Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
CF-RAY
Link
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Request-ID
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-Template
X-Language
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-Buckets
X-FRAME-OPTIONS
Status
X-Content-Security-Policy
Upgrade
Content-Encoding
X-CDN
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Xss-Protection
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
Xkey
X-Pass-Why
X-Cache-Group
P3p
X-Envoy-Upstream-Service-Time
X-AH-Environment
X-Backend
X-Via
CF-Ray
X-Age
X-Server
X-Ua-Compatible
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Server-Powered-By
X-Page-Speed
X-Ws-Request-Id
X-Pingback
EagleId
X-Proxy-Cache
X-Hacker
X-Nginx-Cache-Status
X-UA-Device
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
Cf-Railgun
Grace
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Amz-Version-Id
Report-To
X-LiteSpeed-Cache
X-Rq
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Server-Id
X-WebKit-CSP
X-OneAgent-JS-Injection
X-Host
X-Device
EagleEye-TraceId
X-Origin-Cache
X-Response-Time
X-Node
X-Dns-Prefetch-Control
X-Ac
Content-Location
Surrogate-Control
X-Vhost
X-Readtime
X-Cloud-Trace-Context
X-Backend-Server
Request-Id
X-Dispatcher
X-Origin-Upstream-Status
X-Cnection
X-HW
X-Application-Context
X-ORACLE-DMS-ECID
X-Cache-Lookup
Fusion-Component-Id
Fusion-Content-Id
Fusion-Template-Id
Fusion-Source
Fusion-Content-Source
X-ORACLE-DMS-RID
X-DataDome
NEL
X-Mod-Pagespeed
X-Ruxit-JS-Agent
Rating
X-Rack-Cache
Edge-Control
X-Country
X-Akam-SW-Version
X-Clacks-Overhead
Pinterest-Generated-By
Allow
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-TTL
X-Country-Code
X-DynaTrace
Accept-Ch
X-Instart-Request-ID
X-Varnish-TTL
X-Goog-Hash
X-FTR-Request-ID
X-TtlSet
X-Vname
X-PC
X-ESI
Verso
Accept-Ch-Lifetime
X-Powered-By-Plesk
Content-MD5
Service-Worker-Allowed
X-Url
X-B3-TraceId
X-Forwarded-Proto
X-Version
X-Cdn
X-MS-InvokeApp
X-Exp-Variant
X-Cdn-Fetch
X-GoogleNews-Bot
X-Kinja-Server
X-Use-Magma
X-Kinja-Revision
X-Kinja-Build
X-Kinja
X-GitHub-Request-Id
X-Exp-Id
Edge-Cache-Tag
RTSS
X-D2id
X-Px
X-Debug
AR-ATIME
AR-CACHE
AR-Request-ID
AR-PoweredBy
Ar-Sid
X-Server-Name
X-Abt-Application-Version
SPRequestGuid
X-NF-Request-ID
X-Amz-Server-Side-Encryption
Charset
X-Vcache
X-Cached
X-Accel-Expires
Display
X-Vcap-Request-Id
X-Middleton-Response
Response
X-Middleton-Display
X-MSEdge-Ref
X-Sol
Pagespeed
Arr-Disable-Session-Affinity
X-Amz-Rid
X-Navigation-Version
X-Powered-CMS
X-Pinterest-Rid
X-SharePointHealthScore
Pinterest-Version
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
TCN
X-Fastcgi-Cache
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Trace
X-VARITI-CCR
Realpath
Public-Key-Pins
X-Client-IP
Cache-Tag
X-Fastly-Request-ID
Access-Control-Request-Method
X-Ser
MS-Author-Via
S
Nginx-Cache
X-DynaTrace-JS-Agent
X-Shard
SPIisLatency
SPRequestDuration
X-Upstream
X-Id
X-B3-TraceId-Primal
X-Edge-O15-RID
MRF-Tech
Mrf-Cache-Status
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
X-Hp-Webp
X-Ezoic-Cdn
X-Content-Type
X-Forwarded-For
X-Amzn-Trace-Id
X-Grace
X-T
X-Amz-Meta-S3cmd-Attrs
DynaTrace
Front-End-Https
X-Hits
Fastcgi-Cache
X-Recruiting
Nel
X-Varnish-Age
X-Aspnet-Version
ServerID
X-Dw-Request-Base-Id
X-Element-Page-Cache
X-Node-Name
X-Mobile-URL
MicrosoftSharePointTeamServices
X-Cache-TTL
X-DIS-Request-ID
X-FTR-Cache-Status
X-FTR-Expires
X-Jurisdiction
X-Content-Digest
X-Country-Code-Real
X-Server-ID
NR-ENABLED
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Combine-CSS
X-HS-Hub-Id
X-Goog-Storage-Class
X-FTR-Backend
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-Realm
X-FTR-DC
Powered
X-Frontend
Server-Node
Alternate-Protocol
TP-Cache
TP-L2-Cache
X-Logged-In
Server-Name
X-Correlation-Id
X-XRDS-LOCATION
X-Request-Received
X-Request-Processing-Time
AMP-Access-Control-Allow-Source-Origin
Upgrade-Insecure-Requests
X-Request-Handler-Origin-Region
X-Microsite
X-CST
Backend-Timing
X-ATS-Timestamp
X-Cache-Hit
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Content-Options
X-Page-Id
X-Origin-Server
Refresh
X-Revision
X-Content-Security-Policy-Report-Only
X-Akamai-Edgescape
X-Rid
X-Webkit-Csp
X-User-Agent
X-F-Cache
X-Varnish-Grace
X-Type
Fastly-Restarts
X-Zen-Fury
X-XRDS-Location
X-Content-Powered-By
X-B3-Sampled
X-LB-Cache
X-B
X-AppVersion
X-Activity-Id
X-Geo-Country
X-FTR-Cache-Host
X-Az
X-Shield-Request-Id
PB-PID
PB-RID
X-URL
Arc-Version
X-Mobile-Rewrite
X-N
Cache-Status
X-Kinsta-Cache
X-Pad
X-TT
X-Time
X-Instance
X-Webapp-Samesite-None-Activated-N
X-Cache-Age
X-AOL-HN
X-Request-Guid
X-WebKit-CSP-Report-Only
Paypal-Debug-Id
X-Framework
X-Tumblr-User
X-Tumblr-Pixel
X-Jobs
X-Tumblr-Pixel-0
Actual-Object-TTL
X-App-Environment
X-B-Cache
X-Signature
X-Cache-Action
X-FB-Debug
X-PHP-Backend
Access-Control-Allow-Method
X-Load-Cache
X-Debug-Info
DC
X-Cached-By
X-Git-Hash
X-RateLimit-Remaining
X-Analytics
X-Varnish-Backend
X-Tt-Trace-Tag
Surrogate-Key
X-Erf-Bev-Bev
Fastcgi-Useragent
X-Erf-Bev-Bev-Is-Generated
X-Tt-Trace-Host
X-Amz-Replication-Status
Host-Header
X-Contextid
FilterID
X-IPLB-Instance
MS-CV
X-ATG-Version
X-SS-Set-Cookie
X-Cache-Key
X-WA-Info
X-Cluster
Tracecode
Host
X-Response-Served-From
X-Mobile
X-Accel-Buffering
NGB
X-Via-JSL
X-Host-Name
X-FastCGI-Cache
WPE-Backend
X-Srv
X-ORACLE-APMCS-REQUEST-ID
X-ORACLE-APMCS-TAG
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Cache-NE
Payment
Xserver
X-FW-Hash
Source
X-Cache-2
Eomportal-Instance
X-FW-Type
X-FW-Server
X-FW-Serve
X-FW-Static
X-Varnish-Server
X-Region
X-VCache
X-Cacheable-TTL
X-NWS-LOG-UUID
X-Tumblr-Pixel-1
X-Rendered-As
Filters
X-Is-Bot
X-Varnish-Hostname
X-Tumblr-Pixel-2
Frame-Options
X-IPS-LoggedIn
Cache-Tv-Group
X-GeoIP
X-Cache-Enabled
X-Adobe-Content
X-Cache-Rule
X-Cache-Operation
X-Adobe-Loc
X-Presslabs-Stats
X-Origin-Response-Time
X-RequestSource
X-NewRelic-App-Data
X-Hostname
X-TX-ID
X-EdgeConnect-Cache-Status
X-Seen-By
Retry-After
Cleartype
Server-Info
X-Cache-TTL-Remaining
X-ProcessESI
X-Ruxit-Js-Agent
X-RemovedCookies
Liferay-Portal
X-UA
Accept-CH
X-HTML-Minification-Powered-By
X-Dc
Cache
Ms-Operation-Id
X-RTag
X-B3-Traceid
Datacenter
X-Source
X-Environment-Context
X-FireWall-Port
X-App-Server
X-L-Path
X-Cache-Control
Healthy
X-Endurance-Cache-Level
X-Upgrade-Enabled
X-Ttl
X-Cache-Server
From-Origin
X-Handled-By
X-Backend-Name
X-CACHE-KEY
Version
Accept-CH-Lifetime
X-Status
X-APP-VERSION
X-Path-Route
X-ES-SERVER
X-PressLabs-Stats
X-Wix-Request-Id
X-Rule
Meta-Geo
X-Cache-Var-Map
X-RN-RSRV
X-Cache-Var
X-Section
Selected-Fe
X-RateLimit-Limit
X-Proxy-Build
X-Format
X-Timing-Wait
X-Access
OT-Force-Account-Verify
X-UUID
Mn-Server-Ip
X-Request-Time
X-PCL
X-EIG-Tracking-Id
Azure-SiteName
Azure-InstanceId
X-Sorting-Hat-PodId
Azure-Version
X-Akamai-Request-ID
X-Sorting-Hat-ShopId
X-Tb
Akamai-GRN
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Content-Age
Azure-RegionName
X-Alternate-Cache-Key
X-Origin
X-Shopify-Generated-Cart-Token
X-ShopId
X-ShardId
Azure-SlotName
X-Shopify-Stage
X-Proto
X-OCL
DB-Nickname
Cache-Tags
X-Qloud-Router
X-Generated-By
X-Yottaa-Optimizations
X-ProxyCache-Status
X-Yottaa-Metrics
X-Hl-Ver
X-LJ-Flow-ID
X-JoinUs
X-Proxy
X-Hyper-Cache
X-ProxyCache-Key
X-Human
X-MP-GENERATED-AT
X-Redis-Cache
X-SaId
Node
Ec-Rule-Version
X-Debug-Cache
X-AWS-Id
X-Web-Node
X-ServerID
X-FW-Dynamic
X-Hosted-By
X-Proxy-Cache-Status
S-Rt
Origin-Edge-Control
X-NYM-Debug-Backend
GEO-INFO
X-VWS-Id
X-Soup
X-Vgn-Hpd-Reason
NGX
X-Cluster-Node
X-BYPASS-REASON
Origin-Cache-Control
Now
X-FC-Vary-Parameters
Webcakes-Region
X-Akamai-Request-ID2
X-Cache-Host
Webcakes-App-Version
TWC-GeoIP-Country
Decoy-Debug-TTL
X-Detected-As
Decoy-Debug-Status
Cross-Origin-Window-Policy
Decoy-Debug-Key
Property-Id
TWC-Connection-Speed
TWC-Privacy
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-Device-Class
Webcakes-App-Name
X-Time-Microsecs
X-BCube-Filmed-By
X-Site-Version
Accept-Charset
X-SayCDN-TTL
X-Say-TTL
X-Cache-Config
X-Say-Cacheable
X-Varnish-Hits
X-Pubstack
X-Viewer-Country
X-IP
X-Locale
X-Origin-Hint
X-Www-Served-By
X-Generated
X-Loop
Srv
X-Amzn-Remapped-Content-Length
X-Xfnlog-Site
X-TNCMS
X-CCM
X-FB-TRIP-ID
X-Storage
X-RCS-CacheZone
X-Akamai-Transformed
X-R9-Blue-Green-Version
X-NCache
L5d-Success-Class
X-CS
Cache-Name
X-Unique-Id
X-Drupal-Cache-Tags
Uber-Trace-Id
Viewport
Webserver
Time
X-Trafficlayer-App-Name
X-Trafficlayer-App-Scope
X-Esi
X-UA-Device-Type
Cache-Key
Mime-Version
X-UnsetCookies
X-Cache-Remote
X-Mode
X-From
X-Backend-TTL
X-Forwarded-Host
Accept-Language
Rt-Fastcgi-Cache
Country
X-CDN-Forward
X-Origin-CC
X-Origin-TTL
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Daa-Tunnel
X-Drupal-Cache-Contexts
X-Whom
X-Info
X-Cluster-Name
Odigeo-Trace-Id
X-Newrelic-Synthetics
X-Magnolia-Registration
X-TT-TIMESTAMP
X-NGENIX-Cache
X-Microcachable
X-Varnish-Cache-Hits
X-Edge-Location
X-B3-Spanid
Content-Disposition
X-PERF
X-ApacheServer
ServedBy
X-EC-Lua
X-CLOUD-TRACE-CONTEXT
X-Geo
X-Device-Type
X-Zipkin-Id
Ohc-File-Size
X-Routing-Service
X-Proxied
X-Via-Fastly
X-UPSTREAM-Address
Ohc-Cache-HIT
X-No-Session
X-Uri
Proxy-Connection
Cf-Ipcountry
Mobile-Detection-Method
Meta-Geo-Continent
AsisCache
X-CF-Lambda-Version
X-Rewrite-Enabled
X-S
Fastcgi-X-Cache-Version
X-ScT
GEO-REGION-INFO
X-Rojux
X-Rocket-Build-Number
Rendered-Blocks
X-Region-Sid
X-Request-UUID
MD5-Digest
X-CF-Lambda-Fn
Apple-News-Services-Parsed-Url
X-Session-Fingerprint
X-External-Request-Id
X-D
X-Destination
Content-Style-Type
X-Date
X-G
Content-Script-Type
Apple-News-Services-Handled
X-Geo-Header
X-GeoIP-Country-Code
Machine
X-A
Apple-News-Services-Request-Url
X-DPWN-IS-SECURE
BehaviorPad-Version
Apple-News-Services-Host
X-Connection-Hash
X-S-Cookie
Xc-Version
T-Server
X-ARC
X-Application
X-B-Cookie
X-Vtex-Remote-Cache
X-Vdms-Version
X-VG-TLSProxy
X-VG-WebCache
X-VG-WebServer
X-Aed
Viewtype
Section-Io-Cache
X-A-Dcw
X-A-Dam
X-A-Ccd
X-A-Dgt
X-A-Wwc
VivaBuild
X-Accel-Expires-Debug
W
X-Twitter-Response-Tags
X-Vtex-Processado-Em
X-Transaction
X-SRCache-Key
X-Trv-Group
X-Sigma-Backend
X-Sigma
X-C
HitType
X-Labrador-Cache-Channel
User-Cache-Control
X-Nc
X-PHP-Host
Server-Cache-Control
X-Bip
X-Thanos
X-Agile
X-Agile-Id
X-Agile-Age
X-App-Name
X-Eu-Site
IsBot
CDCHOST
Ha-Gx-Prefs
Environment
Gh-Request-Id
Fastly-Soc-X-Request-Id
X-Cache-ASPX
X-Developers
X-Backend-State
X-Distil-CS
HA-Ipaddr
X-SIPLIST1
X-Real-IP
X-Auto-Login
X-Logging-Id
X-CGP
X-TrackingId
X-Varnish-Authentication
Powered-By
X-Hit
X-VC-Cache
X-Contensis-Viewer-Groups
X-WebServer
X-CUA
X-Tumblr-Pixel-3
X-Cache-Debug
Server-Surrogate-Control
X-Wikidot-Static-Cache
Locid
X-Wikidot-Backend
X-Cache-Backend
X-Cache-Time
Geo-Info
X-GoCache-CacheStatus
X-Cms-Context
X-Clara-WADP
X-Core-Mission
X-Cache-Info
X-Azure-Ref
X-Cache-Bucket
X-BBXSRF
X-Cache-URL
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
X-Block-Status
X-Cdn-Srv
X-Hnp-Log
Access-Control-Request-Headers
X-Webstats-RespID
Fastly-SSL
IBM-Web2-Location
X-FW-Version
Memcached
X-WADP-Cache
X-TT-LOGID
X-SVT-ORM-RULES
X-Server-W
X-SVT-ORM-VERSION
X-Swa-Ws
X-Trace-Id
X-Li-Fabric
X-Li-Pop
Fastly-SWR
Fastly-SIE
X-Clientip
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
Countrycode
X-We-Are-Hiring
X-LI-UUID
X-LI-Proto
X-TH-Server
X-User
X-VServer
X-Render-Time
X-Proxy-Upstream
X-Generation-Time
X-Gen-Mode
X-GeoIP-City
X-Hash
X-IN-APIGATEWAY
X-Gamma-Serve
X-Fetched-On
X-Debug-Log
X-Debug-Cookies
X-Dispatcher-Server
X-Distributor
X-Epic-Correlation-Id
X-IN-APIGATEWAYSSL
X-Instart-Isnd
X-Origin-Expires
X-Origin-Date
X-OVcl
X-OVcl-Cache
X-Owner
X-NX-Host
X-Nginx-Cache-Key
X-Key
X-Irp-Debug
X-Micro-Cache
X-Ms-Request-Id
X-Ms-Version
X-Debug-Cache-Store
X-Fastly-Cache
Mail-Subject
Kp-EeAlive
Heartbleed
Fastly-Backend-Name
Request-Country
Server-Int
RNT-Machine
Server-ID
Request-EU
Cache-Host
AKAMAI
We-Hiring
Web-Mar-Node
RNT-Time
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Status
X-App-Version
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
Cdncip
Cdnsip
X-Service
True-Client-Country-4JS
X-Request-URI
Country-Code
X-Sucuri-Cache
Thinkindot-CacheControl-Type
FNAC-ModuleRouting
X-AK-Request-ID
X-Thinkindot-L3
X-Req
Wxu-Next-Commit
X-NodeID
X-Matched-Rule
V-Age
X-Level-Front-Cache
X-Old-Content-Length
X-Generated-On
X-RateLimit-Remaining-Second
ServerName
X-RateLimit-Limit-Second
X-Generated-In
X-Trafficlayer-App-Version
Thinkindot-Control
Adler-Geo
X-Platform-Server
X-Servername
PFcat
Locale
Is-Eu
X-NU-AKA-ACS-Version
Server-Host
X-Cache-Tags
X-JWT-State
Platform
X-Up
X-Is-Gdpr
X-Urbn-Context-Path
Wxu-Next-Hostname
X-Core-Value
X-Has-Esi
Thinkindot-CacheControl
X-Urbn-Site-Id
X-Variation
X-Internal-Host
X-Reboot
Wxu-Next-Region
X-Oneagent-Js-Injection
X-TA-CDN-Provider
X-Lb-Id
X-ServiceProvider
X-S-Maxage
X-Response-By
Cache-Hits
X-Nginx-Cache
X-Location
X-Air-Hostname
X-Refresh
X-SERVER
RequestId
X-Parent-Response-Time
Pragrma
X-Cache-Expired-At
X-Var-Ttl
Group
X-Tb-Optimization-Total-Bytes-Saved
S-Cnection
X-B3-Parentspanid
Memory
X-Cdn-Forward
Filterid
X-CF-Powered-By
X-NC
ProcessTime
X-BACKEND-TTL
X-CSRF-Token
X-B3-SpanId
Powered-By-ChinaCache
X-Pjax-Url
X-CSRF-TOKEN
X-Wa
User-Agent
Origin
SRV
TTL
X-Pf-Uncompressing
Geoip-Latitude
X-Server-IP
X-Sucuri-ID
X-Vcl-Version
X-Varnish-Cacheable
X-NWS-UUID-VERIFY
Geoip-City
GeoIp-Country-Code
X-Correlation-ID
X-Ua
X-NGINX-Cache
X-Unique-ID
Media-Length
X-Cdn-Request-ID
PICS-Label
X-Via-CDN
X-COUNTRY
X-Developer
X-Sucuri-Id
X-Device-Os
X-Rocket-Nginx-Bypass
X-Node-Id
X-Cache-Grace
X-Cdn-Origin
X-Sn-Servicetimems
X-Ocache
SN
M-TraceId
X-Servedbyhost
Dnion-Transfer-Encoding
X-LAGOON
X-Litespeed-Cache
X-Webkit-CSP
X-MSEdge-Features
X-AIR-PT
A
X-MSEdge-Flight
X-Request-Host
Esi-Enabled
On-Server
X-HS-Status
X-Varnish-Ttl
X-Via-Ucdn
X-Cache-Status-Check
X-Reqid
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Oss-Request-Id
XServer
X-Oss-Server-Time
X-Oss-Storage-Class
X-TIME
Cdn
Tcn
Cloudfront-Viewer-Country
X-Planisys-CDN-TTL
X-Policy
X-Planisys-CDN-Rules
HostName
X-Planisys-CDN-Cache
X-FORWARDED-FOR
X-ServedByHost
X-Beluga-Trace
X-Beluga-Response-Time
Resin-Trace
X-Azure-Ref-OriginShield
X-Beluga-Status
X-Beluga-Cache-Status
X-Beluga-Node
X-Request-Start
X-Beluga-Record
Hostname
X-Ratelimit-Remaining
Rt-Proxy-Cache
X-Fastly-Country-Code
Who
X-Cache-Ttl
X-VHOST
X-Ftr-Cache-Host
Host-ID
Magicmarker
Cteonnt-Length
X-Method
Pics-Label
CF-Cached-On
Request-ID
X-Varnish-URL
NtCoent-Length
GeoIP-Country-Code
X-Slack-Backend
X-VCL-Version
X-APP
MIME-Version
X-Oracle-Dms-Rid
X-LiteSpeed-Cache-Control
X-DW
X-RPS
X-DSS
Ttl
X-DB
X-Varnish-Url
X-DI
X-RPM
X-Action
X-RSL
X-Zone
GeoIP-Latitude
X-Bc
X-Fastly-Backend-Reqs
Load-Balancing
X-DC
X-VarnishDD-TTL
CACHE
X-Dispatch
X-Cache-FS-Status
X-PAYTM-SRV-ID
X-Processor
Pramga
X-Server-Time
X-FPC
Arc-Country
X-PF-Uncompressing
X-Ratelimit-Limit
X-Svr
Ohc-Response-Time
X-Newrelic-App-Data
X-Swift-Error
X-Skip-Cache
X-Be
GeoIP-City
X-HostName
X-PJAX-URL
X-ND-Cache
X-Ftr-Request-Id
WebServer
Vix-Hermes-Req-Id
X-Hello
DSUID
X-Flog
X-SRV
X-ABtesting
Amp-Access-Control-Allow-Source-Origin
X-VCT
X-MServer
Release
X-Hp-Ccpa-Warning
Processtime
X-Dynatrace
X-Served-From
Cdn-Host
Fastly-Drupal-HTML
X-BE
N-Cache
X-Edge-Server
Cdn-Request-Time
X-DevSite-Last-Modified
X-Dynatrace-Js-Agent
Servername
CF-IPCountry
X-WR-MODIFICATION
X-WA
Cache-Provider
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
X-Configured-By
X-ID
X-Tid
X-Aicache-OS
X-Frame-Option
X-Backend-Host
X-Ftr-Backend
SD-X-WS
X-LB-ID
X-Snapshot-Date
CDN
X-Upstream-Ct
X-ZONE
Pagetype
Lfy
Dynatrace
X-Upstream-Ht
X-Bc-Bl
X-Branch-Name
X-Fastly-Cache-Hits
X-StackifyID
X-Ftr-Balancer
Requestid
X-Ftr-Dc
X-Ftr-Realm
X-SD-PageType
X-Ftr-Backend-Server
X-CACHE-AGE
WZWS-RAY
Section-Origin-Responded
X-Apw-Access-Token
X-Apw-Hits
X-Request-Url
X-Apw-Access-Object
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Io-Id
Proxy-Firewall
X-Edge-IP
V-Cache
X-Apw-Access-Action
X-BC
D-Cc-Upstream
X-Cc-Req-Id
X-Cc-Via
L
Warning
X-SB
X-VC
X-Cache-Id
X-Compress-Hint
X-Varnish-Beresp-TTL
X-SN
X-Litespeed-Cache-Control
X-Check-Cacheable
X-Via-NSCOPI
X-Fastly-Cache-Status
FSS-Proxy
FSS-Cache
Cneonction
X-WPE-Loopback-Upstream-Addr
Lb
X-ElasticPress-Search
Backend-Name
Correlation-Id
X-Request-URL
X-Worker
WP-Super-Cache
X-Release
X-Powered-Y
X-ServerName
X-App