Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
CF-RAY
Link
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Request-ID
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-Template
X-Language
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
Status
X-Content-Security-Policy
Upgrade
X-CDN
Content-Encoding
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Xss-Protection
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
Xkey
X-Pass-Why
X-Cache-Group
P3p
X-Envoy-Upstream-Service-Time
X-AH-Environment
X-Via
X-Backend
CF-Ray
X-Age
X-Server
X-Ua-Compatible
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Server-Powered-By
X-Page-Speed
X-Ws-Request-Id
X-Pingback
EagleId
X-Proxy-Cache
X-Nginx-Cache-Status
X-Hacker
X-UA-Device
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
Cf-Railgun
Grace
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Amz-Version-Id
Report-To
X-LiteSpeed-Cache
X-Rq
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-WebKit-CSP
X-Server-Id
X-OneAgent-JS-Injection
X-Host
X-Device
EagleEye-TraceId
X-Origin-Cache
X-Response-Time
X-Dns-Prefetch-Control
X-Ac
X-Node
Content-Location
Surrogate-Control
X-Vhost
X-Readtime
X-Cloud-Trace-Context
Request-Id
X-Backend-Server
X-Dispatcher
X-Origin-Upstream-Status
X-Cnection
X-HW
X-Application-Context
X-ORACLE-DMS-ECID
X-Cache-Lookup
Fusion-Component-Id
Fusion-Content-Source
Fusion-Template-Id
Fusion-Source
Fusion-Content-Id
X-ORACLE-DMS-RID
X-DataDome
NEL
X-Mod-Pagespeed
X-Ruxit-JS-Agent
Rating
Edge-Control
X-Rack-Cache
X-Country
X-Clacks-Overhead
X-Akam-SW-Version
Pinterest-Generated-By
Allow
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Country-Code
X-DynaTrace
X-Instart-Request-ID
X-Varnish-TTL
X-TTL
X-Goog-Hash
X-FTR-Request-ID
X-Vname
X-TtlSet
X-PC
Accept-Ch
X-ESI
Verso
X-Powered-By-Plesk
Service-Worker-Allowed
Content-MD5
X-Url
Accept-Ch-Lifetime
X-Forwarded-Proto
X-Version
X-MS-InvokeApp
X-B3-TraceId
X-Exp-Variant
X-GoogleNews-Bot
X-Cdn-Fetch
X-Exp-Id
X-Use-Magma
X-Kinja
X-Kinja-Server
X-GitHub-Request-Id
X-Kinja-Revision
X-Kinja-Build
RTSS
Edge-Cache-Tag
X-D2id
X-Debug
AR-CACHE
Ar-Sid
AR-Request-ID
AR-PoweredBy
AR-ATIME
X-Px
X-Server-Name
X-Abt-Application-Version
SPRequestGuid
X-Amz-Server-Side-Encryption
Charset
X-NF-Request-ID
X-Vcache
X-Cached
X-Accel-Expires
Response
X-Middleton-Display
X-Sol
Pagespeed
X-Middleton-Response
Display
X-MSEdge-Ref
X-Vcap-Request-Id
X-Amz-Rid
X-Navigation-Version
Arr-Disable-Session-Affinity
X-Powered-CMS
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Pinterest-Rid
Pinterest-Version
X-SharePointHealthScore
X-TEC-API-VERSION
TCN
X-Fastcgi-Cache
X-Trace
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-VARITI-CCR
Realpath
Public-Key-Pins
X-Client-IP
X-Cdn
Cache-Tag
X-Fastly-Request-ID
X-Ser
MS-Author-Via
Access-Control-Request-Method
Nginx-Cache
S
X-Shard
X-DynaTrace-JS-Agent
X-Upstream
SPRequestDuration
SPIisLatency
X-Id
X-Server-ID
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
X-B3-TraceId-Primal
X-Ezoic-Cdn
MRF-Tech
Mrf-Cache-Status
X-Hp-Webp
X-Content-Type
X-Edge-O15-RID
X-Forwarded-For
X-Amzn-Trace-Id
X-Grace
X-T
X-Amz-Meta-S3cmd-Attrs
DynaTrace
X-Hits
Front-End-Https
X-Recruiting
Fastcgi-Cache
Nel
X-Varnish-Age
X-Aspnet-Version
ServerID
X-Cache-TTL
X-Dw-Request-Base-Id
MicrosoftSharePointTeamServices
X-Node-Name
X-Element-Page-Cache
X-DIS-Request-ID
X-Mobile-URL
X-Content-Digest
X-Jurisdiction
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Expires
NR-ENABLED
X-Goog-Metageneration
X-Frontend
X-Goog-Generation
Powered
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
X-HS-Hub-Id
X-FTR-Realm
X-FTR-DC
X-FTR-Backend
X-HS-Content-Id
X-FTR-Balancer
X-FTR-Backend-Server
X-HS-Combine-CSS
X-HS-Cache-Config
Server-Node
Alternate-Protocol
Server-Name
X-Logged-In
TP-Cache
TP-L2-Cache
X-Correlation-Id
X-Request-Received
X-Request-Processing-Time
X-Microsite
Upgrade-Insecure-Requests
X-Request-Handler-Origin-Region
AMP-Access-Control-Allow-Source-Origin
Backend-Timing
X-ATS-Timestamp
X-Amzn-RequestId
X-Amz-Apigw-Id
X-CST
X-Cache-Hit
X-XRDS-Location
X-Content-Options
X-Content-Security-Policy-Report-Only
X-Page-Id
X-Origin-Server
Refresh
X-Revision
X-Rid
X-User-Agent
X-Webkit-Csp
X-Varnish-Grace
X-F-Cache
X-Akamai-Edgescape
X-Type
X-XRDS-LOCATION
Fastly-Restarts
X-Zen-Fury
X-Content-Powered-By
X-B3-Sampled
X-LB-Cache
X-Shield-Request-Id
X-B
X-Activity-Id
X-Az
X-AppVersion
X-FTR-Cache-Host
X-Geo-Country
PB-RID
PB-PID
X-URL
X-Mobile-Rewrite
Arc-Version
X-N
Cache-Status
X-Kinsta-Cache
X-Pad
X-Time
X-Webapp-Samesite-None-Activated-N
X-WebKit-CSP-Report-Only
X-TT
X-Instance
X-Cache-Age
Paypal-Debug-Id
X-Framework
X-App-Environment
X-AOL-HN
X-Tumblr-Pixel-0
X-Tumblr-User
X-B-Cache
X-Request-Guid
X-Signature
X-Tumblr-Pixel
Access-Control-Allow-Method
X-Jobs
Actual-Object-TTL
X-PHP-Backend
X-Debug-Info
X-Cache-Action
X-FB-Debug
X-Load-Cache
DC
X-Cached-By
X-Git-Hash
X-RateLimit-Remaining
X-Analytics
X-Varnish-Backend
X-Tt-Trace-Tag
X-Erf-Bev-Bev
Fastcgi-Useragent
Surrogate-Key
X-Erf-Bev-Bev-Is-Generated
X-Tt-Trace-Host
Host-Header
X-Amz-Replication-Status
FilterID
X-IPLB-Instance
X-Contextid
MS-CV
X-ATG-Version
X-SS-Set-Cookie
X-Cache-Key
X-WA-Info
Tracecode
X-Cluster
Host
X-Response-Served-From
X-FastCGI-Cache
Accept-CH
X-Accel-Buffering
NGB
WPE-Backend
X-Host-Name
X-Via-JSL
X-Mobile
X-Kong-Proxy-Latency
Payment
X-Srv
X-VCache
X-Kong-Upstream-Latency
X-Region
X-FW-Type
X-FW-Static
X-FW-Server
X-FW-Serve
X-Varnish-Server
Eomportal-Instance
X-ORACLE-APMCS-TAG
Source
X-FW-Hash
X-ORACLE-APMCS-REQUEST-ID
X-Cache-2
X-Tumblr-Pixel-2
Frame-Options
X-IPS-LoggedIn
X-Tumblr-Pixel-1
Filters
Cache-Tv-Group
X-Cache-Enabled
X-Cache-NE
X-NWS-LOG-UUID
X-Cacheable-TTL
X-GeoIP
X-Is-Bot
X-Rendered-As
X-Cache-Rule
X-Cache-Operation
X-Varnish-Hostname
X-Presslabs-Stats
X-RequestSource
X-NewRelic-App-Data
X-Adobe-Loc
X-Origin-Response-Time
X-Adobe-Content
Xserver
X-B3-Traceid
X-Hostname
X-TX-ID
X-Ttl
Retry-After
X-Seen-By
X-EdgeConnect-Cache-Status
Cleartype
Server-Info
Accept-CH-Lifetime
X-Cache-TTL-Remaining
X-RemovedCookies
X-ProcessESI
X-Ruxit-Js-Agent
Liferay-Portal
X-UA
X-Dc
X-HTML-Minification-Powered-By
Cache
X-RTag
Datacenter
Ms-Operation-Id
X-Source
X-App-Server
X-Cache-Control
X-Environment-Context
X-L-Path
X-FireWall-Port
Healthy
X-Upgrade-Enabled
X-Cache-Server
From-Origin
X-Endurance-Cache-Level
X-Handled-By
X-CACHE-KEY
X-Backend-Name
X-Status
X-PressLabs-Stats
Version
Meta-Geo
X-Cache-Var-Map
X-Wix-Request-Id
X-Cache-Var
X-APP-VERSION
X-Path-Route
X-Rule
X-ES-SERVER
X-RN-RSRV
X-RateLimit-Limit
X-Access
X-Tb
X-Timing-Wait
Srv
X-Section
Selected-Fe
X-Proxy-Build
X-Format
X-Storage
X-Content-Age
X-Proto
X-Sorting-Hat-PodId
Azure-InstanceId
X-ShardId
Akamai-GRN
X-ShopId
X-Akamai-Request-ID
X-Sorting-Hat-ShopId
X-Shopify-Stage
X-Shopify-Generated-Cart-Token
X-Alternate-Cache-Key
X-Request-Time
Cache-Tags
X-Goog-Meta-Goog-Reserved-File-Mtime
Azure-SiteName
Azure-SlotName
X-EIG-Tracking-Id
OT-Force-Account-Verify
Mn-Server-Ip
Azure-RegionName
Azure-Version
X-UUID
Decoy-Debug-Status
X-Generated-By
X-Hl-Ver
X-Human
NGX
Decoy-Debug-TTL
X-Hyper-Cache
X-Akamai-Request-ID2
Decoy-Debug-Key
X-Proxy
X-Qloud-Router
X-Web-Node
X-FC-Vary-Parameters
X-FW-Dynamic
X-Pubstack
X-Time-Microsecs
X-Soup
S-Rt
X-NYM-Debug-Backend
GEO-INFO
X-Redis-Cache
X-Hosted-By
X-Vgn-Hpd-Reason
Ec-Rule-Version
X-Origin
X-OCL
Node
X-PCL
X-MP-GENERATED-AT
X-Cache-Config
Webcakes-App-Name
TWC-Privacy
X-Site-Version
TWC-GeoIP-LatLong
TWC-Locale-Group
TWC-GeoIP-Country
TWC-Device-Class
Property-Id
X-Viewer-Country
Origin-Edge-Control
X-Www-Served-By
Now
DB-Nickname
Origin-Cache-Control
X-Say-TTL
Webcakes-App-Version
X-SayCDN-TTL
TWC-Connection-Speed
X-Say-Cacheable
X-BYPASS-REASON
X-Yottaa-Optimizations
X-VWS-Id
Webcakes-Region
X-Detected-As
X-Yottaa-Metrics
Accept-Charset
X-Generated
X-ProxyCache-Status
X-ProxyCache-Key
X-Debug-Cache
X-SaId
X-AWS-Id
X-Proxy-Cache-Status
X-LJ-Flow-ID
X-JoinUs
X-IP
X-Locale
X-Origin-Hint
X-Cluster-Node
X-ServerID
X-TNCMS
X-RCS-CacheZone
X-FB-TRIP-ID
X-BCube-Filmed-By
X-Amzn-Remapped-Content-Length
X-Loop
X-R9-Blue-Green-Version
X-Varnish-Hits
Cross-Origin-Window-Policy
X-Akamai-Transformed
X-Cache-Host
X-CCM
X-NCache
X-Xfnlog-Site
L5d-Success-Class
X-CS
Cache-Name
Viewport
X-Unique-Id
Uber-Trace-Id
Webserver
X-Trafficlayer-App-Scope
Time
X-Trafficlayer-App-Name
X-Drupal-Cache-Tags
Cache-Key
X-Esi
X-UA-Device-Type
X-UnsetCookies
X-Cache-Remote
X-Mode
X-Forwarded-Host
X-From
Accept-Language
X-Backend-TTL
X-Origin-CC
Rt-Fastcgi-Cache
X-CDN-Forward
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
Mime-Version
X-Origin-TTL
X-Drupal-Cache-Contexts
X-Daa-Tunnel
Country
X-Info
X-Cluster-Name
Odigeo-Trace-Id
X-Newrelic-Synthetics
X-Magnolia-Registration
X-Whom
X-Microcachable
X-TT-TIMESTAMP
X-NGENIX-Cache
X-ApacheServer
X-PERF
X-Edge-Location
X-B3-Spanid
X-Varnish-Cache-Hits
X-Geo
ServedBy
X-EC-Lua
X-CLOUD-TRACE-CONTEXT
Content-Disposition
X-Zipkin-Id
X-Device-Type
X-Proxied
Proxy-Connection
X-Routing-Service
Ohc-File-Size
X-UPSTREAM-Address
X-Via-Fastly
Ohc-Cache-HIT
Section-Io-Cache
X-A-Ccd
T-Server
X-A-Dam
X-Accel-Expires-Debug
X-Destination
X-Rojux
X-Aed
W
X-S
X-G
X-A
X-A-Dcw
X-Sigma
Rendered-Blocks
X-Sigma-Backend
X-Geo-Header
X-A-Wwc
X-Session-Fingerprint
X-B-Cookie
Cf-Ipcountry
VivaBuild
X-ScT
X-A-Dgt
X-GeoIP-Country-Code
X-Rocket-Build-Number
Apple-News-Services-Handled
Apple-News-Services-Host
Viewtype
X-SRCache-Key
Content-Style-Type
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
X-ARC
Content-Script-Type
BehaviorPad-Version
AsisCache
Fastcgi-X-Cache-Version
X-Region-Sid
X-Date
X-Request-UUID
X-Rewrite-Enabled
X-Application
X-External-Request-Id
Meta-Geo-Continent
GEO-REGION-INFO
Machine
MD5-Digest
X-DPWN-IS-SECURE
Mobile-Detection-Method
X-S-Cookie
X-VG-TLSProxy
X-No-Session
X-VG-WebCache
X-D
X-Vdms-Version
X-Trv-Group
X-Twitter-Response-Tags
X-VG-WebServer
X-CF-Lambda-Fn
X-Transaction
X-Connection-Hash
X-Vtex-Remote-Cache
Xc-Version
X-CF-Lambda-Version
X-Vtex-Processado-Em
X-Nc
X-C
X-Uri
HitType
X-Bip
X-Agile
X-Agile-Id
HA-Ipaddr
X-Distil-CS
X-Backend-State
X-Real-IP
X-Agile-Age
IsBot
X-Wikidot-Backend
Server-Cache-Control
X-SIPLIST1
X-Wikidot-Static-Cache
X-CGP
X-Eu-Site
X-Auto-Login
Ha-Gx-Prefs
X-Cache-ASPX
X-Tumblr-Pixel-3
X-Hit
Server-Surrogate-Control
X-Contensis-Viewer-Groups
X-Developers
X-CUA
X-App-Name
Environment
Fastly-Soc-X-Request-Id
X-Thanos
Gh-Request-Id
X-Logging-Id
X-VC-Cache
Powered-By
X-Varnish-Authentication
X-TrackingId
Geo-Info
X-Cache-Backend
X-GoCache-CacheStatus
X-PHP-Host
User-Cache-Control
X-Labrador-Cache-Channel
X-Debug-Cache-Store
X-Debug-Cookies
X-Debug-Log
X-Hash
X-Cdn-Srv
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-IN-APIGATEWAYSSL
X-Core-Mission
X-Instart-Isnd
X-TH-Server
X-User
X-Cache-URL
X-IN-APIGATEWAY
X-Debug-Cache-Fetch
X-VServer
X-Irp-Debug
X-Epic-Correlation-Id
X-Generated-In
Fastly-SIE
X-Gamma-Serve
Server-Int
X-Fastly-Cache
Fastly-SWR
X-Generation-Time
X-We-Are-Hiring
X-Cache-Info
X-Fetched-On
Request-Country
Request-EU
Countrycode
X-GeoIP-City
X-Clientip
X-FW-Version
X-RateLimit-Remaining-Second
X-Render-Time
X-Urbn-Site-Id
X-Urbn-Context-Path
X-WebServer
X-RateLimit-Limit-Second
X-Origin-Expires
X-OVcl
X-OVcl-Cache
X-Debug-Cache-Expiry
X-TT-LOGID
X-Varnish-Beresp-Ttl
X-Tec-Api-Version
X-Tec-Api-Root
X-SVT-ORM-RULES
X-Tec-Api-Origin
X-SVT-ORM-VERSION
X-Server-W
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
X-Trace-Id
X-Swa-Ws
X-Cache-Debug
X-Origin-Date
X-Cache-Bucket
Fastly-Backend-Name
X-Micro-Cache
Country-Code
X-BBXSRF
Heartbleed
Kp-EeAlive
X-Key
Locid
Locale
X-AK-Request-ID
Cdnsip
Cdncip
Access-Control-Request-Headers
X-Webstats-RespID
AKAMAI
X-NodeID
Fastly-SSL
X-Nginx-Cache-Key
Memcached
CDCHOST
IBM-Web2-Location
X-NX-Host
X-App-Version
X-Cache-Time
X-Request-URI
X-LI-UUID
X-Reboot
X-LI-Proto
X-Li-Pop
X-WADP-Cache
X-Li-Fabric
X-Cache-Tags
X-Has-Esi
X-Servername
X-Up
X-NU-AKA-ACS-Version
X-JWT-State
X-Internal-Host
X-Is-Gdpr
X-Trafficlayer-App-Version
X-Thinkindot-L3
X-Level-Front-Cache
X-Matched-Rule
X-Hnp-Log
X-Generated-On
X-Distributor
X-Gen-Mode
X-Ms-Request-Id
X-Ms-Version
X-ServiceProvider
X-Sucuri-Cache
X-Service
X-Cms-Context
X-Owner
X-Proxy-Upstream
X-Dispatcher-Server
X-Core-Value
PFcat
V-Age
We-Hiring
Web-Mar-Node
Wxu-Next-Commit
ServerName
True-Client-Country-4JS
Server-Host
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
Thinkindot-Control
Server-ID
Wxu-Next-Hostname
RNT-Machine
X-Block-Status
Mail-Subject
Wxu-Next-Region
RNT-Time
X-Azure-Ref
Cache-Host
X-Clara-WADP
X-Oneagent-Js-Injection
Cache-Hits
FNAC-ModuleRouting
X-Lb-Id
X-Response-By
Platform
X-Platform-Server
X-Variation
Is-Eu
Adler-Geo
X-Req
X-TA-CDN-Provider
X-Old-Content-Length
X-Nginx-Cache
X-SERVER
X-Location
X-Refresh
X-S-Maxage
X-Parent-Response-Time
X-Air-Hostname
RequestId
X-Tb-Optimization-Total-Bytes-Saved
X-Var-Ttl
X-Cache-Expired-At
X-B3-Parentspanid
S-Cnection
Memory
Group
Pragrma
X-Cdn-Forward
Filterid
X-CF-Powered-By
X-CSRF-TOKEN
X-BACKEND-TTL
Powered-By-ChinaCache
X-B3-SpanId
X-NC
ProcessTime
X-Wa
X-Pjax-Url
Origin
User-Agent
X-CSRF-Token
X-Server-IP
X-Pf-Uncompressing
Geoip-Latitude
X-Sucuri-ID
X-Varnish-Cacheable
GeoIp-Country-Code
X-NWS-UUID-VERIFY
Geoip-City
TTL
X-Correlation-ID
X-Unique-ID
X-NGINX-Cache
SRV
X-Ua
PICS-Label
Media-Length
X-Via-CDN
X-Vcl-Version
X-Cdn-Request-ID
X-COUNTRY
X-Developer
X-Sucuri-Id
X-Node-Id
X-Rocket-Nginx-Bypass
X-Device-Os
X-Ocache
X-LAGOON
X-Cache-Grace
X-Cdn-Origin
X-Sn-Servicetimems
XServer
On-Server
X-Servedbyhost
Dnion-Transfer-Encoding
M-TraceId
X-Litespeed-Cache
X-Webkit-CSP
SN
X-Reqid
X-Via-Ucdn
Esi-Enabled
X-MSEdge-Flight
X-Varnish-Ttl
A
X-Request-Host
X-HS-Status
X-Cache-Status-Check
X-MSEdge-Features
X-AIR-PT
X-TIME
X-Oss-Server-Time
X-Planisys-CDN-TTL
X-Oss-Storage-Class
X-Policy
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
Hostname
Cloudfront-Viewer-Country
Tcn
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
X-Oss-Object-Type
X-FORWARDED-FOR
X-Azure-Ref-OriginShield
Resin-Trace
X-Request-Start
Cdn
HostName
X-Ratelimit-Remaining
X-Fastly-Country-Code
X-Beluga-Trace
X-Beluga-Record
X-Beluga-Node
X-Beluga-Cache-Status
X-Beluga-Response-Time
X-Beluga-Status
X-ServedByHost
X-Cache-Ttl
Rt-Proxy-Cache
Who
X-Ftr-Cache-Host
X-VHOST
X-Varnish-URL
Host-ID
Magicmarker
Cteonnt-Length
X-Method
Pics-Label
CF-Cached-On
MIME-Version
NtCoent-Length
X-Slack-Backend
GeoIP-Country-Code
X-APP
X-VCL-Version
X-Oracle-Dms-Rid
X-RPM
X-RPS
X-DW
X-Action
X-Varnish-Url
Ttl
X-Zone
X-Fastly-Backend-Reqs
X-DB
X-DSS
X-DI
X-RSL
X-Bc
GeoIP-Latitude
X-LiteSpeed-Cache-Control
Load-Balancing
X-DC
CACHE
X-PAYTM-SRV-ID
X-Ratelimit-Limit
X-VarnishDD-TTL
Arc-Country
Ohc-Response-Time
X-Svr
Pramga
X-Skip-Cache
X-Processor
X-Server-Time
GeoIP-City
X-Newrelic-App-Data
X-Dispatch
X-FPC
X-Swift-Error
X-PF-Uncompressing
X-Be
X-HostName
X-Hello
Amp-Access-Control-Allow-Source-Origin
X-ND-Cache
Vix-Hermes-Req-Id
Processtime
X-ABtesting
X-PJAX-URL
X-Flog
X-Ftr-Request-Id
DSUID
X-SRV
X-Cache-FS-Status
WebServer
Release
X-MServer
X-VCT
X-DevSite-Last-Modified
Cdn-Host
Fastly-Drupal-HTML
X-Edge-Server
X-Served-From
X-Hp-Ccpa-Warning
N-Cache
X-Dynatrace
Cdn-Request-Time
X-BE
X-Dynatrace-Js-Agent
CF-IPCountry
Servername
X-WR-MODIFICATION
X-Tid
Cache-Provider
X-ZONE
X-Configured-By
X-Aicache-OS
X-WA
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
X-Bc-Bl
X-ID
X-Frame-Option
X-Backend-Host
X-StackifyID
Pagetype
X-Ftr-Backend-Server
X-Ftr-Backend
X-Fastly-Cache-Hits
X-SD-PageType
X-Upstream-Ct
X-Upstream-Ht
Dynatrace
X-Ftr-Realm
X-Ftr-Dc
X-Ftr-Balancer
CDN
X-BC
X-Snapshot-Date
SD-X-WS
X-LB-ID
X-Branch-Name
Requestid
Lfy
X-CACHE-AGE
Section-Io-Origin-Time-Seconds
Section-Io-Id
Section-Origin-Responded
Section-Io-Origin-Status
X-Compress-Hint
V-Cache
X-SN
L
X-Varnish-Beresp-TTL
X-Edge-IP
X-Cache-Id
Warning
X-Apw-Access-Object
D-Cc-Upstream
Proxy-Firewall
X-VC
X-Request-Url
X-Apw-Hits
X-SB
X-Apw-Access-Action
X-Apw-Access-Token
X-Cc-Via
X-Cc-Req-Id
X-Litespeed-Cache-Control
X-ElasticPress-Search
WP-Super-Cache
X-ServerName
WZWS-RAY
X-WPE-Loopback-Upstream-Addr
FSS-Proxy
FSS-Cache
Cneonction
X-Worker
X-Powered-Y
Lb
X-Fastly-Cache-Status
X-Check-Cacheable
Correlation-Id
Backend-Name
X-Request-URL
X-Via-NSCOPI
X-Release
X-App