Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
CF-RAY
Link
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-Cache-Hits
X-UA-Compatible
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-Request-ID
X-DNS-Prefetch-Control
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
Status
Upgrade
X-Content-Security-Policy
X-CDN
Content-Encoding
Access-Control-Expose-Headers
X-Ua-Compatible
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Xss-Protection
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
X-Pass-Why
X-Cache-Group
Xkey
X-AH-Environment
P3p
X-Envoy-Upstream-Service-Time
X-Via
X-Backend
CF-Ray
X-Server
X-Age
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Ws-Request-Id
X-Server-Powered-By
X-Page-Speed
X-Pingback
EagleId
X-Proxy-Cache
X-Hacker
X-UA-Device
X-Nginx-Cache-Status
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
Cf-Railgun
Grace
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Amz-Version-Id
Report-To
X-LiteSpeed-Cache
X-Rq
X-OneAgent-JS-Injection
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-WebKit-CSP
X-Server-Id
X-Device
X-Host
X-Origin-Cache
EagleEye-TraceId
X-Response-Time
X-Node
X-Ac
Surrogate-Control
Content-Location
X-Cloud-Trace-Context
X-Vhost
X-Readtime
X-Backend-Server
Request-Id
X-Dispatcher
X-Origin-Upstream-Status
X-Cnection
X-Application-Context
X-HW
X-Cache-Lookup
X-ORACLE-DMS-ECID
Fusion-Content-Id
Fusion-Component-Id
Fusion-Content-Source
Fusion-Source
Fusion-Template-Id
X-Ruxit-JS-Agent
X-ORACLE-DMS-RID
NEL
X-DataDome
X-Mod-Pagespeed
X-Rack-Cache
Rating
Edge-Control
X-Country
X-Clacks-Overhead
X-Akam-SW-Version
X-Dns-Prefetch-Control
Pinterest-Generated-By
X-TTL
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Allow
X-Country-Code
Accept-Ch
X-DynaTrace
X-FTR-Request-ID
X-Instart-Request-ID
X-Varnish-TTL
X-Goog-Hash
X-TtlSet
X-Vname
X-PC
X-ESI
Verso
Accept-Ch-Lifetime
Content-MD5
Service-Worker-Allowed
X-Powered-By-Plesk
X-Url
X-B3-TraceId
X-Forwarded-Proto
X-Version
X-MS-InvokeApp
X-GitHub-Request-Id
X-Cdn-Fetch
X-Exp-Variant
X-Exp-Id
X-Kinja-Server
X-Use-Magma
X-Kinja-Build
X-Kinja-Revision
X-Kinja
X-GoogleNews-Bot
RTSS
Edge-Cache-Tag
X-Server-Name
X-D2id
X-Abt-Application-Version
X-Debug
X-Px
Ar-Sid
AR-Request-ID
AR-PoweredBy
X-Vcache
AR-ATIME
AR-CACHE
X-Amz-Server-Side-Encryption
SPRequestGuid
Charset
X-NF-Request-ID
X-Cached
X-Fastcgi-Cache
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
Pagespeed
X-Vcap-Request-Id
X-Sol
Response
Display
X-Accel-Expires
X-Middleton-Display
X-Middleton-Response
X-Navigation-Version
X-MSEdge-Ref
X-Amz-Rid
Arr-Disable-Session-Affinity
Pinterest-Version
X-Pinterest-Rid
X-SharePointHealthScore
X-Powered-CMS
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-VARITI-CCR
X-Trace
TCN
Public-Key-Pins
Realpath
X-Fastly-Request-ID
Cache-Tag
X-Client-IP
X-Cdn
MS-Author-Via
X-Ser
Access-Control-Request-Method
Nginx-Cache
X-Edge-O15-RID
X-DynaTrace-JS-Agent
X-Shard
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
S
SPIisLatency
X-Server-ID
X-Upstream
SPRequestDuration
X-Content-Type
X-Id
X-Ezoic-Cdn
X-Amzn-Trace-Id
X-Hp-Webp
X-Grace
X-Forwarded-For
X-T
X-Amz-Meta-S3cmd-Attrs
Front-End-Https
X-Hits
X-Recruiting
Fastcgi-Cache
X-Jurisdiction
DynaTrace
Nel
X-Cache-TTL
X-Aspnet-Version
X-Varnish-Age
ServerID
MicrosoftSharePointTeamServices
X-Element-Page-Cache
X-Content-Digest
X-Node-Name
X-Mobile-URL
X-Country-Code-Real
X-Dw-Request-Base-Id
X-FTR-Backend
X-FTR-Balancer
X-FTR-Expires
X-FTR-DC
X-FTR-Cache-Status
X-DIS-Request-ID
X-FTR-Backend-Server
X-FTR-Realm
NR-ENABLED
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Hub-Id
X-Goog-Metageneration
X-Goog-Generation
Powered
X-Goog-Storage-Class
X-GUploader-UploadID
Server-Node
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Frontend
TP-Cache
TP-L2-Cache
Alternate-Protocol
X-Logged-In
Server-Name
X-CST
AMP-Access-Control-Allow-Source-Origin
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Request-Processing-Time
X-Request-Received
Upgrade-Insecure-Requests
X-Correlation-Id
X-Request-Handler-Origin-Region
X-Microsite
X-Cache-Hit
Backend-Timing
X-ATS-Timestamp
X-XRDS-Location
X-Content-Options
Fastly-Restarts
X-Content-Security-Policy-Report-Only
X-F-Cache
Refresh
X-Origin-Server
X-User-Agent
X-Rid
X-Akamai-Edgescape
X-Page-Id
X-Revision
X-Zen-Fury
X-Varnish-Grace
X-Type
X-XRDS-LOCATION
X-Content-Powered-By
X-Webkit-Csp
X-LB-Cache
X-FTR-Cache-Host
X-B
X-B3-Sampled
PB-RID
PB-PID
X-Geo-Country
X-Mobile-Rewrite
Arc-Version
X-AppVersion
X-Az
X-Activity-Id
Cache-Status
X-URL
X-Kinsta-Cache
X-N
X-Cache-Age
X-Shield-Request-Id
X-TT
X-Time
X-Instance
X-AOL-HN
X-Pad
X-WebKit-CSP-Report-Only
X-Cache-Action
X-Signature
X-B-Cache
X-Jobs
X-Tumblr-Pixel
X-Debug-Info
X-Framework
Paypal-Debug-Id
Actual-Object-TTL
X-Tumblr-Pixel-0
Access-Control-Allow-Method
X-Tumblr-User
X-App-Environment
X-FB-Debug
X-Request-Guid
X-PHP-Backend
X-Load-Cache
X-Cached-By
X-Git-Hash
DC
Fastcgi-Useragent
X-RateLimit-Remaining
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Varnish-Backend
X-Amz-Replication-Status
Surrogate-Key
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-IPLB-Instance
Host-Header
MS-CV
X-Contextid
X-Webapp-Samesite-None-Activated-N
X-ATG-Version
X-Analytics
Host
X-WA-Info
X-SS-Set-Cookie
X-NWS-LOG-UUID
FilterID
X-ORACLE-APMCS-TAG
X-ORACLE-APMCS-REQUEST-ID
X-Mobile
X-Via-JSL
X-Cluster
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
NGB
Tracecode
X-Response-Served-From
X-Accel-Buffering
WPE-Backend
X-Cache-Key
X-Host-Name
Payment
X-Cache-NE
Xserver
X-Varnish-Server
X-Region
X-FW-Server
X-FW-Hash
X-Cache-2
X-FW-Serve
Eomportal-Instance
X-FW-Static
X-FW-Type
Source
Filters
X-Srv
Cache-Tv-Group
Frame-Options
X-IPS-LoggedIn
X-GeoIP
X-Varnish-Hostname
X-Tumblr-Pixel-2
X-Origin-Response-Time
X-Tumblr-Pixel-1
X-Cache-Enabled
X-Adobe-Loc
X-Adobe-Content
X-Cacheable-TTL
X-Is-Bot
X-Rendered-As
X-Seen-By
X-Cache-Operation
X-RequestSource
X-Cache-Rule
Retry-After
X-TX-ID
X-EdgeConnect-Cache-Status
X-Hostname
Server-Info
X-Cache-TTL-Remaining
X-NewRelic-App-Data
X-Presslabs-Stats
X-RemovedCookies
X-ProcessESI
Liferay-Portal
Cleartype
X-FastCGI-Cache
X-VCache
X-App-Server
X-Dc
Accept-CH
X-L-Path
X-B3-Traceid
X-Environment-Context
Ms-Operation-Id
X-RTag
X-FireWall-Port
X-UA
X-Source
X-CACHE-KEY
Datacenter
X-HTML-Minification-Powered-By
X-Endurance-Cache-Level
X-Upgrade-Enabled
X-Handled-By
From-Origin
X-Cache-Server
X-PressLabs-Stats
Srv
X-Backend-Name
X-Cache-Control
Healthy
X-Wix-Request-Id
Accept-CH-Lifetime
Cache
Accept-Charset
X-ES-SERVER
X-Cache-Var-Map
X-Cache-Var
X-Path-Route
Meta-Geo
X-RN-RSRV
X-Tb
X-Format
Selected-Fe
X-UUID
X-Section
X-Access
X-Status
X-Timing-Wait
OT-Force-Account-Verify
Version
X-Proxy-Build
X-ShopId
Akamai-GRN
X-Akamai-Request-ID
X-ShardId
X-Alternate-Cache-Key
X-Shopify-Stage
X-Shopify-Generated-Cart-Token
X-Cache-Config
Azure-InstanceId
X-FC-Vary-Parameters
X-OCL
X-Request-Time
X-Proto
X-NYM-Debug-Backend
Azure-SlotName
Cache-Tags
Azure-Version
X-Goog-Meta-Goog-Reserved-File-Mtime
X-EIG-Tracking-Id
X-Origin
X-Sorting-Hat-PodId
X-PCL
X-Content-Age
Azure-RegionName
Azure-SiteName
Mn-Server-Ip
X-Sorting-Hat-ShopId
Decoy-Debug-Key
DB-Nickname
Ec-Rule-Version
Origin-Cache-Control
Origin-Edge-Control
NGX
Now
X-Web-Node
Decoy-Debug-Status
Node
X-Redis-Cache
X-JoinUs
X-LJ-Flow-ID
X-Hyper-Cache
X-VWS-Id
X-Hosted-By
X-Human
X-Viewer-Country
X-Vgn-Hpd-Reason
X-Soup
X-ServerID
X-SayCDN-TTL
X-Time-Microsecs
X-Say-TTL
X-Hl-Ver
X-Say-Cacheable
X-ProxyCache-Key
X-Proxy-Cache-Status
X-BYPASS-REASON
X-Pubstack
X-Akamai-Request-ID2
X-AWS-Id
X-Qloud-Router
X-Cluster-Node
X-Generated-By
X-SaId
X-FW-Dynamic
X-Proxy
X-Debug-Cache
X-ProxyCache-Status
Decoy-Debug-TTL
X-Storage
X-Yottaa-Optimizations
X-RateLimit-Limit
X-Yottaa-Metrics
Webcakes-App-Name
Webcakes-App-Version
TWC-Privacy
TWC-GeoIP-LatLong
TWC-Connection-Speed
Property-Id
TWC-Device-Class
TWC-GeoIP-Country
X-Amzn-Remapped-Content-Length
TWC-Locale-Group
X-BCube-Filmed-By
X-Loop
X-Site-Version
X-MP-GENERATED-AT
X-APP-VERSION
X-Origin-Hint
X-TNCMS
X-Generated
X-CCM
X-Www-Served-By
X-Varnish-Hits
X-FB-TRIP-ID
X-Rule
Webcakes-Region
Cross-Origin-Window-Policy
S-Rt
X-Locale
X-RCS-CacheZone
X-Xfnlog-Site
X-Akamai-Transformed
X-R9-Blue-Green-Version
X-Cache-Host
X-NCache
X-Detected-As
X-IP
GEO-INFO
L5d-Success-Class
X-Drupal-Cache-Tags
X-CS
Cache-Name
Webserver
Cache-Key
Uber-Trace-Id
Time
Viewport
X-UA-Device-Type
X-Esi
X-Mode
X-Unique-Id
X-Forwarded-Host
Mime-Version
X-UnsetCookies
X-Whom
X-Daa-Tunnel
X-Origin-CC
Accept-Language
X-Origin-TTL
X-Cache-Remote
X-Info
Rt-Fastcgi-Cache
Content-Disposition
Country
X-NGENIX-Cache
X-From
X-Varnish-Cache-Hits
X-ApacheServer
Odigeo-Trace-Id
X-PERF
X-B3-Spanid
ServedBy
X-Cluster-Name
X-Backend-TTL
X-Magnolia-Registration
Section-Io-Cache
X-Drupal-Cache-Contexts
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-CDN-Forward
X-Microcachable
X-Ruxit-Js-Agent
X-Newrelic-Synthetics
X-Geo
X-EC-Lua
X-CLOUD-TRACE-CONTEXT
X-Zipkin-Id
X-Device-Type
X-Routing-Service
X-Proxied
X-Nc
X-TT-TIMESTAMP
X-Via-Fastly
Ohc-File-Size
Geo-Info
X-Uri
X-Trafficlayer-App-Scope
X-Trafficlayer-App-Name
Proxy-Connection
X-Ttl
Cf-Ipcountry
Ohc-Cache-HIT
X-Edge-Location
HitType
Content-Script-Type
X-CF-Lambda-Fn
X-CF-Lambda-Version
Xc-Version
Content-Style-Type
X-External-Request-Id
X-G
X-SRCache-Key
X-Sigma-Backend
Access-Control-Request-Headers
X-DPWN-IS-SECURE
X-Vdms-Version
Rendered-Blocks
BehaviorPad-Version
X-VG-WebCache
X-Geo-Header
X-Trv-Group
GEO-REGION-INFO
Machine
X-Date
X-D
X-VG-TLSProxy
X-Connection-Hash
MD5-Digest
X-Destination
X-Sigma
Mobile-Detection-Method
Meta-Geo-Continent
X-Twitter-Response-Tags
X-GeoIP-Country-Code
Fastcgi-X-Cache-Version
X-Session-Fingerprint
X-A
X-A-Ccd
X-A-Dam
Apple-News-Services-Parsed-Url
X-Application
X-Request-UUID
W
X-No-Session
X-A-Dcw
X-Region-Sid
Apple-News-Services-Request-Url
AsisCache
X-Aed
X-Accel-Expires-Debug
X-A-Dgt
X-A-Wwc
X-Rewrite-Enabled
Apple-News-Services-Host
T-Server
X-Vtex-Remote-Cache
X-S-Cookie
X-ScT
X-VG-WebServer
X-Vtex-Processado-Em
X-B-Cookie
X-S
Viewtype
VivaBuild
X-ARC
Apple-News-Services-Handled
X-Rocket-Build-Number
X-Transaction
X-Rojux
X-App-Version
X-Varnish-Beresp-Status
User-Cache-Control
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Grace
X-UPSTREAM-Address
X-C
X-Agile-Age
X-Agile
X-Wikidot-Backend
X-Cache-Debug
X-Wikidot-Static-Cache
Powered-By
CDCHOST
Server-Cache-Control
X-Auto-Login
X-WebServer
Server-Surrogate-Control
X-Bip
X-App-Name
X-Cache-ASPX
X-Eu-Site
Environment
Gh-Request-Id
X-Contensis-Viewer-Groups
Ha-Gx-Prefs
HA-Ipaddr
X-CUA
Locid
Fastly-SWR
Fastly-Soc-X-Request-Id
IsBot
X-Distil-CS
X-Developers
X-CGP
X-Clientip
Fastly-SIE
Countrycode
X-Real-IP
X-Thanos
X-TrackingId
X-Varnish-Authentication
X-Logging-Id
X-Agile-Id
X-SIPLIST1
X-Tumblr-Pixel-3
X-Hit
X-VC-Cache
Fastly-SSL
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Cache-Backend
X-GoCache-CacheStatus
X-Server-W
X-Micro-Cache
X-Ms-Version
X-Backend-State
X-BBXSRF
X-Block-Status
X-Ms-Request-Id
X-Cache-Bucket
X-Cache-Time
X-Cache-URL
X-Cache-Tags
X-Cache-Info
X-LI-UUID
X-LI-Proto
X-Render-Time
X-RateLimit-Remaining-Second
X-WADP-Cache
X-RateLimit-Limit-Second
X-Owner
X-AK-Request-ID
X-We-Are-Hiring
X-Proxy-Upstream
X-Platform-Server
X-PHP-Host
X-OVcl-Cache
X-OVcl
X-NodeID
X-Azure-Ref
X-Request-URI
X-NU-AKA-ACS-Version
X-Li-Pop
X-Origin-Expires
X-Origin-Date
X-NX-Host
X-Nginx-Cache-Key
X-SVT-ORM-RULES
X-Debug-Log
X-Up
X-User
X-GeoIP-City
X-Has-Esi
X-Debug-Cookies
X-Hash
X-TT-LOGID
X-Debug-Cache-Store
X-Urbn-Site-Id
X-Generation-Time
X-FW-Version
X-Epic-Correlation-Id
X-Fetched-On
X-Gamma-Serve
X-Gen-Mode
X-Dispatcher-Server
X-Generated-In
X-Distributor
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-Clara-WADP
X-JWT-State
X-Swa-Ws
X-Is-Gdpr
X-SVT-ORM-VERSION
X-Labrador-Cache-Channel
X-Variation
X-Li-Fabric
X-Fastly-Cache
X-Cms-Context
X-VServer
X-TH-Server
X-Trace-Id
X-Hnp-Log
X-Core-Mission
X-IN-APIGATEWAY
X-Irp-Debug
X-Instart-Isnd
X-IN-APIGATEWAYSSL
X-Cdn-Srv
Heartbleed
Memcached
Mail-Subject
Locale
AKAMAI
Request-Country
RNT-Time
RNT-Machine
Request-EU
Kp-EeAlive
Is-Eu
Adler-Geo
Cdncip
Cache-Host
Cdnsip
Country-Code
IBM-Web2-Location
X-Urbn-Context-Path
X-Webstats-RespID
Platform
True-Client-Country-4JS
Web-Mar-Node
V-Age
Server-Int
We-Hiring
Server-ID
X-Air-Hostname
X-Thinkindot-L3
X-Service
X-ServiceProvider
FNAC-ModuleRouting
X-Generated-On
X-Trafficlayer-App-Version
Wxu-Next-Hostname
Wxu-Next-Commit
ServerName
Fastly-Backend-Name
X-Core-Value
PFcat
X-Reboot
Thinkindot-CacheControl
X-Req
X-Servername
X-Nginx-Cache
Server-Host
X-Old-Content-Length
Thinkindot-Control
Wxu-Next-Region
X-Matched-Rule
X-Level-Front-Cache
Thinkindot-CacheControl-Type
X-S-Maxage
Group
X-Internal-Host
X-Var-Ttl
X-Lb-Id
X-Cache-Expired-At
Cache-Hits
Filterid
S-Cnection
X-Response-By
X-SERVER
X-Key
Pragrma
X-Refresh
RequestId
X-Sucuri-Cache
X-Cdn-Forward
X-Parent-Response-Time
Powered-By-ChinaCache
X-BACKEND-TTL
X-Location
X-VHOST
X-CF-Powered-By
X-Tb-Optimization-Total-Bytes-Saved
ProcessTime
X-CSRF-TOKEN
X-TA-CDN-Provider
Origin
X-Tec-Api-Version
X-Pjax-Url
X-Tec-Api-Origin
X-Tec-Api-Root
X-Correlation-ID
X-B3-Parentspanid
X-Sucuri-ID
X-Wa
X-CSRF-Token
X-Varnish-Cacheable
User-Agent
Memory
X-Unique-ID
X-Ua
X-NC
X-Via-CDN
TTL
X-Pf-Uncompressing
X-B3-SpanId
X-Vcl-Version
X-Node-Id
Geoip-City
Geoip-Latitude
X-Server-IP
X-Developer
SRV
X-NWS-UUID-VERIFY
Tcn
X-Ocache
X-Sn-Servicetimems
X-Cache-Grace
GeoIp-Country-Code
X-Device-Os
X-LAGOON
X-Cdn-Origin
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Storage-Class
X-NGINX-Cache
X-Cache-Status-Check
X-COUNTRY
PICS-Label
On-Server
Hostname
X-Cdn-Request-ID
Media-Length
X-MSEdge-Features
X-Request-Host
X-MSEdge-Flight
A
Dnion-Transfer-Encoding
M-TraceId
X-Servedbyhost
SN
X-Rocket-Nginx-Bypass
Cloudfront-Viewer-Country
X-Litespeed-Cache
X-Webkit-CSP
X-Varnish-Ttl
X-Via-Ucdn
XServer
X-Sucuri-Id
X-TIME
Cdn
X-FORWARDED-FOR
X-HS-Status
X-ServedByHost
X-AIR-PT
X-Reqid
Host-ID
Esi-Enabled
X-Varnish-URL
X-Ratelimit-Remaining
X-Beluga-Trace
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
Resin-Trace
Who
X-Fastly-Country-Code
X-Beluga-Status
X-Policy
X-Beluga-Record
X-Beluga-Response-Time
X-Beluga-Node
X-Beluga-Cache-Status
X-Cache-Ttl
CACHE
HostName
X-Slack-Backend
X-Azure-Ref-OriginShield
X-Request-Start
CF-Cached-On
Pics-Label
GeoIP-Country-Code
Rt-Proxy-Cache
X-Fastly-Backend-Reqs
X-Action
X-LiteSpeed-Cache-Control
X-DW
X-RPM
GeoIP-Latitude
X-RPS
X-DB
X-HostName
X-VCL-Version
X-Server-Time
X-DSS
X-DI
X-Dispatch
Pramga
X-Processor
X-PAYTM-SRV-ID
X-Cache-FS-Status
X-RSL
Arc-Country
MIME-Version
X-Ftr-Cache-Host
X-Oracle-Dms-Rid
Ttl
NtCoent-Length
X-ABtesting
X-PF-Uncompressing
X-Skip-Cache
X-Method
X-Varnish-Url
X-Hello
X-Bc
Magicmarker
X-APP
X-ND-Cache
X-Zone
X-Flog
GeoIP-City
X-DC
Cteonnt-Length
Fastly-Drupal-HTML
X-FPC
X-Newrelic-App-Data
X-Ratelimit-Limit
Cdn-Host
X-Edge-Server
X-VarnishDD-TTL
Cdn-Request-Time
X-Served-From
X-DevSite-Last-Modified
X-PJAX-URL
X-Bc-Bl
N-Cache
Amp-Access-Control-Allow-Source-Origin
X-SRV
WebServer
Section-Origin-Responded
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Io-Id
X-Amzn-Remapped-Date
Ohc-Response-Time
X-Svr
X-Be
X-Backend-Host
X-Dynatrace
X-WA
X-Amzn-Remapped-Connection
X-BE
Processtime
Servername
X-Swift-Error
Load-Balancing
X-Dynatrace-Js-Agent
X-ZONE
Cache-Provider
Vix-Hermes-Req-Id
X-ID
X-Aicache-OS
X-BC
X-WR-MODIFICATION
X-Frame-Option
DSUID
X-StackifyID
X-Snapshot-Date
Lfy
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-Idcheck
Pagetype
FSS-Cache
X-Fastly-Cache-Hits
X-Fmm-Version
FSS-Proxy
Cache-Cookie-Set-From
X-Adobe-Source
Requestid
Dynatrace
X-MServer
CF-IPCountry
X-LB-ID
CDN
X-Branch-Name
X-CACHE-AGE
Release
X-VCT
Trailer
X-Scheme
WZWS-RAY
X-Tid
Fusion-Deployment-Id
V-Cache
X-Apw-Access-Object
X-Apw-Access-Token
X-Request-Url
X-Apw-Access-Action
Proxy-Firewall
X-Hp-Ccpa-Warning
X-Configured-By
X-SB
X-Apw-Hits
X-Cc-Via
Warning
D-Cc-Upstream
X-Cc-Req-Id
X-VC
X-Litespeed-Cache-Control
SD-X-WS
Cneonction
X-ServerName
X-Upstream-Ct
X-Fpc
Backend-Name
X-Edge-IP
X-SD-PageType
X-Varnish-Beresp-TTL
X-App
WP-Super-Cache
X-ElasticPress-Search
X-Upstream-Ht
X-Powered-Y
X-Worker
X-Fastly-Cache-Status
X-WPE-Loopback-Upstream-Addr
X-Request-URL
X-Check-Cacheable
Correlation-Id