Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
CF-RAY
Link
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Request-ID
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-DNS-Prefetch-Control
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
Status
Upgrade
X-Content-Security-Policy
Content-Encoding
X-CDN
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
X-Xss-Protection
Keep-Alive
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
P3p
X-Pass-Why
Xkey
X-Cache-Group
X-AH-Environment
X-Envoy-Upstream-Service-Time
CF-Ray
X-Via
X-Backend
X-Ua-Compatible
X-Server
X-Age
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Server-Powered-By
X-Ws-Request-Id
X-Page-Speed
X-Pingback
EagleId
X-Proxy-Cache
X-Hacker
X-Nginx-Cache-Status
X-UA-Device
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
Cf-Railgun
Grace
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Amz-Version-Id
Report-To
X-LiteSpeed-Cache
X-Rq
X-OneAgent-JS-Injection
X-WebKit-CSP
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Server-Id
X-Device
X-Host
X-Origin-Cache
EagleEye-TraceId
X-Response-Time
X-Ac
X-Node
Surrogate-Control
Content-Location
X-Cloud-Trace-Context
X-Vhost
X-Readtime
X-Backend-Server
Request-Id
X-Dispatcher
X-Origin-Upstream-Status
X-Cnection
X-Application-Context
X-HW
X-Cache-Lookup
X-ORACLE-DMS-ECID
Fusion-Content-Id
Fusion-Component-Id
Fusion-Content-Source
Fusion-Template-Id
Fusion-Source
X-Ruxit-JS-Agent
X-ORACLE-DMS-RID
X-DataDome
NEL
X-Mod-Pagespeed
X-Dns-Prefetch-Control
X-Rack-Cache
Rating
Edge-Control
X-Country
X-Clacks-Overhead
X-Akam-SW-Version
Pinterest-Generated-By
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-TTL
Allow
X-Country-Code
X-DynaTrace
Accept-Ch
X-FTR-Request-ID
X-Instart-Request-ID
X-Varnish-TTL
X-Goog-Hash
X-TtlSet
X-PC
X-Vname
X-ESI
Verso
Accept-Ch-Lifetime
Content-MD5
X-Powered-By-Plesk
Service-Worker-Allowed
X-Url
X-B3-TraceId
X-Forwarded-Proto
X-Version
X-MS-InvokeApp
X-Exp-Id
X-Cdn-Fetch
X-Exp-Variant
X-GoogleNews-Bot
X-Use-Magma
X-Kinja-Revision
X-Kinja-Server
X-Kinja-Build
X-Kinja
X-GitHub-Request-Id
RTSS
Edge-Cache-Tag
X-D2id
X-Abt-Application-Version
X-Debug
X-Server-Name
X-Px
Ar-Sid
AR-Request-ID
AR-PoweredBy
AR-ATIME
AR-CACHE
X-Amz-Server-Side-Encryption
X-Vcache
SPRequestGuid
Charset
X-NF-Request-ID
X-Cached
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Accel-Expires
X-Sol
Display
X-Middleton-Response
X-Middleton-Display
Response
Pagespeed
X-Vcap-Request-Id
X-Fastcgi-Cache
X-Amz-Rid
X-MSEdge-Ref
Arr-Disable-Session-Affinity
X-Navigation-Version
X-Pinterest-Rid
Pinterest-Version
X-Powered-CMS
X-SharePointHealthScore
TCN
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Trace
X-Cdn
X-VARITI-CCR
Public-Key-Pins
Cache-Tag
Realpath
X-Client-IP
X-Fastly-Request-ID
X-Ser
Access-Control-Request-Method
MS-Author-Via
Nginx-Cache
X-Server-ID
X-Edge-O15-RID
X-DynaTrace-JS-Agent
X-Shard
S
MRF-Tech
SPRequestDuration
SPIisLatency
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
X-Upstream
X-Id
X-Content-Type
X-Ezoic-Cdn
X-Hp-Webp
X-Grace
X-Amzn-Trace-Id
X-Forwarded-For
X-T
X-Amz-Meta-S3cmd-Attrs
Nel
Front-End-Https
X-Hits
X-Recruiting
Fastcgi-Cache
DynaTrace
X-Aspnet-Version
X-Jurisdiction
X-Varnish-Age
X-Cache-TTL
ServerID
MicrosoftSharePointTeamServices
X-Element-Page-Cache
X-Node-Name
X-Mobile-URL
X-Content-Digest
X-Country-Code-Real
X-Dw-Request-Base-Id
X-FTR-Backend
X-FTR-Balancer
X-FTR-Expires
X-FTR-DC
X-FTR-Cache-Status
X-DIS-Request-ID
X-FTR-Backend-Server
X-FTR-Realm
NR-ENABLED
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Hub-Id
X-Goog-Metageneration
X-Goog-Generation
Powered
X-Goog-Storage-Class
X-GUploader-UploadID
Server-Node
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Frontend
TP-L2-Cache
TP-Cache
Alternate-Protocol
Server-Name
X-Logged-In
X-CST
X-XRDS-Location
AMP-Access-Control-Allow-Source-Origin
X-Request-Received
X-Request-Processing-Time
X-Amz-Apigw-Id
X-Amzn-RequestId
Upgrade-Insecure-Requests
X-Request-Handler-Origin-Region
X-Correlation-Id
X-Microsite
Backend-Timing
X-ATS-Timestamp
X-Cache-Hit
X-Content-Options
X-Content-Security-Policy-Report-Only
X-F-Cache
Refresh
X-Origin-Server
X-User-Agent
X-Page-Id
X-Rid
X-Akamai-Edgescape
X-Revision
Fastly-Restarts
X-Zen-Fury
X-Varnish-Grace
X-Type
X-Content-Powered-By
X-XRDS-LOCATION
X-LB-Cache
X-B
X-FTR-Cache-Host
X-B3-Sampled
PB-PID
PB-RID
X-Geo-Country
X-URL
X-Activity-Id
X-AppVersion
X-Az
Arc-Version
X-Mobile-Rewrite
Cache-Status
X-Kinsta-Cache
X-N
X-Cache-Age
X-Pad
X-Shield-Request-Id
X-TT
X-Instance
X-AOL-HN
X-WebKit-CSP-Report-Only
X-Signature
X-Cache-Action
X-B-Cache
X-Debug-Info
X-Time
X-Tumblr-User
X-Tumblr-Pixel
X-Jobs
Paypal-Debug-Id
Access-Control-Allow-Method
X-Tumblr-Pixel-0
X-Framework
Actual-Object-TTL
X-App-Environment
X-Load-Cache
X-FB-Debug
X-Request-Guid
X-PHP-Backend
X-Cached-By
DC
X-Git-Hash
Fastcgi-Useragent
X-Webkit-Csp
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-RateLimit-Remaining
X-Varnish-Backend
X-Amz-Replication-Status
Surrogate-Key
X-Erf-Bev-Bev-Is-Generated
X-Webapp-Samesite-None-Activated-N
X-Erf-Bev-Bev
X-IPLB-Instance
Host-Header
X-Contextid
MS-CV
X-Analytics
X-ATG-Version
X-SS-Set-Cookie
X-WA-Info
Host
FilterID
X-NWS-LOG-UUID
X-Mobile
X-ORACLE-APMCS-TAG
X-ORACLE-APMCS-REQUEST-ID
NGB
X-Accel-Buffering
X-Cluster
Tracecode
X-Response-Served-From
WPE-Backend
Payment
X-Via-JSL
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Host-Name
X-Cache-NE
X-FW-Serve
X-FW-Static
Source
X-FW-Server
X-FW-Hash
X-Region
X-FW-Type
Xserver
X-Cache-2
Eomportal-Instance
X-Varnish-Server
X-GeoIP
X-IPS-LoggedIn
Cache-Tv-Group
X-Varnish-Hostname
Filters
X-Origin-Response-Time
Frame-Options
X-Cache-Key
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
X-Adobe-Loc
X-Cache-Enabled
X-Srv
X-Cacheable-TTL
X-Adobe-Content
X-Is-Bot
X-Seen-By
X-RequestSource
X-Cache-Operation
X-Rendered-As
X-Cache-Rule
X-Hostname
X-TX-ID
X-EdgeConnect-Cache-Status
X-Presslabs-Stats
Retry-After
X-NewRelic-App-Data
X-FastCGI-Cache
Server-Info
X-Cache-TTL-Remaining
Cleartype
X-VCache
X-RemovedCookies
X-ProcessESI
Accept-CH
Liferay-Portal
X-B3-Traceid
X-CACHE-KEY
X-Dc
Ms-Operation-Id
X-App-Server
X-RTag
X-L-Path
X-Environment-Context
X-Source
X-HTML-Minification-Powered-By
X-UA
Datacenter
X-FireWall-Port
X-Endurance-Cache-Level
X-Upgrade-Enabled
X-Handled-By
From-Origin
X-Cache-Server
Accept-CH-Lifetime
Cache
X-PressLabs-Stats
X-Backend-Name
X-Cache-Control
Srv
Healthy
X-Wix-Request-Id
X-Cache-Var
X-Cache-Var-Map
X-ES-SERVER
Meta-Geo
X-Path-Route
X-RN-RSRV
X-Section
OT-Force-Account-Verify
X-Status
X-Tb
X-Proxy-Build
X-APP-VERSION
Accept-Charset
X-Format
Selected-Fe
X-Timing-Wait
X-Access
Version
Cache-Tags
X-PCL
X-ShardId
X-UUID
Azure-Version
Azure-RegionName
Azure-InstanceId
Akamai-GRN
X-Akamai-Request-ID
Azure-SiteName
Azure-SlotName
X-Proto
X-Alternate-Cache-Key
X-ShopId
X-Request-Time
X-Sorting-Hat-PodId
X-NYM-Debug-Backend
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Cache-Config
X-EIG-Tracking-Id
X-Content-Age
Mn-Server-Ip
X-OCL
X-Shopify-Stage
X-Shopify-Generated-Cart-Token
X-Origin
X-FC-Vary-Parameters
X-Sorting-Hat-ShopId
NGX
Origin-Cache-Control
Node
Now
Decoy-Debug-Key
DB-Nickname
Decoy-Debug-Status
X-Web-Node
Ec-Rule-Version
Origin-Edge-Control
X-Generated-By
X-Say-Cacheable
X-SaId
X-Say-TTL
X-SayCDN-TTL
X-Soup
X-ServerID
X-Proxy
X-Redis-Cache
X-Pubstack
X-ProxyCache-Status
X-ProxyCache-Key
X-Proxy-Cache-Status
X-Qloud-Router
X-Time-Microsecs
X-Vgn-Hpd-Reason
X-FW-Dynamic
X-Hl-Ver
X-Debug-Cache
X-Cluster-Node
X-AWS-Id
X-BYPASS-REASON
X-Hosted-By
X-Human
X-LJ-Flow-ID
X-Viewer-Country
X-JoinUs
X-VWS-Id
X-Hyper-Cache
X-Akamai-Request-ID2
Decoy-Debug-TTL
X-RateLimit-Limit
X-Storage
X-Yottaa-Optimizations
X-Rule
X-Yottaa-Metrics
Webcakes-Region
X-Amzn-Remapped-Content-Length
X-BCube-Filmed-By
Webcakes-App-Version
TWC-Locale-Group
TWC-Device-Class
TWC-Connection-Speed
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Privacy
Webcakes-App-Name
Cross-Origin-Window-Policy
X-Origin-Hint
Property-Id
X-Www-Served-By
X-Site-Version
X-TNCMS
X-MP-GENERATED-AT
X-Loop
X-CCM
X-FB-TRIP-ID
X-Generated
X-Varnish-Hits
S-Rt
X-Xfnlog-Site
GEO-INFO
X-Cache-Host
X-Locale
X-RCS-CacheZone
X-R9-Blue-Green-Version
X-Akamai-Transformed
X-NCache
X-Detected-As
X-IP
L5d-Success-Class
X-CS
X-Drupal-Cache-Tags
X-Esi
Cache-Name
Cache-Key
X-Unique-Id
Webserver
Viewport
Uber-Trace-Id
Time
X-UA-Device-Type
X-UnsetCookies
X-Mode
X-Forwarded-Host
Mime-Version
X-Cache-Remote
Accept-Language
Rt-Fastcgi-Cache
X-Whom
X-Origin-CC
X-Origin-TTL
X-Daa-Tunnel
X-Info
Content-Disposition
X-From
Country
X-NGENIX-Cache
X-Backend-TTL
X-CDN-Forward
Odigeo-Trace-Id
X-Varnish-Cache-Hits
X-Ruxit-Js-Agent
X-PERF
X-Cluster-Name
X-ApacheServer
X-B3-Spanid
X-Drupal-Cache-Contexts
X-Magnolia-Registration
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-CLOUD-TRACE-CONTEXT
ServedBy
X-Microcachable
X-Newrelic-Synthetics
X-TT-TIMESTAMP
X-Geo
X-Zipkin-Id
X-Routing-Service
X-Proxied
X-Device-Type
X-Ttl
X-EC-Lua
Section-Io-Cache
X-Nc
X-Via-Fastly
Ohc-File-Size
X-Trafficlayer-App-Name
X-Trafficlayer-App-Scope
X-Uri
Cf-Ipcountry
Proxy-Connection
Ohc-Cache-HIT
X-Edge-Location
X-UPSTREAM-Address
HitType
Geo-Info
X-External-Request-Id
Apple-News-Services-Handled
Apple-News-Services-Host
X-Vtex-Remote-Cache
X-VG-TLSProxy
Meta-Geo-Continent
X-Aed
X-VG-WebServer
X-Vdms-Version
X-G
X-Twitter-Response-Tags
X-Geo-Header
X-A-Dam
X-GeoIP-Country-Code
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-Sigma-Backend
X-A-Dgt
Rendered-Blocks
X-A-Ccd
X-Session-Fingerprint
X-A
X-ScT
X-Sigma
GEO-REGION-INFO
Mobile-Detection-Method
Apple-News-Services-Request-Url
Xc-Version
X-Destination
Fastcgi-X-Cache-Version
VivaBuild
Viewtype
Machine
X-Application
X-Rocket-Build-Number
X-Region-Sid
W
X-Request-UUID
X-Rewrite-Enabled
X-A-Wwc
X-D
X-No-Session
X-Trv-Group
X-Vtex-Processado-Em
X-Transaction
X-Rojux
X-ARC
X-S
X-Accel-Expires-Debug
BehaviorPad-Version
X-SRCache-Key
AsisCache
Apple-News-Services-Parsed-Url
X-A-Dcw
MD5-Digest
X-VG-WebCache
X-Date
Content-Script-Type
Content-Style-Type
X-B-Cookie
X-Connection-Hash
T-Server
X-DPWN-IS-SECURE
X-S-Cookie
Access-Control-Request-Headers
User-Cache-Control
X-C
X-Agile-Id
X-Thanos
Server-Cache-Control
X-Eu-Site
X-Cache-ASPX
X-Developers
X-SIPLIST1
X-Logging-Id
X-VC-Cache
Ha-Gx-Prefs
X-Tumblr-Pixel-3
X-Bip
X-Auto-Login
X-Varnish-Authentication
X-Distil-CS
Countrycode
IsBot
X-CUA
Server-Surrogate-Control
HA-Ipaddr
CDCHOST
Gh-Request-Id
Fastly-SIE
X-TrackingId
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
X-Wikidot-Backend
X-Contensis-Viewer-Groups
X-Hit
Powered-By
X-CGP
Fastly-SWR
Locid
Fastly-Soc-X-Request-Id
Environment
X-Cache-Debug
X-Clientip
X-App-Name
X-Rebelmouse-Cache-Control
X-Agile
X-Wikidot-Static-Cache
X-Agile-Age
X-Rebelmouse-Surrogate-Control
X-WebServer
Fastly-SSL
X-Cache-Backend
X-Real-IP
X-GoCache-CacheStatus
X-Core-Mission
X-Backend-State
X-VServer
X-Block-Status
X-BBXSRF
X-Azure-Ref
X-AK-Request-ID
X-Cache-Bucket
X-Cache-Info
X-Cdn-Srv
X-Clara-WADP
X-Cache-URL
X-Cache-Time
X-Cache-Tags
X-Cms-Context
X-Labrador-Cache-Channel
X-Owner
X-OVcl-Cache
X-PHP-Host
X-Platform-Server
X-RateLimit-Limit-Second
X-Proxy-Upstream
X-OVcl
X-Origin-Expires
X-Nginx-Cache-Key
X-Ms-Version
X-NodeID
X-NU-AKA-ACS-Version
X-Origin-Date
X-NX-Host
X-RateLimit-Remaining-Second
X-Render-Time
X-Swa-Ws
X-SVT-ORM-VERSION
X-TH-Server
X-Trace-Id
X-Up
X-TT-LOGID
X-SVT-ORM-RULES
X-Urbn-Site-Id
X-Request-URI
X-Variation
X-User
X-Server-W
X-Servername
X-Ms-Request-Id
X-Micro-Cache
X-Fetched-On
X-Fastly-Cache
X-FW-Version
X-Gamma-Serve
X-Generated-In
X-Gen-Mode
X-Epic-Correlation-Id
X-Distributor
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Debug-Cookies
X-Debug-Log
X-Dispatcher-Server
X-Generation-Time
X-GeoIP-City
X-JWT-State
X-Is-Gdpr
X-Li-Fabric
X-Li-Pop
X-LI-UUID
X-LI-Proto
X-Irp-Debug
X-Instart-Isnd
X-Hash
X-Has-Esi
X-Hnp-Log
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Debug-Cache-Expiry
Heartbleed
Platform
Memcached
Mail-Subject
Locale
X-App-Version
Request-Country
RNT-Time
RNT-Machine
Request-EU
Kp-EeAlive
Is-Eu
Cache-Host
AKAMAI
Adler-Geo
Cdncip
Cdnsip
IBM-Web2-Location
X-Urbn-Context-Path
Country-Code
X-We-Are-Hiring
X-Webstats-RespID
X-WADP-Cache
True-Client-Country-4JS
V-Age
We-Hiring
Web-Mar-Node
Server-ID
Server-Int
X-Level-Front-Cache
X-Thinkindot-L3
Server-Host
FNAC-ModuleRouting
X-Air-Hostname
X-Internal-Host
X-Trafficlayer-App-Version
Wxu-Next-Region
Wxu-Next-Hostname
Fastly-Backend-Name
X-ServiceProvider
PFcat
X-Reboot
ServerName
Thinkindot-CacheControl
X-Req
X-Service
X-Core-Value
Thinkindot-CacheControl-Type
X-Matched-Rule
Thinkindot-Control
X-Generated-On
X-Old-Content-Length
Wxu-Next-Commit
X-Nginx-Cache
Filterid
Group
X-Sucuri-Cache
X-S-Maxage
X-Var-Ttl
X-SERVER
X-Lb-Id
X-Key
X-Cache-Expired-At
Cache-Hits
X-Refresh
X-VHOST
X-Location
Pragrma
X-Response-By
RequestId
S-Cnection
X-Parent-Response-Time
X-CSRF-TOKEN
X-Tb-Optimization-Total-Bytes-Saved
X-TA-CDN-Provider
Powered-By-ChinaCache
X-Cdn-Forward
X-CF-Powered-By
X-BACKEND-TTL
X-Correlation-ID
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
ProcessTime
X-B3-Parentspanid
Origin
X-Wa
Memory
X-Pjax-Url
X-Sucuri-ID
X-Ua
X-Varnish-Cacheable
User-Agent
X-NC
X-B3-SpanId
X-CSRF-Token
TTL
X-Server-IP
X-Pf-Uncompressing
X-Via-CDN
X-Unique-ID
SRV
X-NWS-UUID-VERIFY
Geoip-Latitude
X-Developer
X-Vcl-Version
Geoip-City
X-Node-Id
X-Sn-Servicetimems
X-Ocache
X-Cdn-Origin
GeoIp-Country-Code
X-Cache-Grace
PICS-Label
X-LAGOON
X-Device-Os
X-NGINX-Cache
X-COUNTRY
Media-Length
On-Server
X-Cdn-Request-ID
X-Cache-Status-Check
X-Oss-Storage-Class
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Oss-Request-Id
X-Litespeed-Cache
X-Request-Host
X-Webkit-CSP
X-Servedbyhost
X-MSEdge-Flight
X-MSEdge-Features
A
Hostname
M-TraceId
SN
X-Via-Ucdn
Dnion-Transfer-Encoding
X-Varnish-Ttl
X-Rocket-Nginx-Bypass
Cloudfront-Viewer-Country
X-TIME
XServer
X-Sucuri-Id
Tcn
X-FORWARDED-FOR
X-AIR-PT
X-HS-Status
Esi-Enabled
Cdn
X-Reqid
X-Ratelimit-Remaining
Who
X-Cache-Ttl
Host-ID
X-Policy
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Fastly-Country-Code
X-Beluga-Cache-Status
X-Varnish-URL
X-Beluga-Response-Time
X-Beluga-Node
X-Beluga-Status
Resin-Trace
X-ServedByHost
X-Beluga-Trace
X-Beluga-Record
HostName
X-Azure-Ref-OriginShield
X-Request-Start
CF-Cached-On
GeoIP-Country-Code
X-Slack-Backend
Pics-Label
Rt-Proxy-Cache
CACHE
X-VCL-Version
X-Fastly-Backend-Reqs
GeoIP-Latitude
X-Action
MIME-Version
X-Oracle-Dms-Rid
X-LiteSpeed-Cache-Control
X-Ftr-Cache-Host
X-RPM
X-DW
X-RPS
X-RSL
Pramga
Arc-Country
X-DSS
X-DI
Ttl
NtCoent-Length
X-Method
X-PF-Uncompressing
X-DB
X-Varnish-Url
X-Cache-FS-Status
X-Dispatch
GeoIP-City
X-Zone
X-Bc
X-APP
X-Server-Time
Magicmarker
X-Processor
X-PAYTM-SRV-ID
X-DC
X-ND-Cache
X-VarnishDD-TTL
Cteonnt-Length
X-Hello
X-Flog
X-Skip-Cache
X-Ratelimit-Limit
X-ABtesting
X-Newrelic-App-Data
X-HostName
X-Served-From
X-PJAX-URL
Amp-Access-Control-Allow-Source-Origin
Cdn-Host
X-FPC
X-SRV
WebServer
Fastly-Drupal-HTML
X-Edge-Server
Cdn-Request-Time
X-DevSite-Last-Modified
X-Svr
Ohc-Response-Time
X-Bc-Bl
X-Dynatrace
X-BE
N-Cache
Processtime
X-Be
X-Swift-Error
Servername
Load-Balancing
X-Dynatrace-Js-Agent
Section-Io-Origin-Status
X-Aicache-OS
X-Amzn-Remapped-Connection
Vix-Hermes-Req-Id
Cache-Provider
Section-Io-Id
X-WA
X-Amzn-Remapped-Date
Section-Io-Origin-Time-Seconds
X-ID
X-Backend-Host
Section-Origin-Responded
X-Frame-Option
X-WR-MODIFICATION
X-LB-ID
X-Snapshot-Date
CDN
X-Branch-Name
CF-IPCountry
X-Fastly-Cache-Hits
Lfy
Requestid
X-BC
X-MServer
Dynatrace
DSUID
X-StackifyID
Pagetype
X-ZONE
X-CACHE-AGE
Release
X-VCT
FSS-Proxy
X-Fmm-Version
X-Configured-By
Proxy-Firewall
FSS-Cache
Cache-Cookie-Set-Lfrom
X-Tid
WZWS-RAY
Cache-Cookie-Set-From
Cache-Cookie-Set-Idcheck
D-Cc-Upstream
Warning
X-Cc-Req-Id
X-Cc-Via
X-VC
V-Cache
X-Hp-Ccpa-Warning
X-Request-Url
X-Apw-Hits
X-SB
X-Apw-Access-Action
X-Apw-Access-Object
X-Apw-Access-Token
X-Litespeed-Cache-Control
X-Adobe-Source
Correlation-Id
Cneonction
X-Edge-IP
WP-Super-Cache
X-Worker
Backend-Name
X-Scheme
X-Fpc
Trailer
Fusion-Deployment-Id
X-ElasticPress-Search
X-WPE-Loopback-Upstream-Addr
X-SD-PageType
X-Fastly-Cache-Status
X-App
X-Check-Cacheable
X-Request-URL
X-Powered-Y
X-Upstream-Ht
SD-X-WS
X-Upstream-Ct
X-Varnish-Beresp-TTL