Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-Powered-By
Pragma
CF-Cache-Status
Link
ETag
X-XSS-Protection
Expect-CT
CF-RAY
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Xss-Protection
X-Download-Options
X-AspNet-Version
CF-Ray
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-Request-ID
X-DNS-Prefetch-Control
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
Status
Upgrade
Content-Encoding
X-Content-Security-Policy
X-CDN
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
X-Pass-Why
X-Cache-Group
X-AH-Environment
X-Envoy-Upstream-Service-Time
X-Via
Xkey
X-Backend
X-Server
X-Age
X-Ua-Compatible
X-Ws-Request-Id
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
EagleId
X-Page-Speed
X-Server-Powered-By
X-Pingback
X-Proxy-Cache
X-Hacker
X-Nginx-Cache-Status
Request-Context
Feature-Policy
Server-Timing
X-UA-Device
X-Varnish-Cache
X-Swift-CacheTime
X-Swift-SaveTime
Cf-Railgun
Ali-Swift-Global-Savetime
Grace
X-Amz-Version-Id
Report-To
X-LiteSpeed-Cache
X-Rq
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-OneAgent-JS-Injection
X-Device
X-WebKit-CSP
X-Server-Id
X-Host
X-Origin-Cache
X-Response-Time
EagleEye-TraceId
X-Node
X-Ac
Surrogate-Control
Content-Location
X-Cloud-Trace-Context
X-Vhost
X-Backend-Server
X-Readtime
X-Dispatcher
Request-Id
X-Cache-Lookup
X-Origin-Upstream-Status
X-Ruxit-JS-Agent
X-Cnection
X-Application-Context
X-HW
Fusion-Source
Fusion-Template-Id
Fusion-Component-Id
Fusion-Content-Source
Fusion-Content-Id
X-ORACLE-DMS-ECID
NEL
X-Mod-Pagespeed
X-ORACLE-DMS-RID
X-DataDome
X-Rack-Cache
X-Country
X-Clacks-Overhead
Edge-Control
X-Akam-SW-Version
P3p
Rating
X-Dns-Prefetch-Control
Allow
Pinterest-Generated-By
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Accept-Ch
X-Country-Code
X-FTR-Request-ID
X-Instart-Request-ID
X-Varnish-TTL
X-TTL
X-DynaTrace
X-Vname
X-Goog-Hash
X-PC
X-TtlSet
Content-MD5
X-ESI
Verso
Accept-Ch-Lifetime
Service-Worker-Allowed
X-Url
X-Powered-By-Plesk
X-Vcache
X-B3-TraceId
X-Cdn-Fetch
X-GitHub-Request-Id
X-Exp-Id
X-Exp-Variant
X-Use-Magma
X-Kinja-Server
X-Kinja-Revision
X-Kinja
X-GoogleNews-Bot
X-Kinja-Build
RTSS
X-Version
X-Forwarded-Proto
X-MS-InvokeApp
X-Server-Name
X-D2id
Edge-Cache-Tag
X-Px
X-Abt-Application-Version
X-Debug
AR-ATIME
AR-CACHE
Ar-Sid
AR-Request-ID
AR-PoweredBy
X-Amz-Server-Side-Encryption
SPRequestGuid
X-Cached
Charset
X-NF-Request-ID
X-Vcap-Request-Id
X-Navigation-Version
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-MSEdge-Ref
X-Amz-Rid
Pagespeed
Display
Response
X-Sol
X-Middleton-Display
X-Middleton-Response
X-Accel-Expires
Arr-Disable-Session-Affinity
X-Fastcgi-Cache
X-Server-ID
X-SharePointHealthScore
X-VARITI-CCR
X-Pinterest-Rid
Pinterest-Version
X-Fastly-Request-ID
TCN
MS-Author-Via
Nginx-Cache
Public-Key-Pins
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Powered-CMS
X-Trace
X-Client-IP
X-Cdn
X-Edge-O15-RID
Realpath
Cache-Tag
X-Ser
Access-Control-Request-Method
X-Content-Type
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
SPRequestDuration
SPIisLatency
X-Amzn-Trace-Id
X-Upstream
X-Grace
X-Shard
X-Hp-Webp
X-Jurisdiction
X-Id
X-Forwarded-For
X-Ezoic-Cdn
X-Cache-TTL
Front-End-Https
S
X-Hits
X-DynaTrace-JS-Agent
X-Amz-Meta-S3cmd-Attrs
X-T
Fastcgi-Cache
Nel
X-Recruiting
DynaTrace
X-Aspnet-Version
X-Element-Page-Cache
X-Node-Name
X-Dw-Request-Base-Id
X-Content-Digest
X-Varnish-Age
X-FTR-Backend-Server
X-FTR-Backend
X-Country-Code-Real
X-FTR-Balancer
X-FTR-Cache-Status
X-FTR-Expires
X-Mobile-URL
X-FTR-Realm
X-FTR-DC
MicrosoftSharePointTeamServices
ServerID
X-DIS-Request-ID
NR-ENABLED
Server-Node
TP-Cache
TP-L2-Cache
X-HS-Cache-Config
X-HS-Content-Id
X-HS-Combine-CSS
X-Frontend
X-HS-Hub-Id
X-Goog-Metageneration
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Storage-Class
X-Logged-In
Powered
X-CST
X-Correlation-Id
Alternate-Protocol
Server-Name
Upgrade-Insecure-Requests
X-Amzn-RequestId
X-Amz-Apigw-Id
Fastly-Restarts
X-Cache-Hit
X-FTR-Cache-Host
X-Microsite
X-Request-Handler-Origin-Region
X-XRDS-Location
X-ATS-Timestamp
Backend-Timing
X-Page-Id
AMP-Access-Control-Allow-Source-Origin
X-User-Agent
X-Request-Received
X-Request-Processing-Time
X-Zen-Fury
X-Content-Options
X-F-Cache
Refresh
X-Content-Security-Policy-Report-Only
X-Origin-Server
X-Akamai-Edgescape
X-Varnish-Grace
X-Rid
X-XRDS-LOCATION
X-LB-Cache
X-Revision
X-B
PB-PID
X-Content-Powered-By
PB-RID
X-Mobile-Rewrite
Arc-Version
X-Type
X-Webkit-Csp
X-B3-Sampled
Cache-Status
X-AppVersion
X-Activity-Id
X-Geo-Country
X-Az
X-Kinsta-Cache
X-NWS-LOG-UUID
X-N
X-Cache-Action
X-TT
X-AOL-HN
X-Signature
X-Request-Guid
X-B-Cache
X-Debug-Info
X-Framework
X-Jobs
Access-Control-Allow-Method
X-WebKit-CSP-Report-Only
X-Instance
X-Cache-Age
X-PHP-Backend
X-Time
X-FB-Debug
Actual-Object-TTL
X-App-Environment
X-Cached-By
Paypal-Debug-Id
X-Git-Hash
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel
X-Load-Cache
X-Tt-Trace-Host
X-Tt-Trace-Tag
Fastcgi-Useragent
X-Amz-Replication-Status
X-URL
DC
X-Pad
X-Varnish-Backend
X-Shield-Request-Id
X-RateLimit-Remaining
Host-Header
Host
X-WA-Info
X-ATG-Version
X-ORACLE-APMCS-TAG
X-ORACLE-APMCS-REQUEST-ID
Surrogate-Key
MS-CV
X-Via-JSL
X-Contextid
X-IPLB-Instance
X-Mobile
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-Host-Name
Retry-After
Frame-Options
NGB
X-Response-Served-From
X-Accel-Buffering
X-FastCGI-Cache
Payment
Liferay-Portal
X-Cache-Key
Source
X-Cache-NE
X-Srv
X-Seen-By
X-NewRelic-App-Data
X-SS-Set-Cookie
X-Cache-2
X-Varnish-Server
Xserver
X-Origin-Response-Time
X-Region
Eomportal-Instance
X-FW-Type
X-FW-Static
X-GeoIP
X-IPS-LoggedIn
X-FW-Server
X-FW-Serve
Tracecode
WPE-Backend
X-FW-Hash
X-Is-Bot
X-Cacheable-TTL
Filters
X-Rendered-As
X-Cluster
X-Cache-Enabled
X-Adobe-Loc
Cache-Tv-Group
X-Adobe-Content
X-Varnish-Hostname
Server-Info
X-Cache-Rule
X-Cache-Operation
X-RequestSource
X-Tumblr-Pixel-1
X-Hostname
X-Tumblr-Pixel-2
X-App-Server
X-RemovedCookies
X-ProcessESI
X-EdgeConnect-Cache-Status
X-Cache-TTL-Remaining
X-Presslabs-Stats
FilterID
X-TX-ID
X-FireWall-Port
X-Environment-Context
X-L-Path
Cleartype
Accept-CH
X-Analytics
X-B3-Traceid
X-Upgrade-Enabled
X-Handled-By
Ms-Operation-Id
X-RTag
X-Source
X-Endurance-Cache-Level
X-Cache-Server
Srv
X-CACHE-KEY
Accept-Charset
X-HTML-Minification-Powered-By
From-Origin
X-Backend-Name
X-Ttl
X-UA
X-PressLabs-Stats
X-Webapp-Samesite-None-Activated-N
Datacenter
X-Dc
X-UUID
Accept-CH-Lifetime
X-Wix-Request-Id
Healthy
X-Daa-Tunnel
Meta-Geo
X-ES-SERVER
X-RN-RSRV
X-Cache-Var-Map
X-Path-Route
X-Cache-Var
X-Tb
X-Access
X-Status
X-Timing-Wait
X-Proxy-Build
Selected-Fe
OT-Force-Account-Verify
X-Section
X-OCL
X-Sorting-Hat-ShopId
Mn-Server-Ip
X-Shopify-Generated-Cart-Token
X-Format
X-PCL
X-Akamai-Transformed
X-Shopify-Stage
X-Alternate-Cache-Key
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Content-Age
X-EIG-Tracking-Id
X-Sorting-Hat-PodId
Cache-Tags
X-ShopId
X-Akamai-Request-ID
X-ShardId
X-FC-Vary-Parameters
X-Proto
X-Request-Time
X-Cache-Config
X-Yottaa-Optimizations
X-JoinUs
X-Hl-Ver
X-AWS-Id
X-SayCDN-TTL
X-Proxy-Cache-Status
X-Human
X-Say-TTL
X-Qloud-Router
X-Soup
X-ProxyCache-Status
X-SaId
X-ProxyCache-Key
X-Yottaa-Metrics
X-Say-Cacheable
Node
Ec-Rule-Version
Akamai-GRN
X-LJ-Flow-ID
X-NYM-Debug-Backend
Origin-Cache-Control
X-Vgn-Hpd-Reason
Origin-Edge-Control
X-BYPASS-REASON
X-VWS-Id
X-Origin
X-Web-Node
X-Akamai-Request-ID2
X-Debug-Cache
Now
NGX
X-Proxy
X-FB-TRIP-ID
X-Detected-As
X-BCube-Filmed-By
X-CCM
Version
Cross-Origin-Window-Policy
X-Whom
X-Site-Version
X-Hosted-By
Decoy-Debug-TTL
X-FW-Dynamic
Decoy-Debug-Key
X-TNCMS
X-Hyper-Cache
X-Storage
X-Time-Microsecs
X-Viewer-Country
X-Redis-Cache
X-Www-Served-By
Decoy-Debug-Status
X-Loop
X-MP-GENERATED-AT
X-ServerID
X-Generated-By
X-Generated
X-Pubstack
X-Locale
X-APP-VERSION
Webcakes-Region
Azure-Version
Webcakes-App-Version
Webcakes-App-Name
X-Xfnlog-Site
DB-Nickname
Azure-SlotName
Azure-SiteName
TWC-Privacy
X-RCS-CacheZone
X-Origin-Hint
X-Varnish-Hits
X-IP
Azure-RegionName
Azure-InstanceId
X-R9-Blue-Green-Version
TWC-GeoIP-LatLong
S-Rt
Property-Id
TWC-Locale-Group
TWC-Connection-Speed
TWC-Device-Class
X-Ua-Device
TWC-GeoIP-Country
X-NCache
X-Amzn-Remapped-Content-Length
X-Unique-Id
X-Cluster-Node
X-RateLimit-Limit
Cache-Key
X-UA-Device-Type
GEO-INFO
X-Cache-Control
X-Cache-Host
X-Drupal-Cache-Tags
X-NGENIX-Cache
X-Mode
Section-Io-Cache
X-Rule
X-Forwarded-Host
Cache
Webserver
L5d-Success-Class
X-Esi
X-Backend-TTL
Content-Disposition
Time
Cache-Name
Mime-Version
X-UnsetCookies
Viewport
X-Info
X-CDN-Forward
X-CS
X-Newrelic-Synthetics
Accept-Language
X-PERF
X-ApacheServer
X-Varnish-Cache-Hits
Rt-Fastcgi-Cache
X-Origin-CC
ServedBy
X-Origin-TTL
Uber-Trace-Id
Country
X-B3-Spanid
X-Cache-Remote
X-Routing-Service
X-Zipkin-Id
Odigeo-Trace-Id
X-Device-Type
X-Proxied
X-Via-Fastly
Filterid
X-VCache
X-Magnolia-Registration
X-Uri
Geo-Info
X-From
X-CLOUD-TRACE-CONTEXT
Proxy-Connection
X-EC-Lua
X-Cluster-Name
Access-Control-Request-Headers
X-Drupal-Cache-Contexts
X-Real-IP
HitType
Cf-Ipcountry
X-Geo
X-Microcachable
X-TT-TIMESTAMP
X-Nc
X-A
X-A-Ccd
W
X-Rewrite-Enabled
VivaBuild
VIX-Pulpo-Node
X-Request-UUID
X-Rocket-Build-Number
VIX-Pulpo-Upstream-Status
X-A-Dam
Apple-News-Services-Parsed-Url
X-A-Dgt
X-A-Wwc
X-Accel-Expires-Debug
X-S-Cookie
Group
Viewtype
X-S
X-A-Dcw
X-Rojux
X-Region-Sid
X-PHP-Host
X-Labrador-Cache-Channel
X-Cache-Time
Content-Script-Type
BehaviorPad-Version
AsisCache
Apple-News-Services-Host
Apple-News-Services-Handled
Apple-News-Services-Request-Url
Content-Style-Type
Fastcgi-X-Cache-Version
Rendered-Blocks
T-Server
X-GeoIP-Country-Code
X-Geo-Header
Mobile-Detection-Method
Meta-Geo-Continent
GEO-REGION-INFO
Machine
MD5-Digest
X-Varnish-Beresp-Ttl
X-ScT
X-Vdms-Version
X-Twitter-Response-Tags
X-External-Request-Id
X-VG-TLSProxy
X-VG-WebCache
X-SRCache-Key
X-B-Cookie
X-Varnish-Beresp-Status
X-Date
X-Transaction
X-Connection-Hash
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-D
X-Trv-Group
X-ARC
X-VG-WebServer
Xc-Version
X-Application
X-DPWN-IS-SECURE
X-Destination
X-Varnish-Beresp-Grace
X-Aed
X-Vtex-Remote-Cache
X-G
Ohc-File-Size
X-Sigma-Backend
X-Vtex-Processado-Em
X-Session-Fingerprint
X-Sigma
X-App-Version
User-Cache-Control
Cache-Hits
X-C
X-Logging-Id
Fastly-SIE
Environment
X-Developers
CDCHOST
Fastly-Soc-X-Request-Id
X-CUA
X-Var-Ttl
X-Hit
X-Backend-State
X-Bip
X-Cache-Debug
X-App-Name
X-Agile-Id
X-Agile
X-Agile-Age
X-Cache-Expired-At
Powered-By
HA-Ipaddr
Ha-Gx-Prefs
X-Clientip
IsBot
Locid
X-Eu-Site
X-CGP
Fastly-SWR
Countrycode
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-TrackingId
X-Thanos
X-Distil-CS
X-WebServer
X-VC-Cache
X-SIPLIST1
X-GoCache-CacheStatus
Fastly-SSL
Server-Cache-Control
X-Gen-Mode
X-Generated-In
X-Air-Hostname
X-Hash
X-VServer
RNT-Machine
RNT-Time
Web-Mar-Node
We-Hiring
Server-Surrogate-Control
V-Age
True-Client-Country-4JS
Server-Int
Server-ID
X-Request-URI
X-Has-Esi
AKAMAI
X-Fetched-On
X-Variation
X-Up
X-Epic-Correlation-Id
X-Core-Mission
X-Contensis-Viewer-Groups
X-Distributor
X-Debug-Cookies
X-Dispatcher-Server
X-Urbn-Site-Id
X-Urbn-Context-Path
X-Debug-Log
X-Cms-Context
X-Trace-Id
X-Varnish-Authentication
X-SVT-ORM-RULES
X-Wikidot-Backend
X-Azure-Ref
X-SVT-ORM-VERSION
X-Block-Status
X-Cache-Tags
X-TH-Server
X-Swa-Ws
X-Cache-ASPX
X-Auto-Login
X-GeoIP-City
X-LI-Proto
X-Li-Pop
X-Proxy-Upstream
X-LI-UUID
X-Owner
X-Platform-Server
X-Li-Fabric
Gh-Request-Id
Is-Eu
Kp-EeAlive
IBM-Web2-Location
Heartbleed
X-RateLimit-Limit-Second
X-Origin-Expires
Fastly-Backend-Name
X-NodeID
X-Nginx-Cache-Key
Cache-Host
X-No-Session
Adler-Geo
X-Ms-Version
X-Ms-Request-Id
X-OVcl-Cache
X-Origin-Date
X-NX-Host
Country-Code
X-NU-AKA-ACS-Version
Request-EU
Locale
X-Is-Gdpr
X-Instart-Isnd
X-Cdn-Srv
X-RateLimit-Remaining-Second
Mail-Subject
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-Wikidot-Static-Cache
Request-Country
X-Hnp-Log
Pragrma
Platform
X-OVcl
X-JWT-State
Ohc-Cache-HIT
X-Edge-Location
S-Cnection
X-Trafficlayer-App-Version
X-TT-LOGID
X-Webstats-RespID
X-Reboot
X-Cache-URL
X-Tumblr-Pixel-3
X-Trafficlayer-App-Scope
X-Service
X-Cache-Bucket
X-Server-W
X-BBXSRF
X-Servername
Memcached
X-Matched-Rule
X-Trafficlayer-App-Name
X-Irp-Debug
X-Micro-Cache
X-ServiceProvider
X-Fastly-Cache
X-Gamma-Serve
X-Generated-On
X-WADP-Cache
X-Cache-Info
X-Clara-WADP
X-We-Are-Hiring
X-Thinkindot-L3
X-Generation-Time
X-Req
X-FW-Version
X-Level-Front-Cache
X-Debug-Cache-Expiry
Server-Host
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-Nginx-Cache
ServerName
PFcat
FNAC-ModuleRouting
Cdnsip
Cdncip
Wxu-Next-Commit
Thinkindot-Control
X-AK-Request-ID
X-Debug-Cache-Store
X-Core-Value
Wxu-Next-Region
Wxu-Next-Hostname
X-Debug-Cache-Fetch
X-Response-By
X-Old-Content-Length
X-S-Maxage
X-Lb-Id
X-Oss-Object-Type
X-Oss-Storage-Class
X-VHOST
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
X-UPSTREAM-Address
X-Oss-Request-Id
X-Refresh
X-Node-Id
X-Varnish-Cacheable
X-SERVER
RequestId
X-Sucuri-ID
User-Agent
Powered-By-ChinaCache
X-Wa
X-Render-Time
X-NWS-UUID-VERIFY
X-NC
X-Cache-Backend
X-Developer
X-Cache-Status-Check
X-CSRF-TOKEN
X-User
Hostname
X-CF-Powered-By
X-Parent-Response-Time
X-Tec-Api-Origin
X-Cdn-Origin
X-Tec-Api-Root
X-Sn-Servicetimems
X-Pjax-Url
X-LAGOON
X-Key
X-Tec-Api-Version
X-Device-Os
X-Internal-Host
X-Cache-Grace
X-Sucuri-Cache
X-CSRF-Token
X-Ocache
X-Ua
Origin
On-Server
X-Tb-Optimization-Total-Bytes-Saved
X-Pf-Uncompressing
X-Location
A
X-Via-CDN
X-TA-CDN-Provider
Memory
X-BACKEND-TTL
Geoip-City
Geoip-Latitude
X-MSEdge-Features
X-MSEdge-Flight
X-Request-Host
Cloudfront-Viewer-Country
Tcn
X-Cdn-Forward
SRV
ProcessTime
GeoIp-Country-Code
X-B3-Parentspanid
TTL
PICS-Label
X-COUNTRY
X-NGINX-Cache
X-Vcl-Version
X-Unique-ID
X-Varnish-URL
X-Ruxit-Js-Agent
M-TraceId
X-Litespeed-Cache
X-Server-IP
X-Servedbyhost
Resin-Trace
X-Webkit-CSP
X-Oneagent-Js-Injection
X-Rocket-Nginx-Bypass
Dnion-Transfer-Encoding
X-HS-Status
X-Varnish-Ttl
X-TIME
X-B3-SpanId
XServer
Cdn
SN
CACHE
X-Slack-Backend
X-Cdn-Request-ID
Media-Length
X-Dynatrace-Js-Agent
X-Correlation-ID
X-FORWARDED-FOR
X-Cache-FS-Status
X-ServedByHost
Arc-Country
X-Dispatch
X-Processor
Host-ID
X-Server-Time
Pramga
X-PAYTM-SRV-ID
X-Ratelimit-Remaining
X-Fastly-Country-Code
X-Skip-Cache
Who
X-Beluga-Status
X-Beluga-Response-Time
X-ND-Cache
X-Action
X-Beluga-Record
X-Cache-Ttl
X-Beluga-Node
X-Beluga-Trace
X-Beluga-Cache-Status
X-DC
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
Section-Origin-Responded
Section-Io-Id
HostName
Cdn-Host
X-RPM
X-RSL
Cdn-Request-Time
X-DSS
X-Served-From
X-Edge-Server
X-DB
X-DI
X-DW
X-RPS
Fastly-Drupal-HTML
X-VCL-Version
X-Via-Ucdn
Pics-Label
Fusion-Deployment-Id
N-Cache
X-DevSite-Last-Modified
Ttl
GeoIP-Country-Code
X-Reqid
X-Hello
X-AIR-PT
Esi-Enabled
X-Bc-Bl
Amp-Access-Control-Allow-Source-Origin
X-ABtesting
X-Adobe-Source
X-HostName
GeoIP-Latitude
X-Flog
GeoIP-City
X-Oracle-Dms-Rid
MIME-Version
X-LiteSpeed-Cache-Control
NtCoent-Length
X-Sucuri-Id
X-Planisys-CDN-Cache
X-Planisys-CDN-TTL
X-VarnishDD-TTL
X-Policy
X-PF-Uncompressing
X-Varnish-Url
X-Backend-Host
X-Planisys-CDN-Rules
CF-Cached-On
X-Request-Start
Cache-Cookie-Set-From
X-Ratelimit-Limit
X-Azure-Ref-OriginShield
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
X-APP
X-FPC
Trailer
X-Fmm-Version
X-Scheme
X-Fastly-Backend-Reqs
WebServer
X-SRV
X-Zone
X-Bc
Rt-Proxy-Cache
Cteonnt-Length
X-PJAX-URL
X-Dynatrace
X-BC
X-ZONE
X-BE
Processtime
X-WA
X-Amzn-Remapped-Connection
X-Fpc
X-Amzn-Remapped-Date
X-Newrelic-App-Data
X-Swift-Error
Servername
X-Cache-Id
X-Esi-Check
X-SN
X-Method
Magicmarker
FSS-Cache
FSS-Proxy
Cache-Provider
X-ID
X-Frame-Option
X-WR-MODIFICATION
Load-Balancing
X-StackifyID
X-Gzip
Dynatrace
SD-X-WS
CF-IPCountry
X-Cache-NGX
Release
X-SD-PageType
Requestid
X-Snapshot-Date
X-LB-ID
X-Branch-Name
CDN
Sid
Lb
X-CACHE-AGE
X-Tid
V-Cache
Ohc-Response-Time
X-Compress-Hint
WZWS-RAY
X-Fastly-Cache-Hits
X-ECACHE
X-Request-Url
X-Cc-Via
X-Nananana
X-VCT
X-Wix-Viewer-Type
X-Aicache-OS
X-Cc-Req-Id
D-Cc-Upstream
X-Configured-By
X-VC
L
Warning
X-Instart-Info
X-SB
X-Litespeed-Cache-Control
X-Be
X-Apw-Access-Action
X-Svr
X-Check-Cacheable
X-Worker
X-Fastly-Cache-Status
X-ServerName
SID
LB
Inserted-Into-Cache-At
X-Apw-Access-Object
X-Apw-Access-Token
X-Request-URL
X-Powered-Y
X-ElasticPress-Search
WP-Super-Cache
X-GEO
X-Apw-Hits
X-WPE-Loopback-Upstream-Addr
X-Varnish-Beresp-TTL
Cneonction
X-App