Threat Level: green Handler on Duty: Renato Marinho

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
Link
CF-RAY
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-UA-Compatible
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Request-ID
X-Cache-Status
X-Generator
Content-Security-Policy-Report-Only
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-DNS-Prefetch-Control
X-AspNetMvc-Version
X-Ua-Compatible
X-FRAME-OPTIONS
X-Buckets
Status
X-Content-Security-Policy
X-CDN
Upgrade
Content-Encoding
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Xss-Protection
X-Kinja-Server-Push
Keep-Alive
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
P3p
Xkey
X-Pass-Why
X-Cache-Group
X-AH-Environment
X-Envoy-Upstream-Service-Time
CF-Ray
X-Backend
X-Age
X-Server
X-Via
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Server-Powered-By
X-Page-Speed
X-Pingback
EagleId
X-Proxy-Cache
X-Ws-Request-Id
X-Nginx-Cache-Status
X-UA-Device
X-Hacker
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
Grace
Cf-Railgun
X-Swift-CacheTime
X-Swift-SaveTime
X-Amz-Version-Id
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
X-LiteSpeed-Cache
Report-To
X-Server-Id
X-Rq
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-WebKit-CSP
X-Host
X-Device
EagleEye-TraceId
X-Origin-Cache
X-Response-Time
Content-Location
X-Ac
X-Node
Surrogate-Control
X-OneAgent-JS-Injection
X-Vhost
X-Readtime
Request-Id
X-Cloud-Trace-Context
X-Backend-Server
X-Dispatcher
X-Origin-Upstream-Status
X-Cnection
X-HW
X-ORACLE-DMS-ECID
X-Application-Context
X-DataDome
Fusion-Source
Fusion-Content-Source
Fusion-Component-Id
Fusion-Content-Id
Fusion-Template-Id
X-ORACLE-DMS-RID
X-Cache-Lookup
NEL
X-Mod-Pagespeed
Rating
Edge-Control
X-Rack-Cache
X-Country
X-Akam-SW-Version
X-Clacks-Overhead
Pinterest-Generated-By
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Accept-Ch
X-Ruxit-JS-Agent
X-Varnish-TTL
X-DynaTrace
X-Country-Code
Allow
X-Instart-Request-ID
X-Goog-Hash
X-PC
X-Vname
X-TtlSet
X-FTR-Request-ID
X-ESI
Accept-Ch-Lifetime
Verso
X-TTL
X-Powered-By-Plesk
Service-Worker-Allowed
Content-MD5
X-Url
X-B3-TraceId
X-Forwarded-Proto
X-Version
X-MS-InvokeApp
X-GitHub-Request-Id
X-Use-Magma
X-GoogleNews-Bot
X-Kinja
X-Kinja-Build
X-Exp-Variant
X-Exp-Id
X-Kinja-Server
X-Cdn-Fetch
X-Kinja-Revision
Edge-Cache-Tag
AR-CACHE
Ar-Sid
AR-Request-ID
AR-PoweredBy
AR-ATIME
RTSS
X-Px
X-D2id
X-Debug
X-Abt-Application-Version
X-Server-Name
SPRequestGuid
Charset
X-NF-Request-ID
X-Amz-Server-Side-Encryption
X-Accel-Expires
X-Cached
X-MSEdge-Ref
X-Powered-CMS
X-Amz-Rid
X-TEC-API-ORIGIN
Arr-Disable-Session-Affinity
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Middleton-Response
X-Vcache
X-Sol
X-Middleton-Display
Pagespeed
Response
Display
X-Navigation-Version
X-Vcap-Request-Id
Pinterest-Version
X-Pinterest-Rid
X-SharePointHealthScore
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Trace
TCN
X-Fastcgi-Cache
X-Cdn
X-VARITI-CCR
Realpath
Public-Key-Pins
X-Client-IP
Cache-Tag
Access-Control-Request-Method
X-Ser
X-Fastly-Request-ID
S
X-Upstream
MS-Author-Via
X-DynaTrace-JS-Agent
X-Shard
X-Id
SPRequestDuration
SPIisLatency
Nginx-Cache
X-Hp-Webp
X-Ezoic-Cdn
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Content-Type
X-Forwarded-For
X-T
X-Amz-Meta-S3cmd-Attrs
X-Amzn-Trace-Id
DynaTrace
X-Grace
Nel
X-Recruiting
Front-End-Https
X-Hits
X-Aspnet-Version
Fastcgi-Cache
X-Varnish-Age
ServerID
X-DIS-Request-ID
X-Edge-O15-RID
MicrosoftSharePointTeamServices
X-Mobile-URL
X-Dw-Request-Base-Id
X-Node-Name
X-Element-Page-Cache
NR-ENABLED
X-HS-Hub-Id
X-Content-Digest
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Combine-CSS
Powered
X-Frontend
X-Goog-Metageneration
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-Country-Code-Real
X-Goog-Generation
X-FTR-Expires
X-FTR-Cache-Status
X-Cache-TTL
Server-Name
X-FTR-DC
X-FTR-Backend-Server
X-FTR-Backend
Alternate-Protocol
X-FTR-Balancer
X-FTR-Realm
TP-Cache
Server-Node
TP-L2-Cache
X-Logged-In
X-Jurisdiction
X-Correlation-Id
X-Request-Received
X-Request-Processing-Time
X-Request-Handler-Origin-Region
X-XRDS-Location
AMP-Access-Control-Allow-Source-Origin
X-Microsite
X-ATS-Timestamp
Backend-Timing
Upgrade-Insecure-Requests
X-Server-ID
X-Content-Options
X-Content-Security-Policy-Report-Only
Refresh
X-Origin-Server
X-Rid
X-User-Agent
X-Revision
X-Page-Id
X-F-Cache
X-Cache-Hit
X-Akamai-Edgescape
X-Amz-Apigw-Id
X-Type
X-Amzn-RequestId
X-Shield-Request-Id
X-Ruxit-Js-Agent
X-Varnish-Grace
X-Webapp-Samesite-None-Activated-N
Fastly-Restarts
X-XRDS-LOCATION
X-Zen-Fury
X-Geo-Country
X-Content-Powered-By
X-URL
X-LB-Cache
X-B3-Sampled
X-Az
X-Activity-Id
X-AppVersion
X-B
X-Pad
X-N
X-CST
X-Analytics
X-RateLimit-Remaining
X-Ttl
X-Kinsta-Cache
PB-RID
PB-PID
X-Webkit-Csp
X-Mobile-Rewrite
Arc-Version
Cache-Status
X-Cache-Age
X-TT
X-Debug-Info
X-FTR-Cache-Host
X-AOL-HN
X-WebKit-CSP-Report-Only
X-Oneagent-Js-Injection
X-Tumblr-Pixel-0
X-Tumblr-User
X-Jobs
X-Time
X-Instance
Actual-Object-TTL
Paypal-Debug-Id
X-Signature
X-Tumblr-Pixel
X-B-Cache
X-Framework
X-App-Environment
DC
Access-Control-Allow-Method
X-FB-Debug
X-Request-Guid
X-Cache-Action
X-PHP-Backend
X-Load-Cache
Surrogate-Key
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Varnish-Backend
X-Git-Hash
X-Cached-By
X-Tt-Trace-Tag
Fastcgi-Useragent
Host-Header
X-IPLB-Instance
X-Amz-Replication-Status
X-Tt-Trace-Host
MS-CV
X-Contextid
FilterID
X-SS-Set-Cookie
X-Cluster
X-ATG-Version
X-FastCGI-Cache
X-VCache
X-Response-Served-From
NGB
Tracecode
X-Accel-Buffering
X-WA-Info
Frame-Options
X-Srv
WPE-Backend
X-Varnish-Server
Payment
X-Cache-NE
X-FW-Server
X-Region
X-FW-Type
X-FW-Static
X-FW-Hash
X-Cache-2
Xserver
Host
X-FW-Serve
Eomportal-Instance
X-Mobile
X-Host-Name
Filters
X-Tumblr-Pixel-1
X-RequestSource
X-Tumblr-Pixel-2
X-Varnish-Hostname
X-Cache-Rule
X-Cache-Operation
X-GeoIP
X-IPS-LoggedIn
Cache-Tv-Group
X-Adobe-Content
X-Kong-Upstream-Latency
X-Adobe-Loc
X-Kong-Proxy-Latency
X-Cache-Key
X-TX-ID
X-NewRelic-App-Data
Source
X-Cacheable-TTL
X-Cache-Enabled
X-Is-Bot
X-Rendered-As
X-EdgeConnect-Cache-Status
X-Origin-Response-Time
Cleartype
X-Hostname
X-Via-JSL
X-Seen-By
X-Cache-TTL-Remaining
X-ORACLE-APMCS-REQUEST-ID
X-ORACLE-APMCS-TAG
Cache
Retry-After
X-Presslabs-Stats
X-B3-Traceid
X-Cache-Control
X-ProcessESI
Datacenter
X-RemovedCookies
Server-Info
X-Dc
Healthy
X-CACHE-KEY
Ms-Operation-Id
X-PressLabs-Stats
X-RTag
X-HTML-Minification-Powered-By
X-NWS-LOG-UUID
X-RateLimit-Limit
Liferay-Portal
X-Source
X-UA
X-Environment-Context
X-Cache-Server
X-L-Path
From-Origin
X-Upgrade-Enabled
X-Endurance-Cache-Level
X-Rule
X-Trafficlayer-App-Scope
X-Trafficlayer-App-Name
X-FireWall-Port
X-Wix-Request-Id
X-Status
Version
X-App-Server
X-Handled-By
X-Cache-Var
X-Cache-Var-Map
Meta-Geo
X-RN-RSRV
X-ES-SERVER
X-Path-Route
X-Tb
X-Format
Selected-Fe
X-Section
X-Request-Time
OT-Force-Account-Verify
X-Access
X-Proxy-Build
X-Timing-Wait
X-Alternate-Cache-Key
X-Akamai-Request-ID
X-Origin
Cache-Tags
X-OCL
X-BYPASS-REASON
X-Backend-Name
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Storage
X-ShardId
X-ProxyCache-Key
X-ProxyCache-Status
X-Shopify-Stage
X-ShopId
Akamai-GRN
Azure-InstanceId
X-EIG-Tracking-Id
Azure-RegionName
Azure-SlotName
X-Content-Age
X-Shopify-Generated-Cart-Token
X-Human
X-PCL
Azure-SiteName
X-Sorting-Hat-PodId
Accept-CH
Mn-Server-Ip
Azure-Version
X-Sorting-Hat-ShopId
X-Proto
TWC-Device-Class
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-GeoIP-Country
DB-Nickname
TWC-Connection-Speed
Property-Id
Node
TWC-Privacy
Now
Origin-Edge-Control
NGX
Origin-Cache-Control
Decoy-Debug-Key
Decoy-Debug-Status
X-MP-GENERATED-AT
X-Cache-Config
X-Soup
X-Qloud-Router
X-Debug-Cache
X-Cluster-Node
X-Time-Microsecs
X-UUID
X-Hosted-By
X-Pubstack
X-Proxy-Cache-Status
X-FW-Dynamic
X-Generated-By
X-Origin-Hint
X-FC-Vary-Parameters
X-Hl-Ver
X-Proxy
X-Vgn-Hpd-Reason
X-Viewer-Country
X-Akamai-Request-ID2
X-Redis-Cache
X-AWS-Id
Webcakes-Region
Webcakes-App-Version
X-NYM-Debug-Backend
X-LJ-Flow-ID
X-JoinUs
X-Hyper-Cache
X-VWS-Id
X-Cache-Host
X-ServerID
X-Web-Node
X-RCS-CacheZone
X-SaId
Webcakes-App-Name
Decoy-Debug-TTL
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Generated
X-CCM
X-BCube-Filmed-By
X-Say-Cacheable
X-Say-TTL
X-Xfnlog-Site
X-Varnish-Hits
X-Site-Version
X-SayCDN-TTL
S-Rt
X-Www-Served-By
Cross-Origin-Window-Policy
L5d-Success-Class
X-R9-Blue-Green-Version
X-Locale
X-FB-TRIP-ID
X-Amzn-Remapped-Content-Length
X-APP-VERSION
X-Loop
X-TNCMS
Srv
Ec-Rule-Version
X-Detected-As
Accept-Charset
X-IP
Cache-Name
X-Akamai-Transformed
X-CS
Uber-Trace-Id
Viewport
X-NCache
GEO-INFO
X-Drupal-Cache-Tags
X-Esi
Webserver
Accept-CH-Lifetime
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-UA-Device-Type
Time
Cache-Key
X-Cache-Remote
X-From
X-Unique-Id
Mime-Version
X-Drupal-Cache-Contexts
X-Origin-CC
X-Origin-TTL
X-TT-TIMESTAMP
X-Cluster-Name
Accept-Language
X-Edge-Location
Country
X-Backend-TTL
Odigeo-Trace-Id
X-CDN-Forward
X-Mode
X-Forwarded-Host
Rt-Fastcgi-Cache
X-Microcachable
X-Info
X-CLOUD-TRACE-CONTEXT
X-UnsetCookies
X-EC-Lua
X-Newrelic-Synthetics
X-B3-Spanid
X-Whom
X-Geo
X-Varnish-Cache-Hits
X-Magnolia-Registration
X-ApacheServer
X-PERF
Ohc-File-Size
ServedBy
Ohc-Cache-HIT
Proxy-Connection
X-No-Session
Content-Disposition
X-UPSTREAM-Address
Geo-Info
X-NGENIX-Cache
X-Routing-Service
X-App-Version
Cf-Ipcountry
X-Proxied
X-PHP-Host
X-Zipkin-Id
X-Labrador-Cache-Channel
X-Device-Type
X-ARC
Mobile-Detection-Method
Apple-News-Services-Host
Meta-Geo-Continent
X-Application
Apple-News-Services-Handled
AsisCache
Fastcgi-X-Cache-Version
X-CF-Lambda-Fn
GEO-REGION-INFO
X-DPWN-IS-SECURE
X-Connection-Hash
X-External-Request-Id
X-G
Content-Style-Type
BehaviorPad-Version
Machine
Rendered-Blocks
X-Geo-Header
X-Date
Apple-News-Services-Parsed-Url
X-GeoIP-Country-Code
Content-Script-Type
X-Destination
X-Via-Fastly
MD5-Digest
X-B-Cookie
Apple-News-Services-Request-Url
X-D
X-A-Dgt
X-Rewrite-Enabled
X-Rocket-Build-Number
X-Rojux
X-Transaction
X-Trv-Group
T-Server
X-Twitter-Response-Tags
X-S
X-Vtex-Remote-Cache
X-Sigma
X-Sigma-Backend
Viewtype
X-Session-Fingerprint
VivaBuild
X-S-Cookie
X-ScT
X-Vtex-Processado-Em
X-A
X-VG-TLSProxy
X-CF-Lambda-Version
X-Vdms-Version
X-A-Wwc
X-Accel-Expires-Debug
X-Aed
W
X-VG-WebCache
X-A-Dcw
X-VG-WebServer
X-Region-Sid
X-A-Ccd
X-SRCache-Key
Xc-Version
X-A-Dam
X-Nc
X-Uri
X-Cache-Time
X-C
User-Cache-Control
X-Cache-Debug
X-App-Name
HA-Ipaddr
X-Contensis-Viewer-Groups
X-Render-Time
X-Developers
X-WebServer
X-Distil-CS
X-Logging-Id
X-Request-UUID
X-Varnish-Authentication
X-Wikidot-Backend
Powered-By
X-Agile-Age
X-CUA
CDCHOST
Gh-Request-Id
Ha-Gx-Prefs
X-VC-Cache
Fastly-Soc-X-Request-Id
X-Agile-Id
X-Auto-Login
X-Tumblr-Pixel-3
X-Thanos
X-Agile
Environment
X-TrackingId
X-Hit
Server-Cache-Control
Locid
X-Bip
X-Sucuri-Cache
X-SIPLIST1
X-Cache-ASPX
X-Epic-Correlation-Id
Server-Surrogate-Control
IsBot
X-Wikidot-Static-Cache
X-Eu-Site
X-CGP
X-Real-IP
Access-Control-Request-Headers
HitType
X-Cache-URL
X-Cdn-Srv
X-Block-Status
Wxu-Next-Region
X-BBXSRF
X-Azure-Ref
X-AK-Request-ID
Wxu-Next-Hostname
Wxu-Next-Commit
X-Cache-Info
X-Cache-Bucket
Web-Mar-Node
X-Cache-Backend
We-Hiring
X-Irp-Debug
X-RateLimit-Limit-Second
X-Proxy-Upstream
X-RateLimit-Remaining-Second
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Owner
X-OVcl-Cache
X-NX-Host
X-NodeID
X-Origin-Date
X-Origin-Expires
X-OVcl
X-Req
X-Request-URI
X-User
X-Urbn-Site-Id
X-Webstats-RespID
X-WADP-Cache
X-We-Are-Hiring
X-Urbn-Context-Path
X-TT-LOGID
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Swa-Ws
X-Trace-Id
X-Nginx-Cache-Key
X-Ms-Version
X-Dispatcher-Server
X-Debug-Log
X-Distributor
X-Fastly-Cache
X-FW-Version
X-Debug-Cookies
X-Debug-Cache-Store
X-Cms-Context
X-Clientip
X-Core-Mission
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
X-Gamma-Serve
X-Gen-Mode
X-Instart-Isnd
X-IN-APIGATEWAYSSL
X-Micro-Cache
V-Age
X-Ms-Request-Id
X-IN-APIGATEWAY
X-Hnp-Log
X-Generated-In
X-Generation-Time
X-GeoIP-City
X-Hash
X-Clara-WADP
X-Backend-State
Heartbleed
FNAC-ModuleRouting
Fastly-SIE
Countrycode
IBM-Web2-Location
Kp-EeAlive
Memcached
Mail-Subject
Locale
Fastly-SSL
Country-Code
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
X-Daa-Tunnel
X-Varnish-Beresp-Ttl
AKAMAI
Cdnsip
Cdncip
Cache-Host
Request-Country
Fastly-SWR
RNT-Time
RNT-Machine
True-Client-Country-4JS
Request-EU
Server-Int
Section-Io-Cache
Server-ID
X-GoCache-CacheStatus
X-LI-UUID
X-LI-Proto
Adler-Geo
X-Platform-Server
X-Core-Value
X-Location
X-Variation
X-VServer
Thinkindot-CacheControl
ServerName
X-TH-Server
X-Has-Esi
X-Nginx-Cache
X-Internal-Host
X-JWT-State
X-Is-Gdpr
Thinkindot-Control
X-Level-Front-Cache
X-Li-Pop
X-ServiceProvider
X-Li-Fabric
X-Trafficlayer-App-Version
X-Generated-On
X-Thinkindot-L3
X-Up
Thinkindot-CacheControl-Type
X-NU-AKA-ACS-Version
X-Service
X-Fetched-On
X-Cache-Tags
Server-Host
Is-Eu
PFcat
Platform
Fastly-Backend-Name
X-Server-W
X-Key
X-Old-Content-Length
X-Matched-Rule
X-B3-Parentspanid
X-Lb-Id
X-Servername
X-Refresh
X-Reboot
X-S-Maxage
Cache-Hits
X-SERVER
X-TA-CDN-Provider
RequestId
X-Response-By
X-CSRF-TOKEN
X-B3-SpanId
Filterid
X-Cdn-Forward
X-CF-Powered-By
X-Tec-Api-Root
X-Tec-Api-Version
X-Tec-Api-Origin
ProcessTime
X-Server-IP
X-Correlation-ID
X-Air-Hostname
X-Tb-Optimization-Total-Bytes-Saved
X-Parent-Response-Time
X-Var-Ttl
X-Wa
Group
X-Pjax-Url
X-BACKEND-TTL
Pragrma
X-Cache-Expired-At
X-Ua
X-Unique-ID
X-NC
X-Cdn-Request-ID
Origin
Memory
User-Agent
X-Sucuri-Id
Media-Length
S-Cnection
Powered-By-ChinaCache
TTL
X-CSRF-Token
SRV
X-Vcl-Version
X-Pf-Uncompressing
Geoip-Latitude
X-COUNTRY
X-NGINX-Cache
GeoIp-Country-Code
SN
X-Varnish-Cacheable
PICS-Label
X-Rocket-Nginx-Bypass
X-AIR-PT
X-Reqid
Esi-Enabled
X-Servedbyhost
X-Sucuri-ID
X-Policy
X-Via-CDN
Geoip-City
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
X-Webkit-CSP
X-Litespeed-Cache
X-Planisys-CDN-Rules
X-NWS-UUID-VERIFY
X-Request-Start
X-Developer
X-Azure-Ref-OriginShield
M-TraceId
X-HS-Status
X-Via-Ucdn
HostName
X-TIME
X-Ftr-Cache-Host
XServer
X-LAGOON
X-Device-Os
X-Ocache
X-Cdn-Origin
X-Cache-Grace
Rt-Proxy-Cache
X-Sn-Servicetimems
Dnion-Transfer-Encoding
X-Node-Id
X-FORWARDED-FOR
On-Server
X-Fastly-Country-Code
Tcn
X-MSEdge-Flight
Magicmarker
X-MSEdge-Features
A
Who
X-Cache-Ttl
Resin-Trace
Cdn
X-Request-Host
X-Method
X-VHOST
CF-Cached-On
Cloudfront-Viewer-Country
X-ServedByHost
Pics-Label
Load-Balancing
X-Cache-Status-Check
X-Beluga-Record
X-Beluga-Node
X-Beluga-Response-Time
GeoIP-Country-Code
X-Beluga-Trace
X-Beluga-Cache-Status
Hostname
X-Beluga-Status
X-Oss-Server-Time
X-Oss-Object-Type
X-Oss-Storage-Class
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
DSUID
X-Svr
Ohc-Response-Time
X-Zone
X-APP
NtCoent-Length
X-Be
X-VCL-Version
X-Bc
GeoIP-Latitude
X-MServer
X-VCT
Release
MIME-Version
X-Oracle-Dms-Rid
X-Fastly-Backend-Reqs
X-VarnishDD-TTL
X-Varnish-URL
Ttl
GeoIP-City
Vix-Hermes-Req-Id
X-PF-Uncompressing
Cteonnt-Length
Host-ID
X-Varnish-Url
X-LiteSpeed-Cache-Control
X-Hp-Ccpa-Warning
X-Varnish-Ttl
X-DC
X-Newrelic-App-Data
X-Ftr-Request-Id
X-PJAX-URL
X-SRV
X-Slack-Backend
X-Configured-By
WebServer
Amp-Access-Control-Allow-Source-Origin
CACHE
X-HostName
X-Action
X-Dynatrace
X-Swift-Error
Processtime
X-SD-PageType
X-Upstream-Ht
X-Aicache-OS
X-BE
SD-X-WS
X-Upstream-Ct
X-Ratelimit-Remaining
X-WR-MODIFICATION
Servername
X-Dynatrace-Js-Agent
X-DB
X-RSL
X-DI
X-DW
X-RPM
X-RPS
X-DSS
Arc-Country
X-Processor
X-Server-Time
X-Skip-Cache
X-PAYTM-SRV-ID
X-Dispatch
Pramga
X-Cache-FS-Status
Cache-Provider
X-SN
X-Cache-Id
L
X-Compress-Hint
X-Tid
X-ID
X-Frame-Option
X-Ftr-Backend-Server
X-Ftr-Backend
X-Ftr-Dc
X-Ftr-Balancer
X-LB-ID
Dynatrace
X-StackifyID
X-Ftr-Realm
CF-IPCountry
X-DevSite-Last-Modified
X-Flog
X-Hello
X-ND-Cache
X-ABtesting
Fastly-Drupal-HTML
X-Via-NSCOPI
X-Ratelimit-Limit
X-FPC
X-Release
X-ServerName
X-Snapshot-Date
X-Fastly-Cache-Hits
X-Branch-Name
Lfy
CDN
Pagetype
Requestid
X-CACHE-AGE
X-Request-Url
Cdn-Host
Cdn-Request-Time
Proxy-Firewall
X-Varnish-Beresp-TTL
X-Apw-Access-Object
X-Cc-Via
X-Apw-Access-Action
X-Apw-Access-Token
X-Apw-Hits
X-Scheme
X-Cc-Req-Id
X-SB
X-Served-From
X-ZONE
X-Edge-IP
X-VC
V-Cache
X-Edge-Server
LB
D-Cc-Upstream
Warning
N-Cache
X-Fpc
X-Bc-Bl
X-BC
X-Worker
X-WA
X-Node-ID
X-Check-Cacheable
X-ElasticPress-Search
X-Request-URL
X-Powered-Y
Lb
UCS
Backend-Name
WP-Super-Cache
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-From
X-App
Correlation-Id
X-Fastly-Cache-Status