Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-Powered-By
Pragma
CF-Cache-Status
Link
X-XSS-Protection
ETag
CF-RAY
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Xss-Protection
X-Runtime
CF-Ray
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Request-ID
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-DNS-Prefetch-Control
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
Status
Upgrade
X-Content-Security-Policy
Content-Encoding
X-CDN
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
X-Pass-Why
X-Cache-Group
X-AH-Environment
X-Envoy-Upstream-Service-Time
X-Via
Xkey
X-Backend
X-Age
X-Server
X-Ws-Request-Id
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Page-Speed
X-Server-Powered-By
EagleId
X-Pingback
X-Proxy-Cache
X-Hacker
X-Nginx-Cache-Status
Request-Context
X-UA-Device
Feature-Policy
Server-Timing
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Cf-Railgun
Ali-Swift-Global-Savetime
Grace
X-Amz-Version-Id
X-Ua-Compatible
Report-To
X-LiteSpeed-Cache
X-OneAgent-JS-Injection
X-Rq
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-WebKit-CSP
X-Device
X-Host
X-Server-Id
X-Origin-Cache
X-Response-Time
EagleEye-TraceId
X-Ac
X-Node
Surrogate-Control
Content-Location
X-Cloud-Trace-Context
X-Vhost
X-Backend-Server
X-Readtime
X-Dispatcher
Request-Id
X-Cache-Lookup
X-Ruxit-JS-Agent
X-Origin-Upstream-Status
X-Cnection
X-Application-Context
X-HW
Fusion-Component-Id
Fusion-Source
Fusion-Template-Id
Fusion-Content-Id
Fusion-Content-Source
X-ORACLE-DMS-ECID
X-Mod-Pagespeed
NEL
P3p
X-DataDome
X-ORACLE-DMS-RID
X-Rack-Cache
X-Dns-Prefetch-Control
X-Country
X-Clacks-Overhead
Edge-Control
X-Akam-SW-Version
Rating
Allow
Pinterest-Generated-By
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Country-Code
Accept-Ch
X-FTR-Request-ID
X-Instart-Request-ID
X-Varnish-TTL
X-TTL
X-DynaTrace
X-Vname
X-Goog-Hash
X-TtlSet
X-PC
Verso
Content-MD5
Accept-Ch-Lifetime
Service-Worker-Allowed
X-ESI
X-Url
X-Powered-By-Plesk
X-Vcache
X-Forwarded-Proto
X-GitHub-Request-Id
X-Exp-Id
X-Exp-Variant
X-Kinja-Revision
X-GoogleNews-Bot
X-Kinja-Server
X-Kinja-Build
X-Use-Magma
X-Cdn-Fetch
X-Kinja
X-Version
X-MS-InvokeApp
RTSS
X-Server-Name
X-B3-TraceId
X-D2id
Edge-Cache-Tag
X-Abt-Application-Version
X-Px
X-Debug
X-Amz-Server-Side-Encryption
AR-CACHE
Ar-Sid
AR-Request-ID
AR-PoweredBy
AR-ATIME
SPRequestGuid
X-Cached
Charset
X-NF-Request-ID
X-Vcap-Request-Id
X-TEC-API-ORIGIN
X-Navigation-Version
X-TEC-API-VERSION
X-TEC-API-ROOT
X-MSEdge-Ref
Pagespeed
Response
Display
X-Middleton-Display
X-Sol
X-Amz-Rid
X-Middleton-Response
X-Server-ID
X-Accel-Expires
Arr-Disable-Session-Affinity
TCN
X-SharePointHealthScore
Pinterest-Version
X-Pinterest-Rid
X-VARITI-CCR
X-Fastly-Request-ID
X-Cdn
Public-Key-Pins
Nginx-Cache
MS-Author-Via
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Powered-CMS
X-Edge-O15-RID
X-Fastcgi-Cache
X-Client-IP
Cache-Tag
Realpath
X-Trace
X-Ser
Access-Control-Request-Method
X-Content-Type
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
SPRequestDuration
SPIisLatency
X-Amzn-Trace-Id
X-Shard
X-Upstream
X-Grace
X-Hp-Webp
X-Jurisdiction
X-DynaTrace-JS-Agent
X-Id
X-Ezoic-Cdn
S
Front-End-Https
X-Forwarded-For
X-Cache-TTL
X-Hits
Nel
X-Amz-Meta-S3cmd-Attrs
X-T
Fastcgi-Cache
X-Aspnet-Version
X-Recruiting
DynaTrace
X-Element-Page-Cache
X-Node-Name
X-Varnish-Age
X-Content-Digest
X-Dw-Request-Base-Id
X-Country-Code-Real
MicrosoftSharePointTeamServices
X-FTR-Backend
X-FTR-DC
X-FTR-Realm
X-Mobile-URL
X-FTR-Cache-Status
X-FTR-Expires
X-FTR-Balancer
X-FTR-Backend-Server
ServerID
X-DIS-Request-ID
NR-ENABLED
Server-Node
TP-L2-Cache
TP-Cache
X-HS-Combine-CSS
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Content-Id
X-Frontend
X-CST
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Storage-Class
X-Goog-Metageneration
X-Goog-Generation
Powered
X-Logged-In
Alternate-Protocol
X-Correlation-Id
Server-Name
X-Amz-Apigw-Id
X-Amzn-RequestId
Upgrade-Insecure-Requests
X-XRDS-Location
Fastly-Restarts
X-Cache-Hit
X-FTR-Cache-Host
X-Microsite
X-Request-Handler-Origin-Region
Backend-Timing
X-ATS-Timestamp
AMP-Access-Control-Allow-Source-Origin
X-Page-Id
X-Zen-Fury
X-Request-Processing-Time
X-Request-Received
X-User-Agent
X-Content-Options
X-Content-Security-Policy-Report-Only
X-F-Cache
X-Origin-Server
Refresh
X-Akamai-Edgescape
X-Varnish-Grace
X-Rid
X-Revision
X-Content-Powered-By
X-LB-Cache
X-B
X-Type
PB-PID
Arc-Version
PB-RID
X-Mobile-Rewrite
X-XRDS-LOCATION
X-B3-Sampled
X-Geo-Country
Cache-Status
X-Activity-Id
X-AppVersion
X-Az
X-Kinsta-Cache
X-N
X-TT
X-Cache-Action
X-NWS-LOG-UUID
X-AOL-HN
X-Jobs
X-Signature
X-Cache-Age
X-B-Cache
Access-Control-Allow-Method
X-Debug-Info
X-Framework
X-Request-Guid
X-WebKit-CSP-Report-Only
X-Instance
Actual-Object-TTL
X-FB-Debug
X-PHP-Backend
X-Cached-By
X-Load-Cache
X-Tumblr-Pixel-0
Paypal-Debug-Id
X-Tumblr-Pixel
X-Git-Hash
X-Time
X-App-Environment
X-Tumblr-User
X-URL
X-Tt-Trace-Tag
X-Tt-Trace-Host
Fastcgi-Useragent
X-Amz-Replication-Status
X-Pad
DC
X-FastCGI-Cache
X-Webkit-Csp
X-Varnish-Backend
X-Shield-Request-Id
Host-Header
X-RateLimit-Remaining
X-WA-Info
Host
X-ATG-Version
Surrogate-Key
MS-CV
X-ORACLE-APMCS-TAG
X-ORACLE-APMCS-REQUEST-ID
X-Contextid
X-IPLB-Instance
X-Via-JSL
X-Mobile
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Host-Name
X-Cache-Key
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Retry-After
X-Accel-Buffering
X-Response-Served-From
Frame-Options
NGB
Payment
X-B3-Traceid
Source
X-Cache-NE
X-Origin-Response-Time
X-Seen-By
X-Region
X-NewRelic-App-Data
X-Cache-2
X-Hostname
Liferay-Portal
X-SS-Set-Cookie
Eomportal-Instance
X-Varnish-Server
Xserver
Tracecode
X-Cacheable-TTL
WPE-Backend
X-IPS-LoggedIn
X-FW-Hash
X-Rendered-As
X-FW-Server
X-Srv
X-FW-Serve
Filters
X-FW-Type
X-FW-Static
X-GeoIP
X-Is-Bot
X-Adobe-Loc
X-Varnish-Hostname
Cache-Tv-Group
X-Adobe-Content
X-Cluster
X-Cache-Enabled
Server-Info
X-RequestSource
X-Cache-Operation
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
X-Cache-Rule
FilterID
X-Presslabs-Stats
X-RemovedCookies
X-App-Server
X-ProcessESI
X-EdgeConnect-Cache-Status
X-TX-ID
X-Cache-TTL-Remaining
Accept-CH
X-Analytics
Cleartype
X-FireWall-Port
X-L-Path
X-Environment-Context
X-Handled-By
X-RTag
Ms-Operation-Id
X-Source
X-Upgrade-Enabled
X-Ttl
X-Endurance-Cache-Level
X-HTML-Minification-Powered-By
X-Webapp-Samesite-None-Activated-N
X-Cache-Server
From-Origin
Accept-Charset
Srv
X-Backend-Name
X-UA
Datacenter
X-CACHE-KEY
X-APP-VERSION
Accept-CH-Lifetime
X-Esi
X-Dc
X-UUID
X-Cache-Var-Map
Meta-Geo
X-Wix-Request-Id
X-Cache-Var
X-ES-SERVER
X-Path-Route
X-RN-RSRV
X-PressLabs-Stats
Selected-Fe
Healthy
X-Access
X-Tb
X-Proxy-Build
X-Section
OT-Force-Account-Verify
X-Format
X-Timing-Wait
X-Status
X-FC-Vary-Parameters
X-Goog-Meta-Goog-Reserved-File-Mtime
X-OCL
X-PCL
X-EIG-Tracking-Id
X-Proto
X-Content-Age
Cache-Tags
X-Shopify-Generated-Cart-Token
Mn-Server-Ip
X-ShopId
X-ShardId
X-Request-Time
X-Alternate-Cache-Key
X-Shopify-Stage
X-Akamai-Request-ID
X-Cache-Config
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-Human
X-JoinUs
X-LJ-Flow-ID
X-Akamai-Request-ID2
Origin-Edge-Control
NGX
X-Debug-Cache
X-BYPASS-REASON
Ec-Rule-Version
X-Yottaa-Metrics
Node
X-Hl-Ver
X-AWS-Id
Origin-Cache-Control
X-Yottaa-Optimizations
X-Proxy-Cache-Status
X-ProxyCache-Key
X-Soup
X-Daa-Tunnel
X-VWS-Id
X-Vgn-Hpd-Reason
X-ServerID
X-ProxyCache-Status
X-SaId
X-Qloud-Router
X-Say-Cacheable
X-Say-TTL
X-SayCDN-TTL
Akamai-GRN
X-Web-Node
X-NYM-Debug-Backend
X-Origin
Decoy-Debug-TTL
X-Hosted-By
Now
Decoy-Debug-Status
X-Viewer-Country
X-Storage
Cross-Origin-Window-Policy
X-Site-Version
X-BCube-Filmed-By
X-Proxy
X-Pubstack
Version
X-Redis-Cache
X-Hyper-Cache
X-Unique-Id
X-MP-GENERATED-AT
X-Locale
X-TNCMS
X-Time-Microsecs
X-FB-TRIP-ID
X-Www-Served-By
DB-Nickname
X-FW-Dynamic
X-Generated-By
X-Generated
X-Detected-As
Decoy-Debug-Key
X-CCM
X-Akamai-Transformed
X-Loop
X-Origin-Hint
Azure-Version
Webcakes-Region
Azure-SiteName
Webcakes-App-Version
X-R9-Blue-Green-Version
Azure-SlotName
X-Amzn-Remapped-Content-Length
Azure-InstanceId
X-Xfnlog-Site
X-Varnish-Hits
Webcakes-App-Name
X-IP
Azure-RegionName
X-RCS-CacheZone
TWC-GeoIP-Country
TWC-Connection-Speed
Property-Id
GEO-INFO
TWC-Device-Class
S-Rt
TWC-Privacy
TWC-Locale-Group
TWC-GeoIP-LatLong
X-Cluster-Node
X-NCache
X-Whom
X-RateLimit-Limit
Cache-Key
X-Cache-Control
X-UA-Device-Type
X-Cache-Host
Cache
X-Rule
X-Drupal-Cache-Tags
X-Backend-TTL
X-Forwarded-Host
X-NGENIX-Cache
X-Mode
L5d-Success-Class
Section-Io-Cache
Webserver
X-CDN-Forward
X-UnsetCookies
Cache-Name
Time
Content-Disposition
X-CS
X-Info
Mime-Version
Viewport
Accept-Language
X-PERF
X-B3-Spanid
X-Origin-CC
X-Origin-TTL
X-ApacheServer
Rt-Fastcgi-Cache
X-Varnish-Cache-Hits
ServedBy
X-Newrelic-Synthetics
Uber-Trace-Id
Country
X-VCache
Odigeo-Trace-Id
X-Cache-Remote
X-Routing-Service
X-Zipkin-Id
X-Proxied
X-Device-Type
X-CLOUD-TRACE-CONTEXT
X-Magnolia-Registration
X-Via-Fastly
X-From
X-EC-Lua
X-Uri
Filterid
Proxy-Connection
X-Cluster-Name
X-Drupal-Cache-Contexts
Geo-Info
Access-Control-Request-Headers
X-Microcachable
HitType
X-Real-IP
X-TT-TIMESTAMP
X-Geo
Cf-Ipcountry
Mobile-Detection-Method
Meta-Geo-Continent
X-Vtex-Remote-Cache
BehaviorPad-Version
Rendered-Blocks
Apple-News-Services-Request-Url
Xc-Version
Apple-News-Services-Parsed-Url
MD5-Digest
GEO-REGION-INFO
Fastcgi-X-Cache-Version
Apple-News-Services-Handled
AsisCache
T-Server
Content-Script-Type
Apple-News-Services-Host
Machine
Content-Style-Type
X-Application
X-S
X-S-Cookie
X-ScT
X-Session-Fingerprint
X-Rojux
X-Rocket-Build-Number
X-GeoIP-Country-Code
X-Region-Sid
X-Request-UUID
X-Rewrite-Enabled
X-Sigma
X-Sigma-Backend
X-VG-TLSProxy
X-VG-WebCache
X-VG-WebServer
X-Vtex-Processado-Em
X-Vdms-Version
X-Twitter-Response-Tags
X-SRCache-Key
X-Transaction
X-Trv-Group
X-Geo-Header
X-G
X-A-Dam
X-A-Dcw
X-A-Dgt
X-A-Wwc
X-A-Ccd
X-A
VivaBuild
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
W
X-Accel-Expires-Debug
X-Aed
X-D
X-Destination
X-DPWN-IS-SECURE
X-External-Request-Id
X-Connection-Hash
X-CF-Lambda-Version
X-ARC
X-B-Cookie
X-CF-Lambda-Fn
Viewtype
X-Date
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
Group
Ohc-File-Size
X-Varnish-Beresp-Ttl
X-Cache-Time
X-Labrador-Cache-Channel
User-Cache-Control
X-PHP-Host
X-C
X-Nc
CDCHOST
X-Developers
X-Rebelmouse-Cache-Control
X-Distil-CS
Cache-Hits
X-CUA
Environment
HA-Ipaddr
Ha-Gx-Prefs
X-Hit
IsBot
Locid
X-Logging-Id
Fastly-SWR
Countrycode
X-Eu-Site
Fastly-SIE
Fastly-Soc-X-Request-Id
Powered-By
X-Rebelmouse-Surrogate-Control
X-VC-Cache
X-Var-Ttl
X-SIPLIST1
X-Bip
X-App-Name
X-WebServer
X-Agile
X-Agile-Age
X-Agile-Id
X-TrackingId
X-Backend-State
X-Cache-Expired-At
X-Clientip
X-Thanos
X-Cache-Debug
X-CGP
Fastly-SSL
X-GoCache-CacheStatus
X-Generated-In
X-Gen-Mode
Web-Mar-Node
X-Contensis-Viewer-Groups
X-GeoIP-City
X-Has-Esi
X-Gamma-Serve
X-Hnp-Log
X-Cms-Context
X-Air-Hostname
X-Hash
X-Auto-Login
X-Block-Status
X-Dispatcher-Server
X-Debug-Log
X-Debug-Cookies
X-Cache-ASPX
X-Distributor
X-Cache-Tags
X-Core-Mission
X-Fetched-On
X-Azure-Ref
X-Epic-Correlation-Id
X-IN-APIGATEWAY
X-Ms-Version
X-TH-Server
X-Trace-Id
X-Tumblr-Pixel-3
X-Up
X-Swa-Ws
X-SVT-ORM-VERSION
X-Request-URI
X-Servername
X-SVT-ORM-RULES
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Cdn-Srv
X-OVcl
X-OVcl-Cache
X-Wikidot-Static-Cache
X-Wikidot-Backend
X-Variation
X-Varnish-Authentication
X-VServer
X-RateLimit-Limit-Second
X-Proxy-Upstream
X-LI-Proto
X-LI-UUID
X-Ms-Request-Id
X-Li-Pop
X-Li-Fabric
X-Instart-Isnd
X-Is-Gdpr
X-JWT-State
We-Hiring
X-Nginx-Cache-Key
X-Origin-Expires
X-Owner
X-Platform-Server
X-Origin-Date
X-NX-Host
X-No-Session
X-NodeID
X-NU-AKA-ACS-Version
X-IN-APIGATEWAYSSL
X-RateLimit-Remaining-Second
RNT-Machine
Adler-Geo
Request-EU
Request-Country
RNT-Time
Kp-EeAlive
Server-Surrogate-Control
Server-Int
Server-ID
Pragrma
Platform
Heartbleed
IBM-Web2-Location
Is-Eu
Locale
Mail-Subject
Gh-Request-Id
Cache-Host
Country-Code
Fastly-Backend-Name
True-Client-Country-4JS
Server-Cache-Control
V-Age
X-Edge-Location
Ohc-Cache-HIT
PFcat
Cdnsip
X-FW-Version
Cdncip
X-Irp-Debug
X-Reboot
X-Cache-URL
AKAMAI
X-Clara-WADP
X-Fastly-Cache
X-Micro-Cache
FNAC-ModuleRouting
Wxu-Next-Region
X-Webstats-RespID
Wxu-Next-Hostname
Wxu-Next-Commit
ServerName
X-Level-Front-Cache
X-We-Are-Hiring
X-Cache-Info
X-Matched-Rule
X-Generated-On
X-Generation-Time
X-WADP-Cache
X-Debug-Cache-Store
X-Thinkindot-L3
Thinkindot-CacheControl
X-AK-Request-ID
X-ServiceProvider
X-Service
Thinkindot-CacheControl-Type
X-Trafficlayer-App-Name
S-Cnection
X-Trafficlayer-App-Version
X-Trafficlayer-App-Scope
Thinkindot-Control
X-TT-LOGID
Server-Host
X-Cache-Bucket
X-Req
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
X-Server-W
X-Core-Value
Memcached
X-BBXSRF
X-VHOST
X-UPSTREAM-Address
X-Nginx-Cache
X-Old-Content-Length
X-S-Maxage
X-Lb-Id
X-SERVER
X-Response-By
X-App-Version
X-Refresh
X-NC
X-Varnish-Cacheable
RequestId
X-Render-Time
X-Wa
X-Oss-Hash-Crc64ecma
X-Sucuri-ID
X-Node-Id
X-Cache-Backend
X-Oss-Object-Type
X-Oss-Storage-Class
X-Oss-Request-Id
X-Oss-Server-Time
X-CSRF-TOKEN
X-User
Powered-By-ChinaCache
User-Agent
X-Tec-Api-Root
X-Developer
X-Internal-Host
X-Tec-Api-Origin
X-Key
X-Tec-Api-Version
X-NWS-UUID-VERIFY
X-Cache-Status-Check
X-Parent-Response-Time
X-Ua-Device
X-Ua
Hostname
X-Cache-Grace
X-Cdn-Origin
X-Sn-Servicetimems
Origin
X-Sucuri-Cache
X-Device-Os
X-Pjax-Url
X-LAGOON
X-CF-Powered-By
X-Ocache
X-Location
X-Pf-Uncompressing
X-Tb-Optimization-Total-Bytes-Saved
X-CSRF-Token
On-Server
X-TA-CDN-Provider
X-Via-CDN
A
SRV
X-MSEdge-Flight
Geoip-City
X-MSEdge-Features
PICS-Label
Cloudfront-Viewer-Country
Geoip-Latitude
X-Request-Host
Memory
ProcessTime
X-B3-Parentspanid
X-COUNTRY
X-Cdn-Forward
X-NGINX-Cache
GeoIp-Country-Code
X-BACKEND-TTL
X-Oracle-Dms-Rid
TTL
X-Varnish-URL
X-Vcl-Version
X-Server-IP
X-Litespeed-Cache
X-Servedbyhost
X-Webkit-CSP
Resin-Trace
X-Unique-ID
X-Varnish-Ttl
M-TraceId
XServer
X-TIME
X-HS-Status
Media-Length
Tcn
SN
X-Cdn-Request-ID
Dnion-Transfer-Encoding
Cdn
X-Rocket-Nginx-Bypass
X-B3-SpanId
X-FORWARDED-FOR
X-Correlation-ID
Host-ID
X-Slack-Backend
X-Ratelimit-Remaining
CACHE
X-ServedByHost
X-PAYTM-SRV-ID
X-Beluga-Response-Time
X-Beluga-Record
X-Beluga-Cache-Status
Who
X-Processor
X-Server-Time
X-Beluga-Status
X-Beluga-Trace
X-Beluga-Node
X-Cache-Ttl
X-Cache-FS-Status
X-Dispatch
Arc-Country
X-Action
Pramga
X-DC
HostName
X-RPS
X-DB
X-Skip-Cache
X-DW
X-ND-Cache
X-RSL
X-RPM
X-Via-Ucdn
X-DSS
X-VCL-Version
X-Fastly-Country-Code
X-DI
X-Served-From
Section-Io-Id
Section-Io-Origin-Status
X-Reqid
Section-Io-Origin-Time-Seconds
X-Edge-Server
Cdn-Request-Time
GeoIP-Country-Code
Ttl
Fastly-Drupal-HTML
Cdn-Host
Section-Origin-Responded
NtCoent-Length
X-Dynatrace-Js-Agent
X-ABtesting
N-Cache
Amp-Access-Control-Allow-Source-Origin
Esi-Enabled
X-Hello
X-DevSite-Last-Modified
X-Flog
GeoIP-City
Pics-Label
X-VarnishDD-TTL
GeoIP-Latitude
X-Bc-Bl
X-AIR-PT
Fusion-Deployment-Id
X-Sucuri-Id
X-LiteSpeed-Cache-Control
MIME-Version
X-Planisys-CDN-Cache
X-Varnish-Url
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Policy
CF-Cached-On
X-Adobe-Source
X-APP
X-Zone
X-Request-Start
X-Ratelimit-Limit
X-FPC
X-PF-Uncompressing
X-Azure-Ref-OriginShield
X-Backend-Host
X-Bc
X-HostName
X-Ruxit-Js-Agent
Trailer
Cache-Cookie-Set-Lfrom
Rt-Proxy-Cache
X-SRV
WebServer
Cache-Cookie-Set-From
Cache-Cookie-Set-Idcheck
X-Fastly-Backend-Reqs
X-PJAX-URL
Processtime
X-Scheme
X-Fmm-Version
X-Dynatrace
X-Amzn-Remapped-Connection
X-BE
X-Amzn-Remapped-Date
X-Newrelic-App-Data
X-Swift-Error
Servername
X-Fpc
X-WA
Cteonnt-Length
X-ID
X-ZONE
X-BC
Magicmarker
X-Method
FSS-Cache
FSS-Proxy
Cache-Provider
X-WR-MODIFICATION
X-Frame-Option
Dynatrace
CDN
CF-IPCountry
Requestid
X-Branch-Name
X-LB-ID
X-Snapshot-Date
X-Cache-Id
Lb
X-StackifyID
X-SN
X-Esi-Check
X-CACHE-AGE
X-Aicache-OS
X-Tid
X-SD-PageType
X-Cache-NGX
X-Gzip
SD-X-WS
Ohc-Response-Time
Sid
X-Compress-Hint
L
X-Cc-Via
Release
WZWS-RAY
X-VC
X-SB
Warning
D-Cc-Upstream
X-Cc-Req-Id
V-Cache
X-Fastly-Cache-Hits
X-Request-Url
X-Litespeed-Cache-Control
Load-Balancing
X-Varnish-Beresp-TTL
X-Apw-Access-Action
X-Check-Cacheable
X-Apw-Access-Object
X-Configured-By
X-VCT
X-Wix-Viewer-Type
X-Nananana
X-Instart-Info
X-ECACHE
X-WPE-Loopback-Upstream-Addr
X-Fastly-Cache-Status
WP-Super-Cache
X-Be
X-Apw-Hits
X-Apw-Access-Token
Cneonction
X-ElasticPress-Search
X-App
X-Request-URL
X-Powered-Y
X-Worker
X-Svr
X-GEO