Threat Level: green Handler on Duty: Russell Eubanks

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
CF-RAY
Link
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Request-ID
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-DNS-Prefetch-Control
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
Status
Upgrade
X-Content-Security-Policy
Content-Encoding
X-CDN
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
X-Xss-Protection
Keep-Alive
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
X-Pass-Why
X-Cache-Group
Xkey
X-AH-Environment
X-Envoy-Upstream-Service-Time
CF-Ray
X-Via
X-Backend
X-Server
X-Age
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Ws-Request-Id
X-Server-Powered-By
X-Page-Speed
X-Pingback
EagleId
X-Proxy-Cache
X-Hacker
X-UA-Device
X-Nginx-Cache-Status
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
P3p
Cf-Railgun
Grace
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Amz-Version-Id
X-Ua-Compatible
Report-To
X-LiteSpeed-Cache
X-Rq
X-OneAgent-JS-Injection
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-WebKit-CSP
X-Device
X-Host
X-Server-Id
X-Origin-Cache
X-Response-Time
EagleEye-TraceId
X-Node
X-Ac
Surrogate-Control
Content-Location
X-Cloud-Trace-Context
X-Vhost
X-Readtime
X-Backend-Server
Request-Id
X-Dispatcher
X-Origin-Upstream-Status
X-Cnection
X-Application-Context
X-HW
X-Cache-Lookup
X-Ruxit-JS-Agent
Fusion-Component-Id
Fusion-Content-Source
Fusion-Content-Id
Fusion-Template-Id
Fusion-Source
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
NEL
X-Mod-Pagespeed
X-DataDome
X-Dns-Prefetch-Control
X-Rack-Cache
Rating
Edge-Control
X-Country
X-Clacks-Overhead
X-Akam-SW-Version
Pinterest-Generated-By
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Allow
X-TTL
X-Country-Code
X-FTR-Request-ID
X-Instart-Request-ID
X-DynaTrace
X-Varnish-TTL
X-Goog-Hash
X-TtlSet
X-PC
X-Vname
Accept-Ch
X-ESI
Verso
Content-MD5
Service-Worker-Allowed
X-Powered-By-Plesk
Accept-Ch-Lifetime
X-Url
X-Forwarded-Proto
X-Version
X-MS-InvokeApp
X-Cdn-Fetch
X-GoogleNews-Bot
X-Exp-Id
X-Kinja
X-Kinja-Build
X-Exp-Variant
X-Use-Magma
X-Kinja-Revision
X-GitHub-Request-Id
X-Kinja-Server
X-B3-TraceId
RTSS
Edge-Cache-Tag
X-Server-Name
X-Debug
X-D2id
X-Abt-Application-Version
X-Px
AR-CACHE
AR-ATIME
AR-PoweredBy
AR-Request-ID
Ar-Sid
X-Amz-Server-Side-Encryption
X-Vcache
SPRequestGuid
Charset
X-NF-Request-ID
X-Cached
X-Sol
Pagespeed
X-Middleton-Response
Display
Response
X-Middleton-Display
X-Vcap-Request-Id
X-Accel-Expires
X-Amz-Rid
X-MSEdge-Ref
X-Navigation-Version
X-Server-ID
Arr-Disable-Session-Affinity
Pinterest-Version
X-Pinterest-Rid
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
TCN
X-Fastcgi-Cache
X-Powered-CMS
X-SharePointHealthScore
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Cdn
X-VARITI-CCR
Public-Key-Pins
X-Trace
X-Fastly-Request-ID
Cache-Tag
X-Client-IP
Realpath
X-Edge-O15-RID
Nginx-Cache
MS-Author-Via
Access-Control-Request-Method
X-Ser
X-Shard
X-DynaTrace-JS-Agent
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
MRF-Tech
X-Content-Type
SPIisLatency
SPRequestDuration
S
X-Id
X-Upstream
X-Ezoic-Cdn
X-Grace
X-Hp-Webp
X-Amzn-Trace-Id
X-Forwarded-For
X-T
X-Jurisdiction
X-Amz-Meta-S3cmd-Attrs
Nel
Front-End-Https
X-Hits
Fastcgi-Cache
X-Recruiting
X-Aspnet-Version
DynaTrace
X-Cache-TTL
X-Varnish-Age
ServerID
X-Element-Page-Cache
X-Content-Digest
MicrosoftSharePointTeamServices
X-Node-Name
X-Mobile-URL
X-Country-Code-Real
X-FTR-Realm
X-FTR-DC
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Expires
X-FTR-Cache-Status
X-Dw-Request-Base-Id
X-DIS-Request-ID
NR-ENABLED
Server-Node
X-HS-Hub-Id
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Content-Id
X-Goog-Generation
X-GUploader-UploadID
Powered
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Frontend
Alternate-Protocol
TP-L2-Cache
X-Logged-In
TP-Cache
Server-Name
X-CST
X-Correlation-Id
X-XRDS-Location
AMP-Access-Control-Allow-Source-Origin
X-Amz-Apigw-Id
Upgrade-Insecure-Requests
X-Amzn-RequestId
X-Request-Processing-Time
X-Request-Received
X-Request-Handler-Origin-Region
X-Microsite
X-ATS-Timestamp
X-Cache-Hit
Backend-Timing
Fastly-Restarts
X-Content-Options
X-Content-Security-Policy-Report-Only
X-User-Agent
X-Origin-Server
Refresh
X-Revision
X-Page-Id
X-F-Cache
X-Akamai-Edgescape
X-Rid
X-Zen-Fury
X-Varnish-Grace
X-Type
X-FTR-Cache-Host
X-Content-Powered-By
X-LB-Cache
X-XRDS-LOCATION
X-B
X-B3-Sampled
PB-RID
PB-PID
X-Geo-Country
Arc-Version
X-Mobile-Rewrite
X-URL
X-Az
X-Activity-Id
X-AppVersion
Cache-Status
X-Kinsta-Cache
X-N
X-Cache-Age
X-TT
X-B-Cache
X-WebKit-CSP-Report-Only
X-Signature
X-Cache-Action
X-Instance
Paypal-Debug-Id
Access-Control-Allow-Method
X-Framework
X-Time
X-AOL-HN
X-Load-Cache
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Debug-Info
X-App-Environment
X-Jobs
X-FB-Debug
Actual-Object-TTL
X-Pad
X-Shield-Request-Id
X-Request-Guid
X-PHP-Backend
X-Cached-By
X-Git-Hash
DC
Fastcgi-Useragent
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Webkit-Csp
X-RateLimit-Remaining
X-Amz-Replication-Status
X-Varnish-Backend
Surrogate-Key
Host-Header
X-IPLB-Instance
X-Contextid
MS-CV
X-ATG-Version
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-WA-Info
X-NWS-LOG-UUID
Host
X-Webapp-Samesite-None-Activated-N
X-Analytics
Accept-CH
X-SS-Set-Cookie
X-FastCGI-Cache
FilterID
X-Cache-Key
X-ORACLE-APMCS-TAG
X-Mobile
X-ORACLE-APMCS-REQUEST-ID
X-Via-JSL
X-Response-Served-From
X-Host-Name
Tracecode
X-Kong-Proxy-Latency
X-Accel-Buffering
X-Kong-Upstream-Latency
NGB
X-Cluster
Payment
X-Presslabs-Stats
X-B3-Traceid
X-Origin-Response-Time
X-Region
X-Varnish-Server
X-FW-Serve
X-Cache-2
WPE-Backend
X-FW-Hash
Eomportal-Instance
X-FW-Static
X-FW-Server
X-FW-Type
Source
X-Cache-NE
Frame-Options
Filters
X-GeoIP
X-IPS-LoggedIn
X-Varnish-Hostname
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
Cache-Tv-Group
X-Cacheable-TTL
X-Cache-Enabled
X-Hostname
X-EdgeConnect-Cache-Status
X-Is-Bot
X-RequestSource
Retry-After
X-Cache-Rule
X-Adobe-Content
X-Adobe-Loc
X-Srv
X-Cache-Operation
X-Seen-By
X-Rendered-As
X-NewRelic-App-Data
Xserver
X-TX-ID
Accept-CH-Lifetime
Server-Info
X-VCache
X-RemovedCookies
X-ProcessESI
Liferay-Portal
Cleartype
X-Cache-TTL-Remaining
X-App-Server
X-Dc
Ms-Operation-Id
X-RTag
X-L-Path
X-FireWall-Port
X-Source
X-Environment-Context
X-UA
X-Endurance-Cache-Level
X-Handled-By
Datacenter
X-HTML-Minification-Powered-By
From-Origin
X-Cache-Server
X-Upgrade-Enabled
X-CACHE-KEY
X-Backend-Name
X-APP-VERSION
Srv
Cache
Accept-Charset
X-Wix-Request-Id
X-Cache-Var-Map
X-Path-Route
X-Cache-Var
X-RN-RSRV
Meta-Geo
X-Cache-Control
X-ES-SERVER
GEO-INFO
X-Format
X-Tb
OT-Force-Account-Verify
X-Proxy-Build
X-UUID
X-Timing-Wait
X-Access
Selected-Fe
X-Section
X-Cache-Config
Cache-Tags
X-Sorting-Hat-PodId
X-Akamai-Request-ID
Mn-Server-Ip
X-Alternate-Cache-Key
X-NYM-Debug-Backend
X-Request-Time
X-Status
Healthy
X-Shopify-Generated-Cart-Token
X-Content-Age
Azure-SiteName
X-Origin
X-ShopId
Azure-SlotName
Azure-RegionName
X-PCL
X-FC-Vary-Parameters
Akamai-GRN
X-EIG-Tracking-Id
Azure-InstanceId
Azure-Version
X-Sorting-Hat-ShopId
X-OCL
X-Goog-Meta-Goog-Reserved-File-Mtime
X-ShardId
X-Shopify-Stage
X-Proto
X-Pubstack
NGX
X-Redis-Cache
DB-Nickname
Decoy-Debug-TTL
X-Vgn-Hpd-Reason
X-Soup
Decoy-Debug-Status
X-Say-TTL
Decoy-Debug-Key
X-BYPASS-REASON
X-Time-Microsecs
X-VWS-Id
X-ProxyCache-Key
X-Proxy
X-Hl-Ver
X-Cluster-Node
X-Generated-By
X-Say-Cacheable
X-SayCDN-TTL
X-Debug-Cache
X-FW-Dynamic
X-Viewer-Country
X-Hosted-By
X-AWS-Id
X-ProxyCache-Status
X-Akamai-Request-ID2
Now
X-Web-Node
X-LJ-Flow-ID
X-Proxy-Cache-Status
X-Human
X-Hyper-Cache
X-Qloud-Router
Node
Ec-Rule-Version
X-Yottaa-Metrics
Version
X-Yottaa-Optimizations
X-ServerID
TWC-GeoIP-LatLong
X-Generated
TWC-Locale-Group
TWC-Privacy
X-PressLabs-Stats
TWC-GeoIP-Country
X-FB-TRIP-ID
Origin-Cache-Control
TWC-Device-Class
X-RateLimit-Limit
Origin-Edge-Control
Cross-Origin-Window-Policy
TWC-Connection-Speed
Webcakes-App-Name
X-SaId
X-MP-GENERATED-AT
X-Varnish-Hits
X-Storage
X-TNCMS
X-Origin-Hint
Property-Id
X-Site-Version
X-JoinUs
X-CCM
X-Loop
Webcakes-App-Version
X-Www-Served-By
X-Amzn-Remapped-Content-Length
Webcakes-Region
X-Rule
X-BCube-Filmed-By
S-Rt
X-NCache
X-R9-Blue-Green-Version
X-Xfnlog-Site
X-Akamai-Transformed
X-RCS-CacheZone
X-Locale
X-Detected-As
X-IP
X-Cache-Host
X-Unique-Id
X-Ttl
L5d-Success-Class
Cache-Key
X-Drupal-Cache-Tags
X-Esi
X-CS
Cache-Name
Webserver
Uber-Trace-Id
Viewport
Time
X-UA-Device-Type
X-UnsetCookies
X-Forwarded-Host
X-Mode
X-Backend-TTL
X-Whom
X-CDN-Forward
X-Origin-TTL
X-NGENIX-Cache
X-Origin-CC
X-Daa-Tunnel
Rt-Fastcgi-Cache
Accept-Language
X-Info
Content-Disposition
X-Varnish-Cache-Hits
X-B3-Spanid
Country
X-Cache-Remote
Mime-Version
Odigeo-Trace-Id
X-From
X-ApacheServer
X-PERF
ServedBy
X-CLOUD-TRACE-CONTEXT
X-Cluster-Name
X-Magnolia-Registration
X-Newrelic-Synthetics
Section-Io-Cache
X-Drupal-Cache-Contexts
X-Device-Type
X-Microcachable
VIX-Pulpo-Node
X-Proxied
X-Zipkin-Id
X-Routing-Service
VIX-Pulpo-Upstream-Status
X-Geo
X-EC-Lua
X-TT-TIMESTAMP
X-Via-Fastly
Cf-Ipcountry
Ohc-File-Size
X-Uri
Proxy-Connection
HitType
X-Nc
Ohc-Cache-HIT
X-A-Dgt
T-Server
X-GeoIP-Country-Code
Content-Script-Type
Content-Style-Type
MD5-Digest
X-Date
X-D
X-G
Machine
X-DPWN-IS-SECURE
X-Destination
GEO-REGION-INFO
X-External-Request-Id
Fastcgi-X-Cache-Version
BehaviorPad-Version
AsisCache
Access-Control-Request-Headers
Mobile-Detection-Method
X-Connection-Hash
X-CF-Lambda-Version
X-CF-Lambda-Fn
Meta-Geo-Continent
X-Geo-Header
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Handled
Rendered-Blocks
X-Rewrite-Enabled
X-Vtex-Remote-Cache
X-A-Ccd
X-Vtex-Processado-Em
Viewtype
X-A
X-SRCache-Key
X-A-Dam
X-Application
X-Session-Fingerprint
X-A-Dcw
X-Sigma-Backend
X-VG-WebServer
VivaBuild
X-A-Wwc
X-Accel-Expires-Debug
X-Aed
X-Twitter-Response-Tags
W
X-Trv-Group
X-VG-WebCache
X-VG-TLSProxy
X-Vdms-Version
X-Transaction
X-ARC
X-Sigma
X-S
X-S-Cookie
X-Rojux
X-Rocket-Build-Number
X-Request-UUID
X-B-Cookie
Xc-Version
X-ScT
X-Region-Sid
X-UPSTREAM-Address
X-Varnish-Beresp-Ttl
User-Cache-Control
X-No-Session
X-Edge-Location
X-Varnish-Beresp-Status
X-C
X-Varnish-Beresp-Grace
X-Developers
X-VC-Cache
X-Real-IP
X-Varnish-Authentication
X-CUA
IsBot
X-Agile
HA-Ipaddr
X-Agile-Age
X-Wikidot-Backend
Locid
Environment
X-Hit
X-WebServer
Fastly-Soc-X-Request-Id
Fastly-SIE
Fastly-SWR
Countrycode
X-Distil-CS
Gh-Request-Id
X-Wikidot-Static-Cache
CDCHOST
X-Eu-Site
Ha-Gx-Prefs
X-CGP
Server-Cache-Control
X-Cache-ASPX
X-Cache-Debug
X-SIPLIST1
X-Logging-Id
X-Tec-Api-Version
X-Tec-Api-Root
X-Auto-Login
X-Rebelmouse-Cache-Control
Server-Surrogate-Control
X-Bip
X-Tec-Api-Origin
X-Thanos
X-App-Name
X-Clientip
Powered-By
X-TrackingId
X-Rebelmouse-Surrogate-Control
X-Tumblr-Pixel-3
Fastly-SSL
X-Contensis-Viewer-Groups
X-Agile-Id
X-Cache-Backend
Geo-Info
X-GoCache-CacheStatus
X-Cache-URL
X-Cms-Context
X-Cache-Time
X-BBXSRF
X-Debug-Cookies
X-Cdn-Srv
X-Backend-State
X-Debug-Cache-Expiry
X-Clara-WADP
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Cache-Bucket
X-Cache-Tags
X-Core-Mission
X-Block-Status
X-AK-Request-ID
X-Debug-Log
X-Cache-Info
X-OVcl
X-Render-Time
X-RateLimit-Remaining-Second
X-Request-URI
X-Server-W
X-SVT-ORM-RULES
X-Servername
X-RateLimit-Limit-Second
X-Proxy-Upstream
X-Origin-Date
X-NX-Host
X-Origin-Expires
X-OVcl-Cache
X-PHP-Host
X-SVT-ORM-VERSION
X-Swa-Ws
X-VServer
X-Variation
X-WADP-Cache
X-We-Are-Hiring
X-Webstats-RespID
X-User
X-Urbn-Site-Id
X-Trace-Id
X-TH-Server
X-TT-LOGID
X-Up
X-Urbn-Context-Path
X-NU-AKA-ACS-Version
X-NodeID
X-GeoIP-City
X-Generation-Time
X-Has-Esi
X-Hash
X-IN-APIGATEWAY
X-Hnp-Log
X-Generated-In
X-Gen-Mode
X-Fastly-Cache
X-Epic-Correlation-Id
X-Fetched-On
X-FW-Version
X-Gamma-Serve
X-IN-APIGATEWAYSSL
X-Instart-Isnd
X-Micro-Cache
X-LI-UUID
X-Ms-Request-Id
X-Ms-Version
X-Nginx-Cache-Key
X-LI-Proto
X-Li-Pop
X-Is-Gdpr
X-Irp-Debug
X-JWT-State
X-Labrador-Cache-Channel
X-Li-Fabric
X-Dispatcher-Server
X-Air-Hostname
Mail-Subject
Locale
Kp-EeAlive
Memcached
Request-Country
RNT-Time
RNT-Machine
Request-EU
Is-Eu
IBM-Web2-Location
Cache-Host
AKAMAI
Adler-Geo
Cdncip
Cdnsip
Heartbleed
Country-Code
Server-Int
Platform
True-Client-Country-4JS
Web-Mar-Node
We-Hiring
X-Trafficlayer-App-Name
X-Trafficlayer-App-Scope
X-Old-Content-Length
X-Distributor
V-Age
X-Owner
Group
X-Trafficlayer-App-Version
X-Core-Value
Fastly-Backend-Name
X-Generated-On
Wxu-Next-Commit
Wxu-Next-Hostname
X-Var-Ttl
X-Cache-Expired-At
FNAC-ModuleRouting
ServerName
X-Level-Front-Cache
X-Matched-Rule
X-Platform-Server
X-Thinkindot-L3
X-ServiceProvider
X-Azure-Ref
X-Service
Thinkindot-CacheControl-Type
Server-Host
Wxu-Next-Region
Thinkindot-CacheControl
Server-ID
X-Req
Thinkindot-Control
X-Reboot
PFcat
Filterid
Cache-Hits
X-Lb-Id
X-SERVER
X-Internal-Host
X-S-Maxage
Pragrma
X-App-Version
S-Cnection
X-Response-By
X-VHOST
X-Key
X-Sucuri-Cache
X-Nginx-Cache
X-Refresh
X-Location
Powered-By-ChinaCache
X-Ruxit-Js-Agent
X-CF-Powered-By
X-CSRF-TOKEN
RequestId
X-Tb-Optimization-Total-Bytes-Saved
X-NC
X-Parent-Response-Time
X-Wa
X-TA-CDN-Provider
X-Sucuri-ID
X-Varnish-Cacheable
ProcessTime
Origin
X-Cdn-Forward
X-Ua
X-B3-Parentspanid
X-Pjax-Url
User-Agent
X-BACKEND-TTL
X-Pf-Uncompressing
Memory
X-Via-CDN
X-CSRF-Token
Geoip-Latitude
Geoip-City
X-Developer
SRV
X-NGINX-Cache
X-LAGOON
TTL
X-Server-IP
GeoIp-Country-Code
X-Cache-Grace
X-Correlation-ID
X-Device-Os
PICS-Label
X-Sn-Servicetimems
X-Ocache
X-Cdn-Origin
X-Oss-Server-Time
X-Node-Id
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Oss-Storage-Class
X-B3-SpanId
X-Oss-Request-Id
X-Vcl-Version
X-Cache-Status-Check
On-Server
X-NWS-UUID-VERIFY
X-COUNTRY
Hostname
X-Unique-ID
X-MSEdge-Features
X-Request-Host
XServer
X-MSEdge-Flight
A
X-Litespeed-Cache
X-Servedbyhost
X-Cdn-Request-ID
X-Webkit-CSP
Media-Length
Cloudfront-Viewer-Country
Dnion-Transfer-Encoding
X-Varnish-Ttl
X-Rocket-Nginx-Bypass
SN
X-TIME
Tcn
X-Via-Ucdn
M-TraceId
X-HS-Status
X-FORWARDED-FOR
Resin-Trace
Cdn
Host-ID
X-Varnish-URL
X-Sucuri-Id
X-Ratelimit-Remaining
X-Beluga-Trace
X-ServedByHost
X-Beluga-Status
Esi-Enabled
X-Beluga-Response-Time
X-AIR-PT
X-Beluga-Record
X-Beluga-Cache-Status
X-Beluga-Node
Who
X-Cache-Ttl
X-Reqid
HostName
CF-Cached-On
X-Planisys-CDN-Cache
X-Policy
X-Slack-Backend
X-Fastly-Country-Code
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Request-Start
X-Action
X-VCL-Version
CACHE
MIME-Version
X-Azure-Ref-OriginShield
X-RPS
Rt-Proxy-Cache
X-RPM
GeoIP-Country-Code
X-PAYTM-SRV-ID
X-RSL
Pics-Label
X-Server-Time
Ttl
X-Processor
X-Cache-FS-Status
X-Dispatch
X-DB
X-DI
X-DSS
Pramga
X-DW
Arc-Country
X-Oracle-Dms-Rid
X-LiteSpeed-Cache-Control
X-Skip-Cache
GeoIP-City
GeoIP-Latitude
X-Fastly-Backend-Reqs
X-Varnish-Url
X-Zone
X-Bc
X-Hello
NtCoent-Length
X-ND-Cache
X-ABtesting
X-Flog
X-DC
X-PJAX-URL
Cdn-Host
X-Ratelimit-Limit
Cdn-Request-Time
Fastly-Drupal-HTML
X-FPC
X-PF-Uncompressing
X-VarnishDD-TTL
X-Newrelic-App-Data
X-APP
X-Served-From
Magicmarker
X-Edge-Server
X-Method
X-HostName
X-SRV
X-Bc-Bl
Cteonnt-Length
N-Cache
Amp-Access-Control-Allow-Source-Origin
X-DevSite-Last-Modified
WebServer
Section-Io-Id
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
X-Ftr-Cache-Host
Section-Io-Origin-Status
X-Backend-Host
X-BE
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
X-Dynatrace
Processtime
X-Dynatrace-Js-Agent
Servername
X-Swift-Error
X-Be
Requestid
X-ID
X-WA
Ohc-Response-Time
CDN
X-Svr
Cache-Provider
X-WR-MODIFICATION
X-Frame-Option
CF-IPCountry
X-Fmm-Version
X-Adobe-Source
FSS-Proxy
Load-Balancing
Lfy
X-Aicache-OS
X-Branch-Name
X-ZONE
X-LB-ID
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
X-Snapshot-Date
X-BC
Vix-Hermes-Req-Id
Dynatrace
FSS-Cache
X-StackifyID
Cache-Cookie-Set-From
X-CACHE-AGE
Trailer
Fusion-Deployment-Id
X-Tid
X-Request-Url
V-Cache
X-Cc-Via
Proxy-Firewall
X-Apw-Hits
X-Apw-Access-Token
X-Apw-Access-Action
X-Apw-Access-Object
X-Scheme
X-Fastly-Cache-Hits
D-Cc-Upstream
Warning
Pagetype
X-Cc-Req-Id
X-VC
WZWS-RAY
X-SB
DSUID
X-MServer
X-Litespeed-Cache-Control
X-Node-ID
X-WPE-Loopback-Upstream-Addr
Server-Id
X-Fpc
Cneonction
Backend-Name
Correlation-Id
X-App
X-VCT
Release
X-Hp-Ccpa-Warning
X-Configured-By
X-Worker
WP-Super-Cache
X-Check-Cacheable
X-Varnish-Beresp-TTL
X-Request-URL
X-Powered-Y
X-ElasticPress-Search
X-Fastly-Cache-Status