Threat Level: green Handler on Duty: Russell Eubanks

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
CF-RAY
Link
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-Request-ID
X-DNS-Prefetch-Control
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
Status
Upgrade
X-Content-Security-Policy
Content-Encoding
X-CDN
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Xss-Protection
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
X-Pass-Why
X-Cache-Group
X-AH-Environment
Xkey
X-Envoy-Upstream-Service-Time
X-Via
X-Backend
CF-Ray
X-Server
X-Age
X-Ua-Compatible
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Ws-Request-Id
X-Server-Powered-By
X-Page-Speed
X-Pingback
EagleId
X-Proxy-Cache
X-Hacker
X-UA-Device
X-Nginx-Cache-Status
Request-Context
Feature-Policy
X-Varnish-Cache
Server-Timing
Cf-Railgun
P3p
X-Swift-CacheTime
X-Swift-SaveTime
Grace
Ali-Swift-Global-Savetime
X-Amz-Version-Id
Report-To
X-LiteSpeed-Cache
X-Rq
X-OneAgent-JS-Injection
X-Pantheon-Styx-Hostname
X-WebKit-CSP
X-Styx-Req-Id
X-Device
X-Host
X-Server-Id
X-Origin-Cache
X-Response-Time
EagleEye-TraceId
X-Node
X-Ac
Surrogate-Control
Content-Location
X-Readtime
X-Backend-Server
X-Cloud-Trace-Context
X-Vhost
Request-Id
X-Dispatcher
X-Origin-Upstream-Status
X-Cnection
X-Application-Context
X-Cache-Lookup
X-HW
X-Ruxit-JS-Agent
Fusion-Template-Id
Fusion-Source
Fusion-Content-Source
Fusion-Component-Id
Fusion-Content-Id
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
X-Mod-Pagespeed
X-DataDome
NEL
X-Rack-Cache
Rating
X-Country
Edge-Control
X-Clacks-Overhead
X-Akam-SW-Version
X-Dns-Prefetch-Control
Pinterest-Generated-By
X-TTL
Allow
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Country-Code
Accept-Ch
X-FTR-Request-ID
X-DynaTrace
X-Instart-Request-ID
X-Varnish-TTL
X-Goog-Hash
X-PC
X-TtlSet
X-Vname
X-ESI
Verso
Accept-Ch-Lifetime
Content-MD5
Service-Worker-Allowed
X-Powered-By-Plesk
X-Url
X-B3-TraceId
X-Forwarded-Proto
X-Version
X-GitHub-Request-Id
X-MS-InvokeApp
X-Use-Magma
X-Kinja-Revision
X-Kinja-Server
X-Kinja
X-GoogleNews-Bot
X-Cdn-Fetch
X-Exp-Id
X-Exp-Variant
X-Kinja-Build
RTSS
X-Vcache
X-Server-Name
Edge-Cache-Tag
X-D2id
X-Abt-Application-Version
X-Debug
X-Px
AR-Request-ID
Ar-Sid
AR-ATIME
AR-PoweredBy
AR-CACHE
X-Amz-Server-Side-Encryption
SPRequestGuid
Charset
X-NF-Request-ID
X-Cached
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Fastcgi-Cache
Response
X-Middleton-Display
Pagespeed
X-Sol
Display
X-Middleton-Response
X-Vcap-Request-Id
X-MSEdge-Ref
X-Accel-Expires
X-Navigation-Version
X-Amz-Rid
Arr-Disable-Session-Affinity
X-Pinterest-Rid
Pinterest-Version
TCN
X-Server-ID
X-SharePointHealthScore
X-Powered-CMS
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-VARITI-CCR
X-Edge-O15-RID
Public-Key-Pins
X-Fastly-Request-ID
X-Trace
Cache-Tag
Realpath
X-Client-IP
X-Cdn
MS-Author-Via
Nginx-Cache
X-Ser
Access-Control-Request-Method
Nel
X-Shard
X-DynaTrace-JS-Agent
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
MRF-Tech
X-Content-Type
SPIisLatency
SPRequestDuration
X-Amzn-Trace-Id
X-Ezoic-Cdn
X-Id
S
X-Upstream
X-Grace
X-Hp-Webp
X-Forwarded-For
X-T
X-Amz-Meta-S3cmd-Attrs
X-Jurisdiction
Front-End-Https
X-Hits
Fastcgi-Cache
X-Recruiting
DynaTrace
X-Cache-TTL
X-Aspnet-Version
X-Varnish-Age
ServerID
X-Element-Page-Cache
X-Content-Digest
X-Node-Name
MicrosoftSharePointTeamServices
X-Mobile-URL
X-FTR-Balancer
X-FTR-DC
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Realm
X-Country-Code-Real
X-FTR-Expires
X-FTR-Cache-Status
X-DIS-Request-ID
X-Dw-Request-Base-Id
Server-Node
NR-ENABLED
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Combine-CSS
Powered
X-Frontend
X-Goog-Storage-Class
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Goog-Generation
X-Goog-Stored-Content-Encoding
TP-L2-Cache
TP-Cache
X-Logged-In
Alternate-Protocol
Server-Name
X-CST
X-Amz-Apigw-Id
X-Amzn-RequestId
AMP-Access-Control-Allow-Source-Origin
Upgrade-Insecure-Requests
X-Request-Processing-Time
X-Request-Received
X-Correlation-Id
X-Cache-Hit
X-Request-Handler-Origin-Region
X-Microsite
X-ATS-Timestamp
Backend-Timing
Fastly-Restarts
X-XRDS-Location
X-Content-Options
X-F-Cache
X-Content-Security-Policy-Report-Only
X-User-Agent
X-Origin-Server
Refresh
X-Rid
X-Zen-Fury
X-Page-Id
X-Akamai-Edgescape
X-Revision
X-Varnish-Grace
X-XRDS-LOCATION
X-FTR-Cache-Host
X-Type
X-Content-Powered-By
X-LB-Cache
X-B
PB-RID
PB-PID
X-B3-Sampled
X-Mobile-Rewrite
Arc-Version
X-Geo-Country
X-AppVersion
X-Activity-Id
X-Az
Cache-Status
X-URL
X-Kinsta-Cache
X-N
X-Cache-Age
X-TT
X-Cache-Action
X-Instance
X-WebKit-CSP-Report-Only
X-Signature
X-B-Cache
X-AOL-HN
X-Time
X-Tumblr-User
X-Tumblr-Pixel-0
X-Tumblr-Pixel
Access-Control-Allow-Method
X-Debug-Info
Paypal-Debug-Id
X-Jobs
X-Framework
Actual-Object-TTL
X-App-Environment
X-FB-Debug
X-Request-Guid
X-Cached-By
X-Shield-Request-Id
X-PHP-Backend
X-Load-Cache
X-Git-Hash
X-Pad
Fastcgi-Useragent
DC
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Amz-Replication-Status
X-RateLimit-Remaining
X-Varnish-Backend
Surrogate-Key
X-Webkit-Csp
Host-Header
X-IPLB-Instance
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-ATG-Version
X-Contextid
MS-CV
X-NWS-LOG-UUID
X-WA-Info
Host
X-ORACLE-APMCS-REQUEST-ID
X-ORACLE-APMCS-TAG
X-SS-Set-Cookie
X-Mobile
X-Via-JSL
X-Kong-Upstream-Latency
X-Webapp-Samesite-None-Activated-N
X-Kong-Proxy-Latency
NGB
X-Host-Name
X-Response-Served-From
Tracecode
X-Analytics
X-Accel-Buffering
FilterID
X-Cluster
Payment
Frame-Options
Xserver
X-Cache-NE
X-FW-Hash
X-FW-Serve
X-Region
X-FW-Type
X-Origin-Response-Time
X-FW-Static
X-FW-Server
Eomportal-Instance
WPE-Backend
X-Cache-2
Source
X-Varnish-Server
Filters
X-Varnish-Hostname
X-Tumblr-Pixel-2
X-GeoIP
Cache-Tv-Group
X-IPS-LoggedIn
X-Tumblr-Pixel-1
X-Srv
X-Adobe-Loc
X-Cache-Enabled
X-Cacheable-TTL
X-Hostname
X-Adobe-Content
X-Presslabs-Stats
Retry-After
X-Cache-Rule
X-Cache-Operation
X-Is-Bot
X-Seen-By
X-EdgeConnect-Cache-Status
X-Rendered-As
X-RequestSource
X-NewRelic-App-Data
X-Cache-Key
X-TX-ID
Server-Info
Liferay-Portal
X-ProcessESI
X-RemovedCookies
X-Cache-TTL-Remaining
Cleartype
X-FastCGI-Cache
X-App-Server
X-CACHE-KEY
X-Dc
Accept-CH
X-L-Path
X-Environment-Context
X-RTag
X-B3-Traceid
X-FireWall-Port
Ms-Operation-Id
X-Source
X-Endurance-Cache-Level
X-Handled-By
X-Upgrade-Enabled
X-Cache-Server
X-HTML-Minification-Powered-By
Datacenter
From-Origin
X-UA
X-Backend-Name
Accept-Charset
X-CLOUD-TRACE-CONTEXT
X-VCache
Accept-CH-Lifetime
X-APP-VERSION
X-UUID
Meta-Geo
X-Wix-Request-Id
X-Cache-Var
X-Cache-Var-Map
X-RN-RSRV
X-PressLabs-Stats
X-ES-SERVER
Srv
X-Path-Route
X-Cache-Control
X-Section
Selected-Fe
Cache
OT-Force-Account-Verify
X-Timing-Wait
X-Format
X-Access
X-Tb
X-Proxy-Build
X-OCL
X-Request-Time
X-Akamai-Request-ID
Version
Azure-Version
X-Origin
Azure-InstanceId
X-Proto
Akamai-GRN
Azure-RegionName
Azure-SiteName
Healthy
Cache-Tags
Azure-SlotName
Mn-Server-Ip
X-Status
X-ShardId
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Alternate-Cache-Key
X-FC-Vary-Parameters
X-EIG-Tracking-Id
X-PCL
X-Cache-Config
X-Content-Age
X-Shopify-Generated-Cart-Token
X-ShopId
X-Sorting-Hat-PodId
X-NYM-Debug-Backend
X-Shopify-Stage
X-Sorting-Hat-ShopId
X-ServerID
X-ProxyCache-Key
X-LJ-Flow-ID
X-FW-Dynamic
DB-Nickname
X-Hl-Ver
X-AWS-Id
X-Cluster-Node
X-Time-Microsecs
X-SaId
X-Proxy
Decoy-Debug-Key
X-BYPASS-REASON
X-Proxy-Cache-Status
Decoy-Debug-Status
X-Qloud-Router
Origin-Edge-Control
Origin-Cache-Control
X-Hosted-By
X-Hyper-Cache
X-JoinUs
X-VWS-Id
Now
Node
X-ProxyCache-Status
Ec-Rule-Version
X-Vgn-Hpd-Reason
X-Pubstack
X-Soup
NGX
X-Akamai-Request-ID2
X-Viewer-Country
Decoy-Debug-TTL
X-Yottaa-Metrics
X-Yottaa-Optimizations
GEO-INFO
TWC-Device-Class
X-Debug-Cache
TWC-GeoIP-Country
TWC-Locale-Group
TWC-GeoIP-LatLong
Cross-Origin-Window-Policy
X-Redis-Cache
Property-Id
X-Origin-Hint
X-CCM
X-Amzn-Remapped-Content-Length
TWC-Connection-Speed
X-Loop
X-BCube-Filmed-By
TWC-Privacy
Webcakes-Region
X-Web-Node
X-Www-Served-By
X-Generated-By
X-Varnish-Hits
X-TNCMS
X-Storage
X-Human
Webcakes-App-Version
X-FB-TRIP-ID
X-RateLimit-Limit
Webcakes-App-Name
X-Say-Cacheable
X-SayCDN-TTL
X-Say-TTL
X-MP-GENERATED-AT
S-Rt
X-Locale
X-RCS-CacheZone
X-Akamai-Transformed
X-NCache
X-R9-Blue-Green-Version
X-Generated
X-Site-Version
X-Xfnlog-Site
X-Rule
X-Cache-Host
X-Detected-As
X-IP
X-Unique-Id
Cache-Key
L5d-Success-Class
X-Drupal-Cache-Tags
Webserver
X-CS
X-Whom
Cache-Name
Time
X-Esi
X-UA-Device-Type
Viewport
Uber-Trace-Id
X-Forwarded-Host
X-Daa-Tunnel
X-Mode
X-UnsetCookies
X-NGENIX-Cache
Mime-Version
X-VHOST
X-Info
X-Origin-CC
X-Origin-TTL
Rt-Fastcgi-Cache
Content-Disposition
X-Backend-TTL
Accept-Language
X-Varnish-Cache-Hits
Country
X-ApacheServer
X-B3-Spanid
Section-Io-Cache
X-PERF
X-Cache-Remote
X-CDN-Forward
ServedBy
X-From
Odigeo-Trace-Id
X-Newrelic-Synthetics
X-Cluster-Name
X-Magnolia-Registration
X-Zipkin-Id
X-Routing-Service
X-Device-Type
X-Proxied
X-Drupal-Cache-Contexts
VIX-Pulpo-Node
X-Geo
X-Microcachable
X-Via-Fastly
VIX-Pulpo-Upstream-Status
X-TT-TIMESTAMP
Proxy-Connection
X-Uri
X-EC-Lua
X-Nc
X-Ttl
Cf-Ipcountry
Ohc-File-Size
Access-Control-Request-Headers
HitType
Machine
GEO-REGION-INFO
Fastcgi-X-Cache-Version
X-Application
BehaviorPad-Version
X-ARC
Content-Style-Type
AsisCache
Apple-News-Services-Request-Url
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
X-Varnish-Beresp-Status
X-A-Ccd
X-A-Dam
X-A-Dcw
T-Server
X-A
VivaBuild
Viewtype
W
X-A-Dgt
X-A-Wwc
X-Aed
Mobile-Detection-Method
Meta-Geo-Continent
X-Varnish-Beresp-Grace
Rendered-Blocks
X-Accel-Expires-Debug
X-Varnish-Beresp-Ttl
MD5-Digest
X-External-Request-Id
X-B-Cookie
X-S
X-ScT
X-Session-Fingerprint
X-Sigma
X-Rojux
X-Rocket-Build-Number
X-Region-Sid
Geo-Info
X-Request-UUID
X-Rewrite-Enabled
X-Sigma-Backend
X-SRCache-Key
X-VG-WebServer
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-VG-WebCache
X-VG-TLSProxy
X-Transaction
X-Trv-Group
X-Twitter-Response-Tags
X-Vdms-Version
X-GeoIP-Country-Code
X-S-Cookie
X-Destination
X-Geo-Header
X-Date
X-D
X-Connection-Hash
X-CF-Lambda-Fn
Content-Script-Type
X-DPWN-IS-SECURE
X-CF-Lambda-Version
X-G
X-C
X-Real-IP
X-No-Session
X-Edge-Location
IsBot
Gh-Request-Id
HA-Ipaddr
X-App-Name
X-Agile-Age
Ha-Gx-Prefs
Fastly-SWR
Countrycode
X-WebServer
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Auto-Login
X-Bip
X-Cache-ASPX
Fastly-SIE
Environment
Locid
X-Cache-Debug
Fastly-Soc-X-Request-Id
X-Clientip
X-Distil-CS
X-Developers
X-Agile
X-CUA
X-Eu-Site
X-Rebelmouse-Surrogate-Control
X-Hit
X-Logging-Id
X-Rebelmouse-Cache-Control
X-Contensis-Viewer-Groups
Server-Surrogate-Control
X-CGP
X-Tumblr-Pixel-3
X-Varnish-Authentication
Powered-By
X-TrackingId
X-SIPLIST1
Server-Cache-Control
X-Thanos
X-VC-Cache
X-Agile-Id
CDCHOST
X-Cache-Time
Ohc-Cache-HIT
User-Cache-Control
Fastly-SSL
Filterid
X-GoCache-CacheStatus
X-UPSTREAM-Address
X-Instart-Isnd
X-GeoIP-City
We-Hiring
X-Generation-Time
X-Has-Esi
X-Irp-Debug
X-Hash
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-We-Are-Hiring
X-JWT-State
X-WADP-Cache
X-LI-UUID
Server-Int
Server-ID
X-Clara-WADP
X-LI-Proto
X-Li-Pop
X-Labrador-Cache-Channel
V-Age
X-Li-Fabric
True-Client-Country-4JS
X-Is-Gdpr
X-Air-Hostname
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-Debug-Cache-Store
X-Debug-Cookies
X-Debug-Log
X-Cache-Info
X-Cache-Tags
X-Up
X-Cms-Context
X-Cdn-Srv
X-Core-Mission
X-Cache-URL
X-Dispatcher-Server
X-BBXSRF
X-FW-Version
X-AK-Request-ID
X-Ms-Request-Id
X-Webstats-RespID
X-Gamma-Serve
X-Fetched-On
X-Fastly-Cache
X-Backend-State
X-Distributor
X-Epic-Correlation-Id
X-Azure-Ref
X-Generated-In
X-Micro-Cache
X-Request-URI
Adler-Geo
Locale
X-Server-W
X-Ms-Version
X-Urbn-Site-Id
X-Trace-Id
X-RateLimit-Remaining-Second
X-Urbn-Context-Path
Mail-Subject
Kp-EeAlive
X-Servername
X-SVT-ORM-VERSION
X-Swa-Ws
X-TH-Server
X-Variation
X-SVT-ORM-RULES
X-TT-LOGID
Is-Eu
IBM-Web2-Location
Heartbleed
AKAMAI
Memcached
Request-EU
Request-Country
Cache-Host
X-NX-Host
Cdnsip
Cdncip
RNT-Time
RNT-Machine
X-Nginx-Cache-Key
X-NodeID
X-RateLimit-Limit-Second
X-Origin-Date
Country-Code
X-Platform-Server
X-VServer
X-Owner
X-Proxy-Upstream
X-OVcl-Cache
X-Origin-Expires
X-OVcl
Platform
X-PHP-Host
X-Trafficlayer-App-Scope
X-Trafficlayer-App-Name
X-Core-Value
X-Trafficlayer-App-Version
X-Generated-On
X-Level-Front-Cache
X-Hnp-Log
X-NU-AKA-ACS-Version
X-App-Version
X-Matched-Rule
X-Reboot
X-Render-Time
X-ServiceProvider
X-Service
X-Gen-Mode
X-Req
X-Thinkindot-L3
X-Cache-Expired-At
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
ServerName
Server-Host
X-Var-Ttl
Thinkindot-Control
Web-Mar-Node
Group
Wxu-Next-Region
Wxu-Next-Hostname
Wxu-Next-Commit
X-Block-Status
PFcat
Fastly-Backend-Name
X-Cache-Bucket
FNAC-ModuleRouting
X-Cache-Backend
X-Lb-Id
Pragrma
X-TA-CDN-Provider
X-Old-Content-Length
X-User
Cache-Hits
S-Cnection
X-S-Maxage
X-Nginx-Cache
X-Refresh
X-SERVER
X-Internal-Host
X-Response-By
RequestId
X-Key
Powered-By-ChinaCache
X-Sucuri-Cache
X-Location
X-CSRF-TOKEN
X-Ruxit-Js-Agent
X-Wa
X-Ua
X-Sucuri-ID
X-NC
X-Tb-Optimization-Total-Bytes-Saved
X-Tec-Api-Root
X-Pjax-Url
Origin
X-Varnish-Cacheable
X-Cdn-Forward
X-Tec-Api-Origin
X-Parent-Response-Time
X-Tec-Api-Version
X-BACKEND-TTL
X-Correlation-ID
X-CF-Powered-By
User-Agent
X-CSRF-Token
SRV
ProcessTime
X-B3-Parentspanid
X-Pf-Uncompressing
X-Developer
Memory
TTL
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Object-Type
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
X-Sn-Servicetimems
X-Vcl-Version
X-Cdn-Origin
X-NWS-UUID-VERIFY
X-Ocache
X-Device-Os
X-LAGOON
Geoip-Latitude
X-Via-CDN
X-Node-Id
X-Cache-Grace
Geoip-City
X-Cache-Status-Check
X-Unique-ID
X-NGINX-Cache
X-Server-IP
PICS-Label
GeoIp-Country-Code
On-Server
X-B3-SpanId
X-MSEdge-Flight
X-MSEdge-Features
X-COUNTRY
A
Hostname
Cloudfront-Viewer-Country
X-Request-Host
X-Servedbyhost
X-Cdn-Request-ID
X-Litespeed-Cache
Media-Length
X-Webkit-CSP
Dnion-Transfer-Encoding
X-Varnish-Ttl
Cdn
X-Rocket-Nginx-Bypass
X-TIME
XServer
X-Via-Ucdn
Resin-Trace
SN
M-TraceId
Tcn
X-FORWARDED-FOR
X-ServedByHost
Host-ID
X-Sucuri-Id
X-HS-Status
X-Varnish-URL
HostName
X-Ratelimit-Remaining
Esi-Enabled
Who
X-Cache-Ttl
X-AIR-PT
X-Beluga-Response-Time
X-Reqid
X-Beluga-Trace
X-Beluga-Cache-Status
X-Beluga-Status
X-Beluga-Node
X-Beluga-Record
CACHE
X-Action
X-Slack-Backend
X-Fastly-Country-Code
CF-Cached-On
X-Planisys-CDN-TTL
X-Policy
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Azure-Ref-OriginShield
X-DI
X-DB
X-Cache-FS-Status
X-Server-Time
Trailer
X-Processor
X-PAYTM-SRV-ID
Pics-Label
GeoIP-Country-Code
X-RSL
X-DSS
X-Dispatch
Pramga
Arc-Country
X-RPS
X-RPM
X-Request-Start
X-DW
X-Skip-Cache
X-VCL-Version
X-ND-Cache
X-ABtesting
X-Varnish-Url
X-VarnishDD-TTL
GeoIP-City
X-Hello
Rt-Proxy-Cache
GeoIP-Latitude
X-Flog
X-Oracle-Dms-Rid
X-LiteSpeed-Cache-Control
MIME-Version
NtCoent-Length
X-APP
Cdn-Host
Ttl
X-Edge-Server
X-Served-From
X-PF-Uncompressing
Cdn-Request-Time
X-Fastly-Backend-Reqs
Fastly-Drupal-HTML
X-DC
Magicmarker
X-Bc-Bl
N-Cache
X-Ratelimit-Limit
X-DevSite-Last-Modified
Section-Io-Id
X-Zone
X-FPC
X-Method
X-Bc
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
X-Newrelic-App-Data
X-HostName
X-Swift-Error
Cteonnt-Length
X-Amzn-Remapped-Connection
X-PJAX-URL
WebServer
X-Amzn-Remapped-Date
X-Backend-Host
X-SRV
Amp-Access-Control-Allow-Source-Origin
X-Ftr-Cache-Host
X-BE
X-ZONE
X-BC
Fusion-Deployment-Id
X-Dynatrace
Processtime
Servername
X-Dynatrace-Js-Agent
X-Adobe-Source
FSS-Cache
Cache-Cookie-Set-Lfrom
Cache-Provider
X-Fmm-Version
Cache-Cookie-Set-From
FSS-Proxy
X-Be
X-WA
X-ID
X-Svr
Ohc-Response-Time
Cache-Cookie-Set-Idcheck
X-WR-MODIFICATION
X-Frame-Option
CDN
Requestid
Load-Balancing
X-Scheme
Dynatrace
Lfy
X-Snapshot-Date
X-LB-ID
X-Aicache-OS
X-Branch-Name
Vix-Hermes-Req-Id
CF-IPCountry
X-StackifyID
X-CACHE-AGE
X-Tid
WZWS-RAY
X-Fpc
V-Cache
X-App
X-SB
X-Request-Url
X-Apw-Access-Object
Proxy-Firewall
X-Fastly-Cache-Hits
X-VC
X-Apw-Access-Action
X-Cc-Via
X-Apw-Access-Token
X-Cc-Req-Id
D-Cc-Upstream
Warning
X-Apw-Hits
Pagetype
X-Litespeed-Cache-Control
X-Node-ID
X-MServer
DSUID
X-VCT
X-Compress-Hint
X-Hp-Ccpa-Warning
Correlation-Id
Cneonction
Backend-Name
WP-Super-Cache
X-Powered-Y
X-Request-URL
X-Check-Cacheable
X-Fastly-Cache-Status
X-ElasticPress-Search
X-Varnish-Beresp-TTL
X-Configured-By
X-Worker
Release
X-WPE-Loopback-Upstream-Addr