Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
Pragma
Link
X-Powered-By
ETag
X-XSS-Protection
Expect-CT
CF-RAY
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-UA-Compatible
P3P
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-Served-By
CF-Ray
X-Timer
X-Download-Options
X-Xss-Protection
X-Varnish
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-Adblock-Key
X-Permitted-Cross-Domain-Policies
X-Cache-Status
X-Request-ID
X-Generator
X-Cacheable
X-Kinja-Server-Push
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-Content-Security-Policy
Content-Encoding
Status
X-CDN
X-AspNetMvc-Version
P3p
X-Envoy-Upstream-Service-Time
Upgrade
X-Drupal-Dynamic-Cache
Access-Control-Max-Age
Access-Control-Expose-Headers
Keep-Alive
X-Via
X-Ws-Request-Id
Feature-Policy
X-Age
X-Server
X-Backend
X-Amz-Request-Id
X-Cache-Group
X-Hacker
X-Amz-Id-2
X-Robots-Tag
Request-Context
X-Proxy-Cache
X-UA-Device
X-AH-Environment
EagleId
X-Turbo-Charged-By
Server-Timing
X-Server-Powered-By
X-Dns-Prefetch-Control
X-Nginx-Cache-Status
Grace
Host-Header
Report-To
X-Template
X-Rq
X-Language
X-Page-Speed
Xkey
X-Varnish-Cache
X-Ua-Compatible
X-OneAgent-JS-Injection
X-Swift-SaveTime
X-Swift-CacheTime
X-Pingback
Cf-Railgun
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Amz-Version-Id
X-Vhost
X-Host
X-Backend-Server
X-WebKit-CSP
NEL
X-Buckets
X-Server-Id
X-Device
X-Dispatcher
Accept-CH-Lifetime
Surrogate-Control
Accept-CH
Request-Id
X-Node
X-Ruxit-JS-Agent
Content-Location
EagleEye-TraceId
X-Response-Time
X-Akam-SW-Version
Allow
X-Cache-Lookup
X-Ac
X-Origin-Cache
X-Readtime
X-Country
X-Mod-Pagespeed
Rating
X-HW
X-Application-Context
X-Cloud-Trace-Context
X-ORACLE-DMS-ECID
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-CST
Edge-Control
Pinterest-Generated-By
X-MS-InvokeApp
X-Vname
X-TtlSet
X-PC
X-Cnection
X-ORACLE-DMS-RID
X-Country-Code
X-Varnish-TTL
X-ASPNET-VERSION
X-DataDome
X-FastCGI-Cache
X-GitHub-Request-Id
X-Content-Type
X-D2id
X-Sol
Display
Response
X-Middleton-Display
X-Middleton-Response
Pagespeed
X-Clacks-Overhead
X-Trace
MS-Author-Via
X-ESI
X-Server-Name
X-Url
Pinterest-Version
X-Pinterest-Rid
X-TTL
X-B3-TraceId
X-Vcap-Request-Id
X-Origin-Upstream-Status
X-Rack-Cache
X-Px
X-Abt-Application-Version
X-Navigation-Version
Service-Worker-Allowed
Fusion-Source
Fusion-Template-Id
Fusion-Deployment-Id
Fusion-Content-Id
Fusion-Component-Id
Fusion-Content-Source
Verso
Arr-Disable-Session-Affinity
X-Client-IP
X-Cache-TTL
X-Element-Page-Cache
X-Webkit-CSP
X-Cached
X-Dw-Request-Base-Id
X-Fastly-Request-ID
X-VARITI-CCR
X-FTR-Request-ID
X-GoogleNews-Bot
X-Exp-Id
X-Kinja
X-Exp-Variant
X-Kinja-Revision
SPRequestGuid
X-Use-Magma
X-SharePointHealthScore
X-Kinja-Server
X-Kinja-Build
X-Cdn-Fetch
X-Goog-Hash
X-Pinterest-Direct
X-DynaTrace
X-Upstream
X-Powered-By-Plesk
Fastly-Restarts
X-NF-Request-ID
AR-Request-ID
AR-PoweredBy
AR-CACHE
AR-ATIME
Ar-Sid
X-MSEdge-Ref
SPIisLatency
SPRequestDuration
X-Debug
Content-MD5
X-Release
X-Powered-CMS
X-Amz-Rid
X-Forwarded-Proto
Access-Control-Request-Method
X-Version
X-Edge
X-Jurisdiction
X-T
S
X-Content-Digest
TCN
X-XRDS-Location
RTSS
Public-Key-Pins
X-Ezoic-Cdn
TP-L2-Cache
TP-Cache
Cache-Tag
X-Cache-Key
Front-End-Https
X-MCACHE
X-Mid
X-Mg-S
X-HP-Webp
X-Amz-Server-Side-Encryption
X-Node-Name
Server-Node
X-Yandex-Sdch-Disable
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
Fastcgi-Cache
X-Request-Processing-Time
X-Request-Received
X-Recruiting
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-PressLabs-Stats
X-Grace
X-Accel-Expires
X-Amzn-Trace-Id
X-Kinsta-Cache
X-Ser
Accept-Ch
MicrosoftSharePointTeamServices
X-Litespeed-Cache
X-Microsite
X-Request-Handler-Origin-Region
X-Varnish-Age
X-Origin-Server
X-Ttl
X-DIS-Request-ID
Accept-Charset
X-NWS-LOG-UUID
X-Content-Security-Policy-Report-Only
ServerID
Edge-Cache-Tag
X-Logged-In
X-Shield-Request-Id
X-Page-Id
Powered-By-ChinaCache
X-Forwarded-For
Host
X-ECACHE
Nginx-Cache
Cache-Tags
X-Hits
X-Cache-Hit
X-Server-ID
Cleartype
X-LB-Cache
X-F-Cache
X-Ratelimit-Remaining
X-Respond-Thread
X-B
X-Hostname
X-Az
X-Activity-Id
X-AppVersion
X-Git-Hash
X-Mobile-URL
X-Aspnetmvc-Version
X-Upgrade-Enabled
X-N
X-Amz-Meta-S3cmd-Attrs
X-Cached-By
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Content-Options
Realpath
X-Cache-Age
X-Load-Cache
X-Type
X-Rid
DynaTrace
X-App-Environment
X-Varnish-Backend
Paypal-Debug-Id
X-Request-Guid
Access-Control-Allow-Method
X-Ratelimit-Limit
X-Oneagent-Js-Injection
X-Jobs
Charset
Alternate-Protocol
Fastcgi-Useragent
X-WebKit-CSP-Report-Only
X-FTR-Cache-Status
X-FTR-Realm
X-FTR-DC
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-Backend
X-Country-Code-Real
X-Seen-By
X-FTR-Expires
X-HS-Content-Id
X-HS-Cache-Config
X-Proxy
X-HS-Hub-Id
X-Goog-Metageneration
X-Goog-Storage-Class
X-HS-Combine-CSS
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-B3-Sampled
Filters
X-Akamai-Edgescape
X-VCache
Viewport
X-Zen-Fury
X-IPLB-Instance
MS-CV
Healthy
X-Whom
X-Signature
X-B-Cache
X-Mobile
X-Tec-Api-Version
X-Tec-Api-Origin
X-FB-Debug
X-Tec-Api-Root
X-Debug-Info
X-AOL-HN
X-Host-Name
X-Geo-Country
X-Region
X-FireWall-Port
X-User-Agent
X-Varnish-Grace
DC
Payment
X-Daa-Tunnel
X-Frontend
Filterid
X-Id
X-Response-Served-From
X-Original-Request-Id
X-Accel-Buffering
X-Amz-Replication-Status
X-XRDS-LOCATION
AMP-Access-Control-Allow-Source-Origin
X-Cache-Rule
X-Cache-Operation
Accept-Ch-Lifetime
Liferay-Portal
X-Tumblr-User
X-HTML-Minification-Powered-By
X-Tumblr-Pixel-2
Surrogate-Key
X-Instance
X-Tumblr-Pixel
X-Rule
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-App-Server
X-FW-Dynamic
X-Cache-Time
X-FW-Hash
X-FW-Type
X-Distributor
X-UUID
X-FW-Static
X-FW-Serve
X-FW-Server
X-TEC-API-ROOT
X-TEC-API-VERSION
Refresh
X-TEC-API-ORIGIN
X-Cacheable-TTL
S-Cnection
X-Protected-By
Section-Io-Cache
X-Correlation-ID
Version
X-Via-JSL
X-Cache-Expired-At
X-Cache-Spec
X-Content-Powered-By
CACHE
Server-Name
X-Acc-Debug-Context
X-Cache-Action
X-Hyper-Cache
X-Rendered-As
X-Is-Bot
X-Backend-Name
GEO-INFO
X-Wix-Request-Id
Nel
X-Correlation-Id
X-Ua
X-Air-Hostname
X-Ah-Environment
Retry-After
X-Sucuri-ID
Content-Disposition
X-Cache-Server
X-URL
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Real-IP
Arc-Version
PB-PID
PB-RID
X-Pinterest-Sli-Latency-Threshold
X-Pinterest-Sli-Response-Type
X-Framework
X-Source
X-Pinterest-Sli-Endpoint-Name
X-ProcessESI
X-L-Path
X-Endurance-Cache-Level
X-Environment-Context
X-RemovedCookies
Countrycode
X-Unique-Id
Webserver
Eomportal-Instance
X-Revision
X-EdgeConnect-Cache-Status
X-Yottaa-Optimizations
X-RTag
Ms-Operation-Id
Datacenter
Frame-Options
X-Yottaa-Metrics
Referer-Policy
X-Drupal-Cache-Contexts
X-Providence-Cookie
X-Flags
X-Route-Name
X-Aspnet-Duration-Ms
X-Is-Crawler
X-Sucuri-Cache
X-LLID
X-Drupal-Cache-Tags
X-Varnish-Server
X-App-Version
X-Cache-Var-Map
X-DynaTrace-JS-Agent
X-NewRelic-App-Data
Meta-Geo
X-ES-SERVER
X-Cache-Var
X-RN-RSRV
Selected-Fe
X-Timing-Wait
X-Hl-Ver
X-Proxy-Build
X-Cache-Control
X-Mode
X-WA-Info
X-Time-Microsecs
X-ProxyCache-Status
X-ProxyCache-Key
Cache-Tv-Group
X-TIME
X-BYPASS-REASON
X-Cache-Host
Webcakes-App-Version
TWC-Privacy
X-Proxy-Cache-Status
X-ServerID
Webcakes-App-Name
X-Be
X-Amzn-Remapped-Content-Length
X-Cluster
X-PHP-Host
X-Origin-Hint
X-NYM-Debug-Backend
X-Labrador-Cache-Channel
TWC-Device-Class
X-Proto
Mn-Server-Ip
Property-Id
TWC-Connection-Speed
X-Human
TWC-GeoIP-Country
X-Server-W
X-FW-Version
TWC-GeoIP-LatLong
X-Handled-By
X-Redis-Cache
X-Qloud-Router
X-R9-Blue-Green-Version
TWC-Locale-Group
Webcakes-Region
X-Status
X-TNCMS
X-Loop
X-Hosted-By
X-FB-TRIP-ID
X-AWS-Id
X-Access
X-TT
X-Contextid
X-PCL
Ec-Rule-Version
X-Format
X-Cache-TTL-Remaining
X-OCL
X-Site-Version
X-Section
X-Routing-Service
X-Proxied
X-No-Session
X-Locale
Cross-Origin-Window-Policy
X-Zipkin-Id
X-VWS-Id
X-LJ-Flow-ID
NGB
DB-Nickname
X-GeoIP
X-Azure-Ref
X-Adobe-Content
X-Detected-As
X-Xfnlog-Site
X-Adobe-Loc
X-Via-Fastly
Akamai-Age-Ms
FSS-Cache
X-AIR-PT
X-CDN-Forward
X-From
X-Tt-Trace-Host
X-Tt-Trace-Tag
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
Upgrade-Insecure-Requests
X-Cache-PHP
Uber-Trace-Id
X-Generated-By
X-ATG-Version
X-NC
Azure-SlotName
Azure-RegionName
Azure-InstanceId
Azure-SiteName
X-Debug-Cache
X-Device-Type
X-BCube-Filmed-By
Azure-Version
X-Ratelimit-Reset
X-UPSTREAM-Address
X-CSRF-Token
Access-Control-Request-Headers
X-Page-View
X-Varnish-Cache-Hits
X-PHP-Backend
X-APP-VERSION
Cache
OT-Force-Account-Verify
SD-X-WS
Cache-Status
From-Origin
SRV
X-Backend-TTL
X-NCache
X-G
Cf-Bgj
X-Cache-2
X-Cluster-Name
X-Varnishpool
X-Akamai-Transformed
X-PERF
X-Pubstack
Country
X-Adobe-Source
X-Forwarded-Host
X-LAGOON
X-CCM
X-Cache-Grace
X-ApacheServer
X-Soup
X-Origin
X-GoCache-CacheStatus
Fastly-SSL
Decoy-Debug-TTL
X-Alternate-Cache-Key
X-SayCDN-TTL
X-Sorting-Hat-PodId
X-Shopify-Stage
X-Sorting-Hat-ShopId
X-Web-Node
X-Storage
Decoy-Debug-Status
X-ShopId
Decoy-Debug-Key
X-ShardId
X-Say-TTL
X-Storefront-Renderer-Rendered
X-Say-Cacheable
X-Backend-Host
X-GEO
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Storage-Class
X-ID
CF-Cached-On
X-Via-CDN
Node
X-ECache
X-SaId
X-JoinUs
X-Ruxit-Js-Agent
X-FTR-Cache-Host
X-Cache-Config
X-Time
X-IP
X-Viewer-Country
X-B3-Spanid
X-Erf-Bev-Bev-Is-Generated
X-EC-Lua
X-Erf-Bev-Bev
X-PAYTM-SRV-ID
X-RCS-CacheZone
DCR-Processing-Time-Ms
X-PBS-Appsvrname
X-Processor
Apple-News-Services-Handled
Apple-News-Services-Parsed-Url
X-Request-UUID
Apple-News-Services-Request-Url
Apple-News-Services-Host
DCR-Decision-By
X-Session-Fingerprint
X-VG-WebServer
X-VG-WebCache
X-Vdms-Version
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-Worker
X-Vdms-Path
X-Cache-Remote
X-S
X-Rojux
X-S-Cookie
X-ScT
X-Trv-Group
Gh-Request-Id
X-Rewrite-Enabled
Fastcgi-X-Cache-Version
X-D
X-A-Dgt
X-Connection-Hash
X-A-Dcw
X-A-Ccd
Rendered-Blocks
X-A
X-A-Wwc
X-Aed
X-Cache-NE
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-B-Cookie
X-Auto-Login
X-Application
X-ARC
Mobile-Detection-Method
X-A-Dam
X-Destination
X-External-Request-Id
MD5-Digest
Meta-Geo-Continent
Machine
Host-ID
X-Cache-Enabled
X-TX-ID
X-Platform
X-Varnish-Remaining-TTL
X-Irp-Debug
Is-Eu
X-Cache-Bucket
X-Clientip
C-Via
X-Generation-Time
X-Cache-NGX
X-Varnish-CookieINHashed-On
X-CUA
X-Micro-Cache
X-DefElseHash
X-DPWN-IS-SECURE
Platform
X-Request-Start
X-Request-Host
X-Servername
X-Policy
X-Variation
X-DefHash
Adler-Geo
X-Thanos
X-SN
X-Varnish-CookieHashed-On
X-Bip
Powered
X-Tumblr-Pixel-3
X-IPS-LoggedIn
Backend
X-B3-Traceid
X-Eu-Site
X-Fastly-Cache
CloudFront-Viewer-Country
Fastly-Backend-Name
X-Fmm-Version
Fastly-SWR
X-Envoy-Decorator-Operation
X-Esi-Check
Wxu-Next-Hostname
X-Generated-On
Fastly-SIE
CDN-RequestId
CDN-CachedAt
CDN-Cache
X-Has-Esi
CacheControlHeader
CDN-EdgeStorageId
X-Gzip
X-Dispatcher-Server
CDN-RequestCountryCode
X-Geo-Header
CDN-PullZone
CDN-Uid
HA-Ipaddr
Pagetype
Origin
NM-Fastcgi-Cache
X-Cache-Id
PFcat
X-Cache-Debug
X-Backend-State
X-Branch-Name
X-Cache-Backend
X-Cache-Date
X-Varnish-Ttl
X-Cache-Tags
L
Wxu-Next-Region
X-Developers
Wxu-Next-Commit
L5d-Success-Class
X-Csrf-Jwt
X-CGP
X-Clara-WADP
X-Cms-Context
X-Core-Value
Ha-Gx-Prefs
X-Varnish-Beresp-Grace
X-VarnishDD-TTL
X-VG-TLSProxy
X-WADP-Cache
X-Webstats-RespID
X-Varnish-Cacheable
X-Skip-Cache
X-Rebelmouse-Surrogate-Control
X-Render-Time
X-HN
X-Sql-Count
X-Sql-Duration-Ms
X-Li-Pop
X-LI-UUID
X-Old-Content-Length
X-Owner
X-Li-Fabric
X-Fastly-Backend
X-Wikidot-Backend
X-Wikidot-Static-Cache
Rt-Fastcgi-Cache
X-Rebelmouse-Cache-Control
X-Reqid
X-JWT-State
X-Level-Front-Cache
X-Platform-Server
X-Method
AKAMAI
Akamai-GRN
X-Varnish-Beresp-Status
X-Varnish-Beresp-Ttl
X-HS-Content-Campaign-Id
X-Is-Gdpr
X-Microcachable
X-Location
X-Mvc-Supplant-Cachable
X-OVcl-Cache
X-PF-Uncompressing
X-Ms-Version
X-OVcl
X-Ms-Request-Id
X-Esi
X-Content-Age
X-Slack-Backend
X-COUNTRY
Fastly-Drupal-HTML
UCS
X-Core-Mission
X-Gamma-Serve
X-Hash
X-Refresh
X-Bc-Bl
FSS-Proxy
X-NWS-UUID-VERIFY
X-Www-Served-By
X-Dc
Protected
X-Aicache-OS
X-Twitter-Response-Tags
X-Transaction
X-RateLimit-Remaining
X-Wa
Cache-Hits
X-S-Maxage
XServer
X-NODE
X-Oracle-Dms-Rid
X-NU-AKA-ACS-Version
X-Minions-Version
X-Ftr-Cache-Host
X-EIG-Tracking-Id
X-SRV
X-DC
X-Mvc-Supplant-OutputCached
X-CS
Country-Code
X-Amz-Meta-Cb-Modifiedtime
X-CACHE-GROUP
X-NGENIX-Cache
X-UA
Hostname
X-TA-CDN-Provider
X-Check-Cacheable
Surrogated-Key
X-Svr
NGX
X-Accel-Expires-Debug
ServedBy
X-Date
X-Via-Popn
X-FPC
X-Request-Time
X-Edge-Location
X-Via-SSL
Edge-Copy-Time
X-LB-ID
We-Hiring
X-Varnish-Hostname
X-LI-Proto
X-Up
X-Servedbyhost
X-Via-Poph
X-Via-Edge
X-Req
X-Debug-Cache-Store
X-Erf-Stays-Bingo-Pdp-Web
On-Server
X-Debug-Cache-Fetch
Mail-Subject
X-Ua-Device
HostName
X-Vgn-Hpd-Cached
X-Vgn-Hpd-Variations-Key
X-CACHE-AGE
X-Cs
Geoip-Latitude
T-Server
X-Cache-URL
X-Cdn-Srv
X-Proxy-Upstream
X-Dynatrace
X-NGINX-Cache
Memcached
GeoIp-Country-Code
Ufe-Result
Group
X-Nginx-Cache
X-Pass-Why
X-Presslabs-Stats
X-Webkit-Csp
X-Fastcgi-Cache
Section-Origin-Responded
X-Uri
Section-Io-Id
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Time
N-Cache
X-BC
Server-Host
Now
X-ZONE
X-Varnish-Hits
X-Agile
X-Cluster-Node
Ohc-File-Size
X-SB
X-VC
X-VCL-Version
X-TT-LOGID
Pics-Label
WZWS-RAY
Magicmarker
X-Agile-Age
X-Agile-Id
X-Acc-Rdl
DSUID
Xserver
X-UnsetCookies
X-Srv
Cache-Name
Ohc-Cache-HIT
X-Cdn-Forward
X-Info
X-MP-GENERATED-AT
X-Datadome
X-UA-Device-Type
X-CSRF-TOKEN
X-Hp-Webp
X-Origin-Date
X-LiteSpeed-Cache-Control
X-HS-Status
M-TraceId
X-CF-Powered-By
Odigeo-Trace-Id
NtCoent-Length
SID
Tracecode
Processtime
X-We-Are-Hiring
X-Zone
X-Bc
X-Dynatrace-Js-Agent
Sid
Apigw-Requestid
S-Rt
User-Agent
User-Cache-Control
X-MSEdge-Features
X-APP
X-Via-Popv
W
X-MSEdge-Flight
Arc-Country
Ssr
ProcessTime
LB
X-Magnolia-Registration
VivaBuild
Lfy
X-FORWARDED-FOR
X-Via-Ucdn
Cdn-Host
Cdn-Request-Time
CDN
X-Edge-Server
Cteonnt-Length
Viewtype
Server-Info
CF-IPCountry
X-HOST
WWW-Authenticate
True-Client-Country-4JS
Vix-Hermes-Req-Id
V-Age
X-API-Version
Instruction
IsBot
Locid
X-Scheme
X-Cc-Via
D-Cc-Upstream
X-Cc-Req-Id
Path
Server-Ext
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
SR-User-Adfree
Sever-Int
Server-Hostname
Thinkindot-Control
X-Node-Id
X-Response-By
X-SD-PageType
X-Server-IP
X-SIPLIST1
X-Request-URI
X-Origin-TTL
X-RunCloud-Cache
X-Origin-CC
X-Origin-Expires
X-Origin-Time
X-SRCache-Key
X-SVT-ORM-RULES
X-Varnish-Authentication
X-Varnish-Url
X-VServer
X-Action
Memory
X-User
X-SVT-ORM-VERSION
X-Tb
X-Thinkindot-L3
X-Nginx-Cache-Key
X-Nyt-Route
X-Contensis-Viewer-Groups
X-Cache-Info
X-Cache-ASPX
X-BBXSRF
X-Developer
X-Gdpr
X-Matched-Rule
X-Loc
X-Fastly-Request-Id
X-HITS
Srv
X-Trace-Id
X-BBC-Edge-Cache-Status
X-Cdn-Origin
X-Swa-Ws
X-Cache-Expires
X-Var-Ttl
MIME-Version
X-NodeID
X-Block-Status
Web-Mar-Node
X-Device-Os
X-GeoIP-City
X-Generated-In
Release
CDCHOST
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Gen-Mode
Cache-Host
X-Hnp-Log
X-Sn-Servicetimems
X-Fetched-On
Pramga
X-Azure-Ref-OriginShield
X-RSL
X-DW
X-DSS
X-RPM
X-RPS
X-Cache-Hm
X-Cache-Hfrom
X-DI
X-DB
Amp-Access-Control-Allow-Source-Origin
X-Oss-Cdn-Auth
CountryCode
X-Unique-ID
X-Pjax-Url
X-Vcl-Version
Geo-Info
X-Webkit-CSP-Report-Only
WebServer
X-Vgn-Hpd-Ssi
Server-ID
A
X-Newrelic-Synthetics
X-FC-Vary-Parameters
X-Browser-Type
X-CACHE-KEY
Cf-Device-Type
X-Fastly-Country-Code
GeoIP-Latitude
X-Traceid
X-Lb-Id
Lb
GeoIP-Country-Code
Source
X-Provided-By
X-Origin-Response-Time
X-Newrelic-App-Data
X-Geo
X-Hit
X-Fpc
Cdn
X-Via-NSCOPI
X-Nc
X-Li-Proto
X-Cache-Tag
Server-Ttl
X-ServedByHost
Expiry
FNAC-ModuleRouting
X-Akamai-Request-ID2
X-Via-PopV
X-Via-PopN
X-Via-PopH
X-Men
Kp-EeAlive
X-Sigma-Backend
X-Sigma
X-Rocket-Build-Number
X-Akamai-Pragma-Client-IP
Cache-Key
X-Vgn-Hpd-Reason
X-SERVER-NAME
Url
X-Served-From
X-Epic-Correlation-Id
X-Envoy-Upstream-Healthchecked-Cluster
X-TH-Server
Content-Style-Type
Location
Content-Script-Type
X-StackifyID
Xkeyi7
EpKe-Alive
X-Proxy-Cachei7
Content-Secure-Policy
Cache-Provider
X-Parent-Response-Time
X-MiniProfiler-Ids
Accept-Language
X-No-Cache
X-Request-URL
X-WA
X-B3-Parentspanid
X-Tt-Logid
Esi-Enabled
Req-Svc-Chain
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
X-B3-SpanId
X-VC-Cache
X-BBC-Origin-Response-Status
X-ElasticPress-Query
BehaviorPad-Version
X-ServiceProvider
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Agile-Brick-Ok
X-Yottaa-OS
X-Akamai-Request-ID
X-TraceId
URI
X-ND-Cache
Tcn
X-Apw-Access-Token
Inserted-Into-Cache-At
X-TrackingId
X-Apw-Hits
X-Varnish-Beresp-TTL
X-Apw-Access-Object
Who
X-RateLimit-Limit
X-Key
X-HostName
X-Apw-Access-Action
X-PJAX-URL
X-Selected-Scheme
X-Selected-Host-Header
X-Selected-Name
X-Litespeed-Cache-Control
Server-Id
PICS-Label
DataCenter
Xet-Cookie
X-ORACLE-APMCS-REQUEST-ID
Actual-Object-TTL
Pragrma
X-Instart-Request-ID
X-Batcache
Mime-Version
X-C
Vha6-Origin
X-Snapshot-Date
NnCoection
Resin-Trace