Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
CF-RAY
Link
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Request-ID
X-Cache-Status
X-Generator
Content-Security-Policy-Report-Only
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-DNS-Prefetch-Control
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
Status
Upgrade
X-Content-Security-Policy
X-CDN
Content-Encoding
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Xss-Protection
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
X-Pass-Why
X-Cache-Group
Xkey
P3p
X-AH-Environment
X-Envoy-Upstream-Service-Time
X-Via
CF-Ray
X-Backend
X-Server
X-Age
X-Ua-Compatible
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Server-Powered-By
X-Page-Speed
X-Ws-Request-Id
X-Pingback
EagleId
X-Proxy-Cache
X-Hacker
X-Nginx-Cache-Status
X-UA-Device
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
Cf-Railgun
Grace
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Amz-Version-Id
Report-To
X-LiteSpeed-Cache
X-Rq
X-Server-Id
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-OneAgent-JS-Injection
X-WebKit-CSP
X-Device
X-Host
X-Origin-Cache
EagleEye-TraceId
X-Response-Time
X-Node
X-Ac
Content-Location
Surrogate-Control
X-Vhost
X-Readtime
X-Backend-Server
Request-Id
X-Cloud-Trace-Context
X-Dispatcher
X-Dns-Prefetch-Control
X-Origin-Upstream-Status
X-Cnection
X-Application-Context
X-HW
X-ORACLE-DMS-ECID
X-Cache-Lookup
Fusion-Content-Source
Fusion-Component-Id
Fusion-Content-Id
Fusion-Source
Fusion-Template-Id
X-ORACLE-DMS-RID
X-Ruxit-JS-Agent
X-DataDome
X-Mod-Pagespeed
NEL
X-Rack-Cache
Rating
Edge-Control
X-Country
X-Akam-SW-Version
X-Clacks-Overhead
Pinterest-Generated-By
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Allow
X-TTL
X-Country-Code
X-DynaTrace
Accept-Ch
X-Instart-Request-ID
X-Varnish-TTL
X-Goog-Hash
X-FTR-Request-ID
X-Vname
X-TtlSet
X-PC
X-ESI
Verso
Accept-Ch-Lifetime
Content-MD5
X-Powered-By-Plesk
Service-Worker-Allowed
X-Url
X-B3-TraceId
X-Forwarded-Proto
X-Version
X-MS-InvokeApp
X-GitHub-Request-Id
X-Kinja-Server
X-Use-Magma
X-Kinja
X-Kinja-Revision
X-Kinja-Build
X-Exp-Id
X-Exp-Variant
X-Cdn-Fetch
X-GoogleNews-Bot
RTSS
X-D2id
Edge-Cache-Tag
X-Debug
Ar-Sid
AR-CACHE
AR-PoweredBy
AR-Request-ID
AR-ATIME
X-Abt-Application-Version
X-Server-Name
X-Px
X-Vcache
X-Amz-Server-Side-Encryption
SPRequestGuid
Charset
X-NF-Request-ID
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Cached
X-TEC-API-ORIGIN
X-Fastcgi-Cache
X-Accel-Expires
X-Middleton-Response
X-Sol
Display
X-Middleton-Display
Pagespeed
X-MSEdge-Ref
Response
X-Navigation-Version
X-Vcap-Request-Id
Arr-Disable-Session-Affinity
X-Amz-Rid
X-Powered-CMS
Pinterest-Version
X-Pinterest-Rid
TCN
X-SharePointHealthScore
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Trace
X-VARITI-CCR
Public-Key-Pins
Realpath
X-Client-IP
X-Cdn
Cache-Tag
X-Fastly-Request-ID
MS-Author-Via
X-Ser
Access-Control-Request-Method
Nginx-Cache
S
X-DynaTrace-JS-Agent
X-Shard
Nel
X-Upstream
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
SPRequestDuration
SPIisLatency
X-Edge-O15-RID
X-Id
X-Hp-Webp
X-Ezoic-Cdn
X-Content-Type
X-Amzn-Trace-Id
X-Forwarded-For
X-Grace
X-T
X-Amz-Meta-S3cmd-Attrs
Front-End-Https
DynaTrace
X-Recruiting
X-Hits
Fastcgi-Cache
X-Aspnet-Version
X-Varnish-Age
X-Jurisdiction
X-Cache-TTL
ServerID
X-Mobile-URL
X-Element-Page-Cache
X-Dw-Request-Base-Id
X-Content-Digest
MicrosoftSharePointTeamServices
X-Node-Name
X-DIS-Request-ID
X-Server-ID
X-FTR-Expires
X-Country-Code-Real
X-FTR-Cache-Status
NR-ENABLED
X-Goog-Generation
X-HS-Content-Id
X-HS-Cache-Config
X-Frontend
Powered
X-HS-Combine-CSS
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-Goog-Metageneration
X-HS-Hub-Id
X-FTR-Balancer
X-FTR-Realm
X-FTR-Backend
X-FTR-DC
X-FTR-Backend-Server
Server-Node
TP-L2-Cache
TP-Cache
Alternate-Protocol
Server-Name
X-Logged-In
X-Correlation-Id
X-CST
X-Request-Received
X-Request-Processing-Time
X-XRDS-LOCATION
AMP-Access-Control-Allow-Source-Origin
X-Amz-Apigw-Id
X-Microsite
X-Request-Handler-Origin-Region
X-Amzn-RequestId
X-ATS-Timestamp
Backend-Timing
Upgrade-Insecure-Requests
X-Cache-Hit
X-Content-Options
X-Content-Security-Policy-Report-Only
X-Page-Id
X-Revision
X-Rid
X-Origin-Server
X-User-Agent
X-F-Cache
X-Akamai-Edgescape
Refresh
Fastly-Restarts
X-Varnish-Grace
X-Type
X-Zen-Fury
X-Webkit-Csp
X-XRDS-Location
X-Content-Powered-By
X-B
X-LB-Cache
X-Geo-Country
X-B3-Sampled
PB-PID
PB-RID
X-FTR-Cache-Host
X-Activity-Id
X-Az
X-AppVersion
Arc-Version
X-Mobile-Rewrite
X-URL
Cache-Status
X-Shield-Request-Id
X-Kinsta-Cache
X-N
X-Pad
X-Time
X-WebKit-CSP-Report-Only
X-Instance
X-Cache-Age
X-Tumblr-User
X-Tumblr-Pixel-0
Actual-Object-TTL
X-TT
Paypal-Debug-Id
X-Tumblr-Pixel
X-B-Cache
X-Cache-Action
X-Signature
X-Debug-Info
Access-Control-Allow-Method
X-Jobs
X-AOL-HN
X-App-Environment
X-FB-Debug
X-Framework
X-Load-Cache
DC
X-PHP-Backend
X-Request-Guid
X-Cached-By
X-Git-Hash
X-Webapp-Samesite-None-Activated-N
X-RateLimit-Remaining
X-Varnish-Backend
Fastcgi-Useragent
X-Tt-Trace-Tag
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Amz-Replication-Status
Surrogate-Key
X-Tt-Trace-Host
X-Analytics
Host-Header
X-IPLB-Instance
FilterID
MS-CV
X-Contextid
X-ATG-Version
X-SS-Set-Cookie
Host
X-WA-Info
X-ORACLE-APMCS-REQUEST-ID
X-Cluster
X-ORACLE-APMCS-TAG
X-Mobile
X-Accel-Buffering
X-Response-Served-From
NGB
X-Kong-Upstream-Latency
WPE-Backend
X-Kong-Proxy-Latency
X-NWS-LOG-UUID
X-Host-Name
Tracecode
X-Cache-Key
X-Region
Source
X-Via-JSL
X-Varnish-Server
Payment
Xserver
X-Srv
X-FW-Type
Cache-Tv-Group
X-IPS-LoggedIn
X-FW-Static
X-Cache-2
Filters
Frame-Options
X-FW-Serve
X-FW-Server
Eomportal-Instance
X-FW-Hash
X-Cache-NE
X-GeoIP
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
X-Varnish-Hostname
X-Presslabs-Stats
X-Cacheable-TTL
X-Cache-Operation
X-Is-Bot
X-Cache-Enabled
X-Cache-Rule
X-Rendered-As
X-Origin-Response-Time
X-Hostname
X-RequestSource
X-Seen-By
X-EdgeConnect-Cache-Status
X-NewRelic-App-Data
Retry-After
X-Adobe-Content
X-Adobe-Loc
X-TX-ID
Cleartype
X-FastCGI-Cache
X-Cache-TTL-Remaining
Server-Info
X-ProcessESI
X-RemovedCookies
X-VCache
Liferay-Portal
X-UA
Accept-CH
X-Dc
X-B3-Traceid
Datacenter
Ms-Operation-Id
X-RTag
X-App-Server
X-HTML-Minification-Powered-By
X-Environment-Context
X-L-Path
X-Source
X-FireWall-Port
X-Upgrade-Enabled
X-Cache-Server
X-CACHE-KEY
X-Endurance-Cache-Level
Cache
X-Handled-By
X-Cache-Control
From-Origin
Healthy
X-Backend-Name
X-APP-VERSION
Accept-CH-Lifetime
X-Wix-Request-Id
Meta-Geo
Version
X-Cache-Var-Map
X-Path-Route
X-PressLabs-Stats
X-CLOUD-TRACE-CONTEXT
X-RN-RSRV
X-ES-SERVER
X-Cache-Var
X-Timing-Wait
Selected-Fe
X-Proxy-Build
OT-Force-Account-Verify
X-Tb
X-Section
X-Storage
X-Origin
X-Rule
X-Goog-Meta-Goog-Reserved-File-Mtime
X-OCL
Akamai-GRN
X-Format
X-PCL
X-Access
X-Hosted-By
X-Human
Cache-Tags
X-SaId
X-NYM-Debug-Backend
DB-Nickname
X-Proxy
X-ProxyCache-Key
X-Proxy-Cache-Status
Azure-Version
Azure-InstanceId
X-Redis-Cache
X-FC-Vary-Parameters
Azure-SiteName
X-Request-Time
X-Pubstack
Azure-RegionName
Azure-SlotName
X-JoinUs
X-ProxyCache-Status
X-Web-Node
X-Debug-Cache
X-Cluster-Node
Now
Mn-Server-Ip
X-Generated-By
X-EIG-Tracking-Id
X-Proto
Origin-Cache-Control
X-Akamai-Request-ID2
X-Akamai-Request-ID
X-Alternate-Cache-Key
X-BYPASS-REASON
Origin-Edge-Control
X-Shopify-Stage
X-Sorting-Hat-PodId
Decoy-Debug-TTL
X-Hl-Ver
X-ShardId
X-ServerID
Decoy-Debug-Status
X-Cache-Config
X-Viewer-Country
X-Vgn-Hpd-Reason
X-Soup
X-Sorting-Hat-ShopId
X-Time-Microsecs
X-ShopId
X-UUID
X-Shopify-Generated-Cart-Token
Decoy-Debug-Key
X-Yottaa-Metrics
Accept-Charset
X-Yottaa-Optimizations
Srv
X-Status
X-RateLimit-Limit
X-BCube-Filmed-By
X-CCM
X-FW-Dynamic
X-AWS-Id
Node
Ec-Rule-Version
NGX
X-Generated
X-MP-GENERATED-AT
X-Www-Served-By
X-Say-Cacheable
X-Say-TTL
X-SayCDN-TTL
X-VWS-Id
X-Ruxit-Js-Agent
Cross-Origin-Window-Policy
X-Qloud-Router
X-Site-Version
X-Varnish-Hits
X-LJ-Flow-ID
X-Hyper-Cache
TWC-Locale-Group
TWC-Privacy
Webcakes-App-Name
TWC-GeoIP-LatLong
TWC-GeoIP-Country
S-Rt
TWC-Connection-Speed
TWC-Device-Class
Webcakes-App-Version
Webcakes-Region
X-FB-TRIP-ID
X-Loop
X-TNCMS
X-Amzn-Remapped-Content-Length
X-Locale
X-Cache-Host
X-Content-Age
GEO-INFO
Property-Id
X-Origin-Hint
X-Akamai-Transformed
X-Xfnlog-Site
X-R9-Blue-Green-Version
X-IP
X-NCache
X-Detected-As
X-RCS-CacheZone
L5d-Success-Class
X-CS
X-Ttl
X-Drupal-Cache-Tags
Viewport
Webserver
Time
X-Unique-Id
Cache-Name
Uber-Trace-Id
Cache-Key
X-Esi
X-UA-Device-Type
X-UnsetCookies
Mime-Version
Accept-Language
X-Whom
X-Forwarded-Host
Country
X-Daa-Tunnel
X-Cache-Remote
X-Origin-CC
X-From
X-Mode
X-Origin-TTL
X-Backend-TTL
X-Info
Rt-Fastcgi-Cache
X-Trafficlayer-App-Name
X-Trafficlayer-App-Scope
VIX-Pulpo-Node
X-Cluster-Name
VIX-Pulpo-Upstream-Status
Odigeo-Trace-Id
X-CDN-Forward
X-Varnish-Cache-Hits
X-Drupal-Cache-Contexts
Content-Disposition
X-NGENIX-Cache
X-PERF
X-ApacheServer
X-Newrelic-Synthetics
X-B3-Spanid
ServedBy
X-Geo
X-Microcachable
X-Magnolia-Registration
X-TT-TIMESTAMP
Proxy-Connection
X-Device-Type
X-Edge-Location
Ohc-File-Size
X-Via-Fastly
X-Uri
Section-Io-Cache
X-EC-Lua
Ohc-Cache-HIT
X-Proxied
X-Zipkin-Id
X-Routing-Service
HitType
Cf-Ipcountry
X-No-Session
X-UPSTREAM-Address
Viewtype
GEO-REGION-INFO
VivaBuild
Fastcgi-X-Cache-Version
X-A
Content-Script-Type
Content-Style-Type
X-A-Ccd
X-Nc
Xc-Version
X-A-Dam
Machine
MD5-Digest
Meta-Geo-Continent
X-Transaction
Rendered-Blocks
BehaviorPad-Version
AsisCache
T-Server
Mobile-Detection-Method
X-CF-Lambda-Version
X-Rewrite-Enabled
X-VG-WebServer
X-VG-WebCache
X-Rocket-Build-Number
X-Request-UUID
X-Region-Sid
X-Vtex-Processado-Em
X-Geo-Header
X-GeoIP-Country-Code
X-Vdms-Version
X-Rojux
X-Sigma
X-ScT
X-Session-Fingerprint
X-Twitter-Response-Tags
X-S-Cookie
X-Sigma-Backend
X-Trv-Group
X-SRCache-Key
X-S
X-A-Dcw
X-G
X-B-Cookie
X-External-Request-Id
X-CF-Lambda-Fn
X-ARC
X-Application
X-Accel-Expires-Debug
X-Aed
X-A-Dgt
X-A-Wwc
X-Destination
X-DPWN-IS-SECURE
X-Date
X-Vtex-Remote-Cache
X-Connection-Hash
X-D
X-C
User-Cache-Control
Access-Control-Request-Headers
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Request-Url
Apple-News-Services-Handled
CDCHOST
X-Agile-Age
X-WebServer
X-CGP
X-Cache-Debug
X-Bip
X-Distil-CS
X-Eu-Site
X-Thanos
X-TrackingId
X-VG-TLSProxy
X-Hit
X-Agile-Id
X-Tumblr-Pixel-3
Locid
HA-Ipaddr
Ha-Gx-Prefs
Gh-Request-Id
X-Wikidot-Static-Cache
Powered-By
X-Wikidot-Backend
X-Agile
W
Fastly-Soc-X-Request-Id
X-Auto-Login
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Status
Geo-Info
X-Labrador-Cache-Channel
X-PHP-Host
X-Cache-Backend
X-TA-CDN-Provider
X-Debug-Cache-Expiry
X-Debug-Log
X-Debug-Cache-Fetch
X-Developers
X-Debug-Cache-Store
X-Debug-Cookies
X-WADP-Cache
X-Gamma-Serve
X-Gen-Mode
X-FW-Version
X-Fetched-On
X-We-Are-Hiring
X-Epic-Correlation-Id
X-Dispatcher-Server
X-Contensis-Viewer-Groups
X-Clientip
X-Backend-State
X-BBXSRF
X-App-Name
X-AK-Request-ID
V-Age
We-Hiring
Web-Mar-Node
X-Block-Status
X-Cache-Bucket
X-Cms-Context
X-Generated-In
X-CUA
X-Clara-WADP
Countrycode
X-Cache-Info
X-Cache-Time
X-Cdn-Srv
X-Webstats-RespID
X-Hash
X-Varnish-Authentication
X-Render-Time
X-User
X-Real-IP
X-RateLimit-Remaining-Second
X-VC-Cache
X-Proxy-Upstream
X-RateLimit-Limit-Second
X-Urbn-Site-Id
X-Request-URI
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Swa-Ws
X-TH-Server
X-Trace-Id
X-Urbn-Context-Path
X-SIPLIST1
X-Owner
X-OVcl-Cache
X-Instart-Isnd
X-Irp-Debug
X-Li-Fabric
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-GeoIP-City
True-Client-Country-4JS
X-Hnp-Log
X-Li-Pop
X-LI-UUID
X-NodeID
X-NX-Host
X-OVcl
X-Ms-Version
X-Ms-Request-Id
X-Logging-Id
X-Micro-Cache
X-Generation-Time
X-Cache-ASPX
Server-ID
Mail-Subject
Environment
Memcached
Locale
Heartbleed
Kp-EeAlive
IsBot
Server-Cache-Control
Server-Surrogate-Control
Country-Code
Request-Country
AKAMAI
Request-EU
Cdncip
Cdnsip
Cache-Host
X-GoCache-CacheStatus
X-VServer
X-Distributor
X-Cache-URL
X-Trafficlayer-App-Version
X-App-Version
X-Core-Mission
X-Service
PFcat
X-Server-W
Adler-Geo
X-Generated-On
X-Nginx-Cache-Key
X-Matched-Rule
X-Reboot
X-Old-Content-Length
X-Origin-Expires
X-Origin-Date
X-LI-Proto
X-Level-Front-Cache
IBM-Web2-Location
Thinkindot-CacheControl
Fastly-SIE
X-TT-LOGID
X-Key
Fastly-SSL
X-Fastly-Cache
X-ServiceProvider
X-Is-Gdpr
X-JWT-State
X-NU-AKA-ACS-Version
Server-Host
X-Has-Esi
Platform
X-Cache-Tags
X-Variation
Fastly-SWR
X-Thinkindot-L3
ServerName
Thinkindot-Control
Thinkindot-CacheControl-Type
X-Servername
Server-Int
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Azure-Ref
X-Platform-Server
Is-Eu
RNT-Machine
RNT-Time
Wxu-Next-Hostname
FNAC-ModuleRouting
X-Internal-Host
Wxu-Next-Region
Wxu-Next-Commit
X-S-Maxage
X-Up
X-Lb-Id
X-Req
Cache-Hits
Fastly-Backend-Name
X-Core-Value
X-Air-Hostname
X-Sucuri-Cache
X-Nginx-Cache
Group
X-SERVER
X-Cache-Expired-At
X-Response-By
RequestId
X-Location
X-Refresh
X-Parent-Response-Time
Pragrma
X-Var-Ttl
X-CF-Powered-By
S-Cnection
X-Tb-Optimization-Total-Bytes-Saved
Powered-By-ChinaCache
ProcessTime
Memory
X-B3-Parentspanid
Filterid
X-Cdn-Forward
X-Tec-Api-Version
X-Tec-Api-Origin
X-Pjax-Url
X-BACKEND-TTL
X-CSRF-Token
X-Tec-Api-Root
X-NC
X-B3-SpanId
X-CSRF-TOKEN
X-Sucuri-ID
X-Wa
X-Pf-Uncompressing
User-Agent
SRV
Origin
TTL
Geoip-Latitude
X-Server-IP
X-NWS-UUID-VERIFY
Geoip-City
GeoIp-Country-Code
X-Varnish-Cacheable
X-Vcl-Version
X-Via-CDN
X-Unique-ID
X-Ua
X-Correlation-ID
PICS-Label
X-Developer
X-NGINX-Cache
Media-Length
X-Ocache
X-Cdn-Request-ID
X-COUNTRY
X-Sn-Servicetimems
X-Device-Os
X-LAGOON
On-Server
X-Node-Id
X-Cache-Grace
X-Cdn-Origin
X-Oss-Object-Type
X-Cache-Status-Check
X-Oss-Request-Id
X-Oss-Server-Time
X-Rocket-Nginx-Bypass
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
X-Sucuri-Id
X-Litespeed-Cache
X-Servedbyhost
Dnion-Transfer-Encoding
A
X-Request-Host
X-Webkit-CSP
X-MSEdge-Features
X-MSEdge-Flight
Cloudfront-Viewer-Country
X-Varnish-Ttl
X-Via-Ucdn
SN
X-TIME
Hostname
XServer
X-Oneagent-Js-Injection
M-TraceId
X-Reqid
X-AIR-PT
Esi-Enabled
Cdn
X-HS-Status
Tcn
X-FORWARDED-FOR
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-Policy
X-ServedByHost
X-Planisys-CDN-Cache
Resin-Trace
X-Ratelimit-Remaining
HostName
X-Beluga-Cache-Status
X-Cache-Ttl
X-Azure-Ref-OriginShield
CF-Cached-On
X-Fastly-Country-Code
X-Beluga-Node
Who
X-Request-Start
X-Beluga-Trace
X-Beluga-Response-Time
X-Beluga-Record
X-Beluga-Status
X-Ftr-Cache-Host
X-VHOST
X-Varnish-URL
Host-ID
Rt-Proxy-Cache
X-Slack-Backend
Pics-Label
NtCoent-Length
Magicmarker
X-Bc
X-Zone
X-VCL-Version
X-APP
GeoIP-Country-Code
X-Action
X-Method
MIME-Version
X-Oracle-Dms-Rid
CACHE
X-DSS
X-RPS
GeoIP-Latitude
X-PAYTM-SRV-ID
X-Cache-FS-Status
Pramga
X-DW
X-Dispatch
Ttl
Arc-Country
Cteonnt-Length
X-RPM
X-Varnish-Url
X-DI
X-DB
X-Server-Time
X-RSL
X-Processor
X-Fastly-Backend-Reqs
X-DC
X-LiteSpeed-Cache-Control
X-ND-Cache
X-PF-Uncompressing
X-VarnishDD-TTL
GeoIP-City
X-Ratelimit-Limit
X-Newrelic-App-Data
X-Skip-Cache
X-FPC
X-HostName
X-Svr
Load-Balancing
X-PJAX-URL
Ohc-Response-Time
X-Ftr-Request-Id
Cdn-Host
Cdn-Request-Time
X-Hello
Fastly-Drupal-HTML
X-Be
X-ABtesting
Amp-Access-Control-Allow-Source-Origin
X-SRV
WebServer
X-Served-From
X-Edge-Server
X-Swift-Error
X-Flog
N-Cache
Processtime
Vix-Hermes-Req-Id
X-DevSite-Last-Modified
X-Bc-Bl
X-Dynatrace
X-BE
DSUID
X-MServer
X-Dynatrace-Js-Agent
Servername
X-Amzn-Remapped-Date
Release
X-Amzn-Remapped-Connection
Cache-Provider
X-WA
CF-IPCountry
X-Aicache-OS
X-ID
X-VCT
X-Backend-Host
X-Hp-Ccpa-Warning
Section-Origin-Responded
X-WR-MODIFICATION
Section-Io-Id
Section-Io-Origin-Time-Seconds
X-Frame-Option
Section-Io-Origin-Status
X-StackifyID
WZWS-RAY
CDN
X-Ftr-Backend-Server
X-LB-ID
X-Ftr-Balancer
Pagetype
X-Branch-Name
X-Ftr-Backend
X-Tid
Lfy
X-Fastly-Cache-Hits
X-Ftr-Dc
X-Snapshot-Date
X-ZONE
Requestid
X-Configured-By
Dynatrace
X-Ftr-Realm
X-CACHE-AGE
Proxy-Firewall
X-Apw-Access-Action
X-Upstream-Ht
X-Edge-IP
X-Upstream-Ct
X-SD-PageType
SD-X-WS
X-Apw-Access-Object
Cneonction
Warning
X-Apw-Access-Token
X-VC
X-SB
V-Cache
X-Fmm-Version
X-Request-Url
X-Cc-Req-Id
D-Cc-Upstream
X-Apw-Hits
X-Cc-Via
X-BC
X-Litespeed-Cache-Control
Cache-Cookie-Set-From
X-WPE-Loopback-Upstream-Addr
X-Li-Proto
FSS-Proxy
X-Node-ID
X-SN
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-Idcheck
X-ServerName
FSS-Cache
X-Fastly-Cache-Status
X-Worker
X-Check-Cacheable
X-Request-URL
X-Powered-Y
X-ElasticPress-Search
WP-Super-Cache
L
Lb
Backend-Name
X-Cache-Id
Correlation-Id
X-App
X-Varnish-Beresp-TTL
X-Compress-Hint