Threat Level: green Handler on Duty: Renato Marinho

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-Powered-By
Pragma
CF-Cache-Status
X-XSS-Protection
CF-RAY
Link
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-UA-Compatible
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Cache-Status
X-Generator
Content-Security-Policy-Report-Only
X-Permitted-Cross-Domain-Policies
X-Request-ID
X-Cacheable
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-DNS-Prefetch-Control
X-AspNetMvc-Version
X-Ua-Compatible
X-FRAME-OPTIONS
X-Buckets
Status
X-Content-Security-Policy
X-CDN
Content-Encoding
Upgrade
Access-Control-Expose-Headers
Access-Control-Max-Age
X-XSS-PROTECTION
X-Xss-Protection
X-Kinja-Server-Push
Keep-Alive
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
P3p
Xkey
X-Pass-Why
X-Cache-Group
X-AH-Environment
X-Envoy-Upstream-Service-Time
CF-Ray
X-Backend
X-Age
X-Server
X-Via
X-Amz-Id-2
X-Amz-Request-Id
X-Server-Powered-By
X-Robots-Tag
X-Page-Speed
X-Pingback
EagleId
X-Ws-Request-Id
X-Proxy-Cache
X-Nginx-Cache-Status
X-UA-Device
X-Hacker
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
Grace
Cf-Railgun
X-Swift-CacheTime
X-Swift-SaveTime
X-Amz-Version-Id
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
X-LiteSpeed-Cache
Report-To
X-Server-Id
X-Rq
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-WebKit-CSP
X-Host
X-Device
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Origin-Cache
X-Response-Time
Content-Location
X-Ac
X-Node
Surrogate-Control
X-Vhost
X-Readtime
Request-Id
X-Cloud-Trace-Context
X-Backend-Server
X-Dispatcher
X-Origin-Upstream-Status
X-Cnection
X-HW
X-ORACLE-DMS-ECID
X-Application-Context
X-DataDome
Fusion-Source
Fusion-Template-Id
Fusion-Content-Source
Fusion-Content-Id
Fusion-Component-Id
X-Cache-Lookup
X-ORACLE-DMS-RID
NEL
X-Mod-Pagespeed
Edge-Control
Rating
X-Rack-Cache
X-Country
X-Akam-SW-Version
X-Clacks-Overhead
Pinterest-Generated-By
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Ruxit-JS-Agent
Accept-Ch
X-Varnish-TTL
X-DynaTrace
X-Country-Code
Allow
X-Instart-Request-ID
X-Goog-Hash
X-PC
X-Vname
X-TtlSet
X-FTR-Request-ID
X-TTL
Accept-Ch-Lifetime
Verso
X-ESI
X-Powered-By-Plesk
Service-Worker-Allowed
X-Url
Content-MD5
X-Forwarded-Proto
X-Version
X-MS-InvokeApp
X-B3-TraceId
X-GitHub-Request-Id
X-Cdn-Fetch
X-Exp-Id
X-Kinja-Build
X-Exp-Variant
X-Kinja
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-GoogleNews-Bot
Edge-Cache-Tag
RTSS
AR-PoweredBy
AR-Request-ID
Ar-Sid
AR-CACHE
AR-ATIME
X-Px
X-D2id
X-Debug
X-Abt-Application-Version
X-Server-Name
Charset
SPRequestGuid
X-NF-Request-ID
X-Amz-Server-Side-Encryption
X-Vcache
X-Accel-Expires
X-Cached
X-MSEdge-Ref
X-Powered-CMS
X-Amz-Rid
Arr-Disable-Session-Affinity
X-TEC-API-VERSION
Response
X-Middleton-Display
X-Middleton-Response
X-Sol
Display
Pagespeed
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Vcap-Request-Id
X-Navigation-Version
X-Pinterest-Rid
X-Trace
Pinterest-Version
X-SharePointHealthScore
X-SRCache-Fetch-Status
X-SRCache-Store-Status
TCN
X-Fastcgi-Cache
X-Cdn
X-VARITI-CCR
Realpath
Public-Key-Pins
X-Client-IP
Cache-Tag
Access-Control-Request-Method
X-Ser
X-Fastly-Request-ID
S
X-Upstream
MS-Author-Via
X-DynaTrace-JS-Agent
X-Shard
SPRequestDuration
X-Id
SPIisLatency
Nginx-Cache
X-Hp-Webp
X-Ezoic-Cdn
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
Mrf-Cache-Status
X-B3-TraceId-Primal
MRF-Tech
X-Content-Type
X-Forwarded-For
X-T
X-Amzn-Trace-Id
X-Amz-Meta-S3cmd-Attrs
DynaTrace
Nel
X-Grace
X-Recruiting
Front-End-Https
X-Hits
X-Aspnet-Version
Fastcgi-Cache
X-Varnish-Age
ServerID
X-Edge-O15-RID
X-DIS-Request-ID
MicrosoftSharePointTeamServices
X-Dw-Request-Base-Id
X-Mobile-URL
X-Node-Name
X-Element-Page-Cache
NR-ENABLED
X-Content-Digest
X-HS-Combine-CSS
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Content-Id
X-FTR-Cache-Status
X-Country-Code-Real
X-Frontend
Powered
X-FTR-Expires
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Cache-TTL
Server-Name
X-FTR-DC
X-FTR-Realm
X-FTR-Balancer
X-FTR-Backend
X-FTR-Backend-Server
Alternate-Protocol
Server-Node
TP-Cache
X-Logged-In
TP-L2-Cache
X-Jurisdiction
X-Correlation-Id
X-XRDS-Location
X-Request-Processing-Time
X-Request-Received
X-Microsite
X-Request-Handler-Origin-Region
AMP-Access-Control-Allow-Source-Origin
X-ATS-Timestamp
Backend-Timing
Upgrade-Insecure-Requests
X-Server-ID
X-Page-Id
X-Content-Options
X-Cache-Hit
X-Content-Security-Policy-Report-Only
Refresh
X-Origin-Server
X-Rid
X-User-Agent
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Revision
X-Akamai-Edgescape
X-F-Cache
X-Type
X-Varnish-Grace
X-Shield-Request-Id
X-Webapp-Samesite-None-Activated-N
X-XRDS-LOCATION
Fastly-Restarts
X-Zen-Fury
X-Content-Powered-By
X-Geo-Country
X-LB-Cache
X-URL
X-B3-Sampled
X-B
X-Az
X-Activity-Id
X-AppVersion
X-Pad
X-CST
X-RateLimit-Remaining
X-Analytics
X-FTR-Cache-Host
X-N
X-Kinsta-Cache
PB-PID
PB-RID
X-Ruxit-Js-Agent
X-Webkit-Csp
X-Mobile-Rewrite
Arc-Version
Cache-Status
X-Cache-Age
X-TT
X-WebKit-CSP-Report-Only
X-Debug-Info
X-AOL-HN
X-Instance
X-B-Cache
X-Time
X-Signature
X-Framework
X-Request-Guid
X-Jobs
X-App-Environment
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel
Actual-Object-TTL
DC
Paypal-Debug-Id
Access-Control-Allow-Method
X-PHP-Backend
X-FB-Debug
X-Cache-Action
X-Load-Cache
X-Git-Hash
Surrogate-Key
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Varnish-Backend
X-Ttl
X-Cached-By
Host-Header
X-Tt-Trace-Tag
Fastcgi-Useragent
X-Amz-Replication-Status
X-Contextid
X-IPLB-Instance
FilterID
MS-CV
X-Tt-Trace-Host
X-SS-Set-Cookie
X-Cluster
X-ATG-Version
X-FastCGI-Cache
Tracecode
X-Cache-Key
NGB
X-Response-Served-From
X-WA-Info
X-Accel-Buffering
X-Srv
X-B3-Traceid
WPE-Backend
Frame-Options
X-Cache-NE
X-Varnish-Server
Payment
Host
X-Mobile
X-Host-Name
Xserver
X-FW-Server
X-FW-Hash
Eomportal-Instance
X-FW-Static
X-FW-Serve
X-FW-Type
X-Cache-2
X-Region
X-RequestSource
X-Is-Bot
X-Cache-Rule
Filters
X-GeoIP
X-Rendered-As
Cache-Tv-Group
X-Kong-Upstream-Latency
X-Cacheable-TTL
X-Kong-Proxy-Latency
X-IPS-LoggedIn
Source
X-Adobe-Loc
X-Cache-Operation
X-Adobe-Content
X-Cache-Enabled
X-Varnish-Hostname
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
X-NewRelic-App-Data
X-TX-ID
X-Oneagent-Js-Injection
X-EdgeConnect-Cache-Status
X-Hostname
X-Seen-By
Cleartype
X-Via-JSL
X-Origin-Response-Time
X-ORACLE-APMCS-TAG
X-Cache-TTL-Remaining
X-ORACLE-APMCS-REQUEST-ID
Cache
X-VCache
Retry-After
Server-Info
X-Presslabs-Stats
X-HTML-Minification-Powered-By
X-Cache-Control
Datacenter
X-RemovedCookies
X-ProcessESI
Healthy
X-RTag
Ms-Operation-Id
X-PressLabs-Stats
X-RateLimit-Limit
X-NWS-LOG-UUID
Liferay-Portal
X-Dc
X-Source
X-UA
X-Environment-Context
From-Origin
X-L-Path
X-FireWall-Port
X-Cache-Server
X-Trafficlayer-App-Name
X-Endurance-Cache-Level
X-Rule
X-CACHE-KEY
X-Trafficlayer-App-Scope
X-Upgrade-Enabled
X-Esi
X-Wix-Request-Id
X-Status
Version
X-App-Server
X-Handled-By
X-Cache-Var
X-Cache-Var-Map
Meta-Geo
X-ES-SERVER
X-Path-Route
X-RN-RSRV
OT-Force-Account-Verify
Selected-Fe
X-Access
X-Format
X-Request-Time
X-Section
X-APP-VERSION
X-Tb
X-Proxy-Build
X-Timing-Wait
X-ProxyCache-Status
X-Proto
X-ProxyCache-Key
X-ShopId
X-Storage
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Shopify-Stage
X-PCL
X-Shopify-Generated-Cart-Token
X-ShardId
X-Human
Cache-Tags
Mn-Server-Ip
X-Akamai-Request-ID
Azure-SlotName
Azure-SiteName
Azure-InstanceId
Azure-RegionName
X-Alternate-Cache-Key
X-Backend-Name
Akamai-GRN
X-OCL
X-Goog-Meta-Goog-Reserved-File-Mtime
X-EIG-Tracking-Id
X-BYPASS-REASON
X-Content-Age
X-Origin
Azure-Version
Accept-CH
Webcakes-App-Name
Webcakes-App-Version
TWC-Privacy
TWC-Locale-Group
TWC-GeoIP-LatLong
Webcakes-Region
X-Akamai-Request-ID2
X-Debug-Cache
X-Cache-Host
X-Cache-Config
X-AWS-Id
TWC-GeoIP-Country
TWC-Device-Class
NGX
Node
Ec-Rule-Version
Decoy-Debug-TTL
Decoy-Debug-Status
Now
Origin-Cache-Control
TWC-Connection-Speed
S-Rt
Property-Id
Origin-Edge-Control
X-FC-Vary-Parameters
X-FW-Dynamic
X-SaId
X-ServerID
X-Redis-Cache
X-RCS-CacheZone
X-Qloud-Router
X-Soup
X-Time-Microsecs
X-VWS-Id
X-Viewer-Country
X-Vgn-Hpd-Reason
X-UUID
X-Pubstack
X-Proxy-Cache-Status
X-Hosted-By
X-Hyper-Cache
X-Hl-Ver
X-Generated-By
Decoy-Debug-Key
X-JoinUs
X-LJ-Flow-ID
X-Proxy
X-Origin-Hint
X-NYM-Debug-Backend
X-MP-GENERATED-AT
X-Web-Node
X-Cluster-Node
X-Yottaa-Metrics
DB-Nickname
X-Yottaa-Optimizations
X-IP
X-Generated
X-CCM
X-Detected-As
X-Say-Cacheable
X-Www-Served-By
X-Xfnlog-Site
X-Varnish-Hits
X-Site-Version
X-Say-TTL
X-SayCDN-TTL
X-BCube-Filmed-By
X-Locale
Cross-Origin-Window-Policy
X-TNCMS
X-Amzn-Remapped-Content-Length
X-FB-TRIP-ID
X-R9-Blue-Green-Version
X-Loop
L5d-Success-Class
Srv
X-Akamai-Transformed
Cache-Name
X-CS
Accept-Charset
Viewport
Uber-Trace-Id
GEO-INFO
X-NCache
X-Drupal-Cache-Tags
Accept-CH-Lifetime
Webserver
X-Unique-Id
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-UA-Device-Type
X-Cache-Remote
X-Backend-TTL
X-From
Cache-Key
Mime-Version
X-CDN-Forward
Time
X-Drupal-Cache-Contexts
X-Cluster-Name
X-Origin-TTL
X-TT-TIMESTAMP
X-Origin-CC
Accept-Language
X-Edge-Location
Country
X-B3-Spanid
X-Mode
Odigeo-Trace-Id
X-Forwarded-Host
Rt-Fastcgi-Cache
X-Microcachable
X-CLOUD-TRACE-CONTEXT
X-EC-Lua
X-UnsetCookies
X-Info
X-Newrelic-Synthetics
X-Geo
X-Whom
X-Varnish-Cache-Hits
Ohc-Cache-HIT
X-ApacheServer
Ohc-File-Size
X-Magnolia-Registration
X-PERF
Content-Disposition
Proxy-Connection
X-No-Session
ServedBy
X-UPSTREAM-Address
X-NGENIX-Cache
Geo-Info
X-Labrador-Cache-Channel
Cf-Ipcountry
X-PHP-Host
X-Routing-Service
X-Device-Type
X-Proxied
X-Zipkin-Id
Content-Style-Type
X-VG-WebServer
GEO-REGION-INFO
Fastcgi-X-Cache-Version
X-SRCache-Key
X-Transaction
X-Via-Fastly
X-Twitter-Response-Tags
X-VG-TLSProxy
X-A-Wwc
X-Vdms-Version
X-A-Dgt
Apple-News-Services-Handled
X-A
X-Trv-Group
X-A-Dcw
X-VG-WebCache
X-A-Ccd
X-S
X-Geo-Header
BehaviorPad-Version
X-B-Cookie
X-G
X-GeoIP-Country-Code
X-A-Dam
X-ARC
X-Request-UUID
AsisCache
X-Region-Sid
X-External-Request-Id
Xc-Version
MD5-Digest
Machine
Content-Script-Type
X-CF-Lambda-Fn
Meta-Geo-Continent
Mobile-Detection-Method
X-DPWN-IS-SECURE
T-Server
X-Destination
Rendered-Blocks
X-Rewrite-Enabled
X-Application
X-Session-Fingerprint
X-Vtex-Remote-Cache
VivaBuild
X-ScT
X-Sigma
X-Accel-Expires-Debug
X-Vtex-Processado-Em
X-Sigma-Backend
X-Real-IP
W
X-S-Cookie
X-D
X-Connection-Hash
X-Aed
Viewtype
X-Rocket-Build-Number
Apple-News-Services-Host
Apple-News-Services-Request-Url
X-CF-Lambda-Version
X-Rojux
Apple-News-Services-Parsed-Url
X-Date
X-C
X-Uri
User-Cache-Control
X-Cache-Time
Server-Cache-Control
X-Cache-Debug
X-Hit
X-GoCache-CacheStatus
X-Distil-CS
X-Epic-Correlation-Id
Environment
Server-Surrogate-Control
Gh-Request-Id
X-Cache-ASPX
X-CGP
Fastly-Soc-X-Request-Id
CDCHOST
X-Logging-Id
X-CUA
Fastly-SSL
Powered-By
X-Contensis-Viewer-Groups
X-Developers
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-Render-Time
X-WebServer
X-Eu-Site
X-TrackingId
X-Agile
X-Bip
X-Tumblr-Pixel-3
Locid
X-Varnish-Authentication
X-VC-Cache
IsBot
X-Thanos
X-Agile-Age
X-SIPLIST1
HA-Ipaddr
X-Backend-State
Ha-Gx-Prefs
X-Sucuri-Cache
X-Auto-Login
X-Agile-Id
X-App-Name
X-App-Version
Access-Control-Request-Headers
HitType
X-Debug-Cookies
X-Dispatcher-Server
X-Distributor
X-Fastly-Cache
X-Debug-Log
X-Cdn-Srv
X-Azure-Ref
X-BBXSRF
X-Block-Status
X-AK-Request-ID
Wxu-Next-Region
Web-Mar-Node
Wxu-Next-Commit
Wxu-Next-Hostname
X-Cache-Backend
X-Cache-Info
X-Core-Mission
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
X-Cms-Context
X-Clientip
X-Cache-URL
X-FW-Version
X-Clara-WADP
X-Debug-Cache-Store
X-IN-APIGATEWAY
X-Rebelmouse-Cache-Control
X-RateLimit-Remaining-Second
X-Rebelmouse-Surrogate-Control
X-Req
X-Request-URI
X-RateLimit-Limit-Second
X-Proxy-Upstream
X-Origin-Expires
X-OVcl
X-OVcl-Cache
X-Owner
X-We-Are-Hiring
X-WADP-Cache
X-TT-LOGID
X-Urbn-Context-Path
X-Urbn-Site-Id
X-User
X-Trace-Id
X-TH-Server
X-VServer
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Swa-Ws
X-Origin-Date
X-NX-Host
We-Hiring
X-IN-APIGATEWAYSSL
X-Instart-Isnd
X-Irp-Debug
X-Hnp-Log
X-Hash
X-Gen-Mode
X-Generated-In
X-Generation-Time
X-GeoIP-City
X-Key
X-Li-Fabric
X-Ms-Version
X-Nginx-Cache-Key
X-Webstats-RespID
X-NodeID
X-Ms-Request-Id
X-Micro-Cache
X-Li-Pop
X-LI-Proto
X-LI-UUID
X-Location
X-Gamma-Serve
X-Cache-Bucket
Kp-EeAlive
Locale
Server-Int
IBM-Web2-Location
X-Varnish-Beresp-Grace
True-Client-Country-4JS
Request-EU
Server-ID
Mail-Subject
Request-Country
RNT-Machine
RNT-Time
AKAMAI
Memcached
Section-Io-Cache
Cache-Host
Heartbleed
X-Daa-Tunnel
X-Varnish-Beresp-Status
Countrycode
Country-Code
Cdncip
Cdnsip
X-Varnish-Beresp-Ttl
Fastly-Backend-Name
Fastly-SWR
V-Age
Fastly-SIE
FNAC-ModuleRouting
X-Nc
X-Core-Value
X-Matched-Rule
X-ServiceProvider
X-Service
X-Has-Esi
X-Platform-Server
X-Level-Front-Cache
X-Internal-Host
Is-Eu
X-Reboot
X-Is-Gdpr
X-Generated-On
X-JWT-State
PFcat
Platform
Thinkindot-CacheControl
X-Trafficlayer-App-Version
X-Up
X-Fetched-On
X-Old-Content-Length
Thinkindot-CacheControl-Type
Thinkindot-Control
Server-Host
X-NU-AKA-ACS-Version
X-Nginx-Cache
X-Variation
X-Thinkindot-L3
X-Cache-Tags
ServerName
X-Server-W
Adler-Geo
X-B3-Parentspanid
X-Response-By
X-Refresh
X-S-Maxage
X-Lb-Id
X-Servername
X-SERVER
Cache-Hits
X-TA-CDN-Provider
RequestId
X-CSRF-TOKEN
X-CF-Powered-By
Filterid
X-Tec-Api-Root
X-Server-IP
X-Tb-Optimization-Total-Bytes-Saved
X-Air-Hostname
ProcessTime
X-Tec-Api-Origin
X-Tec-Api-Version
X-NC
X-B3-SpanId
X-Parent-Response-Time
X-Pjax-Url
Group
X-Ua
X-Cache-Expired-At
X-Var-Ttl
X-Wa
Pragrma
X-Cdn-Forward
Origin
X-Cdn-Request-ID
Memory
Media-Length
User-Agent
S-Cnection
X-Sucuri-Id
Powered-By-ChinaCache
X-Pf-Uncompressing
X-CSRF-Token
X-BACKEND-TTL
X-Correlation-ID
SRV
X-Unique-ID
Geoip-Latitude
TTL
X-NGINX-Cache
X-Vcl-Version
X-COUNTRY
SN
PICS-Label
GeoIp-Country-Code
X-Oracle-Dms-Rid
X-Reqid
X-Varnish-Cacheable
Esi-Enabled
X-AIR-PT
X-Rocket-Nginx-Bypass
X-Servedbyhost
X-Sucuri-ID
X-Litespeed-Cache
X-Webkit-CSP
X-Via-CDN
X-Policy
Geoip-City
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-NWS-UUID-VERIFY
X-Request-Start
M-TraceId
X-HS-Status
X-Azure-Ref-OriginShield
X-Developer
X-Via-Ucdn
X-TIME
XServer
HostName
X-Node-Id
Dnion-Transfer-Encoding
X-Ocache
X-Sn-Servicetimems
Rt-Proxy-Cache
X-LAGOON
X-Cdn-Origin
X-Cache-Grace
X-Device-Os
X-FORWARDED-FOR
X-Fastly-Country-Code
On-Server
Tcn
X-MSEdge-Features
Resin-Trace
X-Method
Cdn
Who
X-MSEdge-Flight
X-Request-Host
X-Cache-Ttl
A
Magicmarker
X-VHOST
X-Ftr-Cache-Host
X-ServedByHost
CF-Cached-On
Cloudfront-Viewer-Country
X-Cache-Status-Check
Load-Balancing
Hostname
X-Beluga-Cache-Status
X-Beluga-Record
X-Beluga-Trace
X-Beluga-Response-Time
X-VCL-Version
GeoIP-Country-Code
Pics-Label
X-Beluga-Node
X-Beluga-Status
X-DC
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
X-Oss-Object-Type
X-Oss-Storage-Class
GeoIP-Latitude
X-APP
Ttl
DSUID
X-Be
X-Svr
Ohc-Response-Time
NtCoent-Length
X-VCT
Release
X-MServer
MIME-Version
X-Varnish-Url
Vix-Hermes-Req-Id
X-Bc
X-Zone
X-Fastly-Backend-Reqs
GeoIP-City
Cteonnt-Length
Host-ID
X-Varnish-URL
X-Varnish-Ttl
X-LiteSpeed-Cache-Control
X-Hp-Ccpa-Warning
X-PF-Uncompressing
X-VarnishDD-TTL
X-Newrelic-App-Data
WebServer
X-SRV
X-Ftr-Request-Id
Amp-Access-Control-Allow-Source-Origin
X-Slack-Backend
X-PJAX-URL
X-Configured-By
X-HostName
X-RSL
X-SD-PageType
X-Upstream-Ht
Processtime
X-Upstream-Ct
X-RPM
X-DI
X-DB
X-Action
X-DSS
X-Dynatrace
X-RPS
X-Swift-Error
X-DW
X-Ratelimit-Remaining
X-BE
X-Aicache-OS
SD-X-WS
X-WR-MODIFICATION
X-Dynatrace-Js-Agent
Servername
X-Cache-FS-Status
CACHE
X-Skip-Cache
Cache-Provider
X-ID
X-Compress-Hint
X-Server-Time
X-Cache-Id
X-SN
L
X-Dispatch
X-Processor
X-PAYTM-SRV-ID
X-Tid
Arc-Country
X-FPC
Pramga
X-Frame-Option
X-Ftr-Backend-Server
X-Ftr-Balancer
X-Ftr-Dc
X-Branch-Name
CF-IPCountry
X-Via-NSCOPI
X-ServerName
X-Ftr-Realm
X-StackifyID
X-Ftr-Backend
X-Release
X-ND-Cache
Lfy
Fastly-Drupal-HTML
X-ABtesting
CDN
X-Snapshot-Date
X-LB-ID
X-Ratelimit-Limit
Dynatrace
X-Fastly-Cache-Hits
Requestid
X-Flog
X-Hello
X-DevSite-Last-Modified
Pagetype
X-CACHE-AGE
X-Edge-Server
X-Cc-Req-Id
X-Served-From
Cdn-Host
Cdn-Request-Time
N-Cache
D-Cc-Upstream
X-Cc-Via
X-Request-Url
Warning
X-Scheme
X-Apw-Hits
X-Apw-Access-Token
X-Varnish-Beresp-TTL
X-Apw-Access-Object
X-Apw-Access-Action
X-Edge-IP
X-VC
X-ZONE
X-SB
LB
V-Cache
Proxy-Firewall
Lb
UCS
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
Inserted-Into-Cache-At
X-WA
X-Node-ID
Cache-Cookie-Set-Lfrom
Correlation-Id
X-ElasticPress-Search
WP-Super-Cache
X-Powered-Y
X-Request-URL
X-Check-Cacheable
X-Worker
X-BC
Cache-Cookie-Set-From
Backend-Name
X-App
X-Fastly-Cache-Status
Cache-Cookie-Set-Idcheck