Threat Level: green Handler on Duty: Renato Marinho

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
Link
Pragma
ETag
X-XSS-Protection
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-UA-Compatible
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Request-Id
X-Varnish
X-Xss-Protection
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Runtime
X-AspNet-Version
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-FRAME-OPTIONS
X-Ua-Compatible
X-Iinfo
X-Request-ID
Content-Encoding
X-CDN
X-AspNetMvc-Version
Feature-Policy
Status
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Upgrade
Access-Control-Max-Age
X-Via
Keep-Alive
X-Ws-Request-Id
X-AH-Environment
X-Age
X-Robots-Tag
Request-Context
X-Turbo-Charged-By
EagleId
X-Cache-Group
X-Proxy-Cache
Server-Timing
X-Server
X-Backend
X-Hacker
Host-Header
X-Server-Powered-By
Report-To
X-Amz-Request-Id
X-Nginx-Cache-Status
X-Amz-Id-2
Grace
X-UA-Device
X-Dns-Prefetch-Control
X-Rq
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Page-Speed
X-OneAgent-JS-Injection
Cf-Railgun
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-CST
X-Amz-Version-Id
NEL
X-Cache-Spec
Allow
X-Vhost
X-Host
X-Backend-Server
X-WebKit-CSP
X-Server-Id
X-ASPNET-VERSION
X-Dispatcher
Surrogate-Control
EagleEye-TraceId
X-Node
Xkey
Request-Id
X-Response-Time
Content-Location
X-Akam-SW-Version
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Accept-CH
X-Ruxit-JS-Agent
X-Cache-Lookup
P3p
X-Application-Context
X-Country
X-Ac
Accept-CH-Lifetime
X-Mod-Pagespeed
X-Cloud-Trace-Context
X-Readtime
X-Template
X-Language
X-B3-TraceId
MS-Author-Via
X-HW
Rating
Accept-Ch-Lifetime
X-Url
X-Cnection
X-MS-InvokeApp
X-Origin-Cache
X-Vname
X-PC
X-TtlSet
Edge-Control
Accept-Ch
X-Clacks-Overhead
X-ESI
X-GitHub-Request-Id
X-Trace
X-Webkit-CSP
X-Middleton-Display
X-Middleton-Response
Pagespeed
Display
Response
X-Sol
X-D2id
X-Content-Type
Arr-Disable-Session-Affinity
Verso
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Kinja-Build
X-GoogleNews-Bot
X-Exp-Id
X-Exp-Variant
X-Kinja
X-Cdn-Fetch
X-Varnish-TTL
X-Powered-By-Plesk
X-Country-Code
X-FastCGI-Cache
X-Goog-Hash
X-Rack-Cache
X-Vcap-Request-Id
X-ORACLE-DMS-RID
X-Navigation-Version
X-VARITI-CCR
X-ORACLE-DMS-ECID
X-Server-Name
X-Abt-Application-Version
X-Amz-Rid
Service-Worker-Allowed
X-Fastly-Request-ID
Fastly-Restarts
X-Cached
X-Client-IP
X-TTL
X-Buckets
X-MSEdge-Ref
X-Release
Cache-Tag
X-Element-Page-Cache
X-Dw-Request-Base-Id
X-NF-Request-ID
MRF-Tech
Mrf-Cache-Status
X-Cache-TTL
X-B3-TraceId-Primal
RTSS
Access-Control-Request-Method
X-SharePointHealthScore
SPRequestGuid
Public-Key-Pins
SPIisLatency
SPRequestDuration
Ar-Sid
AR-PoweredBy
AR-Request-ID
AR-CACHE
AR-ATIME
X-Ezoic-Cdn
X-Edge
X-Powered-CMS
X-LLID
Pinterest-Version
Pinterest-Generated-By
X-Pinterest-Rid
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Upstream
X-Version
S
X-HP-Webp
X-Jurisdiction
Content-MD5
X-Ttl
X-Recruiting
X-Kinsta-Cache
X-ECACHE
Charset
X-MCACHE
X-Mid
X-Mg-S
X-Oneagent-Js-Injection
X-PressLabs-Stats
X-DynaTrace
X-T
X-Origin-Upstream-Status
Cache-Tags
X-Content-Digest
X-Accel-Expires
Fusion-Component-Id
Fusion-Template-Id
Fusion-Content-Source
Fusion-Content-Id
Fusion-Deployment-Id
Fusion-Source
X-Forwarded-Proto
Fastcgi-Cache
X-Id
X-Content-Security-Policy-Report-Only
X-Px
X-Logged-In
Filters
TP-L2-Cache
TP-Cache
X-Litespeed-Cache
Server-Node
Edge-Cache-Tag
TCN
Server-Name
X-Correlation-Id
X-Amz-Server-Side-Encryption
Front-End-Https
X-Forwarded-For
X-Request-Processing-Time
X-Request-Received
MicrosoftSharePointTeamServices
X-Ruxit-Js-Agent
Nginx-Cache
X-Grace
X-Shield-Request-Id
X-Hits
X-Amzn-Trace-Id
Alternate-Protocol
X-B3-Sampled
X-Microsite
X-XRDS-Location
X-Request-Handler-Origin-Region
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Az
X-AppVersion
X-Activity-Id
X-F-Cache
X-Amz-Replication-Status
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Content-Id
X-Server-ID
X-HS-Hub-Id
X-NWS-LOG-UUID
X-Debug
X-Varnish-Age
X-Goog-Stored-Content-Length
X-Origin-Server
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Metageneration
X-GUploader-UploadID
X-Fastcgi-Cache
X-Rid
X-Frontend
Section-Io-Cache
X-Yandex-Sdch-Disable
Host
X-Cache-Age
X-Geo-Country
Surrogate-Key
X-DIS-Request-ID
Accept-Charset
Nel
X-Daa-Tunnel
Realpath
X-Hostname
X-Ser
X-RateLimit-Remaining
X-Git-Hash
X-XRDS-LOCATION
X-Time
X-VCache
X-Respond-Thread
X-Mobile-URL
Access-Control-Allow-Method
X-Upgrade-Enabled
MS-CV
X-Seen-By
X-Source
Paypal-Debug-Id
X-AOL-HN
Cleartype
X-DataDome
X-Type
X-Contextid
X-LB-Cache
ServerID
X-TT
Payment
X-IPLB-Instance
X-Varnish-Backend
Healthy
X-Debug-Info
X-Signature
X-WebKit-CSP-Report-Only
X-Cache-Action
X-B-Cache
X-Flags
X-Aspnet-Duration-Ms
X-Content-Options
X-Request-Guid
X-Route-Name
X-Providence-Cookie
X-Whom
X-Is-Crawler
X-Load-Cache
X-Page-Id
X-App-Environment
X-N
X-FB-Debug
Fastcgi-Useragent
X-Cache-Key
Cache
X-Jobs
Node
X-Rule
X-Mobile
X-Webkit-Csp
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Cache-Expired-At
X-Erf-Bev-Bev
Refresh
X-FireWall-Port
X-Accel-Buffering
X-Original-Request-Id
X-Wix-Request-Id
Viewport
X-Response-Served-From
X-RTag
Ms-Operation-Id
DC
X-Cacheable-TTL
X-FTR-Request-ID
Access-Control-Request-Headers
X-Cluster-Name
X-Content-Powered-By
X-RemovedCookies
X-HTML-Minification-Powered-By
X-Real-IP
X-ProcessESI
X-Distributor
X-Debug-IsPreview
X-Tec-Api-Root
X-Debug-IsConnected
X-B
X-Framework
X-Tec-Api-Origin
X-Tec-Api-Version
X-UUID
X-Proxy
X-Cache-Time
Eomportal-Instance
X-Cache-Control
Version
VIX-Pulpo-Upstream-Status
X-Instance
VIX-Pulpo-Node
X-Region
X-IPS-LoggedIn
X-Drupal-Cache-Tags
Referer-Policy
X-Page-View
X-Zen-Fury
Countrycode
X-Www-Served-By
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Protected-By
X-Nginx-Cache
X-Drupal-Cache-Contexts
X-FW-Static
X-FW-Type
X-FW-Serve
X-FW-Hash
X-G
X-FW-Dynamic
X-FW-Server
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Tumblr-User
X-Cached-By
X-Tumblr-Pixel
Xserver
X-App-Server
X-Cache-Operation
X-Cache-Rule
X-Yottaa-Metrics
Liferay-Portal
X-Yottaa-Optimizations
X-Akamai-Edgescape
X-Varnish-Grace
X-Via-JSL
Section-Io-Id
Section-Origin-Responded
Powered-By-ChinaCache
X-Environment-Context
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
X-L-Path
X-Cache-Hit
X-Pass-Why
X-Device-Type
CF-IPCountry
X-Pinterest-Direct
SRV
GEO-INFO
X-TA-CDN-Provider
Server-Info
DynaTrace
X-Adobe-Loc
X-Adobe-Content
X-User-Agent
X-Varnish-Server
Retry-After
Cache-Status
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
Frame-Options
From-Origin
X-Tumblr-Pixel-2
Meta-Geo
X-RN-RSRV
X-UPSTREAM-Address
Ec-Rule-Version
X-Hl-Ver
X-Endurance-Cache-Level
X-Handled-By
X-ES-SERVER
Webserver
X-FB-TRIP-ID
X-Mode
X-Backend-Name
Cache-Tv-Group
Apigw-Requestid
X-Proxy-Cache-Status
X-Cache-Server
X-BYPASS-REASON
X-Be
Country
X-MP-GENERATED-AT
X-Soup
X-Uri
X-Varnishpool
X-Request-Time
X-Pubstack
X-PCL
X-ProxyCache-Key
X-ProxyCache-Status
X-OCL
X-Storage
X-Access
Webcakes-Region
Webcakes-App-Version
X-AWS-Id
X-Format
X-LJ-Flow-ID
X-Labrador-Cache-Channel
X-Info
Webcakes-App-Name
TWC-Privacy
Selected-Fe
Property-Id
Cache-Name
TWC-Connection-Speed
TWC-Device-Class
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-GeoIP-Country
X-No-Session
X-NYM-Debug-Backend
Decoy-Debug-Key
X-VWS-Id
X-UA-Device-Type
Decoy-Debug-Status
Decoy-Debug-TTL
X-WA-Info
X-Human
Fastly-SSL
X-Timing-Wait
X-Server-W
X-PHP-Host
X-Origin-Hint
X-Origin-Date
X-Proto
X-Proxy-Build
X-Section
X-S-Maxage
X-R9-Blue-Green-Version
Uber-Trace-Id
X-Via-Fastly
Protected
X-ApacheServer
X-GG-Cache-Date
Mn-Server-Ip
Azure-Version
Azure-SiteName
Azure-SlotName
X-PERF
X-LAGOON
X-Sql-Duration-Ms
X-TNCMS
X-Web-Node
X-Sql-Count
X-SayCDN-TTL
X-Say-Cacheable
X-Say-TTL
Azure-RegionName
X-Loop
Azure-InstanceId
X-Storefront-Renderer-Rendered
X-Sorting-Hat-ShopId
X-Cache-TTL-Remaining
X-Alternate-Cache-Key
X-Xfnlog-Site
X-Sorting-Hat-PodId
X-Shopify-Stage
X-ShardId
X-Hyper-Cache
X-ShopId
X-Hosted-By
X-Varnish-Ttl
X-Routing-Service
X-Proxied
X-Status
X-Redis-Cache
X-Zipkin-Id
X-Ratelimit-Limit
X-Cache-Enabled
X-Locale
X-SRV
X-NWS-UUID-VERIFY
X-Content-Age
X-Backend-Host
X-Rendered-As
X-Is-Bot
X-Microcachable
X-Site-Version
X-Azure-Ref
X-FW-Version
AMP-Access-Control-Allow-Source-Origin
S-Cnection
X-App-Version
X-Cache-Grace
X-AIR-PT
X-Cluster
Amp-Access-Control-Allow-Source-Origin
X-Platform
X-Qloud-Router
X-Forwarded-Host
X-CSRF-Token
X-Revision
X-Trace-Id
X-TT-LOGID
Akamai-GRN
X-Dc
ServedBy
X-Via-CDN
X-Cache-NGX
X-EdgeConnect-Cache-Status
X-ATG-Version
X-Varnish-Hostname
X-Cache-PHP
Cache-Hits
X-Debug-Cache
X-RCS-CacheZone
X-CACHE-KEY
X-Aspnetmvc-Version
Who
X-Node-Name
X-Akamai-Transformed
Country-Code
X-CCM
DB-Nickname
X-Cache-Host
X-TX-ID
Filterid
X-Detected-As
X-Amzn-Remapped-Content-Length
X-RateLimit-Limit
X-B3-SpanId
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Adobe-Source
X-Ratelimit-Remaining
X-CS
X-BCube-Filmed-By
X-Ms-Request-Id
X-Varnish-Beresp-Grace
X-Ms-Version
SD-X-WS
X-Varnish-Beresp-Ttl
X-Nc
X-Unique-Id
Backend
X-GEO
Fastcgi-X-Cache-Version
X-NAPM-TraceId
Expiry
DCR-Decision-By
DCR-Processing-Time-Ms
X-A-Dcw
X-A-Dam
X-Oss-Hash-Crc64ecma
X-A
Meta-Geo-Continent
Mobile-Detection-Method
Rendered-Blocks
Odigeo-Trace-Id
MD5-Digest
X-VG-WebServer
X-A-Dgt
T-Server
Machine
X-A-Ccd
X-Application
X-Varnish-Beresp-Status
X-Destination
X-D
X-Connection-Hash
X-Level-Front-Cache
X-Varnish-Cache-Hits
X-Generation-Time
X-Generated-On
X-From
X-External-Request-Id
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-Oss-Server-Time
X-Oss-Request-Id
X-Aed
X-Oss-Object-Type
X-ARC
X-Oss-Storage-Class
BehaviorPad-Version
X-Cache-NE
X-Location
X-B-Cookie
X-A-Wwc
X-Session-Fingerprint
X-Owner
X-PAYTM-SRV-ID
X-PBS-Appsvrname
X-Trv-Group
X-S
X-Origin-TTL
X-Vdms-Path
X-Processor
X-Vtex-Remote-Cache
HostName
X-Vtex-Processado-Em
X-Request-UUID
X-Rewrite-Enabled
X-Correlation-ID
X-SRCache-Key
X-Time-Microsecs
X-Rojux
X-VG-WebCache
X-ScT
X-Vdms-Version
X-Origin-CC
X-S-Cookie
X-Magnolia-Registration
Thinkindot-CacheControl
X-Tumblr-Pixel-3
Thinkindot-CacheControl-Type
Thinkindot-Control
X-TrackingId
Ssr
X-Fetched-On
Fastly-Backend-Name
X-Bip
X-FC-Vary-Parameters
X-OVcl-Cache
Content-Disposition
X-Device-Os
AKAMAI
CacheControlHeader
X-Cms-Context
NGB
Arc-Version
Cache-Host
X-Core-Value
X-Cache-Bucket
Host-ID
X-ServerID
UCS
V-Age
Gh-Request-Id
X-Azure-Ref-OriginShield
Server-Host
X-Is-Gdpr
X-JWT-State
X-FTR-DC
Cf-Device-Type
X-OVcl
X-FTR-Cache-Status
X-Edge-Location-Klb
Pagetype
X-Backend-TTL
PB-PID
PB-RID
Path
Release
X-FTR-Balancer
X-Thanos
X-FTR-Realm
X-Geo-Header
X-Thinkindot-L3
X-GeoIP-City
X-Reqid
X-Has-Esi
X-FTR-Backend
X-FTR-Backend-Server
X-Country-Code-Real
X-Instrumentation
X-Kraken-Routeconfig-Destination
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Node-Id
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Scheme
Server-Ext
X-SIPLIST1
X-VServer
Platform
Server-Hostname
Sever-Int
Wxu-Next-Region
X-Skip-Cache
Wxu-Next-Hostname
Wxu-Next-Commit
True-Client-Country-4JS
X-NU-AKA-ACS-Version
X-Origin
X-Generated-In
X-Varnish-CookieINHashed-On
X-Varnish-Hits
X-Varnish-CookieHashed-On
X-Variation
X-Fastly-Backend
X-Fastly-Cache
X-Irp-Debug
X-GeoIP
X-GoCache-CacheStatus
X-Li-Pop
X-Origin-Expires
X-LI-UUID
X-Li-Fabric
X-HS-Content-Campaign-Id
X-Var-Ttl
X-Varnish-Remaining-TTL
X-Epic-Correlation-Id
X-VG-TLSProxy
X-Policy
X-Platform-Server
X-Clientip
X-Nginx-Cache-Key
X-Cache-Tags
Esi-Enabled
X-Branch-Name
X-Cache-Info
X-Micro-Cache
X-IP
X-Developers
X-Dispatcher-Server
X-DPWN-IS-SECURE
X-Developer
X-Mvc-Supplant-Cachable
X-DefElseHash
X-DefHash
X-Ratelimit-Reset
Vix-Hermes-Req-Id
CDN-Uid
CDN-RequestId
CDN-RequestCountryCode
DSUID
Fastly-SIE
Is-Eu
Fastly-SWR
CDN-PullZone
CDN-EdgeStorageId
X-B3-Traceid
X-EC-Lua
Adler-Geo
C-Via
CDN-CachedAt
CDN-Cache
IsBot
X-DynaTrace-JS-Agent
Location
Magicmarker
NGX
NM-Fastcgi-Cache
User-Cache-Control
X-Unique-ID
X-Amz-Meta-S3cmd-Attrs
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
X-Hnp-Log
X-CGP
X-Esi-Check
X-Generated-By
Origin
X-Eu-Site
CDCHOST
X-Sucuri-ID
X-HN
X-Goog-Meta-Goog-Reserved-File-Mtime
X-VarnishDD-TTL
X-Clara-WADP
Apple-News-Services-Host
X-Backend-State
X-Block-Status
Web-Mar-Node
X-APP-VERSION
X-Envoy-Decorator-Operation
X-Loc
X-Fmm-Version
X-Method
Apple-News-Services-Handled
X-Gen-Mode
X-Hash
X-WADP-Cache
X-Csrf-Jwt
X-LB-ID
X-Cache-Id
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
Fastly-Drupal-HTML
X-Gzip
PFcat
X-Gamma-Serve
X-Planisys-CDN-TTL
Ha-Gx-Prefs
L
L5d-Success-Class
X-Request-URI
X-Tb
HA-Ipaddr
Cf-Bgj
Locid
X-Old-Content-Length
On-Server
X-Request-Host
Rt-Fastcgi-Cache
X-User
X-Cache-Debug
X-Aicache-OS
X-NewRelic-App-Data
X-ID
X-Swa-Ws
Cmstype
Xc-Version
X-Origin-Response-Time
Cmsid
X-Slack-Backend
Req-Svc-Chain
X-Wikidot-Static-Cache
X-Servername
X-Wikidot-Backend
X-FTR-Expires
X-Cdn-Forward
X-Air-Hostname
X-Varnish-Url
Svr
X-PF-Uncompressing
X-Mvc-Supplant-OutputCached
X-Via-Poph
X-Via-Popn
X-Via-Popv
X-Served-From
Kp-EeAlive
X-Vgn-Hpd-Reason
Pics-Label
Url
A
X-Refresh
Tracecode
SR-User-Adfree
Instruction
M-TraceId
X-SaId
X-JoinUs
X-PHP-Backend
X-NGENIX-Cache
X-Cache-Var-Map
X-Cache-Var
Cross-Origin-Opener-Policy
Cache-Key
Arc-Country
X-CUA
VivaBuild
Viewtype
X-Edge-Location
X-DC
Sid
Lfy
SID
X-Matched-Rule
TDXMobile
X-NC
X-TraceId
CloudFront-Viewer-Country
X-Sn-Servicetimems
MIME-Version
X-Tb-Optimization-Total-Bytes-Saved
X-Vc
X-Cache-Expires
X-Cdn-Origin
NtCoent-Length
DataCenter
X-CDN-Forward
X-Cache-Backend
X-NCache
Content-Secure-Policy
X-Service
Pramga
Geo-Info
X-Extlb
X-Cache-Date
X-Servedbyhost
X-CLOUD-TRACE-CONTEXT
Server-ID
X-Webkit-CSP-Report-Only
X-Core-Mission
X-Internal-Host
X-Wa
X-Bc-Bl
X-Request-Start
X-Srv
Source
Geoip-Latitude
X-Forwarded-Site
Tcn
GeoIp-Country-Code
X-Newrelic-Synthetics
X-Via-NSCOPI
X-B3-Spanid
Surrogated-Key
X-FireWall-Protection
Memcached
X-Req
X-HS-Status
X-Proxy-Upstream
X-LI-Proto
LB
X-Error
FSS-Cache
X-Varnish-Cacheable
X-VC-Cache
We-Hiring
X-Date
X-Accel-Expires-Debug
X-Vcl-Version
X-Esi
Mail-Subject
CACHE
Hostname
X-VHOST
Upgrade-Insecure-Requests
Resin-Trace
X-Sigma
X-PJAX-URL
X-Response-By
X-Rocket-Build-Number
X-VCL-Version
X-Air-Source
Env
Server-Ttl
X-Sigma-Backend
X-Viewer-Country
X-Li-Proto
X-Geo
X-HOST
Memory
Request-ID
Xkeyi7
X-Cache-Ttl
X-Proxy-Cachei7
X-MSEdge-Features
X-MSEdge-Flight
X-Men
X-App
GeoIP-Latitude
GeoIP-Country-Code
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-ZONE
X-CCDN-CacheTTL
Time
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-LiteSpeed-Cache-Control
X-DW
X-WA
X-RSL
X-DSS
X-DB
CF-Cached-On
N-Cache
X-RPM
X-DI
X-TIM-N
X-RPS
HitType
X-Cs
X-Mg-Request-UUID
X-BBXSRF
X-APP
X-Cache-2
X-RAMCache
VNS-Cache
VNS-Age
X-ServedByHost
CPC-Age
X-Zone
CPC-Cache
XServer
My-App
X-Varnish-Authentication
State
D-Cc-Upstream
X-Svr
S-Rt
ProcessTime
Server-Id
X-UA
X-Cache-ASPX
X-Air-Trace-Id
X-Cc-Req-Id
X-Cc-Via
X-Contensis-Viewer-Groups
X-Action
X-HostName
Srv
Mime-Version
X-Oss-Cdn-Auth
X-Region-Sid
Fastcgi-Cache-TTL
X-Minions-Version
X-FPC
X-Dynatrace-Js-Agent
X-Swift-Error
X-Provided-By
W
X-API-Version
X-Origin-Time
X-Depends-On
X-CF-Powered-By
X-Cache-Type
X-Fpc
X-Gdpr
X-FORWARDED-FOR
X-Cache-Config
X-Nyt-Route
X-Server-IP
Cache-Provider
X-Cache-Remote
X-Cdn-Request-ID
Cteonnt-Length
Cross-Origin-Window-Policy
X-Sucuri-Cache
X-URL
OT-Force-Account-Verify
X-TIME
Ohc-File-Size
CDN
X-Dw-Trace-Id
X-Erf-Stays-Bingo-Pdp-Web
X-UnsetCookies
X-CSRF-TOKEN
X-BACKEND-TTL
X-Client-Ip
X-ServerName
X-Xrds-Location
X-Akamai-Pragma-Client-IP
X-Hello
X-Flog
X-NodeID
Proxy-Connection
X-Check-Cacheable
X-Parent-Response-Time
X-ABtesting
X-Shop-Environment
X-SN
X-Forwarded-Path
X-Orig-Expires
X-ND-Cache
X-Fastly-Request-Id
Cdn
X-VC
X-Tenant
X-Ftr-Cache-Host
Ohc-Cache-HIT
X-Snapshot-Date
X-Fastly-Backend-Reqs
X-SD-PageType
Cf-Ipcountry
X-Oracle-DMS-ECID
Vha6-Origin
X-Pad
X-Presslabs-Stats
X-Pf-Uncompressing
X-Webstats-RespID
X-SB
WZWS-RAY
Dnion-Transfer-Encoding
X-BBC-Edge-Cache-Status
Media-Length
X-NGINX-Cache
X-Host-Name
X-Via-PopN
X-Via-PopV
X-Via-PopH
X-Traceid
X-Cluster-Node
X-Varnish-URL
X-LiteSpeed-Tag
Datacenter
Epwk-X-Cache
X-Ftr-Request-Id
X-ElasticPress-Search
X-Air-Pt
PICS-Label
X-IN-APIGATEWAYSSL
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Acquia-Site
Warning
X-Yottaa-OS
X-Acquia-Application-Trace
X-Conf
X-Pjax-Url
X-BBC-Origin-Response-Status
X-IN-APIGATEWAY
X-Render-Time
X-Lb-Id
X-Ms-Meta-Originalurl
X-Ms-Meta-Staticbatchstarttime
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-Vcache
Xet-Cookie
X-Varnish-Beresp-TTL
X-Cache-Tag
X-Request-URL
EpKe-Alive
X-MiniProfiler-Ids
CountryCode
X-Redis-Duration-Ms
URI
X-B3-Parentspanid
X-Redis-Count
X-C
Environment
NnCoection
X-Mg-Request-Id
X-Apw-Access-Token
X-Debug-Cache-Fetch
Ohc-Response-Time
X-Litespeed-Cache-Control
X-Debug-Cache-Store
X-Tid
Inserted-Into-Cache-At
Phost
Content-Script-Type
X-Amz-Meta-Cb-Modifiedtime
X-Apw-Hits
X-Apw-Access-Object
X-Apw-Access-Action
Content-Style-Type
X-Cache-Status-Check