Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
CF-RAY
Link
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Request-ID
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-DNS-Prefetch-Control
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
Status
Upgrade
X-Content-Security-Policy
Content-Encoding
X-CDN
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
X-Xss-Protection
Keep-Alive
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
X-Pass-Why
X-Cache-Group
X-AH-Environment
Xkey
X-Envoy-Upstream-Service-Time
CF-Ray
X-Via
X-Backend
X-Server
X-Age
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Ws-Request-Id
X-Page-Speed
X-Server-Powered-By
X-Pingback
EagleId
X-Proxy-Cache
X-Hacker
X-UA-Device
X-Nginx-Cache-Status
Request-Context
Feature-Policy
X-Varnish-Cache
Server-Timing
Cf-Railgun
X-Swift-SaveTime
X-Swift-CacheTime
Grace
Ali-Swift-Global-Savetime
X-Amz-Version-Id
X-Ua-Compatible
Report-To
X-LiteSpeed-Cache
X-Rq
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-WebKit-CSP
X-OneAgent-JS-Injection
X-Device
X-Host
X-Server-Id
X-Origin-Cache
X-Response-Time
EagleEye-TraceId
X-Ac
X-Node
Surrogate-Control
Content-Location
X-Cloud-Trace-Context
X-Backend-Server
X-Readtime
X-Vhost
Request-Id
X-Dispatcher
X-Origin-Upstream-Status
X-Cache-Lookup
X-Cnection
X-Application-Context
X-HW
X-Ruxit-JS-Agent
Fusion-Source
Fusion-Component-Id
P3p
Fusion-Template-Id
Fusion-Content-Id
Fusion-Content-Source
X-ORACLE-DMS-ECID
X-Mod-Pagespeed
NEL
X-ORACLE-DMS-RID
X-DataDome
X-Dns-Prefetch-Control
X-Rack-Cache
Rating
X-Clacks-Overhead
Edge-Control
X-Akam-SW-Version
X-Country
Pinterest-Generated-By
Allow
X-TTL
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Country-Code
X-FTR-Request-ID
X-DynaTrace
X-Instart-Request-ID
X-Varnish-TTL
X-Goog-Hash
X-TtlSet
X-PC
X-Vname
Accept-Ch
Verso
Content-MD5
Service-Worker-Allowed
X-ESI
X-Powered-By-Plesk
Accept-Ch-Lifetime
X-Url
X-B3-TraceId
X-Forwarded-Proto
X-GitHub-Request-Id
X-Version
X-GoogleNews-Bot
X-Use-Magma
X-Kinja-Build
X-Vcache
X-Exp-Variant
X-Kinja
X-Kinja-Server
X-Cdn-Fetch
X-Kinja-Revision
X-MS-InvokeApp
X-Exp-Id
RTSS
X-Server-Name
Edge-Cache-Tag
X-D2id
X-Abt-Application-Version
X-Debug
AR-PoweredBy
Ar-Sid
AR-Request-ID
AR-CACHE
X-Px
AR-ATIME
X-Amz-Server-Side-Encryption
SPRequestGuid
Charset
X-NF-Request-ID
X-Cached
Pagespeed
Display
X-Middleton-Display
X-Middleton-Response
X-Sol
X-TEC-API-ORIGIN
Response
X-TEC-API-VERSION
X-TEC-API-ROOT
X-Navigation-Version
X-MSEdge-Ref
X-Vcap-Request-Id
X-Accel-Expires
X-Server-ID
X-Amz-Rid
Arr-Disable-Session-Affinity
Pinterest-Version
X-Pinterest-Rid
TCN
X-Fastcgi-Cache
X-SharePointHealthScore
X-Edge-O15-RID
X-Powered-CMS
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-VARITI-CCR
X-Cdn
X-Fastly-Request-ID
Public-Key-Pins
Cache-Tag
X-Client-IP
X-Trace
Nginx-Cache
Realpath
MS-Author-Via
X-Ser
Access-Control-Request-Method
X-Shard
X-Mrf-Section-Lastmod
Mrf-Cache-Status
X-DynaTrace-JS-Agent
X-B3-TraceId-Primal
MRF-Tech
X-Mrf-Item-Lastmod
X-Content-Type
SPIisLatency
SPRequestDuration
X-Ezoic-Cdn
X-Amzn-Trace-Id
X-Id
X-Grace
S
X-Jurisdiction
X-Hp-Webp
X-Upstream
X-T
X-Amz-Meta-S3cmd-Attrs
Nel
X-Hits
Front-End-Https
Fastcgi-Cache
X-Forwarded-For
X-Recruiting
X-Aspnet-Version
X-Cache-TTL
DynaTrace
X-Varnish-Age
X-Element-Page-Cache
ServerID
X-Node-Name
X-Content-Digest
MicrosoftSharePointTeamServices
X-Mobile-URL
X-FTR-Cache-Status
X-FTR-Realm
X-FTR-Expires
X-Country-Code-Real
X-FTR-Backend
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-DC
X-Dw-Request-Base-Id
X-DIS-Request-ID
Server-Node
NR-ENABLED
X-HS-Hub-Id
X-HS-Combine-CSS
X-HS-Content-Id
X-HS-Cache-Config
X-Goog-Metageneration
X-Goog-Generation
X-Frontend
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-GUploader-UploadID
X-Goog-Stored-Content-Length
Powered
TP-Cache
TP-L2-Cache
X-Logged-In
X-CST
Alternate-Protocol
Server-Name
X-Correlation-Id
X-Amz-Apigw-Id
X-Amzn-RequestId
AMP-Access-Control-Allow-Source-Origin
X-XRDS-Location
Upgrade-Insecure-Requests
Fastly-Restarts
X-Request-Handler-Origin-Region
X-Request-Received
X-Request-Processing-Time
X-Microsite
X-Cache-Hit
Backend-Timing
X-ATS-Timestamp
X-Content-Options
X-Origin-Server
X-User-Agent
X-Content-Security-Policy-Report-Only
X-FTR-Cache-Host
Refresh
X-F-Cache
X-Zen-Fury
X-Rid
X-Akamai-Edgescape
X-Page-Id
X-Varnish-Grace
X-Revision
X-Type
X-Content-Powered-By
X-LB-Cache
X-B
PB-RID
X-XRDS-LOCATION
PB-PID
X-B3-Sampled
Arc-Version
X-Mobile-Rewrite
X-Geo-Country
X-URL
X-AppVersion
X-Activity-Id
X-Az
Cache-Status
X-N
X-Kinsta-Cache
X-Cache-Age
X-Cache-Action
X-TT
X-Signature
X-AOL-HN
X-B-Cache
X-Instance
X-WebKit-CSP-Report-Only
Actual-Object-TTL
Paypal-Debug-Id
Access-Control-Allow-Method
X-Debug-Info
X-Tumblr-User
X-Framework
X-Tumblr-Pixel
X-Jobs
X-Tumblr-Pixel-0
X-App-Environment
X-Cached-By
X-Load-Cache
X-FB-Debug
X-Request-Guid
X-Git-Hash
X-PHP-Backend
DC
Fastcgi-Useragent
X-Pad
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Time
X-Shield-Request-Id
X-Webkit-Csp
X-Amz-Replication-Status
X-RateLimit-Remaining
X-Varnish-Backend
X-NWS-LOG-UUID
X-IPLB-Instance
Surrogate-Key
Host-Header
MS-CV
X-ATG-Version
X-WA-Info
X-Contextid
Host
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-ORACLE-APMCS-TAG
X-ORACLE-APMCS-REQUEST-ID
Accept-CH
X-FastCGI-Cache
X-SS-Set-Cookie
X-Via-JSL
X-Cache-Key
X-Mobile
X-Host-Name
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Accel-Buffering
X-Response-Served-From
NGB
Payment
X-Cluster
X-Cache-NE
Tracecode
X-Analytics
Frame-Options
Eomportal-Instance
X-Region
X-Varnish-Server
WPE-Backend
X-Cache-2
X-FW-Server
X-FW-Hash
X-FW-Type
X-FW-Static
FilterID
Source
X-FW-Serve
X-Origin-Response-Time
X-Varnish-Hostname
X-Webapp-Samesite-None-Activated-N
X-IPS-LoggedIn
X-Tumblr-Pixel-1
X-GeoIP
X-Tumblr-Pixel-2
Cache-Tv-Group
Filters
X-Adobe-Loc
X-Hostname
X-Cache-Enabled
X-Adobe-Content
Retry-After
X-Cacheable-TTL
X-Cache-Operation
X-Is-Bot
X-Rendered-As
X-Seen-By
X-RequestSource
X-NewRelic-App-Data
X-Cache-Rule
Xserver
X-EdgeConnect-Cache-Status
X-Presslabs-Stats
Server-Info
Accept-CH-Lifetime
X-TX-ID
Liferay-Portal
X-RemovedCookies
X-Srv
X-ProcessESI
X-Cache-TTL-Remaining
X-App-Server
Cleartype
X-B3-Traceid
X-Environment-Context
X-Dc
X-L-Path
X-RTag
X-FireWall-Port
Ms-Operation-Id
X-Source
X-Endurance-Cache-Level
X-UA
X-Handled-By
X-Upgrade-Enabled
X-Cache-Server
Datacenter
X-HTML-Minification-Powered-By
From-Origin
X-Backend-Name
X-CACHE-KEY
Accept-Charset
Srv
X-Esi
X-APP-VERSION
X-PressLabs-Stats
X-RN-RSRV
X-Cache-Var-Map
Meta-Geo
X-UUID
X-Cache-Var
X-ES-SERVER
GEO-INFO
X-Path-Route
X-Proxy-Build
X-Timing-Wait
X-Section
X-Tb
OT-Force-Account-Verify
X-Access
X-Wix-Request-Id
X-Format
Selected-Fe
X-Sorting-Hat-ShopId
Azure-SiteName
X-Cache-Config
Azure-SlotName
Azure-RegionName
Azure-Version
X-OCL
Akamai-GRN
X-FC-Vary-Parameters
X-Content-Age
X-Goog-Meta-Goog-Reserved-File-Mtime
X-NYM-Debug-Backend
X-EIG-Tracking-Id
Azure-InstanceId
X-Shopify-Generated-Cart-Token
X-Request-Time
X-Sorting-Hat-PodId
X-PCL
X-Proto
X-Akamai-Request-ID
X-Alternate-Cache-Key
X-Origin
Mn-Server-Ip
X-Shopify-Stage
X-ShopId
X-ShardId
Cache-Tags
X-FW-Dynamic
Origin-Cache-Control
X-Proxy-Cache-Status
Origin-Edge-Control
X-AWS-Id
X-Hosted-By
X-BYPASS-REASON
Node
DB-Nickname
Decoy-Debug-TTL
Decoy-Debug-Status
Ec-Rule-Version
NGX
Decoy-Debug-Key
X-Cluster-Node
Now
X-Hl-Ver
X-Status
X-Akamai-Request-ID2
X-ServerID
X-Time-Microsecs
X-Vgn-Hpd-Reason
X-VWS-Id
X-Viewer-Country
Cache
X-Cache-Control
X-ProxyCache-Status
X-ProxyCache-Key
X-Proxy
X-Pubstack
X-Qloud-Router
X-SaId
Version
X-LJ-Flow-ID
X-Soup
X-Hyper-Cache
X-Yottaa-Metrics
X-JoinUs
X-Yottaa-Optimizations
X-Www-Served-By
Property-Id
X-Redis-Cache
TWC-Connection-Speed
X-Origin-Hint
Healthy
X-BCube-Filmed-By
TWC-Device-Class
X-Say-Cacheable
X-NCache
TWC-GeoIP-LatLong
Webcakes-App-Name
Webcakes-App-Version
Webcakes-Region
X-Web-Node
X-Amzn-Remapped-Content-Length
X-Generated-By
X-SayCDN-TTL
TWC-Locale-Group
TWC-Privacy
TWC-GeoIP-Country
X-Say-TTL
X-Storage
X-Debug-Cache
X-MP-GENERATED-AT
X-TNCMS
X-Varnish-Hits
X-CCM
X-Human
X-Loop
Cross-Origin-Window-Policy
X-FB-TRIP-ID
X-Generated
S-Rt
X-Akamai-Transformed
X-Xfnlog-Site
X-Locale
X-R9-Blue-Green-Version
X-Site-Version
X-RateLimit-Limit
X-RCS-CacheZone
X-IP
X-Rule
X-Detected-As
X-Cache-Host
X-Unique-Id
X-VCache
Cache-Key
X-Drupal-Cache-Tags
L5d-Success-Class
X-Whom
X-CS
Webserver
X-UA-Device-Type
X-NGENIX-Cache
X-Daa-Tunnel
Cache-Name
Time
X-Forwarded-Host
X-VHOST
Viewport
Uber-Trace-Id
X-Mode
X-UnsetCookies
X-Backend-TTL
X-Info
Content-Disposition
Rt-Fastcgi-Cache
X-CDN-Forward
X-Origin-CC
Accept-Language
X-Origin-TTL
X-B3-Spanid
X-Varnish-Cache-Hits
Mime-Version
X-PERF
X-ApacheServer
Country
Section-Io-Cache
X-Cache-Remote
X-Newrelic-Synthetics
ServedBy
Odigeo-Trace-Id
X-From
X-Magnolia-Registration
X-CLOUD-TRACE-CONTEXT
X-Device-Type
X-Cluster-Name
X-EC-Lua
X-Proxied
X-Routing-Service
X-Zipkin-Id
X-Drupal-Cache-Contexts
X-Via-Fastly
X-Ttl
X-Uri
X-Microcachable
X-Geo
Proxy-Connection
X-TT-TIMESTAMP
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
Cf-Ipcountry
X-Nc
HitType
Ohc-File-Size
Access-Control-Request-Headers
Apple-News-Services-Host
Meta-Geo-Continent
MD5-Digest
Mobile-Detection-Method
Rendered-Blocks
Viewtype
T-Server
Machine
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
AsisCache
BehaviorPad-Version
Apple-News-Services-Handled
Content-Script-Type
Content-Style-Type
GEO-REGION-INFO
Fastcgi-X-Cache-Version
VivaBuild
X-Connection-Hash
X-S-Cookie
X-ScT
X-Session-Fingerprint
X-Sigma
X-S
X-Rojux
X-Request-UUID
X-Rewrite-Enabled
X-Rocket-Build-Number
X-Sigma-Backend
X-SRCache-Key
X-VG-WebCache
X-VG-WebServer
X-Vtex-Processado-Em
X-Vtex-Remote-Cache
X-VG-TLSProxy
X-Vdms-Version
X-Transaction
X-Trv-Group
X-Twitter-Response-Tags
X-Region-Sid
X-GeoIP-Country-Code
X-A-Wwc
X-Accel-Expires-Debug
X-Aed
X-Application
X-A-Dgt
X-A-Dcw
X-A
X-A-Ccd
X-A-Dam
X-ARC
X-B-Cookie
X-DPWN-IS-SECURE
X-External-Request-Id
X-G
X-Geo-Header
X-Destination
X-Date
X-CF-Lambda-Fn
X-CF-Lambda-Version
Xc-Version
W
X-D
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-Varnish-Beresp-Ttl
Filterid
X-Real-IP
X-C
Server-Cache-Control
X-CGP
X-No-Session
X-Clientip
Geo-Info
Gh-Request-Id
X-Cache-Time
Locid
X-Rebelmouse-Surrogate-Control
X-SIPLIST1
X-Eu-Site
Countrycode
Fastly-Soc-X-Request-Id
Environment
X-Distil-CS
X-Logging-Id
Server-Surrogate-Control
IsBot
CDCHOST
Powered-By
X-Contensis-Viewer-Groups
Fastly-SWR
X-CUA
X-Rebelmouse-Cache-Control
X-Thanos
X-Hit
X-App-Name
X-Auto-Login
X-VC-Cache
X-WebServer
X-Wikidot-Backend
X-Agile
X-Agile-Id
Ha-Gx-Prefs
X-Wikidot-Static-Cache
X-Agile-Age
X-Varnish-Authentication
X-Cache-Debug
X-Developers
X-TrackingId
HA-Ipaddr
Fastly-SIE
X-Cache-ASPX
X-Tumblr-Pixel-3
X-Bip
User-Cache-Control
Fastly-SSL
X-Edge-Location
X-GoCache-CacheStatus
X-PHP-Host
X-UPSTREAM-Address
X-Labrador-Cache-Channel
X-Fetched-On
X-Generated-In
X-Generation-Time
X-Gamma-Serve
X-FW-Version
X-Epic-Correlation-Id
X-Fastly-Cache
X-Distributor
X-Clara-WADP
X-Cache-Info
X-Cache-Tags
X-Cache-URL
X-BBXSRF
X-Azure-Ref
X-Air-Hostname
X-AK-Request-ID
X-Cdn-Srv
X-GeoIP-City
X-Debug-Cache-Store
X-Debug-Cookies
X-Debug-Log
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-Cms-Context
X-Core-Mission
X-Dispatcher-Server
X-Ms-Request-Id
X-Swa-Ws
X-TH-Server
X-Trace-Id
X-TT-LOGID
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-RateLimit-Remaining-Second
X-Request-URI
X-Server-W
X-Servername
X-Up
X-Urbn-Context-Path
X-Webstats-RespID
X-Backend-State
X-Cache-Expired-At
X-Var-Ttl
X-We-Are-Hiring
X-WADP-Cache
X-Urbn-Site-Id
X-Variation
X-VServer
X-RateLimit-Limit-Second
X-Proxy-Upstream
X-JWT-State
X-Li-Fabric
X-Li-Pop
X-LI-Proto
X-Is-Gdpr
X-Irp-Debug
X-Hash
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-Instart-Isnd
X-LI-UUID
X-Micro-Cache
X-Origin-Expires
X-OVcl-Cache
X-Owner
X-Platform-Server
X-Origin-Date
X-NX-Host
X-Ms-Version
X-Nginx-Cache-Key
X-NodeID
X-Has-Esi
X-OVcl
Heartbleed
IBM-Web2-Location
Platform
True-Client-Country-4JS
Server-Int
Is-Eu
We-Hiring
AKAMAI
Mail-Subject
Locale
Request-EU
Kp-EeAlive
V-Age
Group
Cache-Host
Cdncip
Request-Country
RNT-Time
RNT-Machine
Server-ID
Cdnsip
Adler-Geo
Memcached
Ohc-Cache-HIT
Country-Code
X-COUNTRY
X-Gen-Mode
X-Trafficlayer-App-Name
X-Trafficlayer-App-Version
X-Trafficlayer-App-Scope
PFcat
Fastly-Backend-Name
Cache-Hits
X-NU-AKA-ACS-Version
FNAC-ModuleRouting
X-Req
X-Render-Time
X-Reboot
ServerName
X-Service
X-Hnp-Log
X-Level-Front-Cache
X-Matched-Rule
X-ServiceProvider
X-Generated-On
X-Thinkindot-L3
Wxu-Next-Hostname
Thinkindot-CacheControl-Type
X-Core-Value
X-Cache-Bucket
Wxu-Next-Commit
X-TA-CDN-Provider
Web-Mar-Node
Thinkindot-Control
X-Block-Status
Thinkindot-CacheControl
Wxu-Next-Region
Server-Host
Pragrma
X-Cache-Backend
X-Nginx-Cache
S-Cnection
X-S-Maxage
X-User
X-Old-Content-Length
X-SERVER
X-App-Version
X-Internal-Host
RequestId
X-Response-By
X-Lb-Id
X-Refresh
X-Ruxit-Js-Agent
X-CSRF-TOKEN
X-Wa
Powered-By-ChinaCache
X-Key
X-Sucuri-Cache
X-Sucuri-ID
X-Tec-Api-Root
X-Varnish-Cacheable
X-Tec-Api-Origin
X-NC
X-Location
X-Parent-Response-Time
X-Tec-Api-Version
X-Tb-Optimization-Total-Bytes-Saved
Origin
User-Agent
X-Developer
X-Pjax-Url
X-Cdn-Forward
X-Pf-Uncompressing
X-BACKEND-TTL
X-CF-Powered-By
X-Ua
ProcessTime
X-Oss-Storage-Class
X-B3-Parentspanid
X-CSRF-Token
X-Oss-Object-Type
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-LAGOON
X-Cache-Grace
X-Sn-Servicetimems
X-Node-Id
X-Ocache
X-Cdn-Origin
X-Device-Os
X-Via-CDN
X-NWS-UUID-VERIFY
Memory
Geoip-Latitude
Geoip-City
SRV
X-Cache-Status-Check
PICS-Label
TTL
On-Server
Hostname
X-Correlation-ID
X-Server-IP
X-MSEdge-Flight
X-FORWARDED-FOR
GeoIp-Country-Code
X-NGINX-Cache
A
X-Vcl-Version
X-MSEdge-Features
X-TIME
X-Unique-ID
XServer
X-Request-Host
X-B3-SpanId
X-Litespeed-Cache
Cloudfront-Viewer-Country
X-Webkit-CSP
X-Servedbyhost
X-Varnish-Ttl
Media-Length
X-Cdn-Request-ID
M-TraceId
X-Oneagent-Js-Injection
X-Varnish-URL
X-Rocket-Nginx-Bypass
X-HS-Status
Tcn
Dnion-Transfer-Encoding
SN
Resin-Trace
Host-ID
X-Via-Ucdn
Cdn
X-Ratelimit-Remaining
X-Beluga-Record
X-Beluga-Trace
Who
X-Cache-Ttl
X-Beluga-Response-Time
X-ServedByHost
X-Beluga-Status
X-Beluga-Cache-Status
X-Beluga-Node
HostName
CACHE
X-Sucuri-Id
X-AIR-PT
X-Slack-Backend
X-Action
X-Reqid
X-Fastly-Country-Code
Esi-Enabled
X-Planisys-CDN-TTL
Arc-Country
MIME-Version
X-RPS
X-RPM
Pramga
X-Cache-FS-Status
X-Server-Time
X-Processor
X-PAYTM-SRV-ID
X-Dispatch
X-DW
X-RSL
X-Planisys-CDN-Cache
X-VCL-Version
X-Policy
GeoIP-Country-Code
X-Planisys-CDN-Rules
X-DB
X-DSS
X-DI
Trailer
CF-Cached-On
X-Flog
X-ND-Cache
X-ABtesting
X-Hello
Ttl
Pics-Label
X-Request-Start
X-Skip-Cache
X-Azure-Ref-OriginShield
X-LiteSpeed-Cache-Control
X-Oracle-Dms-Rid
X-SRV
GeoIP-Latitude
X-Varnish-Url
NtCoent-Length
Rt-Proxy-Cache
Fastly-Drupal-HTML
X-Served-From
X-Edge-Server
Cdn-Request-Time
Cdn-Host
X-VarnishDD-TTL
GeoIP-City
X-DC
Section-Origin-Responded
X-Fastly-Backend-Reqs
X-FPC
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
X-Ratelimit-Limit
X-Newrelic-App-Data
Section-Io-Id
X-APP
N-Cache
X-DevSite-Last-Modified
X-Bc-Bl
X-PJAX-URL
X-PF-Uncompressing
X-Swift-Error
X-HostName
X-Backend-Host
Magicmarker
X-Method
WebServer
X-Zone
Amp-Access-Control-Allow-Source-Origin
X-Bc
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
X-Dynatrace
X-BC
Cteonnt-Length
X-ZONE
Processtime
X-BE
Fusion-Deployment-Id
X-Adobe-Source
Servername
X-Dynatrace-Js-Agent
CDN
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
X-LB-ID
FSS-Cache
X-ID
Cache-Cookie-Set-From
FSS-Proxy
X-Fmm-Version
Cache-Provider
X-WA
X-Frame-Option
X-WR-MODIFICATION
X-Svr
Dynatrace
X-Snapshot-Date
Requestid
X-Be
Ohc-Response-Time
X-Scheme
CF-IPCountry
X-StackifyID
X-Branch-Name
X-CACHE-AGE
X-Ftr-Cache-Host
X-Fpc
X-Tid
X-Aicache-OS
X-Apw-Hits
WZWS-RAY
X-Cc-Via
X-Apw-Access-Object
X-SB
X-VC
X-Apw-Access-Action
Vix-Hermes-Req-Id
X-Request-Url
V-Cache
X-Fastly-Cache-Hits
Warning
X-App
X-Cc-Req-Id
D-Cc-Upstream
Lfy
X-Apw-Access-Token
X-Litespeed-Cache-Control
Load-Balancing
X-Node-ID
Backend-Name
X-Worker
Correlation-Id
X-Cache-Id
X-Esi-Check
X-Compress-Hint
X-Fastly-Cache-Status
Lb
CloudFront-Viewer-Country
X-ElasticPress-Search
Pagetype
X-Powered-Y
X-Request-URL
Proxy-Firewall
X-Varnish-Beresp-TTL
WP-Super-Cache
X-Check-Cacheable
X-WPE-Loopback-Upstream-Addr
Cneonction