Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-Powered-By
Pragma
CF-Cache-Status
X-XSS-Protection
Link
ETag
CF-RAY
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Xss-Protection
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Request-ID
X-Permitted-Cross-Domain-Policies
X-Cacheable
CF-Ray
X-DNS-Prefetch-Control
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
Status
Upgrade
X-Content-Security-Policy
Content-Encoding
X-CDN
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
X-Pass-Why
X-Cache-Group
X-AH-Environment
X-Envoy-Upstream-Service-Time
Xkey
X-Via
X-Backend
X-Server
X-Age
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Ws-Request-Id
X-Server-Powered-By
X-Page-Speed
X-Pingback
EagleId
X-Proxy-Cache
X-Hacker
X-Nginx-Cache-Status
Request-Context
X-UA-Device
Feature-Policy
X-Varnish-Cache
Server-Timing
Cf-Railgun
X-Swift-CacheTime
X-Swift-SaveTime
Grace
Ali-Swift-Global-Savetime
X-Amz-Version-Id
X-Ua-Compatible
Report-To
X-LiteSpeed-Cache
X-Rq
X-OneAgent-JS-Injection
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-WebKit-CSP
X-Device
X-Host
X-Server-Id
X-Origin-Cache
X-Response-Time
EagleEye-TraceId
X-Ac
X-Node
Surrogate-Control
Content-Location
X-Cloud-Trace-Context
X-Backend-Server
X-Readtime
X-Vhost
Request-Id
X-Dispatcher
X-Origin-Upstream-Status
X-Cnection
X-Cache-Lookup
X-Ruxit-JS-Agent
X-Application-Context
X-HW
Fusion-Template-Id
Fusion-Source
Fusion-Content-Source
Fusion-Component-Id
Fusion-Content-Id
P3p
X-ORACLE-DMS-ECID
NEL
X-Mod-Pagespeed
X-ORACLE-DMS-RID
X-DataDome
X-Dns-Prefetch-Control
X-Rack-Cache
Rating
X-Country
X-Clacks-Overhead
Edge-Control
X-Akam-SW-Version
Pinterest-Generated-By
Allow
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-TTL
X-Country-Code
Accept-Ch
X-FTR-Request-ID
X-DynaTrace
X-Instart-Request-ID
X-Varnish-TTL
X-Goog-Hash
X-Vname
X-TtlSet
X-PC
Verso
X-ESI
Content-MD5
Accept-Ch-Lifetime
Service-Worker-Allowed
X-Powered-By-Plesk
X-Url
X-B3-TraceId
X-Forwarded-Proto
X-GitHub-Request-Id
X-Version
X-Exp-Variant
X-GoogleNews-Bot
X-Kinja
X-Vcache
X-Kinja-Build
X-Use-Magma
X-MS-InvokeApp
X-Kinja-Server
X-Kinja-Revision
X-Cdn-Fetch
X-Exp-Id
RTSS
X-Server-Name
Edge-Cache-Tag
X-D2id
X-Debug
X-Abt-Application-Version
AR-PoweredBy
AR-CACHE
AR-Request-ID
Ar-Sid
X-Px
AR-ATIME
X-Amz-Server-Side-Encryption
SPRequestGuid
Charset
X-NF-Request-ID
X-Cached
Display
X-TEC-API-VERSION
X-Middleton-Display
X-Middleton-Response
X-Sol
Response
Pagespeed
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-MSEdge-Ref
X-Navigation-Version
X-Vcap-Request-Id
X-Accel-Expires
X-Fastcgi-Cache
X-Server-ID
Arr-Disable-Session-Affinity
X-Amz-Rid
Pinterest-Version
X-Pinterest-Rid
TCN
X-SharePointHealthScore
X-Powered-CMS
X-VARITI-CCR
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Edge-O15-RID
X-Cdn
Public-Key-Pins
X-Fastly-Request-ID
Cache-Tag
X-Client-IP
X-Trace
Realpath
Nginx-Cache
MS-Author-Via
X-Ser
Access-Control-Request-Method
X-Shard
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
MRF-Tech
X-B3-TraceId-Primal
Mrf-Cache-Status
X-Content-Type
SPIisLatency
SPRequestDuration
X-Amzn-Trace-Id
X-Ezoic-Cdn
X-Id
X-Grace
X-Jurisdiction
X-Hp-Webp
S
X-Upstream
X-DynaTrace-JS-Agent
X-Forwarded-For
X-T
X-Amz-Meta-S3cmd-Attrs
Front-End-Https
Nel
X-Hits
Fastcgi-Cache
X-Recruiting
X-Cache-TTL
DynaTrace
X-Aspnet-Version
X-Varnish-Age
X-Element-Page-Cache
ServerID
X-Content-Digest
X-Node-Name
X-Mobile-URL
MicrosoftSharePointTeamServices
X-FTR-Backend-Server
X-FTR-Balancer
X-FTR-Cache-Status
X-Country-Code-Real
X-FTR-Backend
X-FTR-Expires
X-FTR-DC
X-FTR-Realm
X-Dw-Request-Base-Id
X-DIS-Request-ID
NR-ENABLED
Server-Node
X-HS-Content-Id
X-HS-Combine-CSS
X-HS-Hub-Id
X-HS-Cache-Config
Powered
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Storage-Class
X-Frontend
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
TP-L2-Cache
TP-Cache
X-CST
X-Logged-In
Alternate-Protocol
Server-Name
X-Correlation-Id
X-Amz-Apigw-Id
X-Amzn-RequestId
X-XRDS-Location
AMP-Access-Control-Allow-Source-Origin
Upgrade-Insecure-Requests
X-Request-Received
X-Request-Handler-Origin-Region
X-Microsite
X-Request-Processing-Time
X-Cache-Hit
Fastly-Restarts
X-ATS-Timestamp
Backend-Timing
X-Content-Options
X-Content-Security-Policy-Report-Only
Refresh
X-FTR-Cache-Host
X-Origin-Server
X-F-Cache
X-Zen-Fury
X-User-Agent
X-Akamai-Edgescape
X-Rid
X-Page-Id
X-Revision
X-Varnish-Grace
X-Type
X-Content-Powered-By
X-LB-Cache
X-B
PB-RID
PB-PID
X-XRDS-LOCATION
X-B3-Sampled
X-Mobile-Rewrite
Arc-Version
X-Geo-Country
X-URL
X-Az
X-Activity-Id
X-AppVersion
Cache-Status
X-N
X-Kinsta-Cache
X-Cache-Age
X-TT
X-Cache-Action
X-B-Cache
X-Signature
X-Instance
X-WebKit-CSP-Report-Only
X-AOL-HN
Access-Control-Allow-Method
X-Tumblr-Pixel-0
Paypal-Debug-Id
X-Tumblr-Pixel
X-Tumblr-User
Actual-Object-TTL
X-Time
X-Jobs
X-Framework
X-Debug-Info
X-FB-Debug
X-Cached-By
X-App-Environment
X-Load-Cache
X-Request-Guid
X-Git-Hash
X-PHP-Backend
DC
Fastcgi-Useragent
X-Pad
X-Tt-Trace-Tag
X-Shield-Request-Id
X-Tt-Trace-Host
X-Amz-Replication-Status
X-Webkit-Csp
X-Varnish-Backend
X-RateLimit-Remaining
X-NWS-LOG-UUID
X-IPLB-Instance
Host-Header
Surrogate-Key
MS-CV
X-ATG-Version
X-WA-Info
X-Contextid
Host
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-ORACLE-APMCS-REQUEST-ID
X-ORACLE-APMCS-TAG
X-Via-JSL
X-SS-Set-Cookie
X-Mobile
X-Kong-Upstream-Latency
X-Host-Name
X-Kong-Proxy-Latency
NGB
X-Response-Served-From
X-Accel-Buffering
Payment
Frame-Options
Tracecode
X-Cluster
X-Analytics
X-Cache-NE
Source
Xserver
Eomportal-Instance
X-FW-Hash
X-FW-Static
X-FW-Server
X-FW-Type
X-Origin-Response-Time
X-Region
X-FW-Serve
WPE-Backend
X-Varnish-Server
X-Cache-2
FilterID
X-GeoIP
X-IPS-LoggedIn
X-Varnish-Hostname
Filters
Cache-Tv-Group
X-Tumblr-Pixel-1
X-Tumblr-Pixel-2
X-Webapp-Samesite-None-Activated-N
X-Cache-Key
X-Cacheable-TTL
Retry-After
X-Cache-Enabled
X-Hostname
X-Adobe-Content
X-Adobe-Loc
X-Seen-By
X-Rendered-As
X-Cache-Operation
X-NewRelic-App-Data
X-Srv
X-Is-Bot
X-RequestSource
X-Cache-Rule
X-EdgeConnect-Cache-Status
X-Presslabs-Stats
Server-Info
X-TX-ID
X-FastCGI-Cache
Liferay-Portal
X-RemovedCookies
X-ProcessESI
X-Cache-TTL-Remaining
X-App-Server
Cleartype
Accept-CH
X-B3-Traceid
X-L-Path
X-Environment-Context
X-CACHE-KEY
X-FireWall-Port
X-RTag
Ms-Operation-Id
X-Source
X-Endurance-Cache-Level
X-Handled-By
X-Upgrade-Enabled
X-Dc
Datacenter
X-Cache-Server
From-Origin
X-HTML-Minification-Powered-By
X-UA
X-Backend-Name
Accept-CH-Lifetime
Srv
Accept-Charset
X-PressLabs-Stats
X-ES-SERVER
X-Cache-Var-Map
X-Cache-Var
X-UUID
X-Path-Route
X-RN-RSRV
Meta-Geo
OT-Force-Account-Verify
X-Format
X-Proxy-Build
X-Timing-Wait
X-Access
X-Wix-Request-Id
X-Tb
X-Section
Selected-Fe
X-APP-VERSION
Azure-RegionName
Azure-InstanceId
Akamai-GRN
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Origin
X-EIG-Tracking-Id
X-OCL
X-FC-Vary-Parameters
X-NYM-Debug-Backend
Azure-SiteName
X-Content-Age
X-Sorting-Hat-ShopId
X-ShardId
X-ShopId
X-PCL
X-Alternate-Cache-Key
Azure-SlotName
Mn-Server-Ip
X-Proto
X-Shopify-Stage
X-Shopify-Generated-Cart-Token
X-Request-Time
X-Cache-Config
Azure-Version
X-Akamai-Request-ID
Cache-Tags
X-Sorting-Hat-PodId
X-FW-Dynamic
Origin-Cache-Control
Now
X-AWS-Id
X-Hl-Ver
X-Hosted-By
Origin-Edge-Control
Decoy-Debug-Status
X-Cluster-Node
X-BYPASS-REASON
X-Yottaa-Optimizations
DB-Nickname
Decoy-Debug-Key
NGX
Ec-Rule-Version
Decoy-Debug-TTL
Node
X-Hyper-Cache
X-ProxyCache-Status
X-Vgn-Hpd-Reason
X-LJ-Flow-ID
Version
X-Viewer-Country
X-ProxyCache-Key
X-VWS-Id
X-Cache-Control
X-Proxy-Cache-Status
X-Proxy
Cache
X-Soup
X-Akamai-Request-ID2
X-SaId
X-JoinUs
X-Status
X-Yottaa-Metrics
X-Pubstack
X-Time-Microsecs
X-ServerID
X-Qloud-Router
X-BCube-Filmed-By
Healthy
X-SayCDN-TTL
Property-Id
X-Amzn-Remapped-Content-Length
TWC-Privacy
Webcakes-App-Name
Webcakes-App-Version
X-Redis-Cache
Webcakes-Region
TWC-Locale-Group
TWC-GeoIP-LatLong
Cross-Origin-Window-Policy
X-Say-Cacheable
TWC-Connection-Speed
TWC-Device-Class
TWC-GeoIP-Country
X-Say-TTL
X-Storage
X-Www-Served-By
X-Origin-Hint
X-Generated-By
X-FB-TRIP-ID
X-MP-GENERATED-AT
X-Akamai-Transformed
X-NCache
X-Loop
X-Debug-Cache
X-Web-Node
X-Varnish-Hits
X-Human
X-CCM
X-TNCMS
X-RateLimit-Limit
X-Locale
X-Site-Version
X-Generated
S-Rt
X-Xfnlog-Site
X-R9-Blue-Green-Version
X-RCS-CacheZone
GEO-INFO
X-Rule
X-Detected-As
X-IP
X-Cache-Host
X-Ttl
X-VCache
X-Unique-Id
Cache-Key
X-Drupal-Cache-Tags
L5d-Success-Class
X-Esi
X-Whom
Webserver
X-CS
X-NGENIX-Cache
X-UA-Device-Type
X-Daa-Tunnel
Cache-Name
X-VHOST
Uber-Trace-Id
Viewport
Time
X-Forwarded-Host
X-UnsetCookies
X-Backend-TTL
X-Mode
Mime-Version
X-Info
X-Origin-TTL
Accept-Language
Content-Disposition
Rt-Fastcgi-Cache
X-Origin-CC
X-CDN-Forward
X-Varnish-Cache-Hits
Section-Io-Cache
X-PERF
X-B3-Spanid
X-Newrelic-Synthetics
X-ApacheServer
Country
X-Cache-Remote
Odigeo-Trace-Id
ServedBy
X-From
X-Magnolia-Registration
X-CLOUD-TRACE-CONTEXT
X-Device-Type
X-Routing-Service
X-EC-Lua
X-Zipkin-Id
X-Cluster-Name
X-Proxied
X-Drupal-Cache-Contexts
X-Via-Fastly
X-Uri
X-Microcachable
X-Geo
Proxy-Connection
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-TT-TIMESTAMP
Geo-Info
Cf-Ipcountry
X-Nc
Ohc-File-Size
HitType
Access-Control-Request-Headers
Xc-Version
X-External-Request-Id
X-Varnish-Beresp-Ttl
Fastcgi-X-Cache-Version
Content-Style-Type
MD5-Digest
Content-Script-Type
X-Varnish-Beresp-Status
X-Varnish-Beresp-Grace
X-DPWN-IS-SECURE
X-Destination
Machine
Viewtype
GEO-REGION-INFO
X-B-Cookie
X-G
X-CF-Lambda-Fn
Meta-Geo-Continent
Apple-News-Services-Handled
X-Connection-Hash
X-Geo-Header
Mobile-Detection-Method
X-D
Apple-News-Services-Host
Rendered-Blocks
X-Date
X-CF-Lambda-Version
BehaviorPad-Version
AsisCache
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
X-GeoIP-Country-Code
T-Server
X-S-Cookie
X-SRCache-Key
X-ScT
X-Vdms-Version
X-A-Wwc
X-A-Dcw
X-Twitter-Response-Tags
X-A-Dgt
X-Accel-Expires-Debug
X-ARC
X-Sigma-Backend
X-Vtex-Processado-Em
X-Aed
X-Sigma
X-Session-Fingerprint
X-Application
X-Vtex-Remote-Cache
X-S
X-VG-TLSProxy
X-Trv-Group
X-Transaction
VivaBuild
W
X-Region-Sid
X-A-Dam
X-A-Ccd
X-VG-WebServer
X-A
X-Rojux
X-VG-WebCache
X-Rocket-Build-Number
X-Request-UUID
X-Rewrite-Enabled
X-Real-IP
Filterid
X-C
CDCHOST
X-Tumblr-Pixel-3
X-Cache-Time
Countrycode
HA-Ipaddr
Ha-Gx-Prefs
Gh-Request-Id
X-Distil-CS
Locid
X-Agile-Age
X-Developers
IsBot
X-Eu-Site
X-No-Session
X-TrackingId
X-VC-Cache
X-Varnish-Authentication
Environment
Fastly-SIE
Fastly-SWR
Fastly-Soc-X-Request-Id
X-Agile
X-Thanos
X-CGP
X-Logging-Id
X-Auto-Login
X-Cache-Debug
X-Clientip
X-Agile-Id
Server-Cache-Control
Server-Surrogate-Control
X-Wikidot-Static-Cache
X-Cache-ASPX
X-Bip
X-WebServer
X-SIPLIST1
X-Contensis-Viewer-Groups
Powered-By
X-Hit
X-CUA
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Wikidot-Backend
X-App-Name
X-UPSTREAM-Address
X-Edge-Location
User-Cache-Control
Fastly-SSL
X-GoCache-CacheStatus
X-Labrador-Cache-Channel
X-PHP-Host
X-Azure-Ref
X-Debug-Cookies
X-BBXSRF
X-Cdn-Srv
X-AK-Request-ID
X-Clara-WADP
X-Cms-Context
X-Air-Hostname
X-Core-Mission
X-Var-Ttl
X-Debug-Cache-Fetch
X-Cache-Info
X-Cache-Tags
X-Debug-Cache-Store
X-Cache-URL
X-Debug-Log
X-Is-Gdpr
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Webstats-RespID
X-Request-URI
X-Server-W
X-Proxy-Upstream
X-Platform-Server
X-Origin-Expires
X-Backend-State
X-OVcl
X-OVcl-Cache
X-Owner
X-Servername
X-SVT-ORM-RULES
X-WADP-Cache
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Variation
X-VServer
X-Up
X-We-Are-Hiring
X-Swa-Ws
X-SVT-ORM-VERSION
X-TH-Server
X-Trace-Id
X-TT-LOGID
X-Origin-Date
X-NX-Host
X-GeoIP-City
X-Generation-Time
X-Has-Esi
X-Hash
X-IN-APIGATEWAY
X-Generated-In
X-Gamma-Serve
X-Epic-Correlation-Id
X-Distributor
X-Fastly-Cache
X-Fetched-On
X-FW-Version
X-IN-APIGATEWAYSSL
X-Instart-Isnd
X-Cache-Expired-At
X-Ms-Request-Id
X-Ms-Version
X-Nginx-Cache-Key
X-NodeID
X-Micro-Cache
X-LI-UUID
X-JWT-State
X-Irp-Debug
X-Li-Fabric
X-Li-Pop
X-LI-Proto
X-Dispatcher-Server
X-Debug-Cache-Expiry
Request-EU
Request-Country
Cache-Host
RNT-Machine
RNT-Time
X-App-Version
IBM-Web2-Location
AKAMAI
Platform
Cdncip
Heartbleed
Kp-EeAlive
Is-Eu
Locale
Mail-Subject
Cdnsip
Country-Code
Memcached
Server-ID
Adler-Geo
True-Client-Country-4JS
We-Hiring
Server-Int
Ohc-Cache-HIT
Group
V-Age
X-Trafficlayer-App-Scope
X-Render-Time
X-Trafficlayer-App-Version
X-NU-AKA-ACS-Version
X-Reboot
FNAC-ModuleRouting
X-Req
X-Trafficlayer-App-Name
X-ServiceProvider
X-TA-CDN-Provider
X-Hnp-Log
X-Thinkindot-L3
X-Generated-On
X-Level-Front-Cache
X-Gen-Mode
ServerName
X-Service
X-Matched-Rule
Wxu-Next-Region
X-Core-Value
PFcat
Cache-Hits
Fastly-Backend-Name
Thinkindot-CacheControl
X-Cache-Bucket
Server-Host
Thinkindot-CacheControl-Type
Wxu-Next-Commit
Wxu-Next-Hostname
Web-Mar-Node
Thinkindot-Control
X-Block-Status
Pragrma
X-Nginx-Cache
X-Cache-Backend
X-Lb-Id
X-User
X-SERVER
X-Old-Content-Length
S-Cnection
X-S-Maxage
RequestId
X-Response-By
X-Internal-Host
X-Refresh
X-Key
X-Wa
Powered-By-ChinaCache
X-CSRF-TOKEN
X-Sucuri-Cache
X-Sucuri-ID
X-Tec-Api-Origin
X-Parent-Response-Time
X-Tec-Api-Root
X-Varnish-Cacheable
X-Location
X-NC
X-Ua
X-Tec-Api-Version
X-Ua-Device
Origin
X-Tb-Optimization-Total-Bytes-Saved
X-Pjax-Url
X-CF-Powered-By
X-Node-Id
X-BACKEND-TTL
User-Agent
X-Developer
X-Cdn-Forward
ProcessTime
X-B3-Parentspanid
X-Oss-Server-Time
X-Oss-Request-Id
X-Oss-Hash-Crc64ecma
X-Oss-Object-Type
X-CSRF-Token
X-Oss-Storage-Class
X-NWS-UUID-VERIFY
X-Device-Os
Memory
X-Cache-Grace
X-Cdn-Origin
X-Sn-Servicetimems
X-Ocache
X-Pf-Uncompressing
X-LAGOON
X-Via-CDN
SRV
X-Cache-Status-Check
TTL
Geoip-Latitude
On-Server
Geoip-City
Hostname
X-Correlation-ID
GeoIp-Country-Code
X-Server-IP
X-Vcl-Version
X-NGINX-Cache
X-MSEdge-Features
X-MSEdge-Flight
A
PICS-Label
X-COUNTRY
X-Unique-ID
X-B3-SpanId
Cloudfront-Viewer-Country
X-Request-Host
X-Webkit-CSP
X-Litespeed-Cache
X-Servedbyhost
X-Cdn-Request-ID
X-Varnish-Ttl
M-TraceId
Media-Length
X-Ruxit-Js-Agent
X-TIME
XServer
SN
Dnion-Transfer-Encoding
X-Varnish-URL
X-HS-Status
Cdn
Tcn
X-Rocket-Nginx-Bypass
X-FORWARDED-FOR
Resin-Trace
Host-ID
X-Via-Ucdn
X-Ratelimit-Remaining
X-Cache-Ttl
Who
X-ServedByHost
X-Beluga-Response-Time
X-Beluga-Record
X-Beluga-Node
X-Beluga-Cache-Status
X-Beluga-Status
X-Beluga-Trace
CACHE
HostName
X-Sucuri-Id
Esi-Enabled
X-Slack-Backend
X-Reqid
X-AIR-PT
X-Action
X-Fastly-Country-Code
X-Server-Time
X-RPM
X-Processor
X-VCL-Version
X-Planisys-CDN-TTL
X-Policy
X-Planisys-CDN-Cache
GeoIP-Country-Code
X-DB
X-RSL
Arc-Country
X-DSS
X-RPS
X-DW
Pramga
X-Cache-FS-Status
X-Planisys-CDN-Rules
X-DI
X-PAYTM-SRV-ID
X-Dispatch
Pics-Label
CF-Cached-On
X-DC
X-Skip-Cache
X-ABtesting
X-ND-Cache
X-Hello
X-Flog
X-Azure-Ref-OriginShield
Ttl
GeoIP-Latitude
GeoIP-City
X-Dynatrace-Js-Agent
X-Request-Start
X-LiteSpeed-Cache-Control
MIME-Version
X-Oracle-Dms-Rid
X-Edge-Server
NtCoent-Length
X-PF-Uncompressing
X-VarnishDD-TTL
X-Served-From
Cdn-Request-Time
Cdn-Host
Rt-Proxy-Cache
X-Varnish-Url
Fastly-Drupal-HTML
X-APP
X-Bc-Bl
X-Ratelimit-Limit
N-Cache
X-Bc
X-DevSite-Last-Modified
X-Zone
X-Newrelic-App-Data
Section-Origin-Responded
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
X-Fastly-Backend-Reqs
Section-Io-Id
Trailer
X-HostName
Amp-Access-Control-Allow-Source-Origin
X-FPC
X-Method
X-SRV
Magicmarker
X-Backend-Host
X-PJAX-URL
WebServer
X-Swift-Error
Processtime
Fusion-Deployment-Id
Cteonnt-Length
X-BE
X-Amzn-Remapped-Connection
X-Amzn-Remapped-Date
X-Dynatrace
Servername
X-Adobe-Source
Cache-Cookie-Set-Lfrom
X-Fmm-Version
FSS-Proxy
FSS-Cache
X-BC
Cache-Cookie-Set-From
Cache-Provider
X-WA
X-ZONE
Cache-Cookie-Set-Idcheck
X-ID
X-WR-MODIFICATION
X-Frame-Option
X-Be
Dynatrace
X-Scheme
X-Svr
X-StackifyID
X-Snapshot-Date
Ohc-Response-Time
Requestid
CF-IPCountry
X-LB-ID
CDN
X-Branch-Name
X-Fpc
X-Ftr-Cache-Host
X-CACHE-AGE
X-Request-Url
X-Apw-Hits
X-Aicache-OS
V-Cache
Lfy
X-Tid
Vix-Hermes-Req-Id
X-App
X-Apw-Access-Action
X-Apw-Access-Object
X-Apw-Access-Token
WZWS-RAY
X-Fastly-Cache-Hits
Warning
D-Cc-Upstream
X-Cc-Req-Id
X-Cc-Via
X-SB
X-VC
X-Litespeed-Cache-Control
Load-Balancing
X-Cache-Id
X-SN
X-Compress-Hint
Lb
Cneonction
X-Esi-Check
L
Sid
Correlation-Id
X-Powered-Y
X-ElasticPress-Search
X-Request-URL
X-Check-Cacheable
X-Fastly-Cache-Status
WP-Super-Cache
Pagetype
X-Worker
X-WPE-Loopback-Upstream-Addr
X-Varnish-Beresp-TTL
Backend-Name
Proxy-Firewall