Threat Level: green Handler on Duty: Renato Marinho

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
X-Content-Type-Options
Accept-Ranges
Last-Modified
X-XSS-Protection
X-Powered-By
Pragma
CF-Cache-Status
CF-RAY
Link
ETag
Expect-CT
Via
X-Cache
Age
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
P3P
X-Cache-Hits
X-Amz-Cf-Pop
X-Amz-Cf-Id
Referrer-Policy
X-UA-Compatible
X-Served-By
X-Varnish
Alt-Svc
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Download-Options
X-Request-Id
X-AspNet-Version
Access-Control-Allow-Credentials
X-Runtime
X-Drupal-Cache
X-Adblock-Key
X-Check
X-Cache-Status
X-Generator
Content-Security-Policy-Report-Only
X-Permitted-Cross-Domain-Policies
X-Request-ID
X-Cacheable
X-Template
X-Language
Timing-Allow-Origin
X-Iinfo
X-DNS-Prefetch-Control
X-AspNetMvc-Version
X-Ua-Compatible
X-FRAME-OPTIONS
X-Buckets
Status
X-Content-Security-Policy
X-CDN
Content-Encoding
Upgrade
Access-Control-Expose-Headers
Access-Control-Max-Age
X-Xss-Protection
X-Kinja-Server-Push
Keep-Alive
X-Turbo-Charged-By
X-Drupal-Dynamic-Cache
P3p
Xkey
X-Pass-Why
X-Cache-Group
X-AH-Environment
X-Envoy-Upstream-Service-Time
CF-Ray
X-Backend
X-Age
X-Server
X-Via
X-Amz-Request-Id
X-Amz-Id-2
X-Server-Powered-By
X-Robots-Tag
X-Page-Speed
X-Pingback
EagleId
X-Ws-Request-Id
X-Proxy-Cache
X-Nginx-Cache-Status
X-UA-Device
X-Hacker
Request-Context
X-Varnish-Cache
Feature-Policy
Server-Timing
Grace
Cf-Railgun
X-Swift-SaveTime
X-Swift-CacheTime
X-Amz-Version-Id
Ali-Swift-Global-Savetime
X-Dns-Prefetch-Control
X-LiteSpeed-Cache
Report-To
X-Server-Id
X-Rq
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-WebKit-CSP
X-Host
X-Device
EagleEye-TraceId
X-OneAgent-JS-Injection
X-Origin-Cache
X-Response-Time
Content-Location
X-Ac
X-Node
Surrogate-Control
X-Vhost
X-Readtime
Request-Id
X-Cloud-Trace-Context
X-Backend-Server
X-Dispatcher
X-Origin-Upstream-Status
X-Cnection
X-HW
X-Application-Context
X-ORACLE-DMS-ECID
X-DataDome
Fusion-Component-Id
Fusion-Template-Id
Fusion-Source
Fusion-Content-Id
Fusion-Content-Source
X-ORACLE-DMS-RID
X-Cache-Lookup
NEL
X-Mod-Pagespeed
Edge-Control
Rating
X-Rack-Cache
X-Country
X-Akam-SW-Version
X-Clacks-Overhead
Pinterest-Generated-By
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-Ruxit-JS-Agent
Accept-Ch
X-Varnish-TTL
X-DynaTrace
X-Country-Code
Allow
X-Instart-Request-ID
X-Goog-Hash
X-PC
X-TtlSet
X-Vname
X-FTR-Request-ID
X-TTL
X-ESI
Accept-Ch-Lifetime
Verso
X-Powered-By-Plesk
Service-Worker-Allowed
X-Url
Content-MD5
X-B3-TraceId
X-Forwarded-Proto
X-Version
X-MS-InvokeApp
X-GitHub-Request-Id
X-Exp-Id
X-Kinja-Build
X-GoogleNews-Bot
X-Kinja-Revision
X-Kinja-Server
X-Kinja
X-Cdn-Fetch
X-Exp-Variant
X-Use-Magma
Edge-Cache-Tag
AR-ATIME
Ar-Sid
RTSS
AR-CACHE
AR-PoweredBy
AR-Request-ID
X-Px
X-D2id
X-Debug
X-Abt-Application-Version
X-Server-Name
Charset
SPRequestGuid
X-NF-Request-ID
X-Amz-Server-Side-Encryption
X-Vcache
X-Accel-Expires
X-Cached
X-MSEdge-Ref
X-Powered-CMS
X-Amz-Rid
X-TEC-API-ORIGIN
Response
Pagespeed
Display
X-TEC-API-VERSION
X-Middleton-Display
X-Middleton-Response
X-TEC-API-ROOT
X-Sol
Arr-Disable-Session-Affinity
X-Vcap-Request-Id
X-Fastcgi-Cache
X-Navigation-Version
X-Pinterest-Rid
Pinterest-Version
X-SharePointHealthScore
X-Trace
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Cdn
X-VARITI-CCR
Realpath
TCN
Public-Key-Pins
Cache-Tag
X-Client-IP
Access-Control-Request-Method
X-Fastly-Request-ID
X-Ser
S
MS-Author-Via
X-Upstream
X-DynaTrace-JS-Agent
X-Shard
SPIisLatency
SPRequestDuration
X-Id
Nginx-Cache
X-Ezoic-Cdn
X-Hp-Webp
X-B3-TraceId-Primal
Mrf-Cache-Status
MRF-Tech
X-Mrf-Section-Lastmod
X-Mrf-Item-Lastmod
X-Content-Type
X-Forwarded-For
X-T
X-Amzn-Trace-Id
X-Amz-Meta-S3cmd-Attrs
Nel
X-Grace
DynaTrace
X-Recruiting
Front-End-Https
X-Hits
X-Aspnet-Version
Fastcgi-Cache
X-Varnish-Age
ServerID
X-DIS-Request-ID
X-Edge-O15-RID
MicrosoftSharePointTeamServices
X-Dw-Request-Base-Id
X-Mobile-URL
X-Element-Page-Cache
X-Node-Name
NR-ENABLED
X-Content-Digest
X-HS-Hub-Id
X-HS-Cache-Config
X-HS-Combine-CSS
X-HS-Content-Id
X-Country-Code-Real
X-FTR-Cache-Status
X-FTR-Expires
Powered
X-Frontend
X-Goog-Stored-Content-Length
X-Goog-Storage-Class
X-GUploader-UploadID
X-Goog-Stored-Content-Encoding
X-Goog-Metageneration
X-Goog-Generation
X-Cache-TTL
Server-Name
X-FTR-Backend-Server
X-FTR-Backend
X-FTR-Balancer
X-FTR-DC
X-FTR-Realm
Alternate-Protocol
TP-L2-Cache
X-Logged-In
TP-Cache
Server-Node
X-Jurisdiction
X-Correlation-Id
X-Webkit-Csp
X-Request-Received
X-Request-Processing-Time
X-Request-Handler-Origin-Region
X-Microsite
AMP-Access-Control-Allow-Source-Origin
Backend-Timing
Upgrade-Insecure-Requests
X-ATS-Timestamp
X-Server-ID
X-XRDS-LOCATION
X-Page-Id
X-Content-Options
X-Origin-Server
X-Content-Security-Policy-Report-Only
X-Cache-Hit
Refresh
X-Akamai-Edgescape
X-Revision
X-Rid
X-User-Agent
X-F-Cache
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Type
X-Varnish-Grace
X-Shield-Request-Id
X-XRDS-Location
X-Webapp-Samesite-None-Activated-N
Fastly-Restarts
X-Zen-Fury
X-Content-Powered-By
X-LB-Cache
X-B3-Sampled
X-Geo-Country
X-URL
X-Activity-Id
X-B
X-AppVersion
X-Az
X-N
X-Pad
X-Analytics
X-CST
X-FTR-Cache-Host
X-Kinsta-Cache
PB-RID
PB-PID
X-Ruxit-Js-Agent
X-Mobile-Rewrite
X-RateLimit-Remaining
Arc-Version
Cache-Status
X-Cache-Age
X-TT
X-AOL-HN
X-Instance
X-WebKit-CSP-Report-Only
X-Debug-Info
X-Framework
X-B-Cache
DC
Actual-Object-TTL
X-Time
Paypal-Debug-Id
X-App-Environment
X-Request-Guid
X-Jobs
X-Tumblr-Pixel
X-Tumblr-User
X-Signature
X-Tumblr-Pixel-0
Access-Control-Allow-Method
X-FB-Debug
X-PHP-Backend
X-Cache-Action
X-Load-Cache
Surrogate-Key
X-Git-Hash
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Ttl
X-Varnish-Backend
X-Cached-By
Fastcgi-Useragent
Host-Header
X-Tt-Trace-Tag
X-Contextid
X-IPLB-Instance
X-Amz-Replication-Status
X-Tt-Trace-Host
MS-CV
FilterID
X-SS-Set-Cookie
X-Cluster
X-ATG-Version
Tracecode
X-Cache-Key
NGB
X-Accel-Buffering
X-Response-Served-From
X-WA-Info
X-Srv
WPE-Backend
Frame-Options
X-Cache-NE
X-Varnish-Server
Payment
X-Region
Host
X-Mobile
X-Host-Name
X-FW-Server
X-FW-Static
Xserver
Eomportal-Instance
X-FW-Type
X-FW-Serve
X-FW-Hash
X-Cache-2
X-Adobe-Content
X-Tumblr-Pixel-1
X-Cache-Enabled
X-Varnish-Hostname
X-Cache-Operation
Source
X-Adobe-Loc
X-Kong-Proxy-Latency
X-Tumblr-Pixel-2
X-Cacheable-TTL
X-RequestSource
X-Kong-Upstream-Latency
X-Cache-Rule
X-Is-Bot
X-Rendered-As
Filters
X-GeoIP
Cache-Tv-Group
X-IPS-LoggedIn
X-Oneagent-Js-Injection
X-TX-ID
X-NewRelic-App-Data
X-EdgeConnect-Cache-Status
Cleartype
X-Via-JSL
X-Seen-By
X-Origin-Response-Time
X-ORACLE-APMCS-REQUEST-ID
X-Cache-TTL-Remaining
X-ORACLE-APMCS-TAG
X-FastCGI-Cache
X-VCache
X-Hostname
Cache
Retry-After
X-Presslabs-Stats
Server-Info
X-HTML-Minification-Powered-By
X-B3-Traceid
X-Cache-Control
X-RemovedCookies
X-ProcessESI
Datacenter
Healthy
X-Dc
X-UA
Ms-Operation-Id
X-RTag
X-PressLabs-Stats
X-NWS-LOG-UUID
Liferay-Portal
X-Source
X-RateLimit-Limit
X-FireWall-Port
From-Origin
X-Cache-Server
X-L-Path
X-Environment-Context
X-Upgrade-Enabled
X-Trafficlayer-App-Name
X-Trafficlayer-App-Scope
X-CACHE-KEY
X-Rule
X-Endurance-Cache-Level
X-Status
Version
X-Wix-Request-Id
X-Handled-By
X-App-Server
X-Path-Route
X-Cache-Var
X-Cache-Var-Map
X-ES-SERVER
Meta-Geo
X-RN-RSRV
X-Request-Time
X-Access
Selected-Fe
X-Proxy-Build
X-Section
X-Format
X-Timing-Wait
X-Tb
OT-Force-Account-Verify
Mn-Server-Ip
X-Akamai-Request-ID
X-Alternate-Cache-Key
X-Backend-Name
Cache-Tags
Azure-SiteName
Akamai-GRN
X-Storage
Azure-InstanceId
Azure-RegionName
Azure-SlotName
X-BYPASS-REASON
Azure-Version
X-Goog-Meta-Goog-Reserved-File-Mtime
X-ShardId
X-ProxyCache-Status
X-ShopId
X-Shopify-Generated-Cart-Token
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-ProxyCache-Key
X-Proto
Accept-CH
X-EIG-Tracking-Id
X-Human
X-OCL
X-PCL
X-Origin
X-Content-Age
X-Shopify-Stage
S-Rt
Property-Id
Origin-Edge-Control
Origin-Cache-Control
TWC-Connection-Speed
TWC-Device-Class
TWC-Locale-Group
TWC-GeoIP-LatLong
TWC-GeoIP-Country
Node
NGX
Decoy-Debug-Status
Decoy-Debug-Key
DB-Nickname
X-RCS-CacheZone
Decoy-Debug-TTL
X-Qloud-Router
X-Proxy-Cache-Status
X-Pubstack
Ec-Rule-Version
TWC-Privacy
Webcakes-App-Name
X-Hyper-Cache
X-Hosted-By
X-Hl-Ver
X-Generated-By
X-JoinUs
X-Origin-Hint
X-NYM-Debug-Backend
X-MP-GENERATED-AT
X-LJ-Flow-ID
X-FW-Dynamic
X-FC-Vary-Parameters
X-Proxy
X-Akamai-Request-ID2
Webcakes-Region
Webcakes-App-Version
X-AWS-Id
X-Cache-Config
X-Debug-Cache
X-Cluster-Node
X-Cache-Host
X-Redis-Cache
Now
X-Yottaa-Optimizations
X-Yottaa-Metrics
X-Viewer-Country
X-ServerID
X-Web-Node
X-VWS-Id
X-Vgn-Hpd-Reason
X-Soup
X-UUID
X-SaId
X-Time-Microsecs
X-BCube-Filmed-By
X-Xfnlog-Site
X-Www-Served-By
X-Locale
X-Site-Version
X-Generated
X-CCM
X-IP
X-Detected-As
X-Varnish-Hits
X-Say-Cacheable
Cross-Origin-Window-Policy
X-SayCDN-TTL
X-Say-TTL
X-TNCMS
X-Loop
X-R9-Blue-Green-Version
X-FB-TRIP-ID
L5d-Success-Class
X-Amzn-Remapped-Content-Length
X-APP-VERSION
Srv
X-Akamai-Transformed
Accept-Charset
Cache-Name
X-CS
Viewport
Uber-Trace-Id
GEO-INFO
X-NCache
X-Esi
X-Drupal-Cache-Tags
Webserver
Accept-CH-Lifetime
Time
X-UA-Device-Type
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Cache-Remote
X-From
Cache-Key
X-Unique-Id
Mime-Version
X-Drupal-Cache-Contexts
X-TT-TIMESTAMP
X-Cluster-Name
X-Origin-CC
X-Origin-TTL
Accept-Language
X-Edge-Location
X-Backend-TTL
Country
X-CDN-Forward
X-Mode
X-Forwarded-Host
Odigeo-Trace-Id
X-Microcachable
Rt-Fastcgi-Cache
X-EC-Lua
X-CLOUD-TRACE-CONTEXT
X-Info
X-UnsetCookies
X-B3-Spanid
X-Newrelic-Synthetics
X-Whom
X-Geo
X-Varnish-Cache-Hits
X-Magnolia-Registration
X-PERF
X-ApacheServer
X-No-Session
Proxy-Connection
ServedBy
Content-Disposition
Ohc-File-Size
Ohc-Cache-HIT
X-UPSTREAM-Address
X-App-Version
Geo-Info
X-NGENIX-Cache
X-PHP-Host
X-Device-Type
X-Zipkin-Id
Cf-Ipcountry
X-Labrador-Cache-Channel
X-Proxied
X-Routing-Service
Content-Script-Type
Content-Style-Type
T-Server
Apple-News-Services-Request-Url
AsisCache
BehaviorPad-Version
Fastcgi-X-Cache-Version
X-Destination
X-DPWN-IS-SECURE
MD5-Digest
X-External-Request-Id
Meta-Geo-Continent
X-G
Machine
GEO-REGION-INFO
X-Geo-Header
Rendered-Blocks
Apple-News-Services-Parsed-Url
X-Date
X-Accel-Expires-Debug
X-Twitter-Response-Tags
W
X-A
X-A-Ccd
X-A-Dgt
X-A-Wwc
X-A-Dam
Xc-Version
VivaBuild
X-A-Dcw
X-Request-UUID
Apple-News-Services-Handled
X-D
X-Aed
Viewtype
X-Via-Fastly
Apple-News-Services-Host
X-VG-WebCache
X-Sigma
X-Session-Fingerprint
X-Sigma-Backend
X-ScT
X-SRCache-Key
Mobile-Detection-Method
X-B-Cookie
X-Vdms-Version
X-CF-Lambda-Fn
X-Transaction
X-VG-WebServer
X-CF-Lambda-Version
X-S
X-Real-IP
X-Connection-Hash
X-ARC
X-Vtex-Processado-Em
X-Application
X-Rocket-Build-Number
X-Rojux
X-VG-TLSProxy
X-Rewrite-Enabled
X-S-Cookie
X-Region-Sid
X-Trv-Group
X-Vtex-Remote-Cache
X-C
X-Nc
X-TA-CDN-Provider
X-Uri
X-Cache-Time
User-Cache-Control
Server-Surrogate-Control
X-GeoIP-Country-Code
X-Cache-Debug
CDCHOST
X-Hit
X-CGP
Powered-By
Locid
X-Render-Time
X-TrackingId
X-Eu-Site
X-Epic-Correlation-Id
IsBot
X-Distil-CS
Fastly-Soc-X-Request-Id
Server-Cache-Control
X-Developers
Gh-Request-Id
HA-Ipaddr
Ha-Gx-Prefs
Environment
X-CUA
X-SIPLIST1
X-Agile-Id
X-Sucuri-Cache
X-WebServer
X-Contensis-Viewer-Groups
X-Logging-Id
X-Wikidot-Static-Cache
X-Agile
X-Wikidot-Backend
X-Bip
X-Agile-Age
X-Varnish-Authentication
X-Auto-Login
Fastly-SSL
X-Thanos
X-App-Name
X-Backend-State
X-Tumblr-Pixel-3
X-Cache-ASPX
X-VC-Cache
HitType
Access-Control-Request-Headers
X-GoCache-CacheStatus
RNT-Time
RNT-Machine
X-Distributor
X-AK-Request-ID
X-Clientip
X-Cms-Context
X-Clara-WADP
X-Azure-Ref
Request-EU
Request-Country
X-BBXSRF
X-Dispatcher-Server
X-Cdn-Srv
X-Cache-Info
X-Cache-URL
We-Hiring
X-Debug-Cache-Fetch
X-Webstats-RespID
X-Debug-Cache-Expiry
X-Cache-Bucket
X-Core-Mission
X-Cache-Backend
True-Client-Country-4JS
X-Debug-Cache-Store
X-Block-Status
X-Debug-Log
V-Age
Wxu-Next-Hostname
Section-Io-Cache
Server-ID
Server-Int
Web-Mar-Node
Wxu-Next-Commit
X-Debug-Cookies
X-We-Are-Hiring
Wxu-Next-Region
X-Nginx-Cache-Key
X-WADP-Cache
X-Ms-Version
X-Ms-Request-Id
X-TH-Server
X-Swa-Ws
X-SVT-ORM-RULES
X-SVT-ORM-VERSION
X-Micro-Cache
X-Location
X-Fastly-Cache
X-Li-Pop
X-Li-Fabric
X-LI-UUID
X-Varnish-Beresp-Ttl
X-Varnish-Beresp-Grace
X-Varnish-Beresp-Status
X-NodeID
X-NX-Host
X-Rebelmouse-Cache-Control
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Rebelmouse-Surrogate-Control
X-Req
X-Trace-Id
X-Request-URI
X-Proxy-Upstream
X-Owner
X-Daa-Tunnel
X-VServer
X-TT-LOGID
X-Origin-Date
X-Origin-Expires
X-OVcl-Cache
X-OVcl
X-Key
X-LI-Proto
Countrycode
X-GeoIP-City
X-Generated-In
Country-Code
Cdnsip
X-Gen-Mode
Cdncip
Kp-EeAlive
Fastly-Backend-Name
Heartbleed
IBM-Web2-Location
X-Generation-Time
FNAC-ModuleRouting
Fastly-SIE
Fastly-SWR
Locale
Cache-Host
X-Urbn-Site-Id
X-Urbn-Context-Path
Mail-Subject
X-Irp-Debug
X-User
Memcached
X-FW-Version
X-Instart-Isnd
X-IN-APIGATEWAYSSL
AKAMAI
X-Hash
X-IN-APIGATEWAY
X-Gamma-Serve
X-Hnp-Log
X-Reboot
X-Platform-Server
X-Trafficlayer-App-Version
X-Generated-On
X-NU-AKA-ACS-Version
X-Matched-Rule
X-Internal-Host
X-Level-Front-Cache
X-Is-Gdpr
X-Core-Value
X-Has-Esi
X-Service
X-ServiceProvider
X-JWT-State
X-Thinkindot-L3
X-Old-Content-Length
ServerName
Adler-Geo
Server-Host
X-Fetched-On
Is-Eu
X-Server-W
PFcat
Platform
Thinkindot-CacheControl-Type
Thinkindot-CacheControl
X-Nginx-Cache
Thinkindot-Control
X-Up
X-Cache-Tags
X-Variation
X-B3-Parentspanid
X-S-Maxage
X-Response-By
X-Servername
X-Lb-Id
X-Refresh
X-SERVER
Cache-Hits
RequestId
X-B3-SpanId
Filterid
X-Cdn-Forward
X-CF-Powered-By
X-Tec-Api-Root
X-Tec-Api-Origin
X-Air-Hostname
X-Tec-Api-Version
ProcessTime
X-Server-IP
X-Tb-Optimization-Total-Bytes-Saved
X-Parent-Response-Time
X-CSRF-TOKEN
Group
X-Cache-Expired-At
Pragrma
X-Var-Ttl
X-Pjax-Url
Memory
X-BACKEND-TTL
X-CSRF-Token
X-Unique-ID
X-Cdn-Request-ID
X-NC
Media-Length
X-Wa
User-Agent
Origin
X-Sucuri-Id
S-Cnection
X-Pf-Uncompressing
TTL
Powered-By-ChinaCache
Geoip-Latitude
SRV
X-Correlation-ID
X-Ua
GeoIp-Country-Code
X-Vcl-Version
Tcn
X-COUNTRY
X-NGINX-Cache
X-Reqid
Geoip-City
PICS-Label
X-AIR-PT
SN
Esi-Enabled
X-Varnish-Cacheable
X-Rocket-Nginx-Bypass
X-Sucuri-ID
X-Litespeed-Cache
X-Via-CDN
X-Webkit-CSP
X-Servedbyhost
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Planisys-CDN-TTL
X-Policy
X-NWS-UUID-VERIFY
X-Request-Start
X-HS-Status
M-TraceId
Dnion-Transfer-Encoding
X-Azure-Ref-OriginShield
X-Via-Ucdn
X-Developer
XServer
X-TIME
HostName
X-Ocache
X-Sn-Servicetimems
Rt-Proxy-Cache
X-Device-Os
X-Cdn-Origin
X-Node-Id
X-LAGOON
X-Cache-Grace
X-FORWARDED-FOR
X-Fastly-Country-Code
On-Server
X-MSEdge-Flight
X-Cache-Ttl
A
X-Request-Host
X-MSEdge-Features
Magicmarker
Cdn
X-Method
X-ServedByHost
Who
Resin-Trace
X-Ftr-Cache-Host
X-VHOST
Pics-Label
Cloudfront-Viewer-Country
CF-Cached-On
X-Cache-Status-Check
Load-Balancing
X-Beluga-Cache-Status
Hostname
X-Beluga-Response-Time
X-Beluga-Node
X-APP
X-Beluga-Record
X-Beluga-Status
X-Beluga-Trace
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Oss-Request-Id
X-Oss-Server-Time
X-Oss-Storage-Class
X-VCL-Version
GeoIP-Country-Code
X-Zone
DSUID
X-Svr
X-Bc
X-Be
NtCoent-Length
Ohc-Response-Time
X-Oracle-Dms-Rid
Release
X-MServer
X-VCT
MIME-Version
Vix-Hermes-Req-Id
X-HostName
GeoIP-Latitude
Cteonnt-Length
X-VarnishDD-TTL
X-Varnish-URL
X-Varnish-Url
Ttl
X-Fastly-Backend-Reqs
Host-ID
X-Ratelimit-Remaining
X-Hp-Ccpa-Warning
X-LiteSpeed-Cache-Control
X-Varnish-Ttl
X-DC
X-PF-Uncompressing
GeoIP-City
X-Newrelic-App-Data
X-Configured-By
X-Slack-Backend
X-SRV
WebServer
X-Ftr-Request-Id
Amp-Access-Control-Allow-Source-Origin
X-PJAX-URL
CACHE
X-RPM
X-RPS
X-RSL
X-DW
X-Swift-Error
X-Action
X-Dynatrace
X-DB
X-DI
X-DSS
X-BE
Processtime
X-Upstream-Ct
X-Tid
X-Aicache-OS
SD-X-WS
X-Upstream-Ht
X-SD-PageType
X-WR-MODIFICATION
X-Dynatrace-Js-Agent
Servername
X-Ratelimit-Limit
Cache-Provider
L
X-Cache-FS-Status
X-Compress-Hint
Pramga
X-ID
X-Dispatch
X-PAYTM-SRV-ID
Arc-Country
X-Skip-Cache
X-FPC
X-SN
X-Server-Time
X-Cache-Id
X-Processor
X-Frame-Option
X-Ftr-Backend
X-Ftr-Backend-Server
X-ABtesting
X-Ftr-Dc
X-Via-NSCOPI
X-ServerName
X-Release
Fastly-Drupal-HTML
X-DevSite-Last-Modified
X-StackifyID
X-Flog
X-Ftr-Balancer
CF-IPCountry
X-Snapshot-Date
X-LB-ID
Requestid
X-Branch-Name
CDN
X-Fastly-Cache-Hits
X-Hello
X-Ftr-Realm
Dynatrace
X-ND-Cache
Pagetype
Lfy
X-CACHE-AGE
X-Cc-Via
X-Cc-Req-Id
X-WA
X-Apw-Access-Object
X-Apw-Access-Token
X-Apw-Hits
X-Scheme
Proxy-Firewall
Warning
Cdn-Request-Time
X-Request-Url
X-Apw-Access-Action
X-Varnish-Beresp-TTL
LB
Cdn-Host
D-Cc-Upstream
N-Cache
X-VC
V-Cache
X-Edge-IP
X-ZONE
X-Edge-Server
X-SB
X-Served-From
X-Amzn-Remapped-Date
X-Amzn-Remapped-Connection
X-Bc-Bl
UCS
Cache-Cookie-Set-From
X-Worker
Lb
X-BC
Backend-Name
X-App
Correlation-Id
Cache-Cookie-Set-Idcheck
Cache-Cookie-Set-Lfrom
X-Node-ID
X-Check-Cacheable
X-Request-URL
X-Powered-Y
WP-Super-Cache
X-ElasticPress-Search
X-Fastly-Cache-Status