Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
CF-RAY
Link
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Request-ID
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-Template
X-DNS-Prefetch-Control
X-Language
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-Buckets
Status
X-Content-Security-Policy
Upgrade
Content-Encoding
X-CDN
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
X-Xss-Protection
Keep-Alive
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
P3p
Xkey
X-Pass-Why
X-Cache-Group
X-AH-Environment
X-Envoy-Upstream-Service-Time
CF-Ray
X-Via
X-Backend
X-Age
X-Server
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Server-Powered-By
X-Page-Speed
X-Ws-Request-Id
X-Pingback
EagleId
X-Proxy-Cache
X-Hacker
X-Nginx-Cache-Status
X-UA-Device
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
Cf-Railgun
Grace
X-Ua-Compatible
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Amz-Version-Id
Report-To
X-LiteSpeed-Cache
X-Rq
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-WebKit-CSP
X-Server-Id
X-Host
X-Device
X-OneAgent-JS-Injection
X-Origin-Cache
EagleEye-TraceId
X-Response-Time
X-Node
X-Ac
Content-Location
Surrogate-Control
X-Vhost
X-Readtime
X-Cloud-Trace-Context
Request-Id
X-Backend-Server
X-Dns-Prefetch-Control
X-Dispatcher
X-Origin-Upstream-Status
X-Cnection
X-Application-Context
X-HW
X-Cache-Lookup
X-ORACLE-DMS-ECID
Fusion-Content-Id
Fusion-Template-Id
Fusion-Content-Source
Fusion-Component-Id
Fusion-Source
X-ORACLE-DMS-RID
X-DataDome
NEL
X-Mod-Pagespeed
X-Ruxit-JS-Agent
X-Rack-Cache
Rating
Edge-Control
X-Akam-SW-Version
X-Clacks-Overhead
Pinterest-Generated-By
X-Country
X-TTL
Allow
X-Country-Code
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-DynaTrace
X-Instart-Request-ID
X-Varnish-TTL
X-FTR-Request-ID
X-Goog-Hash
X-Vname
X-PC
X-TtlSet
Accept-Ch
Verso
X-ESI
X-Powered-By-Plesk
Content-MD5
Service-Worker-Allowed
Accept-Ch-Lifetime
X-B3-TraceId
X-Forwarded-Proto
X-Version
X-MS-InvokeApp
X-Url
X-Exp-Id
X-Cdn-Fetch
X-Kinja-Build
X-Exp-Variant
X-Kinja-Revision
X-Kinja-Server
X-Use-Magma
X-GoogleNews-Bot
X-Kinja
X-GitHub-Request-Id
RTSS
Edge-Cache-Tag
X-Abt-Application-Version
X-D2id
X-Debug
X-Px
AR-Request-ID
AR-CACHE
AR-ATIME
Ar-Sid
AR-PoweredBy
X-Server-Name
SPRequestGuid
X-Amz-Server-Side-Encryption
Charset
X-NF-Request-ID
X-Cached
X-Accel-Expires
X-Vcache
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
Pagespeed
X-Sol
Display
X-Middleton-Display
X-Middleton-Response
Response
X-MSEdge-Ref
X-Vcap-Request-Id
X-Amz-Rid
Arr-Disable-Session-Affinity
X-Navigation-Version
TCN
X-Powered-CMS
X-Pinterest-Rid
Pinterest-Version
X-SharePointHealthScore
X-Fastcgi-Cache
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Trace
X-Cdn
X-VARITI-CCR
Realpath
Public-Key-Pins
Cache-Tag
X-Client-IP
X-Fastly-Request-ID
Access-Control-Request-Method
X-Ser
MS-Author-Via
Nginx-Cache
X-Server-ID
X-DynaTrace-JS-Agent
S
X-Shard
X-Edge-O15-RID
SPRequestDuration
SPIisLatency
X-Upstream
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
X-Id
Mrf-Cache-Status
MRF-Tech
X-Content-Type
X-Ezoic-Cdn
X-Hp-Webp
X-Amzn-Trace-Id
X-Grace
X-T
X-Amz-Meta-S3cmd-Attrs
Nel
Front-End-Https
Fastcgi-Cache
X-Hits
X-Recruiting
X-Forwarded-For
DynaTrace
X-Aspnet-Version
X-Varnish-Age
X-Jurisdiction
ServerID
X-Cache-TTL
X-Node-Name
X-FTR-Expires
X-Country-Code-Real
X-FTR-Cache-Status
MicrosoftSharePointTeamServices
X-Dw-Request-Base-Id
X-DIS-Request-ID
X-Element-Page-Cache
X-Content-Digest
X-Mobile-URL
NR-ENABLED
X-FTR-Backend
X-FTR-DC
X-FTR-Realm
X-FTR-Balancer
X-FTR-Backend-Server
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
X-Frontend
Powered
X-Goog-Metageneration
X-Goog-Generation
X-GUploader-UploadID
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
Server-Node
TP-L2-Cache
TP-Cache
Alternate-Protocol
Server-Name
X-Logged-In
X-Correlation-Id
X-XRDS-Location
X-Request-Processing-Time
X-CST
X-Request-Received
AMP-Access-Control-Allow-Source-Origin
X-Amz-Apigw-Id
X-Amzn-RequestId
Upgrade-Insecure-Requests
X-Request-Handler-Origin-Region
X-Microsite
X-ATS-Timestamp
Backend-Timing
X-Cache-Hit
X-Content-Options
X-URL
X-Page-Id
X-Origin-Server
X-F-Cache
X-User-Agent
X-Content-Security-Policy-Report-Only
Refresh
X-Rid
X-Varnish-Grace
X-Revision
X-Akamai-Edgescape
X-Type
Fastly-Restarts
X-Zen-Fury
X-XRDS-LOCATION
X-Content-Powered-By
X-LB-Cache
X-B3-Sampled
X-B
X-Geo-Country
X-FTR-Cache-Host
X-Az
X-Activity-Id
X-AppVersion
PB-PID
PB-RID
Arc-Version
X-Mobile-Rewrite
X-Shield-Request-Id
Cache-Status
X-N
X-Kinsta-Cache
X-Pad
X-Cache-Age
X-TT
X-Instance
X-Request-Guid
X-WebKit-CSP-Report-Only
X-AOL-HN
X-Signature
Access-Control-Allow-Method
X-B-Cache
X-App-Environment
X-Framework
X-Jobs
X-Cache-Action
Actual-Object-TTL
X-Tumblr-Pixel
X-Load-Cache
X-Tumblr-Pixel-0
X-Tumblr-User
Paypal-Debug-Id
X-Debug-Info
X-Webkit-Csp
X-PHP-Backend
X-FB-Debug
DC
X-Webapp-Samesite-None-Activated-N
X-Cached-By
X-Git-Hash
Fastcgi-Useragent
X-Time
X-Varnish-Backend
X-Tt-Trace-Tag
X-RateLimit-Remaining
X-Tt-Trace-Host
X-Analytics
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
Host-Header
Surrogate-Key
X-Amz-Replication-Status
X-IPLB-Instance
X-Contextid
MS-CV
FilterID
X-ATG-Version
X-SS-Set-Cookie
Accept-CH
X-FastCGI-Cache
X-WA-Info
X-Cache-Key
Host
X-Cluster
X-VCache
Tracecode
X-Mobile
X-Accel-Buffering
X-Host-Name
NGB
X-Response-Served-From
X-Via-JSL
X-Kong-Proxy-Latency
X-ORACLE-APMCS-TAG
X-ORACLE-APMCS-REQUEST-ID
Payment
X-Kong-Upstream-Latency
X-Presslabs-Stats
WPE-Backend
X-FW-Server
X-FW-Static
X-FW-Type
X-NWS-LOG-UUID
X-FW-Serve
X-Cache-NE
X-FW-Hash
X-Cacheable-TTL
X-Hostname
Cache-Tv-Group
Frame-Options
X-Varnish-Server
X-Cache-2
X-Region
Eomportal-Instance
Source
X-Cache-Rule
X-Tumblr-Pixel-2
X-Cache-Operation
X-Rendered-As
X-Tumblr-Pixel-1
X-Varnish-Hostname
X-Is-Bot
X-Cache-Enabled
X-GeoIP
Filters
X-IPS-LoggedIn
X-Origin-Response-Time
X-Adobe-Loc
X-Adobe-Content
X-Ruxit-Js-Agent
X-RequestSource
X-TX-ID
X-Seen-By
X-NewRelic-App-Data
X-EdgeConnect-Cache-Status
Xserver
Retry-After
X-Srv
Accept-CH-Lifetime
Server-Info
Cleartype
X-Cache-TTL-Remaining
X-ProcessESI
X-RemovedCookies
Liferay-Portal
X-UA
X-B3-Traceid
X-HTML-Minification-Powered-By
X-Dc
Cache
X-RTag
Ms-Operation-Id
X-App-Server
X-Source
Datacenter
X-Environment-Context
X-L-Path
X-FireWall-Port
X-Endurance-Cache-Level
X-Handled-By
X-Upgrade-Enabled
From-Origin
X-Cache-Control
X-Cache-Server
Healthy
X-CACHE-KEY
X-Esi
X-APP-VERSION
X-Backend-Name
X-Wix-Request-Id
X-Status
Version
OT-Force-Account-Verify
Node
X-Path-Route
Meta-Geo
GEO-INFO
X-Cache-Var
X-RN-RSRV
Ec-Rule-Version
X-Cache-Var-Map
Srv
X-ES-SERVER
X-Timing-Wait
X-Tb
X-Storage
X-BCube-Filmed-By
X-Request-Time
X-Akamai-Request-ID
X-Access
X-Proxy-Build
X-Rule
X-Format
Selected-Fe
X-Section
X-Proto
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Hosted-By
X-TNCMS
X-PCL
X-Origin
X-FW-Dynamic
X-Content-Age
X-Proxy-Cache-Status
X-OCL
X-Alternate-Cache-Key
X-Loop
X-Shopify-Generated-Cart-Token
Mn-Server-Ip
X-EIG-Tracking-Id
X-Shopify-Stage
Azure-Version
Azure-SlotName
Akamai-GRN
Azure-InstanceId
Azure-RegionName
Azure-SiteName
S-Rt
X-Sorting-Hat-PodId
X-ShopId
X-FC-Vary-Parameters
X-UUID
X-NYM-Debug-Backend
X-Cache-Config
X-Web-Node
X-Sorting-Hat-ShopId
X-Soup
X-Time-Microsecs
X-ShardId
Cache-Tags
X-RateLimit-Limit
X-BYPASS-REASON
X-AWS-Id
X-Debug-Cache
X-Hl-Ver
X-Human
X-Akamai-Request-ID2
X-Generated-By
Origin-Edge-Control
Decoy-Debug-Status
Decoy-Debug-Key
DB-Nickname
Decoy-Debug-TTL
NGX
Origin-Cache-Control
Now
X-Hyper-Cache
X-JoinUs
X-Viewer-Country
X-Vgn-Hpd-Reason
X-ServerID
X-VWS-Id
X-Say-Cacheable
X-SayCDN-TTL
X-Say-TTL
X-SaId
X-Redis-Cache
X-Proxy
X-MP-GENERATED-AT
X-LJ-Flow-ID
X-ProxyCache-Key
X-ProxyCache-Status
X-Qloud-Router
X-Pubstack
Accept-Charset
X-Cluster-Node
X-Yottaa-Optimizations
X-Yottaa-Metrics
Webcakes-App-Name
TWC-Privacy
Webcakes-App-Version
Webcakes-Region
TWC-Locale-Group
X-Www-Served-By
TWC-GeoIP-Country
TWC-Connection-Speed
Property-Id
X-FB-TRIP-ID
TWC-Device-Class
X-Cache-Host
TWC-GeoIP-LatLong
X-Varnish-Hits
X-IP
X-Locale
X-Origin-Hint
X-PressLabs-Stats
X-Site-Version
X-Generated
X-Amzn-Remapped-Content-Length
Cross-Origin-Window-Policy
X-CCM
X-Detected-As
X-RCS-CacheZone
X-Xfnlog-Site
X-R9-Blue-Green-Version
X-Akamai-Transformed
X-Ttl
X-NCache
X-Unique-Id
L5d-Success-Class
Time
X-CS
Cache-Name
X-Drupal-Cache-Tags
Uber-Trace-Id
Viewport
Webserver
Cache-Key
X-UA-Device-Type
X-Backend-TTL
X-UnsetCookies
X-Cache-Remote
X-CDN-Forward
Rt-Fastcgi-Cache
X-Mode
X-Forwarded-Host
Accept-Language
X-Origin-CC
X-From
X-Origin-TTL
Country
X-Whom
X-Trafficlayer-App-Name
X-Trafficlayer-App-Scope
X-Drupal-Cache-Contexts
Mime-Version
X-Daa-Tunnel
X-Info
X-NGENIX-Cache
X-B3-Spanid
X-Magnolia-Registration
X-Cluster-Name
VIX-Pulpo-Node
X-Newrelic-Synthetics
VIX-Pulpo-Upstream-Status
Odigeo-Trace-Id
X-Varnish-Cache-Hits
Content-Disposition
X-Microcachable
X-TT-TIMESTAMP
X-PERF
X-CLOUD-TRACE-CONTEXT
X-ApacheServer
X-Edge-Location
ServedBy
X-Litespeed-Cache
X-Geo
X-Oneagent-Js-Injection
X-EC-Lua
X-Routing-Service
X-Proxied
X-Zipkin-Id
X-Device-Type
X-Via-Fastly
Proxy-Connection
X-UPSTREAM-Address
Cf-Ipcountry
Ohc-File-Size
Section-Io-Cache
Ohc-Cache-HIT
X-Uri
X-No-Session
HitType
AsisCache
Xc-Version
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Request-Url
Apple-News-Services-Handled
BehaviorPad-Version
Content-Script-Type
Content-Style-Type
VivaBuild
X-Destination
X-Date
X-DPWN-IS-SECURE
X-External-Request-Id
X-G
X-Transaction
X-Trv-Group
X-CF-Lambda-Fn
X-Twitter-Response-Tags
X-CF-Lambda-Version
X-Connection-Hash
X-D
X-Geo-Header
X-GeoIP-Country-Code
X-Rewrite-Enabled
X-Request-UUID
X-Rocket-Build-Number
X-Rojux
X-S
X-ScT
X-Region-Sid
X-SRCache-Key
X-Sigma-Backend
X-Sigma
X-Session-Fingerprint
X-B-Cookie
X-ARC
T-Server
Rendered-Blocks
X-Vtex-Processado-Em
Viewtype
X-S-Cookie
Mobile-Detection-Method
Meta-Geo-Continent
Fastcgi-X-Cache-Version
GEO-REGION-INFO
Machine
MD5-Digest
W
X-VG-WebServer
X-A-Wwc
X-VG-TLSProxy
X-Accel-Expires-Debug
X-Application
X-Vdms-Version
X-A-Dgt
X-A-Dcw
X-A
X-VG-WebCache
X-A-Ccd
X-A-Dam
X-Vtex-Remote-Cache
X-Aed
X-C
X-PHP-Host
X-Labrador-Cache-Channel
X-GoCache-CacheStatus
X-Nc
User-Cache-Control
Environment
Gh-Request-Id
X-Real-IP
X-Distil-CS
X-Developers
Fastly-Soc-X-Request-Id
Fastly-SSL
X-SIPLIST1
X-TrackingId
X-Tumblr-Pixel-3
X-Thanos
CDCHOST
X-CUA
X-Contensis-Viewer-Groups
Ha-Gx-Prefs
X-Auto-Login
X-Li-Pop
X-LI-Proto
Memcached
X-Li-Fabric
Server-Cache-Control
X-Hit
Powered-By
X-LI-UUID
X-Logging-Id
IsBot
IBM-Web2-Location
X-CGP
X-Eu-Site
Server-Surrogate-Control
X-FW-Version
Locid
HA-Ipaddr
X-TH-Server
X-Clientip
X-Agile
X-Agile-Age
X-Cache-ASPX
X-Cache-Debug
X-Wikidot-Static-Cache
Countrycode
Fastly-SWR
X-Agile-Id
X-Bip
X-App-Name
X-Backend-State
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Status
X-Rebelmouse-Surrogate-Control
X-Varnish-Beresp-Grace
X-Rebelmouse-Cache-Control
X-Wikidot-Backend
Fastly-SIE
X-User
X-We-Are-Hiring
X-Varnish-Authentication
Access-Control-Request-Headers
X-WebServer
X-VC-Cache
X-VServer
X-Cache-Backend
X-Cms-Context
X-Hash
X-BBXSRF
X-Clara-WADP
X-GeoIP-City
X-Azure-Ref
X-Generation-Time
X-Generated-In
X-Block-Status
X-Gen-Mode
X-Gamma-Serve
X-Core-Mission
X-Distributor
X-Cdn-Srv
X-Dispatcher-Server
X-Cache-Info
X-Debug-Cookies
X-Cache-Time
X-Debug-Cache-Store
X-Cache-Bucket
X-Cache-URL
X-Debug-Log
X-Fastly-Cache
X-Epic-Correlation-Id
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-Fetched-On
X-Origin-Date
X-WADP-Cache
X-Webstats-RespID
Adler-Geo
Is-Eu
X-Urbn-Site-Id
X-Urbn-Context-Path
X-SVT-ORM-VERSION
X-Swa-Ws
X-Trace-Id
X-TT-LOGID
Platform
X-Cache-Tags
X-Platform-Server
X-Servername
X-Up
X-Variation
X-NU-AKA-ACS-Version
X-JWT-State
X-Has-Esi
X-Internal-Host
X-Is-Gdpr
X-SVT-ORM-RULES
X-Server-W
X-Micro-Cache
X-Ms-Request-Id
X-Ms-Version
X-Nginx-Cache-Key
X-Key
X-Irp-Debug
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Instart-Isnd
X-NodeID
X-NX-Host
X-RateLimit-Remaining-Second
X-Reboot
X-Render-Time
X-Request-URI
X-RateLimit-Limit-Second
X-Proxy-Upstream
X-Origin-Expires
X-OVcl
X-Owner
X-Hnp-Log
X-OVcl-Cache
Server-Int
Server-ID
Country-Code
True-Client-Country-4JS
Cdncip
We-Hiring
Cache-Host
V-Age
RNT-Time
RNT-Machine
Kp-EeAlive
Locale
Mail-Subject
Heartbleed
Fastly-Backend-Name
Request-EU
Request-Country
Web-Mar-Node
Cdnsip
AKAMAI
X-AK-Request-ID
Geo-Info
X-COUNTRY
Server-Host
X-Generated-On
X-Matched-Rule
Thinkindot-Control
Thinkindot-CacheControl
X-ServiceProvider
X-Sucuri-Cache
Thinkindot-CacheControl-Type
X-Req
FNAC-ModuleRouting
X-Old-Content-Length
ServerName
Wxu-Next-Hostname
Wxu-Next-Region
Wxu-Next-Commit
X-Level-Front-Cache
X-Thinkindot-L3
X-Trafficlayer-App-Version
PFcat
X-Core-Value
X-Service
X-Nginx-Cache
X-Location
X-Air-Hostname
X-Response-By
X-SERVER
X-S-Maxage
X-TA-CDN-Provider
Cache-Hits
X-App-Version
X-Refresh
Group
RequestId
Pragrma
X-Var-Ttl
X-Lb-Id
X-Cache-Expired-At
S-Cnection
X-Parent-Response-Time
Memory
X-Tb-Optimization-Total-Bytes-Saved
X-CSRF-TOKEN
Filterid
X-B3-Parentspanid
X-Tec-Api-Version
X-Tec-Api-Root
Powered-By-ChinaCache
X-Tec-Api-Origin
X-NC
X-CF-Powered-By
X-Wa
ProcessTime
X-Cdn-Forward
User-Agent
X-Pjax-Url
X-Pf-Uncompressing
Origin
X-BACKEND-TTL
X-B3-SpanId
Geoip-Latitude
X-Server-IP
X-CSRF-Token
X-Sucuri-ID
Geoip-City
X-Varnish-Cacheable
X-NWS-UUID-VERIFY
GeoIp-Country-Code
X-Ua
SRV
X-Correlation-ID
X-Via-CDN
PICS-Label
TTL
X-FORWARDED-FOR
X-Developer
X-Vcl-Version
X-Cdn-Request-ID
Media-Length
X-NGINX-Cache
X-TIME
X-Unique-ID
X-Servedbyhost
X-Cache-Grace
X-Device-Os
XServer
X-Node-Id
X-LAGOON
X-Ocache
X-Sn-Servicetimems
X-Cdn-Origin
Dnion-Transfer-Encoding
X-Webkit-CSP
X-Sucuri-Id
On-Server
X-Rocket-Nginx-Bypass
A
X-MSEdge-Features
X-MSEdge-Flight
X-Cache-Status-Check
SN
X-Via-Ucdn
X-Request-Host
X-Varnish-Ttl
X-Oss-Storage-Class
X-Oss-Object-Type
Hostname
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
M-TraceId
X-AIR-PT
X-HS-Status
Cloudfront-Viewer-Country
Esi-Enabled
X-Reqid
X-Beluga-Response-Time
X-Planisys-CDN-Cache
X-Beluga-Node
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Beluga-Cache-Status
X-Beluga-Record
X-Policy
X-Beluga-Status
X-Beluga-Trace
X-Ratelimit-Remaining
X-ServedByHost
X-Request-Start
X-Cache-Ttl
X-Fastly-Country-Code
Resin-Trace
X-Azure-Ref-OriginShield
Cdn
Who
X-Ftr-Cache-Host
X-VHOST
HostName
Tcn
CF-Cached-On
X-Varnish-URL
Host-ID
Rt-Proxy-Cache
MIME-Version
X-VCL-Version
NtCoent-Length
Cteonnt-Length
X-APP
Pics-Label
Magicmarker
X-Slack-Backend
X-Method
Ttl
GeoIP-Country-Code
X-Oracle-Dms-Rid
X-SRV
X-Fastly-Backend-Reqs
X-Varnish-Url
X-DB
X-RSL
GeoIP-Latitude
X-DSS
X-Action
X-RPS
X-DW
X-RPM
X-DI
X-LiteSpeed-Cache-Control
X-DC
GeoIP-City
X-Ratelimit-Limit
X-Zone
X-Processor
X-PJAX-URL
X-Server-Time
X-Skip-Cache
X-VarnishDD-TTL
X-PAYTM-SRV-ID
X-Cache-FS-Status
X-FPC
Pramga
Arc-Country
CACHE
X-PF-Uncompressing
X-Bc
X-Dispatch
X-Newrelic-App-Data
X-Swift-Error
X-Flog
Load-Balancing
Ohc-Response-Time
Amp-Access-Control-Allow-Source-Origin
X-ABtesting
Processtime
X-Svr
X-ND-Cache
X-Be
X-Hello
X-Ftr-Request-Id
WebServer
X-DevSite-Last-Modified
X-Dynatrace
Cdn-Request-Time
X-Edge-Server
X-Served-From
Cdn-Host
Fastly-Drupal-HTML
N-Cache
X-HostName
Vix-Hermes-Req-Id
X-BE
X-Dynatrace-Js-Agent
Servername
X-MServer
DSUID
X-LB-ID
X-Bc-Bl
X-Aicache-OS
Cache-Provider
X-Amzn-Remapped-Date
X-ID
X-Amzn-Remapped-Connection
X-ZONE
Release
CDN
X-WA
X-VCT
X-Frame-Option
X-Hp-Ccpa-Warning
X-WR-MODIFICATION
X-Ftr-Backend-Server
X-Ftr-Balancer
Dynatrace
X-Ftr-Backend
X-Backend-Host
Pagetype
X-Snapshot-Date
X-Fastly-Cache-Hits
X-StackifyID
X-Configured-By
X-Tid
X-Ftr-Dc
Requestid
Lfy
X-BC
CF-IPCountry
X-Branch-Name
X-Ftr-Realm
Section-Io-Origin-Time-Seconds
Section-Io-Id
Section-Io-Origin-Status
X-CACHE-AGE
Section-Origin-Responded
WZWS-RAY
X-Request-Url
X-Apw-Hits
X-Cc-Via
X-SD-PageType
SD-X-WS
X-Apw-Access-Token
X-Apw-Access-Object
X-Upstream-Ht
X-Upstream-Ct
Proxy-Firewall
X-Apw-Access-Action
V-Cache
X-Edge-IP
Warning
X-Cc-Req-Id
D-Cc-Upstream
X-SB
X-VC
X-Litespeed-Cache-Control
Backend-Name
X-Compress-Hint
X-Cache-Id
FSS-Proxy
FSS-Cache
Cneonction
X-WPE-Loopback-Upstream-Addr
Correlation-Id
X-Check-Cacheable
WP-Super-Cache
X-Powered-Y
X-ElasticPress-Search
Lb
L
X-ServerName
X-Request-URL
X-Fastly-Cache-Status
X-Varnish-Beresp-TTL
X-SN
X-Worker
X-App