Threat Level: green Handler on Duty: Russ McRee

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
CF-RAY
Link
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-Cache-Hits
X-Amz-Cf-Pop
X-UA-Compatible
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Cache-Status
X-Generator
Content-Security-Policy-Report-Only
X-Permitted-Cross-Domain-Policies
X-Request-ID
X-Cacheable
X-Template
X-Language
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
Status
X-Content-Security-Policy
X-CDN
Upgrade
Content-Encoding
Access-Control-Expose-Headers
X-Ua-Compatible
Access-Control-Max-Age
X-Xss-Protection
X-Kinja-Server-Push
Keep-Alive
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
P3p
Xkey
X-Pass-Why
X-Cache-Group
X-AH-Environment
X-Envoy-Upstream-Service-Time
CF-Ray
X-Backend
X-Via
X-Age
X-Server
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Server-Powered-By
X-Page-Speed
X-Pingback
X-Ws-Request-Id
EagleId
X-Proxy-Cache
X-Nginx-Cache-Status
X-UA-Device
X-Hacker
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
Grace
Cf-Railgun
X-Swift-SaveTime
X-Swift-CacheTime
X-Amz-Version-Id
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
Report-To
X-Dns-Prefetch-Control
X-Rq
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-WebKit-CSP
X-Server-Id
X-Host
X-Device
X-OneAgent-JS-Injection
EagleEye-TraceId
X-Origin-Cache
X-Response-Time
Content-Location
X-Ac
X-Node
Surrogate-Control
X-Vhost
X-Readtime
Request-Id
X-Cloud-Trace-Context
X-Backend-Server
X-Dispatcher
X-Origin-Upstream-Status
X-Cnection
X-HW
X-Application-Context
X-ORACLE-DMS-ECID
Fusion-Content-Id
Fusion-Component-Id
Fusion-Template-Id
Fusion-Source
Fusion-Content-Source
X-DataDome
X-ORACLE-DMS-RID
X-Cache-Lookup
NEL
X-Mod-Pagespeed
Rating
Edge-Control
X-Rack-Cache
X-Country
X-Akam-SW-Version
X-Clacks-Overhead
X-Ruxit-JS-Agent
Pinterest-Generated-By
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Allow
X-Country-Code
X-DynaTrace
X-Instart-Request-ID
X-Varnish-TTL
X-TTL
X-Goog-Hash
X-Vname
X-TtlSet
X-PC
X-FTR-Request-ID
Accept-Ch
Verso
X-ESI
X-Powered-By-Plesk
Service-Worker-Allowed
Content-MD5
X-Url
Accept-Ch-Lifetime
X-Version
X-Forwarded-Proto
X-MS-InvokeApp
X-B3-TraceId
X-GitHub-Request-Id
X-Exp-Id
X-Cdn-Fetch
X-GoogleNews-Bot
X-Exp-Variant
X-Kinja-Revision
X-Use-Magma
X-Kinja-Server
X-Kinja
X-Kinja-Build
Edge-Cache-Tag
RTSS
AR-CACHE
Ar-Sid
AR-Request-ID
AR-PoweredBy
AR-ATIME
X-Px
X-D2id
X-Debug
X-Abt-Application-Version
SPRequestGuid
X-Vcache
Charset
X-Amz-Server-Side-Encryption
X-NF-Request-ID
X-Server-Name
X-Accel-Expires
X-Cached
X-MSEdge-Ref
X-Middleton-Response
X-Middleton-Display
Pagespeed
X-Sol
Response
Display
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Amz-Rid
Arr-Disable-Session-Affinity
X-Powered-CMS
X-Vcap-Request-Id
TCN
X-Navigation-Version
X-Pinterest-Rid
Pinterest-Version
X-SharePointHealthScore
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Trace
X-Fastcgi-Cache
X-Cdn
X-VARITI-CCR
Realpath
Public-Key-Pins
Cache-Tag
X-Client-IP
Access-Control-Request-Method
X-Ser
X-Fastly-Request-ID
MS-Author-Via
S
X-DynaTrace-JS-Agent
X-Upstream
X-Shard
SPRequestDuration
SPIisLatency
Nginx-Cache
X-Id
X-B3-TraceId-Primal
MRF-Tech
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
X-Ezoic-Cdn
Mrf-Cache-Status
X-Hp-Webp
X-Content-Type
X-Grace
X-Amzn-Trace-Id
X-T
X-Amz-Meta-S3cmd-Attrs
Nel
DynaTrace
X-Recruiting
Front-End-Https
X-Forwarded-For
X-Hits
X-Edge-O15-RID
Fastcgi-Cache
X-Aspnet-Version
X-Varnish-Age
ServerID
X-Server-ID
MicrosoftSharePointTeamServices
X-Dw-Request-Base-Id
X-DIS-Request-ID
X-Node-Name
X-Mobile-URL
X-Element-Page-Cache
X-Content-Digest
NR-ENABLED
X-FTR-Expires
X-FTR-Cache-Status
X-Country-Code-Real
X-Cache-TTL
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Combine-CSS
X-Frontend
Powered
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-FTR-Backend
X-FTR-Realm
X-FTR-DC
X-FTR-Balancer
X-FTR-Backend-Server
X-Jurisdiction
Alternate-Protocol
Server-Name
Server-Node
TP-L2-Cache
TP-Cache
X-Logged-In
X-Correlation-Id
X-XRDS-Location
X-Request-Processing-Time
X-Request-Received
AMP-Access-Control-Allow-Source-Origin
X-Microsite
X-Request-Handler-Origin-Region
Backend-Timing
X-ATS-Timestamp
Upgrade-Insecure-Requests
X-Page-Id
X-Content-Options
X-Cache-Hit
Refresh
X-Amzn-RequestId
X-Content-Security-Policy-Report-Only
X-Amz-Apigw-Id
X-Origin-Server
X-Akamai-Edgescape
X-F-Cache
X-User-Agent
X-Revision
X-Rid
X-Type
X-Varnish-Grace
X-Zen-Fury
X-Shield-Request-Id
X-XRDS-LOCATION
Fastly-Restarts
X-Content-Powered-By
X-CST
X-B3-Sampled
X-LB-Cache
X-B
X-URL
X-Webapp-Samesite-None-Activated-N
X-Az
X-Activity-Id
X-N
X-Geo-Country
X-AppVersion
X-FTR-Cache-Host
PB-RID
X-Pad
PB-PID
X-Kinsta-Cache
X-Mobile-Rewrite
Arc-Version
Cache-Status
X-RateLimit-Remaining
X-Analytics
X-TT
X-Cache-Age
X-AOL-HN
X-WebKit-CSP-Report-Only
X-Debug-Info
X-Webkit-Csp
X-Instance
X-Framework
X-Tumblr-Pixel
X-Jobs
X-Time
X-Tumblr-Pixel-0
Actual-Object-TTL
DC
X-Signature
X-B-Cache
Paypal-Debug-Id
X-Request-Guid
X-Tumblr-User
X-App-Environment
Access-Control-Allow-Method
X-FB-Debug
X-PHP-Backend
X-Cache-Action
X-Load-Cache
X-Git-Hash
X-Cached-By
Surrogate-Key
X-Varnish-Backend
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
Fastcgi-Useragent
X-Tt-Trace-Tag
Host-Header
X-Amz-Replication-Status
X-Tt-Trace-Host
X-IPLB-Instance
X-Contextid
MS-CV
FilterID
X-Ruxit-Js-Agent
X-SS-Set-Cookie
Accept-CH
X-ATG-Version
X-FastCGI-Cache
X-Cluster
X-Cache-Key
Tracecode
X-WA-Info
NGB
X-Accel-Buffering
X-Response-Served-From
X-B3-Traceid
WPE-Backend
X-Ttl
X-Mobile
X-Cache-NE
Frame-Options
Payment
X-Varnish-Server
X-Host-Name
X-Srv
Xserver
X-FW-Static
X-FW-Type
X-Kong-Upstream-Latency
X-Hostname
X-Kong-Proxy-Latency
Source
X-Region
Host
X-FW-Hash
X-Cache-2
X-Cache-Rule
X-FW-Serve
X-Cache-Operation
X-FW-Server
Eomportal-Instance
X-Rendered-As
X-Adobe-Loc
X-Tumblr-Pixel-1
X-Tumblr-Pixel-2
X-Varnish-Hostname
X-Cache-Enabled
X-Is-Bot
X-Adobe-Content
X-Cacheable-TTL
Filters
X-IPS-LoggedIn
X-GeoIP
Cache-Tv-Group
X-TX-ID
X-ORACLE-APMCS-TAG
X-ORACLE-APMCS-REQUEST-ID
X-RequestSource
X-Via-JSL
X-Origin-Response-Time
X-EdgeConnect-Cache-Status
X-NewRelic-App-Data
X-Presslabs-Stats
Cleartype
Accept-CH-Lifetime
X-Seen-By
X-Cache-TTL-Remaining
Cache
X-VCache
Retry-After
Server-Info
X-NWS-LOG-UUID
X-ProcessESI
X-RemovedCookies
X-HTML-Minification-Powered-By
X-Cache-Control
Datacenter
Ms-Operation-Id
X-RTag
Liferay-Portal
Healthy
X-Source
X-UA
X-Dc
X-Environment-Context
X-L-Path
X-FireWall-Port
X-Upgrade-Enabled
X-Cache-Server
X-Endurance-Cache-Level
From-Origin
X-RateLimit-Limit
X-CACHE-KEY
X-APP-VERSION
X-App-Server
X-PressLabs-Stats
X-Esi
X-Rule
Version
X-Handled-By
X-Status
X-Wix-Request-Id
X-Cache-Var-Map
Meta-Geo
X-RN-RSRV
X-Cache-Var
X-ES-SERVER
X-Backend-Name
X-Path-Route
Selected-Fe
OT-Force-Account-Verify
X-Access
X-Tb
X-Timing-Wait
X-Proxy-Build
X-Format
X-Section
X-Request-Time
X-ShopId
Azure-SiteName
X-Storage
X-ShardId
X-ProxyCache-Status
X-Content-Age
Azure-RegionName
X-Proto
X-PCL
Akamai-GRN
X-Human
X-OCL
X-Sorting-Hat-PodId
X-Origin
Azure-SlotName
X-Sorting-Hat-ShopId
X-Shopify-Stage
X-Goog-Meta-Goog-Reserved-File-Mtime
Azure-InstanceId
X-Akamai-Request-ID
X-Alternate-Cache-Key
Mn-Server-Ip
X-EIG-Tracking-Id
Azure-Version
X-Shopify-Generated-Cart-Token
X-ProxyCache-Key
X-BYPASS-REASON
Cache-Tags
Origin-Edge-Control
Origin-Cache-Control
X-Trafficlayer-App-Name
S-Rt
X-SaId
X-Cache-Config
X-AWS-Id
X-Akamai-Request-ID2
Node
NGX
DB-Nickname
X-Soup
X-Time-Microsecs
Decoy-Debug-Key
Decoy-Debug-Status
X-ServerID
Ec-Rule-Version
Decoy-Debug-TTL
X-Cache-Host
X-Redis-Cache
X-JoinUs
X-Hyper-Cache
X-Proxy-Cache-Status
X-LJ-Flow-ID
X-MP-GENERATED-AT
X-Trafficlayer-App-Scope
X-NYM-Debug-Backend
X-Proxy
X-Hosted-By
X-Hl-Ver
X-Qloud-Router
X-Debug-Cache
X-Cluster-Node
X-FC-Vary-Parameters
X-Pubstack
X-Generated-By
X-FW-Dynamic
X-UUID
Now
X-Vgn-Hpd-Reason
X-Yottaa-Metrics
X-Viewer-Country
X-Web-Node
X-Yottaa-Optimizations
X-VWS-Id
X-RCS-CacheZone
X-Www-Served-By
Cross-Origin-Window-Policy
Webcakes-App-Version
X-CCM
X-SayCDN-TTL
Srv
X-BCube-Filmed-By
X-Varnish-Hits
X-Detected-As
Webcakes-Region
X-Say-TTL
X-IP
TWC-GeoIP-LatLong
TWC-Locale-Group
X-Locale
X-Origin-Hint
TWC-Privacy
X-Generated
TWC-GeoIP-Country
Webcakes-App-Name
X-Site-Version
Property-Id
X-Say-Cacheable
TWC-Connection-Speed
TWC-Device-Class
X-Amzn-Remapped-Content-Length
X-Xfnlog-Site
X-FB-TRIP-ID
GEO-INFO
X-TNCMS
X-Loop
X-Oneagent-Js-Injection
X-R9-Blue-Green-Version
L5d-Success-Class
Accept-Charset
X-Akamai-Transformed
X-CS
Cache-Name
X-Unique-Id
Uber-Trace-Id
X-NCache
Viewport
X-Drupal-Cache-Tags
Webserver
Time
Cache-Key
X-UA-Device-Type
X-Backend-TTL
X-Cache-Remote
VIX-Pulpo-Node
X-From
X-CDN-Forward
VIX-Pulpo-Upstream-Status
X-Cluster-Name
X-Mode
X-Drupal-Cache-Contexts
X-Origin-TTL
X-Origin-CC
Accept-Language
X-UnsetCookies
X-TT-TIMESTAMP
Country
X-Forwarded-Host
Mime-Version
X-B3-Spanid
X-Edge-Location
Rt-Fastcgi-Cache
Odigeo-Trace-Id
X-Info
X-Microcachable
X-Whom
X-CLOUD-TRACE-CONTEXT
X-Newrelic-Synthetics
X-TA-CDN-Provider
X-Varnish-Cache-Hits
X-Geo
X-ApacheServer
X-PERF
X-Magnolia-Registration
ServedBy
X-NGENIX-Cache
Content-Disposition
X-EC-Lua
X-UPSTREAM-Address
Proxy-Connection
X-No-Session
Ohc-Cache-HIT
Ohc-File-Size
X-Zipkin-Id
X-Proxied
X-Device-Type
X-Routing-Service
X-Daa-Tunnel
X-Via-Fastly
Cf-Ipcountry
BehaviorPad-Version
Apple-News-Services-Request-Url
Apple-News-Services-Host
Apple-News-Services-Handled
Apple-News-Services-Parsed-Url
X-Uri
AsisCache
X-A-Dam
X-Rojux
X-Rocket-Build-Number
X-S
X-S-Cookie
X-ScT
X-Rewrite-Enabled
X-Request-UUID
X-G
X-External-Request-Id
X-Geo-Header
X-GeoIP-Country-Code
X-Region-Sid
X-Session-Fingerprint
X-Sigma
X-VG-WebServer
X-VG-WebCache
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-VG-TLSProxy
X-Vdms-Version
X-SRCache-Key
X-Sigma-Backend
X-Transaction
X-Trv-Group
X-Twitter-Response-Tags
X-DPWN-IS-SECURE
X-Destination
T-Server
Rendered-Blocks
Viewtype
VivaBuild
W
Mobile-Detection-Method
Meta-Geo-Continent
Fastcgi-X-Cache-Version
Content-Style-Type
GEO-REGION-INFO
Machine
MD5-Digest
X-A
X-A-Dcw
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-Connection-Hash
X-D
X-Date
X-B-Cookie
X-ARC
X-A-Wwc
X-A-Dgt
X-Accel-Expires-Debug
X-Aed
X-Application
Content-Script-Type
X-A-Ccd
X-PHP-Host
X-Labrador-Cache-Channel
HitType
X-Real-IP
X-C
User-Cache-Control
X-CUA
CDCHOST
X-Logging-Id
Environment
Powered-By
IsBot
Server-Surrogate-Control
Server-Cache-Control
Locid
X-Contensis-Viewer-Groups
X-Developers
X-Distil-CS
X-Epic-Correlation-Id
X-Eu-Site
Gh-Request-Id
Ha-Gx-Prefs
X-Hit
Geo-Info
Fastly-Soc-X-Request-Id
X-Cache-Time
X-Render-Time
HA-Ipaddr
X-CGP
X-Bip
X-VC-Cache
X-Agile-Id
X-Cache-ASPX
X-Agile-Age
X-Varnish-Authentication
X-Thanos
X-Backend-State
X-TrackingId
X-Auto-Login
X-App-Name
X-Tumblr-Pixel-3
X-WebServer
X-Wikidot-Backend
X-SIPLIST1
X-Wikidot-Static-Cache
X-Cache-Debug
X-Agile
X-Sucuri-Cache
X-GoCache-CacheStatus
Fastly-SSL
X-Fetched-On
X-Distributor
X-AK-Request-ID
X-Azure-Ref
X-FW-Version
X-Gamma-Serve
X-Fastly-Cache
X-BBXSRF
X-Clara-WADP
X-Clientip
X-Cms-Context
X-Gen-Mode
X-Cdn-Srv
X-Cache-Bucket
X-Cache-URL
X-Cache-Backend
X-Core-Mission
X-Cache-Info
X-Debug-Cookies
X-Debug-Log
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Block-Status
X-Debug-Cache-Expiry
X-Dispatcher-Server
X-Irp-Debug
X-Request-URI
X-Server-W
X-Nc
X-SVT-ORM-RULES
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Owner
X-Proxy-Upstream
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-SVT-ORM-VERSION
X-Swa-Ws
X-VServer
X-WADP-Cache
X-We-Are-Hiring
X-Webstats-RespID
X-User
X-Urbn-Site-Id
X-TH-Server
X-Trace-Id
X-TT-LOGID
X-Urbn-Context-Path
X-OVcl-Cache
X-OVcl
X-Instart-Isnd
X-Key
X-Li-Fabric
X-Li-Pop
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-Generation-Time
X-GeoIP-City
X-Hash
X-Hnp-Log
X-LI-Proto
X-LI-UUID
X-NodeID
X-NX-Host
X-Origin-Date
X-Origin-Expires
X-Nginx-Cache-Key
X-Varnish-Beresp-Grace
X-Location
X-Micro-Cache
X-Ms-Request-Id
X-Generated-In
X-Ms-Version
Fastly-SIE
Server-Int
Fastly-SWR
Server-ID
Fastly-Backend-Name
Countrycode
V-Age
X-Varnish-Beresp-Status
Country-Code
Section-Io-Cache
Heartbleed
Request-EU
Mail-Subject
Request-Country
Memcached
Locale
RNT-Machine
IBM-Web2-Location
RNT-Time
Kp-EeAlive
X-Varnish-Beresp-Ttl
True-Client-Country-4JS
Cdnsip
Access-Control-Request-Headers
Web-Mar-Node
We-Hiring
AKAMAI
Cdncip
Cache-Host
ServerName
Wxu-Next-Region
PFcat
Is-Eu
X-Variation
X-Up
X-ServiceProvider
X-Servername
X-Service
X-Req
X-Generated-On
X-Trafficlayer-App-Version
X-Thinkindot-L3
FNAC-ModuleRouting
X-NU-AKA-ACS-Version
X-Old-Content-Length
Platform
X-Nginx-Cache
X-Matched-Rule
X-Level-Front-Cache
X-JWT-State
X-Internal-Host
X-Platform-Server
Adler-Geo
X-Is-Gdpr
X-Reboot
X-Has-Esi
Thinkindot-CacheControl
X-Cache-Tags
Server-Host
X-Core-Value
Thinkindot-CacheControl-Type
Wxu-Next-Hostname
Thinkindot-Control
Wxu-Next-Commit
Cache-Hits
X-SERVER
X-Refresh
X-Response-By
X-S-Maxage
X-App-Version
X-B3-Parentspanid
X-Lb-Id
RequestId
X-Tb-Optimization-Total-Bytes-Saved
X-Air-Hostname
X-CSRF-TOKEN
X-Parent-Response-Time
Filterid
X-CF-Powered-By
X-NC
Group
X-Cache-Expired-At
Pragrma
X-Tec-Api-Version
X-Var-Ttl
ProcessTime
X-Tec-Api-Root
X-Tec-Api-Origin
X-B3-SpanId
X-Ua
Memory
X-Wa
X-Server-IP
S-Cnection
X-Cdn-Forward
User-Agent
X-Pjax-Url
Powered-By-ChinaCache
Origin
X-BACKEND-TTL
X-CSRF-Token
Media-Length
X-Pf-Uncompressing
X-Sucuri-ID
X-Cdn-Request-ID
SRV
X-Correlation-ID
Geoip-Latitude
PICS-Label
TTL
X-COUNTRY
X-Vcl-Version
X-NGINX-Cache
X-FORWARDED-FOR
GeoIp-Country-Code
X-Varnish-Cacheable
X-Sucuri-Id
X-Unique-ID
X-NWS-UUID-VERIFY
Geoip-City
X-Servedbyhost
X-Via-CDN
X-Rocket-Nginx-Bypass
SN
X-Reqid
Dnion-Transfer-Encoding
Esi-Enabled
X-Webkit-CSP
X-Litespeed-Cache
X-AIR-PT
X-Developer
X-Planisys-CDN-Rules
X-Varnish-Ttl
X-Sn-Servicetimems
X-HS-Status
X-Device-Os
X-Node-Id
X-Cache-Grace
X-Cdn-Origin
X-LAGOON
X-Via-Ucdn
X-Ocache
X-Policy
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
X-TIME
XServer
X-Azure-Ref-OriginShield
On-Server
X-Request-Start
M-TraceId
HostName
X-Request-Host
X-MSEdge-Flight
A
X-MSEdge-Features
Rt-Proxy-Cache
Who
Resin-Trace
Cdn
X-Cache-Status-Check
X-Cache-Ttl
X-Fastly-Country-Code
Hostname
X-Ftr-Cache-Host
X-VHOST
X-Beluga-Cache-Status
Cloudfront-Viewer-Country
X-Beluga-Record
X-Beluga-Status
Magicmarker
X-Method
X-Beluga-Trace
X-Beluga-Response-Time
X-Beluga-Node
X-APP
X-ServedByHost
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Oss-Request-Id
X-Oss-Storage-Class
X-Oss-Server-Time
GeoIP-Country-Code
CF-Cached-On
MIME-Version
X-VCL-Version
X-DC
Load-Balancing
Ttl
X-Zone
Pics-Label
NtCoent-Length
Host-ID
X-Bc
X-Varnish-URL
GeoIP-Latitude
X-Oracle-Dms-Rid
Cteonnt-Length
X-Varnish-Url
X-Fastly-Backend-Reqs
X-Svr
Ohc-Response-Time
GeoIP-City
Tcn
X-Be
DSUID
X-Ratelimit-Remaining
X-LiteSpeed-Cache-Control
X-Slack-Backend
X-VCT
Release
X-PF-Uncompressing
X-VarnishDD-TTL
X-PJAX-URL
X-Newrelic-App-Data
X-MServer
Vix-Hermes-Req-Id
X-Hp-Ccpa-Warning
X-SERVER-NAME
Amp-Access-Control-Allow-Source-Origin
X-Action
X-RSL
X-SRV
WebServer
X-Ftr-Request-Id
X-DB
X-RPS
X-DSS
X-DI
X-RPM
X-DW
X-Server-Time
X-Processor
X-BE
X-Tid
Processtime
X-PAYTM-SRV-ID
X-Skip-Cache
X-Configured-By
X-Cache-FS-Status
X-Dynatrace
X-FPC
Arc-Country
X-Swift-Error
Pramga
X-Dispatch
X-WR-MODIFICATION
Servername
X-Ratelimit-Limit
X-Dynatrace-Js-Agent
X-Hello
X-ND-Cache
X-DevSite-Last-Modified
Cache-Provider
Fastly-Drupal-HTML
X-ABtesting
X-Flog
SD-X-WS
X-ID
X-LB-ID
X-Upstream-Ct
X-Upstream-Ht
X-Aicache-OS
CDN
X-SD-PageType
CACHE
X-Frame-Option
X-HostName
Pagetype
X-Served-From
X-Fastly-Cache-Hits
X-StackifyID
L
X-Edge-Server
Cdn-Request-Time
N-Cache
CF-IPCountry
X-SN
Cdn-Host
Lfy
X-Ftr-Backend-Server
X-Branch-Name
X-Ftr-Realm
X-Ftr-Dc
Dynatrace
X-Snapshot-Date
Requestid
X-Cache-Id
X-Ftr-Backend
X-Compress-Hint
X-Ftr-Balancer
X-CACHE-AGE
X-SB
X-ServerName
X-VC
Warning
X-Via-NSCOPI
X-Release
X-Apw-Access-Token
X-Amzn-Remapped-Date
X-Bc-Bl
X-Amzn-Remapped-Connection
X-WA
X-Apw-Access-Object
X-Apw-Access-Action
V-Cache
X-Request-Url
X-Cc-Req-Id
X-Cc-Via
X-Apw-Hits
D-Cc-Upstream
X-ZONE
Proxy-Firewall
X-Varnish-Beresp-TTL
X-Edge-IP
X-Backend-Host
CloudFront-Viewer-Country
X-App
X-Powered-Y
X-Worker
X-Check-Cacheable
X-ElasticPress-Search
Lb
X-Fastly-Cache-Status
LB
X-Scheme
Correlation-Id
Backend-Name
WP-Super-Cache
X-BC
X-Request-URL