Threat Level: green Handler on Duty: Manuel Humberto Santander Pelaez

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-Powered-By
Pragma
CF-Cache-Status
Link
ETag
X-XSS-Protection
Expect-CT
CF-RAY
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
X-Xss-Protection
Access-Control-Allow-Methods
X-Download-Options
X-Request-Id
CF-Ray
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Request-ID
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-DNS-Prefetch-Control
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
Status
Upgrade
Content-Encoding
X-Content-Security-Policy
X-CDN
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
X-Pass-Why
X-Cache-Group
X-AH-Environment
X-Envoy-Upstream-Service-Time
X-Via
Xkey
X-Backend
X-Age
X-Server
X-Ws-Request-Id
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
EagleId
X-Page-Speed
X-Server-Powered-By
X-Pingback
X-Proxy-Cache
X-Hacker
X-Nginx-Cache-Status
Request-Context
Feature-Policy
Server-Timing
X-UA-Device
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Cf-Railgun
Ali-Swift-Global-Savetime
Grace
X-Amz-Version-Id
X-Ua-Compatible
Report-To
X-LiteSpeed-Cache
X-OneAgent-JS-Injection
X-Rq
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-WebKit-CSP
X-Server-Id
X-Device
X-Host
X-Origin-Cache
X-Response-Time
EagleEye-TraceId
X-Node
X-Ac
Surrogate-Control
Content-Location
X-Cloud-Trace-Context
X-Vhost
X-Backend-Server
X-Readtime
X-Dispatcher
X-Cache-Lookup
Request-Id
X-Ruxit-JS-Agent
X-Origin-Upstream-Status
X-Cnection
X-Application-Context
X-HW
Fusion-Content-Id
Fusion-Template-Id
Fusion-Component-Id
Fusion-Source
Fusion-Content-Source
X-ORACLE-DMS-ECID
X-Mod-Pagespeed
NEL
X-ORACLE-DMS-RID
P3p
X-DataDome
X-Dns-Prefetch-Control
X-Rack-Cache
X-Country
X-Clacks-Overhead
Rating
X-Akam-SW-Version
Edge-Control
Allow
Pinterest-Generated-By
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Country-Code
X-FTR-Request-ID
X-Instart-Request-ID
X-Varnish-TTL
X-DynaTrace
X-TTL
X-Vname
X-TtlSet
X-Goog-Hash
X-PC
Accept-Ch
Content-MD5
Verso
X-ESI
Service-Worker-Allowed
X-Url
X-Powered-By-Plesk
Accept-Ch-Lifetime
X-GitHub-Request-Id
X-Cdn-Fetch
X-Kinja-Server
X-Use-Magma
X-Exp-Id
X-Kinja
X-Kinja-Build
X-Kinja-Revision
X-GoogleNews-Bot
X-Exp-Variant
RTSS
X-Version
X-Forwarded-Proto
X-MS-InvokeApp
X-Server-Name
X-Vcache
X-B3-TraceId
X-D2id
Edge-Cache-Tag
X-Px
X-Abt-Application-Version
X-Debug
X-Amz-Server-Side-Encryption
AR-CACHE
AR-ATIME
AR-Request-ID
AR-PoweredBy
Ar-Sid
SPRequestGuid
X-Cached
Charset
X-Vcap-Request-Id
X-NF-Request-ID
X-Navigation-Version
X-MSEdge-Ref
X-Middleton-Display
Response
Display
Pagespeed
X-Amz-Rid
X-Sol
X-Middleton-Response
Arr-Disable-Session-Affinity
X-Accel-Expires
X-TEC-API-VERSION
TCN
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-VARITI-CCR
X-SharePointHealthScore
Pinterest-Version
X-Pinterest-Rid
Nginx-Cache
MS-Author-Via
Public-Key-Pins
X-Cdn
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Fastly-Request-ID
X-Trace
X-Powered-CMS
X-Fastcgi-Cache
X-Edge-O15-RID
X-Client-IP
Cache-Tag
Realpath
X-Ser
Access-Control-Request-Method
X-Server-ID
X-Content-Type
Mrf-Cache-Status
X-Mrf-Item-Lastmod
X-B3-TraceId-Primal
MRF-Tech
X-Mrf-Section-Lastmod
SPRequestDuration
SPIisLatency
X-Amzn-Trace-Id
X-Grace
X-Upstream
X-Shard
X-Jurisdiction
X-Hp-Webp
X-Id
X-Cache-TTL
X-Ezoic-Cdn
X-Forwarded-For
Front-End-Https
X-Hits
Fastcgi-Cache
Nel
X-Amz-Meta-S3cmd-Attrs
S
X-T
X-DynaTrace-JS-Agent
X-Aspnet-Version
X-Recruiting
DynaTrace
X-Element-Page-Cache
X-Node-Name
X-Content-Digest
X-Dw-Request-Base-Id
X-FTR-Realm
X-FTR-Balancer
X-Varnish-Age
X-Mobile-URL
X-FTR-Cache-Status
X-FTR-Expires
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-DC
X-Country-Code-Real
MicrosoftSharePointTeamServices
ServerID
X-DIS-Request-ID
NR-ENABLED
TP-L2-Cache
TP-Cache
Server-Node
X-HS-Hub-Id
X-Frontend
X-HS-Cache-Config
X-HS-Combine-CSS
X-HS-Content-Id
X-Goog-Storage-Class
X-Goog-Generation
Powered
X-GUploader-UploadID
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Correlation-Id
X-Logged-In
X-CST
Alternate-Protocol
Server-Name
Upgrade-Insecure-Requests
X-Amzn-RequestId
X-Amz-Apigw-Id
Fastly-Restarts
X-XRDS-Location
X-Cache-Hit
AMP-Access-Control-Allow-Source-Origin
X-FTR-Cache-Host
X-Request-Handler-Origin-Region
X-Microsite
X-ATS-Timestamp
Backend-Timing
X-Zen-Fury
X-Page-Id
X-Content-Options
X-Content-Security-Policy-Report-Only
Refresh
X-User-Agent
X-F-Cache
X-Akamai-Edgescape
X-Request-Processing-Time
X-Request-Received
X-Origin-Server
X-Varnish-Grace
X-Rid
X-LB-Cache
X-Revision
X-B
X-Mobile-Rewrite
PB-PID
PB-RID
X-Content-Powered-By
Arc-Version
X-Type
X-XRDS-LOCATION
X-B3-Sampled
Cache-Status
X-Geo-Country
X-Activity-Id
X-AppVersion
X-Az
X-Kinsta-Cache
X-NWS-LOG-UUID
X-TT
X-Cache-Action
X-N
X-AOL-HN
X-WebKit-CSP-Report-Only
X-B-Cache
X-Signature
X-Framework
X-App-Environment
Access-Control-Allow-Method
X-Cached-By
X-Jobs
X-Request-Guid
X-Debug-Info
X-Git-Hash
X-PHP-Backend
Actual-Object-TTL
X-FB-Debug
X-Instance
Paypal-Debug-Id
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-User
X-Cache-Age
X-URL
X-Load-Cache
X-Tt-Trace-Host
X-Tt-Trace-Tag
Fastcgi-Useragent
X-Amz-Replication-Status
X-Time
X-Webkit-Csp
X-FastCGI-Cache
DC
X-Varnish-Backend
X-Pad
Host-Header
Host
X-WA-Info
X-ATG-Version
X-RateLimit-Remaining
X-ORACLE-APMCS-TAG
X-ORACLE-APMCS-REQUEST-ID
X-Shield-Request-Id
X-Via-JSL
MS-CV
X-IPLB-Instance
Surrogate-Key
X-Contextid
X-Erf-Bev-Bev
X-Mobile
X-Erf-Bev-Bev-Is-Generated
Accept-CH
X-Host-Name
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Cache-Key
Retry-After
Liferay-Portal
Frame-Options
X-Accel-Buffering
X-Response-Served-From
NGB
Payment
X-Presslabs-Stats
X-Seen-By
X-B3-Traceid
X-Hostname
Source
X-Srv
X-Cache-NE
X-Cache-2
Eomportal-Instance
X-Region
X-Origin-Response-Time
X-Varnish-Server
X-FW-Server
WPE-Backend
Filters
X-Rendered-As
X-Cacheable-TTL
Tracecode
X-GeoIP
X-FW-Serve
X-FW-Type
X-Cache-Enabled
X-Cluster
X-IPS-LoggedIn
X-FW-Static
X-FW-Hash
X-Is-Bot
X-SS-Set-Cookie
X-NewRelic-App-Data
X-Adobe-Content
X-Varnish-Hostname
Server-Info
X-Adobe-Loc
Cache-Tv-Group
X-Tumblr-Pixel-1
X-Tumblr-Pixel-2
X-RequestSource
X-Cache-Rule
X-App-Server
X-Cache-Operation
X-ProcessESI
FilterID
X-RemovedCookies
X-EdgeConnect-Cache-Status
Accept-CH-Lifetime
Xserver
X-TX-ID
X-Cache-TTL-Remaining
X-L-Path
X-Environment-Context
X-FireWall-Port
Cleartype
X-Upgrade-Enabled
X-Analytics
X-Handled-By
Accept-Charset
Ms-Operation-Id
X-Source
X-RTag
X-UA
X-Ttl
X-Endurance-Cache-Level
X-Cache-Server
From-Origin
Srv
X-Backend-Name
X-HTML-Minification-Powered-By
X-Dc
X-APP-VERSION
X-CACHE-KEY
X-UUID
Healthy
Datacenter
X-Wix-Request-Id
X-Daa-Tunnel
Meta-Geo
X-Path-Route
GEO-INFO
X-Cache-Var
X-Cache-Var-Map
X-Unique-Id
X-ES-SERVER
X-RN-RSRV
OT-Force-Account-Verify
X-Tb
X-Akamai-Transformed
X-Proxy-Build
X-Status
X-Timing-Wait
X-Access
Selected-Fe
X-Section
X-Akamai-Request-ID
Mn-Server-Ip
X-OCL
X-PCL
Akamai-GRN
X-Cache-Config
X-EIG-Tracking-Id
X-FC-Vary-Parameters
X-Content-Age
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Alternate-Cache-Key
X-Request-Time
X-Proto
X-Shopify-Stage
X-ShopId
Cache-Tags
X-Sorting-Hat-ShopId
X-Format
X-Webapp-Samesite-None-Activated-N
X-Sorting-Hat-PodId
X-ShardId
X-Shopify-Generated-Cart-Token
X-Ua-Device
X-Hosted-By
X-Soup
X-Debug-Cache
X-AWS-Id
X-BYPASS-REASON
X-Viewer-Country
X-Proxy
X-Hl-Ver
X-Human
Decoy-Debug-Key
Decoy-Debug-Status
Decoy-Debug-TTL
X-NYM-Debug-Backend
Ec-Rule-Version
X-Vgn-Hpd-Reason
X-Origin
X-Hyper-Cache
X-SaId
X-Say-Cacheable
X-Say-TTL
X-VWS-Id
X-Redis-Cache
X-Qloud-Router
X-Proxy-Cache-Status
X-ProxyCache-Key
X-ProxyCache-Status
X-Whom
Origin-Edge-Control
X-SayCDN-TTL
X-Yottaa-Optimizations
Origin-Cache-Control
X-Akamai-Request-ID2
X-LJ-Flow-ID
X-Yottaa-Metrics
X-JoinUs
X-Web-Node
Node
Azure-InstanceId
NGX
Version
X-ServerID
Azure-RegionName
X-Www-Served-By
X-Time-Microsecs
X-Storage
X-Loop
X-Locale
X-FW-Dynamic
DB-Nickname
X-Site-Version
Now
X-MP-GENERATED-AT
X-Generated-By
X-Generated
X-Pubstack
X-CCM
Azure-SlotName
X-Detected-As
Azure-Version
X-FB-TRIP-ID
X-TNCMS
Azure-SiteName
X-BCube-Filmed-By
Cross-Origin-Window-Policy
TWC-Connection-Speed
TWC-GeoIP-Country
TWC-Device-Class
S-Rt
X-RCS-CacheZone
X-Xfnlog-Site
Property-Id
TWC-GeoIP-LatLong
TWC-Privacy
X-IP
X-Origin-Hint
X-Varnish-Hits
Webcakes-Region
Webcakes-App-Version
X-R9-Blue-Green-Version
Webcakes-App-Name
TWC-Locale-Group
X-NCache
X-PressLabs-Stats
X-Cluster-Node
X-Amzn-Remapped-Content-Length
X-UA-Device-Type
X-VCache
Cache-Key
X-Backend-TTL
X-NGENIX-Cache
X-RateLimit-Limit
X-Cache-Control
Section-Io-Cache
X-Cache-Host
X-Mode
X-CDN-Forward
X-Forwarded-Host
X-Drupal-Cache-Tags
X-Esi
X-Rule
Cache
Webserver
L5d-Success-Class
Content-Disposition
X-Info
Time
X-UnsetCookies
X-PERF
X-ApacheServer
X-Varnish-Cache-Hits
Accept-Language
Cache-Name
Viewport
ServedBy
X-CS
X-Origin-TTL
X-Newrelic-Synthetics
X-Origin-CC
X-B3-Spanid
Rt-Fastcgi-Cache
Uber-Trace-Id
X-Cache-Remote
Mime-Version
Country
X-Routing-Service
X-Zipkin-Id
Odigeo-Trace-Id
X-Proxied
X-Device-Type
X-Via-Fastly
X-Magnolia-Registration
X-CLOUD-TRACE-CONTEXT
X-Uri
Proxy-Connection
X-From
X-Geo
Filterid
X-Cluster-Name
X-EC-Lua
X-Real-IP
Access-Control-Request-Headers
HitType
X-Drupal-Cache-Contexts
X-Microcachable
X-TT-TIMESTAMP
X-G
X-A-Dgt
X-A-Dcw
X-Rojux
Machine
X-S
X-Rewrite-Enabled
Group
X-A-Wwc
T-Server
X-Region-Sid
X-Request-UUID
X-External-Request-Id
X-CF-Lambda-Version
AsisCache
BehaviorPad-Version
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Meta-Geo-Continent
Content-Script-Type
X-GeoIP-Country-Code
GEO-REGION-INFO
X-DPWN-IS-SECURE
Fastcgi-X-Cache-Version
Content-Style-Type
Apple-News-Services-Handled
Mobile-Detection-Method
Rendered-Blocks
X-D
X-Connection-Hash
X-Varnish-Beresp-Ttl
X-Geo-Header
X-Date
MD5-Digest
X-Destination
X-PHP-Host
X-Labrador-Cache-Channel
X-Cache-Time
X-CF-Lambda-Fn
X-Rocket-Build-Number
Xc-Version
X-VG-WebServer
X-ARC
X-Application
X-Varnish-Beresp-Status
X-A-Ccd
X-Transaction
VIX-Pulpo-Upstream-Status
X-Vtex-Processado-Em
X-Aed
Cf-Ipcountry
W
X-Vtex-Remote-Cache
Viewtype
X-B-Cookie
X-Trv-Group
X-SRCache-Key
X-Session-Fingerprint
X-Sigma
VIX-Pulpo-Node
X-ScT
X-S-Cookie
X-Accel-Expires-Debug
X-A
X-Sigma-Backend
VivaBuild
X-Twitter-Response-Tags
X-A-Dam
X-VG-WebCache
X-Vdms-Version
X-VG-TLSProxy
X-Varnish-Beresp-Grace
Geo-Info
Cache-Hits
Ohc-File-Size
X-C
User-Cache-Control
HA-Ipaddr
X-OVcl-Cache
X-Eu-Site
Ha-Gx-Prefs
X-Distil-CS
IsBot
Fastly-Soc-X-Request-Id
X-OVcl
X-Backend-State
X-Wikidot-Static-Cache
Environment
X-Hit
Countrycode
CDCHOST
X-Bip
X-VC-Cache
Fastly-SWR
Fastly-SIE
X-Wikidot-Backend
X-WebServer
X-CUA
X-Cache-Debug
X-CGP
X-Cdn-Srv
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Agile-Age
X-Agile
X-Var-Ttl
X-Thanos
X-App-Name
Powered-By
X-Developers
X-SIPLIST1
X-Logging-Id
X-Agile-Id
X-Clientip
X-TrackingId
Locid
X-Cache-Expired-At
X-Tec-Api-Origin
X-Tec-Api-Root
X-Tec-Api-Version
X-GoCache-CacheStatus
X-Dispatcher-Server
X-Core-Mission
X-Debug-Cookies
X-BBXSRF
X-Azure-Ref
X-Clara-WADP
X-Cache-Bucket
X-Cache-Info
X-Cache-Tags
X-Distributor
X-Epic-Correlation-Id
X-Block-Status
X-Cache-URL
X-Request-URI
X-We-Are-Hiring
X-WADP-Cache
X-Webstats-RespID
Gh-Request-Id
Server-Cache-Control
Locale
X-VServer
X-Variation
X-Swa-Ws
X-Servername
X-TH-Server
X-Trace-Id
X-Up
Server-Surrogate-Control
X-Auto-Login
X-Varnish-Authentication
X-Urbn-Site-Id
AKAMAI
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Urbn-Context-Path
X-JWT-State
X-Cms-Context
X-Cache-ASPX
X-Contensis-Viewer-Groups
X-Has-Esi
X-Is-Gdpr
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Instart-Isnd
X-IN-APIGATEWAYSSL
X-Irp-Debug
X-Li-Fabric
X-LI-Proto
X-Li-Pop
X-IN-APIGATEWAY
X-Hnp-Log
X-Gen-Mode
X-Fetched-On
X-Generated-In
X-GeoIP-City
X-Hash
X-LI-UUID
X-Micro-Cache
X-Origin-Expires
X-Origin-Date
X-Owner
X-Platform-Server
X-Proxy-Upstream
X-NX-Host
X-NU-AKA-ACS-Version
X-Ms-Version
X-Ms-Request-Id
X-Nginx-Cache-Key
X-No-Session
X-NodeID
X-Fastly-Cache
X-Debug-Log
Pragrma
Platform
Memcached
Request-Country
Request-EU
RNT-Time
RNT-Machine
Mail-Subject
Kp-EeAlive
Cache-Host
Adler-Geo
X-Nc
Country-Code
Fastly-Backend-Name
IBM-Web2-Location
Heartbleed
Server-ID
Is-Eu
X-Air-Hostname
V-Age
We-Hiring
Server-Int
True-Client-Country-4JS
Web-Mar-Node
X-Edge-Location
S-Cnection
Fastly-SSL
X-Server-W
X-TT-LOGID
X-Thinkindot-L3
Wxu-Next-Region
Wxu-Next-Hostname
FNAC-ModuleRouting
Wxu-Next-Commit
Server-Host
X-Tumblr-Pixel-3
X-Matched-Rule
X-Trafficlayer-App-Name
X-Debug-Cache-Store
X-Generation-Time
X-Level-Front-Cache
X-NC
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
X-Req
X-AK-Request-ID
X-ServiceProvider
Thinkindot-Control
X-Service
PFcat
Thinkindot-CacheControl-Type
X-Core-Value
ServerName
X-Gamma-Serve
Thinkindot-CacheControl
Cdnsip
Cdncip
X-Trafficlayer-App-Scope
X-Reboot
X-Generated-On
Ohc-Cache-HIT
X-Trafficlayer-App-Version
X-FW-Version
X-VHOST
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Object-Type
X-Oss-Request-Id
X-Old-Content-Length
X-Response-By
X-App-Version
X-Varnish-Cacheable
X-Lb-Id
X-SERVER
X-UPSTREAM-Address
X-Sucuri-ID
X-Wa
X-S-Maxage
X-Refresh
X-Nginx-Cache
User-Agent
X-NWS-UUID-VERIFY
X-Node-Id
X-CSRF-TOKEN
RequestId
Powered-By-ChinaCache
X-Render-Time
X-Developer
X-Cache-Status-Check
Hostname
X-Cache-Backend
X-Parent-Response-Time
X-Device-Os
X-Cache-Grace
X-Sn-Servicetimems
X-User
X-Cdn-Origin
X-CF-Powered-By
X-LAGOON
X-Ocache
X-Key
Origin
X-Internal-Host
X-Sucuri-Cache
X-Pf-Uncompressing
A
X-Tb-Optimization-Total-Bytes-Saved
On-Server
X-Pjax-Url
X-CSRF-Token
X-MSEdge-Flight
X-Request-Host
Cloudfront-Viewer-Country
Geoip-City
X-Location
X-MSEdge-Features
X-Via-CDN
Geoip-Latitude
X-TA-CDN-Provider
Memory
SRV
X-NGINX-Cache
X-Ua
PICS-Label
GeoIp-Country-Code
X-COUNTRY
ProcessTime
X-TIME
X-B3-Parentspanid
XServer
X-Varnish-URL
TTL
X-Litespeed-Cache
X-Webkit-CSP
Resin-Trace
X-Cdn-Forward
X-Servedbyhost
X-BACKEND-TTL
X-Vcl-Version
X-Server-IP
X-Varnish-Ttl
X-HS-Status
M-TraceId
X-Rocket-Nginx-Bypass
Dnion-Transfer-Encoding
Tcn
SN
X-Dynatrace-Js-Agent
X-Slack-Backend
X-FORWARDED-FOR
X-Unique-ID
Cdn
Media-Length
X-Cdn-Request-ID
Host-ID
X-Server-Time
X-Processor
X-PAYTM-SRV-ID
Arc-Country
Pramga
X-Cache-FS-Status
X-Dispatch
X-B3-SpanId
X-Ratelimit-Remaining
CACHE
X-Fastly-Country-Code
X-Action
X-Beluga-Cache-Status
X-ServedByHost
X-Skip-Cache
X-ND-Cache
X-VCL-Version
X-Beluga-Status
X-Beluga-Trace
X-Beluga-Response-Time
X-Cache-Ttl
X-Beluga-Node
X-Beluga-Record
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
Section-Io-Origin-Status
HostName
Section-Io-Id
X-DC
X-RPS
X-RPM
X-RSL
Cdn-Request-Time
X-DW
X-DSS
X-Served-From
Cdn-Host
Fastly-Drupal-HTML
X-DI
Ttl
Who
X-DB
X-Edge-Server
X-Ruxit-Js-Agent
Fusion-Deployment-Id
MIME-Version
X-Correlation-ID
X-DevSite-Last-Modified
X-Via-Ucdn
N-Cache
X-ABtesting
X-Flog
X-Hello
GeoIP-Country-Code
X-Reqid
Pics-Label
X-Adobe-Source
X-Bc-Bl
X-Oracle-Dms-Rid
X-LiteSpeed-Cache-Control
NtCoent-Length
CF-Cached-On
X-Backend-Host
Esi-Enabled
GeoIP-City
X-Varnish-Url
X-VarnishDD-TTL
X-AIR-PT
GeoIP-Latitude
Cache-Cookie-Set-Lfrom
X-Planisys-CDN-Rules
X-APP
X-Policy
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
X-Ratelimit-Limit
X-Bc
X-Zone
Cache-Cookie-Set-Idcheck
X-PJAX-URL
Cache-Cookie-Set-From
X-PF-Uncompressing
X-Sucuri-Id
X-FPC
X-HostName
Trailer
WebServer
X-SRV
X-Request-Start
X-Scheme
X-Azure-Ref-OriginShield
X-Fmm-Version
Cteonnt-Length
X-Fastly-Backend-Reqs
Amp-Access-Control-Allow-Source-Origin
X-Fastly-Request-Id
X-Amzn-Remapped-Date
X-Amzn-Remapped-Connection
X-Fpc
X-BE
Processtime
Rt-Proxy-Cache
X-Dynatrace
X-Newrelic-App-Data
Servername
CF-IPCountry
X-Swift-Error
FSS-Proxy
Requestid
X-BC
FSS-Cache
Magicmarker
X-ZONE
X-ID
X-WA
X-Cache-Id
Lb
X-SN
X-Esi-Check
Cache-Provider
X-Frame-Option
X-WR-MODIFICATION
X-StackifyID
Dynatrace
X-Gzip
X-SD-PageType
X-Cache-NGX
Release
SD-X-WS
Sid
Load-Balancing
X-Method
X-Branch-Name
X-Snapshot-Date
CDN
X-LB-ID
X-CACHE-AGE
X-Fastly-Cache-Hits
V-Cache
L
X-Cc-Via
X-Compress-Hint
X-Cc-Req-Id
X-Configured-By
X-ECACHE
X-VCT
X-Request-Url
X-Wix-Viewer-Type
X-Instart-Info
X-SB
X-VC
WZWS-RAY
D-Cc-Upstream
X-Tid
Warning
X-Aicache-OS
X-Node-ID
DataCenter
X-Litespeed-Cache-Control
Request-Time
SID
X-Request-URL
X-Worker
X-Nananana
X-Check-Cacheable
Proxy-Firewall
X-GEO
X-Apw-Access-Action
X-App
Ohc-Response-Time
X-Powered-Y
Cneonction
X-WPE-Loopback-Upstream-Addr
X-Varnish-Beresp-TTL
X-Fastly-Cache-Status
WP-Super-Cache
X-Apw-Hits
X-Apw-Access-Token
X-Apw-Access-Object
X-ElasticPress-Search