Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
CF-RAY
Link
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-Cache-Hits
X-UA-Compatible
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-Request-ID
X-DNS-Prefetch-Control
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
Status
Upgrade
X-Content-Security-Policy
X-CDN
Content-Encoding
Access-Control-Expose-Headers
X-Ua-Compatible
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Xss-Protection
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
X-Pass-Why
X-Cache-Group
Xkey
X-AH-Environment
P3p
X-Envoy-Upstream-Service-Time
X-Via
X-Backend
CF-Ray
X-Server
X-Age
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Ws-Request-Id
X-Server-Powered-By
X-Page-Speed
X-Pingback
EagleId
X-Proxy-Cache
X-Hacker
X-UA-Device
X-Nginx-Cache-Status
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
Cf-Railgun
Grace
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Amz-Version-Id
Report-To
X-LiteSpeed-Cache
X-Rq
X-OneAgent-JS-Injection
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-WebKit-CSP
X-Server-Id
X-Device
X-Host
X-Origin-Cache
EagleEye-TraceId
X-Response-Time
X-Node
X-Ac
Surrogate-Control
Content-Location
X-Cloud-Trace-Context
X-Vhost
X-Readtime
X-Backend-Server
Request-Id
X-Dispatcher
X-Origin-Upstream-Status
X-Cnection
X-Application-Context
X-HW
X-Cache-Lookup
X-ORACLE-DMS-ECID
Fusion-Content-Id
Fusion-Component-Id
Fusion-Content-Source
Fusion-Source
Fusion-Template-Id
X-Ruxit-JS-Agent
X-ORACLE-DMS-RID
NEL
X-DataDome
X-Mod-Pagespeed
X-Rack-Cache
Rating
Edge-Control
X-Country
X-Clacks-Overhead
X-Akam-SW-Version
X-Dns-Prefetch-Control
Pinterest-Generated-By
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-TTL
Allow
X-Country-Code
Accept-Ch
X-DynaTrace
X-FTR-Request-ID
X-Instart-Request-ID
X-Varnish-TTL
X-Goog-Hash
X-TtlSet
X-Vname
X-PC
X-ESI
Verso
Accept-Ch-Lifetime
Content-MD5
Service-Worker-Allowed
X-Powered-By-Plesk
X-Url
X-B3-TraceId
X-Forwarded-Proto
X-Version
X-MS-InvokeApp
X-GitHub-Request-Id
X-Cdn-Fetch
X-Exp-Variant
X-Exp-Id
X-Kinja-Server
X-Use-Magma
X-Kinja-Build
X-Kinja-Revision
X-Kinja
X-GoogleNews-Bot
RTSS
Edge-Cache-Tag
X-Server-Name
X-D2id
X-Abt-Application-Version
X-Debug
X-Px
Ar-Sid
AR-Request-ID
AR-PoweredBy
X-Vcache
AR-ATIME
AR-CACHE
X-Amz-Server-Side-Encryption
SPRequestGuid
Charset
X-NF-Request-ID
X-Cached
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Fastcgi-Cache
X-Vcap-Request-Id
X-Sol
Pagespeed
Response
Display
X-Middleton-Display
X-Middleton-Response
X-Accel-Expires
X-Amz-Rid
X-Navigation-Version
X-MSEdge-Ref
Arr-Disable-Session-Affinity
X-Pinterest-Rid
Pinterest-Version
X-SharePointHealthScore
X-Powered-CMS
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-VARITI-CCR
TCN
X-Trace
Public-Key-Pins
Cache-Tag
Realpath
X-Fastly-Request-ID
X-Client-IP
X-Cdn
MS-Author-Via
Nginx-Cache
X-Ser
Access-Control-Request-Method
X-Edge-O15-RID
X-DynaTrace-JS-Agent
X-Shard
Mrf-Cache-Status
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
MRF-Tech
X-Mrf-Item-Lastmod
S
SPIisLatency
X-Server-ID
X-Upstream
SPRequestDuration
X-Content-Type
X-Id
X-Ezoic-Cdn
X-Amzn-Trace-Id
X-Hp-Webp
X-Grace
X-Forwarded-For
X-T
X-Amz-Meta-S3cmd-Attrs
Front-End-Https
X-Hits
X-Recruiting
Fastcgi-Cache
X-Jurisdiction
DynaTrace
Nel
X-Cache-TTL
X-Aspnet-Version
X-Varnish-Age
ServerID
MicrosoftSharePointTeamServices
X-Element-Page-Cache
X-Content-Digest
X-Mobile-URL
X-Country-Code-Real
X-FTR-Backend
X-Node-Name
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Expires
X-FTR-DC
X-FTR-Cache-Status
X-Dw-Request-Base-Id
X-FTR-Realm
X-DIS-Request-ID
NR-ENABLED
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
X-Goog-Metageneration
Powered
X-Frontend
X-Goog-Generation
X-Goog-Storage-Class
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
Server-Node
X-Goog-Stored-Content-Length
Alternate-Protocol
TP-Cache
TP-L2-Cache
X-Logged-In
Server-Name
X-CST
AMP-Access-Control-Allow-Source-Origin
X-Amz-Apigw-Id
X-Amzn-RequestId
Upgrade-Insecure-Requests
X-Request-Received
X-Request-Processing-Time
X-Correlation-Id
X-Request-Handler-Origin-Region
X-Microsite
X-ATS-Timestamp
X-Cache-Hit
Backend-Timing
X-XRDS-Location
Fastly-Restarts
X-Content-Options
Refresh
X-Origin-Server
X-F-Cache
X-Content-Security-Policy-Report-Only
X-User-Agent
X-Page-Id
X-Revision
X-Akamai-Edgescape
X-Zen-Fury
X-Rid
X-Varnish-Grace
X-Type
X-XRDS-LOCATION
X-Content-Powered-By
X-LB-Cache
X-Webkit-Csp
X-FTR-Cache-Host
X-B
X-B3-Sampled
PB-PID
PB-RID
Arc-Version
X-Mobile-Rewrite
X-Geo-Country
X-AppVersion
X-Activity-Id
X-Az
Cache-Status
X-URL
X-Kinsta-Cache
X-N
X-Cache-Age
X-Shield-Request-Id
X-TT
X-Time
X-Instance
X-AOL-HN
X-Signature
X-B-Cache
X-Cache-Action
X-WebKit-CSP-Report-Only
X-Pad
Access-Control-Allow-Method
X-Tumblr-Pixel
Actual-Object-TTL
X-Debug-Info
X-Tumblr-Pixel-0
X-Jobs
Paypal-Debug-Id
X-Framework
X-Tumblr-User
X-FB-Debug
X-App-Environment
X-Load-Cache
X-PHP-Backend
X-Request-Guid
X-Cached-By
X-Git-Hash
DC
Fastcgi-Useragent
X-RateLimit-Remaining
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Varnish-Backend
X-Amz-Replication-Status
Surrogate-Key
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-IPLB-Instance
Host-Header
X-Contextid
MS-CV
X-Webapp-Samesite-None-Activated-N
X-ATG-Version
X-Analytics
Host
X-WA-Info
X-NWS-LOG-UUID
X-SS-Set-Cookie
FilterID
X-ORACLE-APMCS-REQUEST-ID
X-ORACLE-APMCS-TAG
X-Mobile
X-Response-Served-From
NGB
X-Accel-Buffering
X-Kong-Upstream-Latency
X-Via-JSL
X-Kong-Proxy-Latency
X-Cluster
Tracecode
Payment
WPE-Backend
X-Host-Name
X-Cache-Key
Xserver
X-Cache-NE
X-FW-Server
X-FW-Type
X-Region
X-FW-Serve
X-FW-Hash
X-Cache-2
Eomportal-Instance
Source
X-FW-Static
X-Varnish-Server
X-GeoIP
X-Srv
Filters
Frame-Options
X-IPS-LoggedIn
X-Tumblr-Pixel-2
X-Origin-Response-Time
X-Tumblr-Pixel-1
X-Varnish-Hostname
X-Adobe-Loc
X-Cache-Enabled
X-Adobe-Content
Cache-Tv-Group
X-Rendered-As
X-RequestSource
X-Cacheable-TTL
X-Seen-By
X-Is-Bot
X-Cache-Rule
X-Cache-Operation
X-TX-ID
Retry-After
X-EdgeConnect-Cache-Status
X-Hostname
Server-Info
X-Cache-TTL-Remaining
X-NewRelic-App-Data
X-Presslabs-Stats
Cleartype
X-RemovedCookies
Liferay-Portal
X-ProcessESI
X-FastCGI-Cache
X-VCache
Accept-CH
X-App-Server
X-Dc
Ms-Operation-Id
X-B3-Traceid
X-Environment-Context
X-L-Path
X-RTag
X-FireWall-Port
X-UA
X-Source
X-HTML-Minification-Powered-By
Datacenter
X-Endurance-Cache-Level
X-CACHE-KEY
X-Upgrade-Enabled
X-Handled-By
From-Origin
X-PressLabs-Stats
X-Cache-Server
Srv
X-Backend-Name
X-Cache-Control
X-Wix-Request-Id
Cache
Accept-CH-Lifetime
Healthy
Accept-Charset
X-Path-Route
X-Cache-Var
X-ES-SERVER
X-RN-RSRV
Meta-Geo
X-Cache-Var-Map
X-Status
X-Section
X-Format
X-Proxy-Build
X-UUID
X-Tb
Selected-Fe
Version
X-Timing-Wait
X-Access
OT-Force-Account-Verify
Cache-Tags
X-ShardId
X-Origin
X-ShopId
X-PCL
Mn-Server-Ip
X-Akamai-Request-ID
X-Proto
X-Alternate-Cache-Key
X-Sorting-Hat-PodId
Azure-SlotName
Azure-Version
Azure-InstanceId
X-Shopify-Generated-Cart-Token
Azure-RegionName
X-Content-Age
X-EIG-Tracking-Id
X-NYM-Debug-Backend
X-OCL
X-Sorting-Hat-ShopId
X-FC-Vary-Parameters
X-Shopify-Stage
Azure-SiteName
Akamai-GRN
X-Cache-Config
X-Goog-Meta-Goog-Reserved-File-Mtime
X-ProxyCache-Key
X-Proxy
Decoy-Debug-Status
Decoy-Debug-Key
DB-Nickname
NGX
X-Qloud-Router
X-Pubstack
X-ProxyCache-Status
X-Proxy-Cache-Status
X-Web-Node
Ec-Rule-Version
X-SayCDN-TTL
X-Cluster-Node
X-Hyper-Cache
X-JoinUs
X-Viewer-Country
X-Vgn-Hpd-Reason
X-Human
X-VWS-Id
X-Generated-By
X-FW-Dynamic
X-Hl-Ver
X-Hosted-By
X-Debug-Cache
X-LJ-Flow-ID
X-Soup
X-Request-Time
X-SaId
X-Redis-Cache
Origin-Edge-Control
Origin-Cache-Control
X-Say-Cacheable
X-Say-TTL
X-BYPASS-REASON
X-AWS-Id
X-ServerID
X-Akamai-Request-ID2
Now
Decoy-Debug-TTL
X-Yottaa-Metrics
X-Storage
X-RateLimit-Limit
X-Yottaa-Optimizations
Webcakes-Region
X-Rule
Cross-Origin-Window-Policy
X-Amzn-Remapped-Content-Length
Webcakes-App-Version
Webcakes-App-Name
TWC-Device-Class
TWC-Connection-Speed
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Privacy
TWC-Locale-Group
Property-Id
X-CCM
X-Time-Microsecs
X-Site-Version
X-TNCMS
X-Varnish-Hits
X-Www-Served-By
X-Loop
X-Origin-Hint
X-FB-TRIP-ID
X-Generated
X-APP-VERSION
X-Akamai-Transformed
X-Xfnlog-Site
X-RCS-CacheZone
X-R9-Blue-Green-Version
X-Locale
X-MP-GENERATED-AT
S-Rt
X-Cache-Host
X-NCache
Node
X-IP
X-Detected-As
X-BCube-Filmed-By
GEO-INFO
L5d-Success-Class
X-CS
X-Drupal-Cache-Tags
Cache-Name
Cache-Key
Webserver
Time
Viewport
Uber-Trace-Id
X-Esi
X-UA-Device-Type
X-Mode
X-Unique-Id
X-Forwarded-Host
X-Whom
X-UnsetCookies
Mime-Version
Accept-Language
X-Origin-TTL
X-Origin-CC
X-Daa-Tunnel
X-Cache-Remote
X-Info
Rt-Fastcgi-Cache
Country
Content-Disposition
X-From
X-Varnish-Cache-Hits
X-PERF
X-ApacheServer
Odigeo-Trace-Id
X-B3-Spanid
X-Backend-TTL
X-NGENIX-Cache
ServedBy
X-Cluster-Name
VIX-Pulpo-Upstream-Status
X-Drupal-Cache-Contexts
X-CDN-Forward
VIX-Pulpo-Node
X-Magnolia-Registration
Section-Io-Cache
X-Microcachable
X-EC-Lua
X-Ruxit-Js-Agent
X-Newrelic-Synthetics
X-Geo
X-TT-TIMESTAMP
X-CLOUD-TRACE-CONTEXT
X-Nc
X-Zipkin-Id
X-Routing-Service
X-Device-Type
X-Proxied
X-Via-Fastly
Ohc-File-Size
X-Uri
Geo-Info
X-Ttl
Ohc-Cache-HIT
Proxy-Connection
X-Trafficlayer-App-Name
Cf-Ipcountry
X-Trafficlayer-App-Scope
X-Edge-Location
HitType
X-DPWN-IS-SECURE
MD5-Digest
Machine
X-Destination
GEO-REGION-INFO
X-External-Request-Id
X-G
Apple-News-Services-Request-Url
Xc-Version
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
Apple-News-Services-Host
AsisCache
X-GeoIP-Country-Code
Content-Style-Type
Content-Script-Type
X-Geo-Header
BehaviorPad-Version
Fastcgi-X-Cache-Version
X-CF-Lambda-Version
X-ARC
X-Application
X-Twitter-Response-Tags
X-A
X-Trv-Group
X-Transaction
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
VivaBuild
W
X-A-Ccd
X-A-Dam
X-VG-WebCache
X-VG-TLSProxy
X-Vdms-Version
X-Aed
X-VG-WebServer
X-Accel-Expires-Debug
X-A-Dcw
X-A-Dgt
X-A-Wwc
X-Region-Sid
Viewtype
X-S
X-S-Cookie
X-ScT
X-Date
X-Rojux
X-Rocket-Build-Number
Meta-Geo-Continent
Mobile-Detection-Method
X-Request-UUID
X-Rewrite-Enabled
X-Session-Fingerprint
X-Sigma
Rendered-Blocks
X-CF-Lambda-Fn
X-No-Session
X-Connection-Hash
X-B-Cookie
X-Sigma-Backend
X-D
X-SRCache-Key
T-Server
Access-Control-Request-Headers
X-C
X-UPSTREAM-Address
User-Cache-Control
X-App-Version
X-Cache-ASPX
X-Distil-CS
CDCHOST
X-Cache-Debug
X-Clientip
X-Wikidot-Static-Cache
X-Developers
X-Varnish-Beresp-Grace
X-Bip
X-Agile-Age
IsBot
Server-Surrogate-Control
Ha-Gx-Prefs
X-Wikidot-Backend
X-CGP
X-Eu-Site
Fastly-SIE
Fastly-Soc-X-Request-Id
Environment
Gh-Request-Id
Fastly-SWR
X-Real-IP
Countrycode
Server-Cache-Control
HA-Ipaddr
X-Thanos
X-Contensis-Viewer-Groups
Powered-By
X-Agile-Id
X-App-Name
X-CUA
X-SIPLIST1
X-Agile
X-VC-Cache
X-Logging-Id
X-Varnish-Authentication
X-WebServer
X-Varnish-Beresp-Ttl
X-TrackingId
X-Auto-Login
X-Rebelmouse-Cache-Control
X-Hit
X-Varnish-Beresp-Status
X-Rebelmouse-Surrogate-Control
Fastly-SSL
X-Tumblr-Pixel-3
Locid
X-Cache-Backend
X-GoCache-CacheStatus
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Clara-WADP
X-Cms-Context
X-Core-Mission
X-TH-Server
X-Up
X-AK-Request-ID
X-TT-LOGID
X-Trace-Id
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Variation
X-VServer
X-User
X-WADP-Cache
X-Backend-State
X-Cache-Tags
X-Cache-Time
X-Cache-URL
X-Cdn-Srv
X-Cache-Info
X-Server-W
X-BBXSRF
X-Block-Status
X-Cache-Bucket
X-Swa-Ws
X-RateLimit-Remaining-Second
X-IN-APIGATEWAY
X-Hnp-Log
X-IN-APIGATEWAYSSL
X-Instart-Isnd
X-Irp-Debug
X-Hash
X-Has-Esi
X-OVcl
X-Origin-Expires
X-Origin-Date
X-GeoIP-City
X-Is-Gdpr
X-JWT-State
X-LI-UUID
X-Nginx-Cache-Key
X-Micro-Cache
X-Ms-Version
X-LI-Proto
X-NodeID
X-Li-Fabric
X-NX-Host
X-NU-AKA-ACS-Version
X-Li-Pop
X-OVcl-Cache
X-Owner
X-Debug-Log
X-Dispatcher-Server
X-Distributor
X-Ms-Request-Id
X-Debug-Cookies
X-We-Are-Hiring
X-Render-Time
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Epic-Correlation-Id
X-Webstats-RespID
X-Platform-Server
X-Gen-Mode
X-Generated-In
X-Generation-Time
X-Proxy-Upstream
X-Gamma-Serve
X-Fastly-Cache
X-Fetched-On
X-FW-Version
X-RateLimit-Limit-Second
X-Request-URI
X-Azure-Ref
Platform
Memcached
Mail-Subject
Request-Country
Request-EU
Server-ID
RNT-Time
RNT-Machine
Locale
Kp-EeAlive
Cdncip
Cache-Host
AKAMAI
Cdnsip
Country-Code
Is-Eu
IBM-Web2-Location
Heartbleed
Server-Int
Adler-Geo
We-Hiring
V-Age
Web-Mar-Node
True-Client-Country-4JS
ServerName
Wxu-Next-Commit
X-Matched-Rule
X-Old-Content-Length
X-Trafficlayer-App-Version
X-Level-Front-Cache
X-Labrador-Cache-Channel
Wxu-Next-Hostname
X-Generated-On
Fastly-Backend-Name
X-Core-Value
X-Air-Hostname
FNAC-ModuleRouting
X-PHP-Host
X-Servername
Server-Host
PFcat
X-ServiceProvider
X-Service
Thinkindot-Control
X-Req
X-Reboot
Wxu-Next-Region
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-Thinkindot-L3
X-Nginx-Cache
Cache-Hits
X-Internal-Host
Group
X-Lb-Id
X-Cache-Expired-At
X-S-Maxage
X-Var-Ttl
Filterid
S-Cnection
X-SERVER
RequestId
Pragrma
X-Refresh
X-Sucuri-Cache
X-Response-By
X-Key
X-Parent-Response-Time
X-Cdn-Forward
X-CF-Powered-By
X-BACKEND-TTL
X-VHOST
X-Tb-Optimization-Total-Bytes-Saved
X-Location
Powered-By-ChinaCache
X-TA-CDN-Provider
X-CSRF-TOKEN
ProcessTime
X-Tec-Api-Version
X-Pjax-Url
Origin
X-Tec-Api-Origin
X-Tec-Api-Root
X-Correlation-ID
X-B3-Parentspanid
X-Sucuri-ID
X-CSRF-Token
User-Agent
X-Varnish-Cacheable
Memory
X-Wa
X-Unique-ID
X-Ua
X-Via-CDN
X-Pf-Uncompressing
X-NC
TTL
X-B3-SpanId
Geoip-Latitude
X-Server-IP
X-Developer
Geoip-City
X-Node-Id
X-Vcl-Version
X-NWS-UUID-VERIFY
SRV
X-Device-Os
X-Cdn-Origin
X-Cache-Grace
X-LAGOON
X-Sn-Servicetimems
X-Ocache
GeoIp-Country-Code
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Object-Type
On-Server
X-NGINX-Cache
X-COUNTRY
PICS-Label
X-Cache-Status-Check
Tcn
Hostname
A
X-Request-Host
X-MSEdge-Flight
Media-Length
X-Cdn-Request-ID
X-MSEdge-Features
Cloudfront-Viewer-Country
Dnion-Transfer-Encoding
X-Servedbyhost
SN
X-Webkit-CSP
X-Rocket-Nginx-Bypass
M-TraceId
X-Litespeed-Cache
X-Varnish-Ttl
X-Via-Ucdn
X-TIME
XServer
X-Sucuri-Id
Cdn
X-FORWARDED-FOR
X-ServedByHost
X-AIR-PT
X-Varnish-URL
X-HS-Status
Esi-Enabled
X-Reqid
Host-ID
X-Ratelimit-Remaining
X-Planisys-CDN-Cache
X-Beluga-Response-Time
X-Beluga-Trace
X-Beluga-Status
X-Beluga-Record
X-Beluga-Node
X-Beluga-Cache-Status
X-Planisys-CDN-Rules
X-Fastly-Country-Code
Resin-Trace
X-Planisys-CDN-TTL
Who
X-Policy
X-Cache-Ttl
HostName
CACHE
X-Slack-Backend
X-Request-Start
CF-Cached-On
X-Azure-Ref-OriginShield
Pics-Label
Rt-Proxy-Cache
X-Fastly-Backend-Reqs
GeoIP-Country-Code
X-Action
X-LiteSpeed-Cache-Control
GeoIP-Latitude
X-VCL-Version
X-DI
Pramga
Arc-Country
X-Server-Time
X-Cache-FS-Status
X-PAYTM-SRV-ID
X-Dispatch
X-Processor
X-HostName
X-DSS
X-DB
X-RSL
X-DW
X-RPM
X-RPS
X-Ftr-Cache-Host
X-Oracle-Dms-Rid
MIME-Version
X-ND-Cache
Ttl
X-Hello
X-Bc
X-APP
X-Varnish-Url
X-ABtesting
X-Flog
Magicmarker
X-Zone
GeoIP-City
NtCoent-Length
X-Method
X-PF-Uncompressing
X-DC
X-FPC
X-Newrelic-App-Data
X-Ratelimit-Limit
X-Served-From
Cdn-Request-Time
Fastly-Drupal-HTML
X-VarnishDD-TTL
Cdn-Host
X-Skip-Cache
X-Edge-Server
Cteonnt-Length
WebServer
N-Cache
X-Bc-Bl
Amp-Access-Control-Allow-Source-Origin
X-DevSite-Last-Modified
X-SRV
X-PJAX-URL
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Io-Id
Section-Origin-Responded
X-WA
X-BE
Processtime
Ohc-Response-Time
X-Backend-Host
X-Be
X-Amzn-Remapped-Connection
X-Svr
X-Amzn-Remapped-Date
X-Dynatrace
X-Dynatrace-Js-Agent
Load-Balancing
X-Swift-Error
Servername
X-BC
Cache-Provider
X-ID
Vix-Hermes-Req-Id
X-Aicache-OS
X-ZONE
X-Frame-Option
X-WR-MODIFICATION
X-LB-ID
X-Snapshot-Date
Dynatrace
Requestid
X-MServer
X-Branch-Name
CF-IPCountry
X-Fmm-Version
Lfy
Cache-Cookie-Set-Idcheck
FSS-Cache
Cache-Cookie-Set-From
X-Fastly-Cache-Hits
Cache-Cookie-Set-Lfrom
FSS-Proxy
X-Adobe-Source
CDN
DSUID
X-StackifyID
Pagetype
X-VCT
X-CACHE-AGE
Release
X-Scheme
Fusion-Deployment-Id
Trailer
X-Tid
WZWS-RAY
X-VC
V-Cache
X-Apw-Access-Object
X-SB
X-Hp-Ccpa-Warning
X-Configured-By
X-Request-Url
Proxy-Firewall
X-Apw-Access-Token
X-Apw-Access-Action
X-Cc-Via
Warning
X-Apw-Hits
X-Cc-Req-Id
D-Cc-Upstream
X-Litespeed-Cache-Control
X-ServerName
Backend-Name
X-Edge-IP
X-App
X-Worker
Correlation-Id
Cneonction
X-Fpc
WP-Super-Cache
X-Check-Cacheable
X-Upstream-Ht
X-Upstream-Ct
X-Varnish-Beresp-TTL
X-Request-URL
X-Powered-Y
X-SD-PageType
X-Fastly-Cache-Status
SD-X-WS
X-ElasticPress-Search
X-WPE-Loopback-Upstream-Addr