Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-Powered-By
Pragma
X-XSS-Protection
CF-Cache-Status
Link
ETag
CF-RAY
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Request-ID
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-Xss-Protection
X-DNS-Prefetch-Control
X-Template
X-Language
CF-Ray
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
Status
Upgrade
X-Content-Security-Policy
Content-Encoding
X-CDN
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
X-Pass-Why
X-Cache-Group
X-AH-Environment
X-Envoy-Upstream-Service-Time
Xkey
X-Via
X-Backend
X-Server
X-Age
X-Amz-Request-Id
X-Amz-Id-2
X-Ws-Request-Id
X-Robots-Tag
X-Page-Speed
X-Server-Powered-By
X-Pingback
EagleId
X-Proxy-Cache
X-Hacker
X-Nginx-Cache-Status
X-UA-Device
Request-Context
Feature-Policy
X-Varnish-Cache
Server-Timing
Cf-Railgun
X-Swift-SaveTime
X-Swift-CacheTime
Grace
Ali-Swift-Global-Savetime
P3p
X-Amz-Version-Id
X-Ua-Compatible
Report-To
X-LiteSpeed-Cache
X-Rq
X-OneAgent-JS-Injection
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-WebKit-CSP
X-Device
X-Host
X-Server-Id
X-Origin-Cache
X-Response-Time
EagleEye-TraceId
X-Node
X-Ac
Surrogate-Control
Content-Location
X-Cloud-Trace-Context
X-Backend-Server
X-Readtime
X-Vhost
Request-Id
X-Dispatcher
X-Origin-Upstream-Status
X-Ruxit-JS-Agent
X-Cnection
X-Cache-Lookup
X-Application-Context
X-HW
Fusion-Content-Id
Fusion-Source
Fusion-Template-Id
Fusion-Component-Id
Fusion-Content-Source
X-ORACLE-DMS-ECID
X-Mod-Pagespeed
X-ORACLE-DMS-RID
X-DataDome
NEL
X-Rack-Cache
X-Country
X-Clacks-Overhead
Edge-Control
Rating
X-Akam-SW-Version
X-Dns-Prefetch-Control
Pinterest-Generated-By
X-TTL
Allow
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Accept-Ch
X-Country-Code
X-FTR-Request-ID
X-Instart-Request-ID
X-Varnish-TTL
X-DynaTrace
X-Goog-Hash
X-TtlSet
X-Vname
X-PC
X-ESI
Verso
Content-MD5
Accept-Ch-Lifetime
Service-Worker-Allowed
X-Powered-By-Plesk
X-Url
X-B3-TraceId
X-Forwarded-Proto
X-Version
X-Kinja
X-Exp-Id
X-Vcache
X-GoogleNews-Bot
X-Cdn-Fetch
X-GitHub-Request-Id
X-Exp-Variant
X-Kinja-Build
X-Kinja-Server
X-Kinja-Revision
X-Use-Magma
X-MS-InvokeApp
RTSS
X-Server-Name
X-D2id
X-Abt-Application-Version
Edge-Cache-Tag
X-Debug
X-Server-ID
X-Px
AR-ATIME
Ar-Sid
AR-CACHE
AR-PoweredBy
AR-Request-ID
X-Amz-Server-Side-Encryption
SPRequestGuid
Charset
X-NF-Request-ID
X-Cached
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-TEC-API-VERSION
X-Middleton-Response
X-Navigation-Version
X-Sol
X-Middleton-Display
Response
Pagespeed
Display
X-MSEdge-Ref
X-Vcap-Request-Id
X-Accel-Expires
Arr-Disable-Session-Affinity
X-Amz-Rid
TCN
X-Fastcgi-Cache
X-Pinterest-Rid
Pinterest-Version
X-SharePointHealthScore
X-VARITI-CCR
X-Powered-CMS
Public-Key-Pins
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Fastly-Request-ID
X-Trace
Cache-Tag
X-Edge-O15-RID
X-Cdn
X-Client-IP
Nginx-Cache
MS-Author-Via
Realpath
X-Ser
Access-Control-Request-Method
Nel
MRF-Tech
Mrf-Cache-Status
X-Content-Type
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
X-B3-TraceId-Primal
X-DynaTrace-JS-Agent
X-Shard
SPIisLatency
SPRequestDuration
X-Amzn-Trace-Id
X-Hp-Webp
X-Jurisdiction
S
X-Id
X-Grace
X-Upstream
X-Ezoic-Cdn
X-Forwarded-For
X-Amz-Meta-S3cmd-Attrs
Front-End-Https
X-Hits
X-T
Fastcgi-Cache
X-Cache-TTL
DynaTrace
X-Recruiting
X-Aspnet-Version
X-Varnish-Age
X-Node-Name
X-Element-Page-Cache
ServerID
X-Mobile-URL
X-Content-Digest
X-FTR-DC
X-FTR-Expires
X-FTR-Cache-Status
X-FTR-Backend
X-FTR-Balancer
X-Country-Code-Real
X-FTR-Realm
X-FTR-Backend-Server
X-Dw-Request-Base-Id
MicrosoftSharePointTeamServices
X-DIS-Request-ID
Server-Node
NR-ENABLED
X-Frontend
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Combine-CSS
X-HS-Content-Id
TP-Cache
TP-L2-Cache
X-GUploader-UploadID
X-Goog-Metageneration
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Generation
Powered
X-Logged-In
Alternate-Protocol
X-CST
Server-Name
X-Amzn-RequestId
X-Amz-Apigw-Id
Upgrade-Insecure-Requests
Fastly-Restarts
X-Request-Handler-Origin-Region
X-Microsite
X-Cache-Hit
X-Correlation-Id
Backend-Timing
X-ATS-Timestamp
X-XRDS-Location
X-Request-Received
X-Request-Processing-Time
AMP-Access-Control-Allow-Source-Origin
X-User-Agent
X-Content-Options
X-FTR-Cache-Host
X-Content-Security-Policy-Report-Only
X-F-Cache
X-Page-Id
X-Origin-Server
Refresh
X-Zen-Fury
X-Rid
X-Akamai-Edgescape
X-XRDS-LOCATION
X-Varnish-Grace
X-Revision
X-Type
X-B
X-Content-Powered-By
X-LB-Cache
PB-RID
PB-PID
Arc-Version
X-Mobile-Rewrite
X-B3-Sampled
X-Geo-Country
Cache-Status
X-Activity-Id
X-AppVersion
X-Az
X-URL
X-N
X-Kinsta-Cache
X-Cache-Action
X-Cache-Age
X-B-Cache
Access-Control-Allow-Method
X-TT
X-Signature
X-Jobs
X-Framework
X-Debug-Info
X-WebKit-CSP-Report-Only
X-Instance
X-Time
X-AOL-HN
X-FB-Debug
X-Tumblr-User
X-Tumblr-Pixel
Actual-Object-TTL
Paypal-Debug-Id
X-Tumblr-Pixel-0
X-Cached-By
X-App-Environment
X-Request-Guid
X-PHP-Backend
X-Load-Cache
X-Git-Hash
Fastcgi-Useragent
X-Shield-Request-Id
X-Pad
DC
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Amz-Replication-Status
X-RateLimit-Remaining
X-Varnish-Backend
X-NWS-LOG-UUID
X-Webkit-Csp
Host-Header
Surrogate-Key
X-IPLB-Instance
X-ATG-Version
Host
X-WA-Info
X-Contextid
MS-CV
X-ORACLE-APMCS-REQUEST-ID
X-Erf-Bev-Bev-Is-Generated
X-ORACLE-APMCS-TAG
X-Erf-Bev-Bev
X-Via-JSL
X-Mobile
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
NGB
X-Accel-Buffering
X-Host-Name
X-Response-Served-From
Frame-Options
X-SS-Set-Cookie
Payment
X-FastCGI-Cache
Tracecode
X-Cache-NE
X-Cluster
Source
X-Cache-2
Xserver
X-Region
X-Varnish-Server
Filters
Eomportal-Instance
X-FW-Serve
X-FW-Hash
X-FW-Type
X-Origin-Response-Time
X-Hostname
X-GeoIP
WPE-Backend
X-FW-Static
Retry-After
X-FW-Server
X-Presslabs-Stats
X-Varnish-Hostname
Cache-Tv-Group
X-Cacheable-TTL
X-IPS-LoggedIn
X-Cache-Enabled
X-Is-Bot
X-Rendered-As
X-NewRelic-App-Data
X-RequestSource
X-Cache-Rule
X-Cache-Operation
X-Tumblr-Pixel-1
X-Analytics
X-Tumblr-Pixel-2
X-Adobe-Loc
X-Adobe-Content
FilterID
X-Srv
X-Cache-Key
X-Seen-By
X-Webapp-Samesite-None-Activated-N
Liferay-Portal
X-TX-ID
X-EdgeConnect-Cache-Status
X-RemovedCookies
Server-Info
X-ProcessESI
X-App-Server
X-Cache-TTL-Remaining
Cleartype
X-CACHE-KEY
Accept-CH
X-Dc
X-Environment-Context
X-L-Path
X-B3-Traceid
X-FireWall-Port
X-Handled-By
X-Endurance-Cache-Level
X-Source
X-Upgrade-Enabled
Ms-Operation-Id
X-RTag
X-Cache-Server
X-HTML-Minification-Powered-By
From-Origin
Datacenter
X-UA
X-Backend-Name
Accept-Charset
Srv
Accept-CH-Lifetime
X-APP-VERSION
X-RN-RSRV
X-Cache-Var
X-Cache-Var-Map
X-UUID
X-ES-SERVER
X-Path-Route
Meta-Geo
X-Format
X-Section
OT-Force-Account-Verify
X-Proxy-Build
X-Timing-Wait
X-Access
Selected-Fe
X-Shopify-Generated-Cart-Token
X-Shopify-Stage
X-Sorting-Hat-ShopId
X-Wix-Request-Id
X-Tb
X-ShopId
X-Sorting-Hat-PodId
X-Request-Time
X-Alternate-Cache-Key
Cache-Tags
X-Cache-Config
X-Content-Age
X-Goog-Meta-Goog-Reserved-File-Mtime
X-EIG-Tracking-Id
X-ShardId
Mn-Server-Ip
X-PressLabs-Stats
X-Proto
X-PCL
X-Origin
X-Yottaa-Optimizations
X-OCL
X-Yottaa-Metrics
X-ProxyCache-Status
X-ProxyCache-Key
X-Proxy-Cache-Status
X-NYM-Debug-Backend
X-LJ-Flow-ID
X-Akamai-Request-ID
Akamai-GRN
NGX
X-Akamai-Request-ID2
X-AWS-Id
X-Hl-Ver
X-FC-Vary-Parameters
X-BYPASS-REASON
X-Qloud-Router
X-JoinUs
X-SaId
X-VWS-Id
X-Vgn-Hpd-Reason
Version
X-Soup
X-ServerID
X-Web-Node
X-Viewer-Country
X-CCM
X-FW-Dynamic
X-FB-TRIP-ID
X-Cluster-Node
X-Www-Served-By
X-BCube-Filmed-By
Cross-Origin-Window-Policy
Healthy
Origin-Edge-Control
Node
Now
Ec-Rule-Version
Decoy-Debug-TTL
DB-Nickname
Decoy-Debug-Key
Decoy-Debug-Status
X-TNCMS
X-Debug-Cache
X-Akamai-Transformed
GEO-INFO
X-Loop
X-MP-GENERATED-AT
X-Storage
X-Proxy
X-Say-TTL
X-Status
X-Time-Microsecs
X-SayCDN-TTL
X-Human
X-Hosted-By
X-Hyper-Cache
X-Pubstack
Origin-Cache-Control
X-Cache-Control
X-Say-Cacheable
X-Site-Version
X-Redis-Cache
X-RCS-CacheZone
X-Locale
Property-Id
TWC-Connection-Speed
TWC-Device-Class
Webcakes-App-Name
X-Amzn-Remapped-Content-Length
Webcakes-Region
X-Varnish-Hits
X-R9-Blue-Green-Version
X-Generated
Webcakes-App-Version
X-Generated-By
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Locale-Group
TWC-Privacy
X-Origin-Hint
X-Xfnlog-Site
Azure-RegionName
Azure-InstanceId
Azure-Version
Azure-SlotName
Azure-SiteName
X-RateLimit-Limit
Cache
S-Rt
X-Detected-As
X-NCache
X-IP
X-Cache-Host
Cache-Key
X-Rule
X-Whom
X-Unique-Id
X-VCache
X-Drupal-Cache-Tags
L5d-Success-Class
X-NGENIX-Cache
X-UA-Device-Type
Webserver
X-Mode
X-Esi
X-Daa-Tunnel
Time
X-Forwarded-Host
X-CS
Viewport
X-UnsetCookies
Cache-Name
Mime-Version
Accept-Language
X-VHOST
Uber-Trace-Id
Content-Disposition
X-Backend-TTL
X-Info
X-Origin-CC
X-Origin-TTL
Rt-Fastcgi-Cache
X-PERF
Country
X-Varnish-Cache-Hits
X-ApacheServer
Section-Io-Cache
X-Newrelic-Synthetics
X-B3-Spanid
Odigeo-Trace-Id
X-Cache-Remote
ServedBy
X-CDN-Forward
X-From
X-EC-Lua
X-Zipkin-Id
X-Routing-Service
X-Proxied
X-Device-Type
X-Nc
X-Via-Fastly
X-Cluster-Name
X-Magnolia-Registration
X-Drupal-Cache-Contexts
X-CLOUD-TRACE-CONTEXT
X-Uri
X-Microcachable
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
Proxy-Connection
X-Ttl
Filterid
X-Geo
Access-Control-Request-Headers
X-TT-TIMESTAMP
Ohc-File-Size
HitType
Geo-Info
X-Transaction
X-Region-Sid
GEO-REGION-INFO
MD5-Digest
Machine
Content-Style-Type
Fastcgi-X-Cache-Version
BehaviorPad-Version
Apple-News-Services-Parsed-Url
Meta-Geo-Continent
X-VG-WebServer
Apple-News-Services-Request-Url
AsisCache
Content-Script-Type
Apple-News-Services-Handled
X-TA-CDN-Provider
X-Real-IP
Rendered-Blocks
X-Application
X-ARC
X-Aed
X-Accel-Expires-Debug
X-A-Dgt
X-A-Wwc
X-B-Cookie
X-Destination
X-CF-Lambda-Version
X-Connection-Hash
X-CF-Lambda-Fn
X-D
X-Date
X-A-Dcw
X-A-Dam
T-Server
X-G
X-Trv-Group
X-Geo-Header
X-GeoIP-Country-Code
Viewtype
VivaBuild
X-A
X-A-Ccd
X-DPWN-IS-SECURE
W
X-External-Request-Id
Mobile-Detection-Method
Apple-News-Services-Host
X-Vtex-Processado-Em
X-S-Cookie
X-Rewrite-Enabled
X-S
Xc-Version
X-SRCache-Key
X-Sigma-Backend
X-Vdms-Version
X-VG-WebCache
X-Request-UUID
X-Twitter-Response-Tags
X-Vtex-Remote-Cache
X-Rocket-Build-Number
X-Session-Fingerprint
X-Varnish-Beresp-Status
X-Varnish-Beresp-Ttl
X-Sigma
X-Rojux
X-ScT
X-Varnish-Beresp-Grace
Cf-Ipcountry
X-C
HA-Ipaddr
Ha-Gx-Prefs
X-VG-TLSProxy
X-WebServer
Fastly-SIE
Countrycode
X-PHP-Host
CDCHOST
X-Agile
X-Eu-Site
X-Labrador-Cache-Channel
X-Cache-Time
Fastly-SWR
Fastly-Soc-X-Request-Id
Powered-By
X-Thanos
X-Rebelmouse-Cache-Control
X-Developers
Locid
X-Bip
X-Cache-Debug
X-Rebelmouse-Surrogate-Control
X-CGP
X-Agile-Id
X-Hit
X-No-Session
X-Distil-CS
X-Clientip
X-App-Name
X-Agile-Age
User-Cache-Control
X-GoCache-CacheStatus
Fastly-SSL
X-Hash
Platform
Server-Int
Server-ID
X-Has-Esi
Server-Cache-Control
X-Generated-In
RNT-Time
X-GeoIP-City
Request-EU
Request-Country
RNT-Machine
X-Urbn-Site-Id
X-Epic-Correlation-Id
X-Debug-Cookies
X-Cache-ASPX
X-Debug-Log
X-Dispatcher-Server
X-Auto-Login
X-Cache-Tags
X-Cdn-Srv
X-Contensis-Viewer-Groups
X-Cms-Context
X-CUA
X-VServer
X-Air-Hostname
X-VC-Cache
True-Client-Country-4JS
X-Fetched-On
X-Varnish-Authentication
X-Gamma-Serve
X-Variation
V-Age
X-Servername
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-SIPLIST1
We-Hiring
Server-Surrogate-Control
X-IN-APIGATEWAYSSL
Adler-Geo
AKAMAI
X-Logging-Id
X-Var-Ttl
Mail-Subject
X-SVT-ORM-RULES
X-Core-Mission
X-LI-UUID
X-TrackingId
Cache-Host
X-RateLimit-Remaining-Second
X-Cache-Expired-At
X-RateLimit-Limit-Second
X-Ms-Request-Id
X-Owner
X-Platform-Server
X-OVcl-Cache
X-OVcl
X-Trace-Id
X-SVT-ORM-VERSION
X-NX-Host
X-Ms-Version
X-Nginx-Cache-Key
X-NodeID
X-Proxy-Upstream
X-Li-Pop
X-LI-Proto
X-TH-Server
Gh-Request-Id
Group
X-Is-Gdpr
X-Swa-Ws
Heartbleed
Kp-EeAlive
Is-Eu
X-Instart-Isnd
IsBot
Locale
X-JWT-State
Country-Code
X-Li-Fabric
X-Request-URI
X-Backend-State
X-Urbn-Context-Path
X-IN-APIGATEWAY
X-Tumblr-Pixel-3
Environment
X-Edge-Location
X-UPSTREAM-Address
X-ServiceProvider
X-Trafficlayer-App-Name
X-Debug-Cache-Fetch
X-Reboot
X-Trafficlayer-App-Version
X-Debug-Cache-Expiry
X-Trafficlayer-App-Scope
X-Req
X-Debug-Cache-Store
X-Webstats-RespID
X-Level-Front-Cache
X-Gen-Mode
Pragrma
X-Up
X-Generated-On
X-Irp-Debug
X-Hnp-Log
Fastly-Backend-Name
X-Generation-Time
Cache-Hits
X-FW-Version
X-Server-W
X-Distributor
X-Origin-Expires
X-Thinkindot-L3
X-We-Are-Hiring
X-Origin-Date
X-NU-AKA-ACS-Version
X-Matched-Rule
X-Micro-Cache
X-Service
X-WADP-Cache
Wxu-Next-Commit
FNAC-ModuleRouting
Cdncip
Web-Mar-Node
Wxu-Next-Hostname
Wxu-Next-Region
Cdnsip
Thinkindot-Control
Ohc-Cache-HIT
Server-Host
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
ServerName
X-AK-Request-ID
IBM-Web2-Location
X-Block-Status
X-Cache-Info
Memcached
X-Clara-WADP
X-Azure-Ref
X-Cache-URL
PFcat
X-BBXSRF
X-App-Version
X-Render-Time
X-Lb-Id
X-TT-LOGID
X-S-Maxage
X-Cache-Bucket
S-Cnection
X-Old-Content-Length
X-Core-Value
X-Fastly-Cache
X-Cache-Backend
X-Nginx-Cache
X-User
RequestId
X-SERVER
X-Refresh
X-Response-By
X-Wa
Powered-By-ChinaCache
X-Internal-Host
X-Varnish-Cacheable
X-Sucuri-Cache
X-CSRF-TOKEN
X-Key
X-Sucuri-ID
X-Ua
X-Tec-Api-Root
X-Tec-Api-Version
X-CF-Powered-By
X-Parent-Response-Time
X-Pjax-Url
X-Node-Id
X-Tec-Api-Origin
Origin
X-Location
X-Oss-Object-Type
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-Oss-Storage-Class
X-Cdn-Forward
X-Developer
X-Tb-Optimization-Total-Bytes-Saved
User-Agent
X-CSRF-Token
X-BACKEND-TTL
SRV
X-Correlation-ID
ProcessTime
X-Cache-Status-Check
X-NC
X-Device-Os
X-Pf-Uncompressing
X-B3-Parentspanid
Geoip-City
X-LAGOON
TTL
Memory
X-Sn-Servicetimems
X-Cache-Grace
X-Via-CDN
X-Ocache
Geoip-Latitude
X-Cdn-Origin
X-NWS-UUID-VERIFY
X-NGINX-Cache
PICS-Label
GeoIp-Country-Code
X-Unique-ID
A
X-Vcl-Version
On-Server
Hostname
X-MSEdge-Features
X-Request-Host
Cloudfront-Viewer-Country
X-MSEdge-Flight
X-COUNTRY
X-Server-IP
X-B3-SpanId
M-TraceId
X-Servedbyhost
X-Litespeed-Cache
X-Webkit-CSP
Media-Length
X-Rocket-Nginx-Bypass
X-Varnish-Ttl
Cdn
X-Cdn-Request-ID
X-TIME
X-Ruxit-Js-Agent
XServer
X-Varnish-URL
Tcn
Dnion-Transfer-Encoding
Resin-Trace
SN
X-HS-Status
X-FORWARDED-FOR
Host-ID
X-ServedByHost
X-Via-Ucdn
HostName
X-Ratelimit-Remaining
CACHE
X-Beluga-Status
X-Beluga-Response-Time
X-Beluga-Node
Who
X-Beluga-Cache-Status
X-Beluga-Trace
X-Beluga-Record
X-Slack-Backend
X-Action
X-Cache-Ttl
X-Sucuri-Id
X-RPM
X-Server-Time
X-Processor
X-PAYTM-SRV-ID
X-DW
X-DSS
X-DI
X-DB
X-Dispatch
X-AIR-PT
X-Fastly-Country-Code
Esi-Enabled
X-RPS
X-RSL
X-Reqid
Arc-Country
Pramga
X-Cache-FS-Status
X-Flog
X-Hello
Pics-Label
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
X-ND-Cache
X-Planisys-CDN-Cache
X-ABtesting
X-Policy
X-Skip-Cache
GeoIP-Country-Code
CF-Cached-On
Fastly-Drupal-HTML
Cdn-Request-Time
X-Edge-Server
X-Azure-Ref-OriginShield
Cdn-Host
X-VarnishDD-TTL
X-Served-From
X-VCL-Version
GeoIP-Latitude
Amp-Access-Control-Allow-Source-Origin
X-Varnish-Url
X-Request-Start
GeoIP-City
X-Oracle-Dms-Rid
MIME-Version
X-LiteSpeed-Cache-Control
X-DevSite-Last-Modified
N-Cache
X-Bc-Bl
X-Zone
Section-Io-Origin-Status
Section-Io-Id
Section-Origin-Responded
Ttl
Rt-Proxy-Cache
X-PF-Uncompressing
X-Bc
Section-Io-Origin-Time-Seconds
NtCoent-Length
X-DC
X-Fastly-Backend-Reqs
X-APP
X-Newrelic-App-Data
X-Ratelimit-Limit
X-FPC
Fusion-Deployment-Id
X-HostName
Trailer
Magicmarker
X-Method
WebServer
X-SRV
X-Backend-Host
X-PJAX-URL
X-Swift-Error
X-Dynatrace
Cteonnt-Length
Cache-Cookie-Set-From
Cache-Cookie-Set-Idcheck
Processtime
X-BE
X-Amzn-Remapped-Date
Cache-Cookie-Set-Lfrom
X-Amzn-Remapped-Connection
Servername
X-Dynatrace-Js-Agent
X-Adobe-Source
FSS-Proxy
Cache-Provider
X-Scheme
X-ID
X-BC
X-WA
X-Fmm-Version
FSS-Cache
X-ZONE
X-WR-MODIFICATION
X-Frame-Option
X-Be
CDN
X-Fpc
CF-IPCountry
X-Svr
Dynatrace
X-StackifyID
Requestid
X-Snapshot-Date
X-LB-ID
X-Branch-Name
Ohc-Response-Time
X-Ftr-Cache-Host
X-CACHE-AGE
Vix-Hermes-Req-Id
X-Apw-Access-Action
X-App
X-Cc-Via
X-Apw-Access-Token
X-Apw-Hits
X-Request-Url
X-Aicache-OS
L
WZWS-RAY
X-Tid
V-Cache
X-Apw-Access-Object
X-Fastly-Cache-Hits
X-SN
D-Cc-Upstream
Warning
X-SB
X-VC
X-Cc-Req-Id
Lfy
X-Esi-Check
X-Compress-Hint
X-Cache-Id
Load-Balancing
X-Litespeed-Cache-Control
Lb
X-GEO
Sid
LB
X-Cache-NGX
SID
X-ElasticPress-Search
X-Request-URL
X-Powered-Y
X-Fastly-Cache-Status
X-Check-Cacheable
X-Varnish-Beresp-TTL
Backend-Name
Correlation-Id
X-WPE-Loopback-Upstream-Addr
Cneonction
WP-Super-Cache
Proxy-Firewall
Pagetype
X-Worker