Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-Powered-By
Pragma
CF-Cache-Status
X-XSS-Protection
Link
ETag
CF-RAY
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Request-ID
X-Xss-Protection
X-Permitted-Cross-Domain-Policies
X-Cacheable
CF-Ray
X-DNS-Prefetch-Control
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
Status
Upgrade
X-Content-Security-Policy
Content-Encoding
X-CDN
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
X-Pass-Why
X-Cache-Group
X-AH-Environment
X-Envoy-Upstream-Service-Time
Xkey
X-Via
X-Backend
X-Server
X-Age
X-Ws-Request-Id
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Server-Powered-By
X-Page-Speed
X-Pingback
EagleId
X-Proxy-Cache
X-Hacker
X-Nginx-Cache-Status
X-UA-Device
Request-Context
Feature-Policy
Server-Timing
X-Varnish-Cache
Cf-Railgun
X-Swift-SaveTime
X-Swift-CacheTime
Grace
Ali-Swift-Global-Savetime
X-Amz-Version-Id
X-Ua-Compatible
Report-To
X-LiteSpeed-Cache
X-Rq
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
X-WebKit-CSP
X-Device
X-Host
X-Origin-Cache
X-Response-Time
EagleEye-TraceId
X-Node
X-Ac
Content-Location
Surrogate-Control
X-Server-Id
X-Cloud-Trace-Context
X-Backend-Server
X-Readtime
X-Vhost
Request-Id
X-Dispatcher
X-Dns-Prefetch-Control
X-Origin-Upstream-Status
X-Cache-Lookup
X-Cnection
X-Ruxit-JS-Agent
X-Application-Context
X-HW
Fusion-Template-Id
Fusion-Source
Fusion-Component-Id
Fusion-Content-Source
Fusion-Content-Id
X-ORACLE-DMS-ECID
X-Mod-Pagespeed
NEL
X-ORACLE-DMS-RID
X-DataDome
P3p
X-Rack-Cache
X-Clacks-Overhead
Edge-Control
Rating
X-Akam-SW-Version
X-Country
Pinterest-Generated-By
Allow
X-TTL
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Country-Code
X-FTR-Request-ID
X-Instart-Request-ID
X-DynaTrace
X-Varnish-TTL
Accept-Ch
X-TtlSet
X-PC
X-Goog-Hash
X-Vname
Verso
Content-MD5
Service-Worker-Allowed
X-ESI
X-Powered-By-Plesk
X-Server-ID
Accept-Ch-Lifetime
X-B3-TraceId
X-Kinja
X-Cdn-Fetch
X-Version
X-Exp-Variant
X-GoogleNews-Bot
X-Exp-Id
X-Kinja-Build
X-Use-Magma
X-Kinja-Server
X-Kinja-Revision
X-Forwarded-Proto
X-Vcache
X-MS-InvokeApp
X-GitHub-Request-Id
RTSS
X-Url
X-Server-Name
Edge-Cache-Tag
X-D2id
X-Abt-Application-Version
X-Debug
X-Px
X-Amz-Server-Side-Encryption
AR-ATIME
AR-Request-ID
AR-PoweredBy
AR-CACHE
Ar-Sid
SPRequestGuid
X-Cached
Charset
X-NF-Request-ID
Response
X-Middleton-Display
X-Sol
X-Middleton-Response
Display
Pagespeed
X-Navigation-Version
X-MSEdge-Ref
X-TEC-API-ORIGIN
X-Vcap-Request-Id
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Amz-Rid
X-Accel-Expires
Arr-Disable-Session-Affinity
TCN
X-Pinterest-Rid
Pinterest-Version
X-SharePointHealthScore
X-Cdn
X-Powered-CMS
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-VARITI-CCR
Public-Key-Pins
X-Fastly-Request-ID
Nginx-Cache
X-Edge-O15-RID
X-Fastcgi-Cache
MS-Author-Via
Realpath
X-Client-IP
Cache-Tag
X-Trace
X-Ser
Access-Control-Request-Method
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Mrf-Section-Lastmod
MRF-Tech
X-Shard
X-Mrf-Item-Lastmod
X-Content-Type
X-DynaTrace-JS-Agent
SPRequestDuration
SPIisLatency
X-Amzn-Trace-Id
X-Ezoic-Cdn
X-Hp-Webp
X-Jurisdiction
X-Id
X-Upstream
X-Grace
S
Front-End-Https
Nel
X-T
X-Hits
X-Amz-Meta-S3cmd-Attrs
Fastcgi-Cache
X-Cache-TTL
X-Forwarded-For
X-Aspnet-Version
X-Recruiting
DynaTrace
X-Node-Name
X-Varnish-Age
X-Content-Digest
X-Mobile-URL
X-Element-Page-Cache
X-FTR-Backend
X-Dw-Request-Base-Id
X-Country-Code-Real
X-FTR-Expires
X-FTR-DC
X-FTR-Cache-Status
X-FTR-Realm
X-FTR-Balancer
X-FTR-Backend-Server
MicrosoftSharePointTeamServices
ServerID
X-DIS-Request-ID
NR-ENABLED
Server-Node
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Combine-CSS
X-HS-Content-Id
X-Frontend
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
TP-L2-Cache
X-CST
Powered
X-Logged-In
X-GUploader-UploadID
X-Goog-Generation
X-Goog-Metageneration
TP-Cache
Alternate-Protocol
Server-Name
X-Correlation-Id
X-Amzn-RequestId
X-Amz-Apigw-Id
Upgrade-Insecure-Requests
X-XRDS-Location
Fastly-Restarts
X-Microsite
X-Request-Handler-Origin-Region
X-FTR-Cache-Host
X-Cache-Hit
Backend-Timing
X-ATS-Timestamp
X-Request-Received
X-Request-Processing-Time
X-URL
AMP-Access-Control-Allow-Source-Origin
X-User-Agent
X-Zen-Fury
Refresh
X-Content-Options
X-Page-Id
X-Origin-Server
X-Akamai-Edgescape
X-Content-Security-Policy-Report-Only
X-F-Cache
X-Varnish-Grace
X-Rid
X-Revision
X-Type
X-Content-Powered-By
X-B
X-XRDS-LOCATION
PB-RID
PB-PID
X-LB-Cache
Arc-Version
X-Mobile-Rewrite
X-B3-Sampled
X-Geo-Country
X-Az
X-Activity-Id
X-AppVersion
Cache-Status
X-N
X-Kinsta-Cache
X-Cache-Age
X-Cache-Action
X-TT
X-Request-Guid
X-AOL-HN
X-Signature
X-Framework
X-Debug-Info
X-Instance
X-B-Cache
X-Load-Cache
Paypal-Debug-Id
X-WebKit-CSP-Report-Only
Access-Control-Allow-Method
X-Git-Hash
X-Cached-By
X-Tumblr-Pixel-0
X-App-Environment
X-PHP-Backend
X-Tumblr-User
X-Jobs
X-Tumblr-Pixel
Actual-Object-TTL
X-FB-Debug
Fastcgi-Useragent
X-Pad
X-NWS-LOG-UUID
DC
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Amz-Replication-Status
X-Time
X-Webkit-Csp
X-Shield-Request-Id
X-FastCGI-Cache
X-Varnish-Backend
Host-Header
X-RateLimit-Remaining
X-WA-Info
X-Contextid
X-IPLB-Instance
X-ATG-Version
Surrogate-Key
MS-CV
Host
X-Erf-Bev-Bev
X-Via-JSL
X-Erf-Bev-Bev-Is-Generated
X-ORACLE-APMCS-TAG
X-ORACLE-APMCS-REQUEST-ID
Accept-CH
X-Mobile
X-Cache-Key
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Host-Name
X-Response-Served-From
X-Accel-Buffering
NGB
X-Presslabs-Stats
X-SS-Set-Cookie
Tracecode
Payment
Retry-After
X-Cache-2
Source
Frame-Options
X-Origin-Response-Time
X-FW-Hash
X-Hostname
X-FW-Serve
X-FW-Server
Filters
X-FW-Static
X-FW-Type
X-Cache-NE
X-Region
WPE-Backend
Eomportal-Instance
X-Seen-By
Cache-Tv-Group
X-Varnish-Server
X-GeoIP
X-Cacheable-TTL
X-Cache-Enabled
X-Rendered-As
X-Is-Bot
X-Cache-Operation
X-IPS-LoggedIn
X-Cache-Rule
X-RequestSource
X-Cluster
X-Varnish-Hostname
X-Adobe-Content
X-Adobe-Loc
Server-Info
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
Liferay-Portal
X-Analytics
FilterID
Xserver
X-NewRelic-App-Data
X-RemovedCookies
X-TX-ID
X-ProcessESI
Accept-CH-Lifetime
X-EdgeConnect-Cache-Status
X-Srv
X-Webapp-Samesite-None-Activated-N
X-App-Server
X-Cache-TTL-Remaining
X-B3-Traceid
Cleartype
X-L-Path
X-Environment-Context
X-FireWall-Port
X-RTag
X-Handled-By
X-Dc
X-Endurance-Cache-Level
Ms-Operation-Id
X-Source
X-UA
X-Upgrade-Enabled
X-HTML-Minification-Powered-By
From-Origin
X-Cache-Server
X-CACHE-KEY
Srv
X-APP-VERSION
X-Backend-Name
Accept-Charset
Datacenter
X-UUID
GEO-INFO
X-Cache-Var
X-Cache-Var-Map
X-RN-RSRV
X-Esi
X-Path-Route
X-ES-SERVER
Meta-Geo
X-Section
X-Tb
X-Wix-Request-Id
X-Format
X-Access
Cache-Tags
Mn-Server-Ip
X-Akamai-Request-ID
X-Request-Time
OT-Force-Account-Verify
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Alternate-Cache-Key
X-Sorting-Hat-PodId
X-Shopify-Stage
X-NYM-Debug-Backend
X-Sorting-Hat-ShopId
X-Soup
X-Shopify-Generated-Cart-Token
X-Origin
X-Proto
X-SaId
X-ShardId
X-ShopId
X-LJ-Flow-ID
X-VWS-Id
X-PCL
X-Akamai-Request-ID2
NGX
Ec-Rule-Version
Akamai-GRN
X-AWS-Id
X-Cache-Config
X-OCL
X-JoinUs
X-EIG-Tracking-Id
X-Content-Age
X-Akamai-Transformed
Node
X-Pubstack
X-ProxyCache-Status
X-Proxy-Cache-Status
DB-Nickname
X-Qloud-Router
X-Status
X-Viewer-Country
X-Timing-Wait
X-Time-Microsecs
X-Storage
Decoy-Debug-Key
Decoy-Debug-Status
X-FW-Dynamic
X-FB-TRIP-ID
X-CCM
X-Cluster-Node
X-BYPASS-REASON
Selected-Fe
Decoy-Debug-TTL
X-Proxy-Build
X-MP-GENERATED-AT
X-Locale
X-Www-Served-By
X-ProxyCache-Key
X-Say-Cacheable
X-FC-Vary-Parameters
X-Human
X-Say-TTL
X-Web-Node
X-Debug-Cache
X-SayCDN-TTL
X-Redis-Cache
X-IP
X-Site-Version
Healthy
Webcakes-App-Name
Webcakes-App-Version
X-Proxy
X-Loop
Property-Id
TWC-Device-Class
S-Rt
TWC-GeoIP-Country
Now
Webcakes-Region
X-Origin-Hint
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-Privacy
Azure-SiteName
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Amzn-Remapped-Content-Length
X-Generated-By
X-BCube-Filmed-By
X-TNCMS
Origin-Edge-Control
X-Detected-As
Origin-Cache-Control
X-Hyper-Cache
X-Hosted-By
TWC-Connection-Speed
Azure-SlotName
Azure-Version
Azure-RegionName
Azure-InstanceId
X-RCS-CacheZone
X-R9-Blue-Green-Version
X-Xfnlog-Site
X-Hl-Ver
X-PressLabs-Stats
X-Cache-Control
X-Varnish-Hits
X-Vgn-Hpd-Reason
X-NCache
X-ServerID
Cross-Origin-Window-Policy
Version
X-RateLimit-Limit
Cache
X-Generated
X-Unique-Id
X-VCache
Cache-Key
X-Cache-Host
X-Daa-Tunnel
X-Whom
X-Drupal-Cache-Tags
X-NGENIX-Cache
X-UA-Device-Type
X-Mode
X-Forwarded-Host
X-Rule
Cache-Name
X-VHOST
L5d-Success-Class
Time
Webserver
X-UnsetCookies
X-Backend-TTL
X-Info
Section-Io-Cache
Content-Disposition
X-CS
Uber-Trace-Id
Viewport
X-B3-Spanid
X-CDN-Forward
X-Origin-TTL
Accept-Language
X-Origin-CC
X-ApacheServer
X-PERF
X-Varnish-Cache-Hits
Mime-Version
ServedBy
Country
Rt-Fastcgi-Cache
X-Newrelic-Synthetics
Odigeo-Trace-Id
X-Cache-Remote
X-EC-Lua
X-Zipkin-Id
X-From
X-CLOUD-TRACE-CONTEXT
X-Proxied
X-Routing-Service
X-Via-Fastly
X-Device-Type
X-Cluster-Name
X-Magnolia-Registration
X-Drupal-Cache-Contexts
X-Ttl
Proxy-Connection
X-Microcachable
X-Uri
Filterid
X-TT-TIMESTAMP
HitType
Access-Control-Request-Headers
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Geo
X-Nc
X-Real-IP
Cf-Ipcountry
Ohc-File-Size
X-Trv-Group
X-Transaction
AsisCache
BehaviorPad-Version
Apple-News-Services-Handled
X-SRCache-Key
X-VG-WebServer
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
Apple-News-Services-Host
X-VG-WebCache
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
X-Vdms-Version
X-VG-TLSProxy
X-Twitter-Response-Tags
X-Region-Sid
W
X-A
X-A-Ccd
X-Connection-Hash
VivaBuild
X-D
X-Date
T-Server
Viewtype
X-CF-Lambda-Version
X-A-Dcw
X-A-Dgt
X-Accel-Expires-Debug
X-A-Wwc
X-Aed
X-Application
X-CF-Lambda-Fn
X-B-Cookie
X-ARC
X-Destination
X-DPWN-IS-SECURE
Content-Script-Type
X-Request-UUID
Content-Style-Type
Fastcgi-X-Cache-Version
X-Rewrite-Enabled
X-Rojux
X-ScT
X-S-Cookie
X-S
GEO-REGION-INFO
X-GeoIP-Country-Code
Rendered-Blocks
X-G
X-External-Request-Id
Mobile-Detection-Method
Meta-Geo-Continent
Machine
X-Geo-Header
MD5-Digest
X-Session-Fingerprint
X-A-Dam
X-Litespeed-Cache
X-C
Geo-Info
Fastly-Soc-X-Request-Id
Fastly-SWR
X-Sigma-Backend
IsBot
X-Sigma
Fastly-SIE
CDCHOST
X-Cache-Time
X-Labrador-Cache-Channel
X-PHP-Host
Locid
X-SIPLIST1
X-Rebelmouse-Surrogate-Control
X-Backend-State
X-App-Name
X-Cache-Expired-At
X-CUA
X-Developers
X-Agile-Id
X-Agile-Age
X-Varnish-Beresp-Grace
X-Rebelmouse-Cache-Control
X-Logging-Id
X-Agile
X-Rocket-Build-Number
Powered-By
X-Varnish-Beresp-Ttl
X-Var-Ttl
X-Varnish-Beresp-Status
X-VC-Cache
Group
X-GoCache-CacheStatus
Fastly-SSL
User-Cache-Control
X-No-Session
We-Hiring
Server-Int
X-NodeID
X-OVcl-Cache
Server-Cache-Control
X-OVcl
True-Client-Country-4JS
RNT-Machine
X-RateLimit-Remaining-Second
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-Request-URI
Platform
Pragrma
X-Nginx-Cache-Key
Request-EU
Request-Country
X-RateLimit-Limit-Second
RNT-Time
X-LI-UUID
X-Clientip
X-CGP
Ohc-Cache-HIT
X-Hit
X-Cms-Context
X-Contensis-Viewer-Groups
X-Eu-Site
X-Distil-CS
X-Dispatcher-Server
X-Has-Esi
X-Cdn-Srv
X-Cache-Debug
X-Li-Pop
X-LI-Proto
Mail-Subject
X-Ms-Request-Id
X-Li-Fabric
X-JWT-State
X-Cache-ASPX
X-Bip
X-Instart-Isnd
X-Is-Gdpr
X-Ms-Version
Server-Surrogate-Control
Fastly-Backend-Name
X-Tumblr-Pixel-3
X-SVT-ORM-RULES
AKAMAI
X-Up
X-Varnish-Authentication
X-WebServer
Environment
X-SVT-ORM-VERSION
Cache-Host
X-Thanos
X-VServer
Cache-Hits
X-Trace-Id
X-Swa-Ws
Countrycode
Ha-Gx-Prefs
Adler-Geo
Is-Eu
Heartbleed
Locale
IBM-Web2-Location
HA-Ipaddr
Kp-EeAlive
X-Servername
X-Variation
X-Urbn-Context-Path
X-Urbn-Site-Id
X-UPSTREAM-Address
X-Edge-Location
X-TA-CDN-Provider
X-Distributor
X-NU-AKA-ACS-Version
X-Trafficlayer-App-Name
X-IN-APIGATEWAY
X-Fetched-On
X-Azure-Ref
X-Auto-Login
X-Epic-Correlation-Id
X-Hnp-Log
X-IN-APIGATEWAYSSL
X-BBXSRF
X-FW-Version
X-Cache-URL
X-Debug-Log
X-Core-Value
X-Core-Mission
X-TrackingId
X-GeoIP-City
X-Generated-In
X-Generated-On
X-Generation-Time
X-Hash
Cdncip
X-Trafficlayer-App-Scope
X-Debug-Cookies
X-Cache-Tags
X-Trafficlayer-App-Version
X-TT-LOGID
X-Gamma-Serve
X-Clara-WADP
X-Cache-Info
X-Air-Hostname
X-We-Are-Hiring
Server-ID
Server-Host
FNAC-ModuleRouting
Thinkindot-CacheControl
X-Server-W
Thinkindot-Control
Thinkindot-CacheControl-Type
X-ServiceProvider
X-Owner
Memcached
X-Reboot
X-Webstats-RespID
X-Fastly-Cache
X-Proxy-Upstream
X-Service
Gh-Request-Id
X-Platform-Server
V-Age
X-Origin-Expires
X-AK-Request-ID
Country-Code
X-Block-Status
X-TH-Server
X-Gen-Mode
Cdnsip
X-Level-Front-Cache
X-Thinkindot-L3
ServerName
Web-Mar-Node
X-WADP-Cache
X-NX-Host
X-Origin-Date
Wxu-Next-Commit
Wxu-Next-Hostname
X-Matched-Rule
X-Micro-Cache
Wxu-Next-Region
X-Req
S-Cnection
X-Irp-Debug
X-Response-By
X-Cache-Bucket
X-Render-Time
X-Old-Content-Length
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-Debug-Cache-Store
PFcat
X-Nginx-Cache
X-SERVER
X-COUNTRY
X-App-Version
X-Cache-Backend
X-Lb-Id
X-User
X-Wa
X-S-Maxage
X-Refresh
X-Key
X-Varnish-Cacheable
X-Internal-Host
Powered-By-ChinaCache
X-CSRF-TOKEN
RequestId
X-Sucuri-ID
X-Parent-Response-Time
Origin
X-Sucuri-Cache
X-NC
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
X-Oss-Storage-Class
X-Tb-Optimization-Total-Bytes-Saved
X-Oss-Server-Time
X-Developer
X-Location
X-CF-Powered-By
X-Node-Id
X-Pjax-Url
X-Pf-Uncompressing
X-Device-Os
X-Cache-Grace
X-Cdn-Origin
X-Sn-Servicetimems
X-LAGOON
User-Agent
X-Cache-Status-Check
X-CSRF-Token
X-Ua
X-Ocache
X-Via-CDN
Memory
X-Cdn-Forward
ProcessTime
X-BACKEND-TTL
Geoip-Latitude
Hostname
Geoip-City
X-B3-Parentspanid
SRV
On-Server
A
GeoIp-Country-Code
PICS-Label
X-NWS-UUID-VERIFY
X-Ruxit-Js-Agent
TTL
X-MSEdge-Flight
X-MSEdge-Features
X-NGINX-Cache
Cloudfront-Viewer-Country
X-Correlation-ID
X-Server-IP
X-Vcl-Version
X-FORWARDED-FOR
X-Request-Host
XServer
X-Unique-ID
X-TIME
X-Servedbyhost
X-Webkit-CSP
X-Oneagent-Js-Injection
X-Varnish-URL
X-Varnish-Ttl
X-B3-SpanId
SN
X-HS-Status
Resin-Trace
X-Cdn-Request-ID
M-TraceId
Media-Length
X-Rocket-Nginx-Bypass
Dnion-Transfer-Encoding
Tcn
Host-ID
Cdn
CACHE
X-Ratelimit-Remaining
X-Cache-Ttl
X-Beluga-Trace
X-Via-Ucdn
X-Beluga-Status
X-ServedByHost
Who
X-Beluga-Response-Time
X-Beluga-Cache-Status
X-Beluga-Record
X-Beluga-Node
HostName
Pramga
X-Dispatch
X-Cache-FS-Status
X-Processor
X-Fastly-Country-Code
X-Server-Time
X-PAYTM-SRV-ID
X-Action
X-DW
X-DSS
X-DI
X-DB
Arc-Country
X-RPM
X-RSL
X-RPS
X-Slack-Backend
X-ND-Cache
X-Reqid
X-AIR-PT
X-VCL-Version
X-Skip-Cache
MIME-Version
X-Sucuri-Id
Esi-Enabled
X-Planisys-CDN-Cache
X-Flog
Cdn-Host
X-Planisys-CDN-TTL
Ttl
X-Served-From
Cdn-Request-Time
Amp-Access-Control-Allow-Source-Origin
GeoIP-Country-Code
X-Policy
Pics-Label
X-Hello
X-ABtesting
X-Edge-Server
X-Planisys-CDN-Rules
Section-Io-Id
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
X-Oracle-Dms-Rid
CF-Cached-On
X-LiteSpeed-Cache-Control
GeoIP-Latitude
X-SRV
X-Bc-Bl
X-Azure-Ref-OriginShield
X-Varnish-Url
N-Cache
Fastly-Drupal-HTML
X-Request-Start
NtCoent-Length
GeoIP-City
X-DevSite-Last-Modified
X-DC
X-VarnishDD-TTL
X-PF-Uncompressing
X-Newrelic-App-Data
X-APP
X-FPC
X-PJAX-URL
Rt-Proxy-Cache
X-Ratelimit-Limit
X-HostName
Fusion-Deployment-Id
Trailer
WebServer
X-Adobe-Source
X-Zone
X-Fastly-Backend-Reqs
X-Backend-Host
X-Bc
X-Swift-Error
Cteonnt-Length
X-Amzn-Remapped-Date
X-BE
X-ZONE
X-BC
X-Method
X-Amzn-Remapped-Connection
Processtime
Magicmarker
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-From
X-Dynatrace
Servername
X-Dynatrace-Js-Agent
Cache-Provider
X-Fmm-Version
FSS-Proxy
X-WA
CDN
X-Scheme
FSS-Cache
X-ID
X-Frame-Option
X-WR-MODIFICATION
X-LB-ID
X-Snapshot-Date
X-Branch-Name
Ohc-Response-Time
X-StackifyID
Requestid
X-Fpc
Dynatrace
CF-IPCountry
X-CACHE-AGE
X-App
X-Apw-Access-Object
X-Apw-Access-Action
WZWS-RAY
X-Cache-Id
X-Compress-Hint
X-Esi-Check
L
X-Be
X-Tid
X-Apw-Hits
X-VC
X-Apw-Access-Token
X-SB
X-Fastly-Cache-Hits
X-Request-Url
X-Cc-Via
X-Cc-Req-Id
Warning
D-Cc-Upstream
X-Aicache-OS
V-Cache
X-Svr
X-Litespeed-Cache-Control
X-Node-ID
X-Check-Cacheable
Lfy
X-Request-URL
X-GEO
SD-X-WS
X-Gzip
X-SD-PageType
X-Cache-NGX
SID
Sid
X-SN
X-Powered-Y
WP-Super-Cache
X-WPE-Loopback-Upstream-Addr
X-Varnish-Beresp-TTL
X-Worker
X-ElasticPress-Search
Cneonction
X-Fastly-Cache-Status
Correlation-Id
Backend-Name
Vix-Hermes-Req-Id
Lb