Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-Powered-By
Pragma
CF-Cache-Status
Link
X-XSS-Protection
ETag
CF-RAY
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Xss-Protection
X-Runtime
CF-Ray
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Request-ID
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-DNS-Prefetch-Control
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
Status
Upgrade
X-Content-Security-Policy
Content-Encoding
X-CDN
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
X-Pass-Why
X-Cache-Group
X-AH-Environment
X-Envoy-Upstream-Service-Time
X-Via
Xkey
X-Backend
X-Age
X-Server
X-Ws-Request-Id
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Page-Speed
EagleId
X-Server-Powered-By
X-Pingback
X-Proxy-Cache
X-Hacker
X-Nginx-Cache-Status
Request-Context
X-UA-Device
Feature-Policy
Server-Timing
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Cf-Railgun
Ali-Swift-Global-Savetime
Grace
X-Amz-Version-Id
X-Ua-Compatible
Report-To
X-LiteSpeed-Cache
X-OneAgent-JS-Injection
X-Rq
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-WebKit-CSP
X-Device
X-Host
X-Server-Id
X-Origin-Cache
X-Response-Time
EagleEye-TraceId
X-Ac
X-Node
Surrogate-Control
Content-Location
X-Vhost
X-Backend-Server
X-Cloud-Trace-Context
X-Readtime
X-Dispatcher
Request-Id
X-Ruxit-JS-Agent
X-Cache-Lookup
X-Origin-Upstream-Status
X-Cnection
X-Application-Context
X-HW
Fusion-Content-Id
Fusion-Component-Id
Fusion-Source
Fusion-Template-Id
Fusion-Content-Source
X-ORACLE-DMS-ECID
X-Mod-Pagespeed
NEL
X-ORACLE-DMS-RID
P3p
X-DataDome
X-Rack-Cache
X-Dns-Prefetch-Control
X-Country
X-Clacks-Overhead
Edge-Control
X-Akam-SW-Version
Rating
Allow
Pinterest-Generated-By
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-TTL
X-Country-Code
Accept-Ch
X-FTR-Request-ID
X-Instart-Request-ID
X-Varnish-TTL
X-DynaTrace
X-TtlSet
X-Vname
X-PC
X-Goog-Hash
Verso
Content-MD5
X-ESI
Accept-Ch-Lifetime
Service-Worker-Allowed
X-Url
X-Powered-By-Plesk
X-Vcache
X-Exp-Variant
X-Exp-Id
X-Cdn-Fetch
X-Kinja-Server
X-Use-Magma
X-GoogleNews-Bot
X-Kinja-Revision
X-Kinja
X-Kinja-Build
X-Forwarded-Proto
X-Version
X-B3-TraceId
X-GitHub-Request-Id
X-MS-InvokeApp
RTSS
X-Server-Name
X-D2id
Edge-Cache-Tag
X-Abt-Application-Version
X-Px
X-Debug
AR-CACHE
Ar-Sid
AR-Request-ID
AR-PoweredBy
AR-ATIME
X-Amz-Server-Side-Encryption
SPRequestGuid
X-Cached
Charset
X-NF-Request-ID
X-Navigation-Version
X-Vcap-Request-Id
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-MSEdge-Ref
X-Middleton-Display
Response
X-Middleton-Response
X-Sol
X-Amz-Rid
Display
Pagespeed
X-Accel-Expires
X-Server-ID
Arr-Disable-Session-Affinity
TCN
X-Fastcgi-Cache
Pinterest-Version
X-Pinterest-Rid
X-SharePointHealthScore
X-VARITI-CCR
X-Fastly-Request-ID
X-Cdn
Public-Key-Pins
Nginx-Cache
MS-Author-Via
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Powered-CMS
X-Edge-O15-RID
X-Client-IP
Realpath
Cache-Tag
X-Trace
X-Ser
Access-Control-Request-Method
X-Content-Type
X-Mrf-Item-Lastmod
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Mrf-Section-Lastmod
MRF-Tech
SPIisLatency
X-Amzn-Trace-Id
SPRequestDuration
X-Shard
X-Upstream
X-Jurisdiction
X-Grace
X-Hp-Webp
X-Id
X-DynaTrace-JS-Agent
X-Ezoic-Cdn
Front-End-Https
S
X-Forwarded-For
X-Cache-TTL
X-Hits
Nel
X-Amz-Meta-S3cmd-Attrs
X-T
Fastcgi-Cache
X-Aspnet-Version
X-Recruiting
DynaTrace
X-Element-Page-Cache
X-Node-Name
X-Dw-Request-Base-Id
X-Varnish-Age
X-Content-Digest
X-FTR-Backend
X-Country-Code-Real
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Realm
X-FTR-Expires
X-FTR-Cache-Status
X-Mobile-URL
X-FTR-DC
MicrosoftSharePointTeamServices
ServerID
X-DIS-Request-ID
X-CST
NR-ENABLED
Server-Node
TP-Cache
TP-L2-Cache
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Combine-CSS
X-Frontend
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Generation
X-Goog-Metageneration
Powered
X-Logged-In
Alternate-Protocol
X-Correlation-Id
Server-Name
X-Amz-Apigw-Id
X-Amzn-RequestId
Upgrade-Insecure-Requests
Fastly-Restarts
X-Cache-Hit
X-FTR-Cache-Host
X-Microsite
X-Request-Handler-Origin-Region
Backend-Timing
X-ATS-Timestamp
X-XRDS-LOCATION
X-Page-Id
AMP-Access-Control-Allow-Source-Origin
X-Zen-Fury
X-Request-Processing-Time
X-User-Agent
X-Request-Received
X-Content-Options
X-Content-Security-Policy-Report-Only
Refresh
X-F-Cache
X-XRDS-Location
X-Origin-Server
X-Varnish-Grace
X-Rid
X-Akamai-Edgescape
X-Revision
X-Content-Powered-By
X-LB-Cache
X-B
X-Type
X-Mobile-Rewrite
Arc-Version
PB-RID
PB-PID
X-B3-Sampled
Cache-Status
X-Geo-Country
X-Az
X-AppVersion
X-Activity-Id
X-N
X-Kinsta-Cache
X-TT
X-Cache-Action
X-NWS-LOG-UUID
X-AOL-HN
X-Signature
X-WebKit-CSP-Report-Only
X-Request-Guid
X-Debug-Info
X-B-Cache
Access-Control-Allow-Method
X-Framework
X-Cache-Age
X-Jobs
X-FB-Debug
Actual-Object-TTL
X-Cached-By
X-Instance
X-PHP-Backend
X-Tumblr-User
X-Time
X-Tumblr-Pixel-0
Paypal-Debug-Id
X-App-Environment
X-Tumblr-Pixel
X-Load-Cache
X-Git-Hash
X-URL
X-Tt-Trace-Tag
Fastcgi-Useragent
X-Tt-Trace-Host
X-Amz-Replication-Status
X-Pad
DC
X-Webkit-Csp
X-Varnish-Backend
Host-Header
X-RateLimit-Remaining
X-WA-Info
X-Shield-Request-Id
Host
X-ATG-Version
X-ORACLE-APMCS-TAG
MS-CV
X-ORACLE-APMCS-REQUEST-ID
Surrogate-Key
X-Contextid
X-IPLB-Instance
X-Via-JSL
X-Erf-Bev-Bev
X-Mobile
X-Erf-Bev-Bev-Is-Generated
X-FastCGI-Cache
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Host-Name
Retry-After
NGB
X-Accel-Buffering
X-Response-Served-From
Frame-Options
X-Presslabs-Stats
Payment
Source
X-Cache-NE
FilterID
X-NewRelic-App-Data
X-Region
X-SS-Set-Cookie
X-Varnish-Server
X-Hostname
Eomportal-Instance
X-Cache-2
X-Origin-Response-Time
X-Cache-Key
Tracecode
Xserver
WPE-Backend
X-Seen-By
X-Cacheable-TTL
X-FW-Type
X-FW-Static
X-FW-Serve
X-GeoIP
Filters
X-Rendered-As
X-Is-Bot
X-IPS-LoggedIn
Liferay-Portal
X-FW-Server
X-Srv
X-FW-Hash
X-Cluster
X-Cache-Enabled
Cache-Tv-Group
X-Adobe-Content
X-Varnish-Hostname
X-Adobe-Loc
Server-Info
X-Tumblr-Pixel-1
X-RequestSource
X-Cache-Rule
X-Tumblr-Pixel-2
X-Cache-Operation
X-ProcessESI
X-App-Server
X-RemovedCookies
X-EdgeConnect-Cache-Status
X-TX-ID
X-Cache-TTL-Remaining
Accept-CH
X-Analytics
Cleartype
X-B3-Traceid
X-L-Path
X-FireWall-Port
X-Environment-Context
X-CACHE-KEY
X-Handled-By
X-RTag
Ms-Operation-Id
X-Upgrade-Enabled
X-Source
X-UA
X-Endurance-Cache-Level
X-HTML-Minification-Powered-By
X-Dc
X-Webapp-Samesite-None-Activated-N
From-Origin
Accept-Charset
X-Cache-Server
X-Backend-Name
Accept-CH-Lifetime
X-APP-VERSION
Datacenter
X-UUID
Srv
X-Cache-Var-Map
X-Cache-Var
X-ES-SERVER
GEO-INFO
Meta-Geo
X-CLOUD-TRACE-CONTEXT
X-Path-Route
X-RN-RSRV
X-Section
OT-Force-Account-Verify
X-Access
Selected-Fe
X-Wix-Request-Id
Healthy
X-Tb
X-Timing-Wait
X-Proxy-Build
X-Format
X-Cache-Config
X-PCL
X-Alternate-Cache-Key
Mn-Server-Ip
X-Akamai-Request-ID
X-FC-Vary-Parameters
Cache-Tags
X-Proto
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Content-Age
X-OCL
X-EIG-Tracking-Id
X-ShardId
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Request-Time
X-ShopId
X-Shopify-Generated-Cart-Token
X-Shopify-Stage
X-JoinUs
X-Yottaa-Optimizations
Ec-Rule-Version
X-LJ-Flow-ID
X-BYPASS-REASON
X-Soup
X-Vgn-Hpd-Reason
X-Debug-Cache
X-Akamai-Request-ID2
Akamai-GRN
X-Proxy-Cache-Status
X-Hl-Ver
X-VWS-Id
X-Status
Origin-Edge-Control
X-Human
X-Yottaa-Metrics
X-SaId
X-Say-Cacheable
X-ProxyCache-Key
X-ProxyCache-Status
Origin-Cache-Control
X-AWS-Id
X-Qloud-Router
X-Say-TTL
X-Origin
Node
NGX
X-ServerID
X-Web-Node
X-SayCDN-TTL
X-NYM-Debug-Backend
X-Viewer-Country
X-Detected-As
X-Redis-Cache
X-CCM
Cross-Origin-Window-Policy
Now
Decoy-Debug-Key
Decoy-Debug-Status
X-BCube-Filmed-By
X-Hosted-By
Decoy-Debug-TTL
X-Hyper-Cache
X-Akamai-Transformed
X-Site-Version
X-Loop
X-Locale
X-MP-GENERATED-AT
X-Unique-Id
X-Pubstack
Version
X-Proxy
X-FB-TRIP-ID
X-Storage
X-Generated-By
X-Generated
X-FW-Dynamic
X-TNCMS
X-Www-Served-By
DB-Nickname
X-Time-Microsecs
X-Xfnlog-Site
Webcakes-Region
Webcakes-App-Version
X-Amzn-Remapped-Content-Length
X-Varnish-Hits
X-IP
X-Origin-Hint
X-RCS-CacheZone
X-R9-Blue-Green-Version
Azure-Version
Azure-SlotName
Azure-InstanceId
Azure-RegionName
Azure-SiteName
Webcakes-App-Name
TWC-Locale-Group
TWC-Connection-Speed
S-Rt
X-Daa-Tunnel
TWC-Device-Class
Property-Id
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Privacy
X-Cluster-Node
X-Whom
X-PressLabs-Stats
X-NCache
X-RateLimit-Limit
X-Cache-Control
Cache-Key
X-Ttl
X-UA-Device-Type
X-Cache-Host
Cache
X-Rule
X-Backend-TTL
X-NGENIX-Cache
X-Drupal-Cache-Tags
X-Esi
X-Forwarded-Host
Section-Io-Cache
X-Mode
Webserver
L5d-Success-Class
X-CDN-Forward
X-Info
Cache-Name
X-UnsetCookies
Content-Disposition
Time
Mime-Version
Viewport
X-CS
X-PERF
X-B3-Spanid
Accept-Language
Rt-Fastcgi-Cache
X-Varnish-Cache-Hits
X-ApacheServer
X-Origin-TTL
X-Origin-CC
ServedBy
Uber-Trace-Id
X-Newrelic-Synthetics
Country
X-Cache-Remote
X-VCache
Odigeo-Trace-Id
X-Zipkin-Id
X-Proxied
X-Routing-Service
X-Device-Type
X-Magnolia-Registration
X-Via-Fastly
X-From
X-EC-Lua
X-Uri
Proxy-Connection
X-Cluster-Name
X-Drupal-Cache-Contexts
X-Real-IP
Access-Control-Request-Headers
HitType
X-Microcachable
X-Geo
X-TT-TIMESTAMP
Cf-Ipcountry
Meta-Geo-Continent
MD5-Digest
Rendered-Blocks
Mobile-Detection-Method
Content-Style-Type
Apple-News-Services-Parsed-Url
T-Server
Apple-News-Services-Host
Apple-News-Services-Handled
Apple-News-Services-Request-Url
AsisCache
GEO-REGION-INFO
Fastcgi-X-Cache-Version
Content-Script-Type
BehaviorPad-Version
Machine
X-CF-Lambda-Version
X-S-Cookie
X-ScT
X-Session-Fingerprint
X-Sigma
X-S
X-Rojux
X-Region-Sid
X-Request-UUID
X-Rewrite-Enabled
X-Rocket-Build-Number
X-Sigma-Backend
X-SRCache-Key
X-VG-WebServer
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-VG-WebCache
X-VG-TLSProxy
X-Transaction
X-Trv-Group
X-Twitter-Response-Tags
X-Vdms-Version
X-GeoIP-Country-Code
X-Geo-Header
X-A-Dam
X-A-Dcw
X-A-Dgt
X-A-Wwc
X-A-Ccd
X-A
VivaBuild
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
W
X-Accel-Expires-Debug
X-Aed
X-Destination
X-DPWN-IS-SECURE
X-External-Request-Id
X-G
X-Date
X-Connection-Hash
X-Application
X-ARC
X-B-Cookie
X-CF-Lambda-Fn
Viewtype
X-D
Ohc-File-Size
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
Group
X-Varnish-Beresp-Ttl
X-PHP-Host
X-Labrador-Cache-Channel
X-Cache-Time
User-Cache-Control
X-Nc
Geo-Info
X-C
Filterid
HA-Ipaddr
Ha-Gx-Prefs
Fastly-SWR
X-Rebelmouse-Surrogate-Control
Locid
IsBot
X-Hit
X-Rebelmouse-Cache-Control
X-Clientip
X-CUA
Environment
X-Eu-Site
X-Logging-Id
Fastly-SIE
Cache-Hits
Countrycode
CDCHOST
X-Developers
Powered-By
X-Distil-CS
Fastly-Soc-X-Request-Id
X-CGP
X-Var-Ttl
X-Thanos
X-SIPLIST1
X-VC-Cache
X-TrackingId
X-Backend-State
X-Bip
X-Agile-Id
X-WebServer
X-Agile
X-App-Name
X-Cache-Expired-At
X-Agile-Age
X-Cache-Debug
X-GoCache-CacheStatus
Fastly-SSL
X-Fetched-On
X-Air-Hostname
X-Gamma-Serve
X-GeoIP-City
Web-Mar-Node
X-Hash
X-Has-Esi
X-Generated-In
X-Gen-Mode
X-Distributor
X-Cms-Context
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Cache-Tags
X-Hnp-Log
X-Core-Mission
X-Block-Status
X-Azure-Ref
X-Epic-Correlation-Id
X-Dispatcher-Server
X-Debug-Log
X-Debug-Cookies
X-Auto-Login
X-Ms-Request-Id
X-TH-Server
X-Trace-Id
X-Tumblr-Pixel-3
X-Up
X-Swa-Ws
X-SVT-ORM-VERSION
X-Request-URI
X-Servername
X-SVT-ORM-RULES
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Cdn-Srv
X-OVcl
X-OVcl-Cache
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-Variation
X-Varnish-Authentication
X-VServer
X-RateLimit-Limit-Second
X-Proxy-Upstream
X-Li-Pop
X-LI-Proto
X-LI-UUID
We-Hiring
X-Li-Fabric
X-JWT-State
X-IN-APIGATEWAYSSL
X-Instart-Isnd
X-Is-Gdpr
X-Ms-Version
X-Nginx-Cache-Key
X-Origin-Expires
X-Owner
X-Platform-Server
X-Origin-Date
X-NX-Host
X-No-Session
X-NodeID
X-NU-AKA-ACS-Version
X-IN-APIGATEWAY
X-RateLimit-Remaining-Second
V-Age
Server-Int
Server-ID
Country-Code
Server-Cache-Control
Platform
Server-Surrogate-Control
AKAMAI
True-Client-Country-4JS
Pragrma
Adler-Geo
Fastly-Backend-Name
Locale
Request-EU
Is-Eu
Mail-Subject
Kp-EeAlive
RNT-Machine
IBM-Web2-Location
Request-Country
RNT-Time
Gh-Request-Id
Heartbleed
Cache-Host
X-Edge-Location
Ohc-Cache-HIT
X-Core-Value
FNAC-ModuleRouting
X-FW-Version
X-Level-Front-Cache
X-Generation-Time
X-Generated-On
X-Req
X-Reboot
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Debug-Cache-Expiry
Cdnsip
Cdncip
PFcat
X-Matched-Rule
X-Thinkindot-L3
X-Irp-Debug
X-Micro-Cache
X-Fastly-Cache
X-Clara-WADP
X-Cache-Info
X-Cache-URL
X-WADP-Cache
X-We-Are-Hiring
Wxu-Next-Commit
ServerName
Wxu-Next-Hostname
Wxu-Next-Region
X-Webstats-RespID
X-Cache-Bucket
X-BBXSRF
X-Trafficlayer-App-Scope
X-Trafficlayer-App-Version
Server-Host
X-Trafficlayer-App-Name
X-Service
X-ServiceProvider
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Memcached
X-Server-W
X-AK-Request-ID
S-Cnection
X-TT-LOGID
Thinkindot-Control
X-VHOST
X-UPSTREAM-Address
X-Response-By
X-S-Maxage
X-Lb-Id
X-SERVER
X-Old-Content-Length
X-App-Version
X-NC
X-Nginx-Cache
RequestId
X-Refresh
X-Varnish-Cacheable
X-Wa
X-Render-Time
X-Sucuri-ID
X-Oss-Object-Type
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-Cache-Backend
X-Oss-Storage-Class
X-Oss-Request-Id
X-User
Powered-By-ChinaCache
X-Developer
X-Tec-Api-Root
User-Agent
X-Node-Id
X-Tec-Api-Version
X-Internal-Host
X-Key
X-Tec-Api-Origin
X-Parent-Response-Time
X-Cache-Status-Check
X-Ua-Device
X-CSRF-TOKEN
Origin
X-Sn-Servicetimems
X-Cache-Grace
X-Sucuri-Cache
X-Device-Os
X-CSRF-Token
X-LAGOON
SRV
X-Cdn-Origin
X-Pjax-Url
X-NWS-UUID-VERIFY
X-Tb-Optimization-Total-Bytes-Saved
X-Ocache
X-Location
X-Pf-Uncompressing
X-CF-Powered-By
Hostname
X-Ua
Geoip-City
X-TA-CDN-Provider
Geoip-Latitude
X-Via-CDN
On-Server
A
X-NGINX-Cache
PICS-Label
X-MSEdge-Flight
ProcessTime
X-MSEdge-Features
X-Request-Host
Memory
GeoIp-Country-Code
Cloudfront-Viewer-Country
X-B3-Parentspanid
TTL
X-BACKEND-TTL
X-Cdn-Forward
X-COUNTRY
X-Vcl-Version
X-Server-IP
X-Litespeed-Cache
X-Webkit-CSP
Cdn
X-Unique-ID
Resin-Trace
X-Varnish-URL
X-Varnish-Ttl
X-Servedbyhost
XServer
X-TIME
Media-Length
Dnion-Transfer-Encoding
M-TraceId
SN
Tcn
X-Cdn-Request-ID
X-Rocket-Nginx-Bypass
X-Correlation-ID
X-B3-SpanId
X-FORWARDED-FOR
HostName
Host-ID
X-HS-Status
X-Slack-Backend
X-ServedByHost
CACHE
X-Ratelimit-Remaining
X-Beluga-Node
X-Beluga-Cache-Status
X-Beluga-Record
X-Beluga-Response-Time
X-Action
X-Beluga-Trace
X-Beluga-Status
Who
X-Cache-FS-Status
Pramga
X-Cache-Ttl
X-Dispatch
Arc-Country
X-PAYTM-SRV-ID
X-Processor
X-Server-Time
X-ND-Cache
X-Skip-Cache
X-DB
X-RSL
X-DI
X-Via-Ucdn
X-RPM
X-RPS
X-DSS
X-DW
NtCoent-Length
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Io-Id
X-Fastly-Country-Code
Cdn-Request-Time
Section-Origin-Responded
Cdn-Host
X-VCL-Version
Fastly-Drupal-HTML
X-Reqid
X-Served-From
X-Edge-Server
X-DC
X-Dynatrace-Js-Agent
X-DevSite-Last-Modified
X-Hello
X-Flog
X-ABtesting
Esi-Enabled
N-Cache
X-Bc-Bl
X-Varnish-Url
Ttl
Pics-Label
Amp-Access-Control-Allow-Source-Origin
GeoIP-Country-Code
X-AIR-PT
X-VarnishDD-TTL
MIME-Version
Fusion-Deployment-Id
X-Sucuri-Id
X-LiteSpeed-Cache-Control
X-Oracle-Dms-Rid
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
GeoIP-City
X-Policy
GeoIP-Latitude
X-Adobe-Source
CF-Cached-On
X-Backend-Host
X-FPC
X-Bc
X-PF-Uncompressing
X-Zone
X-Request-Start
X-APP
X-Ratelimit-Limit
X-Azure-Ref-OriginShield
X-HostName
Trailer
X-Ruxit-Js-Agent
Rt-Proxy-Cache
WebServer
X-PJAX-URL
X-SRV
X-Fastly-Backend-Reqs
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-From
Cache-Cookie-Set-Idcheck
X-BE
X-Dynatrace
Processtime
X-Scheme
X-Fmm-Version
X-Amzn-Remapped-Date
X-Amzn-Remapped-Connection
Servername
X-Newrelic-App-Data
X-Swift-Error
X-WA
X-ID
X-BC
Magicmarker
X-Method
Cache-Provider
Cteonnt-Length
X-Fpc
FSS-Cache
FSS-Proxy
X-ZONE
X-Frame-Option
X-WR-MODIFICATION
X-LB-ID
X-Branch-Name
X-SN
Requestid
L
X-Cache-Id
X-Esi-Check
CDN
X-Snapshot-Date
X-StackifyID
Dynatrace
CF-IPCountry
X-CACHE-AGE
Release
V-Cache
X-Tid
X-Fastly-Cache-Hits
WZWS-RAY
X-Cc-Req-Id
D-Cc-Upstream
X-Compress-Hint
Warning
X-Cc-Via
X-SB
Ohc-Response-Time
X-Gzip
Lb
X-SD-PageType
X-Aicache-OS
X-VC
Sid
X-Request-Url
SD-X-WS
X-Cache-NGX
X-Litespeed-Cache-Control
Load-Balancing
X-Node-ID
X-VCT
SID
X-GEO
LB
X-ECACHE
X-Instart-Info
X-Nananana
X-Be
X-Apw-Access-Action
X-Worker
X-Powered-Y
X-Apw-Access-Object
X-Apw-Access-Token
X-Apw-Hits
X-ElasticPress-Search
X-Request-URL
X-Check-Cacheable
X-WPE-Loopback-Upstream-Addr
Cneonction
X-Svr
WP-Super-Cache
X-Varnish-Beresp-TTL
X-Fastly-Cache-Status
X-App