Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
Link
ETag
CF-RAY
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-Request-ID
X-DNS-Prefetch-Control
CF-Ray
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
Status
Upgrade
X-Content-Security-Policy
X-CDN
Content-Encoding
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Xss-Protection
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
X-Pass-Why
X-Cache-Group
Xkey
X-AH-Environment
P3p
X-Envoy-Upstream-Service-Time
X-Via
X-Backend
X-Server
X-Age
X-Ua-Compatible
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Ws-Request-Id
X-Server-Powered-By
X-Page-Speed
X-Pingback
EagleId
X-Proxy-Cache
X-Hacker
X-UA-Device
X-Nginx-Cache-Status
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
Cf-Railgun
Grace
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Amz-Version-Id
Report-To
X-LiteSpeed-Cache
X-Rq
X-OneAgent-JS-Injection
X-WebKit-CSP
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Server-Id
X-Device
X-Host
X-Origin-Cache
X-Response-Time
EagleEye-TraceId
X-Node
X-Ac
Content-Location
Surrogate-Control
X-Vhost
X-Readtime
X-Backend-Server
X-Cloud-Trace-Context
Request-Id
X-Dispatcher
X-Origin-Upstream-Status
X-Cnection
X-Application-Context
X-HW
X-Cache-Lookup
X-ORACLE-DMS-ECID
Fusion-Source
Fusion-Content-Id
Fusion-Template-Id
Fusion-Content-Source
Fusion-Component-Id
X-Ruxit-JS-Agent
X-ORACLE-DMS-RID
NEL
X-DataDome
X-Mod-Pagespeed
Rating
X-Rack-Cache
Edge-Control
X-Country
X-Akam-SW-Version
X-Clacks-Overhead
X-Dns-Prefetch-Control
Pinterest-Generated-By
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-TTL
Allow
X-Country-Code
Accept-Ch
X-DynaTrace
X-FTR-Request-ID
X-Instart-Request-ID
X-Varnish-TTL
X-Goog-Hash
X-TtlSet
X-PC
X-Vname
X-ESI
Verso
Accept-Ch-Lifetime
Content-MD5
Service-Worker-Allowed
X-Powered-By-Plesk
X-Url
X-B3-TraceId
X-Forwarded-Proto
X-Version
X-MS-InvokeApp
X-Exp-Variant
X-Cdn-Fetch
X-Use-Magma
X-Kinja
X-Exp-Id
X-Kinja-Build
X-GoogleNews-Bot
X-Kinja-Revision
X-Kinja-Server
X-GitHub-Request-Id
RTSS
Edge-Cache-Tag
X-D2id
X-Debug
X-Abt-Application-Version
X-Server-Name
X-Px
Ar-Sid
X-Vcache
AR-Request-ID
AR-CACHE
AR-PoweredBy
AR-ATIME
SPRequestGuid
X-Amz-Server-Side-Encryption
Charset
X-NF-Request-ID
X-Cached
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Vcap-Request-Id
X-Sol
Response
Pagespeed
X-Middleton-Display
Display
X-Middleton-Response
X-Accel-Expires
X-Navigation-Version
Arr-Disable-Session-Affinity
X-MSEdge-Ref
X-Amz-Rid
X-Pinterest-Rid
X-Fastcgi-Cache
Pinterest-Version
TCN
X-SharePointHealthScore
X-Powered-CMS
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-VARITI-CCR
X-Trace
Cache-Tag
Public-Key-Pins
Realpath
X-Fastly-Request-ID
X-Client-IP
X-Cdn
MS-Author-Via
X-Ser
Access-Control-Request-Method
Nginx-Cache
X-Edge-O15-RID
X-DynaTrace-JS-Agent
X-Shard
SPRequestDuration
X-Upstream
X-Server-ID
SPIisLatency
S
X-Content-Type
Mrf-Cache-Status
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
X-B3-TraceId-Primal
MRF-Tech
X-Id
X-Amzn-Trace-Id
X-Ezoic-Cdn
X-Hp-Webp
X-Grace
X-Forwarded-For
X-T
X-Amz-Meta-S3cmd-Attrs
Front-End-Https
X-Hits
Fastcgi-Cache
X-Recruiting
DynaTrace
X-Jurisdiction
Nel
X-Cache-TTL
X-Aspnet-Version
X-Varnish-Age
ServerID
X-Element-Page-Cache
MicrosoftSharePointTeamServices
X-Content-Digest
X-Mobile-URL
X-Node-Name
X-FTR-Cache-Status
X-FTR-Realm
X-FTR-Expires
X-Country-Code-Real
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-DC
X-DIS-Request-ID
X-FTR-Backend
X-Dw-Request-Base-Id
NR-ENABLED
X-HS-Combine-CSS
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Hub-Id
Powered
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Frontend
X-Goog-Generation
Server-Node
TP-L2-Cache
TP-Cache
Alternate-Protocol
X-Logged-In
Server-Name
X-CST
AMP-Access-Control-Allow-Source-Origin
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Request-Processing-Time
Upgrade-Insecure-Requests
X-Request-Received
X-Correlation-Id
X-Microsite
X-Request-Handler-Origin-Region
X-Cache-Hit
Backend-Timing
X-ATS-Timestamp
X-XRDS-Location
Fastly-Restarts
X-Content-Options
X-Origin-Server
X-F-Cache
X-Rid
X-Akamai-Edgescape
X-Page-Id
Refresh
X-User-Agent
X-Zen-Fury
X-Content-Security-Policy-Report-Only
X-Revision
X-Varnish-Grace
X-XRDS-LOCATION
X-Type
X-Content-Powered-By
X-LB-Cache
X-FTR-Cache-Host
X-B
X-B3-Sampled
PB-RID
PB-PID
X-Geo-Country
X-Activity-Id
X-Az
Arc-Version
X-Mobile-Rewrite
X-AppVersion
Cache-Status
X-URL
X-N
X-Kinsta-Cache
X-Cache-Age
X-TT
X-Time
X-Signature
X-B-Cache
X-Pad
X-AOL-HN
Paypal-Debug-Id
X-Jobs
X-Debug-Info
X-Instance
Actual-Object-TTL
X-Shield-Request-Id
X-Tumblr-Pixel-0
X-Tumblr-User
Access-Control-Allow-Method
X-Tumblr-Pixel
X-WebKit-CSP-Report-Only
X-FB-Debug
X-Cache-Action
X-App-Environment
X-Framework
X-Request-Guid
X-PHP-Backend
X-Load-Cache
X-Cached-By
X-Git-Hash
DC
Fastcgi-Useragent
X-RateLimit-Remaining
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Varnish-Backend
X-Amz-Replication-Status
Surrogate-Key
X-Webkit-Csp
Host-Header
X-IPLB-Instance
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Webapp-Samesite-None-Activated-N
MS-CV
X-Contextid
X-ATG-Version
X-WA-Info
X-Analytics
X-SS-Set-Cookie
Host
X-NWS-LOG-UUID
X-ORACLE-APMCS-REQUEST-ID
X-ORACLE-APMCS-TAG
X-Mobile
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Tracecode
X-Accel-Buffering
X-Response-Served-From
NGB
X-Cluster
X-Host-Name
FilterID
X-Via-JSL
Payment
X-Cache-Key
WPE-Backend
X-FastCGI-Cache
X-Cache-NE
Xserver
X-FW-Server
X-FW-Static
Eomportal-Instance
X-FW-Serve
X-Cache-2
X-Varnish-Server
X-FW-Hash
X-FW-Type
X-IPS-LoggedIn
X-GeoIP
Filters
X-Region
Frame-Options
X-Tumblr-Pixel-2
Cache-Tv-Group
X-Origin-Response-Time
X-Varnish-Hostname
X-Tumblr-Pixel-1
X-Cache-Enabled
Source
X-Cacheable-TTL
X-Adobe-Content
X-Adobe-Loc
X-Presslabs-Stats
X-Srv
X-RequestSource
X-Cache-Operation
X-Cache-Rule
X-Rendered-As
X-Seen-By
X-Is-Bot
Retry-After
X-Hostname
X-EdgeConnect-Cache-Status
X-TX-ID
X-NewRelic-App-Data
Server-Info
X-Cache-TTL-Remaining
Cleartype
X-RemovedCookies
X-ProcessESI
Liferay-Portal
X-VCache
X-App-Server
X-Dc
Accept-CH
X-RTag
X-B3-Traceid
Ms-Operation-Id
X-FireWall-Port
X-L-Path
X-Source
X-Environment-Context
Datacenter
X-CACHE-KEY
X-HTML-Minification-Powered-By
X-UA
X-Endurance-Cache-Level
X-Handled-By
X-Upgrade-Enabled
From-Origin
X-Cache-Server
X-CLOUD-TRACE-CONTEXT
X-Backend-Name
Cache
X-Cache-Control
Healthy
X-APP-VERSION
Accept-CH-Lifetime
X-Wix-Request-Id
X-Cache-Var-Map
Meta-Geo
X-Cache-Var
X-ES-SERVER
Accept-Charset
X-Path-Route
X-RN-RSRV
X-PressLabs-Stats
X-Section
OT-Force-Account-Verify
X-Timing-Wait
X-Status
Selected-Fe
Srv
X-Access
X-UUID
X-Proxy-Build
X-Format
X-ShardId
X-Sorting-Hat-ShopId
X-Content-Age
X-Tb
X-OCL
Mn-Server-Ip
Azure-Version
X-Sorting-Hat-PodId
X-PCL
X-Proto
Azure-InstanceId
X-Shopify-Stage
Azure-RegionName
X-Shopify-Generated-Cart-Token
Cache-Tags
Azure-SlotName
X-Origin
Azure-SiteName
X-ShopId
X-NYM-Debug-Backend
X-EIG-Tracking-Id
X-FC-Vary-Parameters
X-Cache-Config
Version
X-Alternate-Cache-Key
X-Request-Time
X-Akamai-Request-ID
X-ProxyCache-Key
X-BYPASS-REASON
X-AWS-Id
Decoy-Debug-Status
DB-Nickname
X-Hosted-By
Decoy-Debug-Key
X-Human
X-Generated-By
Akamai-GRN
X-Cluster-Node
X-Debug-Cache
X-FW-Dynamic
X-Goog-Meta-Goog-Reserved-File-Mtime
X-ServerID
X-Hl-Ver
X-ProxyCache-Status
X-Proxy
X-Redis-Cache
X-Qloud-Router
X-Time-Microsecs
X-Akamai-Request-ID2
X-VWS-Id
X-SaId
X-Vgn-Hpd-Reason
X-Soup
X-Pubstack
X-JoinUs
X-Hyper-Cache
X-LJ-Flow-ID
X-Proxy-Cache-Status
Node
Origin-Edge-Control
Origin-Cache-Control
Now
Ec-Rule-Version
Decoy-Debug-TTL
GEO-INFO
X-Storage
X-RateLimit-Limit
X-Yottaa-Optimizations
X-Yottaa-Metrics
Webcakes-Region
TWC-Device-Class
X-Rule
TWC-Connection-Speed
Webcakes-App-Version
TWC-GeoIP-Country
TWC-Privacy
X-Amzn-Remapped-Content-Length
TWC-GeoIP-LatLong
Webcakes-App-Name
TWC-Locale-Group
X-FB-TRIP-ID
X-Origin-Hint
X-TNCMS
X-Site-Version
X-Say-Cacheable
X-SayCDN-TTL
X-Say-TTL
X-MP-GENERATED-AT
X-Loop
X-Www-Served-By
Property-Id
X-Web-Node
X-Generated
X-Varnish-Hits
X-Viewer-Country
X-CCM
X-BCube-Filmed-By
Cross-Origin-Window-Policy
NGX
X-Akamai-Transformed
X-Locale
X-RCS-CacheZone
X-R9-Blue-Green-Version
S-Rt
X-Xfnlog-Site
X-NCache
X-Cache-Host
X-Detected-As
X-IP
L5d-Success-Class
X-Drupal-Cache-Tags
X-Unique-Id
X-CS
Cache-Name
Webserver
Time
Uber-Trace-Id
Cache-Key
Viewport
X-UA-Device-Type
X-Esi
X-Mode
Mime-Version
X-Forwarded-Host
X-Origin-TTL
X-Whom
Accept-Language
X-Origin-CC
X-UnsetCookies
X-Backend-TTL
Rt-Fastcgi-Cache
X-Cache-Remote
X-Info
X-CDN-Forward
X-Daa-Tunnel
X-NGENIX-Cache
Country
Content-Disposition
X-Varnish-Cache-Hits
X-From
X-PERF
X-ApacheServer
Odigeo-Trace-Id
ServedBy
X-Newrelic-Synthetics
X-Cluster-Name
X-B3-Spanid
X-Drupal-Cache-Contexts
VIX-Pulpo-Node
X-Magnolia-Registration
VIX-Pulpo-Upstream-Status
X-Microcachable
X-EC-Lua
Section-Io-Cache
X-Ruxit-Js-Agent
X-Zipkin-Id
X-Routing-Service
X-Device-Type
X-TT-TIMESTAMP
X-Geo
X-Proxied
X-Via-Fastly
X-Uri
X-Ttl
Proxy-Connection
X-Trafficlayer-App-Scope
X-Trafficlayer-App-Name
Cf-Ipcountry
Ohc-File-Size
X-Edge-Location
Ohc-Cache-HIT
X-Nc
HitType
Meta-Geo-Continent
Apple-News-Services-Host
Mobile-Detection-Method
Machine
MD5-Digest
GEO-REGION-INFO
Apple-News-Services-Parsed-Url
Rendered-Blocks
Apple-News-Services-Request-Url
AsisCache
BehaviorPad-Version
Access-Control-Request-Headers
Content-Style-Type
Apple-News-Services-Handled
Content-Script-Type
Fastcgi-X-Cache-Version
X-External-Request-Id
X-S-Cookie
X-ScT
X-Session-Fingerprint
X-Sigma
X-S
X-Rojux
X-Region-Sid
X-Request-UUID
X-Rewrite-Enabled
X-Rocket-Build-Number
X-Sigma-Backend
X-SRCache-Key
X-VG-WebServer
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
Xc-Version
X-VG-WebCache
X-VG-TLSProxy
X-Transaction
X-Trv-Group
X-Twitter-Response-Tags
X-Vdms-Version
X-GeoIP-Country-Code
X-Geo-Header
X-A-Dcw
X-A-Dgt
X-A-Wwc
X-Accel-Expires-Debug
X-A-Dam
X-A-Ccd
Viewtype
VivaBuild
W
X-A
X-Aed
X-ARC
X-Date
X-Destination
X-DPWN-IS-SECURE
X-G
X-D
X-Connection-Hash
X-B-Cookie
X-CF-Lambda-Fn
X-CF-Lambda-Version
T-Server
X-Application
X-No-Session
X-Varnish-Beresp-Ttl
X-UPSTREAM-Address
X-Varnish-Beresp-Grace
Geo-Info
X-Varnish-Beresp-Status
X-C
User-Cache-Control
HA-Ipaddr
Locid
Server-Surrogate-Control
Server-Cache-Control
X-Rebelmouse-Cache-Control
IsBot
Gh-Request-Id
Environment
Countrycode
CDCHOST
Fastly-SIE
Fastly-Soc-X-Request-Id
X-Logging-Id
X-Rebelmouse-Surrogate-Control
Fastly-SWR
Ha-Gx-Prefs
X-App-Name
X-Contensis-Viewer-Groups
X-Clientip
X-CGP
X-CUA
X-Eu-Site
X-Distil-CS
X-Developers
X-Cache-Debug
X-Cache-ASPX
X-Agile-Id
X-Agile-Age
X-Hit
X-SIPLIST1
X-Bip
X-Auto-Login
X-Agile
Powered-By
X-Real-IP
X-Thanos
X-TrackingId
X-VC-Cache
X-Tumblr-Pixel-3
X-Varnish-Authentication
X-WebServer
Fastly-SSL
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-Cache-Backend
X-GoCache-CacheStatus
Filterid
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Instart-Isnd
X-Hnp-Log
X-User
X-AK-Request-ID
X-Has-Esi
X-Hash
X-Variation
X-Irp-Debug
X-Urbn-Site-Id
Web-Mar-Node
True-Client-Country-4JS
X-SVT-ORM-RULES
X-LI-Proto
X-LI-UUID
X-Urbn-Context-Path
X-Dispatcher-Server
X-Li-Fabric
We-Hiring
X-JWT-State
X-Labrador-Cache-Channel
V-Age
X-Is-Gdpr
X-Epic-Correlation-Id
X-Gen-Mode
X-Cdn-Srv
X-Cache-URL
X-Cache-Time
X-Cache-Tags
X-Gamma-Serve
X-FW-Version
X-Fastly-Cache
X-Webstats-RespID
X-Fetched-On
X-Cms-Context
X-Clara-WADP
X-We-Are-Hiring
X-Debug-Cache-Expiry
X-Debug-Cache-Store
X-Micro-Cache
X-Generation-Time
X-Azure-Ref
X-Core-Mission
X-Backend-State
X-BBXSRF
X-Cache-Bucket
X-Debug-Cache-Fetch
X-WADP-Cache
X-Block-Status
X-Generated-In
X-GeoIP-City
X-Li-Pop
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Ms-Request-Id
Locale
Is-Eu
Mail-Subject
X-Proxy-Upstream
X-Owner
X-OVcl-Cache
X-PHP-Host
Memcached
X-Platform-Server
IBM-Web2-Location
Heartbleed
Cdnsip
X-Servername
Cdncip
X-SVT-ORM-VERSION
Cache-Host
X-Server-W
X-TH-Server
X-Render-Time
Adler-Geo
AKAMAI
X-Request-URI
X-OVcl
X-TT-LOGID
X-NU-AKA-ACS-Version
Request-EU
Request-Country
Server-ID
X-Ms-Version
X-Origin-Expires
X-NodeID
RNT-Machine
X-Origin-Date
X-Up
RNT-Time
X-Distributor
Platform
X-Swa-Ws
X-Level-Front-Cache
ServerName
X-Nginx-Cache-Key
X-Air-Hostname
X-Debug-Cookies
X-Debug-Log
X-ServiceProvider
Server-Int
Server-Host
X-Core-Value
X-Service
X-Req
Country-Code
FNAC-ModuleRouting
Kp-EeAlive
X-Generated-On
Fastly-Backend-Name
Wxu-Next-Region
X-NX-Host
PFcat
X-Old-Content-Length
X-App-Version
X-VServer
X-Trafficlayer-App-Version
X-Reboot
Wxu-Next-Hostname
X-Cache-Info
Wxu-Next-Commit
X-Trace-Id
X-Var-Ttl
X-Lb-Id
X-Cache-Expired-At
X-S-Maxage
X-Internal-Host
X-Thinkindot-L3
X-Matched-Rule
Group
Thinkindot-Control
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-Nginx-Cache
X-SERVER
X-Sucuri-Cache
Pragrma
Cache-Hits
X-Refresh
RequestId
S-Cnection
X-Key
X-Location
X-Response-By
X-CF-Powered-By
X-VHOST
Powered-By-ChinaCache
X-Parent-Response-Time
X-CSRF-TOKEN
X-TA-CDN-Provider
X-Tb-Optimization-Total-Bytes-Saved
X-Cdn-Forward
X-Wa
X-Correlation-ID
X-Tec-Api-Version
X-NC
X-BACKEND-TTL
X-Tec-Api-Origin
X-Pjax-Url
ProcessTime
X-Tec-Api-Root
X-B3-Parentspanid
X-Sucuri-ID
X-Varnish-Cacheable
X-CSRF-Token
Memory
Origin
User-Agent
X-Ua
SRV
X-Via-CDN
TTL
X-Pf-Uncompressing
X-B3-SpanId
Geoip-City
X-Vcl-Version
Geoip-Latitude
X-Developer
X-Server-IP
X-NWS-UUID-VERIFY
X-NGINX-Cache
X-Unique-ID
GeoIp-Country-Code
PICS-Label
X-Cdn-Origin
X-LAGOON
X-Sn-Servicetimems
X-Cache-Grace
X-Ocache
X-Device-Os
X-Oss-Object-Type
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
X-Node-Id
On-Server
X-COUNTRY
X-Cache-Status-Check
Media-Length
X-MSEdge-Flight
X-Request-Host
X-Cdn-Request-ID
X-MSEdge-Features
A
Dnion-Transfer-Encoding
Cloudfront-Viewer-Country
M-TraceId
X-Litespeed-Cache
X-Servedbyhost
X-Webkit-CSP
X-Rocket-Nginx-Bypass
SN
Hostname
X-Via-Ucdn
X-Varnish-Ttl
X-Sucuri-Id
X-TIME
XServer
X-HS-Status
Cdn
Tcn
X-FORWARDED-FOR
Host-ID
X-Reqid
Resin-Trace
HostName
X-ServedByHost
X-AIR-PT
Esi-Enabled
X-Ratelimit-Remaining
X-Beluga-Response-Time
X-Beluga-Status
X-Beluga-Record
X-Beluga-Trace
X-Cache-Ttl
X-Beluga-Node
X-Policy
X-Planisys-CDN-Rules
X-Fastly-Country-Code
X-Beluga-Cache-Status
X-Varnish-URL
Who
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
X-Azure-Ref-OriginShield
X-Request-Start
CF-Cached-On
X-Slack-Backend
Rt-Proxy-Cache
X-Fastly-Backend-Reqs
GeoIP-Country-Code
Pics-Label
CACHE
X-LiteSpeed-Cache-Control
GeoIP-Latitude
X-Server-Time
X-Processor
X-PAYTM-SRV-ID
X-Dispatch
X-Action
Arc-Country
X-Varnish-Url
X-Cache-FS-Status
Pramga
X-VCL-Version
X-Ftr-Cache-Host
MIME-Version
X-Oracle-Dms-Rid
Ttl
X-RSL
X-Bc
X-Skip-Cache
X-APP
X-ABtesting
X-DB
X-DI
X-Flog
X-Hello
X-Method
NtCoent-Length
X-ND-Cache
X-DSS
X-DW
Magicmarker
X-Zone
X-PF-Uncompressing
X-RPS
GeoIP-City
X-RPM
X-DC
Cteonnt-Length
X-VarnishDD-TTL
X-Newrelic-App-Data
Cdn-Request-Time
Cdn-Host
X-Edge-Server
X-FPC
X-Ratelimit-Limit
X-Served-From
Fastly-Drupal-HTML
X-HostName
N-Cache
X-SRV
Amp-Access-Control-Allow-Source-Origin
X-PJAX-URL
X-DevSite-Last-Modified
X-Bc-Bl
WebServer
X-Amzn-Remapped-Date
X-Backend-Host
X-BE
X-Svr
X-Be
X-Amzn-Remapped-Connection
Section-Origin-Responded
X-Dynatrace
Section-Io-Id
Processtime
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Ohc-Response-Time
X-Dynatrace-Js-Agent
Servername
X-Swift-Error
Load-Balancing
X-WA
X-ZONE
Cache-Provider
Vix-Hermes-Req-Id
X-Aicache-OS
X-BC
X-ID
X-Frame-Option
X-WR-MODIFICATION
X-StackifyID
CDN
Lfy
Cache-Cookie-Set-Lfrom
Pagetype
X-Fmm-Version
X-Snapshot-Date
X-LB-ID
FSS-Cache
FSS-Proxy
CF-IPCountry
X-Branch-Name
X-Adobe-Source
X-Fastly-Cache-Hits
X-MServer
Cache-Cookie-Set-From
Cache-Cookie-Set-Idcheck
Dynatrace
Requestid
DSUID
Release
X-VCT
Trailer
X-CACHE-AGE
X-Configured-By
Fusion-Deployment-Id
X-Apw-Access-Action
Proxy-Firewall
X-Tid
X-VC
Warning
D-Cc-Upstream
X-SB
X-Scheme
WZWS-RAY
V-Cache
X-Apw-Access-Object
X-Request-Url
X-Apw-Hits
X-Apw-Access-Token
X-Cc-Req-Id
X-Hp-Ccpa-Warning
X-Cc-Via
X-Litespeed-Cache-Control
X-Node-ID
X-Fpc
X-WPE-Loopback-Upstream-Addr
Cneonction
Correlation-Id
Backend-Name
X-App
X-Upstream-Ht
X-Upstream-Ct
SD-X-WS
X-SD-PageType
X-Edge-IP
X-Worker
X-Check-Cacheable
X-Varnish-Beresp-TTL
X-Request-URL
X-Powered-Y
WP-Super-Cache
X-ElasticPress-Search
X-Fastly-Cache-Status