Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-Powered-By
Pragma
CF-Cache-Status
X-XSS-Protection
CF-RAY
Link
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Xss-Protection
X-Request-ID
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-DNS-Prefetch-Control
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
Status
Upgrade
X-Content-Security-Policy
Content-Encoding
X-CDN
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
X-Pass-Why
X-Cache-Group
X-AH-Environment
Xkey
X-Envoy-Upstream-Service-Time
CF-Ray
X-Via
X-Backend
X-Server
X-Age
X-Amz-Id-2
X-Amz-Request-Id
X-Ws-Request-Id
X-Robots-Tag
X-Page-Speed
X-Server-Powered-By
X-Pingback
EagleId
X-Proxy-Cache
X-Hacker
X-UA-Device
X-Nginx-Cache-Status
Request-Context
Feature-Policy
X-Varnish-Cache
Server-Timing
Cf-Railgun
X-Swift-CacheTime
X-Swift-SaveTime
Grace
Ali-Swift-Global-Savetime
X-Amz-Version-Id
X-Ua-Compatible
Report-To
X-LiteSpeed-Cache
X-Rq
X-OneAgent-JS-Injection
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-WebKit-CSP
X-Device
X-Host
X-Origin-Cache
X-Server-Id
X-Response-Time
EagleEye-TraceId
X-Ac
X-Node
Surrogate-Control
Content-Location
X-Cloud-Trace-Context
X-Readtime
X-Backend-Server
Request-Id
X-Vhost
X-Dispatcher
X-Origin-Upstream-Status
X-Cache-Lookup
X-Cnection
X-Ruxit-JS-Agent
X-Application-Context
X-HW
P3p
Fusion-Content-Id
Fusion-Component-Id
Fusion-Content-Source
Fusion-Source
Fusion-Template-Id
X-ORACLE-DMS-ECID
X-Mod-Pagespeed
NEL
X-ORACLE-DMS-RID
X-DataDome
X-Dns-Prefetch-Control
X-Rack-Cache
Rating
X-Country
X-Clacks-Overhead
Edge-Control
X-Akam-SW-Version
Pinterest-Generated-By
Allow
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-TTL
X-Country-Code
X-FTR-Request-ID
X-Instart-Request-ID
X-Varnish-TTL
X-DynaTrace
X-Goog-Hash
Accept-Ch
X-PC
X-Vname
X-TtlSet
Verso
X-ESI
Content-MD5
Service-Worker-Allowed
X-Powered-By-Plesk
Accept-Ch-Lifetime
X-Url
X-B3-TraceId
X-Forwarded-Proto
X-MS-InvokeApp
X-Version
X-Kinja-Build
X-Exp-Id
X-GoogleNews-Bot
X-Exp-Variant
X-Kinja-Revision
X-GitHub-Request-Id
X-Kinja-Server
X-Kinja
X-Cdn-Fetch
X-Use-Magma
X-Vcache
X-Server-Name
X-Server-ID
Edge-Cache-Tag
RTSS
X-Abt-Application-Version
X-Debug
X-Px
X-D2id
AR-CACHE
X-Amz-Server-Side-Encryption
Ar-Sid
AR-Request-ID
AR-PoweredBy
AR-ATIME
SPRequestGuid
Charset
X-Cached
X-NF-Request-ID
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Middleton-Response
X-Sol
Pagespeed
Display
Response
X-Middleton-Display
X-Vcap-Request-Id
X-Fastcgi-Cache
X-MSEdge-Ref
X-Accel-Expires
Arr-Disable-Session-Affinity
X-Amz-Rid
X-Navigation-Version
Pinterest-Version
X-Pinterest-Rid
TCN
X-SharePointHealthScore
X-Powered-CMS
X-Edge-O15-RID
X-SRCache-Store-Status
X-Cdn
X-SRCache-Fetch-Status
X-VARITI-CCR
Public-Key-Pins
X-Fastly-Request-ID
Cache-Tag
X-Client-IP
X-Trace
Realpath
Nginx-Cache
MS-Author-Via
X-Ser
Access-Control-Request-Method
MRF-Tech
X-B3-TraceId-Primal
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
Mrf-Cache-Status
X-Shard
X-Content-Type
SPIisLatency
SPRequestDuration
X-Grace
X-Amzn-Trace-Id
X-Hp-Webp
X-Jurisdiction
X-Ezoic-Cdn
S
X-Id
X-Upstream
X-DynaTrace-JS-Agent
X-Forwarded-For
X-Amz-Meta-S3cmd-Attrs
X-T
Nel
X-Hits
Front-End-Https
Fastcgi-Cache
X-Recruiting
X-Aspnet-Version
X-Cache-TTL
DynaTrace
ServerID
X-Varnish-Age
X-Element-Page-Cache
X-Node-Name
X-Mobile-URL
MicrosoftSharePointTeamServices
X-Content-Digest
X-FTR-Cache-Status
X-FTR-DC
X-FTR-Balancer
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Backend
X-FTR-Realm
X-FTR-Expires
X-Dw-Request-Base-Id
X-DIS-Request-ID
X-HS-Cache-Config
X-HS-Content-Id
Server-Node
X-HS-Combine-CSS
X-HS-Hub-Id
NR-ENABLED
X-Frontend
Powered
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Generation
X-GUploader-UploadID
TP-L2-Cache
TP-Cache
X-Logged-In
X-CST
Alternate-Protocol
Server-Name
X-Correlation-Id
X-Amz-Apigw-Id
X-Amzn-RequestId
Upgrade-Insecure-Requests
AMP-Access-Control-Allow-Source-Origin
X-Request-Handler-Origin-Region
Fastly-Restarts
X-XRDS-Location
X-Microsite
X-Request-Processing-Time
X-Request-Received
Backend-Timing
X-ATS-Timestamp
X-Cache-Hit
X-Origin-Server
X-Content-Options
X-F-Cache
X-User-Agent
X-Content-Security-Policy-Report-Only
X-Page-Id
X-Zen-Fury
X-Rid
X-FTR-Cache-Host
Refresh
X-Akamai-Edgescape
X-Revision
X-Varnish-Grace
X-Type
X-LB-Cache
X-Content-Powered-By
X-XRDS-LOCATION
X-B
PB-RID
PB-PID
X-B3-Sampled
Arc-Version
X-URL
X-Mobile-Rewrite
X-Geo-Country
Cache-Status
X-Activity-Id
X-AppVersion
X-Az
X-Kinsta-Cache
X-N
X-Cache-Age
X-TT
X-Cache-Action
X-Signature
X-Instance
X-B-Cache
X-Tumblr-Pixel
X-Jobs
X-Debug-Info
Access-Control-Allow-Method
Actual-Object-TTL
X-AOL-HN
X-Tumblr-Pixel-0
X-Framework
X-Tumblr-User
X-WebKit-CSP-Report-Only
X-Cached-By
X-App-Environment
X-Time
Paypal-Debug-Id
X-Request-Guid
X-Load-Cache
X-FB-Debug
X-Git-Hash
X-PHP-Backend
Fastcgi-Useragent
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Pad
DC
X-Shield-Request-Id
X-Webkit-Csp
X-Amz-Replication-Status
X-RateLimit-Remaining
X-Varnish-Backend
X-NWS-LOG-UUID
Host-Header
X-IPLB-Instance
Surrogate-Key
MS-CV
X-WA-Info
X-Contextid
X-ATG-Version
Host
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-ORACLE-APMCS-REQUEST-ID
X-ORACLE-APMCS-TAG
X-Via-JSL
X-SS-Set-Cookie
X-Mobile
X-Response-Served-From
NGB
X-Accel-Buffering
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Host-Name
Payment
X-Analytics
Frame-Options
X-Cluster
Tracecode
X-Cache-NE
X-FW-Static
Xserver
X-FW-Serve
X-Varnish-Server
X-FW-Server
WPE-Backend
Source
FilterID
X-Origin-Response-Time
X-FW-Hash
X-FW-Type
X-Cache-2
X-Varnish-Hostname
X-Tumblr-Pixel-1
X-Region
X-Cache-Key
X-Webapp-Samesite-None-Activated-N
X-Tumblr-Pixel-2
Eomportal-Instance
X-IPS-LoggedIn
X-Cache-Enabled
X-Cacheable-TTL
X-GeoIP
X-Adobe-Content
Accept-CH
X-Adobe-Loc
X-Seen-By
X-Cache-Operation
X-Cache-Rule
X-RequestSource
Filters
X-Hostname
X-Srv
Cache-Tv-Group
X-Is-Bot
X-Rendered-As
Retry-After
X-NewRelic-App-Data
X-Presslabs-Stats
X-EdgeConnect-Cache-Status
X-TX-ID
Server-Info
Liferay-Portal
X-FastCGI-Cache
X-Cache-TTL-Remaining
X-App-Server
Cleartype
X-ProcessESI
X-RemovedCookies
X-B3-Traceid
Accept-CH-Lifetime
X-L-Path
X-Environment-Context
X-CACHE-KEY
X-FireWall-Port
X-RTag
Ms-Operation-Id
X-Source
X-Handled-By
X-Dc
X-Endurance-Cache-Level
Datacenter
From-Origin
X-HTML-Minification-Powered-By
X-Upgrade-Enabled
X-UA
X-Backend-Name
Srv
Accept-Charset
X-Cache-Server
X-PressLabs-Stats
X-RN-RSRV
Meta-Geo
X-Path-Route
X-ES-SERVER
X-Cache-Var
X-Cache-Var-Map
X-Timing-Wait
Selected-Fe
X-Tb
OT-Force-Account-Verify
X-UUID
X-Format
X-Wix-Request-Id
X-Proxy-Build
X-APP-VERSION
X-Alternate-Cache-Key
Azure-InstanceId
X-OCL
Azure-Version
X-Content-Age
Azure-SlotName
X-FC-Vary-Parameters
X-Access
Mn-Server-Ip
X-Proto
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Request-Time
X-PCL
X-NYM-Debug-Backend
Azure-SiteName
X-EIG-Tracking-Id
X-ShopId
X-Cache-Config
X-Origin
Akamai-GRN
X-Shopify-Stage
X-Shopify-Generated-Cart-Token
Azure-RegionName
X-Sorting-Hat-PodId
X-ShardId
X-Akamai-Request-ID
X-Sorting-Hat-ShopId
X-Section
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Hosted-By
Ec-Rule-Version
DB-Nickname
Cache-Tags
X-Qloud-Router
X-ProxyCache-Status
X-SaId
X-Proxy-Cache-Status
X-BYPASS-REASON
X-Pubstack
X-Cluster-Node
X-FW-Dynamic
X-JoinUs
X-Viewer-Country
X-Vgn-Hpd-Reason
X-VWS-Id
Origin-Edge-Control
Origin-Cache-Control
X-Cache-Control
Cache
X-ServerID
X-Soup
X-Status
X-Time-Microsecs
Now
X-ProxyCache-Key
Node
NGX
X-LJ-Flow-ID
X-Hyper-Cache
X-AWS-Id
Version
Webcakes-App-Version
TWC-GeoIP-LatLong
TWC-Locale-Group
TWC-Device-Class
TWC-GeoIP-Country
TWC-Connection-Speed
Property-Id
Webcakes-Region
Webcakes-App-Name
X-BCube-Filmed-By
Cross-Origin-Window-Policy
X-Amzn-Remapped-Content-Length
Decoy-Debug-Key
X-Akamai-Request-ID2
Decoy-Debug-TTL
Decoy-Debug-Status
TWC-Privacy
X-Human
X-Hl-Ver
X-Generated-By
X-SayCDN-TTL
X-Web-Node
X-Proxy
X-Loop
X-Say-TTL
X-Varnish-Hits
X-Origin-Hint
X-Storage
X-Debug-Cache
X-CCM
X-Say-Cacheable
X-FB-TRIP-ID
X-NCache
X-TNCMS
X-RateLimit-Limit
X-Xfnlog-Site
Healthy
X-RCS-CacheZone
X-Akamai-Transformed
X-Locale
S-Rt
X-Redis-Cache
GEO-INFO
X-Site-Version
X-Generated
X-R9-Blue-Green-Version
X-MP-GENERATED-AT
X-Rule
X-Cache-Host
X-Www-Served-By
X-IP
X-Detected-As
X-Unique-Id
X-VCache
Cache-Key
X-Drupal-Cache-Tags
L5d-Success-Class
X-Ttl
X-Esi
Webserver
X-CS
X-Whom
X-Daa-Tunnel
X-UA-Device-Type
Cache-Name
X-VHOST
X-NGENIX-Cache
Time
Uber-Trace-Id
X-Backend-TTL
X-Forwarded-Host
X-UnsetCookies
X-Mode
Viewport
X-Info
Mime-Version
X-Origin-CC
X-Origin-TTL
Rt-Fastcgi-Cache
X-CDN-Forward
Content-Disposition
X-Varnish-Cache-Hits
Accept-Language
X-B3-Spanid
Section-Io-Cache
X-Newrelic-Synthetics
ServedBy
X-Cache-Remote
X-PERF
X-ApacheServer
Odigeo-Trace-Id
X-From
Country
X-Magnolia-Registration
X-CLOUD-TRACE-CONTEXT
X-Cluster-Name
X-EC-Lua
X-Drupal-Cache-Contexts
X-Proxied
X-Device-Type
X-Zipkin-Id
X-Routing-Service
X-Geo
X-Uri
VIX-Pulpo-Upstream-Status
X-TT-TIMESTAMP
VIX-Pulpo-Node
Proxy-Connection
X-Via-Fastly
X-Microcachable
Geo-Info
Cf-Ipcountry
X-Nc
Ohc-File-Size
Access-Control-Request-Headers
HitType
Meta-Geo-Continent
MD5-Digest
VivaBuild
Mobile-Detection-Method
Machine
T-Server
Rendered-Blocks
Viewtype
Apple-News-Services-Handled
Apple-News-Services-Request-Url
AsisCache
BehaviorPad-Version
Apple-News-Services-Parsed-Url
Content-Style-Type
GEO-REGION-INFO
Apple-News-Services-Host
Fastcgi-X-Cache-Version
Content-Script-Type
X-Connection-Hash
X-ScT
X-Session-Fingerprint
X-Sigma
X-Sigma-Backend
X-S-Cookie
X-S
X-Rewrite-Enabled
X-Rocket-Build-Number
X-Rojux
X-SRCache-Key
X-Transaction
X-VG-WebServer
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-VG-WebCache
X-VG-TLSProxy
X-Trv-Group
X-Twitter-Response-Tags
X-Vdms-Version
X-Request-UUID
X-Region-Sid
X-A-Wwc
X-Accel-Expires-Debug
X-Aed
X-Application
X-A-Dgt
X-A-Dcw
X-A
X-A-Ccd
X-A-Dam
X-ARC
X-B-Cookie
X-External-Request-Id
X-G
X-Geo-Header
X-GeoIP-Country-Code
X-DPWN-IS-SECURE
X-Destination
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-D
W
X-Date
X-Varnish-Beresp-Status
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Grace
Filterid
X-Real-IP
Ha-Gx-Prefs
Locid
Gh-Request-Id
IsBot
HA-Ipaddr
Fastly-SIE
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
CDCHOST
Countrycode
X-Hit
Environment
X-Logging-Id
X-Eu-Site
X-Auto-Login
X-Bip
X-Cache-ASPX
X-App-Name
X-Agile-Id
X-Agile
X-Agile-Age
X-Cache-Debug
Server-Surrogate-Control
X-CUA
Powered-By
X-Contensis-Viewer-Groups
X-Clientip
X-CGP
Server-Cache-Control
X-Distil-CS
Fastly-SWR
X-WebServer
X-Varnish-Authentication
X-SIPLIST1
X-Tumblr-Pixel-3
X-TrackingId
X-Thanos
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-Cache-Time
X-Labrador-Cache-Channel
X-UPSTREAM-Address
X-PHP-Host
X-C
X-Edge-Location
Fastly-SSL
User-Cache-Control
X-GoCache-CacheStatus
X-Distributor
X-Core-Mission
X-Developers
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
X-Dispatcher-Server
X-VC-Cache
X-Debug-Cookies
X-Debug-Cache-Store
X-Epic-Correlation-Id
X-Debug-Log
X-Cdn-Srv
X-Backend-State
X-Azure-Ref
X-BBXSRF
X-AK-Request-ID
X-Air-Hostname
X-Var-Ttl
X-Cache-Expired-At
X-Webstats-RespID
X-Cache-Info
X-Clara-WADP
X-WADP-Cache
X-Variation
X-We-Are-Hiring
X-Cache-Tags
X-Cache-URL
X-VServer
X-Hash
X-NX-Host
X-Origin-Date
X-Origin-Expires
X-NodeID
X-Nginx-Cache-Key
X-TH-Server
X-Ms-Version
X-Swa-Ws
X-OVcl
X-OVcl-Cache
X-RateLimit-Remaining-Second
X-Request-URI
X-No-Session
X-RateLimit-Limit-Second
X-Proxy-Upstream
X-Platform-Server
X-Servername
X-Ms-Request-Id
X-Micro-Cache
X-Server-W
X-Up
X-IN-APIGATEWAY
X-Generated-In
X-Gamma-Serve
X-Fetched-On
X-FW-Version
X-IN-APIGATEWAYSSL
X-Instart-Isnd
X-Trace-Id
X-LI-Proto
X-LI-UUID
X-TT-LOGID
X-Li-Pop
X-Irp-Debug
X-Li-Fabric
X-Fastly-Cache
X-Owner
Server-Int
Server-ID
RNT-Time
Mail-Subject
True-Client-Country-4JS
V-Age
Fastly-Soc-X-Request-Id
RNT-Machine
Is-Eu
Platform
Cache-Host
Memcached
Adler-Geo
Request-Country
Kp-EeAlive
Request-EU
Group
IBM-Web2-Location
Country-Code
Cdncip
Ohc-Cache-HIT
Cdnsip
We-Hiring
X-App-Version
X-Render-Time
X-Is-Gdpr
X-NU-AKA-ACS-Version
Wxu-Next-Commit
X-JWT-State
Wxu-Next-Region
Wxu-Next-Hostname
Locale
X-Gen-Mode
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Generation-Time
X-GeoIP-City
X-Hnp-Log
X-Has-Esi
X-TA-CDN-Provider
Web-Mar-Node
AKAMAI
X-Block-Status
Pragrma
FNAC-ModuleRouting
Fastly-Backend-Name
ServerName
X-Req
X-Cms-Context
X-Cache-Bucket
Heartbleed
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Cache-Backend
X-Nginx-Cache
X-Generated-On
X-SERVER
X-Lb-Id
X-Level-Front-Cache
X-ServiceProvider
X-Matched-Rule
X-S-Maxage
X-Service
X-Reboot
X-Old-Content-Length
PFcat
X-User
X-Core-Value
S-Cnection
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Cache-Hits
Thinkindot-Control
X-Trafficlayer-App-Version
Server-Host
X-Thinkindot-L3
X-Trafficlayer-App-Name
X-Trafficlayer-App-Scope
X-Internal-Host
X-Response-By
RequestId
X-Refresh
Powered-By-ChinaCache
X-Sucuri-Cache
X-CSRF-TOKEN
X-Key
X-Wa
X-Sucuri-ID
X-Location
X-Parent-Response-Time
X-Tec-Api-Origin
X-Tec-Api-Version
X-Varnish-Cacheable
X-Ua
X-NC
X-Tec-Api-Root
Origin
X-Tb-Optimization-Total-Bytes-Saved
X-Pjax-Url
X-CF-Powered-By
X-Node-Id
ProcessTime
X-BACKEND-TTL
X-Developer
X-Cdn-Forward
User-Agent
X-Oss-Object-Type
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Storage-Class
X-B3-Parentspanid
X-Oss-Hash-Crc64ecma
X-CSRF-Token
Memory
X-LAGOON
X-NWS-UUID-VERIFY
X-Pf-Uncompressing
X-Device-Os
X-Via-CDN
X-Ocache
SRV
X-Sn-Servicetimems
On-Server
TTL
Geoip-Latitude
X-Cache-Grace
X-Cdn-Origin
Hostname
Geoip-City
X-Correlation-ID
X-Vcl-Version
PICS-Label
X-MSEdge-Features
X-MSEdge-Flight
X-Server-IP
A
X-Cache-Status-Check
X-COUNTRY
GeoIp-Country-Code
X-NGINX-Cache
X-Unique-ID
X-Request-Host
Cloudfront-Viewer-Country
X-B3-SpanId
X-Litespeed-Cache
X-Servedbyhost
X-Webkit-CSP
M-TraceId
X-Cdn-Request-ID
X-Varnish-Ttl
Media-Length
X-TIME
XServer
X-Ruxit-Js-Agent
Dnion-Transfer-Encoding
X-HS-Status
X-Varnish-URL
Tcn
Cdn
X-FORWARDED-FOR
Host-ID
X-Rocket-Nginx-Bypass
SN
X-Via-Ucdn
Resin-Trace
X-Ratelimit-Remaining
X-Beluga-Response-Time
X-Cache-Ttl
X-Beluga-Node
Who
X-Beluga-Cache-Status
X-Beluga-Trace
X-ServedByHost
X-Beluga-Status
X-Beluga-Record
X-Sucuri-Id
HostName
CACHE
X-Slack-Backend
X-Action
Esi-Enabled
X-AIR-PT
X-Reqid
X-Fastly-Country-Code
X-VCL-Version
X-Server-Time
X-Planisys-CDN-TTL
X-Processor
X-PAYTM-SRV-ID
GeoIP-Country-Code
X-Planisys-CDN-Cache
X-Policy
X-Planisys-CDN-Rules
X-DB
Arc-Country
X-DSS
X-DI
X-RSL
X-DW
X-RPS
X-RPM
CF-Cached-On
X-DC
Pramga
X-ND-Cache
X-Hello
GeoIP-Latitude
GeoIP-City
X-Request-Start
X-Flog
X-ABtesting
X-Cache-FS-Status
Pics-Label
X-Dispatch
Ttl
X-Azure-Ref-OriginShield
X-LiteSpeed-Cache-Control
X-Dynatrace-Js-Agent
X-Oracle-Dms-Rid
MIME-Version
NtCoent-Length
X-Edge-Server
Cdn-Host
Cdn-Request-Time
X-Skip-Cache
Rt-Proxy-Cache
Fastly-Drupal-HTML
X-Varnish-Url
X-Bc-Bl
X-Served-From
N-Cache
X-DevSite-Last-Modified
X-APP
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Io-Id
X-Ratelimit-Limit
X-Newrelic-App-Data
X-VarnishDD-TTL
Section-Origin-Responded
X-Fastly-Backend-Reqs
X-PF-Uncompressing
X-Datadome
X-HostName
Trailer
X-Method
X-Backend-Host
WebServer
X-SRV
X-Zone
Magicmarker
X-FPC
X-Bc
X-PJAX-URL
Amp-Access-Control-Allow-Source-Origin
X-Swift-Error
X-ZONE
X-BE
X-Dynatrace
Processtime
X-BC
Cteonnt-Length
X-Amzn-Remapped-Date
X-Amzn-Remapped-Connection
Fusion-Deployment-Id
X-Adobe-Source
Servername
X-WA
FSS-Proxy
Cache-Provider
FSS-Cache
X-ID
X-Fmm-Version
X-Frame-Option
X-WR-MODIFICATION
X-Svr
X-StackifyID
Dynatrace
CF-IPCountry
Cache-Cookie-Set-From
X-Snapshot-Date
Requestid
Ohc-Response-Time
X-Be
Cache-Cookie-Set-Lfrom
X-LB-ID
X-Branch-Name
Cache-Cookie-Set-Idcheck
CDN
X-CACHE-AGE
X-Ftr-Cache-Host
X-Apw-Access-Object
X-Aicache-OS
X-Request-Url
Lfy
X-App
X-Apw-Access-Action
Vix-Hermes-Req-Id
X-Fastly-Cache-Hits
X-Apw-Hits
X-SB
X-Cc-Req-Id
D-Cc-Upstream
X-VC
Warning
X-Cc-Via
X-Scheme
V-Cache
WZWS-RAY
X-Apw-Access-Token
X-Fpc
X-Tid
X-Litespeed-Cache-Control
Load-Balancing
X-Cache-Id
L
Cneonction
X-Compress-Hint
Lb
X-SN
X-Esi-Check
Pagetype
X-Request-URL
X-Check-Cacheable
X-Powered-Y
Backend-Name
Correlation-Id
X-ElasticPress-Search
X-Varnish-Beresp-TTL
X-Worker
X-Fastly-Cache-Status
WP-Super-Cache
Proxy-Firewall
X-WPE-Loopback-Upstream-Addr