Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-Powered-By
Pragma
CF-Cache-Status
Link
ETag
X-XSS-Protection
Expect-CT
CF-RAY
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
X-Xss-Protection
Alt-Svc
X-Timer
CF-Ray
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Request-ID
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-DNS-Prefetch-Control
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
Status
Upgrade
Content-Encoding
X-Content-Security-Policy
X-CDN
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
X-Pass-Why
X-Cache-Group
X-AH-Environment
X-Envoy-Upstream-Service-Time
X-Via
Xkey
X-Backend
X-Age
X-Server
Expect-Ct
X-Ws-Request-Id
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
EagleId
X-Page-Speed
X-Server-Powered-By
X-Pingback
X-Proxy-Cache
X-Hacker
X-Nginx-Cache-Status
Request-Context
Feature-Policy
Server-Timing
X-UA-Device
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Cf-Railgun
Ali-Swift-Global-Savetime
Grace
X-Amz-Version-Id
X-Ua-Compatible
Report-To
X-LiteSpeed-Cache
X-OneAgent-JS-Injection
X-Rq
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-WebKit-CSP
X-Device
X-Server-Id
X-Host
X-Origin-Cache
X-Response-Time
EagleEye-TraceId
X-Node
X-Ac
Surrogate-Control
Content-Location
X-Cloud-Trace-Context
X-Vhost
X-Backend-Server
X-Readtime
X-Dispatcher
Request-Id
X-Cache-Lookup
X-Ruxit-JS-Agent
X-Origin-Upstream-Status
X-Cnection
X-Application-Context
X-HW
Fusion-Template-Id
Fusion-Source
Fusion-Content-Source
Fusion-Content-Id
Fusion-Component-Id
X-ORACLE-DMS-ECID
X-Mod-Pagespeed
X-ORACLE-DMS-RID
NEL
X-DataDome
X-Rack-Cache
X-Country
X-Clacks-Overhead
Edge-Control
P3p
X-Akam-SW-Version
Rating
X-Dns-Prefetch-Control
Allow
Pinterest-Generated-By
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Accept-Ch
X-Country-Code
X-FTR-Request-ID
X-Instart-Request-ID
X-Varnish-TTL
X-TTL
X-DynaTrace
X-Vname
X-TtlSet
X-PC
X-Goog-Hash
Content-MD5
X-ESI
Verso
Accept-Ch-Lifetime
Service-Worker-Allowed
X-Url
X-Powered-By-Plesk
X-Vcache
X-B3-TraceId
X-GitHub-Request-Id
X-Exp-Id
X-GoogleNews-Bot
X-Exp-Variant
X-Kinja
X-Kinja-Build
X-Cdn-Fetch
X-Use-Magma
X-Kinja-Server
X-Kinja-Revision
X-Version
RTSS
X-Forwarded-Proto
X-MS-InvokeApp
X-Server-Name
X-D2id
X-Px
X-Abt-Application-Version
Edge-Cache-Tag
X-Debug
AR-ATIME
AR-CACHE
AR-Request-ID
AR-PoweredBy
Ar-Sid
X-Amz-Server-Side-Encryption
SPRequestGuid
X-Cached
Charset
X-NF-Request-ID
X-Vcap-Request-Id
X-Navigation-Version
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-MSEdge-Ref
X-Amz-Rid
X-Sol
Response
X-Middleton-Display
X-Middleton-Response
Pagespeed
Display
X-Accel-Expires
Arr-Disable-Session-Affinity
TCN
X-Fastcgi-Cache
X-Server-ID
X-SharePointHealthScore
X-VARITI-CCR
Pinterest-Version
X-Pinterest-Rid
X-Fastly-Request-ID
MS-Author-Via
Nginx-Cache
Public-Key-Pins
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Powered-CMS
X-Trace
X-Client-IP
X-Cdn
X-Edge-O15-RID
Realpath
Cache-Tag
X-Ser
Access-Control-Request-Method
X-Content-Type
Nel
Mrf-Cache-Status
MRF-Tech
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
X-B3-TraceId-Primal
SPIisLatency
X-Amzn-Trace-Id
SPRequestDuration
X-Upstream
X-Grace
X-Shard
X-Jurisdiction
X-Hp-Webp
X-Id
Front-End-Https
X-Ezoic-Cdn
X-Forwarded-For
X-Cache-TTL
S
X-Hits
X-Amz-Meta-S3cmd-Attrs
X-DynaTrace-JS-Agent
X-T
Fastcgi-Cache
X-Recruiting
DynaTrace
X-Aspnet-Version
X-Element-Page-Cache
X-Node-Name
X-Content-Digest
X-Dw-Request-Base-Id
X-Varnish-Age
X-FTR-Backend-Server
X-FTR-Expires
X-FTR-DC
X-FTR-Realm
X-FTR-Cache-Status
X-FTR-Backend
X-Mobile-URL
X-Country-Code-Real
X-FTR-Balancer
MicrosoftSharePointTeamServices
ServerID
X-DIS-Request-ID
Server-Node
NR-ENABLED
TP-L2-Cache
TP-Cache
X-HS-Combine-CSS
X-HS-Cache-Config
X-Frontend
X-HS-Content-Id
X-HS-Hub-Id
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Storage-Class
X-Goog-Generation
Powered
X-Logged-In
Alternate-Protocol
X-Correlation-Id
X-CST
Server-Name
X-Amz-Apigw-Id
X-Amzn-RequestId
Upgrade-Insecure-Requests
X-Cache-Hit
Fastly-Restarts
X-FTR-Cache-Host
X-Microsite
X-Request-Handler-Origin-Region
X-XRDS-Location
Backend-Timing
X-ATS-Timestamp
X-Page-Id
AMP-Access-Control-Allow-Source-Origin
X-Content-Options
X-User-Agent
X-Zen-Fury
X-F-Cache
X-Request-Processing-Time
X-Request-Received
X-Content-Security-Policy-Report-Only
Refresh
X-Origin-Server
X-Varnish-Grace
X-Akamai-Edgescape
X-Rid
X-XRDS-LOCATION
X-Revision
X-B
X-LB-Cache
PB-PID
X-Content-Powered-By
PB-RID
Arc-Version
X-Mobile-Rewrite
X-Type
X-B3-Sampled
Cache-Status
X-Geo-Country
X-Az
X-Activity-Id
X-AppVersion
X-Kinsta-Cache
X-NWS-LOG-UUID
X-N
X-Cache-Action
X-TT
X-Signature
X-Request-Guid
X-Jobs
X-Framework
X-B-Cache
X-WebKit-CSP-Report-Only
X-Debug-Info
Access-Control-Allow-Method
X-Time
Actual-Object-TTL
X-Cache-Age
X-Instance
X-PHP-Backend
X-FB-Debug
X-AOL-HN
X-Cached-By
X-Git-Hash
X-App-Environment
Paypal-Debug-Id
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Load-Cache
X-Tt-Trace-Host
Fastcgi-Useragent
X-Tt-Trace-Tag
X-URL
X-Amz-Replication-Status
DC
X-Pad
X-Varnish-Backend
X-Shield-Request-Id
X-RateLimit-Remaining
Host
Host-Header
X-Webkit-Csp
X-WA-Info
X-ATG-Version
X-ORACLE-APMCS-REQUEST-ID
X-ORACLE-APMCS-TAG
X-Via-JSL
MS-CV
X-Contextid
Surrogate-Key
X-IPLB-Instance
X-Mobile
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Host-Name
Retry-After
Frame-Options
X-Accel-Buffering
X-Response-Served-From
NGB
X-FastCGI-Cache
Payment
Liferay-Portal
Source
X-Hostname
X-Cache-NE
X-Srv
X-NewRelic-App-Data
X-Cache-2
X-SS-Set-Cookie
Xserver
X-Region
X-Varnish-Server
X-Origin-Response-Time
X-Seen-By
WPE-Backend
Filters
Tracecode
Eomportal-Instance
X-FW-Serve
X-IPS-LoggedIn
X-Is-Bot
X-Rendered-As
X-GeoIP
X-FW-Type
X-FW-Hash
X-FW-Static
X-Cacheable-TTL
X-FW-Server
X-Varnish-Hostname
X-Presslabs-Stats
Cache-Tv-Group
X-Cluster
X-Cache-Enabled
Server-Info
X-Cache-Rule
X-Adobe-Loc
X-RequestSource
X-Adobe-Content
X-Cache-Operation
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
X-App-Server
X-Cache-Key
X-RemovedCookies
X-ProcessESI
X-EdgeConnect-Cache-Status
X-Cache-TTL-Remaining
FilterID
X-TX-ID
X-CACHE-KEY
Cleartype
X-FireWall-Port
X-Environment-Context
X-L-Path
X-Analytics
Accept-CH
X-B3-Traceid
X-Handled-By
X-Upgrade-Enabled
X-RTag
Ms-Operation-Id
X-Source
X-Endurance-Cache-Level
Accept-Charset
X-Cache-Server
X-Backend-Name
X-HTML-Minification-Powered-By
X-Ttl
X-UA
From-Origin
X-Dc
Datacenter
X-Webapp-Samesite-None-Activated-N
Srv
X-UUID
Healthy
Accept-CH-Lifetime
X-APP-VERSION
X-Path-Route
X-Cache-Var-Map
X-Wix-Request-Id
X-Cache-Var
X-ES-SERVER
X-RN-RSRV
Meta-Geo
X-Daa-Tunnel
X-Access
X-Timing-Wait
X-Proxy-Build
X-Status
Selected-Fe
X-Section
OT-Force-Account-Verify
X-Sorting-Hat-ShopId
X-Request-Time
X-Tb
X-Shopify-Stage
X-OCL
X-PCL
X-Akamai-Transformed
X-Alternate-Cache-Key
X-Sorting-Hat-PodId
X-ShardId
X-PressLabs-Stats
X-Content-Age
X-Akamai-Request-ID
Mn-Server-Ip
Cache-Tags
X-Cache-Config
X-Goog-Meta-Goog-Reserved-File-Mtime
X-EIG-Tracking-Id
X-ShopId
X-Shopify-Generated-Cart-Token
X-FC-Vary-Parameters
X-Format
X-Soup
X-JoinUs
X-Yottaa-Optimizations
X-LJ-Flow-ID
X-Hl-Ver
Origin-Cache-Control
X-Yottaa-Metrics
X-BYPASS-REASON
X-Debug-Cache
X-Say-TTL
Ec-Rule-Version
X-Human
X-AWS-Id
X-SaId
Origin-Edge-Control
X-Akamai-Request-ID2
X-Unique-Id
X-Proxy-Cache-Status
X-Web-Node
X-Proto
X-ProxyCache-Status
X-Vgn-Hpd-Reason
Akamai-GRN
X-Qloud-Router
X-VWS-Id
X-ProxyCache-Key
X-SayCDN-TTL
X-NYM-Debug-Backend
X-Origin
X-Say-Cacheable
Cross-Origin-Window-Policy
X-Storage
X-Pubstack
GEO-INFO
X-Loop
X-ServerID
Decoy-Debug-TTL
X-CCM
NGX
X-Time-Microsecs
X-Whom
X-BCube-Filmed-By
Now
Decoy-Debug-Key
Node
Decoy-Debug-Status
X-MP-GENERATED-AT
X-Proxy
X-Generated-By
X-Generated
X-Site-Version
X-TNCMS
X-Www-Served-By
Version
X-Locale
X-FW-Dynamic
X-Redis-Cache
X-Hosted-By
X-Detected-As
X-Viewer-Country
X-FB-TRIP-ID
X-Hyper-Cache
DB-Nickname
Webcakes-App-Version
X-R9-Blue-Green-Version
X-RCS-CacheZone
Webcakes-Region
Azure-SlotName
X-Xfnlog-Site
X-Varnish-Hits
X-IP
Azure-RegionName
Azure-InstanceId
Webcakes-App-Name
X-Origin-Hint
Azure-SiteName
Azure-Version
TWC-Locale-Group
TWC-Connection-Speed
Property-Id
X-Ua-Device
TWC-Device-Class
S-Rt
TWC-Privacy
TWC-GeoIP-Country
TWC-GeoIP-LatLong
X-Amzn-Remapped-Content-Length
X-NCache
X-Cluster-Node
X-RateLimit-Limit
Cache-Key
X-UA-Device-Type
X-Cache-Control
X-Backend-TTL
Cache
X-Cache-Host
X-Mode
X-NGENIX-Cache
X-Drupal-Cache-Tags
Section-Io-Cache
X-Rule
Webserver
X-Forwarded-Host
X-Esi
X-CDN-Forward
L5d-Success-Class
Content-Disposition
Time
X-UnsetCookies
Mime-Version
X-Info
X-CS
Accept-Language
Viewport
X-Varnish-Cache-Hits
X-ApacheServer
X-PERF
ServedBy
Rt-Fastcgi-Cache
Cache-Name
X-Newrelic-Synthetics
X-Origin-CC
X-Origin-TTL
Country
Uber-Trace-Id
X-B3-Spanid
X-Cache-Remote
X-Proxied
X-Device-Type
Odigeo-Trace-Id
X-Zipkin-Id
X-Routing-Service
X-Via-Fastly
Filterid
X-Magnolia-Registration
X-VCache
X-Uri
Proxy-Connection
X-EC-Lua
X-CLOUD-TRACE-CONTEXT
X-From
X-Cluster-Name
X-Real-IP
X-Drupal-Cache-Contexts
Access-Control-Request-Headers
HitType
Cf-Ipcountry
X-Geo
X-Microcachable
Geo-Info
X-TT-TIMESTAMP
X-Nc
X-External-Request-Id
X-Rojux
X-Rocket-Build-Number
Apple-News-Services-Request-Url
X-Rewrite-Enabled
X-Application
X-ARC
X-Varnish-Beresp-Status
X-S
X-B-Cookie
BehaviorPad-Version
T-Server
X-ScT
X-S-Cookie
AsisCache
X-Request-UUID
Group
X-Varnish-Beresp-Ttl
Apple-News-Services-Host
X-A-Dam
VivaBuild
X-Cache-Time
X-A-Dcw
X-A-Ccd
X-A
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-G
X-A-Dgt
X-Labrador-Cache-Channel
X-Geo-Header
X-Region-Sid
Apple-News-Services-Handled
W
Viewtype
X-Aed
X-A-Wwc
X-PHP-Host
X-Accel-Expires-Debug
Apple-News-Services-Parsed-Url
X-Varnish-Beresp-Grace
X-Twitter-Response-Tags
MD5-Digest
X-Connection-Hash
Content-Script-Type
X-CF-Lambda-Version
Fastcgi-X-Cache-Version
X-Vdms-Version
GEO-REGION-INFO
Machine
X-D
X-Date
X-Transaction
X-Trv-Group
Ohc-File-Size
Rendered-Blocks
X-SRCache-Key
X-VG-WebCache
Meta-Geo-Continent
X-Vtex-Remote-Cache
Xc-Version
Mobile-Detection-Method
Content-Style-Type
X-Destination
X-GeoIP-Country-Code
X-Session-Fingerprint
X-VG-WebServer
X-DPWN-IS-SECURE
X-CF-Lambda-Fn
X-Sigma-Backend
X-Vtex-Processado-Em
X-Sigma
User-Cache-Control
Cache-Hits
X-C
Locid
Fastly-SIE
X-Logging-Id
CDCHOST
Countrycode
Fastly-Soc-X-Request-Id
Fastly-SWR
X-Hit
HA-Ipaddr
Ha-Gx-Prefs
Powered-By
X-Agile
X-Cache-Debug
X-Cache-Expired-At
X-Bip
X-Backend-State
X-Eu-Site
X-VG-TLSProxy
X-CGP
X-Distil-CS
X-Var-Ttl
X-TrackingId
X-Thanos
X-Clientip
X-App-Name
X-WebServer
X-Rebelmouse-Surrogate-Control
X-Agile-Age
X-Developers
X-Rebelmouse-Cache-Control
X-Agile-Id
X-GoCache-CacheStatus
X-CUA
X-Hash
X-Distributor
Request-EU
Pragrma
X-Core-Mission
Request-Country
X-Gen-Mode
X-Dispatcher-Server
X-IN-APIGATEWAYSSL
X-Debug-Cookies
X-Debug-Log
X-IN-APIGATEWAY
Web-Mar-Node
Platform
X-Generated-In
X-Hnp-Log
RNT-Machine
X-Cms-Context
V-Age
Server-Surrogate-Control
Server-Int
X-Epic-Correlation-Id
X-GeoIP-City
X-Air-Hostname
X-Auto-Login
True-Client-Country-4JS
X-Block-Status
X-Cache-ASPX
X-Fetched-On
X-Has-Esi
X-Contensis-Viewer-Groups
Server-Cache-Control
X-Cache-Tags
X-Instart-Isnd
We-Hiring
Server-ID
RNT-Time
Country-Code
X-OVcl
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Is-Gdpr
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Proxy-Upstream
X-Platform-Server
X-NX-Host
X-OVcl-Cache
X-Origin-Date
X-Origin-Expires
X-Owner
X-Request-URI
X-Servername
X-TH-Server
X-Swa-Ws
X-Trace-Id
X-Up
X-Urbn-Site-Id
X-Urbn-Context-Path
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-SIPLIST1
X-VServer
X-VC-Cache
X-Varnish-Authentication
X-Variation
X-NU-AKA-ACS-Version
X-Cdn-Srv
X-Li-Fabric
Kp-EeAlive
X-Li-Pop
Fastly-Backend-Name
Environment
X-LI-UUID
IsBot
Gh-Request-Id
Heartbleed
IBM-Web2-Location
Is-Eu
X-Ms-Request-Id
X-LI-Proto
Mail-Subject
X-Nginx-Cache-Key
X-No-Session
X-NodeID
X-JWT-State
Adler-Geo
AKAMAI
Cache-Host
X-Ms-Version
Locale
Ohc-Cache-HIT
X-Edge-Location
Fastly-SSL
X-Level-Front-Cache
X-Trafficlayer-App-Version
X-TT-LOGID
X-Tumblr-Pixel-3
X-ServiceProvider
X-Trafficlayer-App-Scope
X-Trafficlayer-App-Name
X-Thinkindot-L3
X-Cache-Info
X-Reboot
X-We-Are-Hiring
X-Req
X-FW-Version
X-Webstats-RespID
X-Matched-Rule
X-Gamma-Serve
X-Generated-On
X-Generation-Time
X-WADP-Cache
X-Micro-Cache
X-Cache-Bucket
X-BBXSRF
Memcached
X-Server-W
X-Cache-URL
X-Irp-Debug
X-Fastly-Cache
X-Clara-WADP
X-Service
X-Debug-Cache-Fetch
X-App-Version
Server-Host
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
PFcat
ServerName
FNAC-ModuleRouting
Cdnsip
Cdncip
S-Cnection
Wxu-Next-Commit
Thinkindot-Control
X-AK-Request-ID
X-Azure-Ref
X-Debug-Cache-Store
Wxu-Next-Region
X-Debug-Cache-Expiry
X-Core-Value
Wxu-Next-Hostname
X-Old-Content-Length
X-Response-By
X-S-Maxage
X-Lb-Id
X-Oss-Storage-Class
X-Nginx-Cache
X-VHOST
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
X-UPSTREAM-Address
X-Oss-Object-Type
X-Node-Id
X-SERVER
X-Varnish-Cacheable
X-Wa
X-Refresh
RequestId
X-Sucuri-ID
User-Agent
X-NWS-UUID-VERIFY
Powered-By-ChinaCache
X-NC
X-Render-Time
X-Cache-Backend
X-CSRF-TOKEN
X-User
X-Cache-Status-Check
X-Developer
X-Parent-Response-Time
X-Device-Os
Origin
X-Key
X-CF-Powered-By
X-LAGOON
X-Internal-Host
X-Tec-Api-Version
X-Pjax-Url
X-Tec-Api-Origin
X-Tec-Api-Root
Hostname
X-Sucuri-Cache
X-Ua
X-CSRF-Token
SRV
X-Sn-Servicetimems
X-Cache-Grace
X-Cdn-Origin
X-Ocache
On-Server
X-Pf-Uncompressing
X-Tb-Optimization-Total-Bytes-Saved
A
X-Location
Geoip-Latitude
X-Via-CDN
Memory
Cloudfront-Viewer-Country
Geoip-City
X-TA-CDN-Provider
X-MSEdge-Flight
X-MSEdge-Features
X-Request-Host
X-NGINX-Cache
GeoIp-Country-Code
PICS-Label
ProcessTime
X-B3-Parentspanid
X-BACKEND-TTL
X-COUNTRY
X-Cdn-Forward
TTL
X-Vcl-Version
X-Varnish-URL
Resin-Trace
M-TraceId
X-Server-IP
X-Litespeed-Cache
X-Webkit-CSP
X-Servedbyhost
Dnion-Transfer-Encoding
X-HS-Status
X-Rocket-Nginx-Bypass
X-Varnish-Ttl
X-Unique-ID
XServer
X-TIME
X-B3-SpanId
Media-Length
X-Slack-Backend
SN
X-Cdn-Request-ID
Cdn
Tcn
X-Dynatrace-Js-Agent
X-FORWARDED-FOR
X-Correlation-ID
X-PAYTM-SRV-ID
X-Processor
X-ServedByHost
X-Dispatch
Host-ID
HostName
Arc-Country
X-Cache-FS-Status
Pramga
X-Server-Time
X-Ratelimit-Remaining
CACHE
X-Beluga-Status
X-Beluga-Cache-Status
X-Fastly-Country-Code
Who
X-Skip-Cache
X-Action
X-Cache-Ttl
X-Beluga-Node
X-Beluga-Trace
X-Beluga-Record
X-Beluga-Response-Time
X-ND-Cache
Section-Io-Id
Section-Io-Origin-Status
X-DC
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
X-DSS
Cdn-Request-Time
X-Edge-Server
X-DB
X-RSL
X-DI
X-DW
X-VCL-Version
X-Served-From
X-Via-Ucdn
Fastly-Drupal-HTML
X-RPS
X-RPM
Cdn-Host
Fusion-Deployment-Id
GeoIP-Country-Code
Ttl
X-DevSite-Last-Modified
X-Reqid
Pics-Label
N-Cache
Esi-Enabled
X-Varnish-Url
GeoIP-City
X-Bc-Bl
Amp-Access-Control-Allow-Source-Origin
GeoIP-Latitude
X-AIR-PT
X-Flog
X-Hello
X-ABtesting
NtCoent-Length
MIME-Version
X-LiteSpeed-Cache-Control
X-Adobe-Source
X-Oracle-Dms-Rid
X-Sucuri-Id
X-PF-Uncompressing
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
X-VarnishDD-TTL
X-Policy
X-Backend-Host
X-Planisys-CDN-Rules
CF-Cached-On
X-APP
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-From
X-Request-Start
X-Azure-Ref-OriginShield
X-Ratelimit-Limit
X-FPC
X-Ruxit-Js-Agent
Trailer
X-HostName
WebServer
X-Zone
X-Fastly-Backend-Reqs
X-SRV
X-Scheme
Rt-Proxy-Cache
X-PJAX-URL
X-Fmm-Version
X-Bc
Cteonnt-Length
X-BC
X-BE
X-ZONE
X-Dynatrace
X-Amzn-Remapped-Date
X-Fpc
Processtime
X-Amzn-Remapped-Connection
Servername
X-Newrelic-App-Data
X-Swift-Error
X-Cache-Id
X-WA
X-Esi-Check
X-Method
X-SN
X-ID
Magicmarker
Cache-Provider
FSS-Proxy
FSS-Cache
X-WR-MODIFICATION
X-Frame-Option
X-Gzip
X-Cache-NGX
X-SD-PageType
Release
X-Snapshot-Date
Requestid
Lb
X-StackifyID
Sid
Load-Balancing
SD-X-WS
CF-IPCountry
X-Branch-Name
CDN
Dynatrace
X-LB-ID
X-CACHE-AGE
X-Compress-Hint
L
X-Tid
V-Cache
WZWS-RAY
Ohc-Response-Time
X-Request-Url
D-Cc-Upstream
Warning
X-Configured-By
X-SB
X-VC
X-Cc-Req-Id
X-Cc-Via
X-Instart-Info
X-VCT
X-Fastly-Cache-Hits
X-Aicache-OS
X-Litespeed-Cache-Control
Proxy-Firewall
LB
X-ECACHE
Request-Time
X-Nananana
Inserted-Into-Cache-At
SID
X-Wix-Viewer-Type
X-Svr
X-Apw-Access-Token
X-Apw-Hits
WP-Super-Cache
X-Apw-Access-Object
X-Apw-Access-Action
X-Be
X-Worker
X-ElasticPress-Search
X-Powered-Y
X-WPE-Loopback-Upstream-Addr
Cneonction
X-App
X-Fastly-Cache-Status
X-Varnish-Beresp-TTL
X-Request-URL
X-Check-Cacheable
X-GEO