Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
CF-RAY
Link
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Request-ID
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-DNS-Prefetch-Control
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
Status
Upgrade
X-Content-Security-Policy
X-CDN
Content-Encoding
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Xss-Protection
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
X-Pass-Why
X-Cache-Group
Xkey
X-AH-Environment
P3p
X-Envoy-Upstream-Service-Time
X-Via
X-Backend
CF-Ray
X-Server
X-Age
X-Ua-Compatible
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Ws-Request-Id
X-Server-Powered-By
X-Page-Speed
X-Pingback
EagleId
X-Proxy-Cache
X-Hacker
X-UA-Device
X-Nginx-Cache-Status
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
Cf-Railgun
Grace
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Amz-Version-Id
Report-To
X-LiteSpeed-Cache
X-Rq
X-OneAgent-JS-Injection
X-WebKit-CSP
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Server-Id
X-Device
X-Host
X-Origin-Cache
X-Response-Time
EagleEye-TraceId
X-Node
X-Ac
Surrogate-Control
Content-Location
X-Vhost
X-Readtime
X-Backend-Server
X-Cloud-Trace-Context
Request-Id
X-Dispatcher
X-Origin-Upstream-Status
X-Cnection
X-Application-Context
X-HW
X-Cache-Lookup
X-ORACLE-DMS-ECID
Fusion-Template-Id
Fusion-Content-Source
Fusion-Source
Fusion-Component-Id
Fusion-Content-Id
X-Ruxit-JS-Agent
X-ORACLE-DMS-RID
X-DataDome
X-Mod-Pagespeed
NEL
X-Rack-Cache
Rating
Edge-Control
X-Country
X-Clacks-Overhead
X-Akam-SW-Version
X-Dns-Prefetch-Control
Pinterest-Generated-By
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-TTL
Allow
X-Country-Code
Accept-Ch
X-DynaTrace
X-FTR-Request-ID
X-Instart-Request-ID
X-Varnish-TTL
X-Goog-Hash
X-Vname
X-PC
X-TtlSet
X-ESI
Verso
Accept-Ch-Lifetime
Content-MD5
Service-Worker-Allowed
X-Powered-By-Plesk
X-Url
X-B3-TraceId
X-Forwarded-Proto
X-MS-InvokeApp
X-Version
X-Kinja-Build
X-Kinja-Revision
X-Kinja-Server
X-GoogleNews-Bot
X-Kinja
X-Cdn-Fetch
X-Exp-Id
X-Exp-Variant
X-Use-Magma
X-GitHub-Request-Id
RTSS
Edge-Cache-Tag
X-Server-Name
X-D2id
X-Abt-Application-Version
X-Debug
X-Px
AR-Request-ID
AR-PoweredBy
X-Vcache
AR-CACHE
AR-ATIME
Ar-Sid
X-Amz-Server-Side-Encryption
SPRequestGuid
Charset
X-NF-Request-ID
X-Cached
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Fastcgi-Cache
X-TEC-API-ORIGIN
X-Middleton-Response
X-Accel-Expires
Pagespeed
Display
X-Sol
Response
X-Middleton-Display
X-Vcap-Request-Id
X-MSEdge-Ref
X-Navigation-Version
X-Amz-Rid
Arr-Disable-Session-Affinity
Pinterest-Version
X-Pinterest-Rid
X-SharePointHealthScore
TCN
X-Powered-CMS
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-VARITI-CCR
X-Trace
Public-Key-Pins
Cache-Tag
Realpath
X-Client-IP
X-Fastly-Request-ID
X-Cdn
MS-Author-Via
Nginx-Cache
Access-Control-Request-Method
X-Ser
X-Edge-O15-RID
X-DynaTrace-JS-Agent
X-Shard
Nel
X-Mrf-Item-Lastmod
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Mrf-Section-Lastmod
S
X-Server-ID
SPRequestDuration
X-Upstream
SPIisLatency
X-Content-Type
X-Id
X-Ezoic-Cdn
X-Amzn-Trace-Id
X-Hp-Webp
X-Grace
X-Forwarded-For
X-T
X-Amz-Meta-S3cmd-Attrs
Front-End-Https
X-Hits
Fastcgi-Cache
X-Recruiting
X-Jurisdiction
DynaTrace
X-Cache-TTL
X-Aspnet-Version
X-Varnish-Age
ServerID
MicrosoftSharePointTeamServices
X-Element-Page-Cache
X-Content-Digest
X-Mobile-URL
X-Node-Name
X-FTR-Cache-Status
X-FTR-Realm
X-DIS-Request-ID
X-FTR-Expires
X-FTR-Balancer
X-Country-Code-Real
X-FTR-Backend
X-FTR-Backend-Server
X-Dw-Request-Base-Id
X-FTR-DC
NR-ENABLED
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Hub-Id
X-Goog-Generation
X-Frontend
Powered
X-Goog-Metageneration
X-Goog-Stored-Content-Length
Server-Node
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-GUploader-UploadID
TP-Cache
TP-L2-Cache
Alternate-Protocol
X-Logged-In
Server-Name
X-CST
AMP-Access-Control-Allow-Source-Origin
X-Amzn-RequestId
X-Amz-Apigw-Id
Upgrade-Insecure-Requests
X-Request-Received
X-Request-Processing-Time
X-Correlation-Id
X-Request-Handler-Origin-Region
X-Microsite
X-ATS-Timestamp
Backend-Timing
X-Cache-Hit
X-XRDS-Location
Fastly-Restarts
X-Content-Options
X-F-Cache
X-Content-Security-Policy-Report-Only
X-User-Agent
X-Origin-Server
Refresh
X-Akamai-Edgescape
X-Revision
X-Page-Id
X-Rid
X-Zen-Fury
X-Varnish-Grace
X-Type
X-XRDS-LOCATION
X-Content-Powered-By
X-LB-Cache
X-B
X-FTR-Cache-Host
X-B3-Sampled
PB-PID
PB-RID
X-Geo-Country
Arc-Version
X-Mobile-Rewrite
X-Az
X-Activity-Id
X-AppVersion
Cache-Status
X-URL
X-Kinsta-Cache
X-N
X-Cache-Age
X-TT
X-Signature
X-Time
X-Cache-Action
X-Pad
X-WebKit-CSP-Report-Only
X-Instance
X-Shield-Request-Id
X-AOL-HN
X-B-Cache
Access-Control-Allow-Method
X-Debug-Info
X-Tumblr-Pixel-0
X-Tumblr-User
Paypal-Debug-Id
Actual-Object-TTL
X-Tumblr-Pixel
X-Jobs
X-App-Environment
X-FB-Debug
X-PHP-Backend
X-Request-Guid
X-Load-Cache
X-Framework
X-Cached-By
X-Git-Hash
DC
Fastcgi-Useragent
X-RateLimit-Remaining
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Varnish-Backend
X-Amz-Replication-Status
Surrogate-Key
X-Webkit-Csp
X-Erf-Bev-Bev
X-IPLB-Instance
X-Erf-Bev-Bev-Is-Generated
Host-Header
X-Contextid
MS-CV
X-Webapp-Samesite-None-Activated-N
X-ATG-Version
Host
X-WA-Info
X-Analytics
X-NWS-LOG-UUID
X-SS-Set-Cookie
X-ORACLE-APMCS-REQUEST-ID
X-ORACLE-APMCS-TAG
X-Mobile
X-Cluster
X-Response-Served-From
X-Accel-Buffering
X-Via-JSL
Tracecode
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
NGB
FilterID
Payment
WPE-Backend
X-Host-Name
Xserver
X-Cache-NE
X-Cache-2
Source
Eomportal-Instance
X-FW-Server
X-Varnish-Server
X-FW-Hash
X-Region
X-FW-Type
X-FW-Serve
X-FW-Static
X-Varnish-Hostname
X-Origin-Response-Time
X-Tumblr-Pixel-2
X-IPS-LoggedIn
X-GeoIP
Frame-Options
Cache-Tv-Group
X-Tumblr-Pixel-1
Filters
X-Cache-Enabled
X-Presslabs-Stats
X-Cacheable-TTL
X-Adobe-Loc
X-Adobe-Content
X-Srv
X-Cache-Operation
X-Is-Bot
X-Seen-By
X-RequestSource
X-Rendered-As
X-Hostname
X-Cache-Rule
Retry-After
X-Cache-Key
X-EdgeConnect-Cache-Status
X-TX-ID
X-NewRelic-App-Data
Server-Info
X-Cache-TTL-Remaining
Liferay-Portal
X-RemovedCookies
X-ProcessESI
Cleartype
X-FastCGI-Cache
X-CACHE-KEY
X-VCache
X-Dc
Accept-CH
X-App-Server
X-B3-Traceid
X-RTag
X-L-Path
X-Environment-Context
Ms-Operation-Id
X-Source
X-UA
X-FireWall-Port
Datacenter
X-HTML-Minification-Powered-By
X-Endurance-Cache-Level
X-Handled-By
X-Upgrade-Enabled
X-Cache-Server
From-Origin
X-CLOUD-TRACE-CONTEXT
Cache
X-Backend-Name
X-Cache-Control
X-APP-VERSION
Accept-CH-Lifetime
X-Wix-Request-Id
Healthy
Accept-Charset
X-ES-SERVER
X-RN-RSRV
X-Cache-Var
X-Cache-Var-Map
Meta-Geo
X-PressLabs-Stats
X-Path-Route
X-Status
X-Timing-Wait
X-Tb
X-UUID
X-Section
Selected-Fe
X-Access
OT-Force-Account-Verify
X-Proxy-Build
Srv
Version
X-Format
X-ShardId
X-Request-Time
X-Shopify-Stage
Azure-SiteName
X-Sorting-Hat-ShopId
X-EIG-Tracking-Id
Mn-Server-Ip
X-FC-Vary-Parameters
Akamai-GRN
X-Akamai-Request-ID
X-Alternate-Cache-Key
X-ShopId
X-Shopify-Generated-Cart-Token
X-Cache-Config
Azure-InstanceId
X-Proto
X-Origin
Cache-Tags
Azure-Version
X-Content-Age
Azure-SlotName
X-Sorting-Hat-PodId
X-OCL
Azure-RegionName
X-Goog-Meta-Goog-Reserved-File-Mtime
X-NYM-Debug-Backend
X-PCL
Origin-Cache-Control
Node
Now
X-LJ-Flow-ID
X-Hyper-Cache
NGX
Decoy-Debug-Key
X-JoinUs
Decoy-Debug-Status
X-Say-Cacheable
DB-Nickname
Ec-Rule-Version
X-Proxy-Cache-Status
X-Redis-Cache
X-ProxyCache-Key
X-VWS-Id
X-SayCDN-TTL
X-Qloud-Router
X-Cluster-Node
X-Web-Node
X-Debug-Cache
X-Vgn-Hpd-Reason
X-Say-TTL
X-SaId
X-Soup
X-FW-Dynamic
X-Generated-By
X-Hosted-By
X-ServerID
X-ProxyCache-Status
X-Akamai-Request-ID2
Origin-Edge-Control
X-AWS-Id
X-Hl-Ver
X-Time-Microsecs
X-Viewer-Country
X-Pubstack
X-BYPASS-REASON
X-Proxy
X-Human
Decoy-Debug-TTL
X-Yottaa-Optimizations
X-Storage
X-RateLimit-Limit
X-Yottaa-Metrics
GEO-INFO
TWC-Connection-Speed
TWC-Locale-Group
TWC-Device-Class
X-Rule
X-CCM
TWC-GeoIP-Country
X-BCube-Filmed-By
X-Amzn-Remapped-Content-Length
Property-Id
Webcakes-App-Name
Webcakes-App-Version
TWC-GeoIP-LatLong
Webcakes-Region
TWC-Privacy
X-TNCMS
X-Origin-Hint
X-MP-GENERATED-AT
X-Www-Served-By
X-Site-Version
X-Varnish-Hits
X-Generated
X-Loop
X-FB-TRIP-ID
Cross-Origin-Window-Policy
X-RCS-CacheZone
X-Xfnlog-Site
X-Akamai-Transformed
S-Rt
X-R9-Blue-Green-Version
X-Locale
X-NCache
X-Cache-Host
X-IP
X-Detected-As
L5d-Success-Class
X-Drupal-Cache-Tags
X-CS
X-Unique-Id
Webserver
Cache-Name
Cache-Key
Time
Viewport
Uber-Trace-Id
X-Esi
X-UA-Device-Type
X-Mode
Mime-Version
X-Forwarded-Host
X-UnsetCookies
X-Daa-Tunnel
X-Origin-CC
X-Origin-TTL
Accept-Language
X-Whom
X-Cache-Remote
X-Backend-TTL
X-Info
Rt-Fastcgi-Cache
Content-Disposition
Country
X-NGENIX-Cache
X-CDN-Forward
X-Varnish-Cache-Hits
X-From
X-PERF
Odigeo-Trace-Id
X-ApacheServer
X-B3-Spanid
ServedBy
X-Cluster-Name
X-Newrelic-Synthetics
X-Magnolia-Registration
VIX-Pulpo-Node
X-Drupal-Cache-Contexts
Section-Io-Cache
VIX-Pulpo-Upstream-Status
X-Geo
X-EC-Lua
X-Ruxit-Js-Agent
X-Microcachable
X-Zipkin-Id
X-Proxied
X-TT-TIMESTAMP
X-Device-Type
X-Routing-Service
X-Via-Fastly
Ohc-File-Size
X-Uri
Cf-Ipcountry
Ohc-Cache-HIT
X-Ttl
Proxy-Connection
X-Trafficlayer-App-Scope
X-Trafficlayer-App-Name
X-Nc
X-Edge-Location
HitType
X-Application
AsisCache
BehaviorPad-Version
Content-Style-Type
Fastcgi-X-Cache-Version
X-B-Cookie
X-ARC
X-A
Viewtype
Access-Control-Request-Headers
VivaBuild
W
Machine
MD5-Digest
Rendered-Blocks
Mobile-Detection-Method
Meta-Geo-Continent
T-Server
GEO-REGION-INFO
X-A-Ccd
X-A-Dgt
X-A-Wwc
X-Accel-Expires-Debug
X-Aed
Apple-News-Services-Parsed-Url
X-A-Dcw
Apple-News-Services-Handled
Apple-News-Services-Host
X-A-Dam
Apple-News-Services-Request-Url
X-Geo-Header
X-S
X-Rojux
X-S-Cookie
X-ScT
X-Session-Fingerprint
X-CF-Lambda-Fn
X-Rewrite-Enabled
X-GeoIP-Country-Code
Content-Script-Type
X-Region-Sid
X-Request-UUID
X-No-Session
X-Sigma
X-Sigma-Backend
X-VG-WebServer
X-VG-WebCache
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-VG-TLSProxy
X-Vdms-Version
X-SRCache-Key
X-Transaction
X-Trv-Group
X-Twitter-Response-Tags
X-G
X-Rocket-Build-Number
X-D
X-Date
X-Destination
X-DPWN-IS-SECURE
X-CF-Lambda-Version
X-External-Request-Id
X-Connection-Hash
User-Cache-Control
X-Varnish-Beresp-Status
X-Varnish-Beresp-Ttl
Geo-Info
X-UPSTREAM-Address
X-C
X-Varnish-Beresp-Grace
X-Clientip
Fastly-SWR
Gh-Request-Id
Locid
IsBot
HA-Ipaddr
Ha-Gx-Prefs
X-Cache-Debug
X-Wikidot-Backend
X-Wikidot-Static-Cache
Environment
Countrycode
X-WebServer
X-CGP
Fastly-SIE
X-Bip
X-Cache-ASPX
X-VC-Cache
Fastly-Soc-X-Request-Id
Server-Surrogate-Control
X-Agile-Age
X-Eu-Site
X-Agile-Id
X-Distil-CS
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Agile
X-Hit
X-Logging-Id
X-Developers
X-App-Name
Powered-By
X-Tumblr-Pixel-3
X-Contensis-Viewer-Groups
X-CUA
Server-Cache-Control
X-SIPLIST1
X-Thanos
X-TrackingId
X-Varnish-Authentication
X-Auto-Login
X-Real-IP
CDCHOST
Fastly-SSL
X-Cache-Backend
X-GoCache-CacheStatus
Filterid
X-Gen-Mode
X-Gamma-Serve
X-FW-Version
X-Fetched-On
X-Generated-In
X-Fastly-Cache
X-GeoIP-City
X-IN-APIGATEWAYSSL
X-Instart-Isnd
X-Irp-Debug
X-IN-APIGATEWAY
X-Hnp-Log
X-Epic-Correlation-Id
X-Has-Esi
X-Hash
X-Generation-Time
X-Dispatcher-Server
X-Cache-Info
X-Cache-Tags
X-Cache-Time
X-Cache-URL
X-Cache-Bucket
X-Block-Status
X-Azure-Ref
X-Backend-State
X-BBXSRF
X-Cdn-Srv
X-Clara-WADP
X-Debug-Cookies
X-Debug-Log
X-Is-Gdpr
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Cms-Context
X-Core-Mission
X-Debug-Cache-Expiry
X-Distributor
X-Li-Fabric
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Swa-Ws
X-TH-Server
X-Servername
X-Server-W
X-RateLimit-Remaining-Second
X-Render-Time
X-Request-URI
X-Trace-Id
X-TT-LOGID
X-WADP-Cache
X-We-Are-Hiring
X-Webstats-RespID
X-Variation
X-User
X-Up
X-Urbn-Context-Path
X-Urbn-Site-Id
X-RateLimit-Limit-Second
Cdnsip
X-Micro-Cache
X-Ms-Request-Id
X-Ms-Version
X-LI-UUID
X-LI-Proto
X-Labrador-Cache-Channel
X-AK-Request-ID
X-Li-Pop
X-NodeID
X-NU-AKA-ACS-Version
X-Owner
X-PHP-Host
X-Platform-Server
X-OVcl-Cache
X-OVcl
X-NX-Host
X-Origin-Date
X-Origin-Expires
X-JWT-State
X-Proxy-Upstream
Mail-Subject
Memcached
Web-Mar-Node
True-Client-Country-4JS
Kp-EeAlive
IBM-Web2-Location
Is-Eu
We-Hiring
Platform
V-Age
Server-ID
RNT-Time
RNT-Machine
Request-Country
Request-EU
Heartbleed
Locale
Cdncip
Adler-Geo
AKAMAI
Cache-Host
Country-Code
X-Core-Value
X-Level-Front-Cache
Fastly-Backend-Name
X-Req
X-VServer
Server-Int
X-Generated-On
Server-Host
X-Air-Hostname
X-Nginx-Cache-Key
PFcat
Wxu-Next-Commit
ServerName
X-ServiceProvider
X-Service
X-Reboot
X-App-Version
Wxu-Next-Region
FNAC-ModuleRouting
X-Trafficlayer-App-Version
Wxu-Next-Hostname
X-Old-Content-Length
X-S-Maxage
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Thinkindot-Control
X-Matched-Rule
X-Var-Ttl
X-Internal-Host
X-Cache-Expired-At
X-Lb-Id
Cache-Hits
X-Thinkindot-L3
Group
X-Nginx-Cache
S-Cnection
Pragrma
RequestId
X-Key
X-SERVER
X-Refresh
X-Sucuri-Cache
X-Location
X-VHOST
X-CF-Powered-By
X-Response-By
Powered-By-ChinaCache
X-Parent-Response-Time
X-Tb-Optimization-Total-Bytes-Saved
X-TA-CDN-Provider
ProcessTime
X-CSRF-TOKEN
X-Cdn-Forward
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
Origin
X-NC
X-BACKEND-TTL
X-Pjax-Url
X-Wa
X-Correlation-ID
X-B3-Parentspanid
X-Sucuri-ID
User-Agent
X-CSRF-Token
SRV
Memory
X-Varnish-Cacheable
X-Ua
TTL
X-Via-CDN
X-Pf-Uncompressing
X-B3-SpanId
X-Developer
Geoip-Latitude
X-Vcl-Version
X-Server-IP
Geoip-City
X-NWS-UUID-VERIFY
X-NGINX-Cache
X-Unique-ID
X-Cdn-Origin
X-Ocache
X-Sn-Servicetimems
PICS-Label
GeoIp-Country-Code
X-Cache-Grace
X-LAGOON
X-Device-Os
X-Oss-Server-Time
X-Node-Id
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Oss-Request-Id
X-COUNTRY
X-Cache-Status-Check
On-Server
Media-Length
A
X-Request-Host
X-MSEdge-Flight
X-Cdn-Request-ID
X-MSEdge-Features
X-Rocket-Nginx-Bypass
Dnion-Transfer-Encoding
X-Servedbyhost
Hostname
X-Webkit-CSP
M-TraceId
X-Litespeed-Cache
Cloudfront-Viewer-Country
SN
X-Via-Ucdn
X-Varnish-Ttl
XServer
X-TIME
X-Sucuri-Id
X-HS-Status
Tcn
Cdn
X-FORWARDED-FOR
X-AIR-PT
X-ServedByHost
Host-ID
Resin-Trace
X-Reqid
Esi-Enabled
HostName
X-Ratelimit-Remaining
X-Varnish-URL
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Policy
Who
X-Beluga-Node
X-Fastly-Country-Code
X-Beluga-Trace
X-Beluga-Status
X-Beluga-Response-Time
X-Planisys-CDN-TTL
X-Cache-Ttl
X-Beluga-Record
X-Beluga-Cache-Status
CF-Cached-On
X-Slack-Backend
X-Request-Start
X-Azure-Ref-OriginShield
X-Fastly-Backend-Reqs
CACHE
X-Action
Pics-Label
GeoIP-Country-Code
Rt-Proxy-Cache
X-LiteSpeed-Cache-Control
X-Processor
X-Server-Time
X-RSL
X-PAYTM-SRV-ID
X-Cache-FS-Status
X-RPS
Pramga
Arc-Country
X-DW
X-DB
X-Varnish-Url
GeoIP-Latitude
X-DI
X-DSS
X-VCL-Version
X-Dispatch
X-RPM
MIME-Version
X-Ftr-Cache-Host
X-Oracle-Dms-Rid
Ttl
X-ND-Cache
X-Hello
X-ABtesting
X-Flog
X-Zone
X-Method
X-APP
X-PF-Uncompressing
NtCoent-Length
GeoIP-City
X-Skip-Cache
X-Bc
Magicmarker
X-DC
X-Served-From
Cdn-Host
X-FPC
Fastly-Drupal-HTML
Cdn-Request-Time
X-Edge-Server
Cteonnt-Length
X-Newrelic-App-Data
X-VarnishDD-TTL
X-Ratelimit-Limit
X-HostName
Amp-Access-Control-Allow-Source-Origin
N-Cache
WebServer
X-DevSite-Last-Modified
X-PJAX-URL
X-Bc-Bl
X-SRV
Section-Origin-Responded
Section-Io-Origin-Status
Section-Io-Id
Section-Io-Origin-Time-Seconds
X-Dynatrace
X-Be
X-BE
Ohc-Response-Time
X-Svr
X-Amzn-Remapped-Date
Processtime
X-Amzn-Remapped-Connection
X-Backend-Host
X-Swift-Error
Servername
Load-Balancing
X-Dynatrace-Js-Agent
X-BC
X-ZONE
Cache-Provider
Vix-Hermes-Req-Id
X-ID
X-WA
X-Aicache-OS
X-WR-MODIFICATION
X-Frame-Option
DSUID
CDN
X-Fastly-Cache-Hits
X-Adobe-Source
Cache-Cookie-Set-Idcheck
Lfy
Pagetype
Dynatrace
X-Snapshot-Date
X-LB-ID
Requestid
X-Branch-Name
X-MServer
Cache-Cookie-Set-From
X-Fmm-Version
Cache-Cookie-Set-Lfrom
CF-IPCountry
FSS-Proxy
FSS-Cache
X-StackifyID
Trailer
Fusion-Deployment-Id
Release
X-VCT
X-CACHE-AGE
X-Apw-Access-Token
X-Request-Url
X-Apw-Access-Object
X-Apw-Access-Action
Proxy-Firewall
X-Scheme
X-Hp-Ccpa-Warning
X-Configured-By
V-Cache
Warning
X-Cc-Via
X-Cc-Req-Id
X-VC
WZWS-RAY
D-Cc-Upstream
X-Tid
X-SB
X-Apw-Hits
X-Litespeed-Cache-Control
X-Node-ID
Cneonction
X-Check-Cacheable
X-Upstream-Ct
X-Upstream-Ht
X-SD-PageType
X-Powered-Y
X-Fpc
X-Request-URL
X-WPE-Loopback-Upstream-Addr
X-ElasticPress-Search
SD-X-WS
X-App
X-Edge-IP
Correlation-Id
Backend-Name
X-Varnish-Beresp-TTL
WP-Super-Cache
X-Fastly-Cache-Status
X-Worker