Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
Cf-Request-Id
CF-RAY
CF-Cache-Status
X-XSS-Protection
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
Alt-Svc
X-UA-Compatible
X-Served-By
X-Timer
X-Request-Id
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Runtime
X-AspNet-Version
X-Adblock-Key
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Permitted-Cross-Domain-Policies
X-Check
X-Xss-Protection
X-Cache-Status
X-Generator
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
X-Content-Security-Policy
X-FRAME-OPTIONS
X-Iinfo
X-Ua-Compatible
Content-Encoding
X-CDN
Feature-Policy
X-AspNetMvc-Version
Status
X-Request-ID
X-Envoy-Upstream-Service-Time
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Upgrade
Access-Control-Max-Age
X-Via
Keep-Alive
X-Ws-Request-Id
X-Age
X-AH-Environment
X-Robots-Tag
X-Turbo-Charged-By
Request-Context
EagleId
X-Proxy-Cache
X-Cache-Group
Server-Timing
X-Server
X-Backend
X-Hacker
X-Server-Powered-By
Host-Header
Report-To
X-Amz-Request-Id
X-Nginx-Cache-Status
Grace
X-Amz-Id-2
X-UA-Device
X-Dns-Prefetch-Control
X-Rq
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
X-Page-Speed
Cf-Railgun
X-Pingback
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Device
X-CST
X-OneAgent-JS-Injection
NEL
X-Amz-Version-Id
X-Cache-Spec
Allow
X-Host
X-Vhost
X-Backend-Server
X-WebKit-CSP
X-ASPNET-VERSION
X-Server-Id
Xkey
X-Dispatcher
EagleEye-TraceId
Surrogate-Control
X-Node
Request-Id
X-Response-Time
Content-Location
X-Akam-SW-Version
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Accept-CH
P3p
X-Cache-Lookup
X-Application-Context
Accept-Ch-Lifetime
X-Country
X-Ac
X-Ruxit-JS-Agent
X-Mod-Pagespeed
X-Cloud-Trace-Context
X-Template
X-Readtime
X-Language
X-B3-TraceId
Accept-Ch
MS-Author-Via
X-HW
Rating
X-Url
Accept-CH-Lifetime
X-Cnection
X-MS-InvokeApp
X-Origin-Cache
X-Vname
X-TtlSet
X-PC
Edge-Control
X-ESI
X-Clacks-Overhead
X-GitHub-Request-Id
X-Trace
X-Webkit-CSP
X-D2id
Response
Pagespeed
X-Middleton-Response
X-Sol
Display
X-Middleton-Display
X-Content-Type
Verso
Arr-Disable-Session-Affinity
X-Kinja
X-Exp-Id
X-Cdn-Fetch
X-Kinja-Revision
X-Kinja-Server
X-GoogleNews-Bot
X-Use-Magma
X-Kinja-Build
X-Exp-Variant
X-ORACLE-DMS-RID
X-Oneagent-Js-Injection
X-Vcap-Request-Id
X-ORACLE-DMS-ECID
X-Powered-By-Plesk
X-Country-Code
X-Goog-Hash
X-Rack-Cache
X-Varnish-TTL
X-Navigation-Version
X-VARITI-CCR
Service-Worker-Allowed
X-Server-Name
X-Amz-Rid
X-Abt-Application-Version
X-Fastly-Request-ID
X-Client-IP
Fastly-Restarts
X-TTL
X-Buckets
X-Cached
X-Release
X-MSEdge-Ref
X-Cache-TTL
X-Element-Page-Cache
X-NF-Request-ID
X-Dw-Request-Base-Id
X-FastCGI-Cache
SPRequestGuid
X-SharePointHealthScore
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
Public-Key-Pins
Access-Control-Request-Method
SPRequestDuration
SPIisLatency
Cache-Tag
RTSS
X-Pinterest-Rid
Pinterest-Generated-By
Pinterest-Version
X-Ruxit-Js-Agent
X-Edge
AR-CACHE
AR-PoweredBy
AR-ATIME
AR-Request-ID
Ar-Sid
X-Powered-CMS
X-LLID
X-Ezoic-Cdn
X-SRCache-Store-Status
X-Upstream
X-SRCache-Fetch-Status
X-Version
Content-MD5
X-Jurisdiction
X-HP-Webp
S
X-Recruiting
X-Ttl
X-Mid
X-MCACHE
X-ECACHE
Charset
X-Origin-Upstream-Status
X-DynaTrace
X-Kinsta-Cache
X-PressLabs-Stats
X-Mg-S
Fusion-Template-Id
X-T
Fusion-Deployment-Id
Fusion-Component-Id
Fusion-Source
Fusion-Content-Id
Fusion-Content-Source
X-Fastcgi-Cache
Cache-Tags
X-Px
X-Content-Digest
Fastcgi-Cache
X-Accel-Expires
X-Id
X-Forwarded-Proto
X-Logged-In
X-Content-Security-Policy-Report-Only
Filters
Server-Node
X-Litespeed-Cache
Edge-Cache-Tag
TCN
X-Amz-Server-Side-Encryption
TP-Cache
TP-L2-Cache
Server-Name
Front-End-Https
MicrosoftSharePointTeamServices
X-Grace
X-Forwarded-For
X-Request-Received
X-Request-Processing-Time
Nginx-Cache
X-Hits
X-Shield-Request-Id
X-B3-Sampled
X-Amzn-Trace-Id
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Request-Handler-Origin-Region
X-Microsite
X-Correlation-Id
X-Debug
X-Az
X-XRDS-Location
X-AppVersion
X-Activity-Id
X-Varnish-Age
Alternate-Protocol
X-F-Cache
X-Server-ID
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Content-Id
X-Amz-Replication-Status
X-Origin-Server
X-Yandex-Sdch-Disable
Surrogate-Key
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-GUploader-UploadID
X-Goog-Generation
X-Frontend
X-Rid
X-NWS-LOG-UUID
X-DIS-Request-ID
X-Cache-Age
X-Geo-Country
Host
Section-Io-Cache
X-Ser
Nel
Accept-Charset
X-Hostname
X-Git-Hash
X-XRDS-LOCATION
X-RateLimit-Remaining
X-Time
X-Daa-Tunnel
Access-Control-Allow-Method
X-Mobile-URL
X-Respond-Thread
X-VCache
X-Upgrade-Enabled
MS-CV
X-Type
Paypal-Debug-Id
ServerID
X-DataDome
X-LB-Cache
X-AOL-HN
Realpath
X-Source
X-Cache-Key
X-Varnish-Backend
Cleartype
X-TT
Payment
X-IPLB-Instance
X-Seen-By
Healthy
X-Signature
X-Cache-Action
X-Debug-Info
X-B-Cache
X-Content-Options
X-Whom
Cache
X-Contextid
X-Flags
X-Route-Name
X-Request-Guid
X-Load-Cache
X-Providence-Cookie
X-Is-Crawler
X-Aspnet-Duration-Ms
X-Page-Id
X-App-Environment
X-Jobs
X-N
X-FB-Debug
Fastcgi-Useragent
X-FTR-Request-ID
Node
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-WebKit-CSP-Report-Only
X-Browser-Type
X-Mobile
X-Webkit-Csp
X-Pinterest-Direct
X-Rule
X-Cache-Expired-At
Refresh
X-Accel-Buffering
X-Original-Request-Id
X-Response-Served-From
DC
X-RTag
Ms-Operation-Id
X-Content-Powered-By
Version
X-Cluster-Name
Viewport
Access-Control-Request-Headers
X-Cacheable-TTL
X-RemovedCookies
X-Drupal-Cache-Tags
X-B
X-ProcessESI
X-Distributor
X-Proxy
X-Zen-Fury
X-Region
X-Real-IP
X-Instance
X-Cache-Time
VIX-Pulpo-Upstream-Status
Eomportal-Instance
X-Framework
VIX-Pulpo-Node
X-HTML-Minification-Powered-By
X-IPS-LoggedIn
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
Powered-By-ChinaCache
X-FireWall-Port
X-Wix-Request-Id
Referer-Policy
X-UUID
X-Cache-Control
X-Tt-Trace-Tag
X-Tt-Trace-Host
Countrycode
X-Drupal-Cache-Contexts
X-Page-View
X-FW-Hash
X-FW-Static
X-FW-Dynamic
X-FW-Serve
X-FW-Server
X-FW-Type
X-Via-JSL
X-Cached-By
X-G
X-Cache-Operation
X-Cache-Rule
X-Tumblr-Pixel
Liferay-Portal
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Debug-IsConnected
X-Nginx-Cache
X-Debug-IsPreview
X-App-Server
X-Tumblr-User
Xserver
X-Akamai-Edgescape
X-Www-Served-By
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Environment-Context
X-L-Path
X-Pass-Why
X-Protected-By
SRV
Section-Origin-Responded
Section-Io-Id
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
X-Cache-Hit
Server-Info
DynaTrace
X-Device-Type
X-Varnish-Ttl
X-Varnish-Grace
X-User-Agent
X-Tumblr-Pixel-2
X-Adobe-Loc
X-Adobe-Content
X-TEC-API-ROOT
From-Origin
X-TEC-API-ORIGIN
X-TEC-API-VERSION
CF-IPCountry
X-Mode
Ec-Rule-Version
Webserver
Cache-Status
X-Varnish-Server
X-ES-SERVER
GEO-INFO
X-UPSTREAM-Address
X-Hl-Ver
X-Handled-By
Meta-Geo
X-Endurance-Cache-Level
Frame-Options
Cache-Tv-Group
X-Backend-Name
AMP-Access-Control-Allow-Source-Origin
Retry-After
X-Access
X-Cache-Server
X-Varnishpool
X-FB-TRIP-ID
X-ProxyCache-Status
X-Soup
X-Storage
X-Pubstack
X-Section
TWC-GeoIP-LatLong
Webcakes-Region
X-BYPASS-REASON
Apigw-Requestid
X-OCL
Property-Id
X-Format
X-Request-Time
X-Origin-Hint
TWC-Locale-Group
TWC-GeoIP-Country
TWC-Device-Class
TWC-Connection-Speed
X-PCL
Country
TWC-Privacy
Webcakes-App-Name
Webcakes-App-Version
X-ProxyCache-Key
X-ApacheServer
X-Via-Fastly
X-Timing-Wait
X-No-Session
X-Uri
X-RN-RSRV
X-R9-Blue-Green-Version
X-MP-GENERATED-AT
X-S-Maxage
Mn-Server-Ip
X-Be
X-AWS-Id
X-Server-W
X-Proxy-Build
X-PERF
Fastly-SSL
Selected-Fe
X-LJ-Flow-ID
X-NYM-Debug-Backend
X-VWS-Id
X-UA-Device-Type
Protected
Decoy-Debug-Key
Decoy-Debug-Status
Decoy-Debug-TTL
X-Routing-Service
X-Origin-Date
X-WA-Info
X-Zipkin-Id
X-Xfnlog-Site
X-Proto
X-Cache-TTL-Remaining
X-Human
X-Proxied
X-PHP-Host
X-Labrador-Cache-Channel
Cache-Name
X-GG-Cache-Date
Azure-RegionName
Azure-InstanceId
Azure-SlotName
X-LAGOON
Azure-Version
X-ShopId
Azure-SiteName
X-Sorting-Hat-PodId
X-Shopify-Stage
X-Alternate-Cache-Key
X-Info
X-Storefront-Renderer-Rendered
X-Sorting-Hat-ShopId
X-ShardId
X-Sql-Count
X-Sql-Duration-Ms
X-TNCMS
X-SayCDN-TTL
X-Web-Node
Uber-Trace-Id
X-Say-TTL
X-Say-Cacheable
X-Proxy-Cache-Status
X-Status
X-Loop
X-Hyper-Cache
X-Hosted-By
X-Ratelimit-Limit
X-Locale
X-TA-CDN-Provider
X-Microcachable
X-Redis-Cache
X-FW-Version
X-Site-Version
X-Dc
X-Cache-Enabled
X-Cluster
X-App-Version
X-Is-Bot
X-Forwarded-Host
X-Rendered-As
X-Content-Age
X-Qloud-Router
X-Correlation-ID
X-Backend-Host
X-AIR-PT
S-Cnection
X-Platform
X-TT-LOGID
X-Cache-Grace
X-NWS-UUID-VERIFY
X-Node-Name
X-CSRF-Token
X-Azure-Ref
X-CCM
X-Via-CDN
Cache-Hits
X-Revision
X-Trace-Id
ServedBy
Akamai-GRN
X-SRV
X-Cache-NGX
X-Cache-PHP
X-Aspnetmvc-Version
X-Varnish-Hostname
X-EdgeConnect-Cache-Status
X-Cache-Host
X-Debug-Cache
X-RCS-CacheZone
X-ATG-Version
X-Amz-Apigw-Id
X-Amzn-Remapped-Content-Length
X-Amzn-RequestId
X-Detected-As
X-CS
X-Nc
DB-Nickname
HostName
X-B3-SpanId
X-Akamai-Transformed
Amp-Access-Control-Allow-Source-Origin
X-TX-ID
X-FTR-Realm
X-FTR-DC
X-FTR-Backend
X-Ratelimit-Remaining
X-Unique-ID
X-Country-Code-Real
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Cache-Status
X-BCube-Filmed-By
X-RateLimit-Limit
X-Adobe-Source
X-CACHE-KEY
X-Time-Microsecs
Who
SD-X-WS
Country-Code
X-Varnish-Beresp-Grace
X-Ms-Request-Id
X-Ms-Version
X-Oss-Server-Time
X-External-Request-Id
X-Oss-Storage-Class
X-From
X-Generated-On
X-Oss-Request-Id
X-Level-Front-Cache
X-Origin-TTL
X-Owner
X-PAYTM-SRV-ID
MD5-Digest
X-Origin-CC
X-NAPM-TraceId
X-Oss-Hash-Crc64ecma
X-Varnish-Cache-Hits
Meta-Geo-Continent
X-Location
X-Oss-Object-Type
Fastcgi-X-Cache-Version
X-Application
X-A
X-ARC
X-B-Cookie
X-A-Ccd
X-Aed
X-A-Dcw
X-A-Dgt
X-A-Wwc
X-Cache-NE
BehaviorPad-Version
Expiry
X-A-Dam
X-Destination
X-D
X-Connection-Hash
X-PBS-Appsvrname
T-Server
Rendered-Blocks
Odigeo-Trace-Id
X-Generation-Time
X-Request-UUID
X-ServerID
X-Backend-TTL
X-SRCache-Key
X-S
X-Vdms-Path
X-S-Cookie
X-Trv-Group
X-Session-Fingerprint
X-Processor
X-Vdms-Version
X-ScT
X-VG-WebServer
X-VG-WebCache
X-Varnish-Beresp-Ttl
Release
X-Bip
X-CF-Lambda-Version
DCR-Processing-Time-Ms
X-Cms-Context
X-Core-Value
X-CF-Lambda-Fn
DCR-Decision-By
X-Tumblr-Pixel-3
Content-Disposition
Path
X-Policy
X-Vtex-Processado-Em
Ssr
UCS
Thinkindot-Control
Thinkindot-CacheControl-Type
CacheControlHeader
Cache-Host
V-Age
AKAMAI
Server-Host
X-Vtex-Remote-Cache
X-Varnish-Beresp-Status
Wxu-Next-Region
Wxu-Next-Commit
Wxu-Next-Hostname
Pagetype
X-TrackingId
X-Amz-Meta-S3cmd-Attrs
X-Rojux
Mobile-Detection-Method
Thinkindot-CacheControl
X-Generated-In
X-Geo-Header
X-Rewrite-Enabled
Host-ID
X-OVcl-Cache
X-Reqid
X-OVcl
Machine
Magicmarker
X-Magnolia-Registration
Gh-Request-Id
X-GeoIP-City
On-Server
X-Developers
X-Swa-Ws
X-Thanos
X-Thinkindot-L3
X-Fetched-On
X-Device-Os
X-Air-Hostname
X-EC-Lua
Filterid
Backend
Origin
NGX
X-Azure-Ref-OriginShield
Locid
NM-Fastcgi-Cache
PB-RID
Sever-Int
Server-Hostname
X-Is-Gdpr
X-FC-Vary-Parameters
X-Has-Esi
X-JWT-State
Server-Ext
PFcat
X-Varnish-Hits
X-Skip-Cache
Location
X-Eu-Site
X-SVT-ORM-RULES
X-Dispatcher-Server
X-Envoy-Decorator-Operation
X-HN
X-Scheme
X-Request-URI
X-Ratelimit-Reset
X-Origin
X-Nginx-Cache-Key
X-Method
X-SVT-ORM-VERSION
X-Developer
Xc-Version
X-VG-TLSProxy
Arc-Version
Cf-Device-Type
True-Client-Country-4JS
Vix-Hermes-Req-Id
X-VarnishDD-TTL
X-User
X-CGP
X-Csrf-Jwt
X-Cache-Debug
X-Cache-Bucket
X-Branch-Name
PB-PID
X-GeoIP
X-DynaTrace-JS-Agent
CDN-EdgeStorageId
Tracecode
CDN-PullZone
CDN-Uid
CDN-RequestId
CDN-CachedAt
CDN-Cache
Apple-News-Services-Host
Apple-News-Services-Handled
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
CDCHOST
C-Via
Cf-Bgj
CDN-RequestCountryCode
L5d-Success-Class
Ha-Gx-Prefs
Fastly-Backend-Name
DSUID
HA-Ipaddr
L
X-B3-Traceid
X-FTR-Expires
X-NewRelic-App-Data
X-Backend-State
X-Var-Ttl
Adler-Geo
IsBot
Platform
Is-Eu
Fastly-SWR
X-Fastly-Cache
Fastly-SIE
X-Aicache-OS
X-Hash
X-Cache-Tags
X-Mvc-Supplant-Cachable
X-LB-ID
X-Micro-Cache
X-Irp-Debug
X-IP
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Cache-Info
X-Sucuri-ID
X-HS-Content-Campaign-Id
X-Gamma-Serve
X-DefElseHash
X-NU-AKA-ACS-Version
X-Origin-Expires
X-Varnish-CookieINHashed-On
X-Node-Id
X-Varnish-CookieHashed-On
X-Platform-Server
X-Rebelmouse-Cache-Control
Esi-Enabled
Fastly-Drupal-HTML
X-Variation
X-SIPLIST1
X-Rebelmouse-Surrogate-Control
X-Li-Pop
X-LI-UUID
X-DPWN-IS-SECURE
X-GoCache-CacheStatus
X-Li-Fabric
X-Varnish-Remaining-TTL
X-Fastly-Backend
X-Epic-Correlation-Id
X-Cdn-Forward
X-Clientip
X-VServer
X-DefHash
User-Cache-Control
X-ID
X-Tb
X-Unique-Id
X-Gzip
X-Generated-By
X-Gen-Mode
X-Fmm-Version
X-GEO
X-Varnish-Url
X-WADP-Cache
X-Wikidot-Static-Cache
X-Esi-Check
X-Loc
X-Request-Host
X-Old-Content-Length
Rt-Fastcgi-Cache
X-Origin-Response-Time
X-Hnp-Log
X-Wikidot-Backend
X-Block-Status
Web-Mar-Node
X-Cache-Id
X-Clara-WADP
X-Cache-Var-Map
X-Cache-Var
Pics-Label
X-Via-Popv
X-Via-Poph
X-PF-Uncompressing
Instruction
Geo-Info
X-Slack-Backend
SR-User-Adfree
X-Via-Popn
X-Webkit-CSP-Report-Only
X-APP-VERSION
Cmstype
Req-Svc-Chain
X-Planisys-CDN-Rules
X-Mvc-Supplant-OutputCached
X-Planisys-CDN-Cache
X-Refresh
Cmsid
NGB
X-CUA
X-Servername
Url
X-Planisys-CDN-TTL
Kp-EeAlive
X-Matched-Rule
Lfy
X-Srv
X-Served-From
Svr
A
X-Cache-Expires
CloudFront-Viewer-Country
X-Cache-Backend
Sid
X-Vgn-Hpd-Reason
X-TraceId
Pramga
X-Sn-Servicetimems
X-NCache
MIME-Version
M-TraceId
X-Cdn-Origin
X-Core-Mission
VivaBuild
Viewtype
Cross-Origin-Opener-Policy
X-Cache-Date
Arc-Country
X-Kraken-Loop-Name
DataCenter
X-Server-Lifecycle-Phase
X-Instrumentation
X-Kraken-Routeconfig-Destination
X-Edge-Location-Klb
X-PHP-Backend
SID
X-NGENIX-Cache
X-Edge-Location
Server-ID
TDXMobile
X-Tb-Optimization-Total-Bytes-Saved
Cache-Key
X-Request-Start
X-JoinUs
X-SaId
X-Servedbyhost
X-Vc
X-CLOUD-TRACE-CONTEXT
X-CDN-Forward
Content-Secure-Policy
X-Wa
X-Error
X-DC
X-FireWall-Protection
X-Service
Source
X-Geo
X-NC
X-Air-Source
X-Internal-Host
Tcn
X-Extlb
X-Varnish-Cacheable
X-Bc-Bl
NtCoent-Length
X-Vcl-Version
Geoip-Latitude
X-Response-By
GeoIp-Country-Code
X-LI-Proto
X-B3-Spanid
X-HS-Status
FSS-Cache
X-Proxy-Cachei7
Xkeyi7
X-Esi
CACHE
X-VHOST
Resin-Trace
LB
X-Req
Memcached
N-Cache
Server-Ttl
HitType
X-Forwarded-Site
X-PJAX-URL
X-Proxy-Upstream
X-BBXSRF
X-HOST
X-LiteSpeed-Cache-Control
X-CCDN-CacheTTL
X-RAMCache
Request-ID
X-Cache-2
X-CCDN-Origin-Time
GeoIP-Latitude
GeoIP-Country-Code
X-Hcs-Proxy-Type
X-VC-Cache
X-Via-NSCOPI
X-Li-Proto
Surrogated-Key
Upgrade-Insecure-Requests
S-Rt
X-Rocket-Build-Number
X-Sigma-Backend
X-RSL
X-Sigma
X-RPM
X-DW
X-Contensis-Viewer-Groups
X-Newrelic-Synthetics
X-Cc-Via
X-Cc-Req-Id
X-RPS
We-Hiring
X-Svr
Mail-Subject
X-Viewer-Country
X-DB
X-Varnish-Authentication
D-Cc-Upstream
X-VCL-Version
X-TIM-N
X-Date
X-Cache-ASPX
X-Accel-Expires-Debug
X-DSS
X-DI
Hostname
X-Cache-Remote
X-UA
Memory
X-Cs
X-Air-Trace-Id
Time
X-RateLimit-Limit-Second
X-WA
X-APP
X-RateLimit-Remaining-Second
Env
Cteonnt-Length
X-App
X-Zone
X-MSEdge-Flight
X-MSEdge-Features
XServer
Ohc-File-Size
Cross-Origin-Window-Policy
X-Men
X-ZONE
X-ServedByHost
CF-Cached-On
X-Action
X-Sucuri-Cache
ProcessTime
X-Server-IP
X-Erf-Stays-Bingo-Pdp-Web
X-HostName
X-FPC
Server-Id
X-Oss-Cdn-Auth
X-Region-Sid
X-Origin-Time
X-API-Version
X-Nyt-Route
X-Fpc
X-Gdpr
X-Cache-Config
X-Swift-Error
X-Dynatrace-Js-Agent
X-Provided-By
X-Host-Name
X-FORWARDED-FOR
X-Depends-On
X-NodeID
Cf-Ipcountry
W
X-VC
Mime-Version
X-Check-Cacheable
CPC-Age
My-App
State
Fastcgi-Cache-TTL
VNS-Cache
CPC-Cache
VNS-Age
X-Mg-Request-UUID
X-SN
X-Dw-Trace-Id
X-CF-Powered-By
Cache-Provider
X-Cdn-Request-ID
Srv
Ohc-Cache-HIT
X-TIME
X-UnsetCookies
X-Webstats-RespID
X-Ftr-Cache-Host
CDN
X-CSRF-TOKEN
Proxy-Connection
X-Minions-Version
X-SB
X-SD-PageType
X-URL
X-BACKEND-TTL
X-ServerName
X-Akamai-Pragma-Client-IP
X-Xrds-Location
X-Client-Ip
X-Flog
X-ABtesting
X-BBC-Edge-Cache-Status
X-Parent-Response-Time
X-Hello
X-Fastly-Request-Id
X-Cache-Ttl
X-Snapshot-Date
X-Fastly-Backend-Reqs
Cdn
X-Air-Pt
X-Cache-Type
X-Oracle-DMS-ECID
Dnion-Transfer-Encoding
X-Render-Time
Media-Length
X-NGINX-Cache
Vha6-Origin
OT-Force-Account-Verify
X-Presslabs-Stats
X-Pf-Uncompressing
X-Pad
X-Cache-Tag
EpKe-Alive
X-Acquia-Purge-Tags
X-LiteSpeed-Tag
X-Acquia-Application-UUID
PICS-Label
X-Acquia-Application-Trace
X-ElasticPress-Search
X-Tenant
X-Via-PopV
X-Via-PopN
X-Via-PopH
X-Shop-Environment
X-Orig-Expires
Epwk-X-Cache
X-Acquia-Site
X-ND-Cache
X-Forwarded-Path
X-Yottaa-OS
Warning
X-BBC-Origin-Response-Status
X-Traceid
X-ElasticPress-Query
WZWS-RAY
X-MiniProfiler-Ids
X-Cluster-Node
X-Varnish-URL
X-Request-URL
X-Worker
X-Varnish-Beresp-TTL
Processtime
Xet-Cookie
X-Akamai-ERRuleID
X-Auto-Login
X-Akamai-ERPolicy
X-Vcache
X-Ms-Meta-Staticbatchstarttime
X-Ms-Meta-Originalurl
X-Lb-Id
CountryCode
X-Ua
X-Apw-Access-Token
X-Apw-Hits
Phost
X-Cache-Status-Check
X-Mg-Request-Id
X-Apw-Access-Object
Ohc-Response-Time
X-Redis-Count
X-Ftr-Request-Id
Environment
X-Tid
NnCoection
X-Storefront-Renderer-Verified
X-Redis-Duration-Ms
Inserted-Into-Cache-At
X-FTR-Cache-Host
X-Amz-Meta-Cb-Modifiedtime
X-Debug-Cache-Store
Content-Style-Type
X-B3-Parentspanid
Content-Script-Type
X-Litespeed-Cache-Control
X-Debug-Cache-Fetch
URI
X-Apw-Access-Action