc
X-Adobe-Content
X-Device-Type
X-FB-TRIP-ID
X-Storage
X-Labrador-Cache-Channel
X-Soup
X-PHP-Host
X-MP-GENERATED-AT
X-Varnishpool
X-Sql-Count
TWC-Locale-Group
TWC-Privacy
TWC-GeoIP-Country
Selected-Fe
TWC-Connection-Speed
TWC-Device-Class
X-BYPASS-REASON
X-Be
Webcakes-App-Version
Webcakes-Region
Webcakes-App-Name
Decoy-Debug-Status
X-ProxyCache-Status
Decoy-Debug-TTL
X-WA-Info
X-Web-Node
X-ProxyCache-Key
Cache-Status
X-OCL
X-Sql-Duration-Ms
X-NYM-Debug-Backend
X-Redis-Cache
X-Request-Time
X-No-Session
X-Pubstack
X-Origin-Date
X-Via-Fastly
X-Hyper-Cache
X-Timing-Wait
Fastly-SSL
X-Proxy-Build
Country
X-Proto
X-PCL
Decoy-Debug-Key
X-Human
Property-Id
X-Origin-Hint
TWC-GeoIP-LatLong
X-Access
X-Section
X-AWS-Id
X-R9-Blue-Green-Version
X-Server-W
X-Forwarded-Host
X-FW-Version
X-Hosted-By
X-Format
Cache-Name
X-Revision
Retry-After
X-LAGOON
Azure-Version
Azure-InstanceId
X-VWS-Id
X-S-Maxage
Azure-RegionName
Azure-SiteName
Azure-SlotName
X-LJ-Flow-ID
X-Cache-Grace
X-Status
X-Storefront-Renderer-Rendered
X-Say-Cacheable
X-Sorting-Hat-ShopId
X-TNCMS
X-TT-LOGID
X-PERF
X-Xfnlog-Site
X-Loop
X-Sorting-Hat-PodId
X-Say-TTL
X-Cache-TTL-Remaining
X-SayCDN-TTL
X-Alternate-Cache-Key
X-CCM
X-ShardId
X-Shopify-Stage
X-ShopId
X-Cluster
X-AIR-PT
X-ApacheServer
Mn-Server-Ip
X-Proxied
X-Zipkin-Id
X-Routing-Service
X-Rendered-As
Apigw-Requestid
X-Qloud-Router
X-Varnish-Grace
X-Is-Bot
X-Amz-Meta-S3cmd-Attrs
AMP-Access-Control-Allow-Source-Origin
X-Dc
S-Cnection
X-Varnish-Server
X-Info
X-Via-CDN
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
Cache-Hits
X-Cdn
X-SRV
X-FTR-DC
X-FTR-Realm
X-FTR-Cache-Status
X-FTR-Balancer
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Backend
X-Cache-Enabled
X-Content-Age
X-GG-Cache-Date
X-FTR-Expires
X-Detected-As
X-Microcachable
X-Platform
X-Cache-Host
X-Proxy-Cache-Status
Uber-Trace-Id
X-Amzn-RequestId
X-Amzn-Remapped-Content-Length
X-Aspnetmvc-Version
X-EdgeConnect-Cache-Status
X-Azure-Ref
X-Amz-Apigw-Id
X-Backend-Host
X-CSRF-Token
Tracecode
X-NWS-UUID-VERIFY
X-Cache-Var
SD-X-WS
X-App-Version
X-Air-Hostname
X-Cache-Var-Map
Akamai-GRN
Amp-Access-Control-Allow-Source-Origin
X-Time-Microsecs
X-ATG-Version
X-DynaTrace-JS-Agent
HostName
X-ServerID
X-Backend-TTL
X-Oss-Storage-Class
X-Oss-Object-Type
X-Trace-Id
X-Oss-Request-Id
X-Tb
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-Unique-Id
X-RCS-CacheZone
X-Correlation-ID
X-Debug-Cache
X-BCube-Filmed-By
ServedBy
X-GEO
X-Cache-PHP
Backend
X-Cache-NGX
X-Varnish-Hostname
X-Cdn-Forward
DSUID
X-Sucuri-ID
X-Cache-Backend
X-B3-SpanId
X-Akamai-Transformed
Rendered-Blocks
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
T-Server
SR-User-Adfree
Release
DCR-Decision-By
Fastcgi-X-Cache-Version
Instruction
Expiry
DCR-Processing-Time-Ms
X-TX-ID
Thinkindot-Control
Lfy
Machine
Odigeo-Trace-Id
Path
Mobile-Detection-Method
Meta-Geo-Continent
DB-Nickname
MD5-Digest
BehaviorPad-Version
X-From
X-Rewrite-Enabled
X-Request-UUID
X-Rojux
X-S
X-S-Cookie
X-Processor
X-PBS-Appsvrname
X-Origin-CC
X-Origin-TTL
X-Owner
X-PAYTM-SRV-ID
X-ScT
X-Session-Fingerprint
X-VG-WebServer
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-VG-WebCache
X-Vdms-Version
X-SRCache-Key
X-Thinkindot-L3
X-Trv-Group
X-Vdms-Path
X-NAPM-TraceId
X-Matched-Rule
X-Application
X-ARC
X-B-Cookie
X-Cache-NE
X-Aed
X-A-Wwc
X-A-Ccd
X-A-Dam
X-A-Dcw
X-A-Dgt
X-CF-Lambda-Version
X-Connection-Hash
X-Generation-Time
X-GeoIP-City
X-Level-Front-Cache
X-Location
X-Generated-On
X-Fetched-On
X-D
X-Destination
X-Device-Os
X-External-Request-Id
X-A
X-CF-Lambda-Fn
X-TA-CDN-Provider
X-Ms-Version
X-CS
X-Magnolia-Registration
X-Ms-Request-Id
X-Mvc-Supplant-Cachable
Host-ID
X-Fastly-Cache
X-Micro-Cache
CacheControlHeader
X-GeoIP
X-NewRelic-App-Data
X-Reqid
C-Via
X-FC-Vary-Parameters
UCS
X-OVcl-Cache
X-OVcl
X-Geo-Header
Fastly-Backend-Name
On-Server
Server-Host
Cf-Device-Type
Content-Disposition
X-B3-Traceid
Gh-Request-Id
AKAMAI
X-HS-Content-Campaign-Id
X-Skip-Cache
X-Tumblr-Pixel-3
Pagetype
NGX
X-Bip
X-Azure-Ref-OriginShield
X-Core-Value
X-CACHE-KEY
X-Cms-Context
X-TrackingId
X-Thanos
X-VServer
X-SVT-ORM-RULES
X-Cache-Bucket
X-SVT-ORM-VERSION
X-Adobe-Source
X-Irp-Debug
X-Varnish-Cache-Hits
User-Cache-Control
X-Is-Gdpr
Server-Hostname
PB-RID
X-Hnp-Log
PFcat
X-IP
X-HN
X-Has-Esi
X-GoCache-CacheStatus
PB-PID
X-Gzip
Server-Ext
V-Age
X-Developer
X-CUA
X-Developers
X-Dispatcher-Server
X-Envoy-Decorator-Operation
X-Csrf-Jwt
X-Backend-State
X-CGP
X-Cache-Info
X-Clara-WADP
X-Branch-Name
X-Block-Status
X-Esi-Check
X-Eu-Site
X-Gen-Mode
X-Fmm-Version
X-Generated-By
Ssr
X-Generated-In
X-JWT-State
X-Fastly-Backend
Wxu-Next-Region
Wxu-Next-Hostname
Wxu-Next-Commit
Web-Mar-Node
Sever-Int
Magicmarker
CDN-CachedAt
CDN-Cache
CDCHOST
Cache-Host
NM-Fastcgi-Cache
CDN-PullZone
CloudFront-Viewer-Country
CDN-Uid
CDN-RequestId
CDN-RequestCountryCode
Arc-Version
X-Request-Host
X-VarnishDD-TTL
X-WADP-Cache
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Varnish-Beresp-Grace
X-Var-Ttl
X-Scheme
X-Swa-Ws
X-User
X-Ratelimit-Reset
CDN-EdgeStorageId
Locid
X-Policy
L5d-Success-Class
X-Nginx-Cache-Key
X-Cache-Id
X-EC-Lua
X-Li-Fabric
X-Li-Pop
X-LI-UUID
HA-Ipaddr
Location
X-Origin
X-Origin-Expires
Ha-Gx-Prefs
X-Old-Content-Length
X-Origin-Response-Time
X-Node-Id
X-APP-VERSION
X-ID
X-Varnish-Remaining-TTL
X-Varnish-Hits
X-Varnish-CookieINHashed-On
X-Clientip
X-Gamma-Serve
X-Cache-Tags
X-LB-ID
X-Cdn-Origin
X-Rebelmouse-Cache-Control
X-VG-TLSProxy
X-Platform-Server
X-Varnish-CookieHashed-On
X-Varnish-Beresp-Status
X-Sn-Servicetimems
X-Slack-Backend
X-Method
X-DPWN-IS-SECURE
X-Hash
X-DefHash
X-Request-URI
X-Rebelmouse-Surrogate-Control
X-Variation
X-DefElseHash
X-Varnish-Beresp-Ttl
X-NU-AKA-ACS-Version
Fastly-SIE
X-Cache-Expires
Adler-Geo
Pramga
Fastly-SWR
Vix-Hermes-Req-Id
Is-Eu
True-Client-Country-4JS
L
Cf-Bgj
X-Kinja-Server-Push
X-Cache-Debug
Platform
X-CLOUD-TRACE-CONTEXT
Origin
Rt-Fastcgi-Cache
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Loc
Apple-News-Services-Host
X-Cache-Date
X-Aicache-OS
IsBot
Fastly-Drupal-HTML
Apple-News-Services-Handled
X-SIPLIST1
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
X-Unique-ID
X-Servername
X-NCache
Esi-Enabled
X-PF-Uncompressing
X-Via-Poph
X-Nc
X-Mvc-Supplant-OutputCached
X-Via-Popv
X-Via-Popn
X-Core-Mission
Sid
X-Erf-Stays-Bingo-Pdp-Web
X-Varnish-Url
Who
X-Request-Start
X-Refresh
Country-Code
Geo-Info
Url
Pics-Label
X-Epic-Correlation-Id
X-FireWall-Protection
X-Tb-Optimization-Total-Bytes-Saved
X-Cache-Remote
X-NC
X-Response-By
Req-Svc-Chain
X-Dynatrace
X-Varnish-Cacheable
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
S-Rt
X-Srv
X-Proxy-Cachei7
X-TraceId
Xkeyi7
X-Error
X-Webkit-Csp
X-RateLimit-Limit
Source
Cmstype
Content-Secure-Policy
X-BBXSRF
N-Cache
Cmsid
Filterid
X-B3-Spanid
X-Webkit-CSP-Report-Only
Kp-EeAlive
GeoIp-Country-Code
Svr
Geoip-Latitude
X-DC
X-HS-Status
Server-Ttl
X-Host-Name
X-Cache-2
X-Served-From
HitType
Cross-Origin-Window-Policy
X-Sucuri-Cache
X-Cc-Req-Id
X-Varnish-Authentication
A
Ohc-File-Size
D-Cc-Upstream
X-Vcl-Version
X-Cc-Via
X-Cache-ASPX
Cteonnt-Length
MIME-Version
X-LiteSpeed-Cache-Control
Tcn
VivaBuild
Viewtype
X-Contensis-Viewer-Groups
X-URL
X-HostName
Cache-Key
M-TraceId
X-Svr
X-Wa
X-Servedbyhost
X-Oracle-Dms-Rid
X-Server-IP
Server-ID
Arc-Country
Cross-Origin-Opener-Policy
TDXMobile
NGB
X-Li-Proto
X-Esi
CACHE
SID
NtCoent-Length
X-CDN-Forward
X-Vgn-Hpd-Reason
X-Origin-Time
X-Gdpr
X-FPC
X-Nyt-Route
X-API-Version
X-Cache-Config
X-LI-Proto
X-Air-Source
X-RAMCache
X-Cs
X-HOST
X-VC
Request-ID
X-Check-Cacheable
X-Vc
Resin-Trace
X-SN
X-UA
X-Geo
X-DB
X-DSS
X-RSL
X-RPS
X-Webstats-RespID
X-DI
X-Viewer-Country
X-WA
X-RPM
X-SB
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-TIM-N
X-Service
X-ServedByHost
X-DW
Server-Id
X-Internal-Host
X-VCL-Version
X-Newrelic-Synthetics
X-NodeID
Cache-Provider
DataCenter
X-NGENIX-Cache
X-SaId
X-JoinUs
Hostname
Ohc-Cache-HIT
X-PHP-Backend
X-SD-PageType
GeoIP-Country-Code
GeoIP-Latitude
X-Edge-Location
Srv
Mime-Version
X-NGINX-Cache
XServer
X-Action
X-App
X-Forwarded-Site
X-Via-NSCOPI
X-Extlb
X-BBC-Edge-Cache-Status
X-Render-Time
FSS-Cache
ProcessTime
X-FTR-Cache-Host
CF-Cached-On
X-Oss-Cdn-Auth
X-Fpc
X-CF-Powered-By
EpKe-Alive
X-Bc-Bl
X-Provided-By
X-Ua
X-Dynatrace-Js-Agent
Mail-Subject
X-FORWARDED-FOR
Processtime
W
X-Proxy-Upstream
X-Req
X-Auto-Login
LB
X-Worker
X-Depends-On
We-Hiring
Surrogated-Key
Memcached
X-Accel-Expires-Debug
Upgrade-Insecure-Requests
X-Date
X-PJAX-URL
X-Region-Sid
X-HITS
X-Cdn-Request-ID
X-Swift-Error
X-MSEdge-Features
X-MSEdge-Flight
CDN
X-BACKEND-TTL
X-ZONE
X-CSRF-TOKEN
X-Cluster-Node
X-Ftr-Cache-Host
X-TIME
X-Dw-Trace-Id
Cdn
X-RateLimit-Remaining-Second
X-Fastly-Backend-Reqs
X-UnsetCookies
Proxy-Connection
X-VC-Cache
Env
X-APP
X-RateLimit-Limit-Second
X-Client-Ip
X-CACHE-AGE
X-Rocket-Build-Number
X-Flog
X-Hello
X-ABtesting
Datacenter
X-Sigma-Backend
X-Parent-Response-Time
Time
X-Sigma
Dnion-Transfer-Encoding
Memory
X-Cache-Tag
X-BBC-Origin-Response-Status
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-Men
X-Fastly-Request-Id
PICS-Label
X-Akamai-Pragma-Client-IP
Cf-Ipcountry
X-Acquia-Purge-Tags
X-Acquia-Application-Trace
Media-Length
X-Acquia-Application-UUID
X-Acquia-Site
X-Zone
X-Pf-Uncompressing
X-Presslabs-Stats
X-Air-Trace-Id
X-Pad
Vha6-Origin
X-Oracle-DMS-ECID
CPC-Age
VNS-Age
X-LiteSpeed-Tag
Epwk-X-Cache
X-Via-PopH
X-Via-PopN
VNS-Cache
OT-Force-Account-Verify
CPC-Cache
X-Via-PopV
X-Varnish-URL
X-Snapshot-Date
X-ElasticPress-Query
WZWS-RAY
X-Varnish-Beresp-TTL
X-MiniProfiler-Ids
X-ServerName
X-Request-Url
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-ND-Cache
X-Vcache
X-Csrf-Token
X-Request-URL
X-Lb-Id
X-Ms-Meta-Staticbatchstarttime
X-ElasticPress-Search
Xet-Cookie
X-Ms-Meta-Originalurl
CountryCode
X-Amz-Meta-Cb-Modifiedtime
X-Litespeed-Cache-Control
My-App
State
Fastcgi-Cache-TTL
Content-Style-Type
Content-Script-Type
Phost
X-Tid
NnCoection
Environment
X-Redis-Count
X-Redis-Duration-Ms
X-Traceid
X-B3-Parentspanid
Ohc-Response-Time
X-Debug-Cache-Fetch
URI
X-Storefront-Renderer-Verified
X-Debug-Cache-Store
Inserted-Into-Cache-At
X-C