Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
CF-RAY
Link
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Request-ID
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-DNS-Prefetch-Control
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
Status
Upgrade
X-Content-Security-Policy
X-CDN
Content-Encoding
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Xss-Protection
X-Kinja-Server-Push
Keep-Alive
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
P3p
X-Pass-Why
Xkey
X-Cache-Group
X-AH-Environment
X-Envoy-Upstream-Service-Time
CF-Ray
X-Via
X-Backend
X-Ua-Compatible
X-Server
X-Age
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Server-Powered-By
X-Page-Speed
X-Ws-Request-Id
X-Pingback
EagleId
X-Hacker
X-Proxy-Cache
X-Nginx-Cache-Status
X-UA-Device
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
Cf-Railgun
Grace
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Amz-Version-Id
Report-To
X-LiteSpeed-Cache
X-Rq
X-OneAgent-JS-Injection
X-Styx-Req-Id
X-WebKit-CSP
X-Pantheon-Styx-Hostname
X-Server-Id
X-Device
X-Host
X-Origin-Cache
EagleEye-TraceId
X-Response-Time
X-Ac
X-Node
Surrogate-Control
Content-Location
X-Vhost
X-Cloud-Trace-Context
X-Readtime
X-Backend-Server
Request-Id
X-Dispatcher
X-Origin-Upstream-Status
X-Cnection
X-Application-Context
X-HW
X-Cache-Lookup
X-ORACLE-DMS-ECID
Fusion-Source
Fusion-Content-Source
Fusion-Content-Id
Fusion-Component-Id
Fusion-Template-Id
X-Ruxit-JS-Agent
X-ORACLE-DMS-RID
X-DataDome
X-Mod-Pagespeed
NEL
X-Dns-Prefetch-Control
X-Rack-Cache
Rating
Edge-Control
X-Country
X-Clacks-Overhead
X-Akam-SW-Version
Pinterest-Generated-By
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-TTL
Allow
X-Country-Code
X-DynaTrace
X-FTR-Request-ID
X-Instart-Request-ID
X-Varnish-TTL
X-Goog-Hash
X-TtlSet
X-Vname
X-PC
Accept-Ch
Verso
X-ESI
Service-Worker-Allowed
Content-MD5
X-Powered-By-Plesk
Accept-Ch-Lifetime
X-Url
X-Forwarded-Proto
X-Version
X-MS-InvokeApp
X-B3-TraceId
X-Exp-Variant
X-Kinja-Revision
X-Kinja
X-GoogleNews-Bot
X-Cdn-Fetch
X-Exp-Id
X-Kinja-Build
X-Kinja-Server
X-Use-Magma
X-GitHub-Request-Id
RTSS
Edge-Cache-Tag
X-Abt-Application-Version
X-Debug
X-D2id
X-Px
AR-Request-ID
AR-CACHE
AR-PoweredBy
Ar-Sid
AR-ATIME
X-Amz-Server-Side-Encryption
X-Vcache
SPRequestGuid
Charset
X-Server-Name
X-NF-Request-ID
X-Cached
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Middleton-Response
Pagespeed
Display
X-Sol
Response
X-Accel-Expires
X-Middleton-Display
X-Vcap-Request-Id
X-MSEdge-Ref
X-Amz-Rid
Arr-Disable-Session-Affinity
X-Navigation-Version
X-Pinterest-Rid
Pinterest-Version
X-Powered-CMS
X-Fastcgi-Cache
TCN
X-SharePointHealthScore
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Cdn
X-Trace
X-VARITI-CCR
Cache-Tag
Public-Key-Pins
Realpath
X-Client-IP
X-Fastly-Request-ID
Access-Control-Request-Method
X-Ser
Nginx-Cache
MS-Author-Via
X-Shard
X-DynaTrace-JS-Agent
S
Mrf-Cache-Status
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
MRF-Tech
X-Mrf-Item-Lastmod
X-Edge-O15-RID
SPRequestDuration
X-Id
SPIisLatency
X-Upstream
X-Content-Type
X-Hp-Webp
X-Ezoic-Cdn
X-Grace
X-Amzn-Trace-Id
X-T
X-Amz-Meta-S3cmd-Attrs
Nel
Front-End-Https
X-Recruiting
X-Hits
X-Forwarded-For
Fastcgi-Cache
X-Aspnet-Version
X-Jurisdiction
DynaTrace
X-Varnish-Age
ServerID
X-Server-ID
X-Cache-TTL
X-Element-Page-Cache
X-Node-Name
X-Mobile-URL
X-Content-Digest
X-DIS-Request-ID
MicrosoftSharePointTeamServices
X-FTR-Cache-Status
X-FTR-Realm
X-FTR-Expires
X-FTR-DC
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Backend
X-FTR-Balancer
NR-ENABLED
X-Dw-Request-Base-Id
X-HS-Combine-CSS
Powered
X-Goog-Generation
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-HS-Cache-Config
X-HS-Hub-Id
Server-Node
X-HS-Content-Id
X-Frontend
TP-Cache
TP-L2-Cache
Alternate-Protocol
Server-Name
X-Logged-In
X-Correlation-Id
X-CST
AMP-Access-Control-Allow-Source-Origin
X-Request-Processing-Time
X-XRDS-Location
X-Request-Received
Upgrade-Insecure-Requests
X-Request-Handler-Origin-Region
X-Amz-Apigw-Id
X-Microsite
X-Amzn-RequestId
X-ATS-Timestamp
Backend-Timing
X-Cache-Hit
X-F-Cache
Refresh
X-Content-Options
X-Content-Security-Policy-Report-Only
X-Origin-Server
X-Page-Id
X-User-Agent
Fastly-Restarts
X-Zen-Fury
X-Akamai-Edgescape
X-Revision
X-Rid
X-Varnish-Grace
X-Type
X-Content-Powered-By
X-XRDS-LOCATION
X-LB-Cache
X-B
X-B3-Sampled
X-FTR-Cache-Host
X-URL
X-Geo-Country
PB-PID
PB-RID
X-Az
X-Activity-Id
X-AppVersion
Arc-Version
X-Mobile-Rewrite
Cache-Status
X-Kinsta-Cache
X-N
X-Cache-Age
X-Shield-Request-Id
X-Cache-Action
X-WebKit-CSP-Report-Only
X-TT
X-Instance
X-B-Cache
X-Signature
X-AOL-HN
X-Pad
Paypal-Debug-Id
X-Debug-Info
Actual-Object-TTL
Access-Control-Allow-Method
X-Framework
X-Tumblr-Pixel
X-Jobs
X-FB-Debug
X-Load-Cache
X-Tumblr-Pixel-0
X-Tumblr-User
X-Time
X-PHP-Backend
X-Request-Guid
X-Cached-By
X-App-Environment
DC
X-Git-Hash
Fastcgi-Useragent
X-Tt-Trace-Tag
X-RateLimit-Remaining
X-Webkit-Csp
X-Tt-Trace-Host
X-Varnish-Backend
X-Amz-Replication-Status
Surrogate-Key
X-Webapp-Samesite-None-Activated-N
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
Host-Header
X-IPLB-Instance
MS-CV
X-Contextid
X-Analytics
FilterID
X-ATG-Version
X-SS-Set-Cookie
X-WA-Info
X-FastCGI-Cache
Host
Accept-CH
X-Cache-Key
X-NWS-LOG-UUID
X-Mobile
X-Response-Served-From
X-ORACLE-APMCS-TAG
X-ORACLE-APMCS-REQUEST-ID
X-Cluster
X-Accel-Buffering
Tracecode
X-Host-Name
Payment
X-Via-JSL
NGB
X-Cache-NE
WPE-Backend
X-Kong-Proxy-Latency
X-B3-Traceid
X-FW-Static
X-Cache-2
X-FW-Server
X-FW-Serve
X-FW-Type
X-Kong-Upstream-Latency
X-Region
X-FW-Hash
Frame-Options
Eomportal-Instance
X-Tumblr-Pixel-1
Source
Cache-Tv-Group
X-Tumblr-Pixel-2
X-Varnish-Server
X-Origin-Response-Time
Xserver
X-Adobe-Content
X-Cacheable-TTL
X-Varnish-Hostname
X-Adobe-Loc
X-IPS-LoggedIn
X-Seen-By
X-Rendered-As
X-Is-Bot
X-Cache-Enabled
X-Cache-Operation
X-GeoIP
X-Cache-Rule
X-Srv
Filters
X-TX-ID
X-Hostname
Retry-After
X-Presslabs-Stats
X-RequestSource
X-EdgeConnect-Cache-Status
X-NewRelic-App-Data
Accept-CH-Lifetime
Server-Info
X-VCache
X-Cache-TTL-Remaining
Cleartype
X-ProcessESI
X-RemovedCookies
Liferay-Portal
Ms-Operation-Id
X-RTag
X-App-Server
X-L-Path
X-Environment-Context
X-Source
Datacenter
X-HTML-Minification-Powered-By
X-FireWall-Port
X-UA
X-Dc
X-Endurance-Cache-Level
X-Handled-By
X-Upgrade-Enabled
From-Origin
Cache
X-Cache-Server
X-CACHE-KEY
X-Esi
X-APP-VERSION
X-Cache-Control
X-Backend-Name
Srv
X-PressLabs-Stats
X-Wix-Request-Id
Healthy
X-ES-SERVER
X-Cache-Var
X-RN-RSRV
Meta-Geo
X-Cache-Var-Map
X-Path-Route
X-Tb
X-Access
Version
X-Status
OT-Force-Account-Verify
X-Section
Accept-Charset
X-Format
X-UUID
Akamai-GRN
Azure-InstanceId
Azure-SlotName
Azure-Version
Azure-SiteName
Azure-RegionName
Cache-Tags
Selected-Fe
X-Origin
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Request-Time
X-Akamai-Request-ID
X-Timing-Wait
X-Proxy-Build
X-FC-Vary-Parameters
X-Proto
X-OCL
X-NYM-Debug-Backend
X-Cache-Config
X-Content-Age
X-PCL
X-Redis-Cache
X-Viewer-Country
X-Pubstack
X-Qloud-Router
X-Web-Node
DB-Nickname
X-Sorting-Hat-ShopId
X-Say-TTL
X-ShopId
X-ShardId
X-SayCDN-TTL
X-ServerID
X-Say-Cacheable
X-SaId
Decoy-Debug-Status
X-Sorting-Hat-PodId
X-Shopify-Stage
X-Shopify-Generated-Cart-Token
X-Time-Microsecs
X-ProxyCache-Key
X-Hl-Ver
Origin-Cache-Control
X-Hosted-By
X-Human
X-FW-Dynamic
Origin-Edge-Control
X-Alternate-Cache-Key
X-BYPASS-REASON
X-EIG-Tracking-Id
Now
X-Hyper-Cache
Mn-Server-Ip
X-ProxyCache-Status
Ec-Rule-Version
NGX
X-Proxy-Cache-Status
X-JoinUs
Node
X-Proxy
Decoy-Debug-TTL
Decoy-Debug-Key
X-Storage
X-Rule
X-RateLimit-Limit
X-TNCMS
Cross-Origin-Window-Policy
X-MP-GENERATED-AT
X-Cluster-Node
X-Generated
X-Soup
X-Varnish-Hits
X-Site-Version
X-Vgn-Hpd-Reason
X-AWS-Id
X-BCube-Filmed-By
X-Debug-Cache
X-CCM
X-Amzn-Remapped-Content-Length
X-Akamai-Request-ID2
X-VWS-Id
X-Generated-By
X-Loop
X-LJ-Flow-ID
GEO-INFO
Property-Id
TWC-GeoIP-LatLong
Webcakes-App-Name
Webcakes-App-Version
Webcakes-Region
TWC-Privacy
TWC-Locale-Group
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-Country
S-Rt
X-Locale
X-R9-Blue-Green-Version
X-Origin-Hint
X-Xfnlog-Site
X-RCS-CacheZone
X-Www-Served-By
X-Akamai-Transformed
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Detected-As
X-FB-TRIP-ID
X-Cache-Host
X-NCache
X-IP
X-Unique-Id
L5d-Success-Class
X-CS
X-Drupal-Cache-Tags
Time
Viewport
Uber-Trace-Id
Webserver
Cache-Key
Cache-Name
X-UA-Device-Type
X-Mode
X-CDN-Forward
X-Forwarded-Host
X-Backend-TTL
Rt-Fastcgi-Cache
X-UnsetCookies
X-Cache-Remote
X-Origin-TTL
Accept-Language
X-Daa-Tunnel
X-Origin-CC
X-Whom
Content-Disposition
X-Info
X-From
Mime-Version
X-NGENIX-Cache
Country
X-Varnish-Cache-Hits
Odigeo-Trace-Id
X-PERF
X-ApacheServer
X-Cluster-Name
X-Ruxit-Js-Agent
X-B3-Spanid
X-CLOUD-TRACE-CONTEXT
VIX-Pulpo-Node
X-Drupal-Cache-Contexts
VIX-Pulpo-Upstream-Status
X-Magnolia-Registration
ServedBy
X-Newrelic-Synthetics
X-Microcachable
X-TT-TIMESTAMP
X-Geo
X-Zipkin-Id
X-Proxied
X-Routing-Service
X-Ttl
X-Device-Type
Section-Io-Cache
X-Via-Fastly
X-Uri
Cf-Ipcountry
X-EC-Lua
Ohc-File-Size
X-Edge-Location
Ohc-Cache-HIT
HitType
X-UPSTREAM-Address
Proxy-Connection
X-Trafficlayer-App-Name
X-Trafficlayer-App-Scope
Content-Script-Type
Content-Style-Type
X-SRCache-Key
BehaviorPad-Version
AsisCache
X-VG-TLSProxy
X-VG-WebCache
Fastcgi-X-Cache-Version
X-VG-WebServer
X-Vtex-Processado-Em
Xc-Version
X-Vtex-Remote-Cache
X-Vdms-Version
X-Twitter-Response-Tags
X-Transaction
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-Trv-Group
Apple-News-Services-Handled
Apple-News-Services-Request-Url
T-Server
X-Connection-Hash
X-D
X-Date
X-Destination
X-S
X-S-Cookie
X-CF-Lambda-Version
X-Session-Fingerprint
X-ScT
X-DPWN-IS-SECURE
X-Rojux
X-Rewrite-Enabled
X-Request-UUID
X-Region-Sid
X-GeoIP-Country-Code
X-Geo-Header
X-External-Request-Id
X-G
X-Rocket-Build-Number
X-CF-Lambda-Fn
X-B-Cookie
Viewtype
VivaBuild
W
X-A
Rendered-Blocks
Mobile-Detection-Method
Machine
MD5-Digest
Meta-Geo-Continent
X-A-Ccd
X-Sigma-Backend
X-Sigma
X-Aed
X-ARC
X-Accel-Expires-Debug
X-A-Wwc
X-A-Dam
X-A-Dcw
X-A-Dgt
GEO-REGION-INFO
X-Application
X-Nc
Geo-Info
X-No-Session
X-C
User-Cache-Control
X-Agile-Age
X-Agile-Id
Fastly-SWR
X-Tumblr-Pixel-3
X-Logging-Id
X-SIPLIST1
Server-Surrogate-Control
X-App-Name
X-Agile
CDCHOST
X-Thanos
Fastly-SIE
Environment
X-Rebelmouse-Surrogate-Control
X-Clientip
Countrycode
X-Rebelmouse-Cache-Control
X-Contensis-Viewer-Groups
X-CGP
X-TrackingId
Fastly-Soc-X-Request-Id
X-Auto-Login
X-Varnish-Authentication
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Bip
X-Varnish-Beresp-Ttl
Gh-Request-Id
Ha-Gx-Prefs
X-Cache-ASPX
X-Distil-CS
HA-Ipaddr
X-Cache-Debug
Powered-By
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
X-VC-Cache
Locid
X-Eu-Site
IsBot
X-Hit
Server-Cache-Control
X-WebServer
X-Developers
X-Cache-Backend
X-GoCache-CacheStatus
X-Request-URI
V-Age
X-Debug-Cache-Expiry
X-NX-Host
X-Server-W
Server-ID
X-Servername
RNT-Time
RNT-Machine
Server-Int
X-Debug-Log
True-Client-Country-4JS
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Debug-Cookies
X-LI-UUID
X-Real-IP
X-Origin-Expires
X-OVcl-Cache
X-Backend-State
X-Owner
X-Azure-Ref
X-OVcl
X-Block-Status
X-Cache-Time
X-Cache-Tags
X-Cache-Info
X-Cache-Bucket
X-Cdn-Srv
X-PHP-Host
X-Cms-Context
X-Clara-WADP
X-Core-Mission
Web-Mar-Node
X-CUA
Request-EU
X-Origin-Date
X-Li-Fabric
X-AK-Request-ID
X-Platform-Server
X-Proxy-Upstream
X-Render-Time
X-Fastly-Cache
X-TT-LOGID
X-GeoIP-City
X-Up
AKAMAI
Adler-Geo
X-Generation-Time
Cache-Host
Country-Code
X-Generated-In
X-Trace-Id
Cdnsip
Cdncip
Access-Control-Request-Headers
X-Urbn-Context-Path
X-Irp-Debug
X-Hnp-Log
X-Is-Gdpr
X-JWT-State
X-Labrador-Cache-Channel
X-We-Are-Hiring
X-WADP-Cache
X-Urbn-Site-Id
X-Has-Esi
X-Variation
X-VServer
X-Gen-Mode
X-TH-Server
X-Nginx-Cache-Key
X-LI-Proto
Memcached
X-Ms-Version
X-Micro-Cache
X-Cache-URL
X-Epic-Correlation-Id
X-Li-Pop
X-Distributor
Request-Country
Platform
X-NU-AKA-ACS-Version
X-NodeID
X-SVT-ORM-RULES
X-Ms-Request-Id
Heartbleed
X-Swa-Ws
X-Gamma-Serve
Fastly-SSL
IBM-Web2-Location
X-SVT-ORM-VERSION
Is-Eu
Locale
X-FW-Version
X-Internal-Host
X-Dispatcher-Server
X-Old-Content-Length
X-Instart-Isnd
X-Generated-On
X-IN-APIGATEWAY
X-Hash
X-Matched-Rule
X-Fetched-On
X-Core-Value
X-IN-APIGATEWAYSSL
Thinkindot-Control
X-ServiceProvider
PFcat
X-Air-Hostname
X-Webstats-RespID
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-BBXSRF
Mail-Subject
X-Thinkindot-L3
X-User
Fastly-Backend-Name
FNAC-ModuleRouting
Kp-EeAlive
ServerName
X-Level-Front-Cache
X-Service
X-RateLimit-Remaining-Second
We-Hiring
X-Req
X-Reboot
X-RateLimit-Limit-Second
X-Nginx-Cache
X-Sucuri-Cache
Wxu-Next-Region
X-SERVER
X-Trafficlayer-App-Version
Cache-Hits
X-Cache-Expired-At
Group
Wxu-Next-Hostname
Server-Host
X-S-Maxage
X-Key
Wxu-Next-Commit
X-App-Version
X-Refresh
X-Location
S-Cnection
X-Lb-Id
RequestId
X-TA-CDN-Provider
X-Var-Ttl
Pragrma
X-Response-By
X-Parent-Response-Time
Powered-By-ChinaCache
X-Tb-Optimization-Total-Bytes-Saved
Filterid
X-CSRF-TOKEN
Memory
X-NC
X-CF-Powered-By
X-Tec-Api-Root
X-Tec-Api-Version
X-Tec-Api-Origin
X-B3-Parentspanid
ProcessTime
Origin
X-Wa
X-Cdn-Forward
X-Sucuri-ID
X-BACKEND-TTL
X-Pf-Uncompressing
X-Varnish-Cacheable
X-Pjax-Url
X-Ua
User-Agent
X-CSRF-Token
X-B3-SpanId
X-Server-IP
SRV
X-NWS-UUID-VERIFY
X-Correlation-ID
Geoip-City
Geoip-Latitude
PICS-Label
TTL
X-Developer
X-Via-CDN
X-FORWARDED-FOR
X-NGINX-Cache
X-Vcl-Version
X-Sn-Servicetimems
GeoIp-Country-Code
X-Node-Id
X-COUNTRY
X-LAGOON
X-Cache-Grace
X-Ocache
X-Cdn-Origin
X-Unique-ID
On-Server
Media-Length
X-Device-Os
X-Cdn-Request-ID
X-Webkit-CSP
A
X-Request-Host
X-Litespeed-Cache
X-Servedbyhost
X-MSEdge-Features
X-MSEdge-Flight
Hostname
X-Cache-Status-Check
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Oss-Request-Id
Dnion-Transfer-Encoding
X-Varnish-Ttl
X-Via-Ucdn
M-TraceId
X-Rocket-Nginx-Bypass
X-TIME
XServer
X-Sucuri-Id
SN
Cloudfront-Viewer-Country
Tcn
Esi-Enabled
X-HS-Status
X-AIR-PT
X-Reqid
X-Ratelimit-Remaining
Cdn
Who
Resin-Trace
X-Beluga-Status
X-Beluga-Response-Time
X-Planisys-CDN-Cache
X-Varnish-URL
X-Beluga-Cache-Status
X-Beluga-Record
X-Beluga-Node
Host-ID
X-Cache-Ttl
X-Fastly-Country-Code
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-ServedByHost
X-Beluga-Trace
X-Policy
X-VHOST
HostName
X-Azure-Ref-OriginShield
CF-Cached-On
X-Request-Start
MIME-Version
X-VCL-Version
X-Slack-Backend
Rt-Proxy-Cache
X-Action
GeoIP-Country-Code
X-Fastly-Backend-Reqs
Pics-Label
X-DC
Ttl
X-Ftr-Cache-Host
X-LiteSpeed-Cache-Control
X-Oracle-Dms-Rid
CACHE
X-Server-Time
X-Processor
X-PAYTM-SRV-ID
X-RSL
X-DSS
X-DI
X-DB
X-Varnish-Url
X-DW
X-RPM
Pramga
Arc-Country
X-RPS
X-Cache-FS-Status
X-Method
X-Zone
NtCoent-Length
X-Bc
X-APP
Magicmarker
GeoIP-Latitude
X-VarnishDD-TTL
X-ABtesting
X-PJAX-URL
X-Newrelic-App-Data
X-Ratelimit-Limit
X-Dispatch
X-Skip-Cache
GeoIP-City
X-ND-Cache
Cteonnt-Length
X-PF-Uncompressing
X-Hello
X-Flog
X-FPC
X-HostName
X-SRV
Cdn-Host
Cdn-Request-Time
X-Edge-Server
X-Served-From
Amp-Access-Control-Allow-Source-Origin
WebServer
Fastly-Drupal-HTML
X-SERVER-NAME
X-Bc-Bl
X-Be
X-Dynatrace
Processtime
Ohc-Response-Time
X-BE
X-DevSite-Last-Modified
X-Svr
X-Dynatrace-Js-Agent
Load-Balancing
X-Swift-Error
Servername
X-WA
N-Cache
X-Amzn-Remapped-Connection
Vix-Hermes-Req-Id
X-ID
X-Amzn-Remapped-Date
Cache-Provider
CDN
X-LB-ID
X-Aicache-OS
Section-Io-Origin-Status
X-WR-MODIFICATION
Section-Io-Id
X-Frame-Option
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
X-Fastly-Cache-Hits
Requestid
X-Branch-Name
DSUID
X-Snapshot-Date
CF-IPCountry
X-BC
Lfy
X-MServer
Dynatrace
X-Backend-Host
Pagetype
X-StackifyID
X-ZONE
X-VCT
Release
X-CACHE-AGE
Proxy-Firewall
X-Apw-Hits
X-Apw-Access-Object
Cache-Cookie-Set-Lfrom
FSS-Proxy
FSS-Cache
X-Cc-Via
WZWS-RAY
X-Tid
Cache-Cookie-Set-Idcheck
X-Configured-By
Cache-Cookie-Set-From
V-Cache
X-Fmm-Version
X-SB
X-VC
X-Cc-Req-Id
X-Apw-Access-Token
X-Hp-Ccpa-Warning
D-Cc-Upstream
Warning
X-Request-Url
X-Apw-Access-Action
X-Adobe-Source
X-Litespeed-Cache-Control
Trailer
X-WPE-Loopback-Upstream-Addr
Cneonction
X-Powered-Y
X-SD-PageType
X-Worker
X-Upstream-Ct
X-Upstream-Ht
Correlation-Id
X-App
X-Edge-IP
WP-Super-Cache
X-Check-Cacheable
X-Varnish-Beresp-TTL
X-Request-URL
Backend-Name
X-ElasticPress-Search
SD-X-WS
X-Fastly-Cache-Status