Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
CF-RAY
Link
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Request-ID
X-Cache-Status
X-Generator
Content-Security-Policy-Report-Only
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-Template
X-DNS-Prefetch-Control
X-Language
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
Status
Upgrade
X-Content-Security-Policy
X-CDN
Content-Encoding
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Xss-Protection
X-Kinja-Server-Push
Keep-Alive
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
P3p
Xkey
X-Pass-Why
X-Cache-Group
X-AH-Environment
X-Envoy-Upstream-Service-Time
CF-Ray
X-Via
X-Backend
X-Ua-Compatible
X-Age
X-Server
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Server-Powered-By
X-Page-Speed
X-Ws-Request-Id
X-Pingback
EagleId
X-Proxy-Cache
X-Hacker
X-Nginx-Cache-Status
X-UA-Device
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
Cf-Railgun
Grace
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Amz-Version-Id
Report-To
X-LiteSpeed-Cache
X-Rq
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Server-Id
X-OneAgent-JS-Injection
X-WebKit-CSP
X-Host
X-Device
EagleEye-TraceId
X-Origin-Cache
X-Response-Time
X-Ac
X-Node
Content-Location
Surrogate-Control
X-Vhost
X-Readtime
X-Cloud-Trace-Context
Request-Id
X-Backend-Server
X-Dns-Prefetch-Control
X-Dispatcher
X-Origin-Upstream-Status
X-Cnection
X-Application-Context
X-HW
X-ORACLE-DMS-ECID
X-Cache-Lookup
Fusion-Component-Id
Fusion-Content-Id
Fusion-Source
Fusion-Template-Id
Fusion-Content-Source
X-ORACLE-DMS-RID
X-DataDome
X-Ruxit-JS-Agent
NEL
X-Mod-Pagespeed
Rating
X-Rack-Cache
Edge-Control
X-Country
X-Akam-SW-Version
X-Clacks-Overhead
Pinterest-Generated-By
Allow
X-TTL
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Country-Code
X-DynaTrace
X-Instart-Request-ID
Accept-Ch
X-Varnish-TTL
X-Goog-Hash
X-FTR-Request-ID
X-PC
X-Vname
X-TtlSet
X-ESI
Verso
Accept-Ch-Lifetime
X-Powered-By-Plesk
Content-MD5
Service-Worker-Allowed
X-Url
X-B3-TraceId
X-Forwarded-Proto
X-Version
X-MS-InvokeApp
X-GitHub-Request-Id
X-Kinja
X-Kinja-Build
X-GoogleNews-Bot
X-Exp-Variant
X-Cdn-Fetch
X-Exp-Id
X-Kinja-Revision
X-Use-Magma
X-Kinja-Server
RTSS
Edge-Cache-Tag
X-D2id
X-Debug
X-Px
AR-Request-ID
AR-PoweredBy
Ar-Sid
AR-CACHE
AR-ATIME
X-Server-Name
X-Abt-Application-Version
SPRequestGuid
X-Amz-Server-Side-Encryption
X-Vcache
Charset
X-NF-Request-ID
X-Cached
X-Accel-Expires
X-Middleton-Display
Display
Pagespeed
Response
X-Middleton-Response
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Sol
X-TEC-API-ORIGIN
X-MSEdge-Ref
X-Amz-Rid
Arr-Disable-Session-Affinity
X-Vcap-Request-Id
X-Fastcgi-Cache
X-Navigation-Version
X-Pinterest-Rid
X-Powered-CMS
Pinterest-Version
X-SharePointHealthScore
TCN
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Trace
X-Cdn
X-VARITI-CCR
Realpath
Public-Key-Pins
Cache-Tag
X-Client-IP
X-Fastly-Request-ID
Access-Control-Request-Method
X-Ser
MS-Author-Via
Nginx-Cache
X-DynaTrace-JS-Agent
S
X-Shard
SPRequestDuration
SPIisLatency
X-Id
X-Upstream
X-B3-TraceId-Primal
X-Edge-O15-RID
Mrf-Cache-Status
X-Mrf-Section-Lastmod
MRF-Tech
X-Mrf-Item-Lastmod
X-Ezoic-Cdn
X-Hp-Webp
X-Content-Type
X-Grace
X-Forwarded-For
X-Amzn-Trace-Id
X-T
X-Amz-Meta-S3cmd-Attrs
Nel
Front-End-Https
X-Recruiting
DynaTrace
X-Hits
Fastcgi-Cache
X-Aspnet-Version
X-Varnish-Age
X-Jurisdiction
ServerID
X-Server-ID
X-Cache-TTL
MicrosoftSharePointTeamServices
X-Dw-Request-Base-Id
X-Mobile-URL
X-Element-Page-Cache
X-DIS-Request-ID
X-Node-Name
X-Country-Code-Real
X-FTR-Cache-Status
X-Content-Digest
X-FTR-Expires
NR-ENABLED
X-HS-Combine-CSS
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Hub-Id
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-GUploader-UploadID
Powered
X-Goog-Stored-Content-Encoding
X-Frontend
X-Goog-Storage-Class
X-Goog-Generation
X-FTR-Realm
X-FTR-DC
X-FTR-Balancer
X-FTR-Backend
X-FTR-Backend-Server
Server-Node
TP-L2-Cache
TP-Cache
Alternate-Protocol
Server-Name
X-Logged-In
X-Correlation-Id
X-Request-Received
X-Request-Processing-Time
AMP-Access-Control-Allow-Source-Origin
X-Microsite
X-Request-Handler-Origin-Region
Upgrade-Insecure-Requests
Backend-Timing
X-ATS-Timestamp
X-CST
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Cache-Hit
X-Content-Options
X-Content-Security-Policy-Report-Only
X-XRDS-LOCATION
X-Origin-Server
Refresh
X-Page-Id
X-F-Cache
X-Webkit-Csp
X-User-Agent
X-Rid
X-Revision
X-Akamai-Edgescape
X-Type
X-XRDS-Location
X-Zen-Fury
X-Varnish-Grace
Fastly-Restarts
X-Content-Powered-By
X-LB-Cache
X-B3-Sampled
X-B
X-Geo-Country
X-URL
X-AppVersion
X-Activity-Id
X-Az
X-FTR-Cache-Host
PB-RID
PB-PID
Arc-Version
X-Mobile-Rewrite
Cache-Status
X-Shield-Request-Id
X-Kinsta-Cache
X-N
X-Pad
X-Cache-Age
X-TT
X-AOL-HN
X-WebKit-CSP-Report-Only
X-Instance
X-Time
X-Framework
X-B-Cache
X-Signature
X-Cache-Action
X-Tumblr-User
X-Tumblr-Pixel
Paypal-Debug-Id
X-Jobs
Actual-Object-TTL
X-Tumblr-Pixel-0
X-App-Environment
X-Load-Cache
X-Debug-Info
Access-Control-Allow-Method
X-Request-Guid
DC
X-Webapp-Samesite-None-Activated-N
X-FB-Debug
X-PHP-Backend
X-Cached-By
X-Git-Hash
X-RateLimit-Remaining
X-Tt-Trace-Tag
X-Varnish-Backend
X-Analytics
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
Fastcgi-Useragent
X-Tt-Trace-Host
Surrogate-Key
X-Amz-Replication-Status
Host-Header
X-IPLB-Instance
MS-CV
X-Contextid
FilterID
X-ATG-Version
X-SS-Set-Cookie
X-WA-Info
Host
X-Cache-Key
X-Cluster
X-Mobile
Tracecode
NGB
X-Accel-Buffering
X-Response-Served-From
X-ORACLE-APMCS-REQUEST-ID
X-ORACLE-APMCS-TAG
WPE-Backend
X-Cache-NE
X-Kong-Proxy-Latency
X-Host-Name
Payment
X-Kong-Upstream-Latency
X-Varnish-Server
X-Via-JSL
X-FW-Serve
X-FW-Hash
X-Cache-2
X-FW-Server
Eomportal-Instance
Xserver
X-Region
X-FW-Type
X-NWS-LOG-UUID
X-FW-Static
Source
Cache-Tv-Group
Frame-Options
Filters
X-Varnish-Hostname
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
X-IPS-LoggedIn
X-Srv
X-GeoIP
X-Origin-Response-Time
X-Adobe-Content
X-Cache-Enabled
X-Adobe-Loc
X-Cacheable-TTL
X-Is-Bot
X-Cache-Operation
X-Cache-Rule
X-RequestSource
X-Rendered-As
X-TX-ID
X-Hostname
X-EdgeConnect-Cache-Status
X-NewRelic-App-Data
X-Seen-By
X-Presslabs-Stats
X-FastCGI-Cache
Retry-After
Cleartype
X-VCache
Server-Info
X-Cache-TTL-Remaining
X-RemovedCookies
X-ProcessESI
Accept-CH
Liferay-Portal
X-B3-Traceid
X-UA
X-Dc
X-RTag
Ms-Operation-Id
Datacenter
X-Source
X-HTML-Minification-Powered-By
X-L-Path
X-Environment-Context
X-App-Server
Cache
X-FireWall-Port
X-Endurance-Cache-Level
X-Upgrade-Enabled
X-Cache-Server
X-Cache-Control
From-Origin
X-Handled-By
X-CACHE-KEY
Accept-CH-Lifetime
Healthy
X-PressLabs-Stats
X-Backend-Name
Version
X-Status
X-RN-RSRV
Srv
X-Wix-Request-Id
Meta-Geo
X-Path-Route
X-Cache-Var
X-ES-SERVER
X-Cache-Var-Map
X-Timing-Wait
Selected-Fe
X-Proxy-Build
X-Access
X-Tb
X-Ruxit-Js-Agent
OT-Force-Account-Verify
X-APP-VERSION
X-Format
X-Section
X-Rule
X-Sorting-Hat-ShopId
X-PCL
X-Sorting-Hat-PodId
X-Shopify-Generated-Cart-Token
X-Origin
X-Storage
X-Akamai-Request-ID
X-RateLimit-Limit
X-OCL
X-Alternate-Cache-Key
Azure-Version
X-Request-Time
Akamai-GRN
Azure-SlotName
X-ShardId
X-Content-Age
Azure-SiteName
Mn-Server-Ip
X-EIG-Tracking-Id
X-Shopify-Stage
X-Goog-Meta-Goog-Reserved-File-Mtime
Azure-RegionName
X-ShopId
Cache-Tags
X-Proto
Azure-InstanceId
Node
Ec-Rule-Version
Now
Decoy-Debug-Key
NGX
Decoy-Debug-Status
Decoy-Debug-TTL
X-Hosted-By
X-Viewer-Country
X-VWS-Id
X-ServerID
X-ProxyCache-Status
X-ProxyCache-Key
X-Proxy
X-Proxy-Cache-Status
X-Web-Node
X-Cache-Config
X-NYM-Debug-Backend
X-Redis-Cache
X-Qloud-Router
X-SaId
X-Pubstack
X-FC-Vary-Parameters
X-Vgn-Hpd-Reason
X-UUID
X-Cluster-Node
X-Debug-Cache
X-FW-Dynamic
X-BYPASS-REASON
X-AWS-Id
Origin-Edge-Control
X-Akamai-Request-ID2
X-Generated-By
X-Hl-Ver
X-Soup
X-Time-Microsecs
X-LJ-Flow-ID
X-JoinUs
X-Human
X-Hyper-Cache
Origin-Cache-Control
DB-Nickname
X-Yottaa-Metrics
X-Yottaa-Optimizations
TWC-Privacy
Webcakes-App-Name
Webcakes-App-Version
TWC-Locale-Group
TWC-GeoIP-Country
Property-Id
TWC-Connection-Speed
TWC-Device-Class
Webcakes-Region
TWC-GeoIP-LatLong
X-Cache-Host
X-Varnish-Hits
X-Say-Cacheable
X-Say-TTL
X-SayCDN-TTL
X-Site-Version
X-Origin-Hint
X-CCM
Accept-Charset
X-Generated
X-MP-GENERATED-AT
X-BCube-Filmed-By
X-Www-Served-By
Cross-Origin-Window-Policy
X-Locale
X-Loop
X-TNCMS
GEO-INFO
X-Akamai-Transformed
S-Rt
X-FB-TRIP-ID
X-Amzn-Remapped-Content-Length
X-RCS-CacheZone
X-Xfnlog-Site
X-R9-Blue-Green-Version
X-Ttl
X-IP
X-NCache
X-Detected-As
L5d-Success-Class
X-CS
Cache-Name
Viewport
X-Esi
X-Drupal-Cache-Tags
Uber-Trace-Id
Webserver
Time
X-Unique-Id
Cache-Key
X-UA-Device-Type
X-UnsetCookies
X-Mode
X-Cache-Remote
Mime-Version
X-Forwarded-Host
Accept-Language
X-From
X-Origin-TTL
X-Origin-CC
X-Trafficlayer-App-Name
Country
X-Info
X-Backend-TTL
Rt-Fastcgi-Cache
X-Whom
X-Trafficlayer-App-Scope
X-CDN-Forward
X-Daa-Tunnel
Odigeo-Trace-Id
VIX-Pulpo-Node
X-Cluster-Name
X-Newrelic-Synthetics
VIX-Pulpo-Upstream-Status
X-Varnish-Cache-Hits
X-Drupal-Cache-Contexts
Content-Disposition
X-ApacheServer
X-CLOUD-TRACE-CONTEXT
X-PERF
X-Microcachable
X-NGENIX-Cache
X-Magnolia-Registration
X-TT-TIMESTAMP
ServedBy
X-B3-Spanid
X-Geo
X-Edge-Location
X-Device-Type
X-Proxied
Proxy-Connection
X-Routing-Service
X-Zipkin-Id
X-Via-Fastly
X-EC-Lua
Ohc-File-Size
Cf-Ipcountry
X-UPSTREAM-Address
Section-Io-Cache
X-Uri
Ohc-Cache-HIT
X-Nc
HitType
X-No-Session
X-B-Cookie
X-ARC
X-G
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
X-Date
Apple-News-Services-Host
X-CF-Lambda-Fn
MD5-Digest
X-GeoIP-Country-Code
X-Connection-Hash
Machine
X-CF-Lambda-Version
Meta-Geo-Continent
Rendered-Blocks
X-A
X-Geo-Header
Mobile-Detection-Method
X-D
BehaviorPad-Version
X-Twitter-Response-Tags
Xc-Version
VivaBuild
X-A-Wwc
W
Viewtype
X-Trv-Group
Content-Style-Type
X-Region-Sid
X-Accel-Expires-Debug
X-Transaction
Geo-Info
X-Destination
Fastcgi-X-Cache-Version
X-Vtex-Processado-Em
X-A-Dcw
X-Vtex-Remote-Cache
X-A-Dam
X-A-Ccd
X-VG-WebServer
X-A-Dgt
GEO-REGION-INFO
X-Vdms-Version
X-VG-TLSProxy
X-VG-WebCache
X-Aed
Content-Script-Type
X-Sigma
X-Rocket-Build-Number
X-Sigma-Backend
X-S-Cookie
X-DPWN-IS-SECURE
T-Server
X-Session-Fingerprint
X-ScT
AsisCache
X-Request-UUID
X-Rojux
X-Application
X-S
X-Rewrite-Enabled
X-SRCache-Key
X-External-Request-Id
Apple-News-Services-Request-Url
X-C
User-Cache-Control
Access-Control-Request-Headers
Fastly-Soc-X-Request-Id
Ha-Gx-Prefs
HA-Ipaddr
IsBot
CDCHOST
Gh-Request-Id
X-Contensis-Viewer-Groups
X-Eu-Site
X-Distil-CS
X-CUA
X-Developers
X-Hit
Environment
X-Auto-Login
X-TrackingId
X-Cache-ASPX
X-Cache-Debug
X-Agile-Age
X-Agile
X-SIPLIST1
X-Bip
X-Agile-Id
Server-Surrogate-Control
X-Thanos
Server-Cache-Control
Locid
Powered-By
X-App-Name
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Status
X-CGP
X-VC-Cache
X-WebServer
X-Varnish-Beresp-Grace
X-Logging-Id
X-Tumblr-Pixel-3
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-Varnish-Authentication
X-PHP-Host
X-Cache-Backend
X-GoCache-CacheStatus
X-Labrador-Cache-Channel
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-Backend-State
X-Cache-URL
X-Core-Mission
X-Cdn-Srv
X-Clara-WADP
X-Cms-Context
X-Cache-Time
X-Cache-Info
X-Debug-Cache-Store
X-Azure-Ref
X-Block-Status
X-Cache-Bucket
X-AK-Request-ID
X-Rebelmouse-Surrogate-Control
X-RateLimit-Remaining-Second
Fastly-SWR
X-Real-IP
X-Render-Time
X-Server-W
X-Request-URI
X-RateLimit-Limit-Second
X-Proxy-Upstream
X-Origin-Expires
X-Origin-Date
X-OVcl
X-OVcl-Cache
X-Owner
Fastly-SIE
X-SVT-ORM-RULES
X-User
X-Urbn-Site-Id
X-Webstats-RespID
X-VServer
X-We-Are-Hiring
X-WADP-Cache
X-Urbn-Context-Path
X-TT-LOGID
X-Swa-Ws
X-SVT-ORM-VERSION
X-TH-Server
Countrycode
X-Trace-Id
X-Clientip
X-NX-Host
X-Gen-Mode
X-Gamma-Serve
X-Generated-In
X-Generation-Time
X-Hash
X-GeoIP-City
X-FW-Version
X-Fetched-On
X-Dispatcher-Server
X-Debug-Log
X-Distributor
X-Epic-Correlation-Id
X-Fastly-Cache
X-Hnp-Log
X-IN-APIGATEWAY
X-Micro-Cache
X-Rebelmouse-Cache-Control
X-Ms-Request-Id
X-Ms-Version
X-NodeID
X-Nginx-Cache-Key
X-LI-UUID
X-LI-Proto
X-Instart-Isnd
X-IN-APIGATEWAYSSL
X-Irp-Debug
X-Li-Fabric
X-Li-Pop
X-Debug-Cookies
X-BBXSRF
RNT-Time
RNT-Machine
Request-EU
Country-Code
Cdnsip
Server-ID
Cache-Host
Request-Country
Fastly-SSL
Mail-Subject
Locale
Kp-EeAlive
Memcached
Heartbleed
IBM-Web2-Location
Server-Int
Cdncip
We-Hiring
X-App-Version
V-Age
Web-Mar-Node
True-Client-Country-4JS
AKAMAI
X-TA-CDN-Provider
FNAC-ModuleRouting
ServerName
X-Key
X-Core-Value
X-Level-Front-Cache
X-Req
Adler-Geo
Is-Eu
X-Has-Esi
Platform
Wxu-Next-Region
X-Old-Content-Length
X-Cache-Tags
X-Reboot
X-Generated-On
X-Matched-Rule
Fastly-Backend-Name
X-Is-Gdpr
X-Servername
X-Sucuri-Cache
X-Trafficlayer-App-Version
Thinkindot-Control
X-Up
X-Internal-Host
Thinkindot-CacheControl-Type
Server-Host
X-Variation
Thinkindot-CacheControl
X-Platform-Server
X-Service
Wxu-Next-Commit
Wxu-Next-Hostname
X-Thinkindot-L3
X-JWT-State
X-ServiceProvider
X-NU-AKA-ACS-Version
PFcat
X-Nginx-Cache
X-SERVER
X-Lb-Id
X-Location
X-Air-Hostname
X-S-Maxage
Cache-Hits
X-Response-By
X-Var-Ttl
Group
X-Refresh
X-Cache-Expired-At
RequestId
S-Cnection
X-Parent-Response-Time
X-Tb-Optimization-Total-Bytes-Saved
Pragrma
Filterid
X-Cdn-Forward
X-B3-Parentspanid
ProcessTime
Memory
X-Tec-Api-Origin
X-CF-Powered-By
Powered-By-ChinaCache
X-Tec-Api-Version
X-BACKEND-TTL
X-Tec-Api-Root
X-B3-SpanId
X-CSRF-TOKEN
X-Pjax-Url
X-CSRF-Token
X-Wa
X-Server-IP
X-NC
User-Agent
Origin
X-Sucuri-ID
TTL
X-Varnish-Cacheable
Geoip-Latitude
X-Pf-Uncompressing
X-Correlation-ID
X-NWS-UUID-VERIFY
SRV
X-Unique-ID
X-Ua
GeoIp-Country-Code
Geoip-City
X-Vcl-Version
X-Via-CDN
X-Cdn-Request-ID
X-Developer
X-NGINX-Cache
PICS-Label
Media-Length
X-COUNTRY
X-Cache-Grace
X-Ocache
X-Node-Id
X-LAGOON
X-Cdn-Origin
X-Device-Os
X-Sn-Servicetimems
X-Servedbyhost
X-Litespeed-Cache
X-Webkit-CSP
Dnion-Transfer-Encoding
X-Sucuri-Id
On-Server
X-Rocket-Nginx-Bypass
SN
X-Via-Ucdn
X-Varnish-Ttl
A
X-Cache-Status-Check
X-MSEdge-Features
X-MSEdge-Flight
X-Request-Host
X-TIME
X-Oss-Server-Time
X-Oss-Object-Type
X-Oss-Request-Id
Hostname
XServer
X-Oss-Hash-Crc64ecma
X-Oss-Storage-Class
X-Oneagent-Js-Injection
X-Reqid
X-HS-Status
X-AIR-PT
M-TraceId
Esi-Enabled
Cloudfront-Viewer-Country
Tcn
X-FORWARDED-FOR
X-Policy
Cdn
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Ratelimit-Remaining
X-Beluga-Trace
Who
X-ServedByHost
X-Beluga-Status
X-Beluga-Response-Time
X-Beluga-Cache-Status
X-Fastly-Country-Code
X-Cache-Ttl
X-Beluga-Node
X-Beluga-Record
X-Azure-Ref-OriginShield
X-Request-Start
Resin-Trace
HostName
X-Ftr-Cache-Host
X-VHOST
Rt-Proxy-Cache
X-Varnish-URL
Host-ID
CF-Cached-On
Pics-Label
NtCoent-Length
GeoIP-Country-Code
X-Method
X-Slack-Backend
Magicmarker
X-VCL-Version
X-APP
X-Oracle-Dms-Rid
CACHE
MIME-Version
Cteonnt-Length
Ttl
X-Fastly-Backend-Reqs
X-Bc
X-Varnish-Url
GeoIP-Latitude
X-Zone
X-Action
X-DC
X-LiteSpeed-Cache-Control
X-PAYTM-SRV-ID
X-Server-Time
X-Dispatch
X-VarnishDD-TTL
GeoIP-City
X-Processor
X-DB
X-DSS
X-DW
X-DI
X-Newrelic-App-Data
X-Ratelimit-Limit
X-RPM
X-RPS
X-Cache-FS-Status
Pramga
Arc-Country
X-RSL
X-PF-Uncompressing
X-HostName
X-SRV
X-FPC
X-Swift-Error
Amp-Access-Control-Allow-Source-Origin
Load-Balancing
X-PJAX-URL
X-Ftr-Request-Id
Ohc-Response-Time
X-Skip-Cache
X-Be
WebServer
X-Hello
X-ND-Cache
X-Svr
X-Flog
X-ABtesting
X-Dynatrace
Cdn-Host
Processtime
Cdn-Request-Time
Vix-Hermes-Req-Id
X-BE
Fastly-Drupal-HTML
X-Served-From
X-Edge-Server
X-Dynatrace-Js-Agent
DSUID
X-MServer
Servername
N-Cache
X-DevSite-Last-Modified
X-WA
X-Bc-Bl
X-VCT
X-ID
Cache-Provider
Release
X-Aicache-OS
X-Frame-Option
X-Hp-Ccpa-Warning
X-WR-MODIFICATION
X-Fastly-Cache-Hits
X-Tid
X-Branch-Name
CF-IPCountry
X-LB-ID
X-StackifyID
X-Amzn-Remapped-Date
X-Amzn-Remapped-Connection
Pagetype
Dynatrace
X-ZONE
CDN
X-Configured-By
X-Snapshot-Date
X-Backend-Host
X-Ftr-Realm
Requestid
X-Ftr-Backend
X-Ftr-Backend-Server
X-Ftr-Balancer
Lfy
X-Ftr-Dc
Section-Io-Origin-Status
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Id
X-CACHE-AGE
X-Upstream-Ht
X-Apw-Access-Object
X-SD-PageType
X-Apw-Hits
X-BC
WZWS-RAY
SD-X-WS
X-Apw-Access-Action
V-Cache
X-SB
Proxy-Firewall
X-Cc-Via
X-Cc-Req-Id
X-Apw-Access-Token
Warning
X-Request-Url
X-Upstream-Ct
X-Edge-IP
X-VC
D-Cc-Upstream
X-Litespeed-Cache-Control
X-WPE-Loopback-Upstream-Addr
FSS-Proxy
X-Fmm-Version
FSS-Cache
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-From
Cneonction
Cache-Cookie-Set-Lfrom
X-Powered-Y
WP-Super-Cache
X-SN
X-ElasticPress-Search
X-Worker
X-App
Backend-Name
Correlation-Id
X-ServerName
X-Request-URL
X-Compress-Hint
X-Cache-Id
X-Varnish-Beresp-TTL
Lb
X-Check-Cacheable
L
X-Fastly-Cache-Status