Threat Level: green Handler on Duty: Renato Marinho

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
Link
CF-RAY
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-UA-Compatible
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Request-ID
X-Cache-Status
X-Generator
Content-Security-Policy-Report-Only
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-DNS-Prefetch-Control
X-AspNetMvc-Version
X-Ua-Compatible
X-FRAME-OPTIONS
X-Buckets
Status
X-Content-Security-Policy
X-CDN
Content-Encoding
Upgrade
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Xss-Protection
X-Kinja-Server-Push
Keep-Alive
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
P3p
Xkey
X-Pass-Why
X-Cache-Group
X-AH-Environment
X-Envoy-Upstream-Service-Time
CF-Ray
X-Backend
X-Age
X-Server
X-Via
X-Amz-Id-2
X-Amz-Request-Id
X-Server-Powered-By
X-Robots-Tag
X-Page-Speed
X-Pingback
EagleId
X-Ws-Request-Id
X-Nginx-Cache-Status
X-Proxy-Cache
X-UA-Device
X-Hacker
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
Grace
Cf-Railgun
X-Swift-SaveTime
X-Swift-CacheTime
X-Amz-Version-Id
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
Report-To
X-LiteSpeed-Cache
X-Rq
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-WebKit-CSP
X-Server-Id
X-Host
X-Device
EagleEye-TraceId
X-Origin-Cache
X-OneAgent-JS-Injection
X-Response-Time
Content-Location
X-Ac
X-Node
Surrogate-Control
X-Vhost
X-Readtime
Request-Id
X-Cloud-Trace-Context
X-Backend-Server
X-Dispatcher
X-Origin-Upstream-Status
X-Cnection
X-HW
X-ORACLE-DMS-ECID
X-Application-Context
X-DataDome
Fusion-Template-Id
Fusion-Source
Fusion-Content-Source
Fusion-Content-Id
Fusion-Component-Id
X-ORACLE-DMS-RID
X-Cache-Lookup
NEL
X-Mod-Pagespeed
Edge-Control
X-Rack-Cache
Rating
X-Country
X-Akam-SW-Version
X-Clacks-Overhead
Pinterest-Generated-By
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Ruxit-JS-Agent
Accept-Ch
X-Varnish-TTL
X-DynaTrace
X-Country-Code
Allow
X-Instart-Request-ID
X-Goog-Hash
X-Vname
X-TtlSet
X-PC
X-FTR-Request-ID
X-TTL
X-ESI
Accept-Ch-Lifetime
Verso
X-Powered-By-Plesk
Service-Worker-Allowed
X-Url
Content-MD5
X-B3-TraceId
X-Forwarded-Proto
X-Version
X-MS-InvokeApp
X-GitHub-Request-Id
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-Kinja
X-Cdn-Fetch
X-Exp-Id
X-Exp-Variant
X-GoogleNews-Bot
X-Kinja-Build
Edge-Cache-Tag
AR-ATIME
AR-Request-ID
AR-CACHE
Ar-Sid
AR-PoweredBy
RTSS
X-Px
X-D2id
X-Debug
X-Abt-Application-Version
X-Server-Name
SPRequestGuid
Charset
X-NF-Request-ID
X-Vcache
X-Amz-Server-Side-Encryption
X-Accel-Expires
X-Cached
X-MSEdge-Ref
X-Powered-CMS
X-Amz-Rid
X-Sol
X-Middleton-Response
X-Middleton-Display
Response
Pagespeed
Display
X-TEC-API-VERSION
Arr-Disable-Session-Affinity
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Vcap-Request-Id
X-Navigation-Version
X-Pinterest-Rid
Pinterest-Version
X-SharePointHealthScore
TCN
X-Trace
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Fastcgi-Cache
X-Cdn
Realpath
X-VARITI-CCR
Public-Key-Pins
X-Client-IP
Cache-Tag
Access-Control-Request-Method
S
X-Ser
X-Fastly-Request-ID
X-Upstream
X-DynaTrace-JS-Agent
MS-Author-Via
X-Shard
SPRequestDuration
X-Id
SPIisLatency
Nginx-Cache
X-Hp-Webp
X-Ezoic-Cdn
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
X-Content-Type
X-Forwarded-For
X-T
X-Amzn-Trace-Id
Nel
DynaTrace
X-Amz-Meta-S3cmd-Attrs
X-Grace
X-Recruiting
Front-End-Https
X-Hits
Fastcgi-Cache
X-Aspnet-Version
X-Varnish-Age
X-Server-ID
ServerID
X-DIS-Request-ID
X-Edge-O15-RID
MicrosoftSharePointTeamServices
X-Dw-Request-Base-Id
X-Mobile-URL
X-Node-Name
X-Element-Page-Cache
NR-ENABLED
X-Content-Digest
X-Country-Code-Real
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Content-Id
X-FTR-Cache-Status
X-HS-Combine-CSS
X-FTR-Expires
X-Frontend
Powered
X-Cache-TTL
X-GUploader-UploadID
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Length
X-FTR-Balancer
X-FTR-DC
Server-Name
X-FTR-Backend
Alternate-Protocol
X-FTR-Backend-Server
X-FTR-Realm
TP-Cache
TP-L2-Cache
X-Logged-In
Server-Node
X-Jurisdiction
X-XRDS-Location
X-Correlation-Id
X-Request-Processing-Time
X-Request-Received
X-Request-Handler-Origin-Region
X-Microsite
Upgrade-Insecure-Requests
AMP-Access-Control-Allow-Source-Origin
X-ATS-Timestamp
Backend-Timing
X-Page-Id
X-Content-Options
X-Cache-Hit
X-Origin-Server
Refresh
X-Amzn-RequestId
X-Content-Security-Policy-Report-Only
X-User-Agent
X-Amz-Apigw-Id
X-Rid
X-F-Cache
X-Revision
X-Type
X-Akamai-Edgescape
X-Shield-Request-Id
X-Varnish-Grace
X-Webapp-Samesite-None-Activated-N
Fastly-Restarts
X-XRDS-LOCATION
X-Zen-Fury
X-Content-Powered-By
X-Geo-Country
X-B3-Sampled
X-URL
X-LB-Cache
X-Az
X-Activity-Id
X-AppVersion
X-B
X-Pad
X-RateLimit-Remaining
X-Analytics
X-N
X-CST
X-FTR-Cache-Host
PB-PID
PB-RID
X-Kinsta-Cache
X-Ruxit-Js-Agent
X-Webkit-Csp
Arc-Version
X-Mobile-Rewrite
Cache-Status
X-Cache-Age
X-TT
X-Debug-Info
X-AOL-HN
X-Tumblr-Pixel
X-Time
X-Framework
X-Jobs
X-Instance
X-Request-Guid
X-Tumblr-Pixel-0
X-Tumblr-User
X-WebKit-CSP-Report-Only
Paypal-Debug-Id
Actual-Object-TTL
DC
X-Signature
X-B-Cache
Access-Control-Allow-Method
X-FB-Debug
X-PHP-Backend
X-App-Environment
X-Cache-Action
X-Load-Cache
Surrogate-Key
X-Git-Hash
X-Varnish-Backend
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Ttl
X-Cached-By
Host-Header
X-Tt-Trace-Tag
Fastcgi-Useragent
X-Contextid
MS-CV
X-Amz-Replication-Status
FilterID
X-IPLB-Instance
X-Tt-Trace-Host
X-SS-Set-Cookie
X-Cluster
X-ATG-Version
X-FastCGI-Cache
Tracecode
NGB
X-Accel-Buffering
X-WA-Info
X-Response-Served-From
WPE-Backend
Frame-Options
X-Varnish-Server
X-Cache-NE
Payment
X-Srv
Eomportal-Instance
X-Host-Name
X-Cache-2
X-Mobile
Host
Xserver
X-FW-Type
X-FW-Server
X-FW-Static
X-FW-Serve
X-FW-Hash
X-Region
Cache-Tv-Group
X-Kong-Upstream-Latency
Filters
X-Kong-Proxy-Latency
X-Cacheable-TTL
X-Tumblr-Pixel-1
X-RequestSource
X-Tumblr-Pixel-2
X-Varnish-Hostname
X-Cache-Rule
X-Cache-Operation
X-Rendered-As
X-Is-Bot
X-Adobe-Content
X-Adobe-Loc
X-GeoIP
X-IPS-LoggedIn
Source
X-Oneagent-Js-Injection
X-Cache-Enabled
X-TX-ID
X-Cache-Key
X-NewRelic-App-Data
X-Hostname
Cleartype
X-Seen-By
X-Origin-Response-Time
X-EdgeConnect-Cache-Status
X-Via-JSL
X-ORACLE-APMCS-REQUEST-ID
X-ORACLE-APMCS-TAG
X-Cache-TTL-Remaining
X-VCache
Cache
Retry-After
Server-Info
X-Presslabs-Stats
X-Cache-Control
X-B3-Traceid
X-HTML-Minification-Powered-By
X-ProcessESI
Healthy
Datacenter
X-RemovedCookies
X-CACHE-KEY
X-PressLabs-Stats
Ms-Operation-Id
X-RTag
X-NWS-LOG-UUID
X-RateLimit-Limit
Liferay-Portal
X-Dc
X-Source
X-UA
X-Cache-Server
X-FireWall-Port
From-Origin
X-Trafficlayer-App-Name
X-Trafficlayer-App-Scope
X-Rule
X-Endurance-Cache-Level
X-L-Path
X-Environment-Context
X-Upgrade-Enabled
X-Wix-Request-Id
X-Status
Version
X-Handled-By
X-App-Server
Meta-Geo
X-RN-RSRV
X-Path-Route
X-ES-SERVER
X-Cache-Var
X-Cache-Var-Map
X-Section
X-Tb
X-Format
X-Request-Time
X-Access
Selected-Fe
X-Proxy-Build
OT-Force-Account-Verify
X-Timing-Wait
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Proto
X-Sorting-Hat-ShopId
X-Content-Age
Accept-CH
X-Storage
X-EIG-Tracking-Id
X-ShopId
X-Human
X-Akamai-Request-ID
X-ProxyCache-Status
X-ProxyCache-Key
X-PCL
X-OCL
X-Alternate-Cache-Key
X-Backend-Name
X-Sorting-Hat-PodId
X-BYPASS-REASON
X-Shopify-Stage
X-Shopify-Generated-Cart-Token
X-ShardId
Cache-Tags
X-Origin
Mn-Server-Ip
Azure-Version
Now
Azure-SlotName
Azure-SiteName
TWC-Connection-Speed
S-Rt
Property-Id
Origin-Edge-Control
X-VWS-Id
Origin-Cache-Control
Decoy-Debug-Status
X-UUID
X-Generated-By
TWC-Device-Class
X-FW-Dynamic
NGX
X-FC-Vary-Parameters
Decoy-Debug-TTL
X-Web-Node
Node
X-Vgn-Hpd-Reason
Decoy-Debug-Key
X-Pubstack
X-LJ-Flow-ID
X-AWS-Id
X-Origin-Hint
X-RCS-CacheZone
X-JoinUs
Azure-RegionName
X-SaId
X-Cache-Config
X-Cache-Host
X-ServerID
X-MP-GENERATED-AT
X-NYM-Debug-Backend
X-Qloud-Router
X-Proxy
Webcakes-App-Name
Webcakes-App-Version
TWC-Privacy
TWC-Locale-Group
TWC-GeoIP-LatLong
X-Hl-Ver
X-Time-Microsecs
X-Akamai-Request-ID2
X-Soup
X-Proxy-Cache-Status
X-Debug-Cache
Webcakes-Region
TWC-GeoIP-Country
Ec-Rule-Version
X-Yottaa-Optimizations
Azure-InstanceId
X-Yottaa-Metrics
Akamai-GRN
X-Redis-Cache
X-Varnish-Hits
X-Detected-As
X-Viewer-Country
X-Site-Version
X-CCM
X-Generated
X-Xfnlog-Site
X-SayCDN-TTL
X-Www-Served-By
X-Cluster-Node
X-BCube-Filmed-By
Cross-Origin-Window-Policy
DB-Nickname
X-Say-TTL
X-Locale
X-Say-Cacheable
X-Hyper-Cache
X-IP
X-Hosted-By
X-FB-TRIP-ID
X-Amzn-Remapped-Content-Length
X-TNCMS
X-Loop
X-R9-Blue-Green-Version
L5d-Success-Class
Srv
X-APP-VERSION
Cache-Name
X-Akamai-Transformed
Viewport
Accept-Charset
X-CS
Uber-Trace-Id
GEO-INFO
X-NCache
X-Drupal-Cache-Tags
X-Esi
Accept-CH-Lifetime
Webserver
X-UA-Device-Type
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-From
Cache-Key
X-Cache-Remote
X-Unique-Id
Time
Mime-Version
X-Cluster-Name
X-Origin-TTL
X-Drupal-Cache-Contexts
X-Origin-CC
X-TT-TIMESTAMP
X-Edge-Location
Accept-Language
Country
X-Backend-TTL
X-CDN-Forward
X-Mode
Odigeo-Trace-Id
X-Forwarded-Host
Rt-Fastcgi-Cache
X-Microcachable
X-CLOUD-TRACE-CONTEXT
X-EC-Lua
X-Info
X-UnsetCookies
X-Newrelic-Synthetics
X-B3-Spanid
X-Whom
X-Varnish-Cache-Hits
X-PERF
Ohc-Cache-HIT
X-Magnolia-Registration
Ohc-File-Size
X-ApacheServer
X-No-Session
Proxy-Connection
Content-Disposition
ServedBy
X-Litespeed-Cache
X-Geo
X-UPSTREAM-Address
X-NGENIX-Cache
Geo-Info
Cf-Ipcountry
X-Labrador-Cache-Channel
X-Zipkin-Id
X-Routing-Service
X-Proxied
X-PHP-Host
X-Device-Type
X-App-Version
X-A-Dgt
X-A-Dcw
X-A-Wwc
X-ARC
X-Destination
X-Request-UUID
X-Via-Fastly
X-CF-Lambda-Version
X-A
Apple-News-Services-Handled
X-CF-Lambda-Fn
X-A-Ccd
X-A-Dam
Rendered-Blocks
X-Accel-Expires-Debug
Mobile-Detection-Method
X-Twitter-Response-Tags
X-Sigma-Backend
X-Connection-Hash
X-Session-Fingerprint
X-Rojux
X-Sigma
Machine
X-D
X-Date
X-Aed
Meta-Geo-Continent
X-Application
X-Transaction
MD5-Digest
X-Trv-Group
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
X-Real-IP
Content-Script-Type
Content-Style-Type
Viewtype
X-Vtex-Processado-Em
X-G
VivaBuild
X-Vtex-Remote-Cache
T-Server
Fastcgi-X-Cache-Version
Xc-Version
X-GeoIP-Country-Code
X-Rocket-Build-Number
X-Geo-Header
X-S-Cookie
X-Rewrite-Enabled
X-S
X-B-Cookie
X-Vdms-Version
GEO-REGION-INFO
BehaviorPad-Version
AsisCache
X-DPWN-IS-SECURE
Apple-News-Services-Request-Url
X-VG-TLSProxy
X-SRCache-Key
X-Region-Sid
W
X-VG-WebServer
X-VG-WebCache
X-External-Request-Id
X-ScT
X-C
X-Uri
User-Cache-Control
X-Nc
X-Cache-Time
X-Logging-Id
Gh-Request-Id
X-Sucuri-Cache
X-Epic-Correlation-Id
X-VC-Cache
X-Auto-Login
X-Cache-Debug
X-Eu-Site
X-Distil-CS
X-Cache-ASPX
Environment
X-Wikidot-Backend
X-Wikidot-Static-Cache
Fastly-Soc-X-Request-Id
X-WebServer
X-Bip
X-CGP
Server-Cache-Control
Server-Surrogate-Control
CDCHOST
X-Varnish-Authentication
X-App-Name
X-Render-Time
Locid
X-Agile
IsBot
X-CUA
X-SIPLIST1
X-Backend-State
X-Agile-Id
X-Agile-Age
X-Developers
X-TrackingId
X-Contensis-Viewer-Groups
Ha-Gx-Prefs
Powered-By
X-Tumblr-Pixel-3
X-Thanos
X-Hit
Fastly-SSL
HA-Ipaddr
Access-Control-Request-Headers
X-GoCache-CacheStatus
HitType
V-Age
Web-Mar-Node
X-Azure-Ref
Wxu-Next-Region
Wxu-Next-Hostname
Wxu-Next-Commit
We-Hiring
X-AK-Request-ID
X-Clientip
True-Client-Country-4JS
X-Nginx-Cache-Key
X-Ms-Version
X-Ms-Request-Id
X-Req
X-Distributor
X-NodeID
X-Debug-Log
X-Debug-Cookies
X-Origin-Date
X-Dispatcher-Server
X-NX-Host
X-Location
X-LI-UUID
X-Gen-Mode
X-Key
X-Hash
X-Generated-In
X-Generation-Time
X-Gamma-Serve
X-FW-Version
X-Fastly-Cache
X-LI-Proto
X-Li-Pop
X-Li-Fabric
X-Origin-Expires
X-OVcl
X-GeoIP-City
X-Instart-Isnd
X-Cms-Context
X-Rebelmouse-Surrogate-Control
X-IN-APIGATEWAYSSL
X-Irp-Debug
X-Cdn-Srv
X-Block-Status
X-Cache-Backend
X-Cache-Bucket
X-Cache-Info
X-Request-URI
X-IN-APIGATEWAY
X-OVcl-Cache
X-Owner
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Hnp-Log
X-Core-Mission
X-Rebelmouse-Cache-Control
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Proxy-Upstream
X-BBXSRF
Cache-Host
X-Varnish-Beresp-Status
X-Varnish-Beresp-Ttl
FNAC-ModuleRouting
Fastly-SWR
Heartbleed
IBM-Web2-Location
Mail-Subject
X-TH-Server
Kp-EeAlive
X-Varnish-Beresp-Grace
Fastly-SIE
Fastly-Backend-Name
X-TT-LOGID
X-Trace-Id
X-SVT-ORM-VERSION
X-Swa-Ws
AKAMAI
X-SVT-ORM-RULES
Countrycode
Country-Code
Cdnsip
Cdncip
X-Urbn-Context-Path
Locale
RNT-Machine
X-VServer
Server-Int
RNT-Time
X-Daa-Tunnel
Server-ID
Section-Io-Cache
Request-Country
Request-EU
X-User
X-Urbn-Site-Id
X-Generated-On
X-We-Are-Hiring
X-Fetched-On
ServerName
X-Trafficlayer-App-Version
X-Thinkindot-L3
X-Clara-WADP
X-Has-Esi
X-Webstats-RespID
X-Level-Front-Cache
X-JWT-State
X-Variation
X-Up
X-Is-Gdpr
X-Internal-Host
X-WADP-Cache
Thinkindot-Control
X-Nginx-Cache
X-Core-Value
Adler-Geo
X-ServiceProvider
X-Service
X-Old-Content-Length
Memcached
X-NU-AKA-ACS-Version
Platform
Server-Host
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-Reboot
X-Platform-Server
Is-Eu
PFcat
X-Cache-URL
X-Matched-Rule
X-Cache-Tags
X-Micro-Cache
X-Server-W
X-B3-Parentspanid
X-Refresh
X-S-Maxage
X-Lb-Id
X-Response-By
X-Servername
Cache-Hits
X-SERVER
X-TA-CDN-Provider
RequestId
X-CSRF-TOKEN
X-Cdn-Forward
X-CF-Powered-By
X-B3-SpanId
Filterid
X-Tb-Optimization-Total-Bytes-Saved
X-Tec-Api-Version
X-Air-Hostname
X-Tec-Api-Origin
X-Tec-Api-Root
ProcessTime
X-Server-IP
X-Parent-Response-Time
X-Correlation-ID
X-Ua
X-Cache-Expired-At
X-BACKEND-TTL
Pragrma
X-Var-Ttl
X-Pjax-Url
X-Wa
Group
X-Unique-ID
Media-Length
Origin
X-NC
X-Sucuri-Id
User-Agent
X-Cdn-Request-ID
Memory
S-Cnection
Powered-By-ChinaCache
X-CSRF-Token
TTL
SRV
Geoip-Latitude
X-Pf-Uncompressing
X-COUNTRY
X-NGINX-Cache
GeoIp-Country-Code
X-Vcl-Version
X-Reqid
X-Varnish-Cacheable
SN
X-Rocket-Nginx-Bypass
Esi-Enabled
PICS-Label
X-Servedbyhost
X-AIR-PT
X-Sucuri-ID
Geoip-City
X-Policy
X-Webkit-CSP
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
X-NWS-UUID-VERIFY
X-Request-Start
X-Via-Ucdn
X-Via-CDN
X-Developer
X-Azure-Ref-OriginShield
X-HS-Status
M-TraceId
X-TIME
XServer
HostName
X-Node-Id
X-Cache-Grace
X-Cdn-Origin
X-Device-Os
X-Sn-Servicetimems
X-Ocache
Rt-Proxy-Cache
Dnion-Transfer-Encoding
X-LAGOON
X-FORWARDED-FOR
X-Fastly-Country-Code
On-Server
Tcn
Resin-Trace
A
X-Method
X-MSEdge-Features
Who
Magicmarker
X-Cache-Ttl
Cdn
X-Request-Host
X-MSEdge-Flight
X-VHOST
X-Ftr-Cache-Host
Cloudfront-Viewer-Country
CF-Cached-On
Pics-Label
X-ServedByHost
Load-Balancing
X-Cache-Status-Check
GeoIP-Country-Code
Hostname
X-Beluga-Trace
X-Beluga-Status
X-Beluga-Response-Time
X-Beluga-Cache-Status
X-Beluga-Record
X-Beluga-Node
X-DC
X-Oss-Object-Type
X-Oss-Storage-Class
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
Ohc-Response-Time
GeoIP-Latitude
X-Zone
DSUID
X-VCL-Version
X-Bc
X-Svr
X-Be
NtCoent-Length
X-APP
Release
MIME-Version
X-VCT
X-MServer
X-Oracle-Dms-Rid
Vix-Hermes-Req-Id
X-Fastly-Backend-Reqs
X-VarnishDD-TTL
Host-ID
X-Varnish-Url
X-Varnish-URL
GeoIP-City
Cteonnt-Length
Ttl
X-PF-Uncompressing
X-Varnish-Ttl
X-Hp-Ccpa-Warning
X-LiteSpeed-Cache-Control
X-Newrelic-App-Data
X-Configured-By
X-SRV
Amp-Access-Control-Allow-Source-Origin
WebServer
X-Slack-Backend
X-Ftr-Request-Id
X-PJAX-URL
CACHE
X-HostName
X-Action
X-RSL
X-DB
X-BE
X-RPM
X-RPS
Processtime
X-DW
X-DSS
X-DI
X-Ratelimit-Remaining
X-Upstream-Ht
X-Swift-Error
X-SD-PageType
SD-X-WS
X-Aicache-OS
X-Dynatrace
X-Upstream-Ct
X-WR-MODIFICATION
Servername
X-Dynatrace-Js-Agent
X-Cache-Id
L
X-Tid
X-Compress-Hint
X-SN
Arc-Country
X-Processor
X-Server-Time
X-Skip-Cache
X-PAYTM-SRV-ID
X-Dispatch
Pramga
X-Cache-FS-Status
X-ID
Cache-Provider
X-Frame-Option
X-Ftr-Realm
X-StackifyID
X-Hello
X-Branch-Name
X-ServerName
X-Ratelimit-Limit
X-Release
X-LB-ID
CDN
X-ABtesting
X-FPC
Lfy
X-Fastly-Cache-Hits
Pagetype
X-Snapshot-Date
X-DevSite-Last-Modified
X-Flog
X-ND-Cache
X-Ftr-Balancer
X-Ftr-Backend
Dynatrace
X-Via-NSCOPI
Requestid
X-Ftr-Backend-Server
CF-IPCountry
X-Ftr-Dc
Fastly-Drupal-HTML
X-CACHE-AGE
X-Cc-Via
X-Apw-Access-Action
X-Scheme
X-Served-From
X-Edge-IP
Proxy-Firewall
X-Cc-Req-Id
X-ZONE
X-Request-Url
X-Apw-Access-Object
X-Edge-Server
V-Cache
X-Apw-Hits
Cdn-Host
X-Apw-Access-Token
X-SB
X-VC
Warning
D-Cc-Upstream
X-Varnish-Beresp-TTL
LB
Cdn-Request-Time
N-Cache
X-Amzn-Remapped-Date
X-Amzn-Remapped-Connection
X-Fpc
X-GEO
X-WA
X-Bc-Bl
Cache-Cookie-Set-Idcheck
Lb
X-Worker
WP-Super-Cache
X-BC
Backend-Name
X-App
Correlation-Id
X-ElasticPress-Search
Cache-Cookie-Set-From
UCS
X-Node-ID
X-Check-Cacheable
X-Request-URL
Cache-Cookie-Set-Lfrom
X-Powered-Y
X-Fastly-Cache-Status