Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
CF-RAY
Link
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Request-ID
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-Template
X-DNS-Prefetch-Control
X-Language
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
Status
Upgrade
X-Content-Security-Policy
Content-Encoding
X-CDN
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Xss-Protection
X-Kinja-Server-Push
Keep-Alive
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
P3p
X-Pass-Why
Xkey
X-Cache-Group
X-AH-Environment
X-Envoy-Upstream-Service-Time
CF-Ray
X-Via
X-Backend
X-Ua-Compatible
Expect-Ct
X-Age
X-Server
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Server-Powered-By
X-Ws-Request-Id
X-Page-Speed
X-Pingback
EagleId
X-Proxy-Cache
X-Hacker
X-Nginx-Cache-Status
X-UA-Device
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
Cf-Railgun
Grace
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Amz-Version-Id
Report-To
X-LiteSpeed-Cache
X-Rq
X-OneAgent-JS-Injection
X-Styx-Req-Id
X-WebKit-CSP
X-Pantheon-Styx-Hostname
X-Server-Id
X-Device
X-Host
X-Origin-Cache
EagleEye-TraceId
X-Response-Time
X-Ac
X-Node
Surrogate-Control
Content-Location
X-Vhost
X-Cloud-Trace-Context
X-Readtime
X-Backend-Server
Request-Id
X-Dns-Prefetch-Control
X-Dispatcher
X-Origin-Upstream-Status
X-Cnection
X-Application-Context
X-HW
X-Cache-Lookup
X-ORACLE-DMS-ECID
Fusion-Source
Fusion-Template-Id
Fusion-Content-Source
Fusion-Content-Id
Fusion-Component-Id
X-Ruxit-JS-Agent
X-ORACLE-DMS-RID
X-DataDome
NEL
X-Mod-Pagespeed
X-Rack-Cache
Rating
Edge-Control
X-Country
X-Clacks-Overhead
X-Akam-SW-Version
Pinterest-Generated-By
X-TTL
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Allow
X-Country-Code
X-DynaTrace
X-FTR-Request-ID
X-Instart-Request-ID
X-Varnish-TTL
X-Goog-Hash
X-TtlSet
X-PC
X-Vname
Accept-Ch
Verso
Content-MD5
X-ESI
Service-Worker-Allowed
X-Powered-By-Plesk
Accept-Ch-Lifetime
X-Url
X-Forwarded-Proto
X-Version
X-MS-InvokeApp
X-B3-TraceId
X-GitHub-Request-Id
X-Use-Magma
X-Kinja-Revision
X-Kinja-Build
X-Kinja
X-Exp-Id
X-Cdn-Fetch
X-GoogleNews-Bot
X-Kinja-Server
X-Exp-Variant
RTSS
Edge-Cache-Tag
X-D2id
X-Abt-Application-Version
X-Debug
X-Px
AR-Request-ID
Ar-Sid
AR-CACHE
AR-ATIME
AR-PoweredBy
X-Amz-Server-Side-Encryption
X-Vcache
SPRequestGuid
X-Server-Name
Charset
X-NF-Request-ID
X-Cached
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Accel-Expires
Display
X-Middleton-Response
X-Middleton-Display
Pagespeed
Response
X-Sol
X-Vcap-Request-Id
X-MSEdge-Ref
X-Amz-Rid
Arr-Disable-Session-Affinity
X-Navigation-Version
Pinterest-Version
X-Pinterest-Rid
X-SharePointHealthScore
X-Powered-CMS
TCN
X-Fastcgi-Cache
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Cdn
X-Trace
X-VARITI-CCR
Public-Key-Pins
Cache-Tag
Realpath
X-Client-IP
X-Fastly-Request-ID
Access-Control-Request-Method
X-Ser
MS-Author-Via
Nginx-Cache
X-Shard
X-DynaTrace-JS-Agent
S
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
X-B3-TraceId-Primal
SPIisLatency
MRF-Tech
Mrf-Cache-Status
X-Edge-O15-RID
SPRequestDuration
X-Upstream
X-Id
X-Content-Type
X-Ezoic-Cdn
X-Hp-Webp
X-Amzn-Trace-Id
X-Grace
X-Forwarded-For
X-Amz-Meta-S3cmd-Attrs
Nel
X-T
Front-End-Https
X-Recruiting
X-Hits
Fastcgi-Cache
DynaTrace
X-Aspnet-Version
X-Jurisdiction
X-Cache-TTL
X-Varnish-Age
X-Server-ID
ServerID
MicrosoftSharePointTeamServices
X-Element-Page-Cache
X-Mobile-URL
X-Content-Digest
X-Node-Name
X-FTR-Backend
X-Country-Code-Real
X-FTR-Realm
X-DIS-Request-ID
X-FTR-DC
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-Expires
X-FTR-Backend-Server
X-Dw-Request-Base-Id
NR-ENABLED
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Combine-CSS
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Frontend
X-Goog-Stored-Content-Encoding
Server-Node
Powered
TP-L2-Cache
TP-Cache
Alternate-Protocol
Server-Name
X-Logged-In
X-Correlation-Id
X-CST
X-XRDS-Location
X-Request-Processing-Time
X-Request-Received
AMP-Access-Control-Allow-Source-Origin
Upgrade-Insecure-Requests
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Request-Handler-Origin-Region
X-Microsite
Backend-Timing
X-ATS-Timestamp
X-Cache-Hit
X-Content-Options
X-User-Agent
Refresh
X-F-Cache
X-Content-Security-Policy-Report-Only
X-Origin-Server
X-Page-Id
X-Akamai-Edgescape
X-Rid
X-Zen-Fury
X-Revision
Fastly-Restarts
X-Varnish-Grace
X-Type
X-Content-Powered-By
X-XRDS-LOCATION
X-LB-Cache
X-FTR-Cache-Host
X-B3-Sampled
X-B
X-Geo-Country
X-URL
PB-PID
PB-RID
X-Az
X-Activity-Id
X-AppVersion
Arc-Version
X-Mobile-Rewrite
Cache-Status
X-Kinsta-Cache
X-N
X-Cache-Age
X-Shield-Request-Id
X-Pad
X-TT
X-B-Cache
X-AOL-HN
X-Cache-Action
X-Signature
X-WebKit-CSP-Report-Only
X-Instance
X-Framework
Actual-Object-TTL
X-Time
Access-Control-Allow-Method
Paypal-Debug-Id
X-Debug-Info
X-Jobs
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Tumblr-User
X-Load-Cache
X-FB-Debug
X-App-Environment
X-PHP-Backend
X-Request-Guid
DC
X-Cached-By
X-Git-Hash
Fastcgi-Useragent
X-Tt-Trace-Host
X-Tt-Trace-Tag
X-Webkit-Csp
X-RateLimit-Remaining
X-Varnish-Backend
X-Amz-Replication-Status
X-Erf-Bev-Bev-Is-Generated
X-Webapp-Samesite-None-Activated-N
X-Erf-Bev-Bev
Surrogate-Key
Host-Header
X-IPLB-Instance
X-Contextid
MS-CV
X-Analytics
X-ATG-Version
Accept-CH
X-WA-Info
X-SS-Set-Cookie
Host
X-FastCGI-Cache
FilterID
X-Cache-Key
X-NWS-LOG-UUID
X-ORACLE-APMCS-TAG
X-ORACLE-APMCS-REQUEST-ID
X-Accel-Buffering
X-Response-Served-From
Tracecode
X-Cluster
X-Host-Name
WPE-Backend
X-Via-JSL
X-Kong-Proxy-Latency
Payment
X-Mobile
X-Kong-Upstream-Latency
X-Cache-NE
NGB
X-B3-Traceid
X-FW-Server
X-FW-Static
X-FW-Hash
X-Region
Xserver
X-FW-Type
X-FW-Serve
X-Varnish-Server
Source
Eomportal-Instance
X-Cache-2
X-Tumblr-Pixel-1
X-IPS-LoggedIn
X-GeoIP
X-Tumblr-Pixel-2
X-Origin-Response-Time
Cache-Tv-Group
Filters
Frame-Options
X-Varnish-Hostname
X-Srv
X-Cache-Enabled
X-Adobe-Content
X-Adobe-Loc
X-Cacheable-TTL
X-Cache-Rule
X-Seen-By
X-Cache-Operation
X-RequestSource
X-Is-Bot
X-Rendered-As
X-TX-ID
X-Hostname
Retry-After
X-Presslabs-Stats
X-EdgeConnect-Cache-Status
Accept-CH-Lifetime
X-NewRelic-App-Data
Server-Info
X-Cache-TTL-Remaining
Cleartype
X-VCache
X-ProcessESI
X-RemovedCookies
Liferay-Portal
X-RTag
X-App-Server
Ms-Operation-Id
X-Source
X-L-Path
X-Environment-Context
X-HTML-Minification-Powered-By
X-FireWall-Port
X-UA
Datacenter
X-Endurance-Cache-Level
X-Dc
Cache
X-Cache-Server
X-Upgrade-Enabled
From-Origin
X-Handled-By
X-CACHE-KEY
X-APP-VERSION
X-Esi
X-Backend-Name
X-Cache-Control
X-PressLabs-Stats
Srv
X-Wix-Request-Id
Healthy
Meta-Geo
X-Cache-Var
X-Cache-Var-Map
X-ES-SERVER
X-RN-RSRV
X-Path-Route
X-Timing-Wait
OT-Force-Account-Verify
X-Access
X-Section
X-Status
X-Proxy-Build
Accept-Charset
Version
X-Tb
Selected-Fe
X-Format
Cache-Tags
X-OCL
X-Alternate-Cache-Key
X-Akamai-Request-ID
X-Sorting-Hat-ShopId
X-ShardId
X-Sorting-Hat-PodId
Mn-Server-Ip
X-Content-Age
X-Origin
X-ShopId
X-Goog-Meta-Goog-Reserved-File-Mtime
Azure-SiteName
X-Cache-Config
X-Shopify-Stage
Azure-RegionName
Azure-InstanceId
X-UUID
X-EIG-Tracking-Id
Akamai-GRN
X-FC-Vary-Parameters
Azure-SlotName
X-Shopify-Generated-Cart-Token
X-Request-Time
Azure-Version
X-PCL
X-NYM-Debug-Backend
X-Proto
DB-Nickname
NGX
Node
Decoy-Debug-Status
Ec-Rule-Version
X-Proxy
Decoy-Debug-TTL
Now
X-ServerID
X-Viewer-Country
X-BYPASS-REASON
X-Pubstack
X-JoinUs
X-Redis-Cache
X-LJ-Flow-ID
X-Hyper-Cache
X-Hosted-By
X-Cluster-Node
X-Debug-Cache
X-FW-Dynamic
X-Generated-By
X-Hl-Ver
X-ProxyCache-Status
X-SaId
X-Vgn-Hpd-Reason
X-VWS-Id
X-Proxy-Cache-Status
X-Time-Microsecs
Origin-Edge-Control
X-SayCDN-TTL
X-Akamai-Request-ID2
X-AWS-Id
X-Say-Cacheable
X-ProxyCache-Key
X-Web-Node
X-Say-TTL
Origin-Cache-Control
Decoy-Debug-Key
X-Storage
X-Rule
X-RateLimit-Limit
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Amzn-Remapped-Content-Length
Cross-Origin-Window-Policy
X-BCube-Filmed-By
Property-Id
TWC-GeoIP-LatLong
TWC-Locale-Group
Webcakes-App-Version
X-CCM
Webcakes-Region
TWC-Privacy
Webcakes-App-Name
X-FB-TRIP-ID
X-Site-Version
X-Qloud-Router
X-Soup
X-TNCMS
X-Www-Served-By
X-Varnish-Hits
TWC-GeoIP-Country
X-Origin-Hint
X-Human
X-Generated
TWC-Device-Class
TWC-Connection-Speed
X-MP-GENERATED-AT
X-Loop
S-Rt
X-Cache-Host
X-RCS-CacheZone
X-Locale
GEO-INFO
X-Xfnlog-Site
X-Akamai-Transformed
X-NCache
X-R9-Blue-Green-Version
X-IP
X-Detected-As
X-Unique-Id
L5d-Success-Class
X-CS
Cache-Name
X-Drupal-Cache-Tags
Time
Webserver
Viewport
Cache-Key
Uber-Trace-Id
X-UA-Device-Type
X-Mode
X-Backend-TTL
X-UnsetCookies
X-CDN-Forward
X-Forwarded-Host
X-Cache-Remote
Rt-Fastcgi-Cache
X-Whom
Accept-Language
Mime-Version
X-Origin-TTL
X-Origin-CC
X-Daa-Tunnel
X-Info
X-From
Country
X-NGENIX-Cache
Content-Disposition
X-Varnish-Cache-Hits
Odigeo-Trace-Id
X-ApacheServer
X-Ruxit-Js-Agent
X-Cluster-Name
X-PERF
X-B3-Spanid
X-CLOUD-TRACE-CONTEXT
X-Magnolia-Registration
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Drupal-Cache-Contexts
X-Microcachable
ServedBy
X-Newrelic-Synthetics
X-Geo
X-TT-TIMESTAMP
X-Proxied
X-Device-Type
X-Routing-Service
X-Zipkin-Id
X-EC-Lua
X-Ttl
Section-Io-Cache
X-Via-Fastly
Cf-Ipcountry
X-Trafficlayer-App-Scope
Proxy-Connection
X-Trafficlayer-App-Name
X-Uri
Ohc-File-Size
X-Edge-Location
Ohc-Cache-HIT
HitType
X-UPSTREAM-Address
Geo-Info
X-Destination
Machine
X-B-Cookie
T-Server
Apple-News-Services-Handled
X-G
X-D
GEO-REGION-INFO
X-CF-Lambda-Version
Mobile-Detection-Method
Rendered-Blocks
Apple-News-Services-Host
Meta-Geo-Continent
X-Connection-Hash
X-CF-Lambda-Fn
Xc-Version
X-Geo-Header
X-A-Dcw
X-GeoIP-Country-Code
Fastcgi-X-Cache-Version
MD5-Digest
X-Date
Content-Script-Type
X-Nc
X-Transaction
X-Trv-Group
X-Aed
X-External-Request-Id
X-Vtex-Processado-Em
VivaBuild
Apple-News-Services-Parsed-Url
W
X-Vtex-Remote-Cache
Content-Style-Type
X-Twitter-Response-Tags
X-VG-WebServer
X-VG-WebCache
X-VG-TLSProxy
X-Vdms-Version
X-A-Dam
X-A-Ccd
X-Accel-Expires-Debug
X-A-Wwc
X-A-Dgt
X-A
X-No-Session
X-DPWN-IS-SECURE
X-Rocket-Build-Number
X-Rewrite-Enabled
X-Rojux
X-S
Viewtype
X-Request-UUID
X-Application
Apple-News-Services-Request-Url
AsisCache
X-Region-Sid
X-ARC
X-S-Cookie
BehaviorPad-Version
X-Sigma-Backend
X-SRCache-Key
X-Session-Fingerprint
X-Sigma
X-ScT
X-C
Access-Control-Request-Headers
User-Cache-Control
Environment
X-Eu-Site
Countrycode
X-Contensis-Viewer-Groups
X-Hit
Locid
CDCHOST
X-CUA
X-Auto-Login
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-App-Name
X-WebServer
Ha-Gx-Prefs
Gh-Request-Id
Server-Surrogate-Control
HA-Ipaddr
X-Agile-Id
X-Tumblr-Pixel-3
X-Varnish-Authentication
X-VC-Cache
X-TrackingId
X-Agile
X-SIPLIST1
X-Agile-Age
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Logging-Id
Fastly-SIE
Fastly-Soc-X-Request-Id
X-Distil-CS
Powered-By
X-Clientip
X-CGP
IsBot
Fastly-SWR
X-Cache-ASPX
Server-Cache-Control
X-Developers
X-Cache-Debug
Fastly-SSL
X-GoCache-CacheStatus
X-Cache-Backend
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-BBXSRF
X-Block-Status
X-Cache-Bucket
X-Bip
X-Debug-Cookies
X-AK-Request-ID
X-Backend-State
X-Cache-Info
X-Cache-Tags
X-Cms-Context
X-Core-Mission
X-Clara-WADP
X-Cdn-Srv
X-Cache-Time
X-Cache-URL
X-Debug-Cache-Expiry
X-LI-UUID
X-Webstats-RespID
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Real-IP
X-Request-URI
X-Render-Time
X-Proxy-Upstream
X-Platform-Server
X-Origin-Expires
X-Origin-Date
X-OVcl
X-OVcl-Cache
X-PHP-Host
X-We-Are-Hiring
X-Server-W
X-Urbn-Context-Path
X-Up
X-Urbn-Site-Id
X-User
X-Variation
X-VServer
X-TT-LOGID
X-Thanos
X-SVT-ORM-RULES
X-Servername
X-SVT-ORM-VERSION
X-TH-Server
X-WADP-Cache
X-NX-Host
X-NU-AKA-ACS-Version
X-Generated-In
X-Gen-Mode
X-Generation-Time
X-GeoIP-City
X-Hash
X-Has-Esi
X-Gamma-Serve
X-FW-Version
X-Distributor
X-Dispatcher-Server
X-Epic-Correlation-Id
X-Fastly-Cache
X-Fetched-On
X-Hnp-Log
X-IN-APIGATEWAY
X-Ms-Request-Id
X-LI-Proto
X-Ms-Version
X-Nginx-Cache-Key
X-NodeID
X-Li-Pop
X-Li-Fabric
X-Irp-Debug
X-IN-APIGATEWAYSSL
X-Is-Gdpr
X-JWT-State
X-Labrador-Cache-Channel
X-Debug-Log
X-Azure-Ref
AKAMAI
Platform
Cdncip
Request-Country
Request-EU
RNT-Time
RNT-Machine
X-Varnish-Beresp-Status
Cdnsip
Memcached
IBM-Web2-Location
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Grace
Is-Eu
Kp-EeAlive
Mail-Subject
Country-Code
Locale
Server-ID
Adler-Geo
V-Age
True-Client-Country-4JS
We-Hiring
Web-Mar-Node
Server-Int
X-Reboot
Wxu-Next-Hostname
X-Internal-Host
ServerName
X-Req
X-Core-Value
X-Instart-Isnd
Wxu-Next-Commit
FNAC-ModuleRouting
X-Owner
Heartbleed
X-Old-Content-Length
X-Air-Hostname
Fastly-Backend-Name
X-Generated-On
Thinkindot-CacheControl
X-Trace-Id
X-Trafficlayer-App-Version
X-Thinkindot-L3
X-Swa-Ws
Wxu-Next-Region
Server-Host
Thinkindot-CacheControl-Type
Thinkindot-Control
X-Level-Front-Cache
X-Micro-Cache
X-Matched-Rule
Cache-Host
X-ServiceProvider
PFcat
X-Nginx-Cache
Cache-Hits
X-Key
X-S-Maxage
X-Service
X-SERVER
X-Cache-Expired-At
X-Var-Ttl
Filterid
X-Sucuri-Cache
X-App-Version
X-Refresh
X-Lb-Id
X-Location
Pragrma
Group
S-Cnection
X-Response-By
X-TA-CDN-Provider
RequestId
X-Parent-Response-Time
X-CSRF-TOKEN
Powered-By-ChinaCache
X-Tb-Optimization-Total-Bytes-Saved
X-CF-Powered-By
X-Tec-Api-Root
X-Tec-Api-Version
X-Tec-Api-Origin
X-NC
ProcessTime
Memory
X-B3-Parentspanid
X-Wa
Origin
X-Ua
X-Cdn-Forward
X-Pjax-Url
X-Varnish-Cacheable
X-BACKEND-TTL
User-Agent
X-Pf-Uncompressing
X-B3-SpanId
X-CSRF-Token
X-Sucuri-ID
X-Server-IP
X-Via-CDN
SRV
X-Correlation-ID
X-NWS-UUID-VERIFY
PICS-Label
X-Developer
TTL
Geoip-Latitude
Geoip-City
X-Node-Id
GeoIp-Country-Code
X-Device-Os
X-COUNTRY
X-LAGOON
X-Vcl-Version
X-Cdn-Origin
X-Cache-Grace
X-Sn-Servicetimems
X-NGINX-Cache
X-Unique-ID
X-Cdn-Request-ID
Media-Length
On-Server
X-Ocache
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
X-Oss-Object-Type
X-Cache-Status-Check
X-Oss-Storage-Class
X-Servedbyhost
X-MSEdge-Flight
X-Litespeed-Cache
X-Webkit-CSP
Hostname
X-Request-Host
X-MSEdge-Features
A
M-TraceId
Dnion-Transfer-Encoding
X-Via-Ucdn
X-Varnish-Ttl
X-Rocket-Nginx-Bypass
XServer
X-Sucuri-Id
X-TIME
Tcn
SN
Cloudfront-Viewer-Country
X-FORWARDED-FOR
X-HS-Status
X-AIR-PT
X-Reqid
Esi-Enabled
X-Ratelimit-Remaining
Resin-Trace
Cdn
Who
X-Varnish-URL
X-Beluga-Node
X-Planisys-CDN-TTL
X-Policy
X-Beluga-Trace
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Fastly-Country-Code
X-Cache-Ttl
X-ServedByHost
X-Beluga-Status
Host-ID
X-Beluga-Record
X-Beluga-Cache-Status
X-Beluga-Response-Time
HostName
X-VHOST
CF-Cached-On
X-Request-Start
X-Azure-Ref-OriginShield
GeoIP-Country-Code
X-VCL-Version
Rt-Proxy-Cache
X-Slack-Backend
X-DC
X-Fastly-Backend-Reqs
X-Action
GeoIP-Latitude
Pics-Label
Ttl
CACHE
MIME-Version
X-Ftr-Cache-Host
X-Oracle-Dms-Rid
X-LiteSpeed-Cache-Control
X-Cache-FS-Status
Arc-Country
X-Dispatch
X-PAYTM-SRV-ID
X-Server-Time
X-Processor
X-DB
X-DI
X-Varnish-Url
X-DSS
X-DW
X-RPS
X-RPM
X-RSL
GeoIP-City
X-Method
X-Bc
X-APP
X-Zone
NtCoent-Length
Magicmarker
X-VarnishDD-TTL
X-Newrelic-App-Data
X-Skip-Cache
Pramga
Cteonnt-Length
X-PF-Uncompressing
X-FPC
X-Flog
X-ND-Cache
X-ABtesting
X-Ratelimit-Limit
X-Hello
X-HostName
X-SERVER-NAME
X-PJAX-URL
Amp-Access-Control-Allow-Source-Origin
Cdn-Request-Time
X-Edge-Server
Cdn-Host
WebServer
X-SRV
Fastly-Drupal-HTML
X-Svr
X-Be
X-Served-From
X-Dynatrace
X-Bc-Bl
N-Cache
X-DevSite-Last-Modified
Ohc-Response-Time
Processtime
X-BE
X-Dynatrace-Js-Agent
Load-Balancing
Servername
X-Swift-Error
Vix-Hermes-Req-Id
X-Amzn-Remapped-Connection
X-ID
X-Amzn-Remapped-Date
X-Backend-Host
Cache-Provider
X-Aicache-OS
X-WA
Section-Origin-Responded
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Io-Id
X-WR-MODIFICATION
X-Frame-Option
X-Fastly-Cache-Hits
X-Branch-Name
DSUID
CDN
CF-IPCountry
X-LB-ID
Lfy
X-StackifyID
Pagetype
X-Snapshot-Date
X-BC
X-MServer
Dynatrace
X-ZONE
Requestid
X-CACHE-AGE
Release
X-VCT
X-Hp-Ccpa-Warning
X-Apw-Access-Action
X-Apw-Access-Object
X-Apw-Access-Token
Proxy-Firewall
X-Apw-Hits
D-Cc-Upstream
Cache-Cookie-Set-From
FSS-Cache
X-Configured-By
V-Cache
Cache-Cookie-Set-Idcheck
X-Request-Url
Cache-Cookie-Set-Lfrom
FSS-Proxy
WZWS-RAY
X-Tid
X-Cc-Req-Id
X-Cc-Via
Warning
X-Fmm-Version
X-SB
X-VC
X-Adobe-Source
X-Litespeed-Cache-Control
Trailer
X-WPE-Loopback-Upstream-Addr
Cneonction
CloudFront-Viewer-Country
X-Request-URL
X-Worker
WP-Super-Cache
X-Upstream-Ct
X-Upstream-Ht
Correlation-Id
X-App
SD-X-WS
X-ElasticPress-Search
X-Edge-IP
X-Varnish-Beresp-TTL
X-Check-Cacheable
Backend-Name
X-SD-PageType
X-Powered-Y
X-Fastly-Cache-Status