Threat Level: green Handler on Duty: Renato Marinho

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
Link
CF-RAY
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-UA-Compatible
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Cache-Status
X-Generator
Content-Security-Policy-Report-Only
X-Permitted-Cross-Domain-Policies
X-Request-ID
X-Cacheable
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-DNS-Prefetch-Control
X-Ua-Compatible
X-FRAME-OPTIONS
X-Buckets
Status
X-Content-Security-Policy
X-CDN
Content-Encoding
Upgrade
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Xss-Protection
X-Kinja-Server-Push
Keep-Alive
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
P3p
Xkey
X-Pass-Why
X-Cache-Group
X-Envoy-Upstream-Service-Time
X-AH-Environment
CF-Ray
X-Backend
X-Age
X-Server
X-Via
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Server-Powered-By
X-Page-Speed
X-Pingback
EagleId
X-Proxy-Cache
X-Nginx-Cache-Status
X-Ws-Request-Id
X-UA-Device
X-Hacker
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
X-Dns-Prefetch-Control
Cf-Railgun
Grace
X-Swift-CacheTime
X-Swift-SaveTime
X-Amz-Version-Id
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
Report-To
X-Rq
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-WebKit-CSP
X-Server-Id
X-Host
X-Device
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Origin-Cache
Content-Location
X-Response-Time
X-Node
X-Ac
Surrogate-Control
X-Vhost
X-Readtime
Request-Id
X-Cloud-Trace-Context
X-Backend-Server
X-Dispatcher
X-Origin-Upstream-Status
X-Cnection
X-HW
X-Application-Context
X-ORACLE-DMS-ECID
X-DataDome
Fusion-Template-Id
Fusion-Source
Fusion-Content-Id
Fusion-Component-Id
Fusion-Content-Source
X-ORACLE-DMS-RID
X-Cache-Lookup
NEL
X-Mod-Pagespeed
Edge-Control
Rating
X-Rack-Cache
X-Country
X-Akam-SW-Version
X-Clacks-Overhead
Pinterest-Generated-By
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Ruxit-JS-Agent
Accept-Ch
X-Varnish-TTL
X-DynaTrace
X-Country-Code
Allow
X-Instart-Request-ID
X-Goog-Hash
X-PC
X-TtlSet
X-Vname
X-FTR-Request-ID
X-TTL
X-ESI
Accept-Ch-Lifetime
Verso
X-Powered-By-Plesk
Service-Worker-Allowed
X-Url
Content-MD5
X-B3-TraceId
X-Forwarded-Proto
X-Version
X-MS-InvokeApp
X-GitHub-Request-Id
X-Kinja
X-Exp-Variant
X-Exp-Id
X-Cdn-Fetch
X-Kinja-Build
X-GoogleNews-Bot
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
Edge-Cache-Tag
RTSS
Ar-Sid
AR-ATIME
AR-Request-ID
AR-CACHE
AR-PoweredBy
X-Px
X-D2id
X-Abt-Application-Version
X-Debug
X-Server-Name
Charset
SPRequestGuid
X-NF-Request-ID
X-Amz-Server-Side-Encryption
X-Vcache
X-Accel-Expires
X-Cached
X-MSEdge-Ref
X-Powered-CMS
X-Amz-Rid
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Middleton-Display
Pagespeed
X-Middleton-Response
Response
Display
X-Sol
Arr-Disable-Session-Affinity
X-Fastcgi-Cache
X-Vcap-Request-Id
X-Navigation-Version
X-Trace
Pinterest-Version
X-Pinterest-Rid
X-SRCache-Store-Status
TCN
X-SharePointHealthScore
X-SRCache-Fetch-Status
X-Cdn
X-VARITI-CCR
Realpath
Public-Key-Pins
X-Client-IP
Cache-Tag
Access-Control-Request-Method
S
X-Ser
X-Fastly-Request-ID
X-Upstream
MS-Author-Via
X-DynaTrace-JS-Agent
X-Shard
X-Id
SPIisLatency
SPRequestDuration
Nginx-Cache
X-Hp-Webp
MRF-Tech
X-Ezoic-Cdn
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Content-Type
X-Forwarded-For
X-Amzn-Trace-Id
X-Amz-Meta-S3cmd-Attrs
Nel
DynaTrace
X-T
X-Grace
Front-End-Https
X-Recruiting
Fastcgi-Cache
X-Hits
X-Aspnet-Version
X-Varnish-Age
X-Edge-O15-RID
X-DIS-Request-ID
X-Server-ID
X-Dw-Request-Base-Id
ServerID
MicrosoftSharePointTeamServices
X-Mobile-URL
X-Node-Name
X-Element-Page-Cache
NR-ENABLED
X-Content-Digest
X-HS-Cache-Config
X-HS-Hub-Id
X-FTR-Expires
X-FTR-Cache-Status
X-Country-Code-Real
X-HS-Combine-CSS
X-Frontend
X-HS-Content-Id
Powered
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Cache-TTL
Server-Name
X-FTR-Realm
X-FTR-DC
Alternate-Protocol
X-FTR-Backend
X-FTR-Backend-Server
X-FTR-Balancer
X-Logged-In
TP-Cache
TP-L2-Cache
Server-Node
X-Jurisdiction
X-Correlation-Id
X-XRDS-Location
X-Microsite
X-Request-Handler-Origin-Region
X-Request-Processing-Time
X-Request-Received
AMP-Access-Control-Allow-Source-Origin
X-ATS-Timestamp
Upgrade-Insecure-Requests
Backend-Timing
X-Content-Options
X-Page-Id
Refresh
X-Content-Security-Policy-Report-Only
X-Cache-Hit
X-Akamai-Edgescape
X-F-Cache
X-User-Agent
X-Revision
X-Origin-Server
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Varnish-Grace
X-Type
X-Rid
X-Shield-Request-Id
X-Webapp-Samesite-None-Activated-N
X-XRDS-LOCATION
Fastly-Restarts
X-Zen-Fury
X-Geo-Country
X-Content-Powered-By
X-URL
X-B3-Sampled
X-LB-Cache
X-B
X-Az
X-Activity-Id
X-AppVersion
X-Pad
X-N
X-RateLimit-Remaining
X-Analytics
X-CST
X-FTR-Cache-Host
X-Kinsta-Cache
PB-PID
X-Ruxit-Js-Agent
PB-RID
X-Webkit-Csp
X-Mobile-Rewrite
Cache-Status
Arc-Version
X-Cache-Age
X-TT
X-AOL-HN
X-WebKit-CSP-Report-Only
X-Debug-Info
X-Framework
X-B-Cache
X-App-Environment
X-Instance
X-Jobs
X-Request-Guid
X-Signature
X-Time
Access-Control-Allow-Method
DC
Actual-Object-TTL
Paypal-Debug-Id
X-PHP-Backend
X-FB-Debug
X-Tumblr-User
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Cache-Action
X-Load-Cache
X-Git-Hash
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Ttl
Surrogate-Key
X-Varnish-Backend
X-Cached-By
Host-Header
X-Tt-Trace-Tag
Fastcgi-Useragent
X-Amz-Replication-Status
X-Contextid
X-IPLB-Instance
FilterID
MS-CV
X-Tt-Trace-Host
X-Cluster
X-ATG-Version
X-SS-Set-Cookie
Tracecode
X-WA-Info
NGB
X-Response-Served-From
X-Accel-Buffering
Frame-Options
X-Varnish-Server
WPE-Backend
Payment
X-Cache-NE
Host
X-Cache-2
X-Region
Eomportal-Instance
X-Mobile
X-RequestSource
X-Rendered-As
X-Is-Bot
X-FW-Hash
X-IPS-LoggedIn
Xserver
X-Cacheable-TTL
X-FW-Server
X-FW-Static
X-FW-Type
X-FW-Serve
X-GeoIP
X-Cache-Enabled
X-Adobe-Content
X-Kong-Proxy-Latency
X-Cache-Rule
Filters
X-Cache-Operation
X-Host-Name
X-Adobe-Loc
X-Kong-Upstream-Latency
Source
X-NewRelic-App-Data
X-Cache-Key
X-Varnish-Hostname
X-Oneagent-Js-Injection
X-TX-ID
Cache-Tv-Group
X-Tumblr-Pixel-1
X-Srv
X-Tumblr-Pixel-2
X-EdgeConnect-Cache-Status
Cleartype
X-Via-JSL
X-Hostname
X-Seen-By
X-Origin-Response-Time
X-Cache-TTL-Remaining
X-ORACLE-APMCS-REQUEST-ID
X-FastCGI-Cache
X-ORACLE-APMCS-TAG
X-VCache
Cache
Retry-After
Server-Info
X-Presslabs-Stats
X-B3-Traceid
X-HTML-Minification-Powered-By
Datacenter
Healthy
X-RemovedCookies
X-ProcessESI
X-Cache-Control
X-CACHE-KEY
X-RTag
Ms-Operation-Id
X-RateLimit-Limit
X-PressLabs-Stats
X-NWS-LOG-UUID
Liferay-Portal
X-Source
X-Dc
X-UA
X-Environment-Context
X-Cache-Server
X-L-Path
From-Origin
X-FireWall-Port
X-Endurance-Cache-Level
X-Rule
X-Trafficlayer-App-Scope
X-Trafficlayer-App-Name
X-Upgrade-Enabled
X-Status
Version
X-Wix-Request-Id
X-App-Server
X-Handled-By
Meta-Geo
X-Cache-Var-Map
X-Path-Route
X-RN-RSRV
X-Cache-Var
X-ES-SERVER
X-Section
X-Request-Time
X-Access
X-Tb
X-Proxy-Build
OT-Force-Account-Verify
X-Format
Selected-Fe
X-Timing-Wait
X-Shopify-Generated-Cart-Token
X-Sorting-Hat-PodId
X-ProxyCache-Status
Mn-Server-Ip
X-EIG-Tracking-Id
Cache-Tags
X-ShardId
X-ShopId
X-Content-Age
X-Sorting-Hat-ShopId
X-BYPASS-REASON
X-Shopify-Stage
X-Akamai-Request-ID
X-OCL
X-Goog-Meta-Goog-Reserved-File-Mtime
X-ProxyCache-Key
X-Alternate-Cache-Key
X-Storage
X-Human
X-PCL
X-Proto
Accept-CH
Akamai-GRN
NGX
Node
Azure-Version
Azure-InstanceId
X-Proxy
X-Cache-Host
X-Proxy-Cache-Status
Azure-RegionName
Azure-SiteName
X-Cluster-Node
Decoy-Debug-Status
Decoy-Debug-Key
Azure-SlotName
Decoy-Debug-TTL
X-MP-GENERATED-AT
X-AWS-Id
X-Qloud-Router
X-Web-Node
X-SaId
X-VWS-Id
X-Redis-Cache
X-Hyper-Cache
X-RCS-CacheZone
X-Akamai-Request-ID2
X-Hl-Ver
X-Hosted-By
X-JoinUs
X-Viewer-Country
X-Soup
X-Backend-Name
X-FC-Vary-Parameters
Origin-Edge-Control
Origin-Cache-Control
X-ServerID
X-Cache-Config
X-LJ-Flow-ID
X-Debug-Cache
X-Vgn-Hpd-Reason
X-UUID
X-Origin
Ec-Rule-Version
X-Yottaa-Metrics
X-Yottaa-Optimizations
Webcakes-App-Name
Webcakes-App-Version
Webcakes-Region
X-BCube-Filmed-By
TWC-Privacy
TWC-Locale-Group
S-Rt
Property-Id
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-LatLong
TWC-GeoIP-Country
X-CCM
X-Detected-As
X-SayCDN-TTL
X-Say-TTL
X-Site-Version
X-Time-Microsecs
X-Xfnlog-Site
X-Www-Served-By
X-Say-Cacheable
X-Pubstack
X-Generated
X-FW-Dynamic
X-Locale
X-NYM-Debug-Backend
X-Origin-Hint
Now
X-Generated-By
Cross-Origin-Window-Policy
DB-Nickname
X-FB-TRIP-ID
X-TNCMS
X-Varnish-Hits
X-R9-Blue-Green-Version
L5d-Success-Class
X-IP
X-Loop
X-APP-VERSION
Srv
X-Amzn-Remapped-Content-Length
Cache-Name
X-Akamai-Transformed
X-CS
Accept-Charset
Viewport
Uber-Trace-Id
GEO-INFO
X-NCache
X-Drupal-Cache-Tags
X-Esi
Accept-CH-Lifetime
Webserver
X-UA-Device-Type
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Cache-Remote
X-From
Cache-Key
X-Unique-Id
Mime-Version
Time
X-Cluster-Name
X-Origin-TTL
X-Drupal-Cache-Contexts
X-Origin-CC
X-TT-TIMESTAMP
Accept-Language
X-Backend-TTL
Country
X-Mode
X-Forwarded-Host
X-Edge-Location
Odigeo-Trace-Id
X-CDN-Forward
X-Microcachable
Rt-Fastcgi-Cache
X-CLOUD-TRACE-CONTEXT
X-UnsetCookies
X-EC-Lua
X-Info
X-Newrelic-Synthetics
X-B3-Spanid
X-Geo
X-Whom
X-ApacheServer
X-Varnish-Cache-Hits
X-PERF
X-Magnolia-Registration
Ohc-File-Size
Ohc-Cache-HIT
Proxy-Connection
Content-Disposition
ServedBy
X-No-Session
X-UPSTREAM-Address
Geo-Info
X-NGENIX-Cache
X-App-Version
X-PHP-Host
X-Zipkin-Id
X-Proxied
X-Device-Type
X-Routing-Service
X-Labrador-Cache-Channel
Apple-News-Services-Parsed-Url
X-A
X-A-Ccd
Apple-News-Services-Handled
X-Accel-Expires-Debug
Apple-News-Services-Request-Url
Apple-News-Services-Host
W
AsisCache
BehaviorPad-Version
Xc-Version
X-Region-Sid
X-Vtex-Processado-Em
X-CF-Lambda-Version
X-A-Dam
X-VG-TLSProxy
X-Vdms-Version
X-Application
X-VG-WebCache
X-Date
X-D
X-Vtex-Remote-Cache
X-A-Wwc
X-Via-Fastly
X-A-Dcw
X-A-Dgt
Cf-Ipcountry
X-VG-WebServer
VivaBuild
X-Aed
X-CF-Lambda-Fn
X-Geo-Header
Machine
MD5-Digest
X-GeoIP-Country-Code
X-SRCache-Key
GEO-REGION-INFO
X-B-Cookie
Meta-Geo-Continent
Mobile-Detection-Method
X-DPWN-IS-SECURE
X-Transaction
X-Trv-Group
T-Server
Rendered-Blocks
X-G
X-External-Request-Id
X-ARC
X-Sigma-Backend
X-Rojux
X-S
X-S-Cookie
X-Rocket-Build-Number
X-Rewrite-Enabled
Content-Script-Type
X-Request-UUID
X-Connection-Hash
X-Twitter-Response-Tags
X-Session-Fingerprint
X-Sigma
X-Real-IP
Viewtype
Fastcgi-X-Cache-Version
X-Destination
X-ScT
Content-Style-Type
X-C
User-Cache-Control
X-Uri
X-Agile-Id
X-Agile-Age
X-Agile
X-Sucuri-Cache
X-Nc
IsBot
X-WebServer
Environment
Fastly-SSL
X-VC-Cache
Fastly-Soc-X-Request-Id
X-Developers
X-Hit
CDCHOST
X-SIPLIST1
HA-Ipaddr
Ha-Gx-Prefs
X-Distil-CS
X-CUA
X-App-Name
X-Wikidot-Backend
Locid
Powered-By
X-TrackingId
X-Cache-Debug
X-Wikidot-Static-Cache
X-Bip
X-Thanos
X-CGP
X-Backend-State
X-Logging-Id
X-Eu-Site
X-Epic-Correlation-Id
Access-Control-Request-Headers
X-Cache-Time
X-GoCache-CacheStatus
HitType
Server-Int
X-Tumblr-Pixel-3
X-Dispatcher-Server
Server-Surrogate-Control
X-Gamma-Serve
Section-Io-Cache
X-Distributor
RNT-Time
RNT-Machine
Request-EU
Request-Country
X-Fastly-Cache
Server-Cache-Control
X-Trace-Id
Server-ID
Wxu-Next-Region
X-Core-Mission
X-Block-Status
X-BBXSRF
X-Azure-Ref
X-Webstats-RespID
X-Auto-Login
X-Cache-ASPX
X-Cache-Backend
X-Cms-Context
X-Clientip
X-Cache-URL
X-Cache-Info
X-Cache-Bucket
X-Contensis-Viewer-Groups
X-We-Are-Hiring
X-WADP-Cache
X-Urbn-Site-Id
We-Hiring
X-Urbn-Context-Path
V-Age
True-Client-Country-4JS
X-Debug-Cookies
Web-Mar-Node
Wxu-Next-Commit
X-Varnish-Authentication
X-VServer
X-User
X-TH-Server
Wxu-Next-Hostname
X-Debug-Log
Memcached
X-RateLimit-Remaining-Second
X-Rebelmouse-Cache-Control
AKAMAI
X-Key
X-Li-Fabric
X-RateLimit-Limit-Second
X-Rebelmouse-Surrogate-Control
X-Render-Time
Cache-Host
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Instart-Isnd
X-Req
X-Gen-Mode
X-Proxy-Upstream
X-Owner
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Ttl
X-Clara-WADP
X-NodeID
X-Nginx-Cache-Key
X-Origin-Date
X-Ms-Version
X-LI-Proto
X-Li-Pop
X-LI-UUID
X-Micro-Cache
X-Ms-Request-Id
X-Origin-Expires
X-Hnp-Log
X-Irp-Debug
IBM-Web2-Location
Kp-EeAlive
Gh-Request-Id
X-Hash
Fastly-SWR
FNAC-ModuleRouting
X-GeoIP-City
X-SVT-ORM-RULES
X-Generated-In
X-NX-Host
X-Swa-Ws
Mail-Subject
Locale
X-SVT-ORM-VERSION
Fastly-SIE
Heartbleed
Countrycode
X-Request-URI
Fastly-Backend-Name
Country-Code
X-Daa-Tunnel
X-Generated-On
X-Debug-Cache-Store
X-Service
X-Generation-Time
X-Internal-Host
X-Debug-Cache-Expiry
X-Fetched-On
X-NU-AKA-ACS-Version
X-Thinkindot-L3
X-Old-Content-Length
X-Matched-Rule
X-FW-Version
X-Debug-Cache-Fetch
X-Core-Value
X-Has-Esi
X-Variation
X-Level-Front-Cache
X-JWT-State
X-Reboot
X-Is-Gdpr
X-Up
X-Platform-Server
X-OVcl-Cache
X-TT-LOGID
X-Location
X-ServiceProvider
X-Trafficlayer-App-Version
X-OVcl
X-AK-Request-ID
Adler-Geo
Server-Host
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
ServerName
PFcat
Cdncip
X-Nginx-Cache
Is-Eu
Platform
X-Cdn-Srv
X-Cache-Tags
Cdnsip
Thinkindot-Control
X-B3-Parentspanid
X-Lb-Id
X-Server-W
X-Servername
X-S-Maxage
Cache-Hits
X-Refresh
X-SERVER
X-Response-By
X-TA-CDN-Provider
RequestId
X-CSRF-TOKEN
X-B3-SpanId
Filterid
X-CF-Powered-By
X-Tb-Optimization-Total-Bytes-Saved
X-Tec-Api-Root
ProcessTime
X-Tec-Api-Origin
X-Cdn-Forward
X-Tec-Api-Version
X-Server-IP
X-Air-Hostname
X-Parent-Response-Time
X-Var-Ttl
X-Wa
X-Cache-Expired-At
X-Ua
Group
Pragrma
X-Pjax-Url
X-BACKEND-TTL
X-Cdn-Request-ID
Origin
User-Agent
X-Unique-ID
X-NC
Media-Length
Memory
S-Cnection
X-Sucuri-Id
X-CSRF-Token
Powered-By-ChinaCache
X-Correlation-ID
SRV
X-Pf-Uncompressing
TTL
Geoip-Latitude
X-NGINX-Cache
X-Vcl-Version
X-COUNTRY
GeoIp-Country-Code
Esi-Enabled
PICS-Label
X-Servedbyhost
X-Varnish-Cacheable
X-Reqid
SN
X-Rocket-Nginx-Bypass
X-AIR-PT
X-Sucuri-ID
X-Policy
X-Via-CDN
X-Litespeed-Cache
X-Webkit-CSP
X-Planisys-CDN-TTL
Geoip-City
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Developer
X-Request-Start
X-HS-Status
X-NWS-UUID-VERIFY
M-TraceId
X-Via-Ucdn
X-Azure-Ref-OriginShield
HostName
X-TIME
XServer
Dnion-Transfer-Encoding
X-Sn-Servicetimems
X-Cdn-Origin
X-Node-Id
X-LAGOON
X-Cache-Grace
Rt-Proxy-Cache
X-Device-Os
X-FORWARDED-FOR
X-Fastly-Country-Code
Tcn
X-Ocache
Cdn
A
Who
Magicmarker
Resin-Trace
On-Server
X-Request-Host
X-Cache-Ttl
X-Method
X-Ftr-Cache-Host
X-VHOST
Pics-Label
Cloudfront-Viewer-Country
X-ServedByHost
X-MSEdge-Flight
CF-Cached-On
X-MSEdge-Features
X-Cache-Status-Check
Load-Balancing
X-Beluga-Record
X-VCL-Version
Hostname
X-Beluga-Trace
X-Beluga-Response-Time
X-Beluga-Cache-Status
GeoIP-Country-Code
X-Beluga-Status
X-Beluga-Node
X-Oss-Object-Type
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
X-DC
GeoIP-Latitude
X-Be
NtCoent-Length
DSUID
X-APP
X-Svr
Ohc-Response-Time
MIME-Version
Release
X-Oracle-Dms-Rid
X-MServer
X-VCT
X-Fastly-Backend-Reqs
X-PF-Uncompressing
X-Zone
Cteonnt-Length
X-Varnish-Url
X-SRV
Vix-Hermes-Req-Id
X-Bc
Ttl
X-Varnish-URL
GeoIP-City
Host-ID
X-VarnishDD-TTL
X-Varnish-Ttl
X-LiteSpeed-Cache-Control
X-Hp-Ccpa-Warning
X-Newrelic-App-Data
X-Slack-Backend
X-PJAX-URL
WebServer
X-Configured-By
X-Ftr-Request-Id
Amp-Access-Control-Allow-Source-Origin
X-HostName
X-DW
SD-X-WS
X-SD-PageType
X-Upstream-Ct
X-Upstream-Ht
X-BE
X-RPM
X-Dynatrace
X-Aicache-OS
X-Swift-Error
X-RPS
X-DB
X-Action
X-RSL
Processtime
X-Ratelimit-Remaining
X-DSS
X-DI
CACHE
X-Dynatrace-Js-Agent
X-WR-MODIFICATION
Servername
X-Skip-Cache
Cache-Provider
Arc-Country
X-ID
X-SN
X-Compress-Hint
L
X-Tid
X-Server-Time
X-Processor
X-Cache-FS-Status
Pramga
X-PAYTM-SRV-ID
X-Dispatch
X-Cache-Id
X-Frame-Option
CF-IPCountry
X-Ftr-Backend
X-ServerName
X-ND-Cache
X-Release
X-StackifyID
X-Snapshot-Date
X-Ftr-Backend-Server
X-ABtesting
Pagetype
X-Flog
X-Fastly-Cache-Hits
X-FPC
X-Via-NSCOPI
Lfy
Fastly-Drupal-HTML
X-Hello
CDN
X-Ftr-Dc
Requestid
X-Ftr-Balancer
X-Ftr-Realm
X-DevSite-Last-Modified
X-Branch-Name
X-LB-ID
Dynatrace
X-Ratelimit-Limit
Serverid
X-CACHE-AGE
X-Cc-Via
X-Cc-Req-Id
X-Edge-Server
Cdn-Request-Time
X-Served-From
Cdn-Host
N-Cache
D-Cc-Upstream
X-Varnish-Beresp-TTL
LB
X-Request-Url
X-Apw-Hits
X-Apw-Access-Token
X-Apw-Access-Object
Warning
X-Apw-Access-Action
Proxy-Firewall
X-SB
X-VC
X-Scheme
X-Edge-IP
X-ZONE
V-Cache
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
X-Node-ID
X-Amzn-Remapped-Date
X-Fpc
X-Amzn-Remapped-Connection
Inserted-Into-Cache-At
UCS
X-WA
Cache-Cookie-Set-From
X-App
X-ElasticPress-Search
X-Powered-Y
X-Request-URL
X-Check-Cacheable
WP-Super-Cache
X-Worker
Backend-Name
Correlation-Id
X-Fastly-Cache-Status
X-BC
Lb