Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
X-XSS-Protection
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
P3P
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Xss-Protection
X-Request-ID
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-Iinfo
Content-Encoding
X-CDN
X-Ua-Compatible
X-Envoy-Upstream-Service-Time
X-AspNetMvc-Version
Feature-Policy
Status
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Access-Control-Max-Age
X-Via
Upgrade
Keep-Alive
X-Ws-Request-Id
X-Age
X-Turbo-Charged-By
X-AH-Environment
X-Robots-Tag
Request-Context
X-Proxy-Cache
EagleId
X-Cache-Group
Server-Timing
X-Backend
X-Hacker
Report-To
X-Amz-Request-Id
X-Server
Host-Header
X-Amz-Id-2
X-Server-Powered-By
Grace
X-Nginx-Cache-Status
X-UA-Device
X-Dns-Prefetch-Control
P3p
X-LiteSpeed-Cache
X-Rq
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Page-Speed
Cf-Railgun
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
NEL
X-Amz-Version-Id
X-Cache-Spec
X-WebKit-CSP
Xkey
Allow
X-Device
X-CST
X-Backend-Server
X-Vhost
X-Host
EagleEye-TraceId
X-Server-Id
Surrogate-Control
Request-Id
X-Dispatcher
X-Node
Content-Location
X-Response-Time
X-Akam-SW-Version
X-Ruxit-JS-Agent
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Accept-CH
Accept-CH-Lifetime
X-ASPNET-VERSION
X-Ac
X-Template
X-Application-Context
X-Language
X-Country
X-Cache-Lookup
X-Cloud-Trace-Context
X-Mod-Pagespeed
X-Readtime
MS-Author-Via
X-B3-TraceId
X-Origin-Cache
Accept-Ch
Rating
X-Cnection
X-MS-InvokeApp
X-HW
X-Url
Accept-Ch-Lifetime
X-PC
X-TtlSet
X-Vname
X-ORACLE-DMS-ECID
X-Clacks-Overhead
X-GitHub-Request-Id
Edge-Control
X-ESI
X-Trace
X-Middleton-Display
X-Middleton-Response
X-Sol
Response
Pagespeed
Display
X-FastCGI-Cache
X-Content-Type
X-D2id
X-Vcap-Request-Id
X-Exp-Variant
X-Kinja-Server
X-Use-Magma
Arr-Disable-Session-Affinity
X-Kinja-Revision
X-Kinja-Build
X-Exp-Id
X-Kinja
X-Cdn-Fetch
X-GoogleNews-Bot
Verso
X-Goog-Hash
X-Buckets
X-Rack-Cache
X-ORACLE-DMS-RID
X-Country-Code
X-Server-Name
Service-Worker-Allowed
X-Navigation-Version
X-Varnish-TTL
X-VARITI-CCR
X-Abt-Application-Version
X-Amz-Rid
X-Fastly-Request-ID
X-Powered-By-Plesk
X-Webkit-CSP
X-Client-IP
Pinterest-Generated-By
Pinterest-Version
X-Pinterest-Rid
X-Cache-TTL
X-Kinja-Server-Push
X-SharePointHealthScore
SPRequestGuid
X-Release
Fastly-Restarts
X-MSEdge-Ref
X-Element-Page-Cache
SPIisLatency
X-Dw-Request-Base-Id
SPRequestDuration
X-Oneagent-Js-Injection
X-Cached
X-NF-Request-ID
X-Ttl
Public-Key-Pins
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
RTSS
AR-ATIME
AR-CACHE
AR-Request-ID
X-Edge
Ar-Sid
AR-PoweredBy
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Access-Control-Request-Method
X-LLID
X-Powered-CMS
X-Origin-Upstream-Status
X-Px
X-Ezoic-Cdn
X-TTL
Fusion-Template-Id
Fusion-Content-Source
Fusion-Content-Id
Fusion-Source
Fusion-Deployment-Id
Fusion-Component-Id
X-Upstream
Content-MD5
X-HP-Webp
X-Jurisdiction
Cache-Tag
X-ECACHE
X-MCACHE
X-Mid
S
X-Recruiting
X-Mg-S
X-Content-Digest
Charset
X-Version
X-Amz-Server-Side-Encryption
X-PressLabs-Stats
TCN
Fastcgi-Cache
X-Pinterest-Direct
MicrosoftSharePointTeamServices
X-T
X-Kinsta-Cache
X-Content-Security-Policy-Report-Only
Front-End-Https
X-Debug
Filters
X-Id
Cache-Tags
X-Grace
Edge-Cache-Tag
Server-Node
X-Logged-In
X-Accel-Expires
X-Forwarded-Proto
X-DynaTrace
X-Forwarded-For
X-Correlation-Id
X-Amzn-Trace-Id
Nginx-Cache
Server-Name
X-Yandex-Sdch-Disable
Surrogate-Key
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
TP-L2-Cache
TP-Cache
X-Varnish-Age
X-XRDS-Location
X-B3-Sampled
X-Request-Received
X-Request-Processing-Time
X-Server-ID
X-Microsite
X-Ser
X-Request-Handler-Origin-Region
X-Hits
X-Shield-Request-Id
X-AppVersion
X-Activity-Id
X-DIS-Request-ID
X-Az
X-Cache-Key
X-Amz-Replication-Status
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Cache-Config
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-F-Cache
X-Litespeed-Cache
Accept-Charset
X-Origin-Server
Powered-By-ChinaCache
X-Git-Hash
X-Geo-Country
X-Respond-Thread
X-FTR-Request-ID
Cache
X-XRDS-LOCATION
X-Hostname
X-LB-Cache
X-Rid
Section-Io-Cache
X-Upgrade-Enabled
X-DataDome
X-Frontend
Alternate-Protocol
Access-Control-Allow-Method
X-Ruxit-Js-Agent
Host
X-Mobile-URL
X-Cache-Age
X-Seen-By
Cleartype
Paypal-Debug-Id
MS-CV
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-AOL-HN
X-IPLB-Instance
X-Time
Healthy
X-Type
X-Content-Options
X-Varnish-Backend
X-VCache
X-NWS-LOG-UUID
ServerID
X-App-Environment
X-Whom
X-Request-Guid
X-Route-Name
X-Is-Crawler
X-TT
X-Providence-Cookie
X-Aspnet-Duration-Ms
Payment
X-Flags
X-Cache-Action
X-Signature
X-B-Cache
X-Jobs
X-Page-Id
X-Debug-Info
Fastcgi-Useragent
X-Source
X-Fastcgi-Cache
X-WebKit-CSP-Report-Only
X-Load-Cache
X-N
X-RateLimit-Remaining
X-Mobile
X-Daa-Tunnel
X-Erf-Bev-Bev
X-FB-Debug
X-Browser-Type
X-Erf-Bev-Bev-Is-Generated
X-Via-JSL
Nel
X-Cached-By
Version
X-Akamai-Edgescape
X-Cache-Operation
X-Cache-Rule
Refresh
Viewport
X-Response-Served-From
X-Accel-Buffering
X-Rule
X-Original-Request-Id
DC
X-Wix-Request-Id
X-Proxy
X-Framework
X-Cacheable-TTL
X-Drupal-Cache-Tags
Ms-Operation-Id
Access-Control-Request-Headers
X-RemovedCookies
X-ProcessESI
X-RTag
X-Zen-Fury
DynaTrace
X-Real-IP
X-Contextid
X-Instance
Referer-Policy
Node
X-HTML-Minification-Powered-By
X-UUID
X-Cache-Time
X-Region
Realpath
X-Distributor
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Tt-Trace-Tag
X-Drupal-Cache-Contexts
X-Tt-Trace-Host
Eomportal-Instance
X-Page-View
GEO-INFO
X-FW-Hash
X-FW-Serve
X-FW-Dynamic
Countrycode
X-Cache-Expired-At
X-FW-Server
X-Cluster-Name
X-FW-Static
X-FW-Type
X-B
X-Environment-Context
VIX-Pulpo-Node
X-Cache-Control
X-L-Path
X-Content-Powered-By
VIX-Pulpo-Upstream-Status
X-IPS-LoggedIn
X-G
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-Pixel-1
Liferay-Portal
X-Tumblr-User
X-Cache-Hit
Server-Info
X-Node-Name
X-User-Agent
X-App-Server
X-Varnish-Ttl
X-Pass-Why
X-FireWall-Port
From-Origin
X-Tumblr-Pixel-2
Webserver
Section-Origin-Responded
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Io-Id
X-Ratelimit-Limit
Ec-Rule-Version
X-Protected-By
Protected
CF-IPCountry
X-Cache-Server
Xserver
SRV
X-Revision
X-Amz-Meta-S3cmd-Attrs
Frame-Options
X-Backend-Name
X-Www-Served-By
X-Endurance-Cache-Level
X-RN-RSRV
X-UPSTREAM-Address
X-Hl-Ver
X-Handled-By
X-Mode
Meta-Geo
X-ES-SERVER
X-Locale
X-Soup
Cache-Status
X-Site-Version
X-FB-TRIP-ID
X-Hyper-Cache
Cache-Tv-Group
X-Be
Country
X-Web-Node
X-Forwarded-Host
X-Varnishpool
X-Human
X-Cache-Grace
X-NYM-Debug-Backend
X-Storage
X-Origin-Date
X-Request-Time
X-Redis-Cache
X-Origin-Hint
X-Pubstack
X-ProxyCache-Key
X-ProxyCache-Status
X-Proxy-Build
Azure-SiteName
Selected-Fe
TWC-Connection-Speed
Property-Id
X-Labrador-Cache-Channel
Retry-After
X-Timing-Wait
TWC-Device-Class
TWC-GeoIP-Country
Webcakes-App-Name
X-Uri
TWC-Privacy
Webcakes-Region
TWC-GeoIP-LatLong
TWC-Locale-Group
Webcakes-App-Version
Fastly-SSL
Azure-RegionName
X-Proto
Azure-InstanceId
X-UA-Device-Type
X-TT-LOGID
X-BYPASS-REASON
Decoy-Debug-TTL
Azure-SlotName
Decoy-Debug-Key
Decoy-Debug-Status
Azure-Version
Cache-Name
X-PHP-Host
X-Access
X-AIR-PT
X-OCL
X-Hosted-By
X-Loop
X-No-Session
X-FW-Version
X-Format
X-PCL
X-Sql-Duration-Ms
X-WA-Info
X-SayCDN-TTL
X-Via-Fastly
X-Say-Cacheable
X-Section
X-Server-W
X-Adobe-Loc
X-Adobe-Content
X-S-Maxage
X-MP-GENERATED-AT
X-TNCMS
X-Say-TTL
X-Sql-Count
X-Status
X-R9-Blue-Green-Version
X-ApacheServer
X-AWS-Id
X-PERF
X-VWS-Id
X-LAGOON
X-LJ-Flow-ID
X-Shopify-Stage
X-ShopId
X-Nginx-Cache
X-ShardId
X-Alternate-Cache-Key
Mn-Server-Ip
X-Cluster
X-Sorting-Hat-ShopId
X-Via-CDN
X-Sorting-Hat-PodId
X-Storefront-Renderer-Rendered
X-Cache-TTL-Remaining
X-Zipkin-Id
X-Routing-Service
X-Proxied
X-Qloud-Router
X-Device-Type
X-Rendered-As
X-Xfnlog-Site
X-CCM
X-Is-Bot
X-Debug-IsConnected
X-Debug-IsPreview
Cache-Hits
S-Cnection
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-Realm
X-FTR-DC
X-Country-Code-Real
X-Ratelimit-Remaining
X-Info
X-FTR-Expires
Apigw-Requestid
X-Cdn
X-SRV
X-Detected-As
X-Varnish-Grace
X-Dc
X-Varnish-Server
X-Cache-Var-Map
X-Cache-Enabled
X-Cache-Host
X-Cache-Var
X-Amz-Apigw-Id
X-Air-Hostname
X-EdgeConnect-Cache-Status
X-Microcachable
AMP-Access-Control-Allow-Source-Origin
X-Amzn-Remapped-Content-Length
X-Amzn-RequestId
X-Content-Age
X-GG-Cache-Date
Amp-Access-Control-Allow-Source-Origin
X-Unique-Id
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
X-Aspnetmvc-Version
X-Platform
SD-X-WS
X-Azure-Ref
Tracecode
X-GEO
X-DynaTrace-JS-Agent
Uber-Trace-Id
X-Backend-Host
X-TA-CDN-Provider
X-Time-Microsecs
X-CSRF-Token
X-Backend-TTL
X-Proxy-Cache-Status
X-Cache-Backend
X-ServerID
Akamai-GRN
X-NWS-UUID-VERIFY
X-Tb
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
Backend
X-Oss-Object-Type
X-ATG-Version
X-Oracle-Dms-Rid
X-Correlation-ID
X-Trace-Id
DSUID
X-BCube-Filmed-By
X-APP-VERSION
X-Dynatrace
X-Akamai-Transformed
X-Erf-Stays-Bingo-Pdp-Web
ServedBy
X-RCS-CacheZone
X-NewRelic-App-Data
X-Varnish-Hostname
DCR-Processing-Time-Ms
DCR-Decision-By
SR-User-Adfree
T-Server
MD5-Digest
X-Cache-NGX
X-Cache-PHP
Machine
Expiry
Meta-Geo-Continent
Lfy
Odigeo-Trace-Id
Pramga
Path
Mobile-Detection-Method
Instruction
Rendered-Blocks
Release
Thinkindot-CacheControl
Fastcgi-X-Cache-Version
BehaviorPad-Version
X-Aed
X-Rewrite-Enabled
X-Request-UUID
X-Rojux
X-S
X-S-Cookie
X-Processor
X-PBS-Appsvrname
X-Matched-Rule
X-Origin-CC
X-Origin-TTL
X-PAYTM-SRV-ID
X-ScT
X-Session-Fingerprint
X-VG-WebServer
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-VG-WebCache
X-Vdms-Version
X-SRCache-Key
X-Thinkindot-L3
X-Trv-Group
X-Vdms-Path
X-Location
X-Level-Front-Cache
X-Varnish-Cache-Hits
X-A-Wwc
X-Application
X-ARC
X-B-Cookie
X-A-Dgt
X-A-Dcw
Thinkindot-Control
X-A
X-A-Ccd
X-A-Dam
X-Cache-NE
X-CF-Lambda-Fn
X-Fetched-On
X-From
X-Generation-Time
X-GeoIP-City
X-External-Request-Id
X-Device-Os
X-CF-Lambda-Version
X-Connection-Hash
X-D
X-Destination
Thinkindot-CacheControl-Type
X-Generated-On
X-Sucuri-ID
Arc-Version
X-Magnolia-Registration
PB-PID
PB-RID
HostName
X-Debug-Cache
X-JWT-State
X-Irp-Debug
X-HS-Content-Campaign-Id
Fastly-Backend-Name
X-Is-Gdpr
X-App-Version
Cache-Host
C-Via
X-GeoIP
Cf-Device-Type
X-Tumblr-Pixel-3
UCS
X-Sn-Servicetimems
X-Thanos
X-Has-Esi
X-Swa-Ws
Pagetype
X-Geo-Header
X-B3-Traceid
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-FC-Vary-Parameters
Gh-Request-Id
X-Micro-Cache
Host-ID
Ssr
X-TrackingId
CacheControlHeader
X-Azure-Ref-OriginShield
X-Bip
X-OVcl
X-Origin-Response-Time
X-Skip-Cache
X-Cache-Bucket
X-Cdn-Origin
X-Reqid
X-Ms-Request-Id
X-Ms-Version
X-VServer
X-Node-Id
X-OVcl-Cache
AKAMAI
X-Mvc-Supplant-Cachable
X-Owner
X-B3-SpanId
X-Generated-By
X-Cache-Date
Server-Ext
Wxu-Next-Region
X-Developers
X-Cache-Tags
X-Request-Host
X-Developer
PFcat
Server-Hostname
DB-Nickname
X-Generated-In
Sever-Int
X-Fastly-Cache
Wxu-Next-Commit
X-Fastly-Backend
X-Core-Value
X-Csrf-Jwt
X-Eu-Site
X-Scheme
X-CUA
Wxu-Next-Hostname
X-Adobe-Source
X-Clientip
X-Cms-Context
X-Backend-State
X-CGP
Locid
X-Varnish-Beresp-Grace
HA-Ipaddr
X-Policy
X-HN
X-Wikidot-Static-Cache
Ha-Gx-Prefs
X-User
Content-Disposition
CloudFront-Viewer-Country
X-VarnishDD-TTL
X-IP
Server-Host
X-Varnish-Hits
L
X-NAPM-TraceId
X-Nginx-Cache-Key
X-TX-ID
X-Origin-Expires
NGX
X-Cdn-Forward
Magicmarker
X-Cache-Info
X-Var-Ttl
L5d-Success-Class
Location
On-Server
X-Wikidot-Backend
User-Cache-Control
X-ID
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Request-URI
V-Age
X-Ratelimit-Reset
Is-Eu
X-Esi-Check
X-Platform-Server
X-DPWN-IS-SECURE
X-Gzip
X-Clara-WADP
X-DefElseHash
Platform
X-Hash
X-Gamma-Serve
X-Gen-Mode
X-Goog-Meta-Goog-Reserved-File-Mtime
X-GoCache-CacheStatus
X-Dispatcher-Server
NM-Fastcgi-Cache
X-Fmm-Version
X-Method
X-Cache-Id
X-Branch-Name
X-Loc
X-Envoy-Decorator-Operation
X-Hnp-Log
X-DefHash
X-NU-AKA-ACS-Version
X-Variation
Rt-Fastcgi-Cache
Origin
IsBot
Web-Mar-Node
X-Varnish-Remaining-TTL
X-Varnish-CookieINHashed-On
X-Slack-Backend
Fastly-SWR
Fastly-SIE
X-Varnish-Beresp-Ttl
X-WADP-Cache
X-Varnish-Beresp-Status
CDCHOST
Fastly-Drupal-HTML
Cf-Bgj
X-Varnish-CookieHashed-On
X-CS
Adler-Geo
X-Cache-Expires
X-Block-Status
X-Li-Fabric
X-LI-UUID
X-Old-Content-Length
X-Origin
X-Li-Pop
X-SIPLIST1
X-Servername
X-VG-TLSProxy
Apple-News-Services-Request-Url
X-Cache-Debug
Apple-News-Services-Handled
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
CDN-Uid
Vix-Hermes-Req-Id
True-Client-Country-4JS
X-Request-Start
CDN-RequestId
CDN-PullZone
CDN-EdgeStorageId
CDN-CachedAt
CDN-Cache
X-EC-Lua
X-Core-Mission
CDN-RequestCountryCode
X-LB-ID
X-Mvc-Supplant-OutputCached
X-NCache
X-Aicache-OS
X-PF-Uncompressing
X-Cache-Remote
X-NC
Url
X-CACHE-GROUP
X-Refresh
X-Varnish-Url
Sid
X-Response-By
X-Varnish-Cacheable
S-Rt
Esi-Enabled
X-Via-Popn
X-Via-Poph
X-Via-Popv
X-Host-Name
X-FireWall-Protection
Xkeyi7
Pics-Label
X-Tb-Optimization-Total-Bytes-Saved
X-Proxy-Cachei7
X-Webkit-CSP-Report-Only
X-Nc
X-B3-Spanid
N-Cache
X-Unique-ID
X-BBXSRF
Who
X-Epic-Correlation-Id
Country-Code
Content-Secure-Policy
Req-Svc-Chain
Ohc-File-Size
X-Error
X-RateLimit-Limit
X-Cache-2
Cross-Origin-Window-Policy
X-DC
X-Webkit-Csp
X-Srv
X-TraceId
X-Varnish-Authentication
X-Cc-Via
X-Contensis-Viewer-Groups
Source
X-Cc-Req-Id
X-CACHE-KEY
X-Sucuri-Cache
X-Cache-ASPX
Server-Ttl
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
D-Cc-Upstream
X-Planisys-CDN-Cache
X-Wa
CACHE
X-Svr
HitType
MIME-Version
X-HS-Status
X-Servedbyhost
Cteonnt-Length
X-CDN-Forward
Kp-EeAlive
GeoIp-Country-Code
Cmsid
Cmstype
X-LiteSpeed-Cache-Control
Geoip-Latitude
X-Server-IP
X-Cs
X-URL
X-Cache-Config
Svr
X-API-Version
X-Served-From
X-FPC
X-Nyt-Route
X-Gdpr
X-Origin-Time
Geo-Info
Viewtype
A
VivaBuild
Cache-Key
X-LI-Proto
X-Esi
Server-ID
X-SN
X-VC
Ohc-Cache-HIT
SID
M-TraceId
Resin-Trace
X-RAMCache
X-Webstats-RespID
X-Vcl-Version
X-SB
X-NodeID
X-VCL-Version
Hostname
Filterid
NtCoent-Length
X-HOST
X-NGINX-Cache
X-Vgn-Hpd-Reason
Cross-Origin-Opener-Policy
X-Air-Source
X-Li-Proto
Server-Id
Arc-Country
TDXMobile
Request-ID
X-SD-PageType
X-Check-Cacheable
X-UA
Cache-Provider
X-CCDN-CacheTTL
X-DW
X-Viewer-Country
GeoIP-Latitude
GeoIP-Country-Code
X-DI
X-CCDN-Origin-Time
X-DSS
X-RPM
X-RSL
X-Render-Time
XServer
X-DB
X-TIM-N
X-Internal-Host
X-Hcs-Proxy-Type
X-RPS
X-TIME
EpKe-Alive
X-App
X-BBC-Edge-Cache-Status
Srv
X-Vc
NGB
X-Ua
X-HostName
X-Newrelic-Synthetics
X-Action
X-Service
X-Worker
Processtime
ProcessTime
Mime-Version
X-Auto-Login
X-ServedByHost
X-WA
X-CF-Powered-By
Datacenter
X-FTR-Cache-Host
X-Oss-Cdn-Auth
Upgrade-Insecure-Requests
X-Fpc
Tcn
X-SaId
X-PHP-Backend
X-JoinUs
X-NGENIX-Cache
X-Ftr-Cache-Host
X-Dynatrace-Js-Agent
X-CLOUD-TRACE-CONTEXT
FSS-Cache
Proxy-Connection
X-Forwarded-Site
X-Extlb
X-Via-NSCOPI
X-Cluster-Node
X-Edge-Location
X-Geo
CDN
X-CSRF-TOKEN
X-FORWARDED-FOR
X-Parent-Response-Time
X-HITS
CF-Cached-On
X-Cdn-Request-ID
W
X-MSEdge-Features
DataCenter
X-MSEdge-Flight
X-Provided-By
X-Dw-Trace-Id
X-BACKEND-TTL
X-Fastly-Backend-Reqs
X-BBC-Origin-Response-Status
Cdn
X-Swift-Error
X-Client-Ip
X-CACHE-AGE
X-Proxy-Upstream
Surrogated-Key
X-Cache-Tag
X-Accel-Expires-Debug
X-IN-APIGATEWAYSSL
We-Hiring
X-Fastly-Request-Id
PICS-Label
OT-Force-Account-Verify
X-Region-Sid
X-IN-APIGATEWAY
X-Depends-On
X-Hello
X-Flog
X-Bc-Bl
Mail-Subject
X-Req
LB
X-ABtesting
X-Date
X-VC-Cache
Memcached
Dnion-Transfer-Encoding
X-Akamai-Pragma-Client-IP
X-ND-Cache
X-RateLimit-Remaining-Second
X-Pad
X-Via-PopV
Media-Length
X-Via-PopN
X-Via-PopH
X-PJAX-URL
X-UnsetCookies
X-RateLimit-Limit-Second
X-Presslabs-Stats
Env
Vha6-Origin
X-Sigma-Backend
X-Pf-Uncompressing
X-Oracle-DMS-ECID
X-Sigma
X-Zone
X-Rocket-Build-Number
X-Air-Trace-Id
X-Acquia-Purge-Tags
X-Acquia-Site
Epwk-X-Cache
X-ZONE
Time
Memory
X-Men
X-Acquia-Application-UUID
X-MiniProfiler-Ids
X-Lb-Id
WZWS-RAY
Xet-Cookie
X-LiteSpeed-Tag
X-APP
X-Acquia-Application-Trace
Cf-Ipcountry
VNS-Cache
CPC-Age
X-Varnish-URL
CPC-Cache
VNS-Age
X-Ms-Meta-Originalurl
X-Csrf-Token
X-Varnish-Beresp-TTL
X-Request-URL
URI
X-Request-Url
X-Snapshot-Date
X-ElasticPress-Query
X-Akamai-ERPolicy
X-ElasticPress-Search
X-Ms-Meta-Staticbatchstarttime
X-Akamai-ERRuleID
X-Vcache
CountryCode
X-Pjax-Url
Environment
X-Amz-Meta-Cb-Modifiedtime
X-Storefront-Renderer-Verified
X-Redis-Count
X-Litespeed-Cache-Control
X-ServerName
Inserted-Into-Cache-At
X-B3-Parentspanid
X-Debug-Cache-Store
X-Debug-Cache-Fetch
Phost
NnCoection
Ohc-Response-Time
X-Redis-Duration-Ms
X-Traceid
X-C
X-Tid