Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-Powered-By
Pragma
CF-Cache-Status
X-XSS-Protection
Link
CF-RAY
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-UA-Compatible
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
X-Request-Id
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Request-ID
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-DNS-Prefetch-Control
X-AspNetMvc-Version
X-Ua-Compatible
X-FRAME-OPTIONS
X-Buckets
Status
X-Content-Security-Policy
X-CDN
Content-Encoding
Upgrade
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Xss-Protection
X-XSS-PROTECTION
Keep-Alive
X-Kinja-Server-Push
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
P3p
Xkey
X-Pass-Why
X-Cache-Group
X-AH-Environment
X-Envoy-Upstream-Service-Time
CF-Ray
X-Backend
X-Age
X-Server
X-Via
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Server-Powered-By
X-Page-Speed
X-Pingback
EagleId
X-Nginx-Cache-Status
X-Proxy-Cache
X-UA-Device
X-Hacker
X-Ws-Request-Id
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
Grace
Cf-Railgun
X-Swift-SaveTime
X-Swift-CacheTime
X-Amz-Version-Id
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
X-LiteSpeed-Cache
Report-To
X-Server-Id
X-Rq
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-WebKit-CSP
X-Host
X-Device
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Origin-Cache
X-Response-Time
Content-Location
X-Node
X-Ac
Surrogate-Control
X-Vhost
X-Readtime
Request-Id
X-Backend-Server
X-Cloud-Trace-Context
X-Dispatcher
X-Origin-Upstream-Status
X-Cnection
X-HW
X-ORACLE-DMS-ECID
X-Application-Context
X-DataDome
Fusion-Component-Id
Fusion-Content-Id
Fusion-Content-Source
Fusion-Source
Fusion-Template-Id
NEL
X-ORACLE-DMS-RID
X-Cache-Lookup
X-Mod-Pagespeed
Edge-Control
Rating
X-Rack-Cache
X-Country
X-Akam-SW-Version
X-Clacks-Overhead
Pinterest-Generated-By
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Ruxit-JS-Agent
X-Varnish-TTL
Accept-Ch
X-Country-Code
Allow
X-Instart-Request-ID
X-DynaTrace
X-Goog-Hash
X-TtlSet
X-PC
X-Vname
X-FTR-Request-ID
X-TTL
Accept-Ch-Lifetime
Verso
X-ESI
X-Powered-By-Plesk
Service-Worker-Allowed
X-Url
Content-MD5
X-B3-TraceId
X-Forwarded-Proto
X-Version
X-MS-InvokeApp
X-GitHub-Request-Id
Edge-Cache-Tag
X-Kinja
X-Kinja-Build
X-Exp-Variant
X-Exp-Id
X-Cdn-Fetch
X-Kinja-Revision
X-GoogleNews-Bot
X-Use-Magma
X-Kinja-Server
RTSS
X-Px
AR-Request-ID
Ar-Sid
AR-CACHE
AR-PoweredBy
AR-ATIME
X-D2id
X-Debug
X-Abt-Application-Version
Charset
X-Server-Name
X-NF-Request-ID
SPRequestGuid
X-Amz-Server-Side-Encryption
X-Vcache
X-Cached
X-Accel-Expires
X-MSEdge-Ref
X-Powered-CMS
X-Amz-Rid
Arr-Disable-Session-Affinity
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Middleton-Display
Pagespeed
X-Sol
X-Vcap-Request-Id
Display
X-Middleton-Response
Response
X-Navigation-Version
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Trace
X-SharePointHealthScore
TCN
Pinterest-Version
X-Pinterest-Rid
X-VARITI-CCR
X-Cdn
Public-Key-Pins
Realpath
X-Client-IP
Cache-Tag
X-Fastcgi-Cache
Access-Control-Request-Method
S
X-Upstream
X-Fastly-Request-ID
X-Ser
X-DynaTrace-JS-Agent
MS-Author-Via
X-Shard
X-Id
SPRequestDuration
SPIisLatency
X-Hp-Webp
Nginx-Cache
X-Ezoic-Cdn
X-B3-TraceId-Primal
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
Mrf-Cache-Status
MRF-Tech
X-Forwarded-For
X-Content-Type
X-Amz-Meta-S3cmd-Attrs
DynaTrace
X-T
X-Amzn-Trace-Id
X-Recruiting
X-Grace
Front-End-Https
X-Hits
Fastcgi-Cache
X-Varnish-Age
ServerID
X-DIS-Request-ID
MicrosoftSharePointTeamServices
X-Mobile-URL
X-Dw-Request-Base-Id
X-Element-Page-Cache
NR-ENABLED
X-Node-Name
Nel
X-Content-Digest
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Combine-CSS
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
X-Frontend
X-FTR-Cache-Status
X-Country-Code-Real
X-Edge-O15-RID
Powered
X-FTR-Expires
Server-Name
Alternate-Protocol
X-FTR-Balancer
X-FTR-Realm
X-FTR-Backend
X-FTR-DC
X-FTR-Backend-Server
X-Logged-In
TP-Cache
TP-L2-Cache
X-Cache-TTL
Server-Node
X-Correlation-Id
X-Webkit-Csp
AMP-Access-Control-Allow-Source-Origin
X-Jurisdiction
X-Request-Received
X-XRDS-Location
X-Request-Processing-Time
X-Microsite
X-Request-Handler-Origin-Region
X-ATS-Timestamp
Backend-Timing
Upgrade-Insecure-Requests
X-Server-ID
X-Shield-Request-Id
X-Webapp-Samesite-None-Activated-N
X-Page-Id
X-Content-Security-Policy-Report-Only
X-Origin-Server
X-User-Agent
X-Content-Options
X-F-Cache
Refresh
X-Akamai-Edgescape
X-Rid
X-Amzn-RequestId
X-Revision
X-Varnish-Grace
X-Cache-Hit
X-Amz-Apigw-Id
X-Type
X-XRDS-LOCATION
Fastly-Restarts
X-B3-Sampled
X-Content-Powered-By
X-Zen-Fury
X-Geo-Country
X-Pad
X-URL
X-Analytics
X-Az
X-AppVersion
X-Activity-Id
X-LB-Cache
X-N
X-B
X-RateLimit-Remaining
X-Kinsta-Cache
X-FTR-Cache-Host
X-Ruxit-Js-Agent
PB-PID
PB-RID
Arc-Version
X-Cache-Age
X-TT
X-Mobile-Rewrite
X-Request-Guid
X-Jobs
X-CST
X-AOL-HN
X-WebKit-CSP-Report-Only
X-Signature
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-App-Environment
X-B-Cache
X-Instance
Cache-Status
Actual-Object-TTL
X-Debug-Info
Access-Control-Allow-Method
X-Framework
DC
Paypal-Debug-Id
X-FB-Debug
X-PHP-Backend
X-Load-Cache
X-Cache-Action
X-Time
Surrogate-Key
X-Ttl
X-Varnish-Backend
Fastcgi-Useragent
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Git-Hash
X-FastCGI-Cache
FilterID
Host-Header
X-Cached-By
X-Tt-Trace-Tag
X-Contextid
X-IPLB-Instance
MS-CV
X-Amz-Replication-Status
X-SS-Set-Cookie
X-Tt-Trace-Host
X-Cluster
Tracecode
X-ATG-Version
X-Cache-Key
Frame-Options
X-Accel-Buffering
X-Srv
X-Response-Served-From
X-FW-Hash
X-WA-Info
X-FW-Serve
NGB
X-Cache-NE
X-RequestSource
X-FW-Server
X-FW-Type
X-FW-Static
WPE-Backend
Host
Payment
Xserver
X-Region
X-Varnish-Server
Eomportal-Instance
X-Varnish-Hostname
X-TX-ID
X-Host-Name
X-Adobe-Loc
X-Cache-2
X-Cache-Enabled
X-Adobe-Content
X-Tumblr-Pixel-2
X-Rendered-As
Source
Cache-Tv-Group
X-GeoIP
X-Tumblr-Pixel-1
X-Is-Bot
Filters
X-Cacheable-TTL
X-Oneagent-Js-Injection
X-IPS-LoggedIn
X-Kong-Proxy-Latency
X-Mobile
X-NewRelic-App-Data
X-Kong-Upstream-Latency
Cleartype
X-Seen-By
X-Cache-Rule
X-Cache-Operation
X-EdgeConnect-Cache-Status
X-Cache-TTL-Remaining
X-Via-JSL
X-Origin-Response-Time
X-Hostname
Cache
X-VCache
X-ORACLE-APMCS-TAG
X-ORACLE-APMCS-REQUEST-ID
X-B3-Traceid
X-Cache-Control
X-PressLabs-Stats
Healthy
X-HTML-Minification-Powered-By
Datacenter
Server-Info
X-Trafficlayer-App-Name
Retry-After
X-Trafficlayer-App-Scope
X-ProcessESI
X-RemovedCookies
X-RTag
Ms-Operation-Id
X-RateLimit-Limit
Liferay-Portal
X-Dc
X-Presslabs-Stats
X-Source
X-Rule
X-Environment-Context
X-UA
X-L-Path
X-Cache-Server
X-NWS-LOG-UUID
X-CACHE-KEY
Version
X-FireWall-Port
X-Endurance-Cache-Level
X-Wix-Request-Id
From-Origin
X-Status
X-Upgrade-Enabled
X-Esi
X-Cache-Var-Map
X-RN-RSRV
X-Cache-Var
X-Path-Route
Meta-Geo
X-ES-SERVER
X-Handled-By
X-Proxy-Build
OT-Force-Account-Verify
X-Timing-Wait
Selected-Fe
X-RCS-CacheZone
X-Content-Age
Mn-Server-Ip
X-ShopId
X-Akamai-Request-ID
X-Request-Time
X-Shopify-Generated-Cart-Token
X-Storage
X-Alternate-Cache-Key
Azure-SiteName
X-Origin-Hint
Azure-RegionName
TWC-GeoIP-Country
TWC-GeoIP-LatLong
Azure-InstanceId
Akamai-GRN
TWC-Device-Class
TWC-Locale-Group
TWC-Privacy
X-Sorting-Hat-ShopId
Webcakes-Region
X-ShardId
Webcakes-App-Version
Webcakes-App-Name
X-Section
X-AWS-Id
X-Goog-Meta-Goog-Reserved-File-Mtime
X-LJ-Flow-ID
X-Tb
X-FW-Dynamic
X-Backend-Name
X-Shopify-Stage
X-Sorting-Hat-PodId
X-EIG-Tracking-Id
Cache-Tags
X-Access
X-Format
Azure-Version
X-Proto
TWC-Connection-Speed
Azure-SlotName
Property-Id
X-VWS-Id
S-Rt
Decoy-Debug-TTL
Ec-Rule-Version
NGX
Decoy-Debug-Key
Decoy-Debug-Status
Now
Node
X-Qloud-Router
X-Generated-By
X-Proxy
X-FC-Vary-Parameters
X-Debug-Cache
X-ProxyCache-Key
X-ProxyCache-Status
X-Hl-Ver
X-Hosted-By
X-UUID
X-Viewer-Country
X-Time-Microsecs
X-JoinUs
X-Hyper-Cache
X-PCL
X-Cluster-Node
X-BYPASS-REASON
X-Xfnlog-Site
X-Redis-Cache
X-SaId
X-ServerID
X-Vgn-Hpd-Reason
X-Proxy-Cache-Status
X-Cache-Host
X-Origin
X-Cache-Config
X-OCL
X-Web-Node
X-Akamai-Request-ID2
DB-Nickname
Accept-CH
X-Yottaa-Optimizations
X-App-Server
X-Yottaa-Metrics
X-Soup
X-BCube-Filmed-By
X-SayCDN-TTL
X-NYM-Debug-Backend
Origin-Cache-Control
X-Varnish-Hits
X-Human
Origin-Edge-Control
X-CCM
X-MP-GENERATED-AT
X-Say-TTL
X-Say-Cacheable
X-Generated
X-IP
Cross-Origin-Window-Policy
X-Pubstack
X-Detected-As
X-Amzn-Remapped-Content-Length
L5d-Success-Class
X-TNCMS
X-Loop
X-FB-TRIP-ID
X-APP-VERSION
Cache-Name
X-R9-Blue-Green-Version
X-Site-Version
Srv
X-Www-Served-By
X-Locale
Viewport
X-CS
Uber-Trace-Id
Webserver
Accept-Charset
X-Akamai-Transformed
Time
X-NCache
X-Unique-Id
X-Drupal-Cache-Tags
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
Accept-CH-Lifetime
GEO-INFO
X-From
X-Cache-Remote
X-UA-Device-Type
X-Backend-TTL
X-TT-TIMESTAMP
X-Cluster-Name
Cache-Key
X-CDN-Forward
X-Edge-Location
X-Drupal-Cache-Contexts
Mime-Version
X-Origin-TTL
Accept-Language
X-Origin-CC
X-Mode
Country
X-EC-Lua
Odigeo-Trace-Id
X-Microcachable
X-CLOUD-TRACE-CONTEXT
Rt-Fastcgi-Cache
X-B3-Spanid
X-Info
X-Forwarded-Host
X-Newrelic-Synthetics
Ohc-File-Size
Ohc-Cache-HIT
X-No-Session
X-UnsetCookies
X-Geo
X-Magnolia-Registration
Proxy-Connection
X-Whom
Content-Disposition
X-PERF
X-Routing-Service
X-Proxied
X-Varnish-Cache-Hits
X-UPSTREAM-Address
X-ApacheServer
X-Zipkin-Id
X-App-Version
X-Labrador-Cache-Channel
Geo-Info
X-PHP-Host
ServedBy
Fastly-SSL
X-Real-IP
MD5-Digest
X-G
X-S-Cookie
X-Rojux
X-Rewrite-Enabled
X-ScT
X-S
IsBot
X-Destination
X-SRCache-Key
Viewtype
VivaBuild
X-Request-UUID
X-Connection-Hash
X-Session-Fingerprint
X-Geo-Header
X-GeoIP-Country-Code
X-DPWN-IS-SECURE
Content-Style-Type
AsisCache
BehaviorPad-Version
Fastcgi-X-Cache-Version
Content-Script-Type
X-Device-Type
T-Server
X-CF-Lambda-Version
Meta-Geo-Continent
X-CF-Lambda-Fn
Mobile-Detection-Method
Rendered-Blocks
GEO-REGION-INFO
X-Region-Sid
X-SIPLIST1
X-Aed
X-VG-WebCache
X-Application
X-Accel-Expires-Debug
X-A-Wwc
X-D
X-Date
X-A-Dgt
X-Cache-Time
X-ARC
X-B-Cookie
Machine
Xc-Version
X-External-Request-Id
X-Vtex-Remote-Cache
X-VG-WebServer
X-Vtex-Processado-Em
X-Twitter-Response-Tags
X-Vdms-Version
X-A-Ccd
Cf-Ipcountry
X-A-Dam
X-Transaction
X-Trv-Group
X-A
X-A-Dcw
User-Cache-Control
X-Via-Fastly
X-C
Server-Cache-Control
Apple-News-Services-Request-Url
X-WebServer
Locid
Wxu-Next-Hostname
Wxu-Next-Commit
Access-Control-Request-Headers
Fastly-Soc-X-Request-Id
X-Cache-URL
X-Nginx-Cache-Key
X-Wikidot-Static-Cache
Fastly-Backend-Name
Environment
Apple-News-Services-Host
X-Contensis-Viewer-Groups
Apple-News-Services-Handled
X-Cache-Debug
RNT-Machine
X-Core-Mission
RNT-Time
X-NGENIX-Cache
Apple-News-Services-Parsed-Url
X-Wikidot-Backend
X-Uri
FNAC-ModuleRouting
X-Req
Powered-By
W
X-App-Name
Gh-Request-Id
X-VG-TLSProxy
X-Sigma
X-CUA
X-Rocket-Build-Number
X-Sigma-Backend
X-TrackingId
X-Cache-ASPX
X-Tumblr-Pixel-3
X-Auto-Login
X-Developers
Server-Surrogate-Control
Server-Int
Wxu-Next-Region
X-Varnish-Authentication
X-VC-Cache
X-Bip
X-IN-APIGATEWAYSSL
X-Internal-Host
X-Irp-Debug
Mail-Subject
Memcached
X-IN-APIGATEWAY
X-Gamma-Serve
X-FW-Version
V-Age
X-Block-Status
X-Gen-Mode
We-Hiring
Web-Mar-Node
X-BBXSRF
X-Azure-Ref
X-AK-Request-ID
X-Fastly-Cache
True-Client-Country-4JS
X-Generated-In
X-Distributor
X-Hash
Request-EU
Request-Country
X-GoCache-CacheStatus
Section-Io-Cache
X-Generation-Time
Server-ID
X-GeoIP-City
X-Hnp-Log
X-OVcl
X-TH-Server
X-Eu-Site
X-Thanos
X-Epic-Correlation-Id
X-CGP
X-Distil-CS
X-Hit
X-Render-Time
X-Request-URI
X-Debug-Cache-Store
X-Clara-WADP
X-Clientip
X-Debug-Log
X-Cms-Context
X-Backend-State
X-Debug-Cookies
X-VServer
Ha-Gx-Prefs
X-WADP-Cache
CDCHOST
X-Webstats-RespID
X-We-Are-Hiring
HA-Ipaddr
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-TT-LOGID
X-Urbn-Context-Path
X-Urbn-Site-Id
X-User
Locale
X-Rebelmouse-Surrogate-Control
X-LI-UUID
Fastly-SIE
Countrycode
Country-Code
Cdncip
Cdnsip
Fastly-SWR
X-LI-Proto
X-Key
Kp-EeAlive
IBM-Web2-Location
X-Li-Fabric
X-Li-Pop
X-Location
X-Logging-Id
X-Cdn-Srv
X-OVcl-Cache
X-Proxy-Upstream
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Rebelmouse-Cache-Control
X-Origin-Expires
X-Cache-Bucket
X-Dispatcher-Server
X-Cache-Info
X-Origin-Date
X-NX-Host
X-B3-Parentspanid
HitType
X-Cache-Backend
X-Ms-Version
X-Swa-Ws
X-Thinkindot-L3
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-S-Maxage
X-ServiceProvider
X-Trace-Id
X-Trafficlayer-App-Version
X-Up
X-Variation
X-Agile
X-Agile-Age
X-Agile-Id
X-Sucuri-Cache
X-Reboot
X-Matched-Rule
X-Micro-Cache
X-JWT-State
X-Is-Gdpr
X-Instart-Isnd
X-Ms-Request-Id
X-NodeID
X-Platform-Server
X-Server-W
X-Owner
X-Old-Content-Length
X-NU-AKA-ACS-Version
X-Has-Esi
X-Cache-Tags
Is-Eu
Heartbleed
PFcat
Platform
Thinkindot-CacheControl
Server-Host
Cache-Host
AKAMAI
X-Varnish-Beresp-Ttl
ServerName
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
Adler-Geo
Thinkindot-CacheControl-Type
X-Core-Value
Thinkindot-Control
X-Nginx-Cache
X-TA-CDN-Provider
X-Daa-Tunnel
X-Refresh
X-Generated-On
X-Level-Front-Cache
X-SERVER
X-Service
Cache-Hits
X-Fetched-On
X-Response-By
X-Nc
X-Servername
X-Lb-Id
RequestId
X-B3-SpanId
X-Server-IP
X-CSRF-TOKEN
X-Tb-Optimization-Total-Bytes-Saved
X-NC
X-CF-Powered-By
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
ProcessTime
Memory
X-Parent-Response-Time
X-Wa
X-Cdn-Request-ID
X-Ua
Origin
Media-Length
X-Air-Hostname
X-Cdn-Forward
User-Agent
X-Var-Ttl
X-Cache-Expired-At
X-Pjax-Url
Pragrma
Filterid
Group
X-CSRF-Token
X-Pf-Uncompressing
X-Correlation-ID
X-BACKEND-TTL
SRV
X-Unique-ID
Geoip-Latitude
Powered-By-ChinaCache
S-Cnection
X-Sucuri-Id
TTL
Esi-Enabled
X-COUNTRY
GeoIp-Country-Code
X-Reqid
X-Vcl-Version
X-AIR-PT
X-NGINX-Cache
X-Rocket-Nginx-Bypass
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
X-Oracle-Dms-Rid
X-Policy
PICS-Label
X-Servedbyhost
X-Varnish-Cacheable
X-TIME
X-Planisys-CDN-Rules
X-Sucuri-ID
X-Request-Start
X-Webkit-CSP
X-Azure-Ref-OriginShield
X-Litespeed-Cache
SN
HostName
Rt-Proxy-Cache
X-Via-CDN
Dnion-Transfer-Encoding
Geoip-City
X-Via-Ucdn
XServer
M-TraceId
X-HS-Status
X-Developer
X-FORWARDED-FOR
X-NWS-UUID-VERIFY
Magicmarker
Tcn
X-Cdn-Origin
X-Device-Os
X-Cache-Grace
X-LAGOON
X-Fastly-Country-Code
X-Method
X-Sn-Servicetimems
X-Node-Id
Who
Load-Balancing
X-Ocache
Resin-Trace
On-Server
X-Cache-Ttl
X-VHOST
X-Ftr-Cache-Host
X-Dynatrace
Cdn
X-MSEdge-Features
X-ServedByHost
CF-Cached-On
A
X-MSEdge-Flight
X-Request-Host
DSUID
Ohc-Response-Time
X-VCL-Version
NtCoent-Length
X-Be
Pics-Label
GeoIP-Country-Code
Release
X-Svr
X-VCT
X-MServer
X-DC
Ttl
X-Beluga-Record
X-Beluga-Status
X-Beluga-Trace
Vix-Hermes-Req-Id
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Bc
X-Cache-Status-Check
GeoIP-Latitude
X-Oss-Request-Id
X-Beluga-Response-Time
X-Oss-Storage-Class
X-Oss-Server-Time
X-APP
X-Beluga-Node
Cloudfront-Viewer-Country
X-Beluga-Cache-Status
X-Zone
X-Hp-Ccpa-Warning
Hostname
MIME-Version
Cteonnt-Length
X-Fastly-Backend-Reqs
X-Varnish-URL
GeoIP-City
X-Varnish-Url
X-VarnishDD-TTL
X-LiteSpeed-Cache-Control
X-Configured-By
Host-ID
X-Newrelic-App-Data
X-PF-Uncompressing
X-PJAX-URL
SD-X-WS
X-Upstream-Ht
X-Upstream-Ct
X-Ftr-Request-Id
X-SD-PageType
X-SRV
X-WR-MODIFICATION
X-HostName
X-Ratelimit-Remaining
X-Slack-Backend
X-Tid
X-Cache-Id
X-SN
X-Aicache-OS
X-BE
Processtime
X-Compress-Hint
X-Dynatrace-Js-Agent
Servername
X-DSS
X-DB
X-Action
Cache-Provider
X-DI
X-DW
X-RPS
X-RPM
X-RSL
WebServer
X-Via-NSCOPI
X-Swift-Error
X-Release
L
X-ID
CACHE
Amp-Access-Control-Allow-Source-Origin
X-Frame-Option
X-Ftr-Backend-Server
X-Ftr-Realm
LB
X-Ratelimit-Limit
Dynatrace
X-StackifyID
X-Ftr-Balancer
X-Scheme
X-PAYTM-SRV-ID
X-Processor
X-Server-Time
X-Skip-Cache
X-FPC
X-Dispatch
CF-IPCountry
Arc-Country
X-Cache-FS-Status
X-Ftr-Backend
X-Ftr-Dc
Pagetype
X-Branch-Name
X-Fastly-Cache-Hits
X-LB-ID
Lfy
X-Snapshot-Date
CDN
Requestid
X-ServerName
X-CACHE-AGE
X-Node-ID
X-Apw-Hits
Proxy-Firewall
Cache-Cookie-Set-From
X-ND-Cache
X-Cc-Via
Cache-Cookie-Set-Idcheck
X-Hello
X-Flog
X-Cc-Req-Id
X-Apw-Access-Action
X-Apw-Access-Object
X-ABtesting
Pramga
Fastly-Drupal-HTML
X-DevSite-Last-Modified
X-Apw-Access-Token
Cache-Cookie-Set-Lfrom
UCS
X-ZONE
X-Request-Url
X-Varnish-Beresp-TTL
X-Edge-IP
X-SB
V-Cache
Warning
X-VC
D-Cc-Upstream
NnCoection
X-Litespeed-Cache-Control
N-Cache
WP-Super-Cache
Lb
X-Fastly-Cache-Status
X-Request-URL
X-Worker
X-Check-Cacheable
Backend-Name
X-Powered-Y
X-App
X-ElasticPress-Search
Correlation-Id
X-BC