Threat Level: green Handler on Duty: Bojan Zdrnja

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
Link
CF-RAY
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-UA-Compatible
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Request-ID
X-Cache-Status
X-Generator
Content-Security-Policy-Report-Only
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-Template
X-Language
X-Ua-Compatible
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
Status
X-Content-Security-Policy
X-CDN
Content-Encoding
Upgrade
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Xss-Protection
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
Xkey
X-Pass-Why
X-Cache-Group
P3p
X-AH-Environment
X-Envoy-Upstream-Service-Time
CF-Ray
X-Backend
X-Age
X-Server
X-Via
X-Robots-Tag
X-Amz-Request-Id
X-Amz-Id-2
X-Server-Powered-By
X-Page-Speed
X-Pingback
EagleId
X-Proxy-Cache
X-Nginx-Cache-Status
X-UA-Device
X-Hacker
X-Ws-Request-Id
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
Grace
Cf-Railgun
X-Swift-SaveTime
X-Swift-CacheTime
X-Amz-Version-Id
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
X-LiteSpeed-Cache
Report-To
X-Server-Id
X-Rq
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-WebKit-CSP
X-Host
X-Device
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Origin-Cache
X-Response-Time
Content-Location
X-Node
X-Ac
Surrogate-Control
X-Vhost
X-Readtime
Request-Id
X-Backend-Server
X-Cloud-Trace-Context
X-Dispatcher
X-Origin-Upstream-Status
X-Cnection
X-ORACLE-DMS-ECID
X-HW
X-Application-Context
X-DataDome
Fusion-Component-Id
Fusion-Content-Source
Fusion-Content-Id
Fusion-Source
Fusion-Template-Id
X-ORACLE-DMS-RID
NEL
X-Cache-Lookup
X-Mod-Pagespeed
Edge-Control
Rating
X-Rack-Cache
X-Country
X-Akam-SW-Version
X-Clacks-Overhead
Pinterest-Generated-By
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Ruxit-JS-Agent
X-DynaTrace
X-Varnish-TTL
Accept-Ch
X-Country-Code
Allow
X-Instart-Request-ID
X-Goog-Hash
X-TtlSet
X-PC
X-Vname
X-TTL
X-FTR-Request-ID
X-ESI
Verso
Accept-Ch-Lifetime
X-Powered-By-Plesk
X-Url
Service-Worker-Allowed
Content-MD5
X-B3-TraceId
X-Forwarded-Proto
X-Version
X-MS-InvokeApp
X-GitHub-Request-Id
X-Cdn-Fetch
X-Kinja-Build
X-Use-Magma
X-Kinja-Revision
X-Kinja-Server
X-Kinja
X-GoogleNews-Bot
X-Exp-Variant
X-Exp-Id
Edge-Cache-Tag
RTSS
X-Px
AR-PoweredBy
AR-ATIME
AR-CACHE
Ar-Sid
AR-Request-ID
X-D2id
X-Debug
X-Abt-Application-Version
Charset
X-NF-Request-ID
X-Server-Name
SPRequestGuid
X-Vcache
X-Amz-Server-Side-Encryption
X-Powered-CMS
X-Accel-Expires
X-Cached
X-MSEdge-Ref
X-Amz-Rid
Arr-Disable-Session-Affinity
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Vcap-Request-Id
X-Sol
X-Middleton-Display
Display
Pagespeed
X-Navigation-Version
Response
X-Middleton-Response
X-Trace
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-SharePointHealthScore
Pinterest-Version
X-Pinterest-Rid
X-Fastcgi-Cache
TCN
X-VARITI-CCR
Realpath
Public-Key-Pins
Cache-Tag
X-Cdn
Access-Control-Request-Method
X-Client-IP
S
X-Fastly-Request-ID
X-Upstream
X-Ser
X-DynaTrace-JS-Agent
MS-Author-Via
X-Shard
SPRequestDuration
X-Id
SPIisLatency
X-Hp-Webp
DynaTrace
X-Ezoic-Cdn
X-Forwarded-For
Nginx-Cache
Mrf-Cache-Status
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
X-Mrf-Item-Lastmod
MRF-Tech
X-Content-Type
X-T
X-Amz-Meta-S3cmd-Attrs
X-Amzn-Trace-Id
X-Recruiting
Front-End-Https
X-Grace
Nel
X-Hits
Fastcgi-Cache
X-Varnish-Age
X-DIS-Request-ID
ServerID
MicrosoftSharePointTeamServices
X-Mobile-URL
X-Dw-Request-Base-Id
NR-ENABLED
X-Node-Name
X-Element-Page-Cache
X-Edge-O15-RID
X-Content-Digest
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Storage-Class
X-GUploader-UploadID
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Cache-Config
X-Goog-Generation
X-Frontend
Powered
X-Country-Code-Real
X-FTR-Expires
X-FTR-Cache-Status
Server-Name
Alternate-Protocol
X-FTR-Backend
X-FTR-Backend-Server
X-FTR-Balancer
X-Logged-In
X-FTR-Realm
X-FTR-DC
X-Cache-TTL
TP-Cache
TP-L2-Cache
Server-Node
X-Correlation-Id
AMP-Access-Control-Allow-Source-Origin
X-XRDS-LOCATION
X-Webkit-Csp
X-Request-Processing-Time
X-Request-Received
X-Shield-Request-Id
X-Microsite
X-Request-Handler-Origin-Region
X-Jurisdiction
X-Webapp-Samesite-None-Activated-N
Upgrade-Insecure-Requests
Refresh
X-Content-Options
X-Content-Security-Policy-Report-Only
X-Page-Id
X-Origin-Server
X-User-Agent
X-Revision
X-Akamai-Edgescape
X-Rid
X-ATS-Timestamp
X-Cache-Hit
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Varnish-Grace
Backend-Timing
X-F-Cache
X-Server-ID
X-Type
X-XRDS-Location
Fastly-Restarts
X-Content-Powered-By
X-Pad
X-Geo-Country
X-Zen-Fury
X-Az
X-LB-Cache
X-B3-Sampled
X-AppVersion
X-Activity-Id
X-B
X-N
X-Analytics
X-URL
X-Kinsta-Cache
X-FTR-Cache-Host
PB-RID
PB-PID
X-TT
X-WebKit-CSP-Report-Only
Arc-Version
X-Cache-Age
X-Mobile-Rewrite
X-AOL-HN
X-App-Environment
X-Tumblr-Pixel-0
X-Instance
X-CST
X-Request-Guid
X-Jobs
X-Tumblr-User
X-Tumblr-Pixel
Actual-Object-TTL
X-Ruxit-Js-Agent
Paypal-Debug-Id
X-Framework
DC
X-B-Cache
X-Debug-Info
X-RateLimit-Remaining
Cache-Status
X-Signature
Access-Control-Allow-Method
X-FB-Debug
X-PHP-Backend
X-Load-Cache
X-Cache-Action
X-Varnish-Backend
X-Erf-Bev-Bev
X-Git-Hash
Fastcgi-Useragent
X-Erf-Bev-Bev-Is-Generated
Surrogate-Key
X-Time
Host-Header
X-Ttl
X-Cached-By
X-Tt-Trace-Tag
FilterID
X-IPLB-Instance
X-Amz-Replication-Status
MS-CV
X-Contextid
X-SS-Set-Cookie
X-Tt-Trace-Host
X-Cluster
X-Cache-Key
X-ATG-Version
X-Srv
Tracecode
Frame-Options
X-Response-Served-From
X-Accel-Buffering
NGB
WPE-Backend
X-FastCGI-Cache
Payment
X-Varnish-Server
Eomportal-Instance
X-WA-Info
Xserver
Source
X-Tumblr-Pixel-2
X-Varnish-Hostname
Host
X-IPS-LoggedIn
X-GeoIP
Filters
X-Cache-Enabled
X-Cacheable-TTL
X-Cache-NE
X-FW-Hash
X-Region
X-RequestSource
X-Cache-2
X-FW-Type
X-FW-Static
X-FW-Serve
X-FW-Server
Cache-Tv-Group
X-Tumblr-Pixel-1
X-Is-Bot
X-Rendered-As
X-Mobile
X-Adobe-Loc
X-Host-Name
X-Adobe-Content
X-TX-ID
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
Cleartype
X-Seen-By
X-NewRelic-App-Data
X-Oneagent-Js-Injection
X-Cache-Operation
X-Cache-Rule
X-EdgeConnect-Cache-Status
X-Via-JSL
X-Hostname
X-Origin-Response-Time
X-Trafficlayer-App-Scope
Cache
X-Cache-TTL-Remaining
X-Trafficlayer-App-Name
Healthy
X-Presslabs-Stats
X-Cache-Control
X-ORACLE-APMCS-TAG
X-ORACLE-APMCS-REQUEST-ID
Datacenter
X-HTML-Minification-Powered-By
X-VCache
X-Dc
Retry-After
X-RemovedCookies
Server-Info
X-UA
X-ProcessESI
Ms-Operation-Id
X-RTag
X-B3-Traceid
Accept-CH
X-Rule
X-NWS-LOG-UUID
Liferay-Portal
X-Cache-Server
X-PressLabs-Stats
X-FireWall-Port
X-L-Path
X-Wix-Request-Id
X-Status
Version
X-Environment-Context
From-Origin
X-Source
X-RateLimit-Limit
X-Upgrade-Enabled
X-Endurance-Cache-Level
X-CACHE-KEY
X-Cache-Var
X-ES-SERVER
X-Path-Route
X-Cache-Var-Map
X-Handled-By
Meta-Geo
X-RN-RSRV
Selected-Fe
X-Proxy-Build
X-Timing-Wait
OT-Force-Account-Verify
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Shopify-Stage
X-Proto
X-UUID
X-Shopify-Generated-Cart-Token
X-Tb
X-Sorting-Hat-ShopId
X-Storage
Accept-CH-Lifetime
X-EIG-Tracking-Id
X-Alternate-Cache-Key
X-Hyper-Cache
X-ShardId
X-Content-Age
X-Sorting-Hat-PodId
X-ShopId
X-Backend-Name
X-Proxy
X-Origin
X-FC-Vary-Parameters
X-ProxyCache-Key
Decoy-Debug-Key
X-PCL
Webcakes-App-Version
DB-Nickname
Ec-Rule-Version
X-Debug-Cache
X-Section
X-Human
X-Hosted-By
Decoy-Debug-TTL
X-Hl-Ver
X-ProxyCache-Status
X-JoinUs
X-OCL
Webcakes-App-Name
X-Yottaa-Optimizations
Node
NGX
TWC-Privacy
X-Generated-By
X-Yottaa-Metrics
X-Akamai-Request-ID2
Akamai-GRN
TWC-GeoIP-LatLong
X-BYPASS-REASON
X-Web-Node
X-Access
X-ServerID
TWC-GeoIP-Country
Decoy-Debug-Status
X-LJ-Flow-ID
X-Viewer-Country
X-Origin-Hint
TWC-Locale-Group
X-Time-Microsecs
X-Soup
X-Qloud-Router
X-VWS-Id
X-Cache-Config
X-Cache-Host
S-Rt
X-Vgn-Hpd-Reason
X-Pubstack
TWC-Device-Class
Azure-SiteName
Azure-RegionName
Now
Azure-InstanceId
X-Request-Time
X-SaId
X-Redis-Cache
Webcakes-Region
X-Akamai-Request-ID
X-AWS-Id
X-Format
Property-Id
Origin-Edge-Control
TWC-Connection-Speed
X-FW-Dynamic
Origin-Cache-Control
Cache-Tags
Azure-SlotName
Azure-Version
X-BCube-Filmed-By
X-CCM
X-Say-TTL
X-Varnish-Hits
X-Site-Version
X-Proxy-Cache-Status
X-Www-Served-By
X-Xfnlog-Site
X-RCS-CacheZone
X-Cluster-Node
X-SayCDN-TTL
Mn-Server-Ip
X-MP-GENERATED-AT
X-App-Server
X-IP
X-NYM-Debug-Backend
X-Generated
X-Locale
X-Say-Cacheable
X-Amzn-Remapped-Content-Length
X-TNCMS
X-FB-TRIP-ID
X-Detected-As
Cross-Origin-Window-Policy
X-Loop
L5d-Success-Class
X-APP-VERSION
Cache-Name
X-R9-Blue-Green-Version
GEO-INFO
Viewport
X-CS
Uber-Trace-Id
Accept-Charset
Time
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Akamai-Transformed
Webserver
X-Drupal-Cache-Tags
X-Unique-Id
X-NCache
X-Cache-Remote
X-From
X-Esi
X-UA-Device-Type
Srv
X-Edge-Location
X-TT-TIMESTAMP
X-Cluster-Name
Mime-Version
Cache-Key
X-Drupal-Cache-Contexts
X-Origin-CC
X-Backend-TTL
X-Origin-TTL
Accept-Language
Country
X-CDN-Forward
X-EC-Lua
X-Mode
Odigeo-Trace-Id
X-Newrelic-Synthetics
X-Microcachable
X-B3-Spanid
Rt-Fastcgi-Cache
Ohc-Cache-HIT
Ohc-File-Size
X-Forwarded-Host
X-Info
X-Geo
X-No-Session
X-CLOUD-TRACE-CONTEXT
Proxy-Connection
X-Whom
X-Magnolia-Registration
X-UPSTREAM-Address
X-UnsetCookies
X-Zipkin-Id
X-Proxied
X-PHP-Host
ServedBy
X-Varnish-Cache-Hits
X-Labrador-Cache-Channel
Content-Disposition
X-Routing-Service
X-PERF
X-Real-IP
X-ApacheServer
Cf-Ipcountry
Fastly-SSL
X-Cache-Time
Powered-By
X-Region-Sid
X-G
Content-Script-Type
X-Request-UUID
X-S-Cookie
X-ScT
X-Rojux
X-Geo-Header
X-SRCache-Key
X-Rewrite-Enabled
X-S
X-Session-Fingerprint
Content-Style-Type
GEO-REGION-INFO
X-External-Request-Id
AsisCache
X-Date
Machine
Rendered-Blocks
X-DPWN-IS-SECURE
X-Destination
BehaviorPad-Version
X-Device-Type
X-Accel-Expires-Debug
Meta-Geo-Continent
Mobile-Detection-Method
X-GeoIP-Country-Code
X-D
MD5-Digest
Fastcgi-X-Cache-Version
X-Connection-Hash
X-Trv-Group
Xc-Version
X-B-Cookie
X-VG-WebServer
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
VivaBuild
X-App-Version
X-ARC
X-Application
X-Vdms-Version
Viewtype
X-Twitter-Response-Tags
X-Aed
X-CF-Lambda-Fn
X-A-Dgt
X-A-Wwc
X-CF-Lambda-Version
X-A-Dcw
X-A-Dam
T-Server
X-A
X-A-Ccd
X-Transaction
X-VG-WebCache
User-Cache-Control
X-Via-Fastly
Access-Control-Request-Headers
X-Bip
Environment
X-SIPLIST1
X-Uri
W
Gh-Request-Id
IsBot
X-Auto-Login
X-Logging-Id
Server-Surrogate-Control
X-Varnish-Authentication
Server-Cache-Control
X-CUA
X-VG-TLSProxy
X-Cache-Backend
X-Contensis-Viewer-Groups
X-Cache-Debug
X-Rocket-Build-Number
X-Sigma-Backend
X-WebServer
X-Thanos
X-Sigma
X-Cache-ASPX
X-TrackingId
X-VC-Cache
X-Tumblr-Pixel-3
X-NGENIX-Cache
ServerName
X-C
X-Cdn-Srv
X-Gamma-Serve
X-BBXSRF
X-Cache-Info
X-Debug-Cookies
X-Fastly-Cache
X-CGP
X-Debug-Cache-Fetch
X-Clara-WADP
X-Block-Status
X-FW-Version
X-Agile
X-Debug-Cache-Store
X-Eu-Site
X-Dispatcher-Server
X-Agile-Id
X-Backend-State
X-Distil-CS
X-AK-Request-ID
X-Cms-Context
X-Clientip
X-Debug-Log
X-Cache-Bucket
X-Agile-Age
X-Epic-Correlation-Id
X-Distributor
X-OVcl
Fastly-Backend-Name
X-Webstats-RespID
X-We-Are-Hiring
Fastly-Soc-X-Request-Id
FNAC-ModuleRouting
RNT-Machine
Locid
X-WADP-Cache
X-VServer
X-Trace-Id
X-TH-Server
X-TT-LOGID
X-Urbn-Context-Path
X-User
X-Urbn-Site-Id
RNT-Time
Server-Int
X-App-Name
X-Wikidot-Static-Cache
X-Wikidot-Backend
Apple-News-Services-Handled
Apple-News-Services-Host
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
X-Req
X-Nginx-Cache-Key
Wxu-Next-Hostname
Wxu-Next-Commit
Wxu-Next-Region
X-Cache-URL
X-Developers
X-Core-Mission
X-Swa-Ws
X-SVT-ORM-VERSION
X-Irp-Debug
X-Instart-Isnd
X-IN-APIGATEWAYSSL
X-Key
X-Li-Fabric
X-LI-Proto
X-Li-Pop
X-IN-APIGATEWAY
X-Hnp-Log
X-Generation-Time
X-Generated-In
X-GeoIP-City
X-GoCache-CacheStatus
X-Hit
X-Hash
X-LI-UUID
X-Location
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Proxy-Upstream
X-Render-Time
X-Request-URI
X-SVT-ORM-RULES
X-Sucuri-Cache
X-Owner
X-OVcl-Cache
X-Ms-Version
X-Ms-Request-Id
X-NodeID
X-NX-Host
X-Origin-Expires
X-Origin-Date
X-Gen-Mode
X-Debug-Cache-Expiry
IBM-Web2-Location
Heartbleed
HA-Ipaddr
Kp-EeAlive
Locale
Request-Country
Memcached
Mail-Subject
Ha-Gx-Prefs
Countrycode
AKAMAI
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
Cache-Host
CDCHOST
Country-Code
Cdnsip
Cdncip
Request-EU
X-Varnish-Beresp-Ttl
We-Hiring
True-Client-Country-4JS
Server-ID
Web-Mar-Node
Section-Io-Cache
V-Age
Geo-Info
X-Micro-Cache
X-Generated-On
X-Variation
X-Internal-Host
Adler-Geo
X-Has-Esi
X-Up
X-Azure-Ref
X-Is-Gdpr
X-Thinkindot-L3
X-Service
X-ServiceProvider
X-Platform-Server
X-S-Maxage
X-Reboot
X-Old-Content-Length
X-NU-AKA-ACS-Version
X-Level-Front-Cache
X-Matched-Rule
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-JWT-State
X-Trafficlayer-App-Version
Fastly-SIE
Fastly-SWR
X-Daa-Tunnel
X-Cache-Tags
Server-Host
PFcat
Platform
X-Core-Value
Is-Eu
Thinkindot-CacheControl
Thinkindot-Control
Thinkindot-CacheControl-Type
X-B3-Parentspanid
HitType
X-Nc
X-TA-CDN-Provider
X-Lb-Id
X-Response-By
X-Refresh
Cache-Hits
X-Server-W
RequestId
X-Servername
X-Fetched-On
X-SERVER
X-Server-IP
X-Parent-Response-Time
X-Tb-Optimization-Total-Bytes-Saved
X-Nginx-Cache
X-B3-SpanId
ProcessTime
Memory
X-Cdn-Forward
X-NC
Filterid
X-CF-Powered-By
X-CSRF-Token
Media-Length
SRV
X-Tec-Api-Root
X-Tec-Api-Origin
X-Pjax-Url
X-Cdn-Request-ID
X-Tec-Api-Version
X-CSRF-TOKEN
Origin
X-Air-Hostname
X-Wa
User-Agent
Group
X-Cache-Expired-At
X-Pf-Uncompressing
X-BACKEND-TTL
TTL
Geoip-Latitude
X-Var-Ttl
Pragrma
X-NGINX-Cache
X-Vcl-Version
GeoIp-Country-Code
X-Ua
X-Correlation-ID
X-Unique-ID
X-TIME
X-Rocket-Nginx-Bypass
Powered-By-ChinaCache
X-Sucuri-Id
S-Cnection
X-AIR-PT
Esi-Enabled
X-Reqid
X-Sucuri-ID
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
PICS-Label
X-COUNTRY
X-Policy
X-Planisys-CDN-TTL
X-Varnish-Cacheable
X-Request-Start
HostName
X-Servedbyhost
Rt-Proxy-Cache
X-Litespeed-Cache
X-HS-Status
SN
X-Webkit-CSP
X-Azure-Ref-OriginShield
Geoip-City
M-TraceId
X-Via-CDN
X-Fastly-Country-Code
X-Via-Ucdn
Dnion-Transfer-Encoding
XServer
X-Developer
Magicmarker
X-NWS-UUID-VERIFY
X-Method
Load-Balancing
X-FORWARDED-FOR
X-Device-Os
X-Ocache
Resin-Trace
X-Sn-Servicetimems
X-ServedByHost
X-Node-Id
Tcn
X-LAGOON
X-Cdn-Origin
X-Cache-Grace
On-Server
Who
Ohc-Response-Time
DSUID
X-Cache-Ttl
X-Ftr-Cache-Host
X-VHOST
Release
X-Ratelimit-Remaining
Cdn
X-MSEdge-Flight
X-MServer
X-Request-Host
X-MSEdge-Features
A
X-VCT
X-Svr
CF-Cached-On
X-Be
NtCoent-Length
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Object-Type
X-Oss-Storage-Class
X-Oss-Hash-Crc64ecma
X-APP
X-Bc
X-Hp-Ccpa-Warning
Vix-Hermes-Req-Id
Cloudfront-Viewer-Country
X-Zone
Pics-Label
X-Varnish-Url
GeoIP-Country-Code
X-Fastly-Backend-Reqs
X-Cache-Status-Check
X-Beluga-Trace
X-Beluga-Record
X-Beluga-Node
X-Beluga-Response-Time
X-Beluga-Status
Cteonnt-Length
X-Beluga-Cache-Status
X-LiteSpeed-Cache-Control
X-VCL-Version
Hostname
X-Oracle-Dms-Rid
MIME-Version
Ttl
X-Configured-By
X-VarnishDD-TTL
GeoIP-Latitude
X-DC
X-PF-Uncompressing
SD-X-WS
X-Newrelic-App-Data
X-Varnish-Ttl
X-Varnish-URL
GeoIP-City
Host-ID
X-SD-PageType
X-WR-MODIFICATION
X-Ratelimit-Limit
X-SRV
X-Upstream-Ht
X-Tid
X-Compress-Hint
X-PJAX-URL
X-Cache-Id
X-Ftr-Request-Id
X-Upstream-Ct
WebServer
X-SN
X-HostName
X-Aicache-OS
X-Dynatrace
X-BE
X-Via-NSCOPI
X-Slack-Backend
Processtime
X-Release
L
X-Dynatrace-Js-Agent
LB
Cache-Provider
X-DW
X-RSL
X-RPM
X-Scheme
X-Action
X-Swift-Error
CACHE
X-RPS
X-DI
X-DB
X-ID
X-DSS
X-Frame-Option
Amp-Access-Control-Allow-Source-Origin
X-Ftr-Dc
X-Server-Time
X-PAYTM-SRV-ID
X-Skip-Cache
X-Processor
X-Dispatch
Pramga
Arc-Country
X-StackifyID
X-Cache-FS-Status
X-FPC
X-Ftr-Realm
Dynatrace
UCS
Cache-Cookie-Set-Lfrom
X-Ftr-Backend
X-Ftr-Backend-Server
Cache-Cookie-Set-From
X-Branch-Name
Pagetype
Servername
CF-IPCountry
Lfy
X-Fastly-Cache-Hits
X-LB-ID
CDN
X-Snapshot-Date
X-ServerName
X-Ftr-Balancer
Requestid
Cache-Cookie-Set-Idcheck
X-CACHE-AGE
Proxy-Firewall
X-Cc-Via
X-Apw-Access-Object
X-Apw-Access-Action
X-ND-Cache
Fastly-Drupal-HTML
X-Cc-Req-Id
X-Edge-IP
X-Varnish-Beresp-TTL
X-ZONE
X-DevSite-Last-Modified
X-Node-ID
X-Apw-Hits
X-Apw-Access-Token
V-Cache
X-SB
Warning
D-Cc-Upstream
X-VC
NnCoection
X-Worker
Lb
X-ABtesting
X-ElasticPress-Search
X-Hello
X-Flog
X-Request-Url
WZWS-RAY
X-Powered-Y
Correlation-Id
X-App
WP-Super-Cache
Backend-Name
X-Check-Cacheable
X-Fastly-Cache-Status
X-Request-URL
X-Litespeed-Cache-Control
X-BC