Threat Level: green Handler on Duty: Jim Clausing

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
X-XSS-Protection
CF-RAY
Cf-Request-Id
CF-Cache-Status
Last-Modified
Accept-Ranges
Link
Pragma
Expect-CT
ETag
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Cache-Status
X-Generator
X-Request-ID
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Content-Security-Policy
Content-Encoding
X-CDN
X-Envoy-Upstream-Service-Time
Status
X-Ua-Compatible
Feature-Policy
Access-Control-Expose-Headers
X-AspNetMvc-Version
X-Drupal-Dynamic-Cache
Access-Control-Max-Age
X-Via
X-Xss-Protection
Upgrade
Keep-Alive
X-Ws-Request-Id
X-Age
X-Turbo-Charged-By
X-AH-Environment
X-Robots-Tag
Request-Context
X-Proxy-Cache
EagleId
X-Cache-Group
Server-Timing
X-Backend
X-Hacker
X-Amz-Request-Id
Report-To
X-Server
Host-Header
X-Amz-Id-2
X-Server-Powered-By
X-UA-Device
X-Nginx-Cache-Status
Grace
X-LiteSpeed-Cache
X-Dns-Prefetch-Control
X-Varnish-Cache
X-Rq
Ali-Swift-Global-Savetime
X-Swift-SaveTime
X-Swift-CacheTime
X-Page-Speed
Cf-Railgun
X-Pingback
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Amz-Version-Id
NEL
X-OneAgent-JS-Injection
Xkey
X-WebKit-CSP
Allow
X-Cache-Spec
X-Backend-Server
X-Vhost
X-CST
X-Device
EagleEye-TraceId
X-Host
X-Server-Id
Surrogate-Control
Request-Id
X-Dispatcher
Accept-CH
X-Node
X-Kinja-Server-Push
Content-Location
X-Response-Time
Accept-CH-Lifetime
X-Akam-SW-Version
X-Ruxit-JS-Agent
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-ASPNET-VERSION
X-Template
X-Language
X-Ac
X-Application-Context
X-Country
X-Readtime
X-Cloud-Trace-Context
X-Cache-Lookup
X-Mod-Pagespeed
MS-Author-Via
X-Origin-Cache
X-B3-TraceId
Rating
X-MS-InvokeApp
X-Cnection
X-HW
X-ORACLE-DMS-ECID
X-Url
X-TtlSet
X-PC
X-Vname
Accept-Ch
X-Clacks-Overhead
X-ESI
Edge-Control
X-FastCGI-Cache
X-GitHub-Request-Id
Accept-Ch-Lifetime
X-Trace
X-Sol
X-Middleton-Response
X-Middleton-Display
Pagespeed
Response
Display
X-Content-Type
X-D2id
X-Buckets
Verso
X-Exp-Variant
X-Cdn-Fetch
X-Exp-Id
X-GoogleNews-Bot
X-Kinja-Server
X-Use-Magma
X-Kinja-Revision
X-Kinja-Build
X-Kinja
X-Vcap-Request-Id
Arr-Disable-Session-Affinity
X-Goog-Hash
X-Server-Name
X-Rack-Cache
X-Country-Code
Service-Worker-Allowed
X-Navigation-Version
X-VARITI-CCR
X-Varnish-TTL
X-Abt-Application-Version
X-Amz-Rid
X-ORACLE-DMS-RID
X-Oneagent-Js-Injection
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
X-Cache-TTL
X-Client-IP
X-Powered-By-Plesk
SPRequestGuid
X-SharePointHealthScore
X-TTL
SPIisLatency
X-Fastly-Request-ID
SPRequestDuration
X-Release
X-MSEdge-Ref
X-Dw-Request-Base-Id
X-Element-Page-Cache
Fastly-Restarts
X-NF-Request-ID
X-Cached
X-B3-TraceId-Primal
Public-Key-Pins
MRF-Tech
Mrf-Cache-Status
RTSS
X-Origin-Upstream-Status
X-Edge
AR-ATIME
Ar-Sid
AR-CACHE
AR-Request-ID
AR-PoweredBy
X-Px
Access-Control-Request-Method
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Webkit-CSP
X-LLID
Fusion-Deployment-Id
Fusion-Content-Id
Fusion-Template-Id
X-Powered-CMS
Fusion-Component-Id
Fusion-Source
Fusion-Content-Source
X-Upstream
X-Ezoic-Cdn
Content-MD5
X-Pinterest-Direct
X-HP-Webp
X-Jurisdiction
X-Amz-Server-Side-Encryption
X-ECACHE
X-MCACHE
X-Mid
Charset
X-Recruiting
X-Content-Digest
S
X-Mg-S
X-Ttl
Cache-Tag
X-PressLabs-Stats
X-Aspnetmvc-Version
MicrosoftSharePointTeamServices
X-Version
TCN
X-Debug
Front-End-Https
Fastcgi-Cache
X-Content-Security-Policy-Report-Only
X-T
X-Grace
Filters
Cache-Tags
X-Kinsta-Cache
Edge-Cache-Tag
X-XRDS-Location
Server-Node
X-Id
X-Forwarded-Proto
X-Yandex-Sdch-Disable
X-Cache-Key
X-Amzn-Trace-Id
X-Accel-Expires
X-Logged-In
X-Forwarded-For
Server-Name
Nginx-Cache
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Varnish-Age
Surrogate-Key
Powered-By-ChinaCache
X-Correlation-Id
X-DynaTrace
TP-Cache
TP-L2-Cache
X-Hits
X-B3-Sampled
X-Request-Received
X-Microsite
X-Ser
X-Request-Processing-Time
X-DIS-Request-ID
X-Request-Handler-Origin-Region
X-Shield-Request-Id
X-Az
X-AppVersion
X-Amz-Replication-Status
X-Activity-Id
X-Server-ID
X-F-Cache
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
X-FTR-Request-ID
X-Goog-Stored-Content-Length
Accept-Charset
X-Goog-Generation
X-GUploader-UploadID
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Git-Hash
X-Origin-Server
X-Hostname
X-Respond-Thread
X-Geo-Country
X-DataDome
X-LB-Cache
Section-Io-Cache
X-Upgrade-Enabled
Nel
X-Rid
X-Frontend
X-Cache-Age
Access-Control-Allow-Method
X-Mobile-URL
Host
Cleartype
Alternate-Protocol
Paypal-Debug-Id
Healthy
X-Type
MS-CV
X-Content-Options
X-IPLB-Instance
ServerID
Cache
X-AOL-HN
X-WebKit-CSP-Report-Only
X-Ruxit-Js-Agent
X-App-Environment
Payment
X-Whom
X-Varnish-Backend
X-B-Cache
X-Aspnet-Duration-Ms
X-VCache
X-Flags
X-Signature
X-TT
X-Request-Guid
X-Providence-Cookie
X-Debug-Info
X-Is-Crawler
X-Cache-Action
X-Route-Name
X-XRDS-LOCATION
X-Seen-By
X-TEC-API-VERSION
Fastcgi-Useragent
X-Page-Id
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Erf-Bev-Bev
X-Jobs
X-Erf-Bev-Bev-Is-Generated
X-Mobile
X-N
X-Source
X-NWS-LOG-UUID
X-Load-Cache
X-Time
X-Browser-Type
X-Cached-By
X-Via-JSL
X-Akamai-Edgescape
Version
X-FB-Debug
X-RateLimit-Remaining
Viewport
X-Cache-Rule
X-Daa-Tunnel
DynaTrace
X-Cache-Operation
X-Litespeed-Cache
X-Accel-Buffering
X-Original-Request-Id
X-Response-Served-From
X-Rule
Refresh
X-Drupal-Cache-Tags
X-Zen-Fury
DC
X-Framework
Realpath
X-Proxy
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Instance
Referer-Policy
GEO-INFO
X-ProcessESI
X-Cacheable-TTL
X-RemovedCookies
X-RTag
Ms-Operation-Id
Access-Control-Request-Headers
X-Fastcgi-Cache
X-Region
X-Real-IP
X-Contextid
X-UUID
X-HTML-Minification-Powered-By
X-Cache-Time
X-Yottaa-Metrics
X-Environment-Context
X-Drupal-Cache-Contexts
X-Distributor
X-Yottaa-Optimizations
X-FW-Serve
X-FW-Static
X-FW-Type
X-L-Path
X-Page-View
X-FW-Server
X-FW-Hash
X-FW-Dynamic
X-Cache-Expired-At
VIX-Pulpo-Node
Eomportal-Instance
VIX-Pulpo-Upstream-Status
X-Wix-Request-Id
X-Node-Name
X-B
Node
Liferay-Portal
X-Cluster-Name
X-G
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel-1
Countrycode
X-Cache-Control
X-Content-Powered-By
X-IPS-LoggedIn
X-User-Agent
X-Cache-Hit
X-Amz-Meta-S3cmd-Attrs
X-Ratelimit-Limit
X-Tumblr-Pixel-2
Webserver
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Io-Id
Section-Origin-Responded
X-Varnish-Ttl
Server-Info
From-Origin
Protected
X-App-Server
X-Revision
X-Pass-Why
X-Protected-By
SRV
Ec-Rule-Version
X-Backend-Name
X-Cache-Server
X-FireWall-Port
Cache-Status
Frame-Options
X-Oracle-Dms-Rid
X-Hyper-Cache
X-UPSTREAM-Address
X-Hl-Ver
X-Handled-By
X-RN-RSRV
Meta-Geo
X-ES-SERVER
X-Endurance-Cache-Level
Retry-After
X-Mode
X-NYM-Debug-Backend
X-FB-TRIP-ID
X-Soup
X-Www-Served-By
X-Storage
X-Site-Version
X-Adobe-Loc
X-Adobe-Content
X-Forwarded-Host
CF-IPCountry
X-Ratelimit-Remaining
X-Locale
Decoy-Debug-Key
Fastly-SSL
X-Pubstack
Cache-Tv-Group
X-Human
X-Section
TWC-Device-Class
TWC-Privacy
TWC-Locale-Group
TWC-Connection-Speed
TWC-GeoIP-LatLong
Decoy-Debug-TTL
Decoy-Debug-Status
X-Web-Node
Property-Id
X-Varnishpool
Webcakes-App-Name
X-Format
X-Origin-Hint
Country
X-Be
X-Access
Webcakes-Region
X-Via-CDN
Webcakes-App-Version
X-Cache-Grace
TWC-GeoIP-Country
X-PHP-Host
X-PERF
X-PCL
X-Origin-Date
X-Proto
X-Proxy-Build
X-Say-TTL
X-Say-Cacheable
X-Redis-Cache
X-ProxyCache-Key
X-OCL
Azure-InstanceId
X-FW-Version
X-BYPASS-REASON
Selected-Fe
X-ApacheServer
X-Labrador-Cache-Channel
Cache-Name
Azure-RegionName
Azure-SiteName
Azure-SlotName
Azure-Version
X-SayCDN-TTL
X-ProxyCache-Status
X-TT-LOGID
X-Uri
X-UA-Device-Type
X-Timing-Wait
X-FTR-Backend
X-S-Maxage
X-LAGOON
X-WA-Info
X-Country-Code-Real
X-FTR-Backend-Server
X-No-Session
S-Cnection
X-FTR-Balancer
X-Sql-Count
X-Sql-Duration-Ms
X-AIR-PT
X-Via-Fastly
X-FTR-Realm
X-Server-W
X-FTR-Cache-Status
X-FTR-DC
X-Hosted-By
X-AWS-Id
X-VWS-Id
Mn-Server-Ip
X-Loop
X-LJ-Flow-ID
X-TNCMS
X-Qloud-Router
X-Status
X-Cache-TTL-Remaining
X-FTR-Expires
X-Cluster
X-Request-Time
X-R9-Blue-Green-Version
X-Shopify-Stage
X-CCM
X-Sorting-Hat-PodId
X-MP-GENERATED-AT
X-Alternate-Cache-Key
X-Proxied
X-ShardId
X-Routing-Service
X-Zipkin-Id
X-ShopId
X-Sorting-Hat-ShopId
Cache-Hits
X-Storefront-Renderer-Rendered
X-Xfnlog-Site
Xserver
X-Cache-Var
X-Is-Bot
X-Rendered-As
X-Cache-Var-Map
X-Air-Hostname
X-Dynatrace
X-Unique-Id
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
X-SRV
AMP-Access-Control-Allow-Source-Origin
X-Detected-As
X-Amzn-Remapped-Content-Length
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Cache-Host
X-EdgeConnect-Cache-Status
X-Device-Type
X-Webkit-Csp
X-Dc
X-Info
Apigw-Requestid
X-Nginx-Cache
X-Cdn
X-Microcachable
X-APP-VERSION
SD-X-WS
X-Cache-Enabled
X-B3-Traceid
X-GEO
X-Time-Microsecs
X-Content-Age
X-Debug-IsConnected
X-Correlation-ID
X-Varnish-Server
X-Debug-IsPreview
Tracecode
X-Backend-TTL
Amp-Access-Control-Allow-Source-Origin
X-Cache-Backend
X-Platform
X-ServerID
X-Varnish-Grace
X-Azure-Ref
X-Backend-Host
X-DynaTrace-JS-Agent
Uber-Trace-Id
DSUID
X-GG-Cache-Date
X-Erf-Stays-Bingo-Pdp-Web
X-Oss-Request-Id
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Sucuri-ID
X-Tb
X-Oss-Server-Time
Akamai-GRN
X-Oss-Storage-Class
Arc-Version
X-Proxy-Cache-Status
X-BCube-Filmed-By
PB-RID
PB-PID
Backend
X-NewRelic-App-Data
X-ID
X-ATG-Version
X-Akamai-Transformed
X-Magnolia-Registration
X-Trace-Id
X-Origin-Response-Time
Expiry
X-ScT
Xc-Version
Fastcgi-X-Cache-Version
X-S-Cookie
X-SRCache-Key
X-Session-Fingerprint
X-Trv-Group
X-VG-WebServer
DCR-Decision-By
X-RCS-CacheZone
X-VG-WebCache
ServedBy
X-Vtex-Processado-Em
X-Vdms-Version
X-Thinkindot-L3
X-Vdms-Path
DCR-Processing-Time-Ms
X-Vtex-Remote-Cache
X-Varnish-Cache-Hits
X-PBS-Appsvrname
X-Connection-Hash
X-CF-Lambda-Version
T-Server
Thinkindot-CacheControl
SR-User-Adfree
Rendered-Blocks
X-Device-Os
X-Destination
Pramga
X-D
X-CF-Lambda-Fn
X-Cache-NE
X-A-Dgt
X-A-Dcw
Thinkindot-Control
X-A-Dam
X-A-Wwc
X-Aed
Thinkindot-CacheControl-Type
X-B-Cookie
X-ARC
X-Application
Path
X-External-Request-Id
X-A-Ccd
X-PAYTM-SRV-ID
X-Origin-TTL
Machine
Lfy
X-Processor
X-Rojux
X-Rewrite-Enabled
Instruction
X-Request-UUID
X-Origin-CC
X-Matched-Rule
Mobile-Detection-Method
X-From
Odigeo-Trace-Id
X-Fetched-On
X-Generated-On
Meta-Geo-Continent
X-Location
X-Level-Front-Cache
X-Generation-Time
MD5-Digest
X-S
X-A
X-CSRF-Token
X-Cache-Remote
X-Cache-NGX
X-Cache-PHP
X-Varnish-Hostname
X-Adobe-Source
X-CGP
X-Reqid
DB-Nickname
PFcat
HA-Ipaddr
X-Request-URI
X-JWT-State
X-Request-Start
Wxu-Next-Commit
Cache-Host
C-Via
X-HS-Content-Campaign-Id
Pagetype
Host-ID
CacheControlHeader
X-FC-Vary-Parameters
Ha-Gx-Prefs
X-Node-Id
X-Csrf-Jwt
Wxu-Next-Region
X-Has-Esi
X-Mvc-Supplant-Cachable
X-HN
X-Micro-Cache
Fastly-Backend-Name
Wxu-Next-Hostname
Gh-Request-Id
X-Geo-Header
Cf-Device-Type
AKAMAI
X-GeoIP
X-Owner
X-OVcl
X-OVcl-Cache
X-Generated-In
L
X-VarnishDD-TTL
X-Backend-State
X-VServer
Locid
Ssr
CACHE
X-Azure-Ref-OriginShield
X-Cache-Date
X-Cache-Bucket
X-GeoIP-City
X-Bip
Release
BehaviorPad-Version
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Is-Gdpr
X-Developers
X-Sn-Servicetimems
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Skip-Cache
Magicmarker
X-Irp-Debug
X-Cdn-Origin
X-Swa-Ws
X-Thanos
X-Eu-Site
L5d-Success-Class
X-User
X-Cache-Info
X-Tumblr-Pixel-3
X-Ms-Version
X-Debug-Cache
X-Ms-Request-Id
X-Fastly-Backend
Server-Host
Server-Ext
Server-Hostname
Sever-Int
X-Envoy-Decorator-Operation
Rt-Fastcgi-Cache
X-Fastly-Cache
NGX
V-Age
On-Server
X-Generated-By
X-Developer
X-NC
CloudFront-Viewer-Country
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
CDCHOST
X-Request-Host
X-IP
Apple-News-Services-Host
Apple-News-Services-Handled
X-Var-Ttl
User-Cache-Control
X-Cache-Tags
X-Scheme
X-NWS-UUID-VERIFY
X-Clientip
X-Policy
UCS
X-Core-Value
X-CUA
X-Nginx-Cache-Key
X-Origin-Expires
Content-Disposition
X-Cms-Context
Cf-Bgj
X-Varnish-Hits
X-Method
X-Varnish-Beresp-Grace
X-Cache-Expires
X-Cache-Debug
X-Clara-WADP
X-DefElseHash
X-DefHash
X-Dispatcher-Server
X-Cache-Id
X-Loc
X-TX-ID
X-Variation
X-SIPLIST1
X-Servername
X-Rebelmouse-Surrogate-Control
X-B3-Spanid
X-Varnish-CookieHashed-On
X-Varnish-CookieINHashed-On
X-WADP-Cache
X-TrackingId
X-Host-Name
X-VG-TLSProxy
X-Varnish-Remaining-TTL
X-Rebelmouse-Cache-Control
X-Ratelimit-Reset
X-Gzip
X-Hnp-Log
X-GoCache-CacheStatus
X-Gen-Mode
X-Esi-Check
X-Fmm-Version
X-Li-Fabric
X-Li-Pop
X-Origin
X-Platform-Server
X-Old-Content-Length
X-Branch-Name
X-LI-UUID
X-DPWN-IS-SECURE
X-NU-AKA-ACS-Version
Platform
Adler-Geo
X-Block-Status
True-Client-Country-4JS
IsBot
Web-Mar-Node
Vix-Hermes-Req-Id
NM-Fastcgi-Cache
Origin
Fastly-SIE
Location
Fastly-SWR
Is-Eu
CDN-EdgeStorageId
CDN-CachedAt
X-Hash
CDN-PullZone
CDN-RequestId
X-Goog-Meta-Goog-Reserved-File-Mtime
X-HOST
Fastly-Drupal-HTML
X-Gamma-Serve
X-NCache
CDN-Uid
CDN-RequestCountryCode
CDN-Cache
X-Slack-Backend
X-Varnish-Url
X-Varnish-Beresp-Status
HostName
X-Varnish-Beresp-Ttl
S-Rt
X-Varnish-Cacheable
X-Core-Mission
Url
X-NAPM-TraceId
X-Response-By
X-PF-Uncompressing
X-Refresh
X-CS
X-Aicache-OS
X-Mvc-Supplant-OutputCached
X-EC-Lua
X-Cdn-Forward
Xkeyi7
X-Proxy-Cachei7
Content-Secure-Policy
Cross-Origin-Window-Policy
X-Sucuri-Cache
Pics-Label
X-BBXSRF
X-App-Version
N-Cache
X-CACHE-GROUP
X-URL
X-Cache-2
X-FireWall-Protection
X-LB-ID
Sid
Ohc-File-Size
X-CDN-Forward
X-B3-SpanId
Cteonnt-Length
X-Varnish-Authentication
X-Via-Popn
D-Cc-Upstream
X-Via-Popv
X-Via-Poph
X-Cc-Req-Id
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Cc-Via
X-Tb-Optimization-Total-Bytes-Saved
X-Svr
Esi-Enabled
X-Cs
X-Wa
X-Server-IP
Source
X-Servedbyhost
X-TA-CDN-Provider
X-Epic-Correlation-Id
X-DC
X-Error
MIME-Version
X-Srv
X-Unique-ID
X-Origin-Time
Geoip-Latitude
X-FPC
GeoIp-Country-Code
X-Cache-Config
X-API-Version
X-TIME
X-Nyt-Route
X-Gdpr
X-Webkit-CSP-Report-Only
X-TraceId
X-VC
X-SN
Hostname
Req-Svc-Chain
Who
XServer
HitType
X-Nc
X-RateLimit-Limit
Ohc-Cache-HIT
X-SB
Country-Code
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
Server-Ttl
X-NodeID
X-Webstats-RespID
X-LI-Proto
X-Fastly-Request-Id
X-NGINX-Cache
Server-ID
X-SD-PageType
X-HS-Status
X-LiteSpeed-Cache-Control
X-Check-Cacheable
X-VCL-Version
Geo-Info
X-Ua
Cmsid
Svr
Kp-EeAlive
X-Esi
Cmstype
NtCoent-Length
SID
X-Render-Time
X-Vgn-Hpd-Reason
X-Served-From
X-BBC-Edge-Cache-Status
X-Viewer-Country
VivaBuild
Viewtype
EpKe-Alive
Cache-Key
X-Worker
X-Auto-Login
X-RAMCache
X-Vcl-Version
Request-ID
X-Ftr-Cache-Host
A
X-UA
X-Dynatrace-Js-Agent
X-CSRF-TOKEN
X-DB
X-CCDN-Origin-Time
ProcessTime
X-CCDN-CacheTTL
Server-Id
X-RPM
X-Li-Proto
Cache-Provider
X-DSS
X-DW
M-TraceId
X-DI
X-Hcs-Proxy-Type
X-RPS
X-TIM-N
X-CACHE-KEY
X-RSL
Resin-Trace
Upgrade-Insecure-Requests
X-Air-Source
X-Cluster-Node
Cross-Origin-Opener-Policy
X-CF-Powered-By
GeoIP-Latitude
GeoIP-Country-Code
X-App
TDXMobile
Arc-Country
CDN
X-Newrelic-Synthetics
Srv
X-Internal-Host
X-Action
Processtime
X-FTR-Cache-Host
X-Oss-Cdn-Auth
X-ServedByHost
X-WA
Tcn
Mime-Version
X-Vc
Datacenter
X-Fpc
Filterid
X-CLOUD-TRACE-CONTEXT
OT-Force-Account-Verify
CF-Cached-On
WZWS-RAY
X-Service
X-FORWARDED-FOR
X-Geo
X-BBC-Origin-Response-Status
X-HostName
X-HITS
X-ABtesting
X-Flog
X-Hello
X-Cache-Tag
Cdn
X-MSEdge-Flight
X-Fastly-Backend-Reqs
X-Pinterest-Sli-Endpoint-Name
X-Lb-Id
X-Pinterest-Sli-Latency-Threshold
X-Pinterest-Sli-Response-Type
X-BACKEND-TTL
NGB
X-Dw-Trace-Id
X-MSEdge-Features
X-Via-PopN
X-Via-PopV
X-ND-Cache
X-Via-PopH
X-Parent-Response-Time
Proxy-Connection
X-Client-Ip
X-CACHE-AGE
DataCenter
X-Forwarded-Site
PICS-Label
X-IN-APIGATEWAYSSL
X-Via-NSCOPI
Dnion-Transfer-Encoding
X-IN-APIGATEWAY
W
FSS-Cache
X-NGENIX-Cache
X-Cdn-Request-ID
X-Edge-Location
X-SaId
X-JoinUs
X-PHP-Backend
X-Oracle-DMS-ECID
X-Presslabs-Stats
Media-Length
URI
X-Pf-Uncompressing
X-Extlb
Vha6-Origin
X-Acc-Rdl
CountryCode
X-Acc-Debug-Context
X-Region-Sid
X-RateLimit-Remaining-Second
X-Req
X-UnsetCookies
X-VC-Cache
Epwk-X-Cache
X-Bc-Bl
We-Hiring
LB
Surrogated-Key
Mail-Subject
Memcached
X-Accel-Expires-Debug
X-LiteSpeed-Tag
X-PJAX-URL
X-Proxy-Upstream
X-Pad
X-Depends-On
X-Date
X-RateLimit-Limit-Second
X-MiniProfiler-Ids
X-Akamai-Pragma-Client-IP
Inserted-Into-Cache-At
X-ZONE
X-Request-URL
X-Varnish-Beresp-TTL
X-Provided-By
X-Akamai-Request-ID
Cf-Ipcountry
X-Swift-Error
X-Csrf-Token
X-Via-Edge
X-Traceid
Content-Script-Type
Edge-Copy-Time
X-Rocket-Build-Number
X-Sigma
X-Sigma-Backend
X-Tid
Env
X-Vcache
X-Akamai-ERPolicy
X-B3-Parentspanid
X-Akamai-ERRuleID
Content-Style-Type
X-Via-SSL
X-Acquia-Site
X-Ms-Meta-Originalurl
X-ElasticPress-Search
X-ElasticPress-Query
X-Ms-Meta-Staticbatchstarttime
X-Acquia-Application-UUID
X-Acquia-Purge-Tags
X-Acquia-Application-Trace
X-Request-Url
X-Snapshot-Date
X-Varnish-URL
Xet-Cookie
X-Zone
Environment
NnCoection
X-APP
X-Redis-Duration-Ms
X-Redis-Count
Phost
Ohc-Response-Time
Time
X-C
Memory
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Litespeed-Cache-Control
Akamai-Age-Ms
X-ServerName
X-Storefront-Renderer-Verified