Threat Level: green Handler on Duty: Jim Clausing

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
X-XSS-Protection
CF-RAY
Cf-Request-Id
CF-Cache-Status
Last-Modified
Accept-Ranges
Link
Pragma
Expect-CT
ETag
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Cache-Status
X-Generator
X-Request-ID
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Content-Security-Policy
Content-Encoding
X-CDN
X-Ua-Compatible
X-Envoy-Upstream-Service-Time
Status
Feature-Policy
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
X-AspNetMvc-Version
X-Xss-Protection
Access-Control-Max-Age
X-Via
Upgrade
Keep-Alive
X-Ws-Request-Id
X-Turbo-Charged-By
X-Age
X-AH-Environment
X-Robots-Tag
Request-Context
X-Proxy-Cache
EagleId
X-Cache-Group
X-Backend
Server-Timing
X-Hacker
X-Amz-Request-Id
Report-To
X-Server
X-Amz-Id-2
Host-Header
X-Server-Powered-By
X-UA-Device
X-Nginx-Cache-Status
Grace
X-Dns-Prefetch-Control
X-LiteSpeed-Cache
X-Varnish-Cache
X-Rq
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Swift-SaveTime
X-Page-Speed
Cf-Railgun
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
NEL
X-Amz-Version-Id
X-OneAgent-JS-Injection
Xkey
X-WebKit-CSP
Allow
X-Cache-Spec
X-Backend-Server
X-Host
X-Vhost
X-CST
EagleEye-TraceId
X-Device
X-Server-Id
Surrogate-Control
Request-Id
X-Dispatcher
X-Kinja-Server-Push
Accept-CH
X-Node
Content-Location
X-Response-Time
X-Akam-SW-Version
Accept-CH-Lifetime
X-Ruxit-JS-Agent
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-ASPNET-VERSION
X-Template
X-Language
X-Ac
X-Application-Context
X-Country
X-Readtime
X-Cloud-Trace-Context
X-Mod-Pagespeed
X-Cache-Lookup
MS-Author-Via
X-Origin-Cache
X-B3-TraceId
Rating
X-Cnection
X-MS-InvokeApp
X-ORACLE-DMS-ECID
X-HW
Accept-Ch
X-Url
X-TtlSet
X-PC
X-Vname
X-Clacks-Overhead
X-ESI
Edge-Control
X-GitHub-Request-Id
Accept-Ch-Lifetime
X-FastCGI-Cache
X-Trace
Response
Display
X-Middleton-Display
Pagespeed
X-Sol
X-Middleton-Response
X-Content-Type
X-Buckets
X-D2id
Verso
X-Vcap-Request-Id
X-Exp-Variant
X-Kinja
X-Exp-Id
X-GoogleNews-Bot
X-Kinja-Server
X-Cdn-Fetch
X-Kinja-Build
X-Use-Magma
X-Kinja-Revision
Arr-Disable-Session-Affinity
X-Goog-Hash
X-Server-Name
X-Rack-Cache
X-Varnish-TTL
Service-Worker-Allowed
X-Country-Code
X-Oneagent-Js-Injection
X-Navigation-Version
X-VARITI-CCR
X-Abt-Application-Version
X-Amz-Rid
X-ORACLE-DMS-RID
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
X-Cache-TTL
X-Client-IP
X-Powered-By-Plesk
X-SharePointHealthScore
SPRequestGuid
SPRequestDuration
SPIisLatency
X-Fastly-Request-ID
X-Release
X-TTL
X-MSEdge-Ref
X-Dw-Request-Base-Id
X-Element-Page-Cache
Fastly-Restarts
X-NF-Request-ID
X-Cached
X-Origin-Upstream-Status
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Webkit-CSP
Public-Key-Pins
RTSS
X-Px
AR-Request-ID
Ar-Sid
X-Edge
AR-CACHE
AR-PoweredBy
AR-ATIME
Fusion-Content-Source
Fusion-Content-Id
Fusion-Component-Id
Fusion-Template-Id
Fusion-Source
Fusion-Deployment-Id
X-SRCache-Store-Status
Access-Control-Request-Method
X-SRCache-Fetch-Status
X-LLID
X-Powered-CMS
X-Upstream
X-Ezoic-Cdn
X-Pinterest-Direct
Content-MD5
X-HP-Webp
X-Jurisdiction
X-Amz-Server-Side-Encryption
X-Ttl
X-Mid
X-ECACHE
X-MCACHE
Charset
X-Content-Digest
X-Recruiting
S
X-Aspnetmvc-Version
X-Mg-S
Cache-Tag
X-PressLabs-Stats
MicrosoftSharePointTeamServices
TCN
X-Version
X-Debug
Front-End-Https
Fastcgi-Cache
X-Grace
X-Content-Security-Policy-Report-Only
X-XRDS-Location
X-T
Filters
Cache-Tags
X-Kinsta-Cache
Edge-Cache-Tag
Server-Node
X-Id
X-Forwarded-Proto
X-Yandex-Sdch-Disable
X-Amzn-Trace-Id
X-Cache-Key
Powered-By-ChinaCache
X-Accel-Expires
X-Correlation-Id
Surrogate-Key
X-Logged-In
Server-Name
X-Forwarded-For
Nginx-Cache
X-Varnish-Age
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-DynaTrace
X-B3-Sampled
X-DIS-Request-ID
X-Hits
X-Request-Handler-Origin-Region
X-Server-ID
X-Microsite
X-Ser
TP-Cache
TP-L2-Cache
X-Request-Received
X-Request-Processing-Time
X-AppVersion
X-Activity-Id
X-Shield-Request-Id
X-Amz-Replication-Status
X-Az
X-FTR-Request-ID
X-HS-Content-Id
X-HS-Combine-CSS
X-F-Cache
X-HS-Hub-Id
X-HS-Cache-Config
Accept-Charset
X-Goog-Storage-Class
X-Goog-Metageneration
X-Git-Hash
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
X-Origin-Server
X-Respond-Thread
X-Hostname
X-Geo-Country
X-DataDome
X-LB-Cache
Section-Io-Cache
X-Upgrade-Enabled
X-Rid
X-Frontend
X-Cache-Age
X-Ruxit-Js-Agent
Access-Control-Allow-Method
Cleartype
X-Mobile-URL
Host
Healthy
Paypal-Debug-Id
X-Type
Cache
Alternate-Protocol
X-Content-Options
X-TEC-API-VERSION
X-IPLB-Instance
MS-CV
ServerID
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-AOL-HN
X-Varnish-Backend
X-App-Environment
X-WebKit-CSP-Report-Only
Payment
X-Whom
X-Route-Name
X-Request-Guid
X-Is-Crawler
X-TT
X-Signature
X-Providence-Cookie
X-Debug-Info
X-Aspnet-Duration-Ms
X-B-Cache
X-Flags
X-Cache-Action
X-VCache
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Seen-By
Fastcgi-Useragent
X-Page-Id
X-Jobs
X-Mobile
X-Source
X-XRDS-LOCATION
X-N
X-Cached-By
X-Load-Cache
X-Browser-Type
X-NWS-LOG-UUID
X-Time
X-Akamai-Edgescape
Nel
X-Via-JSL
X-RateLimit-Remaining
X-Litespeed-Cache
Version
X-FB-Debug
DynaTrace
X-Cache-Operation
X-Cache-Rule
Viewport
X-Fastcgi-Cache
X-Rule
X-Accel-Buffering
X-Original-Request-Id
X-Response-Served-From
X-Zen-Fury
X-Drupal-Cache-Tags
DC
X-Framework
X-Daa-Tunnel
X-Proxy
Refresh
X-ProcessESI
X-Instance
X-Tt-Trace-Tag
Realpath
X-RemovedCookies
X-Cacheable-TTL
X-Tt-Trace-Host
X-RTag
Access-Control-Request-Headers
Referer-Policy
GEO-INFO
X-Region
Ms-Operation-Id
X-Real-IP
X-Cache-Time
X-Node-Name
X-UUID
X-HTML-Minification-Powered-By
X-FW-Server
X-FW-Serve
X-Yottaa-Optimizations
X-Distributor
X-FW-Hash
X-FW-Type
X-Contextid
X-Page-View
X-L-Path
X-Drupal-Cache-Contexts
X-FW-Static
X-Yottaa-Metrics
X-FW-Dynamic
X-Environment-Context
VIX-Pulpo-Node
Eomportal-Instance
X-Cache-Expired-At
VIX-Pulpo-Upstream-Status
X-Wix-Request-Id
X-B
Liferay-Portal
X-Cluster-Name
Node
Countrycode
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel-1
X-G
X-Cache-Control
X-Amz-Meta-S3cmd-Attrs
X-Content-Powered-By
X-User-Agent
X-IPS-LoggedIn
X-Cache-Hit
X-Tumblr-Pixel-2
Webserver
Section-Io-Id
Section-Io-Origin-Status
Section-Origin-Responded
Server-Info
Section-Io-Origin-Time-Seconds
SRV
X-Ratelimit-Limit
From-Origin
Protected
X-App-Server
X-Revision
X-Protected-By
X-Oracle-Dms-Rid
X-Pass-Why
Ec-Rule-Version
Cache-Status
X-Backend-Name
Frame-Options
X-Cache-Server
X-Hyper-Cache
X-FireWall-Port
X-RN-RSRV
X-Hl-Ver
Meta-Geo
X-Endurance-Cache-Level
Retry-After
X-UPSTREAM-Address
X-ES-SERVER
X-Mode
X-Handled-By
X-Site-Version
X-Varnish-Ttl
X-Via-CDN
X-Soup
X-Storage
X-Adobe-Loc
X-Forwarded-Host
X-Adobe-Content
X-FB-TRIP-ID
X-NYM-Debug-Backend
X-Locale
Cache-Tv-Group
Fastly-SSL
Decoy-Debug-TTL
X-Www-Served-By
Decoy-Debug-Status
TWC-Device-Class
X-Origin-Hint
X-Pubstack
X-Web-Node
X-Be
Country
X-Access
X-Cache-Grace
CF-IPCountry
TWC-Connection-Speed
Property-Id
X-Human
Webcakes-Region
X-Format
TWC-Locale-Group
Decoy-Debug-Key
TWC-GeoIP-LatLong
X-Varnishpool
TWC-Privacy
Webcakes-App-Version
Webcakes-App-Name
X-Section
TWC-GeoIP-Country
Azure-Version
Azure-SlotName
Azure-SiteName
Azure-RegionName
Cache-Name
X-Timing-Wait
X-PCL
X-UA-Device-Type
X-TT-LOGID
X-PERF
Azure-InstanceId
X-PHP-Host
X-ProxyCache-Key
X-Redis-Cache
X-ApacheServer
X-ProxyCache-Status
X-Proxy-Build
X-Say-Cacheable
X-Proto
X-SayCDN-TTL
X-Say-TTL
X-Origin-Date
X-Uri
X-FW-Version
X-Country-Code-Real
X-FTR-Backend-Server
X-FTR-Realm
X-Labrador-Cache-Channel
X-FTR-Backend
X-FTR-Balancer
X-BYPASS-REASON
Selected-Fe
S-Cnection
X-FTR-DC
X-FTR-Cache-Status
X-OCL
X-Server-W
X-S-Maxage
X-Sql-Count
X-No-Session
X-Qloud-Router
X-Via-Fastly
X-AIR-PT
X-WA-Info
X-Sql-Duration-Ms
X-LAGOON
X-AWS-Id
Mn-Server-Ip
X-Loop
X-LJ-Flow-ID
X-Hosted-By
X-R9-Blue-Green-Version
X-FTR-Expires
X-VWS-Id
X-TNCMS
X-Status
X-Cluster
X-Request-Time
X-Cache-Var
X-Ratelimit-Remaining
X-Cache-Var-Map
X-Cache-TTL-Remaining
Cache-Hits
X-Xfnlog-Site
X-CCM
X-Alternate-Cache-Key
X-MP-GENERATED-AT
X-Dynatrace
X-Zipkin-Id
X-Sorting-Hat-ShopId
X-Shopify-Stage
X-Storefront-Renderer-Rendered
X-ShardId
X-Routing-Service
X-Sorting-Hat-PodId
X-ShopId
X-Proxied
Xserver
X-Is-Bot
X-Air-Hostname
X-Rendered-As
AMP-Access-Control-Allow-Source-Origin
X-Webkit-Csp
X-Detected-As
X-Cache-Host
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Amzn-Remapped-Content-Length
X-Cdn
X-Unique-Id
X-EdgeConnect-Cache-Status
X-SRV
Apigw-Requestid
X-Info
X-Device-Type
X-B3-Traceid
X-Dc
X-Microcachable
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
X-Nginx-Cache
SD-X-WS
X-Cache-Backend
X-Time-Microsecs
X-GEO
X-Cache-Enabled
X-APP-VERSION
X-Content-Age
Tracecode
X-Backend-TTL
X-ServerID
X-Platform
X-Debug-IsConnected
X-Varnish-Server
X-Debug-IsPreview
X-Azure-Ref
X-Erf-Stays-Bingo-Pdp-Web
Amp-Access-Control-Allow-Source-Origin
X-Backend-Host
DSUID
X-Varnish-Grace
X-DynaTrace-JS-Agent
Uber-Trace-Id
X-NewRelic-App-Data
X-Sucuri-ID
X-Oss-Object-Type
X-Tb
X-Oss-Request-Id
X-Oss-Storage-Class
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-GG-Cache-Date
X-ID
PB-RID
PB-PID
X-Correlation-ID
Akamai-GRN
Arc-Version
X-BCube-Filmed-By
Backend
X-Cache-Remote
X-Akamai-Transformed
X-Proxy-Cache-Status
X-Origin-Response-Time
X-Magnolia-Registration
X-ATG-Version
X-Session-Fingerprint
X-S
Fastcgi-X-Cache-Version
Xc-Version
X-S-Cookie
X-ScT
DCR-Processing-Time-Ms
X-VG-WebCache
X-Vdms-Version
X-VG-WebServer
Instruction
X-Varnish-Cache-Hits
X-Vtex-Processado-Em
X-Vdms-Path
X-Trace-Id
X-Thinkindot-L3
X-SRCache-Key
X-Trv-Group
X-Vtex-Remote-Cache
DCR-Decision-By
Expiry
X-PBS-Appsvrname
X-CF-Lambda-Fn
SR-User-Adfree
T-Server
Thinkindot-CacheControl
Rendered-Blocks
Pramga
X-D
Path
X-Connection-Hash
X-CF-Lambda-Version
Thinkindot-CacheControl-Type
X-Cache-NE
X-A-Dgt
Thinkindot-Control
X-A-Dcw
X-A-Dam
X-A-Wwc
X-Aed
X-B-Cookie
X-ARC
X-Application
Odigeo-Trace-Id
X-Destination
X-Origin-TTL
Machine
X-Origin-CC
X-Matched-Rule
X-PAYTM-SRV-ID
X-A-Ccd
X-Rewrite-Enabled
X-Request-UUID
X-Processor
Lfy
X-Location
X-Level-Front-Cache
Meta-Geo-Continent
X-External-Request-Id
X-Device-Os
Mobile-Detection-Method
X-Fetched-On
X-From
MD5-Digest
X-Generation-Time
X-Generated-On
X-Rojux
X-A
CACHE
ServedBy
X-CSRF-Token
X-Adobe-Source
X-RCS-CacheZone
X-Bip
X-Generated-In
Fastly-Backend-Name
Gh-Request-Id
Host-ID
X-Backend-State
HA-Ipaddr
Ha-Gx-Prefs
X-Cache-Bucket
X-Csrf-Jwt
Wxu-Next-Hostname
X-Request-URI
X-Cache-Date
X-Has-Esi
X-HN
X-GeoIP
Cf-Device-Type
L
X-VarnishDD-TTL
X-Geo-Header
X-Owner
X-Azure-Ref-OriginShield
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Swa-Ws
X-FC-Vary-Parameters
X-Sn-Servicetimems
Ssr
Wxu-Next-Commit
Wxu-Next-Region
X-Eu-Site
X-Skip-Cache
PFcat
X-Thanos
Magicmarker
X-User
Locid
CacheControlHeader
X-Tumblr-Pixel-3
X-Developers
Pagetype
DB-Nickname
X-NC
L5d-Success-Class
X-OVcl-Cache
X-Mvc-Supplant-Cachable
Release
X-GeoIP-City
X-Cdn-Origin
X-HS-Content-Campaign-Id
X-Reqid
X-Irp-Debug
X-Varnish-Hostname
X-Is-Gdpr
X-JWT-State
X-Wikidot-Static-Cache
BehaviorPad-Version
X-VServer
X-Wikidot-Backend
X-Request-Start
X-CGP
X-OVcl
C-Via
Cache-Host
X-Node-Id
AKAMAI
X-Cache-NGX
X-Cache-PHP
X-Micro-Cache
X-Cache-Info
X-Ms-Version
X-Ms-Request-Id
X-Scheme
X-Developer
X-Policy
NGX
UCS
Server-Hostname
X-Fastly-Cache
Sever-Int
X-Method
Server-Host
Server-Ext
On-Server
User-Cache-Control
X-Fastly-Backend
Rt-Fastcgi-Cache
X-Origin-Expires
X-Var-Ttl
CloudFront-Viewer-Country
Apple-News-Services-Handled
Content-Disposition
X-IP
X-Core-Value
Cf-Bgj
Apple-News-Services-Host
X-Nginx-Cache-Key
X-Host-Name
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
X-Varnish-Hits
V-Age
X-Envoy-Decorator-Operation
X-Clientip
X-Debug-Cache
CDCHOST
X-Cms-Context
X-Cache-Tags
X-CUA
X-Generated-By
X-Request-Host
X-Varnish-Beresp-Grace
X-Servername
X-Clara-WADP
X-Rebelmouse-Surrogate-Control
X-DefElseHash
X-Branch-Name
X-Cache-Debug
X-Cache-Expires
X-Cache-Id
X-Block-Status
X-NWS-UUID-VERIFY
X-Rebelmouse-Cache-Control
X-Dispatcher-Server
X-DefHash
X-Ratelimit-Reset
X-DPWN-IS-SECURE
IsBot
X-Gzip
X-VG-TLSProxy
X-Hnp-Log
X-GoCache-CacheStatus
X-Varnish-Remaining-TTL
Fastly-SIE
Web-Mar-Node
X-Varnish-CookieINHashed-On
Adler-Geo
X-WADP-Cache
X-Loc
X-Origin
X-Old-Content-Length
X-LI-UUID
X-TrackingId
X-Li-Fabric
X-Li-Pop
Fastly-SWR
X-Varnish-CookieHashed-On
Platform
Origin
NM-Fastcgi-Cache
X-NU-AKA-ACS-Version
True-Client-Country-4JS
Vix-Hermes-Req-Id
X-Esi-Check
X-SIPLIST1
X-Gen-Mode
X-Fmm-Version
X-Platform-Server
Location
X-Variation
Is-Eu
X-TX-ID
X-B3-Spanid
X-Varnish-Beresp-Status
X-Varnish-Beresp-Ttl
X-NCache
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Hash
X-Gamma-Serve
X-Slack-Backend
CDN-RequestCountryCode
CDN-RequestId
CDN-Uid
X-Varnish-Url
CDN-PullZone
CDN-EdgeStorageId
S-Rt
CDN-Cache
CDN-CachedAt
X-Varnish-Cacheable
Fastly-Drupal-HTML
X-Response-By
X-CS
X-Core-Mission
Xkeyi7
X-Refresh
X-PF-Uncompressing
Url
X-EC-Lua
X-Proxy-Cachei7
X-NAPM-TraceId
HostName
Cross-Origin-Window-Policy
X-URL
X-BBXSRF
X-CACHE-GROUP
Pics-Label
X-Aicache-OS
X-App-Version
X-Sucuri-Cache
N-Cache
X-Mvc-Supplant-OutputCached
X-Cdn-Forward
X-Cache-2
X-CDN-Forward
Content-Secure-Policy
Ohc-File-Size
X-B3-SpanId
X-Varnish-Authentication
X-LB-ID
D-Cc-Upstream
X-FireWall-Protection
X-Cc-Req-Id
X-Cache-ASPX
X-Cc-Via
X-Contensis-Viewer-Groups
Cteonnt-Length
Sid
X-Svr
X-Via-Popv
X-Via-Poph
X-Via-Popn
Esi-Enabled
X-Servedbyhost
X-TA-CDN-Provider
X-Tb-Optimization-Total-Bytes-Saved
MIME-Version
X-DC
X-Wa
X-Error
X-Server-IP
X-Srv
X-Epic-Correlation-Id
X-Origin-Time
X-Unique-ID
X-Nyt-Route
X-TIME
X-API-Version
X-Cache-Config
X-FPC
X-Gdpr
Source
X-Cs
X-Webkit-CSP-Report-Only
Hostname
XServer
X-SN
X-VC
Geoip-Latitude
HitType
GeoIp-Country-Code
Ohc-Cache-HIT
X-RateLimit-Limit
Server-Ttl
X-NodeID
X-SB
X-TraceId
X-LI-Proto
X-Webstats-RespID
Req-Svc-Chain
Who
X-Fastly-Request-Id
X-NGINX-Cache
X-SD-PageType
Server-ID
X-VCL-Version
X-Check-Cacheable
X-LiteSpeed-Cache-Control
X-Nc
Country-Code
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
X-HS-Status
Geo-Info
X-Ua
X-Esi
EpKe-Alive
Kp-EeAlive
X-BBC-Edge-Cache-Status
Cmstype
SID
Cmsid
X-Render-Time
Svr
X-HOST
NtCoent-Length
X-Viewer-Country
Viewtype
VivaBuild
Request-ID
X-Worker
X-Vgn-Hpd-Reason
X-Served-From
X-Ftr-Cache-Host
X-Auto-Login
X-UA
X-Dynatrace-Js-Agent
X-RAMCache
X-DW
X-CACHE-KEY
X-CSRF-TOKEN
X-RPS
X-RSL
Resin-Trace
ProcessTime
X-Vcl-Version
X-DB
Cache-Key
X-RPM
Cache-Provider
X-DSS
X-DI
A
X-Hcs-Proxy-Type
X-CCDN-CacheTTL
X-Cluster-Node
M-TraceId
GeoIP-Latitude
X-Li-Proto
GeoIP-Country-Code
X-TIM-N
X-CCDN-Origin-Time
CDN
Server-Id
X-Newrelic-Synthetics
Upgrade-Insecure-Requests
Processtime
X-Internal-Host
X-Air-Source
Arc-Country
X-App
X-CF-Powered-By
TDXMobile
Cross-Origin-Opener-Policy
X-Action
X-FTR-Cache-Host
Datacenter
Tcn
X-Fpc
X-Oss-Cdn-Auth
CF-Cached-On
X-CLOUD-TRACE-CONTEXT
OT-Force-Account-Verify
WZWS-RAY
Mime-Version
X-WA
X-ServedByHost
X-Geo
X-BBC-Origin-Response-Status
Srv
X-FORWARDED-FOR
X-Vc
X-HostName
X-HITS
X-Dw-Trace-Id
X-BACKEND-TTL
Cdn
X-Service
X-Via-PopH
X-Via-PopN
X-Via-PopV
X-ND-Cache
X-Pinterest-Sli-Response-Type
X-Pinterest-Sli-Endpoint-Name
X-Pinterest-Sli-Latency-Threshold
X-Lb-Id
X-Cache-Tag
X-Fastly-Backend-Reqs
X-MSEdge-Flight
X-MSEdge-Features
Proxy-Connection
X-CACHE-AGE
X-Client-Ip
Filterid
X-Flog
X-Hello
X-ABtesting
X-IN-APIGATEWAYSSL
Dnion-Transfer-Encoding
X-IN-APIGATEWAY
X-Parent-Response-Time
X-Via-NSCOPI
URI
X-Pf-Uncompressing
Vha6-Origin
X-Presslabs-Stats
DataCenter
X-Oracle-DMS-ECID
W
X-Forwarded-Site
FSS-Cache
NGB
PICS-Label
X-Acc-Rdl
X-Acc-Debug-Context
CountryCode
Media-Length
X-SaId
X-PHP-Backend
X-Akamai-Request-ID
X-LiteSpeed-Tag
X-Cdn-Request-ID
X-Akamai-Pragma-Client-IP
X-NGENIX-Cache
X-Request-URL
X-JoinUs
X-MiniProfiler-Ids
X-Edge-Location
Cf-Ipcountry
X-Extlb
X-Acquia-Purge-Tags
X-ElasticPress-Query
X-Ms-Meta-Staticbatchstarttime
X-Region-Sid
X-Acquia-Application-UUID
X-Req
X-Akamai-ERRuleID
X-Vcache
X-Akamai-ERPolicy
Memcached
X-Bc-Bl
X-Accel-Expires-Debug
X-Date
X-Proxy-Upstream
X-Depends-On
X-PJAX-URL
We-Hiring
X-RateLimit-Limit-Second
Mail-Subject
LB
X-Ms-Meta-Originalurl
X-RateLimit-Remaining-Second
Surrogated-Key
Epwk-X-Cache
X-Acquia-Site
X-Swift-Error
Content-Style-Type
X-UnsetCookies
Inserted-Into-Cache-At
Content-Script-Type
X-VC-Cache
X-B3-Parentspanid
X-Via-SSL
X-Via-Edge
X-Pad
Edge-Copy-Time
X-Varnish-Beresp-TTL
X-Acquia-Application-Trace
X-Csrf-Token
X-ElasticPress-Search
X-Traceid
X-Request-Url
X-Provided-By
X-ZONE
X-Sigma-Backend
X-Zone
X-APP
X-Rocket-Build-Number
X-Tid
X-Varnish-URL
Env
X-Sigma
NnCoection
X-Redis-Count
X-Redis-Duration-Ms
X-Snapshot-Date
Environment
X-C
X-ServerName
X-Storefront-Renderer-Verified
X-Litespeed-Cache-Control
Akamai-Age-Ms
Time
X-Debug-Cache-Fetch
Memory
Ohc-Response-Time
Xet-Cookie
Phost
X-Debug-Cache-Store