Threat Level: green Handler on Duty: Jim Clausing

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
X-XSS-Protection
Cf-Request-Id
CF-RAY
CF-Cache-Status
Last-Modified
Accept-Ranges
Link
Pragma
Expect-CT
ETag
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Cache-Status
X-Generator
X-Request-ID
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Content-Security-Policy
Content-Encoding
X-CDN
X-Envoy-Upstream-Service-Time
Status
X-Ua-Compatible
Feature-Policy
Access-Control-Expose-Headers
X-AspNetMvc-Version
X-Drupal-Dynamic-Cache
Access-Control-Max-Age
X-Xss-Protection
X-Via
Upgrade
Keep-Alive
X-Ws-Request-Id
X-Age
X-Turbo-Charged-By
X-AH-Environment
X-Robots-Tag
Request-Context
X-Proxy-Cache
EagleId
X-Cache-Group
X-Backend
Server-Timing
X-Hacker
X-Amz-Request-Id
Report-To
X-Server
Host-Header
X-Amz-Id-2
X-Server-Powered-By
X-UA-Device
X-Nginx-Cache-Status
Grace
X-Dns-Prefetch-Control
X-LiteSpeed-Cache
X-Varnish-Cache
X-Rq
Ali-Swift-Global-Savetime
X-Swift-SaveTime
X-Swift-CacheTime
X-Page-Speed
Cf-Railgun
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
NEL
X-Amz-Version-Id
X-OneAgent-JS-Injection
Xkey
X-WebKit-CSP
Allow
X-Cache-Spec
X-Backend-Server
X-Host
X-Vhost
X-CST
X-Device
EagleEye-TraceId
X-Server-Id
Surrogate-Control
Request-Id
X-Dispatcher
Accept-CH
X-Node
X-Kinja-Server-Push
Content-Location
X-Response-Time
Accept-CH-Lifetime
X-Akam-SW-Version
X-Ruxit-JS-Agent
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-ASPNET-VERSION
X-Template
X-Language
X-Ac
X-Application-Context
X-Readtime
X-Country
X-Cloud-Trace-Context
X-Cache-Lookup
X-Mod-Pagespeed
MS-Author-Via
X-Origin-Cache
X-B3-TraceId
Rating
X-Cnection
X-MS-InvokeApp
X-HW
X-ORACLE-DMS-ECID
X-TtlSet
X-Vname
X-PC
Accept-Ch
X-Clacks-Overhead
X-Url
Edge-Control
X-FastCGI-Cache
X-GitHub-Request-Id
X-ESI
X-Trace
Accept-Ch-Lifetime
Response
Display
X-Sol
X-Middleton-Display
X-Middleton-Response
Pagespeed
X-Content-Type
X-D2id
Verso
X-Kinja-Build
X-Kinja
X-GoogleNews-Bot
Arr-Disable-Session-Affinity
X-Cdn-Fetch
X-Exp-Id
X-Exp-Variant
X-Use-Magma
X-Kinja-Server
X-Vcap-Request-Id
X-Kinja-Revision
X-Buckets
X-Goog-Hash
X-Varnish-TTL
X-Rack-Cache
X-Server-Name
X-Country-Code
Service-Worker-Allowed
X-Navigation-Version
X-VARITI-CCR
X-Abt-Application-Version
X-Amz-Rid
X-ORACLE-DMS-RID
X-Oneagent-Js-Injection
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
X-Cache-TTL
X-Client-IP
X-Powered-By-Plesk
X-SharePointHealthScore
X-TTL
SPRequestGuid
SPRequestDuration
SPIisLatency
X-Fastly-Request-ID
X-Release
X-MSEdge-Ref
X-Dw-Request-Base-Id
X-Element-Page-Cache
Fastly-Restarts
X-NF-Request-ID
X-Cached
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
Public-Key-Pins
RTSS
X-Origin-Upstream-Status
AR-Request-ID
Ar-Sid
X-Edge
AR-PoweredBy
AR-CACHE
AR-ATIME
X-Px
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Access-Control-Request-Method
X-Webkit-CSP
X-LLID
X-Powered-CMS
Fusion-Component-Id
Fusion-Source
Fusion-Content-Source
Fusion-Content-Id
Fusion-Template-Id
Fusion-Deployment-Id
X-Upstream
X-Ezoic-Cdn
Content-MD5
X-Pinterest-Direct
X-Jurisdiction
X-HP-Webp
X-Amz-Server-Side-Encryption
X-Mid
X-ECACHE
X-MCACHE
Charset
X-Recruiting
X-Content-Digest
S
X-Mg-S
X-Ttl
Cache-Tag
X-Aspnetmvc-Version
X-Version
MicrosoftSharePointTeamServices
TCN
X-PressLabs-Stats
X-Debug
Front-End-Https
Fastcgi-Cache
X-XRDS-Location
X-Content-Security-Policy-Report-Only
X-Grace
X-T
Filters
Cache-Tags
X-Kinsta-Cache
Server-Node
Edge-Cache-Tag
X-Forwarded-Proto
X-Yandex-Sdch-Disable
X-Correlation-Id
X-Cache-Key
X-Amzn-Trace-Id
X-Accel-Expires
X-Logged-In
Server-Name
X-Id
X-Kong-Upstream-Latency
Nginx-Cache
X-Kong-Proxy-Latency
Surrogate-Key
X-Varnish-Age
Powered-By-ChinaCache
X-Forwarded-For
X-DynaTrace
TP-L2-Cache
X-B3-Sampled
X-Hits
TP-Cache
X-Ser
X-DIS-Request-ID
X-Request-Processing-Time
X-Request-Handler-Origin-Region
X-Microsite
X-Request-Received
X-Shield-Request-Id
X-AppVersion
X-Amz-Replication-Status
X-Activity-Id
X-Az
X-Server-ID
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Hub-Id
X-F-Cache
X-HS-Content-Id
X-FTR-Request-ID
X-Goog-Storage-Class
Accept-Charset
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
X-Origin-Server
X-Git-Hash
X-Litespeed-Cache
X-Respond-Thread
X-Hostname
X-Geo-Country
X-LB-Cache
X-DataDome
Section-Io-Cache
X-Upgrade-Enabled
X-Rid
X-Frontend
X-Cache-Age
Access-Control-Allow-Method
X-TEC-API-VERSION
X-Mobile-URL
Cleartype
Host
X-TEC-API-ORIGIN
X-TEC-API-ROOT
Alternate-Protocol
X-Type
Paypal-Debug-Id
Healthy
Cache
X-Content-Options
MS-CV
X-IPLB-Instance
ServerID
X-AOL-HN
X-Ruxit-Js-Agent
X-WebKit-CSP-Report-Only
X-Whom
Payment
X-Varnish-Backend
X-App-Environment
X-Is-Crawler
X-Providence-Cookie
X-Request-Guid
X-Route-Name
X-Flags
X-Debug-Info
X-Aspnet-Duration-Ms
X-B-Cache
X-Cache-Action
X-TT
X-Signature
X-VCache
X-Seen-By
Fastcgi-Useragent
X-Page-Id
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Jobs
X-Mobile
X-N
X-Source
X-NWS-LOG-UUID
X-RateLimit-Remaining
X-Load-Cache
X-XRDS-LOCATION
X-Browser-Type
X-Cached-By
X-Via-JSL
X-Akamai-Edgescape
Version
X-Time
X-FB-Debug
Nel
X-Cache-Rule
X-Cache-Operation
X-Daa-Tunnel
Viewport
DynaTrace
X-Accel-Buffering
X-Original-Request-Id
Refresh
X-Rule
X-Response-Served-From
DC
Realpath
X-Framework
X-Proxy
X-Zen-Fury
X-Drupal-Cache-Tags
X-Cacheable-TTL
X-Tt-Trace-Host
X-RemovedCookies
X-ProcessESI
X-Instance
Referer-Policy
X-Tt-Trace-Tag
GEO-INFO
X-RTag
Ms-Operation-Id
X-Fastcgi-Cache
X-Region
X-Real-IP
Access-Control-Request-Headers
X-UUID
X-HTML-Minification-Powered-By
X-Cache-Time
X-Contextid
X-Drupal-Cache-Contexts
X-Distributor
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-FW-Dynamic
X-Environment-Context
X-FW-Hash
X-Page-View
X-FW-Type
X-L-Path
X-FW-Static
X-FW-Serve
X-FW-Server
X-Node-Name
X-Wix-Request-Id
X-Cache-Expired-At
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
Eomportal-Instance
X-B
Node
Liferay-Portal
X-Cluster-Name
X-G
X-Tumblr-Pixel
Countrycode
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Cache-Control
X-Content-Powered-By
X-IPS-LoggedIn
X-Amz-Meta-S3cmd-Attrs
X-Cache-Hit
X-User-Agent
X-Tumblr-Pixel-2
Webserver
Section-Io-Id
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
SRV
Section-Io-Origin-Status
Server-Info
Protected
From-Origin
X-App-Server
X-Revision
X-Pass-Why
X-Ratelimit-Limit
X-Protected-By
Ec-Rule-Version
X-Backend-Name
X-Cache-Server
Frame-Options
Cache-Status
X-FireWall-Port
X-Oracle-Dms-Rid
X-Hyper-Cache
X-Handled-By
X-UPSTREAM-Address
X-Mode
X-RN-RSRV
Meta-Geo
X-Endurance-Cache-Level
Retry-After
X-ES-SERVER
X-Hl-Ver
X-Www-Served-By
X-Site-Version
X-Forwarded-Host
X-FB-TRIP-ID
X-Storage
X-Soup
X-Adobe-Content
X-Adobe-Loc
X-Locale
X-NYM-Debug-Backend
CF-IPCountry
TWC-Privacy
X-Section
X-Format
X-Be
Property-Id
Webcakes-App-Version
TWC-Locale-Group
X-Varnishpool
Webcakes-App-Name
TWC-Connection-Speed
X-Web-Node
X-Pubstack
X-Access
Cache-Tv-Group
Webcakes-Region
X-Via-CDN
Decoy-Debug-Status
Country
X-Cache-Grace
TWC-Device-Class
Decoy-Debug-Key
X-Human
TWC-GeoIP-LatLong
Fastly-SSL
Decoy-Debug-TTL
X-Origin-Hint
TWC-GeoIP-Country
X-FW-Version
X-BYPASS-REASON
X-Labrador-Cache-Channel
X-OCL
X-PCL
X-ApacheServer
Selected-Fe
Azure-SiteName
Azure-RegionName
Azure-SlotName
Azure-Version
Cache-Name
X-PERF
X-PHP-Host
X-Timing-Wait
X-SayCDN-TTL
X-TT-LOGID
X-UA-Device-Type
X-Uri
X-Say-TTL
X-Say-Cacheable
X-Proxy-Build
X-Proto
X-ProxyCache-Key
X-ProxyCache-Status
X-Redis-Cache
Azure-InstanceId
X-Origin-Date
X-Country-Code-Real
X-FTR-Backend
X-FTR-Backend-Server
X-Varnish-Ttl
X-No-Session
S-Cnection
X-LAGOON
X-S-Maxage
X-FTR-Cache-Status
X-FTR-Realm
X-Via-Fastly
X-WA-Info
X-FTR-DC
X-Sql-Duration-Ms
X-Server-W
X-Sql-Count
X-AIR-PT
X-FTR-Balancer
X-TNCMS
X-AWS-Id
X-VWS-Id
X-LJ-Flow-ID
X-Loop
X-Qloud-Router
X-R9-Blue-Green-Version
Mn-Server-Ip
X-Status
X-Hosted-By
X-FTR-Expires
X-Cache-TTL-Remaining
X-Request-Time
X-Cluster
X-CCM
X-Sorting-Hat-ShopId
X-Storefront-Renderer-Rendered
X-Alternate-Cache-Key
Cache-Hits
X-Zipkin-Id
X-Proxied
X-ShardId
X-Shopify-Stage
X-MP-GENERATED-AT
X-Sorting-Hat-PodId
X-ShopId
X-Xfnlog-Site
X-Routing-Service
X-Rendered-As
X-Is-Bot
X-Cache-Var
X-Ratelimit-Remaining
X-Cache-Var-Map
X-Air-Hostname
X-Dynatrace
X-Unique-Id
X-SRV
Xserver
AMP-Access-Control-Allow-Source-Origin
X-Detected-As
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Amzn-Remapped-Content-Length
X-Device-Type
X-EdgeConnect-Cache-Status
X-Cache-Host
X-Info
X-Webkit-Csp
Apigw-Requestid
X-Cdn
X-Nginx-Cache
X-Microcachable
SD-X-WS
X-B3-Traceid
X-Dc
X-Cache-Enabled
X-GEO
X-ID
X-Content-Age
X-Time-Microsecs
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
X-Cache-Backend
X-Varnish-Server
Tracecode
X-Debug-IsConnected
X-Backend-TTL
Amp-Access-Control-Allow-Source-Origin
X-Debug-IsPreview
X-ServerID
X-Platform
X-Varnish-Grace
X-APP-VERSION
X-Azure-Ref
X-Backend-Host
X-DynaTrace-JS-Agent
Uber-Trace-Id
DSUID
X-GG-Cache-Date
X-Erf-Stays-Bingo-Pdp-Web
X-NewRelic-App-Data
X-Tb
X-Oss-Request-Id
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Oss-Storage-Class
X-Oss-Server-Time
Akamai-GRN
X-Sucuri-ID
X-Proxy-Cache-Status
X-BCube-Filmed-By
Arc-Version
PB-PID
PB-RID
Backend
X-ATG-Version
X-Magnolia-Registration
X-Trace-Id
X-Origin-Response-Time
X-URL
X-Correlation-ID
X-Akamai-Transformed
X-Destination
X-D
Thinkindot-CacheControl-Type
X-VG-WebCache
Thinkindot-CacheControl
X-Vdms-Version
X-Vtex-Remote-Cache
X-External-Request-Id
ServedBy
X-Vtex-Processado-Em
X-Device-Os
X-VG-WebServer
X-CF-Lambda-Fn
X-ARC
X-A-Dcw
X-B-Cookie
X-A-Dam
X-SRCache-Key
X-Application
X-A-Wwc
X-Aed
X-Varnish-Cache-Hits
X-A-Ccd
X-A
X-S-Cookie
X-S
Thinkindot-Control
X-CF-Lambda-Version
X-Rojux
X-Session-Fingerprint
X-Cache-NE
X-ScT
X-Connection-Hash
X-Request-UUID
X-Trv-Group
Machine
Lfy
X-Matched-Rule
X-Fetched-On
X-Origin-CC
Meta-Geo-Continent
MD5-Digest
X-Origin-TTL
DCR-Decision-By
Xc-Version
Fastcgi-X-Cache-Version
Expiry
DCR-Processing-Time-Ms
X-Cache-Remote
X-Level-Front-Cache
Instruction
X-Thinkindot-L3
X-Location
Mobile-Detection-Method
X-Generation-Time
X-Vdms-Path
X-From
SR-User-Adfree
X-PBS-Appsvrname
X-Processor
Rendered-Blocks
Pramga
X-RCS-CacheZone
Path
X-Rewrite-Enabled
X-Generated-On
X-A-Dgt
T-Server
Odigeo-Trace-Id
X-PAYTM-SRV-ID
X-Varnish-Hostname
X-Cache-NGX
X-Cache-PHP
X-Adobe-Source
Magicmarker
Gh-Request-Id
Fastly-Backend-Name
Pagetype
Wxu-Next-Commit
PFcat
Ha-Gx-Prefs
HA-Ipaddr
L5d-Success-Class
L
Wxu-Next-Hostname
Locid
Host-ID
Ssr
X-CGP
X-Node-Id
X-Mvc-Supplant-Cachable
X-Swa-Ws
Release
X-OVcl
X-OVcl-Cache
X-GeoIP-City
X-User
X-Tumblr-Pixel-3
X-Owner
BehaviorPad-Version
X-Micro-Cache
X-JWT-State
X-HS-Content-Campaign-Id
X-Irp-Debug
X-Is-Gdpr
X-HN
X-Thanos
X-Geo-Header
X-GeoIP
X-Has-Esi
X-SVT-ORM-VERSION
X-Wikidot-Backend
X-Skip-Cache
X-Cache-Date
X-Cache-Info
X-Cdn-Origin
X-Cache-Bucket
X-Bip
X-Azure-Ref-OriginShield
X-Sn-Servicetimems
X-Backend-State
X-Wikidot-Static-Cache
X-Csrf-Jwt
X-Request-Start
X-Reqid
X-VarnishDD-TTL
X-Generated-In
X-Request-URI
X-FC-Vary-Parameters
X-Developers
X-VServer
X-Eu-Site
X-SVT-ORM-RULES
Wxu-Next-Region
Cf-Device-Type
C-Via
Cache-Host
AKAMAI
DB-Nickname
CACHE
CacheControlHeader
X-CSRF-Token
X-Ms-Version
X-Debug-Cache
X-Ms-Request-Id
Server-Ext
Server-Host
Server-Hostname
X-Varnish-Hits
User-Cache-Control
X-Policy
On-Server
X-NWS-UUID-VERIFY
Apple-News-Services-Handled
X-Method
Sever-Int
X-Scheme
X-Envoy-Decorator-Operation
UCS
Content-Disposition
X-Request-Host
X-Nginx-Cache-Key
V-Age
X-Origin-Expires
X-Fastly-Cache
X-Developer
X-Fastly-Backend
Apple-News-Services-Host
CloudFront-Viewer-Country
Cf-Bgj
Apple-News-Services-Request-Url
X-Cache-Tags
X-Core-Value
CDCHOST
X-IP
X-Var-Ttl
X-NC
X-Clientip
NGX
Apple-News-Services-Parsed-Url
X-Cms-Context
X-CUA
X-Generated-By
X-Varnish-Beresp-Grace
X-Dispatcher-Server
X-DPWN-IS-SECURE
X-SIPLIST1
X-Gzip
X-TX-ID
X-WADP-Cache
X-Li-Fabric
Fastly-SWR
X-Li-Pop
X-Esi-Check
X-Block-Status
X-Branch-Name
X-Cache-Debug
X-LI-UUID
X-DefElseHash
X-DefHash
X-VG-TLSProxy
X-Loc
X-B3-Spanid
X-Cache-Id
X-Cache-Expires
X-Varnish-Remaining-TTL
X-Old-Content-Length
Fastly-SIE
Location
X-Ratelimit-Reset
X-Varnish-CookieINHashed-On
X-Hnp-Log
NM-Fastcgi-Cache
X-Rebelmouse-Cache-Control
X-Gen-Mode
X-Variation
X-GoCache-CacheStatus
X-Varnish-CookieHashed-On
X-Rebelmouse-Surrogate-Control
IsBot
Is-Eu
X-Fmm-Version
Origin
X-TrackingId
True-Client-Country-4JS
Platform
Vix-Hermes-Req-Id
Web-Mar-Node
X-NU-AKA-ACS-Version
X-Host-Name
X-Origin
X-Clara-WADP
X-Servername
X-Platform-Server
Adler-Geo
Rt-Fastcgi-Cache
X-Varnish-Beresp-Status
X-Varnish-Beresp-Ttl
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Hash
X-Gamma-Serve
X-Varnish-Url
X-NCache
CDN-CachedAt
CDN-EdgeStorageId
CDN-PullZone
X-CS
X-Slack-Backend
CDN-RequestId
Fastly-Drupal-HTML
CDN-Cache
CDN-Uid
CDN-RequestCountryCode
X-App-Version
Url
X-Core-Mission
X-Refresh
X-NAPM-TraceId
S-Rt
X-Response-By
X-Varnish-Cacheable
X-Proxy-Cachei7
X-PF-Uncompressing
X-Aicache-OS
Pics-Label
X-EC-Lua
HostName
X-Mvc-Supplant-OutputCached
Xkeyi7
X-CDN-Forward
Content-Secure-Policy
Cross-Origin-Window-Policy
X-BBXSRF
N-Cache
X-CACHE-GROUP
X-Sucuri-Cache
X-Cdn-Forward
X-Cache-2
Ohc-File-Size
X-LB-ID
X-B3-SpanId
X-TIME
Cteonnt-Length
X-Cc-Req-Id
X-Cache-ASPX
X-Via-Popn
X-Via-Poph
X-Via-Popv
X-Esi
D-Cc-Upstream
X-FireWall-Protection
X-Cc-Via
X-DC
X-Contensis-Viewer-Groups
X-Varnish-Authentication
Sid
X-Wa
Esi-Enabled
MIME-Version
X-Servedbyhost
X-Tb-Optimization-Total-Bytes-Saved
X-Svr
X-RateLimit-Limit
X-Error
X-Server-IP
XServer
Source
X-TA-CDN-Provider
X-Epic-Correlation-Id
X-Srv
Hostname
GeoIp-Country-Code
X-Cache-Config
X-Unique-ID
Geoip-Latitude
X-Origin-Time
X-API-Version
X-Nyt-Route
X-FPC
X-Gdpr
X-Cs
X-TraceId
X-Webkit-CSP-Report-Only
X-VC
X-LI-Proto
Who
Req-Svc-Chain
X-SN
X-Nc
HitType
Ohc-Cache-HIT
X-Planisys-CDN-TTL
X-VCL-Version
X-Planisys-CDN-Rules
Server-Ttl
X-Webstats-RespID
X-Planisys-CDN-Cache
Country-Code
X-SB
Server-ID
X-NodeID
X-Fastly-Request-Id
X-NGINX-Cache
X-SD-PageType
X-Check-Cacheable
X-LiteSpeed-Cache-Control
X-HS-Status
X-Ua
Geo-Info
SID
Kp-EeAlive
Cmstype
Svr
Cmsid
EpKe-Alive
X-Vgn-Hpd-Reason
VivaBuild
X-Render-Time
X-Viewer-Country
Viewtype
X-BBC-Edge-Cache-Status
X-Served-From
NtCoent-Length
X-CSRF-TOKEN
X-HOST
Cache-Key
Request-ID
X-Worker
X-Auto-Login
A
X-RAMCache
X-Ftr-Cache-Host
X-Dynatrace-Js-Agent
X-UA
X-RSL
X-RPM
X-TIM-N
X-DSS
ProcessTime
Cache-Provider
X-Vcl-Version
Resin-Trace
X-FORWARDED-FOR
X-CACHE-KEY
X-DI
X-DB
X-DW
X-RPS
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-CCDN-CacheTTL
M-TraceId
Upgrade-Insecure-Requests
CDN
Server-Id
TDXMobile
X-CF-Powered-By
X-App
X-Cluster-Node
GeoIP-Latitude
GeoIP-Country-Code
Cross-Origin-Opener-Policy
X-Li-Proto
Arc-Country
X-Air-Source
Datacenter
X-Newrelic-Synthetics
Processtime
X-Internal-Host
X-Action
X-COUNTRY
X-FTR-Cache-Host
X-Oss-Cdn-Auth
X-Fpc
X-Vc
Filterid
Tcn
X-Presslabs-Stats
CF-Cached-On
OT-Force-Account-Verify
X-CLOUD-TRACE-CONTEXT
Mime-Version
Srv
X-Service
X-Geo
X-BBC-Origin-Response-Status
X-ServedByHost
WZWS-RAY
X-WA
X-HostName
X-HITS
X-Hello
X-ABtesting
X-MSEdge-Features
X-MSEdge-Flight
X-Flog
Cdn
X-Dw-Trace-Id
X-BACKEND-TTL
X-Cache-Tag
X-Pinterest-Sli-Endpoint-Name
X-ND-Cache
X-Via-PopH
X-Parent-Response-Time
X-Via-PopV
X-Via-PopN
X-Pinterest-Sli-Latency-Threshold
X-Pinterest-Sli-Response-Type
Proxy-Connection
X-Fastly-Backend-Reqs
NGB
X-Lb-Id
X-CACHE-AGE
X-Client-Ip
X-Forwarded-Site
X-Via-NSCOPI
FSS-Cache
W
X-Pf-Uncompressing
X-IN-APIGATEWAY
Dnion-Transfer-Encoding
X-IN-APIGATEWAYSSL
X-NGENIX-Cache
X-Edge-Location
X-JoinUs
X-SaId
X-Cdn-Request-ID
X-PHP-Backend
X-Oracle-DMS-ECID
DataCenter
X-Extlb
Media-Length
Vha6-Origin
URI
PICS-Label
CountryCode
X-Acc-Debug-Context
X-Acc-Rdl
Memcached
Surrogated-Key
X-ZONE
X-LiteSpeed-Tag
X-Region-Sid
X-Request-URL
X-Provided-By
X-Akamai-Pragma-Client-IP
Inserted-Into-Cache-At
X-MiniProfiler-Ids
Epwk-X-Cache
Mail-Subject
LB
X-Accel-Expires-Debug
We-Hiring
X-Pad
X-Req
X-Bc-Bl
X-PJAX-URL
X-Proxy-Upstream
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-VC-Cache
X-UnsetCookies
X-Depends-On
X-Date
X-Akamai-Request-ID
X-Swift-Error
Cf-Ipcountry
X-Tid
Content-Style-Type
X-Request-Url
X-Sigma-Backend
X-Rocket-Build-Number
X-Sigma
Env
X-Akamai-ERPolicy
X-Acquia-Site
X-ElasticPress-Query
X-Traceid
X-Acquia-Application-Trace
X-Csrf-Token
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Via-Edge
X-Via-SSL
X-Varnish-Beresp-TTL
Edge-Copy-Time
X-Ms-Meta-Staticbatchstarttime
X-Vcache
X-Ms-Meta-Originalurl
Content-Script-Type
X-ElasticPress-Search
X-Akamai-ERRuleID
X-B3-Parentspanid
X-Snapshot-Date
X-APP
X-Storefront-Renderer-Verified
X-Varnish-URL
X-Men
Environment
X-Redis-Count
X-Redis-Duration-Ms
X-Litespeed-Cache-Control
X-Zone
X-Debug-Cache-Store
X-C
NnCoection
Xet-Cookie
Ohc-Response-Time
Memory
Akamai-Age-Ms
Phost
X-Debug-Cache-Fetch
Time
X-ServerName