Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
CF-RAY
Link
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-UA-Compatible
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-Request-ID
X-Template
X-Language
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Iinfo
X-AspNetMvc-Version
X-Ua-Compatible
X-FRAME-OPTIONS
X-Buckets
Status
X-Content-Security-Policy
X-CDN
Upgrade
Content-Encoding
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Xss-Protection
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
Xkey
X-Pass-Why
X-Cache-Group
P3p
X-AH-Environment
X-Envoy-Upstream-Service-Time
CF-Ray
X-Backend
X-Age
X-Server
X-Via
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Server-Powered-By
X-Page-Speed
X-Pingback
EagleId
X-Proxy-Cache
X-Nginx-Cache-Status
X-Ws-Request-Id
X-UA-Device
X-Hacker
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
Grace
Cf-Railgun
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Amz-Version-Id
X-Dns-Prefetch-Control
X-LiteSpeed-Cache
Report-To
X-Server-Id
X-Rq
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Host
X-WebKit-CSP
X-Device
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Origin-Cache
X-Response-Time
Content-Location
X-Node
X-Ac
Surrogate-Control
X-Vhost
X-Readtime
Request-Id
X-Backend-Server
X-Dispatcher
X-Cloud-Trace-Context
X-Origin-Upstream-Status
X-Cnection
X-HW
X-ORACLE-DMS-ECID
X-Application-Context
X-DataDome
Fusion-Component-Id
Fusion-Source
Fusion-Content-Id
Fusion-Content-Source
Fusion-Template-Id
X-ORACLE-DMS-RID
X-Cache-Lookup
NEL
X-Mod-Pagespeed
Edge-Control
X-Rack-Cache
Rating
X-Country
X-Akam-SW-Version
X-Clacks-Overhead
Pinterest-Generated-By
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Ruxit-JS-Agent
X-Varnish-TTL
X-DynaTrace
X-Country-Code
Accept-Ch
Allow
X-Instart-Request-ID
X-Goog-Hash
X-TtlSet
X-PC
X-Vname
X-FTR-Request-ID
X-TTL
X-ESI
Verso
Accept-Ch-Lifetime
X-Powered-By-Plesk
X-Url
Service-Worker-Allowed
Content-MD5
X-B3-TraceId
X-Forwarded-Proto
X-Version
X-MS-InvokeApp
X-GitHub-Request-Id
X-Kinja-Build
X-GoogleNews-Bot
X-Exp-Variant
X-Exp-Id
X-Cdn-Fetch
X-Kinja
X-Use-Magma
X-Kinja-Revision
X-Kinja-Server
Edge-Cache-Tag
Ar-Sid
AR-Request-ID
AR-PoweredBy
AR-CACHE
RTSS
AR-ATIME
X-Px
X-D2id
X-Debug
X-Abt-Application-Version
X-Server-Name
Charset
X-NF-Request-ID
SPRequestGuid
X-Vcache
X-Amz-Server-Side-Encryption
X-Accel-Expires
X-MSEdge-Ref
X-Cached
X-Powered-CMS
X-Amz-Rid
X-TEC-API-ORIGIN
X-TEC-API-ROOT
Arr-Disable-Session-Affinity
X-TEC-API-VERSION
Display
X-Middleton-Display
Pagespeed
X-Sol
Response
X-Middleton-Response
X-Vcap-Request-Id
X-Navigation-Version
X-Trace
Pinterest-Version
X-Pinterest-Rid
X-SharePointHealthScore
X-SRCache-Fetch-Status
X-SRCache-Store-Status
TCN
X-VARITI-CCR
Realpath
Public-Key-Pins
X-Fastcgi-Cache
X-Client-IP
Cache-Tag
X-Cdn
Access-Control-Request-Method
X-Fastly-Request-ID
X-Ser
S
X-Upstream
MS-Author-Via
X-DynaTrace-JS-Agent
X-Shard
SPIisLatency
SPRequestDuration
X-Id
Nginx-Cache
X-Hp-Webp
X-Ezoic-Cdn
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
X-Content-Type
MRF-Tech
X-Mrf-Item-Lastmod
Mrf-Cache-Status
X-Forwarded-For
X-T
X-Amz-Meta-S3cmd-Attrs
DynaTrace
X-Amzn-Trace-Id
X-Recruiting
X-Grace
Front-End-Https
X-Hits
Nel
Fastcgi-Cache
X-Varnish-Age
X-Aspnet-Version
X-DIS-Request-ID
ServerID
X-Dw-Request-Base-Id
X-Edge-O15-RID
MicrosoftSharePointTeamServices
X-Mobile-URL
X-Element-Page-Cache
X-Node-Name
NR-ENABLED
X-Content-Digest
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Combine-CSS
X-Goog-Generation
X-Goog-Metageneration
X-FTR-Cache-Status
X-Country-Code-Real
X-Goog-Storage-Class
X-FTR-Expires
X-Goog-Stored-Content-Encoding
X-Frontend
Powered
X-GUploader-UploadID
X-Goog-Stored-Content-Length
Server-Name
X-Cache-TTL
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Realm
Alternate-Protocol
X-FTR-DC
X-Logged-In
TP-Cache
TP-L2-Cache
Server-Node
X-Correlation-Id
X-Jurisdiction
X-XRDS-LOCATION
X-Request-Received
X-Webkit-Csp
X-Request-Processing-Time
X-Microsite
X-Request-Handler-Origin-Region
X-ATS-Timestamp
Backend-Timing
AMP-Access-Control-Allow-Source-Origin
Upgrade-Insecure-Requests
X-Page-Id
X-Content-Options
Refresh
X-Content-Security-Policy-Report-Only
X-Origin-Server
X-Shield-Request-Id
X-Rid
X-Akamai-Edgescape
X-F-Cache
X-Revision
X-User-Agent
X-Cache-Hit
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Varnish-Grace
X-Server-ID
X-Type
X-Webapp-Samesite-None-Activated-N
X-XRDS-Location
Fastly-Restarts
X-Content-Powered-By
X-Zen-Fury
X-Geo-Country
X-LB-Cache
X-B3-Sampled
X-Az
X-AppVersion
X-Activity-Id
X-B
X-Pad
X-Analytics
X-URL
X-N
X-FTR-Cache-Host
X-Kinsta-Cache
PB-PID
PB-RID
X-CST
X-RateLimit-Remaining
Arc-Version
X-Mobile-Rewrite
X-TT
Cache-Status
X-AOL-HN
X-WebKit-CSP-Report-Only
X-Cache-Age
X-Instance
X-Request-Guid
Paypal-Debug-Id
X-App-Environment
DC
Actual-Object-TTL
X-Ruxit-Js-Agent
X-B-Cache
X-Framework
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel
X-Signature
X-Jobs
X-Debug-Info
Access-Control-Allow-Method
X-PHP-Backend
X-FB-Debug
X-Time
X-Cache-Action
X-Load-Cache
X-Varnish-Backend
X-Git-Hash
Surrogate-Key
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Cached-By
X-Tt-Trace-Tag
Host-Header
Fastcgi-Useragent
X-Ttl
X-IPLB-Instance
X-FastCGI-Cache
X-Contextid
X-Amz-Replication-Status
MS-CV
X-SS-Set-Cookie
X-Tt-Trace-Host
X-Cluster
FilterID
X-ATG-Version
Tracecode
X-Srv
Frame-Options
NGB
X-Response-Served-From
X-Accel-Buffering
X-WA-Info
X-Cache-NE
Xserver
WPE-Backend
X-Cache-Key
Payment
X-Varnish-Server
Eomportal-Instance
X-FW-Server
Host
X-Mobile
X-FW-Hash
X-Region
X-FW-Serve
X-FW-Static
X-FW-Type
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Filters
Cache-Tv-Group
Source
X-Adobe-Content
X-Cache-2
X-Rendered-As
X-Tumblr-Pixel-2
X-GeoIP
X-Host-Name
X-IPS-LoggedIn
X-Tumblr-Pixel-1
X-Is-Bot
X-RequestSource
X-Adobe-Loc
X-Varnish-Hostname
X-Cacheable-TTL
X-Cache-Enabled
X-TX-ID
X-NewRelic-App-Data
X-EdgeConnect-Cache-Status
X-Seen-By
X-Cache-Rule
Cleartype
X-Via-JSL
X-Cache-Operation
X-Hostname
X-Origin-Response-Time
X-Oneagent-Js-Injection
X-ORACLE-APMCS-TAG
X-ORACLE-APMCS-REQUEST-ID
X-Cache-TTL-Remaining
Cache
X-Presslabs-Stats
Retry-After
Healthy
X-VCache
X-HTML-Minification-Powered-By
X-Cache-Control
Datacenter
Server-Info
X-Dc
X-ProcessESI
X-RemovedCookies
Accept-CH
X-UA
X-Trafficlayer-App-Name
X-Trafficlayer-App-Scope
X-B3-Traceid
Ms-Operation-Id
X-RTag
X-NWS-LOG-UUID
X-CACHE-KEY
Liferay-Portal
X-RateLimit-Limit
X-Source
X-FireWall-Port
X-L-Path
X-Cache-Server
X-Rule
X-Environment-Context
X-PressLabs-Stats
From-Origin
X-Endurance-Cache-Level
Version
X-Status
X-Upgrade-Enabled
X-Wix-Request-Id
X-CLOUD-TRACE-CONTEXT
X-Handled-By
X-Path-Route
X-Cache-Var
X-Cache-Var-Map
Meta-Geo
X-App-Server
X-RN-RSRV
Accept-CH-Lifetime
X-ES-SERVER
Selected-Fe
OT-Force-Account-Verify
X-Proxy-Build
X-Timing-Wait
Azure-SiteName
X-Request-Time
X-ShardId
Azure-Version
Azure-SlotName
X-Shopify-Stage
Azure-RegionName
X-Sorting-Hat-PodId
X-Section
X-Backend-Name
X-Shopify-Generated-Cart-Token
X-ShopId
X-Content-Age
X-Access
X-Format
X-Proto
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Akamai-Request-ID
X-Sorting-Hat-ShopId
Azure-InstanceId
X-Alternate-Cache-Key
Cache-Tags
Akamai-GRN
X-EIG-Tracking-Id
Mn-Server-Ip
X-Storage
TWC-Privacy
TWC-Locale-Group
DB-Nickname
Ec-Rule-Version
Origin-Cache-Control
Now
TWC-Connection-Speed
S-Rt
Webcakes-App-Name
Property-Id
Node
TWC-Device-Class
Decoy-Debug-Status
Decoy-Debug-Key
Origin-Edge-Control
TWC-GeoIP-Country
NGX
TWC-GeoIP-LatLong
X-FC-Vary-Parameters
X-Vgn-Hpd-Reason
X-Proxy-Cache-Status
X-UUID
X-PCL
X-Origin
X-OCL
X-Proxy
X-Viewer-Country
X-Pubstack
X-ProxyCache-Key
X-Tb
X-Time-Microsecs
X-Soup
X-ServerID
X-SaId
X-Qloud-Router
X-Redis-Cache
X-ProxyCache-Status
X-VWS-Id
X-Human
X-Cluster-Node
X-Debug-Cache
X-FW-Dynamic
X-Cache-Host
X-Cache-Config
Webcakes-Region
X-Akamai-Request-ID2
X-AWS-Id
X-Generated-By
X-Hl-Ver
X-Origin-Hint
X-Web-Node
X-BYPASS-REASON
X-LJ-Flow-ID
X-JoinUs
X-Hosted-By
X-Hyper-Cache
Webcakes-App-Version
Decoy-Debug-TTL
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-IP
X-APP-VERSION
X-Generated
X-Detected-As
X-BCube-Filmed-By
X-CCM
X-Locale
X-Say-TTL
X-Xfnlog-Site
X-MP-GENERATED-AT
X-NYM-Debug-Backend
X-Www-Served-By
X-Varnish-Hits
X-SayCDN-TTL
X-Site-Version
X-Say-Cacheable
X-RCS-CacheZone
Cross-Origin-Window-Policy
X-Amzn-Remapped-Content-Length
X-TNCMS
X-FB-TRIP-ID
X-R9-Blue-Green-Version
X-Loop
GEO-INFO
X-Akamai-Transformed
L5d-Success-Class
Cache-Name
Accept-Charset
Viewport
X-CS
Uber-Trace-Id
Srv
X-NCache
X-Drupal-Cache-Tags
X-Unique-Id
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Esi
X-Cache-Remote
X-UA-Device-Type
X-From
Webserver
Time
X-TT-TIMESTAMP
Cache-Key
X-Origin-TTL
X-Origin-CC
X-Cluster-Name
Mime-Version
Accept-Language
X-Backend-TTL
X-Edge-Location
X-Drupal-Cache-Contexts
X-CDN-Forward
Country
Odigeo-Trace-Id
X-EC-Lua
X-Mode
Rt-Fastcgi-Cache
X-Microcachable
X-Forwarded-Host
X-Info
X-B3-Spanid
Ohc-Cache-HIT
X-Newrelic-Synthetics
X-Geo
Ohc-File-Size
X-UnsetCookies
X-Whom
X-No-Session
X-PERF
X-Magnolia-Registration
X-ApacheServer
X-Webkit-CSP
ServedBy
Proxy-Connection
Content-Disposition
X-Varnish-Cache-Hits
X-UPSTREAM-Address
X-PHP-Host
X-Labrador-Cache-Channel
X-Device-Type
X-Real-IP
X-Zipkin-Id
X-Routing-Service
X-Proxied
X-S
X-S-Cookie
X-CF-Lambda-Fn
X-A-Wwc
X-Rewrite-Enabled
X-Rojux
X-ScT
MD5-Digest
X-Aed
X-G
X-Accel-Expires-Debug
X-Cache-Time
X-Session-Fingerprint
X-SRCache-Key
X-Request-UUID
Rendered-Blocks
X-Connection-Hash
X-A-Ccd
X-NGENIX-Cache
Mobile-Detection-Method
Meta-Geo-Continent
X-GeoIP-Country-Code
X-A
X-Geo-Header
X-A-Dam
Viewtype
X-CF-Lambda-Version
X-A-Dgt
X-Region-Sid
VivaBuild
X-A-Dcw
X-External-Request-Id
BehaviorPad-Version
Fastcgi-X-Cache-Version
X-DPWN-IS-SECURE
X-Vdms-Version
AsisCache
Machine
X-D
GEO-REGION-INFO
X-VG-WebCache
Content-Style-Type
T-Server
X-App-Version
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
X-VG-WebServer
X-B-Cookie
X-Twitter-Response-Tags
Content-Script-Type
X-Date
X-Via-Fastly
X-ARC
Cf-Ipcountry
X-Transaction
X-Application
Xc-Version
X-Trv-Group
X-Destination
X-Uri
User-Cache-Control
X-C
Fastly-SSL
IsBot
X-GoCache-CacheStatus
Locid
Gh-Request-Id
X-Developers
X-Logging-Id
X-CUA
X-Tumblr-Pixel-3
X-Wikidot-Static-Cache
X-Sigma
X-Wikidot-Backend
X-WebServer
X-Contensis-Viewer-Groups
Server-Surrogate-Control
X-Rocket-Build-Number
X-Auto-Login
Apple-News-Services-Request-Url
W
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Handled
X-VC-Cache
X-Sigma-Backend
X-Thanos
Environment
X-TrackingId
Access-Control-Request-Headers
X-Cache-Debug
Fastly-Soc-X-Request-Id
X-SIPLIST1
X-Varnish-Authentication
X-Cache-ASPX
Server-Cache-Control
X-Bip
X-VG-TLSProxy
X-Daa-Tunnel
X-Cache-Backend
X-FW-Version
X-Fastly-Cache
X-Dispatcher-Server
X-Distributor
X-Cache-Bucket
X-Cache-Info
X-Cache-URL
X-Block-Status
X-BBXSRF
X-AK-Request-ID
X-Azure-Ref
X-Clara-WADP
X-Clientip
X-Debug-Cache-Store
X-Debug-Cookies
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-Cms-Context
X-Core-Mission
X-Debug-Log
X-Rebelmouse-Surrogate-Control
X-Urbn-Site-Id
X-Urbn-Context-Path
X-User
X-Sucuri-Cache
X-WADP-Cache
X-VServer
X-TT-LOGID
X-Trace-Id
Wxu-Next-Region
X-Request-URI
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-TH-Server
X-Swa-Ws
X-We-Are-Hiring
X-Webstats-RespID
X-Agile-Id
X-Agile-Age
X-App-Name
X-Backend-State
X-Distil-CS
X-CGP
X-Agile
X-Epic-Correlation-Id
X-Hit
X-Render-Time
X-Eu-Site
CDCHOST
HA-Ipaddr
Ha-Gx-Prefs
X-Req
X-Rebelmouse-Cache-Control
X-Irp-Debug
X-Instart-Isnd
X-Key
X-Li-Fabric
X-LI-Proto
X-Li-Pop
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-Generated-In
X-Gen-Mode
X-Generation-Time
X-GeoIP-City
X-Hnp-Log
X-Hash
X-LI-UUID
X-Location
X-OVcl-Cache
X-OVcl
X-Owner
X-Proxy-Upstream
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Origin-Expires
X-Origin-Date
X-Ms-Request-Id
X-Micro-Cache
X-Ms-Version
X-Nginx-Cache-Key
X-NX-Host
X-NodeID
X-Gamma-Serve
X-Cdn-Srv
Kp-EeAlive
IBM-Web2-Location
Heartbleed
FNAC-ModuleRouting
Locale
Mail-Subject
Request-EU
Request-Country
Powered-By
Memcached
X-Varnish-Beresp-Grace
Fastly-SIE
AKAMAI
Wxu-Next-Hostname
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Status
Cache-Host
Cdncip
Fastly-Backend-Name
Countrycode
Country-Code
Cdnsip
RNT-Machine
Fastly-SWR
Server-ID
Section-Io-Cache
V-Age
RNT-Time
True-Client-Country-4JS
We-Hiring
Web-Mar-Node
Wxu-Next-Commit
Server-Int
Geo-Info
HitType
Thinkindot-Control
X-Has-Esi
X-Old-Content-Length
X-Generated-On
Adler-Geo
X-Trafficlayer-App-Version
X-Up
X-Thinkindot-L3
X-Matched-Rule
X-ServiceProvider
X-Variation
X-Level-Front-Cache
X-NU-AKA-ACS-Version
Thinkindot-CacheControl-Type
X-Internal-Host
X-Is-Gdpr
X-JWT-State
X-Service
X-S-Maxage
Platform
Server-Host
PFcat
Thinkindot-CacheControl
X-Platform-Server
X-Cache-Tags
Is-Eu
X-Reboot
X-Core-Value
X-B3-Parentspanid
X-Nc
X-Server-W
ServerName
Cache-Hits
X-Lb-Id
X-Refresh
X-Response-By
X-Fetched-On
Filterid
X-Nginx-Cache
X-TA-CDN-Provider
X-SERVER
X-Servername
RequestId
X-B3-SpanId
X-Server-IP
ProcessTime
X-Parent-Response-Time
X-NC
X-CF-Powered-By
X-Cdn-Forward
X-Tec-Api-Root
X-Tec-Api-Origin
X-Air-Hostname
X-Tec-Api-Version
X-Tb-Optimization-Total-Bytes-Saved
X-Pjax-Url
X-CSRF-Token
X-CSRF-TOKEN
Group
SRV
Media-Length
Memory
Origin
X-Cdn-Request-ID
X-Cache-Expired-At
Pragrma
User-Agent
X-Wa
X-Var-Ttl
X-BACKEND-TTL
TTL
Geoip-Latitude
X-Pf-Uncompressing
S-Cnection
Powered-By-ChinaCache
X-Vcl-Version
GeoIp-Country-Code
X-Ua
X-NGINX-Cache
X-Unique-ID
X-Correlation-ID
X-Sucuri-Id
X-Sucuri-ID
X-Rocket-Nginx-Bypass
X-COUNTRY
Esi-Enabled
X-AIR-PT
PICS-Label
SN
X-Reqid
X-Planisys-CDN-Cache
Geoip-City
X-Varnish-Cacheable
X-Policy
X-TIME
HostName
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Azure-Ref-OriginShield
X-Request-Start
X-Servedbyhost
X-Via-CDN
X-Litespeed-Cache
X-NWS-UUID-VERIFY
X-Developer
Rt-Proxy-Cache
X-Via-Ucdn
XServer
X-LAGOON
X-HS-Status
M-TraceId
X-Cache-Grace
X-Cdn-Origin
X-Ocache
Dnion-Transfer-Encoding
X-Device-Os
X-Sn-Servicetimems
X-Node-Id
X-FORWARDED-FOR
X-Method
Magicmarker
X-Fastly-Country-Code
X-ServedByHost
Tcn
Resin-Trace
Cdn
On-Server
X-Request-Host
Who
Load-Balancing
X-MSEdge-Flight
X-MSEdge-Features
A
X-Cache-Ttl
X-Ftr-Cache-Host
X-VHOST
CF-Cached-On
Cloudfront-Viewer-Country
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
Ohc-Response-Time
DSUID
X-Cache-Status-Check
X-Oss-Storage-Class
X-Be
X-Svr
X-Beluga-Node
NtCoent-Length
Release
Pics-Label
X-Beluga-Response-Time
X-Beluga-Status
X-Beluga-Record
X-Beluga-Cache-Status
X-Beluga-Trace
X-MServer
X-VCT
X-Bc
X-Varnish-Url
X-VCL-Version
X-Zone
GeoIP-Country-Code
Vix-Hermes-Req-Id
X-APP
X-Oracle-Dms-Rid
X-Hp-Ccpa-Warning
Hostname
MIME-Version
X-Fastly-Backend-Reqs
GeoIP-Latitude
WebServer
X-VarnishDD-TTL
Ttl
X-Ratelimit-Remaining
Cteonnt-Length
Host-ID
X-DC
X-LiteSpeed-Cache-Control
X-Varnish-Ttl
GeoIP-City
X-Newrelic-App-Data
X-Varnish-URL
X-PF-Uncompressing
X-Configured-By
X-PJAX-URL
X-Ftr-Request-Id
X-Slack-Backend
Amp-Access-Control-Allow-Source-Origin
X-Upstream-Ct
X-Upstream-Ht
X-SRV
Servername
X-SD-PageType
SD-X-WS
X-WR-MODIFICATION
X-HostName
X-DW
Processtime
X-BE
X-RSL
X-DSS
X-RPS
X-RPM
X-DB
X-Action
X-DI
X-Cache-Id
X-Dynatrace
X-Aicache-OS
X-Compress-Hint
X-Tid
X-SN
X-Swift-Error
X-Dynatrace-Js-Agent
X-Ratelimit-Limit
X-Release
Arc-Country
X-Via-NSCOPI
X-ID
CACHE
L
X-Cache-FS-Status
Pramga
X-Dispatch
X-PAYTM-SRV-ID
X-Server-Time
X-FPC
X-Skip-Cache
Cache-Provider
X-Processor
X-Frame-Option
X-Ftr-Balancer
X-Ftr-Dc
X-Ftr-Backend-Server
Dynatrace
CF-IPCountry
X-Scheme
X-ABtesting
X-DevSite-Last-Modified
X-StackifyID
X-Flog
X-Ftr-Backend
X-Ftr-Realm
X-Branch-Name
LB
X-Snapshot-Date
Requestid
X-ServerName
Fastly-Drupal-HTML
X-ND-Cache
X-LB-ID
Pagetype
X-Fastly-Cache-Hits
Lfy
CDN
X-Hello
X-CACHE-AGE
X-Node-ID
UCS
X-Cc-Via
X-Apw-Access-Object
X-Apw-Hits
X-Cc-Req-Id
X-Edge-IP
X-ZONE
X-Varnish-Beresp-TTL
Cdn-Host
Warning
X-Served-From
Cdn-Request-Time
X-Edge-Server
Cache-Cookie-Set-Lfrom
X-Apw-Access-Token
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-From
X-Apw-Access-Action
X-Request-URL
Proxy-Firewall
V-Cache
D-Cc-Upstream
N-Cache
X-VC
X-Request-Url
X-SB
NnCoection
X-WA
Lb
X-App
Correlation-Id
Backend-Name
X-Litespeed-Cache-Control
X-BC
X-Worker
X-Check-Cacheable
X-Powered-Y
X-ElasticPress-Search
WP-Super-Cache
X-Fastly-Cache-Status