Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
CF-RAY
Link
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Request-ID
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-DNS-Prefetch-Control
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
Status
Upgrade
X-Content-Security-Policy
X-CDN
Content-Encoding
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Xss-Protection
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
X-Pass-Why
Xkey
P3p
X-AH-Environment
X-Envoy-Upstream-Service-Time
X-Cache-Group
X-Via
X-Backend
CF-Ray
X-Age
X-Server
X-Ua-Compatible
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Server-Powered-By
X-Page-Speed
X-Ws-Request-Id
X-Pingback
EagleId
X-Proxy-Cache
X-Hacker
X-Nginx-Cache-Status
X-UA-Device
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
Cf-Railgun
Grace
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Amz-Version-Id
Report-To
X-LiteSpeed-Cache
X-Rq
X-Server-Id
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
X-WebKit-CSP
X-Device
X-Host
EagleEye-TraceId
X-Origin-Cache
X-Response-Time
X-Ac
X-Node
Content-Location
Surrogate-Control
X-Vhost
X-Cloud-Trace-Context
X-Readtime
Request-Id
X-Backend-Server
X-Dispatcher
X-Dns-Prefetch-Control
X-Origin-Upstream-Status
X-Cnection
X-Application-Context
X-HW
X-Cache-Lookup
X-ORACLE-DMS-ECID
Fusion-Content-Id
Fusion-Content-Source
Fusion-Component-Id
Fusion-Template-Id
Fusion-Source
X-ORACLE-DMS-RID
NEL
X-Ruxit-JS-Agent
X-DataDome
X-Mod-Pagespeed
Rating
X-Rack-Cache
Edge-Control
X-Country
X-Akam-SW-Version
X-Clacks-Overhead
Pinterest-Generated-By
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Allow
X-TTL
X-Country-Code
Accept-Ch
X-DynaTrace
X-Instart-Request-ID
X-Varnish-TTL
X-Goog-Hash
X-FTR-Request-ID
X-Vname
X-TtlSet
X-PC
X-ESI
Verso
Accept-Ch-Lifetime
X-Powered-By-Plesk
Content-MD5
Service-Worker-Allowed
X-Url
X-B3-TraceId
X-Forwarded-Proto
X-MS-InvokeApp
X-Version
X-GitHub-Request-Id
X-Kinja-Revision
X-Use-Magma
X-GoogleNews-Bot
X-Cdn-Fetch
X-Exp-Variant
X-Kinja-Server
X-Kinja
X-Kinja-Build
X-Exp-Id
RTSS
Edge-Cache-Tag
X-D2id
X-Debug
X-Server-Name
X-Px
AR-CACHE
AR-PoweredBy
Ar-Sid
X-Abt-Application-Version
AR-ATIME
AR-Request-ID
SPRequestGuid
X-Amz-Server-Side-Encryption
Charset
X-NF-Request-ID
X-Vcache
X-Cached
X-Accel-Expires
X-Middleton-Display
Response
X-MSEdge-Ref
X-Sol
Display
Pagespeed
X-Middleton-Response
X-Navigation-Version
X-Vcap-Request-Id
X-Amz-Rid
Arr-Disable-Session-Affinity
X-Pinterest-Rid
X-TEC-API-VERSION
Pinterest-Version
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Powered-CMS
X-SharePointHealthScore
X-Fastcgi-Cache
TCN
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Trace
X-VARITI-CCR
Realpath
Public-Key-Pins
X-Client-IP
X-Cdn
Cache-Tag
X-Fastly-Request-ID
MS-Author-Via
X-Ser
Access-Control-Request-Method
Nginx-Cache
X-DynaTrace-JS-Agent
X-Shard
S
SPIisLatency
SPRequestDuration
X-Upstream
X-Mrf-Section-Lastmod
Mrf-Cache-Status
X-Edge-O15-RID
MRF-Tech
X-Id
X-Mrf-Item-Lastmod
X-B3-TraceId-Primal
X-Content-Type
X-Ezoic-Cdn
X-Hp-Webp
X-Grace
X-Amzn-Trace-Id
X-Forwarded-For
X-T
X-Amz-Meta-S3cmd-Attrs
Front-End-Https
X-Hits
DynaTrace
X-Recruiting
Fastcgi-Cache
Nel
X-Varnish-Age
X-Jurisdiction
X-Aspnet-Version
ServerID
X-Cache-TTL
MicrosoftSharePointTeamServices
X-Element-Page-Cache
X-Mobile-URL
X-Dw-Request-Base-Id
X-DIS-Request-ID
X-Content-Digest
X-Node-Name
X-Server-ID
X-FTR-Expires
NR-ENABLED
X-FTR-Cache-Status
X-Country-Code-Real
X-Frontend
Powered
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
X-Goog-Metageneration
X-Goog-Storage-Class
X-Goog-Generation
X-HS-Cache-Config
X-HS-Combine-CSS
X-HS-Hub-Id
X-HS-Content-Id
Server-Node
X-FTR-Backend
X-FTR-DC
X-FTR-Balancer
X-FTR-Realm
X-FTR-Backend-Server
TP-L2-Cache
TP-Cache
Alternate-Protocol
Server-Name
X-Logged-In
X-Correlation-Id
X-CST
AMP-Access-Control-Allow-Source-Origin
X-Request-Received
X-Request-Processing-Time
Upgrade-Insecure-Requests
X-XRDS-LOCATION
X-Amzn-RequestId
X-Microsite
X-Request-Handler-Origin-Region
X-Amz-Apigw-Id
X-ATS-Timestamp
Backend-Timing
X-Cache-Hit
X-Content-Options
X-Content-Security-Policy-Report-Only
X-Origin-Server
X-User-Agent
X-Revision
X-F-Cache
X-Akamai-Edgescape
Refresh
X-Rid
X-Page-Id
Fastly-Restarts
X-Varnish-Grace
X-Type
X-Zen-Fury
X-Webkit-Csp
X-XRDS-Location
X-Content-Powered-By
X-LB-Cache
X-B3-Sampled
X-B
X-Geo-Country
X-AppVersion
X-Az
X-Activity-Id
PB-RID
PB-PID
X-FTR-Cache-Host
X-Mobile-Rewrite
Arc-Version
X-URL
Cache-Status
X-Shield-Request-Id
X-Kinsta-Cache
X-N
X-Pad
X-Cache-Age
X-Time
X-TT
X-AOL-HN
X-Instance
X-WebKit-CSP-Report-Only
X-Signature
X-Jobs
X-Tumblr-Pixel
Actual-Object-TTL
X-Tumblr-User
X-Cache-Action
X-B-Cache
X-Framework
X-Tumblr-Pixel-0
Paypal-Debug-Id
Access-Control-Allow-Method
X-App-Environment
X-Debug-Info
X-Request-Guid
X-FB-Debug
X-Load-Cache
X-PHP-Backend
DC
X-Cached-By
X-Git-Hash
X-Webapp-Samesite-None-Activated-N
X-RateLimit-Remaining
X-Tt-Trace-Tag
X-Varnish-Backend
X-Tt-Trace-Host
Fastcgi-Useragent
X-Erf-Bev-Bev-Is-Generated
X-Amz-Replication-Status
Surrogate-Key
X-Erf-Bev-Bev
X-Analytics
Host-Header
X-IPLB-Instance
MS-CV
X-Contextid
X-ATG-Version
X-SS-Set-Cookie
FilterID
Host
X-Cache-Key
X-WA-Info
X-ORACLE-APMCS-REQUEST-ID
X-Cluster
X-ORACLE-APMCS-TAG
X-Mobile
X-NWS-LOG-UUID
NGB
X-Response-Served-From
X-FastCGI-Cache
X-Accel-Buffering
Tracecode
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Via-JSL
WPE-Backend
X-VCache
X-Cache-NE
X-Host-Name
Payment
X-Cache-2
X-Srv
X-FW-Static
X-FW-Type
X-Varnish-Server
Eomportal-Instance
X-FW-Server
Source
X-FW-Serve
X-FW-Hash
X-Region
X-Varnish-Hostname
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
Cache-Tv-Group
Filters
X-GeoIP
X-IPS-LoggedIn
X-Origin-Response-Time
X-Cache-Enabled
X-Cacheable-TTL
X-Adobe-Loc
X-Presslabs-Stats
Frame-Options
X-Adobe-Content
X-Cache-Rule
X-Cache-Operation
X-RequestSource
X-Hostname
Xserver
X-Seen-By
X-Is-Bot
X-Rendered-As
Retry-After
X-TX-ID
X-NewRelic-App-Data
X-EdgeConnect-Cache-Status
Cleartype
Server-Info
X-Cache-TTL-Remaining
X-RemovedCookies
X-ProcessESI
Liferay-Portal
X-UA
X-Dc
Accept-CH
X-RTag
Ms-Operation-Id
X-B3-Traceid
Datacenter
X-Environment-Context
X-L-Path
X-Source
X-App-Server
X-FireWall-Port
X-HTML-Minification-Powered-By
Cache
X-Cache-Server
X-Upgrade-Enabled
X-Endurance-Cache-Level
X-Handled-By
X-Ttl
From-Origin
X-Cache-Control
Healthy
X-Backend-Name
Srv
X-CACHE-KEY
X-APP-VERSION
X-Wix-Request-Id
Accept-CH-Lifetime
X-Path-Route
X-Cache-Var-Map
X-Status
X-Cache-Var
Version
X-RN-RSRV
X-PressLabs-Stats
X-ES-SERVER
Meta-Geo
X-Format
Selected-Fe
X-Access
X-Proxy-Build
X-Tb
X-Section
OT-Force-Account-Verify
X-Timing-Wait
Azure-Version
X-ShardId
X-Storage
X-Rule
X-RateLimit-Limit
X-Request-Time
Azure-InstanceId
Azure-RegionName
Azure-SiteName
Azure-SlotName
Akamai-GRN
Cache-Tags
X-Akamai-Request-ID
Mn-Server-Ip
X-UUID
X-Alternate-Cache-Key
X-Content-Age
X-EIG-Tracking-Id
X-Shopify-Generated-Cart-Token
X-Sorting-Hat-ShopId
Accept-Charset
X-Proto
X-Origin
X-ShopId
X-Shopify-Stage
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Sorting-Hat-PodId
X-Pubstack
X-FW-Dynamic
X-Akamai-Request-ID2
X-OCL
Ec-Rule-Version
X-Soup
Origin-Edge-Control
X-SaId
X-Generated-By
Origin-Cache-Control
Node
X-Redis-Cache
NGX
X-Qloud-Router
X-Vgn-Hpd-Reason
X-Proxy
X-Hyper-Cache
X-Time-Microsecs
X-JoinUs
X-NYM-Debug-Backend
X-Human
X-FC-Vary-Parameters
X-Hosted-By
X-Web-Node
Decoy-Debug-Key
Decoy-Debug-Status
Decoy-Debug-TTL
X-PCL
X-Hl-Ver
X-ServerID
X-Cache-Config
GEO-INFO
X-Generated
X-LJ-Flow-ID
X-MP-GENERATED-AT
Now
Property-Id
Webcakes-App-Name
X-VWS-Id
X-ProxyCache-Key
X-BYPASS-REASON
X-ProxyCache-Status
X-Viewer-Country
X-Debug-Cache
X-Cluster-Node
X-Proxy-Cache-Status
X-Say-Cacheable
X-Say-TTL
X-SayCDN-TTL
X-BCube-Filmed-By
X-AWS-Id
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Device-Class
X-Varnish-Hits
X-Site-Version
TWC-Locale-Group
TWC-Privacy
X-Origin-Hint
Webcakes-Region
Webcakes-App-Version
X-Www-Served-By
TWC-Connection-Speed
DB-Nickname
X-Ruxit-Js-Agent
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Cache-Host
X-Akamai-Transformed
X-Locale
X-RCS-CacheZone
X-TNCMS
X-Loop
X-FB-TRIP-ID
S-Rt
X-R9-Blue-Green-Version
X-Amzn-Remapped-Content-Length
Cross-Origin-Window-Policy
X-IP
X-Detected-As
X-CCM
X-NCache
X-Xfnlog-Site
L5d-Success-Class
X-CS
Cache-Name
X-Unique-Id
Viewport
Time
X-Drupal-Cache-Tags
Webserver
Cache-Key
Uber-Trace-Id
X-Esi
X-UnsetCookies
X-UA-Device-Type
X-Mode
X-Cache-Remote
X-Forwarded-Host
Accept-Language
X-Whom
X-Backend-TTL
X-Daa-Tunnel
X-From
X-Info
X-Origin-TTL
X-CDN-Forward
X-Origin-CC
Mime-Version
Rt-Fastcgi-Cache
X-Trafficlayer-App-Name
X-Trafficlayer-App-Scope
Country
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
Odigeo-Trace-Id
X-Cluster-Name
X-NGENIX-Cache
X-Varnish-Cache-Hits
X-PERF
X-Drupal-Cache-Contexts
X-ApacheServer
X-Microcachable
X-Magnolia-Registration
X-TT-TIMESTAMP
ServedBy
Content-Disposition
X-Newrelic-Synthetics
X-B3-Spanid
X-Geo
X-CLOUD-TRACE-CONTEXT
X-Device-Type
Proxy-Connection
X-Zipkin-Id
Section-Io-Cache
X-Edge-Location
X-Proxied
X-Routing-Service
Ohc-File-Size
X-Via-Fastly
X-Uri
X-EC-Lua
Ohc-Cache-HIT
X-UPSTREAM-Address
Cf-Ipcountry
HitType
Fastcgi-X-Cache-Version
BehaviorPad-Version
MD5-Digest
X-ARC
X-Application
AsisCache
X-DPWN-IS-SECURE
X-B-Cookie
Content-Style-Type
Machine
Apple-News-Services-Handled
X-Connection-Hash
X-Geo-Header
GEO-REGION-INFO
Meta-Geo-Continent
X-CF-Lambda-Fn
X-GeoIP-Country-Code
X-CF-Lambda-Version
Apple-News-Services-Request-Url
X-External-Request-Id
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-Destination
X-Rojux
X-Vtex-Processado-Em
Rendered-Blocks
Xc-Version
X-Twitter-Response-Tags
X-Date
X-Sigma-Backend
X-Vtex-Remote-Cache
X-SRCache-Key
W
X-Aed
X-Vdms-Version
X-Transaction
X-Trv-Group
X-VG-TLSProxy
X-VG-WebCache
X-VG-WebServer
X-Accel-Expires-Debug
X-Sigma
X-Nc
Content-Script-Type
X-Request-UUID
X-Rewrite-Enabled
X-Rocket-Build-Number
X-Region-Sid
X-S-Cookie
X-ScT
X-Session-Fingerprint
VivaBuild
T-Server
Viewtype
Mobile-Detection-Method
X-C
X-No-Session
Access-Control-Request-Headers
X-VC-Cache
X-Varnish-Authentication
Server-Cache-Control
X-A-Dam
Environment
X-A-Dcw
X-CGP
X-A
X-Wikidot-Backend
Server-Surrogate-Control
Fastly-Soc-X-Request-Id
X-Eu-Site
X-G
X-Distil-CS
X-A-Ccd
X-Varnish-Beresp-Status
X-Cache-ASPX
X-Logging-Id
X-SIPLIST1
X-Agile-Age
X-Agile
IsBot
X-Bip
Powered-By
X-Auto-Login
X-App-Name
X-Developers
X-S
X-Agile-Id
Geo-Info
X-Wikidot-Static-Cache
X-TrackingId
X-Varnish-Beresp-Ttl
X-D
Gh-Request-Id
X-Contensis-Viewer-Groups
X-A-Dgt
X-CUA
X-Varnish-Beresp-Grace
Ha-Gx-Prefs
HA-Ipaddr
X-Thanos
X-Hit
X-A-Wwc
X-Tumblr-Pixel-3
X-TA-CDN-Provider
X-Cache-Backend
X-PHP-Host
User-Cache-Control
X-GoCache-CacheStatus
X-Labrador-Cache-Channel
X-Core-Mission
X-AK-Request-ID
X-Backend-State
X-Azure-Ref
X-Cache-Bucket
X-Cdn-Srv
X-Cache-Time
X-Cache-Info
X-Cache-Debug
X-BBXSRF
X-Instart-Isnd
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Server-W
X-SVT-ORM-RULES
X-Swa-Ws
X-SVT-ORM-VERSION
X-Render-Time
X-Real-IP
X-OVcl-Cache
X-OVcl
X-Owner
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-TH-Server
X-Trace-Id
Countrycode
X-VServer
X-We-Are-Hiring
X-WebServer
X-Webstats-RespID
Fastly-SIE
Fastly-SWR
X-TT-LOGID
X-Clientip
X-Urbn-Context-Path
X-Urbn-Site-Id
X-User
X-Origin-Expires
X-Origin-Date
X-Fetched-On
X-Fastly-Cache
X-FW-Version
X-Gamma-Serve
X-Generated-In
X-Epic-Correlation-Id
X-Distributor
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Debug-Cookies
X-Debug-Log
X-Dispatcher-Server
X-Generation-Time
X-GeoIP-City
X-Micro-Cache
X-LI-UUID
X-Nginx-Cache-Key
X-NodeID
X-NX-Host
V-Age
X-Li-Pop
X-IN-APIGATEWAY
X-Hash
X-IN-APIGATEWAYSSL
X-Irp-Debug
X-Li-Fabric
X-Debug-Cache-Expiry
X-Cache-URL
AKAMAI
CDCHOST
X-Tec-Api-Root
X-Tec-Api-Version
Locale
Locid
Memcached
Request-Country
Request-EU
Kp-EeAlive
X-Tec-Api-Origin
Cdnsip
IBM-Web2-Location
Country-Code
Fastly-SSL
Heartbleed
Server-Int
Cdncip
X-Is-Gdpr
X-JWT-State
X-Has-Esi
X-NU-AKA-ACS-Version
X-Core-Value
ServerName
Cache-Host
X-Up
X-Servername
X-Cms-Context
X-Hnp-Log
X-Thinkindot-L3
X-Proxy-Upstream
X-Trafficlayer-App-Version
Thinkindot-Control
X-Reboot
X-App-Version
X-Service
X-ServiceProvider
X-Request-URI
X-Old-Content-Length
X-Ms-Version
X-Key
X-Clara-WADP
X-Generated-On
X-Gen-Mode
X-Level-Front-Cache
X-WADP-Cache
X-Ms-Request-Id
X-Matched-Rule
X-LI-Proto
X-Cache-Tags
X-Platform-Server
Server-Host
Web-Mar-Node
Mail-Subject
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
PFcat
Wxu-Next-Commit
RNT-Machine
RNT-Time
Server-ID
Wxu-Next-Region
Wxu-Next-Hostname
X-Block-Status
We-Hiring
Fastly-Backend-Name
True-Client-Country-4JS
Cache-Hits
X-Internal-Host
X-Lb-Id
Platform
X-Sucuri-Cache
X-S-Maxage
X-Req
Adler-Geo
Is-Eu
X-Variation
FNAC-ModuleRouting
X-CACHE-GROUP
Filterid
X-Nginx-Cache
X-Refresh
X-Air-Hostname
X-Response-By
X-Cache-Expired-At
X-SERVER
X-Var-Ttl
S-Cnection
X-Location
X-Parent-Response-Time
X-Tb-Optimization-Total-Bytes-Saved
Group
RequestId
X-CF-Powered-By
Memory
Pragrma
Powered-By-ChinaCache
X-B3-Parentspanid
X-Cdn-Forward
X-NC
X-CSRF-Token
ProcessTime
X-BACKEND-TTL
X-CSRF-TOKEN
X-B3-SpanId
Origin
User-Agent
X-Pjax-Url
X-Wa
X-Sucuri-ID
X-Server-IP
X-Pf-Uncompressing
X-Varnish-Cacheable
Geoip-Latitude
X-NWS-UUID-VERIFY
TTL
X-Via-CDN
Geoip-City
GeoIp-Country-Code
X-Unique-ID
SRV
X-NGINX-Cache
X-Ua
X-Correlation-ID
X-Vcl-Version
PICS-Label
X-Developer
X-Cdn-Request-ID
X-LAGOON
X-Ocache
Media-Length
X-COUNTRY
X-Cache-Grace
X-Cdn-Origin
X-Device-Os
X-Sn-Servicetimems
X-Node-Id
On-Server
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
XServer
X-Oss-Request-Id
X-Rocket-Nginx-Bypass
X-Cache-Status-Check
X-Sucuri-Id
X-MSEdge-Features
A
Dnion-Transfer-Encoding
X-Webkit-CSP
X-Litespeed-Cache
X-MSEdge-Flight
X-Servedbyhost
X-Request-Host
Hostname
SN
X-Varnish-Ttl
X-Via-Ucdn
Cloudfront-Viewer-Country
X-TIME
X-Oneagent-Js-Injection
Tcn
X-AIR-PT
M-TraceId
X-HS-Status
Esi-Enabled
X-Reqid
X-FORWARDED-FOR
X-Planisys-CDN-Rules
Cdn
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
X-Policy
X-Ratelimit-Remaining
Who
X-Fastly-Country-Code
Resin-Trace
Host-ID
X-ServedByHost
X-Azure-Ref-OriginShield
X-Beluga-Cache-Status
X-Beluga-Node
X-Request-Start
X-Beluga-Response-Time
X-Beluga-Status
X-Cache-Ttl
X-Beluga-Trace
X-Varnish-URL
X-Beluga-Record
X-Ftr-Cache-Host
X-VHOST
HostName
Rt-Proxy-Cache
CF-Cached-On
X-Slack-Backend
Pics-Label
MIME-Version
NtCoent-Length
X-APP
X-VCL-Version
X-Method
GeoIP-Country-Code
Magicmarker
X-Action
X-Oracle-Dms-Rid
CACHE
X-Zone
Ttl
X-DB
X-RPM
X-Varnish-Url
X-DSS
Cteonnt-Length
X-DI
X-DW
X-RPS
X-Bc
X-Fastly-Backend-Reqs
X-RSL
X-Server-Time
X-PAYTM-SRV-ID
X-Processor
X-Dispatch
X-Cache-FS-Status
Arc-Country
GeoIP-Latitude
Pramga
X-LiteSpeed-Cache-Control
X-DC
X-FPC
X-PJAX-URL
X-Newrelic-App-Data
X-VarnishDD-TTL
GeoIP-City
X-PF-Uncompressing
X-Flog
X-ABtesting
X-Ratelimit-Limit
X-Hello
X-Skip-Cache
X-ND-Cache
X-HostName
Ohc-Response-Time
Processtime
Fastly-Drupal-HTML
X-Be
Amp-Access-Control-Allow-Source-Origin
X-Svr
X-Swift-Error
Load-Balancing
X-Edge-Server
X-Ftr-Request-Id
WebServer
Cdn-Request-Time
Cdn-Host
X-Served-From
X-SRV
X-DevSite-Last-Modified
X-Dynatrace
X-Bc-Bl
X-BE
Vix-Hermes-Req-Id
N-Cache
CF-IPCountry
Servername
DSUID
X-MServer
X-Dynatrace-Js-Agent
X-Backend-Host
Section-Io-Origin-Status
Section-Io-Id
X-Amzn-Remapped-Connection
X-WA
X-VCT
Cache-Provider
Section-Origin-Responded
X-ID
X-Aicache-OS
X-ZONE
Release
X-Amzn-Remapped-Date
Section-Io-Origin-Time-Seconds
X-Hp-Ccpa-Warning
X-Frame-Option
X-WR-MODIFICATION
X-Ftr-Balancer
X-Ftr-Dc
X-Ftr-Backend-Server
X-Ftr-Backend
X-Ftr-Realm
Dynatrace
Pagetype
X-Fastly-Cache-Hits
Lfy
X-Tid
X-StackifyID
X-Configured-By
X-LB-ID
X-Snapshot-Date
Requestid
CDN
X-Branch-Name
X-BC
X-CACHE-AGE
V-Cache
X-Upstream-Ht
FSS-Proxy
FSS-Cache
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-Idcheck
WZWS-RAY
X-SD-PageType
SD-X-WS
X-Edge-IP
Cache-Cookie-Set-From
X-Upstream-Ct
X-Cc-Req-Id
X-Cc-Via
X-VC
X-Apw-Access-Action
D-Cc-Upstream
X-Apw-Access-Token
Warning
Proxy-Firewall
X-Request-Url
X-Apw-Hits
X-SB
X-Apw-Access-Object
X-Adobe-Source
X-Node-ID
X-Litespeed-Cache-Control
Backend-Name
X-Worker
X-Powered-Y
X-WPE-Loopback-Upstream-Addr
Cneonction
WP-Super-Cache
X-Li-Proto
X-Fmm-Version
X-ElasticPress-Search
X-Request-URL
Correlation-Id
X-App
X-SN
X-Varnish-Beresp-TTL
X-ServerName
X-Fastly-Cache-Status
X-Compress-Hint
Lb
L
X-Cache-Id
X-Check-Cacheable