Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
CF-RAY
Link
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
X-Request-Id
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Request-ID
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-Template
X-Language
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-Buckets
X-FRAME-OPTIONS
Status
X-Content-Security-Policy
Upgrade
X-CDN
Content-Encoding
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Xss-Protection
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
Xkey
X-Pass-Why
X-Cache-Group
P3p
X-Envoy-Upstream-Service-Time
X-AH-Environment
X-Backend
X-Via
CF-Ray
X-Age
X-Server
X-Ua-Compatible
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Server-Powered-By
X-Page-Speed
X-Ws-Request-Id
X-Pingback
EagleId
X-Proxy-Cache
X-Nginx-Cache-Status
X-Hacker
X-UA-Device
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
Cf-Railgun
Grace
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Amz-Version-Id
Report-To
X-LiteSpeed-Cache
X-Rq
X-Server-Id
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-OneAgent-JS-Injection
X-Host
X-WebKit-CSP
X-Device
EagleEye-TraceId
X-Origin-Cache
X-Response-Time
X-Node
X-Dns-Prefetch-Control
X-Ac
Content-Location
Surrogate-Control
X-Vhost
X-Readtime
X-Cloud-Trace-Context
Request-Id
X-Backend-Server
X-Dispatcher
X-Origin-Upstream-Status
X-Cnection
X-Application-Context
X-HW
X-ORACLE-DMS-ECID
X-Cache-Lookup
Fusion-Component-Id
Fusion-Content-Id
Fusion-Content-Source
Fusion-Template-Id
Fusion-Source
X-ORACLE-DMS-RID
X-DataDome
NEL
X-Mod-Pagespeed
X-Ruxit-JS-Agent
X-Rack-Cache
Rating
Edge-Control
X-Country
X-Akam-SW-Version
X-Clacks-Overhead
Pinterest-Generated-By
Allow
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-TTL
X-Country-Code
X-DynaTrace
Accept-Ch
X-Instart-Request-ID
X-Varnish-TTL
X-Goog-Hash
X-FTR-Request-ID
X-PC
X-Vname
X-TtlSet
X-ESI
Verso
Accept-Ch-Lifetime
X-Powered-By-Plesk
Content-MD5
Service-Worker-Allowed
X-Url
X-B3-TraceId
X-Forwarded-Proto
X-Version
X-MS-InvokeApp
X-Cdn-Fetch
X-Kinja-Build
X-Kinja
X-Kinja-Revision
X-Kinja-Server
X-GitHub-Request-Id
X-Use-Magma
X-Exp-Variant
X-GoogleNews-Bot
X-Exp-Id
RTSS
Edge-Cache-Tag
X-D2id
X-Debug
X-Px
AR-PoweredBy
AR-Request-ID
AR-ATIME
AR-CACHE
Ar-Sid
X-Server-Name
X-Abt-Application-Version
SPRequestGuid
X-Vcache
X-Amz-Server-Side-Encryption
Charset
X-NF-Request-ID
X-Cached
X-Accel-Expires
Response
X-Sol
X-Middleton-Response
Pagespeed
Display
X-Middleton-Display
X-Vcap-Request-Id
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-MSEdge-Ref
X-Amz-Rid
X-Fastcgi-Cache
Arr-Disable-Session-Affinity
X-Navigation-Version
X-Powered-CMS
X-SharePointHealthScore
X-Pinterest-Rid
Pinterest-Version
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Trace
TCN
X-VARITI-CCR
Realpath
Public-Key-Pins
X-Client-IP
Cache-Tag
X-Cdn
Access-Control-Request-Method
X-Fastly-Request-ID
X-Ser
MS-Author-Via
S
X-DynaTrace-JS-Agent
Nginx-Cache
X-Shard
SPRequestDuration
SPIisLatency
X-Upstream
X-Id
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
X-Edge-O15-RID
X-Ezoic-Cdn
X-Content-Type
X-Hp-Webp
X-Forwarded-For
X-Amzn-Trace-Id
X-Grace
X-T
X-Amz-Meta-S3cmd-Attrs
DynaTrace
Front-End-Https
X-Hits
X-Recruiting
Fastcgi-Cache
Nel
X-Aspnet-Version
X-Varnish-Age
ServerID
X-Dw-Request-Base-Id
MicrosoftSharePointTeamServices
X-Cache-TTL
X-Element-Page-Cache
X-Node-Name
X-DIS-Request-ID
X-Mobile-URL
X-FTR-Expires
X-FTR-Cache-Status
X-Webkit-Csp
X-Content-Digest
X-Country-Code-Real
X-Jurisdiction
X-Server-ID
NR-ENABLED
X-HS-Combine-CSS
X-Goog-Stored-Content-Encoding
X-FTR-Backend
X-FTR-Realm
X-FTR-Balancer
X-Goog-Metageneration
X-Goog-Generation
X-FTR-Backend-Server
X-HS-Hub-Id
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-HS-Cache-Config
X-Goog-Storage-Class
X-HS-Content-Id
X-FTR-DC
Powered
X-Frontend
Server-Node
Alternate-Protocol
TP-Cache
TP-L2-Cache
Server-Name
X-Logged-In
X-Correlation-Id
X-XRDS-LOCATION
X-Request-Processing-Time
X-Request-Received
AMP-Access-Control-Allow-Source-Origin
X-Microsite
X-Request-Handler-Origin-Region
X-CST
Backend-Timing
X-Amz-Apigw-Id
X-Amzn-RequestId
X-ATS-Timestamp
Upgrade-Insecure-Requests
X-Cache-Hit
X-Content-Options
X-Page-Id
Refresh
X-Origin-Server
X-Content-Security-Policy-Report-Only
X-Rid
X-F-Cache
X-Revision
X-Akamai-Edgescape
X-User-Agent
X-Varnish-Grace
X-Type
Fastly-Restarts
X-Zen-Fury
X-XRDS-Location
X-Content-Powered-By
X-B3-Sampled
X-LB-Cache
X-B
X-FTR-Cache-Host
X-Geo-Country
X-Az
X-Shield-Request-Id
X-AppVersion
X-Activity-Id
PB-PID
PB-RID
X-Mobile-Rewrite
X-URL
Arc-Version
X-N
Cache-Status
X-Kinsta-Cache
X-Pad
X-TT
X-WebKit-CSP-Report-Only
X-Instance
X-AOL-HN
X-Webapp-Samesite-None-Activated-N
X-Time
X-Cache-Age
Paypal-Debug-Id
Actual-Object-TTL
X-Signature
X-Request-Guid
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Tumblr-User
X-Jobs
X-B-Cache
X-Framework
X-App-Environment
Access-Control-Allow-Method
X-Cache-Action
X-FB-Debug
X-Load-Cache
X-PHP-Backend
DC
X-Debug-Info
X-Cached-By
X-Git-Hash
X-Analytics
X-Tt-Trace-Tag
X-Varnish-Backend
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
Surrogate-Key
Fastcgi-Useragent
X-Tt-Trace-Host
X-Amz-Replication-Status
Host-Header
X-RateLimit-Remaining
FilterID
X-Contextid
X-IPLB-Instance
MS-CV
X-ATG-Version
X-SS-Set-Cookie
X-Cache-Key
X-WA-Info
Host
X-Cluster
Tracecode
NGB
X-Response-Served-From
X-Accel-Buffering
X-Mobile
X-Via-JSL
X-Host-Name
WPE-Backend
X-ORACLE-APMCS-REQUEST-ID
X-Cache-NE
X-ORACLE-APMCS-TAG
Payment
Xserver
X-Srv
Frame-Options
X-FW-Static
X-FW-Type
X-FW-Server
X-Region
X-FW-Serve
Eomportal-Instance
X-Kong-Upstream-Latency
X-Cache-2
X-FW-Hash
X-Kong-Proxy-Latency
Source
X-Rendered-As
X-GeoIP
X-Cacheable-TTL
Filters
Cache-Tv-Group
X-IPS-LoggedIn
X-NewRelic-App-Data
X-Is-Bot
X-Varnish-Server
X-NWS-LOG-UUID
X-Varnish-Hostname
X-Cache-Enabled
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
X-Adobe-Content
X-RequestSource
X-Origin-Response-Time
X-Adobe-Loc
X-TX-ID
X-Cache-Operation
X-Cache-Rule
Retry-After
X-Seen-By
X-EdgeConnect-Cache-Status
Cleartype
X-Presslabs-Stats
X-Hostname
Server-Info
X-Cache-TTL-Remaining
X-FastCGI-Cache
X-RemovedCookies
X-ProcessESI
X-UA
X-Ruxit-Js-Agent
Liferay-Portal
X-VCache
Accept-CH
X-Dc
X-HTML-Minification-Powered-By
X-B3-Traceid
Ms-Operation-Id
X-RTag
Datacenter
X-Source
X-App-Server
X-L-Path
X-Environment-Context
Cache
X-FireWall-Port
X-Cache-Control
Healthy
X-Endurance-Cache-Level
X-PressLabs-Stats
X-Cache-Server
X-Ttl
X-Upgrade-Enabled
X-Handled-By
From-Origin
X-Backend-Name
X-CACHE-KEY
Accept-CH-Lifetime
X-Status
Version
Srv
X-RN-RSRV
Meta-Geo
X-Wix-Request-Id
X-Path-Route
X-Cache-Var
X-ES-SERVER
X-Cache-Var-Map
X-Rule
X-Format
X-Timing-Wait
X-Tb
X-Section
Selected-Fe
OT-Force-Account-Verify
X-Proxy-Build
X-Access
X-Storage
Azure-RegionName
X-PCL
X-Sorting-Hat-ShopId
X-Akamai-Request-ID
X-Goog-Meta-Goog-Reserved-File-Mtime
Akamai-GRN
Azure-InstanceId
X-ShardId
X-OCL
Mn-Server-Ip
X-Content-Age
X-EIG-Tracking-Id
X-Proto
Cache-Tags
Azure-SiteName
X-Sorting-Hat-PodId
X-Shopify-Stage
X-ShopId
Azure-SlotName
X-Shopify-Generated-Cart-Token
X-Origin
Azure-Version
X-Alternate-Cache-Key
Decoy-Debug-TTL
X-Hl-Ver
X-Hyper-Cache
X-LJ-Flow-ID
Decoy-Debug-Key
X-JoinUs
X-Yottaa-Metrics
X-Yottaa-Optimizations
Decoy-Debug-Status
X-MP-GENERATED-AT
X-Debug-Cache
X-Akamai-Request-ID2
X-Generated-By
Origin-Edge-Control
DB-Nickname
Origin-Cache-Control
NGX
Now
X-Proxy
X-Pubstack
X-Vgn-Hpd-Reason
X-AWS-Id
X-Hosted-By
X-Proxy-Cache-Status
S-Rt
Node
X-VWS-Id
Ec-Rule-Version
X-Request-Time
X-NYM-Debug-Backend
X-Web-Node
X-Time-Microsecs
X-Cluster-Node
X-Soup
X-FC-Vary-Parameters
X-Cache-Config
X-Viewer-Country
X-FW-Dynamic
X-Redis-Cache
X-Qloud-Router
X-ServerID
X-UUID
X-Cache-Host
X-SaId
X-ProxyCache-Key
X-BYPASS-REASON
X-Say-Cacheable
X-ProxyCache-Status
X-Say-TTL
Webcakes-Region
X-Detected-As
TWC-Locale-Group
TWC-Privacy
Webcakes-App-Name
Webcakes-App-Version
TWC-GeoIP-LatLong
TWC-GeoIP-Country
X-SayCDN-TTL
TWC-Connection-Speed
TWC-Device-Class
Property-Id
Cross-Origin-Window-Policy
X-Locale
X-Www-Served-By
Accept-Charset
X-IP
X-Human
X-Site-Version
X-BCube-Filmed-By
X-Varnish-Hits
X-Origin-Hint
X-RateLimit-Limit
X-APP-VERSION
X-Generated
X-CCM
X-Akamai-Transformed
X-Xfnlog-Site
X-R9-Blue-Green-Version
X-Amzn-Remapped-Content-Length
X-FB-TRIP-ID
X-Loop
X-TNCMS
X-RCS-CacheZone
X-NCache
GEO-INFO
L5d-Success-Class
X-CS
Cache-Name
Viewport
Uber-Trace-Id
X-Drupal-Cache-Tags
Time
Webserver
X-Trafficlayer-App-Name
X-Trafficlayer-App-Scope
X-UA-Device-Type
X-Esi
X-Unique-Id
Cache-Key
X-UnsetCookies
X-Cache-Remote
Mime-Version
X-Mode
Accept-Language
X-From
X-Forwarded-Host
Rt-Fastcgi-Cache
Country
X-Origin-CC
X-Origin-TTL
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Drupal-Cache-Contexts
X-Info
X-Newrelic-Synthetics
X-Daa-Tunnel
X-Cluster-Name
X-Whom
Odigeo-Trace-Id
X-Magnolia-Registration
X-NGENIX-Cache
X-Microcachable
X-Backend-TTL
X-Varnish-Cache-Hits
X-TT-TIMESTAMP
X-CDN-Forward
X-Edge-Location
X-ApacheServer
X-PERF
ServedBy
X-Geo
Content-Disposition
X-CLOUD-TRACE-CONTEXT
X-EC-Lua
X-B3-Spanid
X-Proxied
X-Device-Type
Ohc-Cache-HIT
X-Routing-Service
Proxy-Connection
X-Zipkin-Id
Ohc-File-Size
X-Via-Fastly
X-Nc
Cf-Ipcountry
X-UPSTREAM-Address
Geo-Info
X-No-Session
X-Uri
Meta-Geo-Continent
X-A
Mobile-Detection-Method
W
Rendered-Blocks
Viewtype
VivaBuild
T-Server
Content-Script-Type
Apple-News-Services-Request-Url
X-A-Ccd
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Handled
AsisCache
BehaviorPad-Version
Machine
GEO-REGION-INFO
Fastcgi-X-Cache-Version
Content-Style-Type
MD5-Digest
X-CF-Lambda-Version
X-Session-Fingerprint
X-Sigma
X-Sigma-Backend
X-ScT
X-S-Cookie
X-Rocket-Build-Number
X-Rojux
X-S
X-SRCache-Key
X-Trv-Group
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-VG-WebServer
X-VG-WebCache
X-Vdms-Version
X-VG-TLSProxy
X-Rewrite-Enabled
X-Request-UUID
X-Application
X-ARC
X-B-Cookie
X-Aed
X-Accel-Expires-Debug
X-A-Dcw
X-A-Dgt
X-A-Wwc
X-CF-Lambda-Fn
X-D
X-Geo-Header
X-GeoIP-Country-Code
X-Region-Sid
X-G
X-DPWN-IS-SECURE
X-Date
X-Destination
X-A-Dam
X-External-Request-Id
X-App-Version
Section-Io-Cache
X-C
X-PHP-Host
X-Labrador-Cache-Channel
User-Cache-Control
HitType
IsBot
X-Tumblr-Pixel-3
Locid
X-TrackingId
Powered-By
X-Thanos
X-Transaction
Ha-Gx-Prefs
X-Varnish-Authentication
X-VC-Cache
CDCHOST
Environment
Fastly-Soc-X-Request-Id
X-Distil-CS
Gh-Request-Id
X-Twitter-Response-Tags
HA-Ipaddr
X-Real-IP
X-CGP
X-Cache-Debug
X-Cache-ASPX
X-Bip
X-Connection-Hash
X-Contensis-Viewer-Groups
X-Developers
X-Eu-Site
X-CUA
X-Backend-State
X-Hit
X-Logging-Id
X-WebServer
Server-Surrogate-Control
X-Agile
X-Agile-Age
X-Auto-Login
X-App-Name
X-Agile-Id
Server-Cache-Control
X-SIPLIST1
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-Cache-Backend
X-GoCache-CacheStatus
X-Cache-Time
X-Clientip
X-Key
Fastly-SWR
X-Instart-Isnd
X-Irp-Debug
X-IN-APIGATEWAY
X-BBXSRF
X-Hash
X-Hnp-Log
X-Azure-Ref
X-IN-APIGATEWAYSSL
X-AK-Request-ID
X-Ms-Request-Id
X-Webstats-RespID
X-Origin-Date
V-Age
X-OVcl
X-OVcl-Cache
X-NX-Host
We-Hiring
X-Ms-Version
X-GeoIP-City
X-Nginx-Cache-Key
X-NodeID
Web-Mar-Node
X-Micro-Cache
X-Generation-Time
X-Varnish-Beresp-Status
X-Debug-Cache-Expiry
X-Varnish-Beresp-Ttl
X-Fastly-Cache
X-Core-Mission
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Varnish-Beresp-Grace
X-Dispatcher-Server
X-Distributor
X-Debug-Log
X-Debug-Cookies
X-Fetched-On
X-Gamma-Serve
X-Cache-Info
X-Cache-URL
True-Client-Country-4JS
X-Rebelmouse-Cache-Control
X-Cache-Bucket
X-Cdn-Srv
X-Generated-In
X-Cms-Context
X-Clara-WADP
X-Rebelmouse-Surrogate-Control
X-Gen-Mode
X-Block-Status
X-Origin-Expires
Locale
X-LI-Proto
X-Li-Pop
Kp-EeAlive
Heartbleed
X-Li-Fabric
X-TT-LOGID
X-LI-UUID
X-Owner
X-Swa-Ws
X-Trace-Id
X-TH-Server
Mail-Subject
X-FW-Version
Memcached
Cdnsip
Country-Code
Cdncip
X-WADP-Cache
Cache-Host
Access-Control-Request-Headers
Fastly-SSL
IBM-Web2-Location
X-Urbn-Context-Path
Fastly-Backend-Name
AKAMAI
X-Urbn-Site-Id
X-SVT-ORM-VERSION
X-User
Request-Country
Server-ID
RNT-Machine
X-Request-URI
Request-EU
RNT-Time
X-Server-W
X-We-Are-Hiring
Server-Int
X-RateLimit-Limit-Second
X-Proxy-Upstream
X-VServer
X-SVT-ORM-RULES
X-RateLimit-Remaining-Second
Countrycode
Fastly-SIE
X-Variation
X-Up
Adler-Geo
X-Epic-Correlation-Id
X-Req
X-Old-Content-Length
X-Level-Front-Cache
X-Sucuri-Cache
X-NU-AKA-ACS-Version
X-Platform-Server
X-Thinkindot-L3
X-Has-Esi
X-Is-Gdpr
X-JWT-State
X-Trafficlayer-App-Version
X-Reboot
X-Internal-Host
Is-Eu
X-Service
X-ServiceProvider
X-Generated-On
X-Cache-Tags
Platform
X-Matched-Rule
X-Render-Time
Thinkindot-Control
Server-Host
FNAC-ModuleRouting
ServerName
Thinkindot-CacheControl
X-Core-Value
Thinkindot-CacheControl-Type
Wxu-Next-Commit
Wxu-Next-Hostname
Wxu-Next-Region
PFcat
X-Oneagent-Js-Injection
X-Nginx-Cache
X-Response-By
X-Lb-Id
X-S-Maxage
Cache-Hits
X-Servername
X-TA-CDN-Provider
X-Location
RequestId
X-Air-Hostname
X-SERVER
X-Refresh
X-Cdn-Forward
Pragrma
X-BACKEND-TTL
X-Parent-Response-Time
X-Cache-Expired-At
X-Var-Ttl
Group
S-Cnection
X-B3-SpanId
X-B3-Parentspanid
Memory
ProcessTime
X-Tb-Optimization-Total-Bytes-Saved
Filterid
X-Tec-Api-Origin
X-Tec-Api-Root
Powered-By-ChinaCache
X-CSRF-Token
X-Tec-Api-Version
X-Pjax-Url
X-CSRF-TOKEN
X-CF-Powered-By
User-Agent
Origin
X-Unique-ID
X-Pf-Uncompressing
X-Wa
TTL
X-Server-IP
X-NC
Geoip-Latitude
X-Sucuri-ID
X-NWS-UUID-VERIFY
X-Varnish-Cacheable
GeoIp-Country-Code
Geoip-City
X-Vcl-Version
SRV
Tcn
X-Ua
X-Correlation-ID
X-Cdn-Request-ID
Media-Length
X-Via-CDN
PICS-Label
X-NGINX-Cache
X-COUNTRY
X-Developer
X-Sucuri-Id
X-Node-Id
X-Rocket-Nginx-Bypass
X-Cache-Grace
X-Sn-Servicetimems
X-LAGOON
X-Ocache
X-Device-Os
X-Cdn-Origin
On-Server
SN
X-Litespeed-Cache
Dnion-Transfer-Encoding
X-Servedbyhost
X-Webkit-CSP
M-TraceId
Esi-Enabled
X-MSEdge-Flight
A
X-Varnish-Ttl
X-Reqid
X-Ratelimit-Remaining
X-Request-Host
X-AIR-PT
X-Cache-Status-Check
X-Via-Ucdn
X-MSEdge-Features
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Object-Type
XServer
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
Hostname
X-TIME
Cloudfront-Viewer-Country
Cdn
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-HS-Status
X-Policy
X-Planisys-CDN-Cache
X-FORWARDED-FOR
X-Azure-Ref-OriginShield
X-Beluga-Trace
X-Beluga-Record
X-Beluga-Node
X-Beluga-Response-Time
X-Beluga-Cache-Status
X-Request-Start
X-Beluga-Status
X-ServedByHost
HostName
Rt-Proxy-Cache
Resin-Trace
X-Cache-Ttl
X-Fastly-Country-Code
Who
X-Ftr-Cache-Host
X-VHOST
X-Varnish-URL
Pics-Label
Host-ID
NtCoent-Length
Magicmarker
Cteonnt-Length
CF-Cached-On
X-Method
X-VCL-Version
GeoIP-Country-Code
X-APP
X-Slack-Backend
X-HostName
CACHE
MIME-Version
X-Oracle-Dms-Rid
X-Fastly-Backend-Reqs
X-Varnish-Url
X-Bc
X-DI
X-DSS
GeoIP-Latitude
X-RSL
X-RPS
X-Action
X-Ratelimit-Limit
X-DB
X-DW
X-Zone
X-RPM
Ttl
X-DC
Load-Balancing
X-LiteSpeed-Cache-Control
X-VarnishDD-TTL
GeoIP-City
X-Dispatch
X-Cache-FS-Status
X-Swift-Error
X-PF-Uncompressing
X-Server-Time
X-PAYTM-SRV-ID
X-FPC
X-Processor
X-Skip-Cache
Ohc-Response-Time
X-Newrelic-App-Data
Pramga
X-Svr
Arc-Country
X-Be
X-Flog
WebServer
Vix-Hermes-Req-Id
X-PJAX-URL
X-SRV
X-ND-Cache
X-Hello
X-ABtesting
DSUID
X-Ftr-Request-Id
Amp-Access-Control-Allow-Source-Origin
Release
X-VCT
X-MServer
Cdn-Request-Time
Processtime
N-Cache
Cdn-Host
X-Edge-Server
X-Dynatrace
X-WA
X-BE
X-Hp-Ccpa-Warning
X-Served-From
Servername
X-WR-MODIFICATION
X-Dynatrace-Js-Agent
X-Amzn-Remapped-Date
X-Amzn-Remapped-Connection
X-Bc-Bl
X-DevSite-Last-Modified
Fastly-Drupal-HTML
Cache-Provider
X-ZONE
X-Aicache-OS
X-ID
X-Tid
X-Configured-By
X-Frame-Option
X-Ftr-Backend
X-Upstream-Ht
X-Litespeed-Cache-Control
CF-IPCountry
X-Fastly-Cache-Hits
X-Backend-Host
X-Upstream-Ct
X-Ftr-Backend-Server
X-Ftr-Realm
Dynatrace
SD-X-WS
X-SD-PageType
Lfy
X-Ftr-Dc
X-Ftr-Balancer
Pagetype
X-Snapshot-Date
Requestid
X-LB-ID
X-Branch-Name
X-BC
CDN
X-StackifyID
X-CACHE-AGE
X-SN
Section-Origin-Responded
WZWS-RAY
X-WPE-Loopback-Upstream-Addr
L
X-Apw-Hits
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
X-Apw-Access-Object
X-Cache-Id
V-Cache
Section-Io-Id
X-Request-Url
X-Compress-Hint
X-Apw-Access-Token
X-Edge-IP
Proxy-Firewall
X-Cc-Req-Id
X-Cc-Via
X-VC
X-SB
X-Apw-Access-Action
X-Varnish-Beresp-TTL
D-Cc-Upstream
Warning
Backend-Name
X-Check-Cacheable
WP-Super-Cache
X-ServerName
X-Request-URL
X-Via-NSCOPI
X-Fastly-Cache-Status
X-Powered-Y
Lb
X-Release
X-ElasticPress-Search
Correlation-Id
X-Worker
X-App