Threat Level: green Handler on Duty: Russell Eubanks

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
CF-RAY
Link
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Request-ID
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-Template
X-DNS-Prefetch-Control
X-Language
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
Status
Upgrade
X-Content-Security-Policy
Content-Encoding
X-CDN
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
X-Xss-Protection
Keep-Alive
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
X-Pass-Why
X-Cache-Group
Xkey
X-AH-Environment
X-Envoy-Upstream-Service-Time
CF-Ray
X-Via
X-Backend
X-Server
X-Age
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Ws-Request-Id
X-Server-Powered-By
X-Page-Speed
X-Pingback
EagleId
X-Proxy-Cache
X-Hacker
X-UA-Device
X-Nginx-Cache-Status
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
P3p
Cf-Railgun
Grace
X-Swift-CacheTime
X-Swift-SaveTime
Ali-Swift-Global-Savetime
X-Amz-Version-Id
X-Ua-Compatible
Report-To
X-LiteSpeed-Cache
X-Rq
X-OneAgent-JS-Injection
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-WebKit-CSP
X-Device
X-Host
X-Server-Id
X-Origin-Cache
X-Response-Time
EagleEye-TraceId
X-Node
X-Ac
Surrogate-Control
Content-Location
X-Cloud-Trace-Context
X-Vhost
X-Readtime
X-Backend-Server
X-Dns-Prefetch-Control
Request-Id
X-Dispatcher
X-Origin-Upstream-Status
X-Cnection
X-Application-Context
X-HW
X-Cache-Lookup
X-Ruxit-JS-Agent
Fusion-Component-Id
Fusion-Content-Id
Fusion-Content-Source
Fusion-Template-Id
Fusion-Source
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
NEL
X-Mod-Pagespeed
X-DataDome
X-Rack-Cache
Rating
Edge-Control
X-Country
X-Clacks-Overhead
X-Akam-SW-Version
Pinterest-Generated-By
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-TTL
Allow
X-Country-Code
X-FTR-Request-ID
X-DynaTrace
X-Instart-Request-ID
X-Varnish-TTL
X-Goog-Hash
X-TtlSet
X-Vname
X-PC
Accept-Ch
X-ESI
Verso
Content-MD5
Service-Worker-Allowed
X-Powered-By-Plesk
Accept-Ch-Lifetime
X-Url
X-Forwarded-Proto
X-Version
X-MS-InvokeApp
X-Kinja-Server
X-GitHub-Request-Id
X-Use-Magma
X-Cdn-Fetch
X-Kinja-Build
X-Kinja
X-GoogleNews-Bot
X-Kinja-Revision
X-Exp-Variant
X-Exp-Id
X-B3-TraceId
RTSS
Edge-Cache-Tag
X-Server-Name
X-D2id
X-Debug
X-Abt-Application-Version
AR-PoweredBy
Ar-Sid
AR-Request-ID
AR-CACHE
AR-ATIME
X-Px
X-Amz-Server-Side-Encryption
X-Vcache
SPRequestGuid
Charset
X-NF-Request-ID
X-Cached
X-Middleton-Display
X-Middleton-Response
Response
X-Sol
Display
Pagespeed
X-Vcap-Request-Id
X-Accel-Expires
X-MSEdge-Ref
X-Amz-Rid
X-Navigation-Version
Arr-Disable-Session-Affinity
X-Server-ID
X-Pinterest-Rid
X-TEC-API-ROOT
Pinterest-Version
X-TEC-API-VERSION
X-TEC-API-ORIGIN
TCN
X-Powered-CMS
X-SharePointHealthScore
X-Fastcgi-Cache
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-VARITI-CCR
X-Cdn
X-Trace
Public-Key-Pins
X-Fastly-Request-ID
Cache-Tag
X-Client-IP
Realpath
Nginx-Cache
X-Edge-O15-RID
MS-Author-Via
X-Ser
Access-Control-Request-Method
X-DynaTrace-JS-Agent
X-Shard
X-B3-TraceId-Primal
X-Mrf-Item-Lastmod
MRF-Tech
Mrf-Cache-Status
X-Mrf-Section-Lastmod
SPRequestDuration
SPIisLatency
X-Content-Type
S
X-Id
X-Ezoic-Cdn
X-Upstream
X-Amzn-Trace-Id
X-Hp-Webp
X-Grace
X-Forwarded-For
X-T
X-Amz-Meta-S3cmd-Attrs
X-Jurisdiction
Nel
Front-End-Https
X-Hits
Fastcgi-Cache
X-Recruiting
X-Aspnet-Version
DynaTrace
X-Cache-TTL
X-Varnish-Age
ServerID
X-Element-Page-Cache
MicrosoftSharePointTeamServices
X-Node-Name
X-Content-Digest
X-Mobile-URL
X-FTR-Realm
X-FTR-DC
X-FTR-Backend-Server
X-FTR-Backend
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Expires
X-FTR-Balancer
X-DIS-Request-ID
X-Dw-Request-Base-Id
NR-ENABLED
Server-Node
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Combine-CSS
X-Goog-Storage-Class
X-Goog-Metageneration
X-Goog-Generation
X-Frontend
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
Powered
X-GUploader-UploadID
TP-L2-Cache
TP-Cache
Alternate-Protocol
X-Logged-In
Server-Name
X-CST
X-Correlation-Id
AMP-Access-Control-Allow-Source-Origin
X-XRDS-Location
X-Amz-Apigw-Id
X-Amzn-RequestId
Upgrade-Insecure-Requests
X-Request-Received
X-Request-Processing-Time
X-Request-Handler-Origin-Region
X-Microsite
X-ATS-Timestamp
X-Cache-Hit
Backend-Timing
Fastly-Restarts
X-Content-Options
X-Origin-Server
X-User-Agent
X-Content-Security-Policy-Report-Only
X-F-Cache
Refresh
X-Rid
X-Page-Id
X-Revision
X-Akamai-Edgescape
X-Zen-Fury
X-Varnish-Grace
X-Type
X-FTR-Cache-Host
X-Content-Powered-By
X-LB-Cache
X-XRDS-LOCATION
X-B
X-B3-Sampled
PB-RID
X-Geo-Country
PB-PID
X-URL
Arc-Version
X-Mobile-Rewrite
X-AppVersion
X-Activity-Id
X-Az
Cache-Status
X-Kinsta-Cache
X-N
X-Cache-Age
X-TT
X-Cache-Action
X-Signature
X-B-Cache
X-WebKit-CSP-Report-Only
X-Instance
X-AOL-HN
Access-Control-Allow-Method
X-Tumblr-User
X-Tumblr-Pixel-0
Actual-Object-TTL
Paypal-Debug-Id
X-Framework
X-Load-Cache
X-Debug-Info
X-Jobs
X-Tumblr-Pixel
X-FB-Debug
X-App-Environment
X-Cached-By
X-Pad
X-Shield-Request-Id
X-Request-Guid
X-PHP-Backend
X-Git-Hash
DC
Fastcgi-Useragent
X-Time
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Webkit-Csp
X-RateLimit-Remaining
X-Amz-Replication-Status
X-Varnish-Backend
Surrogate-Key
X-IPLB-Instance
Host-Header
X-Contextid
MS-CV
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-ATG-Version
X-WA-Info
Host
X-NWS-LOG-UUID
X-Webapp-Samesite-None-Activated-N
Accept-CH
X-FastCGI-Cache
X-Analytics
X-SS-Set-Cookie
X-ORACLE-APMCS-REQUEST-ID
X-ORACLE-APMCS-TAG
FilterID
X-Cache-Key
X-Mobile
X-Via-JSL
X-Kong-Proxy-Latency
X-Host-Name
Tracecode
NGB
X-Response-Served-From
X-Kong-Upstream-Latency
X-Accel-Buffering
X-Presslabs-Stats
X-Cluster
Payment
X-B3-Traceid
X-Cache-NE
X-Varnish-Server
WPE-Backend
Source
X-Cache-2
Eomportal-Instance
X-Origin-Response-Time
X-Region
X-FW-Serve
X-FW-Static
X-FW-Type
X-FW-Hash
X-FW-Server
X-GeoIP
X-IPS-LoggedIn
X-Tumblr-Pixel-2
Frame-Options
Filters
X-Tumblr-Pixel-1
X-Varnish-Hostname
Cache-Tv-Group
X-Adobe-Content
X-Cacheable-TTL
X-Adobe-Loc
X-Cache-Enabled
Retry-After
X-Seen-By
X-Hostname
X-Rendered-As
X-Cache-Operation
X-EdgeConnect-Cache-Status
X-Is-Bot
X-Srv
X-Cache-Rule
X-RequestSource
X-TX-ID
X-NewRelic-App-Data
Xserver
Accept-CH-Lifetime
Server-Info
X-VCache
X-Cache-TTL-Remaining
X-RemovedCookies
X-ProcessESI
Liferay-Portal
Cleartype
X-App-Server
X-Dc
X-RTag
X-Environment-Context
X-L-Path
Ms-Operation-Id
X-FireWall-Port
X-Source
X-Endurance-Cache-Level
X-UA
X-HTML-Minification-Powered-By
X-Upgrade-Enabled
X-Handled-By
X-Cache-Server
From-Origin
X-CACHE-KEY
Datacenter
X-APP-VERSION
X-Backend-Name
Srv
Accept-Charset
Cache
Meta-Geo
X-RN-RSRV
X-Cache-Control
X-ES-SERVER
X-Cache-Var
X-Wix-Request-Id
X-Cache-Var-Map
X-Path-Route
GEO-INFO
X-UUID
X-Timing-Wait
X-Format
OT-Force-Account-Verify
Selected-Fe
X-Access
X-Proxy-Build
X-Section
X-Tb
X-Status
Azure-SiteName
Azure-InstanceId
Azure-SlotName
Akamai-GRN
Azure-RegionName
X-Alternate-Cache-Key
X-ShardId
Mn-Server-Ip
X-Akamai-Request-ID
X-Cache-Config
Cache-Tags
X-Content-Age
Azure-Version
Version
X-Proto
X-Shopify-Stage
X-Shopify-Generated-Cart-Token
X-ShopId
X-OCL
X-Origin
X-Sorting-Hat-ShopId
X-PCL
X-Sorting-Hat-PodId
X-Request-Time
X-NYM-Debug-Backend
X-Goog-Meta-Goog-Reserved-File-Mtime
X-EIG-Tracking-Id
X-FC-Vary-Parameters
Healthy
X-Say-Cacheable
X-Proxy-Cache-Status
X-Say-TTL
X-SayCDN-TTL
X-Viewer-Country
X-VWS-Id
X-Web-Node
X-SaId
Decoy-Debug-TTL
Decoy-Debug-Key
DB-Nickname
X-Qloud-Router
X-Vgn-Hpd-Reason
Decoy-Debug-Status
X-Redis-Cache
X-ProxyCache-Status
X-Pubstack
X-ProxyCache-Key
Origin-Edge-Control
X-Hosted-By
X-Human
X-Hyper-Cache
X-JoinUs
X-Hl-Ver
X-Generated-By
X-FW-Dynamic
X-Proxy
X-Cluster-Node
X-LJ-Flow-ID
X-BYPASS-REASON
Now
X-Soup
Node
NGX
Origin-Cache-Control
X-Debug-Cache
X-AWS-Id
X-Akamai-Request-ID2
X-ServerID
X-Time-Microsecs
Ec-Rule-Version
X-Yottaa-Optimizations
X-Yottaa-Metrics
TWC-Privacy
TWC-Device-Class
TWC-GeoIP-Country
TWC-GeoIP-LatLong
X-RateLimit-Limit
TWC-Locale-Group
X-Varnish-Hits
X-BCube-Filmed-By
Property-Id
X-Amzn-Remapped-Content-Length
X-CCM
TWC-Connection-Speed
X-Site-Version
Webcakes-Region
X-TNCMS
X-Loop
X-PressLabs-Stats
X-MP-GENERATED-AT
X-Origin-Hint
Webcakes-App-Version
X-FB-TRIP-ID
Cross-Origin-Window-Policy
X-Storage
X-Generated
X-Www-Served-By
Webcakes-App-Name
S-Rt
X-Rule
X-Xfnlog-Site
X-NCache
X-Akamai-Transformed
X-R9-Blue-Green-Version
X-Locale
X-RCS-CacheZone
X-Cache-Host
X-IP
X-Detected-As
X-Unique-Id
L5d-Success-Class
X-Esi
Cache-Key
X-Drupal-Cache-Tags
X-CS
Webserver
Cache-Name
Uber-Trace-Id
Viewport
Time
X-UA-Device-Type
X-Backend-TTL
X-UnsetCookies
X-Whom
X-Forwarded-Host
X-Mode
X-Origin-TTL
X-CDN-Forward
X-Origin-CC
X-NGENIX-Cache
X-Daa-Tunnel
X-Info
Rt-Fastcgi-Cache
Accept-Language
Content-Disposition
X-B3-Spanid
X-Varnish-Cache-Hits
Country
X-Cache-Remote
Mime-Version
Odigeo-Trace-Id
X-ApacheServer
X-From
X-PERF
ServedBy
X-Magnolia-Registration
X-CLOUD-TRACE-CONTEXT
X-Cluster-Name
Section-Io-Cache
X-Newrelic-Synthetics
X-Drupal-Cache-Contexts
X-Microcachable
X-Routing-Service
VIX-Pulpo-Upstream-Status
X-Zipkin-Id
VIX-Pulpo-Node
X-Geo
X-Proxied
X-Device-Type
X-TT-TIMESTAMP
X-Ttl
X-EC-Lua
X-Via-Fastly
X-Uri
Proxy-Connection
Cf-Ipcountry
Ohc-File-Size
HitType
X-Nc
X-Aed
BehaviorPad-Version
Content-Script-Type
X-Request-UUID
X-G
Content-Style-Type
Apple-News-Services-Handled
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
X-GeoIP-Country-Code
X-Region-Sid
Apple-News-Services-Host
X-Rewrite-Enabled
X-Geo-Header
AsisCache
Access-Control-Request-Headers
X-CF-Lambda-Version
Viewtype
VivaBuild
W
X-Vdms-Version
X-Application
X-ARC
X-Twitter-Response-Tags
X-CF-Lambda-Fn
T-Server
X-B-Cookie
X-VG-TLSProxy
X-VG-WebCache
X-A-Dcw
X-A-Dgt
X-A-Wwc
X-Accel-Expires-Debug
X-A-Dam
X-A-Ccd
X-VG-WebServer
X-A
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Rendered-Blocks
X-Rocket-Build-Number
X-Session-Fingerprint
X-Sigma
X-Sigma-Backend
GEO-REGION-INFO
X-External-Request-Id
Fastcgi-X-Cache-Version
X-Rojux
X-S
X-S-Cookie
X-ScT
X-SRCache-Key
X-DPWN-IS-SECURE
Mobile-Detection-Method
X-Connection-Hash
X-Transaction
X-Trv-Group
Meta-Geo-Continent
X-D
X-Destination
Machine
MD5-Digest
X-Date
Xc-Version
X-C
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-Varnish-Beresp-Ttl
User-Cache-Control
Ohc-Cache-HIT
X-Edge-Location
X-No-Session
X-UPSTREAM-Address
Powered-By
Fastly-SIE
Environment
X-CGP
X-Tumblr-Pixel-3
Countrycode
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
Server-Cache-Control
CDCHOST
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
Fastly-Soc-X-Request-Id
X-Clientip
X-Developers
X-Contensis-Viewer-Groups
IsBot
X-CUA
X-Thanos
Locid
X-Distil-CS
HA-Ipaddr
X-SIPLIST1
X-Eu-Site
X-Cache-ASPX
X-TrackingId
Ha-Gx-Prefs
Gh-Request-Id
Fastly-SWR
X-Cache-Debug
X-WebServer
X-Agile-Id
X-Real-IP
X-Agile-Age
X-VC-Cache
Fastly-SSL
X-Logging-Id
X-Varnish-Authentication
X-Auto-Login
Server-Surrogate-Control
X-App-Name
X-Wikidot-Static-Cache
X-Bip
X-Wikidot-Backend
X-Hit
X-Agile
X-GoCache-CacheStatus
Geo-Info
X-Cache-Backend
X-Air-Hostname
X-Cms-Context
X-We-Are-Hiring
X-Webstats-RespID
X-TH-Server
X-Trace-Id
X-Core-Mission
X-WADP-Cache
X-VServer
X-User
X-Cache-Time
X-Cache-URL
X-Cdn-Srv
X-Cache-Tags
X-Cache-Info
X-Cache-Bucket
X-Debug-Cache-Expiry
X-Up
X-Urbn-Context-Path
X-Azure-Ref
X-Clara-WADP
X-Block-Status
X-TT-LOGID
X-Urbn-Site-Id
X-BBXSRF
X-Backend-State
X-Variation
X-Distributor
X-JWT-State
X-Is-Gdpr
X-Labrador-Cache-Channel
X-Owner
X-Li-Fabric
X-Irp-Debug
X-Instart-Isnd
X-Hnp-Log
X-Hash
X-IN-APIGATEWAY
X-PHP-Host
X-IN-APIGATEWAYSSL
X-Li-Pop
X-OVcl-Cache
X-Origin-Date
X-Ms-Version
X-NX-Host
X-NU-AKA-ACS-Version
X-NodeID
X-Ms-Request-Id
X-Origin-Expires
X-LI-Proto
X-OVcl
X-LI-UUID
X-Micro-Cache
X-Has-Esi
X-Platform-Server
X-SVT-ORM-RULES
X-Nginx-Cache-Key
X-Epic-Correlation-Id
X-Servername
X-Server-W
X-Dispatcher-Server
X-SVT-ORM-VERSION
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Debug-Cookies
X-Debug-Log
X-Fastly-Cache
X-Fetched-On
X-RateLimit-Remaining-Second
X-Render-Time
X-RateLimit-Limit-Second
X-Proxy-Upstream
X-GeoIP-City
X-Request-URI
X-Generation-Time
X-FW-Version
X-Gamma-Serve
X-Gen-Mode
X-Generated-In
X-Swa-Ws
X-AK-Request-ID
Cache-Host
Cdncip
Request-EU
RNT-Machine
RNT-Time
Server-ID
Adler-Geo
AKAMAI
Request-Country
Cdnsip
Kp-EeAlive
Locale
Mail-Subject
Is-Eu
IBM-Web2-Location
Country-Code
Platform
Heartbleed
Memcached
Server-Int
Web-Mar-Node
True-Client-Country-4JS
We-Hiring
V-Age
X-Trafficlayer-App-Scope
X-Trafficlayer-App-Name
X-Var-Ttl
Wxu-Next-Region
FNAC-ModuleRouting
X-Cache-Expired-At
X-Thinkindot-L3
X-Trafficlayer-App-Version
Fastly-Backend-Name
X-Service
Group
X-Matched-Rule
ServerName
X-Old-Content-Length
X-Generated-On
X-Level-Front-Cache
X-Reboot
X-ServiceProvider
X-Req
PFcat
Thinkindot-Control
Wxu-Next-Hostname
Server-Host
Thinkindot-CacheControl-Type
Wxu-Next-Commit
Thinkindot-CacheControl
X-Core-Value
Filterid
Pragrma
Cache-Hits
X-SERVER
X-Lb-Id
X-Internal-Host
X-S-Maxage
X-App-Version
S-Cnection
X-Key
X-Nginx-Cache
X-VHOST
X-Sucuri-Cache
X-Refresh
X-Response-By
X-Location
X-CF-Powered-By
Powered-By-ChinaCache
X-Ruxit-Js-Agent
X-CSRF-TOKEN
RequestId
X-Wa
X-NC
X-TA-CDN-Provider
X-Parent-Response-Time
X-Tb-Optimization-Total-Bytes-Saved
X-Sucuri-ID
Origin
X-Varnish-Cacheable
ProcessTime
X-Ua
X-Cdn-Forward
X-B3-Parentspanid
X-Pjax-Url
User-Agent
X-Via-CDN
Memory
X-BACKEND-TTL
X-Pf-Uncompressing
X-CSRF-Token
Geoip-City
Geoip-Latitude
X-Developer
X-NGINX-Cache
SRV
X-Server-IP
X-Ocache
X-Correlation-ID
TTL
PICS-Label
X-Cdn-Origin
X-Cache-Grace
X-Device-Os
X-Sn-Servicetimems
GeoIp-Country-Code
X-LAGOON
X-Oss-Storage-Class
X-Oss-Server-Time
X-B3-SpanId
X-Node-Id
X-Oss-Request-Id
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Cache-Status-Check
X-Vcl-Version
X-COUNTRY
On-Server
X-NWS-UUID-VERIFY
Hostname
X-Unique-ID
X-TIME
X-MSEdge-Features
X-MSEdge-Flight
X-Request-Host
A
XServer
X-Servedbyhost
X-Webkit-CSP
X-Litespeed-Cache
X-Cdn-Request-ID
Cloudfront-Viewer-Country
Media-Length
X-Rocket-Nginx-Bypass
X-Varnish-Ttl
Dnion-Transfer-Encoding
SN
M-TraceId
X-HS-Status
Tcn
X-Via-Ucdn
X-FORWARDED-FOR
X-Sucuri-Id
X-Varnish-URL
Resin-Trace
Cdn
Host-ID
X-Ratelimit-Remaining
X-Beluga-Node
Who
X-Beluga-Cache-Status
X-AIR-PT
X-Beluga-Trace
X-Cache-Ttl
Esi-Enabled
X-ServedByHost
X-Reqid
X-Beluga-Response-Time
X-Beluga-Record
X-Beluga-Status
HostName
X-Slack-Backend
X-Policy
CF-Cached-On
X-Planisys-CDN-TTL
X-Fastly-Country-Code
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
CACHE
X-Azure-Ref-OriginShield
MIME-Version
X-Action
X-Request-Start
X-VCL-Version
X-DB
Rt-Proxy-Cache
X-Cache-FS-Status
GeoIP-Country-Code
Pics-Label
Pramga
X-DW
Ttl
X-DI
X-Processor
X-Server-Time
X-RSL
X-PAYTM-SRV-ID
X-DSS
X-Dispatch
X-RPM
Arc-Country
X-RPS
X-LiteSpeed-Cache-Control
X-Oracle-Dms-Rid
X-Varnish-Url
X-Skip-Cache
NtCoent-Length
X-Zone
X-ND-Cache
X-Hello
X-Flog
X-Fastly-Backend-Reqs
GeoIP-City
X-Bc
X-ABtesting
GeoIP-Latitude
X-DC
Fastly-Drupal-HTML
X-Method
Cdn-Host
Magicmarker
X-Edge-Server
X-Served-From
Cdn-Request-Time
X-Ratelimit-Limit
X-PJAX-URL
X-APP
X-Newrelic-App-Data
X-VarnishDD-TTL
X-PF-Uncompressing
X-FPC
X-HostName
Amp-Access-Control-Allow-Source-Origin
X-DevSite-Last-Modified
X-Bc-Bl
Cteonnt-Length
X-SRV
N-Cache
WebServer
Section-Origin-Responded
X-Ftr-Cache-Host
Section-Io-Id
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
X-Backend-Host
X-Dynatrace
X-BE
X-Amzn-Remapped-Date
X-Amzn-Remapped-Connection
Processtime
X-Dynatrace-Js-Agent
Servername
X-Swift-Error
Cache-Provider
CDN
Ohc-Response-Time
X-Svr
Requestid
X-ID
X-Be
X-WA
X-Frame-Option
X-WR-MODIFICATION
X-Adobe-Source
Lfy
CF-IPCountry
Dynatrace
X-ZONE
X-BC
Vix-Hermes-Req-Id
X-Aicache-OS
FSS-Proxy
X-Fmm-Version
FSS-Cache
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-From
Cache-Cookie-Set-Idcheck
X-Branch-Name
Load-Balancing
X-LB-ID
X-Snapshot-Date
X-StackifyID
X-CACHE-AGE
Fusion-Deployment-Id
Trailer
WZWS-RAY
X-Fastly-Cache-Hits
Warning
X-Cc-Via
X-VC
Pagetype
Proxy-Firewall
X-SB
X-Apw-Access-Token
X-Apw-Hits
D-Cc-Upstream
X-Cc-Req-Id
X-Tid
X-Apw-Access-Object
X-Request-Url
X-Apw-Access-Action
X-Scheme
V-Cache
X-Node-ID
X-MServer
DSUID
DataCenter
X-Litespeed-Cache-Control
X-Fpc
X-WPE-Loopback-Upstream-Addr
X-ElasticPress-Search
Cneonction
WP-Super-Cache
X-Request-URL
X-Powered-Y
X-Hp-Ccpa-Warning
Backend-Name
Correlation-Id
X-App
X-Varnish-Beresp-TTL
X-Fastly-Cache-Status
X-VCT
X-Configured-By
X-Worker
X-Check-Cacheable
Release