Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
CF-RAY
Link
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Request-ID
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-Template
X-DNS-Prefetch-Control
X-Language
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
Status
X-Content-Security-Policy
Upgrade
Content-Encoding
X-CDN
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Xss-Protection
X-Kinja-Server-Push
Keep-Alive
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
P3p
Xkey
X-Pass-Why
X-Cache-Group
X-AH-Environment
X-Envoy-Upstream-Service-Time
CF-Ray
X-Via
X-Backend
X-Age
X-Server
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Server-Powered-By
X-Page-Speed
X-Ws-Request-Id
X-Pingback
EagleId
X-Proxy-Cache
X-Hacker
X-Nginx-Cache-Status
X-UA-Device
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
Cf-Railgun
Grace
X-Ua-Compatible
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Amz-Version-Id
Report-To
X-LiteSpeed-Cache
X-Rq
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-WebKit-CSP
X-OneAgent-JS-Injection
X-Server-Id
X-Host
X-Device
X-Origin-Cache
EagleEye-TraceId
X-Response-Time
X-Node
X-Ac
Content-Location
Surrogate-Control
X-Vhost
X-Readtime
X-Cloud-Trace-Context
Request-Id
X-Backend-Server
X-Dns-Prefetch-Control
X-Dispatcher
X-Origin-Upstream-Status
X-Cnection
X-Application-Context
X-HW
X-Cache-Lookup
X-ORACLE-DMS-ECID
Fusion-Source
Fusion-Component-Id
Fusion-Template-Id
Fusion-Content-Source
Fusion-Content-Id
X-ORACLE-DMS-RID
X-DataDome
NEL
X-Ruxit-JS-Agent
X-Mod-Pagespeed
X-Rack-Cache
Rating
Edge-Control
X-Country
X-Clacks-Overhead
X-Akam-SW-Version
Pinterest-Generated-By
Allow
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Country-Code
X-TTL
X-DynaTrace
X-Instart-Request-ID
X-Varnish-TTL
X-FTR-Request-ID
X-Goog-Hash
X-TtlSet
X-Vname
X-PC
Accept-Ch
X-ESI
Verso
X-Powered-By-Plesk
Content-MD5
Service-Worker-Allowed
X-Url
Accept-Ch-Lifetime
X-Forwarded-Proto
X-Version
X-MS-InvokeApp
X-B3-TraceId
X-Cdn-Fetch
X-Exp-Id
X-Kinja-Build
X-Use-Magma
X-Kinja-Server
X-Exp-Variant
X-Kinja
X-Kinja-Revision
X-GoogleNews-Bot
X-GitHub-Request-Id
RTSS
Edge-Cache-Tag
X-Abt-Application-Version
X-D2id
X-Debug
X-Px
AR-ATIME
AR-Request-ID
Ar-Sid
AR-PoweredBy
AR-CACHE
X-Server-Name
X-Amz-Server-Side-Encryption
SPRequestGuid
Charset
X-NF-Request-ID
X-Cached
X-Accel-Expires
X-Vcache
Pagespeed
X-Middleton-Display
X-Middleton-Response
X-Sol
Response
Display
X-MSEdge-Ref
X-Vcap-Request-Id
Arr-Disable-Session-Affinity
X-Amz-Rid
TCN
X-Navigation-Version
X-Powered-CMS
X-TEC-API-ROOT
X-TEC-API-ORIGIN
Pinterest-Version
X-Pinterest-Rid
X-TEC-API-VERSION
X-SharePointHealthScore
X-Fastcgi-Cache
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Trace
X-Cdn
X-VARITI-CCR
Realpath
Public-Key-Pins
Cache-Tag
X-Client-IP
X-Fastly-Request-ID
Access-Control-Request-Method
X-Ser
MS-Author-Via
X-Server-ID
Nginx-Cache
X-DynaTrace-JS-Agent
S
X-Shard
X-Edge-O15-RID
SPRequestDuration
X-Upstream
SPIisLatency
X-Id
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
X-Ezoic-Cdn
X-Content-Type
X-Hp-Webp
X-Amzn-Trace-Id
X-Forwarded-For
X-Grace
X-T
X-Amz-Meta-S3cmd-Attrs
Nel
Front-End-Https
Fastcgi-Cache
X-Recruiting
X-Hits
DynaTrace
X-Aspnet-Version
X-Varnish-Age
X-Jurisdiction
ServerID
X-Cache-TTL
X-Node-Name
X-FTR-Expires
X-Country-Code-Real
X-FTR-Cache-Status
MicrosoftSharePointTeamServices
X-Dw-Request-Base-Id
X-DIS-Request-ID
X-Element-Page-Cache
X-Content-Digest
X-Mobile-URL
NR-ENABLED
X-FTR-Backend
X-FTR-DC
X-FTR-Realm
X-FTR-Balancer
X-FTR-Backend-Server
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Combine-CSS
Powered
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Frontend
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Storage-Class
X-GUploader-UploadID
Server-Node
TP-Cache
TP-L2-Cache
Alternate-Protocol
Server-Name
X-Logged-In
X-Correlation-Id
X-XRDS-Location
X-CST
X-Request-Processing-Time
X-Request-Received
AMP-Access-Control-Allow-Source-Origin
X-Amz-Apigw-Id
X-Amzn-RequestId
Upgrade-Insecure-Requests
X-Request-Handler-Origin-Region
X-Microsite
X-ATS-Timestamp
Backend-Timing
X-Cache-Hit
X-Content-Options
X-Origin-Server
X-Page-Id
X-F-Cache
X-Content-Security-Policy-Report-Only
X-Rid
Refresh
X-User-Agent
X-Akamai-Edgescape
X-Varnish-Grace
X-Revision
X-Type
Fastly-Restarts
X-Zen-Fury
X-XRDS-LOCATION
X-Content-Powered-By
X-LB-Cache
X-B3-Sampled
X-B
X-Geo-Country
X-URL
X-FTR-Cache-Host
X-Activity-Id
X-AppVersion
X-Az
PB-PID
PB-RID
Arc-Version
X-Mobile-Rewrite
Cache-Status
X-Shield-Request-Id
X-N
X-Kinsta-Cache
X-Pad
X-Cache-Age
X-Instance
X-TT
X-Time
X-Request-Guid
X-Signature
X-AOL-HN
X-B-Cache
X-WebKit-CSP-Report-Only
Access-Control-Allow-Method
X-Cache-Action
X-Framework
X-Debug-Info
X-Load-Cache
X-App-Environment
X-Tumblr-Pixel
X-Tumblr-User
X-Jobs
Paypal-Debug-Id
Actual-Object-TTL
X-Tumblr-Pixel-0
X-FB-Debug
X-PHP-Backend
X-Webkit-Csp
DC
X-Webapp-Samesite-None-Activated-N
X-Cached-By
X-Git-Hash
Fastcgi-Useragent
X-Tt-Trace-Tag
X-Varnish-Backend
X-RateLimit-Remaining
X-Analytics
X-Tt-Trace-Host
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
Surrogate-Key
Host-Header
X-Amz-Replication-Status
X-IPLB-Instance
X-Contextid
FilterID
MS-CV
X-ATG-Version
X-SS-Set-Cookie
Accept-CH
X-FastCGI-Cache
X-WA-Info
X-Cache-Key
Host
Tracecode
X-VCache
X-Cluster
X-Host-Name
X-Mobile
NGB
X-Accel-Buffering
X-Response-Served-From
X-Via-JSL
X-ORACLE-APMCS-TAG
X-ORACLE-APMCS-REQUEST-ID
Payment
WPE-Backend
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Presslabs-Stats
X-B3-Traceid
X-FW-Serve
X-FW-Hash
X-FW-Type
X-FW-Server
X-Cache-NE
X-FW-Static
X-NWS-LOG-UUID
Frame-Options
X-Cacheable-TTL
X-Hostname
X-Cache-2
Source
Cache-Tv-Group
X-Varnish-Server
Eomportal-Instance
X-Region
X-Cache-Rule
X-Origin-Response-Time
Filters
X-Varnish-Hostname
X-Srv
X-Cache-Enabled
X-Cache-Operation
X-Tumblr-Pixel-2
X-GeoIP
X-IPS-LoggedIn
X-Tumblr-Pixel-1
X-Is-Bot
X-Rendered-As
X-Adobe-Loc
X-Adobe-Content
X-TX-ID
X-RequestSource
X-Seen-By
X-NewRelic-App-Data
Retry-After
Xserver
X-EdgeConnect-Cache-Status
Accept-CH-Lifetime
Server-Info
Cleartype
X-Cache-TTL-Remaining
X-ProcessESI
X-RemovedCookies
Liferay-Portal
X-UA
X-HTML-Minification-Powered-By
X-Dc
Ms-Operation-Id
X-RTag
Cache
X-Ttl
Datacenter
X-App-Server
X-Source
X-Environment-Context
X-FireWall-Port
X-L-Path
X-Upgrade-Enabled
X-Handled-By
X-Endurance-Cache-Level
X-Cache-Control
X-Cache-Server
From-Origin
X-CACHE-KEY
Healthy
X-APP-VERSION
X-Backend-Name
X-Wix-Request-Id
Version
OT-Force-Account-Verify
X-Status
Node
X-Cache-Var-Map
Meta-Geo
X-Cache-Var
GEO-INFO
X-Path-Route
X-ES-SERVER
X-RN-RSRV
Srv
Ec-Rule-Version
X-BCube-Filmed-By
X-Tb
X-Timing-Wait
X-Storage
X-Akamai-Request-ID
X-Access
X-Rule
X-Request-Time
X-Ruxit-Js-Agent
Selected-Fe
X-Format
X-Proxy-Build
X-Section
X-Proto
X-Goog-Meta-Goog-Reserved-File-Mtime
X-TNCMS
X-Hosted-By
X-FW-Dynamic
X-Alternate-Cache-Key
X-Content-Age
X-PCL
X-Proxy-Cache-Status
X-Origin
X-OCL
X-FC-Vary-Parameters
X-Shopify-Generated-Cart-Token
Mn-Server-Ip
X-EIG-Tracking-Id
X-Shopify-Stage
Azure-Version
X-UUID
Azure-InstanceId
Azure-RegionName
Azure-SiteName
Azure-SlotName
S-Rt
X-Sorting-Hat-PodId
X-ShopId
Akamai-GRN
X-Loop
X-NYM-Debug-Backend
X-Cache-Config
X-Web-Node
X-Sorting-Hat-ShopId
X-Soup
X-Time-Microsecs
X-ShardId
Cache-Tags
X-RateLimit-Limit
X-BYPASS-REASON
X-AWS-Id
Accept-Charset
X-Cluster-Node
X-Akamai-Request-ID2
X-Say-TTL
X-Vgn-Hpd-Reason
X-Viewer-Country
X-VWS-Id
X-ServerID
Origin-Edge-Control
Now
X-Say-Cacheable
NGX
X-SayCDN-TTL
Origin-Cache-Control
Decoy-Debug-TTL
DB-Nickname
Decoy-Debug-Key
Decoy-Debug-Status
X-Generated-By
X-Debug-Cache
X-LJ-Flow-ID
X-ProxyCache-Key
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Proxy
X-MP-GENERATED-AT
X-Hl-Ver
X-JoinUs
X-Human
X-Redis-Cache
X-SaId
X-ProxyCache-Status
X-Hyper-Cache
X-Pubstack
X-Qloud-Router
X-PressLabs-Stats
TWC-Device-Class
X-Site-Version
X-Origin-Hint
Property-Id
X-FB-TRIP-ID
TWC-Privacy
X-Www-Served-By
X-CCM
X-IP
X-Detected-As
X-Generated
X-Varnish-Hits
X-Cache-Host
X-Locale
TWC-Locale-Group
TWC-GeoIP-LatLong
Webcakes-App-Name
Webcakes-App-Version
X-Amzn-Remapped-Content-Length
Webcakes-Region
TWC-GeoIP-Country
TWC-Connection-Speed
Cross-Origin-Window-Policy
X-R9-Blue-Green-Version
X-Xfnlog-Site
X-Akamai-Transformed
X-RCS-CacheZone
X-NCache
L5d-Success-Class
X-Unique-Id
X-CS
Time
X-Drupal-Cache-Tags
Uber-Trace-Id
Cache-Name
Viewport
X-Esi
Webserver
Cache-Key
X-UA-Device-Type
X-UnsetCookies
X-Backend-TTL
X-Cache-Remote
X-CDN-Forward
X-Mode
Rt-Fastcgi-Cache
X-Forwarded-Host
Accept-Language
X-Origin-CC
X-From
X-Origin-TTL
X-Newrelic-Synthetics
X-Daa-Tunnel
X-Whom
X-Drupal-Cache-Contexts
X-Trafficlayer-App-Scope
Country
Mime-Version
X-Trafficlayer-App-Name
X-Info
X-NGENIX-Cache
X-Magnolia-Registration
X-B3-Spanid
Odigeo-Trace-Id
X-Cluster-Name
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Varnish-Cache-Hits
Content-Disposition
X-CLOUD-TRACE-CONTEXT
X-ApacheServer
X-TT-TIMESTAMP
X-PERF
X-Microcachable
X-Edge-Location
ServedBy
X-Geo
X-Zipkin-Id
X-Device-Type
X-Proxied
X-Routing-Service
X-EC-Lua
X-UPSTREAM-Address
Section-Io-Cache
X-Via-Fastly
Proxy-Connection
Ohc-File-Size
X-Uri
Ohc-Cache-HIT
HitType
X-No-Session
X-Destination
X-Date
X-D
X-A-Dcw
X-Aed
X-A-Ccd
W
X-A
X-Application
Cf-Ipcountry
X-ARC
X-B-Cookie
X-Accel-Expires-Debug
X-Connection-Hash
VivaBuild
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-A-Wwc
X-A-Dgt
Viewtype
X-Request-UUID
X-Transaction
Apple-News-Services-Parsed-Url
X-Trv-Group
Apple-News-Services-Request-Url
X-Twitter-Response-Tags
Apple-News-Services-Host
X-DPWN-IS-SECURE
X-Sigma
X-Sigma-Backend
MD5-Digest
X-SRCache-Key
AsisCache
BehaviorPad-Version
Xc-Version
X-Vtex-Remote-Cache
Content-Script-Type
Content-Style-Type
GEO-REGION-INFO
X-Vtex-Processado-Em
X-VG-WebServer
Machine
X-Vdms-Version
X-VG-TLSProxy
X-VG-WebCache
X-Session-Fingerprint
Apple-News-Services-Handled
X-External-Request-Id
T-Server
Mobile-Detection-Method
Rendered-Blocks
Fastcgi-X-Cache-Version
X-G
X-ScT
X-GeoIP-Country-Code
X-Geo-Header
Meta-Geo-Continent
X-S
X-S-Cookie
X-Rojux
X-Rocket-Build-Number
X-Region-Sid
X-A-Dam
X-Rewrite-Enabled
X-C
X-Nc
X-GoCache-CacheStatus
User-Cache-Control
X-Labrador-Cache-Channel
X-PHP-Host
Powered-By
Gh-Request-Id
Memcached
Fastly-Soc-X-Request-Id
Fastly-SSL
Server-Cache-Control
IBM-Web2-Location
IsBot
HA-Ipaddr
Ha-Gx-Prefs
Locid
Server-Surrogate-Control
X-Li-Fabric
X-User
X-Varnish-Authentication
X-VC-Cache
X-VServer
X-Tumblr-Pixel-3
X-TrackingId
X-SIPLIST1
X-TH-Server
X-Thanos
X-We-Are-Hiring
X-WebServer
X-Clientip
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
Fastly-SWR
Fastly-SIE
X-Wikidot-Backend
X-Wikidot-Static-Cache
Countrycode
X-Real-IP
X-Logging-Id
X-Cache-ASPX
X-Cache-Debug
X-CGP
X-Bip
X-Backend-State
X-Agile-Id
X-App-Name
X-Auto-Login
X-Contensis-Viewer-Groups
X-CUA
X-Li-Pop
X-LI-Proto
X-LI-UUID
X-Hit
X-FW-Version
X-Developers
X-Distil-CS
X-Eu-Site
X-Agile-Age
X-Agile
X-Varnish-Beresp-Ttl
Access-Control-Request-Headers
X-Varnish-Beresp-Status
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
CDCHOST
X-Varnish-Beresp-Grace
Environment
X-Cache-Backend
X-Key
X-TT-LOGID
X-Urbn-Context-Path
We-Hiring
X-Origin-Date
X-AK-Request-ID
X-Debug-Cookies
X-Ms-Request-Id
X-Debug-Log
X-Trace-Id
X-Urbn-Site-Id
Fastly-Backend-Name
X-Distributor
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Epic-Correlation-Id
X-Webstats-RespID
X-Reboot
X-Irp-Debug
X-WADP-Cache
X-Dispatcher-Server
Web-Mar-Node
X-Azure-Ref
X-Render-Time
X-Cdn-Srv
X-IN-APIGATEWAYSSL
X-Cache-URL
X-Server-W
X-Clara-WADP
X-Request-URI
X-Core-Mission
X-Instart-Isnd
X-Cms-Context
X-Cache-Time
X-Cache-Info
X-BBXSRF
X-Swa-Ws
X-Debug-Cache-Store
Country-Code
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Debug-Cache-Expiry
X-Cache-Bucket
X-Debug-Cache-Fetch
X-Block-Status
X-Proxy-Upstream
X-Fastly-Cache
X-GeoIP-City
X-Servername
AKAMAI
Mail-Subject
X-Micro-Cache
X-Ms-Version
X-JWT-State
X-OVcl-Cache
X-NU-AKA-ACS-Version
X-Platform-Server
X-Up
X-OVcl
X-Hnp-Log
Heartbleed
Cdncip
Cdnsip
X-Origin-Expires
Kp-EeAlive
Cache-Host
Locale
X-Variation
X-Hash
X-Is-Gdpr
X-Generation-Time
X-IN-APIGATEWAY
X-Fetched-On
X-Owner
X-Gamma-Serve
X-Gen-Mode
True-Client-Country-4JS
Is-Eu
Adler-Geo
X-NX-Host
V-Age
X-NodeID
Server-Int
X-Generated-In
X-Nginx-Cache-Key
Request-EU
Request-Country
X-Internal-Host
RNT-Machine
RNT-Time
Platform
X-Has-Esi
X-Cache-Tags
Geo-Info
X-Generated-On
X-Core-Value
X-Req
X-Trafficlayer-App-Version
X-Old-Content-Length
Thinkindot-Control
Wxu-Next-Hostname
Wxu-Next-Region
ServerName
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
PFcat
X-Matched-Rule
Server-Host
Server-ID
X-Level-Front-Cache
Wxu-Next-Commit
X-Thinkindot-L3
FNAC-ModuleRouting
X-ServiceProvider
X-Sucuri-Cache
X-Service
X-Location
X-S-Maxage
X-Air-Hostname
Cache-Hits
X-Lb-Id
X-App-Version
X-TA-CDN-Provider
X-Response-By
X-SERVER
Group
Pragrma
X-Cache-Expired-At
X-Var-Ttl
X-Refresh
X-Nginx-Cache
X-Parent-Response-Time
S-Cnection
X-Tb-Optimization-Total-Bytes-Saved
RequestId
Memory
X-CSRF-TOKEN
X-B3-Parentspanid
Filterid
Powered-By-ChinaCache
X-NC
X-CF-Powered-By
ProcessTime
X-Wa
X-Cdn-Forward
X-B3-SpanId
X-Pf-Uncompressing
X-Pjax-Url
X-BACKEND-TTL
Origin
X-Server-IP
User-Agent
Geoip-Latitude
X-CSRF-Token
X-Sucuri-ID
X-Varnish-Cacheable
Geoip-City
GeoIp-Country-Code
X-NWS-UUID-VERIFY
X-NGINX-Cache
X-Ua
SRV
X-Correlation-ID
TTL
PICS-Label
X-Via-CDN
X-Cdn-Request-ID
X-COUNTRY
Media-Length
X-Developer
X-Vcl-Version
X-Unique-ID
X-Cache-Grace
X-Cdn-Origin
X-Node-Id
X-Servedbyhost
X-Device-Os
XServer
X-Ocache
X-LAGOON
X-Sn-Servicetimems
On-Server
X-Sucuri-Id
X-Litespeed-Cache
X-Webkit-CSP
Dnion-Transfer-Encoding
X-Rocket-Nginx-Bypass
X-Varnish-Ttl
X-Cache-Status-Check
X-Request-Host
X-Via-Ucdn
X-MSEdge-Flight
X-MSEdge-Features
SN
A
X-Oss-Server-Time
X-TIME
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
X-Oss-Object-Type
X-Oss-Storage-Class
Hostname
X-Oneagent-Js-Injection
M-TraceId
Cloudfront-Viewer-Country
X-Reqid
Esi-Enabled
X-AIR-PT
X-HS-Status
X-FORWARDED-FOR
X-Beluga-Status
X-Beluga-Response-Time
X-Beluga-Node
X-Planisys-CDN-TTL
X-Policy
X-Planisys-CDN-Rules
X-Beluga-Record
X-Beluga-Cache-Status
X-Planisys-CDN-Cache
X-Beluga-Trace
X-Ratelimit-Remaining
X-ServedByHost
X-Fastly-Country-Code
X-Azure-Ref-OriginShield
X-Request-Start
X-Cache-Ttl
Resin-Trace
Who
Cdn
X-VHOST
HostName
X-Ftr-Cache-Host
Rt-Proxy-Cache
Tcn
X-Varnish-URL
Host-ID
CF-Cached-On
X-VCL-Version
MIME-Version
NtCoent-Length
X-Slack-Backend
Cteonnt-Length
Ttl
X-Method
Pics-Label
Magicmarker
GeoIP-Country-Code
X-APP
X-Oracle-Dms-Rid
X-DSS
X-DI
X-RPS
X-RSL
X-Fastly-Backend-Reqs
X-RPM
X-DW
X-DB
X-Varnish-Url
X-Action
GeoIP-Latitude
X-LiteSpeed-Cache-Control
X-DC
X-Dispatch
X-FPC
X-Processor
X-Skip-Cache
X-Server-Time
X-Cache-FS-Status
Arc-Country
X-Newrelic-App-Data
X-VarnishDD-TTL
X-PJAX-URL
Pramga
X-Swift-Error
X-PAYTM-SRV-ID
CACHE
X-Zone
X-PF-Uncompressing
GeoIP-City
X-Bc
X-Ratelimit-Limit
Load-Balancing
X-Be
X-Svr
Processtime
X-Ftr-Request-Id
Amp-Access-Control-Allow-Source-Origin
X-SRV
X-ND-Cache
Ohc-Response-Time
X-Flog
X-Hello
WebServer
X-ABtesting
X-HostName
X-BE
Cdn-Host
Vix-Hermes-Req-Id
X-DevSite-Last-Modified
Cdn-Request-Time
X-Served-From
X-Dynatrace
Fastly-Drupal-HTML
N-Cache
X-Edge-Server
X-MServer
Servername
CF-IPCountry
DSUID
X-Dynatrace-Js-Agent
X-Aicache-OS
Cache-Provider
X-ID
X-Bc-Bl
X-Amzn-Remapped-Connection
X-WA
X-Amzn-Remapped-Date
Release
CDN
X-ZONE
X-VCT
Requestid
X-WR-MODIFICATION
X-Frame-Option
X-Hp-Ccpa-Warning
X-Ftr-Backend-Server
X-Ftr-Backend
X-Backend-Host
X-StackifyID
Dynatrace
X-Branch-Name
X-LB-ID
X-Tid
Lfy
Pagetype
X-Fastly-Cache-Hits
X-Snapshot-Date
X-BC
X-Ftr-Dc
X-Configured-By
X-Ftr-Balancer
X-Ftr-Realm
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Id
X-CACHE-AGE
Section-Io-Origin-Status
X-Apw-Hits
X-Upstream-Ct
X-Apw-Access-Token
V-Cache
SD-X-WS
WZWS-RAY
X-Edge-IP
Proxy-Firewall
X-Apw-Access-Action
X-Apw-Access-Object
X-Upstream-Ht
X-SD-PageType
X-Cc-Via
D-Cc-Upstream
Warning
X-SB
X-VC
X-Request-Url
X-Cc-Req-Id
X-Litespeed-Cache-Control
X-Varnish-Beresp-TTL
X-Compress-Hint
X-Check-Cacheable
X-SN
X-WPE-Loopback-Upstream-Addr
Server-Id
FSS-Proxy
FSS-Cache
Cneonction
X-Fastly-Cache-Status
WP-Super-Cache
Backend-Name
Correlation-Id
X-App
X-ServerName
L
X-Worker
X-Request-URL
X-ElasticPress-Search
Lb
X-Powered-Y
X-Cache-Id