Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-Powered-By
Pragma
CF-Cache-Status
X-XSS-Protection
CF-RAY
Link
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Xss-Protection
X-Cache-Status
X-Generator
Content-Security-Policy-Report-Only
X-Permitted-Cross-Domain-Policies
X-Request-ID
X-Cacheable
X-Template
X-Language
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
Status
X-Content-Security-Policy
Upgrade
X-CDN
Content-Encoding
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
P3p
Xkey
X-Pass-Why
X-Cache-Group
X-Envoy-Upstream-Service-Time
CF-Ray
X-AH-Environment
X-Backend
X-Via
X-Ua-Compatible
X-Age
X-Server
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Server-Powered-By
X-Page-Speed
X-Pingback
X-Ws-Request-Id
EagleId
X-Proxy-Cache
X-Nginx-Cache-Status
X-Hacker
X-UA-Device
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
Cf-Railgun
Grace
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Amz-Version-Id
Report-To
X-LiteSpeed-Cache
X-Rq
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-WebKit-CSP
X-Server-Id
X-Host
X-OneAgent-JS-Injection
X-Device
X-Dns-Prefetch-Control
EagleEye-TraceId
X-Origin-Cache
X-Response-Time
Content-Location
X-Ac
X-Node
Surrogate-Control
X-Vhost
X-Readtime
X-Cloud-Trace-Context
Request-Id
X-Backend-Server
X-Dispatcher
X-Origin-Upstream-Status
X-Cnection
X-HW
X-Application-Context
X-ORACLE-DMS-ECID
Fusion-Template-Id
Fusion-Content-Source
Fusion-Content-Id
Fusion-Component-Id
Fusion-Source
X-Cache-Lookup
X-DataDome
X-ORACLE-DMS-RID
X-Mod-Pagespeed
NEL
X-Ruxit-JS-Agent
Rating
X-Rack-Cache
Edge-Control
X-Country
X-Akam-SW-Version
X-Clacks-Overhead
Pinterest-Generated-By
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Allow
X-TTL
X-Country-Code
X-Instart-Request-ID
Accept-Ch
X-Varnish-TTL
X-DynaTrace
X-Goog-Hash
X-TtlSet
X-Vname
X-PC
X-FTR-Request-ID
Verso
Accept-Ch-Lifetime
X-ESI
X-Powered-By-Plesk
Service-Worker-Allowed
Content-MD5
X-Url
X-Forwarded-Proto
X-Version
X-MS-InvokeApp
X-B3-TraceId
X-Cdn-Fetch
X-Kinja-Revision
X-Kinja-Build
X-Use-Magma
X-Kinja-Server
X-Exp-Id
X-GoogleNews-Bot
X-Kinja
X-GitHub-Request-Id
X-Exp-Variant
Edge-Cache-Tag
RTSS
Ar-Sid
AR-Request-ID
AR-ATIME
AR-CACHE
AR-PoweredBy
X-D2id
X-Px
X-Debug
X-Server-Name
X-Abt-Application-Version
SPRequestGuid
X-Vcache
X-Amz-Server-Side-Encryption
Charset
X-NF-Request-ID
X-Cached
X-Accel-Expires
X-Middleton-Response
Pagespeed
Display
X-Middleton-Display
X-Sol
Response
X-MSEdge-Ref
X-Amz-Rid
X-Vcap-Request-Id
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
Arr-Disable-Session-Affinity
TCN
X-Navigation-Version
X-Powered-CMS
X-SharePointHealthScore
X-Pinterest-Rid
Pinterest-Version
X-Trace
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Fastcgi-Cache
X-Cdn
Realpath
X-VARITI-CCR
Public-Key-Pins
X-Client-IP
Cache-Tag
Access-Control-Request-Method
X-Ser
X-Fastly-Request-ID
MS-Author-Via
S
X-DynaTrace-JS-Agent
Nginx-Cache
X-Shard
SPRequestDuration
SPIisLatency
X-Upstream
X-Id
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
X-Ezoic-Cdn
X-Hp-Webp
X-Content-Type
X-Forwarded-For
X-Amzn-Trace-Id
X-Grace
X-T
X-Amz-Meta-S3cmd-Attrs
X-Edge-O15-RID
Nel
X-Recruiting
DynaTrace
Front-End-Https
X-Hits
Fastcgi-Cache
X-Aspnet-Version
X-Varnish-Age
ServerID
X-Server-ID
X-Dw-Request-Base-Id
MicrosoftSharePointTeamServices
X-Node-Name
X-Mobile-URL
X-Element-Page-Cache
NR-ENABLED
X-Cache-TTL
X-DIS-Request-ID
X-Content-Digest
X-Jurisdiction
X-FTR-Cache-Status
X-Country-Code-Real
X-FTR-Expires
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Hub-Id
Powered
X-Frontend
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
X-FTR-Realm
X-FTR-DC
X-FTR-Balancer
X-FTR-Backend
X-FTR-Backend-Server
Server-Node
Alternate-Protocol
TP-L2-Cache
TP-Cache
Server-Name
X-Logged-In
X-Correlation-Id
AMP-Access-Control-Allow-Source-Origin
X-Request-Processing-Time
X-Request-Received
X-Microsite
X-XRDS-Location
X-Request-Handler-Origin-Region
Backend-Timing
Upgrade-Insecure-Requests
X-ATS-Timestamp
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Content-Options
X-Page-Id
X-Cache-Hit
X-Content-Security-Policy-Report-Only
X-Origin-Server
X-Akamai-Edgescape
X-Revision
X-User-Agent
X-F-Cache
X-Rid
X-Type
Refresh
X-Varnish-Grace
X-CST
X-Zen-Fury
Fastly-Restarts
X-XRDS-LOCATION
X-Content-Powered-By
X-Geo-Country
X-LB-Cache
X-B3-Sampled
X-B
X-URL
X-Shield-Request-Id
X-AppVersion
X-Az
X-Activity-Id
X-N
X-FTR-Cache-Host
PB-RID
PB-PID
Arc-Version
Cache-Status
X-Kinsta-Cache
X-Mobile-Rewrite
X-Webapp-Samesite-None-Activated-N
X-Pad
X-TT
X-Cache-Age
X-AOL-HN
X-Instance
X-WebKit-CSP-Report-Only
X-Debug-Info
Paypal-Debug-Id
X-App-Environment
Actual-Object-TTL
X-Tumblr-User
X-Request-Guid
X-Framework
X-B-Cache
X-Signature
X-Time
X-Tumblr-Pixel-0
X-Jobs
X-Tumblr-Pixel
X-Webkit-Csp
X-Cache-Action
Access-Control-Allow-Method
DC
X-FB-Debug
X-PHP-Backend
X-RateLimit-Remaining
X-Load-Cache
X-Analytics
X-Cached-By
X-Git-Hash
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Tt-Trace-Tag
Surrogate-Key
X-Varnish-Backend
Fastcgi-Useragent
X-Tt-Trace-Host
Host-Header
X-Amz-Replication-Status
X-Contextid
X-IPLB-Instance
MS-CV
X-SS-Set-Cookie
X-ATG-Version
FilterID
X-WA-Info
X-FastCGI-Cache
X-Cache-Key
X-Cluster
Tracecode
X-Accel-Buffering
NGB
Host
X-Response-Served-From
WPE-Backend
X-B3-Traceid
X-Host-Name
X-Mobile
X-Kong-Upstream-Latency
Source
X-Cache-NE
Payment
X-Kong-Proxy-Latency
X-Varnish-Server
Eomportal-Instance
X-Via-JSL
X-Hostname
Frame-Options
X-Region
X-FW-Server
X-Srv
X-FW-Static
X-FW-Type
X-FW-Serve
X-FW-Hash
Xserver
X-Cache-Operation
X-Cache-Rule
X-Cache-2
X-Cache-Enabled
X-Tumblr-Pixel-1
X-Rendered-As
X-Is-Bot
X-Tumblr-Pixel-2
X-Varnish-Hostname
X-Cacheable-TTL
Cache-Tv-Group
Filters
X-IPS-LoggedIn
X-ORACLE-APMCS-TAG
X-GeoIP
X-ORACLE-APMCS-REQUEST-ID
X-NewRelic-App-Data
X-Adobe-Content
X-Adobe-Loc
X-TX-ID
X-RequestSource
X-Origin-Response-Time
X-EdgeConnect-Cache-Status
X-Presslabs-Stats
X-NWS-LOG-UUID
X-Seen-By
Cleartype
X-Ruxit-Js-Agent
Retry-After
Server-Info
X-Cache-TTL-Remaining
X-VCache
Accept-CH
Cache
X-ProcessESI
X-RemovedCookies
Liferay-Portal
X-HTML-Minification-Powered-By
X-RTag
Datacenter
Ms-Operation-Id
X-Source
X-Cache-Control
X-UA
X-Ttl
X-L-Path
X-Dc
X-Environment-Context
X-App-Server
Healthy
X-FireWall-Port
X-Endurance-Cache-Level
From-Origin
X-Cache-Server
X-Upgrade-Enabled
X-CACHE-KEY
Accept-CH-Lifetime
X-APP-VERSION
X-Esi
X-PressLabs-Stats
X-Handled-By
X-RateLimit-Limit
X-Backend-Name
Version
X-Rule
X-Status
X-RN-RSRV
X-Wix-Request-Id
X-ES-SERVER
X-Cache-Var
X-Cache-Var-Map
X-Path-Route
Meta-Geo
Selected-Fe
X-Access
X-Format
X-Tb
X-Timing-Wait
X-Section
X-Proxy-Build
OT-Force-Account-Verify
X-Request-Time
Azure-SiteName
Azure-InstanceId
X-BYPASS-REASON
Akamai-GRN
X-Alternate-Cache-Key
Azure-RegionName
X-ShopId
X-EIG-Tracking-Id
X-ProxyCache-Status
X-PCL
X-ShardId
X-Shopify-Generated-Cart-Token
X-Content-Age
X-Shopify-Stage
X-ProxyCache-Key
X-OCL
Mn-Server-Ip
X-Origin
X-Akamai-Request-ID
X-Human
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Sorting-Hat-PodId
Azure-Version
Azure-SlotName
X-Sorting-Hat-ShopId
X-Proto
Cache-Tags
Srv
X-Storage
Now
X-FW-Dynamic
Origin-Cache-Control
NGX
X-Akamai-Request-ID2
S-Rt
X-AWS-Id
X-Proxy-Cache-Status
Origin-Edge-Control
X-Soup
X-Web-Node
X-Cache-Config
X-FC-Vary-Parameters
X-Time-Microsecs
DB-Nickname
Decoy-Debug-TTL
Decoy-Debug-Status
Decoy-Debug-Key
X-Cache-Host
Node
X-UUID
X-MP-GENERATED-AT
X-LJ-Flow-ID
X-Proxy
X-ServerID
X-Qloud-Router
X-Pubstack
X-SaId
X-JoinUs
X-Hyper-Cache
X-Debug-Cache
X-Cluster-Node
Ec-Rule-Version
X-VWS-Id
X-Generated-By
X-Vgn-Hpd-Reason
X-Hl-Ver
X-Viewer-Country
X-NYM-Debug-Backend
X-Hosted-By
X-Yottaa-Optimizations
X-Yottaa-Metrics
TWC-Locale-Group
TWC-Privacy
Webcakes-App-Name
Webcakes-App-Version
TWC-GeoIP-LatLong
TWC-GeoIP-Country
Property-Id
TWC-Connection-Speed
TWC-Device-Class
X-BCube-Filmed-By
X-RCS-CacheZone
X-IP
X-Locale
X-Origin-Hint
X-Varnish-Hits
X-Generated
X-Redis-Cache
X-CCM
X-Detected-As
X-Site-Version
Webcakes-Region
Cross-Origin-Window-Policy
X-Say-TTL
X-SayCDN-TTL
X-Say-Cacheable
X-Amzn-Remapped-Content-Length
X-Loop
X-Xfnlog-Site
GEO-INFO
X-FB-TRIP-ID
X-TNCMS
X-Akamai-Transformed
Accept-Charset
X-R9-Blue-Green-Version
X-Www-Served-By
L5d-Success-Class
X-NCache
X-Unique-Id
X-CS
Cache-Name
Uber-Trace-Id
Viewport
X-Trafficlayer-App-Name
X-Trafficlayer-App-Scope
X-Drupal-Cache-Tags
Webserver
Time
Cache-Key
X-UA-Device-Type
X-Backend-TTL
X-UnsetCookies
Mime-Version
X-Cache-Remote
X-CDN-Forward
X-From
X-Forwarded-Host
X-Origin-TTL
X-Origin-CC
Accept-Language
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Mode
X-Drupal-Cache-Contexts
Rt-Fastcgi-Cache
X-Cluster-Name
X-B3-Spanid
X-Newrelic-Synthetics
Country
Odigeo-Trace-Id
X-Info
X-Microcachable
X-Whom
X-TT-TIMESTAMP
X-Varnish-Cache-Hits
X-Magnolia-Registration
X-CLOUD-TRACE-CONTEXT
X-Edge-Location
X-NGENIX-Cache
X-ApacheServer
X-Daa-Tunnel
ServedBy
Content-Disposition
X-Geo
X-PERF
X-EC-Lua
X-UPSTREAM-Address
Proxy-Connection
X-Device-Type
Ohc-Cache-HIT
Ohc-File-Size
X-Routing-Service
X-Zipkin-Id
X-No-Session
Cf-Ipcountry
X-Proxied
X-Uri
X-Via-Fastly
X-A-Ccd
X-A-Dam
X-A
W
Viewtype
VivaBuild
X-A-Dcw
X-A-Dgt
X-ARC
X-B-Cookie
X-Application
X-Aed
X-A-Wwc
X-Accel-Expires-Debug
Xc-Version
Rendered-Blocks
BehaviorPad-Version
Content-Script-Type
AsisCache
Apple-News-Services-Request-Url
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Content-Style-Type
Fastcgi-X-Cache-Version
Meta-Geo-Continent
Mobile-Detection-Method
MD5-Digest
Machine
GEO-REGION-INFO
X-Vtex-Remote-Cache
X-CF-Lambda-Fn
X-Rojux
X-S
X-Rocket-Build-Number
X-Rewrite-Enabled
X-Twitter-Response-Tags
X-Request-UUID
X-S-Cookie
X-ScT
X-Trv-Group
X-Transaction
X-SRCache-Key
X-Sigma-Backend
X-Session-Fingerprint
X-Sigma
X-Region-Sid
X-Vdms-Version
X-D
X-Date
X-Connection-Hash
X-VG-WebServer
X-CF-Lambda-Version
X-Vtex-Processado-Em
X-Destination
X-DPWN-IS-SECURE
X-VG-WebCache
X-VG-TLSProxy
X-GeoIP-Country-Code
X-G
X-External-Request-Id
Apple-News-Services-Handled
T-Server
HitType
X-PHP-Host
Geo-Info
X-C
User-Cache-Control
X-Labrador-Cache-Channel
X-Auto-Login
Server-Cache-Control
X-Agile-Id
Server-Surrogate-Control
X-Agile-Age
X-Wikidot-Backend
X-Agile
Powered-By
Ha-Gx-Prefs
Gh-Request-Id
Fastly-Soc-X-Request-Id
Environment
HA-Ipaddr
IsBot
X-Backend-State
Section-Io-Cache
Locid
X-Wikidot-Static-Cache
X-Cache-ASPX
X-Varnish-Authentication
X-VC-Cache
X-Logging-Id
X-Hit
X-Real-IP
X-Render-Time
X-Thanos
X-SIPLIST1
X-Tumblr-Pixel-3
X-Geo-Header
X-Eu-Site
X-CGP
X-Cache-Debug
CDCHOST
X-Bip
X-Contensis-Viewer-Groups
X-CUA
X-Epic-Correlation-Id
X-Distil-CS
X-Developers
X-WebServer
X-App-Name
X-TrackingId
X-Cache-Time
X-Nc
X-GoCache-CacheStatus
X-Rebelmouse-Cache-Control
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
X-Core-Mission
X-TT-LOGID
X-Cms-Context
X-Rebelmouse-Surrogate-Control
X-Debug-Cache-Store
X-Debug-Cookies
X-Fetched-On
X-Gamma-Serve
X-Gen-Mode
X-Fastly-Cache
X-Distributor
X-Debug-Log
X-Dispatcher-Server
X-Clara-WADP
Cache-Host
X-Webstats-RespID
X-LI-UUID
X-BBXSRF
X-Azure-Ref
X-TH-Server
X-AK-Request-ID
X-Trace-Id
X-WADP-Cache
X-Block-Status
X-Cdn-Srv
X-Swa-Ws
X-Servername
X-Sucuri-Cache
X-Cache-Info
X-Cache-Backend
X-Cache-Bucket
X-Generated-In
X-Generation-Time
X-Owner
X-Proxy-Upstream
X-RateLimit-Limit-Second
X-OVcl-Cache
X-OVcl
X-Origin-Date
X-Origin-Expires
X-RateLimit-Remaining-Second
Fastly-SWR
X-Request-URI
Fastly-SIE
X-Varnish-Beresp-Status
X-Urbn-Context-Path
X-Varnish-Beresp-Ttl
X-Clientip
X-Urbn-Site-Id
X-NX-Host
X-NodeID
X-Hnp-Log
Countrycode
X-IN-APIGATEWAY
X-Varnish-Beresp-Grace
X-Hash
X-GeoIP-City
X-We-Are-Hiring
X-IN-APIGATEWAYSSL
X-Instart-Isnd
X-Ms-Version
X-Nginx-Cache-Key
X-Ms-Request-Id
X-Micro-Cache
X-Irp-Debug
X-Key
X-Server-W
X-Cache-URL
RNT-Time
RNT-Machine
Access-Control-Request-Headers
Request-EU
Country-Code
Server-ID
V-Age
True-Client-Country-4JS
X-Li-Pop
Server-Int
Request-Country
X-LI-Proto
IBM-Web2-Location
Kp-EeAlive
Heartbleed
X-User
Locale
Fastly-Backend-Name
Fastly-SSL
Mail-Subject
Memcached
Cdnsip
X-Li-Fabric
X-FW-Version
Cdncip
Web-Mar-Node
We-Hiring
X-VServer
X-Ah-Environment
X-Oneagent-Js-Injection
X-Matched-Rule
Wxu-Next-Hostname
X-JWT-State
X-Has-Esi
X-NU-AKA-ACS-Version
X-TA-CDN-Provider
PFcat
X-Variation
X-Reboot
X-Level-Front-Cache
X-Req
AKAMAI
X-Generated-On
Wxu-Next-Region
X-Is-Gdpr
Wxu-Next-Commit
ServerName
Is-Eu
X-SVT-ORM-RULES
Platform
X-Cache-Tags
Thinkindot-Control
X-Service
X-ServiceProvider
X-Trafficlayer-App-Version
X-Up
X-Nginx-Cache
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-Platform-Server
X-Internal-Host
Server-Host
X-SVT-ORM-VERSION
X-Core-Value
Adler-Geo
X-Old-Content-Length
X-Thinkindot-L3
FNAC-ModuleRouting
Filterid
X-SERVER
X-App-Version
X-Location
X-S-Maxage
X-Lb-Id
X-Response-By
Cache-Hits
RequestId
X-Air-Hostname
X-B3-Parentspanid
X-CSRF-TOKEN
X-Tb-Optimization-Total-Bytes-Saved
X-Var-Ttl
X-Refresh
X-Cache-Expired-At
Pragrma
X-Parent-Response-Time
Group
Memory
ProcessTime
X-NC
X-Tec-Api-Root
X-Tec-Api-Origin
S-Cnection
X-Tec-Api-Version
X-Pjax-Url
X-Ua
X-Wa
Powered-By-ChinaCache
X-CF-Powered-By
X-B3-SpanId
X-Cdn-Forward
User-Agent
X-BACKEND-TTL
Origin
X-Server-IP
X-CSRF-Token
X-Pf-Uncompressing
SRV
X-Sucuri-ID
X-Correlation-ID
PICS-Label
TTL
X-Varnish-Cacheable
Geoip-Latitude
Media-Length
X-Cdn-Request-ID
X-NWS-UUID-VERIFY
X-Vcl-Version
Geoip-City
X-Via-CDN
X-COUNTRY
GeoIp-Country-Code
X-NGINX-Cache
X-Oracle-Dms-Rid
X-Unique-ID
X-Sucuri-Id
X-Developer
Dnion-Transfer-Encoding
X-Servedbyhost
X-Rocket-Nginx-Bypass
X-Device-Os
X-Cdn-Origin
X-Sn-Servicetimems
SN
X-LAGOON
X-Ocache
X-Webkit-CSP
X-Node-Id
X-Cache-Grace
X-Litespeed-Cache
X-Via-Ucdn
On-Server
X-AIR-PT
M-TraceId
X-Varnish-Ttl
Esi-Enabled
X-Reqid
XServer
X-TIME
X-Request-Host
X-Planisys-CDN-Cache
X-HS-Status
X-MSEdge-Flight
X-MSEdge-Features
X-Planisys-CDN-Rules
A
X-Planisys-CDN-TTL
X-Policy
X-FORWARDED-FOR
X-Cache-Status-Check
X-Azure-Ref-OriginShield
X-Request-Start
Cdn
Cloudfront-Viewer-Country
Hostname
X-Oss-Storage-Class
HostName
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Beluga-Trace
X-Beluga-Cache-Status
X-Beluga-Node
X-Beluga-Record
X-Dynatrace
X-Cache-Ttl
X-Fastly-Country-Code
X-Beluga-Response-Time
X-Beluga-Status
Who
Resin-Trace
Rt-Proxy-Cache
X-Ftr-Cache-Host
X-VHOST
X-ServedByHost
CF-Cached-On
Host-ID
X-Method
X-Ratelimit-Remaining
X-Varnish-URL
X-VCL-Version
GeoIP-Country-Code
NtCoent-Length
Magicmarker
X-DC
Pics-Label
Ttl
X-Zone
X-Bc
GeoIP-Latitude
X-APP
X-LiteSpeed-Cache-Control
MIME-Version
Tcn
X-Slack-Backend
X-Fastly-Backend-Reqs
X-Varnish-Url
Cteonnt-Length
GeoIP-City
Load-Balancing
X-DB
X-VarnishDD-TTL
X-DI
X-Action
X-DW
X-Svr
X-RSL
X-RPS
X-RPM
X-Be
X-DSS
X-Newrelic-App-Data
Ohc-Response-Time
X-PF-Uncompressing
X-Server-Time
X-SRV
Amp-Access-Control-Allow-Source-Origin
Arc-Country
DSUID
X-Swift-Error
X-Processor
X-Ftr-Request-Id
X-Ratelimit-Limit
WebServer
Vix-Hermes-Req-Id
X-PAYTM-SRV-ID
X-PJAX-URL
X-VCT
CACHE
Release
X-MServer
X-FPC
X-Dispatch
X-Cache-FS-Status
X-DevSite-Last-Modified
X-Skip-Cache
Pramga
Fastly-Drupal-HTML
Processtime
X-ABtesting
X-Hp-Ccpa-Warning
X-Flog
X-Tid
X-ND-Cache
X-BE
X-Hello
X-WR-MODIFICATION
Servername
X-Dynatrace-Js-Agent
N-Cache
Cdn-Request-Time
X-HostName
X-Configured-By
X-Edge-Server
Cdn-Host
Cache-Provider
X-ID
X-Aicache-OS
X-Frame-Option
CF-IPCountry
X-Bc-Bl
X-SD-PageType
X-Amzn-Remapped-Connection
X-Upstream-Ht
X-StackifyID
X-Amzn-Remapped-Date
Pagetype
X-Upstream-Ct
Requestid
X-Served-From
X-Ftr-Balancer
X-Ftr-Backend-Server
X-Ftr-Dc
X-Ftr-Realm
Lfy
X-WA
X-Fastly-Cache-Hits
X-Ftr-Backend
X-LB-ID
X-Snapshot-Date
Dynatrace
X-Branch-Name
SD-X-WS
CDN
X-CACHE-AGE
X-Backend-Host
X-Cc-Via
X-Request-Url
X-ZONE
X-Cc-Req-Id
X-Edge-IP
X-Cache-Id
X-Apw-Hits
X-Apw-Access-Token
Proxy-Firewall
L
X-Apw-Access-Action
X-Apw-Access-Object
X-Compress-Hint
V-Cache
X-SB
X-VC
Warning
D-Cc-Upstream
X-Varnish-Beresp-TTL
X-SN
X-WPE-Loopback-Upstream-Addr
Lb
Backend-Name
X-ServerName
Section-Io-Origin-Status
Section-Io-Id
Section-Origin-Responded
WZWS-RAY
Section-Io-Origin-Time-Seconds
X-Worker
X-Release
X-Powered-Y
X-Request-URL
X-Check-Cacheable
X-Fastly-Cache-Status
X-Via-NSCOPI
X-App
X-BC
WP-Super-Cache
X-ElasticPress-Search
Correlation-Id