Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
Link
CF-RAY
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-UA-Compatible
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-Request-ID
X-Template
X-Language
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Iinfo
X-AspNetMvc-Version
X-Ua-Compatible
X-FRAME-OPTIONS
X-Buckets
Status
X-Content-Security-Policy
X-CDN
Upgrade
Content-Encoding
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Xss-Protection
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
Xkey
X-Pass-Why
X-Cache-Group
P3p
X-AH-Environment
X-Envoy-Upstream-Service-Time
CF-Ray
X-Backend
X-Age
X-Server
X-Via
X-Amz-Id-2
X-Amz-Request-Id
X-Robots-Tag
X-Server-Powered-By
X-Page-Speed
X-Pingback
EagleId
X-Proxy-Cache
X-Nginx-Cache-Status
X-UA-Device
X-Ws-Request-Id
X-Hacker
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
Grace
Cf-Railgun
X-Swift-CacheTime
X-Swift-SaveTime
X-Amz-Version-Id
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
X-LiteSpeed-Cache
Report-To
X-Server-Id
X-Rq
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-WebKit-CSP
X-Host
X-Device
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Origin-Cache
X-Response-Time
Content-Location
X-Node
X-Ac
Surrogate-Control
X-Vhost
X-Readtime
Request-Id
X-Backend-Server
X-Cloud-Trace-Context
X-Dispatcher
X-Origin-Upstream-Status
X-Cnection
X-HW
X-ORACLE-DMS-ECID
X-Application-Context
X-DataDome
Fusion-Component-Id
Fusion-Content-Source
Fusion-Content-Id
Fusion-Source
Fusion-Template-Id
X-ORACLE-DMS-RID
X-Cache-Lookup
X-Mod-Pagespeed
NEL
Rating
X-Rack-Cache
Edge-Control
X-Country
X-Akam-SW-Version
X-Clacks-Overhead
Pinterest-Generated-By
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-Ruxit-JS-Agent
X-Varnish-TTL
X-DynaTrace
X-Country-Code
Accept-Ch
Allow
X-Instart-Request-ID
X-Goog-Hash
X-Vname
X-PC
X-TtlSet
X-FTR-Request-ID
X-TTL
X-ESI
Verso
Accept-Ch-Lifetime
X-Powered-By-Plesk
X-Url
Service-Worker-Allowed
Content-MD5
X-Version
X-Forwarded-Proto
X-B3-TraceId
X-MS-InvokeApp
X-GitHub-Request-Id
X-Kinja
X-Exp-Variant
X-Exp-Id
X-Cdn-Fetch
X-Kinja-Build
X-GoogleNews-Bot
X-Use-Magma
X-Kinja-Revision
X-Kinja-Server
Edge-Cache-Tag
RTSS
AR-Request-ID
AR-CACHE
AR-ATIME
Ar-Sid
AR-PoweredBy
X-Px
X-D2id
X-Debug
X-Abt-Application-Version
X-Server-Name
Charset
X-NF-Request-ID
SPRequestGuid
X-Vcache
X-Amz-Server-Side-Encryption
X-Accel-Expires
X-Cached
X-MSEdge-Ref
X-Powered-CMS
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Amz-Rid
X-TEC-API-ROOT
Display
X-Middleton-Display
Pagespeed
Arr-Disable-Session-Affinity
X-Sol
Response
X-Middleton-Response
X-Navigation-Version
X-Vcap-Request-Id
X-Trace
Pinterest-Version
X-Pinterest-Rid
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Fastcgi-Cache
TCN
X-SharePointHealthScore
X-VARITI-CCR
Realpath
Public-Key-Pins
X-Client-IP
X-Cdn
Cache-Tag
Access-Control-Request-Method
X-Fastly-Request-ID
X-Upstream
S
X-Ser
MS-Author-Via
X-DynaTrace-JS-Agent
Nel
X-Shard
X-Id
SPRequestDuration
SPIisLatency
X-Hp-Webp
Nginx-Cache
X-Ezoic-Cdn
X-Mrf-Section-Lastmod
X-Content-Type
X-Mrf-Item-Lastmod
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
X-Forwarded-For
DynaTrace
X-T
X-Amz-Meta-S3cmd-Attrs
X-Amzn-Trace-Id
X-Grace
X-Recruiting
Front-End-Https
X-Hits
Fastcgi-Cache
X-Varnish-Age
X-Aspnet-Version
X-DIS-Request-ID
ServerID
X-Dw-Request-Base-Id
MicrosoftSharePointTeamServices
X-Mobile-URL
X-Edge-O15-RID
X-Element-Page-Cache
X-Node-Name
X-Content-Digest
NR-ENABLED
X-HS-Cache-Config
X-HS-Hub-Id
X-HS-Combine-CSS
X-HS-Content-Id
X-FTR-Expires
X-Goog-Generation
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Goog-Storage-Class
X-GUploader-UploadID
Powered
X-Country-Code-Real
X-Goog-Metageneration
X-FTR-Cache-Status
X-Frontend
Server-Name
X-Cache-TTL
X-FTR-Backend
Alternate-Protocol
X-FTR-DC
X-FTR-Balancer
X-FTR-Realm
X-FTR-Backend-Server
X-Logged-In
TP-Cache
TP-L2-Cache
Server-Node
X-Correlation-Id
X-Jurisdiction
X-XRDS-LOCATION
X-Webkit-Csp
X-Request-Received
X-Request-Processing-Time
X-Request-Handler-Origin-Region
X-Microsite
Backend-Timing
X-ATS-Timestamp
AMP-Access-Control-Allow-Source-Origin
X-Page-Id
Upgrade-Insecure-Requests
X-Content-Security-Policy-Report-Only
X-Content-Options
X-Shield-Request-Id
Refresh
X-User-Agent
X-Origin-Server
X-Revision
X-Rid
X-Cache-Hit
X-Akamai-Edgescape
X-F-Cache
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Varnish-Grace
X-Server-ID
X-Type
X-Webapp-Samesite-None-Activated-N
X-XRDS-Location
Fastly-Restarts
X-Content-Powered-By
X-Zen-Fury
X-Geo-Country
X-B3-Sampled
X-LB-Cache
X-B
X-Activity-Id
X-Az
X-AppVersion
X-Pad
X-URL
X-Analytics
X-FTR-Cache-Host
X-N
X-Kinsta-Cache
PB-PID
X-CST
PB-RID
X-Mobile-Rewrite
Arc-Version
X-RateLimit-Remaining
X-WebKit-CSP-Report-Only
Cache-Status
X-AOL-HN
X-TT
X-Tumblr-Pixel-0
X-Tumblr-Pixel
X-Request-Guid
Paypal-Debug-Id
X-Tumblr-User
X-Jobs
X-Ruxit-Js-Agent
X-Cache-Age
X-App-Environment
X-Instance
X-Framework
Actual-Object-TTL
DC
X-Debug-Info
Access-Control-Allow-Method
X-Signature
X-B-Cache
X-PHP-Backend
X-FB-Debug
X-Time
X-Cache-Action
X-Load-Cache
X-Varnish-Backend
X-Git-Hash
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
Surrogate-Key
X-Cached-By
Host-Header
Fastcgi-Useragent
X-Ttl
X-Tt-Trace-Tag
X-Amz-Replication-Status
X-IPLB-Instance
X-Contextid
MS-CV
X-SS-Set-Cookie
X-Tt-Trace-Host
FilterID
X-Cluster
X-ATG-Version
Tracecode
X-Srv
Frame-Options
X-Accel-Buffering
NGB
X-Response-Served-From
X-Cache-NE
X-Cache-Key
Xserver
X-FastCGI-Cache
WPE-Backend
X-FW-Serve
X-Mobile
X-WA-Info
X-FW-Hash
X-FW-Server
X-Varnish-Server
X-FW-Type
X-Region
X-FW-Static
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
X-RequestSource
X-Varnish-Hostname
Payment
X-B3-Traceid
X-Cache-2
X-Rendered-As
X-Host-Name
X-Kong-Proxy-Latency
Host
X-IPS-LoggedIn
Source
Filters
Eomportal-Instance
X-Kong-Upstream-Latency
X-Cacheable-TTL
X-Is-Bot
X-GeoIP
Cache-Tv-Group
X-Cache-Enabled
X-NewRelic-App-Data
X-TX-ID
X-Adobe-Content
X-Adobe-Loc
X-Cache-Rule
X-Cache-Operation
X-Via-JSL
Cleartype
X-Oneagent-Js-Injection
X-Hostname
X-EdgeConnect-Cache-Status
X-Origin-Response-Time
X-Seen-By
X-ORACLE-APMCS-TAG
X-ORACLE-APMCS-REQUEST-ID
X-Cache-TTL-Remaining
Cache
X-Presslabs-Stats
Retry-After
X-HTML-Minification-Powered-By
X-Cache-Control
X-VCache
Healthy
Datacenter
X-UA
Server-Info
X-ProcessESI
X-RemovedCookies
Accept-CH
X-Trafficlayer-App-Scope
X-Dc
X-Trafficlayer-App-Name
X-RTag
X-NWS-LOG-UUID
Ms-Operation-Id
Liferay-Portal
X-CACHE-KEY
X-Rule
X-Cache-Server
X-FireWall-Port
X-Source
X-L-Path
X-RateLimit-Limit
X-PressLabs-Stats
X-Environment-Context
X-Endurance-Cache-Level
From-Origin
Version
X-Upgrade-Enabled
X-Wix-Request-Id
X-Handled-By
X-Status
X-Cache-Var-Map
X-App-Server
Accept-CH-Lifetime
Meta-Geo
X-RN-RSRV
X-ES-SERVER
X-Path-Route
X-Cache-Var
X-Timing-Wait
X-Proxy-Build
Selected-Fe
OT-Force-Account-Verify
X-Backend-Name
Akamai-GRN
X-Akamai-Request-ID
X-Proto
X-Storage
X-Format
Cache-Tags
X-Access
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Tb
X-Section
Mn-Server-Ip
Webcakes-App-Version
Webcakes-Region
X-Akamai-Request-ID2
Azure-SiteName
Webcakes-App-Name
Property-Id
Ec-Rule-Version
Azure-Version
Now
X-Web-Node
Decoy-Debug-Status
DB-Nickname
Decoy-Debug-Key
Origin-Cache-Control
Origin-Edge-Control
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Locale-Group
TWC-Device-Class
Azure-SlotName
S-Rt
TWC-Connection-Speed
TWC-Privacy
X-Sorting-Hat-ShopId
X-Generated-By
X-Hl-Ver
X-Hosted-By
X-Hyper-Cache
X-FW-Dynamic
X-Proxy
X-EIG-Tracking-Id
X-FC-Vary-Parameters
X-Vgn-Hpd-Reason
X-BYPASS-REASON
X-ProxyCache-Status
X-Viewer-Country
X-PCL
X-OCL
X-Origin
X-Human
X-ProxyCache-Key
X-JoinUs
X-LJ-Flow-ID
X-Origin-Hint
X-Request-Time
Azure-RegionName
X-SaId
X-Redis-Cache
X-Qloud-Router
X-Shopify-Stage
X-ServerID
X-ShardId
X-Alternate-Cache-Key
X-AWS-Id
X-ShopId
X-Sorting-Hat-PodId
X-Pubstack
X-Content-Age
X-Debug-Cache
X-Soup
X-Time-Microsecs
X-Cluster-Node
X-Cache-Host
X-Proxy-Cache-Status
X-VWS-Id
X-Cache-Config
X-Shopify-Generated-Cart-Token
Decoy-Debug-TTL
X-Yottaa-Metrics
X-Yottaa-Optimizations
Azure-InstanceId
X-Locale
X-Detected-As
X-Www-Served-By
X-Xfnlog-Site
X-SayCDN-TTL
X-IP
X-Varnish-Hits
X-RCS-CacheZone
X-Say-Cacheable
X-Site-Version
X-UUID
X-APP-VERSION
X-BCube-Filmed-By
Node
X-Say-TTL
X-CCM
Cross-Origin-Window-Policy
X-MP-GENERATED-AT
X-Generated
NGX
X-NYM-Debug-Backend
X-Loop
X-Amzn-Remapped-Content-Length
X-TNCMS
X-FB-TRIP-ID
X-R9-Blue-Green-Version
L5d-Success-Class
GEO-INFO
Accept-Charset
X-Akamai-Transformed
Viewport
X-CS
Uber-Trace-Id
Cache-Name
Srv
X-NCache
X-Unique-Id
X-Drupal-Cache-Tags
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-UA-Device-Type
X-Esi
X-From
X-Cache-Remote
Webserver
Time
X-TT-TIMESTAMP
Cache-Key
Mime-Version
X-Cluster-Name
X-Origin-TTL
X-Origin-CC
Accept-Language
X-Edge-Location
X-Drupal-Cache-Contexts
X-Backend-TTL
Country
X-CDN-Forward
X-EC-Lua
Odigeo-Trace-Id
Rt-Fastcgi-Cache
X-B3-Spanid
X-Mode
X-Forwarded-Host
X-Microcachable
X-Info
X-Geo
Ohc-File-Size
Ohc-Cache-HIT
X-Newrelic-Synthetics
X-Whom
X-CLOUD-TRACE-CONTEXT
X-UnsetCookies
X-Magnolia-Registration
X-PERF
X-ApacheServer
X-No-Session
Proxy-Connection
Content-Disposition
X-Varnish-Cache-Hits
ServedBy
X-UPSTREAM-Address
X-Labrador-Cache-Channel
X-PHP-Host
X-Zipkin-Id
X-Routing-Service
X-Real-IP
X-Device-Type
X-Proxied
X-CF-Lambda-Version
X-CF-Lambda-Fn
X-Region-Sid
X-Connection-Hash
X-D
Rendered-Blocks
X-B-Cookie
X-Request-UUID
X-Application
T-Server
X-ARC
X-Date
X-Transaction
X-Twitter-Response-Tags
MD5-Digest
X-GeoIP-Country-Code
Meta-Geo-Continent
X-Geo-Header
X-G
X-Trv-Group
X-Destination
X-DPWN-IS-SECURE
X-External-Request-Id
Viewtype
X-Aed
X-A-Dam
X-A-Dcw
Content-Style-Type
X-Via-Fastly
X-A-Ccd
AsisCache
X-A
X-S-Cookie
X-ScT
BehaviorPad-Version
X-S
Mobile-Detection-Method
X-Rewrite-Enabled
X-A-Wwc
Machine
X-Accel-Expires-Debug
VivaBuild
X-Rojux
X-Session-Fingerprint
X-A-Dgt
Fastcgi-X-Cache-Version
GEO-REGION-INFO
Content-Script-Type
X-SRCache-Key
X-Vdms-Version
X-Cache-Time
Xc-Version
X-VG-WebServer
Cf-Ipcountry
X-App-Version
X-Vtex-Remote-Cache
X-Vtex-Processado-Em
X-NGENIX-Cache
X-VG-WebCache
User-Cache-Control
X-C
X-Uri
Fastly-SSL
X-WebServer
X-Auto-Login
X-Wikidot-Backend
Gh-Request-Id
X-Sigma-Backend
Access-Control-Request-Headers
Locid
IsBot
X-Sigma
Fastly-Soc-X-Request-Id
Apple-News-Services-Parsed-Url
X-Bip
X-Rocket-Build-Number
Apple-News-Services-Handled
X-Developers
X-SIPLIST1
X-Wikidot-Static-Cache
Apple-News-Services-Request-Url
Apple-News-Services-Host
X-Tumblr-Pixel-3
X-Cache-Debug
X-CUA
X-Logging-Id
X-TrackingId
X-Thanos
X-Cache-Backend
X-Nc
X-GoCache-CacheStatus
X-Cms-Context
Server-Int
Server-ID
X-Origin-Expires
X-RateLimit-Limit-Second
Server-Surrogate-Control
X-Dispatcher-Server
X-Clientip
X-FW-Version
X-Daa-Tunnel
X-RateLimit-Remaining-Second
X-Gamma-Serve
True-Client-Country-4JS
X-Gen-Mode
Request-Country
Request-EU
X-Epic-Correlation-Id
X-Contensis-Viewer-Groups
X-Hash
Powered-By
X-GeoIP-City
X-Generation-Time
V-Age
X-Origin-Date
X-Generated-In
RNT-Time
RNT-Machine
Server-Cache-Control
Web-Mar-Node
X-OVcl
X-AK-Request-ID
X-Cache-Info
X-Distil-CS
X-Cache-URL
X-Debug-Cache-Fetch
X-Cache-Bucket
X-Cache-ASPX
X-BBXSRF
X-Owner
X-Block-Status
X-Debug-Cache-Expiry
X-Azure-Ref
X-Debug-Cache-Store
X-Sucuri-Cache
Wxu-Next-Commit
Wxu-Next-Hostname
X-OVcl-Cache
We-Hiring
X-Debug-Log
X-Proxy-Upstream
Wxu-Next-Region
X-Debug-Cookies
X-Render-Time
X-Cdn-Srv
X-VG-TLSProxy
X-Hit
X-Eu-Site
X-Clara-WADP
Kp-EeAlive
X-Li-Pop
AKAMAI
X-LI-Proto
X-LI-UUID
X-SVT-ORM-RULES
X-NodeID
CDCHOST
X-Li-Fabric
X-VC-Cache
Cdncip
Cache-Host
X-Key
Ha-Gx-Prefs
X-CGP
X-SVT-ORM-VERSION
X-Webstats-RespID
X-Micro-Cache
X-NX-Host
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Status
X-Ms-Request-Id
X-Varnish-Beresp-Grace
X-Ms-Version
X-Trace-Id
X-Swa-Ws
X-TT-LOGID
X-TH-Server
X-We-Are-Hiring
X-Location
X-WADP-Cache
X-VServer
Cdnsip
X-Urbn-Site-Id
Locale
X-IN-APIGATEWAY
X-Core-Mission
HA-Ipaddr
X-IN-APIGATEWAYSSL
X-App-Name
Mail-Subject
X-Backend-State
X-User
X-Req
Memcached
X-Hnp-Log
X-Request-URI
Heartbleed
X-Instart-Isnd
Countrycode
Country-Code
Fastly-Backend-Name
X-Agile-Age
X-Agile
X-Nginx-Cache-Key
X-Varnish-Authentication
FNAC-ModuleRouting
X-Agile-Id
X-Irp-Debug
W
X-Urbn-Context-Path
Environment
HitType
Geo-Info
X-B3-Parentspanid
X-NU-AKA-ACS-Version
X-Level-Front-Cache
X-Internal-Host
X-Generated-On
X-Has-Esi
X-Fastly-Cache
X-Distributor
X-Old-Content-Length
X-JWT-State
X-Is-Gdpr
X-Matched-Rule
Section-Io-Cache
PFcat
Is-Eu
IBM-Web2-Location
X-Reboot
X-Rebelmouse-Surrogate-Control
Server-Host
X-Variation
Fastly-SWR
Fastly-SIE
X-Thinkindot-L3
X-Trafficlayer-App-Version
X-ServiceProvider
X-Service
X-S-Maxage
Adler-Geo
Thinkindot-CacheControl
Platform
X-Rebelmouse-Cache-Control
X-Platform-Server
Thinkindot-Control
X-Cache-Tags
Thinkindot-CacheControl-Type
X-Response-By
X-Server-W
X-Core-Value
X-Fetched-On
Cache-Hits
X-Lb-Id
X-Refresh
X-Up
ServerName
Filterid
X-Nginx-Cache
X-TA-CDN-Provider
X-SERVER
X-Servername
RequestId
X-B3-SpanId
X-Server-IP
ProcessTime
X-Cdn-Forward
X-CF-Powered-By
X-Tec-Api-Root
X-Tec-Api-Origin
X-Air-Hostname
X-CSRF-Token
X-Tec-Api-Version
X-Pjax-Url
X-Parent-Response-Time
X-Tb-Optimization-Total-Bytes-Saved
X-CSRF-TOKEN
Pragrma
X-Cache-Expired-At
X-Cdn-Request-ID
X-NC
Origin
Media-Length
Memory
Group
X-BACKEND-TTL
SRV
X-Var-Ttl
User-Agent
X-Wa
Geoip-Latitude
TTL
X-Pf-Uncompressing
X-Vcl-Version
S-Cnection
GeoIp-Country-Code
Powered-By-ChinaCache
X-Correlation-ID
X-Unique-ID
X-Ua
X-NGINX-Cache
X-Sucuri-ID
X-Sucuri-Id
X-Rocket-Nginx-Bypass
PICS-Label
X-AIR-PT
Esi-Enabled
X-COUNTRY
X-Reqid
Geoip-City
X-TIME
X-Policy
SN
X-Planisys-CDN-Cache
X-Varnish-Cacheable
X-Planisys-CDN-TTL
X-Planisys-CDN-Rules
HostName
X-Webkit-CSP
X-Via-CDN
X-Request-Start
X-Litespeed-Cache
X-Azure-Ref-OriginShield
X-Servedbyhost
X-Developer
X-Via-Ucdn
X-NWS-UUID-VERIFY
Rt-Proxy-Cache
XServer
X-Sn-Servicetimems
X-Ocache
X-Device-Os
X-Node-Id
X-Cache-Grace
X-Cdn-Origin
M-TraceId
X-HS-Status
Dnion-Transfer-Encoding
X-FORWARDED-FOR
Resin-Trace
Magicmarker
X-LAGOON
X-Fastly-Country-Code
X-Method
Tcn
X-ServedByHost
Cdn
On-Server
Load-Balancing
X-Cache-Ttl
X-Request-Host
Who
A
X-VHOST
X-Ftr-Cache-Host
CF-Cached-On
X-MSEdge-Features
Cloudfront-Viewer-Country
X-MSEdge-Flight
Ohc-Response-Time
X-Oss-Request-Id
X-Oss-Storage-Class
X-Oss-Server-Time
DSUID
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Cache-Status-Check
X-Svr
Pics-Label
X-Beluga-Trace
X-Beluga-Cache-Status
NtCoent-Length
X-Beluga-Status
X-Beluga-Record
X-Beluga-Node
X-Beluga-Response-Time
Release
X-Be
X-MServer
X-VCT
X-Varnish-Url
GeoIP-Country-Code
X-VCL-Version
X-APP
X-Zone
X-Bc
Vix-Hermes-Req-Id
MIME-Version
X-Oracle-Dms-Rid
X-Hp-Ccpa-Warning
Hostname
X-Ratelimit-Remaining
GeoIP-Latitude
Host-ID
Cteonnt-Length
X-Fastly-Backend-Reqs
Ttl
WebServer
X-VarnishDD-TTL
X-Varnish-Ttl
X-LiteSpeed-Cache-Control
X-DC
X-PF-Uncompressing
X-Configured-By
X-Varnish-URL
X-Newrelic-App-Data
GeoIP-City
Servername
X-Ftr-Request-Id
X-Upstream-Ct
X-PJAX-URL
X-Upstream-Ht
SD-X-WS
X-Slack-Backend
Amp-Access-Control-Allow-Source-Origin
X-SRV
X-SD-PageType
X-WR-MODIFICATION
X-HostName
X-BE
X-DW
X-RPM
X-RSL
X-RPS
X-DSS
X-DB
Processtime
X-Cache-Id
X-Compress-Hint
X-SN
X-Aicache-OS
X-Action
X-DI
X-Tid
X-Dynatrace
X-Ratelimit-Limit
X-Dynatrace-Js-Agent
X-Dispatch
L
X-Cache-FS-Status
Pramga
CACHE
Arc-Country
X-Via-NSCOPI
X-FPC
X-ID
Cache-Provider
X-Release
X-Skip-Cache
X-Server-Time
X-Swift-Error
X-Processor
X-PAYTM-SRV-ID
X-Frame-Option
X-StackifyID
Fastly-Drupal-HTML
X-DevSite-Last-Modified
X-ND-Cache
X-Ftr-Backend-Server
LB
X-Ftr-Dc
X-ServerName
Dynatrace
X-Ftr-Balancer
X-Ftr-Realm
X-Ftr-Backend
Lfy
X-Fastly-Cache-Hits
CF-IPCountry
X-Snapshot-Date
X-LB-ID
CDN
X-Branch-Name
Pagetype
Requestid
X-Scheme
X-CACHE-AGE
Cache-Cookie-Set-Lfrom
X-Apw-Access-Action
X-Apw-Access-Object
X-Node-ID
Cache-Cookie-Set-Idcheck
X-Apw-Hits
Proxy-Firewall
X-ABtesting
X-Flog
N-Cache
X-Edge-Server
X-Served-From
Cdn-Request-Time
Cdn-Host
X-Hello
X-Apw-Access-Token
UCS
X-Edge-IP
X-Request-Url
X-SB
D-Cc-Upstream
X-ZONE
X-VC
Warning
X-Varnish-Beresp-TTL
Cache-Cookie-Set-From
X-Cc-Via
V-Cache
X-Cc-Req-Id
NnCoection
X-WA
X-Request-URL
X-Litespeed-Cache-Control
WP-Super-Cache
X-Powered-Y
X-App
Lb
X-ElasticPress-Search
X-Worker
X-Fastly-Cache-Status
Backend-Name
X-BC
Correlation-Id
X-Check-Cacheable