Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
CF-RAY
Link
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Request-ID
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-DNS-Prefetch-Control
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
Status
Upgrade
X-Content-Security-Policy
X-CDN
Content-Encoding
Access-Control-Expose-Headers
P3p
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Xss-Protection
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
X-Pass-Why
Xkey
X-Cache-Group
X-AH-Environment
X-Envoy-Upstream-Service-Time
X-Via
X-Backend
CF-Ray
X-Server
X-Age
X-Ua-Compatible
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Server-Powered-By
X-Page-Speed
X-Ws-Request-Id
X-Pingback
EagleId
X-Proxy-Cache
X-Hacker
X-Nginx-Cache-Status
X-UA-Device
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
Cf-Railgun
Grace
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Amz-Version-Id
Report-To
X-LiteSpeed-Cache
X-Rq
X-Server-Id
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-OneAgent-JS-Injection
X-Host
X-Device
X-WebKit-CSP
X-Origin-Cache
EagleEye-TraceId
X-Response-Time
X-Node
X-Ac
Content-Location
Surrogate-Control
X-Vhost
X-Readtime
X-Backend-Server
Request-Id
X-Cloud-Trace-Context
X-Dispatcher
X-Dns-Prefetch-Control
X-Origin-Upstream-Status
X-Cnection
X-Application-Context
X-HW
X-ORACLE-DMS-ECID
X-Cache-Lookup
Fusion-Content-Source
Fusion-Component-Id
Fusion-Source
Fusion-Content-Id
Fusion-Template-Id
X-ORACLE-DMS-RID
X-Ruxit-JS-Agent
NEL
X-DataDome
X-Mod-Pagespeed
Rating
X-Rack-Cache
Edge-Control
X-Country
X-Akam-SW-Version
X-Clacks-Overhead
Pinterest-Generated-By
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Allow
X-TTL
X-Country-Code
Accept-Ch
X-DynaTrace
X-Instart-Request-ID
X-Varnish-TTL
X-FTR-Request-ID
X-Goog-Hash
X-Vname
X-TtlSet
X-PC
X-ESI
Verso
Accept-Ch-Lifetime
Content-MD5
X-Powered-By-Plesk
Service-Worker-Allowed
X-Url
X-B3-TraceId
X-Forwarded-Proto
X-Version
X-MS-InvokeApp
X-GitHub-Request-Id
X-Use-Magma
X-Kinja
X-Cdn-Fetch
X-Exp-Id
X-Kinja-Server
X-Exp-Variant
X-GoogleNews-Bot
X-Kinja-Build
X-Kinja-Revision
Edge-Cache-Tag
RTSS
X-D2id
X-Debug
X-Server-Name
X-Px
Ar-Sid
X-Abt-Application-Version
AR-ATIME
AR-Request-ID
AR-PoweredBy
AR-CACHE
X-Vcache
X-Amz-Server-Side-Encryption
SPRequestGuid
Charset
X-NF-Request-ID
X-Cached
X-Accel-Expires
X-Fastcgi-Cache
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
Response
Display
X-Sol
X-Middleton-Display
Pagespeed
X-Middleton-Response
X-MSEdge-Ref
Arr-Disable-Session-Affinity
X-Amz-Rid
X-Navigation-Version
X-Vcap-Request-Id
Pinterest-Version
X-Pinterest-Rid
X-SharePointHealthScore
X-Powered-CMS
TCN
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Trace
X-VARITI-CCR
Realpath
Public-Key-Pins
Cache-Tag
X-Client-IP
X-Cdn
X-Fastly-Request-ID
Access-Control-Request-Method
X-Ser
MS-Author-Via
Nginx-Cache
X-DynaTrace-JS-Agent
X-Shard
S
SPIisLatency
SPRequestDuration
X-Upstream
X-Id
X-B3-TraceId-Primal
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
MRF-Tech
X-Edge-O15-RID
Mrf-Cache-Status
X-Ezoic-Cdn
X-Content-Type
X-Hp-Webp
X-Amzn-Trace-Id
X-Forwarded-For
X-Grace
X-T
X-Amz-Meta-S3cmd-Attrs
Front-End-Https
X-Recruiting
X-Hits
Fastcgi-Cache
DynaTrace
Nel
X-Aspnet-Version
X-Jurisdiction
X-Varnish-Age
ServerID
X-Cache-TTL
X-Element-Page-Cache
MicrosoftSharePointTeamServices
X-Mobile-URL
X-Dw-Request-Base-Id
X-Content-Digest
X-DIS-Request-ID
X-Server-ID
X-Node-Name
X-Country-Code-Real
X-FTR-Expires
X-FTR-Cache-Status
NR-ENABLED
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Combine-CSS
X-Frontend
Powered
X-FTR-Backend-Server
X-FTR-DC
X-FTR-Realm
X-FTR-Balancer
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Metageneration
X-Goog-Storage-Class
X-FTR-Backend
Server-Node
TP-L2-Cache
TP-Cache
Alternate-Protocol
Server-Name
X-Logged-In
X-Correlation-Id
AMP-Access-Control-Allow-Source-Origin
X-CST
X-Request-Processing-Time
X-Request-Received
Upgrade-Insecure-Requests
X-XRDS-LOCATION
X-Microsite
X-Request-Handler-Origin-Region
X-Amz-Apigw-Id
X-Amzn-RequestId
X-ATS-Timestamp
Backend-Timing
X-Cache-Hit
X-Content-Options
X-Origin-Server
X-Rid
X-F-Cache
X-Page-Id
X-Akamai-Edgescape
Refresh
X-Content-Security-Policy-Report-Only
X-Revision
X-User-Agent
Fastly-Restarts
X-Varnish-Grace
X-Type
X-Zen-Fury
X-Webkit-Csp
X-XRDS-Location
X-Content-Powered-By
X-B
X-B3-Sampled
X-LB-Cache
X-Geo-Country
PB-PID
PB-RID
X-Az
X-Activity-Id
X-AppVersion
X-FTR-Cache-Host
X-Mobile-Rewrite
Arc-Version
X-URL
Cache-Status
X-Kinsta-Cache
X-Shield-Request-Id
X-N
X-Pad
X-TT
X-Time
X-Cache-Age
X-AOL-HN
X-WebKit-CSP-Report-Only
X-Tumblr-User
X-Instance
Actual-Object-TTL
X-Tumblr-Pixel-0
X-B-Cache
Paypal-Debug-Id
X-Tumblr-Pixel
X-Jobs
X-Signature
X-App-Environment
X-Debug-Info
Access-Control-Allow-Method
X-FB-Debug
X-Load-Cache
X-Request-Guid
X-Framework
X-Cache-Action
X-PHP-Backend
DC
X-Cached-By
X-Git-Hash
X-RateLimit-Remaining
X-Webapp-Samesite-None-Activated-N
X-Varnish-Backend
X-Tt-Trace-Tag
X-Tt-Trace-Host
Fastcgi-Useragent
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Amz-Replication-Status
Surrogate-Key
X-Analytics
X-IPLB-Instance
FilterID
Host-Header
MS-CV
X-Contextid
X-ATG-Version
X-SS-Set-Cookie
Host
X-WA-Info
X-Mobile
X-ORACLE-APMCS-REQUEST-ID
X-Cluster
X-ORACLE-APMCS-TAG
X-Response-Served-From
X-Accel-Buffering
Tracecode
NGB
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-NWS-LOG-UUID
Xserver
Payment
X-Host-Name
WPE-Backend
X-Cache-Key
X-Cache-NE
X-Via-JSL
X-FW-Serve
Eomportal-Instance
X-Varnish-Server
X-FW-Type
X-Cache-2
X-FW-Static
X-FW-Hash
X-FW-Server
X-Tumblr-Pixel-1
X-IPS-LoggedIn
Cache-Tv-Group
Frame-Options
Filters
X-Region
X-Varnish-Hostname
X-GeoIP
X-Srv
X-Tumblr-Pixel-2
X-Cache-Enabled
X-Adobe-Content
X-Origin-Response-Time
X-Cacheable-TTL
Source
X-Adobe-Loc
X-Presslabs-Stats
X-RequestSource
X-Rendered-As
X-Is-Bot
X-Cache-Operation
X-Cache-Rule
X-Seen-By
X-Hostname
X-TX-ID
Retry-After
X-NewRelic-App-Data
X-EdgeConnect-Cache-Status
X-Cache-TTL-Remaining
Server-Info
Cleartype
X-FastCGI-Cache
X-RemovedCookies
X-ProcessESI
Liferay-Portal
X-VCache
X-UA
Accept-CH
X-Dc
X-RTag
X-B3-Traceid
Ms-Operation-Id
X-Source
X-App-Server
Datacenter
X-HTML-Minification-Powered-By
X-L-Path
X-CACHE-KEY
X-FireWall-Port
X-Environment-Context
X-Cache-Server
X-Upgrade-Enabled
X-Endurance-Cache-Level
Cache
X-Handled-By
From-Origin
X-Cache-Control
Healthy
X-CLOUD-TRACE-CONTEXT
X-Backend-Name
X-APP-VERSION
X-Wix-Request-Id
Accept-CH-Lifetime
X-PressLabs-Stats
X-Status
X-Cache-Var
X-RN-RSRV
X-Cache-Var-Map
X-Path-Route
X-ES-SERVER
Meta-Geo
Selected-Fe
OT-Force-Account-Verify
X-Tb
X-Proxy-Build
X-Timing-Wait
X-Access
X-Format
X-Section
Version
Azure-Version
Cache-Tags
X-RateLimit-Limit
Mn-Server-Ip
X-Storage
Azure-SlotName
Azure-RegionName
Azure-SiteName
X-UUID
Azure-InstanceId
X-Rule
X-OCL
X-EIG-Tracking-Id
X-Content-Age
X-Request-Time
X-Proto
X-Origin
X-PCL
X-Sorting-Hat-ShopId
X-ShardId
X-Sorting-Hat-PodId
X-Alternate-Cache-Key
X-Shopify-Generated-Cart-Token
X-Akamai-Request-ID
X-ShopId
X-Shopify-Stage
X-NYM-Debug-Backend
Decoy-Debug-Key
X-FC-Vary-Parameters
Decoy-Debug-TTL
Decoy-Debug-Status
X-Redis-Cache
Akamai-GRN
X-Vgn-Hpd-Reason
X-Time-Microsecs
X-Soup
X-Qloud-Router
X-Viewer-Country
X-SaId
X-VWS-Id
X-ServerID
X-Cache-Config
X-Proxy-Cache-Status
X-FW-Dynamic
X-Generated-By
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Hl-Ver
X-Debug-Cache
X-Cluster-Node
Origin-Edge-Control
X-Akamai-Request-ID2
X-AWS-Id
X-BYPASS-REASON
Now
X-Hosted-By
Ec-Rule-Version
Origin-Cache-Control
X-ProxyCache-Key
X-ProxyCache-Status
X-Proxy
X-LJ-Flow-ID
X-Human
Node
X-JoinUs
X-Pubstack
DB-Nickname
Srv
Accept-Charset
X-Yottaa-Metrics
GEO-INFO
X-Yottaa-Optimizations
Cross-Origin-Window-Policy
X-BCube-Filmed-By
X-CCM
Webcakes-Region
Webcakes-App-Version
TWC-Device-Class
TWC-Connection-Speed
NGX
TWC-GeoIP-Country
TWC-GeoIP-LatLong
Webcakes-App-Name
TWC-Privacy
TWC-Locale-Group
Property-Id
X-Generated
X-Varnish-Hits
X-Ruxit-Js-Agent
X-Hyper-Cache
X-Www-Served-By
X-Site-Version
X-Web-Node
X-MP-GENERATED-AT
X-Origin-Hint
X-Say-TTL
X-Say-Cacheable
X-SayCDN-TTL
X-TNCMS
X-Loop
S-Rt
X-Amzn-Remapped-Content-Length
X-RCS-CacheZone
X-R9-Blue-Green-Version
X-Xfnlog-Site
X-Cache-Host
X-FB-TRIP-ID
X-Locale
X-Akamai-Transformed
X-NCache
X-IP
X-Detected-As
L5d-Success-Class
X-CS
X-Ttl
X-Unique-Id
Cache-Name
X-Drupal-Cache-Tags
Webserver
Viewport
Time
Uber-Trace-Id
X-Esi
Cache-Key
X-UA-Device-Type
Mime-Version
X-UnsetCookies
X-Mode
X-Cache-Remote
Accept-Language
X-Forwarded-Host
X-Backend-TTL
X-CDN-Forward
X-Info
X-Whom
X-Origin-CC
X-Origin-TTL
X-From
Country
Rt-Fastcgi-Cache
X-Daa-Tunnel
X-Trafficlayer-App-Scope
X-Trafficlayer-App-Name
X-Varnish-Cache-Hits
VIX-Pulpo-Upstream-Status
X-Cluster-Name
Odigeo-Trace-Id
VIX-Pulpo-Node
X-NGENIX-Cache
X-Drupal-Cache-Contexts
X-ApacheServer
Content-Disposition
X-PERF
X-Newrelic-Synthetics
X-TT-TIMESTAMP
ServedBy
X-Magnolia-Registration
X-Microcachable
X-B3-Spanid
X-Geo
Section-Io-Cache
X-Routing-Service
X-Edge-Location
X-Proxied
X-Zipkin-Id
X-Device-Type
Proxy-Connection
Ohc-File-Size
X-Via-Fastly
X-Uri
X-EC-Lua
X-Webkit-CSP
Ohc-Cache-HIT
X-No-Session
HitType
X-UPSTREAM-Address
Cf-Ipcountry
X-D
W
Xc-Version
X-Date
X-A-Dcw
X-A-Ccd
X-A-Dam
Fastcgi-X-Cache-Version
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
X-GeoIP-Country-Code
Apple-News-Services-Host
X-Geo-Header
X-DPWN-IS-SECURE
X-External-Request-Id
X-G
Apple-News-Services-Request-Url
AsisCache
VivaBuild
Content-Style-Type
Viewtype
X-Nc
Content-Script-Type
BehaviorPad-Version
X-Destination
X-A
T-Server
X-Vtex-Remote-Cache
X-Session-Fingerprint
X-Sigma
X-Sigma-Backend
X-ScT
X-S-Cookie
X-Rojux
X-Application
MD5-Digest
X-Twitter-Response-Tags
Meta-Geo-Continent
X-Accel-Expires-Debug
X-Transaction
X-Trv-Group
X-ARC
Rendered-Blocks
X-Aed
X-SRCache-Key
Mobile-Detection-Method
X-B-Cookie
X-Rocket-Build-Number
X-S
X-A-Dgt
X-VG-WebCache
X-Rewrite-Enabled
X-Vdms-Version
GEO-REGION-INFO
X-VG-TLSProxy
X-Connection-Hash
X-VG-WebServer
X-CF-Lambda-Version
X-A-Wwc
Machine
X-Request-UUID
X-Region-Sid
X-Vtex-Processado-Em
X-CF-Lambda-Fn
Access-Control-Request-Headers
X-C
User-Cache-Control
Server-Cache-Control
X-Agile-Id
X-Distil-CS
X-App-Name
X-Agile-Age
X-Eu-Site
X-Agile
CDCHOST
HA-Ipaddr
Environment
X-CGP
Ha-Gx-Prefs
Gh-Request-Id
Fastly-Soc-X-Request-Id
X-CUA
IsBot
Locid
X-Developers
X-Bip
Powered-By
X-Contensis-Viewer-Groups
Server-Surrogate-Control
X-Cache-Debug
X-Cache-ASPX
X-Auto-Login
X-Logging-Id
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-Varnish-Beresp-Ttl
X-SIPLIST1
X-VC-Cache
X-Varnish-Authentication
Geo-Info
X-TrackingId
X-Thanos
X-Tumblr-Pixel-3
X-Hit
X-WebServer
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-TA-CDN-Provider
X-GoCache-CacheStatus
X-PHP-Host
X-Labrador-Cache-Channel
X-Cache-Backend
X-TH-Server
X-Real-IP
X-SVT-ORM-VERSION
X-Render-Time
X-Request-URI
X-Server-W
X-Azure-Ref
X-Cache-Bucket
X-Block-Status
X-SVT-ORM-RULES
X-BBXSRF
X-Urbn-Site-Id
X-Clientip
Fastly-SWR
Fastly-SIE
Web-Mar-Node
We-Hiring
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
Countrycode
X-Webstats-RespID
X-AK-Request-ID
X-Urbn-Context-Path
X-Cache-Time
X-User
X-We-Are-Hiring
X-WADP-Cache
X-TT-LOGID
X-RateLimit-Remaining-Second
X-IN-APIGATEWAY
X-Hnp-Log
X-Hash
X-Dispatcher-Server
X-IN-APIGATEWAYSSL
X-Instart-Isnd
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-GeoIP-City
X-Generation-Time
X-FW-Version
X-Fastly-Cache
X-Fetched-On
X-Gamma-Serve
X-Epic-Correlation-Id
X-Distributor
X-Generated-In
X-Gen-Mode
X-Irp-Debug
X-Debug-Cache-Expiry
X-OVcl
X-Clara-WADP
X-Cms-Context
X-OVcl-Cache
X-Owner
X-Cdn-Srv
X-RateLimit-Limit-Second
X-Proxy-Upstream
X-Origin-Expires
X-Origin-Date
X-LI-UUID
X-Li-Pop
X-Li-Fabric
X-Micro-Cache
X-Ms-Request-Id
X-NodeID
X-Ms-Version
X-Core-Mission
X-Cache-URL
X-Backend-State
Memcached
Cdncip
Cache-Host
AKAMAI
RNT-Machine
Request-Country
Mail-Subject
Cdnsip
IBM-Web2-Location
Heartbleed
Fastly-SSL
Locale
Country-Code
RNT-Time
Request-EU
Server-ID
V-Age
True-Client-Country-4JS
X-App-Version
X-NX-Host
X-LI-Proto
X-Nginx-Cache-Key
X-Old-Content-Length
Fastly-Backend-Name
X-VServer
X-Is-Gdpr
FNAC-ModuleRouting
X-Reboot
X-Service
X-Core-Value
X-Level-Front-Cache
Is-Eu
X-JWT-State
ServerName
X-Req
X-Trafficlayer-App-Version
X-Generated-On
X-ServiceProvider
X-Swa-Ws
X-Key
Adler-Geo
X-Has-Esi
X-Cache-Tags
Platform
X-Debug-Cookies
X-Debug-Log
X-Up
Wxu-Next-Region
X-Servername
PFcat
X-Trace-Id
Server-Host
Server-Int
Wxu-Next-Hostname
X-Variation
X-NU-AKA-ACS-Version
X-Platform-Server
Kp-EeAlive
Wxu-Next-Commit
X-Cache-Info
Thinkindot-CacheControl-Type
X-Air-Hostname
Thinkindot-CacheControl
X-Lb-Id
X-Sucuri-Cache
X-S-Maxage
X-Internal-Host
Thinkindot-Control
X-Thinkindot-L3
X-Matched-Rule
X-Nginx-Cache
X-SERVER
X-Var-Ttl
X-Refresh
Cache-Hits
X-Location
X-Cache-Expired-At
Group
RequestId
X-Parent-Response-Time
S-Cnection
Pragrma
X-Response-By
X-Tb-Optimization-Total-Bytes-Saved
X-CF-Powered-By
ProcessTime
Powered-By-ChinaCache
Memory
X-B3-Parentspanid
Filterid
X-Cdn-Forward
X-Tec-Api-Origin
X-Tec-Api-Version
X-CSRF-Token
X-Tec-Api-Root
X-BACKEND-TTL
X-Pjax-Url
X-B3-SpanId
X-NC
X-CSRF-TOKEN
X-Wa
User-Agent
SRV
X-Sucuri-ID
Origin
X-Varnish-Cacheable
X-Server-IP
X-Pf-Uncompressing
TTL
Geoip-Latitude
X-NWS-UUID-VERIFY
X-Vcl-Version
X-Via-CDN
GeoIp-Country-Code
Geoip-City
X-Correlation-ID
X-Unique-ID
X-NGINX-Cache
X-Ua
X-Developer
PICS-Label
X-Ocache
X-Cdn-Request-ID
Media-Length
X-Cdn-Origin
X-LAGOON
X-Sn-Servicetimems
X-Cache-Grace
X-COUNTRY
On-Server
X-Node-Id
X-Device-Os
X-Oss-Object-Type
X-Oss-Server-Time
X-Cache-Status-Check
X-Oss-Hash-Crc64ecma
X-Oss-Storage-Class
X-Oss-Request-Id
X-Rocket-Nginx-Bypass
X-Request-Host
X-MSEdge-Flight
A
Dnion-Transfer-Encoding
X-Litespeed-Cache
X-MSEdge-Features
X-Servedbyhost
X-Sucuri-Id
Cloudfront-Viewer-Country
X-Via-Ucdn
X-Varnish-Ttl
SN
X-Oneagent-Js-Injection
X-TIME
Hostname
XServer
Esi-Enabled
X-AIR-PT
X-HS-Status
Tcn
Cdn
M-TraceId
X-Reqid
X-FORWARDED-FOR
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Policy
HostName
X-ServedByHost
X-Planisys-CDN-Cache
X-Ratelimit-Remaining
X-Fastly-Country-Code
Host-ID
Who
CF-Cached-On
X-Request-Start
Resin-Trace
X-Azure-Ref-OriginShield
X-Beluga-Response-Time
X-Beluga-Record
X-Beluga-Status
X-Beluga-Trace
X-Beluga-Cache-Status
X-Beluga-Node
X-Cache-Ttl
X-VHOST
X-Ftr-Cache-Host
X-Varnish-URL
Rt-Proxy-Cache
Pics-Label
X-Slack-Backend
NtCoent-Length
X-Zone
Magicmarker
GeoIP-Country-Code
X-VCL-Version
X-Varnish-Url
X-Method
X-APP
X-Bc
CACHE
MIME-Version
X-Oracle-Dms-Rid
X-Fastly-Backend-Reqs
Ttl
Cteonnt-Length
X-Processor
X-PAYTM-SRV-ID
X-Server-Time
GeoIP-Latitude
X-Action
X-Dispatch
Pramga
Arc-Country
X-Cache-FS-Status
X-LiteSpeed-Cache-Control
X-DC
GeoIP-City
X-DSS
X-DW
X-VarnishDD-TTL
X-ND-Cache
X-RPM
X-DB
X-DI
X-Flog
X-RPS
X-RSL
X-FPC
X-PF-Uncompressing
X-Skip-Cache
X-Hello
X-Ratelimit-Limit
X-ABtesting
X-Newrelic-App-Data
X-HostName
X-SRV
Fastly-Drupal-HTML
X-Be
WebServer
X-Svr
X-PJAX-URL
Load-Balancing
X-Swift-Error
X-Ftr-Request-Id
Cdn-Host
Ohc-Response-Time
X-Edge-Server
X-Served-From
Cdn-Request-Time
Amp-Access-Control-Allow-Source-Origin
X-Bc-Bl
Processtime
X-BE
X-Dynatrace
Vix-Hermes-Req-Id
N-Cache
X-DevSite-Last-Modified
Servername
X-MServer
DSUID
X-Dynatrace-Js-Agent
CF-IPCountry
Cache-Provider
Section-Origin-Responded
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
X-Backend-Host
X-WA
Section-Io-Origin-Time-Seconds
Section-Io-Id
Section-Io-Origin-Status
X-VCT
X-ID
X-Aicache-OS
Release
X-Frame-Option
X-Hp-Ccpa-Warning
X-WR-MODIFICATION
X-LB-ID
Requestid
X-Branch-Name
CDN
Lfy
WZWS-RAY
X-Fastly-Cache-Hits
Pagetype
X-StackifyID
X-ZONE
X-Configured-By
X-Snapshot-Date
X-Ftr-Dc
X-Ftr-Balancer
X-Ftr-Realm
X-Tid
Dynatrace
X-Ftr-Backend
X-Ftr-Backend-Server
X-CACHE-AGE
V-Cache
X-VC
X-SD-PageType
Cache-Cookie-Set-From
Cache-Cookie-Set-Idcheck
X-Apw-Access-Action
X-SB
Proxy-Firewall
X-Apw-Hits
X-BC
X-Apw-Access-Token
SD-X-WS
X-Apw-Access-Object
D-Cc-Upstream
Cache-Cookie-Set-Lfrom
X-Fmm-Version
FSS-Proxy
X-Upstream-Ht
X-Cc-Via
X-Upstream-Ct
X-Cc-Req-Id
X-Request-Url
FSS-Cache
X-Edge-IP
Warning
X-Adobe-Source
X-Litespeed-Cache-Control
X-Node-ID
X-App
X-WPE-Loopback-Upstream-Addr
Cneonction
X-Li-Proto
L
X-Worker
X-Varnish-Beresp-TTL
X-Powered-Y
X-Request-URL
WP-Super-Cache
X-Check-Cacheable
X-Fastly-Cache-Status
X-Compress-Hint
X-SN
Backend-Name
X-ElasticPress-Search
X-ServerName
Lb
X-Cache-Id
Correlation-Id