Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-RAY
CF-Cache-Status
Accept-Ranges
Link
X-XSS-Protection
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-UA-Compatible
X-Served-By
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
X-Request-Id
X-Xss-Protection
Access-Control-Allow-Credentials
X-AspNet-Version
X-Runtime
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Request-ID
X-Cacheable
Timing-Allow-Origin
X-Ua-Compatible
X-Content-Security-Policy
X-Iinfo
Content-Encoding
X-CDN
Feature-Policy
X-AspNetMvc-Version
Status
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Upgrade
X-Via
Access-Control-Max-Age
Keep-Alive
X-Ws-Request-Id
X-Age
X-AH-Environment
X-Robots-Tag
X-Turbo-Charged-By
Request-Context
EagleId
X-Proxy-Cache
X-Cache-Group
Server-Timing
X-Backend
X-Hacker
X-Server
Host-Header
Report-To
X-Amz-Request-Id
X-Server-Powered-By
X-Amz-Id-2
Grace
X-Nginx-Cache-Status
X-UA-Device
X-Rq
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
X-LiteSpeed-Cache
X-Page-Speed
Cf-Railgun
X-Pingback
X-OneAgent-JS-Injection
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
NEL
X-Cache-Spec
X-Amz-Version-Id
X-Device
X-CST
Allow
X-Vhost
X-Host
Xkey
X-Backend-Server
X-Server-Id
X-WebKit-CSP
EagleEye-TraceId
Surrogate-Control
X-Dispatcher
Request-Id
X-Node
Content-Location
X-Response-Time
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Akam-SW-Version
X-Ruxit-JS-Agent
P3p
X-ASPNET-VERSION
X-Application-Context
X-Ac
Accept-CH
X-Cache-Lookup
X-Country
X-Template
Accept-Ch-Lifetime
X-Language
Accept-Ch
X-Mod-Pagespeed
X-Readtime
X-Cloud-Trace-Context
Accept-CH-Lifetime
MS-Author-Via
X-B3-TraceId
Rating
X-Origin-Cache
X-HW
X-Cnection
X-MS-InvokeApp
X-Url
X-Vname
X-TtlSet
X-PC
X-Clacks-Overhead
Edge-Control
X-GitHub-Request-Id
X-ESI
X-Trace
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
Display
X-Sol
X-Middleton-Response
X-Middleton-Display
Response
Pagespeed
X-Content-Type
X-Webkit-CSP
X-D2id
Arr-Disable-Session-Affinity
X-GoogleNews-Bot
X-Kinja
X-Cdn-Fetch
X-Kinja-Build
X-Use-Magma
X-Exp-Id
X-Exp-Variant
X-Kinja-Server
X-Kinja-Revision
Verso
X-Vcap-Request-Id
X-Varnish-TTL
X-Goog-Hash
X-Rack-Cache
X-Country-Code
X-Buckets
X-Navigation-Version
X-Server-Name
X-Powered-By-Plesk
Service-Worker-Allowed
X-VARITI-CCR
X-Amz-Rid
X-Abt-Application-Version
X-Fastly-Request-ID
X-FastCGI-Cache
X-TTL
X-Client-IP
X-Cache-TTL
Fastly-Restarts
X-Cached
Pinterest-Generated-By
X-Pinterest-Rid
Pinterest-Version
X-Release
X-MSEdge-Ref
X-Dw-Request-Base-Id
X-Element-Page-Cache
SPRequestGuid
X-SharePointHealthScore
X-Oneagent-Js-Injection
X-NF-Request-ID
SPIisLatency
SPRequestDuration
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
Public-Key-Pins
RTSS
Access-Control-Request-Method
AR-ATIME
AR-PoweredBy
Ar-Sid
AR-CACHE
AR-Request-ID
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Edge
X-LLID
X-Powered-CMS
X-Ezoic-Cdn
Cache-Tag
X-Litespeed-Cache
Content-MD5
X-Upstream
X-Origin-Upstream-Status
Fusion-Source
Fusion-Deployment-Id
Fusion-Template-Id
X-HP-Webp
X-Px
Fusion-Content-Source
X-Jurisdiction
Fusion-Content-Id
Fusion-Component-Id
S
X-Version
X-Mid
X-MCACHE
X-ECACHE
X-Recruiting
X-Mg-S
Charset
X-Content-Digest
X-PressLabs-Stats
X-Ttl
X-Kinsta-Cache
Fastcgi-Cache
X-T
X-Amz-Server-Side-Encryption
X-DynaTrace
Cache-Tags
X-Id
MicrosoftSharePointTeamServices
Filters
X-Logged-In
X-Content-Security-Policy-Report-Only
Front-End-Https
X-Accel-Expires
Edge-Cache-Tag
Server-Node
X-Forwarded-Proto
X-Debug
X-Grace
X-Correlation-Id
X-Forwarded-For
TP-L2-Cache
TCN
TP-Cache
Server-Name
X-Fastcgi-Cache
Nginx-Cache
X-Amzn-Trace-Id
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Request-Received
X-Request-Processing-Time
Surrogate-Key
X-XRDS-LOCATION
X-Hits
X-Shield-Request-Id
X-B3-Sampled
X-Varnish-Age
X-Microsite
X-Request-Handler-Origin-Region
X-Yandex-Sdch-Disable
X-Ser
X-Pinterest-Direct
X-Az
X-AppVersion
X-Activity-Id
X-Ruxit-Js-Agent
X-Amz-Replication-Status
X-F-Cache
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Combine-CSS
X-DIS-Request-ID
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Storage-Class
X-Origin-Server
X-Geo-Country
Accept-Charset
Alternate-Protocol
X-Git-Hash
X-XRDS-Location
X-Rid
X-Respond-Thread
X-Frontend
X-Time
Section-Io-Cache
Cache
Host
X-LB-Cache
X-Cache-Key
X-NWS-LOG-UUID
X-FTR-Request-ID
X-Upgrade-Enabled
X-DataDome
Access-Control-Allow-Method
X-Seen-By
X-Mobile-URL
X-Server-ID
X-VCache
MS-CV
Paypal-Debug-Id
X-Cache-Age
X-TT
X-IPLB-Instance
ServerID
Healthy
X-AOL-HN
X-Type
X-Content-Options
X-Hostname
X-Varnish-Backend
X-Whom
X-Is-Crawler
X-Source
X-Flags
X-Aspnet-Duration-Ms
X-Providence-Cookie
X-App-Environment
Payment
X-Request-Guid
X-Route-Name
Cleartype
X-Signature
X-Cache-Action
X-B-Cache
X-Page-Id
Powered-By-ChinaCache
X-Jobs
Fastcgi-Useragent
X-Debug-Info
X-WebKit-CSP-Report-Only
X-Daa-Tunnel
X-Load-Cache
X-N
X-FB-Debug
X-RateLimit-Remaining
X-Mobile
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Browser-Type
X-Via-JSL
Realpath
X-Contextid
Nel
Refresh
Node
X-Rule
Version
X-Wix-Request-Id
X-Drupal-Cache-Tags
X-Original-Request-Id
X-Accel-Buffering
X-Response-Served-From
Ms-Operation-Id
DC
X-Zen-Fury
X-RTag
X-Proxy
X-Cacheable-TTL
X-Framework
X-Akamai-Edgescape
X-RemovedCookies
X-ProcessESI
X-Cached-By
X-Cache-Time
X-HTML-Minification-Powered-By
X-B
Viewport
X-Instance
Referer-Policy
X-Real-IP
Access-Control-Request-Headers
X-Distributor
X-UUID
X-Cluster-Name
X-Drupal-Cache-Contexts
X-Page-View
X-Cache-Expired-At
X-Region
X-Cache-Rule
X-Cache-Operation
Eomportal-Instance
X-Cache-Control
X-Content-Powered-By
X-Tt-Trace-Tag
X-Tt-Trace-Host
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-FW-Server
X-FW-Serve
X-FW-Hash
X-FW-Dynamic
X-FW-Static
X-FW-Type
Countrycode
X-IPS-LoggedIn
Liferay-Portal
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-G
X-Cache-Hit
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Tumblr-Pixel-1
X-FireWall-Port
X-Environment-Context
X-Pass-Why
X-L-Path
DynaTrace
Server-Info
X-App-Server
Xserver
X-User-Agent
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
Ec-Rule-Version
Section-Io-Id
Section-Io-Origin-Status
X-Protected-By
SRV
X-Tumblr-Pixel-2
From-Origin
Webserver
X-Ratelimit-Limit
CF-IPCountry
X-Www-Served-By
X-Nginx-Cache
GEO-INFO
X-Debug-IsPreview
X-Debug-IsConnected
X-Node-Name
Protected
X-UPSTREAM-Address
X-Cache-Server
X-Hl-Ver
X-Endurance-Cache-Level
Meta-Geo
X-ES-SERVER
X-RN-RSRV
X-Device-Type
X-Mode
X-Handled-By
X-Adobe-Loc
X-Uri
X-Backend-Name
X-MP-GENERATED-AT
X-FB-TRIP-ID
X-Site-Version
X-Adobe-Content
X-Locale
Cache-Tv-Group
X-Labrador-Cache-Channel
X-Storage
X-Varnishpool
X-Web-Node
Cache-Status
X-Varnish-Ttl
X-UA-Device-Type
X-Be
X-Soup
X-NYM-Debug-Backend
Frame-Options
X-PHP-Host
Decoy-Debug-Status
Decoy-Debug-TTL
Country
Decoy-Debug-Key
Fastly-SSL
X-BYPASS-REASON
X-Human
Selected-Fe
Cache-Name
TWC-Locale-Group
Property-Id
TWC-Connection-Speed
TWC-Device-Class
X-WA-Info
X-Via-Fastly
X-Sql-Duration-Ms
X-Timing-Wait
TWC-GeoIP-Country
TWC-GeoIP-LatLong
Webcakes-Region
X-Origin-Hint
Webcakes-App-Version
Webcakes-App-Name
Retry-After
TWC-Privacy
X-Sql-Count
X-Ratelimit-Remaining
X-Proxy-Build
X-ProxyCache-Key
X-Proto
X-PCL
X-No-Session
X-Origin-Date
X-ProxyCache-Status
X-OCL
X-Request-Time
X-Redis-Cache
X-Pubstack
Azure-SiteName
X-Server-W
Azure-Version
X-VWS-Id
Azure-SlotName
X-Access
X-Section
X-Format
X-R9-Blue-Green-Version
Azure-InstanceId
Azure-RegionName
X-FW-Version
X-Say-Cacheable
X-S-Maxage
X-TNCMS
X-AIR-PT
X-SayCDN-TTL
X-Say-TTL
X-LJ-Flow-ID
X-Hyper-Cache
X-AWS-Id
X-Loop
X-LAGOON
X-Hosted-By
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
X-Alternate-Cache-Key
X-Shopify-Stage
X-Sorting-Hat-PodId
X-CCM
X-Storefront-Renderer-Rendered
X-ShopId
X-Cache-TTL-Remaining
X-Status
X-PERF
X-Forwarded-Host
X-Cache-Grace
X-ApacheServer
X-Webkit-Csp
X-ShardId
X-Xfnlog-Site
X-Varnish-Grace
X-Sorting-Hat-ShopId
X-Revision
Mn-Server-Ip
X-TT-LOGID
X-Cluster
AMP-Access-Control-Allow-Source-Origin
X-Zipkin-Id
X-Routing-Service
X-Proxied
Apigw-Requestid
X-Is-Bot
X-Varnish-Server
X-Rendered-As
X-Info
X-Qloud-Router
X-Dc
X-GG-Cache-Date
S-Cnection
X-Via-CDN
X-SRV
X-Cache-Enabled
X-Cdn
X-Microcachable
X-Country-Code-Real
X-Content-Age
X-FTR-Realm
X-FTR-Cache-Status
X-Amz-Meta-S3cmd-Attrs
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Backend
X-FTR-DC
Cache-Hits
X-TA-CDN-Provider
Uber-Trace-Id
X-Proxy-Cache-Status
X-Platform
X-Cache-Host
X-App-Version
X-Detected-As
X-Azure-Ref
X-FTR-Expires
X-NWS-UUID-VERIFY
X-Backend-Host
X-Aspnetmvc-Version
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Amzn-Remapped-Content-Length
X-CSRF-Token
X-EdgeConnect-Cache-Status
X-Air-Hostname
Akamai-GRN
Tracecode
Amp-Access-Control-Allow-Source-Origin
X-ATG-Version
SD-X-WS
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Time-Microsecs
X-Oss-Storage-Class
HostName
X-Trace-Id
X-Cache-Var
X-Cache-Var-Map
X-Debug-Cache
ServedBy
X-ServerID
X-Backend-TTL
X-RCS-CacheZone
X-B3-SpanId
X-CS
X-Cache-NGX
X-Varnish-Hostname
X-Correlation-ID
X-DynaTrace-JS-Agent
X-BCube-Filmed-By
X-Cache-PHP
X-Tb
Backend
X-Akamai-Transformed
DB-Nickname
X-Cdn-Forward
X-TX-ID
BehaviorPad-Version
X-Level-Front-Cache
X-CF-Lambda-Fn
Odigeo-Trace-Id
X-Generated-On
X-A-Wwc
X-NAPM-TraceId
X-Magnolia-Registration
X-Aed
Path
X-ARC
X-Processor
X-Ms-Version
X-CF-Lambda-Version
X-Owner
Release
X-Origin-TTL
X-Generation-Time
X-Location
X-Ms-Request-Id
Rendered-Blocks
X-Connection-Hash
X-GeoIP-City
X-PBS-Appsvrname
X-PAYTM-SRV-ID
X-Origin-CC
X-Application
X-A
X-Trv-Group
X-Sucuri-ID
SR-User-Adfree
X-External-Request-Id
X-Vtex-Remote-Cache
X-Thinkindot-L3
X-Unique-Id
X-VG-WebServer
Expiry
Fastcgi-X-Cache-Version
Meta-Geo-Continent
X-Vtex-Processado-Em
X-Vdms-Path
X-Vdms-Version
Xc-Version
X-VG-WebCache
MD5-Digest
Machine
T-Server
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Thinkindot-Control
X-B-Cookie
X-Fetched-On
X-Rojux
X-D
X-Destination
X-S
Instruction
X-Rewrite-Enabled
X-A-Ccd
X-Request-UUID
X-A-Dgt
X-A-Dcw
X-Device-Os
X-A-Dam
DSUID
X-From
X-Session-Fingerprint
Mobile-Detection-Method
X-SRCache-Key
DCR-Decision-By
X-ScT
X-S-Cookie
DCR-Processing-Time-Ms
X-Cache-NE
X-Adobe-Source
X-GEO
Pagetype
Host-ID
X-Core-Value
AKAMAI
X-FC-Vary-Parameters
X-GeoIP
Fastly-Backend-Name
X-Geo-Header
X-HS-Content-Campaign-Id
Cf-Device-Type
Content-Disposition
NGX
X-Fastly-Cache
Gh-Request-Id
C-Via
X-Has-Esi
On-Server
CacheControlHeader
Arc-Version
X-Reqid
X-Skip-Cache
X-SVT-ORM-RULES
X-Azure-Ref-OriginShield
X-Irp-Debug
X-B3-Traceid
X-NewRelic-App-Data
X-SVT-ORM-VERSION
X-Bip
X-EC-Lua
X-Cache-Bucket
X-Tumblr-Pixel-3
X-TrackingId
X-CACHE-KEY
X-Thanos
Server-Host
X-VServer
X-Mvc-Supplant-Cachable
X-Node-Id
X-Micro-Cache
X-Cms-Context
PB-PID
PB-RID
X-JWT-State
UCS
X-Is-Gdpr
X-OVcl-Cache
X-OVcl
X-Cache-Backend
X-Varnish-Cache-Hits
User-Cache-Control
X-Branch-Name
X-Block-Status
X-DefHash
X-Backend-State
X-Developer
X-CGP
X-Clara-WADP
X-Clientip
X-Cache-Tags
X-Csrf-Jwt
X-Cache-Id
X-Cache-Info
X-DefElseHash
X-Ratelimit-Reset
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-Varnish-Remaining-TTL
X-VarnishDD-TTL
X-WADP-Cache
X-Varnish-Beresp-Grace
X-Variation
X-Scheme
X-Request-Host
X-Swa-Ws
X-User
X-Var-Ttl
X-Wikidot-Backend
X-Wikidot-Static-Cache
Wxu-Next-Region
Wxu-Next-Hostname
X-Developers
X-Nginx-Cache-Key
X-Policy
Wxu-Next-Commit
Sever-Int
Locid
Magicmarker
Server-Ext
Server-Hostname
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Generated-By
X-Gen-Mode
X-Generated-In
X-GoCache-CacheStatus
X-Gzip
X-Fmm-Version
X-Fastly-Backend
X-DPWN-IS-SECURE
X-Envoy-Decorator-Operation
X-Esi-Check
X-Eu-Site
X-HN
X-Hnp-Log
X-Origin
X-Old-Content-Length
X-Origin-Expires
X-Origin-Response-Time
X-Platform-Server
X-NU-AKA-ACS-Version
X-Matched-Rule
X-IP
X-Li-Fabric
X-Li-Pop
X-LI-UUID
X-Dispatcher-Server
X-CUA
Is-Eu
HA-Ipaddr
Ha-Gx-Prefs
Fastly-SWR
L5d-Success-Class
Lfy
PFcat
NM-Fastcgi-Cache
Location
Fastly-SIE
CDN-Uid
CDN-Cache
CDCHOST
Adler-Geo
CDN-CachedAt
CDN-EdgeStorageId
CDN-RequestId
CDN-RequestCountryCode
CDN-PullZone
Platform
Cache-Host
Web-Mar-Node
V-Age
Ssr
X-ID
X-Nc
IsBot
X-Hash
L
X-LB-ID
Cf-Bgj
True-Client-Country-4JS
X-Method
X-Gamma-Serve
X-SIPLIST1
CloudFront-Viewer-Country
Vix-Hermes-Req-Id
X-Cache-Debug
X-Unique-ID
X-VG-TLSProxy
Rt-Fastcgi-Cache
X-Varnish-Hits
X-Slack-Backend
X-Varnish-Beresp-Status
X-Varnish-Beresp-Ttl
X-Request-URI
X-CLOUD-TRACE-CONTEXT
X-Sn-Servicetimems
X-Aicache-OS
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Esi-Enabled
X-Cdn-Origin
X-Goog-Meta-Goog-Reserved-File-Mtime
Apple-News-Services-Handled
Origin
Pramga
Fastly-Drupal-HTML
X-Cache-Expires
X-Loc
X-APP-VERSION
Geo-Info
Who
X-PF-Uncompressing
X-Via-Poph
X-Via-Popn
Sid
X-Mvc-Supplant-OutputCached
X-Via-Popv
X-NCache
Country-Code
X-Cache-Date
X-Core-Mission
Pics-Label
X-Servername
X-Varnish-Url
X-Request-Start
X-Epic-Correlation-Id
X-Refresh
X-RateLimit-Limit
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-FireWall-Protection
Url
X-Tb-Optimization-Total-Bytes-Saved
X-Erf-Stays-Bingo-Pdp-Web
Tcn
Req-Svc-Chain
X-TraceId
Filterid
X-NC
Cmsid
Cmstype
X-Srv
X-Error
X-Response-By
X-Varnish-Cacheable
X-Cache-Remote
Svr
Source
Kp-EeAlive
X-Proxy-Cachei7
X-Served-From
Xkeyi7
S-Rt
X-Webkit-CSP-Report-Only
Viewtype
Server-Ttl
Content-Secure-Policy
Cache-Key
HitType
VivaBuild
X-BBXSRF
Geoip-Latitude
GeoIp-Country-Code
A
N-Cache
MIME-Version
X-HS-Status
X-DC
X-Cache-2
NGB
M-TraceId
X-B3-Spanid
X-Vcl-Version
X-URL
TDXMobile
X-Sucuri-Cache
Cross-Origin-Opener-Policy
X-HostName
X-Air-Source
Ohc-File-Size
X-Host-Name
X-Servedbyhost
Arc-Country
X-LiteSpeed-Cache-Control
Server-ID
X-Wa
Cross-Origin-Window-Policy
X-Varnish-Authentication
Cteonnt-Length
X-Cache-ASPX
X-Cc-Via
X-Cc-Req-Id
X-Dynatrace
X-Contensis-Viewer-Groups
D-Cc-Upstream
X-Vgn-Hpd-Reason
X-Li-Proto
X-Svr
X-Esi
X-CDN-Forward
NtCoent-Length
SID
CACHE
X-LI-Proto
Resin-Trace
X-Server-IP
X-RAMCache
X-Vc
X-Geo
X-HOST
X-API-Version
X-Internal-Host
X-Origin-Time
X-PHP-Backend
X-SaId
X-Nyt-Route
DataCenter
X-Service
X-JoinUs
X-NGENIX-Cache
X-Gdpr
X-FPC
X-WA
X-ServedByHost
X-Cache-Config
Request-ID
X-UA
X-Edge-Location
X-Viewer-Country
X-SN
X-VC
X-CCDN-Origin-Time
Cache-Provider
X-TIM-N
X-RPS
X-Hcs-Proxy-Type
X-RSL
X-DB
X-CCDN-CacheTTL
X-DI
X-DSS
X-Cs
X-DW
X-RPM
X-Check-Cacheable
X-VCL-Version
X-Newrelic-Synthetics
Hostname
Ohc-Cache-HIT
X-Forwarded-Site
Server-Id
GeoIP-Country-Code
GeoIP-Latitude
FSS-Cache
X-Via-NSCOPI
X-Webstats-RespID
CF-Cached-On
X-NodeID
X-SB
X-Extlb
XServer
Mime-Version
ProcessTime
X-Action
X-SD-PageType
X-App
X-Bc-Bl
X-Date
X-Accel-Expires-Debug
X-PJAX-URL
We-Hiring
X-Fpc
X-Proxy-Upstream
X-Render-Time
X-Oss-Cdn-Auth
Srv
X-BBC-Edge-Cache-Status
LB
Memcached
Mail-Subject
X-Region-Sid
Surrogated-Key
X-CF-Powered-By
X-NGINX-Cache
X-Req
X-VC-Cache
X-ZONE
X-Dynatrace-Js-Agent
X-Provided-By
W
X-FORWARDED-FOR
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-FTR-Cache-Host
X-Depends-On
Upgrade-Insecure-Requests
EpKe-Alive
Env
X-APP
X-Oracle-Dms-Rid
X-Swift-Error
X-Cdn-Request-ID
X-Worker
X-BACKEND-TTL
X-Ftr-Cache-Host
X-Dw-Trace-Id
X-Men
X-TIME
CDN
X-Sigma-Backend
Cdn
X-Sigma
X-Rocket-Build-Number
X-UnsetCookies
X-MSEdge-Flight
X-MSEdge-Features
X-Air-Trace-Id
Processtime
X-Auto-Login
X-Ua
X-CSRF-TOKEN
X-Client-Ip
X-CACHE-AGE
X-ABtesting
X-Cluster-Node
X-Hello
X-Fastly-Request-Id
X-Fastly-Backend-Reqs
VNS-Age
Memory
Time
Dnion-Transfer-Encoding
X-Cache-Tag
CPC-Age
CPC-Cache
X-Flog
X-Parent-Response-Time
Proxy-Connection
VNS-Cache
X-Akamai-Pragma-Client-IP
Cf-Ipcountry
X-Presslabs-Stats
Media-Length
X-Acquia-Application-UUID
Datacenter
X-BBC-Origin-Response-Status
X-Acquia-Application-Trace
X-Acquia-Purge-Tags
X-Zone
X-Acquia-Site
X-Pad
X-IN-APIGATEWAY
Vha6-Origin
X-IN-APIGATEWAYSSL
PICS-Label
X-Oracle-DMS-ECID
X-Pf-Uncompressing
X-Snapshot-Date
X-HITS
X-Via-PopN
Epwk-X-Cache
X-Via-PopH
X-Via-PopV
X-LiteSpeed-Tag
X-ServerName
X-Vcache
X-Varnish-URL
X-Akamai-ERRuleID
Fastcgi-Cache-TTL
State
X-ElasticPress-Query
X-Akamai-ERPolicy
X-ElasticPress-Search
X-Ms-Meta-Originalurl
X-Lb-Id
X-Request-Url
My-App
X-Ms-Meta-Staticbatchstarttime
X-MiniProfiler-Ids
X-Csrf-Token
X-Request-URL
OT-Force-Account-Verify
X-Varnish-Beresp-TTL
Xet-Cookie
CountryCode
X-Litespeed-Cache-Control
X-Minions-Version
X-Apw-Hits
Content-Style-Type
X-Instrumentation
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Cache-Status-Check
X-Kraken-Routeconfig-Destination
X-Apw-Access-Token
X-Apw-Access-Object
X-Apw-Access-Action
Content-Script-Type
URI
X-Redis-Count
X-Redis-Duration-Ms
X-Traceid
Environment
X-Storefront-Renderer-Verified
X-ND-Cache
X-C
WZWS-RAY
NnCoection
X-Debug-Cache-Store
Inserted-Into-Cache-At
X-Tid
X-Debug-Cache-Fetch
Ohc-Response-Time
X-B3-Parentspanid
Phost
X-Amz-Meta-Cb-Modifiedtime