Threat Level: green Handler on Duty: Bojan Zdrnja

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
Link
CF-RAY
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-UA-Compatible
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
X-Request-Id
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Request-ID
X-Cache-Status
X-Generator
Content-Security-Policy-Report-Only
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-DNS-Prefetch-Control
X-AspNetMvc-Version
X-Ua-Compatible
X-FRAME-OPTIONS
X-Buckets
Status
X-Content-Security-Policy
X-CDN
Content-Encoding
Upgrade
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Xss-Protection
X-Kinja-Server-Push
Keep-Alive
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
P3p
Xkey
X-Pass-Why
X-Cache-Group
X-AH-Environment
X-Envoy-Upstream-Service-Time
CF-Ray
X-Backend
X-Age
X-Server
X-Via
X-Robots-Tag
X-Amz-Id-2
X-Server-Powered-By
X-Amz-Request-Id
X-Page-Speed
X-Pingback
EagleId
X-Nginx-Cache-Status
X-Proxy-Cache
X-UA-Device
X-Hacker
X-Ws-Request-Id
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
Grace
Cf-Railgun
X-Swift-SaveTime
X-Swift-CacheTime
X-Amz-Version-Id
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
X-LiteSpeed-Cache
Report-To
X-Server-Id
X-Rq
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-WebKit-CSP
X-Host
X-Device
EagleEye-TraceId
Content-Location
X-Origin-Cache
X-OneAgent-JS-Injection
X-Response-Time
X-Node
X-Ac
Surrogate-Control
X-Vhost
X-Readtime
Request-Id
X-Backend-Server
X-Cloud-Trace-Context
X-Dispatcher
X-Origin-Upstream-Status
X-ORACLE-DMS-ECID
X-Cnection
X-HW
X-DataDome
X-Application-Context
X-ORACLE-DMS-RID
Fusion-Source
Fusion-Content-Source
Fusion-Content-Id
Fusion-Template-Id
Fusion-Component-Id
NEL
X-Mod-Pagespeed
X-Cache-Lookup
Edge-Control
Rating
X-Rack-Cache
X-Country
X-Akam-SW-Version
Pinterest-Generated-By
X-Clacks-Overhead
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Ruxit-JS-Agent
X-DynaTrace
X-Varnish-TTL
X-Country-Code
Accept-Ch
Allow
X-Instart-Request-ID
X-Goog-Hash
X-TtlSet
X-Vname
X-PC
X-TTL
X-FTR-Request-ID
X-ESI
Verso
Accept-Ch-Lifetime
X-Powered-By-Plesk
X-Url
Service-Worker-Allowed
Content-MD5
X-B3-TraceId
X-Forwarded-Proto
X-Version
X-MS-InvokeApp
X-GitHub-Request-Id
X-Exp-Variant
X-Cdn-Fetch
X-Exp-Id
X-Kinja-Server
X-GoogleNews-Bot
X-Use-Magma
X-Kinja-Revision
X-Kinja
X-Kinja-Build
Edge-Cache-Tag
RTSS
X-Px
AR-CACHE
AR-ATIME
AR-PoweredBy
Ar-Sid
AR-Request-ID
X-D2id
X-Debug
X-Abt-Application-Version
Charset
X-NF-Request-ID
SPRequestGuid
X-Server-Name
X-Amz-Server-Side-Encryption
X-Vcache
X-Powered-CMS
X-Accel-Expires
X-MSEdge-Ref
X-Cached
X-Amz-Rid
Arr-Disable-Session-Affinity
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Vcap-Request-Id
X-Sol
X-Middleton-Display
Display
Pagespeed
X-Middleton-Response
Response
X-Navigation-Version
X-Trace
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Pinterest-Rid
Pinterest-Version
X-SharePointHealthScore
TCN
X-Fastcgi-Cache
X-VARITI-CCR
X-Cdn
Realpath
Public-Key-Pins
Cache-Tag
Access-Control-Request-Method
X-Client-IP
S
X-Upstream
X-Fastly-Request-ID
X-DynaTrace-JS-Agent
X-Ser
MS-Author-Via
X-Shard
X-Id
SPRequestDuration
SPIisLatency
X-Hp-Webp
DynaTrace
X-Forwarded-For
X-Ezoic-Cdn
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Mrf-Item-Lastmod
MRF-Tech
X-Mrf-Section-Lastmod
X-T
Nginx-Cache
X-Content-Type
X-Amz-Meta-S3cmd-Attrs
X-Amzn-Trace-Id
X-Recruiting
Front-End-Https
X-Grace
X-Hits
Fastcgi-Cache
X-Varnish-Age
X-DIS-Request-ID
ServerID
MicrosoftSharePointTeamServices
X-Mobile-URL
X-Dw-Request-Base-Id
NR-ENABLED
X-Node-Name
Nel
X-Element-Page-Cache
X-Content-Digest
X-Goog-Generation
X-Frontend
Powered
X-Goog-Metageneration
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Cache-Config
X-GUploader-UploadID
X-HS-Hub-Id
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
Server-Name
X-Edge-O15-RID
X-FTR-Cache-Status
X-FTR-Expires
X-Country-Code-Real
Alternate-Protocol
X-Logged-In
X-FTR-Balancer
X-FTR-Backend
X-FTR-DC
X-FTR-Realm
X-FTR-Backend-Server
TP-Cache
TP-L2-Cache
Server-Node
X-Correlation-Id
X-Cache-TTL
X-Webkit-Csp
X-Webapp-Samesite-None-Activated-N
X-Shield-Request-Id
AMP-Access-Control-Allow-Source-Origin
X-Request-Processing-Time
X-Request-Received
X-Microsite
X-Request-Handler-Origin-Region
X-Server-ID
X-XRDS-LOCATION
Upgrade-Insecure-Requests
X-Jurisdiction
Refresh
X-Page-Id
X-Content-Options
X-Content-Security-Policy-Report-Only
X-Origin-Server
X-Rid
X-Revision
X-Akamai-Edgescape
X-User-Agent
X-Varnish-Grace
X-Cache-Hit
X-F-Cache
X-Amzn-RequestId
X-ATS-Timestamp
X-Amz-Apigw-Id
Backend-Timing
X-XRDS-Location
X-Type
Fastly-Restarts
X-Pad
X-Content-Powered-By
X-Analytics
X-Geo-Country
X-URL
X-AppVersion
X-N
X-Activity-Id
X-Az
X-Zen-Fury
X-LB-Cache
X-B3-Sampled
X-B
X-Kinsta-Cache
X-Ruxit-Js-Agent
X-RateLimit-Remaining
X-FTR-Cache-Host
X-TT
X-Cache-Age
PB-RID
PB-PID
X-WebKit-CSP-Report-Only
X-AOL-HN
X-Mobile-Rewrite
X-Framework
Arc-Version
X-Instance
X-Request-Guid
X-Jobs
X-Tumblr-Pixel
X-App-Environment
X-Tumblr-User
X-Tumblr-Pixel-0
Actual-Object-TTL
DC
Paypal-Debug-Id
X-B-Cache
X-Debug-Info
Access-Control-Allow-Method
X-Signature
Cache-Status
X-PHP-Backend
X-FB-Debug
X-CST
X-Load-Cache
X-Cache-Action
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
Surrogate-Key
Fastcgi-Useragent
X-Varnish-Backend
X-Git-Hash
X-Ttl
FilterID
Host-Header
X-Time
X-Tt-Trace-Tag
X-IPLB-Instance
X-Cached-By
MS-CV
X-Contextid
X-SS-Set-Cookie
X-Amz-Replication-Status
X-Tt-Trace-Host
X-Cluster
X-FastCGI-Cache
X-ATG-Version
X-Cache-Key
Tracecode
Frame-Options
X-Srv
X-Response-Served-From
NGB
X-Accel-Buffering
WPE-Backend
Source
X-Varnish-Server
Eomportal-Instance
Payment
X-FW-Static
X-FW-Server
Xserver
X-Adobe-Loc
X-RequestSource
X-Adobe-Content
X-Cache-Enabled
X-Cache-2
X-FW-Type
X-IPS-LoggedIn
Host
X-Tumblr-Pixel-2
Filters
X-Tumblr-Pixel-1
Cache-Tv-Group
X-GeoIP
X-Cache-NE
X-Varnish-Hostname
X-FW-Serve
X-Cacheable-TTL
X-FW-Hash
X-WA-Info
X-Region
X-TX-ID
X-Rendered-As
X-Mobile
X-Oneagent-Js-Injection
X-Host-Name
X-Is-Bot
Cleartype
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-NewRelic-App-Data
X-Seen-By
X-Trafficlayer-App-Scope
X-Cache-Rule
X-Cache-Operation
X-Trafficlayer-App-Name
X-EdgeConnect-Cache-Status
Cache
X-Hostname
X-Via-JSL
X-Cache-TTL-Remaining
X-Origin-Response-Time
X-VCache
X-Cache-Control
Healthy
X-HTML-Minification-Powered-By
Datacenter
X-ORACLE-APMCS-REQUEST-ID
X-Presslabs-Stats
X-ORACLE-APMCS-TAG
Accept-CH
X-B3-Traceid
X-Dc
Retry-After
X-RTag
Server-Info
X-ProcessESI
X-RemovedCookies
Ms-Operation-Id
X-UA
X-Rule
X-PressLabs-Stats
X-RateLimit-Limit
X-Cache-Server
Version
X-CACHE-KEY
X-Wix-Request-Id
From-Origin
Liferay-Portal
X-Status
X-FireWall-Port
X-L-Path
X-Source
X-Environment-Context
X-Upgrade-Enabled
X-NWS-LOG-UUID
X-Endurance-Cache-Level
Accept-CH-Lifetime
X-ES-SERVER
X-Cache-Var
X-Cache-Var-Map
X-RN-RSRV
X-Path-Route
Meta-Geo
OT-Force-Account-Verify
X-Timing-Wait
X-Proxy-Build
X-Handled-By
Selected-Fe
X-Storage
X-Alternate-Cache-Key
X-Backend-Name
X-UUID
X-Goog-Meta-Goog-Reserved-File-Mtime
X-EIG-Tracking-Id
X-Proto
X-ShardId
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Content-Age
X-Shopify-Generated-Cart-Token
X-Tb
X-Hyper-Cache
X-ShopId
TWC-Privacy
Azure-SlotName
X-Generated-By
Azure-Version
Cache-Tags
TWC-Connection-Speed
X-Debug-Cache
Property-Id
X-FC-Vary-Parameters
Webcakes-App-Name
Azure-SiteName
X-Hosted-By
X-Human
Azure-RegionName
X-JoinUs
X-Hl-Ver
TWC-Device-Class
Webcakes-Region
Webcakes-App-Version
Decoy-Debug-Key
TWC-Locale-Group
Now
Node
Origin-Cache-Control
Origin-Edge-Control
S-Rt
X-Akamai-Request-ID2
TWC-GeoIP-LatLong
NGX
TWC-GeoIP-Country
Azure-InstanceId
DB-Nickname
X-Cache-Config
Decoy-Debug-Status
Decoy-Debug-TTL
X-Section
Ec-Rule-Version
X-BYPASS-REASON
X-Cache-Host
X-Yottaa-Metrics
X-VWS-Id
X-Yottaa-Optimizations
X-Qloud-Router
X-Vgn-Hpd-Reason
X-Time-Microsecs
X-ProxyCache-Key
X-Viewer-Country
X-ProxyCache-Status
X-Redis-Cache
X-Web-Node
X-Format
Akamai-GRN
X-Access
X-Pubstack
X-Request-Time
X-Origin-Hint
X-AWS-Id
X-Proxy
X-Akamai-Request-ID
X-SaId
X-ServerID
X-Origin
X-OCL
X-Soup
X-FW-Dynamic
X-LJ-Flow-ID
X-PCL
X-Say-TTL
X-SayCDN-TTL
X-Varnish-Hits
X-Site-Version
X-BCube-Filmed-By
X-CCM
X-IP
X-NYM-Debug-Backend
X-MP-GENERATED-AT
X-Say-Cacheable
X-Locale
X-Cluster-Node
X-Generated
X-Www-Served-By
X-Xfnlog-Site
Mn-Server-Ip
X-Proxy-Cache-Status
X-RCS-CacheZone
L5d-Success-Class
X-App-Server
X-FB-TRIP-ID
X-Loop
Cross-Origin-Window-Policy
X-Detected-As
X-Amzn-Remapped-Content-Length
Cache-Name
X-TNCMS
Viewport
X-R9-Blue-Green-Version
Uber-Trace-Id
X-APP-VERSION
X-CS
GEO-INFO
Webserver
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
Time
X-Akamai-Transformed
Accept-Charset
X-Esi
Srv
X-NCache
X-Drupal-Cache-Tags
X-Cache-Remote
X-Unique-Id
X-From
X-UA-Device-Type
X-TT-TIMESTAMP
X-Edge-Location
X-Cluster-Name
X-Drupal-Cache-Contexts
X-Origin-TTL
Mime-Version
X-Origin-CC
Cache-Key
X-EC-Lua
Accept-Language
X-Backend-TTL
Country
X-CDN-Forward
X-Mode
Odigeo-Trace-Id
X-Newrelic-Synthetics
X-Microcachable
X-CLOUD-TRACE-CONTEXT
Ohc-Cache-HIT
Rt-Fastcgi-Cache
X-B3-Spanid
Ohc-File-Size
X-Forwarded-Host
X-No-Session
X-Geo
X-Info
Proxy-Connection
X-UPSTREAM-Address
X-Magnolia-Registration
X-PHP-Host
X-Labrador-Cache-Channel
X-Zipkin-Id
X-App-Version
X-Real-IP
Content-Disposition
X-UnsetCookies
X-Whom
ServedBy
X-Proxied
X-Varnish-Cache-Hits
X-Routing-Service
X-ApacheServer
X-PERF
X-Cache-Time
Cf-Ipcountry
Fastly-SSL
X-A-Dam
X-ARC
X-Application
X-A-Ccd
X-Aed
X-Accel-Expires-Debug
X-A-Dgt
X-A-Wwc
X-A-Dcw
Fastcgi-X-Cache-Version
X-B-Cookie
GEO-REGION-INFO
Machine
Content-Style-Type
Content-Script-Type
AsisCache
BehaviorPad-Version
MD5-Digest
Meta-Geo-Continent
Viewtype
VivaBuild
T-Server
Rendered-Blocks
Mobile-Detection-Method
Powered-By
X-A
X-External-Request-Id
X-Rojux
X-S
X-VG-WebServer
X-Rewrite-Enabled
X-Region-Sid
X-Request-UUID
X-S-Cookie
X-ScT
X-Transaction
X-Trv-Group
X-Vdms-Version
X-SRCache-Key
X-VG-WebCache
X-Session-Fingerprint
X-Twitter-Response-Tags
X-Vtex-Processado-Em
X-Connection-Hash
X-D
X-CF-Lambda-Version
X-CF-Lambda-Fn
Xc-Version
X-Destination
X-Date
X-Vtex-Remote-Cache
X-GeoIP-Country-Code
X-G
X-Geo-Header
X-DPWN-IS-SECURE
Access-Control-Request-Headers
X-Device-Type
User-Cache-Control
X-SIPLIST1
X-Varnish-Authentication
IsBot
X-WebServer
X-VG-TLSProxy
X-Via-Fastly
X-VC-Cache
Gh-Request-Id
W
Server-Surrogate-Control
Server-Cache-Control
X-Contensis-Viewer-Groups
X-Cache-Debug
X-Bip
X-Cache-ASPX
X-Logging-Id
X-Rocket-Build-Number
X-Thanos
X-TrackingId
Environment
X-Sigma-Backend
X-Auto-Login
X-Sigma
X-Tumblr-Pixel-3
X-CUA
X-Cache-Backend
X-C
X-Uri
Geo-Info
FNAC-ModuleRouting
Locid
We-Hiring
RNT-Machine
X-Sucuri-Cache
X-Trace-Id
Web-Mar-Node
Fastly-Soc-X-Request-Id
X-Webstats-RespID
X-Agile
Fastly-Backend-Name
X-Epic-Correlation-Id
X-FW-Version
X-Eu-Site
X-Fastly-Cache
RNT-Time
X-TH-Server
X-Generation-Time
Server-ID
Section-Io-Cache
Wxu-Next-Commit
Wxu-Next-Region
Wxu-Next-Hostname
Server-Int
X-Generated-In
X-Agile-Age
X-Proxy-Upstream
X-RateLimit-Limit-Second
True-Client-Country-4JS
X-Gen-Mode
X-Gamma-Serve
V-Age
X-AK-Request-ID
X-Urbn-Context-Path
X-CGP
X-OVcl-Cache
X-Cdn-Srv
X-Debug-Cookies
X-Debug-Cache-Store
X-Clara-WADP
X-Clientip
X-NGENIX-Cache
X-TT-LOGID
X-OVcl
X-Debug-Cache-Expiry
X-Cms-Context
X-Debug-Cache-Fetch
X-Cache-Info
X-Urbn-Site-Id
X-Distil-CS
X-VServer
X-WADP-Cache
X-We-Are-Hiring
X-Distributor
X-Origin-Expires
X-Backend-State
X-BBXSRF
X-Cache-Bucket
X-User
X-Debug-Log
X-Block-Status
X-Dispatcher-Server
X-Owner
X-Agile-Id
X-GeoIP-City
CDCHOST
Cdncip
Cdnsip
Cache-Host
X-LI-UUID
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Handled
X-LI-Proto
Request-EU
X-Wikidot-Backend
X-Wikidot-Static-Cache
Country-Code
Countrycode
X-App-Name
X-Location
ServerName
X-Render-Time
X-Request-URI
X-SVT-ORM-RULES
X-NX-Host
X-NodeID
X-SVT-ORM-VERSION
X-Varnish-Beresp-Ttl
X-Swa-Ws
AKAMAI
X-Ms-Request-Id
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-Ms-Version
X-Li-Fabric
X-Li-Pop
X-Hnp-Log
X-Developers
Memcached
X-IN-APIGATEWAY
X-Instart-Isnd
X-IN-APIGATEWAYSSL
X-Hit
X-Hash
X-Origin-Date
Request-Country
X-GoCache-CacheStatus
X-Cache-URL
X-Core-Mission
X-Irp-Debug
Mail-Subject
Heartbleed
IBM-Web2-Location
HA-Ipaddr
Ha-Gx-Prefs
X-RateLimit-Remaining-Second
X-Req
Kp-EeAlive
X-Key
X-Nginx-Cache-Key
Locale
X-B3-Parentspanid
X-Trafficlayer-App-Version
X-Level-Front-Cache
X-NU-AKA-ACS-Version
X-Matched-Rule
X-Has-Esi
X-Thinkindot-L3
X-Generated-On
X-Is-Gdpr
X-JWT-State
Fastly-SWR
X-Core-Value
Platform
PFcat
X-Azure-Ref
Adler-Geo
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-ServiceProvider
X-Service
Is-Eu
X-Reboot
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Internal-Host
X-Micro-Cache
Thinkindot-Control
Server-Host
Fastly-SIE
X-S-Maxage
X-Cache-Tags
X-Variation
X-Up
X-Platform-Server
X-Old-Content-Length
X-TA-CDN-Provider
HitType
X-Server-W
X-Daa-Tunnel
Cache-Hits
X-Lb-Id
X-Refresh
X-Response-By
X-SERVER
X-Nc
X-Server-IP
RequestId
X-Fetched-On
X-Servername
X-Nginx-Cache
X-B3-SpanId
X-Parent-Response-Time
X-Tb-Optimization-Total-Bytes-Saved
X-Cdn-Forward
X-CF-Powered-By
X-NC
ProcessTime
X-Tec-Api-Version
X-Cdn-Request-ID
Media-Length
X-Tec-Api-Root
X-Tec-Api-Origin
Memory
X-CSRF-TOKEN
X-Pjax-Url
X-CSRF-Token
Origin
X-Air-Hostname
X-Wa
X-BACKEND-TTL
User-Agent
SRV
Filterid
X-Var-Ttl
TTL
Geoip-Latitude
Pragrma
Group
X-Pf-Uncompressing
X-Cache-Expired-At
X-TIME
X-Ua
X-Unique-ID
X-Correlation-ID
X-Reqid
GeoIp-Country-Code
X-AIR-PT
X-Vcl-Version
X-Sucuri-Id
X-NGINX-Cache
Esi-Enabled
X-Rocket-Nginx-Bypass
Powered-By-ChinaCache
X-COUNTRY
S-Cnection
X-Policy
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Sucuri-ID
X-Request-Start
PICS-Label
HostName
SN
X-Webkit-CSP
X-Litespeed-Cache
X-Azure-Ref-OriginShield
X-Varnish-Cacheable
Rt-Proxy-Cache
X-Servedbyhost
M-TraceId
X-HS-Status
X-Via-Ucdn
Geoip-City
XServer
Dnion-Transfer-Encoding
X-Fastly-Country-Code
X-Via-CDN
Magicmarker
X-Method
X-FORWARDED-FOR
Load-Balancing
X-NWS-UUID-VERIFY
Tcn
X-Developer
X-Cdn-Origin
X-Ocache
Ohc-Response-Time
X-Sn-Servicetimems
Resin-Trace
X-Cache-Ttl
DSUID
X-ServedByHost
X-Device-Os
Who
X-Cache-Grace
X-Node-Id
X-LAGOON
X-Ftr-Cache-Host
X-VHOST
Release
Cdn
On-Server
NtCoent-Length
CF-Cached-On
X-Svr
X-Be
X-VCT
X-MServer
Vix-Hermes-Req-Id
X-Bc
X-MSEdge-Features
X-Hp-Ccpa-Warning
X-MSEdge-Flight
A
X-Request-Host
X-Zone
X-APP
Pics-Label
GeoIP-Country-Code
X-Oss-Server-Time
X-Oss-Object-Type
X-Oss-Storage-Class
X-Ratelimit-Remaining
Cloudfront-Viewer-Country
X-Oss-Hash-Crc64ecma
Cteonnt-Length
X-VCL-Version
X-Oss-Request-Id
X-Oracle-Dms-Rid
MIME-Version
X-VarnishDD-TTL
X-Beluga-Node
X-Fastly-Backend-Reqs
X-Beluga-Record
X-Beluga-Response-Time
GeoIP-Latitude
X-Configured-By
X-Beluga-Trace
Ttl
X-Beluga-Status
X-Varnish-Url
X-Beluga-Cache-Status
X-DC
X-Cache-Status-Check
X-LiteSpeed-Cache-Control
GeoIP-City
X-Varnish-URL
X-SD-PageType
Hostname
X-PF-Uncompressing
X-Newrelic-App-Data
X-Varnish-Ttl
SD-X-WS
X-WR-MODIFICATION
X-Compress-Hint
X-Upstream-Ct
X-Upstream-Ht
X-SN
Host-ID
X-Ftr-Request-Id
X-PJAX-URL
X-Cache-Id
X-SRV
X-Tid
X-HostName
X-Via-NSCOPI
X-Aicache-OS
L
X-Release
Processtime
X-BE
X-Ratelimit-Limit
X-Dynatrace
X-Dynatrace-Js-Agent
CACHE
X-Swift-Error
X-Scheme
LB
X-Slack-Backend
X-ID
Cache-Provider
WebServer
Amp-Access-Control-Allow-Source-Origin
X-Frame-Option
X-ServerName
X-Ftr-Backend
X-Ftr-Realm
X-StackifyID
Requestid
X-Ftr-Dc
X-Ftr-Balancer
X-Ftr-Backend-Server
X-Action
UCS
Cache-Cookie-Set-Idcheck
X-Snapshot-Date
X-RPM
X-RPS
X-DW
X-DSS
CF-IPCountry
Servername
X-RSL
Pagetype
X-Fastly-Cache-Hits
Cache-Cookie-Set-Lfrom
Lfy
X-DB
X-DI
Cache-Cookie-Set-From
X-Branch-Name
X-LB-ID
Dynatrace
CDN
X-CACHE-AGE
Warning
X-Cc-Req-Id
D-Cc-Upstream
X-Dispatch
X-Cc-Via
X-VC
Pramga
X-Cache-FS-Status
X-FPC
X-Server-Time
X-Processor
X-PAYTM-SRV-ID
Arc-Country
X-Skip-Cache
X-ZONE
X-SB
X-Apw-Access-Action
X-Apw-Hits
X-Apw-Access-Token
X-Apw-Access-Object
X-Node-ID
Proxy-Firewall
V-Cache
X-Varnish-Beresp-TTL
X-Edge-IP
NnCoection
X-Litespeed-Cache-Control
WZWS-RAY
X-Hello
X-ND-Cache
X-Flog
X-DevSite-Last-Modified
Fastly-Drupal-HTML
X-ABtesting
X-Fastly-Cache-Status
Correlation-Id
X-ElasticPress-Search
X-Powered-Y
X-Check-Cacheable
X-Request-URL
WP-Super-Cache
X-Request-Url
Backend-Name
X-App
X-BC
X-Worker
Lb