Threat Level: green Handler on Duty: Jim Clausing

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
X-XSS-Protection
CF-RAY
Cf-Request-Id
CF-Cache-Status
Last-Modified
Accept-Ranges
Link
Pragma
Expect-CT
ETag
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Cache-Status
X-Generator
X-Request-ID
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Content-Security-Policy
Content-Encoding
X-CDN
X-Envoy-Upstream-Service-Time
Status
X-Ua-Compatible
Feature-Policy
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-AspNetMvc-Version
Access-Control-Max-Age
X-Xss-Protection
X-Via
Upgrade
Keep-Alive
X-Ws-Request-Id
X-Age
X-Turbo-Charged-By
X-AH-Environment
X-Robots-Tag
Request-Context
X-Proxy-Cache
EagleId
X-Cache-Group
X-Backend
Server-Timing
X-Hacker
X-Amz-Request-Id
Report-To
X-Server
Host-Header
X-Amz-Id-2
X-Server-Powered-By
X-UA-Device
Grace
X-Nginx-Cache-Status
X-Dns-Prefetch-Control
X-LiteSpeed-Cache
X-Varnish-Cache
X-Rq
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Swift-SaveTime
X-Page-Speed
Cf-Railgun
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
NEL
X-Amz-Version-Id
X-OneAgent-JS-Injection
Xkey
X-WebKit-CSP
X-Cache-Spec
Allow
X-Backend-Server
X-Host
X-Vhost
X-CST
X-Device
EagleEye-TraceId
X-Server-Id
Surrogate-Control
Request-Id
X-Dispatcher
Accept-CH
X-Node
X-Kinja-Server-Push
Content-Location
X-Response-Time
Accept-CH-Lifetime
X-Akam-SW-Version
X-Ruxit-JS-Agent
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-ASPNET-VERSION
X-Template
X-Language
X-Ac
X-Application-Context
X-Readtime
X-Country
X-Cloud-Trace-Context
X-Cache-Lookup
X-Mod-Pagespeed
MS-Author-Via
X-Origin-Cache
X-B3-TraceId
Rating
X-Cnection
X-MS-InvokeApp
X-HW
X-ORACLE-DMS-ECID
X-PC
X-TtlSet
X-Vname
Accept-Ch
X-Clacks-Overhead
X-Url
X-FastCGI-Cache
Edge-Control
X-GitHub-Request-Id
X-ESI
Accept-Ch-Lifetime
X-Trace
Response
Display
Pagespeed
X-Middleton-Display
X-Middleton-Response
X-Sol
X-Content-Type
X-D2id
X-Buckets
Arr-Disable-Session-Affinity
X-Vcap-Request-Id
Verso
X-Kinja-Revision
X-GoogleNews-Bot
X-Exp-Variant
X-Kinja-Server
X-Kinja-Build
X-Use-Magma
X-Kinja
X-Cdn-Fetch
X-Exp-Id
X-Goog-Hash
X-Varnish-TTL
X-Server-Name
X-Rack-Cache
Service-Worker-Allowed
X-Country-Code
X-Navigation-Version
X-Abt-Application-Version
X-VARITI-CCR
X-Amz-Rid
X-Oneagent-Js-Injection
X-ORACLE-DMS-RID
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
X-Cache-TTL
X-Powered-By-Plesk
X-Client-IP
X-TTL
X-SharePointHealthScore
SPRequestGuid
X-Fastly-Request-ID
SPIisLatency
SPRequestDuration
X-Release
X-MSEdge-Ref
X-Dw-Request-Base-Id
X-Element-Page-Cache
Fastly-Restarts
X-NF-Request-ID
X-Cached
X-B3-TraceId-Primal
MRF-Tech
Public-Key-Pins
Mrf-Cache-Status
RTSS
X-Origin-Upstream-Status
AR-Request-ID
AR-CACHE
AR-ATIME
X-Px
Ar-Sid
AR-PoweredBy
X-SRCache-Store-Status
X-Edge
X-SRCache-Fetch-Status
X-Webkit-CSP
X-LLID
Fusion-Template-Id
Access-Control-Request-Method
Fusion-Source
Fusion-Component-Id
Fusion-Content-Id
Fusion-Deployment-Id
Fusion-Content-Source
X-Powered-CMS
X-Upstream
Content-MD5
X-Ezoic-Cdn
X-Pinterest-Direct
X-HP-Webp
X-Jurisdiction
X-Amz-Server-Side-Encryption
X-ECACHE
X-Recruiting
X-MCACHE
X-Mid
Charset
X-Content-Digest
X-Mg-S
S
X-Ttl
Cache-Tag
X-Aspnetmvc-Version
MicrosoftSharePointTeamServices
X-Version
TCN
X-PressLabs-Stats
X-Debug
Front-End-Https
Fastcgi-Cache
X-XRDS-Location
X-T
X-Grace
X-Content-Security-Policy-Report-Only
Cache-Tags
X-Kinsta-Cache
Edge-Cache-Tag
Filters
Server-Node
X-Forwarded-Proto
X-Yandex-Sdch-Disable
X-Cache-Key
X-Correlation-Id
X-Accel-Expires
X-Amzn-Trace-Id
X-Id
X-Logged-In
Server-Name
Nginx-Cache
X-Varnish-Age
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Surrogate-Key
Powered-By-ChinaCache
X-Forwarded-For
X-DynaTrace
X-B3-Sampled
TP-L2-Cache
X-Hits
TP-Cache
X-DIS-Request-ID
X-Request-Received
X-Request-Processing-Time
X-Microsite
X-Request-Handler-Origin-Region
X-Ser
X-Shield-Request-Id
X-Activity-Id
X-Server-ID
X-AppVersion
X-Amz-Replication-Status
X-Az
X-HS-Combine-CSS
X-F-Cache
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Content-Id
X-FTR-Request-ID
Accept-Charset
X-Goog-Metageneration
X-Goog-Generation
X-GUploader-UploadID
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Origin-Server
X-Git-Hash
X-Respond-Thread
X-Hostname
X-Litespeed-Cache
X-Geo-Country
X-DataDome
Section-Io-Cache
X-LB-Cache
X-Upgrade-Enabled
X-Rid
X-Frontend
X-Cache-Age
X-Mobile-URL
Cleartype
Host
Access-Control-Allow-Method
Paypal-Debug-Id
Healthy
X-Type
Alternate-Protocol
X-TEC-API-VERSION
X-Content-Options
Cache
X-TEC-API-ROOT
ServerID
X-TEC-API-ORIGIN
X-AOL-HN
X-Ruxit-Js-Agent
X-IPLB-Instance
MS-CV
X-App-Environment
X-Varnish-Backend
X-Providence-Cookie
X-Is-Crawler
X-B-Cache
X-Flags
X-Debug-Info
X-Whom
X-Cache-Action
X-Signature
X-WebKit-CSP-Report-Only
X-Route-Name
X-Aspnet-Duration-Ms
X-Request-Guid
X-TT
X-Seen-By
X-VCache
Payment
Fastcgi-Useragent
X-Erf-Bev-Bev-Is-Generated
X-Jobs
X-Erf-Bev-Bev
X-Page-Id
X-Mobile
X-Source
X-N
X-NWS-LOG-UUID
X-Load-Cache
X-RateLimit-Remaining
X-Browser-Type
X-XRDS-LOCATION
X-Cached-By
X-Via-JSL
X-Akamai-Edgescape
Version
X-Time
X-FB-Debug
Nel
DynaTrace
Viewport
X-Cache-Rule
X-Daa-Tunnel
X-Cache-Operation
X-Response-Served-From
X-Original-Request-Id
X-Accel-Buffering
X-Drupal-Cache-Tags
X-Proxy
X-Rule
X-Zen-Fury
Realpath
Refresh
DC
X-ProcessESI
X-Instance
X-RemovedCookies
X-Tt-Trace-Tag
X-Cacheable-TTL
X-Framework
X-Tt-Trace-Host
Referer-Policy
GEO-INFO
X-Fastcgi-Cache
X-Region
X-RTag
X-Contextid
Access-Control-Request-Headers
X-UUID
X-HTML-Minification-Powered-By
X-Real-IP
X-Cache-Time
Ms-Operation-Id
X-FW-Hash
X-FW-Serve
X-FW-Dynamic
X-Drupal-Cache-Contexts
X-Environment-Context
X-FW-Server
X-FW-Static
X-L-Path
X-Page-View
X-Distributor
X-FW-Type
X-Node-Name
X-Wix-Request-Id
X-Cache-Expired-At
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-B
Eomportal-Instance
Node
Liferay-Portal
X-Cluster-Name
X-Tumblr-User
X-Tumblr-Pixel
X-G
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Cache-Control
X-IPS-LoggedIn
X-Content-Powered-By
X-Cache-Hit
Countrycode
X-User-Agent
X-Amz-Meta-S3cmd-Attrs
X-Tumblr-Pixel-2
SRV
Webserver
Section-Io-Origin-Time-Seconds
Server-Info
Section-Origin-Responded
Section-Io-Id
Section-Io-Origin-Status
Protected
From-Origin
X-App-Server
X-Revision
X-Pass-Why
X-Ratelimit-Limit
X-Protected-By
Ec-Rule-Version
X-Cache-Server
Frame-Options
Cache-Status
X-FireWall-Port
X-Oracle-Dms-Rid
X-Backend-Name
X-Hyper-Cache
X-UPSTREAM-Address
Retry-After
X-RN-RSRV
Meta-Geo
X-Handled-By
X-Mode
X-ES-SERVER
X-Endurance-Cache-Level
X-Site-Version
X-Soup
X-Forwarded-Host
X-Locale
X-NYM-Debug-Backend
CF-IPCountry
X-Adobe-Content
X-Storage
X-FB-TRIP-ID
X-Adobe-Loc
Decoy-Debug-TTL
X-Origin-Hint
Fastly-SSL
X-Format
X-Human
X-Cache-Grace
X-Be
Webcakes-App-Version
X-Pubstack
TWC-GeoIP-LatLong
Decoy-Debug-Status
X-Access
TWC-Connection-Speed
TWC-Locale-Group
X-Via-CDN
X-Www-Served-By
Webcakes-Region
X-Web-Node
TWC-Privacy
Cache-Tv-Group
Property-Id
X-Section
Decoy-Debug-Key
Webcakes-App-Name
TWC-GeoIP-Country
Country
TWC-Device-Class
X-OCL
X-Labrador-Cache-Channel
X-Origin-Date
X-PCL
X-PERF
X-Hl-Ver
X-FW-Version
Azure-SiteName
Azure-RegionName
Azure-SlotName
Azure-Version
X-ApacheServer
Azure-InstanceId
X-PHP-Host
X-SayCDN-TTL
X-UA-Device-Type
X-TT-LOGID
X-Say-TTL
X-Say-Cacheable
X-Redis-Cache
X-Varnishpool
X-Uri
X-Via-Fastly
X-AIR-PT
Cache-Name
X-BYPASS-REASON
X-Server-W
X-S-Maxage
X-Proto
X-ProxyCache-Key
X-Varnish-Ttl
X-No-Session
X-Sql-Count
X-ProxyCache-Status
X-Sql-Duration-Ms
X-LAGOON
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-Realm
X-FTR-DC
S-Cnection
X-Country-Code-Real
X-Loop
X-LJ-Flow-ID
X-Hosted-By
X-AWS-Id
X-Qloud-Router
X-Status
X-WA-Info
X-VWS-Id
X-TNCMS
Mn-Server-Ip
X-R9-Blue-Green-Version
X-Request-Time
Selected-Fe
X-Proxy-Build
X-Cluster
X-FTR-Expires
X-Timing-Wait
X-Cache-TTL-Remaining
X-Routing-Service
X-Zipkin-Id
X-Proxied
X-CCM
Cache-Hits
X-Xfnlog-Site
X-ShardId
X-MP-GENERATED-AT
X-Storefront-Renderer-Rendered
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Alternate-Cache-Key
X-ShopId
X-Shopify-Stage
X-Ratelimit-Remaining
X-Cache-Var-Map
X-Is-Bot
X-Cache-Var
X-Rendered-As
X-Air-Hostname
X-Dynatrace
X-Unique-Id
X-SRV
Xserver
X-Detected-As
AMP-Access-Control-Allow-Source-Origin
X-Amzn-Remapped-Content-Length
X-Cache-Host
X-Amz-Apigw-Id
X-EdgeConnect-Cache-Status
X-Amzn-RequestId
Apigw-Requestid
X-Webkit-Csp
X-Info
X-Cdn
X-Device-Type
X-Microcachable
X-Nginx-Cache
SD-X-WS
X-B3-Traceid
X-Cache-Enabled
X-Dc
X-GEO
X-Content-Age
X-Time-Microsecs
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
X-Debug-IsPreview
X-Cache-Backend
Amp-Access-Control-Allow-Source-Origin
X-Backend-TTL
Tracecode
X-Varnish-Server
X-ID
X-Debug-IsConnected
X-Varnish-Grace
X-APP-VERSION
X-Azure-Ref
X-DynaTrace-JS-Agent
X-Platform
X-ServerID
X-Backend-Host
Uber-Trace-Id
X-Erf-Stays-Bingo-Pdp-Web
X-GG-Cache-Date
X-Oss-Request-Id
X-Oss-Storage-Class
DSUID
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Sucuri-ID
Akamai-GRN
X-Tb
X-Oss-Server-Time
X-BCube-Filmed-By
X-Proxy-Cache-Status
X-ATG-Version
X-NewRelic-App-Data
Backend
X-Trace-Id
X-Correlation-ID
Arc-Version
PB-RID
PB-PID
X-Akamai-Transformed
X-Origin-Response-Time
DCR-Processing-Time-Ms
Path
X-Session-Fingerprint
Thinkindot-CacheControl-Type
X-A-Dam
Thinkindot-CacheControl
T-Server
DCR-Decision-By
X-Varnish-Cache-Hits
Pramga
X-Thinkindot-L3
X-A
Rendered-Blocks
SR-User-Adfree
Expiry
X-A-Ccd
X-ScT
X-A-Dcw
X-Application
Thinkindot-Control
X-ARC
X-Aed
Meta-Geo-Continent
X-Cache-NE
ServedBy
X-RCS-CacheZone
X-B-Cookie
X-A-Wwc
X-A-Dgt
Machine
Odigeo-Trace-Id
Mobile-Detection-Method
Instruction
Fastcgi-X-Cache-Version
MD5-Digest
Xc-Version
X-VG-WebServer
X-External-Request-Id
X-Fetched-On
X-From
X-SRCache-Key
X-Request-UUID
X-Device-Os
X-Vtex-Processado-Em
X-Destination
X-Rojux
X-Rewrite-Enabled
X-Generation-Time
X-VG-WebCache
X-PAYTM-SRV-ID
X-Vdms-Path
X-PBS-Appsvrname
X-Processor
X-Origin-TTL
X-Origin-CC
X-Vdms-Version
X-Level-Front-Cache
X-Location
X-Matched-Rule
X-Vtex-Remote-Cache
X-Generated-On
X-S
X-D
X-URL
X-CF-Lambda-Version
X-Connection-Hash
X-CF-Lambda-Fn
X-Cache-Remote
X-Trv-Group
X-S-Cookie
X-Adobe-Source
X-Magnolia-Registration
X-Varnish-Hostname
X-Owner
X-Node-Id
Locid
X-Sn-Servicetimems
X-OVcl
Magicmarker
X-OVcl-Cache
X-Cdn-Origin
X-Cache-Date
X-Cache-Info
X-Tumblr-Pixel-3
X-Swa-Ws
Cf-Device-Type
CacheControlHeader
X-User
Fastly-Backend-Name
L
Lfy
Pagetype
X-VarnishDD-TTL
Host-ID
X-Cache-Bucket
X-JWT-State
Wxu-Next-Hostname
X-Wikidot-Static-Cache
X-Azure-Ref-OriginShield
X-Backend-State
Wxu-Next-Region
X-Skip-Cache
X-VServer
X-Wikidot-Backend
X-Developers
Cache-Host
X-Geo-Header
X-GeoIP
X-HS-Content-Campaign-Id
X-Is-Gdpr
BehaviorPad-Version
PFcat
X-HN
Ssr
X-Has-Esi
X-Request-URI
X-Reqid
X-Micro-Cache
Wxu-Next-Commit
CACHE
AKAMAI
X-Cache-NGX
DB-Nickname
X-Cache-PHP
X-CSRF-Token
X-Ms-Request-Id
X-Ms-Version
X-Debug-Cache
X-Core-Value
X-Csrf-Jwt
On-Server
X-NC
X-Envoy-Decorator-Operation
X-Developer
X-Cms-Context
X-CUA
User-Cache-Control
Server-Hostname
Server-Host
Server-Ext
Sever-Int
V-Age
X-Bip
X-Eu-Site
X-CGP
X-Fastly-Cache
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Scheme
C-Via
X-Thanos
X-Var-Ttl
X-GeoIP-City
UCS
Release
X-Varnish-Hits
X-NWS-UUID-VERIFY
X-Origin-Expires
X-Generated-In
X-Generated-By
X-FC-Vary-Parameters
NGX
X-IP
X-Irp-Debug
X-Nginx-Cache-Key
X-Mvc-Supplant-Cachable
X-Method
X-Fastly-Backend
X-Request-Start
Content-Disposition
CloudFront-Viewer-Country
Cf-Bgj
Apple-News-Services-Handled
HA-Ipaddr
Gh-Request-Id
Ha-Gx-Prefs
L5d-Success-Class
Apple-News-Services-Host
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
CDCHOST
X-Varnish-Beresp-Grace
X-Branch-Name
X-Block-Status
X-Gzip
X-Cache-Expires
X-Cache-Id
X-Hnp-Log
X-Cache-Debug
X-Li-Fabric
X-VG-TLSProxy
X-NU-AKA-ACS-Version
X-Varnish-Remaining-TTL
X-Loc
X-Li-Pop
X-LI-UUID
X-GoCache-CacheStatus
X-Cache-Tags
X-Dispatcher-Server
X-DPWN-IS-SECURE
Fastly-SWR
NM-Fastcgi-Cache
X-DefHash
X-TrackingId
Platform
Fastly-SIE
X-Fmm-Version
X-Gen-Mode
Adler-Geo
X-Esi-Check
X-Clientip
X-Clara-WADP
X-Old-Content-Length
Origin
X-Servername
X-SIPLIST1
True-Client-Country-4JS
X-Origin
Vix-Hermes-Req-Id
IsBot
X-TX-ID
X-Variation
Rt-Fastcgi-Cache
X-Varnish-CookieINHashed-On
Location
X-Varnish-CookieHashed-On
X-B3-Spanid
Web-Mar-Node
X-Request-Host
X-Platform-Server
X-Policy
X-WADP-Cache
Is-Eu
X-DefElseHash
X-Rebelmouse-Cache-Control
X-Ratelimit-Reset
X-Rebelmouse-Surrogate-Control
X-Host-Name
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Status
CDN-Cache
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Hash
X-NCache
CDN-Uid
CDN-PullZone
X-Gamma-Serve
CDN-RequestCountryCode
X-CS
X-Varnish-Url
Fastly-Drupal-HTML
CDN-RequestId
X-Slack-Backend
CDN-CachedAt
CDN-EdgeStorageId
X-App-Version
Url
X-Refresh
X-Response-By
S-Rt
X-Varnish-Cacheable
X-NAPM-TraceId
X-Core-Mission
HostName
X-EC-Lua
X-PF-Uncompressing
X-Proxy-Cachei7
X-Aicache-OS
Pics-Label
Xkeyi7
Cross-Origin-Window-Policy
X-CDN-Forward
Content-Secure-Policy
X-Sucuri-Cache
X-BBXSRF
X-CACHE-GROUP
N-Cache
X-Mvc-Supplant-OutputCached
X-Cdn-Forward
X-Cache-2
X-B3-SpanId
Ohc-File-Size
X-Cc-Req-Id
X-FireWall-Protection
X-LB-ID
X-Contensis-Viewer-Groups
X-Via-Poph
X-Via-Popn
X-Via-Popv
X-Varnish-Authentication
D-Cc-Upstream
Cteonnt-Length
X-Cc-Via
X-Cache-ASPX
Sid
X-TIME
X-DC
MIME-Version
X-Tb-Optimization-Total-Bytes-Saved
X-Servedbyhost
Esi-Enabled
X-Svr
X-Wa
X-RateLimit-Limit
X-Error
X-Epic-Correlation-Id
X-Esi
XServer
Source
X-TA-CDN-Provider
X-Server-IP
Hostname
X-Srv
X-Unique-ID
X-Origin-Time
X-Gdpr
X-Nyt-Route
GeoIp-Country-Code
X-API-Version
X-FPC
Geoip-Latitude
X-Cache-Config
X-Cs
X-Webkit-CSP-Report-Only
X-LI-Proto
Who
X-SN
HitType
Req-Svc-Chain
X-Nc
X-TraceId
X-VC
Ohc-Cache-HIT
X-SB
X-Webstats-RespID
Country-Code
Server-Ttl
X-NodeID
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
Server-ID
X-Planisys-CDN-TTL
X-VCL-Version
X-Fastly-Request-Id
X-NGINX-Cache
X-SD-PageType
X-LiteSpeed-Cache-Control
X-Check-Cacheable
X-HS-Status
Geo-Info
SID
X-Ua
Cmstype
Cmsid
Svr
Kp-EeAlive
X-Render-Time
EpKe-Alive
X-Viewer-Country
X-BBC-Edge-Cache-Status
Viewtype
VivaBuild
X-Served-From
X-Vgn-Hpd-Reason
X-CSRF-TOKEN
NtCoent-Length
X-HOST
X-Auto-Login
X-RAMCache
A
Request-ID
Cache-Key
X-Worker
X-Ftr-Cache-Host
X-Dynatrace-Js-Agent
X-UA
X-TIM-N
X-Hcs-Proxy-Type
X-CACHE-KEY
X-CCDN-Origin-Time
X-DSS
X-RPM
X-DW
X-Vcl-Version
Cache-Provider
X-RSL
X-RPS
Resin-Trace
X-DB
ProcessTime
M-TraceId
X-DI
X-CCDN-CacheTTL
Upgrade-Insecure-Requests
X-Air-Source
TDXMobile
CDN
Server-Id
X-CF-Powered-By
X-Cluster-Node
GeoIP-Country-Code
Arc-Country
GeoIP-Latitude
X-Li-Proto
X-FORWARDED-FOR
X-App
Cross-Origin-Opener-Policy
X-Newrelic-Synthetics
Datacenter
X-Action
Processtime
X-Internal-Host
X-FTR-Cache-Host
X-Fpc
X-Vc
X-COUNTRY
Filterid
X-Oss-Cdn-Auth
Tcn
X-CLOUD-TRACE-CONTEXT
OT-Force-Account-Verify
X-Presslabs-Stats
CF-Cached-On
WZWS-RAY
Mime-Version
Srv
X-BBC-Origin-Response-Status
X-WA
X-Geo
X-Service
X-ServedByHost
X-HostName
X-HITS
X-Hello
Cdn
X-Dw-Trace-Id
X-MSEdge-Flight
X-ABtesting
X-MSEdge-Features
X-Flog
X-Via-PopN
X-Via-PopH
X-Via-PopV
X-Lb-Id
X-Pinterest-Sli-Latency-Threshold
X-ND-Cache
NGB
X-BACKEND-TTL
X-Pinterest-Sli-Response-Type
X-Cache-Tag
X-Fastly-Backend-Reqs
Proxy-Connection
X-Parent-Response-Time
X-Pinterest-Sli-Endpoint-Name
X-CACHE-AGE
X-Client-Ip
X-IN-APIGATEWAYSSL
W
X-Via-NSCOPI
FSS-Cache
X-IN-APIGATEWAY
Dnion-Transfer-Encoding
X-JoinUs
X-Cdn-Request-ID
X-SaId
X-Edge-Location
Vha6-Origin
X-Extlb
X-Oracle-DMS-ECID
Media-Length
X-Forwarded-Site
DataCenter
URI
X-Pf-Uncompressing
X-NGENIX-Cache
PICS-Label
X-PHP-Backend
CountryCode
X-Acc-Rdl
X-Acc-Debug-Context
X-LiteSpeed-Tag
X-Accel-Expires-Debug
X-Bc-Bl
X-Depends-On
X-Date
We-Hiring
X-Akamai-Request-ID
Memcached
Inserted-Into-Cache-At
X-MiniProfiler-Ids
Epwk-X-Cache
LB
X-Pad
Mail-Subject
Surrogated-Key
X-Akamai-Pragma-Client-IP
X-Region-Sid
X-Req
X-Provided-By
X-VC-Cache
X-RateLimit-Remaining-Second
X-UnsetCookies
X-Request-URL
X-Proxy-Upstream
X-PJAX-URL
X-RateLimit-Limit-Second
Cf-Ipcountry
X-Sigma-Backend
X-Acquia-Application-Trace
X-Tid
X-Sigma
Env
Edge-Copy-Time
X-Rocket-Build-Number
X-Request-Url
X-Acquia-Application-UUID
X-Varnish-Beresp-TTL
X-Csrf-Token
X-Acquia-Site
X-Akamai-ERRuleID
X-B3-Parentspanid
X-Akamai-ERPolicy
X-ElasticPress-Query
Content-Script-Type
X-Traceid
X-ElasticPress-Search
X-Ms-Meta-Staticbatchstarttime
X-Acquia-Purge-Tags
X-Vcache
X-Via-SSL
X-Via-Edge
X-Ms-Meta-Originalurl
Content-Style-Type
X-Swift-Error
X-ZONE
X-APP
X-Snapshot-Date
X-Varnish-URL
Environment
X-Redis-Duration-Ms
X-Zone
X-Redis-Count
X-Debug-Cache-Fetch
Xet-Cookie
NnCoection
X-C
Ohc-Response-Time
Phost
Memory
Time
X-Debug-Cache-Store
Akamai-Age-Ms
X-Litespeed-Cache-Control
X-ServerName
X-Storefront-Renderer-Verified