Threat Level: green Handler on Duty: Bojan Zdrnja

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
Link
CF-RAY
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-UA-Compatible
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-AspNet-Version
X-Request-Id
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Request-ID
X-Adblock-Key
X-Check
X-Cache-Status
X-Generator
Content-Security-Policy-Report-Only
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-Template
X-Language
X-DNS-Prefetch-Control
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-Ua-Compatible
X-FRAME-OPTIONS
X-Buckets
Status
X-Content-Security-Policy
X-CDN
Content-Encoding
Upgrade
Access-Control-Expose-Headers
Access-Control-Max-Age
Keep-Alive
X-Kinja-Server-Push
X-Xss-Protection
X-Drupal-Dynamic-Cache
X-Turbo-Charged-By
Xkey
X-Pass-Why
P3p
X-AH-Environment
X-Envoy-Upstream-Service-Time
X-Cache-Group
CF-Ray
X-Backend
X-Age
X-Server
X-Via
X-Robots-Tag
X-Server-Powered-By
X-Amz-Request-Id
X-Amz-Id-2
X-Page-Speed
X-Pingback
EagleId
X-Proxy-Cache
X-Nginx-Cache-Status
X-UA-Device
X-Hacker
Request-Context
X-Ws-Request-Id
X-Varnish-Cache
Feature-Policy
Server-Timing
Grace
Cf-Railgun
X-Swift-SaveTime
X-Swift-CacheTime
X-Amz-Version-Id
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
X-LiteSpeed-Cache
Report-To
X-Server-Id
X-Rq
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-WebKit-CSP
X-Host
X-Device
EagleEye-TraceId
X-OneAgent-JS-Injection
Content-Location
X-Origin-Cache
X-Response-Time
X-Node
X-Ac
Surrogate-Control
X-Vhost
X-Readtime
Request-Id
X-Backend-Server
X-Cloud-Trace-Context
X-Dispatcher
X-Origin-Upstream-Status
X-ORACLE-DMS-ECID
X-Cnection
X-HW
NEL
X-DataDome
X-Application-Context
X-ORACLE-DMS-RID
Fusion-Component-Id
Fusion-Source
Fusion-Template-Id
Fusion-Content-Source
Fusion-Content-Id
X-Mod-Pagespeed
X-Cache-Lookup
Edge-Control
X-Rack-Cache
Rating
X-Country
Pinterest-Generated-By
X-Akam-SW-Version
X-Clacks-Overhead
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Ruxit-JS-Agent
X-DynaTrace
X-Country-Code
X-Varnish-TTL
Allow
X-Instart-Request-ID
X-Goog-Hash
X-Vname
X-PC
X-TtlSet
Accept-Ch
X-ESI
X-FTR-Request-ID
X-TTL
Verso
X-Powered-By-Plesk
X-Url
Service-Worker-Allowed
Content-MD5
Accept-Ch-Lifetime
X-Forwarded-Proto
X-Version
X-B3-TraceId
X-MS-InvokeApp
X-GitHub-Request-Id
X-GoogleNews-Bot
X-Exp-Variant
X-Exp-Id
X-Kinja
X-Cdn-Fetch
X-Use-Magma
X-Kinja-Build
X-Kinja-Server
X-Kinja-Revision
Edge-Cache-Tag
RTSS
X-Px
AR-PoweredBy
AR-CACHE
AR-Request-ID
Ar-Sid
AR-ATIME
X-D2id
X-Debug
X-Abt-Application-Version
Charset
X-NF-Request-ID
SPRequestGuid
X-Server-Name
X-Amz-Server-Side-Encryption
X-Powered-CMS
X-Accel-Expires
X-MSEdge-Ref
X-Cached
X-Amz-Rid
Arr-Disable-Session-Affinity
X-Vcache
X-Vcap-Request-Id
X-Middleton-Display
Display
X-Sol
Pagespeed
Response
X-Middleton-Response
X-Navigation-Version
X-Trace
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-Pinterest-Rid
Pinterest-Version
X-SharePointHealthScore
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
TCN
X-VARITI-CCR
Public-Key-Pins
Realpath
X-Fastcgi-Cache
Cache-Tag
X-Cdn
Access-Control-Request-Method
X-Upstream
X-Client-IP
S
X-Fastly-Request-ID
X-DynaTrace-JS-Agent
MS-Author-Via
X-Ser
X-Shard
SPRequestDuration
SPIisLatency
X-Id
X-Hp-Webp
DynaTrace
X-Forwarded-For
X-Ezoic-Cdn
X-Mrf-Section-Lastmod
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
X-T
X-Mrf-Item-Lastmod
X-Amz-Meta-S3cmd-Attrs
X-Amzn-Trace-Id
X-Content-Type
Nginx-Cache
X-Recruiting
Front-End-Https
X-Grace
Fastcgi-Cache
X-Hits
X-Varnish-Age
X-DIS-Request-ID
MicrosoftSharePointTeamServices
ServerID
X-Mobile-URL
X-Dw-Request-Base-Id
NR-ENABLED
X-Element-Page-Cache
X-Content-Digest
X-Node-Name
X-Goog-Storage-Class
X-HS-Cache-Config
X-HS-Combine-CSS
X-HS-Content-Id
X-HS-Hub-Id
X-GUploader-UploadID
X-Goog-Stored-Content-Length
X-Frontend
X-Goog-Generation
X-Goog-Metageneration
X-Goog-Stored-Content-Encoding
Powered
Server-Name
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Expires
X-Edge-O15-RID
Alternate-Protocol
X-Logged-In
X-FTR-Realm
X-FTR-Balancer
X-FTR-Backend
X-FTR-Backend-Server
X-FTR-DC
X-Correlation-Id
TP-L2-Cache
TP-Cache
Server-Node
X-Cache-TTL
X-Webapp-Samesite-None-Activated-N
X-Shield-Request-Id
X-XRDS-LOCATION
X-Webkit-Csp
X-Request-Processing-Time
X-Request-Received
AMP-Access-Control-Allow-Source-Origin
X-Microsite
X-Request-Handler-Origin-Region
Upgrade-Insecure-Requests
X-Origin-Server
Refresh
X-Content-Options
X-Content-Security-Policy-Report-Only
X-User-Agent
X-Page-Id
X-Akamai-Edgescape
X-Amzn-RequestId
X-Rid
X-Amz-Apigw-Id
X-Revision
X-Varnish-Grace
Nel
Backend-Timing
X-F-Cache
X-Server-ID
X-ATS-Timestamp
X-Cache-Hit
X-Jurisdiction
X-Type
Fastly-Restarts
X-XRDS-Location
X-Pad
X-Content-Powered-By
X-Geo-Country
X-Analytics
X-Az
X-AppVersion
X-Activity-Id
X-N
X-B3-Sampled
X-LB-Cache
X-B
X-Zen-Fury
X-URL
X-Kinsta-Cache
X-Ttl
X-FTR-Cache-Host
X-RateLimit-Remaining
X-TT
PB-RID
PB-PID
X-Cache-Age
X-WebKit-CSP-Report-Only
X-AOL-HN
Paypal-Debug-Id
X-Instance
X-Framework
X-App-Environment
X-Request-Guid
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-0
X-Ruxit-Js-Agent
X-Jobs
X-Mobile-Rewrite
DC
Arc-Version
Actual-Object-TTL
X-Debug-Info
X-B-Cache
X-Signature
Access-Control-Allow-Method
X-CST
X-PHP-Backend
X-FB-Debug
Cache-Status
X-Load-Cache
X-Cache-Action
X-Erf-Bev-Bev
X-Varnish-Backend
X-Erf-Bev-Bev-Is-Generated
Surrogate-Key
Fastcgi-Useragent
X-Git-Hash
FilterID
Host-Header
X-FastCGI-Cache
X-Cached-By
X-IPLB-Instance
MS-CV
X-SS-Set-Cookie
X-Tt-Trace-Tag
X-Amz-Replication-Status
X-Time
X-Contextid
X-Cluster
X-Tt-Trace-Host
X-Cache-Key
X-Srv
Frame-Options
X-ATG-Version
NGB
Tracecode
X-Accel-Buffering
X-Response-Served-From
X-VCache
Source
WPE-Backend
X-Trafficlayer-App-Name
X-Varnish-Server
Eomportal-Instance
Host
Payment
X-Trafficlayer-App-Scope
X-Cache-2
X-Adobe-Loc
Filters
Cache-Tv-Group
X-Cache-Enabled
X-Adobe-Content
X-FW-Hash
X-Region
X-IPS-LoggedIn
X-RequestSource
X-Tumblr-Pixel-1
X-Varnish-Hostname
X-GeoIP
X-FW-Type
X-Cacheable-TTL
X-FW-Serve
X-FW-Server
X-FW-Static
X-Cache-NE
X-Tumblr-Pixel-2
Accept-CH
X-WA-Info
X-Mobile
X-TX-ID
Cleartype
X-Host-Name
X-Rendered-As
X-Kong-Upstream-Latency
X-Is-Bot
X-Kong-Proxy-Latency
X-B3-Traceid
X-NewRelic-App-Data
Xserver
X-Seen-By
X-Oneagent-Js-Injection
Healthy
X-Cache-Operation
Cache
X-Cache-Rule
X-Via-JSL
X-Hostname
X-EdgeConnect-Cache-Status
X-Cache-Control
X-Origin-Response-Time
X-Cache-TTL-Remaining
X-Presslabs-Stats
Datacenter
X-HTML-Minification-Powered-By
X-Dc
Accept-CH-Lifetime
Retry-After
Ms-Operation-Id
X-RTag
X-ProcessESI
X-ORACLE-APMCS-REQUEST-ID
X-UA
X-RemovedCookies
X-ORACLE-APMCS-TAG
Server-Info
X-Rule
X-RateLimit-Limit
X-Status
From-Origin
X-PressLabs-Stats
Version
Liferay-Portal
X-Wix-Request-Id
X-Cache-Server
X-Environment-Context
X-L-Path
X-FireWall-Port
X-Upgrade-Enabled
X-NWS-LOG-UUID
X-Endurance-Cache-Level
X-Source
X-CACHE-KEY
X-ES-SERVER
X-Cache-Var-Map
Meta-Geo
X-RN-RSRV
X-Cache-Var
X-Path-Route
X-UUID
X-Proxy-Build
Selected-Fe
OT-Force-Account-Verify
X-Timing-Wait
X-Hyper-Cache
X-Handled-By
X-ShopId
X-Tb
X-Content-Age
X-Shopify-Stage
X-ShardId
X-Alternate-Cache-Key
X-Backend-Name
X-Shopify-Generated-Cart-Token
X-Storage
X-EIG-Tracking-Id
X-Sorting-Hat-PodId
X-Sorting-Hat-ShopId
X-Proto
X-Goog-Meta-Goog-Reserved-File-Mtime
X-ProxyCache-Status
X-JoinUs
Akamai-GRN
Cache-Tags
Azure-RegionName
Azure-SiteName
Azure-SlotName
Azure-InstanceId
NGX
X-FC-Vary-Parameters
X-Format
X-SaId
X-Request-Time
X-Web-Node
L5d-Success-Class
Decoy-Debug-TTL
Ec-Rule-Version
X-ProxyCache-Key
X-Redis-Cache
Decoy-Debug-Status
X-Qloud-Router
X-Yottaa-Metrics
X-Yottaa-Optimizations
DB-Nickname
Decoy-Debug-Key
X-Pubstack
X-PCL
X-Akamai-Request-ID2
TWC-Locale-Group
X-Viewer-Country
TWC-Privacy
X-Hl-Ver
X-Generated-By
X-OCL
X-Soup
TWC-GeoIP-LatLong
Webcakes-App-Name
X-Hosted-By
X-Vgn-Hpd-Reason
X-Akamai-Request-ID
Webcakes-Region
X-Access
X-Human
X-Origin-Hint
Webcakes-App-Version
X-FW-Dynamic
X-VWS-Id
X-AWS-Id
TWC-GeoIP-Country
X-Cache-Config
X-ServerID
Origin-Cache-Control
Origin-Edge-Control
X-Proxy
X-Section
X-LJ-Flow-ID
Now
X-Cache-Host
Property-Id
X-Debug-Cache
X-Time-Microsecs
X-Origin
Azure-Version
Node
TWC-Device-Class
TWC-Connection-Speed
S-Rt
X-BYPASS-REASON
X-CCM
Mn-Server-Ip
X-BCube-Filmed-By
X-SayCDN-TTL
X-Generated
X-Varnish-Hits
X-IP
X-Say-TTL
X-Www-Served-By
X-Site-Version
X-Locale
X-MP-GENERATED-AT
X-NYM-Debug-Backend
X-Say-Cacheable
X-Xfnlog-Site
X-RCS-CacheZone
X-Cluster-Node
Cache-Name
X-TNCMS
X-APP-VERSION
X-Loop
X-Proxy-Cache-Status
X-Amzn-Remapped-Content-Length
X-Detected-As
X-FB-TRIP-ID
X-App-Server
Viewport
X-R9-Blue-Green-Version
Cross-Origin-Window-Policy
Uber-Trace-Id
GEO-INFO
X-CS
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
Webserver
Srv
Time
X-Akamai-Transformed
Accept-Charset
X-Unique-Id
X-Drupal-Cache-Tags
X-NCache
X-From
X-Cache-Remote
X-Edge-Location
X-UA-Device-Type
X-Esi
X-Cluster-Name
X-TT-TIMESTAMP
X-Origin-CC
X-Drupal-Cache-Contexts
X-Origin-TTL
Cache-Key
Country
Mime-Version
Accept-Language
X-EC-Lua
Odigeo-Trace-Id
X-Mode
X-Newrelic-Synthetics
X-B3-Spanid
X-Backend-TTL
Ohc-File-Size
X-Microcachable
Ohc-Cache-HIT
X-CDN-Forward
X-Geo
X-No-Session
Rt-Fastcgi-Cache
X-CLOUD-TRACE-CONTEXT
X-Info
X-Forwarded-Host
Proxy-Connection
X-Labrador-Cache-Channel
X-PHP-Host
X-Real-IP
X-Magnolia-Registration
X-UPSTREAM-Address
ServedBy
Content-Disposition
X-Proxied
X-Whom
X-Zipkin-Id
Fastly-SSL
X-Routing-Service
X-Cache-Time
X-Varnish-Cache-Hits
X-ApacheServer
X-PERF
Cf-Ipcountry
X-A-Dam
X-A-Dcw
X-A-Ccd
X-A
VivaBuild
X-A-Dgt
X-A-Wwc
X-ARC
X-B-Cookie
X-Application
X-Aed
X-Accel-Expires-Debug
Viewtype
T-Server
Content-Style-Type
Fastcgi-X-Cache-Version
Content-Script-Type
BehaviorPad-Version
AsisCache
GEO-REGION-INFO
Machine
Powered-By
Rendered-Blocks
Mobile-Detection-Method
Meta-Geo-Continent
MD5-Digest
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Transaction
X-Trv-Group
X-SRCache-Key
X-Session-Fingerprint
X-ScT
X-Twitter-Response-Tags
X-Vdms-Version
X-Vtex-Remote-Cache
Xc-Version
X-Vtex-Processado-Em
X-VG-WebServer
X-VG-WebCache
X-S-Cookie
X-S
X-Destination
X-DPWN-IS-SECURE
X-Date
X-D
X-Connection-Hash
X-G
X-Geo-Header
X-Rewrite-Enabled
X-Rojux
X-Request-UUID
X-Region-Sid
X-GeoIP-Country-Code
X-UnsetCookies
X-External-Request-Id
X-App-Version
Access-Control-Request-Headers
X-Cache-Backend
User-Cache-Control
X-Device-Type
X-Sigma
X-Sigma-Backend
X-Thanos
X-Auto-Login
X-SIPLIST1
X-Bip
X-Cache-Debug
IsBot
Gh-Request-Id
Environment
X-Logging-Id
X-CUA
X-Via-Fastly
X-Contensis-Viewer-Groups
X-Cache-ASPX
X-Rocket-Build-Number
X-VC-Cache
X-Varnish-Authentication
Server-Cache-Control
X-Tumblr-Pixel-3
X-VG-TLSProxy
X-TrackingId
W
X-WebServer
Server-Surrogate-Control
X-Tec-Api-Origin
X-CACHE-GROUP
X-Tec-Api-Root
X-Tec-Api-Version
X-C
X-Debug-Log
X-Developers
X-Debug-Cookies
Web-Mar-Node
X-Debug-Cache-Store
X-App-Name
X-Debug-Cache-Fetch
X-Dispatcher-Server
X-Distil-CS
X-Fastly-Cache
X-FW-Version
X-Gamma-Serve
X-AK-Request-ID
We-Hiring
X-Distributor
X-Epic-Correlation-Id
X-Eu-Site
X-Debug-Cache-Expiry
X-Core-Mission
X-Agile-Age
X-BBXSRF
X-Cache-Info
X-Cache-Bucket
Wxu-Next-Hostname
X-Gen-Mode
Wxu-Next-Region
X-Block-Status
X-Cache-URL
X-Backend-State
X-Clientip
X-Cms-Context
X-Agile
X-Clara-WADP
X-CGP
X-Cdn-Srv
X-Agile-Id
Wxu-Next-Commit
X-Key
X-SVT-ORM-RULES
X-Sucuri-Cache
X-SVT-ORM-VERSION
X-Swa-Ws
X-TH-Server
X-Request-URI
X-Req
X-Proxy-Upstream
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Render-Time
X-Trace-Id
X-TT-LOGID
X-We-Are-Hiring
X-Webstats-RespID
X-Wikidot-Backend
X-Wikidot-Static-Cache
X-WADP-Cache
X-VServer
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Uri
X-User
X-Owner
X-OVcl-Cache
X-IN-APIGATEWAYSSL
X-IN-APIGATEWAY
X-Instart-Isnd
X-Irp-Debug
V-Age
X-Hnp-Log
X-Hit
X-Generation-Time
X-GeoIP-City
X-GoCache-CacheStatus
X-Hash
X-Li-Pop
X-LI-Proto
X-NX-Host
X-Origin-Date
X-Origin-Expires
X-OVcl
X-NodeID
X-Nginx-Cache-Key
X-LI-UUID
X-Location
X-Ms-Request-Id
X-Ms-Version
X-Generated-In
X-Li-Fabric
Country-Code
Request-EU
Countrycode
Request-Country
Cdnsip
Cdncip
Cache-Host
Mail-Subject
RNT-Time
RNT-Machine
Fastly-Backend-Name
Fastly-Soc-X-Request-Id
Kp-EeAlive
Locale
Locid
Memcached
IBM-Web2-Location
Heartbleed
FNAC-ModuleRouting
Ha-Gx-Prefs
HA-Ipaddr
Section-Io-Cache
CDCHOST
True-Client-Country-4JS
Server-Int
Apple-News-Services-Host
Apple-News-Services-Handled
AKAMAI
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
X-B3-Parentspanid
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Status
Geo-Info
X-Varnish-Beresp-Grace
X-ServiceProvider
X-Trafficlayer-App-Version
X-Platform-Server
X-Thinkindot-L3
Is-Eu
X-Reboot
X-Core-Value
X-Has-Esi
X-S-Maxage
X-JWT-State
X-Level-Front-Cache
X-Up
X-Variation
X-Is-Gdpr
X-Internal-Host
Adler-Geo
X-Matched-Rule
X-Old-Content-Length
X-NU-AKA-ACS-Version
X-Generated-On
X-NGENIX-Cache
X-Service
Server-Host
X-Cache-Tags
Thinkindot-Control
Thinkindot-CacheControl-Type
Server-ID
Thinkindot-CacheControl
X-Azure-Ref
PFcat
Platform
ServerName
X-Daa-Tunnel
X-Lb-Id
X-Rebelmouse-Surrogate-Control
X-NC
X-Refresh
X-Micro-Cache
X-Rebelmouse-Cache-Control
Fastly-SWR
X-Response-By
Fastly-SIE
Cache-Hits
X-TA-CDN-Provider
HitType
X-Servername
X-Server-W
X-SERVER
X-Server-IP
X-Cdn-Forward
X-Fetched-On
RequestId
X-CF-Powered-By
X-Nginx-Cache
X-Tb-Optimization-Total-Bytes-Saved
X-B3-SpanId
Media-Length
X-Parent-Response-Time
X-Cdn-Request-ID
Memory
X-Nc
ProcessTime
X-CSRF-Token
X-BACKEND-TTL
X-CSRF-TOKEN
Origin
X-Pjax-Url
User-Agent
X-TIME
X-Wa
X-Pf-Uncompressing
X-Air-Hostname
Geoip-Latitude
X-NGINX-Cache
Filterid
TTL
Group
X-Reqid
X-Cache-Expired-At
X-Var-Ttl
Pragrma
GeoIp-Country-Code
Esi-Enabled
X-AIR-PT
X-Unique-ID
SRV
X-Correlation-ID
X-Ua
X-Planisys-CDN-Cache
X-Sucuri-Id
X-Planisys-CDN-Rules
X-Policy
X-Planisys-CDN-TTL
X-Sucuri-ID
X-Vcl-Version
X-Rocket-Nginx-Bypass
PICS-Label
S-Cnection
X-Request-Start
Powered-By-ChinaCache
X-COUNTRY
HostName
Rt-Proxy-Cache
X-Azure-Ref-OriginShield
XServer
SN
X-Servedbyhost
X-Litespeed-Cache
X-Webkit-CSP
X-Varnish-Cacheable
X-Via-Ucdn
Magicmarker
X-Method
M-TraceId
Load-Balancing
Geoip-City
X-Varnish-Ttl
X-Fastly-Country-Code
X-Via-CDN
X-HS-Status
X-NWS-UUID-VERIFY
Ohc-Response-Time
X-FORWARDED-FOR
DSUID
X-Developer
Dnion-Transfer-Encoding
Tcn
Release
X-VCT
X-MServer
X-Cache-Grace
X-Device-Os
X-Cdn-Origin
X-Ocache
NtCoent-Length
X-LAGOON
Resin-Trace
X-ServedByHost
X-Be
X-Cache-Ttl
Who
X-Sn-Servicetimems
X-Node-Id
X-Svr
X-Zone
X-Hp-Ccpa-Warning
X-Ftr-Cache-Host
X-VHOST
Vix-Hermes-Req-Id
X-Bc
Cdn
X-MSEdge-Flight
X-MSEdge-Features
On-Server
CF-Cached-On
X-Oss-Object-Type
X-Oss-Server-Time
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
X-Oss-Storage-Class
Pics-Label
X-VCL-Version
Cteonnt-Length
X-APP
X-Ratelimit-Remaining
A
MIME-Version
X-Request-Host
X-Configured-By
Ttl
X-VarnishDD-TTL
Cloudfront-Viewer-Country
GeoIP-Country-Code
X-Oracle-Dms-Rid
X-Beluga-Cache-Status
X-Beluga-Node
X-SD-PageType
SD-X-WS
GeoIP-Latitude
X-WR-MODIFICATION
X-Fastly-Backend-Reqs
X-Varnish-URL
X-Beluga-Record
X-Beluga-Status
X-Beluga-Response-Time
X-Beluga-Trace
X-Cache-Status-Check
X-DC
X-SN
X-Cache-Id
GeoIP-City
X-Newrelic-App-Data
Hostname
X-PF-Uncompressing
X-Varnish-Url
X-PJAX-URL
X-Upstream-Ht
X-Upstream-Ct
X-Compress-Hint
X-LiteSpeed-Cache-Control
L
X-Via-NSCOPI
X-SRV
X-Tid
Host-ID
X-Release
X-Ftr-Request-Id
Processtime
X-Ratelimit-Limit
X-HostName
LB
X-BE
X-Scheme
X-Aicache-OS
X-Dynatrace
Servername
X-Dynatrace-Js-Agent
Cache-Cookie-Set-Lfrom
CDN
X-ID
Requestid
Cache-Cookie-Set-From
UCS
X-Slack-Backend
WebServer
CACHE
X-Swift-Error
Cache-Provider
X-Fastly-Cache-Hits
Cache-Cookie-Set-Idcheck
X-Frame-Option
Amp-Access-Control-Allow-Source-Origin
Dynatrace
Lfy
X-StackifyID
X-Ftr-Backend
X-Varnish-Beresp-TTL
X-Ftr-Backend-Server
Pagetype
X-DB
X-RPM
X-RPS
X-RSL
X-DW
X-DSS
X-Ftr-Balancer
X-DI
X-Action
CF-IPCountry
X-LB-ID
X-Branch-Name
X-ServerName
X-Snapshot-Date
X-Ftr-Realm
X-Ftr-Dc
X-CACHE-AGE
WZWS-RAY
X-Cc-Via
X-Cc-Req-Id
D-Cc-Upstream
X-Node-ID
X-PAYTM-SRV-ID
X-Processor
X-Server-Time
X-Skip-Cache
X-FPC
X-Fastly-Cache-Status
Arc-Country
Pramga
X-Cache-FS-Status
X-Dispatch
X-VC
Warning
V-Cache
X-Apw-Access-Action
X-Apw-Access-Object
X-Apw-Access-Token
X-Apw-Hits
X-ZONE
X-Edge-IP
Proxy-Firewall
X-SB
NnCoection
X-Check-Cacheable
X-Amzn-Remapped-Connection
X-ElasticPress-Search
X-Amzn-Remapped-Date
X-Hello
X-Flog
X-ABtesting
Server-Id
WP-Super-Cache
X-Request-URL
Correlation-Id
Backend-Name
X-Request-Url
X-BC
X-Litespeed-Cache-Control
X-App
X-Worker
Lb
X-Powered-Y