Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
Link
CF-RAY
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-UA-Compatible
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Permitted-Cross-Domain-Policies
X-Request-ID
X-Cacheable
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-DNS-Prefetch-Control
X-Ua-Compatible
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
Status
X-Content-Security-Policy
X-CDN
Content-Encoding
Upgrade
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Xss-Protection
X-Kinja-Server-Push
Keep-Alive
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
P3p
Xkey
X-Pass-Why
X-Cache-Group
X-Envoy-Upstream-Service-Time
CF-Ray
X-AH-Environment
X-Backend
X-Age
X-Server
X-Via
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Server-Powered-By
X-Page-Speed
X-Pingback
EagleId
X-Proxy-Cache
X-Nginx-Cache-Status
X-UA-Device
X-Ws-Request-Id
X-Hacker
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
Grace
Cf-Railgun
X-Swift-SaveTime
X-Swift-CacheTime
X-Amz-Version-Id
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
X-LiteSpeed-Cache
Report-To
X-Server-Id
X-Rq
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-WebKit-CSP
X-Host
X-Device
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Origin-Cache
X-Response-Time
Content-Location
X-Node
X-Ac
Surrogate-Control
X-Vhost
X-Readtime
Request-Id
X-Backend-Server
X-Cloud-Trace-Context
X-Dispatcher
X-Origin-Upstream-Status
X-Cnection
X-HW
X-ORACLE-DMS-ECID
X-Application-Context
Fusion-Source
Fusion-Content-Source
Fusion-Component-Id
Fusion-Content-Id
Fusion-Template-Id
X-DataDome
X-ORACLE-DMS-RID
NEL
X-Cache-Lookup
X-Mod-Pagespeed
Edge-Control
Rating
X-Rack-Cache
X-Country
X-Akam-SW-Version
X-Clacks-Overhead
Pinterest-Generated-By
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Ruxit-JS-Agent
X-Varnish-TTL
X-DynaTrace
X-Country-Code
Allow
Accept-Ch
X-Instart-Request-ID
X-TtlSet
X-Goog-Hash
X-Vname
X-PC
X-FTR-Request-ID
Verso
X-TTL
X-ESI
Accept-Ch-Lifetime
X-B3-TraceId
X-Powered-By-Plesk
Service-Worker-Allowed
X-Url
Content-MD5
X-Forwarded-Proto
X-Version
X-MS-InvokeApp
X-GitHub-Request-Id
X-GoogleNews-Bot
X-Cdn-Fetch
X-Exp-Id
X-Exp-Variant
X-Kinja
X-Use-Magma
X-Kinja-Server
X-Kinja-Revision
X-Kinja-Build
Edge-Cache-Tag
X-Px
RTSS
AR-CACHE
Ar-Sid
AR-PoweredBy
AR-ATIME
AR-Request-ID
X-Debug
X-Abt-Application-Version
X-Server-Name
X-D2id
Charset
X-NF-Request-ID
SPRequestGuid
X-Amz-Server-Side-Encryption
X-Vcache
X-Accel-Expires
X-Cached
X-MSEdge-Ref
X-Powered-CMS
X-Amz-Rid
Arr-Disable-Session-Affinity
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Middleton-Display
Pagespeed
X-Sol
Display
X-Middleton-Response
X-Vcap-Request-Id
Response
X-Navigation-Version
X-Pinterest-Rid
Pinterest-Version
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-SharePointHealthScore
X-Trace
TCN
X-Cdn
X-VARITI-CCR
Realpath
Public-Key-Pins
X-Client-IP
Cache-Tag
X-Fastcgi-Cache
Access-Control-Request-Method
S
X-Upstream
X-Fastly-Request-ID
X-Ser
X-DynaTrace-JS-Agent
MS-Author-Via
X-Id
X-Shard
SPIisLatency
SPRequestDuration
X-Hp-Webp
Nginx-Cache
Mrf-Cache-Status
MRF-Tech
X-Mrf-Item-Lastmod
X-B3-TraceId-Primal
X-Mrf-Section-Lastmod
X-Ezoic-Cdn
X-Forwarded-For
X-Content-Type
X-Amz-Meta-S3cmd-Attrs
X-T
X-Amzn-Trace-Id
X-Recruiting
DynaTrace
X-Grace
Front-End-Https
X-Hits
Fastcgi-Cache
X-Varnish-Age
ServerID
X-DIS-Request-ID
MicrosoftSharePointTeamServices
X-Mobile-URL
X-Dw-Request-Base-Id
X-Node-Name
NR-ENABLED
X-Element-Page-Cache
Nel
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Hub-Id
X-HS-Cache-Config
X-Content-Digest
X-Frontend
X-Edge-O15-RID
Powered
X-Goog-Storage-Class
X-Goog-Generation
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-FTR-Expires
X-Country-Code-Real
Server-Name
X-FTR-Cache-Status
Alternate-Protocol
X-Cache-TTL
TP-L2-Cache
X-FTR-Realm
X-Logged-In
X-FTR-Backend
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-DC
TP-Cache
Server-Node
X-Correlation-Id
X-Webkit-Csp
AMP-Access-Control-Allow-Source-Origin
X-Jurisdiction
X-Request-Received
X-XRDS-Location
X-Request-Processing-Time
X-Microsite
X-Request-Handler-Origin-Region
X-ATS-Timestamp
Backend-Timing
Upgrade-Insecure-Requests
X-Server-ID
X-Shield-Request-Id
X-Webapp-Samesite-None-Activated-N
X-Origin-Server
X-Page-Id
X-User-Agent
X-Content-Security-Policy-Report-Only
X-Rid
X-Content-Options
X-Revision
X-Akamai-Edgescape
Refresh
X-Cache-Hit
X-F-Cache
X-Varnish-Grace
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Type
X-XRDS-LOCATION
Fastly-Restarts
X-Content-Powered-By
X-Zen-Fury
X-Geo-Country
X-Pad
X-B3-Sampled
X-Analytics
X-URL
X-Az
X-LB-Cache
X-AppVersion
X-Activity-Id
X-B
X-N
X-RateLimit-Remaining
X-Ttl
X-Kinsta-Cache
X-Ruxit-Js-Agent
X-FTR-Cache-Host
PB-PID
PB-RID
X-CST
X-Cache-Age
X-TT
X-AOL-HN
X-Mobile-Rewrite
Arc-Version
Cache-Status
X-Request-Guid
X-Jobs
X-WebKit-CSP-Report-Only
Actual-Object-TTL
X-Tumblr-User
Paypal-Debug-Id
X-Instance
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Framework
X-B-Cache
X-App-Environment
X-Signature
DC
X-Debug-Info
Access-Control-Allow-Method
X-FB-Debug
X-PHP-Backend
X-Load-Cache
X-Cache-Action
X-Time
X-Git-Hash
X-Erf-Bev-Bev-Is-Generated
Fastcgi-Useragent
Surrogate-Key
X-Erf-Bev-Bev
X-Varnish-Backend
FilterID
X-FastCGI-Cache
Host-Header
X-Cached-By
X-Tt-Trace-Tag
X-IPLB-Instance
X-Contextid
MS-CV
X-SS-Set-Cookie
X-Amz-Replication-Status
X-Tt-Trace-Host
X-Cluster
Tracecode
X-ATG-Version
X-Cache-Key
NGB
X-Srv
X-Accel-Buffering
X-Response-Served-From
Frame-Options
X-RequestSource
X-FW-Type
X-FW-Server
X-WA-Info
X-FW-Serve
WPE-Backend
X-FW-Static
X-FW-Hash
X-Cache-NE
Host
Eomportal-Instance
Xserver
X-Varnish-Server
Payment
X-Cache-2
X-Region
X-Adobe-Content
X-Adobe-Loc
Source
X-Tumblr-Pixel-1
X-Varnish-Hostname
X-TX-ID
X-Cacheable-TTL
X-Cache-Enabled
Cache-Tv-Group
X-Is-Bot
X-Tumblr-Pixel-2
X-Host-Name
X-IPS-LoggedIn
Filters
X-Rendered-As
X-GeoIP
X-Mobile
X-Oneagent-Js-Injection
X-Kong-Proxy-Latency
X-NewRelic-App-Data
X-Kong-Upstream-Latency
X-Seen-By
Cleartype
X-Cache-Operation
X-EdgeConnect-Cache-Status
X-Cache-Rule
X-Origin-Response-Time
X-Via-JSL
X-Cache-TTL-Remaining
X-Hostname
Cache
X-ORACLE-APMCS-TAG
X-ORACLE-APMCS-REQUEST-ID
X-VCache
X-Cache-Control
X-PressLabs-Stats
X-HTML-Minification-Powered-By
Datacenter
Healthy
X-Trafficlayer-App-Name
Server-Info
X-Trafficlayer-App-Scope
Retry-After
Ms-Operation-Id
Accept-CH
X-RTag
X-ProcessESI
X-RemovedCookies
X-RateLimit-Limit
X-Dc
X-Presslabs-Stats
Liferay-Portal
X-Source
X-Rule
X-L-Path
X-Environment-Context
X-UA
X-NWS-LOG-UUID
X-FireWall-Port
X-CACHE-KEY
X-Cache-Server
From-Origin
Version
X-Status
X-Wix-Request-Id
X-Esi
X-Endurance-Cache-Level
X-Upgrade-Enabled
X-Aspnetmvc-Version
X-Handled-By
X-ES-SERVER
X-Cache-Var-Map
Meta-Geo
X-Cache-Var
X-Path-Route
X-RN-RSRV
X-B3-Traceid
Mn-Server-Ip
OT-Force-Account-Verify
X-Timing-Wait
Accept-CH-Lifetime
Selected-Fe
X-Proxy-Build
X-Content-Age
X-RCS-CacheZone
X-FW-Dynamic
X-Sorting-Hat-ShopId
X-VWS-Id
X-Origin-Hint
X-Sorting-Hat-PodId
X-Proto
X-Akamai-Request-ID
X-Shopify-Stage
Cache-Tags
X-Backend-Name
X-Storage
X-LJ-Flow-ID
X-Access
TWC-Device-Class
X-AWS-Id
X-EIG-Tracking-Id
Azure-Version
X-Alternate-Cache-Key
TWC-Connection-Speed
Azure-SlotName
X-Format
Webcakes-Region
Azure-RegionName
TWC-Locale-Group
Azure-SiteName
TWC-Privacy
TWC-GeoIP-LatLong
X-Qloud-Router
Azure-InstanceId
X-Goog-Meta-Goog-Reserved-File-Mtime
Akamai-GRN
TWC-GeoIP-Country
Property-Id
Webcakes-App-Name
X-ShopId
Webcakes-App-Version
X-Shopify-Generated-Cart-Token
X-Request-Time
X-ShardId
X-Tb
X-Section
X-Cache-Config
DB-Nickname
X-Cache-Host
X-Akamai-Request-ID2
Origin-Cache-Control
Decoy-Debug-Key
X-App-Server
X-Web-Node
X-Xfnlog-Site
X-BYPASS-REASON
X-Origin
X-SaId
NGX
X-Pubstack
X-Viewer-Country
X-ServerID
X-ProxyCache-Status
X-Generated-By
X-Proxy-Cache-Status
X-Proxy
X-JoinUs
Now
X-Hosted-By
Node
X-Vgn-Hpd-Reason
Origin-Edge-Control
X-ProxyCache-Key
S-Rt
X-OCL
X-Hyper-Cache
Decoy-Debug-TTL
Decoy-Debug-Status
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Cluster-Node
X-Debug-Cache
Ec-Rule-Version
X-PCL
X-Soup
X-Time-Microsecs
X-UUID
X-FC-Vary-Parameters
X-Human
X-CCM
X-Say-Cacheable
X-Say-TTL
X-Redis-Cache
X-Hl-Ver
X-IP
X-Locale
X-SayCDN-TTL
X-Site-Version
X-Varnish-Hits
X-BCube-Filmed-By
X-MP-GENERATED-AT
X-NYM-Debug-Backend
X-Generated
X-Detected-As
X-Www-Served-By
Cross-Origin-Window-Policy
X-Amzn-Remapped-Content-Length
X-FB-TRIP-ID
X-R9-Blue-Green-Version
X-TNCMS
L5d-Success-Class
X-Loop
Cache-Name
X-CS
Srv
Uber-Trace-Id
X-Akamai-Transformed
Webserver
Accept-Charset
Viewport
Time
X-APP-VERSION
X-Unique-Id
X-NCache
X-Drupal-Cache-Tags
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
GEO-INFO
X-Cache-Remote
X-UA-Device-Type
X-From
X-TT-TIMESTAMP
X-Backend-TTL
X-CDN-Forward
Cache-Key
X-Cluster-Name
Mime-Version
X-Origin-CC
X-Origin-TTL
X-Edge-Location
X-Drupal-Cache-Contexts
Accept-Language
Odigeo-Trace-Id
X-Mode
X-EC-Lua
Country
X-Microcachable
X-CLOUD-TRACE-CONTEXT
Rt-Fastcgi-Cache
X-Info
X-Newrelic-Synthetics
Ohc-File-Size
X-App-Version
X-Forwarded-Host
Ohc-Cache-HIT
X-No-Session
X-Geo
X-UnsetCookies
X-Magnolia-Registration
Proxy-Connection
X-PERF
X-ApacheServer
X-Whom
X-B3-Spanid
X-UPSTREAM-Address
ServedBy
X-Varnish-Cache-Hits
Content-Disposition
X-Zipkin-Id
Geo-Info
X-Labrador-Cache-Channel
X-Routing-Service
X-Proxied
X-PHP-Host
X-Real-IP
Fastly-SSL
X-Application
Fastcgi-X-Cache-Version
Rendered-Blocks
X-Accel-Expires-Debug
X-Aed
X-ARC
X-B-Cookie
X-Connection-Hash
AsisCache
Content-Script-Type
Content-Style-Type
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-A-Wwc
X-A-Dcw
X-A
Viewtype
Machine
MD5-Digest
Mobile-Detection-Method
Meta-Geo-Continent
X-Device-Type
IsBot
X-A-Dam
VivaBuild
X-A-Ccd
T-Server
GEO-REGION-INFO
X-A-Dgt
X-GeoIP-Country-Code
X-Request-UUID
X-Rewrite-Enabled
Cf-Ipcountry
X-Region-Sid
X-Twitter-Response-Tags
X-Trv-Group
X-Rojux
X-S
X-SRCache-Key
X-Session-Fingerprint
X-Transaction
X-ScT
X-S-Cookie
BehaviorPad-Version
X-G
X-Date
X-Destination
X-D
X-Cache-Time
Xc-Version
X-DPWN-IS-SECURE
X-Vtex-Remote-Cache
X-External-Request-Id
X-Vdms-Version
X-SIPLIST1
X-VG-WebCache
X-VG-WebServer
X-Vtex-Processado-Em
X-NGENIX-Cache
X-C
User-Cache-Control
Locid
Apple-News-Services-Host
Gh-Request-Id
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
X-CUA
X-Wikidot-Backend
X-Developers
X-Core-Mission
X-Wikidot-Static-Cache
FNAC-ModuleRouting
Apple-News-Services-Request-Url
Environment
X-Sigma
X-Sigma-Backend
X-VG-TLSProxy
X-Rocket-Build-Number
X-App-Name
W
Fastly-Soc-X-Request-Id
Fastly-Backend-Name
X-WebServer
X-Cache-URL
X-Req
X-Nginx-Cache-Key
Server-Int
X-Tumblr-Pixel-3
Server-Surrogate-Control
Wxu-Next-Region
Wxu-Next-Hostname
X-Thanos
X-TrackingId
Server-Cache-Control
X-Logging-Id
X-Auto-Login
X-Bip
X-Cache-ASPX
X-Cache-Debug
X-Geo-Header
Powered-By
RNT-Time
RNT-Machine
X-Varnish-Authentication
Wxu-Next-Commit
X-Contensis-Viewer-Groups
X-Uri
Access-Control-Request-Headers
X-Cache-Backend
X-Ah-Environment
X-Key
X-AK-Request-ID
X-Li-Fabric
X-Azure-Ref
X-Sucuri-Cache
X-Render-Time
X-Hit
X-Internal-Host
X-Cache-Info
X-Cache-Bucket
X-Irp-Debug
X-Li-Pop
X-Block-Status
X-BBXSRF
X-LI-UUID
Web-Mar-Node
CDCHOST
We-Hiring
X-NodeID
X-NX-Host
V-Age
X-Ms-Version
X-Ms-Request-Id
HA-Ipaddr
X-Instart-Isnd
X-Location
Ha-Gx-Prefs
X-Micro-Cache
X-LI-Proto
X-Cdn-Srv
X-Distributor
X-Agile-Id
X-Dispatcher-Server
X-GoCache-CacheStatus
X-Debug-Cookies
X-Debug-Log
X-Agile-Age
X-Fastly-Cache
X-Generated-In
X-Generation-Time
X-Gen-Mode
X-Gamma-Serve
X-FW-Version
X-Agile
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Clientip
X-Cms-Context
X-Clara-WADP
X-Hnp-Log
X-Origin-Date
X-IN-APIGATEWAY
X-Eu-Site
X-Epic-Correlation-Id
X-Backend-State
X-Debug-Cache-Expiry
X-User
X-CGP
X-Hash
X-Distil-CS
X-IN-APIGATEWAYSSL
X-Varnish-Beresp-Grace
Kp-EeAlive
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
IBM-Web2-Location
X-Swa-Ws
Heartbleed
Locale
X-VServer
Memcached
X-Webstats-RespID
X-We-Are-Hiring
True-Client-Country-4JS
Mail-Subject
X-TH-Server
X-Trace-Id
Cdnsip
AKAMAI
Cdncip
Cache-Host
X-Urbn-Site-Id
X-Urbn-Context-Path
Country-Code
Countrycode
Fastly-SWR
X-VC-Cache
X-Via-Fastly
Fastly-SIE
X-TT-LOGID
X-Request-URI
X-WADP-Cache
Request-Country
X-Owner
X-OVcl-Cache
X-Varnish-Beresp-Status
Request-EU
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Varnish-Beresp-Ttl
X-Origin-Expires
Server-ID
X-OVcl
Section-Io-Cache
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Proxy-Upstream
HitType
X-Trafficlayer-App-Version
Thinkindot-CacheControl
X-Variation
Thinkindot-Control
X-Generated-On
X-Old-Content-Length
Thinkindot-CacheControl-Type
X-Up
Server-Host
X-NU-AKA-ACS-Version
X-GeoIP-City
Adler-Geo
X-Core-Value
X-Cache-Tags
X-Level-Front-Cache
X-ServiceProvider
X-S-Maxage
Platform
X-Is-Gdpr
X-JWT-State
ServerName
X-Server-W
X-Thinkindot-L3
X-Has-Esi
X-Matched-Rule
X-Reboot
X-Platform-Server
Is-Eu
X-Daa-Tunnel
X-TA-CDN-Provider
X-Nginx-Cache
X-B3-Parentspanid
X-Refresh
PFcat
X-SERVER
X-Lb-Id
X-Response-By
X-Fetched-On
X-B3-SpanId
X-Service
X-Nc
Cache-Hits
X-Servername
RequestId
X-Server-IP
X-NC
X-Tb-Optimization-Total-Bytes-Saved
X-CSRF-TOKEN
X-CF-Powered-By
ProcessTime
X-Tec-Api-Root
X-Tec-Api-Origin
X-Tec-Api-Version
X-Parent-Response-Time
Memory
X-Ua
X-Wa
X-Cdn-Request-ID
X-Air-Hostname
X-Pjax-Url
Origin
Media-Length
X-Cdn-Forward
Group
X-Var-Ttl
Pragrma
User-Agent
X-Cache-Expired-At
Filterid
X-CSRF-Token
X-Sucuri-Id
SRV
X-Unique-ID
X-BACKEND-TTL
X-Correlation-ID
Powered-By-ChinaCache
Geoip-Latitude
TTL
X-Pf-Uncompressing
S-Cnection
X-Reqid
X-AIR-PT
GeoIp-Country-Code
X-Vcl-Version
X-COUNTRY
Esi-Enabled
X-NGINX-Cache
X-Rocket-Nginx-Bypass
PICS-Label
X-Varnish-Cacheable
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
X-Policy
X-TIME
X-Servedbyhost
X-Sucuri-ID
X-Litespeed-Cache
X-Webkit-CSP
X-Request-Start
X-Azure-Ref-OriginShield
SN
HostName
X-Via-Ucdn
X-Via-CDN
Geoip-City
Dnion-Transfer-Encoding
Rt-Proxy-Cache
XServer
X-HS-Status
M-TraceId
X-Developer
X-NWS-UUID-VERIFY
X-FORWARDED-FOR
X-Fastly-Country-Code
Magicmarker
Tcn
X-Ocache
X-Method
X-Device-Os
X-Node-Id
X-LAGOON
X-Sn-Servicetimems
Load-Balancing
X-Cdn-Origin
On-Server
Who
X-Cache-Grace
X-Cache-Ttl
Resin-Trace
Cdn
X-VHOST
X-Ftr-Cache-Host
X-MSEdge-Features
X-MSEdge-Flight
CF-Cached-On
X-Request-Host
A
X-ServedByHost
DSUID
Ohc-Response-Time
X-Be
Pics-Label
NtCoent-Length
X-Svr
Cloudfront-Viewer-Country
Release
X-VCL-Version
GeoIP-Country-Code
X-MServer
X-VCT
X-DC
Ttl
GeoIP-Latitude
Vix-Hermes-Req-Id
X-Oss-Request-Id
X-Beluga-Node
X-Beluga-Cache-Status
X-Beluga-Record
X-Beluga-Response-Time
X-Beluga-Status
X-Oss-Storage-Class
X-Bc
X-Oss-Hash-Crc64ecma
X-APP
X-Oss-Object-Type
X-Oss-Server-Time
X-Zone
X-Beluga-Trace
X-Oracle-Dms-Rid
X-Cache-Status-Check
Hostname
MIME-Version
X-Hp-Ccpa-Warning
X-Varnish-Url
X-Varnish-URL
GeoIP-City
Cteonnt-Length
X-Fastly-Backend-Reqs
X-VarnishDD-TTL
X-LiteSpeed-Cache-Control
X-PF-Uncompressing
X-Newrelic-App-Data
X-Configured-By
X-Datadome
X-Upstream-Ht
Host-ID
X-SRV
X-PJAX-URL
X-Ftr-Request-Id
X-Upstream-Ct
X-SD-PageType
SD-X-WS
X-WR-MODIFICATION
X-Ratelimit-Remaining
X-HostName
X-SN
X-BE
X-Aicache-OS
Processtime
X-Tid
X-Slack-Backend
X-Cache-Id
X-Compress-Hint
X-Dynatrace
X-Dynatrace-Js-Agent
Servername
CACHE
X-Release
X-DSS
X-RPS
X-DW
L
WebServer
Cache-Provider
X-Via-NSCOPI
X-RSL
X-ID
X-RPM
X-Swift-Error
X-DI
X-DB
X-Action
X-Frame-Option
Amp-Access-Control-Allow-Source-Origin
X-Ftr-Realm
X-StackifyID
X-Scheme
X-Ratelimit-Limit
Requestid
Dynatrace
X-Ftr-Dc
X-PAYTM-SRV-ID
LB
X-Server-Time
X-Processor
Lfy
Pagetype
X-Fastly-Cache-Hits
X-Ftr-Backend
X-Ftr-Backend-Server
Arc-Country
CDN
X-Branch-Name
X-LB-ID
X-Snapshot-Date
CF-IPCountry
X-ServerName
X-Ftr-Balancer
X-CACHE-AGE
X-ABtesting
D-Cc-Upstream
Warning
X-DevSite-Last-Modified
X-Skip-Cache
Fastly-Drupal-HTML
X-Dispatch
X-Flog
X-ND-Cache
X-Hello
Pramga
X-Cache-FS-Status
X-Cc-Req-Id
X-Cc-Via
X-FPC
X-Apw-Hits
Proxy-Firewall
UCS
X-Apw-Access-Object
X-Apw-Access-Token
X-ZONE
X-Edge-IP
Cache-Cookie-Set-From
X-Node-ID
X-Varnish-Beresp-TTL
X-Request-Url
X-Apw-Access-Action
Cache-Cookie-Set-Lfrom
X-SB
X-VC
Cache-Cookie-Set-Idcheck
V-Cache
NnCoection
N-Cache
X-Powered-Y
Lb
X-Request-URL
X-Litespeed-Cache-Control
Backend-Name
X-ElasticPress-Search
WP-Super-Cache
X-BC
X-Check-Cacheable
X-App
Correlation-Id
X-Fastly-Cache-Status
X-Worker