Threat Level: green Handler on Duty: Renato Marinho

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-XSS-Protection
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-UA-Compatible
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Request-Id
X-Xss-Protection
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Runtime
X-AspNet-Version
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Content-Security-Policy
X-Ua-Compatible
X-Request-ID
X-Iinfo
Content-Encoding
X-CDN
Feature-Policy
X-AspNetMvc-Version
Status
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Upgrade
Access-Control-Max-Age
X-Via
Keep-Alive
X-Ws-Request-Id
X-AH-Environment
X-Age
X-Robots-Tag
Request-Context
EagleId
X-Turbo-Charged-By
X-Cache-Group
X-Proxy-Cache
Server-Timing
X-Server
X-Backend
X-Hacker
Host-Header
X-Server-Powered-By
Report-To
X-Amz-Request-Id
X-Nginx-Cache-Status
Grace
X-Amz-Id-2
X-UA-Device
X-Dns-Prefetch-Control
X-Rq
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Page-Speed
X-OneAgent-JS-Injection
Cf-Railgun
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
X-CST
X-Amz-Version-Id
NEL
X-Cache-Spec
Allow
X-Vhost
X-Host
X-Backend-Server
X-ASPNET-VERSION
X-Server-Id
X-Dispatcher
X-WebKit-CSP
Surrogate-Control
EagleEye-TraceId
X-Node
Xkey
Request-Id
X-Response-Time
Content-Location
X-Akam-SW-Version
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Accept-CH
X-Ruxit-JS-Agent
P3p
X-Cache-Lookup
X-Application-Context
X-Country
X-Ac
Accept-CH-Lifetime
X-Mod-Pagespeed
X-Cloud-Trace-Context
X-Readtime
X-Template
X-Language
X-B3-TraceId
MS-Author-Via
X-HW
Rating
Accept-Ch-Lifetime
X-Url
X-Cnection
X-MS-InvokeApp
Accept-Ch
X-Origin-Cache
X-Vname
X-PC
X-TtlSet
Edge-Control
X-Clacks-Overhead
X-ESI
X-GitHub-Request-Id
X-Webkit-CSP
X-Trace
X-Varnish-TTL
X-Middleton-Response
X-Middleton-Display
Response
Pagespeed
Display
X-Sol
X-D2id
X-Content-Type
Verso
Arr-Disable-Session-Affinity
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Kinja-Build
X-GoogleNews-Bot
X-Cdn-Fetch
X-Exp-Variant
X-Kinja
X-Exp-Id
X-Powered-By-Plesk
X-Vcap-Request-Id
X-Country-Code
X-Goog-Hash
X-Rack-Cache
X-ORACLE-DMS-RID
X-FastCGI-Cache
X-ORACLE-DMS-ECID
X-Navigation-Version
X-VARITI-CCR
X-Abt-Application-Version
X-Server-Name
X-Amz-Rid
X-TTL
Service-Worker-Allowed
Fastly-Restarts
X-Fastly-Request-ID
X-Client-IP
X-Cached
X-Buckets
X-MSEdge-Ref
X-Release
X-Element-Page-Cache
Cache-Tag
X-Dw-Request-Base-Id
X-NF-Request-ID
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
SPRequestGuid
Public-Key-Pins
X-SharePointHealthScore
Access-Control-Request-Method
X-Cache-TTL
RTSS
SPRequestDuration
SPIisLatency
AR-CACHE
AR-ATIME
AR-PoweredBy
AR-Request-ID
Ar-Sid
X-Edge
X-Ezoic-Cdn
X-LLID
X-Powered-CMS
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
X-SRCache-Fetch-Status
X-Upstream
X-SRCache-Store-Status
X-Version
S
Content-MD5
X-HP-Webp
X-Jurisdiction
X-Recruiting
X-Oneagent-Js-Injection
X-Mid
X-Kinsta-Cache
X-MCACHE
X-ECACHE
Charset
X-Mg-S
X-Ttl
X-PressLabs-Stats
X-DynaTrace
X-Origin-Upstream-Status
X-T
Cache-Tags
X-Content-Digest
X-Accel-Expires
Fusion-Content-Id
Fusion-Component-Id
Fusion-Content-Source
Fusion-Template-Id
Fusion-Deployment-Id
Fusion-Source
X-Forwarded-Proto
Fastcgi-Cache
X-Px
X-Litespeed-Cache
X-Content-Security-Policy-Report-Only
X-Id
X-Logged-In
Filters
TP-L2-Cache
TP-Cache
Server-Node
Edge-Cache-Tag
Server-Name
TCN
X-Ruxit-Js-Agent
X-Correlation-Id
X-Amz-Server-Side-Encryption
Front-End-Https
X-Forwarded-For
X-Request-Received
X-Request-Processing-Time
MicrosoftSharePointTeamServices
Nginx-Cache
X-Grace
X-XRDS-Location
X-Shield-Request-Id
X-Hits
X-B3-Sampled
X-Amzn-Trace-Id
Alternate-Protocol
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Request-Handler-Origin-Region
X-Server-ID
X-Microsite
X-Activity-Id
X-AppVersion
X-Az
X-NWS-LOG-UUID
X-F-Cache
X-Amz-Replication-Status
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Combine-CSS
X-HS-Cache-Config
X-Fastcgi-Cache
X-Varnish-Age
X-Debug
X-Origin-Server
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Metageneration
X-Goog-Generation
X-GUploader-UploadID
X-Frontend
X-Yandex-Sdch-Disable
X-Rid
Nel
X-Geo-Country
Host
Surrogate-Key
X-RateLimit-Remaining
Section-Io-Cache
X-Cache-Age
X-DIS-Request-ID
X-Daa-Tunnel
Accept-Charset
X-Ser
X-Hostname
Realpath
X-Git-Hash
X-VCache
X-Time
Access-Control-Allow-Method
X-Respond-Thread
X-Mobile-URL
X-Seen-By
MS-CV
X-Upgrade-Enabled
X-Source
ServerID
X-AOL-HN
X-DataDome
Paypal-Debug-Id
X-Type
Cleartype
X-XRDS-LOCATION
X-LB-Cache
X-Contextid
X-TT
X-Varnish-Backend
Payment
Healthy
X-IPLB-Instance
X-B-Cache
X-Cache-Action
X-Content-Options
X-Signature
X-Debug-Info
X-Request-Guid
X-Route-Name
X-Whom
X-Providence-Cookie
X-Is-Crawler
X-Aspnet-Duration-Ms
X-Cache-Key
X-Flags
X-Load-Cache
X-WebKit-CSP-Report-Only
X-App-Environment
X-Page-Id
Fastcgi-Useragent
X-N
X-FB-Debug
Cache
X-Jobs
Node
X-Webkit-Csp
X-Mobile
X-Rule
X-Cache-Expired-At
Refresh
X-Browser-Type
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-FTR-Request-ID
X-FireWall-Port
Viewport
X-Accel-Buffering
X-Wix-Request-Id
X-Original-Request-Id
X-Response-Served-From
Ms-Operation-Id
DC
X-RTag
X-Cacheable-TTL
X-Cluster-Name
X-Content-Powered-By
Access-Control-Request-Headers
X-Framework
X-Drupal-Cache-Tags
X-Debug-IsPreview
X-Debug-IsConnected
X-Zen-Fury
Referer-Policy
X-Real-IP
X-Instance
X-HTML-Minification-Powered-By
X-RemovedCookies
X-Distributor
X-ProcessESI
X-B
Version
X-Cache-Time
X-Proxy
VIX-Pulpo-Upstream-Status
X-UUID
X-Region
X-Cache-Control
VIX-Pulpo-Node
X-IPS-LoggedIn
Eomportal-Instance
X-Page-View
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Tec-Api-Version
Countrycode
X-Tec-Api-Root
X-Tec-Api-Origin
X-Drupal-Cache-Contexts
X-Www-Served-By
X-FW-Hash
X-FW-Static
X-FW-Dynamic
X-FW-Type
X-FW-Server
X-Nginx-Cache
X-FW-Serve
X-App-Server
X-G
X-Protected-By
Xserver
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Cached-By
X-Tumblr-User
Liferay-Portal
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Cache-Rule
X-Cache-Operation
X-Via-JSL
Powered-By-ChinaCache
X-Akamai-Edgescape
X-Pinterest-Direct
X-Environment-Context
X-L-Path
X-Cache-Hit
X-Pass-Why
Section-Origin-Responded
Section-Io-Origin-Status
SRV
Section-Io-Id
Section-Io-Origin-Time-Seconds
X-Varnish-Grace
X-Device-Type
CF-IPCountry
GEO-INFO
Server-Info
X-TA-CDN-Provider
DynaTrace
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-User-Agent
X-TEC-API-VERSION
X-Varnish-Server
X-Adobe-Loc
X-Adobe-Content
Cache-Status
Retry-After
From-Origin
X-Tumblr-Pixel-2
Frame-Options
Ec-Rule-Version
X-UPSTREAM-Address
X-Mode
X-Hl-Ver
X-Endurance-Cache-Level
Meta-Geo
X-Handled-By
X-RN-RSRV
X-ES-SERVER
Webserver
X-Backend-Name
Cache-Tv-Group
X-FB-TRIP-ID
X-Access
Webcakes-App-Version
X-Be
X-Cache-Server
X-BYPASS-REASON
Webcakes-App-Name
TWC-Locale-Group
Property-Id
Country
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Privacy
X-Format
X-Soup
X-Section
X-Request-Time
X-Storage
X-Uri
Fastly-SSL
X-Varnishpool
X-Pubstack
X-ProxyCache-Status
X-NYM-Debug-Backend
X-MP-GENERATED-AT
X-OCL
X-Origin-Hint
X-ProxyCache-Key
X-PCL
Apigw-Requestid
Webcakes-Region
X-Server-W
Selected-Fe
X-S-Maxage
X-Timing-Wait
Decoy-Debug-TTL
Decoy-Debug-Status
Mn-Server-Ip
Uber-Trace-Id
X-Via-Fastly
X-UA-Device-Type
X-Proxy-Cache-Status
Cache-Name
X-Info
X-VWS-Id
X-R9-Blue-Green-Version
Decoy-Debug-Key
X-Human
X-Origin-Date
X-ApacheServer
X-No-Session
X-WA-Info
X-PERF
X-PHP-Host
X-Proxy-Build
X-AWS-Id
X-LJ-Flow-ID
X-Proto
X-Labrador-Cache-Channel
Azure-RegionName
Azure-SiteName
X-Web-Node
X-Sql-Count
Azure-InstanceId
Azure-SlotName
X-TNCMS
X-Cache-TTL-Remaining
X-Say-Cacheable
Protected
X-GG-Cache-Date
Azure-Version
X-Sql-Duration-Ms
X-Xfnlog-Site
X-SayCDN-TTL
X-LAGOON
X-Say-TTL
X-Loop
X-Sorting-Hat-PodId
X-Proxied
X-Sorting-Hat-ShopId
X-Alternate-Cache-Key
X-ShopId
X-Routing-Service
X-ShardId
X-Zipkin-Id
X-Shopify-Stage
X-Hosted-By
X-Hyper-Cache
X-Storefront-Renderer-Rendered
X-Status
X-Redis-Cache
X-NWS-UUID-VERIFY
X-Locale
X-Cache-Enabled
X-Content-Age
X-Backend-Host
X-Ratelimit-Limit
X-SRV
X-Site-Version
X-Is-Bot
X-Rendered-As
X-Microcachable
X-FW-Version
X-App-Version
Amp-Access-Control-Allow-Source-Origin
X-Azure-Ref
X-Cluster
S-Cnection
X-Cache-Grace
X-Forwarded-Host
X-AIR-PT
X-TT-LOGID
AMP-Access-Control-Allow-Source-Origin
X-Qloud-Router
X-Platform
X-CSRF-Token
Akamai-GRN
X-Varnish-Ttl
X-Trace-Id
X-Revision
X-Via-CDN
ServedBy
X-Aspnetmvc-Version
Cache-Hits
X-ATG-Version
X-Dc
X-EdgeConnect-Cache-Status
X-Cache-PHP
X-Cache-NGX
X-Varnish-Hostname
X-CCM
X-RCS-CacheZone
X-Debug-Cache
X-Node-Name
Who
X-RateLimit-Limit
DB-Nickname
X-Cache-Host
Country-Code
X-Detected-As
X-Akamai-Transformed
X-B3-SpanId
X-Amz-Apigw-Id
X-TX-ID
X-Amzn-Remapped-Content-Length
X-Amzn-RequestId
X-CS
Filterid
X-Adobe-Source
X-CACHE-KEY
X-BCube-Filmed-By
X-Ms-Version
X-Correlation-ID
X-Oss-Hash-Crc64ecma
SD-X-WS
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Object-Type
X-Oss-Request-Id
X-Ms-Request-Id
X-Varnish-Beresp-Grace
X-Connection-Hash
Odigeo-Trace-Id
BehaviorPad-Version
X-D
X-Destination
T-Server
X-External-Request-Id
X-Varnish-Beresp-Ttl
X-From
X-Generated-On
Rendered-Blocks
X-Generation-Time
X-Location
X-Application
X-CF-Lambda-Version
X-A
X-FTR-Realm
Machine
X-A-Ccd
X-A-Dam
X-Aed
X-NAPM-TraceId
X-A-Wwc
X-A-Dgt
X-A-Dcw
X-ARC
MD5-Digest
X-B-Cookie
Mobile-Detection-Method
X-Cache-NE
X-CF-Lambda-Fn
X-Level-Front-Cache
Backend
Meta-Geo-Continent
Fastcgi-X-Cache-Version
Expiry
DCR-Processing-Time-Ms
DCR-Decision-By
X-Varnish-Cache-Hits
X-Time-Microsecs
X-FTR-DC
X-FTR-Cache-Status
X-Trv-Group
X-Vtex-Remote-Cache
X-ScT
X-Session-Fingerprint
X-Vtex-Processado-Em
X-FTR-Balancer
X-GEO
X-FTR-Backend
X-S
X-S-Cookie
X-Rojux
X-Rewrite-Enabled
X-Request-UUID
X-FTR-Backend-Server
X-PBS-Appsvrname
X-Processor
X-VG-WebCache
X-Origin-TTL
X-PAYTM-SRV-ID
X-Origin-CC
X-Vdms-Version
X-Vdms-Path
X-Owner
X-SRCache-Key
X-Country-Code-Real
X-VG-WebServer
X-Varnish-Beresp-Status
X-Magnolia-Registration
X-Unique-Id
X-Ratelimit-Remaining
X-Nc
HostName
X-FC-Vary-Parameters
X-Tumblr-Pixel-3
Wxu-Next-Region
X-Thinkindot-L3
X-TrackingId
X-Thanos
Host-ID
Wxu-Next-Hostname
X-Cache-Bucket
Gh-Request-Id
CacheControlHeader
Cache-Host
X-Azure-Ref-OriginShield
Content-Disposition
Cf-Device-Type
X-Bip
X-Cms-Context
Arc-Version
X-Developers
X-Device-Os
X-Fetched-On
AKAMAI
X-Core-Value
Fastly-Backend-Name
X-Geo-Header
Wxu-Next-Commit
Ssr
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
PB-RID
X-Reqid
X-Backend-TTL
X-Policy
PB-PID
X-OVcl-Cache
Path
X-B3-Traceid
Pagetype
X-JWT-State
Thinkindot-Control
X-Is-Gdpr
X-Generated-In
V-Age
UCS
Release
X-GeoIP-City
Magicmarker
X-OVcl
X-Has-Esi
X-ServerID
Server-Host
X-Unique-ID
X-VG-TLSProxy
Server-Hostname
Server-Ext
X-Var-Ttl
Esi-Enabled
X-IP
X-Branch-Name
True-Client-Country-4JS
X-Irp-Debug
Sever-Int
X-Backend-State
X-VServer
X-DPWN-IS-SECURE
X-Request-URI
X-Rebelmouse-Surrogate-Control
X-Li-Fabric
X-Rebelmouse-Cache-Control
X-HS-Content-Campaign-Id
X-HN
X-SIPLIST1
X-GeoIP
X-GoCache-CacheStatus
X-Scheme
X-Ratelimit-Reset
X-Li-Pop
X-Node-Id
X-Origin-Expires
X-Origin
X-NU-AKA-ACS-Version
X-Nginx-Cache-Key
X-Mvc-Supplant-Cachable
X-LI-UUID
X-Method
X-Platform-Server
X-Micro-Cache
X-Skip-Cache
X-SVT-ORM-RULES
X-Clientip
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-Csrf-Jwt
X-CGP
X-Varnish-Hits
X-Cache-Info
X-VarnishDD-TTL
X-Cache-Tags
X-Varnish-Remaining-TTL
X-Variation
X-DefElseHash
X-Eu-Site
X-Fastly-Backend
X-Fastly-Cache
X-SVT-ORM-VERSION
X-User
X-Epic-Correlation-Id
X-DefHash
X-Developer
X-Dispatcher-Server
X-Envoy-Decorator-Operation
X-Cache-Debug
Vix-Hermes-Req-Id
CDN-RequestId
CDN-RequestCountryCode
CDN-PullZone
CDN-EdgeStorageId
CDN-Uid
Cf-Bgj
Ha-Gx-Prefs
Fastly-SWR
Fastly-SIE
DSUID
CDN-CachedAt
CDN-Cache
Apple-News-Services-Handled
X-EC-Lua
X-DynaTrace-JS-Agent
NGB
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
CDCHOST
C-Via
Apple-News-Services-Request-Url
HA-Ipaddr
Adler-Geo
NGX
Locid
Location
NM-Fastcgi-Cache
Origin
Platform
PFcat
L5d-Success-Class
On-Server
L
IsBot
Is-Eu
User-Cache-Control
X-NewRelic-App-Data
X-Amz-Meta-S3cmd-Attrs
X-ID
X-Clara-WADP
Rt-Fastcgi-Cache
X-Old-Content-Length
X-Hash
X-LB-ID
X-Hnp-Log
Web-Mar-Node
X-Fmm-Version
Xc-Version
X-WADP-Cache
X-Block-Status
X-Esi-Check
X-Request-Host
X-Generated-By
X-Gen-Mode
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Gzip
X-Origin-Response-Time
X-Wikidot-Backend
X-Planisys-CDN-Cache
X-Loc
X-Swa-Ws
X-Cache-Id
X-Planisys-CDN-Rules
X-Aicache-OS
X-Wikidot-Static-Cache
X-Tb
X-Sucuri-ID
X-Gamma-Serve
X-Planisys-CDN-TTL
Fastly-Drupal-HTML
X-FTR-Expires
X-Air-Hostname
Cmstype
Cmsid
Req-Svc-Chain
X-Edge-Location-Klb
X-Slack-Backend
X-Varnish-Url
X-Kraken-Loop-Name
X-APP-VERSION
X-Kraken-Routeconfig-Destination
X-Instrumentation
X-Servername
X-Server-Lifecycle-Phase
X-PF-Uncompressing
X-Cdn-Forward
X-Mvc-Supplant-OutputCached
X-Via-Poph
X-Via-Popn
X-Via-Popv
Tracecode
Kp-EeAlive
Svr
Pics-Label
X-Served-From
A
X-Refresh
SR-User-Adfree
Instruction
X-Vgn-Hpd-Reason
Url
X-Cache-Var
X-Cache-Var-Map
X-CUA
M-TraceId
VivaBuild
Viewtype
X-SaId
SID
Cache-Key
Cross-Origin-Opener-Policy
X-DC
Lfy
X-Matched-Rule
X-NGENIX-Cache
X-JoinUs
Arc-Country
X-PHP-Backend
X-NC
X-Edge-Location
MIME-Version
X-Sn-Servicetimems
X-Cache-Expires
X-Cdn-Origin
X-Tb-Optimization-Total-Bytes-Saved
TDXMobile
CloudFront-Viewer-Country
Sid
X-TraceId
X-CDN-Forward
X-Vc
X-Cache-Backend
X-NCache
Pramga
Geo-Info
X-Service
X-Servedbyhost
X-Webkit-CSP-Report-Only
X-CLOUD-TRACE-CONTEXT
X-Core-Mission
NtCoent-Length
DataCenter
Content-Secure-Policy
Server-ID
X-Cache-Date
X-Extlb
X-Srv
X-Request-Start
X-Internal-Host
X-Wa
Tcn
X-Bc-Bl
Source
Geoip-Latitude
X-LI-Proto
GeoIp-Country-Code
X-HS-Status
X-Forwarded-Site
X-B3-Spanid
X-Error
FSS-Cache
X-FireWall-Protection
LB
X-Proxy-Upstream
X-Newrelic-Synthetics
X-Varnish-Cacheable
Memcached
Surrogated-Key
X-Via-NSCOPI
X-Req
X-Esi
Hostname
X-VHOST
CACHE
X-Response-By
Mail-Subject
X-Air-Source
X-VC-Cache
X-VCL-Version
X-Vcl-Version
We-Hiring
X-Accel-Expires-Debug
X-Date
Resin-Trace
X-HOST
Upgrade-Insecure-Requests
X-Geo
X-CCDN-Origin-Time
GeoIP-Latitude
X-CCDN-CacheTTL
X-Cache-Ttl
X-Proxy-Cachei7
X-Viewer-Country
Xkeyi7
X-App
GeoIP-Country-Code
X-RateLimit-Remaining-Second
X-Li-Proto
Request-ID
Env
X-PJAX-URL
X-Sigma
X-Rocket-Build-Number
X-Sigma-Backend
X-RateLimit-Limit-Second
X-Hcs-Proxy-Type
Server-Ttl
X-LiteSpeed-Cache-Control
X-MSEdge-Features
X-Men
X-MSEdge-Flight
X-DSS
X-TIM-N
N-Cache
HitType
X-RSL
X-RPS
X-DI
X-DW
X-RPM
X-DB
X-BBXSRF
Time
CF-Cached-On
Memory
X-ZONE
X-RAMCache
X-Cache-2
X-WA
X-Zone
X-Cs
X-APP
XServer
X-ServedByHost
X-Cc-Req-Id
D-Cc-Upstream
X-Action
X-Air-Trace-Id
X-Varnish-Authentication
X-Cc-Via
ProcessTime
X-UA
S-Rt
CPC-Age
X-Mg-Request-UUID
X-Contensis-Viewer-Groups
X-Svr
X-Cache-ASPX
VNS-Cache
VNS-Age
CPC-Cache
X-HostName
X-Oss-Cdn-Auth
X-FPC
X-Region-Sid
State
Fastcgi-Cache-TTL
My-App
Server-Id
X-Provided-By
X-Swift-Error
X-Dynatrace-Js-Agent
X-Fpc
X-Server-IP
X-Nyt-Route
X-Origin-Time
X-CF-Powered-By
W
Cache-Provider
X-Cache-Config
X-Depends-On
X-Minions-Version
X-API-Version
X-Gdpr
X-FORWARDED-FOR
Mime-Version
X-Cache-Remote
Srv
X-Cdn-Request-ID
Cteonnt-Length
CDN
X-UnsetCookies
X-TIME
X-Sucuri-Cache
X-Dw-Trace-Id
X-URL
Ohc-File-Size
X-Erf-Stays-Bingo-Pdp-Web
X-BACKEND-TTL
Cross-Origin-Window-Policy
X-Cache-Type
X-CSRF-TOKEN
X-Client-Ip
X-ServerName
X-Xrds-Location
X-Akamai-Pragma-Client-IP
Cdn
X-Hello
X-Flog
X-Check-Cacheable
X-VC
X-NodeID
X-SN
X-ABtesting
X-Fastly-Request-Id
Proxy-Connection
OT-Force-Account-Verify
X-Parent-Response-Time
Ohc-Cache-HIT
X-Ftr-Cache-Host
X-Pf-Uncompressing
X-SB
X-Pad
X-NGINX-Cache
X-Presslabs-Stats
X-SD-PageType
X-Tenant
X-Shop-Environment
X-Orig-Expires
Vha6-Origin
X-Fastly-Backend-Reqs
X-Oracle-DMS-ECID
Cf-Ipcountry
X-Forwarded-Path
X-ND-Cache
X-Snapshot-Date
X-Webstats-RespID
Media-Length
Dnion-Transfer-Encoding
X-Host-Name
X-Via-PopV
X-Via-PopH
X-Via-PopN
Datacenter
X-LiteSpeed-Tag
X-ElasticPress-Search
Epwk-X-Cache
X-Cluster-Node
X-Traceid
X-Air-Pt
WZWS-RAY
PICS-Label
X-BBC-Edge-Cache-Status
X-Ftr-Request-Id
X-Varnish-URL
X-Acquia-Application-Trace
X-Cache-Tag
X-BBC-Origin-Response-Status
Warning
X-Acquia-Site
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
EpKe-Alive
X-Ms-Meta-Staticbatchstarttime
X-Pjax-Url
X-Request-URL
X-Vcache
X-Akamai-ERPolicy
X-Akamai-ERRuleID
X-Render-Time
X-Lb-Id
X-MiniProfiler-Ids
X-Ms-Meta-Originalurl
X-Varnish-Beresp-TTL
Xet-Cookie
CountryCode
X-Cache-Status-Check
X-Mg-Request-Id
X-Apw-Hits
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-Conf
X-C
X-Yottaa-OS
Inserted-Into-Cache-At
X-Debug-Cache-Fetch
X-Debug-Cache-Store
URI
X-Redis-Duration-Ms
X-Redis-Count
Phost
Environment
Ohc-Response-Time
X-B3-Parentspanid
NnCoection
Content-Style-Type
X-Apw-Access-Action
X-Apw-Access-Object
Content-Script-Type
X-Litespeed-Cache-Control
X-Tid
X-Amz-Meta-Cb-Modifiedtime
X-Apw-Access-Token