Threat Level: green Handler on Duty: Russell Eubanks

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
CF-RAY
Link
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-Request-ID
X-DNS-Prefetch-Control
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
Status
Upgrade
X-Content-Security-Policy
Content-Encoding
X-CDN
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Xss-Protection
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
X-Pass-Why
X-Cache-Group
X-AH-Environment
Xkey
X-Envoy-Upstream-Service-Time
X-Via
X-Backend
CF-Ray
X-Server
X-Age
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Ws-Request-Id
X-Server-Powered-By
X-Page-Speed
X-Pingback
EagleId
X-Proxy-Cache
X-Hacker
X-UA-Device
X-Nginx-Cache-Status
Request-Context
Feature-Policy
X-Varnish-Cache
Server-Timing
Cf-Railgun
P3p
X-Swift-CacheTime
X-Swift-SaveTime
Grace
Ali-Swift-Global-Savetime
X-Amz-Version-Id
X-Ua-Compatible
Report-To
X-LiteSpeed-Cache
X-Rq
X-OneAgent-JS-Injection
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-WebKit-CSP
X-Device
X-Host
X-Server-Id
X-Origin-Cache
X-Response-Time
EagleEye-TraceId
X-Node
X-Ac
Surrogate-Control
Content-Location
X-Cloud-Trace-Context
X-Readtime
X-Backend-Server
X-Vhost
Request-Id
X-Dispatcher
X-Origin-Upstream-Status
X-Cnection
X-Cache-Lookup
X-Application-Context
X-HW
X-Ruxit-JS-Agent
Fusion-Template-Id
Fusion-Content-Source
Fusion-Content-Id
Fusion-Source
Fusion-Component-Id
X-ORACLE-DMS-ECID
NEL
X-ORACLE-DMS-RID
X-Mod-Pagespeed
X-DataDome
X-Rack-Cache
Rating
X-Country
Edge-Control
X-Clacks-Overhead
X-Akam-SW-Version
X-Dns-Prefetch-Control
Pinterest-Generated-By
X-TTL
Allow
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Country-Code
X-FTR-Request-ID
X-DynaTrace
X-Instart-Request-ID
X-Varnish-TTL
X-Goog-Hash
Accept-Ch
X-PC
X-TtlSet
X-Vname
X-ESI
Verso
Content-MD5
Service-Worker-Allowed
X-Powered-By-Plesk
Accept-Ch-Lifetime
X-Url
X-B3-TraceId
X-Forwarded-Proto
X-Version
X-GitHub-Request-Id
X-Cdn-Fetch
X-MS-InvokeApp
X-Exp-Id
X-Kinja-Revision
X-Use-Magma
X-Kinja-Build
X-Kinja-Server
X-Exp-Variant
X-GoogleNews-Bot
X-Kinja
RTSS
X-Vcache
X-Server-Name
Edge-Cache-Tag
X-D2id
X-Debug
X-Abt-Application-Version
X-Px
Ar-Sid
AR-Request-ID
AR-CACHE
AR-ATIME
AR-PoweredBy
X-Amz-Server-Side-Encryption
SPRequestGuid
Charset
X-NF-Request-ID
X-Cached
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Fastcgi-Cache
Response
Display
Pagespeed
X-Middleton-Display
X-Sol
X-Middleton-Response
X-Navigation-Version
X-MSEdge-Ref
X-Accel-Expires
X-Vcap-Request-Id
Arr-Disable-Session-Affinity
X-Amz-Rid
X-Pinterest-Rid
Pinterest-Version
TCN
X-Server-ID
X-SharePointHealthScore
X-Powered-CMS
X-SRCache-Fetch-Status
X-VARITI-CCR
X-SRCache-Store-Status
X-Edge-O15-RID
Public-Key-Pins
X-Fastly-Request-ID
X-Trace
Cache-Tag
Realpath
X-Client-IP
X-Cdn
MS-Author-Via
Nginx-Cache
X-Ser
Access-Control-Request-Method
X-Shard
X-DynaTrace-JS-Agent
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
X-Content-Type
SPRequestDuration
SPIisLatency
X-Amzn-Trace-Id
X-Upstream
X-Ezoic-Cdn
S
X-Id
X-Hp-Webp
X-Grace
X-Forwarded-For
X-T
X-Amz-Meta-S3cmd-Attrs
X-Jurisdiction
X-Hits
Front-End-Https
Fastcgi-Cache
X-Recruiting
DynaTrace
Nel
X-Cache-TTL
X-Aspnet-Version
X-Varnish-Age
ServerID
X-Element-Page-Cache
X-Content-Digest
X-Node-Name
MicrosoftSharePointTeamServices
X-Mobile-URL
X-Country-Code-Real
X-FTR-Realm
X-FTR-Backend
X-FTR-Expires
X-FTR-DC
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Cache-Status
X-DIS-Request-ID
X-Dw-Request-Base-Id
NR-ENABLED
Server-Node
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Combine-CSS
X-Goog-Generation
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
Powered
X-Goog-Metageneration
X-Frontend
TP-L2-Cache
TP-Cache
X-Logged-In
Alternate-Protocol
Server-Name
X-CST
X-Amz-Apigw-Id
X-Amzn-RequestId
AMP-Access-Control-Allow-Source-Origin
Upgrade-Insecure-Requests
X-Request-Received
X-Correlation-Id
X-Request-Processing-Time
X-Microsite
X-Cache-Hit
X-Request-Handler-Origin-Region
X-ATS-Timestamp
Backend-Timing
Fastly-Restarts
X-XRDS-Location
X-Content-Options
X-Origin-Server
Refresh
X-F-Cache
X-Content-Security-Policy-Report-Only
X-User-Agent
X-Zen-Fury
X-Page-Id
X-Akamai-Edgescape
X-Rid
X-Varnish-Grace
X-Revision
X-XRDS-LOCATION
X-Type
X-FTR-Cache-Host
X-Content-Powered-By
X-LB-Cache
X-Webkit-Csp
X-B
PB-RID
PB-PID
X-B3-Sampled
Arc-Version
X-Mobile-Rewrite
X-Geo-Country
X-Activity-Id
X-Az
X-AppVersion
Cache-Status
X-URL
X-Kinsta-Cache
X-N
X-Cache-Age
X-TT
X-Cache-Action
X-Signature
X-WebKit-CSP-Report-Only
X-B-Cache
X-AOL-HN
X-Instance
X-Time
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Framework
X-Tumblr-User
X-Jobs
X-Debug-Info
Actual-Object-TTL
Paypal-Debug-Id
Access-Control-Allow-Method
X-FB-Debug
X-App-Environment
X-Request-Guid
X-Cached-By
X-PHP-Backend
X-Git-Hash
X-Shield-Request-Id
X-Load-Cache
X-Pad
Fastcgi-Useragent
DC
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Amz-Replication-Status
X-Varnish-Backend
Surrogate-Key
X-IPLB-Instance
X-RateLimit-Remaining
Host-Header
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-ATG-Version
MS-CV
X-Contextid
X-NWS-LOG-UUID
X-WA-Info
Host
X-ORACLE-APMCS-REQUEST-ID
X-ORACLE-APMCS-TAG
X-SS-Set-Cookie
X-Mobile
X-Via-JSL
X-Webapp-Samesite-None-Activated-N
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Accept-CH
X-Accel-Buffering
X-Host-Name
X-Response-Served-From
Tracecode
NGB
X-Analytics
X-Cache-Key
FilterID
X-Cluster
Payment
Xserver
Frame-Options
X-Cache-NE
Eomportal-Instance
X-FW-Static
X-FW-Server
WPE-Backend
X-Cache-2
Source
X-FW-Serve
X-FW-Hash
X-Varnish-Server
X-FW-Type
X-Region
X-Origin-Response-Time
X-Tumblr-Pixel-1
X-Tumblr-Pixel-2
X-IPS-LoggedIn
X-GeoIP
Filters
X-Varnish-Hostname
Cache-Tv-Group
X-Presslabs-Stats
X-Adobe-Loc
X-Hostname
X-Adobe-Content
X-Cacheable-TTL
X-Cache-Enabled
X-Srv
X-EdgeConnect-Cache-Status
X-RequestSource
X-Rendered-As
X-Seen-By
X-Cache-Operation
X-NewRelic-App-Data
X-Cache-Rule
Retry-After
X-Is-Bot
X-TX-ID
Server-Info
Liferay-Portal
X-RemovedCookies
X-ProcessESI
X-Cache-TTL-Remaining
Accept-CH-Lifetime
X-FastCGI-Cache
Cleartype
X-App-Server
X-Dc
X-Environment-Context
X-L-Path
X-FireWall-Port
X-RTag
Ms-Operation-Id
X-B3-Traceid
X-Endurance-Cache-Level
X-Source
X-Handled-By
X-Upgrade-Enabled
X-CACHE-KEY
X-Cache-Server
Datacenter
X-HTML-Minification-Powered-By
From-Origin
X-UA
X-Backend-Name
Srv
Accept-Charset
X-VCache
X-APP-VERSION
X-UUID
X-Wix-Request-Id
X-Path-Route
X-ES-SERVER
X-PressLabs-Stats
X-Cache-Var
Meta-Geo
X-Cache-Var-Map
X-RN-RSRV
X-Access
X-Timing-Wait
X-Section
Selected-Fe
OT-Force-Account-Verify
X-Format
X-Cache-Control
X-Proxy-Build
X-Tb
Azure-SlotName
X-Cache-Config
X-NYM-Debug-Backend
Healthy
Azure-Version
X-Origin
X-PCL
Mn-Server-Ip
Cache-Tags
X-OCL
X-Status
Azure-SiteName
X-Request-Time
X-Shopify-Stage
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Alternate-Cache-Key
Azure-RegionName
X-FC-Vary-Parameters
Version
X-Content-Age
X-EIG-Tracking-Id
Azure-InstanceId
Akamai-GRN
X-Sorting-Hat-PodId
X-Shopify-Generated-Cart-Token
X-ShopId
X-Akamai-Request-ID
X-Proto
X-Sorting-Hat-ShopId
X-ShardId
X-Pubstack
X-Qloud-Router
Decoy-Debug-TTL
X-Proxy-Cache-Status
X-ProxyCache-Key
DB-Nickname
X-ProxyCache-Status
X-Proxy
Decoy-Debug-Key
X-Time-Microsecs
X-Hosted-By
X-Hyper-Cache
X-ServerID
X-JoinUs
X-Hl-Ver
X-Akamai-Request-ID2
X-Cluster-Node
X-BYPASS-REASON
X-AWS-Id
X-FW-Dynamic
X-SaId
X-LJ-Flow-ID
X-VWS-Id
Now
Node
NGX
Origin-Cache-Control
X-Viewer-Country
X-Soup
Origin-Edge-Control
X-Vgn-Hpd-Reason
Ec-Rule-Version
Decoy-Debug-Status
X-Yottaa-Metrics
X-Yottaa-Optimizations
GEO-INFO
Webcakes-App-Name
X-Storage
Webcakes-App-Version
Webcakes-Region
X-BCube-Filmed-By
X-Amzn-Remapped-Content-Length
X-TNCMS
TWC-Privacy
TWC-Device-Class
TWC-Connection-Speed
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Locale-Group
X-Debug-Cache
X-FB-TRIP-ID
X-Say-Cacheable
X-Redis-Cache
X-Say-TTL
X-SayCDN-TTL
X-Web-Node
X-Www-Served-By
X-Origin-Hint
Cache
Property-Id
X-Generated-By
X-Human
X-Loop
X-MP-GENERATED-AT
X-Varnish-Hits
X-CCM
Cross-Origin-Window-Policy
X-Locale
X-Akamai-Transformed
X-R9-Blue-Green-Version
X-RCS-CacheZone
X-Site-Version
X-Xfnlog-Site
X-NCache
S-Rt
X-Generated
X-Rule
X-IP
X-RateLimit-Limit
X-Detected-As
X-Cache-Host
X-Drupal-Cache-Tags
Cache-Key
X-Unique-Id
L5d-Success-Class
X-CS
Webserver
Cache-Name
X-Whom
Viewport
Time
X-Esi
Uber-Trace-Id
X-Daa-Tunnel
X-UA-Device-Type
X-Forwarded-Host
X-Mode
X-NGENIX-Cache
X-UnsetCookies
Mime-Version
X-Info
X-VHOST
X-Origin-CC
Content-Disposition
Rt-Fastcgi-Cache
X-Origin-TTL
Country
X-Varnish-Cache-Hits
Accept-Language
X-B3-Spanid
X-ApacheServer
Section-Io-Cache
X-PERF
X-Cache-Remote
X-From
Odigeo-Trace-Id
ServedBy
X-Backend-TTL
X-Newrelic-Synthetics
X-Cluster-Name
X-Magnolia-Registration
X-CDN-Forward
X-Zipkin-Id
X-Nc
X-Proxied
X-Device-Type
X-Routing-Service
X-Drupal-Cache-Contexts
VIX-Pulpo-Node
X-CLOUD-TRACE-CONTEXT
X-Via-Fastly
VIX-Pulpo-Upstream-Status
X-Geo
X-Microcachable
X-TT-TIMESTAMP
X-Uri
Proxy-Connection
X-EC-Lua
Cf-Ipcountry
X-Ttl
Ohc-File-Size
HitType
Access-Control-Request-Headers
Fastcgi-X-Cache-Version
Apple-News-Services-Handled
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
BehaviorPad-Version
X-ARC
Mobile-Detection-Method
X-Application
Apple-News-Services-Request-Url
Rendered-Blocks
Content-Style-Type
AsisCache
X-A-Wwc
X-A-Ccd
X-A-Dam
X-A-Dcw
T-Server
X-A
Viewtype
Machine
W
X-A-Dgt
VivaBuild
X-Varnish-Beresp-Grace
Meta-Geo-Continent
X-Aed
X-Varnish-Beresp-Status
X-Varnish-Beresp-Ttl
MD5-Digest
X-Accel-Expires-Debug
GEO-REGION-INFO
X-External-Request-Id
X-B-Cookie
X-S
X-ScT
X-Session-Fingerprint
X-Sigma
X-Rojux
X-Rocket-Build-Number
X-Region-Sid
Geo-Info
X-Request-UUID
X-Rewrite-Enabled
X-Sigma-Backend
X-SRCache-Key
X-VG-WebServer
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-VG-WebCache
X-VG-TLSProxy
X-Transaction
X-Trv-Group
X-Twitter-Response-Tags
X-Vdms-Version
X-GeoIP-Country-Code
X-S-Cookie
X-Destination
X-Geo-Header
X-Date
X-D
X-Connection-Hash
X-CF-Lambda-Fn
Content-Script-Type
X-DPWN-IS-SECURE
X-G
X-CF-Lambda-Version
X-No-Session
X-Edge-Location
X-Real-IP
X-C
IsBot
Fastly-SWR
HA-Ipaddr
X-Agile-Id
Gh-Request-Id
Ha-Gx-Prefs
X-App-Name
X-Cache-Debug
X-Wikidot-Backend
X-Wikidot-Static-Cache
Countrycode
X-Auto-Login
X-WebServer
X-Bip
Fastly-SIE
Environment
Locid
X-Cache-ASPX
Fastly-Soc-X-Request-Id
X-Clientip
X-Distil-CS
X-Developers
X-Agile
X-CUA
X-Eu-Site
X-Rebelmouse-Surrogate-Control
X-Hit
X-Logging-Id
X-Rebelmouse-Cache-Control
X-Contensis-Viewer-Groups
Server-Surrogate-Control
X-CGP
X-Tumblr-Pixel-3
X-Varnish-Authentication
Powered-By
X-TrackingId
X-SIPLIST1
Server-Cache-Control
X-Thanos
X-VC-Cache
X-Agile-Age
CDCHOST
X-Cache-Time
X-GoCache-CacheStatus
Fastly-SSL
X-UPSTREAM-Address
Ohc-Cache-HIT
User-Cache-Control
Filterid
X-Epic-Correlation-Id
X-Generated-In
X-Gamma-Serve
X-FW-Version
X-Generation-Time
X-Fetched-On
X-Fastly-Cache
X-Hash
X-IN-APIGATEWAYSSL
X-Instart-Isnd
X-Irp-Debug
X-IN-APIGATEWAY
X-Webstats-RespID
X-Has-Esi
X-Distributor
X-GeoIP-City
X-Debug-Cookies
X-Cache-Info
X-Cache-Tags
X-Cache-URL
X-BBXSRF
X-Backend-State
X-Air-Hostname
X-AK-Request-ID
X-Azure-Ref
X-Cdn-Srv
X-Clara-WADP
X-Debug-Cache-Store
X-Is-Gdpr
X-Debug-Log
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-Cms-Context
X-Urbn-Context-Path
X-Dispatcher-Server
X-Li-Pop
X-Request-URI
X-Server-W
X-Servername
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Platform-Server
X-VServer
X-Proxy-Upstream
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-TT-LOGID
X-Urbn-Site-Id
X-Up
X-Variation
X-Trace-Id
X-Swa-Ws
X-TH-Server
Cdncip
X-PHP-Host
X-Micro-Cache
X-Ms-Request-Id
X-Ms-Version
X-We-Are-Hiring
X-LI-UUID
X-Labrador-Cache-Channel
X-Li-Fabric
X-LI-Proto
X-Nginx-Cache-Key
X-NodeID
X-OVcl-Cache
X-Owner
X-WADP-Cache
X-OVcl
X-Origin-Expires
X-NX-Host
X-Origin-Date
X-JWT-State
X-Core-Mission
RNT-Machine
Request-EU
Request-Country
Memcached
RNT-Time
Server-ID
V-Age
True-Client-Country-4JS
Server-Int
Mail-Subject
Locale
AKAMAI
Cache-Host
Country-Code
Cdnsip
Adler-Geo
Heartbleed
Kp-EeAlive
Is-Eu
IBM-Web2-Location
We-Hiring
Platform
X-Trafficlayer-App-Name
X-Trafficlayer-App-Scope
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-NU-AKA-ACS-Version
Thinkindot-Control
X-Hnp-Log
Web-Mar-Node
X-Core-Value
X-App-Version
ServerName
Wxu-Next-Commit
X-Level-Front-Cache
X-Gen-Mode
X-Generated-On
X-Nginx-Cache
X-Matched-Rule
X-Reboot
Server-Host
Wxu-Next-Hostname
PFcat
X-Cache-Expired-At
X-Service
X-Block-Status
Wxu-Next-Region
X-ServiceProvider
X-Cache-Bucket
X-Thinkindot-L3
X-Trafficlayer-App-Version
X-Req
X-Render-Time
X-Var-Ttl
Group
FNAC-ModuleRouting
Fastly-Backend-Name
X-Cache-Backend
S-Cnection
X-Lb-Id
X-User
Cache-Hits
Pragrma
X-S-Maxage
X-TA-CDN-Provider
X-Old-Content-Length
X-SERVER
X-Response-By
RequestId
X-Internal-Host
X-Refresh
X-Key
Powered-By-ChinaCache
X-Sucuri-Cache
X-BACKEND-TTL
X-Cdn-Forward
X-Ruxit-Js-Agent
X-CSRF-TOKEN
X-Location
X-Ua
X-Sucuri-ID
X-Pjax-Url
X-Tb-Optimization-Total-Bytes-Saved
X-Tec-Api-Version
X-Parent-Response-Time
X-Tec-Api-Origin
X-Tec-Api-Root
Origin
X-Wa
X-Varnish-Cacheable
X-Correlation-ID
X-CF-Powered-By
X-CSRF-Token
ProcessTime
User-Agent
X-B3-Parentspanid
X-Node-Id
Memory
X-NC
X-Developer
X-Pf-Uncompressing
TTL
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Ocache
Geoip-Latitude
X-Cdn-Origin
X-Device-Os
X-NWS-UUID-VERIFY
Geoip-City
X-Cache-Grace
X-Via-CDN
X-Vcl-Version
X-LAGOON
X-Sn-Servicetimems
X-Unique-ID
SRV
X-Cache-Status-Check
On-Server
X-Server-IP
PICS-Label
Hostname
GeoIp-Country-Code
X-B3-SpanId
X-MSEdge-Flight
X-NGINX-Cache
X-COUNTRY
A
X-MSEdge-Features
Cloudfront-Viewer-Country
X-Request-Host
X-Litespeed-Cache
Media-Length
X-Cdn-Request-ID
X-Servedbyhost
X-Webkit-CSP
X-Varnish-Ttl
X-Ratelimit-Remaining
X-Rocket-Nginx-Bypass
Cdn
Dnion-Transfer-Encoding
XServer
X-TIME
Host-ID
M-TraceId
SN
X-Varnish-URL
Resin-Trace
X-Via-Ucdn
Tcn
X-FORWARDED-FOR
CACHE
X-HS-Status
X-Sucuri-Id
X-ServedByHost
X-AIR-PT
Who
X-Cache-Ttl
X-Beluga-Node
X-Beluga-Status
X-Beluga-Trace
X-Beluga-Response-Time
X-Beluga-Record
X-Beluga-Cache-Status
X-Reqid
Esi-Enabled
HostName
X-Fastly-Country-Code
X-Slack-Backend
X-Action
CF-Cached-On
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Policy
X-PAYTM-SRV-ID
X-Processor
X-Server-Time
X-DW
X-Azure-Ref-OriginShield
X-RSL
X-DSS
Pics-Label
X-Request-Start
Trailer
X-DI
Pramga
X-Cache-FS-Status
X-Dispatch
X-RPM
GeoIP-Country-Code
X-RPS
Arc-Country
X-DB
Rt-Proxy-Cache
X-ND-Cache
X-ABtesting
GeoIP-City
X-VarnishDD-TTL
X-Skip-Cache
X-VCL-Version
X-Flog
X-Hello
GeoIP-Latitude
X-Ratelimit-Limit
X-Oracle-Dms-Rid
X-LiteSpeed-Cache-Control
MIME-Version
NtCoent-Length
Cdn-Host
Fastly-Drupal-HTML
X-Varnish-Url
Cdn-Request-Time
X-Edge-Server
X-Served-From
X-APP
X-PF-Uncompressing
Ttl
X-Fastly-Backend-Reqs
X-DC
Magicmarker
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Io-Id
Section-Origin-Responded
X-Method
X-Zone
X-DevSite-Last-Modified
X-Bc
X-Newrelic-App-Data
X-Bc-Bl
X-FPC
N-Cache
X-HostName
X-Swift-Error
Amp-Access-Control-Allow-Source-Origin
X-SRV
X-Amzn-Remapped-Date
X-Backend-Host
X-PJAX-URL
WebServer
X-Amzn-Remapped-Connection
Cteonnt-Length
X-Ftr-Cache-Host
Processtime
X-Dynatrace
X-BE
X-BC
Fusion-Deployment-Id
X-ZONE
X-WA
Servername
X-Dynatrace-Js-Agent
X-Adobe-Source
X-Fmm-Version
X-Svr
X-Be
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
Ohc-Response-Time
FSS-Cache
Cache-Cookie-Set-From
Cache-Provider
X-ID
FSS-Proxy
X-Frame-Option
X-WR-MODIFICATION
X-Snapshot-Date
X-Aicache-OS
X-StackifyID
Dynatrace
Load-Balancing
X-Scheme
X-Branch-Name
CDN
Requestid
Lfy
X-LB-ID
Vix-Hermes-Req-Id
CF-IPCountry
X-CACHE-AGE
X-Tid
X-Fpc
WZWS-RAY
V-Cache
X-Apw-Access-Action
X-Apw-Hits
X-App
X-Fastly-Cache-Hits
X-Request-Url
Pagetype
X-SB
X-VC
X-Cc-Via
X-Apw-Access-Object
X-Cc-Req-Id
D-Cc-Upstream
X-Apw-Access-Token
Warning
Proxy-Firewall
X-Litespeed-Cache-Control
X-MServer
DSUID
X-Hp-Ccpa-Warning
X-VCT
X-WPE-Loopback-Upstream-Addr
Correlation-Id
Backend-Name
Cneonction
WP-Super-Cache
X-Request-URL
X-Check-Cacheable
X-Varnish-Beresp-TTL
X-Powered-Y
X-ElasticPress-Search
X-Worker
Release
X-Fastly-Cache-Status
X-Configured-By