Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-Powered-By
Pragma
X-XSS-Protection
CF-Cache-Status
Link
ETag
CF-RAY
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-Request-ID
X-Xss-Protection
X-DNS-Prefetch-Control
X-Template
X-Language
CF-Ray
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
Status
Upgrade
X-Content-Security-Policy
Content-Encoding
X-CDN
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
X-Pass-Why
X-Cache-Group
X-AH-Environment
X-Envoy-Upstream-Service-Time
Xkey
X-Via
X-Backend
X-Server
X-Age
X-Ua-Compatible
X-Ws-Request-Id
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Server-Powered-By
X-Page-Speed
EagleId
X-Pingback
X-Proxy-Cache
X-Hacker
X-Nginx-Cache-Status
X-UA-Device
Request-Context
Feature-Policy
X-Varnish-Cache
Server-Timing
Cf-Railgun
X-Swift-CacheTime
X-Swift-SaveTime
Grace
Ali-Swift-Global-Savetime
P3p
X-Amz-Version-Id
Report-To
X-LiteSpeed-Cache
X-Rq
X-OneAgent-JS-Injection
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-WebKit-CSP
X-Device
X-Host
X-Server-Id
X-Origin-Cache
X-Response-Time
EagleEye-TraceId
X-Node
X-Ac
Surrogate-Control
Content-Location
X-Cloud-Trace-Context
X-Backend-Server
X-Readtime
X-Vhost
Request-Id
X-Dispatcher
X-Origin-Upstream-Status
X-Cache-Lookup
X-Cnection
X-Ruxit-JS-Agent
X-Application-Context
X-HW
Fusion-Component-Id
Fusion-Template-Id
Fusion-Content-Source
Fusion-Source
Fusion-Content-Id
X-ORACLE-DMS-ECID
NEL
X-Mod-Pagespeed
X-ORACLE-DMS-RID
X-DataDome
X-Rack-Cache
X-Country
X-Clacks-Overhead
Edge-Control
X-Akam-SW-Version
Rating
X-Dns-Prefetch-Control
Pinterest-Generated-By
X-TTL
Allow
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Country-Code
Accept-Ch
X-FTR-Request-ID
X-Instart-Request-ID
X-Varnish-TTL
X-DynaTrace
X-Goog-Hash
X-Vname
X-TtlSet
X-PC
X-ESI
Verso
Content-MD5
Accept-Ch-Lifetime
Service-Worker-Allowed
X-Powered-By-Plesk
X-Url
X-B3-TraceId
X-Forwarded-Proto
X-Exp-Id
X-Vcache
X-Exp-Variant
X-Kinja
X-Kinja-Revision
X-Kinja-Build
X-GoogleNews-Bot
X-Cdn-Fetch
X-Kinja-Server
X-Version
X-Use-Magma
X-GitHub-Request-Id
X-MS-InvokeApp
RTSS
X-Server-Name
X-D2id
Edge-Cache-Tag
X-Abt-Application-Version
X-Debug
X-Server-ID
X-Px
AR-PoweredBy
AR-ATIME
AR-Request-ID
Ar-Sid
AR-CACHE
X-Amz-Server-Side-Encryption
SPRequestGuid
Charset
X-NF-Request-ID
X-Cached
X-TEC-API-ROOT
X-TEC-API-VERSION
X-TEC-API-ORIGIN
Response
X-Middleton-Response
X-Sol
Pagespeed
X-Middleton-Display
Display
X-Navigation-Version
X-Vcap-Request-Id
X-MSEdge-Ref
X-Amz-Rid
X-Accel-Expires
Arr-Disable-Session-Affinity
X-Fastcgi-Cache
Pinterest-Version
X-Pinterest-Rid
X-SharePointHealthScore
X-VARITI-CCR
X-Powered-CMS
TCN
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Public-Key-Pins
X-Fastly-Request-ID
X-Edge-O15-RID
Realpath
Cache-Tag
X-Trace
X-Client-IP
MS-Author-Via
X-Cdn
Nginx-Cache
X-Ser
Access-Control-Request-Method
X-Mrf-Item-Lastmod
MRF-Tech
X-Content-Type
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Mrf-Section-Lastmod
X-DynaTrace-JS-Agent
X-Shard
SPRequestDuration
SPIisLatency
X-Amzn-Trace-Id
X-Id
X-Jurisdiction
X-Hp-Webp
X-Ezoic-Cdn
X-Grace
S
X-Upstream
X-Forwarded-For
Front-End-Https
X-Amz-Meta-S3cmd-Attrs
X-T
X-Hits
Fastcgi-Cache
X-Cache-TTL
DynaTrace
X-Recruiting
Nel
X-Aspnet-Version
X-Varnish-Age
X-Node-Name
X-Element-Page-Cache
X-Content-Digest
ServerID
X-Mobile-URL
X-FTR-Backend
X-Country-Code-Real
X-FTR-Balancer
X-FTR-Realm
X-FTR-Expires
X-FTR-DC
X-FTR-Backend-Server
MicrosoftSharePointTeamServices
X-FTR-Cache-Status
X-Dw-Request-Base-Id
X-DIS-Request-ID
Server-Node
NR-ENABLED
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Combine-CSS
X-HS-Hub-Id
X-Frontend
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
TP-Cache
TP-L2-Cache
X-Goog-Metageneration
X-Goog-Storage-Class
X-Goog-Generation
Powered
X-Logged-In
X-CST
Alternate-Protocol
Server-Name
Upgrade-Insecure-Requests
X-Amzn-RequestId
X-Amz-Apigw-Id
Fastly-Restarts
X-Correlation-Id
X-Cache-Hit
X-Microsite
X-Request-Handler-Origin-Region
Backend-Timing
X-ATS-Timestamp
X-Request-Processing-Time
X-XRDS-Location
X-Request-Received
AMP-Access-Control-Allow-Source-Origin
X-User-Agent
X-FTR-Cache-Host
X-Content-Options
X-Page-Id
X-Content-Security-Policy-Report-Only
Refresh
X-F-Cache
X-Zen-Fury
X-Origin-Server
X-Rid
X-Akamai-Edgescape
X-XRDS-LOCATION
X-Varnish-Grace
X-Revision
X-Type
X-LB-Cache
X-B
X-Content-Powered-By
X-Webkit-Csp
PB-RID
PB-PID
Arc-Version
X-B3-Sampled
X-Mobile-Rewrite
X-Geo-Country
Cache-Status
X-Az
X-Activity-Id
X-AppVersion
X-URL
X-Kinsta-Cache
X-N
X-Cache-Action
X-TT
X-Cache-Age
X-AOL-HN
X-Debug-Info
X-WebKit-CSP-Report-Only
X-Framework
X-Jobs
Access-Control-Allow-Method
X-B-Cache
X-Signature
X-Instance
X-FB-Debug
X-Time
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel
Actual-Object-TTL
Paypal-Debug-Id
X-Cached-By
X-Load-Cache
X-App-Environment
X-PHP-Backend
X-Request-Guid
X-Git-Hash
X-Shield-Request-Id
X-Pad
Fastcgi-Useragent
DC
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Amz-Replication-Status
X-RateLimit-Remaining
X-Varnish-Backend
X-NWS-LOG-UUID
Host-Header
Surrogate-Key
X-ATG-Version
X-IPLB-Instance
X-WA-Info
Host
X-Contextid
MS-CV
X-ORACLE-APMCS-TAG
X-Erf-Bev-Bev
X-ORACLE-APMCS-REQUEST-ID
X-Erf-Bev-Bev-Is-Generated
X-Via-JSL
X-Mobile
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Accel-Buffering
NGB
X-Response-Served-From
X-Host-Name
X-FastCGI-Cache
X-SS-Set-Cookie
Frame-Options
X-Cache-Key
Payment
X-Cache-NE
Tracecode
X-Varnish-Server
X-Cache-2
X-Origin-Response-Time
Source
X-Region
Xserver
X-Cluster
Eomportal-Instance
X-FW-Type
Filters
Retry-After
X-GeoIP
WPE-Backend
X-FW-Hash
X-FW-Static
X-FW-Serve
X-FW-Server
X-Cacheable-TTL
X-Adobe-Loc
Cache-Tv-Group
X-Adobe-Content
X-IPS-LoggedIn
X-Varnish-Hostname
X-Cache-Enabled
X-Tumblr-Pixel-2
X-Cache-Operation
X-Cache-Rule
X-Tumblr-Pixel-1
X-Seen-By
X-Rendered-As
X-Is-Bot
X-Analytics
X-NewRelic-App-Data
X-RequestSource
FilterID
X-Srv
X-Webapp-Samesite-None-Activated-N
X-Hostname
Liferay-Portal
Server-Info
X-EdgeConnect-Cache-Status
X-TX-ID
X-ProcessESI
X-RemovedCookies
X-Presslabs-Stats
X-Cache-TTL-Remaining
X-App-Server
Cleartype
Accept-CH
X-Dc
X-L-Path
X-Environment-Context
X-B3-Traceid
X-FireWall-Port
X-Endurance-Cache-Level
X-Handled-By
X-RTag
Ms-Operation-Id
X-Source
X-Upgrade-Enabled
X-CACHE-KEY
X-HTML-Minification-Powered-By
X-Cache-Server
From-Origin
Datacenter
Srv
X-UA
X-PressLabs-Stats
X-Backend-Name
Accept-Charset
Accept-CH-Lifetime
X-UUID
Meta-Geo
X-Path-Route
X-ES-SERVER
X-RN-RSRV
X-Cache-Var
X-Cache-Var-Map
OT-Force-Account-Verify
X-Tb
X-Section
Selected-Fe
X-Access
X-Timing-Wait
X-Format
X-Proxy-Build
X-Wix-Request-Id
X-Proto
X-ShopId
X-ShardId
X-Request-Time
X-Cache-Config
X-Content-Age
X-Alternate-Cache-Key
X-Akamai-Request-ID
Cache-Tags
X-EIG-Tracking-Id
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Shopify-Generated-Cart-Token
Mn-Server-Ip
X-Yottaa-Optimizations
X-ProxyCache-Status
X-ProxyCache-Key
X-Yottaa-Metrics
X-Qloud-Router
Akamai-GRN
X-SaId
X-BYPASS-REASON
X-Proxy-Cache-Status
X-PCL
X-LJ-Flow-ID
X-JoinUs
X-Hl-Ver
X-FC-Vary-Parameters
X-NYM-Debug-Backend
X-Origin
X-OCL
X-Akamai-Transformed
X-Akamai-Request-ID2
X-AWS-Id
Ec-Rule-Version
NGX
X-Vgn-Hpd-Reason
X-VWS-Id
Version
Node
X-Status
X-Soup
X-ServerID
X-Cache-Control
Origin-Edge-Control
X-FB-TRIP-ID
Origin-Cache-Control
X-FW-Dynamic
Now
Healthy
X-Cluster-Node
DB-Nickname
X-BCube-Filmed-By
X-Hosted-By
X-CCM
Decoy-Debug-Key
Cross-Origin-Window-Policy
Decoy-Debug-TTL
Decoy-Debug-Status
X-Debug-Cache
X-Hyper-Cache
X-Storage
X-SayCDN-TTL
X-Human
X-Time-Microsecs
X-TNCMS
X-Www-Served-By
X-Web-Node
X-Viewer-Country
X-Say-Cacheable
X-Say-TTL
X-APP-VERSION
X-Loop
X-Proxy
X-MP-GENERATED-AT
X-Pubstack
X-Generated-By
TWC-GeoIP-Country
TWC-Locale-Group
TWC-Privacy
Webcakes-App-Name
X-Xfnlog-Site
X-Locale
TWC-GeoIP-LatLong
TWC-Connection-Speed
Property-Id
X-RateLimit-Limit
Webcakes-App-Version
TWC-Device-Class
X-Varnish-Hits
Azure-Version
X-Amzn-Remapped-Content-Length
Azure-SlotName
Azure-SiteName
Azure-RegionName
Webcakes-Region
X-Origin-Hint
X-RCS-CacheZone
Azure-InstanceId
X-R9-Blue-Green-Version
X-Redis-Cache
X-Site-Version
X-Generated
S-Rt
X-NCache
X-Detected-As
X-IP
GEO-INFO
X-Cache-Host
Cache
Cache-Key
X-Rule
X-Whom
X-VCache
X-Drupal-Cache-Tags
L5d-Success-Class
Webserver
X-UA-Device-Type
X-NGENIX-Cache
X-Forwarded-Host
X-Esi
X-Mode
Cache-Name
X-Daa-Tunnel
X-CS
X-Unique-Id
Viewport
Time
X-UnsetCookies
Mime-Version
Uber-Trace-Id
X-VHOST
Accept-Language
Section-Io-Cache
X-Info
Content-Disposition
X-Origin-CC
X-Origin-TTL
Rt-Fastcgi-Cache
X-ApacheServer
X-PERF
Country
X-Newrelic-Synthetics
X-Varnish-Cache-Hits
X-B3-Spanid
ServedBy
X-Cache-Remote
Odigeo-Trace-Id
X-Backend-TTL
X-EC-Lua
X-From
X-Routing-Service
X-Proxied
X-Device-Type
X-CDN-Forward
X-Zipkin-Id
X-Magnolia-Registration
X-Via-Fastly
X-Nc
X-Cluster-Name
Geo-Info
X-CLOUD-TRACE-CONTEXT
X-Drupal-Cache-Contexts
X-Microcachable
X-Uri
X-TT-TIMESTAMP
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
Proxy-Connection
X-Ttl
X-Geo
Filterid
Access-Control-Request-Headers
Cf-Ipcountry
Ohc-File-Size
HitType
Content-Style-Type
Fastcgi-X-Cache-Version
GEO-REGION-INFO
Content-Script-Type
X-Real-IP
X-Trv-Group
X-TA-CDN-Provider
X-Region-Sid
X-Request-UUID
X-Transaction
Machine
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Handled
BehaviorPad-Version
Rendered-Blocks
X-ARC
X-B-Cookie
X-Application
X-External-Request-Id
X-Accel-Expires-Debug
X-Aed
X-DPWN-IS-SECURE
X-Destination
X-D
X-Date
X-Connection-Hash
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-A-Wwc
X-A-Dgt
T-Server
Viewtype
X-Geo-Header
X-GeoIP-Country-Code
Meta-Geo-Continent
Mobile-Detection-Method
VivaBuild
X-G
X-A-Dam
X-A-Dcw
X-A-Ccd
X-A
W
MD5-Digest
AsisCache
X-Twitter-Response-Tags
X-Vtex-Processado-Em
X-S-Cookie
X-S
X-Vtex-Remote-Cache
X-Rocket-Build-Number
X-Sigma
X-Vdms-Version
X-VG-TLSProxy
X-VG-WebCache
X-Session-Fingerprint
Xc-Version
X-Rewrite-Enabled
X-SRCache-Key
X-Rojux
X-Varnish-Beresp-Status
X-VG-WebServer
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Ttl
X-ScT
X-Sigma-Backend
X-C
X-Logging-Id
X-Labrador-Cache-Channel
X-PHP-Host
X-Cache-Debug
Countrycode
X-Developers
X-No-Session
CDCHOST
X-CGP
Fastly-SWR
IsBot
Powered-By
Locid
X-Hit
HA-Ipaddr
Ha-Gx-Prefs
Fastly-SIE
Fastly-Soc-X-Request-Id
X-Cache-Time
X-SIPLIST1
Environment
X-Clientip
X-Bip
X-Thanos
X-App-Version
X-Eu-Site
X-Rebelmouse-Cache-Control
X-VC-Cache
X-Distil-CS
X-Agile-Id
X-Rebelmouse-Surrogate-Control
X-CUA
X-Agile-Age
X-WebServer
X-Agile
X-App-Name
User-Cache-Control
X-GoCache-CacheStatus
Fastly-SSL
Request-Country
Request-EU
X-GeoIP-City
X-Has-Esi
X-Debug-Cookies
X-Cdn-Srv
X-Auto-Login
X-Epic-Correlation-Id
X-Hash
X-Debug-Log
Platform
X-Air-Hostname
X-Varnish-Authentication
X-Wikidot-Static-Cache
X-SVT-ORM-RULES
X-Generated-In
We-Hiring
True-Client-Country-4JS
X-Dispatcher-Server
X-Gamma-Serve
X-IN-APIGATEWAY
X-Cache-ASPX
X-Fetched-On
Server-Surrogate-Control
X-Wikidot-Backend
V-Age
RNT-Time
Server-Cache-Control
X-Cache-Tags
X-Distributor
Server-Int
Server-ID
RNT-Machine
X-Li-Fabric
X-Swa-Ws
X-Origin-Expires
X-OVcl
X-OVcl-Cache
X-Contensis-Viewer-Groups
X-Origin-Date
X-NX-Host
X-Up
X-Ms-Request-Id
X-Ms-Version
X-Nginx-Cache-Key
X-NodeID
X-Owner
X-TH-Server
X-VServer
X-Trace-Id
Group
X-Request-URI
X-Tumblr-Pixel-3
X-TrackingId
X-RateLimit-Remaining-Second
X-Var-Ttl
X-Core-Mission
X-Platform-Server
X-Proxy-Upstream
X-RateLimit-Limit-Second
X-IN-APIGATEWAYSSL
X-Cms-Context
IBM-Web2-Location
Is-Eu
Heartbleed
Gh-Request-Id
X-JWT-State
Kp-EeAlive
X-Is-Gdpr
Mail-Subject
X-Instart-Isnd
X-Variation
Locale
Adler-Geo
X-Azure-Ref
X-Li-Pop
X-Backend-State
X-Cache-Expired-At
AKAMAI
X-LI-UUID
Cache-Host
X-Urbn-Context-Path
Country-Code
X-LI-Proto
X-Urbn-Site-Id
X-SVT-ORM-VERSION
X-UPSTREAM-Address
X-Edge-Location
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Irp-Debug
X-Debug-Cache-Expiry
X-Micro-Cache
Pragrma
X-Matched-Rule
X-Server-W
X-Level-Front-Cache
X-NU-AKA-ACS-Version
X-Trafficlayer-App-Name
X-Reboot
X-Req
X-Thinkindot-L3
X-TT-LOGID
X-Trafficlayer-App-Version
Fastly-Backend-Name
X-Hnp-Log
X-Trafficlayer-App-Scope
X-FW-Version
X-Fastly-Cache
X-Webstats-RespID
X-We-Are-Hiring
X-ServiceProvider
X-Service
X-Generation-Time
Cache-Hits
X-Servername
X-Generated-On
X-Gen-Mode
X-WADP-Cache
Wxu-Next-Hostname
Server-Host
PFcat
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Web-Mar-Node
Thinkindot-Control
Memcached
FNAC-ModuleRouting
X-Nginx-Cache
X-Core-Value
ServerName
Cdncip
Cdnsip
Wxu-Next-Commit
Ohc-Cache-HIT
X-BBXSRF
Wxu-Next-Region
X-Cache-Info
X-Block-Status
X-AK-Request-ID
X-Clara-WADP
X-Cache-URL
S-Cnection
X-Cache-Bucket
X-S-Maxage
X-Render-Time
X-Old-Content-Length
X-Lb-Id
X-Cache-Backend
X-User
X-Refresh
X-Response-By
X-SERVER
RequestId
X-Internal-Host
Powered-By-ChinaCache
X-BACKEND-TTL
X-Wa
X-CSRF-TOKEN
X-Key
X-Varnish-Cacheable
X-Sucuri-Cache
X-Cdn-Forward
X-Sucuri-ID
X-CF-Powered-By
X-Tec-Api-Root
X-Parent-Response-Time
X-Ua
Origin
X-Location
X-Tec-Api-Version
X-Tec-Api-Origin
X-Node-Id
X-Pjax-Url
X-Oss-Request-Id
X-Oss-Object-Type
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
X-Tb-Optimization-Total-Bytes-Saved
X-Developer
X-CSRF-Token
User-Agent
X-Correlation-ID
X-Cache-Status-Check
X-Unique-ID
ProcessTime
X-Cdn-Origin
X-Cache-Grace
X-LAGOON
X-Device-Os
X-Sn-Servicetimems
X-Pf-Uncompressing
X-NC
Hostname
X-B3-Parentspanid
Geoip-Latitude
Memory
Geoip-City
X-Ocache
X-NWS-UUID-VERIFY
TTL
X-Via-CDN
SRV
Tcn
GeoIp-Country-Code
On-Server
X-Vcl-Version
A
X-COUNTRY
PICS-Label
X-MSEdge-Flight
X-Request-Host
Cloudfront-Viewer-Country
X-NGINX-Cache
X-MSEdge-Features
X-Server-IP
X-B3-SpanId
M-TraceId
X-Webkit-CSP
X-Litespeed-Cache
X-Servedbyhost
SN
X-HS-Status
Media-Length
Cdn
X-Rocket-Nginx-Bypass
X-Varnish-URL
X-Varnish-Ttl
X-Cdn-Request-ID
X-Ruxit-Js-Agent
X-TIME
XServer
CACHE
Dnion-Transfer-Encoding
Resin-Trace
X-FORWARDED-FOR
X-ServedByHost
Host-ID
X-Via-Ucdn
X-Ratelimit-Remaining
X-Action
X-Beluga-Node
X-Beluga-Cache-Status
X-Beluga-Record
X-Slack-Backend
X-Beluga-Status
X-Cache-Ttl
X-Beluga-Response-Time
Who
X-Beluga-Trace
X-Sucuri-Id
HostName
X-Cache-FS-Status
X-PAYTM-SRV-ID
Pramga
Arc-Country
X-RSL
Esi-Enabled
X-Processor
X-AIR-PT
Pics-Label
X-Fastly-Country-Code
X-Server-Time
X-RPS
X-Dispatch
X-RPM
X-Reqid
X-DI
X-DB
X-DW
X-DSS
X-Planisys-CDN-Cache
X-ABtesting
X-Policy
X-Flog
X-Hello
X-Planisys-CDN-Rules
X-ND-Cache
X-Planisys-CDN-TTL
X-Skip-Cache
GeoIP-Country-Code
CF-Cached-On
Cdn-Request-Time
Cdn-Host
Fastly-Drupal-HTML
X-VCL-Version
X-Served-From
X-Edge-Server
X-HostName
GeoIP-City
Amp-Access-Control-Allow-Source-Origin
X-VarnishDD-TTL
X-Request-Start
GeoIP-Latitude
X-Azure-Ref-OriginShield
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
MIME-Version
X-Oracle-Dms-Rid
Section-Io-Origin-Status
X-LiteSpeed-Cache-Control
Section-Io-Id
N-Cache
X-DevSite-Last-Modified
X-Varnish-Url
X-Bc-Bl
NtCoent-Length
X-Zone
X-Bc
X-PF-Uncompressing
Ttl
Rt-Proxy-Cache
Trailer
X-DC
X-Fastly-Backend-Reqs
X-Newrelic-App-Data
X-Ratelimit-Limit
X-FPC
X-APP
Fusion-Deployment-Id
X-Backend-Host
X-Adobe-Source
X-Method
WebServer
X-SRV
Magicmarker
X-PJAX-URL
X-Swift-Error
X-Dynatrace
X-BE
X-Amzn-Remapped-Connection
X-WA
Cteonnt-Length
Cache-Cookie-Set-Lfrom
X-Amzn-Remapped-Date
FSS-Cache
FSS-Proxy
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-From
Processtime
X-Dynatrace-Js-Agent
Servername
X-ZONE
Cache-Provider
X-Scheme
X-BC
X-ID
X-Fmm-Version
X-WR-MODIFICATION
X-Frame-Option
X-LB-ID
CF-IPCountry
X-Branch-Name
X-Svr
CDN
Ohc-Response-Time
X-Fpc
X-Snapshot-Date
X-StackifyID
Dynatrace
X-Be
Requestid
X-Ftr-Cache-Host
X-CACHE-AGE
X-Esi-Check
X-Compress-Hint
X-Tid
X-SN
L
WZWS-RAY
Vix-Hermes-Req-Id
X-Cache-Id
D-Cc-Upstream
X-Apw-Access-Token
X-Fastly-Cache-Hits
X-Apw-Hits
V-Cache
X-Apw-Access-Object
X-App
X-Apw-Access-Action
X-Request-Url
X-VC
X-SB
X-Aicache-OS
Lfy
X-Cc-Req-Id
X-Cc-Via
Warning
Load-Balancing
X-Litespeed-Cache-Control
Correlation-Id
X-ServerName
SID
LB
X-GEO
Sid
Lb
X-ElasticPress-Search
X-Check-Cacheable
X-Request-URL
X-Varnish-Beresp-TTL
X-Fastly-Cache-Status
Proxy-Firewall
X-Powered-Y
X-WPE-Loopback-Upstream-Addr
Backend-Name
Cneonction
WP-Super-Cache
Pagetype
X-Worker