Threat Level: green Handler on Duty: Russ McRee

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
Link
CF-RAY
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-Cache-Hits
X-Amz-Cf-Pop
X-UA-Compatible
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Cache-Status
X-Generator
Content-Security-Policy-Report-Only
X-Permitted-Cross-Domain-Policies
X-Request-ID
X-Cacheable
X-Template
X-Language
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
Status
X-Content-Security-Policy
X-CDN
Upgrade
Content-Encoding
Access-Control-Expose-Headers
X-Ua-Compatible
Access-Control-Max-Age
X-Xss-Protection
X-Kinja-Server-Push
Keep-Alive
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
P3p
Xkey
X-Pass-Why
X-Cache-Group
X-AH-Environment
X-Envoy-Upstream-Service-Time
CF-Ray
X-Backend
X-Via
X-Age
X-Server
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Server-Powered-By
X-Page-Speed
X-Pingback
X-Ws-Request-Id
EagleId
X-Proxy-Cache
X-Nginx-Cache-Status
X-Hacker
X-UA-Device
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
Grace
Cf-Railgun
X-Swift-SaveTime
X-Swift-CacheTime
X-Amz-Version-Id
Ali-Swift-Global-Savetime
X-LiteSpeed-Cache
Report-To
X-Dns-Prefetch-Control
X-Rq
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-WebKit-CSP
X-Server-Id
X-Host
X-Device
X-OneAgent-JS-Injection
EagleEye-TraceId
X-Origin-Cache
X-Response-Time
Content-Location
X-Ac
X-Node
Surrogate-Control
X-Vhost
X-Readtime
Request-Id
X-Cloud-Trace-Context
X-Backend-Server
X-Dispatcher
X-Origin-Upstream-Status
X-Cnection
X-HW
X-Application-Context
X-ORACLE-DMS-ECID
Fusion-Template-Id
Fusion-Content-Id
Fusion-Source
Fusion-Content-Source
Fusion-Component-Id
X-DataDome
X-Cache-Lookup
X-ORACLE-DMS-RID
NEL
X-Mod-Pagespeed
Rating
X-Rack-Cache
Edge-Control
X-Country
X-Akam-SW-Version
X-Clacks-Overhead
X-Ruxit-JS-Agent
Pinterest-Generated-By
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
Allow
X-DynaTrace
X-Country-Code
X-Instart-Request-ID
Accept-Ch
X-Varnish-TTL
X-Goog-Hash
X-TTL
X-Vname
X-TtlSet
X-PC
X-FTR-Request-ID
Verso
X-ESI
Accept-Ch-Lifetime
X-Powered-By-Plesk
Service-Worker-Allowed
Content-MD5
X-Url
X-Forwarded-Proto
X-Version
X-MS-InvokeApp
X-B3-TraceId
X-GitHub-Request-Id
X-Kinja-Revision
X-Use-Magma
X-GoogleNews-Bot
X-Kinja-Server
X-Cdn-Fetch
X-Exp-Variant
X-Exp-Id
X-Kinja-Build
X-Kinja
Edge-Cache-Tag
RTSS
AR-PoweredBy
X-Px
AR-ATIME
AR-CACHE
AR-Request-ID
Ar-Sid
X-D2id
X-Debug
X-Abt-Application-Version
SPRequestGuid
X-Server-Name
X-Vcache
Charset
X-Amz-Server-Side-Encryption
X-NF-Request-ID
X-Accel-Expires
X-Cached
X-MSEdge-Ref
Display
Response
X-TEC-API-VERSION
X-Sol
X-Amz-Rid
X-Middleton-Display
X-Middleton-Response
Pagespeed
X-TEC-API-ROOT
X-TEC-API-ORIGIN
Arr-Disable-Session-Affinity
TCN
X-Vcap-Request-Id
X-Powered-CMS
X-Navigation-Version
X-SharePointHealthScore
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Pinterest-Rid
Pinterest-Version
X-Fastcgi-Cache
X-Trace
X-Cdn
X-VARITI-CCR
Public-Key-Pins
Cache-Tag
X-Client-IP
Realpath
Access-Control-Request-Method
X-Ser
X-Fastly-Request-ID
S
MS-Author-Via
X-DynaTrace-JS-Agent
X-Upstream
X-Shard
SPIisLatency
Nginx-Cache
SPRequestDuration
X-Id
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
X-Ezoic-Cdn
X-Hp-Webp
X-Content-Type
X-Forwarded-For
X-Amzn-Trace-Id
X-Grace
X-Amz-Meta-S3cmd-Attrs
X-T
Nel
X-Recruiting
DynaTrace
Front-End-Https
X-Hits
Fastcgi-Cache
X-Edge-O15-RID
X-Aspnet-Version
X-Varnish-Age
ServerID
X-Server-ID
MicrosoftSharePointTeamServices
X-DIS-Request-ID
X-Dw-Request-Base-Id
X-Mobile-URL
X-Element-Page-Cache
X-Node-Name
X-Content-Digest
NR-ENABLED
X-Country-Code-Real
X-FTR-Expires
X-FTR-Cache-Status
X-Cache-TTL
X-HS-Hub-Id
X-HS-Content-Id
X-HS-Cache-Config
X-HS-Combine-CSS
X-Frontend
Powered
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Metageneration
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-FTR-Realm
X-FTR-Backend
X-FTR-Backend-Server
X-Jurisdiction
X-FTR-Balancer
X-FTR-DC
Alternate-Protocol
Server-Name
TP-L2-Cache
TP-Cache
Server-Node
X-Logged-In
X-Correlation-Id
X-Request-Processing-Time
X-Request-Received
X-XRDS-Location
X-Microsite
X-Request-Handler-Origin-Region
AMP-Access-Control-Allow-Source-Origin
Upgrade-Insecure-Requests
Backend-Timing
X-ATS-Timestamp
X-Page-Id
X-Content-Options
X-Amzn-RequestId
X-Content-Security-Policy-Report-Only
X-Amz-Apigw-Id
X-User-Agent
Refresh
X-Cache-Hit
X-Akamai-Edgescape
X-F-Cache
X-Origin-Server
X-Rid
X-Type
X-Varnish-Grace
X-Revision
X-Zen-Fury
X-Shield-Request-Id
Fastly-Restarts
X-XRDS-LOCATION
X-Content-Powered-By
X-B3-Sampled
X-CST
X-LB-Cache
X-Webapp-Samesite-None-Activated-N
X-URL
X-Az
X-Geo-Country
X-AppVersion
X-Activity-Id
X-N
X-B
X-FTR-Cache-Host
PB-PID
PB-RID
X-Pad
X-Kinsta-Cache
X-Mobile-Rewrite
Arc-Version
Cache-Status
X-Analytics
X-RateLimit-Remaining
X-Cache-Age
X-TT
X-Instance
X-Debug-Info
X-AOL-HN
X-Webkit-Csp
X-WebKit-CSP-Report-Only
X-Request-Guid
X-Signature
X-Jobs
X-Time
X-B-Cache
X-Tumblr-Pixel
X-Tumblr-Pixel-0
X-Tumblr-User
X-App-Environment
X-Framework
Actual-Object-TTL
Access-Control-Allow-Method
Paypal-Debug-Id
DC
X-FB-Debug
X-Cache-Action
X-PHP-Backend
X-Load-Cache
X-Cached-By
X-Git-Hash
X-Varnish-Backend
Surrogate-Key
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
Fastcgi-Useragent
X-Tt-Trace-Tag
Host-Header
X-Tt-Trace-Host
X-Amz-Replication-Status
X-IPLB-Instance
X-Contextid
MS-CV
FilterID
X-Ruxit-Js-Agent
X-SS-Set-Cookie
X-ATG-Version
X-Cluster
X-FastCGI-Cache
X-WA-Info
Tracecode
X-Cache-Key
X-Accel-Buffering
X-Response-Served-From
X-B3-Traceid
WPE-Backend
X-Srv
X-Cache-NE
NGB
X-Ttl
Frame-Options
X-Host-Name
X-Varnish-Server
Payment
X-Region
X-FW-Server
X-Cache-Operation
X-FW-Serve
Host
X-FW-Hash
X-FW-Static
X-Kong-Upstream-Latency
X-Cache-Rule
X-Kong-Proxy-Latency
X-Hostname
Source
Eomportal-Instance
X-FW-Type
Xserver
Cache-Tv-Group
Filters
X-Cache-2
X-Adobe-Content
X-Adobe-Loc
X-Varnish-Hostname
X-Mobile
X-Cache-Enabled
X-Tumblr-Pixel-2
X-GeoIP
X-Rendered-As
X-Is-Bot
X-Tumblr-Pixel-1
X-IPS-LoggedIn
X-TX-ID
X-Cacheable-TTL
X-Via-JSL
X-RequestSource
X-ORACLE-APMCS-REQUEST-ID
X-EdgeConnect-Cache-Status
X-Origin-Response-Time
X-ORACLE-APMCS-TAG
X-Presslabs-Stats
X-NewRelic-App-Data
Cleartype
X-Seen-By
X-Cache-TTL-Remaining
Cache
X-VCache
Retry-After
Server-Info
Accept-CH
X-NWS-LOG-UUID
X-ProcessESI
X-RemovedCookies
X-HTML-Minification-Powered-By
Datacenter
X-Cache-Control
Liferay-Portal
X-RTag
Ms-Operation-Id
Healthy
X-Source
X-UA
X-Dc
X-L-Path
X-Environment-Context
X-Cache-Server
X-FireWall-Port
X-Endurance-Cache-Level
X-Upgrade-Enabled
X-RateLimit-Limit
From-Origin
X-CACHE-KEY
X-APP-VERSION
Accept-CH-Lifetime
X-App-Server
X-Rule
X-Esi
X-PressLabs-Stats
Version
X-Status
X-Handled-By
X-Wix-Request-Id
X-Cache-Var-Map
X-Path-Route
Meta-Geo
X-ES-SERVER
X-RN-RSRV
X-Cache-Var
X-Backend-Name
Selected-Fe
X-Section
X-Proxy-Build
X-Format
X-Tb
OT-Force-Account-Verify
X-Request-Time
X-Access
X-Timing-Wait
X-ProxyCache-Status
Azure-Version
X-Proto
X-Shopify-Stage
Mn-Server-Ip
X-Alternate-Cache-Key
X-BYPASS-REASON
X-Akamai-Request-ID
X-EIG-Tracking-Id
X-PCL
X-Shopify-Generated-Cart-Token
X-Sorting-Hat-ShopId
X-Goog-Meta-Goog-Reserved-File-Mtime
X-OCL
Akamai-GRN
Azure-SiteName
Azure-InstanceId
Azure-RegionName
X-Origin
X-Content-Age
X-ShardId
X-Storage
X-ProxyCache-Key
X-ShopId
Azure-SlotName
X-Sorting-Hat-PodId
Cache-Tags
X-Debug-Cache
X-Cluster-Node
X-Cache-Host
X-FC-Vary-Parameters
X-FW-Dynamic
X-Hosted-By
X-Hl-Ver
X-Generated-By
X-AWS-Id
X-Akamai-Request-ID2
Decoy-Debug-TTL
Decoy-Debug-Status
Decoy-Debug-Key
Ec-Rule-Version
NGX
S-Rt
Now
Node
X-Human
X-Hyper-Cache
X-Time-Microsecs
X-ServerID
X-SaId
X-UUID
X-Vgn-Hpd-Reason
X-Web-Node
X-VWS-Id
X-Viewer-Country
X-Redis-Cache
X-Proxy-Cache-Status
X-MP-GENERATED-AT
X-LJ-Flow-ID
X-JoinUs
X-NYM-Debug-Backend
X-Trafficlayer-App-Scope
X-Proxy
X-Trafficlayer-App-Name
DB-Nickname
X-Cache-Config
X-Yottaa-Metrics
X-Yottaa-Optimizations
TWC-Privacy
TWC-Locale-Group
Webcakes-App-Name
Webcakes-App-Version
Webcakes-Region
Cross-Origin-Window-Policy
TWC-GeoIP-LatLong
X-Varnish-Hits
TWC-Connection-Speed
X-Soup
TWC-Device-Class
TWC-GeoIP-Country
X-BCube-Filmed-By
Origin-Edge-Control
Property-Id
X-CCM
X-RCS-CacheZone
X-IP
X-Qloud-Router
X-Pubstack
X-Origin-Hint
X-Generated
Srv
X-Say-TTL
X-Detected-As
Origin-Cache-Control
X-Say-Cacheable
X-SayCDN-TTL
X-Loop
X-FB-TRIP-ID
X-Amzn-Remapped-Content-Length
X-Oneagent-Js-Injection
X-Xfnlog-Site
X-TNCMS
GEO-INFO
Accept-Charset
L5d-Success-Class
X-R9-Blue-Green-Version
X-Locale
X-CS
X-Www-Served-By
X-Site-Version
X-Unique-Id
X-Akamai-Transformed
Cache-Name
Uber-Trace-Id
X-NCache
Viewport
X-Drupal-Cache-Tags
Webserver
Time
X-UA-Device-Type
Cache-Key
X-Backend-TTL
VIX-Pulpo-Node
X-Cache-Remote
X-From
VIX-Pulpo-Upstream-Status
Mime-Version
X-CDN-Forward
X-Origin-TTL
X-Cluster-Name
X-Drupal-Cache-Contexts
X-Mode
Accept-Language
X-Origin-CC
X-UnsetCookies
Country
X-TT-TIMESTAMP
X-Forwarded-Host
Odigeo-Trace-Id
X-Edge-Location
Rt-Fastcgi-Cache
X-B3-Spanid
X-Microcachable
X-Info
X-CLOUD-TRACE-CONTEXT
X-Whom
X-Varnish-Cache-Hits
X-TA-CDN-Provider
X-Geo
X-Magnolia-Registration
X-Newrelic-Synthetics
Content-Disposition
X-ApacheServer
X-EC-Lua
X-PERF
X-UPSTREAM-Address
X-NGENIX-Cache
ServedBy
Proxy-Connection
Ohc-Cache-HIT
X-No-Session
Ohc-File-Size
X-Routing-Service
X-Device-Type
X-Proxied
X-Zipkin-Id
X-Via-Fastly
Cf-Ipcountry
X-Daa-Tunnel
Xc-Version
Apple-News-Services-Request-Url
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
Apple-News-Services-Parsed-Url
X-VG-WebCache
X-Uri
X-VG-WebServer
Apple-News-Services-Host
Apple-News-Services-Handled
Mobile-Detection-Method
X-Session-Fingerprint
X-CF-Lambda-Version
X-ScT
X-S-Cookie
X-S
X-Sigma
X-CF-Lambda-Fn
X-Sigma-Backend
X-SRCache-Key
X-Application
X-ARC
X-B-Cookie
X-Connection-Hash
X-D
X-Region-Sid
X-GeoIP-Country-Code
X-Request-UUID
X-Rewrite-Enabled
X-Rocket-Build-Number
X-Geo-Header
X-G
X-Date
X-Destination
X-DPWN-IS-SECURE
X-External-Request-Id
X-Aed
X-Accel-Expires-Debug
X-Vdms-Version
Machine
X-Twitter-Response-Tags
MD5-Digest
Meta-Geo-Continent
X-VG-TLSProxy
GEO-REGION-INFO
BehaviorPad-Version
Content-Script-Type
Content-Style-Type
Fastcgi-X-Cache-Version
X-Rojux
X-Trv-Group
X-A-Dam
X-Transaction
X-A-Dcw
X-A-Dgt
X-A-Wwc
X-A-Ccd
W
Rendered-Blocks
T-Server
Viewtype
VivaBuild
AsisCache
X-A
X-PHP-Host
X-Labrador-Cache-Channel
HitType
X-Real-IP
X-C
User-Cache-Control
X-Cache-Debug
IsBot
X-CUA
X-Render-Time
X-SIPLIST1
Fastly-Soc-X-Request-Id
X-Contensis-Viewer-Groups
X-Auto-Login
X-App-Name
HA-Ipaddr
CDCHOST
Gh-Request-Id
Server-Surrogate-Control
X-Hit
X-Cache-ASPX
Server-Cache-Control
X-Cache-Time
Ha-Gx-Prefs
Environment
Locid
X-VC-Cache
X-Wikidot-Backend
X-Developers
X-WebServer
X-Distil-CS
Powered-By
X-Tumblr-Pixel-3
X-Backend-State
X-TrackingId
X-Eu-Site
X-CGP
X-Wikidot-Static-Cache
Geo-Info
X-Epic-Correlation-Id
X-Varnish-Authentication
Fastly-SSL
X-GoCache-CacheStatus
X-Azure-Ref
RNT-Time
Section-Io-Cache
X-Irp-Debug
X-Li-Pop
Request-EU
Request-Country
X-Key
X-Debug-Cache-Store
RNT-Machine
X-LI-UUID
X-LI-Proto
X-Li-Fabric
X-Location
X-Debug-Log
X-FW-Version
X-Fetched-On
X-Gamma-Serve
X-Gen-Mode
Web-Mar-Node
X-Fastly-Cache
X-Distributor
X-Dispatcher-Server
X-AK-Request-ID
X-Agile-Id
X-Agile-Age
X-Agile
We-Hiring
X-Generated-In
X-IN-APIGATEWAY
X-Hnp-Log
X-IN-APIGATEWAYSSL
X-Debug-Cookies
Server-Int
True-Client-Country-4JS
X-Hash
X-Generation-Time
X-GeoIP-City
X-Logging-Id
V-Age
Server-ID
X-Bip
X-Sucuri-Cache
X-Nc
X-Core-Mission
X-Cache-Info
X-TH-Server
Access-Control-Request-Headers
X-Server-W
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Cache-Bucket
X-Request-URI
X-Thanos
X-Cache-URL
X-VServer
X-Clientip
X-WADP-Cache
X-We-Are-Hiring
X-Webstats-RespID
X-User
X-Urbn-Site-Id
X-Cms-Context
X-Cdn-Srv
X-TT-LOGID
X-Urbn-Context-Path
X-Debug-Cache-Fetch
X-RateLimit-Remaining-Second
Kp-EeAlive
X-Debug-Cache-Expiry
X-NX-Host
IBM-Web2-Location
X-Origin-Date
Locale
X-Nginx-Cache-Key
Memcached
X-Clara-WADP
X-BBXSRF
Mail-Subject
X-Origin-Expires
X-OVcl
Country-Code
X-Proxy-Upstream
X-RateLimit-Limit-Second
Cdnsip
Countrycode
X-Block-Status
X-OVcl-Cache
Fastly-SWR
Fastly-SIE
Cdncip
Fastly-Backend-Name
X-Core-Value
X-Ms-Request-Id
X-SVT-ORM-VERSION
X-Swa-Ws
X-SVT-ORM-RULES
X-ServiceProvider
X-Req
X-Thinkindot-L3
X-Trace-Id
X-Servername
X-Variation
X-Up
X-Trafficlayer-App-Version
X-Reboot
X-Platform-Server
X-JWT-State
X-Matched-Rule
X-Is-Gdpr
X-Internal-Host
X-Instart-Isnd
X-Micro-Cache
X-Varnish-Beresp-Status
X-Owner
X-Old-Content-Length
X-NU-AKA-ACS-Version
X-NodeID
X-Has-Esi
X-Ms-Version
Server-Host
Thinkindot-CacheControl
X-Varnish-Beresp-Grace
Platform
ServerName
Thinkindot-CacheControl-Type
Thinkindot-Control
Wxu-Next-Region
Wxu-Next-Hostname
Wxu-Next-Commit
Adler-Geo
X-Varnish-Beresp-Ttl
PFcat
Heartbleed
X-Cache-Tags
Cache-Host
FNAC-ModuleRouting
X-Nginx-Cache
Is-Eu
X-Cache-Backend
AKAMAI
X-Refresh
X-Level-Front-Cache
X-Generated-On
Cache-Hits
X-S-Maxage
X-Response-By
X-Service
X-SERVER
X-App-Version
X-B3-Parentspanid
RequestId
X-Lb-Id
X-Tb-Optimization-Total-Bytes-Saved
X-Parent-Response-Time
X-CSRF-TOKEN
X-Air-Hostname
X-CF-Powered-By
Filterid
X-NC
X-Tec-Api-Root
X-Var-Ttl
X-Cache-Expired-At
X-Tec-Api-Version
Pragrma
X-Tec-Api-Origin
ProcessTime
X-B3-SpanId
X-Wa
X-Ua
Memory
X-Server-IP
Group
S-Cnection
X-Cdn-Forward
X-Pjax-Url
User-Agent
Origin
Powered-By-ChinaCache
X-BACKEND-TTL
X-CSRF-Token
X-Pf-Uncompressing
X-Cdn-Request-ID
Media-Length
SRV
X-Correlation-ID
X-Sucuri-ID
PICS-Label
Geoip-Latitude
TTL
X-Varnish-Cacheable
X-COUNTRY
X-NGINX-Cache
X-Vcl-Version
GeoIp-Country-Code
X-Sucuri-Id
X-Unique-ID
Geoip-City
X-Servedbyhost
X-Via-CDN
X-Oracle-Dms-Rid
X-NWS-UUID-VERIFY
X-Rocket-Nginx-Bypass
X-Reqid
X-Developer
X-AIR-PT
X-Litespeed-Cache
X-Webkit-CSP
SN
Dnion-Transfer-Encoding
Esi-Enabled
X-Node-Id
X-Cache-Grace
X-Cdn-Origin
X-Device-Os
X-Varnish-Ttl
X-Sn-Servicetimems
X-HS-Status
X-Via-Ucdn
X-LAGOON
X-Policy
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Planisys-CDN-Cache
XServer
X-TIME
X-Request-Start
X-Ocache
M-TraceId
X-Azure-Ref-OriginShield
On-Server
X-FORWARDED-FOR
HostName
X-MSEdge-Features
Rt-Proxy-Cache
A
X-Request-Host
X-MSEdge-Flight
X-Cache-Ttl
X-Cache-Status-Check
X-Fastly-Country-Code
Resin-Trace
Cdn
Who
Hostname
X-Ftr-Cache-Host
X-VHOST
Cloudfront-Viewer-Country
X-ServedByHost
X-Beluga-Status
X-Beluga-Trace
X-Beluga-Response-Time
X-APP
X-Beluga-Cache-Status
Magicmarker
X-Beluga-Record
X-Beluga-Node
X-Method
X-Oss-Object-Type
X-Oss-Server-Time
X-Oss-Storage-Class
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
CF-Cached-On
GeoIP-Country-Code
X-VCL-Version
X-DC
X-Zone
X-Bc
X-Varnish-URL
Ttl
GeoIP-Latitude
Host-ID
Load-Balancing
NtCoent-Length
Pics-Label
MIME-Version
Ohc-Response-Time
Tcn
X-Be
X-Varnish-Url
X-Svr
X-Fastly-Backend-Reqs
GeoIP-City
Cteonnt-Length
X-LiteSpeed-Cache-Control
X-Ratelimit-Remaining
DSUID
X-PF-Uncompressing
X-MServer
X-Slack-Backend
X-Newrelic-App-Data
X-VarnishDD-TTL
Vix-Hermes-Req-Id
Release
X-VCT
X-Hp-Ccpa-Warning
X-DW
X-DSS
X-PJAX-URL
X-RPM
X-RPS
Amp-Access-Control-Allow-Source-Origin
X-SRV
X-DI
WebServer
X-Ftr-Request-Id
X-Action
X-RSL
X-DB
X-BE
Arc-Country
X-Configured-By
X-FPC
X-Skip-Cache
X-Processor
X-Cache-FS-Status
Processtime
X-PAYTM-SRV-ID
X-Dynatrace
X-Dispatch
X-Server-Time
X-Swift-Error
X-Tid
X-Dynatrace-Js-Agent
X-Ratelimit-Limit
Servername
X-WR-MODIFICATION
X-SD-PageType
Cache-Provider
CACHE
SD-X-WS
X-ID
Pramga
X-Flog
X-Upstream-Ht
X-Hello
X-ND-Cache
X-DevSite-Last-Modified
X-Upstream-Ct
X-Aicache-OS
X-ABtesting
Fastly-Drupal-HTML
X-Frame-Option
X-HostName
N-Cache
X-Edge-Server
Cdn-Request-Time
Cdn-Host
X-StackifyID
L
X-Ftr-Backend
X-Ftr-Backend-Server
Lfy
X-Compress-Hint
CDN
X-Branch-Name
X-SN
X-Fastly-Cache-Hits
Pagetype
Dynatrace
CF-IPCountry
X-Ftr-Realm
X-Ftr-Dc
X-Ftr-Balancer
X-LB-ID
X-Cache-Id
X-Snapshot-Date
Requestid
X-CACHE-AGE
X-Served-From
X-VC
X-Apw-Access-Action
X-Apw-Access-Object
Proxy-Firewall
X-Request-Url
X-Varnish-Beresp-TTL
X-Release
X-ZONE
X-Via-NSCOPI
X-ServerName
X-Edge-IP
X-Apw-Access-Token
X-Bc-Bl
X-Cc-Req-Id
D-Cc-Upstream
Warning
X-SB
X-Apw-Hits
X-Cc-Via
X-WA
X-Amzn-Remapped-Date
X-Amzn-Remapped-Connection
V-Cache
WP-Super-Cache
X-ElasticPress-Search
X-Scheme
X-Backend-Host
X-Fastly-Cache-Status
X-Powered-Y
X-Request-URL
X-Worker
X-Check-Cacheable
X-BC
X-App
LB
Backend-Name
Correlation-Id
Lb