Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
CF-RAY
Link
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-UA-Compatible
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-Request-ID
X-Template
X-Language
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Iinfo
X-AspNetMvc-Version
X-Ua-Compatible
X-FRAME-OPTIONS
X-Buckets
Status
X-Content-Security-Policy
X-CDN
Upgrade
Content-Encoding
P3p
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Xss-Protection
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
Xkey
X-Pass-Why
X-Cache-Group
X-AH-Environment
X-Envoy-Upstream-Service-Time
CF-Ray
X-Backend
X-Age
X-Server
X-Via
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Server-Powered-By
X-Page-Speed
X-Pingback
EagleId
X-Proxy-Cache
X-Nginx-Cache-Status
X-Ws-Request-Id
X-UA-Device
X-Hacker
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
Grace
Cf-Railgun
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Amz-Version-Id
X-Dns-Prefetch-Control
X-LiteSpeed-Cache
Report-To
X-Server-Id
X-Rq
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Host
X-WebKit-CSP
X-Device
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Origin-Cache
X-Response-Time
Content-Location
X-Node
X-Ac
Surrogate-Control
X-Vhost
X-Readtime
Request-Id
X-Backend-Server
X-Dispatcher
X-Cloud-Trace-Context
X-Origin-Upstream-Status
X-Cnection
X-HW
X-ORACLE-DMS-ECID
X-Application-Context
X-DataDome
Fusion-Component-Id
Fusion-Source
Fusion-Content-Id
Fusion-Content-Source
Fusion-Template-Id
X-ORACLE-DMS-RID
X-Cache-Lookup
NEL
X-Mod-Pagespeed
Edge-Control
X-Rack-Cache
Rating
X-Country
X-Akam-SW-Version
X-Clacks-Overhead
Pinterest-Generated-By
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Ruxit-JS-Agent
X-Varnish-TTL
X-DynaTrace
X-Country-Code
Accept-Ch
Allow
X-Instart-Request-ID
X-Goog-Hash
X-TtlSet
X-PC
X-Vname
X-FTR-Request-ID
X-TTL
X-ESI
Verso
Accept-Ch-Lifetime
X-Powered-By-Plesk
X-Url
Service-Worker-Allowed
Content-MD5
X-B3-TraceId
X-Forwarded-Proto
X-Version
X-MS-InvokeApp
X-GitHub-Request-Id
X-Kinja-Build
X-GoogleNews-Bot
X-Exp-Variant
X-Exp-Id
X-Cdn-Fetch
X-Kinja
X-Use-Magma
X-Kinja-Revision
X-Kinja-Server
Edge-Cache-Tag
RTSS
Ar-Sid
AR-PoweredBy
AR-Request-ID
AR-CACHE
AR-ATIME
X-Px
X-D2id
X-Debug
X-Abt-Application-Version
X-Server-Name
Charset
X-NF-Request-ID
SPRequestGuid
X-Vcache
X-Amz-Server-Side-Encryption
X-Accel-Expires
X-MSEdge-Ref
X-Cached
X-Powered-CMS
X-Amz-Rid
X-TEC-API-ORIGIN
X-TEC-API-ROOT
Arr-Disable-Session-Affinity
X-TEC-API-VERSION
Display
X-Middleton-Display
Pagespeed
X-Sol
Response
X-Middleton-Response
X-Vcap-Request-Id
X-Navigation-Version
X-Trace
Pinterest-Version
X-Pinterest-Rid
X-SharePointHealthScore
X-SRCache-Fetch-Status
X-SRCache-Store-Status
TCN
X-VARITI-CCR
Realpath
Public-Key-Pins
X-Fastcgi-Cache
X-Client-IP
Cache-Tag
X-Cdn
Access-Control-Request-Method
X-Fastly-Request-ID
X-Ser
S
X-Upstream
MS-Author-Via
X-DynaTrace-JS-Agent
X-Shard
SPIisLatency
SPRequestDuration
X-Id
Nginx-Cache
X-Hp-Webp
X-Ezoic-Cdn
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
X-Content-Type
MRF-Tech
X-Mrf-Item-Lastmod
Mrf-Cache-Status
X-Forwarded-For
X-T
X-Amz-Meta-S3cmd-Attrs
DynaTrace
X-Amzn-Trace-Id
X-Recruiting
X-Grace
Front-End-Https
X-Hits
Nel
Fastcgi-Cache
X-Varnish-Age
X-Aspnet-Version
X-DIS-Request-ID
ServerID
X-Dw-Request-Base-Id
X-Edge-O15-RID
MicrosoftSharePointTeamServices
X-Mobile-URL
X-Element-Page-Cache
X-Node-Name
NR-ENABLED
X-Content-Digest
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Hub-Id
X-HS-Combine-CSS
X-Goog-Generation
X-Goog-Metageneration
X-FTR-Cache-Status
X-Country-Code-Real
X-Goog-Storage-Class
X-FTR-Expires
X-Goog-Stored-Content-Encoding
X-Frontend
Powered
X-GUploader-UploadID
X-Goog-Stored-Content-Length
Server-Name
X-Cache-TTL
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Realm
Alternate-Protocol
X-FTR-DC
X-Logged-In
TP-Cache
TP-L2-Cache
Server-Node
X-Correlation-Id
X-Jurisdiction
X-XRDS-LOCATION
X-Request-Received
X-Webkit-Csp
X-Request-Processing-Time
X-Microsite
X-Request-Handler-Origin-Region
X-ATS-Timestamp
Backend-Timing
AMP-Access-Control-Allow-Source-Origin
Upgrade-Insecure-Requests
X-Page-Id
X-Content-Options
Refresh
X-Content-Security-Policy-Report-Only
X-Origin-Server
X-Shield-Request-Id
X-Rid
X-Akamai-Edgescape
X-F-Cache
X-Revision
X-User-Agent
X-Cache-Hit
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Varnish-Grace
X-Server-ID
X-Type
X-Webapp-Samesite-None-Activated-N
X-XRDS-Location
Fastly-Restarts
X-Content-Powered-By
X-Zen-Fury
X-Geo-Country
X-LB-Cache
X-B3-Sampled
X-Az
X-AppVersion
X-Activity-Id
X-B
X-Pad
X-Analytics
X-URL
X-N
X-FTR-Cache-Host
X-Kinsta-Cache
PB-PID
PB-RID
X-CST
X-RateLimit-Remaining
Arc-Version
X-Mobile-Rewrite
X-TT
Cache-Status
X-AOL-HN
X-WebKit-CSP-Report-Only
X-Cache-Age
X-Instance
X-Request-Guid
Paypal-Debug-Id
X-App-Environment
DC
Actual-Object-TTL
X-Ruxit-Js-Agent
X-B-Cache
X-Framework
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel
X-Signature
X-Jobs
X-Debug-Info
Access-Control-Allow-Method
X-PHP-Backend
X-FB-Debug
X-Cache-Action
X-Time
X-Load-Cache
X-Git-Hash
X-Varnish-Backend
X-Erf-Bev-Bev-Is-Generated
Surrogate-Key
X-Erf-Bev-Bev
X-Cached-By
Fastcgi-Useragent
X-Tt-Trace-Tag
Host-Header
X-Ttl
X-IPLB-Instance
X-Contextid
X-Amz-Replication-Status
X-FastCGI-Cache
MS-CV
X-SS-Set-Cookie
X-Tt-Trace-Host
FilterID
X-Cluster
X-ATG-Version
Tracecode
X-Srv
X-Response-Served-From
X-Accel-Buffering
NGB
Frame-Options
X-WA-Info
Xserver
X-Cache-NE
WPE-Backend
X-Cache-Key
Eomportal-Instance
X-Mobile
X-FW-Server
Payment
X-Varnish-Server
X-Region
X-FW-Type
X-FW-Serve
X-FW-Static
X-FW-Hash
X-Adobe-Content
X-Rendered-As
X-Is-Bot
X-IPS-LoggedIn
X-RequestSource
X-Tumblr-Pixel-1
X-Cache-2
X-Varnish-Hostname
X-Tumblr-Pixel-2
X-GeoIP
X-Cacheable-TTL
Filters
Cache-Tv-Group
X-Kong-Upstream-Latency
Host
Source
X-Cache-Enabled
X-Adobe-Loc
X-Kong-Proxy-Latency
X-Host-Name
X-TX-ID
X-NewRelic-App-Data
X-EdgeConnect-Cache-Status
X-Via-JSL
X-Cache-Rule
X-Cache-Operation
Cleartype
X-Seen-By
X-Oneagent-Js-Injection
X-Origin-Response-Time
X-Hostname
X-ORACLE-APMCS-TAG
X-ORACLE-APMCS-REQUEST-ID
X-Cache-TTL-Remaining
Cache
X-Presslabs-Stats
Retry-After
X-HTML-Minification-Powered-By
X-VCache
X-Cache-Control
Healthy
Server-Info
Datacenter
X-ProcessESI
X-UA
X-Dc
X-RemovedCookies
Accept-CH
X-Trafficlayer-App-Name
X-Trafficlayer-App-Scope
X-RTag
X-B3-Traceid
Ms-Operation-Id
X-NWS-LOG-UUID
Liferay-Portal
X-CACHE-KEY
X-Source
X-RateLimit-Limit
X-Rule
X-Cache-Server
X-Environment-Context
X-L-Path
X-PressLabs-Stats
X-FireWall-Port
From-Origin
X-Endurance-Cache-Level
X-Status
X-Wix-Request-Id
X-Upgrade-Enabled
Version
X-CLOUD-TRACE-CONTEXT
X-Handled-By
X-Cache-Var-Map
X-RN-RSRV
X-App-Server
X-Path-Route
Accept-CH-Lifetime
X-Cache-Var
Meta-Geo
X-ES-SERVER
OT-Force-Account-Verify
Selected-Fe
X-Timing-Wait
X-Proxy-Build
X-Sorting-Hat-PodId
X-Section
X-Tb
X-Alternate-Cache-Key
X-Backend-Name
X-Shopify-Stage
X-Sorting-Hat-ShopId
X-Storage
Azure-Version
X-Akamai-Request-ID
X-EIG-Tracking-Id
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Shopify-Generated-Cart-Token
Akamai-GRN
Mn-Server-Ip
X-Proto
X-Format
X-Access
X-Content-Age
Cache-Tags
X-ShopId
X-Request-Time
X-ShardId
Azure-SiteName
Azure-RegionName
Azure-SlotName
Azure-InstanceId
Origin-Cache-Control
Webcakes-App-Name
NGX
Now
TWC-Privacy
TWC-Locale-Group
Node
Property-Id
Decoy-Debug-Status
DB-Nickname
Decoy-Debug-Key
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-LatLong
TWC-GeoIP-Country
S-Rt
Ec-Rule-Version
Origin-Edge-Control
X-FC-Vary-Parameters
X-Vgn-Hpd-Reason
X-Proxy-Cache-Status
X-UUID
X-PCL
X-Origin
X-OCL
X-Proxy
X-Viewer-Country
X-Pubstack
X-ProxyCache-Key
X-ServerID
X-Time-Microsecs
X-Soup
X-SaId
X-ProxyCache-Status
X-Qloud-Router
X-Redis-Cache
X-VWS-Id
X-Human
X-Cluster-Node
X-Debug-Cache
X-FW-Dynamic
X-Cache-Host
X-Cache-Config
Webcakes-Region
X-Akamai-Request-ID2
X-AWS-Id
X-Generated-By
X-Hl-Ver
X-Origin-Hint
X-Web-Node
X-BYPASS-REASON
X-LJ-Flow-ID
X-JoinUs
X-Hosted-By
X-Hyper-Cache
Webcakes-App-Version
Decoy-Debug-TTL
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-IP
X-APP-VERSION
X-Generated
X-Detected-As
X-BCube-Filmed-By
X-CCM
X-Locale
X-Say-TTL
X-Xfnlog-Site
X-MP-GENERATED-AT
X-NYM-Debug-Backend
X-Www-Served-By
X-Varnish-Hits
X-SayCDN-TTL
X-Site-Version
X-Say-Cacheable
X-RCS-CacheZone
Cross-Origin-Window-Policy
X-Amzn-Remapped-Content-Length
X-TNCMS
X-FB-TRIP-ID
X-R9-Blue-Green-Version
X-Loop
GEO-INFO
X-Akamai-Transformed
L5d-Success-Class
Cache-Name
Accept-Charset
Viewport
X-CS
Uber-Trace-Id
Srv
X-NCache
X-Drupal-Cache-Tags
X-Unique-Id
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
X-Esi
X-Cache-Remote
X-UA-Device-Type
X-From
Webserver
Time
X-TT-TIMESTAMP
Cache-Key
X-Origin-TTL
X-Origin-CC
X-Cluster-Name
Mime-Version
Accept-Language
X-Backend-TTL
X-Edge-Location
X-Drupal-Cache-Contexts
X-CDN-Forward
Country
Odigeo-Trace-Id
X-EC-Lua
X-Mode
Rt-Fastcgi-Cache
X-Microcachable
X-Forwarded-Host
X-Info
X-B3-Spanid
Ohc-Cache-HIT
X-Newrelic-Synthetics
X-Geo
Ohc-File-Size
X-UnsetCookies
X-Whom
X-No-Session
X-PERF
X-Magnolia-Registration
X-ApacheServer
X-Webkit-CSP
ServedBy
Proxy-Connection
Content-Disposition
X-Varnish-Cache-Hits
X-UPSTREAM-Address
X-PHP-Host
X-Labrador-Cache-Channel
X-Device-Type
X-Real-IP
X-Zipkin-Id
X-Routing-Service
X-Proxied
X-S
X-S-Cookie
X-CF-Lambda-Fn
X-A-Wwc
X-Rewrite-Enabled
X-Rojux
X-ScT
MD5-Digest
X-Aed
X-G
X-Accel-Expires-Debug
X-Cache-Time
X-Session-Fingerprint
X-SRCache-Key
X-Request-UUID
Rendered-Blocks
X-Connection-Hash
X-A-Ccd
X-NGENIX-Cache
Mobile-Detection-Method
Meta-Geo-Continent
X-GeoIP-Country-Code
X-A
X-Geo-Header
X-A-Dam
Viewtype
X-CF-Lambda-Version
X-A-Dgt
X-Region-Sid
VivaBuild
X-A-Dcw
X-External-Request-Id
BehaviorPad-Version
Fastcgi-X-Cache-Version
X-DPWN-IS-SECURE
X-Vdms-Version
AsisCache
Machine
X-D
GEO-REGION-INFO
X-VG-WebCache
Content-Style-Type
T-Server
X-App-Version
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
X-VG-WebServer
X-B-Cookie
X-Twitter-Response-Tags
Content-Script-Type
X-Date
X-Via-Fastly
X-ARC
Cf-Ipcountry
X-Transaction
X-Application
Xc-Version
X-Trv-Group
X-Destination
X-Uri
User-Cache-Control
X-C
Fastly-SSL
IsBot
X-GoCache-CacheStatus
Locid
Gh-Request-Id
X-Developers
X-Logging-Id
X-CUA
X-Tumblr-Pixel-3
X-Wikidot-Static-Cache
X-Sigma
X-Wikidot-Backend
X-WebServer
X-Contensis-Viewer-Groups
Server-Surrogate-Control
X-Rocket-Build-Number
X-Auto-Login
Apple-News-Services-Request-Url
W
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
Apple-News-Services-Handled
X-VC-Cache
X-Sigma-Backend
X-Thanos
Environment
X-TrackingId
Access-Control-Request-Headers
X-Cache-Debug
Fastly-Soc-X-Request-Id
X-SIPLIST1
X-Varnish-Authentication
X-Cache-ASPX
Server-Cache-Control
X-Bip
X-VG-TLSProxy
X-Daa-Tunnel
X-Cache-Backend
X-FW-Version
X-Fastly-Cache
X-Dispatcher-Server
X-Distributor
X-Cache-Bucket
X-Cache-Info
X-Cache-URL
X-Block-Status
X-BBXSRF
X-AK-Request-ID
X-Azure-Ref
X-Clara-WADP
X-Clientip
X-Debug-Cache-Store
X-Debug-Cookies
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-Cms-Context
X-Core-Mission
X-Debug-Log
X-Rebelmouse-Surrogate-Control
X-Urbn-Site-Id
X-Urbn-Context-Path
X-User
X-Sucuri-Cache
X-WADP-Cache
X-VServer
X-TT-LOGID
X-Trace-Id
Wxu-Next-Region
X-Request-URI
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-TH-Server
X-Swa-Ws
X-We-Are-Hiring
X-Webstats-RespID
X-Agile-Id
X-Agile-Age
X-App-Name
X-Backend-State
X-Distil-CS
X-CGP
X-Agile
X-Epic-Correlation-Id
X-Hit
X-Render-Time
X-Eu-Site
CDCHOST
HA-Ipaddr
Ha-Gx-Prefs
X-Req
X-Rebelmouse-Cache-Control
X-Irp-Debug
X-Instart-Isnd
X-Key
X-Li-Fabric
X-LI-Proto
X-Li-Pop
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-Generated-In
X-Gen-Mode
X-Generation-Time
X-GeoIP-City
X-Hnp-Log
X-Hash
X-LI-UUID
X-Location
X-OVcl-Cache
X-OVcl
X-Owner
X-Proxy-Upstream
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Origin-Expires
X-Origin-Date
X-Ms-Request-Id
X-Micro-Cache
X-Ms-Version
X-Nginx-Cache-Key
X-NX-Host
X-NodeID
X-Gamma-Serve
X-Cdn-Srv
Kp-EeAlive
IBM-Web2-Location
Heartbleed
FNAC-ModuleRouting
Locale
Mail-Subject
Request-EU
Request-Country
Powered-By
Memcached
X-Varnish-Beresp-Grace
Fastly-SIE
AKAMAI
Wxu-Next-Hostname
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Status
Cache-Host
Cdncip
Fastly-Backend-Name
Countrycode
Country-Code
Cdnsip
RNT-Machine
Fastly-SWR
Server-ID
Section-Io-Cache
V-Age
RNT-Time
True-Client-Country-4JS
We-Hiring
Web-Mar-Node
Wxu-Next-Commit
Server-Int
Geo-Info
HitType
Thinkindot-Control
X-Has-Esi
X-Old-Content-Length
X-Generated-On
Adler-Geo
X-Trafficlayer-App-Version
X-Up
X-Thinkindot-L3
X-Matched-Rule
X-ServiceProvider
X-Variation
X-Level-Front-Cache
X-NU-AKA-ACS-Version
Thinkindot-CacheControl-Type
X-Internal-Host
X-Is-Gdpr
X-JWT-State
X-Service
X-S-Maxage
Platform
Server-Host
PFcat
Thinkindot-CacheControl
X-Platform-Server
X-Cache-Tags
Is-Eu
X-Reboot
X-Core-Value
X-B3-Parentspanid
X-Nc
X-Server-W
ServerName
Cache-Hits
X-Lb-Id
X-Refresh
X-Response-By
X-Fetched-On
Filterid
X-Nginx-Cache
X-TA-CDN-Provider
X-SERVER
X-Servername
RequestId
X-B3-SpanId
X-Server-IP
ProcessTime
X-Parent-Response-Time
X-NC
X-CF-Powered-By
X-Cdn-Forward
X-Tec-Api-Root
X-Tec-Api-Origin
X-Air-Hostname
X-Tec-Api-Version
X-Tb-Optimization-Total-Bytes-Saved
X-Pjax-Url
X-CSRF-Token
X-CSRF-TOKEN
Group
SRV
Media-Length
Memory
Origin
X-Cdn-Request-ID
X-Cache-Expired-At
Pragrma
User-Agent
X-Wa
X-Var-Ttl
X-BACKEND-TTL
TTL
Geoip-Latitude
X-Pf-Uncompressing
S-Cnection
Powered-By-ChinaCache
X-Vcl-Version
GeoIp-Country-Code
X-Ua
X-NGINX-Cache
X-Unique-ID
X-Correlation-ID
X-Sucuri-Id
X-Sucuri-ID
X-Rocket-Nginx-Bypass
X-COUNTRY
Esi-Enabled
X-AIR-PT
PICS-Label
SN
X-Reqid
X-Planisys-CDN-Cache
Geoip-City
X-Varnish-Cacheable
X-Policy
X-TIME
HostName
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Azure-Ref-OriginShield
X-Request-Start
X-Servedbyhost
X-Via-CDN
X-Litespeed-Cache
X-NWS-UUID-VERIFY
X-Developer
Rt-Proxy-Cache
X-Via-Ucdn
XServer
X-LAGOON
X-HS-Status
M-TraceId
X-Cache-Grace
X-Cdn-Origin
X-Ocache
Dnion-Transfer-Encoding
X-Device-Os
X-Sn-Servicetimems
X-Node-Id
X-FORWARDED-FOR
X-Method
Magicmarker
X-Fastly-Country-Code
X-ServedByHost
Tcn
Resin-Trace
Cdn
On-Server
X-Request-Host
Who
Load-Balancing
X-MSEdge-Flight
X-MSEdge-Features
A
X-Cache-Ttl
X-Ftr-Cache-Host
X-VHOST
CF-Cached-On
Cloudfront-Viewer-Country
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
Ohc-Response-Time
DSUID
X-Cache-Status-Check
X-Oss-Storage-Class
X-Be
X-Svr
X-Beluga-Node
NtCoent-Length
Release
Pics-Label
X-Beluga-Response-Time
X-Beluga-Status
X-Beluga-Record
X-Beluga-Cache-Status
X-Beluga-Trace
X-MServer
X-VCT
X-Bc
X-Varnish-Url
X-VCL-Version
X-Zone
GeoIP-Country-Code
Vix-Hermes-Req-Id
X-APP
X-Oracle-Dms-Rid
X-Hp-Ccpa-Warning
Hostname
MIME-Version
X-Fastly-Backend-Reqs
GeoIP-Latitude
WebServer
X-VarnishDD-TTL
Ttl
X-Ratelimit-Remaining
Cteonnt-Length
Host-ID
X-DC
X-LiteSpeed-Cache-Control
X-Varnish-Ttl
GeoIP-City
X-Newrelic-App-Data
X-Varnish-URL
X-PF-Uncompressing
X-Configured-By
X-PJAX-URL
X-Ftr-Request-Id
X-Slack-Backend
Amp-Access-Control-Allow-Source-Origin
X-Upstream-Ct
X-Upstream-Ht
X-SRV
Servername
X-SD-PageType
SD-X-WS
X-WR-MODIFICATION
X-HostName
X-DW
Processtime
X-BE
X-RSL
X-DSS
X-RPS
X-RPM
X-DB
X-Action
X-DI
X-Cache-Id
X-Dynatrace
X-Aicache-OS
X-Compress-Hint
X-Tid
X-SN
X-Swift-Error
X-Dynatrace-Js-Agent
X-Ratelimit-Limit
X-Release
Arc-Country
X-Via-NSCOPI
X-ID
CACHE
L
X-Cache-FS-Status
Pramga
X-Dispatch
X-PAYTM-SRV-ID
X-Server-Time
X-FPC
X-Skip-Cache
Cache-Provider
X-Processor
X-Frame-Option
X-Ftr-Balancer
X-Ftr-Dc
X-Ftr-Backend-Server
Dynatrace
CF-IPCountry
X-Scheme
X-ABtesting
X-DevSite-Last-Modified
X-StackifyID
X-Flog
X-Ftr-Backend
X-Ftr-Realm
X-Branch-Name
LB
X-Snapshot-Date
Requestid
X-ServerName
Fastly-Drupal-HTML
X-ND-Cache
X-LB-ID
Pagetype
X-Fastly-Cache-Hits
Lfy
CDN
X-Hello
X-CACHE-AGE
X-Node-ID
UCS
X-Cc-Via
X-Apw-Access-Object
X-Apw-Hits
X-Cc-Req-Id
X-Edge-IP
X-ZONE
X-Varnish-Beresp-TTL
Cdn-Host
Warning
X-Served-From
Cdn-Request-Time
X-Edge-Server
Cache-Cookie-Set-Lfrom
X-Apw-Access-Token
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-From
X-Apw-Access-Action
X-Request-URL
Proxy-Firewall
V-Cache
D-Cc-Upstream
N-Cache
X-VC
X-Request-Url
X-SB
NnCoection
X-WA
Lb
X-App
Correlation-Id
Backend-Name
X-Litespeed-Cache-Control
X-BC
X-Worker
X-Check-Cacheable
X-Powered-Y
X-ElasticPress-Search
WP-Super-Cache
X-Fastly-Cache-Status