Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
X-XSS-Protection
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
P3P
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-UA-Compatible
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
X-Request-Id
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Xss-Protection
X-Cache-Status
X-Generator
X-Cacheable
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Request-ID
X-Content-Security-Policy
X-Iinfo
X-Ua-Compatible
Content-Encoding
X-CDN
X-AspNetMvc-Version
Feature-Policy
Status
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Upgrade
X-Via
Access-Control-Max-Age
Keep-Alive
X-Ws-Request-Id
X-Age
X-Robots-Tag
X-AH-Environment
X-Turbo-Charged-By
Request-Context
EagleId
X-Cache-Group
X-Proxy-Cache
Server-Timing
X-Backend
X-Server
X-Hacker
Host-Header
Report-To
X-Server-Powered-By
X-Dns-Prefetch-Control
X-Amz-Request-Id
X-Nginx-Cache-Status
X-Amz-Id-2
Grace
X-UA-Device
X-Rq
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
P3p
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Page-Speed
Cf-Railgun
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
X-Amz-Version-Id
X-Device
NEL
X-Cache-Spec
X-CST
X-WebKit-CSP
X-Vhost
Allow
X-Host
X-Backend-Server
X-Server-Id
Xkey
EagleEye-TraceId
X-Dispatcher
Surrogate-Control
X-Node
Request-Id
X-Response-Time
Content-Location
X-Akam-SW-Version
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Ruxit-JS-Agent
Accept-Ch
Accept-Ch-Lifetime
X-ASPNET-VERSION
X-Application-Context
X-Cache-Lookup
X-Ac
X-Country
X-Mod-Pagespeed
X-Template
Accept-CH
X-Readtime
X-Language
X-B3-TraceId
MS-Author-Via
X-Cloud-Trace-Context
Rating
X-HW
X-Url
Accept-CH-Lifetime
X-Cnection
X-Origin-Cache
X-MS-InvokeApp
X-Vname
X-PC
X-TtlSet
Edge-Control
X-Clacks-Overhead
X-ESI
X-GitHub-Request-Id
X-Trace
X-Varnish-TTL
X-ORACLE-DMS-RID
Display
X-Sol
X-Middleton-Response
X-Middleton-Display
Response
Pagespeed
X-Content-Type
X-D2id
X-ORACLE-DMS-ECID
Verso
Arr-Disable-Session-Affinity
X-GoogleNews-Bot
X-Vcap-Request-Id
X-Exp-Id
X-Kinja
X-Cdn-Fetch
X-Exp-Variant
X-Kinja-Build
X-Kinja-Server
X-Kinja-Revision
X-Use-Magma
X-Country-Code
X-Rack-Cache
X-Goog-Hash
X-Powered-By-Plesk
X-Navigation-Version
X-VARITI-CCR
Service-Worker-Allowed
X-Server-Name
X-Amz-Rid
X-TTL
X-Fastly-Request-ID
X-Oneagent-Js-Injection
X-Abt-Application-Version
X-Buckets
X-Client-IP
Fastly-Restarts
X-Cached
X-Cache-TTL
X-MSEdge-Ref
X-Release
X-Element-Page-Cache
X-Dw-Request-Base-Id
X-FastCGI-Cache
SPRequestGuid
X-SharePointHealthScore
X-NF-Request-ID
Pinterest-Version
Pinterest-Generated-By
SPRequestDuration
X-Pinterest-Rid
SPIisLatency
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
Access-Control-Request-Method
Public-Key-Pins
RTSS
Cache-Tag
X-Webkit-CSP
AR-CACHE
AR-ATIME
AR-Request-ID
AR-PoweredBy
Ar-Sid
X-Edge
X-LLID
X-Ezoic-Cdn
X-Powered-CMS
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Upstream
X-Litespeed-Cache
Content-MD5
X-Version
X-HP-Webp
X-Jurisdiction
X-Origin-Upstream-Status
S
X-Recruiting
X-Mid
X-ECACHE
X-MCACHE
Charset
Fusion-Template-Id
Fusion-Content-Id
X-Mg-S
Fusion-Content-Source
Fusion-Component-Id
Fusion-Source
Fusion-Deployment-Id
X-DynaTrace
X-PressLabs-Stats
X-Kinsta-Cache
X-Content-Digest
X-Px
X-Fastcgi-Cache
X-Ruxit-Js-Agent
X-T
Cache-Tags
Fastcgi-Cache
X-Ttl
X-Id
X-Amz-Server-Side-Encryption
X-Logged-In
X-Accel-Expires
Filters
X-Forwarded-Proto
X-Content-Security-Policy-Report-Only
Edge-Cache-Tag
Server-Node
Front-End-Https
MicrosoftSharePointTeamServices
TP-L2-Cache
TP-Cache
X-Correlation-Id
Server-Name
X-Forwarded-For
X-Grace
Nginx-Cache
X-XRDS-LOCATION
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Request-Processing-Time
X-Hits
X-Request-Received
TCN
X-Amzn-Trace-Id
X-Debug
X-B3-Sampled
X-Shield-Request-Id
X-Microsite
X-Request-Handler-Origin-Region
X-Varnish-Age
X-Az
X-Activity-Id
X-AppVersion
X-Yandex-Sdch-Disable
Surrogate-Key
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Cache-Config
X-F-Cache
X-Amz-Replication-Status
X-HS-Hub-Id
Alternate-Protocol
X-Origin-Server
X-Ser
X-Goog-Metageneration
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-DIS-Request-ID
Accept-Charset
X-Frontend
X-Rid
X-Geo-Country
Host
Nel
X-Git-Hash
X-NWS-LOG-UUID
Section-Io-Cache
X-Respond-Thread
X-XRDS-Location
X-Time
X-Cache-Age
X-Upgrade-Enabled
Access-Control-Allow-Method
X-LB-Cache
X-Mobile-URL
X-VCache
X-DataDome
X-Pinterest-Direct
X-Seen-By
MS-CV
Paypal-Debug-Id
ServerID
X-IPLB-Instance
X-Type
X-Source
X-AOL-HN
X-Varnish-Backend
X-Content-Options
Healthy
X-TT
X-Hostname
Payment
X-App-Environment
X-Aspnet-Duration-Ms
X-Flags
X-Daa-Tunnel
X-Is-Crawler
X-Providence-Cookie
X-Whom
X-Request-Guid
X-Route-Name
X-Server-ID
X-Signature
Cleartype
X-B-Cache
X-Page-Id
X-Cache-Action
X-Debug-Info
X-FTR-Request-ID
X-RateLimit-Remaining
Cache
Fastcgi-Useragent
X-WebKit-CSP-Report-Only
X-Cache-Key
X-Jobs
X-N
X-Load-Cache
X-FB-Debug
Realpath
X-Contextid
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Mobile
Powered-By-ChinaCache
X-Webkit-Csp
Node
X-Rule
Refresh
X-Cache-Expired-At
X-Accel-Buffering
X-Original-Request-Id
X-Response-Served-From
X-Wix-Request-Id
X-Proxy
DC
X-RTag
Ms-Operation-Id
X-Drupal-Cache-Tags
X-Framework
X-Cacheable-TTL
X-Zen-Fury
Version
X-Instance
X-Content-Powered-By
X-Cluster-Name
Access-Control-Request-Headers
X-ProcessESI
X-RemovedCookies
X-HTML-Minification-Powered-By
X-Real-IP
X-B
Referer-Policy
X-Cache-Control
X-Tt-Trace-Tag
X-Page-View
X-Via-JSL
X-Distributor
X-UUID
Eomportal-Instance
X-Region
Viewport
VIX-Pulpo-Upstream-Status
X-Cache-Time
VIX-Pulpo-Node
X-Tt-Trace-Host
X-Drupal-Cache-Contexts
X-FW-Serve
X-FW-Dynamic
X-IPS-LoggedIn
X-FW-Type
X-FireWall-Port
X-FW-Static
X-Cached-By
X-FW-Server
X-FW-Hash
Countrycode
X-Akamai-Edgescape
Liferay-Portal
X-Cache-Rule
X-Cache-Operation
X-TEC-API-VERSION
X-G
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Cache-Hit
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-Tumblr-User
X-App-Server
X-Pass-Why
Xserver
X-Environment-Context
X-L-Path
X-Tec-Api-Version
X-Tec-Api-Root
SRV
X-Nginx-Cache
X-Tec-Api-Origin
DynaTrace
CF-IPCountry
X-Www-Served-By
Server-Info
X-Protected-By
X-Debug-IsConnected
X-Debug-IsPreview
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Io-Id
X-User-Agent
X-Tumblr-Pixel-2
X-Device-Type
From-Origin
Webserver
X-Mode
X-Varnish-Grace
Ec-Rule-Version
X-Adobe-Content
X-Adobe-Loc
X-Handled-By
Meta-Geo
X-ES-SERVER
X-Endurance-Cache-Level
X-Hl-Ver
X-RN-RSRV
X-Ratelimit-Limit
X-UPSTREAM-Address
Retry-After
AMP-Access-Control-Allow-Source-Origin
X-Backend-Name
X-Uri
Cache-Tv-Group
X-MP-GENERATED-AT
TWC-GeoIP-LatLong
TWC-Locale-Group
TWC-Privacy
Webcakes-App-Version
Webcakes-App-Name
TWC-GeoIP-Country
TWC-Device-Class
Property-Id
Fastly-SSL
Decoy-Debug-TTL
Decoy-Debug-Status
TWC-Connection-Speed
Webcakes-Region
X-PHP-Host
X-Storage
X-FB-TRIP-ID
X-Cache-Server
X-Pubstack
X-Origin-Hint
X-Labrador-Cache-Channel
X-Varnishpool
Decoy-Debug-Key
X-Timing-Wait
Cache-Status
Frame-Options
X-Sql-Duration-Ms
X-Sql-Count
X-Access
X-No-Session
X-LJ-Flow-ID
X-LAGOON
X-NYM-Debug-Backend
X-OCL
X-Proto
X-PERF
X-PCL
X-Format
X-R9-Blue-Green-Version
X-Section
Selected-Fe
X-Server-W
X-ApacheServer
X-AWS-Id
X-Redis-Cache
X-Be
Mn-Server-Ip
X-Varnish-Server
X-ProxyCache-Key
X-Request-Time
X-Human
X-BYPASS-REASON
X-VWS-Id
X-WA-Info
X-ProxyCache-Status
X-Proxy-Build
X-Via-Fastly
Protected
Apigw-Requestid
X-UA-Device-Type
X-Cache-TTL-Remaining
X-Web-Node
X-Soup
Country
Cache-Name
X-Site-Version
X-Routing-Service
X-S-Maxage
X-Zipkin-Id
X-Hosted-By
X-Status
X-Hyper-Cache
X-Xfnlog-Site
X-Locale
Azure-Version
Azure-InstanceId
Azure-SiteName
Azure-SlotName
GEO-INFO
X-Proxied
Azure-RegionName
X-Origin-Date
X-Alternate-Cache-Key
X-FW-Version
X-Loop
X-AIR-PT
X-Shopify-Stage
X-Sorting-Hat-ShopId
X-Storefront-Renderer-Rendered
X-TNCMS
X-ShopId
X-Sorting-Hat-PodId
X-ShardId
X-Say-TTL
X-SayCDN-TTL
X-Say-Cacheable
X-Info
X-Node-Name
X-Is-Bot
X-Rendered-As
X-Cluster
X-GG-Cache-Date
X-Dc
X-TT-LOGID
X-Forwarded-Host
X-Proxy-Cache-Status
X-CCM
S-Cnection
Uber-Trace-Id
X-Cache-Grace
X-Cache-Enabled
X-Qloud-Router
X-Microcachable
X-Content-Age
X-SRV
X-TA-CDN-Provider
X-Revision
X-Ratelimit-Remaining
X-NWS-UUID-VERIFY
X-Platform
X-Azure-Ref
X-Backend-Host
X-App-Version
X-CSRF-Token
X-Via-CDN
Cache-Hits
Akamai-GRN
X-Detected-As
X-Varnish-Ttl
X-Cache-Host
X-FTR-Balancer
X-Country-Code-Real
X-Amz-Meta-S3cmd-Attrs
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-DC
X-FTR-Cache-Status
X-Aspnetmvc-Version
X-FTR-Realm
X-CACHE-KEY
ServedBy
X-Amzn-RequestId
X-Amzn-Remapped-Content-Length
X-ATG-Version
X-Amz-Apigw-Id
X-CLOUD-TRACE-CONTEXT
X-EdgeConnect-Cache-Status
X-B3-SpanId
X-Trace-Id
X-Debug-Cache
X-Cache-PHP
X-Cache-NGX
X-RCS-CacheZone
X-CS
HostName
X-Varnish-Hostname
X-FTR-Expires
SD-X-WS
Amp-Access-Control-Allow-Source-Origin
X-DynaTrace-JS-Agent
X-Nc
X-Oss-Object-Type
X-Time-Microsecs
X-Oss-Hash-Crc64ecma
X-Oss-Storage-Class
DB-Nickname
X-Oss-Request-Id
X-Oss-Server-Time
X-Akamai-Transformed
X-TX-ID
X-BCube-Filmed-By
X-NewRelic-App-Data
X-Backend-TTL
Tracecode
X-Air-Hostname
X-ServerID
Backend
X-Ms-Request-Id
X-Adobe-Source
X-Correlation-ID
X-Ms-Version
X-A-Wwc
X-Owner
X-PAYTM-SRV-ID
X-PBS-Appsvrname
Fastcgi-X-Cache-Version
X-Aed
X-Origin-TTL
X-ARC
X-Origin-CC
X-Application
Expiry
X-Location
X-Destination
X-D
BehaviorPad-Version
X-External-Request-Id
X-Generation-Time
X-From
X-Generated-On
X-Connection-Hash
X-Level-Front-Cache
X-B-Cookie
X-NAPM-TraceId
DCR-Decision-By
X-A-Dgt
X-Cache-NE
X-CF-Lambda-Version
X-CF-Lambda-Fn
DCR-Processing-Time-Ms
X-Processor
Machine
Xc-Version
X-Vtex-Processado-Em
X-Unique-ID
X-VG-WebServer
T-Server
X-Trv-Group
MD5-Digest
Mobile-Detection-Method
X-Vdms-Path
Meta-Geo-Continent
X-Vdms-Version
X-VG-WebCache
X-Cdn-Forward
X-SRCache-Key
X-Request-UUID
X-Rewrite-Enabled
X-A-Ccd
X-A-Dam
X-Vtex-Remote-Cache
X-A-Dcw
X-Session-Fingerprint
X-Rojux
X-S
X-A
Odigeo-Trace-Id
X-ScT
X-S-Cookie
Rendered-Blocks
X-Tb
X-Varnish-Beresp-Grace
AKAMAI
On-Server
Thinkindot-CacheControl
X-Fastly-Cache
X-FC-Vary-Parameters
Server-Host
Thinkindot-CacheControl-Type
X-Device-Os
Pagetype
X-Developers
X-Cache-Bucket
Wxu-Next-Hostname
Wxu-Next-Commit
V-Age
Wxu-Next-Region
Host-ID
Gh-Request-Id
Fastly-Backend-Name
Magicmarker
Content-Disposition
CacheControlHeader
X-Cms-Context
Thinkindot-Control
UCS
X-Bip
X-Fetched-On
X-Core-Value
X-HS-Content-Campaign-Id
X-Policy
X-Reqid
X-Varnish-Cache-Hits
X-OVcl-Cache
X-OVcl
X-Mvc-Supplant-Cachable
X-Micro-Cache
X-Magnolia-Registration
X-Thanos
X-Thinkindot-L3
X-Sucuri-ID
Who
X-Irp-Debug
X-Generated-In
X-Geo-Header
X-GeoIP-City
X-TrackingId
X-Tumblr-Pixel-3
Release
Geo-Info
X-Cache-Var-Map
X-Cache-Var
Country-Code
User-Cache-Control
X-Varnish-Beresp-Ttl
Vix-Hermes-Req-Id
X-GoCache-CacheStatus
X-Eu-Site
X-User
X-GeoIP
Web-Mar-Node
X-SVT-ORM-VERSION
X-Scheme
X-Request-URI
X-Esi-Check
X-Skip-Cache
X-SVT-ORM-RULES
X-Var-Ttl
X-VarnishDD-TTL
Sever-Int
X-Generated-By
Server-Hostname
X-Fmm-Version
X-Swa-Ws
Server-Ext
Ssr
X-Wikidot-Static-Cache
X-Fastly-Backend
True-Client-Country-4JS
X-VServer
X-WADP-Cache
X-Wikidot-Backend
X-Request-Host
X-Envoy-Decorator-Operation
X-IP
X-Cache-Debug
X-Branch-Name
X-Block-Status
X-Csrf-Jwt
X-Method
X-Cache-Id
X-LI-UUID
X-Clara-WADP
X-Is-Gdpr
X-CGP
X-Li-Fabric
X-Li-Pop
X-Backend-State
X-Hnp-Log
X-Has-Esi
X-HN
X-Gzip
X-Dispatcher-Server
X-Ratelimit-Reset
X-Origin-Response-Time
X-Origin
X-Nginx-Cache-Key
X-Developer
X-Azure-Ref-OriginShield
X-Node-Id
X-Old-Content-Length
X-JWT-State
X-Gen-Mode
CDN-CachedAt
CDN-EdgeStorageId
Esi-Enabled
CDN-Cache
CDCHOST
X-B3-Traceid
HA-Ipaddr
Ha-Gx-Prefs
DSUID
X-Unique-Id
CDN-RequestCountryCode
CDN-RequestId
CDN-Uid
Cf-Bgj
Cf-Device-Type
X-Varnish-Beresp-Status
CDN-PullZone
Arc-Version
C-Via
PB-PID
L5d-Success-Class
Path
NGX
Locid
Location
PB-RID
PFcat
NM-Fastcgi-Cache
X-DefElseHash
X-DefHash
X-Platform-Server
X-DPWN-IS-SECURE
Adler-Geo
Apple-News-Services-Handled
Apple-News-Services-Host
X-Cache-Tags
X-NU-AKA-ACS-Version
X-Rebelmouse-Cache-Control
X-Hash
Apple-News-Services-Request-Url
X-LB-ID
X-Clientip
X-Origin-Expires
X-Gamma-Serve
Apple-News-Services-Parsed-Url
X-Slack-Backend
X-VG-TLSProxy
X-Rebelmouse-Surrogate-Control
X-Varnish-Remaining-TTL
Fastly-SWR
Cache-Host
Instruction
L
Origin
IsBot
Is-Eu
X-Cache-Info
X-Aicache-OS
X-Varnish-Hits
X-SIPLIST1
Rt-Fastcgi-Cache
X-RateLimit-Limit
Platform
X-Variation
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
Fastly-SIE
SR-User-Adfree
X-ID
X-EC-Lua
Filterid
X-GEO
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Mvc-Supplant-OutputCached
Fastly-Drupal-HTML
X-Varnish-Url
X-CUA
X-Cache-Backend
X-Matched-Rule
Sid
X-PF-Uncompressing
Lfy
X-Via-Popn
X-Via-Popv
X-Via-Poph
Pics-Label
X-APP-VERSION
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
CloudFront-Viewer-Country
X-Loc
Tcn
X-Refresh
X-Epic-Correlation-Id
X-Planisys-CDN-Cache
X-NCache
Pramga
X-Cache-Expires
Url
X-Sn-Servicetimems
X-Cdn-Origin
X-Servername
X-Cache-Date
X-TraceId
Cmstype
NGB
Cmsid
X-Core-Mission
Req-Svc-Chain
X-Served-From
X-Tb-Optimization-Total-Bytes-Saved
Svr
VivaBuild
Viewtype
A
Kp-EeAlive
X-Request-Start
M-TraceId
X-Error
X-Srv
MIME-Version
Source
Cache-Key
X-FireWall-Protection
X-Vgn-Hpd-Reason
Geoip-Latitude
Arc-Country
X-Varnish-Cacheable
GeoIp-Country-Code
X-Geo
X-Webkit-CSP-Report-Only
X-Vcl-Version
Server-ID
X-DC
X-Response-By
Cross-Origin-Opener-Policy
TDXMobile
X-SaId
X-PHP-Backend
X-NC
DataCenter
X-NGENIX-Cache
X-JoinUs
X-Vc
X-Proxy-Cachei7
X-Air-Source
X-Edge-Location
X-HS-Status
Xkeyi7
CACHE
X-Servedbyhost
Server-Ttl
N-Cache
X-Wa
HitType
X-BBXSRF
X-Li-Proto
SID
X-B3-Spanid
Content-Secure-Policy
X-Service
X-Cache-Remote
X-Erf-Stays-Bingo-Pdp-Web
S-Rt
NtCoent-Length
Resin-Trace
X-Internal-Host
X-Esi
X-Cache-2
X-HostName
X-LiteSpeed-Cache-Control
X-Extlb
X-CDN-Forward
X-LI-Proto
FSS-Cache
X-WA
X-Contensis-Viewer-Groups
X-Forwarded-Site
X-Viewer-Country
X-Varnish-Authentication
D-Cc-Upstream
X-Cache-ASPX
X-Cc-Req-Id
X-Kraken-Loop-Name
X-Instrumentation
X-Cc-Via
X-Kraken-Routeconfig-Destination
X-Server-Lifecycle-Phase
Cteonnt-Length
X-Edge-Location-Klb
X-HOST
Cross-Origin-Window-Policy
X-Via-NSCOPI
Request-ID
X-Svr
X-RAMCache
X-Sucuri-Cache
X-CCDN-CacheTTL
X-CCDN-Origin-Time
X-Hcs-Proxy-Type
Ohc-File-Size
X-Bc-Bl
X-ServedByHost
X-Host-Name
X-UA
X-Req
X-Proxy-Upstream
X-DI
X-DSS
X-DB
X-Accel-Expires-Debug
X-Date
X-TIM-N
X-PJAX-URL
X-DW
X-RSL
Mail-Subject
Surrogated-Key
Memcached
X-Newrelic-Synthetics
X-Server-IP
X-RPS
X-VCL-Version
We-Hiring
LB
X-RPM
Hostname
GeoIP-Country-Code
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
GeoIP-Latitude
X-API-Version
X-FPC
CF-Cached-On
X-Origin-Time
X-Cs
X-Nyt-Route
X-APP
X-Gdpr
X-VC-Cache
Env
X-Cache-Config
XServer
X-Action
ProcessTime
X-App
X-VC
X-Check-Cacheable
X-Men
X-SN
Cache-Provider
X-NodeID
X-ZONE
Ohc-Cache-HIT
X-MSEdge-Flight
Server-Id
X-Sigma-Backend
X-Air-Trace-Id
CPC-Age
CPC-Cache
X-MSEdge-Features
X-Oss-Cdn-Auth
Memory
VNS-Age
X-SB
VNS-Cache
X-Fpc
X-Webstats-RespID
X-Sigma
X-Region-Sid
X-CF-Powered-By
Upgrade-Insecure-Requests
Time
X-Rocket-Build-Number
X-URL
X-Swift-Error
X-Dynatrace-Js-Agent
X-Provided-By
X-Zone
X-SD-PageType
X-Depends-On
Mime-Version
W
X-FORWARDED-FOR
X-Akamai-Pragma-Client-IP
X-Cdn-Request-ID
Srv
CDN
X-Render-Time
X-TIME
X-BBC-Edge-Cache-Status
Cdn
X-Dw-Trace-Id
X-BACKEND-TTL
X-UnsetCookies
X-Ftr-Cache-Host
X-CSRF-TOKEN
X-Client-Ip
X-ServerName
X-Flog
X-NGINX-Cache
X-ABtesting
X-Hello
X-Parent-Response-Time
Dnion-Transfer-Encoding
My-App
X-Fastly-Backend-Reqs
X-Fastly-Request-Id
EpKe-Alive
State
Fastcgi-Cache-TTL
X-Dynatrace
X-Pad
Media-Length
X-Minions-Version
X-Acquia-Purge-Tags
X-FTR-Cache-Host
X-Acquia-Application-UUID
X-Cache-Tag
Proxy-Connection
Vha6-Origin
X-Acquia-Application-Trace
X-Worker
X-Presslabs-Stats
X-Oracle-DMS-ECID
X-Auto-Login
Processtime
X-Pf-Uncompressing
X-Acquia-Site
X-ElasticPress-Search
X-Mg-Request-UUID
X-Via-PopN
X-Via-PopV
X-Cluster-Node
X-BBC-Origin-Response-Status
X-LiteSpeed-Tag
PICS-Label
X-Via-PopH
Epwk-X-Cache
X-Ua
X-Snapshot-Date
Cf-Ipcountry
X-CACHE-AGE
Xet-Cookie
X-Lb-Id
X-Vcache
Datacenter
X-Ms-Meta-Staticbatchstarttime
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-Varnish-URL
X-Ms-Meta-Originalurl
X-Request-URL
X-Varnish-Beresp-TTL
X-MiniProfiler-Ids
Warning
X-ElasticPress-Query
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
CountryCode
X-Litespeed-Cache-Control
X-Mg-Request-Id
X-ND-Cache
X-Cache-Status-Check
X-Apw-Access-Token
X-Apw-Access-Action
X-Apw-Access-Object
Content-Style-Type
X-Apw-Hits
Content-Script-Type
Inserted-Into-Cache-At
X-Redis-Duration-Ms
X-Redis-Count
Environment
URI
NnCoection
OT-Force-Account-Verify
X-Traceid
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Tid
X-Amz-Meta-Cb-Modifiedtime
Ohc-Response-Time
Phost
X-Storefront-Renderer-Verified
X-B3-Parentspanid
X-C