Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
CF-RAY
Link
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Request-ID
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-Template
X-Language
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-Buckets
X-FRAME-OPTIONS
Status
X-Content-Security-Policy
Upgrade
X-CDN
Content-Encoding
P3p
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Xss-Protection
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
Xkey
X-Pass-Why
X-Cache-Group
X-Envoy-Upstream-Service-Time
X-AH-Environment
X-Backend
X-Via
CF-Ray
X-Age
X-Server
X-Ua-Compatible
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Server-Powered-By
X-Page-Speed
X-Ws-Request-Id
X-Pingback
EagleId
X-Proxy-Cache
X-Nginx-Cache-Status
X-Hacker
X-UA-Device
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
Cf-Railgun
Grace
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Amz-Version-Id
X-LiteSpeed-Cache
Report-To
X-Rq
X-Server-Id
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
X-Host
X-WebKit-CSP
X-Device
EagleEye-TraceId
X-Origin-Cache
X-Response-Time
X-Node
X-Dns-Prefetch-Control
X-Ac
Content-Location
Surrogate-Control
X-Vhost
X-Readtime
Request-Id
X-Backend-Server
X-Cloud-Trace-Context
X-Dispatcher
X-Origin-Upstream-Status
X-Cnection
X-Application-Context
X-HW
X-ORACLE-DMS-ECID
X-Cache-Lookup
Fusion-Component-Id
Fusion-Template-Id
Fusion-Content-Id
Fusion-Content-Source
Fusion-Source
X-ORACLE-DMS-RID
X-DataDome
NEL
X-Mod-Pagespeed
X-Ruxit-JS-Agent
X-Rack-Cache
Rating
Edge-Control
X-Country
X-Akam-SW-Version
X-Clacks-Overhead
Pinterest-Generated-By
Allow
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-TTL
X-Country-Code
X-DynaTrace
Accept-Ch
X-Instart-Request-ID
X-Varnish-TTL
X-Goog-Hash
X-FTR-Request-ID
X-Vname
X-PC
X-TtlSet
X-ESI
Verso
Accept-Ch-Lifetime
X-Powered-By-Plesk
Content-MD5
Service-Worker-Allowed
X-Url
X-B3-TraceId
X-Forwarded-Proto
X-Version
X-MS-InvokeApp
X-Kinja
X-Kinja-Build
X-Exp-Variant
X-Cdn-Fetch
X-Kinja-Revision
X-Exp-Id
X-GoogleNews-Bot
X-GitHub-Request-Id
X-Use-Magma
X-Kinja-Server
Edge-Cache-Tag
RTSS
X-D2id
X-Px
X-Debug
AR-PoweredBy
AR-CACHE
AR-Request-ID
Ar-Sid
AR-ATIME
X-Server-Name
X-Abt-Application-Version
X-Vcache
SPRequestGuid
X-Amz-Server-Side-Encryption
Charset
X-NF-Request-ID
X-Cached
X-Accel-Expires
X-TEC-API-VERSION
X-Sol
Pagespeed
Display
X-Middleton-Display
Response
X-TEC-API-ROOT
X-Middleton-Response
X-TEC-API-ORIGIN
X-MSEdge-Ref
X-Vcap-Request-Id
X-Amz-Rid
Arr-Disable-Session-Affinity
X-Navigation-Version
X-Powered-CMS
X-SharePointHealthScore
Pinterest-Version
X-Pinterest-Rid
TCN
X-Fastcgi-Cache
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Trace
X-VARITI-CCR
Realpath
Public-Key-Pins
Cache-Tag
X-Client-IP
X-Cdn
Access-Control-Request-Method
X-Fastly-Request-ID
X-Ser
MS-Author-Via
S
Nginx-Cache
X-DynaTrace-JS-Agent
X-Shard
SPIisLatency
X-Upstream
SPRequestDuration
X-Id
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
X-Ezoic-Cdn
X-Edge-O15-RID
X-Hp-Webp
X-Content-Type
X-Amzn-Trace-Id
X-Forwarded-For
X-Grace
X-T
X-Amz-Meta-S3cmd-Attrs
Front-End-Https
DynaTrace
X-Hits
X-Recruiting
Fastcgi-Cache
Nel
X-Varnish-Age
X-Aspnet-Version
ServerID
X-Cache-TTL
X-Dw-Request-Base-Id
X-Node-Name
MicrosoftSharePointTeamServices
X-Element-Page-Cache
X-DIS-Request-ID
X-Mobile-URL
X-FTR-Cache-Status
X-FTR-Expires
X-Country-Code-Real
X-Content-Digest
X-Jurisdiction
X-Server-ID
NR-ENABLED
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Cache-Config
X-Goog-Metageneration
X-FTR-Realm
X-Goog-Storage-Class
X-Frontend
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-FTR-Backend
X-FTR-DC
X-GUploader-UploadID
X-FTR-Backend-Server
X-Goog-Generation
X-FTR-Balancer
Powered
Server-Node
Alternate-Protocol
TP-L2-Cache
TP-Cache
Server-Name
X-Logged-In
X-Correlation-Id
X-XRDS-LOCATION
X-Request-Received
X-Request-Processing-Time
AMP-Access-Control-Allow-Source-Origin
Upgrade-Insecure-Requests
X-Microsite
X-Request-Handler-Origin-Region
X-ATS-Timestamp
X-Amzn-RequestId
X-Amz-Apigw-Id
X-CST
Backend-Timing
X-Cache-Hit
X-Page-Id
X-Content-Options
Refresh
X-Origin-Server
X-Content-Security-Policy-Report-Only
X-F-Cache
X-Webkit-Csp
X-Rid
X-Revision
X-User-Agent
X-Akamai-Edgescape
X-Varnish-Grace
X-Type
Fastly-Restarts
X-Zen-Fury
X-Content-Powered-By
X-XRDS-Location
X-LB-Cache
X-B3-Sampled
X-B
X-Shield-Request-Id
X-FTR-Cache-Host
X-Az
X-Activity-Id
X-Geo-Country
X-AppVersion
PB-RID
PB-PID
X-Mobile-Rewrite
Arc-Version
X-URL
Cache-Status
X-N
X-Kinsta-Cache
X-Pad
X-TT
X-Instance
X-Cache-Age
X-AOL-HN
X-Time
X-WebKit-CSP-Report-Only
X-Webapp-Samesite-None-Activated-N
X-Signature
Actual-Object-TTL
X-Framework
X-Jobs
X-Tumblr-Pixel
X-Tumblr-User
X-Request-Guid
X-Tumblr-Pixel-0
Paypal-Debug-Id
X-B-Cache
X-App-Environment
X-Debug-Info
Access-Control-Allow-Method
X-Cache-Action
X-Load-Cache
X-FB-Debug
X-PHP-Backend
DC
X-Cached-By
X-Git-Hash
X-RateLimit-Remaining
X-Analytics
X-Tt-Trace-Tag
X-Varnish-Backend
Surrogate-Key
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
Fastcgi-Useragent
X-Tt-Trace-Host
X-Amz-Replication-Status
Host-Header
X-IPLB-Instance
X-Contextid
MS-CV
X-ATG-Version
FilterID
X-SS-Set-Cookie
X-WA-Info
Tracecode
X-Cluster
Host
NGB
X-Mobile
X-Response-Served-From
X-Accel-Buffering
X-FastCGI-Cache
X-Via-JSL
X-Host-Name
WPE-Backend
X-ORACLE-APMCS-TAG
X-Cache-NE
X-Kong-Upstream-Latency
Xserver
Payment
X-Srv
X-Cache-Key
X-ORACLE-APMCS-REQUEST-ID
X-Kong-Proxy-Latency
X-FW-Server
X-FW-Type
X-FW-Serve
Source
X-FW-Static
X-Region
X-Varnish-Server
Eomportal-Instance
X-Cache-2
Frame-Options
X-FW-Hash
X-Varnish-Hostname
X-Tumblr-Pixel-2
X-GeoIP
X-Is-Bot
X-IPS-LoggedIn
Cache-Tv-Group
X-Rendered-As
X-Cacheable-TTL
X-NWS-LOG-UUID
Filters
X-Cache-Enabled
X-Tumblr-Pixel-1
X-Cache-Rule
X-Adobe-Content
X-Adobe-Loc
X-Cache-Operation
X-Presslabs-Stats
X-NewRelic-App-Data
X-Origin-Response-Time
X-RequestSource
X-TX-ID
X-Hostname
X-EdgeConnect-Cache-Status
X-Seen-By
Retry-After
Cleartype
Server-Info
X-Cache-TTL-Remaining
X-Ruxit-Js-Agent
X-ProcessESI
X-RemovedCookies
X-UA
Liferay-Portal
X-VCache
Accept-CH
X-Dc
X-HTML-Minification-Powered-By
Cache
X-B3-Traceid
Datacenter
Ms-Operation-Id
X-RTag
X-Source
X-App-Server
X-Environment-Context
X-CACHE-KEY
X-L-Path
X-FireWall-Port
X-Cache-Control
X-Endurance-Cache-Level
Healthy
X-Upgrade-Enabled
X-Ttl
X-Cache-Server
From-Origin
X-Handled-By
X-CLOUD-TRACE-CONTEXT
X-Backend-Name
Accept-CH-Lifetime
Version
X-Status
X-APP-VERSION
X-Wix-Request-Id
X-ES-SERVER
Meta-Geo
X-Rule
X-Path-Route
X-Cache-Var
X-Cache-Var-Map
X-RN-RSRV
X-PressLabs-Stats
X-Tb
X-Timing-Wait
X-RateLimit-Limit
Selected-Fe
X-Format
X-Section
OT-Force-Account-Verify
X-Access
X-Proxy-Build
X-UUID
Akamai-GRN
Azure-Version
X-Content-Age
Mn-Server-Ip
Cache-Tags
X-Alternate-Cache-Key
X-Goog-Meta-Goog-Reserved-File-Mtime
Azure-SlotName
Azure-SiteName
X-EIG-Tracking-Id
Azure-InstanceId
X-Storage
Azure-RegionName
X-OCL
X-Origin
X-ShardId
X-Shopify-Generated-Cart-Token
X-PCL
X-Akamai-Request-ID
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Proto
X-ShopId
X-Request-Time
X-Shopify-Stage
Ec-Rule-Version
Node
X-Cache-Config
X-Web-Node
X-BYPASS-REASON
X-Hl-Ver
X-ServerID
X-AWS-Id
X-VWS-Id
DB-Nickname
X-Hosted-By
Decoy-Debug-Key
Decoy-Debug-Status
NGX
Decoy-Debug-TTL
Now
X-Vgn-Hpd-Reason
Origin-Edge-Control
X-NYM-Debug-Backend
S-Rt
X-Viewer-Country
Origin-Cache-Control
X-Akamai-Request-ID2
X-FC-Vary-Parameters
X-JoinUs
X-Qloud-Router
X-Redis-Cache
X-FW-Dynamic
X-LJ-Flow-ID
X-Generated-By
X-ProxyCache-Status
X-ProxyCache-Key
X-Proxy
X-MP-GENERATED-AT
X-Pubstack
X-Proxy-Cache-Status
X-Cluster-Node
GEO-INFO
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Time-Microsecs
X-SaId
X-Debug-Cache
X-Hyper-Cache
X-Soup
X-Human
X-Site-Version
X-Generated
X-IP
X-Varnish-Hits
X-SayCDN-TTL
X-Locale
X-Origin-Hint
TWC-GeoIP-LatLong
Webcakes-Region
Webcakes-App-Version
Webcakes-App-Name
X-Www-Served-By
X-BCube-Filmed-By
X-Cache-Host
X-Detected-As
X-Say-Cacheable
TWC-Privacy
TWC-Connection-Speed
X-Say-TTL
TWC-Device-Class
TWC-GeoIP-Country
TWC-Locale-Group
X-CCM
Property-Id
Cross-Origin-Window-Policy
Accept-Charset
Srv
X-Loop
X-FB-TRIP-ID
X-Amzn-Remapped-Content-Length
X-Xfnlog-Site
X-RCS-CacheZone
X-R9-Blue-Green-Version
X-Akamai-Transformed
X-TNCMS
L5d-Success-Class
X-NCache
X-CS
Cache-Name
X-Unique-Id
Viewport
Uber-Trace-Id
X-Drupal-Cache-Tags
X-Trafficlayer-App-Scope
Webserver
X-Trafficlayer-App-Name
Time
X-Esi
Cache-Key
X-UA-Device-Type
X-UnsetCookies
Mime-Version
X-Cache-Remote
X-Mode
X-Forwarded-Host
Accept-Language
X-Backend-TTL
X-From
VIX-Pulpo-Upstream-Status
X-CDN-Forward
VIX-Pulpo-Node
X-Origin-CC
X-Origin-TTL
Rt-Fastcgi-Cache
Country
X-Whom
X-Info
X-Drupal-Cache-Contexts
X-Cluster-Name
X-Daa-Tunnel
X-Magnolia-Registration
X-Newrelic-Synthetics
Odigeo-Trace-Id
X-Varnish-Cache-Hits
X-NGENIX-Cache
X-TT-TIMESTAMP
X-Microcachable
X-Edge-Location
X-B3-Spanid
X-ApacheServer
X-PERF
ServedBy
Content-Disposition
X-Geo
X-EC-Lua
X-Webkit-CSP
X-Proxied
Proxy-Connection
X-Device-Type
X-Zipkin-Id
X-Routing-Service
Ohc-File-Size
X-Via-Fastly
X-UPSTREAM-Address
Ohc-Cache-HIT
X-Uri
X-No-Session
X-ARC
X-B-Cookie
X-Application
X-A-Dam
VivaBuild
Cf-Ipcountry
W
Viewtype
T-Server
Mobile-Detection-Method
Rendered-Blocks
X-A
X-A-Ccd
X-A-Wwc
X-Accel-Expires-Debug
X-Aed
X-A-Dgt
X-A-Dcw
Meta-Geo-Continent
MD5-Digest
Machine
X-Geo-Header
Content-Script-Type
Content-Style-Type
X-Transaction
X-Trv-Group
X-Twitter-Response-Tags
X-SRCache-Key
X-Sigma-Backend
X-S-Cookie
X-CF-Lambda-Fn
X-Session-Fingerprint
X-Sigma
Apple-News-Services-Handled
Apple-News-Services-Host
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
AsisCache
Section-Io-Cache
Xc-Version
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
X-Vdms-Version
X-VG-TLSProxy
X-VG-WebCache
X-VG-WebServer
X-S
X-ScT
X-Destination
X-Connection-Hash
X-G
X-D
X-Date
X-External-Request-Id
X-Rojux
X-DPWN-IS-SECURE
X-GeoIP-Country-Code
X-Request-UUID
X-Rewrite-Enabled
X-Rocket-Build-Number
X-Region-Sid
Fastcgi-X-Cache-Version
BehaviorPad-Version
X-CF-Lambda-Version
GEO-REGION-INFO
X-C
HitType
X-Labrador-Cache-Channel
X-PHP-Host
X-Nc
User-Cache-Control
Locid
Environment
Fastly-Soc-X-Request-Id
Ha-Gx-Prefs
IsBot
HA-Ipaddr
Gh-Request-Id
CDCHOST
X-CGP
X-SIPLIST1
X-Thanos
X-Real-IP
X-Logging-Id
X-Eu-Site
X-Hit
X-TrackingId
X-Tumblr-Pixel-3
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-WebServer
X-VC-Cache
X-Varnish-Authentication
X-Distil-CS
X-Developers
X-Agile-Age
X-Agile-Id
X-Agile
Server-Surrogate-Control
Server-Cache-Control
X-App-Name
X-Auto-Login
X-Cache-Debug
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Bip
X-Backend-State
Powered-By
X-CUA
Geo-Info
X-Cache-Backend
X-Cache-Time
X-GoCache-CacheStatus
X-OVcl-Cache
X-Origin-Expires
X-AK-Request-ID
X-OVcl
X-Origin-Date
X-NX-Host
X-BBXSRF
X-Ms-Request-Id
X-Ms-Version
X-Nginx-Cache-Key
X-Azure-Ref
X-NodeID
X-Owner
X-RateLimit-Remaining-Second
We-Hiring
Web-Mar-Node
X-Swa-Ws
X-Distributor
X-Varnish-Beresp-Grace
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Micro-Cache
X-RateLimit-Limit-Second
X-Render-Time
X-Request-URI
X-Server-W
X-Proxy-Upstream
X-Cache-Bucket
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
X-Gamma-Serve
X-Gen-Mode
X-Core-Mission
X-Generated-In
X-Debug-Cache-Store
X-Debug-Cookies
X-Dispatcher-Server
X-Epic-Correlation-Id
X-Fastly-Cache
X-Fetched-On
X-Debug-Log
X-Generation-Time
X-GeoIP-City
X-Cache-URL
X-Instart-Isnd
X-Cache-Info
X-Irp-Debug
V-Age
X-Key
X-Cdn-Srv
X-IN-APIGATEWAYSSL
X-Cms-Context
X-Hash
X-Clara-WADP
X-Hnp-Log
X-IN-APIGATEWAY
X-Block-Status
X-Trace-Id
Countrycode
Mail-Subject
Fastly-SIE
Fastly-SWR
X-VServer
X-User
X-Li-Pop
X-LI-Proto
X-LI-UUID
X-TH-Server
Locale
Kp-EeAlive
Cdnsip
Cdncip
AKAMAI
Cache-Host
Country-Code
X-Rebelmouse-Surrogate-Control
X-Clientip
Heartbleed
Fastly-Backend-Name
X-Rebelmouse-Cache-Control
X-Li-Fabric
X-We-Are-Hiring
Request-Country
X-Varnish-Beresp-Ttl
Server-ID
X-Webstats-RespID
Access-Control-Request-Headers
X-WADP-Cache
X-Varnish-Beresp-Status
X-TT-LOGID
True-Client-Country-4JS
X-Urbn-Context-Path
X-Urbn-Site-Id
Fastly-SSL
Server-Int
IBM-Web2-Location
X-FW-Version
RNT-Time
Request-EU
Memcached
RNT-Machine
X-App-Version
X-Generated-On
X-Reboot
X-Platform-Server
X-Servername
X-Old-Content-Length
X-Variation
X-Thinkindot-L3
X-Up
X-NU-AKA-ACS-Version
X-Is-Gdpr
Is-Eu
Platform
X-Req
X-Matched-Rule
Adler-Geo
X-Trafficlayer-App-Version
X-Cache-Tags
X-Internal-Host
X-Level-Front-Cache
X-Has-Esi
X-ServiceProvider
X-Service
X-JWT-State
X-Sucuri-Cache
Server-Host
Thinkindot-CacheControl
X-Core-Value
FNAC-ModuleRouting
ServerName
PFcat
Thinkindot-CacheControl-Type
Wxu-Next-Hostname
Thinkindot-Control
Wxu-Next-Region
Wxu-Next-Commit
X-Oneagent-Js-Injection
Cache-Hits
X-Lb-Id
X-TA-CDN-Provider
X-Response-By
X-S-Maxage
X-Nginx-Cache
Filterid
X-SERVER
X-Air-Hostname
X-Location
X-Refresh
RequestId
X-Parent-Response-Time
X-Tb-Optimization-Total-Bytes-Saved
X-Var-Ttl
X-Cache-Expired-At
Pragrma
Group
S-Cnection
X-B3-Parentspanid
Memory
ProcessTime
X-CF-Powered-By
X-Cdn-Forward
X-Tec-Api-Origin
X-NC
X-Tec-Api-Root
X-Pjax-Url
Powered-By-ChinaCache
X-CSRF-Token
X-B3-SpanId
X-Tec-Api-Version
X-BACKEND-TTL
X-CSRF-TOKEN
SRV
User-Agent
Origin
X-Wa
X-Pf-Uncompressing
TTL
Geoip-Latitude
X-Server-IP
X-Sucuri-ID
X-NWS-UUID-VERIFY
GeoIp-Country-Code
X-Varnish-Cacheable
Geoip-City
X-Vcl-Version
X-Unique-ID
X-Correlation-ID
X-NGINX-Cache
X-Ua
X-Via-CDN
PICS-Label
Media-Length
X-Cdn-Request-ID
X-COUNTRY
X-Developer
X-Sucuri-Id
X-Node-Id
X-Rocket-Nginx-Bypass
X-Cache-Grace
X-LAGOON
X-Device-Os
X-Ocache
X-Cdn-Origin
X-Sn-Servicetimems
On-Server
M-TraceId
X-Servedbyhost
X-Litespeed-Cache
Dnion-Transfer-Encoding
SN
X-Request-Host
X-HS-Status
Esi-Enabled
A
X-AIR-PT
X-MSEdge-Features
X-MSEdge-Flight
X-Cache-Status-Check
X-Via-Ucdn
X-Varnish-Ttl
X-Reqid
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
X-TIME
X-Oss-Object-Type
XServer
X-Oss-Server-Time
HostName
Cloudfront-Viewer-Country
X-Policy
Cdn
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
Tcn
X-FORWARDED-FOR
X-Beluga-Trace
X-ServedByHost
X-Beluga-Status
X-Beluga-Record
X-Beluga-Cache-Status
X-Beluga-Node
Resin-Trace
X-Beluga-Response-Time
X-Request-Start
X-Azure-Ref-OriginShield
Hostname
X-Ratelimit-Remaining
X-Fastly-Country-Code
Who
Rt-Proxy-Cache
X-Cache-Ttl
X-Ftr-Cache-Host
X-VHOST
Host-ID
X-Method
Cteonnt-Length
Pics-Label
CF-Cached-On
X-Varnish-URL
Magicmarker
NtCoent-Length
X-VCL-Version
GeoIP-Country-Code
X-Slack-Backend
X-Varnish-Url
X-APP
X-LiteSpeed-Cache-Control
X-Oracle-Dms-Rid
MIME-Version
X-RPM
X-DW
X-Action
X-DB
X-Bc
Ttl
X-RPS
X-Fastly-Backend-Reqs
X-Zone
X-RSL
X-DSS
X-DI
GeoIP-Latitude
X-DC
Load-Balancing
X-PAYTM-SRV-ID
X-FPC
Arc-Country
X-Processor
X-Server-Time
X-VarnishDD-TTL
X-Cache-FS-Status
CACHE
X-Svr
X-Dispatch
Pramga
X-Skip-Cache
X-PF-Uncompressing
X-Ratelimit-Limit
X-Swift-Error
Ohc-Response-Time
X-Newrelic-App-Data
X-Be
GeoIP-City
X-HostName
X-Hello
WebServer
X-Flog
X-ND-Cache
X-SRV
Amp-Access-Control-Allow-Source-Origin
X-PJAX-URL
X-Ftr-Request-Id
Vix-Hermes-Req-Id
DSUID
X-ABtesting
Release
X-MServer
X-VCT
N-Cache
Processtime
X-Hp-Ccpa-Warning
X-DevSite-Last-Modified
Cdn-Host
X-Edge-Server
Cdn-Request-Time
X-Dynatrace
Fastly-Drupal-HTML
X-Served-From
X-BE
Servername
CF-IPCountry
X-Dynatrace-Js-Agent
X-WR-MODIFICATION
X-Bc-Bl
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
X-ID
Cache-Provider
X-Tid
X-Aicache-OS
X-WA
X-Configured-By
X-ZONE
X-Frame-Option
X-Ftr-Backend
SD-X-WS
X-Ftr-Dc
X-StackifyID
X-Ftr-Balancer
X-SD-PageType
Lfy
X-Upstream-Ct
X-Fastly-Cache-Hits
X-BC
X-Branch-Name
Requestid
X-Upstream-Ht
X-Ftr-Backend-Server
Pagetype
CDN
X-Ftr-Realm
Dynatrace
X-Snapshot-Date
X-Backend-Host
X-LB-ID
X-CACHE-AGE
WZWS-RAY
X-Apw-Hits
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
X-Apw-Access-Action
X-Cc-Via
Proxy-Firewall
L
X-Varnish-Beresp-TTL
X-Edge-IP
X-Cache-Id
X-Compress-Hint
X-Apw-Access-Token
X-Apw-Access-Object
X-VC
Warning
D-Cc-Upstream
X-Cc-Req-Id
Section-Io-Origin-Status
X-SB
X-Request-Url
X-SN
Section-Io-Id
V-Cache
X-Litespeed-Cache-Control
FSS-Proxy
FSS-Cache
Cneonction
X-WPE-Loopback-Upstream-Addr
Correlation-Id
X-ServerName
Backend-Name
Lb
X-Via-NSCOPI
X-Release
X-App
X-Worker
X-Request-URL
X-Check-Cacheable
X-Powered-Y
X-ElasticPress-Search
WP-Super-Cache
X-Fastly-Cache-Status