Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-Powered-By
Pragma
CF-Cache-Status
Link
X-XSS-Protection
ETag
CF-RAY
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-Xss-Protection
X-Runtime
CF-Ray
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-Request-ID
X-DNS-Prefetch-Control
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
Status
Upgrade
X-Content-Security-Policy
Content-Encoding
X-CDN
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
X-Pass-Why
X-Cache-Group
X-AH-Environment
X-Envoy-Upstream-Service-Time
Xkey
X-Via
X-Backend
X-Server
X-Age
X-Ws-Request-Id
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Page-Speed
X-Server-Powered-By
EagleId
X-Pingback
X-Proxy-Cache
X-Hacker
X-Nginx-Cache-Status
Request-Context
X-UA-Device
Feature-Policy
Server-Timing
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Cf-Railgun
Ali-Swift-Global-Savetime
Grace
X-Amz-Version-Id
X-Ua-Compatible
Report-To
X-LiteSpeed-Cache
X-Rq
X-OneAgent-JS-Injection
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-WebKit-CSP
X-Device
X-Host
X-Server-Id
X-Origin-Cache
X-Response-Time
EagleEye-TraceId
X-Node
X-Ac
Surrogate-Control
Content-Location
X-Cloud-Trace-Context
X-Backend-Server
X-Vhost
X-Readtime
X-Dispatcher
Request-Id
X-Ruxit-JS-Agent
X-Origin-Upstream-Status
X-Cache-Lookup
X-Cnection
X-Application-Context
X-HW
Fusion-Component-Id
Fusion-Content-Id
Fusion-Content-Source
Fusion-Template-Id
Fusion-Source
X-ORACLE-DMS-ECID
NEL
X-Mod-Pagespeed
X-ORACLE-DMS-RID
X-DataDome
X-Rack-Cache
X-Country
X-Clacks-Overhead
P3p
Edge-Control
X-Akam-SW-Version
Rating
X-Dns-Prefetch-Control
Allow
Pinterest-Generated-By
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-TTL
X-Country-Code
X-FTR-Request-ID
X-Varnish-TTL
X-Instart-Request-ID
X-DynaTrace
Accept-Ch
X-Goog-Hash
X-TtlSet
X-Vname
X-PC
X-ESI
Content-MD5
Verso
Service-Worker-Allowed
X-Powered-By-Plesk
Accept-Ch-Lifetime
X-Url
X-Vcache
X-B3-TraceId
X-Use-Magma
X-Exp-Variant
X-Forwarded-Proto
X-Exp-Id
X-Kinja-Server
X-Kinja-Revision
X-GoogleNews-Bot
X-Kinja
X-Kinja-Build
X-Cdn-Fetch
X-Version
X-GitHub-Request-Id
X-MS-InvokeApp
RTSS
X-Server-Name
X-D2id
Edge-Cache-Tag
X-Abt-Application-Version
X-Px
X-Debug
X-Server-ID
AR-CACHE
AR-PoweredBy
Ar-Sid
AR-ATIME
AR-Request-ID
X-Amz-Server-Side-Encryption
SPRequestGuid
Charset
X-Cached
X-NF-Request-ID
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Navigation-Version
X-Vcap-Request-Id
X-MSEdge-Ref
Pagespeed
Display
Response
X-Sol
X-Middleton-Display
X-Middleton-Response
X-Amz-Rid
X-Accel-Expires
Arr-Disable-Session-Affinity
TCN
X-Fastcgi-Cache
X-SharePointHealthScore
X-Pinterest-Rid
Pinterest-Version
X-VARITI-CCR
Public-Key-Pins
X-Fastly-Request-ID
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Powered-CMS
Nginx-Cache
MS-Author-Via
X-Trace
X-Client-IP
X-Edge-O15-RID
Cache-Tag
Realpath
X-Cdn
X-Ser
Access-Control-Request-Method
X-Content-Type
Mrf-Cache-Status
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
MRF-Tech
X-B3-TraceId-Primal
SPIisLatency
SPRequestDuration
X-Shard
X-Amzn-Trace-Id
X-Upstream
X-Jurisdiction
X-Grace
X-Id
X-Hp-Webp
X-DynaTrace-JS-Agent
X-Ezoic-Cdn
X-Forwarded-For
S
Front-End-Https
X-Amz-Meta-S3cmd-Attrs
X-Cache-TTL
X-Hits
X-T
Fastcgi-Cache
Nel
X-Recruiting
DynaTrace
X-Aspnet-Version
X-Element-Page-Cache
X-Node-Name
X-Varnish-Age
X-Dw-Request-Base-Id
X-Content-Digest
X-FTR-Cache-Status
X-FTR-Backend-Server
X-FTR-Backend
MicrosoftSharePointTeamServices
X-FTR-Balancer
X-FTR-DC
X-FTR-Realm
X-FTR-Expires
X-Mobile-URL
X-Country-Code-Real
ServerID
X-DIS-Request-ID
Server-Node
NR-ENABLED
TP-L2-Cache
X-Frontend
X-HS-Hub-Id
X-HS-Content-Id
TP-Cache
X-HS-Combine-CSS
X-HS-Cache-Config
X-GUploader-UploadID
X-Goog-Storage-Class
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-Goog-Metageneration
Powered
X-CST
X-Logged-In
Alternate-Protocol
Server-Name
X-Correlation-Id
X-Amzn-RequestId
X-Amz-Apigw-Id
Upgrade-Insecure-Requests
Fastly-Restarts
X-Cache-Hit
X-FTR-Cache-Host
X-Microsite
X-Request-Handler-Origin-Region
X-XRDS-Location
X-ATS-Timestamp
Backend-Timing
X-Request-Processing-Time
X-Request-Received
AMP-Access-Control-Allow-Source-Origin
X-Page-Id
X-User-Agent
X-Content-Options
X-Content-Security-Policy-Report-Only
X-Zen-Fury
Refresh
X-F-Cache
X-Origin-Server
X-Rid
X-Varnish-Grace
X-Akamai-Edgescape
X-XRDS-LOCATION
X-Revision
X-Type
X-Content-Powered-By
X-B
X-LB-Cache
PB-PID
PB-RID
X-Webkit-Csp
Arc-Version
X-Mobile-Rewrite
X-B3-Sampled
X-Geo-Country
Cache-Status
X-Az
X-AppVersion
X-Activity-Id
X-URL
X-N
X-Kinsta-Cache
X-TT
X-Cache-Action
X-AOL-HN
X-Cache-Age
X-Jobs
Access-Control-Allow-Method
X-Debug-Info
X-WebKit-CSP-Report-Only
X-Signature
X-Framework
X-B-Cache
X-Time
X-Request-Guid
X-Instance
X-FB-Debug
X-Git-Hash
X-Cached-By
Actual-Object-TTL
X-Tumblr-Pixel
Paypal-Debug-Id
X-Tumblr-Pixel-0
X-Tumblr-User
X-NWS-LOG-UUID
X-PHP-Backend
X-Load-Cache
X-App-Environment
Fastcgi-Useragent
X-Pad
X-Tt-Trace-Host
X-Tt-Trace-Tag
DC
X-Amz-Replication-Status
X-Shield-Request-Id
X-Varnish-Backend
Host-Header
X-WA-Info
X-ATG-Version
Host
Surrogate-Key
X-RateLimit-Remaining
X-Contextid
X-IPLB-Instance
MS-CV
X-ORACLE-APMCS-TAG
X-ORACLE-APMCS-REQUEST-ID
X-Via-JSL
X-Erf-Bev-Bev
X-Erf-Bev-Bev-Is-Generated
X-Mobile
X-Kong-Upstream-Latency
X-Kong-Proxy-Latency
X-Host-Name
Accept-CH
FilterID
X-Response-Served-From
X-Accel-Buffering
Frame-Options
NGB
Payment
X-FastCGI-Cache
X-Cache-Key
Retry-After
X-SS-Set-Cookie
Tracecode
X-Cache-NE
Source
X-Varnish-Server
Eomportal-Instance
X-Hostname
Xserver
X-Region
X-Origin-Response-Time
X-Cache-2
WPE-Backend
X-Cacheable-TTL
X-FW-Hash
X-FW-Serve
X-GeoIP
X-Is-Bot
X-Rendered-As
Filters
X-FW-Type
X-FW-Static
X-FW-Server
X-Cluster
X-Srv
X-Presslabs-Stats
Cache-Tv-Group
X-Cache-Enabled
X-Varnish-Hostname
X-IPS-LoggedIn
X-Adobe-Content
X-Adobe-Loc
X-Seen-By
X-Cache-Rule
X-Cache-Operation
X-Tumblr-Pixel-1
Liferay-Portal
X-Tumblr-Pixel-2
X-RequestSource
X-NewRelic-App-Data
Server-Info
X-RemovedCookies
X-ProcessESI
X-App-Server
X-EdgeConnect-Cache-Status
X-TX-ID
X-Analytics
X-Cache-TTL-Remaining
Accept-CH-Lifetime
Cleartype
X-L-Path
X-Environment-Context
X-Webapp-Samesite-None-Activated-N
X-FireWall-Port
X-B3-Traceid
X-Handled-By
X-Source
X-RTag
X-Upgrade-Enabled
Ms-Operation-Id
X-CACHE-KEY
X-Endurance-Cache-Level
X-Dc
X-HTML-Minification-Powered-By
From-Origin
X-Cache-Server
Srv
Accept-Charset
X-UA
X-Backend-Name
Datacenter
X-UUID
X-APP-VERSION
X-Cache-Var
Meta-Geo
X-RN-RSRV
X-ES-SERVER
X-Cache-Var-Map
X-Path-Route
Selected-Fe
X-Proxy-Build
Healthy
OT-Force-Account-Verify
X-Format
X-Tb
X-Wix-Request-Id
X-Timing-Wait
X-Access
X-Section
X-Content-Age
Cache-Tags
X-Cache-Config
X-Proto
X-EIG-Tracking-Id
X-Sorting-Hat-ShopId
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Sorting-Hat-PodId
X-Request-Time
X-Alternate-Cache-Key
X-Shopify-Stage
X-ShardId
X-PressLabs-Stats
X-Shopify-Generated-Cart-Token
X-ShopId
Mn-Server-Ip
X-Akamai-Request-ID
Node
X-Hl-Ver
X-JoinUs
X-ProxyCache-Key
X-ProxyCache-Status
X-Proxy-Cache-Status
X-Qloud-Router
Akamai-GRN
Ec-Rule-Version
X-Akamai-Request-ID2
X-BYPASS-REASON
X-ServerID
NGX
X-SaId
X-Yottaa-Optimizations
X-NYM-Debug-Backend
X-AWS-Id
X-Yottaa-Metrics
X-Status
X-Origin
X-OCL
GEO-INFO
X-VWS-Id
X-Soup
X-Vgn-Hpd-Reason
X-LJ-Flow-ID
X-PCL
X-FC-Vary-Parameters
X-Say-Cacheable
DB-Nickname
Cross-Origin-Window-Policy
X-Pubstack
X-SayCDN-TTL
Decoy-Debug-Key
Decoy-Debug-Status
Decoy-Debug-TTL
X-BCube-Filmed-By
X-FW-Dynamic
X-FB-TRIP-ID
X-MP-GENERATED-AT
X-Hosted-By
X-Hyper-Cache
X-Loop
X-Locale
Version
Now
X-CCM
X-Proxy
X-Detected-As
X-Web-Node
X-Say-TTL
X-TNCMS
X-Akamai-Transformed
X-Viewer-Country
X-Www-Served-By
X-Time-Microsecs
X-Storage
X-Debug-Cache
X-Human
Origin-Edge-Control
Origin-Cache-Control
S-Rt
X-Redis-Cache
Property-Id
TWC-Device-Class
TWC-Connection-Speed
TWC-Privacy
X-Amzn-Remapped-Content-Length
X-Varnish-Hits
X-Origin-Hint
X-IP
Webcakes-Region
Webcakes-App-Version
TWC-GeoIP-LatLong
X-RCS-CacheZone
Webcakes-App-Name
TWC-GeoIP-Country
TWC-Locale-Group
X-Generated-By
X-Xfnlog-Site
Azure-SlotName
Azure-Version
Azure-SiteName
Azure-RegionName
X-Site-Version
Azure-InstanceId
X-R9-Blue-Green-Version
X-Generated
X-Cluster-Node
X-NCache
X-Unique-Id
X-Whom
X-Cache-Control
X-Daa-Tunnel
X-Cache-Host
X-RateLimit-Limit
Cache-Key
X-UA-Device-Type
X-Drupal-Cache-Tags
X-Ttl
Cache
X-NGENIX-Cache
X-Rule
L5d-Success-Class
Webserver
X-Mode
X-Forwarded-Host
X-Esi
Section-Io-Cache
Time
Cache-Name
X-CS
X-Info
X-UnsetCookies
Content-Disposition
Mime-Version
Viewport
X-VHOST
Accept-Language
X-Backend-TTL
Rt-Fastcgi-Cache
Uber-Trace-Id
X-PERF
X-ApacheServer
X-Varnish-Cache-Hits
X-Origin-TTL
X-Origin-CC
ServedBy
X-Newrelic-Synthetics
Country
X-CDN-Forward
X-B3-Spanid
X-Cache-Remote
Odigeo-Trace-Id
X-Zipkin-Id
X-Routing-Service
X-Proxied
X-EC-Lua
X-Device-Type
X-Via-Fastly
X-From
X-VCache
X-Magnolia-Registration
X-Uri
X-Cluster-Name
Proxy-Connection
X-CLOUD-TRACE-CONTEXT
X-Drupal-Cache-Contexts
X-Nc
X-Microcachable
HitType
X-Real-IP
X-TT-TIMESTAMP
X-Geo
Access-Control-Request-Headers
Geo-Info
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
Ohc-File-Size
Cf-Ipcountry
X-Trv-Group
X-Transaction
X-CF-Lambda-Fn
X-ARC
X-Twitter-Response-Tags
X-Sigma-Backend
Machine
Meta-Geo-Continent
Mobile-Detection-Method
X-B-Cookie
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Status
MD5-Digest
X-Varnish-Beresp-Grace
X-Connection-Hash
X-Destination
BehaviorPad-Version
AsisCache
Apple-News-Services-Request-Url
Content-Script-Type
Content-Style-Type
Fastcgi-X-Cache-Version
X-D
X-Date
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-G
X-Geo-Header
X-GeoIP-Country-Code
X-Application
X-External-Request-Id
Apple-News-Services-Handled
X-DPWN-IS-SECURE
GEO-REGION-INFO
X-CF-Lambda-Version
X-SRCache-Key
X-Region-Sid
X-A-Wwc
X-S-Cookie
X-Vtex-Processado-Em
X-A-Dgt
X-VG-WebServer
X-A-Dam
X-A-Dcw
X-Vtex-Remote-Cache
X-Request-UUID
X-Accel-Expires-Debug
Xc-Version
X-S
X-Rojux
X-Aed
X-Rewrite-Enabled
X-Rocket-Build-Number
X-ScT
X-A-Ccd
W
X-A
X-VG-TLSProxy
T-Server
X-Vdms-Version
Rendered-Blocks
X-VG-WebCache
VivaBuild
Viewtype
X-Session-Fingerprint
X-Sigma
X-C
X-PHP-Host
X-Labrador-Cache-Channel
X-Cache-Time
X-Eu-Site
X-CUA
Environment
Countrycode
Cache-Hits
X-Clientip
CDCHOST
Fastly-SWR
X-Distil-CS
X-Developers
Fastly-Soc-X-Request-Id
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
Fastly-SIE
Ha-Gx-Prefs
X-Backend-State
Group
X-Bip
X-Agile-Age
X-Cache-Debug
X-Logging-Id
X-SIPLIST1
Powered-By
X-Var-Ttl
X-Agile-Id
X-VC-Cache
X-Cache-Expired-At
Locid
HA-Ipaddr
X-WebServer
X-Thanos
X-App-Name
X-Hit
X-CGP
IsBot
X-Agile
Fastly-SSL
X-GoCache-CacheStatus
User-Cache-Control
X-No-Session
Filterid
X-Air-Hostname
X-Auto-Login
X-Cdn-Srv
X-Contensis-Viewer-Groups
X-Cms-Context
X-Core-Mission
X-Cache-Tags
X-Azure-Ref
X-Cache-ASPX
We-Hiring
V-Age
X-Varnish-Authentication
X-Variation
X-Servername
X-VServer
X-Wikidot-Backend
X-Urbn-Site-Id
X-Urbn-Context-Path
X-Nginx-Cache-Key
X-NodeID
X-Up
X-NX-Host
X-Wikidot-Static-Cache
X-Origin-Date
X-OVcl
X-OVcl-Cache
X-TrackingId
X-TH-Server
X-Origin-Expires
X-Owner
X-Platform-Server
X-Request-URI
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Proxy-Upstream
X-Ms-Version
X-Ms-Request-Id
X-GeoIP-City
X-Generated-In
X-Has-Esi
X-Hash
X-Trace-Id
X-Gamma-Serve
X-Fetched-On
X-Debug-Log
X-Dispatcher-Server
X-Distributor
X-Epic-Correlation-Id
X-IN-APIGATEWAY
X-IN-APIGATEWAYSSL
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Li-Pop
X-LI-Proto
X-LI-UUID
X-Swa-Ws
X-Tumblr-Pixel-3
X-Instart-Isnd
X-Is-Gdpr
X-JWT-State
X-Li-Fabric
X-Debug-Cookies
Ohc-Cache-HIT
Request-Country
Is-Eu
Request-EU
RNT-Machine
RNT-Time
Pragrma
AKAMAI
Locale
Mail-Subject
Adler-Geo
Platform
Kp-EeAlive
Heartbleed
IBM-Web2-Location
Server-Surrogate-Control
Server-Cache-Control
Fastly-Backend-Name
True-Client-Country-4JS
Cache-Host
Country-Code
Server-ID
Server-Int
Gh-Request-Id
X-Edge-Location
X-FW-Version
X-Gen-Mode
X-Generated-On
X-NU-AKA-ACS-Version
X-Hnp-Log
X-Fastly-Cache
Cdnsip
X-Generation-Time
X-Debug-Cache-Store
Cdncip
X-Debug-Cache-Fetch
X-Level-Front-Cache
X-Trafficlayer-App-Scope
X-Req
X-Reboot
X-Trafficlayer-App-Version
X-Trafficlayer-App-Name
X-Thinkindot-L3
X-ServiceProvider
X-Service
X-Server-W
X-App-Version
X-TT-LOGID
X-Nginx-Cache
X-Irp-Debug
ServerName
X-Webstats-RespID
S-Cnection
X-We-Are-Hiring
X-Debug-Cache-Expiry
X-Micro-Cache
X-Matched-Rule
X-WADP-Cache
Web-Mar-Node
X-Block-Status
X-Cache-Info
X-Cache-URL
Thinkindot-CacheControl-Type
Memcached
PFcat
Thinkindot-CacheControl
X-BBXSRF
Wxu-Next-Hostname
X-Clara-WADP
FNAC-ModuleRouting
X-Core-Value
Wxu-Next-Region
Wxu-Next-Commit
Server-Host
X-AK-Request-ID
Thinkindot-Control
X-UPSTREAM-Address
X-S-Maxage
X-Lb-Id
X-Cache-Bucket
X-Response-By
X-Old-Content-Length
X-SERVER
RequestId
X-Refresh
X-Render-Time
X-Cache-Backend
X-Varnish-Cacheable
X-User
Powered-By-ChinaCache
X-Wa
X-Oss-Storage-Class
X-Oss-Server-Time
X-Oss-Object-Type
X-Oss-Request-Id
X-Sucuri-ID
X-Node-Id
X-Oss-Hash-Crc64ecma
Origin
X-CSRF-TOKEN
X-Key
X-Parent-Response-Time
X-Internal-Host
X-TA-CDN-Provider
X-Tec-Api-Origin
X-NC
X-Sucuri-Cache
User-Agent
X-Pjax-Url
X-Developer
X-Tec-Api-Version
X-Tec-Api-Root
X-Cache-Status-Check
X-Ua
X-Ua-Device
X-Location
X-Device-Os
X-Tb-Optimization-Total-Bytes-Saved
X-LAGOON
Hostname
X-Sn-Servicetimems
X-BACKEND-TTL
X-Cdn-Origin
X-CSRF-Token
X-Cache-Grace
X-CF-Powered-By
X-Cdn-Forward
X-Ocache
X-Pf-Uncompressing
X-NWS-UUID-VERIFY
X-Via-CDN
Geoip-City
Geoip-Latitude
A
On-Server
ProcessTime
Memory
X-B3-Parentspanid
SRV
GeoIp-Country-Code
PICS-Label
X-MSEdge-Features
Cloudfront-Viewer-Country
TTL
X-MSEdge-Flight
X-Request-Host
X-NGINX-Cache
X-Vcl-Version
X-COUNTRY
X-Correlation-ID
X-Unique-ID
X-Server-IP
X-Litespeed-Cache
X-Webkit-CSP
X-Varnish-URL
X-Servedbyhost
X-B3-SpanId
Resin-Trace
Cdn
X-Varnish-Ttl
Dnion-Transfer-Encoding
X-Ratelimit-Remaining
X-Rocket-Nginx-Bypass
XServer
X-TIME
M-TraceId
X-HS-Status
Media-Length
SN
X-Cdn-Request-ID
CACHE
Tcn
X-FORWARDED-FOR
X-Action
X-ServedByHost
X-Slack-Backend
Host-ID
X-DB
X-DI
X-Beluga-Trace
X-Beluga-Cache-Status
Who
X-Beluga-Node
X-Beluga-Record
X-Beluga-Status
X-Beluga-Response-Time
X-DSS
X-Via-Ucdn
X-Dispatch
X-Cache-FS-Status
X-PAYTM-SRV-ID
X-Processor
X-Server-Time
X-DW
Pramga
X-Cache-Ttl
X-RPS
Arc-Country
X-RSL
X-RPM
HostName
X-Skip-Cache
X-Fastly-Country-Code
X-ND-Cache
X-Edge-Server
X-VCL-Version
X-Reqid
X-Served-From
GeoIP-Country-Code
Section-Origin-Responded
Fastly-Drupal-HTML
X-AIR-PT
Esi-Enabled
Cdn-Host
Cdn-Request-Time
Pics-Label
Section-Io-Id
NtCoent-Length
X-Sucuri-Id
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
X-DC
X-Dynatrace-Js-Agent
X-Planisys-CDN-TTL
GeoIP-Latitude
X-Policy
Amp-Access-Control-Allow-Source-Origin
X-Bc-Bl
N-Cache
X-Planisys-CDN-Cache
GeoIP-City
X-Planisys-CDN-Rules
X-VarnishDD-TTL
X-Flog
Ttl
X-ABtesting
X-DevSite-Last-Modified
X-Hello
MIME-Version
CF-Cached-On
Fusion-Deployment-Id
X-LiteSpeed-Cache-Control
X-Oracle-Dms-Rid
X-Ratelimit-Limit
X-Bc
X-PF-Uncompressing
X-Zone
X-Varnish-Url
X-Azure-Ref-OriginShield
X-Request-Start
X-Adobe-Source
X-APP
Rt-Proxy-Cache
X-Newrelic-App-Data
X-FPC
X-Backend-Host
X-Ruxit-Js-Agent
Trailer
X-HostName
Cache-Cookie-Set-Idcheck
WebServer
X-PJAX-URL
X-Fastly-Backend-Reqs
Cache-Cookie-Set-Lfrom
X-SRV
Cache-Cookie-Set-From
X-Swift-Error
X-Amzn-Remapped-Date
X-Method
X-Scheme
X-BE
Magicmarker
Processtime
Cteonnt-Length
X-Dynatrace
X-Amzn-Remapped-Connection
X-WA
X-Fmm-Version
Servername
X-ID
Cache-Provider
X-Fpc
FSS-Cache
FSS-Proxy
X-ZONE
X-BC
X-WR-MODIFICATION
X-Frame-Option
X-Esi-Check
X-SN
X-Snapshot-Date
X-Branch-Name
Dynatrace
CDN
X-LB-ID
X-Cache-Id
CF-IPCountry
X-StackifyID
Ohc-Response-Time
L
Requestid
X-CACHE-AGE
X-SD-PageType
X-Gzip
WZWS-RAY
X-Compress-Hint
X-Cache-NGX
Release
Sid
Lb
X-Tid
X-Svr
SD-X-WS
D-Cc-Upstream
X-Apw-Access-Action
V-Cache
X-Fastly-Cache-Hits
X-Apw-Access-Token
X-Apw-Hits
X-Aicache-OS
X-Be
X-Request-Url
X-App
X-Apw-Access-Object
X-VC
Warning
X-Cc-Req-Id
X-SB
X-Cc-Via
Load-Balancing
X-Litespeed-Cache-Control
Backend-Name
X-Varnish-Beresp-TTL
LB
SID
X-VCT
X-Nananana
X-Instart-Info
X-ECache
Correlation-Id
X-Worker
X-Check-Cacheable
X-Fastly-Cache-Status
X-ElasticPress-Search
Cneonction
WP-Super-Cache
X-WPE-Loopback-Upstream-Addr
X-GEO
Lfy
X-Powered-Y
Vix-Hermes-Req-Id
X-Request-URL