Threat Level: green Handler on Duty: Renato Marinho

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
CF-RAY
Link
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-UA-Compatible
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Cache-Status
X-Generator
Content-Security-Policy-Report-Only
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-Request-ID
X-Template
X-Language
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Iinfo
X-AspNetMvc-Version
X-Ua-Compatible
X-FRAME-OPTIONS
X-Buckets
Status
X-Content-Security-Policy
X-CDN
Upgrade
Content-Encoding
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Xss-Protection
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
Xkey
X-Pass-Why
X-Cache-Group
X-AH-Environment
P3p
X-Envoy-Upstream-Service-Time
X-Backend
CF-Ray
X-Age
X-Via
X-Server
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Server-Powered-By
X-Page-Speed
X-Pingback
EagleId
X-Ws-Request-Id
X-Proxy-Cache
X-Nginx-Cache-Status
X-UA-Device
X-Hacker
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
Grace
Cf-Railgun
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-Amz-Version-Id
X-Dns-Prefetch-Control
X-LiteSpeed-Cache
Report-To
X-Rq
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Server-Id
X-WebKit-CSP
X-Host
X-Device
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Origin-Cache
X-Response-Time
Content-Location
X-Node
X-Ac
Surrogate-Control
X-Vhost
X-Readtime
Request-Id
X-Backend-Server
X-Dispatcher
X-Cloud-Trace-Context
X-Origin-Upstream-Status
X-Cnection
X-HW
X-Application-Context
X-ORACLE-DMS-ECID
Fusion-Component-Id
Fusion-Content-Id
Fusion-Template-Id
Fusion-Source
Fusion-Content-Source
X-DataDome
X-ORACLE-DMS-RID
X-Cache-Lookup
X-Mod-Pagespeed
NEL
Rating
Edge-Control
X-Rack-Cache
X-Country
X-Akam-SW-Version
X-Clacks-Overhead
Pinterest-Generated-By
X-Ruxit-JS-Agent
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Allow
X-DynaTrace
X-Country-Code
Accept-Ch
X-Instart-Request-ID
X-Varnish-TTL
X-Goog-Hash
X-PC
X-TtlSet
X-Vname
X-FTR-Request-ID
X-TTL
X-ESI
Verso
Accept-Ch-Lifetime
X-Powered-By-Plesk
X-Url
Service-Worker-Allowed
Content-MD5
X-B3-TraceId
X-Version
X-Forwarded-Proto
X-MS-InvokeApp
X-GitHub-Request-Id
X-Cdn-Fetch
X-Kinja
X-Kinja-Build
X-Kinja-Revision
X-Use-Magma
X-GoogleNews-Bot
X-Exp-Id
X-Exp-Variant
X-Kinja-Server
Edge-Cache-Tag
RTSS
Ar-Sid
AR-Request-ID
AR-CACHE
AR-PoweredBy
AR-ATIME
X-Px
X-D2id
X-Debug
X-Abt-Application-Version
X-Server-Name
X-Vcache
SPRequestGuid
Charset
X-NF-Request-ID
X-Amz-Server-Side-Encryption
X-Accel-Expires
X-Cached
X-MSEdge-Ref
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Amz-Rid
X-Fastcgi-Cache
Pagespeed
X-Sol
Display
Response
X-Middleton-Display
X-Middleton-Response
X-Powered-CMS
Arr-Disable-Session-Affinity
X-Vcap-Request-Id
X-Navigation-Version
Pinterest-Version
X-Pinterest-Rid
TCN
X-SharePointHealthScore
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Trace
X-VARITI-CCR
Realpath
Public-Key-Pins
X-Client-IP
Cache-Tag
X-Cdn
Access-Control-Request-Method
X-Fastly-Request-ID
X-Ser
MS-Author-Via
S
X-DynaTrace-JS-Agent
X-Upstream
X-Shard
Nel
X-Id
SPRequestDuration
SPIisLatency
Nginx-Cache
X-Ezoic-Cdn
X-B3-TraceId-Primal
MRF-Tech
Mrf-Cache-Status
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
X-Hp-Webp
X-Content-Type
X-Forwarded-For
X-Amzn-Trace-Id
X-T
X-Amz-Meta-S3cmd-Attrs
X-Grace
DynaTrace
X-Recruiting
Front-End-Https
X-Hits
Fastcgi-Cache
X-Varnish-Age
X-Edge-O15-RID
X-Aspnet-Version
ServerID
X-DIS-Request-ID
X-Dw-Request-Base-Id
MicrosoftSharePointTeamServices
X-Mobile-URL
X-Element-Page-Cache
X-Node-Name
X-Server-ID
NR-ENABLED
X-Content-Digest
X-Cache-TTL
X-HS-Hub-Id
X-FTR-Expires
X-FTR-Cache-Status
X-Country-Code-Real
X-HS-Combine-CSS
X-HS-Cache-Config
X-HS-Content-Id
X-Frontend
Powered
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-Goog-Generation
X-GUploader-UploadID
X-Goog-Storage-Class
X-FTR-Backend
X-FTR-DC
X-FTR-Backend-Server
X-FTR-Realm
X-FTR-Balancer
Server-Name
Alternate-Protocol
TP-L2-Cache
TP-Cache
Server-Node
X-Logged-In
X-Jurisdiction
X-Correlation-Id
X-XRDS-LOCATION
X-Request-Processing-Time
X-Request-Received
AMP-Access-Control-Allow-Source-Origin
X-Microsite
X-Request-Handler-Origin-Region
Backend-Timing
Upgrade-Insecure-Requests
X-ATS-Timestamp
X-Webkit-Csp
X-Content-Options
X-Page-Id
X-Amz-Apigw-Id
X-Amzn-RequestId
Refresh
X-Content-Security-Policy-Report-Only
X-Origin-Server
X-Cache-Hit
X-User-Agent
X-Akamai-Edgescape
X-F-Cache
X-Rid
X-Revision
X-Varnish-Grace
X-Type
X-Shield-Request-Id
Fastly-Restarts
X-XRDS-Location
X-Zen-Fury
X-Content-Powered-By
X-Webapp-Samesite-None-Activated-N
X-B3-Sampled
X-LB-Cache
X-Geo-Country
X-CST
X-B
X-Activity-Id
X-AppVersion
X-Az
X-N
X-URL
X-FTR-Cache-Host
X-Pad
PB-RID
PB-PID
X-Kinsta-Cache
X-Mobile-Rewrite
Arc-Version
Cache-Status
X-Analytics
X-RateLimit-Remaining
X-TT
X-Debug-Info
X-AOL-HN
X-WebKit-CSP-Report-Only
X-Instance
X-Time
X-Cache-Age
X-Tumblr-User
Actual-Object-TTL
X-B-Cache
X-Request-Guid
X-Jobs
X-App-Environment
X-Tumblr-Pixel
Paypal-Debug-Id
X-Framework
DC
X-Tumblr-Pixel-0
X-Signature
X-Ruxit-Js-Agent
Access-Control-Allow-Method
X-FB-Debug
X-PHP-Backend
X-Cache-Action
X-Load-Cache
X-Git-Hash
X-Cached-By
X-Varnish-Backend
Surrogate-Key
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
Fastcgi-Useragent
X-Tt-Trace-Tag
Host-Header
X-Ttl
FilterID
X-Amz-Replication-Status
X-IPLB-Instance
X-Tt-Trace-Host
X-Contextid
MS-CV
X-SS-Set-Cookie
X-ATG-Version
X-Cluster
Tracecode
X-WA-Info
X-Accel-Buffering
X-Srv
NGB
X-Response-Served-From
Frame-Options
WPE-Backend
X-Mobile
Xserver
Payment
X-Cache-NE
X-Cache-Key
X-Varnish-Server
X-FW-Server
X-Region
Host
X-Kong-Upstream-Latency
X-Host-Name
X-Kong-Proxy-Latency
X-Cache-2
Eomportal-Instance
X-FW-Static
X-FW-Hash
X-FW-Type
X-FW-Serve
X-Cacheable-TTL
X-Cache-Enabled
X-Varnish-Hostname
X-Cache-Rule
X-Cache-Operation
Cache-Tv-Group
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
X-IPS-LoggedIn
Source
X-Is-Bot
X-Rendered-As
Filters
X-GeoIP
X-Adobe-Loc
X-Adobe-Content
X-Presslabs-Stats
X-TX-ID
X-EdgeConnect-Cache-Status
X-RequestSource
X-NewRelic-App-Data
X-Via-JSL
X-ORACLE-APMCS-TAG
X-Hostname
X-ORACLE-APMCS-REQUEST-ID
X-Origin-Response-Time
X-Seen-By
Cleartype
X-Oneagent-Js-Injection
X-Cache-TTL-Remaining
Cache
Retry-After
X-FastCGI-Cache
Server-Info
X-VCache
X-ProcessESI
X-UA
X-HTML-Minification-Powered-By
X-RemovedCookies
X-NWS-LOG-UUID
Accept-CH
X-Dc
Healthy
Datacenter
X-Cache-Control
X-RTag
Liferay-Portal
Ms-Operation-Id
X-B3-Traceid
X-CACHE-KEY
X-Source
X-Environment-Context
X-RateLimit-Limit
X-L-Path
X-FireWall-Port
X-Endurance-Cache-Level
X-Cache-Server
From-Origin
X-Upgrade-Enabled
X-Trafficlayer-App-Scope
X-Trafficlayer-App-Name
X-Rule
Version
X-Status
X-Wix-Request-Id
X-CLOUD-TRACE-CONTEXT
X-App-Server
X-Handled-By
X-PressLabs-Stats
X-APP-VERSION
Accept-CH-Lifetime
X-ES-SERVER
X-Path-Route
X-Backend-Name
Meta-Geo
X-RN-RSRV
X-Cache-Var
X-Cache-Var-Map
X-Section
Selected-Fe
OT-Force-Account-Verify
X-Format
X-Proxy-Build
X-Tb
X-Timing-Wait
X-Access
X-Request-Time
Azure-SlotName
Azure-RegionName
Azure-SiteName
Azure-InstanceId
Azure-Version
X-ProxyCache-Status
X-Akamai-Request-ID
X-Storage
Cache-Tags
X-BYPASS-REASON
Mn-Server-Ip
X-Alternate-Cache-Key
X-ProxyCache-Key
X-Proto
X-Shopify-Stage
X-Shopify-Generated-Cart-Token
X-EIG-Tracking-Id
X-Origin
X-Content-Age
X-Goog-Meta-Goog-Reserved-File-Mtime
X-OCL
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-ShardId
X-ShopId
X-PCL
X-Human
Akamai-GRN
Decoy-Debug-TTL
X-UUID
X-Web-Node
X-LJ-Flow-ID
X-FW-Dynamic
X-Time-Microsecs
Ec-Rule-Version
X-FC-Vary-Parameters
X-JoinUs
X-Generated-By
Decoy-Debug-Key
X-Hosted-By
DB-Nickname
X-Hl-Ver
X-Hyper-Cache
X-Vgn-Hpd-Reason
X-MP-GENERATED-AT
X-Viewer-Country
X-Soup
X-ServerID
X-Pubstack
X-Qloud-Router
X-Redis-Cache
X-Proxy-Cache-Status
X-Cache-Config
X-SaId
X-Cache-Host
X-VWS-Id
X-AWS-Id
X-Cluster-Node
Origin-Cache-Control
Now
Node
NGX
Origin-Edge-Control
X-Proxy
X-Akamai-Request-ID2
X-Debug-Cache
S-Rt
X-NYM-Debug-Backend
Decoy-Debug-Status
X-Yottaa-Metrics
GEO-INFO
X-Yottaa-Optimizations
X-IP
TWC-Locale-Group
X-Locale
X-Origin-Hint
TWC-Connection-Speed
TWC-Privacy
X-BCube-Filmed-By
X-Generated
TWC-GeoIP-Country
TWC-Device-Class
TWC-GeoIP-LatLong
Property-Id
X-Site-Version
Webcakes-App-Version
Webcakes-App-Name
X-Say-TTL
X-Say-Cacheable
X-CCM
X-SayCDN-TTL
X-Varnish-Hits
Cross-Origin-Window-Policy
X-Www-Served-By
X-RCS-CacheZone
X-Detected-As
Webcakes-Region
X-Amzn-Remapped-Content-Length
X-Loop
X-FB-TRIP-ID
X-Xfnlog-Site
X-TNCMS
X-R9-Blue-Green-Version
Accept-Charset
L5d-Success-Class
X-Akamai-Transformed
X-CS
Cache-Name
Uber-Trace-Id
Viewport
Srv
X-NCache
X-Drupal-Cache-Tags
X-Unique-Id
Webserver
Time
X-UA-Device-Type
X-Esi
X-Cache-Remote
Cache-Key
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
Mime-Version
X-From
X-Cluster-Name
X-Mode
X-Drupal-Cache-Contexts
X-Origin-CC
X-Origin-TTL
Accept-Language
X-Backend-TTL
X-TT-TIMESTAMP
X-CDN-Forward
Country
X-Edge-Location
X-Forwarded-Host
Odigeo-Trace-Id
Rt-Fastcgi-Cache
X-EC-Lua
X-Microcachable
X-UnsetCookies
X-Info
X-Whom
X-B3-Spanid
X-Varnish-Cache-Hits
X-Geo
X-Newrelic-Synthetics
X-PERF
X-Magnolia-Registration
X-ApacheServer
Proxy-Connection
Content-Disposition
ServedBy
X-TA-CDN-Provider
Ohc-File-Size
X-No-Session
Ohc-Cache-HIT
X-UPSTREAM-Address
X-NGENIX-Cache
X-Device-Type
X-Proxied
X-Routing-Service
X-Zipkin-Id
X-Via-Fastly
X-PHP-Host
X-Labrador-Cache-Channel
Content-Style-Type
Fastcgi-X-Cache-Version
Content-Script-Type
Rendered-Blocks
X-G
VivaBuild
X-B-Cookie
X-Date
X-External-Request-Id
X-ARC
GEO-REGION-INFO
X-D
X-GeoIP-Country-Code
X-Geo-Header
X-Connection-Hash
X-CF-Lambda-Fn
Apple-News-Services-Host
Apple-News-Services-Request-Url
X-Uri
Apple-News-Services-Parsed-Url
AsisCache
MD5-Digest
Meta-Geo-Continent
Mobile-Detection-Method
Machine
X-CF-Lambda-Version
X-DPWN-IS-SECURE
X-Application
Apple-News-Services-Handled
BehaviorPad-Version
X-Destination
X-Rojux
X-Vtex-Processado-Em
X-VG-WebServer
X-Accel-Expires-Debug
X-VG-WebCache
X-SRCache-Key
X-Vtex-Remote-Cache
X-ScT
X-Session-Fingerprint
X-Sigma
X-A-Ccd
X-Daa-Tunnel
X-VG-TLSProxy
X-A-Dcw
X-A
X-Twitter-Response-Tags
X-A-Dam
X-Trv-Group
X-Transaction
X-A-Wwc
T-Server
X-Vdms-Version
X-A-Dgt
X-S-Cookie
X-Sigma-Backend
X-Aed
X-Real-IP
X-Request-UUID
X-Rewrite-Enabled
X-Region-Sid
Viewtype
W
X-Rocket-Build-Number
X-S
Xc-Version
X-Cache-Time
X-C
Cf-Ipcountry
User-Cache-Control
X-Varnish-Authentication
X-VC-Cache
X-Contensis-Viewer-Groups
X-Wikidot-Backend
Fastly-Soc-X-Request-Id
X-Developers
X-CUA
X-Wikidot-Static-Cache
X-Distil-CS
IsBot
X-Eu-Site
X-Epic-Correlation-Id
Ha-Gx-Prefs
CDCHOST
Environment
Gh-Request-Id
Fastly-SSL
X-WebServer
HA-Ipaddr
X-TrackingId
X-SIPLIST1
X-CGP
X-Agile
X-Cache-Debug
Server-Cache-Control
X-Render-Time
X-Backend-State
X-Logging-Id
X-Bip
Powered-By
X-Cache-ASPX
X-Auto-Login
X-Sucuri-Cache
X-Agile-Id
X-App-Name
X-Tumblr-Pixel-3
Locid
X-Hit
X-Thanos
X-Agile-Age
Server-Surrogate-Control
X-Nc
X-GoCache-CacheStatus
HitType
Access-Control-Request-Headers
X-AK-Request-ID
X-Core-Mission
X-Clientip
X-Cache-Info
X-Cache-URL
X-Clara-WADP
X-Cdn-Srv
Web-Mar-Node
X-Cache-Bucket
X-Block-Status
X-Cms-Context
X-Cache-Backend
We-Hiring
X-BBXSRF
X-Nginx-Cache-Key
X-RateLimit-Limit-Second
X-Proxy-Upstream
X-RateLimit-Remaining-Second
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Owner
X-OVcl-Cache
X-NX-Host
X-NodeID
X-Origin-Date
X-Origin-Expires
X-OVcl
X-Request-URI
X-SVT-ORM-RULES
X-VServer
X-User
X-WADP-Cache
X-We-Are-Hiring
X-Webstats-RespID
X-Urbn-Site-Id
X-Urbn-Context-Path
X-Swa-Ws
X-SVT-ORM-VERSION
X-TH-Server
X-Trace-Id
X-TT-LOGID
X-Ms-Version
X-Ms-Request-Id
X-Gamma-Serve
X-FW-Version
X-Gen-Mode
X-Generated-In
X-Generation-Time
X-Fastly-Cache
X-Distributor
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Debug-Cookies
X-Debug-Log
X-Dispatcher-Server
X-GeoIP-City
X-Hash
X-LI-Proto
X-Li-Pop
X-LI-UUID
X-Location
X-Micro-Cache
X-Li-Fabric
X-Key
X-IN-APIGATEWAY
X-Hnp-Log
X-IN-APIGATEWAYSSL
X-Instart-Isnd
X-Irp-Debug
X-Debug-Cache-Expiry
X-Azure-Ref
X-Varnish-Beresp-Ttl
Memcached
AKAMAI
Cache-Host
Request-Country
X-Varnish-Beresp-Status
RNT-Machine
X-Varnish-Beresp-Grace
Heartbleed
Mail-Subject
Cdncip
Fastly-SIE
Kp-EeAlive
Fastly-SWR
IBM-Web2-Location
Fastly-Backend-Name
Locale
Cdnsip
Country-Code
Countrycode
RNT-Time
Request-EU
Server-Int
True-Client-Country-4JS
V-Age
Section-Io-Cache
Server-ID
X-App-Version
Geo-Info
X-Thinkindot-L3
X-Old-Content-Length
X-Fetched-On
X-Trafficlayer-App-Version
X-Up
X-Core-Value
FNAC-ModuleRouting
X-Matched-Rule
X-Variation
X-Server-W
X-ServiceProvider
X-Internal-Host
X-Has-Esi
X-Is-Gdpr
X-Req
X-Level-Front-Cache
ServerName
X-Generated-On
X-Service
X-Platform-Server
X-NU-AKA-ACS-Version
Adler-Geo
X-Reboot
X-JWT-State
X-Cache-Tags
Wxu-Next-Region
Thinkindot-Control
PFcat
Server-Host
Thinkindot-CacheControl
Wxu-Next-Hostname
Thinkindot-CacheControl-Type
Platform
Wxu-Next-Commit
Is-Eu
X-Servername
X-Response-By
X-Refresh
Cache-Hits
X-Nginx-Cache
X-Lb-Id
X-B3-Parentspanid
X-S-Maxage
RequestId
X-SERVER
X-Tb-Optimization-Total-Bytes-Saved
X-Parent-Response-Time
X-B3-SpanId
ProcessTime
X-Air-Hostname
X-CF-Powered-By
X-Cdn-Forward
Filterid
X-Tec-Api-Origin
X-Server-IP
X-CSRF-Token
X-NC
Pragrma
X-Cache-Expired-At
X-Tec-Api-Version
X-Var-Ttl
X-Tec-Api-Root
X-Pjax-Url
Memory
Group
X-CSRF-TOKEN
User-Agent
X-Wa
X-BACKEND-TTL
SRV
S-Cnection
TTL
Media-Length
Geoip-Latitude
Origin
X-Cdn-Request-ID
X-Pf-Uncompressing
Powered-By-ChinaCache
GeoIp-Country-Code
X-Vcl-Version
X-Sucuri-ID
X-Unique-ID
X-Ua
X-NGINX-Cache
X-Correlation-ID
PICS-Label
X-Sucuri-Id
X-Rocket-Nginx-Bypass
X-Varnish-Cacheable
Geoip-City
X-COUNTRY
X-NWS-UUID-VERIFY
SN
X-Reqid
Esi-Enabled
X-Via-CDN
X-AIR-PT
X-HS-Status
X-Developer
X-Litespeed-Cache
Dnion-Transfer-Encoding
X-Webkit-CSP
X-Planisys-CDN-Rules
X-Planisys-CDN-Cache
HostName
X-Planisys-CDN-TTL
X-Policy
X-Servedbyhost
M-TraceId
X-Cdn-Origin
X-LAGOON
X-Ocache
X-Node-Id
X-Azure-Ref-OriginShield
X-Cache-Grace
X-Device-Os
X-Sn-Servicetimems
X-Via-Ucdn
X-Request-Start
X-Varnish-Ttl
XServer
X-TIME
Rt-Proxy-Cache
On-Server
X-FORWARDED-FOR
Tcn
X-MSEdge-Flight
X-MSEdge-Features
Cdn
X-Request-Host
Resin-Trace
X-Fastly-Country-Code
X-ServedByHost
A
Magicmarker
Cloudfront-Viewer-Country
X-Cache-Status-Check
X-Cache-Ttl
X-Method
Who
X-Ftr-Cache-Host
X-VHOST
X-Oss-Request-Id
X-Beluga-Cache-Status
X-Beluga-Trace
X-Beluga-Record
X-Oss-Server-Time
X-Beluga-Node
X-Beluga-Response-Time
X-Beluga-Status
CF-Cached-On
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Oss-Storage-Class
X-APP
Load-Balancing
Pics-Label
Hostname
X-Zone
X-Bc
GeoIP-Country-Code
X-VCL-Version
X-Varnish-Url
Host-ID
DSUID
X-Svr
X-Be
NtCoent-Length
Ohc-Response-Time
X-VarnishDD-TTL
X-VCT
X-MServer
X-Oracle-Dms-Rid
Release
MIME-Version
Ttl
Cteonnt-Length
Vix-Hermes-Req-Id
X-Varnish-URL
X-Fastly-Backend-Reqs
GeoIP-Latitude
X-LiteSpeed-Cache-Control
X-Ratelimit-Remaining
X-Hp-Ccpa-Warning
X-DC
GeoIP-City
X-Slack-Backend
X-Newrelic-App-Data
X-PF-Uncompressing
X-RSL
X-RPS
X-RPM
X-DSS
X-Configured-By
X-DI
Amp-Access-Control-Allow-Source-Origin
X-DB
X-PJAX-URL
WebServer
X-DW
X-Tid
X-Action
X-SRV
X-Ftr-Request-Id
X-HostName
X-Swift-Error
X-Aicache-OS
X-BE
SD-X-WS
X-Dynatrace
Processtime
Pramga
X-SD-PageType
X-Server-Time
X-Upstream-Ht
X-Upstream-Ct
Arc-Country
X-Processor
X-Skip-Cache
X-Dispatch
X-PAYTM-SRV-ID
X-Cache-FS-Status
X-FPC
X-WR-MODIFICATION
CF-IPCountry
X-Ratelimit-Limit
X-Dynatrace-Js-Agent
Servername
X-SN
L
CACHE
X-Cache-Id
X-Hello
X-DevSite-Last-Modified
X-ABtesting
Fastly-Drupal-HTML
X-Flog
X-Compress-Hint
Cache-Provider
X-ND-Cache
X-ID
X-Frame-Option
X-Served-From
X-StackifyID
Cdn-Host
Cdn-Request-Time
N-Cache
X-Edge-Server
Requestid
X-Branch-Name
X-Fastly-Cache-Hits
Pagetype
X-ServerName
X-Ftr-Balancer
CDN
X-Ftr-Backend
X-Release
X-Ftr-Backend-Server
Lfy
X-Snapshot-Date
X-LB-ID
X-Via-NSCOPI
X-Ftr-Realm
Dynatrace
X-Ftr-Dc
X-CACHE-AGE
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
X-Bc-Bl
X-Apw-Access-Action
Proxy-Firewall
X-Apw-Access-Object
X-Varnish-Beresp-TTL
X-Scheme
X-Edge-IP
X-ZONE
X-WA
X-Apw-Access-Token
Warning
D-Cc-Upstream
X-SB
X-Request-Url
V-Cache
LB
X-Cc-Req-Id
X-VC
X-Apw-Hits
X-Cc-Via
WP-Super-Cache
X-Worker
Correlation-Id
X-ElasticPress-Search
Cache-Cookie-Set-Idcheck
X-App
Cache-Cookie-Set-From
X-Node-ID
X-Powered-Y
X-Check-Cacheable
X-BC
X-Fastly-Cache-Status
UCS
Cache-Cookie-Set-Lfrom
X-Request-URL
Backend-Name
Lb