Threat Level: green Handler on Duty: Jim Clausing

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
X-XSS-Protection
Cf-Request-Id
CF-RAY
CF-Cache-Status
Last-Modified
Accept-Ranges
Link
Pragma
Expect-CT
ETag
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Cache-Status
X-Generator
X-Request-ID
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Content-Security-Policy
Content-Encoding
X-CDN
X-Envoy-Upstream-Service-Time
Status
X-Ua-Compatible
Feature-Policy
Access-Control-Expose-Headers
X-AspNetMvc-Version
X-Drupal-Dynamic-Cache
Access-Control-Max-Age
X-Xss-Protection
X-Via
Upgrade
Keep-Alive
X-Ws-Request-Id
X-Age
X-Turbo-Charged-By
X-AH-Environment
X-Robots-Tag
Request-Context
X-Proxy-Cache
EagleId
X-Cache-Group
X-Backend
Server-Timing
X-Hacker
X-Amz-Request-Id
Report-To
X-Server
Host-Header
X-Amz-Id-2
X-Server-Powered-By
X-UA-Device
Grace
X-Nginx-Cache-Status
X-LiteSpeed-Cache
X-Dns-Prefetch-Control
X-Varnish-Cache
X-Rq
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Page-Speed
Cf-Railgun
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
NEL
X-Amz-Version-Id
X-OneAgent-JS-Injection
Xkey
X-WebKit-CSP
Allow
X-Cache-Spec
X-Backend-Server
X-Host
X-Vhost
X-CST
X-Device
EagleEye-TraceId
X-Server-Id
Surrogate-Control
Request-Id
X-Dispatcher
Accept-CH
X-Node
X-Kinja-Server-Push
Content-Location
X-Response-Time
Accept-CH-Lifetime
X-Akam-SW-Version
X-Ruxit-JS-Agent
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-ASPNET-VERSION
X-Template
X-Ac
X-Language
X-Application-Context
X-Readtime
X-Country
X-Cloud-Trace-Context
X-Cache-Lookup
X-Mod-Pagespeed
MS-Author-Via
X-Origin-Cache
X-B3-TraceId
Rating
X-MS-InvokeApp
X-Cnection
X-HW
X-ORACLE-DMS-ECID
X-Url
X-Vname
X-PC
X-TtlSet
Accept-Ch
X-Clacks-Overhead
Edge-Control
X-FastCGI-Cache
X-GitHub-Request-Id
X-ESI
Accept-Ch-Lifetime
X-Trace
X-Middleton-Display
Pagespeed
Response
X-Middleton-Response
Display
X-Sol
X-Content-Type
X-D2id
Verso
X-Vcap-Request-Id
X-Kinja
X-GoogleNews-Bot
X-Exp-Variant
X-Cdn-Fetch
X-Exp-Id
Arr-Disable-Session-Affinity
X-Kinja-Server
X-Use-Magma
X-Kinja-Build
X-Kinja-Revision
X-Buckets
X-Goog-Hash
X-Varnish-TTL
X-Rack-Cache
X-Server-Name
Service-Worker-Allowed
X-Country-Code
X-Navigation-Version
X-VARITI-CCR
X-Abt-Application-Version
X-Amz-Rid
X-ORACLE-DMS-RID
X-Oneagent-Js-Injection
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
X-Cache-TTL
X-Client-IP
X-Powered-By-Plesk
SPRequestGuid
X-SharePointHealthScore
SPIisLatency
X-Fastly-Request-ID
SPRequestDuration
X-Release
X-MSEdge-Ref
X-Dw-Request-Base-Id
X-Element-Page-Cache
Fastly-Restarts
X-TTL
X-Cached
X-NF-Request-ID
MRF-Tech
Mrf-Cache-Status
Public-Key-Pins
X-B3-TraceId-Primal
RTSS
X-Origin-Upstream-Status
AR-PoweredBy
AR-CACHE
Ar-Sid
AR-ATIME
X-Edge
AR-Request-ID
X-Px
X-SRCache-Store-Status
Access-Control-Request-Method
X-SRCache-Fetch-Status
X-Webkit-CSP
X-LLID
Fusion-Template-Id
X-Powered-CMS
Fusion-Source
Fusion-Deployment-Id
Fusion-Content-Id
Fusion-Component-Id
Fusion-Content-Source
X-Upstream
X-Ezoic-Cdn
X-Ttl
Content-MD5
X-Pinterest-Direct
X-Jurisdiction
X-HP-Webp
X-Amz-Server-Side-Encryption
X-Mid
X-ECACHE
X-MCACHE
Charset
X-Content-Digest
X-Recruiting
S
X-Mg-S
Cache-Tag
X-PressLabs-Stats
X-Aspnetmvc-Version
X-Version
MicrosoftSharePointTeamServices
TCN
X-Debug
Front-End-Https
Fastcgi-Cache
X-XRDS-Location
X-Content-Security-Policy-Report-Only
X-Grace
X-T
Filters
Cache-Tags
X-Kinsta-Cache
Edge-Cache-Tag
Server-Node
X-Forwarded-Proto
X-Yandex-Sdch-Disable
X-Amzn-Trace-Id
X-Accel-Expires
X-Correlation-Id
X-Cache-Key
X-Logged-In
Server-Name
X-Id
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Nginx-Cache
X-Varnish-Age
Surrogate-Key
Powered-By-ChinaCache
X-Forwarded-For
X-DynaTrace
TP-L2-Cache
TP-Cache
X-Hits
X-B3-Sampled
X-Ser
X-DIS-Request-ID
X-Request-Processing-Time
X-Request-Handler-Origin-Region
X-Microsite
X-Request-Received
X-Shield-Request-Id
X-AppVersion
X-Amz-Replication-Status
X-Activity-Id
X-Az
X-Server-ID
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Hub-Id
X-F-Cache
X-HS-Content-Id
X-FTR-Request-ID
X-Goog-Storage-Class
Accept-Charset
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
X-Git-Hash
X-Origin-Server
X-Hostname
X-Respond-Thread
X-Geo-Country
X-LB-Cache
X-DataDome
Section-Io-Cache
X-Upgrade-Enabled
X-Rid
X-Frontend
X-Cache-Age
Access-Control-Allow-Method
Cleartype
X-Mobile-URL
X-TEC-API-ORIGIN
X-TEC-API-ROOT
Host
X-TEC-API-VERSION
Alternate-Protocol
X-Cdn
X-Type
Paypal-Debug-Id
Healthy
MS-CV
Cache
X-IPLB-Instance
X-Content-Options
ServerID
X-WebKit-CSP-Report-Only
X-Ruxit-Js-Agent
X-AOL-HN
X-Whom
X-Varnish-Backend
Payment
X-App-Environment
X-Is-Crawler
X-Providence-Cookie
X-Request-Guid
X-Route-Name
X-Flags
X-Debug-Info
X-Aspnet-Duration-Ms
X-B-Cache
X-Cache-Action
X-TT
X-Signature
X-VCache
X-Seen-By
Fastcgi-Useragent
X-Page-Id
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Jobs
X-Mobile
X-N
X-Source
X-NWS-LOG-UUID
X-RateLimit-Remaining
X-Load-Cache
X-XRDS-LOCATION
X-Browser-Type
X-Cached-By
X-Via-JSL
X-Akamai-Edgescape
Version
X-Time
X-FB-Debug
Nel
X-Litespeed-Cache
DynaTrace
Viewport
X-Daa-Tunnel
X-Cache-Rule
X-Cache-Operation
X-Accel-Buffering
Refresh
X-Rule
X-Response-Served-From
X-Original-Request-Id
X-Proxy
X-Framework
Realpath
DC
X-Zen-Fury
X-Drupal-Cache-Tags
X-Tt-Trace-Host
X-Cacheable-TTL
X-Instance
X-ProcessESI
Referer-Policy
X-Tt-Trace-Tag
X-RemovedCookies
GEO-INFO
X-Fastcgi-Cache
X-RTag
Ms-Operation-Id
X-Region
X-Real-IP
Access-Control-Request-Headers
X-UUID
X-HTML-Minification-Powered-By
X-Cache-Time
X-Contextid
X-Environment-Context
X-FW-Hash
X-FW-Dynamic
X-Drupal-Cache-Contexts
X-Yottaa-Metrics
X-Distributor
X-FW-Serve
X-Yottaa-Optimizations
X-L-Path
X-FW-Server
X-FW-Type
X-FW-Static
X-Page-View
X-Cache-Expired-At
X-Node-Name
X-Wix-Request-Id
Eomportal-Instance
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-B
Node
Liferay-Portal
X-Cluster-Name
Countrycode
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
X-Tumblr-User
X-G
X-Tumblr-Pixel
X-Cache-Control
X-Content-Powered-By
X-IPS-LoggedIn
X-User-Agent
X-Amz-Meta-S3cmd-Attrs
X-Cache-Hit
X-Tumblr-Pixel-2
Webserver
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
SRV
Section-Io-Origin-Status
Section-Io-Id
Server-Info
From-Origin
Protected
X-App-Server
X-Pass-Why
X-Revision
X-Ratelimit-Limit
X-Protected-By
Ec-Rule-Version
X-Backend-Name
X-Cache-Server
Frame-Options
Cache-Status
X-Oracle-Dms-Rid
X-FireWall-Port
X-Hyper-Cache
X-RN-RSRV
Retry-After
X-Mode
X-Endurance-Cache-Level
Meta-Geo
X-Hl-Ver
X-Handled-By
X-ES-SERVER
X-UPSTREAM-Address
X-Storage
X-Www-Served-By
X-Soup
X-Adobe-Loc
X-Forwarded-Host
X-Site-Version
X-FB-TRIP-ID
X-Locale
X-Adobe-Content
CF-IPCountry
X-NYM-Debug-Backend
Cache-Tv-Group
Country
Decoy-Debug-Key
X-Cache-Grace
TWC-GeoIP-LatLong
X-Format
Decoy-Debug-Status
X-Web-Node
X-Be
Webcakes-App-Name
Fastly-SSL
Webcakes-Region
TWC-Privacy
X-Human
Webcakes-App-Version
TWC-Device-Class
X-Via-CDN
TWC-Locale-Group
TWC-Connection-Speed
X-Section
X-Access
Property-Id
X-Origin-Hint
X-Varnishpool
X-Pubstack
Decoy-Debug-TTL
TWC-GeoIP-Country
X-FW-Version
X-BYPASS-REASON
X-Labrador-Cache-Channel
X-OCL
X-PCL
X-ApacheServer
Selected-Fe
Azure-SiteName
Azure-RegionName
Azure-SlotName
Azure-Version
Cache-Name
X-PERF
X-PHP-Host
X-Timing-Wait
X-SayCDN-TTL
X-TT-LOGID
X-UA-Device-Type
X-Uri
X-Say-TTL
X-Say-Cacheable
X-Proxy-Build
X-Proto
X-ProxyCache-Key
X-ProxyCache-Status
X-Redis-Cache
Azure-InstanceId
X-Origin-Date
X-FTR-Backend
X-FTR-Backend-Server
X-Varnish-Ttl
X-Country-Code-Real
X-No-Session
S-Cnection
X-LAGOON
X-S-Maxage
X-FTR-Cache-Status
X-FTR-Realm
X-Via-Fastly
X-WA-Info
X-Sql-Duration-Ms
X-Sql-Count
X-FTR-DC
X-Server-W
X-AIR-PT
X-FTR-Balancer
X-Loop
X-Qloud-Router
X-R9-Blue-Green-Version
X-LJ-Flow-ID
X-Hosted-By
X-AWS-Id
Mn-Server-Ip
X-TNCMS
X-VWS-Id
X-Status
X-Cache-TTL-Remaining
X-Cluster
X-FTR-Expires
X-Request-Time
X-Xfnlog-Site
X-Zipkin-Id
X-Alternate-Cache-Key
X-Sorting-Hat-PodId
X-CCM
X-Routing-Service
X-Shopify-Stage
X-ShopId
X-ShardId
X-Storefront-Renderer-Rendered
X-MP-GENERATED-AT
X-Proxied
X-Sorting-Hat-ShopId
Cache-Hits
X-Ratelimit-Remaining
X-Cache-Var
X-Rendered-As
X-Is-Bot
X-Cache-Var-Map
X-Dynatrace
X-Air-Hostname
X-Unique-Id
AMP-Access-Control-Allow-Source-Origin
X-Detected-As
X-SRV
Xserver
X-EdgeConnect-Cache-Status
X-Amzn-Remapped-Content-Length
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Cache-Host
X-Device-Type
Apigw-Requestid
X-Webkit-Csp
X-Info
X-Nginx-Cache
X-Microcachable
SD-X-WS
X-GEO
X-B3-Traceid
X-Dc
X-Cache-Enabled
X-Tec-Api-Origin
X-ID
X-Tec-Api-Root
X-Tec-Api-Version
X-Time-Microsecs
X-Content-Age
Amp-Access-Control-Allow-Source-Origin
X-Cache-Backend
X-Backend-TTL
X-Debug-IsConnected
X-Varnish-Server
Tracecode
X-Debug-IsPreview
X-Platform
X-Varnish-Grace
X-ServerID
X-Azure-Ref
X-APP-VERSION
X-DynaTrace-JS-Agent
X-Backend-Host
Uber-Trace-Id
DSUID
X-Erf-Stays-Bingo-Pdp-Web
X-GG-Cache-Date
X-Oss-Server-Time
X-Oss-Storage-Class
X-Tb
X-Oss-Request-Id
X-NewRelic-App-Data
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
Akamai-GRN
X-Sucuri-ID
Arc-Version
X-Proxy-Cache-Status
PB-PID
X-BCube-Filmed-By
PB-RID
X-ATG-Version
Backend
X-Origin-Response-Time
X-Akamai-Transformed
X-Trace-Id
X-Magnolia-Registration
X-Correlation-ID
X-Vdms-Version
X-A-Ccd
X-A-Wwc
X-CF-Lambda-Fn
X-From
X-Aed
X-Varnish-Cache-Hits
X-CF-Lambda-Version
X-A-Dcw
X-Cache-NE
X-VG-WebCache
X-B-Cookie
X-Destination
X-Connection-Hash
X-D
X-Device-Os
Thinkindot-Control
X-ARC
X-A-Dam
X-Fetched-On
Thinkindot-CacheControl-Type
X-External-Request-Id
X-A
X-Application
SR-User-Adfree
Instruction
X-Origin-TTL
X-PAYTM-SRV-ID
X-PBS-Appsvrname
X-Processor
X-Origin-CC
Lfy
X-Level-Front-Cache
X-Location
X-Matched-Rule
X-Vdms-Path
X-Request-UUID
X-Rewrite-Enabled
Fastcgi-X-Cache-Version
X-Session-Fingerprint
Expiry
X-SRCache-Key
DCR-Processing-Time-Ms
X-ScT
X-S-Cookie
X-Rojux
X-S
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
MD5-Digest
Machine
X-A-Dgt
X-Trv-Group
DCR-Decision-By
Xc-Version
X-Thinkindot-L3
Meta-Geo-Continent
X-RCS-CacheZone
X-VG-WebServer
X-Generated-On
Thinkindot-CacheControl
ServedBy
T-Server
X-Generation-Time
Pramga
Rendered-Blocks
Odigeo-Trace-Id
Path
X-Cache-Remote
Mobile-Detection-Method
X-Cache-NGX
X-Varnish-Hostname
X-Cache-PHP
X-Adobe-Source
Fastly-Backend-Name
Wxu-Next-Hostname
Ssr
Magicmarker
Pagetype
Host-ID
L
PFcat
HA-Ipaddr
Ha-Gx-Prefs
Gh-Request-Id
Wxu-Next-Commit
L5d-Success-Class
Locid
X-VarnishDD-TTL
X-Micro-Cache
X-Swa-Ws
X-Mvc-Supplant-Cachable
X-Node-Id
X-JWT-State
X-Is-Gdpr
X-Thanos
X-Wikidot-Static-Cache
X-HS-Content-Campaign-Id
X-Irp-Debug
X-OVcl
X-OVcl-Cache
X-VServer
X-Skip-Cache
X-Sn-Servicetimems
X-SVT-ORM-RULES
X-Wikidot-Backend
X-Request-URI
X-Owner
X-Reqid
X-Request-Start
X-HN
X-Has-Esi
X-Cdn-Origin
X-CGP
X-Csrf-Jwt
X-Developers
X-Cache-Info
X-Cache-Date
X-Backend-State
X-Bip
X-Cache-Bucket
X-Eu-Site
X-FC-Vary-Parameters
Release
BehaviorPad-Version
X-Geo-Header
X-GeoIP
X-Tumblr-Pixel-3
X-User
X-GeoIP-City
X-Generated-In
X-SVT-ORM-VERSION
X-Azure-Ref-OriginShield
Wxu-Next-Region
Cache-Host
CacheControlHeader
C-Via
AKAMAI
CACHE
X-Ms-Version
Cf-Device-Type
X-Ms-Request-Id
DB-Nickname
X-Debug-Cache
X-CSRF-Token
UCS
Cf-Bgj
X-Cache-Tags
X-Method
V-Age
X-Origin-Expires
Server-Ext
X-Policy
Server-Host
Server-Hostname
X-Scheme
Sever-Int
X-Clientip
X-Fastly-Backend
X-Envoy-Decorator-Operation
X-Fastly-Cache
X-Varnish-Hits
X-NC
X-Generated-By
X-Developer
User-Cache-Control
X-IP
X-Cms-Context
X-Core-Value
X-Var-Ttl
X-CUA
Content-Disposition
X-Nginx-Cache-Key
CloudFront-Viewer-Country
X-NWS-UUID-VERIFY
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
X-Request-Host
CDCHOST
On-Server
Apple-News-Services-Request-Url
NGX
X-Varnish-Beresp-Grace
X-Rebelmouse-Cache-Control
IsBot
X-Clara-WADP
X-Li-Fabric
X-B3-Spanid
X-VG-TLSProxy
X-Cache-Id
X-Loc
X-Branch-Name
X-Block-Status
X-LI-UUID
Origin
X-Cache-Expires
X-Cache-Debug
Is-Eu
X-DefHash
X-Varnish-CookieINHashed-On
X-Hnp-Log
X-Fmm-Version
X-Variation
X-Gen-Mode
X-GoCache-CacheStatus
X-Varnish-CookieHashed-On
Fastly-SIE
X-Varnish-Remaining-TTL
X-WADP-Cache
X-DefElseHash
X-Rebelmouse-Surrogate-Control
X-Dispatcher-Server
X-DPWN-IS-SECURE
Fastly-SWR
X-Esi-Check
X-TX-ID
X-Li-Pop
X-Old-Content-Length
X-Origin
True-Client-Country-4JS
Vix-Hermes-Req-Id
X-Host-Name
Web-Mar-Node
X-SIPLIST1
X-Servername
Platform
Adler-Geo
X-Platform-Server
Rt-Fastcgi-Cache
X-Ratelimit-Reset
NM-Fastcgi-Cache
X-NU-AKA-ACS-Version
X-TrackingId
Location
X-Gzip
X-Varnish-Beresp-Status
X-Varnish-Beresp-Ttl
X-CS
CDN-PullZone
CDN-EdgeStorageId
X-Hash
X-Gamma-Serve
X-Varnish-Url
Fastly-Drupal-HTML
CDN-CachedAt
CDN-RequestId
X-NCache
CDN-RequestCountryCode
X-Goog-Meta-Goog-Reserved-File-Mtime
CDN-Uid
CDN-Cache
X-Slack-Backend
X-App-Version
X-Core-Mission
X-NAPM-TraceId
S-Rt
X-Response-By
X-Refresh
X-EC-Lua
X-Varnish-Cacheable
Url
X-Proxy-Cachei7
X-PF-Uncompressing
X-Mvc-Supplant-OutputCached
Pics-Label
HostName
Xkeyi7
X-Aicache-OS
X-CDN-Forward
Content-Secure-Policy
Cross-Origin-Window-Policy
X-URL
X-CACHE-GROUP
X-Sucuri-Cache
N-Cache
X-BBXSRF
X-Cdn-Forward
X-Cache-2
Ohc-File-Size
X-LB-ID
X-B3-SpanId
X-TIME
Cteonnt-Length
X-Cc-Req-Id
X-Via-Popn
X-Via-Poph
X-Cache-ASPX
X-Via-Popv
X-Varnish-Authentication
X-DC
X-Cc-Via
X-FireWall-Protection
D-Cc-Upstream
X-Esi
X-Contensis-Viewer-Groups
Sid
MIME-Version
X-Tb-Optimization-Total-Bytes-Saved
X-Svr
X-Servedbyhost
X-Wa
Esi-Enabled
X-RateLimit-Limit
X-Epic-Correlation-Id
X-Error
Source
X-TA-CDN-Provider
X-Server-IP
XServer
X-Srv
Hostname
Geoip-Latitude
X-Origin-Time
X-Nyt-Route
X-Cache-Config
X-FPC
X-Gdpr
X-API-Version
X-Unique-ID
X-Cs
X-Webkit-CSP-Report-Only
X-TraceId
X-Nc
X-SN
Who
GeoIp-Country-Code
X-LI-Proto
HitType
Req-Svc-Chain
X-VC
Ohc-Cache-HIT
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-VCL-Version
X-Webstats-RespID
Server-Ttl
Country-Code
X-HS-Status
X-SB
Server-ID
X-NodeID
X-Fastly-Request-Id
X-NGINX-Cache
X-SD-PageType
X-LiteSpeed-Cache-Control
X-Check-Cacheable
SID
X-Ua
Geo-Info
Svr
Cmsid
Cmstype
Kp-EeAlive
X-Vgn-Hpd-Reason
X-BBC-Edge-Cache-Status
EpKe-Alive
X-Render-Time
X-Viewer-Country
Viewtype
X-Served-From
VivaBuild
NtCoent-Length
X-HOST
X-CSRF-TOKEN
X-Worker
X-Auto-Login
A
Cache-Key
Request-ID
X-RAMCache
X-Ftr-Cache-Host
X-UA
X-Dynatrace-Js-Agent
ProcessTime
X-RPS
Cache-Provider
X-Vcl-Version
X-RSL
X-FORWARDED-FOR
X-DB
GeoIP-Country-Code
X-DSS
Resin-Trace
X-DW
X-DI
X-RPM
X-TIM-N
X-CACHE-KEY
X-CCDN-CacheTTL
M-TraceId
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
Upgrade-Insecure-Requests
X-App
X-Cluster-Node
Cross-Origin-Opener-Policy
TDXMobile
GeoIP-Latitude
CDN
Server-Id
X-Air-Source
X-Li-Proto
X-CF-Powered-By
Arc-Country
X-Newrelic-Synthetics
Datacenter
X-Internal-Host
X-Action
Processtime
X-COUNTRY
X-FTR-Cache-Host
X-Fpc
X-Vc
Tcn
X-Oss-Cdn-Auth
Filterid
X-CLOUD-TRACE-CONTEXT
CF-Cached-On
OT-Force-Account-Verify
Srv
X-Service
X-WA
X-ServedByHost
Mime-Version
X-Geo
WZWS-RAY
Proxy-Connection
X-BBC-Origin-Response-Status
X-HITS
X-HostName
X-MSEdge-Flight
X-Hello
X-MSEdge-Features
Cdn
X-Flog
X-ABtesting
X-Dw-Trace-Id
X-Cache-Tag
X-Pinterest-Sli-Endpoint-Name
X-Pinterest-Sli-Latency-Threshold
X-BACKEND-TTL
X-ND-Cache
X-Via-PopV
X-Via-PopN
X-Via-PopH
X-Parent-Response-Time
X-Pinterest-Sli-Response-Type
X-Fastly-Backend-Reqs
NGB
X-Lb-Id
X-Client-Ip
X-CACHE-AGE
X-Via-NSCOPI
X-Forwarded-Site
W
FSS-Cache
X-Pf-Uncompressing
X-IN-APIGATEWAYSSL
Dnion-Transfer-Encoding
X-IN-APIGATEWAY
X-JoinUs
X-PHP-Backend
X-Edge-Location
X-NGENIX-Cache
X-Cdn-Request-ID
X-SaId
DataCenter
Vha6-Origin
X-Oracle-DMS-ECID
PICS-Label
Media-Length
URI
X-Presslabs-Stats
X-Extlb
X-Acc-Debug-Context
X-Acc-Rdl
CountryCode
Surrogated-Key
We-Hiring
X-LiteSpeed-Tag
Epwk-X-Cache
X-MiniProfiler-Ids
X-Provided-By
X-Swift-Error
LB
Memcached
X-Request-URL
Mail-Subject
X-ZONE
X-Date
X-Req
X-Accel-Expires-Debug
X-RateLimit-Remaining-Second
X-UnsetCookies
X-VC-Cache
Inserted-Into-Cache-At
X-Akamai-Pragma-Client-IP
X-RateLimit-Limit-Second
X-Region-Sid
X-Bc-Bl
X-Proxy-Upstream
X-Depends-On
X-Akamai-Request-ID
X-Pad
X-PJAX-URL
Cf-Ipcountry
Content-Script-Type
X-Sigma-Backend
X-Rocket-Build-Number
Env
X-Sigma
X-Request-Url
X-ElasticPress-Search
X-Via-SSL
X-Acquia-Application-UUID
X-Via-Edge
X-Csrf-Token
X-Acquia-Purge-Tags
X-Acquia-Site
Edge-Copy-Time
Content-Style-Type
X-B3-Parentspanid
X-ElasticPress-Query
X-Varnish-Beresp-TTL
X-Acquia-Application-Trace
X-Akamai-ERPolicy
X-Vcache
X-Akamai-ERRuleID
X-Traceid
X-Ms-Meta-Staticbatchstarttime
X-Ms-Meta-Originalurl
X-Varnish-URL
X-Redis-Duration-Ms
X-Men
X-Redis-Count
X-APP
X-Snapshot-Date
X-Storefront-Renderer-Verified
X-Tid
Environment
X-Zone
X-Debug-Cache-Fetch
X-C
NnCoection
Ohc-Response-Time
Xet-Cookie
Akamai-Age-Ms
Memory
X-ServerName
X-Debug-Cache-Store
Phost
Time
X-Litespeed-Cache-Control