Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
CF-RAY
Link
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Request-ID
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-DNS-Prefetch-Control
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-Buckets
X-FRAME-OPTIONS
Status
Upgrade
X-Content-Security-Policy
X-CDN
Content-Encoding
P3p
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Xss-Protection
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
X-Pass-Why
Xkey
X-Cache-Group
X-AH-Environment
X-Envoy-Upstream-Service-Time
X-Via
X-Backend
CF-Ray
X-Age
X-Server
X-Ua-Compatible
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Server-Powered-By
X-Page-Speed
X-Ws-Request-Id
X-Pingback
EagleId
X-Proxy-Cache
X-Hacker
X-Nginx-Cache-Status
X-UA-Device
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
Cf-Railgun
Grace
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Amz-Version-Id
Report-To
X-LiteSpeed-Cache
X-Rq
X-Server-Id
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
X-Device
X-Host
X-WebKit-CSP
X-Origin-Cache
EagleEye-TraceId
X-Response-Time
X-Node
X-Ac
Content-Location
Surrogate-Control
X-Vhost
X-Readtime
Request-Id
X-Backend-Server
X-Cloud-Trace-Context
X-Dispatcher
X-Dns-Prefetch-Control
X-Origin-Upstream-Status
X-Cnection
X-Application-Context
X-HW
X-Cache-Lookup
X-ORACLE-DMS-ECID
Fusion-Component-Id
Fusion-Source
Fusion-Content-Source
Fusion-Template-Id
Fusion-Content-Id
X-ORACLE-DMS-RID
X-Ruxit-JS-Agent
NEL
X-DataDome
X-Mod-Pagespeed
X-Rack-Cache
Rating
Edge-Control
X-Country
X-Akam-SW-Version
X-Clacks-Overhead
Pinterest-Generated-By
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Allow
X-TTL
X-Country-Code
Accept-Ch
X-DynaTrace
X-Instart-Request-ID
X-Varnish-TTL
X-Goog-Hash
X-FTR-Request-ID
X-Vname
X-TtlSet
X-PC
X-ESI
Verso
Accept-Ch-Lifetime
Content-MD5
X-Powered-By-Plesk
Service-Worker-Allowed
X-Url
X-B3-TraceId
X-Forwarded-Proto
X-MS-InvokeApp
X-Version
X-GitHub-Request-Id
X-Kinja-Server
X-Cdn-Fetch
X-Use-Magma
X-Exp-Variant
X-Exp-Id
X-Kinja-Revision
X-Kinja
X-GoogleNews-Bot
X-Kinja-Build
RTSS
Edge-Cache-Tag
X-D2id
X-Debug
X-Server-Name
X-Px
AR-ATIME
AR-Request-ID
Ar-Sid
AR-PoweredBy
AR-CACHE
X-Abt-Application-Version
X-Vcache
SPRequestGuid
X-Amz-Server-Side-Encryption
Charset
X-NF-Request-ID
X-Cached
X-Accel-Expires
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Middleton-Display
Display
Response
X-Middleton-Response
X-Sol
X-MSEdge-Ref
Pagespeed
X-Amz-Rid
Arr-Disable-Session-Affinity
X-Navigation-Version
X-Vcap-Request-Id
Pinterest-Version
X-Pinterest-Rid
X-SharePointHealthScore
X-Powered-CMS
X-Fastcgi-Cache
TCN
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Trace
X-VARITI-CCR
Public-Key-Pins
Realpath
Cache-Tag
X-Client-IP
X-Cdn
X-Fastly-Request-ID
MS-Author-Via
Access-Control-Request-Method
X-Ser
Nginx-Cache
X-DynaTrace-JS-Agent
X-Shard
S
SPRequestDuration
SPIisLatency
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Id
X-Upstream
X-Edge-O15-RID
X-Content-Type
X-Ezoic-Cdn
X-Hp-Webp
X-Amzn-Trace-Id
X-Grace
X-Forwarded-For
X-T
X-Amz-Meta-S3cmd-Attrs
Front-End-Https
X-Hits
X-Recruiting
DynaTrace
Fastcgi-Cache
Nel
X-Jurisdiction
X-Aspnet-Version
X-Varnish-Age
ServerID
X-Cache-TTL
MicrosoftSharePointTeamServices
X-Element-Page-Cache
X-Mobile-URL
X-Dw-Request-Base-Id
X-Node-Name
X-Content-Digest
X-DIS-Request-ID
X-Country-Code-Real
X-Server-ID
X-FTR-Expires
X-FTR-Cache-Status
NR-ENABLED
X-HS-Combine-CSS
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Content-Id
X-Goog-Metageneration
Powered
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
X-Frontend
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Realm
X-FTR-DC
Server-Node
TP-L2-Cache
TP-Cache
Alternate-Protocol
Server-Name
X-Logged-In
X-Correlation-Id
X-CST
AMP-Access-Control-Allow-Source-Origin
X-Request-Processing-Time
X-Request-Received
X-XRDS-LOCATION
Upgrade-Insecure-Requests
X-Amzn-RequestId
X-Request-Handler-Origin-Region
X-Microsite
X-Amz-Apigw-Id
X-ATS-Timestamp
Backend-Timing
X-Cache-Hit
X-Content-Options
Refresh
X-Origin-Server
X-Content-Security-Policy-Report-Only
X-Akamai-Edgescape
X-F-Cache
X-User-Agent
X-Rid
X-Page-Id
X-Revision
Fastly-Restarts
X-Varnish-Grace
X-Zen-Fury
X-Type
X-Webkit-Csp
X-XRDS-Location
X-Content-Powered-By
X-LB-Cache
X-B3-Sampled
X-B
X-Geo-Country
PB-PID
PB-RID
X-Activity-Id
X-Az
X-AppVersion
X-FTR-Cache-Host
Arc-Version
X-Mobile-Rewrite
X-URL
Cache-Status
X-Shield-Request-Id
X-Kinsta-Cache
X-N
X-Pad
X-Cache-Age
X-TT
X-Instance
X-Time
X-AOL-HN
X-WebKit-CSP-Report-Only
X-Framework
X-Tumblr-User
X-Signature
X-Cache-Action
X-B-Cache
X-Tumblr-Pixel-0
X-Tumblr-Pixel
Paypal-Debug-Id
Actual-Object-TTL
X-Jobs
X-App-Environment
Access-Control-Allow-Method
X-Debug-Info
X-Load-Cache
X-FB-Debug
X-Request-Guid
X-PHP-Backend
DC
X-Cached-By
X-Git-Hash
X-RateLimit-Remaining
X-Webapp-Samesite-None-Activated-N
X-Tt-Trace-Tag
X-Varnish-Backend
Fastcgi-Useragent
X-Tt-Trace-Host
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
Surrogate-Key
X-Amz-Replication-Status
X-Analytics
FilterID
X-IPLB-Instance
Host-Header
MS-CV
X-Contextid
X-ATG-Version
X-SS-Set-Cookie
Host
X-WA-Info
X-ORACLE-APMCS-REQUEST-ID
X-Cluster
X-Mobile
X-ORACLE-APMCS-TAG
X-Accel-Buffering
X-NWS-LOG-UUID
X-FastCGI-Cache
NGB
X-Response-Served-From
Tracecode
X-Via-JSL
WPE-Backend
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Cache-NE
Xserver
X-Host-Name
X-Cache-Key
Payment
X-FW-Server
X-FW-Serve
X-FW-Static
X-FW-Type
X-Cache-2
X-Region
X-Varnish-Server
X-FW-Hash
Eomportal-Instance
Source
X-Srv
X-GeoIP
Cache-Tv-Group
X-Varnish-Hostname
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
X-IPS-LoggedIn
Filters
Frame-Options
X-Adobe-Loc
X-Origin-Response-Time
X-Adobe-Content
X-Cache-Enabled
X-Presslabs-Stats
X-Cacheable-TTL
X-Cache-Operation
X-Cache-Rule
X-Rendered-As
X-Is-Bot
X-RequestSource
X-Hostname
X-Seen-By
X-TX-ID
Retry-After
X-EdgeConnect-Cache-Status
X-NewRelic-App-Data
X-Cache-TTL-Remaining
Cleartype
Server-Info
X-ProcessESI
X-RemovedCookies
Liferay-Portal
X-VCache
X-UA
X-Dc
Accept-CH
X-RTag
X-B3-Traceid
Ms-Operation-Id
X-L-Path
X-HTML-Minification-Powered-By
X-Source
X-Environment-Context
Datacenter
X-App-Server
X-CACHE-KEY
X-FireWall-Port
X-Endurance-Cache-Level
X-Upgrade-Enabled
X-Cache-Server
Cache
From-Origin
X-Handled-By
X-Cache-Control
Healthy
X-CLOUD-TRACE-CONTEXT
X-Backend-Name
X-APP-VERSION
X-Wix-Request-Id
Accept-CH-Lifetime
X-RN-RSRV
X-PressLabs-Stats
X-Status
Version
X-ES-SERVER
X-Path-Route
X-Cache-Var-Map
Meta-Geo
X-Cache-Var
X-Access
Selected-Fe
X-Section
OT-Force-Account-Verify
X-Proxy-Build
X-Format
X-Tb
X-Timing-Wait
X-Sorting-Hat-PodId
Mn-Server-Ip
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Request-Time
X-Proto
X-PCL
X-Storage
X-Shopify-Generated-Cart-Token
X-Rule
Cache-Tags
Akamai-GRN
X-Shopify-Stage
X-UUID
Azure-InstanceId
Azure-RegionName
Azure-Version
Azure-SlotName
Azure-SiteName
X-RateLimit-Limit
X-Content-Age
X-Sorting-Hat-ShopId
X-Akamai-Request-ID
X-Origin
X-ShopId
X-EIG-Tracking-Id
X-ShardId
X-OCL
X-Alternate-Cache-Key
Decoy-Debug-Status
X-Debug-Cache
Decoy-Debug-Key
X-JoinUs
X-VWS-Id
X-Akamai-Request-ID2
X-ProxyCache-Key
X-BYPASS-REASON
X-Hosted-By
X-Hyper-Cache
X-Human
X-Hl-Ver
X-AWS-Id
X-Vgn-Hpd-Reason
Decoy-Debug-TTL
X-Proxy
X-Viewer-Country
X-Web-Node
Origin-Cache-Control
X-LJ-Flow-ID
X-Proxy-Cache-Status
X-ProxyCache-Status
X-FC-Vary-Parameters
X-SaId
X-Pubstack
X-Soup
X-ServerID
Origin-Edge-Control
X-Redis-Cache
Now
X-Cache-Config
X-Qloud-Router
X-NYM-Debug-Backend
X-Time-Microsecs
X-Generated-By
X-Cluster-Node
Node
NGX
X-FW-Dynamic
Ec-Rule-Version
DB-Nickname
X-Yottaa-Optimizations
GEO-INFO
Accept-Charset
X-Yottaa-Metrics
Srv
Webcakes-App-Name
Webcakes-App-Version
TWC-Privacy
TWC-GeoIP-LatLong
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-Country
Webcakes-Region
TWC-Locale-Group
X-CCM
X-Ruxit-Js-Agent
X-Say-Cacheable
X-Say-TTL
X-SayCDN-TTL
X-Varnish-Hits
X-Site-Version
Property-Id
X-Generated
X-MP-GENERATED-AT
X-Origin-Hint
X-BCube-Filmed-By
X-Www-Served-By
Cross-Origin-Window-Policy
X-Locale
X-Cache-Host
X-Akamai-Transformed
X-R9-Blue-Green-Version
X-RCS-CacheZone
X-Loop
X-FB-TRIP-ID
X-Amzn-Remapped-Content-Length
X-Xfnlog-Site
S-Rt
X-TNCMS
X-NCache
X-Detected-As
X-IP
L5d-Success-Class
X-CS
X-Ttl
X-Unique-Id
Cache-Name
X-Drupal-Cache-Tags
Webserver
Viewport
Time
Uber-Trace-Id
Cache-Key
X-Esi
X-UA-Device-Type
X-UnsetCookies
Mime-Version
X-Mode
X-Forwarded-Host
Accept-Language
X-Cache-Remote
X-Backend-TTL
X-Daa-Tunnel
X-Whom
X-Origin-CC
X-From
X-Origin-TTL
Country
X-CDN-Forward
X-Info
X-Trafficlayer-App-Name
X-Trafficlayer-App-Scope
Rt-Fastcgi-Cache
Odigeo-Trace-Id
VIX-Pulpo-Upstream-Status
X-Varnish-Cache-Hits
X-Cluster-Name
VIX-Pulpo-Node
X-PERF
X-NGENIX-Cache
X-ApacheServer
Content-Disposition
X-Drupal-Cache-Contexts
X-Newrelic-Synthetics
X-Magnolia-Registration
X-TT-TIMESTAMP
X-Microcachable
ServedBy
X-Geo
X-B3-Spanid
Section-Io-Cache
Proxy-Connection
X-Proxied
X-Zipkin-Id
X-Edge-Location
X-Routing-Service
X-Device-Type
Ohc-File-Size
X-Webkit-CSP
X-Via-Fastly
X-Uri
X-EC-Lua
Ohc-Cache-HIT
HitType
Cf-Ipcountry
X-UPSTREAM-Address
X-No-Session
X-VG-TLSProxy
X-GeoIP-Country-Code
X-External-Request-Id
X-D
Apple-News-Services-Handled
X-Vtex-Remote-Cache
X-Vdms-Version
Machine
X-CF-Lambda-Version
X-G
X-Twitter-Response-Tags
X-Geo-Header
X-A
X-Date
GEO-REGION-INFO
Apple-News-Services-Request-Url
X-VG-WebCache
X-DPWN-IS-SECURE
MD5-Digest
BehaviorPad-Version
Content-Script-Type
Content-Style-Type
Apple-News-Services-Host
Fastcgi-X-Cache-Version
X-Destination
Apple-News-Services-Parsed-Url
X-VG-WebServer
AsisCache
X-Connection-Hash
X-Sigma
X-Session-Fingerprint
X-Sigma-Backend
T-Server
X-SRCache-Key
X-Application
X-ScT
X-Rojux
X-ARC
X-S
X-CF-Lambda-Fn
X-Aed
X-Accel-Expires-Debug
Xc-Version
X-A-Dam
X-Transaction
X-A-Ccd
X-Trv-Group
X-A-Dcw
W
X-A-Wwc
Viewtype
VivaBuild
X-A-Dgt
X-Rocket-Build-Number
X-S-Cookie
X-Region-Sid
X-Vtex-Processado-Em
Mobile-Detection-Method
X-B-Cookie
X-Request-UUID
X-Nc
Meta-Geo-Continent
X-Rewrite-Enabled
Rendered-Blocks
X-C
User-Cache-Control
Access-Control-Request-Headers
Ha-Gx-Prefs
Powered-By
X-Eu-Site
HA-Ipaddr
IsBot
X-CGP
Locid
X-Contensis-Viewer-Groups
X-Cache-Debug
X-CUA
X-Bip
X-Auto-Login
CDCHOST
X-Distil-CS
Fastly-Soc-X-Request-Id
Environment
X-Developers
Server-Cache-Control
Server-Surrogate-Control
X-Agile-Age
X-Agile
X-Agile-Id
Gh-Request-Id
X-App-Name
X-Cache-ASPX
X-Hit
X-Logging-Id
X-VC-Cache
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-Varnish-Beresp-Ttl
X-Varnish-Authentication
X-Tumblr-Pixel-3
Geo-Info
X-Wikidot-Static-Cache
X-TrackingId
X-Thanos
X-SIPLIST1
X-Wikidot-Backend
X-WebServer
X-PHP-Host
X-TA-CDN-Provider
X-Labrador-Cache-Channel
X-GoCache-CacheStatus
X-Cache-Backend
X-Real-IP
X-RateLimit-Remaining-Second
X-Block-Status
X-BBXSRF
X-Cdn-Srv
X-TT-LOGID
X-RateLimit-Limit-Second
X-Cache-Bucket
X-Cache-Info
X-Cache-Time
X-Owner
X-Cache-URL
X-Proxy-Upstream
Fastly-SWR
X-Azure-Ref
X-OVcl-Cache
X-User
X-TH-Server
X-Swa-Ws
X-VServer
X-Urbn-Site-Id
X-Gamma-Serve
X-Generated-In
X-Gen-Mode
X-Trace-Id
Countrycode
X-SVT-ORM-VERSION
X-Server-W
X-OVcl
X-Request-URI
Fastly-SIE
X-Generation-Time
X-SVT-ORM-RULES
X-AK-Request-ID
X-Render-Time
X-Origin-Expires
X-We-Are-Hiring
X-LI-UUID
X-Hash
X-Debug-Log
X-Fastly-Cache
X-Debug-Cache-Store
X-WADP-Cache
X-Debug-Cookies
X-Urbn-Context-Path
X-Dispatcher-Server
X-Irp-Debug
X-Instart-Isnd
X-IN-APIGATEWAYSSL
X-Epic-Correlation-Id
X-Li-Fabric
X-Hnp-Log
X-Distributor
X-Li-Pop
X-Rebelmouse-Surrogate-Control
X-Debug-Cache-Fetch
X-Cms-Context
X-NX-Host
X-NodeID
X-Clara-WADP
X-GeoIP-City
X-FW-Version
X-Origin-Date
X-Fetched-On
X-Core-Mission
X-Nginx-Cache-Key
X-Clientip
X-Rebelmouse-Cache-Control
X-Debug-Cache-Expiry
X-Micro-Cache
X-Ms-Request-Id
X-Ms-Version
X-Webstats-RespID
X-IN-APIGATEWAY
X-Backend-State
Memcached
Mail-Subject
Locale
Request-Country
Request-EU
RNT-Time
RNT-Machine
Kp-EeAlive
IBM-Web2-Location
Cache-Host
AKAMAI
Cdncip
Cdnsip
Heartbleed
Country-Code
Server-ID
Fastly-SSL
Server-Int
True-Client-Country-4JS
Web-Mar-Node
We-Hiring
V-Age
Adler-Geo
Wxu-Next-Hostname
Wxu-Next-Region
Is-Eu
Platform
FNAC-ModuleRouting
Fastly-Backend-Name
X-Generated-On
X-Trafficlayer-App-Version
X-Matched-Rule
X-LI-Proto
X-Req
X-Reboot
X-Old-Content-Length
X-Service
X-ServiceProvider
ServerName
X-Thinkindot-L3
X-App-Version
X-Key
X-Level-Front-Cache
X-Core-Value
Wxu-Next-Commit
X-Platform-Server
Thinkindot-CacheControl-Type
X-NU-AKA-ACS-Version
PFcat
X-Up
Server-Host
X-Variation
Thinkindot-CacheControl
Thinkindot-Control
X-Servername
X-Is-Gdpr
X-Cache-Tags
X-JWT-State
X-Has-Esi
X-Internal-Host
X-Lb-Id
X-Sucuri-Cache
X-Air-Hostname
X-S-Maxage
Cache-Hits
X-Nginx-Cache
X-SERVER
RequestId
X-Refresh
X-Cache-Expired-At
Group
X-Var-Ttl
S-Cnection
X-Location
X-Response-By
X-Parent-Response-Time
X-Tb-Optimization-Total-Bytes-Saved
Pragrma
X-CF-Powered-By
Memory
Powered-By-ChinaCache
ProcessTime
Filterid
X-B3-Parentspanid
X-Cdn-Forward
X-NC
X-BACKEND-TTL
X-Pjax-Url
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
X-CSRF-Token
X-B3-SpanId
X-CSRF-TOKEN
SRV
User-Agent
Origin
X-Wa
X-Sucuri-ID
Geoip-Latitude
TTL
X-Pf-Uncompressing
X-Server-IP
X-Varnish-Cacheable
X-NWS-UUID-VERIFY
GeoIp-Country-Code
X-Vcl-Version
Geoip-City
X-Via-CDN
X-Ua
X-NGINX-Cache
X-Correlation-ID
X-Unique-ID
X-Developer
PICS-Label
X-Cdn-Origin
X-Sn-Servicetimems
X-Cache-Grace
X-Ocache
X-Device-Os
Media-Length
X-COUNTRY
X-LAGOON
X-Cdn-Request-ID
On-Server
X-Node-Id
X-Cache-Status-Check
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-Rocket-Nginx-Bypass
X-Oss-Object-Type
X-Sucuri-Id
Dnion-Transfer-Encoding
A
X-MSEdge-Flight
X-MSEdge-Features
X-Request-Host
X-Servedbyhost
X-Litespeed-Cache
Cloudfront-Viewer-Country
X-Via-Ucdn
SN
X-Varnish-Ttl
X-Oneagent-Js-Injection
Hostname
XServer
X-TIME
M-TraceId
Cdn
Tcn
X-AIR-PT
X-HS-Status
Esi-Enabled
X-Reqid
X-FORWARDED-FOR
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
HostName
X-Policy
X-ServedByHost
X-Ratelimit-Remaining
X-Fastly-Country-Code
X-Request-Start
Resin-Trace
X-Beluga-Cache-Status
CF-Cached-On
X-Beluga-Node
X-Beluga-Trace
X-Cache-Ttl
Host-ID
X-Beluga-Status
Who
X-Azure-Ref-OriginShield
X-Beluga-Record
X-Beluga-Response-Time
X-Ftr-Cache-Host
X-VHOST
Rt-Proxy-Cache
X-Varnish-URL
Pics-Label
X-Slack-Backend
NtCoent-Length
X-Varnish-Url
GeoIP-Country-Code
X-Bc
X-Method
X-VCL-Version
X-APP
X-Action
X-Zone
Magicmarker
CACHE
X-Oracle-Dms-Rid
MIME-Version
X-DI
X-Server-Time
X-Processor
Ttl
X-Fastly-Backend-Reqs
X-PAYTM-SRV-ID
Arc-Country
X-RPM
X-RPS
X-Cache-FS-Status
X-Dispatch
X-DW
Pramga
X-RSL
GeoIP-Latitude
Cteonnt-Length
X-DSS
X-DB
X-LiteSpeed-Cache-Control
X-DC
X-VarnishDD-TTL
X-Flog
X-Ratelimit-Limit
X-ND-Cache
X-Skip-Cache
X-Hello
X-ABtesting
X-Newrelic-App-Data
X-PF-Uncompressing
X-FPC
GeoIP-City
X-HostName
X-Ftr-Request-Id
X-Swift-Error
X-PJAX-URL
Fastly-Drupal-HTML
X-Svr
Cdn-Request-Time
X-SRV
Amp-Access-Control-Allow-Source-Origin
X-Be
X-Served-From
Ohc-Response-Time
Load-Balancing
WebServer
X-Edge-Server
Cdn-Host
N-Cache
X-Bc-Bl
Processtime
X-Dynatrace
X-BE
Vix-Hermes-Req-Id
X-DevSite-Last-Modified
X-Dynatrace-Js-Agent
X-MServer
Servername
DSUID
CF-IPCountry
Cache-Provider
X-Amzn-Remapped-Date
Section-Origin-Responded
Release
X-Backend-Host
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
X-VCT
X-ID
X-Aicache-OS
Section-Io-Id
X-Amzn-Remapped-Connection
X-WA
X-WR-MODIFICATION
X-Hp-Ccpa-Warning
X-Frame-Option
X-Ftr-Realm
Dynatrace
X-Configured-By
X-Tid
X-Ftr-Dc
X-Ftr-Balancer
X-Snapshot-Date
X-LB-ID
X-Ftr-Backend
X-Ftr-Backend-Server
WZWS-RAY
X-StackifyID
CDN
Pagetype
X-Branch-Name
Lfy
X-ZONE
Requestid
X-Fastly-Cache-Hits
X-CACHE-AGE
Cache-Cookie-Set-From
FSS-Cache
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-Idcheck
FSS-Proxy
X-Fmm-Version
Proxy-Firewall
X-Apw-Access-Token
X-Apw-Hits
SD-X-WS
X-BC
X-Cc-Via
X-Apw-Access-Action
X-SD-PageType
X-Upstream-Ct
X-Upstream-Ht
X-Edge-IP
X-Request-Url
X-Apw-Access-Object
D-Cc-Upstream
Warning
X-VC
X-SB
X-Cc-Req-Id
V-Cache
X-Node-ID
X-Adobe-Source
X-Litespeed-Cache-Control
X-SN
X-Varnish-Beresp-TTL
Cneonction
X-WPE-Loopback-Upstream-Addr
L
X-Li-Proto
X-ServerName
Lb
X-Fastly-Cache-Status
X-Request-URL
X-Powered-Y
X-Worker
WP-Super-Cache
X-Check-Cacheable
X-App
X-ElasticPress-Search
X-Cache-Id
Backend-Name
Correlation-Id
X-Compress-Hint