Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
CF-RAY
Link
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Request-ID
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-Template
X-Language
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-Buckets
X-FRAME-OPTIONS
Status
X-Content-Security-Policy
Upgrade
X-CDN
Content-Encoding
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Xss-Protection
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
Xkey
X-Pass-Why
X-Cache-Group
P3p
X-Envoy-Upstream-Service-Time
X-AH-Environment
X-Backend
X-Via
CF-Ray
X-Age
X-Server
X-Ua-Compatible
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Server-Powered-By
X-Page-Speed
X-Ws-Request-Id
X-Pingback
EagleId
X-Proxy-Cache
X-Hacker
X-Nginx-Cache-Status
X-UA-Device
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
Cf-Railgun
Grace
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Amz-Version-Id
Report-To
X-LiteSpeed-Cache
X-Rq
X-Server-Id
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-WebKit-CSP
X-OneAgent-JS-Injection
X-Host
X-Device
EagleEye-TraceId
X-Origin-Cache
X-Response-Time
X-Node
X-Dns-Prefetch-Control
X-Ac
Content-Location
Surrogate-Control
X-Vhost
X-Readtime
Request-Id
X-Backend-Server
X-Cloud-Trace-Context
X-Dispatcher
X-Origin-Upstream-Status
X-Cnection
X-Application-Context
X-HW
X-ORACLE-DMS-ECID
X-Cache-Lookup
Fusion-Component-Id
Fusion-Content-Id
Fusion-Content-Source
Fusion-Source
Fusion-Template-Id
X-ORACLE-DMS-RID
X-DataDome
X-Mod-Pagespeed
X-Ruxit-JS-Agent
NEL
X-Rack-Cache
Rating
Edge-Control
X-Country
X-Akam-SW-Version
X-Clacks-Overhead
Pinterest-Generated-By
Allow
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-TTL
X-Country-Code
X-DynaTrace
Accept-Ch
X-Instart-Request-ID
X-Varnish-TTL
X-FTR-Request-ID
X-Goog-Hash
X-TtlSet
X-Vname
X-PC
X-ESI
Verso
Accept-Ch-Lifetime
X-Powered-By-Plesk
Service-Worker-Allowed
Content-MD5
X-Url
X-B3-TraceId
X-Forwarded-Proto
X-Version
X-MS-InvokeApp
X-Cdn-Fetch
X-Kinja-Server
X-Use-Magma
X-GitHub-Request-Id
X-Kinja-Revision
X-Kinja-Build
X-Exp-Variant
X-GoogleNews-Bot
X-Kinja
X-Exp-Id
RTSS
Edge-Cache-Tag
X-D2id
X-Debug
X-Px
AR-CACHE
AR-ATIME
AR-Request-ID
AR-PoweredBy
Ar-Sid
X-Server-Name
X-Abt-Application-Version
SPRequestGuid
X-Vcache
X-Amz-Server-Side-Encryption
Charset
X-NF-Request-ID
X-Cached
X-Accel-Expires
X-Middleton-Response
Display
X-Sol
X-TEC-API-ORIGIN
X-TEC-API-ROOT
Pagespeed
Response
X-Middleton-Display
X-TEC-API-VERSION
X-MSEdge-Ref
X-Vcap-Request-Id
X-Fastcgi-Cache
X-Amz-Rid
Arr-Disable-Session-Affinity
X-Navigation-Version
X-Powered-CMS
X-SharePointHealthScore
X-Pinterest-Rid
Pinterest-Version
TCN
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Trace
X-VARITI-CCR
Realpath
Public-Key-Pins
X-Client-IP
Cache-Tag
X-Cdn
Access-Control-Request-Method
X-Fastly-Request-ID
MS-Author-Via
X-Ser
Nginx-Cache
S
X-DynaTrace-JS-Agent
Nel
X-Shard
SPRequestDuration
X-Upstream
SPIisLatency
X-Id
X-Mrf-Item-Lastmod
Mrf-Cache-Status
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
MRF-Tech
X-Edge-O15-RID
X-Ezoic-Cdn
X-Hp-Webp
X-Content-Type
X-Amzn-Trace-Id
X-Forwarded-For
X-Grace
X-T
X-Amz-Meta-S3cmd-Attrs
Front-End-Https
DynaTrace
X-Hits
X-Recruiting
Fastcgi-Cache
X-Varnish-Age
X-Aspnet-Version
ServerID
X-Cache-TTL
X-Dw-Request-Base-Id
X-Element-Page-Cache
MicrosoftSharePointTeamServices
X-Node-Name
X-DIS-Request-ID
X-Mobile-URL
X-FTR-Cache-Status
X-Content-Digest
X-Jurisdiction
X-Country-Code-Real
X-FTR-Expires
NR-ENABLED
X-Server-ID
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Combine-CSS
X-HS-Content-Id
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Storage-Class
X-FTR-Backend-Server
X-FTR-Realm
X-Goog-Generation
Powered
X-FTR-Backend
X-FTR-DC
X-Frontend
X-FTR-Balancer
X-Goog-Metageneration
Server-Node
Alternate-Protocol
TP-Cache
TP-L2-Cache
Server-Name
X-Logged-In
X-Correlation-Id
X-XRDS-LOCATION
X-Request-Processing-Time
X-Request-Received
AMP-Access-Control-Allow-Source-Origin
X-Microsite
X-Request-Handler-Origin-Region
Upgrade-Insecure-Requests
X-ATS-Timestamp
Backend-Timing
X-Amz-Apigw-Id
X-CST
X-Amzn-RequestId
X-Cache-Hit
X-Page-Id
X-Content-Options
Refresh
X-Origin-Server
X-Content-Security-Policy-Report-Only
X-Revision
X-User-Agent
X-Webkit-Csp
X-F-Cache
X-Rid
X-Akamai-Edgescape
X-Varnish-Grace
X-Type
Fastly-Restarts
X-Zen-Fury
X-Content-Powered-By
X-XRDS-Location
X-LB-Cache
X-B3-Sampled
X-B
X-FTR-Cache-Host
X-Geo-Country
X-Activity-Id
X-AppVersion
X-Az
X-Shield-Request-Id
PB-PID
PB-RID
Arc-Version
X-URL
X-Mobile-Rewrite
X-N
Cache-Status
X-Kinsta-Cache
X-Pad
X-TT
X-Time
X-Instance
X-WebKit-CSP-Report-Only
X-Cache-Age
X-AOL-HN
X-Webapp-Samesite-None-Activated-N
X-Signature
X-Request-Guid
X-B-Cache
X-Tumblr-User
Paypal-Debug-Id
Actual-Object-TTL
X-Tumblr-Pixel-0
X-App-Environment
X-Tumblr-Pixel
X-Framework
X-Jobs
X-Debug-Info
X-Cache-Action
Access-Control-Allow-Method
X-FB-Debug
X-PHP-Backend
X-Load-Cache
DC
X-Cached-By
X-Git-Hash
X-RateLimit-Remaining
X-Analytics
X-Tt-Trace-Tag
X-Varnish-Backend
X-Erf-Bev-Bev
Surrogate-Key
X-Erf-Bev-Bev-Is-Generated
Fastcgi-Useragent
X-Tt-Trace-Host
X-Amz-Replication-Status
Host-Header
X-Contextid
X-IPLB-Instance
MS-CV
X-ATG-Version
FilterID
X-SS-Set-Cookie
X-WA-Info
Tracecode
Host
X-Cluster
X-Mobile
NGB
X-Accel-Buffering
X-Response-Served-From
X-Via-JSL
WPE-Backend
X-Host-Name
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-ORACLE-APMCS-TAG
Xserver
X-Cache-NE
X-ORACLE-APMCS-REQUEST-ID
X-Srv
Payment
X-Cache-Key
X-FW-Serve
X-Varnish-Server
Frame-Options
X-Cache-2
X-FW-Hash
Eomportal-Instance
X-FW-Server
X-Region
X-FW-Type
X-FW-Static
Source
X-Is-Bot
Filters
X-Cacheable-TTL
X-NWS-LOG-UUID
X-Varnish-Hostname
X-GeoIP
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
X-Rendered-As
Cache-Tv-Group
X-IPS-LoggedIn
X-Cache-Enabled
X-Presslabs-Stats
X-Cache-Rule
X-Cache-Operation
X-Adobe-Content
X-Adobe-Loc
X-RequestSource
X-NewRelic-App-Data
X-Origin-Response-Time
X-TX-ID
X-Hostname
X-EdgeConnect-Cache-Status
X-Seen-By
Retry-After
Cleartype
Server-Info
X-Cache-TTL-Remaining
X-FastCGI-Cache
X-Ruxit-Js-Agent
X-ProcessESI
X-RemovedCookies
X-UA
X-VCache
Liferay-Portal
X-HTML-Minification-Powered-By
X-Dc
Accept-CH
Cache
Ms-Operation-Id
Datacenter
X-B3-Traceid
X-RTag
X-Source
X-FireWall-Port
X-L-Path
X-Environment-Context
X-App-Server
X-CACHE-KEY
X-Cache-Control
X-Upgrade-Enabled
X-Endurance-Cache-Level
Healthy
X-Ttl
X-Cache-Server
From-Origin
X-Handled-By
X-CLOUD-TRACE-CONTEXT
X-Backend-Name
Version
X-APP-VERSION
Accept-CH-Lifetime
X-Status
X-RN-RSRV
X-Rule
X-PressLabs-Stats
X-Path-Route
Meta-Geo
X-Wix-Request-Id
X-Cache-Var
X-Cache-Var-Map
X-ES-SERVER
X-Timing-Wait
X-RateLimit-Limit
X-Proxy-Build
OT-Force-Account-Verify
X-Tb
X-Section
X-Format
X-Access
Selected-Fe
X-UUID
X-Origin
X-Storage
Akamai-GRN
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Akamai-Request-ID
X-Proto
X-Content-Age
X-Request-Time
X-OCL
X-PCL
Azure-Version
X-Shopify-Generated-Cart-Token
Mn-Server-Ip
Azure-InstanceId
X-ShardId
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Alternate-Cache-Key
X-Sorting-Hat-ShopId
X-EIG-Tracking-Id
Cache-Tags
X-ShopId
Azure-SlotName
Azure-SiteName
Azure-RegionName
X-Akamai-Request-ID2
X-Hl-Ver
Origin-Edge-Control
X-Generated-By
X-AWS-Id
X-Debug-Cache
X-Cluster-Node
X-Proxy
X-Cache-Host
X-BYPASS-REASON
Origin-Cache-Control
Now
Decoy-Debug-Status
Decoy-Debug-Key
X-MP-GENERATED-AT
DB-Nickname
Decoy-Debug-TTL
X-JoinUs
NGX
X-Human
X-Hyper-Cache
X-ProxyCache-Key
X-LJ-Flow-ID
X-Qloud-Router
S-Rt
Node
X-SaId
X-Web-Node
X-FW-Dynamic
X-Time-Microsecs
Ec-Rule-Version
X-ProxyCache-Status
X-Vgn-Hpd-Reason
GEO-INFO
X-VWS-Id
X-FC-Vary-Parameters
X-Cache-Config
X-NYM-Debug-Backend
X-Hosted-By
X-ServerID
X-Soup
X-Pubstack
X-Viewer-Country
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Proxy-Cache-Status
X-Redis-Cache
Cross-Origin-Window-Policy
X-SayCDN-TTL
Accept-Charset
X-Generated
X-Www-Served-By
X-Say-TTL
Property-Id
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-Country
X-Detected-As
TWC-Locale-Group
X-Site-Version
TWC-GeoIP-LatLong
X-Say-Cacheable
TWC-Privacy
X-BCube-Filmed-By
X-IP
Webcakes-App-Version
X-Varnish-Hits
X-CCM
Webcakes-App-Name
X-Origin-Hint
Webcakes-Region
X-Locale
Srv
X-Loop
X-R9-Blue-Green-Version
X-RCS-CacheZone
X-TNCMS
X-Akamai-Transformed
X-Amzn-Remapped-Content-Length
X-FB-TRIP-ID
X-Xfnlog-Site
X-NCache
L5d-Success-Class
X-CS
Cache-Name
Viewport
Uber-Trace-Id
X-Unique-Id
X-Drupal-Cache-Tags
Webserver
Time
X-Trafficlayer-App-Name
X-Trafficlayer-App-Scope
X-UA-Device-Type
X-Esi
Cache-Key
X-UnsetCookies
X-Cache-Remote
Mime-Version
X-Mode
X-Forwarded-Host
X-From
Accept-Language
X-Backend-TTL
Rt-Fastcgi-Cache
Country
X-CDN-Forward
X-Origin-CC
X-Origin-TTL
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Daa-Tunnel
X-Drupal-Cache-Contexts
X-Cluster-Name
X-Info
X-Whom
Odigeo-Trace-Id
X-Newrelic-Synthetics
X-Magnolia-Registration
X-NGENIX-Cache
X-Microcachable
X-TT-TIMESTAMP
X-Varnish-Cache-Hits
X-Edge-Location
X-B3-Spanid
X-ApacheServer
X-PERF
ServedBy
X-Geo
Content-Disposition
X-EC-Lua
X-Routing-Service
X-Zipkin-Id
X-Proxied
X-Device-Type
Ohc-File-Size
Proxy-Connection
Ohc-Cache-HIT
X-UPSTREAM-Address
X-Via-Fastly
X-No-Session
X-Uri
Cf-Ipcountry
X-D
Rendered-Blocks
X-Connection-Hash
X-CF-Lambda-Version
X-Destination
X-Request-UUID
X-ScT
X-Session-Fingerprint
X-Sigma
GEO-REGION-INFO
Fastcgi-X-Cache-Version
X-S
X-Region-Sid
X-Rewrite-Enabled
X-Rocket-Build-Number
X-Rojux
X-CF-Lambda-Fn
AsisCache
Content-Style-Type
Apple-News-Services-Parsed-Url
X-DPWN-IS-SECURE
X-GeoIP-Country-Code
Content-Script-Type
Apple-News-Services-Handled
Machine
X-Geo-Header
X-Sigma-Backend
Apple-News-Services-Request-Url
BehaviorPad-Version
X-G
Mobile-Detection-Method
Apple-News-Services-Host
Meta-Geo-Continent
MD5-Digest
X-External-Request-Id
X-Date
X-S-Cookie
W
X-ARC
X-Vdms-Version
X-Application
X-A
X-A-Dcw
X-Twitter-Response-Tags
X-A-Dam
VivaBuild
X-VG-TLSProxy
Viewtype
X-B-Cookie
Xc-Version
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
X-VG-WebCache
X-VG-WebServer
X-A-Dgt
X-A-Ccd
Section-Io-Cache
X-Transaction
T-Server
X-Aed
X-SRCache-Key
X-Trv-Group
X-Accel-Expires-Debug
X-A-Wwc
X-C
X-PHP-Host
X-Labrador-Cache-Channel
X-Nc
HitType
User-Cache-Control
Ha-Gx-Prefs
X-Distil-CS
Gh-Request-Id
X-App-Name
HA-Ipaddr
X-Agile-Id
X-Auto-Login
Fastly-Soc-X-Request-Id
IsBot
Locid
CDCHOST
X-Cache-Backend
X-Developers
X-Agile-Age
Environment
X-Eu-Site
X-Wikidot-Static-Cache
X-Backend-State
X-Contensis-Viewer-Groups
X-Thanos
Powered-By
X-Cache-ASPX
X-Real-IP
X-Hit
X-TrackingId
Server-Cache-Control
X-Tumblr-Pixel-3
X-Bip
X-CGP
X-CUA
X-Cache-Debug
X-WebServer
Server-Surrogate-Control
X-SIPLIST1
X-Wikidot-Backend
X-Varnish-Authentication
X-Agile
X-VC-Cache
X-Logging-Id
Geo-Info
X-GoCache-CacheStatus
X-Cache-Time
X-Block-Status
X-Cache-Bucket
X-Cache-Info
X-Dispatcher-Server
X-Cms-Context
X-Debug-Cache-Store
X-Debug-Cookies
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-Azure-Ref
X-Core-Mission
X-AK-Request-ID
X-Cdn-Srv
X-Clara-WADP
X-Debug-Log
X-BBXSRF
X-Cache-URL
X-Irp-Debug
X-Webstats-RespID
X-WADP-Cache
Access-Control-Request-Headers
Fastly-SSL
Memcached
IBM-Web2-Location
X-Urbn-Site-Id
X-Urbn-Context-Path
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Swa-Ws
X-Trace-Id
X-TT-LOGID
X-FW-Version
X-Li-Fabric
Fastly-SIE
Countrycode
Fastly-SWR
X-Clientip
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-We-Are-Hiring
X-VServer
X-LI-Proto
X-Li-Pop
X-LI-UUID
X-TH-Server
X-User
X-Server-W
X-Request-URI
X-Hnp-Log
X-Hash
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Key
X-Instart-Isnd
X-GeoIP-City
X-Generation-Time
X-Fetched-On
X-Epic-Correlation-Id
X-Gamma-Serve
X-Gen-Mode
X-Generated-In
X-Micro-Cache
X-Ms-Request-Id
X-Owner
X-OVcl-Cache
X-Proxy-Upstream
X-RateLimit-Limit-Second
X-Render-Time
X-RateLimit-Remaining-Second
X-OVcl
X-Origin-Expires
X-Nginx-Cache-Key
X-Ms-Version
X-NodeID
X-NX-Host
X-Origin-Date
X-Distributor
X-Fastly-Cache
X-Varnish-Beresp-Ttl
Server-Int
X-Varnish-Beresp-Status
Request-Country
X-Varnish-Beresp-Grace
Server-ID
AKAMAI
Request-EU
RNT-Machine
RNT-Time
Country-Code
Cache-Host
Mail-Subject
Cdnsip
We-Hiring
Heartbleed
Fastly-Backend-Name
V-Age
Kp-EeAlive
True-Client-Country-4JS
Locale
Cdncip
Web-Mar-Node
X-App-Version
X-Platform-Server
ServerName
X-NU-AKA-ACS-Version
X-Up
X-Variation
X-Generated-On
X-Servername
Platform
X-Service
Wxu-Next-Region
X-Req
X-ServiceProvider
X-Trafficlayer-App-Version
X-Thinkindot-L3
X-Sucuri-Cache
X-Reboot
X-Old-Content-Length
X-Cache-Tags
X-Has-Esi
X-Internal-Host
X-Level-Front-Cache
X-Matched-Rule
Adler-Geo
Is-Eu
X-Is-Gdpr
X-JWT-State
Wxu-Next-Hostname
X-Core-Value
Server-Host
Thinkindot-CacheControl
Thinkindot-Control
Thinkindot-CacheControl-Type
PFcat
Wxu-Next-Commit
FNAC-ModuleRouting
X-Oneagent-Js-Injection
X-Lb-Id
Cache-Hits
X-S-Maxage
X-Response-By
X-TA-CDN-Provider
X-Nginx-Cache
Filterid
X-SERVER
X-Refresh
X-Location
X-Air-Hostname
RequestId
X-Parent-Response-Time
X-Var-Ttl
X-Cache-Expired-At
Group
X-Tb-Optimization-Total-Bytes-Saved
Pragrma
S-Cnection
X-B3-Parentspanid
ProcessTime
Memory
X-Cdn-Forward
X-CF-Powered-By
X-CSRF-Token
X-NC
X-Tec-Api-Root
X-Tec-Api-Version
X-B3-SpanId
X-BACKEND-TTL
Powered-By-ChinaCache
X-Tec-Api-Origin
X-Pjax-Url
X-CSRF-TOKEN
X-Wa
SRV
User-Agent
Origin
X-Server-IP
TTL
Geoip-Latitude
X-Pf-Uncompressing
X-Sucuri-ID
X-NWS-UUID-VERIFY
X-Vcl-Version
X-Varnish-Cacheable
GeoIp-Country-Code
Geoip-City
X-Correlation-ID
X-NGINX-Cache
X-Ua
X-Unique-ID
X-Via-CDN
Media-Length
X-Cdn-Request-ID
PICS-Label
X-Developer
X-COUNTRY
X-Sucuri-Id
X-Sn-Servicetimems
X-Ocache
X-Cache-Grace
X-Node-Id
X-Cdn-Origin
X-LAGOON
X-Rocket-Nginx-Bypass
X-Device-Os
On-Server
X-Servedbyhost
Dnion-Transfer-Encoding
X-Webkit-CSP
SN
M-TraceId
X-Litespeed-Cache
X-Cache-Status-Check
X-Request-Host
X-Reqid
X-HS-Status
X-Varnish-Ttl
X-MSEdge-Flight
A
X-AIR-PT
X-Via-Ucdn
Esi-Enabled
X-MSEdge-Features
X-Oss-Object-Type
XServer
X-TIME
X-Oss-Hash-Crc64ecma
X-Oss-Storage-Class
X-Oss-Server-Time
X-Oss-Request-Id
Tcn
HostName
X-Planisys-CDN-Rules
Cloudfront-Viewer-Country
Cdn
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
X-Policy
X-FORWARDED-FOR
Resin-Trace
X-Request-Start
X-Beluga-Cache-Status
X-Beluga-Status
X-Beluga-Trace
X-ServedByHost
Hostname
X-Azure-Ref-OriginShield
X-Beluga-Response-Time
X-Beluga-Record
X-Beluga-Node
X-Ratelimit-Remaining
X-Fastly-Country-Code
Who
Rt-Proxy-Cache
X-Cache-Ttl
X-VHOST
X-Ftr-Cache-Host
Host-ID
NtCoent-Length
X-Varnish-URL
Magicmarker
X-Method
Pics-Label
Cteonnt-Length
CF-Cached-On
GeoIP-Country-Code
X-Slack-Backend
X-Varnish-Url
X-APP
X-VCL-Version
X-Oracle-Dms-Rid
MIME-Version
X-LiteSpeed-Cache-Control
X-DSS
X-DB
X-DI
X-DW
X-Fastly-Backend-Reqs
X-RPM
X-Action
Ttl
X-Bc
X-RSL
X-Zone
GeoIP-Latitude
X-RPS
Load-Balancing
X-DC
X-Processor
X-PAYTM-SRV-ID
X-VarnishDD-TTL
X-Server-Time
X-FPC
X-Skip-Cache
Ohc-Response-Time
CACHE
X-Be
X-Dispatch
X-Swift-Error
X-Cache-FS-Status
X-Ratelimit-Limit
X-PF-Uncompressing
X-Svr
Arc-Country
X-Newrelic-App-Data
GeoIP-City
Pramga
X-HostName
X-PJAX-URL
WebServer
DSUID
X-Ftr-Request-Id
X-SRV
X-ND-Cache
Amp-Access-Control-Allow-Source-Origin
Vix-Hermes-Req-Id
X-Hello
X-ABtesting
X-Flog
X-MServer
X-VCT
Release
X-Dynatrace
X-DevSite-Last-Modified
Fastly-Drupal-HTML
Processtime
Cdn-Host
X-Hp-Ccpa-Warning
Cdn-Request-Time
X-Edge-Server
X-Served-From
X-BE
N-Cache
CF-IPCountry
X-WR-MODIFICATION
Servername
X-Dynatrace-Js-Agent
X-Bc-Bl
Cache-Provider
X-Amzn-Remapped-Connection
X-Aicache-OS
X-Configured-By
X-WA
X-Tid
X-Amzn-Remapped-Date
X-ZONE
X-ID
X-Frame-Option
X-Upstream-Ht
X-StackifyID
X-Ftr-Backend-Server
X-Fastly-Cache-Hits
X-Ftr-Realm
X-Ftr-Balancer
Dynatrace
X-Upstream-Ct
Lfy
Pagetype
X-Backend-Host
X-Snapshot-Date
X-Ftr-Dc
CDN
X-LB-ID
X-BC
X-Ftr-Backend
SD-X-WS
X-Branch-Name
Requestid
X-SD-PageType
WZWS-RAY
X-CACHE-AGE
Section-Io-Origin-Time-Seconds
Section-Io-Id
Section-Origin-Responded
Section-Io-Origin-Status
X-Apw-Hits
X-Apw-Access-Token
X-Cc-Via
X-Compress-Hint
X-Request-Url
X-Apw-Access-Object
X-Apw-Access-Action
X-SN
X-Varnish-Beresp-TTL
X-Edge-IP
Proxy-Firewall
X-Cache-Id
L
X-SB
X-VC
Warning
X-Cc-Req-Id
D-Cc-Upstream
V-Cache
X-Litespeed-Cache-Control
Lb
FSS-Proxy
X-Release
X-Via-NSCOPI
X-ServerName
FSS-Cache
X-WPE-Loopback-Upstream-Addr
Backend-Name
X-Powered-Y
X-Worker
X-ElasticPress-Search
X-Request-URL
X-Fastly-Cache-Status
WP-Super-Cache
Correlation-Id
X-App
X-Check-Cacheable