Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
CF-RAY
Link
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Request-ID
X-Cache-Status
X-Generator
Content-Security-Policy-Report-Only
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-Template
X-Language
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
Status
X-Content-Security-Policy
Upgrade
X-CDN
Content-Encoding
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Xss-Protection
X-Kinja-Server-Push
Keep-Alive
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
P3p
Xkey
X-Pass-Why
X-Cache-Group
X-AH-Environment
X-Envoy-Upstream-Service-Time
CF-Ray
X-Backend
X-Via
X-Ua-Compatible
X-Age
X-Server
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Server-Powered-By
X-Page-Speed
X-Pingback
X-Ws-Request-Id
EagleId
X-Proxy-Cache
X-Nginx-Cache-Status
X-Hacker
X-UA-Device
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
Cf-Railgun
Grace
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Amz-Version-Id
X-LiteSpeed-Cache
Report-To
X-Rq
X-Dns-Prefetch-Control
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Server-Id
X-WebKit-CSP
X-Host
X-Device
X-OneAgent-JS-Injection
EagleEye-TraceId
X-Origin-Cache
X-Response-Time
X-Node
Content-Location
X-Ac
Surrogate-Control
X-Vhost
X-Readtime
X-Cloud-Trace-Context
Request-Id
X-Backend-Server
X-Dispatcher
X-Origin-Upstream-Status
X-Cnection
X-Application-Context
X-HW
X-ORACLE-DMS-ECID
Fusion-Source
Fusion-Component-Id
Fusion-Content-Id
Fusion-Template-Id
Fusion-Content-Source
X-Cache-Lookup
X-ORACLE-DMS-RID
X-DataDome
X-Mod-Pagespeed
NEL
Rating
Edge-Control
X-Rack-Cache
X-Country
X-Akam-SW-Version
X-Clacks-Overhead
Pinterest-Generated-By
X-Ruxit-JS-Agent
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Allow
X-DynaTrace
X-Country-Code
X-Instart-Request-ID
Accept-Ch
X-Varnish-TTL
X-TTL
X-Goog-Hash
X-Vname
X-TtlSet
X-PC
X-FTR-Request-ID
X-ESI
Verso
Accept-Ch-Lifetime
X-Powered-By-Plesk
Service-Worker-Allowed
Content-MD5
X-Url
X-B3-TraceId
X-Forwarded-Proto
X-MS-InvokeApp
X-Version
X-GitHub-Request-Id
X-Kinja-Revision
X-Cdn-Fetch
X-Use-Magma
X-Kinja-Server
X-Exp-Id
X-Kinja
X-Kinja-Build
X-Exp-Variant
X-GoogleNews-Bot
Edge-Cache-Tag
RTSS
AR-ATIME
AR-PoweredBy
AR-CACHE
Ar-Sid
X-D2id
AR-Request-ID
X-Px
X-Debug
X-Server-Name
SPRequestGuid
X-Amz-Server-Side-Encryption
X-Abt-Application-Version
Charset
X-Vcache
X-NF-Request-ID
X-Accel-Expires
X-Cached
X-MSEdge-Ref
X-Amz-Rid
Response
Display
X-Middleton-Display
X-Middleton-Response
Pagespeed
X-Sol
Arr-Disable-Session-Affinity
X-Vcap-Request-Id
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Navigation-Version
TCN
X-Fastcgi-Cache
X-Powered-CMS
X-Pinterest-Rid
Pinterest-Version
X-SharePointHealthScore
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Trace
X-Cdn
X-VARITI-CCR
Realpath
X-Client-IP
Public-Key-Pins
Cache-Tag
Access-Control-Request-Method
X-Ser
X-Fastly-Request-ID
MS-Author-Via
S
Nginx-Cache
X-Shard
X-DynaTrace-JS-Agent
SPRequestDuration
SPIisLatency
X-Upstream
X-Id
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Mrf-Section-Lastmod
MRF-Tech
X-Mrf-Item-Lastmod
X-Hp-Webp
X-Ezoic-Cdn
X-Content-Type
X-Forwarded-For
X-Grace
X-Amzn-Trace-Id
X-T
X-Amz-Meta-S3cmd-Attrs
Nel
X-Edge-O15-RID
DynaTrace
X-Recruiting
X-Hits
Front-End-Https
Fastcgi-Cache
X-Aspnet-Version
X-Varnish-Age
ServerID
X-Server-ID
X-ASPNET-VERSION
X-Dw-Request-Base-Id
MicrosoftSharePointTeamServices
X-Mobile-URL
X-Element-Page-Cache
X-DIS-Request-ID
X-Node-Name
X-Cache-TTL
X-Jurisdiction
NR-ENABLED
X-Content-Digest
X-FTR-Expires
X-HS-Content-Id
X-FTR-Cache-Status
X-Country-Code-Real
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Hub-Id
X-Frontend
Powered
X-Goog-Storage-Class
X-GUploader-UploadID
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
Server-Node
X-FTR-Balancer
X-FTR-Backend
X-FTR-Realm
X-FTR-DC
X-FTR-Backend-Server
TP-L2-Cache
TP-Cache
Alternate-Protocol
Server-Name
X-Logged-In
X-Correlation-Id
X-Request-Received
X-Request-Processing-Time
X-Microsite
AMP-Access-Control-Allow-Source-Origin
X-Request-Handler-Origin-Region
Backend-Timing
X-ATS-Timestamp
Upgrade-Insecure-Requests
X-Webkit-Csp
X-Cache-Hit
X-Content-Security-Policy-Report-Only
X-Amz-Apigw-Id
Refresh
X-Amzn-RequestId
X-Content-Options
X-Origin-Server
X-Rid
X-Revision
X-Akamai-Edgescape
X-Page-Id
X-Type
X-User-Agent
X-F-Cache
X-XRDS-LOCATION
X-XRDS-Location
X-CST
X-Varnish-Grace
X-Zen-Fury
Fastly-Restarts
X-Content-Powered-By
X-B3-Sampled
X-B
X-LB-Cache
X-URL
X-Shield-Request-Id
X-Geo-Country
X-Az
X-Activity-Id
X-AppVersion
X-FTR-Cache-Host
PB-PID
X-N
PB-RID
Cache-Status
X-Mobile-Rewrite
Arc-Version
X-Kinsta-Cache
X-Webapp-Samesite-None-Activated-N
X-Pad
X-Cache-Age
X-TT
X-AOL-HN
X-WebKit-CSP-Report-Only
X-Instance
X-Debug-Info
X-Tumblr-User
X-Tumblr-Pixel-0
X-Framework
X-Jobs
X-Tumblr-Pixel
Paypal-Debug-Id
Actual-Object-TTL
X-Cache-Action
X-Time
X-Signature
X-B-Cache
X-App-Environment
X-Load-Cache
X-RateLimit-Remaining
DC
X-FB-Debug
Access-Control-Allow-Method
X-Analytics
X-Request-Guid
X-PHP-Backend
X-Cached-By
X-Git-Hash
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Varnish-Backend
Surrogate-Key
X-Tt-Trace-Tag
X-Ruxit-Js-Agent
X-Tt-Trace-Host
X-Amz-Replication-Status
X-Contextid
Host-Header
MS-CV
Fastcgi-Useragent
X-IPLB-Instance
FilterID
X-ATG-Version
X-SS-Set-Cookie
X-WA-Info
X-Cache-Key
X-Cluster
Host
X-Response-Served-From
X-Accel-Buffering
Tracecode
NGB
WPE-Backend
X-Mobile
X-Cache-NE
X-Varnish-Server
X-Host-Name
X-Kong-Upstream-Latency
X-Region
Payment
Xserver
X-Cache-2
Eomportal-Instance
Source
X-Kong-Proxy-Latency
X-Srv
Frame-Options
X-FW-Serve
X-Tumblr-Pixel-2
X-FW-Server
Filters
X-Varnish-Hostname
X-FW-Hash
X-Cache-Operation
Cache-Tv-Group
X-FW-Static
X-Cache-Rule
X-Tumblr-Pixel-1
X-ORACLE-APMCS-REQUEST-ID
X-GeoIP
X-IPS-LoggedIn
X-ORACLE-APMCS-TAG
X-Via-JSL
X-FW-Type
X-Adobe-Content
X-Adobe-Loc
X-Cache-Enabled
X-Ttl
X-RequestSource
X-Is-Bot
X-Cacheable-TTL
X-NewRelic-App-Data
X-Rendered-As
X-Origin-Response-Time
X-TX-ID
X-Hostname
X-EdgeConnect-Cache-Status
X-Presslabs-Stats
X-NWS-LOG-UUID
Cleartype
X-FastCGI-Cache
X-Seen-By
Retry-After
X-Cache-TTL-Remaining
X-VCache
Server-Info
Accept-CH
X-ProcessESI
X-RemovedCookies
X-B3-Traceid
X-UA
Liferay-Portal
X-Dc
Cache
Ms-Operation-Id
Datacenter
X-RTag
X-Source
X-HTML-Minification-Powered-By
X-Cache-Control
X-L-Path
X-Environment-Context
X-Upgrade-Enabled
X-FireWall-Port
From-Origin
X-Cache-Server
Healthy
X-Endurance-Cache-Level
X-App-Server
X-CACHE-KEY
X-PressLabs-Stats
Accept-CH-Lifetime
X-RateLimit-Limit
X-Handled-By
X-Rule
Version
X-Status
X-Backend-Name
X-RN-RSRV
Meta-Geo
X-Cache-Var
X-Cache-Var-Map
X-Path-Route
X-ES-SERVER
X-Request-Time
X-Oneagent-Js-Injection
X-APP-VERSION
X-Access
X-Timing-Wait
Selected-Fe
X-Proxy-Build
X-Format
X-Section
X-Tb
X-Sorting-Hat-ShopId
X-EIG-Tracking-Id
OT-Force-Account-Verify
X-BYPASS-REASON
X-Content-Age
X-Alternate-Cache-Key
X-Human
X-Shopify-Generated-Cart-Token
X-ShopId
X-ProxyCache-Key
X-Shopify-Stage
Mn-Server-Ip
X-PCL
X-ShardId
X-ProxyCache-Status
Azure-RegionName
Azure-SiteName
Azure-SlotName
Azure-InstanceId
Azure-Version
X-Sorting-Hat-PodId
Akamai-GRN
Cache-Tags
Srv
X-Goog-Meta-Goog-Reserved-File-Mtime
X-OCL
X-Origin
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-AWS-Id
X-Time-Microsecs
Decoy-Debug-Key
DB-Nickname
Node
X-Akamai-Request-ID
X-SaId
X-Akamai-Request-ID2
X-Qloud-Router
X-Cache-Host
X-VWS-Id
X-Redis-Cache
Decoy-Debug-TTL
Origin-Edge-Control
X-Proto
X-Vgn-Hpd-Reason
X-LJ-Flow-ID
Now
X-ServerID
X-JoinUs
Decoy-Debug-Status
X-Hl-Ver
X-Hyper-Cache
X-UUID
NGX
X-MP-GENERATED-AT
X-Proxy
X-Viewer-Country
X-Cluster-Node
Origin-Cache-Control
X-Pubstack
X-Generated-By
X-Debug-Cache
X-Storage
X-Wix-Request-Id
TWC-Device-Class
TWC-Connection-Speed
Property-Id
TWC-GeoIP-Country
X-Generated
X-Soup
X-Web-Node
X-BCube-Filmed-By
X-Cache-Config
X-FW-Dynamic
X-Hosted-By
X-Proxy-Cache-Status
X-RCS-CacheZone
X-Www-Served-By
S-Rt
X-FC-Vary-Parameters
X-Site-Version
Webcakes-App-Version
Webcakes-App-Name
TWC-Privacy
TWC-Locale-Group
Webcakes-Region
X-CCM
X-Origin-Hint
X-Varnish-Hits
X-NYM-Debug-Backend
TWC-GeoIP-LatLong
Cross-Origin-Window-Policy
X-Xfnlog-Site
X-SayCDN-TTL
X-Say-Cacheable
X-Locale
X-R9-Blue-Green-Version
GEO-INFO
X-Akamai-Transformed
X-Say-TTL
X-FB-TRIP-ID
Accept-Charset
Ec-Rule-Version
X-Amzn-Remapped-Content-Length
X-Detected-As
X-IP
L5d-Success-Class
X-TNCMS
X-Loop
X-CS
X-NCache
Cache-Name
Viewport
X-Trafficlayer-App-Scope
X-Esi
X-Trafficlayer-App-Name
Webserver
X-Drupal-Cache-Tags
X-Unique-Id
Uber-Trace-Id
Cache-Key
X-UA-Device-Type
Time
X-Cache-Remote
X-UnsetCookies
Mime-Version
X-Mode
X-From
Accept-Language
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Forwarded-Host
X-Origin-TTL
X-Origin-CC
Country
X-Backend-TTL
X-Cluster-Name
Rt-Fastcgi-Cache
X-Info
Odigeo-Trace-Id
X-CDN-Forward
X-Newrelic-Synthetics
X-Microcachable
X-TT-TIMESTAMP
X-Whom
X-Drupal-Cache-Contexts
X-NGENIX-Cache
X-CLOUD-TRACE-CONTEXT
X-Magnolia-Registration
X-Varnish-Cache-Hits
X-B3-Spanid
X-PERF
X-ApacheServer
X-Geo
ServedBy
X-Edge-Location
X-Daa-Tunnel
Content-Disposition
X-UPSTREAM-Address
X-EC-Lua
Proxy-Connection
Ohc-Cache-HIT
X-Device-Type
Ohc-File-Size
X-Routing-Service
X-Proxied
X-Zipkin-Id
X-Via-Fastly
X-No-Session
Cf-Ipcountry
X-Uri
X-B-Cookie
X-Application
Rendered-Blocks
X-ARC
X-A-Dgt
Meta-Geo-Continent
X-A-Dcw
X-A-Dam
W
Mobile-Detection-Method
X-A-Ccd
VivaBuild
Viewtype
X-Aed
MD5-Digest
X-Accel-Expires-Debug
X-A-Wwc
X-A
T-Server
Machine
X-G
X-Transaction
Apple-News-Services-Handled
X-Trv-Group
Apple-News-Services-Host
X-Nc
Content-Style-Type
X-SRCache-Key
X-ScT
X-CF-Lambda-Fn
X-Session-Fingerprint
X-Sigma
X-Sigma-Backend
X-Twitter-Response-Tags
Apple-News-Services-Parsed-Url
AsisCache
X-Vtex-Remote-Cache
BehaviorPad-Version
Content-Script-Type
Xc-Version
X-Vtex-Processado-Em
X-VG-WebServer
Apple-News-Services-Request-Url
X-Vdms-Version
X-VG-TLSProxy
X-VG-WebCache
X-S
X-S-Cookie
X-Geo-Header
X-GeoIP-Country-Code
GEO-REGION-INFO
X-Destination
X-External-Request-Id
X-D
X-Rojux
X-DPWN-IS-SECURE
X-Connection-Hash
X-Rewrite-Enabled
X-Rocket-Build-Number
X-Request-UUID
Fastcgi-X-Cache-Version
X-Region-Sid
X-CF-Lambda-Version
X-Date
X-C
HitType
X-Labrador-Cache-Channel
X-PHP-Host
Geo-Info
User-Cache-Control
Environment
Fastly-Soc-X-Request-Id
HA-Ipaddr
IsBot
Locid
Gh-Request-Id
Ha-Gx-Prefs
X-CGP
X-SIPLIST1
X-Thanos
X-Render-Time
X-Logging-Id
X-Eu-Site
X-Hit
X-TrackingId
X-Tumblr-Pixel-3
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-WebServer
X-VC-Cache
X-Varnish-Authentication
X-Epic-Correlation-Id
X-Distil-CS
X-Agile-Id
X-App-Name
X-Agile-Age
X-Agile
Server-Cache-Control
Server-Surrogate-Control
X-Auto-Login
X-Bip
X-CUA
X-Developers
CDCHOST
X-Cache-Debug
X-Cache-ASPX
Powered-By
X-Contensis-Viewer-Groups
Section-Io-Cache
X-Cache-Time
X-Cache-Backend
X-Fetched-On
X-Gamma-Serve
X-Fastly-Cache
X-Distributor
X-Debug-Log
X-Dispatcher-Server
X-Gen-Mode
X-IN-APIGATEWAYSSL
X-GeoIP-City
X-App-Version
X-Generation-Time
X-IN-APIGATEWAY
X-Generated-In
X-Debug-Cookies
X-Hnp-Log
X-Debug-Cache-Expiry
X-Block-Status
X-Cache-Bucket
X-BBXSRF
X-Backend-State
X-AK-Request-ID
X-Azure-Ref
X-Cache-Info
X-Cache-URL
X-Instart-Isnd
X-Debug-Cache-Fetch
X-Core-Mission
X-Cms-Context
X-Cdn-Srv
X-Clara-WADP
X-Debug-Cache-Store
X-Micro-Cache
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
Cache-Host
X-Sucuri-Cache
X-Request-URI
X-Server-W
X-Swa-Ws
X-Trace-Id
X-Webstats-RespID
Access-Control-Request-Headers
X-WADP-Cache
X-Urbn-Site-Id
X-TT-LOGID
X-Urbn-Context-Path
X-Real-IP
X-RateLimit-Remaining-Second
X-NodeID
X-NX-Host
X-Nginx-Cache-Key
X-Ms-Version
Web-Mar-Node
X-Ms-Request-Id
X-Origin-Date
X-Origin-Expires
X-Proxy-Upstream
X-RateLimit-Limit-Second
X-Owner
X-OVcl-Cache
X-OVcl
X-Irp-Debug
X-Hash
Cdncip
Cdnsip
Heartbleed
We-Hiring
Kp-EeAlive
AKAMAI
Country-Code
Server-ID
V-Age
True-Client-Country-4JS
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
Mail-Subject
Locale
Request-EU
RNT-Machine
RNT-Time
Server-Int
X-Varnish-Beresp-Ttl
Request-Country
X-GoCache-CacheStatus
Server-Host
X-Nginx-Cache
X-Service
X-Matched-Rule
X-ServiceProvider
X-Level-Front-Cache
X-Req
X-Old-Content-Length
X-Key
X-Generated-On
PFcat
X-Thinkindot-L3
X-User
X-TH-Server
X-Rebelmouse-Cache-Control
X-LI-UUID
X-VServer
X-We-Are-Hiring
X-Clientip
Fastly-SWR
Fastly-SIE
Countrycode
X-LI-Proto
X-Li-Pop
IBM-Web2-Location
Fastly-SSL
X-Trafficlayer-App-Version
Fastly-Backend-Name
X-Servername
Memcached
X-Li-Fabric
X-FW-Version
X-Rebelmouse-Surrogate-Control
FNAC-ModuleRouting
ServerName
X-Core-Value
Wxu-Next-Region
X-TA-CDN-Provider
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
Wxu-Next-Hostname
Thinkindot-Control
Wxu-Next-Commit
X-JWT-State
X-Is-Gdpr
X-Has-Esi
X-Location
X-Internal-Host
X-Variation
X-Lb-Id
X-Up
X-Reboot
X-S-Maxage
X-Cache-Tags
X-NU-AKA-ACS-Version
Is-Eu
Platform
Cache-Hits
Adler-Geo
X-SERVER
X-Platform-Server
X-Response-By
RequestId
X-Air-Hostname
X-Refresh
X-B3-Parentspanid
X-Tb-Optimization-Total-Bytes-Saved
X-Cache-Expired-At
X-Var-Ttl
X-Parent-Response-Time
Group
X-Cdn-Forward
Filterid
X-CF-Powered-By
S-Cnection
X-BACKEND-TTL
ProcessTime
X-Tec-Api-Origin
X-Tec-Api-Root
X-B3-SpanId
X-Tec-Api-Version
Pragrma
X-CSRF-TOKEN
Memory
X-Pjax-Url
Powered-By-ChinaCache
X-Server-IP
X-CSRF-Token
User-Agent
Origin
X-NC
X-Wa
TTL
SRV
X-Sucuri-ID
X-Unique-ID
X-Correlation-ID
X-Ua
X-Vcl-Version
X-Cdn-Request-ID
X-Pf-Uncompressing
X-Varnish-Cacheable
Media-Length
Geoip-Latitude
X-NWS-UUID-VERIFY
X-COUNTRY
Geoip-City
PICS-Label
GeoIp-Country-Code
X-NGINX-Cache
X-Via-CDN
X-Sucuri-Id
X-Developer
Dnion-Transfer-Encoding
X-Cache-Grace
X-Ocache
X-Webkit-CSP
X-LAGOON
X-Device-Os
SN
X-Rocket-Nginx-Bypass
X-Litespeed-Cache
X-Servedbyhost
X-Cdn-Origin
X-Sn-Servicetimems
X-Via-Ucdn
X-Reqid
X-Varnish-Ttl
X-AIR-PT
M-TraceId
X-Node-Id
On-Server
Esi-Enabled
XServer
X-TIME
X-Planisys-CDN-TTL
A
X-MSEdge-Features
X-Planisys-CDN-Rules
X-MSEdge-Flight
X-HS-Status
X-Policy
X-Planisys-CDN-Cache
X-Request-Host
X-FORWARDED-FOR
X-Cache-Status-Check
X-Azure-Ref-OriginShield
Cloudfront-Viewer-Country
Hostname
X-Request-Start
Cdn
X-Oss-Object-Type
HostName
X-Oss-Storage-Class
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-Beluga-Record
X-Cache-Ttl
X-Beluga-Node
X-Beluga-Cache-Status
Resin-Trace
X-Beluga-Status
X-Fastly-Country-Code
X-Beluga-Response-Time
X-Beluga-Trace
Rt-Proxy-Cache
Who
X-VHOST
X-Ftr-Cache-Host
X-ServedByHost
Magicmarker
X-Varnish-URL
CF-Cached-On
Pics-Label
X-Method
X-Ratelimit-Remaining
Host-ID
NtCoent-Length
Cteonnt-Length
X-VCL-Version
X-APP
GeoIP-Country-Code
X-Oracle-Dms-Rid
Tcn
MIME-Version
X-Fastly-Backend-Reqs
X-Slack-Backend
X-Zone
Ttl
GeoIP-Latitude
X-Bc
X-Varnish-Url
X-DC
Load-Balancing
X-LiteSpeed-Cache-Control
X-Action
X-VarnishDD-TTL
GeoIP-City
X-PF-Uncompressing
X-Svr
CACHE
Ohc-Response-Time
X-Newrelic-App-Data
X-Be
X-RPS
X-RPM
X-DW
X-SRV
Amp-Access-Control-Allow-Source-Origin
Pramga
Arc-Country
X-DSS
X-DI
Vix-Hermes-Req-Id
X-Swift-Error
X-PJAX-URL
X-Ratelimit-Limit
X-DB
X-Cache-FS-Status
X-Ftr-Request-Id
X-RSL
DSUID
X-Server-Time
X-Skip-Cache
X-Processor
WebServer
X-PAYTM-SRV-ID
X-Dispatch
X-MServer
X-VCT
X-HostName
Release
Processtime
Fastly-Drupal-HTML
X-Tid
X-Dynatrace
X-FPC
X-Hello
X-ND-Cache
X-Hp-Ccpa-Warning
X-ABtesting
X-Flog
X-BE
X-Dynatrace-Js-Agent
X-WR-MODIFICATION
Servername
X-Served-From
X-Configured-By
X-Edge-Server
Cdn-Host
X-ID
Cdn-Request-Time
X-DevSite-Last-Modified
Cache-Provider
X-Aicache-OS
X-Frame-Option
CDN
X-Branch-Name
X-LB-ID
X-Snapshot-Date
X-Upstream-Ct
X-StackifyID
Lfy
X-WA
X-Bc-Bl
Pagetype
N-Cache
Dynatrace
X-ZONE
X-Upstream-Ht
X-SD-PageType
X-Fastly-Cache-Hits
Requestid
X-Ftr-Dc
X-Ftr-Backend
X-Ftr-Realm
X-Ftr-Balancer
X-Ftr-Backend-Server
SD-X-WS
CF-IPCountry
X-CACHE-AGE
X-Apw-Access-Action
X-Apw-Access-Object
V-Cache
X-Backend-Host
X-Varnish-Beresp-TTL
X-Amzn-Remapped-Connection
X-Edge-IP
X-Amzn-Remapped-Date
X-Apw-Access-Token
X-Compress-Hint
Proxy-Firewall
X-Cache-Id
X-SN
D-Cc-Upstream
X-Cc-Req-Id
Warning
L
X-SB
X-VC
X-Apw-Hits
X-Cc-Via
X-Request-Url
X-BC
X-WPE-Loopback-Upstream-Addr
Section-Io-Origin-Status
Section-Io-Id
Section-Io-Origin-Time-Seconds
X-ElasticPress-Search
Section-Origin-Responded
WZWS-RAY
X-Litespeed-Cache-Control
X-App
X-Release
WP-Super-Cache
X-Worker
X-Check-Cacheable
X-Powered-Y
X-Fastly-Cache-Status
X-Request-URL
Lb
X-Via-NSCOPI
Backend-Name
Correlation-Id
X-ServerName