Threat Level: green Handler on Duty: Manuel Humberto Santander Pelaez

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-Powered-By
Pragma
CF-Cache-Status
Link
ETag
Expect-CT
X-XSS-Protection
CF-RAY
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Xss-Protection
X-Varnish
Alt-Svc
X-Timer
CF-Ray
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-Request-ID
X-DNS-Prefetch-Control
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
Status
Upgrade
Content-Encoding
X-Content-Security-Policy
X-CDN
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
X-Pass-Why
X-Cache-Group
X-Envoy-Upstream-Service-Time
X-AH-Environment
X-Via
Xkey
X-Backend
X-Age
X-Server
X-Ws-Request-Id
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
EagleId
X-Page-Speed
X-Server-Powered-By
X-Pingback
X-Proxy-Cache
X-Hacker
X-Nginx-Cache-Status
Request-Context
Feature-Policy
Server-Timing
X-Varnish-Cache
X-UA-Device
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
Cf-Railgun
Grace
X-Amz-Version-Id
P3p
X-Ua-Compatible
Report-To
X-LiteSpeed-Cache
X-OneAgent-JS-Injection
X-Rq
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-WebKit-CSP
X-Device
X-Host
X-Origin-Cache
X-Server-Id
X-Response-Time
EagleEye-TraceId
X-Node
X-Ac
Surrogate-Control
Content-Location
X-Vhost
X-Cloud-Trace-Context
X-Backend-Server
X-Readtime
X-Dispatcher
X-Ruxit-JS-Agent
Request-Id
X-Cache-Lookup
X-Origin-Upstream-Status
X-Cnection
X-Application-Context
X-HW
Fusion-Content-Id
Fusion-Component-Id
Fusion-Content-Source
Fusion-Template-Id
Fusion-Source
X-ORACLE-DMS-ECID
NEL
X-Mod-Pagespeed
X-ORACLE-DMS-RID
X-Country
X-Clacks-Overhead
X-Rack-Cache
X-Akam-SW-Version
Edge-Control
Rating
X-DataDome
X-Dns-Prefetch-Control
Allow
Pinterest-Generated-By
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Country-Code
X-FTR-Request-ID
X-Varnish-TTL
X-Instart-Request-ID
Accept-Ch
X-DynaTrace
X-PC
X-Vname
X-TtlSet
X-Goog-Hash
X-TTL
Content-MD5
Verso
X-ESI
Service-Worker-Allowed
X-Url
Accept-Ch-Lifetime
X-Powered-By-Plesk
X-Vcache
X-Cdn-Fetch
X-Use-Magma
RTSS
X-Exp-Variant
X-GitHub-Request-Id
X-Exp-Id
X-Kinja-Revision
X-Kinja-Server
X-Kinja
X-Kinja-Build
X-GoogleNews-Bot
X-B3-TraceId
X-Version
X-Forwarded-Proto
X-MS-InvokeApp
X-Server-Name
X-D2id
Edge-Cache-Tag
X-Px
X-Abt-Application-Version
X-Server-ID
X-Debug
X-Amz-Server-Side-Encryption
AR-PoweredBy
AR-CACHE
AR-ATIME
AR-Request-ID
Ar-Sid
SPRequestGuid
X-Cached
Charset
X-Navigation-Version
X-Vcap-Request-Id
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-NF-Request-ID
X-TEC-API-VERSION
X-MSEdge-Ref
X-Amz-Rid
X-Middleton-Display
X-Sol
X-Middleton-Response
Response
Pagespeed
Display
Arr-Disable-Session-Affinity
X-Accel-Expires
TCN
X-VARITI-CCR
X-SharePointHealthScore
X-Fastly-Request-ID
Nginx-Cache
MS-Author-Via
Pinterest-Version
X-Pinterest-Rid
Public-Key-Pins
X-Fastcgi-Cache
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Trace
X-Powered-CMS
X-Cdn
X-Client-IP
Realpath
Cache-Tag
X-Edge-O15-RID
X-Ser
Access-Control-Request-Method
X-Content-Type
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
SPRequestDuration
SPIisLatency
X-Upstream
X-Amzn-Trace-Id
X-Shard
X-Grace
X-Jurisdiction
X-Hp-Webp
X-Cache-TTL
X-Id
Front-End-Https
X-Ezoic-Cdn
X-Forwarded-For
X-Hits
X-Amz-Meta-S3cmd-Attrs
X-T
S
Fastcgi-Cache
Nel
X-DynaTrace-JS-Agent
X-Recruiting
DynaTrace
X-Aspnet-Version
X-Element-Page-Cache
X-Node-Name
X-Dw-Request-Base-Id
X-Content-Digest
X-FTR-DC
X-FTR-Expires
X-Mobile-URL
X-FTR-Cache-Status
X-FTR-Balancer
X-FTR-Backend
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Realm
X-Varnish-Age
MicrosoftSharePointTeamServices
X-DIS-Request-ID
ServerID
TP-Cache
TP-L2-Cache
Server-Node
NR-ENABLED
X-Frontend
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Hub-Id
X-Logged-In
X-Goog-Metageneration
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
X-Goog-Generation
Powered
X-Correlation-Id
X-CST
Alternate-Protocol
X-XRDS-Location
Server-Name
Upgrade-Insecure-Requests
X-Amz-Apigw-Id
X-Amzn-RequestId
Fastly-Restarts
X-Cache-Hit
X-FTR-Cache-Host
AMP-Access-Control-Allow-Source-Origin
X-Microsite
X-Request-Handler-Origin-Region
Backend-Timing
X-ATS-Timestamp
X-Page-Id
X-Zen-Fury
X-Content-Options
X-User-Agent
X-Request-Processing-Time
X-Request-Received
Refresh
X-Content-Security-Policy-Report-Only
X-F-Cache
X-Varnish-Grace
X-Akamai-Edgescape
X-Origin-Server
X-Rid
X-LB-Cache
PB-RID
PB-PID
Arc-Version
X-Mobile-Rewrite
X-B
X-Content-Powered-By
X-Revision
X-Type
X-B3-Sampled
Cache-Status
X-XRDS-LOCATION
X-Geo-Country
X-AppVersion
X-Activity-Id
X-Az
X-NWS-LOG-UUID
X-Kinsta-Cache
X-TT
X-Cache-Action
X-AOL-HN
X-Framework
X-Debug-Info
X-Jobs
X-N
Access-Control-Allow-Method
X-Signature
X-Request-Guid
X-PHP-Backend
X-Cached-By
X-WebKit-CSP-Report-Only
X-FB-Debug
X-B-Cache
X-Time
X-App-Environment
Actual-Object-TTL
X-Git-Hash
X-Instance
X-Cache-Age
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tt-Trace-Tag
X-Tt-Trace-Host
Paypal-Debug-Id
X-Load-Cache
Fastcgi-Useragent
X-Amz-Replication-Status
X-URL
X-Varnish-Backend
X-WA-Info
X-Pad
DC
Host
X-ATG-Version
X-Webkit-Csp
X-RateLimit-Remaining
Host-Header
X-ORACLE-APMCS-REQUEST-ID
X-FastCGI-Cache
X-ORACLE-APMCS-TAG
X-Via-JSL
X-Shield-Request-Id
MS-CV
Surrogate-Key
X-IPLB-Instance
X-Contextid
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Mobile
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Host-Name
Liferay-Portal
Retry-After
Frame-Options
NGB
X-Response-Served-From
X-Seen-By
Accept-CH
X-Accel-Buffering
X-Hostname
X-Srv
X-NewRelic-App-Data
Payment
X-Cache-NE
Source
Xserver
X-Origin-Response-Time
X-Varnish-Server
X-Cacheable-TTL
WPE-Backend
X-Is-Bot
X-Region
X-SS-Set-Cookie
X-Rendered-As
X-Cache-2
Eomportal-Instance
Tracecode
X-Varnish-Hostname
Server-Info
X-GeoIP
X-Adobe-Loc
X-FW-Type
X-Cache-Enabled
X-Adobe-Content
X-IPS-LoggedIn
X-Cluster
X-FW-Hash
X-FW-Serve
X-FW-Static
X-FW-Server
Filters
X-RequestSource
X-Cache-Rule
X-App-Server
Cache-Tv-Group
X-ProcessESI
X-Cache-Operation
X-Tumblr-Pixel-1
X-Tumblr-Pixel-2
X-Cache-Key
X-RemovedCookies
X-Ttl
X-EdgeConnect-Cache-Status
X-Presslabs-Stats
FilterID
X-Cache-TTL-Remaining
X-TX-ID
Accept-CH-Lifetime
X-L-Path
X-FireWall-Port
X-Environment-Context
X-CACHE-KEY
Cleartype
X-Handled-By
X-Upgrade-Enabled
Accept-Charset
X-B3-Traceid
X-Source
From-Origin
Ms-Operation-Id
X-Endurance-Cache-Level
X-RTag
Srv
X-Cache-Server
X-Analytics
X-Backend-Name
X-HTML-Minification-Powered-By
X-UUID
X-PressLabs-Stats
Datacenter
Healthy
X-UA
X-Wix-Request-Id
X-Daa-Tunnel
X-RN-RSRV
Meta-Geo
X-Dc
X-ES-SERVER
X-Status
X-Cache-Var
X-Cache-Var-Map
X-Path-Route
X-Tb
OT-Force-Account-Verify
X-Whom
X-Proxy-Build
X-Timing-Wait
Selected-Fe
Version
Mn-Server-Ip
X-Akamai-Transformed
X-Akamai-Request-ID
X-Content-Age
X-EIG-Tracking-Id
X-Shopify-Generated-Cart-Token
X-ShardId
X-Request-Time
X-Sorting-Hat-PodId
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Section
X-Format
X-Access
X-Sorting-Hat-ShopId
X-Proto
X-Shopify-Stage
X-ShopId
X-Cache-Config
X-Alternate-Cache-Key
X-LJ-Flow-ID
X-Web-Node
X-VWS-Id
X-Say-TTL
X-JoinUs
Cache-Tags
X-PCL
X-Qloud-Router
X-SaId
X-NYM-Debug-Backend
X-Proxy-Cache-Status
X-Vgn-Hpd-Reason
X-Say-Cacheable
X-SayCDN-TTL
X-Debug-Cache
Node
X-BYPASS-REASON
X-ProxyCache-Key
X-OCL
X-FC-Vary-Parameters
Ec-Rule-Version
Akamai-GRN
X-Hl-Ver
X-Soup
X-ProxyCache-Status
X-Human
X-AWS-Id
X-Yottaa-Optimizations
X-Unique-Id
X-Yottaa-Metrics
Origin-Cache-Control
Origin-Edge-Control
X-Viewer-Country
X-Www-Served-By
NGX
Decoy-Debug-Key
X-FB-TRIP-ID
Decoy-Debug-Status
Decoy-Debug-TTL
Now
X-TNCMS
X-Site-Version
X-Hosted-By
X-Detected-As
X-APP-VERSION
X-Generated
X-Hyper-Cache
X-Locale
X-BCube-Filmed-By
X-Redis-Cache
X-CCM
X-Loop
X-Storage
Cross-Origin-Window-Policy
X-ServerID
X-Origin
X-Akamai-Request-ID2
X-Varnish-Hits
X-Webapp-Samesite-None-Activated-N
X-Time-Microsecs
X-Proxy
X-Generated-By
X-Xfnlog-Site
X-FW-Dynamic
DB-Nickname
X-Ua-Device
X-Pubstack
X-RCS-CacheZone
X-R9-Blue-Green-Version
X-Origin-Hint
S-Rt
X-IP
X-NCache
TWC-Connection-Speed
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-GeoIP-Country
X-UA-Device-Type
TWC-Privacy
Webcakes-App-Name
TWC-Device-Class
Webcakes-Region
Webcakes-App-Version
Property-Id
Cache-Key
X-Amzn-Remapped-Content-Length
Azure-Version
Azure-SlotName
Azure-RegionName
Azure-InstanceId
X-MP-GENERATED-AT
Azure-SiteName
GEO-INFO
X-RateLimit-Limit
Section-Io-Cache
X-NGENIX-Cache
X-Cluster-Node
X-Backend-TTL
X-Drupal-Cache-Tags
X-Forwarded-Host
X-Mode
X-Cache-Host
X-Cache-Control
Webserver
X-CDN-Forward
X-Esi
Content-Disposition
L5d-Success-Class
X-Rule
Time
Cache
X-PERF
X-Varnish-Cache-Hits
X-UnsetCookies
Mime-Version
X-Newrelic-Synthetics
X-ApacheServer
X-Cache-Remote
ServedBy
X-Info
Cache-Name
Accept-Language
X-Origin-TTL
Viewport
X-Origin-CC
Rt-Fastcgi-Cache
X-Zipkin-Id
X-Routing-Service
X-CS
X-Proxied
Country
X-Device-Type
Odigeo-Trace-Id
Uber-Trace-Id
X-Via-Fastly
X-B3-Spanid
Filterid
X-EC-Lua
X-Magnolia-Registration
X-VCache
Geo-Info
X-Uri
X-From
X-CLOUD-TRACE-CONTEXT
Access-Control-Request-Headers
X-Real-IP
Proxy-Connection
Cf-Ipcountry
X-Cluster-Name
X-Geo
HitType
X-Drupal-Cache-Contexts
X-Microcachable
X-Labrador-Cache-Channel
X-PHP-Host
X-TT-TIMESTAMP
X-CF-Lambda-Version
X-Connection-Hash
X-Cache-Time
Mobile-Detection-Method
Viewtype
X-Destination
VIX-Pulpo-Node
Apple-News-Services-Handled
X-CF-Lambda-Fn
Machine
X-DPWN-IS-SECURE
X-Varnish-Beresp-Status
X-External-Request-Id
MD5-Digest
VIX-Pulpo-Upstream-Status
X-B-Cookie
X-GeoIP-Country-Code
GEO-REGION-INFO
Cache-Hits
X-Varnish-Beresp-Ttl
Meta-Geo-Continent
Group
X-Varnish-Beresp-Grace
X-VG-WebServer
X-Rewrite-Enabled
X-Request-UUID
X-Rocket-Build-Number
X-Rojux
X-S
X-A-Wwc
X-D
Content-Style-Type
X-Date
W
X-Region-Sid
X-S-Cookie
X-ScT
X-Sigma-Backend
Fastcgi-X-Cache-Version
X-SRCache-Key
X-Trv-Group
X-Sigma
X-Session-Fingerprint
X-A-Dgt
X-Twitter-Response-Tags
Rendered-Blocks
X-Transaction
X-Aed
Content-Script-Type
X-ARC
X-A-Ccd
Apple-News-Services-Request-Url
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
X-A
VivaBuild
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
T-Server
Xc-Version
X-A-Dcw
X-A-Dam
AsisCache
BehaviorPad-Version
X-Accel-Expires-Debug
X-VG-TLSProxy
X-Vdms-Version
X-G
X-Application
X-VG-WebCache
X-App-Version
User-Cache-Control
Ohc-File-Size
X-Eu-Site
X-CGP
Countrycode
Fastly-SWR
X-Distil-CS
CDCHOST
Environment
X-Clientip
X-CUA
X-Nc
X-Var-Ttl
X-Agile-Age
X-Thanos
Ha-Gx-Prefs
X-SIPLIST1
X-WebServer
Fastly-SIE
Powered-By
X-Agile-Id
X-Rebelmouse-Surrogate-Control
X-App-Name
X-VC-Cache
X-Backend-State
X-Bip
X-Agile
X-Hit
X-Geo-Header
HA-Ipaddr
IsBot
X-Cache-Expired-At
X-Logging-Id
X-Rebelmouse-Cache-Control
X-Cache-Debug
Locid
X-C
X-GoCache-CacheStatus
X-Core-Mission
X-Cache-Tags
X-Azure-Ref
We-Hiring
Web-Mar-Node
X-Air-Hostname
X-Origin-Date
X-Swa-Ws
X-Servername
X-TH-Server
X-Trace-Id
X-TrackingId
X-Request-URI
X-RateLimit-Remaining-Second
X-Owner
X-Platform-Server
X-Proxy-Upstream
X-RateLimit-Limit-Second
X-Up
X-Variation
X-Cdn-Srv
X-Developers
X-OVcl
X-OVcl-Cache
X-Auto-Login
Gh-Request-Id
X-VServer
X-Wikidot-Backend
X-Wikidot-Static-Cache
Fastly-Soc-X-Request-Id
X-Origin-Expires
X-NX-Host
X-Generated-In
X-GeoIP-City
X-Hash
X-Hnp-Log
X-Gen-Mode
X-Fetched-On
X-Debug-Log
X-Dispatcher-Server
X-Distributor
X-Epic-Correlation-Id
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Ms-Version
X-Nginx-Cache-Key
X-NodeID
X-NU-AKA-ACS-Version
X-Ms-Request-Id
X-LI-UUID
X-Instart-Isnd
X-Li-Fabric
X-Li-Pop
X-LI-Proto
X-Debug-Cookies
X-Block-Status
Request-EU
Is-Eu
RNT-Machine
RNT-Time
Request-Country
Kp-EeAlive
Mail-Subject
Platform
Pragrma
V-Age
IBM-Web2-Location
Server-ID
Adler-Geo
S-Cnection
True-Client-Country-4JS
Country-Code
Cache-Host
Fastly-Backend-Name
Server-Int
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Storage-Class
X-Edge-Location
X-Oss-Object-Type
X-Varnish-Authentication
AKAMAI
X-Req
X-Urbn-Site-Id
X-Service
X-Nginx-Cache
X-ServiceProvider
X-Urbn-Context-Path
X-Reboot
X-SVT-ORM-RULES
Ohc-Cache-HIT
ServerName
X-SVT-ORM-VERSION
X-Irp-Debug
X-Level-Front-Cache
X-No-Session
X-Micro-Cache
X-Matched-Rule
X-Thinkindot-L3
X-Trafficlayer-App-Name
X-Generated-On
X-Cms-Context
X-Webstats-RespID
X-Cache-ASPX
Cdncip
Server-Cache-Control
X-AK-Request-ID
Cdnsip
X-Contensis-Viewer-Groups
X-Gamma-Serve
X-TT-LOGID
X-Trafficlayer-App-Version
X-Trafficlayer-App-Scope
X-JWT-State
X-Is-Gdpr
X-We-Are-Hiring
X-Has-Esi
X-WADP-Cache
Server-Surrogate-Control
Locale
Thinkindot-CacheControl
PFcat
Memcached
Server-Host
Wxu-Next-Commit
Wxu-Next-Region
Wxu-Next-Hostname
X-Clara-WADP
X-Fastly-Cache
Thinkindot-CacheControl-Type
X-Core-Value
X-Cache-Info
X-Cache-URL
Heartbleed
FNAC-ModuleRouting
Thinkindot-Control
X-Cache-Bucket
X-BBXSRF
Fastly-SSL
X-Node-Id
X-Server-W
X-Debug-Cache-Store
X-Debug-Cache-Expiry
X-NC
X-FW-Version
X-Debug-Cache-Fetch
X-Response-By
X-Old-Content-Length
X-Tumblr-Pixel-3
X-Lb-Id
X-Generation-Time
X-Varnish-Cacheable
X-VHOST
X-Sucuri-ID
User-Agent
X-Refresh
RequestId
X-SERVER
X-Wa
X-CSRF-TOKEN
X-UPSTREAM-Address
Powered-By-ChinaCache
X-Developer
X-S-Maxage
Hostname
X-Cache-Status-Check
X-NWS-UUID-VERIFY
X-Parent-Response-Time
X-Device-Os
X-Sn-Servicetimems
X-LAGOON
X-Render-Time
X-Cdn-Origin
X-Cache-Grace
X-Cache-Backend
X-CF-Powered-By
X-Ua
X-Ocache
X-Tec-Api-Root
X-Pjax-Url
X-User
X-Tec-Api-Origin
X-Tec-Api-Version
Origin
X-Tb-Optimization-Total-Bytes-Saved
X-Internal-Host
X-Key
A
On-Server
X-Request-Host
Cloudfront-Viewer-Country
X-Sucuri-Cache
X-CSRF-Token
X-Location
Memory
X-MSEdge-Flight
X-TA-CDN-Provider
X-Via-CDN
X-MSEdge-Features
X-Pf-Uncompressing
SRV
Geoip-City
Geoip-Latitude
X-Dynatrace-Js-Agent
GeoIp-Country-Code
PICS-Label
X-NGINX-Cache
X-Varnish-URL
ProcessTime
X-COUNTRY
X-B3-Parentspanid
X-BACKEND-TTL
X-Cdn-Forward
Resin-Trace
TTL
X-Servedbyhost
X-Webkit-CSP
X-Litespeed-Cache
X-Vcl-Version
Cdn
X-HS-Status
X-Varnish-Ttl
X-Slack-Backend
Dnion-Transfer-Encoding
X-Server-IP
X-Unique-ID
X-Rocket-Nginx-Bypass
XServer
X-TIME
Pramga
X-B3-SpanId
Tcn
M-TraceId
Arc-Country
X-Cache-FS-Status
SN
X-Server-Time
X-Processor
X-PAYTM-SRV-ID
X-Dispatch
X-FORWARDED-FOR
Trailer
CACHE
X-Correlation-ID
X-DC
X-Skip-Cache
Section-Origin-Responded
X-Cdn-Request-ID
Section-Io-Id
X-ND-Cache
Section-Io-Origin-Time-Seconds
Media-Length
Section-Io-Origin-Status
Fusion-Deployment-Id
Host-ID
X-Ratelimit-Remaining
X-Edge-Server
X-Action
X-Served-From
X-Beluga-Trace
X-VCL-Version
X-ServedByHost
X-Beluga-Record
X-Cache-Ttl
X-Beluga-Node
X-Beluga-Status
Cdn-Host
Cdn-Request-Time
X-Beluga-Cache-Status
Fastly-Drupal-HTML
X-Beluga-Response-Time
HostName
X-DevSite-Last-Modified
GeoIP-Country-Code
X-Fastly-Country-Code
Ttl
Who
Pics-Label
X-DB
X-DI
X-RSL
X-RPM
X-RPS
X-DW
N-Cache
X-DSS
NtCoent-Length
X-Adobe-Source
X-Via-Ucdn
GeoIP-Latitude
GeoIP-City
X-Bc-Bl
CF-Cached-On
X-Reqid
X-Hello
X-Flog
X-PF-Uncompressing
X-ABtesting
X-Datadome
X-LiteSpeed-Cache-Control
MIME-Version
X-Oracle-Dms-Rid
X-AIR-PT
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
X-Varnish-Url
X-Zone
Cache-Cookie-Set-From
X-VarnishDD-TTL
X-Backend-Host
Esi-Enabled
X-Bc
X-Scheme
X-Fpc
X-Planisys-CDN-TTL
X-Sucuri-Id
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Ratelimit-Limit
X-APP
X-Policy
X-HostName
X-PJAX-URL
X-FPC
X-Request-Start
X-Fmm-Version
X-SRV
X-Fastly-Backend-Reqs
WebServer
X-Azure-Ref-OriginShield
Amp-Access-Control-Allow-Source-Origin
Rt-Proxy-Cache
X-BE
X-Amzn-Remapped-Connection
X-Dynatrace
X-Amzn-Remapped-Date
Sid
Lb
X-Esi-Check
X-SN
Cteonnt-Length
Processtime
X-Cache-Id
Servername
X-Cache-NGX
X-Newrelic-App-Data
X-Swift-Error
Load-Balancing
X-Gzip
X-BC
X-ZONE
X-SD-PageType
Magicmarker
SD-X-WS
Release
FSS-Proxy
FSS-Cache
X-WA
Cache-Provider
X-ID
X-WR-MODIFICATION
X-Frame-Option
X-VCT
X-Branch-Name
X-Snapshot-Date
X-Instart-Info
X-StackifyID
X-Method
CF-IPCountry
X-LB-ID
X-Wix-Viewer-Type
CDN
X-ECACHE
Dynatrace
Requestid
X-Configured-By
X-CACHE-AGE
X-GEO
X-Fastly-Cache-Hits
X-Compress-Hint
X-SB
L
X-Request-Url
WZWS-RAY
X-Cc-Via
X-Cc-Req-Id
X-Cache-PHP
X-Aicache-OS
V-Cache
Proxy-Firewall
D-Cc-Upstream
X-Tid
Warning
X-VC
Request-Time
X-Litespeed-Cache-Control
X-ElasticPress-Search
WP-Super-Cache
X-Be
X-Nananana
X-Request-URL
X-WPE-Loopback-Upstream-Addr
Cneonction
X-Check-Cacheable
X-Varnish-Beresp-TTL
Ohc-Response-Time
X-Fastly-Cache-Status
X-Powered-Y
X-Apw-Access-Object
X-Apw-Access-Token
X-Apw-Access-Action
X-App
X-Worker
X-Apw-Hits