Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
CF-RAY
Link
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-Request-ID
X-DNS-Prefetch-Control
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
Status
Upgrade
X-Content-Security-Policy
X-CDN
Content-Encoding
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Xss-Protection
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
X-Pass-Why
X-Cache-Group
Xkey
X-AH-Environment
P3p
X-Envoy-Upstream-Service-Time
X-Via
X-Backend
CF-Ray
X-Server
X-Age
X-Ua-Compatible
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Ws-Request-Id
X-Server-Powered-By
X-Page-Speed
X-Pingback
EagleId
X-Proxy-Cache
X-Hacker
X-UA-Device
X-Nginx-Cache-Status
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
Cf-Railgun
Grace
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Amz-Version-Id
Report-To
X-LiteSpeed-Cache
X-Rq
X-OneAgent-JS-Injection
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-WebKit-CSP
X-Server-Id
X-Device
X-Host
X-Origin-Cache
EagleEye-TraceId
X-Response-Time
X-Node
X-Ac
Surrogate-Control
Content-Location
X-Cloud-Trace-Context
X-Vhost
X-Readtime
X-Backend-Server
Request-Id
X-Dispatcher
X-Origin-Upstream-Status
X-Cnection
X-Application-Context
X-HW
X-Cache-Lookup
X-ORACLE-DMS-ECID
Fusion-Template-Id
Fusion-Source
Fusion-Content-Source
Fusion-Content-Id
Fusion-Component-Id
X-Ruxit-JS-Agent
X-ORACLE-DMS-RID
NEL
X-DataDome
X-Mod-Pagespeed
X-Rack-Cache
Rating
Edge-Control
X-Country
X-Clacks-Overhead
X-Akam-SW-Version
X-Dns-Prefetch-Control
Pinterest-Generated-By
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-TTL
Allow
X-Country-Code
X-FTR-Request-ID
X-DynaTrace
X-Instart-Request-ID
X-Varnish-TTL
X-Goog-Hash
Accept-Ch
X-Vname
X-PC
X-TtlSet
X-ESI
Verso
Content-MD5
Service-Worker-Allowed
X-Powered-By-Plesk
Accept-Ch-Lifetime
X-Url
X-B3-TraceId
X-Forwarded-Proto
X-Version
X-MS-InvokeApp
X-GitHub-Request-Id
X-Cdn-Fetch
X-Kinja-Build
X-Exp-Id
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-GoogleNews-Bot
X-Kinja
X-Exp-Variant
RTSS
Edge-Cache-Tag
X-Server-Name
X-D2id
X-Abt-Application-Version
X-Debug
X-Px
AR-Request-ID
AR-CACHE
AR-PoweredBy
Ar-Sid
AR-ATIME
X-Vcache
X-Amz-Server-Side-Encryption
SPRequestGuid
Charset
X-NF-Request-ID
X-Cached
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-Fastcgi-Cache
X-TEC-API-ROOT
X-Accel-Expires
Display
Response
X-Sol
X-Vcap-Request-Id
X-Middleton-Response
X-Middleton-Display
Pagespeed
X-MSEdge-Ref
X-Amz-Rid
X-Navigation-Version
Arr-Disable-Session-Affinity
X-Pinterest-Rid
Pinterest-Version
X-SharePointHealthScore
TCN
X-Powered-CMS
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-VARITI-CCR
X-Trace
Public-Key-Pins
Cache-Tag
X-Fastly-Request-ID
Realpath
X-Client-IP
X-Cdn
MS-Author-Via
X-Ser
Nginx-Cache
Access-Control-Request-Method
X-Edge-O15-RID
X-DynaTrace-JS-Agent
X-Shard
MRF-Tech
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Mrf-Item-Lastmod
X-Upstream
X-Server-ID
SPIisLatency
SPRequestDuration
S
X-Content-Type
X-Id
X-Amzn-Trace-Id
X-Ezoic-Cdn
X-Hp-Webp
X-Grace
X-Forwarded-For
X-T
X-Amz-Meta-S3cmd-Attrs
Front-End-Https
X-Hits
X-Recruiting
Fastcgi-Cache
X-Jurisdiction
DynaTrace
Nel
X-Cache-TTL
X-Aspnet-Version
X-Varnish-Age
ServerID
MicrosoftSharePointTeamServices
X-Element-Page-Cache
X-Content-Digest
X-Mobile-URL
X-Node-Name
X-FTR-Realm
X-DIS-Request-ID
X-FTR-Backend
X-Dw-Request-Base-Id
X-FTR-Expires
X-FTR-Cache-Status
X-FTR-Backend-Server
X-FTR-DC
X-Country-Code-Real
X-FTR-Balancer
NR-ENABLED
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Hub-Id
X-Goog-Metageneration
X-Goog-Generation
X-Frontend
X-Goog-Storage-Class
X-GUploader-UploadID
Server-Node
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
Powered
TP-L2-Cache
TP-Cache
Alternate-Protocol
X-Logged-In
Server-Name
X-CST
AMP-Access-Control-Allow-Source-Origin
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Request-Received
X-Request-Processing-Time
Upgrade-Insecure-Requests
X-Correlation-Id
X-Microsite
X-Request-Handler-Origin-Region
X-ATS-Timestamp
Backend-Timing
X-Cache-Hit
X-XRDS-Location
Fastly-Restarts
X-Content-Options
X-F-Cache
X-Origin-Server
Refresh
X-Content-Security-Policy-Report-Only
X-User-Agent
X-Revision
X-Page-Id
X-Akamai-Edgescape
X-Rid
X-Zen-Fury
X-Varnish-Grace
X-Type
X-XRDS-LOCATION
X-Webkit-Csp
X-Content-Powered-By
X-LB-Cache
X-B
X-FTR-Cache-Host
X-B3-Sampled
PB-PID
PB-RID
X-Geo-Country
X-Mobile-Rewrite
Arc-Version
X-Az
X-Activity-Id
X-AppVersion
Cache-Status
X-URL
X-Kinsta-Cache
X-N
X-Cache-Age
X-TT
X-Shield-Request-Id
X-B-Cache
X-WebKit-CSP-Report-Only
X-Time
X-Cache-Action
X-Signature
X-Instance
X-AOL-HN
X-Pad
Actual-Object-TTL
X-Framework
X-Debug-Info
Paypal-Debug-Id
X-Tumblr-Pixel-0
Access-Control-Allow-Method
X-Jobs
X-Tumblr-Pixel
X-Tumblr-User
X-FB-Debug
X-App-Environment
X-Load-Cache
X-Request-Guid
X-PHP-Backend
X-Cached-By
DC
X-Git-Hash
Fastcgi-Useragent
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Varnish-Backend
X-Amz-Replication-Status
Surrogate-Key
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-RateLimit-Remaining
X-IPLB-Instance
Host-Header
X-Webapp-Samesite-None-Activated-N
X-Contextid
MS-CV
X-ATG-Version
X-Analytics
Host
X-WA-Info
X-NWS-LOG-UUID
X-SS-Set-Cookie
X-ORACLE-APMCS-REQUEST-ID
X-ORACLE-APMCS-TAG
X-Mobile
Accept-CH
X-Via-JSL
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Cluster
X-Response-Served-From
X-Accel-Buffering
Tracecode
NGB
X-Host-Name
FilterID
X-Cache-Key
Payment
WPE-Backend
Xserver
X-Cache-NE
Eomportal-Instance
X-FW-Type
X-Region
X-Varnish-Server
X-FW-Static
X-FW-Server
X-FW-Hash
X-FW-Serve
X-Cache-2
Source
Cache-Tv-Group
X-GeoIP
Frame-Options
Filters
X-Tumblr-Pixel-1
X-IPS-LoggedIn
X-Srv
X-Tumblr-Pixel-2
X-Origin-Response-Time
X-Varnish-Hostname
X-Adobe-Content
X-Cacheable-TTL
X-Presslabs-Stats
X-Adobe-Loc
X-Cache-Enabled
X-Is-Bot
X-Cache-Operation
X-Cache-Rule
X-Rendered-As
X-RequestSource
X-Seen-By
X-Hostname
Retry-After
X-TX-ID
X-EdgeConnect-Cache-Status
Server-Info
X-Cache-TTL-Remaining
X-NewRelic-App-Data
X-ProcessESI
X-RemovedCookies
Liferay-Portal
Cleartype
Accept-CH-Lifetime
X-FastCGI-Cache
X-VCache
X-App-Server
X-Dc
X-RTag
X-Environment-Context
X-L-Path
X-B3-Traceid
Ms-Operation-Id
X-UA
X-FireWall-Port
X-Source
X-CACHE-KEY
Datacenter
X-HTML-Minification-Powered-By
X-Endurance-Cache-Level
X-Upgrade-Enabled
X-Handled-By
X-Cache-Server
From-Origin
Srv
X-Backend-Name
X-Cache-Control
Cache
X-Wix-Request-Id
X-APP-VERSION
Accept-Charset
Healthy
X-Path-Route
X-PressLabs-Stats
X-Cache-Var-Map
Meta-Geo
X-Cache-Var
X-RN-RSRV
X-ES-SERVER
X-Tb
X-Section
X-UUID
Selected-Fe
X-Access
X-Timing-Wait
X-Status
X-Format
X-Proxy-Build
OT-Force-Account-Verify
Version
X-Sorting-Hat-ShopId
Azure-RegionName
X-Alternate-Cache-Key
X-Origin
Akamai-GRN
Azure-InstanceId
X-ShopId
X-Akamai-Request-ID
Azure-SiteName
Cache-Tags
X-PCL
Mn-Server-Ip
Azure-Version
X-Request-Time
Azure-SlotName
X-Goog-Meta-Goog-Reserved-File-Mtime
X-ShardId
X-OCL
X-Shopify-Generated-Cart-Token
X-Shopify-Stage
X-NYM-Debug-Backend
X-FC-Vary-Parameters
X-Content-Age
X-Proto
X-EIG-Tracking-Id
X-Cache-Config
X-Sorting-Hat-PodId
X-VWS-Id
X-SayCDN-TTL
Decoy-Debug-Key
Decoy-Debug-Status
X-Soup
Ec-Rule-Version
X-Web-Node
X-Cluster-Node
X-Human
X-LJ-Flow-ID
X-Qloud-Router
X-Hl-Ver
X-SaId
X-Hyper-Cache
X-Debug-Cache
X-Vgn-Hpd-Reason
X-Viewer-Country
DB-Nickname
Now
X-Redis-Cache
X-ServerID
X-JoinUs
X-Say-Cacheable
X-Say-TTL
X-Hosted-By
X-BYPASS-REASON
X-Time-Microsecs
X-AWS-Id
X-FW-Dynamic
X-Generated-By
X-Proxy-Cache-Status
X-ProxyCache-Status
Node
NGX
X-ProxyCache-Key
Origin-Cache-Control
X-Akamai-Request-ID2
X-Pubstack
Origin-Edge-Control
X-Proxy
Decoy-Debug-TTL
GEO-INFO
X-Storage
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-BCube-Filmed-By
X-Rule
TWC-Privacy
X-CCM
X-Amzn-Remapped-Content-Length
Webcakes-App-Version
Webcakes-App-Name
TWC-Connection-Speed
Webcakes-Region
Property-Id
TWC-GeoIP-LatLong
TWC-GeoIP-Country
TWC-Device-Class
TWC-Locale-Group
X-Site-Version
X-Origin-Hint
X-TNCMS
X-Varnish-Hits
X-Www-Served-By
X-MP-GENERATED-AT
X-Loop
X-Generated
Cross-Origin-Window-Policy
X-FB-TRIP-ID
X-Xfnlog-Site
X-R9-Blue-Green-Version
S-Rt
X-RCS-CacheZone
X-Akamai-Transformed
X-Locale
X-RateLimit-Limit
X-Cache-Host
X-NCache
X-IP
X-Detected-As
L5d-Success-Class
X-CS
X-Unique-Id
X-Drupal-Cache-Tags
Webserver
Cache-Key
Cache-Name
Uber-Trace-Id
Time
Viewport
X-UA-Device-Type
X-Esi
X-Mode
Mime-Version
X-UnsetCookies
X-Forwarded-Host
X-Whom
Accept-Language
X-Origin-TTL
X-Origin-CC
X-Cache-Remote
X-Daa-Tunnel
Rt-Fastcgi-Cache
X-Info
Content-Disposition
X-NGENIX-Cache
Country
X-Varnish-Cache-Hits
X-From
X-PERF
X-ApacheServer
Odigeo-Trace-Id
X-B3-Spanid
X-Backend-TTL
ServedBy
X-Cluster-Name
X-Drupal-Cache-Contexts
X-Newrelic-Synthetics
X-CDN-Forward
X-Magnolia-Registration
VIX-Pulpo-Upstream-Status
Section-Io-Cache
VIX-Pulpo-Node
X-EC-Lua
X-Geo
X-Ruxit-Js-Agent
X-Microcachable
X-Zipkin-Id
X-TT-TIMESTAMP
X-Routing-Service
X-CLOUD-TRACE-CONTEXT
X-Nc
X-Device-Type
X-Proxied
X-Via-Fastly
X-Uri
Ohc-File-Size
X-Trafficlayer-App-Name
X-Ttl
Ohc-Cache-HIT
Proxy-Connection
X-Trafficlayer-App-Scope
Cf-Ipcountry
X-Edge-Location
HitType
BehaviorPad-Version
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
AsisCache
Access-Control-Request-Headers
X-Geo-Header
X-VG-TLSProxy
X-VG-WebServer
X-G
X-SRCache-Key
Apple-News-Services-Handled
X-VG-WebCache
Apple-News-Services-Host
GEO-REGION-INFO
VivaBuild
W
X-ARC
Viewtype
X-B-Cookie
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
X-Application
X-A
X-A-Wwc
X-Accel-Expires-Debug
X-Aed
X-A-Dgt
X-A-Dcw
X-A-Ccd
X-A-Dam
T-Server
Rendered-Blocks
X-Destination
X-Date
X-D
Fastcgi-X-Cache-Version
X-DPWN-IS-SECURE
Content-Script-Type
Content-Style-Type
Machine
MD5-Digest
X-CF-Lambda-Version
X-CF-Lambda-Fn
Xc-Version
Mobile-Detection-Method
X-Connection-Hash
Meta-Geo-Continent
X-External-Request-Id
X-GeoIP-Country-Code
X-Request-UUID
X-S
X-S-Cookie
X-ScT
X-No-Session
X-Transaction
X-Vdms-Version
X-Rocket-Build-Number
X-Rojux
X-Trv-Group
X-Session-Fingerprint
X-Twitter-Response-Tags
X-Sigma
X-Sigma-Backend
X-Region-Sid
X-Rewrite-Enabled
X-Varnish-Beresp-Status
User-Cache-Control
X-Varnish-Beresp-Ttl
Geo-Info
X-C
X-Varnish-Beresp-Grace
X-UPSTREAM-Address
X-CUA
X-Rebelmouse-Surrogate-Control
X-VC-Cache
X-Contensis-Viewer-Groups
Locid
X-Clientip
Gh-Request-Id
X-Developers
X-Tumblr-Pixel-3
Environment
X-Distil-CS
Fastly-SIE
Fastly-Soc-X-Request-Id
IsBot
HA-Ipaddr
Ha-Gx-Prefs
X-Rebelmouse-Cache-Control
X-Cache-ASPX
X-App-Name
X-WebServer
X-Thanos
X-Varnish-Authentication
X-SIPLIST1
X-Agile-Id
X-Agile-Age
X-Agile
X-TrackingId
X-Auto-Login
X-Wikidot-Backend
Powered-By
X-Wikidot-Static-Cache
X-Cache-Debug
Server-Cache-Control
X-Bip
Server-Surrogate-Control
Countrycode
X-CGP
Fastly-SWR
X-Eu-Site
CDCHOST
Fastly-SSL
X-Hit
X-Real-IP
X-Logging-Id
Filterid
X-Cache-Backend
X-GoCache-CacheStatus
X-LI-UUID
X-Up
X-Backend-State
X-Hash
X-Hnp-Log
X-BBXSRF
X-Cache-Bucket
X-Cache-Info
X-Cache-Tags
X-Cache-Time
X-Swa-Ws
X-Ms-Request-Id
X-Micro-Cache
X-Has-Esi
X-Block-Status
X-User
X-Irp-Debug
X-Li-Pop
X-Servername
X-Server-W
X-Trace-Id
X-Is-Gdpr
X-Li-Fabric
X-Labrador-Cache-Channel
X-We-Are-Hiring
X-JWT-State
X-Instart-Isnd
X-AK-Request-ID
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-IN-APIGATEWAY
X-Cache-URL
X-LI-Proto
X-Urbn-Site-Id
X-WADP-Cache
X-IN-APIGATEWAYSSL
X-Variation
X-Azure-Ref
X-Ms-Version
X-Debug-Log
X-RateLimit-Remaining-Second
X-TT-LOGID
X-Debug-Cookies
X-Origin-Date
X-Debug-Cache-Store
X-NU-AKA-ACS-Version
X-NX-Host
X-Origin-Expires
X-OVcl
X-Epic-Correlation-Id
X-RateLimit-Limit-Second
X-Proxy-Upstream
X-Distributor
X-Dispatcher-Server
X-OVcl-Cache
X-Owner
X-PHP-Host
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-Clara-WADP
X-Gamma-Serve
X-Request-URI
X-Gen-Mode
X-Generated-In
X-GeoIP-City
X-Platform-Server
X-Generation-Time
X-Nginx-Cache-Key
X-Cms-Context
X-Fetched-On
X-TH-Server
X-Fastly-Cache
X-FW-Version
X-Core-Mission
X-VServer
X-Render-Time
X-NodeID
X-Cdn-Srv
IBM-Web2-Location
AKAMAI
Platform
Cache-Host
Request-Country
Adler-Geo
X-Urbn-Context-Path
RNT-Machine
Request-EU
Cdncip
Cdnsip
Locale
Kp-EeAlive
Is-Eu
Heartbleed
Mail-Subject
Country-Code
Memcached
X-Webstats-RespID
RNT-Time
V-Age
Web-Mar-Node
We-Hiring
Server-Int
Server-ID
True-Client-Country-4JS
FNAC-ModuleRouting
Fastly-Backend-Name
X-ServiceProvider
X-Trafficlayer-App-Version
X-Thinkindot-L3
X-Air-Hostname
X-Nginx-Cache
X-Old-Content-Length
X-Matched-Rule
X-Generated-On
X-Reboot
X-Req
ServerName
X-App-Version
X-Service
X-Level-Front-Cache
Server-Host
Thinkindot-CacheControl-Type
PFcat
Thinkindot-Control
Wxu-Next-Region
Wxu-Next-Hostname
Thinkindot-CacheControl
X-Core-Value
Wxu-Next-Commit
Cache-Hits
X-Var-Ttl
X-Internal-Host
X-S-Maxage
X-Cache-Expired-At
Group
X-Lb-Id
S-Cnection
RequestId
X-Refresh
X-SERVER
X-Key
X-Parent-Response-Time
X-Response-By
Pragrma
X-Sucuri-Cache
X-Cdn-Forward
X-VHOST
Powered-By-ChinaCache
X-BACKEND-TTL
X-CF-Powered-By
X-Location
X-Tb-Optimization-Total-Bytes-Saved
X-CSRF-TOKEN
X-TA-CDN-Provider
ProcessTime
X-Correlation-ID
X-Pjax-Url
Origin
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
X-Sucuri-ID
X-B3-Parentspanid
X-Varnish-Cacheable
Memory
User-Agent
X-Wa
X-CSRF-Token
X-Ua
X-Via-CDN
TTL
X-NC
X-Pf-Uncompressing
X-B3-SpanId
Geoip-Latitude
Geoip-City
X-Node-Id
X-Developer
X-Vcl-Version
X-Server-IP
X-NWS-UUID-VERIFY
SRV
X-Unique-ID
X-Sn-Servicetimems
X-Ocache
X-Cache-Grace
X-Device-Os
X-LAGOON
PICS-Label
GeoIp-Country-Code
X-Cdn-Origin
X-Oss-Storage-Class
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-NGINX-Cache
X-COUNTRY
On-Server
X-Cache-Status-Check
Hostname
Media-Length
X-Cdn-Request-ID
X-Request-Host
X-MSEdge-Flight
X-MSEdge-Features
A
Dnion-Transfer-Encoding
Cloudfront-Viewer-Country
X-Servedbyhost
X-Webkit-CSP
X-Rocket-Nginx-Bypass
M-TraceId
X-Litespeed-Cache
SN
X-Ratelimit-Remaining
X-Varnish-Ttl
X-Via-Ucdn
X-TIME
X-Sucuri-Id
XServer
X-HS-Status
Tcn
Cdn
X-FORWARDED-FOR
X-ServedByHost
Host-ID
X-Varnish-URL
X-AIR-PT
X-Reqid
Esi-Enabled
Resin-Trace
X-Beluga-Node
X-Cache-Ttl
X-Beluga-Cache-Status
X-Policy
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Beluga-Trace
X-Beluga-Record
X-Beluga-Status
X-Fastly-Country-Code
X-Beluga-Response-Time
Who
HostName
CACHE
X-Slack-Backend
X-Azure-Ref-OriginShield
X-Request-Start
CF-Cached-On
X-Fastly-Backend-Reqs
GeoIP-Country-Code
Rt-Proxy-Cache
X-Action
Pics-Label
X-LiteSpeed-Cache-Control
Pramga
X-Dispatch
X-Cache-FS-Status
GeoIP-Latitude
X-Processor
Arc-Country
X-RPM
X-DI
X-VCL-Version
X-DB
X-DSS
X-DW
X-RPS
X-Server-Time
X-RSL
X-PAYTM-SRV-ID
X-Ftr-Cache-Host
X-Ratelimit-Limit
X-Oracle-Dms-Rid
MIME-Version
X-ND-Cache
X-Hello
GeoIP-City
Ttl
X-Bc
X-PF-Uncompressing
X-Method
X-Flog
X-ABtesting
X-Zone
NtCoent-Length
X-APP
X-Skip-Cache
Magicmarker
X-Varnish-Url
X-DC
X-Served-From
X-Newrelic-App-Data
Cdn-Request-Time
X-VarnishDD-TTL
Fastly-Drupal-HTML
X-FPC
Cteonnt-Length
X-Edge-Server
Cdn-Host
X-HostName
N-Cache
X-Bc-Bl
X-DevSite-Last-Modified
WebServer
X-SRV
Amp-Access-Control-Allow-Source-Origin
X-PJAX-URL
Section-Io-Id
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
X-WA
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
X-BE
X-Be
Processtime
Ohc-Response-Time
X-Backend-Host
X-Svr
X-Dynatrace
Servername
X-Dynatrace-Js-Agent
X-Swift-Error
Load-Balancing
Vix-Hermes-Req-Id
Cache-Provider
X-ID
X-ZONE
X-Aicache-OS
X-BC
X-Frame-Option
X-WR-MODIFICATION
Lfy
CF-IPCountry
X-Fmm-Version
FSS-Cache
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-Idcheck
X-Fastly-Cache-Hits
Cache-Cookie-Set-From
Pagetype
FSS-Proxy
X-Adobe-Source
X-Branch-Name
X-MServer
Dynatrace
X-LB-ID
X-Snapshot-Date
Requestid
X-StackifyID
CDN
DSUID
X-VCT
Release
X-CACHE-AGE
X-Hp-Ccpa-Warning
X-VC
X-Configured-By
WZWS-RAY
X-Apw-Access-Token
X-Apw-Hits
V-Cache
X-Tid
X-Cc-Via
Warning
X-Cc-Req-Id
D-Cc-Upstream
Trailer
X-Scheme
X-Apw-Access-Action
X-Apw-Access-Object
Proxy-Firewall
Fusion-Deployment-Id
X-Request-Url
X-SB
X-Litespeed-Cache-Control
WP-Super-Cache
X-WPE-Loopback-Upstream-Addr
X-Fpc
Cneonction
X-ElasticPress-Search
X-Upstream-Ht
X-SD-PageType
Backend-Name
X-Worker
Correlation-Id
X-Fastly-Cache-Status
X-App
X-Request-URL
SD-X-WS
X-Check-Cacheable
X-Edge-IP
X-Varnish-Beresp-TTL
X-Powered-Y
X-Upstream-Ct