Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
CF-RAY
Link
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Request-ID
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-Template
X-DNS-Prefetch-Control
X-Language
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
Status
X-Content-Security-Policy
Upgrade
X-CDN
Content-Encoding
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Xss-Protection
X-Kinja-Server-Push
Keep-Alive
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
P3p
Xkey
X-Pass-Why
X-Cache-Group
X-AH-Environment
X-Envoy-Upstream-Service-Time
CF-Ray
X-Via
X-Backend
X-Age
X-Server
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Server-Powered-By
X-Page-Speed
X-Ws-Request-Id
X-Pingback
EagleId
X-Proxy-Cache
X-Hacker
X-Nginx-Cache-Status
X-UA-Device
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
Cf-Railgun
Grace
X-Ua-Compatible
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Amz-Version-Id
Report-To
X-LiteSpeed-Cache
X-Rq
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-WebKit-CSP
X-Server-Id
X-OneAgent-JS-Injection
X-Host
X-Device
X-Origin-Cache
EagleEye-TraceId
X-Response-Time
X-Node
X-Ac
Content-Location
Surrogate-Control
X-Vhost
X-Readtime
X-Cloud-Trace-Context
Request-Id
X-Backend-Server
X-Dns-Prefetch-Control
X-Dispatcher
X-Origin-Upstream-Status
X-Cnection
X-Application-Context
X-HW
X-Cache-Lookup
X-ORACLE-DMS-ECID
Fusion-Source
Fusion-Template-Id
Fusion-Content-Id
Fusion-Component-Id
Fusion-Content-Source
X-ORACLE-DMS-RID
X-DataDome
NEL
X-Ruxit-JS-Agent
X-Mod-Pagespeed
X-Rack-Cache
Rating
Edge-Control
X-Country
X-Akam-SW-Version
X-Clacks-Overhead
Pinterest-Generated-By
X-TTL
Allow
X-Country-Code
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-DynaTrace
X-Instart-Request-ID
X-Varnish-TTL
X-FTR-Request-ID
X-Goog-Hash
X-TtlSet
X-Vname
X-PC
Accept-Ch
Verso
X-ESI
X-Powered-By-Plesk
Content-MD5
Service-Worker-Allowed
X-Url
Accept-Ch-Lifetime
X-Forwarded-Proto
X-Version
X-MS-InvokeApp
X-B3-TraceId
X-Exp-Variant
X-Kinja-Server
X-Exp-Id
X-Cdn-Fetch
X-GoogleNews-Bot
X-Use-Magma
X-Kinja
X-Kinja-Build
X-Kinja-Revision
X-GitHub-Request-Id
RTSS
Edge-Cache-Tag
X-Abt-Application-Version
X-D2id
X-Debug
X-Px
AR-PoweredBy
AR-ATIME
AR-CACHE
AR-Request-ID
Ar-Sid
X-Vcache
SPRequestGuid
X-Amz-Server-Side-Encryption
Charset
X-NF-Request-ID
X-Server-Name
X-Cached
X-Accel-Expires
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
Pagespeed
X-Sol
X-Middleton-Response
X-Middleton-Display
Response
Display
X-Vcap-Request-Id
X-MSEdge-Ref
Arr-Disable-Session-Affinity
X-Amz-Rid
TCN
X-Navigation-Version
X-Powered-CMS
Pinterest-Version
X-Pinterest-Rid
X-SharePointHealthScore
X-Fastcgi-Cache
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Trace
X-Cdn
X-VARITI-CCR
Realpath
Public-Key-Pins
Cache-Tag
X-Client-IP
Access-Control-Request-Method
X-Fastly-Request-ID
X-Ser
MS-Author-Via
Nginx-Cache
X-DynaTrace-JS-Agent
S
X-Shard
X-Edge-O15-RID
X-Upstream
SPIisLatency
SPRequestDuration
X-B3-TraceId-Primal
X-Id
Mrf-Cache-Status
X-Mrf-Item-Lastmod
MRF-Tech
X-Mrf-Section-Lastmod
X-Ezoic-Cdn
X-Content-Type
X-Hp-Webp
X-Amzn-Trace-Id
X-Grace
X-T
X-Amz-Meta-S3cmd-Attrs
Nel
Front-End-Https
X-Forwarded-For
X-Recruiting
Fastcgi-Cache
X-Hits
DynaTrace
X-Aspnet-Version
X-Varnish-Age
ServerID
X-Jurisdiction
X-Server-ID
X-Cache-TTL
X-Country-Code-Real
X-FTR-Expires
X-FTR-Cache-Status
X-Node-Name
MicrosoftSharePointTeamServices
X-DIS-Request-ID
X-Dw-Request-Base-Id
X-Element-Page-Cache
X-Content-Digest
X-Mobile-URL
NR-ENABLED
X-FTR-DC
X-FTR-Backend
X-FTR-Realm
X-FTR-Backend-Server
X-FTR-Balancer
X-HS-Cache-Config
X-HS-Combine-CSS
X-HS-Hub-Id
X-HS-Content-Id
Powered
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Storage-Class
X-Goog-Metageneration
X-Frontend
X-Goog-Generation
X-Goog-Stored-Content-Encoding
Server-Node
TP-Cache
TP-L2-Cache
Alternate-Protocol
Server-Name
X-Logged-In
X-Correlation-Id
X-XRDS-Location
X-Request-Received
X-CST
X-Request-Processing-Time
AMP-Access-Control-Allow-Source-Origin
X-Amz-Apigw-Id
Upgrade-Insecure-Requests
X-Microsite
X-Amzn-RequestId
X-Request-Handler-Origin-Region
Backend-Timing
X-ATS-Timestamp
X-Cache-Hit
X-Content-Options
X-Origin-Server
X-Page-Id
X-Content-Security-Policy-Report-Only
Refresh
X-Rid
X-F-Cache
X-User-Agent
X-Akamai-Edgescape
X-Varnish-Grace
X-Revision
X-Type
Fastly-Restarts
X-Zen-Fury
X-XRDS-LOCATION
X-Content-Powered-By
X-LB-Cache
X-B3-Sampled
X-B
X-Geo-Country
X-URL
X-FTR-Cache-Host
X-Az
X-AppVersion
X-Activity-Id
PB-RID
PB-PID
X-Mobile-Rewrite
Arc-Version
X-Shield-Request-Id
Cache-Status
X-N
X-Kinsta-Cache
X-Pad
X-Cache-Age
X-TT
X-Instance
X-Time
Access-Control-Allow-Method
X-AOL-HN
X-WebKit-CSP-Report-Only
X-B-Cache
X-Signature
X-Request-Guid
X-Framework
X-App-Environment
Paypal-Debug-Id
X-Jobs
X-Tumblr-Pixel
X-Debug-Info
X-Tumblr-User
X-Tumblr-Pixel-0
Actual-Object-TTL
X-Cache-Action
X-Load-Cache
X-PHP-Backend
X-FB-Debug
X-Webkit-Csp
DC
X-Webapp-Samesite-None-Activated-N
X-Cached-By
X-Git-Hash
Fastcgi-Useragent
X-Tt-Trace-Tag
X-Varnish-Backend
X-RateLimit-Remaining
X-Tt-Trace-Host
X-Analytics
X-Erf-Bev-Bev-Is-Generated
Host-Header
Surrogate-Key
X-Erf-Bev-Bev
X-Amz-Replication-Status
X-IPLB-Instance
X-Contextid
MS-CV
FilterID
X-ATG-Version
X-SS-Set-Cookie
Accept-CH
X-WA-Info
X-FastCGI-Cache
X-Cache-Key
Host
X-Cluster
Tracecode
X-Mobile
NGB
X-Accel-Buffering
X-Host-Name
X-Response-Served-From
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Via-JSL
X-ORACLE-APMCS-REQUEST-ID
X-ORACLE-APMCS-TAG
Payment
X-B3-Traceid
WPE-Backend
X-FW-Type
X-Cache-NE
X-FW-Serve
X-FW-Static
X-NWS-LOG-UUID
X-FW-Hash
X-FW-Server
X-Cache-2
Eomportal-Instance
Frame-Options
X-Varnish-Server
X-Hostname
X-Region
Xserver
X-Cacheable-TTL
Source
Cache-Tv-Group
X-Is-Bot
X-GeoIP
Filters
X-Srv
X-IPS-LoggedIn
X-Origin-Response-Time
X-Tumblr-Pixel-1
X-Cache-Enabled
X-Cache-Operation
X-Cache-Rule
X-Varnish-Hostname
X-Tumblr-Pixel-2
X-Rendered-As
X-Adobe-Content
X-Adobe-Loc
X-RequestSource
X-TX-ID
X-Seen-By
X-NewRelic-App-Data
Retry-After
X-EdgeConnect-Cache-Status
X-Presslabs-Stats
Accept-CH-Lifetime
Server-Info
Cleartype
X-Cache-TTL-Remaining
X-VCache
X-RemovedCookies
X-ProcessESI
Liferay-Portal
X-HTML-Minification-Powered-By
Cache
Ms-Operation-Id
X-RTag
X-App-Server
X-Source
Datacenter
X-UA
X-L-Path
X-Environment-Context
X-FireWall-Port
X-Dc
X-Endurance-Cache-Level
X-Cache-Server
X-Upgrade-Enabled
X-Handled-By
From-Origin
X-Cache-Control
Healthy
X-CACHE-KEY
X-Esi
X-APP-VERSION
X-PressLabs-Stats
X-Backend-Name
X-Wix-Request-Id
Version
X-ES-SERVER
Srv
X-Path-Route
Node
Meta-Geo
X-Status
X-Cache-Var
X-RN-RSRV
X-Cache-Var-Map
Ec-Rule-Version
OT-Force-Account-Verify
X-Timing-Wait
X-Request-Time
X-BCube-Filmed-By
X-Section
X-Format
X-Tb
X-Storage
X-Rule
X-Ruxit-Js-Agent
X-Proto
X-Proxy-Build
X-Access
X-Akamai-Request-ID
Selected-Fe
S-Rt
X-Shopify-Stage
X-Sorting-Hat-PodId
X-FC-Vary-Parameters
X-Shopify-Generated-Cart-Token
X-Content-Age
X-NYM-Debug-Backend
X-Loop
X-Sorting-Hat-ShopId
X-Cache-Config
X-Hosted-By
X-Origin
X-Goog-Meta-Goog-Reserved-File-Mtime
X-FW-Dynamic
X-Soup
X-EIG-Tracking-Id
X-Alternate-Cache-Key
X-TNCMS
Azure-SlotName
Azure-Version
Azure-SiteName
Azure-RegionName
Akamai-GRN
Azure-InstanceId
X-ShopId
Mn-Server-Ip
X-Time-Microsecs
X-Proxy-Cache-Status
X-OCL
X-Web-Node
X-ShardId
X-PCL
X-UUID
Cache-Tags
X-RateLimit-Limit
X-Hl-Ver
X-Generated-By
X-Debug-Cache
X-Human
X-Cluster-Node
NGX
X-MP-GENERATED-AT
X-LJ-Flow-ID
X-JoinUs
X-BYPASS-REASON
X-AWS-Id
Decoy-Debug-TTL
Origin-Edge-Control
Origin-Cache-Control
Now
Decoy-Debug-Status
Decoy-Debug-Key
X-Akamai-Request-ID2
Accept-Charset
DB-Nickname
X-Proxy
X-Hyper-Cache
X-Viewer-Country
X-Yottaa-Optimizations
X-Vgn-Hpd-Reason
X-VWS-Id
X-Say-Cacheable
X-SayCDN-TTL
X-Say-TTL
X-ServerID
X-Yottaa-Metrics
X-Pubstack
X-SaId
X-Redis-Cache
X-Qloud-Router
X-ProxyCache-Key
X-ProxyCache-Status
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-Country
Property-Id
X-Locale
X-Amzn-Remapped-Content-Length
TWC-GeoIP-LatLong
X-Www-Served-By
X-FB-TRIP-ID
X-IP
X-Varnish-Hits
X-Site-Version
X-Detected-As
X-Generated
X-Cache-Host
X-Origin-Hint
TWC-Privacy
Webcakes-App-Name
Webcakes-App-Version
Webcakes-Region
TWC-Locale-Group
X-CCM
Cross-Origin-Window-Policy
X-Xfnlog-Site
GEO-INFO
X-RCS-CacheZone
X-Akamai-Transformed
X-R9-Blue-Green-Version
X-Ttl
X-NCache
X-Unique-Id
L5d-Success-Class
Time
X-CS
Uber-Trace-Id
X-Drupal-Cache-Tags
Cache-Name
Webserver
Viewport
Cache-Key
X-UA-Device-Type
X-Backend-TTL
X-UnsetCookies
Rt-Fastcgi-Cache
X-Cache-Remote
X-CDN-Forward
X-Mode
Accept-Language
X-Forwarded-Host
X-Origin-TTL
X-Origin-CC
X-From
X-Whom
X-NGENIX-Cache
X-Drupal-Cache-Contexts
X-Trafficlayer-App-Scope
Country
X-Info
X-Trafficlayer-App-Name
Mime-Version
X-Daa-Tunnel
VIX-Pulpo-Node
Odigeo-Trace-Id
X-Newrelic-Synthetics
X-B3-Spanid
VIX-Pulpo-Upstream-Status
X-Cluster-Name
Content-Disposition
X-Varnish-Cache-Hits
X-TT-TIMESTAMP
X-Microcachable
X-PERF
X-ApacheServer
X-Magnolia-Registration
X-CLOUD-TRACE-CONTEXT
ServedBy
X-Edge-Location
X-Geo
Proxy-Connection
X-Device-Type
X-Zipkin-Id
X-Routing-Service
X-Proxied
Ohc-File-Size
Cf-Ipcountry
X-UPSTREAM-Address
X-EC-Lua
X-Via-Fastly
Section-Io-Cache
Ohc-Cache-HIT
X-Uri
X-No-Session
HitType
BehaviorPad-Version
Content-Script-Type
Apple-News-Services-Parsed-Url
X-VG-WebServer
Apple-News-Services-Handled
X-Vtex-Remote-Cache
Apple-News-Services-Host
Apple-News-Services-Request-Url
X-Vtex-Processado-Em
AsisCache
Xc-Version
T-Server
X-Rojux
X-S
X-ARC
X-B-Cookie
X-CF-Lambda-Fn
X-Application
X-Aed
X-Session-Fingerprint
X-ScT
X-A-Wwc
X-S-Cookie
X-Rocket-Build-Number
X-Rewrite-Enabled
X-G
X-Geo-Header
X-Date
X-External-Request-Id
X-Destination
X-D
X-Connection-Hash
X-Request-UUID
X-Region-Sid
X-GeoIP-Country-Code
X-CF-Lambda-Version
X-A-Dgt
X-A-Dcw
Mobile-Detection-Method
X-VG-TLSProxy
Rendered-Blocks
X-DPWN-IS-SECURE
X-Vdms-Version
Meta-Geo-Continent
MD5-Digest
Fastcgi-X-Cache-Version
X-VG-WebCache
GEO-REGION-INFO
Machine
X-Twitter-Response-Tags
Viewtype
X-Sigma-Backend
X-Sigma
X-A-Ccd
X-A-Dam
X-A
W
X-Trv-Group
X-Transaction
X-SRCache-Key
VivaBuild
Content-Style-Type
X-Accel-Expires-Debug
Geo-Info
X-Labrador-Cache-Channel
X-PHP-Host
X-C
User-Cache-Control
X-GoCache-CacheStatus
X-Nc
Access-Control-Request-Headers
X-Distil-CS
Environment
X-Varnish-Beresp-Ttl
Fastly-SSL
Fastly-Soc-X-Request-Id
X-Developers
X-CUA
X-TH-Server
X-SIPLIST1
X-Thanos
Server-Surrogate-Control
CDCHOST
X-Real-IP
Gh-Request-Id
X-Li-Pop
X-LI-Proto
Locid
X-Li-Fabric
Memcached
Powered-By
X-Hit
X-FW-Version
X-LI-UUID
X-Logging-Id
HA-Ipaddr
Ha-Gx-Prefs
X-TrackingId
X-Eu-Site
IBM-Web2-Location
Server-Cache-Control
IsBot
X-App-Name
X-Contensis-Viewer-Groups
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Agile-Id
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-We-Are-Hiring
X-WebServer
Countrycode
X-Agile-Age
X-Cache-ASPX
X-Clientip
X-Cache-Debug
Fastly-SWR
X-Agile
Fastly-SIE
X-Bip
X-Backend-State
X-VC-Cache
X-Varnish-Authentication
X-Auto-Login
X-VServer
X-CGP
X-Tumblr-Pixel-3
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-User
X-Cache-Backend
X-Gamma-Serve
X-Azure-Ref
X-Fastly-Cache
X-BBXSRF
X-Gen-Mode
X-Generation-Time
X-Fetched-On
X-Generated-In
X-Distributor
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
X-Cache-URL
X-Core-Mission
X-GeoIP-City
X-Cms-Context
X-Cdn-Srv
X-Debug-Cache-Store
X-Debug-Cookies
X-Clara-WADP
X-Epic-Correlation-Id
X-Cache-Bucket
X-Cache-Info
X-Cache-Time
X-Debug-Log
X-Dispatcher-Server
X-Block-Status
X-Nginx-Cache-Key
X-WADP-Cache
X-Webstats-RespID
Adler-Geo
Is-Eu
X-Urbn-Site-Id
X-Urbn-Context-Path
X-SVT-ORM-VERSION
X-Swa-Ws
X-Trace-Id
X-TT-LOGID
Platform
X-Cache-Tags
X-Platform-Server
X-Servername
X-Up
X-Variation
X-NU-AKA-ACS-Version
X-JWT-State
X-Has-Esi
X-Internal-Host
X-Is-Gdpr
X-SVT-ORM-RULES
X-Server-W
X-Micro-Cache
X-Ms-Request-Id
X-Ms-Version
X-NodeID
X-Key
X-Irp-Debug
X-Hnp-Log
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Instart-Isnd
X-NX-Host
X-Origin-Date
X-RateLimit-Remaining-Second
X-Reboot
X-Render-Time
X-Request-URI
X-RateLimit-Limit-Second
X-Proxy-Upstream
X-OVcl
X-OVcl-Cache
X-Owner
X-Hash
X-Origin-Expires
Server-ID
Cdncip
Cdnsip
Server-Int
Mail-Subject
We-Hiring
V-Age
Cache-Host
RNT-Time
RNT-Machine
Heartbleed
Kp-EeAlive
Locale
Fastly-Backend-Name
Country-Code
Request-EU
Request-Country
Web-Mar-Node
True-Client-Country-4JS
AKAMAI
X-AK-Request-ID
Wxu-Next-Hostname
Server-Host
Thinkindot-CacheControl
Thinkindot-Control
ServerName
Thinkindot-CacheControl-Type
FNAC-ModuleRouting
X-Matched-Rule
X-Level-Front-Cache
X-Old-Content-Length
PFcat
X-Service
X-Generated-On
X-Req
Wxu-Next-Commit
Wxu-Next-Region
X-Core-Value
X-Sucuri-Cache
X-Trafficlayer-App-Version
X-Thinkindot-L3
X-ServiceProvider
X-Nginx-Cache
X-TA-CDN-Provider
X-App-Version
X-Air-Hostname
X-Location
X-SERVER
Cache-Hits
X-Response-By
X-S-Maxage
Pragrma
X-Var-Ttl
X-Lb-Id
Group
X-Cache-Expired-At
X-Refresh
RequestId
S-Cnection
X-Parent-Response-Time
Memory
X-Tb-Optimization-Total-Bytes-Saved
X-CSRF-TOKEN
Filterid
X-B3-Parentspanid
X-NC
Powered-By-ChinaCache
ProcessTime
X-Tec-Api-Root
X-Tec-Api-Version
X-Tec-Api-Origin
X-CF-Powered-By
X-Wa
X-Cdn-Forward
X-Ua
Origin
X-Pf-Uncompressing
User-Agent
X-Server-IP
X-Pjax-Url
X-B3-SpanId
X-BACKEND-TTL
X-CSRF-Token
X-Sucuri-ID
X-Varnish-Cacheable
Geoip-Latitude
X-Correlation-ID
X-NWS-UUID-VERIFY
SRV
X-Via-CDN
TTL
PICS-Label
GeoIp-Country-Code
Geoip-City
X-Cdn-Request-ID
X-Vcl-Version
X-COUNTRY
X-NGINX-Cache
X-Developer
X-FORWARDED-FOR
Media-Length
X-Unique-ID
X-Node-Id
X-Device-Os
X-Sn-Servicetimems
X-LAGOON
X-Ocache
X-Servedbyhost
X-Cache-Grace
X-Cdn-Origin
Dnion-Transfer-Encoding
X-Sucuri-Id
On-Server
X-Litespeed-Cache
X-Webkit-CSP
X-Rocket-Nginx-Bypass
X-Via-Ucdn
X-Cache-Status-Check
X-MSEdge-Features
X-MSEdge-Flight
A
X-Request-Host
SN
X-Varnish-Ttl
Hostname
X-Oss-Storage-Class
X-Oneagent-Js-Injection
XServer
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
X-Oss-Server-Time
X-TIME
X-Oss-Object-Type
X-AIR-PT
Esi-Enabled
X-Reqid
M-TraceId
X-HS-Status
X-Beluga-Trace
X-Beluga-Status
X-Beluga-Response-Time
X-Beluga-Record
Cloudfront-Viewer-Country
X-Policy
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Beluga-Node
X-Beluga-Cache-Status
X-Ratelimit-Remaining
Cdn
X-ServedByHost
X-Azure-Ref-OriginShield
X-Cache-Ttl
Who
X-Request-Start
Resin-Trace
X-Fastly-Country-Code
X-VHOST
HostName
X-Ftr-Cache-Host
X-Varnish-URL
Host-ID
CF-Cached-On
Tcn
Rt-Proxy-Cache
GeoIP-Country-Code
MIME-Version
X-VCL-Version
NtCoent-Length
X-DC
X-APP
GeoIP-Latitude
Ttl
Magicmarker
X-Method
Pics-Label
X-Slack-Backend
Cteonnt-Length
X-Oracle-Dms-Rid
X-Fastly-Backend-Reqs
GeoIP-City
X-DW
X-RPS
X-RPM
X-RSL
X-DSS
X-Varnish-Url
X-DB
X-DI
X-Action
X-LiteSpeed-Cache-Control
X-PAYTM-SRV-ID
X-FPC
X-Server-Time
X-Processor
X-Cache-FS-Status
Arc-Country
X-PJAX-URL
Pramga
X-Newrelic-App-Data
X-Zone
X-Dispatch
X-VarnishDD-TTL
X-PF-Uncompressing
X-Ratelimit-Limit
CACHE
X-Bc
X-Skip-Cache
X-SERVER-NAME
Load-Balancing
Ohc-Response-Time
X-Svr
Amp-Access-Control-Allow-Source-Origin
WebServer
X-Hello
X-Swift-Error
X-ABtesting
X-Ftr-Request-Id
X-ND-Cache
X-SRV
X-Flog
X-Be
X-BE
X-Dynatrace
X-Edge-Server
Cdn-Request-Time
Cdn-Host
X-DevSite-Last-Modified
Fastly-Drupal-HTML
N-Cache
X-HostName
X-Served-From
Vix-Hermes-Req-Id
Processtime
X-MServer
DSUID
Servername
X-Dynatrace-Js-Agent
X-ID
X-ZONE
X-Amzn-Remapped-Connection
CDN
X-WA
X-Aicache-OS
Cache-Provider
X-Amzn-Remapped-Date
Release
X-Bc-Bl
X-LB-ID
X-VCT
X-Frame-Option
X-Hp-Ccpa-Warning
X-WR-MODIFICATION
X-Backend-Host
X-StackifyID
Requestid
Lfy
X-Tid
X-Ftr-Backend-Server
Dynatrace
X-Snapshot-Date
X-Configured-By
X-Ftr-Backend
X-BC
X-Branch-Name
CF-IPCountry
X-Ftr-Balancer
X-Ftr-Realm
X-Ftr-Dc
X-Fastly-Cache-Hits
Pagetype
X-CACHE-AGE
Section-Origin-Responded
Section-Io-Id
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
X-Apw-Access-Object
WZWS-RAY
V-Cache
Proxy-Firewall
X-Upstream-Ht
X-Upstream-Ct
X-Apw-Access-Token
X-Apw-Access-Action
X-VC
Warning
D-Cc-Upstream
X-Apw-Hits
X-Request-Url
SD-X-WS
X-Edge-IP
X-SD-PageType
X-Cc-Req-Id
X-SB
X-Cc-Via
X-Litespeed-Cache-Control
X-Varnish-Beresp-TTL
WP-Super-Cache
X-Cache-Id
X-ElasticPress-Search
CloudFront-Viewer-Country
FSS-Proxy
FSS-Cache
Cneonction
L
X-WPE-Loopback-Upstream-Addr
X-Powered-Y
X-Fastly-Cache-Status
Lb
X-Check-Cacheable
X-Worker
Backend-Name
X-ServerName
X-Compress-Hint
X-Request-URL
X-App
Correlation-Id
X-SN