Threat Level: green Handler on Duty: Manuel Humberto Santander Pelaez

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-Powered-By
Pragma
CF-Cache-Status
Link
ETag
X-XSS-Protection
Expect-CT
CF-RAY
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Xss-Protection
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-Request-Id
CF-Ray
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Request-ID
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-DNS-Prefetch-Control
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
Status
Upgrade
Content-Encoding
X-Content-Security-Policy
X-CDN
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
X-Pass-Why
X-Cache-Group
X-AH-Environment
X-Envoy-Upstream-Service-Time
X-Via
Xkey
X-Backend
X-Age
X-Server
X-Ws-Request-Id
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
EagleId
X-Page-Speed
X-Server-Powered-By
X-Pingback
X-Proxy-Cache
X-Hacker
X-Nginx-Cache-Status
Request-Context
Feature-Policy
Server-Timing
X-UA-Device
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Cf-Railgun
Ali-Swift-Global-Savetime
Grace
X-Amz-Version-Id
X-Ua-Compatible
Report-To
X-LiteSpeed-Cache
X-OneAgent-JS-Injection
X-Rq
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-WebKit-CSP
X-Device
X-Host
X-Server-Id
X-Origin-Cache
X-Response-Time
EagleEye-TraceId
X-Node
X-Ac
Surrogate-Control
Content-Location
X-Cloud-Trace-Context
X-Vhost
X-Backend-Server
X-Readtime
X-Dispatcher
X-Dns-Prefetch-Control
X-Cache-Lookup
Request-Id
X-Ruxit-JS-Agent
X-Origin-Upstream-Status
X-Cnection
X-Application-Context
X-HW
Fusion-Source
Fusion-Template-Id
Fusion-Content-Source
Fusion-Content-Id
Fusion-Component-Id
X-ORACLE-DMS-ECID
X-Mod-Pagespeed
NEL
X-ORACLE-DMS-RID
P3p
X-DataDome
X-Rack-Cache
X-Country
X-Clacks-Overhead
X-Akam-SW-Version
Rating
Edge-Control
Allow
Pinterest-Generated-By
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Country-Code
Accept-Ch
X-FTR-Request-ID
X-Instart-Request-ID
X-Varnish-TTL
X-DynaTrace
X-Goog-Hash
X-TtlSet
X-Vname
X-PC
X-TTL
Content-MD5
Verso
X-ESI
Accept-Ch-Lifetime
Service-Worker-Allowed
X-Url
X-Powered-By-Plesk
X-GitHub-Request-Id
X-GoogleNews-Bot
X-Exp-Variant
X-Kinja-Server
X-Exp-Id
X-Kinja-Build
X-Kinja-Revision
X-Cdn-Fetch
X-Use-Magma
X-Kinja
RTSS
X-Version
X-Forwarded-Proto
X-Server-Name
X-MS-InvokeApp
X-Vcache
X-D2id
X-B3-TraceId
Edge-Cache-Tag
X-Abt-Application-Version
X-Px
X-Debug
AR-ATIME
AR-PoweredBy
Ar-Sid
X-Amz-Server-Side-Encryption
AR-Request-ID
AR-CACHE
SPRequestGuid
X-Cached
Charset
X-NF-Request-ID
X-Vcap-Request-Id
X-Navigation-Version
X-MSEdge-Ref
Pagespeed
Display
X-Amz-Rid
Response
X-Middleton-Response
X-Middleton-Display
X-Server-ID
X-Sol
Arr-Disable-Session-Affinity
X-Accel-Expires
TCN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-SharePointHealthScore
X-VARITI-CCR
X-Fastly-Request-ID
X-Pinterest-Rid
Pinterest-Version
Nginx-Cache
MS-Author-Via
X-Cdn
Public-Key-Pins
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Trace
X-Powered-CMS
X-Fastcgi-Cache
X-Client-IP
X-Edge-O15-RID
Cache-Tag
Realpath
X-Ser
Access-Control-Request-Method
X-Content-Type
X-B3-TraceId-Primal
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
MRF-Tech
Mrf-Cache-Status
SPIisLatency
SPRequestDuration
X-Amzn-Trace-Id
X-Grace
X-Upstream
X-Shard
X-Hp-Webp
X-Jurisdiction
X-Id
X-Cache-TTL
X-Ezoic-Cdn
Front-End-Https
X-Forwarded-For
X-Hits
Fastcgi-Cache
X-Amz-Meta-S3cmd-Attrs
Nel
S
X-T
X-DynaTrace-JS-Agent
X-Aspnet-Version
X-Recruiting
DynaTrace
X-Element-Page-Cache
X-Content-Digest
X-Node-Name
X-Dw-Request-Base-Id
X-FTR-DC
X-FTR-Expires
X-FTR-Realm
X-FTR-Cache-Status
X-Mobile-URL
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Backend
X-Varnish-Age
X-FTR-Balancer
MicrosoftSharePointTeamServices
ServerID
X-DIS-Request-ID
NR-ENABLED
TP-Cache
Server-Node
TP-L2-Cache
X-Frontend
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Combine-CSS
X-Goog-Storage-Class
X-GUploader-UploadID
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
Powered
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Logged-In
X-Correlation-Id
X-CST
Alternate-Protocol
Server-Name
X-Amz-Apigw-Id
Upgrade-Insecure-Requests
X-Amzn-RequestId
X-XRDS-Location
Fastly-Restarts
X-Cache-Hit
X-FTR-Cache-Host
AMP-Access-Control-Allow-Source-Origin
X-Microsite
X-Request-Handler-Origin-Region
Backend-Timing
X-ATS-Timestamp
X-Zen-Fury
X-Content-Options
X-Page-Id
Refresh
X-User-Agent
X-Content-Security-Policy-Report-Only
X-Request-Processing-Time
X-Request-Received
X-F-Cache
X-Akamai-Edgescape
X-Origin-Server
X-Varnish-Grace
X-Rid
X-LB-Cache
X-Revision
X-B
PB-PID
Arc-Version
X-Content-Powered-By
X-Mobile-Rewrite
PB-RID
X-Type
X-XRDS-LOCATION
X-B3-Sampled
Cache-Status
X-Geo-Country
X-Activity-Id
X-AppVersion
X-Az
X-Kinsta-Cache
X-NWS-LOG-UUID
X-Cache-Action
X-TT
X-AOL-HN
X-WebKit-CSP-Report-Only
X-N
X-B-Cache
X-Cached-By
X-Framework
X-Signature
X-Request-Guid
X-Jobs
X-App-Environment
Access-Control-Allow-Method
X-Instance
X-FB-Debug
X-Time
X-Git-Hash
X-PHP-Backend
X-Debug-Info
Actual-Object-TTL
Paypal-Debug-Id
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Cache-Age
X-URL
X-Load-Cache
X-Tt-Trace-Tag
X-Tt-Trace-Host
Fastcgi-Useragent
X-Amz-Replication-Status
X-Webkit-Csp
X-FastCGI-Cache
DC
X-Varnish-Backend
X-Pad
Host-Header
Host
X-ATG-Version
X-WA-Info
X-RateLimit-Remaining
X-ORACLE-APMCS-TAG
X-ORACLE-APMCS-REQUEST-ID
X-Shield-Request-Id
X-Via-JSL
MS-CV
X-IPLB-Instance
Surrogate-Key
X-Contextid
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Mobile
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Host-Name
X-Cache-Key
Retry-After
Frame-Options
Liferay-Portal
X-Response-Served-From
X-Accel-Buffering
NGB
X-Seen-By
X-Presslabs-Stats
Payment
X-B3-Traceid
X-Hostname
Source
X-Cache-NE
X-Srv
X-Origin-Response-Time
Eomportal-Instance
X-Cache-2
X-Varnish-Server
X-Region
X-Cache-Enabled
X-Cacheable-TTL
Tracecode
X-GeoIP
X-NewRelic-App-Data
X-Cluster
Filters
X-IPS-LoggedIn
X-FW-Static
X-FW-Hash
X-FW-Serve
WPE-Backend
X-SS-Set-Cookie
X-FW-Type
X-Rendered-As
X-FW-Server
X-Is-Bot
Cache-Tv-Group
X-Ttl
X-Varnish-Hostname
Server-Info
X-Adobe-Content
X-Adobe-Loc
X-Cache-Rule
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
X-RequestSource
X-Cache-Operation
X-App-Server
X-RemovedCookies
X-ProcessESI
FilterID
X-EdgeConnect-Cache-Status
Xserver
X-TX-ID
X-Cache-TTL-Remaining
Accept-CH
X-L-Path
X-Environment-Context
X-FireWall-Port
Cleartype
X-Analytics
X-Upgrade-Enabled
X-Handled-By
Accept-Charset
X-Source
X-RTag
Ms-Operation-Id
X-UA
X-Endurance-Cache-Level
X-Cache-Server
From-Origin
X-Backend-Name
Srv
X-HTML-Minification-Powered-By
Datacenter
Accept-CH-Lifetime
X-Dc
X-APP-VERSION
X-CACHE-KEY
X-UUID
X-Daa-Tunnel
X-Wix-Request-Id
Healthy
X-ES-SERVER
GEO-INFO
Meta-Geo
X-Cache-Var-Map
X-Cache-Var
X-RN-RSRV
X-Path-Route
X-Unique-Id
X-Proxy-Build
X-Tb
X-Section
X-Timing-Wait
X-Status
OT-Force-Account-Verify
X-Access
Selected-Fe
X-Akamai-Transformed
X-Akamai-Request-ID
X-Format
X-Content-Age
Akamai-GRN
X-EIG-Tracking-Id
X-Cache-Config
X-Alternate-Cache-Key
X-OCL
Mn-Server-Ip
X-Goog-Meta-Goog-Reserved-File-Mtime
X-FC-Vary-Parameters
X-Sorting-Hat-PodId
X-Webapp-Samesite-None-Activated-N
X-Ua-Device
X-ShardId
X-Sorting-Hat-ShopId
X-Shopify-Stage
X-Request-Time
X-ShopId
Cache-Tags
X-PCL
X-Shopify-Generated-Cart-Token
X-Proto
X-SaId
Origin-Edge-Control
X-Debug-Cache
X-Say-Cacheable
X-Soup
X-VWS-Id
X-Qloud-Router
X-Redis-Cache
X-Web-Node
X-Vgn-Hpd-Reason
X-AWS-Id
Decoy-Debug-Status
Decoy-Debug-TTL
Ec-Rule-Version
Node
Decoy-Debug-Key
X-Hl-Ver
X-Say-TTL
X-SayCDN-TTL
Origin-Cache-Control
X-BYPASS-REASON
X-Whom
X-ProxyCache-Status
X-JoinUs
X-Hyper-Cache
X-ProxyCache-Key
X-LJ-Flow-ID
X-Yottaa-Metrics
X-NYM-Debug-Backend
X-Yottaa-Optimizations
X-Human
X-Proxy-Cache-Status
X-Origin
X-Hosted-By
X-Proxy
X-Akamai-Request-ID2
X-Viewer-Country
Now
Azure-Version
X-Www-Served-By
Azure-InstanceId
X-Loop
X-Site-Version
DB-Nickname
X-MP-GENERATED-AT
X-FW-Dynamic
X-Locale
X-Generated
X-FB-TRIP-ID
Azure-SiteName
X-Generated-By
X-Storage
NGX
X-TNCMS
X-Pubstack
Version
Azure-RegionName
Azure-SlotName
X-CCM
X-Detected-As
X-Time-Microsecs
X-BCube-Filmed-By
Cross-Origin-Window-Policy
X-IP
X-R9-Blue-Green-Version
Property-Id
S-Rt
X-NCache
X-RCS-CacheZone
X-ServerID
X-Origin-Hint
X-Xfnlog-Site
X-Varnish-Hits
TWC-Connection-Speed
TWC-Privacy
Webcakes-App-Name
Webcakes-App-Version
Webcakes-Region
TWC-Device-Class
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-GeoIP-Country
X-Amzn-Remapped-Content-Length
X-PressLabs-Stats
X-Cluster-Node
X-Backend-TTL
X-VCache
X-UA-Device-Type
Cache-Key
X-RateLimit-Limit
X-NGENIX-Cache
X-Cache-Control
Section-Io-Cache
X-Cache-Host
X-Forwarded-Host
X-Mode
X-Drupal-Cache-Tags
X-Esi
X-CDN-Forward
Webserver
Cache
X-Rule
Content-Disposition
Time
L5d-Success-Class
X-Info
X-UnsetCookies
Cache-Name
X-Varnish-Cache-Hits
X-PERF
X-ApacheServer
Accept-Language
Rt-Fastcgi-Cache
X-B3-Spanid
Viewport
X-Origin-CC
X-CS
ServedBy
X-Origin-TTL
X-Newrelic-Synthetics
Uber-Trace-Id
Country
Mime-Version
Odigeo-Trace-Id
X-Device-Type
X-Zipkin-Id
X-Proxied
X-Routing-Service
X-Cache-Remote
X-Via-Fastly
X-Magnolia-Registration
X-CLOUD-TRACE-CONTEXT
X-Uri
Proxy-Connection
X-From
Filterid
X-Geo
X-Real-IP
Access-Control-Request-Headers
X-EC-Lua
X-Cluster-Name
X-Drupal-Cache-Contexts
HitType
X-Microcachable
X-TT-TIMESTAMP
Content-Script-Type
Apple-News-Services-Handled
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
X-PHP-Host
Mobile-Detection-Method
X-Cache-Time
X-Labrador-Cache-Channel
Apple-News-Services-Request-Url
AsisCache
Machine
MD5-Digest
GEO-REGION-INFO
Fastcgi-X-Cache-Version
BehaviorPad-Version
Content-Style-Type
Meta-Geo-Continent
X-A-Dcw
X-S-Cookie
X-S
X-ScT
X-Session-Fingerprint
X-Sigma
X-Rojux
X-Rocket-Build-Number
X-GeoIP-Country-Code
X-Region-Sid
X-Request-UUID
X-Rewrite-Enabled
X-Sigma-Backend
X-SRCache-Key
X-VG-WebServer
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-VG-WebCache
X-VG-TLSProxy
X-Transaction
X-Trv-Group
X-Twitter-Response-Tags
X-Vdms-Version
X-Geo-Header
X-G
X-A-Ccd
X-A
X-A-Dam
X-A-Dgt
X-A-Wwc
W
VIX-Pulpo-Upstream-Status
T-Server
Viewtype
VivaBuild
VIX-Pulpo-Node
X-Accel-Expires-Debug
X-Aed
X-D
X-Date
X-DPWN-IS-SECURE
X-External-Request-Id
X-Connection-Hash
X-CF-Lambda-Version
X-Application
X-ARC
X-B-Cookie
X-CF-Lambda-Fn
Rendered-Blocks
X-Destination
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Status
Cf-Ipcountry
Group
X-Varnish-Beresp-Grace
X-C
Cache-Hits
Ohc-File-Size
Geo-Info
User-Cache-Control
Countrycode
Environment
Fastly-Soc-X-Request-Id
Powered-By
X-App-Name
X-CGP
CDCHOST
X-Agile-Id
X-Cache-Expired-At
IsBot
X-Bip
X-VC-Cache
Locid
X-Backend-State
X-WebServer
X-Var-Ttl
HA-Ipaddr
X-Clientip
Fastly-SWR
X-Wikidot-Static-Cache
X-Wikidot-Backend
Ha-Gx-Prefs
X-Cache-Debug
Fastly-SIE
X-Agile-Age
X-Rebelmouse-Cache-Control
X-Eu-Site
X-Developers
X-Rebelmouse-Surrogate-Control
X-OVcl
X-Hit
X-SIPLIST1
X-OVcl-Cache
X-Distil-CS
X-Thanos
X-Logging-Id
X-Cdn-Srv
X-Agile
X-CUA
X-TrackingId
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
X-GoCache-CacheStatus
We-Hiring
Web-Mar-Node
X-Nc
X-Origin-Date
X-Proxy-Upstream
X-Azure-Ref
X-Owner
X-NU-AKA-ACS-Version
X-Air-Hostname
X-Origin-Expires
X-NodeID
X-RateLimit-Remaining-Second
X-Request-URI
X-RateLimit-Limit-Second
X-NX-Host
X-Cache-Tags
X-Li-Fabric
X-Fastly-Cache
X-Fetched-On
X-Epic-Correlation-Id
X-Li-Pop
X-Dispatcher-Server
X-Distributor
X-Irp-Debug
X-Gen-Mode
X-IN-APIGATEWAY
X-Hash
X-GeoIP-City
X-IN-APIGATEWAYSSL
X-Generated-In
X-Instart-Isnd
X-LI-Proto
X-Debug-Log
X-Cache-Info
X-Servername
X-Cache-Bucket
X-Block-Status
X-BBXSRF
X-Nginx-Cache-Key
X-Cache-URL
X-Ms-Version
X-LI-UUID
X-Debug-Cookies
X-Core-Mission
X-Micro-Cache
X-Ms-Request-Id
X-Clara-WADP
X-No-Session
X-Trace-Id
Locale
Country-Code
Server-Cache-Control
Cache-Host
Server-Surrogate-Control
Gh-Request-Id
V-Age
Is-Eu
Kp-EeAlive
IBM-Web2-Location
Heartbleed
X-Webstats-RespID
Adler-Geo
X-Auto-Login
X-Varnish-Authentication
X-Urbn-Site-Id
AKAMAI
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Urbn-Context-Path
X-JWT-State
X-Cms-Context
X-Cache-ASPX
X-Contensis-Viewer-Groups
X-Has-Esi
X-Is-Gdpr
X-We-Are-Hiring
Fastly-Backend-Name
X-Hnp-Log
Request-EU
Request-Country
Pragrma
RNT-Machine
Mail-Subject
True-Client-Country-4JS
X-Swa-Ws
Server-Int
X-TH-Server
Platform
RNT-Time
X-VServer
Memcached
X-Variation
X-WADP-Cache
X-Up
S-Cnection
Fastly-SSL
X-Edge-Location
X-Server-W
X-Level-Front-Cache
X-TT-LOGID
X-Req
X-ServiceProvider
X-Generation-Time
X-NC
X-Reboot
X-Tumblr-Pixel-3
X-Gamma-Serve
X-Matched-Rule
X-Platform-Server
X-AK-Request-ID
X-Trafficlayer-App-Version
X-Trafficlayer-App-Scope
Cdnsip
Cdncip
X-FW-Version
X-Trafficlayer-App-Name
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-Thinkindot-L3
X-Service
Server-ID
X-Core-Value
Wxu-Next-Commit
FNAC-ModuleRouting
PFcat
Wxu-Next-Region
ServerName
Thinkindot-CacheControl
Ohc-Cache-HIT
Server-Host
Thinkindot-Control
Thinkindot-CacheControl-Type
Wxu-Next-Hostname
X-Generated-On
X-Oss-Request-Id
X-VHOST
X-Oss-Storage-Class
X-Oss-Object-Type
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-Varnish-Cacheable
X-SERVER
X-Old-Content-Length
X-App-Version
X-Response-By
X-Lb-Id
X-Sucuri-ID
X-UPSTREAM-Address
X-Wa
User-Agent
X-Refresh
X-Nginx-Cache
X-S-Maxage
X-Node-Id
X-NWS-UUID-VERIFY
X-Render-Time
X-Developer
Powered-By-ChinaCache
X-CSRF-TOKEN
RequestId
X-Cache-Status-Check
X-Cache-Backend
Hostname
X-Parent-Response-Time
X-Device-Os
X-User
X-Cache-Grace
X-Cdn-Origin
X-Sn-Servicetimems
X-LAGOON
X-CF-Powered-By
X-Ocache
X-Internal-Host
X-Key
Origin
X-Sucuri-Cache
On-Server
X-Tb-Optimization-Total-Bytes-Saved
X-Pjax-Url
A
X-Pf-Uncompressing
X-CSRF-Token
X-MSEdge-Features
X-Via-CDN
X-MSEdge-Flight
X-Request-Host
Cloudfront-Viewer-Country
Geoip-City
Geoip-Latitude
Memory
X-TA-CDN-Provider
X-Location
SRV
X-NGINX-Cache
X-Ua
PICS-Label
GeoIp-Country-Code
X-COUNTRY
ProcessTime
X-B3-Parentspanid
X-Varnish-URL
XServer
X-BACKEND-TTL
X-Cdn-Forward
Resin-Trace
X-Litespeed-Cache
X-Webkit-CSP
X-Servedbyhost
X-Vcl-Version
TTL
X-Varnish-Ttl
X-Server-IP
X-TIME
Dnion-Transfer-Encoding
Tcn
M-TraceId
X-Dynatrace-Js-Agent
X-HS-Status
X-Rocket-Nginx-Bypass
X-Slack-Backend
SN
X-FORWARDED-FOR
X-PAYTM-SRV-ID
Host-ID
X-B3-SpanId
Media-Length
X-Dispatch
X-Cache-FS-Status
Pramga
Arc-Country
X-Server-Time
X-Unique-ID
X-Processor
X-Cdn-Request-ID
Cdn
X-Ratelimit-Remaining
CACHE
X-Beluga-Node
X-Beluga-Cache-Status
X-Fastly-Country-Code
X-Action
X-Beluga-Record
X-ND-Cache
X-Cache-Ttl
X-VCL-Version
X-Beluga-Trace
X-Beluga-Response-Time
X-Skip-Cache
X-Beluga-Status
X-ServedByHost
HostName
X-DC
Section-Origin-Responded
Section-Io-Id
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Cdn-Request-Time
Cdn-Host
Fastly-Drupal-HTML
X-RPM
X-DW
X-Ruxit-Js-Agent
X-RPS
X-RSL
X-Served-From
X-DSS
Who
X-DI
X-Edge-Server
X-DB
Ttl
Fusion-Deployment-Id
X-DevSite-Last-Modified
N-Cache
X-Correlation-ID
MIME-Version
X-Via-Ucdn
X-Hello
GeoIP-Country-Code
Pics-Label
X-Reqid
X-Adobe-Source
X-Flog
X-ABtesting
X-Bc-Bl
NtCoent-Length
X-Oracle-Dms-Rid
CF-Cached-On
X-LiteSpeed-Cache-Control
GeoIP-Latitude
GeoIP-City
X-Varnish-Url
Esi-Enabled
X-AIR-PT
X-VarnishDD-TTL
X-Backend-Host
X-Planisys-CDN-TTL
X-Ratelimit-Limit
X-Policy
X-Planisys-CDN-Rules
X-Bc
Cache-Cookie-Set-From
X-Zone
X-PJAX-URL
X-PF-Uncompressing
X-FPC
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
X-APP
X-Sucuri-Id
X-Planisys-CDN-Cache
Trailer
X-HostName
WebServer
X-SRV
Cteonnt-Length
X-Request-Start
X-Fastly-Backend-Reqs
X-Azure-Ref-OriginShield
X-Scheme
X-Fmm-Version
Amp-Access-Control-Allow-Source-Origin
X-Amzn-Remapped-Connection
X-Dynatrace
X-Amzn-Remapped-Date
Processtime
X-BE
Rt-Proxy-Cache
X-Fpc
X-Swift-Error
Servername
CF-IPCountry
X-Newrelic-App-Data
X-Esi-Check
Magicmarker
X-ZONE
Cache-Provider
X-Cache-Id
X-BC
X-SN
X-ID
FSS-Proxy
X-WA
FSS-Cache
Requestid
X-WR-MODIFICATION
X-Frame-Option
X-Gzip
X-Snapshot-Date
X-Branch-Name
X-LB-ID
Lb
CDN
Dynatrace
Load-Balancing
Sid
X-SD-PageType
Release
X-Cache-NGX
SD-X-WS
X-StackifyID
X-Method
X-CACHE-AGE
X-Compress-Hint
X-Tid
WZWS-RAY
L
X-VCT
X-Fastly-Cache-Hits
X-Instart-Info
X-Cc-Via
X-Wix-Viewer-Type
X-Aicache-OS
X-Request-Url
X-ECACHE
V-Cache
X-SB
D-Cc-Upstream
X-Cc-Req-Id
Warning
X-VC
X-Configured-By
X-Litespeed-Cache-Control
X-Node-ID
SID
Request-Time
X-Nananana
Proxy-Firewall
Server-Id
X-ElasticPress-Search
X-Apw-Access-Token
X-Apw-Hits
WP-Super-Cache
X-Apw-Access-Object
X-Apw-Access-Action
Ohc-Response-Time
X-Worker
X-Powered-Y
X-Request-URL
Cneonction
X-App
X-WPE-Loopback-Upstream-Addr
X-Fastly-Cache-Status
X-Check-Cacheable
X-Varnish-Beresp-TTL
X-GEO