Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-Powered-By
Pragma
CF-Cache-Status
Link
X-XSS-Protection
ETag
CF-RAY
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Request-Id
X-Download-Options
X-AspNet-Version
Access-Control-Allow-Credentials
X-Xss-Protection
X-Runtime
CF-Ray
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Cache-Status
Content-Security-Policy-Report-Only
X-Generator
X-Permitted-Cross-Domain-Policies
X-Cacheable
X-Request-ID
X-DNS-Prefetch-Control
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-AspNetMvc-Version
X-FRAME-OPTIONS
X-Buckets
Status
Upgrade
X-Content-Security-Policy
Content-Encoding
X-CDN
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Kinja-Server-Push
Keep-Alive
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
X-Pass-Why
X-Cache-Group
X-AH-Environment
X-Envoy-Upstream-Service-Time
Xkey
X-Via
X-Backend
X-Server
X-Age
X-Ua-Compatible
X-Ws-Request-Id
X-Amz-Request-Id
X-Amz-Id-2
X-Robots-Tag
X-Page-Speed
X-Server-Powered-By
EagleId
X-Pingback
X-Proxy-Cache
X-Hacker
X-Nginx-Cache-Status
Request-Context
X-UA-Device
Feature-Policy
Server-Timing
X-Varnish-Cache
X-Swift-SaveTime
X-Swift-CacheTime
Cf-Railgun
Grace
Ali-Swift-Global-Savetime
X-Amz-Version-Id
Report-To
X-LiteSpeed-Cache
X-Rq
X-OneAgent-JS-Injection
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-WebKit-CSP
X-Device
X-Host
X-Server-Id
X-Origin-Cache
X-Response-Time
EagleEye-TraceId
X-Node
X-Ac
Surrogate-Control
Content-Location
X-Backend-Server
X-Cloud-Trace-Context
X-Vhost
X-Readtime
X-Dispatcher
Request-Id
X-Ruxit-JS-Agent
X-Origin-Upstream-Status
X-Cache-Lookup
X-Cnection
X-Application-Context
X-HW
Fusion-Content-Id
Fusion-Content-Source
Fusion-Source
Fusion-Template-Id
Fusion-Component-Id
X-ORACLE-DMS-ECID
X-Mod-Pagespeed
X-ORACLE-DMS-RID
NEL
X-DataDome
X-Rack-Cache
X-Country
X-Clacks-Overhead
P3p
Rating
Edge-Control
X-Akam-SW-Version
X-Dns-Prefetch-Control
Pinterest-Generated-By
Allow
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-TTL
Accept-Ch
X-Country-Code
X-FTR-Request-ID
X-Varnish-TTL
X-Instart-Request-ID
X-DynaTrace
X-Goog-Hash
X-TtlSet
X-PC
X-Vname
X-ESI
Verso
Content-MD5
Accept-Ch-Lifetime
Service-Worker-Allowed
X-Powered-By-Plesk
X-Url
X-Vcache
X-B3-TraceId
X-Version
X-Forwarded-Proto
X-GitHub-Request-Id
X-Kinja-Revision
X-Cdn-Fetch
X-Kinja-Build
X-Exp-Id
X-Exp-Variant
X-GoogleNews-Bot
X-Kinja
X-Use-Magma
X-Kinja-Server
X-MS-InvokeApp
RTSS
X-Server-Name
X-D2id
X-Abt-Application-Version
X-Px
Edge-Cache-Tag
X-Server-ID
X-Debug
AR-PoweredBy
AR-CACHE
AR-ATIME
Ar-Sid
AR-Request-ID
X-Amz-Server-Side-Encryption
SPRequestGuid
Charset
X-Cached
X-NF-Request-ID
X-TEC-API-VERSION
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-Navigation-Version
X-Vcap-Request-Id
X-MSEdge-Ref
X-Middleton-Response
X-Middleton-Display
Response
Pagespeed
Display
X-Sol
X-Accel-Expires
X-Amz-Rid
Arr-Disable-Session-Affinity
TCN
X-Fastcgi-Cache
X-Pinterest-Rid
Pinterest-Version
X-SharePointHealthScore
X-VARITI-CCR
Public-Key-Pins
X-Fastly-Request-ID
X-Powered-CMS
X-SRCache-Fetch-Status
X-SRCache-Store-Status
MS-Author-Via
Nginx-Cache
X-Trace
X-Cdn
X-Client-IP
X-Edge-O15-RID
Cache-Tag
Realpath
X-Ser
Access-Control-Request-Method
X-Content-Type
Nel
X-Mrf-Item-Lastmod
Mrf-Cache-Status
X-Mrf-Section-Lastmod
MRF-Tech
X-B3-TraceId-Primal
X-Amzn-Trace-Id
SPIisLatency
SPRequestDuration
X-Shard
X-Upstream
X-Hp-Webp
X-Jurisdiction
X-Id
X-Grace
X-Ezoic-Cdn
X-DynaTrace-JS-Agent
S
X-Forwarded-For
Front-End-Https
X-Amz-Meta-S3cmd-Attrs
X-Hits
X-Cache-TTL
X-T
Fastcgi-Cache
DynaTrace
X-Recruiting
X-Aspnet-Version
X-Element-Page-Cache
X-Node-Name
X-Varnish-Age
X-Content-Digest
X-Dw-Request-Base-Id
X-Country-Code-Real
X-FTR-Realm
X-FTR-Backend
X-FTR-Balancer
X-FTR-Backend-Server
X-FTR-DC
X-Mobile-URL
X-FTR-Cache-Status
X-FTR-Expires
ServerID
MicrosoftSharePointTeamServices
X-DIS-Request-ID
Server-Node
NR-ENABLED
TP-L2-Cache
X-HS-Hub-Id
TP-Cache
X-HS-Cache-Config
X-Frontend
X-HS-Content-Id
X-HS-Combine-CSS
X-Goog-Generation
X-Goog-Storage-Class
X-Goog-Metageneration
X-Goog-Stored-Content-Length
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
Powered
X-Logged-In
X-CST
Alternate-Protocol
Server-Name
X-Amz-Apigw-Id
X-Correlation-Id
X-Amzn-RequestId
Upgrade-Insecure-Requests
X-Cache-Hit
X-FTR-Cache-Host
Fastly-Restarts
X-Microsite
X-Request-Handler-Origin-Region
X-ATS-Timestamp
X-XRDS-Location
Backend-Timing
X-Page-Id
AMP-Access-Control-Allow-Source-Origin
X-Request-Received
X-Content-Options
X-Request-Processing-Time
X-User-Agent
X-F-Cache
X-Content-Security-Policy-Report-Only
X-Zen-Fury
Refresh
X-Origin-Server
X-Varnish-Grace
X-Rid
X-Akamai-Edgescape
X-XRDS-LOCATION
X-Revision
X-B
X-Type
X-Content-Powered-By
PB-PID
X-LB-Cache
PB-RID
X-Mobile-Rewrite
Arc-Version
X-B3-Sampled
X-Geo-Country
Cache-Status
X-Az
X-AppVersion
X-Activity-Id
X-URL
X-Kinsta-Cache
X-N
X-Cache-Action
X-Cache-Age
X-B-Cache
X-TT
X-WebKit-CSP-Report-Only
X-Signature
X-Jobs
X-Framework
Access-Control-Allow-Method
X-Debug-Info
X-FB-Debug
X-Instance
X-Request-Guid
X-AOL-HN
X-Time
X-Cached-By
Paypal-Debug-Id
X-Git-Hash
X-Tumblr-Pixel
Actual-Object-TTL
X-Tumblr-User
X-Tumblr-Pixel-0
X-Load-Cache
X-App-Environment
X-NWS-LOG-UUID
X-PHP-Backend
Fastcgi-Useragent
X-Pad
X-Tt-Trace-Host
X-Tt-Trace-Tag
DC
X-Shield-Request-Id
X-Amz-Replication-Status
X-Varnish-Backend
X-RateLimit-Remaining
X-Webkit-Csp
Host-Header
Host
X-WA-Info
X-ATG-Version
X-IPLB-Instance
Surrogate-Key
MS-CV
X-ORACLE-APMCS-TAG
X-Contextid
X-ORACLE-APMCS-REQUEST-ID
X-Via-JSL
X-Mobile
X-Erf-Bev-Bev-Is-Generated
X-Kong-Proxy-Latency
X-Erf-Bev-Bev
X-Kong-Upstream-Latency
X-Host-Name
X-Response-Served-From
FilterID
Frame-Options
X-Accel-Buffering
NGB
X-FastCGI-Cache
Payment
Retry-After
Tracecode
Source
X-SS-Set-Cookie
X-Cache-NE
Xserver
X-Varnish-Server
X-Region
X-Cache-2
X-Hostname
X-GeoIP
X-Srv
X-Rendered-As
Eomportal-Instance
X-FW-Type
WPE-Backend
X-FW-Hash
X-FW-Static
X-Cacheable-TTL
Filters
X-FW-Serve
X-Cluster
X-FW-Server
X-Is-Bot
X-Origin-Response-Time
X-Presslabs-Stats
Cache-Tv-Group
X-Cache-Enabled
X-IPS-LoggedIn
X-Varnish-Hostname
X-RequestSource
X-Tumblr-Pixel-1
X-Tumblr-Pixel-2
X-Cache-Operation
Liferay-Portal
X-NewRelic-App-Data
X-Cache-Rule
X-Seen-By
X-Adobe-Content
X-Adobe-Loc
X-Cache-Key
Server-Info
X-App-Server
X-TX-ID
X-RemovedCookies
X-EdgeConnect-Cache-Status
X-ProcessESI
X-Analytics
X-Cache-TTL-Remaining
X-CACHE-KEY
Cleartype
X-Webapp-Samesite-None-Activated-N
X-L-Path
Accept-CH
X-Environment-Context
X-FireWall-Port
X-Handled-By
X-B3-Traceid
X-Upgrade-Enabled
X-Source
X-RTag
Ms-Operation-Id
X-Endurance-Cache-Level
X-Dc
X-HTML-Minification-Powered-By
X-Cache-Server
From-Origin
X-UA
Accept-Charset
X-Backend-Name
Datacenter
Srv
X-APP-VERSION
X-UUID
Accept-CH-Lifetime
Meta-Geo
X-Cache-Var-Map
X-Cache-Var
X-RN-RSRV
X-ES-SERVER
X-Path-Route
Selected-Fe
X-Access
X-Section
X-Proxy-Build
X-Format
X-Timing-Wait
Healthy
OT-Force-Account-Verify
X-Alternate-Cache-Key
X-EIG-Tracking-Id
Mn-Server-Ip
Cache-Tags
X-Content-Age
X-Cache-Config
X-Tb
X-Sorting-Hat-PodId
X-PressLabs-Stats
X-Sorting-Hat-ShopId
X-ShopId
X-Request-Time
X-Wix-Request-Id
X-Goog-Meta-Goog-Reserved-File-Mtime
X-Shopify-Generated-Cart-Token
X-ShardId
X-Shopify-Stage
X-BYPASS-REASON
X-Soup
X-Yottaa-Metrics
X-AWS-Id
X-OCL
NGX
X-PCL
X-FC-Vary-Parameters
X-VWS-Id
X-Vgn-Hpd-Reason
X-Akamai-Request-ID2
X-Akamai-Request-ID
X-Yottaa-Optimizations
Akamai-GRN
X-ServerID
X-JoinUs
X-Proxy-Cache-Status
X-NYM-Debug-Backend
X-Hl-Ver
X-Origin
X-Proto
X-ProxyCache-Key
X-ProxyCache-Status
X-Qloud-Router
X-SaId
X-LJ-Flow-ID
X-Debug-Cache
X-Hosted-By
X-Human
Node
Ec-Rule-Version
DB-Nickname
Cross-Origin-Window-Policy
X-SayCDN-TTL
X-Web-Node
Decoy-Debug-Key
Decoy-Debug-Status
X-Say-TTL
Origin-Edge-Control
Decoy-Debug-TTL
X-Say-Cacheable
X-Loop
X-Storage
X-FW-Dynamic
X-Time-Microsecs
X-Status
X-CCM
X-Detected-As
X-Pubstack
X-FB-TRIP-ID
X-Proxy
X-Locale
X-Www-Served-By
Version
X-Viewer-Country
X-MP-GENERATED-AT
X-BCube-Filmed-By
X-TNCMS
Origin-Cache-Control
Now
GEO-INFO
TWC-GeoIP-Country
TWC-GeoIP-LatLong
TWC-Device-Class
TWC-Connection-Speed
Property-Id
X-Xfnlog-Site
S-Rt
TWC-Locale-Group
TWC-Privacy
Webcakes-App-Version
Webcakes-Region
X-Amzn-Remapped-Content-Length
Webcakes-App-Name
X-Generated-By
X-Generated
X-R9-Blue-Green-Version
X-Akamai-Transformed
X-Redis-Cache
Azure-SiteName
X-Varnish-Hits
X-RCS-CacheZone
X-Hyper-Cache
Azure-Version
X-IP
Azure-SlotName
Azure-RegionName
Azure-InstanceId
X-Origin-Hint
X-CLOUD-TRACE-CONTEXT
X-Site-Version
X-NCache
X-Cluster-Node
X-Cache-Control
X-RateLimit-Limit
X-Unique-Id
X-Whom
X-Daa-Tunnel
Cache
Cache-Key
X-Cache-Host
X-Ttl
X-Drupal-Cache-Tags
X-UA-Device-Type
X-NGENIX-Cache
X-Rule
L5d-Success-Class
X-Mode
Webserver
X-Backend-TTL
X-Forwarded-Host
X-Esi
Time
X-CS
Section-Io-Cache
Viewport
Mime-Version
Content-Disposition
X-UnsetCookies
Cache-Name
X-Info
X-VHOST
Accept-Language
X-ApacheServer
X-PERF
X-Varnish-Cache-Hits
X-CDN-Forward
Rt-Fastcgi-Cache
X-Origin-TTL
X-Origin-CC
Uber-Trace-Id
Country
X-Newrelic-Synthetics
ServedBy
X-B3-Spanid
Odigeo-Trace-Id
X-Cache-Remote
X-Routing-Service
X-Device-Type
X-Proxied
X-Zipkin-Id
X-EC-Lua
X-From
X-VCache
X-Via-Fastly
X-Magnolia-Registration
X-Uri
Proxy-Connection
X-Cluster-Name
X-Drupal-Cache-Contexts
X-Microcachable
X-Real-IP
Access-Control-Request-Headers
X-Geo
HitType
Geo-Info
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
Ohc-File-Size
X-TT-TIMESTAMP
W
X-SRCache-Key
X-A
X-Sigma-Backend
VivaBuild
Viewtype
X-Nc
Rendered-Blocks
T-Server
Xc-Version
X-A-Ccd
X-Sigma
X-A-Dcw
X-Session-Fingerprint
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
Apple-News-Services-Host
X-A-Dam
X-G
Apple-News-Services-Parsed-Url
X-Transaction
X-Vtex-Remote-Cache
GEO-REGION-INFO
X-Vtex-Processado-Em
Fastcgi-X-Cache-Version
Content-Style-Type
AsisCache
BehaviorPad-Version
Content-Script-Type
X-VG-WebServer
X-VG-WebCache
X-Twitter-Response-Tags
X-ScT
X-Trv-Group
Mobile-Detection-Method
Meta-Geo-Continent
X-Vdms-Version
Machine
MD5-Digest
Apple-News-Services-Request-Url
X-Varnish-Beresp-Ttl
X-Connection-Hash
X-D
X-CF-Lambda-Version
X-B-Cookie
X-Application
X-ARC
X-Date
X-Destination
X-External-Request-Id
X-Geo-Header
Apple-News-Services-Handled
X-GeoIP-Country-Code
X-DPWN-IS-SECURE
X-Region-Sid
X-CF-Lambda-Fn
X-Accel-Expires-Debug
X-S-Cookie
X-S
X-Aed
X-Rojux
X-Rocket-Build-Number
X-A-Wwc
X-Rewrite-Enabled
X-A-Dgt
X-Request-UUID
X-C
Cf-Ipcountry
X-PHP-Host
X-Labrador-Cache-Channel
X-Cache-Time
X-Agile
Fastly-Soc-X-Request-Id
Countrycode
Fastly-SIE
X-Eu-Site
X-Hit
X-WebServer
CDCHOST
X-Distil-CS
X-Developers
Ha-Gx-Prefs
X-Bip
X-Cache-Debug
X-Cache-Expired-At
X-Rebelmouse-Cache-Control
X-Rebelmouse-Surrogate-Control
X-Thanos
Powered-By
X-Var-Ttl
X-Agile-Id
X-Clientip
X-App-Name
X-Agile-Age
X-VG-TLSProxy
HA-Ipaddr
Locid
X-CGP
Fastly-SWR
X-Backend-State
Cache-Hits
Group
User-Cache-Control
Filterid
X-No-Session
Fastly-SSL
X-GoCache-CacheStatus
Server-ID
Server-Cache-Control
X-Servername
RNT-Time
Server-Int
Server-Surrogate-Control
True-Client-Country-4JS
X-LI-UUID
X-LI-Proto
X-Cache-Tags
RNT-Machine
X-Cdn-Srv
X-SVT-ORM-RULES
Platform
X-SVT-ORM-VERSION
X-Li-Fabric
Pragrma
X-SIPLIST1
Request-EU
Request-Country
X-Li-Pop
X-Cache-ASPX
V-Age
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-Nginx-Cache-Key
X-Ms-Version
X-Proxy-Upstream
X-Air-Hostname
X-OVcl
X-Owner
X-Platform-Server
Adler-Geo
X-Ms-Request-Id
X-Fetched-On
X-NX-Host
X-Logging-Id
X-Hash
X-NodeID
We-Hiring
X-Request-URI
X-Auto-Login
X-Has-Esi
X-OVcl-Cache
X-Swa-Ws
X-VServer
X-Generated-In
Environment
X-Is-Gdpr
Fastly-Backend-Name
X-Gamma-Serve
X-Variation
X-Varnish-Authentication
X-TH-Server
X-VC-Cache
Country-Code
X-Wikidot-Backend
X-Dispatcher-Server
X-TrackingId
X-IN-APIGATEWAYSSL
AKAMAI
X-Instart-Isnd
Cache-Host
X-Wikidot-Static-Cache
X-Debug-Cookies
X-Debug-Log
X-Urbn-Site-Id
X-CUA
X-Urbn-Context-Path
Kp-EeAlive
IsBot
Is-Eu
Mail-Subject
X-GeoIP-City
X-JWT-State
X-Contensis-Viewer-Groups
Locale
Ohc-Cache-HIT
X-Cms-Context
X-Tumblr-Pixel-3
X-IN-APIGATEWAY
Gh-Request-Id
X-Epic-Correlation-Id
Heartbleed
X-Core-Mission
X-Trace-Id
X-Edge-Location
X-Azure-Ref
X-Clara-WADP
X-Level-Front-Cache
X-Irp-Debug
X-Matched-Rule
X-Cache-URL
X-Cache-Info
X-Micro-Cache
X-BBXSRF
X-Debug-Cache-Fetch
X-Debug-Cache-Expiry
X-Debug-Cache-Store
Thinkindot-CacheControl
X-Up
FNAC-ModuleRouting
X-WADP-Cache
IBM-Web2-Location
ServerName
Memcached
X-Trafficlayer-App-Scope
X-Trafficlayer-App-Version
X-We-Are-Hiring
X-Webstats-RespID
X-Hnp-Log
X-NU-AKA-ACS-Version
X-Generated-On
X-Gen-Mode
X-Block-Status
Web-Mar-Node
Cdnsip
Cdncip
X-Trafficlayer-App-Name
X-Thinkindot-L3
Wxu-Next-Region
Wxu-Next-Hostname
Wxu-Next-Commit
X-Req
X-App-Version
X-Origin-Expires
X-AK-Request-ID
X-Reboot
X-Generation-Time
X-FW-Version
X-Service
X-ServiceProvider
PFcat
Server-Host
X-Server-W
Thinkindot-Control
Thinkindot-CacheControl-Type
X-Distributor
X-Origin-Date
X-UPSTREAM-Address
S-Cnection
X-S-Maxage
X-TT-LOGID
X-Core-Value
X-Cache-Bucket
X-Response-By
X-Old-Content-Length
X-Fastly-Cache
X-Lb-Id
X-Nginx-Cache
X-Refresh
X-Wa
X-Render-Time
X-SERVER
RequestId
X-Cache-Backend
X-User
X-Varnish-Cacheable
Powered-By-ChinaCache
X-Sucuri-ID
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Oss-Server-Time
X-NC
X-Oss-Storage-Class
X-Oss-Request-Id
X-CSRF-TOKEN
X-Key
X-Internal-Host
X-TA-CDN-Provider
X-Pjax-Url
X-Tec-Api-Origin
X-Tec-Api-Root
X-Developer
User-Agent
X-Parent-Response-Time
Origin
X-Sucuri-Cache
X-Tec-Api-Version
X-Node-Id
X-Ua
X-Cache-Status-Check
X-Ua-Device
X-CSRF-Token
X-Location
SRV
X-Tb-Optimization-Total-Bytes-Saved
X-CF-Powered-By
X-NWS-UUID-VERIFY
X-LAGOON
X-Sn-Servicetimems
X-Ocache
X-Cdn-Origin
X-Cache-Grace
X-Device-Os
X-Pf-Uncompressing
Hostname
Geoip-City
Geoip-Latitude
Memory
ProcessTime
X-Cdn-Forward
X-BACKEND-TTL
A
X-Via-CDN
On-Server
X-B3-Parentspanid
X-NGINX-Cache
X-Request-Host
X-MSEdge-Features
TTL
PICS-Label
GeoIp-Country-Code
X-MSEdge-Flight
Cloudfront-Viewer-Country
X-COUNTRY
X-Vcl-Version
X-Correlation-ID
X-Server-IP
X-Unique-ID
X-Servedbyhost
X-Litespeed-Cache
X-Webkit-CSP
X-B3-SpanId
X-Varnish-Ttl
X-Rocket-Nginx-Bypass
X-Varnish-URL
Dnion-Transfer-Encoding
Resin-Trace
Cdn
XServer
X-TIME
M-TraceId
Media-Length
SN
Tcn
X-HS-Status
X-Cdn-Request-ID
X-FORWARDED-FOR
X-Action
X-ServedByHost
Host-ID
X-Slack-Backend
CACHE
X-Ratelimit-Remaining
HostName
X-RPS
X-RSL
Arc-Country
Pramga
X-Dispatch
X-Processor
X-PAYTM-SRV-ID
Who
X-RPM
X-DB
X-Beluga-Response-Time
X-Beluga-Record
X-Beluga-Node
X-Beluga-Cache-Status
X-Beluga-Status
X-Beluga-Trace
X-DSS
X-DI
X-Server-Time
X-DW
X-Cache-FS-Status
X-Cache-Ttl
X-Via-Ucdn
X-Skip-Cache
X-ND-Cache
X-Fastly-Country-Code
X-Reqid
Cdn-Host
X-Edge-Server
X-Sucuri-Id
GeoIP-Country-Code
NtCoent-Length
Pics-Label
X-VCL-Version
Fastly-Drupal-HTML
X-AIR-PT
Cdn-Request-Time
X-Served-From
Esi-Enabled
X-DC
Section-Origin-Responded
X-Dynatrace-Js-Agent
Section-Io-Id
Section-Io-Origin-Status
Section-Io-Origin-Time-Seconds
X-Policy
X-ABtesting
X-Varnish-Url
X-DevSite-Last-Modified
GeoIP-City
X-Planisys-CDN-Rules
X-Hello
GeoIP-Latitude
Amp-Access-Control-Allow-Source-Origin
N-Cache
X-Planisys-CDN-Cache
X-VarnishDD-TTL
X-Flog
X-Planisys-CDN-TTL
X-Bc-Bl
Ttl
CF-Cached-On
X-Oracle-Dms-Rid
X-LiteSpeed-Cache-Control
Fusion-Deployment-Id
MIME-Version
X-Bc
X-PF-Uncompressing
X-Request-Start
X-Zone
X-Azure-Ref-OriginShield
X-FPC
Rt-Proxy-Cache
X-Newrelic-App-Data
X-Backend-Host
X-APP
X-Ratelimit-Limit
X-HostName
X-Ruxit-Js-Agent
Trailer
Cache-Cookie-Set-Lfrom
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-From
X-PJAX-URL
X-Adobe-Source
X-SRV
X-Fastly-Backend-Reqs
WebServer
X-Swift-Error
X-Dynatrace
Magicmarker
X-Method
Processtime
X-Scheme
X-Amzn-Remapped-Connection
X-BE
X-Fmm-Version
X-Amzn-Remapped-Date
Cteonnt-Length
Servername
X-ZONE
FSS-Cache
X-WA
X-Fpc
X-ID
X-BC
FSS-Proxy
Cache-Provider
X-Frame-Option
X-WR-MODIFICATION
Requestid
X-SN
X-StackifyID
X-Branch-Name
Dynatrace
X-LB-ID
CF-IPCountry
L
X-Snapshot-Date
Ohc-Response-Time
CDN
X-Esi-Check
X-Cache-Id
X-CACHE-AGE
Lb
X-Svr
Sid
X-Tid
WZWS-RAY
X-Apw-Access-Token
X-Be
X-App
X-Apw-Access-Object
V-Cache
X-Apw-Access-Action
X-Apw-Hits
Warning
X-VC
X-SD-PageType
D-Cc-Upstream
X-Cc-Req-Id
X-Aicache-OS
X-Gzip
X-Cache-NGX
X-Fastly-Cache-Hits
X-Cc-Via
X-Request-Url
X-SB
SD-X-WS
X-Compress-Hint
Release
X-Litespeed-Cache-Control
Load-Balancing
X-Node-ID
X-VCT
X-Instart-Info
SID
LB
X-GEO
X-ElasticPress-Search
X-Check-Cacheable
X-Worker
X-Request-URL
X-Powered-Y
WP-Super-Cache
X-Varnish-Beresp-TTL
Backend-Name
X-WPE-Loopback-Upstream-Addr
Vix-Hermes-Req-Id
Lfy
Correlation-Id
X-Fastly-Cache-Status
Cneonction