Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
X-XSS-Protection
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-UA-Compatible
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Xss-Protection
X-Request-ID
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
X-Ua-Compatible
X-Content-Security-Policy
X-Iinfo
Content-Encoding
X-CDN
X-Envoy-Upstream-Service-Time
Feature-Policy
X-AspNetMvc-Version
Status
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-Via
Access-Control-Max-Age
Upgrade
Keep-Alive
X-Ws-Request-Id
X-Age
X-Turbo-Charged-By
X-AH-Environment
X-Robots-Tag
Request-Context
X-Proxy-Cache
EagleId
X-Cache-Group
Server-Timing
X-Backend
X-Hacker
X-Server
Report-To
X-Amz-Request-Id
Host-Header
X-Server-Powered-By
X-Amz-Id-2
Grace
X-Nginx-Cache-Status
X-UA-Device
X-Rq
X-Varnish-Cache
X-LiteSpeed-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
X-Page-Speed
Cf-Railgun
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
X-Amz-Version-Id
NEL
X-Cache-Spec
X-Device
Allow
X-CST
Xkey
X-Backend-Server
X-Vhost
X-Host
X-WebKit-CSP
X-Server-Id
EagleEye-TraceId
Surrogate-Control
Request-Id
X-Dispatcher
X-Node
Content-Location
X-Response-Time
X-Akam-SW-Version
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Ruxit-JS-Agent
Accept-CH
P3p
X-ASPNET-VERSION
Accept-CH-Lifetime
X-Application-Context
X-Ac
X-Template
X-Country
X-Language
X-Cache-Lookup
X-Mod-Pagespeed
X-Readtime
X-Cloud-Trace-Context
Accept-Ch
MS-Author-Via
X-B3-TraceId
Accept-Ch-Lifetime
Rating
X-Origin-Cache
X-Cnection
X-MS-InvokeApp
X-HW
X-Url
X-Vname
X-TtlSet
X-PC
X-Clacks-Overhead
X-GitHub-Request-Id
Edge-Control
X-ORACLE-DMS-ECID
X-ESI
X-Trace
X-Middleton-Display
Response
X-Content-Type
X-Middleton-Response
Pagespeed
X-Sol
Display
X-D2id
Arr-Disable-Session-Affinity
X-Cdn-Fetch
X-Kinja-Build
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Kinja
X-GoogleNews-Bot
X-Exp-Id
X-Exp-Variant
X-Vcap-Request-Id
Verso
X-FastCGI-Cache
X-ORACLE-DMS-RID
X-Goog-Hash
X-Buckets
X-Rack-Cache
X-Country-Code
X-Server-Name
X-Navigation-Version
Service-Worker-Allowed
X-Varnish-TTL
X-VARITI-CCR
X-Abt-Application-Version
X-Amz-Rid
X-Powered-By-Plesk
X-Fastly-Request-ID
X-Webkit-CSP
X-Client-IP
Pinterest-Version
X-Cache-TTL
Pinterest-Generated-By
X-Pinterest-Rid
Fastly-Restarts
X-Release
X-SharePointHealthScore
X-MSEdge-Ref
SPRequestGuid
X-TTL
X-Dw-Request-Base-Id
X-Element-Page-Cache
SPIisLatency
SPRequestDuration
X-Oneagent-Js-Injection
X-Cached
X-NF-Request-ID
Public-Key-Pins
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
RTSS
X-Edge
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Ar-Sid
Access-Control-Request-Method
AR-CACHE
AR-ATIME
AR-Request-ID
AR-PoweredBy
X-LLID
X-Powered-CMS
X-Origin-Upstream-Status
X-Ezoic-Cdn
X-Px
X-Upstream
Fusion-Content-Id
Fusion-Component-Id
Fusion-Content-Source
Fusion-Deployment-Id
Fusion-Template-Id
Fusion-Source
Content-MD5
Cache-Tag
X-Jurisdiction
X-HP-Webp
X-Ttl
X-ECACHE
X-MCACHE
X-Mid
S
X-Mg-S
X-Version
X-Recruiting
Charset
X-Content-Digest
X-PressLabs-Stats
X-Amz-Server-Side-Encryption
Fastcgi-Cache
X-Litespeed-Cache
X-T
X-Kinsta-Cache
MicrosoftSharePointTeamServices
X-Id
Cache-Tags
X-Content-Security-Policy-Report-Only
Front-End-Https
Filters
X-Debug
X-Pinterest-Direct
TCN
X-Grace
X-Accel-Expires
Edge-Cache-Tag
X-Logged-In
X-DynaTrace
Server-Node
X-Forwarded-Proto
X-Correlation-Id
X-Forwarded-For
Server-Name
X-Amzn-Trace-Id
Nginx-Cache
TP-L2-Cache
TP-Cache
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Surrogate-Key
X-Yandex-Sdch-Disable
X-XRDS-LOCATION
X-Varnish-Age
X-Request-Processing-Time
X-Request-Received
X-B3-Sampled
X-Request-Handler-Origin-Region
X-Ruxit-Js-Agent
X-Ser
X-Microsite
X-Shield-Request-Id
X-Hits
X-AppVersion
X-Activity-Id
X-Az
X-Amz-Replication-Status
X-Kinja-Server-Push
X-DIS-Request-ID
X-HS-Cache-Config
X-F-Cache
X-HS-Combine-CSS
X-HS-Hub-Id
X-HS-Content-Id
X-Goog-Metageneration
X-Goog-Generation
X-GUploader-UploadID
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Origin-Server
Accept-Charset
X-Git-Hash
X-Geo-Country
Cache
Nel
X-Respond-Thread
X-XRDS-Location
X-Cache-Key
Powered-By-ChinaCache
Alternate-Protocol
X-Rid
X-FTR-Request-ID
X-Fastcgi-Cache
Section-Io-Cache
X-Frontend
X-LB-Cache
X-Upgrade-Enabled
X-DataDome
Host
X-Hostname
X-Time
Access-Control-Allow-Method
X-Mobile-URL
X-Cache-Age
X-Server-ID
X-Seen-By
MS-CV
X-AOL-HN
Paypal-Debug-Id
X-NWS-LOG-UUID
X-VCache
Cleartype
Healthy
X-Type
X-Content-Options
X-IPLB-Instance
X-Whom
X-Varnish-Backend
X-TT
X-Cache-Action
X-App-Environment
ServerID
Payment
X-Route-Name
X-Request-Guid
X-Aspnet-Duration-Ms
X-Jobs
X-Providence-Cookie
X-Flags
X-Is-Crawler
X-Debug-Info
X-Page-Id
X-B-Cache
X-Signature
X-WebKit-CSP-Report-Only
X-Source
Fastcgi-Useragent
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Load-Cache
X-Daa-Tunnel
X-N
X-Mobile
X-FB-Debug
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-RateLimit-Remaining
X-Browser-Type
X-Via-JSL
Version
X-Cache-Rule
Refresh
X-Cache-Operation
X-Cached-By
X-Akamai-Edgescape
X-Rule
X-Response-Served-From
X-Accel-Buffering
X-Wix-Request-Id
X-Original-Request-Id
X-Contextid
X-Drupal-Cache-Tags
X-Framework
DC
X-Cacheable-TTL
Viewport
X-Proxy
X-Zen-Fury
Node
Access-Control-Request-Headers
X-ProcessESI
X-RTag
Ms-Operation-Id
Realpath
X-RemovedCookies
X-B
X-Cache-Time
X-Instance
X-Real-IP
Referer-Policy
X-HTML-Minification-Powered-By
X-Distributor
X-Region
X-UUID
DynaTrace
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Page-View
Eomportal-Instance
X-Cluster-Name
X-Drupal-Cache-Contexts
VIX-Pulpo-Upstream-Status
X-Cache-Expired-At
X-Tt-Trace-Host
X-FW-Static
Countrycode
X-Tt-Trace-Tag
VIX-Pulpo-Node
X-FW-Type
X-FW-Server
X-FW-Hash
X-FW-Serve
X-FW-Dynamic
X-Content-Powered-By
X-Cache-Control
X-G
X-Environment-Context
X-L-Path
X-IPS-LoggedIn
X-Cache-Hit
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Tumblr-Pixel
Liferay-Portal
Server-Info
GEO-INFO
X-App-Server
X-FireWall-Port
X-Pass-Why
X-User-Agent
X-Varnish-Ttl
X-Ratelimit-Limit
X-Node-Name
X-Tumblr-Pixel-2
Ec-Rule-Version
Section-Io-Id
Webserver
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
From-Origin
Section-Origin-Responded
Xserver
X-Protected-By
CF-IPCountry
Protected
SRV
X-Www-Served-By
X-Cache-Server
X-Backend-Name
X-Hl-Ver
X-Handled-By
X-RN-RSRV
Meta-Geo
X-Revision
X-ES-SERVER
Frame-Options
X-Mode
X-UPSTREAM-Address
X-Endurance-Cache-Level
Cache-Tv-Group
X-Site-Version
X-FB-TRIP-ID
X-Soup
X-Locale
Cache-Status
X-Web-Node
X-Nginx-Cache
X-Hyper-Cache
X-PHP-Host
X-Varnishpool
Country
X-Be
X-Labrador-Cache-Channel
X-Ratelimit-Remaining
X-Uri
X-NYM-Debug-Backend
X-Storage
X-Human
Property-Id
X-S-Maxage
X-Origin-Hint
X-Timing-Wait
Selected-Fe
TWC-Connection-Speed
X-Origin-Date
X-BYPASS-REASON
Azure-RegionName
Azure-SiteName
Azure-SlotName
Cache-Name
X-UA-Device-Type
Decoy-Debug-Status
X-ProxyCache-Key
X-ProxyCache-Status
X-MP-GENERATED-AT
Azure-Version
X-Pubstack
X-Amz-Meta-S3cmd-Attrs
X-Request-Time
Webcakes-Region
X-Proxy-Build
X-Proto
X-Forwarded-Host
TWC-Device-Class
Webcakes-App-Version
Fastly-SSL
Decoy-Debug-Key
TWC-GeoIP-LatLong
TWC-GeoIP-Country
X-Adobe-Content
X-Adobe-Loc
X-Redis-Cache
TWC-Locale-Group
Azure-InstanceId
Decoy-Debug-TTL
TWC-Privacy
X-Cache-Grace
Webcakes-App-Name
X-SayCDN-TTL
X-Section
X-Say-Cacheable
X-Say-TTL
X-Server-W
X-Sql-Duration-Ms
X-Sql-Count
X-AIR-PT
X-Access
X-PCL
X-Via-Fastly
X-WA-Info
X-Format
X-FW-Version
X-Hosted-By
X-No-Session
X-OCL
X-Loop
Retry-After
X-TT-LOGID
X-TNCMS
X-Debug-IsConnected
X-VWS-Id
X-Status
X-Cluster
X-PERF
X-ApacheServer
X-Debug-IsPreview
X-LAGOON
X-AWS-Id
X-R9-Blue-Green-Version
X-LJ-Flow-ID
Mn-Server-Ip
X-Sorting-Hat-PodId
X-ShopId
X-ShardId
X-Shopify-Stage
X-Sorting-Hat-ShopId
X-Webkit-Csp
X-Storefront-Renderer-Rendered
X-Cache-TTL-Remaining
X-Alternate-Cache-Key
X-Device-Type
X-Zipkin-Id
X-Routing-Service
X-Proxied
X-Qloud-Router
X-Is-Bot
X-Xfnlog-Site
X-Rendered-As
X-CCM
Cache-Hits
X-Via-CDN
Apigw-Requestid
X-Tec-Api-Root
X-Dc
X-Tec-Api-Origin
S-Cnection
X-Info
X-Tec-Api-Version
AMP-Access-Control-Allow-Source-Origin
X-FTR-DC
X-FTR-Backend
X-FTR-Realm
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Balancer
X-Varnish-Grace
X-SRV
X-Varnish-Server
X-Cdn
X-GG-Cache-Date
X-FTR-Expires
X-Detected-As
X-Cache-Enabled
X-Cache-Host
X-Microcachable
X-Content-Age
X-Platform
X-Amzn-RequestId
X-Amzn-Remapped-Content-Length
X-EdgeConnect-Cache-Status
X-Amz-Apigw-Id
X-Aspnetmvc-Version
X-Air-Hostname
X-Cache-Var-Map
Uber-Trace-Id
X-CSRF-Token
X-Azure-Ref
X-Cache-Var
Tracecode
X-Backend-Host
X-Proxy-Cache-Status
SD-X-WS
X-Unique-Id
X-Time-Microsecs
X-DynaTrace-JS-Agent
Amp-Access-Control-Allow-Source-Origin
X-NWS-UUID-VERIFY
X-Backend-TTL
Akamai-GRN
X-ServerID
X-GEO
X-ATG-Version
X-Oss-Object-Type
X-Tb
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-Oss-Storage-Class
X-Cache-Backend
X-Trace-Id
X-Oss-Server-Time
X-App-Version
Backend
X-BCube-Filmed-By
X-Correlation-ID
X-Varnish-Hostname
ServedBy
DSUID
X-RCS-CacheZone
HostName
X-Akamai-Transformed
X-Cache-PHP
X-Cache-NGX
X-Connection-Hash
X-Fetched-On
X-Generation-Time
Rendered-Blocks
Release
X-GeoIP-City
X-Generated-On
X-From
X-Destination
X-Device-Os
X-External-Request-Id
X-CF-Lambda-Version
X-D
X-Application
SR-User-Adfree
X-A
X-A-Ccd
X-A-Dam
Thinkindot-Control
X-Debug-Cache
T-Server
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-Varnish-Cache-Hits
X-A-Dcw
X-B-Cookie
X-Cache-NE
X-CF-Lambda-Fn
X-ARC
Path
X-A-Dgt
X-A-Wwc
X-Aed
X-Magnolia-Registration
MD5-Digest
X-SRCache-Key
Fastcgi-X-Cache-Version
X-Thinkindot-L3
BehaviorPad-Version
Instruction
X-Session-Fingerprint
X-Rojux
X-S
X-ScT
X-Trv-Group
Expiry
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
DCR-Decision-By
DCR-Processing-Time-Ms
X-VG-WebServer
X-Vdms-Path
X-Vdms-Version
X-VG-WebCache
X-Rewrite-Enabled
X-S-Cookie
Machine
X-Location
X-Owner
X-Origin-TTL
X-Origin-CC
Meta-Geo-Continent
X-Matched-Rule
Mobile-Detection-Method
X-Level-Front-Cache
X-PAYTM-SRV-ID
X-Processor
Lfy
X-TA-CDN-Provider
X-PBS-Appsvrname
Odigeo-Trace-Id
X-Request-UUID
X-Sucuri-ID
Arc-Version
PB-RID
PB-PID
DB-Nickname
X-Cdn-Forward
X-B3-SpanId
X-APP-VERSION
Pagetype
Host-ID
Gh-Request-Id
Server-Host
Fastly-Backend-Name
Ssr
X-HS-Content-Campaign-Id
X-Skip-Cache
X-SVT-ORM-RULES
X-Reqid
X-OVcl-Cache
X-OVcl
X-SVT-ORM-VERSION
X-Swa-Ws
X-VServer
X-NAPM-TraceId
X-Tumblr-Pixel-3
X-TrackingId
X-Thanos
X-Node-Id
X-Mvc-Supplant-Cachable
X-FC-Vary-Parameters
X-Geo-Header
X-Cache-Bucket
X-Bip
X-Azure-Ref-OriginShield
X-GeoIP
X-Has-Esi
X-Micro-Cache
X-JWT-State
X-Irp-Debug
Cf-Device-Type
UCS
X-Is-Gdpr
X-B3-Traceid
X-NewRelic-App-Data
AKAMAI
C-Via
X-Ms-Version
X-Ms-Request-Id
Cache-Host
CacheControlHeader
X-TX-ID
X-CS
X-Eu-Site
X-Esi-Check
X-DPWN-IS-SECURE
X-Dispatcher-Server
X-Gzip
X-Generated-In
X-Generated-By
X-HN
X-Fastly-Backend
X-IP
X-Developers
X-CUA
X-Cache-Info
X-Cache-Tags
X-Cache-Id
X-Branch-Name
X-Backend-State
X-Cdn-Origin
X-CGP
X-DefElseHash
X-DefHash
X-Li-Fabric
X-Csrf-Jwt
X-Clientip
X-Developer
X-Old-Content-Length
X-Wikidot-Static-Cache
CloudFront-Viewer-Country
X-Wikidot-Backend
X-VarnishDD-TTL
X-Varnish-Hits
X-Varnish-Remaining-TTL
Content-Disposition
NGX
X-Core-Value
X-Fastly-Cache
X-Cms-Context
X-Adobe-Source
On-Server
X-Varnish-CookieHashed-On
X-Varnish-Beresp-Grace
X-Origin-Expires
X-Origin-Response-Time
X-Origin
Wxu-Next-Region
X-LI-UUID
X-Nginx-Cache-Key
X-Policy
X-Request-Host
X-Var-Ttl
X-Variation
X-User
X-Sn-Servicetimems
X-Scheme
X-Li-Pop
X-Varnish-CookieINHashed-On
V-Age
L
L5d-Success-Class
Location
Locid
Is-Eu
HA-Ipaddr
Server-Hostname
Sever-Int
Wxu-Next-Hostname
Ha-Gx-Prefs
Server-Ext
Wxu-Next-Commit
Adler-Geo
Magicmarker
PFcat
Platform
NM-Fastcgi-Cache
Pramga
User-Cache-Control
X-ID
X-Erf-Stays-Bingo-Pdp-Web
X-Request-URI
CDN-EdgeStorageId
X-Loc
X-Method
CDN-CachedAt
Origin
CDCHOST
X-Gamma-Serve
X-Varnish-Beresp-Status
CDN-PullZone
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Slack-Backend
X-SIPLIST1
X-Varnish-Beresp-Ttl
IsBot
X-Hash
Cf-Bgj
Rt-Fastcgi-Cache
CDN-Cache
X-GoCache-CacheStatus
X-Block-Status
X-Hnp-Log
X-NU-AKA-ACS-Version
True-Client-Country-4JS
X-Gen-Mode
X-Cache-Date
CDN-RequestCountryCode
X-Fmm-Version
X-Clara-WADP
X-Cache-Expires
Vix-Hermes-Req-Id
X-Platform-Server
Fastly-SIE
X-Rebelmouse-Surrogate-Control
CDN-Uid
CDN-RequestId
X-Rebelmouse-Cache-Control
Fastly-SWR
X-WADP-Cache
Web-Mar-Node
X-Ratelimit-Reset
Fastly-Drupal-HTML
X-Envoy-Decorator-Operation
X-EC-Lua
X-Dynatrace
X-LB-ID
X-CACHE-KEY
Apple-News-Services-Handled
Apple-News-Services-Parsed-Url
X-Core-Mission
Apple-News-Services-Host
X-Aicache-OS
Apple-News-Services-Request-Url
X-VG-TLSProxy
X-Servername
X-Cache-Debug
Sid
X-NCache
X-Mvc-Supplant-OutputCached
X-PF-Uncompressing
X-Request-Start
X-Via-Popv
X-Via-Poph
X-Varnish-Url
Esi-Enabled
X-Via-Popn
X-Refresh
X-CACHE-GROUP
Url
X-Nc
X-Oracle-Dms-Rid
X-Cache-Remote
X-NC
X-Unique-ID
Who
Country-Code
X-Response-By
X-Varnish-Cacheable
X-Epic-Correlation-Id
Pics-Label
X-FireWall-Protection
S-Rt
X-Proxy-Cachei7
X-Tb-Optimization-Total-Bytes-Saved
Req-Svc-Chain
Xkeyi7
Geo-Info
X-TraceId
Content-Secure-Policy
X-Host-Name
X-Planisys-CDN-TTL
X-B3-Spanid
X-BBXSRF
X-Planisys-CDN-Rules
X-RateLimit-Limit
X-Planisys-CDN-Cache
N-Cache
X-Error
X-Srv
Source
X-Cache-2
Ohc-File-Size
Cross-Origin-Window-Policy
X-Webkit-CSP-Report-Only
X-Cache-ASPX
Cmsid
X-CLOUD-TRACE-CONTEXT
Cmstype
X-Varnish-Authentication
X-Cc-Req-Id
X-Cc-Via
Geoip-Latitude
HitType
GeoIp-Country-Code
X-Contensis-Viewer-Groups
Server-Ttl
D-Cc-Upstream
X-HS-Status
X-DC
Kp-EeAlive
Cteonnt-Length
X-Sucuri-Cache
X-LiteSpeed-Cache-Control
X-Served-From
Svr
X-Svr
Tcn
MIME-Version
X-URL
Viewtype
Filterid
X-Vcl-Version
VivaBuild
A
Cache-Key
X-Servedbyhost
X-Wa
X-Server-IP
X-CDN-Forward
X-Gdpr
X-API-Version
X-Li-Proto
X-RAMCache
M-TraceId
X-Esi
X-Cache-Config
Server-ID
X-Nyt-Route
X-FPC
X-Cs
X-Origin-Time
CACHE
TDXMobile
X-VC
Arc-Country
X-SN
X-Air-Source
Resin-Trace
X-Vgn-Hpd-Reason
Cross-Origin-Opener-Policy
X-LI-Proto
X-HostName
NtCoent-Length
X-HOST
X-NodeID
X-Check-Cacheable
NGB
Ohc-Cache-HIT
SID
Request-ID
X-Webstats-RespID
Server-Id
X-SB
X-UA
Hostname
X-Newrelic-Synthetics
X-Vc
X-RPM
X-DI
X-DSS
X-TIM-N
X-DB
X-VCL-Version
X-ServedByHost
X-SD-PageType
X-Internal-Host
X-NGINX-Cache
X-DW
X-Viewer-Country
X-WA
X-Hcs-Proxy-Type
Cache-Provider
X-CCDN-Origin-Time
X-RPS
X-CCDN-CacheTTL
X-RSL
X-Service
GeoIP-Country-Code
GeoIP-Latitude
Mime-Version
X-Geo
Srv
X-Render-Time
XServer
X-NGENIX-Cache
X-JoinUs
X-SaId
ProcessTime
X-Action
X-App
X-CF-Powered-By
X-PHP-Backend
EpKe-Alive
X-BBC-Edge-Cache-Status
DataCenter
X-Edge-Location
X-Ua
X-FTR-Cache-Host
Processtime
X-Oss-Cdn-Auth
X-Via-NSCOPI
X-Forwarded-Site
X-Worker
Upgrade-Insecure-Requests
X-TIME
X-Fpc
FSS-Cache
X-Auto-Login
X-Extlb
X-Provided-By
CF-Cached-On
X-Dynatrace-Js-Agent
Proxy-Connection
X-FORWARDED-FOR
W
X-Cluster-Node
X-HITS
X-Cdn-Request-ID
X-PJAX-URL
CDN
X-Depends-On
X-MSEdge-Flight
X-MSEdge-Features
X-BACKEND-TTL
X-VC-Cache
X-Dw-Trace-Id
X-Req
X-Region-Sid
X-Date
X-Proxy-Upstream
X-Bc-Bl
X-Fastly-Backend-Reqs
LB
Mail-Subject
Memcached
Surrogated-Key
Datacenter
Cdn
X-Accel-Expires-Debug
X-CSRF-TOKEN
We-Hiring
X-Parent-Response-Time
X-Ftr-Cache-Host
X-Client-Ip
X-CACHE-AGE
X-Swift-Error
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
Env
X-ABtesting
PICS-Label
X-Sigma-Backend
X-Rocket-Build-Number
X-Sigma
X-APP
X-BBC-Origin-Response-Status
X-Fastly-Request-Id
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Hello
Dnion-Transfer-Encoding
X-Flog
X-Cache-Tag
X-UnsetCookies
X-Akamai-Pragma-Client-IP
X-ZONE
Time
Media-Length
X-Men
X-Air-Trace-Id
X-Pad
Memory
OT-Force-Account-Verify
X-Zone
Vha6-Origin
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
X-Acquia-Site
X-Pf-Uncompressing
X-Acquia-Application-Trace
X-Oracle-DMS-ECID
X-Presslabs-Stats
Epwk-X-Cache
VNS-Age
X-ND-Cache
VNS-Cache
CPC-Cache
CPC-Age
X-Via-PopH
X-LiteSpeed-Tag
X-Via-PopN
X-Via-PopV
Cf-Ipcountry
X-Varnish-URL
X-Lb-Id
X-Csrf-Token
X-Akamai-ERPolicy
X-Request-Url
X-Akamai-ERRuleID
X-Varnish-Beresp-TTL
X-ElasticPress-Query
X-MiniProfiler-Ids
X-ServerName
X-Snapshot-Date
X-Vcache
WZWS-RAY
X-Ms-Meta-Originalurl
X-Ms-Meta-Staticbatchstarttime
X-ElasticPress-Search
Xet-Cookie
X-Request-URL
CountryCode
Content-Style-Type
X-Amz-Meta-Cb-Modifiedtime
Environment
Content-Script-Type
X-Tid
X-Storefront-Renderer-Verified
X-Litespeed-Cache-Control
X-C
X-B3-Parentspanid
X-Debug-Cache-Store
X-Debug-Cache-Fetch
Phost
NnCoection
Ohc-Response-Time
X-Redis-Duration-Ms
URI
Inserted-Into-Cache-At
X-Traceid
X-Redis-Count