Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
CF-RAY
Link
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Request-ID
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-Template
X-Language
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-Buckets
X-FRAME-OPTIONS
Status
X-Content-Security-Policy
Upgrade
Content-Encoding
X-CDN
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Xss-Protection
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
Xkey
X-Pass-Why
X-Cache-Group
P3p
X-Envoy-Upstream-Service-Time
X-AH-Environment
X-Backend
X-Via
CF-Ray
X-Age
X-Server
X-Ua-Compatible
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Server-Powered-By
X-Page-Speed
X-Ws-Request-Id
X-Pingback
EagleId
X-Proxy-Cache
X-Nginx-Cache-Status
X-Hacker
X-UA-Device
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
Cf-Railgun
Grace
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Amz-Version-Id
Report-To
X-LiteSpeed-Cache
X-Rq
X-Server-Id
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-WebKit-CSP
X-OneAgent-JS-Injection
X-Host
X-Device
EagleEye-TraceId
X-Origin-Cache
X-Response-Time
X-Node
X-Dns-Prefetch-Control
X-Ac
Content-Location
Surrogate-Control
X-Vhost
X-Readtime
X-Cloud-Trace-Context
X-Backend-Server
Request-Id
X-Dispatcher
X-Origin-Upstream-Status
X-Cnection
X-Application-Context
X-HW
X-ORACLE-DMS-ECID
X-Cache-Lookup
Fusion-Component-Id
Fusion-Content-Id
Fusion-Source
Fusion-Template-Id
Fusion-Content-Source
X-ORACLE-DMS-RID
X-DataDome
NEL
X-Mod-Pagespeed
X-Ruxit-JS-Agent
X-Rack-Cache
Rating
Edge-Control
X-Country
X-Akam-SW-Version
X-Clacks-Overhead
Pinterest-Generated-By
Allow
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-TTL
X-Country-Code
X-DynaTrace
Accept-Ch
X-Instart-Request-ID
X-Varnish-TTL
X-Goog-Hash
X-FTR-Request-ID
X-PC
X-Vname
X-TtlSet
X-ESI
Verso
Accept-Ch-Lifetime
X-Powered-By-Plesk
Content-MD5
Service-Worker-Allowed
X-Url
X-B3-TraceId
X-Cdn
X-Forwarded-Proto
X-Version
X-MS-InvokeApp
X-Exp-Id
X-Kinja
X-GoogleNews-Bot
X-Exp-Variant
X-Cdn-Fetch
X-GitHub-Request-Id
X-Kinja-Build
X-Use-Magma
X-Kinja-Server
X-Kinja-Revision
RTSS
Edge-Cache-Tag
X-D2id
X-Px
X-Debug
AR-Request-ID
AR-CACHE
AR-ATIME
Ar-Sid
AR-PoweredBy
X-Server-Name
X-Abt-Application-Version
SPRequestGuid
X-Amz-Server-Side-Encryption
Charset
X-NF-Request-ID
X-Cached
X-Vcache
X-Accel-Expires
X-Sol
X-Middleton-Response
X-Middleton-Display
Pagespeed
Response
Display
X-MSEdge-Ref
X-Vcap-Request-Id
X-Amz-Rid
Arr-Disable-Session-Affinity
X-Navigation-Version
X-Powered-CMS
X-SharePointHealthScore
X-Pinterest-Rid
Pinterest-Version
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
TCN
X-Fastcgi-Cache
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Trace
X-VARITI-CCR
Realpath
Public-Key-Pins
Cache-Tag
X-Client-IP
Access-Control-Request-Method
X-Fastly-Request-ID
MS-Author-Via
X-Ser
S
Nginx-Cache
X-DynaTrace-JS-Agent
X-Shard
SPIisLatency
X-Upstream
SPRequestDuration
X-Id
Mrf-Cache-Status
MRF-Tech
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
X-B3-TraceId-Primal
X-Ezoic-Cdn
X-Edge-O15-RID
X-Content-Type
X-Hp-Webp
X-Forwarded-For
X-Amzn-Trace-Id
X-Grace
X-T
X-Amz-Meta-S3cmd-Attrs
DynaTrace
Front-End-Https
X-Hits
X-Recruiting
Fastcgi-Cache
Nel
X-Varnish-Age
X-Aspnet-Version
ServerID
X-Cache-TTL
X-Dw-Request-Base-Id
MicrosoftSharePointTeamServices
X-Element-Page-Cache
X-Node-Name
X-Mobile-URL
X-DIS-Request-ID
X-FTR-Expires
X-FTR-Cache-Status
X-Jurisdiction
X-Content-Digest
X-Country-Code-Real
X-Server-ID
NR-ENABLED
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Combine-CSS
X-HS-Hub-Id
X-Goog-Storage-Class
X-FTR-Backend
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Metageneration
X-Frontend
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-Realm
X-FTR-DC
Powered
Server-Node
Alternate-Protocol
TP-L2-Cache
TP-Cache
Server-Name
X-Logged-In
X-Correlation-Id
X-XRDS-LOCATION
X-Request-Received
X-Request-Processing-Time
AMP-Access-Control-Allow-Source-Origin
Upgrade-Insecure-Requests
X-Request-Handler-Origin-Region
X-Microsite
X-ATS-Timestamp
X-CST
X-Amz-Apigw-Id
Backend-Timing
X-Amzn-RequestId
X-Cache-Hit
X-Page-Id
X-Content-Options
X-Origin-Server
X-Content-Security-Policy-Report-Only
Refresh
X-Akamai-Edgescape
X-Rid
X-Revision
X-User-Agent
X-F-Cache
X-Webkit-Csp
X-Varnish-Grace
X-Type
Fastly-Restarts
X-Zen-Fury
X-XRDS-Location
X-Content-Powered-By
X-B3-Sampled
X-LB-Cache
X-B
X-AppVersion
X-Activity-Id
X-Geo-Country
X-FTR-Cache-Host
X-Az
X-Shield-Request-Id
PB-RID
PB-PID
Arc-Version
X-Mobile-Rewrite
X-URL
Cache-Status
X-N
X-Kinsta-Cache
X-Pad
X-TT
X-Instance
X-AOL-HN
X-WebKit-CSP-Report-Only
X-Webapp-Samesite-None-Activated-N
X-Time
X-Cache-Age
X-B-Cache
X-Tumblr-User
Paypal-Debug-Id
X-Signature
X-App-Environment
X-Tumblr-Pixel-0
X-Request-Guid
X-Tumblr-Pixel
Actual-Object-TTL
X-Jobs
X-Framework
X-Cache-Action
X-Debug-Info
Access-Control-Allow-Method
X-Load-Cache
X-PHP-Backend
X-FB-Debug
DC
X-Cached-By
X-Git-Hash
X-RateLimit-Remaining
X-Analytics
X-Varnish-Backend
X-Tt-Trace-Tag
Surrogate-Key
X-Erf-Bev-Bev
Fastcgi-Useragent
X-Erf-Bev-Bev-Is-Generated
X-Tt-Trace-Host
Host-Header
X-Amz-Replication-Status
FilterID
X-Contextid
X-IPLB-Instance
MS-CV
X-ATG-Version
X-SS-Set-Cookie
X-Cache-Key
X-WA-Info
Tracecode
X-Cluster
Host
X-Mobile
X-Response-Served-From
X-FastCGI-Cache
X-Accel-Buffering
NGB
X-Host-Name
WPE-Backend
X-Via-JSL
X-ORACLE-APMCS-TAG
X-ORACLE-APMCS-REQUEST-ID
Xserver
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Payment
X-VCache
X-Srv
X-Cache-NE
X-FW-Hash
Eomportal-Instance
Source
X-FW-Server
X-FW-Type
X-FW-Static
X-Cache-2
X-FW-Serve
X-Varnish-Server
X-Region
Frame-Options
X-IPS-LoggedIn
Filters
X-GeoIP
X-Cache-Enabled
X-Tumblr-Pixel-1
X-Tumblr-Pixel-2
X-Rendered-As
X-Cacheable-TTL
X-Is-Bot
X-Varnish-Hostname
X-NWS-LOG-UUID
Cache-Tv-Group
X-Adobe-Loc
X-Presslabs-Stats
X-Adobe-Content
X-Cache-Operation
X-Cache-Rule
X-Origin-Response-Time
X-NewRelic-App-Data
X-RequestSource
X-Hostname
X-TX-ID
Retry-After
X-Seen-By
X-EdgeConnect-Cache-Status
Cleartype
Server-Info
X-Cache-TTL-Remaining
X-RemovedCookies
X-ProcessESI
X-Ruxit-Js-Agent
Liferay-Portal
X-UA
X-Dc
Accept-CH
X-HTML-Minification-Powered-By
Cache
X-RTag
Datacenter
Ms-Operation-Id
X-B3-Traceid
X-Source
X-L-Path
X-FireWall-Port
X-Environment-Context
X-App-Server
X-Cache-Control
X-Upgrade-Enabled
Healthy
X-Endurance-Cache-Level
X-Cache-Server
X-Ttl
From-Origin
X-Handled-By
X-Backend-Name
X-CACHE-KEY
X-APP-VERSION
X-Status
Version
Accept-CH-Lifetime
X-Wix-Request-Id
X-Cache-Var
X-Rule
Meta-Geo
X-ES-SERVER
X-RN-RSRV
X-Cache-Var-Map
X-PressLabs-Stats
X-Path-Route
X-Tb
X-Timing-Wait
X-Proxy-Build
OT-Force-Account-Verify
X-Access
X-Section
X-RateLimit-Limit
X-Format
Selected-Fe
X-UUID
Akamai-GRN
Azure-RegionName
Azure-SiteName
Azure-InstanceId
Azure-SlotName
X-Storage
X-Akamai-Request-ID
X-Origin
X-PCL
X-OCL
X-Content-Age
X-Goog-Meta-Goog-Reserved-File-Mtime
X-ShopId
X-Request-Time
Azure-Version
X-ShardId
X-Proto
Mn-Server-Ip
Cache-Tags
X-EIG-Tracking-Id
X-Shopify-Stage
X-Shopify-Generated-Cart-Token
X-Sorting-Hat-ShopId
X-Alternate-Cache-Key
X-Sorting-Hat-PodId
X-Viewer-Country
X-Akamai-Request-ID2
Origin-Cache-Control
X-Vgn-Hpd-Reason
Origin-Edge-Control
X-Debug-Cache
Now
X-VWS-Id
X-Proxy
X-JoinUs
Decoy-Debug-Status
X-Hl-Ver
X-Generated-By
Decoy-Debug-Key
X-Yottaa-Metrics
DB-Nickname
X-Human
X-AWS-Id
X-LJ-Flow-ID
X-MP-GENERATED-AT
X-BYPASS-REASON
X-Hyper-Cache
Decoy-Debug-TTL
NGX
X-Yottaa-Optimizations
X-Qloud-Router
X-SaId
X-Soup
X-Cache-Config
S-Rt
Node
Ec-Rule-Version
X-FC-Vary-Parameters
X-NYM-Debug-Backend
X-Cluster-Node
X-Redis-Cache
X-Time-Microsecs
X-Web-Node
X-ProxyCache-Status
X-ServerID
X-Pubstack
X-ProxyCache-Key
X-Proxy-Cache-Status
X-Hosted-By
X-FW-Dynamic
GEO-INFO
TWC-GeoIP-Country
Cross-Origin-Window-Policy
X-Site-Version
X-Cache-Host
X-SayCDN-TTL
X-Detected-As
TWC-Device-Class
X-BCube-Filmed-By
Property-Id
X-Say-TTL
X-Say-Cacheable
TWC-GeoIP-LatLong
X-Www-Served-By
Webcakes-App-Name
X-IP
X-CCM
Webcakes-Region
Webcakes-App-Version
TWC-Privacy
TWC-Locale-Group
X-Origin-Hint
X-Varnish-Hits
X-Locale
Accept-Charset
TWC-Connection-Speed
X-Generated
X-Akamai-Transformed
Srv
X-Xfnlog-Site
X-Loop
X-Amzn-Remapped-Content-Length
X-RCS-CacheZone
X-R9-Blue-Green-Version
X-FB-TRIP-ID
X-TNCMS
L5d-Success-Class
X-NCache
X-CS
Cache-Name
X-Unique-Id
X-Drupal-Cache-Tags
Viewport
Uber-Trace-Id
Time
X-Trafficlayer-App-Name
Webserver
X-Trafficlayer-App-Scope
X-UA-Device-Type
Cache-Key
X-Esi
X-Cache-Remote
X-UnsetCookies
Mime-Version
X-Mode
X-Forwarded-Host
X-Backend-TTL
X-From
Accept-Language
Rt-Fastcgi-Cache
Country
X-CDN-Forward
X-Origin-CC
VIX-Pulpo-Node
X-Origin-TTL
VIX-Pulpo-Upstream-Status
X-Whom
X-Cluster-Name
X-Drupal-Cache-Contexts
X-Info
X-Daa-Tunnel
Odigeo-Trace-Id
X-Newrelic-Synthetics
X-Magnolia-Registration
X-Varnish-Cache-Hits
X-Microcachable
X-NGENIX-Cache
X-TT-TIMESTAMP
X-Edge-Location
X-ApacheServer
X-PERF
X-B3-Spanid
ServedBy
Content-Disposition
X-Geo
X-EC-Lua
X-CLOUD-TRACE-CONTEXT
X-Routing-Service
X-Proxied
X-Zipkin-Id
X-Device-Type
Ohc-File-Size
Proxy-Connection
X-UPSTREAM-Address
X-Via-Fastly
Ohc-Cache-HIT
X-Uri
X-No-Session
Section-Io-Cache
Mobile-Detection-Method
Meta-Geo-Continent
MD5-Digest
X-A-Ccd
X-A
Rendered-Blocks
Machine
VivaBuild
Viewtype
T-Server
X-Vtex-Processado-Em
W
AsisCache
Apple-News-Services-Host
Apple-News-Services-Parsed-Url
Apple-News-Services-Handled
X-Vtex-Remote-Cache
Xc-Version
Apple-News-Services-Request-Url
X-A-Dam
Fastcgi-X-Cache-Version
Content-Style-Type
Content-Script-Type
BehaviorPad-Version
GEO-REGION-INFO
X-A-Wwc
X-Request-UUID
X-Trv-Group
X-Rewrite-Enabled
X-Twitter-Response-Tags
X-Vdms-Version
X-Geo-Header
X-GeoIP-Country-Code
X-Region-Sid
X-Rocket-Build-Number
X-Transaction
X-S
X-S-Cookie
X-ScT
X-Sigma
X-Sigma-Backend
X-SRCache-Key
X-Rojux
X-G
X-External-Request-Id
X-Aed
X-Application
X-ARC
X-Accel-Expires-Debug
X-VG-WebServer
X-A-Dgt
X-Session-Fingerprint
X-B-Cookie
X-CF-Lambda-Fn
X-Destination
X-VG-WebCache
X-VG-TLSProxy
X-Date
X-D
X-CF-Lambda-Version
X-Connection-Hash
X-A-Dcw
X-DPWN-IS-SECURE
Cf-Ipcountry
HitType
X-Labrador-Cache-Channel
X-Nc
X-C
User-Cache-Control
X-PHP-Host
X-Cache-ASPX
X-Developers
X-Cache-Debug
X-Distil-CS
Locid
X-Bip
X-TrackingId
X-Backend-State
Fastly-Soc-X-Request-Id
X-Eu-Site
X-Thanos
CDCHOST
X-SIPLIST1
HA-Ipaddr
Ha-Gx-Prefs
Environment
X-Contensis-Viewer-Groups
Gh-Request-Id
X-CUA
X-Hit
IsBot
X-CGP
X-Auto-Login
X-Logging-Id
X-Wikidot-Static-Cache
X-Agile-Age
X-VC-Cache
X-Agile
Powered-By
X-Varnish-Authentication
Server-Cache-Control
Server-Surrogate-Control
X-Tumblr-Pixel-3
X-Agile-Id
X-WebServer
X-Real-IP
X-Wikidot-Backend
X-App-Name
X-Cache-Time
X-GoCache-CacheStatus
X-Cache-Backend
Geo-Info
X-Webstats-RespID
X-Request-URI
Web-Mar-Node
X-Cache-URL
X-WADP-Cache
X-Cache-Bucket
X-AK-Request-ID
X-Azure-Ref
X-Cdn-Srv
X-TT-LOGID
X-BBXSRF
X-Trace-Id
X-Urbn-Site-Id
X-Urbn-Context-Path
X-Block-Status
X-Cache-Info
X-Core-Mission
X-Micro-Cache
X-Ms-Request-Id
X-Ms-Version
X-Nginx-Cache-Key
X-Server-W
X-Key
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Instart-Isnd
X-Irp-Debug
X-NodeID
X-NX-Host
X-Proxy-Upstream
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Render-Time
X-Owner
X-OVcl-Cache
X-Origin-Date
X-Origin-Expires
X-OVcl
X-Hnp-Log
X-Hash
X-Debug-Cache-Expiry
X-Debug-Cache-Fetch
X-Debug-Cache-Store
X-Debug-Cookies
V-Age
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Clara-WADP
X-Cms-Context
X-Debug-Log
X-Dispatcher-Server
X-Gen-Mode
X-Generated-In
X-Generation-Time
X-GeoIP-City
X-Gamma-Serve
X-Fetched-On
X-Distributor
X-Epic-Correlation-Id
X-Fastly-Cache
X-Swa-Ws
We-Hiring
Fastly-Backend-Name
Heartbleed
Country-Code
X-TH-Server
Cdnsip
X-User
Kp-EeAlive
X-LI-UUID
Mail-Subject
X-FW-Version
X-Li-Fabric
X-Li-Pop
Locale
X-LI-Proto
Cdncip
X-VServer
X-Rebelmouse-Cache-Control
X-Tec-Api-Origin
X-Rebelmouse-Surrogate-Control
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-Tec-Api-Root
X-Tec-Api-Version
Countrycode
Cache-Host
Fastly-SIE
Fastly-SWR
X-Clientip
AKAMAI
Memcached
X-We-Are-Hiring
Access-Control-Request-Headers
Request-Country
Request-EU
RNT-Time
Fastly-SSL
RNT-Machine
True-Client-Country-4JS
Server-Int
IBM-Web2-Location
Server-ID
X-App-Version
X-Level-Front-Cache
Wxu-Next-Hostname
Wxu-Next-Region
X-Has-Esi
Is-Eu
X-Cache-Tags
X-Old-Content-Length
Platform
X-Internal-Host
X-Service
Thinkindot-CacheControl
X-NU-AKA-ACS-Version
X-Platform-Server
Thinkindot-CacheControl-Type
X-JWT-State
X-Variation
X-Generated-On
X-Up
X-ServiceProvider
X-Is-Gdpr
Wxu-Next-Commit
X-Servername
X-Reboot
X-Req
X-Trafficlayer-App-Version
PFcat
FNAC-ModuleRouting
Thinkindot-Control
X-Matched-Rule
X-Sucuri-Cache
X-Core-Value
ServerName
Server-Host
X-Thinkindot-L3
Adler-Geo
X-Oneagent-Js-Injection
Cache-Hits
X-S-Maxage
X-Lb-Id
X-TA-CDN-Provider
X-Response-By
X-Nginx-Cache
X-Air-Hostname
RequestId
X-Refresh
X-SERVER
X-Location
X-Parent-Response-Time
X-Var-Ttl
X-Tb-Optimization-Total-Bytes-Saved
Group
X-Cache-Expired-At
Pragrma
X-B3-Parentspanid
S-Cnection
Memory
Filterid
X-CF-Powered-By
X-Cdn-Forward
X-NC
ProcessTime
Powered-By-ChinaCache
X-Pjax-Url
X-BACKEND-TTL
X-B3-SpanId
X-CSRF-Token
X-CSRF-TOKEN
User-Agent
SRV
X-Wa
Origin
X-Pf-Uncompressing
X-Server-IP
TTL
Geoip-Latitude
X-Sucuri-ID
Geoip-City
X-NWS-UUID-VERIFY
X-Vcl-Version
X-Varnish-Cacheable
GeoIp-Country-Code
X-Unique-ID
X-NGINX-Cache
X-Ua
X-Correlation-ID
PICS-Label
Media-Length
X-Cdn-Request-ID
X-Via-CDN
X-Developer
X-COUNTRY
X-Sucuri-Id
X-LAGOON
X-Cdn-Origin
X-Sn-Servicetimems
X-Rocket-Nginx-Bypass
X-Ocache
X-Device-Os
X-Cache-Grace
X-Node-Id
X-Litespeed-Cache
X-Servedbyhost
Dnion-Transfer-Encoding
On-Server
M-TraceId
X-Webkit-CSP
SN
X-MSEdge-Flight
X-Request-Host
X-Varnish-Ttl
X-AIR-PT
A
X-Cache-Status-Check
X-MSEdge-Features
Esi-Enabled
X-Via-Ucdn
X-HS-Status
X-Reqid
XServer
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-Oss-Storage-Class
X-Oss-Request-Id
X-Oss-Object-Type
X-TIME
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
Tcn
HostName
Cdn
X-Planisys-CDN-Rules
X-Policy
Cloudfront-Viewer-Country
X-FORWARDED-FOR
X-Beluga-Status
X-Azure-Ref-OriginShield
Resin-Trace
X-Beluga-Trace
X-Request-Start
X-Beluga-Response-Time
X-Beluga-Record
X-Beluga-Node
Hostname
X-ServedByHost
X-Beluga-Cache-Status
X-Ratelimit-Remaining
X-Fastly-Country-Code
Who
X-Cache-Ttl
Rt-Proxy-Cache
X-Ftr-Cache-Host
X-VHOST
X-Varnish-URL
Host-ID
Request-ID
CF-Cached-On
Cteonnt-Length
Pics-Label
Magicmarker
X-Method
NtCoent-Length
X-APP
GeoIP-Country-Code
X-Slack-Backend
X-VCL-Version
X-LiteSpeed-Cache-Control
MIME-Version
X-Oracle-Dms-Rid
X-RPM
X-RPS
X-RSL
X-Bc
X-DW
X-Fastly-Backend-Reqs
GeoIP-Latitude
X-DSS
Ttl
X-Zone
X-DB
X-Action
X-DI
X-Varnish-Url
X-DC
Load-Balancing
X-Newrelic-App-Data
X-Svr
GeoIP-City
X-VarnishDD-TTL
CACHE
Arc-Country
X-PAYTM-SRV-ID
Ohc-Response-Time
X-Be
X-Processor
X-Server-Time
Pramga
X-Swift-Error
X-Skip-Cache
X-Dispatch
X-FPC
X-Cache-FS-Status
X-PF-Uncompressing
X-Ratelimit-Limit
X-HostName
DSUID
X-PJAX-URL
Amp-Access-Control-Allow-Source-Origin
WebServer
X-ND-Cache
Vix-Hermes-Req-Id
X-Flog
X-Hello
X-SRV
Processtime
X-ABtesting
X-Ftr-Request-Id
Release
X-VCT
X-MServer
X-Served-From
Cdn-Host
Fastly-Drupal-HTML
N-Cache
X-Hp-Ccpa-Warning
X-BE
X-Edge-Server
X-DevSite-Last-Modified
Cdn-Request-Time
X-Dynatrace
X-WR-MODIFICATION
X-Dynatrace-Js-Agent
CF-IPCountry
Servername
X-Bc-Bl
X-Amzn-Remapped-Date
X-ID
X-Amzn-Remapped-Connection
Cache-Provider
X-Aicache-OS
X-ZONE
X-Configured-By
X-Tid
X-WA
X-Frame-Option
X-Upstream-Ct
X-StackifyID
X-Upstream-Ht
Dynatrace
CDN
X-Fastly-Cache-Hits
X-Ftr-Dc
X-LB-ID
X-BC
X-Ftr-Balancer
Pagetype
SD-X-WS
X-Snapshot-Date
X-Branch-Name
X-SD-PageType
X-Ftr-Backend-Server
X-Backend-Host
Lfy
X-Ftr-Realm
Requestid
X-Ftr-Backend
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Io-Id
Section-Origin-Responded
X-CACHE-AGE
X-Compress-Hint
L
X-Edge-IP
Proxy-Firewall
X-Cache-Id
X-Apw-Access-Token
X-VC
X-SN
Warning
X-SB
WZWS-RAY
X-Varnish-Beresp-TTL
X-Request-Url
D-Cc-Upstream
X-Apw-Hits
X-Apw-Access-Action
X-Apw-Access-Object
V-Cache
X-Cc-Req-Id
X-Cc-Via
X-Litespeed-Cache-Control
Cneonction
X-WPE-Loopback-Upstream-Addr
FSS-Proxy
FSS-Cache
X-Worker
X-App
Lb
Correlation-Id
Backend-Name
X-ServerName
WP-Super-Cache
X-ElasticPress-Search
X-Request-URL
X-Check-Cacheable
X-Powered-Y
X-Release
X-Via-NSCOPI
X-Fastly-Cache-Status