Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
CF-RAY
Link
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Request-ID
X-Cache-Status
X-Generator
Content-Security-Policy-Report-Only
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-DNS-Prefetch-Control
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
Status
Upgrade
X-Content-Security-Policy
X-CDN
Content-Encoding
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Xss-Protection
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
X-Pass-Why
Xkey
X-Cache-Group
P3p
X-AH-Environment
X-Envoy-Upstream-Service-Time
X-Via
X-Backend
CF-Ray
X-Server
X-Age
X-Ua-Compatible
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Server-Powered-By
X-Page-Speed
X-Ws-Request-Id
X-Pingback
EagleId
X-Proxy-Cache
X-Hacker
X-Nginx-Cache-Status
X-UA-Device
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
Cf-Railgun
Grace
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Amz-Version-Id
Report-To
X-LiteSpeed-Cache
X-Rq
X-Server-Id
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-OneAgent-JS-Injection
X-WebKit-CSP
X-Device
X-Host
X-Origin-Cache
EagleEye-TraceId
X-Response-Time
X-Ac
X-Node
Content-Location
Surrogate-Control
X-Vhost
X-Cloud-Trace-Context
X-Readtime
Request-Id
X-Backend-Server
X-Dispatcher
X-Dns-Prefetch-Control
X-Origin-Upstream-Status
X-Cnection
X-Application-Context
X-HW
X-Cache-Lookup
X-ORACLE-DMS-ECID
Fusion-Content-Id
Fusion-Content-Source
Fusion-Component-Id
Fusion-Source
Fusion-Template-Id
X-ORACLE-DMS-RID
X-Ruxit-JS-Agent
X-DataDome
NEL
X-Mod-Pagespeed
X-Rack-Cache
Rating
Edge-Control
X-Country
X-Akam-SW-Version
X-Clacks-Overhead
Pinterest-Generated-By
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Allow
X-TTL
X-Country-Code
X-DynaTrace
X-Instart-Request-ID
X-Goog-Hash
X-FTR-Request-ID
Accept-Ch
X-Vname
X-PC
X-TtlSet
X-Varnish-TTL
X-ESI
Verso
Content-MD5
X-Powered-By-Plesk
Service-Worker-Allowed
Accept-Ch-Lifetime
X-Url
X-B3-TraceId
X-Forwarded-Proto
X-MS-InvokeApp
X-Version
X-GitHub-Request-Id
X-Cdn-Fetch
X-Use-Magma
X-Exp-Variant
X-Kinja-Server
X-Kinja-Revision
X-GoogleNews-Bot
X-Kinja
X-Kinja-Build
X-Exp-Id
RTSS
Edge-Cache-Tag
X-D2id
X-Debug
X-Px
X-Server-Name
AR-PoweredBy
X-Abt-Application-Version
AR-ATIME
Ar-Sid
AR-Request-ID
AR-CACHE
X-Vcache
SPRequestGuid
X-Amz-Server-Side-Encryption
Charset
X-NF-Request-ID
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Cached
X-TEC-API-ORIGIN
X-Fastcgi-Cache
X-Accel-Expires
X-Middleton-Display
Response
Display
X-Middleton-Response
Pagespeed
X-Sol
X-MSEdge-Ref
X-Amz-Rid
X-Vcap-Request-Id
X-Navigation-Version
Arr-Disable-Session-Affinity
Pinterest-Version
X-Pinterest-Rid
X-Powered-CMS
X-SharePointHealthScore
TCN
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Trace
X-VARITI-CCR
Public-Key-Pins
Realpath
X-Client-IP
Cache-Tag
X-Cdn
X-Fastly-Request-ID
MS-Author-Via
X-Ser
Access-Control-Request-Method
Nginx-Cache
X-DynaTrace-JS-Agent
S
X-Shard
SPIisLatency
SPRequestDuration
X-Upstream
X-Mrf-Item-Lastmod
MRF-Tech
X-Mrf-Section-Lastmod
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Id
X-Content-Type
X-Ezoic-Cdn
X-Edge-O15-RID
X-Hp-Webp
X-Amzn-Trace-Id
X-Grace
X-Forwarded-For
X-T
X-Amz-Meta-S3cmd-Attrs
Front-End-Https
DynaTrace
X-Recruiting
X-Hits
Fastcgi-Cache
Nel
X-Jurisdiction
X-Varnish-Age
X-Aspnet-Version
X-Cache-TTL
ServerID
MicrosoftSharePointTeamServices
X-Mobile-URL
X-Dw-Request-Base-Id
X-Element-Page-Cache
X-DIS-Request-ID
X-Node-Name
X-Content-Digest
X-FTR-Cache-Status
X-FTR-Expires
X-Country-Code-Real
X-Server-ID
NR-ENABLED
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Length
Powered
X-Frontend
X-HS-Hub-Id
X-GUploader-UploadID
X-HS-Combine-CSS
X-HS-Content-Id
X-HS-Cache-Config
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-DC
X-FTR-Backend
X-FTR-Realm
Server-Node
TP-Cache
Alternate-Protocol
TP-L2-Cache
Server-Name
X-Logged-In
X-Correlation-Id
X-CST
X-Request-Processing-Time
X-Request-Received
AMP-Access-Control-Allow-Source-Origin
X-XRDS-LOCATION
X-Request-Handler-Origin-Region
X-Amz-Apigw-Id
X-Microsite
Upgrade-Insecure-Requests
X-Amzn-RequestId
Backend-Timing
X-ATS-Timestamp
X-Cache-Hit
X-Content-Options
X-Content-Security-Policy-Report-Only
Refresh
X-Revision
X-Page-Id
X-Akamai-Edgescape
X-Rid
X-Origin-Server
X-F-Cache
X-User-Agent
Fastly-Restarts
X-Zen-Fury
X-Varnish-Grace
X-Type
X-Webkit-Csp
X-XRDS-Location
X-Content-Powered-By
X-LB-Cache
X-B
X-B3-Sampled
X-Geo-Country
PB-RID
X-AppVersion
PB-PID
X-Az
X-Activity-Id
X-FTR-Cache-Host
Arc-Version
X-Mobile-Rewrite
X-URL
Cache-Status
X-Shield-Request-Id
X-Kinsta-Cache
X-N
X-Pad
X-TT
X-WebKit-CSP-Report-Only
X-Instance
X-Time
X-Cache-Age
X-AOL-HN
Actual-Object-TTL
X-Framework
Paypal-Debug-Id
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel
X-Debug-Info
X-Signature
X-Cache-Action
X-App-Environment
X-B-Cache
Access-Control-Allow-Method
X-Jobs
X-Load-Cache
X-FB-Debug
X-Request-Guid
X-PHP-Backend
DC
X-Cached-By
X-Git-Hash
X-Webapp-Samesite-None-Activated-N
X-Tt-Trace-Tag
X-Varnish-Backend
X-Tt-Trace-Host
Fastcgi-Useragent
Surrogate-Key
X-Erf-Bev-Bev
X-Amz-Replication-Status
X-Erf-Bev-Bev-Is-Generated
X-RateLimit-Remaining
X-Analytics
X-IPLB-Instance
FilterID
Host-Header
X-Contextid
MS-CV
X-ATG-Version
X-SS-Set-Cookie
X-Cache-Key
Host
X-WA-Info
X-Cluster
X-Mobile
X-ORACLE-APMCS-TAG
X-ORACLE-APMCS-REQUEST-ID
X-NWS-LOG-UUID
X-Response-Served-From
X-Accel-Buffering
NGB
Accept-CH
WPE-Backend
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Host-Name
X-Via-JSL
Tracecode
Payment
X-Region
X-Srv
Source
Xserver
X-Varnish-Server
Eomportal-Instance
Filters
X-Cache-2
X-Tumblr-Pixel-1
X-Cache-NE
Frame-Options
X-IPS-LoggedIn
X-FW-Static
X-FW-Type
X-FW-Server
X-FW-Serve
X-FW-Hash
X-GeoIP
X-Varnish-Hostname
X-Tumblr-Pixel-2
Cache-Tv-Group
X-Presslabs-Stats
X-Cache-Enabled
X-Adobe-Loc
X-Adobe-Content
X-Cacheable-TTL
X-Origin-Response-Time
X-Rendered-As
X-Cache-Operation
X-Cache-Rule
X-Is-Bot
X-Seen-By
X-Hostname
X-RequestSource
X-NewRelic-App-Data
X-TX-ID
X-EdgeConnect-Cache-Status
Retry-After
Cleartype
Server-Info
X-Cache-TTL-Remaining
X-RemovedCookies
X-ProcessESI
Accept-CH-Lifetime
X-FastCGI-Cache
X-VCache
Liferay-Portal
X-UA
X-Dc
Ms-Operation-Id
X-RTag
X-B3-Traceid
Datacenter
X-HTML-Minification-Powered-By
X-App-Server
X-Environment-Context
X-Source
X-FireWall-Port
X-L-Path
X-Upgrade-Enabled
X-Cache-Server
X-Endurance-Cache-Level
Cache
From-Origin
X-Handled-By
X-Cache-Control
Healthy
X-Backend-Name
X-CACHE-KEY
X-Wix-Request-Id
X-APP-VERSION
X-Status
X-Path-Route
X-ES-SERVER
X-Cache-Var-Map
X-RN-RSRV
Meta-Geo
Version
X-PressLabs-Stats
X-Cache-Var
Selected-Fe
OT-Force-Account-Verify
X-Proxy-Build
X-Tb
X-Timing-Wait
X-Proto
X-UUID
X-PCL
X-ShopId
X-ShardId
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Shopify-Stage
X-Akamai-Request-ID
Akamai-GRN
X-Alternate-Cache-Key
X-Sorting-Hat-PodId
X-Storage
X-Access
X-EIG-Tracking-Id
X-OCL
X-Origin
X-Section
X-Sorting-Hat-ShopId
X-Format
X-Rule
X-Shopify-Generated-Cart-Token
Mn-Server-Ip
NGX
Now
X-Pubstack
Origin-Edge-Control
Origin-Cache-Control
X-Yottaa-Metrics
X-Redis-Cache
X-Yottaa-Optimizations
Node
X-Human
Azure-Version
X-Hl-Ver
Cache-Tags
Azure-SlotName
Azure-SiteName
Azure-InstanceId
Azure-RegionName
X-Soup
DB-Nickname
Decoy-Debug-TTL
X-JoinUs
Ec-Rule-Version
X-Generated-By
X-Hyper-Cache
Decoy-Debug-Key
Decoy-Debug-Status
X-Request-Time
X-BYPASS-REASON
X-NYM-Debug-Backend
X-Proxy
X-Proxy-Cache-Status
X-Akamai-Request-ID2
X-Hosted-By
X-Cluster-Node
X-FC-Vary-Parameters
X-Debug-Cache
X-Vgn-Hpd-Reason
X-Content-Age
X-Web-Node
X-Cache-Config
X-Time-Microsecs
X-ServerID
X-ProxyCache-Key
Accept-Charset
X-Viewer-Country
X-SaId
Srv
X-ProxyCache-Status
X-Www-Served-By
X-FW-Dynamic
X-VWS-Id
X-Site-Version
X-Generated
X-Qloud-Router
X-BCube-Filmed-By
X-LJ-Flow-ID
X-SayCDN-TTL
X-MP-GENERATED-AT
X-CCM
X-Say-TTL
X-Varnish-Hits
X-Say-Cacheable
X-AWS-Id
Cross-Origin-Window-Policy
X-Ruxit-Js-Agent
GEO-INFO
TWC-GeoIP-LatLong
TWC-Locale-Group
TWC-Privacy
TWC-GeoIP-Country
TWC-Device-Class
Property-Id
S-Rt
TWC-Connection-Speed
Webcakes-App-Name
Webcakes-App-Version
X-Locale
X-Origin-Hint
X-R9-Blue-Green-Version
X-Amzn-Remapped-Content-Length
X-FB-TRIP-ID
Webcakes-Region
X-Cache-Host
X-Loop
X-TNCMS
X-RateLimit-Limit
X-Akamai-Transformed
X-Xfnlog-Site
X-IP
X-Detected-As
X-NCache
X-RCS-CacheZone
L5d-Success-Class
X-CS
X-Ttl
Cache-Name
X-Drupal-Cache-Tags
Webserver
Time
Viewport
X-Unique-Id
Cache-Key
Uber-Trace-Id
X-UA-Device-Type
X-Esi
X-UnsetCookies
Mime-Version
Accept-Language
X-Forwarded-Host
X-Cache-Remote
X-Daa-Tunnel
X-Whom
X-Origin-CC
Country
X-Origin-TTL
X-From
X-Info
X-Mode
Rt-Fastcgi-Cache
X-Trafficlayer-App-Scope
X-Trafficlayer-App-Name
VIX-Pulpo-Upstream-Status
X-Varnish-Cache-Hits
VIX-Pulpo-Node
X-Cluster-Name
Odigeo-Trace-Id
Content-Disposition
X-NGENIX-Cache
X-Backend-TTL
X-Drupal-Cache-Contexts
ServedBy
X-CDN-Forward
X-Newrelic-Synthetics
X-TT-TIMESTAMP
X-PERF
X-ApacheServer
X-Magnolia-Registration
X-Geo
X-B3-Spanid
X-Microcachable
X-CLOUD-TRACE-CONTEXT
X-Device-Type
X-Edge-Location
Proxy-Connection
Section-Io-Cache
X-Nc
X-Via-Fastly
Ohc-File-Size
Cf-Ipcountry
X-Uri
X-EC-Lua
X-Routing-Service
X-Proxied
Ohc-Cache-HIT
X-Zipkin-Id
HitType
X-No-Session
X-UPSTREAM-Address
Machine
X-Aed
Rendered-Blocks
Mobile-Detection-Method
T-Server
X-Application
X-Accel-Expires-Debug
Fastcgi-X-Cache-Version
X-A-Dam
W
Xc-Version
VivaBuild
MD5-Digest
X-A
X-A-Ccd
Viewtype
X-A-Dgt
X-A-Dcw
Meta-Geo-Continent
X-A-Wwc
X-Region-Sid
X-Sigma-Backend
X-SRCache-Key
BehaviorPad-Version
X-Transaction
X-Sigma
X-Session-Fingerprint
X-S
X-S-Cookie
X-ScT
X-Trv-Group
AsisCache
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
GEO-REGION-INFO
X-VG-WebServer
X-VG-WebCache
X-Twitter-Response-Tags
X-Vdms-Version
X-VG-TLSProxy
X-ARC
X-Rojux
X-Connection-Hash
X-D
X-Rocket-Build-Number
Content-Script-Type
X-CF-Lambda-Version
X-B-Cookie
Content-Style-Type
X-CF-Lambda-Fn
X-Destination
X-Date
X-Request-UUID
X-Rewrite-Enabled
X-Geo-Header
X-GeoIP-Country-Code
X-G
X-External-Request-Id
X-DPWN-IS-SECURE
User-Cache-Control
X-C
Access-Control-Request-Headers
Fastly-Soc-X-Request-Id
CDCHOST
Apple-News-Services-Handled
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
Environment
X-Distil-CS
X-Logging-Id
X-Thanos
X-Hit
X-Eu-Site
X-CUA
X-TrackingId
X-Tumblr-Pixel-3
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-WebServer
X-VC-Cache
X-Varnish-Authentication
X-Contensis-Viewer-Groups
X-CGP
Powered-By
Server-Cache-Control
Locid
HA-Ipaddr
Ha-Gx-Prefs
Server-Surrogate-Control
X-Agile
X-Bip
X-Cache-ASPX
X-Auto-Login
X-Agile-Id
X-Agile-Age
Gh-Request-Id
X-Cache-Debug
X-Varnish-Beresp-Status
X-Varnish-Beresp-Ttl
Geo-Info
X-Varnish-Beresp-Grace
X-PHP-Host
X-GoCache-CacheStatus
X-Cache-Backend
X-Labrador-Cache-Channel
X-TA-CDN-Provider
X-IN-APIGATEWAY
X-Hnp-Log
X-Hash
X-VServer
Countrycode
X-Generation-Time
X-GeoIP-City
Server-ID
Request-EU
X-Li-Fabric
X-Li-Pop
X-Clientip
X-LI-UUID
X-Azure-Ref
Request-Country
X-Instart-Isnd
X-Irp-Debug
X-Generated-In
X-IN-APIGATEWAYSSL
X-FW-Version
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Debug-Cookies
X-Debug-Log
X-Debug-Cache-Expiry
X-We-Are-Hiring
X-Cms-Context
X-Webstats-RespID
X-Clara-WADP
X-App-Name
X-WADP-Cache
X-Developers
V-Age
X-Fetched-On
True-Client-Country-4JS
X-Gamma-Serve
X-Fastly-Cache
X-Epic-Correlation-Id
X-Dispatcher-Server
Web-Mar-Node
We-Hiring
X-Distributor
X-Gen-Mode
X-Cdn-Srv
X-TT-LOGID
Cdnsip
Cdncip
X-Request-URI
X-Render-Time
Country-Code
X-Proxy-Upstream
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Real-IP
X-Cache-Time
Cache-Host
X-Cache-Bucket
X-SVT-ORM-RULES
X-SIPLIST1
X-SVT-ORM-VERSION
AKAMAI
X-Swa-Ws
X-Trace-Id
X-Block-Status
X-TH-Server
X-Cache-Info
X-AK-Request-ID
X-Urbn-Context-Path
X-Backend-State
X-NodeID
Kp-EeAlive
IsBot
Locale
X-Ms-Version
Memcached
X-Micro-Cache
Mail-Subject
X-Ms-Request-Id
IBM-Web2-Location
Heartbleed
X-OVcl-Cache
X-Owner
X-User
X-Urbn-Site-Id
X-OVcl
X-Origin-Expires
X-BBXSRF
X-NX-Host
X-Origin-Date
Adler-Geo
X-Cache-URL
Fastly-SIE
X-Key
X-Trafficlayer-App-Version
X-Reboot
X-Old-Content-Length
X-Thinkindot-L3
X-Server-W
X-ServiceProvider
X-Service
X-Nginx-Cache-Key
X-Matched-Rule
X-App-Version
X-Core-Value
X-Generated-On
Fastly-SWR
X-LI-Proto
X-Level-Front-Cache
X-Core-Mission
Is-Eu
X-Variation
ServerName
X-Up
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
PFcat
Thinkindot-Control
Thinkindot-CacheControl-Type
RNT-Time
Server-Host
Server-Int
RNT-Machine
Thinkindot-CacheControl
Fastly-SSL
X-Servername
X-Is-Gdpr
X-Has-Esi
X-Cache-Tags
Platform
X-Platform-Server
X-JWT-State
X-NU-AKA-ACS-Version
Cache-Hits
X-Req
Fastly-Backend-Name
X-Air-Hostname
X-Internal-Host
X-S-Maxage
X-Sucuri-Cache
X-Lb-Id
FNAC-ModuleRouting
Wxu-Next-Region
Wxu-Next-Hostname
Wxu-Next-Commit
X-Nginx-Cache
X-Location
X-Refresh
Group
X-SERVER
RequestId
X-Cache-Expired-At
X-Response-By
X-Parent-Response-Time
X-Cdn-Forward
S-Cnection
Pragrma
X-Tb-Optimization-Total-Bytes-Saved
X-BACKEND-TTL
X-Var-Ttl
X-CF-Powered-By
ProcessTime
Memory
Powered-By-ChinaCache
X-B3-Parentspanid
Filterid
X-Pjax-Url
X-CSRF-Token
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
X-B3-SpanId
X-CSRF-TOKEN
X-Varnish-Ttl
User-Agent
X-Sucuri-ID
Geoip-Latitude
SRV
X-Server-IP
X-NC
X-Wa
TTL
Origin
X-Pf-Uncompressing
X-NWS-UUID-VERIFY
X-Vcl-Version
Geoip-City
X-Via-CDN
X-Varnish-Cacheable
GeoIp-Country-Code
X-Unique-ID
X-Ua
X-Correlation-ID
X-NGINX-Cache
PICS-Label
X-Developer
X-Node-Id
X-COUNTRY
X-Cdn-Request-ID
X-Cdn-Origin
X-Sn-Servicetimems
X-Ocache
X-Cache-Grace
Media-Length
X-LAGOON
X-Device-Os
On-Server
X-Oss-Object-Type
X-Cache-Status-Check
X-Oss-Server-Time
X-Oss-Storage-Class
X-Rocket-Nginx-Bypass
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
Hostname
X-Request-Host
X-Servedbyhost
X-Webkit-CSP
X-Litespeed-Cache
Dnion-Transfer-Encoding
A
X-Sucuri-Id
X-Ratelimit-Remaining
X-MSEdge-Features
X-Via-Ucdn
X-MSEdge-Flight
SN
Cloudfront-Viewer-Country
XServer
X-TIME
X-Oneagent-Js-Injection
X-HS-Status
Cdn
Esi-Enabled
X-Reqid
M-TraceId
Tcn
X-AIR-PT
X-FORWARDED-FOR
X-Policy
X-Planisys-CDN-TTL
Resin-Trace
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-ServedByHost
X-Beluga-Response-Time
CF-Cached-On
Who
X-Beluga-Record
X-Beluga-Status
X-Fastly-Country-Code
X-Cache-Ttl
X-Request-Start
X-Azure-Ref-OriginShield
X-Beluga-Cache-Status
X-Beluga-Node
X-Beluga-Trace
X-Ftr-Cache-Host
X-VHOST
HostName
Host-ID
Rt-Proxy-Cache
X-Varnish-URL
X-Slack-Backend
Pics-Label
NtCoent-Length
X-APP
X-Action
GeoIP-Country-Code
X-Bc
X-Method
Magicmarker
X-VCL-Version
X-Zone
X-Oracle-Dms-Rid
X-Ratelimit-Limit
MIME-Version
CACHE
Pramga
Arc-Country
X-RSL
X-Cache-FS-Status
X-Dispatch
X-Server-Time
X-Processor
X-PAYTM-SRV-ID
X-RPS
Ttl
X-RPM
X-DB
X-Varnish-Url
Cteonnt-Length
X-Fastly-Backend-Reqs
X-DI
GeoIP-Latitude
X-DW
X-DSS
X-DC
X-LiteSpeed-Cache-Control
X-VarnishDD-TTL
X-Skip-Cache
X-ABtesting
X-Newrelic-App-Data
X-FPC
X-Hello
X-ND-Cache
GeoIP-City
X-PF-Uncompressing
X-Flog
X-HostName
Fastly-Drupal-HTML
Ohc-Response-Time
X-Svr
Load-Balancing
X-Be
Amp-Access-Control-Allow-Source-Origin
X-PJAX-URL
X-Served-From
X-Edge-Server
X-Swift-Error
Cdn-Request-Time
Cdn-Host
X-SRV
X-Ftr-Request-Id
WebServer
Vix-Hermes-Req-Id
X-Bc-Bl
X-DevSite-Last-Modified
Processtime
X-WA
X-Dynatrace
N-Cache
X-BE
Servername
DSUID
X-Dynatrace-Js-Agent
X-MServer
Section-Io-Id
Section-Origin-Responded
X-Amzn-Remapped-Connection
Cache-Provider
X-Backend-Host
Release
Section-Io-Origin-Time-Seconds
X-Amzn-Remapped-Date
Section-Io-Origin-Status
X-Aicache-OS
X-ID
X-VCT
X-Hp-Ccpa-Warning
X-WR-MODIFICATION
X-Frame-Option
Dynatrace
X-Fastly-Cache-Hits
X-Ftr-Backend
X-Snapshot-Date
WZWS-RAY
CDN
X-Branch-Name
X-LB-ID
CF-IPCountry
X-Ftr-Backend-Server
X-StackifyID
X-ZONE
X-Tid
X-Configured-By
Requestid
X-Ftr-Balancer
X-Ftr-Realm
Pagetype
Lfy
X-Ftr-Dc
X-CACHE-AGE
X-Edge-IP
X-Apw-Access-Object
SD-X-WS
Proxy-Firewall
X-Apw-Access-Action
X-BC
X-Apw-Access-Token
X-Apw-Hits
X-Cc-Via
X-Fmm-Version
FSS-Proxy
FSS-Cache
X-Request-Url
X-Upstream-Ht
V-Cache
X-Upstream-Ct
X-VC
X-SB
Cache-Cookie-Set-Idcheck
X-Cc-Req-Id
Cache-Cookie-Set-From
X-SD-PageType
D-Cc-Upstream
Cache-Cookie-Set-Lfrom
Cneonction
Warning
X-Litespeed-Cache-Control
X-WPE-Loopback-Upstream-Addr
X-Li-Proto
X-Cache-Id
X-Varnish-Beresp-TTL
X-Check-Cacheable
X-ServerName
X-Worker
X-Request-URL
WP-Super-Cache
X-Powered-Y
X-SN
L
Correlation-Id
Backend-Name
X-App
X-Fastly-Cache-Status
Lb
X-ElasticPress-Search
X-Compress-Hint