Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
CF-RAY
Link
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Request-ID
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-DNS-Prefetch-Control
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-Buckets
X-FRAME-OPTIONS
Status
Upgrade
X-Content-Security-Policy
X-CDN
Content-Encoding
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Xss-Protection
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
X-Pass-Why
Xkey
X-Cache-Group
P3p
X-Envoy-Upstream-Service-Time
X-AH-Environment
X-Via
X-Backend
CF-Ray
X-Age
X-Server
X-Ua-Compatible
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Server-Powered-By
X-Page-Speed
X-Ws-Request-Id
X-Pingback
EagleId
X-Proxy-Cache
X-Hacker
X-Nginx-Cache-Status
X-UA-Device
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
Cf-Railgun
Grace
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Amz-Version-Id
Report-To
X-LiteSpeed-Cache
X-Rq
X-Server-Id
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
X-Device
X-Host
X-WebKit-CSP
X-Origin-Cache
EagleEye-TraceId
X-Response-Time
X-Node
X-Ac
Content-Location
Surrogate-Control
X-Vhost
X-Readtime
X-Cloud-Trace-Context
Request-Id
X-Backend-Server
X-Dispatcher
X-Dns-Prefetch-Control
X-Origin-Upstream-Status
X-Cnection
X-Application-Context
X-HW
X-Cache-Lookup
X-ORACLE-DMS-ECID
Fusion-Template-Id
Fusion-Content-Source
Fusion-Component-Id
Fusion-Content-Id
Fusion-Source
X-ORACLE-DMS-RID
X-Ruxit-JS-Agent
NEL
X-DataDome
X-Mod-Pagespeed
X-Rack-Cache
Rating
Edge-Control
X-Country
X-Clacks-Overhead
X-Akam-SW-Version
Pinterest-Generated-By
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Allow
X-TTL
X-Country-Code
Accept-Ch
X-DynaTrace
X-Instart-Request-ID
X-Varnish-TTL
X-Goog-Hash
X-FTR-Request-ID
X-Vname
X-TtlSet
X-PC
X-ESI
Verso
Accept-Ch-Lifetime
Content-MD5
X-Powered-By-Plesk
Service-Worker-Allowed
X-Url
X-B3-TraceId
X-Forwarded-Proto
X-Version
X-MS-InvokeApp
X-GitHub-Request-Id
X-Kinja-Build
X-Kinja-Server
X-Kinja-Revision
X-Kinja
X-Cdn-Fetch
X-Exp-Id
X-Exp-Variant
X-Use-Magma
X-GoogleNews-Bot
RTSS
Edge-Cache-Tag
X-D2id
X-Debug
X-Px
X-Server-Name
AR-CACHE
AR-ATIME
AR-PoweredBy
AR-Request-ID
X-Abt-Application-Version
Ar-Sid
X-Vcache
SPRequestGuid
X-Amz-Server-Side-Encryption
Charset
X-NF-Request-ID
X-Cached
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Accel-Expires
X-TEC-API-ORIGIN
X-MSEdge-Ref
X-Fastcgi-Cache
X-Middleton-Response
Display
X-Sol
X-Middleton-Display
Pagespeed
Response
X-Amz-Rid
X-Vcap-Request-Id
Arr-Disable-Session-Affinity
X-Navigation-Version
X-Pinterest-Rid
Pinterest-Version
X-Powered-CMS
X-SharePointHealthScore
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Trace
X-VARITI-CCR
TCN
Realpath
Public-Key-Pins
Cache-Tag
X-Client-IP
X-Cdn
X-Fastly-Request-ID
MS-Author-Via
X-Ser
Access-Control-Request-Method
Nginx-Cache
X-DynaTrace-JS-Agent
S
X-Shard
SPIisLatency
SPRequestDuration
X-Upstream
Mrf-Cache-Status
MRF-Tech
X-Id
X-B3-TraceId-Primal
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
X-Edge-O15-RID
X-Content-Type
X-Ezoic-Cdn
X-Hp-Webp
X-Grace
X-Amzn-Trace-Id
X-Forwarded-For
X-T
X-Amz-Meta-S3cmd-Attrs
Front-End-Https
DynaTrace
X-Hits
X-Recruiting
Fastcgi-Cache
Nel
X-Jurisdiction
X-Aspnet-Version
ServerID
X-Varnish-Age
X-Cache-TTL
X-Element-Page-Cache
MicrosoftSharePointTeamServices
X-Dw-Request-Base-Id
X-Mobile-URL
X-DIS-Request-ID
X-Content-Digest
X-FTR-Cache-Status
X-FTR-Expires
X-Node-Name
X-Country-Code-Real
X-Server-ID
NR-ENABLED
X-GUploader-UploadID
X-HS-Hub-Id
X-Goog-Storage-Class
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Cache-Config
X-Frontend
Powered
X-FTR-Realm
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Balancer
X-FTR-DC
X-Webkit-Csp
Server-Node
TP-Cache
TP-L2-Cache
Alternate-Protocol
Server-Name
X-Logged-In
X-Correlation-Id
X-CST
AMP-Access-Control-Allow-Source-Origin
X-Request-Processing-Time
X-Request-Received
X-XRDS-LOCATION
X-Amz-Apigw-Id
X-Amzn-RequestId
Upgrade-Insecure-Requests
X-Request-Handler-Origin-Region
X-Microsite
X-ATS-Timestamp
Backend-Timing
X-Cache-Hit
X-Content-Options
X-Origin-Server
X-Content-Security-Policy-Report-Only
Refresh
X-F-Cache
X-User-Agent
X-Rid
X-Akamai-Edgescape
X-Page-Id
X-Revision
Fastly-Restarts
X-Zen-Fury
X-Varnish-Grace
X-Type
X-XRDS-Location
X-Content-Powered-By
X-B3-Sampled
X-LB-Cache
X-B
PB-RID
X-Activity-Id
X-AppVersion
PB-PID
X-Az
X-Geo-Country
X-FTR-Cache-Host
Arc-Version
X-Mobile-Rewrite
Cache-Status
X-URL
X-Shield-Request-Id
X-Kinsta-Cache
X-N
X-Pad
X-Cache-Age
X-TT
X-Instance
X-AOL-HN
X-Time
X-WebKit-CSP-Report-Only
X-Signature
X-B-Cache
X-Jobs
X-Tumblr-Pixel-0
X-Tumblr-User
Actual-Object-TTL
Paypal-Debug-Id
X-Framework
X-Tumblr-Pixel
X-Cache-Action
X-App-Environment
Access-Control-Allow-Method
X-Load-Cache
X-Request-Guid
X-FB-Debug
DC
X-Debug-Info
X-PHP-Backend
X-Cached-By
X-Webapp-Samesite-None-Activated-N
X-Git-Hash
X-Tt-Trace-Tag
X-Varnish-Backend
Fastcgi-Useragent
X-Tt-Trace-Host
Surrogate-Key
X-Erf-Bev-Bev
X-Amz-Replication-Status
X-Erf-Bev-Bev-Is-Generated
X-RateLimit-Remaining
X-Analytics
Host-Header
FilterID
X-IPLB-Instance
X-Contextid
MS-CV
X-ATG-Version
X-SS-Set-Cookie
X-Cache-Key
Host
X-WA-Info
X-ORACLE-APMCS-REQUEST-ID
X-ORACLE-APMCS-TAG
X-Mobile
X-Cluster
X-NWS-LOG-UUID
X-Accel-Buffering
NGB
Tracecode
X-Response-Served-From
X-Via-JSL
WPE-Backend
X-Host-Name
X-Cache-NE
Xserver
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
Source
X-FW-Static
X-FW-Server
X-FW-Type
X-Region
Payment
X-FW-Hash
X-FW-Serve
X-Srv
Eomportal-Instance
X-IPS-LoggedIn
Cache-Tv-Group
X-Tumblr-Pixel-1
X-Varnish-Server
X-Varnish-Hostname
X-Tumblr-Pixel-2
Filters
X-GeoIP
X-Cache-2
Frame-Options
X-Adobe-Loc
X-Origin-Response-Time
X-Cacheable-TTL
X-Adobe-Content
X-Cache-Enabled
X-RequestSource
X-Rendered-As
X-Is-Bot
X-Seen-By
X-TX-ID
X-Cache-Rule
X-Cache-Operation
Retry-After
X-EdgeConnect-Cache-Status
X-NewRelic-App-Data
Cleartype
X-Presslabs-Stats
X-Hostname
Server-Info
X-Cache-TTL-Remaining
X-RemovedCookies
X-FastCGI-Cache
X-ProcessESI
Liferay-Portal
X-VCache
X-UA
Accept-CH
X-Dc
X-RTag
Ms-Operation-Id
X-B3-Traceid
X-Source
X-Environment-Context
X-HTML-Minification-Powered-By
X-L-Path
X-App-Server
Datacenter
X-FireWall-Port
X-Cache-Server
X-Endurance-Cache-Level
X-Upgrade-Enabled
X-PressLabs-Stats
X-Handled-By
X-Cache-Control
From-Origin
Cache
Healthy
Srv
X-CACHE-KEY
X-Backend-Name
X-Wix-Request-Id
Accept-CH-Lifetime
X-Path-Route
X-Status
X-Cache-Var-Map
X-ES-SERVER
Version
Meta-Geo
X-RN-RSRV
X-Cache-Var
Selected-Fe
OT-Force-Account-Verify
X-Proxy-Build
X-Tb
X-Timing-Wait
X-EIG-Tracking-Id
X-Sorting-Hat-ShopId
X-Shopify-Generated-Cart-Token
X-Content-Age
X-Storage
X-OCL
X-Rule
X-Alternate-Cache-Key
Cache-Tags
Azure-Version
X-Sorting-Hat-PodId
X-Format
X-Shopify-Stage
X-Goog-Meta-Goog-Reserved-File-Mtime
Akamai-GRN
Azure-InstanceId
Azure-SlotName
Azure-SiteName
Azure-RegionName
X-Section
Mn-Server-Ip
X-ShopId
X-ShardId
X-Access
X-Proto
X-Origin
X-PCL
X-Akamai-Request-ID
X-Proxy
X-VWS-Id
X-Qloud-Router
Decoy-Debug-Key
X-Web-Node
X-JoinUs
X-Viewer-Country
Now
X-Hosted-By
X-Hl-Ver
Origin-Edge-Control
X-Generated-By
X-FW-Dynamic
Node
Origin-Cache-Control
X-UUID
X-Hyper-Cache
X-Debug-Cache
X-Proxy-Cache-Status
X-Cache-Config
X-ServerID
X-Vgn-Hpd-Reason
X-FC-Vary-Parameters
X-SaId
X-Akamai-Request-ID2
NGX
X-NYM-Debug-Backend
X-AWS-Id
X-Pubstack
Decoy-Debug-TTL
Decoy-Debug-Status
X-Soup
Ec-Rule-Version
X-Redis-Cache
X-LJ-Flow-ID
X-Cluster-Node
X-Request-Time
X-Time-Microsecs
DB-Nickname
X-Yottaa-Metrics
Accept-Charset
X-Yottaa-Optimizations
Webcakes-App-Name
Webcakes-Region
X-BCube-Filmed-By
Webcakes-App-Version
TWC-Privacy
TWC-Connection-Speed
Property-Id
TWC-Device-Class
TWC-GeoIP-Country
TWC-Locale-Group
TWC-GeoIP-LatLong
X-BYPASS-REASON
X-CCM
X-Varnish-Hits
X-Site-Version
X-Www-Served-By
X-Say-Cacheable
X-SayCDN-TTL
X-Say-TTL
X-ProxyCache-Status
X-ProxyCache-Key
X-Generated
X-APP-VERSION
X-Human
X-MP-GENERATED-AT
X-Origin-Hint
Cross-Origin-Window-Policy
X-Ruxit-Js-Agent
X-FB-TRIP-ID
X-Loop
X-RateLimit-Limit
X-Amzn-Remapped-Content-Length
X-Cache-Host
X-Locale
X-R9-Blue-Green-Version
S-Rt
X-TNCMS
X-Xfnlog-Site
X-Akamai-Transformed
X-RCS-CacheZone
X-Detected-As
X-NCache
X-IP
GEO-INFO
L5d-Success-Class
X-CS
X-Ttl
X-Drupal-Cache-Tags
Cache-Name
Time
Webserver
Viewport
Uber-Trace-Id
Cache-Key
X-UA-Device-Type
X-Esi
X-Unique-Id
X-UnsetCookies
X-Cache-Remote
Mime-Version
X-Mode
Accept-Language
X-Daa-Tunnel
X-Forwarded-Host
X-Whom
X-Info
X-Origin-CC
X-From
X-Origin-TTL
Country
X-Trafficlayer-App-Scope
Rt-Fastcgi-Cache
X-Trafficlayer-App-Name
VIX-Pulpo-Node
Odigeo-Trace-Id
VIX-Pulpo-Upstream-Status
X-Cluster-Name
X-ApacheServer
X-Varnish-Cache-Hits
Content-Disposition
X-PERF
X-NGENIX-Cache
X-Backend-TTL
X-Drupal-Cache-Contexts
X-CDN-Forward
X-TT-TIMESTAMP
X-Magnolia-Registration
X-Microcachable
X-Newrelic-Synthetics
ServedBy
X-Geo
X-CLOUD-TRACE-CONTEXT
X-Proxied
X-Zipkin-Id
X-Routing-Service
Proxy-Connection
X-Edge-Location
X-Device-Type
X-B3-Spanid
Section-Io-Cache
X-Via-Fastly
Cf-Ipcountry
Ohc-File-Size
X-EC-Lua
Geo-Info
X-Uri
X-Nc
Ohc-Cache-HIT
X-No-Session
X-UPSTREAM-Address
HitType
MD5-Digest
X-A-Dgt
X-CF-Lambda-Fn
Machine
X-CF-Lambda-Version
X-A-Wwc
Meta-Geo-Continent
Mobile-Detection-Method
X-Accel-Expires-Debug
X-Vdms-Version
X-VG-TLSProxy
X-SRCache-Key
X-VG-WebServer
X-VG-WebCache
X-Vtex-Processado-Em
VivaBuild
Content-Style-Type
Content-Script-Type
X-DPWN-IS-SECURE
BehaviorPad-Version
X-Destination
X-D
Fastcgi-X-Cache-Version
X-Date
GEO-REGION-INFO
AsisCache
X-External-Request-Id
W
X-Transaction
X-A-Dcw
X-Aed
X-A-Dam
X-Geo-Header
X-G
X-Connection-Hash
X-Trv-Group
Viewtype
X-Twitter-Response-Tags
X-Rocket-Build-Number
X-Sigma
X-Rewrite-Enabled
Rendered-Blocks
X-B-Cookie
X-Session-Fingerprint
X-Vtex-Remote-Cache
T-Server
X-Application
X-Rojux
X-S
Xc-Version
X-ScT
X-S-Cookie
X-Sigma-Backend
X-A-Ccd
X-Region-Sid
X-A
X-ARC
X-Request-UUID
User-Cache-Control
X-C
X-App-Version
Access-Control-Request-Headers
X-GeoIP-Country-Code
X-Agile-Age
X-CUA
IsBot
X-Eu-Site
Server-Surrogate-Control
Apple-News-Services-Handled
Apple-News-Services-Host
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Ha-Gx-Prefs
HA-Ipaddr
X-Developers
CDCHOST
Gh-Request-Id
X-Contensis-Viewer-Groups
X-App-Name
X-Distil-CS
Locid
X-Varnish-Authentication
X-Cache-ASPX
X-Thanos
Environment
X-Agile
X-Logging-Id
Powered-By
Fastly-Soc-X-Request-Id
X-Cache-Debug
X-SIPLIST1
X-VC-Cache
X-Wikidot-Backend
X-Agile-Id
X-Varnish-Beresp-Grace
X-Wikidot-Static-Cache
Server-Cache-Control
X-TrackingId
X-Tumblr-Pixel-3
X-Hit
X-Auto-Login
X-WebServer
X-Varnish-Beresp-Status
X-Varnish-Beresp-Ttl
X-Bip
X-CGP
X-PHP-Host
X-TA-CDN-Provider
X-GoCache-CacheStatus
X-Cache-Backend
X-Labrador-Cache-Channel
X-Cache-URL
X-Cdn-Srv
X-Cache-Time
X-Cache-Bucket
X-Block-Status
X-Debug-Cache-Expiry
X-Backend-State
X-Cms-Context
X-Core-Mission
X-Clara-WADP
X-Cache-Info
X-AK-Request-ID
X-BBXSRF
X-IN-APIGATEWAY
X-Real-IP
X-RateLimit-Remaining-Second
X-Request-URI
X-WADP-Cache
X-Clientip
X-Rebelmouse-Cache-Control
X-RateLimit-Limit-Second
X-Proxy-Upstream
X-Origin-Expires
X-Origin-Date
X-OVcl
X-OVcl-Cache
X-Owner
X-We-Are-Hiring
X-Server-W
Countrycode
X-User
X-Urbn-Site-Id
X-Urbn-Context-Path
X-TT-LOGID
X-Webstats-RespID
Fastly-SIE
X-Trace-Id
X-SVT-ORM-RULES
Fastly-SWR
X-SVT-ORM-VERSION
X-Swa-Ws
X-TH-Server
X-NX-Host
X-NodeID
X-Gamma-Serve
X-FW-Version
X-Gen-Mode
X-Generated-In
X-GeoIP-City
X-Generation-Time
X-Fetched-On
X-Fastly-Cache
X-Debug-Cookies
X-Debug-Cache-Store
X-Debug-Log
X-Dispatcher-Server
X-Distributor
X-Hash
X-Hnp-Log
X-Ms-Request-Id
X-Micro-Cache
X-Rebelmouse-Surrogate-Control
X-Ms-Version
X-Nginx-Cache-Key
X-LI-UUID
X-VServer
X-Instart-Isnd
X-IN-APIGATEWAYSSL
X-Irp-Debug
X-Li-Fabric
X-Li-Pop
X-Debug-Cache-Fetch
X-Azure-Ref
Memcached
Mail-Subject
Locale
Request-Country
Request-EU
RNT-Time
RNT-Machine
Kp-EeAlive
IBM-Web2-Location
Cache-Host
AKAMAI
Cdncip
Cdnsip
Fastly-SSL
Country-Code
Server-ID
Heartbleed
Server-Int
We-Hiring
Web-Mar-Node
V-Age
True-Client-Country-4JS
X-Req
X-NU-AKA-ACS-Version
Wxu-Next-Commit
X-Is-Gdpr
Is-Eu
X-Thinkindot-L3
FNAC-ModuleRouting
X-JWT-State
Fastly-Backend-Name
X-Epic-Correlation-Id
X-Matched-Rule
X-Service
X-Key
X-Level-Front-Cache
X-LI-Proto
X-ServiceProvider
ServerName
X-Platform-Server
Wxu-Next-Region
X-Up
X-Generated-On
X-Variation
X-Core-Value
X-Trafficlayer-App-Version
Adler-Geo
Thinkindot-CacheControl-Type
X-Cache-Tags
Thinkindot-CacheControl
X-Reboot
PFcat
Platform
Thinkindot-Control
X-Internal-Host
X-Old-Content-Length
Server-Host
X-Has-Esi
Wxu-Next-Hostname
X-Render-Time
X-Nginx-Cache
X-Servername
X-Air-Hostname
X-Lb-Id
X-S-Maxage
X-Sucuri-Cache
Cache-Hits
X-Var-Ttl
RequestId
X-Refresh
X-Parent-Response-Time
X-SERVER
X-Cache-Expired-At
X-Location
Group
X-Response-By
S-Cnection
X-Cdn-Forward
Pragrma
X-BACKEND-TTL
X-Tb-Optimization-Total-Bytes-Saved
X-CF-Powered-By
Powered-By-ChinaCache
ProcessTime
X-B3-SpanId
Memory
X-B3-Parentspanid
Filterid
X-Tec-Api-Origin
X-Tec-Api-Root
X-CSRF-Token
X-Tec-Api-Version
X-Pjax-Url
X-CSRF-TOKEN
Origin
User-Agent
X-Sucuri-ID
X-Unique-ID
X-Varnish-Cacheable
X-Pf-Uncompressing
X-Server-IP
TTL
X-NC
X-Wa
Geoip-Latitude
X-NWS-UUID-VERIFY
X-Vcl-Version
Geoip-City
GeoIp-Country-Code
X-Via-CDN
X-Correlation-ID
Tcn
X-Ua
SRV
X-Developer
X-Node-Id
X-NGINX-Cache
X-LAGOON
X-Device-Os
X-Ocache
X-Cdn-Request-ID
Media-Length
PICS-Label
X-Cdn-Origin
X-Cache-Grace
X-Sn-Servicetimems
X-COUNTRY
On-Server
X-Oss-Request-Id
X-Cache-Status-Check
X-Oss-Server-Time
X-Oss-Object-Type
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
X-Rocket-Nginx-Bypass
Hostname
X-Sucuri-Id
A
X-Request-Host
X-Litespeed-Cache
X-Webkit-CSP
Dnion-Transfer-Encoding
X-MSEdge-Flight
X-Servedbyhost
X-MSEdge-Features
X-Ratelimit-Remaining
X-Varnish-Ttl
X-Via-Ucdn
SN
Cloudfront-Viewer-Country
XServer
X-TIME
X-Oneagent-Js-Injection
Esi-Enabled
X-HS-Status
M-TraceId
Cdn
X-Reqid
X-AIR-PT
X-FORWARDED-FOR
X-ServedByHost
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Policy
X-Planisys-CDN-TTL
Resin-Trace
X-Varnish-URL
X-Beluga-Status
X-Beluga-Trace
Host-ID
X-Azure-Ref-OriginShield
X-Request-Start
X-Fastly-Country-Code
X-Beluga-Cache-Status
Who
X-Beluga-Response-Time
X-Cache-Ttl
X-Beluga-Node
X-Beluga-Record
HostName
X-Ftr-Cache-Host
X-VHOST
CF-Cached-On
Rt-Proxy-Cache
Pics-Label
X-Slack-Backend
CACHE
NtCoent-Length
X-Action
GeoIP-Country-Code
X-Zone
X-VCL-Version
X-Bc
X-HostName
X-Method
Magicmarker
X-APP
X-Oracle-Dms-Rid
MIME-Version
Arc-Country
X-RSL
X-RPS
X-Processor
X-Cache-FS-Status
X-PAYTM-SRV-ID
X-Dispatch
Pramga
X-DI
X-Ratelimit-Limit
GeoIP-Latitude
Cteonnt-Length
X-Varnish-Url
X-DB
X-DSS
X-Server-Time
Ttl
X-DW
X-RPM
X-Fastly-Backend-Reqs
X-LiteSpeed-Cache-Control
X-DC
X-Hello
X-PF-Uncompressing
X-Flog
X-Newrelic-App-Data
X-VarnishDD-TTL
X-Skip-Cache
X-ND-Cache
X-ABtesting
GeoIP-City
X-FPC
Cdn-Request-Time
X-Swift-Error
Load-Balancing
X-PJAX-URL
Cdn-Host
X-Ftr-Request-Id
Ohc-Response-Time
X-Edge-Server
X-Served-From
X-Svr
X-SRV
WebServer
X-Be
Amp-Access-Control-Allow-Source-Origin
N-Cache
Vix-Hermes-Req-Id
Processtime
X-Dynatrace
X-Bc-Bl
X-WA
Fastly-Drupal-HTML
X-BE
X-MServer
Servername
X-Dynatrace-Js-Agent
DSUID
X-Backend-Host
Section-Io-Origin-Time-Seconds
Section-Io-Id
Section-Io-Origin-Status
Cache-Provider
Section-Origin-Responded
Release
X-VCT
X-ID
X-DevSite-Last-Modified
X-Amzn-Remapped-Date
X-Aicache-OS
X-Amzn-Remapped-Connection
X-Hp-Ccpa-Warning
X-WR-MODIFICATION
X-Frame-Option
X-StackifyID
Requestid
X-Ftr-Balancer
Lfy
X-Ftr-Backend-Server
CDN
X-LB-ID
X-Branch-Name
X-Ftr-Dc
X-Ftr-Realm
Pagetype
X-ZONE
X-Fastly-Cache-Hits
X-Tid
Dynatrace
X-Snapshot-Date
X-Ftr-Backend
X-Configured-By
CF-IPCountry
X-CACHE-AGE
X-Request-Url
Warning
Proxy-Firewall
X-SD-PageType
X-Fmm-Version
WZWS-RAY
X-Upstream-Ht
X-Upstream-Ct
X-Edge-IP
V-Cache
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
X-Cc-Req-Id
X-Cc-Via
X-VC
D-Cc-Upstream
SD-X-WS
X-SB
X-BC
X-Apw-Access-Object
X-Apw-Access-Action
Cneonction
X-Apw-Access-Token
X-Apw-Hits
Cache-Cookie-Set-From
X-Litespeed-Cache-Control
X-WPE-Loopback-Upstream-Addr
FSS-Proxy
FSS-Cache
X-Li-Proto
X-ElasticPress-Search
X-App
X-Worker
WP-Super-Cache
Correlation-Id
Backend-Name
X-SN
X-ServerName
X-Compress-Hint
L
X-Check-Cacheable
X-Varnish-Beresp-TTL
X-Request-URL
X-Powered-Y
Lb
X-Cache-Id
X-Fastly-Cache-Status